|
Packit |
7b22a4 |
/*
|
|
Packit |
7b22a4 |
* Copyright (c) 2012-2013 Patrick McHardy <kaber@trash.net>
|
|
Packit |
7b22a4 |
*/
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
#include <stdio.h>
|
|
Packit |
7b22a4 |
#include <string.h>
|
|
Packit |
7b22a4 |
#include <xtables.h>
|
|
Packit |
7b22a4 |
#include <linux/netfilter_ipv6/ip6_tables.h>
|
|
Packit |
7b22a4 |
#include <linux/netfilter_ipv6/ip6t_NPT.h>
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
enum {
|
|
Packit |
7b22a4 |
O_SRC_PFX = 1 << 0,
|
|
Packit |
7b22a4 |
O_DST_PFX = 1 << 1,
|
|
Packit |
7b22a4 |
};
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static const struct xt_option_entry SNPT_options[] = {
|
|
Packit |
7b22a4 |
{ .name = "src-pfx", .id = O_SRC_PFX, .type = XTTYPE_HOSTMASK,
|
|
Packit |
7b22a4 |
.flags = XTOPT_MAND },
|
|
Packit |
7b22a4 |
{ .name = "dst-pfx", .id = O_DST_PFX, .type = XTTYPE_HOSTMASK,
|
|
Packit |
7b22a4 |
.flags = XTOPT_MAND },
|
|
Packit |
7b22a4 |
{ }
|
|
Packit |
7b22a4 |
};
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static void SNPT_help(void)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
printf("SNPT target options:"
|
|
Packit |
7b22a4 |
"\n"
|
|
Packit |
7b22a4 |
" --src-pfx prefix/length\n"
|
|
Packit |
7b22a4 |
" --dst-pfx prefix/length\n"
|
|
Packit |
7b22a4 |
"\n");
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static void SNPT_parse(struct xt_option_call *cb)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
struct ip6t_npt_tginfo *npt = cb->data;
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
xtables_option_parse(cb);
|
|
Packit |
7b22a4 |
switch (cb->entry->id) {
|
|
Packit |
7b22a4 |
case O_SRC_PFX:
|
|
Packit |
7b22a4 |
npt->src_pfx = cb->val.haddr;
|
|
Packit |
7b22a4 |
npt->src_pfx_len = cb->val.hlen;
|
|
Packit |
7b22a4 |
break;
|
|
Packit |
7b22a4 |
case O_DST_PFX:
|
|
Packit |
7b22a4 |
npt->dst_pfx = cb->val.haddr;
|
|
Packit |
7b22a4 |
npt->dst_pfx_len = cb->val.hlen;
|
|
Packit |
7b22a4 |
break;
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static void SNPT_print(const void *ip, const struct xt_entry_target *target,
|
|
Packit |
7b22a4 |
int numeric)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
const struct ip6t_npt_tginfo *npt = (const void *)target->data;
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
printf(" SNPT src-pfx %s/%u", xtables_ip6addr_to_numeric(&npt->src_pfx.in6),
|
|
Packit |
7b22a4 |
npt->src_pfx_len);
|
|
Packit |
7b22a4 |
printf(" dst-pfx %s/%u", xtables_ip6addr_to_numeric(&npt->dst_pfx.in6),
|
|
Packit |
7b22a4 |
npt->dst_pfx_len);
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static void SNPT_save(const void *ip, const struct xt_entry_target *target)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
static const struct in6_addr zero_addr;
|
|
Packit |
7b22a4 |
const struct ip6t_npt_tginfo *info = (const void *)target->data;
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
if (memcmp(&info->src_pfx.in6, &zero_addr, sizeof(zero_addr)) != 0 ||
|
|
Packit |
7b22a4 |
info->src_pfx_len != 0)
|
|
Packit |
7b22a4 |
printf(" --src-pfx %s/%u",
|
|
Packit |
7b22a4 |
xtables_ip6addr_to_numeric(&info->src_pfx.in6),
|
|
Packit |
7b22a4 |
info->src_pfx_len);
|
|
Packit |
7b22a4 |
if (memcmp(&info->dst_pfx.in6, &zero_addr, sizeof(zero_addr)) != 0 ||
|
|
Packit |
7b22a4 |
info->dst_pfx_len != 0)
|
|
Packit |
7b22a4 |
printf(" --dst-pfx %s/%u",
|
|
Packit |
7b22a4 |
xtables_ip6addr_to_numeric(&info->dst_pfx.in6),
|
|
Packit |
7b22a4 |
info->dst_pfx_len);
|
|
Packit |
7b22a4 |
}
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
static struct xtables_target snpt_tg_reg = {
|
|
Packit |
7b22a4 |
.name = "SNPT",
|
|
Packit |
7b22a4 |
.version = XTABLES_VERSION,
|
|
Packit |
7b22a4 |
.family = NFPROTO_IPV6,
|
|
Packit |
7b22a4 |
.size = XT_ALIGN(sizeof(struct ip6t_npt_tginfo)),
|
|
Packit |
7b22a4 |
.userspacesize = offsetof(struct ip6t_npt_tginfo, adjustment),
|
|
Packit |
7b22a4 |
.help = SNPT_help,
|
|
Packit |
7b22a4 |
.x6_parse = SNPT_parse,
|
|
Packit |
7b22a4 |
.print = SNPT_print,
|
|
Packit |
7b22a4 |
.save = SNPT_save,
|
|
Packit |
7b22a4 |
.x6_options = SNPT_options,
|
|
Packit |
7b22a4 |
};
|
|
Packit |
7b22a4 |
|
|
Packit |
7b22a4 |
void _init(void)
|
|
Packit |
7b22a4 |
{
|
|
Packit |
7b22a4 |
xtables_register_target(&snpt_tg_reg);
|
|
Packit |
7b22a4 |
}
|