#ifndef _NET_BPF_H_
#define _NET_BPF_H_
#include <sys/param.h>
#include <sys/time.h>
#include <sys/ioccom.h>
__BEGIN_DECLS
#define BPF_MAX_CLONES 128
#define BPF_RELEASE 199606
typedef int32_t bpf_int32;
typedef u_int32_t bpf_u_int32;
#define BPF_ALIGNMENT sizeof(long)
#define BPF_WORDALIGN(x) roundup2(x, BPF_ALIGNMENT)
#define BPF_MAXINSNS 512
#define BPF_MAXBUFSIZE 0x80000
#define BPF_DEFAULTBUFSIZE 4096
#define BPF_MINBUFSIZE 32
struct bpf_program {
u_int bf_len;
struct bpf_insn *bf_insns;
};
struct bpf_stat {
u_int bs_recv;
u_int bs_drop;
};
struct bpf_version {
u_short bv_major;
u_short bv_minor;
};
#define BPF_MAJOR_VERSION 1
#define BPF_MINOR_VERSION 1
#define BIOCGBLEN _IOR('B',102, u_int)
#define BIOCSBLEN _IOWR('B',102, u_int)
#define BIOCSETF _IOW('B',103, struct bpf_program)
#define BIOCFLUSH _IO('B',104)
#define BIOCPROMISC _IO('B',105)
#define BIOCGDLT _IOR('B',106, u_int)
#define BIOCGETIF _IOR('B',107, struct ifreq)
#define BIOCSETIF _IOW('B',108, struct ifreq)
#define BIOCSRTIMEOUT _IOW('B',109, struct timeval)
#define BIOCGRTIMEOUT _IOR('B',110, struct timeval)
#define BIOCGSTATS _IOR('B',111, struct bpf_stat)
#define BIOCIMMEDIATE _IOW('B',112, u_int)
#define BIOCVERSION _IOR('B',113, struct bpf_version)
#define BIOCGRSIG _IOR('B',114, u_int)
#define BIOCSRSIG _IOW('B',115, u_int)
#define BIOCGHDRCMPLT _IOR('B',116, u_int)
#define BIOCSHDRCMPLT _IOW('B',117, u_int)
#define BIOCGSEESENT _IOR('B',118, u_int)
#define BIOCSSEESENT _IOW('B',119, u_int)
#define BIOCSDLT _IOW('B',120, u_int)
#define BIOCGDLTLIST _IOWR('B',121, struct bpf_dltlist)
#define BIOCLOCK _IO('B', 122)
#define BIOCSETWF _IOW('B',123, struct bpf_program)
#define BIOCGFEEDBACK _IOR('B',124, u_int)
#define BIOCSFEEDBACK _IOW('B',125, u_int)
#define BIOCFEEDBACK BIOCSFEEDBACK
struct bpf_hdr {
struct timeval bh_tstamp;
bpf_u_int32 bh_caplen;
bpf_u_int32 bh_datalen;
u_short bh_hdrlen;
};
#ifdef _KERNEL
#define SIZEOF_BPF_HDR (sizeof(struct bpf_hdr) <= 20 ? 18 : \
sizeof(struct bpf_hdr))
#endif
#include <net/dlt.h>
#define BPF_CLASS(code) ((code) & 0x07)
#define BPF_LD 0x00
#define BPF_LDX 0x01
#define BPF_ST 0x02
#define BPF_STX 0x03
#define BPF_ALU 0x04
#define BPF_JMP 0x05
#define BPF_RET 0x06
#define BPF_MISC 0x07
#define BPF_SIZE(code) ((code) & 0x18)
#define BPF_W 0x00
#define BPF_H 0x08
#define BPF_B 0x10
#define BPF_MODE(code) ((code) & 0xe0)
#define BPF_IMM 0x00
#define BPF_ABS 0x20
#define BPF_IND 0x40
#define BPF_MEM 0x60
#define BPF_LEN 0x80
#define BPF_MSH 0xa0
#define BPF_OP(code) ((code) & 0xf0)
#define BPF_ADD 0x00
#define BPF_SUB 0x10
#define BPF_MUL 0x20
#define BPF_DIV 0x30
#define BPF_OR 0x40
#define BPF_AND 0x50
#define BPF_LSH 0x60
#define BPF_RSH 0x70
#define BPF_NEG 0x80
#define BPF_MOD 0x90
#define BPF_XOR 0xa0
#define BPF_JA 0x00
#define BPF_JEQ 0x10
#define BPF_JGT 0x20
#define BPF_JGE 0x30
#define BPF_JSET 0x40
#define BPF_SRC(code) ((code) & 0x08)
#define BPF_K 0x00
#define BPF_X 0x08
#define BPF_RVAL(code) ((code) & 0x18)
#define BPF_A 0x10
#define BPF_MISCOP(code) ((code) & 0xf8)
#define BPF_TAX 0x00
#define BPF_TXA 0x80
struct bpf_insn {
u_short code;
u_char jt;
u_char jf;
bpf_u_int32 k;
};
#define BPF_STMT(code, k) { (u_short)(code), 0, 0, k }
#define BPF_JUMP(code, k, jt, jf) { (u_short)(code), jt, jf, k }
struct bpf_dltlist {
u_int bfl_len;
u_int *bfl_list;
};
#ifdef _KERNEL
struct bpf_if;
struct ifnet;
struct mbuf;
int bpf_validate(const struct bpf_insn *, int);
void bpf_tap(struct bpf_if *, u_char *, u_int);
void bpf_mtap(struct bpf_if *, struct mbuf *);
void bpf_mtap_family(struct bpf_if *, struct mbuf *m, __uint8_t family);
void bpf_mtap_hdr(struct bpf_if *, caddr_t, u_int, struct mbuf *, u_int);
void bpf_ptap(struct bpf_if *, struct mbuf *, const void *, u_int);
void bpfattach(struct ifnet *, u_int, u_int);
void bpfattach_dlt(struct ifnet *, u_int, u_int, struct bpf_if **);
void bpfdetach(struct ifnet *);
void bpf_gettoken(void);
void bpf_reltoken(void);
u_int bpf_filter(const struct bpf_insn *, u_char *, u_int, u_int);
#define BPF_TAP(_ifp,_pkt,_pktlen) do { \
if ((_ifp)->if_bpf) { \
bpf_gettoken(); \
if ((_ifp)->if_bpf) \
bpf_tap((_ifp)->if_bpf, (_pkt), (_pktlen)); \
bpf_reltoken(); \
} \
} while (0)
#define BPF_MTAP(_ifp,_m) do { \
if ((_ifp)->if_bpf) { \
bpf_gettoken(); \
if ((_ifp)->if_bpf) \
bpf_mtap((_ifp)->if_bpf, (_m)); \
bpf_reltoken(); \
} \
} while (0)
#include <sys/eventhandler.h>
typedef void (*bpf_track_fn)(void *, struct ifnet *, int ,
int );
EVENTHANDLER_DECLARE(bpf_track, bpf_track_fn);
#endif
#define BPF_MEMWORDS 16
__END_DECLS
#endif