2006-11-28 18:34:58 -07:00
|
|
|
/*
|
|
|
|
* connection tracking expectations.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef _NF_CONNTRACK_EXPECT_H
|
|
|
|
#define _NF_CONNTRACK_EXPECT_H
|
2015-08-08 13:40:01 -06:00
|
|
|
|
2017-03-16 02:03:34 -06:00
|
|
|
#include <linux/refcount.h>
|
|
|
|
|
2006-11-28 18:34:58 -07:00
|
|
|
#include <net/netfilter/nf_conntrack.h>
|
2015-08-08 13:40:01 -06:00
|
|
|
#include <net/netfilter/nf_conntrack_zones.h>
|
2006-11-28 18:34:58 -07:00
|
|
|
|
2007-07-07 23:33:47 -06:00
|
|
|
extern unsigned int nf_ct_expect_hsize;
|
2007-07-07 23:36:24 -06:00
|
|
|
extern unsigned int nf_ct_expect_max;
|
2016-05-05 16:51:49 -06:00
|
|
|
extern struct hlist_head *nf_ct_expect_hash;
|
2006-11-28 18:34:58 -07:00
|
|
|
|
2009-11-02 20:26:03 -07:00
|
|
|
struct nf_conntrack_expect {
|
2007-07-07 23:35:56 -06:00
|
|
|
/* Conntrack expectation list member */
|
|
|
|
struct hlist_node lnode;
|
2006-11-28 18:34:58 -07:00
|
|
|
|
2007-07-07 23:33:47 -06:00
|
|
|
/* Hash member */
|
|
|
|
struct hlist_node hnode;
|
|
|
|
|
2006-11-28 18:34:58 -07:00
|
|
|
/* We expect this tuple, with the following mask */
|
2007-07-07 23:31:32 -06:00
|
|
|
struct nf_conntrack_tuple tuple;
|
|
|
|
struct nf_conntrack_tuple_mask mask;
|
2006-11-28 18:34:58 -07:00
|
|
|
|
|
|
|
/* Function to call after setup and insertion */
|
|
|
|
void (*expectfn)(struct nf_conn *new,
|
|
|
|
struct nf_conntrack_expect *this);
|
|
|
|
|
2006-12-02 23:05:25 -07:00
|
|
|
/* Helper to assign to new connection */
|
|
|
|
struct nf_conntrack_helper *helper;
|
|
|
|
|
2006-11-28 18:34:58 -07:00
|
|
|
/* The conntrack of the master connection */
|
|
|
|
struct nf_conn *master;
|
|
|
|
|
|
|
|
/* Timer function; deletes the expectation. */
|
|
|
|
struct timer_list timeout;
|
|
|
|
|
|
|
|
/* Usage count. */
|
2017-03-16 02:03:34 -06:00
|
|
|
refcount_t use;
|
2006-11-28 18:34:58 -07:00
|
|
|
|
|
|
|
/* Flags */
|
|
|
|
unsigned int flags;
|
|
|
|
|
2008-03-25 21:09:15 -06:00
|
|
|
/* Expectation class */
|
|
|
|
unsigned int class;
|
|
|
|
|
2006-11-28 18:34:58 -07:00
|
|
|
#ifdef CONFIG_NF_NAT_NEEDED
|
2012-08-26 11:14:06 -06:00
|
|
|
union nf_inet_addr saved_addr;
|
2006-11-28 18:34:58 -07:00
|
|
|
/* This is the original per-proto part, used to map the
|
|
|
|
* expected connection the way the recipient expects. */
|
2006-12-02 23:07:13 -07:00
|
|
|
union nf_conntrack_man_proto saved_proto;
|
2006-11-28 18:34:58 -07:00
|
|
|
/* Direction relative to the master connection. */
|
|
|
|
enum ip_conntrack_dir dir;
|
|
|
|
#endif
|
2008-01-31 05:38:19 -07:00
|
|
|
|
|
|
|
struct rcu_head rcu;
|
2006-11-28 18:34:58 -07:00
|
|
|
};
|
|
|
|
|
2008-10-08 03:35:03 -06:00
|
|
|
static inline struct net *nf_ct_exp_net(struct nf_conntrack_expect *exp)
|
|
|
|
{
|
2010-02-11 22:24:46 -07:00
|
|
|
return nf_ct_net(exp->master);
|
2008-10-08 03:35:03 -06:00
|
|
|
}
|
|
|
|
|
2012-01-15 08:34:08 -07:00
|
|
|
#define NF_CT_EXP_POLICY_NAME_LEN 16
|
|
|
|
|
2009-11-02 20:26:03 -07:00
|
|
|
struct nf_conntrack_expect_policy {
|
2008-03-25 21:09:15 -06:00
|
|
|
unsigned int max_expected;
|
|
|
|
unsigned int timeout;
|
2012-01-15 08:34:08 -07:00
|
|
|
char name[NF_CT_EXP_POLICY_NAME_LEN];
|
2008-03-25 21:09:15 -06:00
|
|
|
};
|
|
|
|
|
|
|
|
#define NF_CT_EXPECT_CLASS_DEFAULT 0
|
2017-03-24 07:32:19 -06:00
|
|
|
#define NF_CT_EXPECT_MAX_CNT 255
|
2008-03-25 21:09:15 -06:00
|
|
|
|
2013-01-21 15:10:25 -07:00
|
|
|
int nf_conntrack_expect_pernet_init(struct net *net);
|
|
|
|
void nf_conntrack_expect_pernet_fini(struct net *net);
|
|
|
|
|
|
|
|
int nf_conntrack_expect_init(void);
|
|
|
|
void nf_conntrack_expect_fini(void);
|
2006-11-28 18:34:58 -07:00
|
|
|
|
|
|
|
struct nf_conntrack_expect *
|
2015-08-08 13:40:01 -06:00
|
|
|
__nf_ct_expect_find(struct net *net,
|
|
|
|
const struct nf_conntrack_zone *zone,
|
2010-02-15 10:13:33 -07:00
|
|
|
const struct nf_conntrack_tuple *tuple);
|
2006-11-28 18:34:58 -07:00
|
|
|
|
|
|
|
struct nf_conntrack_expect *
|
2015-08-08 13:40:01 -06:00
|
|
|
nf_ct_expect_find_get(struct net *net,
|
|
|
|
const struct nf_conntrack_zone *zone,
|
2010-02-15 10:13:33 -07:00
|
|
|
const struct nf_conntrack_tuple *tuple);
|
2006-11-28 18:34:58 -07:00
|
|
|
|
|
|
|
struct nf_conntrack_expect *
|
2015-08-08 13:40:01 -06:00
|
|
|
nf_ct_find_expectation(struct net *net,
|
|
|
|
const struct nf_conntrack_zone *zone,
|
2010-02-15 10:13:33 -07:00
|
|
|
const struct nf_conntrack_tuple *tuple);
|
2006-11-28 18:34:58 -07:00
|
|
|
|
2010-10-19 02:19:06 -06:00
|
|
|
void nf_ct_unlink_expect_report(struct nf_conntrack_expect *exp,
|
2013-04-17 00:47:08 -06:00
|
|
|
u32 portid, int report);
|
2010-10-19 02:19:06 -06:00
|
|
|
static inline void nf_ct_unlink_expect(struct nf_conntrack_expect *exp)
|
|
|
|
{
|
|
|
|
nf_ct_unlink_expect_report(exp, 0, 0);
|
|
|
|
}
|
|
|
|
|
2006-11-28 18:34:58 -07:00
|
|
|
void nf_ct_remove_expectations(struct nf_conn *ct);
|
2007-07-07 23:30:49 -06:00
|
|
|
void nf_ct_unexpect_related(struct nf_conntrack_expect *exp);
|
2017-03-26 20:31:26 -06:00
|
|
|
bool nf_ct_remove_expect(struct nf_conntrack_expect *exp);
|
2006-11-28 18:34:58 -07:00
|
|
|
|
|
|
|
/* Allocate space for an expectation: this is mandatory before calling
|
2007-07-07 23:30:49 -06:00
|
|
|
nf_ct_expect_related. You will have to call put afterwards. */
|
|
|
|
struct nf_conntrack_expect *nf_ct_expect_alloc(struct nf_conn *me);
|
2008-10-08 03:35:00 -06:00
|
|
|
void nf_ct_expect_init(struct nf_conntrack_expect *, unsigned int, u_int8_t,
|
2008-03-25 21:07:58 -06:00
|
|
|
const union nf_inet_addr *,
|
|
|
|
const union nf_inet_addr *,
|
|
|
|
u_int8_t, const __be16 *, const __be16 *);
|
2007-07-07 23:30:49 -06:00
|
|
|
void nf_ct_expect_put(struct nf_conntrack_expect *exp);
|
2008-11-18 03:56:20 -07:00
|
|
|
int nf_ct_expect_related_report(struct nf_conntrack_expect *expect,
|
2013-04-17 00:47:08 -06:00
|
|
|
u32 portid, int report);
|
2009-04-06 09:47:20 -06:00
|
|
|
static inline int nf_ct_expect_related(struct nf_conntrack_expect *expect)
|
|
|
|
{
|
|
|
|
return nf_ct_expect_related_report(expect, 0, 0);
|
|
|
|
}
|
2006-11-28 18:34:58 -07:00
|
|
|
|
|
|
|
#endif /*_NF_CONNTRACK_EXPECT_H*/
|
|
|
|
|