--- iptables-1.2.11/extensions/libipt_owner.c 2004-06-14 23:02:17.000000000 +0100 +++ /home/lkcl/src/iptables-1.2.11/debian/build/iptables-1.2.11/extensions/libipt_owner.c 2004-09-09 17:12:28.000000000 +0100 @@ -1,4 +1,8 @@ /* Shared library add-on to iptables to add OWNER matching support. */ + +/* lkcl2004sep09: code to do per-program packet filtering (by device name and inode number) + * Copyright (C) Luke Kenneth Casson Leighton + */ #include #include #include @@ -34,6 +38,14 @@ "\n", IPTABLES_VERSION); #endif /* IPT_OWNER_COMM */ +#ifdef IPT_OWNER_INO + printf( +"OWNER match v%s options:\n" +"[!] --dev-owner name Match local device\n" +"[!] --ino-owner inode Match local inode (always use with --dev-owner)\n" +"\n", +IPTABLES_VERSION); +#endif /* IPT_OWNER_INO */ } static struct option opts[] = { @@ -44,6 +56,12 @@ #ifdef IPT_OWNER_COMM { "cmd-owner", 1, 0, '5' }, #endif +#ifdef IPT_OWNER_INO + { "ino-owner", 1, 0, '6' }, +#endif +#ifdef IPT_OWNER_DEV + { "dev-owner", 1, 0, '7' }, +#endif {0} }; @@ -136,6 +154,33 @@ *flags = 1; break; #endif +#ifdef IPT_OWNER_INO + case '6': + check_inverse(optarg, &invert, &optind, 0); + ownerinfo->ino = strtoul(optarg, &end, 0); + if (*end != '\0' || end == optarg) + exit_error(PARAMETER_PROBLEM, "Bad OWNER INODE value `%s'", optarg); + if (invert) + ownerinfo->invert |= IPT_OWNER_INO; + ownerinfo->match |= IPT_OWNER_INO; + *flags = 1; + break; +#endif +#ifdef IPT_OWNER_DEV + case '7': + check_inverse(optarg, &invert, &optind, 0); + if(strlen(optarg) > sizeof(ownerinfo->device)) + exit_error(PARAMETER_PROBLEM, "OWNER DEV `%s' too long, max %u characters", optarg, (unsigned int)sizeof(ownerinfo->device)); + + strncpy(ownerinfo->device, optarg, sizeof(ownerinfo->device)); + ownerinfo->device[sizeof(ownerinfo->device)-1] = '\0'; + + if (invert) + ownerinfo->invert |= IPT_OWNER_DEV; + ownerinfo->match |= IPT_OWNER_DEV; + *flags = 1; + break; +#endif default: return 0; @@ -189,6 +234,16 @@ printf("%.*s ", (int)sizeof(info->comm), info->comm); break; #endif +#ifdef IPT_OWNER_DEV + case IPT_OWNER_DEV: + printf("%.*s ", (int)sizeof(info->device), info->device); + break; +#endif +#ifdef IPT_OWNER_INO + case IPT_OWNER_INO: + printf("%lu ", info->ino); + break; +#endif default: break; } @@ -219,6 +274,12 @@ #ifdef IPT_OWNER_COMM print_item(info, IPT_OWNER_COMM, numeric, "OWNER CMD match "); #endif +#ifdef IPT_OWNER_INO + print_item(info, IPT_OWNER_INO, numeric, "OWNER INO match "); +#endif +#ifdef IPT_OWNER_DEV + print_item(info, IPT_OWNER_DEV, numeric, "OWNER DEV match "); +#endif } /* Saves the union ipt_matchinfo in parsable form to stdout. */ @@ -234,6 +295,12 @@ #ifdef IPT_OWNER_COMM print_item(info, IPT_OWNER_COMM, 0, "--cmd-owner "); #endif +#ifdef IPT_OWNER_DEV + print_item(info, IPT_OWNER_DEV, 0, "--dev-owner "); +#endif +#ifdef IPT_OWNER_INO + print_item(info, IPT_OWNER_INO, 0, "--ino-owner "); +#endif } static