Skip to content

Commit 3c1fece

Browse files
Phil Sutterummakynes
authored andcommitted
netfilter: nft_exthdr: Allow checking TCP option presence, too
Honor NFT_EXTHDR_F_PRESENT flag so we check if the TCP option is present. Signed-off-by: Phil Sutter <phil@nwl.cc> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
1 parent 8d70eeb commit 3c1fece

File tree

1 file changed

+10
-3
lines changed

1 file changed

+10
-3
lines changed

net/netfilter/nft_exthdr.c

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -98,14 +98,21 @@ static void nft_exthdr_tcp_eval(const struct nft_expr *expr,
9898
goto err;
9999

100100
offset = i + priv->offset;
101-
dest[priv->len / NFT_REG32_SIZE] = 0;
102-
memcpy(dest, opt + offset, priv->len);
101+
if (priv->flags & NFT_EXTHDR_F_PRESENT) {
102+
*dest = 1;
103+
} else {
104+
dest[priv->len / NFT_REG32_SIZE] = 0;
105+
memcpy(dest, opt + offset, priv->len);
106+
}
103107

104108
return;
105109
}
106110

107111
err:
108-
regs->verdict.code = NFT_BREAK;
112+
if (priv->flags & NFT_EXTHDR_F_PRESENT)
113+
*dest = 0;
114+
else
115+
regs->verdict.code = NFT_BREAK;
109116
}
110117

111118
static const struct nla_policy nft_exthdr_policy[NFTA_EXTHDR_MAX + 1] = {

0 commit comments

Comments
 (0)