summaryrefslogtreecommitdiffstats
path: root/net
diff options
context:
space:
mode:
authorArtur Molchanov <arturmolchanov@gmail.com>2016-12-30 19:46:36 +0300
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2017-01-19 20:18:01 +0100
commit259495a0440f6b8025277171d7becb8b92cece82 (patch)
treef5308e31ddcc0e4873275ccf96d79bb1ee2d103c /net
parent6ba35da690f30af09706095b914d8031902fd3e5 (diff)
downloadlinux-stable-259495a0440f6b8025277171d7becb8b92cece82.tar.gz
linux-stable-259495a0440f6b8025277171d7becb8b92cece82.tar.bz2
linux-stable-259495a0440f6b8025277171d7becb8b92cece82.zip
bridge: netfilter: Fix dropping packets that moving through bridge interface
commit 14221cc45caad2fcab3a8543234bb7eda9b540d5 upstream. Problem: br_nf_pre_routing_finish() calls itself instead of br_nf_pre_routing_finish_bridge(). Due to this bug reverse path filter drops packets that go through bridge interface. User impact: Local docker containers with bridge network can not communicate with each other. Fixes: c5136b15ea36 ("netfilter: bridge: add and use br_nf_hook_thresh") Signed-off-by: Artur Molchanov <artur.molchanov@synesis.ru> Acked-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'net')
-rw-r--r--net/bridge/br_netfilter_hooks.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/net/bridge/br_netfilter_hooks.c b/net/bridge/br_netfilter_hooks.c
index 2fe9345c1407..7fbdbae58e65 100644
--- a/net/bridge/br_netfilter_hooks.c
+++ b/net/bridge/br_netfilter_hooks.c
@@ -399,7 +399,7 @@ bridged_dnat:
br_nf_hook_thresh(NF_BR_PRE_ROUTING,
net, sk, skb, skb->dev,
NULL,
- br_nf_pre_routing_finish);
+ br_nf_pre_routing_finish_bridge);
return 0;
}
ether_addr_copy(eth_hdr(skb)->h_dest, dev->dev_addr);