From owner-svn-src-projects@FreeBSD.ORG Wed Jun 17 21:24:36 2009 Return-Path: Delivered-To: svn-src-projects@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 57725106567E; Wed, 17 Jun 2009 21:24:36 +0000 (UTC) (envelope-from rpaulo@FreeBSD.org) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:4f8:fff6::2c]) by mx1.freebsd.org (Postfix) with ESMTP id 457538FC1E; Wed, 17 Jun 2009 21:24:36 +0000 (UTC) (envelope-from rpaulo@FreeBSD.org) Received: from svn.freebsd.org (localhost [127.0.0.1]) by svn.freebsd.org (8.14.3/8.14.3) with ESMTP id n5HLOaLg088773; Wed, 17 Jun 2009 21:24:36 GMT (envelope-from rpaulo@svn.freebsd.org) Received: (from rpaulo@localhost) by svn.freebsd.org (8.14.3/8.14.3/Submit) id n5HLOaHv088771; Wed, 17 Jun 2009 21:24:36 GMT (envelope-from rpaulo@svn.freebsd.org) Message-Id: <200906172124.n5HLOaHv088771@svn.freebsd.org> From: Rui Paulo Date: Wed, 17 Jun 2009 21:24:36 +0000 (UTC) To: src-committers@freebsd.org, svn-src-projects@freebsd.org X-SVN-Group: projects MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Cc: Subject: svn commit: r194402 - projects/mesh11s/sys/net80211 X-BeenThere: svn-src-projects@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "SVN commit messages for the src " projects" tree" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 17 Jun 2009 21:24:36 -0000 Author: rpaulo Date: Wed Jun 17 21:24:36 2009 New Revision: 194402 URL: http://svn.freebsd.org/changeset/base/194402 Log: Add MAC ACL support. Sponsored by: The FreeBSD Foundation Modified: projects/mesh11s/sys/net80211/ieee80211_mesh.c Modified: projects/mesh11s/sys/net80211/ieee80211_mesh.c ============================================================================== --- projects/mesh11s/sys/net80211/ieee80211_mesh.c Wed Jun 17 21:14:07 2009 (r194401) +++ projects/mesh11s/sys/net80211/ieee80211_mesh.c Wed Jun 17 21:24:36 2009 (r194402) @@ -546,6 +546,15 @@ mesh_recv_mgmt(struct ieee80211_node *ni if (vap->iv_state != IEEE80211_S_RUN) return; /* + * Consult the ACL policy module if setup. + */ + if (vap->iv_acl != NULL && !vap->iv_acl->iac_check(vap, wh->i_addr2)) { + IEEE80211_DISCARD(vap, IEEE80211_MSG_MESH | IEEE80211_MSG_ACL, + wh, NULL, "%s", "disallowed by ACL"); + vap->iv_stats.is_rx_acl++; + return; + } + /* * Ignore non-mesh STAs and STAs for other mesh networks. */ if (scan.meshid && @@ -727,7 +736,15 @@ mesh_recv_action(struct ieee80211_node * */ if (!IEEE80211_ADDR_EQ(vap->iv_myaddr, wh->i_addr1)) return; - + /* + * Consult the ACL policy module if setup. + */ + if (vap->iv_acl != NULL && !vap->iv_acl->iac_check(vap, wh->i_addr2)) { + IEEE80211_DISCARD(vap, IEEE80211_MSG_MESH | IEEE80211_MSG_ACL, + wh, NULL, "%s", "disallowed by ACL"); + vap->iv_stats.is_rx_acl++; + return; + } /* * Compute the start of fixed/tagged parameters. */