Pablo Neira Ayuso | 0ca743a | 2013-10-14 00:06:06 +0200 | [diff] [blame] | 1 | #ifndef _NF_TABLES_IPV4_H_ |
| 2 | #define _NF_TABLES_IPV4_H_ |
| 3 | |
| 4 | #include <net/netfilter/nf_tables.h> |
| 5 | #include <net/ip.h> |
| 6 | |
| 7 | static inline void |
| 8 | nft_set_pktinfo_ipv4(struct nft_pktinfo *pkt, |
Pablo Neira Ayuso | 0ca743a | 2013-10-14 00:06:06 +0200 | [diff] [blame] | 9 | struct sk_buff *skb, |
David S. Miller | 073bfd5 | 2015-04-03 21:16:25 -0400 | [diff] [blame] | 10 | const struct nf_hook_state *state) |
Pablo Neira Ayuso | 0ca743a | 2013-10-14 00:06:06 +0200 | [diff] [blame] | 11 | { |
| 12 | struct iphdr *ip; |
| 13 | |
Eric W. Biederman | 6aa187f | 2015-09-18 14:32:57 -0500 | [diff] [blame] | 14 | nft_set_pktinfo(pkt, skb, state); |
Pablo Neira Ayuso | 0ca743a | 2013-10-14 00:06:06 +0200 | [diff] [blame] | 15 | |
Pablo Neira Ayuso | 0ca743a | 2013-10-14 00:06:06 +0200 | [diff] [blame] | 16 | ip = ip_hdr(pkt->skb); |
Pablo Neira Ayuso | beac5af | 2016-09-09 12:42:49 +0200 | [diff] [blame] | 17 | pkt->tprot_set = true; |
Patrick McHardy | 4566bf2 | 2014-01-03 12:16:18 +0000 | [diff] [blame] | 18 | pkt->tprot = ip->protocol; |
| 19 | pkt->xt.thoff = ip_hdrlen(pkt->skb); |
Pablo Neira Ayuso | 0ca743a | 2013-10-14 00:06:06 +0200 | [diff] [blame] | 20 | pkt->xt.fragoff = ntohs(ip->frag_off) & IP_OFFSET; |
| 21 | } |
| 22 | |
Pablo Neira Ayuso | ddc8b60 | 2016-09-09 12:42:51 +0200 | [diff] [blame] | 23 | static inline int |
| 24 | __nft_set_pktinfo_ipv4_validate(struct nft_pktinfo *pkt, |
| 25 | struct sk_buff *skb, |
| 26 | const struct nf_hook_state *state) |
| 27 | { |
| 28 | struct iphdr *iph, _iph; |
| 29 | u32 len, thoff; |
| 30 | |
| 31 | iph = skb_header_pointer(skb, skb_network_offset(skb), sizeof(*iph), |
| 32 | &_iph); |
| 33 | if (!iph) |
| 34 | return -1; |
| 35 | |
| 36 | iph = ip_hdr(skb); |
| 37 | if (iph->ihl < 5 || iph->version != 4) |
| 38 | return -1; |
| 39 | |
| 40 | len = ntohs(iph->tot_len); |
| 41 | thoff = iph->ihl * 4; |
| 42 | if (skb->len < len) |
| 43 | return -1; |
| 44 | else if (len < thoff) |
| 45 | return -1; |
| 46 | |
| 47 | pkt->tprot_set = true; |
| 48 | pkt->tprot = iph->protocol; |
| 49 | pkt->xt.thoff = thoff; |
| 50 | pkt->xt.fragoff = ntohs(iph->frag_off) & IP_OFFSET; |
| 51 | |
| 52 | return 0; |
| 53 | } |
| 54 | |
| 55 | static inline void |
| 56 | nft_set_pktinfo_ipv4_validate(struct nft_pktinfo *pkt, |
| 57 | struct sk_buff *skb, |
| 58 | const struct nf_hook_state *state) |
| 59 | { |
| 60 | nft_set_pktinfo(pkt, skb, state); |
| 61 | if (__nft_set_pktinfo_ipv4_validate(pkt, skb, state) < 0) |
| 62 | nft_set_pktinfo_proto_unspec(pkt, skb); |
| 63 | } |
| 64 | |
Patrick McHardy | 1d49144 | 2014-01-03 12:16:16 +0000 | [diff] [blame] | 65 | extern struct nft_af_info nft_af_ipv4; |
| 66 | |
Pablo Neira Ayuso | 0ca743a | 2013-10-14 00:06:06 +0200 | [diff] [blame] | 67 | #endif |