1 /* Shared library add-on to iptables to add packet length matching support. */
9 #include <linux/netfilter_ipv4/ipt_length.h>
11 /* Function which prints out usage message. */
16 "length v%s options:\n"
17 "[!] --length length[:length] Match packet length against value or range\n"
18 " of values (inclusive)\n",
23 static struct option opts[] = {
24 { "length", 1, 0, '1' },
28 /* Initialize the match. */
30 init(struct ipt_entry_match *m, unsigned int *nfcache)
32 *nfcache |= NFC_UNKNOWN;
36 parse_length(const char *s)
40 if (string_to_number(s, 0, 0xFFFF, &len) == -1)
41 exit_error(PARAMETER_PROBLEM, "length invalid: `%s'\n", s);
43 return (u_int16_t )len;
46 /* If a single value is provided, min and max are both set to the value */
48 parse_lengths(const char *s, struct ipt_length_info *info)
54 if ((cp = strchr(buffer, ':')) == NULL)
55 info->min = info->max = parse_length(buffer);
60 info->min = buffer[0] ? parse_length(buffer) : 0;
61 info->max = cp[0] ? parse_length(cp) : 0xFFFF;
65 if (info->min > info->max)
66 exit_error(PARAMETER_PROBLEM,
67 "length min. range value `%u' greater than max. "
68 "range value `%u'", info->min, info->max);
72 /* Function which parses command options; returns true if it
75 parse(int c, char **argv, int invert, unsigned int *flags,
76 const struct ipt_entry *entry,
77 unsigned int *nfcache,
78 struct ipt_entry_match **match)
80 struct ipt_length_info *info = (struct ipt_length_info *)(*match)->data;
85 exit_error(PARAMETER_PROBLEM,
86 "length: `--length' may only be "
88 check_inverse(optarg, &invert, &optind, 0);
89 parse_lengths(argv[optind-1], info);
101 /* Final check; must have specified --length. */
103 final_check(unsigned int flags)
106 exit_error(PARAMETER_PROBLEM,
107 "length: You must specify `--length'");
110 /* Common match printing code. */
112 print_length(struct ipt_length_info *info)
117 if (info->max == info->min)
118 printf("%u ", info->min);
120 printf("%u:%u ", info->min, info->max);
123 /* Prints out the matchinfo. */
125 print(const struct ipt_ip *ip,
126 const struct ipt_entry_match *match,
130 print_length((struct ipt_length_info *)match->data);
133 /* Saves the union ipt_matchinfo in parsable form to stdout. */
135 save(const struct ipt_ip *ip, const struct ipt_entry_match *match)
138 print_length((struct ipt_length_info *)match->data);
142 struct iptables_match length
146 IPT_ALIGN(sizeof(struct ipt_length_info)),
147 IPT_ALIGN(sizeof(struct ipt_length_info)),
159 register_match(&length);