X-Git-Url: http://git.openwrt.org/?a=blobdiff_plain;f=options.h;h=cffc01cc4f6f294b09a44bb456b961cf623a7266;hb=4d0c703e750cdbaa7d8afc56de05bd1238e3c981;hp=0a22cb689bd845180bec0e2663731ff538bf6640;hpb=8875f2d067b84a40731983fd495f3e0e4daa493b;p=project%2Ffirewall3.git diff --git a/options.h b/options.h index 0a22cb6..cffc01c 100644 --- a/options.h +++ b/options.h @@ -1,7 +1,7 @@ /* * firewall3 - 3rd OpenWrt UCI firewall implementation * - * Copyright (C) 2013 Jo-Philipp Wich + * Copyright (C) 2013-2014 Jo-Philipp Wich * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -32,6 +32,8 @@ #include #include #include +#define _LINUX_IN_H +#define _LINUX_IN6_H #include #include @@ -41,6 +43,7 @@ #include #include +#include #include "icmp_codes.h" #include "utils.h" @@ -68,21 +71,33 @@ enum fw3_flag FW3_FLAG_REJECT = 7, FW3_FLAG_DROP = 8, FW3_FLAG_NOTRACK = 9, - FW3_FLAG_MARK = 10, - FW3_FLAG_DNAT = 11, - FW3_FLAG_SNAT = 12, - FW3_FLAG_SRC_ACCEPT = 13, - FW3_FLAG_SRC_REJECT = 14, - FW3_FLAG_SRC_DROP = 15, - FW3_FLAG_CUSTOM_CHAINS = 16, - FW3_FLAG_SYN_FLOOD = 17, - FW3_FLAG_MTU_FIX = 18, - FW3_FLAG_DROP_INVALID = 19, - FW3_FLAG_HOTPLUG = 20, + FW3_FLAG_HELPER = 10, + FW3_FLAG_MARK = 11, + FW3_FLAG_DSCP = 12, + FW3_FLAG_DNAT = 13, + FW3_FLAG_SNAT = 14, + FW3_FLAG_MASQUERADE = 15, + FW3_FLAG_SRC_ACCEPT = 16, + FW3_FLAG_SRC_REJECT = 17, + FW3_FLAG_SRC_DROP = 18, + FW3_FLAG_CUSTOM_CHAINS = 19, + FW3_FLAG_SYN_FLOOD = 20, + FW3_FLAG_MTU_FIX = 21, + FW3_FLAG_DROP_INVALID = 22, + FW3_FLAG_HOTPLUG = 23, __FW3_FLAG_MAX }; +enum fw3_reject_code +{ + FW3_REJECT_CODE_TCP_RESET = 0, + FW3_REJECT_CODE_PORT_UNREACH = 1, + FW3_REJECT_CODE_ADM_PROHIBITED = 2, + + __FW3_REJECT_CODE_MAX +}; + extern const char *fw3_flag_names[__FW3_FLAG_MAX]; @@ -92,8 +107,13 @@ enum fw3_limit_unit FW3_LIMIT_UNIT_MINUTE = 1, FW3_LIMIT_UNIT_HOUR = 2, FW3_LIMIT_UNIT_DAY = 3, + + __FW3_LIMIT_UNIT_MAX }; +extern const char *fw3_limit_units[__FW3_LIMIT_UNIT_MAX]; + + enum fw3_ipset_method { FW3_IPSET_METHOD_UNSPEC = 0, @@ -136,7 +156,16 @@ struct fw3_ipset_datatype { struct list_head list; enum fw3_ipset_type type; - bool dest; + const char *dir; +}; + +struct fw3_setmatch +{ + bool set; + bool invert; + char name[32]; + const char *dir[3]; + struct fw3_ipset *ptr; }; struct fw3_device @@ -157,8 +186,8 @@ struct fw3_address bool set; bool range; bool invert; + bool resolved; enum fw3_family family; - int mask; union { struct in_addr v4; struct in6_addr v6; @@ -168,7 +197,7 @@ struct fw3_address struct in_addr v4; struct in6_addr v6; struct ether_addr mac; - } address2; + } mask; }; struct fw3_mac @@ -240,6 +269,23 @@ struct fw3_mark uint32_t mask; }; +struct fw3_dscp +{ + bool set; + bool invert; + uint8_t dscp; +}; + +struct fw3_cthelpermatch +{ + struct list_head list; + + bool set; + bool invert; + char name[32]; + struct fw3_cthelper *ptr; +}; + struct fw3_defaults { enum fw3_flag policy_input; @@ -247,18 +293,23 @@ struct fw3_defaults enum fw3_flag policy_forward; bool drop_invalid; + enum fw3_reject_code tcp_reject_code; + enum fw3_reject_code any_reject_code; bool syn_flood; struct fw3_limit syn_flood_rate; bool tcp_syncookies; - bool tcp_ecn; + int tcp_ecn; bool tcp_window_scaling; bool accept_redirects; bool accept_source_route; bool custom_chains; + bool auto_helper; + bool flow_offloading; + bool flow_offloading_hw; bool disable_ipv6; @@ -286,18 +337,23 @@ struct fw3_zone const char *extra_dest; bool masq; + bool masq_allow_invalid; struct list_head masq_src; struct list_head masq_dest; - bool conntrack; bool mtu_fix; - bool log; + struct list_head cthelpers; + + int log; struct fw3_limit log_limit; bool custom_chains; + bool auto_helper; uint32_t flags[2]; + + struct list_head old_addrs; }; struct fw3_rule @@ -312,11 +368,13 @@ struct fw3_rule struct fw3_zone *_src; struct fw3_zone *_dest; + const char *device; + bool direction_out; + struct fw3_device src; struct fw3_device dest; - - struct fw3_ipset *_ipset; - struct fw3_device ipset; + struct fw3_setmatch ipset; + struct fw3_cthelpermatch helper; struct list_head proto; @@ -332,10 +390,13 @@ struct fw3_rule struct fw3_limit limit; struct fw3_time time; struct fw3_mark mark; + struct fw3_dscp dscp; enum fw3_flag target; struct fw3_mark set_mark; struct fw3_mark set_xmark; + struct fw3_dscp set_dscp; + struct fw3_cthelpermatch set_helper; const char *extra; }; @@ -354,9 +415,8 @@ struct fw3_redirect struct fw3_device src; struct fw3_device dest; - - struct fw3_ipset *_ipset; - struct fw3_device ipset; + struct fw3_setmatch ipset; + struct fw3_cthelpermatch helper; struct list_head proto; @@ -370,6 +430,7 @@ struct fw3_redirect struct fw3_address ip_redir; struct fw3_port port_redir; + struct fw3_limit limit; struct fw3_time time; struct fw3_mark mark; @@ -377,10 +438,48 @@ struct fw3_redirect const char *extra; + bool local; bool reflection; enum fw3_reflection_source reflection_src; }; +struct fw3_snat +{ + struct list_head list; + + bool enabled; + const char *name; + + enum fw3_family family; + + struct fw3_zone *_src; + + struct fw3_device src; + struct fw3_setmatch ipset; + struct fw3_cthelpermatch helper; + const char *device; + + struct list_head proto; + + struct fw3_address ip_src; + struct fw3_port port_src; + + struct fw3_address ip_dest; + struct fw3_port port_dest; + + struct fw3_address ip_snat; + struct fw3_port port_snat; + + struct fw3_limit limit; + struct fw3_time time; + struct fw3_mark mark; + bool connlimit_ports; + + enum fw3_flag target; + + const char *extra; +}; + struct fw3_forward { struct list_head list; @@ -402,6 +501,10 @@ struct fw3_ipset struct list_head list; bool enabled; + bool reload_set; + bool counters; + bool comment; + const char *name; enum fw3_family family; @@ -419,6 +522,9 @@ struct fw3_ipset const char *external; + struct list_head entries; + const char *loadfile; + uint32_t flags[2]; }; @@ -436,6 +542,25 @@ struct fw3_include bool reload; }; +struct fw3_cthelper +{ + struct list_head list; + + bool enabled; + const char *name; + const char *module; + const char *description; + enum fw3_family family; + struct list_head proto; + struct fw3_port port; +}; + +struct fw3_setentry +{ + struct list_head list; + const char *value; +}; + struct fw3_state { struct uci_context *uci; @@ -443,14 +568,23 @@ struct fw3_state struct list_head zones; struct list_head rules; struct list_head redirects; + struct list_head snats; struct list_head forwards; struct list_head ipsets; struct list_head includes; + struct list_head cthelpers; bool disable_ipsets; bool statefile; }; +struct fw3_chain_spec { + int family; + int table; + int flag; + const char *format; +}; + struct fw3_option { @@ -471,6 +605,7 @@ bool fw3_parse_bool(void *ptr, const char *val, bool is_list); bool fw3_parse_int(void *ptr, const char *val, bool is_list); bool fw3_parse_string(void *ptr, const char *val, bool is_list); bool fw3_parse_target(void *ptr, const char *val, bool is_list); +bool fw3_parse_reject_code(void *ptr, const char *val, bool is_list); bool fw3_parse_limit(void *ptr, const char *val, bool is_list); bool fw3_parse_device(void *ptr, const char *val, bool is_list); bool fw3_parse_address(void *ptr, const char *val, bool is_list); @@ -492,27 +627,18 @@ bool fw3_parse_time(void *ptr, const char *val, bool is_list); bool fw3_parse_weekdays(void *ptr, const char *val, bool is_list); bool fw3_parse_monthdays(void *ptr, const char *val, bool is_list); bool fw3_parse_mark(void *ptr, const char *val, bool is_list); +bool fw3_parse_dscp(void *ptr, const char *val, bool is_list); +bool fw3_parse_setmatch(void *ptr, const char *val, bool is_list); +bool fw3_parse_direction(void *ptr, const char *val, bool is_list); +bool fw3_parse_cthelper(void *ptr, const char *val, bool is_list); +bool fw3_parse_setentry(void *ptr, const char *val, bool is_list); -void fw3_parse_options(void *s, const struct fw3_option *opts, +bool fw3_parse_options(void *s, const struct fw3_option *opts, struct uci_section *section); +bool fw3_parse_blob_options(void *s, const struct fw3_option *opts, + struct blob_attr *a, const char *name); const char * fw3_address_to_string(struct fw3_address *address, - bool allow_invert); - -void fw3_format_in_out(struct fw3_device *in, struct fw3_device *out); -void fw3_format_src_dest(struct fw3_address *src, struct fw3_address *dest); -void fw3_format_sport_dport(struct fw3_port *sp, struct fw3_port *dp); -void fw3_format_mac(struct fw3_mac *mac); -void fw3_format_protocol(struct fw3_protocol *proto, enum fw3_family family); -void fw3_format_icmptype(struct fw3_icmptype *icmp, enum fw3_family family); -void fw3_format_limit(struct fw3_limit *limit); -void fw3_format_ipset(struct fw3_ipset *ipset, bool invert); -void fw3_format_time(struct fw3_time *time); -void fw3_format_mark(struct fw3_mark *mark); - -void __fw3_format_comment(const char *comment, ...); -#define fw3_format_comment(...) __fw3_format_comment(__VA_ARGS__, NULL) - -void fw3_format_extra(const char *extra); + bool allow_invert, bool as_cidr); #endif