netfilter: nf_tables: remove nhooks field from struct nft_af_info
authorPablo Neira Ayuso <pablo@netfilter.org>
Tue, 19 Dec 2017 12:53:45 +0000 (13:53 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 10 Jan 2018 14:32:04 +0000 (15:32 +0100)
We already validate the hook through bitmask, so this check is
superfluous. When removing this, this patch is also fixing a bug in the
new flowtable codebase, since ctx->afi points to the table family
instead of the netdev family which is where the flowtable is really
hooked in.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/net/netfilter/nf_tables.h
net/bridge/netfilter/nf_tables_bridge.c
net/ipv4/netfilter/nf_tables_arp.c
net/ipv4/netfilter/nf_tables_ipv4.c
net/ipv6/netfilter/nf_tables_ipv6.c
net/netfilter/nf_tables_api.c
net/netfilter/nf_tables_inet.c
net/netfilter/nf_tables_netdev.c

index dd238950df81d526f50885362e8af5da7498a01b..536aaec96a07dcc2629c3c1a83d8804add5527a0 100644 (file)
@@ -973,7 +973,6 @@ enum nft_af_flags {
  *
  *     @list: used internally
  *     @family: address family
- *     @nhooks: number of hooks in this family
  *     @owner: module owner
  *     @tables: used internally
  *     @flags: family flags
@@ -981,7 +980,6 @@ enum nft_af_flags {
 struct nft_af_info {
        struct list_head                list;
        int                             family;
-       unsigned int                    nhooks;
        struct module                   *owner;
        struct list_head                tables;
        u32                             flags;
index 86774b5c3b731747a7194c20a3ace058464d66e8..66c97b1e3303664fea77262ad905bdd9bd1310bf 100644 (file)
@@ -44,7 +44,6 @@ nft_do_chain_bridge(void *priv,
 
 static struct nft_af_info nft_af_bridge __read_mostly = {
        .family         = NFPROTO_BRIDGE,
-       .nhooks         = NF_BR_NUMHOOKS,
        .owner          = THIS_MODULE,
 };
 
index f84c17763f6f24c0fb34c38bdc585fe2a242042d..f9089b2ad90533d40f6636de3f0fc25e406705c1 100644 (file)
@@ -29,7 +29,6 @@ nft_do_chain_arp(void *priv,
 
 static struct nft_af_info nft_af_arp __read_mostly = {
        .family         = NFPROTO_ARP,
-       .nhooks         = NF_ARP_NUMHOOKS,
        .owner          = THIS_MODULE,
 };
 
index f4675253f1e64102129077f86b347b9b78c6a606..a98f2de63771f13e7a117294858f5ccb74b98efe 100644 (file)
@@ -32,7 +32,6 @@ static unsigned int nft_do_chain_ipv4(void *priv,
 
 static struct nft_af_info nft_af_ipv4 __read_mostly = {
        .family         = NFPROTO_IPV4,
-       .nhooks         = NF_INET_NUMHOOKS,
        .owner          = THIS_MODULE,
 };
 
index 9cd45b964123512335eddfddb0f4ea513d6f84f4..bddd39dc1cf3983a2c5329790a24e62ae3b53506 100644 (file)
@@ -30,7 +30,6 @@ static unsigned int nft_do_chain_ipv6(void *priv,
 
 static struct nft_af_info nft_af_ipv6 __read_mostly = {
        .family         = NFPROTO_IPV6,
-       .nhooks         = NF_INET_NUMHOOKS,
        .owner          = THIS_MODULE,
 };
 
index 336b81689ac915d20d93f9ffc3e50bb09d6ce980..93e4e67e4b4dcc1323ba97c713cb3e329642d850 100644 (file)
@@ -1328,9 +1328,6 @@ static int nft_chain_parse_hook(struct net *net,
                return -EINVAL;
 
        hook->num = ntohl(nla_get_be32(ha[NFTA_HOOK_HOOKNUM]));
-       if (hook->num >= afi->nhooks)
-               return -EINVAL;
-
        hook->priority = ntohl(nla_get_be32(ha[NFTA_HOOK_PRIORITY]));
 
        type = chain_type[afi->family][NFT_CHAIN_T_DEFAULT];
@@ -4993,7 +4990,7 @@ static int nf_tables_flowtable_parse_hook(const struct nft_ctx *ctx,
                return -EINVAL;
 
        hooknum = ntohl(nla_get_be32(tb[NFTA_FLOWTABLE_HOOK_NUM]));
-       if (hooknum >= ctx->afi->nhooks)
+       if (hooknum != NF_NETDEV_INGRESS)
                return -EINVAL;
 
        priority = ntohl(nla_get_be32(tb[NFTA_FLOWTABLE_HOOK_PRIORITY]));
index 58b9be7480bbd3d2a3454fa85270bc64c9383e53..00b1fc9cea2e8cce3243002b51195b4b89a77683 100644 (file)
@@ -40,7 +40,6 @@ static unsigned int nft_do_chain_inet(void *priv, struct sk_buff *skb,
 
 static struct nft_af_info nft_af_inet __read_mostly = {
        .family         = NFPROTO_INET,
-       .nhooks         = NF_INET_NUMHOOKS,
        .owner          = THIS_MODULE,
 };
 
index 42f6f6d42a6d1a05f02050333beb8dcb0919e39f..3da3dc7de9455357c408d47f4fe7004db29fe188 100644 (file)
@@ -40,7 +40,6 @@ nft_do_chain_netdev(void *priv, struct sk_buff *skb,
 
 static struct nft_af_info nft_af_netdev __read_mostly = {
        .family         = NFPROTO_NETDEV,
-       .nhooks         = NF_NETDEV_NUMHOOKS,
        .owner          = THIS_MODULE,
        .flags          = NFT_AF_NEEDS_DEV,
 };