diff options
author | Patrick McHardy <kaber@trash.net> | 2014-01-09 13:42:35 -0500 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2014-01-09 14:17:14 -0500 |
commit | 88ce65a71c39901494eb2f1393856bff8ba0158d (patch) | |
tree | 74ec344b9b23c85c96c47d26afe1a8bae3aa539e /net/ipv4 | |
parent | baae3e62f31618d90e08fb886b4481e5d7b7f27c (diff) |
netfilter: nf_tables: add missing module references to chain types
In some cases we neither take a reference to the AF info nor to the
chain type, allowing the module to be unloaded while in use.
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/ipv4')
-rw-r--r-- | net/ipv4/netfilter/nf_tables_arp.c | 1 | ||||
-rw-r--r-- | net/ipv4/netfilter/nf_tables_ipv4.c | 1 |
2 files changed, 2 insertions, 0 deletions
diff --git a/net/ipv4/netfilter/nf_tables_arp.c b/net/ipv4/netfilter/nf_tables_arp.c index 36d27fc7e859..228df003f3cc 100644 --- a/net/ipv4/netfilter/nf_tables_arp.c +++ b/net/ipv4/netfilter/nf_tables_arp.c | |||
@@ -72,6 +72,7 @@ static struct nf_chain_type filter_arp = { | |||
72 | .family = NFPROTO_ARP, | 72 | .family = NFPROTO_ARP, |
73 | .name = "filter", | 73 | .name = "filter", |
74 | .type = NFT_CHAIN_T_DEFAULT, | 74 | .type = NFT_CHAIN_T_DEFAULT, |
75 | .me = THIS_MODULE, | ||
75 | .hook_mask = (1 << NF_ARP_IN) | | 76 | .hook_mask = (1 << NF_ARP_IN) | |
76 | (1 << NF_ARP_OUT) | | 77 | (1 << NF_ARP_OUT) | |
77 | (1 << NF_ARP_FORWARD), | 78 | (1 << NF_ARP_FORWARD), |
diff --git a/net/ipv4/netfilter/nf_tables_ipv4.c b/net/ipv4/netfilter/nf_tables_ipv4.c index da927dc9f636..d6fc1b4ace4e 100644 --- a/net/ipv4/netfilter/nf_tables_ipv4.c +++ b/net/ipv4/netfilter/nf_tables_ipv4.c | |||
@@ -95,6 +95,7 @@ static struct nf_chain_type filter_ipv4 = { | |||
95 | .family = NFPROTO_IPV4, | 95 | .family = NFPROTO_IPV4, |
96 | .name = "filter", | 96 | .name = "filter", |
97 | .type = NFT_CHAIN_T_DEFAULT, | 97 | .type = NFT_CHAIN_T_DEFAULT, |
98 | .me = THIS_MODULE, | ||
98 | .hook_mask = (1 << NF_INET_LOCAL_IN) | | 99 | .hook_mask = (1 << NF_INET_LOCAL_IN) | |
99 | (1 << NF_INET_LOCAL_OUT) | | 100 | (1 << NF_INET_LOCAL_OUT) | |
100 | (1 << NF_INET_FORWARD) | | 101 | (1 << NF_INET_FORWARD) | |