[NETFILTER]: bridge netfilter: add deferred output hooks to feature-removal-schedule
Add bridge netfilter deferred output hooks to feature-removal-schedule and disable them by default. Until their removal they will be activated by the physdev match when needed. Signed-off-by: Patrick McHardy <kaber@trash.net> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
committed by
David S. Miller
parent
28658c8967
commit
10ea6ac895
@@ -61,6 +61,9 @@ static int brnf_filter_vlan_tagged = 1;
|
||||
#define brnf_filter_vlan_tagged 1
|
||||
#endif
|
||||
|
||||
int brnf_deferred_hooks;
|
||||
EXPORT_SYMBOL_GPL(brnf_deferred_hooks);
|
||||
|
||||
static __be16 inline vlan_proto(const struct sk_buff *skb)
|
||||
{
|
||||
return vlan_eth_hdr(skb)->h_vlan_encapsulated_proto;
|
||||
@@ -890,6 +893,8 @@ static unsigned int ip_sabotage_out(unsigned int hook, struct sk_buff **pskb,
|
||||
return NF_ACCEPT;
|
||||
else if (ip->version == 6 && !brnf_call_ip6tables)
|
||||
return NF_ACCEPT;
|
||||
else if (!brnf_deferred_hooks)
|
||||
return NF_ACCEPT;
|
||||
#endif
|
||||
if (hook == NF_IP_POST_ROUTING)
|
||||
return NF_ACCEPT;
|
||||
|
Reference in New Issue
Block a user