diff options
| author | David Gibson <david@gibson.dropbear.id.au> | 2026-07-10 15:26:51 +1000 |
|---|---|---|
| committer | David Gibson <david@gibson.dropbear.id.au> | 2026-07-13 14:47:21 +1000 |
| commit | 0b31c0be7efb588c7da0eb89f54dc62a167fa8c9 (patch) | |
| tree | bf1bb216cb16f37f06d855b4d64e21f2a71d2b8a | |
| parent | 4158a393c6f8a6ce5b6d3a5acb2887d2cbf39917 (diff) | |
| download | passt-0b31c0be7efb588c7da0eb89f54dc62a167fa8c9.tar passt-0b31c0be7efb588c7da0eb89f54dc62a167fa8c9.tar.gz passt-0b31c0be7efb588c7da0eb89f54dc62a167fa8c9.tar.bz2 passt-0b31c0be7efb588c7da0eb89f54dc62a167fa8c9.tar.lz passt-0b31c0be7efb588c7da0eb89f54dc62a167fa8c9.tar.xz passt-0b31c0be7efb588c7da0eb89f54dc62a167fa8c9.tar.zst passt-0b31c0be7efb588c7da0eb89f54dc62a167fa8c9.zip | |
fwd: Reorder DNAPT and SNAT steps in fwd_nat_from_host()
The order in which we translate source and destination addresses is a bit
unclear in fwd_nat_from_host(). Reorder things to make it clearer:
1. Pick guest-side destination address, where options require it
2. Pick guest-side source address (needs to be different for SPLICE and
TAP)
3. If (1) didn't determine destination, pick a fallback to match family
and scope of source address from (2).
As a small bonus this lets us make step (1) common between SPLICE and TAP
paths. The value of this is a bit dubious right now, but it will make some
future changes clearer.
Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
| -rw-r--r-- | fwd.c | 14 |
1 files changed, 7 insertions, 7 deletions
@@ -1038,8 +1038,12 @@ uint8_t fwd_nat_from_host(const struct ctx *c, const struct fwd_rule *rule, uint8_t proto, const struct flowside *ini, struct flowside *tgt) { - /* Common for spliced and non-spliced cases */ + /* DNAPT: Common for splice and non-spliced where possible */ tgt->eport = rule->to + (ini->oport - rule->first); + if (!inany_is_unspecified(&rule->taddr)) + tgt->eaddr = rule->taddr; + else if (c->host_lo_to_ns_lo && inany_is_loopback(&ini->oaddr)) + tgt->eaddr = ini->oaddr; /* TODO: Allow splicing with specified target address */ if (!c->no_splice && inany_is_unspecified(&rule->taddr) && @@ -1056,10 +1060,8 @@ uint8_t fwd_nat_from_host(const struct ctx *c, * In either case, let the kernel pick the source address to * match. */ - if (c->host_lo_to_ns_lo && inany_is_loopback(&ini->oaddr)) - tgt->eaddr = ini->oaddr; - /* Let the kernel pick source address and port */ + /* SNAT: (implicit) let the kernel pick source addr/port */ if (inany_v4(&ini->eaddr)) tgt->oaddr = inany_any4; else @@ -1079,6 +1081,7 @@ uint8_t fwd_nat_from_host(const struct ctx *c, if (c->splice_only) return PIF_NONE; + /* SNAT: translate source address if necessary */ if (!nat_inbound(c, &ini->eaddr, &tgt->oaddr)) { if (inany_v4(&ini->eaddr)) { if (IN4_IS_ADDR_UNSPECIFIED(&c->ip4.our_tap_addr)) @@ -1091,9 +1094,6 @@ uint8_t fwd_nat_from_host(const struct ctx *c, } tgt->oport = ini->eport; - if (!inany_is_unspecified(&rule->taddr)) - tgt->eaddr = rule->taddr; - /* Use guest address as destination, if otherwise unspecified */ if (inany_is_unspecified(&tgt->eaddr)) tgt->eaddr = fwd_default_guest_addr(c, &tgt->oaddr); |
