]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
netfilter: bridge: eb_tables: close module init race
authorFlorian Westphal <fw@strlen.de>
Thu, 7 May 2026 09:19:22 +0000 (11:19 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 7 May 2026 23:30:17 +0000 (01:30 +0200)
commit27414ff1b287ea9a2a11675149ec28e05539f3cc
tree204b11af30db96529c8ebfdf048889d387dd07fa
parent16bc4b6686b2c112c10e67d6b493adc3607256d3
netfilter: bridge: eb_tables: close module init race

sashiko reports for unrelated patch:
 Does the core ebtables initialization in ebtables.c suffer from a similar race?
 Once nf_register_sockopt() completes, the sockopts are exposed globally.

sockopt has to be registered last, just like in ip/ip6/arptables.

Fixes: 5b53951cfc85 ("netfilter: ebtables: use net_generic infra")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/bridge/netfilter/ebtables.c