Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 1 | /* |
| 2 | * connection tracking expectations. |
| 3 | */ |
| 4 | |
| 5 | #ifndef _NF_CONNTRACK_EXPECT_H |
| 6 | #define _NF_CONNTRACK_EXPECT_H |
| 7 | #include <net/netfilter/nf_conntrack.h> |
| 8 | |
Patrick McHardy | a71c085 | 2007-07-07 22:33:47 -0700 | [diff] [blame] | 9 | extern unsigned int nf_ct_expect_hsize; |
Patrick McHardy | f264a7d | 2007-07-07 22:36:24 -0700 | [diff] [blame] | 10 | extern unsigned int nf_ct_expect_max; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 11 | |
Eric Dumazet | fd2c3ef | 2009-11-03 03:26:03 +0000 | [diff] [blame] | 12 | struct nf_conntrack_expect { |
Patrick McHardy | b560580 | 2007-07-07 22:35:56 -0700 | [diff] [blame] | 13 | /* Conntrack expectation list member */ |
| 14 | struct hlist_node lnode; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 15 | |
Patrick McHardy | a71c085 | 2007-07-07 22:33:47 -0700 | [diff] [blame] | 16 | /* Hash member */ |
| 17 | struct hlist_node hnode; |
| 18 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 19 | /* We expect this tuple, with the following mask */ |
Patrick McHardy | d4156e8 | 2007-07-07 22:31:32 -0700 | [diff] [blame] | 20 | struct nf_conntrack_tuple tuple; |
| 21 | struct nf_conntrack_tuple_mask mask; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 22 | |
| 23 | /* Function to call after setup and insertion */ |
| 24 | void (*expectfn)(struct nf_conn *new, |
| 25 | struct nf_conntrack_expect *this); |
| 26 | |
Patrick McHardy | 9457d85 | 2006-12-02 22:05:25 -0800 | [diff] [blame] | 27 | /* Helper to assign to new connection */ |
| 28 | struct nf_conntrack_helper *helper; |
| 29 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 30 | /* The conntrack of the master connection */ |
| 31 | struct nf_conn *master; |
| 32 | |
| 33 | /* Timer function; deletes the expectation. */ |
| 34 | struct timer_list timeout; |
| 35 | |
| 36 | /* Usage count. */ |
| 37 | atomic_t use; |
| 38 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 39 | /* Flags */ |
| 40 | unsigned int flags; |
| 41 | |
Patrick McHardy | 6002f266 | 2008-03-25 20:09:15 -0700 | [diff] [blame] | 42 | /* Expectation class */ |
| 43 | unsigned int class; |
| 44 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 45 | #ifdef CONFIG_NF_NAT_NEEDED |
Patrick McHardy | f587de0 | 2006-12-02 22:08:46 -0800 | [diff] [blame] | 46 | __be32 saved_ip; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 47 | /* This is the original per-proto part, used to map the |
| 48 | * expected connection the way the recipient expects. */ |
Jozsef Kadlecsik | 5b1158e | 2006-12-02 22:07:13 -0800 | [diff] [blame] | 49 | union nf_conntrack_man_proto saved_proto; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 50 | /* Direction relative to the master connection. */ |
| 51 | enum ip_conntrack_dir dir; |
| 52 | #endif |
Patrick McHardy | 7d0742d | 2008-01-31 04:38:19 -0800 | [diff] [blame] | 53 | |
| 54 | struct rcu_head rcu; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 55 | }; |
| 56 | |
Alexey Dobriyan | 9b03f38 | 2008-10-08 11:35:03 +0200 | [diff] [blame] | 57 | static inline struct net *nf_ct_exp_net(struct nf_conntrack_expect *exp) |
| 58 | { |
Alexey Dobriyan | 857b409 | 2010-02-12 06:24:46 +0100 | [diff] [blame] | 59 | return nf_ct_net(exp->master); |
Alexey Dobriyan | 9b03f38 | 2008-10-08 11:35:03 +0200 | [diff] [blame] | 60 | } |
| 61 | |
Pablo Neira Ayuso | 3a8fc53 | 2012-01-15 16:34:08 +0100 | [diff] [blame] | 62 | #define NF_CT_EXP_POLICY_NAME_LEN 16 |
| 63 | |
Eric Dumazet | fd2c3ef | 2009-11-03 03:26:03 +0000 | [diff] [blame] | 64 | struct nf_conntrack_expect_policy { |
Patrick McHardy | 6002f266 | 2008-03-25 20:09:15 -0700 | [diff] [blame] | 65 | unsigned int max_expected; |
| 66 | unsigned int timeout; |
Pablo Neira Ayuso | 3a8fc53 | 2012-01-15 16:34:08 +0100 | [diff] [blame] | 67 | char name[NF_CT_EXP_POLICY_NAME_LEN]; |
Patrick McHardy | 6002f266 | 2008-03-25 20:09:15 -0700 | [diff] [blame] | 68 | }; |
| 69 | |
| 70 | #define NF_CT_EXPECT_CLASS_DEFAULT 0 |
| 71 | |
Alexey Dobriyan | 9b03f38 | 2008-10-08 11:35:03 +0200 | [diff] [blame] | 72 | int nf_conntrack_expect_init(struct net *net); |
| 73 | void nf_conntrack_expect_fini(struct net *net); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 74 | |
| 75 | struct nf_conntrack_expect * |
Patrick McHardy | 5d0aa2c | 2010-02-15 18:13:33 +0100 | [diff] [blame] | 76 | __nf_ct_expect_find(struct net *net, u16 zone, |
| 77 | const struct nf_conntrack_tuple *tuple); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 78 | |
| 79 | struct nf_conntrack_expect * |
Patrick McHardy | 5d0aa2c | 2010-02-15 18:13:33 +0100 | [diff] [blame] | 80 | nf_ct_expect_find_get(struct net *net, u16 zone, |
| 81 | const struct nf_conntrack_tuple *tuple); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 82 | |
| 83 | struct nf_conntrack_expect * |
Patrick McHardy | 5d0aa2c | 2010-02-15 18:13:33 +0100 | [diff] [blame] | 84 | nf_ct_find_expectation(struct net *net, u16 zone, |
| 85 | const struct nf_conntrack_tuple *tuple); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 86 | |
Pablo Neira Ayuso | ebbf41d | 2010-10-19 10:19:06 +0200 | [diff] [blame] | 87 | void nf_ct_unlink_expect_report(struct nf_conntrack_expect *exp, |
| 88 | u32 pid, int report); |
| 89 | static inline void nf_ct_unlink_expect(struct nf_conntrack_expect *exp) |
| 90 | { |
| 91 | nf_ct_unlink_expect_report(exp, 0, 0); |
| 92 | } |
| 93 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 94 | void nf_ct_remove_expectations(struct nf_conn *ct); |
Patrick McHardy | 6823645 | 2007-07-07 22:30:49 -0700 | [diff] [blame] | 95 | void nf_ct_unexpect_related(struct nf_conntrack_expect *exp); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 96 | |
| 97 | /* Allocate space for an expectation: this is mandatory before calling |
Patrick McHardy | 6823645 | 2007-07-07 22:30:49 -0700 | [diff] [blame] | 98 | nf_ct_expect_related. You will have to call put afterwards. */ |
| 99 | struct nf_conntrack_expect *nf_ct_expect_alloc(struct nf_conn *me); |
Jan Engelhardt | 76108ce | 2008-10-08 11:35:00 +0200 | [diff] [blame] | 100 | void nf_ct_expect_init(struct nf_conntrack_expect *, unsigned int, u_int8_t, |
Patrick McHardy | 1d9d752 | 2008-03-25 20:07:58 -0700 | [diff] [blame] | 101 | const union nf_inet_addr *, |
| 102 | const union nf_inet_addr *, |
| 103 | u_int8_t, const __be16 *, const __be16 *); |
Patrick McHardy | 6823645 | 2007-07-07 22:30:49 -0700 | [diff] [blame] | 104 | void nf_ct_expect_put(struct nf_conntrack_expect *exp); |
Pablo Neira Ayuso | 19abb7b | 2008-11-18 11:56:20 +0100 | [diff] [blame] | 105 | int nf_ct_expect_related_report(struct nf_conntrack_expect *expect, |
| 106 | u32 pid, int report); |
Pablo Neira Ayuso | 8373167 | 2009-04-06 17:47:20 +0200 | [diff] [blame] | 107 | static inline int nf_ct_expect_related(struct nf_conntrack_expect *expect) |
| 108 | { |
| 109 | return nf_ct_expect_related_report(expect, 0, 0); |
| 110 | } |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 111 | |
| 112 | #endif /*_NF_CONNTRACK_EXPECT_H*/ |
| 113 | |