1/* $USAGI: $ */
2
3/*
4 * Copyright (C)2004 USAGI/WIDE Project
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
19 */
20/*
21 * Authors:
22 *	Masahide NAKAMURA @USAGI
23 */
24
25#ifndef __XFRM_H__
26#define __XFRM_H__ 1
27
28#include <stdio.h>
29#include <sys/socket.h>
30#include <linux/xfrm.h>
31
32#ifndef IPPROTO_SCTP
33# define IPPROTO_SCTP	132
34#endif
35#ifndef IPPROTO_DCCP
36# define IPPROTO_DCCP	33
37#endif
38#ifndef IPPROTO_MH
39# define IPPROTO_MH	135
40#endif
41
42#define XFRMS_RTA(x)  ((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_usersa_info))))
43#define XFRMS_PAYLOAD(n) NLMSG_PAYLOAD(n,sizeof(struct xfrm_usersa_info))
44
45#define XFRMP_RTA(x)  ((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_userpolicy_info))))
46#define XFRMP_PAYLOAD(n) NLMSG_PAYLOAD(n,sizeof(struct xfrm_userpoilcy_info))
47
48#define XFRMSID_RTA(x)  ((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_usersa_id))))
49#define XFRMSID_PAYLOAD(n) NLMSG_PAYLOAD(n,sizeof(struct xfrm_usersa_id))
50
51#define XFRMPID_RTA(x)  ((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_userpolicy_id))))
52#define XFRMPID_PAYLOAD(n) NLMSG_PAYLOAD(n,sizeof(struct xfrm_userpoilcy_id))
53
54#define XFRMACQ_RTA(x)	((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_user_acquire))))
55#define XFRMEXP_RTA(x)	((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_user_expire))))
56#define XFRMPEXP_RTA(x)	((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_user_polexpire))))
57
58#define XFRMREP_RTA(x)	((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(struct xfrm_user_report))))
59
60#define XFRMSAPD_RTA(x)	((struct rtattr*)(((char*)(x)) + NLMSG_ALIGN(sizeof(__u32))))
61#define XFRM_FLAG_PRINT(fp, flags, f, s) \
62	do { \
63		if (flags & f) { \
64			flags &= ~f; \
65			fprintf(fp, s "%s", (flags ? " " : "")); \
66		} \
67	} while(0)
68
69struct xfrm_buffer {
70	char *buf;
71	int size;
72	int offset;
73
74	int nlmsg_count;
75	struct rtnl_handle *rth;
76};
77
78struct xfrm_filter {
79	int use;
80
81	struct xfrm_usersa_info xsinfo;
82	__u8 id_src_mask;
83	__u8 id_dst_mask;
84	__u8 id_proto_mask;
85	__u32 id_spi_mask;
86	__u8 mode_mask;
87	__u32 reqid_mask;
88	__u8 state_flags_mask;
89
90	struct xfrm_userpolicy_info xpinfo;
91	__u8 dir_mask;
92	__u8 sel_src_mask;
93	__u8 sel_dst_mask;
94	__u32 sel_dev_mask;
95	__u8 upspec_proto_mask;
96	__u16 upspec_sport_mask;
97	__u16 upspec_dport_mask;
98	__u32 index_mask;
99	__u8 action_mask;
100	__u32 priority_mask;
101	__u8 policy_flags_mask;
102
103	__u8 ptype;
104	__u8 ptype_mask;
105
106};
107#define XFRM_FILTER_MASK_FULL (~0)
108
109extern struct xfrm_filter filter;
110
111int xfrm_state_print(const struct sockaddr_nl *who, struct nlmsghdr *n,
112		     void *arg);
113int xfrm_policy_print(const struct sockaddr_nl *who, struct nlmsghdr *n,
114		      void *arg);
115int do_xfrm_state(int argc, char **argv);
116int do_xfrm_policy(int argc, char **argv);
117int do_xfrm_monitor(int argc, char **argv);
118
119int xfrm_addr_match(xfrm_address_t *x1, xfrm_address_t *x2, int bits);
120int xfrm_xfrmproto_is_ipsec(__u8 proto);
121int xfrm_xfrmproto_is_ro(__u8 proto);
122int xfrm_xfrmproto_getbyname(char *name);
123int xfrm_algotype_getbyname(char *name);
124int xfrm_parse_mark(struct xfrm_mark *mark, int *argcp, char ***argvp);
125const char *strxf_xfrmproto(__u8 proto);
126const char *strxf_algotype(int type);
127const char *strxf_mask8(__u8 mask);
128const char *strxf_mask32(__u32 mask);
129const char *strxf_share(__u8 share);
130const char *strxf_proto(__u8 proto);
131const char *strxf_ptype(__u8 ptype);
132void xfrm_id_info_print(xfrm_address_t *saddr, struct xfrm_id *id,
133			__u8 mode, __u32 reqid, __u16 family, int force_spi,
134			FILE *fp, const char *prefix, const char *title);
135void xfrm_stats_print(struct xfrm_stats *s, FILE *fp, const char *prefix);
136void xfrm_lifetime_print(struct xfrm_lifetime_cfg *cfg,
137			 struct xfrm_lifetime_cur *cur,
138			 FILE *fp, const char *prefix);
139void xfrm_selector_print(struct xfrm_selector *sel, __u16 family,
140			 FILE *fp, const char *prefix);
141void xfrm_xfrma_print(struct rtattr *tb[], __u16 family,
142		      FILE *fp, const char *prefix);
143void xfrm_state_info_print(struct xfrm_usersa_info *xsinfo,
144			    struct rtattr *tb[], FILE *fp, const char *prefix,
145			   const char *title);
146void xfrm_policy_info_print(struct xfrm_userpolicy_info *xpinfo,
147			    struct rtattr *tb[], FILE *fp, const char *prefix,
148			    const char *title);
149int xfrm_id_parse(xfrm_address_t *saddr, struct xfrm_id *id, __u16 *family,
150		  int loose, int *argcp, char ***argvp);
151int xfrm_mode_parse(__u8 *mode, int *argcp, char ***argvp);
152int xfrm_encap_type_parse(__u16 *type, int *argcp, char ***argvp);
153int xfrm_reqid_parse(__u32 *reqid, int *argcp, char ***argvp);
154int xfrm_selector_parse(struct xfrm_selector *sel, int *argcp, char ***argvp);
155int xfrm_lifetime_cfg_parse(struct xfrm_lifetime_cfg *lft,
156			    int *argcp, char ***argvp);
157int xfrm_sctx_parse(char *ctxstr, char *context,
158		    struct xfrm_user_sec_ctx *sctx);
159#endif
160