提交 a7c439d3 编写于 作者: G Gao feng 提交者: Pablo Neira Ayuso

netfilter: nf_ct_ipv6: add namespace support

This patch adds namespace support for IPv6 protocol tracker.
Acked-by: NEric W. Biederman <ebiederm@xmission.com>
Signed-off-by: NGao feng <gaofeng@cn.fujitsu.com>
Signed-off-by: NPablo Neira Ayuso <pablo@netfilter.org>
上级 3ea04dd3
...@@ -333,37 +333,75 @@ MODULE_ALIAS("nf_conntrack-" __stringify(AF_INET6)); ...@@ -333,37 +333,75 @@ MODULE_ALIAS("nf_conntrack-" __stringify(AF_INET6));
MODULE_LICENSE("GPL"); MODULE_LICENSE("GPL");
MODULE_AUTHOR("Yasuyuki KOZAKAI @USAGI <yasuyuki.kozakai@toshiba.co.jp>"); MODULE_AUTHOR("Yasuyuki KOZAKAI @USAGI <yasuyuki.kozakai@toshiba.co.jp>");
static int __init nf_conntrack_l3proto_ipv6_init(void) static int ipv6_net_init(struct net *net)
{ {
int ret = 0; int ret = 0;
need_conntrack(); ret = nf_conntrack_l4proto_register(net,
nf_defrag_ipv6_enable(); &nf_conntrack_l4proto_tcp6);
ret = nf_conntrack_l4proto_register(&init_net, &nf_conntrack_l4proto_tcp6);
if (ret < 0) { if (ret < 0) {
pr_err("nf_conntrack_ipv6: can't register tcp.\n"); printk(KERN_ERR "nf_conntrack_l4proto_tcp6: protocol register failed\n");
return ret; goto out;
} }
ret = nf_conntrack_l4proto_register(net,
ret = nf_conntrack_l4proto_register(&init_net, &nf_conntrack_l4proto_udp6); &nf_conntrack_l4proto_udp6);
if (ret < 0) { if (ret < 0) {
pr_err("nf_conntrack_ipv6: can't register udp.\n"); printk(KERN_ERR "nf_conntrack_l4proto_udp6: protocol register failed\n");
goto cleanup_tcp; goto cleanup_tcp6;
} }
ret = nf_conntrack_l4proto_register(net,
ret = nf_conntrack_l4proto_register(&init_net, &nf_conntrack_l4proto_icmpv6); &nf_conntrack_l4proto_icmpv6);
if (ret < 0) { if (ret < 0) {
pr_err("nf_conntrack_ipv6: can't register icmpv6.\n"); printk(KERN_ERR "nf_conntrack_l4proto_icmp6: protocol register failed\n");
goto cleanup_udp; goto cleanup_udp6;
} }
ret = nf_conntrack_l3proto_register(net,
ret = nf_conntrack_l3proto_register(&init_net, &nf_conntrack_l3proto_ipv6); &nf_conntrack_l3proto_ipv6);
if (ret < 0) { if (ret < 0) {
pr_err("nf_conntrack_ipv6: can't register ipv6\n"); printk(KERN_ERR "nf_conntrack_l3proto_ipv6: protocol register failed\n");
goto cleanup_icmpv6; goto cleanup_icmpv6;
} }
return 0;
cleanup_icmpv6:
nf_conntrack_l4proto_unregister(net,
&nf_conntrack_l4proto_icmpv6);
cleanup_udp6:
nf_conntrack_l4proto_unregister(net,
&nf_conntrack_l4proto_udp6);
cleanup_tcp6:
nf_conntrack_l4proto_unregister(net,
&nf_conntrack_l4proto_tcp6);
out:
return ret;
}
static void ipv6_net_exit(struct net *net)
{
nf_conntrack_l3proto_unregister(net,
&nf_conntrack_l3proto_ipv6);
nf_conntrack_l4proto_unregister(net,
&nf_conntrack_l4proto_icmpv6);
nf_conntrack_l4proto_unregister(net,
&nf_conntrack_l4proto_udp6);
nf_conntrack_l4proto_unregister(net,
&nf_conntrack_l4proto_tcp6);
}
static struct pernet_operations ipv6_net_ops = {
.init = ipv6_net_init,
.exit = ipv6_net_exit,
};
static int __init nf_conntrack_l3proto_ipv6_init(void)
{
int ret = 0;
need_conntrack();
nf_defrag_ipv6_enable();
ret = register_pernet_subsys(&ipv6_net_ops);
if (ret < 0)
goto cleanup_pernet;
ret = nf_register_hooks(ipv6_conntrack_ops, ret = nf_register_hooks(ipv6_conntrack_ops,
ARRAY_SIZE(ipv6_conntrack_ops)); ARRAY_SIZE(ipv6_conntrack_ops));
if (ret < 0) { if (ret < 0) {
...@@ -374,13 +412,8 @@ static int __init nf_conntrack_l3proto_ipv6_init(void) ...@@ -374,13 +412,8 @@ static int __init nf_conntrack_l3proto_ipv6_init(void)
return ret; return ret;
cleanup_ipv6: cleanup_ipv6:
nf_conntrack_l3proto_unregister(&init_net, &nf_conntrack_l3proto_ipv6); unregister_pernet_subsys(&ipv6_net_ops);
cleanup_icmpv6: cleanup_pernet:
nf_conntrack_l4proto_unregister(&init_net, &nf_conntrack_l4proto_icmpv6);
cleanup_udp:
nf_conntrack_l4proto_unregister(&init_net, &nf_conntrack_l4proto_udp6);
cleanup_tcp:
nf_conntrack_l4proto_unregister(&init_net, &nf_conntrack_l4proto_tcp6);
return ret; return ret;
} }
...@@ -388,10 +421,7 @@ static void __exit nf_conntrack_l3proto_ipv6_fini(void) ...@@ -388,10 +421,7 @@ static void __exit nf_conntrack_l3proto_ipv6_fini(void)
{ {
synchronize_net(); synchronize_net();
nf_unregister_hooks(ipv6_conntrack_ops, ARRAY_SIZE(ipv6_conntrack_ops)); nf_unregister_hooks(ipv6_conntrack_ops, ARRAY_SIZE(ipv6_conntrack_ops));
nf_conntrack_l3proto_unregister(&init_net, &nf_conntrack_l3proto_ipv6); unregister_pernet_subsys(&ipv6_net_ops);
nf_conntrack_l4proto_unregister(&init_net, &nf_conntrack_l4proto_icmpv6);
nf_conntrack_l4proto_unregister(&init_net, &nf_conntrack_l4proto_udp6);
nf_conntrack_l4proto_unregister(&init_net, &nf_conntrack_l4proto_tcp6);
} }
module_init(nf_conntrack_l3proto_ipv6_init); module_init(nf_conntrack_l3proto_ipv6_init);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册