| From 19547d93f7312f5721bc02a7764bbf030a0bf1d7 Mon Sep 17 00:00:00 2001 |
| From: Pablo Neira Ayuso <pablo@netfilter.org> |
| Date: Fri, 5 Jul 2019 23:38:54 +0200 |
| Subject: [PATCH] netfilter: nf_tables: force module load in case select_ops() |
| returns -EAGAIN |
| |
| commit 0ef1efd1354d732d040f29b2005420f83fcdd8f4 upstream. |
| |
| nft_meta needs to pull in the nft_meta_bridge module in case that this |
| is a bridge family rule from the select_ops() path. |
| |
| Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> |
| Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com> |
| |
| diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c |
| index ef944631b976..4b1baf172b76 100644 |
| --- a/net/netfilter/nf_tables_api.c |
| +++ b/net/netfilter/nf_tables_api.c |
| @@ -2164,6 +2164,12 @@ static int nf_tables_expr_parse(const struct nft_ctx *ctx, |
| (const struct nlattr * const *)info->tb); |
| if (IS_ERR(ops)) { |
| err = PTR_ERR(ops); |
| +#ifdef CONFIG_MODULES |
| + if (err == -EAGAIN) |
| + nft_expr_type_request_module(ctx->net, |
| + ctx->family, |
| + tb[NFTA_EXPR_NAME]); |
| +#endif |
| goto err1; |
| } |
| } else |
| diff --git a/net/netfilter/nft_meta.c b/net/netfilter/nft_meta.c |
| index a54329b8634a..9abd01f6512a 100644 |
| --- a/net/netfilter/nft_meta.c |
| +++ b/net/netfilter/nft_meta.c |
| @@ -544,6 +544,10 @@ nft_meta_select_ops(const struct nft_ctx *ctx, |
| if (tb[NFTA_META_DREG] && tb[NFTA_META_SREG]) |
| return ERR_PTR(-EINVAL); |
| |
| +#ifdef CONFIG_NF_TABLES_BRIDGE |
| + if (ctx->family == NFPROTO_BRIDGE) |
| + return ERR_PTR(-EAGAIN); |
| +#endif |
| if (tb[NFTA_META_DREG]) |
| return &nft_meta_get_ops; |
| |
| -- |
| 2.7.4 |
| |