summaryrefslogtreecommitdiffstats
path: root/src/obj/secmark.c
blob: e5c24b35a7eb608e465c19026756e349188cac1c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
/*
 * (C) 2012-2016 by Pablo Neira Ayuso <pablo@netfilter.org>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published
 * by the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 */

#include <stdio.h>
#include <stdint.h>
#include <arpa/inet.h>
#include <errno.h>
#include <inttypes.h>

#include <linux/netfilter/nf_tables.h>

#include "internal.h"
#include <libmnl/libmnl.h>
#include <libnftnl/object.h>

#include "obj.h"

static int nftnl_obj_secmark_set(struct nftnl_obj *e, uint16_t type,
				const void *data, uint32_t data_len)
{
	struct nftnl_obj_secmark *secmark = nftnl_obj_data(e);

	switch (type) {
	case NFTNL_OBJ_SECMARK_CTX:
		snprintf(secmark->ctx, sizeof(secmark->ctx), "%s", (const char *)data);
		break;
	default:
		return -1;
	}
	return 0;
}

static const void *nftnl_obj_secmark_get(const struct nftnl_obj *e,
					uint16_t type, uint32_t *data_len)
{
	struct nftnl_obj_secmark *secmark = nftnl_obj_data(e);

	switch (type) {
	case NFTNL_OBJ_SECMARK_CTX:
		*data_len = strlen(secmark->ctx);
		return secmark->ctx;
	}
	return NULL;
}

static int nftnl_obj_secmark_cb(const struct nlattr *attr, void *data)
{
	const struct nftnl_obj_secmark *secmark = NULL;
	int type = mnl_attr_get_type(attr);
	const struct nlattr **tb = data;

	if (mnl_attr_type_valid(attr, NFTA_SECMARK_MAX) < 0)
		return MNL_CB_OK;

	switch(type) {
	case NFTA_SECMARK_CTX:
		if (mnl_attr_validate(attr, MNL_TYPE_STRING) < 0)
			abi_breakage();
		if (mnl_attr_get_payload_len(attr) >= sizeof(secmark->ctx))
			abi_breakage();
		break;
	}

	tb[type] = attr;
	return MNL_CB_OK;
}

static void
nftnl_obj_secmark_build(struct nlmsghdr *nlh, const struct nftnl_obj *e)
{
	struct nftnl_obj_secmark *secmark = nftnl_obj_data(e);

	if (e->flags & (1 << NFTNL_OBJ_SECMARK_CTX))
		mnl_attr_put_str(nlh, NFTA_SECMARK_CTX, secmark->ctx);
}

static int
nftnl_obj_secmark_parse(struct nftnl_obj *e, struct nlattr *attr)
{
	struct nftnl_obj_secmark *secmark = nftnl_obj_data(e);
	struct nlattr *tb[NFTA_SECMARK_MAX + 1] = {};

	if (mnl_attr_parse_nested(attr, nftnl_obj_secmark_cb, tb) < 0)
		return -1;

	if (tb[NFTA_SECMARK_CTX]) {
		snprintf(secmark->ctx, sizeof(secmark->ctx), "%s",
			 mnl_attr_get_str(tb[NFTA_SECMARK_CTX]));
		e->flags |= (1 << NFTNL_OBJ_SECMARK_CTX);
	}

	return 0;
}

static int nftnl_obj_secmark_snprintf(char *buf, size_t len,
				       uint32_t flags,
				       const struct nftnl_obj *e)
{
	struct nftnl_obj_secmark *secmark = nftnl_obj_data(e);

	return snprintf(buf, len, "context %s ", secmark->ctx);
}

struct obj_ops obj_ops_secmark = {
	.name		= "secmark",
	.type		= NFT_OBJECT_SECMARK,
	.alloc_len	= sizeof(struct nftnl_obj_secmark),
	.max_attr	= NFTA_SECMARK_MAX,
	.set		= nftnl_obj_secmark_set,
	.get		= nftnl_obj_secmark_get,
	.parse		= nftnl_obj_secmark_parse,
	.build		= nftnl_obj_secmark_build,
	.output		= nftnl_obj_secmark_snprintf,
};