Florian Westphal
54b5ab456e
netfilter: bridge: add support for pppoe filtering
...
[ Upstream commit 28b78ecffea8078d81466b2e01bb5a154509f1ba ]
This makes 'bridge-nf-filter-pppoe-tagged' sysctl work for
bridged traffic.
Looking at the original commit it doesn't appear this ever worked:
static unsigned int br_nf_post_routing(unsigned int hook, struct sk_buff **pskb,
[..]
if (skb->protocol == htons(ETH_P_8021Q)) {
skb_pull(skb, VLAN_HLEN);
skb->network_header += VLAN_HLEN;
+ } else if (skb->protocol == htons(ETH_P_PPP_SES)) {
+ skb_pull(skb, PPPOE_SES_HLEN);
+ skb->network_header += PPPOE_SES_HLEN;
}
[..]
NF_HOOK(... POST_ROUTING, ...)
... but the adjusted offsets are never restored.
The alternative would be to rip this code out for good,
but otoh we'd have to keep this anyway for the vlan handling
(which works because vlan tag info is in the skb, not the packet
payload).
Reported-and-tested-by: Amish Chana <amish@3g.co.za>
Fixes: 516299d2f5 ("[NETFILTER]: bridge-nf: filter bridged IPv4/IPv6 encapsulated in pppoe traffic")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-01-27 09:19:31 +01:00
..
6lowpan
6lowpan: iphc: Fix an off-by-one check of array index
2021-09-15 09:47:31 +02:00
9p
9p/net: fix missing error check in p9_check_errors
2021-11-17 09:48:49 +01:00
802
net/802/garp: fix memleak in garp_request_join()
2021-07-31 08:19:38 +02:00
8021q
net: vlan: fix underflow for the real_dev refcnt
2021-12-01 09:23:34 +01:00
appletalk
atm
ax25
ax25: NPD bug when detaching AX25 device
2021-12-29 12:23:38 +01:00
batman-adv
batman-adv: mcast: don't send link-local multicast to mcast routers
2022-01-11 15:23:32 +01:00
bluetooth
Bluetooth: stop proccessing malicious adv data
2022-01-27 09:19:30 +01:00
bpf
bpfilter
bpfilter: Specify the log level for the kmsg message
2021-07-14 16:53:33 +02:00
bridge
netfilter: bridge: add support for pppoe filtering
2022-01-27 09:19:31 +01:00
caif
net-caif: avoid user-triggerable WARN_ON(1)
2021-09-22 12:26:40 +02:00
can
can: j1939: j1939_tp_cmd_recv(): check the dst address of TP.CM_BAM
2021-12-08 09:01:08 +01:00
ceph
core
lwtunnel: Validate RTA_ENCAP_TYPE attribute length
2022-01-11 15:23:32 +01:00
dcb
dccp
dccp: don't duplicate ccid when cloning dccp sock
2021-09-22 12:26:40 +02:00
decnet
net: decnet: Fix sleeping inside in af_decnet
2021-07-28 13:30:56 +02:00
dns_resolver
dsa
net: dsa: destroy the phylink instance on any error in dsa_slave_phy_setup
2021-09-22 12:26:42 +02:00
ethernet
hsr
hsr: use netdev_err() instead of WARN_ONCE()
2021-05-14 09:44:10 +02:00
ieee802154
net: Fix memory leak in ieee802154_raw_deliver
2021-08-18 08:57:00 +02:00
ife
ipv4
net: udp: fix alignment problem in udp4_seq_show()
2022-01-11 15:23:33 +01:00
ipv6
ip6_vti: initialize __ip6_tnl_parm struct in vti6_siocdevprivate
2022-01-11 15:23:33 +01:00
iucv
kcm
key
l2tp
net/l2tp: Fix reference count leak in l2tp_udp_recv_core
2021-09-22 12:26:41 +02:00
l3mdev
lapb
llc
net: llc: fix skb_over_panic
2021-08-04 12:27:39 +02:00
mac80211
mac80211: initialize variable have_higher_than_11mbit
2022-01-11 15:23:31 +01:00
mac802154
mpls
net: mpls: Fix notifications when deleting a device
2021-12-08 09:01:12 +01:00
ncsi
net/ncsi: check for error return from call to nla_put_u32
2022-01-05 12:37:45 +01:00
netfilter
netfilter: fix regression in looped (broad|multi)cast's MAC handling
2021-12-29 12:23:34 +01:00
netlabel
net: fix NULL pointer reference in cipso_v4_doi_free
2021-09-22 12:26:36 +02:00
netlink
net: netlink: af_netlink: Prevent empty skb by adding a check on len.
2021-12-17 10:12:23 +01:00
netrom
netrom: Decrease sock refcount when sock timers expire
2021-07-28 13:30:56 +02:00
nfc
nfc: llcp: fix NULL error pointer dereference on sendmsg() after failed bind()
2022-01-27 09:19:26 +01:00
nsh
openvswitch
ovs: clear skb->tstamp in forwarding path
2021-08-26 08:36:19 -04:00
packet
net/packet: rx_owner_map depends on pg_vec
2021-12-22 09:29:38 +01:00
phonet
phonet: refcount leak in pep_sock_accep
2022-01-11 15:23:33 +01:00
psample
qrtr
net: qrtr: fix another OOB Read in qrtr_endpoint_post
2021-09-03 10:08:12 +02:00
rds
rds: memory leak in __rds_conn_create()
2021-12-22 09:29:37 +01:00
rfkill
rose
rxrpc
rxrpc: Fix rxrpc_local leak in rxrpc_lookup_peer()
2021-12-08 09:01:12 +01:00
sched
sch_qfq: prevent shift-out-of-bounds in qfq_init_qdisc
2022-01-11 15:23:32 +01:00
sctp
sctp: use call_rcu to free endpoint
2022-01-05 12:37:44 +01:00
smc
net/smc: Prevent smc_release() from long blocking
2021-12-22 09:29:38 +01:00
strparser
bpf: sockmap, strparser, and tls are reusing qdisc_skb_cb and colliding
2021-11-17 09:48:48 +01:00
sunrpc
SUNRPC: Partial revert of commit 6f9f17287e78
2021-11-17 09:48:50 +01:00
switchdev
net: switchdev: do not propagate bridge updates across bridges
2021-10-27 09:54:24 +02:00
tipc
tipc: increase timeout in tipc_sk_enqueue()
2021-09-22 12:26:41 +02:00
tls
net/tls: Fix authentication failure in CCM mode
2021-12-08 09:01:14 +01:00
unix
af_unix: fix races in sk_peer_pid and sk_peer_cred accesses
2021-10-06 15:42:35 +02:00
vmw_vsock
vsock: prevent unnecessary refcnt inc for nonblocking connect
2021-11-17 09:48:48 +01:00
wimax
wireless
cfg80211: call cfg80211_stop_ap when switch from P2P_GO type
2021-11-26 10:47:22 +01:00
x25
net/x25: Return the correct errno code
2021-06-18 09:59:00 +02:00
xdp
Revert "xsk: Do not sleep in poll() when need_wakeup set"
2021-12-22 09:29:40 +01:00
xfrm
xfrm: Fix error reporting in xfrm_state_construct.
2021-07-19 08:53:11 +02:00
compat.c
net: Return the correct errno code
2021-06-18 09:59:00 +02:00
Kconfig
Makefile
socket.c
net: don't unconditionally copy_from_user a struct ifreq for socket ioctls
2021-09-03 10:08:16 +02:00
sysctl_net.c