Jan Engelhardt | 32b8e61 | 2010-07-23 21:16:14 +0200 | [diff] [blame] | 1 | #include <stdbool.h> |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 2 | #include <stdio.h> |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 3 | #include <string.h> |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 4 | #include <xtables.h> |
| 5 | #include <linux/netfilter/xt_recent.h> |
Harald Welte | 122e7c0 | 2003-03-30 20:26:42 +0000 | [diff] [blame] | 6 | |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 7 | enum { |
| 8 | O_SET = 0, |
| 9 | O_RCHECK, |
| 10 | O_UPDATE, |
| 11 | O_REMOVE, |
| 12 | O_SECONDS, |
Tim Gardner | 79ddbf2 | 2011-11-30 08:16:53 -0700 | [diff] [blame] | 13 | O_REAP, |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 14 | O_HITCOUNT, |
| 15 | O_RTTL, |
| 16 | O_NAME, |
| 17 | O_RSOURCE, |
| 18 | O_RDEST, |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 19 | O_MASK, |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 20 | F_SET = 1 << O_SET, |
| 21 | F_RCHECK = 1 << O_RCHECK, |
| 22 | F_UPDATE = 1 << O_UPDATE, |
| 23 | F_REMOVE = 1 << O_REMOVE, |
Tim Gardner | 79ddbf2 | 2011-11-30 08:16:53 -0700 | [diff] [blame] | 24 | F_SECONDS = 1 << O_SECONDS, |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 25 | F_ANY_OP = F_SET | F_RCHECK | F_UPDATE | F_REMOVE, |
Stephen Frost | 27e1fa8 | 2003-04-14 13:33:15 +0000 | [diff] [blame] | 26 | }; |
| 27 | |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 28 | #define s struct xt_recent_mtinfo |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 29 | static const struct xt_option_entry recent_opts_v0[] = { |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 30 | {.name = "set", .id = O_SET, .type = XTTYPE_NONE, |
| 31 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 32 | {.name = "rcheck", .id = O_RCHECK, .type = XTTYPE_NONE, |
| 33 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 34 | {.name = "update", .id = O_UPDATE, .type = XTTYPE_NONE, |
| 35 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 36 | {.name = "remove", .id = O_REMOVE, .type = XTTYPE_NONE, |
| 37 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 38 | {.name = "seconds", .id = O_SECONDS, .type = XTTYPE_UINT32, |
Tim Gardner | 79ddbf2 | 2011-11-30 08:16:53 -0700 | [diff] [blame] | 39 | .flags = XTOPT_PUT, XTOPT_POINTER(s, seconds), .min = 1}, |
| 40 | {.name = "reap", .id = O_REAP, .type = XTTYPE_NONE, |
| 41 | .also = F_SECONDS }, |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 42 | {.name = "hitcount", .id = O_HITCOUNT, .type = XTTYPE_UINT32, |
| 43 | .flags = XTOPT_PUT, XTOPT_POINTER(s, hit_count)}, |
| 44 | {.name = "rttl", .id = O_RTTL, .type = XTTYPE_NONE, |
| 45 | .excl = F_SET | F_REMOVE}, |
| 46 | {.name = "name", .id = O_NAME, .type = XTTYPE_STRING, |
| 47 | .flags = XTOPT_PUT, XTOPT_POINTER(s, name)}, |
| 48 | {.name = "rsource", .id = O_RSOURCE, .type = XTTYPE_NONE}, |
| 49 | {.name = "rdest", .id = O_RDEST, .type = XTTYPE_NONE}, |
| 50 | XTOPT_TABLEEND, |
| 51 | }; |
| 52 | #undef s |
| 53 | |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 54 | #define s struct xt_recent_mtinfo_v1 |
| 55 | static const struct xt_option_entry recent_opts_v1[] = { |
| 56 | {.name = "set", .id = O_SET, .type = XTTYPE_NONE, |
| 57 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 58 | {.name = "rcheck", .id = O_RCHECK, .type = XTTYPE_NONE, |
| 59 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 60 | {.name = "update", .id = O_UPDATE, .type = XTTYPE_NONE, |
| 61 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 62 | {.name = "remove", .id = O_REMOVE, .type = XTTYPE_NONE, |
| 63 | .excl = F_ANY_OP, .flags = XTOPT_INVERT}, |
| 64 | {.name = "seconds", .id = O_SECONDS, .type = XTTYPE_UINT32, |
Pablo Neira Ayuso | 88b73a2 | 2013-07-15 12:14:55 +0200 | [diff] [blame] | 65 | .flags = XTOPT_PUT, XTOPT_POINTER(s, seconds), .min = 1}, |
Russell Senior | 8cf6fb8 | 2013-07-13 10:08:07 +0000 | [diff] [blame] | 66 | {.name = "reap", .id = O_REAP, .type = XTTYPE_NONE, |
| 67 | .also = F_SECONDS }, |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 68 | {.name = "hitcount", .id = O_HITCOUNT, .type = XTTYPE_UINT32, |
| 69 | .flags = XTOPT_PUT, XTOPT_POINTER(s, hit_count)}, |
| 70 | {.name = "rttl", .id = O_RTTL, .type = XTTYPE_NONE, |
| 71 | .excl = F_SET | F_REMOVE}, |
| 72 | {.name = "name", .id = O_NAME, .type = XTTYPE_STRING, |
| 73 | .flags = XTOPT_PUT, XTOPT_POINTER(s, name)}, |
| 74 | {.name = "rsource", .id = O_RSOURCE, .type = XTTYPE_NONE}, |
| 75 | {.name = "rdest", .id = O_RDEST, .type = XTTYPE_NONE}, |
| 76 | {.name = "mask", .id = O_MASK, .type = XTTYPE_HOST, |
| 77 | .flags = XTOPT_PUT, XTOPT_POINTER(s, mask)}, |
| 78 | XTOPT_TABLEEND, |
| 79 | }; |
| 80 | #undef s |
| 81 | |
Jan Engelhardt | 59d1640 | 2007-10-04 16:28:39 +0000 | [diff] [blame] | 82 | static void recent_help(void) |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 83 | { |
| 84 | printf( |
Jan Engelhardt | 8b7c64d | 2008-04-15 11:48:25 +0200 | [diff] [blame] | 85 | "recent match options:\n" |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 86 | "[!] --set Add source address to list, always matches.\n" |
| 87 | "[!] --rcheck Match if source address in list.\n" |
| 88 | "[!] --update Match if source address in list, also update last-seen time.\n" |
| 89 | "[!] --remove Match if source address in list, also removes that address from list.\n" |
| 90 | " --seconds seconds For check and update commands above.\n" |
| 91 | " Specifies that the match will only occur if source address last seen within\n" |
| 92 | " the last 'seconds' seconds.\n" |
Tim Gardner | 79ddbf2 | 2011-11-30 08:16:53 -0700 | [diff] [blame] | 93 | " --reap Purge entries older then 'seconds'.\n" |
| 94 | " Can only be used in conjunction with the seconds option.\n" |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 95 | " --hitcount hits For check and update commands above.\n" |
| 96 | " Specifies that the match will only occur if source address seen hits times.\n" |
Fabrice MARIE | ae31bb6 | 2002-06-14 07:38:16 +0000 | [diff] [blame] | 97 | " May be used in conjunction with the seconds option.\n" |
Stephen Frost | 4fce44c | 2002-02-04 11:58:22 +0000 | [diff] [blame] | 98 | " --rttl For check and update commands above.\n" |
| 99 | " Specifies that the match will only occur if the source address and the TTL\n" |
| 100 | " match between this packet and the one which was set.\n" |
| 101 | " Useful if you have problems with people spoofing their source address in order\n" |
| 102 | " to DoS you via this module.\n" |
Stephen Frost | 7fdbc95 | 2002-06-21 17:26:33 +0000 | [diff] [blame] | 103 | " --name name Name of the recent list to be used. DEFAULT used if none given.\n" |
Stephen Frost | 27e1fa8 | 2003-04-14 13:33:15 +0000 | [diff] [blame] | 104 | " --rsource Match/Save the source address of each packet in the recent list table (default).\n" |
| 105 | " --rdest Match/Save the destination address of each packet in the recent list table.\n" |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 106 | " --mask netmask Netmask that will be applied to this recent list.\n" |
Laurence J. Lane | 8fa26de | 2013-08-23 16:55:55 -0400 | [diff] [blame] | 107 | "xt_recent by: Stephen Frost <sfrost@snowman.net>.\n"); |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 108 | } |
Jan Engelhardt | ddac6c5 | 2008-09-01 14:22:19 +0200 | [diff] [blame] | 109 | |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 110 | enum { |
| 111 | XT_RECENT_REV_0 = 0, |
| 112 | XT_RECENT_REV_1, |
| 113 | }; |
| 114 | |
| 115 | static void recent_init(struct xt_entry_match *match, unsigned int rev) |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 116 | { |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 117 | struct xt_recent_mtinfo *info = (struct xt_recent_mtinfo *)match->data; |
| 118 | struct xt_recent_mtinfo_v1 *info_v1 = |
| 119 | (struct xt_recent_mtinfo_v1 *)match->data; |
Stephen Frost | 7fdbc95 | 2002-06-21 17:26:33 +0000 | [diff] [blame] | 120 | |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 121 | strncpy(info->name,"DEFAULT", XT_RECENT_NAME_LEN); |
| 122 | /* even though XT_RECENT_NAME_LEN is currently defined as 200, |
Karsten Desler | 073df8f | 2004-01-31 15:33:55 +0000 | [diff] [blame] | 123 | * better be safe, than sorry */ |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 124 | info->name[XT_RECENT_NAME_LEN-1] = '\0'; |
| 125 | info->side = XT_RECENT_SOURCE; |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 126 | if (rev == XT_RECENT_REV_1) |
| 127 | memset(&info_v1->mask, 0xFF, sizeof(info_v1->mask)); |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 128 | } |
| 129 | |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 130 | static void recent_parse(struct xt_option_call *cb) |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 131 | { |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 132 | struct xt_recent_mtinfo *info = cb->data; |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 133 | |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 134 | xtables_option_parse(cb); |
| 135 | switch (cb->entry->id) { |
| 136 | case O_SET: |
| 137 | info->check_set |= XT_RECENT_SET; |
| 138 | if (cb->invert) |
| 139 | info->invert = true; |
| 140 | break; |
| 141 | case O_RCHECK: |
| 142 | info->check_set |= XT_RECENT_CHECK; |
| 143 | if (cb->invert) |
| 144 | info->invert = true; |
| 145 | break; |
| 146 | case O_UPDATE: |
| 147 | info->check_set |= XT_RECENT_UPDATE; |
| 148 | if (cb->invert) |
| 149 | info->invert = true; |
| 150 | break; |
| 151 | case O_REMOVE: |
| 152 | info->check_set |= XT_RECENT_REMOVE; |
| 153 | if (cb->invert) |
| 154 | info->invert = true; |
| 155 | break; |
| 156 | case O_RTTL: |
| 157 | info->check_set |= XT_RECENT_TTL; |
| 158 | break; |
| 159 | case O_RSOURCE: |
| 160 | info->side = XT_RECENT_SOURCE; |
| 161 | break; |
| 162 | case O_RDEST: |
| 163 | info->side = XT_RECENT_DEST; |
| 164 | break; |
Tim Gardner | 79ddbf2 | 2011-11-30 08:16:53 -0700 | [diff] [blame] | 165 | case O_REAP: |
| 166 | info->check_set |= XT_RECENT_REAP; |
| 167 | break; |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 168 | } |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 169 | } |
| 170 | |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 171 | static void recent_check(struct xt_fcheck_call *cb) |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 172 | { |
Jan Engelhardt | 51a746e | 2011-05-04 12:30:15 +0200 | [diff] [blame] | 173 | if (!(cb->xflags & F_ANY_OP)) |
Jan Engelhardt | 1829ed4 | 2009-02-21 03:29:44 +0100 | [diff] [blame] | 174 | xtables_error(PARAMETER_PROBLEM, |
Stephen Frost | d590395 | 2003-03-03 07:24:27 +0000 | [diff] [blame] | 175 | "recent: you must specify one of `--set', `--rcheck' " |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 176 | "`--update' or `--remove'"); |
| 177 | } |
| 178 | |
Jan Engelhardt | 59d1640 | 2007-10-04 16:28:39 +0000 | [diff] [blame] | 179 | static void recent_print(const void *ip, const struct xt_entry_match *match, |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 180 | unsigned int family) |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 181 | { |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 182 | const struct xt_recent_mtinfo_v1 *info = (const void *)match->data; |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 183 | |
Sven Strickroth | 0c1b776 | 2003-06-01 10:11:43 +0000 | [diff] [blame] | 184 | if (info->invert) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 185 | printf(" !"); |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 186 | |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 187 | printf(" recent:"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 188 | if (info->check_set & XT_RECENT_SET) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 189 | printf(" SET"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 190 | if (info->check_set & XT_RECENT_CHECK) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 191 | printf(" CHECK"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 192 | if (info->check_set & XT_RECENT_UPDATE) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 193 | printf(" UPDATE"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 194 | if (info->check_set & XT_RECENT_REMOVE) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 195 | printf(" REMOVE"); |
| 196 | if(info->seconds) printf(" seconds: %d", info->seconds); |
Tim Gardner | 79ddbf2 | 2011-11-30 08:16:53 -0700 | [diff] [blame] | 197 | if (info->check_set & XT_RECENT_REAP) |
| 198 | printf(" reap"); |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 199 | if(info->hit_count) printf(" hit_count: %d", info->hit_count); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 200 | if (info->check_set & XT_RECENT_TTL) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 201 | printf(" TTL-Match"); |
| 202 | if(info->name) printf(" name: %s", info->name); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 203 | if (info->side == XT_RECENT_SOURCE) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 204 | printf(" side: source"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 205 | if (info->side == XT_RECENT_DEST) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 206 | printf(" side: dest"); |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 207 | |
| 208 | switch(family) { |
| 209 | case NFPROTO_IPV4: |
| 210 | printf(" mask: %s", |
| 211 | xtables_ipaddr_to_numeric(&info->mask.in)); |
| 212 | break; |
| 213 | case NFPROTO_IPV6: |
| 214 | printf(" mask: %s", |
| 215 | xtables_ip6addr_to_numeric(&info->mask.in6)); |
| 216 | break; |
| 217 | } |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 218 | } |
| 219 | |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 220 | static void recent_save(const void *ip, const struct xt_entry_match *match, |
| 221 | unsigned int family) |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 222 | { |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 223 | const struct xt_recent_mtinfo_v1 *info = (const void *)match->data; |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 224 | |
Sven Strickroth | 0c1b776 | 2003-06-01 10:11:43 +0000 | [diff] [blame] | 225 | if (info->invert) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 226 | printf(" !"); |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 227 | |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 228 | if (info->check_set & XT_RECENT_SET) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 229 | printf(" --set"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 230 | if (info->check_set & XT_RECENT_CHECK) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 231 | printf(" --rcheck"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 232 | if (info->check_set & XT_RECENT_UPDATE) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 233 | printf(" --update"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 234 | if (info->check_set & XT_RECENT_REMOVE) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 235 | printf(" --remove"); |
| 236 | if(info->seconds) printf(" --seconds %d", info->seconds); |
Tim Gardner | 79ddbf2 | 2011-11-30 08:16:53 -0700 | [diff] [blame] | 237 | if (info->check_set & XT_RECENT_REAP) |
| 238 | printf(" --reap"); |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 239 | if(info->hit_count) printf(" --hitcount %d", info->hit_count); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 240 | if (info->check_set & XT_RECENT_TTL) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 241 | printf(" --rttl"); |
| 242 | if(info->name) printf(" --name %s",info->name); |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 243 | |
| 244 | switch(family) { |
| 245 | case NFPROTO_IPV4: |
| 246 | printf(" --mask %s", |
| 247 | xtables_ipaddr_to_numeric(&info->mask.in)); |
| 248 | break; |
| 249 | case NFPROTO_IPV6: |
| 250 | printf(" --mask %s", |
| 251 | xtables_ip6addr_to_numeric(&info->mask.in6)); |
| 252 | break; |
| 253 | } |
| 254 | |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 255 | if (info->side == XT_RECENT_SOURCE) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 256 | printf(" --rsource"); |
Jan Engelhardt | af1660f | 2008-10-22 18:53:39 +0200 | [diff] [blame] | 257 | if (info->side == XT_RECENT_DEST) |
Jan Engelhardt | 7386635 | 2010-12-18 02:04:59 +0100 | [diff] [blame] | 258 | printf(" --rdest"); |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 259 | } |
| 260 | |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 261 | static void recent_init_v0(struct xt_entry_match *match) |
| 262 | { |
| 263 | recent_init(match, XT_RECENT_REV_0); |
| 264 | } |
| 265 | |
| 266 | static void recent_init_v1(struct xt_entry_match *match) |
| 267 | { |
| 268 | recent_init(match, XT_RECENT_REV_1); |
| 269 | } |
| 270 | |
| 271 | static void recent_save_v0(const void *ip, const struct xt_entry_match *match) |
| 272 | { |
| 273 | recent_save(ip, match, NFPROTO_UNSPEC); |
| 274 | } |
| 275 | |
| 276 | static void recent_save_v4(const void *ip, const struct xt_entry_match *match) |
| 277 | { |
| 278 | recent_save(ip, match, NFPROTO_IPV4); |
| 279 | } |
| 280 | |
| 281 | static void recent_save_v6(const void *ip, const struct xt_entry_match *match) |
| 282 | { |
| 283 | recent_save(ip, match, NFPROTO_IPV6); |
| 284 | } |
| 285 | |
| 286 | static void recent_print_v0(const void *ip, const struct xt_entry_match *match, |
| 287 | int numeric) |
| 288 | { |
| 289 | recent_print(ip, match, NFPROTO_UNSPEC); |
| 290 | } |
| 291 | |
| 292 | static void recent_print_v4(const void *ip, const struct xt_entry_match *match, |
| 293 | int numeric) |
| 294 | { |
| 295 | recent_print(ip, match, NFPROTO_IPV4); |
| 296 | } |
| 297 | |
| 298 | static void recent_print_v6(const void *ip, const struct xt_entry_match *match, |
| 299 | int numeric) |
| 300 | { |
| 301 | recent_print(ip, match, NFPROTO_IPV6); |
| 302 | } |
| 303 | |
| 304 | static struct xtables_match recent_mt_reg[] = { |
| 305 | { |
| 306 | .name = "recent", |
| 307 | .version = XTABLES_VERSION, |
| 308 | .revision = 0, |
| 309 | .family = NFPROTO_UNSPEC, |
| 310 | .size = XT_ALIGN(sizeof(struct xt_recent_mtinfo)), |
| 311 | .userspacesize = XT_ALIGN(sizeof(struct xt_recent_mtinfo)), |
| 312 | .help = recent_help, |
| 313 | .init = recent_init_v0, |
| 314 | .x6_parse = recent_parse, |
| 315 | .x6_fcheck = recent_check, |
| 316 | .print = recent_print_v0, |
| 317 | .save = recent_save_v0, |
| 318 | .x6_options = recent_opts_v0, |
| 319 | }, |
| 320 | { |
| 321 | .name = "recent", |
| 322 | .version = XTABLES_VERSION, |
| 323 | .revision = 1, |
| 324 | .family = NFPROTO_IPV4, |
| 325 | .size = XT_ALIGN(sizeof(struct xt_recent_mtinfo_v1)), |
| 326 | .userspacesize = XT_ALIGN(sizeof(struct xt_recent_mtinfo_v1)), |
| 327 | .help = recent_help, |
| 328 | .init = recent_init_v1, |
| 329 | .x6_parse = recent_parse, |
| 330 | .x6_fcheck = recent_check, |
| 331 | .print = recent_print_v4, |
| 332 | .save = recent_save_v4, |
| 333 | .x6_options = recent_opts_v1, |
| 334 | }, |
| 335 | { |
| 336 | .name = "recent", |
| 337 | .version = XTABLES_VERSION, |
| 338 | .revision = 1, |
| 339 | .family = NFPROTO_IPV6, |
| 340 | .size = XT_ALIGN(sizeof(struct xt_recent_mtinfo_v1)), |
| 341 | .userspacesize = XT_ALIGN(sizeof(struct xt_recent_mtinfo_v1)), |
| 342 | .help = recent_help, |
| 343 | .init = recent_init_v1, |
| 344 | .x6_parse = recent_parse, |
| 345 | .x6_fcheck = recent_check, |
| 346 | .print = recent_print_v6, |
| 347 | .save = recent_save_v6, |
| 348 | .x6_options = recent_opts_v1, |
| 349 | }, |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 350 | }; |
| 351 | |
| 352 | void _init(void) |
| 353 | { |
Denys Fedoryshchenko | 74ded72 | 2012-05-17 10:08:57 +0000 | [diff] [blame] | 354 | xtables_register_matches(recent_mt_reg, ARRAY_SIZE(recent_mt_reg)); |
Stephen Frost | 93c7e5a | 2001-11-08 22:35:03 +0000 | [diff] [blame] | 355 | } |