2 * m_egress.c ingress/egress packet mirror/redir actions module
4 * This program is free software; you can distribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version
7 * 2 of the License, or (at your option) any later version.
9 * Authors: J Hadi Salim (hadi@cyberus.ca)
11 * TODO: Add Ingress support
20 #include <sys/socket.h>
21 #include <netinet/in.h>
22 #include <arpa/inet.h>
26 #include "tc_common.h"
27 #include <linux/tc_act/tc_mirred.h>
34 fprintf(stderr, "Usage: mirred <DIRECTION> <ACTION> [index INDEX] <dev DEVICENAME> \n");
35 fprintf(stderr, "where: \n");
36 fprintf(stderr, "\tDIRECTION := <ingress | egress>\n");
37 fprintf(stderr, "\tACTION := <mirror | redirect>\n");
38 fprintf(stderr, "\tINDEX is the specific policy instance id\n");
39 fprintf(stderr, "\tDEVICENAME is the devicename \n");
50 char *mirred_n2a(int action)
53 case TCA_EGRESS_REDIR:
54 return "Egress Redirect";
55 case TCA_INGRESS_REDIR:
56 return "Ingress Redirect";
57 case TCA_EGRESS_MIRROR:
58 return "Egress Mirror";
59 case TCA_INGRESS_MIRROR:
60 return "Ingress Mirror";
67 parse_egress(struct action_util *a, int *argc_p, char ***argv_p, int tca_id, struct nlmsghdr *n)
71 char **argv = *argv_p;
72 int ok = 0, iok = 0, mirror=0,redir=0;
77 memset(d,0,sizeof(d)-1);
78 memset(&p,0,sizeof(struct tc_mirred));
82 if (matches(*argv, "action") == 0) {
84 } else if (matches(*argv, "egress") == 0) {
90 if (matches(*argv, "index") == 0) {
92 if (get_u32(&p.index, *argv, 10)) {
93 fprintf(stderr, "Illegal \"index\"\n");
103 fprintf(stderr, "was expecting egress (%s)\n", *argv);
106 } else if (!mirror && matches(*argv, "mirror") == 0) {
109 fprintf(stderr, "Cant have both mirror and redir\n");
112 p.eaction = TCA_EGRESS_MIRROR;
113 p.action = TC_ACT_PIPE;
115 } else if (!redir && matches(*argv, "redirect") == 0) {
118 fprintf(stderr, "Cant have both mirror and redir\n");
121 p.eaction = TCA_EGRESS_REDIR;
122 p.action = TC_ACT_STOLEN;
124 } else if ((redir || mirror) && matches(*argv, "dev") == 0) {
127 duparg("dev", *argv);
129 strncpy(d, *argv, sizeof(d)-1);
151 if ((idx = ll_name_to_index(d)) == 0) {
152 fprintf(stderr, "Cannot find device \"%s\"\n", d);
160 if (argc && p.eaction == TCA_EGRESS_MIRROR) {
162 if (matches(*argv, "reclassify") == 0) {
163 p.action = TC_POLICE_RECLASSIFY;
165 } else if (matches(*argv, "pipe") == 0) {
166 p.action = TC_POLICE_PIPE;
168 } else if (matches(*argv, "drop") == 0 ||
169 matches(*argv, "shot") == 0) {
170 p.action = TC_POLICE_SHOT;
172 } else if (matches(*argv, "continue") == 0) {
173 p.action = TC_POLICE_UNSPEC;
175 } else if (matches(*argv, "pass") == 0) {
176 p.action = TC_POLICE_OK;
183 if (iok && matches(*argv, "index") == 0) {
184 fprintf(stderr, "mirred: Illegal double index\n");
187 if (matches(*argv, "index") == 0) {
189 if (get_u32(&p.index, *argv, 10)) {
190 fprintf(stderr, "mirred: Illegal \"index\"\n");
200 fprintf(stdout, "Action %d device %s ifindex %d\n",p.action, d,p.ifindex);
202 tail = NLMSG_TAIL(n);
203 addattr_l(n, MAX_MSG, tca_id, NULL, 0);
204 addattr_l(n, MAX_MSG, TCA_MIRRED_PARMS, &p, sizeof (p));
205 tail->rta_len = (void *) NLMSG_TAIL(n) - (void *) tail;
214 parse_mirred(struct action_util *a, int *argc_p, char ***argv_p, int tca_id, struct nlmsghdr *n)
218 char **argv = *argv_p;
221 fprintf(stderr,"mirred bad arguement count %d\n", argc);
225 if (matches(*argv, "mirred") == 0) {
228 fprintf(stderr,"mirred bad arguement %s\n", *argv);
233 if (matches(*argv, "egress") == 0 || matches(*argv, "index") == 0) {
234 int ret = parse_egress(a, &argc, &argv, tca_id, n);
241 } else if (matches(*argv, "ingress") == 0) {
242 fprintf(stderr,"mirred ingress not supported at the moment\n");
243 } else if (matches(*argv, "help") == 0) {
246 fprintf(stderr,"mirred option not supported %s\n", *argv);
254 print_mirred(struct action_util *au,FILE * f, struct rtattr *arg)
257 struct rtattr *tb[TCA_MIRRED_MAX + 1];
264 parse_rtattr_nested(tb, TCA_MIRRED_MAX, arg);
266 if (tb[TCA_MIRRED_PARMS] == NULL) {
267 fprintf(f, "[NULL mirred parameters]");
270 p = RTA_DATA(tb[TCA_MIRRED_PARMS]);
277 if ((dev = ll_index_to_name(p->ifindex)) == 0) {
278 fprintf(stderr, "Cannot find device %d\n", p->ifindex);
282 fprintf(f, "mirred (%s to device %s) %s", mirred_n2a(p->eaction), dev,action_n2a(p->action, b1, sizeof (b1)));
285 fprintf(f, "\tindex %d ref %d bind %d",p->index,p->refcnt,p->bindcnt);
288 if (tb[TCA_MIRRED_TM]) {
289 struct tcf_t *tm = RTA_DATA(tb[TCA_MIRRED_TM]);
297 struct action_util mirred_action_util = {
299 .parse_aopt = parse_mirred,
300 .print_aopt = print_mirred,