1224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng/*
2224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * Copyright (c) 2003+ Evgeniy Polyakov <johnpol@2ka.mxt.ru>
3224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng *
4224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng *
5224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * This program is free software; you can redistribute it and/or modify
6224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * it under the terms of the GNU General Public License as published by
7224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * the Free Software Foundation; either version 2 of the License, or
8224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * (at your option) any later version.
9224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng *
10224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * This program is distributed in the hope that it will be useful,
11224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * but WITHOUT ANY WARRANTY; without even the implied warranty of
12224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
13224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * GNU General Public License for more details.
14224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng *
15224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * You should have received a copy of the GNU General Public License
16e084501669a4e4931c9d648351ecd7d595b81b79Christopher Ferris * along with this program; if not, see <http://www.gnu.org/licenses/>.
17224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng */
18224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
19224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#ifndef _XT_OSF_H
20224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define _XT_OSF_H
21224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
22224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#include <linux/types.h>
23224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
24224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define MAXGENRELEN		32
25224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
26224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_GENRE		(1<<0)
27224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define	XT_OSF_TTL		(1<<1)
28224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_LOG		(1<<2)
29224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_INVERT		(1<<3)
30224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
31224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_LOGLEVEL_ALL	0	/* log all matched fingerprints */
32224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_LOGLEVEL_FIRST	1	/* log only the first matced fingerprint */
33224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_LOGLEVEL_ALL_KNOWN	2 /* do not log unknown packets */
34224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
35224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_TTL_TRUE		0	/* True ip and fingerprint TTL comparison */
36224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_TTL_LESS		1	/* Check if ip TTL is less than fingerprint one */
37224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#define XT_OSF_TTL_NOCHECK	2	/* Do not compare ip and fingerprint TTL at all */
38224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
39224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengstruct xt_osf_info {
40224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	char			genre[MAXGENRELEN];
41224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u32			len;
42224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u32			flags;
43224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u32			loglevel;
44224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u32			ttl;
45224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
46224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
47224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng/*
48224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * Wildcard MSS (kind of).
49224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * It is used to implement a state machine for the different wildcard values
50224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * of the MSS and window sizes.
51224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng */
52224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengstruct xt_osf_wc {
53224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u32			wc;
54224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u32			val;
55224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
56224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
57224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng/*
58224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * This struct represents IANA options
59224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * http://www.iana.org/assignments/tcp-parameters
60224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng */
61224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengstruct xt_osf_opt {
62224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u16			kind, length;
63224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	struct xt_osf_wc	wc;
64224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
65224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
66224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengstruct xt_osf_user_finger {
67224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	struct xt_osf_wc	wss;
68224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
69224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u8			ttl, df;
70224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u16			ss, mss;
71224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	__u16			opt_num;
72224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
73224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	char			genre[MAXGENRELEN];
74224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	char			version[MAXGENRELEN];
75224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	char			subtype[MAXGENRELEN];
76224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
77224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	/* MAX_IPOPTLEN is maximum if all options are NOPs or EOLs */
78224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	struct xt_osf_opt	opt[MAX_IPOPTLEN];
79224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
80224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
81224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengstruct xt_osf_nlmsg {
82224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	struct xt_osf_user_finger	f;
83224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	struct iphdr		ip;
84224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	struct tcphdr		tcp;
85224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
86224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
87224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng/* Defines for IANA option kinds */
88224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
89224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengenum iana_options {
90224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_EOL = 0,		/* End of options */
91224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_NOP, 		/* NOP */
92224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_MSS, 		/* Maximum segment size */
93224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_WSO, 		/* Window scale option */
94224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_SACKP,		/* SACK permitted */
95224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_SACK,		/* SACK */
96224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_ECHO,
97224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_ECHOREPLY,
98224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_TS,		/* Timestamp option */
99224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_POCP,		/* Partial Order Connection Permitted */
100224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_POSP,		/* Partial Order Service Profile */
101224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
102224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	/* Others are not used in the current OSF */
103224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSFOPT_EMPTY = 255,
104224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
105224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
106224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng/*
107224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * Initial window size option state machine: multiple of mss, mtu or
108224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * plain numeric value. Can also be made as plain numeric value which
109224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * is not a multiple of specified value.
110224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng */
111224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengenum xt_osf_window_size_options {
112224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_WSS_PLAIN	= 0,
113224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_WSS_MSS,
114224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_WSS_MTU,
115224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_WSS_MODULO,
116224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_WSS_MAX,
117224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
118224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
119224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng/*
120224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng * Add/remove fingerprint from the kernel.
121224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng */
122224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengenum xt_osf_msg_types {
123224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_MSG_ADD,
124224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_MSG_REMOVE,
125224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_MSG_MAX,
126224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
127224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
128224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Chengenum xt_osf_attr_type {
129224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_ATTR_UNSPEC,
130224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_ATTR_FINGER,
131224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng	OSF_ATTR_MAX,
132224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng};
133224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng
134224b54f69543a5c0ec18f99bd717d2b724582eb6Ben Cheng#endif				/* _XT_OSF_H */
135