Blame extensions/libxt_SYNPROXY.c

Packit 7b22a4
Packit 7b22a4
/*
Packit 7b22a4
 * Copyright (c) 2013 Patrick McHardy <kaber@trash.net>
Packit 7b22a4
 *
Packit 7b22a4
 * This program is free software; you can redistribute it and/or modify
Packit 7b22a4
 * it under the terms of the GNU General Public License version 2 as
Packit 7b22a4
 * published by the Free Software Foundation.
Packit 7b22a4
 */
Packit 7b22a4
Packit 7b22a4
#include <stdbool.h>
Packit 7b22a4
#include <stdio.h>
Packit 7b22a4
#include <xtables.h>
Packit 7b22a4
#include <linux/netfilter/xt_SYNPROXY.h>
Packit 7b22a4
Packit 7b22a4
enum {
Packit 7b22a4
	O_SACK_PERM = 0,
Packit 7b22a4
	O_TIMESTAMP,
Packit 7b22a4
	O_WSCALE,
Packit 7b22a4
	O_MSS,
Packit 7b22a4
	O_ECN,
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
static void SYNPROXY_help(void)
Packit 7b22a4
{
Packit 7b22a4
	printf(
Packit 7b22a4
"SYNPROXY target options:\n"
Packit 7b22a4
"  --sack-perm                        Set SACK_PERM\n"
Packit 7b22a4
"  --timestamp                        Set TIMESTAMP\n"
Packit 7b22a4
"  --wscale value                     Set window scaling factor\n"
Packit 7b22a4
"  --mss value                        Set MSS value\n"
Packit 7b22a4
"  --ecn                              Set ECN\n");
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static const struct xt_option_entry SYNPROXY_opts[] = {
Packit 7b22a4
	{.name = "sack-perm", .id = O_SACK_PERM, .type = XTTYPE_NONE, },
Packit 7b22a4
	{.name = "timestamp", .id = O_TIMESTAMP, .type = XTTYPE_NONE, },
Packit 7b22a4
	{.name = "wscale",    .id = O_WSCALE,    .type = XTTYPE_UINT32, },
Packit 7b22a4
	{.name = "mss",       .id = O_MSS,       .type = XTTYPE_UINT32, },
Packit 7b22a4
	{.name = "ecn",       .id = O_ECN,	 .type = XTTYPE_NONE, },
Packit 7b22a4
	XTOPT_TABLEEND,
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
static void SYNPROXY_parse(struct xt_option_call *cb)
Packit 7b22a4
{
Packit 7b22a4
	struct xt_synproxy_info *info = cb->data;
Packit 7b22a4
Packit 7b22a4
	xtables_option_parse(cb);
Packit 7b22a4
	switch (cb->entry->id) {
Packit 7b22a4
	case O_SACK_PERM:
Packit 7b22a4
		info->options |= XT_SYNPROXY_OPT_SACK_PERM;
Packit 7b22a4
		break;
Packit 7b22a4
	case O_TIMESTAMP:
Packit 7b22a4
		info->options |= XT_SYNPROXY_OPT_TIMESTAMP;
Packit 7b22a4
		break;
Packit 7b22a4
	case O_WSCALE:
Packit 7b22a4
		info->options |= XT_SYNPROXY_OPT_WSCALE;
Packit 7b22a4
		info->wscale = cb->val.u32;
Packit 7b22a4
		break;
Packit 7b22a4
	case O_MSS:
Packit 7b22a4
		info->options |= XT_SYNPROXY_OPT_MSS;
Packit 7b22a4
		info->mss = cb->val.u32;
Packit 7b22a4
		break;
Packit 7b22a4
	case O_ECN:
Packit 7b22a4
		info->options |= XT_SYNPROXY_OPT_ECN;
Packit 7b22a4
		break;
Packit 7b22a4
	}
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static void SYNPROXY_check(struct xt_fcheck_call *cb)
Packit 7b22a4
{
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static void SYNPROXY_print(const void *ip, const struct xt_entry_target *target,
Packit 7b22a4
                           int numeric)
Packit 7b22a4
{
Packit 7b22a4
	const struct xt_synproxy_info *info =
Packit 7b22a4
		(const struct xt_synproxy_info *)target->data;
Packit 7b22a4
Packit 7b22a4
	printf(" SYNPROXY ");
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_SACK_PERM)
Packit 7b22a4
		printf("sack-perm ");
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_TIMESTAMP)
Packit 7b22a4
		printf("timestamp ");
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_WSCALE)
Packit 7b22a4
		printf("wscale %u ", info->wscale);
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_MSS)
Packit 7b22a4
		printf("mss %u ", info->mss);
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_ECN)
Packit 7b22a4
		printf("ecn ");
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static void SYNPROXY_save(const void *ip, const struct xt_entry_target *target)
Packit 7b22a4
{
Packit 7b22a4
	const struct xt_synproxy_info *info =
Packit 7b22a4
		(const struct xt_synproxy_info *)target->data;
Packit 7b22a4
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_SACK_PERM)
Packit 7b22a4
		printf(" --sack-perm");
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_TIMESTAMP)
Packit 7b22a4
		printf(" --timestamp");
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_WSCALE)
Packit 7b22a4
		printf(" --wscale %u", info->wscale);
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_MSS)
Packit 7b22a4
		printf(" --mss %u", info->mss);
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_ECN)
Packit 7b22a4
		printf(" --ecn");
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static int SYNPROXY_xlate(struct xt_xlate *xl,
Packit 7b22a4
		          const struct xt_xlate_tg_params *params)
Packit 7b22a4
{
Packit 7b22a4
	const struct xt_synproxy_info *info =
Packit 7b22a4
		(const struct xt_synproxy_info *)params->target->data;
Packit 7b22a4
Packit 7b22a4
	xt_xlate_add(xl, "synproxy ");
Packit 7b22a4
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_SACK_PERM)
Packit 7b22a4
		xt_xlate_add(xl, "sack-perm ");
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_TIMESTAMP)
Packit 7b22a4
		xt_xlate_add(xl, "timestamp ");
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_WSCALE)
Packit 7b22a4
		xt_xlate_add(xl, "wscale %u ", info->wscale);
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_MSS)
Packit 7b22a4
		xt_xlate_add(xl, "mss %u ", info->mss);
Packit 7b22a4
	if (info->options & XT_SYNPROXY_OPT_ECN)
Packit 7b22a4
		xt_xlate_add(xl, "ecn ");
Packit 7b22a4
Packit 7b22a4
	return 1;
Packit 7b22a4
}
Packit 7b22a4
Packit 7b22a4
static struct xtables_target synproxy_tg_reg = {
Packit 7b22a4
	.family        = NFPROTO_UNSPEC,
Packit 7b22a4
	.name          = "SYNPROXY",
Packit 7b22a4
	.version       = XTABLES_VERSION,
Packit 7b22a4
	.revision      = 0,
Packit 7b22a4
	.size          = XT_ALIGN(sizeof(struct xt_synproxy_info)),
Packit 7b22a4
	.userspacesize = XT_ALIGN(sizeof(struct xt_synproxy_info)),
Packit 7b22a4
	.help          = SYNPROXY_help,
Packit 7b22a4
	.print         = SYNPROXY_print,
Packit 7b22a4
	.save          = SYNPROXY_save,
Packit 7b22a4
	.x6_parse      = SYNPROXY_parse,
Packit 7b22a4
	.x6_fcheck     = SYNPROXY_check,
Packit 7b22a4
	.x6_options    = SYNPROXY_opts,
Packit 7b22a4
	.xlate         = SYNPROXY_xlate,
Packit 7b22a4
};
Packit 7b22a4
Packit 7b22a4
void _init(void)
Packit 7b22a4
{
Packit 7b22a4
	xtables_register_target(&synproxy_tg_reg);
Packit 7b22a4
}