1*a71a9546SAutomerger Merge Worker /*
2*a71a9546SAutomerger Merge Worker * "quota2" match extension for iptables
3*a71a9546SAutomerger Merge Worker * Sam Johnston <samj [at] samj net>
4*a71a9546SAutomerger Merge Worker * Jan Engelhardt <jengelh [at] medozas de>, 2008
5*a71a9546SAutomerger Merge Worker *
6*a71a9546SAutomerger Merge Worker * This program is free software; you can redistribute it and/or
7*a71a9546SAutomerger Merge Worker * modify it under the terms of the GNU General Public License; either
8*a71a9546SAutomerger Merge Worker * version 2 of the License, or any later version, as published by the
9*a71a9546SAutomerger Merge Worker * Free Software Foundation.
10*a71a9546SAutomerger Merge Worker */
11*a71a9546SAutomerger Merge Worker #include <getopt.h>
12*a71a9546SAutomerger Merge Worker #include <stddef.h>
13*a71a9546SAutomerger Merge Worker #include <stdio.h>
14*a71a9546SAutomerger Merge Worker #include <stdlib.h>
15*a71a9546SAutomerger Merge Worker #include <string.h>
16*a71a9546SAutomerger Merge Worker #include <xtables.h>
17*a71a9546SAutomerger Merge Worker #include <linux/netfilter/xt_quota2.h>
18*a71a9546SAutomerger Merge Worker
19*a71a9546SAutomerger Merge Worker enum {
20*a71a9546SAutomerger Merge Worker FL_QUOTA = 1 << 0,
21*a71a9546SAutomerger Merge Worker FL_NAME = 1 << 1,
22*a71a9546SAutomerger Merge Worker FL_GROW = 1 << 2,
23*a71a9546SAutomerger Merge Worker FL_PACKET = 1 << 3,
24*a71a9546SAutomerger Merge Worker FL_NO_CHANGE = 1 << 4,
25*a71a9546SAutomerger Merge Worker };
26*a71a9546SAutomerger Merge Worker
27*a71a9546SAutomerger Merge Worker enum {
28*a71a9546SAutomerger Merge Worker O_QUOTA = 0,
29*a71a9546SAutomerger Merge Worker O_NAME,
30*a71a9546SAutomerger Merge Worker O_GROW,
31*a71a9546SAutomerger Merge Worker O_PACKET,
32*a71a9546SAutomerger Merge Worker O_NO_CHANGE,
33*a71a9546SAutomerger Merge Worker };
34*a71a9546SAutomerger Merge Worker
35*a71a9546SAutomerger Merge Worker
36*a71a9546SAutomerger Merge Worker static const struct xt_option_entry quota_mt2_opts[] = {
37*a71a9546SAutomerger Merge Worker {.name = "grow", .id = O_GROW, .type = XTTYPE_NONE},
38*a71a9546SAutomerger Merge Worker {.name = "no-change", .id = O_NO_CHANGE, .type = XTTYPE_NONE},
39*a71a9546SAutomerger Merge Worker {.name = "name", .id = O_NAME, .type = XTTYPE_STRING,
40*a71a9546SAutomerger Merge Worker .flags = XTOPT_PUT, XTOPT_POINTER(struct xt_quota_mtinfo2, name)},
41*a71a9546SAutomerger Merge Worker {.name = "quota", .id = O_QUOTA, .type = XTTYPE_UINT64,
42*a71a9546SAutomerger Merge Worker .flags = XTOPT_INVERT | XTOPT_PUT,
43*a71a9546SAutomerger Merge Worker XTOPT_POINTER(struct xt_quota_mtinfo2, quota)},
44*a71a9546SAutomerger Merge Worker {.name = "packets", .id = O_PACKET, .type = XTTYPE_NONE},
45*a71a9546SAutomerger Merge Worker XTOPT_TABLEEND,
46*a71a9546SAutomerger Merge Worker };
47*a71a9546SAutomerger Merge Worker
quota_mt2_help(void)48*a71a9546SAutomerger Merge Worker static void quota_mt2_help(void)
49*a71a9546SAutomerger Merge Worker {
50*a71a9546SAutomerger Merge Worker printf(
51*a71a9546SAutomerger Merge Worker "quota match options:\n"
52*a71a9546SAutomerger Merge Worker " --grow provide an increasing counter\n"
53*a71a9546SAutomerger Merge Worker " --no-change never change counter/quota value for matching packets\n"
54*a71a9546SAutomerger Merge Worker " --name name name for the file in sysfs\n"
55*a71a9546SAutomerger Merge Worker "[!] --quota quota initial quota (bytes or packets)\n"
56*a71a9546SAutomerger Merge Worker " --packets count packets instead of bytes\n"
57*a71a9546SAutomerger Merge Worker );
58*a71a9546SAutomerger Merge Worker }
59*a71a9546SAutomerger Merge Worker
quota_mt2_parse(struct xt_option_call * cb)60*a71a9546SAutomerger Merge Worker static void quota_mt2_parse(struct xt_option_call *cb)
61*a71a9546SAutomerger Merge Worker {
62*a71a9546SAutomerger Merge Worker struct xt_quota_mtinfo2 *info = cb->data;
63*a71a9546SAutomerger Merge Worker
64*a71a9546SAutomerger Merge Worker xtables_option_parse(cb);
65*a71a9546SAutomerger Merge Worker switch (cb->entry->id) {
66*a71a9546SAutomerger Merge Worker case O_GROW:
67*a71a9546SAutomerger Merge Worker info->flags |= XT_QUOTA_GROW;
68*a71a9546SAutomerger Merge Worker break;
69*a71a9546SAutomerger Merge Worker case O_NO_CHANGE:
70*a71a9546SAutomerger Merge Worker info->flags |= XT_QUOTA_NO_CHANGE;
71*a71a9546SAutomerger Merge Worker break;
72*a71a9546SAutomerger Merge Worker case O_NAME:
73*a71a9546SAutomerger Merge Worker break;
74*a71a9546SAutomerger Merge Worker case O_PACKET:
75*a71a9546SAutomerger Merge Worker info->flags |= XT_QUOTA_PACKET;
76*a71a9546SAutomerger Merge Worker break;
77*a71a9546SAutomerger Merge Worker case O_QUOTA:
78*a71a9546SAutomerger Merge Worker if (cb->invert)
79*a71a9546SAutomerger Merge Worker info->flags |= XT_QUOTA_INVERT;
80*a71a9546SAutomerger Merge Worker break;
81*a71a9546SAutomerger Merge Worker }
82*a71a9546SAutomerger Merge Worker }
83*a71a9546SAutomerger Merge Worker
84*a71a9546SAutomerger Merge Worker static void
quota_mt2_save(const void * ip,const struct xt_entry_match * match)85*a71a9546SAutomerger Merge Worker quota_mt2_save(const void *ip, const struct xt_entry_match *match)
86*a71a9546SAutomerger Merge Worker {
87*a71a9546SAutomerger Merge Worker const struct xt_quota_mtinfo2 *q = (void *)match->data;
88*a71a9546SAutomerger Merge Worker
89*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_INVERT)
90*a71a9546SAutomerger Merge Worker printf(" !");
91*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_GROW)
92*a71a9546SAutomerger Merge Worker printf(" --grow ");
93*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_NO_CHANGE)
94*a71a9546SAutomerger Merge Worker printf(" --no-change ");
95*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_PACKET)
96*a71a9546SAutomerger Merge Worker printf(" --packets ");
97*a71a9546SAutomerger Merge Worker if (*q->name != '\0')
98*a71a9546SAutomerger Merge Worker printf(" --name %s ", q->name);
99*a71a9546SAutomerger Merge Worker printf(" --quota %llu ", (unsigned long long)q->quota);
100*a71a9546SAutomerger Merge Worker }
101*a71a9546SAutomerger Merge Worker
quota_mt2_print(const void * ip,const struct xt_entry_match * match,int numeric)102*a71a9546SAutomerger Merge Worker static void quota_mt2_print(const void *ip, const struct xt_entry_match *match,
103*a71a9546SAutomerger Merge Worker int numeric)
104*a71a9546SAutomerger Merge Worker {
105*a71a9546SAutomerger Merge Worker const struct xt_quota_mtinfo2 *q = (const void *)match->data;
106*a71a9546SAutomerger Merge Worker
107*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_INVERT)
108*a71a9546SAutomerger Merge Worker printf(" !");
109*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_GROW)
110*a71a9546SAutomerger Merge Worker printf(" counter");
111*a71a9546SAutomerger Merge Worker else
112*a71a9546SAutomerger Merge Worker printf(" quota");
113*a71a9546SAutomerger Merge Worker if (*q->name != '\0')
114*a71a9546SAutomerger Merge Worker printf(" %s:", q->name);
115*a71a9546SAutomerger Merge Worker printf(" %llu ", (unsigned long long)q->quota);
116*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_PACKET)
117*a71a9546SAutomerger Merge Worker printf("packets ");
118*a71a9546SAutomerger Merge Worker else
119*a71a9546SAutomerger Merge Worker printf("bytes ");
120*a71a9546SAutomerger Merge Worker if (q->flags & XT_QUOTA_NO_CHANGE)
121*a71a9546SAutomerger Merge Worker printf("(no-change mode) ");
122*a71a9546SAutomerger Merge Worker }
123*a71a9546SAutomerger Merge Worker
124*a71a9546SAutomerger Merge Worker static struct xtables_match quota_mt2_reg = {
125*a71a9546SAutomerger Merge Worker .family = NFPROTO_UNSPEC,
126*a71a9546SAutomerger Merge Worker .revision = 3,
127*a71a9546SAutomerger Merge Worker .name = "quota2",
128*a71a9546SAutomerger Merge Worker .version = XTABLES_VERSION,
129*a71a9546SAutomerger Merge Worker .size = XT_ALIGN(sizeof (struct xt_quota_mtinfo2)),
130*a71a9546SAutomerger Merge Worker .userspacesize = offsetof(struct xt_quota_mtinfo2, quota),
131*a71a9546SAutomerger Merge Worker .help = quota_mt2_help,
132*a71a9546SAutomerger Merge Worker .x6_parse = quota_mt2_parse,
133*a71a9546SAutomerger Merge Worker .print = quota_mt2_print,
134*a71a9546SAutomerger Merge Worker .save = quota_mt2_save,
135*a71a9546SAutomerger Merge Worker .x6_options = quota_mt2_opts,
136*a71a9546SAutomerger Merge Worker };
137*a71a9546SAutomerger Merge Worker
_init(void)138*a71a9546SAutomerger Merge Worker void _init(void)
139*a71a9546SAutomerger Merge Worker {
140*a71a9546SAutomerger Merge Worker xtables_register_match("a_mt2_reg);
141*a71a9546SAutomerger Merge Worker }
142