-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
netfilter: split netfilter IPv4 defragmentation into a separate module
Netfilter connection tracking requires all IPv4 packets to be defragmented. Both the socket match and the TPROXY target depend on this functionality, so this patch separates the Netfilter IPv4 defrag hooks into a separate module. Signed-off-by: KOVACS Krisztian <hidden@sch.bme.hu> Signed-off-by: Patrick McHardy <kaber@trash.net>
- Loading branch information
KOVACS Krisztian
authored and
Patrick McHardy
committed
Oct 8, 2008
1 parent
4de6f16
commit 73e4022
Showing
5 changed files
with
113 additions
and
53 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
#ifndef _NF_DEFRAG_IPV4_H | ||
#define _NF_DEFRAG_IPV4_H | ||
|
||
extern void nf_defrag_ipv4_enable(void); | ||
|
||
#endif /* _NF_DEFRAG_IPV4_H */ |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,96 @@ | ||
/* (C) 1999-2001 Paul `Rusty' Russell | ||
* (C) 2002-2004 Netfilter Core Team <coreteam@netfilter.org> | ||
* | ||
* This program is free software; you can redistribute it and/or modify | ||
* it under the terms of the GNU General Public License version 2 as | ||
* published by the Free Software Foundation. | ||
*/ | ||
|
||
#include <linux/types.h> | ||
#include <linux/ip.h> | ||
#include <linux/netfilter.h> | ||
#include <linux/module.h> | ||
#include <linux/skbuff.h> | ||
#include <net/route.h> | ||
#include <net/ip.h> | ||
|
||
#include <linux/netfilter_ipv4.h> | ||
#include <net/netfilter/ipv4/nf_defrag_ipv4.h> | ||
|
||
/* Returns new sk_buff, or NULL */ | ||
static int nf_ct_ipv4_gather_frags(struct sk_buff *skb, u_int32_t user) | ||
{ | ||
int err; | ||
|
||
skb_orphan(skb); | ||
|
||
local_bh_disable(); | ||
err = ip_defrag(skb, user); | ||
local_bh_enable(); | ||
|
||
if (!err) | ||
ip_send_check(ip_hdr(skb)); | ||
|
||
return err; | ||
} | ||
|
||
static unsigned int ipv4_conntrack_defrag(unsigned int hooknum, | ||
struct sk_buff *skb, | ||
const struct net_device *in, | ||
const struct net_device *out, | ||
int (*okfn)(struct sk_buff *)) | ||
{ | ||
#if defined(CONFIG_NF_CONNTRACK) || defined(CONFIG_NF_CONNTRACK_MODULE) | ||
/* Previously seen (loopback)? Ignore. Do this before | ||
fragment check. */ | ||
if (skb->nfct) | ||
return NF_ACCEPT; | ||
#endif | ||
|
||
/* Gather fragments. */ | ||
if (ip_hdr(skb)->frag_off & htons(IP_MF | IP_OFFSET)) { | ||
if (nf_ct_ipv4_gather_frags(skb, | ||
hooknum == NF_INET_PRE_ROUTING ? | ||
IP_DEFRAG_CONNTRACK_IN : | ||
IP_DEFRAG_CONNTRACK_OUT)) | ||
return NF_STOLEN; | ||
} | ||
return NF_ACCEPT; | ||
} | ||
|
||
static struct nf_hook_ops ipv4_defrag_ops[] = { | ||
{ | ||
.hook = ipv4_conntrack_defrag, | ||
.owner = THIS_MODULE, | ||
.pf = PF_INET, | ||
.hooknum = NF_INET_PRE_ROUTING, | ||
.priority = NF_IP_PRI_CONNTRACK_DEFRAG, | ||
}, | ||
{ | ||
.hook = ipv4_conntrack_defrag, | ||
.owner = THIS_MODULE, | ||
.pf = PF_INET, | ||
.hooknum = NF_INET_LOCAL_OUT, | ||
.priority = NF_IP_PRI_CONNTRACK_DEFRAG, | ||
}, | ||
}; | ||
|
||
static int __init nf_defrag_init(void) | ||
{ | ||
return nf_register_hooks(ipv4_defrag_ops, ARRAY_SIZE(ipv4_defrag_ops)); | ||
} | ||
|
||
static void __exit nf_defrag_fini(void) | ||
{ | ||
nf_unregister_hooks(ipv4_defrag_ops, ARRAY_SIZE(ipv4_defrag_ops)); | ||
} | ||
|
||
void nf_defrag_ipv4_enable(void) | ||
{ | ||
} | ||
EXPORT_SYMBOL_GPL(nf_defrag_ipv4_enable); | ||
|
||
module_init(nf_defrag_init); | ||
module_exit(nf_defrag_fini); | ||
|
||
MODULE_LICENSE("GPL"); |