netfilter: IPv6: fix DSCP mangle code
authorFernando Luis Vazquez Cao <fernando@oss.ntt.co.jp>
Tue, 10 May 2011 08:00:21 +0000 (10:00 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 10 May 2011 08:00:21 +0000 (10:00 +0200)
The mask indicates the bits one wants to zero out, so it needs to be
inverted before applying to the original TOS field.

Signed-off-by: Fernando Luis Vazquez Cao <fernando@oss.ntt.co.jp>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/xt_DSCP.c

index 0a22919..ae82716 100644 (file)
@@ -99,7 +99,7 @@ tos_tg6(struct sk_buff *skb, const struct xt_action_param *par)
        u_int8_t orig, nv;
 
        orig = ipv6_get_dsfield(iph);
-       nv   = (orig & info->tos_mask) ^ info->tos_value;
+       nv   = (orig & ~info->tos_mask) ^ info->tos_value;
 
        if (orig != nv) {
                if (!skb_make_writable(skb, sizeof(struct iphdr)))