forked from Minki/linux
netfilter: ctnetlink: nla_policy updates
Add stricter checking for a few attributes. Note that these changes don't fix any bug in the current code base. Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
0360ae412d
commit
6d1fafcaec
@ -898,7 +898,8 @@ ctnetlink_parse_zone(const struct nlattr *attr, u16 *zone)
|
||||
}
|
||||
|
||||
static const struct nla_policy help_nla_policy[CTA_HELP_MAX+1] = {
|
||||
[CTA_HELP_NAME] = { .type = NLA_NUL_STRING },
|
||||
[CTA_HELP_NAME] = { .type = NLA_NUL_STRING,
|
||||
.len = NF_CT_HELPER_NAME_LEN - 1 },
|
||||
};
|
||||
|
||||
static inline int
|
||||
@ -932,6 +933,8 @@ static const struct nla_policy ct_nla_policy[CTA_MAX+1] = {
|
||||
[CTA_ID] = { .type = NLA_U32 },
|
||||
[CTA_NAT_DST] = { .type = NLA_NESTED },
|
||||
[CTA_TUPLE_MASTER] = { .type = NLA_NESTED },
|
||||
[CTA_NAT_SEQ_ADJ_ORIG] = { .type = NLA_NESTED },
|
||||
[CTA_NAT_SEQ_ADJ_REPLY] = { .type = NLA_NESTED },
|
||||
[CTA_ZONE] = { .type = NLA_U16 },
|
||||
[CTA_MARK_MASK] = { .type = NLA_U32 },
|
||||
};
|
||||
@ -2322,7 +2325,8 @@ static const struct nla_policy exp_nla_policy[CTA_EXPECT_MAX+1] = {
|
||||
[CTA_EXPECT_MASK] = { .type = NLA_NESTED },
|
||||
[CTA_EXPECT_TIMEOUT] = { .type = NLA_U32 },
|
||||
[CTA_EXPECT_ID] = { .type = NLA_U32 },
|
||||
[CTA_EXPECT_HELP_NAME] = { .type = NLA_NUL_STRING },
|
||||
[CTA_EXPECT_HELP_NAME] = { .type = NLA_NUL_STRING,
|
||||
.len = NF_CT_HELPER_NAME_LEN - 1 },
|
||||
[CTA_EXPECT_ZONE] = { .type = NLA_U16 },
|
||||
[CTA_EXPECT_FLAGS] = { .type = NLA_U32 },
|
||||
[CTA_EXPECT_CLASS] = { .type = NLA_U32 },
|
||||
|
@ -1353,6 +1353,8 @@ static const struct nla_policy tcp_timeout_nla_policy[CTA_TIMEOUT_TCP_MAX+1] = {
|
||||
[CTA_TIMEOUT_TCP_TIME_WAIT] = { .type = NLA_U32 },
|
||||
[CTA_TIMEOUT_TCP_CLOSE] = { .type = NLA_U32 },
|
||||
[CTA_TIMEOUT_TCP_SYN_SENT2] = { .type = NLA_U32 },
|
||||
[CTA_TIMEOUT_TCP_RETRANS] = { .type = NLA_U32 },
|
||||
[CTA_TIMEOUT_TCP_UNACK] = { .type = NLA_U32 },
|
||||
};
|
||||
#endif /* CONFIG_NF_CT_NETLINK_TIMEOUT */
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user