libnl  3.7.0
queue_msg.c
1 /* SPDX-License-Identifier: LGPL-2.1-only */
2 /*
3  * Copyright (c) 2007, 2008 Patrick McHardy <kaber@trash.net>
4  * Copyright (c) 2010 Karl Hiramoto <karl@hiramoto.org>
5  */
6 
7 /**
8  * @ingroup nfnl
9  * @defgroup queue Queue
10  * @brief
11  * @{
12  */
13 
14 #include <sys/types.h>
15 #include <linux/netfilter/nfnetlink_queue.h>
16 
17 #include <netlink-private/netlink.h>
18 #include <netlink/attr.h>
19 #include <netlink/netfilter/nfnl.h>
20 #include <netlink/netfilter/queue_msg.h>
21 #include <netlink-private/utils.h>
22 
23 static struct nl_cache_ops nfnl_queue_msg_ops;
24 
25 static struct nla_policy queue_policy[NFQA_MAX+1] = {
26  [NFQA_PACKET_HDR] = {
27  .minlen = sizeof(struct nfqnl_msg_packet_hdr),
28  },
29  [NFQA_VERDICT_HDR] = {
30  .minlen = sizeof(struct nfqnl_msg_verdict_hdr),
31  },
32  [NFQA_MARK] = { .type = NLA_U32 },
33  [NFQA_TIMESTAMP] = {
34  .minlen = sizeof(struct nfqnl_msg_packet_timestamp),
35  },
36  [NFQA_IFINDEX_INDEV] = { .type = NLA_U32 },
37  [NFQA_IFINDEX_OUTDEV] = { .type = NLA_U32 },
38  [NFQA_IFINDEX_PHYSINDEV] = { .type = NLA_U32 },
39  [NFQA_IFINDEX_PHYSOUTDEV] = { .type = NLA_U32 },
40  [NFQA_HWADDR] = {
41  .minlen = sizeof(struct nfqnl_msg_packet_hw),
42  },
43 };
44 
45 int nfnlmsg_queue_msg_parse(struct nlmsghdr *nlh,
46  struct nfnl_queue_msg **result)
47 {
48  struct nfnl_queue_msg *msg;
49  struct nlattr *tb[NFQA_MAX+1];
50  struct nlattr *attr;
51  int err;
52 
53  msg = nfnl_queue_msg_alloc();
54  if (!msg)
55  return -NLE_NOMEM;
56 
57  msg->ce_msgtype = nlh->nlmsg_type;
58 
59  err = nlmsg_parse(nlh, sizeof(struct nfgenmsg), tb, NFQA_MAX,
60  queue_policy);
61  if (err < 0)
62  goto errout;
63 
64  nfnl_queue_msg_set_group(msg, nfnlmsg_res_id(nlh));
65  nfnl_queue_msg_set_family(msg, nfnlmsg_family(nlh));
66 
67  attr = tb[NFQA_PACKET_HDR];
68  if (attr) {
69  struct nfqnl_msg_packet_hdr *hdr = nla_data(attr);
70 
71  nfnl_queue_msg_set_packetid(msg, ntohl(hdr->packet_id));
72  if (hdr->hw_protocol)
73  nfnl_queue_msg_set_hwproto(msg, hdr->hw_protocol);
74  nfnl_queue_msg_set_hook(msg, hdr->hook);
75  }
76 
77  attr = tb[NFQA_MARK];
78  if (attr)
79  nfnl_queue_msg_set_mark(msg, ntohl(nla_get_u32(attr)));
80 
81  attr = tb[NFQA_TIMESTAMP];
82  if (attr) {
83  struct nfqnl_msg_packet_timestamp *timestamp = nla_data(attr);
84  struct timeval tv;
85 
86  tv.tv_sec = ntohll(timestamp->sec);
87  tv.tv_usec = ntohll(timestamp->usec);
88  nfnl_queue_msg_set_timestamp(msg, &tv);
89  }
90 
91  attr = tb[NFQA_IFINDEX_INDEV];
92  if (attr)
93  nfnl_queue_msg_set_indev(msg, ntohl(nla_get_u32(attr)));
94 
95  attr = tb[NFQA_IFINDEX_OUTDEV];
96  if (attr)
97  nfnl_queue_msg_set_outdev(msg, ntohl(nla_get_u32(attr)));
98 
99  attr = tb[NFQA_IFINDEX_PHYSINDEV];
100  if (attr)
101  nfnl_queue_msg_set_physindev(msg, ntohl(nla_get_u32(attr)));
102 
103  attr = tb[NFQA_IFINDEX_PHYSOUTDEV];
104  if (attr)
105  nfnl_queue_msg_set_physoutdev(msg, ntohl(nla_get_u32(attr)));
106 
107  attr = tb[NFQA_HWADDR];
108  if (attr) {
109  struct nfqnl_msg_packet_hw *hw = nla_data(attr);
110 
111  nfnl_queue_msg_set_hwaddr(msg, hw->hw_addr,
112  ntohs(hw->hw_addrlen));
113  }
114 
115  attr = tb[NFQA_PAYLOAD];
116  if (attr) {
117  err = nfnl_queue_msg_set_payload(msg, nla_data(attr),
118  nla_len(attr));
119  if (err < 0)
120  goto errout;
121  }
122 
123  *result = msg;
124  return 0;
125 
126 errout:
127  nfnl_queue_msg_put(msg);
128  return err;
129 }
130 
131 static int queue_msg_parser(struct nl_cache_ops *ops, struct sockaddr_nl *who,
132  struct nlmsghdr *nlh, struct nl_parser_param *pp)
133 {
134  struct nfnl_queue_msg *msg;
135  int err;
136 
137  if ((err = nfnlmsg_queue_msg_parse(nlh, &msg)) < 0)
138  return err;
139 
140  err = pp->pp_cb((struct nl_object *) msg, pp);
141  nfnl_queue_msg_put(msg);
142  return err;
143 }
144 
145 /** @} */
146 
147 static struct nl_msg *
148 __nfnl_queue_msg_build_verdict(const struct nfnl_queue_msg *msg,
149  uint8_t type)
150 {
151  struct nl_msg *nlmsg;
152  struct nfqnl_msg_verdict_hdr verdict;
153 
154  nlmsg = nfnlmsg_alloc_simple(NFNL_SUBSYS_QUEUE, type, 0,
155  nfnl_queue_msg_get_family(msg),
156  nfnl_queue_msg_get_group(msg));
157  if (nlmsg == NULL)
158  return NULL;
159 
160  verdict.id = htonl(nfnl_queue_msg_get_packetid(msg));
161  verdict.verdict = htonl(nfnl_queue_msg_get_verdict(msg));
162  if (nla_put(nlmsg, NFQA_VERDICT_HDR, sizeof(verdict), &verdict) < 0)
163  goto nla_put_failure;
164 
165  if (nfnl_queue_msg_test_mark(msg) &&
166  nla_put_u32(nlmsg, NFQA_MARK,
167  ntohl(nfnl_queue_msg_get_mark(msg))) < 0)
168  goto nla_put_failure;
169 
170  return nlmsg;
171 
172 nla_put_failure:
173  nlmsg_free(nlmsg);
174  return NULL;
175 }
176 
177 struct nl_msg *
178 nfnl_queue_msg_build_verdict(const struct nfnl_queue_msg *msg)
179 {
180  return __nfnl_queue_msg_build_verdict(msg, NFQNL_MSG_VERDICT);
181 }
182 
183 struct nl_msg *
184 nfnl_queue_msg_build_verdict_batch(const struct nfnl_queue_msg *msg)
185 {
186  return __nfnl_queue_msg_build_verdict(msg, NFQNL_MSG_VERDICT_BATCH);
187 }
188 
189 /**
190 * Send a message verdict/mark
191 * @arg nlh netlink messsage header
192 * @arg msg queue msg
193 * @return 0 on OK or error code
194 */
195 int nfnl_queue_msg_send_verdict(struct nl_sock *nlh,
196  const struct nfnl_queue_msg *msg)
197 {
198  struct nl_msg *nlmsg;
199  int err;
200 
201  nlmsg = nfnl_queue_msg_build_verdict(msg);
202  if (nlmsg == NULL)
203  return -NLE_NOMEM;
204 
205  err = nl_send_auto_complete(nlh, nlmsg);
206  nlmsg_free(nlmsg);
207  if (err < 0)
208  return err;
209  return wait_for_ack(nlh);
210 }
211 
212 /**
213 * Send a message batched verdict/mark
214 * @arg nlh netlink messsage header
215 * @arg msg queue msg
216 * @return 0 on OK or error code
217 */
218 int nfnl_queue_msg_send_verdict_batch(struct nl_sock *nlh,
219  const struct nfnl_queue_msg *msg)
220 {
221  struct nl_msg *nlmsg;
222  int err;
223 
224  nlmsg = nfnl_queue_msg_build_verdict_batch(msg);
225  if (nlmsg == NULL)
226  return -NLE_NOMEM;
227 
228  err = nl_send_auto_complete(nlh, nlmsg);
229  nlmsg_free(nlmsg);
230  if (err < 0)
231  return err;
232  return wait_for_ack(nlh);
233 }
234 
235 /**
236 * Send a message verdict including the payload
237 * @arg nlh netlink messsage header
238 * @arg msg queue msg
239 * @arg payload_data packet payload data
240 * @arg payload_len payload length
241 * @return 0 on OK or error code
242 */
243 int nfnl_queue_msg_send_verdict_payload(struct nl_sock *nlh,
244  const struct nfnl_queue_msg *msg,
245  const void *payload_data, unsigned payload_len)
246 {
247  struct nl_msg *nlmsg;
248  int err;
249  struct iovec iov[3];
250  struct nlattr nla;
251 
252  nlmsg = nfnl_queue_msg_build_verdict(msg);
253  if (nlmsg == NULL)
254  return -NLE_NOMEM;
255 
256  memset(iov, 0, sizeof(iov));
257 
258  iov[0].iov_base = (void *) nlmsg_hdr(nlmsg);
259  iov[0].iov_len = nlmsg_hdr(nlmsg)->nlmsg_len;
260 
261  nla.nla_type = NFQA_PAYLOAD;
262  nla.nla_len = payload_len + sizeof(nla);
263  nlmsg_hdr(nlmsg)->nlmsg_len += nla.nla_len;
264 
265  iov[1].iov_base = (void *) &nla;
266  iov[1].iov_len = sizeof(nla);
267 
268  iov[2].iov_base = (void *) payload_data;
269  iov[2].iov_len = NLA_ALIGN(payload_len);
270 
271  nl_complete_msg(nlh, nlmsg);
272  err = nl_send_iovec(nlh, nlmsg, iov, 3);
273 
274  nlmsg_free(nlmsg);
275  if (err < 0)
276  return err;
277  return wait_for_ack(nlh);
278 }
279 
280 #define NFNLMSG_QUEUE_TYPE(type) NFNLMSG_TYPE(NFNL_SUBSYS_QUEUE, (type))
281 static struct nl_cache_ops nfnl_queue_msg_ops = {
282  .co_name = "netfilter/queue_msg",
283  .co_hdrsize = NFNL_HDRLEN,
284  .co_msgtypes = {
285  { NFNLMSG_QUEUE_TYPE(NFQNL_MSG_PACKET), NL_ACT_NEW, "new" },
286  END_OF_MSGTYPES_LIST,
287  },
288  .co_protocol = NETLINK_NETFILTER,
289  .co_msg_parser = queue_msg_parser,
290  .co_obj_ops = &queue_msg_obj_ops,
291 };
292 
293 static void __init nfnl_msg_queue_init(void)
294 {
295  nl_cache_mngt_register(&nfnl_queue_msg_ops);
296 }
297 
298 static void __exit nfnl_queue_msg_exit(void)
299 {
300  nl_cache_mngt_unregister(&nfnl_queue_msg_ops);
301 }
302 
303 /** @} */
uint32_t nla_get_u32(const struct nlattr *nla)
Return payload of 32 bit integer attribute.
Definition: attr.c:699
int nla_put_u32(struct nl_msg *msg, int attrtype, uint32_t value)
Add 32 bit integer attribute to netlink message.
Definition: attr.c:688
int nla_len(const struct nlattr *nla)
Return length of the payload .
Definition: attr.c:125
int nla_put(struct nl_msg *msg, int attrtype, int datalen, const void *data)
Add a unspecific attribute to netlink message.
Definition: attr.c:493
void * nla_data(const struct nlattr *nla)
Return pointer to the payload section.
Definition: attr.c:114
@ NLA_U32
32 bit integer
Definition: attr.h:37
int nl_cache_mngt_unregister(struct nl_cache_ops *ops)
Unregister a set of cache operations.
Definition: cache_mngt.c:281
int nl_cache_mngt_register(struct nl_cache_ops *ops)
Register a set of cache operations.
Definition: cache_mngt.c:246
void nlmsg_free(struct nl_msg *msg)
Release a reference from an netlink message.
Definition: msg.c:558
int nlmsg_parse(struct nlmsghdr *nlh, int hdrlen, struct nlattr *tb[], int maxtype, const struct nla_policy *policy)
parse attributes of a netlink message
Definition: msg.c:208
struct nlmsghdr * nlmsg_hdr(struct nl_msg *n)
Return actual netlink message.
Definition: msg.c:536
uint16_t nfnlmsg_res_id(struct nlmsghdr *nlh)
Get netfilter resource id from message.
Definition: nfnl.c:157
uint8_t nfnlmsg_family(struct nlmsghdr *nlh)
Get netfilter family from message.
Definition: nfnl.c:146
struct nl_msg * nfnlmsg_alloc_simple(uint8_t subsys_id, uint8_t type, int flags, uint8_t family, uint16_t res_id)
Allocate a new netfilter netlink message.
Definition: nfnl.c:197
int nl_send_iovec(struct nl_sock *sk, struct nl_msg *msg, struct iovec *iov, unsigned iovlen)
Transmit Netlink message (taking IO vector)
Definition: nl.c:367
void nl_complete_msg(struct nl_sock *sk, struct nl_msg *msg)
Finalize Netlink message.
Definition: nl.c:475
int nl_send_auto_complete(struct nl_sock *sk, struct nl_msg *msg)
Definition: nl.c:1241
Attribute validation policy.
Definition: attr.h:63
uint16_t minlen
Minimal length of payload required.
Definition: attr.h:68