From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
Cc: netfilter-devel@vger.kernel.org, giuseppelng@gmail.com
Subject: Re: [ebtables-compat-experimental5 PATCH] iptables: xtables-eb: user-defined chains default policy is always RETURN
Date: Thu, 20 Nov 2014 13:07:18 +0100 [thread overview]
Message-ID: <20141120120718.GA9745@salvia> (raw)
In-Reply-To: <20141119131147.15524.18916.stgit@nfdev.cica.es>
On Wed, Nov 19, 2014 at 02:11:47PM +0100, Arturo Borrero Gonzalez wrote:
> The RETURN default policy is mandatory in user-defined chains.
> Builtin chains must have one of ACCEPT or DROP.
>
> So, with this patch, ebtables-compat ends with:
>
> Command: Result:
>
> -L Always RETURN for user-defined chains
> -P builtin RETURN Policy RETURN only allowed for user defined chains
> -P builtin ACCEPT|DROP ok
> -P userdefined RETURN Default policy in user-defined chains is RETURN
> -P userdefined ACCEPT|DROP Default policy in user-defined chains is RETURN
> -N userdefined ok
> -N userdefined -P RETURN Default policy in user-defined chains is RETURN
> -N userdefined -P ACCEPT|DROP Default policy in user-defined chains is RETURN
>
> Signed-off-by: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
> ---
> iptables/nft-bridge.c | 3 ++-
> iptables/xtables-eb.c | 13 +++++++++++--
> 2 files changed, 13 insertions(+), 3 deletions(-)
>
> diff --git a/iptables/nft-bridge.c b/iptables/nft-bridge.c
> index b5aec00..a1bd906 100644
> --- a/iptables/nft-bridge.c
> +++ b/iptables/nft-bridge.c
> @@ -356,7 +356,8 @@ static void nft_bridge_print_header(unsigned int format, const char *chain,
> const struct xt_counters *counters,
> bool basechain, uint32_t refs)
> {
> - printf("Bridge chain: %s, entries: %u, policy: %s\n", chain, refs, pol);
> + printf("Bridge chain: %s, entries: %u, policy: %s\n",
> + chain, refs, basechain ? pol : "RETURN");
> }
>
> static void nft_bridge_print_firewall(struct nft_rule *r, unsigned int num,
> diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c
> index 917bca2..0775ee7 100644
> --- a/iptables/xtables-eb.c
> +++ b/iptables/xtables-eb.c
> @@ -616,6 +616,7 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table)
> case 'E': /* Rename chain */
> case 'X': /* Delete chain */
> /* We allow -N chainname -P policy */
> + /* XXX: Not in ebtables-compat */
> if (command == 'N' && c == 'P') {
> command = c;
> optind--; /* No table specified */
> @@ -1146,9 +1147,17 @@ check_extension: */
> cs.fw.ethproto = htons(cs.fw.ethproto);
>
> if (command == 'P') {
> - if (selected_chain < NF_BR_NUMHOOKS && strcmp(policy, "RETURN")==0)
> + if (selected_chain < 0) {
> xtables_error(PARAMETER_PROBLEM,
> - "Policy RETURN only allowed for user defined chains");
> + "Default policy in user-defined"
> + " chains is mandatory RETURN");
Wait.
This changes the existing behaviour. I mean, this check rejects rules
using RETURN from base chains, that should still be there to mimic
ebtables behaviour. Why change this?
> + }
> + if (strcmp(policy, "ACCEPT") != 0 &&
> + strcmp(policy, "DROP") != 0) {
> + xtables_error(PARAMETER_PROBLEM,
> + "Default policy in default chains"
> + " is either ACCEPT or DROP");
Please use the same error message the ebtables uses:
"Policy RETURN only allowed for user defined chains");
And explicitly check for RETURN instead. This is a compat tool, we
should spot the same errors than the original.
> + }
> ret = nft_chain_set(h, *table, chain, policy, NULL);
> if (ret < 0)
> xtables_error(PARAMETER_PROBLEM, "Wrong policy");
>
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
next prev parent reply other threads:[~2014-11-20 12:05 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-19 13:11 [ebtables-compat-experimental5 PATCH] iptables: xtables-eb: user-defined chains default policy is always RETURN Arturo Borrero Gonzalez
2014-11-20 12:01 ` Pablo Neira Ayuso
2014-11-20 12:07 ` Pablo Neira Ayuso [this message]
2014-11-24 9:46 ` Arturo Borrero Gonzalez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20141120120718.GA9745@salvia \
--to=pablo@netfilter.org \
--cc=arturo.borrero.glez@gmail.com \
--cc=giuseppelng@gmail.com \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.