From: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
To: netfilter-devel@vger.kernel.org
Cc: kaber@trash.net, pablo@netfilter.org
Subject: [nf_tables PATCH 5/5] netfilter: nf_tables: extend NFT_MSG_DELTABLE to support flushing the ruleset
Date: Tue, 26 Aug 2014 11:57:01 +0200 [thread overview]
Message-ID: <20140826095700.3266.48972.stgit@nfdev.cica.es> (raw)
In-Reply-To: <20140826095238.3266.80742.stgit@nfdev.cica.es>
This patch extend the NFT_MSG_DELTABLE call to support flushing the entire
ruleset.
The options now are:
* No family speficied, no table specified: flush all the ruleset.
* Family specified, no table specified: flush all tables in the AF.
* Family specified, table specified: flush the given table.
Signed-off-by: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
---
net/netfilter/nf_tables_api.c | 84 +++++++++++++++++++++++++++++++++++++++--
1 file changed, 80 insertions(+), 4 deletions(-)
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index d954eed..917bbc2 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -698,6 +698,72 @@ static int nf_tables_newtable(struct sock *nlsk, struct sk_buff *skb,
return 0;
}
+static int nft_flush_table(struct nft_ctx *ctx)
+{
+ int err;
+ struct nft_chain *chain, *nc;
+ struct nft_set *set, *ns;
+
+ list_for_each_entry_safe(chain, nc, &ctx->table->chains, list) {
+ ctx->chain = chain;
+
+ err = nft_delrule_by_chain(ctx);
+ if (err < 0)
+ goto out;
+
+ err = nft_delchain(ctx);
+ if (err < 0)
+ goto out;
+ }
+
+ list_for_each_entry_safe(set, ns, &ctx->table->sets, list) {
+ if (set->flags & NFT_SET_ANONYMOUS)
+ continue;
+
+ err = nft_delset(ctx, set);
+ if (err < 0)
+ goto out;
+ }
+
+ err = nft_deltable(ctx);
+out:
+ return err;
+}
+
+static int nft_flush_family(struct nft_ctx *ctx)
+{
+ int err = 0;
+ struct nft_table *table, *nt;
+
+ list_for_each_entry_safe(table, nt, &ctx->afi->tables, list) {
+ ctx->table = table;
+
+ err = nft_flush_table(ctx);
+ if (err < 0)
+ goto out;
+ }
+
+out:
+ return err;
+}
+
+static int nft_flush_ruleset(struct nft_ctx *ctx)
+{
+ int err = 0;
+ struct nft_af_info *afi;
+
+ list_for_each_entry(afi, &ctx->net->nft.af_info, list) {
+ ctx->afi = afi;
+
+ err = nft_flush_family(ctx);
+ if (err < 0)
+ goto out;
+ }
+
+out:
+ return err;
+}
+
static int nf_tables_deltable(struct sock *nlsk, struct sk_buff *skb,
const struct nlmsghdr *nlh,
const struct nlattr * const nla[])
@@ -709,21 +775,31 @@ static int nf_tables_deltable(struct sock *nlsk, struct sk_buff *skb,
int family = nfmsg->nfgen_family;
struct nft_ctx ctx;
+ if (family == NFPROTO_UNSPEC) {
+ if (nla[NFTA_TABLE_NAME] != NULL)
+ return -EINVAL;
+
+ nft_ctx_init(&ctx, skb, nlh, NULL, NULL, NULL, nla);
+ return nft_flush_ruleset(&ctx);
+ }
+
afi = nf_tables_afinfo_lookup(net, family, false);
if (IS_ERR(afi))
return PTR_ERR(afi);
+ if (nla[NFTA_TABLE_NAME] == NULL) {
+ nft_ctx_init(&ctx, skb, nlh, afi, NULL, NULL, nla);
+ return nft_flush_family(&ctx);
+ }
+
table = nf_tables_table_lookup(afi, nla[NFTA_TABLE_NAME]);
if (IS_ERR(table))
return PTR_ERR(table);
if (table->flags & NFT_TABLE_INACTIVE)
return -ENOENT;
- if (table->use > 0)
- return -EBUSY;
nft_ctx_init(&ctx, skb, nlh, afi, table, NULL, nla);
-
- return nft_deltable(&ctx);
+ return nft_flush_table(&ctx);
}
static void nf_tables_table_destroy(struct nft_ctx *ctx)
next prev parent reply other threads:[~2014-08-26 9:57 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-08-26 9:56 [nf_tables PATCH 0/5] Extended NFT_MSG_DELTABLE Arturo Borrero Gonzalez
2014-08-26 9:56 ` [nf_tables PATCH 1/5] netfilter: nf_tables: refactor rule deletion helper Arturo Borrero Gonzalez
2014-08-26 9:56 ` [nf_tables PATCH 2/5] netfilter: nf_tables: add helper to unregister chain hooks Arturo Borrero Gonzalez
2014-08-26 9:56 ` [nf_tables PATCH 3/5] netfilter: nf_tables: rename nf_table_delrule_by_chain() Arturo Borrero Gonzalez
2014-08-26 9:56 ` [nf_tables PATCH 4/5] netfilter: nf_tables: add helpers to schedule objects deletion Arturo Borrero Gonzalez
2014-08-26 9:57 ` Arturo Borrero Gonzalez [this message]
2014-08-26 10:53 ` [nf_tables PATCH 5/5] netfilter: nf_tables: extend NFT_MSG_DELTABLE to support flushing the ruleset Pablo Neira Ayuso
2014-08-26 11:40 ` Arturo Borrero Gonzalez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140826095700.3266.48972.stgit@nfdev.cica.es \
--to=arturo.borrero.glez@gmail.com \
--cc=kaber@trash.net \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).