netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire
[ Upstream commite0c4728172] Element timeout that is below CONFIG_HZ never expires because the timeout extension is not allocated given that nf_msecs_to_jiffies64() returns 0. Set timeout to the minimum value to honor timeout. Fixes:8e1102d5a1("netfilter: nf_tables: support timeouts larger than 23 days") Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
94e8c98846
commit
616aa28739
@@ -4153,7 +4153,7 @@ int nf_msecs_to_jiffies64(const struct nlattr *nla, u64 *result)
|
||||
return -ERANGE;
|
||||
|
||||
ms *= NSEC_PER_MSEC;
|
||||
*result = nsecs_to_jiffies64(ms);
|
||||
*result = nsecs_to_jiffies64(ms) ? : !!ms;
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user