Pablo Neira Ayuso | 4b7fd5d | 2014-10-02 11:13:21 +0200 | [diff] [blame] | 1 | #ifndef _BR_NETFILTER_H_ |
| 2 | #define _BR_NETFILTER_H_ |
| 3 | |
Pablo Neira Ayuso | 230ac49 | 2015-06-16 14:07:03 +0200 | [diff] [blame] | 4 | #include "../../../net/bridge/br_private.h" |
| 5 | |
| 6 | static inline struct nf_bridge_info *nf_bridge_alloc(struct sk_buff *skb) |
| 7 | { |
| 8 | skb->nf_bridge = kzalloc(sizeof(struct nf_bridge_info), GFP_ATOMIC); |
| 9 | |
| 10 | if (likely(skb->nf_bridge)) |
| 11 | atomic_set(&(skb->nf_bridge->use), 1); |
| 12 | |
| 13 | return skb->nf_bridge; |
| 14 | } |
| 15 | |
| 16 | void nf_bridge_update_protocol(struct sk_buff *skb); |
| 17 | |
Florian Westphal | c5136b1 | 2016-09-21 11:35:01 -0400 | [diff] [blame] | 18 | int br_nf_hook_thresh(unsigned int hook, struct net *net, struct sock *sk, |
| 19 | struct sk_buff *skb, struct net_device *indev, |
| 20 | struct net_device *outdev, |
| 21 | int (*okfn)(struct net *, struct sock *, |
| 22 | struct sk_buff *)); |
| 23 | |
Pablo Neira Ayuso | 230ac49 | 2015-06-16 14:07:03 +0200 | [diff] [blame] | 24 | static inline struct nf_bridge_info * |
| 25 | nf_bridge_info_get(const struct sk_buff *skb) |
| 26 | { |
| 27 | return skb->nf_bridge; |
| 28 | } |
| 29 | |
| 30 | unsigned int nf_bridge_encap_header_len(const struct sk_buff *skb); |
| 31 | |
| 32 | static inline void nf_bridge_push_encap_header(struct sk_buff *skb) |
| 33 | { |
| 34 | unsigned int len = nf_bridge_encap_header_len(skb); |
| 35 | |
| 36 | skb_push(skb, len); |
| 37 | skb->network_header -= len; |
| 38 | } |
| 39 | |
Eric W. Biederman | 0c4b51f | 2015-09-15 20:04:18 -0500 | [diff] [blame] | 40 | int br_nf_pre_routing_finish_bridge(struct net *net, struct sock *sk, struct sk_buff *skb); |
Pablo Neira Ayuso | 230ac49 | 2015-06-16 14:07:03 +0200 | [diff] [blame] | 41 | |
| 42 | static inline struct rtable *bridge_parent_rtable(const struct net_device *dev) |
| 43 | { |
| 44 | struct net_bridge_port *port; |
| 45 | |
| 46 | port = br_port_get_rcu(dev); |
| 47 | return port ? &port->br->fake_rtable : NULL; |
| 48 | } |
| 49 | |
| 50 | struct net_device *setup_pre_routing(struct sk_buff *skb); |
Pablo Neira Ayuso | 4b7fd5d | 2014-10-02 11:13:21 +0200 | [diff] [blame] | 51 | void br_netfilter_enable(void); |
| 52 | |
Pablo Neira Ayuso | 230ac49 | 2015-06-16 14:07:03 +0200 | [diff] [blame] | 53 | #if IS_ENABLED(CONFIG_IPV6) |
Eric W. Biederman | c1444c6 | 2015-09-25 16:52:51 -0500 | [diff] [blame] | 54 | int br_validate_ipv6(struct net *net, struct sk_buff *skb); |
Eric W. Biederman | 06198b3 | 2015-09-18 14:33:06 -0500 | [diff] [blame] | 55 | unsigned int br_nf_pre_routing_ipv6(void *priv, |
Pablo Neira Ayuso | 230ac49 | 2015-06-16 14:07:03 +0200 | [diff] [blame] | 56 | struct sk_buff *skb, |
| 57 | const struct nf_hook_state *state); |
| 58 | #else |
Eric W. Biederman | c1444c6 | 2015-09-25 16:52:51 -0500 | [diff] [blame] | 59 | static inline int br_validate_ipv6(struct net *net, struct sk_buff *skb) |
Pablo Neira Ayuso | 230ac49 | 2015-06-16 14:07:03 +0200 | [diff] [blame] | 60 | { |
| 61 | return -1; |
| 62 | } |
| 63 | |
| 64 | static inline unsigned int |
| 65 | br_nf_pre_routing_ipv6(const struct nf_hook_ops *ops, struct sk_buff *skb, |
| 66 | const struct nf_hook_state *state) |
| 67 | { |
Bernhard Thaler | 18e1db6 | 2015-08-13 08:58:15 +0200 | [diff] [blame] | 68 | return NF_ACCEPT; |
Pablo Neira Ayuso | 230ac49 | 2015-06-16 14:07:03 +0200 | [diff] [blame] | 69 | } |
| 70 | #endif |
| 71 | |
Pablo Neira Ayuso | 4b7fd5d | 2014-10-02 11:13:21 +0200 | [diff] [blame] | 72 | #endif /* _BR_NETFILTER_H_ */ |