14 #include <arpa/inet.h>
16 #include <linux/netfilter/nf_tables.h>
19 #include <libmnl/libmnl.h>
20 #include <libnftnl/expr.h>
21 #include <libnftnl/rule.h>
24 enum nft_registers dreg;
26 enum nft_ng_types type;
35 nftnl_expr_ng_set(
struct nftnl_expr *e, uint16_t type,
36 const void *data, uint32_t data_len)
41 case NFTNL_EXPR_NG_DREG:
42 memcpy(&ng->dreg, data,
sizeof(ng->dreg));
44 case NFTNL_EXPR_NG_MODULUS:
45 memcpy(&ng->modulus, data,
sizeof(ng->modulus));
47 case NFTNL_EXPR_NG_TYPE:
48 memcpy(&ng->type, data,
sizeof(ng->type));
50 case NFTNL_EXPR_NG_OFFSET:
51 memcpy(&ng->offset, data,
sizeof(ng->offset));
53 case NFTNL_EXPR_NG_SET_NAME:
54 ng->map.name = strdup(data);
58 case NFTNL_EXPR_NG_SET_ID:
59 memcpy(&ng->map.id, data,
sizeof(ng->map.id));
68 nftnl_expr_ng_get(
const struct nftnl_expr *e, uint16_t type,
74 case NFTNL_EXPR_NG_DREG:
75 *data_len =
sizeof(ng->dreg);
77 case NFTNL_EXPR_NG_MODULUS:
78 *data_len =
sizeof(ng->modulus);
80 case NFTNL_EXPR_NG_TYPE:
81 *data_len =
sizeof(ng->type);
83 case NFTNL_EXPR_NG_OFFSET:
84 *data_len =
sizeof(ng->offset);
86 case NFTNL_EXPR_NG_SET_NAME:
87 *data_len = strlen(ng->map.name) + 1;
89 case NFTNL_EXPR_NG_SET_ID:
90 *data_len =
sizeof(ng->map.id);
96 static int nftnl_expr_ng_cb(
const struct nlattr *attr,
void *data)
98 const struct nlattr **tb = data;
99 int type = mnl_attr_get_type(attr);
101 if (mnl_attr_type_valid(attr, NFTA_NG_MAX) < 0)
106 case NFTA_NG_MODULUS:
110 if (mnl_attr_validate(attr, MNL_TYPE_U32) < 0)
113 case NFTA_NG_SET_NAME:
114 if (mnl_attr_validate(attr, MNL_TYPE_STRING) < 0)
124 nftnl_expr_ng_build(
struct nlmsghdr *nlh,
const struct nftnl_expr *e)
128 if (e->flags & (1 << NFTNL_EXPR_NG_DREG))
129 mnl_attr_put_u32(nlh, NFTA_NG_DREG, htonl(ng->dreg));
130 if (e->flags & (1 << NFTNL_EXPR_NG_MODULUS))
131 mnl_attr_put_u32(nlh, NFTA_NG_MODULUS, htonl(ng->modulus));
132 if (e->flags & (1 << NFTNL_EXPR_NG_TYPE))
133 mnl_attr_put_u32(nlh, NFTA_NG_TYPE, htonl(ng->type));
134 if (e->flags & (1 << NFTNL_EXPR_NG_OFFSET))
135 mnl_attr_put_u32(nlh, NFTA_NG_OFFSET, htonl(ng->offset));
136 if (e->flags & (1 << NFTNL_EXPR_NG_SET_NAME))
137 mnl_attr_put_str(nlh, NFTA_NG_SET_NAME, ng->map.name);
138 if (e->flags & (1 << NFTNL_EXPR_NG_SET_ID))
139 mnl_attr_put_u32(nlh, NFTA_NG_SET_ID, htonl(ng->map.id));
143 nftnl_expr_ng_parse(
struct nftnl_expr *e,
struct nlattr *attr)
146 struct nlattr *tb[NFTA_NG_MAX+1] = {};
149 if (mnl_attr_parse_nested(attr, nftnl_expr_ng_cb, tb) < 0)
152 if (tb[NFTA_NG_DREG]) {
153 ng->dreg = ntohl(mnl_attr_get_u32(tb[NFTA_NG_DREG]));
154 e->flags |= (1 << NFTNL_EXPR_NG_DREG);
156 if (tb[NFTA_NG_MODULUS]) {
157 ng->modulus = ntohl(mnl_attr_get_u32(tb[NFTA_NG_MODULUS]));
158 e->flags |= (1 << NFTNL_EXPR_NG_MODULUS);
160 if (tb[NFTA_NG_TYPE]) {
161 ng->type = ntohl(mnl_attr_get_u32(tb[NFTA_NG_TYPE]));
162 e->flags |= (1 << NFTNL_EXPR_NG_TYPE);
164 if (tb[NFTA_NG_OFFSET]) {
165 ng->offset = ntohl(mnl_attr_get_u32(tb[NFTA_NG_OFFSET]));
166 e->flags |= (1 << NFTNL_EXPR_NG_OFFSET);
168 if (tb[NFTA_NG_SET_NAME]) {
170 strdup(mnl_attr_get_str(tb[NFTA_NG_SET_NAME]));
171 e->flags |= (1 << NFTNL_EXPR_NG_SET_NAME);
173 if (tb[NFTA_NG_SET_ID]) {
175 ntohl(mnl_attr_get_u32(tb[NFTA_NG_SET_ID]));
176 e->flags |= (1 << NFTNL_EXPR_NG_SET_ID);
183 nftnl_expr_ng_snprintf_default(
char *buf,
size_t size,
184 const struct nftnl_expr *e)
187 int remain = size, offset = 0, ret;
190 case NFT_NG_INCREMENTAL:
191 ret = snprintf(buf, remain,
"reg %u = inc mod %u ",
192 ng->dreg, ng->modulus);
193 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
196 ret = snprintf(buf, remain,
"reg %u = random mod %u ",
197 ng->dreg, ng->modulus);
198 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
205 ret = snprintf(buf + offset, remain,
"offset %u ", ng->offset);
206 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
210 ret = snprintf(buf + offset, remain,
"set %s id %u ",
211 ng->map.name, ng->map.id);
212 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
219 nftnl_expr_ng_snprintf(
char *buf,
size_t len, uint32_t type,
220 uint32_t flags,
const struct nftnl_expr *e)
223 case NFTNL_OUTPUT_DEFAULT:
224 return nftnl_expr_ng_snprintf_default(buf, len, e);
225 case NFTNL_OUTPUT_XML:
226 case NFTNL_OUTPUT_JSON:
233 struct expr_ops expr_ops_ng = {
236 .max_attr = NFTA_NG_MAX,
237 .set = nftnl_expr_ng_set,
238 .get = nftnl_expr_ng_get,
239 .parse = nftnl_expr_ng_parse,
240 .build = nftnl_expr_ng_build,
241 .snprintf = nftnl_expr_ng_snprintf,