You've already forked linux-apfs
mirror of
https://github.com/linux-apfs/linux-apfs.git
synced 2026-05-01 15:00:59 -07:00
netfilter: xt_nat: fix incorrect hooks for SNAT and DNAT targets
In (c7232c9 netfilter: add protocol independent NAT core), the
hooks were accidentally modified:
SNAT hooks are POST_ROUTING and LOCAL_IN (before it was LOCAL_OUT).
DNAT hooks are PRE_ROUTING and LOCAL_OUT (before it was LOCAL_IN).
Signed-off-by: Elison Niven <elison.niven@cyberoam.com>
Signed-off-by: Sanket Shah <sanket.shah@cyberoam.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
committed by
Pablo Neira Ayuso
parent
0153d5a810
commit
939ccba437
@@ -111,7 +111,7 @@ static struct xt_target xt_nat_target_reg[] __read_mostly = {
|
|||||||
.family = NFPROTO_IPV4,
|
.family = NFPROTO_IPV4,
|
||||||
.table = "nat",
|
.table = "nat",
|
||||||
.hooks = (1 << NF_INET_POST_ROUTING) |
|
.hooks = (1 << NF_INET_POST_ROUTING) |
|
||||||
(1 << NF_INET_LOCAL_OUT),
|
(1 << NF_INET_LOCAL_IN),
|
||||||
.me = THIS_MODULE,
|
.me = THIS_MODULE,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -123,7 +123,7 @@ static struct xt_target xt_nat_target_reg[] __read_mostly = {
|
|||||||
.family = NFPROTO_IPV4,
|
.family = NFPROTO_IPV4,
|
||||||
.table = "nat",
|
.table = "nat",
|
||||||
.hooks = (1 << NF_INET_PRE_ROUTING) |
|
.hooks = (1 << NF_INET_PRE_ROUTING) |
|
||||||
(1 << NF_INET_LOCAL_IN),
|
(1 << NF_INET_LOCAL_OUT),
|
||||||
.me = THIS_MODULE,
|
.me = THIS_MODULE,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -133,7 +133,7 @@ static struct xt_target xt_nat_target_reg[] __read_mostly = {
|
|||||||
.targetsize = sizeof(struct nf_nat_range),
|
.targetsize = sizeof(struct nf_nat_range),
|
||||||
.table = "nat",
|
.table = "nat",
|
||||||
.hooks = (1 << NF_INET_POST_ROUTING) |
|
.hooks = (1 << NF_INET_POST_ROUTING) |
|
||||||
(1 << NF_INET_LOCAL_OUT),
|
(1 << NF_INET_LOCAL_IN),
|
||||||
.me = THIS_MODULE,
|
.me = THIS_MODULE,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -143,7 +143,7 @@ static struct xt_target xt_nat_target_reg[] __read_mostly = {
|
|||||||
.targetsize = sizeof(struct nf_nat_range),
|
.targetsize = sizeof(struct nf_nat_range),
|
||||||
.table = "nat",
|
.table = "nat",
|
||||||
.hooks = (1 << NF_INET_PRE_ROUTING) |
|
.hooks = (1 << NF_INET_PRE_ROUTING) |
|
||||||
(1 << NF_INET_LOCAL_IN),
|
(1 << NF_INET_LOCAL_OUT),
|
||||||
.me = THIS_MODULE,
|
.me = THIS_MODULE,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user