Before patch:
# nft -j list ruleset | tee rules.json | jq '.'
{
"nftables": [
{
"metainfo": {
"version": "0.9.2",
"release_name": "Scram",
"json_schema_version": 1
}
},
{
"table": {
"family": "inet",
"name": "t",
"handle": 11
}
},
{
"secmark": {
"family": "inet",
"name": "s",
"table": "t",
"handle": 1,
"context": "system_u:object_r:ssh_server_packet_t:s0"
}
}
]
}
# nft flush ruleset
# nft -j -f rules.json
Segmentation fault
Use "&tmp" instead of "tmp" in json_unpack() while translating "context" keyword.
After patch:
# nft -j -f rules.json
# nft list ruleset
table inet t {
secmark s {
"system_u:object_r:ssh_server_packet_t:s0"
}
}
Fixes: 3bc84e5c1fdd1 ("src: add support for setting secmark")
Signed-off-by: Eric Jallot <ejallot@gmail.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
break;
case CMD_OBJ_SECMARK:
obj->type = NFT_OBJECT_SECMARK;
- if (!json_unpack(root, "{s:s}", "context", tmp)) {
+ if (!json_unpack(root, "{s:s}", "context", &tmp)) {
int ret;
ret = snprintf(obj->secmark.ctx, sizeof(obj->secmark.ctx), "%s", tmp);
if (ret < 0 || ret >= (int)sizeof(obj->secmark.ctx)) {