2006-11-29 01:34:58 +00:00
|
|
|
/*
|
|
|
|
* connection tracking expectations.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef _NF_CONNTRACK_EXPECT_H
|
|
|
|
#define _NF_CONNTRACK_EXPECT_H
|
|
|
|
#include <net/netfilter/nf_conntrack.h>
|
|
|
|
|
2007-07-08 05:33:47 +00:00
|
|
|
extern unsigned int nf_ct_expect_hsize;
|
2007-07-08 05:36:24 +00:00
|
|
|
extern unsigned int nf_ct_expect_max;
|
2006-11-29 01:34:58 +00:00
|
|
|
|
2009-11-03 03:26:03 +00:00
|
|
|
struct nf_conntrack_expect {
|
2007-07-08 05:35:56 +00:00
|
|
|
/* Conntrack expectation list member */
|
|
|
|
struct hlist_node lnode;
|
2006-11-29 01:34:58 +00:00
|
|
|
|
2007-07-08 05:33:47 +00:00
|
|
|
/* Hash member */
|
|
|
|
struct hlist_node hnode;
|
|
|
|
|
2006-11-29 01:34:58 +00:00
|
|
|
/* We expect this tuple, with the following mask */
|
2007-07-08 05:31:32 +00:00
|
|
|
struct nf_conntrack_tuple tuple;
|
|
|
|
struct nf_conntrack_tuple_mask mask;
|
2006-11-29 01:34:58 +00:00
|
|
|
|
|
|
|
/* Function to call after setup and insertion */
|
|
|
|
void (*expectfn)(struct nf_conn *new,
|
|
|
|
struct nf_conntrack_expect *this);
|
|
|
|
|
2006-12-03 06:05:25 +00:00
|
|
|
/* Helper to assign to new connection */
|
|
|
|
struct nf_conntrack_helper *helper;
|
|
|
|
|
2006-11-29 01:34:58 +00:00
|
|
|
/* The conntrack of the master connection */
|
|
|
|
struct nf_conn *master;
|
|
|
|
|
|
|
|
/* Timer function; deletes the expectation. */
|
|
|
|
struct timer_list timeout;
|
|
|
|
|
|
|
|
/* Usage count. */
|
|
|
|
atomic_t use;
|
|
|
|
|
|
|
|
/* Flags */
|
|
|
|
unsigned int flags;
|
|
|
|
|
2008-03-26 03:09:15 +00:00
|
|
|
/* Expectation class */
|
|
|
|
unsigned int class;
|
|
|
|
|
2006-11-29 01:34:58 +00:00
|
|
|
#ifdef CONFIG_NF_NAT_NEEDED
|
2006-12-03 06:08:46 +00:00
|
|
|
__be32 saved_ip;
|
2006-11-29 01:34:58 +00:00
|
|
|
/* This is the original per-proto part, used to map the
|
|
|
|
* expected connection the way the recipient expects. */
|
2006-12-03 06:07:13 +00:00
|
|
|
union nf_conntrack_man_proto saved_proto;
|
2006-11-29 01:34:58 +00:00
|
|
|
/* Direction relative to the master connection. */
|
|
|
|
enum ip_conntrack_dir dir;
|
|
|
|
#endif
|
2008-01-31 12:38:19 +00:00
|
|
|
|
|
|
|
struct rcu_head rcu;
|
2006-11-29 01:34:58 +00:00
|
|
|
};
|
|
|
|
|
2008-10-08 09:35:03 +00:00
|
|
|
static inline struct net *nf_ct_exp_net(struct nf_conntrack_expect *exp)
|
|
|
|
{
|
2010-02-12 05:24:46 +00:00
|
|
|
return nf_ct_net(exp->master);
|
2008-10-08 09:35:03 +00:00
|
|
|
}
|
|
|
|
|
2009-11-03 03:26:03 +00:00
|
|
|
struct nf_conntrack_expect_policy {
|
2008-03-26 03:09:15 +00:00
|
|
|
unsigned int max_expected;
|
|
|
|
unsigned int timeout;
|
2010-02-11 11:22:48 +00:00
|
|
|
const char *name;
|
2008-03-26 03:09:15 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
#define NF_CT_EXPECT_CLASS_DEFAULT 0
|
|
|
|
|
2008-03-26 03:08:37 +00:00
|
|
|
#define NF_CT_EXPECT_PERMANENT 0x1
|
|
|
|
#define NF_CT_EXPECT_INACTIVE 0x2
|
2006-11-29 01:34:58 +00:00
|
|
|
|
2008-10-08 09:35:03 +00:00
|
|
|
int nf_conntrack_expect_init(struct net *net);
|
|
|
|
void nf_conntrack_expect_fini(struct net *net);
|
2006-11-29 01:34:58 +00:00
|
|
|
|
|
|
|
struct nf_conntrack_expect *
|
2010-02-15 17:13:33 +00:00
|
|
|
__nf_ct_expect_find(struct net *net, u16 zone,
|
|
|
|
const struct nf_conntrack_tuple *tuple);
|
2006-11-29 01:34:58 +00:00
|
|
|
|
|
|
|
struct nf_conntrack_expect *
|
2010-02-15 17:13:33 +00:00
|
|
|
nf_ct_expect_find_get(struct net *net, u16 zone,
|
|
|
|
const struct nf_conntrack_tuple *tuple);
|
2006-11-29 01:34:58 +00:00
|
|
|
|
|
|
|
struct nf_conntrack_expect *
|
2010-02-15 17:13:33 +00:00
|
|
|
nf_ct_find_expectation(struct net *net, u16 zone,
|
|
|
|
const struct nf_conntrack_tuple *tuple);
|
2006-11-29 01:34:58 +00:00
|
|
|
|
|
|
|
void nf_ct_unlink_expect(struct nf_conntrack_expect *exp);
|
|
|
|
void nf_ct_remove_expectations(struct nf_conn *ct);
|
2007-07-08 05:30:49 +00:00
|
|
|
void nf_ct_unexpect_related(struct nf_conntrack_expect *exp);
|
2006-11-29 01:34:58 +00:00
|
|
|
|
|
|
|
/* Allocate space for an expectation: this is mandatory before calling
|
2007-07-08 05:30:49 +00:00
|
|
|
nf_ct_expect_related. You will have to call put afterwards. */
|
|
|
|
struct nf_conntrack_expect *nf_ct_expect_alloc(struct nf_conn *me);
|
2008-10-08 09:35:00 +00:00
|
|
|
void nf_ct_expect_init(struct nf_conntrack_expect *, unsigned int, u_int8_t,
|
2008-03-26 03:07:58 +00:00
|
|
|
const union nf_inet_addr *,
|
|
|
|
const union nf_inet_addr *,
|
|
|
|
u_int8_t, const __be16 *, const __be16 *);
|
2007-07-08 05:30:49 +00:00
|
|
|
void nf_ct_expect_put(struct nf_conntrack_expect *exp);
|
2008-11-18 10:56:20 +00:00
|
|
|
int nf_ct_expect_related_report(struct nf_conntrack_expect *expect,
|
|
|
|
u32 pid, int report);
|
2009-04-06 15:47:20 +00:00
|
|
|
static inline int nf_ct_expect_related(struct nf_conntrack_expect *expect)
|
|
|
|
{
|
|
|
|
return nf_ct_expect_related_report(expect, 0, 0);
|
|
|
|
}
|
2006-11-29 01:34:58 +00:00
|
|
|
|
|
|
|
#endif /*_NF_CONNTRACK_EXPECT_H*/
|
|
|
|
|