Blame view
net/netfilter/xt_statistic.c
2.5 KB
f3389805e
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 |
/* * Copyright (c) 2006 Patrick McHardy <kaber@trash.net> * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License version 2 as * published by the Free Software Foundation. * * Based on ipt_random and ipt_nth by Fabrice MARIE <fabrice@netfilter.org>. */ #include <linux/init.h> #include <linux/spinlock.h> #include <linux/skbuff.h> #include <linux/net.h> |
5a0e3ad6a
|
15 |
#include <linux/slab.h> |
f3389805e
|
16 17 18 |
#include <linux/netfilter/xt_statistic.h> #include <linux/netfilter/x_tables.h> |
acc738fec
|
19 |
struct xt_statistic_priv { |
fabf3a85a
|
20 21 |
atomic_t count; } ____cacheline_aligned_in_smp; |
acc738fec
|
22 |
|
f3389805e
|
23 24 |
MODULE_LICENSE("GPL"); MODULE_AUTHOR("Patrick McHardy <kaber@trash.net>"); |
2ae15b64e
|
25 |
MODULE_DESCRIPTION("Xtables: statistics-based matching (\"Nth\", random)"); |
f3389805e
|
26 27 |
MODULE_ALIAS("ipt_statistic"); MODULE_ALIAS("ip6t_statistic"); |
1d93a9cba
|
28 |
static bool |
62fc80510
|
29 |
statistic_mt(const struct sk_buff *skb, struct xt_action_param *par) |
f3389805e
|
30 |
{ |
acc738fec
|
31 |
const struct xt_statistic_info *info = par->matchinfo; |
1d93a9cba
|
32 |
bool ret = info->flags & XT_STATISTIC_INVERT; |
fabf3a85a
|
33 |
int nval, oval; |
f3389805e
|
34 35 36 37 |
switch (info->mode) { case XT_STATISTIC_MODE_RANDOM: if ((net_random() & 0x7FFFFFFF) < info->u.random.probability) |
1d93a9cba
|
38 |
ret = !ret; |
f3389805e
|
39 40 |
break; case XT_STATISTIC_MODE_NTH: |
fabf3a85a
|
41 42 43 44 45 |
do { oval = atomic_read(&info->master->count); nval = (oval == info->u.nth.every) ? 0 : oval + 1; } while (atomic_cmpxchg(&info->master->count, oval, nval) != oval); if (nval == 0) |
1d93a9cba
|
46 |
ret = !ret; |
f3389805e
|
47 48 49 50 51 |
break; } return ret; } |
b0f38452f
|
52 |
static int statistic_mt_check(const struct xt_mtchk_param *par) |
f3389805e
|
53 |
{ |
9b4fce7a3
|
54 |
struct xt_statistic_info *info = par->matchinfo; |
f3389805e
|
55 56 57 |
if (info->mode > XT_STATISTIC_MODE_MAX || info->flags & ~XT_STATISTIC_MASK) |
bd414ee60
|
58 |
return -EINVAL; |
acc738fec
|
59 60 |
info->master = kzalloc(sizeof(*info->master), GFP_KERNEL); |
85bc3f381
|
61 |
if (info->master == NULL) |
4a5a5c73b
|
62 |
return -ENOMEM; |
fabf3a85a
|
63 |
atomic_set(&info->master->count, info->u.nth.count); |
acc738fec
|
64 |
|
bd414ee60
|
65 |
return 0; |
f3389805e
|
66 |
} |
acc738fec
|
67 68 69 70 71 72 |
static void statistic_mt_destroy(const struct xt_mtdtor_param *par) { const struct xt_statistic_info *info = par->matchinfo; kfree(info->master); } |
55b69e910
|
73 74 75 76 77 78 |
static struct xt_match xt_statistic_mt_reg __read_mostly = { .name = "statistic", .revision = 0, .family = NFPROTO_UNSPEC, .match = statistic_mt, .checkentry = statistic_mt_check, |
acc738fec
|
79 |
.destroy = statistic_mt_destroy, |
55b69e910
|
80 81 |
.matchsize = sizeof(struct xt_statistic_info), .me = THIS_MODULE, |
f3389805e
|
82 |
}; |
d3c5ee6d5
|
83 |
static int __init statistic_mt_init(void) |
f3389805e
|
84 |
{ |
55b69e910
|
85 |
return xt_register_match(&xt_statistic_mt_reg); |
f3389805e
|
86 |
} |
d3c5ee6d5
|
87 |
static void __exit statistic_mt_exit(void) |
f3389805e
|
88 |
{ |
55b69e910
|
89 |
xt_unregister_match(&xt_statistic_mt_reg); |
f3389805e
|
90 |
} |
d3c5ee6d5
|
91 92 |
module_init(statistic_mt_init); module_exit(statistic_mt_exit); |