Index: webrtc/base/firewallsocketserver.cc |
diff --git a/webrtc/base/firewallsocketserver.cc b/webrtc/base/firewallsocketserver.cc |
index 30e5c3bfaa8c14a6cc4b9edaff4610763bd96d8a..4f80738f66144f639f0415d0e54757a80f003b24 100644 |
--- a/webrtc/base/firewallsocketserver.cc |
+++ b/webrtc/base/firewallsocketserver.cc |
@@ -24,6 +24,14 @@ class FirewallSocket : public AsyncSocketAdapter { |
: AsyncSocketAdapter(socket), server_(server), type_(type) { |
} |
+ int Bind(const SocketAddress& addr) override { |
+ if (!server_->CanBindToIp(addr.ipaddr())) { |
+ SetError(EINVAL); |
+ return SOCKET_ERROR; |
+ } |
+ return AsyncSocketAdapter::Bind(addr); |
+ } |
+ |
int Connect(const SocketAddress& addr) override { |
if (type_ == SOCK_STREAM) { |
if (!server_->Check(FP_TCP, GetLocalAddress(), addr)) { |
@@ -176,6 +184,16 @@ bool FirewallSocketServer::Check(FirewallProtocol p, |
return true; |
} |
+void FirewallSocketServer::SetInvalidBindIps( |
+ const std::vector<rtc::IPAddress>& invalid_bind_ips) { |
+ invalid_bind_ips_ = invalid_bind_ips; |
+} |
+ |
+bool FirewallSocketServer::CanBindToIp(const rtc::IPAddress& ip) { |
+ return std::find(invalid_bind_ips_.begin(), invalid_bind_ips_.end(), ip) == |
+ invalid_bind_ips_.end(); |
+} |
+ |
Socket* FirewallSocketServer::CreateSocket(int type) { |
return CreateSocket(AF_INET, type); |
} |