netfilter: nf_tables: check if same extensions are set when adding elements
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 1 May 2017 10:58:50 +0000 (12:58 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 3 May 2017 08:58:00 +0000 (10:58 +0200)
If no NLM_F_EXCL is set and the element already exists in the set, make
sure that both elements have the same extensions.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c

index 434c739dfecaa8727dc193f8ad86e18133932660..11a96e8dd3cd5af4bdbc734fb74107a0c173e837 100644 (file)
@@ -3749,6 +3749,11 @@ static int nft_add_set_elem(struct nft_ctx *ctx, struct nft_set *set,
        err = set->ops->insert(ctx->net, set, &elem, &ext2);
        if (err) {
                if (err == -EEXIST) {
+                       if (nft_set_ext_exists(ext, NFT_SET_EXT_DATA) ^
+                           nft_set_ext_exists(ext2, NFT_SET_EXT_DATA) ||
+                           nft_set_ext_exists(ext, NFT_SET_EXT_OBJREF) ^
+                           nft_set_ext_exists(ext2, NFT_SET_EXT_OBJREF))
+                               return -EBUSY;
                        if ((nft_set_ext_exists(ext, NFT_SET_EXT_DATA) &&
                             nft_set_ext_exists(ext2, NFT_SET_EXT_DATA) &&
                             memcmp(nft_set_ext_data(ext),