Blame bootstrap_ver/extensions/libxt_rpfilter.c

Packit Service dd8e2b
#include <stdio.h>
Packit Service dd8e2b
#include <xtables.h>
Packit Service dd8e2b
#include <linux/netfilter/xt_rpfilter.h>
Packit Service dd8e2b
Packit Service dd8e2b
enum {
Packit Service dd8e2b
	O_RPF_LOOSE = 0,
Packit Service dd8e2b
	O_RPF_VMARK = 1,
Packit Service dd8e2b
	O_RPF_ACCEPT_LOCAL = 2,
Packit Service dd8e2b
	O_RPF_INVERT = 3,
Packit Service dd8e2b
};
Packit Service dd8e2b
Packit Service dd8e2b
static void rpfilter_help(void)
Packit Service dd8e2b
{
Packit Service dd8e2b
	printf(
Packit Service dd8e2b
"rpfilter match options:\n"
Packit Service dd8e2b
"    --loose          permit reverse path via any interface\n"
Packit Service dd8e2b
"    --validmark      use skb nfmark when performing route lookup\n"
Packit Service dd8e2b
"    --accept-local   do not reject packets with a local source address\n"
Packit Service dd8e2b
"    --invert         match packets that failed the reverse path test\n"
Packit Service dd8e2b
	);
Packit Service dd8e2b
}
Packit Service dd8e2b
Packit Service dd8e2b
static const struct xt_option_entry rpfilter_opts[] = {
Packit Service dd8e2b
	{.name = "loose", .id = O_RPF_LOOSE, .type = XTTYPE_NONE, },
Packit Service dd8e2b
	{.name = "validmark", .id = O_RPF_VMARK, .type = XTTYPE_NONE, },
Packit Service dd8e2b
	{.name = "accept-local", .id = O_RPF_ACCEPT_LOCAL, .type = XTTYPE_NONE, },
Packit Service dd8e2b
	{.name = "invert", .id = O_RPF_INVERT, .type = XTTYPE_NONE, },
Packit Service dd8e2b
	XTOPT_TABLEEND,
Packit Service dd8e2b
};
Packit Service dd8e2b
Packit Service dd8e2b
static void rpfilter_parse(struct xt_option_call *cb)
Packit Service dd8e2b
{
Packit Service dd8e2b
	struct xt_rpfilter_info *rpfinfo = cb->data;
Packit Service dd8e2b
Packit Service dd8e2b
	xtables_option_parse(cb);
Packit Service dd8e2b
	switch (cb->entry->id) {
Packit Service dd8e2b
	case O_RPF_LOOSE:
Packit Service dd8e2b
		rpfinfo->flags |= XT_RPFILTER_LOOSE;
Packit Service dd8e2b
		break;
Packit Service dd8e2b
	case O_RPF_VMARK:
Packit Service dd8e2b
		rpfinfo->flags |= XT_RPFILTER_VALID_MARK;
Packit Service dd8e2b
		break;
Packit Service dd8e2b
	case O_RPF_ACCEPT_LOCAL:
Packit Service dd8e2b
		rpfinfo->flags |= XT_RPFILTER_ACCEPT_LOCAL;
Packit Service dd8e2b
		break;
Packit Service dd8e2b
	case O_RPF_INVERT:
Packit Service dd8e2b
		rpfinfo->flags |= XT_RPFILTER_INVERT;
Packit Service dd8e2b
		break;
Packit Service dd8e2b
	}
Packit Service dd8e2b
}
Packit Service dd8e2b
Packit Service dd8e2b
static void
Packit Service dd8e2b
rpfilter_print_prefix(const void *ip, const void *matchinfo,
Packit Service dd8e2b
			const char *prefix)
Packit Service dd8e2b
{
Packit Service dd8e2b
	const struct xt_rpfilter_info *info = matchinfo;
Packit Service dd8e2b
	if (info->flags & XT_RPFILTER_LOOSE)
Packit Service dd8e2b
		printf(" %s%s", prefix, rpfilter_opts[O_RPF_LOOSE].name);
Packit Service dd8e2b
	if (info->flags & XT_RPFILTER_VALID_MARK)
Packit Service dd8e2b
		printf(" %s%s", prefix, rpfilter_opts[O_RPF_VMARK].name);
Packit Service dd8e2b
	if (info->flags & XT_RPFILTER_ACCEPT_LOCAL)
Packit Service dd8e2b
		printf(" %s%s", prefix, rpfilter_opts[O_RPF_ACCEPT_LOCAL].name);
Packit Service dd8e2b
	if (info->flags & XT_RPFILTER_INVERT)
Packit Service dd8e2b
		printf(" %s%s", prefix, rpfilter_opts[O_RPF_INVERT].name);
Packit Service dd8e2b
}
Packit Service dd8e2b
Packit Service dd8e2b
Packit Service dd8e2b
static void
Packit Service dd8e2b
rpfilter_print(const void *ip, const struct xt_entry_match *match, int numeric)
Packit Service dd8e2b
{
Packit Service dd8e2b
	printf(" rpfilter");
Packit Service dd8e2b
	return rpfilter_print_prefix(ip, match->data, "");
Packit Service dd8e2b
}
Packit Service dd8e2b
Packit Service dd8e2b
static void rpfilter_save(const void *ip, const struct xt_entry_match *match)
Packit Service dd8e2b
{
Packit Service dd8e2b
	return rpfilter_print_prefix(ip, match->data, "--");
Packit Service dd8e2b
}
Packit Service dd8e2b
Packit Service dd8e2b
static int rpfilter_xlate(struct xt_xlate *xl,
Packit Service dd8e2b
			  const struct xt_xlate_mt_params *params)
Packit Service dd8e2b
{
Packit Service dd8e2b
	const struct xt_rpfilter_info *info = (void *)params->match->data;
Packit Service dd8e2b
	bool invert = info->flags & XT_RPFILTER_INVERT;
Packit Service dd8e2b
Packit Service dd8e2b
	if (info->flags & XT_RPFILTER_ACCEPT_LOCAL) {
Packit Service dd8e2b
		if (invert)
Packit Service dd8e2b
			xt_xlate_add(xl, "fib saddr type != local ");
Packit Service dd8e2b
		else
Packit Service dd8e2b
			return 0;
Packit Service dd8e2b
	}
Packit Service dd8e2b
Packit Service dd8e2b
	xt_xlate_add(xl, "fib saddr ");
Packit Service dd8e2b
Packit Service dd8e2b
	if (info->flags & XT_RPFILTER_VALID_MARK)
Packit Service dd8e2b
		xt_xlate_add(xl, ". mark ");
Packit Service dd8e2b
	if (!(info->flags & XT_RPFILTER_LOOSE))
Packit Service dd8e2b
		xt_xlate_add(xl, ". iif ");
Packit Service dd8e2b
Packit Service dd8e2b
	xt_xlate_add(xl, "oif %s0", invert ? "" : "!= ");
Packit Service dd8e2b
Packit Service dd8e2b
	return 1;
Packit Service dd8e2b
}
Packit Service dd8e2b
Packit Service dd8e2b
static struct xtables_match rpfilter_match = {
Packit Service dd8e2b
	.family		= NFPROTO_UNSPEC,
Packit Service dd8e2b
	.name		= "rpfilter",
Packit Service dd8e2b
	.version	= XTABLES_VERSION,
Packit Service dd8e2b
	.size		= XT_ALIGN(sizeof(struct xt_rpfilter_info)),
Packit Service dd8e2b
	.userspacesize	= XT_ALIGN(sizeof(struct xt_rpfilter_info)),
Packit Service dd8e2b
	.help		= rpfilter_help,
Packit Service dd8e2b
	.print		= rpfilter_print,
Packit Service dd8e2b
	.save		= rpfilter_save,
Packit Service dd8e2b
	.x6_parse	= rpfilter_parse,
Packit Service dd8e2b
	.x6_options	= rpfilter_opts,
Packit Service dd8e2b
	.xlate		= rpfilter_xlate,
Packit Service dd8e2b
};
Packit Service dd8e2b
Packit Service dd8e2b
void _init(void)
Packit Service dd8e2b
{
Packit Service dd8e2b
	xtables_register_match(&rpfilter_match);
Packit Service dd8e2b
}