Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 1 | /* |
| 2 | * connection tracking expectations. |
| 3 | */ |
| 4 | |
| 5 | #ifndef _NF_CONNTRACK_EXPECT_H |
| 6 | #define _NF_CONNTRACK_EXPECT_H |
Daniel Borkmann | 308ac91 | 2015-08-08 21:40:01 +0200 | [diff] [blame] | 7 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 8 | #include <net/netfilter/nf_conntrack.h> |
Daniel Borkmann | 308ac91 | 2015-08-08 21:40:01 +0200 | [diff] [blame] | 9 | #include <net/netfilter/nf_conntrack_zones.h> |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 10 | |
Patrick McHardy | a71c085 | 2007-07-07 22:33:47 -0700 | [diff] [blame] | 11 | extern unsigned int nf_ct_expect_hsize; |
Patrick McHardy | f264a7d | 2007-07-07 22:36:24 -0700 | [diff] [blame] | 12 | extern unsigned int nf_ct_expect_max; |
Florian Westphal | 0a93aae | 2016-05-06 00:51:49 +0200 | [diff] [blame] | 13 | extern struct hlist_head *nf_ct_expect_hash; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 14 | |
Eric Dumazet | fd2c3ef | 2009-11-03 03:26:03 +0000 | [diff] [blame] | 15 | struct nf_conntrack_expect { |
Patrick McHardy | b560580 | 2007-07-07 22:35:56 -0700 | [diff] [blame] | 16 | /* Conntrack expectation list member */ |
| 17 | struct hlist_node lnode; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 18 | |
Patrick McHardy | a71c085 | 2007-07-07 22:33:47 -0700 | [diff] [blame] | 19 | /* Hash member */ |
| 20 | struct hlist_node hnode; |
| 21 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 22 | /* We expect this tuple, with the following mask */ |
Patrick McHardy | d4156e8 | 2007-07-07 22:31:32 -0700 | [diff] [blame] | 23 | struct nf_conntrack_tuple tuple; |
| 24 | struct nf_conntrack_tuple_mask mask; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 25 | |
| 26 | /* Function to call after setup and insertion */ |
| 27 | void (*expectfn)(struct nf_conn *new, |
| 28 | struct nf_conntrack_expect *this); |
| 29 | |
Patrick McHardy | 9457d85 | 2006-12-02 22:05:25 -0800 | [diff] [blame] | 30 | /* Helper to assign to new connection */ |
| 31 | struct nf_conntrack_helper *helper; |
| 32 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 33 | /* The conntrack of the master connection */ |
| 34 | struct nf_conn *master; |
| 35 | |
| 36 | /* Timer function; deletes the expectation. */ |
| 37 | struct timer_list timeout; |
| 38 | |
| 39 | /* Usage count. */ |
| 40 | atomic_t use; |
| 41 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 42 | /* Flags */ |
| 43 | unsigned int flags; |
| 44 | |
Patrick McHardy | 6002f266 | 2008-03-25 20:09:15 -0700 | [diff] [blame] | 45 | /* Expectation class */ |
| 46 | unsigned int class; |
| 47 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 48 | #ifdef CONFIG_NF_NAT_NEEDED |
Patrick McHardy | c7232c9 | 2012-08-26 19:14:06 +0200 | [diff] [blame] | 49 | union nf_inet_addr saved_addr; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 50 | /* This is the original per-proto part, used to map the |
| 51 | * expected connection the way the recipient expects. */ |
Jozsef Kadlecsik | 5b1158e | 2006-12-02 22:07:13 -0800 | [diff] [blame] | 52 | union nf_conntrack_man_proto saved_proto; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 53 | /* Direction relative to the master connection. */ |
| 54 | enum ip_conntrack_dir dir; |
| 55 | #endif |
Patrick McHardy | 7d0742d | 2008-01-31 04:38:19 -0800 | [diff] [blame] | 56 | |
| 57 | struct rcu_head rcu; |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 58 | }; |
| 59 | |
Alexey Dobriyan | 9b03f38 | 2008-10-08 11:35:03 +0200 | [diff] [blame] | 60 | static inline struct net *nf_ct_exp_net(struct nf_conntrack_expect *exp) |
| 61 | { |
Alexey Dobriyan | 857b409 | 2010-02-12 06:24:46 +0100 | [diff] [blame] | 62 | return nf_ct_net(exp->master); |
Alexey Dobriyan | 9b03f38 | 2008-10-08 11:35:03 +0200 | [diff] [blame] | 63 | } |
| 64 | |
Pablo Neira Ayuso | 3a8fc53 | 2012-01-15 16:34:08 +0100 | [diff] [blame] | 65 | #define NF_CT_EXP_POLICY_NAME_LEN 16 |
| 66 | |
Eric Dumazet | fd2c3ef | 2009-11-03 03:26:03 +0000 | [diff] [blame] | 67 | struct nf_conntrack_expect_policy { |
Patrick McHardy | 6002f266 | 2008-03-25 20:09:15 -0700 | [diff] [blame] | 68 | unsigned int max_expected; |
| 69 | unsigned int timeout; |
Pablo Neira Ayuso | 3a8fc53 | 2012-01-15 16:34:08 +0100 | [diff] [blame] | 70 | char name[NF_CT_EXP_POLICY_NAME_LEN]; |
Patrick McHardy | 6002f266 | 2008-03-25 20:09:15 -0700 | [diff] [blame] | 71 | }; |
| 72 | |
| 73 | #define NF_CT_EXPECT_CLASS_DEFAULT 0 |
| 74 | |
Gao feng | 83b4dbe | 2013-01-21 22:10:25 +0000 | [diff] [blame] | 75 | int nf_conntrack_expect_pernet_init(struct net *net); |
| 76 | void nf_conntrack_expect_pernet_fini(struct net *net); |
| 77 | |
| 78 | int nf_conntrack_expect_init(void); |
| 79 | void nf_conntrack_expect_fini(void); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 80 | |
| 81 | struct nf_conntrack_expect * |
Daniel Borkmann | 308ac91 | 2015-08-08 21:40:01 +0200 | [diff] [blame] | 82 | __nf_ct_expect_find(struct net *net, |
| 83 | const struct nf_conntrack_zone *zone, |
Patrick McHardy | 5d0aa2c | 2010-02-15 18:13:33 +0100 | [diff] [blame] | 84 | const struct nf_conntrack_tuple *tuple); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 85 | |
| 86 | struct nf_conntrack_expect * |
Daniel Borkmann | 308ac91 | 2015-08-08 21:40:01 +0200 | [diff] [blame] | 87 | nf_ct_expect_find_get(struct net *net, |
| 88 | const struct nf_conntrack_zone *zone, |
Patrick McHardy | 5d0aa2c | 2010-02-15 18:13:33 +0100 | [diff] [blame] | 89 | const struct nf_conntrack_tuple *tuple); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 90 | |
| 91 | struct nf_conntrack_expect * |
Daniel Borkmann | 308ac91 | 2015-08-08 21:40:01 +0200 | [diff] [blame] | 92 | nf_ct_find_expectation(struct net *net, |
| 93 | const struct nf_conntrack_zone *zone, |
Patrick McHardy | 5d0aa2c | 2010-02-15 18:13:33 +0100 | [diff] [blame] | 94 | const struct nf_conntrack_tuple *tuple); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 95 | |
Pablo Neira Ayuso | ebbf41d | 2010-10-19 10:19:06 +0200 | [diff] [blame] | 96 | void nf_ct_unlink_expect_report(struct nf_conntrack_expect *exp, |
Patrick McHardy | ec464e5 | 2013-04-17 06:47:08 +0000 | [diff] [blame] | 97 | u32 portid, int report); |
Pablo Neira Ayuso | ebbf41d | 2010-10-19 10:19:06 +0200 | [diff] [blame] | 98 | static inline void nf_ct_unlink_expect(struct nf_conntrack_expect *exp) |
| 99 | { |
| 100 | nf_ct_unlink_expect_report(exp, 0, 0); |
| 101 | } |
| 102 | |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 103 | void nf_ct_remove_expectations(struct nf_conn *ct); |
Patrick McHardy | 6823645 | 2007-07-07 22:30:49 -0700 | [diff] [blame] | 104 | void nf_ct_unexpect_related(struct nf_conntrack_expect *exp); |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 105 | |
| 106 | /* Allocate space for an expectation: this is mandatory before calling |
Patrick McHardy | 6823645 | 2007-07-07 22:30:49 -0700 | [diff] [blame] | 107 | nf_ct_expect_related. You will have to call put afterwards. */ |
| 108 | struct nf_conntrack_expect *nf_ct_expect_alloc(struct nf_conn *me); |
Jan Engelhardt | 76108ce | 2008-10-08 11:35:00 +0200 | [diff] [blame] | 109 | void nf_ct_expect_init(struct nf_conntrack_expect *, unsigned int, u_int8_t, |
Patrick McHardy | 1d9d752 | 2008-03-25 20:07:58 -0700 | [diff] [blame] | 110 | const union nf_inet_addr *, |
| 111 | const union nf_inet_addr *, |
| 112 | u_int8_t, const __be16 *, const __be16 *); |
Patrick McHardy | 6823645 | 2007-07-07 22:30:49 -0700 | [diff] [blame] | 113 | void nf_ct_expect_put(struct nf_conntrack_expect *exp); |
Pablo Neira Ayuso | 19abb7b | 2008-11-18 11:56:20 +0100 | [diff] [blame] | 114 | int nf_ct_expect_related_report(struct nf_conntrack_expect *expect, |
Patrick McHardy | ec464e5 | 2013-04-17 06:47:08 +0000 | [diff] [blame] | 115 | u32 portid, int report); |
Pablo Neira Ayuso | 8373167 | 2009-04-06 17:47:20 +0200 | [diff] [blame] | 116 | static inline int nf_ct_expect_related(struct nf_conntrack_expect *expect) |
| 117 | { |
| 118 | return nf_ct_expect_related_report(expect, 0, 0); |
| 119 | } |
Martin Josefsson | 77ab9cf | 2006-11-29 02:34:58 +0100 | [diff] [blame] | 120 | |
| 121 | #endif /*_NF_CONNTRACK_EXPECT_H*/ |
| 122 | |