2015-11-15 22:07:25 -08:00
|
|
|
/*
|
2017-08-06 10:51:14 -07:00
|
|
|
* Copyright (c) 2015, 2016, 2017 Nicira, Inc.
|
2015-11-15 22:07:25 -08:00
|
|
|
*
|
|
|
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
* you may not use this file except in compliance with the License.
|
|
|
|
* You may obtain a copy of the License at:
|
|
|
|
*
|
|
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
*
|
|
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
|
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
* See the License for the specific language governing permissions and
|
|
|
|
* limitations under the License.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef CONNTRACK_PRIVATE_H
|
|
|
|
#define CONNTRACK_PRIVATE_H 1
|
|
|
|
|
|
|
|
#include <sys/types.h>
|
|
|
|
#include <netinet/in.h>
|
|
|
|
#include <netinet/ip6.h>
|
|
|
|
|
|
|
|
#include "conntrack.h"
|
2015-11-15 22:07:25 -08:00
|
|
|
#include "ct-dpif.h"
|
2015-11-15 22:07:25 -08:00
|
|
|
#include "openvswitch/hmap.h"
|
|
|
|
#include "openvswitch/list.h"
|
|
|
|
#include "openvswitch/types.h"
|
|
|
|
#include "packets.h"
|
|
|
|
#include "unaligned.h"
|
2017-05-30 14:21:33 -07:00
|
|
|
#include "dp-packet.h"
|
2015-11-15 22:07:25 -08:00
|
|
|
|
|
|
|
struct ct_endpoint {
|
|
|
|
struct ct_addr addr;
|
2016-05-13 15:04:17 -07:00
|
|
|
union {
|
|
|
|
ovs_be16 port;
|
|
|
|
struct {
|
|
|
|
ovs_be16 icmp_id;
|
|
|
|
uint8_t icmp_type;
|
|
|
|
uint8_t icmp_code;
|
|
|
|
};
|
|
|
|
};
|
2015-11-15 22:07:25 -08:00
|
|
|
};
|
|
|
|
|
2017-06-09 15:30:43 -07:00
|
|
|
/* Verify that there is no padding in struct ct_endpoint, to facilitate
|
|
|
|
* hashing in ct_endpoint_hash_add(). */
|
|
|
|
BUILD_ASSERT_DECL(sizeof(struct ct_endpoint) == sizeof(struct ct_addr) + 4);
|
|
|
|
|
2017-08-06 10:51:14 -07:00
|
|
|
/* Changes to this structure need to be reflected in conn_key_hash()
|
|
|
|
* and conn_key_cmp(). */
|
2015-11-15 22:07:25 -08:00
|
|
|
struct conn_key {
|
|
|
|
struct ct_endpoint src;
|
|
|
|
struct ct_endpoint dst;
|
|
|
|
|
|
|
|
ovs_be16 dl_type;
|
|
|
|
uint16_t zone;
|
2017-08-06 10:51:14 -07:00
|
|
|
uint8_t nw_proto;
|
2015-11-15 22:07:25 -08:00
|
|
|
};
|
|
|
|
|
2017-05-30 10:49:27 -07:00
|
|
|
struct nat_conn_key_node {
|
|
|
|
struct hmap_node node;
|
|
|
|
struct conn_key key;
|
|
|
|
struct conn_key value;
|
|
|
|
};
|
|
|
|
|
2017-08-06 10:51:14 -07:00
|
|
|
/* This is used for alg expectations; an expectation is a
|
|
|
|
* context created in preparation for establishing a data
|
|
|
|
* connection. The expectation is created by the control
|
|
|
|
* connection. */
|
|
|
|
struct alg_exp_node {
|
2018-01-09 15:44:54 -08:00
|
|
|
/* Node in alg_expectations. */
|
2017-08-06 10:51:14 -07:00
|
|
|
struct hmap_node node;
|
2018-01-09 15:44:54 -08:00
|
|
|
/* Node in alg_expectation_refs. */
|
|
|
|
struct hindex_node node_ref;
|
2017-08-06 10:51:14 -07:00
|
|
|
/* Key of data connection to be created. */
|
|
|
|
struct conn_key key;
|
|
|
|
/* Corresponding key of the control connection. */
|
|
|
|
struct conn_key master_key;
|
|
|
|
/* The NAT replacement address to be used by the data connection. */
|
|
|
|
struct ct_addr alg_nat_repl_addr;
|
|
|
|
/* The data connection inherits the master control
|
|
|
|
* connection label and mark. */
|
|
|
|
ovs_u128 master_label;
|
|
|
|
uint32_t master_mark;
|
2018-01-09 15:44:55 -08:00
|
|
|
/* True if for NAT application, the alg replaces the dest address;
|
|
|
|
* otherwise, the source address is replaced. */
|
|
|
|
bool nat_rpl_dst;
|
2017-08-06 10:51:14 -07:00
|
|
|
};
|
|
|
|
|
2015-11-15 22:07:25 -08:00
|
|
|
struct conn {
|
|
|
|
struct conn_key key;
|
|
|
|
struct conn_key rev_key;
|
2017-08-06 10:51:14 -07:00
|
|
|
/* Only used for orig_tuple support. */
|
|
|
|
struct conn_key master_key;
|
2015-11-15 22:07:25 -08:00
|
|
|
long long expiration;
|
|
|
|
struct ovs_list exp_node;
|
|
|
|
struct hmap_node node;
|
|
|
|
ovs_u128 label;
|
2017-05-30 10:49:27 -07:00
|
|
|
/* XXX: consider flattening. */
|
|
|
|
struct nat_action_info_t *nat_info;
|
2017-08-06 10:51:14 -07:00
|
|
|
char *alg;
|
|
|
|
int seq_skew;
|
2017-05-30 10:49:27 -07:00
|
|
|
uint32_t mark;
|
|
|
|
uint8_t conn_type;
|
2017-08-06 10:51:14 -07:00
|
|
|
/* TCP sequence skew due to NATTing of FTP control messages. */
|
|
|
|
uint8_t seq_skew_dir;
|
|
|
|
/* True if alg data connection. */
|
|
|
|
uint8_t alg_related;
|
2015-11-15 22:07:25 -08:00
|
|
|
};
|
|
|
|
|
|
|
|
enum ct_update_res {
|
|
|
|
CT_UPDATE_INVALID,
|
|
|
|
CT_UPDATE_VALID,
|
|
|
|
CT_UPDATE_NEW,
|
|
|
|
};
|
|
|
|
|
2017-05-30 10:49:27 -07:00
|
|
|
enum ct_conn_type {
|
|
|
|
CT_CONN_TYPE_DEFAULT,
|
|
|
|
CT_CONN_TYPE_UN_NAT,
|
|
|
|
};
|
|
|
|
|
2015-11-15 22:07:25 -08:00
|
|
|
struct ct_l4_proto {
|
2016-05-16 12:59:23 -07:00
|
|
|
struct conn *(*new_conn)(struct conntrack_bucket *, struct dp_packet *pkt,
|
|
|
|
long long now);
|
2015-11-15 22:07:25 -08:00
|
|
|
bool (*valid_new)(struct dp_packet *pkt);
|
2016-05-16 12:59:23 -07:00
|
|
|
enum ct_update_res (*conn_update)(struct conn *conn,
|
|
|
|
struct conntrack_bucket *,
|
|
|
|
struct dp_packet *pkt, bool reply,
|
|
|
|
long long now);
|
2015-11-15 22:07:25 -08:00
|
|
|
void (*conn_get_protoinfo)(const struct conn *,
|
|
|
|
struct ct_dpif_protoinfo *);
|
2015-11-15 22:07:25 -08:00
|
|
|
};
|
|
|
|
|
|
|
|
extern struct ct_l4_proto ct_proto_tcp;
|
|
|
|
extern struct ct_l4_proto ct_proto_other;
|
2016-05-13 15:04:17 -07:00
|
|
|
extern struct ct_l4_proto ct_proto_icmp4;
|
|
|
|
extern struct ct_l4_proto ct_proto_icmp6;
|
2015-11-15 22:07:25 -08:00
|
|
|
|
|
|
|
extern long long ct_timeout_val[];
|
|
|
|
|
|
|
|
static inline void
|
2016-05-16 12:59:23 -07:00
|
|
|
conn_init_expiration(struct conntrack_bucket *ctb, struct conn *conn,
|
|
|
|
enum ct_timeout tm, long long now)
|
2015-11-15 22:07:25 -08:00
|
|
|
{
|
|
|
|
conn->expiration = now + ct_timeout_val[tm];
|
2016-05-16 12:59:23 -07:00
|
|
|
ovs_list_push_back(&ctb->exp_lists[tm], &conn->exp_node);
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void
|
|
|
|
conn_update_expiration(struct conntrack_bucket *ctb, struct conn *conn,
|
|
|
|
enum ct_timeout tm, long long now)
|
|
|
|
{
|
|
|
|
ovs_list_remove(&conn->exp_node);
|
|
|
|
conn_init_expiration(ctb, conn, tm, now);
|
2015-11-15 22:07:25 -08:00
|
|
|
}
|
|
|
|
|
2017-05-30 14:21:33 -07:00
|
|
|
static inline uint32_t
|
|
|
|
tcp_payload_length(struct dp_packet *pkt)
|
|
|
|
{
|
|
|
|
const char *tcp_payload = dp_packet_get_tcp_payload(pkt);
|
|
|
|
if (tcp_payload) {
|
|
|
|
return ((char *) dp_packet_tail(pkt) - dp_packet_l2_pad_size(pkt)
|
|
|
|
- tcp_payload);
|
|
|
|
} else {
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-11-15 22:07:25 -08:00
|
|
|
#endif /* conntrack-private.h */
|