The spec defines encap-type (unspec / direct / gue), but no attribute
references it, so the definition exists only to emit FOU_ENCAP_* into
the uAPI header - while FOU_ATTR_TYPE is exactly that value space:
fou_create() switches on FOU_ENCAP_DIRECT / FOU_ENCAP_GUE and returns
-EINVAL for anything else. Python YNL could not accept or display the
names and the generated C exposed a raw __u8 setter.
The global policy entry becomes NLA_POLICY_MAX(NLA_U8, 2). For add
that only moves the existing fou_create() rejection earlier; del and
get ignore FOU_ATTR_TYPE altogether, so a bogus type there now fails
validation instead of being dropped on the floor.
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
Documentation/netlink/specs/fou.yaml | 1 +
net/ipv4/fou_nl.c | 2 +-
2 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/Documentation/netlink/specs/fou.yaml b/Documentation/netlink/specs/fou.yaml
index 1d0db6ba7e52..3e6a38e31202 100644
--- a/Documentation/netlink/specs/fou.yaml
+++ b/Documentation/netlink/specs/fou.yaml
@@ -44,6 +44,7 @@ kernel-policy: global
-
name: type
type: u8
+ enum: encap-type
-
name: remcsum-nopartial
type: flagdiff --git a/net/ipv4/fou_nl.c b/net/ipv4/fou_nl.c
index cdb174b92cdd..ccd134ba352d 100644
--- a/net/ipv4/fou_nl.c
+++ b/net/ipv4/fou_nl.c
@@ -16,7 +16,7 @@ const struct nla_policy fou_nl_policy[FOU_ATTR_IFINDEX + 1] = {
[FOU_ATTR_PORT] = { .type = NLA_BE16, },
[FOU_ATTR_AF] = { .type = NLA_U8, },
[FOU_ATTR_IPPROTO] = NLA_POLICY_MIN(NLA_U8, 1),
- [FOU_ATTR_TYPE] = { .type = NLA_U8, },
+ [FOU_ATTR_TYPE] = NLA_POLICY_MAX(NLA_U8, 2),
[FOU_ATTR_REMCSUM_NOPARTIAL] = { .type = NLA_FLAG, },
[FOU_ATTR_LOCAL_V4] = { .type = NLA_BE32, },
[FOU_ATTR_LOCAL_V6] = NLA_POLICY_EXACT_LEN(16),--
2.55.0