libxt_NFLOG.c 4.29 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
12
13
14
#include <stdbool.h>
#include <stdlib.h>
#include <stdio.h>
#include <string.h>
#include <getopt.h>
#include <xtables.h>

#include <linux/netfilter/x_tables.h>
#include <linux/netfilter/xt_NFLOG.h>

enum {
	O_GROUP = 0,
	O_PREFIX,
	O_RANGE,
15
	O_SIZE,
16
	O_THRESHOLD,
17
18
	F_RANGE = 1 << O_RANGE,
	F_SIZE = 1 << O_SIZE,
19
20
21
22
23
24
25
26
27
};

#define s struct xt_nflog_info
static const struct xt_option_entry NFLOG_opts[] = {
	{.name = "nflog-group", .id = O_GROUP, .type = XTTYPE_UINT16,
	 .flags = XTOPT_PUT, XTOPT_POINTER(s, group)},
	{.name = "nflog-prefix", .id = O_PREFIX, .type = XTTYPE_STRING,
	 .min = 1, .flags = XTOPT_PUT, XTOPT_POINTER(s, prefix)},
	{.name = "nflog-range", .id = O_RANGE, .type = XTTYPE_UINT32,
28
29
30
	 .excl = F_SIZE, .flags = XTOPT_PUT, XTOPT_POINTER(s, len)},
	{.name = "nflog-size", .id = O_SIZE, .type = XTTYPE_UINT32,
	 .excl = F_RANGE, .flags = XTOPT_PUT, XTOPT_POINTER(s, len)},
31
32
33
34
35
36
37
38
39
40
	{.name = "nflog-threshold", .id = O_THRESHOLD, .type = XTTYPE_UINT16,
	 .flags = XTOPT_PUT, XTOPT_POINTER(s, threshold)},
	XTOPT_TABLEEND,
};
#undef s

static void NFLOG_help(void)
{
	printf("NFLOG target options:\n"
	       " --nflog-group NUM		NETLINK group used for logging\n"
41
42
	       " --nflog-range NUM		This option has no effect, use --nflog-size\n"
	       " --nflog-size NUM		Number of bytes to copy\n"
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
	       " --nflog-threshold NUM		Message threshold of in-kernel queue\n"
	       " --nflog-prefix STRING		Prefix string for log messages\n");
}

static void NFLOG_init(struct xt_entry_target *t)
{
	struct xt_nflog_info *info = (struct xt_nflog_info *)t->data;

	info->threshold	= XT_NFLOG_DEFAULT_THRESHOLD;
}

static void NFLOG_parse(struct xt_option_call *cb)
{
	xtables_option_parse(cb);
	switch (cb->entry->id) {
	case O_PREFIX:
		if (strchr(cb->arg, '\n') != NULL)
			xtables_error(PARAMETER_PROBLEM,
				   "Newlines not allowed in --log-prefix");
		break;
	}
}

66
67
68
69
70
71
72
73
74
75
76
77
static void NFLOG_check(struct xt_fcheck_call *cb)
{
	struct xt_nflog_info *info = cb->data;

	if (cb->xflags & F_RANGE)
		fprintf(stderr, "warn: --nflog-range has never worked and is no"
			" longer supported, please use --nflog-size insted\n");

	if (cb->xflags & F_SIZE)
		info->flags |= XT_NFLOG_F_COPY_LEN;
}

78
79
80
81
82
83
84
85
static void nflog_print(const struct xt_nflog_info *info, char *prefix)
{
	if (info->prefix[0] != '\0') {
		printf(" %snflog-prefix ", prefix);
		xtables_save_string(info->prefix);
	}
	if (info->group)
		printf(" %snflog-group %u", prefix, info->group);
86
87
88
	if (info->flags & XT_NFLOG_F_COPY_LEN)
		printf(" %snflog-size %u", prefix, info->len);
	else if (info->len)
89
90
91
92
93
94
		printf(" %snflog-range %u", prefix, info->len);
	if (info->threshold != XT_NFLOG_DEFAULT_THRESHOLD)
		printf(" %snflog-threshold %u", prefix, info->threshold);
}

static void NFLOG_print(const void *ip, const struct xt_entry_target *target,
95
			int numeric)
96
97
98
99
100
101
102
103
104
105
106
107
108
{
	const struct xt_nflog_info *info = (struct xt_nflog_info *)target->data;

	nflog_print(info, "");
}

static void NFLOG_save(const void *ip, const struct xt_entry_target *target)
{
	const struct xt_nflog_info *info = (struct xt_nflog_info *)target->data;

	nflog_print(info, "--");
}

109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
static void nflog_print_xlate(const struct xt_nflog_info *info,
			      struct xt_xlate *xl, bool escape_quotes)
{
	xt_xlate_add(xl, "log ");
	if (info->prefix[0] != '\0') {
		if (escape_quotes)
			xt_xlate_add(xl, "prefix \\\"%s\\\" ", info->prefix);
		else
			xt_xlate_add(xl, "prefix \"%s\" ", info->prefix);

	}
	if (info->flags & XT_NFLOG_F_COPY_LEN)
		xt_xlate_add(xl, "snaplen %u ", info->len);
	if (info->threshold != XT_NFLOG_DEFAULT_THRESHOLD)
		xt_xlate_add(xl, "queue-threshold %u ", info->threshold);
	xt_xlate_add(xl, "group %u ", info->group);
}

static int NFLOG_xlate(struct xt_xlate *xl,
		       const struct xt_xlate_tg_params *params)
{
	const struct xt_nflog_info *info =
		(struct xt_nflog_info *)params->target->data;

	nflog_print_xlate(info, xl, params->escape_quotes);

	return 1;
}

138
139
140
141
142
143
144
145
static struct xtables_target nflog_target = {
	.family		= NFPROTO_UNSPEC,
	.name		= "NFLOG",
	.version	= XTABLES_VERSION,
	.size		= XT_ALIGN(sizeof(struct xt_nflog_info)),
	.userspacesize	= XT_ALIGN(sizeof(struct xt_nflog_info)),
	.help		= NFLOG_help,
	.init		= NFLOG_init,
146
	.x6_fcheck	= NFLOG_check,
147
148
149
150
	.x6_parse	= NFLOG_parse,
	.print		= NFLOG_print,
	.save		= NFLOG_save,
	.x6_options	= NFLOG_opts,
151
	.xlate		= NFLOG_xlate,
152
153
154
155
156
157
};

void _init(void)
{
	xtables_register_target(&nflog_target);
}