diff options
| author | Tamaki Yanagawa <ty@000ty.net> | 2026-07-03 16:22:57 +0000 |
|---|---|---|
| committer | Florian Westphal <fw@strlen.de> | 2026-07-08 15:33:37 +0200 |
| commit | e6107a4c74b54cb33e3bce162a63048ae5a6b198 (patch) | |
| tree | 7eb26e84bfb0137112bcfc8fc943d82d1246c37d | |
| parent | 084d23f818321390509e9738a0b08bbf46df6425 (diff) | |
| download | linux-next-e6107a4c74b54cb33e3bce162a63048ae5a6b198.tar.gz linux-next-e6107a4c74b54cb33e3bce162a63048ae5a6b198.zip | |
netfilter: nft_lookup: fix catchall element handling with inverted lookups
nft_lookup_eval() decides whether a lookup matched (`found`) from the
direct set lookup and priv->invert before falling back to the
catchall element used by interval sets (e.g. nft_set_rbtree) for the
open-ended default range. Since `found` is never recomputed after
`ext` is replaced by the catchall lookup, inverted lookups
(NFT_LOOKUP_F_INV, "!= @set") can wrongly match or wrongly skip the
catchall element, producing the wrong verdict. Fold the catchall
lookup into `ext` before computing `found`, matching the order
already used by nft_objref_map_eval().
Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support")
Signed-off-by: Tamaki Yanagawa <ty@000ty.net>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Florian Westphal <fw@strlen.de>
| -rw-r--r-- | net/netfilter/nft_lookup.c | 10 |
1 files changed, 5 insertions, 5 deletions
diff --git a/net/netfilter/nft_lookup.c b/net/netfilter/nft_lookup.c index ba512e94b402..19887439847d 100644 --- a/net/netfilter/nft_lookup.c +++ b/net/netfilter/nft_lookup.c @@ -103,13 +103,13 @@ void nft_lookup_eval(const struct nft_expr *expr, bool found; ext = nft_set_do_lookup(net, set, ®s->data[priv->sreg]); + if (!ext) + ext = nft_set_catchall_lookup(net, set); + found = !!ext ^ priv->invert; if (!found) { - ext = nft_set_catchall_lookup(net, set); - if (!ext) { - regs->verdict.code = NFT_BREAK; - return; - } + regs->verdict.code = NFT_BREAK; + return; } if (ext) { |
