From nobody Fri Dec 12 15:15:59 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) client-ip=8.43.85.245; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1761912777; cv=none; d=zohomail.com; s=zohoarc; b=TFr/Za8GSU6/GKbadUaPnVRjHHwbn1K+G0wawkb/rmN23j6BFRol3iAuD2FClUtB6fiuiWrZ7dUfQVXeL860UdOIBJUlILh+3f49CsLbGbeqTia/JXBJZvKF4EE0WkV0bwL/+G7pqly7QR33WYagTdNbXo8FaIRvVHh1AgDex3Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1761912777; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Subject:Subject:To:To:Message-Id:Reply-To; bh=w7sWf8+DjIEnCDKqkkcTdRfr1ThUCoZJPXwYvWMu8Mw=; b=NRaBkcNUH0DTYSZhWXniQ1mmVbiaW2SI9VOusPa65ycX9iAcn6n/tPHhTz4VD8DeAn3fygVw2Q8bjB8sKtwLPZAVHwfcADePiv/89e/HwI0RKYlMb3Qt9oSPI1CuUs/LugI5K2XLE1U2Gm6jN5n4HkfNQoOtOs/Jw4FCVqY20gU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [8.43.85.245]) by mx.zohomail.com with SMTPS id 1761912777910678.8186151994457; Fri, 31 Oct 2025 05:12:57 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 0278643F44; Fri, 31 Oct 2025 08:12:56 -0400 (EDT) Received: from [172.19.199.29] (lists.libvirt.org [8.43.85.245]) by lists.libvirt.org (Postfix) with ESMTP id E198C44070; Fri, 31 Oct 2025 08:08:15 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id EACCE41BAE; Fri, 31 Oct 2025 08:07:52 -0400 (EDT) Received: from mail-ej1-f44.google.com (mail-ej1-f44.google.com [209.85.218.44]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id F315843E57 for ; Fri, 31 Oct 2025 08:07:50 -0400 (EDT) Received: by mail-ej1-f44.google.com with SMTP id a640c23a62f3a-b6d6984a5baso415446566b.3 for ; Fri, 31 Oct 2025 05:07:50 -0700 (PDT) Received: from thinkiepadje.home (2a02-a470-a384-0-62ef-bf5-dc71-bd78.fixed6.kpn.net. [2a02:a470:a384:0:62ef:bf5:dc71:bd78]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-b70779ddf48sm158255866b.32.2025.10.31.05.07.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Oct 2025 05:07:49 -0700 (PDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=-5.3 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED,SPF_PASS autolearn=unavailable autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1761912470; x=1762517270; darn=lists.libvirt.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=w7sWf8+DjIEnCDKqkkcTdRfr1ThUCoZJPXwYvWMu8Mw=; b=mm/byGiGi8XzmgearBvVdeZOy5JAOwNMW06cI49MXEsX7ioS8CZ/FYA7lQ5TL31aP0 5LmlRwh4COypoziUbGsXJkKyKdicPNxabGb1pw1YqPuPJ8czIfOr1rA9s2CFPzvSVVOI r1s1oHkWYfOWBn+HuT4VfnP297tyC2AjNppXKgwTQxEdxpo7JHuX58obkfMxb5oPb0c4 UJwN0pLgA/TcygOYZxVuC+1CQfFmGA023sX5U7tl/KtiTI86050SIo4XWt6OhRKfkLkQ qmhlQ/qOzCRuCJC1GEYjryagfYD4ArAuKI+8DscXvSvmhYf7MHEkepBwP3Ca4F+Wj6B+ xOdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1761912470; x=1762517270; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=w7sWf8+DjIEnCDKqkkcTdRfr1ThUCoZJPXwYvWMu8Mw=; b=fKlP7aNUF1RUofu4bfVm8/5lJ2KHFspnsfIVHbNpQWv7uLDNiaq6BZxt1Ppo61ZFUI RaT0PbpvoqGGIoS1bBwxgy5nGJOUMdG86u/n6SOKdkimiFmeZwnE85sPpL1tccxSTL+1 OeVzMBiG0u94OCXgr45xcsM79dChxbCFhSd1QAiD8GsWC7YYzA2TKuaezmFAk68Rx44l 7a3i3EIIMSVcbXCMt6+FEH7Y22rO2D1v9ZW1/7JwlGtvvhpc72yh7DrSY0/X5DpCS+LZ M2jTENH9ebDDVwcb+kVFSZmIgbvGll2NNItxlpW9BsOZWdm0+QC/GbmF7JhD4qNR7WG3 zH1Q== X-Gm-Message-State: AOJu0Ywvx4j4WNIsv/FO3400+u4+qKmwjl8yfWX5OJL16E9JSv1uMqMc 9nklHCKilrLnVdNBuvMyiin5xBCg8MZh/1XvIkw/Y0i7e5Zo+PJbtip3xHA86+RJPw== X-Gm-Gg: ASbGncssyV0HdeK0k4pSAAxfrvWK53M5b2ZQS2y/OcYZsib0QeBrvNGYxFqVjNhaY28 3ncZ1yxtHGJFtVnMPRn+K0yvQ4qEVjl8SokBEglfWR9v2Gm2gBHA2aG9mkpEXqxNQvonfJg1Hjm 6r/D96mkoKjbJjsQjV7VAJBhFkrfsfPYnfkPiprB0FongVLT4XfbLqauIWHR9PYdoO+9Mws9QIJ DNwJU78suTxnMmO05BG+w8eRd7awcYD06JFrdz1TZQ+8936ywn2kkMZJo6g/lramTF8HxhL88Vm BCyPR9N+D+cZW9tVE3LLMn+73Z33q6TCFMXNfqUnL2XW3ODTFy8+qCPEVhaGQngirdSG2vfC+yU a3r79sd64eZmhuXB7OTn8YFyYoD3scag8rSJ2XXy3qjakAyq+hiu84bsAj48MQ79Vlngf1Cxgqz dDU1KsQPO5PsIDshWiJSXm6AaADN/JYnfa8XkbNnUE1yFHNymv7Zg5Oa8YqA6YNiF7kOb52sUtE h8IUGuMJQ== X-Google-Smtp-Source: AGHT+IHEpsYvmiA86gR0u6cCbK/KNLj44C589Xz9SwDcHjjfce9i74qToY/dmgc+dwnFeo1vV8G5/Q== X-Received: by 2002:a17:906:6a14:b0:b3c:f0f2:842f with SMTP id a640c23a62f3a-b7070628352mr297852066b.49.1761912469544; Fri, 31 Oct 2025 05:07:49 -0700 (PDT) From: Dion Bosschieter To: devel@lists.libvirt.org Subject: [PATCH 4/5] nwfilter: allow use of nftables nwfilter driver via nwfilter.conf Date: Fri, 31 Oct 2025 13:05:44 +0100 Message-ID: <20251031120546.942126-5-dionbosschieter@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20251031120546.942126-1-dionbosschieter@gmail.com> References: <20251031120546.942126-1-dionbosschieter@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Message-ID-Hash: 6L5OOI6WRU2HXHWOQOD7A6Z3SXRTLVPY X-Message-ID-Hash: 6L5OOI6WRU2HXHWOQOD7A6Z3SXRTLVPY X-MailFrom: dionbosschieter@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: jean-louis@dupond.be, Dion Bosschieter X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1761912779479158500 Content-Type: text/plain; charset="utf-8" Change the nwfilter driver loading mechanism to read from nwfilter.conf. By default, it will use the existing ebiptables driver, which can be replaced in the future to remove the {eb,ip}tables dependency. Added nftables to *filter_tech_drivers as an available driver option for users to choose from. Signed-off-by: Dion Bosschieter --- src/nwfilter/nwfilter_driver.c | 49 +++++++++++++++++++-- src/nwfilter/nwfilter_gentech_driver.c | 60 +++++++++++--------------- src/nwfilter/nwfilter_gentech_driver.h | 4 +- 3 files changed, 73 insertions(+), 40 deletions(-) diff --git a/src/nwfilter/nwfilter_driver.c b/src/nwfilter/nwfilter_driver.c index 522cfda022..18d322574d 100644 --- a/src/nwfilter/nwfilter_driver.c +++ b/src/nwfilter/nwfilter_driver.c @@ -26,9 +26,7 @@ =20 #include "virgdbus.h" #include "virlog.h" - #include "internal.h" - #include "virerror.h" #include "datatypes.h" #include "nwfilter_driver.h" @@ -36,7 +34,6 @@ #include "configmake.h" #include "virpidfile.h" #include "viraccessapicheck.h" - #include "nwfilter_ipaddrmap.h" #include "nwfilter_dhcpsnoop.h" #include "nwfilter_learnipaddr.h" @@ -203,6 +200,41 @@ nwfilterStateCleanup(void) } =20 =20 +/** + * virNWFilterLoadGentechDriverFromConfig: + * + * Loading driver name from nwfilter.conf config file + */ +static char * +virNWFilterLoadGentechDriverFromConfig(const char *configfile) +{ + g_autoptr(virConf) conf =3D NULL; + g_autofree char *drivername =3D NULL; + + if (access(configfile, R_OK) =3D=3D 0) { + + conf =3D virConfReadFile(configfile, 0); + if (!conf) + return NULL; + + if (virConfGetValueString(conf, "driver", &drivername) < 0) + return NULL; + + if (drivername) { + VIR_DEBUG("nwfilter driver setting requested from config file = %s: '%s'", + configfile, drivername); + } + } + + if (!drivername) { + drivername =3D g_strdup(NWFILTER_DEFAULT_DRIVER); + } + + + return g_steal_pointer(&drivername); +} + + /** * nwfilterStateInitialize: * @@ -217,6 +249,8 @@ nwfilterStateInitialize(bool privileged, { VIR_LOCK_GUARD lock =3D virLockGuardLock(&driverMutex); GDBusConnection *sysbus =3D NULL; + g_autofree char *configfile =3D NULL; + char *gentechdrivername =3D NULL; =20 if (root !=3D NULL) { virReportError(VIR_ERR_INVALID_ARG, "%s", @@ -266,7 +300,14 @@ nwfilterStateInitialize(bool privileged, if (virNWFilterDHCPSnoopInit() < 0) goto error; =20 - if (virNWFilterTechDriversInit(privileged) < 0) + configfile =3D g_strdup(SYSCONFDIR "/libvirt/nwfilter.conf"); + + /* get chosen driver from config file */ + gentechdrivername =3D virNWFilterLoadGentechDriverFromConfig(configfil= e); + if (gentechdrivername =3D=3D NULL) + goto error; + + if (virNWFilterTechDriversInit(privileged, gentechdrivername) < 0) goto error; =20 if (virNWFilterConfLayerInit(virNWFilterTriggerRebuildImpl, driver) < = 0) diff --git a/src/nwfilter/nwfilter_gentech_driver.c b/src/nwfilter/nwfilter= _gentech_driver.c index 1465734a54..adb96acca6 100644 --- a/src/nwfilter/nwfilter_gentech_driver.c +++ b/src/nwfilter/nwfilter_gentech_driver.c @@ -32,6 +32,7 @@ #include "nwfilter_dhcpsnoop.h" #include "nwfilter_ipaddrmap.h" #include "nwfilter_learnipaddr.h" +#include "nwfilter_nftables_driver.h" #include "virnetdev.h" =20 #define VIR_FROM_THIS VIR_FROM_NWFILTER @@ -48,18 +49,20 @@ static int _virNWFilterTeardownFilter(const char *ifnam= e); =20 static virNWFilterTechDriver *filter_tech_drivers[] =3D { &ebiptables_driver, - NULL + &nftables_driver, }; =20 -int virNWFilterTechDriversInit(bool privileged) +int virNWFilterTechDriversInit(bool privileged, const char *drivername) { size_t i =3D 0; - VIR_DEBUG("Initializing NWFilter technology drivers"); - while (filter_tech_drivers[i]) { - if (!(filter_tech_drivers[i]->flags & TECHDRV_FLAG_INITIALIZED)) + VIR_DEBUG("Initializing NWFilter technology drivers, chosen %s", drive= rname); + + for (i =3D 0; i < G_N_ELEMENTS(filter_tech_drivers); i++) { + if (!(filter_tech_drivers[i]->flags & TECHDRV_FLAG_INITIALIZED) + && STREQ(filter_tech_drivers[i]->name, drivername)) filter_tech_drivers[i]->init(privileged); - i++; } + return 0; } =20 @@ -67,25 +70,20 @@ int virNWFilterTechDriversInit(bool privileged) void virNWFilterTechDriversShutdown(void) { size_t i =3D 0; - while (filter_tech_drivers[i]) { + for (i =3D 0; i < G_N_ELEMENTS(filter_tech_drivers); i++) { if ((filter_tech_drivers[i]->flags & TECHDRV_FLAG_INITIALIZED)) filter_tech_drivers[i]->shutdown(); - i++; } } =20 =20 static virNWFilterTechDriver * -virNWFilterTechDriverForName(const char *name) +virNWFilterInitializedTechDriver(void) { size_t i =3D 0; - while (filter_tech_drivers[i]) { - if (STREQ(filter_tech_drivers[i]->name, name)) { - if ((filter_tech_drivers[i]->flags & TECHDRV_FLAG_INITIALIZED)= =3D=3D 0) - break; + for (i =3D 0; i < G_N_ELEMENTS(filter_tech_drivers); i++) { + if ((filter_tech_drivers[i]->flags & TECHDRV_FLAG_INITIALIZED)) return filter_tech_drivers[i]; - } - i++; } return NULL; } @@ -617,7 +615,6 @@ virNWFilterInstantiateFilterUpdate(virNWFilterDriverSta= te *driver, bool *foundNewFilter) { int rc =3D -1; - const char *drvname =3D EBIPTABLES_DRIVER_ID; virNWFilterTechDriver *techdriver; virNWFilterObj *obj; virNWFilterDef *filter; @@ -625,12 +622,11 @@ virNWFilterInstantiateFilterUpdate(virNWFilterDriverS= tate *driver, char vmmacaddr[VIR_MAC_STRING_BUFLEN] =3D {0}; virNWFilterVarValue *ipaddr; =20 - techdriver =3D virNWFilterTechDriverForName(drvname); + techdriver =3D virNWFilterInitializedTechDriver(); =20 if (!techdriver) { - virReportError(VIR_ERR_INTERNAL_ERROR, - _("Could not get access to ACL tech driver '%1$s'"), - drvname); + virReportError(VIR_ERR_INTERNAL_ERROR, "%s", + _("Could not get access to ACL tech driver")); return -1; } =20 @@ -768,15 +764,13 @@ virNWFilterUpdateInstantiateFilter(virNWFilterDriverS= tate *driver, static int virNWFilterRollbackUpdateFilter(virNWFilterBindingDef *binding) { - const char *drvname =3D EBIPTABLES_DRIVER_ID; int ifindex; virNWFilterTechDriver *techdriver; =20 - techdriver =3D virNWFilterTechDriverForName(drvname); + techdriver =3D virNWFilterInitializedTechDriver(); if (!techdriver) { - virReportError(VIR_ERR_INTERNAL_ERROR, - _("Could not get access to ACL tech driver '%1$s'"), - drvname); + virReportError(VIR_ERR_INTERNAL_ERROR, "%s", + _("Could not get access to ACL tech driver")); return -1; } =20 @@ -793,15 +787,13 @@ virNWFilterRollbackUpdateFilter(virNWFilterBindingDef= *binding) static int virNWFilterTearOldFilter(virNWFilterBindingDef *binding) { - const char *drvname =3D EBIPTABLES_DRIVER_ID; int ifindex; virNWFilterTechDriver *techdriver; =20 - techdriver =3D virNWFilterTechDriverForName(drvname); + techdriver =3D virNWFilterInitializedTechDriver(); if (!techdriver) { - virReportError(VIR_ERR_INTERNAL_ERROR, - _("Could not get access to ACL tech driver '%1$s'"), - drvname); + virReportError(VIR_ERR_INTERNAL_ERROR, "%s", + _("Could not get access to ACL tech driver")); return -1; } =20 @@ -818,14 +810,12 @@ virNWFilterTearOldFilter(virNWFilterBindingDef *bindi= ng) static int _virNWFilterTeardownFilter(const char *ifname) { - const char *drvname =3D EBIPTABLES_DRIVER_ID; virNWFilterTechDriver *techdriver; - techdriver =3D virNWFilterTechDriverForName(drvname); + techdriver =3D virNWFilterInitializedTechDriver(); =20 if (!techdriver) { - virReportError(VIR_ERR_INTERNAL_ERROR, - _("Could not get access to ACL tech driver '%1$s'"), - drvname); + virReportError(VIR_ERR_INTERNAL_ERROR, "%s", + _("Could not get access to ACL tech driver")); return -1; } =20 diff --git a/src/nwfilter/nwfilter_gentech_driver.h b/src/nwfilter/nwfilter= _gentech_driver.h index 946d5d3d56..8f6f4d164a 100644 --- a/src/nwfilter/nwfilter_gentech_driver.h +++ b/src/nwfilter/nwfilter_gentech_driver.h @@ -25,7 +25,9 @@ #include "virnwfilterobj.h" #include "virnwfilterbindingdef.h" =20 -int virNWFilterTechDriversInit(bool privileged); +#define NWFILTER_DEFAULT_DRIVER "ebiptables" + +int virNWFilterTechDriversInit(bool privileged, const char *drivername); void virNWFilterTechDriversShutdown(void); =20 enum instCase { --=20 2.43.0