mirror of https://gitee.com/openkylin/linux.git
netfilter: nf_tables: accept QUEUE/DROP verdict parameters
Allow userspace to specify the queue number or the errno code for QUEUE and DROP verdicts. Signed-off-by: Patrick McHardy <kaber@trash.net> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
67a8fc27cc
commit
e0abdadcc6
|
@ -3174,9 +3174,16 @@ static int nft_verdict_init(const struct nft_ctx *ctx, struct nft_data *data,
|
||||||
data->verdict = ntohl(nla_get_be32(tb[NFTA_VERDICT_CODE]));
|
data->verdict = ntohl(nla_get_be32(tb[NFTA_VERDICT_CODE]));
|
||||||
|
|
||||||
switch (data->verdict) {
|
switch (data->verdict) {
|
||||||
|
default:
|
||||||
|
switch (data->verdict & NF_VERDICT_MASK) {
|
||||||
case NF_ACCEPT:
|
case NF_ACCEPT:
|
||||||
case NF_DROP:
|
case NF_DROP:
|
||||||
case NF_QUEUE:
|
case NF_QUEUE:
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
return -EINVAL;
|
||||||
|
}
|
||||||
|
/* fall through */
|
||||||
case NFT_CONTINUE:
|
case NFT_CONTINUE:
|
||||||
case NFT_BREAK:
|
case NFT_BREAK:
|
||||||
case NFT_RETURN:
|
case NFT_RETURN:
|
||||||
|
@ -3197,8 +3204,6 @@ static int nft_verdict_init(const struct nft_ctx *ctx, struct nft_data *data,
|
||||||
data->chain = chain;
|
data->chain = chain;
|
||||||
desc->len = sizeof(data);
|
desc->len = sizeof(data);
|
||||||
break;
|
break;
|
||||||
default:
|
|
||||||
return -EINVAL;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
desc->type = NFT_DATA_VERDICT;
|
desc->type = NFT_DATA_VERDICT;
|
||||||
|
|
Loading…
Reference in New Issue