net: bridge: Set strict_start_type for br_policy
authorJohannes Nixdorf <jnixdorf-oss@avm.de>
Mon, 16 Oct 2023 13:27:23 +0000 (15:27 +0200)
committerJakub Kicinski <kuba@kernel.org>
Wed, 18 Oct 2023 00:39:02 +0000 (17:39 -0700)
Set any new attributes added to br_policy to be parsed strictly, to
prevent userspace from passing garbage.

Signed-off-by: Johannes Nixdorf <jnixdorf-oss@avm.de>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://lore.kernel.org/r/20231016-fdb_limit-v5-4-32cddff87758@avm.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/bridge/br_netlink.c

index 0c3cf6e..5ad4abf 100644 (file)
@@ -1229,6 +1229,8 @@ static size_t br_port_get_slave_size(const struct net_device *brdev,
 }
 
 static const struct nla_policy br_policy[IFLA_BR_MAX + 1] = {
+       [IFLA_BR_UNSPEC]        = { .strict_start_type =
+                                   IFLA_BR_FDB_N_LEARNED },
        [IFLA_BR_FORWARD_DELAY] = { .type = NLA_U32 },
        [IFLA_BR_HELLO_TIME]    = { .type = NLA_U32 },
        [IFLA_BR_MAX_AGE]       = { .type = NLA_U32 },