aboutsummaryrefslogtreecommitdiffstats
path: root/net/ipv4
diff options
context:
space:
mode:
authorPablo Neira Ayuso <pablo@netfilter.org>2006-11-28 20:35:31 -0500
committerDavid S. Miller <davem@sunset.davemloft.net>2006-12-03 00:31:27 -0500
commitbbb3357d14f6becd156469220992ef7ab0f10e69 (patch)
treef24b5b6491c76d3b384bc09307d6b841fbc0370c /net/ipv4
parent1b683b551209ca46ae59b29572018001db5af078 (diff)
[NETFILTER]: ctnetlink: check for status attribute existence on conntrack creation
Check that status flags are available in the netlink message received to create a new conntrack. Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Patrick McHardy <kaber@trash.net>
Diffstat (limited to 'net/ipv4')
-rw-r--r--net/ipv4/netfilter/ip_conntrack_netlink.c8
1 files changed, 5 insertions, 3 deletions
diff --git a/net/ipv4/netfilter/ip_conntrack_netlink.c b/net/ipv4/netfilter/ip_conntrack_netlink.c
index 3d277aa869dd..d5d2efddba57 100644
--- a/net/ipv4/netfilter/ip_conntrack_netlink.c
+++ b/net/ipv4/netfilter/ip_conntrack_netlink.c
@@ -945,9 +945,11 @@ ctnetlink_create_conntrack(struct nfattr *cda[],
945 ct->timeout.expires = jiffies + ct->timeout.expires * HZ; 945 ct->timeout.expires = jiffies + ct->timeout.expires * HZ;
946 ct->status |= IPS_CONFIRMED; 946 ct->status |= IPS_CONFIRMED;
947 947
948 err = ctnetlink_change_status(ct, cda); 948 if (cda[CTA_STATUS-1]) {
949 if (err < 0) 949 err = ctnetlink_change_status(ct, cda);
950 goto err; 950 if (err < 0)
951 goto err;
952 }
951 953
952 if (cda[CTA_PROTOINFO-1]) { 954 if (cda[CTA_PROTOINFO-1]) {
953 err = ctnetlink_change_protoinfo(ct, cda); 955 err = ctnetlink_change_protoinfo(ct, cda);