]>
Commit | Line | Data |
---|---|---|
b0d623f7 | 1 | /* |
5ba3f43e | 2 | * Copyright (c) 2007-2017 Apple Inc. All rights reserved. |
b0d623f7 A |
3 | * |
4 | * @APPLE_OSREFERENCE_LICENSE_HEADER_START@ | |
5 | * | |
6 | * This file contains Original Code and/or Modifications of Original Code | |
7 | * as defined in and that are subject to the Apple Public Source License | |
8 | * Version 2.0 (the 'License'). You may not use this file except in | |
9 | * compliance with the License. The rights granted to you under the License | |
10 | * may not be used to create, or enable the creation or redistribution of, | |
11 | * unlawful or unlicensed copies of an Apple operating system, or to | |
12 | * circumvent, violate, or enable the circumvention or violation of, any | |
13 | * terms of an Apple operating system software license agreement. | |
14 | * | |
15 | * Please obtain a copy of the License at | |
16 | * http://www.opensource.apple.com/apsl/ and read it before using this file. | |
17 | * | |
18 | * The Original Code and all software distributed under the License are | |
19 | * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER | |
20 | * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, | |
21 | * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, | |
22 | * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. | |
23 | * Please see the License for the specific language governing rights and | |
24 | * limitations under the License. | |
25 | * | |
26 | * @APPLE_OSREFERENCE_LICENSE_HEADER_END@ | |
27 | */ | |
28 | ||
29 | /* $apfw: if_pflog.c,v 1.4 2008/08/27 00:01:32 jhw Exp $ */ | |
30 | /* $OpenBSD: if_pflog.c,v 1.22 2006/12/15 09:31:20 otto Exp $ */ | |
31 | /* | |
32 | * The authors of this code are John Ioannidis (ji@tla.org), | |
33 | * Angelos D. Keromytis (kermit@csd.uch.gr) and | |
34 | * Niels Provos (provos@physnet.uni-hamburg.de). | |
35 | * | |
36 | * This code was written by John Ioannidis for BSD/OS in Athens, Greece, | |
37 | * in November 1995. | |
38 | * | |
39 | * Ported to OpenBSD and NetBSD, with additional transforms, in December 1996, | |
40 | * by Angelos D. Keromytis. | |
41 | * | |
42 | * Additional transforms and features in 1997 and 1998 by Angelos D. Keromytis | |
43 | * and Niels Provos. | |
44 | * | |
45 | * Copyright (C) 1995, 1996, 1997, 1998 by John Ioannidis, Angelos D. Keromytis | |
46 | * and Niels Provos. | |
47 | * Copyright (c) 2001, Angelos D. Keromytis, Niels Provos. | |
48 | * | |
49 | * Permission to use, copy, and modify this software with or without fee | |
50 | * is hereby granted, provided that this entire notice is included in | |
51 | * all copies of any software which is or includes a copy or | |
52 | * modification of this software. | |
53 | * You may use this code under the GNU public license if you so wish. Please | |
54 | * contribute changes back to the authors under this freer than GPL license | |
55 | * so that we may further the use of strong encryption without limitations to | |
56 | * all. | |
57 | * | |
58 | * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR | |
59 | * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY | |
60 | * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE | |
61 | * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR | |
62 | * PURPOSE. | |
63 | */ | |
64 | ||
65 | #include <sys/param.h> | |
66 | #include <sys/systm.h> | |
67 | #include <sys/mbuf.h> | |
68 | #include <sys/proc_internal.h> | |
69 | #include <sys/socket.h> | |
70 | #include <sys/ioctl.h> | |
6d2010ae | 71 | #include <sys/mcache.h> |
b0d623f7 A |
72 | |
73 | #include <net/if.h> | |
d1ecb069 | 74 | #include <net/if_var.h> |
b0d623f7 A |
75 | #include <net/if_types.h> |
76 | #include <net/route.h> | |
77 | #include <net/bpf.h> | |
78 | ||
79 | #if INET | |
80 | #include <netinet/in.h> | |
81 | #include <netinet/in_var.h> | |
82 | #include <netinet/in_systm.h> | |
83 | #include <netinet/ip.h> | |
84 | #endif | |
85 | ||
86 | #if INET6 | |
87 | #if !INET | |
88 | #include <netinet/in.h> | |
89 | #endif | |
90 | #include <netinet6/nd6.h> | |
91 | #endif /* INET6 */ | |
92 | ||
93 | #include <net/pfvar.h> | |
94 | #include <net/if_pflog.h> | |
95 | ||
96 | #define PFLOGNAME "pflog" | |
97 | #define PFLOGMTU (32768 + MHLEN + MLEN) | |
98 | ||
99 | #ifdef PFLOGDEBUG | |
100 | #define DPRINTF(x) do { if (pflogdebug) printf x ; } while (0) | |
101 | #else | |
102 | #define DPRINTF(x) | |
103 | #endif | |
104 | ||
d1ecb069 A |
105 | static int pflog_clone_create(struct if_clone *, u_int32_t, void *); |
106 | static int pflog_clone_destroy(struct ifnet *); | |
b0d623f7 A |
107 | static errno_t pflogoutput(struct ifnet *, struct mbuf *); |
108 | static errno_t pflogioctl(struct ifnet *, unsigned long, void *); | |
109 | static errno_t pflogdemux(struct ifnet *, struct mbuf *, char *, | |
110 | protocol_family_t *); | |
111 | static errno_t pflogaddproto(struct ifnet *, protocol_family_t, | |
112 | const struct ifnet_demux_desc *, u_int32_t); | |
113 | static errno_t pflogdelproto(struct ifnet *, protocol_family_t); | |
d1ecb069 | 114 | static void pflogfree(struct ifnet *); |
b0d623f7 A |
115 | |
116 | static LIST_HEAD(, pflog_softc) pflogif_list; | |
d1ecb069 A |
117 | static struct if_clone pflog_cloner = |
118 | IF_CLONE_INITIALIZER(PFLOGNAME, pflog_clone_create, pflog_clone_destroy, | |
119 | 0, (PFLOGIFS_MAX - 1)); | |
b0d623f7 A |
120 | |
121 | struct ifnet *pflogifs[PFLOGIFS_MAX]; /* for fast access */ | |
b0d623f7 A |
122 | |
123 | void | |
124 | pfloginit(void) | |
125 | { | |
126 | int i; | |
127 | ||
b0d623f7 A |
128 | LIST_INIT(&pflogif_list); |
129 | for (i = 0; i < PFLOGIFS_MAX; i++) | |
130 | pflogifs[i] = NULL; | |
131 | ||
d1ecb069 | 132 | (void) if_clone_attach(&pflog_cloner); |
b0d623f7 A |
133 | } |
134 | ||
135 | static int | |
d1ecb069 | 136 | pflog_clone_create(struct if_clone *ifc, u_int32_t unit, __unused void *params) |
b0d623f7 A |
137 | { |
138 | struct pflog_softc *pflogif; | |
5ba3f43e | 139 | struct ifnet_init_eparams pf_init; |
b0d623f7 A |
140 | int error = 0; |
141 | ||
d1ecb069 A |
142 | if (unit >= PFLOGIFS_MAX) { |
143 | /* Either the interface cloner or our initializer is broken */ | |
144 | panic("%s: unit (%d) exceeds max (%d)", __func__, unit, | |
145 | PFLOGIFS_MAX); | |
146 | /* NOTREACHED */ | |
b0d623f7 A |
147 | } |
148 | ||
149 | if ((pflogif = _MALLOC(sizeof (*pflogif), | |
150 | M_DEVBUF, M_WAITOK|M_ZERO)) == NULL) { | |
151 | error = ENOMEM; | |
152 | goto done; | |
153 | } | |
154 | ||
155 | bzero(&pf_init, sizeof (pf_init)); | |
5ba3f43e A |
156 | pf_init.ver = IFNET_INIT_CURRENT_VERSION; |
157 | pf_init.len = sizeof (pf_init); | |
158 | pf_init.flags = IFNET_INIT_LEGACY; | |
d1ecb069 A |
159 | pf_init.name = ifc->ifc_name; |
160 | pf_init.unit = unit; | |
b0d623f7 A |
161 | pf_init.type = IFT_PFLOG; |
162 | pf_init.family = IFNET_FAMILY_LOOPBACK; | |
163 | pf_init.output = pflogoutput; | |
164 | pf_init.demux = pflogdemux; | |
165 | pf_init.add_proto = pflogaddproto; | |
166 | pf_init.del_proto = pflogdelproto; | |
167 | pf_init.softc = pflogif; | |
168 | pf_init.ioctl = pflogioctl; | |
d1ecb069 | 169 | pf_init.detach = pflogfree; |
b0d623f7 A |
170 | |
171 | bzero(pflogif, sizeof (*pflogif)); | |
d1ecb069 | 172 | pflogif->sc_unit = unit; |
b0d623f7 | 173 | |
5ba3f43e | 174 | error = ifnet_allocate_extended(&pf_init, &pflogif->sc_if); |
b0d623f7 A |
175 | if (error != 0) { |
176 | printf("%s: ifnet_allocate failed - %d\n", __func__, error); | |
177 | _FREE(pflogif, M_DEVBUF); | |
178 | goto done; | |
179 | } | |
180 | ||
181 | ifnet_set_mtu(pflogif->sc_if, PFLOGMTU); | |
182 | ifnet_set_flags(pflogif->sc_if, IFF_UP, IFF_UP); | |
183 | ||
184 | error = ifnet_attach(pflogif->sc_if, NULL); | |
185 | if (error != 0) { | |
186 | printf("%s: ifnet_attach failed - %d\n", __func__, error); | |
187 | ifnet_release(pflogif->sc_if); | |
188 | _FREE(pflogif, M_DEVBUF); | |
189 | goto done; | |
190 | } | |
191 | ||
192 | #if NBPFILTER > 0 | |
193 | bpfattach(pflogif->sc_if, DLT_PFLOG, PFLOG_HDRLEN); | |
194 | #endif | |
195 | ||
d1ecb069 A |
196 | lck_rw_lock_shared(pf_perim_lock); |
197 | lck_mtx_lock(pf_lock); | |
b0d623f7 | 198 | LIST_INSERT_HEAD(&pflogif_list, pflogif, sc_list); |
d1ecb069 A |
199 | pflogifs[unit] = pflogif->sc_if; |
200 | lck_mtx_unlock(pf_lock); | |
201 | lck_rw_done(pf_perim_lock); | |
b0d623f7 | 202 | |
d1ecb069 | 203 | done: |
b0d623f7 A |
204 | return (error); |
205 | } | |
206 | ||
d1ecb069 A |
207 | static int |
208 | pflog_clone_destroy(struct ifnet *ifp) | |
b0d623f7 | 209 | { |
d1ecb069 | 210 | struct pflog_softc *pflogif = ifp->if_softc; |
b0d623f7 | 211 | |
d1ecb069 A |
212 | lck_rw_lock_shared(pf_perim_lock); |
213 | lck_mtx_lock(pf_lock); | |
b0d623f7 A |
214 | pflogifs[pflogif->sc_unit] = NULL; |
215 | LIST_REMOVE(pflogif, sc_list); | |
d1ecb069 A |
216 | lck_mtx_unlock(pf_lock); |
217 | lck_rw_done(pf_perim_lock); | |
b0d623f7 | 218 | |
d1ecb069 A |
219 | /* bpfdetach() is taken care of as part of interface detach */ |
220 | (void) ifnet_detach(ifp); | |
221 | ||
222 | return 0; | |
b0d623f7 | 223 | } |
b0d623f7 A |
224 | |
225 | static errno_t | |
226 | pflogoutput(struct ifnet *ifp, struct mbuf *m) | |
227 | { | |
39236c6e | 228 | printf("%s: freeing data for %s\n", __func__, if_name(ifp)); |
b0d623f7 A |
229 | m_freem(m); |
230 | return (ENOTSUP); | |
231 | } | |
232 | ||
233 | static errno_t | |
234 | pflogioctl(struct ifnet *ifp, unsigned long cmd, void *data) | |
235 | { | |
236 | #pragma unused(data) | |
237 | switch (cmd) { | |
238 | case SIOCSIFADDR: | |
239 | case SIOCAIFADDR: | |
240 | case SIOCSIFDSTADDR: | |
241 | case SIOCSIFFLAGS: | |
242 | if (ifnet_flags(ifp) & IFF_UP) | |
243 | ifnet_set_flags(ifp, IFF_RUNNING, IFF_RUNNING); | |
244 | else | |
245 | ifnet_set_flags(ifp, 0, IFF_RUNNING); | |
246 | break; | |
247 | default: | |
248 | return (ENOTTY); | |
249 | } | |
250 | ||
251 | return (0); | |
252 | } | |
253 | ||
254 | static errno_t | |
255 | pflogdemux(struct ifnet *ifp, struct mbuf *m, char *h, protocol_family_t *ppf) | |
256 | { | |
257 | #pragma unused(h, ppf) | |
39236c6e | 258 | printf("%s: freeing data for %s\n", __func__, if_name(ifp)); |
b0d623f7 A |
259 | m_freem(m); |
260 | return (EJUSTRETURN); | |
261 | } | |
262 | ||
263 | static errno_t | |
264 | pflogaddproto(struct ifnet *ifp, protocol_family_t pf, | |
265 | const struct ifnet_demux_desc *d, u_int32_t cnt) | |
266 | { | |
267 | #pragma unused(ifp, pf, d, cnt) | |
268 | return (0); | |
269 | } | |
270 | ||
271 | static errno_t | |
272 | pflogdelproto(struct ifnet *ifp, protocol_family_t pf) | |
273 | { | |
274 | #pragma unused(ifp, pf) | |
275 | return (0); | |
276 | } | |
277 | ||
d1ecb069 A |
278 | static void |
279 | pflogfree(struct ifnet *ifp) | |
280 | { | |
281 | _FREE(ifp->if_softc, M_DEVBUF); | |
282 | ifp->if_softc = NULL; | |
283 | (void) ifnet_release(ifp); | |
284 | } | |
285 | ||
b0d623f7 | 286 | int |
5ba3f43e | 287 | pflog_packet(struct pfi_kif *kif, pbuf_t *pbuf, sa_family_t af, u_int8_t dir, |
b0d623f7 A |
288 | u_int8_t reason, struct pf_rule *rm, struct pf_rule *am, |
289 | struct pf_ruleset *ruleset, struct pf_pdesc *pd) | |
290 | { | |
291 | #if NBPFILTER > 0 | |
292 | struct ifnet *ifn; | |
293 | struct pfloghdr hdr; | |
5ba3f43e | 294 | struct mbuf *m; |
b0d623f7 | 295 | |
5ba3f43e | 296 | LCK_MTX_ASSERT(pf_lock, LCK_MTX_ASSERT_OWNED); |
d1ecb069 | 297 | |
5ba3f43e | 298 | if (kif == NULL || !pbuf_is_valid(pbuf) || rm == NULL || pd == NULL) |
b0d623f7 A |
299 | return (-1); |
300 | ||
301 | if (rm->logif >= PFLOGIFS_MAX || | |
302 | (ifn = pflogifs[rm->logif]) == NULL || !ifn->if_bpf) { | |
303 | return (0); | |
304 | } | |
305 | ||
5ba3f43e A |
306 | if ((m = pbuf_to_mbuf(pbuf, FALSE)) == NULL) |
307 | return (0); | |
308 | ||
b0d623f7 A |
309 | bzero(&hdr, sizeof (hdr)); |
310 | hdr.length = PFLOG_REAL_HDRLEN; | |
311 | hdr.af = af; | |
312 | hdr.action = rm->action; | |
313 | hdr.reason = reason; | |
314 | memcpy(hdr.ifname, kif->pfik_name, sizeof (hdr.ifname)); | |
315 | ||
316 | if (am == NULL) { | |
317 | hdr.rulenr = htonl(rm->nr); | |
318 | hdr.subrulenr = -1; | |
319 | } else { | |
320 | hdr.rulenr = htonl(am->nr); | |
321 | hdr.subrulenr = htonl(rm->nr); | |
322 | if (ruleset != NULL && ruleset->anchor != NULL) | |
323 | strlcpy(hdr.ruleset, ruleset->anchor->name, | |
324 | sizeof (hdr.ruleset)); | |
325 | } | |
326 | if (rm->log & PF_LOG_SOCKET_LOOKUP && !pd->lookup.done) | |
327 | pd->lookup.done = pf_socket_lookup(dir, pd); | |
328 | if (pd->lookup.done > 0) { | |
329 | hdr.uid = pd->lookup.uid; | |
330 | hdr.pid = pd->lookup.pid; | |
331 | } else { | |
332 | hdr.uid = UID_MAX; | |
333 | hdr.pid = NO_PID; | |
334 | } | |
335 | hdr.rule_uid = rm->cuid; | |
336 | hdr.rule_pid = rm->cpid; | |
337 | hdr.dir = dir; | |
338 | ||
339 | #if INET | |
340 | if (af == AF_INET && dir == PF_OUT) { | |
341 | struct ip *ip; | |
342 | ||
343 | ip = mtod(m, struct ip *); | |
344 | ip->ip_sum = 0; | |
345 | ip->ip_sum = in_cksum(m, ip->ip_hl << 2); | |
346 | } | |
347 | #endif /* INET */ | |
348 | ||
6d2010ae A |
349 | atomic_add_64(&ifn->if_opackets, 1); |
350 | atomic_add_64(&ifn->if_obytes, m->m_pkthdr.len); | |
b0d623f7 A |
351 | |
352 | switch (dir) { | |
353 | case PF_IN: | |
354 | bpf_tap_in(ifn, DLT_PFLOG, m, &hdr, PFLOG_HDRLEN); | |
355 | break; | |
356 | ||
357 | case PF_OUT: | |
358 | bpf_tap_out(ifn, DLT_PFLOG, m, &hdr, PFLOG_HDRLEN); | |
359 | break; | |
360 | ||
361 | default: | |
362 | break; | |
363 | } | |
364 | #endif /* NBPFILTER > 0 */ | |
365 | return (0); | |
366 | } |