1 /* 2 * Copyright (C) 1995-2001 by Darren Reed. 3 * 4 * See the IPFILTER.LICENCE file for details on licencing. 5 * 6 * @(#)ip_state.h 1.3 1/12/96 (C) 1995 Darren Reed 7 * $Id: ip_state.h,v 2.68.2.5 2005/08/11 19:58:04 darrenr Exp $ 8 * 9 * Copyright 2008 Sun Microsystems, Inc. All rights reserved. 10 * Use is subject to license terms. 11 */ 12 13 #ifndef __IP_STATE_H__ 14 #define __IP_STATE_H__ 15 16 #if defined(__STDC__) || defined(__GNUC__) || defined(_AIX51) 17 # define SIOCDELST _IOW('r', 61, struct ipfobj) 18 #else 19 # define SIOCDELST _IOW(r, 61, struct ipfobj) 20 #endif 21 22 struct ipscan; 23 24 #ifndef IPSTATE_SIZE 25 # define IPSTATE_SIZE 5737 26 #endif 27 #ifndef IPSTATE_MAX 28 # define IPSTATE_MAX 4013 /* Maximum number of states held */ 29 #endif 30 31 #define PAIRS(s1,d1,s2,d2) ((((s1) == (s2)) && ((d1) == (d2))) ||\ 32 (((s1) == (d2)) && ((d1) == (s2)))) 33 #define IPPAIR(s1,d1,s2,d2) PAIRS((s1).s_addr, (d1).s_addr, \ 34 (s2).s_addr, (d2).s_addr) 35 36 37 typedef struct ipstate { 38 ipfmutex_t is_lock; 39 struct ipstate *is_next; 40 struct ipstate **is_pnext; 41 struct ipstate *is_hnext; 42 struct ipstate **is_phnext; 43 struct ipstate **is_me; 44 void *is_ifp[4]; 45 void *is_sync; 46 struct nat *is_nat[2]; 47 frentry_t *is_rule; 48 struct ipftq *is_tqehead[2]; 49 struct ipscan *is_isc; 50 U_QUAD_T is_pkts[4]; 51 U_QUAD_T is_bytes[4]; 52 U_QUAD_T is_icmppkts[4]; 53 struct ipftqent is_sti; 54 u_int is_frage[2]; 55 int is_ref; /* reference count */ 56 int is_isninc[2]; 57 u_short is_sumd[2]; 58 i6addr_t is_src; 59 i6addr_t is_dst; 60 u_int is_pass; 61 u_char is_p; /* Protocol */ 62 u_char is_v; 63 u_32_t is_hv; 64 u_32_t is_tag; 65 u_32_t is_opt[2]; /* packet options set */ 66 /* in both directions */ 67 u_32_t is_optmsk[2]; /* " " mask */ 68 /* in both directions */ 69 u_short is_sec; /* security options set */ 70 u_short is_secmsk; /* " " mask */ 71 u_short is_auth; /* authentication options set */ 72 u_short is_authmsk; /* " " mask */ 73 union { 74 icmpinfo_t is_ics; 75 tcpinfo_t is_ts; 76 udpinfo_t is_us; 77 greinfo_t is_ug; 78 } is_ps; 79 u_32_t is_flags; 80 int is_flx[2][2]; 81 u_32_t is_rulen; /* rule number when created */ 82 u_32_t is_s0[2]; 83 u_short is_smsk[2]; 84 char is_group[FR_GROUPLEN]; 85 char is_sbuf[2][16]; 86 char is_ifname[4][LIFNAMSIZ]; 87 } ipstate_t; 88 89 #define is_die is_sti.tqe_die 90 #define is_state is_sti.tqe_state 91 #define is_touched is_sti.tqe_touched 92 #define is_saddr is_src.in4.s_addr 93 #define is_daddr is_dst.in4.s_addr 94 #define is_icmp is_ps.is_ics 95 #define is_type is_icmp.ici_type 96 #define is_code is_icmp.ici_code 97 #define is_tcp is_ps.is_ts 98 #define is_udp is_ps.is_us 99 #define is_send is_tcp.ts_data[0].td_end 100 #define is_dend is_tcp.ts_data[1].td_end 101 #define is_maxswin is_tcp.ts_data[0].td_maxwin 102 #define is_maxdwin is_tcp.ts_data[1].td_maxwin 103 #define is_maxsend is_tcp.ts_data[0].td_maxend 104 #define is_maxdend is_tcp.ts_data[1].td_maxend 105 #define is_swinscale is_tcp.ts_data[0].td_winscale 106 #define is_dwinscale is_tcp.ts_data[1].td_winscale 107 #define is_swinflags is_tcp.ts_data[0].td_winflags 108 #define is_dwinflags is_tcp.ts_data[1].td_winflags 109 #define is_sport is_tcp.ts_sport 110 #define is_dport is_tcp.ts_dport 111 #define is_ifpin is_ifp[0] 112 #define is_ifpout is_ifp[2] 113 #define is_gre is_ps.is_ug 114 #define is_call is_gre.gs_call 115 116 #define IS_WSPORT SI_W_SPORT /* 0x00100 */ 117 #define IS_WDPORT SI_W_DPORT /* 0x00200 */ 118 #define IS_WSADDR SI_W_SADDR /* 0x00400 */ 119 #define IS_WDADDR SI_W_DADDR /* 0x00800 */ 120 #define IS_NEWFR SI_NEWFR /* 0x01000 */ 121 #define IS_CLONE SI_CLONE /* 0x02000 */ 122 #define IS_CLONED SI_CLONED /* 0x04000 */ 123 #define IS_TCPFSM 0x10000 124 #define IS_STRICT 0x20000 125 #define IS_ISNSYN 0x40000 126 #define IS_ISNACK 0x80000 127 #define IS_STATESYNC 0x100000 128 /* 129 * IS_SC flags are for scan-operations that need to be recognised in state. 130 */ 131 #define IS_SC_CLIENT 0x10000000 132 #define IS_SC_SERVER 0x20000000 133 #define IS_SC_MATCHC 0x40000000 134 #define IS_SC_MATCHS 0x80000000 135 #define IS_SC_MATCHALL (IS_SC_MATCHC|IS_SC_MATCHC) 136 #define IS_SC_ALL (IS_SC_MATCHC|IS_SC_MATCHC|IS_SC_CLIENT|IS_SC_SERVER) 137 138 /* 139 * Flags that can be passed into fr_addstate 140 */ 141 #define IS_INHERITED 0x0fffff00 142 143 #define TH_OPENING (TH_SYN|TH_ACK) 144 /* 145 * is_flags: 146 * Bits 0 - 3 are use as a mask with the current packet's bits to check for 147 * whether it is short, tcp/udp, a fragment or the presence of IP options. 148 * Bits 4 - 7 are set from the initial packet and contain what the packet 149 * anded with bits 0-3 must match. 150 * Bits 8,9 are used to indicate wildcard source/destination port matching. 151 * Bits 10,11 are reserved for other wildcard flag compatibility. 152 * Bits 12,13 are for scaning. 153 */ 154 155 typedef struct ipstate_save { 156 void *ips_next; 157 struct ipstate ips_is; 158 struct frentry ips_fr; 159 } ipstate_save_t; 160 161 #define ips_rule ips_is.is_rule 162 163 164 typedef struct ipslog { 165 U_QUAD_T isl_pkts[4]; 166 U_QUAD_T isl_bytes[4]; 167 i6addr_t isl_src; 168 i6addr_t isl_dst; 169 u_32_t isl_tag; 170 u_short isl_type; 171 union { 172 u_short isl_filler[2]; 173 u_short isl_ports[2]; 174 u_short isl_icmp; 175 } isl_ps; 176 u_char isl_v; 177 u_char isl_p; 178 u_char isl_flags; 179 u_char isl_state[2]; 180 u_32_t isl_rulen; 181 char isl_group[FR_GROUPLEN]; 182 } ipslog_t; 183 184 #define isl_sport isl_ps.isl_ports[0] 185 #define isl_dport isl_ps.isl_ports[1] 186 #define isl_itype isl_ps.isl_icmp 187 188 #define ISL_NEW 0 189 #define ISL_CLONE 1 190 #define ISL_EXPIRE 0xffff 191 #define ISL_FLUSH 0xfffe 192 #define ISL_REMOVE 0xfffd 193 #define ISL_INTERMEDIATE 0xfffc 194 #define ISL_KILLED 0xfffb 195 #define ISL_ORPHAN 0xfffa 196 197 198 typedef struct ips_stat { 199 u_long iss_hits; 200 u_long iss_miss; 201 u_long iss_max; 202 u_long iss_maxref; 203 u_long iss_tcp; 204 u_long iss_udp; 205 u_long iss_icmp; 206 u_long iss_nomem; 207 u_long iss_expire; 208 u_long iss_fin; 209 u_long iss_active; 210 u_long iss_logged; 211 u_long iss_logfail; 212 u_long iss_inuse; 213 u_long iss_wild; 214 u_long iss_killed; 215 u_long iss_ticks; 216 u_long iss_bucketfull; 217 int iss_statesize; 218 int iss_statemax; 219 ipstate_t **iss_table; 220 ipstate_t *iss_list; 221 u_long *iss_bucketlen; 222 u_int iss_orphans; 223 } ips_stat_t; 224 225 typedef struct port_pair { 226 uint16_t pp_sport; 227 uint16_t pp_dport; 228 } port_pair_t; 229 230 extern int fr_stateinit __P((ipf_stack_t *)); 231 extern ipstate_t *fr_addstate __P((fr_info_t *, ipstate_t **, u_int)); 232 extern frentry_t *fr_checkstate __P((struct fr_info *, u_32_t *)); 233 extern ipstate_t *fr_stlookup __P((fr_info_t *, tcphdr_t *, ipftq_t **)); 234 extern void fr_statesync __P((int, int, void *, char *, ipf_stack_t *)); 235 extern void fr_timeoutstate __P((ipf_stack_t *)); 236 extern int fr_tcp_age __P((struct ipftqent *, struct fr_info *, 237 struct ipftq *, int)); 238 extern int fr_tcpinwindow __P((struct fr_info *, struct tcpdata *, 239 struct tcpdata *, tcphdr_t *, int)); 240 extern void fr_stateunload __P((ipf_stack_t *)); 241 extern void ipstate_log __P((struct ipstate *, u_int, ipf_stack_t *)); 242 extern int fr_state_ioctl __P((caddr_t, ioctlcmd_t, int, int, void *, ipf_stack_t *)); 243 extern void fr_stinsert __P((struct ipstate *, int, ipf_stack_t *)); 244 extern void fr_sttab_init __P((struct ipftq *, ipf_stack_t *)); 245 extern void fr_sttab_destroy __P((struct ipftq *)); 246 extern void fr_updatestate __P((fr_info_t *, ipstate_t *, ipftq_t *)); 247 extern void fr_statederef __P((ipstate_t **, ipf_stack_t *)); 248 extern void fr_setstatequeue __P((ipstate_t *, int, ipf_stack_t *)); 249 250 #endif /* __IP_STATE_H__ */ 251