netfilter: nft_exthdr: Allow checking TCP option presence, too
Honor NFT_EXTHDR_F_PRESENT flag so we check if the TCP option is present. Signed-off-by: Phil Sutter <phil@nwl.cc> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
8d70eeb84a
commit
3c1fece881
@ -98,13 +98,20 @@ static void nft_exthdr_tcp_eval(const struct nft_expr *expr,
|
|||||||
goto err;
|
goto err;
|
||||||
|
|
||||||
offset = i + priv->offset;
|
offset = i + priv->offset;
|
||||||
|
if (priv->flags & NFT_EXTHDR_F_PRESENT) {
|
||||||
|
*dest = 1;
|
||||||
|
} else {
|
||||||
dest[priv->len / NFT_REG32_SIZE] = 0;
|
dest[priv->len / NFT_REG32_SIZE] = 0;
|
||||||
memcpy(dest, opt + offset, priv->len);
|
memcpy(dest, opt + offset, priv->len);
|
||||||
|
}
|
||||||
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
err:
|
err:
|
||||||
|
if (priv->flags & NFT_EXTHDR_F_PRESENT)
|
||||||
|
*dest = 0;
|
||||||
|
else
|
||||||
regs->verdict.code = NFT_BREAK;
|
regs->verdict.code = NFT_BREAK;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user