| From cca5838a3c9ae1249b20deb1d724abe1193b0b21 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Tue, 20 Jul 2021 18:22:50 +0200 |
| Subject: netfilter: nft_nat: allow to specify layer 4 protocol NAT only |
| |
| From: Pablo Neira Ayuso <pablo@netfilter.org> |
| |
| [ Upstream commit a33f387ecd5aafae514095c2c4a8c24f7aea7e8b ] |
| |
| nft_nat reports a bogus EAFNOSUPPORT if no layer 3 information is specified. |
| |
| Fixes: d07db9884a5f ("netfilter: nf_tables: introduce nft_validate_register_load()") |
| Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/netfilter/nft_nat.c | 4 +++- |
| 1 file changed, 3 insertions(+), 1 deletion(-) |
| |
| diff --git a/net/netfilter/nft_nat.c b/net/netfilter/nft_nat.c |
| index 4bcf33b049c4..ea53fd999f46 100644 |
| --- a/net/netfilter/nft_nat.c |
| +++ b/net/netfilter/nft_nat.c |
| @@ -201,7 +201,9 @@ static int nft_nat_init(const struct nft_ctx *ctx, const struct nft_expr *expr, |
| alen = sizeof_field(struct nf_nat_range, min_addr.ip6); |
| break; |
| default: |
| - return -EAFNOSUPPORT; |
| + if (tb[NFTA_NAT_REG_ADDR_MIN]) |
| + return -EAFNOSUPPORT; |
| + break; |
| } |
| priv->family = family; |
| |
| -- |
| 2.30.2 |
| |