]>
Commit | Line | Data |
---|---|---|
1 | /* | |
2 | * Copyright (c) 2012-2019 Apple Inc. All rights reserved. | |
3 | * | |
4 | * @APPLE_OSREFERENCE_LICENSE_HEADER_START@ | |
5 | * | |
6 | * This file contains Original Code and/or Modifications of Original Code | |
7 | * as defined in and that are subject to the Apple Public Source License | |
8 | * Version 2.0 (the 'License'). You may not use this file except in | |
9 | * compliance with the License. The rights granted to you under the License | |
10 | * may not be used to create, or enable the creation or redistribution of, | |
11 | * unlawful or unlicensed copies of an Apple operating system, or to | |
12 | * circumvent, violate, or enable the circumvention or violation of, any | |
13 | * terms of an Apple operating system software license agreement. | |
14 | * | |
15 | * Please obtain a copy of the License at | |
16 | * http://www.opensource.apple.com/apsl/ and read it before using this file. | |
17 | * | |
18 | * The Original Code and all software distributed under the License are | |
19 | * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER | |
20 | * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, | |
21 | * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, | |
22 | * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. | |
23 | * Please see the License for the specific language governing rights and | |
24 | * limitations under the License. | |
25 | * | |
26 | * @APPLE_OSREFERENCE_LICENSE_HEADER_END@ | |
27 | */ | |
28 | ||
29 | ||
30 | #ifndef _NET_IF_IPSEC_H_ | |
31 | #define _NET_IF_IPSEC_H_ | |
32 | ||
33 | #ifdef BSD_KERNEL_PRIVATE | |
34 | ||
35 | #include <sys/kern_control.h> | |
36 | #include <netinet/ip_var.h> | |
37 | ||
38 | ||
39 | errno_t ipsec_register_control(void); | |
40 | ||
41 | /* Helpers */ | |
42 | int ipsec_interface_isvalid(ifnet_t interface); | |
43 | ||
44 | errno_t ipsec_inject_inbound_packet(ifnet_t interface, mbuf_t packet); | |
45 | ||
46 | void ipsec_set_pkthdr_for_interface(ifnet_t interface, mbuf_t packet, int family); | |
47 | ||
48 | void ipsec_set_ipoa_for_interface(ifnet_t interface, struct ip_out_args *ipoa); | |
49 | ||
50 | struct ip6_out_args; | |
51 | void ipsec_set_ip6oa_for_interface(ifnet_t interface, struct ip6_out_args *ip6oa); | |
52 | ||
53 | #endif | |
54 | ||
55 | /* | |
56 | * Name registered by the ipsec kernel control | |
57 | */ | |
58 | #define IPSEC_CONTROL_NAME "com.apple.net.ipsec_control" | |
59 | ||
60 | /* | |
61 | * Socket option names to manage ipsec | |
62 | */ | |
63 | #define IPSEC_OPT_FLAGS 1 | |
64 | #define IPSEC_OPT_IFNAME 2 | |
65 | #define IPSEC_OPT_EXT_IFDATA_STATS 3 /* get|set (type int) */ | |
66 | #define IPSEC_OPT_INC_IFDATA_STATS_IN 4 /* set to increment stat counters (type struct ipsec_stats_param) */ | |
67 | #define IPSEC_OPT_INC_IFDATA_STATS_OUT 5 /* set to increment stat counters (type struct ipsec_stats_param) */ | |
68 | #define IPSEC_OPT_SET_DELEGATE_INTERFACE 6 /* set the delegate interface (char[]) */ | |
69 | #define IPSEC_OPT_OUTPUT_TRAFFIC_CLASS 7 /* set the traffic class for packets leaving the interface, see sys/socket.h */ | |
70 | #define IPSEC_OPT_ENABLE_CHANNEL 8 /* enable a kernel pipe nexus that allows the owner to open a channel to act as a driver, | |
71 | * Must be set before connecting */ | |
72 | #define IPSEC_OPT_GET_CHANNEL_UUID 9 /* get the uuid of the kernel pipe nexus instance */ | |
73 | #define IPSEC_OPT_ENABLE_FLOWSWITCH 10 /* enable a flowswitch nexus that clients can use */ | |
74 | #define IPSEC_OPT_INPUT_FRAG_SIZE 11 /* set the maximum size of input packets before fragmenting as a uint32_t */ | |
75 | ||
76 | #define IPSEC_OPT_ENABLE_NETIF 12 /* Must be set before connecting */ | |
77 | #define IPSEC_OPT_SLOT_SIZE 13 /* Must be set before connecting */ | |
78 | #define IPSEC_OPT_NETIF_RING_SIZE 14 /* Must be set before connecting */ | |
79 | #define IPSEC_OPT_TX_FSW_RING_SIZE 15 /* Must be set before connecting */ | |
80 | #define IPSEC_OPT_RX_FSW_RING_SIZE 16 /* Must be set before connecting */ | |
81 | #define IPSEC_OPT_CHANNEL_BIND_PID 17 /* Must be set before connecting */ | |
82 | #define IPSEC_OPT_KPIPE_TX_RING_SIZE 18 /* Must be set before connecting */ | |
83 | #define IPSEC_OPT_KPIPE_RX_RING_SIZE 19 /* Must be set before connecting */ | |
84 | ||
85 | /* | |
86 | * ipsec stats parameter structure | |
87 | */ | |
88 | struct ipsec_stats_param { | |
89 | u_int64_t utsp_packets; | |
90 | u_int64_t utsp_bytes; | |
91 | u_int64_t utsp_errors; | |
92 | }; | |
93 | ||
94 | #endif |