diff options
author | Phil Sutter <phil@nwl.cc> | 2019-10-30 21:45:39 +0100 |
---|---|---|
committer | Phil Sutter <phil@nwl.cc> | 2019-11-07 12:46:16 +0100 |
commit | 332325e3c3fab4c25bb5f387f9663205f63748dc (patch) | |
tree | b9e616a69a3b87829c4f6531a6677119d9af6275 /include/nftables.h | |
parent | 856c78d4fdc73ac746ef1473f08d78cf2ebcbc4c (diff) |
libnftables: Store top_scope in struct nft_ctx
Allow for interactive sessions to make use of defines. Since parser is
initialized for each line, top scope defines didn't persist although
they are actually useful for stuff like:
| # nft -i
| define goodports = { 22, 23, 80, 443 }
| add rule inet t c tcp dport $goodports accept
| add rule inet t c tcp sport $goodports accept
While being at it, introduce scope_alloc() and scope_free().
Signed-off-by: Phil Sutter <phil@nwl.cc>
Acked-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'include/nftables.h')
-rw-r--r-- | include/nftables.h | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/include/nftables.h b/include/nftables.h index 21553c6b..90d33196 100644 --- a/include/nftables.h +++ b/include/nftables.h @@ -104,6 +104,7 @@ struct nft_cache { struct mnl_socket; struct parser_state; +struct scope; #define MAX_INCLUDE_DEPTH 16 @@ -119,6 +120,7 @@ struct nft_ctx { uint32_t flags; struct parser_state *state; void *scanner; + struct scope *top_scope; void *json_root; FILE *f[MAX_INCLUDE_DEPTH]; }; |