Skip to content
  • Pablo Neira Ayuso's avatar
    netfilter: bridge: add generic packet logger · 960649d1
    Pablo Neira Ayuso authored
    
    
    This adds the generic plain text packet loggger for bridged packets.
    It routes the logging message to the real protocol packet logger.
    I decided not to refactor the ebt_log code for two reasons:
    
    1) The ebt_log output is not consistent with the IPv4 and IPv6
       Netfilter packet loggers. The output is different for no good
       reason and it adds redundant code to handle packet logging.
    
    2) To avoid breaking backward compatibility for applications
       outthere that are parsing the specific ebt_log output, the ebt_log
       output has been left as is. So only nftables will use the new
       consistent logging format for logged bridged packets.
    
    More decisions coming in this patch:
    
    1) This also removes ebt_log as default logger for bridged packets.
       Thus, nf_log_packet() routes packet to this new packet logger
       instead. This doesn't break backward compatibility since
       nf_log_packet() is not used to log packets in plain text format
       from anywhere in the ebtables/netfilter bridge code.
    
    2) The new bridge packet logger also performs a lazy request to
       register the real IPv4, ARP and IPv6 netfilter packet loggers.
       If the real protocol logger is no available (not compiled or the
       module is not available in the system, not packet logging happens.
    
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    960649d1