Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

netfilter: ipset: Removed invalid IPSET_ATTR_MARKMASK validation

Markmask is an u32, hence it can't be greater then 4294967295 ( i.e.
0xffffffff ). This was causing smatch warning:
net/netfilter/ipset/ip_set_hash_gen.h:1084 hash_ipmark_create() warn:
impossible condition '(markmask > 4294967295) => (0-u32max > u32max)'

Signed-off-by: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>

authored by

Vytas Dauksa and committed by
Jozsef Kadlecsik
ecc245c2 afc5be30

+1 -1
+1 -1
net/netfilter/ipset/ip_set_hash_gen.h
··· 1093 1093 if (tb[IPSET_ATTR_MARKMASK]) { 1094 1094 markmask = ntohl(nla_get_u32(tb[IPSET_ATTR_MARKMASK])); 1095 1095 1096 - if ((markmask > 4294967295u) || markmask == 0) 1096 + if (markmask == 0) 1097 1097 return -IPSET_ERR_INVALID_MARKMASK; 1098 1098 } 1099 1099 #endif