]> git.karo-electronics.de Git - linux-beck.git/commitdiff
netfilter: ipset: Removed invalid IPSET_ATTR_MARKMASK validation
authorVytas Dauksa <vytas.dauksa@smoothwall.net>
Fri, 4 Apr 2014 15:10:14 +0000 (16:10 +0100)
committerJozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Sun, 24 Aug 2014 17:31:34 +0000 (19:31 +0200)
Markmask is an u32, hence it can't be greater then 4294967295 ( i.e.
0xffffffff ). This was causing smatch warning:
 net/netfilter/ipset/ip_set_hash_gen.h:1084 hash_ipmark_create() warn:
 impossible condition '(markmask > 4294967295) => (0-u32max > u32max)'

Signed-off-by: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
net/netfilter/ipset/ip_set_hash_gen.h

index 61c7fb052802e7c0cb291289ee29c484b4f84179..0398a92da6cca8bbece002e62293ce718841f161 100644 (file)
@@ -1093,7 +1093,7 @@ IPSET_TOKEN(HTYPE, _create)(struct net *net, struct ip_set *set,
        if (tb[IPSET_ATTR_MARKMASK]) {
                markmask = ntohl(nla_get_u32(tb[IPSET_ATTR_MARKMASK]));
 
-               if ((markmask > 4294967295u) || markmask == 0)
+               if (markmask == 0)
                        return -IPSET_ERR_INVALID_MARKMASK;
        }
 #endif