From: Florian Westphal Date: Wed, 21 Jun 2023 08:36:26 +0000 (+0200) Subject: netfilter: nf_tables: allow loop termination for pending fatal signal X-Git-Tag: 6.6-rc-smb3-client-fixes-part2~52^2~47^2 X-Git-Url: http://git.samba.org/?a=commitdiff_plain;h=169384fbe8513185499bcbb817d198e6a63eb37e;p=sfrench%2Fcifs-2.6.git netfilter: nf_tables: allow loop termination for pending fatal signal abort early so task can exit faster if a fatal signal is pending, no need to continue validation in that case. Signed-off-by: Florian Westphal --- diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c index 3e841e45f2c0..f00a1dff85e8 100644 --- a/net/netfilter/nf_tables_api.c +++ b/net/netfilter/nf_tables_api.c @@ -3675,6 +3675,9 @@ int nft_chain_validate(const struct nft_ctx *ctx, const struct nft_chain *chain) return -EMLINK; list_for_each_entry(rule, &chain->rules, list) { + if (fatal_signal_pending(current)) + return -EINTR; + if (!nft_is_active_next(ctx->net, rule)) continue; @@ -10479,6 +10482,9 @@ static int nf_tables_check_loops(const struct nft_ctx *ctx, if (ctx->chain == chain) return -ELOOP; + if (fatal_signal_pending(current)) + return -EINTR; + list_for_each_entry(rule, &chain->rules, list) { nft_rule_for_each_expr(expr, last, rule) { struct nft_immediate_expr *priv;