1*a71a9546SAutomerger Merge Worker /*
2*a71a9546SAutomerger Merge Worker * Shared library add-on to iptables to add quota support
3*a71a9546SAutomerger Merge Worker *
4*a71a9546SAutomerger Merge Worker * Sam Johnston <[email protected]>
5*a71a9546SAutomerger Merge Worker */
6*a71a9546SAutomerger Merge Worker #include <stdio.h>
7*a71a9546SAutomerger Merge Worker #include <xtables.h>
8*a71a9546SAutomerger Merge Worker #include <linux/netfilter/xt_quota.h>
9*a71a9546SAutomerger Merge Worker
10*a71a9546SAutomerger Merge Worker enum {
11*a71a9546SAutomerger Merge Worker O_QUOTA = 0,
12*a71a9546SAutomerger Merge Worker };
13*a71a9546SAutomerger Merge Worker
14*a71a9546SAutomerger Merge Worker static const struct xt_option_entry quota_opts[] = {
15*a71a9546SAutomerger Merge Worker {.name = "quota", .id = O_QUOTA, .type = XTTYPE_UINT64,
16*a71a9546SAutomerger Merge Worker .flags = XTOPT_MAND | XTOPT_INVERT | XTOPT_PUT,
17*a71a9546SAutomerger Merge Worker XTOPT_POINTER(struct xt_quota_info, quota)},
18*a71a9546SAutomerger Merge Worker XTOPT_TABLEEND,
19*a71a9546SAutomerger Merge Worker };
20*a71a9546SAutomerger Merge Worker
quota_help(void)21*a71a9546SAutomerger Merge Worker static void quota_help(void)
22*a71a9546SAutomerger Merge Worker {
23*a71a9546SAutomerger Merge Worker printf("quota match options:\n"
24*a71a9546SAutomerger Merge Worker "[!] --quota quota quota (bytes)\n");
25*a71a9546SAutomerger Merge Worker }
26*a71a9546SAutomerger Merge Worker
27*a71a9546SAutomerger Merge Worker static void
quota_print(const void * ip,const struct xt_entry_match * match,int numeric)28*a71a9546SAutomerger Merge Worker quota_print(const void *ip, const struct xt_entry_match *match, int numeric)
29*a71a9546SAutomerger Merge Worker {
30*a71a9546SAutomerger Merge Worker const struct xt_quota_info *q = (const void *)match->data;
31*a71a9546SAutomerger Merge Worker printf(" quota: %llu bytes", (unsigned long long)q->quota);
32*a71a9546SAutomerger Merge Worker }
33*a71a9546SAutomerger Merge Worker
34*a71a9546SAutomerger Merge Worker static void
quota_save(const void * ip,const struct xt_entry_match * match)35*a71a9546SAutomerger Merge Worker quota_save(const void *ip, const struct xt_entry_match *match)
36*a71a9546SAutomerger Merge Worker {
37*a71a9546SAutomerger Merge Worker const struct xt_quota_info *q = (const void *)match->data;
38*a71a9546SAutomerger Merge Worker
39*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_INVERT)
40*a71a9546SAutomerger Merge Worker printf(" !");
41*a71a9546SAutomerger Merge Worker printf(" --quota %llu", (unsigned long long) q->quota);
42*a71a9546SAutomerger Merge Worker }
43*a71a9546SAutomerger Merge Worker
quota_parse(struct xt_option_call * cb)44*a71a9546SAutomerger Merge Worker static void quota_parse(struct xt_option_call *cb)
45*a71a9546SAutomerger Merge Worker {
46*a71a9546SAutomerger Merge Worker struct xt_quota_info *info = cb->data;
47*a71a9546SAutomerger Merge Worker
48*a71a9546SAutomerger Merge Worker xtables_option_parse(cb);
49*a71a9546SAutomerger Merge Worker if (cb->invert)
50*a71a9546SAutomerger Merge Worker info->flags |= XT_QUOTA_INVERT;
51*a71a9546SAutomerger Merge Worker }
52*a71a9546SAutomerger Merge Worker
quota_xlate(struct xt_xlate * xl,const struct xt_xlate_mt_params * params)53*a71a9546SAutomerger Merge Worker static int quota_xlate(struct xt_xlate *xl,
54*a71a9546SAutomerger Merge Worker const struct xt_xlate_mt_params *params)
55*a71a9546SAutomerger Merge Worker {
56*a71a9546SAutomerger Merge Worker const struct xt_quota_info *q = (void *)params->match->data;
57*a71a9546SAutomerger Merge Worker
58*a71a9546SAutomerger Merge Worker xt_xlate_add(xl, "quota %s%llu bytes",
59*a71a9546SAutomerger Merge Worker q->flags & XT_QUOTA_INVERT ? "over " : "",
60*a71a9546SAutomerger Merge Worker (unsigned long long) q->quota);
61*a71a9546SAutomerger Merge Worker return 1;
62*a71a9546SAutomerger Merge Worker }
63*a71a9546SAutomerger Merge Worker
64*a71a9546SAutomerger Merge Worker static struct xtables_match quota_match = {
65*a71a9546SAutomerger Merge Worker .family = NFPROTO_UNSPEC,
66*a71a9546SAutomerger Merge Worker .name = "quota",
67*a71a9546SAutomerger Merge Worker .version = XTABLES_VERSION,
68*a71a9546SAutomerger Merge Worker .size = XT_ALIGN(sizeof (struct xt_quota_info)),
69*a71a9546SAutomerger Merge Worker .userspacesize = offsetof(struct xt_quota_info, master),
70*a71a9546SAutomerger Merge Worker .help = quota_help,
71*a71a9546SAutomerger Merge Worker .print = quota_print,
72*a71a9546SAutomerger Merge Worker .save = quota_save,
73*a71a9546SAutomerger Merge Worker .x6_parse = quota_parse,
74*a71a9546SAutomerger Merge Worker .x6_options = quota_opts,
75*a71a9546SAutomerger Merge Worker .xlate = quota_xlate,
76*a71a9546SAutomerger Merge Worker };
77*a71a9546SAutomerger Merge Worker
78*a71a9546SAutomerger Merge Worker void
_init(void)79*a71a9546SAutomerger Merge Worker _init(void)
80*a71a9546SAutomerger Merge Worker {
81*a71a9546SAutomerger Merge Worker xtables_register_match("a_match);
82*a71a9546SAutomerger Merge Worker }
83