diff options
author | Pablo Neira Ayuso <pablo@netfilter.org> | 2013-07-18 19:25:16 +0200 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2013-07-18 19:25:29 +0200 |
commit | 5ecac519cd78043d0a5bfead1922a683d32db9d2 (patch) | |
tree | 120c8dc026c42d75623f1bdf8887d0003682e4a6 /examples/nft-chain-add.c | |
parent | d7e0d23e32f72454b4868c62aa4add5c10675695 (diff) |
examples: nft-chain-add: allow to create custom chains
So far, it was only possible to create base chains. This patch
allows you to create custom chains as well.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'examples/nft-chain-add.c')
-rw-r--r-- | examples/nft-chain-add.c | 41 |
1 files changed, 23 insertions, 18 deletions
diff --git a/examples/nft-chain-add.c b/examples/nft-chain-add.c index 0bf8b43..22f9f3b 100644 --- a/examples/nft-chain-add.c +++ b/examples/nft-chain-add.c @@ -27,11 +27,11 @@ int main(int argc, char *argv[]) struct nlmsghdr *nlh; uint32_t portid, seq; struct nft_chain *t = NULL; - int ret, family, hooknum; + int ret, family, hooknum = 0; - if (argc != 6) { + if (argc != 4 && argc != 6) { fprintf(stderr, "Usage: %s <family> <table> <chain> " - "<hooknum> <prio>\n", + "[<hooknum> <prio>]\n", argv[0]); exit(EXIT_FAILURE); } @@ -49,19 +49,22 @@ int main(int argc, char *argv[]) exit(EXIT_FAILURE); } - if (strcmp(argv[4], "NF_INET_LOCAL_IN") == 0) - hooknum = NF_INET_LOCAL_IN; - else if (strcmp(argv[4], "NF_INET_LOCAL_OUT") == 0) - hooknum = NF_INET_LOCAL_OUT; - else if (strcmp(argv[4], "NF_INET_PRE_ROUTING") == 0) - hooknum = NF_INET_PRE_ROUTING; - else if (strcmp(argv[4], "NF_INET_POST_ROUTING") == 0) - hooknum = NF_INET_POST_ROUTING; - else if (strcmp(argv[4], "NF_INET_FORWARD") == 0) - hooknum = NF_INET_FORWARD; - else { - fprintf(stderr, "Unknown hook: %s\n", argv[4]); - exit(EXIT_FAILURE); + if (argc == 6) { + /* This is a base chain, set the hook number */ + if (strcmp(argv[4], "NF_INET_LOCAL_IN") == 0) + hooknum = NF_INET_LOCAL_IN; + else if (strcmp(argv[4], "NF_INET_LOCAL_OUT") == 0) + hooknum = NF_INET_LOCAL_OUT; + else if (strcmp(argv[4], "NF_INET_PRE_ROUTING") == 0) + hooknum = NF_INET_PRE_ROUTING; + else if (strcmp(argv[4], "NF_INET_POST_ROUTING") == 0) + hooknum = NF_INET_POST_ROUTING; + else if (strcmp(argv[4], "NF_INET_FORWARD") == 0) + hooknum = NF_INET_FORWARD; + else { + fprintf(stderr, "Unknown hook: %s\n", argv[4]); + exit(EXIT_FAILURE); + } } t = nft_chain_alloc(); @@ -74,8 +77,10 @@ int main(int argc, char *argv[]) NLM_F_EXCL|NLM_F_ACK, seq); nft_chain_attr_set(t, NFT_CHAIN_ATTR_TABLE, argv[2]); nft_chain_attr_set(t, NFT_CHAIN_ATTR_NAME, argv[3]); - nft_chain_attr_set_u32(t, NFT_CHAIN_ATTR_HOOKNUM, hooknum); - nft_chain_attr_set_u32(t, NFT_CHAIN_ATTR_PRIO, atoi(argv[5])); + if (argc == 6) { + nft_chain_attr_set_u32(t, NFT_CHAIN_ATTR_HOOKNUM, hooknum); + nft_chain_attr_set_u32(t, NFT_CHAIN_ATTR_PRIO, atoi(argv[5])); + } nft_chain_nlmsg_build_payload(nlh, t); nft_chain_free(t); |