]> granicus.if.org Git - ipset/commit
Enforce network-order data in the netlink protocol
authorJozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Thu, 20 Jan 2011 16:54:26 +0000 (17:54 +0100)
committerJozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Thu, 20 Jan 2011 16:54:26 +0000 (17:54 +0100)
commit13f42a71e49164769a98fc51033c65a211861404
tree966741c7765a2cf866f3a67ca4a432178eadfabe
parentc8396bdc040f4b16e6f6e3f8b81b9fb67a499d9c
Enforce network-order data in the netlink protocol

Allow only network-order data, with NLA_F_NET_BYTEORDER flag.
Sanity checks also added to prevent processing broken messages
where mandatory attributes are missing. (Patrick McHardy's review)
12 files changed:
kernel/include/linux/netfilter/ipset/ip_set.h
kernel/ip_set_bitmap_ip.c
kernel/ip_set_bitmap_ipmac.c
kernel/ip_set_bitmap_port.c
kernel/ip_set_core.c
kernel/ip_set_hash_ip.c
kernel/ip_set_hash_ipport.c
kernel/ip_set_hash_ipportip.c
kernel/ip_set_hash_ipportnet.c
kernel/ip_set_hash_net.c
kernel/ip_set_hash_netport.c
kernel/ip_set_list_set.c