summaryrefslogtreecommitdiffstats
path: root/net
diff options
context:
space:
mode:
authorMartin Topholm <mph@one.com>2013-11-14 15:35:31 +0100
committerPablo Neira Ayuso <pablo@netfilter.org>2013-11-18 12:53:38 +0100
commitc1898c4c295b735c05af4c09664993fd8f257c2b (patch)
tree869130e70b5c9b01734bbb3211a4fdb45c8dde9a /net
parenta6441b7a39f18acb68c83cd738f1310881aa8a0b (diff)
downloadlinux-stable-c1898c4c295b735c05af4c09664993fd8f257c2b.tar.gz
linux-stable-c1898c4c295b735c05af4c09664993fd8f257c2b.tar.bz2
linux-stable-c1898c4c295b735c05af4c09664993fd8f257c2b.zip
netfilter: synproxy: correct wscale option passing
Timestamp are used to store additional syncookie parameters such as sack, ecn, and wscale. The wscale value we need to encode is the client's wscale, since we can't recover that later in the session. Next overwrite the wscale option so the later synproxy_send_client_synack will send the backend's wscale to the client. Signed-off-by: Martin Topholm <mph@one.com> Reviewed-by: Jesper Dangaard Brouer <brouer@redhat.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net')
-rw-r--r--net/netfilter/nf_synproxy_core.c7
1 files changed, 4 insertions, 3 deletions
diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index cdf4567ba9b3..9858e3e51a3a 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -151,9 +151,10 @@ void synproxy_init_timestamp_cookie(const struct xt_synproxy_info *info,
opts->tsecr = opts->tsval;
opts->tsval = tcp_time_stamp & ~0x3f;
- if (opts->options & XT_SYNPROXY_OPT_WSCALE)
- opts->tsval |= info->wscale;
- else
+ if (opts->options & XT_SYNPROXY_OPT_WSCALE) {
+ opts->tsval |= opts->wscale;
+ opts->wscale = info->wscale;
+ } else
opts->tsval |= 0xf;
if (opts->options & XT_SYNPROXY_OPT_SACK_PERM)