Commit 917d80d3 authored by Pablo Neira Ayuso's avatar Pablo Neira Ayuso

netfilter: nft_dynset: fix timeouts later than 23 days

Use nf_msecs_to_jiffies64 and nf_jiffies64_to_msecs as provided by
8e1102d5 ("netfilter: nf_tables: support timeouts larger than 23
days"), otherwise ruleset listing breaks.

Fixes: a8b1e36d ("netfilter: nft_dynset: fix element timeout for HZ != 1000")
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent cc00bcaa
...@@ -1524,4 +1524,8 @@ void __init nft_chain_route_init(void); ...@@ -1524,4 +1524,8 @@ void __init nft_chain_route_init(void);
void nft_chain_route_fini(void); void nft_chain_route_fini(void);
void nf_tables_trans_destroy_flush_work(void); void nf_tables_trans_destroy_flush_work(void);
int nf_msecs_to_jiffies64(const struct nlattr *nla, u64 *result);
__be64 nf_jiffies64_to_msecs(u64 input);
#endif /* _NET_NF_TABLES_H */ #endif /* _NET_NF_TABLES_H */
...@@ -3719,7 +3719,7 @@ static int nf_tables_set_alloc_name(struct nft_ctx *ctx, struct nft_set *set, ...@@ -3719,7 +3719,7 @@ static int nf_tables_set_alloc_name(struct nft_ctx *ctx, struct nft_set *set,
return 0; return 0;
} }
static int nf_msecs_to_jiffies64(const struct nlattr *nla, u64 *result) int nf_msecs_to_jiffies64(const struct nlattr *nla, u64 *result)
{ {
u64 ms = be64_to_cpu(nla_get_be64(nla)); u64 ms = be64_to_cpu(nla_get_be64(nla));
u64 max = (u64)(~((u64)0)); u64 max = (u64)(~((u64)0));
...@@ -3733,7 +3733,7 @@ static int nf_msecs_to_jiffies64(const struct nlattr *nla, u64 *result) ...@@ -3733,7 +3733,7 @@ static int nf_msecs_to_jiffies64(const struct nlattr *nla, u64 *result)
return 0; return 0;
} }
static __be64 nf_jiffies64_to_msecs(u64 input) __be64 nf_jiffies64_to_msecs(u64 input)
{ {
return cpu_to_be64(jiffies64_to_msecs(input)); return cpu_to_be64(jiffies64_to_msecs(input));
} }
......
...@@ -157,8 +157,10 @@ static int nft_dynset_init(const struct nft_ctx *ctx, ...@@ -157,8 +157,10 @@ static int nft_dynset_init(const struct nft_ctx *ctx,
if (tb[NFTA_DYNSET_TIMEOUT] != NULL) { if (tb[NFTA_DYNSET_TIMEOUT] != NULL) {
if (!(set->flags & NFT_SET_TIMEOUT)) if (!(set->flags & NFT_SET_TIMEOUT))
return -EINVAL; return -EINVAL;
timeout = msecs_to_jiffies(be64_to_cpu(nla_get_be64(
tb[NFTA_DYNSET_TIMEOUT]))); err = nf_msecs_to_jiffies64(tb[NFTA_DYNSET_TIMEOUT], &timeout);
if (err)
return err;
} }
priv->sreg_key = nft_parse_register(tb[NFTA_DYNSET_SREG_KEY]); priv->sreg_key = nft_parse_register(tb[NFTA_DYNSET_SREG_KEY]);
...@@ -267,7 +269,7 @@ static int nft_dynset_dump(struct sk_buff *skb, const struct nft_expr *expr) ...@@ -267,7 +269,7 @@ static int nft_dynset_dump(struct sk_buff *skb, const struct nft_expr *expr)
if (nla_put_string(skb, NFTA_DYNSET_SET_NAME, priv->set->name)) if (nla_put_string(skb, NFTA_DYNSET_SET_NAME, priv->set->name))
goto nla_put_failure; goto nla_put_failure;
if (nla_put_be64(skb, NFTA_DYNSET_TIMEOUT, if (nla_put_be64(skb, NFTA_DYNSET_TIMEOUT,
cpu_to_be64(jiffies_to_msecs(priv->timeout)), nf_jiffies64_to_msecs(priv->timeout),
NFTA_DYNSET_PAD)) NFTA_DYNSET_PAD))
goto nla_put_failure; goto nla_put_failure;
if (priv->expr && nft_expr_dump(skb, NFTA_DYNSET_EXPR, priv->expr)) if (priv->expr && nft_expr_dump(skb, NFTA_DYNSET_EXPR, priv->expr))
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment