forked from Freescale/linux-fslc
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
netfilter: combine IPv4 and IPv6 nf_nat_redirect code in one module
This resolves linking problems with CONFIG_IPV6=n: net/built-in.o: In function `redirect_tg6': xt_REDIRECT.c:(.text+0x6d021): undefined reference to `nf_nat_redirect_ipv6' Reported-by: Andreas Ruprecht <[email protected]> Reported-by: Or Gerlitz <[email protected]> Signed-off-by: Pablo Neira Ayuso <[email protected]>
- Loading branch information
Showing
14 changed files
with
72 additions
and
115 deletions.
There are no files selected for viewing
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,12 @@ | ||
#ifndef _NF_NAT_REDIRECT_H_ | ||
#define _NF_NAT_REDIRECT_H_ | ||
|
||
unsigned int | ||
nf_nat_redirect_ipv4(struct sk_buff *skb, | ||
const struct nf_nat_ipv4_multi_range_compat *mr, | ||
unsigned int hooknum); | ||
unsigned int | ||
nf_nat_redirect_ipv6(struct sk_buff *skb, const struct nf_nat_range *range, | ||
unsigned int hooknum); | ||
|
||
#endif /* _NF_NAT_REDIRECT_H_ */ |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -20,12 +20,13 @@ | |
#include <linux/netfilter.h> | ||
#include <linux/types.h> | ||
#include <linux/netfilter_ipv4.h> | ||
#include <linux/netfilter_ipv6.h> | ||
#include <linux/netfilter/x_tables.h> | ||
#include <net/addrconf.h> | ||
#include <net/checksum.h> | ||
#include <net/protocol.h> | ||
#include <net/netfilter/nf_nat.h> | ||
#include <net/netfilter/ipv4/nf_nat_redirect.h> | ||
#include <net/netfilter/nf_nat_redirect.h> | ||
|
||
unsigned int | ||
nf_nat_redirect_ipv4(struct sk_buff *skb, | ||
|
@@ -78,5 +79,49 @@ nf_nat_redirect_ipv4(struct sk_buff *skb, | |
} | ||
EXPORT_SYMBOL_GPL(nf_nat_redirect_ipv4); | ||
|
||
static const struct in6_addr loopback_addr = IN6ADDR_LOOPBACK_INIT; | ||
|
||
unsigned int | ||
nf_nat_redirect_ipv6(struct sk_buff *skb, const struct nf_nat_range *range, | ||
unsigned int hooknum) | ||
{ | ||
struct nf_nat_range newrange; | ||
struct in6_addr newdst; | ||
enum ip_conntrack_info ctinfo; | ||
struct nf_conn *ct; | ||
|
||
ct = nf_ct_get(skb, &ctinfo); | ||
if (hooknum == NF_INET_LOCAL_OUT) { | ||
newdst = loopback_addr; | ||
} else { | ||
struct inet6_dev *idev; | ||
struct inet6_ifaddr *ifa; | ||
bool addr = false; | ||
|
||
rcu_read_lock(); | ||
idev = __in6_dev_get(skb->dev); | ||
if (idev != NULL) { | ||
list_for_each_entry(ifa, &idev->addr_list, if_list) { | ||
newdst = ifa->addr; | ||
addr = true; | ||
break; | ||
} | ||
} | ||
rcu_read_unlock(); | ||
|
||
if (!addr) | ||
return NF_DROP; | ||
} | ||
|
||
newrange.flags = range->flags | NF_NAT_RANGE_MAP_IPS; | ||
newrange.min_addr.in6 = newdst; | ||
newrange.max_addr.in6 = newdst; | ||
newrange.min_proto = range->min_proto; | ||
newrange.max_proto = range->max_proto; | ||
|
||
return nf_nat_setup_info(ct, &newrange, NF_NAT_MANIP_DST); | ||
} | ||
EXPORT_SYMBOL_GPL(nf_nat_redirect_ipv6); | ||
|
||
MODULE_LICENSE("GPL"); | ||
MODULE_AUTHOR("Patrick McHardy <[email protected]>"); |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters