blob: e104760f7a67702be2636d07c90a0b5170166d32 [file] [log] [blame]
Harald Weltef6ebe772005-08-09 20:21:49 -07001#include <linux/config.h>
2#include <linux/kernel.h>
3#include <linux/init.h>
4#include <linux/module.h>
5#include <linux/proc_fs.h>
6#include <linux/skbuff.h>
7#include <linux/netfilter.h>
Harald Weltebbd86b9f2005-08-09 20:23:11 -07008#include <linux/seq_file.h>
Harald Weltef6ebe772005-08-09 20:21:49 -07009#include <net/protocol.h>
10
11#include "nf_internals.h"
12
13/* Internal logging interface, which relies on the real
14 LOG target modules */
15
16#define NF_LOG_PREFIXLEN 128
17
18static struct nf_logger *nf_logging[NPROTO]; /* = NULL */
19static DEFINE_SPINLOCK(nf_log_lock);
20
Harald Welted72367b2005-08-09 20:23:36 -070021/* return EBUSY if somebody else is registered, EEXIST if the same logger
22 * is registred, 0 on success. */
Harald Weltef6ebe772005-08-09 20:21:49 -070023int nf_log_register(int pf, struct nf_logger *logger)
24{
25 int ret = -EBUSY;
26
27 /* Any setup of logging members must be done before
28 * substituting pointer. */
29 spin_lock(&nf_log_lock);
30 if (!nf_logging[pf]) {
31 rcu_assign_pointer(nf_logging[pf], logger);
32 ret = 0;
Harald Welted72367b2005-08-09 20:23:36 -070033 } else if (nf_logging[pf] == logger)
34 ret = -EEXIST;
35
Harald Weltef6ebe772005-08-09 20:21:49 -070036 spin_unlock(&nf_log_lock);
37 return ret;
38}
39EXPORT_SYMBOL(nf_log_register);
40
41void nf_log_unregister_pf(int pf)
42{
43 spin_lock(&nf_log_lock);
44 nf_logging[pf] = NULL;
45 spin_unlock(&nf_log_lock);
46
47 /* Give time to concurrent readers. */
48 synchronize_net();
49}
50EXPORT_SYMBOL(nf_log_unregister_pf);
51
52void nf_log_unregister_logger(struct nf_logger *logger)
53{
54 int i;
55
56 spin_lock(&nf_log_lock);
57 for (i = 0; i < NPROTO; i++) {
58 if (nf_logging[i] == logger)
59 nf_logging[i] = NULL;
60 }
61 spin_unlock(&nf_log_lock);
62
63 synchronize_net();
64}
65EXPORT_SYMBOL(nf_log_unregister_logger);
66
67void nf_log_packet(int pf,
68 unsigned int hooknum,
69 const struct sk_buff *skb,
70 const struct net_device *in,
71 const struct net_device *out,
72 struct nf_loginfo *loginfo,
73 const char *fmt, ...)
74{
75 va_list args;
76 char prefix[NF_LOG_PREFIXLEN];
77 struct nf_logger *logger;
78
79 rcu_read_lock();
80 logger = rcu_dereference(nf_logging[pf]);
81 if (logger) {
82 va_start(args, fmt);
83 vsnprintf(prefix, sizeof(prefix), fmt, args);
84 va_end(args);
85 /* We must read logging before nf_logfn[pf] */
86 logger->logfn(pf, hooknum, skb, in, out, loginfo, prefix);
87 } else if (net_ratelimit()) {
88 printk(KERN_WARNING "nf_log_packet: can\'t log since "
89 "no backend logging module loaded in! Please either "
90 "load one, or disable logging explicitly\n");
91 }
92 rcu_read_unlock();
93}
94EXPORT_SYMBOL(nf_log_packet);
95
96#ifdef CONFIG_PROC_FS
97static void *seq_start(struct seq_file *seq, loff_t *pos)
98{
99 rcu_read_lock();
100
101 if (*pos >= NPROTO)
102 return NULL;
103
104 return pos;
105}
106
107static void *seq_next(struct seq_file *s, void *v, loff_t *pos)
108{
109 (*pos)++;
110
111 if (*pos >= NPROTO)
112 return NULL;
113
114 return pos;
115}
116
117static void seq_stop(struct seq_file *s, void *v)
118{
119 rcu_read_unlock();
120}
121
122static int seq_show(struct seq_file *s, void *v)
123{
124 loff_t *pos = v;
125 const struct nf_logger *logger;
126
127 logger = rcu_dereference(nf_logging[*pos]);
128
129 if (!logger)
130 return seq_printf(s, "%2lld NONE\n", *pos);
131
132 return seq_printf(s, "%2lld %s\n", *pos, logger->name);
133}
134
135static struct seq_operations nflog_seq_ops = {
136 .start = seq_start,
137 .next = seq_next,
138 .stop = seq_stop,
139 .show = seq_show,
140};
141
142static int nflog_open(struct inode *inode, struct file *file)
143{
144 return seq_open(file, &nflog_seq_ops);
145}
146
147static struct file_operations nflog_file_ops = {
148 .owner = THIS_MODULE,
149 .open = nflog_open,
150 .read = seq_read,
151 .llseek = seq_lseek,
152 .release = seq_release,
153};
154
155#endif /* PROC_FS */
156
157
158int __init netfilter_log_init(void)
159{
160#ifdef CONFIG_PROC_FS
161 struct proc_dir_entry *pde;
162 pde = create_proc_entry("nf_log", S_IRUGO, proc_net_netfilter);
163#endif
164 if (!pde)
165 return -1;
166
167 pde->proc_fops = &nflog_file_ops;
168
169 return 0;
170}