提交 44d34e72 编写于 作者: A Alexey Dobriyan 提交者: David S. Miller

[NETFILTER]: x_tables: return new table from {arp,ip,ip6}t_register_table()

Typical table module registers xt_table structure (i.e. packet_filter)
and link it to list during it. We can't use one template for it because
corresponding list_head will become corrupted. We also can't unregister
with template because it wasn't changed at all and thus doesn't know in
which list it is.

So, we duplicate template at the very first step of table registration.
Table modules will save it for use during unregistration time and actual
filtering.

Do it at once to not screw bisection.

P.S.: renaming i.e. packet_filter => __packet_filter is temporary until
      full netnsization of table modules is done.
Signed-off-by: NAlexey Dobriyan <adobriyan@sw.ru>
Signed-off-by: NPatrick McHardy <kaber@trash.net>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 8d870052
...@@ -271,7 +271,7 @@ struct arpt_error ...@@ -271,7 +271,7 @@ struct arpt_error
xt_register_target(tgt); }) xt_register_target(tgt); })
#define arpt_unregister_target(tgt) xt_unregister_target(tgt) #define arpt_unregister_target(tgt) xt_unregister_target(tgt)
extern int arpt_register_table(struct arpt_table *table, extern struct arpt_table *arpt_register_table(struct arpt_table *table,
const struct arpt_replace *repl); const struct arpt_replace *repl);
extern void arpt_unregister_table(struct arpt_table *table); extern void arpt_unregister_table(struct arpt_table *table);
extern unsigned int arpt_do_table(struct sk_buff *skb, extern unsigned int arpt_do_table(struct sk_buff *skb,
......
...@@ -244,7 +244,8 @@ ipt_get_target(struct ipt_entry *e) ...@@ -244,7 +244,8 @@ ipt_get_target(struct ipt_entry *e)
#include <linux/init.h> #include <linux/init.h>
extern void ipt_init(void) __init; extern void ipt_init(void) __init;
extern int ipt_register_table(struct xt_table *table, extern struct xt_table *ipt_register_table(struct net *net,
struct xt_table *table,
const struct ipt_replace *repl); const struct ipt_replace *repl);
extern void ipt_unregister_table(struct xt_table *table); extern void ipt_unregister_table(struct xt_table *table);
......
...@@ -305,7 +305,7 @@ ip6t_get_target(struct ip6t_entry *e) ...@@ -305,7 +305,7 @@ ip6t_get_target(struct ip6t_entry *e)
#include <linux/init.h> #include <linux/init.h>
extern void ip6t_init(void) __init; extern void ip6t_init(void) __init;
extern int ip6t_register_table(struct xt_table *table, extern struct xt_table *ip6t_register_table(struct xt_table *table,
const struct ip6t_replace *repl); const struct ip6t_replace *repl);
extern void ip6t_unregister_table(struct xt_table *table); extern void ip6t_unregister_table(struct xt_table *table);
extern unsigned int ip6t_do_table(struct sk_buff *skb, extern unsigned int ip6t_do_table(struct sk_buff *skb,
......
...@@ -1719,7 +1719,7 @@ static int do_arpt_get_ctl(struct sock *sk, int cmd, void __user *user, int *len ...@@ -1719,7 +1719,7 @@ static int do_arpt_get_ctl(struct sock *sk, int cmd, void __user *user, int *len
return ret; return ret;
} }
int arpt_register_table(struct arpt_table *table, struct arpt_table *arpt_register_table(struct arpt_table *table,
const struct arpt_replace *repl) const struct arpt_replace *repl)
{ {
int ret; int ret;
...@@ -1732,7 +1732,7 @@ int arpt_register_table(struct arpt_table *table, ...@@ -1732,7 +1732,7 @@ int arpt_register_table(struct arpt_table *table,
newinfo = xt_alloc_table_info(repl->size); newinfo = xt_alloc_table_info(repl->size);
if (!newinfo) { if (!newinfo) {
ret = -ENOMEM; ret = -ENOMEM;
return ret; goto out;
} }
/* choose the copy on our node/cpu */ /* choose the copy on our node/cpu */
...@@ -1746,18 +1746,20 @@ int arpt_register_table(struct arpt_table *table, ...@@ -1746,18 +1746,20 @@ int arpt_register_table(struct arpt_table *table,
repl->underflow); repl->underflow);
duprintf("arpt_register_table: translate table gives %d\n", ret); duprintf("arpt_register_table: translate table gives %d\n", ret);
if (ret != 0) { if (ret != 0)
xt_free_table_info(newinfo); goto out_free;
return ret;
}
new_table = xt_register_table(&init_net, table, &bootstrap, newinfo); new_table = xt_register_table(&init_net, table, &bootstrap, newinfo);
if (IS_ERR(new_table)) { if (IS_ERR(new_table)) {
xt_free_table_info(newinfo); ret = PTR_ERR(new_table);
return PTR_ERR(new_table); goto out_free;
} }
return new_table;
return 0; out_free:
xt_free_table_info(newinfo);
out:
return ERR_PTR(ret);
} }
void arpt_unregister_table(struct arpt_table *table) void arpt_unregister_table(struct arpt_table *table)
......
...@@ -45,7 +45,7 @@ static struct ...@@ -45,7 +45,7 @@ static struct
.term = ARPT_ERROR_INIT, .term = ARPT_ERROR_INIT,
}; };
static struct arpt_table packet_filter = { static struct arpt_table __packet_filter = {
.name = "filter", .name = "filter",
.valid_hooks = FILTER_VALID_HOOKS, .valid_hooks = FILTER_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
...@@ -53,6 +53,7 @@ static struct arpt_table packet_filter = { ...@@ -53,6 +53,7 @@ static struct arpt_table packet_filter = {
.me = THIS_MODULE, .me = THIS_MODULE,
.af = NF_ARP, .af = NF_ARP,
}; };
static struct arpt_table *packet_filter;
/* The work comes in here from netfilter.c */ /* The work comes in here from netfilter.c */
static unsigned int arpt_hook(unsigned int hook, static unsigned int arpt_hook(unsigned int hook,
...@@ -61,7 +62,7 @@ static unsigned int arpt_hook(unsigned int hook, ...@@ -61,7 +62,7 @@ static unsigned int arpt_hook(unsigned int hook,
const struct net_device *out, const struct net_device *out,
int (*okfn)(struct sk_buff *)) int (*okfn)(struct sk_buff *))
{ {
return arpt_do_table(skb, hook, in, out, &packet_filter); return arpt_do_table(skb, hook, in, out, packet_filter);
} }
static struct nf_hook_ops arpt_ops[] __read_mostly = { static struct nf_hook_ops arpt_ops[] __read_mostly = {
...@@ -90,9 +91,9 @@ static int __init arptable_filter_init(void) ...@@ -90,9 +91,9 @@ static int __init arptable_filter_init(void)
int ret; int ret;
/* Register table */ /* Register table */
ret = arpt_register_table(&packet_filter, &initial_table.repl); packet_filter = arpt_register_table(&__packet_filter, &initial_table.repl);
if (ret < 0) if (IS_ERR(packet_filter))
return ret; return PTR_ERR(packet_filter);
ret = nf_register_hooks(arpt_ops, ARRAY_SIZE(arpt_ops)); ret = nf_register_hooks(arpt_ops, ARRAY_SIZE(arpt_ops));
if (ret < 0) if (ret < 0)
...@@ -100,14 +101,14 @@ static int __init arptable_filter_init(void) ...@@ -100,14 +101,14 @@ static int __init arptable_filter_init(void)
return ret; return ret;
cleanup_table: cleanup_table:
arpt_unregister_table(&packet_filter); arpt_unregister_table(packet_filter);
return ret; return ret;
} }
static void __exit arptable_filter_fini(void) static void __exit arptable_filter_fini(void)
{ {
nf_unregister_hooks(arpt_ops, ARRAY_SIZE(arpt_ops)); nf_unregister_hooks(arpt_ops, ARRAY_SIZE(arpt_ops));
arpt_unregister_table(&packet_filter); arpt_unregister_table(packet_filter);
} }
module_init(arptable_filter_init); module_init(arptable_filter_init);
......
...@@ -2048,7 +2048,8 @@ do_ipt_get_ctl(struct sock *sk, int cmd, void __user *user, int *len) ...@@ -2048,7 +2048,8 @@ do_ipt_get_ctl(struct sock *sk, int cmd, void __user *user, int *len)
return ret; return ret;
} }
int ipt_register_table(struct xt_table *table, const struct ipt_replace *repl) struct xt_table *ipt_register_table(struct net *net, struct xt_table *table,
const struct ipt_replace *repl)
{ {
int ret; int ret;
struct xt_table_info *newinfo; struct xt_table_info *newinfo;
...@@ -2058,8 +2059,10 @@ int ipt_register_table(struct xt_table *table, const struct ipt_replace *repl) ...@@ -2058,8 +2059,10 @@ int ipt_register_table(struct xt_table *table, const struct ipt_replace *repl)
struct xt_table *new_table; struct xt_table *new_table;
newinfo = xt_alloc_table_info(repl->size); newinfo = xt_alloc_table_info(repl->size);
if (!newinfo) if (!newinfo) {
return -ENOMEM; ret = -ENOMEM;
goto out;
}
/* choose the copy on our node/cpu, but dont care about preemption */ /* choose the copy on our node/cpu, but dont care about preemption */
loc_cpu_entry = newinfo->entries[raw_smp_processor_id()]; loc_cpu_entry = newinfo->entries[raw_smp_processor_id()];
...@@ -2070,18 +2073,21 @@ int ipt_register_table(struct xt_table *table, const struct ipt_replace *repl) ...@@ -2070,18 +2073,21 @@ int ipt_register_table(struct xt_table *table, const struct ipt_replace *repl)
repl->num_entries, repl->num_entries,
repl->hook_entry, repl->hook_entry,
repl->underflow); repl->underflow);
if (ret != 0) { if (ret != 0)
xt_free_table_info(newinfo); goto out_free;
return ret;
}
new_table = xt_register_table(&init_net, table, &bootstrap, newinfo); new_table = xt_register_table(net, table, &bootstrap, newinfo);
if (IS_ERR(new_table)) { if (IS_ERR(new_table)) {
xt_free_table_info(newinfo); ret = PTR_ERR(new_table);
return PTR_ERR(new_table); goto out_free;
} }
return 0; return new_table;
out_free:
xt_free_table_info(newinfo);
out:
return ERR_PTR(ret);
} }
void ipt_unregister_table(struct xt_table *table) void ipt_unregister_table(struct xt_table *table)
......
...@@ -53,13 +53,14 @@ static struct ...@@ -53,13 +53,14 @@ static struct
.term = IPT_ERROR_INIT, /* ERROR */ .term = IPT_ERROR_INIT, /* ERROR */
}; };
static struct xt_table packet_filter = { static struct xt_table __packet_filter = {
.name = "filter", .name = "filter",
.valid_hooks = FILTER_VALID_HOOKS, .valid_hooks = FILTER_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
.me = THIS_MODULE, .me = THIS_MODULE,
.af = AF_INET, .af = AF_INET,
}; };
static struct xt_table *packet_filter;
/* The work comes in here from netfilter.c. */ /* The work comes in here from netfilter.c. */
static unsigned int static unsigned int
...@@ -69,7 +70,7 @@ ipt_hook(unsigned int hook, ...@@ -69,7 +70,7 @@ ipt_hook(unsigned int hook,
const struct net_device *out, const struct net_device *out,
int (*okfn)(struct sk_buff *)) int (*okfn)(struct sk_buff *))
{ {
return ipt_do_table(skb, hook, in, out, &packet_filter); return ipt_do_table(skb, hook, in, out, packet_filter);
} }
static unsigned int static unsigned int
...@@ -88,7 +89,7 @@ ipt_local_out_hook(unsigned int hook, ...@@ -88,7 +89,7 @@ ipt_local_out_hook(unsigned int hook,
return NF_ACCEPT; return NF_ACCEPT;
} }
return ipt_do_table(skb, hook, in, out, &packet_filter); return ipt_do_table(skb, hook, in, out, packet_filter);
} }
static struct nf_hook_ops ipt_ops[] __read_mostly = { static struct nf_hook_ops ipt_ops[] __read_mostly = {
...@@ -132,9 +133,10 @@ static int __init iptable_filter_init(void) ...@@ -132,9 +133,10 @@ static int __init iptable_filter_init(void)
initial_table.entries[1].target.verdict = -forward - 1; initial_table.entries[1].target.verdict = -forward - 1;
/* Register table */ /* Register table */
ret = ipt_register_table(&packet_filter, &initial_table.repl); packet_filter = ipt_register_table(&init_net, &__packet_filter,
if (ret < 0) &initial_table.repl);
return ret; if (IS_ERR(packet_filter))
return PTR_ERR(packet_filter);
/* Register hooks */ /* Register hooks */
ret = nf_register_hooks(ipt_ops, ARRAY_SIZE(ipt_ops)); ret = nf_register_hooks(ipt_ops, ARRAY_SIZE(ipt_ops));
...@@ -144,14 +146,14 @@ static int __init iptable_filter_init(void) ...@@ -144,14 +146,14 @@ static int __init iptable_filter_init(void)
return ret; return ret;
cleanup_table: cleanup_table:
ipt_unregister_table(&packet_filter); ipt_unregister_table(packet_filter);
return ret; return ret;
} }
static void __exit iptable_filter_fini(void) static void __exit iptable_filter_fini(void)
{ {
nf_unregister_hooks(ipt_ops, ARRAY_SIZE(ipt_ops)); nf_unregister_hooks(ipt_ops, ARRAY_SIZE(ipt_ops));
ipt_unregister_table(&packet_filter); ipt_unregister_table(packet_filter);
} }
module_init(iptable_filter_init); module_init(iptable_filter_init);
......
...@@ -64,13 +64,14 @@ static struct ...@@ -64,13 +64,14 @@ static struct
.term = IPT_ERROR_INIT, /* ERROR */ .term = IPT_ERROR_INIT, /* ERROR */
}; };
static struct xt_table packet_mangler = { static struct xt_table __packet_mangler = {
.name = "mangle", .name = "mangle",
.valid_hooks = MANGLE_VALID_HOOKS, .valid_hooks = MANGLE_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
.me = THIS_MODULE, .me = THIS_MODULE,
.af = AF_INET, .af = AF_INET,
}; };
static struct xt_table *packet_mangler;
/* The work comes in here from netfilter.c. */ /* The work comes in here from netfilter.c. */
static unsigned int static unsigned int
...@@ -80,7 +81,7 @@ ipt_route_hook(unsigned int hook, ...@@ -80,7 +81,7 @@ ipt_route_hook(unsigned int hook,
const struct net_device *out, const struct net_device *out,
int (*okfn)(struct sk_buff *)) int (*okfn)(struct sk_buff *))
{ {
return ipt_do_table(skb, hook, in, out, &packet_mangler); return ipt_do_table(skb, hook, in, out, packet_mangler);
} }
static unsigned int static unsigned int
...@@ -112,7 +113,7 @@ ipt_local_hook(unsigned int hook, ...@@ -112,7 +113,7 @@ ipt_local_hook(unsigned int hook,
daddr = iph->daddr; daddr = iph->daddr;
tos = iph->tos; tos = iph->tos;
ret = ipt_do_table(skb, hook, in, out, &packet_mangler); ret = ipt_do_table(skb, hook, in, out, packet_mangler);
/* Reroute for ANY change. */ /* Reroute for ANY change. */
if (ret != NF_DROP && ret != NF_STOLEN && ret != NF_QUEUE) { if (ret != NF_DROP && ret != NF_STOLEN && ret != NF_QUEUE) {
iph = ip_hdr(skb); iph = ip_hdr(skb);
...@@ -171,9 +172,10 @@ static int __init iptable_mangle_init(void) ...@@ -171,9 +172,10 @@ static int __init iptable_mangle_init(void)
int ret; int ret;
/* Register table */ /* Register table */
ret = ipt_register_table(&packet_mangler, &initial_table.repl); packet_mangler = ipt_register_table(&init_net, &__packet_mangler,
if (ret < 0) &initial_table.repl);
return ret; if (IS_ERR(packet_mangler))
return PTR_ERR(packet_mangler);
/* Register hooks */ /* Register hooks */
ret = nf_register_hooks(ipt_ops, ARRAY_SIZE(ipt_ops)); ret = nf_register_hooks(ipt_ops, ARRAY_SIZE(ipt_ops));
...@@ -183,14 +185,14 @@ static int __init iptable_mangle_init(void) ...@@ -183,14 +185,14 @@ static int __init iptable_mangle_init(void)
return ret; return ret;
cleanup_table: cleanup_table:
ipt_unregister_table(&packet_mangler); ipt_unregister_table(packet_mangler);
return ret; return ret;
} }
static void __exit iptable_mangle_fini(void) static void __exit iptable_mangle_fini(void)
{ {
nf_unregister_hooks(ipt_ops, ARRAY_SIZE(ipt_ops)); nf_unregister_hooks(ipt_ops, ARRAY_SIZE(ipt_ops));
ipt_unregister_table(&packet_mangler); ipt_unregister_table(packet_mangler);
} }
module_init(iptable_mangle_init); module_init(iptable_mangle_init);
......
...@@ -36,13 +36,14 @@ static struct ...@@ -36,13 +36,14 @@ static struct
.term = IPT_ERROR_INIT, /* ERROR */ .term = IPT_ERROR_INIT, /* ERROR */
}; };
static struct xt_table packet_raw = { static struct xt_table __packet_raw = {
.name = "raw", .name = "raw",
.valid_hooks = RAW_VALID_HOOKS, .valid_hooks = RAW_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
.me = THIS_MODULE, .me = THIS_MODULE,
.af = AF_INET, .af = AF_INET,
}; };
static struct xt_table *packet_raw;
/* The work comes in here from netfilter.c. */ /* The work comes in here from netfilter.c. */
static unsigned int static unsigned int
...@@ -52,7 +53,7 @@ ipt_hook(unsigned int hook, ...@@ -52,7 +53,7 @@ ipt_hook(unsigned int hook,
const struct net_device *out, const struct net_device *out,
int (*okfn)(struct sk_buff *)) int (*okfn)(struct sk_buff *))
{ {
return ipt_do_table(skb, hook, in, out, &packet_raw); return ipt_do_table(skb, hook, in, out, packet_raw);
} }
static unsigned int static unsigned int
...@@ -70,7 +71,7 @@ ipt_local_hook(unsigned int hook, ...@@ -70,7 +71,7 @@ ipt_local_hook(unsigned int hook,
"packet.\n"); "packet.\n");
return NF_ACCEPT; return NF_ACCEPT;
} }
return ipt_do_table(skb, hook, in, out, &packet_raw); return ipt_do_table(skb, hook, in, out, packet_raw);
} }
/* 'raw' is the very first table. */ /* 'raw' is the very first table. */
...@@ -96,9 +97,10 @@ static int __init iptable_raw_init(void) ...@@ -96,9 +97,10 @@ static int __init iptable_raw_init(void)
int ret; int ret;
/* Register table */ /* Register table */
ret = ipt_register_table(&packet_raw, &initial_table.repl); packet_raw = ipt_register_table(&init_net, &__packet_raw,
if (ret < 0) &initial_table.repl);
return ret; if (IS_ERR(packet_raw))
return PTR_ERR(packet_raw);
/* Register hooks */ /* Register hooks */
ret = nf_register_hooks(ipt_ops, ARRAY_SIZE(ipt_ops)); ret = nf_register_hooks(ipt_ops, ARRAY_SIZE(ipt_ops));
...@@ -108,14 +110,14 @@ static int __init iptable_raw_init(void) ...@@ -108,14 +110,14 @@ static int __init iptable_raw_init(void)
return ret; return ret;
cleanup_table: cleanup_table:
ipt_unregister_table(&packet_raw); ipt_unregister_table(packet_raw);
return ret; return ret;
} }
static void __exit iptable_raw_fini(void) static void __exit iptable_raw_fini(void)
{ {
nf_unregister_hooks(ipt_ops, ARRAY_SIZE(ipt_ops)); nf_unregister_hooks(ipt_ops, ARRAY_SIZE(ipt_ops));
ipt_unregister_table(&packet_raw); ipt_unregister_table(packet_raw);
} }
module_init(iptable_raw_init); module_init(iptable_raw_init);
......
...@@ -58,13 +58,14 @@ static struct ...@@ -58,13 +58,14 @@ static struct
.term = IPT_ERROR_INIT, /* ERROR */ .term = IPT_ERROR_INIT, /* ERROR */
}; };
static struct xt_table nat_table = { static struct xt_table __nat_table = {
.name = "nat", .name = "nat",
.valid_hooks = NAT_VALID_HOOKS, .valid_hooks = NAT_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
.me = THIS_MODULE, .me = THIS_MODULE,
.af = AF_INET, .af = AF_INET,
}; };
static struct xt_table *nat_table;
/* Source NAT */ /* Source NAT */
static unsigned int ipt_snat_target(struct sk_buff *skb, static unsigned int ipt_snat_target(struct sk_buff *skb,
...@@ -214,7 +215,7 @@ int nf_nat_rule_find(struct sk_buff *skb, ...@@ -214,7 +215,7 @@ int nf_nat_rule_find(struct sk_buff *skb,
{ {
int ret; int ret;
ret = ipt_do_table(skb, hooknum, in, out, &nat_table); ret = ipt_do_table(skb, hooknum, in, out, nat_table);
if (ret == NF_ACCEPT) { if (ret == NF_ACCEPT) {
if (!nf_nat_initialized(ct, HOOK2MANIP(hooknum))) if (!nf_nat_initialized(ct, HOOK2MANIP(hooknum)))
...@@ -248,9 +249,10 @@ int __init nf_nat_rule_init(void) ...@@ -248,9 +249,10 @@ int __init nf_nat_rule_init(void)
{ {
int ret; int ret;
ret = ipt_register_table(&nat_table, &nat_initial_table.repl); nat_table = ipt_register_table(&init_net, &__nat_table,
if (ret != 0) &nat_initial_table.repl);
return ret; if (IS_ERR(nat_table))
return PTR_ERR(nat_table);
ret = xt_register_target(&ipt_snat_reg); ret = xt_register_target(&ipt_snat_reg);
if (ret != 0) if (ret != 0)
goto unregister_table; goto unregister_table;
...@@ -264,7 +266,7 @@ int __init nf_nat_rule_init(void) ...@@ -264,7 +266,7 @@ int __init nf_nat_rule_init(void)
unregister_snat: unregister_snat:
xt_unregister_target(&ipt_snat_reg); xt_unregister_target(&ipt_snat_reg);
unregister_table: unregister_table:
ipt_unregister_table(&nat_table); ipt_unregister_table(nat_table);
return ret; return ret;
} }
...@@ -273,5 +275,5 @@ void nf_nat_rule_cleanup(void) ...@@ -273,5 +275,5 @@ void nf_nat_rule_cleanup(void)
{ {
xt_unregister_target(&ipt_dnat_reg); xt_unregister_target(&ipt_dnat_reg);
xt_unregister_target(&ipt_snat_reg); xt_unregister_target(&ipt_snat_reg);
ipt_unregister_table(&nat_table); ipt_unregister_table(nat_table);
} }
...@@ -2074,7 +2074,7 @@ do_ip6t_get_ctl(struct sock *sk, int cmd, void __user *user, int *len) ...@@ -2074,7 +2074,7 @@ do_ip6t_get_ctl(struct sock *sk, int cmd, void __user *user, int *len)
return ret; return ret;
} }
int ip6t_register_table(struct xt_table *table, const struct ip6t_replace *repl) struct xt_table *ip6t_register_table(struct xt_table *table, const struct ip6t_replace *repl)
{ {
int ret; int ret;
struct xt_table_info *newinfo; struct xt_table_info *newinfo;
...@@ -2084,8 +2084,10 @@ int ip6t_register_table(struct xt_table *table, const struct ip6t_replace *repl) ...@@ -2084,8 +2084,10 @@ int ip6t_register_table(struct xt_table *table, const struct ip6t_replace *repl)
struct xt_table *new_table; struct xt_table *new_table;
newinfo = xt_alloc_table_info(repl->size); newinfo = xt_alloc_table_info(repl->size);
if (!newinfo) if (!newinfo) {
return -ENOMEM; ret = -ENOMEM;
goto out;
}
/* choose the copy on our node/cpu, but dont care about preemption */ /* choose the copy on our node/cpu, but dont care about preemption */
loc_cpu_entry = newinfo->entries[raw_smp_processor_id()]; loc_cpu_entry = newinfo->entries[raw_smp_processor_id()];
...@@ -2096,18 +2098,20 @@ int ip6t_register_table(struct xt_table *table, const struct ip6t_replace *repl) ...@@ -2096,18 +2098,20 @@ int ip6t_register_table(struct xt_table *table, const struct ip6t_replace *repl)
repl->num_entries, repl->num_entries,
repl->hook_entry, repl->hook_entry,
repl->underflow); repl->underflow);
if (ret != 0) { if (ret != 0)
xt_free_table_info(newinfo); goto out_free;
return ret;
}
new_table = xt_register_table(&init_net, table, &bootstrap, newinfo); new_table = xt_register_table(&init_net, table, &bootstrap, newinfo);
if (IS_ERR(new_table)) { if (IS_ERR(new_table)) {
xt_free_table_info(newinfo); ret = PTR_ERR(new_table);
return PTR_ERR(new_table); goto out_free;
} }
return new_table;
return 0; out_free:
xt_free_table_info(newinfo);
out:
return ERR_PTR(ret);
} }
void ip6t_unregister_table(struct xt_table *table) void ip6t_unregister_table(struct xt_table *table)
......
...@@ -51,13 +51,14 @@ static struct ...@@ -51,13 +51,14 @@ static struct
.term = IP6T_ERROR_INIT, /* ERROR */ .term = IP6T_ERROR_INIT, /* ERROR */
}; };
static struct xt_table packet_filter = { static struct xt_table __packet_filter = {
.name = "filter", .name = "filter",
.valid_hooks = FILTER_VALID_HOOKS, .valid_hooks = FILTER_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
.me = THIS_MODULE, .me = THIS_MODULE,
.af = AF_INET6, .af = AF_INET6,
}; };
static struct xt_table *packet_filter;
/* The work comes in here from netfilter.c. */ /* The work comes in here from netfilter.c. */
static unsigned int static unsigned int
...@@ -67,7 +68,7 @@ ip6t_hook(unsigned int hook, ...@@ -67,7 +68,7 @@ ip6t_hook(unsigned int hook,
const struct net_device *out, const struct net_device *out,
int (*okfn)(struct sk_buff *)) int (*okfn)(struct sk_buff *))
{ {
return ip6t_do_table(skb, hook, in, out, &packet_filter); return ip6t_do_table(skb, hook, in, out, packet_filter);
} }
static unsigned int static unsigned int
...@@ -87,7 +88,7 @@ ip6t_local_out_hook(unsigned int hook, ...@@ -87,7 +88,7 @@ ip6t_local_out_hook(unsigned int hook,
} }
#endif #endif
return ip6t_do_table(skb, hook, in, out, &packet_filter); return ip6t_do_table(skb, hook, in, out, packet_filter);
} }
static struct nf_hook_ops ip6t_ops[] __read_mostly = { static struct nf_hook_ops ip6t_ops[] __read_mostly = {
...@@ -131,9 +132,9 @@ static int __init ip6table_filter_init(void) ...@@ -131,9 +132,9 @@ static int __init ip6table_filter_init(void)
initial_table.entries[1].target.verdict = -forward - 1; initial_table.entries[1].target.verdict = -forward - 1;
/* Register table */ /* Register table */
ret = ip6t_register_table(&packet_filter, &initial_table.repl); packet_filter = ip6t_register_table(&__packet_filter, &initial_table.repl);
if (ret < 0) if (IS_ERR(packet_filter))
return ret; return PTR_ERR(packet_filter);
/* Register hooks */ /* Register hooks */
ret = nf_register_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops)); ret = nf_register_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops));
...@@ -143,14 +144,14 @@ static int __init ip6table_filter_init(void) ...@@ -143,14 +144,14 @@ static int __init ip6table_filter_init(void)
return ret; return ret;
cleanup_table: cleanup_table:
ip6t_unregister_table(&packet_filter); ip6t_unregister_table(packet_filter);
return ret; return ret;
} }
static void __exit ip6table_filter_fini(void) static void __exit ip6table_filter_fini(void)
{ {
nf_unregister_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops)); nf_unregister_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops));
ip6t_unregister_table(&packet_filter); ip6t_unregister_table(packet_filter);
} }
module_init(ip6table_filter_init); module_init(ip6table_filter_init);
......
...@@ -57,13 +57,14 @@ static struct ...@@ -57,13 +57,14 @@ static struct
.term = IP6T_ERROR_INIT, /* ERROR */ .term = IP6T_ERROR_INIT, /* ERROR */
}; };
static struct xt_table packet_mangler = { static struct xt_table __packet_mangler = {
.name = "mangle", .name = "mangle",
.valid_hooks = MANGLE_VALID_HOOKS, .valid_hooks = MANGLE_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
.me = THIS_MODULE, .me = THIS_MODULE,
.af = AF_INET6, .af = AF_INET6,
}; };
static struct xt_table *packet_mangler;
/* The work comes in here from netfilter.c. */ /* The work comes in here from netfilter.c. */
static unsigned int static unsigned int
...@@ -73,7 +74,7 @@ ip6t_route_hook(unsigned int hook, ...@@ -73,7 +74,7 @@ ip6t_route_hook(unsigned int hook,
const struct net_device *out, const struct net_device *out,
int (*okfn)(struct sk_buff *)) int (*okfn)(struct sk_buff *))
{ {
return ip6t_do_table(skb, hook, in, out, &packet_mangler); return ip6t_do_table(skb, hook, in, out, packet_mangler);
} }
static unsigned int static unsigned int
...@@ -108,7 +109,7 @@ ip6t_local_hook(unsigned int hook, ...@@ -108,7 +109,7 @@ ip6t_local_hook(unsigned int hook,
/* flowlabel and prio (includes version, which shouldn't change either */ /* flowlabel and prio (includes version, which shouldn't change either */
flowlabel = *((u_int32_t *)ipv6_hdr(skb)); flowlabel = *((u_int32_t *)ipv6_hdr(skb));
ret = ip6t_do_table(skb, hook, in, out, &packet_mangler); ret = ip6t_do_table(skb, hook, in, out, packet_mangler);
if (ret != NF_DROP && ret != NF_STOLEN if (ret != NF_DROP && ret != NF_STOLEN
&& (memcmp(&ipv6_hdr(skb)->saddr, &saddr, sizeof(saddr)) && (memcmp(&ipv6_hdr(skb)->saddr, &saddr, sizeof(saddr))
...@@ -163,9 +164,9 @@ static int __init ip6table_mangle_init(void) ...@@ -163,9 +164,9 @@ static int __init ip6table_mangle_init(void)
int ret; int ret;
/* Register table */ /* Register table */
ret = ip6t_register_table(&packet_mangler, &initial_table.repl); packet_mangler = ip6t_register_table(&__packet_mangler, &initial_table.repl);
if (ret < 0) if (IS_ERR(packet_mangler))
return ret; return PTR_ERR(packet_mangler);
/* Register hooks */ /* Register hooks */
ret = nf_register_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops)); ret = nf_register_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops));
...@@ -175,14 +176,14 @@ static int __init ip6table_mangle_init(void) ...@@ -175,14 +176,14 @@ static int __init ip6table_mangle_init(void)
return ret; return ret;
cleanup_table: cleanup_table:
ip6t_unregister_table(&packet_mangler); ip6t_unregister_table(packet_mangler);
return ret; return ret;
} }
static void __exit ip6table_mangle_fini(void) static void __exit ip6table_mangle_fini(void)
{ {
nf_unregister_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops)); nf_unregister_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops));
ip6t_unregister_table(&packet_mangler); ip6t_unregister_table(packet_mangler);
} }
module_init(ip6table_mangle_init); module_init(ip6table_mangle_init);
......
...@@ -35,13 +35,14 @@ static struct ...@@ -35,13 +35,14 @@ static struct
.term = IP6T_ERROR_INIT, /* ERROR */ .term = IP6T_ERROR_INIT, /* ERROR */
}; };
static struct xt_table packet_raw = { static struct xt_table __packet_raw = {
.name = "raw", .name = "raw",
.valid_hooks = RAW_VALID_HOOKS, .valid_hooks = RAW_VALID_HOOKS,
.lock = RW_LOCK_UNLOCKED, .lock = RW_LOCK_UNLOCKED,
.me = THIS_MODULE, .me = THIS_MODULE,
.af = AF_INET6, .af = AF_INET6,
}; };
static struct xt_table *packet_raw;
/* The work comes in here from netfilter.c. */ /* The work comes in here from netfilter.c. */
static unsigned int static unsigned int
...@@ -51,7 +52,7 @@ ip6t_hook(unsigned int hook, ...@@ -51,7 +52,7 @@ ip6t_hook(unsigned int hook,
const struct net_device *out, const struct net_device *out,
int (*okfn)(struct sk_buff *)) int (*okfn)(struct sk_buff *))
{ {
return ip6t_do_table(skb, hook, in, out, &packet_raw); return ip6t_do_table(skb, hook, in, out, packet_raw);
} }
static struct nf_hook_ops ip6t_ops[] __read_mostly = { static struct nf_hook_ops ip6t_ops[] __read_mostly = {
...@@ -76,9 +77,9 @@ static int __init ip6table_raw_init(void) ...@@ -76,9 +77,9 @@ static int __init ip6table_raw_init(void)
int ret; int ret;
/* Register table */ /* Register table */
ret = ip6t_register_table(&packet_raw, &initial_table.repl); packet_raw = ip6t_register_table(&__packet_raw, &initial_table.repl);
if (ret < 0) if (IS_ERR(packet_raw))
return ret; return PTR_ERR(packet_raw);
/* Register hooks */ /* Register hooks */
ret = nf_register_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops)); ret = nf_register_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops));
...@@ -88,14 +89,14 @@ static int __init ip6table_raw_init(void) ...@@ -88,14 +89,14 @@ static int __init ip6table_raw_init(void)
return ret; return ret;
cleanup_table: cleanup_table:
ip6t_unregister_table(&packet_raw); ip6t_unregister_table(packet_raw);
return ret; return ret;
} }
static void __exit ip6table_raw_fini(void) static void __exit ip6table_raw_fini(void)
{ {
nf_unregister_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops)); nf_unregister_hooks(ip6t_ops, ARRAY_SIZE(ip6t_ops));
ip6t_unregister_table(&packet_raw); ip6t_unregister_table(packet_raw);
} }
module_init(ip6table_raw_init); module_init(ip6table_raw_init);
......
...@@ -667,9 +667,16 @@ struct xt_table *xt_register_table(struct net *net, struct xt_table *table, ...@@ -667,9 +667,16 @@ struct xt_table *xt_register_table(struct net *net, struct xt_table *table,
struct xt_table_info *private; struct xt_table_info *private;
struct xt_table *t; struct xt_table *t;
/* Don't add one object to multiple lists. */
table = kmemdup(table, sizeof(struct xt_table), GFP_KERNEL);
if (!table) {
ret = -ENOMEM;
goto out;
}
ret = mutex_lock_interruptible(&xt[table->af].mutex); ret = mutex_lock_interruptible(&xt[table->af].mutex);
if (ret != 0) if (ret != 0)
goto out; goto out_free;
/* Don't autoload: we'd eat our tail... */ /* Don't autoload: we'd eat our tail... */
list_for_each_entry(t, &net->xt.tables[table->af], list) { list_for_each_entry(t, &net->xt.tables[table->af], list) {
...@@ -697,6 +704,8 @@ struct xt_table *xt_register_table(struct net *net, struct xt_table *table, ...@@ -697,6 +704,8 @@ struct xt_table *xt_register_table(struct net *net, struct xt_table *table,
unlock: unlock:
mutex_unlock(&xt[table->af].mutex); mutex_unlock(&xt[table->af].mutex);
out_free:
kfree(table);
out: out:
return ERR_PTR(ret); return ERR_PTR(ret);
} }
...@@ -710,6 +719,7 @@ void *xt_unregister_table(struct xt_table *table) ...@@ -710,6 +719,7 @@ void *xt_unregister_table(struct xt_table *table)
private = table->private; private = table->private;
list_del(&table->list); list_del(&table->list);
mutex_unlock(&xt[table->af].mutex); mutex_unlock(&xt[table->af].mutex);
kfree(table);
return private; return private;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册