]>
git.proxmox.com Git - mirror_iproute2.git/blob - tc/tc_filter.c
2 * tc_filter.c "tc filter".
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version
7 * 2 of the License, or (at your option) any later version.
9 * Authors: Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
17 #include <sys/socket.h>
18 #include <netinet/in.h>
19 #include <arpa/inet.h>
21 #include <linux/if_ether.h>
26 #include "tc_common.h"
28 static void usage(void)
31 "Usage: tc filter [ add | del | change | replace | show ] [ dev STRING ]\n"
32 " tc filter [ add | del | change | replace | show ] [ block BLOCK_INDEX ]\n"
33 " tc filter get dev STRING parent CLASSID protocol PROTO handle FILTERID pref PRIO FILTER_TYPE\n"
34 " tc filter get block BLOCK_INDEX protocol PROTO handle FILTERID pref PRIO FILTER_TYPE\n"
35 " [ pref PRIO ] protocol PROTO [ chain CHAIN_INDEX ]\n"
36 " [ estimator INTERVAL TIME_CONSTANT ]\n"
37 " [ root | ingress | egress | parent CLASSID ]\n"
38 " [ handle FILTERID ] [ [ FILTER_TYPE ] [ help | OPTIONS ] ]\n"
40 " tc filter show [ dev STRING ] [ root | ingress | egress | parent CLASSID ]\n"
41 " tc filter show [ block BLOCK_INDEX ]\n"
43 "FILTER_TYPE := { rsvp | u32 | bpf | fw | route | etc. }\n"
44 "FILTERID := ... format depends on classifier, see there\n"
45 "OPTIONS := ... try tc filter add <desired FILTER_KIND> help\n");
48 struct tc_filter_req
{
54 static int tc_filter_modify(int cmd
, unsigned int flags
, int argc
, char **argv
,
55 void *buf
, size_t buflen
)
57 struct tc_filter_req
*req
, filter_req
;
58 struct filter_util
*q
= NULL
;
59 struct tc_estimator est
= {};
60 char k
[FILTER_NAMESZ
] = {};
61 int chain_index_set
= 0;
62 char d
[IFNAMSIZ
] = {};
64 __u32 block_index
= 0;
74 if (buflen
< sizeof (struct tc_filter_req
)) {
75 fprintf(stderr
, "buffer is too small: %zu\n", buflen
);
79 memset(&filter_req
, 0, sizeof (struct tc_filter_req
));
83 req
->n
.nlmsg_len
= NLMSG_LENGTH(sizeof(struct tcmsg
));
84 req
->n
.nlmsg_flags
= NLM_F_REQUEST
| flags
;
85 req
->n
.nlmsg_type
= cmd
;
86 req
->t
.tcm_family
= AF_UNSPEC
;
88 if (cmd
== RTM_NEWTFILTER
&& flags
& NLM_F_CREATE
)
89 protocol
= htons(ETH_P_ALL
);
92 if (strcmp(*argv
, "dev") == 0) {
97 fprintf(stderr
, "Error: \"dev\" and \"block\" are mutually exlusive\n");
100 strncpy(d
, *argv
, sizeof(d
)-1);
101 } else if (matches(*argv
, "block") == 0) {
104 duparg("block", *argv
);
106 fprintf(stderr
, "Error: \"dev\" and \"block\" are mutually exlusive\n");
109 if (get_u32(&block_index
, *argv
, 0) || !block_index
)
110 invarg("invalid block index value", *argv
);
111 } else if (strcmp(*argv
, "root") == 0) {
112 if (req
->t
.tcm_parent
) {
114 "Error: \"root\" is duplicate parent ID\n");
117 req
->t
.tcm_parent
= TC_H_ROOT
;
118 } else if (strcmp(*argv
, "ingress") == 0) {
119 if (req
->t
.tcm_parent
) {
121 "Error: \"ingress\" is duplicate parent ID\n");
124 req
->t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
126 } else if (strcmp(*argv
, "egress") == 0) {
127 if (req
->t
.tcm_parent
) {
129 "Error: \"egress\" is duplicate parent ID\n");
132 req
->t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
134 } else if (strcmp(*argv
, "parent") == 0) {
138 if (req
->t
.tcm_parent
)
139 duparg("parent", *argv
);
140 if (get_tc_classid(&handle
, *argv
))
141 invarg("Invalid parent ID", *argv
);
142 req
->t
.tcm_parent
= handle
;
143 } else if (strcmp(*argv
, "handle") == 0) {
146 duparg("handle", *argv
);
148 } else if (matches(*argv
, "preference") == 0 ||
149 matches(*argv
, "priority") == 0) {
152 duparg("priority", *argv
);
153 if (get_u32(&prio
, *argv
, 0) || prio
> 0xFFFF)
154 invarg("invalid priority value", *argv
);
155 } else if (matches(*argv
, "protocol") == 0) {
160 duparg("protocol", *argv
);
161 if (ll_proto_a2n(&id
, *argv
))
162 invarg("invalid protocol", *argv
);
165 } else if (matches(*argv
, "chain") == 0) {
168 duparg("chain", *argv
);
169 if (get_u32(&chain_index
, *argv
, 0))
170 invarg("invalid chain index value", *argv
);
172 } else if (matches(*argv
, "estimator") == 0) {
173 if (parse_estimator(&argc
, &argv
, &est
) < 0)
175 } else if (matches(*argv
, "help") == 0) {
179 strncpy(k
, *argv
, sizeof(k
)-1);
181 q
= get_filter_kind(k
);
189 req
->t
.tcm_info
= TC_H_MAKE(prio
<<16, protocol
);
192 addattr32(&req
->n
, sizeof(*req
), TCA_CHAIN
, chain_index
);
195 addattr_l(&req
->n
, sizeof(*req
), TCA_KIND
, k
, strlen(k
)+1);
200 req
->t
.tcm_ifindex
= ll_name_to_index(d
);
201 if (!req
->t
.tcm_ifindex
)
203 } else if (block_index
) {
204 req
->t
.tcm_ifindex
= TCM_IFINDEX_MAGIC_BLOCK
;
205 req
->t
.tcm_block_index
= block_index
;
209 if (q
->parse_fopt(q
, fhandle
, argc
, argv
, &req
->n
))
214 "Must specify filter type when using \"handle\"\n");
218 if (matches(*argv
, "help") == 0)
221 "Garbage instead of arguments \"%s ...\". Try \"tc filter help\".\n",
228 addattr_l(&req
->n
, sizeof(*req
), TCA_RATE
, &est
, sizeof(est
));
233 iov
.iov_base
= &req
->n
;
234 iov
.iov_len
= req
->n
.nlmsg_len
;
235 ret
= rtnl_talk_iov(&rth
, &iov
, 1, NULL
);
237 fprintf(stderr
, "We have an error talking to the kernel, %d\n", ret
);
244 static __u32 filter_parent
;
245 static int filter_ifindex
;
246 static __u32 filter_prio
;
247 static __u32 filter_protocol
;
248 static __u32 filter_chain_index
;
249 static int filter_chain_index_set
;
250 static __u32 filter_block_index
;
253 int print_filter(const struct sockaddr_nl
*who
, struct nlmsghdr
*n
, void *arg
)
255 FILE *fp
= (FILE *)arg
;
256 struct tcmsg
*t
= NLMSG_DATA(n
);
257 int len
= n
->nlmsg_len
;
258 struct rtattr
*tb
[TCA_MAX
+1];
259 struct filter_util
*q
;
262 if (n
->nlmsg_type
!= RTM_NEWTFILTER
&&
263 n
->nlmsg_type
!= RTM_GETTFILTER
&&
264 n
->nlmsg_type
!= RTM_DELTFILTER
) {
265 fprintf(stderr
, "Not a filter(cmd %d)\n", n
->nlmsg_type
);
268 len
-= NLMSG_LENGTH(sizeof(*t
));
270 fprintf(stderr
, "Wrong len %d\n", len
);
274 parse_rtattr(tb
, TCA_MAX
, TCA_RTA(t
), len
);
276 if (tb
[TCA_KIND
] == NULL
) {
277 fprintf(stderr
, "print_filter: NULL kind\n");
281 open_json_object(NULL
);
283 if (n
->nlmsg_type
== RTM_DELTFILTER
)
284 print_bool(PRINT_ANY
, "deleted", "deleted ", true);
286 if (n
->nlmsg_type
== RTM_NEWTFILTER
&&
287 (n
->nlmsg_flags
& NLM_F_CREATE
) &&
288 !(n
->nlmsg_flags
& NLM_F_EXCL
))
289 print_bool(PRINT_ANY
, "replaced", "replaced ", true);
291 if (n
->nlmsg_type
== RTM_NEWTFILTER
&&
292 (n
->nlmsg_flags
& NLM_F_CREATE
) &&
293 (n
->nlmsg_flags
& NLM_F_EXCL
))
294 print_bool(PRINT_ANY
, "added", "added ", true);
296 print_string(PRINT_FP
, NULL
, "filter ", NULL
);
297 if (t
->tcm_ifindex
== TCM_IFINDEX_MAGIC_BLOCK
) {
298 if (!filter_block_index
||
299 filter_block_index
!= t
->tcm_block_index
)
300 print_uint(PRINT_ANY
, "block", "block %u ",
303 if (!filter_ifindex
|| filter_ifindex
!= t
->tcm_ifindex
)
304 print_devname(PRINT_ANY
, t
->tcm_ifindex
);
306 if (!filter_parent
|| filter_parent
!= t
->tcm_parent
) {
307 if (t
->tcm_parent
== TC_H_ROOT
)
308 print_bool(PRINT_ANY
, "root", "root ", true);
309 else if (t
->tcm_parent
== TC_H_MAKE(TC_H_CLSACT
, TC_H_MIN_INGRESS
))
310 print_bool(PRINT_ANY
, "ingress", "ingress ", true);
311 else if (t
->tcm_parent
== TC_H_MAKE(TC_H_CLSACT
, TC_H_MIN_EGRESS
))
312 print_bool(PRINT_ANY
, "egress", "egress ", true);
314 print_tc_classid(abuf
, sizeof(abuf
), t
->tcm_parent
);
315 print_string(PRINT_ANY
, "parent", "parent %s ", abuf
);
321 f_proto
= TC_H_MIN(t
->tcm_info
);
322 __u32 prio
= TC_H_MAJ(t
->tcm_info
)>>16;
324 if (!filter_protocol
|| filter_protocol
!= f_proto
) {
327 print_string(PRINT_ANY
, "protocol",
329 ll_proto_n2a(f_proto
, b1
, sizeof(b1
)));
332 if (!filter_prio
|| filter_prio
!= prio
) {
334 print_uint(PRINT_ANY
, "pref", "pref %u ", prio
);
337 print_string(PRINT_ANY
, "kind", "%s ", rta_getattr_str(tb
[TCA_KIND
]));
340 __u32 chain_index
= rta_getattr_u32(tb
[TCA_CHAIN
]);
342 if (!filter_chain_index_set
||
343 filter_chain_index
!= chain_index
)
344 print_uint(PRINT_ANY
, "chain", "chain %u ",
348 q
= get_filter_kind(RTA_DATA(tb
[TCA_KIND
]));
349 if (tb
[TCA_OPTIONS
]) {
350 open_json_object("options");
352 q
->print_fopt(q
, fp
, tb
[TCA_OPTIONS
], t
->tcm_handle
);
354 print_string(PRINT_FP
, NULL
,
355 "[cannot parse parameters]", NULL
);
358 print_string(PRINT_FP
, NULL
, "\n", NULL
);
360 if (show_stats
&& (tb
[TCA_STATS
] || tb
[TCA_STATS2
])) {
361 print_tcstats_attr(fp
, tb
, " ", NULL
);
362 print_string(PRINT_FP
, NULL
, "\n", NULL
);
370 static int tc_filter_get(int cmd
, unsigned int flags
, int argc
, char **argv
)
377 .n
.nlmsg_len
= NLMSG_LENGTH(sizeof(struct tcmsg
)),
378 /* NLM_F_ECHO is for backward compatibility. old kernels never
379 * respond without it and newer kernels will ignore it.
380 * In old kernels there is a side effect:
381 * In addition to a response to the GET you will receive an
382 * event (if you do tc mon).
384 .n
.nlmsg_flags
= NLM_F_REQUEST
| NLM_F_ECHO
| flags
,
386 .t
.tcm_parent
= TC_H_UNSPEC
,
387 .t
.tcm_family
= AF_UNSPEC
,
389 struct nlmsghdr
*answer
;
390 struct filter_util
*q
= NULL
;
393 int protocol_set
= 0;
395 int chain_index_set
= 0;
396 __u32 block_index
= 0;
397 __u32 parent_handle
= 0;
398 char *fhandle
= NULL
;
399 char d
[IFNAMSIZ
] = {};
400 char k
[FILTER_NAMESZ
] = {};
403 if (strcmp(*argv
, "dev") == 0) {
406 duparg("dev", *argv
);
408 fprintf(stderr
, "Error: \"dev\" and \"block\" are mutually exlusive\n");
411 strncpy(d
, *argv
, sizeof(d
)-1);
412 } else if (matches(*argv
, "block") == 0) {
415 duparg("block", *argv
);
417 fprintf(stderr
, "Error: \"dev\" and \"block\" are mutually exlusive\n");
420 if (get_u32(&block_index
, *argv
, 0) || !block_index
)
421 invarg("invalid block index value", *argv
);
422 } else if (strcmp(*argv
, "root") == 0) {
423 if (req
.t
.tcm_parent
) {
425 "Error: \"root\" is duplicate parent ID\n");
428 req
.t
.tcm_parent
= TC_H_ROOT
;
429 } else if (strcmp(*argv
, "ingress") == 0) {
430 if (req
.t
.tcm_parent
) {
432 "Error: \"ingress\" is duplicate parent ID\n");
435 req
.t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
437 } else if (strcmp(*argv
, "egress") == 0) {
438 if (req
.t
.tcm_parent
) {
440 "Error: \"egress\" is duplicate parent ID\n");
443 req
.t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
445 } else if (strcmp(*argv
, "parent") == 0) {
448 if (req
.t
.tcm_parent
)
449 duparg("parent", *argv
);
450 if (get_tc_classid(&parent_handle
, *argv
))
451 invarg("Invalid parent ID", *argv
);
452 req
.t
.tcm_parent
= parent_handle
;
453 } else if (strcmp(*argv
, "handle") == 0) {
456 duparg("handle", *argv
);
458 } else if (matches(*argv
, "preference") == 0 ||
459 matches(*argv
, "priority") == 0) {
462 duparg("priority", *argv
);
463 if (get_u32(&prio
, *argv
, 0) || prio
> 0xFFFF)
464 invarg("invalid priority value", *argv
);
465 } else if (matches(*argv
, "protocol") == 0) {
470 duparg("protocol", *argv
);
471 if (ll_proto_a2n(&id
, *argv
))
472 invarg("invalid protocol", *argv
);
475 } else if (matches(*argv
, "chain") == 0) {
478 duparg("chain", *argv
);
479 if (get_u32(&chain_index
, *argv
, 0))
480 invarg("invalid chain index value", *argv
);
482 } else if (matches(*argv
, "help") == 0) {
487 invarg("invalid filter name", *argv
);
489 strncpy(k
, *argv
, sizeof(k
)-1);
491 q
= get_filter_kind(k
);
500 fprintf(stderr
, "Must specify filter protocol\n");
505 fprintf(stderr
, "Must specify filter priority\n");
509 req
.t
.tcm_info
= TC_H_MAKE(prio
<<16, protocol
);
512 addattr32(&req
.n
, sizeof(req
), TCA_CHAIN
, chain_index
);
514 if (req
.t
.tcm_parent
== TC_H_UNSPEC
) {
515 fprintf(stderr
, "Must specify filter parent\n");
520 addattr_l(&req
.n
, sizeof(req
), TCA_KIND
, k
, strlen(k
)+1);
522 fprintf(stderr
, "Must specify filter type\n");
529 req
.t
.tcm_ifindex
= ll_name_to_index(d
);
530 if (!req
.t
.tcm_ifindex
)
532 filter_ifindex
= req
.t
.tcm_ifindex
;
533 } else if (block_index
) {
534 req
.t
.tcm_ifindex
= TCM_IFINDEX_MAGIC_BLOCK
;
535 req
.t
.tcm_block_index
= block_index
;
536 filter_block_index
= block_index
;
538 fprintf(stderr
, "Must specify netdevice \"dev\" or block index \"block\"\n");
542 if (q
->parse_fopt(q
, fhandle
, argc
, argv
, &req
.n
))
546 fprintf(stderr
, "Must specify filter \"handle\"\n");
551 if (matches(*argv
, "help") == 0)
554 "Garbage instead of arguments \"%s ...\". Try \"tc filter help\".\n",
559 if (rtnl_talk(&rth
, &req
.n
, &answer
) < 0) {
560 fprintf(stderr
, "We have an error talking to the kernel\n");
565 print_filter(NULL
, answer
, (void *)stdout
);
572 static int tc_filter_list(int argc
, char **argv
)
579 .n
.nlmsg_len
= NLMSG_LENGTH(sizeof(struct tcmsg
)),
580 .n
.nlmsg_type
= RTM_GETTFILTER
,
581 .t
.tcm_parent
= TC_H_UNSPEC
,
582 .t
.tcm_family
= AF_UNSPEC
,
584 char d
[IFNAMSIZ
] = {};
588 __u32 block_index
= 0;
589 char *fhandle
= NULL
;
592 if (strcmp(*argv
, "dev") == 0) {
595 duparg("dev", *argv
);
597 fprintf(stderr
, "Error: \"dev\" cannot be used in the same time as \"block\"\n");
600 strncpy(d
, *argv
, sizeof(d
)-1);
601 } else if (matches(*argv
, "block") == 0) {
604 duparg("block", *argv
);
606 fprintf(stderr
, "Error: \"block\" cannot be used in the same time as \"dev\"\n");
609 if (get_u32(&block_index
, *argv
, 0) || !block_index
)
610 invarg("invalid block index value", *argv
);
611 } else if (strcmp(*argv
, "root") == 0) {
612 if (req
.t
.tcm_parent
) {
614 "Error: \"root\" is duplicate parent ID\n");
617 filter_parent
= req
.t
.tcm_parent
= TC_H_ROOT
;
618 } else if (strcmp(*argv
, "ingress") == 0) {
619 if (req
.t
.tcm_parent
) {
621 "Error: \"ingress\" is duplicate parent ID\n");
624 filter_parent
= TC_H_MAKE(TC_H_CLSACT
,
626 req
.t
.tcm_parent
= filter_parent
;
627 } else if (strcmp(*argv
, "egress") == 0) {
628 if (req
.t
.tcm_parent
) {
630 "Error: \"egress\" is duplicate parent ID\n");
633 filter_parent
= TC_H_MAKE(TC_H_CLSACT
,
635 req
.t
.tcm_parent
= filter_parent
;
636 } else if (strcmp(*argv
, "parent") == 0) {
640 if (req
.t
.tcm_parent
)
641 duparg("parent", *argv
);
642 if (get_tc_classid(&handle
, *argv
))
643 invarg("invalid parent ID", *argv
);
644 filter_parent
= req
.t
.tcm_parent
= handle
;
645 } else if (strcmp(*argv
, "handle") == 0) {
648 duparg("handle", *argv
);
650 } else if (matches(*argv
, "preference") == 0 ||
651 matches(*argv
, "priority") == 0) {
654 duparg("priority", *argv
);
655 if (get_u32(&prio
, *argv
, 0))
656 invarg("invalid preference", *argv
);
658 } else if (matches(*argv
, "protocol") == 0) {
663 duparg("protocol", *argv
);
664 if (ll_proto_a2n(&res
, *argv
))
665 invarg("invalid protocol", *argv
);
667 filter_protocol
= protocol
;
668 } else if (matches(*argv
, "chain") == 0) {
670 if (filter_chain_index_set
)
671 duparg("chain", *argv
);
672 if (get_u32(&chain_index
, *argv
, 0))
673 invarg("invalid chain index value", *argv
);
674 filter_chain_index_set
= 1;
675 filter_chain_index
= chain_index
;
676 } else if (matches(*argv
, "help") == 0) {
680 " What is \"%s\"? Try \"tc filter help\"\n",
688 req
.t
.tcm_info
= TC_H_MAKE(prio
<<16, protocol
);
693 req
.t
.tcm_ifindex
= ll_name_to_index(d
);
694 if (!req
.t
.tcm_ifindex
)
696 filter_ifindex
= req
.t
.tcm_ifindex
;
697 } else if (block_index
) {
698 if (!tc_qdisc_block_exists(block_index
)) {
699 fprintf(stderr
, "Cannot find block \"%u\"\n", block_index
);
702 req
.t
.tcm_ifindex
= TCM_IFINDEX_MAGIC_BLOCK
;
703 req
.t
.tcm_block_index
= block_index
;
704 filter_block_index
= block_index
;
707 if (filter_chain_index_set
)
708 addattr32(&req
.n
, sizeof(req
), TCA_CHAIN
, chain_index
);
710 if (rtnl_dump_request_n(&rth
, &req
.n
) < 0) {
711 perror("Cannot send dump request");
716 if (rtnl_dump_filter(&rth
, print_filter
, stdout
) < 0) {
717 fprintf(stderr
, "Dump terminated\n");
725 int do_filter(int argc
, char **argv
, void *buf
, size_t buflen
)
728 return tc_filter_list(0, NULL
);
729 if (matches(*argv
, "add") == 0)
730 return tc_filter_modify(RTM_NEWTFILTER
, NLM_F_EXCL
|NLM_F_CREATE
,
731 argc
-1, argv
+1, buf
, buflen
);
732 if (matches(*argv
, "change") == 0)
733 return tc_filter_modify(RTM_NEWTFILTER
, 0, argc
-1, argv
+1,
735 if (matches(*argv
, "replace") == 0)
736 return tc_filter_modify(RTM_NEWTFILTER
, NLM_F_CREATE
, argc
-1,
737 argv
+1, buf
, buflen
);
738 if (matches(*argv
, "delete") == 0)
739 return tc_filter_modify(RTM_DELTFILTER
, 0, argc
-1, argv
+1,
741 if (matches(*argv
, "get") == 0)
742 return tc_filter_get(RTM_GETTFILTER
, 0, argc
-1, argv
+1);
743 if (matches(*argv
, "list") == 0 || matches(*argv
, "show") == 0
744 || matches(*argv
, "lst") == 0)
745 return tc_filter_list(argc
-1, argv
+1);
746 if (matches(*argv
, "help") == 0) {
750 fprintf(stderr
, "Command \"%s\" is unknown, try \"tc filter help\".\n",