Skip to content

Commit adf76cf

Browse files
committed
Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/kaber/nf-next-2.6
2 parents 17d0cdf + 24992ea commit adf76cf

40 files changed

+1459
-699
lines changed

include/linux/netfilter/Kbuild

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ header-y += xt_limit.h
3333
header-y += xt_mac.h
3434
header-y += xt_mark.h
3535
header-y += xt_multiport.h
36+
header-y += xt_osf.h
3637
header-y += xt_owner.h
3738
header-y += xt_pkttype.h
3839
header-y += xt_quota.h

include/linux/netfilter/nf_conntrack_common.h

Lines changed: 0 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -75,75 +75,6 @@ enum ip_conntrack_status {
7575
IPS_FIXED_TIMEOUT = (1 << IPS_FIXED_TIMEOUT_BIT),
7676
};
7777

78-
/* Connection tracking event bits */
79-
enum ip_conntrack_events
80-
{
81-
/* New conntrack */
82-
IPCT_NEW_BIT = 0,
83-
IPCT_NEW = (1 << IPCT_NEW_BIT),
84-
85-
/* Expected connection */
86-
IPCT_RELATED_BIT = 1,
87-
IPCT_RELATED = (1 << IPCT_RELATED_BIT),
88-
89-
/* Destroyed conntrack */
90-
IPCT_DESTROY_BIT = 2,
91-
IPCT_DESTROY = (1 << IPCT_DESTROY_BIT),
92-
93-
/* Timer has been refreshed */
94-
IPCT_REFRESH_BIT = 3,
95-
IPCT_REFRESH = (1 << IPCT_REFRESH_BIT),
96-
97-
/* Status has changed */
98-
IPCT_STATUS_BIT = 4,
99-
IPCT_STATUS = (1 << IPCT_STATUS_BIT),
100-
101-
/* Update of protocol info */
102-
IPCT_PROTOINFO_BIT = 5,
103-
IPCT_PROTOINFO = (1 << IPCT_PROTOINFO_BIT),
104-
105-
/* Volatile protocol info */
106-
IPCT_PROTOINFO_VOLATILE_BIT = 6,
107-
IPCT_PROTOINFO_VOLATILE = (1 << IPCT_PROTOINFO_VOLATILE_BIT),
108-
109-
/* New helper for conntrack */
110-
IPCT_HELPER_BIT = 7,
111-
IPCT_HELPER = (1 << IPCT_HELPER_BIT),
112-
113-
/* Update of helper info */
114-
IPCT_HELPINFO_BIT = 8,
115-
IPCT_HELPINFO = (1 << IPCT_HELPINFO_BIT),
116-
117-
/* Volatile helper info */
118-
IPCT_HELPINFO_VOLATILE_BIT = 9,
119-
IPCT_HELPINFO_VOLATILE = (1 << IPCT_HELPINFO_VOLATILE_BIT),
120-
121-
/* NAT info */
122-
IPCT_NATINFO_BIT = 10,
123-
IPCT_NATINFO = (1 << IPCT_NATINFO_BIT),
124-
125-
/* Counter highest bit has been set, unused */
126-
IPCT_COUNTER_FILLING_BIT = 11,
127-
IPCT_COUNTER_FILLING = (1 << IPCT_COUNTER_FILLING_BIT),
128-
129-
/* Mark is set */
130-
IPCT_MARK_BIT = 12,
131-
IPCT_MARK = (1 << IPCT_MARK_BIT),
132-
133-
/* NAT sequence adjustment */
134-
IPCT_NATSEQADJ_BIT = 13,
135-
IPCT_NATSEQADJ = (1 << IPCT_NATSEQADJ_BIT),
136-
137-
/* Secmark is set */
138-
IPCT_SECMARK_BIT = 14,
139-
IPCT_SECMARK = (1 << IPCT_SECMARK_BIT),
140-
};
141-
142-
enum ip_conntrack_expect_events {
143-
IPEXP_NEW_BIT = 0,
144-
IPEXP_NEW = (1 << IPEXP_NEW_BIT),
145-
};
146-
14778
#ifdef __KERNEL__
14879
struct ip_conntrack_stat
14980
{

include/linux/netfilter/nf_conntrack_tcp.h

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,8 @@ enum tcp_conntrack {
1515
TCP_CONNTRACK_LAST_ACK,
1616
TCP_CONNTRACK_TIME_WAIT,
1717
TCP_CONNTRACK_CLOSE,
18-
TCP_CONNTRACK_LISTEN,
18+
TCP_CONNTRACK_LISTEN, /* obsolete */
19+
#define TCP_CONNTRACK_SYN_SENT2 TCP_CONNTRACK_LISTEN
1920
TCP_CONNTRACK_MAX,
2021
TCP_CONNTRACK_IGNORE
2122
};

include/linux/netfilter/nfnetlink.h

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,8 @@ struct nfgenmsg {
4646
#define NFNL_SUBSYS_CTNETLINK_EXP 2
4747
#define NFNL_SUBSYS_QUEUE 3
4848
#define NFNL_SUBSYS_ULOG 4
49-
#define NFNL_SUBSYS_COUNT 5
49+
#define NFNL_SUBSYS_OSF 5
50+
#define NFNL_SUBSYS_COUNT 6
5051

5152
#ifdef __KERNEL__
5253

@@ -75,7 +76,7 @@ extern int nfnetlink_subsys_unregister(const struct nfnetlink_subsystem *n);
7576

7677
extern int nfnetlink_has_listeners(unsigned int group);
7778
extern int nfnetlink_send(struct sk_buff *skb, u32 pid, unsigned group,
78-
int echo);
79+
int echo, gfp_t flags);
7980
extern void nfnetlink_set_err(u32 pid, u32 group, int error);
8081
extern int nfnetlink_unicast(struct sk_buff *skb, u_int32_t pid, int flags);
8182

include/linux/netfilter/nfnetlink_conntrack.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,7 @@ enum ctattr_protoinfo_dccp {
101101
CTA_PROTOINFO_DCCP_UNSPEC,
102102
CTA_PROTOINFO_DCCP_STATE,
103103
CTA_PROTOINFO_DCCP_ROLE,
104+
CTA_PROTOINFO_DCCP_HANDSHAKE_SEQ,
104105
__CTA_PROTOINFO_DCCP_MAX,
105106
};
106107
#define CTA_PROTOINFO_DCCP_MAX (__CTA_PROTOINFO_DCCP_MAX - 1)

include/linux/netfilter/x_tables.h

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -184,18 +184,20 @@ struct xt_counters_info
184184
* @matchinfo: per-match data
185185
* @fragoff: packet is a fragment, this is the data offset
186186
* @thoff: position of transport header relative to skb->data
187-
* @hotdrop: drop packet if we had inspection problems
187+
* @hook: hook number given packet came from
188188
* @family: Actual NFPROTO_* through which the function is invoked
189189
* (helpful when match->family == NFPROTO_UNSPEC)
190+
* @hotdrop: drop packet if we had inspection problems
190191
*/
191192
struct xt_match_param {
192193
const struct net_device *in, *out;
193194
const struct xt_match *match;
194195
const void *matchinfo;
195196
int fragoff;
196197
unsigned int thoff;
197-
bool *hotdrop;
198+
unsigned int hooknum;
198199
u_int8_t family;
200+
bool *hotdrop;
199201
};
200202

201203
/**

include/linux/netfilter/xt_NFQUEUE.h

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,4 +15,9 @@ struct xt_NFQ_info {
1515
__u16 queuenum;
1616
};
1717

18+
struct xt_NFQ_info_v1 {
19+
__u16 queuenum;
20+
__u16 queues_total;
21+
};
22+
1823
#endif /* _XT_NFQ_TARGET_H */

include/linux/netfilter/xt_osf.h

Lines changed: 133 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,133 @@
1+
/*
2+
* Copyright (c) 2003+ Evgeniy Polyakov <johnpol@2ka.mxt.ru>
3+
*
4+
*
5+
* This program is free software; you can redistribute it and/or modify
6+
* it under the terms of the GNU General Public License as published by
7+
* the Free Software Foundation; either version 2 of the License, or
8+
* (at your option) any later version.
9+
*
10+
* This program is distributed in the hope that it will be useful,
11+
* but WITHOUT ANY WARRANTY; without even the implied warranty of
12+
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13+
* GNU General Public License for more details.
14+
*
15+
* You should have received a copy of the GNU General Public License
16+
* along with this program; if not, write to the Free Software
17+
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
18+
*/
19+
20+
#ifndef _XT_OSF_H
21+
#define _XT_OSF_H
22+
23+
#define MAXGENRELEN 32
24+
25+
#define XT_OSF_GENRE (1<<0)
26+
#define XT_OSF_TTL (1<<1)
27+
#define XT_OSF_LOG (1<<2)
28+
#define XT_OSF_INVERT (1<<3)
29+
30+
#define XT_OSF_LOGLEVEL_ALL 0 /* log all matched fingerprints */
31+
#define XT_OSF_LOGLEVEL_FIRST 1 /* log only the first matced fingerprint */
32+
#define XT_OSF_LOGLEVEL_ALL_KNOWN 2 /* do not log unknown packets */
33+
34+
#define XT_OSF_TTL_TRUE 0 /* True ip and fingerprint TTL comparison */
35+
#define XT_OSF_TTL_LESS 1 /* Check if ip TTL is less than fingerprint one */
36+
#define XT_OSF_TTL_NOCHECK 2 /* Do not compare ip and fingerprint TTL at all */
37+
38+
struct xt_osf_info {
39+
char genre[MAXGENRELEN];
40+
__u32 len;
41+
__u32 flags;
42+
__u32 loglevel;
43+
__u32 ttl;
44+
};
45+
46+
/*
47+
* Wildcard MSS (kind of).
48+
* It is used to implement a state machine for the different wildcard values
49+
* of the MSS and window sizes.
50+
*/
51+
struct xt_osf_wc {
52+
__u32 wc;
53+
__u32 val;
54+
};
55+
56+
/*
57+
* This struct represents IANA options
58+
* http://www.iana.org/assignments/tcp-parameters
59+
*/
60+
struct xt_osf_opt {
61+
__u16 kind, length;
62+
struct xt_osf_wc wc;
63+
};
64+
65+
struct xt_osf_user_finger {
66+
struct xt_osf_wc wss;
67+
68+
__u8 ttl, df;
69+
__u16 ss, mss;
70+
__u16 opt_num;
71+
72+
char genre[MAXGENRELEN];
73+
char version[MAXGENRELEN];
74+
char subtype[MAXGENRELEN];
75+
76+
/* MAX_IPOPTLEN is maximum if all options are NOPs or EOLs */
77+
struct xt_osf_opt opt[MAX_IPOPTLEN];
78+
};
79+
80+
struct xt_osf_nlmsg {
81+
struct xt_osf_user_finger f;
82+
struct iphdr ip;
83+
struct tcphdr tcp;
84+
};
85+
86+
/* Defines for IANA option kinds */
87+
88+
enum iana_options {
89+
OSFOPT_EOL = 0, /* End of options */
90+
OSFOPT_NOP, /* NOP */
91+
OSFOPT_MSS, /* Maximum segment size */
92+
OSFOPT_WSO, /* Window scale option */
93+
OSFOPT_SACKP, /* SACK permitted */
94+
OSFOPT_SACK, /* SACK */
95+
OSFOPT_ECHO,
96+
OSFOPT_ECHOREPLY,
97+
OSFOPT_TS, /* Timestamp option */
98+
OSFOPT_POCP, /* Partial Order Connection Permitted */
99+
OSFOPT_POSP, /* Partial Order Service Profile */
100+
101+
/* Others are not used in the current OSF */
102+
OSFOPT_EMPTY = 255,
103+
};
104+
105+
/*
106+
* Initial window size option state machine: multiple of mss, mtu or
107+
* plain numeric value. Can also be made as plain numeric value which
108+
* is not a multiple of specified value.
109+
*/
110+
enum xt_osf_window_size_options {
111+
OSF_WSS_PLAIN = 0,
112+
OSF_WSS_MSS,
113+
OSF_WSS_MTU,
114+
OSF_WSS_MODULO,
115+
OSF_WSS_MAX,
116+
};
117+
118+
/*
119+
* Add/remove fingerprint from the kernel.
120+
*/
121+
enum xt_osf_msg_types {
122+
OSF_MSG_ADD,
123+
OSF_MSG_REMOVE,
124+
OSF_MSG_MAX,
125+
};
126+
127+
enum xt_osf_attr_type {
128+
OSF_ATTR_UNSPEC,
129+
OSF_ATTR_FINGER,
130+
OSF_ATTR_MAX,
131+
};
132+
133+
#endif /* _XT_OSF_H */
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
#ifndef _XT_SOCKET_H
2+
#define _XT_SOCKET_H
3+
4+
enum {
5+
XT_SOCKET_TRANSPARENT = 1 << 0,
6+
};
7+
8+
struct xt_socket_mtinfo1 {
9+
__u8 flags;
10+
};
11+
12+
#endif /* _XT_SOCKET_H */

include/net/netfilter/ipv4/nf_conntrack_icmp.h

Lines changed: 0 additions & 11 deletions
This file was deleted.

0 commit comments

Comments
 (0)