]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
3.10-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 17 Oct 2015 19:48:36 +0000 (12:48 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 17 Oct 2015 19:48:36 +0000 (12:48 -0700)
added patches:
netfilter-nf_conntrack-support-expectations-in-different-zones.patch

queue-3.10/netfilter-nf_conntrack-support-expectations-in-different-zones.patch [new file with mode: 0644]
queue-3.10/series

diff --git a/queue-3.10/netfilter-nf_conntrack-support-expectations-in-different-zones.patch b/queue-3.10/netfilter-nf_conntrack-support-expectations-in-different-zones.patch
new file mode 100644 (file)
index 0000000..83943c5
--- /dev/null
@@ -0,0 +1,36 @@
+From 4b31814d20cbe5cd4ccf18089751e77a04afe4f2 Mon Sep 17 00:00:00 2001
+From: Joe Stringer <joestringer@nicira.com>
+Date: Tue, 21 Jul 2015 21:37:31 -0700
+Subject: netfilter: nf_conntrack: Support expectations in different zones
+
+From: Joe Stringer <joestringer@nicira.com>
+
+commit 4b31814d20cbe5cd4ccf18089751e77a04afe4f2 upstream.
+
+When zones were originally introduced, the expectation functions were
+all extended to perform lookup using the zone. However, insertion was
+not modified to check the zone. This means that two expectations which
+are intended to apply for different connections that have the same tuple
+but exist in different zones cannot both be tracked.
+
+Fixes: 5d0aa2ccd4 (netfilter: nf_conntrack: add support for "conntrack zones")
+Signed-off-by: Joe Stringer <joestringer@nicira.com>
+Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ net/netfilter/nf_conntrack_expect.c |    3 ++-
+ 1 file changed, 2 insertions(+), 1 deletion(-)
+
+--- a/net/netfilter/nf_conntrack_expect.c
++++ b/net/netfilter/nf_conntrack_expect.c
+@@ -202,7 +202,8 @@ static inline int expect_clash(const str
+                       a->mask.src.u3.all[count] & b->mask.src.u3.all[count];
+       }
+-      return nf_ct_tuple_mask_cmp(&a->tuple, &b->tuple, &intersect_mask);
++      return nf_ct_tuple_mask_cmp(&a->tuple, &b->tuple, &intersect_mask) &&
++             nf_ct_zone(a->master) == nf_ct_zone(b->master);
+ }
+ static inline int expect_matches(const struct nf_conntrack_expect *a,
index 8f0dc13842f6c6aa3326c02b0fb27e20479e9fc8..440afb75b931e63ec33d2ecaa3d858793cd6e63c 100644 (file)
@@ -18,3 +18,4 @@ staging-comedi-adl_pci7x3x-fix-digital-output-on-pci-7230.patch
 dm-btree-add-ref-counting-ops-for-the-leaves-of-top-level-btrees.patch
 usb-option-add-zte-pids.patch
 dm-raid-fix-round-up-of-default-region-size.patch
+netfilter-nf_conntrack-support-expectations-in-different-zones.patch