Commit 57de0abb authored by Jan Engelhardt's avatar Jan Engelhardt Committed by David S. Miller

[NETFILTER]: xt_pkttype: IPv6 multicast address recognition

Signed-off-by: default avatarJan Engelhart <jengelh@computergmbh.de>
Signed-off-by: default avatarPatrick McHardy <kaber@trash.net>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent 13b0e83b
...@@ -11,6 +11,7 @@ ...@@ -11,6 +11,7 @@
#include <linux/if_packet.h> #include <linux/if_packet.h>
#include <linux/in.h> #include <linux/in.h>
#include <linux/ip.h> #include <linux/ip.h>
#include <linux/ipv6.h>
#include <linux/netfilter/xt_pkttype.h> #include <linux/netfilter/xt_pkttype.h>
#include <linux/netfilter/x_tables.h> #include <linux/netfilter/x_tables.h>
...@@ -27,16 +28,19 @@ pkttype_mt(const struct sk_buff *skb, const struct net_device *in, ...@@ -27,16 +28,19 @@ pkttype_mt(const struct sk_buff *skb, const struct net_device *in,
const void *matchinfo, int offset, unsigned int protoff, const void *matchinfo, int offset, unsigned int protoff,
bool *hotdrop) bool *hotdrop)
{ {
u_int8_t type;
const struct xt_pkttype_info *info = matchinfo; const struct xt_pkttype_info *info = matchinfo;
u_int8_t type;
if (skb->pkt_type == PACKET_LOOPBACK) if (skb->pkt_type != PACKET_LOOPBACK)
type = match->family == AF_INET &&
ipv4_is_multicast(ip_hdr(skb)->daddr)
? PACKET_MULTICAST
: PACKET_BROADCAST;
else
type = skb->pkt_type; type = skb->pkt_type;
else if (match->family == AF_INET &&
ipv4_is_multicast(ip_hdr(skb)->daddr))
type = PACKET_MULTICAST;
else if (match->family == AF_INET6 &&
ipv6_hdr(skb)->daddr.s6_addr[0] == 0xFF)
type = PACKET_MULTICAST;
else
type = PACKET_BROADCAST;
return (type == info->pkttype) ^ info->invert; return (type == info->pkttype) ^ info->invert;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment