diff options
author | Pablo Neira Ayuso | 2014-07-01 12:23:12 +0200 |
---|---|---|
committer | Pablo Neira Ayuso | 2014-07-14 12:00:16 +0200 |
commit | 38e029f14a9702f71d5953246df9f722bca49017 (patch) | |
tree | ca7c55906f83d30277e75791b9eff8d25ba7272b /include/net | |
parent | e688a7f8c6cb7a18aae7e55ccdd175f0ad9e69c0 (diff) |
netfilter: nf_tables: set NLM_F_DUMP_INTR if netlink dumping is stale
An updater may interfer with the dumping of any of the object lists.
Fix this by using a per-net generation counter and use the
nl_dump_check_consistent() interface so the NLM_F_DUMP_INTR flag is set
to notify userspace that it has to restart the dump since an updater
has interfered.
This patch also replaces the existing consistency checking code in the
rule dumping path since it is broken. Basically, the value that the
dump callback returns is not propagated to userspace via
netlink_dump_start().
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'include/net')
-rw-r--r-- | include/net/netns/nftables.h | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/include/net/netns/nftables.h b/include/net/netns/nftables.h index 26a394cb91a8..eee608b12cc9 100644 --- a/include/net/netns/nftables.h +++ b/include/net/netns/nftables.h @@ -13,8 +13,8 @@ struct netns_nftables { struct nft_af_info *inet; struct nft_af_info *arp; struct nft_af_info *bridge; + unsigned int base_seq; u8 gencursor; - u8 genctr; }; #endif |