Commit | Line | Data |
---|---|---|
1da177e4 LT |
1 | /* module that allows mangling of the arp payload */ |
2 | #include <linux/module.h> | |
3 | #include <linux/netfilter_arp/arpt_mangle.h> | |
4 | #include <net/sock.h> | |
5 | ||
6 | MODULE_LICENSE("GPL"); | |
7 | MODULE_AUTHOR("Bart De Schuymer <bdschuym@pandora.be>"); | |
8 | MODULE_DESCRIPTION("arptables arp payload mangle target"); | |
9 | ||
10 | static unsigned int | |
2e4e6a17 HW |
11 | target(struct sk_buff **pskb, const struct net_device *in, |
12 | const struct net_device *out, unsigned int hooknum, const void *targinfo, | |
13 | void *userinfo) | |
1da177e4 LT |
14 | { |
15 | const struct arpt_mangle *mangle = targinfo; | |
16 | struct arphdr *arp; | |
17 | unsigned char *arpptr; | |
18 | int pln, hln; | |
19 | ||
20 | if (skb_shared(*pskb) || skb_cloned(*pskb)) { | |
21 | struct sk_buff *nskb; | |
22 | ||
23 | nskb = skb_copy(*pskb, GFP_ATOMIC); | |
24 | if (!nskb) | |
25 | return NF_DROP; | |
26 | if ((*pskb)->sk) | |
27 | skb_set_owner_w(nskb, (*pskb)->sk); | |
28 | kfree_skb(*pskb); | |
29 | *pskb = nskb; | |
30 | } | |
31 | ||
32 | arp = (*pskb)->nh.arph; | |
33 | arpptr = (*pskb)->nh.raw + sizeof(*arp); | |
34 | pln = arp->ar_pln; | |
35 | hln = arp->ar_hln; | |
36 | /* We assume that pln and hln were checked in the match */ | |
37 | if (mangle->flags & ARPT_MANGLE_SDEV) { | |
38 | if (ARPT_DEV_ADDR_LEN_MAX < hln || | |
39 | (arpptr + hln > (**pskb).tail)) | |
40 | return NF_DROP; | |
41 | memcpy(arpptr, mangle->src_devaddr, hln); | |
42 | } | |
43 | arpptr += hln; | |
44 | if (mangle->flags & ARPT_MANGLE_SIP) { | |
45 | if (ARPT_MANGLE_ADDR_LEN_MAX < pln || | |
46 | (arpptr + pln > (**pskb).tail)) | |
47 | return NF_DROP; | |
48 | memcpy(arpptr, &mangle->u_s.src_ip, pln); | |
49 | } | |
50 | arpptr += pln; | |
51 | if (mangle->flags & ARPT_MANGLE_TDEV) { | |
52 | if (ARPT_DEV_ADDR_LEN_MAX < hln || | |
53 | (arpptr + hln > (**pskb).tail)) | |
54 | return NF_DROP; | |
55 | memcpy(arpptr, mangle->tgt_devaddr, hln); | |
56 | } | |
57 | arpptr += hln; | |
58 | if (mangle->flags & ARPT_MANGLE_TIP) { | |
59 | if (ARPT_MANGLE_ADDR_LEN_MAX < pln || | |
60 | (arpptr + pln > (**pskb).tail)) | |
61 | return NF_DROP; | |
62 | memcpy(arpptr, &mangle->u_t.tgt_ip, pln); | |
63 | } | |
64 | return mangle->target; | |
65 | } | |
66 | ||
67 | static int | |
2e4e6a17 | 68 | checkentry(const char *tablename, const void *e, void *targinfo, |
1da177e4 LT |
69 | unsigned int targinfosize, unsigned int hook_mask) |
70 | { | |
71 | const struct arpt_mangle *mangle = targinfo; | |
72 | ||
73 | if (mangle->flags & ~ARPT_MANGLE_MASK || | |
74 | !(mangle->flags & ARPT_MANGLE_MASK)) | |
75 | return 0; | |
76 | ||
77 | if (mangle->target != NF_DROP && mangle->target != NF_ACCEPT && | |
78 | mangle->target != ARPT_CONTINUE) | |
79 | return 0; | |
80 | return 1; | |
81 | } | |
82 | ||
83 | static struct arpt_target arpt_mangle_reg | |
84 | = { | |
85 | .name = "mangle", | |
86 | .target = target, | |
87 | .checkentry = checkentry, | |
88 | .me = THIS_MODULE, | |
89 | }; | |
90 | ||
91 | static int __init init(void) | |
92 | { | |
93 | if (arpt_register_target(&arpt_mangle_reg)) | |
94 | return -EINVAL; | |
95 | ||
96 | return 0; | |
97 | } | |
98 | ||
99 | static void __exit fini(void) | |
100 | { | |
101 | arpt_unregister_target(&arpt_mangle_reg); | |
102 | } | |
103 | ||
104 | module_init(init); | |
105 | module_exit(fini); |