pfil.h revision 1.30 1 1.30 dholland /* $NetBSD: pfil.h,v 1.30 2012/09/30 05:02:08 dholland Exp $ */
2 1.1 mrg
3 1.1 mrg /*
4 1.1 mrg * Copyright (c) 1996 Matthew R. Green
5 1.1 mrg * All rights reserved.
6 1.1 mrg *
7 1.1 mrg * Redistribution and use in source and binary forms, with or without
8 1.1 mrg * modification, are permitted provided that the following conditions
9 1.1 mrg * are met:
10 1.1 mrg * 1. Redistributions of source code must retain the above copyright
11 1.1 mrg * notice, this list of conditions and the following disclaimer.
12 1.1 mrg * 2. Redistributions in binary form must reproduce the above copyright
13 1.1 mrg * notice, this list of conditions and the following disclaimer in the
14 1.1 mrg * documentation and/or other materials provided with the distribution.
15 1.1 mrg *
16 1.1 mrg * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
17 1.1 mrg * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
18 1.1 mrg * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
19 1.1 mrg * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
20 1.1 mrg * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21 1.1 mrg * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
22 1.1 mrg * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23 1.1 mrg * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24 1.1 mrg * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 1.1 mrg * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 1.1 mrg * SUCH DAMAGE.
27 1.1 mrg */
28 1.1 mrg
29 1.1 mrg #ifndef _NET_PFIL_H_
30 1.1 mrg #define _NET_PFIL_H_
31 1.21 martin
32 1.22 martin #ifdef _KERNEL_OPT
33 1.21 martin #include "opt_pfil_hooks.h"
34 1.22 martin #endif
35 1.1 mrg
36 1.10 darrenr #include <sys/queue.h>
37 1.15 thorpej #include <net/dlt.h>
38 1.19 itojun #include <sys/null.h>
39 1.1 mrg
40 1.10 darrenr struct mbuf;
41 1.10 darrenr struct ifnet;
42 1.1 mrg
43 1.1 mrg /*
44 1.1 mrg * The packet filter hooks are designed for anything to call them to
45 1.1 mrg * possibly intercept the packet.
46 1.1 mrg */
47 1.1 mrg struct packet_filter_hook {
48 1.9 mrg TAILQ_ENTRY(packet_filter_hook) pfil_link;
49 1.14 thorpej int (*pfil_func)(void *, struct mbuf **, struct ifnet *, int);
50 1.14 thorpej void *pfil_arg;
51 1.1 mrg int pfil_flags;
52 1.1 mrg };
53 1.1 mrg
54 1.1 mrg #define PFIL_IN 0x00000001
55 1.1 mrg #define PFIL_OUT 0x00000002
56 1.23 itojun #define PFIL_ALL (PFIL_IN|PFIL_OUT)
57 1.10 darrenr #define PFIL_WAITOK 0x00000004
58 1.23 itojun #define PFIL_IFADDR 0x00000008
59 1.24 yamt #define PFIL_IFNET 0x00000010
60 1.24 yamt
61 1.24 yamt /* events notified by PFIL_IFNET */
62 1.24 yamt #define PFIL_IFNET_ATTACH 0
63 1.24 yamt #define PFIL_IFNET_DETACH 1
64 1.1 mrg
65 1.10 darrenr typedef TAILQ_HEAD(pfil_list, packet_filter_hook) pfil_list_t;
66 1.10 darrenr
67 1.18 thorpej #define PFIL_TYPE_AF 1 /* key is AF_* type */
68 1.18 thorpej #define PFIL_TYPE_IFNET 2 /* key is ifnet pointer */
69 1.18 thorpej
70 1.10 darrenr struct pfil_head {
71 1.10 darrenr pfil_list_t ph_in;
72 1.10 darrenr pfil_list_t ph_out;
73 1.23 itojun pfil_list_t ph_ifaddr;
74 1.24 yamt pfil_list_t ph_ifnetevent; /* XXX naming collision */
75 1.18 thorpej int ph_type;
76 1.18 thorpej union {
77 1.30 dholland unsigned long phu_val;
78 1.18 thorpej void *phu_ptr;
79 1.18 thorpej } ph_un;
80 1.18 thorpej #define ph_af ph_un.phu_val
81 1.18 thorpej #define ph_ifnet ph_un.phu_ptr
82 1.14 thorpej LIST_ENTRY(pfil_head) ph_list;
83 1.13 itojun };
84 1.13 itojun typedef struct pfil_head pfil_head_t;
85 1.10 darrenr
86 1.27 perry #ifdef _KERNEL
87 1.27 perry
88 1.14 thorpej int pfil_run_hooks(struct pfil_head *, struct mbuf **, struct ifnet *,
89 1.14 thorpej int);
90 1.14 thorpej
91 1.14 thorpej int pfil_add_hook(int (*func)(void *, struct mbuf **,
92 1.14 thorpej struct ifnet *, int), void *, int, struct pfil_head *);
93 1.14 thorpej int pfil_remove_hook(int (*func)(void *, struct mbuf **,
94 1.14 thorpej struct ifnet *, int), void *, int, struct pfil_head *);
95 1.14 thorpej
96 1.14 thorpej int pfil_head_register(struct pfil_head *);
97 1.14 thorpej int pfil_head_unregister(struct pfil_head *);
98 1.14 thorpej
99 1.30 dholland struct pfil_head *pfil_head_get(int, unsigned long);
100 1.14 thorpej
101 1.28 perry static __inline struct packet_filter_hook *
102 1.14 thorpej pfil_hook_get(int dir, struct pfil_head *ph)
103 1.14 thorpej {
104 1.14 thorpej
105 1.14 thorpej if (dir == PFIL_IN)
106 1.14 thorpej return (TAILQ_FIRST(&ph->ph_in));
107 1.14 thorpej else if (dir == PFIL_OUT)
108 1.14 thorpej return (TAILQ_FIRST(&ph->ph_out));
109 1.23 itojun else if (dir == PFIL_IFADDR)
110 1.23 itojun return (TAILQ_FIRST(&ph->ph_ifaddr));
111 1.24 yamt else if (dir == PFIL_IFNET)
112 1.24 yamt return (TAILQ_FIRST(&ph->ph_ifnetevent));
113 1.14 thorpej else
114 1.14 thorpej return (NULL);
115 1.14 thorpej }
116 1.4 mrg
117 1.27 perry #endif /* _KERNEL */
118 1.27 perry
119 1.4 mrg /* XXX */
120 1.20 mrg #if defined(_KERNEL_OPT)
121 1.4 mrg #include "ipfilter.h"
122 1.5 scottr #endif
123 1.4 mrg
124 1.4 mrg #if NIPFILTER > 0
125 1.6 scottr #ifdef PFIL_HOOKS
126 1.6 scottr #undef PFIL_HOOKS
127 1.6 scottr #endif
128 1.4 mrg #define PFIL_HOOKS
129 1.4 mrg #endif /* NIPFILTER */
130 1.1 mrg
131 1.23 itojun #ifdef _KERNEL
132 1.23 itojun /* in sys/net/if.c */
133 1.23 itojun extern struct pfil_head if_pfil; /* packet filtering hook for interfaces */
134 1.27 perry #endif /* _KERNEL */
135 1.23 itojun
136 1.25 elad #endif /* !_NET_PFIL_H_ */
137