| lh | 9ed821d | 2023-04-07 01:36:19 -0700 | [diff] [blame] | 1 | /* Code to save the iptables state, in human readable-form. */ | 
|  | 2 | /* (C) 1999 by Paul 'Rusty' Russell <rusty@rustcorp.com.au> and | 
|  | 3 | * (C) 2000-2002 by Harald Welte <laforge@gnumonks.org> | 
|  | 4 | * | 
|  | 5 | * This code is distributed under the terms of GNU GPL v2 | 
|  | 6 | * | 
|  | 7 | */ | 
|  | 8 | #include <getopt.h> | 
|  | 9 | #include <sys/errno.h> | 
|  | 10 | #include <stdio.h> | 
|  | 11 | #include <fcntl.h> | 
|  | 12 | #include <stdlib.h> | 
|  | 13 | #include <string.h> | 
|  | 14 | #include <time.h> | 
|  | 15 | #include <netdb.h> | 
|  | 16 | #include "libiptc/libiptc.h" | 
|  | 17 | #include "iptables.h" | 
|  | 18 | #include "iptables-multi.h" | 
|  | 19 |  | 
|  | 20 | #ifndef NO_SHARED_LIBS | 
|  | 21 | #include <dlfcn.h> | 
|  | 22 | #endif | 
|  | 23 |  | 
|  | 24 | static int show_binary = 0, show_counters = 0; | 
|  | 25 |  | 
|  | 26 | static const struct option options[] = { | 
|  | 27 | {.name = "binary",   .has_arg = false, .val = 'b'}, | 
|  | 28 | {.name = "counters", .has_arg = false, .val = 'c'}, | 
|  | 29 | {.name = "dump",     .has_arg = false, .val = 'd'}, | 
|  | 30 | {.name = "table",    .has_arg = true,  .val = 't'}, | 
|  | 31 | {.name = "modprobe", .has_arg = true,  .val = 'M'}, | 
|  | 32 | {NULL}, | 
|  | 33 | }; | 
|  | 34 |  | 
|  | 35 | /* Debugging prototype. */ | 
|  | 36 | static int for_each_table(int (*func)(const char *tablename)) | 
|  | 37 | { | 
|  | 38 | int ret = 1; | 
|  | 39 | FILE *procfile = NULL; | 
|  | 40 | char tablename[IPT_TABLE_MAXNAMELEN+1]; | 
|  | 41 |  | 
|  | 42 | procfile = fopen("/proc/net/ip_tables_names", "r"); | 
|  | 43 | if (!procfile) | 
|  | 44 | return ret; | 
|  | 45 |  | 
|  | 46 | while (fgets(tablename, sizeof(tablename), procfile)) { | 
|  | 47 | if (tablename[strlen(tablename) - 1] != '\n') | 
|  | 48 | xtables_error(OTHER_PROBLEM, | 
|  | 49 | "Badly formed tablename `%s'\n", | 
|  | 50 | tablename); | 
|  | 51 | tablename[strlen(tablename) - 1] = '\0'; | 
|  | 52 | ret &= func(tablename); | 
|  | 53 | } | 
|  | 54 |  | 
|  | 55 | return ret; | 
|  | 56 | } | 
|  | 57 |  | 
|  | 58 |  | 
|  | 59 | static int do_output(const char *tablename) | 
|  | 60 | { | 
|  | 61 | struct iptc_handle *h; | 
|  | 62 | const char *chain = NULL; | 
|  | 63 |  | 
|  | 64 | if (!tablename) | 
|  | 65 | return for_each_table(&do_output); | 
|  | 66 |  | 
|  | 67 | h = iptc_init(tablename); | 
|  | 68 | if (h == NULL) { | 
|  | 69 | xtables_load_ko(xtables_modprobe_program, false); | 
|  | 70 | h = iptc_init(tablename); | 
|  | 71 | } | 
|  | 72 | if (!h) | 
|  | 73 | xtables_error(OTHER_PROBLEM, "Cannot initialize: %s\n", | 
|  | 74 | iptc_strerror(errno)); | 
|  | 75 |  | 
|  | 76 | if (!show_binary) { | 
|  | 77 | time_t now = time(NULL); | 
|  | 78 |  | 
|  | 79 | printf("# Generated by iptables-save v%s on %s", | 
|  | 80 | IPTABLES_VERSION, ctime(&now)); | 
|  | 81 | printf("*%s\n", tablename); | 
|  | 82 |  | 
|  | 83 | /* Dump out chain names first, | 
|  | 84 | * thereby preventing dependency conflicts */ | 
|  | 85 | for (chain = iptc_first_chain(h); | 
|  | 86 | chain; | 
|  | 87 | chain = iptc_next_chain(h)) { | 
|  | 88 |  | 
|  | 89 | printf(":%s ", chain); | 
|  | 90 | if (iptc_builtin(chain, h)) { | 
|  | 91 | struct ipt_counters count; | 
|  | 92 | printf("%s ", | 
|  | 93 | iptc_get_policy(chain, &count, h)); | 
|  | 94 | printf("[%llu:%llu]\n", (unsigned long long)count.pcnt, (unsigned long long)count.bcnt); | 
|  | 95 | } else { | 
|  | 96 | printf("- [0:0]\n"); | 
|  | 97 | } | 
|  | 98 | } | 
|  | 99 |  | 
|  | 100 |  | 
|  | 101 | for (chain = iptc_first_chain(h); | 
|  | 102 | chain; | 
|  | 103 | chain = iptc_next_chain(h)) { | 
|  | 104 | const struct ipt_entry *e; | 
|  | 105 |  | 
|  | 106 | /* Dump out rules */ | 
|  | 107 | e = iptc_first_rule(chain, h); | 
|  | 108 | while(e) { | 
|  | 109 | print_rule(e, h, chain, show_counters); | 
|  | 110 | e = iptc_next_rule(e, h); | 
|  | 111 | } | 
|  | 112 | } | 
|  | 113 |  | 
|  | 114 | now = time(NULL); | 
|  | 115 | printf("COMMIT\n"); | 
|  | 116 | printf("# Completed on %s", ctime(&now)); | 
|  | 117 | } else { | 
|  | 118 | /* Binary, huh?  OK. */ | 
|  | 119 | xtables_error(OTHER_PROBLEM, "Binary NYI\n"); | 
|  | 120 | } | 
|  | 121 |  | 
|  | 122 | iptc_free(h); | 
|  | 123 |  | 
|  | 124 | return 1; | 
|  | 125 | } | 
|  | 126 |  | 
|  | 127 | /* Format: | 
|  | 128 | * :Chain name POLICY packets bytes | 
|  | 129 | * rule | 
|  | 130 | */ | 
|  | 131 | #ifdef IPTABLES_MULTI | 
|  | 132 | int | 
|  | 133 | iptables_save_main(int argc, char *argv[]) | 
|  | 134 | #else | 
|  | 135 | int | 
|  | 136 | main(int argc, char *argv[]) | 
|  | 137 | #endif | 
|  | 138 | { | 
|  | 139 | const char *tablename = NULL; | 
|  | 140 | int c; | 
|  | 141 |  | 
|  | 142 | iptables_globals.program_name = "iptables-save"; | 
|  | 143 | c = xtables_init_all(&iptables_globals, NFPROTO_IPV4); | 
|  | 144 | if (c < 0) { | 
|  | 145 | fprintf(stderr, "%s/%s Failed to initialize xtables\n", | 
|  | 146 | iptables_globals.program_name, | 
|  | 147 | iptables_globals.program_version); | 
|  | 148 | exit(1); | 
|  | 149 | } | 
|  | 150 | #ifdef NO_SHARED_LIBS | 
|  | 151 | init_extensions(); | 
|  | 152 | #endif | 
|  | 153 |  | 
|  | 154 | while ((c = getopt_long(argc, argv, "bcdt:", options, NULL)) != -1) { | 
|  | 155 | switch (c) { | 
|  | 156 | case 'b': | 
|  | 157 | show_binary = 1; | 
|  | 158 | break; | 
|  | 159 |  | 
|  | 160 | case 'c': | 
|  | 161 | show_counters = 1; | 
|  | 162 | break; | 
|  | 163 |  | 
|  | 164 | case 't': | 
|  | 165 | /* Select specific table. */ | 
|  | 166 | tablename = optarg; | 
|  | 167 | break; | 
|  | 168 | case 'M': | 
|  | 169 | xtables_modprobe_program = optarg; | 
|  | 170 | break; | 
|  | 171 | case 'd': | 
|  | 172 | do_output(tablename); | 
|  | 173 | exit(0); | 
|  | 174 | } | 
|  | 175 | } | 
|  | 176 |  | 
|  | 177 | if (optind < argc) { | 
|  | 178 | fprintf(stderr, "Unknown arguments found on commandline\n"); | 
|  | 179 | exit(1); | 
|  | 180 | } | 
|  | 181 |  | 
|  | 182 | return !do_output(tablename); | 
|  | 183 | } |