netfilter: nf_tables: Audit log setelem reset
authorPhil Sutter <phil@nwl.cc>
Tue, 29 Aug 2023 17:51:57 +0000 (19:51 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 30 Aug 2023 23:29:27 +0000 (01:29 +0200)
commit7e9be1124dbe7888907e82cab20164578e3f9ab7
tree09fbb6809610a2bde1d514ac57a31b041ece18fb
parent69c5d284f67089b4750d28ff6ac6f52ec224b330
netfilter: nf_tables: Audit log setelem reset

Since set element reset is not integrated into nf_tables' transaction
logic, an explicit log call is needed, similar to NFT_MSG_GETOBJ_RESET
handling.

For the sake of simplicity, catchall element reset will always generate
a dedicated log entry. This relieves nf_tables_dump_set() from having to
adjust the logged element count depending on whether a catchall element
was found or not.

Fixes: 079cd633219d7 ("netfilter: nf_tables: Introduce NFT_MSG_GETSETELEM_RESET")
Signed-off-by: Phil Sutter <phil@nwl.cc>
Reviewed-by: Richard Guy Briggs <rgb@redhat.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/linux/audit.h
kernel/auditsc.c
net/netfilter/nf_tables_api.c