Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 1 | /* |
| 2 | * ebtable_broute |
| 3 | * |
| 4 | * Authors: |
| 5 | * Bart De Schuymer <bdschuym@pandora.be> |
| 6 | * |
| 7 | * April, 2002 |
| 8 | * |
| 9 | * This table lets you choose between routing and bridging for frames |
| 10 | * entering on a bridge enslaved nic. This table is traversed before any |
| 11 | * other ebtables table. See net/bridge/br_input.c. |
| 12 | */ |
| 13 | |
| 14 | #include <linux/netfilter_bridge/ebtables.h> |
| 15 | #include <linux/module.h> |
| 16 | #include <linux/if_bridge.h> |
| 17 | |
| 18 | /* EBT_ACCEPT means the frame will be bridged |
| 19 | * EBT_DROP means the frame will be routed |
| 20 | */ |
| 21 | static struct ebt_entries initial_chain = { |
| 22 | .name = "BROUTING", |
| 23 | .policy = EBT_ACCEPT, |
| 24 | }; |
| 25 | |
Al Viro | 1e419cd | 2006-11-30 19:28:48 -0800 | [diff] [blame] | 26 | static struct ebt_replace_kernel initial_table = |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 27 | { |
| 28 | .name = "broute", |
| 29 | .valid_hooks = 1 << NF_BR_BROUTING, |
| 30 | .entries_size = sizeof(struct ebt_entries), |
| 31 | .hook_entry = { |
| 32 | [NF_BR_BROUTING] = &initial_chain, |
| 33 | }, |
| 34 | .entries = (char *)&initial_chain, |
| 35 | }; |
| 36 | |
| 37 | static int check(const struct ebt_table_info *info, unsigned int valid_hooks) |
| 38 | { |
| 39 | if (valid_hooks & ~(1 << NF_BR_BROUTING)) |
| 40 | return -EINVAL; |
| 41 | return 0; |
| 42 | } |
| 43 | |
Alexey Dobriyan | 8157e6d | 2008-11-04 14:29:03 +0100 | [diff] [blame] | 44 | static struct ebt_table broute_table = |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 45 | { |
| 46 | .name = "broute", |
| 47 | .table = &initial_table, |
| 48 | .valid_hooks = 1 << NF_BR_BROUTING, |
Alexey Dobriyan | 8157e6d | 2008-11-04 14:29:03 +0100 | [diff] [blame] | 49 | .lock = __RW_LOCK_UNLOCKED(broute_table.lock), |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 50 | .check = check, |
| 51 | .me = THIS_MODULE, |
| 52 | }; |
| 53 | |
Herbert Xu | 3db05fe | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 54 | static int ebt_broute(struct sk_buff *skb) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 55 | { |
| 56 | int ret; |
| 57 | |
Herbert Xu | 3db05fe | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 58 | ret = ebt_do_table(NF_BR_BROUTING, skb, skb->dev, NULL, |
Alexey Dobriyan | 8157e6d | 2008-11-04 14:29:03 +0100 | [diff] [blame] | 59 | dev_net(skb->dev)->xt.broute_table); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 60 | if (ret == NF_DROP) |
| 61 | return 1; /* route it */ |
| 62 | return 0; /* bridge it */ |
| 63 | } |
| 64 | |
Alexey Dobriyan | 8157e6d | 2008-11-04 14:29:03 +0100 | [diff] [blame] | 65 | static int __net_init broute_net_init(struct net *net) |
| 66 | { |
| 67 | net->xt.broute_table = ebt_register_table(net, &broute_table); |
| 68 | if (IS_ERR(net->xt.broute_table)) |
| 69 | return PTR_ERR(net->xt.broute_table); |
| 70 | return 0; |
| 71 | } |
| 72 | |
| 73 | static void __net_exit broute_net_exit(struct net *net) |
| 74 | { |
| 75 | ebt_unregister_table(net->xt.broute_table); |
| 76 | } |
| 77 | |
| 78 | static struct pernet_operations broute_net_ops = { |
| 79 | .init = broute_net_init, |
| 80 | .exit = broute_net_exit, |
| 81 | }; |
| 82 | |
Andrew Morton | 65b4b4e | 2006-03-28 16:37:06 -0800 | [diff] [blame] | 83 | static int __init ebtable_broute_init(void) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 84 | { |
Alexey Dobriyan | 8157e6d | 2008-11-04 14:29:03 +0100 | [diff] [blame] | 85 | int ret; |
| 86 | |
| 87 | ret = register_pernet_subsys(&broute_net_ops); |
| 88 | if (ret < 0) |
| 89 | return ret; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 90 | /* see br_input.c */ |
Pavel Emelyanov | 82de382 | 2007-11-29 23:58:58 +1100 | [diff] [blame] | 91 | rcu_assign_pointer(br_should_route_hook, ebt_broute); |
Alexey Dobriyan | 6beceee | 2008-11-04 14:27:15 +0100 | [diff] [blame] | 92 | return 0; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 93 | } |
| 94 | |
Andrew Morton | 65b4b4e | 2006-03-28 16:37:06 -0800 | [diff] [blame] | 95 | static void __exit ebtable_broute_fini(void) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 96 | { |
Pavel Emelyanov | 82de382 | 2007-11-29 23:58:58 +1100 | [diff] [blame] | 97 | rcu_assign_pointer(br_should_route_hook, NULL); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 98 | synchronize_net(); |
Alexey Dobriyan | 8157e6d | 2008-11-04 14:29:03 +0100 | [diff] [blame] | 99 | unregister_pernet_subsys(&broute_net_ops); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 100 | } |
| 101 | |
Andrew Morton | 65b4b4e | 2006-03-28 16:37:06 -0800 | [diff] [blame] | 102 | module_init(ebtable_broute_init); |
| 103 | module_exit(ebtable_broute_fini); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 104 | MODULE_LICENSE("GPL"); |