summaryrefslogtreecommitdiffstats
path: root/extensions/libnetfilter_conntrack_icmp.c
diff options
context:
space:
mode:
author/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=pablo/emailAddress=pablo@netfilter.org </C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=pablo/emailAddress=pablo@netfilter.org>2005-12-03 22:50:27 +0000
committer/C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=pablo/emailAddress=pablo@netfilter.org </C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=pablo/emailAddress=pablo@netfilter.org>2005-12-03 22:50:27 +0000
commit25b2d74cebc9680dde4028f2f50aec396b29559e (patch)
tree30c9403c402cc6c4184e8546f1d2b876e84886df /extensions/libnetfilter_conntrack_icmp.c
parentade771be804b64a5d5a5aede5d1a6d4fe6e6a43b (diff)
o Fixed bugs in UDP and SCTP protocol handlers (parse_proto)
o Added the comparison infrastructure for layer-4 protocols o Added libnetfilter_conntrack_[tcp|udp|icmp|sctp].h that contains the protocol flags used by the comparison infrastructure o Added nfct_conntrack_compare to compare two conntracks based on flags o Killed nfct_event_netlink_handler o nfct_event_[conntrack|expect] requires ROOT privileges (reason: netlink multicast) o Bumped version to 0.29
Diffstat (limited to 'extensions/libnetfilter_conntrack_icmp.c')
-rw-r--r--extensions/libnetfilter_conntrack_icmp.c24
1 files changed, 24 insertions, 0 deletions
diff --git a/extensions/libnetfilter_conntrack_icmp.c b/extensions/libnetfilter_conntrack_icmp.c
index a6cfe77..a69f43d 100644
--- a/extensions/libnetfilter_conntrack_icmp.c
+++ b/extensions/libnetfilter_conntrack_icmp.c
@@ -15,6 +15,7 @@
#include <libnetfilter_conntrack/linux_nfnetlink_conntrack.h>
#include <libnetfilter_conntrack/libnetfilter_conntrack.h>
#include <libnetfilter_conntrack/libnetfilter_conntrack_extensions.h>
+#include <libnetfilter_conntrack/libnetfilter_conntrack_icmp.h>
static void parse_proto(struct nfattr *cda[], struct nfct_tuple *tuple)
{
@@ -51,12 +52,35 @@ static int print_proto(char *buf, struct nfct_tuple *t)
ntohs(t->l4src.icmp.id)));
}
+static int compare(struct nfct_conntrack *ct1,
+ struct nfct_conntrack *ct2,
+ unsigned int flags)
+{
+ int ret = 1;
+
+ if (flags & ICMP_TYPE)
+ if (ct1->tuple[NFCT_DIR_ORIGINAL].l4dst.icmp.type !=
+ ct2->tuple[NFCT_DIR_ORIGINAL].l4dst.icmp.type)
+ ret = 0;
+ if (flags & ICMP_CODE)
+ if (ct1->tuple[NFCT_DIR_ORIGINAL].l4dst.icmp.code !=
+ ct2->tuple[NFCT_DIR_ORIGINAL].l4dst.icmp.code)
+ ret = 0;
+ if (flags & ICMP_ID)
+ if (ct1->tuple[NFCT_DIR_REPLY].l4src.icmp.id !=
+ ct2->tuple[NFCT_DIR_REPLY].l4src.icmp.id)
+ ret = 0;
+
+ return ret;
+}
+
static struct nfct_proto icmp = {
.name = "icmp",
.protonum = IPPROTO_ICMP,
.parse_proto = parse_proto,
.build_tuple_proto = build_tuple_proto,
.print_proto = print_proto,
+ .compare = compare,
.version = VERSION
};