14 #include <arpa/inet.h>
16 #include <linux/netfilter/nf_tables.h>
19 #include <libmnl/libmnl.h>
20 #include <libnftnl/expr.h>
21 #include <libnftnl/rule.h>
24 enum nft_registers dreg;
26 enum nft_ng_types type;
31 nftnl_expr_ng_set(
struct nftnl_expr *e, uint16_t type,
32 const void *data, uint32_t data_len)
37 case NFTNL_EXPR_NG_DREG:
38 memcpy(&ng->dreg, data,
sizeof(ng->dreg));
40 case NFTNL_EXPR_NG_MODULUS:
41 memcpy(&ng->modulus, data,
sizeof(ng->modulus));
43 case NFTNL_EXPR_NG_TYPE:
44 memcpy(&ng->type, data,
sizeof(ng->type));
46 case NFTNL_EXPR_NG_OFFSET:
47 memcpy(&ng->offset, data,
sizeof(ng->offset));
56 nftnl_expr_ng_get(
const struct nftnl_expr *e, uint16_t type,
62 case NFTNL_EXPR_NG_DREG:
63 *data_len =
sizeof(ng->dreg);
65 case NFTNL_EXPR_NG_MODULUS:
66 *data_len =
sizeof(ng->modulus);
68 case NFTNL_EXPR_NG_TYPE:
69 *data_len =
sizeof(ng->type);
71 case NFTNL_EXPR_NG_OFFSET:
72 *data_len =
sizeof(ng->offset);
78 static int nftnl_expr_ng_cb(
const struct nlattr *attr,
void *data)
80 const struct nlattr **tb = data;
81 int type = mnl_attr_get_type(attr);
83 if (mnl_attr_type_valid(attr, NFTA_NG_MAX) < 0)
91 if (mnl_attr_validate(attr, MNL_TYPE_U32) < 0)
101 nftnl_expr_ng_build(
struct nlmsghdr *nlh,
const struct nftnl_expr *e)
105 if (e->flags & (1 << NFTNL_EXPR_NG_DREG))
106 mnl_attr_put_u32(nlh, NFTA_NG_DREG, htonl(ng->dreg));
107 if (e->flags & (1 << NFTNL_EXPR_NG_MODULUS))
108 mnl_attr_put_u32(nlh, NFTA_NG_MODULUS, htonl(ng->modulus));
109 if (e->flags & (1 << NFTNL_EXPR_NG_TYPE))
110 mnl_attr_put_u32(nlh, NFTA_NG_TYPE, htonl(ng->type));
111 if (e->flags & (1 << NFTNL_EXPR_NG_OFFSET))
112 mnl_attr_put_u32(nlh, NFTA_NG_OFFSET, htonl(ng->offset));
116 nftnl_expr_ng_parse(
struct nftnl_expr *e,
struct nlattr *attr)
119 struct nlattr *tb[NFTA_NG_MAX+1] = {};
122 if (mnl_attr_parse_nested(attr, nftnl_expr_ng_cb, tb) < 0)
125 if (tb[NFTA_NG_DREG]) {
126 ng->dreg = ntohl(mnl_attr_get_u32(tb[NFTA_NG_DREG]));
127 e->flags |= (1 << NFTNL_EXPR_NG_DREG);
129 if (tb[NFTA_NG_MODULUS]) {
130 ng->modulus = ntohl(mnl_attr_get_u32(tb[NFTA_NG_MODULUS]));
131 e->flags |= (1 << NFTNL_EXPR_NG_MODULUS);
133 if (tb[NFTA_NG_TYPE]) {
134 ng->type = ntohl(mnl_attr_get_u32(tb[NFTA_NG_TYPE]));
135 e->flags |= (1 << NFTNL_EXPR_NG_TYPE);
137 if (tb[NFTA_NG_OFFSET]) {
138 ng->offset = ntohl(mnl_attr_get_u32(tb[NFTA_NG_OFFSET]));
139 e->flags |= (1 << NFTNL_EXPR_NG_OFFSET);
146 nftnl_expr_ng_snprintf_default(
char *buf,
size_t size,
147 const struct nftnl_expr *e)
150 int remain = size, offset = 0, ret;
153 case NFT_NG_INCREMENTAL:
154 ret = snprintf(buf, remain,
"reg %u = inc mod %u ",
155 ng->dreg, ng->modulus);
156 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
159 ret = snprintf(buf, remain,
"reg %u = random mod %u ",
160 ng->dreg, ng->modulus);
161 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
168 ret = snprintf(buf + offset, remain,
"offset %u ", ng->offset);
169 SNPRINTF_BUFFER_SIZE(ret, remain, offset);
176 nftnl_expr_ng_snprintf(
char *buf,
size_t len, uint32_t type,
177 uint32_t flags,
const struct nftnl_expr *e)
180 case NFTNL_OUTPUT_DEFAULT:
181 return nftnl_expr_ng_snprintf_default(buf, len, e);
182 case NFTNL_OUTPUT_XML:
183 case NFTNL_OUTPUT_JSON:
190 struct expr_ops expr_ops_ng = {
193 .max_attr = NFTA_NG_MAX,
194 .set = nftnl_expr_ng_set,
195 .get = nftnl_expr_ng_get,
196 .parse = nftnl_expr_ng_parse,
197 .build = nftnl_expr_ng_build,
198 .snprintf = nftnl_expr_ng_snprintf,