1 /* Shared library add-on to iptables to add TOS matching support. */
9 #include <linux/netfilter_ipv4/ipt_tos.h>
11 /* TOS names and values. */
18 { IPTOS_LOWDELAY, "Minimize-Delay" },
19 { IPTOS_THROUGHPUT, "Maximize-Throughput" },
20 { IPTOS_RELIABILITY, "Maximize-Reliability" },
21 { IPTOS_MINCOST, "Minimize-Cost" },
22 { IPTOS_NORMALSVC, "Normal-Service" },
25 /* Function which prints out usage message. */
32 "TOS match v%s options:\n"
33 "[!] --tos value Match Type of Service field from one of the\n"
34 " following numeric or descriptive values:\n",
37 for (i = 0; i < sizeof(TOS_values)/sizeof(struct TOS_value);i++)
38 printf(" %s %u (0x%02x)\n",
45 static struct option opts[] = {
50 /* Initialize the match. */
52 init(struct ipt_entry_match *m, unsigned int *nfcache)
54 *nfcache |= NFC_IP_TOS;
58 parse_tos(const unsigned char *s, struct ipt_tos_info *info)
63 if (string_to_number(s, 0, 255, &tos) != -1) {
64 if (tos == IPTOS_LOWDELAY
65 || tos == IPTOS_THROUGHPUT
66 || tos == IPTOS_RELIABILITY
67 || tos == IPTOS_MINCOST
68 || tos == IPTOS_NORMALSVC) {
69 info->tos = (u_int8_t )tos;
73 for (i = 0; i<sizeof(TOS_values)/sizeof(struct TOS_value); i++)
74 if (strcasecmp(s,TOS_values[i].name) == 0) {
75 info->tos = TOS_values[i].TOS;
79 exit_error(PARAMETER_PROBLEM, "Bad TOS value `%s'", s);
82 /* Function which parses command options; returns true if it
85 parse(int c, char **argv, int invert, unsigned int *flags,
86 const struct ipt_entry *entry,
87 unsigned int *nfcache,
88 struct ipt_entry_match **match)
90 struct ipt_tos_info *tosinfo = (struct ipt_tos_info *)(*match)->data;
94 check_inverse(optarg, &invert, &optind, 0);
95 parse_tos(argv[optind-1], tosinfo);
108 print_tos(u_int8_t tos, int numeric)
113 for (i = 0; i<sizeof(TOS_values)/sizeof(struct TOS_value); i++)
114 if (TOS_values[i].TOS == tos) {
115 printf("%s ", TOS_values[i].name);
119 printf("0x%02x ", tos);
122 /* Final check; must have specified --tos. */
124 final_check(unsigned int flags)
127 exit_error(PARAMETER_PROBLEM,
128 "TOS match: You must specify `--tos'");
131 /* Prints out the matchinfo. */
133 print(const struct ipt_ip *ip,
134 const struct ipt_entry_match *match,
137 const struct ipt_tos_info *info = (const struct ipt_tos_info *)match->data;
139 printf("TOS match ");
142 print_tos(info->tos, numeric);
145 /* Saves the union ipt_matchinfo in parsable form to stdout. */
147 save(const struct ipt_ip *ip, const struct ipt_entry_match *match)
149 const struct ipt_tos_info *info = (const struct ipt_tos_info *)match->data;
154 print_tos(info->tos, 0);
158 struct iptables_match tos
162 IPT_ALIGN(sizeof(struct ipt_tos_info)),
163 IPT_ALIGN(sizeof(struct ipt_tos_info)),
175 register_match(&tos);