4 #include <linux/netfilter/xt_MARK.h>
7 struct xt_mark_target_info {
18 struct xt_mark_target_info_v1 {
29 F_SET_MARK = 1 << O_SET_MARK,
30 F_AND_MARK = 1 << O_AND_MARK,
31 F_OR_MARK = 1 << O_OR_MARK,
32 F_XOR_MARK = 1 << O_XOR_MARK,
33 F_SET_XMARK = 1 << O_SET_XMARK,
34 F_ANY = F_SET_MARK | F_AND_MARK | F_OR_MARK |
35 F_XOR_MARK | F_SET_XMARK,
38 static void MARK_help(void)
41 "MARK target options:\n"
42 " --set-mark value Set nfmark value\n"
43 " --and-mark value Binary AND the nfmark with value\n"
44 " --or-mark value Binary OR the nfmark with value\n");
47 static const struct xt_option_entry MARK_opts[] = {
48 {.name = "set-mark", .id = O_SET_MARK, .type = XTTYPE_UINT32,
50 {.name = "and-mark", .id = O_AND_MARK, .type = XTTYPE_UINT32,
52 {.name = "or-mark", .id = O_OR_MARK, .type = XTTYPE_UINT32,
57 static const struct xt_option_entry mark_tg_opts[] = {
58 {.name = "set-xmark", .id = O_SET_XMARK, .type = XTTYPE_MARKMASK32,
60 {.name = "set-mark", .id = O_SET_MARK, .type = XTTYPE_MARKMASK32,
62 {.name = "and-mark", .id = O_AND_MARK, .type = XTTYPE_UINT32,
64 {.name = "or-mark", .id = O_OR_MARK, .type = XTTYPE_UINT32,
66 {.name = "xor-mark", .id = O_XOR_MARK, .type = XTTYPE_UINT32,
71 static void mark_tg_help(void)
74 "MARK target options:\n"
75 " --set-xmark value[/mask] Clear bits in mask and XOR value into nfmark\n"
76 " --set-mark value[/mask] Clear bits in mask and OR value into nfmark\n"
77 " --and-mark bits Binary AND the nfmark with bits\n"
78 " --or-mark bits Binary OR the nfmark with bits\n"
79 " --xor-mask bits Binary XOR the nfmark with bits\n"
83 static void MARK_parse_v0(struct xt_option_call *cb)
85 struct xt_mark_target_info *markinfo = cb->data;
87 xtables_option_parse(cb);
88 switch (cb->entry->id) {
90 markinfo->mark = cb->val.mark;
93 xtables_error(PARAMETER_PROBLEM,
94 "MARK target: kernel too old for --%s",
99 static void MARK_check(struct xt_fcheck_call *cb)
102 xtables_error(PARAMETER_PROBLEM,
103 "MARK target: Parameter --set/and/or-mark"
107 static void MARK_parse_v1(struct xt_option_call *cb)
109 struct xt_mark_target_info_v1 *markinfo = cb->data;
111 xtables_option_parse(cb);
112 switch (cb->entry->id) {
114 markinfo->mode = XT_MARK_SET;
117 markinfo->mode = XT_MARK_AND;
120 markinfo->mode = XT_MARK_OR;
123 markinfo->mark = cb->val.u32;
126 static void mark_tg_parse(struct xt_option_call *cb)
128 struct xt_mark_tginfo2 *info = cb->data;
130 xtables_option_parse(cb);
131 switch (cb->entry->id) {
133 info->mark = cb->val.mark;
134 info->mask = cb->val.mask;
137 info->mark = cb->val.mark;
138 info->mask = cb->val.mark | cb->val.mask;
142 info->mask = ~cb->val.u32;
145 info->mark = info->mask = cb->val.u32;
148 info->mark = cb->val.u32;
154 static void mark_tg_check(struct xt_fcheck_call *cb)
157 xtables_error(PARAMETER_PROBLEM, "MARK: One of the --set-xmark, "
158 "--{and,or,xor,set}-mark options is required");
162 print_mark(unsigned long mark)
164 printf(" 0x%lx", mark);
167 static void MARK_print_v0(const void *ip,
168 const struct xt_entry_target *target, int numeric)
170 const struct xt_mark_target_info *markinfo =
171 (const struct xt_mark_target_info *)target->data;
173 print_mark(markinfo->mark);
176 static void MARK_save_v0(const void *ip, const struct xt_entry_target *target)
178 const struct xt_mark_target_info *markinfo =
179 (const struct xt_mark_target_info *)target->data;
181 printf(" --set-mark");
182 print_mark(markinfo->mark);
185 static void MARK_print_v1(const void *ip, const struct xt_entry_target *target,
188 const struct xt_mark_target_info_v1 *markinfo =
189 (const struct xt_mark_target_info_v1 *)target->data;
191 switch (markinfo->mode) {
202 print_mark(markinfo->mark);
205 static void mark_tg_print(const void *ip, const struct xt_entry_target *target,
208 const struct xt_mark_tginfo2 *info = (const void *)target->data;
211 printf(" MARK and 0x%x", (unsigned int)(uint32_t)~info->mask);
212 else if (info->mark == info->mask)
213 printf(" MARK or 0x%x", info->mark);
214 else if (info->mask == 0)
215 printf(" MARK xor 0x%x", info->mark);
216 else if (info->mask == 0xffffffffU)
217 printf(" MARK set 0x%x", info->mark);
219 printf(" MARK xset 0x%x/0x%x", info->mark, info->mask);
222 static void MARK_save_v1(const void *ip, const struct xt_entry_target *target)
224 const struct xt_mark_target_info_v1 *markinfo =
225 (const struct xt_mark_target_info_v1 *)target->data;
227 switch (markinfo->mode) {
229 printf(" --set-mark");
232 printf(" --and-mark");
235 printf(" --or-mark");
238 print_mark(markinfo->mark);
241 static void mark_tg_save(const void *ip, const struct xt_entry_target *target)
243 const struct xt_mark_tginfo2 *info = (const void *)target->data;
245 printf(" --set-xmark 0x%x/0x%x", info->mark, info->mask);
248 static struct xtables_target mark_tg_reg[] = {
250 .family = NFPROTO_UNSPEC,
252 .version = XTABLES_VERSION,
254 .size = XT_ALIGN(sizeof(struct xt_mark_target_info)),
255 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info)),
257 .print = MARK_print_v0,
258 .save = MARK_save_v0,
259 .x6_parse = MARK_parse_v0,
260 .x6_fcheck = MARK_check,
261 .x6_options = MARK_opts,
264 .family = NFPROTO_IPV4,
266 .version = XTABLES_VERSION,
268 .size = XT_ALIGN(sizeof(struct xt_mark_target_info_v1)),
269 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_target_info_v1)),
271 .print = MARK_print_v1,
272 .save = MARK_save_v1,
273 .x6_parse = MARK_parse_v1,
274 .x6_fcheck = MARK_check,
275 .x6_options = MARK_opts,
278 .version = XTABLES_VERSION,
281 .family = NFPROTO_UNSPEC,
282 .size = XT_ALIGN(sizeof(struct xt_mark_tginfo2)),
283 .userspacesize = XT_ALIGN(sizeof(struct xt_mark_tginfo2)),
284 .help = mark_tg_help,
285 .print = mark_tg_print,
286 .save = mark_tg_save,
287 .x6_parse = mark_tg_parse,
288 .x6_fcheck = mark_tg_check,
289 .x6_options = mark_tg_opts,
295 xtables_register_targets(mark_tg_reg, ARRAY_SIZE(mark_tg_reg));