]>
Commit | Line | Data |
---|---|---|
1 | /* | |
2 | * Filtering ARP tables module. | |
3 | * | |
4 | * Copyright (C) 2002 David S. Miller (davem@redhat.com) | |
5 | * | |
6 | */ | |
7 | ||
8 | #include <linux/module.h> | |
9 | #include <linux/netfilter/x_tables.h> | |
10 | #include <linux/netfilter_arp/arp_tables.h> | |
11 | #include <linux/slab.h> | |
12 | ||
13 | MODULE_LICENSE("GPL"); | |
14 | MODULE_AUTHOR("David S. Miller <davem@redhat.com>"); | |
15 | MODULE_DESCRIPTION("arptables filter table"); | |
16 | ||
17 | #define FILTER_VALID_HOOKS ((1 << NF_ARP_IN) | (1 << NF_ARP_OUT) | \ | |
18 | (1 << NF_ARP_FORWARD)) | |
19 | ||
20 | static const struct xt_table packet_filter = { | |
21 | .name = "filter", | |
22 | .valid_hooks = FILTER_VALID_HOOKS, | |
23 | .me = THIS_MODULE, | |
24 | .af = NFPROTO_ARP, | |
25 | .priority = NF_IP_PRI_FILTER, | |
26 | }; | |
27 | ||
28 | /* The work comes in here from netfilter.c */ | |
29 | static unsigned int | |
30 | arptable_filter_hook(void *priv, struct sk_buff *skb, | |
31 | const struct nf_hook_state *state) | |
32 | { | |
33 | return arpt_do_table(skb, state, state->net->ipv4.arptable_filter); | |
34 | } | |
35 | ||
36 | static struct nf_hook_ops *arpfilter_ops __read_mostly; | |
37 | ||
38 | static int __net_init arptable_filter_net_init(struct net *net) | |
39 | { | |
40 | struct arpt_replace *repl; | |
41 | int err; | |
42 | ||
43 | repl = arpt_alloc_initial_table(&packet_filter); | |
44 | if (repl == NULL) | |
45 | return -ENOMEM; | |
46 | err = arpt_register_table(net, &packet_filter, repl, arpfilter_ops, | |
47 | &net->ipv4.arptable_filter); | |
48 | kfree(repl); | |
49 | return err; | |
50 | } | |
51 | ||
52 | static void __net_exit arptable_filter_net_exit(struct net *net) | |
53 | { | |
54 | arpt_unregister_table(net, net->ipv4.arptable_filter, arpfilter_ops); | |
55 | } | |
56 | ||
57 | static struct pernet_operations arptable_filter_net_ops = { | |
58 | .init = arptable_filter_net_init, | |
59 | .exit = arptable_filter_net_exit, | |
60 | }; | |
61 | ||
62 | static int __init arptable_filter_init(void) | |
63 | { | |
64 | int ret; | |
65 | ||
66 | ret = register_pernet_subsys(&arptable_filter_net_ops); | |
67 | if (ret < 0) | |
68 | return ret; | |
69 | ||
70 | arpfilter_ops = xt_hook_link(&packet_filter, arptable_filter_hook); | |
71 | if (IS_ERR(arpfilter_ops)) { | |
72 | ret = PTR_ERR(arpfilter_ops); | |
73 | goto cleanup_table; | |
74 | } | |
75 | return ret; | |
76 | ||
77 | cleanup_table: | |
78 | unregister_pernet_subsys(&arptable_filter_net_ops); | |
79 | return ret; | |
80 | } | |
81 | ||
82 | static void __exit arptable_filter_fini(void) | |
83 | { | |
84 | xt_hook_unlink(&packet_filter, arpfilter_ops); | |
85 | unregister_pernet_subsys(&arptable_filter_net_ops); | |
86 | } | |
87 | ||
88 | module_init(arptable_filter_init); | |
89 | module_exit(arptable_filter_fini); |