From: Pablo Neira Ayuso Date: Mon, 4 Nov 2019 13:52:42 +0000 (+0100) Subject: netfilter: nf_tables_offload: skip EBUSY on chain update X-Git-Tag: v5.3.15~88 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=cd73a78a6f91db5ebf038b5edc657e1f2ee8618c;p=thirdparty%2Fkernel%2Fstable.git netfilter: nf_tables_offload: skip EBUSY on chain update [ Upstream commit 88c749840dff58e7a40e18bf9bdace15f27ef259 ] Do not try to bind a chain again if it exists, otherwise the driver returns EBUSY. Fixes: c9626a2cbdb2 ("netfilter: nf_tables: add hardware offload support") Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- diff --git a/net/netfilter/nf_tables_offload.c b/net/netfilter/nf_tables_offload.c index c0d18c1d77ac0..04fbab60e8080 100644 --- a/net/netfilter/nf_tables_offload.c +++ b/net/netfilter/nf_tables_offload.c @@ -241,7 +241,8 @@ int nft_flow_rule_offload_commit(struct net *net) switch (trans->msg_type) { case NFT_MSG_NEWCHAIN: - if (!(trans->ctx.chain->flags & NFT_CHAIN_HW_OFFLOAD)) + if (!(trans->ctx.chain->flags & NFT_CHAIN_HW_OFFLOAD) || + nft_trans_chain_update(trans)) continue; err = nft_flow_offload_chain(trans, FLOW_BLOCK_BIND);