netfilter: nft_exthdr: Allow checking TCP option presence, too
Honor NFT_EXTHDR_F_PRESENT flag so we check if the TCP option is present. Signed-off-by: Phil Sutter <phil@nwl.cc> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
8d70eeb84a
commit
3c1fece881
@ -98,14 +98,21 @@ static void nft_exthdr_tcp_eval(const struct nft_expr *expr,
|
|||||||
goto err;
|
goto err;
|
||||||
|
|
||||||
offset = i + priv->offset;
|
offset = i + priv->offset;
|
||||||
dest[priv->len / NFT_REG32_SIZE] = 0;
|
if (priv->flags & NFT_EXTHDR_F_PRESENT) {
|
||||||
memcpy(dest, opt + offset, priv->len);
|
*dest = 1;
|
||||||
|
} else {
|
||||||
|
dest[priv->len / NFT_REG32_SIZE] = 0;
|
||||||
|
memcpy(dest, opt + offset, priv->len);
|
||||||
|
}
|
||||||
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
err:
|
err:
|
||||||
regs->verdict.code = NFT_BREAK;
|
if (priv->flags & NFT_EXTHDR_F_PRESENT)
|
||||||
|
*dest = 0;
|
||||||
|
else
|
||||||
|
regs->verdict.code = NFT_BREAK;
|
||||||
}
|
}
|
||||||
|
|
||||||
static const struct nla_policy nft_exthdr_policy[NFTA_EXTHDR_MAX + 1] = {
|
static const struct nla_policy nft_exthdr_policy[NFTA_EXTHDR_MAX + 1] = {
|
||||||
|
Loading…
x
Reference in New Issue
Block a user