1*199767f8SToomas Soome /*-
2*199767f8SToomas Soome  * Copyright (c) 1982, 1986, 1993
3*199767f8SToomas Soome  *	The Regents of the University of California.  All rights reserved.
4*199767f8SToomas Soome  *
5*199767f8SToomas Soome  * Redistribution and use in source and binary forms, with or without
6*199767f8SToomas Soome  * modification, are permitted provided that the following conditions
7*199767f8SToomas Soome  * are met:
8*199767f8SToomas Soome  * 1. Redistributions of source code must retain the above copyright
9*199767f8SToomas Soome  *    notice, this list of conditions and the following disclaimer.
10*199767f8SToomas Soome  * 2. Redistributions in binary form must reproduce the above copyright
11*199767f8SToomas Soome  *    notice, this list of conditions and the following disclaimer in the
12*199767f8SToomas Soome  *    documentation and/or other materials provided with the distribution.
13*199767f8SToomas Soome  * 4. Neither the name of the University nor the names of its contributors
14*199767f8SToomas Soome  *    may be used to endorse or promote products derived from this software
15*199767f8SToomas Soome  *    without specific prior written permission.
16*199767f8SToomas Soome  *
17*199767f8SToomas Soome  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
18*199767f8SToomas Soome  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19*199767f8SToomas Soome  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20*199767f8SToomas Soome  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
21*199767f8SToomas Soome  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
22*199767f8SToomas Soome  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
23*199767f8SToomas Soome  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24*199767f8SToomas Soome  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25*199767f8SToomas Soome  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
26*199767f8SToomas Soome  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27*199767f8SToomas Soome  * SUCH DAMAGE.
28*199767f8SToomas Soome  *
29*199767f8SToomas Soome  *	@(#)ip_var.h	8.2 (Berkeley) 1/9/95
30*199767f8SToomas Soome  * $FreeBSD$
31*199767f8SToomas Soome  */
32*199767f8SToomas Soome 
33*199767f8SToomas Soome #ifndef _NETINET_IP_VAR_H_
34*199767f8SToomas Soome #define	_NETINET_IP_VAR_H_
35*199767f8SToomas Soome 
36*199767f8SToomas Soome #include <sys/queue.h>
37*199767f8SToomas Soome 
38*199767f8SToomas Soome /*
39*199767f8SToomas Soome  * Overlay for ip header used by other protocols (tcp, udp).
40*199767f8SToomas Soome  */
41*199767f8SToomas Soome struct ipovly {
42*199767f8SToomas Soome 	u_char	ih_x1[9];		/* (unused) */
43*199767f8SToomas Soome 	u_char	ih_pr;			/* protocol */
44*199767f8SToomas Soome 	u_short	ih_len;			/* protocol length */
45*199767f8SToomas Soome 	struct	in_addr ih_src;		/* source internet address */
46*199767f8SToomas Soome 	struct	in_addr ih_dst;		/* destination internet address */
47*199767f8SToomas Soome };
48*199767f8SToomas Soome 
49*199767f8SToomas Soome #ifdef _KERNEL
50*199767f8SToomas Soome /*
51*199767f8SToomas Soome  * Ip reassembly queue structure.  Each fragment
52*199767f8SToomas Soome  * being reassembled is attached to one of these structures.
53*199767f8SToomas Soome  * They are timed out after ipq_ttl drops to 0, and may also
54*199767f8SToomas Soome  * be reclaimed if memory becomes tight.
55*199767f8SToomas Soome  */
56*199767f8SToomas Soome struct ipq {
57*199767f8SToomas Soome 	TAILQ_ENTRY(ipq) ipq_list;	/* to other reass headers */
58*199767f8SToomas Soome 	u_char	ipq_ttl;		/* time for reass q to live */
59*199767f8SToomas Soome 	u_char	ipq_p;			/* protocol of this fragment */
60*199767f8SToomas Soome 	u_short	ipq_id;			/* sequence id for reassembly */
61*199767f8SToomas Soome 	struct mbuf *ipq_frags;		/* to ip headers of fragments */
62*199767f8SToomas Soome 	struct	in_addr ipq_src,ipq_dst;
63*199767f8SToomas Soome 	u_char	ipq_nfrags;		/* # frags in this packet */
64*199767f8SToomas Soome 	struct label *ipq_label;	/* MAC label */
65*199767f8SToomas Soome };
66*199767f8SToomas Soome #endif /* _KERNEL */
67*199767f8SToomas Soome 
68*199767f8SToomas Soome /*
69*199767f8SToomas Soome  * Structure stored in mbuf in inpcb.ip_options
70*199767f8SToomas Soome  * and passed to ip_output when ip options are in use.
71*199767f8SToomas Soome  * The actual length of the options (including ipopt_dst)
72*199767f8SToomas Soome  * is in m_len.
73*199767f8SToomas Soome  */
74*199767f8SToomas Soome #define MAX_IPOPTLEN	40
75*199767f8SToomas Soome 
76*199767f8SToomas Soome struct ipoption {
77*199767f8SToomas Soome 	struct	in_addr ipopt_dst;	/* first-hop dst if source routed */
78*199767f8SToomas Soome 	char	ipopt_list[MAX_IPOPTLEN];	/* options proper */
79*199767f8SToomas Soome };
80*199767f8SToomas Soome 
81*199767f8SToomas Soome /*
82*199767f8SToomas Soome  * Structure attached to inpcb.ip_moptions and
83*199767f8SToomas Soome  * passed to ip_output when IP multicast options are in use.
84*199767f8SToomas Soome  * This structure is lazy-allocated.
85*199767f8SToomas Soome  */
86*199767f8SToomas Soome struct ip_moptions {
87*199767f8SToomas Soome 	struct	ifnet *imo_multicast_ifp; /* ifp for outgoing multicasts */
88*199767f8SToomas Soome 	struct in_addr imo_multicast_addr; /* ifindex/addr on MULTICAST_IF */
89*199767f8SToomas Soome 	u_long	imo_multicast_vif;	/* vif num outgoing multicasts */
90*199767f8SToomas Soome 	u_char	imo_multicast_ttl;	/* TTL for outgoing multicasts */
91*199767f8SToomas Soome 	u_char	imo_multicast_loop;	/* 1 => hear sends if a member */
92*199767f8SToomas Soome 	u_short	imo_num_memberships;	/* no. memberships this socket */
93*199767f8SToomas Soome 	u_short	imo_max_memberships;	/* max memberships this socket */
94*199767f8SToomas Soome 	struct	in_multi **imo_membership;	/* group memberships */
95*199767f8SToomas Soome 	struct	in_mfilter *imo_mfilters;	/* source filters */
96*199767f8SToomas Soome 	STAILQ_ENTRY(ip_moptions) imo_link;
97*199767f8SToomas Soome };
98*199767f8SToomas Soome 
99*199767f8SToomas Soome struct	ipstat {
100*199767f8SToomas Soome 	uint64_t ips_total;		/* total packets received */
101*199767f8SToomas Soome 	uint64_t ips_badsum;		/* checksum bad */
102*199767f8SToomas Soome 	uint64_t ips_tooshort;		/* packet too short */
103*199767f8SToomas Soome 	uint64_t ips_toosmall;		/* not enough data */
104*199767f8SToomas Soome 	uint64_t ips_badhlen;		/* ip header length < data size */
105*199767f8SToomas Soome 	uint64_t ips_badlen;		/* ip length < ip header length */
106*199767f8SToomas Soome 	uint64_t ips_fragments;		/* fragments received */
107*199767f8SToomas Soome 	uint64_t ips_fragdropped;	/* frags dropped (dups, out of space) */
108*199767f8SToomas Soome 	uint64_t ips_fragtimeout;	/* fragments timed out */
109*199767f8SToomas Soome 	uint64_t ips_forward;		/* packets forwarded */
110*199767f8SToomas Soome 	uint64_t ips_fastforward;	/* packets fast forwarded */
111*199767f8SToomas Soome 	uint64_t ips_cantforward;	/* packets rcvd for unreachable dest */
112*199767f8SToomas Soome 	uint64_t ips_redirectsent;	/* packets forwarded on same net */
113*199767f8SToomas Soome 	uint64_t ips_noproto;		/* unknown or unsupported protocol */
114*199767f8SToomas Soome 	uint64_t ips_delivered;		/* datagrams delivered to upper level*/
115*199767f8SToomas Soome 	uint64_t ips_localout;		/* total ip packets generated here */
116*199767f8SToomas Soome 	uint64_t ips_odropped;		/* lost packets due to nobufs, etc. */
117*199767f8SToomas Soome 	uint64_t ips_reassembled;	/* total packets reassembled ok */
118*199767f8SToomas Soome 	uint64_t ips_fragmented;	/* datagrams successfully fragmented */
119*199767f8SToomas Soome 	uint64_t ips_ofragments;	/* output fragments created */
120*199767f8SToomas Soome 	uint64_t ips_cantfrag;		/* don't fragment flag was set, etc. */
121*199767f8SToomas Soome 	uint64_t ips_badoptions;		/* error in option processing */
122*199767f8SToomas Soome 	uint64_t ips_noroute;		/* packets discarded due to no route */
123*199767f8SToomas Soome 	uint64_t ips_badvers;		/* ip version != 4 */
124*199767f8SToomas Soome 	uint64_t ips_rawout;		/* total raw ip packets generated */
125*199767f8SToomas Soome 	uint64_t ips_toolong;		/* ip length > max ip packet size */
126*199767f8SToomas Soome 	uint64_t ips_notmember;		/* multicasts for unregistered grps */
127*199767f8SToomas Soome 	uint64_t ips_nogif;		/* no match gif found */
128*199767f8SToomas Soome 	uint64_t ips_badaddr;		/* invalid address on header */
129*199767f8SToomas Soome };
130*199767f8SToomas Soome 
131*199767f8SToomas Soome #ifdef _KERNEL
132*199767f8SToomas Soome 
133*199767f8SToomas Soome #include <sys/counter.h>
134*199767f8SToomas Soome #include <net/vnet.h>
135*199767f8SToomas Soome 
136*199767f8SToomas Soome VNET_PCPUSTAT_DECLARE(struct ipstat, ipstat);
137*199767f8SToomas Soome /*
138*199767f8SToomas Soome  * In-kernel consumers can use these accessor macros directly to update
139*199767f8SToomas Soome  * stats.
140*199767f8SToomas Soome  */
141*199767f8SToomas Soome #define	IPSTAT_ADD(name, val)	\
142*199767f8SToomas Soome     VNET_PCPUSTAT_ADD(struct ipstat, ipstat, name, (val))
143*199767f8SToomas Soome #define	IPSTAT_SUB(name, val)	IPSTAT_ADD(name, -(val))
144*199767f8SToomas Soome #define	IPSTAT_INC(name)	IPSTAT_ADD(name, 1)
145*199767f8SToomas Soome #define	IPSTAT_DEC(name)	IPSTAT_SUB(name, 1)
146*199767f8SToomas Soome 
147*199767f8SToomas Soome /*
148*199767f8SToomas Soome  * Kernel module consumers must use this accessor macro.
149*199767f8SToomas Soome  */
150*199767f8SToomas Soome void	kmod_ipstat_inc(int statnum);
151*199767f8SToomas Soome #define	KMOD_IPSTAT_INC(name)	\
152*199767f8SToomas Soome     kmod_ipstat_inc(offsetof(struct ipstat, name) / sizeof(uint64_t))
153*199767f8SToomas Soome void	kmod_ipstat_dec(int statnum);
154*199767f8SToomas Soome #define	KMOD_IPSTAT_DEC(name)	\
155*199767f8SToomas Soome     kmod_ipstat_dec(offsetof(struct ipstat, name) / sizeof(uint64_t))
156*199767f8SToomas Soome 
157*199767f8SToomas Soome /* flags passed to ip_output as last parameter */
158*199767f8SToomas Soome #define	IP_FORWARDING		0x1		/* most of ip header exists */
159*199767f8SToomas Soome #define	IP_RAWOUTPUT		0x2		/* raw ip header exists */
160*199767f8SToomas Soome #define	IP_SENDONES		0x4		/* send all-ones broadcast */
161*199767f8SToomas Soome #define	IP_SENDTOIF		0x8		/* send on specific ifnet */
162*199767f8SToomas Soome #define IP_ROUTETOIF		SO_DONTROUTE	/* 0x10 bypass routing tables */
163*199767f8SToomas Soome #define IP_ALLOWBROADCAST	SO_BROADCAST	/* 0x20 can send broadcast packets */
164*199767f8SToomas Soome #define	IP_NODEFAULTFLOWID	0x40		/* Don't set the flowid from inp */
165*199767f8SToomas Soome 
166*199767f8SToomas Soome #ifdef __NO_STRICT_ALIGNMENT
167*199767f8SToomas Soome #define IP_HDR_ALIGNED_P(ip)	1
168*199767f8SToomas Soome #else
169*199767f8SToomas Soome #define IP_HDR_ALIGNED_P(ip)	((((intptr_t) (ip)) & 3) == 0)
170*199767f8SToomas Soome #endif
171*199767f8SToomas Soome 
172*199767f8SToomas Soome struct ip;
173*199767f8SToomas Soome struct inpcb;
174*199767f8SToomas Soome struct route;
175*199767f8SToomas Soome struct sockopt;
176*199767f8SToomas Soome 
177*199767f8SToomas Soome VNET_DECLARE(int, ip_defttl);			/* default IP ttl */
178*199767f8SToomas Soome VNET_DECLARE(int, ipforwarding);		/* ip forwarding */
179*199767f8SToomas Soome #ifdef IPSTEALTH
180*199767f8SToomas Soome VNET_DECLARE(int, ipstealth);			/* stealth forwarding */
181*199767f8SToomas Soome #endif
182*199767f8SToomas Soome extern u_char	ip_protox[];
183*199767f8SToomas Soome VNET_DECLARE(struct socket *, ip_rsvpd);	/* reservation protocol daemon*/
184*199767f8SToomas Soome VNET_DECLARE(struct socket *, ip_mrouter);	/* multicast routing daemon */
185*199767f8SToomas Soome extern int	(*legal_vif_num)(int);
186*199767f8SToomas Soome extern u_long	(*ip_mcast_src)(int);
187*199767f8SToomas Soome VNET_DECLARE(int, rsvp_on);
188*199767f8SToomas Soome VNET_DECLARE(int, drop_redirect);
189*199767f8SToomas Soome extern struct	pr_usrreqs rip_usrreqs;
190*199767f8SToomas Soome 
191*199767f8SToomas Soome #define	V_ip_id			VNET(ip_id)
192*199767f8SToomas Soome #define	V_ip_defttl		VNET(ip_defttl)
193*199767f8SToomas Soome #define	V_ipforwarding		VNET(ipforwarding)
194*199767f8SToomas Soome #ifdef IPSTEALTH
195*199767f8SToomas Soome #define	V_ipstealth		VNET(ipstealth)
196*199767f8SToomas Soome #endif
197*199767f8SToomas Soome #define	V_ip_rsvpd		VNET(ip_rsvpd)
198*199767f8SToomas Soome #define	V_ip_mrouter		VNET(ip_mrouter)
199*199767f8SToomas Soome #define	V_rsvp_on		VNET(rsvp_on)
200*199767f8SToomas Soome #define	V_drop_redirect		VNET(drop_redirect)
201*199767f8SToomas Soome 
202*199767f8SToomas Soome void	inp_freemoptions(struct ip_moptions *);
203*199767f8SToomas Soome int	inp_getmoptions(struct inpcb *, struct sockopt *);
204*199767f8SToomas Soome int	inp_setmoptions(struct inpcb *, struct sockopt *);
205*199767f8SToomas Soome 
206*199767f8SToomas Soome int	ip_ctloutput(struct socket *, struct sockopt *sopt);
207*199767f8SToomas Soome void	ip_drain(void);
208*199767f8SToomas Soome int	ip_fragment(struct ip *ip, struct mbuf **m_frag, int mtu,
209*199767f8SToomas Soome 	    u_long if_hwassist_flags);
210*199767f8SToomas Soome void	ip_forward(struct mbuf *m, int srcrt);
211*199767f8SToomas Soome void	ip_init(void);
212*199767f8SToomas Soome #ifdef VIMAGE
213*199767f8SToomas Soome void	ip_destroy(void);
214*199767f8SToomas Soome #endif
215*199767f8SToomas Soome extern int
216*199767f8SToomas Soome 	(*ip_mforward)(struct ip *, struct ifnet *, struct mbuf *,
217*199767f8SToomas Soome 	    struct ip_moptions *);
218*199767f8SToomas Soome int	ip_output(struct mbuf *,
219*199767f8SToomas Soome 	    struct mbuf *, struct route *, int, struct ip_moptions *,
220*199767f8SToomas Soome 	    struct inpcb *);
221*199767f8SToomas Soome int	ipproto_register(short);
222*199767f8SToomas Soome int	ipproto_unregister(short);
223*199767f8SToomas Soome struct mbuf *
224*199767f8SToomas Soome 	ip_reass(struct mbuf *);
225*199767f8SToomas Soome struct in_ifaddr *
226*199767f8SToomas Soome 	ip_rtaddr(struct in_addr, u_int fibnum);
227*199767f8SToomas Soome void	ip_savecontrol(struct inpcb *, struct mbuf **, struct ip *,
228*199767f8SToomas Soome 	    struct mbuf *);
229*199767f8SToomas Soome void	ip_slowtimo(void);
230*199767f8SToomas Soome void	ip_fillid(struct ip *);
231*199767f8SToomas Soome int	rip_ctloutput(struct socket *, struct sockopt *);
232*199767f8SToomas Soome void	rip_ctlinput(int, struct sockaddr *, void *);
233*199767f8SToomas Soome void	rip_init(void);
234*199767f8SToomas Soome #ifdef VIMAGE
235*199767f8SToomas Soome void	rip_destroy(void);
236*199767f8SToomas Soome #endif
237*199767f8SToomas Soome int	rip_input(struct mbuf **, int *, int);
238*199767f8SToomas Soome int	rip_output(struct mbuf *, struct socket *, ...);
239*199767f8SToomas Soome int	ipip_input(struct mbuf **, int *, int);
240*199767f8SToomas Soome int	rsvp_input(struct mbuf **, int *, int);
241*199767f8SToomas Soome int	ip_rsvp_init(struct socket *);
242*199767f8SToomas Soome int	ip_rsvp_done(void);
243*199767f8SToomas Soome extern int	(*ip_rsvp_vif)(struct socket *, struct sockopt *);
244*199767f8SToomas Soome extern void	(*ip_rsvp_force_done)(struct socket *);
245*199767f8SToomas Soome extern int	(*rsvp_input_p)(struct mbuf **, int *, int);
246*199767f8SToomas Soome 
247*199767f8SToomas Soome VNET_DECLARE(struct pfil_head, inet_pfil_hook);	/* packet filter hooks */
248*199767f8SToomas Soome #define	V_inet_pfil_hook	VNET(inet_pfil_hook)
249*199767f8SToomas Soome 
250*199767f8SToomas Soome void	in_delayed_cksum(struct mbuf *m);
251*199767f8SToomas Soome 
252*199767f8SToomas Soome /* Hooks for ipfw, dummynet, divert etc. Most are declared in raw_ip.c */
253*199767f8SToomas Soome /*
254*199767f8SToomas Soome  * Reference to an ipfw or packet filter rule that can be carried
255*199767f8SToomas Soome  * outside critical sections.
256*199767f8SToomas Soome  * A rule is identified by rulenum:rule_id which is ordered.
257*199767f8SToomas Soome  * In version chain_id the rule can be found in slot 'slot', so
258*199767f8SToomas Soome  * we don't need a lookup if chain_id == chain->id.
259*199767f8SToomas Soome  *
260*199767f8SToomas Soome  * On exit from the firewall this structure refers to the rule after
261*199767f8SToomas Soome  * the matching one (slot points to the new rule; rulenum:rule_id-1
262*199767f8SToomas Soome  * is the matching rule), and additional info (e.g. info often contains
263*199767f8SToomas Soome  * the insn argument or tablearg in the low 16 bits, in host format).
264*199767f8SToomas Soome  * On entry, the structure is valid if slot>0, and refers to the starting
265*199767f8SToomas Soome  * rules. 'info' contains the reason for reinject, e.g. divert port,
266*199767f8SToomas Soome  * divert direction, and so on.
267*199767f8SToomas Soome  */
268*199767f8SToomas Soome struct ipfw_rule_ref {
269*199767f8SToomas Soome 	uint32_t	slot;		/* slot for matching rule	*/
270*199767f8SToomas Soome 	uint32_t	rulenum;	/* matching rule number		*/
271*199767f8SToomas Soome 	uint32_t	rule_id;	/* matching rule id		*/
272*199767f8SToomas Soome 	uint32_t	chain_id;	/* ruleset id			*/
273*199767f8SToomas Soome 	uint32_t	info;		/* see below			*/
274*199767f8SToomas Soome };
275*199767f8SToomas Soome 
276*199767f8SToomas Soome enum {
277*199767f8SToomas Soome 	IPFW_INFO_MASK	= 0x0000ffff,
278*199767f8SToomas Soome 	IPFW_INFO_OUT	= 0x00000000,	/* outgoing, just for convenience */
279*199767f8SToomas Soome 	IPFW_INFO_IN	= 0x80000000,	/* incoming, overloads dir */
280*199767f8SToomas Soome 	IPFW_ONEPASS	= 0x40000000,	/* One-pass, do not reinject */
281*199767f8SToomas Soome 	IPFW_IS_MASK	= 0x30000000,	/* which source ? */
282*199767f8SToomas Soome 	IPFW_IS_DIVERT	= 0x20000000,
283*199767f8SToomas Soome 	IPFW_IS_DUMMYNET =0x10000000,
284*199767f8SToomas Soome 	IPFW_IS_PIPE	= 0x08000000,	/* pipe=1, queue = 0 */
285*199767f8SToomas Soome };
286*199767f8SToomas Soome #define MTAG_IPFW	1148380143	/* IPFW-tagged cookie */
287*199767f8SToomas Soome #define MTAG_IPFW_RULE	1262273568	/* rule reference */
288*199767f8SToomas Soome #define	MTAG_IPFW_CALL	1308397630	/* call stack */
289*199767f8SToomas Soome 
290*199767f8SToomas Soome struct ip_fw_args;
291*199767f8SToomas Soome typedef int	(*ip_fw_chk_ptr_t)(struct ip_fw_args *args);
292*199767f8SToomas Soome typedef int	(*ip_fw_ctl_ptr_t)(struct sockopt *);
293*199767f8SToomas Soome VNET_DECLARE(ip_fw_ctl_ptr_t, ip_fw_ctl_ptr);
294*199767f8SToomas Soome #define	V_ip_fw_ctl_ptr		VNET(ip_fw_ctl_ptr)
295*199767f8SToomas Soome 
296*199767f8SToomas Soome /* Divert hooks. */
297*199767f8SToomas Soome extern void	(*ip_divert_ptr)(struct mbuf *m, int incoming);
298*199767f8SToomas Soome /* ng_ipfw hooks -- XXX make it the same as divert and dummynet */
299*199767f8SToomas Soome extern int	(*ng_ipfw_input_p)(struct mbuf **, int,
300*199767f8SToomas Soome 			struct ip_fw_args *, int);
301*199767f8SToomas Soome 
302*199767f8SToomas Soome extern int	(*ip_dn_ctl_ptr)(struct sockopt *);
303*199767f8SToomas Soome extern int	(*ip_dn_io_ptr)(struct mbuf **, int, struct ip_fw_args *);
304*199767f8SToomas Soome #endif /* _KERNEL */
305*199767f8SToomas Soome 
306*199767f8SToomas Soome #endif /* !_NETINET_IP_VAR_H_ */
307