Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 15714f7b authored by Eric Paris's avatar Eric Paris Committed by James Morris
Browse files

secmark: do not return early if there was no error



Commit 4a5a5c73 attempted to pass decent error messages back to userspace for
netfilter errors.  In xt_SECMARK.c however the patch screwed up and returned
on 0 (aka no error) early and didn't finish setting up secmark.  This results
in a kernel BUG if you use SECMARK.

Signed-off-by: default avatarEric Paris <eparis@redhat.com>
Acked-by: default avatarPaul Moore <paul.moore@hp.com>
Signed-off-by: default avatarJames Morris <jmorris@namei.org>
parent 3ed02ada
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -101,7 +101,7 @@ static int secmark_tg_check(const struct xt_tgchk_param *par)
	switch (info->mode) {
	case SECMARK_MODE_SEL:
		err = checkentry_selinux(info);
		if (err <= 0)
		if (err)
			return err;
		break;