diff --git a/backport-rule-set_elem-fix-printing-of-user-data.patch b/backport-rule-set_elem-fix-printing-of-user-data.patch new file mode 100644 index 0000000..bfe1a3a --- /dev/null +++ b/backport-rule-set_elem-fix-printing-of-user-data.patch @@ -0,0 +1,61 @@ +From 212479ad2c9200fa858a37de14a2e5e996f10105 Mon Sep 17 00:00:00 2001 +From: Jeremy Sowden +Date: Sat, 27 Aug 2022 18:17:17 +0100 +Subject: [PATCH] rule, set_elem: fix printing of user data + +Hitherto, alphanumeric characters have been printed as-is, but anything +else was replaced by '\0'. However, this effectively truncates the +output. Instead, print any printable character as-is and print anything +else as a hexadecimal escape sequence: + + userdata = { \x01\x04\x01\x00\x00\x00 } + +Signed-off-by: Jeremy Sowden +Signed-off-by: Pablo Neira Ayuso +--- + src/rule.c | 5 +++-- + src/set_elem.c | 7 ++++--- + 2 files changed, 7 insertions(+), 5 deletions(-) + +diff --git a/src/rule.c b/src/rule.c +index 0bb1c2a..a1a64bd 100644 +--- a/src/rule.c ++++ b/src/rule.c +@@ -622,8 +622,9 @@ static int nftnl_rule_snprintf_default(char *buf, size_t remain, + for (i = 0; i < r->user.len; i++) { + char *c = r->user.data; + +- ret = snprintf(buf + offset, remain, "%c", +- isalnum(c[i]) ? c[i] : 0); ++ ret = snprintf(buf + offset, remain, ++ isprint(c[i]) ? "%c" : "\\x%02hhx", ++ c[i]); + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + } + +diff --git a/src/set_elem.c b/src/set_elem.c +index 90632a2..104719b 100644 +--- a/src/set_elem.c ++++ b/src/set_elem.c +@@ -732,14 +732,15 @@ int nftnl_set_elem_snprintf_default(char *buf, size_t remain, + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + + if (e->user.len) { +- ret = snprintf(buf + offset, remain, " userdata = {"); ++ ret = snprintf(buf + offset, remain, " userdata = { "); + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + + for (i = 0; i < e->user.len; i++) { + char *c = e->user.data; + +- ret = snprintf(buf + offset, remain, "%c", +- isalnum(c[i]) ? c[i] : 0); ++ ret = snprintf(buf + offset, remain, ++ isprint(c[i]) ? "%c" : "\\x%02hhx", ++ c[i]); + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + } + +-- +2.33.0 + diff --git a/backport-rule-set_elem-remove-trailing-n-in-userdata-snprintf.patch b/backport-rule-set_elem-remove-trailing-n-in-userdata-snprintf.patch new file mode 100644 index 0000000..11fb79e --- /dev/null +++ b/backport-rule-set_elem-remove-trailing-n-in-userdata-snprintf.patch @@ -0,0 +1,43 @@ +From c759027a526ac09ce413dc88c308a4ed98b33416 Mon Sep 17 00:00:00 2001 +From: Pablo Neira Ayuso +Date: Wed, 31 Aug 2022 16:52:51 +0200 +Subject: [PATCH] rule, set_elem: remove trailing \n in userdata snprintf + +212479ad2c92 ("rule, set_elem: fix printing of user data") uncovered +another an extra line break in the userdata printing, remove it. + +Signed-off-by: Pablo Neira Ayuso +--- + src/rule.c | 2 +- + src/set_elem.c | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/rule.c b/src/rule.c +index a1a64bd..a52012b 100644 +--- a/src/rule.c ++++ b/src/rule.c +@@ -628,7 +628,7 @@ static int nftnl_rule_snprintf_default(char *buf, size_t remain, + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + } + +- ret = snprintf(buf + offset, remain, " }\n"); ++ ret = snprintf(buf + offset, remain, " }"); + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + + } +diff --git a/src/set_elem.c b/src/set_elem.c +index 104719b..1c9a96b 100644 +--- a/src/set_elem.c ++++ b/src/set_elem.c +@@ -744,7 +744,7 @@ int nftnl_set_elem_snprintf_default(char *buf, size_t remain, + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + } + +- ret = snprintf(buf + offset, remain, " }\n"); ++ ret = snprintf(buf + offset, remain, " }"); + SNPRINTF_BUFFER_SIZE(ret, remain, offset); + } + +-- +2.33.0 + diff --git a/libnftnl.spec b/libnftnl.spec index f563320..21400b0 100644 --- a/libnftnl.spec +++ b/libnftnl.spec @@ -1,11 +1,14 @@ Name: libnftnl Version: 1.2.0 -Release: 2 +Release: 3 Summary: Library for low-level interaction with nftables Netlink's API over libmnl License: GPLv2+ URL: http://netfilter.org/projects/libnftnl/ Source0: http://netfilter.org/projects/libnftnl/files/%{name}-%{version}.tar.bz2 +Patch6000: backport-rule-set_elem-fix-printing-of-user-data.patch +Patch6001: backport-rule-set_elem-remove-trailing-n-in-userdata-snprintf.patch + BuildRequires: libmnl-devel jansson-devel gcc # replace old libnftables package @@ -51,6 +54,9 @@ make %{?_smp_mflags} check %{_includedir}/libnftnl %changelog +* Sun May 28 2023 shixuantong - 1.2.0-3 +- sync community patch + * Tue Oct 25 2022 yanglongkang - 1.2.0-2 - rebuild for next release