* [PATCH] netfilter: nf_nat: Also handle non-ESTABLISHED routing changes in MASQUERADE
@ 2012-12-12 23:49 Andrew Collins
2012-12-13 0:17 ` Andrew Collins
0 siblings, 1 reply; 2+ messages in thread
From: Andrew Collins @ 2012-12-12 23:49 UTC (permalink / raw)
To: netfilter-devel, netdev, kadlec
The MASQUERADE target now handles routing changes which affect
the output interface of a connection, but only for ESTABLISHED
connections. It is also possible for NEW connections which
already have a conntrack entry to be affected by routing changes.
This adds a check to drop entries in the NEW+conntrack state
when the oif has changed.
Signed-off-by: Andrew Collins <bsderandrew@gmail.com>
---
net/ipv4/netfilter/iptable_nat.c | 15 ++++++++++-----
1 files changed, 10 insertions(+), 5 deletions(-)
diff --git a/net/ipv4/netfilter/iptable_nat.c b/net/ipv4/netfilter/iptable_nat.c
index da2c8a3..eeaff7e 100644
--- a/net/ipv4/netfilter/iptable_nat.c
+++ b/net/ipv4/netfilter/iptable_nat.c
@@ -124,23 +124,28 @@ nf_nat_ipv4_fn(unsigned int hooknum,
ret = nf_nat_rule_find(skb, hooknum, in, out, ct);
if (ret != NF_ACCEPT)
return ret;
- } else
+ } else {
pr_debug("Already setup manip %s for ct %p\n",
maniptype == NF_NAT_MANIP_SRC ? "SRC" : "DST",
ct);
+ if (nf_nat_oif_changed(hooknum, ctinfo, nat, out))
+ goto oif_changed;
+ }
break;
default:
/* ESTABLISHED */
NF_CT_ASSERT(ctinfo == IP_CT_ESTABLISHED ||
ctinfo == IP_CT_ESTABLISHED_REPLY);
- if (nf_nat_oif_changed(hooknum, ctinfo, nat, out)) {
- nf_ct_kill_acct(ct, ctinfo, skb);
- return NF_DROP;
- }
+ if (nf_nat_oif_changed(hooknum, ctinfo, nat, out))
+ goto oif_changed;
}
return nf_nat_packet(ct, ctinfo, hooknum, skb);
+
+oif_changed:
+ nf_ct_kill_acct(ct, ctinfo, skb);
+ return NF_DROP;
}
static unsigned int
--
1.7.1
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] netfilter: nf_nat: Also handle non-ESTABLISHED routing changes in MASQUERADE
2012-12-12 23:49 [PATCH] netfilter: nf_nat: Also handle non-ESTABLISHED routing changes in MASQUERADE Andrew Collins
@ 2012-12-13 0:17 ` Andrew Collins
0 siblings, 0 replies; 2+ messages in thread
From: Andrew Collins @ 2012-12-13 0:17 UTC (permalink / raw)
To: netfilter-devel, netdev, kadlec
On Wed, Dec 12, 2012 at 4:49 PM, Andrew Collins <bsderandrew@gmail.com> wrote:
> The MASQUERADE target now handles routing changes which affect
> the output interface of a connection, but only for ESTABLISHED
> connections. It is also possible for NEW connections which
> already have a conntrack entry to be affected by routing changes.
>
> This adds a check to drop entries in the NEW+conntrack state
> when the oif has changed.
>
> Signed-off-by: Andrew Collins <bsderandrew@gmail.com>
> ---
> net/ipv4/netfilter/iptable_nat.c | 15 ++++++++++-----
> 1 files changed, 10 insertions(+), 5 deletions(-)
My mistake, I forgot to include the corresponding ip6table_nat.c
change (it's identical), ignore this for now.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2012-12-13 0:17 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-12-12 23:49 [PATCH] netfilter: nf_nat: Also handle non-ESTABLISHED routing changes in MASQUERADE Andrew Collins
2012-12-13 0:17 ` Andrew Collins
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).