netfilter: xtables: remove old comments about reentrancy
Signed-off-by: Jan Engelhardt <jengelh@medozas.de> Signed-off-by: Patrick McHardy <kaber@trash.net>
This commit is contained in:
committed by
Patrick McHardy
parent
cd58bcd978
commit
5b775eb1c0
@@ -434,8 +434,6 @@ ipt_do_table(struct sk_buff *skb,
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Targets which reenter must return
|
|
||||||
abs. verdicts */
|
|
||||||
tgpar.target = t->u.kernel.target;
|
tgpar.target = t->u.kernel.target;
|
||||||
tgpar.targinfo = t->data;
|
tgpar.targinfo = t->data;
|
||||||
|
|
||||||
|
@@ -139,9 +139,6 @@ reject_tg(struct sk_buff *skb, const struct xt_target_param *par)
|
|||||||
{
|
{
|
||||||
const struct ipt_reject_info *reject = par->targinfo;
|
const struct ipt_reject_info *reject = par->targinfo;
|
||||||
|
|
||||||
/* WARNING: This code causes reentry within iptables.
|
|
||||||
This means that the iptables jump stack is now crap. We
|
|
||||||
must return an absolute verdict. --RR */
|
|
||||||
switch (reject->with) {
|
switch (reject->with) {
|
||||||
case IPT_ICMP_NET_UNREACHABLE:
|
case IPT_ICMP_NET_UNREACHABLE:
|
||||||
send_unreach(skb, ICMP_NET_UNREACH);
|
send_unreach(skb, ICMP_NET_UNREACH);
|
||||||
|
@@ -451,8 +451,6 @@ ip6t_do_table(struct sk_buff *skb,
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Targets which reenter must return
|
|
||||||
abs. verdicts */
|
|
||||||
tgpar.target = t->u.kernel.target;
|
tgpar.target = t->u.kernel.target;
|
||||||
tgpar.targinfo = t->data;
|
tgpar.targinfo = t->data;
|
||||||
|
|
||||||
|
@@ -179,9 +179,6 @@ reject_tg6(struct sk_buff *skb, const struct xt_target_param *par)
|
|||||||
struct net *net = dev_net((par->in != NULL) ? par->in : par->out);
|
struct net *net = dev_net((par->in != NULL) ? par->in : par->out);
|
||||||
|
|
||||||
pr_debug("%s: medium point\n", __func__);
|
pr_debug("%s: medium point\n", __func__);
|
||||||
/* WARNING: This code causes reentry within ip6tables.
|
|
||||||
This means that the ip6tables jump stack is now crap. We
|
|
||||||
must return an absolute verdict. --RR */
|
|
||||||
switch (reject->with) {
|
switch (reject->with) {
|
||||||
case IP6T_ICMP6_NO_ROUTE:
|
case IP6T_ICMP6_NO_ROUTE:
|
||||||
send_unreach(net, skb, ICMPV6_NOROUTE, par->hooknum);
|
send_unreach(net, skb, ICMPV6_NOROUTE, par->hooknum);
|
||||||
|
Reference in New Issue
Block a user