Home | History | Annotate | Line # | Download | only in netinet
ip_frag.c revision 1.1
      1  1.1  christos /*	$NetBSD: ip_frag.c,v 1.1 2012/03/23 20:36:56 christos Exp $	*/
      2  1.1  christos 
      3  1.1  christos /*
      4  1.1  christos  * Copyright (C) 2012 by Darren Reed.
      5  1.1  christos  *
      6  1.1  christos  * See the IPFILTER.LICENCE file for details on licencing.
      7  1.1  christos  */
      8  1.1  christos #if defined(KERNEL) || defined(_KERNEL)
      9  1.1  christos # undef KERNEL
     10  1.1  christos # undef _KERNEL
     11  1.1  christos # define        KERNEL	1
     12  1.1  christos # define        _KERNEL	1
     13  1.1  christos #endif
     14  1.1  christos #include <sys/errno.h>
     15  1.1  christos #include <sys/types.h>
     16  1.1  christos #include <sys/param.h>
     17  1.1  christos #include <sys/time.h>
     18  1.1  christos #include <sys/file.h>
     19  1.1  christos #ifdef __hpux
     20  1.1  christos # include <sys/timeout.h>
     21  1.1  christos #endif
     22  1.1  christos #if !defined(_KERNEL)
     23  1.1  christos # include <stdio.h>
     24  1.1  christos # include <string.h>
     25  1.1  christos # include <stdlib.h>
     26  1.1  christos # define _KERNEL
     27  1.1  christos # ifdef __OpenBSD__
     28  1.1  christos struct file;
     29  1.1  christos # endif
     30  1.1  christos # include <sys/uio.h>
     31  1.1  christos # undef _KERNEL
     32  1.1  christos #endif
     33  1.1  christos #if defined(_KERNEL) && \
     34  1.1  christos     defined(__FreeBSD_version) && (__FreeBSD_version >= 220000)
     35  1.1  christos # include <sys/filio.h>
     36  1.1  christos # include <sys/fcntl.h>
     37  1.1  christos #else
     38  1.1  christos # include <sys/ioctl.h>
     39  1.1  christos #endif
     40  1.1  christos #if !defined(linux)
     41  1.1  christos # include <sys/protosw.h>
     42  1.1  christos #endif
     43  1.1  christos #include <sys/socket.h>
     44  1.1  christos #if defined(_KERNEL)
     45  1.1  christos # include <sys/systm.h>
     46  1.1  christos # if !defined(__SVR4) && !defined(__svr4__)
     47  1.1  christos #  include <sys/mbuf.h>
     48  1.1  christos # endif
     49  1.1  christos #endif
     50  1.1  christos #if !defined(__SVR4) && !defined(__svr4__)
     51  1.1  christos # if defined(_KERNEL) && !defined(__sgi) && !defined(AIX)
     52  1.1  christos #  include <sys/kernel.h>
     53  1.1  christos # endif
     54  1.1  christos #else
     55  1.1  christos # include <sys/byteorder.h>
     56  1.1  christos # ifdef _KERNEL
     57  1.1  christos #  include <sys/dditypes.h>
     58  1.1  christos # endif
     59  1.1  christos # include <sys/stream.h>
     60  1.1  christos # include <sys/kmem.h>
     61  1.1  christos #endif
     62  1.1  christos #include <net/if.h>
     63  1.1  christos #ifdef sun
     64  1.1  christos # include <net/af.h>
     65  1.1  christos #endif
     66  1.1  christos #include <netinet/in.h>
     67  1.1  christos #include <netinet/in_systm.h>
     68  1.1  christos #include <netinet/ip.h>
     69  1.1  christos #if !defined(linux)
     70  1.1  christos # include <netinet/ip_var.h>
     71  1.1  christos #endif
     72  1.1  christos #include <netinet/tcp.h>
     73  1.1  christos #include <netinet/udp.h>
     74  1.1  christos #include <netinet/ip_icmp.h>
     75  1.1  christos #include "netinet/ip_compat.h"
     76  1.1  christos #include <netinet/tcpip.h>
     77  1.1  christos #include "netinet/ip_fil.h"
     78  1.1  christos #include "netinet/ip_nat.h"
     79  1.1  christos #include "netinet/ip_frag.h"
     80  1.1  christos #include "netinet/ip_state.h"
     81  1.1  christos #include "netinet/ip_auth.h"
     82  1.1  christos #include "netinet/ip_lookup.h"
     83  1.1  christos #include "netinet/ip_proxy.h"
     84  1.1  christos #include "netinet/ip_sync.h"
     85  1.1  christos /* END OF INCLUDES */
     86  1.1  christos 
     87  1.1  christos #if !defined(lint)
     88  1.1  christos static const char sccsid[] = "@(#)ip_frag.c	1.11 3/24/96 (C) 1993-2000 Darren Reed";
     89  1.1  christos static const char rcsid[] = "@(#)Id";
     90  1.1  christos #endif
     91  1.1  christos 
     92  1.1  christos 
     93  1.1  christos typedef struct ipf_frag_softc_s  {
     94  1.1  christos 	ipfrwlock_t	ipfr_ipidfrag;
     95  1.1  christos 	ipfrwlock_t	ipfr_frag;
     96  1.1  christos 	ipfrwlock_t	ipfr_natfrag;
     97  1.1  christos 	int		ipfr_size;
     98  1.1  christos 	int		ipfr_ttl;
     99  1.1  christos 	int		ipfr_lock;
    100  1.1  christos 	int		ipfr_inited;
    101  1.1  christos 	ipfr_t		*ipfr_list;
    102  1.1  christos 	ipfr_t		**ipfr_tail;
    103  1.1  christos 	ipfr_t		*ipfr_natlist;
    104  1.1  christos 	ipfr_t		**ipfr_nattail;
    105  1.1  christos 	ipfr_t		*ipfr_ipidlist;
    106  1.1  christos 	ipfr_t		**ipfr_ipidtail;
    107  1.1  christos 	ipfr_t		**ipfr_heads;
    108  1.1  christos 	ipfr_t		**ipfr_nattab;
    109  1.1  christos 	ipfr_t		**ipfr_ipidtab;
    110  1.1  christos 	ipfrstat_t	ipfr_stats;
    111  1.1  christos } ipf_frag_softc_t;
    112  1.1  christos 
    113  1.1  christos 
    114  1.1  christos #ifdef USE_MUTEXES
    115  1.1  christos static ipfr_t *ipfr_frag_new __P((ipf_main_softc_t *, ipf_frag_softc_t *,
    116  1.1  christos 				  fr_info_t *, u_32_t, ipfr_t **,
    117  1.1  christos 				  ipfrwlock_t *));
    118  1.1  christos static ipfr_t *ipf_frag_lookup __P((ipf_main_softc_t *, ipf_frag_softc_t *, fr_info_t *, ipfr_t **, ipfrwlock_t *));
    119  1.1  christos static void ipf_frag_deref __P((void *, ipfr_t **, ipfrwlock_t *));
    120  1.1  christos static int ipf_frag_next __P((ipf_main_softc_t *, ipftoken_t *, ipfgeniter_t *,
    121  1.1  christos 			      ipfr_t **, ipfrwlock_t *));
    122  1.1  christos #else
    123  1.1  christos static ipfr_t *ipfr_frag_new __P((ipf_main_softc_t *, ipf_frag_softc_t *,
    124  1.1  christos 				  fr_info_t *, u_32_t, ipfr_t **));
    125  1.1  christos static ipfr_t *ipf_frag_lookup __P((ipf_main_softc_t *, ipf_frag_softc_t *, fr_info_t *, ipfr_t **));
    126  1.1  christos static void ipf_frag_deref __P((void *, ipfr_t **));
    127  1.1  christos static int ipf_frag_next __P((ipf_main_softc_t *, ipftoken_t *, ipfgeniter_t *,
    128  1.1  christos 			      ipfr_t **));
    129  1.1  christos #endif
    130  1.1  christos static void ipf_frag_delete __P((ipf_main_softc_t *, ipfr_t *, ipfr_t ***));
    131  1.1  christos static void ipf_frag_free __P((ipf_frag_softc_t *, ipfr_t *));
    132  1.1  christos 
    133  1.1  christos static frentry_t ipfr_block;
    134  1.1  christos 
    135  1.1  christos ipftuneable_t ipf_tuneables[] = {
    136  1.1  christos 	{ { (void *)offsetof(ipf_frag_softc_t, ipfr_size) },
    137  1.1  christos 		"frag_size",		1,	0x7fffffff,
    138  1.1  christos 		stsizeof(ipf_frag_softc_t, ipfr_size),
    139  1.1  christos 		IPFT_WRDISABLED,	NULL,	NULL },
    140  1.1  christos 	{ { (void *)offsetof(ipf_frag_softc_t, ipfr_ttl) },
    141  1.1  christos 		"frag_ttl",		1,	0x7fffffff,
    142  1.1  christos 		stsizeof(ipf_frag_softc_t, ipfr_ttl),
    143  1.1  christos 		0,			NULL,	NULL },
    144  1.1  christos 	{ { NULL },
    145  1.1  christos 		NULL,			0,	0,
    146  1.1  christos 		0,
    147  1.1  christos 		0,			NULL,	NULL }
    148  1.1  christos };
    149  1.1  christos 
    150  1.1  christos #define	FBUMP(x)	softf->ipfr_stats.x++
    151  1.1  christos #define	FBUMPD(x)	do { softf->ipfr_stats.x++; DT(x); } while (0)
    152  1.1  christos 
    153  1.1  christos 
    154  1.1  christos /* ------------------------------------------------------------------------ */
    155  1.1  christos /* Function:    ipf_frag_main_load                                          */
    156  1.1  christos /* Returns:     int - 0 == success, -1 == error                             */
    157  1.1  christos /* Parameters:  Nil                                                         */
    158  1.1  christos /*                                                                          */
    159  1.1  christos /* Initialise the filter rule associted with blocked packets - everyone can */
    160  1.1  christos /* use it.                                                                  */
    161  1.1  christos /* ------------------------------------------------------------------------ */
    162  1.1  christos int
    163  1.1  christos ipf_frag_main_load()
    164  1.1  christos {
    165  1.1  christos 	bzero((char *)&ipfr_block, sizeof(ipfr_block));
    166  1.1  christos 	ipfr_block.fr_flags = FR_BLOCK|FR_QUICK;
    167  1.1  christos 	ipfr_block.fr_ref = 1;
    168  1.1  christos 
    169  1.1  christos 	return 0;
    170  1.1  christos }
    171  1.1  christos 
    172  1.1  christos 
    173  1.1  christos /* ------------------------------------------------------------------------ */
    174  1.1  christos /* Function:    ipf_frag_main_unload                                        */
    175  1.1  christos /* Returns:     int - 0 == success, -1 == error                             */
    176  1.1  christos /* Parameters:  Nil                                                         */
    177  1.1  christos /*                                                                          */
    178  1.1  christos /* A null-op function that exists as a placeholder so that the flow in      */
    179  1.1  christos /* other functions is obvious.                                              */
    180  1.1  christos /* ------------------------------------------------------------------------ */
    181  1.1  christos int
    182  1.1  christos ipf_frag_main_unload()
    183  1.1  christos {
    184  1.1  christos 	return 0;
    185  1.1  christos }
    186  1.1  christos 
    187  1.1  christos 
    188  1.1  christos /* ------------------------------------------------------------------------ */
    189  1.1  christos /* Function:    ipf_frag_soft_create                                        */
    190  1.1  christos /* Returns:     void *   - NULL = failure, else pointer to local context    */
    191  1.1  christos /* Parameters:  softc(I) - pointer to soft context main structure           */
    192  1.1  christos /*                                                                          */
    193  1.1  christos /* Allocate a new soft context structure to track fragment related info.    */
    194  1.1  christos /* ------------------------------------------------------------------------ */
    195  1.1  christos /*ARGSUSED*/
    196  1.1  christos void *
    197  1.1  christos ipf_frag_soft_create(softc)
    198  1.1  christos 	ipf_main_softc_t *softc;
    199  1.1  christos {
    200  1.1  christos 	ipf_frag_softc_t *softf;
    201  1.1  christos 
    202  1.1  christos 	KMALLOC(softf, ipf_frag_softc_t *);
    203  1.1  christos 	if (softf == NULL)
    204  1.1  christos 		return NULL;
    205  1.1  christos 
    206  1.1  christos 	bzero((char *)softf, sizeof(*softf));
    207  1.1  christos 
    208  1.1  christos 	RWLOCK_INIT(&softf->ipfr_ipidfrag, "frag ipid lock");
    209  1.1  christos 	RWLOCK_INIT(&softf->ipfr_frag, "ipf fragment rwlock");
    210  1.1  christos 	RWLOCK_INIT(&softf->ipfr_natfrag, "ipf NAT fragment rwlock");
    211  1.1  christos 
    212  1.1  christos 	softf->ipfr_size = IPFT_SIZE;
    213  1.1  christos 	softf->ipfr_ttl = IPF_TTLVAL(60);
    214  1.1  christos 	softf->ipfr_lock = 1;
    215  1.1  christos 	softf->ipfr_tail = &softf->ipfr_list;
    216  1.1  christos 	softf->ipfr_nattail = &softf->ipfr_natlist;
    217  1.1  christos 	softf->ipfr_ipidtail = &softf->ipfr_ipidlist;
    218  1.1  christos 
    219  1.1  christos 	return softf;
    220  1.1  christos }
    221  1.1  christos 
    222  1.1  christos 
    223  1.1  christos /* ------------------------------------------------------------------------ */
    224  1.1  christos /* Function:    ipf_frag_soft_destroy                                       */
    225  1.1  christos /* Returns:     Nil                                                         */
    226  1.1  christos /* Parameters:  softc(I) - pointer to soft context main structure           */
    227  1.1  christos /*              arg(I)   - pointer to local context to use                  */
    228  1.1  christos /*                                                                          */
    229  1.1  christos /* Initialise the hash tables for the fragment cache lookups.               */
    230  1.1  christos /* ------------------------------------------------------------------------ */
    231  1.1  christos void
    232  1.1  christos ipf_frag_soft_destroy(softc, arg)
    233  1.1  christos 	ipf_main_softc_t *softc;
    234  1.1  christos 	void *arg;
    235  1.1  christos {
    236  1.1  christos 	ipf_frag_softc_t *softf = arg;
    237  1.1  christos 
    238  1.1  christos 	RW_DESTROY(&softf->ipfr_ipidfrag);
    239  1.1  christos 	RW_DESTROY(&softf->ipfr_frag);
    240  1.1  christos 	RW_DESTROY(&softf->ipfr_natfrag);
    241  1.1  christos 
    242  1.1  christos 	KFREE(softf);
    243  1.1  christos }
    244  1.1  christos 
    245  1.1  christos 
    246  1.1  christos /* ------------------------------------------------------------------------ */
    247  1.1  christos /* Function:    ipf_frag_soft_init                                          */
    248  1.1  christos /* Returns:     int      - 0 == success, -1 == error                        */
    249  1.1  christos /* Parameters:  softc(I) - pointer to soft context main structure           */
    250  1.1  christos /*              arg(I)   - pointer to local context to use                  */
    251  1.1  christos /*                                                                          */
    252  1.1  christos /* Initialise the hash tables for the fragment cache lookups.               */
    253  1.1  christos /* ------------------------------------------------------------------------ */
    254  1.1  christos /*ARGSUSED*/
    255  1.1  christos int
    256  1.1  christos ipf_frag_soft_init(softc, arg)
    257  1.1  christos 	ipf_main_softc_t *softc;
    258  1.1  christos 	void *arg;
    259  1.1  christos {
    260  1.1  christos 	ipf_frag_softc_t *softf = arg;
    261  1.1  christos 
    262  1.1  christos 	KMALLOCS(softf->ipfr_heads, ipfr_t **,
    263  1.1  christos 		 softf->ipfr_size * sizeof(ipfr_t *));
    264  1.1  christos 	if (softf->ipfr_heads == NULL)
    265  1.1  christos 		return -1;
    266  1.1  christos 
    267  1.1  christos 	bzero((char *)softf->ipfr_heads, softf->ipfr_size * sizeof(ipfr_t *));
    268  1.1  christos 
    269  1.1  christos 	KMALLOCS(softf->ipfr_nattab, ipfr_t **,
    270  1.1  christos 		 softf->ipfr_size * sizeof(ipfr_t *));
    271  1.1  christos 	if (softf->ipfr_nattab == NULL)
    272  1.1  christos 		return -2;
    273  1.1  christos 
    274  1.1  christos 	bzero((char *)softf->ipfr_nattab, softf->ipfr_size * sizeof(ipfr_t *));
    275  1.1  christos 
    276  1.1  christos 	KMALLOCS(softf->ipfr_ipidtab, ipfr_t **,
    277  1.1  christos 		 softf->ipfr_size * sizeof(ipfr_t *));
    278  1.1  christos 	if (softf->ipfr_ipidtab == NULL)
    279  1.1  christos 		return -3;
    280  1.1  christos 
    281  1.1  christos 	bzero((char *)softf->ipfr_ipidtab,
    282  1.1  christos 	      softf->ipfr_size * sizeof(ipfr_t *));
    283  1.1  christos 
    284  1.1  christos 	softf->ipfr_lock = 0;
    285  1.1  christos 	softf->ipfr_inited = 1;
    286  1.1  christos 
    287  1.1  christos 	return 0;
    288  1.1  christos }
    289  1.1  christos 
    290  1.1  christos 
    291  1.1  christos /* ------------------------------------------------------------------------ */
    292  1.1  christos /* Function:    ipf_frag_soft_fini                                          */
    293  1.1  christos /* Returns:     int      - 0 == success, -1 == error                        */
    294  1.1  christos /* Parameters:  softc(I) - pointer to soft context main structure           */
    295  1.1  christos /*              arg(I)   - pointer to local context to use                  */
    296  1.1  christos /*                                                                          */
    297  1.1  christos /* Free all memory allocated whilst running and from initialisation.        */
    298  1.1  christos /* ------------------------------------------------------------------------ */
    299  1.1  christos int
    300  1.1  christos ipf_frag_soft_fini(softc, arg)
    301  1.1  christos 	ipf_main_softc_t *softc;
    302  1.1  christos 	void *arg;
    303  1.1  christos {
    304  1.1  christos 	ipf_frag_softc_t *softf = arg;
    305  1.1  christos 
    306  1.1  christos 	softf->ipfr_lock = 1;
    307  1.1  christos 
    308  1.1  christos 	if (softf->ipfr_inited == 1) {
    309  1.1  christos 		ipf_frag_clear(softc);
    310  1.1  christos 
    311  1.1  christos 		softf->ipfr_inited = 0;
    312  1.1  christos 	}
    313  1.1  christos 
    314  1.1  christos 	if (softf->ipfr_heads != NULL)
    315  1.1  christos 		KFREES(softf->ipfr_heads,
    316  1.1  christos 		       softf->ipfr_size * sizeof(ipfr_t *));
    317  1.1  christos 	softf->ipfr_heads = NULL;
    318  1.1  christos 
    319  1.1  christos 	if (softf->ipfr_nattab != NULL)
    320  1.1  christos 		KFREES(softf->ipfr_nattab,
    321  1.1  christos 		       softf->ipfr_size * sizeof(ipfr_t *));
    322  1.1  christos 	softf->ipfr_nattab = NULL;
    323  1.1  christos 
    324  1.1  christos 	if (softf->ipfr_ipidtab != NULL)
    325  1.1  christos 		KFREES(softf->ipfr_ipidtab,
    326  1.1  christos 		       softf->ipfr_size * sizeof(ipfr_t *));
    327  1.1  christos 	softf->ipfr_ipidtab = NULL;
    328  1.1  christos 
    329  1.1  christos 	return 0;
    330  1.1  christos }
    331  1.1  christos 
    332  1.1  christos 
    333  1.1  christos /* ------------------------------------------------------------------------ */
    334  1.1  christos /* Function:    ipf_frag_set_lock                                           */
    335  1.1  christos /* Returns:     Nil                                                         */
    336  1.1  christos /* Parameters:  arg(I) - pointer to local context to use                    */
    337  1.1  christos /*              tmp(I) - new value for lock                                 */
    338  1.1  christos /*                                                                          */
    339  1.1  christos /* Stub function that allows for external manipulation of ipfr_lock         */
    340  1.1  christos /* ------------------------------------------------------------------------ */
    341  1.1  christos void
    342  1.1  christos ipf_frag_setlock(arg, tmp)
    343  1.1  christos 	void *arg;
    344  1.1  christos 	int tmp;
    345  1.1  christos {
    346  1.1  christos 	ipf_frag_softc_t *softf = arg;
    347  1.1  christos 
    348  1.1  christos 	softf->ipfr_lock = tmp;
    349  1.1  christos }
    350  1.1  christos 
    351  1.1  christos 
    352  1.1  christos /* ------------------------------------------------------------------------ */
    353  1.1  christos /* Function:    ipf_frag_stats                                              */
    354  1.1  christos /* Returns:     ipfrstat_t* - pointer to struct with current frag stats     */
    355  1.1  christos /* Parameters:  arg(I) - pointer to local context to use                    */
    356  1.1  christos /*                                                                          */
    357  1.1  christos /* Updates ipfr_stats with current information and returns a pointer to it  */
    358  1.1  christos /* ------------------------------------------------------------------------ */
    359  1.1  christos ipfrstat_t *
    360  1.1  christos ipf_frag_stats(arg)
    361  1.1  christos 	void *arg;
    362  1.1  christos {
    363  1.1  christos 	ipf_frag_softc_t *softf = arg;
    364  1.1  christos 
    365  1.1  christos 	softf->ipfr_stats.ifs_table = softf->ipfr_heads;
    366  1.1  christos 	softf->ipfr_stats.ifs_nattab = softf->ipfr_nattab;
    367  1.1  christos 	return &softf->ipfr_stats;
    368  1.1  christos }
    369  1.1  christos 
    370  1.1  christos 
    371  1.1  christos /* ------------------------------------------------------------------------ */
    372  1.1  christos /* Function:    ipfr_frag_new                                               */
    373  1.1  christos /* Returns:     ipfr_t * - pointer to fragment cache state info or NULL     */
    374  1.1  christos /* Parameters:  fin(I)   - pointer to packet information                    */
    375  1.1  christos /*              table(I) - pointer to frag table to add to                  */
    376  1.1  christos /*              lock(I)  - pointer to lock to get a write hold of           */
    377  1.1  christos /*                                                                          */
    378  1.1  christos /* Add a new entry to the fragment cache, registering it as having come     */
    379  1.1  christos /* through this box, with the result of the filter operation.               */
    380  1.1  christos /*                                                                          */
    381  1.1  christos /* If this function succeeds, it returns with a write lock held on "lock".  */
    382  1.1  christos /* If it fails, no lock is held on return.                                  */
    383  1.1  christos /* ------------------------------------------------------------------------ */
    384  1.1  christos static ipfr_t *
    385  1.1  christos ipfr_frag_new(softc, softf, fin, pass, table
    386  1.1  christos #ifdef USE_MUTEXES
    387  1.1  christos , lock
    388  1.1  christos #endif
    389  1.1  christos )
    390  1.1  christos 	ipf_main_softc_t *softc;
    391  1.1  christos 	ipf_frag_softc_t *softf;
    392  1.1  christos 	fr_info_t *fin;
    393  1.1  christos 	u_32_t pass;
    394  1.1  christos 	ipfr_t *table[];
    395  1.1  christos #ifdef USE_MUTEXES
    396  1.1  christos 	ipfrwlock_t *lock;
    397  1.1  christos #endif
    398  1.1  christos {
    399  1.1  christos 	ipfr_t *fra, frag, *fran;
    400  1.1  christos 	u_int idx, off;
    401  1.1  christos 	frentry_t *fr;
    402  1.1  christos 
    403  1.1  christos 	if (softf->ipfr_stats.ifs_inuse >= softf->ipfr_size) {
    404  1.1  christos 		FBUMPD(ifs_maximum);
    405  1.1  christos 		return NULL;
    406  1.1  christos 	}
    407  1.1  christos 
    408  1.1  christos 	if ((fin->fin_flx & (FI_FRAG|FI_BAD)) != FI_FRAG) {
    409  1.1  christos 		FBUMPD(ifs_newbad);
    410  1.1  christos 		return NULL;
    411  1.1  christos 	}
    412  1.1  christos 
    413  1.1  christos 	if (pass & FR_FRSTRICT) {
    414  1.1  christos 		if (fin->fin_off != 0) {
    415  1.1  christos 			FBUMPD(ifs_newrestrictnot0);
    416  1.1  christos 			return NULL;
    417  1.1  christos 		}
    418  1.1  christos 	}
    419  1.1  christos 
    420  1.1  christos 	frag.ipfr_v = fin->fin_v;
    421  1.1  christos 	idx = fin->fin_v;
    422  1.1  christos 	frag.ipfr_p = fin->fin_p;
    423  1.1  christos 	idx += fin->fin_p;
    424  1.1  christos 	frag.ipfr_id = fin->fin_id;
    425  1.1  christos 	idx += fin->fin_id;
    426  1.1  christos 	frag.ipfr_source = fin->fin_fi.fi_src;
    427  1.1  christos 	idx += frag.ipfr_src.s_addr;
    428  1.1  christos 	frag.ipfr_dest = fin->fin_fi.fi_dst;
    429  1.1  christos 	idx += frag.ipfr_dst.s_addr;
    430  1.1  christos 	frag.ipfr_ifp = fin->fin_ifp;
    431  1.1  christos 	idx *= 127;
    432  1.1  christos 	idx %= softf->ipfr_size;
    433  1.1  christos 
    434  1.1  christos 	frag.ipfr_optmsk = fin->fin_fi.fi_optmsk & IPF_OPTCOPY;
    435  1.1  christos 	frag.ipfr_secmsk = fin->fin_fi.fi_secmsk;
    436  1.1  christos 	frag.ipfr_auth = fin->fin_fi.fi_auth;
    437  1.1  christos 
    438  1.1  christos 	off = fin->fin_off >> 3;
    439  1.1  christos #ifdef USE_INET6
    440  1.1  christos 	if ((off == 0) && (fin->fin_v == 6)) {
    441  1.1  christos 		char *ptr;
    442  1.1  christos 		int end;
    443  1.1  christos 
    444  1.1  christos 		ptr = (char *)fin->fin_fraghdr + sizeof(struct ip6_frag);
    445  1.1  christos 		end = fin->fin_plen - (ptr - (char *)fin->fin_ip);
    446  1.1  christos 		frag.ipfr_firstend = end >> 3;
    447  1.1  christos 	} else
    448  1.1  christos #endif
    449  1.1  christos 		frag.ipfr_firstend = 0;
    450  1.1  christos 
    451  1.1  christos 	/*
    452  1.1  christos 	 * allocate some memory, if possible, if not, just record that we
    453  1.1  christos 	 * failed to do so.
    454  1.1  christos 	 */
    455  1.1  christos 	KMALLOC(fran, ipfr_t *);
    456  1.1  christos 	if (fran == NULL) {
    457  1.1  christos 		FBUMPD(ifs_nomem);
    458  1.1  christos 		return NULL;
    459  1.1  christos 	}
    460  1.1  christos 
    461  1.1  christos 	WRITE_ENTER(lock);
    462  1.1  christos 
    463  1.1  christos 	/*
    464  1.1  christos 	 * first, make sure it isn't already there...
    465  1.1  christos 	 */
    466  1.1  christos 	for (fra = table[idx]; (fra != NULL); fra = fra->ipfr_hnext)
    467  1.1  christos 		if (!bcmp((char *)&frag.ipfr_ifp, (char *)&fra->ipfr_ifp,
    468  1.1  christos 			  IPFR_CMPSZ)) {
    469  1.1  christos 			RWLOCK_EXIT(lock);
    470  1.1  christos 			FBUMPD(ifs_exists);
    471  1.1  christos 			KFREE(fra);
    472  1.1  christos 			return NULL;
    473  1.1  christos 		}
    474  1.1  christos 
    475  1.1  christos 	fra = fran;
    476  1.1  christos 	fran = NULL;
    477  1.1  christos 	fr = fin->fin_fr;
    478  1.1  christos 	fra->ipfr_rule = fr;
    479  1.1  christos 	if (fr != NULL) {
    480  1.1  christos 		MUTEX_ENTER(&fr->fr_lock);
    481  1.1  christos 		fr->fr_ref++;
    482  1.1  christos 		MUTEX_EXIT(&fr->fr_lock);
    483  1.1  christos 	}
    484  1.1  christos 
    485  1.1  christos 	/*
    486  1.1  christos 	 * Insert the fragment into the fragment table, copy the struct used
    487  1.1  christos 	 * in the search using bcopy rather than reassign each field.
    488  1.1  christos 	 * Set the ttl to the default.
    489  1.1  christos 	 */
    490  1.1  christos 	if ((fra->ipfr_hnext = table[idx]) != NULL)
    491  1.1  christos 		table[idx]->ipfr_hprev = &fra->ipfr_hnext;
    492  1.1  christos 	fra->ipfr_hprev = table + idx;
    493  1.1  christos 	fra->ipfr_data = NULL;
    494  1.1  christos 	table[idx] = fra;
    495  1.1  christos 	bcopy((char *)&frag.ipfr_ifp, (char *)&fra->ipfr_ifp, IPFR_CMPSZ);
    496  1.1  christos 	fra->ipfr_v = fin->fin_v;
    497  1.1  christos 	fra->ipfr_ttl = softc->ipf_ticks + softf->ipfr_ttl;
    498  1.1  christos 	fra->ipfr_firstend = frag.ipfr_firstend;
    499  1.1  christos 
    500  1.1  christos 	/*
    501  1.1  christos 	 * Compute the offset of the expected start of the next packet.
    502  1.1  christos 	 */
    503  1.1  christos 	if (off == 0)
    504  1.1  christos 		fra->ipfr_seen0 = 1;
    505  1.1  christos 	fra->ipfr_off = off + (fin->fin_dlen >> 3);
    506  1.1  christos 	fra->ipfr_pass = pass;
    507  1.1  christos 	fra->ipfr_ref = 1;
    508  1.1  christos 	fra->ipfr_pkts = 1;
    509  1.1  christos 	fra->ipfr_bytes = fin->fin_plen;
    510  1.1  christos 	FBUMP(ifs_inuse);
    511  1.1  christos 	FBUMP(ifs_new);
    512  1.1  christos 	return fra;
    513  1.1  christos }
    514  1.1  christos 
    515  1.1  christos 
    516  1.1  christos /* ------------------------------------------------------------------------ */
    517  1.1  christos /* Function:    ipf_frag_new                                                */
    518  1.1  christos /* Returns:     int - 0 == success, -1 == error                             */
    519  1.1  christos /* Parameters:  fin(I)  - pointer to packet information                     */
    520  1.1  christos /*                                                                          */
    521  1.1  christos /* Add a new entry to the fragment cache table based on the current packet  */
    522  1.1  christos /* ------------------------------------------------------------------------ */
    523  1.1  christos int
    524  1.1  christos ipf_frag_new(softc, fin, pass)
    525  1.1  christos 	ipf_main_softc_t *softc;
    526  1.1  christos 	u_32_t pass;
    527  1.1  christos 	fr_info_t *fin;
    528  1.1  christos {
    529  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    530  1.1  christos 	ipfr_t	*fra;
    531  1.1  christos 
    532  1.1  christos 	if (softf->ipfr_lock != 0)
    533  1.1  christos 		return -1;
    534  1.1  christos 
    535  1.1  christos #ifdef USE_MUTEXES
    536  1.1  christos 	fra = ipfr_frag_new(softc, softf, fin, pass, softf->ipfr_heads, &softc->ipf_frag);
    537  1.1  christos #else
    538  1.1  christos 	fra = ipfr_frag_new(softc, softf, fin, pass, softf->ipfr_heads);
    539  1.1  christos #endif
    540  1.1  christos 	if (fra != NULL) {
    541  1.1  christos 		*softf->ipfr_tail = fra;
    542  1.1  christos 		fra->ipfr_prev = softf->ipfr_tail;
    543  1.1  christos 		softf->ipfr_tail = &fra->ipfr_next;
    544  1.1  christos 		fra->ipfr_next = NULL;
    545  1.1  christos 		RWLOCK_EXIT(&softc->ipf_frag);
    546  1.1  christos 	}
    547  1.1  christos 	return fra ? 0 : -1;
    548  1.1  christos }
    549  1.1  christos 
    550  1.1  christos 
    551  1.1  christos /* ------------------------------------------------------------------------ */
    552  1.1  christos /* Function:    ipf_frag_natnew                                             */
    553  1.1  christos /* Returns:     int - 0 == success, -1 == error                             */
    554  1.1  christos /* Parameters:  fin(I)  - pointer to packet information                     */
    555  1.1  christos /*              nat(I)  - pointer to NAT structure                          */
    556  1.1  christos /*                                                                          */
    557  1.1  christos /* Create a new NAT fragment cache entry based on the current packet and    */
    558  1.1  christos /* the NAT structure for this "session".                                    */
    559  1.1  christos /* ------------------------------------------------------------------------ */
    560  1.1  christos int
    561  1.1  christos ipf_frag_natnew(softc, fin, pass, nat)
    562  1.1  christos 	ipf_main_softc_t *softc;
    563  1.1  christos 	fr_info_t *fin;
    564  1.1  christos 	u_32_t pass;
    565  1.1  christos 	nat_t *nat;
    566  1.1  christos {
    567  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    568  1.1  christos 	ipfr_t	*fra;
    569  1.1  christos 
    570  1.1  christos 	if ((fin->fin_v != 4) || (softf->ipfr_lock != 0))
    571  1.1  christos 		return 0;
    572  1.1  christos 
    573  1.1  christos #ifdef USE_MUTEXES
    574  1.1  christos 	fra = ipfr_frag_new(softc, softf, fin, pass, softf->ipfr_nattab,
    575  1.1  christos 			    &softf->ipfr_natfrag);
    576  1.1  christos #else
    577  1.1  christos 	fra = ipfr_frag_new(softc, softf, fin, pass, softf->ipfr_nattab);
    578  1.1  christos #endif
    579  1.1  christos 	if (fra != NULL) {
    580  1.1  christos 		fra->ipfr_data = nat;
    581  1.1  christos 		nat->nat_data = fra;
    582  1.1  christos 		*softf->ipfr_nattail = fra;
    583  1.1  christos 		fra->ipfr_prev = softf->ipfr_nattail;
    584  1.1  christos 		softf->ipfr_nattail = &fra->ipfr_next;
    585  1.1  christos 		fra->ipfr_next = NULL;
    586  1.1  christos 		RWLOCK_EXIT(&softf->ipfr_natfrag);
    587  1.1  christos 	}
    588  1.1  christos 	return fra ? 0 : -1;
    589  1.1  christos }
    590  1.1  christos 
    591  1.1  christos 
    592  1.1  christos /* ------------------------------------------------------------------------ */
    593  1.1  christos /* Function:    ipf_frag_ipidnew                                            */
    594  1.1  christos /* Returns:     int - 0 == success, -1 == error                             */
    595  1.1  christos /* Parameters:  fin(I)  - pointer to packet information                     */
    596  1.1  christos /*              ipid(I) - new IP ID for this fragmented packet              */
    597  1.1  christos /*                                                                          */
    598  1.1  christos /* Create a new fragment cache entry for this packet and store, as a data   */
    599  1.1  christos /* pointer, the new IP ID value.                                            */
    600  1.1  christos /* ------------------------------------------------------------------------ */
    601  1.1  christos int
    602  1.1  christos ipf_frag_ipidnew(fin, ipid)
    603  1.1  christos 	fr_info_t *fin;
    604  1.1  christos 	u_32_t ipid;
    605  1.1  christos {
    606  1.1  christos 	ipf_main_softc_t *softc = fin->fin_main_soft;
    607  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    608  1.1  christos 	ipfr_t	*fra;
    609  1.1  christos 
    610  1.1  christos 	if (softf->ipfr_lock)
    611  1.1  christos 		return 0;
    612  1.1  christos 
    613  1.1  christos #ifdef USE_MUTEXES
    614  1.1  christos 	fra = ipfr_frag_new(softc, softf, fin, 0, softf->ipfr_ipidtab, &softf->ipfr_ipidfrag);
    615  1.1  christos #else
    616  1.1  christos 	fra = ipfr_frag_new(softc, softf, fin, 0, softf->ipfr_ipidtab);
    617  1.1  christos #endif
    618  1.1  christos 	if (fra != NULL) {
    619  1.1  christos 		fra->ipfr_data = (void *)(intptr_t)ipid;
    620  1.1  christos 		*softf->ipfr_ipidtail = fra;
    621  1.1  christos 		fra->ipfr_prev = softf->ipfr_ipidtail;
    622  1.1  christos 		softf->ipfr_ipidtail = &fra->ipfr_next;
    623  1.1  christos 		fra->ipfr_next = NULL;
    624  1.1  christos 		RWLOCK_EXIT(&softf->ipfr_ipidfrag);
    625  1.1  christos 	}
    626  1.1  christos 	return fra ? 0 : -1;
    627  1.1  christos }
    628  1.1  christos 
    629  1.1  christos 
    630  1.1  christos /* ------------------------------------------------------------------------ */
    631  1.1  christos /* Function:    ipf_frag_lookup                                             */
    632  1.1  christos /* Returns:     ipfr_t * - pointer to ipfr_t structure if there's a         */
    633  1.1  christos /*                         matching entry in the frag table, else NULL      */
    634  1.1  christos /* Parameters:  fin(I)   - pointer to packet information                    */
    635  1.1  christos /*              table(I) - pointer to fragment cache table to search        */
    636  1.1  christos /*                                                                          */
    637  1.1  christos /* Check the fragment cache to see if there is already a record of this     */
    638  1.1  christos /* packet with its filter result known.                                     */
    639  1.1  christos /*                                                                          */
    640  1.1  christos /* If this function succeeds, it returns with a write lock held on "lock".  */
    641  1.1  christos /* If it fails, no lock is held on return.                                  */
    642  1.1  christos /* ------------------------------------------------------------------------ */
    643  1.1  christos static ipfr_t *
    644  1.1  christos ipf_frag_lookup(softc, softf, fin, table
    645  1.1  christos #ifdef USE_MUTEXES
    646  1.1  christos , lock
    647  1.1  christos #endif
    648  1.1  christos )
    649  1.1  christos 	ipf_main_softc_t *softc;
    650  1.1  christos 	ipf_frag_softc_t *softf;
    651  1.1  christos 	fr_info_t *fin;
    652  1.1  christos 	ipfr_t *table[];
    653  1.1  christos #ifdef USE_MUTEXES
    654  1.1  christos 	ipfrwlock_t *lock;
    655  1.1  christos #endif
    656  1.1  christos {
    657  1.1  christos 	ipfr_t *f, frag;
    658  1.1  christos 	u_int idx;
    659  1.1  christos 
    660  1.1  christos 	/*
    661  1.1  christos 	 * We don't want to let short packets match because they could be
    662  1.1  christos 	 * compromising the security of other rules that want to match on
    663  1.1  christos 	 * layer 4 fields (and can't because they have been fragmented off.)
    664  1.1  christos 	 * Why do this check here?  The counter acts as an indicator of this
    665  1.1  christos 	 * kind of attack, whereas if it was elsewhere, it wouldn't know if
    666  1.1  christos 	 * other matching packets had been seen.
    667  1.1  christos 	 */
    668  1.1  christos 	if (fin->fin_flx & FI_SHORT) {
    669  1.1  christos 		FBUMPD(ifs_short);
    670  1.1  christos 		return NULL;
    671  1.1  christos 	}
    672  1.1  christos 
    673  1.1  christos 	if ((fin->fin_flx & FI_BAD) != 0) {
    674  1.1  christos 		FBUMPD(ifs_bad);
    675  1.1  christos 		return NULL;
    676  1.1  christos 	}
    677  1.1  christos 
    678  1.1  christos 	/*
    679  1.1  christos 	 * For fragments, we record protocol, packet id, TOS and both IP#'s
    680  1.1  christos 	 * (these should all be the same for all fragments of a packet).
    681  1.1  christos 	 *
    682  1.1  christos 	 * build up a hash value to index the table with.
    683  1.1  christos 	 */
    684  1.1  christos 	frag.ipfr_v = fin->fin_v;
    685  1.1  christos 	idx = fin->fin_v;
    686  1.1  christos 	frag.ipfr_p = fin->fin_p;
    687  1.1  christos 	idx += fin->fin_p;
    688  1.1  christos 	frag.ipfr_id = fin->fin_id;
    689  1.1  christos 	idx += fin->fin_id;
    690  1.1  christos 	frag.ipfr_source = fin->fin_fi.fi_src;
    691  1.1  christos 	idx += frag.ipfr_src.s_addr;
    692  1.1  christos 	frag.ipfr_dest = fin->fin_fi.fi_dst;
    693  1.1  christos 	idx += frag.ipfr_dst.s_addr;
    694  1.1  christos 	frag.ipfr_ifp = fin->fin_ifp;
    695  1.1  christos 	idx *= 127;
    696  1.1  christos 	idx %= softf->ipfr_size;
    697  1.1  christos 
    698  1.1  christos 	frag.ipfr_optmsk = fin->fin_fi.fi_optmsk & IPF_OPTCOPY;
    699  1.1  christos 	frag.ipfr_secmsk = fin->fin_fi.fi_secmsk;
    700  1.1  christos 	frag.ipfr_auth = fin->fin_fi.fi_auth;
    701  1.1  christos 
    702  1.1  christos 	READ_ENTER(lock);
    703  1.1  christos 
    704  1.1  christos 	/*
    705  1.1  christos 	 * check the table, careful to only compare the right amount of data
    706  1.1  christos 	 */
    707  1.1  christos 	for (f = table[idx]; f; f = f->ipfr_hnext) {
    708  1.1  christos 		if (!bcmp((char *)&frag.ipfr_ifp, (char *)&f->ipfr_ifp,
    709  1.1  christos 			  IPFR_CMPSZ)) {
    710  1.1  christos 			u_short	off;
    711  1.1  christos 
    712  1.1  christos 			/*
    713  1.1  christos 			 * XXX - We really need to be guarding against the
    714  1.1  christos 			 * retransmission of (src,dst,id,offset-range) here
    715  1.1  christos 			 * because a fragmented packet is never resent with
    716  1.1  christos 			 * the same IP ID# (or shouldn't).
    717  1.1  christos 			 */
    718  1.1  christos 			off = fin->fin_off >> 3;
    719  1.1  christos 			if (f->ipfr_seen0) {
    720  1.1  christos 				if (off == 0) {
    721  1.1  christos 					FBUMPD(ifs_retrans0);
    722  1.1  christos 					continue;
    723  1.1  christos 				}
    724  1.1  christos 
    725  1.1  christos 				/*
    726  1.1  christos 				 * Case 3. See comment for frpr_fragment6.
    727  1.1  christos 				 */
    728  1.1  christos 				if ((f->ipfr_firstend != 0) &&
    729  1.1  christos 				    (off < f->ipfr_firstend)) {
    730  1.1  christos 					FBUMPD(ifs_overlap);
    731  1.1  christos 					fin->fin_flx |= FI_BAD;
    732  1.1  christos 					break;
    733  1.1  christos 				}
    734  1.1  christos 			} else if (off == 0)
    735  1.1  christos 				f->ipfr_seen0 = 1;
    736  1.1  christos 
    737  1.1  christos 			if (f != table[idx]) {
    738  1.1  christos 				ipfr_t **fp;
    739  1.1  christos 
    740  1.1  christos 				/*
    741  1.1  christos 				 * Move fragment info. to the top of the list
    742  1.1  christos 				 * to speed up searches.  First, delink...
    743  1.1  christos 				 */
    744  1.1  christos 				fp = f->ipfr_hprev;
    745  1.1  christos 				(*fp) = f->ipfr_hnext;
    746  1.1  christos 				if (f->ipfr_hnext != NULL)
    747  1.1  christos 					f->ipfr_hnext->ipfr_hprev = fp;
    748  1.1  christos 				/*
    749  1.1  christos 				 * Then put back at the top of the chain.
    750  1.1  christos 				 */
    751  1.1  christos 				f->ipfr_hnext = table[idx];
    752  1.1  christos 				table[idx]->ipfr_hprev = &f->ipfr_hnext;
    753  1.1  christos 				f->ipfr_hprev = table + idx;
    754  1.1  christos 				table[idx] = f;
    755  1.1  christos 			}
    756  1.1  christos 
    757  1.1  christos 			/*
    758  1.1  christos 			 * If we've follwed the fragments, and this is the
    759  1.1  christos 			 * last (in order), shrink expiration time.
    760  1.1  christos 			 */
    761  1.1  christos 			if (off == f->ipfr_off) {
    762  1.1  christos 				f->ipfr_off = (fin->fin_dlen >> 3) + off;
    763  1.1  christos 
    764  1.1  christos 				/*
    765  1.1  christos 				 * Well, we could shrink the expiration time
    766  1.1  christos 				 * but only if every fragment has been seen
    767  1.1  christos 				 * in order upto this, the last. ipfr_badorder
    768  1.1  christos 				 * is used here to count those out of order
    769  1.1  christos 				 * and if it equals 0 when we get to the last
    770  1.1  christos 				 * fragment then we can assume all of the
    771  1.1  christos 				 * fragments have been seen and in order.
    772  1.1  christos 				 */
    773  1.1  christos #if 0
    774  1.1  christos 				/*
    775  1.1  christos 				 * Doing this properly requires moving it to
    776  1.1  christos 				 * the head of the list which is infesible.
    777  1.1  christos 				 */
    778  1.1  christos 				if ((more == 0) && (f->ipfr_badorder == 0))
    779  1.1  christos 					f->ipfr_ttl = softc->ipf_ticks + 1;
    780  1.1  christos #endif
    781  1.1  christos 			} else {
    782  1.1  christos 				f->ipfr_badorder++;
    783  1.1  christos 				FBUMPD(ifs_unordered);
    784  1.1  christos 				if (f->ipfr_pass & FR_FRSTRICT) {
    785  1.1  christos 					FBUMPD(ifs_strict);
    786  1.1  christos 					continue;
    787  1.1  christos 				}
    788  1.1  christos 			}
    789  1.1  christos 			f->ipfr_pkts++;
    790  1.1  christos 			f->ipfr_bytes += fin->fin_plen;
    791  1.1  christos 			FBUMP(ifs_hits);
    792  1.1  christos 			return f;
    793  1.1  christos 		}
    794  1.1  christos 	}
    795  1.1  christos 
    796  1.1  christos 	RWLOCK_EXIT(lock);
    797  1.1  christos 	FBUMP(ifs_miss);
    798  1.1  christos 	return NULL;
    799  1.1  christos }
    800  1.1  christos 
    801  1.1  christos 
    802  1.1  christos /* ------------------------------------------------------------------------ */
    803  1.1  christos /* Function:    ipf_frag_natknown                                           */
    804  1.1  christos /* Returns:     nat_t* - pointer to 'parent' NAT structure if frag table    */
    805  1.1  christos /*                       match found, else NULL                             */
    806  1.1  christos /* Parameters:  fin(I)  - pointer to packet information                     */
    807  1.1  christos /*                                                                          */
    808  1.1  christos /* Functional interface for NAT lookups of the NAT fragment cache           */
    809  1.1  christos /* ------------------------------------------------------------------------ */
    810  1.1  christos nat_t *
    811  1.1  christos ipf_frag_natknown(fin)
    812  1.1  christos 	fr_info_t *fin;
    813  1.1  christos {
    814  1.1  christos 	ipf_main_softc_t *softc = fin->fin_main_soft;
    815  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    816  1.1  christos 	nat_t	*nat;
    817  1.1  christos 	ipfr_t	*ipf;
    818  1.1  christos 
    819  1.1  christos 	if ((softf->ipfr_lock) || !softf->ipfr_natlist)
    820  1.1  christos 		return NULL;
    821  1.1  christos #ifdef USE_MUTEXES
    822  1.1  christos 	ipf = ipf_frag_lookup(softc, softf, fin, softf->ipfr_nattab,
    823  1.1  christos 			      &softf->ipfr_natfrag);
    824  1.1  christos #else
    825  1.1  christos 	ipf = ipf_frag_lookup(softc, softf, fin, softf->ipfr_nattab);
    826  1.1  christos #endif
    827  1.1  christos 	if (ipf != NULL) {
    828  1.1  christos 		nat = ipf->ipfr_data;
    829  1.1  christos 		/*
    830  1.1  christos 		 * This is the last fragment for this packet.
    831  1.1  christos 		 */
    832  1.1  christos 		if ((ipf->ipfr_ttl == softc->ipf_ticks + 1) && (nat != NULL)) {
    833  1.1  christos 			nat->nat_data = NULL;
    834  1.1  christos 			ipf->ipfr_data = NULL;
    835  1.1  christos 		}
    836  1.1  christos 		RWLOCK_EXIT(&softf->ipfr_natfrag);
    837  1.1  christos 	} else
    838  1.1  christos 		nat = NULL;
    839  1.1  christos 	return nat;
    840  1.1  christos }
    841  1.1  christos 
    842  1.1  christos 
    843  1.1  christos /* ------------------------------------------------------------------------ */
    844  1.1  christos /* Function:    ipf_frag_ipidknown                                          */
    845  1.1  christos /* Returns:     u_32_t - IPv4 ID for this packet if match found, else       */
    846  1.1  christos /*                       return 0xfffffff to indicate no match.             */
    847  1.1  christos /* Parameters:  fin(I) - pointer to packet information                      */
    848  1.1  christos /*                                                                          */
    849  1.1  christos /* Functional interface for IP ID lookups of the IP ID fragment cache       */
    850  1.1  christos /* ------------------------------------------------------------------------ */
    851  1.1  christos u_32_t
    852  1.1  christos ipf_frag_ipidknown(fin)
    853  1.1  christos 	fr_info_t *fin;
    854  1.1  christos {
    855  1.1  christos 	ipf_main_softc_t *softc = fin->fin_main_soft;
    856  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    857  1.1  christos 	ipfr_t	*ipf;
    858  1.1  christos 	u_32_t	id;
    859  1.1  christos 
    860  1.1  christos 	if ((fin->fin_v != 4) || (softf->ipfr_lock) ||
    861  1.1  christos 	    !softf->ipfr_ipidlist)
    862  1.1  christos 		return 0xffffffff;
    863  1.1  christos 
    864  1.1  christos #ifdef USE_MUTEXES
    865  1.1  christos 	ipf = ipf_frag_lookup(softc, softf, fin, softf->ipfr_ipidtab,
    866  1.1  christos 			      &softf->ipfr_ipidfrag);
    867  1.1  christos #else
    868  1.1  christos 	ipf = ipf_frag_lookup(softc, softf, fin, softf->ipfr_ipidtab);
    869  1.1  christos #endif
    870  1.1  christos 	if (ipf != NULL) {
    871  1.1  christos 		id = (u_32_t)(intptr_t)ipf->ipfr_data;
    872  1.1  christos 		RWLOCK_EXIT(&softf->ipfr_ipidfrag);
    873  1.1  christos 	} else
    874  1.1  christos 		id = 0xffffffff;
    875  1.1  christos 	return id;
    876  1.1  christos }
    877  1.1  christos 
    878  1.1  christos 
    879  1.1  christos /* ------------------------------------------------------------------------ */
    880  1.1  christos /* Function:    ipf_frag_known                                              */
    881  1.1  christos /* Returns:     frentry_t* - pointer to filter rule if a match is found in  */
    882  1.1  christos /*                           the frag cache table, else NULL.               */
    883  1.1  christos /* Parameters:  fin(I)   - pointer to packet information                    */
    884  1.1  christos /*              passp(O) - pointer to where to store rule flags resturned   */
    885  1.1  christos /*                                                                          */
    886  1.1  christos /* Functional interface for normal lookups of the fragment cache.  If a     */
    887  1.1  christos /* match is found, return the rule pointer and flags from the rule, except  */
    888  1.1  christos /* that if FR_LOGFIRST is set, reset FR_LOG.                                */
    889  1.1  christos /* ------------------------------------------------------------------------ */
    890  1.1  christos frentry_t *
    891  1.1  christos ipf_frag_known(fin, passp)
    892  1.1  christos 	fr_info_t *fin;
    893  1.1  christos 	u_32_t *passp;
    894  1.1  christos {
    895  1.1  christos 	ipf_main_softc_t *softc = fin->fin_main_soft;
    896  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    897  1.1  christos 	frentry_t *fr = NULL;
    898  1.1  christos 	ipfr_t	*fra;
    899  1.1  christos 	u_32_t pass;
    900  1.1  christos 
    901  1.1  christos 	if ((softf->ipfr_lock) || (softf->ipfr_list == NULL))
    902  1.1  christos 		return NULL;
    903  1.1  christos 
    904  1.1  christos #ifdef USE_MUTEXES
    905  1.1  christos 	fra = ipf_frag_lookup(softc, softf, fin, softf->ipfr_heads,
    906  1.1  christos 			      &softc->ipf_frag);
    907  1.1  christos #else
    908  1.1  christos 	fra = ipf_frag_lookup(softc, softf, fin, softf->ipfr_heads);
    909  1.1  christos #endif
    910  1.1  christos 	if (fra != NULL) {
    911  1.1  christos 		if (fin->fin_flx & FI_BAD) {
    912  1.1  christos 			fr = &ipfr_block;
    913  1.1  christos 			fin->fin_reason = FRB_BADFRAG;
    914  1.1  christos 		} else {
    915  1.1  christos 			fr = fra->ipfr_rule;
    916  1.1  christos 		}
    917  1.1  christos 		fin->fin_fr = fr;
    918  1.1  christos 		if (fr != NULL) {
    919  1.1  christos 			pass = fr->fr_flags;
    920  1.1  christos 			if ((pass & FR_KEEPSTATE) != 0) {
    921  1.1  christos 				fin->fin_flx |= FI_STATE;
    922  1.1  christos 				/*
    923  1.1  christos 				 * Reset the keep state flag here so that we
    924  1.1  christos 				 * don't try and add a new state entry because
    925  1.1  christos 				 * of a match here. That leads to blocking of
    926  1.1  christos 				 * the packet later because the add fails.
    927  1.1  christos 				 */
    928  1.1  christos 				pass &= ~FR_KEEPSTATE;
    929  1.1  christos 			}
    930  1.1  christos 			if ((pass & FR_LOGFIRST) != 0)
    931  1.1  christos 				pass &= ~(FR_LOGFIRST|FR_LOG);
    932  1.1  christos 			*passp = pass;
    933  1.1  christos 		}
    934  1.1  christos 		RWLOCK_EXIT(&softc->ipf_frag);
    935  1.1  christos 	}
    936  1.1  christos 	return fr;
    937  1.1  christos }
    938  1.1  christos 
    939  1.1  christos 
    940  1.1  christos /* ------------------------------------------------------------------------ */
    941  1.1  christos /* Function:    ipf_frag_natforget                                          */
    942  1.1  christos /* Returns:     Nil                                                         */
    943  1.1  christos /* Parameters:  ptr(I) - pointer to data structure                          */
    944  1.1  christos /*                                                                          */
    945  1.1  christos /* Search through all of the fragment cache entries for NAT and wherever a  */
    946  1.1  christos /* pointer  is found to match ptr, reset it to NULL.                        */
    947  1.1  christos /* ------------------------------------------------------------------------ */
    948  1.1  christos void
    949  1.1  christos ipf_frag_natforget(softc, ptr)
    950  1.1  christos 	ipf_main_softc_t *softc;
    951  1.1  christos 	void *ptr;
    952  1.1  christos {
    953  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    954  1.1  christos 	ipfr_t	*fr;
    955  1.1  christos 
    956  1.1  christos 	WRITE_ENTER(&softf->ipfr_natfrag);
    957  1.1  christos 	for (fr = softf->ipfr_natlist; fr; fr = fr->ipfr_next)
    958  1.1  christos 		if (fr->ipfr_data == ptr)
    959  1.1  christos 			fr->ipfr_data = NULL;
    960  1.1  christos 	RWLOCK_EXIT(&softf->ipfr_natfrag);
    961  1.1  christos }
    962  1.1  christos 
    963  1.1  christos 
    964  1.1  christos /* ------------------------------------------------------------------------ */
    965  1.1  christos /* Function:    ipf_frag_delete                                             */
    966  1.1  christos /* Returns:     Nil                                                         */
    967  1.1  christos /* Parameters:  fra(I)   - pointer to fragment structure to delete          */
    968  1.1  christos /*              tail(IO) - pointer to the pointer to the tail of the frag   */
    969  1.1  christos /*                         list                                             */
    970  1.1  christos /*                                                                          */
    971  1.1  christos /* Remove a fragment cache table entry from the table & list.  Also free    */
    972  1.1  christos /* the filter rule it is associated with it if it is no longer used as a    */
    973  1.1  christos /* result of decreasing the reference count.                                */
    974  1.1  christos /* ------------------------------------------------------------------------ */
    975  1.1  christos static void
    976  1.1  christos ipf_frag_delete(softc, fra, tail)
    977  1.1  christos 	ipf_main_softc_t *softc;
    978  1.1  christos 	ipfr_t *fra, ***tail;
    979  1.1  christos {
    980  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
    981  1.1  christos 
    982  1.1  christos 	if (fra->ipfr_next)
    983  1.1  christos 		fra->ipfr_next->ipfr_prev = fra->ipfr_prev;
    984  1.1  christos 	*fra->ipfr_prev = fra->ipfr_next;
    985  1.1  christos 	if (*tail == &fra->ipfr_next)
    986  1.1  christos 		*tail = fra->ipfr_prev;
    987  1.1  christos 
    988  1.1  christos 	if (fra->ipfr_hnext)
    989  1.1  christos 		fra->ipfr_hnext->ipfr_hprev = fra->ipfr_hprev;
    990  1.1  christos 	*fra->ipfr_hprev = fra->ipfr_hnext;
    991  1.1  christos 
    992  1.1  christos 	if (fra->ipfr_rule != NULL) {
    993  1.1  christos 		(void) ipf_derefrule(softc, &fra->ipfr_rule);
    994  1.1  christos 	}
    995  1.1  christos 
    996  1.1  christos 	if (fra->ipfr_ref <= 0)
    997  1.1  christos 		ipf_frag_free(softf, fra);
    998  1.1  christos }
    999  1.1  christos 
   1000  1.1  christos 
   1001  1.1  christos /* ------------------------------------------------------------------------ */
   1002  1.1  christos /* Function:    ipf_frag_free                                               */
   1003  1.1  christos /* Returns:     Nil                                                         */
   1004  1.1  christos /*                                                                          */
   1005  1.1  christos /* ------------------------------------------------------------------------ */
   1006  1.1  christos static void
   1007  1.1  christos ipf_frag_free(softf, fra)
   1008  1.1  christos 	ipf_frag_softc_t *softf;
   1009  1.1  christos 	ipfr_t *fra;
   1010  1.1  christos {
   1011  1.1  christos 	KFREE(fra);
   1012  1.1  christos 	FBUMP(ifs_expire);
   1013  1.1  christos 	softf->ipfr_stats.ifs_inuse--;
   1014  1.1  christos }
   1015  1.1  christos 
   1016  1.1  christos 
   1017  1.1  christos /* ------------------------------------------------------------------------ */
   1018  1.1  christos /* Function:    ipf_frag_clear                                              */
   1019  1.1  christos /* Returns:     Nil                                                         */
   1020  1.1  christos /* Parameters:  Nil                                                         */
   1021  1.1  christos /*                                                                          */
   1022  1.1  christos /* Free memory in use by fragment state information kept.  Do the normal    */
   1023  1.1  christos /* fragment state stuff first and then the NAT-fragment table.              */
   1024  1.1  christos /* ------------------------------------------------------------------------ */
   1025  1.1  christos void
   1026  1.1  christos ipf_frag_clear(softc)
   1027  1.1  christos 	ipf_main_softc_t *softc;
   1028  1.1  christos {
   1029  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
   1030  1.1  christos 	ipfr_t	*fra;
   1031  1.1  christos 	nat_t	*nat;
   1032  1.1  christos 
   1033  1.1  christos 	WRITE_ENTER(&softc->ipf_frag);
   1034  1.1  christos 	while ((fra = softf->ipfr_list) != NULL) {
   1035  1.1  christos 		fra->ipfr_ref--;
   1036  1.1  christos 		ipf_frag_delete(softc, fra, &softf->ipfr_tail);
   1037  1.1  christos 	}
   1038  1.1  christos 	softf->ipfr_tail = &softf->ipfr_list;
   1039  1.1  christos 	RWLOCK_EXIT(&softc->ipf_frag);
   1040  1.1  christos 
   1041  1.1  christos 	WRITE_ENTER(&softc->ipf_nat);
   1042  1.1  christos 	WRITE_ENTER(&softf->ipfr_natfrag);
   1043  1.1  christos 	while ((fra = softf->ipfr_natlist) != NULL) {
   1044  1.1  christos 		nat = fra->ipfr_data;
   1045  1.1  christos 		if (nat != NULL) {
   1046  1.1  christos 			if (nat->nat_data == fra)
   1047  1.1  christos 				nat->nat_data = NULL;
   1048  1.1  christos 		}
   1049  1.1  christos 		fra->ipfr_ref--;
   1050  1.1  christos 		ipf_frag_delete(softc, fra, &softf->ipfr_nattail);
   1051  1.1  christos 	}
   1052  1.1  christos 	softf->ipfr_nattail = &softf->ipfr_natlist;
   1053  1.1  christos 	RWLOCK_EXIT(&softf->ipfr_natfrag);
   1054  1.1  christos 	RWLOCK_EXIT(&softc->ipf_nat);
   1055  1.1  christos }
   1056  1.1  christos 
   1057  1.1  christos 
   1058  1.1  christos /* ------------------------------------------------------------------------ */
   1059  1.1  christos /* Function:    ipf_frag_expire                                             */
   1060  1.1  christos /* Returns:     Nil                                                         */
   1061  1.1  christos /* Parameters:  Nil                                                         */
   1062  1.1  christos /*                                                                          */
   1063  1.1  christos /* Expire entries in the fragment cache table that have been there too long */
   1064  1.1  christos /* ------------------------------------------------------------------------ */
   1065  1.1  christos void
   1066  1.1  christos ipf_frag_expire(softc)
   1067  1.1  christos 	ipf_main_softc_t *softc;
   1068  1.1  christos {
   1069  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
   1070  1.1  christos 	ipfr_t	**fp, *fra;
   1071  1.1  christos 	nat_t	*nat;
   1072  1.1  christos 	SPL_INT(s);
   1073  1.1  christos 
   1074  1.1  christos 	if (softf->ipfr_lock)
   1075  1.1  christos 		return;
   1076  1.1  christos 
   1077  1.1  christos 	SPL_NET(s);
   1078  1.1  christos 	WRITE_ENTER(&softc->ipf_frag);
   1079  1.1  christos 	/*
   1080  1.1  christos 	 * Go through the entire table, looking for entries to expire,
   1081  1.1  christos 	 * which is indicated by the ttl being less than or equal to ipf_ticks.
   1082  1.1  christos 	 */
   1083  1.1  christos 	for (fp = &softf->ipfr_list; ((fra = *fp) != NULL); ) {
   1084  1.1  christos 		if (fra->ipfr_ttl > softc->ipf_ticks)
   1085  1.1  christos 			break;
   1086  1.1  christos 		fra->ipfr_ref--;
   1087  1.1  christos 		ipf_frag_delete(softc, fra, &softf->ipfr_tail);
   1088  1.1  christos 	}
   1089  1.1  christos 	RWLOCK_EXIT(&softc->ipf_frag);
   1090  1.1  christos 
   1091  1.1  christos 	WRITE_ENTER(&softf->ipfr_ipidfrag);
   1092  1.1  christos 	for (fp = &softf->ipfr_ipidlist; ((fra = *fp) != NULL); ) {
   1093  1.1  christos 		if (fra->ipfr_ttl > softc->ipf_ticks)
   1094  1.1  christos 			break;
   1095  1.1  christos 		fra->ipfr_ref--;
   1096  1.1  christos 		ipf_frag_delete(softc, fra, &softf->ipfr_ipidtail);
   1097  1.1  christos 	}
   1098  1.1  christos 	RWLOCK_EXIT(&softf->ipfr_ipidfrag);
   1099  1.1  christos 
   1100  1.1  christos 	/*
   1101  1.1  christos 	 * Same again for the NAT table, except that if the structure also
   1102  1.1  christos 	 * still points to a NAT structure, and the NAT structure points back
   1103  1.1  christos 	 * at the one to be free'd, NULL the reference from the NAT struct.
   1104  1.1  christos 	 * NOTE: We need to grab both mutex's early, and in this order so as
   1105  1.1  christos 	 * to prevent a deadlock if both try to expire at the same time.
   1106  1.1  christos 	 * The extra if() statement here is because it locks out all NAT
   1107  1.1  christos 	 * operations - no need to do that if there are no entries in this
   1108  1.1  christos 	 * list, right?
   1109  1.1  christos 	 */
   1110  1.1  christos 	if (softf->ipfr_natlist != NULL) {
   1111  1.1  christos 		WRITE_ENTER(&softc->ipf_nat);
   1112  1.1  christos 		WRITE_ENTER(&softf->ipfr_natfrag);
   1113  1.1  christos 		for (fp = &softf->ipfr_natlist; ((fra = *fp) != NULL); ) {
   1114  1.1  christos 			if (fra->ipfr_ttl > softc->ipf_ticks)
   1115  1.1  christos 				break;
   1116  1.1  christos 			nat = fra->ipfr_data;
   1117  1.1  christos 			if (nat != NULL) {
   1118  1.1  christos 				if (nat->nat_data == fra)
   1119  1.1  christos 					nat->nat_data = NULL;
   1120  1.1  christos 			}
   1121  1.1  christos 			fra->ipfr_ref--;
   1122  1.1  christos 			ipf_frag_delete(softc, fra, &softf->ipfr_nattail);
   1123  1.1  christos 		}
   1124  1.1  christos 		RWLOCK_EXIT(&softf->ipfr_natfrag);
   1125  1.1  christos 		RWLOCK_EXIT(&softc->ipf_nat);
   1126  1.1  christos 	}
   1127  1.1  christos 	SPL_X(s);
   1128  1.1  christos }
   1129  1.1  christos 
   1130  1.1  christos 
   1131  1.1  christos /* ------------------------------------------------------------------------ */
   1132  1.1  christos /* Function:    ipf_frag_pkt_next                                           */
   1133  1.1  christos /* ------------------------------------------------------------------------ */
   1134  1.1  christos int
   1135  1.1  christos ipf_frag_pkt_next(softc, token, itp)
   1136  1.1  christos 	ipf_main_softc_t *softc;
   1137  1.1  christos 	ipftoken_t *token;
   1138  1.1  christos 	ipfgeniter_t *itp;
   1139  1.1  christos {
   1140  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
   1141  1.1  christos 
   1142  1.1  christos #ifdef USE_MUTEXES
   1143  1.1  christos 	return ipf_frag_next(softc, token, itp, &softf->ipfr_list,
   1144  1.1  christos 			     &softf->ipfr_frag);
   1145  1.1  christos #else
   1146  1.1  christos 	return ipf_frag_next(softc, token, itp, &softf->ipfr_list);
   1147  1.1  christos #endif
   1148  1.1  christos }
   1149  1.1  christos 
   1150  1.1  christos 
   1151  1.1  christos /* ------------------------------------------------------------------------ */
   1152  1.1  christos /* Function:    ipf_frag_nat_next                                           */
   1153  1.1  christos /* ------------------------------------------------------------------------ */
   1154  1.1  christos int
   1155  1.1  christos ipf_frag_nat_next(softc, token, itp)
   1156  1.1  christos 	ipf_main_softc_t *softc;
   1157  1.1  christos 	ipftoken_t *token;
   1158  1.1  christos 	ipfgeniter_t *itp;
   1159  1.1  christos {
   1160  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;;
   1161  1.1  christos 
   1162  1.1  christos #ifdef USE_MUTEXES
   1163  1.1  christos 	return ipf_frag_next(softc, token, itp, &softf->ipfr_natlist,
   1164  1.1  christos 			     &softf->ipfr_natfrag);
   1165  1.1  christos #else
   1166  1.1  christos 	return ipf_frag_next(softc, token, itp, &softf->ipfr_natlist);
   1167  1.1  christos #endif
   1168  1.1  christos }
   1169  1.1  christos 
   1170  1.1  christos /* ------------------------------------------------------------------------ */
   1171  1.1  christos /* Function:    ipf_frag_next                                               */
   1172  1.1  christos /* Returns:     int      - 0 == success, else error                         */
   1173  1.1  christos /* Parameters:  token(I) - pointer to token information for this caller     */
   1174  1.1  christos /*              itp(I)   - pointer to generic iterator from caller          */
   1175  1.1  christos /*              top(I)   - top of the fragment list                         */
   1176  1.1  christos /*              lock(I)  - fragment cache lock                              */
   1177  1.1  christos /*                                                                          */
   1178  1.1  christos /* This function is used to interate through the list of entries in the     */
   1179  1.1  christos /* fragment cache.  It increases the reference count on the one currently   */
   1180  1.1  christos /* being returned so that the caller can come back and resume from it later.*/
   1181  1.1  christos /*                                                                          */
   1182  1.1  christos /* This function is used for both the NAT fragment cache as well as the ipf */
   1183  1.1  christos /* fragment cache - hence the reason for passing in top and lock.           */
   1184  1.1  christos /* ------------------------------------------------------------------------ */
   1185  1.1  christos static int
   1186  1.1  christos ipf_frag_next(softc, token, itp, top
   1187  1.1  christos #ifdef USE_MUTEXES
   1188  1.1  christos , lock
   1189  1.1  christos #endif
   1190  1.1  christos )
   1191  1.1  christos 	ipf_main_softc_t *softc;
   1192  1.1  christos 	ipftoken_t *token;
   1193  1.1  christos 	ipfgeniter_t *itp;
   1194  1.1  christos 	ipfr_t **top;
   1195  1.1  christos #ifdef USE_MUTEXES
   1196  1.1  christos 	ipfrwlock_t *lock;
   1197  1.1  christos #endif
   1198  1.1  christos {
   1199  1.1  christos 	ipfr_t *frag, *next, zero;
   1200  1.1  christos 	int error = 0;
   1201  1.1  christos 
   1202  1.1  christos 	if (itp->igi_data == NULL) {
   1203  1.1  christos 		IPFERROR(20001);
   1204  1.1  christos 		return EFAULT;
   1205  1.1  christos 	}
   1206  1.1  christos 
   1207  1.1  christos 	if (itp->igi_nitems != 1) {
   1208  1.1  christos 		IPFERROR(20003);
   1209  1.1  christos 		return EFAULT;
   1210  1.1  christos 	}
   1211  1.1  christos 
   1212  1.1  christos 	frag = token->ipt_data;
   1213  1.1  christos 
   1214  1.1  christos 	READ_ENTER(lock);
   1215  1.1  christos 
   1216  1.1  christos 	if (frag == NULL)
   1217  1.1  christos 		next = *top;
   1218  1.1  christos 	else
   1219  1.1  christos 		next = frag->ipfr_next;
   1220  1.1  christos 
   1221  1.1  christos 	if (next != NULL) {
   1222  1.1  christos 		ATOMIC_INC(next->ipfr_ref);
   1223  1.1  christos 		token->ipt_data = next;
   1224  1.1  christos 	} else {
   1225  1.1  christos 		bzero(&zero, sizeof(zero));
   1226  1.1  christos 		next = &zero;
   1227  1.1  christos 		token->ipt_data = NULL;
   1228  1.1  christos 	}
   1229  1.1  christos 	if (next->ipfr_next == NULL)
   1230  1.1  christos 		ipf_token_mark_complete(token);
   1231  1.1  christos 
   1232  1.1  christos 	RWLOCK_EXIT(lock);
   1233  1.1  christos 
   1234  1.1  christos 	error = COPYOUT(next, itp->igi_data, sizeof(*next));
   1235  1.1  christos 	if (error != 0)
   1236  1.1  christos 		IPFERROR(20002);
   1237  1.1  christos 
   1238  1.1  christos         if (frag != NULL) {
   1239  1.1  christos #ifdef USE_MUTEXES
   1240  1.1  christos 		ipf_frag_deref(softc, &frag, lock);
   1241  1.1  christos #else
   1242  1.1  christos 		ipf_frag_deref(softc, &frag);
   1243  1.1  christos #endif
   1244  1.1  christos         }
   1245  1.1  christos         return error;
   1246  1.1  christos }
   1247  1.1  christos 
   1248  1.1  christos 
   1249  1.1  christos /* ------------------------------------------------------------------------ */
   1250  1.1  christos /* Function:    ipf_frag_pkt_deref                                          */
   1251  1.1  christos /* Returns:     Nil                                                         */
   1252  1.1  christos /*                                                                          */
   1253  1.1  christos /* ------------------------------------------------------------------------ */
   1254  1.1  christos void
   1255  1.1  christos ipf_frag_pkt_deref(softc, data)
   1256  1.1  christos 	ipf_main_softc_t *softc;
   1257  1.1  christos 	void *data;
   1258  1.1  christos {
   1259  1.1  christos 	ipfr_t **frp = data;
   1260  1.1  christos 
   1261  1.1  christos #ifdef USE_MUTEXES
   1262  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
   1263  1.1  christos 
   1264  1.1  christos 	ipf_frag_deref(softc->ipf_frag_soft, frp, &softf->ipfr_frag);
   1265  1.1  christos #else
   1266  1.1  christos 	ipf_frag_deref(softc->ipf_frag_soft, frp);
   1267  1.1  christos #endif
   1268  1.1  christos }
   1269  1.1  christos 
   1270  1.1  christos 
   1271  1.1  christos /* ------------------------------------------------------------------------ */
   1272  1.1  christos /* Function:    ipf_frag_nat_deref                                          */
   1273  1.1  christos /* Returns:     Nil                                                         */
   1274  1.1  christos /*                                                                          */
   1275  1.1  christos /* ------------------------------------------------------------------------ */
   1276  1.1  christos void
   1277  1.1  christos ipf_frag_nat_deref(softc, data)
   1278  1.1  christos 	ipf_main_softc_t *softc;
   1279  1.1  christos 	void *data;
   1280  1.1  christos {
   1281  1.1  christos 	ipfr_t **frp = data;
   1282  1.1  christos 
   1283  1.1  christos #ifdef USE_MUTEXES
   1284  1.1  christos 	ipf_frag_softc_t *softf = softc->ipf_frag_soft;
   1285  1.1  christos 
   1286  1.1  christos 	ipf_frag_deref(softc->ipf_frag_soft, frp, &softf->ipfr_natfrag);
   1287  1.1  christos #else
   1288  1.1  christos 	ipf_frag_deref(softc->ipf_frag_soft, frp);
   1289  1.1  christos #endif
   1290  1.1  christos }
   1291  1.1  christos 
   1292  1.1  christos 
   1293  1.1  christos /* ------------------------------------------------------------------------ */
   1294  1.1  christos /* Function:    ipf_frag_deref                                              */
   1295  1.1  christos /* Returns:     Nil                                                         */
   1296  1.1  christos /* Parameters:  frp(IO) - pointer to fragment structure to deference        */
   1297  1.1  christos /*              lock(I) - lock associated with the fragment                 */
   1298  1.1  christos /*                                                                          */
   1299  1.1  christos /* This function dereferences a fragment structure (ipfr_t).  The pointer   */
   1300  1.1  christos /* passed in will always be reset back to NULL, even if the structure is    */
   1301  1.1  christos /* not freed, to enforce the notion that the caller is no longer entitled   */
   1302  1.1  christos /* to use the pointer it is dropping the reference to.                      */
   1303  1.1  christos /* ------------------------------------------------------------------------ */
   1304  1.1  christos static void
   1305  1.1  christos ipf_frag_deref(arg, frp
   1306  1.1  christos #ifdef USE_MUTEXES
   1307  1.1  christos , lock
   1308  1.1  christos #endif
   1309  1.1  christos )
   1310  1.1  christos 	void *arg;
   1311  1.1  christos 	ipfr_t **frp;
   1312  1.1  christos #ifdef USE_MUTEXES
   1313  1.1  christos 	ipfrwlock_t *lock;
   1314  1.1  christos #endif
   1315  1.1  christos {
   1316  1.1  christos 	ipf_frag_softc_t *softf = arg;
   1317  1.1  christos 	ipfr_t *fra;
   1318  1.1  christos 
   1319  1.1  christos 	fra = *frp;
   1320  1.1  christos 	*frp = NULL;
   1321  1.1  christos 
   1322  1.1  christos 	WRITE_ENTER(lock);
   1323  1.1  christos 	fra->ipfr_ref--;
   1324  1.1  christos 	if (fra->ipfr_ref <= 0)
   1325  1.1  christos 		ipf_frag_free(softf, fra);
   1326  1.1  christos 	RWLOCK_EXIT(lock);
   1327  1.1  christos }
   1328