]> git.proxmox.com Git - mirror_ubuntu-zesty-kernel.git/blame - net/ipv4/netfilter/ipt_MARK.c
[NETFILTER]: reduce netfilter sk_buff enlargement
[mirror_ubuntu-zesty-kernel.git] / net / ipv4 / netfilter / ipt_MARK.c
CommitLineData
1da177e4
LT
1/* This is a module which is used for setting the NFMARK field of an skb. */
2
3/* (C) 1999-2001 Marc Boucher <marc@mbsi.ca>
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License version 2 as
7 * published by the Free Software Foundation.
8 */
9
10#include <linux/module.h>
11#include <linux/skbuff.h>
12#include <linux/ip.h>
13#include <net/checksum.h>
14
15#include <linux/netfilter_ipv4/ip_tables.h>
16#include <linux/netfilter_ipv4/ipt_MARK.h>
17
18MODULE_LICENSE("GPL");
19MODULE_AUTHOR("Marc Boucher <marc@mbsi.ca>");
20MODULE_DESCRIPTION("iptables MARK modification module");
21
22static unsigned int
23target_v0(struct sk_buff **pskb,
24 const struct net_device *in,
25 const struct net_device *out,
26 unsigned int hooknum,
27 const void *targinfo,
28 void *userinfo)
29{
30 const struct ipt_mark_target_info *markinfo = targinfo;
31
6869c4d8 32 if((*pskb)->nfmark != markinfo->mark)
1da177e4 33 (*pskb)->nfmark = markinfo->mark;
6869c4d8 34
1da177e4
LT
35 return IPT_CONTINUE;
36}
37
38static unsigned int
39target_v1(struct sk_buff **pskb,
40 const struct net_device *in,
41 const struct net_device *out,
42 unsigned int hooknum,
43 const void *targinfo,
44 void *userinfo)
45{
46 const struct ipt_mark_target_info_v1 *markinfo = targinfo;
47 int mark = 0;
48
49 switch (markinfo->mode) {
50 case IPT_MARK_SET:
51 mark = markinfo->mark;
52 break;
53
54 case IPT_MARK_AND:
55 mark = (*pskb)->nfmark & markinfo->mark;
56 break;
57
58 case IPT_MARK_OR:
59 mark = (*pskb)->nfmark | markinfo->mark;
60 break;
61 }
62
6869c4d8 63 if((*pskb)->nfmark != mark)
1da177e4 64 (*pskb)->nfmark = mark;
6869c4d8 65
1da177e4
LT
66 return IPT_CONTINUE;
67}
68
69
70static int
71checkentry_v0(const char *tablename,
72 const struct ipt_entry *e,
73 void *targinfo,
74 unsigned int targinfosize,
75 unsigned int hook_mask)
76{
bf3a46aa
HW
77 struct ipt_mark_target_info *markinfo = targinfo;
78
1da177e4
LT
79 if (targinfosize != IPT_ALIGN(sizeof(struct ipt_mark_target_info))) {
80 printk(KERN_WARNING "MARK: targinfosize %u != %Zu\n",
81 targinfosize,
82 IPT_ALIGN(sizeof(struct ipt_mark_target_info)));
83 return 0;
84 }
85
86 if (strcmp(tablename, "mangle") != 0) {
87 printk(KERN_WARNING "MARK: can only be called from \"mangle\" table, not \"%s\"\n", tablename);
88 return 0;
89 }
90
bf3a46aa
HW
91 if (markinfo->mark > 0xffffffff) {
92 printk(KERN_WARNING "MARK: Only supports 32bit wide mark\n");
93 return 0;
94 }
95
1da177e4
LT
96 return 1;
97}
98
99static int
100checkentry_v1(const char *tablename,
101 const struct ipt_entry *e,
102 void *targinfo,
103 unsigned int targinfosize,
104 unsigned int hook_mask)
105{
106 struct ipt_mark_target_info_v1 *markinfo = targinfo;
107
108 if (targinfosize != IPT_ALIGN(sizeof(struct ipt_mark_target_info_v1))){
109 printk(KERN_WARNING "MARK: targinfosize %u != %Zu\n",
110 targinfosize,
111 IPT_ALIGN(sizeof(struct ipt_mark_target_info_v1)));
112 return 0;
113 }
114
115 if (strcmp(tablename, "mangle") != 0) {
116 printk(KERN_WARNING "MARK: can only be called from \"mangle\" table, not \"%s\"\n", tablename);
117 return 0;
118 }
119
120 if (markinfo->mode != IPT_MARK_SET
121 && markinfo->mode != IPT_MARK_AND
122 && markinfo->mode != IPT_MARK_OR) {
123 printk(KERN_WARNING "MARK: unknown mode %u\n",
124 markinfo->mode);
125 return 0;
126 }
127
bf3a46aa
HW
128 if (markinfo->mark > 0xffffffff) {
129 printk(KERN_WARNING "MARK: Only supports 32bit wide mark\n");
130 return 0;
131 }
132
1da177e4
LT
133 return 1;
134}
135
136static struct ipt_target ipt_mark_reg_v0 = {
137 .name = "MARK",
138 .target = target_v0,
139 .checkentry = checkentry_v0,
140 .me = THIS_MODULE,
141 .revision = 0,
142};
143
144static struct ipt_target ipt_mark_reg_v1 = {
145 .name = "MARK",
146 .target = target_v1,
147 .checkentry = checkentry_v1,
148 .me = THIS_MODULE,
149 .revision = 1,
150};
151
152static int __init init(void)
153{
154 int err;
155
156 err = ipt_register_target(&ipt_mark_reg_v0);
157 if (!err) {
158 err = ipt_register_target(&ipt_mark_reg_v1);
159 if (err)
160 ipt_unregister_target(&ipt_mark_reg_v0);
161 }
162 return err;
163}
164
165static void __exit fini(void)
166{
167 ipt_unregister_target(&ipt_mark_reg_v0);
168 ipt_unregister_target(&ipt_mark_reg_v1);
169}
170
171module_init(init);
172module_exit(fini);