Blame tc/m_ct.c

Packit Service 3880ab
// SPDX-License-Identifier: GPL-2.0 OR Linux-OpenIB
Packit Service 3880ab
/* -
Packit Service 3880ab
 * m_ct.c     Connection tracking action
Packit Service 3880ab
 *
Packit Service 3880ab
 * Authors:   Paul Blakey <paulb@mellanox.com>
Packit Service 3880ab
 *            Yossi Kuperman <yossiku@mellanox.com>
Packit Service 3880ab
 *            Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Packit Service 3880ab
 */
Packit Service 3880ab
Packit Service 3880ab
#include <stdio.h>
Packit Service 3880ab
#include <stdlib.h>
Packit Service 3880ab
#include <unistd.h>
Packit Service 3880ab
#include <string.h>
Packit Service 3880ab
#include "utils.h"
Packit Service 3880ab
#include "tc_util.h"
Packit Service 3880ab
#include <linux/tc_act/tc_ct.h>
Packit Service 3880ab
Packit Service 3880ab
static void
Packit Service 3880ab
usage(void)
Packit Service 3880ab
{
Packit Service 3880ab
	fprintf(stderr,
Packit Service 3880ab
		"Usage: ct clear\n"
Packit Service 3880ab
		"	ct commit [force] [zone ZONE] [mark MASKED_MARK] [label MASKED_LABEL] [nat NAT_SPEC]\n"
Packit Service 3880ab
		"	ct [nat] [zone ZONE]\n"
Packit Service 3880ab
		"Where: ZONE is the conntrack zone table number\n"
Packit Service 3880ab
		"	NAT_SPEC is {src|dst} addr addr1[-addr2] [port port1[-port2]]\n"
Packit Service 3880ab
		"\n");
Packit Service 3880ab
	exit(-1);
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int ct_parse_nat_addr_range(const char *str, struct nlmsghdr *n)
Packit Service 3880ab
{
Packit Service 3880ab
	inet_prefix addr = { .family = AF_UNSPEC, };
Packit Service 3880ab
	char *addr1, *addr2 = 0;
Packit Service 3880ab
	SPRINT_BUF(buffer);
Packit Service 3880ab
	int attr;
Packit Service 3880ab
	int ret;
Packit Service 3880ab
Packit Service 3880ab
	strncpy(buffer, str, sizeof(buffer) - 1);
Packit Service 3880ab
Packit Service 3880ab
	addr1 = buffer;
Packit Service 3880ab
	addr2 = strchr(addr1, '-');
Packit Service 3880ab
	if (addr2) {
Packit Service 3880ab
		*addr2 = '\0';
Packit Service 3880ab
		addr2++;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	ret = get_addr(&addr, addr1, AF_UNSPEC);
Packit Service 3880ab
	if (ret)
Packit Service 3880ab
		return ret;
Packit Service 3880ab
	attr = addr.family == AF_INET ? TCA_CT_NAT_IPV4_MIN :
Packit Service 3880ab
					TCA_CT_NAT_IPV6_MIN;
Packit Service 3880ab
	addattr_l(n, MAX_MSG, attr, addr.data, addr.bytelen);
Packit Service 3880ab
Packit Service 3880ab
	if (addr2) {
Packit Service 3880ab
		ret = get_addr(&addr, addr2, addr.family);
Packit Service 3880ab
		if (ret)
Packit Service 3880ab
			return ret;
Packit Service 3880ab
	}
Packit Service 3880ab
	attr = addr.family == AF_INET ? TCA_CT_NAT_IPV4_MAX :
Packit Service 3880ab
					TCA_CT_NAT_IPV6_MAX;
Packit Service 3880ab
	addattr_l(n, MAX_MSG, attr, addr.data, addr.bytelen);
Packit Service 3880ab
Packit Service 3880ab
	return 0;
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int ct_parse_nat_port_range(const char *str, struct nlmsghdr *n)
Packit Service 3880ab
{
Packit Service 3880ab
	char *port1, *port2 = 0;
Packit Service 3880ab
	SPRINT_BUF(buffer);
Packit Service 3880ab
	__be16 port;
Packit Service 3880ab
	int ret;
Packit Service 3880ab
Packit Service 3880ab
	strncpy(buffer, str, sizeof(buffer) - 1);
Packit Service 3880ab
Packit Service 3880ab
	port1 = buffer;
Packit Service 3880ab
	port2 = strchr(port1, '-');
Packit Service 3880ab
	if (port2) {
Packit Service 3880ab
		*port2 = '\0';
Packit Service 3880ab
		port2++;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	ret = get_be16(&port, port1, 10);
Packit Service 3880ab
	if (ret)
Packit Service 3880ab
		return -1;
Packit Service 3880ab
	addattr16(n, MAX_MSG, TCA_CT_NAT_PORT_MIN, port);
Packit Service 3880ab
Packit Service 3880ab
	if (port2) {
Packit Service 3880ab
		ret = get_be16(&port, port2, 10);
Packit Service 3880ab
		if (ret)
Packit Service 3880ab
			return -1;
Packit Service 3880ab
	}
Packit Service 3880ab
	addattr16(n, MAX_MSG, TCA_CT_NAT_PORT_MAX, port);
Packit Service 3880ab
Packit Service 3880ab
	return 0;
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
Packit Service 3880ab
static int ct_parse_u16(char *str, int value_type, int mask_type,
Packit Service 3880ab
			struct nlmsghdr *n)
Packit Service 3880ab
{
Packit Service 3880ab
	__u16 value, mask;
Packit Service 3880ab
	char *slash = 0;
Packit Service 3880ab
Packit Service 3880ab
	if (mask_type != TCA_CT_UNSPEC) {
Packit Service 3880ab
		slash = strchr(str, '/');
Packit Service 3880ab
		if (slash)
Packit Service 3880ab
			*slash = '\0';
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if (get_u16(&value, str, 0))
Packit Service 3880ab
		return -1;
Packit Service 3880ab
Packit Service 3880ab
	if (slash) {
Packit Service 3880ab
		if (get_u16(&mask, slash + 1, 0))
Packit Service 3880ab
			return -1;
Packit Service 3880ab
	} else {
Packit Service 3880ab
		mask = UINT16_MAX;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	addattr16(n, MAX_MSG, value_type, value);
Packit Service 3880ab
	if (mask_type != TCA_CT_UNSPEC)
Packit Service 3880ab
		addattr16(n, MAX_MSG, mask_type, mask);
Packit Service 3880ab
Packit Service 3880ab
	return 0;
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int ct_parse_u32(char *str, int value_type, int mask_type,
Packit Service 3880ab
			struct nlmsghdr *n)
Packit Service 3880ab
{
Packit Service 3880ab
	__u32 value, mask;
Packit Service 3880ab
	char *slash;
Packit Service 3880ab
Packit Service 3880ab
	slash = strchr(str, '/');
Packit Service 3880ab
	if (slash)
Packit Service 3880ab
		*slash = '\0';
Packit Service 3880ab
Packit Service 3880ab
	if (get_u32(&value, str, 0))
Packit Service 3880ab
		return -1;
Packit Service 3880ab
Packit Service 3880ab
	if (slash) {
Packit Service 3880ab
		if (get_u32(&mask, slash + 1, 0))
Packit Service 3880ab
			return -1;
Packit Service 3880ab
	} else {
Packit Service 3880ab
		mask = UINT32_MAX;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	addattr32(n, MAX_MSG, value_type, value);
Packit Service 3880ab
	addattr32(n, MAX_MSG, mask_type, mask);
Packit Service 3880ab
Packit Service 3880ab
	return 0;
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int ct_parse_mark(char *str, struct nlmsghdr *n)
Packit Service 3880ab
{
Packit Service 3880ab
	return ct_parse_u32(str, TCA_CT_MARK, TCA_CT_MARK_MASK, n);
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int ct_parse_labels(char *str, struct nlmsghdr *n)
Packit Service 3880ab
{
Packit Service 3880ab
#define LABELS_SIZE	16
Packit Service 3880ab
	uint8_t labels[LABELS_SIZE], lmask[LABELS_SIZE];
Packit Service 3880ab
	char *slash, *mask = NULL;
Packit Service 3880ab
	size_t slen, slen_mask = 0;
Packit Service 3880ab
Packit Service 3880ab
	slash = index(str, '/');
Packit Service 3880ab
	if (slash) {
Packit Service 3880ab
		*slash = 0;
Packit Service 3880ab
		mask = slash+1;
Packit Service 3880ab
		slen_mask = strlen(mask);
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	slen = strlen(str);
Packit Service 3880ab
	if (slen > LABELS_SIZE*2 || slen_mask > LABELS_SIZE*2) {
Packit Service 3880ab
		char errmsg[128];
Packit Service 3880ab
Packit Service 3880ab
		snprintf(errmsg, sizeof(errmsg),
Packit Service 3880ab
				"%zd Max allowed size %d",
Packit Service 3880ab
				slen, LABELS_SIZE*2);
Packit Service 3880ab
		invarg(errmsg, str);
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if (hex2mem(str, labels, slen/2) < 0)
Packit Service 3880ab
		invarg("ct: labels must be a hex string\n", str);
Packit Service 3880ab
	addattr_l(n, MAX_MSG, TCA_CT_LABELS, labels, slen/2);
Packit Service 3880ab
Packit Service 3880ab
	if (mask) {
Packit Service 3880ab
		if (hex2mem(mask, lmask, slen_mask/2) < 0)
Packit Service 3880ab
			invarg("ct: labels mask must be a hex string\n", mask);
Packit Service 3880ab
	} else {
Packit Service 3880ab
		memset(lmask, 0xff, sizeof(lmask));
Packit Service 3880ab
		slen_mask = sizeof(lmask)*2;
Packit Service 3880ab
	}
Packit Service 3880ab
	addattr_l(n, MAX_MSG, TCA_CT_LABELS_MASK, lmask, slen_mask/2);
Packit Service 3880ab
Packit Service 3880ab
	return 0;
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int
Packit Service 3880ab
parse_ct(struct action_util *a, int *argc_p, char ***argv_p, int tca_id,
Packit Service 3880ab
		struct nlmsghdr *n)
Packit Service 3880ab
{
Packit Service 3880ab
	struct tc_ct sel = {};
Packit Service 3880ab
	char **argv = *argv_p;
Packit Service 3880ab
	struct rtattr *tail;
Packit Service 3880ab
	int argc = *argc_p;
Packit Service 3880ab
	int ct_action = 0;
Packit Service 3880ab
	int ret;
Packit Service 3880ab
Packit Service 3880ab
	tail = addattr_nest(n, MAX_MSG, tca_id);
Packit Service 3880ab
Packit Service 3880ab
	if (argc && matches(*argv, "ct") == 0)
Packit Service 3880ab
		NEXT_ARG_FWD();
Packit Service 3880ab
Packit Service 3880ab
	while (argc > 0) {
Packit Service 3880ab
		if (matches(*argv, "zone") == 0) {
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
Packit Service 3880ab
			if (ct_parse_u16(*argv,
Packit Service 3880ab
					 TCA_CT_ZONE, TCA_CT_UNSPEC, n)) {
Packit Service 3880ab
				fprintf(stderr, "ct: Illegal \"zone\"\n");
Packit Service 3880ab
				return -1;
Packit Service 3880ab
			}
Packit Service 3880ab
		} else if (matches(*argv, "nat") == 0) {
Packit Service 3880ab
			ct_action |= TCA_CT_ACT_NAT;
Packit Service 3880ab
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
			if (matches(*argv, "src") == 0)
Packit Service 3880ab
				ct_action |= TCA_CT_ACT_NAT_SRC;
Packit Service 3880ab
			else if (matches(*argv, "dst") == 0)
Packit Service 3880ab
				ct_action |= TCA_CT_ACT_NAT_DST;
Packit Service 3880ab
			else
Packit Service 3880ab
				continue;
Packit Service 3880ab
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
			if (matches(*argv, "addr") != 0)
Packit Service 3880ab
				usage();
Packit Service 3880ab
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
			ret = ct_parse_nat_addr_range(*argv, n);
Packit Service 3880ab
			if (ret) {
Packit Service 3880ab
				fprintf(stderr, "ct: Illegal nat address range\n");
Packit Service 3880ab
				return -1;
Packit Service 3880ab
			}
Packit Service 3880ab
Packit Service 3880ab
			NEXT_ARG_FWD();
Packit Service 3880ab
			if (matches(*argv, "port") != 0)
Packit Service 3880ab
				continue;
Packit Service 3880ab
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
			ret = ct_parse_nat_port_range(*argv, n);
Packit Service 3880ab
			if (ret) {
Packit Service 3880ab
				fprintf(stderr, "ct: Illegal nat port range\n");
Packit Service 3880ab
				return -1;
Packit Service 3880ab
			}
Packit Service 3880ab
		} else if (matches(*argv, "clear") == 0) {
Packit Service 3880ab
			ct_action |= TCA_CT_ACT_CLEAR;
Packit Service 3880ab
		} else if (matches(*argv, "commit") == 0) {
Packit Service 3880ab
			ct_action |= TCA_CT_ACT_COMMIT;
Packit Service 3880ab
		} else if (matches(*argv, "force") == 0) {
Packit Service 3880ab
			ct_action |= TCA_CT_ACT_FORCE;
Packit Service 3880ab
		} else if (matches(*argv, "index") == 0) {
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
			if (get_u32(&sel.index, *argv, 10)) {
Packit Service 3880ab
				fprintf(stderr, "ct: Illegal \"index\"\n");
Packit Service 3880ab
				return -1;
Packit Service 3880ab
			}
Packit Service 3880ab
		} else if (matches(*argv, "mark") == 0) {
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
Packit Service 3880ab
			ret = ct_parse_mark(*argv, n);
Packit Service 3880ab
			if (ret) {
Packit Service 3880ab
				fprintf(stderr, "ct: Illegal \"mark\"\n");
Packit Service 3880ab
				return -1;
Packit Service 3880ab
			}
Packit Service 3880ab
		} else if (matches(*argv, "label") == 0) {
Packit Service 3880ab
			NEXT_ARG();
Packit Service 3880ab
Packit Service 3880ab
			ret = ct_parse_labels(*argv, n);
Packit Service 3880ab
			if (ret) {
Packit Service 3880ab
				fprintf(stderr, "ct: Illegal \"label\"\n");
Packit Service 3880ab
				return -1;
Packit Service 3880ab
			}
Packit Service 3880ab
		} else if (matches(*argv, "help") == 0) {
Packit Service 3880ab
			usage();
Packit Service 3880ab
		} else {
Packit Service 3880ab
			break;
Packit Service 3880ab
		}
Packit Service 3880ab
		NEXT_ARG_FWD();
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if (ct_action & TCA_CT_ACT_CLEAR &&
Packit Service 3880ab
	    ct_action & ~TCA_CT_ACT_CLEAR) {
Packit Service 3880ab
		fprintf(stderr, "ct: clear can only be used alone\n");
Packit Service 3880ab
		return -1;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if (ct_action & TCA_CT_ACT_NAT_SRC &&
Packit Service 3880ab
	    ct_action & TCA_CT_ACT_NAT_DST) {
Packit Service 3880ab
		fprintf(stderr, "ct: src and dst nat can't be used together\n");
Packit Service 3880ab
		return -1;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if ((ct_action & TCA_CT_ACT_COMMIT) &&
Packit Service 3880ab
	    (ct_action & TCA_CT_ACT_NAT) &&
Packit Service 3880ab
	    !(ct_action & (TCA_CT_ACT_NAT_SRC | TCA_CT_ACT_NAT_DST))) {
Packit Service 3880ab
		fprintf(stderr, "ct: commit and nat must set src or dst\n");
Packit Service 3880ab
		return -1;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if (!(ct_action & TCA_CT_ACT_COMMIT) &&
Packit Service 3880ab
	    (ct_action & (TCA_CT_ACT_NAT_SRC | TCA_CT_ACT_NAT_DST))) {
Packit Service 3880ab
		fprintf(stderr, "ct: src or dst is only valid if commit is set\n");
Packit Service 3880ab
		return -1;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	parse_action_control_dflt(&argc, &argv, &sel.action, false,
Packit Service 3880ab
				  TC_ACT_PIPE);
Packit Service 3880ab
Packit Service 3880ab
	addattr16(n, MAX_MSG, TCA_CT_ACTION, ct_action);
Packit Service 3880ab
	addattr_l(n, MAX_MSG, TCA_CT_PARMS, &sel, sizeof(sel));
Packit Service 3880ab
	addattr_nest_end(n, tail);
Packit Service 3880ab
Packit Service 3880ab
	*argc_p = argc;
Packit Service 3880ab
	*argv_p = argv;
Packit Service 3880ab
	return 0;
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int ct_sprint_port(char *buf, const char *prefix, struct rtattr *attr)
Packit Service 3880ab
{
Packit Service 3880ab
	if (!attr)
Packit Service 3880ab
		return 0;
Packit Service 3880ab
Packit Service 3880ab
	return sprintf(buf, "%s%d", prefix, rta_getattr_be16(attr));
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int ct_sprint_ip_addr(char *buf, const char *prefix,
Packit Service 3880ab
			     struct rtattr *attr)
Packit Service 3880ab
{
Packit Service 3880ab
	int family;
Packit Service 3880ab
	size_t len;
Packit Service 3880ab
Packit Service 3880ab
	if (!attr)
Packit Service 3880ab
		return 0;
Packit Service 3880ab
Packit Service 3880ab
	len = RTA_PAYLOAD(attr);
Packit Service 3880ab
Packit Service 3880ab
	if (len == 4)
Packit Service 3880ab
		family = AF_INET;
Packit Service 3880ab
	else if (len == 16)
Packit Service 3880ab
		family = AF_INET6;
Packit Service 3880ab
	else
Packit Service 3880ab
		return 0;
Packit Service 3880ab
Packit Service 3880ab
	return sprintf(buf, "%s%s", prefix, rt_addr_n2a_rta(family, attr));
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static void ct_print_nat(int ct_action, struct rtattr **tb)
Packit Service 3880ab
{
Packit Service 3880ab
	size_t done = 0;
Packit Service 3880ab
	char out[256] = "";
Packit Service 3880ab
	bool nat = false;
Packit Service 3880ab
Packit Service 3880ab
	if (!(ct_action & TCA_CT_ACT_NAT))
Packit Service 3880ab
		return;
Packit Service 3880ab
Packit Service 3880ab
	if (ct_action & TCA_CT_ACT_NAT_SRC) {
Packit Service 3880ab
		nat = true;
Packit Service 3880ab
		done += sprintf(out + done, "src");
Packit Service 3880ab
	} else if (ct_action & TCA_CT_ACT_NAT_DST) {
Packit Service 3880ab
		nat = true;
Packit Service 3880ab
		done += sprintf(out + done, "dst");
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if (nat) {
Packit Service 3880ab
		done += ct_sprint_ip_addr(out + done, " addr ",
Packit Service 3880ab
					  tb[TCA_CT_NAT_IPV4_MIN]);
Packit Service 3880ab
		done += ct_sprint_ip_addr(out + done, " addr ",
Packit Service 3880ab
					  tb[TCA_CT_NAT_IPV6_MIN]);
Packit Service 3880ab
		if (tb[TCA_CT_NAT_IPV4_MAX] &&
Packit Service 3880ab
		    memcmp(RTA_DATA(tb[TCA_CT_NAT_IPV4_MIN]),
Packit Service 3880ab
			   RTA_DATA(tb[TCA_CT_NAT_IPV4_MAX]), 4))
Packit Service 3880ab
			done += ct_sprint_ip_addr(out + done, "-",
Packit Service 3880ab
						  tb[TCA_CT_NAT_IPV4_MAX]);
Packit Service 3880ab
		else if (tb[TCA_CT_NAT_IPV6_MAX] &&
Packit Service 3880ab
			    memcmp(RTA_DATA(tb[TCA_CT_NAT_IPV6_MIN]),
Packit Service 3880ab
				   RTA_DATA(tb[TCA_CT_NAT_IPV6_MAX]), 16))
Packit Service 3880ab
			done += ct_sprint_ip_addr(out + done, "-",
Packit Service 3880ab
						  tb[TCA_CT_NAT_IPV6_MAX]);
Packit Service 3880ab
		done += ct_sprint_port(out + done, " port ",
Packit Service 3880ab
				       tb[TCA_CT_NAT_PORT_MIN]);
Packit Service 3880ab
		if (tb[TCA_CT_NAT_PORT_MAX] &&
Packit Service 3880ab
		    memcmp(RTA_DATA(tb[TCA_CT_NAT_PORT_MIN]),
Packit Service 3880ab
			   RTA_DATA(tb[TCA_CT_NAT_PORT_MAX]), 2))
Packit Service 3880ab
			done += ct_sprint_port(out + done, "-",
Packit Service 3880ab
					       tb[TCA_CT_NAT_PORT_MAX]);
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	if (done)
Packit Service 3880ab
		print_string(PRINT_ANY, "nat", " nat %s", out);
Packit Service 3880ab
	else
Packit Service 3880ab
		print_string(PRINT_ANY, "nat", " nat", "");
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static void ct_print_labels(struct rtattr *attr,
Packit Service 3880ab
			    struct rtattr *mask_attr)
Packit Service 3880ab
{
Packit Service 3880ab
	const unsigned char *str;
Packit Service 3880ab
	bool print_mask = false;
Packit Service 3880ab
	char out[256], *p;
Packit Service 3880ab
	int data_len, i;
Packit Service 3880ab
Packit Service 3880ab
	if (!attr)
Packit Service 3880ab
		return;
Packit Service 3880ab
Packit Service 3880ab
	data_len = RTA_PAYLOAD(attr);
Packit Service 3880ab
	hexstring_n2a(RTA_DATA(attr), data_len, out, sizeof(out));
Packit Service 3880ab
	p = out + data_len*2;
Packit Service 3880ab
Packit Service 3880ab
	data_len = RTA_PAYLOAD(attr);
Packit Service 3880ab
	str = RTA_DATA(mask_attr);
Packit Service 3880ab
	if (data_len != 16)
Packit Service 3880ab
		print_mask = true;
Packit Service 3880ab
	for (i = 0; !print_mask && i < data_len; i++) {
Packit Service 3880ab
		if (str[i] != 0xff)
Packit Service 3880ab
			print_mask = true;
Packit Service 3880ab
	}
Packit Service 3880ab
	if (print_mask) {
Packit Service 3880ab
		*p++ = '/';
Packit Service 3880ab
		hexstring_n2a(RTA_DATA(mask_attr), data_len, p,
Packit Service 3880ab
			      sizeof(out)-(p-out));
Packit Service 3880ab
		p += data_len*2;
Packit Service 3880ab
	}
Packit Service 3880ab
	*p = '\0';
Packit Service 3880ab
Packit Service 3880ab
	print_string(PRINT_ANY, "label", " label %s", out);
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
static int print_ct(struct action_util *au, FILE *f, struct rtattr *arg)
Packit Service 3880ab
{
Packit Service 3880ab
	struct rtattr *tb[TCA_CT_MAX + 1];
Packit Service 3880ab
	const char *commit;
Packit Service 3880ab
	struct tc_ct *p;
Packit Service 3880ab
	int ct_action = 0;
Packit Service 3880ab
Packit Service 3880ab
	if (arg == NULL)
Packit Service 3880ab
		return -1;
Packit Service 3880ab
Packit Service 3880ab
	parse_rtattr_nested(tb, TCA_CT_MAX, arg);
Packit Service 3880ab
	if (tb[TCA_CT_PARMS] == NULL) {
Packit Service 3880ab
		print_string(PRINT_FP, NULL, "%s", "[NULL ct parameters]");
Packit Service 3880ab
		return -1;
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	p = RTA_DATA(tb[TCA_CT_PARMS]);
Packit Service 3880ab
Packit Service 3880ab
	print_string(PRINT_ANY, "kind", "%s", "ct");
Packit Service 3880ab
Packit Service 3880ab
	if (tb[TCA_CT_ACTION])
Packit Service 3880ab
		ct_action = rta_getattr_u16(tb[TCA_CT_ACTION]);
Packit Service 3880ab
	if (ct_action & TCA_CT_ACT_COMMIT) {
Packit Service 3880ab
		commit = ct_action & TCA_CT_ACT_FORCE ?
Packit Service 3880ab
			 "commit force" : "commit";
Packit Service 3880ab
		print_string(PRINT_ANY, "action", " %s", commit);
Packit Service 3880ab
	} else if (ct_action & TCA_CT_ACT_CLEAR) {
Packit Service 3880ab
		print_string(PRINT_ANY, "action", " %s", "clear");
Packit Service 3880ab
	}
Packit Service 3880ab
Packit Service 3880ab
	print_masked_u32("mark", tb[TCA_CT_MARK], tb[TCA_CT_MARK_MASK], false);
Packit Service 3880ab
	print_masked_u16("zone", tb[TCA_CT_ZONE], NULL, false);
Packit Service 3880ab
	ct_print_labels(tb[TCA_CT_LABELS], tb[TCA_CT_LABELS_MASK]);
Packit Service 3880ab
	ct_print_nat(ct_action, tb);
Packit Service 3880ab
Packit Service 3880ab
	print_action_control(f, " ", p->action, "");
Packit Service 3880ab
Packit Service 3880ab
	print_nl();
Packit Service 3880ab
	print_uint(PRINT_ANY, "index", "\t index %u", p->index);
Packit Service 3880ab
	print_int(PRINT_ANY, "ref", " ref %d", p->refcnt);
Packit Service 3880ab
	print_int(PRINT_ANY, "bind", " bind %d", p->bindcnt);
Packit Service 3880ab
Packit Service 3880ab
	if (show_stats) {
Packit Service 3880ab
		if (tb[TCA_CT_TM]) {
Packit Service 3880ab
			struct tcf_t *tm = RTA_DATA(tb[TCA_CT_TM]);
Packit Service 3880ab
Packit Service 3880ab
			print_tm(f, tm);
Packit Service 3880ab
		}
Packit Service 3880ab
	}
Packit Service 3880ab
	print_nl();
Packit Service 3880ab
Packit Service 3880ab
	return 0;
Packit Service 3880ab
}
Packit Service 3880ab
Packit Service 3880ab
struct action_util ct_action_util = {
Packit Service 3880ab
	.id = "ct",
Packit Service 3880ab
	.parse_aopt = parse_ct,
Packit Service 3880ab
	.print_aopt = print_ct,
Packit Service 3880ab
};