From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Markus Koetter <koetter@rrzn.uni-hannover.de>
Cc: netfilter-devel@vger.kernel.org
Subject: Re: [PATCH 4/5] trace: implement commands action
Date: Thu, 25 Jun 2015 16:11:54 +0200 [thread overview]
Message-ID: <20150625141154.GB6579@salvia> (raw)
In-Reply-To: <1434571657-20047-5-git-send-email-koetter@rrzn.uni-hannover.de>
On Wed, Jun 17, 2015 at 10:07:36PM +0200, Markus Koetter wrote:
>
> trace.c is based upon https://git.netfilter.org/libmnl/tree/examples/netfilter/nf-log.c
>
> ---
> include/Makefile.am | 1 +
> include/trace.h | 2 +
> src/Makefile.am | 1 +
> src/rule.c | 1 +
> src/trace.c | 361 ++++++++++++++++++++++++++++++++++++++++++++++++++++
> 5 files changed, 366 insertions(+)
> create mode 100644 include/trace.h
> create mode 100644 src/trace.c
>
> diff --git a/include/Makefile.am b/include/Makefile.am
> index f22561b..c351b55 100644
> --- a/include/Makefile.am
> +++ b/include/Makefile.am
> @@ -19,4 +19,5 @@ noinst_HEADERS = cli.h \
> parser.h \
> proto.h \
> rule.h \
> + trace.h \
> utils.h
> diff --git a/include/trace.h b/include/trace.h
> new file mode 100644
> index 0000000..8c43c86
> --- /dev/null
> +++ b/include/trace.h
> @@ -0,0 +1,2 @@
> +int nft_trace(int qnum, int family);
> +
> diff --git a/src/Makefile.am b/src/Makefile.am
> index 2410fd3..db77e8e 100644
> --- a/src/Makefile.am
> +++ b/src/Makefile.am
> @@ -45,6 +45,7 @@ nft_SOURCES = main.c \
> erec.c \
> mnl.c \
> scanner.l \
> + trace.c \
> parser_bison.y
>
> if BUILD_CLI
> diff --git a/src/rule.c b/src/rule.c
> index dc65452..cd21de0 100644
> --- a/src/rule.c
> +++ b/src/rule.c
> @@ -18,6 +18,7 @@
>
> #include <statement.h>
> #include <rule.h>
> +#include <trace.h>
> #include <utils.h>
> #include <netlink.h>
>
> diff --git a/src/trace.c b/src/trace.c
> new file mode 100644
> index 0000000..a9c9b5f
> --- /dev/null
> +++ b/src/trace.c
> @@ -0,0 +1,361 @@
> +#include <stddef.h>
> +#include <stdio.h>
> +#include <stdlib.h>
> +#include <unistd.h>
> +#include <string.h>
> +#include <time.h>
> +#include <arpa/inet.h>
> +
> +#include <net/ethernet.h>
> +
> +#include <libmnl/libmnl.h>
> +#include <linux/netfilter.h>
> +#include <linux/netfilter/nfnetlink.h>
> +
> +#ifndef aligned_be64
> +#define aligned_be64 u_int64_t __attribute__((aligned(8)))
> +#endif
> +
> +#include <linux/netfilter/nfnetlink_log.h>
> +#include <libmnl/libmnl.h>
> +
> +#include "trace.h"
> +#include "rule.h"
> +#include "statement.h"
> +#include "log.h"
> +
> +struct prefix
> +{
> + char *table;
> + char *chain;
> + char *action;
> + char *num;
> +};
> +
> +static int parse_prefix(char *prefix, struct prefix *td)
> +{
> + static const char *TRACE = "TRACE: ";
> + char *pos;
> + char *cur = NULL;
> + char *end = prefix + strlen(prefix);
> + pos = prefix;
> +
> + /* "TRACE: filter:input:rule:2 " */
> + if (strncmp(prefix, TRACE, strlen(TRACE)) != 0)
> + return -1;
> +
> + pos += strlen(TRACE);
> +
> + if (pos >= end)
> + goto invalid_format_error;
> +
> + /* "filter:input:rule:2 " */
> + /* TABLE:CHAIN:ACTION:NUM */
> + if ( (cur=strchr(pos, ':')) == NULL || cur+1 >= end)
> + goto invalid_format_error;
> + *cur = '\0';
> + td->table = pos;
> + pos = cur+1;
> +
> + if ( (cur=strchr(pos, ':')) == NULL || cur+1 >= end)
> + goto invalid_format_error;
> + *cur = '\0';
> + td->chain = pos;
> + pos = cur+1;
> +
> + if ( (cur=strchr(pos, ':')) == NULL || cur+1 >= end)
> + goto invalid_format_error;
> + *cur = '\0';
> + td->action = pos;
> +
> + td->num = cur+1;
We have to pass this information to nfnetlink_log to express it as
netlink attributes. This requires some changes in the kernel side.
This string parsing is not a good idea.
next prev parent reply other threads:[~2015-06-25 14:06 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-06-17 20:07 [PATCH 0/5] nft trace Markus Koetter
2015-06-17 20:07 ` [PATCH 1/5] parser: add trace command Markus Koetter
2015-06-17 20:07 ` [PATCH 2/5] netlink: delinarize chain policy Markus Koetter
2015-06-26 8:09 ` Pablo Neira Ayuso
2015-06-17 20:07 ` [PATCH 3/5] rule: make cache creation a function Markus Koetter
2015-06-17 20:07 ` [PATCH 4/5] trace: implement commands action Markus Koetter
2015-06-25 14:11 ` Pablo Neira Ayuso [this message]
2015-06-17 20:07 ` [PATCH 5/5] trace: add log for packets Markus Koetter
2015-06-25 13:38 ` Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150625141154.GB6579@salvia \
--to=pablo@netfilter.org \
--cc=koetter@rrzn.uni-hannover.de \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox