arpt_mangle.c 2.52 KB
Newer Older
Linus Torvalds's avatar
Linus Torvalds committed
1
2
/* module that allows mangling of the arp payload */
#include <linux/module.h>
3
#include <linux/netfilter.h>
Linus Torvalds's avatar
Linus Torvalds committed
4
5
6
7
8
9
10
11
#include <linux/netfilter_arp/arpt_mangle.h>
#include <net/sock.h>

MODULE_LICENSE("GPL");
MODULE_AUTHOR("Bart De Schuymer <bdschuym@pandora.be>");
MODULE_DESCRIPTION("arptables arp payload mangle target");

static unsigned int
12
target(struct sk_buff *skb,
13
14
       const struct net_device *in, const struct net_device *out,
       unsigned int hooknum, const struct xt_target *target,
15
       const void *targinfo)
Linus Torvalds's avatar
Linus Torvalds committed
16
17
18
19
20
21
{
	const struct arpt_mangle *mangle = targinfo;
	struct arphdr *arp;
	unsigned char *arpptr;
	int pln, hln;

22
	if (!skb_make_writable(skb, skb->len))
23
		return NF_DROP;
Linus Torvalds's avatar
Linus Torvalds committed
24

25
26
	arp = arp_hdr(skb);
	arpptr = skb_network_header(skb) + sizeof(*arp);
Linus Torvalds's avatar
Linus Torvalds committed
27
28
29
30
31
	pln = arp->ar_pln;
	hln = arp->ar_hln;
	/* We assume that pln and hln were checked in the match */
	if (mangle->flags & ARPT_MANGLE_SDEV) {
		if (ARPT_DEV_ADDR_LEN_MAX < hln ||
32
		   (arpptr + hln > skb_tail_pointer(skb)))
Linus Torvalds's avatar
Linus Torvalds committed
33
34
35
36
37
38
			return NF_DROP;
		memcpy(arpptr, mangle->src_devaddr, hln);
	}
	arpptr += hln;
	if (mangle->flags & ARPT_MANGLE_SIP) {
		if (ARPT_MANGLE_ADDR_LEN_MAX < pln ||
39
		   (arpptr + pln > skb_tail_pointer(skb)))
Linus Torvalds's avatar
Linus Torvalds committed
40
41
42
43
44
45
			return NF_DROP;
		memcpy(arpptr, &mangle->u_s.src_ip, pln);
	}
	arpptr += pln;
	if (mangle->flags & ARPT_MANGLE_TDEV) {
		if (ARPT_DEV_ADDR_LEN_MAX < hln ||
46
		   (arpptr + hln > skb_tail_pointer(skb)))
Linus Torvalds's avatar
Linus Torvalds committed
47
48
49
50
51
52
			return NF_DROP;
		memcpy(arpptr, mangle->tgt_devaddr, hln);
	}
	arpptr += hln;
	if (mangle->flags & ARPT_MANGLE_TIP) {
		if (ARPT_MANGLE_ADDR_LEN_MAX < pln ||
53
		   (arpptr + pln > skb_tail_pointer(skb)))
Linus Torvalds's avatar
Linus Torvalds committed
54
55
56
57
58
59
			return NF_DROP;
		memcpy(arpptr, &mangle->u_t.tgt_ip, pln);
	}
	return mangle->target;
}

60
static bool
61
checkentry(const char *tablename, const void *e, const struct xt_target *target,
62
	   void *targinfo, unsigned int hook_mask)
Linus Torvalds's avatar
Linus Torvalds committed
63
64
65
66
67
{
	const struct arpt_mangle *mangle = targinfo;

	if (mangle->flags & ~ARPT_MANGLE_MASK ||
	    !(mangle->flags & ARPT_MANGLE_MASK))
68
		return false;
Linus Torvalds's avatar
Linus Torvalds committed
69
70
71

	if (mangle->target != NF_DROP && mangle->target != NF_ACCEPT &&
	   mangle->target != ARPT_CONTINUE)
72
73
		return false;
	return true;
Linus Torvalds's avatar
Linus Torvalds committed
74
75
}

76
static struct arpt_target arpt_mangle_reg __read_mostly = {
77
78
79
80
81
	.name		= "mangle",
	.target		= target,
	.targetsize	= sizeof(struct arpt_mangle),
	.checkentry	= checkentry,
	.me		= THIS_MODULE,
Linus Torvalds's avatar
Linus Torvalds committed
82
83
};

84
static int __init arpt_mangle_init(void)
Linus Torvalds's avatar
Linus Torvalds committed
85
86
87
88
89
90
91
{
	if (arpt_register_target(&arpt_mangle_reg))
		return -EINVAL;

	return 0;
}

92
static void __exit arpt_mangle_fini(void)
Linus Torvalds's avatar
Linus Torvalds committed
93
94
95
96
{
	arpt_unregister_target(&arpt_mangle_reg);
}

97
98
module_init(arpt_mangle_init);
module_exit(arpt_mangle_fini);