1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
|
# By Peter V. Saveliev https://pypi.python.org/pypi/pyroute2. Dual licensed under the Apache 2 and GPLv2+ see https://github.com/svinota/pyroute2 for License details.
'''
Netlink proxy engine
'''
import errno
import struct
import logging
import traceback
import threading
class NetlinkProxy(object):
'''
Proxy schemes::
User -> NetlinkProxy -> Kernel
|
<---------+
User <- NetlinkProxy <- Kernel
'''
def __init__(self, policy='forward', nl=None, lock=None):
self.nl = nl
self.lock = lock or threading.Lock()
self.pmap = {}
self.policy = policy
def handle(self, data):
#
# match the packet
#
ptype = struct.unpack('H', data[4:6])[0]
plugin = self.pmap.get(ptype, None)
if plugin is not None:
with self.lock:
try:
ret = plugin(data, self.nl)
if ret is None:
msg = struct.pack('IHH', 40, 2, 0)
msg += data[8:16]
msg += struct.pack('I', 0)
# nlmsgerr struct alignment
msg += b'\0' * 20
return {'verdict': self.policy,
'data': msg}
else:
return ret
except Exception as e:
logging.error(traceback.format_exc())
# errmsg
if isinstance(e, (OSError, IOError)):
code = e.errno
else:
code = errno.ECOMM
msg = struct.pack('HH', 2, 0)
msg += data[8:16]
msg += struct.pack('I', code)
msg += data
msg = struct.pack('I', len(msg) + 4) + msg
return {'verdict': 'error',
'data': msg}
return None
|