Re: [PATCH nf-next 5/7] netfilter: flowtable: store ethertype in flowtable context

Lorenzo Bianconi <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel
Message-ID <anWg7P5MeunmMdnP@lore-desk>
> Add a new field to store the ethertype of the packet, skipping layer 2
> encapsulation. Store the ether_type in the context after parsing the
> layer 2 header for the first time and then use it later on.
> 
> Signed-off-by: Pablo Neira Ayuso <[email protected]>

Acked-by: Lorenzo Bianconi <[email protected]>

> ---
>  net/netfilter/nf_flow_table_ip.c | 47 +++++++++++++++++++-------------
>  1 file changed, 28 insertions(+), 19 deletions(-)
> 
> diff --git a/net/netfilter/nf_flow_table_ip.c b/net/netfilter/nf_flow_table_ip.c
> index ed90809b206e..4437f3a13cb2 100644
> --- a/net/netfilter/nf_flow_table_ip.c
> +++ b/net/netfilter/nf_flow_table_ip.c
> @@ -147,6 +147,7 @@ static bool ip_has_options(unsigned int thoff)
>  
>  struct nf_flowtable_ctx {
>  	const struct net_device	*in;
> +	__be16			ether_type;
>  	u32			offset;
>  	u32			hdrsize;
>  	struct {
> @@ -161,7 +162,6 @@ static void nf_flow_tuple_encap(struct nf_flowtable_ctx *ctx,
>  				struct sk_buff *skb,
>  				struct flow_offload_tuple *tuple)
>  {
> -	__be16 inner_proto = skb->protocol;
>  	struct vlan_ethhdr *veth;
>  	struct pppoe_hdr *phdr;
>  	struct ipv6hdr *ip6h;
> @@ -179,19 +179,17 @@ static void nf_flow_tuple_encap(struct nf_flowtable_ctx *ctx,
>  		veth = (struct vlan_ethhdr *)skb_mac_header(skb);
>  		tuple->encap[i].id = ntohs(veth->h_vlan_TCI);
>  		tuple->encap[i].proto = skb->protocol;
> -		inner_proto = veth->h_vlan_encapsulated_proto;
>  		offset += VLAN_HLEN;
>  		break;
>  	case htons(ETH_P_PPP_SES):
>  		phdr = (struct pppoe_hdr *)skb_network_header(skb);
>  		tuple->encap[i].id = ntohs(phdr->sid);
>  		tuple->encap[i].proto = skb->protocol;
> -		inner_proto = *((__be16 *)(phdr + 1));
>  		offset += PPPOE_SES_HLEN;
>  		break;
>  	}
>  
> -	switch (inner_proto) {
> +	switch (ctx->ether_type) {
>  	case htons(ETH_P_IP):
>  		iph = (struct iphdr *)(skb_network_header(skb) + offset);
>  		if (ctx->tun.inner_proto == IPPROTO_IPIP) {
> @@ -376,10 +374,10 @@ static void nf_flow_ip_tunnel_pop(struct nf_flowtable_ctx *ctx,
>  }
>  
>  static bool nf_flow_skb_encap_protocol(struct nf_flowtable_ctx *ctx,
> -				       struct sk_buff *skb, __be16 proto)
> +				       struct sk_buff *skb)
>  {
> -	__be16 inner_proto = skb->protocol;
>  	struct vlan_ethhdr *veth;
> +	__be16 ether_type;
>  	bool ret = false;
>  
>  	switch (skb->protocol) {
> @@ -388,22 +386,27 @@ static bool nf_flow_skb_encap_protocol(struct nf_flowtable_ctx *ctx,
>  			return false;
>  
>  		veth = (struct vlan_ethhdr *)skb_mac_header(skb);
> -		if (veth->h_vlan_encapsulated_proto == proto) {
> -			ctx->offset += VLAN_HLEN;
> -			inner_proto = proto;
> -			ret = true;
> -		}
> +		ctx->ether_type = veth->h_vlan_encapsulated_proto;
> +		ctx->offset += VLAN_HLEN;
> +		ret = true;
>  		break;
>  	case htons(ETH_P_PPP_SES):
> -		if (nf_flow_pppoe_proto(skb, &inner_proto) &&
> -		    inner_proto == proto) {
> -			ctx->offset += PPPOE_SES_HLEN;
> -			ret = true;
> -		}
> +		if (!nf_flow_pppoe_proto(skb, &ether_type))
> +			return false;
> +
> +		ctx->ether_type = ether_type;
> +		ctx->offset += PPPOE_SES_HLEN;
> +		ret = true;
> +		break;
> +	case htons(ETH_P_IP):
> +	case htons(ETH_P_IPV6):
> +		ctx->ether_type = skb->protocol;
>  		break;
> +	default:
> +		return false;
>  	}
>  
> -	switch (inner_proto) {
> +	switch (ctx->ether_type) {
>  	case htons(ETH_P_IP):
>  		ret = nf_flow_ip4_tunnel_proto(ctx, skb);
>  		break;
> @@ -455,7 +458,10 @@ nf_flow_offload_lookup(struct nf_flowtable_ctx *ctx,
>  {
>  	struct flow_offload_tuple tuple = {};
>  
> -	if (!nf_flow_skb_encap_protocol(ctx, skb, htons(ETH_P_IP)))
> +	if (!nf_flow_skb_encap_protocol(ctx, skb))
> +		return NULL;
> +
> +	if (unlikely(ctx->ether_type != htons(ETH_P_IP)))
>  		return NULL;
>  
>  	if (nf_flow_tuple_ip(ctx, skb, &tuple) < 0)
> @@ -1101,7 +1107,10 @@ nf_flow_offload_ipv6_lookup(struct nf_flowtable_ctx *ctx,
>  {
>  	struct flow_offload_tuple tuple = {};
>  
> -	if (!nf_flow_skb_encap_protocol(ctx, skb, htons(ETH_P_IPV6)))
> +	if (!nf_flow_skb_encap_protocol(ctx, skb))
> +		return NULL;
> +
> +	if (unlikely(ctx->ether_type != htons(ETH_P_IPV6)))
>  		return NULL;
>  
>  	if (nf_flow_tuple_ipv6(ctx, skb, &tuple) < 0)
> -- 
> 2.47.3
>
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQTquNwa3Txd3rGGn7Y6cBh0uS2trAUCanWg7AAKCRA6cBh0uS2t
rMeaAPoDIQGDy/kk8swiUfhibdhBglNMxuVokL7yHTkHComMQQEAiUm2UKxKw2Ws
AMKtcYkHiTk4UPolugS5+TSHJQyVqgM=
=GjS4
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.