netfilter: nf_tables: move hardware offload step after building the chain blob
authorPablo Neira Ayuso <pablo@netfilter.org>
Thu, 13 Aug 2026 00:16:02 +0000 (02:16 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 27 Aug 2026 14:10:57 +0000 (16:10 +0200)
Allocate the chain blob before the ruleset offload to reduce chances of
entering an inconsistent state where the offloaded ruleset in the nic
and the software ruleset differ.

Fixes: c9626a2cbdb2 ("netfilter: nf_tables: add hardware offload support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c

index c112ecc..71f4227 100644 (file)
@@ -10982,10 +10982,6 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
                return -EAGAIN;
        }
 
-       err = nft_flow_rule_offload_commit(net);
-       if (err < 0)
-               return err;
-
        /* 1.  Allocate space for next generation rules_gen_X[] */
        list_for_each_entry_safe(trans, next, &nft_net->commit_list, list) {
                struct nft_table *table = trans->table;
@@ -11010,6 +11006,16 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
                }
        }
 
+       /* must be last, so audit and chain blob set up does not leave hardware
+        * in consistent state.
+        */
+       err = nft_flow_rule_offload_commit(net);
+       if (err < 0) {
+               nf_tables_commit_chain_prepare_cancel(net);
+               nf_tables_commit_audit_free(&adl);
+               return err;
+       }
+
        /* step 2.  Make rules_gen_X visible to packet path */
        nft_set_commit_update(&ctx, nft_net);