Blame extensions/libebt_nflog.c

Packit 7b22a4
/* ebt_nflog
Packit 7b22a4
 *
Packit 7b22a4
 * Authors:
Packit 7b22a4
 * Peter Warasin <peter@endian.com>
Packit 7b22a4
 *
Packit 7b22a4
 *  February, 2008
Packit 7b22a4
 *
Packit 7b22a4
 * Based on:
Packit 7b22a4
 *  ebt_ulog.c, (C) 2004, Bart De Schuymer <bdschuym@pandora.be>
Packit 7b22a4
 *  libxt_NFLOG.c
Packit 7b22a4
 *
Packit 7b22a4
 * Adapted to libxtables for ebtables-compat in 2015 by
Packit 7b22a4
 * Arturo Borrero Gonzalez <arturo@debian.org>
Packit 7b22a4
 */
Packit 7b22a4
Packit 7b22a4
#include <stdio.h>
Packit 7b22a4
#include <stdlib.h>
Packit 7b22a4
#include <string.h>
Packit 7b22a4
#include <getopt.h>
Packit 7b22a4
#include <xtables.h>
Packit 7b22a4
#include "iptables/nft.h"
Packit 7b22a4
#include "iptables/nft-bridge.h"
Packit 7b22a4
#include <linux/netfilter_bridge/ebt_nflog.h>
Packit 7b22a4
Packit 7b22a4
enum {
Packit 7b22a4
	NFLOG_GROUP	= 0x1,
Packit 7b22a4
	NFLOG_PREFIX	= 0x2,
Packit 7b22a4
	NFLOG_RANGE	= 0x4,
Packit 7b22a4
	NFLOG_THRESHOLD	= 0x8,
Packit 7b22a4
	NFLOG_NFLOG	= 0x16,
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
static const struct option brnflog_opts[] = {
Packit 7b22a4
	{ .name = "nflog-group",     .has_arg = true,  .val = NFLOG_GROUP},
Packit 7b22a4
	{ .name = "nflog-prefix",    .has_arg = true,  .val = NFLOG_PREFIX},
Packit 7b22a4
	{ .name = "nflog-range",     .has_arg = true,  .val = NFLOG_RANGE},
Packit 7b22a4
	{ .name = "nflog-threshold", .has_arg = true,  .val = NFLOG_THRESHOLD},
Packit 7b22a4
	{ .name = "nflog",           .has_arg = false, .val = NFLOG_NFLOG},
Packit 7b22a4
	XT_GETOPT_TABLEEND,
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
static void brnflog_help(void)
Packit 7b22a4
{
Packit 7b22a4
	printf("nflog options:\n"
Packit 7b22a4
	       "--nflog               : use the default nflog parameters\n"
Packit 7b22a4
	       "--nflog-prefix prefix : Prefix string for log message\n"
Packit 7b22a4
	       "--nflog-group group   : NETLINK group used for logging\n"
Packit 7b22a4
	       "--nflog-range range   : Number of byte to copy\n"
Packit 7b22a4
	       "--nflog-threshold     : Message threshold of"
Packit 7b22a4
	       "in-kernel queue\n");
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static void brnflog_init(struct xt_entry_target *t)
Packit 7b22a4
{
Packit 7b22a4
	struct ebt_nflog_info *info = (struct ebt_nflog_info *)t->data;
Packit 7b22a4
Packit 7b22a4
	info->prefix[0]	= '\0';
Packit 7b22a4
	info->group	= EBT_NFLOG_DEFAULT_GROUP;
Packit 7b22a4
	info->threshold = EBT_NFLOG_DEFAULT_THRESHOLD;
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static int brnflog_parse(int c, char **argv, int invert, unsigned int *flags,
Packit 7b22a4
			 const void *entry, struct xt_entry_target **target)
Packit 7b22a4
{
Packit 7b22a4
	struct ebt_nflog_info *info = (struct ebt_nflog_info *)(*target)->data;
Packit 7b22a4
	unsigned int i;
Packit 7b22a4
Packit 7b22a4
	if (invert)
Packit 7b22a4
		xtables_error(PARAMETER_PROBLEM,
Packit 7b22a4
			      "The use of '!' makes no sense for the"
Packit 7b22a4
			      " nflog watcher");
Packit 7b22a4
Packit 7b22a4
	switch (c) {
Packit 7b22a4
	case NFLOG_PREFIX:
Packit 7b22a4
		EBT_CHECK_OPTION(flags, NFLOG_PREFIX);
Packit 7b22a4
		if (strlen(optarg) > EBT_NFLOG_PREFIX_SIZE - 1)
Packit 7b22a4
			xtables_error(PARAMETER_PROBLEM,
Packit 7b22a4
				      "Prefix too long for nflog-prefix");
Packit 7b22a4
		strncpy(info->prefix, optarg, EBT_NFLOG_PREFIX_SIZE);
Packit 7b22a4
		break;
Packit 7b22a4
	case NFLOG_GROUP:
Packit 7b22a4
		EBT_CHECK_OPTION(flags, NFLOG_GROUP);
Packit 7b22a4
		if (!xtables_strtoui(optarg, NULL, &i, 1, UINT32_MAX))
Packit 7b22a4
			xtables_error(PARAMETER_PROBLEM,
Packit 7b22a4
				      "--nflog-group must be a number!");
Packit 7b22a4
		info->group = i;
Packit 7b22a4
		break;
Packit 7b22a4
	case NFLOG_RANGE:
Packit 7b22a4
		EBT_CHECK_OPTION(flags, NFLOG_RANGE);
Packit 7b22a4
		if (!xtables_strtoui(optarg, NULL, &i, 1, UINT32_MAX))
Packit 7b22a4
			xtables_error(PARAMETER_PROBLEM,
Packit 7b22a4
				      "--nflog-range must be a number!");
Packit 7b22a4
		info->len = i;
Packit 7b22a4
		break;
Packit 7b22a4
	case NFLOG_THRESHOLD:
Packit 7b22a4
		EBT_CHECK_OPTION(flags, NFLOG_THRESHOLD);
Packit 7b22a4
		if (!xtables_strtoui(optarg, NULL, &i, 1, UINT32_MAX))
Packit 7b22a4
			xtables_error(PARAMETER_PROBLEM,
Packit 7b22a4
				      "--nflog-threshold must be a number!");
Packit 7b22a4
		info->threshold = i;
Packit 7b22a4
		break;
Packit 7b22a4
	case NFLOG_NFLOG:
Packit 7b22a4
		EBT_CHECK_OPTION(flags, NFLOG_NFLOG);
Packit 7b22a4
		break;
Packit 7b22a4
	default:
Packit 7b22a4
		return 0;
Packit 7b22a4
	}
Packit 7b22a4
	return 1;
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static void
Packit 7b22a4
brnflog_print(const void *ip, const struct xt_entry_target *target,
Packit 7b22a4
	      int numeric)
Packit 7b22a4
{
Packit 7b22a4
	struct ebt_nflog_info *info = (struct ebt_nflog_info *)target->data;
Packit 7b22a4
Packit 7b22a4
	if (info->prefix[0] != '\0')
Packit 7b22a4
		printf("--nflog-prefix \"%s\" ", info->prefix);
Packit 7b22a4
	if (info->group)
Packit 7b22a4
		printf("--nflog-group %d ", info->group);
Packit 7b22a4
	if (info->len)
Packit 7b22a4
		printf("--nflog-range %d ", info->len);
Packit 7b22a4
	if (info->threshold != EBT_NFLOG_DEFAULT_THRESHOLD)
Packit 7b22a4
		printf("--nflog-threshold %d ", info->threshold);
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static int brnflog_xlate(struct xt_xlate *xl,
Packit 7b22a4
			 const struct xt_xlate_tg_params *params)
Packit 7b22a4
{
Packit 7b22a4
	const struct ebt_nflog_info *info = (void *)params->target->data;
Packit 7b22a4
Packit 7b22a4
	xt_xlate_add(xl, "log ");
Packit 7b22a4
	if (info->prefix[0] != '\0') {
Packit 7b22a4
		if (params->escape_quotes)
Packit 7b22a4
			xt_xlate_add(xl, "prefix \\\"%s\\\" ", info->prefix);
Packit 7b22a4
		else
Packit 7b22a4
			xt_xlate_add(xl, "prefix \"%s\" ", info->prefix);
Packit 7b22a4
	}
Packit 7b22a4
Packit 7b22a4
	xt_xlate_add(xl, "group %u ", info->group);
Packit 7b22a4
Packit 7b22a4
	if (info->len)
Packit 7b22a4
		xt_xlate_add(xl, "snaplen %u ", info->len);
Packit 7b22a4
	if (info->threshold != EBT_NFLOG_DEFAULT_THRESHOLD)
Packit 7b22a4
		xt_xlate_add(xl, "queue-threshold %u ", info->threshold);
Packit 7b22a4
Packit 7b22a4
	return 1;
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static struct xtables_target brnflog_watcher = {
Packit 7b22a4
	.name		= "nflog",
Packit 7b22a4
	.revision	= 0,
Packit 7b22a4
	.version	= XTABLES_VERSION,
Packit 7b22a4
	.family		= NFPROTO_BRIDGE,
Packit 7b22a4
	.size		= XT_ALIGN(sizeof(struct ebt_nflog_info)),
Packit 7b22a4
	.userspacesize	= XT_ALIGN(sizeof(struct ebt_nflog_info)),
Packit 7b22a4
	.init		= brnflog_init,
Packit 7b22a4
	.help		= brnflog_help,
Packit 7b22a4
	.parse		= brnflog_parse,
Packit 7b22a4
	.print		= brnflog_print,
Packit 7b22a4
	.xlate		= brnflog_xlate,
Packit 7b22a4
	.extra_opts	= brnflog_opts,
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
void _init(void)
Packit 7b22a4
{
Packit 7b22a4
	xtables_register_target(&brnflog_watcher);
Packit 7b22a4
}