netfilter: ebtables: compat: un-break 32bit setsockopt when no rules are present
authorFlorian Westphal <fw@strlen.de>
Mon, 21 Jan 2019 20:54:36 +0000 (21:54 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 28 Jan 2019 09:49:43 +0000 (10:49 +0100)
commit2035f3ff8eaa29cfb5c8e2160b0f6e85eeb21a95
tree3e11285dc009f789270795b845d8e9b0d31715ad
parent53ab60baa1ac4f20b080a22c13b77b6373922fd7
netfilter: ebtables: compat: un-break 32bit setsockopt when no rules are present

Unlike ip(6)tables ebtables only counts user-defined chains.

The effect is that a 32bit ebtables binary on a 64bit kernel can do
'ebtables -N FOO' only after adding at least one rule, else the request
fails with -EINVAL.

This is a similar fix as done in
3f1e53abff84 ("netfilter: ebtables: don't attempt to allocate 0-sized compat array").

Fixes: 7d7d7e02111e9 ("netfilter: compat: reject huge allocation requests")
Reported-by: Francesco Ruggeri <fruggeri@arista.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/bridge/netfilter/ebtables.c