|
Packit |
7b22a4 |
/* ebt_nflog
|
|
Packit |
7b22a4 |
*
|
|
Packit |
7b22a4 |
* Authors:
|
|
Packit |
7b22a4 |
* Peter Warasin <peter@endian.com>
|
|
Packit |
7b22a4 |
*
|
|
Packit |
7b22a4 |
* February, 2008
|
|
Packit |
7b22a4 |
*
|
|
Packit |
7b22a4 |
* Based on:
|
|
Packit |
7b22a4 |
* ebt_ulog.c, (C) 2004, Bart De Schuymer <bdschuym@pandora.be>
|
|
Packit |
7b22a4 |
* libxt_NFLOG.c
|
|
Packit |
7b22a4 |
*
|
|
Packit |
7b22a4 |
* Adapted to libxtables for ebtables-compat in 2015 by
|
|
Packit |
7b22a4 |
* Arturo Borrero Gonzalez <arturo@debian.org>
|
|
Packit |
7b22a4 |
*/
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
#include <stdio.h>
|
|
Packit |
7b22a4 |
#include <stdlib.h>
|
|
Packit |
7b22a4 |
#include <string.h>
|
|
Packit |
7b22a4 |
#include <getopt.h>
|
|
Packit |
7b22a4 |
#include <xtables.h>
|
|
Packit |
7b22a4 |
#include "iptables/nft.h"
|
|
Packit |
7b22a4 |
#include "iptables/nft-bridge.h"
|
|
Packit |
7b22a4 |
#include <linux/netfilter_bridge/ebt_nflog.h>
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
enum {
|
|
Packit |
7b22a4 |
NFLOG_GROUP = 0x1,
|
|
Packit |
7b22a4 |
NFLOG_PREFIX = 0x2,
|
|
Packit |
7b22a4 |
NFLOG_RANGE = 0x4,
|
|
Packit |
7b22a4 |
NFLOG_THRESHOLD = 0x8,
|
|
Packit |
7b22a4 |
NFLOG_NFLOG = 0x16,
|
|
Packit |
7b22a4 |
};
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static const struct option brnflog_opts[] = {
|
|
Packit |
7b22a4 |
{ .name = "nflog-group", .has_arg = true, .val = NFLOG_GROUP},
|
|
Packit |
7b22a4 |
{ .name = "nflog-prefix", .has_arg = true, .val = NFLOG_PREFIX},
|
|
Packit |
7b22a4 |
{ .name = "nflog-range", .has_arg = true, .val = NFLOG_RANGE},
|
|
Packit |
7b22a4 |
{ .name = "nflog-threshold", .has_arg = true, .val = NFLOG_THRESHOLD},
|
|
Packit |
7b22a4 |
{ .name = "nflog", .has_arg = false, .val = NFLOG_NFLOG},
|
|
Packit |
7b22a4 |
XT_GETOPT_TABLEEND,
|
|
Packit |
7b22a4 |
};
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static void brnflog_help(void)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
printf("nflog options:\n"
|
|
Packit |
7b22a4 |
"--nflog : use the default nflog parameters\n"
|
|
Packit |
7b22a4 |
"--nflog-prefix prefix : Prefix string for log message\n"
|
|
Packit |
7b22a4 |
"--nflog-group group : NETLINK group used for logging\n"
|
|
Packit |
7b22a4 |
"--nflog-range range : Number of byte to copy\n"
|
|
Packit |
7b22a4 |
"--nflog-threshold : Message threshold of"
|
|
Packit |
7b22a4 |
"in-kernel queue\n");
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static void brnflog_init(struct xt_entry_target *t)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
struct ebt_nflog_info *info = (struct ebt_nflog_info *)t->data;
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
info->prefix[0] = '\0';
|
|
Packit |
7b22a4 |
info->group = EBT_NFLOG_DEFAULT_GROUP;
|
|
Packit |
7b22a4 |
info->threshold = EBT_NFLOG_DEFAULT_THRESHOLD;
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static int brnflog_parse(int c, char **argv, int invert, unsigned int *flags,
|
|
Packit |
7b22a4 |
const void *entry, struct xt_entry_target **target)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
struct ebt_nflog_info *info = (struct ebt_nflog_info *)(*target)->data;
|
|
Packit |
7b22a4 |
unsigned int i;
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
if (invert)
|
|
Packit |
7b22a4 |
xtables_error(PARAMETER_PROBLEM,
|
|
Packit |
7b22a4 |
"The use of '!' makes no sense for the"
|
|
Packit |
7b22a4 |
" nflog watcher");
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
switch (c) {
|
|
Packit |
7b22a4 |
case NFLOG_PREFIX:
|
|
Packit |
7b22a4 |
EBT_CHECK_OPTION(flags, NFLOG_PREFIX);
|
|
Packit |
7b22a4 |
if (strlen(optarg) > EBT_NFLOG_PREFIX_SIZE - 1)
|
|
Packit |
7b22a4 |
xtables_error(PARAMETER_PROBLEM,
|
|
Packit |
7b22a4 |
"Prefix too long for nflog-prefix");
|
|
Packit |
7b22a4 |
strncpy(info->prefix, optarg, EBT_NFLOG_PREFIX_SIZE);
|
|
Packit |
7b22a4 |
break;
|
|
Packit |
7b22a4 |
case NFLOG_GROUP:
|
|
Packit |
7b22a4 |
EBT_CHECK_OPTION(flags, NFLOG_GROUP);
|
|
Packit |
7b22a4 |
if (!xtables_strtoui(optarg, NULL, &i, 1, UINT32_MAX))
|
|
Packit |
7b22a4 |
xtables_error(PARAMETER_PROBLEM,
|
|
Packit |
7b22a4 |
"--nflog-group must be a number!");
|
|
Packit |
7b22a4 |
info->group = i;
|
|
Packit |
7b22a4 |
break;
|
|
Packit |
7b22a4 |
case NFLOG_RANGE:
|
|
Packit |
7b22a4 |
EBT_CHECK_OPTION(flags, NFLOG_RANGE);
|
|
Packit |
7b22a4 |
if (!xtables_strtoui(optarg, NULL, &i, 1, UINT32_MAX))
|
|
Packit |
7b22a4 |
xtables_error(PARAMETER_PROBLEM,
|
|
Packit |
7b22a4 |
"--nflog-range must be a number!");
|
|
Packit |
7b22a4 |
info->len = i;
|
|
Packit |
7b22a4 |
break;
|
|
Packit |
7b22a4 |
case NFLOG_THRESHOLD:
|
|
Packit |
7b22a4 |
EBT_CHECK_OPTION(flags, NFLOG_THRESHOLD);
|
|
Packit |
7b22a4 |
if (!xtables_strtoui(optarg, NULL, &i, 1, UINT32_MAX))
|
|
Packit |
7b22a4 |
xtables_error(PARAMETER_PROBLEM,
|
|
Packit |
7b22a4 |
"--nflog-threshold must be a number!");
|
|
Packit |
7b22a4 |
info->threshold = i;
|
|
Packit |
7b22a4 |
break;
|
|
Packit |
7b22a4 |
case NFLOG_NFLOG:
|
|
Packit |
7b22a4 |
EBT_CHECK_OPTION(flags, NFLOG_NFLOG);
|
|
Packit |
7b22a4 |
break;
|
|
Packit |
7b22a4 |
default:
|
|
Packit |
7b22a4 |
return 0;
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
return 1;
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static void
|
|
Packit |
7b22a4 |
brnflog_print(const void *ip, const struct xt_entry_target *target,
|
|
Packit |
7b22a4 |
int numeric)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
struct ebt_nflog_info *info = (struct ebt_nflog_info *)target->data;
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
if (info->prefix[0] != '\0')
|
|
Packit |
7b22a4 |
printf("--nflog-prefix \"%s\" ", info->prefix);
|
|
Packit |
7b22a4 |
if (info->group)
|
|
Packit |
7b22a4 |
printf("--nflog-group %d ", info->group);
|
|
Packit |
7b22a4 |
if (info->len)
|
|
Packit |
7b22a4 |
printf("--nflog-range %d ", info->len);
|
|
Packit |
7b22a4 |
if (info->threshold != EBT_NFLOG_DEFAULT_THRESHOLD)
|
|
Packit |
7b22a4 |
printf("--nflog-threshold %d ", info->threshold);
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static int brnflog_xlate(struct xt_xlate *xl,
|
|
Packit |
7b22a4 |
const struct xt_xlate_tg_params *params)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
const struct ebt_nflog_info *info = (void *)params->target->data;
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
xt_xlate_add(xl, "log ");
|
|
Packit |
7b22a4 |
if (info->prefix[0] != '\0') {
|
|
Packit |
7b22a4 |
if (params->escape_quotes)
|
|
Packit |
7b22a4 |
xt_xlate_add(xl, "prefix \\\"%s\\\" ", info->prefix);
|
|
Packit |
7b22a4 |
else
|
|
Packit |
7b22a4 |
xt_xlate_add(xl, "prefix \"%s\" ", info->prefix);
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
xt_xlate_add(xl, "group %u ", info->group);
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
if (info->len)
|
|
Packit |
7b22a4 |
xt_xlate_add(xl, "snaplen %u ", info->len);
|
|
Packit |
7b22a4 |
if (info->threshold != EBT_NFLOG_DEFAULT_THRESHOLD)
|
|
Packit |
7b22a4 |
xt_xlate_add(xl, "queue-threshold %u ", info->threshold);
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
return 1;
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static struct xtables_target brnflog_watcher = {
|
|
Packit |
7b22a4 |
.name = "nflog",
|
|
Packit |
7b22a4 |
.revision = 0,
|
|
Packit |
7b22a4 |
.version = XTABLES_VERSION,
|
|
Packit |
7b22a4 |
.family = NFPROTO_BRIDGE,
|
|
Packit |
7b22a4 |
.size = XT_ALIGN(sizeof(struct ebt_nflog_info)),
|
|
Packit |
7b22a4 |
.userspacesize = XT_ALIGN(sizeof(struct ebt_nflog_info)),
|
|
Packit |
7b22a4 |
.init = brnflog_init,
|
|
Packit |
7b22a4 |
.help = brnflog_help,
|
|
Packit |
7b22a4 |
.parse = brnflog_parse,
|
|
Packit |
7b22a4 |
.print = brnflog_print,
|
|
Packit |
7b22a4 |
.xlate = brnflog_xlate,
|
|
Packit |
7b22a4 |
.extra_opts = brnflog_opts,
|
|
Packit |
7b22a4 |
};
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
void _init(void)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
xtables_register_target(&brnflog_watcher);
|
|
Packit |
7b22a4 |
}
|