netfilter: nf_tables: validate NFPROTO_* family
[ Upstream commit
d0009effa8862c20a13af4cb7475d9771b905693 ]
Several expressions explicitly refer to NF_INET_* hook definitions
from expr->ops->validate, however, family is not validated.
Bail out with EOPNOTSUPP in case they are used from unsupported
families.
Fixes:
0ca743a55991 ("netfilter: nf_tables: add compatibility layer for x_tables")
Fixes:
a3c90f7a2323 ("netfilter: nf_tables: flow offload expression")
Fixes:
2fa841938c64 ("netfilter: nf_tables: introduce routing expression")
Fixes:
554ced0a6e29 ("netfilter: nf_tables: add support for native socket matching")
Fixes:
ad49d86e07a4 ("netfilter: nf_tables: Add synproxy support")
Fixes:
4ed8eb6570a4 ("netfilter: nf_tables: Add native tproxy support")
Fixes:
6c47260250fc ("netfilter: nf_tables: add xfrm expression")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>