Blame iptables/nft-shared.h

Packit 7b22a4
#ifndef _NFT_SHARED_H_
Packit 7b22a4
#define _NFT_SHARED_H_
Packit 7b22a4
Packit 7b22a4
#include <stdbool.h>
Packit 7b22a4
Packit 7b22a4
#include <libnftnl/rule.h>
Packit 7b22a4
#include <libnftnl/expr.h>
Packit 7b22a4
#include <libnftnl/chain.h>
Packit 7b22a4
Packit 7b22a4
#include <linux/netfilter_arp/arp_tables.h>
Packit Service bfea89
#include <linux/netfilter/nf_tables.h>
Packit 7b22a4
Packit 7b22a4
#include "xshared.h"
Packit 7b22a4
Packit 7b22a4
#ifdef DEBUG
Packit 7b22a4
#define NLDEBUG
Packit 7b22a4
#define DEBUG_DEL
Packit 7b22a4
#endif
Packit 7b22a4
Packit 7b22a4
/*
Packit 7b22a4
 * iptables print output emulation
Packit 7b22a4
 */
Packit 7b22a4
Packit 7b22a4
#define FMT_NUMERIC	0x0001
Packit 7b22a4
#define FMT_NOCOUNTS	0x0002
Packit 7b22a4
#define FMT_KILOMEGAGIGA 0x0004
Packit 7b22a4
#define FMT_OPTIONS	0x0008
Packit 7b22a4
#define FMT_NOTABLE	0x0010
Packit 7b22a4
#define FMT_NOTARGET	0x0020
Packit 7b22a4
#define FMT_VIA		0x0040
Packit 7b22a4
#define FMT_NONEWLINE	0x0080
Packit 7b22a4
#define FMT_LINENUMBERS 0x0100
Packit 7b22a4
Packit 7b22a4
#define FMT_PRINT_RULE (FMT_NOCOUNTS | FMT_OPTIONS | FMT_VIA \
Packit 7b22a4
			| FMT_NUMERIC | FMT_NOTABLE)
Packit 7b22a4
#define FMT(tab,notab) ((format) & FMT_NOTABLE ? (notab) : (tab))
Packit 7b22a4
Packit 7b22a4
struct xtables_args;
Packit 7b22a4
struct nft_handle;
Packit 7b22a4
struct xt_xlate;
Packit 7b22a4
Packit 7b22a4
enum {
Packit 7b22a4
	NFT_XT_CTX_PAYLOAD	= (1 << 0),
Packit 7b22a4
	NFT_XT_CTX_META		= (1 << 1),
Packit 7b22a4
	NFT_XT_CTX_BITWISE	= (1 << 2),
Packit 7b22a4
	NFT_XT_CTX_IMMEDIATE	= (1 << 3),
Packit 7b22a4
	NFT_XT_CTX_PREV_PAYLOAD	= (1 << 4),
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
struct nft_xt_ctx {
Packit 7b22a4
	struct iptables_command_state *cs;
Packit 7b22a4
	struct nftnl_expr_iter *iter;
Packit 7b22a4
	struct nft_handle *h;
Packit 7b22a4
	uint32_t flags;
Packit 7b22a4
	const char *table;
Packit 7b22a4
Packit 7b22a4
	uint32_t reg;
Packit 7b22a4
	struct {
Packit 7b22a4
		uint32_t base;
Packit 7b22a4
		uint32_t offset;
Packit 7b22a4
		uint32_t len;
Packit 7b22a4
	} payload, prev_payload;
Packit 7b22a4
	struct {
Packit 7b22a4
		uint32_t key;
Packit 7b22a4
	} meta;
Packit 7b22a4
	struct {
Packit 7b22a4
		uint32_t data[4];
Packit 7b22a4
		uint32_t len, reg;
Packit 7b22a4
	} immediate;
Packit 7b22a4
	struct {
Packit 7b22a4
		uint32_t mask[4];
Packit 7b22a4
		uint32_t xor[4];
Packit 7b22a4
	} bitwise;
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
struct nft_family_ops {
Packit 7b22a4
	int (*add)(struct nft_handle *h, struct nftnl_rule *r, void *data);
Packit 7b22a4
	bool (*is_same)(const void *data_a,
Packit 7b22a4
			const void *data_b);
Packit 7b22a4
	void (*print_payload)(struct nftnl_expr *e,
Packit 7b22a4
			      struct nftnl_expr_iter *iter);
Packit 7b22a4
	void (*parse_meta)(struct nft_xt_ctx *ctx, struct nftnl_expr *e,
Packit 7b22a4
			   void *data);
Packit 7b22a4
	void (*parse_payload)(struct nft_xt_ctx *ctx, struct nftnl_expr *e,
Packit 7b22a4
			      void *data);
Packit 7b22a4
	void (*parse_bitwise)(struct nft_xt_ctx *ctx, struct nftnl_expr *e,
Packit 7b22a4
			      void *data);
Packit 7b22a4
	void (*parse_cmp)(struct nft_xt_ctx *ctx, struct nftnl_expr *e,
Packit 7b22a4
			  void *data);
Packit 7b22a4
	void (*parse_lookup)(struct nft_xt_ctx *ctx, struct nftnl_expr *e,
Packit 7b22a4
			     void *data);
Packit 7b22a4
	void (*parse_immediate)(const char *jumpto, bool nft_goto, void *data);
Packit 7b22a4
Packit 7b22a4
	void (*print_table_header)(const char *tablename);
Packit 7b22a4
	void (*print_header)(unsigned int format, const char *chain,
Packit 7b22a4
			     const char *pol,
Packit 7b22a4
			     const struct xt_counters *counters, bool basechain,
Packit 7b22a4
			     uint32_t refs, uint32_t entries);
Packit 7b22a4
	void (*print_rule)(struct nft_handle *h, struct nftnl_rule *r,
Packit 7b22a4
			   unsigned int num, unsigned int format);
Packit 7b22a4
	void (*save_rule)(const void *data, unsigned int format);
Packit 7b22a4
	void (*save_counters)(const void *data);
Packit 7b22a4
	void (*save_chain)(const struct nftnl_chain *c, const char *policy);
Packit 7b22a4
	void (*proto_parse)(struct iptables_command_state *cs,
Packit 7b22a4
			    struct xtables_args *args);
Packit 7b22a4
	void (*post_parse)(int command, struct iptables_command_state *cs,
Packit 7b22a4
			   struct xtables_args *args);
Packit 7b22a4
	void (*parse_match)(struct xtables_match *m, void *data);
Packit 7b22a4
	void (*parse_target)(struct xtables_target *t, void *data);
Packit 7b22a4
	void (*rule_to_cs)(struct nft_handle *h, const struct nftnl_rule *r,
Packit 7b22a4
			   struct iptables_command_state *cs);
Packit 7b22a4
	void (*clear_cs)(struct iptables_command_state *cs);
Packit 7b22a4
	bool (*rule_find)(struct nft_handle *h, struct nftnl_rule *r,
Packit 7b22a4
			  void *data);
Packit 7b22a4
	int (*xlate)(const void *data, struct xt_xlate *xl);
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
void add_meta(struct nftnl_rule *r, uint32_t key);
Packit 7b22a4
void add_payload(struct nftnl_rule *r, int offset, int len, uint32_t base);
Packit 7b22a4
void add_bitwise(struct nftnl_rule *r, uint8_t *mask, size_t len);
Packit 7b22a4
void add_bitwise_u16(struct nftnl_rule *r, uint16_t mask, uint16_t xor);
Packit 7b22a4
void add_cmp_ptr(struct nftnl_rule *r, uint32_t op, void *data, size_t len);
Packit 7b22a4
void add_cmp_u8(struct nftnl_rule *r, uint8_t val, uint32_t op);
Packit 7b22a4
void add_cmp_u16(struct nftnl_rule *r, uint16_t val, uint32_t op);
Packit 7b22a4
void add_cmp_u32(struct nftnl_rule *r, uint32_t val, uint32_t op);
Packit 7b22a4
void add_iniface(struct nftnl_rule *r, char *iface, uint32_t op);
Packit 7b22a4
void add_outiface(struct nftnl_rule *r, char *iface, uint32_t op);
Packit Service bfea89
void add_addr(struct nftnl_rule *r, enum nft_payload_bases base, int offset,
Packit 7b22a4
	      void *data, void *mask, size_t len, uint32_t op);
Packit 7b22a4
void add_proto(struct nftnl_rule *r, int offset, size_t len,
Packit 7b22a4
	       uint8_t proto, uint32_t op);
Packit 7b22a4
void add_l4proto(struct nftnl_rule *r, uint8_t proto, uint32_t op);
Packit 7b22a4
void add_compat(struct nftnl_rule *r, uint32_t proto, bool inv);
Packit 7b22a4
Packit 7b22a4
bool is_same_interfaces(const char *a_iniface, const char *a_outiface,
Packit 7b22a4
			unsigned const char *a_iniface_mask,
Packit 7b22a4
			unsigned const char *a_outiface_mask,
Packit 7b22a4
			const char *b_iniface, const char *b_outiface,
Packit 7b22a4
			unsigned const char *b_iniface_mask,
Packit 7b22a4
			unsigned const char *b_outiface_mask);
Packit 7b22a4
Packit 7b22a4
int parse_meta(struct nftnl_expr *e, uint8_t key, char *iniface,
Packit 7b22a4
		unsigned char *iniface_mask, char *outiface,
Packit 7b22a4
		unsigned char *outiface_mask, uint8_t *invflags);
Packit 7b22a4
void print_proto(uint16_t proto, int invert);
Packit 7b22a4
void get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, bool *inv);
Packit 7b22a4
void nft_rule_to_iptables_command_state(struct nft_handle *h,
Packit 7b22a4
					const struct nftnl_rule *r,
Packit 7b22a4
					struct iptables_command_state *cs);
Packit 7b22a4
void nft_clear_iptables_command_state(struct iptables_command_state *cs);
Packit 7b22a4
void print_header(unsigned int format, const char *chain, const char *pol,
Packit 7b22a4
		  const struct xt_counters *counters, bool basechain,
Packit 7b22a4
		  uint32_t refs, uint32_t entries);
Packit 7b22a4
void print_rule_details(const struct iptables_command_state *cs,
Packit 7b22a4
			const char *targname, uint8_t flags,
Packit 7b22a4
			uint8_t invflags, uint8_t proto,
Packit 7b22a4
			unsigned int num, unsigned int format);
Packit 7b22a4
void print_matches_and_target(struct iptables_command_state *cs,
Packit 7b22a4
			      unsigned int format);
Packit 7b22a4
void save_rule_details(const struct iptables_command_state *cs,
Packit 7b22a4
		       uint8_t invflags, uint16_t proto,
Packit 7b22a4
		       const char *iniface,
Packit 7b22a4
		       unsigned const char *iniface_mask,
Packit 7b22a4
		       const char *outiface,
Packit 7b22a4
		       unsigned const char *outiface_mask);
Packit 7b22a4
void save_counters(const void *data);
Packit 7b22a4
void nft_ipv46_save_chain(const struct nftnl_chain *c, const char *policy);
Packit 7b22a4
void save_matches_and_target(const struct iptables_command_state *cs,
Packit 7b22a4
			     bool goto_flag, const void *fw,
Packit 7b22a4
			     unsigned int format);
Packit 7b22a4
Packit 7b22a4
struct nft_family_ops *nft_family_ops_lookup(int family);
Packit 7b22a4
Packit 7b22a4
void nft_ipv46_parse_target(struct xtables_target *t, void *data);
Packit 7b22a4
bool nft_ipv46_rule_find(struct nft_handle *h, struct nftnl_rule *r,
Packit 7b22a4
			 void *data);
Packit 7b22a4
Packit 7b22a4
bool compare_matches(struct xtables_rule_match *mt1, struct xtables_rule_match *mt2);
Packit 7b22a4
bool compare_targets(struct xtables_target *tg1, struct xtables_target *tg2);
Packit 7b22a4
Packit 7b22a4
struct addr_mask {
Packit 7b22a4
	union {
Packit 7b22a4
		struct in_addr	*v4;
Packit 7b22a4
		struct in6_addr *v6;
Packit 7b22a4
	} addr;
Packit 7b22a4
Packit 7b22a4
	unsigned int naddrs;
Packit 7b22a4
Packit 7b22a4
	union {
Packit 7b22a4
		struct in_addr	*v4;
Packit 7b22a4
		struct in6_addr *v6;
Packit 7b22a4
	} mask;
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
struct xtables_args {
Packit 7b22a4
	int		family;
Packit 7b22a4
	uint16_t	proto;
Packit 7b22a4
	uint8_t		flags;
Packit 7b22a4
	uint8_t		invflags;
Packit 7b22a4
	char		iniface[IFNAMSIZ], outiface[IFNAMSIZ];
Packit 7b22a4
	unsigned char	iniface_mask[IFNAMSIZ], outiface_mask[IFNAMSIZ];
Packit 7b22a4
	bool		goto_set;
Packit 7b22a4
	const char	*shostnetworkmask, *dhostnetworkmask;
Packit 7b22a4
	const char	*pcnt, *bcnt;
Packit 7b22a4
	struct addr_mask s, d;
Packit 7b22a4
	unsigned long long pcnt_cnt, bcnt_cnt;
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
struct nft_xt_cmd_parse {
Packit 7b22a4
	unsigned int			command;
Packit 7b22a4
	unsigned int			rulenum;
Packit 7b22a4
	char				*table;
Packit 7b22a4
	const char			*chain;
Packit 7b22a4
	const char			*newname;
Packit 7b22a4
	const char			*policy;
Packit 7b22a4
	bool				restore;
Packit 7b22a4
	int				verbose;
Packit 7b22a4
	bool				xlate;
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
void do_parse(struct nft_handle *h, int argc, char *argv[],
Packit 7b22a4
	      struct nft_xt_cmd_parse *p, struct iptables_command_state *cs,
Packit 7b22a4
	      struct xtables_args *args);
Packit 7b22a4
Packit 7b22a4
struct nftnl_chain_list;
Packit 7b22a4
Packit 7b22a4
struct nft_xt_restore_cb {
Packit 7b22a4
	void (*table_new)(struct nft_handle *h, const char *table);
Packit 7b22a4
	int (*chain_set)(struct nft_handle *h, const char *table,
Packit 7b22a4
			 const char *chain, const char *policy,
Packit 7b22a4
			 const struct xt_counters *counters);
Packit 7b22a4
	int (*chain_restore)(struct nft_handle *h, const char *chain,
Packit 7b22a4
			     const char *table);
Packit 7b22a4
Packit 7b22a4
	int (*table_flush)(struct nft_handle *h, const char *table);
Packit 7b22a4
Packit 7b22a4
	int (*do_command)(struct nft_handle *h, int argc, char *argv[],
Packit 7b22a4
			  char **table, bool restore);
Packit 7b22a4
Packit 7b22a4
	int (*commit)(struct nft_handle *h);
Packit 7b22a4
	int (*abort)(struct nft_handle *h);
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
struct nft_xt_restore_parse {
Packit 7b22a4
	FILE				*in;
Packit 7b22a4
	int				testing;
Packit 7b22a4
	const char			*tablename;
Packit 7b22a4
	bool				commit;
Packit 7b22a4
	const struct nft_xt_restore_cb	*cb;
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
void xtables_restore_parse(struct nft_handle *h,
Packit 7b22a4
			   const struct nft_xt_restore_parse *p);
Packit 7b22a4
Packit 7b22a4
void nft_check_xt_legacy(int family, bool is_ipt_save);
Packit Service a6c5f4
Packit Service a6c5f4
#define min(x, y) ((x) < (y) ? (x) : (y))
Packit Service a6c5f4
#define max(x, y) ((x) > (y) ? (x) : (y))
Packit Service a6c5f4
Packit 7b22a4
#endif