]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 2 Sep 2024 23:06:41 +0000 (01:06 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 4 Oct 2024 14:28:53 +0000 (16:28 +0200)
commit08b25d59ffb049ca6c3ed87fecbbef70c9a16f39
tree2a987e6409811b396f302b0c7de0cc630fe0a935
parent8ad28208be7bbe748e90442c45963ddbef0fd1e2
netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire

[ Upstream commit e0c47281723f301894c14e6f5cd5884fdfb813f9 ]

Element timeout that is below CONFIG_HZ never expires because the
timeout extension is not allocated given that nf_msecs_to_jiffies64()
returns 0. Set timeout to the minimum value to honor timeout.

Fixes: 8e1102d5a159 ("netfilter: nf_tables: support timeouts larger than 23 days")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/netfilter/nf_tables_api.c