1 /* $OpenBSD: pfctl.c,v 1.278 2008/08/31 20:18:17 jmc Exp $ */ 2 3 /*- 4 * SPDX-License-Identifier: BSD-2-Clause 5 * 6 * Copyright (c) 2001 Daniel Hartmeier 7 * Copyright (c) 2002,2003 Henning Brauer 8 * All rights reserved. 9 * 10 * Redistribution and use in source and binary forms, with or without 11 * modification, are permitted provided that the following conditions 12 * are met: 13 * 14 * - Redistributions of source code must retain the above copyright 15 * notice, this list of conditions and the following disclaimer. 16 * - Redistributions in binary form must reproduce the above 17 * copyright notice, this list of conditions and the following 18 * disclaimer in the documentation and/or other materials provided 19 * with the distribution. 20 * 21 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 22 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 23 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 24 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE 25 * COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, 26 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, 27 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 28 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER 29 * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN 31 * ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 32 * POSSIBILITY OF SUCH DAMAGE. 33 * 34 */ 35 36 #include <sys/cdefs.h> 37 #define PFIOC_USE_LATEST 38 39 #include <sys/types.h> 40 #include <sys/ioctl.h> 41 #include <sys/socket.h> 42 #include <sys/stat.h> 43 #include <sys/endian.h> 44 45 #include <net/if.h> 46 #include <netinet/in.h> 47 #include <net/pfvar.h> 48 #include <arpa/inet.h> 49 #include <net/altq/altq.h> 50 51 #include <err.h> 52 #include <errno.h> 53 #include <fcntl.h> 54 #include <libpfctl.h> 55 #include <limits.h> 56 #include <netdb.h> 57 #include <stdint.h> 58 #include <stdio.h> 59 #include <stdlib.h> 60 #include <string.h> 61 #include <unistd.h> 62 63 #include "pfctl_parser.h" 64 #include "pfctl.h" 65 66 void usage(void); 67 int pfctl_enable(int, int); 68 int pfctl_disable(int, int); 69 int pfctl_clear_stats(struct pfctl_handle *, int); 70 int pfctl_get_skip_ifaces(void); 71 int pfctl_check_skip_ifaces(char *); 72 int pfctl_adjust_skip_ifaces(struct pfctl *); 73 int pfctl_clear_interface_flags(int, int); 74 int pfctl_flush_eth_rules(int, int, char *); 75 int pfctl_flush_rules(int, int, char *); 76 int pfctl_flush_nat(int, int, char *); 77 int pfctl_clear_altq(int, int); 78 int pfctl_clear_src_nodes(int, int); 79 int pfctl_clear_iface_states(int, const char *, int); 80 void pfctl_addrprefix(char *, struct pf_addr *); 81 int pfctl_kill_src_nodes(int, const char *, int); 82 int pfctl_net_kill_states(int, const char *, int); 83 int pfctl_gateway_kill_states(int, const char *, int); 84 int pfctl_label_kill_states(int, const char *, int); 85 int pfctl_id_kill_states(int, const char *, int); 86 void pfctl_init_options(struct pfctl *); 87 int pfctl_load_options(struct pfctl *); 88 int pfctl_load_limit(struct pfctl *, unsigned int, unsigned int); 89 int pfctl_load_timeout(struct pfctl *, unsigned int, unsigned int); 90 int pfctl_load_debug(struct pfctl *, unsigned int); 91 int pfctl_load_logif(struct pfctl *, char *); 92 int pfctl_load_hostid(struct pfctl *, u_int32_t); 93 int pfctl_load_reassembly(struct pfctl *, u_int32_t); 94 int pfctl_load_syncookies(struct pfctl *, u_int8_t); 95 int pfctl_get_pool(int, struct pfctl_pool *, u_int32_t, u_int32_t, int, 96 const char *, int); 97 void pfctl_print_eth_rule_counters(struct pfctl_eth_rule *, int); 98 void pfctl_print_rule_counters(struct pfctl_rule *, int); 99 int pfctl_show_eth_rules(int, char *, int, enum pfctl_show, char *, int, int); 100 int pfctl_show_rules(int, char *, int, enum pfctl_show, char *, int, int); 101 int pfctl_show_nat(int, const char *, int, char *, int, int); 102 int pfctl_show_src_nodes(int, int); 103 int pfctl_show_states(int, const char *, int); 104 int pfctl_show_status(int, int); 105 int pfctl_show_running(int); 106 int pfctl_show_timeouts(int, int); 107 int pfctl_show_limits(int, int); 108 void pfctl_debug(int, u_int32_t, int); 109 int pfctl_test_altqsupport(int, int); 110 int pfctl_show_anchors(int, int, char *); 111 int pfctl_show_eth_anchors(int, int, char *); 112 int pfctl_ruleset_trans(struct pfctl *, char *, struct pfctl_anchor *, bool); 113 int pfctl_eth_ruleset_trans(struct pfctl *, char *, 114 struct pfctl_eth_anchor *); 115 int pfctl_load_eth_ruleset(struct pfctl *, char *, 116 struct pfctl_eth_ruleset *, int); 117 int pfctl_load_eth_rule(struct pfctl *, char *, struct pfctl_eth_rule *, 118 int); 119 int pfctl_load_ruleset(struct pfctl *, char *, 120 struct pfctl_ruleset *, int, int); 121 int pfctl_load_rule(struct pfctl *, char *, struct pfctl_rule *, int); 122 const char *pfctl_lookup_option(char *, const char * const *); 123 124 static struct pfctl_anchor_global pf_anchors; 125 struct pfctl_anchor pf_main_anchor; 126 struct pfctl_eth_anchor pf_eth_main_anchor; 127 static struct pfr_buffer skip_b; 128 129 static const char *clearopt; 130 static char *rulesopt; 131 static const char *showopt; 132 static const char *debugopt; 133 static char *anchoropt; 134 static const char *optiopt = NULL; 135 static const char *pf_device = PF_DEVICE; 136 static char *ifaceopt; 137 static char *tableopt; 138 static const char *tblcmdopt; 139 static int src_node_killers; 140 static char *src_node_kill[2]; 141 static int state_killers; 142 static char *state_kill[2]; 143 int loadopt; 144 int altqsupport; 145 146 int dev = -1; 147 struct pfctl_handle *pfh = NULL; 148 static int first_title = 1; 149 static int labels = 0; 150 151 #define INDENT(d, o) do { \ 152 if (o) { \ 153 int i; \ 154 for (i=0; i < d; i++) \ 155 printf(" "); \ 156 } \ 157 } while (0); \ 158 159 160 static const struct { 161 const char *name; 162 int index; 163 } pf_limits[] = { 164 { "states", PF_LIMIT_STATES }, 165 { "src-nodes", PF_LIMIT_SRC_NODES }, 166 { "frags", PF_LIMIT_FRAGS }, 167 { "table-entries", PF_LIMIT_TABLE_ENTRIES }, 168 { NULL, 0 } 169 }; 170 171 struct pf_hint { 172 const char *name; 173 int timeout; 174 }; 175 static const struct pf_hint pf_hint_normal[] = { 176 { "tcp.first", 2 * 60 }, 177 { "tcp.opening", 30 }, 178 { "tcp.established", 24 * 60 * 60 }, 179 { "tcp.closing", 15 * 60 }, 180 { "tcp.finwait", 45 }, 181 { "tcp.closed", 90 }, 182 { "tcp.tsdiff", 30 }, 183 { NULL, 0 } 184 }; 185 static const struct pf_hint pf_hint_satellite[] = { 186 { "tcp.first", 3 * 60 }, 187 { "tcp.opening", 30 + 5 }, 188 { "tcp.established", 24 * 60 * 60 }, 189 { "tcp.closing", 15 * 60 + 5 }, 190 { "tcp.finwait", 45 + 5 }, 191 { "tcp.closed", 90 + 5 }, 192 { "tcp.tsdiff", 60 }, 193 { NULL, 0 } 194 }; 195 static const struct pf_hint pf_hint_conservative[] = { 196 { "tcp.first", 60 * 60 }, 197 { "tcp.opening", 15 * 60 }, 198 { "tcp.established", 5 * 24 * 60 * 60 }, 199 { "tcp.closing", 60 * 60 }, 200 { "tcp.finwait", 10 * 60 }, 201 { "tcp.closed", 3 * 60 }, 202 { "tcp.tsdiff", 60 }, 203 { NULL, 0 } 204 }; 205 static const struct pf_hint pf_hint_aggressive[] = { 206 { "tcp.first", 30 }, 207 { "tcp.opening", 5 }, 208 { "tcp.established", 5 * 60 * 60 }, 209 { "tcp.closing", 60 }, 210 { "tcp.finwait", 30 }, 211 { "tcp.closed", 30 }, 212 { "tcp.tsdiff", 10 }, 213 { NULL, 0 } 214 }; 215 216 static const struct { 217 const char *name; 218 const struct pf_hint *hint; 219 } pf_hints[] = { 220 { "normal", pf_hint_normal }, 221 { "satellite", pf_hint_satellite }, 222 { "high-latency", pf_hint_satellite }, 223 { "conservative", pf_hint_conservative }, 224 { "aggressive", pf_hint_aggressive }, 225 { NULL, NULL } 226 }; 227 228 static const char * const clearopt_list[] = { 229 "nat", "queue", "rules", "Sources", 230 "states", "info", "Tables", "osfp", "all", 231 "ethernet", NULL 232 }; 233 234 static const char * const showopt_list[] = { 235 "ether", "nat", "queue", "rules", "Anchors", "Sources", "states", 236 "info", "Interfaces", "labels", "timeouts", "memory", "Tables", 237 "osfp", "Running", "all", "creatorids", NULL 238 }; 239 240 static const char * const tblcmdopt_list[] = { 241 "kill", "flush", "add", "delete", "load", "replace", "show", 242 "test", "zero", "expire", "reset", NULL 243 }; 244 245 static const char * const debugopt_list[] = { 246 "none", "urgent", "misc", "loud", NULL 247 }; 248 249 static const char * const optiopt_list[] = { 250 "none", "basic", "profile", NULL 251 }; 252 253 void 254 usage(void) 255 { 256 extern char *__progname; 257 258 fprintf(stderr, 259 "usage: %s [-AdeghMmNnOPqRrvz] [-a anchor] [-D macro=value] [-F modifier]\n" 260 "\t[-f file] [-i interface] [-K host | network]\n" 261 "\t[-k host | network | gateway | label | id] [-o level] [-p device]\n" 262 "\t[-s modifier] [-t table -T command [address ...]] [-x level]\n", 263 __progname); 264 265 exit(1); 266 } 267 268 /* 269 * Cache protocol number to name translations. 270 * 271 * Translation is performed a lot e.g., when dumping states and 272 * getprotobynumber is incredibly expensive. 273 * 274 * Note from the getprotobynumber(3) manpage: 275 * <quote> 276 * These functions use a thread-specific data space; if the data is needed 277 * for future use, it should be copied before any subsequent calls overwrite 278 * it. Only the Internet protocols are currently understood. 279 * </quote> 280 * 281 * Consequently we only cache the name and strdup it for safety. 282 * 283 * At the time of writing this comment the last entry in /etc/protocols is: 284 * divert 258 DIVERT # Divert pseudo-protocol [non IANA] 285 */ 286 const char * 287 pfctl_proto2name(int proto) 288 { 289 static const char *pfctl_proto_cache[259]; 290 struct protoent *p; 291 292 if (proto >= nitems(pfctl_proto_cache)) { 293 p = getprotobynumber(proto); 294 if (p == NULL) { 295 return (NULL); 296 } 297 return (p->p_name); 298 } 299 300 if (pfctl_proto_cache[proto] == NULL) { 301 p = getprotobynumber(proto); 302 if (p == NULL) { 303 return (NULL); 304 } 305 pfctl_proto_cache[proto] = strdup(p->p_name); 306 } 307 308 return (pfctl_proto_cache[proto]); 309 } 310 311 int 312 pfctl_enable(int dev, int opts) 313 { 314 int ret; 315 316 if ((ret = pfctl_startstop(pfh, 1)) != 0) { 317 if (ret == EEXIST) 318 errx(1, "pf already enabled"); 319 else if (ret == ESRCH) 320 errx(1, "pfil registeration failed"); 321 else 322 errc(1, ret, "DIOCSTART"); 323 } 324 if ((opts & PF_OPT_QUIET) == 0) 325 fprintf(stderr, "pf enabled\n"); 326 327 if (altqsupport && ioctl(dev, DIOCSTARTALTQ)) 328 if (errno != EEXIST) 329 err(1, "DIOCSTARTALTQ"); 330 331 return (0); 332 } 333 334 int 335 pfctl_disable(int dev, int opts) 336 { 337 int ret; 338 339 if ((ret = pfctl_startstop(pfh, 0)) != 0) { 340 if (ret == ENOENT) 341 errx(1, "pf not enabled"); 342 else 343 errc(1, ret, "DIOCSTOP"); 344 } 345 if ((opts & PF_OPT_QUIET) == 0) 346 fprintf(stderr, "pf disabled\n"); 347 348 if (altqsupport && ioctl(dev, DIOCSTOPALTQ)) 349 if (errno != ENOENT) 350 err(1, "DIOCSTOPALTQ"); 351 352 return (0); 353 } 354 355 int 356 pfctl_clear_stats(struct pfctl_handle *h, int opts) 357 { 358 int ret; 359 if ((ret = pfctl_clear_status(h)) != 0) 360 errc(1, ret, "DIOCCLRSTATUS"); 361 if ((opts & PF_OPT_QUIET) == 0) 362 fprintf(stderr, "pf: statistics cleared\n"); 363 return (0); 364 } 365 366 int 367 pfctl_get_skip_ifaces(void) 368 { 369 bzero(&skip_b, sizeof(skip_b)); 370 skip_b.pfrb_type = PFRB_IFACES; 371 for (;;) { 372 pfr_buf_grow(&skip_b, skip_b.pfrb_size); 373 skip_b.pfrb_size = skip_b.pfrb_msize; 374 if (pfi_get_ifaces(NULL, skip_b.pfrb_caddr, &skip_b.pfrb_size)) 375 err(1, "pfi_get_ifaces"); 376 if (skip_b.pfrb_size <= skip_b.pfrb_msize) 377 break; 378 } 379 return (0); 380 } 381 382 int 383 pfctl_check_skip_ifaces(char *ifname) 384 { 385 struct pfi_kif *p; 386 struct node_host *h = NULL, *n = NULL; 387 388 PFRB_FOREACH(p, &skip_b) { 389 if (!strcmp(ifname, p->pfik_name) && 390 (p->pfik_flags & PFI_IFLAG_SKIP)) 391 p->pfik_flags &= ~PFI_IFLAG_SKIP; 392 if (!strcmp(ifname, p->pfik_name) && p->pfik_group != NULL) { 393 if ((h = ifa_grouplookup(p->pfik_name, 0)) == NULL) 394 continue; 395 396 for (n = h; n != NULL; n = n->next) { 397 if (strncmp(p->pfik_name, ifname, IFNAMSIZ)) 398 continue; 399 400 p->pfik_flags &= ~PFI_IFLAG_SKIP; 401 } 402 } 403 } 404 return (0); 405 } 406 407 int 408 pfctl_adjust_skip_ifaces(struct pfctl *pf) 409 { 410 struct pfi_kif *p, *pp; 411 struct node_host *h = NULL, *n = NULL; 412 413 PFRB_FOREACH(p, &skip_b) { 414 if (p->pfik_group == NULL || !(p->pfik_flags & PFI_IFLAG_SKIP)) 415 continue; 416 417 pfctl_set_interface_flags(pf, p->pfik_name, PFI_IFLAG_SKIP, 0); 418 if ((h = ifa_grouplookup(p->pfik_name, 0)) == NULL) 419 continue; 420 421 for (n = h; n != NULL; n = n->next) 422 PFRB_FOREACH(pp, &skip_b) { 423 if (strncmp(pp->pfik_name, n->ifname, IFNAMSIZ)) 424 continue; 425 426 if (!(pp->pfik_flags & PFI_IFLAG_SKIP)) 427 pfctl_set_interface_flags(pf, 428 pp->pfik_name, PFI_IFLAG_SKIP, 1); 429 if (pp->pfik_flags & PFI_IFLAG_SKIP) 430 pp->pfik_flags &= ~PFI_IFLAG_SKIP; 431 } 432 } 433 434 PFRB_FOREACH(p, &skip_b) { 435 if (! (p->pfik_flags & PFI_IFLAG_SKIP)) 436 continue; 437 438 pfctl_set_interface_flags(pf, p->pfik_name, PFI_IFLAG_SKIP, 0); 439 } 440 441 return (0); 442 } 443 444 int 445 pfctl_clear_interface_flags(int dev, int opts) 446 { 447 struct pfioc_iface pi; 448 449 if ((opts & PF_OPT_NOACTION) == 0) { 450 bzero(&pi, sizeof(pi)); 451 pi.pfiio_flags = PFI_IFLAG_SKIP; 452 453 if (ioctl(dev, DIOCCLRIFFLAG, &pi)) 454 err(1, "DIOCCLRIFFLAG"); 455 if ((opts & PF_OPT_QUIET) == 0) 456 fprintf(stderr, "pf: interface flags reset\n"); 457 } 458 return (0); 459 } 460 461 int 462 pfctl_flush_eth_rules(int dev, int opts, char *anchorname) 463 { 464 int ret; 465 466 ret = pfctl_clear_eth_rules(dev, anchorname); 467 if (ret != 0) 468 err(1, "pfctl_clear_eth_rules"); 469 470 if ((opts & PF_OPT_QUIET) == 0) 471 fprintf(stderr, "Ethernet rules cleared\n"); 472 473 return (ret); 474 } 475 476 int 477 pfctl_flush_rules(int dev, int opts, char *anchorname) 478 { 479 int ret; 480 481 ret = pfctl_clear_rules(dev, anchorname); 482 if (ret != 0) 483 err(1, "pfctl_clear_rules"); 484 if ((opts & PF_OPT_QUIET) == 0) 485 fprintf(stderr, "rules cleared\n"); 486 return (0); 487 } 488 489 int 490 pfctl_flush_nat(int dev, int opts, char *anchorname) 491 { 492 int ret; 493 494 ret = pfctl_clear_nat(dev, anchorname); 495 if (ret != 0) 496 err(1, "pfctl_clear_nat"); 497 if ((opts & PF_OPT_QUIET) == 0) 498 fprintf(stderr, "nat cleared\n"); 499 return (0); 500 } 501 502 int 503 pfctl_clear_altq(int dev, int opts) 504 { 505 struct pfr_buffer t; 506 507 if (!altqsupport) 508 return (-1); 509 memset(&t, 0, sizeof(t)); 510 t.pfrb_type = PFRB_TRANS; 511 if (pfctl_add_trans(&t, PF_RULESET_ALTQ, "") || 512 pfctl_trans(dev, &t, DIOCXBEGIN, 0) || 513 pfctl_trans(dev, &t, DIOCXCOMMIT, 0)) 514 err(1, "pfctl_clear_altq"); 515 if ((opts & PF_OPT_QUIET) == 0) 516 fprintf(stderr, "altq cleared\n"); 517 return (0); 518 } 519 520 int 521 pfctl_clear_src_nodes(int dev, int opts) 522 { 523 if (ioctl(dev, DIOCCLRSRCNODES)) 524 err(1, "DIOCCLRSRCNODES"); 525 if ((opts & PF_OPT_QUIET) == 0) 526 fprintf(stderr, "source tracking entries cleared\n"); 527 return (0); 528 } 529 530 int 531 pfctl_clear_iface_states(int dev, const char *iface, int opts) 532 { 533 struct pfctl_kill kill; 534 unsigned int killed; 535 int ret; 536 537 memset(&kill, 0, sizeof(kill)); 538 if (iface != NULL && strlcpy(kill.ifname, iface, 539 sizeof(kill.ifname)) >= sizeof(kill.ifname)) 540 errx(1, "invalid interface: %s", iface); 541 542 if (opts & PF_OPT_KILLMATCH) 543 kill.kill_match = true; 544 545 if ((ret = pfctl_clear_states_h(pfh, &kill, &killed)) != 0) 546 errc(1, ret, "DIOCCLRSTATES"); 547 if ((opts & PF_OPT_QUIET) == 0) 548 fprintf(stderr, "%d states cleared\n", killed); 549 return (0); 550 } 551 552 void 553 pfctl_addrprefix(char *addr, struct pf_addr *mask) 554 { 555 char *p; 556 const char *errstr; 557 int prefix, ret_ga, q, r; 558 struct addrinfo hints, *res; 559 560 if ((p = strchr(addr, '/')) == NULL) 561 return; 562 563 *p++ = '\0'; 564 prefix = strtonum(p, 0, 128, &errstr); 565 if (errstr) 566 errx(1, "prefix is %s: %s", errstr, p); 567 568 bzero(&hints, sizeof(hints)); 569 /* prefix only with numeric addresses */ 570 hints.ai_flags |= AI_NUMERICHOST; 571 572 if ((ret_ga = getaddrinfo(addr, NULL, &hints, &res))) { 573 errx(1, "getaddrinfo: %s", gai_strerror(ret_ga)); 574 /* NOTREACHED */ 575 } 576 577 if (res->ai_family == AF_INET && prefix > 32) 578 errx(1, "prefix too long for AF_INET"); 579 else if (res->ai_family == AF_INET6 && prefix > 128) 580 errx(1, "prefix too long for AF_INET6"); 581 582 q = prefix >> 3; 583 r = prefix & 7; 584 switch (res->ai_family) { 585 case AF_INET: 586 bzero(&mask->v4, sizeof(mask->v4)); 587 mask->v4.s_addr = htonl((u_int32_t) 588 (0xffffffffffULL << (32 - prefix))); 589 break; 590 case AF_INET6: 591 bzero(&mask->v6, sizeof(mask->v6)); 592 if (q > 0) 593 memset((void *)&mask->v6, 0xff, q); 594 if (r > 0) 595 *((u_char *)&mask->v6 + q) = 596 (0xff00 >> r) & 0xff; 597 break; 598 } 599 freeaddrinfo(res); 600 } 601 602 int 603 pfctl_kill_src_nodes(int dev, const char *iface, int opts) 604 { 605 struct pfioc_src_node_kill psnk; 606 struct addrinfo *res[2], *resp[2]; 607 struct sockaddr last_src, last_dst; 608 int killed, sources, dests; 609 int ret_ga; 610 611 killed = sources = dests = 0; 612 613 memset(&psnk, 0, sizeof(psnk)); 614 memset(&psnk.psnk_src.addr.v.a.mask, 0xff, 615 sizeof(psnk.psnk_src.addr.v.a.mask)); 616 memset(&last_src, 0xff, sizeof(last_src)); 617 memset(&last_dst, 0xff, sizeof(last_dst)); 618 619 pfctl_addrprefix(src_node_kill[0], &psnk.psnk_src.addr.v.a.mask); 620 621 if ((ret_ga = getaddrinfo(src_node_kill[0], NULL, NULL, &res[0]))) { 622 errx(1, "getaddrinfo: %s", gai_strerror(ret_ga)); 623 /* NOTREACHED */ 624 } 625 for (resp[0] = res[0]; resp[0]; resp[0] = resp[0]->ai_next) { 626 if (resp[0]->ai_addr == NULL) 627 continue; 628 /* We get lots of duplicates. Catch the easy ones */ 629 if (memcmp(&last_src, resp[0]->ai_addr, sizeof(last_src)) == 0) 630 continue; 631 last_src = *(struct sockaddr *)resp[0]->ai_addr; 632 633 psnk.psnk_af = resp[0]->ai_family; 634 sources++; 635 636 if (psnk.psnk_af == AF_INET) 637 psnk.psnk_src.addr.v.a.addr.v4 = 638 ((struct sockaddr_in *)resp[0]->ai_addr)->sin_addr; 639 else if (psnk.psnk_af == AF_INET6) 640 psnk.psnk_src.addr.v.a.addr.v6 = 641 ((struct sockaddr_in6 *)resp[0]->ai_addr)-> 642 sin6_addr; 643 else 644 errx(1, "Unknown address family %d", psnk.psnk_af); 645 646 if (src_node_killers > 1) { 647 dests = 0; 648 memset(&psnk.psnk_dst.addr.v.a.mask, 0xff, 649 sizeof(psnk.psnk_dst.addr.v.a.mask)); 650 memset(&last_dst, 0xff, sizeof(last_dst)); 651 pfctl_addrprefix(src_node_kill[1], 652 &psnk.psnk_dst.addr.v.a.mask); 653 if ((ret_ga = getaddrinfo(src_node_kill[1], NULL, NULL, 654 &res[1]))) { 655 errx(1, "getaddrinfo: %s", 656 gai_strerror(ret_ga)); 657 /* NOTREACHED */ 658 } 659 for (resp[1] = res[1]; resp[1]; 660 resp[1] = resp[1]->ai_next) { 661 if (resp[1]->ai_addr == NULL) 662 continue; 663 if (psnk.psnk_af != resp[1]->ai_family) 664 continue; 665 666 if (memcmp(&last_dst, resp[1]->ai_addr, 667 sizeof(last_dst)) == 0) 668 continue; 669 last_dst = *(struct sockaddr *)resp[1]->ai_addr; 670 671 dests++; 672 673 if (psnk.psnk_af == AF_INET) 674 psnk.psnk_dst.addr.v.a.addr.v4 = 675 ((struct sockaddr_in *)resp[1]-> 676 ai_addr)->sin_addr; 677 else if (psnk.psnk_af == AF_INET6) 678 psnk.psnk_dst.addr.v.a.addr.v6 = 679 ((struct sockaddr_in6 *)resp[1]-> 680 ai_addr)->sin6_addr; 681 else 682 errx(1, "Unknown address family %d", 683 psnk.psnk_af); 684 685 if (ioctl(dev, DIOCKILLSRCNODES, &psnk)) 686 err(1, "DIOCKILLSRCNODES"); 687 killed += psnk.psnk_killed; 688 } 689 freeaddrinfo(res[1]); 690 } else { 691 if (ioctl(dev, DIOCKILLSRCNODES, &psnk)) 692 err(1, "DIOCKILLSRCNODES"); 693 killed += psnk.psnk_killed; 694 } 695 } 696 697 freeaddrinfo(res[0]); 698 699 if ((opts & PF_OPT_QUIET) == 0) 700 fprintf(stderr, "killed %d src nodes from %d sources and %d " 701 "destinations\n", killed, sources, dests); 702 return (0); 703 } 704 705 int 706 pfctl_net_kill_states(int dev, const char *iface, int opts) 707 { 708 struct pfctl_kill kill; 709 struct addrinfo *res[2], *resp[2]; 710 struct sockaddr last_src, last_dst; 711 unsigned int newkilled; 712 int killed, sources, dests; 713 int ret_ga, ret; 714 715 killed = sources = dests = 0; 716 717 memset(&kill, 0, sizeof(kill)); 718 memset(&kill.src.addr.v.a.mask, 0xff, 719 sizeof(kill.src.addr.v.a.mask)); 720 memset(&last_src, 0xff, sizeof(last_src)); 721 memset(&last_dst, 0xff, sizeof(last_dst)); 722 if (iface != NULL && strlcpy(kill.ifname, iface, 723 sizeof(kill.ifname)) >= sizeof(kill.ifname)) 724 errx(1, "invalid interface: %s", iface); 725 726 if (state_killers == 2 && (strcmp(state_kill[0], "nat") == 0)) { 727 kill.nat = true; 728 state_kill[0] = state_kill[1]; 729 state_killers = 1; 730 } 731 732 pfctl_addrprefix(state_kill[0], &kill.src.addr.v.a.mask); 733 734 if (opts & PF_OPT_KILLMATCH) 735 kill.kill_match = true; 736 737 if ((ret_ga = getaddrinfo(state_kill[0], NULL, NULL, &res[0]))) { 738 errx(1, "getaddrinfo: %s", gai_strerror(ret_ga)); 739 /* NOTREACHED */ 740 } 741 for (resp[0] = res[0]; resp[0]; resp[0] = resp[0]->ai_next) { 742 if (resp[0]->ai_addr == NULL) 743 continue; 744 /* We get lots of duplicates. Catch the easy ones */ 745 if (memcmp(&last_src, resp[0]->ai_addr, sizeof(last_src)) == 0) 746 continue; 747 last_src = *(struct sockaddr *)resp[0]->ai_addr; 748 749 kill.af = resp[0]->ai_family; 750 sources++; 751 752 if (kill.af == AF_INET) 753 kill.src.addr.v.a.addr.v4 = 754 ((struct sockaddr_in *)resp[0]->ai_addr)->sin_addr; 755 else if (kill.af == AF_INET6) 756 kill.src.addr.v.a.addr.v6 = 757 ((struct sockaddr_in6 *)resp[0]->ai_addr)-> 758 sin6_addr; 759 else 760 errx(1, "Unknown address family %d", kill.af); 761 762 if (state_killers > 1) { 763 dests = 0; 764 memset(&kill.dst.addr.v.a.mask, 0xff, 765 sizeof(kill.dst.addr.v.a.mask)); 766 memset(&last_dst, 0xff, sizeof(last_dst)); 767 pfctl_addrprefix(state_kill[1], 768 &kill.dst.addr.v.a.mask); 769 if ((ret_ga = getaddrinfo(state_kill[1], NULL, NULL, 770 &res[1]))) { 771 errx(1, "getaddrinfo: %s", 772 gai_strerror(ret_ga)); 773 /* NOTREACHED */ 774 } 775 for (resp[1] = res[1]; resp[1]; 776 resp[1] = resp[1]->ai_next) { 777 if (resp[1]->ai_addr == NULL) 778 continue; 779 if (kill.af != resp[1]->ai_family) 780 continue; 781 782 if (memcmp(&last_dst, resp[1]->ai_addr, 783 sizeof(last_dst)) == 0) 784 continue; 785 last_dst = *(struct sockaddr *)resp[1]->ai_addr; 786 787 dests++; 788 789 if (kill.af == AF_INET) 790 kill.dst.addr.v.a.addr.v4 = 791 ((struct sockaddr_in *)resp[1]-> 792 ai_addr)->sin_addr; 793 else if (kill.af == AF_INET6) 794 kill.dst.addr.v.a.addr.v6 = 795 ((struct sockaddr_in6 *)resp[1]-> 796 ai_addr)->sin6_addr; 797 else 798 errx(1, "Unknown address family %d", 799 kill.af); 800 801 if ((ret = pfctl_kill_states_h(pfh, &kill, &newkilled)) != 0) 802 errc(1, ret, "DIOCKILLSTATES"); 803 killed += newkilled; 804 } 805 freeaddrinfo(res[1]); 806 } else { 807 if ((ret = pfctl_kill_states_h(pfh, &kill, &newkilled)) != 0) 808 errc(1, ret, "DIOCKILLSTATES"); 809 killed += newkilled; 810 } 811 } 812 813 freeaddrinfo(res[0]); 814 815 if ((opts & PF_OPT_QUIET) == 0) 816 fprintf(stderr, "killed %d states from %d sources and %d " 817 "destinations\n", killed, sources, dests); 818 return (0); 819 } 820 821 int 822 pfctl_gateway_kill_states(int dev, const char *iface, int opts) 823 { 824 struct pfctl_kill kill; 825 struct addrinfo *res, *resp; 826 struct sockaddr last_src; 827 unsigned int newkilled; 828 int killed = 0; 829 int ret_ga; 830 831 if (state_killers != 2 || (strlen(state_kill[1]) == 0)) { 832 warnx("no gateway specified"); 833 usage(); 834 } 835 836 memset(&kill, 0, sizeof(kill)); 837 memset(&kill.rt_addr.addr.v.a.mask, 0xff, 838 sizeof(kill.rt_addr.addr.v.a.mask)); 839 memset(&last_src, 0xff, sizeof(last_src)); 840 if (iface != NULL && strlcpy(kill.ifname, iface, 841 sizeof(kill.ifname)) >= sizeof(kill.ifname)) 842 errx(1, "invalid interface: %s", iface); 843 844 if (opts & PF_OPT_KILLMATCH) 845 kill.kill_match = true; 846 847 pfctl_addrprefix(state_kill[1], &kill.rt_addr.addr.v.a.mask); 848 849 if ((ret_ga = getaddrinfo(state_kill[1], NULL, NULL, &res))) { 850 errx(1, "getaddrinfo: %s", gai_strerror(ret_ga)); 851 /* NOTREACHED */ 852 } 853 for (resp = res; resp; resp = resp->ai_next) { 854 if (resp->ai_addr == NULL) 855 continue; 856 /* We get lots of duplicates. Catch the easy ones */ 857 if (memcmp(&last_src, resp->ai_addr, sizeof(last_src)) == 0) 858 continue; 859 last_src = *(struct sockaddr *)resp->ai_addr; 860 861 kill.af = resp->ai_family; 862 863 if (kill.af == AF_INET) 864 kill.rt_addr.addr.v.a.addr.v4 = 865 ((struct sockaddr_in *)resp->ai_addr)->sin_addr; 866 else if (kill.af == AF_INET6) 867 kill.rt_addr.addr.v.a.addr.v6 = 868 ((struct sockaddr_in6 *)resp->ai_addr)-> 869 sin6_addr; 870 else 871 errx(1, "Unknown address family %d", kill.af); 872 873 if (pfctl_kill_states_h(pfh, &kill, &newkilled)) 874 err(1, "DIOCKILLSTATES"); 875 killed += newkilled; 876 } 877 878 freeaddrinfo(res); 879 880 if ((opts & PF_OPT_QUIET) == 0) 881 fprintf(stderr, "killed %d states\n", killed); 882 return (0); 883 } 884 885 int 886 pfctl_label_kill_states(int dev, const char *iface, int opts) 887 { 888 struct pfctl_kill kill; 889 unsigned int killed; 890 int ret; 891 892 if (state_killers != 2 || (strlen(state_kill[1]) == 0)) { 893 warnx("no label specified"); 894 usage(); 895 } 896 memset(&kill, 0, sizeof(kill)); 897 if (iface != NULL && strlcpy(kill.ifname, iface, 898 sizeof(kill.ifname)) >= sizeof(kill.ifname)) 899 errx(1, "invalid interface: %s", iface); 900 901 if (opts & PF_OPT_KILLMATCH) 902 kill.kill_match = true; 903 904 if (strlcpy(kill.label, state_kill[1], sizeof(kill.label)) >= 905 sizeof(kill.label)) 906 errx(1, "label too long: %s", state_kill[1]); 907 908 if ((ret = pfctl_kill_states_h(pfh, &kill, &killed)) != 0) 909 errc(1, ret, "DIOCKILLSTATES"); 910 911 if ((opts & PF_OPT_QUIET) == 0) 912 fprintf(stderr, "killed %d states\n", killed); 913 914 return (0); 915 } 916 917 int 918 pfctl_id_kill_states(int dev, const char *iface, int opts) 919 { 920 struct pfctl_kill kill; 921 unsigned int killed; 922 int ret; 923 924 if (state_killers != 2 || (strlen(state_kill[1]) == 0)) { 925 warnx("no id specified"); 926 usage(); 927 } 928 929 memset(&kill, 0, sizeof(kill)); 930 931 if (opts & PF_OPT_KILLMATCH) 932 kill.kill_match = true; 933 934 if ((sscanf(state_kill[1], "%jx/%x", 935 &kill.cmp.id, &kill.cmp.creatorid)) == 2) { 936 } 937 else if ((sscanf(state_kill[1], "%jx", &kill.cmp.id)) == 1) { 938 kill.cmp.creatorid = 0; 939 } else { 940 warnx("wrong id format specified"); 941 usage(); 942 } 943 if (kill.cmp.id == 0) { 944 warnx("cannot kill id 0"); 945 usage(); 946 } 947 948 if ((ret = pfctl_kill_states_h(pfh, &kill, &killed)) != 0) 949 errc(1, ret, "DIOCKILLSTATES"); 950 951 if ((opts & PF_OPT_QUIET) == 0) 952 fprintf(stderr, "killed %d states\n", killed); 953 954 return (0); 955 } 956 957 int 958 pfctl_get_pool(int dev, struct pfctl_pool *pool, u_int32_t nr, 959 u_int32_t ticket, int r_action, const char *anchorname, int which) 960 { 961 struct pfioc_pooladdr pp; 962 struct pf_pooladdr *pa; 963 u_int32_t pnr, mpnr; 964 int ret; 965 966 memset(&pp, 0, sizeof(pp)); 967 if ((ret = pfctl_get_addrs(pfh, ticket, nr, r_action, anchorname, &mpnr, which)) != 0) { 968 warnc(ret, "DIOCGETADDRS"); 969 return (-1); 970 } 971 972 TAILQ_INIT(&pool->list); 973 for (pnr = 0; pnr < mpnr; ++pnr) { 974 if ((ret = pfctl_get_addr(pfh, ticket, nr, r_action, anchorname, pnr, &pp, which)) != 0) { 975 warnc(ret, "DIOCGETADDR"); 976 return (-1); 977 } 978 pa = calloc(1, sizeof(struct pf_pooladdr)); 979 if (pa == NULL) 980 err(1, "calloc"); 981 bcopy(&pp.addr, pa, sizeof(struct pf_pooladdr)); 982 TAILQ_INSERT_TAIL(&pool->list, pa, entries); 983 } 984 985 return (0); 986 } 987 988 void 989 pfctl_move_pool(struct pfctl_pool *src, struct pfctl_pool *dst) 990 { 991 struct pf_pooladdr *pa; 992 993 while ((pa = TAILQ_FIRST(&src->list)) != NULL) { 994 TAILQ_REMOVE(&src->list, pa, entries); 995 TAILQ_INSERT_TAIL(&dst->list, pa, entries); 996 } 997 } 998 999 void 1000 pfctl_clear_pool(struct pfctl_pool *pool) 1001 { 1002 struct pf_pooladdr *pa; 1003 1004 while ((pa = TAILQ_FIRST(&pool->list)) != NULL) { 1005 TAILQ_REMOVE(&pool->list, pa, entries); 1006 free(pa); 1007 } 1008 } 1009 1010 void 1011 pfctl_print_eth_rule_counters(struct pfctl_eth_rule *rule, int opts) 1012 { 1013 if (opts & PF_OPT_VERBOSE) { 1014 printf(" [ Evaluations: %-8llu Packets: %-8llu " 1015 "Bytes: %-10llu]\n", 1016 (unsigned long long)rule->evaluations, 1017 (unsigned long long)(rule->packets[0] + 1018 rule->packets[1]), 1019 (unsigned long long)(rule->bytes[0] + 1020 rule->bytes[1])); 1021 } 1022 if (opts & PF_OPT_VERBOSE2) { 1023 char timestr[30]; 1024 1025 if (rule->last_active_timestamp != 0) { 1026 bcopy(ctime(&rule->last_active_timestamp), timestr, 1027 sizeof(timestr)); 1028 *strchr(timestr, '\n') = '\0'; 1029 } else { 1030 snprintf(timestr, sizeof(timestr), "N/A"); 1031 } 1032 printf(" [ Last Active Time: %s ]\n", timestr); 1033 } 1034 } 1035 1036 void 1037 pfctl_print_rule_counters(struct pfctl_rule *rule, int opts) 1038 { 1039 if (opts & PF_OPT_DEBUG) { 1040 const char *t[PF_SKIP_COUNT] = { "i", "d", "f", 1041 "p", "sa", "da", "sp", "dp" }; 1042 int i; 1043 1044 printf(" [ Skip steps: "); 1045 for (i = 0; i < PF_SKIP_COUNT; ++i) { 1046 if (rule->skip[i].nr == rule->nr + 1) 1047 continue; 1048 printf("%s=", t[i]); 1049 if (rule->skip[i].nr == -1) 1050 printf("end "); 1051 else 1052 printf("%u ", rule->skip[i].nr); 1053 } 1054 printf("]\n"); 1055 1056 printf(" [ queue: qname=%s qid=%u pqname=%s pqid=%u ]\n", 1057 rule->qname, rule->qid, rule->pqname, rule->pqid); 1058 } 1059 if (opts & PF_OPT_VERBOSE) { 1060 printf(" [ Evaluations: %-8llu Packets: %-8llu " 1061 "Bytes: %-10llu States: %-6ju]\n", 1062 (unsigned long long)rule->evaluations, 1063 (unsigned long long)(rule->packets[0] + 1064 rule->packets[1]), 1065 (unsigned long long)(rule->bytes[0] + 1066 rule->bytes[1]), (uintmax_t)rule->states_cur); 1067 printf(" [ Source Nodes: %-6ju " 1068 "Limit: %-6ju " 1069 "NAT/RDR: %-6ju " 1070 "Route: %-6ju " 1071 "]\n", 1072 (uintmax_t)rule->src_nodes, 1073 (uintmax_t)rule->src_nodes_type[PF_SN_LIMIT], 1074 (uintmax_t)rule->src_nodes_type[PF_SN_NAT], 1075 (uintmax_t)rule->src_nodes_type[PF_SN_ROUTE]); 1076 if (!(opts & PF_OPT_DEBUG)) 1077 printf(" [ Inserted: uid %u pid %u " 1078 "State Creations: %-6ju]\n", 1079 (unsigned)rule->cuid, (unsigned)rule->cpid, 1080 (uintmax_t)rule->states_tot); 1081 } 1082 if (opts & PF_OPT_VERBOSE2) { 1083 char timestr[30]; 1084 if (rule->last_active_timestamp != 0) { 1085 bcopy(ctime(&rule->last_active_timestamp), timestr, 1086 sizeof(timestr)); 1087 *strchr(timestr, '\n') = '\0'; 1088 } else { 1089 snprintf(timestr, sizeof(timestr), "N/A"); 1090 } 1091 printf(" [ Last Active Time: %s ]\n", timestr); 1092 } 1093 } 1094 1095 void 1096 pfctl_print_title(char *title) 1097 { 1098 if (!first_title) 1099 printf("\n"); 1100 first_title = 0; 1101 printf("%s\n", title); 1102 } 1103 1104 int 1105 pfctl_show_eth_rules(int dev, char *path, int opts, enum pfctl_show format, 1106 char *anchorname, int depth, int wildcard) 1107 { 1108 char anchor_call[MAXPATHLEN]; 1109 struct pfctl_eth_rules_info info; 1110 struct pfctl_eth_rule rule; 1111 int brace; 1112 int dotitle = opts & PF_OPT_SHOWALL; 1113 int len = strlen(path); 1114 int ret; 1115 char *npath, *p; 1116 1117 /* 1118 * Truncate a trailing / and * on an anchorname before searching for 1119 * the ruleset, this is syntactic sugar that doesn't actually make it 1120 * to the kernel. 1121 */ 1122 if ((p = strrchr(anchorname, '/')) != NULL && 1123 p[1] == '*' && p[2] == '\0') { 1124 p[0] = '\0'; 1125 } 1126 1127 if (anchorname[0] == '/') { 1128 if ((npath = calloc(1, MAXPATHLEN)) == NULL) 1129 errx(1, "pfctl_rules: calloc"); 1130 snprintf(npath, MAXPATHLEN, "%s", anchorname); 1131 } else { 1132 if (path[0]) 1133 snprintf(&path[len], MAXPATHLEN - len, "/%s", anchorname); 1134 else 1135 snprintf(&path[len], MAXPATHLEN - len, "%s", anchorname); 1136 npath = path; 1137 } 1138 1139 /* 1140 * If this anchor was called with a wildcard path, go through 1141 * the rulesets in the anchor rather than the rules. 1142 */ 1143 if (wildcard && (opts & PF_OPT_RECURSE)) { 1144 struct pfctl_eth_rulesets_info ri; 1145 u_int32_t mnr, nr; 1146 1147 if ((ret = pfctl_get_eth_rulesets_info(dev, &ri, npath)) != 0) { 1148 if (ret == EINVAL) { 1149 fprintf(stderr, "Anchor '%s' " 1150 "not found.\n", anchorname); 1151 } else { 1152 warnc(ret, "DIOCGETETHRULESETS"); 1153 return (-1); 1154 } 1155 } 1156 mnr = ri.nr; 1157 1158 pfctl_print_eth_rule_counters(&rule, opts); 1159 for (nr = 0; nr < mnr; ++nr) { 1160 struct pfctl_eth_ruleset_info rs; 1161 1162 if ((ret = pfctl_get_eth_ruleset(dev, npath, nr, &rs)) != 0) 1163 errc(1, ret, "DIOCGETETHRULESET"); 1164 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1165 printf("anchor \"%s\" all {\n", rs.name); 1166 pfctl_show_eth_rules(dev, npath, opts, 1167 format, rs.name, depth + 1, 0); 1168 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1169 printf("}\n"); 1170 } 1171 path[len] = '\0'; 1172 return (0); 1173 } 1174 1175 if ((ret = pfctl_get_eth_rules_info(dev, &info, path)) != 0) { 1176 warnc(ret, "DIOCGETETHRULES"); 1177 return (-1); 1178 } 1179 for (int nr = 0; nr < info.nr; nr++) { 1180 brace = 0; 1181 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1182 if ((ret = pfctl_get_eth_rule(dev, nr, info.ticket, path, &rule, 1183 opts & PF_OPT_CLRRULECTRS, anchor_call)) != 0) { 1184 warnc(ret, "DIOCGETETHRULE"); 1185 return (-1); 1186 } 1187 if (anchor_call[0] && 1188 ((((p = strrchr(anchor_call, '_')) != NULL) && 1189 (p == anchor_call || 1190 *(--p) == '/')) || (opts & PF_OPT_RECURSE))) { 1191 brace++; 1192 int aclen = strlen(anchor_call); 1193 if (anchor_call[aclen - 1] == '*') 1194 anchor_call[aclen - 2] = '\0'; 1195 } 1196 p = &anchor_call[0]; 1197 if (dotitle) { 1198 pfctl_print_title("ETH RULES:"); 1199 dotitle = 0; 1200 } 1201 print_eth_rule(&rule, anchor_call, 1202 opts & (PF_OPT_VERBOSE2 | PF_OPT_DEBUG)); 1203 if (brace) 1204 printf(" {\n"); 1205 else 1206 printf("\n"); 1207 pfctl_print_eth_rule_counters(&rule, opts); 1208 if (brace) { 1209 pfctl_show_eth_rules(dev, path, opts, format, 1210 p, depth + 1, rule.anchor_wildcard); 1211 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1212 printf("}\n"); 1213 } 1214 } 1215 1216 path[len] = '\0'; 1217 return (0); 1218 } 1219 1220 int 1221 pfctl_show_rules(int dev, char *path, int opts, enum pfctl_show format, 1222 char *anchorname, int depth, int wildcard) 1223 { 1224 struct pfctl_rules_info ri; 1225 struct pfctl_rule rule; 1226 char anchor_call[MAXPATHLEN]; 1227 u_int32_t nr, header = 0; 1228 int rule_numbers = opts & (PF_OPT_VERBOSE2 | PF_OPT_DEBUG); 1229 int numeric = opts & PF_OPT_NUMERIC; 1230 int len = strlen(path), ret = 0; 1231 char *npath, *p; 1232 1233 /* 1234 * Truncate a trailing / and * on an anchorname before searching for 1235 * the ruleset, this is syntactic sugar that doesn't actually make it 1236 * to the kernel. 1237 */ 1238 if ((p = strrchr(anchorname, '/')) != NULL && 1239 p[1] == '*' && p[2] == '\0') { 1240 p[0] = '\0'; 1241 } 1242 1243 if (anchorname[0] == '/') { 1244 if ((npath = calloc(1, MAXPATHLEN)) == NULL) 1245 errx(1, "pfctl_rules: calloc"); 1246 strlcpy(npath, anchorname, MAXPATHLEN); 1247 } else { 1248 if (path[0]) 1249 snprintf(&path[len], MAXPATHLEN - len, "/%s", anchorname); 1250 else 1251 snprintf(&path[len], MAXPATHLEN - len, "%s", anchorname); 1252 npath = path; 1253 } 1254 1255 /* 1256 * If this anchor was called with a wildcard path, go through 1257 * the rulesets in the anchor rather than the rules. 1258 */ 1259 if (wildcard && (opts & PF_OPT_RECURSE)) { 1260 struct pfioc_ruleset prs; 1261 u_int32_t mnr, nr; 1262 1263 memset(&prs, 0, sizeof(prs)); 1264 if ((ret = pfctl_get_rulesets(pfh, npath, &mnr)) != 0) { 1265 if (ret == EINVAL) 1266 fprintf(stderr, "Anchor '%s' " 1267 "not found.\n", anchorname); 1268 else 1269 errc(1, ret, "DIOCGETRULESETS"); 1270 } 1271 1272 pfctl_print_rule_counters(&rule, opts); 1273 for (nr = 0; nr < mnr; ++nr) { 1274 if ((ret = pfctl_get_ruleset(pfh, npath, nr, &prs)) != 0) 1275 errc(1, ret, "DIOCGETRULESET"); 1276 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1277 printf("anchor \"%s\" all {\n", prs.name); 1278 pfctl_show_rules(dev, npath, opts, 1279 format, prs.name, depth + 1, 0); 1280 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1281 printf("}\n"); 1282 } 1283 path[len] = '\0'; 1284 return (0); 1285 } 1286 1287 if (opts & PF_OPT_SHOWALL) { 1288 ret = pfctl_get_rules_info_h(pfh, &ri, PF_PASS, path); 1289 if (ret != 0) { 1290 warnc(ret, "DIOCGETRULES"); 1291 goto error; 1292 } 1293 header++; 1294 } 1295 ret = pfctl_get_rules_info_h(pfh, &ri, PF_SCRUB, path); 1296 if (ret != 0) { 1297 warnc(ret, "DIOCGETRULES"); 1298 goto error; 1299 } 1300 if (opts & PF_OPT_SHOWALL) { 1301 if (format == PFCTL_SHOW_RULES && (ri.nr > 0 || header)) 1302 pfctl_print_title("FILTER RULES:"); 1303 else if (format == PFCTL_SHOW_LABELS && labels) 1304 pfctl_print_title("LABEL COUNTERS:"); 1305 } 1306 1307 for (nr = 0; nr < ri.nr; ++nr) { 1308 if ((ret = pfctl_get_clear_rule_h(pfh, nr, ri.ticket, path, PF_SCRUB, 1309 &rule, anchor_call, opts & PF_OPT_CLRRULECTRS)) != 0) { 1310 warnc(ret, "DIOCGETRULENV"); 1311 goto error; 1312 } 1313 1314 if (pfctl_get_pool(dev, &rule.rdr, 1315 nr, ri.ticket, PF_SCRUB, path, PF_RDR) != 0) 1316 goto error; 1317 1318 if (pfctl_get_pool(dev, &rule.nat, 1319 nr, ri.ticket, PF_SCRUB, path, PF_NAT) != 0) 1320 goto error; 1321 1322 if (pfctl_get_pool(dev, &rule.route, 1323 nr, ri.ticket, PF_SCRUB, path, PF_RT) != 0) 1324 goto error; 1325 1326 switch (format) { 1327 case PFCTL_SHOW_LABELS: 1328 break; 1329 case PFCTL_SHOW_RULES: 1330 if (rule.label[0][0] && (opts & PF_OPT_SHOWALL)) 1331 labels = 1; 1332 print_rule(&rule, anchor_call, rule_numbers, numeric); 1333 printf("\n"); 1334 pfctl_print_rule_counters(&rule, opts); 1335 break; 1336 case PFCTL_SHOW_NOTHING: 1337 break; 1338 } 1339 pfctl_clear_pool(&rule.rdr); 1340 pfctl_clear_pool(&rule.nat); 1341 pfctl_clear_pool(&rule.route); 1342 } 1343 ret = pfctl_get_rules_info_h(pfh, &ri, PF_PASS, path); 1344 if (ret != 0) { 1345 warnc(ret, "DIOCGETRULES"); 1346 goto error; 1347 } 1348 for (nr = 0; nr < ri.nr; ++nr) { 1349 if ((ret = pfctl_get_clear_rule_h(pfh, nr, ri.ticket, path, PF_PASS, 1350 &rule, anchor_call, opts & PF_OPT_CLRRULECTRS)) != 0) { 1351 warnc(ret, "DIOCGETRULE"); 1352 goto error; 1353 } 1354 1355 if (pfctl_get_pool(dev, &rule.rdr, 1356 nr, ri.ticket, PF_PASS, path, PF_RDR) != 0) 1357 goto error; 1358 1359 if (pfctl_get_pool(dev, &rule.nat, 1360 nr, ri.ticket, PF_PASS, path, PF_NAT) != 0) 1361 goto error; 1362 1363 if (pfctl_get_pool(dev, &rule.route, 1364 nr, ri.ticket, PF_PASS, path, PF_RT) != 0) 1365 goto error; 1366 1367 switch (format) { 1368 case PFCTL_SHOW_LABELS: { 1369 bool show = false; 1370 int i = 0; 1371 1372 while (rule.label[i][0]) { 1373 printf("%s ", rule.label[i++]); 1374 show = true; 1375 } 1376 1377 if (show) { 1378 printf("%llu %llu %llu %llu" 1379 " %llu %llu %llu %ju\n", 1380 (unsigned long long)rule.evaluations, 1381 (unsigned long long)(rule.packets[0] + 1382 rule.packets[1]), 1383 (unsigned long long)(rule.bytes[0] + 1384 rule.bytes[1]), 1385 (unsigned long long)rule.packets[0], 1386 (unsigned long long)rule.bytes[0], 1387 (unsigned long long)rule.packets[1], 1388 (unsigned long long)rule.bytes[1], 1389 (uintmax_t)rule.states_tot); 1390 } 1391 1392 if (anchor_call[0] && 1393 (((p = strrchr(anchor_call, '/')) ? 1394 p[1] == '_' : anchor_call[0] == '_') || 1395 opts & PF_OPT_RECURSE)) { 1396 pfctl_show_rules(dev, npath, opts, format, 1397 anchor_call, depth, rule.anchor_wildcard); 1398 } 1399 break; 1400 } 1401 case PFCTL_SHOW_RULES: 1402 if (rule.label[0][0] && (opts & PF_OPT_SHOWALL)) 1403 labels = 1; 1404 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1405 print_rule(&rule, anchor_call, rule_numbers, numeric); 1406 1407 /* 1408 * If this is a 'unnamed' brace notation 1409 * anchor, OR the user has explicitly requested 1410 * recursion, print it recursively. 1411 */ 1412 if (anchor_call[0] && 1413 (((p = strrchr(anchor_call, '/')) ? 1414 p[1] == '_' : anchor_call[0] == '_') || 1415 opts & PF_OPT_RECURSE)) { 1416 printf(" {\n"); 1417 pfctl_print_rule_counters(&rule, opts); 1418 pfctl_show_rules(dev, npath, opts, format, 1419 anchor_call, depth + 1, 1420 rule.anchor_wildcard); 1421 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1422 printf("}\n"); 1423 } else { 1424 printf("\n"); 1425 pfctl_print_rule_counters(&rule, opts); 1426 } 1427 break; 1428 case PFCTL_SHOW_NOTHING: 1429 break; 1430 } 1431 pfctl_clear_pool(&rule.rdr); 1432 pfctl_clear_pool(&rule.nat); 1433 } 1434 1435 error: 1436 path[len] = '\0'; 1437 return (ret); 1438 } 1439 1440 int 1441 pfctl_show_nat(int dev, const char *path, int opts, char *anchorname, int depth, 1442 int wildcard) 1443 { 1444 struct pfctl_rules_info ri; 1445 struct pfctl_rule rule; 1446 char anchor_call[MAXPATHLEN]; 1447 u_int32_t nr; 1448 static int nattype[3] = { PF_NAT, PF_RDR, PF_BINAT }; 1449 int i, dotitle = opts & PF_OPT_SHOWALL; 1450 int ret; 1451 int len = strlen(path); 1452 char *npath, *p; 1453 1454 /* 1455 * Truncate a trailing / and * on an anchorname before searching for 1456 * the ruleset, this is syntactic sugar that doesn't actually make it 1457 * to the kernel. 1458 */ 1459 if ((p = strrchr(anchorname, '/')) != NULL && 1460 p[1] == '*' && p[2] == '\0') { 1461 p[0] = '\0'; 1462 } 1463 1464 if ((npath = calloc(1, MAXPATHLEN)) == NULL) 1465 errx(1, "pfctl_rules: calloc"); 1466 1467 if (anchorname[0] == '/') { 1468 snprintf(npath, MAXPATHLEN, "%s", anchorname); 1469 } else { 1470 snprintf(npath, MAXPATHLEN, "%s", path); 1471 if (npath[0]) 1472 snprintf(&npath[len], MAXPATHLEN - len, "/%s", anchorname); 1473 else 1474 snprintf(&npath[len], MAXPATHLEN - len, "%s", anchorname); 1475 } 1476 1477 /* 1478 * If this anchor was called with a wildcard path, go through 1479 * the rulesets in the anchor rather than the rules. 1480 */ 1481 if (wildcard && (opts & PF_OPT_RECURSE)) { 1482 struct pfioc_ruleset prs; 1483 u_int32_t mnr, nr; 1484 memset(&prs, 0, sizeof(prs)); 1485 if ((ret = pfctl_get_rulesets(pfh, npath, &mnr)) != 0) { 1486 if (ret == EINVAL) 1487 fprintf(stderr, "NAT anchor '%s' " 1488 "not found.\n", anchorname); 1489 else 1490 errc(1, ret, "DIOCGETRULESETS"); 1491 } 1492 1493 pfctl_print_rule_counters(&rule, opts); 1494 for (nr = 0; nr < mnr; ++nr) { 1495 if ((ret = pfctl_get_ruleset(pfh, npath, nr, &prs)) != 0) 1496 errc(1, ret, "DIOCGETRULESET"); 1497 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1498 printf("nat-anchor \"%s\" all {\n", prs.name); 1499 pfctl_show_nat(dev, npath, opts, 1500 prs.name, depth + 1, 0); 1501 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1502 printf("}\n"); 1503 } 1504 npath[len] = '\0'; 1505 return (0); 1506 } 1507 1508 for (i = 0; i < 3; i++) { 1509 ret = pfctl_get_rules_info_h(pfh, &ri, nattype[i], npath); 1510 if (ret != 0) { 1511 warnc(ret, "DIOCGETRULES"); 1512 return (-1); 1513 } 1514 for (nr = 0; nr < ri.nr; ++nr) { 1515 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1516 1517 if ((ret = pfctl_get_rule_h(pfh, nr, ri.ticket, npath, 1518 nattype[i], &rule, anchor_call)) != 0) { 1519 warnc(ret, "DIOCGETRULE"); 1520 return (-1); 1521 } 1522 if (pfctl_get_pool(dev, &rule.rdr, nr, 1523 ri.ticket, nattype[i], npath, PF_RDR) != 0) 1524 return (-1); 1525 if (pfctl_get_pool(dev, &rule.nat, nr, 1526 ri.ticket, nattype[i], npath, PF_NAT) != 0) 1527 return (-1); 1528 if (pfctl_get_pool(dev, &rule.route, nr, 1529 ri.ticket, nattype[i], npath, PF_RT) != 0) 1530 return (-1); 1531 1532 if (dotitle) { 1533 pfctl_print_title("TRANSLATION RULES:"); 1534 dotitle = 0; 1535 } 1536 print_rule(&rule, anchor_call, 1537 opts & PF_OPT_VERBOSE2, opts & PF_OPT_NUMERIC); 1538 if (anchor_call[0] && 1539 (((p = strrchr(anchor_call, '/')) ? 1540 p[1] == '_' : anchor_call[0] == '_') || 1541 opts & PF_OPT_RECURSE)) { 1542 printf(" {\n"); 1543 pfctl_print_rule_counters(&rule, opts); 1544 pfctl_show_nat(dev, npath, opts, anchor_call, 1545 depth + 1, rule.anchor_wildcard); 1546 INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1547 printf("}\n"); 1548 } else { 1549 printf("\n"); 1550 pfctl_print_rule_counters(&rule, opts); 1551 } 1552 } 1553 } 1554 return (0); 1555 } 1556 1557 static int 1558 pfctl_print_src_node(struct pfctl_src_node *sn, void *arg) 1559 { 1560 int *opts = (int *)arg; 1561 1562 if (*opts & PF_OPT_SHOWALL) { 1563 pfctl_print_title("SOURCE TRACKING NODES:"); 1564 *opts &= ~PF_OPT_SHOWALL; 1565 } 1566 1567 print_src_node(sn, *opts); 1568 1569 return (0); 1570 } 1571 1572 int 1573 pfctl_show_src_nodes(int dev, int opts) 1574 { 1575 int error; 1576 1577 error = pfctl_get_srcnodes(pfh, pfctl_print_src_node, &opts); 1578 1579 return (error); 1580 } 1581 1582 struct pfctl_show_state_arg { 1583 int opts; 1584 int dotitle; 1585 const char *iface; 1586 }; 1587 1588 static int 1589 pfctl_show_state(struct pfctl_state *s, void *arg) 1590 { 1591 struct pfctl_show_state_arg *a = (struct pfctl_show_state_arg *)arg; 1592 1593 if (a->dotitle) { 1594 pfctl_print_title("STATES:"); 1595 a->dotitle = 0; 1596 } 1597 print_state(s, a->opts); 1598 1599 return (0); 1600 } 1601 1602 int 1603 pfctl_show_states(int dev, const char *iface, int opts) 1604 { 1605 struct pfctl_show_state_arg arg; 1606 struct pfctl_state_filter filter = {}; 1607 1608 if (iface != NULL) 1609 strncpy(filter.ifname, iface, IFNAMSIZ); 1610 1611 arg.opts = opts; 1612 arg.dotitle = opts & PF_OPT_SHOWALL; 1613 arg.iface = iface; 1614 1615 if (pfctl_get_filtered_states_iter(&filter, pfctl_show_state, &arg)) 1616 return (-1); 1617 1618 return (0); 1619 } 1620 1621 int 1622 pfctl_show_status(int dev, int opts) 1623 { 1624 struct pfctl_status *status; 1625 struct pfctl_syncookies cookies; 1626 int ret; 1627 1628 if ((status = pfctl_get_status_h(pfh)) == NULL) { 1629 warn("DIOCGETSTATUS"); 1630 return (-1); 1631 } 1632 if ((ret = pfctl_get_syncookies(dev, &cookies)) != 0) { 1633 pfctl_free_status(status); 1634 warnc(ret, "DIOCGETSYNCOOKIES"); 1635 return (-1); 1636 } 1637 if (opts & PF_OPT_SHOWALL) 1638 pfctl_print_title("INFO:"); 1639 print_status(status, &cookies, opts); 1640 pfctl_free_status(status); 1641 return (0); 1642 } 1643 1644 int 1645 pfctl_show_running(int dev) 1646 { 1647 struct pfctl_status *status; 1648 int running; 1649 1650 if ((status = pfctl_get_status_h(pfh)) == NULL) { 1651 warn("DIOCGETSTATUS"); 1652 return (-1); 1653 } 1654 1655 running = status->running; 1656 1657 print_running(status); 1658 pfctl_free_status(status); 1659 return (!running); 1660 } 1661 1662 int 1663 pfctl_show_timeouts(int dev, int opts) 1664 { 1665 uint32_t seconds; 1666 int i; 1667 int ret; 1668 1669 if (opts & PF_OPT_SHOWALL) 1670 pfctl_print_title("TIMEOUTS:"); 1671 for (i = 0; pf_timeouts[i].name; i++) { 1672 if ((ret = pfctl_get_timeout(pfh, pf_timeouts[i].timeout, &seconds)) != 0) 1673 errc(1, ret, "DIOCGETTIMEOUT"); 1674 printf("%-20s %10d", pf_timeouts[i].name, seconds); 1675 if (pf_timeouts[i].timeout >= PFTM_ADAPTIVE_START && 1676 pf_timeouts[i].timeout <= PFTM_ADAPTIVE_END) 1677 printf(" states"); 1678 else 1679 printf("s"); 1680 printf("\n"); 1681 } 1682 return (0); 1683 1684 } 1685 1686 int 1687 pfctl_show_limits(int dev, int opts) 1688 { 1689 unsigned int limit; 1690 int i; 1691 int ret; 1692 1693 if (opts & PF_OPT_SHOWALL) 1694 pfctl_print_title("LIMITS:"); 1695 for (i = 0; pf_limits[i].name; i++) { 1696 if ((ret = pfctl_get_limit(pfh, pf_limits[i].index, &limit)) != 0) 1697 errc(1, ret, "DIOCGETLIMIT"); 1698 printf("%-13s ", pf_limits[i].name); 1699 if (limit == UINT_MAX) 1700 printf("unlimited\n"); 1701 else 1702 printf("hard limit %8u\n", limit); 1703 } 1704 return (0); 1705 } 1706 1707 void 1708 pfctl_show_creators(int opts) 1709 { 1710 int ret; 1711 uint32_t creators[16]; 1712 size_t count = nitems(creators); 1713 1714 ret = pfctl_get_creatorids(pfh, creators, &count); 1715 if (ret != 0) 1716 errx(ret, "Failed to retrieve creators"); 1717 1718 printf("Creator IDs:\n"); 1719 for (size_t i = 0; i < count; i++) 1720 printf("%08x\n", creators[i]); 1721 } 1722 1723 /* callbacks for rule/nat/rdr/addr */ 1724 int 1725 pfctl_add_pool(struct pfctl *pf, struct pfctl_pool *p, sa_family_t af, int which) 1726 { 1727 struct pf_pooladdr *pa; 1728 int ret; 1729 1730 pf->paddr.af = af; 1731 TAILQ_FOREACH(pa, &p->list, entries) { 1732 memcpy(&pf->paddr.addr, pa, sizeof(struct pf_pooladdr)); 1733 if ((pf->opts & PF_OPT_NOACTION) == 0) { 1734 if ((ret = pfctl_add_addr(pf->h, &pf->paddr, which)) != 0) 1735 errc(1, ret, "DIOCADDADDR"); 1736 } 1737 } 1738 return (0); 1739 } 1740 1741 void 1742 pfctl_init_rule(struct pfctl_rule *r) 1743 { 1744 1745 memset(r, 0, sizeof(struct pfctl_rule)); 1746 TAILQ_INIT(&(r->rdr.list)); 1747 TAILQ_INIT(&(r->nat.list)); 1748 TAILQ_INIT(&(r->route.list)); 1749 } 1750 1751 int 1752 pfctl_append_rule(struct pfctl *pf, struct pfctl_rule *r, 1753 const char *anchor_call) 1754 { 1755 u_int8_t rs_num; 1756 struct pfctl_rule *rule; 1757 struct pfctl_ruleset *rs; 1758 char *p; 1759 1760 rs_num = pf_get_ruleset_number(r->action); 1761 if (rs_num == PF_RULESET_MAX) 1762 errx(1, "Invalid rule type %d", r->action); 1763 1764 rs = &pf->anchor->ruleset; 1765 1766 if (anchor_call[0] && r->anchor == NULL) { 1767 /* 1768 * Don't make non-brace anchors part of the main anchor pool. 1769 */ 1770 if ((r->anchor = calloc(1, sizeof(*r->anchor))) == NULL) 1771 err(1, "pfctl_append_rule: calloc"); 1772 1773 pf_init_ruleset(&r->anchor->ruleset); 1774 r->anchor->ruleset.anchor = r->anchor; 1775 if (strlcpy(r->anchor->path, anchor_call, 1776 sizeof(rule->anchor->path)) >= sizeof(rule->anchor->path)) 1777 errx(1, "pfctl_append_rule: strlcpy"); 1778 if ((p = strrchr(anchor_call, '/')) != NULL) { 1779 if (!strlen(p)) 1780 err(1, "pfctl_append_rule: bad anchor name %s", 1781 anchor_call); 1782 } else 1783 p = (char *)anchor_call; 1784 if (strlcpy(r->anchor->name, p, 1785 sizeof(rule->anchor->name)) >= sizeof(rule->anchor->name)) 1786 errx(1, "pfctl_append_rule: strlcpy"); 1787 } 1788 1789 if ((rule = calloc(1, sizeof(*rule))) == NULL) 1790 err(1, "calloc"); 1791 bcopy(r, rule, sizeof(*rule)); 1792 TAILQ_INIT(&rule->rdr.list); 1793 pfctl_move_pool(&r->rdr, &rule->rdr); 1794 TAILQ_INIT(&rule->nat.list); 1795 pfctl_move_pool(&r->nat, &rule->nat); 1796 TAILQ_INIT(&rule->route.list); 1797 pfctl_move_pool(&r->route, &rule->route); 1798 1799 TAILQ_INSERT_TAIL(rs->rules[rs_num].active.ptr, rule, entries); 1800 return (0); 1801 } 1802 1803 int 1804 pfctl_append_eth_rule(struct pfctl *pf, struct pfctl_eth_rule *r, 1805 const char *anchor_call) 1806 { 1807 struct pfctl_eth_rule *rule; 1808 struct pfctl_eth_ruleset *rs; 1809 char *p; 1810 1811 rs = &pf->eanchor->ruleset; 1812 1813 if (anchor_call[0] && r->anchor == NULL) { 1814 /* 1815 * Don't make non-brace anchors part of the main anchor pool. 1816 */ 1817 if ((r->anchor = calloc(1, sizeof(*r->anchor))) == NULL) 1818 err(1, "pfctl_append_rule: calloc"); 1819 1820 pf_init_eth_ruleset(&r->anchor->ruleset); 1821 r->anchor->ruleset.anchor = r->anchor; 1822 if (strlcpy(r->anchor->path, anchor_call, 1823 sizeof(rule->anchor->path)) >= sizeof(rule->anchor->path)) 1824 errx(1, "pfctl_append_rule: strlcpy"); 1825 if ((p = strrchr(anchor_call, '/')) != NULL) { 1826 if (!strlen(p)) 1827 err(1, "pfctl_append_eth_rule: bad anchor name %s", 1828 anchor_call); 1829 } else 1830 p = (char *)anchor_call; 1831 if (strlcpy(r->anchor->name, p, 1832 sizeof(rule->anchor->name)) >= sizeof(rule->anchor->name)) 1833 errx(1, "pfctl_append_eth_rule: strlcpy"); 1834 } 1835 1836 if ((rule = calloc(1, sizeof(*rule))) == NULL) 1837 err(1, "calloc"); 1838 bcopy(r, rule, sizeof(*rule)); 1839 1840 TAILQ_INSERT_TAIL(&rs->rules, rule, entries); 1841 return (0); 1842 } 1843 1844 int 1845 pfctl_eth_ruleset_trans(struct pfctl *pf, char *path, 1846 struct pfctl_eth_anchor *a) 1847 { 1848 int osize = pf->trans->pfrb_size; 1849 1850 if ((pf->loadopt & PFCTL_FLAG_ETH) != 0) { 1851 if (pfctl_add_trans(pf->trans, PF_RULESET_ETH, path)) 1852 return (1); 1853 } 1854 if (pfctl_trans(pf->dev, pf->trans, DIOCXBEGIN, osize)) 1855 return (5); 1856 1857 return (0); 1858 } 1859 1860 int 1861 pfctl_ruleset_trans(struct pfctl *pf, char *path, struct pfctl_anchor *a, bool do_eth) 1862 { 1863 int osize = pf->trans->pfrb_size; 1864 1865 if ((pf->loadopt & PFCTL_FLAG_ETH) != 0 && do_eth) { 1866 if (pfctl_add_trans(pf->trans, PF_RULESET_ETH, path)) 1867 return (1); 1868 } 1869 if ((pf->loadopt & PFCTL_FLAG_NAT) != 0) { 1870 if (pfctl_add_trans(pf->trans, PF_RULESET_NAT, path) || 1871 pfctl_add_trans(pf->trans, PF_RULESET_BINAT, path) || 1872 pfctl_add_trans(pf->trans, PF_RULESET_RDR, path)) 1873 return (1); 1874 } 1875 if (a == pf->astack[0] && ((altqsupport && 1876 (pf->loadopt & PFCTL_FLAG_ALTQ) != 0))) { 1877 if (pfctl_add_trans(pf->trans, PF_RULESET_ALTQ, path)) 1878 return (2); 1879 } 1880 if ((pf->loadopt & PFCTL_FLAG_FILTER) != 0) { 1881 if (pfctl_add_trans(pf->trans, PF_RULESET_SCRUB, path) || 1882 pfctl_add_trans(pf->trans, PF_RULESET_FILTER, path)) 1883 return (3); 1884 } 1885 if (pf->loadopt & PFCTL_FLAG_TABLE) 1886 if (pfctl_add_trans(pf->trans, PF_RULESET_TABLE, path)) 1887 return (4); 1888 if (pfctl_trans(pf->dev, pf->trans, DIOCXBEGIN, osize)) 1889 return (5); 1890 1891 return (0); 1892 } 1893 1894 int 1895 pfctl_load_eth_ruleset(struct pfctl *pf, char *path, 1896 struct pfctl_eth_ruleset *rs, int depth) 1897 { 1898 struct pfctl_eth_rule *r; 1899 int error, len = strlen(path); 1900 int brace = 0; 1901 1902 pf->eanchor = rs->anchor; 1903 if (path[0]) 1904 snprintf(&path[len], MAXPATHLEN - len, "/%s", pf->eanchor->name); 1905 else 1906 snprintf(&path[len], MAXPATHLEN - len, "%s", pf->eanchor->name); 1907 1908 if (depth) { 1909 if (TAILQ_FIRST(&rs->rules) != NULL) { 1910 brace++; 1911 if (pf->opts & PF_OPT_VERBOSE) 1912 printf(" {\n"); 1913 if ((pf->opts & PF_OPT_NOACTION) == 0 && 1914 (error = pfctl_eth_ruleset_trans(pf, 1915 path, rs->anchor))) { 1916 printf("pfctl_load_eth_rulesets: " 1917 "pfctl_eth_ruleset_trans %d\n", error); 1918 goto error; 1919 } 1920 } else if (pf->opts & PF_OPT_VERBOSE) 1921 printf("\n"); 1922 } 1923 1924 while ((r = TAILQ_FIRST(&rs->rules)) != NULL) { 1925 TAILQ_REMOVE(&rs->rules, r, entries); 1926 1927 error = pfctl_load_eth_rule(pf, path, r, depth); 1928 if (error) 1929 return (error); 1930 1931 if (r->anchor) { 1932 if ((error = pfctl_load_eth_ruleset(pf, path, 1933 &r->anchor->ruleset, depth + 1))) 1934 return (error); 1935 } else if (pf->opts & PF_OPT_VERBOSE) 1936 printf("\n"); 1937 free(r); 1938 } 1939 if (brace && pf->opts & PF_OPT_VERBOSE) { 1940 INDENT(depth - 1, (pf->opts & PF_OPT_VERBOSE)); 1941 printf("}\n"); 1942 } 1943 path[len] = '\0'; 1944 1945 return (0); 1946 error: 1947 path[len] = '\0'; 1948 return (error); 1949 } 1950 1951 int 1952 pfctl_load_eth_rule(struct pfctl *pf, char *path, struct pfctl_eth_rule *r, 1953 int depth) 1954 { 1955 char *name; 1956 char anchor[PF_ANCHOR_NAME_SIZE]; 1957 int len = strlen(path); 1958 int ret; 1959 1960 if (strlcpy(anchor, path, sizeof(anchor)) >= sizeof(anchor)) 1961 errx(1, "pfctl_load_eth_rule: strlcpy"); 1962 1963 if (r->anchor) { 1964 if (r->anchor->match) { 1965 if (path[0]) 1966 snprintf(&path[len], MAXPATHLEN - len, 1967 "/%s", r->anchor->name); 1968 else 1969 snprintf(&path[len], MAXPATHLEN - len, 1970 "%s", r->anchor->name); 1971 name = r->anchor->name; 1972 } else 1973 name = r->anchor->path; 1974 } else 1975 name = ""; 1976 1977 if ((pf->opts & PF_OPT_NOACTION) == 0) 1978 if ((ret = pfctl_add_eth_rule(pf->dev, r, anchor, name, 1979 pf->eth_ticket)) != 0) 1980 errc(1, ret, "DIOCADDETHRULENV"); 1981 1982 if (pf->opts & PF_OPT_VERBOSE) { 1983 INDENT(depth, !(pf->opts & PF_OPT_VERBOSE2)); 1984 print_eth_rule(r, r->anchor ? r->anchor->name : "", 1985 pf->opts & (PF_OPT_VERBOSE2 | PF_OPT_DEBUG)); 1986 } 1987 1988 path[len] = '\0'; 1989 1990 return (0); 1991 } 1992 1993 int 1994 pfctl_load_ruleset(struct pfctl *pf, char *path, struct pfctl_ruleset *rs, 1995 int rs_num, int depth) 1996 { 1997 struct pfctl_rule *r; 1998 int error, len = strlen(path); 1999 int brace = 0; 2000 2001 pf->anchor = rs->anchor; 2002 2003 if (path[0]) 2004 snprintf(&path[len], MAXPATHLEN - len, "/%s", pf->anchor->name); 2005 else 2006 snprintf(&path[len], MAXPATHLEN - len, "%s", pf->anchor->name); 2007 2008 if (depth) { 2009 if (TAILQ_FIRST(rs->rules[rs_num].active.ptr) != NULL) { 2010 brace++; 2011 if (pf->opts & PF_OPT_VERBOSE) 2012 printf(" {\n"); 2013 if ((pf->opts & PF_OPT_NOACTION) == 0 && 2014 (error = pfctl_ruleset_trans(pf, 2015 path, rs->anchor, false))) { 2016 printf("pfctl_load_rulesets: " 2017 "pfctl_ruleset_trans %d\n", error); 2018 goto error; 2019 } 2020 } else if (pf->opts & PF_OPT_VERBOSE) 2021 printf("\n"); 2022 2023 } 2024 2025 if (pf->optimize && rs_num == PF_RULESET_FILTER) 2026 pfctl_optimize_ruleset(pf, rs); 2027 2028 while ((r = TAILQ_FIRST(rs->rules[rs_num].active.ptr)) != NULL) { 2029 TAILQ_REMOVE(rs->rules[rs_num].active.ptr, r, entries); 2030 2031 for (int i = 0; i < PF_RULE_MAX_LABEL_COUNT; i++) 2032 expand_label(r->label[i], PF_RULE_LABEL_SIZE, r); 2033 expand_label(r->tagname, PF_TAG_NAME_SIZE, r); 2034 expand_label(r->match_tagname, PF_TAG_NAME_SIZE, r); 2035 2036 if ((error = pfctl_load_rule(pf, path, r, depth))) 2037 goto error; 2038 if (r->anchor) { 2039 if ((error = pfctl_load_ruleset(pf, path, 2040 &r->anchor->ruleset, rs_num, depth + 1))) 2041 goto error; 2042 } else if (pf->opts & PF_OPT_VERBOSE) 2043 printf("\n"); 2044 free(r); 2045 } 2046 if (brace && pf->opts & PF_OPT_VERBOSE) { 2047 INDENT(depth - 1, (pf->opts & PF_OPT_VERBOSE)); 2048 printf("}\n"); 2049 } 2050 path[len] = '\0'; 2051 return (0); 2052 2053 error: 2054 path[len] = '\0'; 2055 return (error); 2056 2057 } 2058 2059 int 2060 pfctl_load_rule(struct pfctl *pf, char *path, struct pfctl_rule *r, int depth) 2061 { 2062 u_int8_t rs_num = pf_get_ruleset_number(r->action); 2063 char *name; 2064 u_int32_t ticket; 2065 char anchor[PF_ANCHOR_NAME_SIZE]; 2066 int len = strlen(path); 2067 int error; 2068 bool was_present; 2069 2070 /* set up anchor before adding to path for anchor_call */ 2071 if ((pf->opts & PF_OPT_NOACTION) == 0) 2072 ticket = pfctl_get_ticket(pf->trans, rs_num, path); 2073 if (strlcpy(anchor, path, sizeof(anchor)) >= sizeof(anchor)) 2074 errx(1, "pfctl_load_rule: strlcpy"); 2075 2076 if (r->anchor) { 2077 if (r->anchor->match) { 2078 if (path[0]) 2079 snprintf(&path[len], MAXPATHLEN - len, 2080 "/%s", r->anchor->name); 2081 else 2082 snprintf(&path[len], MAXPATHLEN - len, 2083 "%s", r->anchor->name); 2084 name = r->anchor->name; 2085 } else 2086 name = r->anchor->path; 2087 } else 2088 name = ""; 2089 2090 was_present = false; 2091 if ((pf->opts & PF_OPT_NOACTION) == 0) { 2092 if ((pf->opts & PF_OPT_NOACTION) == 0) { 2093 if ((error = pfctl_begin_addrs(pf->h, 2094 &pf->paddr.ticket)) != 0) 2095 errc(1, error, "DIOCBEGINADDRS"); 2096 } 2097 2098 if (pfctl_add_pool(pf, &r->rdr, r->af, PF_RDR)) 2099 return (1); 2100 if (pfctl_add_pool(pf, &r->nat, r->naf ? r->naf : r->af, PF_NAT)) 2101 return (1); 2102 if (pfctl_add_pool(pf, &r->route, r->af, PF_RT)) 2103 return (1); 2104 error = pfctl_add_rule_h(pf->h, r, anchor, name, ticket, 2105 pf->paddr.ticket); 2106 switch (error) { 2107 case 0: 2108 /* things worked, do nothing */ 2109 break; 2110 case EEXIST: 2111 /* an identical rule is already present */ 2112 was_present = true; 2113 break; 2114 default: 2115 errc(1, error, "DIOCADDRULE"); 2116 } 2117 } 2118 2119 if (pf->opts & PF_OPT_VERBOSE) { 2120 INDENT(depth, !(pf->opts & PF_OPT_VERBOSE2)); 2121 print_rule(r, name, 2122 pf->opts & PF_OPT_VERBOSE2, 2123 pf->opts & PF_OPT_NUMERIC); 2124 if (was_present) 2125 printf(" -- rule was already present"); 2126 } 2127 path[len] = '\0'; 2128 pfctl_clear_pool(&r->rdr); 2129 pfctl_clear_pool(&r->nat); 2130 return (0); 2131 } 2132 2133 int 2134 pfctl_add_altq(struct pfctl *pf, struct pf_altq *a) 2135 { 2136 if (altqsupport && 2137 (loadopt & PFCTL_FLAG_ALTQ) != 0) { 2138 memcpy(&pf->paltq->altq, a, sizeof(struct pf_altq)); 2139 if ((pf->opts & PF_OPT_NOACTION) == 0) { 2140 if (ioctl(pf->dev, DIOCADDALTQ, pf->paltq)) { 2141 if (errno == ENXIO) 2142 errx(1, "qtype not configured"); 2143 else if (errno == ENODEV) 2144 errx(1, "%s: driver does not support " 2145 "altq", a->ifname); 2146 else 2147 err(1, "DIOCADDALTQ"); 2148 } 2149 } 2150 pfaltq_store(&pf->paltq->altq); 2151 } 2152 return (0); 2153 } 2154 2155 int 2156 pfctl_rules(int dev, char *filename, int opts, int optimize, 2157 char *anchorname, struct pfr_buffer *trans) 2158 { 2159 #define ERR(x) do { warn(x); goto _error; } while(0) 2160 #define ERRX(x) do { warnx(x); goto _error; } while(0) 2161 2162 struct pfr_buffer *t, buf; 2163 struct pfioc_altq pa; 2164 struct pfctl pf; 2165 struct pfctl_ruleset *rs; 2166 struct pfctl_eth_ruleset *ethrs; 2167 struct pfr_table trs; 2168 char *path; 2169 int osize; 2170 2171 RB_INIT(&pf_anchors); 2172 memset(&pf_main_anchor, 0, sizeof(pf_main_anchor)); 2173 pf_init_ruleset(&pf_main_anchor.ruleset); 2174 pf_main_anchor.ruleset.anchor = &pf_main_anchor; 2175 2176 memset(&pf_eth_main_anchor, 0, sizeof(pf_eth_main_anchor)); 2177 pf_init_eth_ruleset(&pf_eth_main_anchor.ruleset); 2178 pf_eth_main_anchor.ruleset.anchor = &pf_eth_main_anchor; 2179 2180 if (trans == NULL) { 2181 bzero(&buf, sizeof(buf)); 2182 buf.pfrb_type = PFRB_TRANS; 2183 t = &buf; 2184 osize = 0; 2185 } else { 2186 t = trans; 2187 osize = t->pfrb_size; 2188 } 2189 2190 memset(&pa, 0, sizeof(pa)); 2191 pa.version = PFIOC_ALTQ_VERSION; 2192 memset(&pf, 0, sizeof(pf)); 2193 memset(&trs, 0, sizeof(trs)); 2194 if ((path = calloc(1, MAXPATHLEN)) == NULL) 2195 ERRX("pfctl_rules: calloc"); 2196 if (strlcpy(trs.pfrt_anchor, anchorname, 2197 sizeof(trs.pfrt_anchor)) >= sizeof(trs.pfrt_anchor)) 2198 ERRX("pfctl_rules: strlcpy"); 2199 pf.dev = dev; 2200 pf.h = pfh; 2201 pf.opts = opts; 2202 pf.optimize = optimize; 2203 pf.loadopt = loadopt; 2204 2205 /* non-brace anchor, create without resolving the path */ 2206 if ((pf.anchor = calloc(1, sizeof(*pf.anchor))) == NULL) 2207 ERRX("pfctl_rules: calloc"); 2208 rs = &pf.anchor->ruleset; 2209 pf_init_ruleset(rs); 2210 rs->anchor = pf.anchor; 2211 if (strlcpy(pf.anchor->path, anchorname, 2212 sizeof(pf.anchor->path)) >= sizeof(pf.anchor->path)) 2213 errx(1, "pfctl_rules: strlcpy"); 2214 if (strlcpy(pf.anchor->name, anchorname, 2215 sizeof(pf.anchor->name)) >= sizeof(pf.anchor->name)) 2216 errx(1, "pfctl_rules: strlcpy"); 2217 2218 2219 pf.astack[0] = pf.anchor; 2220 pf.asd = 0; 2221 if (anchorname[0]) 2222 pf.loadopt &= ~PFCTL_FLAG_ALTQ; 2223 pf.paltq = &pa; 2224 pf.trans = t; 2225 pfctl_init_options(&pf); 2226 2227 /* Set up ethernet anchor */ 2228 if ((pf.eanchor = calloc(1, sizeof(*pf.eanchor))) == NULL) 2229 ERRX("pfctl_rules: calloc"); 2230 2231 if (strlcpy(pf.eanchor->path, anchorname, 2232 sizeof(pf.eanchor->path)) >= sizeof(pf.eanchor->path)) 2233 errx(1, "pfctl_rules: strlcpy"); 2234 if (strlcpy(pf.eanchor->name, anchorname, 2235 sizeof(pf.eanchor->name)) >= sizeof(pf.eanchor->name)) 2236 errx(1, "pfctl_rules: strlcpy"); 2237 2238 ethrs = &pf.eanchor->ruleset; 2239 pf_init_eth_ruleset(ethrs); 2240 ethrs->anchor = pf.eanchor; 2241 pf.eastack[0] = pf.eanchor; 2242 2243 if ((opts & PF_OPT_NOACTION) == 0) { 2244 /* 2245 * XXX For the time being we need to open transactions for 2246 * the main ruleset before parsing, because tables are still 2247 * loaded at parse time. 2248 */ 2249 if (pfctl_ruleset_trans(&pf, anchorname, pf.anchor, true)) 2250 ERRX("pfctl_rules"); 2251 if (pf.loadopt & PFCTL_FLAG_ETH) 2252 pf.eth_ticket = pfctl_get_ticket(t, PF_RULESET_ETH, anchorname); 2253 if (altqsupport && (pf.loadopt & PFCTL_FLAG_ALTQ)) 2254 pa.ticket = 2255 pfctl_get_ticket(t, PF_RULESET_ALTQ, anchorname); 2256 if (pf.loadopt & PFCTL_FLAG_TABLE) 2257 pf.astack[0]->ruleset.tticket = 2258 pfctl_get_ticket(t, PF_RULESET_TABLE, anchorname); 2259 } 2260 2261 if (parse_config(filename, &pf) < 0) { 2262 if ((opts & PF_OPT_NOACTION) == 0) 2263 ERRX("Syntax error in config file: " 2264 "pf rules not loaded"); 2265 else 2266 goto _error; 2267 } 2268 if (loadopt & PFCTL_FLAG_OPTION) 2269 pfctl_adjust_skip_ifaces(&pf); 2270 2271 if ((pf.loadopt & PFCTL_FLAG_FILTER && 2272 (pfctl_load_ruleset(&pf, path, rs, PF_RULESET_SCRUB, 0))) || 2273 (pf.loadopt & PFCTL_FLAG_ETH && 2274 (pfctl_load_eth_ruleset(&pf, path, ethrs, 0))) || 2275 (pf.loadopt & PFCTL_FLAG_NAT && 2276 (pfctl_load_ruleset(&pf, path, rs, PF_RULESET_NAT, 0) || 2277 pfctl_load_ruleset(&pf, path, rs, PF_RULESET_RDR, 0) || 2278 pfctl_load_ruleset(&pf, path, rs, PF_RULESET_BINAT, 0))) || 2279 (pf.loadopt & PFCTL_FLAG_FILTER && 2280 pfctl_load_ruleset(&pf, path, rs, PF_RULESET_FILTER, 0))) { 2281 if ((opts & PF_OPT_NOACTION) == 0) 2282 ERRX("Unable to load rules into kernel"); 2283 else 2284 goto _error; 2285 } 2286 2287 if ((altqsupport && (pf.loadopt & PFCTL_FLAG_ALTQ) != 0)) 2288 if (check_commit_altq(dev, opts) != 0) 2289 ERRX("errors in altq config"); 2290 2291 /* process "load anchor" directives */ 2292 if (!anchorname[0]) 2293 if (pfctl_load_anchors(dev, &pf, t) == -1) 2294 ERRX("load anchors"); 2295 2296 if (trans == NULL && (opts & PF_OPT_NOACTION) == 0) { 2297 if (!anchorname[0]) 2298 if (pfctl_load_options(&pf)) 2299 goto _error; 2300 if (pfctl_trans(dev, t, DIOCXCOMMIT, osize)) 2301 ERR("DIOCXCOMMIT"); 2302 } 2303 free(path); 2304 return (0); 2305 2306 _error: 2307 if (trans == NULL) { /* main ruleset */ 2308 if ((opts & PF_OPT_NOACTION) == 0) 2309 if (pfctl_trans(dev, t, DIOCXROLLBACK, osize)) 2310 err(1, "DIOCXROLLBACK"); 2311 exit(1); 2312 } else { /* sub ruleset */ 2313 free(path); 2314 return (-1); 2315 } 2316 2317 #undef ERR 2318 #undef ERRX 2319 } 2320 2321 FILE * 2322 pfctl_fopen(const char *name, const char *mode) 2323 { 2324 struct stat st; 2325 FILE *fp; 2326 2327 fp = fopen(name, mode); 2328 if (fp == NULL) 2329 return (NULL); 2330 if (fstat(fileno(fp), &st)) { 2331 fclose(fp); 2332 return (NULL); 2333 } 2334 if (S_ISDIR(st.st_mode)) { 2335 fclose(fp); 2336 errno = EISDIR; 2337 return (NULL); 2338 } 2339 return (fp); 2340 } 2341 2342 void 2343 pfctl_init_options(struct pfctl *pf) 2344 { 2345 2346 pf->timeout[PFTM_TCP_FIRST_PACKET] = PFTM_TCP_FIRST_PACKET_VAL; 2347 pf->timeout[PFTM_TCP_OPENING] = PFTM_TCP_OPENING_VAL; 2348 pf->timeout[PFTM_TCP_ESTABLISHED] = PFTM_TCP_ESTABLISHED_VAL; 2349 pf->timeout[PFTM_TCP_CLOSING] = PFTM_TCP_CLOSING_VAL; 2350 pf->timeout[PFTM_TCP_FIN_WAIT] = PFTM_TCP_FIN_WAIT_VAL; 2351 pf->timeout[PFTM_TCP_CLOSED] = PFTM_TCP_CLOSED_VAL; 2352 pf->timeout[PFTM_SCTP_FIRST_PACKET] = PFTM_TCP_FIRST_PACKET_VAL; 2353 pf->timeout[PFTM_SCTP_OPENING] = PFTM_TCP_OPENING_VAL; 2354 pf->timeout[PFTM_SCTP_ESTABLISHED] = PFTM_TCP_ESTABLISHED_VAL; 2355 pf->timeout[PFTM_SCTP_CLOSING] = PFTM_TCP_CLOSING_VAL; 2356 pf->timeout[PFTM_SCTP_CLOSED] = PFTM_TCP_CLOSED_VAL; 2357 pf->timeout[PFTM_UDP_FIRST_PACKET] = PFTM_UDP_FIRST_PACKET_VAL; 2358 pf->timeout[PFTM_UDP_SINGLE] = PFTM_UDP_SINGLE_VAL; 2359 pf->timeout[PFTM_UDP_MULTIPLE] = PFTM_UDP_MULTIPLE_VAL; 2360 pf->timeout[PFTM_ICMP_FIRST_PACKET] = PFTM_ICMP_FIRST_PACKET_VAL; 2361 pf->timeout[PFTM_ICMP_ERROR_REPLY] = PFTM_ICMP_ERROR_REPLY_VAL; 2362 pf->timeout[PFTM_OTHER_FIRST_PACKET] = PFTM_OTHER_FIRST_PACKET_VAL; 2363 pf->timeout[PFTM_OTHER_SINGLE] = PFTM_OTHER_SINGLE_VAL; 2364 pf->timeout[PFTM_OTHER_MULTIPLE] = PFTM_OTHER_MULTIPLE_VAL; 2365 pf->timeout[PFTM_FRAG] = PFTM_FRAG_VAL; 2366 pf->timeout[PFTM_INTERVAL] = PFTM_INTERVAL_VAL; 2367 pf->timeout[PFTM_SRC_NODE] = PFTM_SRC_NODE_VAL; 2368 pf->timeout[PFTM_TS_DIFF] = PFTM_TS_DIFF_VAL; 2369 pf->timeout[PFTM_ADAPTIVE_START] = PFSTATE_ADAPT_START; 2370 pf->timeout[PFTM_ADAPTIVE_END] = PFSTATE_ADAPT_END; 2371 2372 pf->limit[PF_LIMIT_STATES] = PFSTATE_HIWAT; 2373 pf->limit[PF_LIMIT_FRAGS] = PFFRAG_FRENT_HIWAT; 2374 pf->limit[PF_LIMIT_SRC_NODES] = PFSNODE_HIWAT; 2375 pf->limit[PF_LIMIT_TABLE_ENTRIES] = PFR_KENTRY_HIWAT; 2376 2377 pf->debug = PF_DEBUG_URGENT; 2378 pf->reassemble = 0; 2379 2380 pf->syncookies = false; 2381 pf->syncookieswat[0] = PF_SYNCOOKIES_LOWATPCT; 2382 pf->syncookieswat[1] = PF_SYNCOOKIES_HIWATPCT; 2383 } 2384 2385 int 2386 pfctl_load_options(struct pfctl *pf) 2387 { 2388 int i, error = 0; 2389 2390 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2391 return (0); 2392 2393 /* load limits */ 2394 for (i = 0; i < PF_LIMIT_MAX; i++) { 2395 if ((pf->opts & PF_OPT_MERGE) && !pf->limit_set[i]) 2396 continue; 2397 if (pfctl_load_limit(pf, i, pf->limit[i])) 2398 error = 1; 2399 } 2400 2401 /* 2402 * If we've set the limit, but haven't explicitly set adaptive 2403 * timeouts, do it now with a start of 60% and end of 120%. 2404 */ 2405 if (pf->limit_set[PF_LIMIT_STATES] && 2406 !pf->timeout_set[PFTM_ADAPTIVE_START] && 2407 !pf->timeout_set[PFTM_ADAPTIVE_END]) { 2408 pf->timeout[PFTM_ADAPTIVE_START] = 2409 (pf->limit[PF_LIMIT_STATES] / 10) * 6; 2410 pf->timeout_set[PFTM_ADAPTIVE_START] = 1; 2411 pf->timeout[PFTM_ADAPTIVE_END] = 2412 (pf->limit[PF_LIMIT_STATES] / 10) * 12; 2413 pf->timeout_set[PFTM_ADAPTIVE_END] = 1; 2414 } 2415 2416 /* load timeouts */ 2417 for (i = 0; i < PFTM_MAX; i++) { 2418 if ((pf->opts & PF_OPT_MERGE) && !pf->timeout_set[i]) 2419 continue; 2420 if (pfctl_load_timeout(pf, i, pf->timeout[i])) 2421 error = 1; 2422 } 2423 2424 /* load debug */ 2425 if (!(pf->opts & PF_OPT_MERGE) || pf->debug_set) 2426 if (pfctl_load_debug(pf, pf->debug)) 2427 error = 1; 2428 2429 /* load logif */ 2430 if (!(pf->opts & PF_OPT_MERGE) || pf->ifname_set) 2431 if (pfctl_load_logif(pf, pf->ifname)) 2432 error = 1; 2433 2434 /* load hostid */ 2435 if (!(pf->opts & PF_OPT_MERGE) || pf->hostid_set) 2436 if (pfctl_load_hostid(pf, pf->hostid)) 2437 error = 1; 2438 2439 /* load reassembly settings */ 2440 if (!(pf->opts & PF_OPT_MERGE) || pf->reass_set) 2441 if (pfctl_load_reassembly(pf, pf->reassemble)) 2442 error = 1; 2443 2444 /* load keepcounters */ 2445 if (pfctl_set_keepcounters(pf->dev, pf->keep_counters)) 2446 error = 1; 2447 2448 /* load syncookies settings */ 2449 if (pfctl_load_syncookies(pf, pf->syncookies)) 2450 error = 1; 2451 2452 return (error); 2453 } 2454 2455 int 2456 pfctl_apply_limit(struct pfctl *pf, const char *opt, unsigned int limit) 2457 { 2458 int i; 2459 2460 2461 for (i = 0; pf_limits[i].name; i++) { 2462 if (strcasecmp(opt, pf_limits[i].name) == 0) { 2463 pf->limit[pf_limits[i].index] = limit; 2464 pf->limit_set[pf_limits[i].index] = 1; 2465 break; 2466 } 2467 } 2468 if (pf_limits[i].name == NULL) { 2469 warnx("Bad pool name."); 2470 return (1); 2471 } 2472 2473 if (pf->opts & PF_OPT_VERBOSE) 2474 printf("set limit %s %d\n", opt, limit); 2475 2476 return (0); 2477 } 2478 2479 int 2480 pfctl_load_limit(struct pfctl *pf, unsigned int index, unsigned int limit) 2481 { 2482 if (pfctl_set_limit(pf->h, index, limit)) { 2483 if (errno == EBUSY) 2484 warnx("Current pool size exceeds requested %s limit %u", 2485 pf_limits[index].name, limit); 2486 else 2487 warnx("Cannot set %s limit to %u", 2488 pf_limits[index].name, limit); 2489 return (1); 2490 } 2491 return (0); 2492 } 2493 2494 int 2495 pfctl_apply_timeout(struct pfctl *pf, const char *opt, int seconds, int quiet) 2496 { 2497 int i; 2498 2499 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2500 return (0); 2501 2502 for (i = 0; pf_timeouts[i].name; i++) { 2503 if (strcasecmp(opt, pf_timeouts[i].name) == 0) { 2504 pf->timeout[pf_timeouts[i].timeout] = seconds; 2505 pf->timeout_set[pf_timeouts[i].timeout] = 1; 2506 break; 2507 } 2508 } 2509 2510 if (pf_timeouts[i].name == NULL) { 2511 warnx("Bad timeout name."); 2512 return (1); 2513 } 2514 2515 2516 if (pf->opts & PF_OPT_VERBOSE && ! quiet) 2517 printf("set timeout %s %d\n", opt, seconds); 2518 2519 return (0); 2520 } 2521 2522 int 2523 pfctl_load_timeout(struct pfctl *pf, unsigned int timeout, unsigned int seconds) 2524 { 2525 if (pfctl_set_timeout(pf->h, timeout, seconds)) { 2526 warnx("DIOCSETTIMEOUT"); 2527 return (1); 2528 } 2529 return (0); 2530 } 2531 2532 int 2533 pfctl_set_reassembly(struct pfctl *pf, int on, int nodf) 2534 { 2535 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2536 return (0); 2537 2538 pf->reass_set = 1; 2539 if (on) { 2540 pf->reassemble = PF_REASS_ENABLED; 2541 if (nodf) 2542 pf->reassemble |= PF_REASS_NODF; 2543 } else { 2544 pf->reassemble = 0; 2545 } 2546 2547 if (pf->opts & PF_OPT_VERBOSE) 2548 printf("set reassemble %s %s\n", on ? "yes" : "no", 2549 nodf ? "no-df" : ""); 2550 2551 return (0); 2552 } 2553 2554 int 2555 pfctl_set_optimization(struct pfctl *pf, const char *opt) 2556 { 2557 const struct pf_hint *hint; 2558 int i, r; 2559 2560 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2561 return (0); 2562 2563 for (i = 0; pf_hints[i].name; i++) 2564 if (strcasecmp(opt, pf_hints[i].name) == 0) 2565 break; 2566 2567 hint = pf_hints[i].hint; 2568 if (hint == NULL) { 2569 warnx("invalid state timeouts optimization"); 2570 return (1); 2571 } 2572 2573 for (i = 0; hint[i].name; i++) 2574 if ((r = pfctl_apply_timeout(pf, hint[i].name, 2575 hint[i].timeout, 1))) 2576 return (r); 2577 2578 if (pf->opts & PF_OPT_VERBOSE) 2579 printf("set optimization %s\n", opt); 2580 2581 return (0); 2582 } 2583 2584 int 2585 pfctl_set_logif(struct pfctl *pf, char *ifname) 2586 { 2587 2588 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2589 return (0); 2590 2591 if (!strcmp(ifname, "none")) { 2592 free(pf->ifname); 2593 pf->ifname = NULL; 2594 } else { 2595 pf->ifname = strdup(ifname); 2596 if (!pf->ifname) 2597 errx(1, "pfctl_set_logif: strdup"); 2598 } 2599 pf->ifname_set = 1; 2600 2601 if (pf->opts & PF_OPT_VERBOSE) 2602 printf("set loginterface %s\n", ifname); 2603 2604 return (0); 2605 } 2606 2607 int 2608 pfctl_load_logif(struct pfctl *pf, char *ifname) 2609 { 2610 if (ifname != NULL && strlen(ifname) >= IFNAMSIZ) { 2611 warnx("pfctl_load_logif: strlcpy"); 2612 return (1); 2613 } 2614 return (pfctl_set_statusif(pfh, ifname ? ifname : "")); 2615 } 2616 2617 void 2618 pfctl_set_hostid(struct pfctl *pf, u_int32_t hostid) 2619 { 2620 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2621 return; 2622 2623 HTONL(hostid); 2624 2625 pf->hostid = hostid; 2626 pf->hostid_set = 1; 2627 2628 if (pf->opts & PF_OPT_VERBOSE) 2629 printf("set hostid 0x%08x\n", ntohl(hostid)); 2630 } 2631 2632 int 2633 pfctl_load_hostid(struct pfctl *pf, u_int32_t hostid) 2634 { 2635 if (ioctl(dev, DIOCSETHOSTID, &hostid)) { 2636 warnx("DIOCSETHOSTID"); 2637 return (1); 2638 } 2639 return (0); 2640 } 2641 2642 int 2643 pfctl_load_reassembly(struct pfctl *pf, u_int32_t reassembly) 2644 { 2645 if (ioctl(dev, DIOCSETREASS, &reassembly)) { 2646 warnx("DIOCSETREASS"); 2647 return (1); 2648 } 2649 return (0); 2650 } 2651 2652 int 2653 pfctl_load_syncookies(struct pfctl *pf, u_int8_t val) 2654 { 2655 struct pfctl_syncookies cookies; 2656 2657 bzero(&cookies, sizeof(cookies)); 2658 2659 cookies.mode = val; 2660 cookies.lowwater = pf->syncookieswat[0]; 2661 cookies.highwater = pf->syncookieswat[1]; 2662 2663 if (pfctl_set_syncookies(dev, &cookies)) { 2664 warnx("DIOCSETSYNCOOKIES"); 2665 return (1); 2666 } 2667 return (0); 2668 } 2669 2670 int 2671 pfctl_cfg_syncookies(struct pfctl *pf, uint8_t val, struct pfctl_watermarks *w) 2672 { 2673 if (val != PF_SYNCOOKIES_ADAPTIVE && w != NULL) { 2674 warnx("syncookies start/end only apply to adaptive"); 2675 return (1); 2676 } 2677 if (val == PF_SYNCOOKIES_ADAPTIVE && w != NULL) { 2678 if (!w->hi) 2679 w->hi = PF_SYNCOOKIES_HIWATPCT; 2680 if (!w->lo) 2681 w->lo = w->hi / 2; 2682 if (w->lo >= w->hi) { 2683 warnx("start must be higher than end"); 2684 return (1); 2685 } 2686 pf->syncookieswat[0] = w->lo; 2687 pf->syncookieswat[1] = w->hi; 2688 pf->syncookieswat_set = 1; 2689 } 2690 2691 if (pf->opts & PF_OPT_VERBOSE) { 2692 if (val == PF_SYNCOOKIES_NEVER) 2693 printf("set syncookies never\n"); 2694 else if (val == PF_SYNCOOKIES_ALWAYS) 2695 printf("set syncookies always\n"); 2696 else if (val == PF_SYNCOOKIES_ADAPTIVE) { 2697 if (pf->syncookieswat_set) 2698 printf("set syncookies adaptive (start %u%%, " 2699 "end %u%%)\n", pf->syncookieswat[1], 2700 pf->syncookieswat[0]); 2701 else 2702 printf("set syncookies adaptive\n"); 2703 } else { /* cannot happen */ 2704 warnx("king bula ate all syncookies"); 2705 return (1); 2706 } 2707 } 2708 2709 pf->syncookies = val; 2710 return (0); 2711 } 2712 2713 int 2714 pfctl_do_set_debug(struct pfctl *pf, char *d) 2715 { 2716 u_int32_t level; 2717 int ret; 2718 2719 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2720 return (0); 2721 2722 if (!strcmp(d, "none")) 2723 pf->debug = PF_DEBUG_NONE; 2724 else if (!strcmp(d, "urgent")) 2725 pf->debug = PF_DEBUG_URGENT; 2726 else if (!strcmp(d, "misc")) 2727 pf->debug = PF_DEBUG_MISC; 2728 else if (!strcmp(d, "loud")) 2729 pf->debug = PF_DEBUG_NOISY; 2730 else { 2731 warnx("unknown debug level \"%s\"", d); 2732 return (-1); 2733 } 2734 2735 pf->debug_set = 1; 2736 level = pf->debug; 2737 2738 if ((pf->opts & PF_OPT_NOACTION) == 0) 2739 if ((ret = pfctl_set_debug(pfh, level)) != 0) 2740 errc(1, ret, "DIOCSETDEBUG"); 2741 2742 if (pf->opts & PF_OPT_VERBOSE) 2743 printf("set debug %s\n", d); 2744 2745 return (0); 2746 } 2747 2748 int 2749 pfctl_load_debug(struct pfctl *pf, unsigned int level) 2750 { 2751 if (pfctl_set_debug(pf->h, level)) { 2752 warnx("DIOCSETDEBUG"); 2753 return (1); 2754 } 2755 return (0); 2756 } 2757 2758 int 2759 pfctl_set_interface_flags(struct pfctl *pf, char *ifname, int flags, int how) 2760 { 2761 struct pfioc_iface pi; 2762 struct node_host *h = NULL, *n = NULL; 2763 2764 if ((loadopt & PFCTL_FLAG_OPTION) == 0) 2765 return (0); 2766 2767 bzero(&pi, sizeof(pi)); 2768 2769 pi.pfiio_flags = flags; 2770 2771 /* Make sure our cache matches the kernel. If we set or clear the flag 2772 * for a group this applies to all members. */ 2773 h = ifa_grouplookup(ifname, 0); 2774 for (n = h; n != NULL; n = n->next) 2775 pfctl_set_interface_flags(pf, n->ifname, flags, how); 2776 2777 if (strlcpy(pi.pfiio_name, ifname, sizeof(pi.pfiio_name)) >= 2778 sizeof(pi.pfiio_name)) 2779 errx(1, "pfctl_set_interface_flags: strlcpy"); 2780 2781 if ((pf->opts & PF_OPT_NOACTION) == 0) { 2782 if (how == 0) { 2783 if (ioctl(pf->dev, DIOCCLRIFFLAG, &pi)) 2784 err(1, "DIOCCLRIFFLAG"); 2785 } else { 2786 if (ioctl(pf->dev, DIOCSETIFFLAG, &pi)) 2787 err(1, "DIOCSETIFFLAG"); 2788 pfctl_check_skip_ifaces(ifname); 2789 } 2790 } 2791 return (0); 2792 } 2793 2794 void 2795 pfctl_debug(int dev, u_int32_t level, int opts) 2796 { 2797 int ret; 2798 2799 if ((ret = pfctl_set_debug(pfh, level)) != 0) 2800 errc(1, ret, "DIOCSETDEBUG"); 2801 if ((opts & PF_OPT_QUIET) == 0) { 2802 fprintf(stderr, "debug level set to '"); 2803 switch (level) { 2804 case PF_DEBUG_NONE: 2805 fprintf(stderr, "none"); 2806 break; 2807 case PF_DEBUG_URGENT: 2808 fprintf(stderr, "urgent"); 2809 break; 2810 case PF_DEBUG_MISC: 2811 fprintf(stderr, "misc"); 2812 break; 2813 case PF_DEBUG_NOISY: 2814 fprintf(stderr, "loud"); 2815 break; 2816 default: 2817 fprintf(stderr, "<invalid>"); 2818 break; 2819 } 2820 fprintf(stderr, "'\n"); 2821 } 2822 } 2823 2824 int 2825 pfctl_test_altqsupport(int dev, int opts) 2826 { 2827 struct pfioc_altq pa; 2828 2829 pa.version = PFIOC_ALTQ_VERSION; 2830 if (ioctl(dev, DIOCGETALTQS, &pa)) { 2831 if (errno == ENODEV) { 2832 if (opts & PF_OPT_VERBOSE) 2833 fprintf(stderr, "No ALTQ support in kernel\n" 2834 "ALTQ related functions disabled\n"); 2835 return (0); 2836 } else 2837 err(1, "DIOCGETALTQS"); 2838 } 2839 return (1); 2840 } 2841 2842 int 2843 pfctl_show_anchors(int dev, int opts, char *anchorname) 2844 { 2845 struct pfioc_ruleset pr; 2846 u_int32_t mnr, nr; 2847 int ret; 2848 2849 memset(&pr, 0, sizeof(pr)); 2850 if ((ret = pfctl_get_rulesets(pfh, anchorname, &mnr)) != 0) { 2851 if (ret == EINVAL) 2852 fprintf(stderr, "Anchor '%s' not found.\n", 2853 anchorname); 2854 else 2855 errc(1, ret, "DIOCGETRULESETS"); 2856 return (-1); 2857 } 2858 for (nr = 0; nr < mnr; ++nr) { 2859 char sub[MAXPATHLEN]; 2860 2861 if ((ret = pfctl_get_ruleset(pfh, anchorname, nr, &pr)) != 0) 2862 errc(1, ret, "DIOCGETRULESET"); 2863 if (!strcmp(pr.name, PF_RESERVED_ANCHOR)) 2864 continue; 2865 sub[0] = 0; 2866 if (pr.path[0]) { 2867 strlcat(sub, pr.path, sizeof(sub)); 2868 strlcat(sub, "/", sizeof(sub)); 2869 } 2870 strlcat(sub, pr.name, sizeof(sub)); 2871 if (sub[0] != '_' || (opts & PF_OPT_VERBOSE)) 2872 printf(" %s\n", sub); 2873 if ((opts & PF_OPT_VERBOSE) && pfctl_show_anchors(dev, opts, sub)) 2874 return (-1); 2875 } 2876 return (0); 2877 } 2878 2879 int 2880 pfctl_show_eth_anchors(int dev, int opts, char *anchorname) 2881 { 2882 struct pfctl_eth_rulesets_info ri; 2883 struct pfctl_eth_ruleset_info rs; 2884 int ret; 2885 2886 if ((ret = pfctl_get_eth_rulesets_info(dev, &ri, anchorname)) != 0) { 2887 if (ret == ENOENT) 2888 fprintf(stderr, "Anchor '%s' not found.\n", 2889 anchorname); 2890 else 2891 errc(1, ret, "DIOCGETETHRULESETS"); 2892 return (-1); 2893 } 2894 2895 for (int nr = 0; nr < ri.nr; nr++) { 2896 char sub[MAXPATHLEN]; 2897 2898 if ((ret = pfctl_get_eth_ruleset(dev, anchorname, nr, &rs)) != 0) 2899 errc(1, ret, "DIOCGETETHRULESET"); 2900 2901 if (!strcmp(rs.name, PF_RESERVED_ANCHOR)) 2902 continue; 2903 sub[0] = 0; 2904 if (rs.path[0]) { 2905 strlcat(sub, rs.path, sizeof(sub)); 2906 strlcat(sub, "/", sizeof(sub)); 2907 } 2908 strlcat(sub, rs.name, sizeof(sub)); 2909 if (sub[0] != '_' || (opts & PF_OPT_VERBOSE)) 2910 printf(" %s\n", sub); 2911 if ((opts & PF_OPT_VERBOSE) && pfctl_show_eth_anchors(dev, opts, sub)) 2912 return (-1); 2913 } 2914 return (0); 2915 } 2916 2917 const char * 2918 pfctl_lookup_option(char *cmd, const char * const *list) 2919 { 2920 if (cmd != NULL && *cmd) 2921 for (; *list; list++) 2922 if (!strncmp(cmd, *list, strlen(cmd))) 2923 return (*list); 2924 return (NULL); 2925 } 2926 2927 int 2928 main(int argc, char *argv[]) 2929 { 2930 int error = 0; 2931 int ch; 2932 int mode = O_RDONLY; 2933 int opts = 0; 2934 int optimize = PF_OPTIMIZE_BASIC; 2935 char anchorname[MAXPATHLEN]; 2936 char *path; 2937 2938 if (argc < 2) 2939 usage(); 2940 2941 while ((ch = getopt(argc, argv, 2942 "a:AdD:eqf:F:ghi:k:K:mMnNOo:Pp:rRs:t:T:vx:z")) != -1) { 2943 switch (ch) { 2944 case 'a': 2945 anchoropt = optarg; 2946 break; 2947 case 'd': 2948 opts |= PF_OPT_DISABLE; 2949 mode = O_RDWR; 2950 break; 2951 case 'D': 2952 if (pfctl_cmdline_symset(optarg) < 0) 2953 warnx("could not parse macro definition %s", 2954 optarg); 2955 break; 2956 case 'e': 2957 opts |= PF_OPT_ENABLE; 2958 mode = O_RDWR; 2959 break; 2960 case 'q': 2961 opts |= PF_OPT_QUIET; 2962 break; 2963 case 'F': 2964 clearopt = pfctl_lookup_option(optarg, clearopt_list); 2965 if (clearopt == NULL) { 2966 warnx("Unknown flush modifier '%s'", optarg); 2967 usage(); 2968 } 2969 mode = O_RDWR; 2970 break; 2971 case 'i': 2972 ifaceopt = optarg; 2973 break; 2974 case 'k': 2975 if (state_killers >= 2) { 2976 warnx("can only specify -k twice"); 2977 usage(); 2978 /* NOTREACHED */ 2979 } 2980 state_kill[state_killers++] = optarg; 2981 mode = O_RDWR; 2982 break; 2983 case 'K': 2984 if (src_node_killers >= 2) { 2985 warnx("can only specify -K twice"); 2986 usage(); 2987 /* NOTREACHED */ 2988 } 2989 src_node_kill[src_node_killers++] = optarg; 2990 mode = O_RDWR; 2991 break; 2992 case 'm': 2993 opts |= PF_OPT_MERGE; 2994 break; 2995 case 'M': 2996 opts |= PF_OPT_KILLMATCH; 2997 break; 2998 case 'n': 2999 opts |= PF_OPT_NOACTION; 3000 break; 3001 case 'N': 3002 loadopt |= PFCTL_FLAG_NAT; 3003 break; 3004 case 'r': 3005 opts |= PF_OPT_USEDNS; 3006 break; 3007 case 'f': 3008 rulesopt = optarg; 3009 mode = O_RDWR; 3010 break; 3011 case 'g': 3012 opts |= PF_OPT_DEBUG; 3013 break; 3014 case 'A': 3015 loadopt |= PFCTL_FLAG_ALTQ; 3016 break; 3017 case 'R': 3018 loadopt |= PFCTL_FLAG_FILTER; 3019 break; 3020 case 'o': 3021 optiopt = pfctl_lookup_option(optarg, optiopt_list); 3022 if (optiopt == NULL) { 3023 warnx("Unknown optimization '%s'", optarg); 3024 usage(); 3025 } 3026 opts |= PF_OPT_OPTIMIZE; 3027 break; 3028 case 'O': 3029 loadopt |= PFCTL_FLAG_OPTION; 3030 break; 3031 case 'p': 3032 pf_device = optarg; 3033 break; 3034 case 'P': 3035 opts |= PF_OPT_NUMERIC; 3036 break; 3037 case 's': 3038 showopt = pfctl_lookup_option(optarg, showopt_list); 3039 if (showopt == NULL) { 3040 warnx("Unknown show modifier '%s'", optarg); 3041 usage(); 3042 } 3043 break; 3044 case 't': 3045 tableopt = optarg; 3046 break; 3047 case 'T': 3048 tblcmdopt = pfctl_lookup_option(optarg, tblcmdopt_list); 3049 if (tblcmdopt == NULL) { 3050 warnx("Unknown table command '%s'", optarg); 3051 usage(); 3052 } 3053 break; 3054 case 'v': 3055 if (opts & PF_OPT_VERBOSE) 3056 opts |= PF_OPT_VERBOSE2; 3057 opts |= PF_OPT_VERBOSE; 3058 break; 3059 case 'x': 3060 debugopt = pfctl_lookup_option(optarg, debugopt_list); 3061 if (debugopt == NULL) { 3062 warnx("Unknown debug level '%s'", optarg); 3063 usage(); 3064 } 3065 mode = O_RDWR; 3066 break; 3067 case 'z': 3068 opts |= PF_OPT_CLRRULECTRS; 3069 mode = O_RDWR; 3070 break; 3071 case 'h': 3072 /* FALLTHROUGH */ 3073 default: 3074 usage(); 3075 /* NOTREACHED */ 3076 } 3077 } 3078 3079 if (tblcmdopt != NULL) { 3080 argc -= optind; 3081 argv += optind; 3082 ch = *tblcmdopt; 3083 if (ch == 'l') { 3084 loadopt |= PFCTL_FLAG_TABLE; 3085 tblcmdopt = NULL; 3086 } else 3087 mode = strchr("acdefkrz", ch) ? O_RDWR : O_RDONLY; 3088 } else if (argc != optind) { 3089 warnx("unknown command line argument: %s ...", argv[optind]); 3090 usage(); 3091 /* NOTREACHED */ 3092 } 3093 if (loadopt == 0) 3094 loadopt = ~0; 3095 3096 if ((path = calloc(1, MAXPATHLEN)) == NULL) 3097 errx(1, "pfctl: calloc"); 3098 memset(anchorname, 0, sizeof(anchorname)); 3099 if (anchoropt != NULL) { 3100 int len = strlen(anchoropt); 3101 3102 if (len >= 1 && anchoropt[len - 1] == '*') { 3103 if (len >= 2 && anchoropt[len - 2] == '/') 3104 anchoropt[len - 2] = '\0'; 3105 else 3106 anchoropt[len - 1] = '\0'; 3107 opts |= PF_OPT_RECURSE; 3108 } 3109 if (strlcpy(anchorname, anchoropt, 3110 sizeof(anchorname)) >= sizeof(anchorname)) 3111 errx(1, "anchor name '%s' too long", 3112 anchoropt); 3113 loadopt &= PFCTL_FLAG_FILTER|PFCTL_FLAG_NAT|PFCTL_FLAG_TABLE|PFCTL_FLAG_ETH; 3114 } 3115 3116 if ((opts & PF_OPT_NOACTION) == 0) { 3117 dev = open(pf_device, mode); 3118 if (dev == -1) 3119 err(1, "%s", pf_device); 3120 altqsupport = pfctl_test_altqsupport(dev, opts); 3121 } else { 3122 dev = open(pf_device, O_RDONLY); 3123 if (dev >= 0) 3124 opts |= PF_OPT_DUMMYACTION; 3125 /* turn off options */ 3126 opts &= ~ (PF_OPT_DISABLE | PF_OPT_ENABLE); 3127 clearopt = showopt = debugopt = NULL; 3128 #if !defined(ENABLE_ALTQ) 3129 altqsupport = 0; 3130 #else 3131 altqsupport = 1; 3132 #endif 3133 } 3134 pfh = pfctl_open(pf_device); 3135 if (pfh == NULL) 3136 err(1, "Failed to open netlink"); 3137 3138 if (opts & PF_OPT_DISABLE) 3139 if (pfctl_disable(dev, opts)) 3140 error = 1; 3141 3142 if (showopt != NULL) { 3143 switch (*showopt) { 3144 case 'A': 3145 pfctl_show_anchors(dev, opts, anchorname); 3146 if (opts & PF_OPT_VERBOSE2) 3147 printf("Ethernet:\n"); 3148 pfctl_show_eth_anchors(dev, opts, anchorname); 3149 break; 3150 case 'r': 3151 pfctl_load_fingerprints(dev, opts); 3152 pfctl_show_rules(dev, path, opts, PFCTL_SHOW_RULES, 3153 anchorname, 0, 0); 3154 break; 3155 case 'l': 3156 pfctl_load_fingerprints(dev, opts); 3157 pfctl_show_rules(dev, path, opts, PFCTL_SHOW_LABELS, 3158 anchorname, 0, 0); 3159 break; 3160 case 'n': 3161 pfctl_load_fingerprints(dev, opts); 3162 pfctl_show_nat(dev, path, opts, anchorname, 0, 0); 3163 break; 3164 case 'q': 3165 pfctl_show_altq(dev, ifaceopt, opts, 3166 opts & PF_OPT_VERBOSE2); 3167 break; 3168 case 's': 3169 pfctl_show_states(dev, ifaceopt, opts); 3170 break; 3171 case 'S': 3172 pfctl_show_src_nodes(dev, opts); 3173 break; 3174 case 'i': 3175 pfctl_show_status(dev, opts); 3176 break; 3177 case 'R': 3178 error = pfctl_show_running(dev); 3179 break; 3180 case 't': 3181 pfctl_show_timeouts(dev, opts); 3182 break; 3183 case 'm': 3184 pfctl_show_limits(dev, opts); 3185 break; 3186 case 'e': 3187 pfctl_show_eth_rules(dev, path, opts, 0, anchorname, 0, 3188 0); 3189 break; 3190 case 'a': 3191 opts |= PF_OPT_SHOWALL; 3192 pfctl_load_fingerprints(dev, opts); 3193 3194 pfctl_show_eth_rules(dev, path, opts, 0, anchorname, 0, 3195 0); 3196 3197 pfctl_show_nat(dev, path, opts, anchorname, 0, 0); 3198 pfctl_show_rules(dev, path, opts, 0, anchorname, 0, 0); 3199 pfctl_show_altq(dev, ifaceopt, opts, 0); 3200 pfctl_show_states(dev, ifaceopt, opts); 3201 pfctl_show_src_nodes(dev, opts); 3202 pfctl_show_status(dev, opts); 3203 pfctl_show_rules(dev, path, opts, 1, anchorname, 0, 0); 3204 pfctl_show_timeouts(dev, opts); 3205 pfctl_show_limits(dev, opts); 3206 pfctl_show_tables(anchorname, opts); 3207 pfctl_show_fingerprints(opts); 3208 break; 3209 case 'T': 3210 pfctl_show_tables(anchorname, opts); 3211 break; 3212 case 'o': 3213 pfctl_load_fingerprints(dev, opts); 3214 pfctl_show_fingerprints(opts); 3215 break; 3216 case 'I': 3217 pfctl_show_ifaces(ifaceopt, opts); 3218 break; 3219 case 'c': 3220 pfctl_show_creators(opts); 3221 break; 3222 } 3223 } 3224 3225 if ((opts & PF_OPT_CLRRULECTRS) && showopt == NULL) { 3226 pfctl_show_eth_rules(dev, path, opts, PFCTL_SHOW_NOTHING, 3227 anchorname, 0, 0); 3228 pfctl_show_rules(dev, path, opts, PFCTL_SHOW_NOTHING, 3229 anchorname, 0, 0); 3230 } 3231 3232 if (clearopt != NULL) { 3233 if (anchorname[0] == '_' || strstr(anchorname, "/_") != NULL) 3234 errx(1, "anchor names beginning with '_' cannot " 3235 "be modified from the command line"); 3236 3237 switch (*clearopt) { 3238 case 'e': 3239 pfctl_flush_eth_rules(dev, opts, anchorname); 3240 break; 3241 case 'r': 3242 pfctl_flush_rules(dev, opts, anchorname); 3243 break; 3244 case 'n': 3245 pfctl_flush_nat(dev, opts, anchorname); 3246 break; 3247 case 'q': 3248 pfctl_clear_altq(dev, opts); 3249 break; 3250 case 's': 3251 pfctl_clear_iface_states(dev, ifaceopt, opts); 3252 break; 3253 case 'S': 3254 pfctl_clear_src_nodes(dev, opts); 3255 break; 3256 case 'i': 3257 pfctl_clear_stats(pfh, opts); 3258 break; 3259 case 'a': 3260 pfctl_flush_eth_rules(dev, opts, anchorname); 3261 pfctl_flush_rules(dev, opts, anchorname); 3262 pfctl_flush_nat(dev, opts, anchorname); 3263 pfctl_do_clear_tables(anchorname, opts); 3264 if (!*anchorname) { 3265 pfctl_clear_altq(dev, opts); 3266 pfctl_clear_iface_states(dev, ifaceopt, opts); 3267 pfctl_clear_src_nodes(dev, opts); 3268 pfctl_clear_stats(pfh, opts); 3269 pfctl_clear_fingerprints(dev, opts); 3270 pfctl_clear_interface_flags(dev, opts); 3271 } 3272 break; 3273 case 'o': 3274 pfctl_clear_fingerprints(dev, opts); 3275 break; 3276 case 'T': 3277 pfctl_do_clear_tables(anchorname, opts); 3278 break; 3279 } 3280 } 3281 if (state_killers) { 3282 if (!strcmp(state_kill[0], "label")) 3283 pfctl_label_kill_states(dev, ifaceopt, opts); 3284 else if (!strcmp(state_kill[0], "id")) 3285 pfctl_id_kill_states(dev, ifaceopt, opts); 3286 else if (!strcmp(state_kill[0], "gateway")) 3287 pfctl_gateway_kill_states(dev, ifaceopt, opts); 3288 else 3289 pfctl_net_kill_states(dev, ifaceopt, opts); 3290 } 3291 3292 if (src_node_killers) 3293 pfctl_kill_src_nodes(dev, ifaceopt, opts); 3294 3295 if (tblcmdopt != NULL) { 3296 error = pfctl_command_tables(argc, argv, tableopt, 3297 tblcmdopt, rulesopt, anchorname, opts); 3298 rulesopt = NULL; 3299 } 3300 if (optiopt != NULL) { 3301 switch (*optiopt) { 3302 case 'n': 3303 optimize = 0; 3304 break; 3305 case 'b': 3306 optimize |= PF_OPTIMIZE_BASIC; 3307 break; 3308 case 'o': 3309 case 'p': 3310 optimize |= PF_OPTIMIZE_PROFILE; 3311 break; 3312 } 3313 } 3314 3315 if ((rulesopt != NULL) && (loadopt & PFCTL_FLAG_OPTION) && 3316 !anchorname[0] && !(opts & PF_OPT_NOACTION)) 3317 if (pfctl_get_skip_ifaces()) 3318 error = 1; 3319 3320 if (rulesopt != NULL && !(opts & PF_OPT_MERGE) && 3321 !anchorname[0] && (loadopt & PFCTL_FLAG_OPTION)) 3322 if (pfctl_file_fingerprints(dev, opts, PF_OSFP_FILE)) 3323 error = 1; 3324 3325 if (rulesopt != NULL) { 3326 if (anchorname[0] == '_' || strstr(anchorname, "/_") != NULL) 3327 errx(1, "anchor names beginning with '_' cannot " 3328 "be modified from the command line"); 3329 if (pfctl_rules(dev, rulesopt, opts, optimize, 3330 anchorname, NULL)) 3331 error = 1; 3332 else if (!(opts & PF_OPT_NOACTION) && 3333 (loadopt & PFCTL_FLAG_TABLE)) 3334 warn_namespace_collision(NULL); 3335 } 3336 3337 if (opts & PF_OPT_ENABLE) 3338 if (pfctl_enable(dev, opts)) 3339 error = 1; 3340 3341 if (debugopt != NULL) { 3342 switch (*debugopt) { 3343 case 'n': 3344 pfctl_debug(dev, PF_DEBUG_NONE, opts); 3345 break; 3346 case 'u': 3347 pfctl_debug(dev, PF_DEBUG_URGENT, opts); 3348 break; 3349 case 'm': 3350 pfctl_debug(dev, PF_DEBUG_MISC, opts); 3351 break; 3352 case 'l': 3353 pfctl_debug(dev, PF_DEBUG_NOISY, opts); 3354 break; 3355 } 3356 } 3357 3358 exit(error); 3359 } 3360