[NETFILTER]: ip6t_mh: drop piggyback payload packet on MH packets
authorMasahide NAKAMURA <nakam@linux-ipv6.org>
Mon, 12 Feb 2007 19:16:17 +0000 (11:16 -0800)
committerDavid S. Miller <davem@davemloft.net>
Mon, 12 Feb 2007 19:16:17 +0000 (11:16 -0800)
commit138939e0662ccb0e805aefe400bcf9cfcbece8e7
tree9c3ec935238bc2850435230b099c12dfc216f1dc
parent601e68e100b6bf8ba13a32db8faf92d43acaa997
[NETFILTER]: ip6t_mh: drop piggyback payload packet on MH packets

Regarding RFC3775, MH payload proto field should be IPPROTO_NONE. Otherwise
it must be discarded (and the receiver should send ICMP error).

We assume filter should drop such piggyback everytime to disallow slipping
through firewall rules, even the final receiver will discard it.

Signed-off-by: Masahide NAKAMURA <nakam@linux-ipv6.org>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/ipv6/netfilter/ip6t_mh.c