On Thu, Mar 13, 2008 at 08:40:07PM -0400, James Snow wrote:
> 
> Also, I took a cue from the IN_LINKLOCAL() macro and added two new
> macros to sys/netinet/in.h to perform checks for the loopback network
> and the "zero" network.  IN_LOOPBACK() and IN_ZERONET(), respectively.

Woops.  I suppose the macros are more useful when they're actually
called.

Attached is a revised patch that performs the check for loopback
addresses less than twice but more than never.


-Snow

diff -ru src/sys/netinet/in.h src.new/sys/netinet/in.h
--- src/sys/netinet/in.h	2007-06-12 16:24:53.000000000 +0000
+++ src.new/sys/netinet/in.h	2008-03-13 10:44:29.000000000 +0000
@@ -379,6 +379,8 @@
 #define	IN_BADCLASS(i)		(((u_int32_t)(i) & 0xf0000000) == 0xf0000000)
 
 #define IN_LINKLOCAL(i)		(((u_int32_t)(i) & 0xffff0000) == 0xa9fe0000)
+#define IN_LOOPBACK(i)		(((u_int32_t)(i) & 0xff000000) == 0x7f000000)
+#define IN_ZERONET(i)		(((u_int32_t)(i) & 0xff000000) == 0)
 
 #define	IN_PRIVATE(i)	((((u_int32_t)(i) & 0xff000000) == 0x0a000000) || \
 			 (((u_int32_t)(i) & 0xfff00000) == 0xac100000) || \
diff -ru src/sys/netinet/ip_icmp.c src.new/sys/netinet/ip_icmp.c
--- src/sys/netinet/ip_icmp.c	2007-10-07 20:44:23.000000000 +0000
+++ src.new/sys/netinet/ip_icmp.c	2008-03-14 00:47:44.000000000 +0000
@@ -622,13 +622,15 @@
 	struct mbuf *opts = 0;
 	int optlen = (ip->ip_hl << 2) - sizeof(struct ip);
 
-	if (!in_canforward(ip->ip_src) &&
-	    ((ntohl(ip->ip_src.s_addr) & IN_CLASSA_NET) !=
-	     (IN_LOOPBACKNET << IN_CLASSA_NSHIFT))) {
+	if (IN_MULTICAST(ntohl(ip->ip_src.s_addr)) ||
+	    IN_EXPERIMENTAL(ntohl(ip->ip_src.s_addr)) ||
+	    IN_LOOPBACK(ntohl(ip->ip_src.s_addr)) ||
+	    IN_ZERONET(ntohl(ip->ip_src.s_addr)) ) {
 		m_freem(m);	/* Bad return address */
 		icmpstat.icps_badaddr++;
 		goto done;	/* Ip_output() will check for broadcast */
 	}
+
 	t = ip->ip_dst;
 	ip->ip_dst = ip->ip_src;
 
_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to