Home | History | Annotate | Line # | Download | only in npf
npf_ext_log.c revision 1.2
      1  1.2  rmind /*	$NetBSD: npf_ext_log.c,v 1.2 2012/12/24 19:05:42 rmind Exp $	*/
      2  1.1  rmind 
      3  1.1  rmind /*-
      4  1.1  rmind  * Copyright (c) 2010-2012 The NetBSD Foundation, Inc.
      5  1.1  rmind  * All rights reserved.
      6  1.1  rmind  *
      7  1.1  rmind  * This material is based upon work partially supported by The
      8  1.1  rmind  * NetBSD Foundation under a contract with Mindaugas Rasiukevicius.
      9  1.1  rmind  *
     10  1.1  rmind  * Redistribution and use in source and binary forms, with or without
     11  1.1  rmind  * modification, are permitted provided that the following conditions
     12  1.1  rmind  * are met:
     13  1.1  rmind  * 1. Redistributions of source code must retain the above copyright
     14  1.1  rmind  *    notice, this list of conditions and the following disclaimer.
     15  1.1  rmind  * 2. Redistributions in binary form must reproduce the above copyright
     16  1.1  rmind  *    notice, this list of conditions and the following disclaimer in the
     17  1.1  rmind  *    documentation and/or other materials provided with the distribution.
     18  1.1  rmind  *
     19  1.1  rmind  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20  1.1  rmind  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21  1.1  rmind  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22  1.1  rmind  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23  1.1  rmind  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24  1.1  rmind  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25  1.1  rmind  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26  1.1  rmind  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27  1.1  rmind  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28  1.1  rmind  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29  1.1  rmind  * POSSIBILITY OF SUCH DAMAGE.
     30  1.1  rmind  */
     31  1.1  rmind 
     32  1.1  rmind /*
     33  1.1  rmind  * NPF logging extension.
     34  1.1  rmind  */
     35  1.1  rmind 
     36  1.1  rmind #include <sys/cdefs.h>
     37  1.2  rmind __KERNEL_RCSID(0, "$NetBSD: npf_ext_log.c,v 1.2 2012/12/24 19:05:42 rmind Exp $");
     38  1.1  rmind 
     39  1.1  rmind #include <sys/types.h>
     40  1.1  rmind #include <sys/module.h>
     41  1.1  rmind 
     42  1.1  rmind #include <sys/conf.h>
     43  1.1  rmind #include <sys/kmem.h>
     44  1.1  rmind #include <sys/mbuf.h>
     45  1.1  rmind #include <sys/mutex.h>
     46  1.1  rmind #include <sys/queue.h>
     47  1.1  rmind 
     48  1.1  rmind #include <net/if.h>
     49  1.1  rmind #include <net/if_types.h>
     50  1.1  rmind #include <net/bpf.h>
     51  1.1  rmind 
     52  1.1  rmind #include "npf_impl.h"
     53  1.1  rmind 
     54  1.1  rmind NPF_EXT_MODULE(npf_ext_log, "");
     55  1.1  rmind 
     56  1.1  rmind #define	NPFEXT_LOG_VER		1
     57  1.1  rmind 
     58  1.1  rmind static void *		npf_ext_log_id;
     59  1.1  rmind 
     60  1.1  rmind typedef struct {
     61  1.1  rmind 	unsigned int	if_idx;
     62  1.1  rmind } npf_ext_log_t;
     63  1.1  rmind 
     64  1.1  rmind typedef struct npflog_softc {
     65  1.1  rmind 	LIST_ENTRY(npflog_softc)	sc_entry;
     66  1.1  rmind 	kmutex_t			sc_lock;
     67  1.1  rmind 	ifnet_t				sc_if;
     68  1.1  rmind 	int				sc_unit;
     69  1.1  rmind } npflog_softc_t;
     70  1.1  rmind 
     71  1.1  rmind static int	npflog_clone_create(struct if_clone *, int);
     72  1.1  rmind static int	npflog_clone_destroy(ifnet_t *);
     73  1.1  rmind 
     74  1.1  rmind static LIST_HEAD(, npflog_softc)	npflog_if_list	__cacheline_aligned;
     75  1.1  rmind static struct if_clone			npflog_cloner =
     76  1.1  rmind     IF_CLONE_INITIALIZER("npflog", npflog_clone_create, npflog_clone_destroy);
     77  1.1  rmind 
     78  1.1  rmind void
     79  1.1  rmind npflogattach(int nunits)
     80  1.1  rmind {
     81  1.1  rmind 
     82  1.1  rmind 	LIST_INIT(&npflog_if_list);
     83  1.1  rmind 	if_clone_attach(&npflog_cloner);
     84  1.1  rmind }
     85  1.1  rmind 
     86  1.1  rmind void
     87  1.1  rmind npflogdetach(void)
     88  1.1  rmind {
     89  1.1  rmind 	npflog_softc_t *sc;
     90  1.1  rmind 
     91  1.1  rmind 	while ((sc = LIST_FIRST(&npflog_if_list)) != NULL) {
     92  1.1  rmind 		npflog_clone_destroy(&sc->sc_if);
     93  1.1  rmind 	}
     94  1.1  rmind 	if_clone_detach(&npflog_cloner);
     95  1.1  rmind }
     96  1.1  rmind 
     97  1.1  rmind static int
     98  1.1  rmind npflog_ioctl(ifnet_t *ifp, u_long cmd, void *data)
     99  1.1  rmind {
    100  1.1  rmind 	npflog_softc_t *sc = ifp->if_softc;
    101  1.1  rmind 	int error = 0;
    102  1.1  rmind 
    103  1.1  rmind 	mutex_enter(&sc->sc_lock);
    104  1.1  rmind 	switch (cmd) {
    105  1.1  rmind 	case SIOCINITIFADDR:
    106  1.1  rmind 		ifp->if_flags |= (IFF_UP | IFF_RUNNING);
    107  1.1  rmind 		break;
    108  1.1  rmind 	default:
    109  1.1  rmind 		error = ifioctl_common(ifp, cmd, data);
    110  1.1  rmind 		break;
    111  1.1  rmind 	}
    112  1.1  rmind 	mutex_exit(&sc->sc_lock);
    113  1.1  rmind 	return error;
    114  1.1  rmind }
    115  1.1  rmind 
    116  1.1  rmind static int
    117  1.1  rmind npflog_clone_create(struct if_clone *ifc, int unit)
    118  1.1  rmind {
    119  1.1  rmind 	npflog_softc_t *sc;
    120  1.1  rmind 	ifnet_t *ifp;
    121  1.1  rmind 
    122  1.1  rmind 	sc = kmem_zalloc(sizeof(npflog_softc_t), KM_SLEEP);
    123  1.1  rmind 	mutex_init(&sc->sc_lock, MUTEX_DEFAULT, IPL_SOFTNET);
    124  1.1  rmind 
    125  1.1  rmind 	ifp = &sc->sc_if;
    126  1.1  rmind 	ifp->if_softc = sc;
    127  1.1  rmind 
    128  1.1  rmind 	if_initname(ifp, "npflog", unit);
    129  1.1  rmind 	ifp->if_type = IFT_OTHER;
    130  1.1  rmind 	ifp->if_dlt = DLT_NULL;
    131  1.1  rmind 	ifp->if_ioctl = npflog_ioctl;
    132  1.1  rmind 
    133  1.1  rmind 	KERNEL_LOCK(1, NULL);
    134  1.1  rmind 	if_attach(ifp);
    135  1.1  rmind 	if_alloc_sadl(ifp);
    136  1.1  rmind 	bpf_attach(ifp, DLT_NULL, 0);
    137  1.1  rmind 	LIST_INSERT_HEAD(&npflog_if_list, sc, sc_entry);
    138  1.1  rmind 	KERNEL_UNLOCK_ONE(NULL);
    139  1.1  rmind 
    140  1.1  rmind 	return 0;
    141  1.1  rmind }
    142  1.1  rmind 
    143  1.1  rmind static int
    144  1.1  rmind npflog_clone_destroy(ifnet_t *ifp)
    145  1.1  rmind {
    146  1.1  rmind 	npflog_softc_t *sc = ifp->if_softc;
    147  1.1  rmind 
    148  1.1  rmind 	KERNEL_LOCK(1, NULL);
    149  1.1  rmind 	LIST_REMOVE(sc, sc_entry);
    150  1.1  rmind 	bpf_detach(ifp);
    151  1.1  rmind 	if_detach(ifp);
    152  1.1  rmind 	KERNEL_UNLOCK_ONE(NULL);
    153  1.1  rmind 
    154  1.1  rmind 	mutex_destroy(&sc->sc_lock);
    155  1.1  rmind 	kmem_free(sc, sizeof(npflog_softc_t));
    156  1.1  rmind 	return 0;
    157  1.1  rmind }
    158  1.1  rmind 
    159  1.1  rmind static int
    160  1.1  rmind npf_log_ctor(npf_rproc_t *rp, prop_dictionary_t params)
    161  1.1  rmind {
    162  1.1  rmind 	npf_ext_log_t *meta;
    163  1.1  rmind 
    164  1.1  rmind 	meta = kmem_zalloc(sizeof(npf_ext_log_t), KM_SLEEP);
    165  1.1  rmind 	prop_dictionary_get_uint32(params, "log-interface", &meta->if_idx);
    166  1.1  rmind 	npf_rproc_assign(rp, meta);
    167  1.1  rmind 	return 0;
    168  1.1  rmind }
    169  1.1  rmind 
    170  1.1  rmind static void
    171  1.1  rmind npf_log_dtor(npf_rproc_t *rp, void *meta)
    172  1.1  rmind {
    173  1.1  rmind 	kmem_free(meta, sizeof(npf_ext_log_t));
    174  1.1  rmind }
    175  1.1  rmind 
    176  1.1  rmind static void
    177  1.1  rmind npf_log(npf_cache_t *npc, nbuf_t *nbuf, void *meta, int *decision)
    178  1.1  rmind {
    179  1.2  rmind 	struct mbuf *m = nbuf_head_mbuf(nbuf);
    180  1.1  rmind 	const npf_ext_log_t *log = meta;
    181  1.1  rmind 	ifnet_t *ifp;
    182  1.1  rmind 	int family;
    183  1.1  rmind 
    184  1.1  rmind 	/* Set the address family. */
    185  1.1  rmind 	if (npf_iscached(npc, NPC_IP4)) {
    186  1.1  rmind 		family = AF_INET;
    187  1.1  rmind 	} else if (npf_iscached(npc, NPC_IP6)) {
    188  1.1  rmind 		family = AF_INET6;
    189  1.1  rmind 	} else {
    190  1.1  rmind 		family = AF_UNSPEC;
    191  1.1  rmind 	}
    192  1.1  rmind 
    193  1.1  rmind 	KERNEL_LOCK(1, NULL);
    194  1.1  rmind 
    195  1.1  rmind 	/* Find a pseudo-interface to log. */
    196  1.1  rmind 	ifp = if_byindex(log->if_idx);
    197  1.1  rmind 	if (ifp == NULL) {
    198  1.1  rmind 		/* No interface. */
    199  1.1  rmind 		KERNEL_UNLOCK_ONE(NULL);
    200  1.1  rmind 		return;
    201  1.1  rmind 	}
    202  1.1  rmind 
    203  1.1  rmind 	/* Pass through BPF. */
    204  1.1  rmind 	ifp->if_opackets++;
    205  1.1  rmind 	ifp->if_obytes += m->m_pkthdr.len;
    206  1.1  rmind 	bpf_mtap_af(ifp, family, m);
    207  1.1  rmind 	KERNEL_UNLOCK_ONE(NULL);
    208  1.1  rmind }
    209  1.1  rmind 
    210  1.1  rmind /*
    211  1.1  rmind  * Module interface.
    212  1.1  rmind  */
    213  1.1  rmind static int
    214  1.1  rmind npf_ext_log_modcmd(modcmd_t cmd, void *arg)
    215  1.1  rmind {
    216  1.1  rmind 	static const npf_ext_ops_t npf_log_ops = {
    217  1.1  rmind 		.version	= NPFEXT_LOG_VER,
    218  1.1  rmind 		.ctx		= NULL,
    219  1.1  rmind 		.ctor		= npf_log_ctor,
    220  1.1  rmind 		.dtor		= npf_log_dtor,
    221  1.1  rmind 		.proc		= npf_log
    222  1.1  rmind 	};
    223  1.1  rmind 	int error;
    224  1.1  rmind 
    225  1.1  rmind 	switch (cmd) {
    226  1.1  rmind 	case MODULE_CMD_INIT:
    227  1.1  rmind 		/*
    228  1.1  rmind 		 * Initialise the NPF logging extension.
    229  1.1  rmind 		 */
    230  1.1  rmind 		npflogattach(1);
    231  1.1  rmind 		npf_ext_log_id = npf_ext_register("log", &npf_log_ops);
    232  1.1  rmind 		if (!npf_ext_log_id) {
    233  1.1  rmind 			npflogdetach();
    234  1.1  rmind 			return EEXIST;
    235  1.1  rmind 		}
    236  1.1  rmind 		break;
    237  1.1  rmind 
    238  1.1  rmind 	case MODULE_CMD_FINI:
    239  1.1  rmind 		error = npf_ext_unregister(npf_ext_log_id);
    240  1.1  rmind 		if (error) {
    241  1.1  rmind 			return error;
    242  1.1  rmind 		}
    243  1.1  rmind 		npflogdetach();
    244  1.1  rmind 		break;
    245  1.1  rmind 
    246  1.1  rmind 	case MODULE_CMD_AUTOUNLOAD:
    247  1.1  rmind 		/* Allow auto-unload only if NPF permits it. */
    248  1.1  rmind 		return npf_autounload_p() ? 0 : EBUSY;
    249  1.1  rmind 
    250  1.1  rmind 	default:
    251  1.1  rmind 		return ENOTTY;
    252  1.1  rmind 	}
    253  1.1  rmind 	return 0;
    254  1.1  rmind }
    255