2
* Shared library add-on to iptables to add tos match support
4
* Copyright © CC Computer Consultants GmbH, 2007
5
* Contact: Jan Engelhardt <jengelh@computergmbh.de>
15
#include <linux/netfilter/xt_dscp.h>
16
#include <linux/netfilter_ipv4/ipt_tos.h>
17
#include "tos_values.c"
23
static const struct option tos_mt_opts[] = {
24
{.name = "tos", .has_arg = true, .val = 't'},
28
static void tos_mt_help(void)
30
const struct tos_symbol_info *symbol;
33
"tos match options:\n"
34
"[!] --tos value[/mask] Match Type of Service/Priority field value\n"
35
"[!] --tos symbol Match TOS field (IPv4 only) by symbol\n"
36
" Accepted symbolic names for value are:\n");
38
for (symbol = tos_symbol_names; symbol->name != NULL; ++symbol)
39
printf(" (0x%02x) %2u %s\n",
40
symbol->value, symbol->value, symbol->name);
45
static int tos_mt_parse_v0(int c, char **argv, int invert, unsigned int *flags,
46
const void *entry, struct xt_entry_match **match)
48
struct ipt_tos_info *info = (void *)(*match)->data;
49
struct tos_value_mask tvm;
53
param_act(P_ONLY_ONCE, "tos", "--tos", *flags & FLAG_TOS);
54
if (!tos_parse_symbolic(optarg, &tvm, 0xFF))
55
param_act(P_BAD_VALUE, "tos", "--tos", optarg);
57
exit_error(PARAMETER_PROBLEM, "tos: Your kernel is "
58
"too old to support anything besides /0xFF "
60
info->tos = tvm.value;
69
static int tos_mt_parse(int c, char **argv, int invert, unsigned int *flags,
70
const void *entry, struct xt_entry_match **match)
72
struct xt_tos_match_info *info = (void *)(*match)->data;
73
struct tos_value_mask tvm = {.mask = 0xFF};
77
param_act(P_ONLY_ONCE, "tos", "--tos", *flags & FLAG_TOS);
78
if (!tos_parse_symbolic(optarg, &tvm, 0x3F))
79
param_act(P_BAD_VALUE, "tos", "--tos", optarg);
80
info->tos_value = tvm.value;
81
info->tos_mask = tvm.mask;
90
static void tos_mt_check(unsigned int flags)
93
exit_error(PARAMETER_PROBLEM,
94
"tos: --tos parameter required");
97
static void tos_mt_print_v0(const void *ip, const struct xt_entry_match *match,
100
const struct ipt_tos_info *info = (const void *)match->data;
102
printf("tos match ");
105
if (numeric || !tos_try_print_symbolic("", info->tos, 0x3F))
106
printf("0x%02x ", info->tos);
109
static void tos_mt_print(const void *ip, const struct xt_entry_match *match,
112
const struct xt_tos_match_info *info = (const void *)match->data;
114
printf("tos match ");
118
!tos_try_print_symbolic("", info->tos_value, info->tos_mask))
119
printf("0x%02x/0x%02x ", info->tos_value, info->tos_mask);
122
static void tos_mt_save_v0(const void *ip, const struct xt_entry_match *match)
124
const struct ipt_tos_info *info = (const void *)match->data;
128
printf("--tos 0x%02x ", info->tos);
131
static void tos_mt_save(const void *ip, const struct xt_entry_match *match)
133
const struct xt_tos_match_info *info = (const void *)match->data;
137
printf("--tos 0x%02x/0x%02x ", info->tos_value, info->tos_mask);
140
static struct xtables_match tos_mt_reg_v0 = {
141
.version = XTABLES_VERSION,
145
.size = XT_ALIGN(sizeof(struct ipt_tos_info)),
146
.userspacesize = XT_ALIGN(sizeof(struct ipt_tos_info)),
148
.parse = tos_mt_parse_v0,
149
.final_check = tos_mt_check,
150
.print = tos_mt_print_v0,
151
.save = tos_mt_save_v0,
152
.extra_opts = tos_mt_opts,
155
static struct xtables_match tos_mt_reg = {
156
.version = XTABLES_VERSION,
160
.size = XT_ALIGN(sizeof(struct xt_tos_match_info)),
161
.userspacesize = XT_ALIGN(sizeof(struct xt_tos_match_info)),
163
.parse = tos_mt_parse,
164
.final_check = tos_mt_check,
165
.print = tos_mt_print,
167
.extra_opts = tos_mt_opts,
170
static struct xtables_match tos_mt6_reg = {
171
.version = XTABLES_VERSION,
175
.size = XT_ALIGN(sizeof(struct xt_tos_match_info)),
176
.userspacesize = XT_ALIGN(sizeof(struct xt_tos_match_info)),
178
.parse = tos_mt_parse,
179
.final_check = tos_mt_check,
180
.print = tos_mt_print,
182
.extra_opts = tos_mt_opts,
187
xtables_register_match(&tos_mt_reg_v0);
188
xtables_register_match(&tos_mt_reg);
189
xtables_register_match(&tos_mt6_reg);