Symbol: NF_DROP
include/uapi/linux/netfilter.h
33
#define NF_DROP_ERR(x) (((-x) << 16) | NF_DROP)
kernel/bpf/verifier.c
18094
range = retval_range(NF_DROP, NF_ACCEPT);
net/bridge/br_input.c
299
case NF_DROP:
net/bridge/br_netfilter_hooks.c
711
return NF_DROP;
net/bridge/netfilter/ebtable_broute.c
62
if (ret != NF_DROP)
net/bridge/netfilter/ebtables.c
234
return NF_DROP;
net/bridge/netfilter/ebtables.c
259
return NF_DROP;
net/bridge/netfilter/ebtables.c
283
return NF_DROP;
net/bridge/netfilter/ebtables.c
295
return NF_DROP;
net/bridge/netfilter/ebtables.c
316
return NF_DROP;
net/bridge/netfilter/nf_conntrack_bridge.c
197
return err == 0 ? NF_ACCEPT : NF_DROP;
net/bridge/netfilter/nf_conntrack_bridge.c
357
return NF_DROP;
net/bridge/netfilter/nft_reject_bridge.c
169
regs->verdict.code = NF_DROP;
net/ipv4/netfilter/arp_tables.c
161
return NF_DROP;
net/ipv4/netfilter/arp_tables.c
189
unsigned int verdict = NF_DROP;
net/ipv4/netfilter/arp_tables.c
200
return NF_DROP;
net/ipv4/netfilter/arp_tables.c
258
verdict = NF_DROP;
net/ipv4/netfilter/arp_tables.c
285
return NF_DROP;
net/ipv4/netfilter/arp_tables.c
449
return verdict == NF_DROP || verdict == NF_ACCEPT;
net/ipv4/netfilter/arpt_mangle.c
21
return NF_DROP;
net/ipv4/netfilter/arpt_mangle.c
31
return NF_DROP;
net/ipv4/netfilter/arpt_mangle.c
38
return NF_DROP;
net/ipv4/netfilter/arpt_mangle.c
45
return NF_DROP;
net/ipv4/netfilter/arpt_mangle.c
52
return NF_DROP;
net/ipv4/netfilter/arpt_mangle.c
66
if (mangle->target != NF_DROP && mangle->target != NF_ACCEPT &&
net/ipv4/netfilter/ip_tables.c
232
unsigned int verdict = NF_DROP;
net/ipv4/netfilter/ip_tables.c
332
verdict = NF_DROP;
net/ipv4/netfilter/ip_tables.c
360
return NF_DROP;
net/ipv4/netfilter/ip_tables.c
583
return verdict == NF_DROP || verdict == NF_ACCEPT;
net/ipv4/netfilter/ip_tables.c
96
return NF_DROP;
net/ipv4/netfilter/ipt_ECN.c
83
return NF_DROP;
net/ipv4/netfilter/ipt_ECN.c
88
return NF_DROP;
net/ipv4/netfilter/ipt_REJECT.c
66
return NF_DROP;
net/ipv4/netfilter/ipt_SYNPROXY.c
22
return NF_DROP;
net/ipv4/netfilter/ipt_SYNPROXY.c
26
return NF_DROP;
net/ipv4/netfilter/ipt_SYNPROXY.c
29
return NF_DROP;
net/ipv4/netfilter/ipt_SYNPROXY.c
57
return NF_DROP;
net/ipv4/netfilter/iptable_filter.c
47
forward ? -NF_ACCEPT - 1 : NF_DROP - 1;
net/ipv4/netfilter/iptable_mangle.c
56
if (verdict != NF_DROP && verdict != NF_STOLEN) {
net/ipv4/netfilter/nf_nat_pptp.c
136
return NF_DROP;
net/ipv4/netfilter/nf_nat_pptp.c
194
return NF_DROP;
net/ipv4/netfilter/nf_nat_pptp.c
245
return NF_DROP;
net/ipv4/netfilter/nf_nat_pptp.c
294
return NF_DROP;
net/ipv4/netfilter/nf_nat_snmp_basic_main.c
151
return NF_DROP;
net/ipv4/netfilter/nf_nat_snmp_basic_main.c
186
return NF_DROP;
net/ipv4/netfilter/nf_nat_snmp_basic_main.c
191
return NF_DROP;
net/ipv4/netfilter/nft_reject_ipv4.c
37
regs->verdict.code = NF_DROP;
net/ipv6/netfilter/ip6_tables.c
122
return NF_DROP;
net/ipv6/netfilter/ip6_tables.c
255
unsigned int verdict = NF_DROP;
net/ipv6/netfilter/ip6_tables.c
353
verdict = NF_DROP;
net/ipv6/netfilter/ip6_tables.c
378
return NF_DROP;
net/ipv6/netfilter/ip6_tables.c
601
return verdict == NF_DROP || verdict == NF_ACCEPT;
net/ipv6/netfilter/ip6t_NPT.c
106
return NF_DROP;
net/ipv6/netfilter/ip6t_NPT.c
131
return NF_DROP;
net/ipv6/netfilter/ip6t_REJECT.c
75
return NF_DROP;
net/ipv6/netfilter/ip6t_SYNPROXY.c
22
return NF_DROP;
net/ipv6/netfilter/ip6t_SYNPROXY.c
26
return NF_DROP;
net/ipv6/netfilter/ip6t_SYNPROXY.c
29
return NF_DROP;
net/ipv6/netfilter/ip6t_SYNPROXY.c
59
return NF_DROP;
net/ipv6/netfilter/ip6table_filter.c
46
forward ? -NF_ACCEPT - 1 : NF_DROP - 1;
net/ipv6/netfilter/ip6table_mangle.c
52
if (verdict != NF_DROP && verdict != NF_STOLEN &&
net/ipv6/netfilter/nf_defrag_ipv6_hooks.c
73
return err == 0 ? NF_ACCEPT : NF_DROP;
net/ipv6/netfilter/nft_reject_ipv6.c
38
regs->verdict.code = NF_DROP;
net/netfilter/core.c
627
case NF_DROP:
net/netfilter/ipvs/ip_vs_core.c
1003
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
1020
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
1454
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
1604
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
1718
verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
1816
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
1833
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
2022
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
2039
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
2043
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
593
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
620
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
651
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
669
return NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
862
unsigned int verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_core.c
937
return NF_DROP;
net/netfilter/ipvs/ip_vs_proto_sctp.c
46
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_sctp.c
64
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_sctp.c
76
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_tcp.c
61
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_tcp.c
82
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_tcp.c
95
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_udp.c
51
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_udp.c
70
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_proto_udp.c
83
*verdict = NF_DROP;
net/netfilter/ipvs/ip_vs_xmit.c
1267
else if (ret == NF_DROP)
net/netfilter/ipvs/ip_vs_xmit.c
1409
else if (ret == NF_DROP)
net/netfilter/nf_conntrack_amanda.c
149
ret = NF_DROP;
net/netfilter/nf_conntrack_amanda.c
164
ret = NF_DROP;
net/netfilter/nf_conntrack_core.c
1065
return NF_DROP;
net/netfilter/nf_conntrack_core.c
1198
return NF_DROP;
net/netfilter/nf_conntrack_core.c
1214
int ret = NF_DROP;
net/netfilter/nf_conntrack_core.c
1253
return NF_DROP;
net/netfilter/nf_conntrack_core.c
1292
ret = NF_DROP;
net/netfilter/nf_conntrack_core.c
1330
return NF_DROP;
net/netfilter/nf_conntrack_core.c
2052
ret = NF_DROP;
net/netfilter/nf_conntrack_core.c
2078
if (ret == NF_DROP)
net/netfilter/nf_conntrack_core.c
2252
return NF_DROP;
net/netfilter/nf_conntrack_ftp.c
398
return NF_DROP;
net/netfilter/nf_conntrack_ftp.c
463
ret = NF_DROP;
net/netfilter/nf_conntrack_ftp.c
477
ret = NF_DROP;
net/netfilter/nf_conntrack_ftp.c
529
ret = NF_DROP;
net/netfilter/nf_conntrack_h323_main.c
1134
return NF_DROP;
net/netfilter/nf_conntrack_h323_main.c
1706
return NF_DROP;
net/netfilter/nf_conntrack_h323_main.c
572
return NF_DROP;
net/netfilter/nf_conntrack_irc.c
233
ret = NF_DROP;
net/netfilter/nf_conntrack_irc.c
252
ret = NF_DROP;
net/netfilter/nf_conntrack_ovs.c
57
return NF_DROP;
net/netfilter/nf_conntrack_ovs.c
73
return NF_DROP;
net/netfilter/nf_conntrack_pptp.c
514
return NF_DROP;
net/netfilter/nf_conntrack_proto.c
192
return NF_DROP;
net/netfilter/nf_conntrack_proto_tcp.c
1026
return NF_DROP;
net/netfilter/nf_conntrack_sane.c
148
return NF_DROP;
net/netfilter/nf_conntrack_sane.c
162
ret = NF_DROP;
net/netfilter/nf_conntrack_sip.c
1088
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1104
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1265
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1281
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1292
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1301
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1316
ret = NF_DROP;
net/netfilter/nf_conntrack_sip.c
1373
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1391
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1428
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1434
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1439
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1500
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1505
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1531
ret = NF_DROP;
net/netfilter/nf_conntrack_sip.c
1566
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
1640
return NF_DROP;
net/netfilter/nf_conntrack_sip.c
860
int direct_rtp = 0, skip_expect = 0, ret = NF_DROP;
net/netfilter/nf_conntrack_tftp.c
68
return NF_DROP;
net/netfilter/nf_conntrack_tftp.c
84
ret = NF_DROP;
net/netfilter/nf_flow_table_ip.c
1101
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
1120
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
1123
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
1131
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
1136
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
1145
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
1152
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
780
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
798
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
801
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
809
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
814
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
823
return NF_DROP;
net/netfilter/nf_flow_table_ip.c
830
return NF_DROP;
net/netfilter/nf_nat_amanda.c
50
return NF_DROP;
net/netfilter/nf_nat_amanda.c
59
return NF_DROP;
net/netfilter/nf_nat_bpf.c
52
return nf_nat_setup_info(ct, &range, manip) == NF_DROP ? -ENOMEM : 0;
net/netfilter/nf_nat_core.c
1157
return __nf_nat_alloc_null_binding(ct, manip) == NF_DROP ? -ENOMEM : 0;
net/netfilter/nf_nat_core.c
1163
return nf_nat_setup_info(ct, &range, manip) == NF_DROP ? -ENOMEM : 0;
net/netfilter/nf_nat_core.c
786
return NF_DROP;
net/netfilter/nf_nat_core.c
813
return NF_DROP;
net/netfilter/nf_nat_core.c
974
return NF_DROP;
net/netfilter/nf_nat_ftp.c
111
return NF_DROP;
net/netfilter/nf_nat_ftp.c
92
return NF_DROP;
net/netfilter/nf_nat_irc.c
55
return NF_DROP;
net/netfilter/nf_nat_irc.c
80
return NF_DROP;
net/netfilter/nf_nat_masquerade.c
256
return NF_DROP;
net/netfilter/nf_nat_masquerade.c
57
return NF_DROP;
net/netfilter/nf_nat_ovs.c
34
err = NF_DROP;
net/netfilter/nf_nat_ovs.c
48
err = NF_DROP;
net/netfilter/nf_nat_ovs.c
76
err = NF_DROP;
net/netfilter/nf_nat_ovs.c
99
return NF_DROP; /* Can't NAT. */
net/netfilter/nf_nat_proto.c
400
return NF_DROP;
net/netfilter/nf_nat_proto.c
597
return NF_DROP;
net/netfilter/nf_nat_proto.c
926
return NF_DROP;
net/netfilter/nf_nat_proto.c
965
if (verdict != NF_DROP && verdict != NF_STOLEN &&
net/netfilter/nf_nat_redirect.c
133
return NF_DROP;
net/netfilter/nf_nat_redirect.c
74
return NF_DROP;
net/netfilter/nf_nat_sip.c
167
return NF_DROP;
net/netfilter/nf_nat_sip.c
203
return NF_DROP;
net/netfilter/nf_nat_sip.c
221
return NF_DROP;
net/netfilter/nf_nat_sip.c
238
return NF_DROP;
net/netfilter/nf_nat_sip.c
254
return NF_DROP;
net/netfilter/nf_nat_sip.c
271
return NF_DROP;
net/netfilter/nf_nat_sip.c
278
return NF_DROP;
net/netfilter/nf_nat_sip.c
287
return NF_DROP;
net/netfilter/nf_nat_sip.c
296
return NF_DROP;
net/netfilter/nf_nat_sip.c
416
return NF_DROP;
net/netfilter/nf_nat_sip.c
432
return NF_DROP;
net/netfilter/nf_nat_sip.c
640
return NF_DROP;
net/netfilter/nf_nat_tftp.c
35
return NF_DROP;
net/netfilter/nf_synproxy_core.c
1091
return NF_DROP;
net/netfilter/nf_synproxy_core.c
1116
return NF_DROP;
net/netfilter/nf_synproxy_core.c
1130
return NF_DROP;
net/netfilter/nf_synproxy_core.c
1145
return NF_DROP;
net/netfilter/nf_synproxy_core.c
668
return NF_DROP;
net/netfilter/nf_synproxy_core.c
693
return NF_DROP;
net/netfilter/nf_synproxy_core.c
707
return NF_DROP;
net/netfilter/nf_synproxy_core.c
722
return NF_DROP;
net/netfilter/nf_tables_api.c
10038
if (trans->policy != NF_DROP)
net/netfilter/nf_tables_api.c
10045
basechain->policy = NF_DROP;
net/netfilter/nf_tables_api.c
10072
case NF_DROP:
net/netfilter/nf_tables_api.c
11669
case NF_DROP:
net/netfilter/nf_tables_api.c
3120
case NF_DROP:
net/netfilter/nf_tables_core.c
311
case NF_DROP:
net/netfilter/nf_tables_core.c
318
return NF_DROP;
net/netfilter/nf_tables_core.c
343
if (nft_base_chain(basechain)->policy == NF_DROP)
net/netfilter/nf_tables_offload.c
510
if (cmd == FLOW_BLOCK_BIND && policy == NF_DROP)
net/netfilter/nfnetlink_cthelper.c
49
return NF_DROP;
net/netfilter/nfnetlink_cthelper.c
54
return NF_DROP;
net/netfilter/nfnetlink_queue.c
1513
nfqnl_reinject(entry, NF_DROP);
net/netfilter/nfnetlink_queue.c
1524
verdict = NF_DROP;
net/netfilter/nfnetlink_queue.c
371
verdict = NF_DROP;
net/netfilter/nfnetlink_queue.c
457
if (verdict != NF_DROP && entry->nf_ct_is_unconfirmed) {
net/netfilter/nfnetlink_queue.c
471
verdict = NF_DROP;
net/netfilter/nfnetlink_queue.c
486
nfqnl_reinject(entry, NF_DROP);
net/netfilter/nft_chain_filter.c
178
return NF_DROP;
net/netfilter/nft_chain_filter.c
186
return NF_DROP;
net/netfilter/nft_compat.c
115
ret = NF_DROP;
net/netfilter/nft_compat.c
122
regs->verdict.code = NF_DROP;
net/netfilter/nft_compat.c
407
regs->verdict.code = NF_DROP;
net/netfilter/nft_compat.c
88
ret = NF_DROP;
net/netfilter/nft_connlimit.c
40
regs->verdict.code = NF_DROP;
net/netfilter/nft_ct.c
1202
regs->verdict.code = NF_DROP;
net/netfilter/nft_ct.c
1360
regs->verdict.code = NF_DROP;
net/netfilter/nft_ct.c
1373
regs->verdict.code = NF_DROP;
net/netfilter/nft_ct.c
1383
regs->verdict.code = NF_DROP;
net/netfilter/nft_ct.c
266
regs->verdict.code = NF_DROP;
net/netfilter/nft_ct.c
943
regs->verdict.code = NF_DROP;
net/netfilter/nft_exthdr.c
366
regs->verdict.code = NF_DROP;
net/netfilter/nft_fib_inet.c
41
regs->verdict.code = NF_DROP;
net/netfilter/nft_fwd_netdev.c
115
verdict = NF_DROP;
net/netfilter/nft_fwd_netdev.c
131
verdict = NF_DROP;
net/netfilter/nft_immediate.c
289
case NF_DROP:
net/netfilter/nft_reject_inet.c
60
regs->verdict.code = NF_DROP;
net/netfilter/nft_reject_netdev.c
144
regs->verdict.code = NF_DROP;
net/netfilter/nft_synproxy.c
101
regs->verdict.code = NF_DROP;
net/netfilter/nft_synproxy.c
123
regs->verdict.code = NF_DROP;
net/netfilter/nft_synproxy.c
131
regs->verdict.code = NF_DROP;
net/netfilter/nft_synproxy.c
136
regs->verdict.code = NF_DROP;
net/netfilter/nft_synproxy.c
70
regs->verdict.code = NF_DROP;
net/netfilter/x_tables.c
657
case NF_DROP: return true;
net/netfilter/xt_DSCP.c
103
return NF_DROP;
net/netfilter/xt_DSCP.c
37
return NF_DROP;
net/netfilter/xt_DSCP.c
54
return NF_DROP;
net/netfilter/xt_DSCP.c
83
return NF_DROP;
net/netfilter/xt_HL.c
33
return NF_DROP;
net/netfilter/xt_HL.c
73
return NF_DROP;
net/netfilter/xt_TCPMSS.c
207
return NF_DROP;
net/netfilter/xt_TCPMSS.c
230
return NF_DROP;
net/netfilter/xt_TCPMSS.c
236
return NF_DROP;
net/netfilter/xt_TCPOPTSTRIP.c
106
return NF_DROP;
net/netfilter/xt_TCPOPTSTRIP.c
46
return NF_DROP;
net/netfilter/xt_TCPOPTSTRIP.c
50
return NF_DROP;
net/netfilter/xt_TCPOPTSTRIP.c
53
return NF_DROP;
net/netfilter/xt_TPROXY.c
118
return NF_DROP;
net/netfilter/xt_TPROXY.c
122
return NF_DROP;
net/netfilter/xt_TPROXY.c
163
return NF_DROP;
net/netfilter/xt_TPROXY.c
45
return NF_DROP;
net/netfilter/xt_TPROXY.c
81
return NF_DROP;
net/openvswitch/conntrack.c
707
case NF_DROP:
net/sched/act_ct.c
1123
case NF_DROP:
security/selinux/hooks.c
5873
return NF_DROP;
security/selinux/hooks.c
5878
return NF_DROP;
security/selinux/hooks.c
5887
return NF_DROP;
security/selinux/hooks.c
5894
return NF_DROP;
security/selinux/hooks.c
5902
return NF_DROP;
security/selinux/hooks.c
5944
return NF_DROP;
security/selinux/hooks.c
5966
return NF_DROP;
security/selinux/hooks.c
6033
return NF_DROP;
security/selinux/hooks.c
6053
return NF_DROP;
security/selinux/hooks.c
6075
return NF_DROP;
security/selinux/hooks.c
6088
return NF_DROP;
security/selinux/hooks.c
6100
return NF_DROP;
security/selinux/hooks.c
6106
return NF_DROP;
tools/include/uapi/linux/netfilter.h
33
#define NF_DROP_ERR(x) (((-x) << 16) | NF_DROP)
tools/testing/selftests/bpf/progs/ip_check_defrag.c
47
return NF_DROP;
tools/testing/selftests/bpf/progs/ip_check_defrag.c
51
return NF_DROP;
tools/testing/selftests/bpf/progs/ip_check_defrag.c
56
return NF_DROP;
tools/testing/selftests/bpf/progs/ip_check_defrag.c
69
return NF_DROP;
tools/testing/selftests/bpf/progs/ip_check_defrag.c
73
return NF_DROP;
tools/testing/selftests/bpf/progs/ip_check_defrag.c
78
return NF_DROP;
tools/testing/selftests/bpf/progs/verifier_netfilter_ctx.c
113
return th->dest == bpf_htons(22) ? NF_ACCEPT : NF_DROP;