Browse Source

[NETFILTER] nf_conntrack: Add missing code to TCP conntrack module

Looks like the nf_conntrack TCP code was slightly mismerged: it does
not contain an else branch present in the IPv4 version. Let's add that
code and make the testsuite happy.

Signed-off-by: KOVACS Krisztian <hidden@balabit.hu>
Signed-off-by: Harald Welte <laforge@netfilter.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
KOVACS Krisztian 19 years ago
parent
commit
3746a2b140
1 changed files with 6 additions and 0 deletions
  1. 6 0
      net/netfilter/nf_conntrack_proto_tcp.c

+ 6 - 0
net/netfilter/nf_conntrack_proto_tcp.c

@@ -970,6 +970,12 @@ static int tcp_packet(struct nf_conn *conntrack,
 		    		conntrack->timeout.function((unsigned long)
 		    		conntrack->timeout.function((unsigned long)
 		    					    conntrack);
 		    					    conntrack);
 		    	return -NF_REPEAT;
 		    	return -NF_REPEAT;
+		} else {
+			write_unlock_bh(&tcp_lock);
+			if (LOG_INVALID(IPPROTO_TCP))
+				nf_log_packet(pf, 0, skb, NULL, NULL,
+					      NULL, "nf_ct_tcp: invalid SYN");
+			return -NF_ACCEPT;
 		}
 		}
 	case TCP_CONNTRACK_CLOSE:
 	case TCP_CONNTRACK_CLOSE:
 		if (index == TCP_RST_SET
 		if (index == TCP_RST_SET