]>
git.proxmox.com Git - mirror_iproute2.git/blob - tc/tc_filter.c
2 * tc_filter.c "tc filter".
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version
7 * 2 of the License, or (at your option) any later version.
9 * Authors: Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
18 #include <sys/socket.h>
19 #include <netinet/in.h>
20 #include <arpa/inet.h>
22 #include <linux/if_ether.h>
27 #include "tc_common.h"
29 static void usage(void)
32 "Usage: tc filter [ add | del | change | replace | show ] dev STRING\n"
33 "Usage: tc filter get dev STRING parent CLASSID protocol PROTO handle FILTERID pref PRIO FILTER_TYPE\n"
34 " [ pref PRIO ] protocol PROTO [ chain CHAIN_INDEX ]\n"
35 " [ estimator INTERVAL TIME_CONSTANT ]\n"
36 " [ root | ingress | egress | parent CLASSID ]\n"
37 " [ handle FILTERID ] [ [ FILTER_TYPE ] [ help | OPTIONS ] ]\n"
39 " tc filter show [ dev STRING ] [ root | ingress | egress | parent CLASSID ]\n"
41 "FILTER_TYPE := { rsvp | u32 | bpf | fw | route | etc. }\n"
42 "FILTERID := ... format depends on classifier, see there\n"
43 "OPTIONS := ... try tc filter add <desired FILTER_KIND> help\n");
46 static int tc_filter_modify(int cmd
, unsigned int flags
, int argc
, char **argv
)
53 .n
.nlmsg_len
= NLMSG_LENGTH(sizeof(struct tcmsg
)),
54 .n
.nlmsg_flags
= NLM_F_REQUEST
| flags
,
56 .t
.tcm_family
= AF_UNSPEC
,
58 struct filter_util
*q
= NULL
;
63 int chain_index_set
= 0;
67 struct tc_estimator est
= {};
69 if (cmd
== RTM_NEWTFILTER
&& flags
& NLM_F_CREATE
)
70 protocol
= htons(ETH_P_ALL
);
73 if (strcmp(*argv
, "dev") == 0) {
77 strncpy(d
, *argv
, sizeof(d
)-1);
78 } else if (strcmp(*argv
, "root") == 0) {
79 if (req
.t
.tcm_parent
) {
81 "Error: \"root\" is duplicate parent ID\n");
84 req
.t
.tcm_parent
= TC_H_ROOT
;
85 } else if (strcmp(*argv
, "ingress") == 0) {
86 if (req
.t
.tcm_parent
) {
88 "Error: \"ingress\" is duplicate parent ID\n");
91 req
.t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
93 } else if (strcmp(*argv
, "egress") == 0) {
94 if (req
.t
.tcm_parent
) {
96 "Error: \"egress\" is duplicate parent ID\n");
99 req
.t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
101 } else if (strcmp(*argv
, "parent") == 0) {
105 if (req
.t
.tcm_parent
)
106 duparg("parent", *argv
);
107 if (get_tc_classid(&handle
, *argv
))
108 invarg("Invalid parent ID", *argv
);
109 req
.t
.tcm_parent
= handle
;
110 } else if (strcmp(*argv
, "handle") == 0) {
113 duparg("handle", *argv
);
115 } else if (matches(*argv
, "preference") == 0 ||
116 matches(*argv
, "priority") == 0) {
119 duparg("priority", *argv
);
120 if (get_u32(&prio
, *argv
, 0) || prio
> 0xFFFF)
121 invarg("invalid priority value", *argv
);
122 } else if (matches(*argv
, "protocol") == 0) {
127 duparg("protocol", *argv
);
128 if (ll_proto_a2n(&id
, *argv
))
129 invarg("invalid protocol", *argv
);
132 } else if (matches(*argv
, "chain") == 0) {
135 duparg("chain", *argv
);
136 if (get_u32(&chain_index
, *argv
, 0))
137 invarg("invalid chain index value", *argv
);
139 } else if (matches(*argv
, "estimator") == 0) {
140 if (parse_estimator(&argc
, &argv
, &est
) < 0)
142 } else if (matches(*argv
, "help") == 0) {
146 strncpy(k
, *argv
, sizeof(k
)-1);
148 q
= get_filter_kind(k
);
156 req
.t
.tcm_info
= TC_H_MAKE(prio
<<16, protocol
);
159 addattr32(&req
.n
, sizeof(req
), TCA_CHAIN
, chain_index
);
162 addattr_l(&req
.n
, sizeof(req
), TCA_KIND
, k
, strlen(k
)+1);
165 if (q
->parse_fopt(q
, fhandle
, argc
, argv
, &req
.n
))
170 "Must specify filter type when using \"handle\"\n");
174 if (matches(*argv
, "help") == 0)
177 "Garbage instead of arguments \"%s ...\". Try \"tc filter help\".\n",
184 addattr_l(&req
.n
, sizeof(req
), TCA_RATE
, &est
, sizeof(est
));
190 req
.t
.tcm_ifindex
= ll_name_to_index(d
);
191 if (req
.t
.tcm_ifindex
== 0) {
192 fprintf(stderr
, "Cannot find device \"%s\"\n", d
);
197 if (rtnl_talk(&rth
, &req
.n
, NULL
, 0) < 0) {
198 fprintf(stderr
, "We have an error talking to the kernel\n");
205 static __u32 filter_parent
;
206 static int filter_ifindex
;
207 static __u32 filter_prio
;
208 static __u32 filter_protocol
;
209 static __u32 filter_chain_index
;
210 static int filter_chain_index_set
;
213 int print_filter(const struct sockaddr_nl
*who
, struct nlmsghdr
*n
, void *arg
)
215 FILE *fp
= (FILE *)arg
;
216 struct tcmsg
*t
= NLMSG_DATA(n
);
217 int len
= n
->nlmsg_len
;
218 struct rtattr
*tb
[TCA_MAX
+1];
219 struct filter_util
*q
;
222 if (n
->nlmsg_type
!= RTM_NEWTFILTER
&&
223 n
->nlmsg_type
!= RTM_GETTFILTER
&&
224 n
->nlmsg_type
!= RTM_DELTFILTER
) {
225 fprintf(stderr
, "Not a filter(cmd %d)\n", n
->nlmsg_type
);
228 len
-= NLMSG_LENGTH(sizeof(*t
));
230 fprintf(stderr
, "Wrong len %d\n", len
);
234 parse_rtattr(tb
, TCA_MAX
, TCA_RTA(t
), len
);
236 if (tb
[TCA_KIND
] == NULL
) {
237 fprintf(stderr
, "print_filter: NULL kind\n");
241 if (n
->nlmsg_type
== RTM_DELTFILTER
)
242 fprintf(fp
, "deleted ");
244 if (n
->nlmsg_type
== RTM_NEWTFILTER
&&
245 (n
->nlmsg_flags
& NLM_F_CREATE
) &&
246 !(n
->nlmsg_flags
& NLM_F_EXCL
))
247 fprintf(fp
, "replaced ");
249 if (n
->nlmsg_type
== RTM_NEWTFILTER
&&
250 (n
->nlmsg_flags
& NLM_F_CREATE
) &&
251 (n
->nlmsg_flags
& NLM_F_EXCL
))
252 fprintf(fp
, "added ");
254 fprintf(fp
, "filter ");
255 if (!filter_ifindex
|| filter_ifindex
!= t
->tcm_ifindex
)
256 fprintf(fp
, "dev %s ", ll_index_to_name(t
->tcm_ifindex
));
258 if (!filter_parent
|| filter_parent
!= t
->tcm_parent
) {
259 if (t
->tcm_parent
== TC_H_ROOT
)
260 fprintf(fp
, "root ");
261 else if (t
->tcm_parent
== TC_H_MAKE(TC_H_CLSACT
, TC_H_MIN_INGRESS
))
262 fprintf(fp
, "ingress ");
263 else if (t
->tcm_parent
== TC_H_MAKE(TC_H_CLSACT
, TC_H_MIN_EGRESS
))
264 fprintf(fp
, "egress ");
266 print_tc_classid(abuf
, sizeof(abuf
), t
->tcm_parent
);
267 fprintf(fp
, "parent %s ", abuf
);
272 f_proto
= TC_H_MIN(t
->tcm_info
);
273 __u32 prio
= TC_H_MAJ(t
->tcm_info
)>>16;
275 if (!filter_protocol
|| filter_protocol
!= f_proto
) {
278 fprintf(fp
, "protocol %s ",
279 ll_proto_n2a(f_proto
, b1
, sizeof(b1
)));
282 if (!filter_prio
|| filter_prio
!= prio
) {
284 fprintf(fp
, "pref %u ", prio
);
287 fprintf(fp
, "%s ", rta_getattr_str(tb
[TCA_KIND
]));
290 __u32 chain_index
= rta_getattr_u32(tb
[TCA_CHAIN
]);
292 if (!filter_chain_index_set
||
293 filter_chain_index
!= chain_index
)
294 fprintf(fp
, "chain %u ", chain_index
);
297 q
= get_filter_kind(RTA_DATA(tb
[TCA_KIND
]));
298 if (tb
[TCA_OPTIONS
]) {
300 q
->print_fopt(q
, fp
, tb
[TCA_OPTIONS
], t
->tcm_handle
);
302 fprintf(fp
, "[cannot parse parameters]");
306 if (show_stats
&& (tb
[TCA_STATS
] || tb
[TCA_STATS2
])) {
307 print_tcstats_attr(fp
, tb
, " ", NULL
);
315 static int tc_filter_get(int cmd
, unsigned int flags
, int argc
, char **argv
)
322 .n
.nlmsg_len
= NLMSG_LENGTH(sizeof(struct tcmsg
)),
323 /* NLM_F_ECHO is for backward compatibility. old kernels never
324 * respond without it and newer kernels will ignore it.
325 * In old kernels there is a side effect:
326 * In addition to a response to the GET you will receive an
327 * event (if you do tc mon).
329 .n
.nlmsg_flags
= NLM_F_REQUEST
| NLM_F_ECHO
| flags
,
331 .t
.tcm_parent
= TC_H_UNSPEC
,
332 .t
.tcm_family
= AF_UNSPEC
,
334 struct filter_util
*q
= NULL
;
337 int protocol_set
= 0;
339 int chain_index_set
= 0;
340 __u32 parent_handle
= 0;
341 char *fhandle
= NULL
;
346 if (strcmp(*argv
, "dev") == 0) {
349 duparg("dev", *argv
);
350 strncpy(d
, *argv
, sizeof(d
)-1);
351 } else if (strcmp(*argv
, "root") == 0) {
352 if (req
.t
.tcm_parent
) {
354 "Error: \"root\" is duplicate parent ID\n");
357 req
.t
.tcm_parent
= TC_H_ROOT
;
358 } else if (strcmp(*argv
, "ingress") == 0) {
359 if (req
.t
.tcm_parent
) {
361 "Error: \"ingress\" is duplicate parent ID\n");
364 req
.t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
366 } else if (strcmp(*argv
, "egress") == 0) {
367 if (req
.t
.tcm_parent
) {
369 "Error: \"egress\" is duplicate parent ID\n");
372 req
.t
.tcm_parent
= TC_H_MAKE(TC_H_CLSACT
,
374 } else if (strcmp(*argv
, "parent") == 0) {
377 if (req
.t
.tcm_parent
)
378 duparg("parent", *argv
);
379 if (get_tc_classid(&parent_handle
, *argv
))
380 invarg("Invalid parent ID", *argv
);
381 req
.t
.tcm_parent
= parent_handle
;
382 } else if (strcmp(*argv
, "handle") == 0) {
385 duparg("handle", *argv
);
387 } else if (matches(*argv
, "preference") == 0 ||
388 matches(*argv
, "priority") == 0) {
391 duparg("priority", *argv
);
392 if (get_u32(&prio
, *argv
, 0) || prio
> 0xFFFF)
393 invarg("invalid priority value", *argv
);
394 } else if (matches(*argv
, "protocol") == 0) {
399 duparg("protocol", *argv
);
400 if (ll_proto_a2n(&id
, *argv
))
401 invarg("invalid protocol", *argv
);
404 } else if (matches(*argv
, "chain") == 0) {
407 duparg("chain", *argv
);
408 if (get_u32(&chain_index
, *argv
, 0))
409 invarg("invalid chain index value", *argv
);
411 } else if (matches(*argv
, "help") == 0) {
415 strncpy(k
, *argv
, sizeof(k
)-1);
417 q
= get_filter_kind(k
);
426 fprintf(stderr
, "Must specify filter protocol\n");
431 fprintf(stderr
, "Must specify filter priority\n");
435 req
.t
.tcm_info
= TC_H_MAKE(prio
<<16, protocol
);
438 addattr32(&req
.n
, sizeof(req
), TCA_CHAIN
, chain_index
);
440 if (req
.t
.tcm_parent
== TC_H_UNSPEC
) {
441 fprintf(stderr
, "Must specify filter parent\n");
446 addattr_l(&req
.n
, sizeof(req
), TCA_KIND
, k
, strlen(k
)+1);
448 fprintf(stderr
, "Must specify filter type\n");
452 if (q
->parse_fopt(q
, fhandle
, argc
, argv
, &req
.n
))
457 fprintf(stderr
, "Must specify filter \"handle\"\n");
462 if (matches(*argv
, "help") == 0)
465 "Garbage instead of arguments \"%s ...\". Try \"tc filter help\".\n",
473 req
.t
.tcm_ifindex
= ll_name_to_index(d
);
474 if (req
.t
.tcm_ifindex
== 0) {
475 fprintf(stderr
, "Cannot find device \"%s\"\n", d
);
478 filter_ifindex
= req
.t
.tcm_ifindex
;
480 fprintf(stderr
, "Must specify netdevice \"dev\"\n");
484 if (rtnl_talk(&rth
, &req
.n
, &req
.n
, MAX_MSG
) < 0) {
485 fprintf(stderr
, "We have an error talking to the kernel\n");
489 print_filter(NULL
, &req
.n
, (void *)stdout
);
494 static int tc_filter_list(int argc
, char **argv
)
501 .n
.nlmsg_len
= NLMSG_LENGTH(sizeof(struct tcmsg
)),
502 .n
.nlmsg_type
= RTM_GETTFILTER
,
503 .t
.tcm_parent
= TC_H_UNSPEC
,
504 .t
.tcm_family
= AF_UNSPEC
,
510 char *fhandle
= NULL
;
513 if (strcmp(*argv
, "dev") == 0) {
516 duparg("dev", *argv
);
517 strncpy(d
, *argv
, sizeof(d
)-1);
518 } else if (strcmp(*argv
, "root") == 0) {
519 if (req
.t
.tcm_parent
) {
521 "Error: \"root\" is duplicate parent ID\n");
524 filter_parent
= req
.t
.tcm_parent
= TC_H_ROOT
;
525 } else if (strcmp(*argv
, "ingress") == 0) {
526 if (req
.t
.tcm_parent
) {
528 "Error: \"ingress\" is duplicate parent ID\n");
531 filter_parent
= TC_H_MAKE(TC_H_CLSACT
,
533 req
.t
.tcm_parent
= filter_parent
;
534 } else if (strcmp(*argv
, "egress") == 0) {
535 if (req
.t
.tcm_parent
) {
537 "Error: \"egress\" is duplicate parent ID\n");
540 filter_parent
= TC_H_MAKE(TC_H_CLSACT
,
542 req
.t
.tcm_parent
= filter_parent
;
543 } else if (strcmp(*argv
, "parent") == 0) {
547 if (req
.t
.tcm_parent
)
548 duparg("parent", *argv
);
549 if (get_tc_classid(&handle
, *argv
))
550 invarg("invalid parent ID", *argv
);
551 filter_parent
= req
.t
.tcm_parent
= handle
;
552 } else if (strcmp(*argv
, "handle") == 0) {
555 duparg("handle", *argv
);
557 } else if (matches(*argv
, "preference") == 0 ||
558 matches(*argv
, "priority") == 0) {
561 duparg("priority", *argv
);
562 if (get_u32(&prio
, *argv
, 0))
563 invarg("invalid preference", *argv
);
565 } else if (matches(*argv
, "protocol") == 0) {
570 duparg("protocol", *argv
);
571 if (ll_proto_a2n(&res
, *argv
))
572 invarg("invalid protocol", *argv
);
574 filter_protocol
= protocol
;
575 } else if (matches(*argv
, "chain") == 0) {
577 if (filter_chain_index_set
)
578 duparg("chain", *argv
);
579 if (get_u32(&chain_index
, *argv
, 0))
580 invarg("invalid chain index value", *argv
);
581 filter_chain_index_set
= 1;
582 filter_chain_index
= chain_index
;
583 } else if (matches(*argv
, "help") == 0) {
587 " What is \"%s\"? Try \"tc filter help\"\n",
595 req
.t
.tcm_info
= TC_H_MAKE(prio
<<16, protocol
);
600 req
.t
.tcm_ifindex
= ll_name_to_index(d
);
601 if (req
.t
.tcm_ifindex
== 0) {
602 fprintf(stderr
, "Cannot find device \"%s\"\n", d
);
605 filter_ifindex
= req
.t
.tcm_ifindex
;
608 if (filter_chain_index_set
)
609 addattr32(&req
.n
, sizeof(req
), TCA_CHAIN
, chain_index
);
611 if (rtnl_dump_request_n(&rth
, &req
.n
) < 0) {
612 perror("Cannot send dump request");
616 if (rtnl_dump_filter(&rth
, print_filter
, stdout
) < 0) {
617 fprintf(stderr
, "Dump terminated\n");
624 int do_filter(int argc
, char **argv
)
627 return tc_filter_list(0, NULL
);
628 if (matches(*argv
, "add") == 0)
629 return tc_filter_modify(RTM_NEWTFILTER
, NLM_F_EXCL
|NLM_F_CREATE
,
631 if (matches(*argv
, "change") == 0)
632 return tc_filter_modify(RTM_NEWTFILTER
, 0, argc
-1, argv
+1);
633 if (matches(*argv
, "replace") == 0)
634 return tc_filter_modify(RTM_NEWTFILTER
, NLM_F_CREATE
, argc
-1,
636 if (matches(*argv
, "delete") == 0)
637 return tc_filter_modify(RTM_DELTFILTER
, 0, argc
-1, argv
+1);
638 if (matches(*argv
, "get") == 0)
639 return tc_filter_get(RTM_GETTFILTER
, 0, argc
-1, argv
+1);
640 if (matches(*argv
, "list") == 0 || matches(*argv
, "show") == 0
641 || matches(*argv
, "lst") == 0)
642 return tc_filter_list(argc
-1, argv
+1);
643 if (matches(*argv
, "help") == 0) {
647 fprintf(stderr
, "Command \"%s\" is unknown, try \"tc filter help\".\n",