diff options
Diffstat (limited to 'src/expr/socket.c')
-rw-r--r-- | src/expr/socket.c | 65 |
1 files changed, 30 insertions, 35 deletions
diff --git a/src/expr/socket.c b/src/expr/socket.c index 8cd4536..7a25cdf 100644 --- a/src/expr/socket.c +++ b/src/expr/socket.c @@ -22,6 +22,7 @@ struct nftnl_expr_socket { enum nft_socket_keys key; enum nft_registers dreg; + uint32_t level; }; static int @@ -32,13 +33,14 @@ nftnl_expr_socket_set(struct nftnl_expr *e, uint16_t type, switch (type) { case NFTNL_EXPR_SOCKET_KEY: - memcpy(&socket->key, data, sizeof(socket->key)); + memcpy(&socket->key, data, data_len); break; case NFTNL_EXPR_SOCKET_DREG: - memcpy(&socket->dreg, data, sizeof(socket->dreg)); + memcpy(&socket->dreg, data, data_len); + break; + case NFTNL_EXPR_SOCKET_LEVEL: + memcpy(&socket->level, data, data_len); break; - default: - return -1; } return 0; } @@ -56,6 +58,9 @@ nftnl_expr_socket_get(const struct nftnl_expr *e, uint16_t type, case NFTNL_EXPR_SOCKET_DREG: *data_len = sizeof(socket->dreg); return &socket->dreg; + case NFTNL_EXPR_SOCKET_LEVEL: + *data_len = sizeof(socket->level); + return &socket->level; } return NULL; } @@ -71,6 +76,7 @@ static int nftnl_expr_socket_cb(const struct nlattr *attr, void *data) switch (type) { case NFTA_SOCKET_KEY: case NFTA_SOCKET_DREG: + case NFTA_SOCKET_LEVEL: if (mnl_attr_validate(attr, MNL_TYPE_U32) < 0) abi_breakage(); break; @@ -89,6 +95,8 @@ nftnl_expr_socket_build(struct nlmsghdr *nlh, const struct nftnl_expr *e) mnl_attr_put_u32(nlh, NFTA_SOCKET_KEY, htonl(socket->key)); if (e->flags & (1 << NFTNL_EXPR_SOCKET_DREG)) mnl_attr_put_u32(nlh, NFTA_SOCKET_DREG, htonl(socket->dreg)); + if (e->flags & (1 << NFTNL_EXPR_SOCKET_LEVEL)) + mnl_attr_put_u32(nlh, NFTA_SOCKET_LEVEL, htonl(socket->level)); } static int @@ -108,6 +116,10 @@ nftnl_expr_socket_parse(struct nftnl_expr *e, struct nlattr *attr) socket->dreg = ntohl(mnl_attr_get_u32(tb[NFTA_SOCKET_DREG])); e->flags |= (1 << NFTNL_EXPR_SOCKET_DREG); } + if (tb[NFTA_SOCKET_LEVEL]) { + socket->level = ntohl(mnl_attr_get_u32(tb[NFTA_SOCKET_LEVEL])); + e->flags |= (1 << NFTNL_EXPR_SOCKET_LEVEL); + } return 0; } @@ -116,6 +128,7 @@ static const char *socket_key2str_array[NFT_SOCKET_MAX + 1] = { [NFT_SOCKET_TRANSPARENT] = "transparent", [NFT_SOCKET_MARK] = "mark", [NFT_SOCKET_WILDCARD] = "wildcard", + [NFT_SOCKET_CGROUPV2] = "cgroupv2", }; static const char *socket_key2str(uint8_t key) @@ -126,22 +139,9 @@ static const char *socket_key2str(uint8_t key) return "unknown"; } -static inline int str2socket_key(const char *str) -{ - int i; - - for (i = 0; i < NFT_SOCKET_MAX + 1; i++) { - if (strcmp(str, socket_key2str_array[i]) == 0) - return i; - } - - errno = EINVAL; - return -1; -} - static int -nftnl_expr_socket_snprintf_default(char *buf, size_t len, - const struct nftnl_expr *e) +nftnl_expr_socket_snprintf(char *buf, size_t len, + uint32_t flags, const struct nftnl_expr *e) { struct nftnl_expr_socket *socket = nftnl_expr_data(e); @@ -149,31 +149,26 @@ nftnl_expr_socket_snprintf_default(char *buf, size_t len, return snprintf(buf, len, "load %s => reg %u ", socket_key2str(socket->key), socket->dreg); } + if (e->flags & (1 << NFTNL_EXPR_SOCKET_LEVEL)) + return snprintf(buf, len, "level %u ", socket->level); + return 0; } -static int -nftnl_expr_socket_snprintf(char *buf, size_t len, uint32_t type, - uint32_t flags, const struct nftnl_expr *e) -{ - switch (type) { - case NFTNL_OUTPUT_DEFAULT: - return nftnl_expr_socket_snprintf_default(buf, len, e); - case NFTNL_OUTPUT_XML: - case NFTNL_OUTPUT_JSON: - default: - break; - } - return -1; -} +static struct attr_policy socket_attr_policy[__NFTNL_EXPR_SOCKET_MAX] = { + [NFTNL_EXPR_SOCKET_KEY] = { .maxlen = sizeof(uint32_t) }, + [NFTNL_EXPR_SOCKET_DREG] = { .maxlen = sizeof(uint32_t) }, + [NFTNL_EXPR_SOCKET_LEVEL] = { .maxlen = sizeof(uint32_t) }, +}; struct expr_ops expr_ops_socket = { .name = "socket", .alloc_len = sizeof(struct nftnl_expr_socket), - .max_attr = NFTA_SOCKET_MAX, + .nftnl_max_attr = __NFTNL_EXPR_SOCKET_MAX - 1, + .attr_policy = socket_attr_policy, .set = nftnl_expr_socket_set, .get = nftnl_expr_socket_get, .parse = nftnl_expr_socket_parse, .build = nftnl_expr_socket_build, - .snprintf = nftnl_expr_socket_snprintf, + .output = nftnl_expr_socket_snprintf, }; |