|
77 | 77 | #include "lwip/netif.h" |
78 | 78 | #include "lwip/ip_addr.h" |
79 | 79 | #include "lwip/icmp.h" |
80 | | -#include "lwip/tcp_impl.h" |
| 80 | +/* lwIP 2.1 adaptation: tcp_impl.h was renamed/moved to prot/tcp.h (SiFli local modification) */ |
| 81 | +#include "lwip/prot/tcp.h" |
81 | 82 | #include "lwip/udp.h" |
82 | 83 | #include "lwip/mem.h" |
83 | 84 | #include "lwip/sys.h" |
84 | | -#include "lwip/timers.h" |
| 85 | +/* lwIP 2.1 adaptation: timers.h was renamed/moved to timeouts.h (SiFli local modification) */ |
| 86 | +#include "lwip/timeouts.h" |
85 | 87 | #include "netif/etharp.h" |
86 | 88 |
|
87 | 89 | #include <limits.h> |
@@ -371,8 +373,15 @@ ip_nat_shallnat(const struct ip_hdr *iphdr) |
371 | 373 | ip_nat_conf_t *nat_config = ip_nat_cfg; |
372 | 374 |
|
373 | 375 | for (nat_config = ip_nat_cfg; nat_config != NULL; nat_config = nat_config->next) { |
| 376 | + /* |
| 377 | + * SiFli local modification |
| 378 | + * Original RT-Thread implementation (NAT if either source or dest |
| 379 | + * matches the rule). |
| 380 | + * Changed to && locally: NAT is applied only when both the source and |
| 381 | + * dest networks match the rule. |
| 382 | + */ |
374 | 383 | if (ip_addr_netcmp(&(iphdr->dest), &(nat_config->entry.dest_net), |
375 | | - &(nat_config->entry.dest_netmask)) || |
| 384 | + &(nat_config->entry.dest_netmask)) && |
376 | 385 | ip_addr_netcmp(&(iphdr->src), &(nat_config->entry.source_net), |
377 | 386 | &(nat_config->entry.source_netmask))) { |
378 | 387 | break; |
@@ -679,18 +688,37 @@ ip_nat_out(struct pbuf *p) |
679 | 688 | ("ip_nat_out: short icmp echo packet (%" U16_F " bytes) discarded\n", p->tot_len)); |
680 | 689 | } else { |
681 | 690 | if (ICMPH_TYPE(icmphdr) == ICMP_ECHO) { |
| 691 | + /* |
| 692 | + * SiFli local modification |
| 693 | + * Original RT-Thread implementation (drops new ICMP requests when |
| 694 | + * the table is full). |
| 695 | + * Changed locally: when no free slot is found, evict the oldest entry |
| 696 | + * (smallest ttl) using LRU and reuse its slot, so new echo requests |
| 697 | + * are not dropped when the ICMP table is full. |
| 698 | + */ |
| 699 | + int oldest = -1; |
| 700 | + s32_t oldest_ttl = LWIP_NAT_TTL_INFINITE; |
| 701 | + |
682 | 702 | for (i = 0; i < LWIP_NAT_DEFAULT_STATE_TABLES_ICMP; i++) { |
683 | 703 | if (!ip_nat_icmp_table[i].common.ttl) { |
684 | 704 | nat_entry.icmp = &ip_nat_icmp_table[i]; |
685 | | - ip_nat_cmn_init(nat_config, iphdr, nat_entry.cmn); |
686 | | - nat_entry.icmp->id = icmphdr->id; |
687 | | - nat_entry.icmp->seqno = icmphdr->seqno; |
688 | | - ip_nat_dbg_dump_icmp_nat_entry(" ip_nat_out: created new NAT entry ", nat_entry.icmp); |
689 | 705 | break; |
690 | 706 | } |
| 707 | + if (ip_nat_icmp_table[i].common.ttl < oldest_ttl) { |
| 708 | + oldest = i; |
| 709 | + oldest_ttl = ip_nat_icmp_table[i].common.ttl; |
| 710 | + } |
| 711 | + } |
| 712 | + if (nat_entry.icmp == NULL && oldest >= 0) { |
| 713 | + nat_entry.icmp = &ip_nat_icmp_table[oldest]; |
| 714 | + IPNAT_ENTRY_RESET(&nat_entry.icmp->common); |
691 | 715 | } |
692 | | - if (NULL == nat_entry.icmp) |
693 | | - { |
| 716 | + if (nat_entry.icmp != NULL) { |
| 717 | + ip_nat_cmn_init(nat_config, iphdr, nat_entry.cmn); |
| 718 | + nat_entry.icmp->id = icmphdr->id; |
| 719 | + nat_entry.icmp->seqno = icmphdr->seqno; |
| 720 | + ip_nat_dbg_dump_icmp_nat_entry(" ip_nat_out: created new NAT entry ", nat_entry.icmp); |
| 721 | + } else { |
694 | 722 | LWIP_DEBUGF(LWIP_NAT_DEBUG, ("ip_nat_out: no more NAT entries for ICMP available\n")); |
695 | 723 | } |
696 | 724 | } |
@@ -817,7 +845,8 @@ ip_nat_udp_lookup_outgoing(ip_nat_conf_t *nat_config, const struct ip_hdr *iphdr |
817 | 845 | if (allocate) { |
818 | 846 | if (last_free != -1) { |
819 | 847 | nat_entry.udp = &ip_nat_udp_table[last_free]; |
820 | | - nat_entry.udp->nport = htons((u16_t) (LWIP_NAT_DEFAULT_UDP_SOURCE_PORT + i)); |
| 848 | + /* SiFli local modification */ |
| 849 | + nat_entry.udp->nport = htons((u16_t) (LWIP_NAT_DEFAULT_UDP_SOURCE_PORT + last_free)); |
821 | 850 | nat_entry.udp->sport = udphdr->src; |
822 | 851 | nat_entry.udp->dport = udphdr->dest; |
823 | 852 | ip_nat_cmn_init(nat_config, iphdr, nat_entry.cmn); |
@@ -902,7 +931,8 @@ ip_nat_tcp_lookup_outgoing(ip_nat_conf_t *nat_config, const struct ip_hdr *iphdr |
902 | 931 | if (allocate) { |
903 | 932 | if (last_free != -1) { |
904 | 933 | nat_entry.tcp = &ip_nat_tcp_table[last_free]; |
905 | | - nat_entry.tcp->nport = htons((u16_t) (LWIP_NAT_DEFAULT_TCP_SOURCE_PORT + i)); |
| 934 | + /* SiFli local modification */ |
| 935 | + nat_entry.tcp->nport = htons((u16_t) (LWIP_NAT_DEFAULT_TCP_SOURCE_PORT + last_free)); |
906 | 936 | nat_entry.tcp->sport = tcphdr->src; |
907 | 937 | nat_entry.tcp->dport = tcphdr->dest; |
908 | 938 | ip_nat_cmn_init(nat_config, iphdr, nat_entry.cmn); |
|
0 commit comments