netfilter: synproxy: use nf_cookie_v6_check() from core
This helper function is never used and it is intended to avoid a direct
dependency with the ipv6 module.
Fixes: d7f9b2f18e
("netfilter: synproxy: extract SYNPROXY infrastructure from {ipt, ip6t}_SYNPROXY")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
Родитель
8527fa6cc6
Коммит
22f2efd337
|
@ -1056,7 +1056,7 @@ synproxy_recv_client_ack_ipv6(struct net *net,
|
||||||
struct synproxy_net *snet = synproxy_pernet(net);
|
struct synproxy_net *snet = synproxy_pernet(net);
|
||||||
int mss;
|
int mss;
|
||||||
|
|
||||||
mss = __cookie_v6_check(ipv6_hdr(skb), th, ntohl(th->ack_seq) - 1);
|
mss = nf_cookie_v6_check(ipv6_hdr(skb), th, ntohl(th->ack_seq) - 1);
|
||||||
if (mss == 0) {
|
if (mss == 0) {
|
||||||
this_cpu_inc(snet->stats->cookie_invalid);
|
this_cpu_inc(snet->stats->cookie_invalid);
|
||||||
return false;
|
return false;
|
||||||
|
|
Загрузка…
Ссылка в новой задаче