Received: by 2002:a05:6358:45e:b0:b5:b6eb:e1f9 with SMTP id 30csp3078669rwe; Mon, 29 Aug 2022 05:35:30 -0700 (PDT) X-Google-Smtp-Source: AA6agR5LGJybZteL8onw6e3j2G2SLMqQFi6dUCT3jW1AZW4T46pIKI5BLJW3/tnRhkln2aBesvSQ X-Received: by 2002:a17:902:f68d:b0:16f:2314:7484 with SMTP id l13-20020a170902f68d00b0016f23147484mr15947370plg.136.1661776530123; Mon, 29 Aug 2022 05:35:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1661776530; cv=none; d=google.com; s=arc-20160816; b=KiA/UuTgqR0ui2Dx3nZQfbYCQyOimD1HSDwkcvR1D3LOocVE/sqOA+HclDE6hY+Scf 8ztMJ5flz6Lg8TsqDItg9PF7Ywqb1n9/EuP/USrShOgZt6wFZ+mTnQigIOKEMyKz7L07 2zT37m3nNNhJgX+Be7SGEMvB18w0oLBawuU8a7QnZlOpPQ0GGkOIX6wYvBiWiYloXnWU ybL41GGWvkX1vOs5LIr4nsJZ+Ws7A/suwqzogp5JZOT90arVSk0xLc1ND+gQ/wR2hd1n f8tR2KRj+WRTXLwS3ABPN7vgr2MczvH51C4GhYTQZHng9AgxcIeJWeVbMydvw1OBrtSv fP4g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=O35swKcUk33914JHYIDDyJqHN5ppa0k1BEez0+EVmtA=; b=Xj02A1KNOddosUm9vHxT4fZUvAhaVJubZr9AgXIntfnLyRoLdM9BC3IH1OCKcLrd/k JDk5eVRU60PY+gakE8l/Pk2DM1S75qi+UkytaqwwvhXbM/ANS9v6jeUM1wMr4qB8Bf/1 DASYv6dL10qiLgKmKQm1zuNd/XLBiaq9WI9zkSHH4XbfiqmiQ3mlGrDkxStc6mR20Fnx OGd3IL0quTTygwv1WSGBQHblF/ZdmFnCqjD20qui1dT2uLoLdvEPsU0Gd5mf9OA5KKSU g5NRw3O88+XLmIKTreIu0aHzBfLXh/6LTqvyvqhRinGTOVZqCQGtWYwNkMb78y9r6hFD 5g9A== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=nXzSWpfw; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id d14-20020a621d0e000000b00534eb9da2e7si8691317pfd.304.2022.08.29.05.35.18; Mon, 29 Aug 2022 05:35:30 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=nXzSWpfw; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231855AbiH2LYw (ORCPT + 99 others); Mon, 29 Aug 2022 07:24:52 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:40844 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231824AbiH2LWo (ORCPT ); Mon, 29 Aug 2022 07:22:44 -0400 Received: from ams.source.kernel.org (ams.source.kernel.org [IPv6:2604:1380:4601:e00::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 8E850659CE; Mon, 29 Aug 2022 04:14:35 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ams.source.kernel.org (Postfix) with ESMTPS id 7FAAFB80DB5; Mon, 29 Aug 2022 11:14:32 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id E2EEDC433C1; Mon, 29 Aug 2022 11:14:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1661771671; bh=2Qd5Ik5nIknKsHU9CHRPsD8hGOXLnY9fX2gc9fd5pVQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=nXzSWpfwPGlBw2dAzo031R8srYyVazltNbs9YMX0lg4+NltphLaxwa8UlfSUh0m3M GZVddatEkjz3Yvdc2/1KnNh0bA1Vg/v+NfUc5S0Y4ay80HW12HHhByeKwzskoBUvQ9 PyAKFZb9A32QiplLrBTYtIXIMCqggSn+Ti5Cv8yg= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 5.19 059/158] netfilter: nf_tables: do not leave chain stats enabled on error Date: Mon, 29 Aug 2022 12:58:29 +0200 Message-Id: <20220829105811.188507964@linuxfoundation.org> X-Mailer: git-send-email 2.37.2 In-Reply-To: <20220829105808.828227973@linuxfoundation.org> References: <20220829105808.828227973@linuxfoundation.org> User-Agent: quilt/0.67 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-7.1 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_HI, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Pablo Neira Ayuso [ Upstream commit 43eb8949cfdffa764b92bc6c54b87cbe5b0003fe ] Error might occur later in the nf_tables_addchain() codepath, enable static key only after transaction has been created. Fixes: 9f08ea848117 ("netfilter: nf_tables: keep chain counters away from hot path") Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/netfilter/nf_tables_api.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c index e171257739c2f..b2c89e8c2a655 100644 --- a/net/netfilter/nf_tables_api.c +++ b/net/netfilter/nf_tables_api.c @@ -2195,9 +2195,9 @@ static int nf_tables_addchain(struct nft_ctx *ctx, u8 family, u8 genmask, struct netlink_ext_ack *extack) { const struct nlattr * const *nla = ctx->nla; + struct nft_stats __percpu *stats = NULL; struct nft_table *table = ctx->table; struct nft_base_chain *basechain; - struct nft_stats __percpu *stats; struct net *net = ctx->net; char name[NFT_NAME_MAXLEN]; struct nft_rule_blob *blob; @@ -2235,7 +2235,6 @@ static int nf_tables_addchain(struct nft_ctx *ctx, u8 family, u8 genmask, return PTR_ERR(stats); } rcu_assign_pointer(basechain->stats, stats); - static_branch_inc(&nft_counters_enabled); } err = nft_basechain_init(basechain, family, &hook, flags); @@ -2318,6 +2317,9 @@ static int nf_tables_addchain(struct nft_ctx *ctx, u8 family, u8 genmask, goto err_unregister_hook; } + if (stats) + static_branch_inc(&nft_counters_enabled); + table->use++; return 0; -- 2.35.1