libnl 3.7.0
queue_msg.c
1/* SPDX-License-Identifier: LGPL-2.1-only */
2/*
3 * Copyright (c) 2007, 2008 Patrick McHardy <kaber@trash.net>
4 * Copyright (c) 2010 Karl Hiramoto <karl@hiramoto.org>
5 */
6
7/**
8 * @ingroup nfnl
9 * @defgroup queue Queue
10 * @brief
11 * @{
12 */
13
14#include <sys/types.h>
15#include <linux/netfilter/nfnetlink_queue.h>
16
17#include <netlink-private/netlink.h>
18#include <netlink/attr.h>
19#include <netlink/netfilter/nfnl.h>
20#include <netlink/netfilter/queue_msg.h>
21#include <netlink-private/utils.h>
22
23static struct nl_cache_ops nfnl_queue_msg_ops;
24
25static struct nla_policy queue_policy[NFQA_MAX+1] = {
26 [NFQA_PACKET_HDR] = {
27 .minlen = sizeof(struct nfqnl_msg_packet_hdr),
28 },
29 [NFQA_VERDICT_HDR] = {
30 .minlen = sizeof(struct nfqnl_msg_verdict_hdr),
31 },
32 [NFQA_MARK] = { .type = NLA_U32 },
33 [NFQA_TIMESTAMP] = {
34 .minlen = sizeof(struct nfqnl_msg_packet_timestamp),
35 },
36 [NFQA_IFINDEX_INDEV] = { .type = NLA_U32 },
37 [NFQA_IFINDEX_OUTDEV] = { .type = NLA_U32 },
38 [NFQA_IFINDEX_PHYSINDEV] = { .type = NLA_U32 },
39 [NFQA_IFINDEX_PHYSOUTDEV] = { .type = NLA_U32 },
40 [NFQA_HWADDR] = {
41 .minlen = sizeof(struct nfqnl_msg_packet_hw),
42 },
43};
44
45int nfnlmsg_queue_msg_parse(struct nlmsghdr *nlh,
46 struct nfnl_queue_msg **result)
47{
48 struct nfnl_queue_msg *msg;
49 struct nlattr *tb[NFQA_MAX+1];
50 struct nlattr *attr;
51 int err;
52
53 msg = nfnl_queue_msg_alloc();
54 if (!msg)
55 return -NLE_NOMEM;
56
57 msg->ce_msgtype = nlh->nlmsg_type;
58
59 err = nlmsg_parse(nlh, sizeof(struct nfgenmsg), tb, NFQA_MAX,
60 queue_policy);
61 if (err < 0)
62 goto errout;
63
64 nfnl_queue_msg_set_group(msg, nfnlmsg_res_id(nlh));
65 nfnl_queue_msg_set_family(msg, nfnlmsg_family(nlh));
66
67 attr = tb[NFQA_PACKET_HDR];
68 if (attr) {
69 struct nfqnl_msg_packet_hdr *hdr = nla_data(attr);
70
71 nfnl_queue_msg_set_packetid(msg, ntohl(hdr->packet_id));
72 if (hdr->hw_protocol)
73 nfnl_queue_msg_set_hwproto(msg, hdr->hw_protocol);
74 nfnl_queue_msg_set_hook(msg, hdr->hook);
75 }
76
77 attr = tb[NFQA_MARK];
78 if (attr)
79 nfnl_queue_msg_set_mark(msg, ntohl(nla_get_u32(attr)));
80
81 attr = tb[NFQA_TIMESTAMP];
82 if (attr) {
83 struct nfqnl_msg_packet_timestamp *timestamp = nla_data(attr);
84 struct timeval tv;
85
86 tv.tv_sec = ntohll(timestamp->sec);
87 tv.tv_usec = ntohll(timestamp->usec);
88 nfnl_queue_msg_set_timestamp(msg, &tv);
89 }
90
91 attr = tb[NFQA_IFINDEX_INDEV];
92 if (attr)
93 nfnl_queue_msg_set_indev(msg, ntohl(nla_get_u32(attr)));
94
95 attr = tb[NFQA_IFINDEX_OUTDEV];
96 if (attr)
97 nfnl_queue_msg_set_outdev(msg, ntohl(nla_get_u32(attr)));
98
99 attr = tb[NFQA_IFINDEX_PHYSINDEV];
100 if (attr)
101 nfnl_queue_msg_set_physindev(msg, ntohl(nla_get_u32(attr)));
102
103 attr = tb[NFQA_IFINDEX_PHYSOUTDEV];
104 if (attr)
105 nfnl_queue_msg_set_physoutdev(msg, ntohl(nla_get_u32(attr)));
106
107 attr = tb[NFQA_HWADDR];
108 if (attr) {
109 struct nfqnl_msg_packet_hw *hw = nla_data(attr);
110
111 nfnl_queue_msg_set_hwaddr(msg, hw->hw_addr,
112 ntohs(hw->hw_addrlen));
113 }
114
115 attr = tb[NFQA_PAYLOAD];
116 if (attr) {
117 err = nfnl_queue_msg_set_payload(msg, nla_data(attr),
118 nla_len(attr));
119 if (err < 0)
120 goto errout;
121 }
122
123 *result = msg;
124 return 0;
125
126errout:
127 nfnl_queue_msg_put(msg);
128 return err;
129}
130
131static int queue_msg_parser(struct nl_cache_ops *ops, struct sockaddr_nl *who,
132 struct nlmsghdr *nlh, struct nl_parser_param *pp)
133{
134 struct nfnl_queue_msg *msg;
135 int err;
136
137 if ((err = nfnlmsg_queue_msg_parse(nlh, &msg)) < 0)
138 return err;
139
140 err = pp->pp_cb((struct nl_object *) msg, pp);
141 nfnl_queue_msg_put(msg);
142 return err;
143}
144
145/** @} */
146
147static struct nl_msg *
148__nfnl_queue_msg_build_verdict(const struct nfnl_queue_msg *msg,
149 uint8_t type)
150{
151 struct nl_msg *nlmsg;
152 struct nfqnl_msg_verdict_hdr verdict;
153
154 nlmsg = nfnlmsg_alloc_simple(NFNL_SUBSYS_QUEUE, type, 0,
155 nfnl_queue_msg_get_family(msg),
156 nfnl_queue_msg_get_group(msg));
157 if (nlmsg == NULL)
158 return NULL;
159
160 verdict.id = htonl(nfnl_queue_msg_get_packetid(msg));
161 verdict.verdict = htonl(nfnl_queue_msg_get_verdict(msg));
162 if (nla_put(nlmsg, NFQA_VERDICT_HDR, sizeof(verdict), &verdict) < 0)
163 goto nla_put_failure;
164
165 if (nfnl_queue_msg_test_mark(msg) &&
166 nla_put_u32(nlmsg, NFQA_MARK,
167 ntohl(nfnl_queue_msg_get_mark(msg))) < 0)
168 goto nla_put_failure;
169
170 return nlmsg;
171
172nla_put_failure:
173 nlmsg_free(nlmsg);
174 return NULL;
175}
176
177struct nl_msg *
178nfnl_queue_msg_build_verdict(const struct nfnl_queue_msg *msg)
179{
180 return __nfnl_queue_msg_build_verdict(msg, NFQNL_MSG_VERDICT);
181}
182
183struct nl_msg *
184nfnl_queue_msg_build_verdict_batch(const struct nfnl_queue_msg *msg)
185{
186 return __nfnl_queue_msg_build_verdict(msg, NFQNL_MSG_VERDICT_BATCH);
187}
188
189/**
190* Send a message verdict/mark
191* @arg nlh netlink messsage header
192* @arg msg queue msg
193* @return 0 on OK or error code
194*/
195int nfnl_queue_msg_send_verdict(struct nl_sock *nlh,
196 const struct nfnl_queue_msg *msg)
197{
198 struct nl_msg *nlmsg;
199 int err;
200
201 nlmsg = nfnl_queue_msg_build_verdict(msg);
202 if (nlmsg == NULL)
203 return -NLE_NOMEM;
204
205 err = nl_send_auto_complete(nlh, nlmsg);
206 nlmsg_free(nlmsg);
207 if (err < 0)
208 return err;
209 return wait_for_ack(nlh);
210}
211
212/**
213* Send a message batched verdict/mark
214* @arg nlh netlink messsage header
215* @arg msg queue msg
216* @return 0 on OK or error code
217*/
218int nfnl_queue_msg_send_verdict_batch(struct nl_sock *nlh,
219 const struct nfnl_queue_msg *msg)
220{
221 struct nl_msg *nlmsg;
222 int err;
223
224 nlmsg = nfnl_queue_msg_build_verdict_batch(msg);
225 if (nlmsg == NULL)
226 return -NLE_NOMEM;
227
228 err = nl_send_auto_complete(nlh, nlmsg);
229 nlmsg_free(nlmsg);
230 if (err < 0)
231 return err;
232 return wait_for_ack(nlh);
233}
234
235/**
236* Send a message verdict including the payload
237* @arg nlh netlink messsage header
238* @arg msg queue msg
239* @arg payload_data packet payload data
240* @arg payload_len payload length
241* @return 0 on OK or error code
242*/
243int nfnl_queue_msg_send_verdict_payload(struct nl_sock *nlh,
244 const struct nfnl_queue_msg *msg,
245 const void *payload_data, unsigned payload_len)
246{
247 struct nl_msg *nlmsg;
248 int err;
249 struct iovec iov[3];
250 struct nlattr nla;
251
252 nlmsg = nfnl_queue_msg_build_verdict(msg);
253 if (nlmsg == NULL)
254 return -NLE_NOMEM;
255
256 memset(iov, 0, sizeof(iov));
257
258 iov[0].iov_base = (void *) nlmsg_hdr(nlmsg);
259 iov[0].iov_len = nlmsg_hdr(nlmsg)->nlmsg_len;
260
261 nla.nla_type = NFQA_PAYLOAD;
262 nla.nla_len = payload_len + sizeof(nla);
263 nlmsg_hdr(nlmsg)->nlmsg_len += nla.nla_len;
264
265 iov[1].iov_base = (void *) &nla;
266 iov[1].iov_len = sizeof(nla);
267
268 iov[2].iov_base = (void *) payload_data;
269 iov[2].iov_len = NLA_ALIGN(payload_len);
270
271 nl_complete_msg(nlh, nlmsg);
272 err = nl_send_iovec(nlh, nlmsg, iov, 3);
273
274 nlmsg_free(nlmsg);
275 if (err < 0)
276 return err;
277 return wait_for_ack(nlh);
278}
279
280#define NFNLMSG_QUEUE_TYPE(type) NFNLMSG_TYPE(NFNL_SUBSYS_QUEUE, (type))
281static struct nl_cache_ops nfnl_queue_msg_ops = {
282 .co_name = "netfilter/queue_msg",
283 .co_hdrsize = NFNL_HDRLEN,
284 .co_msgtypes = {
285 { NFNLMSG_QUEUE_TYPE(NFQNL_MSG_PACKET), NL_ACT_NEW, "new" },
286 END_OF_MSGTYPES_LIST,
287 },
288 .co_protocol = NETLINK_NETFILTER,
289 .co_msg_parser = queue_msg_parser,
290 .co_obj_ops = &queue_msg_obj_ops,
291};
292
293static void __init nfnl_msg_queue_init(void)
294{
295 nl_cache_mngt_register(&nfnl_queue_msg_ops);
296}
297
298static void __exit nfnl_queue_msg_exit(void)
299{
300 nl_cache_mngt_unregister(&nfnl_queue_msg_ops);
301}
302
303/** @} */
uint32_t nla_get_u32(const struct nlattr *nla)
Return payload of 32 bit integer attribute.
Definition: attr.c:702
void * nla_data(const struct nlattr *nla)
Return pointer to the payload section.
Definition: attr.c:114
int nla_put_u32(struct nl_msg *msg, int attrtype, uint32_t value)
Add 32 bit integer attribute to netlink message.
Definition: attr.c:691
int nla_len(const struct nlattr *nla)
Return length of the payload .
Definition: attr.c:125
int nla_put(struct nl_msg *msg, int attrtype, int datalen, const void *data)
Add a unspecific attribute to netlink message.
Definition: attr.c:493
@ NLA_U32
32 bit integer
Definition: attr.h:37
int nl_cache_mngt_unregister(struct nl_cache_ops *ops)
Unregister a set of cache operations.
Definition: cache_mngt.c:281
int nl_cache_mngt_register(struct nl_cache_ops *ops)
Register a set of cache operations.
Definition: cache_mngt.c:246
struct nlmsghdr * nlmsg_hdr(struct nl_msg *n)
Return actual netlink message.
Definition: msg.c:536
void nlmsg_free(struct nl_msg *msg)
Release a reference from an netlink message.
Definition: msg.c:558
int nlmsg_parse(struct nlmsghdr *nlh, int hdrlen, struct nlattr *tb[], int maxtype, const struct nla_policy *policy)
parse attributes of a netlink message
Definition: msg.c:208
uint16_t nfnlmsg_res_id(struct nlmsghdr *nlh)
Get netfilter resource id from message.
Definition: nfnl.c:157
uint8_t nfnlmsg_family(struct nlmsghdr *nlh)
Get netfilter family from message.
Definition: nfnl.c:146
struct nl_msg * nfnlmsg_alloc_simple(uint8_t subsys_id, uint8_t type, int flags, uint8_t family, uint16_t res_id)
Allocate a new netfilter netlink message.
Definition: nfnl.c:197
int nl_send_iovec(struct nl_sock *sk, struct nl_msg *msg, struct iovec *iov, unsigned iovlen)
Transmit Netlink message (taking IO vector)
Definition: nl.c:367
void nl_complete_msg(struct nl_sock *sk, struct nl_msg *msg)
Finalize Netlink message.
Definition: nl.c:475
int nl_send_auto_complete(struct nl_sock *sk, struct nl_msg *msg)
Definition: nl.c:1241
Attribute validation policy.
Definition: attr.h:63
uint16_t minlen
Minimal length of payload required.
Definition: attr.h:68