• Hannes Frederic Sowa's avatar
    ipv6: fib6_rules should return exact return value · 46b3a421
    Hannes Frederic Sowa authored
    With the addition of the suppress operation
    (7764a45a ("fib_rules: add .suppress
    operation") we rely on accurate error reporting of the fib_rules.actions.
    
    fib6_rule_action always returned -EAGAIN in case we could not find a
    matching route and 0 if a rule was matched. This also included a match
    for blackhole or prohibited rule actions which could get suppressed by
    the new logic.
    
    So adapt fib6_rule_action to always return the correct error code as
    its counterpart fib4_rule_action does. This also fixes a possiblity of
    nullptr-deref where we don't find a table, thus rt == NULL. Because
    the condition rt != ip6_null_entry still holdes it seems we could later
    get a nullptr bug on dereference rt->dst.
    
    v2:
    a) Fixed a brain fart in the commit msg (the rule => a table, etc). No
       changes to the patch.
    
    Cc: Stefan Tomanek <stefan.tomanek@wertarbyte.de>
    Cc: Hideaki YOSHIFUJI <yoshfuji@linux-ipv6.org>
    Signed-off-by: default avatarHannes Frederic Sowa <hannes@stressinduktion.org>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    46b3a421
fib6_rules.c 7.38 KB