瀏覽代碼

[VLAN]: Allow VLAN interface on top of bridge interface

When a VLAN interface is created on top of a bridge interface and 
netfilter is enabled to see the bridged packets, the packets can be 
corrupted when passing through the netfilter code. This is caused by the 
VLAN driver not setting the 'protocol' and 'nh' members of the sk_buff 
structure. In general, this is no problem as the VLAN interface is mostly 
connected to a physical ethernet interface which does not use the 
'protocol' and 'nh' members. For a bridge interface, however, these 
members do matter.

Signed-off-by: Jerome Borsboom <j.borsboom@erasmusmc.nl>
Signed-off-by: David S. Miller <davem@davemloft.net>
Jerome Borsboom 18 年之前
父節點
當前提交
279e172a58
共有 1 個文件被更改,包括 3 次插入0 次删除
  1. 3 0
      net/8021q/vlan_dev.c

+ 3 - 0
net/8021q/vlan_dev.c

@@ -380,6 +380,9 @@ int vlan_dev_hard_header(struct sk_buff *skb, struct net_device *dev,
 		} else {
 		} else {
 			vhdr->h_vlan_encapsulated_proto = htons(len);
 			vhdr->h_vlan_encapsulated_proto = htons(len);
 		}
 		}
+
+		skb->protocol = htons(ETH_P_8021Q);
+		skb->nh.raw = skb->data;
 	}
 	}
 
 
 	/* Before delegating work to the lower layer, enter our MAC-address */
 	/* Before delegating work to the lower layer, enter our MAC-address */