]> git.hungrycats.org Git - linux/commit
netfilter: nft_lookup: fix catchall element handling with inverted lookups
authorTamaki Yanagawa <ty@000ty.net>
Fri, 3 Jul 2026 16:22:57 +0000 (16:22 +0000)
committerFlorian Westphal <fw@strlen.de>
Wed, 8 Jul 2026 13:33:37 +0000 (15:33 +0200)
commite6107a4c74b54cb33e3bce162a63048ae5a6b198
tree7eb26e84bfb0137112bcfc8fc943d82d1246c37d
parent084d23f818321390509e9738a0b08bbf46df6425
netfilter: nft_lookup: fix catchall element handling with inverted lookups

nft_lookup_eval() decides whether a lookup matched (`found`) from the
direct set lookup and priv->invert before falling back to the
catchall element used by interval sets (e.g. nft_set_rbtree) for the
open-ended default range. Since `found` is never recomputed after
`ext` is replaced by the catchall lookup, inverted lookups
(NFT_LOOKUP_F_INV, "!= @set") can wrongly match or wrongly skip the
catchall element, producing the wrong verdict. Fold the catchall
lookup into `ext` before computing `found`, matching the order
already used by nft_objref_map_eval().

Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support")
Signed-off-by: Tamaki Yanagawa <ty@000ty.net>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Florian Westphal <fw@strlen.de>
net/netfilter/nft_lookup.c