From 8877968858a8dd6b7ae096988d57a7511c81733d Mon Sep 17 00:00:00 2001 From: Giuseppe Longo Date: Mon, 10 Feb 2014 16:49:33 +0100 Subject: nft: adds save_matches_and_target This patch permits to save matches and target for ip/ip6/arp/eb family, required for xtables-events. Also, generalizes nft_rule_print_save to be reused for all protocol families. Signed-off-by: Giuseppe Longo Signed-off-by: Pablo Neira Ayuso --- iptables/nft.c | 33 +++------------------------------ 1 file changed, 3 insertions(+), 30 deletions(-) (limited to 'iptables/nft.c') diff --git a/iptables/nft.c b/iptables/nft.c index fc9db998..515d124a 100644 --- a/iptables/nft.c +++ b/iptables/nft.c @@ -1009,15 +1009,13 @@ nft_rule_append(struct nft_handle *h, const char *chain, const char *table, } void -nft_rule_print_save(const struct iptables_command_state *cs, +nft_rule_print_save(const void *data, struct nft_rule *r, enum nft_rule_print type, unsigned int format) { const char *chain = nft_rule_attr_get_str(r, NFT_RULE_ATTR_CHAIN); int family = nft_rule_attr_get_u8(r, NFT_RULE_ATTR_FAMILY); - struct xtables_rule_match *matchp; struct nft_family_ops *ops; - int ip_flags = 0; /* print chain name */ switch(type) { @@ -1030,35 +1028,10 @@ nft_rule_print_save(const struct iptables_command_state *cs, } ops = nft_family_ops_lookup(family); - ip_flags = ops->save_firewall(cs, format); - - for (matchp = cs->matches; matchp; matchp = matchp->next) { - if (matchp->match->alias) { - printf("-m %s", - matchp->match->alias(matchp->match->m)); - } else - printf("-m %s", matchp->match->name); - - if (matchp->match->save != NULL) { - /* cs->fw union makes the trick */ - matchp->match->save(&cs->fw, matchp->match->m); - } - printf(" "); - } - if (cs->target != NULL) { - if (cs->target->alias) { - printf("-j %s", cs->target->alias(cs->target->t)); - } else - printf("-j %s", cs->jumpto); + if (ops->save_firewall) + ops->save_firewall(data, format); - if (cs->target->save != NULL) - cs->target->save(&cs->fw, cs->target->t); - } else if (strlen(cs->jumpto) > 0) - printf("-%c %s", ip_flags & IPT_F_GOTO ? 'g' : 'j', - cs->jumpto); - - printf("\n"); } static int nft_chain_list_cb(const struct nlmsghdr *nlh, void *data) -- cgit v1.2.3