1*de1e4e89SAndroid Build Coastguard Worker /*
2*de1e4e89SAndroid Build Coastguard Worker * f_fw.c FW filter.
3*de1e4e89SAndroid Build Coastguard Worker *
4*de1e4e89SAndroid Build Coastguard Worker * This program is free software; you can redistribute it and/or
5*de1e4e89SAndroid Build Coastguard Worker * modify it under the terms of the GNU General Public License
6*de1e4e89SAndroid Build Coastguard Worker * as published by the Free Software Foundation; either version
7*de1e4e89SAndroid Build Coastguard Worker * 2 of the License, or (at your option) any later version.
8*de1e4e89SAndroid Build Coastguard Worker *
9*de1e4e89SAndroid Build Coastguard Worker * Authors: Alexey Kuznetsov, <[email protected]>
10*de1e4e89SAndroid Build Coastguard Worker *
11*de1e4e89SAndroid Build Coastguard Worker */
12*de1e4e89SAndroid Build Coastguard Worker
13*de1e4e89SAndroid Build Coastguard Worker #include <stdio.h>
14*de1e4e89SAndroid Build Coastguard Worker #include <stdlib.h>
15*de1e4e89SAndroid Build Coastguard Worker #include <unistd.h>
16*de1e4e89SAndroid Build Coastguard Worker #include <syslog.h>
17*de1e4e89SAndroid Build Coastguard Worker #include <fcntl.h>
18*de1e4e89SAndroid Build Coastguard Worker #include <sys/socket.h>
19*de1e4e89SAndroid Build Coastguard Worker #include <netinet/in.h>
20*de1e4e89SAndroid Build Coastguard Worker #include <arpa/inet.h>
21*de1e4e89SAndroid Build Coastguard Worker #include <string.h>
22*de1e4e89SAndroid Build Coastguard Worker #include <linux/if.h> /* IFNAMSIZ */
23*de1e4e89SAndroid Build Coastguard Worker #include "utils.h"
24*de1e4e89SAndroid Build Coastguard Worker #include "tc_util.h"
25*de1e4e89SAndroid Build Coastguard Worker
explain(void)26*de1e4e89SAndroid Build Coastguard Worker static void explain(void)
27*de1e4e89SAndroid Build Coastguard Worker {
28*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr,
29*de1e4e89SAndroid Build Coastguard Worker "Usage: ... fw [ classid CLASSID ] [ indev DEV ] [ action ACTION_SPEC ]\n");
30*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr,
31*de1e4e89SAndroid Build Coastguard Worker " CLASSID := Push matching packets to the class identified by CLASSID with format X:Y\n");
32*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr,
33*de1e4e89SAndroid Build Coastguard Worker " CLASSID is parsed as hexadecimal input.\n");
34*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr,
35*de1e4e89SAndroid Build Coastguard Worker " DEV := specify device for incoming device classification.\n");
36*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr,
37*de1e4e89SAndroid Build Coastguard Worker " ACTION_SPEC := Apply an action on matching packets.\n");
38*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr,
39*de1e4e89SAndroid Build Coastguard Worker " NOTE: handle is represented as HANDLE[/FWMASK].\n");
40*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, " FWMASK is 0xffffffff by default.\n");
41*de1e4e89SAndroid Build Coastguard Worker }
42*de1e4e89SAndroid Build Coastguard Worker
fw_parse_opt(struct filter_util * qu,char * handle,int argc,char ** argv,struct nlmsghdr * n)43*de1e4e89SAndroid Build Coastguard Worker static int fw_parse_opt(struct filter_util *qu, char *handle, int argc, char **argv, struct nlmsghdr *n)
44*de1e4e89SAndroid Build Coastguard Worker {
45*de1e4e89SAndroid Build Coastguard Worker struct tcmsg *t = NLMSG_DATA(n);
46*de1e4e89SAndroid Build Coastguard Worker struct rtattr *tail;
47*de1e4e89SAndroid Build Coastguard Worker __u32 mask = 0;
48*de1e4e89SAndroid Build Coastguard Worker int mask_set = 0;
49*de1e4e89SAndroid Build Coastguard Worker
50*de1e4e89SAndroid Build Coastguard Worker if (handle) {
51*de1e4e89SAndroid Build Coastguard Worker char *slash;
52*de1e4e89SAndroid Build Coastguard Worker
53*de1e4e89SAndroid Build Coastguard Worker if ((slash = strchr(handle, '/')) != NULL)
54*de1e4e89SAndroid Build Coastguard Worker *slash = '\0';
55*de1e4e89SAndroid Build Coastguard Worker if (get_u32(&t->tcm_handle, handle, 0)) {
56*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, "Illegal \"handle\"\n");
57*de1e4e89SAndroid Build Coastguard Worker return -1;
58*de1e4e89SAndroid Build Coastguard Worker }
59*de1e4e89SAndroid Build Coastguard Worker if (slash) {
60*de1e4e89SAndroid Build Coastguard Worker if (get_u32(&mask, slash+1, 0)) {
61*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, "Illegal \"handle\" mask\n");
62*de1e4e89SAndroid Build Coastguard Worker return -1;
63*de1e4e89SAndroid Build Coastguard Worker }
64*de1e4e89SAndroid Build Coastguard Worker mask_set = 1;
65*de1e4e89SAndroid Build Coastguard Worker }
66*de1e4e89SAndroid Build Coastguard Worker }
67*de1e4e89SAndroid Build Coastguard Worker
68*de1e4e89SAndroid Build Coastguard Worker if (argc == 0)
69*de1e4e89SAndroid Build Coastguard Worker return 0;
70*de1e4e89SAndroid Build Coastguard Worker
71*de1e4e89SAndroid Build Coastguard Worker tail = NLMSG_TAIL(n);
72*de1e4e89SAndroid Build Coastguard Worker addattr_l(n, 4096, TCA_OPTIONS, NULL, 0);
73*de1e4e89SAndroid Build Coastguard Worker
74*de1e4e89SAndroid Build Coastguard Worker if (mask_set)
75*de1e4e89SAndroid Build Coastguard Worker addattr32(n, MAX_MSG, TCA_FW_MASK, mask);
76*de1e4e89SAndroid Build Coastguard Worker
77*de1e4e89SAndroid Build Coastguard Worker while (argc > 0) {
78*de1e4e89SAndroid Build Coastguard Worker if (matches(*argv, "classid") == 0 ||
79*de1e4e89SAndroid Build Coastguard Worker matches(*argv, "flowid") == 0) {
80*de1e4e89SAndroid Build Coastguard Worker unsigned int handle;
81*de1e4e89SAndroid Build Coastguard Worker
82*de1e4e89SAndroid Build Coastguard Worker NEXT_ARG();
83*de1e4e89SAndroid Build Coastguard Worker if (get_tc_classid(&handle, *argv)) {
84*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, "Illegal \"classid\"\n");
85*de1e4e89SAndroid Build Coastguard Worker return -1;
86*de1e4e89SAndroid Build Coastguard Worker }
87*de1e4e89SAndroid Build Coastguard Worker addattr_l(n, 4096, TCA_FW_CLASSID, &handle, 4);
88*de1e4e89SAndroid Build Coastguard Worker } else if (matches(*argv, "police") == 0) {
89*de1e4e89SAndroid Build Coastguard Worker NEXT_ARG();
90*de1e4e89SAndroid Build Coastguard Worker if (parse_police(&argc, &argv, TCA_FW_POLICE, n)) {
91*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, "Illegal \"police\"\n");
92*de1e4e89SAndroid Build Coastguard Worker return -1;
93*de1e4e89SAndroid Build Coastguard Worker }
94*de1e4e89SAndroid Build Coastguard Worker continue;
95*de1e4e89SAndroid Build Coastguard Worker } else if (matches(*argv, "action") == 0) {
96*de1e4e89SAndroid Build Coastguard Worker NEXT_ARG();
97*de1e4e89SAndroid Build Coastguard Worker if (parse_action(&argc, &argv, TCA_FW_ACT, n)) {
98*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, "Illegal fw \"action\"\n");
99*de1e4e89SAndroid Build Coastguard Worker return -1;
100*de1e4e89SAndroid Build Coastguard Worker }
101*de1e4e89SAndroid Build Coastguard Worker continue;
102*de1e4e89SAndroid Build Coastguard Worker } else if (strcmp(*argv, "indev") == 0) {
103*de1e4e89SAndroid Build Coastguard Worker char d[IFNAMSIZ+1] = {};
104*de1e4e89SAndroid Build Coastguard Worker
105*de1e4e89SAndroid Build Coastguard Worker argc--;
106*de1e4e89SAndroid Build Coastguard Worker argv++;
107*de1e4e89SAndroid Build Coastguard Worker if (argc < 1) {
108*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, "Illegal indev\n");
109*de1e4e89SAndroid Build Coastguard Worker return -1;
110*de1e4e89SAndroid Build Coastguard Worker }
111*de1e4e89SAndroid Build Coastguard Worker strncpy(d, *argv, sizeof(d) - 1);
112*de1e4e89SAndroid Build Coastguard Worker addattr_l(n, MAX_MSG, TCA_FW_INDEV, d, strlen(d) + 1);
113*de1e4e89SAndroid Build Coastguard Worker } else if (strcmp(*argv, "help") == 0) {
114*de1e4e89SAndroid Build Coastguard Worker explain();
115*de1e4e89SAndroid Build Coastguard Worker return -1;
116*de1e4e89SAndroid Build Coastguard Worker } else {
117*de1e4e89SAndroid Build Coastguard Worker fprintf(stderr, "What is \"%s\"?\n", *argv);
118*de1e4e89SAndroid Build Coastguard Worker explain();
119*de1e4e89SAndroid Build Coastguard Worker return -1;
120*de1e4e89SAndroid Build Coastguard Worker }
121*de1e4e89SAndroid Build Coastguard Worker argc--; argv++;
122*de1e4e89SAndroid Build Coastguard Worker }
123*de1e4e89SAndroid Build Coastguard Worker tail->rta_len = (void *) NLMSG_TAIL(n) - (void *) tail;
124*de1e4e89SAndroid Build Coastguard Worker return 0;
125*de1e4e89SAndroid Build Coastguard Worker }
126*de1e4e89SAndroid Build Coastguard Worker
fw_print_opt(struct filter_util * qu,FILE * f,struct rtattr * opt,__u32 handle)127*de1e4e89SAndroid Build Coastguard Worker static int fw_print_opt(struct filter_util *qu, FILE *f, struct rtattr *opt, __u32 handle)
128*de1e4e89SAndroid Build Coastguard Worker {
129*de1e4e89SAndroid Build Coastguard Worker struct rtattr *tb[TCA_FW_MAX+1];
130*de1e4e89SAndroid Build Coastguard Worker
131*de1e4e89SAndroid Build Coastguard Worker if (opt == NULL)
132*de1e4e89SAndroid Build Coastguard Worker return 0;
133*de1e4e89SAndroid Build Coastguard Worker
134*de1e4e89SAndroid Build Coastguard Worker parse_rtattr_nested(tb, TCA_FW_MAX, opt);
135*de1e4e89SAndroid Build Coastguard Worker
136*de1e4e89SAndroid Build Coastguard Worker if (handle || tb[TCA_FW_MASK]) {
137*de1e4e89SAndroid Build Coastguard Worker __u32 mark = 0, mask = 0;
138*de1e4e89SAndroid Build Coastguard Worker
139*de1e4e89SAndroid Build Coastguard Worker if (handle)
140*de1e4e89SAndroid Build Coastguard Worker mark = handle;
141*de1e4e89SAndroid Build Coastguard Worker if (tb[TCA_FW_MASK] &&
142*de1e4e89SAndroid Build Coastguard Worker (mask = rta_getattr_u32(tb[TCA_FW_MASK])) != 0xFFFFFFFF)
143*de1e4e89SAndroid Build Coastguard Worker fprintf(f, "handle 0x%x/0x%x ", mark, mask);
144*de1e4e89SAndroid Build Coastguard Worker else
145*de1e4e89SAndroid Build Coastguard Worker fprintf(f, "handle 0x%x ", handle);
146*de1e4e89SAndroid Build Coastguard Worker }
147*de1e4e89SAndroid Build Coastguard Worker
148*de1e4e89SAndroid Build Coastguard Worker if (tb[TCA_FW_CLASSID]) {
149*de1e4e89SAndroid Build Coastguard Worker SPRINT_BUF(b1);
150*de1e4e89SAndroid Build Coastguard Worker fprintf(f, "classid %s ", sprint_tc_classid(rta_getattr_u32(tb[TCA_FW_CLASSID]), b1));
151*de1e4e89SAndroid Build Coastguard Worker }
152*de1e4e89SAndroid Build Coastguard Worker
153*de1e4e89SAndroid Build Coastguard Worker if (tb[TCA_FW_POLICE])
154*de1e4e89SAndroid Build Coastguard Worker tc_print_police(f, tb[TCA_FW_POLICE]);
155*de1e4e89SAndroid Build Coastguard Worker if (tb[TCA_FW_INDEV]) {
156*de1e4e89SAndroid Build Coastguard Worker struct rtattr *idev = tb[TCA_FW_INDEV];
157*de1e4e89SAndroid Build Coastguard Worker
158*de1e4e89SAndroid Build Coastguard Worker fprintf(f, "input dev %s ", rta_getattr_str(idev));
159*de1e4e89SAndroid Build Coastguard Worker }
160*de1e4e89SAndroid Build Coastguard Worker
161*de1e4e89SAndroid Build Coastguard Worker if (tb[TCA_FW_ACT]) {
162*de1e4e89SAndroid Build Coastguard Worker fprintf(f, "\n");
163*de1e4e89SAndroid Build Coastguard Worker tc_print_action(f, tb[TCA_FW_ACT], 0);
164*de1e4e89SAndroid Build Coastguard Worker }
165*de1e4e89SAndroid Build Coastguard Worker return 0;
166*de1e4e89SAndroid Build Coastguard Worker }
167*de1e4e89SAndroid Build Coastguard Worker
168*de1e4e89SAndroid Build Coastguard Worker struct filter_util fw_filter_util = {
169*de1e4e89SAndroid Build Coastguard Worker .id = "fw",
170*de1e4e89SAndroid Build Coastguard Worker .parse_fopt = fw_parse_opt,
171*de1e4e89SAndroid Build Coastguard Worker .print_fopt = fw_print_opt,
172*de1e4e89SAndroid Build Coastguard Worker };
173