14 #include <arpa/inet.h>
16 #include <linux/netfilter/nf_tables.h>
19 #include <libmnl/libmnl.h>
20 #include <libnftnl/expr.h>
21 #include <libnftnl/rule.h>
24 enum nft_registers dreg;
26 enum nft_ng_types type;
31 nftnl_expr_ng_set(
struct nftnl_expr *e, uint16_t type,
32 const void *data, uint32_t data_len)
37 case NFTNL_EXPR_NG_DREG:
38 ng->dreg = *((uint32_t *)data);
40 case NFTNL_EXPR_NG_MODULUS:
41 ng->modulus = *((uint32_t *)data);
43 case NFTNL_EXPR_NG_TYPE:
44 ng->type = *((uint32_t *)data);
46 case NFTNL_EXPR_NG_OFFSET:
47 ng->offset = *((uint32_t *)data);
56 nftnl_expr_ng_get(
const struct nftnl_expr *e, uint16_t type,
62 case NFTNL_EXPR_NG_DREG:
63 *data_len =
sizeof(ng->dreg);
65 case NFTNL_EXPR_NG_MODULUS:
66 *data_len =
sizeof(ng->modulus);
68 case NFTNL_EXPR_NG_TYPE:
69 *data_len =
sizeof(ng->type);
71 case NFTNL_EXPR_NG_OFFSET:
72 *data_len =
sizeof(ng->offset);
78 static int nftnl_expr_ng_cb(
const struct nlattr *attr,
void *data)
80 const struct nlattr **tb = data;
81 int type = mnl_attr_get_type(attr);
83 if (mnl_attr_type_valid(attr, NFTA_NG_MAX) < 0)
91 if (mnl_attr_validate(attr, MNL_TYPE_U32) < 0)
101 nftnl_expr_ng_build(
struct nlmsghdr *nlh,
const struct nftnl_expr *e)
105 if (e->flags & (1 << NFTNL_EXPR_NG_DREG))
106 mnl_attr_put_u32(nlh, NFTA_NG_DREG, htonl(ng->dreg));
107 if (e->flags & (1 << NFTNL_EXPR_NG_MODULUS))
108 mnl_attr_put_u32(nlh, NFTA_NG_MODULUS, htonl(ng->modulus));
109 if (e->flags & (1 << NFTNL_EXPR_NG_TYPE))
110 mnl_attr_put_u32(nlh, NFTA_NG_TYPE, htonl(ng->type));
111 if (e->flags & (1 << NFTNL_EXPR_NG_OFFSET))
112 mnl_attr_put_u32(nlh, NFTA_NG_OFFSET, htonl(ng->offset));
116 nftnl_expr_ng_parse(
struct nftnl_expr *e,
struct nlattr *attr)
119 struct nlattr *tb[NFTA_NG_MAX+1] = {};
122 if (mnl_attr_parse_nested(attr, nftnl_expr_ng_cb, tb) < 0)
125 if (tb[NFTA_NG_DREG]) {
126 ng->dreg = ntohl(mnl_attr_get_u32(tb[NFTA_NG_DREG]));
127 e->flags |= (1 << NFTNL_EXPR_NG_DREG);
129 if (tb[NFTA_NG_MODULUS]) {
130 ng->modulus = ntohl(mnl_attr_get_u32(tb[NFTA_NG_MODULUS]));
131 e->flags |= (1 << NFTNL_EXPR_NG_MODULUS);
133 if (tb[NFTA_NG_TYPE]) {
134 ng->type = ntohl(mnl_attr_get_u32(tb[NFTA_NG_TYPE]));
135 e->flags |= (1 << NFTNL_EXPR_NG_TYPE);
137 if (tb[NFTA_NG_OFFSET]) {
138 ng->offset = ntohl(mnl_attr_get_u32(tb[NFTA_NG_OFFSET]));
139 e->flags |= (1 << NFTNL_EXPR_NG_OFFSET);
145 static int nftnl_expr_ng_json_parse(
struct nftnl_expr *e, json_t *root,
146 struct nftnl_parse_err *err)
149 uint32_t dreg, modulus, type, offset;
151 if (nftnl_jansson_parse_reg(root,
"dreg", NFTNL_TYPE_U32,
153 nftnl_expr_set_u32(e, NFTNL_EXPR_NG_DREG, dreg);
155 if (nftnl_jansson_parse_val(root,
"modulus", NFTNL_TYPE_U32,
157 nftnl_expr_set_u32(e, NFTNL_EXPR_NG_MODULUS, modulus);
159 if (nftnl_jansson_parse_val(root,
"type", NFTNL_TYPE_U32,
161 nftnl_expr_set_u32(e, NFTNL_EXPR_NG_TYPE, type);
163 if (nftnl_jansson_parse_val(root,
"offset", NFTNL_TYPE_U32,
165 nftnl_expr_set_u32(e, NFTNL_EXPR_NG_OFFSET, offset);
175 nftnl_expr_ng_snprintf_default(
char *buf,
size_t size,
176 const struct nftnl_expr *e)
179 int remain = size, offset = 0, ret;
182 case NFT_NG_INCREMENTAL:
183 ret = snprintf(buf, remain,
"reg %u = inc mod %u ",
184 ng->dreg, ng->modulus);
185 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
188 ret = snprintf(buf, remain,
"reg %u = random mod %u ",
189 ng->dreg, ng->modulus);
190 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
197 ret = snprintf(buf + offset, remain,
"offset %u ", ng->offset);
198 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
204 static int nftnl_expr_ng_export(
char *buf,
size_t size,
205 const struct nftnl_expr *e,
int type)
209 NFTNL_BUF_INIT(b, buf, size);
211 if (e->flags & (1 << NFTNL_EXPR_NG_DREG))
212 nftnl_buf_u32(&b, type, ng->dreg, DREG);
213 if (e->flags & (1 << NFTNL_EXPR_NG_MODULUS))
214 nftnl_buf_u32(&b, type, ng->modulus, MODULUS);
215 if (e->flags & (1 << NFTNL_EXPR_NG_TYPE))
216 nftnl_buf_u32(&b, type, ng->type, TYPE);
217 if (e->flags & (1 << NFTNL_EXPR_NG_OFFSET))
218 nftnl_buf_u32(&b, type, ng->type, OFFSET);
220 return nftnl_buf_done(&b);
224 nftnl_expr_ng_snprintf(
char *buf,
size_t len, uint32_t type,
225 uint32_t flags,
const struct nftnl_expr *e)
228 case NFTNL_OUTPUT_DEFAULT:
229 return nftnl_expr_ng_snprintf_default(buf, len, e);
230 case NFTNL_OUTPUT_XML:
231 case NFTNL_OUTPUT_JSON:
232 return nftnl_expr_ng_export(buf, len, e, type);
239 static bool nftnl_expr_ng_cmp(
const struct nftnl_expr *e1,
240 const struct nftnl_expr *e2)
246 if (e1->flags & (1 << NFTNL_EXPR_NG_DREG))
247 eq &= (n1->dreg == n2->dreg);
248 if (e1->flags & (1 << NFTNL_EXPR_NG_MODULUS))
249 eq &= (n1->modulus == n2->modulus);
250 if (e1->flags & (1 << NFTNL_EXPR_NG_TYPE))
251 eq &= (n1->type == n2->type);
252 if (e1->flags & (1 << NFTNL_EXPR_NG_OFFSET))
253 eq &= (n1->offset == n2->offset);
258 struct expr_ops expr_ops_ng = {
261 .max_attr = NFTA_NG_MAX,
262 .cmp = nftnl_expr_ng_cmp,
263 .set = nftnl_expr_ng_set,
264 .get = nftnl_expr_ng_get,
265 .parse = nftnl_expr_ng_parse,
266 .build = nftnl_expr_ng_build,
267 .snprintf = nftnl_expr_ng_snprintf,
268 .json_parse = nftnl_expr_ng_json_parse,