diff options
| author | Julian Elischer <julian@FreeBSD.org> | 1998-05-25 10:37:48 +0000 |
|---|---|---|
| committer | Julian Elischer <julian@FreeBSD.org> | 1998-05-25 10:37:48 +0000 |
| commit | bb60f459a0577f2159b498164b72a36f5e98c3e8 (patch) | |
| tree | 855a17205dc7a0daa31c684dd21d9b21759dfab7 /sys/netinet/ip_fw.c | |
| parent | 6c920910277d960fc34edcc84de1eb1d058dfa6f (diff) | |
Notes
Diffstat (limited to 'sys/netinet/ip_fw.c')
| -rw-r--r-- | sys/netinet/ip_fw.c | 37 |
1 files changed, 36 insertions, 1 deletions
diff --git a/sys/netinet/ip_fw.c b/sys/netinet/ip_fw.c index bcdfda0afb57..112d9ca47c00 100644 --- a/sys/netinet/ip_fw.c +++ b/sys/netinet/ip_fw.c @@ -12,7 +12,7 @@ * * This software is provided ``AS IS'' without any warranties of any kind. * - * $Id: ip_fw.c,v 1.82 1998/04/21 18:54:53 julian Exp $ + * $Id: ip_fw.c,v 1.83 1998/05/19 14:04:29 dg Exp $ */ /* @@ -103,8 +103,13 @@ static ip_fw_chk_t *old_chk_ptr; static ip_fw_ctl_t *old_ctl_ptr; #endif +#ifndef IPFW_DIVERT_RESTART static int ip_fw_chk __P((struct ip **pip, int hlen, struct ifnet *oif, int ignport, struct mbuf **m)); +#else +static int ip_fw_chk __P((struct ip **pip, int hlen, + struct ifnet *oif, int pastrule, struct mbuf **m)); +#endif /* IPFW_DIVERT_RESTART */ static int ip_fw_ctl __P((int stage, struct mbuf **mm)); static char err_prefix[] = "ip_fw_ctl:"; @@ -381,7 +386,11 @@ ipfw_report(struct ip_fw *f, struct ip *ip, * ip Pointer to packet header (struct ip *) * hlen Packet header length * oif Outgoing interface, or NULL if packet is incoming + * #ifndef IPFW_DIVERT_RESTART * ignport Ignore all divert/tee rules to this port (if non-zero) + * #else + * pastrule Skip up to the first rule past this rule number; + * #endif * *m The packet; we set to NULL when/if we nuke it. * * Return value: @@ -393,8 +402,13 @@ ipfw_report(struct ip_fw *f, struct ip *ip, */ static int +#ifndef IPFW_DIVERT_RESTART ip_fw_chk(struct ip **pip, int hlen, struct ifnet *oif, int ignport, struct mbuf **m) +#else +ip_fw_chk(struct ip **pip, int hlen, + struct ifnet *oif, int pastrule, struct mbuf **m) +#endif /* IPFW_DIVERT_RESTART */ { struct ip_fw_chain *chain; struct ip_fw *rule = NULL; @@ -405,8 +419,24 @@ ip_fw_chk(struct ip **pip, int hlen, /* * Go down the chain, looking for enlightment + * #ifdef IPFW_DIVERT_RESTART + * If we've been asked to start at a given rule immediatly, do so. + * #endif */ +#ifndef IPFW_DIVERT_RESTART for (chain=LIST_FIRST(&ip_fw_chain); chain; chain = LIST_NEXT(chain, chain)) { +#else + chain=LIST_FIRST(&ip_fw_chain); + if ( pastrule ) { + if (pastrule >= 65535) + goto dropit; + while (chain && (chain->rule->fw_number <= pastrule)) { + chain = LIST_NEXT(chain, chain); + } + if (! chain) goto dropit; + } + for (; chain; chain = LIST_NEXT(chain, chain)) { +#endif /* IPFW_DIVERT_RESTART */ register struct ip_fw *const f = chain->rule; if (oif) { @@ -556,6 +586,7 @@ bogusfrag: } got_match: +#ifndef IPFW_DIVERT_RESTART /* Ignore divert/tee rule if socket port is "ignport" */ switch (f->fw_flg & IP_FW_F_COMMAND) { case IP_FW_F_DIVERT: @@ -565,6 +596,7 @@ got_match: break; } +#endif /* IPFW_DIVERT_RESTART */ /* Update statistics */ f->fw_pcnt += 1; f->fw_bcnt += ip->ip_len; @@ -581,6 +613,9 @@ got_match: case IP_FW_F_COUNT: continue; case IP_FW_F_DIVERT: +#ifdef IPFW_DIVERT_RESTART + ip_divert_in_cookie = f->fw_number; +#endif /* IPFW_DIVERT_RESTART */ return(f->fw_divert_port); case IP_FW_F_TEE: /* |
