]> git.ipfire.org Git - thirdparty/nftables.git/commitdiff
netlink_delinearize: add postprocessing for payload binops
authorJeremy Sowden <jeremy@azazel.net>
Mon, 4 Apr 2022 12:13:47 +0000 (13:13 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 7 Feb 2023 11:40:18 +0000 (12:40 +0100)
If a user uses a payload expression as a statement argument:

  nft add rule t c meta mark set ip dscp lshift 2 or 0x10

we may need to undo munging during delinearization.

Signed-off-by: Jeremy Sowden <jeremy@azazel.net>
src/netlink_delinearize.c

index 4cd6cc3a6f9b82d5bf9d034f78174f904a5eb970..f4ab476e0345584731cf6a466b7cfbad4c3e092e 100644 (file)
@@ -2603,6 +2603,42 @@ static void relational_binop_postprocess(struct rule_pp_ctx *ctx,
        }
 }
 
+static bool payload_binop_postprocess(struct rule_pp_ctx *ctx,
+                                     struct expr **exprp)
+{
+       struct expr *expr = *exprp;
+
+       if (expr->op != OP_RSHIFT)
+               return false;
+
+       if (expr->left->etype == EXPR_UNARY) {
+               /*
+                * If the payload value was originally in a different byte-order
+                * from the payload expression, there will be a byte-order
+                * conversion to remove.
+                */
+               struct expr *left = expr_get(expr->left->arg);
+               expr_free(expr->left);
+               expr->left = left;
+       }
+
+       if (expr->left->etype != EXPR_BINOP || expr->left->op != OP_AND)
+               return false;
+
+       if (expr->left->left->etype != EXPR_PAYLOAD)
+               return false;
+
+       expr_set_type(expr->right, &integer_type,
+                     BYTEORDER_HOST_ENDIAN);
+       expr_postprocess(ctx, &expr->right);
+
+       binop_postprocess(ctx, expr, &expr->left);
+       *exprp = expr_get(expr->left);
+       expr_free(expr);
+
+       return true;
+}
+
 static struct expr *string_wildcard_expr_alloc(struct location *loc,
                                               const struct expr *mask,
                                               const struct expr *expr)
@@ -2723,6 +2759,9 @@ static void expr_postprocess(struct rule_pp_ctx *ctx, struct expr **exprp)
                expr_set_type(expr, expr->arg->dtype, !expr->arg->byteorder);
                break;
        case EXPR_BINOP:
+               if (payload_binop_postprocess(ctx, exprp))
+                       break;
+
                expr_postprocess(ctx, &expr->left);
                switch (expr->op) {
                case OP_LSHIFT: