Blame extensions/libip6t_mh.c

Packit Service d1fe03
/* Shared library add-on to ip6tables to add mobility header support. */
Packit Service d1fe03
/*
Packit Service d1fe03
 * Copyright (C)2006 USAGI/WIDE Project
Packit Service d1fe03
 *
Packit Service d1fe03
 * This program is free software; you can redistribute it and/or modify
Packit Service d1fe03
 * it under the terms of the GNU General Public License version 2 as
Packit Service d1fe03
 * published by the Free Software Foundation.
Packit Service d1fe03
 *
Packit Service d1fe03
 * Author:
Packit Service d1fe03
 *	Masahide NAKAMURA @USAGI <masahide.nakamura.cz@hitachi.com>
Packit Service d1fe03
 *
Packit Service d1fe03
 * Based on libip6t_{icmpv6,udp}.c
Packit Service d1fe03
 */
Packit Service d1fe03
#include <stdint.h>
Packit Service d1fe03
#include <stdio.h>
Packit Service d1fe03
#include <string.h>
Packit Service d1fe03
#include <stdlib.h>
Packit Service d1fe03
#include <xtables.h>
Packit Service d1fe03
#include <linux/netfilter_ipv6/ip6t_mh.h>
Packit Service d1fe03
Packit Service d1fe03
enum {
Packit Service d1fe03
	O_MH_TYPE = 0,
Packit Service d1fe03
};
Packit Service d1fe03
Packit Service d1fe03
struct mh_name {
Packit Service d1fe03
	const char *name;
Packit Service d1fe03
	uint8_t type;
Packit Service d1fe03
};
Packit Service d1fe03
Packit Service d1fe03
static const struct mh_name mh_names[] = {
Packit Service d1fe03
	{ "binding-refresh-request", 0, },
Packit Service d1fe03
	/* Alias */ { "brr", 0, },
Packit Service d1fe03
	{ "home-test-init", 1, },
Packit Service d1fe03
	/* Alias */ { "hoti", 1, },
Packit Service d1fe03
	{ "careof-test-init", 2, },
Packit Service d1fe03
	/* Alias */ { "coti", 2, },
Packit Service d1fe03
	{ "home-test", 3, },
Packit Service d1fe03
	/* Alias */ { "hot", 3, },
Packit Service d1fe03
	{ "careof-test", 4, },
Packit Service d1fe03
	/* Alias */ { "cot", 4, },
Packit Service d1fe03
	{ "binding-update", 5, },
Packit Service d1fe03
	/* Alias */ { "bu", 5, },
Packit Service d1fe03
	{ "binding-acknowledgement", 6, },
Packit Service d1fe03
	/* Alias */ { "ba", 6, },
Packit Service d1fe03
	{ "binding-error", 7, },
Packit Service d1fe03
	/* Alias */ { "be", 7, },
Packit Service d1fe03
};
Packit Service d1fe03
Packit Service d1fe03
static void print_types_all(void)
Packit Service d1fe03
{
Packit Service d1fe03
	unsigned int i;
Packit Service d1fe03
	printf("Valid MH types:");
Packit Service d1fe03
Packit Service d1fe03
	for (i = 0; i < ARRAY_SIZE(mh_names); ++i) {
Packit Service d1fe03
		if (i && mh_names[i].type == mh_names[i-1].type)
Packit Service d1fe03
			printf(" (%s)", mh_names[i].name);
Packit Service d1fe03
		else
Packit Service d1fe03
			printf("\n%s", mh_names[i].name);
Packit Service d1fe03
	}
Packit Service d1fe03
	printf("\n");
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void mh_help(void)
Packit Service d1fe03
{
Packit Service d1fe03
	printf(
Packit Service d1fe03
"mh match options:\n"
Packit Service d1fe03
"[!] --mh-type type[:type]	match mh type\n");
Packit Service d1fe03
	print_types_all();
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void mh_init(struct xt_entry_match *m)
Packit Service d1fe03
{
Packit Service d1fe03
	struct ip6t_mh *mhinfo = (struct ip6t_mh *)m->data;
Packit Service d1fe03
Packit Service d1fe03
	mhinfo->types[1] = 0xFF;
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static unsigned int name_to_type(const char *name)
Packit Service d1fe03
{
Packit Service d1fe03
	int namelen = strlen(name);
Packit Service d1fe03
	static const unsigned int limit = ARRAY_SIZE(mh_names);
Packit Service d1fe03
	unsigned int match = limit;
Packit Service d1fe03
	unsigned int i;
Packit Service d1fe03
Packit Service d1fe03
	for (i = 0; i < limit; i++) {
Packit Service d1fe03
		if (strncasecmp(mh_names[i].name, name, namelen) == 0) {
Packit Service d1fe03
			int len = strlen(mh_names[i].name);
Packit Service d1fe03
			if (match == limit || len == namelen)
Packit Service d1fe03
				match = i;
Packit Service d1fe03
		}
Packit Service d1fe03
	}
Packit Service d1fe03
Packit Service d1fe03
	if (match != limit) {
Packit Service d1fe03
		return mh_names[match].type;
Packit Service d1fe03
	} else {
Packit Service d1fe03
		unsigned int number;
Packit Service d1fe03
Packit Service d1fe03
		if (!xtables_strtoui(name, NULL, &number, 0, UINT8_MAX))
Packit Service d1fe03
			xtables_error(PARAMETER_PROBLEM,
Packit Service d1fe03
				   "Invalid MH type `%s'\n", name);
Packit Service d1fe03
		return number;
Packit Service d1fe03
	}
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void parse_mh_types(const char *mhtype, uint8_t *types)
Packit Service d1fe03
{
Packit Service d1fe03
	char *buffer;
Packit Service d1fe03
	char *cp;
Packit Service d1fe03
Packit Service d1fe03
	buffer = strdup(mhtype);
Packit Service d1fe03
	if ((cp = strchr(buffer, ':')) == NULL)
Packit Service d1fe03
		types[0] = types[1] = name_to_type(buffer);
Packit Service d1fe03
	else {
Packit Service d1fe03
		*cp = '\0';
Packit Service d1fe03
		cp++;
Packit Service d1fe03
Packit Service d1fe03
		types[0] = buffer[0] ? name_to_type(buffer) : 0;
Packit Service d1fe03
		types[1] = cp[0] ? name_to_type(cp) : 0xFF;
Packit Service d1fe03
Packit Service d1fe03
		if (types[0] > types[1])
Packit Service d1fe03
			xtables_error(PARAMETER_PROBLEM,
Packit Service d1fe03
				   "Invalid MH type range (min > max)");
Packit Service d1fe03
	}
Packit Service d1fe03
	free(buffer);
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void mh_parse(struct xt_option_call *cb)
Packit Service d1fe03
{
Packit Service d1fe03
	struct ip6t_mh *mhinfo = cb->data;
Packit Service d1fe03
Packit Service d1fe03
	xtables_option_parse(cb);
Packit Service d1fe03
	parse_mh_types(cb->arg, mhinfo->types);
Packit Service d1fe03
	if (cb->invert)
Packit Service d1fe03
		mhinfo->invflags |= IP6T_MH_INV_TYPE;
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static const char *type_to_name(uint8_t type)
Packit Service d1fe03
{
Packit Service d1fe03
	unsigned int i;
Packit Service d1fe03
Packit Service d1fe03
	for (i = 0; i < ARRAY_SIZE(mh_names); ++i)
Packit Service d1fe03
		if (mh_names[i].type == type)
Packit Service d1fe03
			return mh_names[i].name;
Packit Service d1fe03
Packit Service d1fe03
	return NULL;
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void print_type(uint8_t type, int numeric)
Packit Service d1fe03
{
Packit Service d1fe03
	const char *name;
Packit Service d1fe03
	if (numeric || !(name = type_to_name(type)))
Packit Service d1fe03
		printf("%u", type);
Packit Service d1fe03
	else
Packit Service d1fe03
		printf("%s", name);
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void print_types(uint8_t min, uint8_t max, int invert, int numeric)
Packit Service d1fe03
{
Packit Service d1fe03
	const char *inv = invert ? "!" : "";
Packit Service d1fe03
Packit Service d1fe03
	if (min != 0 || max != 0xFF || invert) {
Packit Service d1fe03
		printf(" ");
Packit Service d1fe03
		if (min == max) {
Packit Service d1fe03
			printf("%s", inv);
Packit Service d1fe03
			print_type(min, numeric);
Packit Service d1fe03
		} else {
Packit Service d1fe03
			printf("%s", inv);
Packit Service d1fe03
			print_type(min, numeric);
Packit Service d1fe03
			printf(":");
Packit Service d1fe03
			print_type(max, numeric);
Packit Service d1fe03
		}
Packit Service d1fe03
	}
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void mh_print(const void *ip, const struct xt_entry_match *match,
Packit Service d1fe03
                     int numeric)
Packit Service d1fe03
{
Packit Service d1fe03
	const struct ip6t_mh *mhinfo = (struct ip6t_mh *)match->data;
Packit Service d1fe03
Packit Service d1fe03
	printf(" mh");
Packit Service d1fe03
	print_types(mhinfo->types[0], mhinfo->types[1],
Packit Service d1fe03
		    mhinfo->invflags & IP6T_MH_INV_TYPE,
Packit Service d1fe03
		    numeric);
Packit Service d1fe03
	if (mhinfo->invflags & ~IP6T_MH_INV_MASK)
Packit Service d1fe03
		printf(" Unknown invflags: 0x%X",
Packit Service d1fe03
		       mhinfo->invflags & ~IP6T_MH_INV_MASK);
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static void mh_save(const void *ip, const struct xt_entry_match *match)
Packit Service d1fe03
{
Packit Service d1fe03
	const struct ip6t_mh *mhinfo = (struct ip6t_mh *)match->data;
Packit Service d1fe03
Packit Service d1fe03
	if (mhinfo->types[0] == 0 && mhinfo->types[1] == 0xFF)
Packit Service d1fe03
		return;
Packit Service d1fe03
Packit Service d1fe03
	if (mhinfo->invflags & IP6T_MH_INV_TYPE)
Packit Service d1fe03
		printf(" !");
Packit Service d1fe03
Packit Service d1fe03
	if (mhinfo->types[0] != mhinfo->types[1])
Packit Service d1fe03
		printf(" --mh-type %u:%u", mhinfo->types[0], mhinfo->types[1]);
Packit Service d1fe03
	else
Packit Service d1fe03
		printf(" --mh-type %u", mhinfo->types[0]);
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static int mh_xlate(struct xt_xlate *xl,
Packit Service d1fe03
		    const struct xt_xlate_mt_params *params)
Packit Service d1fe03
{
Packit Service d1fe03
	const struct ip6t_mh *mhinfo = (struct ip6t_mh *)params->match->data;
Packit Service d1fe03
Packit Service d1fe03
	if (mhinfo->types[0] == 0 && mhinfo->types[1] == 0xff)
Packit Service d1fe03
		return 1;
Packit Service d1fe03
Packit Service d1fe03
	if (mhinfo->types[0] != mhinfo->types[1])
Packit Service d1fe03
		xt_xlate_add(xl, "mh type %s%u-%u",
Packit Service d1fe03
			     mhinfo->invflags & IP6T_MH_INV_TYPE ? "!= " : "",
Packit Service d1fe03
			     mhinfo->types[0], mhinfo->types[1]);
Packit Service d1fe03
	else
Packit Service d1fe03
		xt_xlate_add(xl, "mh type %s%u",
Packit Service d1fe03
			     mhinfo->invflags & IP6T_MH_INV_TYPE ? "!= " : "",
Packit Service d1fe03
			     mhinfo->types[0]);
Packit Service d1fe03
Packit Service d1fe03
	return 1;
Packit Service d1fe03
}
Packit Service d1fe03
Packit Service d1fe03
static const struct xt_option_entry mh_opts[] = {
Packit Service d1fe03
	{.name = "mh-type", .id = O_MH_TYPE, .type = XTTYPE_STRING,
Packit Service d1fe03
	 .flags = XTOPT_INVERT},
Packit Service d1fe03
	XTOPT_TABLEEND,
Packit Service d1fe03
};
Packit Service d1fe03
Packit Service d1fe03
static struct xtables_match mh_mt6_reg = {
Packit Service d1fe03
	.name		= "mh",
Packit Service d1fe03
	.version	= XTABLES_VERSION,
Packit Service d1fe03
	.family		= NFPROTO_IPV6,
Packit Service d1fe03
	.size		= XT_ALIGN(sizeof(struct ip6t_mh)),
Packit Service d1fe03
	.userspacesize	= XT_ALIGN(sizeof(struct ip6t_mh)),
Packit Service d1fe03
	.help		= mh_help,
Packit Service d1fe03
	.init		= mh_init,
Packit Service d1fe03
	.x6_parse	= mh_parse,
Packit Service d1fe03
	.print		= mh_print,
Packit Service d1fe03
	.save		= mh_save,
Packit Service d1fe03
	.x6_options	= mh_opts,
Packit Service d1fe03
	.xlate		= mh_xlate,
Packit Service d1fe03
};
Packit Service d1fe03
Packit Service d1fe03
void _init(void)
Packit Service d1fe03
{
Packit Service d1fe03
	xtables_register_match(&mh_mt6_reg);
Packit Service d1fe03
}