]> git.karo-electronics.de Git - linux-beck.git/commitdiff
netfilter: xt_TRACE: add explicitly nf_logger_find_get call
authorLiping Zhang <liping.zhang@spreadtrum.com>
Wed, 8 Jun 2016 12:43:19 +0000 (20:43 +0800)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 23 Jun 2016 11:26:49 +0000 (13:26 +0200)
Consider such situation, if nf_log_ipv4 kernel module is not installed,
and the user add a following iptables rule:
  # iptables -t raw -I PREROUTING -j TRACE

There will be no trace log generated until the user install nf_log_ipv4
module manully. So we should add request related nf_log module
appropriately here.

Signed-off-by: Liping Zhang <liping.zhang@spreadtrum.com>
Acked-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/xt_TRACE.c

index df48967af38210e766f2bb85568f4d5ddb67bbfa..858d189a130316f603ec519e4be32a0b567ffc28 100644 (file)
@@ -4,12 +4,23 @@
 #include <linux/skbuff.h>
 
 #include <linux/netfilter/x_tables.h>
+#include <net/netfilter/nf_log.h>
 
 MODULE_DESCRIPTION("Xtables: packet flow tracing");
 MODULE_LICENSE("GPL");
 MODULE_ALIAS("ipt_TRACE");
 MODULE_ALIAS("ip6t_TRACE");
 
+static int trace_tg_check(const struct xt_tgchk_param *par)
+{
+       return nf_logger_find_get(par->family, NF_LOG_TYPE_LOG);
+}
+
+static void trace_tg_destroy(const struct xt_tgdtor_param *par)
+{
+       nf_logger_put(par->family, NF_LOG_TYPE_LOG);
+}
+
 static unsigned int
 trace_tg(struct sk_buff *skb, const struct xt_action_param *par)
 {
@@ -18,12 +29,14 @@ trace_tg(struct sk_buff *skb, const struct xt_action_param *par)
 }
 
 static struct xt_target trace_tg_reg __read_mostly = {
-       .name       = "TRACE",
-       .revision   = 0,
-       .family     = NFPROTO_UNSPEC,
-       .table      = "raw",
-       .target     = trace_tg,
-       .me         = THIS_MODULE,
+       .name           = "TRACE",
+       .revision       = 0,
+       .family         = NFPROTO_UNSPEC,
+       .table          = "raw",
+       .target         = trace_tg,
+       .checkentry     = trace_tg_check,
+       .destroy        = trace_tg_destroy,
+       .me             = THIS_MODULE,
 };
 
 static int __init trace_tg_init(void)