#ifndef _IP_FW3_H_
#define _IP_FW3_H_
#ifndef _IPFW2_H
#include <net/bpf.h>
#define NEED1(msg) {if (ac < 1) errx(EX_USAGE, msg);}
#define NEED2(msg) {if (ac < 2) errx(EX_USAGE, msg);}
#define NEED(c, n, msg) {if (c < n) errx(EX_USAGE, msg);}
#define NEXT_ARG ac--; if(ac > 0){av++;}
#define NEXT_ARG1 (*ac)--; if(*ac > 0){(*av)++;}
#define SWAP_ARG \
do { \
if (ac > 2 && isdigit(*(av[1]))) { \
char *p = av[1]; \
av[1] = av[2]; \
av[2] = p; \
} \
} while (0)
#define IPFW_RULE_SIZE_MAX 255
#define NONE 0
#define BEFORE 1
#define ACTION 2
#define PROTO 3
#define FROM 4
#define TO 5
#define FILTER 6
#define AFTER 7
#define NOT_IN_USE 0
#define IN_USE 1
#define SIZE_OF_IPFWINSN 8
#define LEN_OF_IPFWINSN 2
#define IPFW_DEFAULT_RULE 65535
#define IPFW_DEFAULT_SET 0
#define IPFW_ALL_SETS 0
#define F_NOT 0x80
#define F_OR 0x40
#define F_LEN_MASK 0x3f
#define F_LEN(cmd) ((cmd)->len & F_LEN_MASK)
typedef struct _ipfw_insn {
uint8_t opcode;
uint8_t len;
uint16_t arg1;
uint8_t module;
uint8_t arg3;
uint16_t arg2;
} ipfw_insn;
#define ACTION_PTR(rule) \
(ipfw_insn *)((uint32_t *)((rule)->cmd) + ((rule)->act_ofs))
#define F_INSN_SIZE(t) ((sizeof (t))/sizeof(uint32_t))
#define MTAG_IPFW 1148380143
typedef struct _ipfw_insn_u16 {
ipfw_insn o;
uint16_t ports[2];
} ipfw_insn_u16;
typedef struct _ipfw_insn_u32 {
ipfw_insn o;
uint32_t d[1];
} ipfw_insn_u32;
typedef struct _ipfw_insn_ip {
ipfw_insn o;
struct in_addr addr;
struct in_addr mask;
} ipfw_insn_ip;
typedef struct _ipfw_insn_sa {
ipfw_insn o;
struct sockaddr_in sa;
} ipfw_insn_sa;
typedef struct _ipfw_insn_mac {
ipfw_insn o;
u_char addr[12];
u_char mask[12];
} ipfw_insn_mac;
typedef struct _ipfw_insn_if {
ipfw_insn o;
union {
struct in_addr ip;
int glob;
} p;
char name[IFNAMSIZ];
} ipfw_insn_if;
typedef struct _ipfw_insn_pipe {
ipfw_insn o;
void *pipe_ptr;
} ipfw_insn_pipe;
typedef struct _ipfw_insn_limit {
ipfw_insn o;
uint8_t _pad;
uint8_t limit_mask;
#define DYN_SRC_ADDR 0x1
#define DYN_SRC_PORT 0x2
#define DYN_DST_ADDR 0x4
#define DYN_DST_PORT 0x8
uint16_t conn_limit;
} ipfw_insn_limit;
typedef struct _ipfw_insn_bpf {
ipfw_insn o;
char bf_str[128];
u_int bf_len;
struct bpf_insn bf_insn[1];
} ipfw_insn_bpf;
struct ip_fw {
struct ip_fw *next;
struct ip_fw *next_rule;
uint16_t act_ofs;
uint16_t cmd_len;
uint16_t rulenum;
uint8_t set;
uint8_t flags;
uint64_t pcnt;
uint64_t bcnt;
uint32_t timestamp;
struct ip_fw *sibling;
ipfw_insn cmd[1];
};
#define LEN_FW3 sizeof(struct ip_fw)
#define IPFW_RULE_F_INVALID 0x1
#define IPFW_RULE_F_STATE 0x2
#define RULESIZE(rule) (sizeof(struct ip_fw) + (rule)->cmd_len * 4 - SIZE_OF_IPFWINSN)
struct ipfw_flow_id {
uint32_t dst_ip;
uint32_t src_ip;
uint16_t dst_port;
uint16_t src_port;
uint8_t proto;
uint8_t flags;
};
#define IP_FW_PASS 0
#define IP_FW_DENY 1
#define IP_FW_DIVERT 2
#define IP_FW_TEE 3
#define IP_FW_DUMMYNET 4
#define IP_FW_NAT 5
#define IP_FW_ROUTE 6
#define IP_FW_CTL_NO 0
#define IP_FW_CTL_DONE 1
#define IP_FW_CTL_AGAIN 2
#define IP_FW_CTL_NEXT 3
#define IP_FW_CTL_NAT 4
#define IP_FW_CTL_LOOP 5
#define IP_FW_CTL_CHK_STATE 6
#define IP_FW_NOT_MATCH 0
#define IP_FW_MATCH 1
struct ip_fw_args {
struct mbuf *m;
struct ifnet *oif;
struct ip_fw *rule;
struct ether_header *eh;
struct ipfw_flow_id f_id;
uint32_t cookie;
};
struct ipfw_ioc_rule {
uint16_t act_ofs;
uint16_t cmd_len;
uint16_t rulenum;
uint8_t set;
uint8_t insert;
uint32_t sets;
uint64_t pcnt;
uint64_t bcnt;
uint32_t timestamp;
ipfw_insn cmd[1];
};
#define IOC_RULESIZE(rule) \
(sizeof(struct ipfw_ioc_rule) + (rule)->cmd_len * 4 - SIZE_OF_IPFWINSN)
typedef struct _ip_fw_x_header {
uint16_t opcode;
uint16_t _pad;
} ip_fw_x_header;
#define IP_FW_ADD 50
#define IP_FW_DEL 51
#define IP_FW_FLUSH 52
#define IP_FW_ZERO 53
#define IP_FW_GET 54
#define IP_FW_RESETLOG 55
#define IP_FW_STATE_ADD 56
#define IP_FW_STATE_DEL 57
#define IP_FW_STATE_FLUSH 58
#define IP_FW_STATE_GET 59
#define IP_DUMMYNET_CONFIGURE 60
#define IP_DUMMYNET_DEL 61
#define IP_DUMMYNET_FLUSH 62
#define IP_DUMMYNET_GET 64
#define IP_FW_MODULE 67
#define IP_FW_NAT_ADD 68
#define IP_FW_NAT_DEL 69
#define IP_FW_NAT_FLUSH 70
#define IP_FW_NAT_GET 71
#define IP_FW_NAT_GET_RECORD 72
#define IP_FW_TABLE_CREATE 73
#define IP_FW_TABLE_DELETE 74
#define IP_FW_TABLE_APPEND 75
#define IP_FW_TABLE_REMOVE 76
#define IP_FW_TABLE_LIST 77
#define IP_FW_TABLE_FLUSH 78
#define IP_FW_TABLE_SHOW 79
#define IP_FW_TABLE_TEST 80
#define IP_FW_TABLE_RENAME 81
#define IP_FW_SYNC_SHOW_CONF 82
#define IP_FW_SYNC_SHOW_STATUS 83
#define IP_FW_SYNC_EDGE_CONF 84
#define IP_FW_SYNC_EDGE_START 85
#define IP_FW_SYNC_EDGE_STOP 86
#define IP_FW_SYNC_EDGE_TEST 87
#define IP_FW_SYNC_EDGE_CLEAR 88
#define IP_FW_SYNC_CENTRE_CONF 89
#define IP_FW_SYNC_CENTRE_START 90
#define IP_FW_SYNC_CENTRE_STOP 91
#define IP_FW_SYNC_CENTRE_TEST 92
#define IP_FW_SYNC_CENTRE_CLEAR 93
#define IP_FW_SET_GET 95
#define IP_FW_SET_MOVE_RULE 96
#define IP_FW_SET_MOVE_SET 97
#define IP_FW_SET_SWAP 98
#define IP_FW_SET_TOGGLE 99
#define IP_FW_SET_FLUSH 100
#endif
#ifdef _KERNEL
#include <net/netisr2.h>
int ip_fw3_sockopt(struct sockopt *);
extern int ip_fw3_loaded;
#define IPFW3_LOADED (ip_fw3_loaded)
#ifdef IPFIREWALL3_DEBUG
#define IPFW3_DEBUG1(str) \
do { \
kprintf(str); \
} while (0)
#define IPFW3_DEBUG(fmt, ...) \
do { \
kprintf(fmt, __VA_ARGS__); \
} while (0)
#else
#define IPFW3_DEBUG1(str) ((void)0)
#define IPFW3_DEBUG(fmt, ...) ((void)0)
#endif
typedef int ip_fw_ctl_t(struct sockopt *);
typedef int ip_fw_chk_t(struct ip_fw_args *);
typedef struct mbuf *ip_fw_dn_io_t(struct mbuf *, int, int, struct ip_fw_args *);
typedef void *ip_fw_log_t(struct mbuf *m, struct ether_header *eh, uint16_t id);
#ifndef _IPFW2_H
int ip_fw_sockopt(struct sockopt *);
struct sockopt;
struct dn_flow_set;
extern ip_fw_chk_t *ip_fw_chk_ptr;
extern ip_fw_ctl_t *ip_fw_ctl_x_ptr;
extern ip_fw_dn_io_t *ip_fw_dn_io_ptr;
#define IPFW_TABLES_MAX 32
#define IPFW_USR_F_NORULE 0x01
#define IPFW_CFGCPUID 0
#define IPFW_CFGPORT netisr_cpuport(IPFW_CFGCPUID)
#define IPFW_ASSERT_CFGPORT(msgport) \
KASSERT((msgport) == IPFW_CFGPORT, ("not IPFW CFGPORT"))
struct ipfw3_context {
struct ip_fw *rules;
struct ip_fw *default_rule;
struct ipfw3_state_context *state_ctx;
struct ipfw3_table_context *table_ctx;
uint32_t sets;
};
#define LEN_FW3_CTX sizeof(struct ipfw3_context)
struct ipfw3_module{
int type;
int id;
char name[20];
};
#define IP_FW_IPOPT_LSRR 0x01
#define IP_FW_IPOPT_SSRR 0x02
#define IP_FW_IPOPT_RR 0x04
#define IP_FW_IPOPT_TS 0x08
#define IP_FW_TCPOPT_MSS 0x01
#define IP_FW_TCPOPT_WINDOW 0x02
#define IP_FW_TCPOPT_SACK 0x04
#define IP_FW_TCPOPT_TS 0x08
#define IP_FW_TCPOPT_CC 0x10
#define ICMP_REJECT_RST 0x100
#define MATCH_REVERSE 0
#define MATCH_FORWARD 1
#define MATCH_NONE 2
#define MATCH_UNKNOWN 3
#define L3HDR(T, ip) ((T *)((uint32_t *)(ip) + (ip)->ip_hl))
typedef void (*filter_func)(int *cmd_ctl,int *cmd_val,struct ip_fw_args **args,
struct ip_fw **f,ipfw_insn *cmd, uint16_t ip_len);
void check_accept(int *cmd_ctl, int *cmd_val, struct ip_fw_args **args,
struct ip_fw **f, ipfw_insn *cmd, uint16_t ip_len);
void check_deny(int *cmd_ctl, int *cmd_val, struct ip_fw_args **args,
struct ip_fw **f, ipfw_insn *cmd, uint16_t ip_len);
void ip_fw3_register_module(int module_id,char *module_name);
int ip_fw3_unregister_module(int module_id);
void ip_fw3_register_filter_funcs(int module, int opcode, filter_func func);
void ip_fw3_unregister_filter_funcs(int module,filter_func func);
void init_module(void);
int ip_fw3_free_rule(struct ip_fw *rule);
int ip_fw3_chk(struct ip_fw_args *args);
struct mbuf *ip_fw3_dummynet_io(struct mbuf *m, int pipe_nr, int dir, struct ip_fw_args *fwa);
void add_rule_dispatch(netmsg_t nmsg);
void ip_fw3_add_rule(struct ipfw_ioc_rule *ioc_rule);
struct ip_fw *ip_fw3_delete_rule(struct ipfw3_context *ctx,
struct ip_fw *prev, struct ip_fw *rule);
void flush_rule_dispatch(netmsg_t nmsg);
void ip_fw3_ctl_flush_rule(int);
void delete_rule_dispatch(netmsg_t nmsg);
int ip_fw3_ctl_delete_rule(struct sockopt *sopt);
void ip_fw3_clear_counters(struct ip_fw *rule);
void ip_fw3_zero_entry_dispatch(netmsg_t nmsg);
int ip_fw3_ctl_zero_entry(int rulenum, int log_only);
int ip_fw3_ctl_add_rule(struct sockopt *sopt);
int ip_fw3_ctl_get_modules(struct sockopt *sopt);
int ip_fw3_ctl_get_rules(struct sockopt *sopt);
int ip_fw3_ctl_x(struct sockopt *sopt);
int ip_fw3_ctl(struct sockopt *sopt);
int ip_fw3_ctl_sockopt(struct sockopt *sopt);
int ip_fw3_check_in(void *arg, struct mbuf **m0, struct ifnet *ifp, int dir);
int ip_fw3_check_out(void *arg, struct mbuf **m0, struct ifnet *ifp, int dir);
void ip_fw3_hook(void);
void ip_fw3_dehook(void);
void ip_fw3_sysctl_enable_dispatch(netmsg_t nmsg);
void ctx_init_dispatch(netmsg_t nmsg);
void init_dispatch(netmsg_t nmsg);
int ip_fw3_init(void);
void fini_dispatch(netmsg_t nmsg);
int ip_fw3_fini(void);
#endif
#endif
#endif