1 /* Shared library add-on to iptables to add MARK target support. */
9 #include <linux/netfilter/x_tables.h>
10 #include <linux/netfilter/xt_MARK.h>
16 /* Function which prints out usage message. */
17 static void MARK_help(void)
20 "MARK target options:\n"
21 " --set-mark value Set nfmark value\n"
22 " --and-mark value Binary AND the nfmark with value\n"
23 " --or-mark value Binary OR the nfmark with value\n"
24 " --copy-xid Set nfmark to be the connection xid (PlanetLab specific)\n"
28 static const struct option MARK_opts[] = {
29 { "set-mark", 1, NULL, '1' },
30 { "and-mark", 1, NULL, '2' },
31 { "or-mark", 1, NULL, '3' },
32 { "copy-xid", 1, 0, '4' },
36 static const struct option mark_tg_opts[] = {
37 {.name = "set-xmark", .has_arg = true, .val = 'X'},
38 {.name = "set-mark", .has_arg = true, .val = '='},
39 {.name = "and-mark", .has_arg = true, .val = '&'},
40 {.name = "or-mark", .has_arg = true, .val = '|'},
41 {.name = "xor-mark", .has_arg = true, .val = '^'},
42 {.name = "copy-xid", .has_arg = true, .val = '%'},
46 static void mark_tg_help(void)
49 "MARK target options:\n"
50 " --set-xmark value[/mask] Clear bits in mask and XOR value into nfmark\n"
51 " --set-mark value[/mask] Clear bits in mask and OR value into nfmark\n"
52 " --and-mark bits Binary AND the nfmark with bits\n"
53 " --or-mark bits Binary OR the nfmark with bits\n"
54 " --copy-xid Set nfmark to be the connection xid (PlanetLab specific)\n"
55 " --xor-mask bits Binary XOR the nfmark with bits\n"
59 /* Function which parses command options; returns true if it
62 MARK_parse_v0(int c, char **argv, int invert, unsigned int *flags,
63 const void *entry, struct xt_entry_target **target)
65 struct xt_mark_target_info *markinfo
66 = (struct xt_mark_target_info *)(*target)->data;
70 if (string_to_number_l(optarg, 0, 0,
72 exit_error(PARAMETER_PROBLEM, "Bad MARK value `%s'", optarg);
74 exit_error(PARAMETER_PROBLEM,
75 "MARK target: Can't specify --set-mark twice");
79 exit_error(PARAMETER_PROBLEM,
80 "MARK target: kernel too old for --and-mark");
82 exit_error(PARAMETER_PROBLEM,
83 "MARK target: kernel too old for --or-mark");
91 static void MARK_check(unsigned int flags)
94 exit_error(PARAMETER_PROBLEM,
95 "MARK target: Parameter --set/and/or-mark"
99 /* Function which parses command options; returns true if it
102 MARK_parse_v1(int c, char **argv, int invert, unsigned int *flags,
103 const void *entry, struct xt_entry_target **target)
105 struct xt_mark_target_info_v1 *markinfo
106 = (struct xt_mark_target_info_v1 *)(*target)->data;
110 markinfo->mode = XT_MARK_SET;
113 markinfo->mode = XT_MARK_AND;
116 markinfo->mode = XT_MARK_OR;
119 markinfo->mode = IPT_MARK_COPYXID;
125 if (string_to_number_l(optarg, 0, 0, &markinfo->mark))
126 exit_error(PARAMETER_PROBLEM, "Bad MARK value `%s'", optarg);
129 exit_error(PARAMETER_PROBLEM,
130 "MARK target: Can't specify --set-mark twice");
136 static int mark_tg_parse(int c, char **argv, int invert, unsigned int *flags,
137 const void *entry, struct xt_entry_target **target)
139 struct xt_mark_tginfo2 *info = (void *)(*target)->data;
140 unsigned int value, mask = ~0U;
144 case 'X': /* --set-xmark */
145 case '=': /* --set-mark */
146 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
147 param_act(P_NO_INVERT, "MARK", "--set-xmark/--set-mark", invert);
148 if (!strtonum(optarg, &end, &value, 0, ~0U))
149 param_act(P_BAD_VALUE, "MARK", "--set-xmark/--set-mark", optarg);
151 if (!strtonum(end + 1, &end, &mask, 0, ~0U))
152 param_act(P_BAD_VALUE, "MARK", "--set-xmark/--set-mark", optarg);
154 param_act(P_BAD_VALUE, "MARK", "--set-xmark/--set-mark", optarg);
159 info->mask = value | mask;
162 case '&': /* --and-mark */
163 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
164 param_act(P_NO_INVERT, "MARK", "--and-mark", invert);
165 if (!strtonum(optarg, NULL, &mask, 0, ~0U))
166 param_act(P_BAD_VALUE, "MARK", "--and-mark", optarg);
171 case '|': /* --or-mark */
172 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
173 param_act(P_NO_INVERT, "MARK", "--or-mark", invert);
174 if (!strtonum(optarg, NULL, &value, 0, ~0U))
175 param_act(P_BAD_VALUE, "MARK", "--or-mark", optarg);
180 case '^': /* --xor-mark */
181 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
182 param_act(P_NO_INVERT, "MARK", "--xor-mark", invert);
183 if (!strtonum(optarg, NULL, &value, 0, ~0U))
184 param_act(P_BAD_VALUE, "MARK", "--xor-mark", optarg);
189 case '%': /* --copy-xid */
190 param_act(P_ONE_ACTION, "MARK", *flags & F_MARK);
191 info->mark = ~0U; /* Consistency check */
203 static void mark_tg_check(unsigned int flags)
206 exit_error(PARAMETER_PROBLEM, "MARK: One of the --set-xmark, "
207 "--{and,or,xor,set}-mark, or --copy-xid options is required");
211 print_mark(unsigned long mark)
213 printf("0x%lx ", mark);
216 /* Prints out the targinfo. */
217 static void MARK_print_v0(const void *ip,
218 const struct xt_entry_target *target, int numeric)
220 const struct xt_mark_target_info *markinfo =
221 (const struct xt_mark_target_info *)target->data;
223 print_mark(markinfo->mark);
226 /* Saves the union ipt_targinfo in parsable form to stdout. */
227 static void MARK_save_v0(const void *ip, const struct xt_entry_target *target)
229 const struct xt_mark_target_info *markinfo =
230 (const struct xt_mark_target_info *)target->data;
232 printf("--set-mark ");
233 print_mark(markinfo->mark);
236 /* Prints out the targinfo. */
237 static void MARK_print_v1(const void *ip, const struct xt_entry_target *target,
240 const struct xt_mark_target_info_v1 *markinfo =
241 (const struct xt_mark_target_info_v1 *)target->data;
243 switch (markinfo->mode) {
253 case IPT_MARK_COPYXID:
254 printf("MARK copyxid ");
257 print_mark(markinfo->mark);
260 static void mark_tg_print(const void *ip, const struct xt_entry_target *target,
263 const struct xt_mark_tginfo2 *info = (const void *)target->data;
265 if (info->mark == ~0U)
266 printf("MARK copy-xid");
267 else if (info->mark == 0)
268 printf("MARK and 0x%x ", (unsigned int)(u_int32_t)~info->mask);
269 else if (info->mark == info->mask)
270 printf("MARK or 0x%x ", info->mark);
271 else if (info->mask == 0)
272 printf("MARK xor 0x%x ", info->mark);
274 printf("MARK xset 0x%x/0x%x ", info->mark, info->mask);
277 /* Saves the union ipt_targinfo in parsable form to stdout. */
278 static void MARK_save_v1(const void *ip, const struct xt_entry_target *target)
280 const struct xt_mark_target_info_v1 *markinfo =
281 (const struct xt_mark_target_info_v1 *)target->data;
283 switch (markinfo->mode) {
285 printf("--set-mark ");
288 printf("--and-mark ");
291 printf("--or-mark ");
293 case IPT_MARK_COPYXID:
294 printf("--copy-xid ");
297 print_mark(markinfo->mark);
300 static void mark_tg_save(const void *ip, const struct xt_entry_target *target)
302 const struct xt_mark_tginfo2 *info = (const void *)target->data;
305 printf("--copy-xid 0x0");
307 printf("--set-xmark 0x%x/0x%x ", info->mark, info->mask);
310 static struct xtables_target mark_target_v0 = {
313 .version = XTABLES_VERSION,
315 .size = XT_ALIGN(sizeof(struct xt_mark_target_info)),
316 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info)),
318 .parse = MARK_parse_v0,
319 .final_check = MARK_check,
320 .print = MARK_print_v0,
321 .save = MARK_save_v0,
322 .extra_opts = MARK_opts,
325 static struct xtables_target mark_target_v1 = {
328 .version = XTABLES_VERSION,
330 .size = XT_ALIGN(sizeof(struct xt_mark_target_info_v1)),
331 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info_v1)),
333 .parse = MARK_parse_v1,
334 .final_check = MARK_check,
335 .print = MARK_print_v1,
336 .save = MARK_save_v1,
337 .extra_opts = MARK_opts,
340 static struct xtables_target mark_target6_v0 = {
343 .version = XTABLES_VERSION,
345 .size = XT_ALIGN(sizeof(struct xt_mark_target_info)),
346 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info)),
348 .parse = MARK_parse_v0,
349 .final_check = MARK_check,
350 .print = MARK_print_v0,
351 .save = MARK_save_v0,
352 .extra_opts = MARK_opts,
355 static struct xtables_target mark_tg_reg_v2 = {
356 .version = XTABLES_VERSION,
360 .size = XT_ALIGN(sizeof(struct xt_mark_tginfo2)),
361 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_tginfo2)),
362 .help = mark_tg_help,
363 .parse = mark_tg_parse,
364 .final_check = mark_tg_check,
365 .print = mark_tg_print,
366 .save = mark_tg_save,
367 .extra_opts = mark_tg_opts,
372 xtables_register_target(&mark_target_v0);
373 xtables_register_target(&mark_target_v1);
374 xtables_register_target(&mark_target6_v0);
375 xtables_register_target(&mark_tg_reg_v2);