From: Michael Zintakis <michael.zintakis@googlemail.com>
To: netfilter-devel@vger.kernel.org
Cc: pablo@netfilter.org
Subject: [PATCH v3 nfacct 8/29] add 2 new options: "replace" and "flush"
Date: Wed, 10 Jul 2013 19:25:06 +0100 [thread overview]
Message-ID: <1373480727-11254-9-git-send-email-michael.zintakis@googlemail.com> (raw)
In-Reply-To: <1373480727-11254-1-git-send-email-michael.zintakis@googlemail.com>
* add "replace" option to the "add" command, allowing nfacct object to be
replaced even if it is used by the kernel/iptables;
* add "replace" and "flush" options to the "restore" command, allowing nfacct
objects to be replaced even if used by the kernel/iptables and also allow the
entire nfacct object list to be deleted, when permissable, prior to "restore"
being executed;
Signed-off-by: Michael Zintakis <michael.zintakis@googlemail.com>
---
src/nfacct.c | 99 +++++++++++++++++++++++++++++++++++++++++++++---------------
1 file changed, 74 insertions(+), 25 deletions(-)
diff --git a/src/nfacct.c b/src/nfacct.c
index fbf9aa6..7808ebb 100644
--- a/src/nfacct.c
+++ b/src/nfacct.c
@@ -214,29 +214,21 @@ static int nfacct_cmd_list(int argc, char *argv[])
return 0;
}
-static int _nfacct_cmd_add(char *name, uint64_t pkts, uint64_t bytes)
+static int _nfacct_cmd_add(struct nfacct *nfacct, bool replace)
{
struct mnl_socket *nl;
char buf[MNL_SOCKET_BUFFER_SIZE];
struct nlmsghdr *nlh;
uint32_t portid, seq;
- struct nfacct *nfacct;
int ret;
- nfacct = nfacct_alloc();
- if (nfacct == NULL) {
- nfacct_perror("OOM");
+ if (nfacct == NULL)
return -1;
- }
-
- nfacct_attr_set(nfacct, NFACCT_ATTR_NAME, name);
-
- nfacct_attr_set_u64(nfacct, NFACCT_ATTR_PKTS, pkts);
- nfacct_attr_set_u64(nfacct, NFACCT_ATTR_BYTES, bytes);
seq = time(NULL);
nlh = nfacct_nlmsg_build_hdr(buf, NFNL_MSG_ACCT_NEW,
- NLM_F_CREATE | NLM_F_ACK, seq);
+ NLM_F_CREATE | NLM_F_ACK |
+ (replace ? NLM_F_REPLACE : 0), seq);
nfacct_nlmsg_build_payload(nlh, nfacct);
nfacct_free(nfacct);
@@ -278,15 +270,41 @@ static int _nfacct_cmd_add(char *name, uint64_t pkts, uint64_t bytes)
static int nfacct_cmd_add(int argc, char *argv[])
{
+ int ret = -1;
+ bool replace = false;
+ char *name;
+ struct nfacct *nfacct;
+
if (argc < 1 || strlen(argv[0]) == 0) {
nfacct_perror("missing object name");
return -1;
- } else if (argc > 1) {
- nfacct_perror("too many arguments");
+ }
+ name = strdup(argv[0]);
+ if (!name) {
+ nfacct_perror("OOM");
return -1;
}
+ NFACCT_NEXT_ARG();
+ while (argc > 0) {
+ if (!replace && nfacct_matches(argv[0],"replace")) {
+ replace = true;
+ } else {
+ NFACCT_RET_ARG_ERR();
+ }
+ argc--; argv++;
+ }
- return _nfacct_cmd_add(argv[0], 0, 0);
+ nfacct = nfacct_alloc();
+ if (nfacct == NULL) {
+ NFACCT_RET_ERR("OOM");
+ }
+
+ nfacct_attr_set(nfacct, NFACCT_ATTR_NAME, name);
+ ret = _nfacct_cmd_add(nfacct, replace);
+
+err:
+ free(name);
+ return ret;
}
static int nfacct_cmd_delete(int argc, char *argv[])
@@ -509,14 +527,14 @@ static const char help_msg[] =
"infrastructure\n"
"Usage: nfacct command [parameters]...\n\n"
"Commands:\n"
- " list [reset]\t\tList the accounting object table (and reset)\n"
- " add object-name\tAdd new accounting object to table\n"
- " delete object-name\tDelete existing accounting object\n"
- " get object-name\tGet existing accounting object\n"
+ " list [reset]\t\t\tList the accounting object table (and reset)\n"
+ " add object-name [replace]\tAdd new accounting object to table\n"
+ " delete object-name\t\tDelete existing accounting object\n"
+ " get object-name\t\tGet existing accounting object\n"
" flush\t\t\tFlush accounting object table\n"
- " restore\t\tRestore accounting object table reading 'list' output from stdin\n"
- " version\t\tDisplay version and disclaimer\n"
- " help\t\t\tDisplay this help message\n";
+ " restore [flush] [replace]\tRestore accounting object table reading 'list' output from stdin\n"
+ " version\t\t\tDisplay version and disclaimer\n"
+ " help\t\t\t\tDisplay this help message\n";
static int nfacct_cmd_help(int argc, char *argv[])
{
@@ -530,11 +548,30 @@ static int nfacct_cmd_restore(int argc, char *argv[])
char name[512];
char buffer[512];
int ret;
+ bool replace = false, flush = false;
+ struct nfacct *nfacct;
- if (argc > 0) {
+ if (argc > 2) {
nfacct_perror("too many arguments");
return -1;
}
+ while (argc > 0) {
+ if (!replace && nfacct_matches(argv[0],"replace")) {
+ replace = true;
+ } else if (!flush && nfacct_matches(argv[0],"flush")) {
+ flush = true;
+ } else {
+ NFACCT_RET_ARG_ERR();
+ }
+ argc--; argv++;
+ }
+
+ if (flush) {
+ ret = nfacct_cmd_flush(0, NULL);
+ if (ret == -1) {
+ NFACCT_RET_ERR("flush not successful");
+ }
+ }
while (fgets(buffer, sizeof(buffer), stdin)) {
char *semicolon = strchr(buffer, ';');
@@ -550,9 +587,21 @@ static int nfacct_cmd_restore(int argc, char *argv[])
nfacct_perror("error reading input");
return -1;
}
- if ((ret = _nfacct_cmd_add(name, pkts, bytes)) != 0)
- return ret;
+ nfacct = nfacct_alloc();
+ if (nfacct == NULL) {
+ NFACCT_RET_ERR("OOM error");
+ }
+ nfacct_attr_set(nfacct, NFACCT_ATTR_NAME, name);
+ nfacct_attr_set_u64(nfacct, NFACCT_ATTR_PKTS, pkts);
+ nfacct_attr_set_u64(nfacct, NFACCT_ATTR_BYTES, bytes);
+ ret = _nfacct_cmd_add(nfacct, replace);
+ if (ret != 0) {
+ NFACCT_RET_ERR("error during add");
+ }
}
return 0;
+
+err:
+ return -1;
}
--
1.8.3.1
next prev parent reply other threads:[~2013-07-10 18:25 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-07-10 18:24 [PATCH v3 0/29] nfacct changes and additions Michael Zintakis
2013-07-10 18:24 ` [PATCH v3 kernel 1/29] bugfix: pkts/bytes need to be specified simultaneously Michael Zintakis
2013-07-10 20:04 ` Florian Westphal
2013-07-11 18:56 ` Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 kernel 2/29] bugfix: restore pkts/bytes counters in NLM_F_REPLACE Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 3/29] bugfix: correct xml name parsing Michael Zintakis
2013-07-15 22:24 ` Pablo Neira Ayuso
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 4/29] bugfix: correct (plain) " Michael Zintakis
2013-07-15 22:29 ` Pablo Neira Ayuso
2013-07-10 18:25 ` [PATCH v3 nfacct 5/29] bugfix: prevent 0-sized parameter being accepted Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 6/29] bugfix: prevent 0-sized nfacct name " Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 7/29] code-refactoring changes to the "command menu" Michael Zintakis
2013-07-15 22:41 ` Pablo Neira Ayuso
2013-07-10 18:25 ` Michael Zintakis [this message]
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 9/29] add *_SAVE template allowing save/restore Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 10/29] add *_BONLY template to show bytes-only Michael Zintakis
2013-07-15 22:42 ` Pablo Neira Ayuso
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 11/29] add variable width and on-the-fly formatting Michael Zintakis
2013-07-15 22:51 ` Pablo Neira Ayuso
2013-07-10 18:25 ` [PATCH v3 nfacct 12/29] add variable width and on-the-fly number formatting Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 13/29] add new "save" and correct existing "restore" commands Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 14/29] add sort option to the "list" command Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 15/29] add "show bytes" option to "list" and "get" commands Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 kernel 16/29] add permanent byte/packet format capability to nfacct Michael Zintakis
2013-07-10 20:00 ` Florian Westphal
2013-07-11 18:56 ` Michael Zintakis
2013-07-11 20:12 ` Florian Westphal
2013-07-14 8:29 ` Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 17/29] add *permanent* number formatting support Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 18/29] add permanent number formatting to nfacct objects Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 kernel 19/29] add byte threshold capability to nfacct Michael Zintakis
2013-07-10 20:00 ` Florian Westphal
2013-07-11 18:56 ` Michael Zintakis
2013-07-11 20:25 ` Florian Westphal
2013-07-17 19:44 ` Alexey Perevalov
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 20/29] add byte threshold capability support Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 21/29] add byte threshold capabilities to nfacct objects Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 22/29] add *_EXTENDED template support Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 23/29] add "show extended" option to "list" and "get" commands Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 kernel 24/29] add packets and bytes mark capability to nfacct Michael Zintakis
2013-07-10 20:01 ` Florian Westphal
2013-07-11 18:56 ` Michael Zintakis
2013-07-11 1:14 ` Pablo Neira Ayuso
2013-07-11 18:56 ` Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 25/29] add packets/bytes mark capability support Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 26/29] add setmark and clrmark to "get" and "list" commands Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 libnetfilter_acct 27/29] add *_MONLY template support Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 28/29] add "show marks" option to "list" and "get" commands Michael Zintakis
2013-07-10 18:25 ` [PATCH v3 nfacct 29/29] change man page to describe all new features Michael Zintakis
2013-07-15 12:36 ` [0/29] nfacct changes and additions Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1373480727-11254-9-git-send-email-michael.zintakis@googlemail.com \
--to=michael.zintakis@googlemail.com \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).