Commit | Line | Data |
---|---|---|
09c434b8 | 1 | // SPDX-License-Identifier: GPL-2.0-only |
1da177e4 LT |
2 | /* |
3 | * ebt_dnat | |
4 | * | |
5 | * Authors: | |
6 | * Bart De Schuymer <bdschuym@pandora.be> | |
7 | * | |
8 | * June, 2002 | |
9 | * | |
10 | */ | |
18219d3f JE |
11 | #include <linux/module.h> |
12 | #include <net/sock.h> | |
cf3cb246 | 13 | #include "../br_private.h" |
2ca7b0ac | 14 | #include <linux/netfilter.h> |
18219d3f | 15 | #include <linux/netfilter/x_tables.h> |
1da177e4 LT |
16 | #include <linux/netfilter_bridge/ebtables.h> |
17 | #include <linux/netfilter_bridge/ebt_nat.h> | |
1da177e4 | 18 | |
2d06d4a5 | 19 | static unsigned int |
4b560b44 | 20 | ebt_dnat_tg(struct sk_buff *skb, const struct xt_action_param *par) |
1da177e4 | 21 | { |
7eb35586 | 22 | const struct ebt_nat_info *info = par->targinfo; |
cf3cb246 | 23 | struct net_device *dev; |
1da177e4 | 24 | |
eb1197bc | 25 | if (!skb_make_writable(skb, 0)) |
1b04ab45 | 26 | return EBT_DROP; |
1da177e4 | 27 | |
04091142 | 28 | ether_addr_copy(eth_hdr(skb)->h_dest, info->mac); |
cf3cb246 LL |
29 | |
30 | if (is_multicast_ether_addr(info->mac)) { | |
31 | if (is_broadcast_ether_addr(info->mac)) | |
32 | skb->pkt_type = PACKET_BROADCAST; | |
33 | else | |
34 | skb->pkt_type = PACKET_MULTICAST; | |
35 | } else { | |
36 | if (xt_hooknum(par) != NF_BR_BROUTING) | |
37 | dev = br_port_get_rcu(xt_in(par))->br->dev; | |
38 | else | |
39 | dev = xt_in(par); | |
40 | ||
41 | if (ether_addr_equal(info->mac, dev->dev_addr)) | |
42 | skb->pkt_type = PACKET_HOST; | |
43 | else | |
44 | skb->pkt_type = PACKET_OTHERHOST; | |
45 | } | |
46 | ||
1da177e4 LT |
47 | return info->target; |
48 | } | |
49 | ||
135367b8 | 50 | static int ebt_dnat_tg_check(const struct xt_tgchk_param *par) |
1da177e4 | 51 | { |
af5d6dc2 JE |
52 | const struct ebt_nat_info *info = par->targinfo; |
53 | unsigned int hook_mask; | |
1da177e4 LT |
54 | |
55 | if (BASE_CHAIN && info->target == EBT_RETURN) | |
d6b00a53 | 56 | return -EINVAL; |
af5d6dc2 JE |
57 | |
58 | hook_mask = par->hook_mask & ~(1 << NF_BR_NUMHOOKS); | |
59 | if ((strcmp(par->table, "nat") != 0 || | |
60 | (hook_mask & ~((1 << NF_BR_PRE_ROUTING) | | |
61 | (1 << NF_BR_LOCAL_OUT)))) && | |
62 | (strcmp(par->table, "broute") != 0 || | |
63 | hook_mask & ~(1 << NF_BR_BROUTING))) | |
d6b00a53 | 64 | return -EINVAL; |
e15b9c50 | 65 | if (ebt_invalid_target(info->target)) |
d6b00a53 JE |
66 | return -EINVAL; |
67 | return 0; | |
1da177e4 LT |
68 | } |
69 | ||
043ef46c JE |
70 | static struct xt_target ebt_dnat_tg_reg __read_mostly = { |
71 | .name = "dnat", | |
001a18d3 JE |
72 | .revision = 0, |
73 | .family = NFPROTO_BRIDGE, | |
f2ff525c JE |
74 | .hooks = (1 << NF_BR_NUMHOOKS) | (1 << NF_BR_PRE_ROUTING) | |
75 | (1 << NF_BR_LOCAL_OUT) | (1 << NF_BR_BROUTING), | |
2d06d4a5 JE |
76 | .target = ebt_dnat_tg, |
77 | .checkentry = ebt_dnat_tg_check, | |
fc0e3df4 | 78 | .targetsize = sizeof(struct ebt_nat_info), |
1da177e4 LT |
79 | .me = THIS_MODULE, |
80 | }; | |
81 | ||
65b4b4e8 | 82 | static int __init ebt_dnat_init(void) |
1da177e4 | 83 | { |
043ef46c | 84 | return xt_register_target(&ebt_dnat_tg_reg); |
1da177e4 LT |
85 | } |
86 | ||
65b4b4e8 | 87 | static void __exit ebt_dnat_fini(void) |
1da177e4 | 88 | { |
043ef46c | 89 | xt_unregister_target(&ebt_dnat_tg_reg); |
1da177e4 LT |
90 | } |
91 | ||
65b4b4e8 AM |
92 | module_init(ebt_dnat_init); |
93 | module_exit(ebt_dnat_fini); | |
f776c4cd | 94 | MODULE_DESCRIPTION("Ebtables: Destination MAC address translation"); |
1da177e4 | 95 | MODULE_LICENSE("GPL"); |