netfilter: nf_nat: Handle routing changes in MASQUERADE target
[deliverable/linux.git] / include / net / netfilter / nf_nat.h
1 #ifndef _NF_NAT_H
2 #define _NF_NAT_H
3 #include <linux/netfilter_ipv4.h>
4 #include <linux/netfilter/nf_nat.h>
5 #include <net/netfilter/nf_conntrack_tuple.h>
6
7 enum nf_nat_manip_type {
8 NF_NAT_MANIP_SRC,
9 NF_NAT_MANIP_DST
10 };
11
12 /* SRC manip occurs POST_ROUTING or LOCAL_IN */
13 #define HOOK2MANIP(hooknum) ((hooknum) != NF_INET_POST_ROUTING && \
14 (hooknum) != NF_INET_LOCAL_IN)
15
16 /* NAT sequence number modifications */
17 struct nf_nat_seq {
18 /* position of the last TCP sequence number modification (if any) */
19 u_int32_t correction_pos;
20
21 /* sequence number offset before and after last modification */
22 int16_t offset_before, offset_after;
23 };
24
25 #include <linux/list.h>
26 #include <linux/netfilter/nf_conntrack_pptp.h>
27 #include <net/netfilter/nf_conntrack_extend.h>
28
29 /* per conntrack: nat application helper private data */
30 union nf_conntrack_nat_help {
31 /* insert nat helper private data here */
32 #if defined(CONFIG_NF_NAT_PPTP) || defined(CONFIG_NF_NAT_PPTP_MODULE)
33 struct nf_nat_pptp nat_pptp_info;
34 #endif
35 };
36
37 struct nf_conn;
38
39 /* The structure embedded in the conntrack structure. */
40 struct nf_conn_nat {
41 struct hlist_node bysource;
42 struct nf_nat_seq seq[IP_CT_DIR_MAX];
43 struct nf_conn *ct;
44 union nf_conntrack_nat_help help;
45 #if defined(CONFIG_IP_NF_TARGET_MASQUERADE) || \
46 defined(CONFIG_IP_NF_TARGET_MASQUERADE_MODULE) || \
47 defined(CONFIG_IP6_NF_TARGET_MASQUERADE) || \
48 defined(CONFIG_IP6_NF_TARGET_MASQUERADE_MODULE)
49 int masq_index;
50 #endif
51 };
52
53 /* Set up the info structure to map into this range. */
54 extern unsigned int nf_nat_setup_info(struct nf_conn *ct,
55 const struct nf_nat_range *range,
56 enum nf_nat_manip_type maniptype);
57
58 /* Is this tuple already taken? (not by us)*/
59 extern int nf_nat_used_tuple(const struct nf_conntrack_tuple *tuple,
60 const struct nf_conn *ignored_conntrack);
61
62 static inline struct nf_conn_nat *nfct_nat(const struct nf_conn *ct)
63 {
64 #if defined(CONFIG_NF_NAT) || defined(CONFIG_NF_NAT_MODULE)
65 return nf_ct_ext_find(ct, NF_CT_EXT_NAT);
66 #else
67 return NULL;
68 #endif
69 }
70
71 static inline bool nf_nat_oif_changed(unsigned int hooknum,
72 enum ip_conntrack_info ctinfo,
73 struct nf_conn_nat *nat,
74 const struct net_device *out)
75 {
76 #if IS_ENABLED(CONFIG_IP_NF_TARGET_MASQUERADE) || \
77 IS_ENABLED(CONFIG_IP6_NF_TARGET_MASQUERADE)
78 return nat->masq_index && hooknum == NF_INET_POST_ROUTING &&
79 CTINFO2DIR(ctinfo) == IP_CT_DIR_ORIGINAL &&
80 nat->masq_index != out->ifindex;
81 #else
82 return false;
83 #endif
84 }
85
86 #endif
This page took 0.037075 seconds and 5 git commands to generate.