libnftnl  1.0.5
utils.c
1 /*
2  * (C) 2012-2013 by Pablo Neira Ayuso <pablo@netfilter.org>
3  * (C) 2013 by Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
4  *
5  * This program is free software; you can redistribute it and/or modify
6  * it under the terms of the GNU General Public License as published
7  * by the Free Software Foundation; either version 2 of the License, or
8  * (at your option) any later version.
9  */
10 
11 #include <internal.h>
12 #include <stdlib.h>
13 #include <string.h>
14 #include <limits.h>
15 #include <stdint.h>
16 #include <arpa/inet.h>
17 #include <errno.h>
18 #include <inttypes.h>
19 
20 #include <libnftnl/common.h>
21 
22 #include <linux/netfilter.h>
23 #include <linux/netfilter/nf_tables.h>
24 
25 static const char *const nftnl_family_str[NFPROTO_NUMPROTO] = {
26  [NFPROTO_INET] = "inet",
27  [NFPROTO_IPV4] = "ip",
28  [NFPROTO_ARP] = "arp",
29  [NFPROTO_BRIDGE] = "bridge",
30  [NFPROTO_IPV6] = "ip6",
31 };
32 
33 const char *nftnl_family2str(uint32_t family)
34 {
35  if (nftnl_family_str[family] == NULL)
36  return "unknown";
37 
38  return nftnl_family_str[family];
39 }
40 
41 int nftnl_str2family(const char *family)
42 {
43  int i;
44 
45  for (i = 0; i < NFPROTO_NUMPROTO; i++) {
46  if (nftnl_family_str[i] == NULL)
47  continue;
48 
49  if (strcmp(nftnl_family_str[i], family) == 0)
50  return i;
51  }
52 
53  errno = EAFNOSUPPORT;
54  return -1;
55 }
56 
57 static struct {
58  int len;
59  int64_t min;
60  uint64_t max;
61 } basetype[] = {
62  [NFTNL_TYPE_U8] = { .len = sizeof(uint8_t), .max = UINT8_MAX },
63  [NFTNL_TYPE_U16] = { .len = sizeof(uint16_t), .max = UINT16_MAX },
64  [NFTNL_TYPE_U32] = { .len = sizeof(uint32_t), .max = UINT32_MAX },
65  [NFTNL_TYPE_U64] = { .len = sizeof(uint64_t), .max = UINT64_MAX },
66  [NFTNL_TYPE_S8] = { .len = sizeof(int8_t), .min = INT8_MIN, .max = INT8_MAX },
67  [NFTNL_TYPE_S16] = { .len = sizeof(int16_t), .min = INT16_MIN, .max = INT16_MAX },
68  [NFTNL_TYPE_S32] = { .len = sizeof(int32_t), .min = INT32_MIN, .max = INT32_MAX },
69  [NFTNL_TYPE_S64] = { .len = sizeof(int64_t), .min = INT64_MIN, .max = INT64_MAX },
70 };
71 
72 int nftnl_get_value(enum nftnl_type type, void *val, void *out)
73 {
74  int64_t sval;
75  uint64_t uval;
76 
77  switch (type) {
78  case NFTNL_TYPE_U8:
79  case NFTNL_TYPE_U16:
80  case NFTNL_TYPE_U32:
81  case NFTNL_TYPE_U64:
82  uval = *((uint64_t *)val);
83  if (uval > basetype[type].max) {
84  errno = ERANGE;
85  return -1;
86  }
87  memcpy(out, &uval, basetype[type].len);
88  break;
89  case NFTNL_TYPE_S8:
90  case NFTNL_TYPE_S16:
91  case NFTNL_TYPE_S32:
92  case NFTNL_TYPE_S64:
93  sval = *((int64_t *)val);
94  if (sval < basetype[type].min ||
95  sval > (int64_t)basetype[type].max) {
96  errno = ERANGE;
97  return -1;
98  }
99  memcpy(out, &sval, basetype[type].len);
100  break;
101  }
102 
103  return 0;
104 }
105 
106 int nftnl_strtoi(const char *string, int base, void *out, enum nftnl_type type)
107 {
108  int ret;
109  int64_t sval = 0;
110  uint64_t uval = -1;
111  char *endptr;
112 
113  switch (type) {
114  case NFTNL_TYPE_U8:
115  case NFTNL_TYPE_U16:
116  case NFTNL_TYPE_U32:
117  case NFTNL_TYPE_U64:
118  uval = strtoll(string, &endptr, base);
119  ret = nftnl_get_value(type, &uval, out);
120  break;
121  case NFTNL_TYPE_S8:
122  case NFTNL_TYPE_S16:
123  case NFTNL_TYPE_S32:
124  case NFTNL_TYPE_S64:
125  sval = strtoull(string, &endptr, base);
126  ret = nftnl_get_value(type, &sval, out);
127  break;
128  default:
129  errno = EINVAL;
130  return -1;
131  }
132 
133  if (*endptr) {
134  errno = EINVAL;
135  return -1;
136  }
137 
138  return ret;
139 }
140 
141 const char *nftnl_verdict2str(uint32_t verdict)
142 {
143  switch (verdict) {
144  case NF_ACCEPT:
145  return "accept";
146  case NF_DROP:
147  return "drop";
148  case NFT_RETURN:
149  return "return";
150  case NFT_JUMP:
151  return "jump";
152  case NFT_GOTO:
153  return "goto";
154  default:
155  return "unknown";
156  }
157 }
158 
159 int nftnl_str2verdict(const char *verdict, int *verdict_num)
160 {
161  if (strcmp(verdict, "accept") == 0) {
162  *verdict_num = NF_ACCEPT;
163  return 0;
164  } else if (strcmp(verdict, "drop") == 0) {
165  *verdict_num = NF_DROP;
166  return 0;
167  } else if (strcmp(verdict, "return") == 0) {
168  *verdict_num = NFT_RETURN;
169  return 0;
170  } else if (strcmp(verdict, "jump") == 0) {
171  *verdict_num = NFT_JUMP;
172  return 0;
173  } else if (strcmp(verdict, "goto") == 0) {
174  *verdict_num = NFT_GOTO;
175  return 0;
176  }
177 
178  return -1;
179 }
180 
181 enum nftnl_cmd_type nftnl_flag2cmd(uint32_t flags)
182 {
183  if (flags & NFTNL_OF_EVENT_NEW)
184  return NFTNL_CMD_ADD;
185  else if (flags & NFTNL_OF_EVENT_DEL)
186  return NFTNL_CMD_DELETE;
187 
188  return NFTNL_CMD_UNSPEC;
189 }
190 
191 const char *cmd2tag[NFTNL_CMD_MAX] = {
192  [NFTNL_CMD_ADD] = ADD,
193  [NFTNL_CMD_INSERT] = INSERT,
194  [NFTNL_CMD_DELETE] = DELETE,
195  [NFTNL_CMD_REPLACE] = REPLACE,
196  [NFTNL_CMD_FLUSH] = FLUSH,
197 };
198 
199 const char *nftnl_cmd2tag(enum nftnl_cmd_type cmd)
200 {
201  if (cmd >= NFTNL_CMD_MAX)
202  return "unknown";
203 
204  return cmd2tag[cmd];
205 }
206 
207 uint32_t nftnl_str2cmd(const char *cmd)
208 {
209  if (strcmp(cmd, ADD) == 0)
210  return NFTNL_CMD_ADD;
211  else if (strcmp(cmd, INSERT) == 0)
212  return NFTNL_CMD_INSERT;
213  else if (strcmp(cmd, DELETE) == 0)
214  return NFTNL_CMD_DELETE;
215  else if (strcmp(cmd, REPLACE) == 0)
216  return NFTNL_CMD_REPLACE;
217  else if (strcmp(cmd, FLUSH) == 0)
218  return NFTNL_CMD_FLUSH;
219 
220  return NFTNL_CMD_UNSPEC;
221 }
222 
223 int nftnl_fprintf(FILE *fp, void *obj, uint32_t cmd, uint32_t type, uint32_t flags,
224  int (*snprintf_cb)(char *buf, size_t bufsiz, void *obj,
225  uint32_t cmd, uint32_t type, uint32_t flags))
226 {
227  char _buf[NFTNL_SNPRINTF_BUFSIZ];
228  char *buf = _buf;
229  size_t bufsiz = sizeof(_buf);
230  int ret;
231 
232  ret = snprintf_cb(buf, bufsiz, obj, cmd, type, flags);
233  if (ret <= 0)
234  goto out;
235 
236  if (ret >= NFTNL_SNPRINTF_BUFSIZ) {
237  bufsiz = ret + 1;
238 
239  buf = malloc(bufsiz);
240  if (buf == NULL)
241  return -1;
242 
243  ret = snprintf_cb(buf, bufsiz, obj, cmd, type, flags);
244  if (ret <= 0)
245  goto out;
246  }
247 
248  ret = fprintf(fp, "%s", buf);
249 
250 out:
251  if (buf != _buf)
252  xfree(buf);
253 
254  return ret;
255 }
256 
257 void __nftnl_assert_fail(uint16_t attr, const char *filename, int line)
258 {
259  fprintf(stderr, "libnftnl: attribute %d assertion failed in %s:%d\n",
260  attr, filename, line);
261  exit(EXIT_FAILURE);
262 }
263 
264 void __noreturn __abi_breakage(const char *file, int line, const char *reason)
265 {
266  fprintf(stderr, "nf_tables kernel ABI is broken, contact your vendor.\n"
267  "%s:%d reason: %s\n", file, line, reason);
268  exit(EXIT_FAILURE);
269 }