Home
last modified time | relevance | path

Searched refs:verdict (Results 1 – 25 of 73) sorted by relevance

123

/Linux-v5.4/net/netfilter/
Dnf_queue.c231 unsigned int index, unsigned int verdict) in nf_queue() argument
235 ret = __nf_queue(skb, state, index, verdict >> NF_VERDICT_QBITS); in nf_queue()
238 (verdict & NF_VERDICT_FLAG_QUEUE_BYPASS)) in nf_queue()
253 unsigned int verdict, i = *index; in nf_iterate() local
258 verdict = nf_hook_entry_hookfn(hook, skb, state); in nf_iterate()
259 if (verdict != NF_ACCEPT) { in nf_iterate()
261 if (verdict != NF_REPEAT) in nf_iterate()
262 return verdict; in nf_iterate()
292 void nf_reinject(struct nf_queue_entry *entry, unsigned int verdict) in nf_reinject() argument
319 if (verdict == NF_REPEAT) in nf_reinject()
[all …]
Dnft_fwd_netdev.c32 regs->verdict.code = NF_STOLEN; in nft_fwd_netdev_eval()
90 unsigned int verdict = NF_STOLEN; in nft_fwd_neigh_eval() local
100 verdict = NFT_BREAK; in nft_fwd_neigh_eval()
104 verdict = NF_DROP; in nft_fwd_neigh_eval()
116 verdict = NFT_BREAK; in nft_fwd_neigh_eval()
120 verdict = NF_DROP; in nft_fwd_neigh_eval()
129 verdict = NFT_BREAK; in nft_fwd_neigh_eval()
140 regs->verdict.code = verdict; in nft_fwd_neigh_eval()
Dnf_tables_core.c58 regs->verdict.code = NFT_BREAK; in nft_cmp_fast_eval()
164 nft_trace_init(&info, pkt, &regs.verdict, basechain); in nft_do_chain()
173 regs.verdict.code = NFT_CONTINUE; in nft_do_chain()
183 if (regs.verdict.code != NFT_CONTINUE) in nft_do_chain()
187 switch (regs.verdict.code) { in nft_do_chain()
189 regs.verdict.code = NFT_CONTINUE; in nft_do_chain()
199 switch (regs.verdict.code & NF_VERDICT_MASK) { in nft_do_chain()
206 return regs.verdict.code; in nft_do_chain()
209 switch (regs.verdict.code) { in nft_do_chain()
221 chain = regs.verdict.chain; in nft_do_chain()
Dnft_synproxy.c61 regs->verdict.code = NF_STOLEN; in nft_synproxy_eval_v4()
67 regs->verdict.code = NF_STOLEN; in nft_synproxy_eval_v4()
69 regs->verdict.code = NF_DROP; in nft_synproxy_eval_v4()
92 regs->verdict.code = NF_STOLEN; in nft_synproxy_eval_v6()
98 regs->verdict.code = NF_STOLEN; in nft_synproxy_eval_v6()
100 regs->verdict.code = NF_DROP; in nft_synproxy_eval_v6()
117 regs->verdict.code = NFT_BREAK; in nft_synproxy_do_eval()
122 regs->verdict.code = NF_DROP; in nft_synproxy_do_eval()
130 regs->verdict.code = NF_DROP; in nft_synproxy_do_eval()
135 regs->verdict.code = NF_DROP; in nft_synproxy_do_eval()
[all …]
Dnf_tables_trace.c154 info->verdict->code == NFT_CONTINUE) in nf_trace_fill_rule_info()
172 switch (info->verdict->code) { in nft_trace_have_verdict_chain()
215 size += nla_total_size(strlen(info->verdict->chain->name)); /* jump target */ in nft_trace_notify()
255 if (nft_verdict_dump(skb, NFTA_TRACE_VERDICT, info->verdict)) in nft_trace_notify()
288 const struct nft_verdict *verdict, in nft_trace_init() argument
295 info->verdict = verdict; in nft_trace_init()
Dnft_socket.c41 regs->verdict.code = NFT_BREAK; in nft_socket_eval()
46 regs->verdict.code = NFT_BREAK; in nft_socket_eval()
58 regs->verdict.code = NFT_BREAK; in nft_socket_eval()
64 regs->verdict.code = NFT_BREAK; in nft_socket_eval()
Dnft_xfrm.c126 regs->verdict.code = NFT_BREAK; in nft_xfrm_state_get_key()
155 regs->verdict.code = NFT_BREAK; in nft_xfrm_state_get_key()
166 regs->verdict.code = NFT_BREAK; in nft_xfrm_get_eval_in()
190 regs->verdict.code = NFT_BREAK; in nft_xfrm_get_eval_out()
208 regs->verdict.code = NFT_BREAK; in nft_xfrm_get_eval()
Dnft_tproxy.c35 regs->verdict.code = NFT_BREAK; in nft_tproxy_eval_v4()
74 regs->verdict.code = NFT_BREAK; in nft_tproxy_eval_v4()
95 regs->verdict.code = NFT_BREAK; in nft_tproxy_eval_v6()
102 regs->verdict.code = NFT_BREAK; in nft_tproxy_eval_v6()
146 regs->verdict.code = NFT_BREAK; in nft_tproxy_eval_v6()
175 regs->verdict.code = NFT_BREAK; in nft_tproxy_eval()
Dnfnetlink_queue.c226 static void nfqnl_reinject(struct nf_queue_entry *entry, unsigned int verdict) in nfqnl_reinject() argument
231 if (verdict == NF_ACCEPT || in nfqnl_reinject()
232 verdict == NF_REPEAT || in nfqnl_reinject()
233 verdict == NF_STOP) { in nfqnl_reinject()
239 verdict = NF_DROP; in nfqnl_reinject()
243 nf_reinject(entry, verdict); in nfqnl_reinject()
1042 unsigned int verdict; in verdicthdr_get() local
1048 verdict = ntohl(vhdr->verdict) & NF_VERDICT_MASK; in verdicthdr_get()
1049 if (verdict > NF_MAX_VERDICT || verdict == NF_STOLEN) in verdicthdr_get()
1067 unsigned int verdict, maxid; in nfqnl_recv_verdict_batch() local
[all …]
Dnft_immediate.c112 switch (data->verdict.code) { in nft_immediate_validate()
116 err = nft_chain_validate(ctx, data->verdict.chain); in nft_immediate_validate()
138 switch (data->verdict.code) { in nft_immediate_offload_verdict()
Dnft_compat.c85 regs->verdict.code = NFT_CONTINUE; in nft_target_eval_xt()
88 regs->verdict.code = ret; in nft_target_eval_xt()
111 regs->verdict.code = NF_ACCEPT; in nft_target_eval_bridge()
114 regs->verdict.code = NF_DROP; in nft_target_eval_bridge()
117 regs->verdict.code = NFT_CONTINUE; in nft_target_eval_bridge()
120 regs->verdict.code = NFT_RETURN; in nft_target_eval_bridge()
123 regs->verdict.code = ret; in nft_target_eval_bridge()
342 regs->verdict.code = NF_DROP; in __nft_match_eval()
348 regs->verdict.code = NFT_CONTINUE; in __nft_match_eval()
351 regs->verdict.code = NFT_BREAK; in __nft_match_eval()
Dnft_limit.c136 regs->verdict.code = NFT_BREAK; in nft_limit_pkts_eval()
186 regs->verdict.code = NFT_BREAK; in nft_limit_bytes_eval()
246 regs->verdict.code = NFT_BREAK; in nft_limit_obj_pkts_eval()
290 regs->verdict.code = NFT_BREAK; in nft_limit_obj_bytes_eval()
Dnft_connlimit.c42 regs->verdict.code = NF_DROP; in nft_connlimit_do_eval()
47 regs->verdict.code = NF_DROP; in nft_connlimit_do_eval()
54 regs->verdict.code = NFT_BREAK; in nft_connlimit_do_eval()
Dnft_lookup.c38 regs->verdict.code = NFT_BREAK; in nft_lookup_eval()
178 switch (data->verdict.code) { in nft_lookup_validate_setelem()
182 err = nft_chain_validate(ctx, data->verdict.chain); in nft_lookup_validate_setelem()
Dnft_osf.c34 regs->verdict.code = NFT_BREAK; in nft_osf_eval()
38 regs->verdict.code = NFT_BREAK; in nft_osf_eval()
Dnft_range.c34 regs->verdict.code = NFT_BREAK; in nft_range_eval()
38 regs->verdict.code = NFT_BREAK; in nft_range_eval()
/Linux-v5.4/samples/bpf/
Dtest_cgrp2_attach.c42 static int prog_load(int map_fd, int verdict) in prog_load() argument
69 BPF_MOV64_IMM(BPF_REG_0, verdict), /* r0 = verdict */ in prog_load()
87 static int attach_filter(int cg_fd, int type, int verdict) in attach_filter() argument
100 prog_fd = prog_load(map_fd, verdict); in attach_filter()
131 int detach_only = 0, verdict = 1; in main() local
138 verdict = 0; in main()
169 ret = attach_filter(cg_fd, type, verdict); in main()
/Linux-v5.4/net/netfilter/ipvs/
Dip_vs_core.c881 unsigned int verdict = NF_DROP; in handle_response_icmp() local
920 verdict = NF_ACCEPT; in handle_response_icmp()
925 return verdict; in handle_response_icmp()
1382 int verdict = ip_vs_out_icmp_v6(ipvs, skb, &related, in ip_vs_out() local
1386 return verdict; in ip_vs_out()
1392 int verdict = ip_vs_out_icmp(ipvs, skb, &related, hooknum); in ip_vs_out() local
1395 return verdict; in ip_vs_out()
1547 int *verdict, struct ip_vs_conn **cpp, in ip_vs_try_to_schedule() argument
1558 if (!pp->conn_schedule(ipvs, af, skb, pd, verdict, cpp, iph)) in ip_vs_try_to_schedule()
1572 *verdict = NF_ACCEPT; in ip_vs_try_to_schedule()
[all …]
Dip_vs_proto_udp.c33 int *verdict, struct ip_vs_conn **cpp, in udp_conn_schedule() argument
51 *verdict = NF_DROP; in udp_conn_schedule()
70 *verdict = NF_DROP; in udp_conn_schedule()
81 *verdict = ip_vs_leave(svc, skb, pd, iph); in udp_conn_schedule()
83 *verdict = NF_DROP; in udp_conn_schedule()
Dip_vs_proto_ah_esp.c105 int *verdict, struct ip_vs_conn **cpp, in ah_esp_conn_schedule() argument
111 *verdict = NF_ACCEPT; in ah_esp_conn_schedule()
/Linux-v5.4/net/ipv4/netfilter/
Darp_tables.c188 unsigned int verdict = NF_DROP; in arpt_do_table() local
238 v = ((struct xt_standard_target *)t)->verdict; in arpt_do_table()
242 verdict = (unsigned int)(-v) - 1; in arpt_do_table()
257 verdict = NF_DROP; in arpt_do_table()
269 verdict = t->u.kernel.target->target(skb, &acpar); in arpt_do_table()
271 if (verdict == XT_CONTINUE) { in arpt_do_table()
286 return verdict; in arpt_do_table()
335 t->verdict < 0) || visited) { in mark_source_chains()
362 int newpos = t->verdict; in mark_source_chains()
437 unsigned int verdict; in check_underflow() local
[all …]
Dip_tables.c174 t->verdict < 0) { in get_chainname_rulenum()
233 unsigned int verdict = NF_DROP; in ipt_do_table() local
314 v = ((struct xt_standard_target *)t)->verdict; in ipt_do_table()
318 verdict = (unsigned int)(-v) - 1; in ipt_do_table()
333 verdict = NF_DROP; in ipt_do_table()
346 verdict = t->u.kernel.target->target(skb, &acpar); in ipt_do_table()
347 if (verdict == XT_CONTINUE) { in ipt_do_table()
362 else return verdict; in ipt_do_table()
400 t->verdict < 0) || visited) { in mark_source_chains()
426 int newpos = t->verdict; in mark_source_chains()
[all …]
/Linux-v5.4/drivers/w1/slaves/
Dw1_therm.c52 u8 verdict; member
497 info->verdict = 0; in read_therm()
551 info->verdict = 1; in read_therm()
555 if (info->verdict) in read_therm()
584 info.crc, (info.verdict) ? "YES" : "NO"); in w1_slave_show()
585 if (info.verdict) in w1_slave_show()
615 if (!info.verdict) { in w1_read_temp()
/Linux-v5.4/net/bridge/
Dbr_input.c204 unsigned int verdict, i; in nf_hook_bridge_pre() local
223 verdict = nf_hook_entry_hookfn(&e->hooks[i], skb, &state); in nf_hook_bridge_pre()
224 switch (verdict & NF_VERDICT_MASK) { in nf_hook_bridge_pre()
235 ret = nf_queue(skb, &state, i, verdict); in nf_hook_bridge_pre()
/Linux-v5.4/net/ipv6/netfilter/
Dip6_tables.c199 t->verdict < 0) { in get_chainname_rulenum()
257 unsigned int verdict = NF_DROP; in ip6t_do_table() local
337 v = ((struct xt_standard_target *)t)->verdict; in ip6t_do_table()
341 verdict = (unsigned int)(-v) - 1; in ip6t_do_table()
354 verdict = NF_DROP; in ip6t_do_table()
367 verdict = t->u.kernel.target->target(skb, &acpar); in ip6t_do_table()
368 if (verdict == XT_CONTINUE) in ip6t_do_table()
380 else return verdict; in ip6t_do_table()
418 t->verdict < 0) || visited) { in mark_source_chains()
444 int newpos = t->verdict; in mark_source_chains()
[all …]

123