From 9f50db220a4c2ff39a44b1789d4feedff919cfbb Mon Sep 17 00:00:00 2001 From: maosiping Date: Thu, 20 Apr 2023 20:37:22 +0800 Subject: [PATCH] update to 1.8.7-5.oe2203 Signed-off-by: maosiping Signed-off-by: liyufan Signed-off-by: maosiping --- .gitignore | 1 + BUILD.gn | 3 + COMMIT_NOTES | 19 - INCOMPATIBILITIES | 14 - INSTALL | 101 - Makefile.am | 33 - OAT.xml | 10 + autogen.sh | 4 - bugfix-add-check-fw-in-entry.patch | 135 + config.h | 101 - configure.ac | 274 -- etc/ethertypes | 39 - etc/xtables.conf | 74 - extensions/.gitignore | 9 - extensions/BUILD.gn | 254 -- extensions/GNUmakefile.in | 307 -- extensions/dscp_helper.c | 79 - extensions/genInit.py | 118 - extensions/generic.txlate | 36 - extensions/iptables.t | 6 - extensions/libarpt_CLASSIFY.t | 4 - extensions/libarpt_MARK.t | 4 - extensions/libarpt_mangle.c | 193 - extensions/libarpt_mangle.t | 5 - extensions/libarpt_standard.t | 14 - extensions/libebt_802_3.c | 133 - extensions/libebt_802_3.t | 3 - extensions/libebt_among.c | 243 -- extensions/libebt_among.t | 16 - extensions/libebt_arp.c | 363 -- extensions/libebt_arp.t | 12 - extensions/libebt_arpreply.c | 101 - extensions/libebt_arpreply.t | 4 - extensions/libebt_dnat.c | 129 - extensions/libebt_dnat.t | 5 - extensions/libebt_dnat.txlate | 8 - extensions/libebt_ip.c | 732 ---- extensions/libebt_ip.t | 13 - extensions/libebt_ip.txlate | 26 - extensions/libebt_ip6.c | 632 --- extensions/libebt_ip6.t | 15 - extensions/libebt_ip6.txlate | 29 - extensions/libebt_limit.txlate | 8 - extensions/libebt_log.c | 217 - extensions/libebt_log.t | 6 - extensions/libebt_log.txlate | 15 - extensions/libebt_mark.c | 228 -- extensions/libebt_mark.t | 5 - extensions/libebt_mark.xlate | 11 - extensions/libebt_mark_m.c | 143 - extensions/libebt_mark_m.t | 6 - extensions/libebt_mark_m.txlate | 14 - extensions/libebt_nflog.c | 168 - extensions/libebt_nflog.t | 5 - extensions/libebt_nflog.txlate | 11 - extensions/libebt_pkttype.c | 119 - extensions/libebt_pkttype.t | 14 - extensions/libebt_pkttype.txlate | 20 - extensions/libebt_redirect.c | 109 - extensions/libebt_redirect.t | 4 - extensions/libebt_snat.c | 146 - extensions/libebt_snat.t | 4 - extensions/libebt_snat.txlate | 5 - extensions/libebt_standard.t | 28 - extensions/libebt_stp.c | 318 -- extensions/libebt_stp.t | 13 - extensions/libebt_vlan.c | 156 - extensions/libebt_vlan.t | 13 - extensions/libebt_vlan.txlate | 11 - extensions/libip6t_DNAT.c | 411 -- extensions/libip6t_DNAT.t | 16 - extensions/libip6t_DNAT.txlate | 11 - extensions/libip6t_DNPT.c | 94 - extensions/libip6t_DNPT.man | 30 - extensions/libip6t_DNPT.t | 7 - extensions/libip6t_HL.c | 127 - extensions/libip6t_HL.man | 17 - extensions/libip6t_HL.t | 10 - extensions/libip6t_LOG.c | 250 -- extensions/libip6t_LOG.t | 12 - extensions/libip6t_LOG.txlate | 8 - extensions/libip6t_MASQUERADE.c | 188 - extensions/libip6t_MASQUERADE.t | 9 - extensions/libip6t_MASQUERADE.txlate | 8 - extensions/libip6t_NETMAP.c | 100 - extensions/libip6t_NETMAP.t | 4 - extensions/libip6t_REDIRECT.c | 170 - extensions/libip6t_REDIRECT.t | 6 - extensions/libip6t_REDIRECT.txlate | 5 - extensions/libip6t_REJECT.c | 185 - extensions/libip6t_REJECT.man | 52 - extensions/libip6t_REJECT.t | 11 - extensions/libip6t_REJECT.txlate | 8 - extensions/libip6t_SNAT.c | 317 -- extensions/libip6t_SNAT.t | 11 - extensions/libip6t_SNAT.txlate | 11 - extensions/libip6t_SNPT.c | 94 - extensions/libip6t_SNPT.man | 30 - extensions/libip6t_SNPT.t | 7 - extensions/libip6t_ah.c | 185 - extensions/libip6t_ah.man | 10 - extensions/libip6t_ah.t | 15 - extensions/libip6t_ah.txlate | 17 - extensions/libip6t_dst.c | 196 - extensions/libip6t_dst.man | 7 - extensions/libip6t_dst.t | 5 - extensions/libip6t_eui64.c | 15 - extensions/libip6t_eui64.man | 10 - extensions/libip6t_eui64.t | 8 - extensions/libip6t_frag.c | 234 -- extensions/libip6t_frag.man | 20 - extensions/libip6t_frag.t | 13 - extensions/libip6t_frag.txlate | 17 - extensions/libip6t_hbh.c | 200 - extensions/libip6t_hbh.man | 7 - extensions/libip6t_hbh.t | 5 - extensions/libip6t_hbh.txlate | 5 - extensions/libip6t_hl.c | 137 - extensions/libip6t_hl.man | 10 - extensions/libip6t_hl.t | 8 - extensions/libip6t_hl.txlate | 5 - extensions/libip6t_icmp6.c | 282 -- extensions/libip6t_icmp6.man | 14 - extensions/libip6t_icmp6.t | 6 - extensions/libip6t_icmp6.txlate | 8 - extensions/libip6t_ipv6header.c | 245 -- extensions/libip6t_ipv6header.man | 37 - extensions/libip6t_ipv6header.t | 4 - extensions/libip6t_mh.c | 249 -- extensions/libip6t_mh.man | 12 - extensions/libip6t_mh.t | 6 - extensions/libip6t_mh.txlate | 5 - extensions/libip6t_rt.c | 304 -- extensions/libip6t_rt.man | 19 - extensions/libip6t_rt.t | 5 - extensions/libip6t_rt.txlate | 14 - extensions/libip6t_srh.c | 501 --- extensions/libip6t_srh.t | 28 - extensions/libip6t_standard.t | 5 - extensions/libipt_CLUSTERIP.c | 195 - extensions/libipt_CLUSTERIP.man | 27 - extensions/libipt_CLUSTERIP.t | 4 - extensions/libipt_DNAT.c | 555 --- extensions/libipt_DNAT.t | 16 - extensions/libipt_DNAT.txlate | 14 - extensions/libipt_ECN.c | 145 - extensions/libipt_ECN.man | 7 - extensions/libipt_ECN.t | 5 - extensions/libipt_LOG.c | 250 -- extensions/libipt_LOG.t | 12 - extensions/libipt_LOG.txlate | 5 - extensions/libipt_MASQUERADE.c | 190 - extensions/libipt_MASQUERADE.t | 9 - extensions/libipt_MASQUERADE.txlate | 8 - extensions/libipt_NETMAP.c | 113 - extensions/libipt_NETMAP.t | 4 - extensions/libipt_REDIRECT.c | 174 - extensions/libipt_REDIRECT.t | 6 - extensions/libipt_REDIRECT.txlate | 5 - extensions/libipt_REJECT.c | 203 - extensions/libipt_REJECT.man | 52 - extensions/libipt_REJECT.t | 9 - extensions/libipt_REJECT.txlate | 8 - extensions/libipt_SNAT.c | 325 -- extensions/libipt_SNAT.t | 11 - extensions/libipt_SNAT.txlate | 14 - extensions/libipt_TTL.c | 126 - extensions/libipt_TTL.man | 19 - extensions/libipt_TTL.t | 10 - extensions/libipt_ULOG.c | 129 - extensions/libipt_ULOG.man | 28 - extensions/libipt_ah.c | 132 - extensions/libipt_ah.man | 3 - extensions/libipt_ah.t | 13 - extensions/libipt_ah.txlate | 8 - extensions/libipt_icmp.c | 286 -- extensions/libipt_icmp.man | 9 - extensions/libipt_icmp.t | 15 - extensions/libipt_icmp.txlate | 11 - extensions/libipt_realm.c | 131 - extensions/libipt_realm.man | 9 - extensions/libipt_realm.t | 4 - extensions/libipt_realm.txlate | 11 - extensions/libipt_ttl.c | 165 - extensions/libipt_ttl.man | 10 - extensions/libipt_ttl.t | 15 - extensions/libipt_ttl.txlate | 5 - extensions/libxt_AUDIT.c | 112 - extensions/libxt_AUDIT.man | 16 - extensions/libxt_AUDIT.t | 6 - extensions/libxt_AUDIT.txlate | 8 - extensions/libxt_CHECKSUM.c | 77 - extensions/libxt_CHECKSUM.man | 8 - extensions/libxt_CHECKSUM.t | 4 - extensions/libxt_CLASSIFY.c | 151 - extensions/libxt_CLASSIFY.man | 5 - extensions/libxt_CLASSIFY.t | 9 - extensions/libxt_CLASSIFY.txlate | 8 - extensions/libxt_CONNMARK.c | 695 ---- extensions/libxt_CONNMARK.man | 53 - extensions/libxt_CONNMARK.t | 7 - extensions/libxt_CONNMARK.txlate | 20 - extensions/libxt_CONNSECMARK.c | 112 - extensions/libxt_CONNSECMARK.man | 18 - extensions/libxt_CONNSECMARK.t | 5 - extensions/libxt_CT.c | 449 --- extensions/libxt_CT.man | 42 - extensions/libxt_CT.t | 20 - extensions/libxt_DNAT.man | 38 - extensions/libxt_DSCP.c | 150 - extensions/libxt_DSCP.man | 9 - extensions/libxt_DSCP.t | 11 - extensions/libxt_DSCP.txlate | 5 - extensions/libxt_HMARK.c | 450 --- extensions/libxt_HMARK.man | 60 - extensions/libxt_HMARK.t | 8 - extensions/libxt_IDLETIMER.c | 162 - extensions/libxt_IDLETIMER.man | 20 - extensions/libxt_IDLETIMER.t | 5 - extensions/libxt_LED.c | 138 - extensions/libxt_LED.man | 30 - extensions/libxt_LED.t | 4 - extensions/libxt_LOG.man | 32 - extensions/libxt_MARK.c | 438 -- extensions/libxt_MARK.man | 27 - extensions/libxt_MARK.t | 7 - extensions/libxt_MARK.txlate | 26 - extensions/libxt_MASQUERADE.man | 35 - extensions/libxt_NETMAP.man | 11 - extensions/libxt_NFLOG.c | 157 - extensions/libxt_NFLOG.man | 32 - extensions/libxt_NFLOG.t | 24 - extensions/libxt_NFLOG.txlate | 14 - extensions/libxt_NFQUEUE.c | 401 -- extensions/libxt_NFQUEUE.man | 33 - extensions/libxt_NFQUEUE.t | 16 - extensions/libxt_NFQUEUE.txlate | 8 - extensions/libxt_NOTRACK.man | 3 - extensions/libxt_NOTRACK.t | 3 - extensions/libxt_NOTRACK.txlate | 2 - extensions/libxt_RATEEST.c | 187 - extensions/libxt_RATEEST.man | 12 - extensions/libxt_RATEEST.t | 2 - extensions/libxt_REDIRECT.man | 25 - extensions/libxt_SECMARK.c | 88 - extensions/libxt_SECMARK.man | 10 - extensions/libxt_SET.c | 583 --- extensions/libxt_SET.man | 46 - extensions/libxt_SET.t | 3 - extensions/libxt_SNAT.man | 50 - extensions/libxt_SYNPROXY.c | 150 - extensions/libxt_SYNPROXY.man | 66 - extensions/libxt_SYNPROXY.t | 3 - extensions/libxt_SYNPROXY.txlate | 2 - extensions/libxt_TCPMSS.c | 140 - extensions/libxt_TCPMSS.man | 41 - extensions/libxt_TCPMSS.t | 6 - extensions/libxt_TCPMSS.txlate | 5 - extensions/libxt_TCPOPTSTRIP.c | 182 - extensions/libxt_TCPOPTSTRIP.man | 7 - extensions/libxt_TCPOPTSTRIP.t | 8 - extensions/libxt_TEE.c | 163 - extensions/libxt_TEE.man | 12 - extensions/libxt_TEE.t | 4 - extensions/libxt_TEE.txlate | 11 - extensions/libxt_TOS.c | 246 -- extensions/libxt_TOS.man | 36 - extensions/libxt_TOS.t | 16 - extensions/libxt_TOS.txlate | 23 - extensions/libxt_TPROXY.c | 195 - extensions/libxt_TPROXY.man | 21 - extensions/libxt_TPROXY.t | 5 - extensions/libxt_TRACE.c | 29 - extensions/libxt_TRACE.man | 20 - extensions/libxt_TRACE.t | 3 - extensions/libxt_TRACE.txlate | 2 - extensions/libxt_addrtype.c | 372 -- extensions/libxt_addrtype.man | 69 - extensions/libxt_addrtype.t | 17 - extensions/libxt_addrtype.txlate | 11 - extensions/libxt_bpf.c | 297 -- extensions/libxt_bpf.man | 60 - extensions/libxt_bpf.t | 2 - extensions/libxt_cgroup.c | 278 -- extensions/libxt_cgroup.man | 30 - extensions/libxt_cgroup.t | 8 - extensions/libxt_cgroup.txlate | 5 - extensions/libxt_cluster.c | 197 - extensions/libxt_cluster.man | 67 - extensions/libxt_cluster.t | 10 - extensions/libxt_cluster.txlate | 26 - extensions/libxt_comment.c | 87 - extensions/libxt_comment.man | 6 - extensions/libxt_comment.t | 14 - extensions/libxt_comment.txlate | 8 - extensions/libxt_connbytes.c | 231 -- extensions/libxt_connbytes.man | 36 - extensions/libxt_connbytes.t | 21 - extensions/libxt_connbytes.txlate | 14 - extensions/libxt_connlabel.c | 193 - extensions/libxt_connlabel.man | 33 - extensions/libxt_connlabel.t | 7 - extensions/libxt_connlabel.txlate | 5 - extensions/libxt_connlimit.c | 252 -- extensions/libxt_connlimit.man | 42 - extensions/libxt_connlimit.t | 16 - extensions/libxt_connmark.c | 197 - extensions/libxt_connmark.man | 6 - extensions/libxt_connmark.t | 9 - extensions/libxt_connmark.txlate | 14 - extensions/libxt_conntrack.c | 1569 -------- extensions/libxt_conntrack.man | 86 - extensions/libxt_conntrack.t | 27 - extensions/libxt_conntrack.txlate | 51 - extensions/libxt_cpu.c | 74 - extensions/libxt_cpu.man | 15 - extensions/libxt_cpu.t | 6 - extensions/libxt_cpu.txlate | 5 - extensions/libxt_dccp.c | 402 -- extensions/libxt_dccp.man | 12 - extensions/libxt_dccp.t | 30 - extensions/libxt_dccp.txlate | 20 - extensions/libxt_devgroup.c | 185 - extensions/libxt_devgroup.man | 7 - extensions/libxt_devgroup.txlate | 17 - extensions/libxt_dscp.c | 156 - extensions/libxt_dscp.man | 10 - extensions/libxt_dscp.t | 10 - extensions/libxt_dscp.txlate | 5 - extensions/libxt_ecn.c | 182 - extensions/libxt_ecn.man | 11 - extensions/libxt_ecn.t | 5 - extensions/libxt_ecn.txlate | 29 - extensions/libxt_esp.c | 126 - extensions/libxt_esp.man | 3 - extensions/libxt_esp.t | 8 - extensions/libxt_esp.txlate | 11 - extensions/libxt_hashlimit.c | 1576 -------- extensions/libxt_hashlimit.man | 84 - extensions/libxt_hashlimit.t | 33 - extensions/libxt_hashlimit.txlate | 5 - extensions/libxt_helper.c | 79 - extensions/libxt_helper.man | 11 - extensions/libxt_helper.t | 6 - extensions/libxt_helper.txlate | 5 - extensions/libxt_icmp.h | 25 - extensions/libxt_ipcomp.c | 134 - extensions/libxt_ipcomp.c.man | 7 - extensions/libxt_ipcomp.t | 3 - extensions/libxt_ipcomp.txlate | 5 - extensions/libxt_iprange.c | 442 -- extensions/libxt_iprange.man | 7 - extensions/libxt_iprange.t | 11 - extensions/libxt_iprange.txlate | 14 - extensions/libxt_ipvs.c | 284 -- extensions/libxt_ipvs.man | 24 - extensions/libxt_ipvs.t | 20 - extensions/libxt_length.c | 91 - extensions/libxt_length.man | 5 - extensions/libxt_length.t | 10 - extensions/libxt_length.txlate | 11 - extensions/libxt_limit.c | 293 -- extensions/libxt_limit.man | 18 - extensions/libxt_limit.t | 6 - extensions/libxt_limit.txlate | 8 - extensions/libxt_mac.c | 102 - extensions/libxt_mac.man | 10 - extensions/libxt_mac.t | 5 - extensions/libxt_mac.txlate | 5 - extensions/libxt_mark.c | 174 - extensions/libxt_mark.man | 9 - extensions/libxt_mark.t | 7 - extensions/libxt_mark.txlate | 5 - extensions/libxt_multiport.c | 640 --- extensions/libxt_multiport.man | 22 - extensions/libxt_multiport.t | 23 - extensions/libxt_multiport.txlate | 11 - extensions/libxt_nfacct.c | 105 - extensions/libxt_nfacct.man | 30 - extensions/libxt_nfacct.t | 10 - extensions/libxt_osf.c | 121 - extensions/libxt_osf.man | 45 - extensions/libxt_osf.t | 4 - extensions/libxt_owner.c | 604 --- extensions/libxt_owner.man | 23 - extensions/libxt_owner.t | 16 - extensions/libxt_owner.txlate | 8 - extensions/libxt_physdev.c | 149 - extensions/libxt_physdev.man | 34 - extensions/libxt_physdev.t | 14 - extensions/libxt_pkttype.c | 171 - extensions/libxt_pkttype.man | 3 - extensions/libxt_pkttype.t | 6 - extensions/libxt_pkttype.txlate | 8 - extensions/libxt_policy.c | 438 -- extensions/libxt_policy.man | 53 - extensions/libxt_policy.t | 8 - extensions/libxt_policy.txlate | 5 - extensions/libxt_quota.c | 82 - extensions/libxt_quota.man | 7 - extensions/libxt_quota.t | 7 - extensions/libxt_quota.txlate | 5 - extensions/libxt_quota2.c | 113 - extensions/libxt_quota2.man | 38 - extensions/libxt_rateest.c | 449 --- extensions/libxt_rateest.man | 96 - extensions/libxt_rateest.t | 16 - extensions/libxt_recent.c | 355 -- extensions/libxt_recent.man | 109 - extensions/libxt_recent.t | 11 - extensions/libxt_rpfilter.c | 122 - extensions/libxt_rpfilter.man | 39 - extensions/libxt_rpfilter.t | 4 - extensions/libxt_rpfilter.txlate | 8 - extensions/libxt_sctp.c | 544 --- extensions/libxt_sctp.man | 29 - extensions/libxt_sctp.t | 29 - extensions/libxt_sctp.txlate | 38 - extensions/libxt_set.c | 749 ---- extensions/libxt_set.h | 191 - extensions/libxt_set.man | 65 - extensions/libxt_set.t | 4 - extensions/libxt_socket.c | 215 - extensions/libxt_socket.man | 36 - extensions/libxt_socket.t | 8 - extensions/libxt_standard.c | 24 - extensions/libxt_standard.t | 11 - extensions/libxt_state.man | 8 - extensions/libxt_state.t | 6 - extensions/libxt_statistic.c | 174 - extensions/libxt_statistic.man | 29 - extensions/libxt_statistic.t | 8 - extensions/libxt_statistic.txlate | 8 - extensions/libxt_string.c | 339 -- extensions/libxt_string.man | 31 - extensions/libxt_string.t | 18 - extensions/libxt_tcp.c | 467 --- extensions/libxt_tcp.man | 43 - extensions/libxt_tcp.t | 26 - extensions/libxt_tcp.txlate | 26 - extensions/libxt_tcpmss.c | 79 - extensions/libxt_tcpmss.man | 4 - extensions/libxt_tcpmss.t | 6 - extensions/libxt_time.c | 543 --- extensions/libxt_time.man | 98 - extensions/libxt_time.t | 4 - extensions/libxt_time.txlate | 26 - extensions/libxt_tos.c | 156 - extensions/libxt_tos.man | 12 - extensions/libxt_tos.t | 13 - extensions/libxt_u32.c | 279 -- extensions/libxt_u32.man | 134 - extensions/libxt_u32.t | 2 - extensions/libxt_udp.c | 212 - extensions/libxt_udp.man | 14 - extensions/libxt_udp.t | 22 - extensions/libxt_udp.txlate | 11 - extensions/tos_values.c | 41 - include/Makefile.am | 17 - include/ip6tables.h | 20 - include/iptables.h | 25 - include/iptables/internal.h | 11 - include/libipq/libipq.h | 83 - include/libiptc/ipt_kernel_headers.h | 15 - include/libiptc/libip6tc.h | 161 - include/libiptc/libiptc.h | 172 - include/libiptc/libxtc.h | 33 - include/libiptc/xtcshared.h | 25 - include/libipulog/libipulog.h | 39 - include/linux/filter.h | 139 - include/linux/kernel.h | 29 - include/linux/netfilter.h | 80 - include/linux/netfilter/ipset/ip_set.h | 284 -- include/linux/netfilter/nf_conntrack_common.h | 113 - .../netfilter/nf_conntrack_tuple_common.h | 39 - include/linux/netfilter/nf_nat.h | 52 - include/linux/netfilter/nf_tables.h | 1463 ------- include/linux/netfilter/nf_tables_compat.h | 20 - include/linux/netfilter/nfnetlink.h | 80 - include/linux/netfilter/x_tables.h | 185 - include/linux/netfilter/xt_AUDIT.h | 30 - include/linux/netfilter/xt_CHECKSUM.h | 20 - include/linux/netfilter/xt_CLASSIFY.h | 10 - include/linux/netfilter/xt_CONNMARK.h | 6 - include/linux/netfilter/xt_CONNSECMARK.h | 15 - include/linux/netfilter/xt_CT.h | 37 - include/linux/netfilter/xt_DSCP.h | 26 - include/linux/netfilter/xt_HMARK.h | 50 - include/linux/netfilter/xt_IDLETIMER.h | 57 - include/linux/netfilter/xt_LED.h | 15 - include/linux/netfilter/xt_MARK.h | 6 - include/linux/netfilter/xt_NFLOG.h | 24 - include/linux/netfilter/xt_NFQUEUE.h | 38 - include/linux/netfilter/xt_RATEEST.h | 15 - include/linux/netfilter/xt_SECMARK.h | 22 - include/linux/netfilter/xt_SYNPROXY.h | 16 - include/linux/netfilter/xt_TCPMSS.h | 12 - include/linux/netfilter/xt_TCPOPTSTRIP.h | 15 - include/linux/netfilter/xt_TEE.h | 12 - include/linux/netfilter/xt_TPROXY.h | 23 - include/linux/netfilter/xt_addrtype.h | 44 - include/linux/netfilter/xt_bpf.h | 40 - include/linux/netfilter/xt_cgroup.h | 41 - include/linux/netfilter/xt_cluster.h | 19 - include/linux/netfilter/xt_comment.h | 10 - include/linux/netfilter/xt_connbytes.h | 26 - include/linux/netfilter/xt_connlabel.h | 12 - include/linux/netfilter/xt_connlimit.h | 34 - include/linux/netfilter/xt_connmark.h | 36 - include/linux/netfilter/xt_conntrack.h | 77 - include/linux/netfilter/xt_cpu.h | 11 - include/linux/netfilter/xt_dccp.h | 25 - include/linux/netfilter/xt_devgroup.h | 21 - include/linux/netfilter/xt_dscp.h | 31 - include/linux/netfilter/xt_ecn.h | 33 - include/linux/netfilter/xt_esp.h | 15 - include/linux/netfilter/xt_hashlimit.h | 120 - include/linux/netfilter/xt_helper.h | 8 - include/linux/netfilter/xt_ipcomp.h | 16 - include/linux/netfilter/xt_iprange.h | 19 - include/linux/netfilter/xt_ipvs.h | 29 - include/linux/netfilter/xt_length.h | 11 - include/linux/netfilter/xt_limit.h | 24 - include/linux/netfilter/xt_mac.h | 8 - include/linux/netfilter/xt_mark.h | 15 - include/linux/netfilter/xt_multiport.h | 29 - include/linux/netfilter/xt_nfacct.h | 22 - include/linux/netfilter/xt_osf.h | 135 - include/linux/netfilter/xt_owner.h | 19 - include/linux/netfilter/xt_physdev.h | 23 - include/linux/netfilter/xt_pkttype.h | 8 - include/linux/netfilter/xt_policy.h | 58 - include/linux/netfilter/xt_quota.h | 22 - include/linux/netfilter/xt_quota2.h | 25 - include/linux/netfilter/xt_rateest.h | 37 - include/linux/netfilter/xt_realm.h | 12 - include/linux/netfilter/xt_recent.h | 45 - include/linux/netfilter/xt_rpfilter.h | 17 - include/linux/netfilter/xt_sctp.h | 92 - include/linux/netfilter/xt_set.h | 93 - include/linux/netfilter/xt_socket.h | 29 - include/linux/netfilter/xt_state.h | 12 - include/linux/netfilter/xt_statistic.h | 36 - include/linux/netfilter/xt_string.h | 34 - include/linux/netfilter/xt_tcpmss.h | 11 - include/linux/netfilter/xt_tcpudp.h | 36 - include/linux/netfilter/xt_time.h | 28 - include/linux/netfilter/xt_u32.h | 42 - include/linux/netfilter_arp.h | 19 - include/linux/netfilter_arp/arp_tables.h | 204 - include/linux/netfilter_arp/arpt_mangle.h | 26 - include/linux/netfilter_bridge.h | 33 - include/linux/netfilter_bridge/ebt_802_3.h | 63 - include/linux/netfilter_bridge/ebt_ip.h | 44 - include/linux/netfilter_bridge/ebt_mark_m.h | 16 - include/linux/netfilter_bridge/ebt_mark_t.h | 23 - include/linux/netfilter_ipv4.h | 75 - include/linux/netfilter_ipv4/ip_queue.h | 72 - include/linux/netfilter_ipv4/ip_tables.h | 227 -- include/linux/netfilter_ipv4/ipt_CLUSTERIP.h | 36 - include/linux/netfilter_ipv4/ipt_ECN.h | 33 - include/linux/netfilter_ipv4/ipt_LOG.h | 19 - include/linux/netfilter_ipv4/ipt_REJECT.h | 20 - include/linux/netfilter_ipv4/ipt_TTL.h | 23 - include/linux/netfilter_ipv4/ipt_ULOG.h | 49 - include/linux/netfilter_ipv4/ipt_addrtype.h | 27 - include/linux/netfilter_ipv4/ipt_ah.h | 17 - include/linux/netfilter_ipv4/ipt_realm.h | 7 - include/linux/netfilter_ipv4/ipt_ttl.h | 23 - include/linux/netfilter_ipv6.h | 73 - include/linux/netfilter_ipv6/ip6_tables.h | 268 -- include/linux/netfilter_ipv6/ip6t_HL.h | 24 - include/linux/netfilter_ipv6/ip6t_LOG.h | 19 - include/linux/netfilter_ipv6/ip6t_NPT.h | 16 - include/linux/netfilter_ipv6/ip6t_REJECT.h | 22 - include/linux/netfilter_ipv6/ip6t_ah.h | 22 - include/linux/netfilter_ipv6/ip6t_frag.h | 25 - include/linux/netfilter_ipv6/ip6t_hl.h | 24 - .../linux/netfilter_ipv6/ip6t_ipv6header.h | 28 - include/linux/netfilter_ipv6/ip6t_mh.h | 16 - include/linux/netfilter_ipv6/ip6t_opts.h | 24 - include/linux/netfilter_ipv6/ip6t_rt.h | 33 - include/linux/netfilter_ipv6/ip6t_srh.h | 95 - include/linux/types.h | 51 - include/xtables-version.h | 17 - include/xtables-version.h.in | 2 - include/xtables.h | 655 --- extensions/genClear.py => install.sh | 21 +- iptables-1.8.7.tar.bz2 | Bin 0 -> 425535 bytes iptables-config | 59 + iptables-test.py | 387 -- iptables.init | 440 ++ iptables.service | 16 + iptables.spec | 369 ++ iptables/.gitignore | 25 - iptables/Makefile.am | 140 - iptables/arptables-nft-restore.8 | 39 - iptables/arptables-nft-save.8 | 47 - iptables/arptables-nft.8 | 348 -- iptables/ebtables-nft.8 | 1116 ------ iptables/ip6tables-apply.8 | 1 - iptables/ip6tables-multi.h | 8 - iptables/ip6tables-restore.8 | 1 - iptables/ip6tables-save.8 | 1 - iptables/ip6tables-standalone.c | 83 - iptables/ip6tables.8 | 1 - iptables/ip6tables.c | 1713 -------- iptables/iptables-apply | 296 -- iptables/iptables-apply.8.in | 60 - iptables/iptables-extensions.8.tmpl.in | 28 - iptables/iptables-multi.h | 8 - iptables/iptables-restore.8.in | 94 - iptables/iptables-restore.c | 429 -- iptables/iptables-save.8.in | 69 - iptables/iptables-save.c | 286 -- iptables/iptables-standalone.c | 83 - iptables/iptables-xml.1.in | 87 - iptables/iptables-xml.c | 695 ---- iptables/iptables.8.in | 486 --- iptables/iptables.c | 1703 -------- iptables/iptables.xslt | 138 - iptables/nft-arp.c | 647 --- iptables/nft-arp.h | 14 - iptables/nft-bridge.c | 905 ----- iptables/nft-bridge.h | 181 - iptables/nft-cache.c | 772 ---- iptables/nft-cache.h | 26 - iptables/nft-chain.c | 59 - iptables/nft-chain.h | 29 - iptables/nft-cmd.c | 395 -- iptables/nft-cmd.h | 79 - iptables/nft-ipv4.c | 464 --- iptables/nft-ipv6.c | 416 -- iptables/nft-shared.c | 1016 ----- iptables/nft-shared.h | 255 -- iptables/nft.c | 3550 ----------------- iptables/nft.h | 270 -- iptables/tests/shell/README | 17 - iptables/tests/shell/run-tests.sh | 198 - .../arptables/0001-arptables-save-restore_0 | 61 - .../0002-arptables-restore-defaults_0 | 26 - .../arptables/0003-arptables-verbose-output_0 | 63 - .../shell/testcases/chain/0001duplicate_1 | 12 - .../shell/testcases/chain/0002newchain_0 | 9 - .../tests/shell/testcases/chain/0003rename_1 | 12 - .../testcases/ebtables/0001-ebtables-basic_0 | 93 - .../ebtables/0002-ebtables-save-restore_0 | 117 - .../ebtables/0003-ebtables-restore-defaults_0 | 31 - .../testcases/ebtables/0004-save-counters_0 | 64 - .../testcases/ebtables/0005-ifnamechecks_0 | 21 - .../firewalld-restore/0001-firewalld_0 | 238 -- .../0002-firewalld-restart_0 | 17 - .../dumps/ipt-save-completed.txt | 151 - .../testcases/ip6tables/0002-verbose-output_0 | 51 - .../testcases/ip6tables/0003-list-rules_0 | 64 - .../ipt-restore/0001load-specific-table_0 | 41 - .../testcases/ipt-restore/0002-parameters_0 | 21 - .../ipt-restore/0003-restore-ordering_0 | 125 - .../testcases/ipt-restore/0004-restore-race_0 | 117 - .../shell/testcases/ipt-restore/0005-ipt-6_0 | 26 - .../shell/testcases/ipt-restore/0006-ip6t-4_0 | 26 - .../ipt-restore/0007-flush-noflush_0 | 42 - .../ipt-restore/0008-restore-counters_0 | 22 - .../ipt-restore/0009-table-name-comment_0 | 30 - .../ipt-restore/0010-noflush-new-chain_0 | 11 - .../ipt-restore/0011-noflush-empty-line_0 | 16 - .../shell/testcases/ipt-restore/0012-dash-F_0 | 12 - .../testcases/ipt-restore/0013-test-mode_0 | 7 - .../ipt-restore/0014-verbose-restore_0 | 76 - .../ipt-restore/0016-concurrent-restores_0 | 67 - .../0017-pointless-compat-checks_0 | 25 - .../ipt-restore/dumps/ip6tables.dump | 30 - .../testcases/ipt-restore/dumps/iptables.dump | 30 - .../shell/testcases/ipt-save/0001load-dumps_0 | 53 - .../ipt-save/0002load-fedora27-firewalld_0 | 59 - .../testcases/ipt-save/0003save-restore_0 | 47 - .../shell/testcases/ipt-save/0005iptables_0 | 30 - .../testcases/ipt-save/0006iptables-xml_0 | 13 - .../ipt-save/dumps/fedora27-ip6tables | 125 - .../ipt-save/dumps/fedora27-iptables | 136 - .../ipt-save/dumps/fedora27-iptables.xml | 925 ----- .../ipt-save/dumps/ipt-save-filter.txt | 69 - .../testcases/ipt-save/dumps/policy-drop.txt | 8 - .../testcases/ipt-save/dumps/wireless.txt | 81 - .../testcases/iptables/0001-chain-refs_0 | 14 - .../testcases/iptables/0002-verbose-output_0 | 56 - .../testcases/iptables/0003-list-rules_0 | 64 - .../testcases/iptables/0004-return-codes_0 | 96 - .../testcases/iptables/0005-delete-rules_0 | 14 - .../testcases/iptables/0005-rule-replace_0 | 38 - .../shell/testcases/iptables/0006-46-args_0 | 88 - .../shell/testcases/nft-only/0001compat_0 | 22 - .../shell/testcases/nft-only/0002invflags_0 | 10 - .../nft-only/0003delete-with-comment_0 | 15 - .../testcases/nft-only/0006-policy-override_0 | 29 - .../nft-only/0007-mid-restore-flush_0 | 23 - .../nft-only/0008-basechain-policy_0 | 29 - .../nft-only/0009-needless-bitwise_0 | 346 -- iptables/xshared.c | 855 ---- iptables/xshared.h | 227 -- iptables/xtables-arp-standalone.c | 65 - iptables/xtables-arp.c | 971 ----- iptables/xtables-eb-standalone.c | 62 - iptables/xtables-eb-translate.c | 580 --- iptables/xtables-eb.c | 1238 ------ iptables/xtables-legacy-multi.c | 54 - iptables/xtables-legacy.8 | 78 - iptables/xtables-monitor.8.in | 93 - iptables/xtables-monitor.c | 710 ---- iptables/xtables-multi.h | 27 - iptables/xtables-nft-multi.c | 53 - iptables/xtables-nft.8 | 208 - iptables/xtables-restore.c | 477 --- iptables/xtables-save.c | 272 -- iptables/xtables-standalone.c | 97 - iptables/xtables-translate.8 | 136 - iptables/xtables-translate.c | 599 --- iptables/xtables.c | 1078 ----- iptables/xtables.pc.in | 13 - libipq/.gitignore | 1 - libipq/Makefile.am | 13 - libipq/ipq_create_handle.3 | 82 - libipq/ipq_destroy_handle.3 | 1 - libipq/ipq_errstr.3 | 64 - libipq/ipq_get_msgerr.3 | 1 - libipq/ipq_get_packet.3 | 1 - libipq/ipq_message_type.3 | 134 - libipq/ipq_perror.3 | 1 - libipq/ipq_read.3 | 104 - libipq/ipq_set_mode.3 | 105 - libipq/ipq_set_verdict.3 | 100 - libipq/libipq.3 | 277 -- libipq/libipq.c | 379 -- libipq/libipq.pc.in | 11 - libiptc/.gitignore | 1 - libiptc/BUILD.gn | 74 - libiptc/Makefile.am | 12 - libiptc/libip4tc.c | 311 -- libiptc/libip4tc.pc.in | 10 - libiptc/libip6tc.c | 260 -- libiptc/libip6tc.pc.in | 10 - libiptc/libiptc.c | 2751 ------------- libiptc/libiptc.pc.in | 10 - libiptc/linux_list.h | 723 ---- libiptc/linux_stddef.h | 39 - libxtables/BUILD.gn | 52 - libxtables/Makefile.am | 20 - libxtables/getethertype.c | 160 - libxtables/xtables.c | 2392 ----------- libxtables/xtoptions.c | 1188 ------ m4/.gitignore | 2 - sysconfig_ip6tables | 15 + sysconfig_iptables | 14 + utils/.gitignore | 4 - utils/Makefile.am | 35 - utils/nfbpf_compile.8.in | 70 - utils/nfbpf_compile.c | 55 - utils/nfnl_osf.8.in | 67 - utils/nfnl_osf.c | 492 --- utils/nfsynproxy.c | 229 -- utils/pf.os | 709 ---- xlate-test.py | 114 - 762 files changed, 1068 insertions(+), 87527 deletions(-) delete mode 100644 COMMIT_NOTES delete mode 100644 INCOMPATIBILITIES delete mode 100644 INSTALL delete mode 100644 Makefile.am delete mode 100755 autogen.sh create mode 100644 bugfix-add-check-fw-in-entry.patch delete mode 100644 config.h delete mode 100644 configure.ac delete mode 100644 etc/ethertypes delete mode 100644 etc/xtables.conf delete mode 100644 extensions/.gitignore delete mode 100644 extensions/BUILD.gn delete mode 100644 extensions/GNUmakefile.in delete mode 100644 extensions/dscp_helper.c delete mode 100755 extensions/genInit.py delete mode 100644 extensions/generic.txlate delete mode 100644 extensions/iptables.t delete mode 100644 extensions/libarpt_CLASSIFY.t delete mode 100644 extensions/libarpt_MARK.t delete mode 100644 extensions/libarpt_mangle.c delete mode 100644 extensions/libarpt_mangle.t delete mode 100644 extensions/libarpt_standard.t delete mode 100644 extensions/libebt_802_3.c delete mode 100644 extensions/libebt_802_3.t delete mode 100644 extensions/libebt_among.c delete mode 100644 extensions/libebt_among.t delete mode 100644 extensions/libebt_arp.c delete mode 100644 extensions/libebt_arp.t delete mode 100644 extensions/libebt_arpreply.c delete mode 100644 extensions/libebt_arpreply.t delete mode 100644 extensions/libebt_dnat.c delete mode 100644 extensions/libebt_dnat.t delete mode 100644 extensions/libebt_dnat.txlate delete mode 100644 extensions/libebt_ip.c delete mode 100644 extensions/libebt_ip.t delete mode 100644 extensions/libebt_ip.txlate delete mode 100644 extensions/libebt_ip6.c delete mode 100644 extensions/libebt_ip6.t delete mode 100644 extensions/libebt_ip6.txlate delete mode 100644 extensions/libebt_limit.txlate delete mode 100644 extensions/libebt_log.c delete mode 100644 extensions/libebt_log.t delete mode 100644 extensions/libebt_log.txlate delete mode 100644 extensions/libebt_mark.c delete mode 100644 extensions/libebt_mark.t delete mode 100644 extensions/libebt_mark.xlate delete mode 100644 extensions/libebt_mark_m.c delete mode 100644 extensions/libebt_mark_m.t delete mode 100644 extensions/libebt_mark_m.txlate delete mode 100644 extensions/libebt_nflog.c delete mode 100644 extensions/libebt_nflog.t delete mode 100644 extensions/libebt_nflog.txlate delete mode 100644 extensions/libebt_pkttype.c delete mode 100644 extensions/libebt_pkttype.t delete mode 100644 extensions/libebt_pkttype.txlate delete mode 100644 extensions/libebt_redirect.c delete mode 100644 extensions/libebt_redirect.t delete mode 100644 extensions/libebt_snat.c delete mode 100644 extensions/libebt_snat.t delete mode 100644 extensions/libebt_snat.txlate delete mode 100644 extensions/libebt_standard.t delete mode 100644 extensions/libebt_stp.c delete mode 100644 extensions/libebt_stp.t delete mode 100644 extensions/libebt_vlan.c delete mode 100644 extensions/libebt_vlan.t delete mode 100644 extensions/libebt_vlan.txlate delete mode 100644 extensions/libip6t_DNAT.c delete mode 100644 extensions/libip6t_DNAT.t delete mode 100644 extensions/libip6t_DNAT.txlate delete mode 100644 extensions/libip6t_DNPT.c delete mode 100644 extensions/libip6t_DNPT.man delete mode 100644 extensions/libip6t_DNPT.t delete mode 100644 extensions/libip6t_HL.c delete mode 100644 extensions/libip6t_HL.man delete mode 100644 extensions/libip6t_HL.t delete mode 100644 extensions/libip6t_LOG.c delete mode 100644 extensions/libip6t_LOG.t delete mode 100644 extensions/libip6t_LOG.txlate delete mode 100644 extensions/libip6t_MASQUERADE.c delete mode 100644 extensions/libip6t_MASQUERADE.t delete mode 100644 extensions/libip6t_MASQUERADE.txlate delete mode 100644 extensions/libip6t_NETMAP.c delete mode 100644 extensions/libip6t_NETMAP.t delete mode 100644 extensions/libip6t_REDIRECT.c delete mode 100644 extensions/libip6t_REDIRECT.t delete mode 100644 extensions/libip6t_REDIRECT.txlate delete mode 100644 extensions/libip6t_REJECT.c delete mode 100644 extensions/libip6t_REJECT.man delete mode 100644 extensions/libip6t_REJECT.t delete mode 100644 extensions/libip6t_REJECT.txlate delete mode 100644 extensions/libip6t_SNAT.c delete mode 100644 extensions/libip6t_SNAT.t delete mode 100644 extensions/libip6t_SNAT.txlate delete mode 100644 extensions/libip6t_SNPT.c delete mode 100644 extensions/libip6t_SNPT.man delete mode 100644 extensions/libip6t_SNPT.t delete mode 100644 extensions/libip6t_ah.c delete mode 100644 extensions/libip6t_ah.man delete mode 100644 extensions/libip6t_ah.t delete mode 100644 extensions/libip6t_ah.txlate delete mode 100644 extensions/libip6t_dst.c delete mode 100644 extensions/libip6t_dst.man delete mode 100644 extensions/libip6t_dst.t delete mode 100644 extensions/libip6t_eui64.c delete mode 100644 extensions/libip6t_eui64.man delete mode 100644 extensions/libip6t_eui64.t delete mode 100644 extensions/libip6t_frag.c delete mode 100644 extensions/libip6t_frag.man delete mode 100644 extensions/libip6t_frag.t delete mode 100644 extensions/libip6t_frag.txlate delete mode 100644 extensions/libip6t_hbh.c delete mode 100644 extensions/libip6t_hbh.man delete mode 100644 extensions/libip6t_hbh.t delete mode 100644 extensions/libip6t_hbh.txlate delete mode 100644 extensions/libip6t_hl.c delete mode 100644 extensions/libip6t_hl.man delete mode 100644 extensions/libip6t_hl.t delete mode 100644 extensions/libip6t_hl.txlate delete mode 100644 extensions/libip6t_icmp6.c delete mode 100644 extensions/libip6t_icmp6.man delete mode 100644 extensions/libip6t_icmp6.t delete mode 100644 extensions/libip6t_icmp6.txlate delete mode 100644 extensions/libip6t_ipv6header.c delete mode 100644 extensions/libip6t_ipv6header.man delete mode 100644 extensions/libip6t_ipv6header.t delete mode 100644 extensions/libip6t_mh.c delete mode 100644 extensions/libip6t_mh.man delete mode 100644 extensions/libip6t_mh.t delete mode 100644 extensions/libip6t_mh.txlate delete mode 100644 extensions/libip6t_rt.c delete mode 100644 extensions/libip6t_rt.man delete mode 100644 extensions/libip6t_rt.t delete mode 100644 extensions/libip6t_rt.txlate delete mode 100644 extensions/libip6t_srh.c delete mode 100644 extensions/libip6t_srh.t delete mode 100644 extensions/libip6t_standard.t delete mode 100644 extensions/libipt_CLUSTERIP.c delete mode 100644 extensions/libipt_CLUSTERIP.man delete mode 100644 extensions/libipt_CLUSTERIP.t delete mode 100644 extensions/libipt_DNAT.c delete mode 100644 extensions/libipt_DNAT.t delete mode 100644 extensions/libipt_DNAT.txlate delete mode 100644 extensions/libipt_ECN.c delete mode 100644 extensions/libipt_ECN.man delete mode 100644 extensions/libipt_ECN.t delete mode 100644 extensions/libipt_LOG.c delete mode 100644 extensions/libipt_LOG.t delete mode 100644 extensions/libipt_LOG.txlate delete mode 100644 extensions/libipt_MASQUERADE.c delete mode 100644 extensions/libipt_MASQUERADE.t delete mode 100644 extensions/libipt_MASQUERADE.txlate delete mode 100644 extensions/libipt_NETMAP.c delete mode 100644 extensions/libipt_NETMAP.t delete mode 100644 extensions/libipt_REDIRECT.c delete mode 100644 extensions/libipt_REDIRECT.t delete mode 100644 extensions/libipt_REDIRECT.txlate delete mode 100644 extensions/libipt_REJECT.c delete mode 100644 extensions/libipt_REJECT.man delete mode 100644 extensions/libipt_REJECT.t delete mode 100644 extensions/libipt_REJECT.txlate delete mode 100644 extensions/libipt_SNAT.c delete mode 100644 extensions/libipt_SNAT.t delete mode 100644 extensions/libipt_SNAT.txlate delete mode 100644 extensions/libipt_TTL.c delete mode 100644 extensions/libipt_TTL.man delete mode 100644 extensions/libipt_TTL.t delete mode 100644 extensions/libipt_ULOG.c delete mode 100644 extensions/libipt_ULOG.man delete mode 100644 extensions/libipt_ah.c delete mode 100644 extensions/libipt_ah.man delete mode 100644 extensions/libipt_ah.t delete mode 100644 extensions/libipt_ah.txlate delete mode 100644 extensions/libipt_icmp.c delete mode 100644 extensions/libipt_icmp.man delete mode 100644 extensions/libipt_icmp.t delete mode 100644 extensions/libipt_icmp.txlate delete mode 100644 extensions/libipt_realm.c delete mode 100644 extensions/libipt_realm.man delete mode 100644 extensions/libipt_realm.t delete mode 100644 extensions/libipt_realm.txlate delete mode 100644 extensions/libipt_ttl.c delete mode 100644 extensions/libipt_ttl.man delete mode 100644 extensions/libipt_ttl.t delete mode 100644 extensions/libipt_ttl.txlate delete mode 100644 extensions/libxt_AUDIT.c delete mode 100644 extensions/libxt_AUDIT.man delete mode 100644 extensions/libxt_AUDIT.t delete mode 100644 extensions/libxt_AUDIT.txlate delete mode 100644 extensions/libxt_CHECKSUM.c delete mode 100644 extensions/libxt_CHECKSUM.man delete mode 100644 extensions/libxt_CHECKSUM.t delete mode 100644 extensions/libxt_CLASSIFY.c delete mode 100644 extensions/libxt_CLASSIFY.man delete mode 100644 extensions/libxt_CLASSIFY.t delete mode 100644 extensions/libxt_CLASSIFY.txlate delete mode 100644 extensions/libxt_CONNMARK.c delete mode 100644 extensions/libxt_CONNMARK.man delete mode 100644 extensions/libxt_CONNMARK.t delete mode 100644 extensions/libxt_CONNMARK.txlate delete mode 100644 extensions/libxt_CONNSECMARK.c delete mode 100644 extensions/libxt_CONNSECMARK.man delete mode 100644 extensions/libxt_CONNSECMARK.t delete mode 100644 extensions/libxt_CT.c delete mode 100644 extensions/libxt_CT.man delete mode 100644 extensions/libxt_CT.t delete mode 100644 extensions/libxt_DNAT.man delete mode 100644 extensions/libxt_DSCP.c delete mode 100644 extensions/libxt_DSCP.man delete mode 100644 extensions/libxt_DSCP.t delete mode 100644 extensions/libxt_DSCP.txlate delete mode 100644 extensions/libxt_HMARK.c delete mode 100644 extensions/libxt_HMARK.man delete mode 100644 extensions/libxt_HMARK.t delete mode 100644 extensions/libxt_IDLETIMER.c delete mode 100644 extensions/libxt_IDLETIMER.man delete mode 100644 extensions/libxt_IDLETIMER.t delete mode 100644 extensions/libxt_LED.c delete mode 100644 extensions/libxt_LED.man delete mode 100644 extensions/libxt_LED.t delete mode 100644 extensions/libxt_LOG.man delete mode 100644 extensions/libxt_MARK.c delete mode 100644 extensions/libxt_MARK.man delete mode 100644 extensions/libxt_MARK.t delete mode 100644 extensions/libxt_MARK.txlate delete mode 100644 extensions/libxt_MASQUERADE.man delete mode 100644 extensions/libxt_NETMAP.man delete mode 100644 extensions/libxt_NFLOG.c delete mode 100644 extensions/libxt_NFLOG.man delete mode 100644 extensions/libxt_NFLOG.t delete mode 100644 extensions/libxt_NFLOG.txlate delete mode 100644 extensions/libxt_NFQUEUE.c delete mode 100644 extensions/libxt_NFQUEUE.man delete mode 100644 extensions/libxt_NFQUEUE.t delete mode 100644 extensions/libxt_NFQUEUE.txlate delete mode 100644 extensions/libxt_NOTRACK.man delete mode 100644 extensions/libxt_NOTRACK.t delete mode 100644 extensions/libxt_NOTRACK.txlate delete mode 100644 extensions/libxt_RATEEST.c delete mode 100644 extensions/libxt_RATEEST.man delete mode 100644 extensions/libxt_RATEEST.t delete mode 100644 extensions/libxt_REDIRECT.man delete mode 100644 extensions/libxt_SECMARK.c delete mode 100644 extensions/libxt_SECMARK.man delete mode 100644 extensions/libxt_SET.c delete mode 100644 extensions/libxt_SET.man delete mode 100644 extensions/libxt_SET.t delete mode 100644 extensions/libxt_SNAT.man delete mode 100644 extensions/libxt_SYNPROXY.c delete mode 100644 extensions/libxt_SYNPROXY.man delete mode 100644 extensions/libxt_SYNPROXY.t delete mode 100644 extensions/libxt_SYNPROXY.txlate delete mode 100644 extensions/libxt_TCPMSS.c delete mode 100644 extensions/libxt_TCPMSS.man delete mode 100644 extensions/libxt_TCPMSS.t delete mode 100644 extensions/libxt_TCPMSS.txlate delete mode 100644 extensions/libxt_TCPOPTSTRIP.c delete mode 100644 extensions/libxt_TCPOPTSTRIP.man delete mode 100644 extensions/libxt_TCPOPTSTRIP.t delete mode 100644 extensions/libxt_TEE.c delete mode 100644 extensions/libxt_TEE.man delete mode 100644 extensions/libxt_TEE.t delete mode 100644 extensions/libxt_TEE.txlate delete mode 100644 extensions/libxt_TOS.c delete mode 100644 extensions/libxt_TOS.man delete mode 100644 extensions/libxt_TOS.t delete mode 100644 extensions/libxt_TOS.txlate delete mode 100644 extensions/libxt_TPROXY.c delete mode 100644 extensions/libxt_TPROXY.man delete mode 100644 extensions/libxt_TPROXY.t delete mode 100644 extensions/libxt_TRACE.c delete mode 100644 extensions/libxt_TRACE.man delete mode 100644 extensions/libxt_TRACE.t delete mode 100644 extensions/libxt_TRACE.txlate delete mode 100644 extensions/libxt_addrtype.c delete mode 100644 extensions/libxt_addrtype.man delete mode 100644 extensions/libxt_addrtype.t delete mode 100644 extensions/libxt_addrtype.txlate delete mode 100644 extensions/libxt_bpf.c delete mode 100644 extensions/libxt_bpf.man delete mode 100644 extensions/libxt_bpf.t delete mode 100644 extensions/libxt_cgroup.c delete mode 100644 extensions/libxt_cgroup.man delete mode 100644 extensions/libxt_cgroup.t delete mode 100644 extensions/libxt_cgroup.txlate delete mode 100644 extensions/libxt_cluster.c delete mode 100644 extensions/libxt_cluster.man delete mode 100644 extensions/libxt_cluster.t delete mode 100644 extensions/libxt_cluster.txlate delete mode 100644 extensions/libxt_comment.c delete mode 100644 extensions/libxt_comment.man delete mode 100644 extensions/libxt_comment.t delete mode 100644 extensions/libxt_comment.txlate delete mode 100644 extensions/libxt_connbytes.c delete mode 100644 extensions/libxt_connbytes.man delete mode 100644 extensions/libxt_connbytes.t delete mode 100644 extensions/libxt_connbytes.txlate delete mode 100644 extensions/libxt_connlabel.c delete mode 100644 extensions/libxt_connlabel.man delete mode 100644 extensions/libxt_connlabel.t delete mode 100644 extensions/libxt_connlabel.txlate delete mode 100644 extensions/libxt_connlimit.c delete mode 100644 extensions/libxt_connlimit.man delete mode 100644 extensions/libxt_connlimit.t delete mode 100644 extensions/libxt_connmark.c delete mode 100644 extensions/libxt_connmark.man delete mode 100644 extensions/libxt_connmark.t delete mode 100644 extensions/libxt_connmark.txlate delete mode 100644 extensions/libxt_conntrack.c delete mode 100644 extensions/libxt_conntrack.man delete mode 100644 extensions/libxt_conntrack.t delete mode 100644 extensions/libxt_conntrack.txlate delete mode 100644 extensions/libxt_cpu.c delete mode 100644 extensions/libxt_cpu.man delete mode 100644 extensions/libxt_cpu.t delete mode 100644 extensions/libxt_cpu.txlate delete mode 100644 extensions/libxt_dccp.c delete mode 100644 extensions/libxt_dccp.man delete mode 100644 extensions/libxt_dccp.t delete mode 100644 extensions/libxt_dccp.txlate delete mode 100644 extensions/libxt_devgroup.c delete mode 100644 extensions/libxt_devgroup.man delete mode 100644 extensions/libxt_devgroup.txlate delete mode 100644 extensions/libxt_dscp.c delete mode 100644 extensions/libxt_dscp.man delete mode 100644 extensions/libxt_dscp.t delete mode 100644 extensions/libxt_dscp.txlate delete mode 100644 extensions/libxt_ecn.c delete mode 100644 extensions/libxt_ecn.man delete mode 100644 extensions/libxt_ecn.t delete mode 100644 extensions/libxt_ecn.txlate delete mode 100644 extensions/libxt_esp.c delete mode 100644 extensions/libxt_esp.man delete mode 100644 extensions/libxt_esp.t delete mode 100644 extensions/libxt_esp.txlate delete mode 100644 extensions/libxt_hashlimit.c delete mode 100644 extensions/libxt_hashlimit.man delete mode 100644 extensions/libxt_hashlimit.t delete mode 100644 extensions/libxt_hashlimit.txlate delete mode 100644 extensions/libxt_helper.c delete mode 100644 extensions/libxt_helper.man delete mode 100644 extensions/libxt_helper.t delete mode 100644 extensions/libxt_helper.txlate delete mode 100644 extensions/libxt_icmp.h delete mode 100644 extensions/libxt_ipcomp.c delete mode 100644 extensions/libxt_ipcomp.c.man delete mode 100644 extensions/libxt_ipcomp.t delete mode 100644 extensions/libxt_ipcomp.txlate delete mode 100644 extensions/libxt_iprange.c delete mode 100644 extensions/libxt_iprange.man delete mode 100644 extensions/libxt_iprange.t delete mode 100644 extensions/libxt_iprange.txlate delete mode 100644 extensions/libxt_ipvs.c delete mode 100644 extensions/libxt_ipvs.man delete mode 100644 extensions/libxt_ipvs.t delete mode 100644 extensions/libxt_length.c delete mode 100644 extensions/libxt_length.man delete mode 100644 extensions/libxt_length.t delete mode 100644 extensions/libxt_length.txlate delete mode 100644 extensions/libxt_limit.c delete mode 100644 extensions/libxt_limit.man delete mode 100644 extensions/libxt_limit.t delete mode 100644 extensions/libxt_limit.txlate delete mode 100644 extensions/libxt_mac.c delete mode 100644 extensions/libxt_mac.man delete mode 100644 extensions/libxt_mac.t delete mode 100644 extensions/libxt_mac.txlate delete mode 100644 extensions/libxt_mark.c delete mode 100644 extensions/libxt_mark.man delete mode 100644 extensions/libxt_mark.t delete mode 100644 extensions/libxt_mark.txlate delete mode 100644 extensions/libxt_multiport.c delete mode 100644 extensions/libxt_multiport.man delete mode 100644 extensions/libxt_multiport.t delete mode 100644 extensions/libxt_multiport.txlate delete mode 100644 extensions/libxt_nfacct.c delete mode 100644 extensions/libxt_nfacct.man delete mode 100644 extensions/libxt_nfacct.t delete mode 100644 extensions/libxt_osf.c delete mode 100644 extensions/libxt_osf.man delete mode 100644 extensions/libxt_osf.t delete mode 100644 extensions/libxt_owner.c delete mode 100644 extensions/libxt_owner.man delete mode 100644 extensions/libxt_owner.t delete mode 100644 extensions/libxt_owner.txlate delete mode 100644 extensions/libxt_physdev.c delete mode 100644 extensions/libxt_physdev.man delete mode 100644 extensions/libxt_physdev.t delete mode 100644 extensions/libxt_pkttype.c delete mode 100644 extensions/libxt_pkttype.man delete mode 100644 extensions/libxt_pkttype.t delete mode 100644 extensions/libxt_pkttype.txlate delete mode 100644 extensions/libxt_policy.c delete mode 100644 extensions/libxt_policy.man delete mode 100644 extensions/libxt_policy.t delete mode 100644 extensions/libxt_policy.txlate delete mode 100644 extensions/libxt_quota.c delete mode 100644 extensions/libxt_quota.man delete mode 100644 extensions/libxt_quota.t delete mode 100644 extensions/libxt_quota.txlate delete mode 100644 extensions/libxt_quota2.c delete mode 100644 extensions/libxt_quota2.man delete mode 100644 extensions/libxt_rateest.c delete mode 100644 extensions/libxt_rateest.man delete mode 100644 extensions/libxt_rateest.t delete mode 100644 extensions/libxt_recent.c delete mode 100644 extensions/libxt_recent.man delete mode 100644 extensions/libxt_recent.t delete mode 100644 extensions/libxt_rpfilter.c delete mode 100644 extensions/libxt_rpfilter.man delete mode 100644 extensions/libxt_rpfilter.t delete mode 100644 extensions/libxt_rpfilter.txlate delete mode 100644 extensions/libxt_sctp.c delete mode 100644 extensions/libxt_sctp.man delete mode 100644 extensions/libxt_sctp.t delete mode 100644 extensions/libxt_sctp.txlate delete mode 100644 extensions/libxt_set.c delete mode 100644 extensions/libxt_set.h delete mode 100644 extensions/libxt_set.man delete mode 100644 extensions/libxt_set.t delete mode 100644 extensions/libxt_socket.c delete mode 100644 extensions/libxt_socket.man delete mode 100644 extensions/libxt_socket.t delete mode 100644 extensions/libxt_standard.c delete mode 100644 extensions/libxt_standard.t delete mode 100644 extensions/libxt_state.man delete mode 100644 extensions/libxt_state.t delete mode 100644 extensions/libxt_statistic.c delete mode 100644 extensions/libxt_statistic.man delete mode 100644 extensions/libxt_statistic.t delete mode 100644 extensions/libxt_statistic.txlate delete mode 100644 extensions/libxt_string.c delete mode 100644 extensions/libxt_string.man delete mode 100644 extensions/libxt_string.t delete mode 100644 extensions/libxt_tcp.c delete mode 100644 extensions/libxt_tcp.man delete mode 100644 extensions/libxt_tcp.t delete mode 100644 extensions/libxt_tcp.txlate delete mode 100644 extensions/libxt_tcpmss.c delete mode 100644 extensions/libxt_tcpmss.man delete mode 100644 extensions/libxt_tcpmss.t delete mode 100644 extensions/libxt_time.c delete mode 100644 extensions/libxt_time.man delete mode 100644 extensions/libxt_time.t delete mode 100644 extensions/libxt_time.txlate delete mode 100644 extensions/libxt_tos.c delete mode 100644 extensions/libxt_tos.man delete mode 100644 extensions/libxt_tos.t delete mode 100644 extensions/libxt_u32.c delete mode 100644 extensions/libxt_u32.man delete mode 100644 extensions/libxt_u32.t delete mode 100644 extensions/libxt_udp.c delete mode 100644 extensions/libxt_udp.man delete mode 100644 extensions/libxt_udp.t delete mode 100644 extensions/libxt_udp.txlate delete mode 100644 extensions/tos_values.c delete mode 100644 include/Makefile.am delete mode 100644 include/ip6tables.h delete mode 100644 include/iptables.h delete mode 100644 include/iptables/internal.h delete mode 100644 include/libipq/libipq.h delete mode 100644 include/libiptc/ipt_kernel_headers.h delete mode 100644 include/libiptc/libip6tc.h delete mode 100644 include/libiptc/libiptc.h delete mode 100644 include/libiptc/libxtc.h delete mode 100644 include/libiptc/xtcshared.h delete mode 100644 include/libipulog/libipulog.h delete mode 100644 include/linux/filter.h delete mode 100644 include/linux/kernel.h delete mode 100644 include/linux/netfilter.h delete mode 100644 include/linux/netfilter/ipset/ip_set.h delete mode 100644 include/linux/netfilter/nf_conntrack_common.h delete mode 100644 include/linux/netfilter/nf_conntrack_tuple_common.h delete mode 100644 include/linux/netfilter/nf_nat.h delete mode 100644 include/linux/netfilter/nf_tables.h delete mode 100644 include/linux/netfilter/nf_tables_compat.h delete mode 100644 include/linux/netfilter/nfnetlink.h delete mode 100644 include/linux/netfilter/x_tables.h delete mode 100644 include/linux/netfilter/xt_AUDIT.h delete mode 100644 include/linux/netfilter/xt_CHECKSUM.h delete mode 100644 include/linux/netfilter/xt_CLASSIFY.h delete mode 100644 include/linux/netfilter/xt_CONNMARK.h delete mode 100644 include/linux/netfilter/xt_CONNSECMARK.h delete mode 100644 include/linux/netfilter/xt_CT.h delete mode 100644 include/linux/netfilter/xt_DSCP.h delete mode 100644 include/linux/netfilter/xt_HMARK.h delete mode 100644 include/linux/netfilter/xt_IDLETIMER.h delete mode 100644 include/linux/netfilter/xt_LED.h delete mode 100644 include/linux/netfilter/xt_MARK.h delete mode 100644 include/linux/netfilter/xt_NFLOG.h delete mode 100644 include/linux/netfilter/xt_NFQUEUE.h delete mode 100644 include/linux/netfilter/xt_RATEEST.h delete mode 100644 include/linux/netfilter/xt_SECMARK.h delete mode 100644 include/linux/netfilter/xt_SYNPROXY.h delete mode 100644 include/linux/netfilter/xt_TCPMSS.h delete mode 100644 include/linux/netfilter/xt_TCPOPTSTRIP.h delete mode 100644 include/linux/netfilter/xt_TEE.h delete mode 100644 include/linux/netfilter/xt_TPROXY.h delete mode 100644 include/linux/netfilter/xt_addrtype.h delete mode 100644 include/linux/netfilter/xt_bpf.h delete mode 100644 include/linux/netfilter/xt_cgroup.h delete mode 100644 include/linux/netfilter/xt_cluster.h delete mode 100644 include/linux/netfilter/xt_comment.h delete mode 100644 include/linux/netfilter/xt_connbytes.h delete mode 100644 include/linux/netfilter/xt_connlabel.h delete mode 100644 include/linux/netfilter/xt_connlimit.h delete mode 100644 include/linux/netfilter/xt_connmark.h delete mode 100644 include/linux/netfilter/xt_conntrack.h delete mode 100644 include/linux/netfilter/xt_cpu.h delete mode 100644 include/linux/netfilter/xt_dccp.h delete mode 100644 include/linux/netfilter/xt_devgroup.h delete mode 100644 include/linux/netfilter/xt_dscp.h delete mode 100644 include/linux/netfilter/xt_ecn.h delete mode 100644 include/linux/netfilter/xt_esp.h delete mode 100644 include/linux/netfilter/xt_hashlimit.h delete mode 100644 include/linux/netfilter/xt_helper.h delete mode 100644 include/linux/netfilter/xt_ipcomp.h delete mode 100644 include/linux/netfilter/xt_iprange.h delete mode 100644 include/linux/netfilter/xt_ipvs.h delete mode 100644 include/linux/netfilter/xt_length.h delete mode 100644 include/linux/netfilter/xt_limit.h delete mode 100644 include/linux/netfilter/xt_mac.h delete mode 100644 include/linux/netfilter/xt_mark.h delete mode 100644 include/linux/netfilter/xt_multiport.h delete mode 100644 include/linux/netfilter/xt_nfacct.h delete mode 100644 include/linux/netfilter/xt_osf.h delete mode 100644 include/linux/netfilter/xt_owner.h delete mode 100644 include/linux/netfilter/xt_physdev.h delete mode 100644 include/linux/netfilter/xt_pkttype.h delete mode 100644 include/linux/netfilter/xt_policy.h delete mode 100644 include/linux/netfilter/xt_quota.h delete mode 100644 include/linux/netfilter/xt_quota2.h delete mode 100644 include/linux/netfilter/xt_rateest.h delete mode 100644 include/linux/netfilter/xt_realm.h delete mode 100644 include/linux/netfilter/xt_recent.h delete mode 100644 include/linux/netfilter/xt_rpfilter.h delete mode 100644 include/linux/netfilter/xt_sctp.h delete mode 100644 include/linux/netfilter/xt_set.h delete mode 100644 include/linux/netfilter/xt_socket.h delete mode 100644 include/linux/netfilter/xt_state.h delete mode 100644 include/linux/netfilter/xt_statistic.h delete mode 100644 include/linux/netfilter/xt_string.h delete mode 100644 include/linux/netfilter/xt_tcpmss.h delete mode 100644 include/linux/netfilter/xt_tcpudp.h delete mode 100644 include/linux/netfilter/xt_time.h delete mode 100644 include/linux/netfilter/xt_u32.h delete mode 100644 include/linux/netfilter_arp.h delete mode 100644 include/linux/netfilter_arp/arp_tables.h delete mode 100644 include/linux/netfilter_arp/arpt_mangle.h delete mode 100644 include/linux/netfilter_bridge.h delete mode 100644 include/linux/netfilter_bridge/ebt_802_3.h delete mode 100644 include/linux/netfilter_bridge/ebt_ip.h delete mode 100644 include/linux/netfilter_bridge/ebt_mark_m.h delete mode 100644 include/linux/netfilter_bridge/ebt_mark_t.h delete mode 100644 include/linux/netfilter_ipv4.h delete mode 100644 include/linux/netfilter_ipv4/ip_queue.h delete mode 100644 include/linux/netfilter_ipv4/ip_tables.h delete mode 100644 include/linux/netfilter_ipv4/ipt_CLUSTERIP.h delete mode 100644 include/linux/netfilter_ipv4/ipt_ECN.h delete mode 100644 include/linux/netfilter_ipv4/ipt_LOG.h delete mode 100644 include/linux/netfilter_ipv4/ipt_REJECT.h delete mode 100644 include/linux/netfilter_ipv4/ipt_TTL.h delete mode 100644 include/linux/netfilter_ipv4/ipt_ULOG.h delete mode 100644 include/linux/netfilter_ipv4/ipt_addrtype.h delete mode 100644 include/linux/netfilter_ipv4/ipt_ah.h delete mode 100644 include/linux/netfilter_ipv4/ipt_realm.h delete mode 100644 include/linux/netfilter_ipv4/ipt_ttl.h delete mode 100644 include/linux/netfilter_ipv6.h delete mode 100644 include/linux/netfilter_ipv6/ip6_tables.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_HL.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_LOG.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_NPT.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_REJECT.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_ah.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_frag.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_hl.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_ipv6header.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_mh.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_opts.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_rt.h delete mode 100644 include/linux/netfilter_ipv6/ip6t_srh.h delete mode 100644 include/linux/types.h delete mode 100644 include/xtables-version.h delete mode 100644 include/xtables-version.h.in delete mode 100644 include/xtables.h rename extensions/genClear.py => install.sh (58%) create mode 100644 iptables-1.8.7.tar.bz2 create mode 100644 iptables-config delete mode 100755 iptables-test.py create mode 100644 iptables.init create mode 100644 iptables.service create mode 100644 iptables.spec delete mode 100644 iptables/.gitignore delete mode 100644 iptables/Makefile.am delete mode 100644 iptables/arptables-nft-restore.8 delete mode 100644 iptables/arptables-nft-save.8 delete mode 100644 iptables/arptables-nft.8 delete mode 100644 iptables/ebtables-nft.8 delete mode 100644 iptables/ip6tables-apply.8 delete mode 100644 iptables/ip6tables-multi.h delete mode 100644 iptables/ip6tables-restore.8 delete mode 100644 iptables/ip6tables-save.8 delete mode 100644 iptables/ip6tables-standalone.c delete mode 100644 iptables/ip6tables.8 delete mode 100644 iptables/ip6tables.c delete mode 100755 iptables/iptables-apply delete mode 100644 iptables/iptables-apply.8.in delete mode 100644 iptables/iptables-extensions.8.tmpl.in delete mode 100644 iptables/iptables-multi.h delete mode 100644 iptables/iptables-restore.8.in delete mode 100644 iptables/iptables-restore.c delete mode 100644 iptables/iptables-save.8.in delete mode 100644 iptables/iptables-save.c delete mode 100644 iptables/iptables-standalone.c delete mode 100644 iptables/iptables-xml.1.in delete mode 100644 iptables/iptables-xml.c delete mode 100644 iptables/iptables.8.in delete mode 100644 iptables/iptables.c delete mode 100644 iptables/iptables.xslt delete mode 100644 iptables/nft-arp.c delete mode 100644 iptables/nft-arp.h delete mode 100644 iptables/nft-bridge.c delete mode 100644 iptables/nft-bridge.h delete mode 100644 iptables/nft-cache.c delete mode 100644 iptables/nft-cache.h delete mode 100644 iptables/nft-chain.c delete mode 100644 iptables/nft-chain.h delete mode 100644 iptables/nft-cmd.c delete mode 100644 iptables/nft-cmd.h delete mode 100644 iptables/nft-ipv4.c delete mode 100644 iptables/nft-ipv6.c delete mode 100644 iptables/nft-shared.c delete mode 100644 iptables/nft-shared.h delete mode 100644 iptables/nft.c delete mode 100644 iptables/nft.h delete mode 100644 iptables/tests/shell/README delete mode 100755 iptables/tests/shell/run-tests.sh delete mode 100755 iptables/tests/shell/testcases/arptables/0001-arptables-save-restore_0 delete mode 100755 iptables/tests/shell/testcases/arptables/0002-arptables-restore-defaults_0 delete mode 100755 iptables/tests/shell/testcases/arptables/0003-arptables-verbose-output_0 delete mode 100755 iptables/tests/shell/testcases/chain/0001duplicate_1 delete mode 100755 iptables/tests/shell/testcases/chain/0002newchain_0 delete mode 100755 iptables/tests/shell/testcases/chain/0003rename_1 delete mode 100755 iptables/tests/shell/testcases/ebtables/0001-ebtables-basic_0 delete mode 100755 iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 delete mode 100755 iptables/tests/shell/testcases/ebtables/0003-ebtables-restore-defaults_0 delete mode 100755 iptables/tests/shell/testcases/ebtables/0004-save-counters_0 delete mode 100755 iptables/tests/shell/testcases/ebtables/0005-ifnamechecks_0 delete mode 100755 iptables/tests/shell/testcases/firewalld-restore/0001-firewalld_0 delete mode 100755 iptables/tests/shell/testcases/firewalld-restore/0002-firewalld-restart_0 delete mode 100644 iptables/tests/shell/testcases/firewalld-restore/dumps/ipt-save-completed.txt delete mode 100755 iptables/tests/shell/testcases/ip6tables/0002-verbose-output_0 delete mode 100755 iptables/tests/shell/testcases/ip6tables/0003-list-rules_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0001load-specific-table_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0002-parameters_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0004-restore-race_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0005-ipt-6_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0006-ip6t-4_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0007-flush-noflush_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0008-restore-counters_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0009-table-name-comment_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0010-noflush-new-chain_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0011-noflush-empty-line_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0012-dash-F_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0013-test-mode_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0014-verbose-restore_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0016-concurrent-restores_0 delete mode 100755 iptables/tests/shell/testcases/ipt-restore/0017-pointless-compat-checks_0 delete mode 100644 iptables/tests/shell/testcases/ipt-restore/dumps/ip6tables.dump delete mode 100644 iptables/tests/shell/testcases/ipt-restore/dumps/iptables.dump delete mode 100755 iptables/tests/shell/testcases/ipt-save/0001load-dumps_0 delete mode 100755 iptables/tests/shell/testcases/ipt-save/0002load-fedora27-firewalld_0 delete mode 100644 iptables/tests/shell/testcases/ipt-save/0003save-restore_0 delete mode 100755 iptables/tests/shell/testcases/ipt-save/0005iptables_0 delete mode 100755 iptables/tests/shell/testcases/ipt-save/0006iptables-xml_0 delete mode 100644 iptables/tests/shell/testcases/ipt-save/dumps/fedora27-ip6tables delete mode 100644 iptables/tests/shell/testcases/ipt-save/dumps/fedora27-iptables delete mode 100644 iptables/tests/shell/testcases/ipt-save/dumps/fedora27-iptables.xml delete mode 100644 iptables/tests/shell/testcases/ipt-save/dumps/ipt-save-filter.txt delete mode 100644 iptables/tests/shell/testcases/ipt-save/dumps/policy-drop.txt delete mode 100644 iptables/tests/shell/testcases/ipt-save/dumps/wireless.txt delete mode 100755 iptables/tests/shell/testcases/iptables/0001-chain-refs_0 delete mode 100755 iptables/tests/shell/testcases/iptables/0002-verbose-output_0 delete mode 100755 iptables/tests/shell/testcases/iptables/0003-list-rules_0 delete mode 100755 iptables/tests/shell/testcases/iptables/0004-return-codes_0 delete mode 100755 iptables/tests/shell/testcases/iptables/0005-delete-rules_0 delete mode 100755 iptables/tests/shell/testcases/iptables/0005-rule-replace_0 delete mode 100755 iptables/tests/shell/testcases/iptables/0006-46-args_0 delete mode 100755 iptables/tests/shell/testcases/nft-only/0001compat_0 delete mode 100755 iptables/tests/shell/testcases/nft-only/0002invflags_0 delete mode 100755 iptables/tests/shell/testcases/nft-only/0003delete-with-comment_0 delete mode 100755 iptables/tests/shell/testcases/nft-only/0006-policy-override_0 delete mode 100755 iptables/tests/shell/testcases/nft-only/0007-mid-restore-flush_0 delete mode 100755 iptables/tests/shell/testcases/nft-only/0008-basechain-policy_0 delete mode 100755 iptables/tests/shell/testcases/nft-only/0009-needless-bitwise_0 delete mode 100644 iptables/xshared.c delete mode 100644 iptables/xshared.h delete mode 100644 iptables/xtables-arp-standalone.c delete mode 100644 iptables/xtables-arp.c delete mode 100644 iptables/xtables-eb-standalone.c delete mode 100644 iptables/xtables-eb-translate.c delete mode 100644 iptables/xtables-eb.c delete mode 100644 iptables/xtables-legacy-multi.c delete mode 100644 iptables/xtables-legacy.8 delete mode 100644 iptables/xtables-monitor.8.in delete mode 100644 iptables/xtables-monitor.c delete mode 100644 iptables/xtables-multi.h delete mode 100644 iptables/xtables-nft-multi.c delete mode 100644 iptables/xtables-nft.8 delete mode 100644 iptables/xtables-restore.c delete mode 100644 iptables/xtables-save.c delete mode 100644 iptables/xtables-standalone.c delete mode 100644 iptables/xtables-translate.8 delete mode 100644 iptables/xtables-translate.c delete mode 100644 iptables/xtables.c delete mode 100644 iptables/xtables.pc.in delete mode 100644 libipq/.gitignore delete mode 100644 libipq/Makefile.am delete mode 100644 libipq/ipq_create_handle.3 delete mode 100644 libipq/ipq_destroy_handle.3 delete mode 100644 libipq/ipq_errstr.3 delete mode 100644 libipq/ipq_get_msgerr.3 delete mode 100644 libipq/ipq_get_packet.3 delete mode 100644 libipq/ipq_message_type.3 delete mode 100644 libipq/ipq_perror.3 delete mode 100644 libipq/ipq_read.3 delete mode 100644 libipq/ipq_set_mode.3 delete mode 100644 libipq/ipq_set_verdict.3 delete mode 100644 libipq/libipq.3 delete mode 100644 libipq/libipq.c delete mode 100644 libipq/libipq.pc.in delete mode 100644 libiptc/.gitignore delete mode 100644 libiptc/BUILD.gn delete mode 100644 libiptc/Makefile.am delete mode 100644 libiptc/libip4tc.c delete mode 100644 libiptc/libip4tc.pc.in delete mode 100644 libiptc/libip6tc.c delete mode 100644 libiptc/libip6tc.pc.in delete mode 100644 libiptc/libiptc.c delete mode 100644 libiptc/libiptc.pc.in delete mode 100644 libiptc/linux_list.h delete mode 100644 libiptc/linux_stddef.h delete mode 100644 libxtables/BUILD.gn delete mode 100644 libxtables/Makefile.am delete mode 100644 libxtables/getethertype.c delete mode 100644 libxtables/xtables.c delete mode 100644 libxtables/xtoptions.c delete mode 100644 m4/.gitignore create mode 100644 sysconfig_ip6tables create mode 100644 sysconfig_iptables delete mode 100644 utils/.gitignore delete mode 100644 utils/Makefile.am delete mode 100644 utils/nfbpf_compile.8.in delete mode 100644 utils/nfbpf_compile.c delete mode 100644 utils/nfnl_osf.8.in delete mode 100644 utils/nfnl_osf.c delete mode 100644 utils/nfsynproxy.c delete mode 100644 utils/pf.os delete mode 100755 xlate-test.py diff --git a/.gitignore b/.gitignore index e5595264..20a03620 100644 --- a/.gitignore +++ b/.gitignore @@ -25,3 +25,4 @@ Makefile.in # vim/nano swap file *.swp +.idea diff --git a/BUILD.gn b/BUILD.gn index 620f535b..d0638a15 100644 --- a/BUILD.gn +++ b/BUILD.gn @@ -13,6 +13,9 @@ import("//build/ohos.gni") +iptables_path = rebase_path("//third_party/iptables") +exec_script("install.sh", [ "$iptables_path" ]) + config("iptables_config") { cflags = [ "-D_LARGEFILE_SOURCE=1", diff --git a/COMMIT_NOTES b/COMMIT_NOTES deleted file mode 100644 index 592808c5..00000000 --- a/COMMIT_NOTES +++ /dev/null @@ -1,19 +0,0 @@ -A quick list of rules for committing stuff into netfilter git: - -- Always add an appropriate description, in git format - (i.e. first line is a summary) - -- Please try to include references to bugs when the description does not - include total discussion coverage or when the bug report is external to - netfilter-devel, e.g. - "Closes: netfilter bugzilla #123", or - "Reference: http://bugs.{debian,gentoo}.org/..." - -- If you touch any parts of libxtables (xtables.c, include/xtables.h.in), - make sure the so-version is updated _appropriately_ (i.e. read the - libtool manual about Versioning:: first, if need be) in configure.ac. - Adding fields to a struct always entails a vcurrent bump. - - - Check, whether a bump (vcurrent,vage) has already been made since the - last release (no more than one per release), e.g.: - git log v1.4.4.. configure.ac diff --git a/INCOMPATIBILITIES b/INCOMPATIBILITIES deleted file mode 100644 index ddb24087..00000000 --- a/INCOMPATIBILITIES +++ /dev/null @@ -1,14 +0,0 @@ -INCOMPATIBILITIES: - -- The REJECT target has an '--reject-with admin-prohib' option which used - with kernels that do not support it, will result in a plain DROP instead - of REJECT. Use with caution. - Kernels that do support it: - 2.4 - since 2.4.22-pre9 - 2.6 - all - -- There are some issues related to upgrading from 1.2.x to 1.3.x on a system - with dynamic ruleset changes during runtime. (Please see - https://bugzilla.netfilter.org/bugzilla/show_bug.cgi?id=334). - After upgrading from 1.2 to 1.3, it suggest go do an iptables-save, then - iptables-restore to ensure your dynamic rule changes continue to work. diff --git a/INSTALL b/INSTALL deleted file mode 100644 index d62b428c..00000000 --- a/INSTALL +++ /dev/null @@ -1,101 +0,0 @@ -Installation instructions for iptables -====================================== - -iptables uses the well-known configure(autotools) infrastructure. - - $ ./configure - $ make - # make install - - -Prerequisites -============= - - * no kernel-source required - - * but obviously a compiler, glibc-devel and linux-kernel-headers - (/usr/include/linux) - - -Configuring and compiling -========================= - -./configure [options] - ---prefix= - - The prefix to put all installed files under. It defaults to - /usr/local, so the binaries will go into /usr/local/bin, sbin, - manpages into /usr/local/share/man, etc. - ---with-xtlibdir= - - The path to where Xtables extensions should be installed to. It - defaults to ${libdir}/xtables. - ---enable-devel (or --disable-devel) - - This option causes development files to be installed to - ${includedir}, which is needed for building additional packages, - such as Xtables-addons or other 3rd-party extensions. - - It is enabled by default. - ---enable-static - - Produce additional binaries, iptables-static/ip6tables-static, - which have all shipped extensions compiled in. - ---disable-shared - - Produce binaries that have dynamic loading of extensions disabled. - This implies --enable-static. - (See some details below.) - ---enable-libipq - - This option causes libipq to be installed into ${libdir} and - ${includedir}. - ---with-ksource= - - Xtables does not depend on kernel headers anymore, but you can - optionally specify a search path to include anyway. This is - probably only useful for development. - -If you want to enable debugging, use - - ./configure CFLAGS="-ggdb3 -O0" - -(-O0 is used to turn off instruction reordering, which makes debugging -much easier.) - -To show debug traces you can add -DDEBUG to CFLAGS option - - -Other notes -=========== - -The make process will automatically build multipurpose binaries. -These have the core (iptables), -save, -restore and -xml code -compiled into one binary, but extensions remain as modules. - - -Static and shared -================= - -Basically there are three configuration modes defined: - - --disable-static --enable-shared (this is the default) - - Build a binary that relies upon dynamic loading of extensions. - - --enable-static --enable-shared - - Build a binary that has the shipped extensions built-in, but - is still capable of loading additional extensions. - - --enable-static --disable-shared - - Shipped extensions are built-in, and dynamic loading is - deactivated. diff --git a/Makefile.am b/Makefile.am deleted file mode 100644 index 799bf8b8..00000000 --- a/Makefile.am +++ /dev/null @@ -1,33 +0,0 @@ -# -*- Makefile -*- - -ACLOCAL_AMFLAGS = -I m4 -AUTOMAKE_OPTIONS = foreign subdir-objects - -SUBDIRS = libiptc libxtables -if ENABLE_DEVEL -SUBDIRS += include -endif -if ENABLE_LIBIPQ -SUBDIRS += libipq -endif -SUBDIRS += utils -# Depends on libxtables: -SUBDIRS += extensions -# Depends on extensions/libext.a: -SUBDIRS += iptables - -if ENABLE_NFTABLES -confdir = $(sysconfdir) -dist_conf_DATA = etc/ethertypes -endif - -.PHONY: tarball -tarball: - rm -Rf /tmp/${PACKAGE_TARNAME}-${PACKAGE_VERSION}; - pushd ${top_srcdir} && git archive --prefix=${PACKAGE_TARNAME}-${PACKAGE_VERSION}/ HEAD | tar -C /tmp -x && popd; - pushd /tmp/${PACKAGE_TARNAME}-${PACKAGE_VERSION} && ./autogen.sh && popd; - tar -C /tmp -cjf ${PACKAGE_TARNAME}-${PACKAGE_VERSION}.tar.bz2 --owner=root --group=root ${PACKAGE_TARNAME}-${PACKAGE_VERSION}/; - rm -Rf /tmp/${PACKAGE_TARNAME}-${PACKAGE_VERSION}; - -config.status: extensions/GNUmakefile.in \ - include/xtables-version.h.in diff --git a/OAT.xml b/OAT.xml index 82d66afc..82711ff7 100644 --- a/OAT.xml +++ b/OAT.xml @@ -59,6 +59,9 @@ + + + + + + + + + + diff --git a/autogen.sh b/autogen.sh deleted file mode 100755 index a0c4395f..00000000 --- a/autogen.sh +++ /dev/null @@ -1,4 +0,0 @@ -#!/bin/sh -e - -autoreconf -fi; -rm -Rf autom4te*.cache; diff --git a/bugfix-add-check-fw-in-entry.patch b/bugfix-add-check-fw-in-entry.patch new file mode 100644 index 00000000..36617912 --- /dev/null +++ b/bugfix-add-check-fw-in-entry.patch @@ -0,0 +1,135 @@ +From cbc3a30711701f0e8d7f5df14f84adfb2c9fec1f Mon Sep 17 00:00:00 2001 +From: majun +Date: Fri, 16 Apr 2021 14:52:42 +0800 +Subject: [PATCH] + +iptables: add null check for fw in X_entry +If the fw pointer is empty, a core dump occurs. + +--- + iptables/ip6tables.c | 21 +++++++++++++++++++++ + iptables/iptables.c | 20 ++++++++++++++++++++ + 2 files changed, 41 insertions(+) + +diff --git a/iptables/ip6tables.c b/iptables/ip6tables.c +index c95355b..1902cb4 100644 +--- a/iptables/ip6tables.c ++++ b/iptables/ip6tables.c +@@ -478,6 +478,10 @@ append_entry(const xt_chainlabel chain, + unsigned int i, j; + int ret = 1; + ++ if (!fw) { ++ return 0; ++ } ++ + for (i = 0; i < nsaddrs; i++) { + fw->ipv6.src = saddrs[i]; + fw->ipv6.smsk = smasks[i]; +@@ -502,6 +506,11 @@ replace_entry(const xt_chainlabel chain, + int verbose, + struct xtc_handle *handle) + { ++ ++ if (!fw) { ++ return 0; ++ } ++ + fw->ipv6.src = *saddr; + fw->ipv6.dst = *daddr; + fw->ipv6.smsk = *smask; +@@ -528,6 +537,10 @@ insert_entry(const xt_chainlabel chain, + unsigned int i, j; + int ret = 1; + ++ if (!fw) { ++ return 0; ++ } ++ + for (i = 0; i < nsaddrs; i++) { + fw->ipv6.src = saddrs[i]; + fw->ipv6.smsk = smasks[i]; +@@ -595,6 +608,10 @@ delete_entry(const xt_chainlabel chain, + int ret = 1; + unsigned char *mask; + ++ if (!fw) { ++ return 0; ++ } ++ + mask = make_delete_mask(matches, target); + for (i = 0; i < nsaddrs; i++) { + fw->ipv6.src = saddrs[i]; +@@ -625,6 +642,10 @@ check_entry(const xt_chainlabel chain, struct ip6t_entry *fw, + int ret = 1; + unsigned char *mask; + ++ if (!fw) { ++ return 0; ++ } ++ + mask = make_delete_mask(matches, target); + for (i = 0; i < nsaddrs; i++) { + fw->ipv6.src = saddrs[i]; +diff --git a/iptables/iptables.c b/iptables/iptables.c +index 7d61831..a206825 100644 +--- a/iptables/iptables.c ++++ b/iptables/iptables.c +@@ -469,6 +469,10 @@ append_entry(const xt_chainlabel chain, + unsigned int i, j; + int ret = 1; + ++ if (!fw) { ++ return 0; ++ } ++ + for (i = 0; i < nsaddrs; i++) { + fw->ip.src.s_addr = saddrs[i].s_addr; + fw->ip.smsk.s_addr = smasks[i].s_addr; +@@ -493,6 +497,10 @@ replace_entry(const xt_chainlabel chain, + int verbose, + struct xtc_handle *handle) + { ++ if (!fw) { ++ return 0; ++ } ++ + fw->ip.src.s_addr = saddr->s_addr; + fw->ip.dst.s_addr = daddr->s_addr; + fw->ip.smsk.s_addr = smask->s_addr; +@@ -519,6 +527,10 @@ insert_entry(const xt_chainlabel chain, + unsigned int i, j; + int ret = 1; + ++ if (!fw) { ++ return 0; ++ } ++ + for (i = 0; i < nsaddrs; i++) { + fw->ip.src.s_addr = saddrs[i].s_addr; + fw->ip.smsk.s_addr = smasks[i].s_addr; +@@ -586,6 +598,10 @@ delete_entry(const xt_chainlabel chain, + int ret = 1; + unsigned char *mask; + ++ if (!fw) { ++ return 0; ++ } ++ + mask = make_delete_mask(matches, target); + for (i = 0; i < nsaddrs; i++) { + fw->ip.src.s_addr = saddrs[i].s_addr; +@@ -616,6 +632,10 @@ check_entry(const xt_chainlabel chain, struct ipt_entry *fw, + int ret = 1; + unsigned char *mask; + ++ if (!fw) { ++ return 0; ++ } ++ + mask = make_delete_mask(matches, target); + for (i = 0; i < nsaddrs; i++) { + fw->ip.src.s_addr = saddrs[i].s_addr; +-- +2.27.0 + diff --git a/config.h b/config.h deleted file mode 100644 index a75f7c76..00000000 --- a/config.h +++ /dev/null @@ -1,101 +0,0 @@ -/* - * Copyright (C) 2022 Huawei Device Co., Ltd. - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -/* config.h. Generated from config.h.in by configure. */ -/* config.h.in. Generated from configure.ac by autoheader. */ - -/* Define to 1 if you have the header file. */ -#define HAVE_DLFCN_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_INTTYPES_H 1 - -/* Define to 1 if you have the `pcap' library (-lpcap). */ -/* #undef HAVE_LIBPCAP */ - -/* Define to 1 if you have the header file. */ -#define HAVE_LINUX_BPF_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_LINUX_DCCP_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_LINUX_IP_VS_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_LINUX_MAGIC_H 1 - -/* Define to 1 if you have the header file. */ -/* #undef HAVE_LINUX_PROC_FS_H */ - -/* Define to 1 if you have the header file. */ -#define HAVE_MEMORY_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_STDINT_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_STDLIB_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_STRINGS_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_STRING_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_SYS_STAT_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_SYS_TYPES_H 1 - -/* Define to 1 if you have the header file. */ -#define HAVE_UNISTD_H 1 - -/* Define to the sub-directory where libtool stores uninstalled libraries. */ -#define LT_OBJDIR ".libs/" - -/* Name of package */ -#define PACKAGE "iptables" - -/* Define to the address where bug reports for this package should be sent. */ -#define PACKAGE_BUGREPORT "" - -/* Define to the full name of this package. */ -#define PACKAGE_NAME "iptables" - -/* Define to the full name and version of this package. */ -#define PACKAGE_STRING "iptables 1.8.7" - -/* Define to the one symbol short name of this package. */ -#define PACKAGE_TARNAME "iptables" - -/* Define to the home page for this package. */ -#define PACKAGE_URL "" - -/* Define to the version of this package. */ -#define PACKAGE_VERSION "1.8.7" - -/* The size of `struct ip6_hdr', as computed by sizeof. */ -#define SIZEOF_STRUCT_IP6_HDR 40 - -/* Define to 1 if you have the ANSI C header files. */ -#define STDC_HEADERS 1 - -/* Version number of package */ -#define VERSION "1.8.7" - -/* Location of the iptables lock file */ -#define XT_LOCK_NAME "/system/etc/xtables.lock" diff --git a/configure.ac b/configure.ac deleted file mode 100644 index 6864378a..00000000 --- a/configure.ac +++ /dev/null @@ -1,274 +0,0 @@ - -AC_INIT([iptables], [1.8.7]) - -# See libtool.info "Libtool's versioning system" -libxtables_vcurrent=16 -libxtables_vage=4 - -AC_CONFIG_AUX_DIR([build-aux]) -AC_CONFIG_HEADERS([config.h]) -AC_CONFIG_MACRO_DIR([m4]) -AC_PROG_INSTALL -AM_INIT_AUTOMAKE([-Wall]) -AC_PROG_CC -AM_PROG_CC_C_O -AC_DISABLE_STATIC -m4_ifdef([AM_PROG_AR], [AM_PROG_AR]) -AM_PROG_LIBTOOL - -AC_ARG_WITH([kernel], - AS_HELP_STRING([--with-kernel=PATH], - [Path to kernel source/build directory]), - [kbuilddir="$withval"; ksourcedir="$withval";]) -AC_ARG_WITH([kbuild], - AS_HELP_STRING([--with-kbuild=PATH], - [Path to kernel build directory [[/lib/modules/CURRENT/build]]]), - [kbuilddir="$withval"]) -AC_ARG_WITH([ksource], - AS_HELP_STRING([--with-ksource=PATH], - [Path to kernel source directory [[/lib/modules/CURRENT/source]]]), - [ksourcedir="$withval"]) -AC_ARG_WITH([xtlibdir], - AS_HELP_STRING([--with-xtlibdir=PATH], - [Path where to install Xtables extensions [[LIBEXECDIR/xtables]]]), - [xtlibdir="$withval"], - [xtlibdir="${libdir}/xtables"]) -AC_ARG_ENABLE([ipv4], - AS_HELP_STRING([--disable-ipv4], [Do not build iptables]), - [enable_ipv4="$enableval"], [enable_ipv4="yes"]) -AC_ARG_ENABLE([ipv6], - AS_HELP_STRING([--disable-ipv6], [Do not build ip6tables]), - [enable_ipv6="$enableval"], [enable_ipv6="yes"]) -AC_ARG_ENABLE([largefile], - AS_HELP_STRING([--disable-largefile], [Do not build largefile support]), - [enable_largefile="$enableval"], - [enable_largefile="yes"]) -AS_IF([test "$enable_largefile" = "yes"], [largefile_cppflags='-D_LARGEFILE_SOURCE=1 -D_LARGE_FILES -D_FILE_OFFSET_BITS=64']) - -AC_ARG_ENABLE([devel], - AS_HELP_STRING([--enable-devel], - [Install Xtables development headers]), - [enable_devel="$enableval"], [enable_devel="yes"]) -AC_ARG_ENABLE([libipq], - AS_HELP_STRING([--enable-libipq], [Build and install libipq]), - [enable_libipq="$enableval"], [enable_libipq="no"]) -AC_ARG_ENABLE([bpf-compiler], - AS_HELP_STRING([--enable-bpf-compiler], [Build bpf compiler]), - [enable_bpfc="$enableval"], [enable_bpfc="no"]) -AC_ARG_ENABLE([nfsynproxy], - AS_HELP_STRING([--enable-nfsynproxy], [Build SYNPROXY configuration tool]), - [enable_nfsynproxy="$enableval"], [enable_nfsynproxy="no"]) -AC_ARG_WITH([pkgconfigdir], AS_HELP_STRING([--with-pkgconfigdir=PATH], - [Path to the pkgconfig directory [[LIBDIR/pkgconfig]]]), - [pkgconfigdir="$withval"], [pkgconfigdir='${libdir}/pkgconfig']) -AC_ARG_ENABLE([nftables], - AS_HELP_STRING([--disable-nftables], [Do not build nftables compat]), - [enable_nftables="$enableval"], [enable_nftables="yes"]) -AC_ARG_ENABLE([connlabel], - AS_HELP_STRING([--disable-connlabel], - [Do not build libnetfilter_conntrack]), - [enable_connlabel="$enableval"], [enable_connlabel="yes"]) -AC_ARG_WITH([xt-lock-name], AS_HELP_STRING([--with-xt-lock-name=PATH], - [Path to the xtables lock [[/run/xtables.lock]]]), - [xt_lock_name="$withval"], - [xt_lock_name="/run/xtables.lock"]) - -AC_MSG_CHECKING([whether $LD knows -Wl,--no-undefined]) -saved_LDFLAGS="$LDFLAGS"; -LDFLAGS="-Wl,--no-undefined"; -AC_LINK_IFELSE([AC_LANG_SOURCE([int main(void) {}])], - [noundef_LDFLAGS="$LDFLAGS"; AC_MSG_RESULT([yes])], - [AC_MSG_RESULT([no])] -) -LDFLAGS="$saved_LDFLAGS"; - -blacklist_modules="" -blacklist_x_modules="" -blacklist_b_modules="" -blacklist_a_modules="" -blacklist_4_modules="" -blacklist_6_modules="" - -AC_CHECK_HEADERS([linux/dccp.h linux/ip_vs.h linux/magic.h linux/proc_fs.h linux/bpf.h]) -if test "$ac_cv_header_linux_dccp_h" != "yes"; then - blacklist_modules="$blacklist_modules dccp"; -fi; -if test "$ac_cv_header_linux_ip_vs_h" != "yes"; then - blacklist_modules="$blacklist_modules ipvs"; -fi; - -AC_CHECK_SIZEOF([struct ip6_hdr], [], [#include ]) - -AM_CONDITIONAL([ENABLE_STATIC], [test "$enable_static" = "yes"]) -AM_CONDITIONAL([ENABLE_SHARED], [test "$enable_shared" = "yes"]) -AM_CONDITIONAL([ENABLE_IPV4], [test "$enable_ipv4" = "yes"]) -AM_CONDITIONAL([ENABLE_IPV6], [test "$enable_ipv6" = "yes"]) -AM_CONDITIONAL([ENABLE_LARGEFILE], [test "$enable_largefile" = "yes"]) -AM_CONDITIONAL([ENABLE_DEVEL], [test "$enable_devel" = "yes"]) -AM_CONDITIONAL([ENABLE_LIBIPQ], [test "$enable_libipq" = "yes"]) -AM_CONDITIONAL([ENABLE_BPFC], [test "$enable_bpfc" = "yes"]) -AM_CONDITIONAL([ENABLE_SYNCONF], [test "$enable_nfsynproxy" = "yes"]) -AM_CONDITIONAL([ENABLE_NFTABLES], [test "$enable_nftables" = "yes"]) -AM_CONDITIONAL([ENABLE_CONNLABEL], [test "$enable_connlabel" = "yes"]) - -if test "x$enable_bpfc" = "xyes" || test "x$enable_nfsynproxy" = "xyes"; then - AC_CHECK_LIB(pcap, pcap_compile,, AC_MSG_ERROR(missing libpcap library required by bpf compiler or nfsynproxy tool)) -fi - -PKG_CHECK_MODULES([libnfnetlink], [libnfnetlink >= 1.0], - [nfnetlink=1], [nfnetlink=0]) -AM_CONDITIONAL([HAVE_LIBNFNETLINK], [test "$nfnetlink" = 1]) - -if test "x$enable_nftables" = "xyes"; then - PKG_CHECK_MODULES([libmnl], [libmnl >= 1.0], [mnl=1], [mnl=0]) - - if test "$mnl" = 0; - then - echo "*** Error: No suitable libmnl found. ***" - echo " Please install the 'libmnl' package" - echo " Or consider --disable-nftables to skip" - echo " iptables-compat over nftables support." - exit 1 - fi - - PKG_CHECK_MODULES([libnftnl], [libnftnl >= 1.1.6], [nftables=1], [nftables=0]) - - if test "$nftables" = 0; - then - echo "*** Error: no suitable libnftnl found. ***" - echo " Please install the 'libnftnl' package" - echo " Or consider --disable-nftables to skip" - echo " iptables-compat over nftables support." - exit 1 - fi -fi - -AM_CONDITIONAL([HAVE_LIBMNL], [test "$mnl" = 1]) -AM_CONDITIONAL([HAVE_LIBNFTNL], [test "$nftables" = 1]) - -if test "$nftables" != 1; then - blacklist_b_modules="$blacklist_b_modules limit mark nflog mangle" - blacklist_a_modules="$blacklist_a_modules mangle" -fi - -if test "x$enable_connlabel" = "xyes"; then - PKG_CHECK_MODULES([libnetfilter_conntrack], - [libnetfilter_conntrack >= 1.0.6], - [nfconntrack=1], [nfconntrack=0]) - - if test "$nfconntrack" -ne 1; then - blacklist_modules="$blacklist_modules connlabel"; - echo "WARNING: libnetfilter_conntrack not found, connlabel match will not be built"; - enable_connlabel="no"; - fi; -else - blacklist_modules="$blacklist_modules connlabel"; -fi; - -AM_CONDITIONAL([HAVE_LIBNETFILTER_CONNTRACK], [test "$nfconntrack" = 1]) - -AC_SUBST([blacklist_modules]) -AC_SUBST([blacklist_x_modules]) -AC_SUBST([blacklist_b_modules]) -AC_SUBST([blacklist_a_modules]) -AC_SUBST([blacklist_4_modules]) -AC_SUBST([blacklist_6_modules]) - -regular_CFLAGS="-Wall -Waggregate-return -Wmissing-declarations \ - -Wmissing-prototypes -Wredundant-decls -Wshadow -Wstrict-prototypes \ - -Wlogical-op \ - -Winline -pipe"; -regular_CPPFLAGS="${largefile_cppflags} -D_REENTRANT \ - -DXTABLES_LIBDIR=\\\"\${xtlibdir}\\\" -DXTABLES_INTERNAL"; -kinclude_CPPFLAGS=""; -if [[ -n "$kbuilddir" ]]; then - kinclude_CPPFLAGS="$kinclude_CPPFLAGS -I$kbuilddir/include/uapi -I$kbuilddir/include"; -fi; -if [[ -n "$ksourcedir" ]]; then - kinclude_CPPFLAGS="$kinclude_CPPFLAGS -I$ksourcedir/include/uapi -I$ksourcedir/include"; -fi; -pkgdatadir='${datadir}/xtables'; - -define([EXPAND_VARIABLE], -[$2=[$]$1 -if test $prefix = 'NONE'; then - prefix="/usr/local" -fi -while true; do - case "[$]$2" in - *\[$]* ) eval "$2=[$]$2" ;; - *) break ;; - esac -done -eval "$2=[$]$2" -])dnl EXPAND_VARIABLE - -AC_SUBST([regular_CFLAGS]) -AC_SUBST([regular_CPPFLAGS]) -AC_SUBST([noundef_LDFLAGS]) -AC_SUBST([kinclude_CPPFLAGS]) -AC_SUBST([kbuilddir]) -AC_SUBST([ksourcedir]) -AC_SUBST([xtlibdir]) -AC_SUBST([pkgconfigdir]) -AC_SUBST([pkgdatadir]) -AC_SUBST([libxtables_vcurrent]) -AC_SUBST([libxtables_vage]) -libxtables_vmajor=$(($libxtables_vcurrent - $libxtables_vage)); -AC_SUBST([libxtables_vmajor]) - -AC_DEFINE_UNQUOTED([XT_LOCK_NAME], "${xt_lock_name}", - [Location of the iptables lock file]) -AC_SUBST([XT_LOCK_NAME], "${xt_lock_name}") - -AC_CONFIG_FILES([Makefile extensions/GNUmakefile include/Makefile - iptables/Makefile iptables/xtables.pc - iptables/iptables.8 iptables/iptables-extensions.8.tmpl - iptables/iptables-save.8 iptables/iptables-restore.8 - iptables/iptables-apply.8 iptables/iptables-xml.1 - libipq/Makefile libipq/libipq.pc - libiptc/Makefile libiptc/libiptc.pc - libiptc/libip4tc.pc libiptc/libip6tc.pc - libxtables/Makefile utils/Makefile - include/xtables-version.h - iptables/xtables-monitor.8 - utils/nfnl_osf.8 - utils/nfbpf_compile.8]) -AC_OUTPUT - - -EXPAND_VARIABLE(xtlibdir, e_xtlibdir) -EXPAND_VARIABLE(pkgconfigdir, e_pkgconfigdir) - -echo " -Iptables Configuration: - IPv4 support: ${enable_ipv4} - IPv6 support: ${enable_ipv6} - Devel support: ${enable_devel} - IPQ support: ${enable_libipq} - Large file support: ${enable_largefile} - BPF utils support: ${enable_bpfc} - nfsynproxy util support: ${enable_nfsynproxy} - nftables support: ${enable_nftables} - connlabel support: ${enable_connlabel} - -Build parameters: - Put plugins into executable (static): ${enable_static} - Support plugins via dlopen (shared): ${enable_shared} - Installation prefix (--prefix): ${prefix} - Xtables extension directory: ${e_xtlibdir} - Pkg-config directory: ${e_pkgconfigdir} - Xtables lock file: ${xt_lock_name}" - -if [[ -n "$ksourcedir" ]]; then - echo " Kernel source directory: ${ksourcedir}" -fi; -if [[ -n "$kbuilddir" ]]; then - echo " Kernel build directory: ${kbuilddir}" -fi; - -echo " Host: ${host} - GCC binary: ${CC}" - -test x"$blacklist_modules" = "x" || echo " -Iptables modules that will not be built: $blacklist_modules" diff --git a/etc/ethertypes b/etc/ethertypes deleted file mode 100644 index 813177b7..00000000 --- a/etc/ethertypes +++ /dev/null @@ -1,39 +0,0 @@ -# -# Ethernet frame types -# This file describes some of the various Ethernet -# protocol types that are used on Ethernet networks. -# -# This list could be found on: -# http://www.iana.org/assignments/ethernet-numbers -# http://www.iana.org/assignments/ieee-802-numbers -# -# ... #Comment -# -IPv4 0800 ip ip4 # Internet IP (IPv4) -X25 0805 -ARP 0806 ether-arp # -FR_ARP 0808 # Frame Relay ARP [RFC1701] -BPQ 08FF # G8BPQ AX.25 Ethernet Packet -DEC 6000 # DEC Assigned proto -DNA_DL 6001 # DEC DNA Dump/Load -DNA_RC 6002 # DEC DNA Remote Console -DNA_RT 6003 # DEC DNA Routing -LAT 6004 # DEC LAT -DIAG 6005 # DEC Diagnostics -CUST 6006 # DEC Customer use -SCA 6007 # DEC Systems Comms Arch -TEB 6558 # Trans Ether Bridging [RFC1701] -RAW_FR 6559 # Raw Frame Relay [RFC1701] -RARP 8035 # Reverse ARP [RFC903] -AARP 80F3 # Appletalk AARP -ATALK 809B # Appletalk -802_1Q 8100 8021q 1q 802.1q dot1q # 802.1Q Virtual LAN tagged frame -IPX 8137 # Novell IPX -NetBEUI 8191 # NetBEUI -IPv6 86DD ip6 # IP version 6 -PPP 880B # PPP -ATMMPOA 884C # MultiProtocol over ATM -PPP_DISC 8863 # PPPoE discovery messages -PPP_SES 8864 # PPPoE session messages -ATMFATE 8884 # Frame-based ATM Transport over Ethernet -LOOP 9000 loopback # loop proto diff --git a/etc/xtables.conf b/etc/xtables.conf deleted file mode 100644 index 3c54ced0..00000000 --- a/etc/xtables.conf +++ /dev/null @@ -1,74 +0,0 @@ -family ipv4 { - table raw { - chain PREROUTING hook NF_INET_PRE_ROUTING prio -300 - chain OUTPUT hook NF_INET_LOCAL_OUT prio -300 - } - - table mangle { - chain PREROUTING hook NF_INET_PRE_ROUTING prio -150 - chain INPUT hook NF_INET_LOCAL_IN prio -150 - chain FORWARD hook NF_INET_FORWARD prio -150 - chain OUTPUT hook NF_INET_LOCAL_OUT prio -150 - chain POSTROUTING hook NF_INET_POST_ROUTING prio -150 - } - - table filter { - chain INPUT hook NF_INET_LOCAL_IN prio 0 - chain FORWARD hook NF_INET_FORWARD prio 0 - chain OUTPUT hook NF_INET_LOCAL_OUT prio 0 - } - - table nat { - chain PREROUTING hook NF_INET_PRE_ROUTING prio -100 - chain INPUT hook NF_INET_LOCAL_IN prio 100 - chain OUTPUT hook NF_INET_LOCAL_OUT prio -100 - chain POSTROUTING hook NF_INET_POST_ROUTING prio 100 - } - - table security { - chain INPUT hook NF_INET_LOCAL_IN prio 50 - chain FORWARD hook NF_INET_FORWARD prio 50 - chain OUTPUT hook NF_INET_LOCAL_OUT prio 50 - } -} - -family ipv6 { - table raw { - chain PREROUTING hook NF_INET_PRE_ROUTING prio -300 - chain OUTPUT hook NF_INET_LOCAL_OUT prio -300 - } - - table mangle { - chain PREROUTING hook NF_INET_PRE_ROUTING prio -150 - chain INPUT hook NF_INET_LOCAL_IN prio -150 - chain FORWARD hook NF_INET_FORWARD prio -150 - chain OUTPUT hook NF_INET_LOCAL_OUT prio -150 - chain POSTROUTING hook NF_INET_POST_ROUTING prio -150 - } - - table filter { - chain INPUT hook NF_INET_LOCAL_IN prio 0 - chain FORWARD hook NF_INET_FORWARD prio 0 - chain OUTPUT hook NF_INET_LOCAL_OUT prio 0 - } - - table nat { - chain PREROUTING hook NF_INET_PRE_ROUTING prio -100 - chain INPUT hook NF_INET_LOCAL_IN prio 100 - chain OUTPUT hook NF_INET_LOCAL_OUT prio -100 - chain POSTROUTING hook NF_INET_POST_ROUTING prio 100 - } - - table security { - chain INPUT hook NF_INET_LOCAL_IN prio 50 - chain FORWARD hook NF_INET_FORWARD prio 50 - chain OUTPUT hook NF_INET_LOCAL_OUT prio 50 - } -} - -family arp { - table filter { - chain INPUT hook NF_ARP_IN prio 0 - chain OUTPUT hook NF_ARP_OUT prio 0 - } -} diff --git a/extensions/.gitignore b/extensions/.gitignore deleted file mode 100644 index b1260f0b..00000000 --- a/extensions/.gitignore +++ /dev/null @@ -1,9 +0,0 @@ -.*.d -.*.dd -*.oo - -/GNUmakefile -/initext.c -/initext?.c -/matches.man -/targets.man diff --git a/extensions/BUILD.gn b/extensions/BUILD.gn deleted file mode 100644 index dc723072..00000000 --- a/extensions/BUILD.gn +++ /dev/null @@ -1,254 +0,0 @@ -# Copyright (c) 2022 Huawei Device Co., Ltd. -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. - -import("//build/ohos.gni") -LIBEXT_COMMON_PATH = "//out/gen" -config("ext_config") { - cflags = [ - "-D_LARGEFILE_SOURCE=1", - "-D_LARGE_FILES", - "-D_FILE_OFFSET_BITS=64", - "-D_REENTRANT", - "-DENABLE_IPV4", - "-DENABLE_IPV6", - "-Wall", - "-Wno-error", - "-Wno-pointer-arith", - "-Wno-sign-compare", - "-Wno-unused-parameter", - "-DNO_SHARED_LIBS=1", - "-DXTABLES_INTERNAL", - "-Wno-format", - "-Wno-missing-field-initializers", - "-Wno-pointer-bool-conversion", - "-Wno-tautological-pointer-compare", - ] -} - -args_libext = [ - "libxt_", - "[libxt_cgroup.c,libxt_ipvs.c,libxt_TCPOPTSTRIP.c,libxt_connlabel.c,libxt_dccp.c]", - "initext.c", - "extensions", -] - -exec_script("genInit.py", args_libext) - -ohos_static_library("libext") { - sources = [ - "$LIBEXT_COMMON_PATH/initext.c", - "$LIBEXT_COMMON_PATH/libxt_AUDIT.c", - "$LIBEXT_COMMON_PATH/libxt_CHECKSUM.c", - "$LIBEXT_COMMON_PATH/libxt_CLASSIFY.c", - "$LIBEXT_COMMON_PATH/libxt_CONNMARK.c", - "$LIBEXT_COMMON_PATH/libxt_CONNSECMARK.c", - "$LIBEXT_COMMON_PATH/libxt_CT.c", - "$LIBEXT_COMMON_PATH/libxt_DSCP.c", - "$LIBEXT_COMMON_PATH/libxt_HMARK.c", - "$LIBEXT_COMMON_PATH/libxt_IDLETIMER.c", - "$LIBEXT_COMMON_PATH/libxt_LED.c", - "$LIBEXT_COMMON_PATH/libxt_MARK.c", - "$LIBEXT_COMMON_PATH/libxt_NFLOG.c", - "$LIBEXT_COMMON_PATH/libxt_NFQUEUE.c", - "$LIBEXT_COMMON_PATH/libxt_RATEEST.c", - "$LIBEXT_COMMON_PATH/libxt_SECMARK.c", - "$LIBEXT_COMMON_PATH/libxt_SET.c", - "$LIBEXT_COMMON_PATH/libxt_SYNPROXY.c", - "$LIBEXT_COMMON_PATH/libxt_TCPMSS.c", - "$LIBEXT_COMMON_PATH/libxt_TEE.c", - "$LIBEXT_COMMON_PATH/libxt_TOS.c", - "$LIBEXT_COMMON_PATH/libxt_TPROXY.c", - "$LIBEXT_COMMON_PATH/libxt_TRACE.c", - "$LIBEXT_COMMON_PATH/libxt_addrtype.c", - "$LIBEXT_COMMON_PATH/libxt_bpf.c", - "$LIBEXT_COMMON_PATH/libxt_cluster.c", - "$LIBEXT_COMMON_PATH/libxt_comment.c", - "$LIBEXT_COMMON_PATH/libxt_connbytes.c", - "$LIBEXT_COMMON_PATH/libxt_connlimit.c", - "$LIBEXT_COMMON_PATH/libxt_connmark.c", - "$LIBEXT_COMMON_PATH/libxt_conntrack.c", - "$LIBEXT_COMMON_PATH/libxt_cpu.c", - "$LIBEXT_COMMON_PATH/libxt_devgroup.c", - "$LIBEXT_COMMON_PATH/libxt_dscp.c", - "$LIBEXT_COMMON_PATH/libxt_ecn.c", - "$LIBEXT_COMMON_PATH/libxt_esp.c", - "$LIBEXT_COMMON_PATH/libxt_hashlimit.c", - "$LIBEXT_COMMON_PATH/libxt_helper.c", - "$LIBEXT_COMMON_PATH/libxt_ipcomp.c", - "$LIBEXT_COMMON_PATH/libxt_iprange.c", - "$LIBEXT_COMMON_PATH/libxt_length.c", - "$LIBEXT_COMMON_PATH/libxt_limit.c", - "$LIBEXT_COMMON_PATH/libxt_mac.c", - "$LIBEXT_COMMON_PATH/libxt_mark.c", - "$LIBEXT_COMMON_PATH/libxt_multiport.c", - "$LIBEXT_COMMON_PATH/libxt_nfacct.c", - "$LIBEXT_COMMON_PATH/libxt_osf.c", - "$LIBEXT_COMMON_PATH/libxt_owner.c", - "$LIBEXT_COMMON_PATH/libxt_physdev.c", - "$LIBEXT_COMMON_PATH/libxt_pkttype.c", - "$LIBEXT_COMMON_PATH/libxt_policy.c", - "$LIBEXT_COMMON_PATH/libxt_quota.c", - "$LIBEXT_COMMON_PATH/libxt_quota2.c", - "$LIBEXT_COMMON_PATH/libxt_rateest.c", - "$LIBEXT_COMMON_PATH/libxt_recent.c", - "$LIBEXT_COMMON_PATH/libxt_rpfilter.c", - "$LIBEXT_COMMON_PATH/libxt_sctp.c", - "$LIBEXT_COMMON_PATH/libxt_set.c", - "$LIBEXT_COMMON_PATH/libxt_socket.c", - "$LIBEXT_COMMON_PATH/libxt_standard.c", - "$LIBEXT_COMMON_PATH/libxt_statistic.c", - "$LIBEXT_COMMON_PATH/libxt_string.c", - "$LIBEXT_COMMON_PATH/libxt_tcp.c", - "$LIBEXT_COMMON_PATH/libxt_tcpmss.c", - "$LIBEXT_COMMON_PATH/libxt_time.c", - "$LIBEXT_COMMON_PATH/libxt_tos.c", - "$LIBEXT_COMMON_PATH/libxt_u32.c", - "$LIBEXT_COMMON_PATH/libxt_udp.c", - ] - include_dirs = [ - "//third_party/iptables", - "//third_party/iptables/extensions", - "//third_party/iptables/include", - "//third_party/iptables/iptables", - "//third_party/iptables/libiptc", - ] - configs = [ ":ext_config" ] - deps = [] - part_name = "netmanager_standard" - subsystem_name = "communication" -} - -args_libext4 = [ - "libipt", - "[]", - "initext4.c", - "extensions4", -] - -exec_script("genInit.py", args_libext4) - -ohos_static_library("libext4") { - sources = [ - "$LIBEXT_COMMON_PATH/initext4.c", - "$LIBEXT_COMMON_PATH/libipt_CLUSTERIP.c", - "$LIBEXT_COMMON_PATH/libipt_DNAT.c", - "$LIBEXT_COMMON_PATH/libipt_ECN.c", - "$LIBEXT_COMMON_PATH/libipt_LOG.c", - "$LIBEXT_COMMON_PATH/libipt_MASQUERADE.c", - "$LIBEXT_COMMON_PATH/libipt_NETMAP.c", - "$LIBEXT_COMMON_PATH/libipt_REDIRECT.c", - "$LIBEXT_COMMON_PATH/libipt_REJECT.c", - "$LIBEXT_COMMON_PATH/libipt_SNAT.c", - "$LIBEXT_COMMON_PATH/libipt_TTL.c", - "$LIBEXT_COMMON_PATH/libipt_ULOG.c", - "$LIBEXT_COMMON_PATH/libipt_ah.c", - "$LIBEXT_COMMON_PATH/libipt_icmp.c", - "$LIBEXT_COMMON_PATH/libipt_realm.c", - "$LIBEXT_COMMON_PATH/libipt_ttl.c", - ] - include_dirs = [ - "//third_party/iptables", - "//third_party/iptables/extensions", - "//third_party/iptables/include", - "//third_party/iptables/iptables", - "//third_party/iptables/libiptc", - ] - cflags = [ - "-D_LARGEFILE_SOURCE=1", - "-D_LARGE_FILES", - "-D_FILE_OFFSET_BITS=64", - "-D_REENTRANT", - "-DENABLE_IPV4", - "-DENABLE_IPV6", - "-Wall", - "-Werror", - "-Wno-pointer-arith", - "-Wno-sign-compare", - "-Wno-unused-parameter", - "-DNO_SHARED_LIBS=1", - "-DXTABLES_INTERNAL", - "-Wno-format", - "-Wno-missing-field-initializers", - "-Wno-pointer-bool-conversion", - "-Wno-tautological-pointer-compare", - ] - deps = [] - part_name = "netmanager_base" - subsystem_name = "communication" -} - -args_libext6 = [ - "libip6t_", - "[]", - "initext6.c", - "extensions6", -] - -exec_script("genInit.py", args_libext6) - -ohos_static_library("libext6") { - sources = [ - "$LIBEXT_COMMON_PATH/initext6.c", - "$LIBEXT_COMMON_PATH/libip6t_DNAT.c", - "$LIBEXT_COMMON_PATH/libip6t_DNPT.c", - "$LIBEXT_COMMON_PATH/libip6t_HL.c", - "$LIBEXT_COMMON_PATH/libip6t_LOG.c", - "$LIBEXT_COMMON_PATH/libip6t_MASQUERADE.c", - "$LIBEXT_COMMON_PATH/libip6t_NETMAP.c", - "$LIBEXT_COMMON_PATH/libip6t_REDIRECT.c", - "$LIBEXT_COMMON_PATH/libip6t_REJECT.c", - "$LIBEXT_COMMON_PATH/libip6t_SNAT.c", - "$LIBEXT_COMMON_PATH/libip6t_SNPT.c", - "$LIBEXT_COMMON_PATH/libip6t_ah.c", - "$LIBEXT_COMMON_PATH/libip6t_dst.c", - "$LIBEXT_COMMON_PATH/libip6t_eui64.c", - "$LIBEXT_COMMON_PATH/libip6t_frag.c", - "$LIBEXT_COMMON_PATH/libip6t_hbh.c", - "$LIBEXT_COMMON_PATH/libip6t_hl.c", - "$LIBEXT_COMMON_PATH/libip6t_icmp6.c", - "$LIBEXT_COMMON_PATH/libip6t_ipv6header.c", - "$LIBEXT_COMMON_PATH/libip6t_mh.c", - "$LIBEXT_COMMON_PATH/libip6t_rt.c", - "$LIBEXT_COMMON_PATH/libip6t_srh.c", - ] - include_dirs = [ - "//third_party/iptables", - "//third_party/iptables/extensions", - "//third_party/iptables/include", - "//third_party/iptables/iptables", - "//third_party/iptables/libiptc", - ] - license_file = "//third_party/iptables/COPYING" - cflags = [ - "-D_LARGEFILE_SOURCE=1", - "-D_LARGE_FILES", - "-D_FILE_OFFSET_BITS=64", - "-D_REENTRANT", - "-DENABLE_IPV4", - "-DENABLE_IPV6", - "-Wall", - "-Werror", - "-Wno-pointer-arith", - "-Wno-sign-compare", - "-Wno-unused-parameter", - "-DNO_SHARED_LIBS=1", - "-DXTABLES_INTERNAL", - "-Wno-format", - "-Wno-missing-field-initializers", - "-Wno-pointer-bool-conversion", - "-Wno-tautological-pointer-compare", - ] - deps = [] - part_name = "netmanager_base" - subsystem_name = "communication" -} diff --git a/extensions/GNUmakefile.in b/extensions/GNUmakefile.in deleted file mode 100644 index 956ccb38..00000000 --- a/extensions/GNUmakefile.in +++ /dev/null @@ -1,307 +0,0 @@ -# -*- Makefile -*- - -top_builddir = @top_builddir@ -builddir = @builddir@ -top_srcdir = @top_srcdir@ -srcdir = @srcdir@ -ksourcedir = @ksourcedir@ -prefix = @prefix@ -exec_prefix = @exec_prefix@ -libdir = @libdir@ -libexecdir = @libexecdir@ -xtlibdir = @xtlibdir@ - -AR = @AR@ -CC = @CC@ -CCLD = ${CC} -CFLAGS = @CFLAGS@ -CPPFLAGS = @CPPFLAGS@ -LDFLAGS = @LDFLAGS@ -regular_CFLAGS = @regular_CFLAGS@ -regular_CPPFLAGS = @regular_CPPFLAGS@ -kinclude_CPPFLAGS = @kinclude_CPPFLAGS@ - -AM_CFLAGS = ${regular_CFLAGS} -AM_CPPFLAGS = ${regular_CPPFLAGS} -I${top_builddir}/include -I${top_builddir} -I${top_srcdir}/include -I${top_srcdir} ${kinclude_CPPFLAGS} ${CPPFLAGS} @libnetfilter_conntrack_CFLAGS@ @libnftnl_CFLAGS@ -AM_DEPFLAGS = -Wp,-MMD,$(@D)/.$(@F).d,-MT,$@ -AM_LDFLAGS = @noundef_LDFLAGS@ - -ifeq (${V},) -AM_LIBTOOL_SILENT = --silent -AM_VERBOSE_CC = @echo " CC " $@; -AM_VERBOSE_CCLD = @echo " CCLD " $@; -AM_VERBOSE_CXX = @echo " CXX " $@; -AM_VERBOSE_CXXLD = @echo " CXXLD " $@; -AM_VERBOSE_AR = @echo " AR " $@; -AM_VERBOSE_GEN = @echo " GEN " $@; -endif - -# -# Wildcard module list -# -pfx_build_mod := $(patsubst ${srcdir}/libxt_%.c,%,$(sort $(wildcard ${srcdir}/libxt_*.c))) -@ENABLE_NFTABLES_TRUE@ pfb_build_mod := $(patsubst ${srcdir}/libebt_%.c,%,$(sort $(wildcard ${srcdir}/libebt_*.c))) -@ENABLE_NFTABLES_TRUE@ pfa_build_mod := $(patsubst ${srcdir}/libarpt_%.c,%,$(sort $(wildcard ${srcdir}/libarpt_*.c))) -pfx_symlinks := NOTRACK state -@ENABLE_IPV4_TRUE@ pf4_build_mod := $(patsubst ${srcdir}/libipt_%.c,%,$(sort $(wildcard ${srcdir}/libipt_*.c))) -@ENABLE_IPV6_TRUE@ pf6_build_mod := $(patsubst ${srcdir}/libip6t_%.c,%,$(sort $(wildcard ${srcdir}/libip6t_*.c))) -pfx_build_mod := $(filter-out @blacklist_modules@ @blacklist_x_modules@,${pfx_build_mod}) -pfb_build_mod := $(filter-out @blacklist_modules@ @blacklist_b_modules@,${pfb_build_mod}) -pfa_build_mod := $(filter-out @blacklist_modules@ @blacklist_a_modules@,${pfa_build_mod}) -pf4_build_mod := $(filter-out @blacklist_modules@ @blacklist_4_modules@,${pf4_build_mod}) -pf6_build_mod := $(filter-out @blacklist_modules@ @blacklist_6_modules@,${pf6_build_mod}) -pfx_objs := $(patsubst %,libxt_%.o,${pfx_build_mod}) -pfb_objs := $(patsubst %,libebt_%.o,${pfb_build_mod}) -pfa_objs := $(patsubst %,libarpt_%.o,${pfa_build_mod}) -pf4_objs := $(patsubst %,libipt_%.o,${pf4_build_mod}) -pf6_objs := $(patsubst %,libip6t_%.o,${pf6_build_mod}) -pfx_solibs := $(patsubst %,libxt_%.so,${pfx_build_mod}) -pfb_solibs := $(patsubst %,libebt_%.so,${pfb_build_mod}) -pfa_solibs := $(patsubst %,libarpt_%.so,${pfa_build_mod}) -pf4_solibs := $(patsubst %,libipt_%.so,${pf4_build_mod}) -pf6_solibs := $(patsubst %,libip6t_%.so,${pf6_build_mod}) -pfx_symlink_files := $(patsubst %,libxt_%.so,${pfx_symlinks}) - - -# -# Building blocks -# -targets := libext.a libext4.a libext6.a libext_ebt.a libext_arpt.a matches.man targets.man -targets_install := -@ENABLE_STATIC_TRUE@ libext_objs := ${pfx_objs} -@ENABLE_STATIC_TRUE@ libext_ebt_objs := ${pfb_objs} -@ENABLE_STATIC_TRUE@ libext_arpt_objs := ${pfa_objs} -@ENABLE_STATIC_TRUE@ libext4_objs := ${pf4_objs} -@ENABLE_STATIC_TRUE@ libext6_objs := ${pf6_objs} -@ENABLE_STATIC_FALSE@ targets += ${pfx_solibs} ${pfb_solibs} ${pf4_solibs} ${pf6_solibs} ${pfa_solibs} ${pfx_symlink_files} -@ENABLE_STATIC_FALSE@ targets_install += ${pfx_solibs} ${pfb_solibs} ${pf4_solibs} ${pf6_solibs} ${pfa_solibs} -@ENABLE_STATIC_FALSE@ symlinks_install := ${pfx_symlink_files} - -.SECONDARY: - -.PHONY: all install uninstall clean distclean FORCE - -all: ${targets} - -install: ${targets_install} ${symlinks_install} - @mkdir -p "${DESTDIR}${xtlibdir}"; - if test -n "${targets_install}"; then \ - install -pm0755 ${targets_install} "${DESTDIR}${xtlibdir}/"; \ - fi; - if test -n "${symlinks_install}"; then \ - cp -P ${symlinks_install} "${DESTDIR}${xtlibdir}/"; \ - fi; - -uninstall: - dir=${DESTDIR}${xtlibdir}; { \ - test ! -d "$$dir" && test ! -f "$$dir" && test ! -r "$$dir"; \ - } || { \ - test -z "${targets_install}" || ( \ - cd "$$dir" && rm -f ${targets_install} \ - ); \ - test -z "${symlinks_install}" || ( \ - cd "$$dir" && rm -f ${symlinks_install} \ - ); \ - rmdir -p --ignore-fail-on-non-empty "$$dir"; \ - } - -clean: - rm -f *.o *.oo *.so *.a {matches,targets}.man initext.c initext4.c initext6.c initextb.c initexta.c; - rm -f .*.d .*.dd; - -distclean: clean - -init%.o: init%.c - ${AM_VERBOSE_CC} ${CC} ${AM_CPPFLAGS} ${AM_DEPFLAGS} ${AM_CFLAGS} -D_INIT=$*_init ${CFLAGS} -o $@ -c $<; - --include .*.d - - -# -# Shared libraries -# -lib%.so: lib%.oo - ${AM_VERBOSE_CCLD} ${CCLD} ${AM_LDFLAGS} ${LDFLAGS} -shared -o $@ $< -L../libxtables/.libs -lxtables ${$*_LIBADD}; - -lib%.oo: ${srcdir}/lib%.c - ${AM_VERBOSE_CC} ${CC} ${AM_CPPFLAGS} ${AM_DEPFLAGS} ${AM_CFLAGS} -D_INIT=lib$*_init -DPIC -fPIC ${CFLAGS} -o $@ -c $<; - -libxt_NOTRACK.so: libxt_CT.so - ln -fs $< $@ -libxt_state.so: libxt_conntrack.so - ln -fs $< $@ - -# Need the LIBADDs in iptables/Makefile.am too for libxtables_la_LIBADD -xt_RATEEST_LIBADD = -lm -xt_statistic_LIBADD = -lm -xt_connlabel_LIBADD = @libnetfilter_conntrack_LIBS@ - -# -# Static bits -# -# If static building is disabled, libext*.a will still be generated, -# but will be empty. This is good since we can do with less case -# handling code in the Makefiles. -# -lib%.o: ${srcdir}/lib%.c - ${AM_VERBOSE_CC} ${CC} ${AM_CPPFLAGS} ${AM_DEPFLAGS} ${AM_CFLAGS} -DNO_SHARED_LIBS=1 -D_INIT=lib$*_init ${CFLAGS} -o $@ -c $<; - -libext.a: initext.o ${libext_objs} - ${AM_VERBOSE_AR} ${AR} crs $@ $^; - -libext_ebt.a: initextb.o ${libext_ebt_objs} - ${AM_VERBOSE_AR} ${AR} crs $@ $^; - -libext_arpt.a: initexta.o ${libext_arpt_objs} - ${AM_VERBOSE_AR} ${AR} crs $@ $^; - -libext4.a: initext4.o ${libext4_objs} - ${AM_VERBOSE_AR} ${AR} crs $@ $^; - -libext6.a: initext6.o ${libext6_objs} - ${AM_VERBOSE_AR} ${AR} crs $@ $^; - -initext_func := $(addprefix xt_,${pfx_build_mod}) -initextb_func := $(addprefix ebt_,${pfb_build_mod}) -initexta_func := $(addprefix arpt_,${pfa_build_mod}) -initext4_func := $(addprefix ipt_,${pf4_build_mod}) -initext6_func := $(addprefix ip6t_,${pf6_build_mod}) - -.initext.dd: FORCE - @echo "${initext_func}" >$@.tmp; \ - cmp -s $@ $@.tmp || mv $@.tmp $@; \ - rm -f $@.tmp; - -.initextb.dd: FORCE - @echo "${initextb_func}" >$@.tmp; \ - cmp -s $@ $@.tmp || mv $@.tmp $@; \ - rm -f $@.tmp; - -.initexta.dd: FORCE - @echo "${initexta_func}" >$@.tmp; \ - cmp -s $@ $@.tmp || mv $@.tmp $@; \ - rm -f $@.tmp; - -.initext4.dd: FORCE - @echo "${initext4_func}" >$@.tmp; \ - cmp -s $@ $@.tmp || mv $@.tmp $@; \ - rm -f $@.tmp; - -.initext6.dd: FORCE - @echo "${initext6_func}" >$@.tmp; \ - cmp -s $@ $@.tmp || mv $@.tmp $@; \ - rm -f $@.tmp; - -initext.c: .initext.dd - ${AM_VERBOSE_GEN} - @( \ - echo "" >$@; \ - for i in ${initext_func}; do \ - echo "extern void lib$${i}_init(void);" >>$@; \ - done; \ - echo "void init_extensions(void);" >>$@; \ - echo "void init_extensions(void)" >>$@; \ - echo "{" >>$@; \ - for i in ${initext_func}; do \ - echo " ""lib$${i}_init();" >>$@; \ - done; \ - echo "}" >>$@; \ - ); - -initextb.c: .initextb.dd - ${AM_VERBOSE_GEN} - @( \ - echo "" >$@; \ - for i in ${initextb_func}; do \ - echo "extern void lib$${i}_init(void);" >>$@; \ - done; \ - echo "void init_extensionsb(void);" >>$@; \ - echo "void init_extensionsb(void)" >>$@; \ - echo "{" >>$@; \ - for i in ${initextb_func}; do \ - echo " ""lib$${i}_init();" >>$@; \ - done; \ - echo "}" >>$@; \ - ); - -initexta.c: .initexta.dd - ${AM_VERBOSE_GEN} - @( \ - echo "" >$@; \ - for i in ${initexta_func}; do \ - echo "extern void lib$${i}_init(void);" >>$@; \ - done; \ - echo "void init_extensionsa(void);" >>$@; \ - echo "void init_extensionsa(void)" >>$@; \ - echo "{" >>$@; \ - for i in ${initexta_func}; do \ - echo " ""lib$${i}_init();" >>$@; \ - done; \ - echo "}" >>$@; \ - ); - -initext4.c: .initext4.dd - ${AM_VERBOSE_GEN} - @( \ - echo "" >$@; \ - for i in ${initext4_func}; do \ - echo "extern void lib$${i}_init(void);" >>$@; \ - done; \ - echo "void init_extensions4(void);" >>$@; \ - echo "void init_extensions4(void)" >>$@; \ - echo "{" >>$@; \ - for i in ${initext4_func}; do \ - echo " ""lib$${i}_init();" >>$@; \ - done; \ - echo "}" >>$@; \ - ); - -initext6.c: .initext6.dd - ${AM_VERBOSE_GEN} - @( \ - echo "" >$@; \ - for i in ${initext6_func}; do \ - echo "extern void lib$${i}_init(void);" >>$@; \ - done; \ - echo "void init_extensions6(void);" >>$@; \ - echo "void init_extensions6(void)" >>$@; \ - echo "{" >>$@; \ - for i in ${initext6_func}; do \ - echo " ""lib$${i}_init();" >>$@; \ - done; \ - echo "}" >>$@; \ - ); - -# -# Manual pages -# -ex_matches = $(shell echo ${1} | LC_ALL=POSIX grep -Eo '\b[[:lower:][:digit:]_]+\b') -ex_targets = $(shell echo ${1} | LC_ALL=POSIX grep -Eo '\b[[:upper:][:digit:]_]+\b') -man_run = \ - ${AM_VERBOSE_GEN} \ - for ext in $(sort ${1}); do \ - f="${srcdir}/libxt_$$ext.man"; \ - if [ -f "$$f" ]; then \ - echo -e "\t+ $$f" >&2; \ - echo ".SS $$ext"; \ - cat "$$f" || exit $$?; \ - fi; \ - f="${srcdir}/libip6t_$$ext.man"; \ - if [ -f "$$f" ]; then \ - echo -e "\t+ $$f" >&2; \ - echo ".SS $$ext (IPv6-specific)"; \ - cat "$$f" || exit $$?; \ - fi; \ - f="${srcdir}/libipt_$$ext.man"; \ - if [ -f "$$f" ]; then \ - echo -e "\t+ $$f" >&2; \ - echo ".SS $$ext (IPv4-specific)"; \ - cat "$$f" || exit $$?; \ - fi; \ - done >$@; - -matches.man: .initext.dd .initextb.dd .initexta.dd .initext4.dd .initext6.dd $(wildcard ${srcdir}/lib*.man) - $(call man_run,$(call ex_matches,${pfx_build_mod} ${pfb_build_mod} ${pfa_build_mod} ${pf4_build_mod} ${pf6_build_mod} ${pfx_symlinks})) - -targets.man: .initext.dd .initextb.dd .initexta.dd .initext4.dd .initext6.dd $(wildcard ${srcdir}/lib*.man) - $(call man_run,$(call ex_targets,${pfx_build_mod} ${pfb_build_mod} ${pfa_build_mod} ${pf4_build_mod} ${pf6_build_mod} ${pfx_symlinks})) diff --git a/extensions/dscp_helper.c b/extensions/dscp_helper.c deleted file mode 100644 index 75b1fece..00000000 --- a/extensions/dscp_helper.c +++ /dev/null @@ -1,79 +0,0 @@ -/* - * DiffServ classname <-> DiffServ codepoint mapping functions. - * - * The latest list of the mappings can be found at: - * - * - * This code is released under the GNU GPL v2, 1991 - * - * Author: Iain Barnes - */ - -#include -#include -#include - - -static const struct ds_class -{ - const char *name; - unsigned int dscp; -} ds_classes[] = -{ - { "CS0", 0x00 }, - { "CS1", 0x08 }, - { "CS2", 0x10 }, - { "CS3", 0x18 }, - { "CS4", 0x20 }, - { "CS5", 0x28 }, - { "CS6", 0x30 }, - { "CS7", 0x38 }, - { "BE", 0x00 }, - { "AF11", 0x0a }, - { "AF12", 0x0c }, - { "AF13", 0x0e }, - { "AF21", 0x12 }, - { "AF22", 0x14 }, - { "AF23", 0x16 }, - { "AF31", 0x1a }, - { "AF32", 0x1c }, - { "AF33", 0x1e }, - { "AF41", 0x22 }, - { "AF42", 0x24 }, - { "AF43", 0x26 }, - { "EF", 0x2e } -}; - - - -static unsigned int -class_to_dscp(const char *name) -{ - unsigned int i; - - for (i = 0; i < ARRAY_SIZE(ds_classes); i++) { - if (!strncasecmp(name, ds_classes[i].name, - strlen(ds_classes[i].name))) - return ds_classes[i].dscp; - } - - xtables_error(PARAMETER_PROBLEM, - "Invalid DSCP value `%s'\n", name); -} - - -#if 0 -static const char * -dscp_to_name(unsigned int dscp) -{ - int i; - - for (i = 0; i < ARRAY_SIZE(ds_classes); ++i) - if (dscp == ds_classes[i].dscp) - return ds_classes[i].name; - - xtables_error(PARAMETER_PROBLEM, - "Invalid DSCP value `%d'\n", dscp); -} -#endif - diff --git a/extensions/genInit.py b/extensions/genInit.py deleted file mode 100755 index 0fda8921..00000000 --- a/extensions/genInit.py +++ /dev/null @@ -1,118 +0,0 @@ -#!/usr/bin/env python -# Copyright (c) 2022 Huawei Device Co., Ltd. -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. - -from dataclasses import replace -import os -import shutil -import sys -import subprocess - - -def _run_cmd(cmd): - print(cmd) - res = subprocess.Popen(cmd, shell=True, stdout=subprocess.PIPE, - stderr=subprocess.PIPE) - sout, serr = res.communicate() - return sout.rstrip().decode('utf-8'), serr, res.returncode - - -def _make_dir(file_path): - is_exist = os.path.exists(file_path) - print (file_path) - if not is_exist: - os.makedirs(file_path) - print (file_path) - - -def _read_file(file_path): - file_handler = open(file_path, 'r+', encoding='utf-8') - content = file_handler.read() - file_handler.close - - return content - -def _write_file(file_path, content): - file_handler = open(file_path, 'w', encoding='utf-8') - file_handler.write(content) - file_handler.close - - -def _write_internal_methods(new_init_file, internal_method_name, init_file_list): - new_init_file.write("void init_" + internal_method_name + "(void);\n") - new_init_file.write("void init_" + internal_method_name + "(void)\n{\n") - for init_file_name in init_file_list: - new_init_file.write(init_file_name) - new_init_file.write("}") - - -def _need_rebuild(src_file, dest_file, src_md5_file): - if os.path.exists(src_file) and os.path.exists(dest_file) and os.path.exists(src_md5_file): - this_md5, err, returncode = _run_cmd("md5sum " + src_file + " | awk '{print $1}'") - last_md5, err, returncode = _run_cmd("cat " + src_md5_file) - if this_md5 == last_md5: - return 0 - else: - return 1 - else: - print("src_file, dest_file or src_md5_file doesn't exist. Generate new md5 file.") - this_md5, err, returncode = _run_cmd("md5sum " + src_file + " | awk '{print $1}' >" + src_md5_file) - return 1 - - -def main(): - # sys.argv[1]: filter pattern - # sys.argv[2]: exclude file list - # sys.argv[3]: output file - # sys.argv[4]: internal method name - ori_path = os.path.dirname(os.path.abspath(__file__)) - out_path = os.path.dirname(os.path.dirname(os.path.dirname(ori_path))) - out_path += "/out" - gen_path = out_path + "/gen" - md5_path = out_path + "/gen/md5" - _make_dir(gen_path) - _make_dir(md5_path) - new_init_file_name = gen_path + "/" + sys.argv[3] - if os.path.exists(new_init_file_name): - os.remove(new_init_file_name) - os.mknod(new_init_file_name) - new_init_file = open(new_init_file_name, 'a', encoding='utf-8') - - init_file_list = [] - for filter_file in os.listdir(ori_path): - file_name, extension = os.path.splitext(filter_file) - if (sys.argv[1] in filter_file) & (extension == ".c") & (filter_file not in sys.argv[2]): - print(filter_file) - src_path = os.path.join(ori_path, filter_file) - src_md5_file = os.path.join(md5_path, filter_file + ".md5") - dst_path = os.path.join(gen_path, filter_file) - need_rebuild = _need_rebuild(src_path, dst_path, src_md5_file) - if need_rebuild: - shutil.copy(src_path, dst_path) - content = _read_file(dst_path) - if "_init(void)" in content: - replace_init_text = filter_file.rstrip("\.c") + "_init(void)" - new_content = content.replace("_init(void)", replace_init_text) - if need_rebuild: - _write_file(dst_path, new_content) - - new_init_file.write("extern " + "void " + replace_init_text + ";\n") - init_file_list.append(filter_file.rstrip("\.c") + "_init" + "();\n") - - internal_method_name = sys.argv[4] - _write_internal_methods(new_init_file, internal_method_name, init_file_list) - new_init_file.close - - -if __name__ == '__main__': - sys.exit(main()) diff --git a/extensions/generic.txlate b/extensions/generic.txlate deleted file mode 100644 index 0e256c37..00000000 --- a/extensions/generic.txlate +++ /dev/null @@ -1,36 +0,0 @@ -iptables-translate -I OUTPUT -p udp -d 8.8.8.8 -j ACCEPT -nft insert rule ip filter OUTPUT ip protocol udp ip daddr 8.8.8.8 counter accept - -iptables-translate -F -t nat -nft flush table ip nat - -iptables-translate -I INPUT -i iifname -s 10.0.0.0/8 -nft insert rule ip filter INPUT iifname "iifname" ip saddr 10.0.0.0/8 counter - -iptables-translate -A INPUT -i iif+ ! -d 10.0.0.0/8 -nft add rule ip filter INPUT iifname "iif*" ip daddr != 10.0.0.0/8 counter - -ebtables-translate -I INPUT -i iname --logical-in ilogname -s 0:0:0:0:0:0 -nft insert rule bridge filter INPUT iifname "iname" meta ibrname "ilogname" ether saddr 00:00:00:00:00:00 counter - -ebtables-translate -A FORWARD ! -i iname --logical-in ilogname -o out+ --logical-out lout+ -d 1:2:3:4:de:af -nft add rule bridge filter FORWARD iifname != "iname" meta ibrname "ilogname" oifname "out*" meta obrname "lout*" ether daddr 01:02:03:04:de:af counter - -ebtables-translate -I INPUT -p ip -d 1:2:3:4:5:6/ff:ff:ff:ff:00:00 -nft insert rule bridge filter INPUT ether type 0x800 ether daddr 01:02:03:04:00:00 and ff:ff:ff:ff:00:00 == 01:02:03:04:00:00 counter - -# asterisk is not special in iptables and it is even a valid interface name -iptables-translate -A FORWARD -i '*' -o 'eth*foo' -nft add rule ip filter FORWARD iifname "\*" oifname "eth\*foo" counter - -# escape all asterisks but translate only the first plus character -iptables-translate -A FORWARD -i 'eth*foo*+' -o 'eth++' -nft add rule ip filter FORWARD iifname "eth\*foo\**" oifname "eth+*" counter - -# skip for always matching interface names -iptables-translate -A FORWARD -i '+' -nft add rule ip filter FORWARD counter - -# match against invalid interface name to simulate never matching rule -iptables-translate -A FORWARD ! -i '+' -nft add rule ip filter FORWARD iifname "INVAL/D" counter diff --git a/extensions/iptables.t b/extensions/iptables.t deleted file mode 100644 index b4b6d677..00000000 --- a/extensions/iptables.t +++ /dev/null @@ -1,6 +0,0 @@ -:FORWARD --i alongifacename0;=;OK --i thisinterfaceistoolong0;;FAIL --i eth+ -o alongifacename+;=;OK -! -i eth0;=;OK -! -o eth+;=;OK diff --git a/extensions/libarpt_CLASSIFY.t b/extensions/libarpt_CLASSIFY.t deleted file mode 100644 index 0cf0f2ce..00000000 --- a/extensions/libarpt_CLASSIFY.t +++ /dev/null @@ -1,4 +0,0 @@ -:OUTPUT --o lo --destination-mac 11:22:33:44:55:66;-o lo --dst-mac 11:22:33:44:55:66;OK ---dst-mac Broadcast ;--dst-mac ff:ff:ff:ff:ff:ff;OK -! -o eth+ -d 1.2.3.4/24 -j CLASSIFY --set-class 0:0;-j CLASSIFY ! -o eth+ -d 1.2.3.0/24 --set-class 0:0;OK diff --git a/extensions/libarpt_MARK.t b/extensions/libarpt_MARK.t deleted file mode 100644 index 3b13d44f..00000000 --- a/extensions/libarpt_MARK.t +++ /dev/null @@ -1,4 +0,0 @@ -:INPUT,OUTPUT --j MARK -d 0.0.0.0/8 --set-mark 1;=;OK --s ! 0.0.0.0 -j MARK --and-mark 0x17;-j MARK ! -s 0.0.0.0 --and-mark 17;OK --j MARK -s 0.0.0.0 --or-mark 17;=;OK diff --git a/extensions/libarpt_mangle.c b/extensions/libarpt_mangle.c deleted file mode 100644 index a2378a8b..00000000 --- a/extensions/libarpt_mangle.c +++ /dev/null @@ -1,193 +0,0 @@ -/* - * Arturo Borrero Gonzalez adapted - * this code to libxtables for arptables-compat in 2015 - */ - -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include "iptables/nft.h" -#include "iptables/nft-arp.h" - -static void arpmangle_print_help(void) -{ - printf( - "mangle target options:\n" - "--mangle-ip-s IP address\n" - "--mangle-ip-d IP address\n" - "--mangle-mac-s MAC address\n" - "--mangle-mac-d MAC address\n" - "--mangle-target target (DROP, CONTINUE or ACCEPT -- default is ACCEPT)\n"); -} - -#define MANGLE_IPS '1' -#define MANGLE_IPT '2' -#define MANGLE_DEVS '3' -#define MANGLE_DEVT '4' -#define MANGLE_TARGET '5' - -static const struct option arpmangle_opts[] = { - { .name = "mangle-ip-s", .has_arg = true, .val = MANGLE_IPS }, - { .name = "mangle-ip-d", .has_arg = true, .val = MANGLE_IPT }, - { .name = "mangle-mac-s", .has_arg = true, .val = MANGLE_DEVS }, - { .name = "mangle-mac-d", .has_arg = true, .val = MANGLE_DEVT }, - { .name = "mangle-target", .has_arg = true, .val = MANGLE_TARGET }, - XT_GETOPT_TABLEEND, -}; - -static void arpmangle_init(struct xt_entry_target *target) -{ - struct arpt_mangle *mangle = (struct arpt_mangle *)target->data; - - mangle->target = NF_ACCEPT; -} - -static int -arpmangle_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_target **target) -{ - struct arpt_mangle *mangle = (struct arpt_mangle *)(*target)->data; - struct in_addr *ipaddr, mask; - struct ether_addr *macaddr; - const struct arpt_entry *e = (const struct arpt_entry *)entry; - unsigned int nr; - int ret = 1; - - memset(&mask, 0, sizeof(mask)); - - switch (c) { - case MANGLE_IPS: - xtables_ipparse_any(optarg, &ipaddr, &mask, &nr); - mangle->u_s.src_ip.s_addr = ipaddr->s_addr; - free(ipaddr); - mangle->flags |= ARPT_MANGLE_SIP; - break; - case MANGLE_IPT: - xtables_ipparse_any(optarg, &ipaddr, &mask, &nr); - mangle->u_t.tgt_ip.s_addr = ipaddr->s_addr; - free(ipaddr); - mangle->flags |= ARPT_MANGLE_TIP; - break; - case MANGLE_DEVS: - if (e->arp.arhln_mask == 0) - xtables_error(PARAMETER_PROBLEM, - "no --h-length defined"); - if (e->arp.invflags & ARPT_INV_ARPHLN) - xtables_error(PARAMETER_PROBLEM, - "! --h-length not allowed for " - "--mangle-mac-s"); - if (e->arp.arhln != 6) - xtables_error(PARAMETER_PROBLEM, - "only --h-length 6 supported"); - macaddr = ether_aton(optarg); - if (macaddr == NULL) - xtables_error(PARAMETER_PROBLEM, - "invalid source MAC"); - memcpy(mangle->src_devaddr, macaddr, e->arp.arhln); - mangle->flags |= ARPT_MANGLE_SDEV; - break; - case MANGLE_DEVT: - if (e->arp.arhln_mask == 0) - xtables_error(PARAMETER_PROBLEM, - "no --h-length defined"); - if (e->arp.invflags & ARPT_INV_ARPHLN) - xtables_error(PARAMETER_PROBLEM, - "! hln not allowed for --mangle-mac-d"); - if (e->arp.arhln != 6) - xtables_error(PARAMETER_PROBLEM, - "only --h-length 6 supported"); - macaddr = ether_aton(optarg); - if (macaddr == NULL) - xtables_error(PARAMETER_PROBLEM, "invalid target MAC"); - memcpy(mangle->tgt_devaddr, macaddr, e->arp.arhln); - mangle->flags |= ARPT_MANGLE_TDEV; - break; - case MANGLE_TARGET: - if (!strcmp(optarg, "DROP")) - mangle->target = NF_DROP; - else if (!strcmp(optarg, "ACCEPT")) - mangle->target = NF_ACCEPT; - else if (!strcmp(optarg, "CONTINUE")) - mangle->target = XT_CONTINUE; - else - xtables_error(PARAMETER_PROBLEM, - "bad target for --mangle-target"); - break; - default: - ret = 0; - } - - return ret; -} - -static void arpmangle_final_check(unsigned int flags) -{ -} - -static const char *ipaddr_to(const struct in_addr *addrp, int numeric) -{ - if (numeric) - return xtables_ipaddr_to_numeric(addrp); - else - return xtables_ipaddr_to_anyname(addrp); -} - -static void -arpmangle_print(const void *ip, const struct xt_entry_target *target, - int numeric) -{ - struct arpt_mangle *m = (struct arpt_mangle *)(target->data); - - if (m->flags & ARPT_MANGLE_SIP) { - printf(" --mangle-ip-s %s", - ipaddr_to(&(m->u_s.src_ip), numeric)); - } - if (m->flags & ARPT_MANGLE_SDEV) { - printf(" --mangle-mac-s "); - xtables_print_mac((unsigned char *)m->src_devaddr); - } - if (m->flags & ARPT_MANGLE_TIP) { - printf(" --mangle-ip-d %s", - ipaddr_to(&(m->u_t.tgt_ip), numeric)); - } - if (m->flags & ARPT_MANGLE_TDEV) { - printf(" --mangle-mac-d "); - xtables_print_mac((unsigned char *)m->tgt_devaddr); - } - if (m->target != NF_ACCEPT) { - printf(" --mangle-target %s", - m->target == NF_DROP ? "DROP" : "CONTINUE"); - } -} - -static void arpmangle_save(const void *ip, const struct xt_entry_target *target) -{ - arpmangle_print(ip, target, 0); -} - -static struct xtables_target arpmangle_target = { - .name = "mangle", - .revision = 0, - .version = XTABLES_VERSION, - .family = NFPROTO_ARP, - .size = XT_ALIGN(sizeof(struct arpt_mangle)), - .userspacesize = XT_ALIGN(sizeof(struct arpt_mangle)), - .help = arpmangle_print_help, - .init = arpmangle_init, - .parse = arpmangle_parse, - .final_check = arpmangle_final_check, - .print = arpmangle_print, - .save = arpmangle_save, - .extra_opts = arpmangle_opts, -}; - -void _init(void) -{ - xtables_register_target(&arpmangle_target); -} diff --git a/extensions/libarpt_mangle.t b/extensions/libarpt_mangle.t deleted file mode 100644 index da966948..00000000 --- a/extensions/libarpt_mangle.t +++ /dev/null @@ -1,5 +0,0 @@ -:OUTPUT --j mangle -s 1.2.3.4 --mangle-ip-s 1.2.3.5;=;OK --j mangle -d 1.2.3.4 --mangle-ip-d 1.2.3.5;=;OK --j mangle -d 1.2.3.4 --mangle-mac-d 00:01:02:03:04:05;=;OK --d 1.2.3.4 --h-length 5 -j mangle --mangle-mac-s 00:01:02:03:04:05;=;FAIL diff --git a/extensions/libarpt_standard.t b/extensions/libarpt_standard.t deleted file mode 100644 index e84a00b7..00000000 --- a/extensions/libarpt_standard.t +++ /dev/null @@ -1,14 +0,0 @@ -:INPUT --s 192.168.0.1;=;OK --s 0.0.0.0/8;=;OK --s ! 0.0.0.0;! -s 0.0.0.0;OK --d 192.168.0.1;=;OK -! -d 0.0.0.0;=;OK --d 0.0.0.0/24;=;OK --j DROP -i lo;=;OK --j ACCEPT ! -i lo;=;OK --i ppp+;=;OK -! -i ppp+;=;OK --i lo --destination-mac 11:22:33:44:55:66;-i lo --dst-mac 11:22:33:44:55:66;OK ---source-mac Unicast;--src-mac 00:00:00:00:00:00/01:00:00:00:00:00;OK -! --src-mac Multicast;! --src-mac 01:00:00:00:00:00/01:00:00:00:00:00;OK diff --git a/extensions/libebt_802_3.c b/extensions/libebt_802_3.c deleted file mode 100644 index f05d02ea..00000000 --- a/extensions/libebt_802_3.c +++ /dev/null @@ -1,133 +0,0 @@ -/* 802_3 - * - * Author: - * Chris Vitale - * - * May 2003 - * - * Adapted by Arturo Borrero Gonzalez - * to use libxtables for ebtables-compat - */ - -#include -#include -#include -#include -#include -#include -#include - -#define _802_3_SAP '1' -#define _802_3_TYPE '2' - -static const struct option br802_3_opts[] = { - { .name = "802_3-sap", .has_arg = true, .val = _802_3_SAP }, - { .name = "802_3-type", .has_arg = true, .val = _802_3_TYPE }, - XT_GETOPT_TABLEEND, -}; - -static void br802_3_print_help(void) -{ - printf( -"802_3 options:\n" -"--802_3-sap [!] protocol : 802.3 DSAP/SSAP- 1 byte value (hex)\n" -" DSAP and SSAP are always the same. One SAP applies to both fields\n" -"--802_3-type [!] protocol : 802.3 SNAP Type- 2 byte value (hex)\n" -" Type implies SAP value 0xaa\n"); -} - -static void br802_3_init(struct xt_entry_match *match) -{ - struct ebt_802_3_info *info = (struct ebt_802_3_info *)match->data; - - info->invflags = 0; - info->bitmask = 0; -} - -static int -br802_3_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_match **match) -{ - struct ebt_802_3_info *info = (struct ebt_802_3_info *) (*match)->data; - unsigned int i; - char *end; - - switch (c) { - case _802_3_SAP: - if (invert) - info->invflags |= EBT_802_3_SAP; - i = strtoul(optarg, &end, 16); - if (i > 255 || *end != '\0') - xtables_error(PARAMETER_PROBLEM, - "Problem with specified " - "sap hex value, %x",i); - info->sap = i; /* one byte, so no byte order worries */ - info->bitmask |= EBT_802_3_SAP; - break; - case _802_3_TYPE: - if (invert) - info->invflags |= EBT_802_3_TYPE; - i = strtoul(optarg, &end, 16); - if (i > 65535 || *end != '\0') { - xtables_error(PARAMETER_PROBLEM, - "Problem with the specified " - "type hex value, %x",i); - } - info->type = htons(i); - info->bitmask |= EBT_802_3_TYPE; - break; - default: - return 0; - } - - *flags |= info->bitmask; - return 1; -} - -static void -br802_3_final_check(unsigned int flags) -{ - if (!flags) - xtables_error(PARAMETER_PROBLEM, - "You must specify proper arguments"); -} - -static void br802_3_print(const void *ip, const struct xt_entry_match *match, - int numeric) -{ - struct ebt_802_3_info *info = (struct ebt_802_3_info *)match->data; - - if (info->bitmask & EBT_802_3_SAP) { - printf("--802_3-sap "); - if (info->invflags & EBT_802_3_SAP) - printf("! "); - printf("0x%.2x ", info->sap); - } - if (info->bitmask & EBT_802_3_TYPE) { - printf("--802_3-type "); - if (info->invflags & EBT_802_3_TYPE) - printf("! "); - printf("0x%.4x ", ntohs(info->type)); - } -} - -static struct xtables_match br802_3_match = -{ - .name = "802_3", - .revision = 0, - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_802_3_info)), - .userspacesize = XT_ALIGN(sizeof(struct ebt_802_3_info)), - .init = br802_3_init, - .help = br802_3_print_help, - .parse = br802_3_parse, - .final_check = br802_3_final_check, - .print = br802_3_print, - .extra_opts = br802_3_opts, -}; - -void _init(void) -{ - xtables_register_match(&br802_3_match); -} diff --git a/extensions/libebt_802_3.t b/extensions/libebt_802_3.t deleted file mode 100644 index ddfb2f0a..00000000 --- a/extensions/libebt_802_3.t +++ /dev/null @@ -1,3 +0,0 @@ -:INPUT,FORWARD,OUTPUT ---802_3-sap ! 0x0a -j CONTINUE;=;OK ---802_3-type 0x000a -j RETURN;=;OK diff --git a/extensions/libebt_among.c b/extensions/libebt_among.c deleted file mode 100644 index 2b9a1b65..00000000 --- a/extensions/libebt_among.c +++ /dev/null @@ -1,243 +0,0 @@ -/* ebt_among - * - * Authors: - * Grzegorz Borowiak - * - * August, 2003 - */ - -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include "iptables/nft.h" -#include "iptables/nft-bridge.h" - -#define AMONG_DST '1' -#define AMONG_SRC '2' -#define AMONG_DST_F '3' -#define AMONG_SRC_F '4' - -static const struct option bramong_opts[] = { - {"among-dst", required_argument, 0, AMONG_DST}, - {"among-src", required_argument, 0, AMONG_SRC}, - {"among-dst-file", required_argument, 0, AMONG_DST_F}, - {"among-src-file", required_argument, 0, AMONG_SRC_F}, - {0} -}; - -static void bramong_print_help(void) -{ - printf( -"`among' options:\n" -"--among-dst [!] list : matches if ether dst is in list\n" -"--among-src [!] list : matches if ether src is in list\n" -"--among-dst-file [!] file : obtain dst list from file\n" -"--among-src-file [!] file : obtain src list from file\n" -"list has form:\n" -" xx:xx:xx:xx:xx:xx[=ip.ip.ip.ip],yy:yy:yy:yy:yy:yy[=ip.ip.ip.ip]" -",...,zz:zz:zz:zz:zz:zz[=ip.ip.ip.ip][,]\n" -"Things in brackets are optional.\n" -"If you want to allow two (or more) IP addresses to one MAC address, you\n" -"can specify two (or more) pairs with the same MAC, e.g.\n" -" 00:00:00:fa:eb:fe=153.19.120.250,00:00:00:fa:eb:fe=192.168.0.1\n" - ); -} - -static void -parse_nft_among_pair(char *buf, struct nft_among_pair *pair, bool have_ip) -{ - char *sep = index(buf, '='); - struct ether_addr *ether; - - if (sep) { - *sep = '\0'; - - if (!inet_aton(sep + 1, &pair->in)) - xtables_error(PARAMETER_PROBLEM, - "Invalid IP address '%s'\n", sep + 1); - } - ether = ether_aton(buf); - if (!ether) - xtables_error(PARAMETER_PROBLEM, - "Invalid MAC address '%s'\n", buf); - memcpy(&pair->ether, ether, sizeof(*ether)); -} - -static void -parse_nft_among_pairs(struct nft_among_pair *pairs, char *buf, - size_t cnt, bool have_ip) -{ - size_t tmpcnt = 0; - - buf = strtok(buf, ","); - while (buf) { - struct nft_among_pair pair = {}; - - parse_nft_among_pair(buf, &pair, have_ip); - nft_among_insert_pair(pairs, &tmpcnt, &pair); - buf = strtok(NULL, ","); - } -} - -static size_t count_nft_among_pairs(char *buf) -{ - size_t cnt = 0; - char *p = buf; - - if (!*buf) - return 0; - - do { - cnt++; - p = index(++p, ','); - } while (p); - - return cnt; -} - -static bool nft_among_pairs_have_ip(char *buf) -{ - return !!index(buf, '='); -} - -static int bramong_parse(int c, char **argv, int invert, - unsigned int *flags, const void *entry, - struct xt_entry_match **match) -{ - struct nft_among_data *data = (struct nft_among_data *)(*match)->data; - struct xt_entry_match *new_match; - bool have_ip, dst = false; - size_t new_size, cnt; - struct stat stats; - int fd = -1, poff; - long flen = 0; - - switch (c) { - case AMONG_DST_F: - dst = true; - /* fall through */ - case AMONG_SRC_F: - if ((fd = open(optarg, O_RDONLY)) == -1) - xtables_error(PARAMETER_PROBLEM, - "Couldn't open file '%s'", optarg); - if (fstat(fd, &stats) < 0) - xtables_error(PARAMETER_PROBLEM, - "fstat(%s) failed: '%s'", - optarg, strerror(errno)); - flen = stats.st_size; - /* use mmap because the file will probably be big */ - optarg = mmap(0, flen, PROT_READ | PROT_WRITE, - MAP_PRIVATE, fd, 0); - if (optarg == MAP_FAILED) - xtables_error(PARAMETER_PROBLEM, - "Couldn't map file to memory"); - if (optarg[flen-1] != '\n') - xtables_error(PARAMETER_PROBLEM, - "File should end with a newline"); - if (strchr(optarg, '\n') != optarg+flen-1) - xtables_error(PARAMETER_PROBLEM, - "File should only contain one line"); - optarg[flen-1] = '\0'; - /* fall through */ - case AMONG_DST: - if (c == AMONG_DST) - dst = true; - /* fall through */ - case AMONG_SRC: - break; - default: - return 0; - } - - cnt = count_nft_among_pairs(optarg); - if (cnt == 0) - return 0; - - new_size = data->src.cnt + data->dst.cnt + cnt; - new_size *= sizeof(struct nft_among_pair); - new_size += XT_ALIGN(sizeof(struct xt_entry_match)) + - sizeof(struct nft_among_data); - new_match = xtables_calloc(1, new_size); - memcpy(new_match, *match, (*match)->u.match_size); - new_match->u.match_size = new_size; - - data = (struct nft_among_data *)new_match->data; - have_ip = nft_among_pairs_have_ip(optarg); - poff = nft_among_prepare_data(data, dst, cnt, invert, have_ip); - parse_nft_among_pairs(data->pairs + poff, optarg, cnt, have_ip); - - free(*match); - *match = new_match; - - if (c == AMONG_DST_F || c == AMONG_SRC_F) { - munmap(argv, flen); - close(fd); - } - return 1; -} - -static void __bramong_print(struct nft_among_pair *pairs, - int cnt, bool inv, bool have_ip) -{ - const char *isep = inv ? "! " : ""; - int i; - - for (i = 0; i < cnt; i++) { - printf("%s", isep); - isep = ","; - - printf("%s", ether_ntoa(&pairs[i].ether)); - if (pairs[i].in.s_addr != INADDR_ANY) - printf("=%s", inet_ntoa(pairs[i].in)); - } - printf(" "); -} - -static void bramong_print(const void *ip, const struct xt_entry_match *match, - int numeric) -{ - struct nft_among_data *data = (struct nft_among_data *)match->data; - - if (data->src.cnt) { - printf("--among-src "); - __bramong_print(data->pairs, - data->src.cnt, data->src.inv, data->src.ip); - } - if (data->dst.cnt) { - printf("--among-dst "); - __bramong_print(data->pairs + data->src.cnt, - data->dst.cnt, data->dst.inv, data->dst.ip); - } -} - -static struct xtables_match bramong_match = { - .name = "among", - .revision = 0, - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct nft_among_data)), - .userspacesize = XT_ALIGN(sizeof(struct nft_among_data)), - .help = bramong_print_help, - .parse = bramong_parse, - .print = bramong_print, - .extra_opts = bramong_opts, -}; - -void _init(void) -{ - xtables_register_match(&bramong_match); -} diff --git a/extensions/libebt_among.t b/extensions/libebt_among.t deleted file mode 100644 index a02206f3..00000000 --- a/extensions/libebt_among.t +++ /dev/null @@ -1,16 +0,0 @@ -:INPUT,FORWARD,OUTPUT ---among-dst de:ad:0:be:ee:ff,c0:ff:ee:0:ba:be;--among-dst c0:ff:ee:0:ba:be,de:ad:0:be:ee:ff;OK ---among-dst ! c0:ff:ee:0:ba:be,de:ad:0:be:ee:ff;=;OK ---among-src be:ef:0:c0:ff:ee,c0:ff:ee:0:ba:be,de:ad:0:be:ee:ff;=;OK ---among-src de:ad:0:be:ee:ff=10.0.0.1,c0:ff:ee:0:ba:be=192.168.1.1;--among-src c0:ff:ee:0:ba:be=192.168.1.1,de:ad:0:be:ee:ff=10.0.0.1;OK ---among-src ! c0:ff:ee:0:ba:be=192.168.1.1,de:ad:0:be:ee:ff=10.0.0.1;=;OK ---among-src de:ad:0:be:ee:ff --among-dst c0:ff:ee:0:ba:be;=;OK ---among-src de:ad:0:be:ee:ff=10.0.0.1 --among-dst c0:ff:ee:0:ba:be=192.168.1.1;=;OK ---among-src ! de:ad:0:be:ee:ff --among-dst c0:ff:ee:0:ba:be;=;OK ---among-src de:ad:0:be:ee:ff=10.0.0.1 --among-dst ! c0:ff:ee:0:ba:be=192.168.1.1;=;OK ---among-src ! de:ad:0:be:ee:ff --among-dst c0:ff:ee:0:ba:be=192.168.1.1;=;OK ---among-src de:ad:0:be:ee:ff=10.0.0.1 --among-dst ! c0:ff:ee:0:ba:be=192.168.1.1;=;OK ---among-src;=;FAIL ---among-src 00:11=10.0.0.1;=;FAIL ---among-src de:ad:0:be:ee:ff=10.256.0.1;=;FAIL ---among-src c0:ff:ee:0:ba:be=192.168.1.1,de:ad:0:be:ee:ff;=;OK diff --git a/extensions/libebt_arp.c b/extensions/libebt_arp.c deleted file mode 100644 index d5035b95..00000000 --- a/extensions/libebt_arp.c +++ /dev/null @@ -1,363 +0,0 @@ -/* ebt_arp - * - * Authors: - * Bart De Schuymer - * Tim Gardner - * - * April, 2002 - */ - -#include -#include -#include -#include -#include -#include - -#include -#include -#include -#include "iptables/nft.h" -#include "iptables/nft-bridge.h" - -#define ARP_OPCODE '1' -#define ARP_HTYPE '2' -#define ARP_PTYPE '3' -#define ARP_IP_S '4' -#define ARP_IP_D '5' -#define ARP_MAC_S '6' -#define ARP_MAC_D '7' -#define ARP_GRAT '8' - -static const struct option brarp_opts[] = { - { "arp-opcode" , required_argument, 0, ARP_OPCODE }, - { "arp-op" , required_argument, 0, ARP_OPCODE }, - { "arp-htype" , required_argument, 0, ARP_HTYPE }, - { "arp-ptype" , required_argument, 0, ARP_PTYPE }, - { "arp-ip-src" , required_argument, 0, ARP_IP_S }, - { "arp-ip-dst" , required_argument, 0, ARP_IP_D }, - { "arp-mac-src" , required_argument, 0, ARP_MAC_S }, - { "arp-mac-dst" , required_argument, 0, ARP_MAC_D }, - { "arp-gratuitous", no_argument, 0, ARP_GRAT }, - XT_GETOPT_TABLEEND, -}; - -/* a few names */ -static char *opcodes[] = -{ - "Request", - "Reply", - "Request_Reverse", - "Reply_Reverse", - "DRARP_Request", - "DRARP_Reply", - "DRARP_Error", - "InARP_Request", - "ARP_NAK", -}; - -static void brarp_print_help(void) -{ - int i; - - printf( -"arp options:\n" -"--arp-opcode [!] opcode : ARP opcode (integer or string)\n" -"--arp-htype [!] type : ARP hardware type (integer or string)\n" -"--arp-ptype [!] type : ARP protocol type (hexadecimal or string)\n" -"--arp-ip-src [!] address[/mask]: ARP IP source specification\n" -"--arp-ip-dst [!] address[/mask]: ARP IP target specification\n" -"--arp-mac-src [!] address[/mask]: ARP MAC source specification\n" -"--arp-mac-dst [!] address[/mask]: ARP MAC target specification\n" -"[!] --arp-gratuitous : ARP gratuitous packet\n" -" opcode strings: \n"); - for (i = 0; i < ARRAY_SIZE(opcodes); i++) - printf(" %d = %s\n", i + 1, opcodes[i]); - printf( -" hardware type string: 1 = Ethernet\n" -" protocol type string: see "XT_PATH_ETHERTYPES"\n"); -} - -#define OPT_OPCODE 0x01 -#define OPT_HTYPE 0x02 -#define OPT_PTYPE 0x04 -#define OPT_IP_S 0x08 -#define OPT_IP_D 0x10 -#define OPT_MAC_S 0x20 -#define OPT_MAC_D 0x40 -#define OPT_GRAT 0x80 - -static int undot_ip(char *ip, unsigned char *ip2) -{ - char *p, *q, *end; - long int onebyte; - int i; - char buf[20]; - - strncpy(buf, ip, sizeof(buf) - 1); - - p = buf; - for (i = 0; i < 3; i++) { - if ((q = strchr(p, '.')) == NULL) - return -1; - *q = '\0'; - onebyte = strtol(p, &end, 10); - if (*end != '\0' || onebyte > 255 || onebyte < 0) - return -1; - ip2[i] = (unsigned char)onebyte; - p = q + 1; - } - - onebyte = strtol(p, &end, 10); - if (*end != '\0' || onebyte > 255 || onebyte < 0) - return -1; - ip2[3] = (unsigned char)onebyte; - - return 0; -} - -static int ip_mask(char *mask, unsigned char *mask2) -{ - char *end; - long int bits; - uint32_t mask22; - - if (undot_ip(mask, mask2)) { - /* not the /a.b.c.e format, maybe the /x format */ - bits = strtol(mask, &end, 10); - if (*end != '\0' || bits > 32 || bits < 0) - return -1; - if (bits != 0) { - mask22 = htonl(0xFFFFFFFF << (32 - bits)); - memcpy(mask2, &mask22, 4); - } else { - mask22 = 0xFFFFFFFF; - memcpy(mask2, &mask22, 4); - } - } - return 0; -} - -static void ebt_parse_ip_address(char *address, uint32_t *addr, uint32_t *msk) -{ - char *p; - - /* first the mask */ - if ((p = strrchr(address, '/')) != NULL) { - *p = '\0'; - if (ip_mask(p + 1, (unsigned char *)msk)) { - xtables_error(PARAMETER_PROBLEM, - "Problem with the IP mask '%s'", p + 1); - return; - } - } else - *msk = 0xFFFFFFFF; - - if (undot_ip(address, (unsigned char *)addr)) { - xtables_error(PARAMETER_PROBLEM, - "Problem with the IP address '%s'", address); - return; - } - *addr = *addr & *msk; -} - -static int -brarp_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_match **match) -{ - struct ebt_arp_info *arpinfo = (struct ebt_arp_info *)(*match)->data; - long int i; - char *end; - uint32_t *addr; - uint32_t *mask; - unsigned char *maddr; - unsigned char *mmask; - - switch (c) { - case ARP_OPCODE: - EBT_CHECK_OPTION(flags, OPT_OPCODE); - if (invert) - arpinfo->invflags |= EBT_ARP_OPCODE; - i = strtol(optarg, &end, 10); - if (i < 0 || i >= (0x1 << 16) || *end !='\0') { - for (i = 0; i < ARRAY_SIZE(opcodes); i++) - if (!strcasecmp(opcodes[i], optarg)) - break; - if (i == ARRAY_SIZE(opcodes)) - xtables_error(PARAMETER_PROBLEM, "Problem with specified ARP opcode"); - i++; - } - arpinfo->opcode = htons(i); - arpinfo->bitmask |= EBT_ARP_OPCODE; - break; - - case ARP_HTYPE: - EBT_CHECK_OPTION(flags, OPT_HTYPE); - if (invert) - arpinfo->invflags |= EBT_ARP_HTYPE; - i = strtol(optarg, &end, 10); - if (i < 0 || i >= (0x1 << 16) || *end !='\0') { - if (!strcasecmp("Ethernet", argv[optind - 1])) - i = 1; - else - xtables_error(PARAMETER_PROBLEM, "Problem with specified ARP hardware type"); - } - arpinfo->htype = htons(i); - arpinfo->bitmask |= EBT_ARP_HTYPE; - break; - case ARP_PTYPE: { - uint16_t proto; - - EBT_CHECK_OPTION(flags, OPT_PTYPE); - if (invert) - arpinfo->invflags |= EBT_ARP_PTYPE; - - i = strtol(optarg, &end, 16); - if (i < 0 || i >= (0x1 << 16) || *end !='\0') { - struct xt_ethertypeent *ent; - - ent = xtables_getethertypebyname(argv[optind - 1]); - if (!ent) - xtables_error(PARAMETER_PROBLEM, "Problem with specified ARP " - "protocol type"); - proto = ent->e_ethertype; - - } else - proto = i; - arpinfo->ptype = htons(proto); - arpinfo->bitmask |= EBT_ARP_PTYPE; - break; - } - - case ARP_IP_S: - case ARP_IP_D: - if (c == ARP_IP_S) { - EBT_CHECK_OPTION(flags, OPT_IP_S); - addr = &arpinfo->saddr; - mask = &arpinfo->smsk; - arpinfo->bitmask |= EBT_ARP_SRC_IP; - } else { - EBT_CHECK_OPTION(flags, OPT_IP_D); - addr = &arpinfo->daddr; - mask = &arpinfo->dmsk; - arpinfo->bitmask |= EBT_ARP_DST_IP; - } - if (invert) { - if (c == ARP_IP_S) - arpinfo->invflags |= EBT_ARP_SRC_IP; - else - arpinfo->invflags |= EBT_ARP_DST_IP; - } - ebt_parse_ip_address(optarg, addr, mask); - break; - case ARP_MAC_S: - case ARP_MAC_D: - if (c == ARP_MAC_S) { - EBT_CHECK_OPTION(flags, OPT_MAC_S); - maddr = arpinfo->smaddr; - mmask = arpinfo->smmsk; - arpinfo->bitmask |= EBT_ARP_SRC_MAC; - } else { - EBT_CHECK_OPTION(flags, OPT_MAC_D); - maddr = arpinfo->dmaddr; - mmask = arpinfo->dmmsk; - arpinfo->bitmask |= EBT_ARP_DST_MAC; - } - if (invert) { - if (c == ARP_MAC_S) - arpinfo->invflags |= EBT_ARP_SRC_MAC; - else - arpinfo->invflags |= EBT_ARP_DST_MAC; - } - if (xtables_parse_mac_and_mask(optarg, maddr, mmask)) - xtables_error(PARAMETER_PROBLEM, "Problem with ARP MAC address argument"); - break; - case ARP_GRAT: - EBT_CHECK_OPTION(flags, OPT_GRAT); - arpinfo->bitmask |= EBT_ARP_GRAT; - if (invert) - arpinfo->invflags |= EBT_ARP_GRAT; - break; - default: - return 0; - } - return 1; -} - -static void brarp_print(const void *ip, const struct xt_entry_match *match, int numeric) -{ - const struct ebt_arp_info *arpinfo = (struct ebt_arp_info *)match->data; - - if (arpinfo->bitmask & EBT_ARP_OPCODE) { - int opcode = ntohs(arpinfo->opcode); - printf("--arp-op "); - if (arpinfo->invflags & EBT_ARP_OPCODE) - printf("! "); - if (opcode > 0 && opcode <= ARRAY_SIZE(opcodes)) - printf("%s ", opcodes[opcode - 1]); - else - printf("%d ", opcode); - } - if (arpinfo->bitmask & EBT_ARP_HTYPE) { - printf("--arp-htype "); - if (arpinfo->invflags & EBT_ARP_HTYPE) - printf("! "); - printf("%d ", ntohs(arpinfo->htype)); - } - if (arpinfo->bitmask & EBT_ARP_PTYPE) { - printf("--arp-ptype "); - if (arpinfo->invflags & EBT_ARP_PTYPE) - printf("! "); - printf("0x%x ", ntohs(arpinfo->ptype)); - } - if (arpinfo->bitmask & EBT_ARP_SRC_IP) { - printf("--arp-ip-src "); - if (arpinfo->invflags & EBT_ARP_SRC_IP) - printf("! "); - printf("%s%s ", xtables_ipaddr_to_numeric((const struct in_addr*) &arpinfo->saddr), - xtables_ipmask_to_numeric((const struct in_addr*)&arpinfo->smsk)); - } - if (arpinfo->bitmask & EBT_ARP_DST_IP) { - printf("--arp-ip-dst "); - if (arpinfo->invflags & EBT_ARP_DST_IP) - printf("! "); - printf("%s%s ", xtables_ipaddr_to_numeric((const struct in_addr*) &arpinfo->daddr), - xtables_ipmask_to_numeric((const struct in_addr*)&arpinfo->dmsk)); - } - if (arpinfo->bitmask & EBT_ARP_SRC_MAC) { - printf("--arp-mac-src "); - if (arpinfo->invflags & EBT_ARP_SRC_MAC) - printf("! "); - xtables_print_mac_and_mask(arpinfo->smaddr, arpinfo->smmsk); - printf(" "); - } - if (arpinfo->bitmask & EBT_ARP_DST_MAC) { - printf("--arp-mac-dst "); - if (arpinfo->invflags & EBT_ARP_DST_MAC) - printf("! "); - xtables_print_mac_and_mask(arpinfo->dmaddr, arpinfo->dmmsk); - printf(" "); - } - if (arpinfo->bitmask & EBT_ARP_GRAT) { - if (arpinfo->invflags & EBT_ARP_GRAT) - printf("! "); - printf("--arp-gratuitous "); - } -} - -static struct xtables_match brarp_match = { - .name = "arp", - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_arp_info)), - .userspacesize = XT_ALIGN(sizeof(struct ebt_arp_info)), - .help = brarp_print_help, - .parse = brarp_parse, - .print = brarp_print, - .extra_opts = brarp_opts, -}; - -void _init(void) -{ - xtables_register_match(&brarp_match); -} diff --git a/extensions/libebt_arp.t b/extensions/libebt_arp.t deleted file mode 100644 index 14ff0f09..00000000 --- a/extensions/libebt_arp.t +++ /dev/null @@ -1,12 +0,0 @@ -:INPUT,FORWARD,OUTPUT --p ARP --arp-op Request;=;OK --p ARP --arp-htype ! 1;=;OK --p ARP --arp-ptype 0x2;=;OK --p ARP --arp-ip-src 1.2.3.4;=;OK --p ARP ! --arp-ip-dst 1.2.3.4;-p ARP --arp-ip-dst ! 1.2.3.4 -j CONTINUE;OK --p ARP --arp-ip-src ! 0.0.0.0;=;OK --p ARP --arp-ip-dst ! 0.0.0.0/8;=;OK --p ARP --arp-mac-src 00:de:ad:be:ef:00;=;OK --p ARP --arp-mac-dst de:ad:be:ef:00:00/ff:ff:ff:ff:00:00;=;OK --p ARP --arp-gratuitous;=;OK ---arp-htype 1;=;FAIL diff --git a/extensions/libebt_arpreply.c b/extensions/libebt_arpreply.c deleted file mode 100644 index 80ba2159..00000000 --- a/extensions/libebt_arpreply.c +++ /dev/null @@ -1,101 +0,0 @@ -/* ebt_arpreply - * - * Authors: - * Grzegorz Borowiak - * Bart De Schuymer - * - * August, 2003 - */ - -#include -#include -#include -#include -#include -#include -#include -#include "iptables/nft.h" -#include "iptables/nft-bridge.h" - -#define OPT_REPLY_MAC 0x01 -#define OPT_REPLY_TARGET 0x02 - -#define REPLY_MAC '1' -#define REPLY_TARGET '2' -static const struct option brarpreply_opts[] = { - { "arpreply-mac" , required_argument, 0, REPLY_MAC }, - { "arpreply-target" , required_argument, 0, REPLY_TARGET }, - XT_GETOPT_TABLEEND, -}; - -static void brarpreply_print_help(void) -{ - printf( - "arpreply target options:\n" - " --arpreply-mac address : source MAC of generated reply\n" - " --arpreply-target target : ACCEPT, DROP, RETURN or CONTINUE\n" - " (standard target is DROP)\n"); -} - -static void brarpreply_init(struct xt_entry_target *target) -{ - struct ebt_arpreply_info *replyinfo = (void *)target->data; - - replyinfo->target = EBT_DROP; -} - -static int -brarpreply_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_target **tg) - -{ - struct ebt_arpreply_info *replyinfo = (void *)(*tg)->data; - struct ether_addr *addr; - - switch (c) { - case REPLY_MAC: - EBT_CHECK_OPTION(flags, OPT_REPLY_MAC); - if (!(addr = ether_aton(optarg))) - xtables_error(PARAMETER_PROBLEM, "Problem with specified --arpreply-mac mac"); - memcpy(replyinfo->mac, addr, ETH_ALEN); - break; - case REPLY_TARGET: - EBT_CHECK_OPTION(flags, OPT_REPLY_TARGET); - if (ebt_fill_target(optarg, (unsigned int *)&replyinfo->target)) - xtables_error(PARAMETER_PROBLEM, "Illegal --arpreply-target target"); - break; - - default: - return 0; - } - return 1; -} - -static void brarpreply_print(const void *ip, const struct xt_entry_target *t, int numeric) -{ - struct ebt_arpreply_info *replyinfo = (void *)t->data; - - printf("--arpreply-mac "); - xtables_print_mac(replyinfo->mac); - if (replyinfo->target == EBT_DROP) - return; - printf(" --arpreply-target %s", ebt_target_name(replyinfo->target)); -} - -static struct xtables_target arpreply_target = { - .name = "arpreply", - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .init = brarpreply_init, - .size = XT_ALIGN(sizeof(struct ebt_arpreply_info)), - .userspacesize = XT_ALIGN(sizeof(struct ebt_arpreply_info)), - .help = brarpreply_print_help, - .parse = brarpreply_parse, - .print = brarpreply_print, - .extra_opts = brarpreply_opts, -}; - -void _init(void) -{ - xtables_register_target(&arpreply_target); -} diff --git a/extensions/libebt_arpreply.t b/extensions/libebt_arpreply.t deleted file mode 100644 index 6734501a..00000000 --- a/extensions/libebt_arpreply.t +++ /dev/null @@ -1,4 +0,0 @@ -:PREROUTING -*nat --p ARP -i foo -j arpreply --arpreply-mac de:ad:00:be:ee:ff --arpreply-target ACCEPT;=;OK --p ARP -i foo -j arpreply --arpreply-mac de:ad:00:be:ee:ff;=;OK diff --git a/extensions/libebt_dnat.c b/extensions/libebt_dnat.c deleted file mode 100644 index 9f5f721e..00000000 --- a/extensions/libebt_dnat.c +++ /dev/null @@ -1,129 +0,0 @@ -/* ebt_nat - * - * Authors: - * Bart De Schuymer - * - * June, 2002 - */ - -#include -#include -#include -#include -#include -#include -#include -#include "iptables/nft.h" -#include "iptables/nft-bridge.h" - -#define NAT_D '1' -#define NAT_D_TARGET '2' -static const struct option brdnat_opts[] = -{ - { "to-destination", required_argument, 0, NAT_D }, - { "to-dst" , required_argument, 0, NAT_D }, - { "dnat-target" , required_argument, 0, NAT_D_TARGET }, - { 0 } -}; - -static void brdnat_print_help(void) -{ - printf( - "dnat options:\n" - " --to-dst address : MAC address to map destination to\n" - " --dnat-target target : ACCEPT, DROP, RETURN or CONTINUE\n"); -} - -static void brdnat_init(struct xt_entry_target *target) -{ - struct ebt_nat_info *natinfo = (struct ebt_nat_info *)target->data; - - natinfo->target = EBT_ACCEPT; -} - -#define OPT_DNAT 0x01 -#define OPT_DNAT_TARGET 0x02 -static int brdnat_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_target **target) -{ - struct ebt_nat_info *natinfo = (struct ebt_nat_info *)(*target)->data; - struct ether_addr *addr; - - switch (c) { - case NAT_D: - EBT_CHECK_OPTION(flags, OPT_DNAT); - if (!(addr = ether_aton(optarg))) - xtables_error(PARAMETER_PROBLEM, "Problem with specified --to-destination mac"); - memcpy(natinfo->mac, addr, ETH_ALEN); - break; - case NAT_D_TARGET: - EBT_CHECK_OPTION(flags, OPT_DNAT_TARGET); - if (ebt_fill_target(optarg, (unsigned int *)&natinfo->target)) - xtables_error(PARAMETER_PROBLEM, "Illegal --dnat-target target"); - break; - default: - return 0; - } - return 1; -} - -static void brdnat_final_check(unsigned int flags) -{ - if (!flags) - xtables_error(PARAMETER_PROBLEM, - "You must specify proper arguments"); -} - -static void brdnat_print(const void *ip, const struct xt_entry_target *target, int numeric) -{ - struct ebt_nat_info *natinfo = (struct ebt_nat_info *)target->data; - - printf("--to-dst "); - xtables_print_mac(natinfo->mac); - printf(" --dnat-target %s", ebt_target_name(natinfo->target)); -} - -static const char* brdnat_verdict(int verdict) -{ - switch (verdict) { - case EBT_ACCEPT: return "accept"; - case EBT_DROP: return "drop"; - case EBT_CONTINUE: return "continue"; - case EBT_RETURN: return "return"; - } - - return ""; -} - -static int brdnat_xlate(struct xt_xlate *xl, - const struct xt_xlate_tg_params *params) -{ - const struct ebt_nat_info *natinfo = (const void*)params->target->data; - - xt_xlate_add(xl, "ether daddr set %s %s ", - ether_ntoa((struct ether_addr *)natinfo->mac), - brdnat_verdict(natinfo->target)); - - return 1; -} - -static struct xtables_target brdnat_target = -{ - .name = "dnat", - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_nat_info)), - .userspacesize = XT_ALIGN(sizeof(struct ebt_nat_info)), - .help = brdnat_print_help, - .init = brdnat_init, - .parse = brdnat_parse, - .final_check = brdnat_final_check, - .print = brdnat_print, - .xlate = brdnat_xlate, - .extra_opts = brdnat_opts, -}; - -void _init(void) -{ - xtables_register_target(&brdnat_target); -} diff --git a/extensions/libebt_dnat.t b/extensions/libebt_dnat.t deleted file mode 100644 index 9428d237..00000000 --- a/extensions/libebt_dnat.t +++ /dev/null @@ -1,5 +0,0 @@ -:PREROUTING -*nat --i someport -j dnat --to-dst de:ad:0:be:ee:ff;-i someport -j dnat --to-dst de:ad:00:be:ee:ff --dnat-target ACCEPT;OK --j dnat --to-dst de:ad:00:be:ee:ff --dnat-target ACCEPT;=;OK --j dnat --to-dst de:ad:00:be:ee:ff --dnat-target CONTINUE;=;OK diff --git a/extensions/libebt_dnat.txlate b/extensions/libebt_dnat.txlate deleted file mode 100644 index 2652dd55..00000000 --- a/extensions/libebt_dnat.txlate +++ /dev/null @@ -1,8 +0,0 @@ -ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff -nft add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff accept counter - -ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff --dnat-target ACCEPT -nft add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff accept counter - -ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff --dnat-target CONTINUE -nft add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff continue counter diff --git a/extensions/libebt_ip.c b/extensions/libebt_ip.c deleted file mode 100644 index acb9bfcd..00000000 --- a/extensions/libebt_ip.c +++ /dev/null @@ -1,732 +0,0 @@ -/* ebt_ip - * - * Authors: - * Bart De Schuymer - * - * Changes: - * added ip-sport and ip-dport; parsing of port arguments is - * based on code from iptables-1.2.7a - * Innominate Security Technologies AG - * September, 2002 - * - * Adapted by Arturo Borrero Gonzalez - * to use libxtables for ebtables-compat in 2015. - */ - -#include -#include -#include -#include -#include -#include -#include - -#include "libxt_icmp.h" - -#define EBT_IP_SOURCE 0x01 -#define EBT_IP_DEST 0x02 -#define EBT_IP_TOS 0x04 -#define EBT_IP_PROTO 0x08 -#define EBT_IP_SPORT 0x10 -#define EBT_IP_DPORT 0x20 -#define EBT_IP_ICMP 0x40 -#define EBT_IP_IGMP 0x80 -#define EBT_IP_MASK (EBT_IP_SOURCE | EBT_IP_DEST | EBT_IP_TOS | EBT_IP_PROTO |\ - EBT_IP_SPORT | EBT_IP_DPORT | EBT_IP_ICMP | EBT_IP_IGMP) - -struct ebt_ip_info { - __be32 saddr; - __be32 daddr; - __be32 smsk; - __be32 dmsk; - __u8 tos; - __u8 protocol; - __u8 bitmask; - __u8 invflags; - union { - __u16 sport[2]; - __u8 icmp_type[2]; - __u8 igmp_type[2]; - }; - union { - __u16 dport[2]; - __u8 icmp_code[2]; - }; -}; - -#define IP_SOURCE '1' -#define IP_DEST '2' -#define IP_EBT_TOS '3' /* include/bits/in.h seems to already define IP_TOS */ -#define IP_PROTO '4' -#define IP_SPORT '5' -#define IP_DPORT '6' -#define IP_EBT_ICMP '7' -#define IP_EBT_IGMP '8' - -static const struct option brip_opts[] = { - { .name = "ip-source", .has_arg = true, .val = IP_SOURCE }, - { .name = "ip-src", .has_arg = true, .val = IP_SOURCE }, - { .name = "ip-destination", .has_arg = true, .val = IP_DEST }, - { .name = "ip-dst", .has_arg = true, .val = IP_DEST }, - { .name = "ip-tos", .has_arg = true, .val = IP_EBT_TOS }, - { .name = "ip-protocol", .has_arg = true, .val = IP_PROTO }, - { .name = "ip-proto", .has_arg = true, .val = IP_PROTO }, - { .name = "ip-source-port", .has_arg = true, .val = IP_SPORT }, - { .name = "ip-sport", .has_arg = true, .val = IP_SPORT }, - { .name = "ip-destination-port",.has_arg = true, .val = IP_DPORT }, - { .name = "ip-dport", .has_arg = true, .val = IP_DPORT }, - { .name = "ip-icmp-type", .has_arg = true, .val = IP_EBT_ICMP }, - { .name = "ip-igmp-type", .has_arg = true, .val = IP_EBT_IGMP }, - XT_GETOPT_TABLEEND, -}; - -static const struct xt_icmp_names icmp_codes[] = { - { "echo-reply", 0, 0, 0xFF }, - /* Alias */ { "pong", 0, 0, 0xFF }, - - { "destination-unreachable", 3, 0, 0xFF }, - { "network-unreachable", 3, 0, 0 }, - { "host-unreachable", 3, 1, 1 }, - { "protocol-unreachable", 3, 2, 2 }, - { "port-unreachable", 3, 3, 3 }, - { "fragmentation-needed", 3, 4, 4 }, - { "source-route-failed", 3, 5, 5 }, - { "network-unknown", 3, 6, 6 }, - { "host-unknown", 3, 7, 7 }, - { "network-prohibited", 3, 9, 9 }, - { "host-prohibited", 3, 10, 10 }, - { "TOS-network-unreachable", 3, 11, 11 }, - { "TOS-host-unreachable", 3, 12, 12 }, - { "communication-prohibited", 3, 13, 13 }, - { "host-precedence-violation", 3, 14, 14 }, - { "precedence-cutoff", 3, 15, 15 }, - - { "source-quench", 4, 0, 0xFF }, - - { "redirect", 5, 0, 0xFF }, - { "network-redirect", 5, 0, 0 }, - { "host-redirect", 5, 1, 1 }, - { "TOS-network-redirect", 5, 2, 2 }, - { "TOS-host-redirect", 5, 3, 3 }, - - { "echo-request", 8, 0, 0xFF }, - /* Alias */ { "ping", 8, 0, 0xFF }, - - { "router-advertisement", 9, 0, 0xFF }, - - { "router-solicitation", 10, 0, 0xFF }, - - { "time-exceeded", 11, 0, 0xFF }, - /* Alias */ { "ttl-exceeded", 11, 0, 0xFF }, - { "ttl-zero-during-transit", 11, 0, 0 }, - { "ttl-zero-during-reassembly", 11, 1, 1 }, - - { "parameter-problem", 12, 0, 0xFF }, - { "ip-header-bad", 12, 0, 0 }, - { "required-option-missing", 12, 1, 1 }, - - { "timestamp-request", 13, 0, 0xFF }, - - { "timestamp-reply", 14, 0, 0xFF }, - - { "address-mask-request", 17, 0, 0xFF }, - - { "address-mask-reply", 18, 0, 0xFF } -}; - -static const struct xt_icmp_names igmp_types[] = { - { "membership-query", 0x11 }, - { "membership-report-v1", 0x12 }, - { "membership-report-v2", 0x16 }, - { "leave-group", 0x17 }, - { "membership-report-v3", 0x22 }, -}; - -static void brip_print_help(void) -{ - printf( -"ip options:\n" -"--ip-src [!] address[/mask]: ip source specification\n" -"--ip-dst [!] address[/mask]: ip destination specification\n" -"--ip-tos [!] tos : ip tos specification\n" -"--ip-proto [!] protocol : ip protocol specification\n" -"--ip-sport [!] port[:port] : tcp/udp source port or port range\n" -"--ip-dport [!] port[:port] : tcp/udp destination port or port range\n" -"--ip-icmp-type [!] type[[:type]/code[:code]] : icmp type/code or type/code range\n" -"--ip-igmp-type [!] type[:type] : igmp type or type range\n"); - - printf("\nValid ICMP Types:\n"); - xt_print_icmp_types(icmp_codes, ARRAY_SIZE(icmp_codes)); - printf("\nValid IGMP Types:\n"); - xt_print_icmp_types(igmp_types, ARRAY_SIZE(igmp_types)); -} - -static void brip_init(struct xt_entry_match *match) -{ - struct ebt_ip_info *info = (struct ebt_ip_info *)match->data; - - info->invflags = 0; - info->bitmask = 0; -} - -static void -parse_port_range(const char *protocol, const char *portstring, uint16_t *ports) -{ - char *buffer; - char *cp; - - buffer = strdup(portstring); - if ((cp = strchr(buffer, ':')) == NULL) - ports[0] = ports[1] = xtables_parse_port(buffer, NULL); - else { - *cp = '\0'; - cp++; - - ports[0] = buffer[0] ? xtables_parse_port(buffer, NULL) : 0; - ports[1] = cp[0] ? xtables_parse_port(cp, NULL) : 0xFFFF; - - if (ports[0] > ports[1]) - xtables_error(PARAMETER_PROBLEM, - "invalid portrange (min > max)"); - } - free(buffer); -} - -/* original code from ebtables: useful_functions.c */ -static int undot_ip(char *ip, unsigned char *ip2) -{ - char *p, *q, *end; - long int onebyte; - int i; - char buf[20]; - - strncpy(buf, ip, sizeof(buf) - 1); - - p = buf; - for (i = 0; i < 3; i++) { - if ((q = strchr(p, '.')) == NULL) - return -1; - *q = '\0'; - onebyte = strtol(p, &end, 10); - if (*end != '\0' || onebyte > 255 || onebyte < 0) - return -1; - ip2[i] = (unsigned char)onebyte; - p = q + 1; - } - - onebyte = strtol(p, &end, 10); - if (*end != '\0' || onebyte > 255 || onebyte < 0) - return -1; - ip2[3] = (unsigned char)onebyte; - - return 0; -} - -static int ip_mask(char *mask, unsigned char *mask2) -{ - char *end; - long int bits; - uint32_t mask22; - - if (undot_ip(mask, mask2)) { - /* not the /a.b.c.e format, maybe the /x format */ - bits = strtol(mask, &end, 10); - if (*end != '\0' || bits > 32 || bits < 0) - return -1; - if (bits != 0) { - mask22 = htonl(0xFFFFFFFF << (32 - bits)); - memcpy(mask2, &mask22, 4); - } else { - mask22 = 0xFFFFFFFF; - memcpy(mask2, &mask22, 4); - } - } - return 0; -} - -static void ebt_parse_ip_address(char *address, uint32_t *addr, uint32_t *msk) -{ - char *p; - - /* first the mask */ - if ((p = strrchr(address, '/')) != NULL) { - *p = '\0'; - if (ip_mask(p + 1, (unsigned char *)msk)) { - xtables_error(PARAMETER_PROBLEM, - "Problem with the IP mask '%s'", p + 1); - return; - } - } else - *msk = 0xFFFFFFFF; - - if (undot_ip(address, (unsigned char *)addr)) { - xtables_error(PARAMETER_PROBLEM, - "Problem with the IP address '%s'", address); - return; - } - *addr = *addr & *msk; -} - -static char *parse_range(const char *str, unsigned int res[]) -{ - char *next; - - if (!xtables_strtoui(str, &next, &res[0], 0, 255)) - return NULL; - - res[1] = res[0]; - if (*next == ':') { - str = next + 1; - if (!xtables_strtoui(str, &next, &res[1], 0, 255)) - return NULL; - } - - return next; -} - -static int ebt_parse_icmp(const struct xt_icmp_names *codes, size_t n_codes, - const char *icmptype, uint8_t type[], uint8_t code[]) -{ - unsigned int match = n_codes; - unsigned int i, number[2]; - - for (i = 0; i < n_codes; i++) { - if (strncasecmp(codes[i].name, icmptype, strlen(icmptype))) - continue; - if (match != n_codes) - xtables_error(PARAMETER_PROBLEM, "Ambiguous ICMP type `%s':" - " `%s' or `%s'?", - icmptype, codes[match].name, - codes[i].name); - match = i; - } - - if (match < n_codes) { - type[0] = type[1] = codes[match].type; - if (code) { - code[0] = codes[match].code_min; - code[1] = codes[match].code_max; - } - } else { - char *next = parse_range(icmptype, number); - if (!next) { - xtables_error(PARAMETER_PROBLEM, "Unknown ICMP type `%s'", - icmptype); - return -1; - } - - type[0] = (uint8_t) number[0]; - type[1] = (uint8_t) number[1]; - switch (*next) { - case 0: - if (code) { - code[0] = 0; - code[1] = 255; - } - return 0; - case '/': - if (code) { - next = parse_range(next+1, number); - code[0] = (uint8_t) number[0]; - code[1] = (uint8_t) number[1]; - if (next == NULL) - return -1; - if (next && *next == 0) - return 0; - } - /* fallthrough */ - default: - xtables_error(PARAMETER_PROBLEM, "unknown character %c", *next); - return -1; - } - } - return 0; -} - -static void print_icmp_code(uint8_t *code) -{ - if (!code) - return; - - if (code[0] == code[1]) - printf("/%"PRIu8 " ", code[0]); - else - printf("/%"PRIu8":%"PRIu8 " ", code[0], code[1]); -} - -static void ebt_print_icmp_type(const struct xt_icmp_names *codes, - size_t n_codes, uint8_t *type, uint8_t *code) -{ - unsigned int i; - - if (type[0] != type[1]) { - printf("%"PRIu8 ":%" PRIu8, type[0], type[1]); - print_icmp_code(code); - return; - } - - for (i = 0; i < n_codes; i++) { - if (codes[i].type != type[0]) - continue; - - if (!code || (codes[i].code_min == code[0] && - codes[i].code_max == code[1])) { - printf("%s ", codes[i].name); - return; - } - } - printf("%"PRIu8, type[0]); - print_icmp_code(code); -} - -static int -brip_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_match **match) -{ - struct ebt_ip_info *info = (struct ebt_ip_info *)(*match)->data; - - switch (c) { - case IP_SOURCE: - if (invert) - info->invflags |= EBT_IP_SOURCE; - ebt_parse_ip_address(optarg, &info->saddr, &info->smsk); - info->bitmask |= EBT_IP_SOURCE; - break; - case IP_DEST: - if (invert) - info->invflags |= EBT_IP_DEST; - ebt_parse_ip_address(optarg, &info->daddr, &info->dmsk); - info->bitmask |= EBT_IP_DEST; - break; - case IP_SPORT: - if (invert) - info->invflags |= EBT_IP_SPORT; - parse_port_range(NULL, optarg, info->sport); - info->bitmask |= EBT_IP_SPORT; - break; - case IP_DPORT: - if (invert) - info->invflags |= EBT_IP_DPORT; - parse_port_range(NULL, optarg, info->dport); - info->bitmask |= EBT_IP_DPORT; - break; - case IP_EBT_ICMP: - if (invert) - info->invflags |= EBT_IP_ICMP; - ebt_parse_icmp(icmp_codes, ARRAY_SIZE(icmp_codes), optarg, - info->icmp_type, info->icmp_code); - info->bitmask |= EBT_IP_ICMP; - break; - case IP_EBT_IGMP: - if (invert) - info->invflags |= EBT_IP_IGMP; - ebt_parse_icmp(igmp_types, ARRAY_SIZE(igmp_types), optarg, - info->igmp_type, NULL); - info->bitmask |= EBT_IP_IGMP; - break; - case IP_EBT_TOS: { - uintmax_t tosvalue; - - if (invert) - info->invflags |= EBT_IP_TOS; - if (!xtables_strtoul(optarg, NULL, &tosvalue, 0, 255)) - xtables_error(PARAMETER_PROBLEM, - "Problem with specified IP tos"); - info->tos = tosvalue; - info->bitmask |= EBT_IP_TOS; - } - break; - case IP_PROTO: - if (invert) - info->invflags |= EBT_IP_PROTO; - info->protocol = xtables_parse_protocol(optarg); - info->bitmask |= EBT_IP_PROTO; - break; - default: - return 0; - } - - *flags |= info->bitmask; - return 1; -} - -static void brip_final_check(unsigned int flags) -{ - if (!flags) - xtables_error(PARAMETER_PROBLEM, - "You must specify proper arguments"); -} - -static void print_port_range(uint16_t *ports) -{ - if (ports[0] == ports[1]) - printf("%d ", ports[0]); - else - printf("%d:%d ", ports[0], ports[1]); -} - -static void brip_print(const void *ip, const struct xt_entry_match *match, - int numeric) -{ - struct ebt_ip_info *info = (struct ebt_ip_info *)match->data; - struct in_addr *addrp, *maskp; - - if (info->bitmask & EBT_IP_SOURCE) { - printf("--ip-src "); - if (info->invflags & EBT_IP_SOURCE) - printf("! "); - addrp = (struct in_addr *)&info->saddr; - maskp = (struct in_addr *)&info->smsk; - printf("%s%s ", xtables_ipaddr_to_numeric(addrp), - xtables_ipmask_to_numeric(maskp)); - } - if (info->bitmask & EBT_IP_DEST) { - printf("--ip-dst "); - if (info->invflags & EBT_IP_DEST) - printf("! "); - addrp = (struct in_addr *)&info->daddr; - maskp = (struct in_addr *)&info->dmsk; - printf("%s%s ", xtables_ipaddr_to_numeric(addrp), - xtables_ipmask_to_numeric(maskp)); - } - if (info->bitmask & EBT_IP_TOS) { - printf("--ip-tos "); - if (info->invflags & EBT_IP_TOS) - printf("! "); - printf("0x%02X ", info->tos); - } - if (info->bitmask & EBT_IP_PROTO) { - struct protoent *pe; - - printf("--ip-proto "); - if (info->invflags & EBT_IP_PROTO) - printf("! "); - pe = getprotobynumber(info->protocol); - if (pe == NULL) { - printf("%d ", info->protocol); - } else { - printf("%s ", pe->p_name); - } - } - if (info->bitmask & EBT_IP_SPORT) { - printf("--ip-sport "); - if (info->invflags & EBT_IP_SPORT) - printf("! "); - print_port_range(info->sport); - } - if (info->bitmask & EBT_IP_DPORT) { - printf("--ip-dport "); - if (info->invflags & EBT_IP_DPORT) - printf("! "); - print_port_range(info->dport); - } - if (info->bitmask & EBT_IP_ICMP) { - printf("--ip-icmp-type "); - if (info->invflags & EBT_IP_ICMP) - printf("! "); - ebt_print_icmp_type(icmp_codes, ARRAY_SIZE(icmp_codes), - info->icmp_type, info->icmp_code); - } - if (info->bitmask & EBT_IP_IGMP) { - printf("--ip-igmp-type "); - if (info->invflags & EBT_IP_IGMP) - printf("! "); - ebt_print_icmp_type(igmp_types, ARRAY_SIZE(igmp_types), - info->igmp_type, NULL); - } -} - -static const char *brip_xlate_proto_to_name(uint8_t proto) -{ - switch (proto) { - case IPPROTO_TCP: - return "tcp"; - case IPPROTO_UDP: - return "udp"; - case IPPROTO_UDPLITE: - return "udplite"; - case IPPROTO_SCTP: - return "sctp"; - case IPPROTO_DCCP: - return "dccp"; - default: - return NULL; - } -} - -static void brip_xlate_icmp(struct xt_xlate *xl, - const struct ebt_ip_info *info, int bit) -{ - if ((info->bitmask & bit) == 0) - return; - - xt_xlate_add(xl, "icmp type "); - if (info->invflags & bit) - xt_xlate_add(xl, "!= "); - if (info->icmp_type[0] == info->icmp_type[1]) - xt_xlate_add(xl, "%d ", info->icmp_type[0]); - else - xt_xlate_add(xl, "%d-%d ", info->icmp_type[0], - info->icmp_type[1]); - if (info->icmp_code[0] == 0 && - info->icmp_code[1] == 0xff) - return; - - xt_xlate_add(xl, "icmp code "); - if (info->invflags & bit) - xt_xlate_add(xl, "!= "); - if (info->icmp_code[0] == info->icmp_code[1]) - xt_xlate_add(xl, "%d ", info->icmp_code[0]); - else - xt_xlate_add(xl, "%d-%d ", info->icmp_code[0], - info->icmp_code[1]); -} - -static void brip_xlate_igmp(struct xt_xlate *xl, - const struct ebt_ip_info *info, int bit) -{ - if ((info->bitmask & bit) == 0) - return; - - xt_xlate_add(xl, "@th,0,8 "); - if (info->invflags & bit) - xt_xlate_add(xl, "!= "); - if (info->icmp_type[0] == info->icmp_type[1]) - xt_xlate_add(xl, "%d ", info->icmp_type[0]); - else - xt_xlate_add(xl, "%d-%d ", info->icmp_type[0], - info->icmp_type[1]); -} - -static void brip_xlate_th(struct xt_xlate *xl, - const struct ebt_ip_info *info, int bit, - const char *pname) -{ - const uint16_t *ports; - - if ((info->bitmask & bit) == 0) - return; - - switch (bit) { - case EBT_IP_SPORT: - if (pname) - xt_xlate_add(xl, "%s sport ", pname); - else - xt_xlate_add(xl, "@th,0,16 "); - - ports = info->sport; - break; - case EBT_IP_DPORT: - if (pname) - xt_xlate_add(xl, "%s dport ", pname); - else - xt_xlate_add(xl, "@th,16,16 "); - - ports = info->dport; - break; - default: - return; - } - - if (info->invflags & bit) - xt_xlate_add(xl, "!= "); - - if (ports[0] == ports[1]) - xt_xlate_add(xl, "%d ", ports[0]); - else - xt_xlate_add(xl, "%d-%d ", ports[0], ports[1]); -} - -static void brip_xlate_nh(struct xt_xlate *xl, - const struct ebt_ip_info *info, int bit) -{ - struct in_addr *addrp, *maskp; - - if ((info->bitmask & bit) == 0) - return; - - switch (bit) { - case EBT_IP_SOURCE: - xt_xlate_add(xl, "ip saddr "); - addrp = (struct in_addr *)&info->saddr; - maskp = (struct in_addr *)&info->smsk; - break; - case EBT_IP_DEST: - xt_xlate_add(xl, "ip daddr "); - addrp = (struct in_addr *)&info->daddr; - maskp = (struct in_addr *)&info->dmsk; - break; - default: - return; - } - - if (info->invflags & bit) - xt_xlate_add(xl, "!= "); - - xt_xlate_add(xl, "%s%s ", xtables_ipaddr_to_numeric(addrp), - xtables_ipmask_to_numeric(maskp)); -} - -static int brip_xlate(struct xt_xlate *xl, - const struct xt_xlate_mt_params *params) -{ - const struct ebt_ip_info *info = (const void *)params->match->data; - const char *pname = NULL; - - brip_xlate_nh(xl, info, EBT_IP_SOURCE); - brip_xlate_nh(xl, info, EBT_IP_DEST); - - if (info->bitmask & EBT_IP_TOS) { - xt_xlate_add(xl, "ip dscp "); - if (info->invflags & EBT_IP_TOS) - xt_xlate_add(xl, "!= "); - xt_xlate_add(xl, "0x%02x ", info->tos & 0x3f); /* remove ECN bits */ - } - if (info->bitmask & EBT_IP_PROTO) { - struct protoent *pe; - - if (info->bitmask & (EBT_IP_SPORT|EBT_IP_DPORT|EBT_IP_ICMP) && - (info->invflags & EBT_IP_PROTO) == 0) { - /* port number or icmp given and not inverted, no need to print this */ - pname = brip_xlate_proto_to_name(info->protocol); - } else { - xt_xlate_add(xl, "ip protocol "); - if (info->invflags & EBT_IP_PROTO) - xt_xlate_add(xl, "!= "); - pe = getprotobynumber(info->protocol); - if (pe == NULL) - xt_xlate_add(xl, "%d ", info->protocol); - else - xt_xlate_add(xl, "%s ", pe->p_name); - } - } - - brip_xlate_th(xl, info, EBT_IP_SPORT, pname); - brip_xlate_th(xl, info, EBT_IP_DPORT, pname); - - brip_xlate_icmp(xl, info, EBT_IP_ICMP); - brip_xlate_igmp(xl, info, EBT_IP_IGMP); - - return 1; -} - -static struct xtables_match brip_match = { - .name = "ip", - .revision = 0, - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_ip_info)), - .userspacesize = XT_ALIGN(sizeof(struct ebt_ip_info)), - .init = brip_init, - .help = brip_print_help, - .parse = brip_parse, - .final_check = brip_final_check, - .print = brip_print, - .xlate = brip_xlate, - .extra_opts = brip_opts, -}; - -void _init(void) -{ - xtables_register_match(&brip_match); -} diff --git a/extensions/libebt_ip.t b/extensions/libebt_ip.t deleted file mode 100644 index 8be5dfbb..00000000 --- a/extensions/libebt_ip.t +++ /dev/null @@ -1,13 +0,0 @@ -:INPUT,FORWARD,OUTPUT --p ip --ip-src ! 192.168.0.0/24 -j ACCEPT;-p IPv4 --ip-src ! 192.168.0.0/24 -j ACCEPT;OK --p IPv4 --ip-dst 10.0.0.1;=;OK --p IPv4 --ip-tos 0xFF;=;OK --p IPv4 --ip-tos ! 0xFF;=;OK --p IPv4 --ip-proto tcp --ip-dport 22;=;OK --p IPv4 --ip-proto udp --ip-sport 1024:65535;=;OK --p IPv4 --ip-proto 253;=;OK --p IPv4 --ip-proto icmp --ip-icmp-type echo-request;=;OK --p IPv4 --ip-proto icmp --ip-icmp-type 1/1;=;OK --p ip --ip-protocol icmp --ip-icmp-type ! 1:10;-p IPv4 --ip-proto icmp --ip-icmp-type ! 1:10/0:255 -j CONTINUE;OK ---ip-proto icmp --ip-icmp-type 1/1;=;FAIL -! -p ip --ip-proto icmp --ip-icmp-type 1/1;=;FAIL diff --git a/extensions/libebt_ip.txlate b/extensions/libebt_ip.txlate deleted file mode 100644 index b5882c34..00000000 --- a/extensions/libebt_ip.txlate +++ /dev/null @@ -1,26 +0,0 @@ -ebtables-translate -A FORWARD -p ip --ip-src ! 192.168.0.0/24 -j ACCEPT -nft add rule bridge filter FORWARD ip saddr != 192.168.0.0/24 counter accept - -ebtables-translate -I FORWARD -p ip --ip-dst 10.0.0.1 -nft insert rule bridge filter FORWARD ip daddr 10.0.0.1 counter - -ebtables-translate -I OUTPUT 3 -p ip -o eth0 --ip-tos 0xff -nft insert rule bridge filter OUTPUT oifname "eth0" ip dscp 0x3f counter - -ebtables-translate -A FORWARD -p ip --ip-proto tcp --ip-dport 22 -nft add rule bridge filter FORWARD tcp dport 22 counter - -ebtables-translate -A FORWARD -p ip --ip-proto udp --ip-sport 1024:65535 -nft add rule bridge filter FORWARD udp sport 1024-65535 counter - -ebtables-translate -A FORWARD -p ip --ip-proto 253 -nft add rule bridge filter FORWARD ip protocol 253 counter - -ebtables-translate -A FORWARD -p ip --ip-protocol icmp --ip-icmp-type "echo-request" -nft add rule bridge filter FORWARD icmp type 8 counter - -ebtables-translate -A FORWARD -p ip --ip-proto icmp --ip-icmp-type 1/1 -nft add rule bridge filter FORWARD icmp type 1 icmp code 1 counter - -ebtables-translate -A FORWARD -p ip --ip-protocol icmp --ip-icmp-type ! 1:10 -nft add rule bridge filter FORWARD icmp type != 1-10 counter diff --git a/extensions/libebt_ip6.c b/extensions/libebt_ip6.c deleted file mode 100644 index b8a5a5d8..00000000 --- a/extensions/libebt_ip6.c +++ /dev/null @@ -1,632 +0,0 @@ -/* ebt_ip6 - * - * Authors: - * Kuo-Lang Tseng - * Manohar Castelino - * - * Summary: - * This is just a modification of the IPv4 code written by - * Bart De Schuymer - * with the changes required to support IPv6 - * - */ - -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include -#include - -#include "libxt_icmp.h" - -#define IP_SOURCE '1' -#define IP_DEST '2' -#define IP_TCLASS '3' -#define IP_PROTO '4' -#define IP_SPORT '5' -#define IP_DPORT '6' -#define IP_ICMP6 '7' - -static const struct option brip6_opts[] = { - { .name = "ip6-source", .has_arg = true, .val = IP_SOURCE }, - { .name = "ip6-src", .has_arg = true, .val = IP_SOURCE }, - { .name = "ip6-destination", .has_arg = true, .val = IP_DEST }, - { .name = "ip6-dst", .has_arg = true, .val = IP_DEST }, - { .name = "ip6-tclass", .has_arg = true, .val = IP_TCLASS }, - { .name = "ip6-protocol", .has_arg = true, .val = IP_PROTO }, - { .name = "ip6-proto", .has_arg = true, .val = IP_PROTO }, - { .name = "ip6-source-port", .has_arg = true, .val = IP_SPORT }, - { .name = "ip6-sport", .has_arg = true, .val = IP_SPORT }, - { .name = "ip6-destination-port",.has_arg = true,.val = IP_DPORT }, - { .name = "ip6-dport", .has_arg = true, .val = IP_DPORT }, - { .name = "ip6-icmp-type", .has_arg = true, .val = IP_ICMP6 }, - XT_GETOPT_TABLEEND, -}; - -static const struct xt_icmp_names icmpv6_codes[] = { - { "destination-unreachable", 1, 0, 0xFF }, - { "no-route", 1, 0, 0 }, - { "communication-prohibited", 1, 1, 1 }, - { "address-unreachable", 1, 3, 3 }, - { "port-unreachable", 1, 4, 4 }, - - { "packet-too-big", 2, 0, 0xFF }, - - { "time-exceeded", 3, 0, 0xFF }, - /* Alias */ { "ttl-exceeded", 3, 0, 0xFF }, - { "ttl-zero-during-transit", 3, 0, 0 }, - { "ttl-zero-during-reassembly", 3, 1, 1 }, - - { "parameter-problem", 4, 0, 0xFF }, - { "bad-header", 4, 0, 0 }, - { "unknown-header-type", 4, 1, 1 }, - { "unknown-option", 4, 2, 2 }, - - { "echo-request", 128, 0, 0xFF }, - /* Alias */ { "ping", 128, 0, 0xFF }, - - { "echo-reply", 129, 0, 0xFF }, - /* Alias */ { "pong", 129, 0, 0xFF }, - - { "router-solicitation", 133, 0, 0xFF }, - - { "router-advertisement", 134, 0, 0xFF }, - - { "neighbour-solicitation", 135, 0, 0xFF }, - /* Alias */ { "neighbor-solicitation", 135, 0, 0xFF }, - - { "neighbour-advertisement", 136, 0, 0xFF }, - /* Alias */ { "neighbor-advertisement", 136, 0, 0xFF }, - - { "redirect", 137, 0, 0xFF }, -}; - -static void -parse_port_range(const char *protocol, const char *portstring, uint16_t *ports) -{ - char *buffer; - char *cp; - - buffer = strdup(portstring); - if ((cp = strchr(buffer, ':')) == NULL) - ports[0] = ports[1] = xtables_parse_port(buffer, NULL); - else { - *cp = '\0'; - cp++; - - ports[0] = buffer[0] ? xtables_parse_port(buffer, NULL) : 0; - ports[1] = cp[0] ? xtables_parse_port(cp, NULL) : 0xFFFF; - - if (ports[0] > ports[1]) - xtables_error(PARAMETER_PROBLEM, - "invalid portrange (min > max)"); - } - free(buffer); -} - -static char *parse_range(const char *str, unsigned int res[]) -{ - char *next; - - if (!xtables_strtoui(str, &next, &res[0], 0, 255)) - return NULL; - - res[1] = res[0]; - if (*next == ':') { - str = next + 1; - if (!xtables_strtoui(str, &next, &res[1], 0, 255)) - return NULL; - } - - return next; -} - -static int -parse_icmpv6(const char *icmpv6type, uint8_t type[], uint8_t code[]) -{ - static const unsigned int limit = ARRAY_SIZE(icmpv6_codes); - unsigned int match = limit; - unsigned int i, number[2]; - - for (i = 0; i < limit; i++) { - if (strncasecmp(icmpv6_codes[i].name, icmpv6type, strlen(icmpv6type))) - continue; - if (match != limit) - xtables_error(PARAMETER_PROBLEM, "Ambiguous ICMPv6 type `%s':" - " `%s' or `%s'?", - icmpv6type, icmpv6_codes[match].name, - icmpv6_codes[i].name); - match = i; - } - - if (match < limit) { - type[0] = type[1] = icmpv6_codes[match].type; - code[0] = icmpv6_codes[match].code_min; - code[1] = icmpv6_codes[match].code_max; - } else { - char *next = parse_range(icmpv6type, number); - if (!next) { - xtables_error(PARAMETER_PROBLEM, "Unknown ICMPv6 type `%s'", - icmpv6type); - return -1; - } - type[0] = (uint8_t) number[0]; - type[1] = (uint8_t) number[1]; - switch (*next) { - case 0: - code[0] = 0; - code[1] = 255; - return 0; - case '/': - next = parse_range(next+1, number); - code[0] = (uint8_t) number[0]; - code[1] = (uint8_t) number[1]; - if (next == NULL) - return -1; - if (next && *next == 0) - return 0; - /* fallthrough */ - default: - xtables_error(PARAMETER_PROBLEM, "unknown character %c", *next); - return -1; - } - } - return 0; -} - -static void print_port_range(uint16_t *ports) -{ - if (ports[0] == ports[1]) - printf("%d ", ports[0]); - else - printf("%d:%d ", ports[0], ports[1]); -} - -static void print_icmp_code(uint8_t *code) -{ - if (code[0] == code[1]) - printf("/%"PRIu8 " ", code[0]); - else - printf("/%"PRIu8":%"PRIu8 " ", code[0], code[1]); -} - -static void print_icmp_type(uint8_t *type, uint8_t *code) -{ - unsigned int i; - - if (type[0] != type[1]) { - printf("%"PRIu8 ":%" PRIu8, type[0], type[1]); - print_icmp_code(code); - return; - } - - for (i = 0; i < ARRAY_SIZE(icmpv6_codes); i++) { - if (icmpv6_codes[i].type != type[0]) - continue; - - if (icmpv6_codes[i].code_min == code[0] && - icmpv6_codes[i].code_max == code[1]) { - printf("%s ", icmpv6_codes[i].name); - return; - } - } - printf("%"PRIu8, type[0]); - print_icmp_code(code); -} - -static void brip6_print_help(void) -{ - printf( -"ip6 options:\n" -"--ip6-src [!] address[/mask]: ipv6 source specification\n" -"--ip6-dst [!] address[/mask]: ipv6 destination specification\n" -"--ip6-tclass [!] tclass : ipv6 traffic class specification\n" -"--ip6-proto [!] protocol : ipv6 protocol specification\n" -"--ip6-sport [!] port[:port] : tcp/udp source port or port range\n" -"--ip6-dport [!] port[:port] : tcp/udp destination port or port range\n" -"--ip6-icmp-type [!] type[[:type]/code[:code]] : ipv6-icmp type/code or type/code range\n"); - printf("Valid ICMPv6 Types:"); - xt_print_icmp_types(icmpv6_codes, ARRAY_SIZE(icmpv6_codes)); -} - -static void brip6_init(struct xt_entry_match *match) -{ - struct ebt_ip6_info *ipinfo = (struct ebt_ip6_info *)match->data; - - ipinfo->invflags = 0; - ipinfo->bitmask = 0; - memset(ipinfo->saddr.s6_addr, 0, sizeof(ipinfo->saddr.s6_addr)); - memset(ipinfo->smsk.s6_addr, 0, sizeof(ipinfo->smsk.s6_addr)); - memset(ipinfo->daddr.s6_addr, 0, sizeof(ipinfo->daddr.s6_addr)); - memset(ipinfo->dmsk.s6_addr, 0, sizeof(ipinfo->dmsk.s6_addr)); -} - -static struct in6_addr *numeric_to_addr(const char *num) -{ - static struct in6_addr ap; - int err; - - if ((err=inet_pton(AF_INET6, num, &ap)) == 1) - return ≈ - return (struct in6_addr *)NULL; -} - -static struct in6_addr *parse_ip6_mask(char *mask) -{ - static struct in6_addr maskaddr; - struct in6_addr *addrp; - unsigned int bits; - - if (mask == NULL) { - /* no mask at all defaults to 128 bits */ - memset(&maskaddr, 0xff, sizeof maskaddr); - return &maskaddr; - } - if ((addrp = numeric_to_addr(mask)) != NULL) - return addrp; - if (!xtables_strtoui(mask, NULL, &bits, 0, 128)) - xtables_error(PARAMETER_PROBLEM, "Invalid IPv6 Mask '%s' specified", mask); - if (bits != 0) { - char *p = (char *)&maskaddr; - memset(p, 0xff, bits / 8); - memset(p + (bits / 8) + 1, 0, (128 - bits) / 8); - p[bits / 8] = 0xff << (8 - (bits & 7)); - return &maskaddr; - } - - memset(&maskaddr, 0, sizeof maskaddr); - return &maskaddr; -} - -/* Set the ipv6 mask and address. Callers should check ebt_errormsg[0]. - * The string pointed to by address can be altered. */ -static void ebt_parse_ip6_address(char *address, struct in6_addr *addr, struct in6_addr *msk) -{ - struct in6_addr *tmp_addr; - char buf[256]; - char *p; - int i; - int err; - - strncpy(buf, address, sizeof(buf) - 1); - /* first the mask */ - buf[sizeof(buf) - 1] = '\0'; - if ((p = strrchr(buf, '/')) != NULL) { - *p = '\0'; - tmp_addr = parse_ip6_mask(p + 1); - } else - tmp_addr = parse_ip6_mask(NULL); - - *msk = *tmp_addr; - - /* if a null mask is given, the name is ignored, like in "any/0" */ - if (!memcmp(msk, &in6addr_any, sizeof(in6addr_any))) - strcpy(buf, "::"); - - if ((err=inet_pton(AF_INET6, buf, addr)) < 1) { - xtables_error(PARAMETER_PROBLEM, "Invalid IPv6 Address '%s' specified", buf); - return; - } - - for (i = 0; i < 4; i++) - addr->s6_addr32[i] &= msk->s6_addr32[i]; -} - -#define OPT_SOURCE 0x01 -#define OPT_DEST 0x02 -#define OPT_TCLASS 0x04 -#define OPT_PROTO 0x08 -#define OPT_SPORT 0x10 -#define OPT_DPORT 0x20 -static int -brip6_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_match **match) -{ - struct ebt_ip6_info *info = (struct ebt_ip6_info *)(*match)->data; - unsigned int i; - char *end; - - switch (c) { - case IP_SOURCE: - if (invert) - info->invflags |= EBT_IP6_SOURCE; - ebt_parse_ip6_address(optarg, &info->saddr, &info->smsk); - info->bitmask |= EBT_IP6_SOURCE; - break; - case IP_DEST: - if (invert) - info->invflags |= EBT_IP6_DEST; - ebt_parse_ip6_address(optarg, &info->daddr, &info->dmsk); - info->bitmask |= EBT_IP6_DEST; - break; - case IP_SPORT: - if (invert) - info->invflags |= EBT_IP6_SPORT; - parse_port_range(NULL, optarg, info->sport); - info->bitmask |= EBT_IP6_SPORT; - break; - case IP_DPORT: - if (invert) - info->invflags |= EBT_IP6_DPORT; - parse_port_range(NULL, optarg, info->dport); - info->bitmask |= EBT_IP6_DPORT; - break; - case IP_ICMP6: - if (invert) - info->invflags |= EBT_IP6_ICMP6; - if (parse_icmpv6(optarg, info->icmpv6_type, info->icmpv6_code)) - return 0; - info->bitmask |= EBT_IP6_ICMP6; - break; - case IP_TCLASS: - if (invert) - info->invflags |= EBT_IP6_TCLASS; - if (!xtables_strtoui(optarg, &end, &i, 0, 255)) - xtables_error(PARAMETER_PROBLEM, "Problem with specified IPv6 traffic class '%s'", optarg); - info->tclass = i; - info->bitmask |= EBT_IP6_TCLASS; - break; - case IP_PROTO: - if (invert) - info->invflags |= EBT_IP6_PROTO; - info->protocol = xtables_parse_protocol(optarg); - info->bitmask |= EBT_IP6_PROTO; - break; - default: - return 0; - } - - *flags |= info->bitmask; - return 1; -} - -static void brip6_final_check(unsigned int flags) -{ - if (!flags) - xtables_error(PARAMETER_PROBLEM, - "You must specify proper arguments"); -} - -static void brip6_print(const void *ip, const struct xt_entry_match *match, - int numeric) -{ - struct ebt_ip6_info *ipinfo = (struct ebt_ip6_info *)match->data; - - if (ipinfo->bitmask & EBT_IP6_SOURCE) { - printf("--ip6-src "); - if (ipinfo->invflags & EBT_IP6_SOURCE) - printf("! "); - printf("%s", xtables_ip6addr_to_numeric(&ipinfo->saddr)); - printf("%s ", xtables_ip6mask_to_numeric(&ipinfo->smsk)); - } - if (ipinfo->bitmask & EBT_IP6_DEST) { - printf("--ip6-dst "); - if (ipinfo->invflags & EBT_IP6_DEST) - printf("! "); - printf("%s", xtables_ip6addr_to_numeric(&ipinfo->daddr)); - printf("%s ", xtables_ip6mask_to_numeric(&ipinfo->dmsk)); - } - if (ipinfo->bitmask & EBT_IP6_TCLASS) { - printf("--ip6-tclass "); - if (ipinfo->invflags & EBT_IP6_TCLASS) - printf("! "); - printf("0x%02X ", ipinfo->tclass); - } - if (ipinfo->bitmask & EBT_IP6_PROTO) { - struct protoent *pe; - - printf("--ip6-proto "); - if (ipinfo->invflags & EBT_IP6_PROTO) - printf("! "); - pe = getprotobynumber(ipinfo->protocol); - if (pe == NULL) { - printf("%d ", ipinfo->protocol); - } else { - printf("%s ", pe->p_name); - } - } - if (ipinfo->bitmask & EBT_IP6_SPORT) { - printf("--ip6-sport "); - if (ipinfo->invflags & EBT_IP6_SPORT) - printf("! "); - print_port_range(ipinfo->sport); - } - if (ipinfo->bitmask & EBT_IP6_DPORT) { - printf("--ip6-dport "); - if (ipinfo->invflags & EBT_IP6_DPORT) - printf("! "); - print_port_range(ipinfo->dport); - } - if (ipinfo->bitmask & EBT_IP6_ICMP6) { - printf("--ip6-icmp-type "); - if (ipinfo->invflags & EBT_IP6_ICMP6) - printf("! "); - print_icmp_type(ipinfo->icmpv6_type, ipinfo->icmpv6_code); - } -} - -static void brip_xlate_th(struct xt_xlate *xl, - const struct ebt_ip6_info *info, int bit, - const char *pname) -{ - const uint16_t *ports; - - if ((info->bitmask & bit) == 0) - return; - - switch (bit) { - case EBT_IP6_SPORT: - if (pname) - xt_xlate_add(xl, "%s sport ", pname); - else - xt_xlate_add(xl, "@th,0,16 "); - - ports = info->sport; - break; - case EBT_IP6_DPORT: - if (pname) - xt_xlate_add(xl, "%s dport ", pname); - else - xt_xlate_add(xl, "@th,16,16 "); - - ports = info->dport; - break; - default: - return; - } - - if (info->invflags & bit) - xt_xlate_add(xl, "!= "); - - if (ports[0] == ports[1]) - xt_xlate_add(xl, "%d ", ports[0]); - else - xt_xlate_add(xl, "%d-%d ", ports[0], ports[1]); -} - -static void brip_xlate_nh(struct xt_xlate *xl, - const struct ebt_ip6_info *info, int bit) -{ - struct in6_addr *addrp, *maskp; - - if ((info->bitmask & bit) == 0) - return; - - switch (bit) { - case EBT_IP6_SOURCE: - xt_xlate_add(xl, "ip6 saddr "); - addrp = (struct in6_addr *)&info->saddr; - maskp = (struct in6_addr *)&info->smsk; - break; - case EBT_IP6_DEST: - xt_xlate_add(xl, "ip6 daddr "); - addrp = (struct in6_addr *)&info->daddr; - maskp = (struct in6_addr *)&info->dmsk; - break; - default: - return; - } - - if (info->invflags & bit) - xt_xlate_add(xl, "!= "); - - xt_xlate_add(xl, "%s%s ", xtables_ip6addr_to_numeric(addrp), - xtables_ip6mask_to_numeric(maskp)); -} - -static const char *brip6_xlate_proto_to_name(uint8_t proto) -{ - switch (proto) { - case IPPROTO_TCP: - return "tcp"; - case IPPROTO_UDP: - return "udp"; - case IPPROTO_UDPLITE: - return "udplite"; - case IPPROTO_SCTP: - return "sctp"; - case IPPROTO_DCCP: - return "dccp"; - default: - return NULL; - } -} - -static int brip6_xlate(struct xt_xlate *xl, - const struct xt_xlate_mt_params *params) -{ - const struct ebt_ip6_info *info = (const void *)params->match->data; - const char *pname = NULL; - - if ((info->bitmask & (EBT_IP6_SOURCE|EBT_IP6_DEST|EBT_IP6_ICMP6|EBT_IP6_TCLASS)) == 0) - xt_xlate_add(xl, "ether type ip6 "); - - brip_xlate_nh(xl, info, EBT_IP6_SOURCE); - brip_xlate_nh(xl, info, EBT_IP6_DEST); - - if (info->bitmask & EBT_IP6_TCLASS) { - xt_xlate_add(xl, "ip6 dscp "); - if (info->invflags & EBT_IP6_TCLASS) - xt_xlate_add(xl, "!= "); - xt_xlate_add(xl, "0x%02x ", info->tclass & 0x3f); /* remove ECN bits */ - } - - if (info->bitmask & EBT_IP6_PROTO) { - struct protoent *pe; - - if (info->bitmask & (EBT_IP6_SPORT|EBT_IP6_DPORT|EBT_IP6_ICMP6) && - (info->invflags & EBT_IP6_PROTO) == 0) { - /* port number given and not inverted, no need to - * add explicit 'meta l4proto'. - */ - pname = brip6_xlate_proto_to_name(info->protocol); - } else { - xt_xlate_add(xl, "meta l4proto "); - if (info->invflags & EBT_IP6_PROTO) - xt_xlate_add(xl, "!= "); - pe = getprotobynumber(info->protocol); - if (pe == NULL) - xt_xlate_add(xl, "%d ", info->protocol); - else - xt_xlate_add(xl, "%s ", pe->p_name); - } - } - - brip_xlate_th(xl, info, EBT_IP6_SPORT, pname); - brip_xlate_th(xl, info, EBT_IP6_DPORT, pname); - - if (info->bitmask & EBT_IP6_ICMP6) { - xt_xlate_add(xl, "icmpv6 type "); - if (info->invflags & EBT_IP6_ICMP6) - xt_xlate_add(xl, "!= "); - - if (info->icmpv6_type[0] == info->icmpv6_type[1]) - xt_xlate_add(xl, "%d ", info->icmpv6_type[0]); - else - xt_xlate_add(xl, "%d-%d ", info->icmpv6_type[0], - info->icmpv6_type[1]); - - if (info->icmpv6_code[0] == 0 && - info->icmpv6_code[1] == 0xff) - return 1; - - xt_xlate_add(xl, "icmpv6 code "); - if (info->invflags & EBT_IP6_ICMP6) - xt_xlate_add(xl, "!= "); - - if (info->icmpv6_code[0] == info->icmpv6_code[1]) - xt_xlate_add(xl, "%d ", info->icmpv6_code[0]); - else - xt_xlate_add(xl, "%d-%d ", info->icmpv6_code[0], - info->icmpv6_code[1]); - } - - return 1; -} - -static struct xtables_match brip6_match = { - .name = "ip6", - .revision = 0, - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_ip6_info)), - .userspacesize = XT_ALIGN(sizeof(struct ebt_ip6_info)), - .init = brip6_init, - .help = brip6_print_help, - .parse = brip6_parse, - .final_check = brip6_final_check, - .print = brip6_print, - .xlate = brip6_xlate, - .extra_opts = brip6_opts, -}; - -void _init(void) -{ - xtables_register_match(&brip6_match); -} diff --git a/extensions/libebt_ip6.t b/extensions/libebt_ip6.t deleted file mode 100644 index fa1038af..00000000 --- a/extensions/libebt_ip6.t +++ /dev/null @@ -1,15 +0,0 @@ -:INPUT,FORWARD,OUTPUT --p ip6 --ip6-src ! dead::beef/64 -j ACCEPT;-p IPv6 --ip6-src ! dead::/64 -j ACCEPT;OK --p IPv6 --ip6-dst dead:beef::/64 -j ACCEPT;=;OK --p IPv6 --ip6-dst f00:ba::;=;OK --p IPv6 --ip6-tclass 0xFF;=;OK --p IPv6 --ip6-proto tcp --ip6-dport 22;=;OK --p IPv6 --ip6-proto tcp --ip6-dport ! 22;=;OK --p IPv6 --ip6-proto udp --ip6-sport 1024:65535;=;OK --p IPv6 --ip6-proto 253;=;OK --p IPv6 --ip6-proto ipv6-icmp --ip6-icmp-type echo-request -j CONTINUE;=;OK --p IPv6 --ip6-proto ipv6-icmp --ip6-icmp-type echo-request;=;OK --p ip6 --ip6-protocol icmpv6 --ip6-icmp-type 1/1;-p IPv6 --ip6-proto ipv6-icmp --ip6-icmp-type communication-prohibited -j CONTINUE;OK --p IPv6 --ip6-proto ipv6-icmp --ip6-icmp-type ! 1:10/0:255;=;OK ---ip6-proto ipv6-icmp ! --ip6-icmp-type 1:10/0:255;=;FAIL -! -p IPv6 --ip6-proto ipv6-icmp ! --ip6-icmp-type 1:10/0:255;=;FAIL diff --git a/extensions/libebt_ip6.txlate b/extensions/libebt_ip6.txlate deleted file mode 100644 index 0271734c..00000000 --- a/extensions/libebt_ip6.txlate +++ /dev/null @@ -1,29 +0,0 @@ -ebtables-translate -A FORWARD -p ip6 --ip6-src ! dead::beef/64 -j ACCEPT -nft add rule bridge filter FORWARD ip6 saddr != dead::/64 counter accept - -ebtables-translate -A FORWARD -p ip6 ! --ip6-dst dead:beef::/64 -j ACCEPT -nft add rule bridge filter FORWARD ip6 daddr != dead:beef::/64 counter accept - -ebtables-translate -I FORWARD -p ip6 --ip6-dst f00:ba:: -nft insert rule bridge filter FORWARD ip6 daddr f00:ba:: counter - -ebtables-translate -I OUTPUT -o eth0 -p ip6 --ip6-tclass 0xff -nft insert rule bridge filter OUTPUT oifname "eth0" ip6 dscp 0x3f counter - -ebtables-translate -A FORWARD -p ip6 --ip6-proto tcp --ip6-dport 22 -nft add rule bridge filter FORWARD ether type ip6 tcp dport 22 counter - -ebtables-translate -A FORWARD -p ip6 --ip6-proto udp --ip6-sport 1024:65535 -nft add rule bridge filter FORWARD ether type ip6 udp sport 1024-65535 counter - -ebtables-translate -A FORWARD -p ip6 --ip6-proto 253 -nft add rule bridge filter FORWARD ether type ip6 meta l4proto 253 counter - -ebtables-translate -A FORWARD -p ip6 --ip6-protocol icmpv6 --ip6-icmp-type "echo-request" -nft add rule bridge filter FORWARD icmpv6 type 128 counter - -ebtables-translate -A FORWARD -p ip6 --ip6-protocol icmpv6 --ip6-icmp-type 1/1 -nft add rule bridge filter FORWARD icmpv6 type 1 icmpv6 code 1 counter - -ebtables-translate -A FORWARD -p ip6 --ip6-protocol icmpv6 --ip6-icmp-type ! 1:10 -nft add rule bridge filter FORWARD icmpv6 type != 1-10 counter diff --git a/extensions/libebt_limit.txlate b/extensions/libebt_limit.txlate deleted file mode 100644 index b6af15d5..00000000 --- a/extensions/libebt_limit.txlate +++ /dev/null @@ -1,8 +0,0 @@ -ebtables-translate -A INPUT --limit 3/m --limit-burst 3 -nft add rule bridge filter INPUT limit rate 3/minute burst 3 packets counter - -ebtables-translate -A INPUT --limit 10/s --limit-burst 5 -nft add rule bridge filter INPUT limit rate 10/second burst 5 packets counter - -ebtables-translate -A INPUT --limit 10/s --limit-burst 0 -nft add rule bridge filter INPUT limit rate 10/second counter diff --git a/extensions/libebt_log.c b/extensions/libebt_log.c deleted file mode 100644 index 8858cf0e..00000000 --- a/extensions/libebt_log.c +++ /dev/null @@ -1,217 +0,0 @@ -/* - * Bart De Schuymer - * - * This program is free software; you can redistribute it and/or modify - * it under the terms of the GNU General Public License version 2 as - * published by the Free Software Foundation. - * - * Giuseppe Longo adapted the original code to the - * xtables-compat environment in 2015. - * - */ - -#include -#include -#include -#include -#include -#include -#include - -#define LOG_DEFAULT_LEVEL LOG_INFO - -#define LOG_PREFIX '1' -#define LOG_LEVEL '2' -#define LOG_ARP '3' -#define LOG_IP '4' -#define LOG_LOG '5' -#define LOG_IP6 '6' - -struct code { - char *c_name; - int c_val; -}; - -static struct code eight_priority[] = { - { "emerg", LOG_EMERG }, - { "alert", LOG_ALERT }, - { "crit", LOG_CRIT }, - { "error", LOG_ERR }, - { "warning", LOG_WARNING }, - { "notice", LOG_NOTICE }, - { "info", LOG_INFO }, - { "debug", LOG_DEBUG } -}; - -static int name_to_loglevel(const char *arg) -{ - int i; - - for (i = 0; i < 8; i++) - if (!strcmp(arg, eight_priority[i].c_name)) - return eight_priority[i].c_val; - - /* return bad loglevel */ - return 9; -} - -static const struct option brlog_opts[] = { - { .name = "log-prefix", .has_arg = true, .val = LOG_PREFIX }, - { .name = "log-level", .has_arg = true, .val = LOG_LEVEL }, - { .name = "log-arp", .has_arg = false, .val = LOG_ARP }, - { .name = "log-ip", .has_arg = false, .val = LOG_IP }, - { .name = "log", .has_arg = false, .val = LOG_LOG }, - { .name = "log-ip6", .has_arg = false, .val = LOG_IP6 }, - XT_GETOPT_TABLEEND, -}; - -static void brlog_help(void) -{ - int i; - - printf( -"log options:\n" -"--log : use this if you're not specifying anything\n" -"--log-level level : level = [1-8] or a string\n" -"--log-prefix prefix : max. %d chars.\n" -"--log-ip : put ip info. in the log for ip packets\n" -"--log-arp : put (r)arp info. in the log for (r)arp packets\n" -"--log-ip6 : put ip6 info. in the log for ip6 packets\n" - , EBT_LOG_PREFIX_SIZE - 1); - for (i = 0; i < 8; i++) - printf("%d = %s\n", eight_priority[i].c_val, - eight_priority[i].c_name); -} - -static void brlog_init(struct xt_entry_target *t) -{ - struct ebt_log_info *loginfo = (struct ebt_log_info *)t->data; - - loginfo->bitmask = 0; - loginfo->prefix[0] = '\0'; - loginfo->loglevel = LOG_NOTICE; -} - -static unsigned int log_chk_inv(int inv, unsigned int bit, const char *suffix) -{ - if (inv) - xtables_error(PARAMETER_PROBLEM, - "Unexpected `!' after --log%s", suffix); - return bit; -} - -static int brlog_parse(int c, char **argv, int invert, unsigned int *flags, - const void *entry, struct xt_entry_target **target) -{ - struct ebt_log_info *loginfo = (struct ebt_log_info *)(*target)->data; - long int i; - char *end; - - switch (c) { - case LOG_PREFIX: - if (invert) - xtables_error(PARAMETER_PROBLEM, - "Unexpected `!` after --log-prefix"); - if (strlen(optarg) > sizeof(loginfo->prefix) - 1) - xtables_error(PARAMETER_PROBLEM, - "Prefix too long"); - if (strchr(optarg, '\"')) - xtables_error(PARAMETER_PROBLEM, - "Use of \\\" is not allowed" - " in the prefix"); - strcpy((char *)loginfo->prefix, (char *)optarg); - break; - case LOG_LEVEL: - i = strtol(optarg, &end, 16); - if (*end != '\0' || i < 0 || i > 7) - loginfo->loglevel = name_to_loglevel(optarg); - else - loginfo->loglevel = i; - - if (loginfo->loglevel == 9) - xtables_error(PARAMETER_PROBLEM, - "Problem with the log-level"); - break; - case LOG_IP: - loginfo->bitmask |= log_chk_inv(invert, EBT_LOG_IP, "-ip"); - break; - case LOG_ARP: - loginfo->bitmask |= log_chk_inv(invert, EBT_LOG_ARP, "-arp"); - break; - case LOG_LOG: - loginfo->bitmask |= log_chk_inv(invert, 0, ""); - break; - case LOG_IP6: - loginfo->bitmask |= log_chk_inv(invert, EBT_LOG_IP6, "-ip6"); - break; - default: - return 0; - } - - *flags |= loginfo->bitmask; - return 1; -} - -static void brlog_final_check(unsigned int flags) -{ -} - -static void brlog_print(const void *ip, const struct xt_entry_target *target, - int numeric) -{ - struct ebt_log_info *loginfo = (struct ebt_log_info *)target->data; - - printf("--log-level %s --log-prefix \"%s\"", - eight_priority[loginfo->loglevel].c_name, - loginfo->prefix); - - if (loginfo->bitmask & EBT_LOG_IP) - printf(" --log-ip"); - if (loginfo->bitmask & EBT_LOG_ARP) - printf(" --log-arp"); - if (loginfo->bitmask & EBT_LOG_IP6) - printf(" --log-ip6"); - printf(" "); -} - -static int brlog_xlate(struct xt_xlate *xl, - const struct xt_xlate_tg_params *params) -{ - const struct ebt_log_info *loginfo = (const void *)params->target->data; - - xt_xlate_add(xl, "log"); - if (loginfo->prefix[0]) { - if (params->escape_quotes) - xt_xlate_add(xl, " prefix \\\"%s\\\"", loginfo->prefix); - else - xt_xlate_add(xl, " prefix \"%s\"", loginfo->prefix); - } - - if (loginfo->loglevel != LOG_DEFAULT_LEVEL) - xt_xlate_add(xl, " level %s", eight_priority[loginfo->loglevel].c_name); - - xt_xlate_add(xl, " flags ether "); - - return 1; -} - -static struct xtables_target brlog_target = { - .name = "log", - .revision = 0, - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_log_info)), - .userspacesize = XT_ALIGN(sizeof(struct ebt_log_info)), - .init = brlog_init, - .help = brlog_help, - .parse = brlog_parse, - .final_check = brlog_final_check, - .print = brlog_print, - .xlate = brlog_xlate, - .extra_opts = brlog_opts, -}; - -void _init(void) -{ - xtables_register_target(&brlog_target); -} diff --git a/extensions/libebt_log.t b/extensions/libebt_log.t deleted file mode 100644 index a0df6169..00000000 --- a/extensions/libebt_log.t +++ /dev/null @@ -1,6 +0,0 @@ -:INPUT,FORWARD,OUTPUT ---log;=;OK ---log-level crit;=;OK ---log-level 1;--log-level alert --log-prefix "";OK ---log-level emerg --log-ip --log-arp --log-ip6;--log-level emerg --log-prefix "" --log-ip --log-arp --log-ip6 -j CONTINUE;OK ---log-level crit --log-ip --log-arp --log-ip6 --log-prefix foo;--log-level crit --log-prefix "foo" --log-ip --log-arp --log-ip6 -j CONTINUE;OK diff --git a/extensions/libebt_log.txlate b/extensions/libebt_log.txlate deleted file mode 100644 index 7ef8d5e1..00000000 --- a/extensions/libebt_log.txlate +++ /dev/null @@ -1,15 +0,0 @@ -ebtables-translate -A INPUT --log -nft add rule bridge filter INPUT log level notice flags ether counter - -ebtables-translate -A INPUT --log-level 1 -nft add rule bridge filter INPUT log level alert flags ether counter - -ebtables-translate -A INPUT --log-level crit -nft add rule bridge filter INPUT log level crit flags ether counter - -ebtables-translate -A INPUT --log-level emerg --log-ip --log-arp --log-ip6 -nft add rule bridge filter INPUT log level emerg flags ether counter - -ebtables-translate -A INPUT --log-level crit --log-ip --log-arp --log-ip6 --log-prefix foo -nft add rule bridge filter INPUT log prefix "foo" level crit flags ether counter - diff --git a/extensions/libebt_mark.c b/extensions/libebt_mark.c deleted file mode 100644 index 423c5c91..00000000 --- a/extensions/libebt_mark.c +++ /dev/null @@ -1,228 +0,0 @@ -/* ebt_mark - * - * Authors: - * Bart De Schuymer - * - * July, 2002, September 2006 - * - * Adapted by Arturo Borrero Gonzalez - * to use libxtables for ebtables-compat in 2015. - */ - -#include -#include -#include -#include -#include -#include -#include "iptables/nft.h" -#include "iptables/nft-bridge.h" - -#define MARK_TARGET '1' -#define MARK_SETMARK '2' -#define MARK_ORMARK '3' -#define MARK_ANDMARK '4' -#define MARK_XORMARK '5' -static const struct option brmark_opts[] = { - { .name = "mark-target",.has_arg = true, .val = MARK_TARGET }, - /* an oldtime messup, we should have always used the scheme - * -