cregit-Linux how code gets into the kernel

Release 4.11 net/netfilter/xt_ecn.c

Directory: net/netfilter
/*
 * Xtables module for matching the value of the IPv4/IPv6 and TCP ECN bits
 *
 * (C) 2002 by Harald Welte <laforge@gnumonks.org>
 * (C) 2011 Patrick McHardy <kaber@trash.net>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
#include <linux/in.h>
#include <linux/ip.h>
#include <net/ip.h>
#include <linux/module.h>
#include <linux/skbuff.h>
#include <linux/tcp.h>

#include <linux/netfilter/x_tables.h>
#include <linux/netfilter/xt_ecn.h>
#include <linux/netfilter_ipv4/ip_tables.h>
#include <linux/netfilter_ipv6/ip6_tables.h>

MODULE_AUTHOR("Harald Welte <laforge@netfilter.org>");
MODULE_DESCRIPTION("Xtables: Explicit Congestion Notification (ECN) flag match");
MODULE_LICENSE("GPL");
MODULE_ALIAS("ipt_ecn");
MODULE_ALIAS("ip6t_ecn");


static bool match_tcp(const struct sk_buff *skb, struct xt_action_param *par) { const struct xt_ecn_info *einfo = par->matchinfo; struct tcphdr _tcph; const struct tcphdr *th; /* In practice, TCP match does this, so can't fail. But let's * be good citizens. */ th = skb_header_pointer(skb, par->thoff, sizeof(_tcph), &_tcph); if (th == NULL) return false; if (einfo->operation & XT_ECN_OP_MATCH_ECE) { if (einfo->invert & XT_ECN_OP_MATCH_ECE) { if (th->ece == 1) return false; } else { if (th->ece == 0) return false; } } if (einfo->operation & XT_ECN_OP_MATCH_CWR) { if (einfo->invert & XT_ECN_OP_MATCH_CWR) { if (th->cwr == 1) return false; } else { if (th->cwr == 0) return false; } } return true; }

Contributors

PersonTokensPropCommitsCommitProp
Harald Welte9257.86%114.29%
David S. Miller2515.72%114.29%
Jan Engelhardt1610.06%342.86%
Patrick McHardy148.81%114.29%
Rusty Russell127.55%114.29%
Total159100.00%7100.00%


static inline bool match_ip(const struct sk_buff *skb, const struct xt_ecn_info *einfo) { return ((ip_hdr(skb)->tos & XT_ECN_IP_MASK) == einfo->ip_ect) ^ !!(einfo->invert & XT_ECN_OP_MATCH_IP); }

Contributors

PersonTokensPropCommitsCommitProp
Patrick McHardy4595.74%133.33%
Harald Welte12.13%133.33%
Jan Engelhardt12.13%133.33%
Total47100.00%3100.00%


static bool ecn_mt4(const struct sk_buff *skb, struct xt_action_param *par) { const struct xt_ecn_info *info = par->matchinfo; if (info->operation & XT_ECN_OP_MATCH_IP && !match_ip(skb, info)) return false; if (info->operation & (XT_ECN_OP_MATCH_ECE | XT_ECN_OP_MATCH_CWR) && !match_tcp(skb, par)) return false; return true; }

Contributors

PersonTokensPropCommitsCommitProp
Harald Welte5576.39%114.29%
Jan Engelhardt1419.44%571.43%
Patrick McHardy34.17%114.29%
Total72100.00%7100.00%


static int ecn_mt_check4(const struct xt_mtchk_param *par) { const struct xt_ecn_info *info = par->matchinfo; const struct ipt_ip *ip = par->entryinfo; if (info->operation & XT_ECN_OP_MATCH_MASK) return -EINVAL; if (info->invert & XT_ECN_OP_MATCH_MASK) return -EINVAL; if (info->operation & (XT_ECN_OP_MATCH_ECE | XT_ECN_OP_MATCH_CWR) && (ip->proto != IPPROTO_TCP || ip->invflags & IPT_INV_PROTO)) { pr_info("cannot match TCP bits in rule for non-tcp packets\n"); return -EINVAL; } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Harald Welte6365.62%220.00%
Jan Engelhardt2222.92%550.00%
Patrick McHardy1111.46%330.00%
Total96100.00%10100.00%


static inline bool match_ipv6(const struct sk_buff *skb, const struct xt_ecn_info *einfo) { return (((ipv6_hdr(skb)->flow_lbl[0] >> 4) & XT_ECN_IP_MASK) == einfo->ip_ect) ^ !!(einfo->invert & XT_ECN_OP_MATCH_IP); }

Contributors

PersonTokensPropCommitsCommitProp
Patrick McHardy54100.00%1100.00%
Total54100.00%1100.00%


static bool ecn_mt6(const struct sk_buff *skb, struct xt_action_param *par) { const struct xt_ecn_info *info = par->matchinfo; if (info->operation & XT_ECN_OP_MATCH_IP && !match_ipv6(skb, info)) return false; if (info->operation & (XT_ECN_OP_MATCH_ECE | XT_ECN_OP_MATCH_CWR) && !match_tcp(skb, par)) return false; return true; }

Contributors

PersonTokensPropCommitsCommitProp
Patrick McHardy72100.00%1100.00%
Total72100.00%1100.00%


static int ecn_mt_check6(const struct xt_mtchk_param *par) { const struct xt_ecn_info *info = par->matchinfo; const struct ip6t_ip6 *ip = par->entryinfo; if (info->operation & XT_ECN_OP_MATCH_MASK) return -EINVAL; if (info->invert & XT_ECN_OP_MATCH_MASK) return -EINVAL; if (info->operation & (XT_ECN_OP_MATCH_ECE | XT_ECN_OP_MATCH_CWR) && (ip->proto != IPPROTO_TCP || ip->invflags & IP6T_INV_PROTO)) { pr_info("cannot match TCP bits in rule for non-tcp packets\n"); return -EINVAL; } return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Patrick McHardy96100.00%1100.00%
Total96100.00%1100.00%

static struct xt_match ecn_mt_reg[] __read_mostly = { { .name = "ecn", .family = NFPROTO_IPV4, .match = ecn_mt4, .matchsize = sizeof(struct xt_ecn_info), .checkentry = ecn_mt_check4, .me = THIS_MODULE, }, { .name = "ecn", .family = NFPROTO_IPV6, .match = ecn_mt6, .matchsize = sizeof(struct xt_ecn_info), .checkentry = ecn_mt_check6, .me = THIS_MODULE, }, };
static int __init ecn_mt_init(void) { return xt_register_matches(ecn_mt_reg, ARRAY_SIZE(ecn_mt_reg)); }

Contributors

PersonTokensPropCommitsCommitProp
Harald Welte1260.00%133.33%
Patrick McHardy630.00%133.33%
Jan Engelhardt210.00%133.33%
Total20100.00%3100.00%


static void __exit ecn_mt_exit(void) { xt_unregister_matches(ecn_mt_reg, ARRAY_SIZE(ecn_mt_reg)); }

Contributors

PersonTokensPropCommitsCommitProp
Harald Welte1157.89%133.33%
Patrick McHardy631.58%133.33%
Jan Engelhardt210.53%133.33%
Total19100.00%3100.00%

module_init(ecn_mt_init); module_exit(ecn_mt_exit);

Overall Contributors

PersonTokensPropCommitsCommitProp
Patrick McHardy36546.26%518.52%
Harald Welte27935.36%311.11%
Jan Engelhardt9011.41%1451.85%
David S. Miller253.17%13.70%
Art Haas131.65%13.70%
Rusty Russell121.52%13.70%
Arnaldo Carvalho de Melo50.63%27.41%
Total789100.00%27100.00%
Directory: net/netfilter
Information contained on this website is for historical information purposes only and does not indicate or represent copyright ownership.
Created with cregit.