177701Sbrian/*- 285964Sbrian * Copyright (c) 2001 Charles Mott <cm@linktel.net> 377701Sbrian * All rights reserved. 477701Sbrian * 577701Sbrian * Redistribution and use in source and binary forms, with or without 677701Sbrian * modification, are permitted provided that the following conditions 777701Sbrian * are met: 877701Sbrian * 1. Redistributions of source code must retain the above copyright 977701Sbrian * notice, this list of conditions and the following disclaimer. 1077701Sbrian * 2. Redistributions in binary form must reproduce the above copyright 1177701Sbrian * notice, this list of conditions and the following disclaimer in the 1277701Sbrian * documentation and/or other materials provided with the distribution. 1377701Sbrian * 1477701Sbrian * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 1577701Sbrian * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 1677701Sbrian * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 1777701Sbrian * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 1877701Sbrian * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 1977701Sbrian * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 2077701Sbrian * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 2177701Sbrian * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 2277701Sbrian * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 2377701Sbrian * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 2477701Sbrian * SUCH DAMAGE. 2577701Sbrian * 2677701Sbrian * $FreeBSD: releng/10.2/sys/netinet/libalias/alias_local.h 223437 2011-06-22 20:00:27Z ae $ 2777701Sbrian */ 2877701Sbrian 2974778Sbrian/* 3074778Sbrian * Alias_local.h contains the function prototypes for alias.c, 3174778Sbrian * alias_db.c, alias_util.c and alias_ftp.c, alias_irc.c (as well 3274778Sbrian * as any future add-ons). It also includes macros, globals and 3374778Sbrian * struct definitions shared by more than one alias*.c file. 3474778Sbrian * 3574778Sbrian * This include file is intended to be used only within the aliasing 3674778Sbrian * software. Outside world interfaces are defined in alias.h 3774778Sbrian * 3874778Sbrian * This software is placed into the public domain with no restrictions 3974778Sbrian * on its distribution. 4074778Sbrian * 4199207Sbrian * Initial version: August, 1996 (cjm) 4274778Sbrian * 4374778Sbrian * <updated several times by original author and Eivind Eklund> 4474778Sbrian */ 4526026Sbrian 4674778Sbrian#ifndef _ALIAS_LOCAL_H_ 4774778Sbrian#define _ALIAS_LOCAL_H_ 4844307Sbrian 49162674Spiso#include <sys/types.h> 50162674Spiso#include <sys/sysctl.h> 51124621Sphk 52162674Spiso#ifdef _KERNEL 53162674Spiso#include <sys/malloc.h> 54165243Spiso#include <sys/param.h> 55162674Spiso#include <sys/lock.h> 56165243Spiso#include <sys/mutex.h> 57165243Spiso 58145927Sglebius/* XXX: LibAliasSetTarget() uses this constant. */ 59145927Sglebius#define INADDR_NONE 0xffffffff 60188294Spiso 61188294Spiso#include <netinet/libalias/alias_sctp.h> 62188294Spiso#else 63188294Spiso#include "alias_sctp.h" 64145927Sglebius#endif 65145927Sglebius 66124621Sphk/* Sizes of input and output link tables */ 67179480Smav#define LINK_TABLE_OUT_SIZE 4001 68124621Sphk#define LINK_TABLE_IN_SIZE 4001 69124621Sphk 70223437Sae#define GET_ALIAS_PORT -1 71223437Sae#define GET_ALIAS_ID GET_ALIAS_PORT 72223437Sae 73124621Sphkstruct proxy_entry; 74124621Sphk 75124621Sphkstruct libalias { 76127094Sdes LIST_ENTRY(libalias) instancelist; 77124621Sphk 78127094Sdes int packetAliasMode; /* Mode flags */ 79127094Sdes /* - documented in alias.h */ 80124621Sphk 81127094Sdes struct in_addr aliasAddress; /* Address written onto source */ 82127094Sdes /* field of IP packet. */ 83124621Sphk 84127094Sdes struct in_addr targetAddress; /* IP address incoming packets */ 85127094Sdes /* are sent to if no aliasing */ 86127094Sdes /* link already exists */ 87124621Sphk 88127094Sdes struct in_addr nullAddress; /* Used as a dummy parameter for */ 89127094Sdes /* some function calls */ 90124621Sphk 91127094Sdes LIST_HEAD (, alias_link) linkTableOut[LINK_TABLE_OUT_SIZE]; 92127094Sdes /* Lookup table of pointers to */ 93127094Sdes /* chains of link records. Each */ 94124621Sphk 95127094Sdes LIST_HEAD (, alias_link) linkTableIn[LINK_TABLE_IN_SIZE]; 96127094Sdes /* link record is doubly indexed */ 97127094Sdes /* into input and output lookup */ 98127094Sdes /* tables. */ 99124621Sphk 100127094Sdes /* Link statistics */ 101127094Sdes int icmpLinkCount; 102127094Sdes int udpLinkCount; 103127094Sdes int tcpLinkCount; 104127094Sdes int pptpLinkCount; 105127094Sdes int protoLinkCount; 106127094Sdes int fragmentIdLinkCount; 107127094Sdes int fragmentPtrLinkCount; 108127094Sdes int sockCount; 109124621Sphk 110127094Sdes int cleanupIndex; /* Index to chain of link table */ 111127094Sdes /* being inspected for old links */ 112124621Sphk 113127094Sdes int timeStamp; /* System time in seconds for */ 114127094Sdes /* current packet */ 115124621Sphk 116127094Sdes int lastCleanupTime; /* Last time 117127094Sdes * IncrementalCleanup() */ 118127094Sdes /* was called */ 119124621Sphk 120127094Sdes int deleteAllLinks; /* If equal to zero, DeleteLink() */ 121127094Sdes /* will not remove permanent links */ 122162674Spiso 123162674Spiso /* log descriptor */ 124162674Spiso#ifdef _KERNEL 125162674Spiso char *logDesc; 126162674Spiso#else 127162674Spiso FILE *logDesc; 128145925Sglebius#endif 129162674Spiso /* statistics monitoring */ 130124621Sphk 131127094Sdes int newDefaultLink; /* Indicates if a new aliasing */ 132127094Sdes /* link has been created after a */ 133127094Sdes /* call to PacketAliasIn/Out(). */ 134124621Sphk 135124621Sphk#ifndef NO_FW_PUNCH 136127094Sdes int fireWallFD; /* File descriptor to be able to */ 137127094Sdes /* control firewall. Opened by */ 138127094Sdes /* PacketAliasSetMode on first */ 139127094Sdes /* setting the PKT_ALIAS_PUNCH_FW */ 140127094Sdes /* flag. */ 141127094Sdes int fireWallBaseNum; /* The first firewall entry 142127094Sdes * free for our use */ 143127094Sdes int fireWallNumNums; /* How many entries can we 144127094Sdes * use? */ 145127094Sdes int fireWallActiveNum; /* Which entry did we last 146127094Sdes * use? */ 147127094Sdes char *fireWallField; /* bool array for entries */ 148124621Sphk#endif 149124621Sphk 150127094Sdes unsigned int skinnyPort; /* TCP port used by the Skinny */ 151127094Sdes /* protocol. */ 152124621Sphk 153124621Sphk struct proxy_entry *proxyList; 154124621Sphk 155127094Sdes struct in_addr true_addr; /* in network byte order. */ 156127094Sdes u_short true_port; /* in host byte order. */ 157188294Spiso 158188294Spiso /* 159188294Spiso * sctp code support 160188294Spiso */ 161188294Spiso 162188294Spiso /* counts associations that have progressed to UP and not yet removed */ 163188294Spiso int sctpLinkCount; 164165243Spiso#ifdef _KERNEL 165188294Spiso /* timing queue for keeping track of association timeouts */ 166188294Spiso struct sctp_nat_timer sctpNatTimer; 167188294Spiso 168188294Spiso /* size of hash table used in this instance */ 169188294Spiso u_int sctpNatTableSize; 170188294Spiso 171188294Spiso/* 172188294Spiso * local look up table sorted by l_vtag/l_port 173188294Spiso */ 174188294Spiso LIST_HEAD(sctpNatTableL, sctp_nat_assoc) *sctpTableLocal; 175188294Spiso/* 176188294Spiso * global look up table sorted by g_vtag/g_port 177188294Spiso */ 178188294Spiso LIST_HEAD(sctpNatTableG, sctp_nat_assoc) *sctpTableGlobal; 179188294Spiso 180165243Spiso /* 181165243Spiso * avoid races in libalias: every public function has to use it. 182165243Spiso */ 183165243Spiso struct mtx mutex; 184165243Spiso#endif 185124621Sphk}; 186124621Sphk 18774778Sbrian/* Macros */ 18826026Sbrian 189165243Spiso#ifdef _KERNEL 190165243Spiso#define LIBALIAS_LOCK_INIT(l) \ 191165243Spiso mtx_init(&l->mutex, "per-instance libalias mutex", NULL, MTX_DEF) 192165243Spiso#define LIBALIAS_LOCK_ASSERT(l) mtx_assert(&l->mutex, MA_OWNED) 193165243Spiso#define LIBALIAS_LOCK(l) mtx_lock(&l->mutex) 194165243Spiso#define LIBALIAS_UNLOCK(l) mtx_unlock(&l->mutex) 195165243Spiso#define LIBALIAS_LOCK_DESTROY(l) mtx_destroy(&l->mutex) 196165243Spiso#else 197165243Spiso#define LIBALIAS_LOCK_INIT(l) 198165243Spiso#define LIBALIAS_LOCK_ASSERT(l) 199165243Spiso#define LIBALIAS_LOCK(l) 200165243Spiso#define LIBALIAS_UNLOCK(l) 201165243Spiso#define LIBALIAS_LOCK_DESTROY(l) 202165243Spiso#endif 203165243Spiso 20444307Sbrian/* 20574778Sbrian * The following macro is used to update an 20674778Sbrian * internet checksum. "delta" is a 32-bit 20774778Sbrian * accumulation of all the changes to the 20874778Sbrian * checksum (adding in new 16-bit words and 20974778Sbrian * subtracting out old words), and "cksum" 21074778Sbrian * is the checksum value to be updated. 21144307Sbrian */ 21274778Sbrian#define ADJUST_CHECKSUM(acc, cksum) \ 21374778Sbrian do { \ 21474778Sbrian acc += cksum; \ 21574778Sbrian if (acc < 0) { \ 21674778Sbrian acc = -acc; \ 21774778Sbrian acc = (acc >> 16) + (acc & 0xffff); \ 21874778Sbrian acc += acc >> 16; \ 21974778Sbrian cksum = (u_short) ~acc; \ 22074778Sbrian } else { \ 22174778Sbrian acc = (acc >> 16) + (acc & 0xffff); \ 22274778Sbrian acc += acc >> 16; \ 22374778Sbrian cksum = (u_short) acc; \ 22474778Sbrian } \ 22574778Sbrian } while (0) 22644307Sbrian 22744307Sbrian 22874778Sbrian/* Prototypes */ 22926026Sbrian 230147623Sglebius/* 231188294Spiso * SctpFunction prototypes 232188294Spiso * 233188294Spiso */ 234188294Spisovoid AliasSctpInit(struct libalias *la); 235188294Spisovoid AliasSctpTerm(struct libalias *la); 236188294Spisoint SctpAlias(struct libalias *la, struct ip *ip, int direction); 237188294Spiso 238188294Spiso/* 239147623Sglebius * We do not calculate TCP checksums when libalias is a kernel 240147623Sglebius * module, since it has no idea about checksum offloading. 241147623Sglebius * If TCP data has changed, then we just set checksum to zero, 242147623Sglebius * and caller must recalculate it himself. 243147623Sglebius * In case if libalias will edit UDP data, the same approach 244147623Sglebius * should be used. 245147623Sglebius */ 246147623Sglebius#ifndef _KERNEL 247127094Sdesu_short IpChecksum(struct ip *_pip); 248127094Sdesu_short TcpChecksum(struct ip *_pip); 249147623Sglebius#endif 250127094Sdesvoid 251127689SdesDifferentialChecksum(u_short * _cksum, void * _new, void * _old, int _n); 25226026Sbrian 25326026Sbrian/* Internal data access */ 25426026Sbrianstruct alias_link * 255223437SaeAddLink(struct libalias *la, struct in_addr src_addr, struct in_addr dst_addr, 256223437Sae struct in_addr alias_addr, u_short src_port, u_short dst_port, 257223437Sae int alias_param, int link_type); 258223437Saestruct alias_link * 259127094SdesFindIcmpIn(struct libalias *la, struct in_addr _dst_addr, struct in_addr _alias_addr, 260127094Sdes u_short _id_alias, int _create); 26126026Sbrianstruct alias_link * 262127094SdesFindIcmpOut(struct libalias *la, struct in_addr _src_addr, struct in_addr _dst_addr, 263127094Sdes u_short _id, int _create); 26426026Sbrianstruct alias_link * 265127094SdesFindFragmentIn1(struct libalias *la, struct in_addr _dst_addr, struct in_addr _alias_addr, 266127094Sdes u_short _ip_id); 26726026Sbrianstruct alias_link * 268127094SdesFindFragmentIn2(struct libalias *la, struct in_addr _dst_addr, struct in_addr _alias_addr, 269127094Sdes u_short _ip_id); 27026026Sbrianstruct alias_link * 271127094Sdes AddFragmentPtrLink(struct libalias *la, struct in_addr _dst_addr, u_short _ip_id); 27226026Sbrianstruct alias_link * 273127094Sdes FindFragmentPtr(struct libalias *la, struct in_addr _dst_addr, u_short _ip_id); 27426026Sbrianstruct alias_link * 275127094SdesFindProtoIn(struct libalias *la, struct in_addr _dst_addr, struct in_addr _alias_addr, 276127094Sdes u_char _proto); 27759356Srustruct alias_link * 278127094SdesFindProtoOut(struct libalias *la, struct in_addr _src_addr, struct in_addr _dst_addr, 279127094Sdes u_char _proto); 28059356Srustruct alias_link * 281127094SdesFindUdpTcpIn(struct libalias *la, struct in_addr _dst_addr, struct in_addr _alias_addr, 282127094Sdes u_short _dst_port, u_short _alias_port, u_char _proto, int _create); 28326026Sbrianstruct alias_link * 284127094SdesFindUdpTcpOut(struct libalias *la, struct in_addr _src_addr, struct in_addr _dst_addr, 285127094Sdes u_short _src_port, u_short _dst_port, u_char _proto, int _create); 28661861Srustruct alias_link * 287127094SdesAddPptp(struct libalias *la, struct in_addr _src_addr, struct in_addr _dst_addr, 288127094Sdes struct in_addr _alias_addr, u_int16_t _src_call_id); 28961861Srustruct alias_link * 290127094SdesFindPptpOutByCallId(struct libalias *la, struct in_addr _src_addr, 291127094Sdes struct in_addr _dst_addr, u_int16_t _src_call_id); 29263899Sarchiestruct alias_link * 293127094SdesFindPptpInByCallId(struct libalias *la, struct in_addr _dst_addr, 294127094Sdes struct in_addr _alias_addr, u_int16_t _dst_call_id); 29567966Srustruct alias_link * 296127094SdesFindPptpOutByPeerCallId(struct libalias *la, struct in_addr _src_addr, 297127094Sdes struct in_addr _dst_addr, u_int16_t _dst_call_id); 29867966Srustruct alias_link * 299127094SdesFindPptpInByPeerCallId(struct libalias *la, struct in_addr _dst_addr, 300127094Sdes struct in_addr _alias_addr, u_int16_t _alias_call_id); 30167966Srustruct alias_link * 302127094SdesFindRtspOut(struct libalias *la, struct in_addr _src_addr, struct in_addr _dst_addr, 303127094Sdes u_short _src_port, u_short _alias_port, u_char _proto); 30426026Sbrianstruct in_addr 305127094Sdes FindOriginalAddress(struct libalias *la, struct in_addr _alias_addr); 30626026Sbrianstruct in_addr 307127094Sdes FindAliasAddress(struct libalias *la, struct in_addr _original_addr); 308188294Spisostruct in_addr 309188294SpisoFindSctpRedirectAddress(struct libalias *la, struct sctp_nat_msg *sm); 31026026Sbrian 31126026Sbrian/* External data access/modification */ 312127094Sdesint 313127094SdesFindNewPortGroup(struct libalias *la, struct in_addr _dst_addr, struct in_addr _alias_addr, 314127094Sdes u_short _src_port, u_short _dst_port, u_short _port_count, 315127094Sdes u_char _proto, u_char _align); 316131614Sdesvoid GetFragmentAddr(struct alias_link *_lnk, struct in_addr *_src_addr); 317131614Sdesvoid SetFragmentAddr(struct alias_link *_lnk, struct in_addr _src_addr); 318131614Sdesvoid GetFragmentPtr(struct alias_link *_lnk, char **_fptr); 319131614Sdesvoid SetFragmentPtr(struct alias_link *_lnk, char *fptr); 320131614Sdesvoid SetStateIn(struct alias_link *_lnk, int _state); 321131614Sdesvoid SetStateOut(struct alias_link *_lnk, int _state); 322131614Sdesint GetStateIn (struct alias_link *_lnk); 323131614Sdesint GetStateOut(struct alias_link *_lnk); 32474778Sbrianstruct in_addr 325131614Sdes GetOriginalAddress(struct alias_link *_lnk); 32674778Sbrianstruct in_addr 327131614Sdes GetDestAddress(struct alias_link *_lnk); 32874778Sbrianstruct in_addr 329131614Sdes GetAliasAddress(struct alias_link *_lnk); 33074778Sbrianstruct in_addr 331127094Sdes GetDefaultAliasAddress(struct libalias *la); 332127094Sdesvoid SetDefaultAliasAddress(struct libalias *la, struct in_addr _alias_addr); 333131614Sdesu_short GetOriginalPort(struct alias_link *_lnk); 334131614Sdesu_short GetAliasPort(struct alias_link *_lnk); 33574778Sbrianstruct in_addr 336131614Sdes GetProxyAddress(struct alias_link *_lnk); 337131614Sdesvoid SetProxyAddress(struct alias_link *_lnk, struct in_addr _addr); 338131614Sdesu_short GetProxyPort(struct alias_link *_lnk); 339131614Sdesvoid SetProxyPort(struct alias_link *_lnk, u_short _port); 340131614Sdesvoid SetAckModified(struct alias_link *_lnk); 341131614Sdesint GetAckModified(struct alias_link *_lnk); 342176884Spisoint GetDeltaAckIn(u_long, struct alias_link *_lnk); 343176884Spisoint GetDeltaSeqOut(u_long, struct alias_link *lnk); 344176884Spisovoid AddSeq(struct alias_link *lnk, int delta, u_int ip_hl, 345176884Spiso u_short ip_len, u_long th_seq, u_int th_off); 346131614Sdesvoid SetExpire (struct alias_link *_lnk, int _expire); 347127094Sdesvoid ClearCheckNewLink(struct libalias *la); 348131614Sdesvoid SetProtocolFlags(struct alias_link *_lnk, int _pflags); 349131614Sdesint GetProtocolFlags(struct alias_link *_lnk); 350131614Sdesvoid SetDestCallId(struct alias_link *_lnk, u_int16_t _cid); 351127094Sdes 35236711Sbrian#ifndef NO_FW_PUNCH 353131614Sdesvoid PunchFWHole(struct alias_link *_lnk); 354127094Sdes 35536711Sbrian#endif 35626026Sbrian 35726026Sbrian/* Housekeeping function */ 358127094Sdesvoid HouseKeeping(struct libalias *); 35926026Sbrian 36026026Sbrian/* Tcp specfic routines */ 36174778Sbrian/* lint -save -library Suppress flexelint warnings */ 36244307Sbrian 36344307Sbrian/* Transparent proxy routines */ 364127094Sdesint 365176884SpisoProxyCheck(struct libalias *la, struct in_addr *proxy_server_addr, 366176884Spiso u_short * proxy_server_port, struct in_addr src_addr, 367176884Spiso struct in_addr dst_addr, u_short dst_port, u_char ip_p); 368127094Sdesvoid 369131614SdesProxyModify(struct libalias *la, struct alias_link *_lnk, struct ip *_pip, 370127094Sdes int _maxpacketsize, int _proxy_type); 37136321Samurai 37232377Seivindenum alias_tcp_state { 37374778Sbrian ALIAS_TCP_STATE_NOT_CONNECTED, 37474778Sbrian ALIAS_TCP_STATE_CONNECTED, 37574778Sbrian ALIAS_TCP_STATE_DISCONNECTED 37632377Seivind}; 37774778Sbrian 378131699Sdes#if defined(_NETINET_IP_H_) 379131699Sdesstatic __inline void * 380131699Sdesip_next(struct ip *iphdr) 381131699Sdes{ 382131699Sdes char *p = (char *)iphdr; 383131699Sdes return (&p[iphdr->ip_hl * 4]); 384131699Sdes} 385131699Sdes#endif 386131699Sdes 387131699Sdes#if defined(_NETINET_TCP_H_) 388131699Sdesstatic __inline void * 389131699Sdestcp_next(struct tcphdr *tcphdr) 390131699Sdes{ 391131699Sdes char *p = (char *)tcphdr; 392131699Sdes return (&p[tcphdr->th_off * 4]); 393131699Sdes} 394131699Sdes#endif 395131699Sdes 396131699Sdes#if defined(_NETINET_UDP_H_) 397131699Sdesstatic __inline void * 398131699Sdesudp_next(struct udphdr *udphdr) 399131699Sdes{ 400131699Sdes return ((void *)(udphdr + 1)); 401131699Sdes} 402131699Sdes#endif 403131699Sdes 404127094Sdes#endif /* !_ALIAS_LOCAL_H_ */ 405