]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: nf_conntrack_bridge: register inet conntrack for bridge
authorPablo Neira Ayuso <pablo@netfilter.org>
Wed, 29 May 2019 11:25:39 +0000 (13:25 +0200)
committerDavid S. Miller <davem@davemloft.net>
Thu, 30 May 2019 21:18:18 +0000 (14:18 -0700)
commit9b5f2bb10ff5c716c01be718955b9d3c0a1d37ca
treeca54f38639e9f82bfd03b997ba4431884eeae790
parente96e04f5f6cfb7f97f8982f75ff8f495368b1268
netfilter: nf_conntrack_bridge: register inet conntrack for bridge

This patch enables IPv4 and IPv6 conntrack from the bridge to deal with
local traffic. Hence, packets that are passed up to the local input path
are confirmed later on from the {ipv4,ipv6}_confirm() hooks.

For packets leaving the IP stack (ie. output path), fragmentation occurs
after the inet postrouting hook. Therefore, the bridge local out and
postrouting bridge hooks see fragments with conntrack objects, which is
inconsistent. In this case, we could defragment again from the bridge
output hook, but this is expensive. The recommended filtering spot for
outgoing locally generated traffic leaving through the bridge interface
is to use the classic IPv4/IPv6 output hook, which comes earlier.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/netfilter/nf_conntrack_proto.c