[PATCH nf-next 2/2] netfilter: nft_payload: access ipip payload for inner offset

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



ipip is an special case, transport and inner header offset are set to
the same offset to use the upcoming inner expression for matching on
inner tunnel headers.

Signed-off-by: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
---
 net/netfilter/nft_payload.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/netfilter/nft_payload.c b/net/netfilter/nft_payload.c
index 81913b74f7c8..47425ccd9fae 100644
--- a/net/netfilter/nft_payload.c
+++ b/net/netfilter/nft_payload.c
@@ -104,6 +104,9 @@ static int __nft_payload_inner_offset(struct nft_pktinfo *pkt)
 	case IPPROTO_GRE:
 		pkt->inneroff = thoff + sizeof(struct gre_base_hdr);
 		break;
+	case IPPROTO_IPIP:
+		pkt->inneroff = thoff;
+		break;
 	default:
 		return -1;
 	}
-- 
2.30.2




[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux