Blame SOURCES/0053-nft-arp-Make-use-of-ipv4_addr_to_string.patch

ea9c6b
From 201fd565a1ce44b4af11ce9f245b2fa77c026fed Mon Sep 17 00:00:00 2001
ea9c6b
From: Phil Sutter <phil@nwl.cc>
ea9c6b
Date: Tue, 27 Apr 2021 10:02:34 +0200
ea9c6b
Subject: [PATCH] nft-arp: Make use of ipv4_addr_to_string()
ea9c6b
ea9c6b
This eliminates quite a bit of redundant code apart from also dropping
ea9c6b
use of obsolete function gethostbyaddr().
ea9c6b
ea9c6b
Signed-off-by: Phil Sutter <phil@nwl.cc>
ea9c6b
(cherry picked from commit 1e984079817a3c804eae25dea937d63d18c57a6c)
ea9c6b
---
ea9c6b
 iptables/nft-arp.c | 99 ++++------------------------------------------
ea9c6b
 iptables/xshared.c |  6 +--
ea9c6b
 iptables/xshared.h |  3 ++
ea9c6b
 3 files changed, 14 insertions(+), 94 deletions(-)
ea9c6b
ea9c6b
diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c
ea9c6b
index ec8147dd58c0d..7c61c31a13c40 100644
ea9c6b
--- a/iptables/nft-arp.c
ea9c6b
+++ b/iptables/nft-arp.c
ea9c6b
@@ -42,78 +42,6 @@ char *arp_opcodes[] =
ea9c6b
 	"ARP_NAK",
ea9c6b
 };
ea9c6b
 
ea9c6b
-static char *
ea9c6b
-addr_to_dotted(const struct in_addr *addrp)
ea9c6b
-{
ea9c6b
-	static char buf[20];
ea9c6b
-	const unsigned char *bytep;
ea9c6b
-
ea9c6b
-	bytep = (const unsigned char *) &(addrp->s_addr);
ea9c6b
-	sprintf(buf, "%d.%d.%d.%d", bytep[0], bytep[1], bytep[2], bytep[3]);
ea9c6b
-	return buf;
ea9c6b
-}
ea9c6b
-
ea9c6b
-static char *
ea9c6b
-addr_to_host(const struct in_addr *addr)
ea9c6b
-{
ea9c6b
-	struct hostent *host;
ea9c6b
-
ea9c6b
-	if ((host = gethostbyaddr((char *) addr,
ea9c6b
-					sizeof(struct in_addr), AF_INET)) != NULL)
ea9c6b
-		return (char *) host->h_name;
ea9c6b
-
ea9c6b
-	return (char *) NULL;
ea9c6b
-}
ea9c6b
-
ea9c6b
-static char *
ea9c6b
-addr_to_network(const struct in_addr *addr)
ea9c6b
-{
ea9c6b
-	struct netent *net;
ea9c6b
-
ea9c6b
-	if ((net = getnetbyaddr((long) ntohl(addr->s_addr), AF_INET)) != NULL)
ea9c6b
-		return (char *) net->n_name;
ea9c6b
-
ea9c6b
-	return (char *) NULL;
ea9c6b
-}
ea9c6b
-
ea9c6b
-static char *
ea9c6b
-addr_to_anyname(const struct in_addr *addr)
ea9c6b
-{
ea9c6b
-	char *name;
ea9c6b
-
ea9c6b
-	if ((name = addr_to_host(addr)) != NULL ||
ea9c6b
-		(name = addr_to_network(addr)) != NULL)
ea9c6b
-		return name;
ea9c6b
-
ea9c6b
-	return addr_to_dotted(addr);
ea9c6b
-}
ea9c6b
-
ea9c6b
-static char *
ea9c6b
-mask_to_dotted(const struct in_addr *mask)
ea9c6b
-{
ea9c6b
-	int i;
ea9c6b
-	static char buf[22];
ea9c6b
-	u_int32_t maskaddr, bits;
ea9c6b
-
ea9c6b
-	maskaddr = ntohl(mask->s_addr);
ea9c6b
-
ea9c6b
-	if (maskaddr == 0xFFFFFFFFL)
ea9c6b
-		/* we don't want to see "/32" */
ea9c6b
-		return "";
ea9c6b
-
ea9c6b
-	i = 32;
ea9c6b
-	bits = 0xFFFFFFFEL;
ea9c6b
-	while (--i >= 0 && maskaddr != bits)
ea9c6b
-		bits <<= 1;
ea9c6b
-	if (i >= 0)
ea9c6b
-		sprintf(buf, "/%d", i);
ea9c6b
-	else
ea9c6b
-		/* mask was not a decent combination of 1's and 0's */
ea9c6b
-		snprintf(buf, sizeof(buf), "/%s", addr_to_dotted(mask));
ea9c6b
-
ea9c6b
-	return buf;
ea9c6b
-}
ea9c6b
-
ea9c6b
 static bool need_devaddr(struct arpt_devaddr_info *info)
ea9c6b
 {
ea9c6b
 	int i;
ea9c6b
@@ -403,7 +331,6 @@ static void nft_arp_print_rule_details(const struct iptables_command_state *cs,
ea9c6b
 				       unsigned int format)
ea9c6b
 {
ea9c6b
 	const struct arpt_entry *fw = &cs->arp;
ea9c6b
-	char buf[BUFSIZ];
ea9c6b
 	char iface[IFNAMSIZ+2];
ea9c6b
 	const char *sep = "";
ea9c6b
 	int print_iface = 0;
ea9c6b
@@ -450,15 +377,10 @@ static void nft_arp_print_rule_details(const struct iptables_command_state *cs,
ea9c6b
 	}
ea9c6b
 
ea9c6b
 	if (fw->arp.smsk.s_addr != 0L) {
ea9c6b
-		printf("%s%s", sep, fw->arp.invflags & IPT_INV_SRCIP
ea9c6b
-			? "! " : "");
ea9c6b
-		if (format & FMT_NUMERIC)
ea9c6b
-			sprintf(buf, "%s", addr_to_dotted(&(fw->arp.src)));
ea9c6b
-		else
ea9c6b
-			sprintf(buf, "%s", addr_to_anyname(&(fw->arp.src)));
ea9c6b
-		strncat(buf, mask_to_dotted(&(fw->arp.smsk)),
ea9c6b
-			sizeof(buf) - strlen(buf) - 1);
ea9c6b
-		printf("-s %s", buf);
ea9c6b
+		printf("%s%s-s %s", sep,
ea9c6b
+		       fw->arp.invflags & IPT_INV_SRCIP ? "! " : "",
ea9c6b
+		       ipv4_addr_to_string(&fw->arp.src,
ea9c6b
+					   &fw->arp.smsk, format));
ea9c6b
 		sep = " ";
ea9c6b
 	}
ea9c6b
 
ea9c6b
@@ -476,15 +398,10 @@ static void nft_arp_print_rule_details(const struct iptables_command_state *cs,
ea9c6b
 after_devsrc:
ea9c6b
 
ea9c6b
 	if (fw->arp.tmsk.s_addr != 0L) {
ea9c6b
-		printf("%s%s", sep, fw->arp.invflags & IPT_INV_DSTIP
ea9c6b
-			? "! " : "");
ea9c6b
-		if (format & FMT_NUMERIC)
ea9c6b
-			sprintf(buf, "%s", addr_to_dotted(&(fw->arp.tgt)));
ea9c6b
-		else
ea9c6b
-			sprintf(buf, "%s", addr_to_anyname(&(fw->arp.tgt)));
ea9c6b
-		strncat(buf, mask_to_dotted(&(fw->arp.tmsk)),
ea9c6b
-			sizeof(buf) - strlen(buf) - 1);
ea9c6b
-		printf("-d %s", buf);
ea9c6b
+		printf("%s%s-d %s", sep,
ea9c6b
+		       fw->arp.invflags & IPT_INV_DSTIP ? "! " : "",
ea9c6b
+		       ipv4_addr_to_string(&fw->arp.tgt,
ea9c6b
+					   &fw->arp.tmsk, format));
ea9c6b
 		sep = " ";
ea9c6b
 	}
ea9c6b
 
ea9c6b
diff --git a/iptables/xshared.c b/iptables/xshared.c
ea9c6b
index 16c58914e59a5..e3c8072b5ca96 100644
ea9c6b
--- a/iptables/xshared.c
ea9c6b
+++ b/iptables/xshared.c
ea9c6b
@@ -546,9 +546,9 @@ void debug_print_argv(struct argv_store *store)
ea9c6b
 }
ea9c6b
 #endif
ea9c6b
 
ea9c6b
-static const char *ipv4_addr_to_string(const struct in_addr *addr,
ea9c6b
-				       const struct in_addr *mask,
ea9c6b
-				       unsigned int format)
ea9c6b
+const char *ipv4_addr_to_string(const struct in_addr *addr,
ea9c6b
+				const struct in_addr *mask,
ea9c6b
+				unsigned int format)
ea9c6b
 {
ea9c6b
 	static char buf[BUFSIZ];
ea9c6b
 
ea9c6b
diff --git a/iptables/xshared.h b/iptables/xshared.h
ea9c6b
index 490b19ade5106..e4015c00e2a35 100644
ea9c6b
--- a/iptables/xshared.h
ea9c6b
+++ b/iptables/xshared.h
ea9c6b
@@ -200,6 +200,9 @@ void debug_print_argv(struct argv_store *store);
ea9c6b
 #  define debug_print_argv(...) /* nothing */
ea9c6b
 #endif
ea9c6b
 
ea9c6b
+const char *ipv4_addr_to_string(const struct in_addr *addr,
ea9c6b
+				const struct in_addr *mask,
ea9c6b
+				unsigned int format);
ea9c6b
 void print_ipv4_addresses(const struct ipt_entry *fw, unsigned int format);
ea9c6b
 void print_ipv6_addresses(const struct ip6t_entry *fw6, unsigned int format);
ea9c6b
 
ea9c6b
-- 
ea9c6b
2.31.1
ea9c6b