Commit ef53d702 authored by Jan Engelhardt's avatar Jan Engelhardt

netfilter: xtables: dissolve do_match function

Signed-off-by: default avatarJan Engelhardt <jengelh@medozas.de>
parent c29c9492
...@@ -173,21 +173,6 @@ ipt_error(struct sk_buff *skb, const struct xt_target_param *par) ...@@ -173,21 +173,6 @@ ipt_error(struct sk_buff *skb, const struct xt_target_param *par)
return NF_DROP; return NF_DROP;
} }
/* Performance critical - called for every packet */
static inline bool
do_match(const struct ipt_entry_match *m, const struct sk_buff *skb,
struct xt_match_param *par)
{
par->match = m->u.kernel.match;
par->matchinfo = m->data;
/* Stop iteration if it doesn't match */
if (!m->u.kernel.match->match(skb, par))
return true;
else
return false;
}
/* Performance critical */ /* Performance critical */
static inline struct ipt_entry * static inline struct ipt_entry *
get_entry(const void *base, unsigned int offset) get_entry(const void *base, unsigned int offset)
...@@ -379,9 +364,12 @@ ipt_do_table(struct sk_buff *skb, ...@@ -379,9 +364,12 @@ ipt_do_table(struct sk_buff *skb,
continue; continue;
} }
xt_ematch_foreach(ematch, e) xt_ematch_foreach(ematch, e) {
if (do_match(ematch, skb, &mtpar) != 0) mtpar.match = ematch->u.kernel.match;
mtpar.matchinfo = ematch->data;
if (!mtpar.match->match(skb, &mtpar))
goto no_match; goto no_match;
}
ADD_COUNTER(e->counters, ntohs(ip->tot_len), 1); ADD_COUNTER(e->counters, ntohs(ip->tot_len), 1);
......
...@@ -205,21 +205,6 @@ ip6t_error(struct sk_buff *skb, const struct xt_target_param *par) ...@@ -205,21 +205,6 @@ ip6t_error(struct sk_buff *skb, const struct xt_target_param *par)
return NF_DROP; return NF_DROP;
} }
/* Performance critical - called for every packet */
static inline bool
do_match(const struct ip6t_entry_match *m, const struct sk_buff *skb,
struct xt_match_param *par)
{
par->match = m->u.kernel.match;
par->matchinfo = m->data;
/* Stop iteration if it doesn't match */
if (!m->u.kernel.match->match(skb, par))
return true;
else
return false;
}
static inline struct ip6t_entry * static inline struct ip6t_entry *
get_entry(const void *base, unsigned int offset) get_entry(const void *base, unsigned int offset)
{ {
...@@ -402,9 +387,12 @@ ip6t_do_table(struct sk_buff *skb, ...@@ -402,9 +387,12 @@ ip6t_do_table(struct sk_buff *skb,
continue; continue;
} }
xt_ematch_foreach(ematch, e) xt_ematch_foreach(ematch, e) {
if (do_match(ematch, skb, &mtpar) != 0) mtpar.match = ematch->u.kernel.match;
mtpar.matchinfo = ematch->data;
if (!mtpar.match->match(skb, &mtpar))
goto no_match; goto no_match;
}
ADD_COUNTER(e->counters, ADD_COUNTER(e->counters,
ntohs(ipv6_hdr(skb)->payload_len) + ntohs(ipv6_hdr(skb)->payload_len) +
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment