17 #include <arpa/inet.h> 19 #include <libmnl/libmnl.h> 20 #include <linux/netfilter/nf_tables.h> 21 #include <libnftnl/expr.h> 22 #include <libnftnl/rule.h> 25 enum nft_registers sreg;
26 enum nft_registers dreg;
27 enum nft_bitwise_ops op;
29 union nftnl_data_reg mask;
30 union nftnl_data_reg xor;
31 union nftnl_data_reg data;
35 nftnl_expr_bitwise_set(
struct nftnl_expr *e, uint16_t type,
36 const void *data, uint32_t data_len)
41 case NFTNL_EXPR_BITWISE_SREG:
42 memcpy(&bitwise->sreg, data,
sizeof(bitwise->sreg));
44 case NFTNL_EXPR_BITWISE_DREG:
45 memcpy(&bitwise->dreg, data,
sizeof(bitwise->dreg));
47 case NFTNL_EXPR_BITWISE_OP:
48 memcpy(&bitwise->op, data,
sizeof(bitwise->op));
50 case NFTNL_EXPR_BITWISE_LEN:
51 memcpy(&bitwise->len, data,
sizeof(bitwise->len));
53 case NFTNL_EXPR_BITWISE_MASK:
54 memcpy(&bitwise->mask.val, data, data_len);
55 bitwise->mask.len = data_len;
57 case NFTNL_EXPR_BITWISE_XOR:
58 memcpy(&bitwise->xor.val, data, data_len);
59 bitwise->xor.len = data_len;
61 case NFTNL_EXPR_BITWISE_DATA:
62 memcpy(&bitwise->data.val, data, data_len);
63 bitwise->data.len = data_len;
72 nftnl_expr_bitwise_get(
const struct nftnl_expr *e, uint16_t type,
78 case NFTNL_EXPR_BITWISE_SREG:
79 *data_len =
sizeof(bitwise->sreg);
80 return &bitwise->sreg;
81 case NFTNL_EXPR_BITWISE_DREG:
82 *data_len =
sizeof(bitwise->dreg);
83 return &bitwise->dreg;
84 case NFTNL_EXPR_BITWISE_OP:
85 *data_len =
sizeof(bitwise->op);
87 case NFTNL_EXPR_BITWISE_LEN:
88 *data_len =
sizeof(bitwise->len);
90 case NFTNL_EXPR_BITWISE_MASK:
91 *data_len = bitwise->mask.len;
92 return &bitwise->mask.val;
93 case NFTNL_EXPR_BITWISE_XOR:
94 *data_len = bitwise->xor.len;
95 return &bitwise->xor.val;
96 case NFTNL_EXPR_BITWISE_DATA:
97 *data_len = bitwise->data.len;
98 return &bitwise->data.val;
103 static int nftnl_expr_bitwise_cb(
const struct nlattr *attr,
void *data)
105 const struct nlattr **tb = data;
106 int type = mnl_attr_get_type(attr);
108 if (mnl_attr_type_valid(attr, NFTA_BITWISE_MAX) < 0)
112 case NFTA_BITWISE_SREG:
113 case NFTA_BITWISE_DREG:
114 case NFTA_BITWISE_OP:
115 case NFTA_BITWISE_LEN:
116 if (mnl_attr_validate(attr, MNL_TYPE_U32) < 0)
119 case NFTA_BITWISE_MASK:
120 case NFTA_BITWISE_XOR:
121 case NFTA_BITWISE_DATA:
122 if (mnl_attr_validate(attr, MNL_TYPE_BINARY) < 0)
132 nftnl_expr_bitwise_build(
struct nlmsghdr *nlh,
const struct nftnl_expr *e)
136 if (e->flags & (1 << NFTNL_EXPR_BITWISE_SREG))
137 mnl_attr_put_u32(nlh, NFTA_BITWISE_SREG, htonl(bitwise->sreg));
138 if (e->flags & (1 << NFTNL_EXPR_BITWISE_DREG))
139 mnl_attr_put_u32(nlh, NFTA_BITWISE_DREG, htonl(bitwise->dreg));
140 if (e->flags & (1 << NFTNL_EXPR_BITWISE_OP))
141 mnl_attr_put_u32(nlh, NFTA_BITWISE_OP, htonl(bitwise->op));
142 if (e->flags & (1 << NFTNL_EXPR_BITWISE_LEN))
143 mnl_attr_put_u32(nlh, NFTA_BITWISE_LEN, htonl(bitwise->len));
144 if (e->flags & (1 << NFTNL_EXPR_BITWISE_MASK)) {
147 nest = mnl_attr_nest_start(nlh, NFTA_BITWISE_MASK);
148 mnl_attr_put(nlh, NFTA_DATA_VALUE, bitwise->mask.len,
150 mnl_attr_nest_end(nlh, nest);
152 if (e->flags & (1 << NFTNL_EXPR_BITWISE_XOR)) {
155 nest = mnl_attr_nest_start(nlh, NFTA_BITWISE_XOR);
156 mnl_attr_put(nlh, NFTA_DATA_VALUE, bitwise->xor.len,
158 mnl_attr_nest_end(nlh, nest);
160 if (e->flags & (1 << NFTNL_EXPR_BITWISE_DATA)) {
163 nest = mnl_attr_nest_start(nlh, NFTA_BITWISE_DATA);
164 mnl_attr_put(nlh, NFTA_DATA_VALUE, bitwise->data.len,
166 mnl_attr_nest_end(nlh, nest);
171 nftnl_expr_bitwise_parse(
struct nftnl_expr *e,
struct nlattr *attr)
174 struct nlattr *tb[NFTA_BITWISE_MAX+1] = {};
177 if (mnl_attr_parse_nested(attr, nftnl_expr_bitwise_cb, tb) < 0)
180 if (tb[NFTA_BITWISE_SREG]) {
181 bitwise->sreg = ntohl(mnl_attr_get_u32(tb[NFTA_BITWISE_SREG]));
182 e->flags |= (1 << NFTNL_EXPR_BITWISE_SREG);
184 if (tb[NFTA_BITWISE_DREG]) {
185 bitwise->dreg = ntohl(mnl_attr_get_u32(tb[NFTA_BITWISE_DREG]));
186 e->flags |= (1 << NFTNL_EXPR_BITWISE_DREG);
188 if (tb[NFTA_BITWISE_OP]) {
189 bitwise->op = ntohl(mnl_attr_get_u32(tb[NFTA_BITWISE_OP]));
190 e->flags |= (1 << NFTNL_EXPR_BITWISE_OP);
192 if (tb[NFTA_BITWISE_LEN]) {
193 bitwise->len = ntohl(mnl_attr_get_u32(tb[NFTA_BITWISE_LEN]));
194 e->flags |= (1 << NFTNL_EXPR_BITWISE_LEN);
196 if (tb[NFTA_BITWISE_MASK]) {
197 ret = nftnl_parse_data(&bitwise->mask, tb[NFTA_BITWISE_MASK], NULL);
198 e->flags |= (1 << NFTA_BITWISE_MASK);
200 if (tb[NFTA_BITWISE_XOR]) {
201 ret = nftnl_parse_data(&bitwise->xor, tb[NFTA_BITWISE_XOR], NULL);
202 e->flags |= (1 << NFTA_BITWISE_XOR);
204 if (tb[NFTA_BITWISE_DATA]) {
205 ret = nftnl_parse_data(&bitwise->data, tb[NFTA_BITWISE_DATA], NULL);
206 e->flags |= (1 << NFTNL_EXPR_BITWISE_DATA);
213 nftnl_expr_bitwise_snprintf_bool(
char *buf,
size_t size,
216 int remain = size, offset = 0, ret;
218 ret = snprintf(buf, remain,
"reg %u = ( reg %u & ",
219 bitwise->dreg, bitwise->sreg);
220 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
222 ret = nftnl_data_reg_snprintf(buf + offset, remain, &bitwise->mask,
223 NFTNL_OUTPUT_DEFAULT, 0, DATA_VALUE);
224 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
226 ret = snprintf(buf + offset, remain,
") ^ ");
227 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
229 ret = nftnl_data_reg_snprintf(buf + offset, remain, &bitwise->xor,
230 NFTNL_OUTPUT_DEFAULT, 0, DATA_VALUE);
231 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
237 nftnl_expr_bitwise_snprintf_shift(
char *buf,
size_t size,
const char *op,
239 {
int remain = size, offset = 0, ret;
241 ret = snprintf(buf, remain,
"reg %u = ( reg %u %s ",
242 bitwise->dreg, bitwise->sreg, op);
243 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
245 ret = nftnl_data_reg_snprintf(buf + offset, remain, &bitwise->data,
246 NFTNL_OUTPUT_DEFAULT, 0, DATA_VALUE);
247 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
249 ret = snprintf(buf + offset, remain,
") ");
250 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
255 static int nftnl_expr_bitwise_snprintf_default(
char *buf,
size_t size,
256 const struct nftnl_expr *e)
261 switch (bitwise->op) {
262 case NFT_BITWISE_BOOL:
263 err = nftnl_expr_bitwise_snprintf_bool(buf, size, bitwise);
265 case NFT_BITWISE_LSHIFT:
266 err = nftnl_expr_bitwise_snprintf_shift(buf, size,
"<<", bitwise);
268 case NFT_BITWISE_RSHIFT:
269 err = nftnl_expr_bitwise_snprintf_shift(buf, size,
">>", bitwise);
277 nftnl_expr_bitwise_snprintf(
char *buf,
size_t size, uint32_t type,
278 uint32_t flags,
const struct nftnl_expr *e)
281 case NFTNL_OUTPUT_DEFAULT:
282 return nftnl_expr_bitwise_snprintf_default(buf, size, e);
289 struct expr_ops expr_ops_bitwise = {
292 .max_attr = NFTA_BITWISE_MAX,
293 .set = nftnl_expr_bitwise_set,
294 .get = nftnl_expr_bitwise_get,
295 .parse = nftnl_expr_bitwise_parse,
296 .build = nftnl_expr_bitwise_build,
297 .snprintf = nftnl_expr_bitwise_snprintf,