Re: [PATCH/RFC net-next 1/2] flow dissector: ND support
From: Simon Horman <hidden>
Date: 2017-03-10 15:20:26
On Fri, Mar 10, 2017 at 03:27:32PM +0100, Jiri Pirko wrote:
Fri, Mar 10, 2017 at 03:19:13PM CET, simon.horman@netronome.com wrote:quoted
On Tue, Feb 21, 2017 at 04:28:10PM +0100, Jiri Pirko wrote:quoted
Thu, Feb 02, 2017 at 11:37:34AM CET, simon.horman@netronome.com wrote:quoted
Allow dissection of Neighbour Discovery target IP, and source and destination link-layer addresses for neighbour solicitation and advertisement messages. Signed-off-by: Simon Horman <redacted> ---[...]quoted
@@ -633,6 +702,18 @@ bool __skb_flow_dissect(const struct sk_buff *skb,FLOW_DISSECTOR_KEY_ICMP, target_container); key_icmp->icmp = skb_flow_get_be16(skb, nhoff, data, hlen); + + if (dissector_uses_key(flow_dissector, FLOW_DISSECTOR_KEY_ND) && + ip_proto == IPPROTO_IPV6 && key_icmp->code == 0 &&IPPROTO_IPV6 say "IPv6-in-IPv4 tunnelling". Please use "NEXTHDR_IPV6" instead.Thanks, will do.quoted
quoted
+ (key_icmp->type == NDISC_NEIGHBOUR_SOLICITATION || + key_icmp->type == NDISC_NEIGHBOUR_ADVERTISEMENT)) { + key_nd = skb_flow_dissector_target(flow_dissector, + FLOW_DISSECTOR_KEY_ND, + target_container); + if (!(skb_flow_dissect_nd(skb, key_nd, data, nhoff, + hlen, ipv6_payload_len))) + goto out_bad; + }You should put this under "switch (ip_proto) {"I see that makes sense in terms of the check against ip_proto. But I added it here to allow checking against key_icmp->code and key_icmp->type as well.Sure. Just add under "switch (ip_proto) {" and call a wrapper nd function from there. In that function, you check dissector_uses_key and other needed things.
Sorry, but I'm still a little unclear on how that interacts with the dissection of key_icmp.