summaryrefslogtreecommitdiff
path: root/net/netfilter/nf_tables_core.c
diff options
context:
space:
mode:
authorFlorian Westphal <fw@strlen.de>2023-10-11 10:59:34 +0300
committerFlorian Westphal <fw@strlen.de>2023-10-18 11:26:43 +0300
commite15e5027106f3f6009d2fb46b3a1bb3d9e6a1b77 (patch)
treee448bbfa0e109251e300956f0e61a7b67be3bfb4 /net/netfilter/nf_tables_core.c
parenta0a86022474304e012aad5d41943fdd31a036284 (diff)
downloadlinux-e15e5027106f3f6009d2fb46b3a1bb3d9e6a1b77.tar.xz
netfilter: xt_mangle: only check verdict part of return value
These checks assume that the caller only returns NF_DROP without any errno embedded in the upper bits. This is fine right now, but followup patches will start to propagate such errors to allow kfree_skb_drop_reason() in the called functions, those would then indicate 'errno << 8 | NF_STOLEN'. To not break things we have to mask those parts out. Signed-off-by: Florian Westphal <fw@strlen.de>
Diffstat (limited to 'net/netfilter/nf_tables_core.c')
0 files changed, 0 insertions, 0 deletions