提交 3b760dcb 编写于 作者: L Liping Zhang 提交者: Pablo Neira Ayuso

netfilter: rpfilter: bypass ipv4 lbcast packets with zeronet source

Otherwise, DHCP Discover packets(0.0.0.0->255.255.255.255) may be
dropped incorrectly.
Signed-off-by: NLiping Zhang <zlpnobody@gmail.com>
Acked-by: NFlorian Westphal <fw@strlen.de>
Signed-off-by: NPablo Neira Ayuso <pablo@netfilter.org>
上级 a9fea2a3
...@@ -83,10 +83,12 @@ static bool rpfilter_mt(const struct sk_buff *skb, struct xt_action_param *par) ...@@ -83,10 +83,12 @@ static bool rpfilter_mt(const struct sk_buff *skb, struct xt_action_param *par)
return true ^ invert; return true ^ invert;
iph = ip_hdr(skb); iph = ip_hdr(skb);
if (ipv4_is_multicast(iph->daddr)) { if (ipv4_is_zeronet(iph->saddr)) {
if (ipv4_is_zeronet(iph->saddr)) if (ipv4_is_lbcast(iph->daddr) ||
return ipv4_is_local_multicast(iph->daddr) ^ invert; ipv4_is_local_multicast(iph->daddr))
return true ^ invert;
} }
flow.flowi4_iif = LOOPBACK_IFINDEX; flow.flowi4_iif = LOOPBACK_IFINDEX;
flow.daddr = iph->saddr; flow.daddr = iph->saddr;
flow.saddr = rpfilter_get_saddr(iph->daddr); flow.saddr = rpfilter_get_saddr(iph->daddr);
......
...@@ -101,13 +101,14 @@ void nft_fib4_eval(const struct nft_expr *expr, struct nft_regs *regs, ...@@ -101,13 +101,14 @@ void nft_fib4_eval(const struct nft_expr *expr, struct nft_regs *regs,
} }
iph = ip_hdr(pkt->skb); iph = ip_hdr(pkt->skb);
if (ipv4_is_multicast(iph->daddr) && if (ipv4_is_zeronet(iph->saddr)) {
ipv4_is_zeronet(iph->saddr) && if (ipv4_is_lbcast(iph->daddr) ||
ipv4_is_local_multicast(iph->daddr)) { ipv4_is_local_multicast(iph->daddr)) {
nft_fib_store_result(dest, priv->result, pkt, nft_fib_store_result(dest, priv->result, pkt,
get_ifindex(pkt->skb->dev)); get_ifindex(pkt->skb->dev));
return; return;
} }
}
if (priv->flags & NFTA_FIB_F_MARK) if (priv->flags & NFTA_FIB_F_MARK)
fl4.flowi4_mark = pkt->skb->mark; fl4.flowi4_mark = pkt->skb->mark;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册