nft_dynset.c 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268
  1. /*
  2. * Copyright (c) 2015 Patrick McHardy <kaber@trash.net>
  3. *
  4. * This program is free software; you can redistribute it and/or modify
  5. * it under the terms of the GNU General Public License version 2 as
  6. * published by the Free Software Foundation.
  7. *
  8. */
  9. #include <linux/kernel.h>
  10. #include <linux/module.h>
  11. #include <linux/init.h>
  12. #include <linux/netlink.h>
  13. #include <linux/netfilter.h>
  14. #include <linux/netfilter/nf_tables.h>
  15. #include <net/netfilter/nf_tables.h>
  16. #include <net/netfilter/nf_tables_core.h>
  17. struct nft_dynset {
  18. struct nft_set *set;
  19. struct nft_set_ext_tmpl tmpl;
  20. enum nft_dynset_ops op:8;
  21. enum nft_registers sreg_key:8;
  22. enum nft_registers sreg_data:8;
  23. u64 timeout;
  24. struct nft_expr *expr;
  25. struct nft_set_binding binding;
  26. };
  27. static void *nft_dynset_new(struct nft_set *set, const struct nft_expr *expr,
  28. struct nft_regs *regs)
  29. {
  30. const struct nft_dynset *priv = nft_expr_priv(expr);
  31. struct nft_set_ext *ext;
  32. u64 timeout;
  33. void *elem;
  34. if (set->size && !atomic_add_unless(&set->nelems, 1, set->size))
  35. return NULL;
  36. timeout = priv->timeout ? : set->timeout;
  37. elem = nft_set_elem_init(set, &priv->tmpl,
  38. &regs->data[priv->sreg_key],
  39. &regs->data[priv->sreg_data],
  40. timeout, GFP_ATOMIC);
  41. if (elem == NULL) {
  42. if (set->size)
  43. atomic_dec(&set->nelems);
  44. return NULL;
  45. }
  46. ext = nft_set_elem_ext(set, elem);
  47. if (priv->expr != NULL &&
  48. nft_expr_clone(nft_set_ext_expr(ext), priv->expr) < 0)
  49. return NULL;
  50. return elem;
  51. }
  52. static void nft_dynset_eval(const struct nft_expr *expr,
  53. struct nft_regs *regs,
  54. const struct nft_pktinfo *pkt)
  55. {
  56. const struct nft_dynset *priv = nft_expr_priv(expr);
  57. struct nft_set *set = priv->set;
  58. const struct nft_set_ext *ext;
  59. const struct nft_expr *sexpr;
  60. u64 timeout;
  61. if (set->ops->update(set, &regs->data[priv->sreg_key], nft_dynset_new,
  62. expr, regs, &ext)) {
  63. sexpr = NULL;
  64. if (nft_set_ext_exists(ext, NFT_SET_EXT_EXPR))
  65. sexpr = nft_set_ext_expr(ext);
  66. if (priv->op == NFT_DYNSET_OP_UPDATE &&
  67. nft_set_ext_exists(ext, NFT_SET_EXT_EXPIRATION)) {
  68. timeout = priv->timeout ? : set->timeout;
  69. *nft_set_ext_expiration(ext) = jiffies + timeout;
  70. } else if (sexpr == NULL)
  71. goto out;
  72. if (sexpr != NULL)
  73. sexpr->ops->eval(sexpr, regs, pkt);
  74. return;
  75. }
  76. out:
  77. regs->verdict.code = NFT_BREAK;
  78. }
  79. static const struct nla_policy nft_dynset_policy[NFTA_DYNSET_MAX + 1] = {
  80. [NFTA_DYNSET_SET_NAME] = { .type = NLA_STRING },
  81. [NFTA_DYNSET_SET_ID] = { .type = NLA_U32 },
  82. [NFTA_DYNSET_OP] = { .type = NLA_U32 },
  83. [NFTA_DYNSET_SREG_KEY] = { .type = NLA_U32 },
  84. [NFTA_DYNSET_SREG_DATA] = { .type = NLA_U32 },
  85. [NFTA_DYNSET_TIMEOUT] = { .type = NLA_U64 },
  86. [NFTA_DYNSET_EXPR] = { .type = NLA_NESTED },
  87. };
  88. static int nft_dynset_init(const struct nft_ctx *ctx,
  89. const struct nft_expr *expr,
  90. const struct nlattr * const tb[])
  91. {
  92. struct nft_dynset *priv = nft_expr_priv(expr);
  93. struct nft_set *set;
  94. u64 timeout;
  95. int err;
  96. if (tb[NFTA_DYNSET_SET_NAME] == NULL ||
  97. tb[NFTA_DYNSET_OP] == NULL ||
  98. tb[NFTA_DYNSET_SREG_KEY] == NULL)
  99. return -EINVAL;
  100. set = nf_tables_set_lookup(ctx->table, tb[NFTA_DYNSET_SET_NAME]);
  101. if (IS_ERR(set)) {
  102. if (tb[NFTA_DYNSET_SET_ID])
  103. set = nf_tables_set_lookup_byid(ctx->net,
  104. tb[NFTA_DYNSET_SET_ID]);
  105. if (IS_ERR(set))
  106. return PTR_ERR(set);
  107. }
  108. if (set->flags & NFT_SET_CONSTANT)
  109. return -EBUSY;
  110. priv->op = ntohl(nla_get_be32(tb[NFTA_DYNSET_OP]));
  111. switch (priv->op) {
  112. case NFT_DYNSET_OP_ADD:
  113. break;
  114. case NFT_DYNSET_OP_UPDATE:
  115. if (!(set->flags & NFT_SET_TIMEOUT))
  116. return -EOPNOTSUPP;
  117. break;
  118. default:
  119. return -EOPNOTSUPP;
  120. }
  121. timeout = 0;
  122. if (tb[NFTA_DYNSET_TIMEOUT] != NULL) {
  123. if (!(set->flags & NFT_SET_TIMEOUT))
  124. return -EINVAL;
  125. timeout = msecs_to_jiffies(be64_to_cpu(nla_get_be64(
  126. tb[NFTA_DYNSET_TIMEOUT])));
  127. }
  128. priv->sreg_key = nft_parse_register(tb[NFTA_DYNSET_SREG_KEY]);
  129. err = nft_validate_register_load(priv->sreg_key, set->klen);;
  130. if (err < 0)
  131. return err;
  132. if (tb[NFTA_DYNSET_SREG_DATA] != NULL) {
  133. if (!(set->flags & NFT_SET_MAP))
  134. return -EINVAL;
  135. if (set->dtype == NFT_DATA_VERDICT)
  136. return -EOPNOTSUPP;
  137. priv->sreg_data = nft_parse_register(tb[NFTA_DYNSET_SREG_DATA]);
  138. err = nft_validate_register_load(priv->sreg_data, set->dlen);
  139. if (err < 0)
  140. return err;
  141. } else if (set->flags & NFT_SET_MAP)
  142. return -EINVAL;
  143. if (tb[NFTA_DYNSET_EXPR] != NULL) {
  144. if (!(set->flags & NFT_SET_EVAL))
  145. return -EINVAL;
  146. if (!(set->flags & NFT_SET_ANONYMOUS))
  147. return -EOPNOTSUPP;
  148. priv->expr = nft_expr_init(ctx, tb[NFTA_DYNSET_EXPR]);
  149. if (IS_ERR(priv->expr))
  150. return PTR_ERR(priv->expr);
  151. err = -EOPNOTSUPP;
  152. if (!(priv->expr->ops->type->flags & NFT_EXPR_STATEFUL))
  153. goto err1;
  154. } else if (set->flags & NFT_SET_EVAL)
  155. return -EINVAL;
  156. nft_set_ext_prepare(&priv->tmpl);
  157. nft_set_ext_add_length(&priv->tmpl, NFT_SET_EXT_KEY, set->klen);
  158. if (set->flags & NFT_SET_MAP)
  159. nft_set_ext_add_length(&priv->tmpl, NFT_SET_EXT_DATA, set->dlen);
  160. if (priv->expr != NULL)
  161. nft_set_ext_add_length(&priv->tmpl, NFT_SET_EXT_EXPR,
  162. priv->expr->ops->size);
  163. if (set->flags & NFT_SET_TIMEOUT) {
  164. if (timeout || set->timeout)
  165. nft_set_ext_add(&priv->tmpl, NFT_SET_EXT_EXPIRATION);
  166. }
  167. priv->timeout = timeout;
  168. err = nf_tables_bind_set(ctx, set, &priv->binding);
  169. if (err < 0)
  170. goto err1;
  171. priv->set = set;
  172. return 0;
  173. err1:
  174. if (priv->expr != NULL)
  175. nft_expr_destroy(ctx, priv->expr);
  176. return err;
  177. }
  178. static void nft_dynset_destroy(const struct nft_ctx *ctx,
  179. const struct nft_expr *expr)
  180. {
  181. struct nft_dynset *priv = nft_expr_priv(expr);
  182. nf_tables_unbind_set(ctx, priv->set, &priv->binding);
  183. if (priv->expr != NULL)
  184. nft_expr_destroy(ctx, priv->expr);
  185. }
  186. static int nft_dynset_dump(struct sk_buff *skb, const struct nft_expr *expr)
  187. {
  188. const struct nft_dynset *priv = nft_expr_priv(expr);
  189. if (nft_dump_register(skb, NFTA_DYNSET_SREG_KEY, priv->sreg_key))
  190. goto nla_put_failure;
  191. if (priv->set->flags & NFT_SET_MAP &&
  192. nft_dump_register(skb, NFTA_DYNSET_SREG_DATA, priv->sreg_data))
  193. goto nla_put_failure;
  194. if (nla_put_be32(skb, NFTA_DYNSET_OP, htonl(priv->op)))
  195. goto nla_put_failure;
  196. if (nla_put_string(skb, NFTA_DYNSET_SET_NAME, priv->set->name))
  197. goto nla_put_failure;
  198. if (nla_put_be64(skb, NFTA_DYNSET_TIMEOUT,
  199. cpu_to_be64(jiffies_to_msecs(priv->timeout))))
  200. goto nla_put_failure;
  201. if (priv->expr && nft_expr_dump(skb, NFTA_DYNSET_EXPR, priv->expr))
  202. goto nla_put_failure;
  203. return 0;
  204. nla_put_failure:
  205. return -1;
  206. }
  207. static struct nft_expr_type nft_dynset_type;
  208. static const struct nft_expr_ops nft_dynset_ops = {
  209. .type = &nft_dynset_type,
  210. .size = NFT_EXPR_SIZE(sizeof(struct nft_dynset)),
  211. .eval = nft_dynset_eval,
  212. .init = nft_dynset_init,
  213. .destroy = nft_dynset_destroy,
  214. .dump = nft_dynset_dump,
  215. };
  216. static struct nft_expr_type nft_dynset_type __read_mostly = {
  217. .name = "dynset",
  218. .ops = &nft_dynset_ops,
  219. .policy = nft_dynset_policy,
  220. .maxattr = NFTA_DYNSET_MAX,
  221. .owner = THIS_MODULE,
  222. };
  223. int __init nft_dynset_module_init(void)
  224. {
  225. return nft_register_expr(&nft_dynset_type);
  226. }
  227. void nft_dynset_module_exit(void)
  228. {
  229. nft_unregister_expr(&nft_dynset_type);
  230. }