Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 1 | /* (C) 1999-2001 Paul `Rusty' Russell |
| 2 | * (C) 2002-2004 Netfilter Core Team <coreteam@netfilter.org> |
| 3 | * |
| 4 | * This program is free software; you can redistribute it and/or modify |
| 5 | * it under the terms of the GNU General Public License version 2 as |
| 6 | * published by the Free Software Foundation. |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 7 | */ |
| 8 | |
| 9 | #include <linux/types.h> |
Tim Schmielau | cd354f1 | 2007-02-14 00:33:14 -0800 | [diff] [blame] | 10 | #include <linux/jiffies.h> |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 11 | #include <linux/timer.h> |
| 12 | #include <linux/netfilter.h> |
Martin Josefsson | 605dcad | 2006-11-29 02:35:06 +0100 | [diff] [blame] | 13 | #include <net/netfilter/nf_conntrack_l4proto.h> |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 14 | |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 15 | static unsigned int nf_ct_generic_timeout __read_mostly = 600*HZ; |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 16 | |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 17 | static inline struct nf_generic_net *generic_pernet(struct net *net) |
| 18 | { |
| 19 | return &net->ct.nf_ct_proto.generic; |
| 20 | } |
| 21 | |
Jan Engelhardt | 09f263c | 2008-04-14 11:15:53 +0200 | [diff] [blame] | 22 | static bool generic_pkt_to_tuple(const struct sk_buff *skb, |
| 23 | unsigned int dataoff, |
| 24 | struct nf_conntrack_tuple *tuple) |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 25 | { |
| 26 | tuple->src.u.all = 0; |
| 27 | tuple->dst.u.all = 0; |
| 28 | |
Jan Engelhardt | 09f263c | 2008-04-14 11:15:53 +0200 | [diff] [blame] | 29 | return true; |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 30 | } |
| 31 | |
Jan Engelhardt | 09f263c | 2008-04-14 11:15:53 +0200 | [diff] [blame] | 32 | static bool generic_invert_tuple(struct nf_conntrack_tuple *tuple, |
| 33 | const struct nf_conntrack_tuple *orig) |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 34 | { |
| 35 | tuple->src.u.all = 0; |
| 36 | tuple->dst.u.all = 0; |
| 37 | |
Jan Engelhardt | 09f263c | 2008-04-14 11:15:53 +0200 | [diff] [blame] | 38 | return true; |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 39 | } |
| 40 | |
| 41 | /* Print out the per-protocol part of the tuple. */ |
| 42 | static int generic_print_tuple(struct seq_file *s, |
| 43 | const struct nf_conntrack_tuple *tuple) |
| 44 | { |
| 45 | return 0; |
| 46 | } |
| 47 | |
Pablo Neira Ayuso | 2c8503f | 2012-02-28 18:23:31 +0100 | [diff] [blame] | 48 | static unsigned int *generic_get_timeouts(struct net *net) |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 49 | { |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 50 | return &(generic_pernet(net)->timeout); |
Pablo Neira Ayuso | 2c8503f | 2012-02-28 18:23:31 +0100 | [diff] [blame] | 51 | } |
| 52 | |
| 53 | /* Returns verdict for packet, or -1 for invalid. */ |
| 54 | static int generic_packet(struct nf_conn *ct, |
| 55 | const struct sk_buff *skb, |
| 56 | unsigned int dataoff, |
| 57 | enum ip_conntrack_info ctinfo, |
| 58 | u_int8_t pf, |
| 59 | unsigned int hooknum, |
| 60 | unsigned int *timeout) |
| 61 | { |
| 62 | nf_ct_refresh_acct(ct, ctinfo, skb, *timeout); |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 63 | return NF_ACCEPT; |
| 64 | } |
| 65 | |
| 66 | /* Called when a new connection for this protocol found. */ |
Pablo Neira Ayuso | 2c8503f | 2012-02-28 18:23:31 +0100 | [diff] [blame] | 67 | static bool generic_new(struct nf_conn *ct, const struct sk_buff *skb, |
| 68 | unsigned int dataoff, unsigned int *timeouts) |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 69 | { |
Jan Engelhardt | 09f263c | 2008-04-14 11:15:53 +0200 | [diff] [blame] | 70 | return true; |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 71 | } |
| 72 | |
Pablo Neira Ayuso | 5097846 | 2012-02-28 19:13:48 +0100 | [diff] [blame] | 73 | #if IS_ENABLED(CONFIG_NF_CT_NETLINK_TIMEOUT) |
| 74 | |
| 75 | #include <linux/netfilter/nfnetlink.h> |
| 76 | #include <linux/netfilter/nfnetlink_cttimeout.h> |
| 77 | |
Gao feng | 8264deb | 2012-05-28 21:04:23 +0000 | [diff] [blame] | 78 | static int generic_timeout_nlattr_to_obj(struct nlattr *tb[], |
| 79 | struct net *net, void *data) |
Pablo Neira Ayuso | 5097846 | 2012-02-28 19:13:48 +0100 | [diff] [blame] | 80 | { |
| 81 | unsigned int *timeout = data; |
Gao feng | 8264deb | 2012-05-28 21:04:23 +0000 | [diff] [blame] | 82 | struct nf_generic_net *gn = generic_pernet(net); |
Pablo Neira Ayuso | 5097846 | 2012-02-28 19:13:48 +0100 | [diff] [blame] | 83 | |
| 84 | if (tb[CTA_TIMEOUT_GENERIC_TIMEOUT]) |
| 85 | *timeout = |
| 86 | ntohl(nla_get_be32(tb[CTA_TIMEOUT_GENERIC_TIMEOUT])) * HZ; |
| 87 | else { |
| 88 | /* Set default generic timeout. */ |
Gao feng | 8264deb | 2012-05-28 21:04:23 +0000 | [diff] [blame] | 89 | *timeout = gn->timeout; |
Pablo Neira Ayuso | 5097846 | 2012-02-28 19:13:48 +0100 | [diff] [blame] | 90 | } |
| 91 | |
| 92 | return 0; |
| 93 | } |
| 94 | |
| 95 | static int |
| 96 | generic_timeout_obj_to_nlattr(struct sk_buff *skb, const void *data) |
| 97 | { |
| 98 | const unsigned int *timeout = data; |
| 99 | |
David S. Miller | f577694 | 2012-04-01 18:52:31 -0400 | [diff] [blame] | 100 | if (nla_put_be32(skb, CTA_TIMEOUT_GENERIC_TIMEOUT, htonl(*timeout / HZ))) |
| 101 | goto nla_put_failure; |
Pablo Neira Ayuso | 5097846 | 2012-02-28 19:13:48 +0100 | [diff] [blame] | 102 | |
| 103 | return 0; |
| 104 | |
| 105 | nla_put_failure: |
| 106 | return -ENOSPC; |
| 107 | } |
| 108 | |
| 109 | static const struct nla_policy |
| 110 | generic_timeout_nla_policy[CTA_TIMEOUT_GENERIC_MAX+1] = { |
| 111 | [CTA_TIMEOUT_GENERIC_TIMEOUT] = { .type = NLA_U32 }, |
| 112 | }; |
| 113 | #endif /* CONFIG_NF_CT_NETLINK_TIMEOUT */ |
| 114 | |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 115 | #ifdef CONFIG_SYSCTL |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 116 | static struct ctl_table generic_sysctl_table[] = { |
| 117 | { |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 118 | .procname = "nf_conntrack_generic_timeout", |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 119 | .maxlen = sizeof(unsigned int), |
| 120 | .mode = 0644, |
Alexey Dobriyan | 6d9f239 | 2008-11-03 18:21:05 -0800 | [diff] [blame] | 121 | .proc_handler = proc_dointvec_jiffies, |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 122 | }, |
Eric W. Biederman | f8572d8 | 2009-11-05 13:32:03 -0800 | [diff] [blame] | 123 | { } |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 124 | }; |
Patrick McHardy | a999e68 | 2006-11-29 02:35:20 +0100 | [diff] [blame] | 125 | #ifdef CONFIG_NF_CONNTRACK_PROC_COMPAT |
| 126 | static struct ctl_table generic_compat_sysctl_table[] = { |
| 127 | { |
Patrick McHardy | a999e68 | 2006-11-29 02:35:20 +0100 | [diff] [blame] | 128 | .procname = "ip_conntrack_generic_timeout", |
Patrick McHardy | a999e68 | 2006-11-29 02:35:20 +0100 | [diff] [blame] | 129 | .maxlen = sizeof(unsigned int), |
| 130 | .mode = 0644, |
Alexey Dobriyan | 6d9f239 | 2008-11-03 18:21:05 -0800 | [diff] [blame] | 131 | .proc_handler = proc_dointvec_jiffies, |
Patrick McHardy | a999e68 | 2006-11-29 02:35:20 +0100 | [diff] [blame] | 132 | }, |
Eric W. Biederman | f8572d8 | 2009-11-05 13:32:03 -0800 | [diff] [blame] | 133 | { } |
Patrick McHardy | a999e68 | 2006-11-29 02:35:20 +0100 | [diff] [blame] | 134 | }; |
| 135 | #endif /* CONFIG_NF_CONNTRACK_PROC_COMPAT */ |
Patrick McHardy | 933a41e | 2006-11-29 02:35:18 +0100 | [diff] [blame] | 136 | #endif /* CONFIG_SYSCTL */ |
| 137 | |
Gao feng | 22ac037 | 2012-06-21 04:36:47 +0000 | [diff] [blame] | 138 | static int generic_kmemdup_sysctl_table(struct nf_proto_net *pn, |
| 139 | struct nf_generic_net *gn) |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 140 | { |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 141 | #ifdef CONFIG_SYSCTL |
| 142 | pn->ctl_table = kmemdup(generic_sysctl_table, |
| 143 | sizeof(generic_sysctl_table), |
| 144 | GFP_KERNEL); |
| 145 | if (!pn->ctl_table) |
| 146 | return -ENOMEM; |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 147 | |
Gao feng | 22ac037 | 2012-06-21 04:36:47 +0000 | [diff] [blame] | 148 | pn->ctl_table[0].data = &gn->timeout; |
| 149 | #endif |
| 150 | return 0; |
| 151 | } |
| 152 | |
| 153 | static int generic_kmemdup_compat_sysctl_table(struct nf_proto_net *pn, |
| 154 | struct nf_generic_net *gn) |
| 155 | { |
| 156 | #ifdef CONFIG_SYSCTL |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 157 | #ifdef CONFIG_NF_CONNTRACK_PROC_COMPAT |
| 158 | pn->ctl_compat_table = kmemdup(generic_compat_sysctl_table, |
| 159 | sizeof(generic_compat_sysctl_table), |
| 160 | GFP_KERNEL); |
Gao feng | 22ac037 | 2012-06-21 04:36:47 +0000 | [diff] [blame] | 161 | if (!pn->ctl_compat_table) |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 162 | return -ENOMEM; |
Gao feng | 22ac037 | 2012-06-21 04:36:47 +0000 | [diff] [blame] | 163 | |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 164 | pn->ctl_compat_table[0].data = &gn->timeout; |
| 165 | #endif |
| 166 | #endif |
| 167 | return 0; |
| 168 | } |
| 169 | |
Gao feng | 22ac037 | 2012-06-21 04:36:47 +0000 | [diff] [blame] | 170 | static int generic_init_net(struct net *net, u_int16_t proto) |
| 171 | { |
| 172 | int ret; |
| 173 | struct nf_generic_net *gn = generic_pernet(net); |
| 174 | struct nf_proto_net *pn = &gn->pn; |
| 175 | |
| 176 | gn->timeout = nf_ct_generic_timeout; |
| 177 | |
| 178 | ret = generic_kmemdup_compat_sysctl_table(pn, gn); |
| 179 | if (ret < 0) |
| 180 | return ret; |
| 181 | |
| 182 | ret = generic_kmemdup_sysctl_table(pn, gn); |
| 183 | if (ret < 0) |
| 184 | nf_ct_kfree_compat_sysctl_table(pn); |
| 185 | |
| 186 | return ret; |
| 187 | } |
| 188 | |
Pablo Neira Ayuso | 0891147 | 2012-06-29 05:23:24 +0000 | [diff] [blame] | 189 | static struct nf_proto_net *generic_get_net_proto(struct net *net) |
| 190 | { |
| 191 | return &net->ct.nf_ct_proto.generic.pn; |
| 192 | } |
| 193 | |
Patrick McHardy | 61075af | 2007-07-14 20:48:19 -0700 | [diff] [blame] | 194 | struct nf_conntrack_l4proto nf_conntrack_l4proto_generic __read_mostly = |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 195 | { |
| 196 | .l3proto = PF_UNSPEC, |
Christoph Paasch | fe2a7ce | 2009-02-18 16:28:35 +0100 | [diff] [blame] | 197 | .l4proto = 255, |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 198 | .name = "unknown", |
| 199 | .pkt_to_tuple = generic_pkt_to_tuple, |
| 200 | .invert_tuple = generic_invert_tuple, |
| 201 | .print_tuple = generic_print_tuple, |
Pablo Neira Ayuso | 2c8503f | 2012-02-28 18:23:31 +0100 | [diff] [blame] | 202 | .packet = generic_packet, |
| 203 | .get_timeouts = generic_get_timeouts, |
| 204 | .new = generic_new, |
Pablo Neira Ayuso | 5097846 | 2012-02-28 19:13:48 +0100 | [diff] [blame] | 205 | #if IS_ENABLED(CONFIG_NF_CT_NETLINK_TIMEOUT) |
| 206 | .ctnl_timeout = { |
| 207 | .nlattr_to_obj = generic_timeout_nlattr_to_obj, |
| 208 | .obj_to_nlattr = generic_timeout_obj_to_nlattr, |
| 209 | .nlattr_max = CTA_TIMEOUT_GENERIC_MAX, |
| 210 | .obj_size = sizeof(unsigned int), |
| 211 | .nla_policy = generic_timeout_nla_policy, |
| 212 | }, |
| 213 | #endif /* CONFIG_NF_CT_NETLINK_TIMEOUT */ |
Gao feng | 15f585b | 2012-05-28 21:04:11 +0000 | [diff] [blame] | 214 | .init_net = generic_init_net, |
Pablo Neira Ayuso | 0891147 | 2012-06-29 05:23:24 +0000 | [diff] [blame] | 215 | .get_net_proto = generic_get_net_proto, |
Yasuyuki Kozakai | 9fb9cbb | 2005-11-09 16:38:16 -0800 | [diff] [blame] | 216 | }; |