Commit | Line | Data |
---|---|---|
1da177e4 LT |
1 | /* module that allows mangling of the arp payload */ |
2 | #include <linux/module.h> | |
3 | #include <linux/netfilter_arp/arpt_mangle.h> | |
4 | #include <net/sock.h> | |
5 | ||
6 | MODULE_LICENSE("GPL"); | |
7 | MODULE_AUTHOR("Bart De Schuymer <bdschuym@pandora.be>"); | |
8 | MODULE_DESCRIPTION("arptables arp payload mangle target"); | |
9 | ||
10 | static unsigned int | |
11 | target(struct sk_buff **pskb, unsigned int hooknum, const struct net_device *in, | |
12 | const struct net_device *out, const void *targinfo, void *userinfo) | |
13 | { | |
14 | const struct arpt_mangle *mangle = targinfo; | |
15 | struct arphdr *arp; | |
16 | unsigned char *arpptr; | |
17 | int pln, hln; | |
18 | ||
19 | if (skb_shared(*pskb) || skb_cloned(*pskb)) { | |
20 | struct sk_buff *nskb; | |
21 | ||
22 | nskb = skb_copy(*pskb, GFP_ATOMIC); | |
23 | if (!nskb) | |
24 | return NF_DROP; | |
25 | if ((*pskb)->sk) | |
26 | skb_set_owner_w(nskb, (*pskb)->sk); | |
27 | kfree_skb(*pskb); | |
28 | *pskb = nskb; | |
29 | } | |
30 | ||
31 | arp = (*pskb)->nh.arph; | |
32 | arpptr = (*pskb)->nh.raw + sizeof(*arp); | |
33 | pln = arp->ar_pln; | |
34 | hln = arp->ar_hln; | |
35 | /* We assume that pln and hln were checked in the match */ | |
36 | if (mangle->flags & ARPT_MANGLE_SDEV) { | |
37 | if (ARPT_DEV_ADDR_LEN_MAX < hln || | |
38 | (arpptr + hln > (**pskb).tail)) | |
39 | return NF_DROP; | |
40 | memcpy(arpptr, mangle->src_devaddr, hln); | |
41 | } | |
42 | arpptr += hln; | |
43 | if (mangle->flags & ARPT_MANGLE_SIP) { | |
44 | if (ARPT_MANGLE_ADDR_LEN_MAX < pln || | |
45 | (arpptr + pln > (**pskb).tail)) | |
46 | return NF_DROP; | |
47 | memcpy(arpptr, &mangle->u_s.src_ip, pln); | |
48 | } | |
49 | arpptr += pln; | |
50 | if (mangle->flags & ARPT_MANGLE_TDEV) { | |
51 | if (ARPT_DEV_ADDR_LEN_MAX < hln || | |
52 | (arpptr + hln > (**pskb).tail)) | |
53 | return NF_DROP; | |
54 | memcpy(arpptr, mangle->tgt_devaddr, hln); | |
55 | } | |
56 | arpptr += hln; | |
57 | if (mangle->flags & ARPT_MANGLE_TIP) { | |
58 | if (ARPT_MANGLE_ADDR_LEN_MAX < pln || | |
59 | (arpptr + pln > (**pskb).tail)) | |
60 | return NF_DROP; | |
61 | memcpy(arpptr, &mangle->u_t.tgt_ip, pln); | |
62 | } | |
63 | return mangle->target; | |
64 | } | |
65 | ||
66 | static int | |
67 | checkentry(const char *tablename, const struct arpt_entry *e, void *targinfo, | |
68 | unsigned int targinfosize, unsigned int hook_mask) | |
69 | { | |
70 | const struct arpt_mangle *mangle = targinfo; | |
71 | ||
72 | if (mangle->flags & ~ARPT_MANGLE_MASK || | |
73 | !(mangle->flags & ARPT_MANGLE_MASK)) | |
74 | return 0; | |
75 | ||
76 | if (mangle->target != NF_DROP && mangle->target != NF_ACCEPT && | |
77 | mangle->target != ARPT_CONTINUE) | |
78 | return 0; | |
79 | return 1; | |
80 | } | |
81 | ||
82 | static struct arpt_target arpt_mangle_reg | |
83 | = { | |
84 | .name = "mangle", | |
85 | .target = target, | |
86 | .checkentry = checkentry, | |
87 | .me = THIS_MODULE, | |
88 | }; | |
89 | ||
90 | static int __init init(void) | |
91 | { | |
92 | if (arpt_register_target(&arpt_mangle_reg)) | |
93 | return -EINVAL; | |
94 | ||
95 | return 0; | |
96 | } | |
97 | ||
98 | static void __exit fini(void) | |
99 | { | |
100 | arpt_unregister_target(&arpt_mangle_reg); | |
101 | } | |
102 | ||
103 | module_init(init); | |
104 | module_exit(fini); |