]> git.itanic.dy.fi Git - linux-stable/commit
netfilter: nf_tables: fix ct untracked match breakage
authorFlorian Westphal <fw@strlen.de>
Wed, 3 May 2023 10:00:18 +0000 (12:00 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 3 May 2023 11:49:08 +0000 (13:49 +0200)
commitf057b63bc11d86a98176de31b437e46789f44d8f
tree430d496c035af6d595a619ddca3b0f59fd002dc9
parent6a341729fb31b4c5df9f74f24b4b1c98410c9b87
netfilter: nf_tables: fix ct untracked match breakage

"ct untracked" no longer works properly due to erroneous NFT_BREAK.
We have to check ctinfo enum first.

Fixes: d9e789147605 ("netfilter: nf_tables: avoid retpoline overhead for some ct expression calls")
Reported-by: Rvfg <i@rvf6.com>
Link: https://marc.info/?l=netfilter&m=168294996212038&w=2
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_ct_fast.c