Received: by 2002:ab2:6857:0:b0:1ef:ffd0:ce49 with SMTP id l23csp2494964lqp; Sun, 24 Mar 2024 23:34:18 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCVlNPxJR30gGAfO4r43TmfSXTaCaJMp02d/D37wdDpPbC1ZNlTUIgAZFVQX/wFuPQ6AKKIyKQG4D5a443WDtOYLjlvnsDK59eWVTmIPhA== X-Google-Smtp-Source: AGHT+IEZlrlXsB3GaPIlf84zvInppE+hWICJYMvod6JWs2KYWHgx7+rmKidvvUMcRpphTRGabv1V X-Received: by 2002:aca:1a08:0:b0:3c3:98e4:db5 with SMTP id a8-20020aca1a08000000b003c398e40db5mr6802201oia.22.1711348458301; Sun, 24 Mar 2024 23:34:18 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1711348458; cv=pass; d=google.com; s=arc-20160816; b=QtCJFe5pqNYubWkwqUuCm4Z/8YnMGyb5IfLwAuwYfJTAvJHhSoFc0LGlw7I779Dcr0 0JLQcHZoqQeIcUHjIKUMbZ7zDYTAq5Y4lZISnBP5ke8rraVmhY5QdY2W3/hJZz5D4dmX lez+vm2NXZbgUnk037pdCoWZ612cmyOrFtGT9OL4KveZRNS3faFivCPaGrQly2J0oJC7 /d4vNxVxIlm0+T5Bzjh49zXSq1UfWmujSIvy1DqT5+bbVEurY5J51ml+4FbkoSTifHSJ aTRCu8MGMOQpoiv07uQ+wpHjDmenDiN6EVtCA+IisdqKvFUQNCoa2v72crVrrvf/YYMo 2gBw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from:dkim-signature; bh=LW7KzkBfkdmPUX0RY5cRhd3qbBlvUlsDBdk4brjZKG4=; fh=JCupzcIQwtmyJ2C2xrsc2nqgcJfRphMLLtiVBgyhfvk=; b=PMkqY/uhPX7qDbOW9DIxW/NHhKIVDtNhmVNXTOgGJ7g7U+2VKGMg1PmNLZcIwHHodJ Uxxz6c4MQSgrQf3qzuM/tUHvomdy2jJHRjJ0Z6Iy/0xJejl694esnpojOZO+50wL0aIB RnHiFhXQrPfrSU86ZF4/KWX253s91DH86pk5VtUD2hkIw3MNOO5GLZ++fPBsvVg4dlMl xCQS3mlWQQorkul4ZLl6OiXdnJykF7zo4k1YOE5jwH1W6Qw/HetNmev3yIlsv8H3SYb+ QttwkBOfC0V8If6lrCyCg9aR7DGTGxxTEbwCRTfSXQYTvCeZfXSTofyWCZq1od2Ou8Kk lJ0w==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=WKQX+Y0g; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-114705-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-114705-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [139.178.88.99]) by mx.google.com with ESMTPS id r18-20020a63d912000000b005cf60fc5fc9si6684086pgg.274.2024.03.24.23.34.17 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 24 Mar 2024 23:34:18 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-114705-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) client-ip=139.178.88.99; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=WKQX+Y0g; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-114705-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-114705-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id 91CA52975B8 for ; Mon, 25 Mar 2024 06:26:58 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id C28ECEED8; Mon, 25 Mar 2024 00:01:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="WKQX+Y0g" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 092E01509BD; Sun, 24 Mar 2024 23:19:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1711322357; cv=none; b=FrQwLV4kLOp+lIpmc3OB2mSb7RhC8kN5wNajV/4JXVG1rhQ3ZQ8VB3xLjgo/wm3IZ5z5Ni6SFUFlxDn9hezjful/r1b5L/p+IhgO/oIcy7ju40InXTetNasRE0uQP12NMTAeQzxLTkdAJLI6cxWZhCpAXjY6xHqKH3g9k56aIWk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1711322357; c=relaxed/simple; bh=l9CF472xzA5Sds7a3d5p9A9eJDKLLEW/h/YvlFUgIUM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CS6sNQvfzXvmKsPtZJ7JsKWdnDzQwk9u/+ADoFNeEMk1G7pQvn3Q3uCurHKWL2LhttKE3aXezeVS4U/zWjjJVdxZxGSbreTVqfvLVxqa6Xa1OXbHUiNbedr5V9/4NEeLL4C3aIWdctueQLJMDO3gQ8YxhP2v6dMY/rMNzBEhu3A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=WKQX+Y0g; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6354EC433F1; Sun, 24 Mar 2024 23:19:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1711322355; bh=l9CF472xzA5Sds7a3d5p9A9eJDKLLEW/h/YvlFUgIUM=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=WKQX+Y0gmPZP7Y7QCE5aK/u+PUvbJZDiewcUfZMHvBZtMgYYsLLhH9ZXHa+INXv3I x9GDhCWY2e73hsEi5m9ECWMYRoHMa7oWcUpQ6yDJCdVAsBjQaymZtngvm+Fys3PEtF ZWPkalEs4Rc1R/KdA1fq1LQLOWnhMWuXheAJaaKtQhQ8/pM984dyqshg/ZUWLfDNq+ DbKKfIQhXOg5N9YTAXxOCA741q2a2EFN0U2g7FwlG4tIlP4udpjnkNT0wSJvo95zzS wUHzA6TlU7JlFC+ERDIccGZX05FAzftBlmbPZipOucfwVm83F/eZERyd3oLvWxGJsW SOpqc9EGtzc3Q== From: Sasha Levin To: linux-kernel@vger.kernel.org, stable@vger.kernel.org Cc: Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 6.1 438/451] netfilter: nf_tables: do not compare internal table flags on updates Date: Sun, 24 Mar 2024 19:11:54 -0400 Message-ID: <20240324231207.1351418-439-sashal@kernel.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20240324231207.1351418-1-sashal@kernel.org> References: <20240324231207.1351418-1-sashal@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-stable: review X-Patchwork-Hint: Ignore Content-Transfer-Encoding: 8bit From: Pablo Neira Ayuso [ Upstream commit 4a0e7f2decbf9bd72461226f1f5f7dcc4b08f139 ] Restore skipping transaction if table update does not modify flags. Fixes: 179d9ba5559a ("netfilter: nf_tables: fix table flag updates") Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/netfilter/nf_tables_api.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c index d3ba947f43761..0a86c019a75de 100644 --- a/net/netfilter/nf_tables_api.c +++ b/net/netfilter/nf_tables_api.c @@ -1205,7 +1205,7 @@ static int nf_tables_updtable(struct nft_ctx *ctx) if (flags & ~NFT_TABLE_F_MASK) return -EOPNOTSUPP; - if (flags == ctx->table->flags) + if (flags == (ctx->table->flags & NFT_TABLE_F_MASK)) return 0; if ((nft_table_has_owner(ctx->table) && -- 2.43.0