Commit 5f4fc4b
committed
netfilter: nf_tables: reject constant set with timeout
This set combination is weird: it allows for elements to be
added/deleted, but once bound to the rule it cannot be updated anymore.
Eventually, all elements expire, leading to an empty set which cannot
be updated anymore. Reject this flags combination.
Cc: stable@vger.kernel.org
Fixes: 761da29 ("netfilter: nf_tables: add set timeout API support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>1 parent 1660360 commit 5f4fc4b
1 file changed
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5004 | 5004 | | |
5005 | 5005 | | |
5006 | 5006 | | |
| 5007 | + | |
| 5008 | + | |
| 5009 | + | |
5007 | 5010 | | |
5008 | 5011 | | |
5009 | 5012 | | |
| |||
0 commit comments