aboutsummaryrefslogtreecommitdiff
path: root/src/expr/meta.rs
blob: bb8023d869860d06df2150766ebaf213fefdd484 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
use super::{Expression, Register, Rule};
use crate::{
    create_wrapper_type,
    nlmsg::{NfNetlinkAttribute, NfNetlinkDeserializable},
    parser::DecodeError,
    sys,
};
use std::convert::TryFrom;

/// A meta expression refers to meta data associated with a packet.
#[derive(Debug, Copy, Clone, Eq, PartialEq)]
#[repr(u32)]
#[non_exhaustive]
pub enum MetaType {
    /// Packet ethertype protocol (skb->protocol), invalid in OUTPUT.
    Protocol = sys::NFT_META_PROTOCOL,
    /// Packet mark.
    Mark = sys::NFT_META_MARK,
    /// Packet input interface index (dev->ifindex).
    Iif = sys::NFT_META_IIF,
    /// Packet output interface index (dev->ifindex).
    Oif = sys::NFT_META_OIF,
    /// Packet input interface name (dev->name).
    IifName = sys::NFT_META_IIFNAME,
    /// Packet output interface name (dev->name).
    OifName = sys::NFT_META_OIFNAME,
    /// Packet input interface type (dev->type).
    IifType = sys::NFT_META_IFTYPE,
    /// Packet output interface type (dev->type).
    OifType = sys::NFT_META_OIFTYPE,
    /// Originating socket UID (fsuid).
    SkUid = sys::NFT_META_SKUID,
    /// Originating socket GID (fsgid).
    SkGid = sys::NFT_META_SKGID,
    /// Netfilter protocol (Transport layer protocol).
    NfProto = sys::NFT_META_NFPROTO,
    /// Layer 4 protocol number.
    L4Proto = sys::NFT_META_L4PROTO,
    /// Socket control group (skb->sk->sk_classid).
    Cgroup = sys::NFT_META_CGROUP,
    /// A 32bit pseudo-random number.
    PRandom = sys::NFT_META_PRANDOM,
}

impl NfNetlinkAttribute for MetaType {
    fn get_size(&self) -> usize {
        (*self as u32).get_size()
    }

    unsafe fn write_payload(&self, addr: *mut u8) {
        (*self as u32).write_payload(addr);
    }
}

impl NfNetlinkDeserializable for MetaType {
    fn deserialize(buf: &[u8]) -> Result<(Self, &[u8]), DecodeError> {
        let (v, remaining_data) = u32::deserialize(buf)?;
        Ok((
            match v {
                sys::NFT_META_PROTOCOL => Self::Protocol,
                sys::NFT_META_MARK => Self::Mark,
                sys::NFT_META_IIF => Self::Iif,
                sys::NFT_META_OIF => Self::Oif,
                sys::NFT_META_IIFNAME => Self::IifName,
                sys::NFT_META_OIFNAME => Self::OifName,
                sys::NFT_META_IFTYPE => Self::IifType,
                sys::NFT_META_OIFTYPE => Self::OifType,
                sys::NFT_META_SKUID => Self::SkUid,
                sys::NFT_META_SKGID => Self::SkGid,
                sys::NFT_META_NFPROTO => Self::NfProto,
                sys::NFT_META_L4PROTO => Self::L4Proto,
                sys::NFT_META_CGROUP => Self::Cgroup,
                sys::NFT_META_PRANDOM => Self::PRandom,
                value => return Err(DecodeError::UnknownMetaType(value)),
            },
            remaining_data,
        ))
    }
}

create_wrapper_type!(
    inline: Meta,
    [
        (
            get_dreg,
            set_dreg,
            with_dreg,
            sys::NFTA_META_DREG,
            dreg,
            Register
        ),
        (
            get_key,
            set_key,
            with_key,
            sys::NFTA_META_KEY,
            key,
            MetaType
        ),
        (
            get_sreg,
            set_sreg,
            with_sreg,
            sys::NFTA_META_SREG,
            sreg,
            Register
        )
    ]
);

impl Expression for Meta {
    fn get_name() -> &'static str {
        "meta"
    }
}