1223637Sbz/* $OpenBSD: pfctl.c,v 1.278 2008/08/31 20:18:17 jmc Exp $ */ 2126353Smlaier 3330449Seadler/*- 4330449Seadler * SPDX-License-Identifier: BSD-2-Clause 5330449Seadler * 6126353Smlaier * Copyright (c) 2001 Daniel Hartmeier 7130617Smlaier * Copyright (c) 2002,2003 Henning Brauer 8126353Smlaier * All rights reserved. 9126353Smlaier * 10126353Smlaier * Redistribution and use in source and binary forms, with or without 11126353Smlaier * modification, are permitted provided that the following conditions 12126353Smlaier * are met: 13126353Smlaier * 14126353Smlaier * - Redistributions of source code must retain the above copyright 15126353Smlaier * notice, this list of conditions and the following disclaimer. 16126353Smlaier * - Redistributions in binary form must reproduce the above 17126353Smlaier * copyright notice, this list of conditions and the following 18126353Smlaier * disclaimer in the documentation and/or other materials provided 19126353Smlaier * with the distribution. 20126353Smlaier * 21126353Smlaier * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 22126353Smlaier * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 23126353Smlaier * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 24126353Smlaier * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE 25126353Smlaier * COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, 26126353Smlaier * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, 27126353Smlaier * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 28126353Smlaier * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER 29126353Smlaier * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 30126353Smlaier * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN 31126353Smlaier * ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 32126353Smlaier * POSSIBILITY OF SUCH DAMAGE. 33126353Smlaier * 34126353Smlaier */ 35126353Smlaier 36127082Sobrien#include <sys/cdefs.h> 37127082Sobrien__FBSDID("$FreeBSD: stable/11/sbin/pfctl/pfctl.c 343229 2019-01-20 22:01:41Z kp $"); 38127082Sobrien 39126353Smlaier#include <sys/types.h> 40126353Smlaier#include <sys/ioctl.h> 41126353Smlaier#include <sys/socket.h> 42145840Smlaier#include <sys/stat.h> 43223637Sbz#include <sys/endian.h> 44223637Sbz 45126353Smlaier#include <net/if.h> 46126353Smlaier#include <netinet/in.h> 47126353Smlaier#include <net/pfvar.h> 48126353Smlaier#include <arpa/inet.h> 49281613Sglebius#include <net/altq/altq.h> 50171172Smlaier#include <sys/sysctl.h> 51126353Smlaier 52126353Smlaier#include <err.h> 53126353Smlaier#include <errno.h> 54126353Smlaier#include <fcntl.h> 55126353Smlaier#include <limits.h> 56126353Smlaier#include <netdb.h> 57262799Sglebius#include <stdint.h> 58126353Smlaier#include <stdio.h> 59126353Smlaier#include <stdlib.h> 60126353Smlaier#include <string.h> 61126353Smlaier#include <unistd.h> 62126353Smlaier 63126353Smlaier#include "pfctl_parser.h" 64126353Smlaier#include "pfctl.h" 65126353Smlaier 66126353Smlaiervoid usage(void); 67126353Smlaierint pfctl_enable(int, int); 68126353Smlaierint pfctl_disable(int, int); 69126353Smlaierint pfctl_clear_stats(int, int); 70333181Skpint pfctl_get_skip_ifaces(void); 71333181Skpint pfctl_check_skip_ifaces(char *); 72338390Skpint pfctl_adjust_skip_ifaces(struct pfctl *); 73145840Smlaierint pfctl_clear_interface_flags(int, int); 74145840Smlaierint pfctl_clear_rules(int, int, char *); 75145840Smlaierint pfctl_clear_nat(int, int, char *); 76126353Smlaierint pfctl_clear_altq(int, int); 77130617Smlaierint pfctl_clear_src_nodes(int, int); 78130617Smlaierint pfctl_clear_states(int, const char *, int); 79171172Smlaiervoid pfctl_addrprefix(char *, struct pf_addr *); 80171172Smlaierint pfctl_kill_src_nodes(int, const char *, int); 81223637Sbzint pfctl_net_kill_states(int, const char *, int); 82223637Sbzint pfctl_label_kill_states(int, const char *, int); 83223637Sbzint pfctl_id_kill_states(int, const char *, int); 84145840Smlaiervoid pfctl_init_options(struct pfctl *); 85145840Smlaierint pfctl_load_options(struct pfctl *); 86145840Smlaierint pfctl_load_limit(struct pfctl *, unsigned int, unsigned int); 87145840Smlaierint pfctl_load_timeout(struct pfctl *, unsigned int, unsigned int); 88145840Smlaierint pfctl_load_debug(struct pfctl *, unsigned int); 89145840Smlaierint pfctl_load_logif(struct pfctl *, char *); 90145840Smlaierint pfctl_load_hostid(struct pfctl *, unsigned int); 91126353Smlaierint pfctl_get_pool(int, struct pf_pool *, u_int32_t, u_int32_t, int, 92145840Smlaier char *); 93126353Smlaiervoid pfctl_print_rule_counters(struct pf_rule *, int); 94171172Smlaierint pfctl_show_rules(int, char *, int, enum pfctl_show, char *, int); 95145840Smlaierint pfctl_show_nat(int, int, char *); 96130617Smlaierint pfctl_show_src_nodes(int, int); 97130617Smlaierint pfctl_show_states(int, const char *, int); 98130617Smlaierint pfctl_show_status(int, int); 99335058Skpint pfctl_show_running(int); 100130617Smlaierint pfctl_show_timeouts(int, int); 101130617Smlaierint pfctl_show_limits(int, int); 102145840Smlaiervoid pfctl_debug(int, u_int32_t, int); 103126353Smlaierint pfctl_test_altqsupport(int, int); 104126353Smlaierint pfctl_show_anchors(int, int, char *); 105171172Smlaierint pfctl_ruleset_trans(struct pfctl *, char *, struct pf_anchor *); 106171172Smlaierint pfctl_load_ruleset(struct pfctl *, char *, 107171172Smlaier struct pf_ruleset *, int, int); 108171172Smlaierint pfctl_load_rule(struct pfctl *, char *, struct pf_rule *, int); 109126353Smlaierconst char *pfctl_lookup_option(char *, const char **); 110126353Smlaier 111171172Smlaierstruct pf_anchor_global pf_anchors; 112171172Smlaierstruct pf_anchor pf_main_anchor; 113333181Skpstatic struct pfr_buffer skip_b; 114171172Smlaier 115126353Smlaierconst char *clearopt; 116126353Smlaierchar *rulesopt; 117126353Smlaierconst char *showopt; 118126353Smlaierconst char *debugopt; 119126353Smlaierchar *anchoropt; 120171172Smlaierconst char *optiopt = NULL; 121130617Smlaierchar *pf_device = "/dev/pf"; 122130617Smlaierchar *ifaceopt; 123126353Smlaierchar *tableopt; 124126353Smlaierconst char *tblcmdopt; 125171172Smlaierint src_node_killers; 126171172Smlaierchar *src_node_kill[2]; 127126353Smlaierint state_killers; 128126353Smlaierchar *state_kill[2]; 129126353Smlaierint loadopt; 130126353Smlaierint altqsupport; 131126353Smlaier 132126353Smlaierint dev = -1; 133130617Smlaierint first_title = 1; 134130617Smlaierint labels = 0; 135126353Smlaier 136171172Smlaier#define INDENT(d, o) do { \ 137171172Smlaier if (o) { \ 138171172Smlaier int i; \ 139171172Smlaier for (i=0; i < d; i++) \ 140171172Smlaier printf(" "); \ 141171172Smlaier } \ 142171172Smlaier } while (0); \ 143171172Smlaier 144171172Smlaier 145126353Smlaierstatic const struct { 146126353Smlaier const char *name; 147126353Smlaier int index; 148126353Smlaier} pf_limits[] = { 149171172Smlaier { "states", PF_LIMIT_STATES }, 150171172Smlaier { "src-nodes", PF_LIMIT_SRC_NODES }, 151171172Smlaier { "frags", PF_LIMIT_FRAGS }, 152171172Smlaier { "table-entries", PF_LIMIT_TABLE_ENTRIES }, 153171172Smlaier { NULL, 0 } 154126353Smlaier}; 155126353Smlaier 156126353Smlaierstruct pf_hint { 157126353Smlaier const char *name; 158126353Smlaier int timeout; 159126353Smlaier}; 160126353Smlaierstatic const struct pf_hint pf_hint_normal[] = { 161126353Smlaier { "tcp.first", 2 * 60 }, 162126353Smlaier { "tcp.opening", 30 }, 163126353Smlaier { "tcp.established", 24 * 60 * 60 }, 164126353Smlaier { "tcp.closing", 15 * 60 }, 165126353Smlaier { "tcp.finwait", 45 }, 166126353Smlaier { "tcp.closed", 90 }, 167145840Smlaier { "tcp.tsdiff", 30 }, 168126353Smlaier { NULL, 0 } 169126353Smlaier}; 170126353Smlaierstatic const struct pf_hint pf_hint_satellite[] = { 171126353Smlaier { "tcp.first", 3 * 60 }, 172126353Smlaier { "tcp.opening", 30 + 5 }, 173126353Smlaier { "tcp.established", 24 * 60 * 60 }, 174126353Smlaier { "tcp.closing", 15 * 60 + 5 }, 175126353Smlaier { "tcp.finwait", 45 + 5 }, 176126353Smlaier { "tcp.closed", 90 + 5 }, 177145840Smlaier { "tcp.tsdiff", 60 }, 178126353Smlaier { NULL, 0 } 179126353Smlaier}; 180126353Smlaierstatic const struct pf_hint pf_hint_conservative[] = { 181126353Smlaier { "tcp.first", 60 * 60 }, 182126353Smlaier { "tcp.opening", 15 * 60 }, 183126353Smlaier { "tcp.established", 5 * 24 * 60 * 60 }, 184126353Smlaier { "tcp.closing", 60 * 60 }, 185126353Smlaier { "tcp.finwait", 10 * 60 }, 186126353Smlaier { "tcp.closed", 3 * 60 }, 187145840Smlaier { "tcp.tsdiff", 60 }, 188126353Smlaier { NULL, 0 } 189126353Smlaier}; 190126353Smlaierstatic const struct pf_hint pf_hint_aggressive[] = { 191126353Smlaier { "tcp.first", 30 }, 192126353Smlaier { "tcp.opening", 5 }, 193126353Smlaier { "tcp.established", 5 * 60 * 60 }, 194126353Smlaier { "tcp.closing", 60 }, 195126353Smlaier { "tcp.finwait", 30 }, 196126353Smlaier { "tcp.closed", 30 }, 197145840Smlaier { "tcp.tsdiff", 10 }, 198126353Smlaier { NULL, 0 } 199126353Smlaier}; 200126353Smlaier 201126353Smlaierstatic const struct { 202126353Smlaier const char *name; 203126353Smlaier const struct pf_hint *hint; 204126353Smlaier} pf_hints[] = { 205126353Smlaier { "normal", pf_hint_normal }, 206126353Smlaier { "satellite", pf_hint_satellite }, 207126353Smlaier { "high-latency", pf_hint_satellite }, 208126353Smlaier { "conservative", pf_hint_conservative }, 209126353Smlaier { "aggressive", pf_hint_aggressive }, 210126353Smlaier { NULL, NULL } 211126353Smlaier}; 212126353Smlaier 213126353Smlaierstatic const char *clearopt_list[] = { 214130617Smlaier "nat", "queue", "rules", "Sources", 215223637Sbz "states", "info", "Tables", "osfp", "all", NULL 216126353Smlaier}; 217126353Smlaier 218126353Smlaierstatic const char *showopt_list[] = { 219223637Sbz "nat", "queue", "rules", "Anchors", "Sources", "states", "info", 220130617Smlaier "Interfaces", "labels", "timeouts", "memory", "Tables", "osfp", 221335058Skp "Running", "all", NULL 222126353Smlaier}; 223126353Smlaier 224126353Smlaierstatic const char *tblcmdopt_list[] = { 225126353Smlaier "kill", "flush", "add", "delete", "load", "replace", "show", 226171172Smlaier "test", "zero", "expire", NULL 227126353Smlaier}; 228126353Smlaier 229126353Smlaierstatic const char *debugopt_list[] = { 230126353Smlaier "none", "urgent", "misc", "loud", NULL 231126353Smlaier}; 232126353Smlaier 233171172Smlaierstatic const char *optiopt_list[] = { 234223637Sbz "none", "basic", "profile", NULL 235171172Smlaier}; 236126353Smlaier 237126353Smlaiervoid 238126353Smlaierusage(void) 239126353Smlaier{ 240126353Smlaier extern char *__progname; 241126353Smlaier 242258484Sglebius fprintf(stderr, 243258484Sglebius"usage: %s [-AdeghmNnOPqRrvz] [-a anchor] [-D macro=value] [-F modifier]\n" 244258484Sglebius "\t[-f file] [-i interface] [-K host | network]\n" 245258484Sglebius "\t[-k host | network | label | id] [-o level] [-p device]\n" 246258484Sglebius "\t[-s modifier] [-t table -T command [address ...]] [-x level]\n", 247258484Sglebius __progname); 248258484Sglebius 249126353Smlaier exit(1); 250126353Smlaier} 251126353Smlaier 252126353Smlaierint 253126353Smlaierpfctl_enable(int dev, int opts) 254126353Smlaier{ 255126353Smlaier if (ioctl(dev, DIOCSTART)) { 256126353Smlaier if (errno == EEXIST) 257126353Smlaier errx(1, "pf already enabled"); 258126355Smlaier else if (errno == ESRCH) 259126355Smlaier errx(1, "pfil registeration failed"); 260126353Smlaier else 261126353Smlaier err(1, "DIOCSTART"); 262126353Smlaier } 263126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 264126353Smlaier fprintf(stderr, "pf enabled\n"); 265126353Smlaier 266126353Smlaier if (altqsupport && ioctl(dev, DIOCSTARTALTQ)) 267126353Smlaier if (errno != EEXIST) 268126353Smlaier err(1, "DIOCSTARTALTQ"); 269126353Smlaier 270126353Smlaier return (0); 271126353Smlaier} 272126353Smlaier 273126353Smlaierint 274126353Smlaierpfctl_disable(int dev, int opts) 275126353Smlaier{ 276126353Smlaier if (ioctl(dev, DIOCSTOP)) { 277126353Smlaier if (errno == ENOENT) 278126353Smlaier errx(1, "pf not enabled"); 279126353Smlaier else 280126353Smlaier err(1, "DIOCSTOP"); 281126353Smlaier } 282126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 283126353Smlaier fprintf(stderr, "pf disabled\n"); 284126353Smlaier 285126353Smlaier if (altqsupport && ioctl(dev, DIOCSTOPALTQ)) 286126353Smlaier if (errno != ENOENT) 287126353Smlaier err(1, "DIOCSTOPALTQ"); 288126353Smlaier 289126353Smlaier return (0); 290126353Smlaier} 291126353Smlaier 292126353Smlaierint 293126353Smlaierpfctl_clear_stats(int dev, int opts) 294126353Smlaier{ 295126353Smlaier if (ioctl(dev, DIOCCLRSTATUS)) 296126353Smlaier err(1, "DIOCCLRSTATUS"); 297126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 298126353Smlaier fprintf(stderr, "pf: statistics cleared\n"); 299126353Smlaier return (0); 300126353Smlaier} 301126353Smlaier 302126353Smlaierint 303333181Skppfctl_get_skip_ifaces(void) 304333181Skp{ 305333181Skp bzero(&skip_b, sizeof(skip_b)); 306333181Skp skip_b.pfrb_type = PFRB_IFACES; 307333181Skp for (;;) { 308333181Skp pfr_buf_grow(&skip_b, skip_b.pfrb_size); 309333181Skp skip_b.pfrb_size = skip_b.pfrb_msize; 310333181Skp if (pfi_get_ifaces(NULL, skip_b.pfrb_caddr, &skip_b.pfrb_size)) 311333181Skp err(1, "pfi_get_ifaces"); 312333181Skp if (skip_b.pfrb_size <= skip_b.pfrb_msize) 313333181Skp break; 314333181Skp } 315333181Skp return (0); 316333181Skp} 317333181Skp 318333181Skpint 319333181Skppfctl_check_skip_ifaces(char *ifname) 320333181Skp{ 321333181Skp struct pfi_kif *p; 322338390Skp struct node_host *h = NULL, *n = NULL; 323333181Skp 324338390Skp PFRB_FOREACH(p, &skip_b) { 325338390Skp if (!strcmp(ifname, p->pfik_name) && 326338390Skp (p->pfik_flags & PFI_IFLAG_SKIP)) 327333181Skp p->pfik_flags &= ~PFI_IFLAG_SKIP; 328338390Skp if (!strcmp(ifname, p->pfik_name) && p->pfik_group != NULL) { 329338390Skp if ((h = ifa_grouplookup(p->pfik_name, 0)) == NULL) 330338390Skp continue; 331338390Skp 332338390Skp for (n = h; n != NULL; n = n->next) { 333338390Skp if (p->pfik_ifp == NULL) 334338390Skp continue; 335338390Skp if (strncmp(p->pfik_name, ifname, IFNAMSIZ)) 336338390Skp continue; 337338390Skp 338338390Skp p->pfik_flags &= ~PFI_IFLAG_SKIP; 339338390Skp } 340338390Skp } 341338390Skp } 342333181Skp return (0); 343333181Skp} 344333181Skp 345333181Skpint 346338390Skppfctl_adjust_skip_ifaces(struct pfctl *pf) 347333181Skp{ 348338390Skp struct pfi_kif *p, *pp; 349338390Skp struct node_host *h = NULL, *n = NULL; 350333181Skp 351338390Skp PFRB_FOREACH(p, &skip_b) { 352338390Skp if (p->pfik_group == NULL || !(p->pfik_flags & PFI_IFLAG_SKIP)) 353338390Skp continue; 354338390Skp 355338390Skp pfctl_set_interface_flags(pf, p->pfik_name, PFI_IFLAG_SKIP, 0); 356338390Skp if ((h = ifa_grouplookup(p->pfik_name, 0)) == NULL) 357338390Skp continue; 358338390Skp 359338390Skp for (n = h; n != NULL; n = n->next) 360338390Skp PFRB_FOREACH(pp, &skip_b) { 361338390Skp if (pp->pfik_ifp == NULL) 362338390Skp continue; 363338390Skp 364338390Skp if (strncmp(pp->pfik_name, n->ifname, IFNAMSIZ)) 365338390Skp continue; 366338390Skp 367338390Skp if (!(pp->pfik_flags & PFI_IFLAG_SKIP)) 368338390Skp pfctl_set_interface_flags(pf, 369338390Skp pp->pfik_name, PFI_IFLAG_SKIP, 1); 370338390Skp if (pp->pfik_flags & PFI_IFLAG_SKIP) 371338390Skp pp->pfik_flags &= ~PFI_IFLAG_SKIP; 372338390Skp } 373338390Skp } 374338390Skp 375338390Skp PFRB_FOREACH(p, &skip_b) { 376338390Skp if (p->pfik_ifp == NULL || ! (p->pfik_flags & PFI_IFLAG_SKIP)) 377338390Skp continue; 378338390Skp 379338390Skp pfctl_set_interface_flags(pf, p->pfik_name, PFI_IFLAG_SKIP, 0); 380338390Skp } 381338390Skp 382333181Skp return (0); 383333181Skp} 384333181Skp 385333181Skpint 386145840Smlaierpfctl_clear_interface_flags(int dev, int opts) 387126353Smlaier{ 388145840Smlaier struct pfioc_iface pi; 389126353Smlaier 390145840Smlaier if ((opts & PF_OPT_NOACTION) == 0) { 391145840Smlaier bzero(&pi, sizeof(pi)); 392171172Smlaier pi.pfiio_flags = PFI_IFLAG_SKIP; 393126353Smlaier 394145840Smlaier if (ioctl(dev, DIOCCLRIFFLAG, &pi)) 395145840Smlaier err(1, "DIOCCLRIFFLAG"); 396126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 397145840Smlaier fprintf(stderr, "pf: interface flags reset\n"); 398126353Smlaier } 399145840Smlaier return (0); 400145840Smlaier} 401145840Smlaier 402145840Smlaierint 403145840Smlaierpfctl_clear_rules(int dev, int opts, char *anchorname) 404145840Smlaier{ 405145840Smlaier struct pfr_buffer t; 406145840Smlaier 407130617Smlaier memset(&t, 0, sizeof(t)); 408130617Smlaier t.pfrb_type = PFRB_TRANS; 409145840Smlaier if (pfctl_add_trans(&t, PF_RULESET_SCRUB, anchorname) || 410145840Smlaier pfctl_add_trans(&t, PF_RULESET_FILTER, anchorname) || 411130617Smlaier pfctl_trans(dev, &t, DIOCXBEGIN, 0) || 412130617Smlaier pfctl_trans(dev, &t, DIOCXCOMMIT, 0)) 413130617Smlaier err(1, "pfctl_clear_rules"); 414126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 415126353Smlaier fprintf(stderr, "rules cleared\n"); 416126353Smlaier return (0); 417126353Smlaier} 418126353Smlaier 419126353Smlaierint 420145840Smlaierpfctl_clear_nat(int dev, int opts, char *anchorname) 421126353Smlaier{ 422130617Smlaier struct pfr_buffer t; 423126353Smlaier 424130617Smlaier memset(&t, 0, sizeof(t)); 425130617Smlaier t.pfrb_type = PFRB_TRANS; 426145840Smlaier if (pfctl_add_trans(&t, PF_RULESET_NAT, anchorname) || 427145840Smlaier pfctl_add_trans(&t, PF_RULESET_BINAT, anchorname) || 428145840Smlaier pfctl_add_trans(&t, PF_RULESET_RDR, anchorname) || 429130617Smlaier pfctl_trans(dev, &t, DIOCXBEGIN, 0) || 430130617Smlaier pfctl_trans(dev, &t, DIOCXCOMMIT, 0)) 431130617Smlaier err(1, "pfctl_clear_nat"); 432126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 433126353Smlaier fprintf(stderr, "nat cleared\n"); 434126353Smlaier return (0); 435126353Smlaier} 436126353Smlaier 437126353Smlaierint 438126353Smlaierpfctl_clear_altq(int dev, int opts) 439126353Smlaier{ 440130617Smlaier struct pfr_buffer t; 441126353Smlaier 442126353Smlaier if (!altqsupport) 443126353Smlaier return (-1); 444130617Smlaier memset(&t, 0, sizeof(t)); 445130617Smlaier t.pfrb_type = PFRB_TRANS; 446145840Smlaier if (pfctl_add_trans(&t, PF_RULESET_ALTQ, "") || 447130617Smlaier pfctl_trans(dev, &t, DIOCXBEGIN, 0) || 448130617Smlaier pfctl_trans(dev, &t, DIOCXCOMMIT, 0)) 449130617Smlaier err(1, "pfctl_clear_altq"); 450126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 451126353Smlaier fprintf(stderr, "altq cleared\n"); 452126353Smlaier return (0); 453126353Smlaier} 454126353Smlaier 455126353Smlaierint 456130617Smlaierpfctl_clear_src_nodes(int dev, int opts) 457126353Smlaier{ 458130617Smlaier if (ioctl(dev, DIOCCLRSRCNODES)) 459130617Smlaier err(1, "DIOCCLRSRCNODES"); 460130617Smlaier if ((opts & PF_OPT_QUIET) == 0) 461130617Smlaier fprintf(stderr, "source tracking entries cleared\n"); 462130617Smlaier return (0); 463130617Smlaier} 464130617Smlaier 465130617Smlaierint 466130617Smlaierpfctl_clear_states(int dev, const char *iface, int opts) 467130617Smlaier{ 468130617Smlaier struct pfioc_state_kill psk; 469130617Smlaier 470130617Smlaier memset(&psk, 0, sizeof(psk)); 471130617Smlaier if (iface != NULL && strlcpy(psk.psk_ifname, iface, 472130617Smlaier sizeof(psk.psk_ifname)) >= sizeof(psk.psk_ifname)) 473130617Smlaier errx(1, "invalid interface: %s", iface); 474130617Smlaier 475130617Smlaier if (ioctl(dev, DIOCCLRSTATES, &psk)) 476126353Smlaier err(1, "DIOCCLRSTATES"); 477126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 478223637Sbz fprintf(stderr, "%d states cleared\n", psk.psk_killed); 479126353Smlaier return (0); 480126353Smlaier} 481126353Smlaier 482171172Smlaiervoid 483171172Smlaierpfctl_addrprefix(char *addr, struct pf_addr *mask) 484171172Smlaier{ 485171172Smlaier char *p; 486171172Smlaier const char *errstr; 487171172Smlaier int prefix, ret_ga, q, r; 488171172Smlaier struct addrinfo hints, *res; 489171172Smlaier 490171172Smlaier if ((p = strchr(addr, '/')) == NULL) 491171172Smlaier return; 492171172Smlaier 493171172Smlaier *p++ = '\0'; 494171172Smlaier prefix = strtonum(p, 0, 128, &errstr); 495171172Smlaier if (errstr) 496171172Smlaier errx(1, "prefix is %s: %s", errstr, p); 497171172Smlaier 498171172Smlaier bzero(&hints, sizeof(hints)); 499171172Smlaier /* prefix only with numeric addresses */ 500171172Smlaier hints.ai_flags |= AI_NUMERICHOST; 501171172Smlaier 502171172Smlaier if ((ret_ga = getaddrinfo(addr, NULL, &hints, &res))) { 503171172Smlaier errx(1, "getaddrinfo: %s", gai_strerror(ret_ga)); 504171172Smlaier /* NOTREACHED */ 505171172Smlaier } 506171172Smlaier 507171172Smlaier if (res->ai_family == AF_INET && prefix > 32) 508171172Smlaier errx(1, "prefix too long for AF_INET"); 509171172Smlaier else if (res->ai_family == AF_INET6 && prefix > 128) 510171172Smlaier errx(1, "prefix too long for AF_INET6"); 511171172Smlaier 512171172Smlaier q = prefix >> 3; 513171172Smlaier r = prefix & 7; 514171172Smlaier switch (res->ai_family) { 515171172Smlaier case AF_INET: 516171172Smlaier bzero(&mask->v4, sizeof(mask->v4)); 517171172Smlaier mask->v4.s_addr = htonl((u_int32_t) 518171172Smlaier (0xffffffffffULL << (32 - prefix))); 519171172Smlaier break; 520171172Smlaier case AF_INET6: 521171172Smlaier bzero(&mask->v6, sizeof(mask->v6)); 522171172Smlaier if (q > 0) 523171172Smlaier memset((void *)&mask->v6, 0xff, q); 524171172Smlaier if (r > 0) 525171172Smlaier *((u_char *)&mask->v6 + q) = 526171172Smlaier (0xff00 >> r) & 0xff; 527171172Smlaier break; 528171172Smlaier } 529171172Smlaier freeaddrinfo(res); 530171172Smlaier} 531171172Smlaier 532126353Smlaierint 533171172Smlaierpfctl_kill_src_nodes(int dev, const char *iface, int opts) 534171172Smlaier{ 535171172Smlaier struct pfioc_src_node_kill psnk; 536171172Smlaier struct addrinfo *res[2], *resp[2]; 537171172Smlaier struct sockaddr last_src, last_dst; 538171172Smlaier int killed, sources, dests; 539171172Smlaier int ret_ga; 540171172Smlaier 541171172Smlaier killed = sources = dests = 0; 542171172Smlaier 543171172Smlaier memset(&psnk, 0, sizeof(psnk)); 544171172Smlaier memset(&psnk.psnk_src.addr.v.a.mask, 0xff, 545171172Smlaier sizeof(psnk.psnk_src.addr.v.a.mask)); 546171172Smlaier memset(&last_src, 0xff, sizeof(last_src)); 547171172Smlaier memset(&last_dst, 0xff, sizeof(last_dst)); 548171172Smlaier 549171172Smlaier pfctl_addrprefix(src_node_kill[0], &psnk.psnk_src.addr.v.a.mask); 550171172Smlaier 551171172Smlaier if ((ret_ga = getaddrinfo(src_node_kill[0], NULL, NULL, &res[0]))) { 552171172Smlaier errx(1, "getaddrinfo: %s", gai_strerror(ret_ga)); 553171172Smlaier /* NOTREACHED */ 554171172Smlaier } 555171172Smlaier for (resp[0] = res[0]; resp[0]; resp[0] = resp[0]->ai_next) { 556171172Smlaier if (resp[0]->ai_addr == NULL) 557171172Smlaier continue; 558171172Smlaier /* We get lots of duplicates. Catch the easy ones */ 559171172Smlaier if (memcmp(&last_src, resp[0]->ai_addr, sizeof(last_src)) == 0) 560171172Smlaier continue; 561171172Smlaier last_src = *(struct sockaddr *)resp[0]->ai_addr; 562171172Smlaier 563171172Smlaier psnk.psnk_af = resp[0]->ai_family; 564171172Smlaier sources++; 565171172Smlaier 566171172Smlaier if (psnk.psnk_af == AF_INET) 567171172Smlaier psnk.psnk_src.addr.v.a.addr.v4 = 568171172Smlaier ((struct sockaddr_in *)resp[0]->ai_addr)->sin_addr; 569171172Smlaier else if (psnk.psnk_af == AF_INET6) 570171172Smlaier psnk.psnk_src.addr.v.a.addr.v6 = 571171172Smlaier ((struct sockaddr_in6 *)resp[0]->ai_addr)-> 572171172Smlaier sin6_addr; 573171172Smlaier else 574171172Smlaier errx(1, "Unknown address family %d", psnk.psnk_af); 575171172Smlaier 576171172Smlaier if (src_node_killers > 1) { 577171172Smlaier dests = 0; 578171172Smlaier memset(&psnk.psnk_dst.addr.v.a.mask, 0xff, 579171172Smlaier sizeof(psnk.psnk_dst.addr.v.a.mask)); 580171172Smlaier memset(&last_dst, 0xff, sizeof(last_dst)); 581171172Smlaier pfctl_addrprefix(src_node_kill[1], 582171172Smlaier &psnk.psnk_dst.addr.v.a.mask); 583171172Smlaier if ((ret_ga = getaddrinfo(src_node_kill[1], NULL, NULL, 584171172Smlaier &res[1]))) { 585171172Smlaier errx(1, "getaddrinfo: %s", 586171172Smlaier gai_strerror(ret_ga)); 587171172Smlaier /* NOTREACHED */ 588171172Smlaier } 589171172Smlaier for (resp[1] = res[1]; resp[1]; 590171172Smlaier resp[1] = resp[1]->ai_next) { 591171172Smlaier if (resp[1]->ai_addr == NULL) 592171172Smlaier continue; 593171172Smlaier if (psnk.psnk_af != resp[1]->ai_family) 594171172Smlaier continue; 595171172Smlaier 596171172Smlaier if (memcmp(&last_dst, resp[1]->ai_addr, 597171172Smlaier sizeof(last_dst)) == 0) 598171172Smlaier continue; 599171172Smlaier last_dst = *(struct sockaddr *)resp[1]->ai_addr; 600171172Smlaier 601171172Smlaier dests++; 602171172Smlaier 603171172Smlaier if (psnk.psnk_af == AF_INET) 604171172Smlaier psnk.psnk_dst.addr.v.a.addr.v4 = 605171172Smlaier ((struct sockaddr_in *)resp[1]-> 606171172Smlaier ai_addr)->sin_addr; 607171172Smlaier else if (psnk.psnk_af == AF_INET6) 608171172Smlaier psnk.psnk_dst.addr.v.a.addr.v6 = 609171172Smlaier ((struct sockaddr_in6 *)resp[1]-> 610171172Smlaier ai_addr)->sin6_addr; 611171172Smlaier else 612171172Smlaier errx(1, "Unknown address family %d", 613171172Smlaier psnk.psnk_af); 614171172Smlaier 615171172Smlaier if (ioctl(dev, DIOCKILLSRCNODES, &psnk)) 616171172Smlaier err(1, "DIOCKILLSRCNODES"); 617223637Sbz killed += psnk.psnk_killed; 618171172Smlaier } 619171172Smlaier freeaddrinfo(res[1]); 620171172Smlaier } else { 621171172Smlaier if (ioctl(dev, DIOCKILLSRCNODES, &psnk)) 622171172Smlaier err(1, "DIOCKILLSRCNODES"); 623223637Sbz killed += psnk.psnk_killed; 624171172Smlaier } 625171172Smlaier } 626171172Smlaier 627171172Smlaier freeaddrinfo(res[0]); 628171172Smlaier 629171172Smlaier if ((opts & PF_OPT_QUIET) == 0) 630171172Smlaier fprintf(stderr, "killed %d src nodes from %d sources and %d " 631171172Smlaier "destinations\n", killed, sources, dests); 632171172Smlaier return (0); 633171172Smlaier} 634171172Smlaier 635171172Smlaierint 636223637Sbzpfctl_net_kill_states(int dev, const char *iface, int opts) 637126353Smlaier{ 638126353Smlaier struct pfioc_state_kill psk; 639126353Smlaier struct addrinfo *res[2], *resp[2]; 640126353Smlaier struct sockaddr last_src, last_dst; 641126353Smlaier int killed, sources, dests; 642126353Smlaier int ret_ga; 643126353Smlaier 644126353Smlaier killed = sources = dests = 0; 645126353Smlaier 646126353Smlaier memset(&psk, 0, sizeof(psk)); 647126353Smlaier memset(&psk.psk_src.addr.v.a.mask, 0xff, 648126353Smlaier sizeof(psk.psk_src.addr.v.a.mask)); 649126353Smlaier memset(&last_src, 0xff, sizeof(last_src)); 650126353Smlaier memset(&last_dst, 0xff, sizeof(last_dst)); 651130617Smlaier if (iface != NULL && strlcpy(psk.psk_ifname, iface, 652130617Smlaier sizeof(psk.psk_ifname)) >= sizeof(psk.psk_ifname)) 653130617Smlaier errx(1, "invalid interface: %s", iface); 654126353Smlaier 655171172Smlaier pfctl_addrprefix(state_kill[0], &psk.psk_src.addr.v.a.mask); 656171172Smlaier 657126353Smlaier if ((ret_ga = getaddrinfo(state_kill[0], NULL, NULL, &res[0]))) { 658126353Smlaier errx(1, "getaddrinfo: %s", gai_strerror(ret_ga)); 659126353Smlaier /* NOTREACHED */ 660126353Smlaier } 661126353Smlaier for (resp[0] = res[0]; resp[0]; resp[0] = resp[0]->ai_next) { 662126353Smlaier if (resp[0]->ai_addr == NULL) 663126353Smlaier continue; 664126353Smlaier /* We get lots of duplicates. Catch the easy ones */ 665126353Smlaier if (memcmp(&last_src, resp[0]->ai_addr, sizeof(last_src)) == 0) 666126353Smlaier continue; 667126353Smlaier last_src = *(struct sockaddr *)resp[0]->ai_addr; 668126353Smlaier 669126353Smlaier psk.psk_af = resp[0]->ai_family; 670126353Smlaier sources++; 671126353Smlaier 672126353Smlaier if (psk.psk_af == AF_INET) 673126353Smlaier psk.psk_src.addr.v.a.addr.v4 = 674126353Smlaier ((struct sockaddr_in *)resp[0]->ai_addr)->sin_addr; 675126353Smlaier else if (psk.psk_af == AF_INET6) 676126353Smlaier psk.psk_src.addr.v.a.addr.v6 = 677126353Smlaier ((struct sockaddr_in6 *)resp[0]->ai_addr)-> 678126353Smlaier sin6_addr; 679126353Smlaier else 680126353Smlaier errx(1, "Unknown address family %d", psk.psk_af); 681126353Smlaier 682126353Smlaier if (state_killers > 1) { 683126353Smlaier dests = 0; 684126353Smlaier memset(&psk.psk_dst.addr.v.a.mask, 0xff, 685126353Smlaier sizeof(psk.psk_dst.addr.v.a.mask)); 686126353Smlaier memset(&last_dst, 0xff, sizeof(last_dst)); 687171172Smlaier pfctl_addrprefix(state_kill[1], 688171172Smlaier &psk.psk_dst.addr.v.a.mask); 689126353Smlaier if ((ret_ga = getaddrinfo(state_kill[1], NULL, NULL, 690126353Smlaier &res[1]))) { 691130617Smlaier errx(1, "getaddrinfo: %s", 692130617Smlaier gai_strerror(ret_ga)); 693126353Smlaier /* NOTREACHED */ 694126353Smlaier } 695126353Smlaier for (resp[1] = res[1]; resp[1]; 696126353Smlaier resp[1] = resp[1]->ai_next) { 697126353Smlaier if (resp[1]->ai_addr == NULL) 698126353Smlaier continue; 699126353Smlaier if (psk.psk_af != resp[1]->ai_family) 700126353Smlaier continue; 701126353Smlaier 702126353Smlaier if (memcmp(&last_dst, resp[1]->ai_addr, 703126353Smlaier sizeof(last_dst)) == 0) 704126353Smlaier continue; 705126353Smlaier last_dst = *(struct sockaddr *)resp[1]->ai_addr; 706126353Smlaier 707126353Smlaier dests++; 708126353Smlaier 709126353Smlaier if (psk.psk_af == AF_INET) 710126353Smlaier psk.psk_dst.addr.v.a.addr.v4 = 711126353Smlaier ((struct sockaddr_in *)resp[1]-> 712126353Smlaier ai_addr)->sin_addr; 713126353Smlaier else if (psk.psk_af == AF_INET6) 714126353Smlaier psk.psk_dst.addr.v.a.addr.v6 = 715126353Smlaier ((struct sockaddr_in6 *)resp[1]-> 716126353Smlaier ai_addr)->sin6_addr; 717126353Smlaier else 718126353Smlaier errx(1, "Unknown address family %d", 719126353Smlaier psk.psk_af); 720126353Smlaier 721126353Smlaier if (ioctl(dev, DIOCKILLSTATES, &psk)) 722126353Smlaier err(1, "DIOCKILLSTATES"); 723223637Sbz killed += psk.psk_killed; 724126353Smlaier } 725126353Smlaier freeaddrinfo(res[1]); 726126353Smlaier } else { 727126353Smlaier if (ioctl(dev, DIOCKILLSTATES, &psk)) 728126353Smlaier err(1, "DIOCKILLSTATES"); 729223637Sbz killed += psk.psk_killed; 730126353Smlaier } 731126353Smlaier } 732126353Smlaier 733126353Smlaier freeaddrinfo(res[0]); 734126353Smlaier 735126353Smlaier if ((opts & PF_OPT_QUIET) == 0) 736126353Smlaier fprintf(stderr, "killed %d states from %d sources and %d " 737126353Smlaier "destinations\n", killed, sources, dests); 738126353Smlaier return (0); 739126353Smlaier} 740126353Smlaier 741126353Smlaierint 742223637Sbzpfctl_label_kill_states(int dev, const char *iface, int opts) 743223637Sbz{ 744223637Sbz struct pfioc_state_kill psk; 745223637Sbz 746223637Sbz if (state_killers != 2 || (strlen(state_kill[1]) == 0)) { 747223637Sbz warnx("no label specified"); 748223637Sbz usage(); 749223637Sbz } 750223637Sbz memset(&psk, 0, sizeof(psk)); 751223637Sbz if (iface != NULL && strlcpy(psk.psk_ifname, iface, 752223637Sbz sizeof(psk.psk_ifname)) >= sizeof(psk.psk_ifname)) 753223637Sbz errx(1, "invalid interface: %s", iface); 754223637Sbz 755223637Sbz if (strlcpy(psk.psk_label, state_kill[1], sizeof(psk.psk_label)) >= 756223637Sbz sizeof(psk.psk_label)) 757223637Sbz errx(1, "label too long: %s", state_kill[1]); 758223637Sbz 759223637Sbz if (ioctl(dev, DIOCKILLSTATES, &psk)) 760223637Sbz err(1, "DIOCKILLSTATES"); 761223637Sbz 762223637Sbz if ((opts & PF_OPT_QUIET) == 0) 763223637Sbz fprintf(stderr, "killed %d states\n", psk.psk_killed); 764223637Sbz 765223637Sbz return (0); 766223637Sbz} 767223637Sbz 768223637Sbzint 769223637Sbzpfctl_id_kill_states(int dev, const char *iface, int opts) 770223637Sbz{ 771223637Sbz struct pfioc_state_kill psk; 772223637Sbz 773223637Sbz if (state_killers != 2 || (strlen(state_kill[1]) == 0)) { 774223637Sbz warnx("no id specified"); 775223637Sbz usage(); 776223637Sbz } 777223637Sbz 778223637Sbz memset(&psk, 0, sizeof(psk)); 779223637Sbz if ((sscanf(state_kill[1], "%jx/%x", 780223637Sbz &psk.psk_pfcmp.id, &psk.psk_pfcmp.creatorid)) == 2) 781223637Sbz HTONL(psk.psk_pfcmp.creatorid); 782223637Sbz else if ((sscanf(state_kill[1], "%jx", &psk.psk_pfcmp.id)) == 1) { 783223637Sbz psk.psk_pfcmp.creatorid = 0; 784223637Sbz } else { 785223637Sbz warnx("wrong id format specified"); 786223637Sbz usage(); 787223637Sbz } 788223637Sbz if (psk.psk_pfcmp.id == 0) { 789223637Sbz warnx("cannot kill id 0"); 790223637Sbz usage(); 791223637Sbz } 792223637Sbz 793223637Sbz psk.psk_pfcmp.id = htobe64(psk.psk_pfcmp.id); 794223637Sbz if (ioctl(dev, DIOCKILLSTATES, &psk)) 795223637Sbz err(1, "DIOCKILLSTATES"); 796223637Sbz 797223637Sbz if ((opts & PF_OPT_QUIET) == 0) 798223637Sbz fprintf(stderr, "killed %d states\n", psk.psk_killed); 799223637Sbz 800223637Sbz return (0); 801223637Sbz} 802223637Sbz 803223637Sbzint 804126353Smlaierpfctl_get_pool(int dev, struct pf_pool *pool, u_int32_t nr, 805145840Smlaier u_int32_t ticket, int r_action, char *anchorname) 806126353Smlaier{ 807126353Smlaier struct pfioc_pooladdr pp; 808126353Smlaier struct pf_pooladdr *pa; 809126353Smlaier u_int32_t pnr, mpnr; 810126353Smlaier 811126353Smlaier memset(&pp, 0, sizeof(pp)); 812126353Smlaier memcpy(pp.anchor, anchorname, sizeof(pp.anchor)); 813126353Smlaier pp.r_action = r_action; 814126353Smlaier pp.r_num = nr; 815126353Smlaier pp.ticket = ticket; 816126353Smlaier if (ioctl(dev, DIOCGETADDRS, &pp)) { 817126353Smlaier warn("DIOCGETADDRS"); 818126353Smlaier return (-1); 819126353Smlaier } 820126353Smlaier mpnr = pp.nr; 821126353Smlaier TAILQ_INIT(&pool->list); 822126353Smlaier for (pnr = 0; pnr < mpnr; ++pnr) { 823126353Smlaier pp.nr = pnr; 824126353Smlaier if (ioctl(dev, DIOCGETADDR, &pp)) { 825126353Smlaier warn("DIOCGETADDR"); 826126353Smlaier return (-1); 827126353Smlaier } 828126353Smlaier pa = calloc(1, sizeof(struct pf_pooladdr)); 829126353Smlaier if (pa == NULL) 830126353Smlaier err(1, "calloc"); 831126353Smlaier bcopy(&pp.addr, pa, sizeof(struct pf_pooladdr)); 832126353Smlaier TAILQ_INSERT_TAIL(&pool->list, pa, entries); 833126353Smlaier } 834126353Smlaier 835126353Smlaier return (0); 836126353Smlaier} 837126353Smlaier 838126353Smlaiervoid 839171172Smlaierpfctl_move_pool(struct pf_pool *src, struct pf_pool *dst) 840171172Smlaier{ 841171172Smlaier struct pf_pooladdr *pa; 842171172Smlaier 843171172Smlaier while ((pa = TAILQ_FIRST(&src->list)) != NULL) { 844171172Smlaier TAILQ_REMOVE(&src->list, pa, entries); 845171172Smlaier TAILQ_INSERT_TAIL(&dst->list, pa, entries); 846171172Smlaier } 847171172Smlaier} 848171172Smlaier 849171172Smlaiervoid 850126353Smlaierpfctl_clear_pool(struct pf_pool *pool) 851126353Smlaier{ 852126353Smlaier struct pf_pooladdr *pa; 853126353Smlaier 854126353Smlaier while ((pa = TAILQ_FIRST(&pool->list)) != NULL) { 855126353Smlaier TAILQ_REMOVE(&pool->list, pa, entries); 856126353Smlaier free(pa); 857126353Smlaier } 858126353Smlaier} 859126353Smlaier 860126353Smlaiervoid 861126353Smlaierpfctl_print_rule_counters(struct pf_rule *rule, int opts) 862126353Smlaier{ 863126353Smlaier if (opts & PF_OPT_DEBUG) { 864126353Smlaier const char *t[PF_SKIP_COUNT] = { "i", "d", "f", 865126353Smlaier "p", "sa", "sp", "da", "dp" }; 866126353Smlaier int i; 867126353Smlaier 868126353Smlaier printf(" [ Skip steps: "); 869126353Smlaier for (i = 0; i < PF_SKIP_COUNT; ++i) { 870126353Smlaier if (rule->skip[i].nr == rule->nr + 1) 871126353Smlaier continue; 872126353Smlaier printf("%s=", t[i]); 873126353Smlaier if (rule->skip[i].nr == -1) 874126353Smlaier printf("end "); 875126353Smlaier else 876126353Smlaier printf("%u ", rule->skip[i].nr); 877126353Smlaier } 878126353Smlaier printf("]\n"); 879126353Smlaier 880126353Smlaier printf(" [ queue: qname=%s qid=%u pqname=%s pqid=%u ]\n", 881126353Smlaier rule->qname, rule->qid, rule->pqname, rule->pqid); 882126353Smlaier } 883171172Smlaier if (opts & PF_OPT_VERBOSE) { 884127024Smlaier printf(" [ Evaluations: %-8llu Packets: %-8llu " 885262799Sglebius "Bytes: %-10llu States: %-6ju]\n", 886127024Smlaier (unsigned long long)rule->evaluations, 887171172Smlaier (unsigned long long)(rule->packets[0] + 888171172Smlaier rule->packets[1]), 889171172Smlaier (unsigned long long)(rule->bytes[0] + 890262799Sglebius rule->bytes[1]), (uintmax_t)rule->u_states_cur); 891171172Smlaier if (!(opts & PF_OPT_DEBUG)) 892223637Sbz printf(" [ Inserted: uid %u pid %u " 893262799Sglebius "State Creations: %-6ju]\n", 894223637Sbz (unsigned)rule->cuid, (unsigned)rule->cpid, 895262799Sglebius (uintmax_t)rule->u_states_tot); 896171172Smlaier } 897126353Smlaier} 898126353Smlaier 899130617Smlaiervoid 900130617Smlaierpfctl_print_title(char *title) 901130617Smlaier{ 902130617Smlaier if (!first_title) 903130617Smlaier printf("\n"); 904130617Smlaier first_title = 0; 905130617Smlaier printf("%s\n", title); 906130617Smlaier} 907130617Smlaier 908126353Smlaierint 909171172Smlaierpfctl_show_rules(int dev, char *path, int opts, enum pfctl_show format, 910171172Smlaier char *anchorname, int depth) 911126353Smlaier{ 912126353Smlaier struct pfioc_rule pr; 913130617Smlaier u_int32_t nr, mnr, header = 0; 914126353Smlaier int rule_numbers = opts & (PF_OPT_VERBOSE2 | PF_OPT_DEBUG); 915223057Sbz int numeric = opts & PF_OPT_NUMERIC; 916171172Smlaier int len = strlen(path); 917171172Smlaier int brace; 918171172Smlaier char *p; 919126353Smlaier 920171172Smlaier if (path[0]) 921171172Smlaier snprintf(&path[len], MAXPATHLEN - len, "/%s", anchorname); 922171172Smlaier else 923171172Smlaier snprintf(&path[len], MAXPATHLEN - len, "%s", anchorname); 924171172Smlaier 925126353Smlaier memset(&pr, 0, sizeof(pr)); 926171172Smlaier memcpy(pr.anchor, path, sizeof(pr.anchor)); 927130617Smlaier if (opts & PF_OPT_SHOWALL) { 928130617Smlaier pr.rule.action = PF_PASS; 929130617Smlaier if (ioctl(dev, DIOCGETRULES, &pr)) { 930130617Smlaier warn("DIOCGETRULES"); 931171172Smlaier goto error; 932130617Smlaier } 933130617Smlaier header++; 934130617Smlaier } 935126353Smlaier pr.rule.action = PF_SCRUB; 936126353Smlaier if (ioctl(dev, DIOCGETRULES, &pr)) { 937126353Smlaier warn("DIOCGETRULES"); 938171172Smlaier goto error; 939126353Smlaier } 940130617Smlaier if (opts & PF_OPT_SHOWALL) { 941171172Smlaier if (format == PFCTL_SHOW_RULES && (pr.nr > 0 || header)) 942130617Smlaier pfctl_print_title("FILTER RULES:"); 943171172Smlaier else if (format == PFCTL_SHOW_LABELS && labels) 944130617Smlaier pfctl_print_title("LABEL COUNTERS:"); 945130617Smlaier } 946126353Smlaier mnr = pr.nr; 947171172Smlaier if (opts & PF_OPT_CLRRULECTRS) 948171172Smlaier pr.action = PF_GET_CLR_CNTR; 949171172Smlaier 950126353Smlaier for (nr = 0; nr < mnr; ++nr) { 951126353Smlaier pr.nr = nr; 952126353Smlaier if (ioctl(dev, DIOCGETRULE, &pr)) { 953126353Smlaier warn("DIOCGETRULE"); 954171172Smlaier goto error; 955126353Smlaier } 956126353Smlaier 957126353Smlaier if (pfctl_get_pool(dev, &pr.rule.rpool, 958171172Smlaier nr, pr.ticket, PF_SCRUB, path) != 0) 959171172Smlaier goto error; 960126353Smlaier 961126353Smlaier switch (format) { 962171172Smlaier case PFCTL_SHOW_LABELS: 963126353Smlaier break; 964171172Smlaier case PFCTL_SHOW_RULES: 965130617Smlaier if (pr.rule.label[0] && (opts & PF_OPT_SHOWALL)) 966130617Smlaier labels = 1; 967223057Sbz print_rule(&pr.rule, pr.anchor_call, rule_numbers, numeric); 968171172Smlaier printf("\n"); 969126353Smlaier pfctl_print_rule_counters(&pr.rule, opts); 970171172Smlaier break; 971171172Smlaier case PFCTL_SHOW_NOTHING: 972171172Smlaier break; 973126353Smlaier } 974126353Smlaier pfctl_clear_pool(&pr.rule.rpool); 975126353Smlaier } 976126353Smlaier pr.rule.action = PF_PASS; 977126353Smlaier if (ioctl(dev, DIOCGETRULES, &pr)) { 978126353Smlaier warn("DIOCGETRULES"); 979171172Smlaier goto error; 980126353Smlaier } 981126353Smlaier mnr = pr.nr; 982126353Smlaier for (nr = 0; nr < mnr; ++nr) { 983126353Smlaier pr.nr = nr; 984126353Smlaier if (ioctl(dev, DIOCGETRULE, &pr)) { 985126353Smlaier warn("DIOCGETRULE"); 986171172Smlaier goto error; 987126353Smlaier } 988126353Smlaier 989126353Smlaier if (pfctl_get_pool(dev, &pr.rule.rpool, 990171172Smlaier nr, pr.ticket, PF_PASS, path) != 0) 991171172Smlaier goto error; 992126353Smlaier 993126353Smlaier switch (format) { 994171172Smlaier case PFCTL_SHOW_LABELS: 995126353Smlaier if (pr.rule.label[0]) { 996223637Sbz printf("%s %llu %llu %llu %llu" 997262799Sglebius " %llu %llu %llu %ju\n", 998223637Sbz pr.rule.label, 999127024Smlaier (unsigned long long)pr.rule.evaluations, 1000171172Smlaier (unsigned long long)(pr.rule.packets[0] + 1001171172Smlaier pr.rule.packets[1]), 1002171172Smlaier (unsigned long long)(pr.rule.bytes[0] + 1003171172Smlaier pr.rule.bytes[1]), 1004171172Smlaier (unsigned long long)pr.rule.packets[0], 1005171172Smlaier (unsigned long long)pr.rule.bytes[0], 1006171172Smlaier (unsigned long long)pr.rule.packets[1], 1007223637Sbz (unsigned long long)pr.rule.bytes[1], 1008262799Sglebius (uintmax_t)pr.rule.u_states_tot); 1009126353Smlaier } 1010126353Smlaier break; 1011171172Smlaier case PFCTL_SHOW_RULES: 1012171172Smlaier brace = 0; 1013130617Smlaier if (pr.rule.label[0] && (opts & PF_OPT_SHOWALL)) 1014130617Smlaier labels = 1; 1015171172Smlaier INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1016171172Smlaier if (pr.anchor_call[0] && 1017171172Smlaier ((((p = strrchr(pr.anchor_call, '_')) != NULL) && 1018171172Smlaier ((void *)p == (void *)pr.anchor_call || 1019171172Smlaier *(--p) == '/')) || (opts & PF_OPT_RECURSE))) { 1020171172Smlaier brace++; 1021171172Smlaier if ((p = strrchr(pr.anchor_call, '/')) != 1022171172Smlaier NULL) 1023171172Smlaier p++; 1024171172Smlaier else 1025171172Smlaier p = &pr.anchor_call[0]; 1026171172Smlaier } else 1027171172Smlaier p = &pr.anchor_call[0]; 1028171172Smlaier 1029223057Sbz print_rule(&pr.rule, p, rule_numbers, numeric); 1030171172Smlaier if (brace) 1031171172Smlaier printf(" {\n"); 1032171172Smlaier else 1033171172Smlaier printf("\n"); 1034126353Smlaier pfctl_print_rule_counters(&pr.rule, opts); 1035171172Smlaier if (brace) { 1036171172Smlaier pfctl_show_rules(dev, path, opts, format, 1037171172Smlaier p, depth + 1); 1038171172Smlaier INDENT(depth, !(opts & PF_OPT_VERBOSE)); 1039171172Smlaier printf("}\n"); 1040171172Smlaier } 1041171172Smlaier break; 1042171172Smlaier case PFCTL_SHOW_NOTHING: 1043171172Smlaier break; 1044126353Smlaier } 1045126353Smlaier pfctl_clear_pool(&pr.rule.rpool); 1046126353Smlaier } 1047171172Smlaier path[len] = '\0'; 1048126353Smlaier return (0); 1049171172Smlaier 1050171172Smlaier error: 1051171172Smlaier path[len] = '\0'; 1052171172Smlaier return (-1); 1053126353Smlaier} 1054126353Smlaier 1055126353Smlaierint 1056145840Smlaierpfctl_show_nat(int dev, int opts, char *anchorname) 1057126353Smlaier{ 1058126353Smlaier struct pfioc_rule pr; 1059126353Smlaier u_int32_t mnr, nr; 1060126353Smlaier static int nattype[3] = { PF_NAT, PF_RDR, PF_BINAT }; 1061130617Smlaier int i, dotitle = opts & PF_OPT_SHOWALL; 1062126353Smlaier 1063126353Smlaier memset(&pr, 0, sizeof(pr)); 1064126353Smlaier memcpy(pr.anchor, anchorname, sizeof(pr.anchor)); 1065126353Smlaier for (i = 0; i < 3; i++) { 1066126353Smlaier pr.rule.action = nattype[i]; 1067126353Smlaier if (ioctl(dev, DIOCGETRULES, &pr)) { 1068126353Smlaier warn("DIOCGETRULES"); 1069126353Smlaier return (-1); 1070126353Smlaier } 1071126353Smlaier mnr = pr.nr; 1072126353Smlaier for (nr = 0; nr < mnr; ++nr) { 1073126353Smlaier pr.nr = nr; 1074126353Smlaier if (ioctl(dev, DIOCGETRULE, &pr)) { 1075126353Smlaier warn("DIOCGETRULE"); 1076126353Smlaier return (-1); 1077126353Smlaier } 1078126353Smlaier if (pfctl_get_pool(dev, &pr.rule.rpool, nr, 1079145840Smlaier pr.ticket, nattype[i], anchorname) != 0) 1080126353Smlaier return (-1); 1081130617Smlaier if (dotitle) { 1082130617Smlaier pfctl_print_title("TRANSLATION RULES:"); 1083130617Smlaier dotitle = 0; 1084130617Smlaier } 1085145840Smlaier print_rule(&pr.rule, pr.anchor_call, 1086223057Sbz opts & PF_OPT_VERBOSE2, opts & PF_OPT_NUMERIC); 1087171172Smlaier printf("\n"); 1088126353Smlaier pfctl_print_rule_counters(&pr.rule, opts); 1089126353Smlaier pfctl_clear_pool(&pr.rule.rpool); 1090126353Smlaier } 1091126353Smlaier } 1092126353Smlaier return (0); 1093126353Smlaier} 1094126353Smlaier 1095126353Smlaierint 1096130617Smlaierpfctl_show_src_nodes(int dev, int opts) 1097126353Smlaier{ 1098130617Smlaier struct pfioc_src_nodes psn; 1099130617Smlaier struct pf_src_node *p; 1100130617Smlaier char *inbuf = NULL, *newinbuf = NULL; 1101223637Sbz unsigned int len = 0; 1102130617Smlaier int i; 1103130617Smlaier 1104130617Smlaier memset(&psn, 0, sizeof(psn)); 1105130617Smlaier for (;;) { 1106130617Smlaier psn.psn_len = len; 1107130617Smlaier if (len) { 1108130617Smlaier newinbuf = realloc(inbuf, len); 1109130617Smlaier if (newinbuf == NULL) 1110130617Smlaier err(1, "realloc"); 1111130617Smlaier psn.psn_buf = inbuf = newinbuf; 1112130617Smlaier } 1113130617Smlaier if (ioctl(dev, DIOCGETSRCNODES, &psn) < 0) { 1114130617Smlaier warn("DIOCGETSRCNODES"); 1115171172Smlaier free(inbuf); 1116130617Smlaier return (-1); 1117130617Smlaier } 1118130617Smlaier if (psn.psn_len + sizeof(struct pfioc_src_nodes) < len) 1119130617Smlaier break; 1120130617Smlaier if (len == 0 && psn.psn_len == 0) 1121171172Smlaier goto done; 1122130617Smlaier if (len == 0 && psn.psn_len != 0) 1123130617Smlaier len = psn.psn_len; 1124130617Smlaier if (psn.psn_len == 0) 1125171172Smlaier goto done; /* no src_nodes */ 1126130617Smlaier len *= 2; 1127130617Smlaier } 1128130617Smlaier p = psn.psn_src_nodes; 1129130617Smlaier if (psn.psn_len > 0 && (opts & PF_OPT_SHOWALL)) 1130130617Smlaier pfctl_print_title("SOURCE TRACKING NODES:"); 1131130617Smlaier for (i = 0; i < psn.psn_len; i += sizeof(*p)) { 1132130617Smlaier print_src_node(p, opts); 1133130617Smlaier p++; 1134130617Smlaier } 1135171172Smlaierdone: 1136171172Smlaier free(inbuf); 1137130617Smlaier return (0); 1138130617Smlaier} 1139130617Smlaier 1140130617Smlaierint 1141130617Smlaierpfctl_show_states(int dev, const char *iface, int opts) 1142130617Smlaier{ 1143126353Smlaier struct pfioc_states ps; 1144223637Sbz struct pfsync_state *p; 1145130617Smlaier char *inbuf = NULL, *newinbuf = NULL; 1146223637Sbz unsigned int len = 0; 1147130617Smlaier int i, dotitle = (opts & PF_OPT_SHOWALL); 1148126353Smlaier 1149126353Smlaier memset(&ps, 0, sizeof(ps)); 1150126353Smlaier for (;;) { 1151126353Smlaier ps.ps_len = len; 1152126353Smlaier if (len) { 1153130617Smlaier newinbuf = realloc(inbuf, len); 1154130617Smlaier if (newinbuf == NULL) 1155126353Smlaier err(1, "realloc"); 1156130617Smlaier ps.ps_buf = inbuf = newinbuf; 1157126353Smlaier } 1158126353Smlaier if (ioctl(dev, DIOCGETSTATES, &ps) < 0) { 1159126353Smlaier warn("DIOCGETSTATES"); 1160171172Smlaier free(inbuf); 1161126353Smlaier return (-1); 1162126353Smlaier } 1163126353Smlaier if (ps.ps_len + sizeof(struct pfioc_states) < len) 1164126353Smlaier break; 1165126353Smlaier if (len == 0 && ps.ps_len == 0) 1166171172Smlaier goto done; 1167126353Smlaier if (len == 0 && ps.ps_len != 0) 1168126353Smlaier len = ps.ps_len; 1169126353Smlaier if (ps.ps_len == 0) 1170171172Smlaier goto done; /* no states */ 1171126353Smlaier len *= 2; 1172126353Smlaier } 1173126353Smlaier p = ps.ps_states; 1174130617Smlaier for (i = 0; i < ps.ps_len; i += sizeof(*p), p++) { 1175223637Sbz if (iface != NULL && strcmp(p->ifname, iface)) 1176130617Smlaier continue; 1177130617Smlaier if (dotitle) { 1178130617Smlaier pfctl_print_title("STATES:"); 1179130617Smlaier dotitle = 0; 1180130617Smlaier } 1181130617Smlaier print_state(p, opts); 1182126353Smlaier } 1183171172Smlaierdone: 1184171172Smlaier free(inbuf); 1185126353Smlaier return (0); 1186126353Smlaier} 1187126353Smlaier 1188126353Smlaierint 1189130617Smlaierpfctl_show_status(int dev, int opts) 1190126353Smlaier{ 1191126353Smlaier struct pf_status status; 1192126353Smlaier 1193126353Smlaier if (ioctl(dev, DIOCGETSTATUS, &status)) { 1194126353Smlaier warn("DIOCGETSTATUS"); 1195126353Smlaier return (-1); 1196126353Smlaier } 1197130617Smlaier if (opts & PF_OPT_SHOWALL) 1198130617Smlaier pfctl_print_title("INFO:"); 1199130617Smlaier print_status(&status, opts); 1200126353Smlaier return (0); 1201126353Smlaier} 1202126353Smlaier 1203126353Smlaierint 1204335058Skppfctl_show_running(int dev) 1205335058Skp{ 1206335058Skp struct pf_status status; 1207335058Skp 1208335058Skp if (ioctl(dev, DIOCGETSTATUS, &status)) { 1209335058Skp warn("DIOCGETSTATUS"); 1210335058Skp return (-1); 1211335058Skp } 1212335058Skp 1213335058Skp print_running(&status); 1214335058Skp return (!status.running); 1215335058Skp} 1216335058Skp 1217335058Skpint 1218130617Smlaierpfctl_show_timeouts(int dev, int opts) 1219126353Smlaier{ 1220126353Smlaier struct pfioc_tm pt; 1221126353Smlaier int i; 1222126353Smlaier 1223130617Smlaier if (opts & PF_OPT_SHOWALL) 1224130617Smlaier pfctl_print_title("TIMEOUTS:"); 1225126353Smlaier memset(&pt, 0, sizeof(pt)); 1226126353Smlaier for (i = 0; pf_timeouts[i].name; i++) { 1227126353Smlaier pt.timeout = pf_timeouts[i].timeout; 1228126353Smlaier if (ioctl(dev, DIOCGETTIMEOUT, &pt)) 1229126353Smlaier err(1, "DIOCGETTIMEOUT"); 1230126353Smlaier printf("%-20s %10d", pf_timeouts[i].name, pt.seconds); 1231145840Smlaier if (pf_timeouts[i].timeout >= PFTM_ADAPTIVE_START && 1232145840Smlaier pf_timeouts[i].timeout <= PFTM_ADAPTIVE_END) 1233126353Smlaier printf(" states"); 1234126353Smlaier else 1235126353Smlaier printf("s"); 1236126353Smlaier printf("\n"); 1237126353Smlaier } 1238126353Smlaier return (0); 1239126353Smlaier 1240126353Smlaier} 1241126353Smlaier 1242126353Smlaierint 1243130617Smlaierpfctl_show_limits(int dev, int opts) 1244126353Smlaier{ 1245126353Smlaier struct pfioc_limit pl; 1246126353Smlaier int i; 1247126353Smlaier 1248130617Smlaier if (opts & PF_OPT_SHOWALL) 1249130617Smlaier pfctl_print_title("LIMITS:"); 1250126353Smlaier memset(&pl, 0, sizeof(pl)); 1251126353Smlaier for (i = 0; pf_limits[i].name; i++) { 1252130617Smlaier pl.index = pf_limits[i].index; 1253126353Smlaier if (ioctl(dev, DIOCGETLIMIT, &pl)) 1254126353Smlaier err(1, "DIOCGETLIMIT"); 1255171172Smlaier printf("%-13s ", pf_limits[i].name); 1256126353Smlaier if (pl.limit == UINT_MAX) 1257126353Smlaier printf("unlimited\n"); 1258126353Smlaier else 1259171172Smlaier printf("hard limit %8u\n", pl.limit); 1260126353Smlaier } 1261126353Smlaier return (0); 1262126353Smlaier} 1263126353Smlaier 1264126353Smlaier/* callbacks for rule/nat/rdr/addr */ 1265126353Smlaierint 1266126353Smlaierpfctl_add_pool(struct pfctl *pf, struct pf_pool *p, sa_family_t af) 1267126353Smlaier{ 1268126353Smlaier struct pf_pooladdr *pa; 1269126353Smlaier 1270126353Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0) { 1271126353Smlaier if (ioctl(pf->dev, DIOCBEGINADDRS, &pf->paddr)) 1272126353Smlaier err(1, "DIOCBEGINADDRS"); 1273126353Smlaier } 1274126353Smlaier 1275126353Smlaier pf->paddr.af = af; 1276126353Smlaier TAILQ_FOREACH(pa, &p->list, entries) { 1277126353Smlaier memcpy(&pf->paddr.addr, pa, sizeof(struct pf_pooladdr)); 1278126353Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0) { 1279126353Smlaier if (ioctl(pf->dev, DIOCADDADDR, &pf->paddr)) 1280126353Smlaier err(1, "DIOCADDADDR"); 1281126353Smlaier } 1282126353Smlaier } 1283126353Smlaier return (0); 1284126353Smlaier} 1285126353Smlaier 1286126353Smlaierint 1287145840Smlaierpfctl_add_rule(struct pfctl *pf, struct pf_rule *r, const char *anchor_call) 1288126353Smlaier{ 1289130617Smlaier u_int8_t rs_num; 1290171172Smlaier struct pf_rule *rule; 1291171172Smlaier struct pf_ruleset *rs; 1292171172Smlaier char *p; 1293126353Smlaier 1294171172Smlaier rs_num = pf_get_ruleset_number(r->action); 1295171172Smlaier if (rs_num == PF_RULESET_MAX) 1296145840Smlaier errx(1, "Invalid rule type %d", r->action); 1297126353Smlaier 1298171172Smlaier rs = &pf->anchor->ruleset; 1299145840Smlaier 1300171172Smlaier if (anchor_call[0] && r->anchor == NULL) { 1301171172Smlaier /* 1302171172Smlaier * Don't make non-brace anchors part of the main anchor pool. 1303145840Smlaier */ 1304171172Smlaier if ((r->anchor = calloc(1, sizeof(*r->anchor))) == NULL) 1305171172Smlaier err(1, "pfctl_add_rule: calloc"); 1306171172Smlaier 1307171172Smlaier pf_init_ruleset(&r->anchor->ruleset); 1308171172Smlaier r->anchor->ruleset.anchor = r->anchor; 1309171172Smlaier if (strlcpy(r->anchor->path, anchor_call, 1310171172Smlaier sizeof(rule->anchor->path)) >= sizeof(rule->anchor->path)) 1311223637Sbz errx(1, "pfctl_add_rule: strlcpy"); 1312171172Smlaier if ((p = strrchr(anchor_call, '/')) != NULL) { 1313171172Smlaier if (!strlen(p)) 1314171172Smlaier err(1, "pfctl_add_rule: bad anchor name %s", 1315171172Smlaier anchor_call); 1316171172Smlaier } else 1317171172Smlaier p = (char *)anchor_call; 1318171172Smlaier if (strlcpy(r->anchor->name, p, 1319171172Smlaier sizeof(rule->anchor->name)) >= sizeof(rule->anchor->name)) 1320223637Sbz errx(1, "pfctl_add_rule: strlcpy"); 1321171172Smlaier } 1322145840Smlaier 1323171172Smlaier if ((rule = calloc(1, sizeof(*rule))) == NULL) 1324171172Smlaier err(1, "calloc"); 1325171172Smlaier bcopy(r, rule, sizeof(*rule)); 1326171172Smlaier TAILQ_INIT(&rule->rpool.list); 1327171172Smlaier pfctl_move_pool(&r->rpool, &rule->rpool); 1328145840Smlaier 1329171172Smlaier TAILQ_INSERT_TAIL(rs->rules[rs_num].active.ptr, rule, entries); 1330171172Smlaier return (0); 1331171172Smlaier} 1332171172Smlaier 1333171172Smlaierint 1334171172Smlaierpfctl_ruleset_trans(struct pfctl *pf, char *path, struct pf_anchor *a) 1335171172Smlaier{ 1336171172Smlaier int osize = pf->trans->pfrb_size; 1337171172Smlaier 1338171172Smlaier if ((pf->loadopt & PFCTL_FLAG_NAT) != 0) { 1339171172Smlaier if (pfctl_add_trans(pf->trans, PF_RULESET_NAT, path) || 1340171172Smlaier pfctl_add_trans(pf->trans, PF_RULESET_BINAT, path) || 1341171172Smlaier pfctl_add_trans(pf->trans, PF_RULESET_RDR, path)) 1342171172Smlaier return (1); 1343171172Smlaier } 1344171172Smlaier if (a == pf->astack[0] && ((altqsupport && 1345223637Sbz (pf->loadopt & PFCTL_FLAG_ALTQ) != 0))) { 1346171172Smlaier if (pfctl_add_trans(pf->trans, PF_RULESET_ALTQ, path)) 1347171172Smlaier return (2); 1348171172Smlaier } 1349171172Smlaier if ((pf->loadopt & PFCTL_FLAG_FILTER) != 0) { 1350171172Smlaier if (pfctl_add_trans(pf->trans, PF_RULESET_SCRUB, path) || 1351171172Smlaier pfctl_add_trans(pf->trans, PF_RULESET_FILTER, path)) 1352171172Smlaier return (3); 1353171172Smlaier } 1354171172Smlaier if (pf->loadopt & PFCTL_FLAG_TABLE) 1355171172Smlaier if (pfctl_add_trans(pf->trans, PF_RULESET_TABLE, path)) 1356171172Smlaier return (4); 1357171172Smlaier if (pfctl_trans(pf->dev, pf->trans, DIOCXBEGIN, osize)) 1358171172Smlaier return (5); 1359171172Smlaier 1360171172Smlaier return (0); 1361171172Smlaier} 1362171172Smlaier 1363171172Smlaierint 1364171172Smlaierpfctl_load_ruleset(struct pfctl *pf, char *path, struct pf_ruleset *rs, 1365171172Smlaier int rs_num, int depth) 1366171172Smlaier{ 1367171172Smlaier struct pf_rule *r; 1368171172Smlaier int error, len = strlen(path); 1369171172Smlaier int brace = 0; 1370171172Smlaier 1371171172Smlaier pf->anchor = rs->anchor; 1372171172Smlaier 1373171172Smlaier if (path[0]) 1374171172Smlaier snprintf(&path[len], MAXPATHLEN - len, "/%s", pf->anchor->name); 1375171172Smlaier else 1376171172Smlaier snprintf(&path[len], MAXPATHLEN - len, "%s", pf->anchor->name); 1377171172Smlaier 1378171172Smlaier if (depth) { 1379171172Smlaier if (TAILQ_FIRST(rs->rules[rs_num].active.ptr) != NULL) { 1380171172Smlaier brace++; 1381171172Smlaier if (pf->opts & PF_OPT_VERBOSE) 1382171172Smlaier printf(" {\n"); 1383171172Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0 && 1384171172Smlaier (error = pfctl_ruleset_trans(pf, 1385171172Smlaier path, rs->anchor))) { 1386171172Smlaier printf("pfctl_load_rulesets: " 1387171172Smlaier "pfctl_ruleset_trans %d\n", error); 1388171172Smlaier goto error; 1389145840Smlaier } 1390171172Smlaier } else if (pf->opts & PF_OPT_VERBOSE) 1391171172Smlaier printf("\n"); 1392145840Smlaier 1393145840Smlaier } 1394145840Smlaier 1395171172Smlaier if (pf->optimize && rs_num == PF_RULESET_FILTER) 1396171172Smlaier pfctl_optimize_ruleset(pf, rs); 1397171172Smlaier 1398171172Smlaier while ((r = TAILQ_FIRST(rs->rules[rs_num].active.ptr)) != NULL) { 1399171172Smlaier TAILQ_REMOVE(rs->rules[rs_num].active.ptr, r, entries); 1400171172Smlaier if ((error = pfctl_load_rule(pf, path, r, depth))) 1401171172Smlaier goto error; 1402171172Smlaier if (r->anchor) { 1403171172Smlaier if ((error = pfctl_load_ruleset(pf, path, 1404171172Smlaier &r->anchor->ruleset, rs_num, depth + 1))) 1405171172Smlaier goto error; 1406171172Smlaier } else if (pf->opts & PF_OPT_VERBOSE) 1407171172Smlaier printf("\n"); 1408171172Smlaier free(r); 1409171172Smlaier } 1410171172Smlaier if (brace && pf->opts & PF_OPT_VERBOSE) { 1411171172Smlaier INDENT(depth - 1, (pf->opts & PF_OPT_VERBOSE)); 1412171172Smlaier printf("}\n"); 1413171172Smlaier } 1414171172Smlaier path[len] = '\0'; 1415171172Smlaier return (0); 1416171172Smlaier 1417171172Smlaier error: 1418171172Smlaier path[len] = '\0'; 1419171172Smlaier return (error); 1420171172Smlaier 1421171172Smlaier} 1422171172Smlaier 1423171172Smlaierint 1424171172Smlaierpfctl_load_rule(struct pfctl *pf, char *path, struct pf_rule *r, int depth) 1425171172Smlaier{ 1426171172Smlaier u_int8_t rs_num = pf_get_ruleset_number(r->action); 1427171172Smlaier char *name; 1428171172Smlaier struct pfioc_rule pr; 1429171172Smlaier int len = strlen(path); 1430171172Smlaier 1431171172Smlaier bzero(&pr, sizeof(pr)); 1432171172Smlaier /* set up anchor before adding to path for anchor_call */ 1433171172Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0) 1434171172Smlaier pr.ticket = pfctl_get_ticket(pf->trans, rs_num, path); 1435171172Smlaier if (strlcpy(pr.anchor, path, sizeof(pr.anchor)) >= sizeof(pr.anchor)) 1436171172Smlaier errx(1, "pfctl_load_rule: strlcpy"); 1437171172Smlaier 1438171172Smlaier if (r->anchor) { 1439171172Smlaier if (r->anchor->match) { 1440171172Smlaier if (path[0]) 1441171172Smlaier snprintf(&path[len], MAXPATHLEN - len, 1442171172Smlaier "/%s", r->anchor->name); 1443171172Smlaier else 1444171172Smlaier snprintf(&path[len], MAXPATHLEN - len, 1445171172Smlaier "%s", r->anchor->name); 1446171172Smlaier name = path; 1447171172Smlaier } else 1448171172Smlaier name = r->anchor->path; 1449171172Smlaier } else 1450171172Smlaier name = ""; 1451171172Smlaier 1452126353Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0) { 1453126353Smlaier if (pfctl_add_pool(pf, &r->rpool, r->af)) 1454126353Smlaier return (1); 1455130617Smlaier pr.pool_ticket = pf->paddr.ticket; 1456130617Smlaier memcpy(&pr.rule, r, sizeof(pr.rule)); 1457171172Smlaier if (r->anchor && strlcpy(pr.anchor_call, name, 1458171172Smlaier sizeof(pr.anchor_call)) >= sizeof(pr.anchor_call)) 1459171172Smlaier errx(1, "pfctl_load_rule: strlcpy"); 1460130617Smlaier if (ioctl(pf->dev, DIOCADDRULE, &pr)) 1461126353Smlaier err(1, "DIOCADDRULE"); 1462126353Smlaier } 1463171172Smlaier 1464171172Smlaier if (pf->opts & PF_OPT_VERBOSE) { 1465171172Smlaier INDENT(depth, !(pf->opts & PF_OPT_VERBOSE2)); 1466171172Smlaier print_rule(r, r->anchor ? r->anchor->name : "", 1467223057Sbz pf->opts & PF_OPT_VERBOSE2, 1468223057Sbz pf->opts & PF_OPT_NUMERIC); 1469171172Smlaier } 1470171172Smlaier path[len] = '\0'; 1471126353Smlaier pfctl_clear_pool(&r->rpool); 1472126353Smlaier return (0); 1473126353Smlaier} 1474126353Smlaier 1475126353Smlaierint 1476126353Smlaierpfctl_add_altq(struct pfctl *pf, struct pf_altq *a) 1477126353Smlaier{ 1478126353Smlaier if (altqsupport && 1479126353Smlaier (loadopt & PFCTL_FLAG_ALTQ) != 0) { 1480126353Smlaier memcpy(&pf->paltq->altq, a, sizeof(struct pf_altq)); 1481126353Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0) { 1482126353Smlaier if (ioctl(pf->dev, DIOCADDALTQ, pf->paltq)) { 1483126353Smlaier if (errno == ENXIO) 1484126353Smlaier errx(1, "qtype not configured"); 1485126353Smlaier else if (errno == ENODEV) 1486126353Smlaier errx(1, "%s: driver does not support " 1487126353Smlaier "altq", a->ifname); 1488126353Smlaier else 1489126353Smlaier err(1, "DIOCADDALTQ"); 1490126353Smlaier } 1491126353Smlaier } 1492126353Smlaier pfaltq_store(&pf->paltq->altq); 1493126353Smlaier } 1494126353Smlaier return (0); 1495126353Smlaier} 1496126353Smlaier 1497126353Smlaierint 1498223637Sbzpfctl_rules(int dev, char *filename, int opts, int optimize, 1499171172Smlaier char *anchorname, struct pfr_buffer *trans) 1500126353Smlaier{ 1501126353Smlaier#define ERR(x) do { warn(x); goto _error; } while(0) 1502126353Smlaier#define ERRX(x) do { warnx(x); goto _error; } while(0) 1503126353Smlaier 1504130617Smlaier struct pfr_buffer *t, buf; 1505130617Smlaier struct pfioc_altq pa; 1506130617Smlaier struct pfctl pf; 1507171172Smlaier struct pf_ruleset *rs; 1508130617Smlaier struct pfr_table trs; 1509171172Smlaier char *path; 1510130617Smlaier int osize; 1511126353Smlaier 1512171172Smlaier RB_INIT(&pf_anchors); 1513171172Smlaier memset(&pf_main_anchor, 0, sizeof(pf_main_anchor)); 1514171172Smlaier pf_init_ruleset(&pf_main_anchor.ruleset); 1515171172Smlaier pf_main_anchor.ruleset.anchor = &pf_main_anchor; 1516130617Smlaier if (trans == NULL) { 1517171172Smlaier bzero(&buf, sizeof(buf)); 1518171172Smlaier buf.pfrb_type = PFRB_TRANS; 1519171172Smlaier t = &buf; 1520171172Smlaier osize = 0; 1521130617Smlaier } else { 1522171172Smlaier t = trans; 1523171172Smlaier osize = t->pfrb_size; 1524130617Smlaier } 1525130617Smlaier 1526126353Smlaier memset(&pa, 0, sizeof(pa)); 1527126353Smlaier memset(&pf, 0, sizeof(pf)); 1528126353Smlaier memset(&trs, 0, sizeof(trs)); 1529171172Smlaier if ((path = calloc(1, MAXPATHLEN)) == NULL) 1530171172Smlaier ERRX("pfctl_rules: calloc"); 1531126353Smlaier if (strlcpy(trs.pfrt_anchor, anchorname, 1532145840Smlaier sizeof(trs.pfrt_anchor)) >= sizeof(trs.pfrt_anchor)) 1533126353Smlaier ERRX("pfctl_rules: strlcpy"); 1534126353Smlaier pf.dev = dev; 1535126353Smlaier pf.opts = opts; 1536171172Smlaier pf.optimize = optimize; 1537126353Smlaier pf.loadopt = loadopt; 1538171172Smlaier 1539171172Smlaier /* non-brace anchor, create without resolving the path */ 1540171172Smlaier if ((pf.anchor = calloc(1, sizeof(*pf.anchor))) == NULL) 1541171172Smlaier ERRX("pfctl_rules: calloc"); 1542171172Smlaier rs = &pf.anchor->ruleset; 1543171172Smlaier pf_init_ruleset(rs); 1544171172Smlaier rs->anchor = pf.anchor; 1545171172Smlaier if (strlcpy(pf.anchor->path, anchorname, 1546171172Smlaier sizeof(pf.anchor->path)) >= sizeof(pf.anchor->path)) 1547171172Smlaier errx(1, "pfctl_add_rule: strlcpy"); 1548171172Smlaier if (strlcpy(pf.anchor->name, anchorname, 1549171172Smlaier sizeof(pf.anchor->name)) >= sizeof(pf.anchor->name)) 1550171172Smlaier errx(1, "pfctl_add_rule: strlcpy"); 1551171172Smlaier 1552171172Smlaier 1553171172Smlaier pf.astack[0] = pf.anchor; 1554171172Smlaier pf.asd = 0; 1555130617Smlaier if (anchorname[0]) 1556130617Smlaier pf.loadopt &= ~PFCTL_FLAG_ALTQ; 1557126353Smlaier pf.paltq = &pa; 1558130617Smlaier pf.trans = t; 1559145840Smlaier pfctl_init_options(&pf); 1560130617Smlaier 1561130617Smlaier if ((opts & PF_OPT_NOACTION) == 0) { 1562171172Smlaier /* 1563171172Smlaier * XXX For the time being we need to open transactions for 1564171172Smlaier * the main ruleset before parsing, because tables are still 1565171172Smlaier * loaded at parse time. 1566171172Smlaier */ 1567171172Smlaier if (pfctl_ruleset_trans(&pf, anchorname, pf.anchor)) 1568171172Smlaier ERRX("pfctl_rules"); 1569130617Smlaier if (altqsupport && (pf.loadopt & PFCTL_FLAG_ALTQ)) 1570171172Smlaier pa.ticket = 1571171172Smlaier pfctl_get_ticket(t, PF_RULESET_ALTQ, anchorname); 1572130617Smlaier if (pf.loadopt & PFCTL_FLAG_TABLE) 1573171172Smlaier pf.astack[0]->ruleset.tticket = 1574171172Smlaier pfctl_get_ticket(t, PF_RULESET_TABLE, anchorname); 1575130617Smlaier } 1576171172Smlaier 1577223637Sbz if (parse_config(filename, &pf) < 0) { 1578126353Smlaier if ((opts & PF_OPT_NOACTION) == 0) 1579126353Smlaier ERRX("Syntax error in config file: " 1580126353Smlaier "pf rules not loaded"); 1581126353Smlaier else 1582126353Smlaier goto _error; 1583126353Smlaier } 1584333181Skp if (loadopt & PFCTL_FLAG_OPTION) 1585338390Skp pfctl_adjust_skip_ifaces(&pf); 1586171172Smlaier 1587171172Smlaier if ((pf.loadopt & PFCTL_FLAG_FILTER && 1588171172Smlaier (pfctl_load_ruleset(&pf, path, rs, PF_RULESET_SCRUB, 0))) || 1589171172Smlaier (pf.loadopt & PFCTL_FLAG_NAT && 1590171172Smlaier (pfctl_load_ruleset(&pf, path, rs, PF_RULESET_NAT, 0) || 1591171172Smlaier pfctl_load_ruleset(&pf, path, rs, PF_RULESET_RDR, 0) || 1592171172Smlaier pfctl_load_ruleset(&pf, path, rs, PF_RULESET_BINAT, 0))) || 1593171172Smlaier (pf.loadopt & PFCTL_FLAG_FILTER && 1594171172Smlaier pfctl_load_ruleset(&pf, path, rs, PF_RULESET_FILTER, 0))) { 1595171172Smlaier if ((opts & PF_OPT_NOACTION) == 0) 1596171172Smlaier ERRX("Unable to load rules into kernel"); 1597171172Smlaier else 1598171172Smlaier goto _error; 1599145840Smlaier } 1600145840Smlaier 1601130617Smlaier if ((altqsupport && (pf.loadopt & PFCTL_FLAG_ALTQ) != 0)) 1602126353Smlaier if (check_commit_altq(dev, opts) != 0) 1603126353Smlaier ERRX("errors in altq config"); 1604145840Smlaier 1605126353Smlaier /* process "load anchor" directives */ 1606145840Smlaier if (!anchorname[0]) 1607171172Smlaier if (pfctl_load_anchors(dev, &pf, t) == -1) 1608126353Smlaier ERRX("load anchors"); 1609126353Smlaier 1610145840Smlaier if (trans == NULL && (opts & PF_OPT_NOACTION) == 0) { 1611145840Smlaier if (!anchorname[0]) 1612145840Smlaier if (pfctl_load_options(&pf)) 1613145840Smlaier goto _error; 1614171172Smlaier if (pfctl_trans(dev, t, DIOCXCOMMIT, osize)) 1615130617Smlaier ERR("DIOCXCOMMIT"); 1616145840Smlaier } 1617126353Smlaier return (0); 1618126353Smlaier 1619126353Smlaier_error: 1620130617Smlaier if (trans == NULL) { /* main ruleset */ 1621130617Smlaier if ((opts & PF_OPT_NOACTION) == 0) 1622171172Smlaier if (pfctl_trans(dev, t, DIOCXROLLBACK, osize)) 1623130617Smlaier err(1, "DIOCXROLLBACK"); 1624130617Smlaier exit(1); 1625145840Smlaier } else { /* sub ruleset */ 1626130617Smlaier return (-1); 1627145840Smlaier } 1628126353Smlaier 1629126353Smlaier#undef ERR 1630126353Smlaier#undef ERRX 1631126353Smlaier} 1632126353Smlaier 1633145840SmlaierFILE * 1634145840Smlaierpfctl_fopen(const char *name, const char *mode) 1635145840Smlaier{ 1636145840Smlaier struct stat st; 1637145840Smlaier FILE *fp; 1638145840Smlaier 1639145840Smlaier fp = fopen(name, mode); 1640145840Smlaier if (fp == NULL) 1641145840Smlaier return (NULL); 1642145840Smlaier if (fstat(fileno(fp), &st)) { 1643145840Smlaier fclose(fp); 1644145840Smlaier return (NULL); 1645145840Smlaier } 1646145840Smlaier if (S_ISDIR(st.st_mode)) { 1647145840Smlaier fclose(fp); 1648145840Smlaier errno = EISDIR; 1649145840Smlaier return (NULL); 1650145840Smlaier } 1651145840Smlaier return (fp); 1652145840Smlaier} 1653145840Smlaier 1654145840Smlaiervoid 1655145840Smlaierpfctl_init_options(struct pfctl *pf) 1656145840Smlaier{ 1657171172Smlaier 1658145840Smlaier pf->timeout[PFTM_TCP_FIRST_PACKET] = PFTM_TCP_FIRST_PACKET_VAL; 1659145840Smlaier pf->timeout[PFTM_TCP_OPENING] = PFTM_TCP_OPENING_VAL; 1660145840Smlaier pf->timeout[PFTM_TCP_ESTABLISHED] = PFTM_TCP_ESTABLISHED_VAL; 1661145840Smlaier pf->timeout[PFTM_TCP_CLOSING] = PFTM_TCP_CLOSING_VAL; 1662145840Smlaier pf->timeout[PFTM_TCP_FIN_WAIT] = PFTM_TCP_FIN_WAIT_VAL; 1663145840Smlaier pf->timeout[PFTM_TCP_CLOSED] = PFTM_TCP_CLOSED_VAL; 1664145840Smlaier pf->timeout[PFTM_UDP_FIRST_PACKET] = PFTM_UDP_FIRST_PACKET_VAL; 1665145840Smlaier pf->timeout[PFTM_UDP_SINGLE] = PFTM_UDP_SINGLE_VAL; 1666145840Smlaier pf->timeout[PFTM_UDP_MULTIPLE] = PFTM_UDP_MULTIPLE_VAL; 1667145840Smlaier pf->timeout[PFTM_ICMP_FIRST_PACKET] = PFTM_ICMP_FIRST_PACKET_VAL; 1668145840Smlaier pf->timeout[PFTM_ICMP_ERROR_REPLY] = PFTM_ICMP_ERROR_REPLY_VAL; 1669145840Smlaier pf->timeout[PFTM_OTHER_FIRST_PACKET] = PFTM_OTHER_FIRST_PACKET_VAL; 1670145840Smlaier pf->timeout[PFTM_OTHER_SINGLE] = PFTM_OTHER_SINGLE_VAL; 1671145840Smlaier pf->timeout[PFTM_OTHER_MULTIPLE] = PFTM_OTHER_MULTIPLE_VAL; 1672145840Smlaier pf->timeout[PFTM_FRAG] = PFTM_FRAG_VAL; 1673145840Smlaier pf->timeout[PFTM_INTERVAL] = PFTM_INTERVAL_VAL; 1674145840Smlaier pf->timeout[PFTM_SRC_NODE] = PFTM_SRC_NODE_VAL; 1675145840Smlaier pf->timeout[PFTM_TS_DIFF] = PFTM_TS_DIFF_VAL; 1676171172Smlaier pf->timeout[PFTM_ADAPTIVE_START] = PFSTATE_ADAPT_START; 1677171172Smlaier pf->timeout[PFTM_ADAPTIVE_END] = PFSTATE_ADAPT_END; 1678145840Smlaier 1679171172Smlaier pf->limit[PF_LIMIT_STATES] = PFSTATE_HIWAT; 1680171172Smlaier pf->limit[PF_LIMIT_FRAGS] = PFFRAG_FRENT_HIWAT; 1681171172Smlaier pf->limit[PF_LIMIT_SRC_NODES] = PFSNODE_HIWAT; 1682171172Smlaier pf->limit[PF_LIMIT_TABLE_ENTRIES] = PFR_KENTRY_HIWAT; 1683145840Smlaier 1684145840Smlaier pf->debug = PF_DEBUG_URGENT; 1685145840Smlaier} 1686145840Smlaier 1687126353Smlaierint 1688145840Smlaierpfctl_load_options(struct pfctl *pf) 1689126353Smlaier{ 1690145840Smlaier int i, error = 0; 1691126353Smlaier 1692126353Smlaier if ((loadopt & PFCTL_FLAG_OPTION) == 0) 1693126353Smlaier return (0); 1694126353Smlaier 1695145840Smlaier /* load limits */ 1696145840Smlaier for (i = 0; i < PF_LIMIT_MAX; i++) { 1697145840Smlaier if ((pf->opts & PF_OPT_MERGE) && !pf->limit_set[i]) 1698145840Smlaier continue; 1699145840Smlaier if (pfctl_load_limit(pf, i, pf->limit[i])) 1700145840Smlaier error = 1; 1701145840Smlaier } 1702145840Smlaier 1703171172Smlaier /* 1704223637Sbz * If we've set the limit, but haven't explicitly set adaptive 1705171172Smlaier * timeouts, do it now with a start of 60% and end of 120%. 1706171172Smlaier */ 1707171172Smlaier if (pf->limit_set[PF_LIMIT_STATES] && 1708171172Smlaier !pf->timeout_set[PFTM_ADAPTIVE_START] && 1709171172Smlaier !pf->timeout_set[PFTM_ADAPTIVE_END]) { 1710171172Smlaier pf->timeout[PFTM_ADAPTIVE_START] = 1711171172Smlaier (pf->limit[PF_LIMIT_STATES] / 10) * 6; 1712171172Smlaier pf->timeout_set[PFTM_ADAPTIVE_START] = 1; 1713171172Smlaier pf->timeout[PFTM_ADAPTIVE_END] = 1714171172Smlaier (pf->limit[PF_LIMIT_STATES] / 10) * 12; 1715171172Smlaier pf->timeout_set[PFTM_ADAPTIVE_END] = 1; 1716171172Smlaier } 1717171172Smlaier 1718145840Smlaier /* load timeouts */ 1719145840Smlaier for (i = 0; i < PFTM_MAX; i++) { 1720145840Smlaier if ((pf->opts & PF_OPT_MERGE) && !pf->timeout_set[i]) 1721145840Smlaier continue; 1722145840Smlaier if (pfctl_load_timeout(pf, i, pf->timeout[i])) 1723145840Smlaier error = 1; 1724145840Smlaier } 1725145840Smlaier 1726145840Smlaier /* load debug */ 1727145840Smlaier if (!(pf->opts & PF_OPT_MERGE) || pf->debug_set) 1728145840Smlaier if (pfctl_load_debug(pf, pf->debug)) 1729145840Smlaier error = 1; 1730145840Smlaier 1731145840Smlaier /* load logif */ 1732145840Smlaier if (!(pf->opts & PF_OPT_MERGE) || pf->ifname_set) 1733145840Smlaier if (pfctl_load_logif(pf, pf->ifname)) 1734145840Smlaier error = 1; 1735145840Smlaier 1736145840Smlaier /* load hostid */ 1737145840Smlaier if (!(pf->opts & PF_OPT_MERGE) || pf->hostid_set) 1738145840Smlaier if (pfctl_load_hostid(pf, pf->hostid)) 1739145840Smlaier error = 1; 1740145840Smlaier 1741145840Smlaier return (error); 1742145840Smlaier} 1743145840Smlaier 1744145840Smlaierint 1745145840Smlaierpfctl_set_limit(struct pfctl *pf, const char *opt, unsigned int limit) 1746145840Smlaier{ 1747145840Smlaier int i; 1748145840Smlaier 1749145840Smlaier 1750126353Smlaier for (i = 0; pf_limits[i].name; i++) { 1751126353Smlaier if (strcasecmp(opt, pf_limits[i].name) == 0) { 1752145840Smlaier pf->limit[pf_limits[i].index] = limit; 1753145840Smlaier pf->limit_set[pf_limits[i].index] = 1; 1754126353Smlaier break; 1755126353Smlaier } 1756126353Smlaier } 1757126353Smlaier if (pf_limits[i].name == NULL) { 1758126353Smlaier warnx("Bad pool name."); 1759126353Smlaier return (1); 1760126353Smlaier } 1761126353Smlaier 1762126353Smlaier if (pf->opts & PF_OPT_VERBOSE) 1763126353Smlaier printf("set limit %s %d\n", opt, limit); 1764126353Smlaier 1765126353Smlaier return (0); 1766126353Smlaier} 1767126353Smlaier 1768126353Smlaierint 1769145840Smlaierpfctl_load_limit(struct pfctl *pf, unsigned int index, unsigned int limit) 1770145840Smlaier{ 1771145840Smlaier struct pfioc_limit pl; 1772145840Smlaier 1773145840Smlaier memset(&pl, 0, sizeof(pl)); 1774145840Smlaier pl.index = index; 1775145840Smlaier pl.limit = limit; 1776145840Smlaier if (ioctl(pf->dev, DIOCSETLIMIT, &pl)) { 1777145840Smlaier if (errno == EBUSY) 1778145840Smlaier warnx("Current pool size exceeds requested hard limit"); 1779145840Smlaier else 1780145840Smlaier warnx("DIOCSETLIMIT"); 1781145840Smlaier return (1); 1782145840Smlaier } 1783145840Smlaier return (0); 1784145840Smlaier} 1785145840Smlaier 1786145840Smlaierint 1787126353Smlaierpfctl_set_timeout(struct pfctl *pf, const char *opt, int seconds, int quiet) 1788126353Smlaier{ 1789126353Smlaier int i; 1790126353Smlaier 1791126353Smlaier if ((loadopt & PFCTL_FLAG_OPTION) == 0) 1792126353Smlaier return (0); 1793126353Smlaier 1794126353Smlaier for (i = 0; pf_timeouts[i].name; i++) { 1795126353Smlaier if (strcasecmp(opt, pf_timeouts[i].name) == 0) { 1796145840Smlaier pf->timeout[pf_timeouts[i].timeout] = seconds; 1797145840Smlaier pf->timeout_set[pf_timeouts[i].timeout] = 1; 1798126353Smlaier break; 1799126353Smlaier } 1800126353Smlaier } 1801126353Smlaier 1802126353Smlaier if (pf_timeouts[i].name == NULL) { 1803126353Smlaier warnx("Bad timeout name."); 1804126353Smlaier return (1); 1805126353Smlaier } 1806126353Smlaier 1807126353Smlaier 1808126353Smlaier if (pf->opts & PF_OPT_VERBOSE && ! quiet) 1809126353Smlaier printf("set timeout %s %d\n", opt, seconds); 1810126353Smlaier 1811126353Smlaier return (0); 1812126353Smlaier} 1813126353Smlaier 1814126353Smlaierint 1815145840Smlaierpfctl_load_timeout(struct pfctl *pf, unsigned int timeout, unsigned int seconds) 1816145840Smlaier{ 1817145840Smlaier struct pfioc_tm pt; 1818145840Smlaier 1819145840Smlaier memset(&pt, 0, sizeof(pt)); 1820145840Smlaier pt.timeout = timeout; 1821145840Smlaier pt.seconds = seconds; 1822145840Smlaier if (ioctl(pf->dev, DIOCSETTIMEOUT, &pt)) { 1823145840Smlaier warnx("DIOCSETTIMEOUT"); 1824145840Smlaier return (1); 1825145840Smlaier } 1826145840Smlaier return (0); 1827145840Smlaier} 1828145840Smlaier 1829145840Smlaierint 1830126353Smlaierpfctl_set_optimization(struct pfctl *pf, const char *opt) 1831126353Smlaier{ 1832126353Smlaier const struct pf_hint *hint; 1833126353Smlaier int i, r; 1834126353Smlaier 1835126353Smlaier if ((loadopt & PFCTL_FLAG_OPTION) == 0) 1836126353Smlaier return (0); 1837126353Smlaier 1838126353Smlaier for (i = 0; pf_hints[i].name; i++) 1839126353Smlaier if (strcasecmp(opt, pf_hints[i].name) == 0) 1840126353Smlaier break; 1841126353Smlaier 1842126353Smlaier hint = pf_hints[i].hint; 1843126353Smlaier if (hint == NULL) { 1844171172Smlaier warnx("invalid state timeouts optimization"); 1845126353Smlaier return (1); 1846126353Smlaier } 1847126353Smlaier 1848126353Smlaier for (i = 0; hint[i].name; i++) 1849126353Smlaier if ((r = pfctl_set_timeout(pf, hint[i].name, 1850126353Smlaier hint[i].timeout, 1))) 1851126353Smlaier return (r); 1852126353Smlaier 1853126353Smlaier if (pf->opts & PF_OPT_VERBOSE) 1854126353Smlaier printf("set optimization %s\n", opt); 1855126353Smlaier 1856126353Smlaier return (0); 1857126353Smlaier} 1858126353Smlaier 1859126353Smlaierint 1860126353Smlaierpfctl_set_logif(struct pfctl *pf, char *ifname) 1861126353Smlaier{ 1862126353Smlaier 1863126353Smlaier if ((loadopt & PFCTL_FLAG_OPTION) == 0) 1864126353Smlaier return (0); 1865126353Smlaier 1866145840Smlaier if (!strcmp(ifname, "none")) { 1867145840Smlaier free(pf->ifname); 1868145840Smlaier pf->ifname = NULL; 1869145840Smlaier } else { 1870145840Smlaier pf->ifname = strdup(ifname); 1871145840Smlaier if (!pf->ifname) 1872145840Smlaier errx(1, "pfctl_set_logif: strdup"); 1873126353Smlaier } 1874145840Smlaier pf->ifname_set = 1; 1875126353Smlaier 1876126353Smlaier if (pf->opts & PF_OPT_VERBOSE) 1877126353Smlaier printf("set loginterface %s\n", ifname); 1878126353Smlaier 1879126353Smlaier return (0); 1880126353Smlaier} 1881126353Smlaier 1882126353Smlaierint 1883145840Smlaierpfctl_load_logif(struct pfctl *pf, char *ifname) 1884145840Smlaier{ 1885145840Smlaier struct pfioc_if pi; 1886145840Smlaier 1887145840Smlaier memset(&pi, 0, sizeof(pi)); 1888145840Smlaier if (ifname && strlcpy(pi.ifname, ifname, 1889145840Smlaier sizeof(pi.ifname)) >= sizeof(pi.ifname)) { 1890171172Smlaier warnx("pfctl_load_logif: strlcpy"); 1891145840Smlaier return (1); 1892145840Smlaier } 1893145840Smlaier if (ioctl(pf->dev, DIOCSETSTATUSIF, &pi)) { 1894145840Smlaier warnx("DIOCSETSTATUSIF"); 1895145840Smlaier return (1); 1896145840Smlaier } 1897145840Smlaier return (0); 1898145840Smlaier} 1899145840Smlaier 1900145840Smlaierint 1901130617Smlaierpfctl_set_hostid(struct pfctl *pf, u_int32_t hostid) 1902130617Smlaier{ 1903130617Smlaier if ((loadopt & PFCTL_FLAG_OPTION) == 0) 1904130617Smlaier return (0); 1905130617Smlaier 1906130617Smlaier HTONL(hostid); 1907130617Smlaier 1908145840Smlaier pf->hostid = hostid; 1909145840Smlaier pf->hostid_set = 1; 1910130617Smlaier 1911130617Smlaier if (pf->opts & PF_OPT_VERBOSE) 1912130617Smlaier printf("set hostid 0x%08x\n", ntohl(hostid)); 1913130617Smlaier 1914130617Smlaier return (0); 1915130617Smlaier} 1916130617Smlaier 1917130617Smlaierint 1918145840Smlaierpfctl_load_hostid(struct pfctl *pf, u_int32_t hostid) 1919145840Smlaier{ 1920145840Smlaier if (ioctl(dev, DIOCSETHOSTID, &hostid)) { 1921145840Smlaier warnx("DIOCSETHOSTID"); 1922145840Smlaier return (1); 1923145840Smlaier } 1924145840Smlaier return (0); 1925145840Smlaier} 1926145840Smlaier 1927145840Smlaierint 1928130617Smlaierpfctl_set_debug(struct pfctl *pf, char *d) 1929130617Smlaier{ 1930130617Smlaier u_int32_t level; 1931130617Smlaier 1932130617Smlaier if ((loadopt & PFCTL_FLAG_OPTION) == 0) 1933130617Smlaier return (0); 1934130617Smlaier 1935130617Smlaier if (!strcmp(d, "none")) 1936145840Smlaier pf->debug = PF_DEBUG_NONE; 1937130617Smlaier else if (!strcmp(d, "urgent")) 1938145840Smlaier pf->debug = PF_DEBUG_URGENT; 1939130617Smlaier else if (!strcmp(d, "misc")) 1940145840Smlaier pf->debug = PF_DEBUG_MISC; 1941130617Smlaier else if (!strcmp(d, "loud")) 1942145840Smlaier pf->debug = PF_DEBUG_NOISY; 1943130617Smlaier else { 1944130617Smlaier warnx("unknown debug level \"%s\"", d); 1945130617Smlaier return (-1); 1946130617Smlaier } 1947130617Smlaier 1948145840Smlaier pf->debug_set = 1; 1949290236Skp level = pf->debug; 1950145840Smlaier 1951130617Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0) 1952130617Smlaier if (ioctl(dev, DIOCSETDEBUG, &level)) 1953130617Smlaier err(1, "DIOCSETDEBUG"); 1954130617Smlaier 1955130617Smlaier if (pf->opts & PF_OPT_VERBOSE) 1956130617Smlaier printf("set debug %s\n", d); 1957130617Smlaier 1958130617Smlaier return (0); 1959130617Smlaier} 1960130617Smlaier 1961130617Smlaierint 1962145840Smlaierpfctl_load_debug(struct pfctl *pf, unsigned int level) 1963145840Smlaier{ 1964145840Smlaier if (ioctl(pf->dev, DIOCSETDEBUG, &level)) { 1965145840Smlaier warnx("DIOCSETDEBUG"); 1966145840Smlaier return (1); 1967145840Smlaier } 1968145840Smlaier return (0); 1969145840Smlaier} 1970145840Smlaier 1971145840Smlaierint 1972145840Smlaierpfctl_set_interface_flags(struct pfctl *pf, char *ifname, int flags, int how) 1973145840Smlaier{ 1974145840Smlaier struct pfioc_iface pi; 1975343229Skp struct node_host *h = NULL, *n = NULL; 1976145840Smlaier 1977145840Smlaier if ((loadopt & PFCTL_FLAG_OPTION) == 0) 1978145840Smlaier return (0); 1979145840Smlaier 1980145840Smlaier bzero(&pi, sizeof(pi)); 1981145840Smlaier 1982145840Smlaier pi.pfiio_flags = flags; 1983145840Smlaier 1984343229Skp /* Make sure our cache matches the kernel. If we set or clear the flag 1985343229Skp * for a group this applies to all members. */ 1986343229Skp h = ifa_grouplookup(ifname, 0); 1987343229Skp for (n = h; n != NULL; n = n->next) 1988343229Skp pfctl_set_interface_flags(pf, n->ifname, flags, how); 1989343229Skp 1990145840Smlaier if (strlcpy(pi.pfiio_name, ifname, sizeof(pi.pfiio_name)) >= 1991145840Smlaier sizeof(pi.pfiio_name)) 1992145840Smlaier errx(1, "pfctl_set_interface_flags: strlcpy"); 1993145840Smlaier 1994145840Smlaier if ((pf->opts & PF_OPT_NOACTION) == 0) { 1995145840Smlaier if (how == 0) { 1996145840Smlaier if (ioctl(pf->dev, DIOCCLRIFFLAG, &pi)) 1997145840Smlaier err(1, "DIOCCLRIFFLAG"); 1998145840Smlaier } else { 1999145840Smlaier if (ioctl(pf->dev, DIOCSETIFFLAG, &pi)) 2000145840Smlaier err(1, "DIOCSETIFFLAG"); 2001333181Skp pfctl_check_skip_ifaces(ifname); 2002145840Smlaier } 2003145840Smlaier } 2004145840Smlaier return (0); 2005145840Smlaier} 2006145840Smlaier 2007145840Smlaiervoid 2008126353Smlaierpfctl_debug(int dev, u_int32_t level, int opts) 2009126353Smlaier{ 2010126353Smlaier if (ioctl(dev, DIOCSETDEBUG, &level)) 2011126353Smlaier err(1, "DIOCSETDEBUG"); 2012126353Smlaier if ((opts & PF_OPT_QUIET) == 0) { 2013126353Smlaier fprintf(stderr, "debug level set to '"); 2014126353Smlaier switch (level) { 2015126353Smlaier case PF_DEBUG_NONE: 2016126353Smlaier fprintf(stderr, "none"); 2017126353Smlaier break; 2018126353Smlaier case PF_DEBUG_URGENT: 2019126353Smlaier fprintf(stderr, "urgent"); 2020126353Smlaier break; 2021126353Smlaier case PF_DEBUG_MISC: 2022126353Smlaier fprintf(stderr, "misc"); 2023126353Smlaier break; 2024126353Smlaier case PF_DEBUG_NOISY: 2025126353Smlaier fprintf(stderr, "loud"); 2026126353Smlaier break; 2027126353Smlaier default: 2028126353Smlaier fprintf(stderr, "<invalid>"); 2029126353Smlaier break; 2030126353Smlaier } 2031126353Smlaier fprintf(stderr, "'\n"); 2032126353Smlaier } 2033126353Smlaier} 2034126353Smlaier 2035126353Smlaierint 2036126353Smlaierpfctl_test_altqsupport(int dev, int opts) 2037126353Smlaier{ 2038126353Smlaier struct pfioc_altq pa; 2039126353Smlaier 2040126353Smlaier if (ioctl(dev, DIOCGETALTQS, &pa)) { 2041126353Smlaier if (errno == ENODEV) { 2042285730Sgnn if (opts & PF_OPT_VERBOSE) 2043126353Smlaier fprintf(stderr, "No ALTQ support in kernel\n" 2044126353Smlaier "ALTQ related functions disabled\n"); 2045126353Smlaier return (0); 2046126353Smlaier } else 2047126353Smlaier err(1, "DIOCGETALTQS"); 2048126353Smlaier } 2049126353Smlaier return (1); 2050126353Smlaier} 2051126353Smlaier 2052126353Smlaierint 2053126353Smlaierpfctl_show_anchors(int dev, int opts, char *anchorname) 2054126353Smlaier{ 2055145840Smlaier struct pfioc_ruleset pr; 2056145840Smlaier u_int32_t mnr, nr; 2057126353Smlaier 2058145840Smlaier memset(&pr, 0, sizeof(pr)); 2059145840Smlaier memcpy(pr.path, anchorname, sizeof(pr.path)); 2060145840Smlaier if (ioctl(dev, DIOCGETRULESETS, &pr)) { 2061145840Smlaier if (errno == EINVAL) 2062145840Smlaier fprintf(stderr, "Anchor '%s' not found.\n", 2063145840Smlaier anchorname); 2064145840Smlaier else 2065145840Smlaier err(1, "DIOCGETRULESETS"); 2066145840Smlaier return (-1); 2067145840Smlaier } 2068145840Smlaier mnr = pr.nr; 2069145840Smlaier for (nr = 0; nr < mnr; ++nr) { 2070145840Smlaier char sub[MAXPATHLEN]; 2071126353Smlaier 2072145840Smlaier pr.nr = nr; 2073145840Smlaier if (ioctl(dev, DIOCGETRULESET, &pr)) 2074145840Smlaier err(1, "DIOCGETRULESET"); 2075145840Smlaier if (!strcmp(pr.name, PF_RESERVED_ANCHOR)) 2076145840Smlaier continue; 2077145840Smlaier sub[0] = 0; 2078145840Smlaier if (pr.path[0]) { 2079145840Smlaier strlcat(sub, pr.path, sizeof(sub)); 2080145840Smlaier strlcat(sub, "/", sizeof(sub)); 2081126353Smlaier } 2082145840Smlaier strlcat(sub, pr.name, sizeof(sub)); 2083171172Smlaier if (sub[0] != '_' || (opts & PF_OPT_VERBOSE)) 2084171172Smlaier printf(" %s\n", sub); 2085171172Smlaier if ((opts & PF_OPT_VERBOSE) && pfctl_show_anchors(dev, opts, sub)) 2086126353Smlaier return (-1); 2087126353Smlaier } 2088126353Smlaier return (0); 2089126353Smlaier} 2090126353Smlaier 2091126353Smlaierconst char * 2092126353Smlaierpfctl_lookup_option(char *cmd, const char **list) 2093126353Smlaier{ 2094126353Smlaier if (cmd != NULL && *cmd) 2095126353Smlaier for (; *list; list++) 2096126353Smlaier if (!strncmp(cmd, *list, strlen(cmd))) 2097126353Smlaier return (*list); 2098126353Smlaier return (NULL); 2099126353Smlaier} 2100126353Smlaier 2101126353Smlaierint 2102126353Smlaiermain(int argc, char *argv[]) 2103126353Smlaier{ 2104171172Smlaier int error = 0; 2105171172Smlaier int ch; 2106171172Smlaier int mode = O_RDONLY; 2107171172Smlaier int opts = 0; 2108223637Sbz int optimize = PF_OPTIMIZE_BASIC; 2109171172Smlaier char anchorname[MAXPATHLEN]; 2110171172Smlaier char *path; 2111126353Smlaier 2112126353Smlaier if (argc < 2) 2113126353Smlaier usage(); 2114126353Smlaier 2115130617Smlaier while ((ch = getopt(argc, argv, 2116223637Sbz "a:AdD:eqf:F:ghi:k:K:mnNOo:Pp:rRs:t:T:vx:z")) != -1) { 2117126353Smlaier switch (ch) { 2118126353Smlaier case 'a': 2119126353Smlaier anchoropt = optarg; 2120126353Smlaier break; 2121126353Smlaier case 'd': 2122126353Smlaier opts |= PF_OPT_DISABLE; 2123126353Smlaier mode = O_RDWR; 2124126353Smlaier break; 2125126353Smlaier case 'D': 2126126353Smlaier if (pfctl_cmdline_symset(optarg) < 0) 2127126353Smlaier warnx("could not parse macro definition %s", 2128126353Smlaier optarg); 2129126353Smlaier break; 2130126353Smlaier case 'e': 2131126353Smlaier opts |= PF_OPT_ENABLE; 2132126353Smlaier mode = O_RDWR; 2133126353Smlaier break; 2134126353Smlaier case 'q': 2135126353Smlaier opts |= PF_OPT_QUIET; 2136126353Smlaier break; 2137126353Smlaier case 'F': 2138126353Smlaier clearopt = pfctl_lookup_option(optarg, clearopt_list); 2139126353Smlaier if (clearopt == NULL) { 2140126353Smlaier warnx("Unknown flush modifier '%s'", optarg); 2141126353Smlaier usage(); 2142126353Smlaier } 2143126353Smlaier mode = O_RDWR; 2144126353Smlaier break; 2145130617Smlaier case 'i': 2146130617Smlaier ifaceopt = optarg; 2147130617Smlaier break; 2148126353Smlaier case 'k': 2149126353Smlaier if (state_killers >= 2) { 2150126353Smlaier warnx("can only specify -k twice"); 2151126353Smlaier usage(); 2152126353Smlaier /* NOTREACHED */ 2153126353Smlaier } 2154126353Smlaier state_kill[state_killers++] = optarg; 2155126353Smlaier mode = O_RDWR; 2156126353Smlaier break; 2157171172Smlaier case 'K': 2158171172Smlaier if (src_node_killers >= 2) { 2159171172Smlaier warnx("can only specify -K twice"); 2160171172Smlaier usage(); 2161171172Smlaier /* NOTREACHED */ 2162171172Smlaier } 2163171172Smlaier src_node_kill[src_node_killers++] = optarg; 2164171172Smlaier mode = O_RDWR; 2165171172Smlaier break; 2166145840Smlaier case 'm': 2167145840Smlaier opts |= PF_OPT_MERGE; 2168145840Smlaier break; 2169126353Smlaier case 'n': 2170126353Smlaier opts |= PF_OPT_NOACTION; 2171126353Smlaier break; 2172126353Smlaier case 'N': 2173126353Smlaier loadopt |= PFCTL_FLAG_NAT; 2174126353Smlaier break; 2175126353Smlaier case 'r': 2176126353Smlaier opts |= PF_OPT_USEDNS; 2177126353Smlaier break; 2178126353Smlaier case 'f': 2179126353Smlaier rulesopt = optarg; 2180126353Smlaier mode = O_RDWR; 2181126353Smlaier break; 2182126353Smlaier case 'g': 2183126353Smlaier opts |= PF_OPT_DEBUG; 2184126353Smlaier break; 2185126353Smlaier case 'A': 2186126353Smlaier loadopt |= PFCTL_FLAG_ALTQ; 2187126353Smlaier break; 2188126353Smlaier case 'R': 2189126353Smlaier loadopt |= PFCTL_FLAG_FILTER; 2190126353Smlaier break; 2191145840Smlaier case 'o': 2192223637Sbz optiopt = pfctl_lookup_option(optarg, optiopt_list); 2193223637Sbz if (optiopt == NULL) { 2194223637Sbz warnx("Unknown optimization '%s'", optarg); 2195223637Sbz usage(); 2196171172Smlaier } 2197171172Smlaier opts |= PF_OPT_OPTIMIZE; 2198145840Smlaier break; 2199126353Smlaier case 'O': 2200126353Smlaier loadopt |= PFCTL_FLAG_OPTION; 2201126353Smlaier break; 2202130617Smlaier case 'p': 2203130617Smlaier pf_device = optarg; 2204130617Smlaier break; 2205223057Sbz case 'P': 2206223057Sbz opts |= PF_OPT_NUMERIC; 2207223057Sbz break; 2208126353Smlaier case 's': 2209126353Smlaier showopt = pfctl_lookup_option(optarg, showopt_list); 2210126353Smlaier if (showopt == NULL) { 2211126353Smlaier warnx("Unknown show modifier '%s'", optarg); 2212126353Smlaier usage(); 2213126353Smlaier } 2214126353Smlaier break; 2215126353Smlaier case 't': 2216126353Smlaier tableopt = optarg; 2217126353Smlaier break; 2218126353Smlaier case 'T': 2219126353Smlaier tblcmdopt = pfctl_lookup_option(optarg, tblcmdopt_list); 2220126353Smlaier if (tblcmdopt == NULL) { 2221126353Smlaier warnx("Unknown table command '%s'", optarg); 2222126353Smlaier usage(); 2223126353Smlaier } 2224126353Smlaier break; 2225126353Smlaier case 'v': 2226126353Smlaier if (opts & PF_OPT_VERBOSE) 2227126353Smlaier opts |= PF_OPT_VERBOSE2; 2228126353Smlaier opts |= PF_OPT_VERBOSE; 2229126353Smlaier break; 2230126353Smlaier case 'x': 2231126353Smlaier debugopt = pfctl_lookup_option(optarg, debugopt_list); 2232126353Smlaier if (debugopt == NULL) { 2233126353Smlaier warnx("Unknown debug level '%s'", optarg); 2234126353Smlaier usage(); 2235126353Smlaier } 2236126353Smlaier mode = O_RDWR; 2237126353Smlaier break; 2238126353Smlaier case 'z': 2239126353Smlaier opts |= PF_OPT_CLRRULECTRS; 2240126353Smlaier mode = O_RDWR; 2241126353Smlaier break; 2242126353Smlaier case 'h': 2243126353Smlaier /* FALLTHROUGH */ 2244126353Smlaier default: 2245126353Smlaier usage(); 2246126353Smlaier /* NOTREACHED */ 2247126353Smlaier } 2248126353Smlaier } 2249126353Smlaier 2250126353Smlaier if (tblcmdopt != NULL) { 2251126353Smlaier argc -= optind; 2252126353Smlaier argv += optind; 2253126353Smlaier ch = *tblcmdopt; 2254126353Smlaier if (ch == 'l') { 2255126353Smlaier loadopt |= PFCTL_FLAG_TABLE; 2256126353Smlaier tblcmdopt = NULL; 2257130617Smlaier } else 2258171172Smlaier mode = strchr("acdefkrz", ch) ? O_RDWR : O_RDONLY; 2259126353Smlaier } else if (argc != optind) { 2260126353Smlaier warnx("unknown command line argument: %s ...", argv[optind]); 2261126353Smlaier usage(); 2262126353Smlaier /* NOTREACHED */ 2263126353Smlaier } 2264126353Smlaier if (loadopt == 0) 2265126353Smlaier loadopt = ~0; 2266126353Smlaier 2267171172Smlaier if ((path = calloc(1, MAXPATHLEN)) == NULL) 2268171172Smlaier errx(1, "pfctl: calloc"); 2269126353Smlaier memset(anchorname, 0, sizeof(anchorname)); 2270126353Smlaier if (anchoropt != NULL) { 2271171172Smlaier int len = strlen(anchoropt); 2272171172Smlaier 2273171172Smlaier if (anchoropt[len - 1] == '*') { 2274171172Smlaier if (len >= 2 && anchoropt[len - 2] == '/') 2275171172Smlaier anchoropt[len - 2] = '\0'; 2276171172Smlaier else 2277171172Smlaier anchoropt[len - 1] = '\0'; 2278171172Smlaier opts |= PF_OPT_RECURSE; 2279171172Smlaier } 2280145840Smlaier if (strlcpy(anchorname, anchoropt, 2281145840Smlaier sizeof(anchorname)) >= sizeof(anchorname)) 2282145840Smlaier errx(1, "anchor name '%s' too long", 2283145840Smlaier anchoropt); 2284126353Smlaier loadopt &= PFCTL_FLAG_FILTER|PFCTL_FLAG_NAT|PFCTL_FLAG_TABLE; 2285126353Smlaier } 2286126353Smlaier 2287126353Smlaier if ((opts & PF_OPT_NOACTION) == 0) { 2288130617Smlaier dev = open(pf_device, mode); 2289126353Smlaier if (dev == -1) 2290130617Smlaier err(1, "%s", pf_device); 2291126353Smlaier altqsupport = pfctl_test_altqsupport(dev, opts); 2292126353Smlaier } else { 2293130617Smlaier dev = open(pf_device, O_RDONLY); 2294130617Smlaier if (dev >= 0) 2295130617Smlaier opts |= PF_OPT_DUMMYACTION; 2296126353Smlaier /* turn off options */ 2297126353Smlaier opts &= ~ (PF_OPT_DISABLE | PF_OPT_ENABLE); 2298126353Smlaier clearopt = showopt = debugopt = NULL; 2299258485Sglebius#if !defined(ENABLE_ALTQ) 2300126355Smlaier altqsupport = 0; 2301126355Smlaier#else 2302126353Smlaier altqsupport = 1; 2303126355Smlaier#endif 2304126353Smlaier } 2305126353Smlaier 2306126353Smlaier if (opts & PF_OPT_DISABLE) 2307126353Smlaier if (pfctl_disable(dev, opts)) 2308126353Smlaier error = 1; 2309126353Smlaier 2310126353Smlaier if (showopt != NULL) { 2311126353Smlaier switch (*showopt) { 2312126353Smlaier case 'A': 2313126353Smlaier pfctl_show_anchors(dev, opts, anchorname); 2314126353Smlaier break; 2315126353Smlaier case 'r': 2316126353Smlaier pfctl_load_fingerprints(dev, opts); 2317171172Smlaier pfctl_show_rules(dev, path, opts, PFCTL_SHOW_RULES, 2318171172Smlaier anchorname, 0); 2319126353Smlaier break; 2320126353Smlaier case 'l': 2321126353Smlaier pfctl_load_fingerprints(dev, opts); 2322171172Smlaier pfctl_show_rules(dev, path, opts, PFCTL_SHOW_LABELS, 2323171172Smlaier anchorname, 0); 2324126353Smlaier break; 2325126353Smlaier case 'n': 2326126353Smlaier pfctl_load_fingerprints(dev, opts); 2327145840Smlaier pfctl_show_nat(dev, opts, anchorname); 2328126353Smlaier break; 2329126353Smlaier case 'q': 2330130617Smlaier pfctl_show_altq(dev, ifaceopt, opts, 2331130617Smlaier opts & PF_OPT_VERBOSE2); 2332126353Smlaier break; 2333126353Smlaier case 's': 2334130617Smlaier pfctl_show_states(dev, ifaceopt, opts); 2335126353Smlaier break; 2336130617Smlaier case 'S': 2337130617Smlaier pfctl_show_src_nodes(dev, opts); 2338130617Smlaier break; 2339126353Smlaier case 'i': 2340130617Smlaier pfctl_show_status(dev, opts); 2341126353Smlaier break; 2342335058Skp case 'R': 2343335058Skp error = pfctl_show_running(dev); 2344335058Skp break; 2345126353Smlaier case 't': 2346130617Smlaier pfctl_show_timeouts(dev, opts); 2347126353Smlaier break; 2348126353Smlaier case 'm': 2349130617Smlaier pfctl_show_limits(dev, opts); 2350126353Smlaier break; 2351126353Smlaier case 'a': 2352130617Smlaier opts |= PF_OPT_SHOWALL; 2353126353Smlaier pfctl_load_fingerprints(dev, opts); 2354126353Smlaier 2355145840Smlaier pfctl_show_nat(dev, opts, anchorname); 2356171172Smlaier pfctl_show_rules(dev, path, opts, 0, anchorname, 0); 2357130617Smlaier pfctl_show_altq(dev, ifaceopt, opts, 0); 2358130617Smlaier pfctl_show_states(dev, ifaceopt, opts); 2359130617Smlaier pfctl_show_src_nodes(dev, opts); 2360130617Smlaier pfctl_show_status(dev, opts); 2361171172Smlaier pfctl_show_rules(dev, path, opts, 1, anchorname, 0); 2362130617Smlaier pfctl_show_timeouts(dev, opts); 2363130617Smlaier pfctl_show_limits(dev, opts); 2364145840Smlaier pfctl_show_tables(anchorname, opts); 2365126353Smlaier pfctl_show_fingerprints(opts); 2366126353Smlaier break; 2367126353Smlaier case 'T': 2368145840Smlaier pfctl_show_tables(anchorname, opts); 2369126353Smlaier break; 2370126353Smlaier case 'o': 2371126353Smlaier pfctl_load_fingerprints(dev, opts); 2372126353Smlaier pfctl_show_fingerprints(opts); 2373126353Smlaier break; 2374130617Smlaier case 'I': 2375130617Smlaier pfctl_show_ifaces(ifaceopt, opts); 2376130617Smlaier break; 2377126353Smlaier } 2378126353Smlaier } 2379126353Smlaier 2380171172Smlaier if ((opts & PF_OPT_CLRRULECTRS) && showopt == NULL) 2381171172Smlaier pfctl_show_rules(dev, path, opts, PFCTL_SHOW_NOTHING, 2382171172Smlaier anchorname, 0); 2383171172Smlaier 2384126353Smlaier if (clearopt != NULL) { 2385171172Smlaier if (anchorname[0] == '_' || strstr(anchorname, "/_") != NULL) 2386171172Smlaier errx(1, "anchor names beginning with '_' cannot " 2387171172Smlaier "be modified from the command line"); 2388171172Smlaier 2389126353Smlaier switch (*clearopt) { 2390126353Smlaier case 'r': 2391145840Smlaier pfctl_clear_rules(dev, opts, anchorname); 2392126353Smlaier break; 2393126353Smlaier case 'n': 2394145840Smlaier pfctl_clear_nat(dev, opts, anchorname); 2395126353Smlaier break; 2396126353Smlaier case 'q': 2397126353Smlaier pfctl_clear_altq(dev, opts); 2398126353Smlaier break; 2399126353Smlaier case 's': 2400130617Smlaier pfctl_clear_states(dev, ifaceopt, opts); 2401126353Smlaier break; 2402130617Smlaier case 'S': 2403130617Smlaier pfctl_clear_src_nodes(dev, opts); 2404130617Smlaier break; 2405126353Smlaier case 'i': 2406126353Smlaier pfctl_clear_stats(dev, opts); 2407126353Smlaier break; 2408126353Smlaier case 'a': 2409145840Smlaier pfctl_clear_rules(dev, opts, anchorname); 2410145840Smlaier pfctl_clear_nat(dev, opts, anchorname); 2411145840Smlaier pfctl_clear_tables(anchorname, opts); 2412145840Smlaier if (!*anchorname) { 2413130617Smlaier pfctl_clear_altq(dev, opts); 2414130617Smlaier pfctl_clear_states(dev, ifaceopt, opts); 2415130617Smlaier pfctl_clear_src_nodes(dev, opts); 2416130617Smlaier pfctl_clear_stats(dev, opts); 2417130617Smlaier pfctl_clear_fingerprints(dev, opts); 2418145840Smlaier pfctl_clear_interface_flags(dev, opts); 2419130617Smlaier } 2420126353Smlaier break; 2421126353Smlaier case 'o': 2422126353Smlaier pfctl_clear_fingerprints(dev, opts); 2423126353Smlaier break; 2424126353Smlaier case 'T': 2425145840Smlaier pfctl_clear_tables(anchorname, opts); 2426126353Smlaier break; 2427126353Smlaier } 2428126353Smlaier } 2429223637Sbz if (state_killers) { 2430223637Sbz if (!strcmp(state_kill[0], "label")) 2431223637Sbz pfctl_label_kill_states(dev, ifaceopt, opts); 2432223637Sbz else if (!strcmp(state_kill[0], "id")) 2433223637Sbz pfctl_id_kill_states(dev, ifaceopt, opts); 2434223637Sbz else 2435223637Sbz pfctl_net_kill_states(dev, ifaceopt, opts); 2436223637Sbz } 2437126353Smlaier 2438171172Smlaier if (src_node_killers) 2439171172Smlaier pfctl_kill_src_nodes(dev, ifaceopt, opts); 2440171172Smlaier 2441126353Smlaier if (tblcmdopt != NULL) { 2442126353Smlaier error = pfctl_command_tables(argc, argv, tableopt, 2443145840Smlaier tblcmdopt, rulesopt, anchorname, opts); 2444126353Smlaier rulesopt = NULL; 2445126353Smlaier } 2446171172Smlaier if (optiopt != NULL) { 2447171172Smlaier switch (*optiopt) { 2448171172Smlaier case 'n': 2449171172Smlaier optimize = 0; 2450171172Smlaier break; 2451171172Smlaier case 'b': 2452171172Smlaier optimize |= PF_OPTIMIZE_BASIC; 2453171172Smlaier break; 2454171172Smlaier case 'o': 2455171172Smlaier case 'p': 2456171172Smlaier optimize |= PF_OPTIMIZE_PROFILE; 2457171172Smlaier break; 2458171172Smlaier } 2459171172Smlaier } 2460126353Smlaier 2461171172Smlaier if ((rulesopt != NULL) && (loadopt & PFCTL_FLAG_OPTION) && 2462336164Skp !anchorname[0] && !(opts & PF_OPT_NOACTION)) 2463333181Skp if (pfctl_get_skip_ifaces()) 2464145840Smlaier error = 1; 2465145840Smlaier 2466145840Smlaier if (rulesopt != NULL && !(opts & (PF_OPT_MERGE|PF_OPT_NOACTION)) && 2467145840Smlaier !anchorname[0] && (loadopt & PFCTL_FLAG_OPTION)) 2468126353Smlaier if (pfctl_file_fingerprints(dev, opts, PF_OSFP_FILE)) 2469126353Smlaier error = 1; 2470126353Smlaier 2471126353Smlaier if (rulesopt != NULL) { 2472171172Smlaier if (anchorname[0] == '_' || strstr(anchorname, "/_") != NULL) 2473171172Smlaier errx(1, "anchor names beginning with '_' cannot " 2474171172Smlaier "be modified from the command line"); 2475223637Sbz if (pfctl_rules(dev, rulesopt, opts, optimize, 2476171172Smlaier anchorname, NULL)) 2477126353Smlaier error = 1; 2478126353Smlaier else if (!(opts & PF_OPT_NOACTION) && 2479126353Smlaier (loadopt & PFCTL_FLAG_TABLE)) 2480126353Smlaier warn_namespace_collision(NULL); 2481126353Smlaier } 2482126353Smlaier 2483126353Smlaier if (opts & PF_OPT_ENABLE) 2484126353Smlaier if (pfctl_enable(dev, opts)) 2485126353Smlaier error = 1; 2486126353Smlaier 2487126353Smlaier if (debugopt != NULL) { 2488126353Smlaier switch (*debugopt) { 2489126353Smlaier case 'n': 2490126353Smlaier pfctl_debug(dev, PF_DEBUG_NONE, opts); 2491126353Smlaier break; 2492126353Smlaier case 'u': 2493126353Smlaier pfctl_debug(dev, PF_DEBUG_URGENT, opts); 2494126353Smlaier break; 2495126353Smlaier case 'm': 2496126353Smlaier pfctl_debug(dev, PF_DEBUG_MISC, opts); 2497126353Smlaier break; 2498126353Smlaier case 'l': 2499126353Smlaier pfctl_debug(dev, PF_DEBUG_NOISY, opts); 2500126353Smlaier break; 2501126353Smlaier } 2502126353Smlaier } 2503126353Smlaier 2504126353Smlaier exit(error); 2505126353Smlaier} 2506