libnftnl  1.0.5
lookup.c
1 /*
2  * (C) 2012-2013 by Pablo Neira Ayuso <pablo@netfilter.org>
3  *
4  * This program is free software; you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License as published
6  * by the Free Software Foundation; either version 2 of the License, or
7  * (at your option) any later version.
8  *
9  * This code has been sponsored by Sophos Astaro <http://www.sophos.com>
10  */
11 
12 #include "internal.h"
13 
14 #include <stdio.h>
15 #include <stdint.h>
16 #include <string.h> /* for memcpy */
17 #include <arpa/inet.h>
18 #include <errno.h>
19 #include <libmnl/libmnl.h>
20 #include <linux/netfilter/nf_tables.h>
21 #include <libnftnl/rule.h>
22 #include <libnftnl/expr.h>
23 
24 #ifndef IFNAMSIZ
25 #define IFNAMSIZ 16
26 #endif
27 
29  enum nft_registers sreg;
30  enum nft_registers dreg;
31  char set_name[IFNAMSIZ];
32  uint32_t set_id;
33 };
34 
35 static int
36 nftnl_expr_lookup_set(struct nftnl_expr *e, uint16_t type,
37  const void *data, uint32_t data_len)
38 {
39  struct nftnl_expr_lookup *lookup = nftnl_expr_data(e);
40 
41  switch(type) {
42  case NFTNL_EXPR_LOOKUP_SREG:
43  lookup->sreg = *((uint32_t *)data);
44  break;
45  case NFTNL_EXPR_LOOKUP_DREG:
46  lookup->dreg = *((uint32_t *)data);
47  break;
48  case NFTNL_EXPR_LOOKUP_SET:
49  snprintf(lookup->set_name, sizeof(lookup->set_name), "%s",
50  (const char *)data);
51  break;
52  case NFTNL_EXPR_LOOKUP_SET_ID:
53  lookup->set_id = *((uint32_t *)data);
54  break;
55  default:
56  return -1;
57  }
58  return 0;
59 }
60 
61 static const void *
62 nftnl_expr_lookup_get(const struct nftnl_expr *e, uint16_t type,
63  uint32_t *data_len)
64 {
65  struct nftnl_expr_lookup *lookup = nftnl_expr_data(e);
66 
67  switch(type) {
68  case NFTNL_EXPR_LOOKUP_SREG:
69  *data_len = sizeof(lookup->sreg);
70  return &lookup->sreg;
71  case NFTNL_EXPR_LOOKUP_DREG:
72  *data_len = sizeof(lookup->dreg);
73  return &lookup->dreg;
74  case NFTNL_EXPR_LOOKUP_SET:
75  return lookup->set_name;
76  case NFTNL_EXPR_LOOKUP_SET_ID:
77  return &lookup->set_id;
78  }
79  return NULL;
80 }
81 
82 static int nftnl_expr_lookup_cb(const struct nlattr *attr, void *data)
83 {
84  const struct nlattr **tb = data;
85  int type = mnl_attr_get_type(attr);
86 
87  if (mnl_attr_type_valid(attr, NFTA_LOOKUP_MAX) < 0)
88  return MNL_CB_OK;
89 
90  switch(type) {
91  case NFTA_LOOKUP_SREG:
92  case NFTA_LOOKUP_DREG:
93  case NFTA_LOOKUP_SET_ID:
94  if (mnl_attr_validate(attr, MNL_TYPE_U32) < 0)
95  abi_breakage();
96  break;
97  case NFTA_LOOKUP_SET:
98  if (mnl_attr_validate(attr, MNL_TYPE_STRING) < 0)
99  abi_breakage();
100  break;
101  }
102 
103  tb[type] = attr;
104  return MNL_CB_OK;
105 }
106 
107 static void
108 nftnl_expr_lookup_build(struct nlmsghdr *nlh, struct nftnl_expr *e)
109 {
110  struct nftnl_expr_lookup *lookup = nftnl_expr_data(e);
111 
112  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_SREG))
113  mnl_attr_put_u32(nlh, NFTA_LOOKUP_SREG, htonl(lookup->sreg));
114  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_DREG))
115  mnl_attr_put_u32(nlh, NFTA_LOOKUP_DREG, htonl(lookup->dreg));
116  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_SET))
117  mnl_attr_put_strz(nlh, NFTA_LOOKUP_SET, lookup->set_name);
118  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_SET_ID)) {
119  mnl_attr_put_u32(nlh, NFTA_LOOKUP_SET_ID,
120  htonl(lookup->set_id));
121  }
122 }
123 
124 static int
125 nftnl_expr_lookup_parse(struct nftnl_expr *e, struct nlattr *attr)
126 {
127  struct nftnl_expr_lookup *lookup = nftnl_expr_data(e);
128  struct nlattr *tb[NFTA_LOOKUP_MAX+1] = {};
129  int ret = 0;
130 
131  if (mnl_attr_parse_nested(attr, nftnl_expr_lookup_cb, tb) < 0)
132  return -1;
133 
134  if (tb[NFTA_LOOKUP_SREG]) {
135  lookup->sreg = ntohl(mnl_attr_get_u32(tb[NFTA_LOOKUP_SREG]));
136  e->flags |= (1 << NFTNL_EXPR_LOOKUP_SREG);
137  }
138  if (tb[NFTA_LOOKUP_DREG]) {
139  lookup->dreg = ntohl(mnl_attr_get_u32(tb[NFTA_LOOKUP_DREG]));
140  e->flags |= (1 << NFTNL_EXPR_LOOKUP_DREG);
141  }
142  if (tb[NFTA_LOOKUP_SET]) {
143  strcpy(lookup->set_name, mnl_attr_get_str(tb[NFTA_LOOKUP_SET]));
144  e->flags |= (1 << NFTNL_EXPR_LOOKUP_SET);
145  }
146  if (tb[NFTA_LOOKUP_SET_ID]) {
147  lookup->set_id =
148  ntohl(mnl_attr_get_u32(tb[NFTA_LOOKUP_SET_ID]));
149  e->flags |= (1 << NFTNL_EXPR_LOOKUP_SET_ID);
150  }
151 
152  return ret;
153 }
154 
155 static int
156 nftnl_expr_lookup_json_parse(struct nftnl_expr *e, json_t *root,
157  struct nftnl_parse_err *err)
158 {
159 #ifdef JSON_PARSING
160  const char *set_name;
161  uint32_t sreg, dreg;
162 
163  set_name = nftnl_jansson_parse_str(root, "set", err);
164  if (set_name != NULL)
165  nftnl_expr_set_str(e, NFTNL_EXPR_LOOKUP_SET, set_name);
166 
167  if (nftnl_jansson_parse_reg(root, "sreg", NFTNL_TYPE_U32, &sreg, err) == 0)
168  nftnl_expr_set_u32(e, NFTNL_EXPR_LOOKUP_SREG, sreg);
169 
170  if (nftnl_jansson_parse_reg(root, "dreg", NFTNL_TYPE_U32, &dreg, err) == 0)
171  nftnl_expr_set_u32(e, NFTNL_EXPR_LOOKUP_DREG, dreg);
172 
173  return 0;
174 #else
175  errno = EOPNOTSUPP;
176  return -1;
177 #endif
178 }
179 
180 static int
181 nftnl_expr_lookup_xml_parse(struct nftnl_expr *e, mxml_node_t *tree,
182  struct nftnl_parse_err *err)
183 {
184 #ifdef XML_PARSING
185  const char *set_name;
186  uint32_t sreg, dreg;
187 
188  set_name = nftnl_mxml_str_parse(tree, "set", MXML_DESCEND_FIRST,
189  NFTNL_XML_MAND, err);
190  if (set_name != NULL)
191  nftnl_expr_set_str(e, NFTNL_EXPR_LOOKUP_SET, set_name);
192 
193  if (nftnl_mxml_reg_parse(tree, "sreg", &sreg, MXML_DESCEND, NFTNL_XML_MAND,
194  err) == 0)
195  nftnl_expr_set_u32(e, NFTNL_EXPR_LOOKUP_SREG, sreg);
196 
197  if (nftnl_mxml_reg_parse(tree, "dreg", &dreg, MXML_DESCEND, NFTNL_XML_OPT,
198  err) == 0)
199  nftnl_expr_set_u32(e, NFTNL_EXPR_LOOKUP_DREG, dreg);
200 
201  return 0;
202 #else
203  errno = EOPNOTSUPP;
204  return -1;
205 #endif
206 }
207 
208 static int
209 nftnl_expr_lookup_export(char *buf, size_t size,
210  struct nftnl_expr *e, int type)
211 {
212  struct nftnl_expr_lookup *l = nftnl_expr_data(e);
213  NFTNL_BUF_INIT(b, buf, size);
214 
215  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_SET))
216  nftnl_buf_str(&b, type, l->set_name, SET);
217  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_SREG))
218  nftnl_buf_u32(&b, type, l->sreg, SREG);
219  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_DREG))
220  nftnl_buf_u32(&b, type, l->dreg, DREG);
221 
222  return nftnl_buf_done(&b);
223 }
224 
225 static int
226 nftnl_expr_lookup_snprintf_default(char *buf, size_t size,
227  struct nftnl_expr *e)
228 {
229  int len = size, offset = 0, ret;
230  struct nftnl_expr_lookup *l = nftnl_expr_data(e);
231 
232  ret = snprintf(buf, len, "reg %u set %s ", l->sreg, l->set_name);
233  SNPRINTF_BUFFER_SIZE(ret, size, len, offset);
234 
235 
236  if (e->flags & (1 << NFTNL_EXPR_LOOKUP_DREG)) {
237  ret = snprintf(buf+offset, len, "dreg %u ", l->dreg);
238  SNPRINTF_BUFFER_SIZE(ret, size, len, offset);
239  }
240 
241  return offset;
242 }
243 
244 static int
245 nftnl_expr_lookup_snprintf(char *buf, size_t size, uint32_t type,
246  uint32_t flags, struct nftnl_expr *e)
247 {
248 
249  switch(type) {
250  case NFTNL_OUTPUT_DEFAULT:
251  return nftnl_expr_lookup_snprintf_default(buf, size, e);
252  case NFTNL_OUTPUT_XML:
253  case NFTNL_OUTPUT_JSON:
254  return nftnl_expr_lookup_export(buf, size, e, type);
255  default:
256  break;
257  }
258  return -1;
259 }
260 
261 struct expr_ops expr_ops_lookup = {
262  .name = "lookup",
263  .alloc_len = sizeof(struct nftnl_expr_lookup),
264  .max_attr = NFTA_LOOKUP_MAX,
265  .set = nftnl_expr_lookup_set,
266  .get = nftnl_expr_lookup_get,
267  .parse = nftnl_expr_lookup_parse,
268  .build = nftnl_expr_lookup_build,
269  .snprintf = nftnl_expr_lookup_snprintf,
270  .xml_parse = nftnl_expr_lookup_xml_parse,
271  .json_parse = nftnl_expr_lookup_json_parse,
272 };