Skip to content
  • Florian Westphal's avatar
    netfilter: ebtables: try native set/getsockopt handlers, too · 90b89af7
    Florian Westphal authored
    
    
    ebtables can be compiled to perform userspace-side padding of
    structures. In that case, all the structures are already in the
    'native' format expected by the kernel.
    
    This tries to determine what format the userspace program is
    using.
    
    For most set/getsockopts, this can be done by checking
    the len argument for sizeof(compat_ebt_replace) and
    re-trying the native handler on error.
    
    In case of EBT_SO_GET_ENTRIES, the native handler is tried first,
    it will error out early when checking the *len argument
    (the compat version has to defer this check until after
     iterating over the kernel data set once, to adjust for all
     the structure size differences).
    
    As this would cause error printks, remove those as well, as
    recommended by Bart de Schuymer.
    
    Signed-off-by: default avatarFlorian Westphal <fw@strlen.de>
    90b89af7