From 39d498c9250ff9ad21c4a8a18b7696d44676d5ea Mon Sep 17 00:00:00 2001 From: "/C=EU/ST=EU/CN=Pablo Neira Ayuso/emailAddress=pablo@netfilter.org" Date: Sat, 9 Feb 2008 17:23:16 +0000 Subject: From: Eric Leblond : When using NFLOG or ULOG, obb.family (protocol IPv4 or IPv6) has to be setup manually in ulogd.conf configuration file. This is used by the BASE filter to properly parse the packet. This patch suppress oob.family as output keys of NFLOG and ULOG and let the BASE filter determine the family of the packet by itself (by parsing the raw header). A good side effect is to be able to log in IPv6 and IPv4 in the same group. Before that, two loggers have to be setup separatly. --- filter/raw2packet/ulogd_raw2packet_BASE.c | 32 ++++++++++++++++++++++--------- 1 file changed, 23 insertions(+), 9 deletions(-) (limited to 'filter/raw2packet/ulogd_raw2packet_BASE.c') diff --git a/filter/raw2packet/ulogd_raw2packet_BASE.c b/filter/raw2packet/ulogd_raw2packet_BASE.c index 48f2993..62a9a87 100644 --- a/filter/raw2packet/ulogd_raw2packet_BASE.c +++ b/filter/raw2packet/ulogd_raw2packet_BASE.c @@ -44,6 +44,7 @@ #include enum output_keys { + KEY_OOB_FAMILY, KEY_IP_SADDR, KEY_IP_DADDR, KEY_IP_PROTOCOL, @@ -98,6 +99,11 @@ enum output_keys { }; static struct ulogd_key iphdr_rets[] = { + [KEY_OOB_FAMILY] = { + .type = ULOGD_RET_UINT8, + .flags = ULOGD_RETF_NONE, + .name = "oob.family", + }, [KEY_IP_SADDR] = { .type = ULOGD_RET_IPADDR, .flags = ULOGD_RETF_NONE, @@ -819,15 +825,27 @@ out: static int _interp_pkt(struct ulogd_pluginstance *pi) { + struct ulogd_key *ret = pi->output.keys; + struct iphdr *iph = pi->input.keys[0].u.source->u.value.ptr; u_int32_t len = pi->input.keys[1].u.source->u.value.ui32; u_int8_t family = pi->input.keys[2].u.source->u.value.ui8; - switch (family) { - case AF_INET: - return _interp_iphdr(pi, len); - case AF_INET6: - return _interp_ipv6hdr(pi, len); + switch (iph->version) { + case 4: + ret[KEY_OOB_FAMILY].u.value.ui8 = AF_INET; + ret[KEY_OOB_FAMILY].flags |= ULOGD_RETF_VALID; + + return _interp_iphdr(pi, len); + case 6: + ret[KEY_OOB_FAMILY].u.value.ui8 = AF_INET6; + ret[KEY_OOB_FAMILY].flags |= ULOGD_RETF_VALID; + + return _interp_ipv6hdr(pi, len); + default: + /* unknown protocol */ + return 0; } + return 0; } @@ -847,10 +865,6 @@ static struct ulogd_key base_inp[] = { .vendor = IPFIX_VENDOR_NETFILTER, .field_id = IPFIX_NF_rawpacket_length, }, - }, - { - .type = ULOGD_RET_UINT8, - .name = "oob.family", } }; -- cgit v1.2.3