blob: a60d6a7ea46614fe0a7ca36094ce840dcaa321d7 [file] [log] [blame]
Bart De Schuymer1abc55d2002-06-01 19:23:47 +00001#include <stdio.h>
2#include <string.h>
3#include <stdlib.h>
Bart De Schuymer1abc55d2002-06-01 19:23:47 +00004#include <getopt.h>
5#include "../include/ebtables_u.h"
Bart De Schuymerc1939b12002-11-20 19:41:54 +00006#include "../include/ethernetdb.h"
Bart De Schuymerf46b2632003-05-01 20:18:00 +00007#include <linux/if_ether.h>
Bart De Schuymer1abc55d2002-06-01 19:23:47 +00008#include <linux/netfilter_bridge/ebt_arp.h>
9
10#define ARP_OPCODE '1'
11#define ARP_HTYPE '2'
12#define ARP_PTYPE '3'
13#define ARP_IP_S '4'
14#define ARP_IP_D '5'
Bart De Schuymerf46b2632003-05-01 20:18:00 +000015#define ARP_MAC_S '6'
16#define ARP_MAC_D '7'
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000017static struct option opts[] =
18{
19 { "arp-opcode" , required_argument, 0, ARP_OPCODE },
20 { "arp-op" , required_argument, 0, ARP_OPCODE },
21 { "arp-htype" , required_argument, 0, ARP_HTYPE },
22 { "arp-ptype" , required_argument, 0, ARP_PTYPE },
23 { "arp-ip-src" , required_argument, 0, ARP_IP_S },
24 { "arp-ip-dst" , required_argument, 0, ARP_IP_D },
Bart De Schuymerf46b2632003-05-01 20:18:00 +000025 { "arp-mac-src" , required_argument, 0, ARP_MAC_S },
26 { "arp-mac-dst" , required_argument, 0, ARP_MAC_D },
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000027 { 0 }
28};
29
Bart De Schuymer9cfd6542002-08-13 16:08:08 +000030#define NUMOPCODES 9
Bart De Schuymer9895a8e2003-01-11 10:14:24 +000031/* a few names */
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000032static char *opcodes[] =
33{
34 "Request",
35 "Reply",
Bart De Schuymer9cfd6542002-08-13 16:08:08 +000036 "Request_Reverse",
37 "Reply_Reverse",
38 "DRARP_Request",
39 "DRARP_Reply",
40 "DRARP_Error",
41 "InARP_Request",
42 "ARP_NAK",
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000043};
44
45static void print_help()
46{
Bart De Schuymer9cfd6542002-08-13 16:08:08 +000047 int i;
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000048
49 printf(
50"arp options:\n"
Bart De Schuymerf46b2632003-05-01 20:18:00 +000051"--arp-opcode opcode : ARP opcode (integer or string)\n"
52"--arp-htype type : ARP hardware type (integer or string)\n"
53"--arp-ptype type : ARP protocol type (hexadecimal or string)\n"
54"--arp-ip-src [!] address[/mask]: ARP IP source specification\n"
55"--arp-ip-dst [!] address[/mask]: ARP IP target specification\n"
56"--arp-mac-src [!] address[/mask]: ARP MAC source specification\n"
57"--arp-mac-dst [!] address[/mask]: ARP MAC target specification\n"
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000058" opcode strings: \n");
Bart De Schuymer9cfd6542002-08-13 16:08:08 +000059 for (i = 0; i < NUMOPCODES; i++)
Bart De Schuymer1446c292003-05-25 09:47:01 +000060 printf(" %d = %s\n", i + 1, opcodes[i]);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000061 printf(
Bart De Schuymer9cfd6542002-08-13 16:08:08 +000062" hardware type string: 1 = Ethernet\n"
fnm36c3dc652002-11-21 10:49:38 +000063" protocol type string: see "_PATH_ETHERTYPES"\n");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000064}
65
66static void init(struct ebt_entry_match *match)
67{
68 struct ebt_arp_info *arpinfo = (struct ebt_arp_info *)match->data;
69
70 arpinfo->invflags = 0;
71 arpinfo->bitmask = 0;
72}
73
Bart De Schuymerf46b2632003-05-01 20:18:00 +000074
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000075#define OPT_OPCODE 0x01
76#define OPT_HTYPE 0x02
77#define OPT_PTYPE 0x04
78#define OPT_IP_S 0x08
79#define OPT_IP_D 0x10
Bart De Schuymerf46b2632003-05-01 20:18:00 +000080#define OPT_MAC_S 0x20
81#define OPT_MAC_D 0x40
Bart De Schuymer7b9aaeb2002-06-23 20:38:34 +000082static int parse(int c, char **argv, int argc, const struct ebt_u_entry *entry,
83 unsigned int *flags, struct ebt_entry_match **match)
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000084{
85 struct ebt_arp_info *arpinfo = (struct ebt_arp_info *)(*match)->data;
Bart De Schuymer9cfd6542002-08-13 16:08:08 +000086 long int i;
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000087 char *end;
Bart De Schuymer9cfd6542002-08-13 16:08:08 +000088 uint32_t *addr;
89 uint32_t *mask;
Bart De Schuymerf46b2632003-05-01 20:18:00 +000090 char *maddr;
91 char *mmask;
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000092
93 switch (c) {
94 case ARP_OPCODE:
Bart De Schuymer8339ff12004-01-14 20:05:27 +000095 ebt_check_option(flags, OPT_OPCODE);
96 if (ebt_check_inverse(optarg))
Bart De Schuymer1abc55d2002-06-01 19:23:47 +000097 arpinfo->invflags |= EBT_ARP_OPCODE;
98
99 if (optind > argc)
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000100 print_error("Missing ARP opcode argument");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000101 i = strtol(argv[optind - 1], &end, 10);
102 if (i < 0 || i >= (0x1 << 16) || *end !='\0') {
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000103 for (i = 0; i < NUMOPCODES; i++)
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000104 if (!strcasecmp(opcodes[i], optarg))
105 break;
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000106 if (i == NUMOPCODES)
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000107 print_error("Problem with specified "
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000108 "ARP opcode");
109 i++;
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000110 }
111 arpinfo->opcode = htons(i);
112 arpinfo->bitmask |= EBT_ARP_OPCODE;
113 break;
114
115 case ARP_HTYPE:
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000116 ebt_check_option(flags, OPT_HTYPE);
117 if (ebt_check_inverse(optarg))
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000118 arpinfo->invflags |= EBT_ARP_HTYPE;
119
120 if (optind > argc)
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000121 print_error("Missing ARP hardware type argument");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000122 i = strtol(argv[optind - 1], &end, 10);
123 if (i < 0 || i >= (0x1 << 16) || *end !='\0') {
124 if (!strcasecmp("Ethernet", argv[optind - 1]))
125 i = 1;
126 else
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000127 print_error("Problem with specified ARP "
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000128 "hardware type");
129 }
130 arpinfo->htype = htons(i);
131 arpinfo->bitmask |= EBT_ARP_HTYPE;
132 break;
133
134 case ARP_PTYPE:
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000135 {
136 uint16_t proto;
137
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000138 ebt_check_option(flags, OPT_PTYPE);
139 if (ebt_check_inverse(optarg))
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000140 arpinfo->invflags |= EBT_ARP_PTYPE;
141
142 if (optind > argc)
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000143 print_error("Missing ARP protocol type argument");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000144 i = strtol(argv[optind - 1], &end, 16);
145 if (i < 0 || i >= (0x1 << 16) || *end !='\0') {
Bart De Schuymerc1939b12002-11-20 19:41:54 +0000146 struct ethertypeent *ent;
147
148 ent = getethertypebyname(argv[optind - 1]);
149 if (!ent)
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000150 print_error("Problem with specified ARP "
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000151 "protocol type");
Bart De Schuymerc1939b12002-11-20 19:41:54 +0000152 proto = ent->e_ethertype;
153
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000154 } else
155 proto = i;
156 arpinfo->ptype = htons(proto);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000157 arpinfo->bitmask |= EBT_ARP_PTYPE;
158 break;
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000159 }
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000160
161 case ARP_IP_S:
162 case ARP_IP_D:
163 if (c == ARP_IP_S) {
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000164 ebt_check_option(flags, OPT_IP_S);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000165 addr = &arpinfo->saddr;
166 mask = &arpinfo->smsk;
167 arpinfo->bitmask |= EBT_ARP_SRC_IP;
168 } else {
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000169 ebt_check_option(flags, OPT_IP_D);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000170 addr = &arpinfo->daddr;
171 mask = &arpinfo->dmsk;
172 arpinfo->bitmask |= EBT_ARP_DST_IP;
173 }
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000174 if (ebt_check_inverse(optarg)) {
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000175 if (c == ARP_IP_S)
176 arpinfo->invflags |= EBT_ARP_SRC_IP;
177 else
178 arpinfo->invflags |= EBT_ARP_DST_IP;
179 }
180 if (optind > argc)
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000181 print_error("Missing ARP IP address argument");
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000182 ebt_parse_ip_address(argv[optind - 1], addr, mask);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000183 break;
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000184
185 case ARP_MAC_S:
186 case ARP_MAC_D:
187 if (c == ARP_MAC_S) {
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000188 ebt_check_option(flags, OPT_MAC_S);
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000189 maddr = arpinfo->smaddr;
190 mmask = arpinfo->smmsk;
191 arpinfo->bitmask |= EBT_ARP_SRC_MAC;
192 } else {
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000193 ebt_check_option(flags, OPT_MAC_D);
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000194 maddr = arpinfo->dmaddr;
195 mmask = arpinfo->dmmsk;
196 arpinfo->bitmask |= EBT_ARP_DST_MAC;
197 }
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000198 if (ebt_check_inverse(optarg)) {
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000199 if (c == ARP_MAC_S)
200 arpinfo->invflags |= EBT_ARP_SRC_MAC;
201 else
202 arpinfo->invflags |= EBT_ARP_DST_MAC;
203 }
204 if (optind > argc)
205 print_error("Missing ARP MAC address argument");
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000206 if (ebt_get_mac_and_mask(argv[optind - 1], maddr, mmask))
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000207 print_error("Problem with ARP MAC address argument");
208 break;
209
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000210 default:
211 return 0;
212 }
213 return 1;
214}
215
216static void final_check(const struct ebt_u_entry *entry,
Bart De Schuymer7b9aaeb2002-06-23 20:38:34 +0000217 const struct ebt_entry_match *match, const char *name,
Bart De Schuymerc9b52932002-08-24 13:26:34 +0000218 unsigned int hookmask, unsigned int time)
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000219{
Bart De Schuymer40573192002-08-29 16:48:36 +0000220 if ((entry->ethproto != ETH_P_ARP && entry->ethproto != ETH_P_RARP) ||
Bart De Schuymerb2632c52002-08-09 18:57:05 +0000221 entry->invflags & EBT_IPROTO)
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000222 print_error("For (R)ARP filtering the protocol must be "
223 "specified as ARP or RARP");
224}
225
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000226static void print(const struct ebt_u_entry *entry,
227 const struct ebt_entry_match *match)
228{
229 struct ebt_arp_info *arpinfo = (struct ebt_arp_info *)match->data;
230 int i;
231
232 if (arpinfo->bitmask & EBT_ARP_OPCODE) {
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000233 int opcode = ntohs(arpinfo->opcode);
Bart De Schuymer41e8a192002-06-23 08:03:12 +0000234 printf("--arp-op ");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000235 if (arpinfo->invflags & EBT_ARP_OPCODE)
236 printf("! ");
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000237 if (opcode > 0 && opcode <= NUMOPCODES)
238 printf("%s ", opcodes[opcode - 1]);
239 else
240 printf("%d ", opcode);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000241 }
242 if (arpinfo->bitmask & EBT_ARP_HTYPE) {
Bart De Schuymer41e8a192002-06-23 08:03:12 +0000243 printf("--arp-htype ");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000244 if (arpinfo->invflags & EBT_ARP_HTYPE)
245 printf("! ");
246 printf("%d ", ntohs(arpinfo->htype));
247 }
248 if (arpinfo->bitmask & EBT_ARP_PTYPE) {
Bart De Schuymerc1939b12002-11-20 19:41:54 +0000249 struct ethertypeent *ent;
250
Bart De Schuymer41e8a192002-06-23 08:03:12 +0000251 printf("--arp-ptype ");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000252 if (arpinfo->invflags & EBT_ARP_PTYPE)
253 printf("! ");
Bart De Schuymerc1939b12002-11-20 19:41:54 +0000254 ent = getethertypebynumber(ntohs(arpinfo->ptype));
255 if (!ent)
Bart De Schuymer9cfd6542002-08-13 16:08:08 +0000256 printf("0x%x ", ntohs(arpinfo->ptype));
257 else
Bart De Schuymerc1939b12002-11-20 19:41:54 +0000258 printf("%s ", ent->e_name);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000259 }
260 if (arpinfo->bitmask & EBT_ARP_SRC_IP) {
Bart De Schuymer41e8a192002-06-23 08:03:12 +0000261 printf("--arp-ip-src ");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000262 if (arpinfo->invflags & EBT_ARP_SRC_IP)
263 printf("! ");
264 for (i = 0; i < 4; i++)
265 printf("%d%s", ((unsigned char *)&arpinfo->saddr)[i],
266 (i == 3) ? "" : ".");
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000267 printf("%s ", ebt_mask_to_dotted(arpinfo->smsk));
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000268 }
269 if (arpinfo->bitmask & EBT_ARP_DST_IP) {
Bart De Schuymer41e8a192002-06-23 08:03:12 +0000270 printf("--arp-ip-dst ");
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000271 if (arpinfo->invflags & EBT_ARP_DST_IP)
272 printf("! ");
273 for (i = 0; i < 4; i++)
274 printf("%d%s", ((unsigned char *)&arpinfo->daddr)[i],
275 (i == 3) ? "" : ".");
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000276 printf("%s ", ebt_mask_to_dotted(arpinfo->dmsk));
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000277 }
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000278 if (arpinfo->bitmask & EBT_ARP_SRC_MAC) {
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000279 printf("--arp-mac-src ");
280 if (arpinfo->invflags & EBT_ARP_SRC_MAC)
281 printf("! ");
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000282 ebt_print_mac_and_mask(arpinfo->smaddr, arpinfo->smmsk);
Bart De Schuymer1446c292003-05-25 09:47:01 +0000283 printf(" ");
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000284 }
285 if (arpinfo->bitmask & EBT_ARP_DST_MAC) {
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000286 printf("--arp-mac-dst ");
287 if (arpinfo->invflags & EBT_ARP_DST_MAC)
288 printf("! ");
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000289 ebt_print_mac_and_mask(arpinfo->dmaddr, arpinfo->dmmsk);
Bart De Schuymer1446c292003-05-25 09:47:01 +0000290 printf(" ");
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000291 }
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000292}
293
294static int compare(const struct ebt_entry_match *m1,
295 const struct ebt_entry_match *m2)
296{
297 struct ebt_arp_info *arpinfo1 = (struct ebt_arp_info *)m1->data;
298 struct ebt_arp_info *arpinfo2 = (struct ebt_arp_info *)m2->data;
299
300 if (arpinfo1->bitmask != arpinfo2->bitmask)
301 return 0;
302 if (arpinfo1->invflags != arpinfo2->invflags)
303 return 0;
304 if (arpinfo1->bitmask & EBT_ARP_OPCODE) {
305 if (arpinfo1->opcode != arpinfo2->opcode)
306 return 0;
307 }
308 if (arpinfo1->bitmask & EBT_ARP_HTYPE) {
309 if (arpinfo1->htype != arpinfo2->htype)
310 return 0;
311 }
312 if (arpinfo1->bitmask & EBT_ARP_PTYPE) {
313 if (arpinfo1->ptype != arpinfo2->ptype)
314 return 0;
315 }
316 if (arpinfo1->bitmask & EBT_ARP_SRC_IP) {
317 if (arpinfo1->saddr != arpinfo2->saddr)
318 return 0;
319 if (arpinfo1->smsk != arpinfo2->smsk)
320 return 0;
321 }
322 if (arpinfo1->bitmask & EBT_ARP_DST_IP) {
323 if (arpinfo1->daddr != arpinfo2->daddr)
324 return 0;
325 if (arpinfo1->dmsk != arpinfo2->dmsk)
326 return 0;
327 }
Bart De Schuymerf46b2632003-05-01 20:18:00 +0000328 if (arpinfo1->bitmask & EBT_ARP_SRC_MAC) {
329 if (arpinfo1->smaddr != arpinfo2->smaddr)
330 return 0;
331 if (arpinfo1->smmsk != arpinfo2->smmsk)
332 return 0;
333 }
334 if (arpinfo1->bitmask & EBT_ARP_DST_MAC) {
335 if (arpinfo1->dmaddr != arpinfo2->dmaddr)
336 return 0;
337 if (arpinfo1->dmmsk != arpinfo2->dmmsk)
338 return 0;
339 }
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000340 return 1;
341}
342
343static struct ebt_u_match arp_match =
344{
Bart De Schuymer7cf1cca2003-08-30 16:20:19 +0000345 .name = EBT_ARP_MATCH,
346 .size = sizeof(struct ebt_arp_info),
347 .help = print_help,
348 .init = init,
349 .parse = parse,
350 .final_check = final_check,
351 .print = print,
352 .compare = compare,
353 .extra_ops = opts,
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000354};
355
356static void _init(void) __attribute__ ((constructor));
357static void _init(void)
358{
Bart De Schuymer8339ff12004-01-14 20:05:27 +0000359 ebt_register_match(&arp_match);
Bart De Schuymer1abc55d2002-06-01 19:23:47 +0000360}