1 /* Shared library add-on to iptables to add MARK target support. */
9 #include <linux/netfilter/x_tables.h>
10 #include <linux/netfilter/xt_MARK.h>
16 /* Function which prints out usage message. */
17 static void MARK_help(void)
20 "MARK target options:\n"
21 " --set-mark value Set nfmark value\n"
22 " --and-mark value Binary AND the nfmark with value\n"
23 " --or-mark value Binary OR the nfmark with value\n"
24 " --copy-xid Set nfmark to be the connection xid (PlanetLab specific)\n"
28 static const struct option MARK_opts[] = {
29 { "set-mark", 1, NULL, '1' },
30 { "and-mark", 1, NULL, '2' },
31 { "or-mark", 1, NULL, '3' },
32 { "copy-xid", 1, 0, '4' },
36 static const struct option mark_tg_opts[] = {
37 {.name = "set-xmark", .has_arg = true, .val = 'X'},
38 {.name = "set-mark", .has_arg = true, .val = '='},
39 {.name = "and-mark", .has_arg = true, .val = '&'},
40 {.name = "or-mark", .has_arg = true, .val = '|'},
41 {.name = "xor-mark", .has_arg = true, .val = '^'},
42 {.name = "copy-xid", .has_arg = true, .val = '%'},
46 static void mark_tg_help(void)
49 "MARK target options:\n"
50 " --set-xmark value[/mask] Clear bits in mask and XOR value into nfmark\n"
51 " --set-mark value[/mask] Clear bits in mask and OR value into nfmark\n"
52 " --and-mark bits Binary AND the nfmark with bits\n"
53 " --or-mark bits Binary OR the nfmark with bits\n"
54 " --copy-xid Set nfmark to be the connection xid (PlanetLab specific)\n"
55 " --xor-mask bits Binary XOR the nfmark with bits\n"
59 /* Function which parses command options; returns true if it
62 MARK_parse_v0(int c, char **argv, int invert, unsigned int *flags,
63 const void *entry, struct xt_entry_target **target)
65 struct xt_mark_target_info *markinfo
66 = (struct xt_mark_target_info *)(*target)->data;
70 if (string_to_number_l(optarg, 0, 0,
72 exit_error(PARAMETER_PROBLEM, "Bad MARK value `%s'", optarg);
74 exit_error(PARAMETER_PROBLEM,
75 "MARK target: Can't specify --set-mark twice");
79 exit_error(PARAMETER_PROBLEM,
80 "MARK target: kernel too old for --and-mark");
82 exit_error(PARAMETER_PROBLEM,
83 "MARK target: kernel too old for --or-mark");
91 static void MARK_check(unsigned int flags)
94 exit_error(PARAMETER_PROBLEM,
95 "MARK target: Parameter --set/and/or-mark"
99 /* Function which parses command options; returns true if it
102 MARK_parse_v1(int c, char **argv, int invert, unsigned int *flags,
103 const void *entry, struct xt_entry_target **target)
105 struct xt_mark_target_info_v1 *markinfo
106 = (struct xt_mark_target_info_v1 *)(*target)->data;
110 markinfo->mode = XT_MARK_SET;
113 markinfo->mode = XT_MARK_AND;
116 markinfo->mode = XT_MARK_OR;
119 markinfo->mode = IPT_MARK_COPYXID;
125 if (string_to_number_l(optarg, 0, 0, &markinfo->mark))
126 exit_error(PARAMETER_PROBLEM, "Bad MARK value `%s'", optarg);
129 exit_error(PARAMETER_PROBLEM,
130 "MARK target: Can't specify --set-mark twice");
136 static int mark_tg_parse(int c, char **argv, int invert, unsigned int *flags,
137 const void *entry, struct xt_entry_target **target)
139 struct xt_mark_tginfo2 *info = (void *)(*target)->data;
140 unsigned int value, mask = ~0U;
144 case 'X': /* --set-xmark */
145 case '=': /* --set-mark */
146 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
147 param_act(P_NO_INVERT, "MARK", "--set-xmark/--set-mark", invert);
148 if (!strtonum(optarg, &end, &value, 0, ~0U))
149 param_act(P_BAD_VALUE, "MARK", "--set-xmark/--set-mark", optarg);
151 if (!strtonum(end + 1, &end, &mask, 0, ~0U))
152 param_act(P_BAD_VALUE, "MARK", "--set-xmark/--set-mark", optarg);
154 param_act(P_BAD_VALUE, "MARK", "--set-xmark/--set-mark", optarg);
159 info->mask = value | mask;
162 case '&': /* --and-mark */
163 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
164 param_act(P_NO_INVERT, "MARK", "--and-mark", invert);
165 if (!strtonum(optarg, NULL, &mask, 0, ~0U))
166 param_act(P_BAD_VALUE, "MARK", "--and-mark", optarg);
171 case '|': /* --or-mark */
172 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
173 param_act(P_NO_INVERT, "MARK", "--or-mark", invert);
174 if (!strtonum(optarg, NULL, &value, 0, ~0U))
175 param_act(P_BAD_VALUE, "MARK", "--or-mark", optarg);
180 case '^': /* --xor-mark */
181 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
182 param_act(P_NO_INVERT, "MARK", "--xor-mark", invert);
183 if (!strtonum(optarg, NULL, &value, 0, ~0U))
184 param_act(P_BAD_VALUE, "MARK", "--xor-mark", optarg);
189 case '%': /* --copy-xid */
190 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
203 static void mark_tg_check(unsigned int flags)
206 exit_error(PARAMETER_PROBLEM, "MARK: One of the --set-xmark, "
207 "--{and,or,xor,set}-mark, or --copy-xid options is required");
211 print_mark(unsigned long mark)
213 printf("0x%lx ", mark);
216 /* Prints out the targinfo. */
217 static void MARK_print_v0(const void *ip,
218 const struct xt_entry_target *target, int numeric)
220 const struct xt_mark_target_info *markinfo =
221 (const struct xt_mark_target_info *)target->data;
223 print_mark(markinfo->mark);
226 /* Saves the union ipt_targinfo in parsable form to stdout. */
227 static void MARK_save_v0(const void *ip, const struct xt_entry_target *target)
229 const struct xt_mark_target_info *markinfo =
230 (const struct xt_mark_target_info *)target->data;
232 printf("--set-mark ");
233 print_mark(markinfo->mark);
236 /* Prints out the targinfo. */
237 static void MARK_print_v1(const void *ip, const struct xt_entry_target *target,
240 const struct xt_mark_target_info_v1 *markinfo =
241 (const struct xt_mark_target_info_v1 *)target->data;
243 switch (markinfo->mode) {
253 case IPT_MARK_COPYXID:
254 printf("MARK copyxid ");
257 print_mark(markinfo->mark);
260 static void mark_tg_print(const void *ip, const struct xt_entry_target *target,
263 const struct xt_mark_tginfo2 *info = (const void *)target->data;
266 printf("MARK and 0x%x ", (unsigned int)(u_int32_t)~info->mask);
267 else if (info->mark == info->mask)
268 printf("MARK or 0x%x ", info->mark);
269 else if (info->mask == 0)
270 printf("MARK xor 0x%x ", info->mark);
272 printf("MARK xset 0x%x/0x%x ", info->mark, info->mask);
275 /* Saves the union ipt_targinfo in parsable form to stdout. */
276 static void MARK_save_v1(const void *ip, const struct xt_entry_target *target)
278 const struct xt_mark_target_info_v1 *markinfo =
279 (const struct xt_mark_target_info_v1 *)target->data;
281 switch (markinfo->mode) {
283 printf("--set-mark ");
286 printf("--and-mark ");
289 printf("--or-mark ");
291 case IPT_MARK_COPYXID:
292 printf("--copy-xid ");
295 print_mark(markinfo->mark);
298 static void mark_tg_save(const void *ip, const struct xt_entry_target *target)
300 const struct xt_mark_tginfo2 *info = (const void *)target->data;
302 printf("--set-xmark 0x%x/0x%x ", info->mark, info->mask);
305 static struct xtables_target mark_target_v0 = {
308 .version = XTABLES_VERSION,
310 .size = XT_ALIGN(sizeof(struct xt_mark_target_info)),
311 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info)),
313 .parse = MARK_parse_v0,
314 .final_check = MARK_check,
315 .print = MARK_print_v0,
316 .save = MARK_save_v0,
317 .extra_opts = MARK_opts,
320 static struct xtables_target mark_target_v1 = {
323 .version = XTABLES_VERSION,
325 .size = XT_ALIGN(sizeof(struct xt_mark_target_info_v1)),
326 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info_v1)),
328 .parse = MARK_parse_v1,
329 .final_check = MARK_check,
330 .print = MARK_print_v1,
331 .save = MARK_save_v1,
332 .extra_opts = MARK_opts,
335 static struct xtables_target mark_target6_v0 = {
338 .version = XTABLES_VERSION,
340 .size = XT_ALIGN(sizeof(struct xt_mark_target_info)),
341 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info)),
343 .parse = MARK_parse_v0,
344 .final_check = MARK_check,
345 .print = MARK_print_v0,
346 .save = MARK_save_v0,
347 .extra_opts = MARK_opts,
350 static struct xtables_target mark_tg_reg_v2 = {
351 .version = XTABLES_VERSION,
355 .size = XT_ALIGN(sizeof(struct xt_mark_tginfo2)),
356 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_tginfo2)),
357 .help = mark_tg_help,
358 .parse = mark_tg_parse,
359 .final_check = mark_tg_check,
360 .print = mark_tg_print,
361 .save = mark_tg_save,
362 .extra_opts = mark_tg_opts,
367 xtables_register_target(&mark_target_v0);
368 xtables_register_target(&mark_target_v1);
369 xtables_register_target(&mark_target6_v0);
370 xtables_register_target(&mark_tg_reg_v2);