Store location object in handle to improve error reporting.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
const char *name;
};
+struct chain_spec {
+ struct location location;
+ const char *name;
+};
+
/**
* struct handle - handle for tables, chains, rules and sets
*
struct handle {
uint32_t family;
struct table_spec table;
- const char *chain;
+ struct chain_spec chain;
const char *set;
const char *obj;
const char *flowtable;
cmd->handle.table.name);
if (chain_lookup(table, &cmd->handle) == NULL)
return cmd_error(ctx, "Could not process rule: Chain '%s' does not exist",
- cmd->handle.chain);
+ cmd->handle.chain.name);
return 0;
case CMD_OBJ_QUOTA:
return cmd_evaluate_list_obj(ctx, cmd, NFT_OBJECT_QUOTA);
ctx->cmd->handle.table.name);
if (chain_lookup(table, &ctx->cmd->handle) == NULL)
return cmd_error(ctx, "Could not process rule: Chain '%s' does not exist",
- ctx->cmd->handle.chain);
+ ctx->cmd->handle.chain.name);
break;
default:
BUG("invalid command object type %u\n", cmd->obj);
nftnl_chain_set_str(nlc, NFTNL_CHAIN_TABLE, h->table.name);
if (h->handle.id)
nftnl_chain_set_u64(nlc, NFTNL_CHAIN_HANDLE, h->handle.id);
- if (h->chain != NULL)
- nftnl_chain_set_str(nlc, NFTNL_CHAIN_NAME, h->chain);
+ if (h->chain.name != NULL)
+ nftnl_chain_set_str(nlc, NFTNL_CHAIN_NAME, h->chain.name);
return nlc;
}
nftnl_rule_set_u32(nlr, NFTNL_RULE_FAMILY, h->family);
nftnl_rule_set_str(nlr, NFTNL_RULE_TABLE, h->table.name);
- if (h->chain != NULL)
- nftnl_rule_set_str(nlr, NFTNL_RULE_CHAIN, h->chain);
+ if (h->chain.name != NULL)
+ nftnl_rule_set_str(nlr, NFTNL_RULE_CHAIN, h->chain.name);
if (h->handle.id)
nftnl_rule_set_u64(nlr, NFTNL_RULE_HANDLE, h->handle.id);
if (h->position.id)
if (h->family != family ||
strcmp(table, h->table.name) != 0 ||
- (h->chain && strcmp(chain, h->chain) != 0))
+ (h->chain.name && strcmp(chain, h->chain.name) != 0))
return 0;
netlink_dump_rule(nlr, ctx);
if (h->family != family || strcmp(table, h->table.name) != 0)
return 0;
- if (h->chain && strcmp(name, h->chain) != 0)
+ if (h->chain.name && strcmp(name, h->chain.name) != 0)
return 0;
chain = netlink_delinearize_chain(ctx, nlc);
h.family = nftnl_trace_get_u32(nlt, NFTNL_TRACE_FAMILY);
h.table.name = nftnl_trace_get_str(nlt, NFTNL_TRACE_TABLE);
- h.chain = nftnl_trace_get_str(nlt, NFTNL_TRACE_CHAIN);
+ h.chain.name = nftnl_trace_get_str(nlt, NFTNL_TRACE_CHAIN);
if (!h.table.name)
return;
memset(&h, 0, sizeof(h));
h.family = nftnl_rule_get_u32(nlr, NFTNL_RULE_FAMILY);
- h.table.name = xstrdup(nftnl_rule_get_str(nlr, NFTNL_RULE_TABLE));
- h.chain = xstrdup(nftnl_rule_get_str(nlr, NFTNL_RULE_CHAIN));
+ h.table.name = xstrdup(nftnl_rule_get_str(nlr, NFTNL_RULE_TABLE));
+ h.chain.name = xstrdup(nftnl_rule_get_str(nlr, NFTNL_RULE_CHAIN));
h.handle.id = nftnl_rule_get_u64(nlr, NFTNL_RULE_HANDLE);
if (nftnl_rule_is_set(nlr, NFTNL_RULE_POSITION))
chain_spec : table_spec identifier
{
$$ = $1;
- $$.chain = $2;
+ $$.chain.name = $2;
+ $$.chain.location = @2;
}
;
chain_identifier : identifier
{
memset(&$$, 0, sizeof($$));
- $$.chain = $1;
+ $$.chain.name = $1;
+ $$.chain.location = @1;
}
;
void handle_free(struct handle *h)
{
xfree(h->table.name);
- xfree(h->chain);
+ xfree(h->chain.name);
xfree(h->set);
xfree(h->flowtable);
}
dst->family = src->family;
if (dst->table.name == NULL && src->table.name != NULL)
dst->table.name = xstrdup(src->table.name);
- if (dst->chain == NULL && src->chain != NULL)
- dst->chain = xstrdup(src->chain);
+ if (dst->chain.name == NULL && src->chain.name != NULL)
+ dst->chain.name = xstrdup(src->chain.name);
if (dst->set == NULL && src->set != NULL)
dst->set = xstrdup(src->set);
if (dst->flowtable == NULL && src->flowtable != NULL)
init_list_head(&chain->rules);
init_list_head(&chain->scope.symbols);
if (name != NULL)
- chain->handle.chain = xstrdup(name);
+ chain->handle.chain.name = xstrdup(name);
chain->policy = -1;
return chain;
struct chain *chain;
list_for_each_entry(chain, &table->chains, list) {
- if (!strcmp(chain->handle.chain, h->chain))
+ if (!strcmp(chain->handle.chain.name, h->chain.name))
return chain;
}
return NULL;
static void chain_print_declaration(const struct chain *chain,
struct output_ctx *octx)
{
- nft_print(octx, "\tchain %s {", chain->handle.chain);
+ nft_print(octx, "\tchain %s {", chain->handle.chain.name);
if (octx->handle > 0)
nft_print(octx, " # handle %" PRIu64, chain->handle.handle.id);
nft_print(octx, "\n");
void chain_print_plain(const struct chain *chain, struct output_ctx *octx)
{
nft_print(octx, "chain %s %s %s", family2str(chain->handle.family),
- chain->handle.table.name, chain->handle.chain);
+ chain->handle.table.name, chain->handle.chain.name);
if (chain->flags & CHAIN_F_BASECHAIN) {
nft_print(octx, " { type %s hook %s priority %d; policy %s; }",
list_for_each_entry(chain, &table->chains, list) {
if (chain->handle.family != cmd->handle.family ||
- strcmp(cmd->handle.chain, chain->handle.chain) != 0)
+ strcmp(cmd->handle.chain.name, chain->handle.chain.name) != 0)
continue;
chain_print(chain, ctx->octx);