Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 1 | /* Code to save the iptables state, in human readable-form. */ |
Harald Welte | 10a907f | 2002-08-07 09:07:41 +0000 | [diff] [blame] | 2 | /* (C) 1999 by Paul 'Rusty' Russell <rusty@rustcorp.com.au> and |
| 3 | * (C) 2000-2002 by Harald Welte <laforge@gnumonks.org> |
| 4 | * |
| 5 | * This code is distributed under the terms of GNU GPL v2 |
| 6 | * |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 7 | */ |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 8 | #include <getopt.h> |
| 9 | #include <sys/errno.h> |
| 10 | #include <stdio.h> |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 11 | #include <fcntl.h> |
| 12 | #include <stdlib.h> |
| 13 | #include <string.h> |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 14 | #include <time.h> |
Harald Welte | d8ac967 | 2004-04-15 10:10:19 +0000 | [diff] [blame] | 15 | #include <netdb.h> |
Rusty Russell | b1f69be | 2000-08-27 07:42:54 +0000 | [diff] [blame] | 16 | #include "libiptc/libiptc.h" |
| 17 | #include "iptables.h" |
Jan Engelhardt | 33690a1 | 2008-02-11 00:54:00 +0100 | [diff] [blame] | 18 | #include "iptables-multi.h" |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 19 | |
Mike Frysinger | 5a26b5f | 2007-12-19 14:51:17 +0000 | [diff] [blame] | 20 | #ifndef NO_SHARED_LIBS |
| 21 | #include <dlfcn.h> |
| 22 | #endif |
| 23 | |
Jan Engelhardt | dbb7754 | 2008-02-11 00:33:30 +0100 | [diff] [blame] | 24 | static int show_binary = 0, show_counters = 0; |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 25 | |
Gáspár Lajos | 7bc3cb7 | 2008-03-27 08:20:39 +0100 | [diff] [blame] | 26 | static const struct option options[] = { |
| 27 | {.name = "binary", .has_arg = false, .val = 'b'}, |
| 28 | {.name = "counters", .has_arg = false, .val = 'c'}, |
| 29 | {.name = "dump", .has_arg = false, .val = 'd'}, |
| 30 | {.name = "table", .has_arg = true, .val = 't'}, |
Jan Engelhardt | fbb5639 | 2009-03-19 16:57:35 +0100 | [diff] [blame] | 31 | {.name = "modprobe", .has_arg = true, .val = 'M'}, |
Gáspár Lajos | 7bc3cb7 | 2008-03-27 08:20:39 +0100 | [diff] [blame] | 32 | {NULL}, |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 33 | }; |
| 34 | |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 35 | /* Debugging prototype. */ |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 36 | static int for_each_table(int (*func)(const char *tablename)) |
| 37 | { |
Max Kellermann | 5b76f68 | 2008-01-29 13:42:48 +0000 | [diff] [blame] | 38 | int ret = 1; |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 39 | FILE *procfile = NULL; |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 40 | char tablename[IPT_TABLE_MAXNAMELEN+1]; |
| 41 | |
Maciej Zenczykowski | a239728 | 2011-04-04 15:30:32 +0200 | [diff] [blame] | 42 | procfile = fopen("/proc/net/ip_tables_names", "re"); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 43 | if (!procfile) |
Jan Engelhardt | fbb5639 | 2009-03-19 16:57:35 +0100 | [diff] [blame] | 44 | return ret; |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 45 | |
| 46 | while (fgets(tablename, sizeof(tablename), procfile)) { |
| 47 | if (tablename[strlen(tablename) - 1] != '\n') |
Jan Engelhardt | 1829ed4 | 2009-02-21 03:29:44 +0100 | [diff] [blame] | 48 | xtables_error(OTHER_PROBLEM, |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 49 | "Badly formed tablename `%s'\n", |
| 50 | tablename); |
| 51 | tablename[strlen(tablename) - 1] = '\0'; |
| 52 | ret &= func(tablename); |
| 53 | } |
| 54 | |
Jan Engelhardt | f1afcc8 | 2009-06-10 13:52:58 +0200 | [diff] [blame] | 55 | fclose(procfile); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 56 | return ret; |
| 57 | } |
Max Kellermann | 5b76f68 | 2008-01-29 13:42:48 +0000 | [diff] [blame] | 58 | |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 59 | |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 60 | static int do_output(const char *tablename) |
| 61 | { |
Jan Engelhardt | fd18731 | 2008-11-10 16:59:27 +0100 | [diff] [blame] | 62 | struct iptc_handle *h; |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 63 | const char *chain = NULL; |
| 64 | |
| 65 | if (!tablename) |
| 66 | return for_each_table(&do_output); |
| 67 | |
| 68 | h = iptc_init(tablename); |
Jan Engelhardt | fbb5639 | 2009-03-19 16:57:35 +0100 | [diff] [blame] | 69 | if (h == NULL) { |
| 70 | xtables_load_ko(xtables_modprobe_program, false); |
| 71 | h = iptc_init(tablename); |
| 72 | } |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 73 | if (!h) |
Jan Engelhardt | 1829ed4 | 2009-02-21 03:29:44 +0100 | [diff] [blame] | 74 | xtables_error(OTHER_PROBLEM, "Cannot initialize: %s\n", |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 75 | iptc_strerror(errno)); |
| 76 | |
Jan Engelhardt | dbb7754 | 2008-02-11 00:33:30 +0100 | [diff] [blame] | 77 | if (!show_binary) { |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 78 | time_t now = time(NULL); |
| 79 | |
| 80 | printf("# Generated by iptables-save v%s on %s", |
Jan Engelhardt | dacafa5 | 2009-01-27 20:56:23 +0100 | [diff] [blame] | 81 | IPTABLES_VERSION, ctime(&now)); |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 82 | printf("*%s\n", tablename); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 83 | |
Max Kellermann | 5b76f68 | 2008-01-29 13:42:48 +0000 | [diff] [blame] | 84 | /* Dump out chain names first, |
Harald Welte | 9f7fa49 | 2001-03-15 15:12:02 +0000 | [diff] [blame] | 85 | * thereby preventing dependency conflicts */ |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 86 | for (chain = iptc_first_chain(h); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 87 | chain; |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 88 | chain = iptc_next_chain(h)) { |
Max Kellermann | 5b76f68 | 2008-01-29 13:42:48 +0000 | [diff] [blame] | 89 | |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 90 | printf(":%s ", chain); |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 91 | if (iptc_builtin(chain, h)) { |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 92 | struct ipt_counters count; |
| 93 | printf("%s ", |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 94 | iptc_get_policy(chain, &count, h)); |
Martin Josefsson | a28d495 | 2004-05-26 16:04:48 +0000 | [diff] [blame] | 95 | printf("[%llu:%llu]\n", (unsigned long long)count.pcnt, (unsigned long long)count.bcnt); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 96 | } else { |
Harald Welte | d8e6563 | 2001-01-05 15:20:07 +0000 | [diff] [blame] | 97 | printf("- [0:0]\n"); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 98 | } |
Harald Welte | 9f7fa49 | 2001-03-15 15:12:02 +0000 | [diff] [blame] | 99 | } |
Max Kellermann | 5b76f68 | 2008-01-29 13:42:48 +0000 | [diff] [blame] | 100 | |
Harald Welte | 9f7fa49 | 2001-03-15 15:12:02 +0000 | [diff] [blame] | 101 | |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 102 | for (chain = iptc_first_chain(h); |
Harald Welte | 9f7fa49 | 2001-03-15 15:12:02 +0000 | [diff] [blame] | 103 | chain; |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 104 | chain = iptc_next_chain(h)) { |
Harald Welte | 9f7fa49 | 2001-03-15 15:12:02 +0000 | [diff] [blame] | 105 | const struct ipt_entry *e; |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 106 | |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 107 | /* Dump out rules */ |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 108 | e = iptc_first_rule(chain, h); |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 109 | while(e) { |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 110 | print_rule(e, h, chain, show_counters); |
| 111 | e = iptc_next_rule(e, h); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 112 | } |
| 113 | } |
| 114 | |
| 115 | now = time(NULL); |
| 116 | printf("COMMIT\n"); |
| 117 | printf("# Completed on %s", ctime(&now)); |
| 118 | } else { |
| 119 | /* Binary, huh? OK. */ |
Jan Engelhardt | 1829ed4 | 2009-02-21 03:29:44 +0100 | [diff] [blame] | 120 | xtables_error(OTHER_PROBLEM, "Binary NYI\n"); |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 121 | } |
| 122 | |
Jan Engelhardt | 1c9015b | 2008-11-10 17:00:41 +0100 | [diff] [blame] | 123 | iptc_free(h); |
Martin Josefsson | 841e4ae | 2003-05-02 15:30:11 +0000 | [diff] [blame] | 124 | |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 125 | return 1; |
| 126 | } |
| 127 | |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 128 | /* Format: |
| 129 | * :Chain name POLICY packets bytes |
| 130 | * rule |
| 131 | */ |
Bastiaan Bakker | 4e3771f | 2004-06-25 11:18:57 +0000 | [diff] [blame] | 132 | #ifdef IPTABLES_MULTI |
| 133 | int |
| 134 | iptables_save_main(int argc, char *argv[]) |
| 135 | #else |
| 136 | int |
| 137 | main(int argc, char *argv[]) |
| 138 | #endif |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 139 | { |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 140 | const char *tablename = NULL; |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 141 | int c; |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 142 | |
Jamal Hadi Salim | 617d3d1 | 2009-02-11 16:28:31 -0500 | [diff] [blame] | 143 | iptables_globals.program_name = "iptables-save"; |
Jamal Hadi Salim | 7e4db2f | 2009-02-13 09:14:17 -0500 | [diff] [blame] | 144 | c = xtables_init_all(&iptables_globals, NFPROTO_IPV4); |
| 145 | if (c < 0) { |
| 146 | fprintf(stderr, "%s/%s Failed to initialize xtables\n", |
| 147 | iptables_globals.program_name, |
| 148 | iptables_globals.program_version); |
| 149 | exit(1); |
| 150 | } |
Jan Engelhardt | b79ec69 | 2009-07-23 17:41:21 +0200 | [diff] [blame] | 151 | #if defined(ALL_INCLUSIVE) || defined(NO_SHARED_LIBS) |
Harald Welte | 3efb6ea | 2001-08-06 18:50:21 +0000 | [diff] [blame] | 152 | init_extensions(); |
| 153 | #endif |
| 154 | |
Marc Boucher | 163ad78 | 2001-12-06 15:05:48 +0000 | [diff] [blame] | 155 | while ((c = getopt_long(argc, argv, "bcdt:", options, NULL)) != -1) { |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 156 | switch (c) { |
| 157 | case 'b': |
Jan Engelhardt | dbb7754 | 2008-02-11 00:33:30 +0100 | [diff] [blame] | 158 | show_binary = 1; |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 159 | break; |
| 160 | |
| 161 | case 'c': |
Jan Engelhardt | dbb7754 | 2008-02-11 00:33:30 +0100 | [diff] [blame] | 162 | show_counters = 1; |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 163 | break; |
| 164 | |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 165 | case 't': |
| 166 | /* Select specific table. */ |
| 167 | tablename = optarg; |
| 168 | break; |
Jan Engelhardt | fbb5639 | 2009-03-19 16:57:35 +0100 | [diff] [blame] | 169 | case 'M': |
| 170 | xtables_modprobe_program = optarg; |
| 171 | break; |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 172 | case 'd': |
Harald Welte | ae1ff9f | 2000-12-01 14:26:20 +0000 | [diff] [blame] | 173 | do_output(tablename); |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 174 | exit(0); |
| 175 | } |
| 176 | } |
| 177 | |
| 178 | if (optind < argc) { |
Pavel Rusnak | 972af09 | 2007-05-10 15:00:39 +0000 | [diff] [blame] | 179 | fprintf(stderr, "Unknown arguments found on commandline\n"); |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 180 | exit(1); |
| 181 | } |
| 182 | |
Rusty Russell | a8f033e | 2000-07-30 01:43:01 +0000 | [diff] [blame] | 183 | return !do_output(tablename); |
Marc Boucher | e6869a8 | 2000-03-20 06:03:29 +0000 | [diff] [blame] | 184 | } |