-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
yaml --- r: 6239 b: refs/heads/master c: 020b4c1 h: refs/heads/master i: 6237: dc82367 6235: 1ae6c1f 6231: 1c82ead 6223: 30cb91b 6207: afe06d6 v: v3
- Loading branch information
Harald Welte
authored and
David S. Miller
committed
Aug 29, 2005
1 parent
37d0e17
commit 07f7c0d
Showing
8 changed files
with
125 additions
and
110 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,2 +1,2 @@ | ||
--- | ||
refs/heads/master: 089af26c706d1473f641c909fee7c878d29c1f1a | ||
refs/heads/master: 020b4c12dbe3868d792a01d7c1470cd837abe10f |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,79 @@ | ||
#include <linux/config.h> | ||
|
||
#ifdef CONFIG_NETFILTER | ||
|
||
/* IPv4 specific functions of netfilter core */ | ||
#include <linux/kernel.h> | ||
#include <linux/netfilter.h> | ||
|
||
#include <linux/tcp.h> | ||
#include <linux/udp.h> | ||
#include <linux/icmp.h> | ||
#include <net/route.h> | ||
#include <linux/ip.h> | ||
|
||
/* route_me_harder function, used by iptable_nat, iptable_mangle + ip_queue */ | ||
int ip_route_me_harder(struct sk_buff **pskb) | ||
{ | ||
struct iphdr *iph = (*pskb)->nh.iph; | ||
struct rtable *rt; | ||
struct flowi fl = {}; | ||
struct dst_entry *odst; | ||
unsigned int hh_len; | ||
|
||
/* some non-standard hacks like ipt_REJECT.c:send_reset() can cause | ||
* packets with foreign saddr to appear on the NF_IP_LOCAL_OUT hook. | ||
*/ | ||
if (inet_addr_type(iph->saddr) == RTN_LOCAL) { | ||
fl.nl_u.ip4_u.daddr = iph->daddr; | ||
fl.nl_u.ip4_u.saddr = iph->saddr; | ||
fl.nl_u.ip4_u.tos = RT_TOS(iph->tos); | ||
fl.oif = (*pskb)->sk ? (*pskb)->sk->sk_bound_dev_if : 0; | ||
#ifdef CONFIG_IP_ROUTE_FWMARK | ||
fl.nl_u.ip4_u.fwmark = (*pskb)->nfmark; | ||
#endif | ||
fl.proto = iph->protocol; | ||
if (ip_route_output_key(&rt, &fl) != 0) | ||
return -1; | ||
|
||
/* Drop old route. */ | ||
dst_release((*pskb)->dst); | ||
(*pskb)->dst = &rt->u.dst; | ||
} else { | ||
/* non-local src, find valid iif to satisfy | ||
* rp-filter when calling ip_route_input. */ | ||
fl.nl_u.ip4_u.daddr = iph->saddr; | ||
if (ip_route_output_key(&rt, &fl) != 0) | ||
return -1; | ||
|
||
odst = (*pskb)->dst; | ||
if (ip_route_input(*pskb, iph->daddr, iph->saddr, | ||
RT_TOS(iph->tos), rt->u.dst.dev) != 0) { | ||
dst_release(&rt->u.dst); | ||
return -1; | ||
} | ||
dst_release(&rt->u.dst); | ||
dst_release(odst); | ||
} | ||
|
||
if ((*pskb)->dst->error) | ||
return -1; | ||
|
||
/* Change in oif may mean change in hh_len. */ | ||
hh_len = (*pskb)->dst->dev->hard_header_len; | ||
if (skb_headroom(*pskb) < hh_len) { | ||
struct sk_buff *nskb; | ||
|
||
nskb = skb_realloc_headroom(*pskb, hh_len); | ||
if (!nskb) | ||
return -1; | ||
if ((*pskb)->sk) | ||
skb_set_owner_w(nskb, (*pskb)->sk); | ||
kfree_skb(*pskb); | ||
*pskb = nskb; | ||
} | ||
|
||
return 0; | ||
} | ||
EXPORT_SYMBOL(ip_route_me_harder); | ||
#endif /* CONFIG_NETFILTER */ |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,43 @@ | ||
#include <linux/config.h> | ||
#include <linux/init.h> | ||
|
||
#ifdef CONFIG_NETFILTER | ||
|
||
#include <linux/kernel.h> | ||
#include <linux/ipv6.h> | ||
#include <net/dst.h> | ||
#include <net/ipv6.h> | ||
#include <net/ip6_route.h> | ||
|
||
int ip6_route_me_harder(struct sk_buff *skb) | ||
{ | ||
struct ipv6hdr *iph = skb->nh.ipv6h; | ||
struct dst_entry *dst; | ||
struct flowi fl = { | ||
.oif = skb->sk ? skb->sk->sk_bound_dev_if : 0, | ||
.nl_u = | ||
{ .ip6_u = | ||
{ .daddr = iph->daddr, | ||
.saddr = iph->saddr, } }, | ||
.proto = iph->nexthdr, | ||
}; | ||
|
||
dst = ip6_route_output(skb->sk, &fl); | ||
|
||
if (dst->error) { | ||
IP6_INC_STATS(IPSTATS_MIB_OUTNOROUTES); | ||
LIMIT_NETDEBUG( | ||
printk(KERN_DEBUG "ip6_route_me_harder: No more route.\n")); | ||
dst_release(dst); | ||
return -EINVAL; | ||
} | ||
|
||
/* Drop old route. */ | ||
dst_release(skb->dst); | ||
|
||
skb->dst = dst; | ||
return 0; | ||
} | ||
EXPORT_SYMBOL(ip6_route_me_harder); | ||
|
||
#endif /* CONFIG_NETFILTER */ |