]>
Commit | Line | Data |
---|---|---|
baf7b1e1 PM |
1 | /* |
2 | * Copyright (c) 2006 Patrick McHardy <kaber@trash.net> | |
3 | * | |
4 | * This program is free software; you can redistribute it and/or modify | |
5 | * it under the terms of the GNU General Public License version 2 as | |
6 | * published by the Free Software Foundation. | |
7 | */ | |
8 | ||
9 | #include <linux/module.h> | |
10 | #include <linux/init.h> | |
11 | #include <linux/skbuff.h> | |
12 | ||
13 | #include <linux/netfilter/x_tables.h> | |
14 | #include <linux/netfilter/xt_NFLOG.h> | |
f01ffbd6 | 15 | #include <net/netfilter/nf_log.h> |
5f7340ef | 16 | #include <net/netfilter/nfnetlink_log.h> |
baf7b1e1 PM |
17 | |
18 | MODULE_AUTHOR("Patrick McHardy <kaber@trash.net>"); | |
2ae15b64 | 19 | MODULE_DESCRIPTION("Xtables: packet logging to netlink using NFLOG"); |
baf7b1e1 PM |
20 | MODULE_LICENSE("GPL"); |
21 | MODULE_ALIAS("ipt_NFLOG"); | |
22 | MODULE_ALIAS("ip6t_NFLOG"); | |
23 | ||
24 | static unsigned int | |
4b560b44 | 25 | nflog_tg(struct sk_buff *skb, const struct xt_action_param *par) |
baf7b1e1 | 26 | { |
7eb35586 | 27 | const struct xt_nflog_info *info = par->targinfo; |
613dbd95 | 28 | struct net *net = xt_net(par); |
baf7b1e1 PM |
29 | struct nf_loginfo li; |
30 | ||
31 | li.type = NF_LOG_TYPE_ULOG; | |
32 | li.u.ulog.copy_len = info->len; | |
33 | li.u.ulog.group = info->group; | |
34 | li.u.ulog.qthreshold = info->threshold; | |
6d19375b | 35 | li.u.ulog.flags = 0; |
baf7b1e1 | 36 | |
7643507f VP |
37 | if (info->flags & XT_NFLOG_F_COPY_LEN) |
38 | li.u.ulog.flags |= NF_LOG_F_COPY_LEN; | |
39 | ||
613dbd95 PNA |
40 | nfulnl_log_packet(net, xt_family(par), xt_hooknum(par), skb, |
41 | xt_in(par), xt_out(par), &li, info->prefix); | |
baf7b1e1 PM |
42 | return XT_CONTINUE; |
43 | } | |
44 | ||
135367b8 | 45 | static int nflog_tg_check(const struct xt_tgchk_param *par) |
baf7b1e1 | 46 | { |
af5d6dc2 | 47 | const struct xt_nflog_info *info = par->targinfo; |
baf7b1e1 PM |
48 | |
49 | if (info->flags & ~XT_NFLOG_MASK) | |
d6b00a53 | 50 | return -EINVAL; |
baf7b1e1 | 51 | if (info->prefix[sizeof(info->prefix) - 1] != '\0') |
d6b00a53 JE |
52 | return -EINVAL; |
53 | return 0; | |
baf7b1e1 PM |
54 | } |
55 | ||
92f3b2b1 JE |
56 | static struct xt_target nflog_tg_reg __read_mostly = { |
57 | .name = "NFLOG", | |
58 | .revision = 0, | |
59 | .family = NFPROTO_UNSPEC, | |
60 | .checkentry = nflog_tg_check, | |
61 | .target = nflog_tg, | |
62 | .targetsize = sizeof(struct xt_nflog_info), | |
63 | .me = THIS_MODULE, | |
baf7b1e1 PM |
64 | }; |
65 | ||
d3c5ee6d | 66 | static int __init nflog_tg_init(void) |
baf7b1e1 | 67 | { |
92f3b2b1 | 68 | return xt_register_target(&nflog_tg_reg); |
baf7b1e1 PM |
69 | } |
70 | ||
d3c5ee6d | 71 | static void __exit nflog_tg_exit(void) |
baf7b1e1 | 72 | { |
92f3b2b1 | 73 | xt_unregister_target(&nflog_tg_reg); |
baf7b1e1 PM |
74 | } |
75 | ||
d3c5ee6d JE |
76 | module_init(nflog_tg_init); |
77 | module_exit(nflog_tg_exit); |