~ [ source navigation ] ~ [ diff markup ] ~ [ identifier search ] ~

TOMOYO Linux Cross Reference
Linux/net/netfilter/nf_conntrack_netbios_ns.c

Version: ~ [ linux-5.8 ] ~ [ linux-5.7.12 ] ~ [ linux-5.6.19 ] ~ [ linux-5.5.19 ] ~ [ linux-5.4.55 ] ~ [ linux-5.3.18 ] ~ [ linux-5.2.21 ] ~ [ linux-5.1.21 ] ~ [ linux-5.0.21 ] ~ [ linux-4.20.17 ] ~ [ linux-4.19.136 ] ~ [ linux-4.18.20 ] ~ [ linux-4.17.19 ] ~ [ linux-4.16.18 ] ~ [ linux-4.15.18 ] ~ [ linux-4.14.191 ] ~ [ linux-4.13.16 ] ~ [ linux-4.12.14 ] ~ [ linux-4.11.12 ] ~ [ linux-4.10.17 ] ~ [ linux-4.9.232 ] ~ [ linux-4.8.17 ] ~ [ linux-4.7.10 ] ~ [ linux-4.6.7 ] ~ [ linux-4.5.7 ] ~ [ linux-4.4.232 ] ~ [ linux-4.3.6 ] ~ [ linux-4.2.8 ] ~ [ linux-4.1.52 ] ~ [ linux-4.0.9 ] ~ [ linux-3.19.8 ] ~ [ linux-3.18.140 ] ~ [ linux-3.17.8 ] ~ [ linux-3.16.85 ] ~ [ linux-3.15.10 ] ~ [ linux-3.14.79 ] ~ [ linux-3.13.11 ] ~ [ linux-3.12.74 ] ~ [ linux-3.11.10 ] ~ [ linux-3.10.108 ] ~ [ linux-2.6.32.71 ] ~ [ linux-2.6.0 ] ~ [ linux-2.4.37.11 ] ~ [ unix-v6-master ] ~ [ ccs-tools-1.8.5 ] ~ [ policy-sample ] ~
Architecture: ~ [ i386 ] ~ [ alpha ] ~ [ m68k ] ~ [ mips ] ~ [ ppc ] ~ [ sparc ] ~ [ sparc64 ] ~

  1 /*
  2  *      NetBIOS name service broadcast connection tracking helper
  3  *
  4  *      (c) 2005 Patrick McHardy <kaber@trash.net>
  5  *
  6  *      This program is free software; you can redistribute it and/or
  7  *      modify it under the terms of the GNU General Public License
  8  *      as published by the Free Software Foundation; either version
  9  *      2 of the License, or (at your option) any later version.
 10  */
 11 /*
 12  *      This helper tracks locally originating NetBIOS name service
 13  *      requests by issuing permanent expectations (valid until
 14  *      timing out) matching all reply connections from the
 15  *      destination network. The only NetBIOS specific thing is
 16  *      actually the port number.
 17  */
 18 #include <linux/kernel.h>
 19 #include <linux/module.h>
 20 #include <linux/init.h>
 21 #include <linux/skbuff.h>
 22 #include <linux/netdevice.h>
 23 #include <linux/inetdevice.h>
 24 #include <linux/if_addr.h>
 25 #include <linux/in.h>
 26 #include <linux/ip.h>
 27 #include <linux/netfilter.h>
 28 #include <net/route.h>
 29 
 30 #include <net/netfilter/nf_conntrack.h>
 31 #include <net/netfilter/nf_conntrack_helper.h>
 32 #include <net/netfilter/nf_conntrack_expect.h>
 33 
 34 #define NMBD_PORT       137
 35 
 36 MODULE_AUTHOR("Patrick McHardy <kaber@trash.net>");
 37 MODULE_DESCRIPTION("NetBIOS name service broadcast connection tracking helper");
 38 MODULE_LICENSE("GPL");
 39 MODULE_ALIAS("ip_conntrack_netbios_ns");
 40 MODULE_ALIAS_NFCT_HELPER("netbios_ns");
 41 
 42 static unsigned int timeout __read_mostly = 3;
 43 module_param(timeout, uint, 0400);
 44 MODULE_PARM_DESC(timeout, "timeout for master connection/replies in seconds");
 45 
 46 static int help(struct sk_buff *skb, unsigned int protoff,
 47                 struct nf_conn *ct, enum ip_conntrack_info ctinfo)
 48 {
 49         struct nf_conntrack_expect *exp;
 50         struct iphdr *iph = ip_hdr(skb);
 51         struct rtable *rt = skb_rtable(skb);
 52         struct in_device *in_dev;
 53         __be32 mask = 0;
 54 
 55         /* we're only interested in locally generated packets */
 56         if (skb->sk == NULL)
 57                 goto out;
 58         if (rt == NULL || !(rt->rt_flags & RTCF_BROADCAST))
 59                 goto out;
 60         if (CTINFO2DIR(ctinfo) != IP_CT_DIR_ORIGINAL)
 61                 goto out;
 62 
 63         rcu_read_lock();
 64         in_dev = __in_dev_get_rcu(rt->u.dst.dev);
 65         if (in_dev != NULL) {
 66                 for_primary_ifa(in_dev) {
 67                         if (ifa->ifa_broadcast == iph->daddr) {
 68                                 mask = ifa->ifa_mask;
 69                                 break;
 70                         }
 71                 } endfor_ifa(in_dev);
 72         }
 73         rcu_read_unlock();
 74 
 75         if (mask == 0)
 76                 goto out;
 77 
 78         exp = nf_ct_expect_alloc(ct);
 79         if (exp == NULL)
 80                 goto out;
 81 
 82         exp->tuple                = ct->tuplehash[IP_CT_DIR_REPLY].tuple;
 83         exp->tuple.src.u.udp.port = htons(NMBD_PORT);
 84 
 85         exp->mask.src.u3.ip       = mask;
 86         exp->mask.src.u.udp.port  = htons(0xFFFF);
 87 
 88         exp->expectfn             = NULL;
 89         exp->flags                = NF_CT_EXPECT_PERMANENT;
 90         exp->class                = NF_CT_EXPECT_CLASS_DEFAULT;
 91         exp->helper               = NULL;
 92 
 93         nf_ct_expect_related(exp);
 94         nf_ct_expect_put(exp);
 95 
 96         nf_ct_refresh(ct, skb, timeout * HZ);
 97 out:
 98         return NF_ACCEPT;
 99 }
100 
101 static struct nf_conntrack_expect_policy exp_policy = {
102         .max_expected   = 1,
103 };
104 
105 static struct nf_conntrack_helper helper __read_mostly = {
106         .name                   = "netbios-ns",
107         .tuple.src.l3num        = AF_INET,
108         .tuple.src.u.udp.port   = cpu_to_be16(NMBD_PORT),
109         .tuple.dst.protonum     = IPPROTO_UDP,
110         .me                     = THIS_MODULE,
111         .help                   = help,
112         .expect_policy          = &exp_policy,
113 };
114 
115 static int __init nf_conntrack_netbios_ns_init(void)
116 {
117         exp_policy.timeout = timeout;
118         return nf_conntrack_helper_register(&helper);
119 }
120 
121 static void __exit nf_conntrack_netbios_ns_fini(void)
122 {
123         nf_conntrack_helper_unregister(&helper);
124 }
125 
126 module_init(nf_conntrack_netbios_ns_init);
127 module_exit(nf_conntrack_netbios_ns_fini);
128 

~ [ source navigation ] ~ [ diff markup ] ~ [ identifier search ] ~

kernel.org | git.kernel.org | LWN.net | Project Home | Wiki (Japanese) | Wiki (English) | SVN repository | Mail admin

Linux® is a registered trademark of Linus Torvalds in the United States and other countries.
TOMOYO® is a registered trademark of NTT DATA CORPORATION.

osdn.jp