|
| 1 | +// Copyright 2025 The gVisor Authors. |
| 2 | +// |
| 3 | +// Licensed under the Apache License, Version 2.0 (the "License"); |
| 4 | +// you may not use this file except in compliance with the License. |
| 5 | +// You may obtain a copy of the License at |
| 6 | +// |
| 7 | +// http://www.apache.org/licenses/LICENSE-2.0 |
| 8 | +// |
| 9 | +// Unless required by applicable law or agreed to in writing, software |
| 10 | +// distributed under the License is distributed on an "AS IS" BASIS, |
| 11 | +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 12 | +// See the License for the specific language governing permissions and |
| 13 | +// limitations under the License. |
| 14 | + |
| 15 | +package nftables |
| 16 | + |
| 17 | +import ( |
| 18 | + "fmt" |
| 19 | + |
| 20 | + "gvisor.dev/gvisor/pkg/abi/linux" |
| 21 | + "gvisor.dev/gvisor/pkg/syserr" |
| 22 | +) |
| 23 | + |
| 24 | +// metaKey is the key that determines the specific meta data to retrieve. |
| 25 | +// Note: corresponds to enum nft_meta_keys from |
| 26 | +// include/uapi/linux/netfilter/nf_tables.h and uses the same constants. |
| 27 | +type metaKey int |
| 28 | + |
| 29 | +// metaKeyStrings is a map of meta key to its string representation. |
| 30 | +var metaKeyStrings = map[metaKey]string{ |
| 31 | + linux.NFT_META_LEN: "NFT_META_LEN", |
| 32 | + linux.NFT_META_PROTOCOL: "NFT_META_PROTOCOL", |
| 33 | + linux.NFT_META_PRIORITY: "NFT_META_PRIORITY", |
| 34 | + linux.NFT_META_MARK: "NFT_META_MARK", |
| 35 | + linux.NFT_META_IIF: "NFT_META_IIF", |
| 36 | + linux.NFT_META_OIF: "NFT_META_OIF", |
| 37 | + linux.NFT_META_IIFNAME: "NFT_META_IIFNAME", |
| 38 | + linux.NFT_META_OIFNAME: "NFT_META_OIFNAME", |
| 39 | + linux.NFT_META_IIFTYPE: "NFT_META_IIFTYPE", |
| 40 | + linux.NFT_META_OIFTYPE: "NFT_META_OIFTYPE", |
| 41 | + linux.NFT_META_SKUID: "NFT_META_SKUID", |
| 42 | + linux.NFT_META_SKGID: "NFT_META_SKGID", |
| 43 | + linux.NFT_META_NFTRACE: "NFT_META_NFTRACE", |
| 44 | + linux.NFT_META_RTCLASSID: "NFT_META_RTCLASSID", |
| 45 | + linux.NFT_META_SECMARK: "NFT_META_SECMARK", |
| 46 | + linux.NFT_META_NFPROTO: "NFT_META_NFPROTO", |
| 47 | + linux.NFT_META_L4PROTO: "NFT_META_L4PROTO", |
| 48 | + linux.NFT_META_BRI_IIFNAME: "NFT_META_BRI_IIFNAME", |
| 49 | + linux.NFT_META_BRI_OIFNAME: "NFT_META_BRI_OIFNAME", |
| 50 | + linux.NFT_META_PKTTYPE: "NFT_META_PKTTYPE", |
| 51 | + linux.NFT_META_CPU: "NFT_META_CPU", |
| 52 | + linux.NFT_META_IIFGROUP: "NFT_META_IIFGROUP", |
| 53 | + linux.NFT_META_OIFGROUP: "NFT_META_OIFGROUP", |
| 54 | + linux.NFT_META_CGROUP: "NFT_META_CGROUP", |
| 55 | + linux.NFT_META_PRANDOM: "NFT_META_PRANDOM", |
| 56 | + linux.NFT_META_SECPATH: "NFT_META_SECPATH", |
| 57 | + linux.NFT_META_IIFKIND: "NFT_META_IIFKIND", |
| 58 | + linux.NFT_META_OIFKIND: "NFT_META_OIFKIND", |
| 59 | + linux.NFT_META_BRI_IIFPVID: "NFT_META_BRI_IIFPVID", |
| 60 | + linux.NFT_META_BRI_IIFVPROTO: "NFT_META_BRI_IIFVPROTO", |
| 61 | + linux.NFT_META_TIME_NS: "NFT_META_TIME_NS", |
| 62 | + linux.NFT_META_TIME_DAY: "NFT_META_TIME_DAY", |
| 63 | + linux.NFT_META_TIME_HOUR: "NFT_META_TIME_HOUR", |
| 64 | + linux.NFT_META_SDIF: "NFT_META_SDIF", |
| 65 | + linux.NFT_META_SDIFNAME: "NFT_META_SDIFNAME", |
| 66 | + linux.NFT_META_BRI_BROUTE: "NFT_META_BRI_BROUTE", |
| 67 | +} |
| 68 | + |
| 69 | +// String for metaKey returns the string representation of the meta key. This |
| 70 | +// supports strings for supported and unsupported meta keys. |
| 71 | +func (key metaKey) String() string { |
| 72 | + if keyStr, ok := metaKeyStrings[key]; ok { |
| 73 | + return keyStr |
| 74 | + } |
| 75 | + panic(fmt.Sprintf("invalid meta key: %d", int(key))) |
| 76 | +} |
| 77 | + |
| 78 | +// metaDataLengths holds the length in bytes for each supported meta key. |
| 79 | +var metaDataLengths = map[metaKey]int{ |
| 80 | + linux.NFT_META_LEN: 4, |
| 81 | + linux.NFT_META_PROTOCOL: 2, |
| 82 | + linux.NFT_META_NFPROTO: 1, |
| 83 | + linux.NFT_META_L4PROTO: 1, |
| 84 | + linux.NFT_META_SKUID: 4, |
| 85 | + linux.NFT_META_SKGID: 4, |
| 86 | + linux.NFT_META_RTCLASSID: 4, |
| 87 | + linux.NFT_META_PKTTYPE: 1, |
| 88 | + linux.NFT_META_PRANDOM: 4, |
| 89 | + linux.NFT_META_TIME_NS: 8, |
| 90 | + linux.NFT_META_TIME_DAY: 1, |
| 91 | + linux.NFT_META_TIME_HOUR: 4, |
| 92 | +} |
| 93 | + |
| 94 | +// validateMetaKey ensures the meta key is valid. |
| 95 | +func validateMetaKey(key metaKey) *syserr.AnnotatedError { |
| 96 | + switch key { |
| 97 | + case linux.NFT_META_LEN, linux.NFT_META_PROTOCOL, linux.NFT_META_NFPROTO, |
| 98 | + linux.NFT_META_L4PROTO, linux.NFT_META_SKUID, linux.NFT_META_SKGID, |
| 99 | + linux.NFT_META_RTCLASSID, linux.NFT_META_PKTTYPE, linux.NFT_META_PRANDOM, |
| 100 | + linux.NFT_META_TIME_NS, linux.NFT_META_TIME_DAY, linux.NFT_META_TIME_HOUR: |
| 101 | + |
| 102 | + return nil |
| 103 | + default: |
| 104 | + return syserr.NewAnnotatedError(syserr.ErrInvalidArgument, fmt.Sprintf("meta key %v is not supported", key)) |
| 105 | + } |
| 106 | +} |
| 107 | + |
| 108 | +var metaAttrPolicy = []NlaPolicy{ |
| 109 | + linux.NFTA_META_DREG: NlaPolicy{nlaType: linux.NLA_U32}, |
| 110 | + linux.NFTA_META_KEY: NlaPolicy{nlaType: linux.NLA_BE32, validator: AttrMaxValidator[uint32](255)}, |
| 111 | + linux.NFTA_META_SREG: NlaPolicy{nlaType: linux.NLA_U32}, |
| 112 | +} |
| 113 | + |
| 114 | +func initMeta(tab *Table, exprInfo ExprInfo) (operation, *syserr.AnnotatedError) { |
| 115 | + attrs, ok := NfParseWithPolicy(exprInfo.ExprData, metaAttrPolicy) |
| 116 | + if !ok { |
| 117 | + return nil, syserr.NewAnnotatedError(syserr.ErrInvalidArgument, "Nftables: Failed to parse meta expression data") |
| 118 | + } |
| 119 | + if _, ok := attrs[linux.NFTA_META_SREG]; ok { |
| 120 | + if _, ok := attrs[linux.NFTA_META_DREG]; ok { |
| 121 | + return nil, syserr.NewAnnotatedError(syserr.ErrInvalidArgument, "Nftables: Only one of NFTA_PAYLOAD_SREG and NFTA_PAYLOAD_DREG should be set") |
| 122 | + } |
| 123 | + return initMetaSet(attrs) |
| 124 | + } |
| 125 | + if _, ok := attrs[linux.NFTA_META_DREG]; ok { |
| 126 | + return initMetaLoad(attrs) |
| 127 | + } |
| 128 | + return nil, syserr.NewAnnotatedError(syserr.ErrInvalidArgument, "Nftables: NFTA_PAYLOAD_SREG or NFTA_PAYLOAD_DREG attribute is not found") |
| 129 | +} |
0 commit comments