5 * Bart De Schuymer <bdschuym@pandora.be>
9 * This table lets you choose between routing and bridging for frames
10 * entering on a bridge enslaved nic. This table is traversed before any
11 * other ebtables table. See net/bridge/br_input.c.
14 #include <linux/netfilter_bridge/ebtables.h>
15 #include <linux/module.h>
16 #include <linux/if_bridge.h>
18 /* EBT_ACCEPT means the frame will be bridged
19 * EBT_DROP means the frame will be routed
21 static struct ebt_entries initial_chain
= {
26 static struct ebt_replace_kernel initial_table
=
29 .valid_hooks
= 1 << NF_BR_BROUTING
,
30 .entries_size
= sizeof(struct ebt_entries
),
32 [NF_BR_BROUTING
] = &initial_chain
,
34 .entries
= (char *)&initial_chain
,
37 static int check(const struct ebt_table_info
*info
, unsigned int valid_hooks
)
39 if (valid_hooks
& ~(1 << NF_BR_BROUTING
))
44 static const struct ebt_table broute_table
=
47 .table
= &initial_table
,
48 .valid_hooks
= 1 << NF_BR_BROUTING
,
53 static int ebt_broute(struct sk_buff
*skb
)
57 ret
= ebt_do_table(NF_BR_BROUTING
, skb
, skb
->dev
, NULL
,
58 dev_net(skb
->dev
)->xt
.broute_table
);
60 return 1; /* route it */
61 return 0; /* bridge it */
64 static int __net_init
broute_net_init(struct net
*net
)
66 net
->xt
.broute_table
= ebt_register_table(net
, &broute_table
);
67 if (IS_ERR(net
->xt
.broute_table
))
68 return PTR_ERR(net
->xt
.broute_table
);
72 static void __net_exit
broute_net_exit(struct net
*net
)
74 ebt_unregister_table(net
->xt
.broute_table
);
77 static struct pernet_operations broute_net_ops
= {
78 .init
= broute_net_init
,
79 .exit
= broute_net_exit
,
82 static int __init
ebtable_broute_init(void)
86 ret
= register_pernet_subsys(&broute_net_ops
);
90 rcu_assign_pointer(br_should_route_hook
, ebt_broute
);
94 static void __exit
ebtable_broute_fini(void)
96 rcu_assign_pointer(br_should_route_hook
, NULL
);
98 unregister_pernet_subsys(&broute_net_ops
);
101 module_init(ebtable_broute_init
);
102 module_exit(ebtable_broute_fini
);
103 MODULE_LICENSE("GPL");