From 033ec6be245261cd5e53e5a01435afea71ef6230 Mon Sep 17 00:00:00 2001 From: Florian Westphal Date: Wed, 3 Jul 2013 13:06:22 +0200 Subject: conntrack: api: add nfct_snprintf_labels nfct_snprintf doesn't print connlabels, as they're system specific and can easily generate lots of output. This adds a new helper function, nfct_snprintf_labels. It behaves like nfct_snprintf, except that the label names in the labelmap whose bits are contained in connlabel attribute bitset are added to the buffer. output looks like this: output looks like this: ... mark=0 use=1 labels=eth0-in,eth1-in or Signed-off-by: Florian Westphal --- src/conntrack/api.c | 29 +++++++++++++++++++-- src/conntrack/snprintf.c | 7 ++--- src/conntrack/snprintf_default.c | 56 +++++++++++++++++++++++++++++++++++++++- src/conntrack/snprintf_xml.c | 33 ++++++++++++++++++++++- 4 files changed, 118 insertions(+), 7 deletions(-) (limited to 'src') diff --git a/src/conntrack/api.c b/src/conntrack/api.c index b6c453f..cad860e 100644 --- a/src/conntrack/api.c +++ b/src/conntrack/api.c @@ -1071,13 +1071,38 @@ int nfct_snprintf(char *buf, const struct nf_conntrack *ct, unsigned int msg_type, unsigned int out_type, - unsigned int flags) + unsigned int flags) { assert(buf != NULL); assert(size > 0); assert(ct != NULL); - return __snprintf_conntrack(buf, size, ct, msg_type, out_type, flags); + return __snprintf_conntrack(buf, size, ct, msg_type, out_type, flags, NULL); +} + +/** + * nfct_snprintf_labels - print a bitmask object to a buffer including labels + * \param buf buffer used to build the printable conntrack + * \param size size of the buffer + * \param ct pointer to a valid conntrack object + * \param message_type print message type (NFCT_T_UNKNOWN, NFCT_T_NEW,...) + * \param output_type print type (NFCT_O_DEFAULT, NFCT_O_XML, ...) + * \param flags extra flags for the output type (NFCT_OF_LAYER3) + * \param map nfct_labelmap describing the connlabel translation, or NULL. + * + * When map is NULL, the function is equal to nfct_snprintf(). + * Otherwise, if the conntrack object has a connlabel attribute, the active + * labels are translated using the label map and added to the buffer. + */ +int nfct_snprintf_labels(char *buf, + unsigned int size, + const struct nf_conntrack *ct, + unsigned int msg_type, + unsigned int out_type, + unsigned int flags, + struct nfct_labelmap *map) +{ + return __snprintf_conntrack(buf, size, ct, msg_type, out_type, flags, map); } /** diff --git a/src/conntrack/snprintf.c b/src/conntrack/snprintf.c index 9a9017d..17ad885 100644 --- a/src/conntrack/snprintf.c +++ b/src/conntrack/snprintf.c @@ -68,16 +68,17 @@ int __snprintf_conntrack(char *buf, const struct nf_conntrack *ct, unsigned int type, unsigned int msg_output, - unsigned int flags) + unsigned int flags, + struct nfct_labelmap *map) { int size; switch(msg_output) { case NFCT_O_DEFAULT: - size = __snprintf_conntrack_default(buf, len, ct, type, flags); + size = __snprintf_conntrack_default(buf, len, ct, type, flags, map); break; case NFCT_O_XML: - size = __snprintf_conntrack_xml(buf, len, ct, type, flags); + size = __snprintf_conntrack_xml(buf, len, ct, type, flags, map); break; default: errno = ENOENT; diff --git a/src/conntrack/snprintf_default.c b/src/conntrack/snprintf_default.c index 911faea..24e2f28 100644 --- a/src/conntrack/snprintf_default.c +++ b/src/conntrack/snprintf_default.c @@ -288,11 +288,60 @@ __snprintf_helper_name(char *buf, unsigned int len, const struct nf_conntrack *c return (snprintf(buf, len, "helper=%s ", ct->helper_name)); } +int +__snprintf_connlabels(char *buf, unsigned int len, + struct nfct_labelmap *map, + const struct nfct_bitmask *b, const char *fmt) +{ + unsigned int i, max; + int ret, size = 0, offset = 0; + + max = nfct_bitmask_maxbit(b); + for (i = 0; i <= max && len; i++) { + const char *name; + if (!nfct_bitmask_test_bit(b, i)) + continue; + name = nfct_labelmap_get_name(map, i); + if (!name || strcmp(name, "") == 0) + continue; + + ret = snprintf(buf + offset, len, fmt, name); + BUFFER_SIZE(ret, size, len, offset); + } + return size; +} + +static int +__snprintf_clabels(char *buf, unsigned int len, + const struct nf_conntrack *ct, struct nfct_labelmap *map) +{ + const struct nfct_bitmask *b = nfct_get_attr(ct, ATTR_CONNLABELS); + int ret, size = 0, offset = 0; + + if (!b) + return 0; + + ret = snprintf(buf, len, "labels="); + BUFFER_SIZE(ret, size, len, offset); + + ret = __snprintf_connlabels(buf + offset, len, map, b, "%s,"); + + BUFFER_SIZE(ret, size, len, offset); + + offset--; /* remove last , */ + size--; + ret = snprintf(buf + offset, len, " "); + BUFFER_SIZE(ret, size, len, offset); + + return size; +} + int __snprintf_conntrack_default(char *buf, unsigned int len, const struct nf_conntrack *ct, unsigned int msg_type, - unsigned int flags) + unsigned int flags, + struct nfct_labelmap *map) { int ret = 0, size = 0, offset = 0; @@ -426,6 +475,11 @@ int __snprintf_conntrack_default(char *buf, BUFFER_SIZE(ret, size, len, offset); } + if (map && test_bit(ATTR_CONNLABELS, ct->head.set)) { + ret = __snprintf_clabels(buf+offset, len, ct, map); + BUFFER_SIZE(ret, size, len, offset); + } + /* Delete the last blank space */ size--; diff --git a/src/conntrack/snprintf_xml.c b/src/conntrack/snprintf_xml.c index ad53075..37f51b4 100644 --- a/src/conntrack/snprintf_xml.c +++ b/src/conntrack/snprintf_xml.c @@ -348,11 +348,35 @@ static int __snprintf_tuple_xml(char *buf, return size; } +static int +__snprintf_clabels_xml(char *buf, unsigned int len, + const struct nf_conntrack *ct, struct nfct_labelmap *map) +{ + const struct nfct_bitmask *b = nfct_get_attr(ct, ATTR_CONNLABELS); + int ret, size = 0, offset = 0; + + if (!b) + return 0; + + ret = snprintf(buf, len, ""); + BUFFER_SIZE(ret, size, len, offset); + + ret = __snprintf_connlabels(buf + offset, len, map, b, ""); + + BUFFER_SIZE(ret, size, len, offset); + + ret = snprintf(buf + offset, len, ""); + BUFFER_SIZE(ret, size, len, offset); + + return size; +} + int __snprintf_conntrack_xml(char *buf, unsigned int len, const struct nf_conntrack *ct, const unsigned int msg_type, - const unsigned int flags) + const unsigned int flags, + struct nfct_labelmap *map) { int ret = 0; unsigned int size = 0, offset = 0; @@ -390,6 +414,7 @@ int __snprintf_conntrack_xml(char *buf, test_bit(ATTR_USE, ct->head.set) || test_bit(ATTR_STATUS, ct->head.set) || test_bit(ATTR_ID, ct->head.set) || + test_bit(ATTR_CONNLABELS, ct->head.set) || test_bit(ATTR_TIMESTAMP_START, ct->head.set) || test_bit(ATTR_TIMESTAMP_STOP, ct->head.set)) { ret = snprintf(buf+offset, len, @@ -432,6 +457,11 @@ int __snprintf_conntrack_xml(char *buf, BUFFER_SIZE(ret, size, len, offset); } + if (map && test_bit(ATTR_CONNLABELS, ct->head.set)) { + ret = __snprintf_clabels_xml(buf+offset, len, ct, map); + BUFFER_SIZE(ret, size, len, offset); + } + if (test_bit(ATTR_SECMARK, ct->head.set)) { ret = snprintf(buf+offset, len, "%u", ct->secmark); @@ -510,6 +540,7 @@ int __snprintf_conntrack_xml(char *buf, test_bit(ATTR_USE, ct->head.set) || test_bit(ATTR_STATUS, ct->head.set) || test_bit(ATTR_ID, ct->head.set) || + test_bit(ATTR_CONNLABELS, ct->head.set) || test_bit(ATTR_TIMESTAMP_START, ct->head.set) || test_bit(ATTR_TIMESTAMP_STOP, ct->head.set)) { ret = snprintf(buf+offset, len, ""); -- cgit v1.2.3