This commit is contained in:
commit
c39949ce35
339
LICENSE
Normal file
339
LICENSE
Normal file
@ -0,0 +1,339 @@
|
||||
GNU GENERAL PUBLIC LICENSE
|
||||
Version 2, June 1991
|
||||
|
||||
Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
|
||||
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
||||
Everyone is permitted to copy and distribute verbatim copies
|
||||
of this license document, but changing it is not allowed.
|
||||
|
||||
Preamble
|
||||
|
||||
The licenses for most software are designed to take away your
|
||||
freedom to share and change it. By contrast, the GNU General Public
|
||||
License is intended to guarantee your freedom to share and change free
|
||||
software--to make sure the software is free for all its users. This
|
||||
General Public License applies to most of the Free Software
|
||||
Foundation's software and to any other program whose authors commit to
|
||||
using it. (Some other Free Software Foundation software is covered by
|
||||
the GNU Lesser General Public License instead.) You can apply it to
|
||||
your programs, too.
|
||||
|
||||
When we speak of free software, we are referring to freedom, not
|
||||
price. Our General Public Licenses are designed to make sure that you
|
||||
have the freedom to distribute copies of free software (and charge for
|
||||
this service if you wish), that you receive source code or can get it
|
||||
if you want it, that you can change the software or use pieces of it
|
||||
in new free programs; and that you know you can do these things.
|
||||
|
||||
To protect your rights, we need to make restrictions that forbid
|
||||
anyone to deny you these rights or to ask you to surrender the rights.
|
||||
These restrictions translate to certain responsibilities for you if you
|
||||
distribute copies of the software, or if you modify it.
|
||||
|
||||
For example, if you distribute copies of such a program, whether
|
||||
gratis or for a fee, you must give the recipients all the rights that
|
||||
you have. You must make sure that they, too, receive or can get the
|
||||
source code. And you must show them these terms so they know their
|
||||
rights.
|
||||
|
||||
We protect your rights with two steps: (1) copyright the software, and
|
||||
(2) offer you this license which gives you legal permission to copy,
|
||||
distribute and/or modify the software.
|
||||
|
||||
Also, for each author's protection and ours, we want to make certain
|
||||
that everyone understands that there is no warranty for this free
|
||||
software. If the software is modified by someone else and passed on, we
|
||||
want its recipients to know that what they have is not the original, so
|
||||
that any problems introduced by others will not reflect on the original
|
||||
authors' reputations.
|
||||
|
||||
Finally, any free program is threatened constantly by software
|
||||
patents. We wish to avoid the danger that redistributors of a free
|
||||
program will individually obtain patent licenses, in effect making the
|
||||
program proprietary. To prevent this, we have made it clear that any
|
||||
patent must be licensed for everyone's free use or not licensed at all.
|
||||
|
||||
The precise terms and conditions for copying, distribution and
|
||||
modification follow.
|
||||
|
||||
GNU GENERAL PUBLIC LICENSE
|
||||
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
|
||||
|
||||
0. This License applies to any program or other work which contains
|
||||
a notice placed by the copyright holder saying it may be distributed
|
||||
under the terms of this General Public License. The "Program", below,
|
||||
refers to any such program or work, and a "work based on the Program"
|
||||
means either the Program or any derivative work under copyright law:
|
||||
that is to say, a work containing the Program or a portion of it,
|
||||
either verbatim or with modifications and/or translated into another
|
||||
language. (Hereinafter, translation is included without limitation in
|
||||
the term "modification".) Each licensee is addressed as "you".
|
||||
|
||||
Activities other than copying, distribution and modification are not
|
||||
covered by this License; they are outside its scope. The act of
|
||||
running the Program is not restricted, and the output from the Program
|
||||
is covered only if its contents constitute a work based on the
|
||||
Program (independent of having been made by running the Program).
|
||||
Whether that is true depends on what the Program does.
|
||||
|
||||
1. You may copy and distribute verbatim copies of the Program's
|
||||
source code as you receive it, in any medium, provided that you
|
||||
conspicuously and appropriately publish on each copy an appropriate
|
||||
copyright notice and disclaimer of warranty; keep intact all the
|
||||
notices that refer to this License and to the absence of any warranty;
|
||||
and give any other recipients of the Program a copy of this License
|
||||
along with the Program.
|
||||
|
||||
You may charge a fee for the physical act of transferring a copy, and
|
||||
you may at your option offer warranty protection in exchange for a fee.
|
||||
|
||||
2. You may modify your copy or copies of the Program or any portion
|
||||
of it, thus forming a work based on the Program, and copy and
|
||||
distribute such modifications or work under the terms of Section 1
|
||||
above, provided that you also meet all of these conditions:
|
||||
|
||||
a) You must cause the modified files to carry prominent notices
|
||||
stating that you changed the files and the date of any change.
|
||||
|
||||
b) You must cause any work that you distribute or publish, that in
|
||||
whole or in part contains or is derived from the Program or any
|
||||
part thereof, to be licensed as a whole at no charge to all third
|
||||
parties under the terms of this License.
|
||||
|
||||
c) If the modified program normally reads commands interactively
|
||||
when run, you must cause it, when started running for such
|
||||
interactive use in the most ordinary way, to print or display an
|
||||
announcement including an appropriate copyright notice and a
|
||||
notice that there is no warranty (or else, saying that you provide
|
||||
a warranty) and that users may redistribute the program under
|
||||
these conditions, and telling the user how to view a copy of this
|
||||
License. (Exception: if the Program itself is interactive but
|
||||
does not normally print such an announcement, your work based on
|
||||
the Program is not required to print an announcement.)
|
||||
|
||||
These requirements apply to the modified work as a whole. If
|
||||
identifiable sections of that work are not derived from the Program,
|
||||
and can be reasonably considered independent and separate works in
|
||||
themselves, then this License, and its terms, do not apply to those
|
||||
sections when you distribute them as separate works. But when you
|
||||
distribute the same sections as part of a whole which is a work based
|
||||
on the Program, the distribution of the whole must be on the terms of
|
||||
this License, whose permissions for other licensees extend to the
|
||||
entire whole, and thus to each and every part regardless of who wrote it.
|
||||
|
||||
Thus, it is not the intent of this section to claim rights or contest
|
||||
your rights to work written entirely by you; rather, the intent is to
|
||||
exercise the right to control the distribution of derivative or
|
||||
collective works based on the Program.
|
||||
|
||||
In addition, mere aggregation of another work not based on the Program
|
||||
with the Program (or with a work based on the Program) on a volume of
|
||||
a storage or distribution medium does not bring the other work under
|
||||
the scope of this License.
|
||||
|
||||
3. You may copy and distribute the Program (or a work based on it,
|
||||
under Section 2) in object code or executable form under the terms of
|
||||
Sections 1 and 2 above provided that you also do one of the following:
|
||||
|
||||
a) Accompany it with the complete corresponding machine-readable
|
||||
source code, which must be distributed under the terms of Sections
|
||||
1 and 2 above on a medium customarily used for software interchange; or,
|
||||
|
||||
b) Accompany it with a written offer, valid for at least three
|
||||
years, to give any third party, for a charge no more than your
|
||||
cost of physically performing source distribution, a complete
|
||||
machine-readable copy of the corresponding source code, to be
|
||||
distributed under the terms of Sections 1 and 2 above on a medium
|
||||
customarily used for software interchange; or,
|
||||
|
||||
c) Accompany it with the information you received as to the offer
|
||||
to distribute corresponding source code. (This alternative is
|
||||
allowed only for noncommercial distribution and only if you
|
||||
received the program in object code or executable form with such
|
||||
an offer, in accord with Subsection b above.)
|
||||
|
||||
The source code for a work means the preferred form of the work for
|
||||
making modifications to it. For an executable work, complete source
|
||||
code means all the source code for all modules it contains, plus any
|
||||
associated interface definition files, plus the scripts used to
|
||||
control compilation and installation of the executable. However, as a
|
||||
special exception, the source code distributed need not include
|
||||
anything that is normally distributed (in either source or binary
|
||||
form) with the major components (compiler, kernel, and so on) of the
|
||||
operating system on which the executable runs, unless that component
|
||||
itself accompanies the executable.
|
||||
|
||||
If distribution of executable or object code is made by offering
|
||||
access to copy from a designated place, then offering equivalent
|
||||
access to copy the source code from the same place counts as
|
||||
distribution of the source code, even though third parties are not
|
||||
compelled to copy the source along with the object code.
|
||||
|
||||
4. You may not copy, modify, sublicense, or distribute the Program
|
||||
except as expressly provided under this License. Any attempt
|
||||
otherwise to copy, modify, sublicense or distribute the Program is
|
||||
void, and will automatically terminate your rights under this License.
|
||||
However, parties who have received copies, or rights, from you under
|
||||
this License will not have their licenses terminated so long as such
|
||||
parties remain in full compliance.
|
||||
|
||||
5. You are not required to accept this License, since you have not
|
||||
signed it. However, nothing else grants you permission to modify or
|
||||
distribute the Program or its derivative works. These actions are
|
||||
prohibited by law if you do not accept this License. Therefore, by
|
||||
modifying or distributing the Program (or any work based on the
|
||||
Program), you indicate your acceptance of this License to do so, and
|
||||
all its terms and conditions for copying, distributing or modifying
|
||||
the Program or works based on it.
|
||||
|
||||
6. Each time you redistribute the Program (or any work based on the
|
||||
Program), the recipient automatically receives a license from the
|
||||
original licensor to copy, distribute or modify the Program subject to
|
||||
these terms and conditions. You may not impose any further
|
||||
restrictions on the recipients' exercise of the rights granted herein.
|
||||
You are not responsible for enforcing compliance by third parties to
|
||||
this License.
|
||||
|
||||
7. If, as a consequence of a court judgment or allegation of patent
|
||||
infringement or for any other reason (not limited to patent issues),
|
||||
conditions are imposed on you (whether by court order, agreement or
|
||||
otherwise) that contradict the conditions of this License, they do not
|
||||
excuse you from the conditions of this License. If you cannot
|
||||
distribute so as to satisfy simultaneously your obligations under this
|
||||
License and any other pertinent obligations, then as a consequence you
|
||||
may not distribute the Program at all. For example, if a patent
|
||||
license would not permit royalty-free redistribution of the Program by
|
||||
all those who receive copies directly or indirectly through you, then
|
||||
the only way you could satisfy both it and this License would be to
|
||||
refrain entirely from distribution of the Program.
|
||||
|
||||
If any portion of this section is held invalid or unenforceable under
|
||||
any particular circumstance, the balance of the section is intended to
|
||||
apply and the section as a whole is intended to apply in other
|
||||
circumstances.
|
||||
|
||||
It is not the purpose of this section to induce you to infringe any
|
||||
patents or other property right claims or to contest validity of any
|
||||
such claims; this section has the sole purpose of protecting the
|
||||
integrity of the free software distribution system, which is
|
||||
implemented by public license practices. Many people have made
|
||||
generous contributions to the wide range of software distributed
|
||||
through that system in reliance on consistent application of that
|
||||
system; it is up to the author/donor to decide if he or she is willing
|
||||
to distribute software through any other system and a licensee cannot
|
||||
impose that choice.
|
||||
|
||||
This section is intended to make thoroughly clear what is believed to
|
||||
be a consequence of the rest of this License.
|
||||
|
||||
8. If the distribution and/or use of the Program is restricted in
|
||||
certain countries either by patents or by copyrighted interfaces, the
|
||||
original copyright holder who places the Program under this License
|
||||
may add an explicit geographical distribution limitation excluding
|
||||
those countries, so that distribution is permitted only in or among
|
||||
countries not thus excluded. In such case, this License incorporates
|
||||
the limitation as if written in the body of this License.
|
||||
|
||||
9. The Free Software Foundation may publish revised and/or new versions
|
||||
of the General Public License from time to time. Such new versions will
|
||||
be similar in spirit to the present version, but may differ in detail to
|
||||
address new problems or concerns.
|
||||
|
||||
Each version is given a distinguishing version number. If the Program
|
||||
specifies a version number of this License which applies to it and "any
|
||||
later version", you have the option of following the terms and conditions
|
||||
either of that version or of any later version published by the Free
|
||||
Software Foundation. If the Program does not specify a version number of
|
||||
this License, you may choose any version ever published by the Free Software
|
||||
Foundation.
|
||||
|
||||
10. If you wish to incorporate parts of the Program into other free
|
||||
programs whose distribution conditions are different, write to the author
|
||||
to ask for permission. For software which is copyrighted by the Free
|
||||
Software Foundation, write to the Free Software Foundation; we sometimes
|
||||
make exceptions for this. Our decision will be guided by the two goals
|
||||
of preserving the free status of all derivatives of our free software and
|
||||
of promoting the sharing and reuse of software generally.
|
||||
|
||||
NO WARRANTY
|
||||
|
||||
11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
|
||||
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
|
||||
OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
|
||||
PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED
|
||||
OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
|
||||
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS
|
||||
TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE
|
||||
PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING,
|
||||
REPAIR OR CORRECTION.
|
||||
|
||||
12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
||||
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR
|
||||
REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
|
||||
INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING
|
||||
OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED
|
||||
TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY
|
||||
YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
|
||||
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
|
||||
POSSIBILITY OF SUCH DAMAGES.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
How to Apply These Terms to Your New Programs
|
||||
|
||||
If you develop a new program, and you want it to be of the greatest
|
||||
possible use to the public, the best way to achieve this is to make it
|
||||
free software which everyone can redistribute and change under these terms.
|
||||
|
||||
To do so, attach the following notices to the program. It is safest
|
||||
to attach them to the start of each source file to most effectively
|
||||
convey the exclusion of warranty; and each file should have at least
|
||||
the "copyright" line and a pointer to where the full notice is found.
|
||||
|
||||
<one line to give the program's name and a brief idea of what it does.>
|
||||
Copyright (C) <year> <name of author>
|
||||
|
||||
This program is free software; you can redistribute it and/or modify
|
||||
it under the terms of the GNU General Public License as published by
|
||||
the Free Software Foundation; either version 2 of the License, or
|
||||
(at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License along
|
||||
with this program; if not, write to the Free Software Foundation, Inc.,
|
||||
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
|
||||
Also add information on how to contact you by electronic and paper mail.
|
||||
|
||||
If the program is interactive, make it output a short notice like this
|
||||
when it starts in an interactive mode:
|
||||
|
||||
Gnomovision version 69, Copyright (C) year name of author
|
||||
Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
|
||||
This is free software, and you are welcome to redistribute it
|
||||
under certain conditions; type `show c' for details.
|
||||
|
||||
The hypothetical commands `show w' and `show c' should show the appropriate
|
||||
parts of the General Public License. Of course, the commands you use may
|
||||
be called something other than `show w' and `show c'; they could even be
|
||||
mouse-clicks or menu items--whatever suits your program.
|
||||
|
||||
You should also get your employer (if you work as a programmer) or your
|
||||
school, if any, to sign a "copyright disclaimer" for the program, if
|
||||
necessary. Here is a sample; alter the names:
|
||||
|
||||
Yoyodyne, Inc., hereby disclaims all copyright interest in the program
|
||||
`Gnomovision' (which makes passes at compilers) written by James Hacker.
|
||||
|
||||
<signature of Ty Coon>, 1 April 1989
|
||||
Ty Coon, President of Vice
|
||||
|
||||
This General Public License does not permit incorporating your program into
|
||||
proprietary programs. If your program is a subroutine library, you may
|
||||
consider it more useful to permit linking proprietary applications with the
|
||||
library. If this is what you want to do, use the GNU Lesser General
|
||||
Public License instead of this License.
|
@ -13,12 +13,17 @@ local SYS = require "luci.sys"
|
||||
local m, s
|
||||
|
||||
m = Map("appfilter", translate("App Filter"), translate(
|
||||
"Bypass mode is not currently supported, please turn off all possible conflicting modules such as acceleration (acc), advertisement filtering, multi-dialing, etc."))
|
||||
"Please turn off all possible conflicting modules such as acceleration (acc), advertisement filtering, multi-dialing, etc."))
|
||||
|
||||
s = m:section(TypedSection, "global", translate("Basic Settings"))
|
||||
s:option(Flag, "enable", translate("Enable App Filter"), translate(""))
|
||||
s.anonymous = true
|
||||
|
||||
o=s:option(ListValue, "work_mode", translate("Working mode"),translate("Please select the mode correctly. Generally, it is the main route after WAN port forwarding. It is recommended to restart the device after switching the mode."))
|
||||
o.default=0
|
||||
o:value(0, translate("Main router mode"))
|
||||
o:value(1, translate("Bypass mode"))
|
||||
|
||||
local rule_count = 0
|
||||
local version = ""
|
||||
|
||||
|
@ -14,14 +14,15 @@ local m, s
|
||||
|
||||
m = Map("appfilter", translate(""), translate(""))
|
||||
|
||||
s = m:section(TypedSection, "time", translate("Time Setting"))
|
||||
s = m:section(TypedSection, "time", translate("Time Setting"),translate("Time 2 is optional, the start and end times need to be set at the same time, and the end time must be greater than the start time"))
|
||||
s.anonymous = true
|
||||
hv = s:option(Value, "start_time", translate("Start Time"))
|
||||
hv.default = "00:00"
|
||||
hv.optional = false
|
||||
hv = s:option(Value, "end_time", translate("End Time"))
|
||||
hv.default = "23:59"
|
||||
hv.optional = false
|
||||
|
||||
|
||||
o=s:option(ListValue, "time_mode", translate("Time Match Mode:"),translate(""))
|
||||
o.default=0
|
||||
o:value(0, translate("Rules take effect within the time frame"))
|
||||
o:value(1, translate("Rules take effect outside of time frame"))
|
||||
|
||||
days = s:option(MultiValue, "days", "", translate(""))
|
||||
days.widget = "checkbox"
|
||||
days.size = 10
|
||||
@ -33,4 +34,14 @@ days:value("4", translate("Thur"));
|
||||
days:value("5", translate("Fri"));
|
||||
days:value("6", translate("Sat"));
|
||||
|
||||
hv = s:option(Value, "start_time", translate("Start Time1"), translate("Format 01:00"))
|
||||
hv.optional = false
|
||||
hv = s:option(Value, "end_time", translate("End Time1"))
|
||||
hv.optional = false
|
||||
|
||||
hv = s:option(Value, "start_time2", translate("Start Time2"), translate("Format 01:00"))
|
||||
hv.optional = false
|
||||
hv = s:option(Value, "end_time2", translate("End Time2"))
|
||||
hv.optional = false
|
||||
|
||||
return m
|
||||
|
@ -53,8 +53,8 @@ msgstr "生效用户"
|
||||
msgid "Effective Time"
|
||||
msgstr "生效时间"
|
||||
|
||||
msgid "Bypass mode is not currently supported, please turn off all possible conflicting modules such as acceleration (acc), advertisement filtering, multi-dialing, etc."
|
||||
msgstr "目前不支持旁路模式,请先关闭所有加速(acc)、广告过滤、多拨等可能冲突的模块"
|
||||
msgid "Please turn off all possible conflicting modules such as acceleration (acc), advertisement filtering, multi-dialing, etc."
|
||||
msgstr "请先关闭所有加速(acc)、广告过滤、多拨等可能冲突的模块"
|
||||
|
||||
msgid "It takes effect for all users by default, and only takes effect for the selected users when checked"
|
||||
msgstr "默认对所有用户生效,勾选后只对选择的用户生效"
|
||||
@ -140,11 +140,18 @@ msgstr "更新特征库失败,格式错误!"
|
||||
msgid "Select feature file"
|
||||
msgstr "选择特征库文件"
|
||||
|
||||
msgid "Start Time"
|
||||
msgstr "开始时间"
|
||||
msgid "Start Time1"
|
||||
msgstr "开始时间1"
|
||||
|
||||
msgid "End Time"
|
||||
msgstr "结束时间"
|
||||
msgid "End Time1"
|
||||
msgstr "结束时间1"
|
||||
|
||||
|
||||
msgid "Start Time2"
|
||||
msgstr "开始时间2"
|
||||
|
||||
msgid "End Time2"
|
||||
msgstr "结束时间2"
|
||||
|
||||
msgid "App Name"
|
||||
msgstr "App名称"
|
||||
@ -178,3 +185,30 @@ msgstr "MAC 地址"
|
||||
|
||||
msgid "IP"
|
||||
msgstr "IP 地址"
|
||||
|
||||
msgid "Working mode"
|
||||
msgstr "工作模式"
|
||||
|
||||
msgid "Please select the mode correctly. Generally, it is the main route after WAN port forwarding. It is recommended to restart the device after switching the mode."
|
||||
msgstr "请正确选择模式,一般经过了WAN口转发则为主路由,建议切换模式后重启设备"
|
||||
|
||||
msgid "Main router mode"
|
||||
msgstr "主路由模式"
|
||||
|
||||
msgid "Bypass mode"
|
||||
msgstr "旁路由模式"
|
||||
|
||||
msgid "Time 2 is optional, the start and end times need to be set at the same time, and the end time must be greater than the start time"
|
||||
msgstr "时间 2 为选填,开始和结束时间需要同时设置,结束时间要大于开始时间"
|
||||
|
||||
msgid "Time Match Mode:"
|
||||
msgstr "时间匹配模式:"
|
||||
|
||||
msgid "Rules take effect within the time frame"
|
||||
msgstr "时间范围内规则生效"
|
||||
|
||||
msgid "Rules take effect outside of time frame"
|
||||
msgstr "时间范围外规则生效"
|
||||
|
||||
msgid "Format 01:00"
|
||||
msgstr "格式 01:00"
|
||||
|
11
luci-app-oaf/root/etc/uci-defaults/91_luci-oaf
Executable file
11
luci-app-oaf/root/etc/uci-defaults/91_luci-oaf
Executable file
@ -0,0 +1,11 @@
|
||||
#!/bin/sh
|
||||
|
||||
uci -q batch <<-EOF >/dev/null
|
||||
del ucitrack.@appfilter[-1]
|
||||
add ucitrack appfilter
|
||||
set ucitrack.@appfilter[-1].exec="/usr/bin/oaf_rule reload"
|
||||
commit ucitrack
|
||||
EOF
|
||||
|
||||
# remove LuCI cache
|
||||
rm -rf /tmp/luci-indexcache /tmp/luci-modulecache
|
8
luci-app-oaf/root/etc/uci-defaults/92_oaf_time
Executable file
8
luci-app-oaf/root/etc/uci-defaults/92_oaf_time
Executable file
@ -0,0 +1,8 @@
|
||||
#!/bin/sh
|
||||
|
||||
uci -q batch <<-EOF >/dev/null
|
||||
set appfilter.time.time_mode="0"
|
||||
set appfilter.time.start_time2=""
|
||||
set appfilter.time.end_time2=""
|
||||
commit appfilter
|
||||
EOF
|
@ -102,12 +102,22 @@ af_client_info_t *find_af_client(unsigned char *mac)
|
||||
{
|
||||
if (0 == memcmp(node->mac, mac, 6))
|
||||
{
|
||||
node->update_jiffies = jiffies;
|
||||
return node;
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
|
||||
af_client_info_t *find_and_add_af_client(unsigned char *mac)
|
||||
{
|
||||
af_client_info_t *nfc;
|
||||
nfc = find_af_client(mac);
|
||||
if (!nfc){
|
||||
nfc = nf_client_add(mac);
|
||||
}
|
||||
return nfc;
|
||||
}
|
||||
|
||||
|
||||
af_client_info_t *find_af_client_by_ip(unsigned int ip)
|
||||
{
|
||||
@ -128,7 +138,7 @@ af_client_info_t *find_af_client_by_ip(unsigned int ip)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static af_client_info_t *
|
||||
af_client_info_t *
|
||||
nf_client_add(unsigned char *mac)
|
||||
{
|
||||
af_client_info_t *node;
|
||||
@ -154,6 +164,9 @@ nf_client_add(unsigned char *mac)
|
||||
return node;
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
void check_client_expire(void)
|
||||
{
|
||||
af_client_info_t *node;
|
||||
@ -243,8 +256,6 @@ int __af_visit_info_report(af_client_info_t *node)
|
||||
{
|
||||
if (node->visit_info[i].app_id == 0)
|
||||
continue;
|
||||
if (node->visit_info[i].total_num < 3)
|
||||
continue;
|
||||
count++;
|
||||
visit_obj = cJSON_CreateObject();
|
||||
cJSON_AddNumberToObject(visit_obj, "appid", node->visit_info[i].app_id);
|
||||
@ -373,6 +384,7 @@ static u_int32_t af_client_hook(unsigned int hook,
|
||||
if (nfc && nfc->ip != iph->saddr)
|
||||
{
|
||||
AF_DEBUG("update node " MAC_FMT " ip %pI4--->%pI4\n", MAC_ARRAY(nfc->mac), &nfc->ip, &iph->saddr);
|
||||
nfc->update_jiffies = jiffies;
|
||||
nfc->ip = iph->saddr;
|
||||
}
|
||||
AF_CLIENT_UNLOCK_W();
|
||||
|
@ -60,11 +60,14 @@ int af_client_init(void);
|
||||
|
||||
void af_client_exit(void);
|
||||
af_client_info_t *find_af_client_by_ip(unsigned int ip);
|
||||
af_client_info_t *find_af_client(unsigned char *mac);
|
||||
|
||||
void check_client_expire(void);
|
||||
|
||||
void af_visit_info_report(void);
|
||||
|
||||
void af_client_list_reset_report_num(void);
|
||||
af_client_info_t *nf_client_add(unsigned char *mac);
|
||||
af_client_info_t *find_and_add_af_client(unsigned char *mac);
|
||||
|
||||
#endif
|
||||
|
@ -4,13 +4,13 @@
|
||||
#include <linux/seq_file.h>
|
||||
#include <linux/list.h>
|
||||
#include <linux/sysctl.h>
|
||||
|
||||
#include "app_filter.h"
|
||||
#include "af_log.h"
|
||||
int af_log_lvl = 1;
|
||||
int af_test_mode = 0;
|
||||
// todo: rename af_log.c
|
||||
int g_oaf_enable __read_mostly = 0;
|
||||
|
||||
int af_work_mode = AF_MODE_GATEWAY;
|
||||
/*
|
||||
cat /proc/sys/oaf/debug
|
||||
*/
|
||||
@ -36,6 +36,13 @@ static struct ctl_table oaf_table[] = {
|
||||
.mode = 0666,
|
||||
.proc_handler = proc_dointvec,
|
||||
},
|
||||
{
|
||||
.procname = "work_mode",
|
||||
.data = &af_work_mode,
|
||||
.maxlen = sizeof(int),
|
||||
.mode = 0666,
|
||||
.proc_handler = proc_dointvec,
|
||||
},
|
||||
{
|
||||
}
|
||||
};
|
||||
|
@ -2,6 +2,7 @@
|
||||
#define __AF_DEBUG_H__
|
||||
extern int af_log_lvl;
|
||||
extern int af_test_mode;
|
||||
extern int af_work_mode;
|
||||
#define LOG(level, fmt, ...) do { \
|
||||
if ((level) <= af_log_lvl) { \
|
||||
printk(fmt, ##__VA_ARGS__); \
|
||||
|
@ -19,6 +19,27 @@ u_int32_t af_get_timestamp_sec(void)
|
||||
#endif
|
||||
|
||||
}
|
||||
char *k_trim(char *s)
|
||||
{
|
||||
char *start, *last, *bk;
|
||||
int len;
|
||||
|
||||
start = s;
|
||||
while (isspace(*start))
|
||||
start++;
|
||||
|
||||
bk = last = s + strlen(s) - 1;
|
||||
while (last > start && isspace(*last))
|
||||
last--;
|
||||
|
||||
if ((s != start) || (bk != last))
|
||||
{
|
||||
len = last - start + 1;
|
||||
strncpy(s, start, len);
|
||||
s[len] = '\0';
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
int check_local_network_ip(unsigned int ip)
|
||||
{
|
||||
|
@ -2,6 +2,8 @@
|
||||
#define AF_UTILS_H
|
||||
u_int32_t af_get_timestamp_sec(void);
|
||||
|
||||
char *k_trim(char *s);
|
||||
|
||||
int check_local_network_ip(unsigned int ip);
|
||||
|
||||
void dump_str(char *name, unsigned char *p, int len);
|
||||
|
@ -42,7 +42,7 @@ DEFINE_RWLOCK(af_feature_lock);
|
||||
#define MAX_OAF_NETLINK_MSG_LEN 1024
|
||||
|
||||
int __add_app_feature(int appid, char *name, int proto, int src_port,
|
||||
int dst_port, char *host_url, char *request_url, char *dict)
|
||||
port_info_t dport_info, char *host_url, char *request_url, char *dict)
|
||||
{
|
||||
af_feature_node_t *node = NULL;
|
||||
char *p = dict;
|
||||
@ -61,7 +61,7 @@ int __add_app_feature(int appid, char *name, int proto, int src_port,
|
||||
node->app_id = appid;
|
||||
strcpy(node->app_name, name);
|
||||
node->proto = proto;
|
||||
node->dport = dst_port;
|
||||
node->dport_info = dport_info;
|
||||
node->sport = src_port;
|
||||
strcpy(node->host_url, host_url);
|
||||
strcpy(node->request_url, request_url);
|
||||
@ -85,13 +85,10 @@ int __add_app_feature(int appid, char *name, int proto, int src_port,
|
||||
}
|
||||
|
||||
if (begin != dict)
|
||||
{
|
||||
strncpy(pos, begin, p - begin);
|
||||
}
|
||||
else
|
||||
{
|
||||
strcpy(pos, dict);
|
||||
}
|
||||
|
||||
k_sscanf(pos, "%d:%x", &index, &value);
|
||||
node->pos_info[node->pos_num].pos = index;
|
||||
node->pos_info[node->pos_num].value = value;
|
||||
@ -102,13 +99,119 @@ int __add_app_feature(int appid, char *name, int proto, int src_port,
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
int validate_range_value(char *range_str){
|
||||
if (!range_str)
|
||||
return 0;
|
||||
char *p = range_str;
|
||||
while(*p){
|
||||
if (*p == ' ' || *p == '!' || *p == '-' ||
|
||||
((*p >= '0') && (*p <= '9'))){
|
||||
p++;
|
||||
continue;
|
||||
}
|
||||
else{
|
||||
printk("error, invalid char %x\n", *p);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
int parse_range_value(char *range_str, range_value_t *range){
|
||||
char pure_range[128] = {0};
|
||||
if (!validate_range_value(range_str)){
|
||||
printk("validate range str failed, value = %s\n", range_str);
|
||||
return -1;
|
||||
}
|
||||
k_trim(range_str);
|
||||
if (range_str[0] == '!'){
|
||||
range->not = 1;
|
||||
strcpy(pure_range, range_str + 1);
|
||||
}
|
||||
else{
|
||||
range->not = 0;
|
||||
strcpy(pure_range, range_str);
|
||||
}
|
||||
k_trim(pure_range);
|
||||
int start, end;
|
||||
if (strstr(pure_range, "-")){
|
||||
if (2 != sscanf(pure_range, "%d-%d",&start, &end))
|
||||
return -1;
|
||||
}
|
||||
else{
|
||||
if (1 != sscanf(pure_range, "%d", &start))
|
||||
return -1;
|
||||
end = start;
|
||||
}
|
||||
range->start = start;
|
||||
range->end = end;
|
||||
return 0;
|
||||
}
|
||||
|
||||
int parse_port_info(char *port_str, port_info_t *info){
|
||||
char *p = port_str;
|
||||
char *begin = port_str;
|
||||
int param_num = 0;
|
||||
char one_port_buf[128] = {0};
|
||||
k_trim(port_str);
|
||||
if (strlen(port_str) == 0)
|
||||
return -1;
|
||||
|
||||
while(*p++) {
|
||||
if (*p != '|')
|
||||
continue;
|
||||
memset(one_port_buf, 0x0, sizeof(one_port_buf));
|
||||
strncpy(one_port_buf, begin, p - begin);
|
||||
if (0 == parse_range_value(one_port_buf, &info->range_list[info->num])){
|
||||
info->num++;
|
||||
}
|
||||
param_num++;
|
||||
begin = p + 1;
|
||||
}
|
||||
memset(one_port_buf, 0x0, sizeof(one_port_buf));
|
||||
strncpy(one_port_buf, begin, p - begin);
|
||||
if (0 == parse_range_value(one_port_buf, &info->range_list[info->num])){
|
||||
info->num++;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
int af_match_port(port_info_t *info, int port){
|
||||
int i;
|
||||
int with_not = 0;
|
||||
if (info->num == 0)
|
||||
return 1;
|
||||
for (i = 0; i < info->num; i++){
|
||||
if (info->range_list[i].not){
|
||||
with_not = 1;
|
||||
break;
|
||||
}
|
||||
}
|
||||
for (i = 0; i < info->num; i++){
|
||||
if (with_not){
|
||||
if (info->range_list[i].not && port >= info->range_list[i].start
|
||||
&& port <= info->range_list[i].end){
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
else{
|
||||
if (port >= info->range_list[i].start
|
||||
&& port <= info->range_list[i].end){
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
if (with_not)
|
||||
return 1;
|
||||
else
|
||||
return 0;
|
||||
}
|
||||
//[tcp;;443;baidu.com;;]
|
||||
int add_app_feature(int appid, char *name, char *feature)
|
||||
{
|
||||
char proto_str[16] = {0};
|
||||
char src_port_str[16] = {0};
|
||||
|
||||
port_info_t dport_info;
|
||||
char dst_port_str[16] = {0};
|
||||
char host_url[32] = {0};
|
||||
char request_url[128] = {0};
|
||||
@ -126,6 +229,7 @@ int add_app_feature(int appid, char *name, char *feature)
|
||||
return -1;
|
||||
}
|
||||
// tcp;8000;www.sina.com;0:get_name;00:0a-01:11
|
||||
memset(&dport_info, 0x0, sizeof(dport_info));
|
||||
while (*p++)
|
||||
{
|
||||
if (*p != ';')
|
||||
@ -172,8 +276,10 @@ int add_app_feature(int appid, char *name, char *feature)
|
||||
return -1;
|
||||
}
|
||||
sscanf(src_port_str, "%d", &src_port);
|
||||
sscanf(dst_port_str, "%d", &dst_port);
|
||||
__add_app_feature(appid, name, proto, src_port, dst_port, host_url, request_url, dict);
|
||||
// sscanf(dst_port_str, "%d", &dst_port);
|
||||
parse_port_info(dst_port_str, &dport_info);
|
||||
|
||||
__add_app_feature(appid, name, proto, src_port, dport_info, host_url, request_url, dict);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@ -333,7 +439,7 @@ static void af_clean_feature_list(void)
|
||||
feature_list_write_unlock();
|
||||
}
|
||||
|
||||
int parse_flow_base(struct sk_buff *skb, flow_info_t *flow)
|
||||
int parse_flow_proto(struct sk_buff *skb, flow_info_t *flow)
|
||||
{
|
||||
struct tcphdr *tcph = NULL;
|
||||
struct udphdr *udph = NULL;
|
||||
@ -341,17 +447,9 @@ int parse_flow_base(struct sk_buff *skb, flow_info_t *flow)
|
||||
struct iphdr *iph = NULL;
|
||||
if (!skb)
|
||||
return -1;
|
||||
#if LINUX_VERSION_CODE >= KERNEL_VERSION(4, 13, 0)
|
||||
ct = (struct nf_conn *)skb->_nfct;
|
||||
#else
|
||||
ct = (struct nf_conn *)skb->nfct;
|
||||
#endif
|
||||
if (!ct)
|
||||
return -1;
|
||||
iph = ip_hdr(skb);
|
||||
if (!iph)
|
||||
return -1;
|
||||
flow->ct = ct;
|
||||
flow->src = iph->saddr;
|
||||
flow->dst = iph->daddr;
|
||||
flow->l4_protocol = iph->protocol;
|
||||
@ -379,7 +477,7 @@ int parse_flow_base(struct sk_buff *skb, flow_info_t *flow)
|
||||
return -1;
|
||||
}
|
||||
|
||||
int parse_https_proto(flow_info_t *flow)
|
||||
int dpi_https_proto(flow_info_t *flow)
|
||||
{
|
||||
int i;
|
||||
short url_len = 0;
|
||||
@ -398,6 +496,7 @@ int parse_https_proto(flow_info_t *flow)
|
||||
if (!(p[0] == 0x16 && p[1] == 0x03 && p[2] == 0x01))
|
||||
return -1;
|
||||
|
||||
|
||||
for (i = 0; i < data_len; i++)
|
||||
{
|
||||
if (i + HTTPS_URL_OFFSET >= data_len)
|
||||
@ -425,7 +524,7 @@ int parse_https_proto(flow_info_t *flow)
|
||||
return -1;
|
||||
}
|
||||
|
||||
void parse_http_proto(flow_info_t *flow)
|
||||
void dpi_http_proto(flow_info_t *flow)
|
||||
{
|
||||
int i = 0;
|
||||
int start = 0;
|
||||
@ -658,9 +757,8 @@ int af_match_one(flow_info_t *flow, af_feature_node_t *node)
|
||||
{
|
||||
return AF_FALSE;
|
||||
}
|
||||
|
||||
if (node->dport != 0 && flow->dport != node->dport)
|
||||
{
|
||||
|
||||
if (!af_match_port(&node->dport_info, flow->dport)){
|
||||
return AF_FALSE;
|
||||
}
|
||||
|
||||
@ -702,7 +800,6 @@ int app_filter_match(flow_info_t *flow)
|
||||
}
|
||||
if (is_user_match_enable() && !find_af_mac(client->mac))
|
||||
{
|
||||
AF_DEBUG("not match mac:" MAC_FMT "\n", MAC_ARRAY(client->mac));
|
||||
goto EXIT;
|
||||
}
|
||||
if (af_get_app_status(node->app_id))
|
||||
@ -724,7 +821,7 @@ EXIT:
|
||||
return AF_FALSE;
|
||||
}
|
||||
|
||||
#define APP_FILTER_DROP_BITS 0x80000000
|
||||
#define NF_DROP_BIT 0x80000000
|
||||
|
||||
static int af_get_visit_index(af_client_info_t *node, int app_id)
|
||||
{
|
||||
@ -740,49 +837,177 @@ static int af_get_visit_index(af_client_info_t *node, int app_id)
|
||||
return 0;
|
||||
}
|
||||
|
||||
int __af_update_client_app_info(flow_info_t *flow, af_client_info_t *node)
|
||||
int af_update_client_app_info(af_client_info_t *node, int app_id, int drop)
|
||||
{
|
||||
int index = -1;
|
||||
if (!node)
|
||||
return -1;
|
||||
if (!flow)
|
||||
return -1;
|
||||
index = af_get_visit_index(node, flow->app_id);
|
||||
|
||||
index = af_get_visit_index(node, app_id);
|
||||
if (index < 0 || index >= MAX_RECORD_APP_NUM)
|
||||
{
|
||||
AF_ERROR("invalid index:%d\n\n", index);
|
||||
return 0;
|
||||
}
|
||||
// todo: up bytes
|
||||
node->visit_info[index].total_down_bytes += flow->l4_len + 66;
|
||||
node->visit_info[index].total_num++;
|
||||
if (flow->drop)
|
||||
if (drop)
|
||||
node->visit_info[index].drop_num++;
|
||||
|
||||
node->visit_info[index].app_id = flow->app_id;
|
||||
node->visit_info[index].app_id = app_id;
|
||||
node->visit_info[index].latest_time = af_get_timestamp_sec();
|
||||
node->visit_info[index].latest_action = flow->drop;
|
||||
node->visit_info[index].latest_action = drop;
|
||||
return 0;
|
||||
}
|
||||
|
||||
void af_update_client_app_info(flow_info_t *flow)
|
||||
{
|
||||
af_client_info_t *node = NULL;
|
||||
if (!flow)
|
||||
return;
|
||||
if (flow->app_id <= 0)
|
||||
return;
|
||||
AF_CLIENT_LOCK_W();
|
||||
node = find_af_client_by_ip(flow->src);
|
||||
if (node)
|
||||
{
|
||||
__af_update_client_app_info(flow, node);
|
||||
}
|
||||
AF_CLIENT_UNLOCK_W();
|
||||
int af_send_msg_to_user(char *pbuf, uint16_t len);
|
||||
int af_match_bcast_packet(flow_info_t *f){
|
||||
if (!f)
|
||||
return 0;
|
||||
if (0 == f->src || 0 == f->dst
|
||||
|| 0xffffffff == f->dst || 0 == f->dst)
|
||||
return 1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
int af_match_local_packet(flow_info_t *f){
|
||||
if (!f)
|
||||
return 0;
|
||||
if (0x0100007f == f->src || 0x0100007f == f->dst){
|
||||
return 1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
int dpi_main(struct sk_buff *skb, flow_info_t *flow){
|
||||
dpi_http_proto(flow);
|
||||
dpi_https_proto(flow);
|
||||
if (TEST_MODE())
|
||||
dump_flow_info(flow);
|
||||
return 0;
|
||||
}
|
||||
|
||||
void af_get_smac(struct sk_buff *skb, u_int8_t *smac){
|
||||
struct ethhdr *ethhdr = NULL;
|
||||
ethhdr = eth_hdr(skb);
|
||||
if (ethhdr)
|
||||
memcpy(smac, ethhdr->h_source, ETH_ALEN);
|
||||
else
|
||||
memcpy(smac, &skb->cb[40], ETH_ALEN);
|
||||
}
|
||||
|
||||
u_int32_t app_filter_hook_bypass_handle(struct sk_buff *skb, struct net_device *dev){
|
||||
flow_info_t flow;
|
||||
u_int8_t smac[ETH_ALEN];
|
||||
af_client_info_t *client = NULL;
|
||||
|
||||
if (!skb || !dev)
|
||||
return NF_ACCEPT;
|
||||
|
||||
if (skb->len > MAX_BYPASS_DPI_PKT_LEN)
|
||||
return NF_ACCEPT;
|
||||
|
||||
memset((char *)&flow, 0x0, sizeof(flow_info_t));
|
||||
if (parse_flow_proto(skb, &flow) < 0)
|
||||
return NF_ACCEPT;
|
||||
if (af_match_bcast_packet(&flow) || af_match_local_packet(&flow))
|
||||
return NF_ACCEPT;
|
||||
|
||||
af_get_smac(skb, smac);
|
||||
|
||||
AF_CLIENT_LOCK_W();
|
||||
client = find_and_add_af_client(smac);
|
||||
if (!client){
|
||||
AF_CLIENT_UNLOCK_W();
|
||||
return NF_ACCEPT;
|
||||
}
|
||||
client->update_jiffies = jiffies;
|
||||
AF_CLIENT_UNLOCK_W();
|
||||
|
||||
if (0 != dpi_main(skb, &flow))
|
||||
return NF_ACCEPT;
|
||||
|
||||
client->ip = flow.src;
|
||||
app_filter_match(&flow);
|
||||
if (flow.app_id != 0){
|
||||
af_update_client_app_info(client, flow.app_id, flow.drop);
|
||||
}
|
||||
if (flow.drop)
|
||||
{
|
||||
return NF_DROP;
|
||||
}
|
||||
return NF_ACCEPT;
|
||||
}
|
||||
|
||||
u_int32_t app_filter_hook_gateway_handle(struct sk_buff *skb, struct net_device *dev){
|
||||
unsigned long long total_packets = 0;
|
||||
flow_info_t flow;
|
||||
enum ip_conntrack_info ctinfo;
|
||||
struct nf_conn *ct = NULL;
|
||||
struct nf_conn_acct *acct;
|
||||
af_client_info_t *client = NULL;
|
||||
int app_id = 0;
|
||||
int drop = 0;
|
||||
|
||||
memset((char *)&flow, 0x0, sizeof(flow_info_t));
|
||||
if (parse_flow_proto(skb, &flow) < 0)
|
||||
return NF_ACCEPT;
|
||||
|
||||
ct = nf_ct_get(skb, &ctinfo);
|
||||
if (ct == NULL || !nf_ct_is_confirmed(ct))
|
||||
return NF_ACCEPT;
|
||||
|
||||
AF_CLIENT_LOCK_R();
|
||||
client = find_af_client_by_ip(flow.src);
|
||||
if (!client){
|
||||
AF_CLIENT_UNLOCK_R();
|
||||
return NF_ACCEPT;
|
||||
}
|
||||
client->update_jiffies = jiffies;
|
||||
AF_CLIENT_UNLOCK_R();
|
||||
|
||||
if (ct->mark != 0)
|
||||
{
|
||||
app_id = ct->mark & (~NF_DROP_BIT);
|
||||
if (app_id > 1000 && app_id < 9999){
|
||||
if (NF_DROP_BIT == (ct->mark & NF_DROP_BIT))
|
||||
drop = 1;
|
||||
AF_CLIENT_LOCK_W();
|
||||
af_update_client_app_info(client, app_id, drop);
|
||||
AF_CLIENT_UNLOCK_W();
|
||||
|
||||
if (drop){
|
||||
return NF_DROP;
|
||||
}
|
||||
}
|
||||
}
|
||||
acct = nf_conn_acct_find(ct);
|
||||
if(!acct)
|
||||
return NF_ACCEPT;
|
||||
total_packets = (unsigned long long)atomic64_read(&acct->counter[IP_CT_DIR_ORIGINAL].packets)
|
||||
+ (unsigned long long)atomic64_read(&acct->counter[IP_CT_DIR_REPLY].packets);
|
||||
|
||||
if(total_packets > MAX_DPI_PKT_NUM)
|
||||
return NF_ACCEPT;
|
||||
|
||||
if (0 != dpi_main(skb, &flow))
|
||||
return NF_ACCEPT;
|
||||
|
||||
app_filter_match(&flow);
|
||||
|
||||
if (flow.app_id != 0)
|
||||
{
|
||||
ct->mark = flow.app_id;
|
||||
AF_CLIENT_LOCK_W();
|
||||
af_update_client_app_info(client, flow.app_id, flow.drop);
|
||||
AF_CLIENT_UNLOCK_W();
|
||||
AF_LMT_INFO("match %s %pI4(%d)--> %pI4(%d) len = %d, %d\n ", IPPROTO_TCP == flow.l4_protocol ? "tcp" : "udp",
|
||||
&flow.src, flow.sport, &flow.dst, flow.dport, skb->len, flow.app_id);
|
||||
}
|
||||
if (flow.drop)
|
||||
{
|
||||
ct->mark |= NF_DROP_BIT;
|
||||
AF_LMT_INFO("##Drop app %s flow, appid is %d\n", flow.app_name, flow.app_id);
|
||||
return NF_DROP;
|
||||
}
|
||||
return NF_ACCEPT;
|
||||
}
|
||||
|
||||
int af_send_msg_to_user(char *pbuf, uint16_t len);
|
||||
|
||||
#if LINUX_VERSION_CODE >= KERNEL_VERSION(4, 4, 0)
|
||||
static u_int32_t app_filter_hook(void *priv,
|
||||
@ -797,74 +1022,34 @@ static u_int32_t app_filter_hook(unsigned int hook,
|
||||
int (*okfn)(struct sk_buff *))
|
||||
{
|
||||
#endif
|
||||
unsigned long long total_packets = 0;
|
||||
flow_info_t flow;
|
||||
enum ip_conntrack_info ctinfo;
|
||||
struct nf_conn *ct = NULL;
|
||||
struct nf_conn_acct *acct;
|
||||
if (!g_oaf_enable)
|
||||
return NF_ACCEPT;
|
||||
|
||||
ct = nf_ct_get(skb, &ctinfo);
|
||||
if (ct == NULL)
|
||||
if (AF_MODE_BYPASS == af_work_mode)
|
||||
return NF_ACCEPT;
|
||||
|
||||
#if defined(CONFIG_NF_CONNTRACK_MARK)
|
||||
if (ct->mark != 0)
|
||||
{
|
||||
if (APP_FILTER_DROP_BITS == (ct->mark & APP_FILTER_DROP_BITS))
|
||||
return NF_DROP;
|
||||
}
|
||||
#endif
|
||||
// 3.12.74-->3.13-rc1
|
||||
#if LINUX_VERSION_CODE >= KERNEL_VERSION(3, 13, 0)
|
||||
acct = nf_conn_acct_find(ct);
|
||||
if(!acct)
|
||||
return NF_ACCEPT;
|
||||
total_packets = (unsigned long long)atomic64_read(&acct->counter[IP_CT_DIR_ORIGINAL].packets)
|
||||
+ (unsigned long long)atomic64_read(&acct->counter[IP_CT_DIR_REPLY].packets);
|
||||
#else
|
||||
struct nf_conn_counter *counter;
|
||||
counter = nf_conn_acct_find(ct);
|
||||
if (!counter)
|
||||
return NF_ACCEPT;
|
||||
total_packets = (unsigned long long)atomic64_read(&counter[IP_CT_DIR_ORIGINAL].packets)
|
||||
+ (unsigned long long)atomic64_read(&counter[IP_CT_DIR_REPLY].packets);
|
||||
#endif
|
||||
if(total_packets > MAX_PARSE_PKT_NUM){
|
||||
return NF_ACCEPT;
|
||||
}
|
||||
|
||||
memset((char *)&flow, 0x0, sizeof(flow_info_t));
|
||||
if (parse_flow_base(skb, &flow) < 0)
|
||||
return NF_ACCEPT;
|
||||
|
||||
parse_http_proto(&flow);
|
||||
parse_https_proto(&flow);
|
||||
if (TEST_MODE())
|
||||
dump_flow_info(&flow);
|
||||
app_filter_match(&flow);
|
||||
|
||||
if (flow.app_id != 0)
|
||||
{
|
||||
if (flow.app_id > 1000 && flow.app_id <= 8999)
|
||||
{
|
||||
af_update_client_app_info(&flow);
|
||||
AF_LMT_INFO("match %s %pI4(%d)--> %pI4(%d) len = %d, %d\n ", IPPROTO_TCP == flow.l4_protocol ? "tcp" : "udp",
|
||||
&flow.src, flow.sport, &flow.dst, flow.dport, skb->len, flow.app_id);
|
||||
}
|
||||
}
|
||||
if (flow.drop)
|
||||
{
|
||||
#if defined(CONFIG_NF_CONNTRACK_MARK)
|
||||
ct->mark |= APP_FILTER_DROP_BITS;
|
||||
#endif
|
||||
AF_LMT_INFO("##Drop app %s flow, appid is %d\n", flow.app_name, flow.app_id);
|
||||
return NF_DROP;
|
||||
}
|
||||
return NF_ACCEPT;
|
||||
return app_filter_hook_gateway_handle(skb, skb->dev);
|
||||
}
|
||||
|
||||
#if LINUX_VERSION_CODE >= KERNEL_VERSION(4, 4, 0)
|
||||
static u_int32_t app_filter_by_pass_hook(void *priv,
|
||||
struct sk_buff *skb,
|
||||
const struct nf_hook_state *state)
|
||||
{
|
||||
#else
|
||||
static u_int32_t app_filter_by_pass_hook(unsigned int hook,
|
||||
struct sk_buff *skb,
|
||||
const struct net_device *in,
|
||||
const struct net_device *out,
|
||||
int (*okfn)(struct sk_buff *))
|
||||
{
|
||||
#endif
|
||||
if (!g_oaf_enable)
|
||||
return NF_ACCEPT;
|
||||
if (AF_MODE_GATEWAY == af_work_mode)
|
||||
return NF_ACCEPT;
|
||||
return app_filter_hook_bypass_handle(skb, skb->dev);
|
||||
}
|
||||
|
||||
|
||||
#if LINUX_VERSION_CODE >= KERNEL_VERSION(4, 4, 0)
|
||||
static struct nf_hook_ops app_filter_ops[] __read_mostly = {
|
||||
{
|
||||
@ -872,6 +1057,13 @@ static struct nf_hook_ops app_filter_ops[] __read_mostly = {
|
||||
.pf = PF_INET,
|
||||
.hooknum = NF_INET_FORWARD,
|
||||
.priority = NF_IP_PRI_MANGLE + 1,
|
||||
|
||||
},
|
||||
{
|
||||
.hook = app_filter_by_pass_hook,
|
||||
.pf = PF_INET,
|
||||
.hooknum = NF_INET_PRE_ROUTING,
|
||||
.priority = NF_IP_PRI_MANGLE + 1,
|
||||
},
|
||||
};
|
||||
#else
|
||||
@ -943,14 +1135,12 @@ int af_send_msg_to_user(char *pbuf, uint16_t len)
|
||||
nl_skb = nlmsg_new(len + sizeof(struct af_msg_hdr), GFP_ATOMIC);
|
||||
if (!nl_skb)
|
||||
{
|
||||
printk("netlink alloc failure\n");
|
||||
return -1;
|
||||
}
|
||||
|
||||
nlh = nlmsg_put(nl_skb, 0, 0, OAF_NETLINK_ID, len + sizeof(struct af_msg_hdr), 0);
|
||||
if (nlh == NULL)
|
||||
{
|
||||
printk("error, nlh is NULL\n");
|
||||
nlmsg_free(nl_skb);
|
||||
return -1;
|
||||
}
|
||||
@ -989,15 +1179,9 @@ static void oaf_msg_rcv(struct sk_buff *skb)
|
||||
umsg = NLMSG_DATA(nlh);
|
||||
af_hdr = (struct af_msg_hdr *)umsg;
|
||||
if (af_hdr->magic != 0xa0b0c0d0)
|
||||
{
|
||||
printk("magic error %x\n", af_hdr->magic);
|
||||
return;
|
||||
}
|
||||
if (af_hdr->len <= 0 || af_hdr->len >= MAX_OAF_NETLINK_MSG_LEN)
|
||||
{
|
||||
printk("data len error\n");
|
||||
return;
|
||||
}
|
||||
udata = umsg + sizeof(struct af_msg_hdr);
|
||||
|
||||
if (udata)
|
||||
|
@ -4,7 +4,7 @@
|
||||
#define AF_VERSION "5.0"
|
||||
#define AF_FEATURE_CONFIG_FILE "/tmp/feature.cfg"
|
||||
|
||||
#define MAX_PARSE_PKT_NUM 64
|
||||
#define MAX_DPI_PKT_NUM 64
|
||||
#define MIN_HTTP_DATA_LEN 16
|
||||
#define MAX_APP_NAME_LEN 64
|
||||
#define MAX_FEATURE_NUM_PER_APP 16
|
||||
@ -17,6 +17,7 @@
|
||||
#define MAX_FEATURE_LINE_LEN 256
|
||||
#define MIN_FEATURE_LINE_LEN 16
|
||||
#define MAX_URL_MATCH_LEN 64
|
||||
#define MAX_BYPASS_DPI_PKT_LEN 600
|
||||
|
||||
//#define CONFIG_KERNEL_FUNC_TEST 1
|
||||
|
||||
@ -59,6 +60,11 @@ enum E_MSG_TYPE{
|
||||
AF_MSG_INIT,
|
||||
AF_MSG_MAX
|
||||
};
|
||||
enum AF_WORK_MODE {
|
||||
AF_MODE_GATEWAY,
|
||||
AF_MODE_BYPASS,
|
||||
AF_MODE_BRIDGE,
|
||||
};
|
||||
|
||||
typedef struct af_msg{
|
||||
int action;
|
||||
@ -116,6 +122,22 @@ typedef struct af_pos_info{
|
||||
unsigned char value;
|
||||
}af_pos_info_t;
|
||||
|
||||
#define MAX_PORT_RANGE_NUM 5
|
||||
|
||||
typedef struct range_value
|
||||
{
|
||||
int not ;
|
||||
int start;
|
||||
int end;
|
||||
} range_value_t;
|
||||
|
||||
typedef struct port_info
|
||||
{
|
||||
u_int8_t mode; // 0: match, 1: not match
|
||||
int num;
|
||||
range_value_t range_list[MAX_PORT_RANGE_NUM];
|
||||
} port_info_t;
|
||||
|
||||
typedef struct af_feature_node{
|
||||
struct list_head head;
|
||||
u_int32_t app_id;
|
||||
@ -124,6 +146,7 @@ typedef struct af_feature_node{
|
||||
u_int32_t proto;
|
||||
u_int32_t sport;
|
||||
u_int32_t dport;
|
||||
port_info_t dport_info;
|
||||
char host_url[MAX_HOST_URL_LEN];
|
||||
char request_url[MAX_REQUEST_URL_LEN];
|
||||
int pos_num;
|
||||
|
@ -1,12 +1,16 @@
|
||||
config global global
|
||||
option enable '0'
|
||||
option work_mode '0'
|
||||
|
||||
config appfilter appfilter
|
||||
|
||||
config feature feature
|
||||
|
||||
config time 'time'
|
||||
option end_time '23:59'
|
||||
option time_mode '0'
|
||||
option days '0 1 2 3 4 5 6'
|
||||
option start_time '00:00'
|
||||
option end_time '23:59'
|
||||
option start_time2 ''
|
||||
option end_time2 ''
|
||||
config user user
|
||||
|
@ -78,10 +78,18 @@ reload_rule(){
|
||||
load_mac_list
|
||||
}
|
||||
|
||||
reload_base_config(){
|
||||
local old_work_mode
|
||||
config_load appfilter
|
||||
config_get work_mode "global" "work_mode"
|
||||
echo "work mode=$work_mode"
|
||||
echo "$work_mode" >/proc/sys/oaf/work_mode
|
||||
}
|
||||
|
||||
case $1 in
|
||||
"reload")
|
||||
echo "reload appfilter rule..."
|
||||
reload_base_config
|
||||
reload_rule
|
||||
;;
|
||||
esac
|
||||
|
@ -229,29 +229,43 @@ af_ctl_time_t *load_appfilter_ctl_time_config(void)
|
||||
{
|
||||
char start_time_str[64] = {0};
|
||||
char end_time_str[64] = {0};
|
||||
char start_time_str2[64] = {0};
|
||||
char end_time_str2[64] = {0};
|
||||
char days_str[64] = {0};
|
||||
int value = 0;
|
||||
int ret = 0;
|
||||
af_ctl_time_t *t = NULL;
|
||||
struct uci_context *ctx = uci_alloc_context();
|
||||
if (!ctx)
|
||||
return NULL;
|
||||
|
||||
ret |= uci_get_value(ctx, "appfilter.time.start_time", start_time_str, sizeof(start_time_str));
|
||||
ret |= uci_get_value(ctx, "appfilter.time.end_time", end_time_str, sizeof(end_time_str));
|
||||
ret |= uci_get_value(ctx, "appfilter.time.days", days_str, sizeof(days_str));
|
||||
if (ret != 0){
|
||||
printf("time config error\n");
|
||||
return NULL;
|
||||
}
|
||||
memset(start_time_str, 0x0, sizeof(start_time_str));
|
||||
memset(end_time_str, 0x0, sizeof(end_time_str));
|
||||
memset(start_time_str2, 0x0, sizeof(start_time_str2));
|
||||
memset(end_time_str2, 0x0, sizeof(end_time_str2));
|
||||
|
||||
uci_get_value(ctx, "appfilter.time.start_time", start_time_str, sizeof(start_time_str));
|
||||
uci_get_value(ctx, "appfilter.time.end_time", end_time_str, sizeof(end_time_str));
|
||||
uci_get_value(ctx, "appfilter.time.start_time2", start_time_str2, sizeof(start_time_str2));
|
||||
uci_get_value(ctx, "appfilter.time.end_time2", end_time_str2, sizeof(end_time_str2));
|
||||
uci_get_value(ctx, "appfilter.time.days", days_str, sizeof(days_str));
|
||||
|
||||
|
||||
if (!check_time_valid(start_time_str) || !check_time_valid(end_time_str)){
|
||||
printf("format error\n");
|
||||
return NULL;
|
||||
}
|
||||
t = malloc(sizeof(af_ctl_time_t));
|
||||
|
||||
sscanf(start_time_str, "%d:%d", &t->start.hour, &t->start.min);
|
||||
sscanf(end_time_str, "%d:%d", &t->end.hour, &t->end.min);
|
||||
value = uci_get_int_value(ctx, "appfilter.time.time_mode");
|
||||
if (value < 0)
|
||||
t->time_mode = 0;
|
||||
else
|
||||
t->time_mode = value;
|
||||
if (check_time_valid(start_time_str) && check_time_valid(end_time_str)){
|
||||
sscanf(start_time_str, "%d:%d", &t->start.hour, &t->start.min);
|
||||
sscanf(end_time_str, "%d:%d", &t->end.hour, &t->end.min);
|
||||
}
|
||||
if (check_time_valid(start_time_str2) && check_time_valid(end_time_str2)){
|
||||
sscanf(start_time_str2, "%d:%d", &t->start2.hour, &t->start2.min);
|
||||
sscanf(end_time_str2, "%d:%d", &t->end2.hour, &t->end2.min);
|
||||
}
|
||||
|
||||
char *p = strtok(days_str, " ");
|
||||
if (!p)
|
||||
|
@ -34,8 +34,11 @@ typedef struct af_time
|
||||
} af_time_t;
|
||||
typedef struct af_ctl_time
|
||||
{
|
||||
int time_mode; // 0,1
|
||||
af_time_t start;
|
||||
af_time_t end;
|
||||
af_time_t start2; // todo: time group list
|
||||
af_time_t end2;
|
||||
int days[7];
|
||||
} af_ctl_time_t;
|
||||
|
||||
|
@ -44,6 +44,8 @@ void appfilter_nl_handler(struct uloop_fd *u, unsigned int ev)
|
||||
struct sockaddr_nl nladdr;
|
||||
struct iovec iov = {buf, sizeof(buf)};
|
||||
struct nlmsghdr *h;
|
||||
int type;
|
||||
int id;
|
||||
char *mac = NULL;
|
||||
printf("%s %d\n", __func__, __LINE__);
|
||||
|
||||
@ -90,6 +92,7 @@ void appfilter_nl_handler(struct uloop_fd *u, unsigned int ev)
|
||||
printf("parse json failed:%s", kdata);
|
||||
return;
|
||||
}
|
||||
printf("recv msg = %s\n", kdata);
|
||||
|
||||
struct json_object *mac_obj = json_object_object_get(root, "mac");
|
||||
|
||||
@ -137,10 +140,10 @@ void appfilter_nl_handler(struct uloop_fd *u, unsigned int ev)
|
||||
int appid = json_object_get_int(appid_obj);
|
||||
int action = json_object_get_int(action_obj);
|
||||
|
||||
int type = appid / 1000;
|
||||
int id = appid % 1000;
|
||||
printf("%s %d\n", __func__, __LINE__);
|
||||
|
||||
type = appid / 1000;
|
||||
id = appid % 1000;
|
||||
if (id <= 0 || type <= 0)
|
||||
continue;
|
||||
node->stat[type - 1][id - 1].total_time += REPORT_INTERVAL_SECS;
|
||||
|
||||
// node->stat[type - 1][id - 1].total_down_bytes += json_object_get_int(down_obj);
|
||||
@ -148,6 +151,7 @@ void appfilter_nl_handler(struct uloop_fd *u, unsigned int ev)
|
||||
|
||||
int hash = hash_appid(appid);
|
||||
visit_info_t *head = node->visit_htable[hash];
|
||||
|
||||
if (head && (cur_time.tv_sec - head->latest_time) < 300)
|
||||
{
|
||||
head->latest_time = cur_time.tv_sec;
|
||||
@ -163,7 +167,6 @@ void appfilter_nl_handler(struct uloop_fd *u, unsigned int ev)
|
||||
visit_node->first_time = cur_time.tv_sec - MIN_VISIT_TIME;
|
||||
visit_node->next = NULL;
|
||||
add_visit_info_node(&node->visit_htable[hash], visit_node);
|
||||
printf("%s %d\n", __func__, __LINE__);
|
||||
|
||||
//printf("add visit info curtime=%d\n", cur_time.tv_sec);
|
||||
}
|
||||
|
@ -190,8 +190,10 @@ void clean_dev_online_status(void)
|
||||
dev_node_t *node = dev_hash_table[i];
|
||||
while (node)
|
||||
{
|
||||
node->online = 0;
|
||||
node->offline_time = get_timestamp();
|
||||
if (node->online){
|
||||
node->offline_time = get_timestamp();
|
||||
node->online = 0;
|
||||
}
|
||||
node = node->next;
|
||||
}
|
||||
}
|
||||
@ -201,7 +203,7 @@ void clean_dev_online_status(void)
|
||||
Id Mac Ip
|
||||
1 10:bf:48:37:0c:94 192.168.66.244
|
||||
*/
|
||||
void check_dev_expire(void)
|
||||
void update_dev_online_status(void)
|
||||
{
|
||||
char line_buf[256] = {0};
|
||||
char mac_buf[32] = {0};
|
||||
@ -234,6 +236,88 @@ void check_dev_expire(void)
|
||||
}
|
||||
fclose(fp);
|
||||
}
|
||||
|
||||
|
||||
#define DEV_OFFLINE_TIME (SECONDS_PER_DAY * 3)
|
||||
|
||||
int check_dev_expire(void)
|
||||
{
|
||||
int i, j;
|
||||
int count = 0;
|
||||
int cur_time = get_timestamp();
|
||||
int offline_time = 0;
|
||||
int expire_count = 0;
|
||||
int visit_count = 0;
|
||||
for (i = 0; i < MAX_DEV_NODE_HASH_SIZE; i++)
|
||||
{
|
||||
dev_node_t *node = dev_hash_table[i];
|
||||
while (node)
|
||||
{
|
||||
if (node->online)
|
||||
goto NEXT;
|
||||
visit_count = 0;
|
||||
offline_time = cur_time - node->offline_time;
|
||||
if (offline_time > DEV_OFFLINE_TIME)
|
||||
{
|
||||
node->expire = 1;
|
||||
for (j = 0; j < MAX_VISIT_HASH_SIZE; j++)
|
||||
{
|
||||
visit_info_t *p_info = node->visit_htable[j];
|
||||
while (p_info)
|
||||
{
|
||||
p_info->expire = 1;
|
||||
visit_count++;
|
||||
p_info = p_info->next;
|
||||
}
|
||||
}
|
||||
expire_count++;
|
||||
printf("dev:%s expired, offline time = %ds, count=%d, visit_count=%d\n",
|
||||
node->mac, offline_time, expire_count, visit_count);
|
||||
}
|
||||
NEXT:
|
||||
node = node->next;
|
||||
}
|
||||
}
|
||||
return expire_count;
|
||||
}
|
||||
|
||||
void flush_dev_expire_node(void)
|
||||
{
|
||||
int i, j;
|
||||
int count = 0;
|
||||
dev_node_t *node = NULL;
|
||||
dev_node_t *prev = NULL;
|
||||
for (i = 0; i < MAX_DEV_NODE_HASH_SIZE; i++)
|
||||
{
|
||||
dev_node_t *node = dev_hash_table[i];
|
||||
prev = NULL;
|
||||
while (node)
|
||||
{
|
||||
if (node->expire)
|
||||
{
|
||||
if (NULL == prev)
|
||||
{
|
||||
dev_hash_table[i] = node->next;
|
||||
free(node);
|
||||
node = dev_hash_table[i];
|
||||
prev = NULL;
|
||||
}
|
||||
else
|
||||
{
|
||||
prev->next = node->next;
|
||||
free(node);
|
||||
node = prev->next;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
prev = node;
|
||||
node = node->next;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
void dump_dev_list(void)
|
||||
{
|
||||
int i, j;
|
||||
@ -242,7 +326,7 @@ void dump_dev_list(void)
|
||||
char ip_buf[MAX_IP_LEN] = {0};
|
||||
clean_dev_online_status();
|
||||
update_dev_hostname();
|
||||
check_dev_expire();
|
||||
update_dev_online_status();
|
||||
FILE *fp = fopen(OAF_DEV_LIST_FILE, "w");
|
||||
if (!fp)
|
||||
{
|
||||
@ -359,9 +443,6 @@ void flush_expire_visit_info(void)
|
||||
while (p_info)
|
||||
{
|
||||
if (p_info->expire){
|
||||
printf("del node %-20s %-20s %d\n",
|
||||
node->mac, node->ip, p_info->appid
|
||||
);
|
||||
if (NULL == prev){
|
||||
node->visit_htable[j] = p_info->next;
|
||||
free(p_info);
|
||||
|
@ -35,6 +35,7 @@ THE SOFTWARE.
|
||||
#define MAX_APP_TYPE 16
|
||||
#define MAX_APP_ID_NUM 128
|
||||
#define MAX_SUPPORT_DEV_NUM 64
|
||||
#define SECONDS_PER_DAY (24 * 3600)
|
||||
|
||||
//extern dev_node_t *dev_hash_table[MAX_DEV_NODE_HASH_SIZE];
|
||||
|
||||
@ -78,6 +79,7 @@ typedef struct dev_node
|
||||
char ip[MAX_IP_LEN];
|
||||
char hostname[MAX_HOSTNAME_SIZE];
|
||||
int online;
|
||||
int expire;
|
||||
int offline_time;
|
||||
int online_time;
|
||||
visit_info_t *visit_htable[MAX_VISIT_HASH_SIZE];
|
||||
@ -110,5 +112,7 @@ void dev_foreach(void *arg, iter_func iter);
|
||||
void add_visit_info_node(visit_info_t **head, visit_info_t *node);
|
||||
void check_dev_visit_info_expire(void);
|
||||
void flush_expire_visit_info();
|
||||
|
||||
int check_dev_expire(void);
|
||||
void flush_dev_expire_node(void);
|
||||
void flush_expire_visit_info(void);
|
||||
#endif
|
||||
|
@ -47,26 +47,37 @@ void check_appfilter_enable(void)
|
||||
enable = 0;
|
||||
goto EXIT;
|
||||
}
|
||||
|
||||
|
||||
t = localtime(&tt);
|
||||
if (af_t->days[t->tm_wday] != 1)
|
||||
{
|
||||
enable = 0;
|
||||
goto EXIT;
|
||||
if (af_t->time_mode == 0){
|
||||
enable = 0;
|
||||
goto EXIT;
|
||||
}
|
||||
}
|
||||
|
||||
if (af_t->start.hour <= af_t->end.hour)
|
||||
|
||||
int cur_mins = t->tm_hour * 60 + t->tm_min;
|
||||
if (((af_t->start.hour * 60 + af_t->start.min < cur_mins) && (cur_mins < af_t->end.hour * 60 + af_t->end.min))
|
||||
|| ((af_t->start2.hour * 60 + af_t->start2.min < cur_mins) && (cur_mins < af_t->end2.hour * 60 + af_t->end2.min))
|
||||
)
|
||||
{
|
||||
int cur_mins = t->tm_hour * 60 + t->tm_min;
|
||||
if ((af_t->start.hour * 60 + af_t->start.min > cur_mins) || (cur_mins > af_t->end.hour * 60 + af_t->end.min))
|
||||
{
|
||||
if (af_t->time_mode == 0){
|
||||
enable = 1;
|
||||
}
|
||||
else{
|
||||
enable = 0;
|
||||
}
|
||||
}
|
||||
else
|
||||
enable = 0;
|
||||
else{
|
||||
if (af_t->time_mode == 0){
|
||||
enable = 0;
|
||||
}
|
||||
else{
|
||||
enable = 1;
|
||||
}
|
||||
}
|
||||
EXIT:
|
||||
|
||||
if (enable)
|
||||
{
|
||||
system("echo 1 >/proc/sys/oaf/enable ");
|
||||
@ -79,13 +90,16 @@ EXIT:
|
||||
|
||||
void dev_list_timeout_handler(struct uloop_timeout *t)
|
||||
{
|
||||
|
||||
dump_dev_list();
|
||||
check_dev_visit_info_expire();
|
||||
flush_expire_visit_info();
|
||||
//dump_dev_visit_list();
|
||||
check_appfilter_enable();
|
||||
//todo: dev list expire
|
||||
if (check_dev_expire()){
|
||||
flush_expire_visit_info();
|
||||
flush_dev_expire_node();
|
||||
}
|
||||
uloop_timeout_set(t, 10000);
|
||||
}
|
||||
|
||||
@ -108,7 +122,8 @@ int main(int argc, char **argv)
|
||||
{
|
||||
fprintf(stderr, "Failed to connect to ubus\n");
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
appfilter_nl_fd.fd = appfilter_nl_init();
|
||||
uloop_fd_add(&appfilter_nl_fd, ULOOP_READ);
|
||||
|
Loading…
Reference in New Issue
Block a user