From: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
To: netfilter-devel@vger.kernel.org
Cc: giuseppelng@gmail.com, pablo@netfilter.org
Subject: [ebtables-compat PATCH 4/7] ebtables-compat: prevent same matches to be included multiple times
Date: Mon, 19 Jan 2015 14:27:51 +0100 [thread overview]
Message-ID: <20150119132751.7422.77819.stgit@nfdev.cica.es> (raw)
In-Reply-To: <20150119132735.7422.85388.stgit@nfdev.cica.es>
Using two matches options results in two copies of the match being included
in the nft rule.
Example before this patch:
% ebtables-compat -A FORWARD -p 0x0800 --ip-src 10.0.0.1 --ip-dst 10.0.0.2 -j ACCEPT
% ebtables-compat -L
[...]
-p 0x0800 --ip-src 10.0.0.1 --ip-dst 10.0.0.2 --ip-src 10.0.0.1 --ip-dst 10.0.0.2 -j ACCEPT
Example with this patch:
% ebtables-compat -A FORWARD -p 0x0800 --ip-src 10.0.0.1 --ip-dst 10.0.0.2 -j ACCEPT
% ebtables-compat -L
[...]
% -p 0x0800 --ip-src 10.0.0.1 --ip-dst 10.0.0.2 -j ACCEPT
[Note: the br_ip extension comes in a follow-up patch]
Signed-off-by: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
---
iptables/xtables-eb.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c
index b559a53..a078679 100644
--- a/iptables/xtables-eb.c
+++ b/iptables/xtables-eb.c
@@ -644,6 +644,14 @@ static void ebt_load_matches(void)
static void ebt_add_match(struct xtables_match *m,
struct xtables_rule_match **rule_matches)
{
+ struct xtables_rule_match *i;
+
+ /* match already in rule_matches, skip inclusion */
+ for (i = *rule_matches; i; i = i->next) {
+ if (strcmp(m->name, i->match->name) == 0)
+ return;
+ }
+
if (xtables_find_match(m->name, XTF_LOAD_MUST_SUCCEED, rule_matches) == NULL)
xtables_error(OTHER_PROBLEM,
"Unable to add match %s", m->name);
next prev parent reply other threads:[~2015-01-19 13:28 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-01-19 13:27 [ebtables-compat PATCH 1/7] include: cache copy of Linux header uapi/linux/netfilter_bridge/ebt_802_3.h Arturo Borrero Gonzalez
2015-01-19 13:27 ` [ebtables-compat PATCH 2/7] ebtables-compat: add nft rule compat information to bridge rules Arturo Borrero Gonzalez
2015-01-19 13:27 ` [ebtables-compat PATCH 3/7] ebtables-compat: prevent options overwrite Arturo Borrero Gonzalez
2015-01-19 13:27 ` Arturo Borrero Gonzalez [this message]
2015-01-19 13:27 ` [ebtables-compat PATCH 5/7] ebtables-compat: include rule counters in ebtables rules Arturo Borrero Gonzalez
2015-01-19 13:28 ` [ebtables-compat PATCH 6/7] ebtables-compat: fix nft payload bases Arturo Borrero Gonzalez
2015-01-19 13:28 ` [ebtables-compat PATCH 7/7] ebtables-compat: add 'ip' match extension Arturo Borrero Gonzalez
2015-01-28 16:24 ` [ebtables-compat PATCH 1/7] include: cache copy of Linux header uapi/linux/netfilter_bridge/ebt_802_3.h Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150119132751.7422.77819.stgit@nfdev.cica.es \
--to=arturo.borrero.glez@gmail.com \
--cc=giuseppelng@gmail.com \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).