]>
Commit | Line | Data |
---|---|---|
77ab9cff MJ |
1 | /* |
2 | * connection tracking expectations. | |
3 | */ | |
4 | ||
5 | #ifndef _NF_CONNTRACK_EXPECT_H | |
6 | #define _NF_CONNTRACK_EXPECT_H | |
7 | #include <net/netfilter/nf_conntrack.h> | |
8 | ||
a71c0855 | 9 | extern unsigned int nf_ct_expect_hsize; |
f264a7df | 10 | extern unsigned int nf_ct_expect_max; |
77ab9cff | 11 | |
fd2c3ef7 | 12 | struct nf_conntrack_expect { |
b560580a PM |
13 | /* Conntrack expectation list member */ |
14 | struct hlist_node lnode; | |
77ab9cff | 15 | |
a71c0855 PM |
16 | /* Hash member */ |
17 | struct hlist_node hnode; | |
18 | ||
77ab9cff | 19 | /* We expect this tuple, with the following mask */ |
d4156e8c PM |
20 | struct nf_conntrack_tuple tuple; |
21 | struct nf_conntrack_tuple_mask mask; | |
77ab9cff MJ |
22 | |
23 | /* Function to call after setup and insertion */ | |
24 | void (*expectfn)(struct nf_conn *new, | |
25 | struct nf_conntrack_expect *this); | |
26 | ||
9457d851 PM |
27 | /* Helper to assign to new connection */ |
28 | struct nf_conntrack_helper *helper; | |
29 | ||
77ab9cff MJ |
30 | /* The conntrack of the master connection */ |
31 | struct nf_conn *master; | |
32 | ||
33 | /* Timer function; deletes the expectation. */ | |
34 | struct timer_list timeout; | |
35 | ||
36 | /* Usage count. */ | |
37 | atomic_t use; | |
38 | ||
77ab9cff MJ |
39 | /* Flags */ |
40 | unsigned int flags; | |
41 | ||
6002f266 PM |
42 | /* Expectation class */ |
43 | unsigned int class; | |
44 | ||
77ab9cff | 45 | #ifdef CONFIG_NF_NAT_NEEDED |
f587de0e | 46 | __be32 saved_ip; |
77ab9cff MJ |
47 | /* This is the original per-proto part, used to map the |
48 | * expected connection the way the recipient expects. */ | |
5b1158e9 | 49 | union nf_conntrack_man_proto saved_proto; |
77ab9cff MJ |
50 | /* Direction relative to the master connection. */ |
51 | enum ip_conntrack_dir dir; | |
52 | #endif | |
7d0742da PM |
53 | |
54 | struct rcu_head rcu; | |
77ab9cff MJ |
55 | }; |
56 | ||
9b03f38d AD |
57 | static inline struct net *nf_ct_exp_net(struct nf_conntrack_expect *exp) |
58 | { | |
59 | #ifdef CONFIG_NET_NS | |
60 | return exp->master->ct_net; /* by definition */ | |
61 | #else | |
62 | return &init_net; | |
63 | #endif | |
64 | } | |
65 | ||
fd2c3ef7 | 66 | struct nf_conntrack_expect_policy { |
6002f266 PM |
67 | unsigned int max_expected; |
68 | unsigned int timeout; | |
b87921bd | 69 | const char *name; |
6002f266 PM |
70 | }; |
71 | ||
72 | #define NF_CT_EXPECT_CLASS_DEFAULT 0 | |
73 | ||
359b9ab6 PM |
74 | #define NF_CT_EXPECT_PERMANENT 0x1 |
75 | #define NF_CT_EXPECT_INACTIVE 0x2 | |
77ab9cff | 76 | |
9b03f38d AD |
77 | int nf_conntrack_expect_init(struct net *net); |
78 | void nf_conntrack_expect_fini(struct net *net); | |
77ab9cff MJ |
79 | |
80 | struct nf_conntrack_expect * | |
9b03f38d | 81 | __nf_ct_expect_find(struct net *net, const struct nf_conntrack_tuple *tuple); |
77ab9cff MJ |
82 | |
83 | struct nf_conntrack_expect * | |
9b03f38d | 84 | nf_ct_expect_find_get(struct net *net, const struct nf_conntrack_tuple *tuple); |
77ab9cff MJ |
85 | |
86 | struct nf_conntrack_expect * | |
9b03f38d | 87 | nf_ct_find_expectation(struct net *net, const struct nf_conntrack_tuple *tuple); |
77ab9cff MJ |
88 | |
89 | void nf_ct_unlink_expect(struct nf_conntrack_expect *exp); | |
90 | void nf_ct_remove_expectations(struct nf_conn *ct); | |
6823645d | 91 | void nf_ct_unexpect_related(struct nf_conntrack_expect *exp); |
77ab9cff MJ |
92 | |
93 | /* Allocate space for an expectation: this is mandatory before calling | |
6823645d PM |
94 | nf_ct_expect_related. You will have to call put afterwards. */ |
95 | struct nf_conntrack_expect *nf_ct_expect_alloc(struct nf_conn *me); | |
76108cea | 96 | void nf_ct_expect_init(struct nf_conntrack_expect *, unsigned int, u_int8_t, |
1d9d7522 PM |
97 | const union nf_inet_addr *, |
98 | const union nf_inet_addr *, | |
99 | u_int8_t, const __be16 *, const __be16 *); | |
6823645d | 100 | void nf_ct_expect_put(struct nf_conntrack_expect *exp); |
19abb7b0 PNA |
101 | int nf_ct_expect_related_report(struct nf_conntrack_expect *expect, |
102 | u32 pid, int report); | |
83731671 PNA |
103 | static inline int nf_ct_expect_related(struct nf_conntrack_expect *expect) |
104 | { | |
105 | return nf_ct_expect_related_report(expect, 0, 0); | |
106 | } | |
77ab9cff MJ |
107 | |
108 | #endif /*_NF_CONNTRACK_EXPECT_H*/ | |
109 |