From 1acd024a6ba46ab0d9f9c25c089f79a4cba93f25 Mon Sep 17 00:00:00 2001 From: Maxim Mamontov Date: Sun, 8 Jun 2014 12:46:20 +0300 Subject: [PATCH 1/1] Initial adding of netfilter_queue capturer. --- .../plugins/capture/nfqueue/Makefile | 13 ++ .../plugins/capture/nfqueue/nfqueue.cpp | 143 ++++++++++++++++++ .../plugins/capture/nfqueue/nfqueue.h | 80 ++++++++++ 3 files changed, 236 insertions(+) create mode 100644 projects/stargazer/plugins/capture/nfqueue/Makefile create mode 100644 projects/stargazer/plugins/capture/nfqueue/nfqueue.cpp create mode 100644 projects/stargazer/plugins/capture/nfqueue/nfqueue.h diff --git a/projects/stargazer/plugins/capture/nfqueue/Makefile b/projects/stargazer/plugins/capture/nfqueue/Makefile new file mode 100644 index 00000000..a9f4a803 --- /dev/null +++ b/projects/stargazer/plugins/capture/nfqueue/Makefile @@ -0,0 +1,13 @@ +include ../../../../../Makefile.conf + +PROG = mod_cap_nfqueue.so + +SRCS = ./nfqueue.cpp + +LIBS += $(NFQ_LIBS) $(LIB_THREAD) + +STGLIBS = common \ + logger + +include ../../Makefile.in + diff --git a/projects/stargazer/plugins/capture/nfqueue/nfqueue.cpp b/projects/stargazer/plugins/capture/nfqueue/nfqueue.cpp new file mode 100644 index 00000000..a007c890 --- /dev/null +++ b/projects/stargazer/plugins/capture/nfqueue/nfqueue.cpp @@ -0,0 +1,143 @@ +/* + * This program is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation; either version 2 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA + */ + +/* +* Author : Maxim Mamontov +*/ + +#include "nfqueue.h" + +#include "stg/traffcounter.h" +#include "stg/plugin_creator.h" +#include "stg/common.h" +#include "stg/raw_ip_packet.h" + +#include + +//----------------------------------------------------------------------------- +//----------------------------------------------------------------------------- +//----------------------------------------------------------------------------- +namespace +{ +PLUGIN_CREATOR ncc; +} + +extern "C" PLUGIN * GetPlugin(); +//----------------------------------------------------------------------------- +//----------------------------------------------------------------------------- +//----------------------------------------------------------------------------- +PLUGIN * GetPlugin() +{ +return ncc.GetPlugin(); +} +//----------------------------------------------------------------------------- +//----------------------------------------------------------------------------- +//----------------------------------------------------------------------------- +std::string NFQ_CAP::GetVersion() const +{ +return "cap_nfqueue v.1.0"; +} +//----------------------------------------------------------------------------- +NFQ_CAP::NFQ_CAP() + : errorStr(), + thread(), + nonstop(false), + isRunning(false), + traffCnt(NULL), + logger(GetPluginLogger(GetStgLogger(), "cap_nfqueue")) +{ +} +//----------------------------------------------------------------------------- +int NFQ_CAP::ParseSettings() +{ +return 0; +} +//----------------------------------------------------------------------------- +int NFQ_CAP::Start() +{ +if (isRunning) + return 0; + +nonstop = true; + +if (pthread_create(&thread, NULL, Run, this)) + { + errorStr = "Cannot create thread."; + logger("Cannot create thread."); + printfd(__FILE__, "Cannot create thread\n"); + return -1; + } + +return 0; +} +//----------------------------------------------------------------------------- +int NFQ_CAP::Stop() +{ +if (!isRunning) + return 0; + +nonstop = false; + +//5 seconds to thread stops itself +for (int i = 0; i < 25 && isRunning; i++) + { + struct timespec ts = {0, 200000000}; + nanosleep(&ts, NULL); + } +//after 5 seconds waiting thread still running. now killing it +if (isRunning) + { + if (pthread_kill(thread, SIGUSR1)) + { + errorStr = "Cannot kill thread."; + logger("Cannot send signal to thread."); + return -1; + } + for (int i = 0; i < 25 && isRunning; ++i) + { + struct timespec ts = {0, 200000000}; + nanosleep(&ts, NULL); + } + if (isRunning) + { + errorStr = "NFQ_CAP not stopped."; + logger("Cannot stop thread."); + printfd(__FILE__, "Cannot stop thread\n"); + return -1; + } + } + +pthread_join(thread, NULL); + +return 0; +} +//----------------------------------------------------------------------------- +void * NFQ_CAP::Run(void * d) +{ +sigset_t signalSet; +sigfillset(&signalSet); +pthread_sigmask(SIG_BLOCK, &signalSet, NULL); + +NFQ_CAP * dc = static_cast(d); +dc->isRunning = true; + +while (dc->nonstop) + { + } + +dc->isRunning = false; +return NULL; +} diff --git a/projects/stargazer/plugins/capture/nfqueue/nfqueue.h b/projects/stargazer/plugins/capture/nfqueue/nfqueue.h new file mode 100644 index 00000000..02452bb8 --- /dev/null +++ b/projects/stargazer/plugins/capture/nfqueue/nfqueue.h @@ -0,0 +1,80 @@ +/* + * This program is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation; either version 2 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA + */ + +/* +* Author : Maxim Mamontov +*/ + +#ifndef NFQ_CAP_H +#define NFQ_CAP_H + +#include "stg/plugin.h" +#include "stg/module_settings.h" +#include "stg/logger.h" + +#include +#include + +#include + +class USERS; +class TARIFFS; +class ADMINS; +class TRAFFCOUNTER; +class SETTINGS; + +class TRAFFCOUNTER; + +class NFQ_CAP : public PLUGIN { +public: + NFQ_CAP(); + virtual ~NFQ_CAP() {} + + void SetTraffcounter(TRAFFCOUNTER * tc) { traffCnt = tc; } + + int Start(); + int Stop(); + int Reload() { return 0; } + bool IsRunning() { return isRunning; } + + void SetSettings(const MODULE_SETTINGS & s) { settings = s; } + int ParseSettings(); + + const std::string & GetStrError() const { return errorStr; } + std::string GetVersion() const; + uint16_t GetStartPosition() const { return 40; } + uint16_t GetStopPosition() const { return 40; } + +private: + NFQ_CAP(const NFQ_CAP & rvalue); + NFQ_CAP & operator=(const NFQ_CAP & rvalue); + + static void * Run(void *); + + mutable std::string errorStr; + + pthread_t thread; + bool nonstop; + bool isRunning; + MODULE_SETTINGS settings; + + TRAFFCOUNTER * traffCnt; + + PLUGIN_LOGGER logger; +}; +//----------------------------------------------------------------------------- + +#endif -- 2.44.2