Patrick McHardy | f229f6c | 2013-04-06 15:24:29 +0200 | [diff] [blame] | 1 | /* |
| 2 | * Rusty Russell (C)2000 -- This code is GPL. |
| 3 | * Patrick McHardy (c) 2006-2012 |
| 4 | */ |
| 5 | |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 6 | #include <linux/kernel.h> |
Tejun Heo | 5a0e3ad | 2010-03-24 17:04:11 +0900 | [diff] [blame] | 7 | #include <linux/slab.h> |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 8 | #include <linux/init.h> |
| 9 | #include <linux/module.h> |
| 10 | #include <linux/proc_fs.h> |
| 11 | #include <linux/skbuff.h> |
| 12 | #include <linux/netfilter.h> |
Pablo Neira Ayuso | 7db9a51 | 2017-12-20 16:12:55 +0100 | [diff] [blame] | 13 | #include <linux/netfilter_ipv4.h> |
| 14 | #include <linux/netfilter_ipv6.h> |
Florian Westphal | c737b7c | 2015-04-02 14:31:41 +0200 | [diff] [blame] | 15 | #include <linux/netfilter_bridge.h> |
Harald Welte | bbd86b9f | 2005-08-09 20:23:11 -0700 | [diff] [blame] | 16 | #include <linux/seq_file.h> |
Patrick McHardy | 7a11b98 | 2006-02-27 13:03:24 -0800 | [diff] [blame] | 17 | #include <linux/rcupdate.h> |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 18 | #include <net/protocol.h> |
Patrick McHardy | c01cd42 | 2007-12-05 01:24:48 -0800 | [diff] [blame] | 19 | #include <net/netfilter/nf_queue.h> |
Eric Dumazet | 7fee226 | 2010-05-11 23:19:48 +0000 | [diff] [blame] | 20 | #include <net/dst.h> |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 21 | |
| 22 | #include "nf_internals.h" |
| 23 | |
YOSHIFUJI Hideaki | 601e68e | 2007-02-12 11:15:49 -0800 | [diff] [blame] | 24 | /* |
Florian Westphal | 0360ae4 | 2012-11-23 06:22:21 +0000 | [diff] [blame] | 25 | * Hook for nfnetlink_queue to register its queue handler. |
| 26 | * We do this so that most of the NFQUEUE code can be modular. |
| 27 | * |
| 28 | * Once the queue is registered it must reinject all packets it |
| 29 | * receives, no matter what. |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 30 | */ |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 31 | |
Harald Welte | d72367b | 2005-08-09 20:23:36 -0700 | [diff] [blame] | 32 | /* return EBUSY when somebody else is registered, return EEXIST if the |
| 33 | * same handler is registered, return 0 in case of success. */ |
Eric W. Biederman | dc3ee32 | 2016-05-13 21:18:52 -0500 | [diff] [blame] | 34 | void nf_register_queue_handler(struct net *net, const struct nf_queue_handler *qh) |
YOSHIFUJI Hideaki | 601e68e | 2007-02-12 11:15:49 -0800 | [diff] [blame] | 35 | { |
Florian Westphal | 0360ae4 | 2012-11-23 06:22:21 +0000 | [diff] [blame] | 36 | /* should never happen, we only have one queueing backend in kernel */ |
Eric W. Biederman | dc3ee32 | 2016-05-13 21:18:52 -0500 | [diff] [blame] | 37 | WARN_ON(rcu_access_pointer(net->nf.queue_handler)); |
| 38 | rcu_assign_pointer(net->nf.queue_handler, qh); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 39 | } |
| 40 | EXPORT_SYMBOL(nf_register_queue_handler); |
| 41 | |
| 42 | /* The caller must flush their queue before this */ |
Eric W. Biederman | dc3ee32 | 2016-05-13 21:18:52 -0500 | [diff] [blame] | 43 | void nf_unregister_queue_handler(struct net *net) |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 44 | { |
Eric W. Biederman | dc3ee32 | 2016-05-13 21:18:52 -0500 | [diff] [blame] | 45 | RCU_INIT_POINTER(net->nf.queue_handler, NULL); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 46 | } |
| 47 | EXPORT_SYMBOL(nf_unregister_queue_handler); |
| 48 | |
Florian Westphal | dd3cc11 | 2020-03-27 03:24:46 +0100 | [diff] [blame] | 49 | static void nf_queue_entry_release_refs(struct nf_queue_entry *entry) |
Patrick McHardy | daaa8be | 2007-12-05 01:27:19 -0800 | [diff] [blame] | 50 | { |
David S. Miller | 1d1de89 | 2015-04-03 16:31:01 -0400 | [diff] [blame] | 51 | struct nf_hook_state *state = &entry->state; |
| 52 | |
Patrick McHardy | daaa8be | 2007-12-05 01:27:19 -0800 | [diff] [blame] | 53 | /* Release those devices we held, or Alexey will kill me. */ |
David S. Miller | 1d1de89 | 2015-04-03 16:31:01 -0400 | [diff] [blame] | 54 | if (state->in) |
| 55 | dev_put(state->in); |
| 56 | if (state->out) |
| 57 | dev_put(state->out); |
David Miller | 1c984f8a | 2015-04-05 22:19:00 -0400 | [diff] [blame] | 58 | if (state->sk) |
| 59 | sock_put(state->sk); |
Florian Westphal | c4b0e77 | 2018-12-18 17:15:15 +0100 | [diff] [blame] | 60 | |
Florian Westphal | 119e52e | 2020-03-27 03:24:47 +0100 | [diff] [blame] | 61 | #if IS_ENABLED(CONFIG_BRIDGE_NETFILTER) |
| 62 | if (entry->physin) |
| 63 | dev_put(entry->physin); |
| 64 | if (entry->physout) |
| 65 | dev_put(entry->physout); |
| 66 | #endif |
Florian Westphal | c4b0e77 | 2018-12-18 17:15:15 +0100 | [diff] [blame] | 67 | } |
Florian Westphal | dd3cc11 | 2020-03-27 03:24:46 +0100 | [diff] [blame] | 68 | |
| 69 | void nf_queue_entry_free(struct nf_queue_entry *entry) |
| 70 | { |
| 71 | nf_queue_entry_release_refs(entry); |
| 72 | kfree(entry); |
| 73 | } |
| 74 | EXPORT_SYMBOL_GPL(nf_queue_entry_free); |
Florian Westphal | c4b0e77 | 2018-12-18 17:15:15 +0100 | [diff] [blame] | 75 | |
Florian Westphal | 119e52e | 2020-03-27 03:24:47 +0100 | [diff] [blame] | 76 | static void __nf_queue_entry_init_physdevs(struct nf_queue_entry *entry) |
Florian Westphal | c4b0e77 | 2018-12-18 17:15:15 +0100 | [diff] [blame] | 77 | { |
Pablo Neira Ayuso | 1109a90 | 2014-10-01 11:19:17 +0200 | [diff] [blame] | 78 | #if IS_ENABLED(CONFIG_BRIDGE_NETFILTER) |
Florian Westphal | 119e52e | 2020-03-27 03:24:47 +0100 | [diff] [blame] | 79 | const struct sk_buff *skb = entry->skb; |
| 80 | struct nf_bridge_info *nf_bridge; |
Florian Westphal | c4b0e77 | 2018-12-18 17:15:15 +0100 | [diff] [blame] | 81 | |
Florian Westphal | 119e52e | 2020-03-27 03:24:47 +0100 | [diff] [blame] | 82 | nf_bridge = nf_bridge_info_get(skb); |
Florian Westphal | c4b0e77 | 2018-12-18 17:15:15 +0100 | [diff] [blame] | 83 | if (nf_bridge) { |
Florian Westphal | 119e52e | 2020-03-27 03:24:47 +0100 | [diff] [blame] | 84 | entry->physin = nf_bridge_get_physindev(skb); |
| 85 | entry->physout = nf_bridge_get_physoutdev(skb); |
| 86 | } else { |
| 87 | entry->physin = NULL; |
| 88 | entry->physout = NULL; |
Patrick McHardy | daaa8be | 2007-12-05 01:27:19 -0800 | [diff] [blame] | 89 | } |
| 90 | #endif |
Patrick McHardy | daaa8be | 2007-12-05 01:27:19 -0800 | [diff] [blame] | 91 | } |
| 92 | |
Florian Westphal | 4bd6044 | 2013-04-19 04:58:23 +0000 | [diff] [blame] | 93 | /* Bump dev refs so they don't vanish while packet is out */ |
Florian Westphal | ed78d09 | 2015-10-13 14:33:27 +0200 | [diff] [blame] | 94 | void nf_queue_entry_get_refs(struct nf_queue_entry *entry) |
Florian Westphal | 4bd6044 | 2013-04-19 04:58:23 +0000 | [diff] [blame] | 95 | { |
David S. Miller | 1d1de89 | 2015-04-03 16:31:01 -0400 | [diff] [blame] | 96 | struct nf_hook_state *state = &entry->state; |
| 97 | |
David S. Miller | 1d1de89 | 2015-04-03 16:31:01 -0400 | [diff] [blame] | 98 | if (state->in) |
| 99 | dev_hold(state->in); |
| 100 | if (state->out) |
| 101 | dev_hold(state->out); |
David Miller | 1c984f8a | 2015-04-05 22:19:00 -0400 | [diff] [blame] | 102 | if (state->sk) |
| 103 | sock_hold(state->sk); |
Florian Westphal | 4bd6044 | 2013-04-19 04:58:23 +0000 | [diff] [blame] | 104 | |
Florian Westphal | 119e52e | 2020-03-27 03:24:47 +0100 | [diff] [blame] | 105 | #if IS_ENABLED(CONFIG_BRIDGE_NETFILTER) |
| 106 | if (entry->physin) |
| 107 | dev_hold(entry->physin); |
| 108 | if (entry->physout) |
| 109 | dev_hold(entry->physout); |
| 110 | #endif |
Florian Westphal | 4bd6044 | 2013-04-19 04:58:23 +0000 | [diff] [blame] | 111 | } |
Florian Westphal | a5fedd43 | 2013-04-19 04:58:25 +0000 | [diff] [blame] | 112 | EXPORT_SYMBOL_GPL(nf_queue_entry_get_refs); |
Florian Westphal | 4bd6044 | 2013-04-19 04:58:23 +0000 | [diff] [blame] | 113 | |
Florian Westphal | 26888df | 2017-12-01 00:21:03 +0100 | [diff] [blame] | 114 | void nf_queue_nf_hook_drop(struct net *net) |
Eric W. Biederman | 8405a8f | 2015-06-19 14:03:39 -0500 | [diff] [blame] | 115 | { |
| 116 | const struct nf_queue_handler *qh; |
Eric W. Biederman | 8405a8f | 2015-06-19 14:03:39 -0500 | [diff] [blame] | 117 | |
Eric W. Biederman | 8405a8f | 2015-06-19 14:03:39 -0500 | [diff] [blame] | 118 | rcu_read_lock(); |
Eric W. Biederman | dc3ee32 | 2016-05-13 21:18:52 -0500 | [diff] [blame] | 119 | qh = rcu_dereference(net->nf.queue_handler); |
Pablo Neira Ayuso | 2385eb0 | 2015-07-20 12:55:02 +0200 | [diff] [blame] | 120 | if (qh) |
Florian Westphal | 26888df | 2017-12-01 00:21:03 +0100 | [diff] [blame] | 121 | qh->nf_hook_drop(net); |
Eric W. Biederman | 8405a8f | 2015-06-19 14:03:39 -0500 | [diff] [blame] | 122 | rcu_read_unlock(); |
Eric W. Biederman | 8405a8f | 2015-06-19 14:03:39 -0500 | [diff] [blame] | 123 | } |
Florian Westphal | e2a7500 | 2017-07-26 00:02:33 +0200 | [diff] [blame] | 124 | EXPORT_SYMBOL_GPL(nf_queue_nf_hook_drop); |
Eric W. Biederman | 8405a8f | 2015-06-19 14:03:39 -0500 | [diff] [blame] | 125 | |
Pablo Neira Ayuso | 7db9a51 | 2017-12-20 16:12:55 +0100 | [diff] [blame] | 126 | static void nf_ip_saveroute(const struct sk_buff *skb, |
| 127 | struct nf_queue_entry *entry) |
| 128 | { |
| 129 | struct ip_rt_info *rt_info = nf_queue_entry_reroute(entry); |
| 130 | |
| 131 | if (entry->state.hook == NF_INET_LOCAL_OUT) { |
| 132 | const struct iphdr *iph = ip_hdr(skb); |
| 133 | |
| 134 | rt_info->tos = iph->tos; |
| 135 | rt_info->daddr = iph->daddr; |
| 136 | rt_info->saddr = iph->saddr; |
| 137 | rt_info->mark = skb->mark; |
| 138 | } |
| 139 | } |
| 140 | |
| 141 | static void nf_ip6_saveroute(const struct sk_buff *skb, |
| 142 | struct nf_queue_entry *entry) |
| 143 | { |
| 144 | struct ip6_rt_info *rt_info = nf_queue_entry_reroute(entry); |
| 145 | |
| 146 | if (entry->state.hook == NF_INET_LOCAL_OUT) { |
| 147 | const struct ipv6hdr *iph = ipv6_hdr(skb); |
| 148 | |
| 149 | rt_info->daddr = iph->daddr; |
| 150 | rt_info->saddr = iph->saddr; |
| 151 | rt_info->mark = skb->mark; |
| 152 | } |
| 153 | } |
| 154 | |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 155 | static int __nf_queue(struct sk_buff *skb, const struct nf_hook_state *state, |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 156 | unsigned int index, unsigned int queuenum) |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 157 | { |
Patrick McHardy | daaa8be | 2007-12-05 01:27:19 -0800 | [diff] [blame] | 158 | struct nf_queue_entry *entry = NULL; |
Patrick McHardy | e3ac529 | 2007-12-05 01:23:57 -0800 | [diff] [blame] | 159 | const struct nf_queue_handler *qh; |
Eric W. Biederman | dc3ee32 | 2016-05-13 21:18:52 -0500 | [diff] [blame] | 160 | struct net *net = state->net; |
Pablo Neira Ayuso | 4643562 | 2017-11-27 22:58:37 +0100 | [diff] [blame] | 161 | unsigned int route_key_size; |
Florian Westphal | 28f715b | 2020-03-27 03:24:49 +0100 | [diff] [blame] | 162 | int status; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 163 | |
Lucas De Marchi | 25985ed | 2011-03-30 22:57:33 -0300 | [diff] [blame] | 164 | /* QUEUE == DROP if no one is waiting, to be safe. */ |
Eric W. Biederman | dc3ee32 | 2016-05-13 21:18:52 -0500 | [diff] [blame] | 165 | qh = rcu_dereference(net->nf.queue_handler); |
Florian Westphal | 28f715b | 2020-03-27 03:24:49 +0100 | [diff] [blame] | 166 | if (!qh) |
| 167 | return -ESRCH; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 168 | |
Pablo Neira Ayuso | 4643562 | 2017-11-27 22:58:37 +0100 | [diff] [blame] | 169 | switch (state->pf) { |
| 170 | case AF_INET: |
| 171 | route_key_size = sizeof(struct ip_rt_info); |
| 172 | break; |
| 173 | case AF_INET6: |
| 174 | route_key_size = sizeof(struct ip6_rt_info); |
| 175 | break; |
| 176 | default: |
| 177 | route_key_size = 0; |
| 178 | break; |
| 179 | } |
Patrick McHardy | bce8032 | 2006-04-06 14:18:09 -0700 | [diff] [blame] | 180 | |
Pablo Neira Ayuso | 4643562 | 2017-11-27 22:58:37 +0100 | [diff] [blame] | 181 | entry = kmalloc(sizeof(*entry) + route_key_size, GFP_ATOMIC); |
Florian Westphal | 28f715b | 2020-03-27 03:24:49 +0100 | [diff] [blame] | 182 | if (!entry) |
| 183 | return -ENOMEM; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 184 | |
Marco Oliverio | 0b9173f | 2019-12-02 19:54:30 +0100 | [diff] [blame] | 185 | if (skb_dst(skb) && !skb_dst_force(skb)) { |
Florian Westphal | 28f715b | 2020-03-27 03:24:49 +0100 | [diff] [blame] | 186 | kfree(entry); |
| 187 | return -ENETDOWN; |
Florian Westphal | b60a773 | 2019-06-26 20:40:45 +0200 | [diff] [blame] | 188 | } |
| 189 | |
Patrick McHardy | 02f014d | 2007-12-05 01:26:33 -0800 | [diff] [blame] | 190 | *entry = (struct nf_queue_entry) { |
| 191 | .skb = skb, |
David S. Miller | 1d1de89 | 2015-04-03 16:31:01 -0400 | [diff] [blame] | 192 | .state = *state, |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 193 | .hook_index = index, |
Pablo Neira Ayuso | 4643562 | 2017-11-27 22:58:37 +0100 | [diff] [blame] | 194 | .size = sizeof(*entry) + route_key_size, |
Patrick McHardy | 02f014d | 2007-12-05 01:26:33 -0800 | [diff] [blame] | 195 | }; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 196 | |
Florian Westphal | 119e52e | 2020-03-27 03:24:47 +0100 | [diff] [blame] | 197 | __nf_queue_entry_init_physdevs(entry); |
| 198 | |
Florian Westphal | ed78d09 | 2015-10-13 14:33:27 +0200 | [diff] [blame] | 199 | nf_queue_entry_get_refs(entry); |
Pablo Neira Ayuso | 7db9a51 | 2017-12-20 16:12:55 +0100 | [diff] [blame] | 200 | |
| 201 | switch (entry->state.pf) { |
| 202 | case AF_INET: |
| 203 | nf_ip_saveroute(skb, entry); |
| 204 | break; |
| 205 | case AF_INET6: |
| 206 | nf_ip6_saveroute(skb, entry); |
| 207 | break; |
| 208 | } |
| 209 | |
Patrick McHardy | 02f014d | 2007-12-05 01:26:33 -0800 | [diff] [blame] | 210 | status = qh->outfn(entry, queuenum); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 211 | if (status < 0) { |
Florian Westphal | 28f715b | 2020-03-27 03:24:49 +0100 | [diff] [blame] | 212 | nf_queue_entry_free(entry); |
| 213 | return status; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 214 | } |
| 215 | |
Florian Westphal | f158508 | 2011-01-18 15:27:28 +0100 | [diff] [blame] | 216 | return 0; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 217 | } |
| 218 | |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 219 | /* Packets leaving via this function must come back through nf_reinject(). */ |
| 220 | int nf_queue(struct sk_buff *skb, struct nf_hook_state *state, |
Florian Westphal | 0d9cb30 | 2019-07-02 20:41:14 +0200 | [diff] [blame] | 221 | unsigned int index, unsigned int verdict) |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 222 | { |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 223 | int ret; |
| 224 | |
Florian Westphal | 0d9cb30 | 2019-07-02 20:41:14 +0200 | [diff] [blame] | 225 | ret = __nf_queue(skb, state, index, verdict >> NF_VERDICT_QBITS); |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 226 | if (ret < 0) { |
| 227 | if (ret == -ESRCH && |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 228 | (verdict & NF_VERDICT_FLAG_QUEUE_BYPASS)) |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 229 | return 1; |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 230 | kfree_skb(skb); |
| 231 | } |
| 232 | |
| 233 | return 0; |
| 234 | } |
Florian Westphal | 971502d | 2019-04-11 16:36:41 +0200 | [diff] [blame] | 235 | EXPORT_SYMBOL_GPL(nf_queue); |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 236 | |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 237 | static unsigned int nf_iterate(struct sk_buff *skb, |
| 238 | struct nf_hook_state *state, |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 239 | const struct nf_hook_entries *hooks, |
| 240 | unsigned int *index) |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 241 | { |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 242 | const struct nf_hook_entry *hook; |
| 243 | unsigned int verdict, i = *index; |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 244 | |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 245 | while (i < hooks->num_hook_entries) { |
| 246 | hook = &hooks->hooks[i]; |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 247 | repeat: |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 248 | verdict = nf_hook_entry_hookfn(hook, skb, state); |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 249 | if (verdict != NF_ACCEPT) { |
Jagdish Motwani | 946c0d8 | 2019-05-13 23:47:40 +0530 | [diff] [blame] | 250 | *index = i; |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 251 | if (verdict != NF_REPEAT) |
| 252 | return verdict; |
| 253 | goto repeat; |
| 254 | } |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 255 | i++; |
| 256 | } |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 257 | |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 258 | *index = i; |
Pablo Neira Ayuso | 26dfab7 | 2016-11-03 10:56:39 +0100 | [diff] [blame] | 259 | return NF_ACCEPT; |
| 260 | } |
| 261 | |
Florian Westphal | b0f3833 | 2017-12-03 00:58:47 +0100 | [diff] [blame] | 262 | static struct nf_hook_entries *nf_hook_entries_head(const struct net *net, u8 pf, u8 hooknum) |
| 263 | { |
| 264 | switch (pf) { |
Florian Westphal | 2a95183 | 2017-12-07 16:28:26 +0100 | [diff] [blame] | 265 | #ifdef CONFIG_NETFILTER_FAMILY_BRIDGE |
Florian Westphal | b0f3833 | 2017-12-03 00:58:47 +0100 | [diff] [blame] | 266 | case NFPROTO_BRIDGE: |
| 267 | return rcu_dereference(net->nf.hooks_bridge[hooknum]); |
Florian Westphal | 2a95183 | 2017-12-07 16:28:26 +0100 | [diff] [blame] | 268 | #endif |
Florian Westphal | b0f3833 | 2017-12-03 00:58:47 +0100 | [diff] [blame] | 269 | case NFPROTO_IPV4: |
| 270 | return rcu_dereference(net->nf.hooks_ipv4[hooknum]); |
| 271 | case NFPROTO_IPV6: |
| 272 | return rcu_dereference(net->nf.hooks_ipv6[hooknum]); |
| 273 | default: |
| 274 | WARN_ON_ONCE(1); |
| 275 | return NULL; |
| 276 | } |
| 277 | |
| 278 | return NULL; |
| 279 | } |
| 280 | |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 281 | /* Caller must hold rcu read-side lock */ |
Patrick McHardy | 02f014d | 2007-12-05 01:26:33 -0800 | [diff] [blame] | 282 | void nf_reinject(struct nf_queue_entry *entry, unsigned int verdict) |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 283 | { |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 284 | const struct nf_hook_entry *hook_entry; |
| 285 | const struct nf_hook_entries *hooks; |
Patrick McHardy | 02f014d | 2007-12-05 01:26:33 -0800 | [diff] [blame] | 286 | struct sk_buff *skb = entry->skb; |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 287 | const struct net *net; |
| 288 | unsigned int i; |
Florian Westphal | f158508 | 2011-01-18 15:27:28 +0100 | [diff] [blame] | 289 | int err; |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 290 | u8 pf; |
| 291 | |
| 292 | net = entry->state.net; |
| 293 | pf = entry->state.pf; |
| 294 | |
Florian Westphal | b0f3833 | 2017-12-03 00:58:47 +0100 | [diff] [blame] | 295 | hooks = nf_hook_entries_head(net, pf, entry->state.hook); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 296 | |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 297 | i = entry->hook_index; |
Florian Westphal | b0f3833 | 2017-12-03 00:58:47 +0100 | [diff] [blame] | 298 | if (WARN_ON_ONCE(!hooks || i >= hooks->num_hook_entries)) { |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 299 | kfree_skb(skb); |
Florian Westphal | af370ab | 2020-03-27 03:24:48 +0100 | [diff] [blame] | 300 | nf_queue_entry_free(entry); |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 301 | return; |
| 302 | } |
| 303 | |
| 304 | hook_entry = &hooks->hooks[i]; |
| 305 | |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 306 | /* Continue traversal iff userspace said ok... */ |
Florian Westphal | 7ceebfe | 2015-10-09 13:10:37 +0200 | [diff] [blame] | 307 | if (verdict == NF_REPEAT) |
Aaron Conole | 0aa8c57 | 2016-11-15 17:48:44 -0500 | [diff] [blame] | 308 | verdict = nf_hook_entry_hookfn(hook_entry, skb, &entry->state); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 309 | |
| 310 | if (verdict == NF_ACCEPT) { |
Pablo Neira Ayuso | ce388f4 | 2017-11-27 22:50:26 +0100 | [diff] [blame] | 311 | if (nf_reroute(skb, entry) < 0) |
Patrick McHardy | 7a11b98 | 2006-02-27 13:03:24 -0800 | [diff] [blame] | 312 | verdict = NF_DROP; |
| 313 | } |
| 314 | |
| 315 | if (verdict == NF_ACCEPT) { |
Pablo Neira Ayuso | 7034b56 | 2016-10-17 18:05:32 +0100 | [diff] [blame] | 316 | next_hook: |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 317 | ++i; |
| 318 | verdict = nf_iterate(skb, &entry->state, hooks, &i); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 319 | } |
| 320 | |
| 321 | switch (verdict & NF_VERDICT_MASK) { |
| 322 | case NF_ACCEPT: |
Patrick McHardy | 3bc3871 | 2006-07-24 22:52:47 -0700 | [diff] [blame] | 323 | case NF_STOP: |
Patrick McHardy | 4b3d15e | 2007-12-05 01:27:02 -0800 | [diff] [blame] | 324 | local_bh_disable(); |
Eric W. Biederman | 0c4b51f | 2015-09-15 20:04:18 -0500 | [diff] [blame] | 325 | entry->state.okfn(entry->state.net, entry->state.sk, skb); |
Patrick McHardy | 4b3d15e | 2007-12-05 01:27:02 -0800 | [diff] [blame] | 326 | local_bh_enable(); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 327 | break; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 328 | case NF_QUEUE: |
Florian Westphal | 0d9cb30 | 2019-07-02 20:41:14 +0200 | [diff] [blame] | 329 | err = nf_queue(skb, &entry->state, i, verdict); |
Aaron Conole | 960632e | 2017-08-24 00:08:32 +0200 | [diff] [blame] | 330 | if (err == 1) |
| 331 | goto next_hook; |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 332 | break; |
Eric Dumazet | 64507fd | 2010-02-19 15:28:38 +0100 | [diff] [blame] | 333 | case NF_STOLEN: |
Julian Anastasov | fad5444 | 2011-08-05 00:36:28 +0000 | [diff] [blame] | 334 | break; |
Patrick McHardy | 3bc3871 | 2006-07-24 22:52:47 -0700 | [diff] [blame] | 335 | default: |
| 336 | kfree_skb(skb); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 337 | } |
Florian Westphal | 81b4325 | 2015-10-13 14:33:28 +0200 | [diff] [blame] | 338 | |
Florian Westphal | af370ab | 2020-03-27 03:24:48 +0100 | [diff] [blame] | 339 | nf_queue_entry_free(entry); |
Harald Welte | f6ebe77 | 2005-08-09 20:21:49 -0700 | [diff] [blame] | 340 | } |
| 341 | EXPORT_SYMBOL(nf_reinject); |