Skip to content
Commit 2cdaa3ee authored by Pablo Neira Ayuso's avatar Pablo Neira Ayuso
Browse files

netfilter: conntrack: restore IPS_CONFIRMED out of nf_conntrack_hash_check_insert()



e6d57e9f ("netfilter: conntrack: fix rmmod double-free race")
consolidates IPS_CONFIRMED bit set in nf_conntrack_hash_check_insert().
However, this breaks ctnetlink:

 # conntrack -I -p tcp --timeout 123 --src 1.2.3.4 --dst 5.6.7.8 --state ESTABLISHED --sport 1 --dport 4 -u SEEN_REPLY
 conntrack v1.4.6 (conntrack-tools): Operation failed: Device or resource busy

This is a partial revert of the aforementioned commit to restore
IPS_CONFIRMED.

Fixes: e6d57e9f ("netfilter: conntrack: fix rmmod double-free race")
Reported-by: default avatarStéphane Graber <stgraber@stgraber.org>
Tested-by: default avatarStéphane Graber <stgraber@stgraber.org>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent 92e8c732
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment