Blame view

net/netfilter/xt_statistic.c 2.5 KB
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
1
2
3
4
5
6
7
8
9
10
11
12
13
14
  /*
   * Copyright (c) 2006 Patrick McHardy <kaber@trash.net>
   *
   * This program is free software; you can redistribute it and/or modify
   * it under the terms of the GNU General Public License version 2 as
   * published by the Free Software Foundation.
   *
   * Based on ipt_random and ipt_nth by Fabrice MARIE <fabrice@netfilter.org>.
   */
  
  #include <linux/init.h>
  #include <linux/spinlock.h>
  #include <linux/skbuff.h>
  #include <linux/net.h>
5a0e3ad6a   Tejun Heo   include cleanup: ...
15
  #include <linux/slab.h>
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
16
17
18
  
  #include <linux/netfilter/xt_statistic.h>
  #include <linux/netfilter/x_tables.h>
acc738fec   Jan Engelhardt   netfilter: xtable...
19
  struct xt_statistic_priv {
fabf3a85a   Eric Dumazet   netfilter: xt_sta...
20
21
  	atomic_t count;
  } ____cacheline_aligned_in_smp;
acc738fec   Jan Engelhardt   netfilter: xtable...
22

f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
23
24
  MODULE_LICENSE("GPL");
  MODULE_AUTHOR("Patrick McHardy <kaber@trash.net>");
2ae15b64e   Jan Engelhardt   [NETFILTER]: Upda...
25
  MODULE_DESCRIPTION("Xtables: statistics-based matching (\"Nth\", random)");
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
26
27
  MODULE_ALIAS("ipt_statistic");
  MODULE_ALIAS("ip6t_statistic");
1d93a9cba   Jan Engelhardt   [NETFILTER]: x_ta...
28
  static bool
62fc80510   Jan Engelhardt   netfilter: xtable...
29
  statistic_mt(const struct sk_buff *skb, struct xt_action_param *par)
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
30
  {
acc738fec   Jan Engelhardt   netfilter: xtable...
31
  	const struct xt_statistic_info *info = par->matchinfo;
1d93a9cba   Jan Engelhardt   [NETFILTER]: x_ta...
32
  	bool ret = info->flags & XT_STATISTIC_INVERT;
fabf3a85a   Eric Dumazet   netfilter: xt_sta...
33
  	int nval, oval;
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
34
35
36
37
  
  	switch (info->mode) {
  	case XT_STATISTIC_MODE_RANDOM:
  		if ((net_random() & 0x7FFFFFFF) < info->u.random.probability)
1d93a9cba   Jan Engelhardt   [NETFILTER]: x_ta...
38
  			ret = !ret;
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
39
40
  		break;
  	case XT_STATISTIC_MODE_NTH:
fabf3a85a   Eric Dumazet   netfilter: xt_sta...
41
42
43
44
45
  		do {
  			oval = atomic_read(&info->master->count);
  			nval = (oval == info->u.nth.every) ? 0 : oval + 1;
  		} while (atomic_cmpxchg(&info->master->count, oval, nval) != oval);
  		if (nval == 0)
1d93a9cba   Jan Engelhardt   [NETFILTER]: x_ta...
46
  			ret = !ret;
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
47
48
49
50
51
  		break;
  	}
  
  	return ret;
  }
b0f38452f   Jan Engelhardt   netfilter: xtable...
52
  static int statistic_mt_check(const struct xt_mtchk_param *par)
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
53
  {
9b4fce7a3   Jan Engelhardt   netfilter: xtable...
54
  	struct xt_statistic_info *info = par->matchinfo;
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
55
56
57
  
  	if (info->mode > XT_STATISTIC_MODE_MAX ||
  	    info->flags & ~XT_STATISTIC_MASK)
bd414ee60   Jan Engelhardt   netfilter: xtable...
58
  		return -EINVAL;
acc738fec   Jan Engelhardt   netfilter: xtable...
59
60
  
  	info->master = kzalloc(sizeof(*info->master), GFP_KERNEL);
85bc3f381   Jan Engelhardt   netfilter: xtable...
61
  	if (info->master == NULL)
4a5a5c73b   Jan Engelhardt   netfilter: xtable...
62
  		return -ENOMEM;
fabf3a85a   Eric Dumazet   netfilter: xt_sta...
63
  	atomic_set(&info->master->count, info->u.nth.count);
acc738fec   Jan Engelhardt   netfilter: xtable...
64

bd414ee60   Jan Engelhardt   netfilter: xtable...
65
  	return 0;
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
66
  }
acc738fec   Jan Engelhardt   netfilter: xtable...
67
68
69
70
71
72
  static void statistic_mt_destroy(const struct xt_mtdtor_param *par)
  {
  	const struct xt_statistic_info *info = par->matchinfo;
  
  	kfree(info->master);
  }
55b69e910   Jan Engelhardt   netfilter: implem...
73
74
75
76
77
78
  static struct xt_match xt_statistic_mt_reg __read_mostly = {
  	.name       = "statistic",
  	.revision   = 0,
  	.family     = NFPROTO_UNSPEC,
  	.match      = statistic_mt,
  	.checkentry = statistic_mt_check,
acc738fec   Jan Engelhardt   netfilter: xtable...
79
  	.destroy    = statistic_mt_destroy,
55b69e910   Jan Engelhardt   netfilter: implem...
80
81
  	.matchsize  = sizeof(struct xt_statistic_info),
  	.me         = THIS_MODULE,
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
82
  };
d3c5ee6d5   Jan Engelhardt   [NETFILTER]: x_ta...
83
  static int __init statistic_mt_init(void)
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
84
  {
55b69e910   Jan Engelhardt   netfilter: implem...
85
  	return xt_register_match(&xt_statistic_mt_reg);
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
86
  }
d3c5ee6d5   Jan Engelhardt   [NETFILTER]: x_ta...
87
  static void __exit statistic_mt_exit(void)
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
88
  {
55b69e910   Jan Engelhardt   netfilter: implem...
89
  	xt_unregister_match(&xt_statistic_mt_reg);
f3389805e   Patrick McHardy   [NETFILTER]: x_ta...
90
  }
d3c5ee6d5   Jan Engelhardt   [NETFILTER]: x_ta...
91
92
  module_init(statistic_mt_init);
  module_exit(statistic_mt_exit);