Commit f3bb5333 authored by Liping Zhang's avatar Liping Zhang Committed by Pablo Neira Ayuso

netfilter: nf_log: handle NFPROTO_INET properly in nf_logger_[find_get|put]

When we request NFPROTO_INET, it means both NFPROTO_IPV4 and NFPROTO_IPV6.
Signed-off-by: default avatarLiping Zhang <liping.zhang@spreadtrum.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent a6d0bae1
...@@ -159,6 +159,20 @@ int nf_logger_find_get(int pf, enum nf_log_type type) ...@@ -159,6 +159,20 @@ int nf_logger_find_get(int pf, enum nf_log_type type)
struct nf_logger *logger; struct nf_logger *logger;
int ret = -ENOENT; int ret = -ENOENT;
if (pf == NFPROTO_INET) {
ret = nf_logger_find_get(NFPROTO_IPV4, type);
if (ret < 0)
return ret;
ret = nf_logger_find_get(NFPROTO_IPV6, type);
if (ret < 0) {
nf_logger_put(NFPROTO_IPV4, type);
return ret;
}
return 0;
}
if (rcu_access_pointer(loggers[pf][type]) == NULL) if (rcu_access_pointer(loggers[pf][type]) == NULL)
request_module("nf-logger-%u-%u", pf, type); request_module("nf-logger-%u-%u", pf, type);
...@@ -179,6 +193,12 @@ void nf_logger_put(int pf, enum nf_log_type type) ...@@ -179,6 +193,12 @@ void nf_logger_put(int pf, enum nf_log_type type)
{ {
struct nf_logger *logger; struct nf_logger *logger;
if (pf == NFPROTO_INET) {
nf_logger_put(NFPROTO_IPV4, type);
nf_logger_put(NFPROTO_IPV6, type);
return;
}
BUG_ON(loggers[pf][type] == NULL); BUG_ON(loggers[pf][type] == NULL);
rcu_read_lock(); rcu_read_lock();
......
...@@ -52,7 +52,6 @@ static int nft_log_init(const struct nft_ctx *ctx, ...@@ -52,7 +52,6 @@ static int nft_log_init(const struct nft_ctx *ctx,
struct nft_log *priv = nft_expr_priv(expr); struct nft_log *priv = nft_expr_priv(expr);
struct nf_loginfo *li = &priv->loginfo; struct nf_loginfo *li = &priv->loginfo;
const struct nlattr *nla; const struct nlattr *nla;
int ret;
nla = tb[NFTA_LOG_PREFIX]; nla = tb[NFTA_LOG_PREFIX];
if (nla != NULL) { if (nla != NULL) {
...@@ -97,19 +96,6 @@ static int nft_log_init(const struct nft_ctx *ctx, ...@@ -97,19 +96,6 @@ static int nft_log_init(const struct nft_ctx *ctx,
break; break;
} }
if (ctx->afi->family == NFPROTO_INET) {
ret = nf_logger_find_get(NFPROTO_IPV4, li->type);
if (ret < 0)
return ret;
ret = nf_logger_find_get(NFPROTO_IPV6, li->type);
if (ret < 0) {
nf_logger_put(NFPROTO_IPV4, li->type);
return ret;
}
return 0;
}
return nf_logger_find_get(ctx->afi->family, li->type); return nf_logger_find_get(ctx->afi->family, li->type);
} }
...@@ -122,12 +108,7 @@ static void nft_log_destroy(const struct nft_ctx *ctx, ...@@ -122,12 +108,7 @@ static void nft_log_destroy(const struct nft_ctx *ctx,
if (priv->prefix != nft_log_null_prefix) if (priv->prefix != nft_log_null_prefix)
kfree(priv->prefix); kfree(priv->prefix);
if (ctx->afi->family == NFPROTO_INET) { nf_logger_put(ctx->afi->family, li->type);
nf_logger_put(NFPROTO_IPV4, li->type);
nf_logger_put(NFPROTO_IPV6, li->type);
} else {
nf_logger_put(ctx->afi->family, li->type);
}
} }
static int nft_log_dump(struct sk_buff *skb, const struct nft_expr *expr) static int nft_log_dump(struct sk_buff *skb, const struct nft_expr *expr)
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment