1*a71a9546SAutomerger Merge Worker /*
2*a71a9546SAutomerger Merge Worker * Shared library add-on to iptables to add TCPOPTSTRIP target support.
3*a71a9546SAutomerger Merge Worker * Copyright (c) 2007 Sven Schnelle <[email protected]>
4*a71a9546SAutomerger Merge Worker * Copyright © CC Computer Consultants GmbH, 2007
5*a71a9546SAutomerger Merge Worker * Jan Engelhardt <[email protected]>
6*a71a9546SAutomerger Merge Worker */
7*a71a9546SAutomerger Merge Worker #include <stdio.h>
8*a71a9546SAutomerger Merge Worker #include <string.h>
9*a71a9546SAutomerger Merge Worker #include <xtables.h>
10*a71a9546SAutomerger Merge Worker #include <netinet/tcp.h>
11*a71a9546SAutomerger Merge Worker #include <linux/netfilter/xt_TCPOPTSTRIP.h>
12*a71a9546SAutomerger Merge Worker #ifndef TCPOPT_MD5SIG
13*a71a9546SAutomerger Merge Worker # define TCPOPT_MD5SIG 19
14*a71a9546SAutomerger Merge Worker #endif
15*a71a9546SAutomerger Merge Worker #ifndef TCPOPT_MAXSEG
16*a71a9546SAutomerger Merge Worker # define TCPOPT_MAXSEG 2
17*a71a9546SAutomerger Merge Worker #endif
18*a71a9546SAutomerger Merge Worker #ifndef TCPOPT_WINDOW
19*a71a9546SAutomerger Merge Worker # define TCPOPT_WINDOW 3
20*a71a9546SAutomerger Merge Worker #endif
21*a71a9546SAutomerger Merge Worker #ifndef TCPOPT_SACK_PERMITTED
22*a71a9546SAutomerger Merge Worker # define TCPOPT_SACK_PERMITTED 4
23*a71a9546SAutomerger Merge Worker #endif
24*a71a9546SAutomerger Merge Worker #ifndef TCPOPT_SACK
25*a71a9546SAutomerger Merge Worker # define TCPOPT_SACK 5
26*a71a9546SAutomerger Merge Worker #endif
27*a71a9546SAutomerger Merge Worker #ifndef TCPOPT_TIMESTAMP
28*a71a9546SAutomerger Merge Worker # define TCPOPT_TIMESTAMP 8
29*a71a9546SAutomerger Merge Worker #endif
30*a71a9546SAutomerger Merge Worker
31*a71a9546SAutomerger Merge Worker enum {
32*a71a9546SAutomerger Merge Worker O_STRIP_OPTION = 0,
33*a71a9546SAutomerger Merge Worker };
34*a71a9546SAutomerger Merge Worker
35*a71a9546SAutomerger Merge Worker struct tcp_optionmap {
36*a71a9546SAutomerger Merge Worker const char *name, *desc;
37*a71a9546SAutomerger Merge Worker const unsigned int option;
38*a71a9546SAutomerger Merge Worker };
39*a71a9546SAutomerger Merge Worker
40*a71a9546SAutomerger Merge Worker static const struct xt_option_entry tcpoptstrip_tg_opts[] = {
41*a71a9546SAutomerger Merge Worker {.name = "strip-options", .id = O_STRIP_OPTION, .type = XTTYPE_STRING},
42*a71a9546SAutomerger Merge Worker XTOPT_TABLEEND,
43*a71a9546SAutomerger Merge Worker };
44*a71a9546SAutomerger Merge Worker
45*a71a9546SAutomerger Merge Worker static const struct tcp_optionmap tcp_optionmap[] = {
46*a71a9546SAutomerger Merge Worker {"wscale", "Window scale", TCPOPT_WINDOW},
47*a71a9546SAutomerger Merge Worker {"mss", "Maximum Segment Size", TCPOPT_MAXSEG},
48*a71a9546SAutomerger Merge Worker {"sack-permitted", "SACK permitted", TCPOPT_SACK_PERMITTED},
49*a71a9546SAutomerger Merge Worker {"sack", "Selective ACK", TCPOPT_SACK},
50*a71a9546SAutomerger Merge Worker {"timestamp", "Timestamp", TCPOPT_TIMESTAMP},
51*a71a9546SAutomerger Merge Worker {"md5", "MD5 signature", TCPOPT_MD5SIG},
52*a71a9546SAutomerger Merge Worker {NULL},
53*a71a9546SAutomerger Merge Worker };
54*a71a9546SAutomerger Merge Worker
tcpoptstrip_tg_help(void)55*a71a9546SAutomerger Merge Worker static void tcpoptstrip_tg_help(void)
56*a71a9546SAutomerger Merge Worker {
57*a71a9546SAutomerger Merge Worker const struct tcp_optionmap *w;
58*a71a9546SAutomerger Merge Worker
59*a71a9546SAutomerger Merge Worker printf(
60*a71a9546SAutomerger Merge Worker "TCPOPTSTRIP target options:\n"
61*a71a9546SAutomerger Merge Worker " --strip-options value strip specified TCP options denoted by value\n"
62*a71a9546SAutomerger Merge Worker " (separated by comma) from TCP header\n"
63*a71a9546SAutomerger Merge Worker " Instead of the numeric value, you can also use the following names:\n"
64*a71a9546SAutomerger Merge Worker );
65*a71a9546SAutomerger Merge Worker
66*a71a9546SAutomerger Merge Worker for (w = tcp_optionmap; w->name != NULL; ++w)
67*a71a9546SAutomerger Merge Worker printf(" %-14s strip \"%s\" option\n", w->name, w->desc);
68*a71a9546SAutomerger Merge Worker }
69*a71a9546SAutomerger Merge Worker
70*a71a9546SAutomerger Merge Worker static void
parse_list(struct xt_tcpoptstrip_target_info * info,const char * arg)71*a71a9546SAutomerger Merge Worker parse_list(struct xt_tcpoptstrip_target_info *info, const char *arg)
72*a71a9546SAutomerger Merge Worker {
73*a71a9546SAutomerger Merge Worker unsigned int option;
74*a71a9546SAutomerger Merge Worker char *p;
75*a71a9546SAutomerger Merge Worker int i;
76*a71a9546SAutomerger Merge Worker
77*a71a9546SAutomerger Merge Worker while (true) {
78*a71a9546SAutomerger Merge Worker p = strchr(arg, ',');
79*a71a9546SAutomerger Merge Worker if (p != NULL)
80*a71a9546SAutomerger Merge Worker *p = '\0';
81*a71a9546SAutomerger Merge Worker
82*a71a9546SAutomerger Merge Worker option = 0;
83*a71a9546SAutomerger Merge Worker for (i = 0; tcp_optionmap[i].name != NULL; ++i)
84*a71a9546SAutomerger Merge Worker if (strcmp(tcp_optionmap[i].name, arg) == 0) {
85*a71a9546SAutomerger Merge Worker option = tcp_optionmap[i].option;
86*a71a9546SAutomerger Merge Worker break;
87*a71a9546SAutomerger Merge Worker }
88*a71a9546SAutomerger Merge Worker
89*a71a9546SAutomerger Merge Worker if (option == 0 &&
90*a71a9546SAutomerger Merge Worker !xtables_strtoui(arg, NULL, &option, 0, UINT8_MAX))
91*a71a9546SAutomerger Merge Worker xtables_error(PARAMETER_PROBLEM,
92*a71a9546SAutomerger Merge Worker "Bad TCP option value \"%s\"", arg);
93*a71a9546SAutomerger Merge Worker
94*a71a9546SAutomerger Merge Worker if (option < 2)
95*a71a9546SAutomerger Merge Worker xtables_error(PARAMETER_PROBLEM,
96*a71a9546SAutomerger Merge Worker "Option value may not be 0 or 1");
97*a71a9546SAutomerger Merge Worker
98*a71a9546SAutomerger Merge Worker if (tcpoptstrip_test_bit(info->strip_bmap, option))
99*a71a9546SAutomerger Merge Worker xtables_error(PARAMETER_PROBLEM,
100*a71a9546SAutomerger Merge Worker "Option \"%s\" already specified", arg);
101*a71a9546SAutomerger Merge Worker
102*a71a9546SAutomerger Merge Worker tcpoptstrip_set_bit(info->strip_bmap, option);
103*a71a9546SAutomerger Merge Worker if (p == NULL)
104*a71a9546SAutomerger Merge Worker break;
105*a71a9546SAutomerger Merge Worker arg = p + 1;
106*a71a9546SAutomerger Merge Worker }
107*a71a9546SAutomerger Merge Worker }
108*a71a9546SAutomerger Merge Worker
tcpoptstrip_tg_parse(struct xt_option_call * cb)109*a71a9546SAutomerger Merge Worker static void tcpoptstrip_tg_parse(struct xt_option_call *cb)
110*a71a9546SAutomerger Merge Worker {
111*a71a9546SAutomerger Merge Worker struct xt_tcpoptstrip_target_info *info = cb->data;
112*a71a9546SAutomerger Merge Worker
113*a71a9546SAutomerger Merge Worker xtables_option_parse(cb);
114*a71a9546SAutomerger Merge Worker parse_list(info, cb->arg);
115*a71a9546SAutomerger Merge Worker }
116*a71a9546SAutomerger Merge Worker
117*a71a9546SAutomerger Merge Worker static void
tcpoptstrip_print_list(const struct xt_tcpoptstrip_target_info * info,bool numeric)118*a71a9546SAutomerger Merge Worker tcpoptstrip_print_list(const struct xt_tcpoptstrip_target_info *info,
119*a71a9546SAutomerger Merge Worker bool numeric)
120*a71a9546SAutomerger Merge Worker {
121*a71a9546SAutomerger Merge Worker unsigned int i, j;
122*a71a9546SAutomerger Merge Worker const char *name;
123*a71a9546SAutomerger Merge Worker bool first = true;
124*a71a9546SAutomerger Merge Worker
125*a71a9546SAutomerger Merge Worker for (i = 0; i < 256; ++i) {
126*a71a9546SAutomerger Merge Worker if (!tcpoptstrip_test_bit(info->strip_bmap, i))
127*a71a9546SAutomerger Merge Worker continue;
128*a71a9546SAutomerger Merge Worker if (!first)
129*a71a9546SAutomerger Merge Worker printf(",");
130*a71a9546SAutomerger Merge Worker
131*a71a9546SAutomerger Merge Worker first = false;
132*a71a9546SAutomerger Merge Worker name = NULL;
133*a71a9546SAutomerger Merge Worker if (!numeric)
134*a71a9546SAutomerger Merge Worker for (j = 0; tcp_optionmap[j].name != NULL; ++j)
135*a71a9546SAutomerger Merge Worker if (tcp_optionmap[j].option == i)
136*a71a9546SAutomerger Merge Worker name = tcp_optionmap[j].name;
137*a71a9546SAutomerger Merge Worker
138*a71a9546SAutomerger Merge Worker if (name != NULL)
139*a71a9546SAutomerger Merge Worker printf("%s", name);
140*a71a9546SAutomerger Merge Worker else
141*a71a9546SAutomerger Merge Worker printf("%u", i);
142*a71a9546SAutomerger Merge Worker }
143*a71a9546SAutomerger Merge Worker }
144*a71a9546SAutomerger Merge Worker
tcpoptstrip_empty(const struct xt_tcpoptstrip_target_info * info)145*a71a9546SAutomerger Merge Worker static bool tcpoptstrip_empty(const struct xt_tcpoptstrip_target_info *info)
146*a71a9546SAutomerger Merge Worker {
147*a71a9546SAutomerger Merge Worker static const struct xt_tcpoptstrip_target_info empty = {};
148*a71a9546SAutomerger Merge Worker
149*a71a9546SAutomerger Merge Worker return memcmp(info, &empty, sizeof(empty)) == 0;
150*a71a9546SAutomerger Merge Worker }
151*a71a9546SAutomerger Merge Worker
152*a71a9546SAutomerger Merge Worker static void
tcpoptstrip_tg_print(const void * ip,const struct xt_entry_target * target,int numeric)153*a71a9546SAutomerger Merge Worker tcpoptstrip_tg_print(const void *ip, const struct xt_entry_target *target,
154*a71a9546SAutomerger Merge Worker int numeric)
155*a71a9546SAutomerger Merge Worker {
156*a71a9546SAutomerger Merge Worker const struct xt_tcpoptstrip_target_info *info =
157*a71a9546SAutomerger Merge Worker (const void *)target->data;
158*a71a9546SAutomerger Merge Worker
159*a71a9546SAutomerger Merge Worker if (tcpoptstrip_empty(info))
160*a71a9546SAutomerger Merge Worker return;
161*a71a9546SAutomerger Merge Worker
162*a71a9546SAutomerger Merge Worker printf(" TCPOPTSTRIP options ");
163*a71a9546SAutomerger Merge Worker tcpoptstrip_print_list(info, numeric);
164*a71a9546SAutomerger Merge Worker }
165*a71a9546SAutomerger Merge Worker
166*a71a9546SAutomerger Merge Worker static void
tcpoptstrip_tg_save(const void * ip,const struct xt_entry_target * target)167*a71a9546SAutomerger Merge Worker tcpoptstrip_tg_save(const void *ip, const struct xt_entry_target *target)
168*a71a9546SAutomerger Merge Worker {
169*a71a9546SAutomerger Merge Worker const struct xt_tcpoptstrip_target_info *info =
170*a71a9546SAutomerger Merge Worker (const void *)target->data;
171*a71a9546SAutomerger Merge Worker
172*a71a9546SAutomerger Merge Worker if (tcpoptstrip_empty(info))
173*a71a9546SAutomerger Merge Worker return;
174*a71a9546SAutomerger Merge Worker
175*a71a9546SAutomerger Merge Worker printf(" --strip-options ");
176*a71a9546SAutomerger Merge Worker tcpoptstrip_print_list(info, true);
177*a71a9546SAutomerger Merge Worker }
178*a71a9546SAutomerger Merge Worker
179*a71a9546SAutomerger Merge Worker static struct xtables_target tcpoptstrip_tg_reg = {
180*a71a9546SAutomerger Merge Worker .version = XTABLES_VERSION,
181*a71a9546SAutomerger Merge Worker .name = "TCPOPTSTRIP",
182*a71a9546SAutomerger Merge Worker .family = NFPROTO_UNSPEC,
183*a71a9546SAutomerger Merge Worker .size = XT_ALIGN(sizeof(struct xt_tcpoptstrip_target_info)),
184*a71a9546SAutomerger Merge Worker .userspacesize = XT_ALIGN(sizeof(struct xt_tcpoptstrip_target_info)),
185*a71a9546SAutomerger Merge Worker .help = tcpoptstrip_tg_help,
186*a71a9546SAutomerger Merge Worker .print = tcpoptstrip_tg_print,
187*a71a9546SAutomerger Merge Worker .save = tcpoptstrip_tg_save,
188*a71a9546SAutomerger Merge Worker .x6_parse = tcpoptstrip_tg_parse,
189*a71a9546SAutomerger Merge Worker .x6_options = tcpoptstrip_tg_opts,
190*a71a9546SAutomerger Merge Worker };
191*a71a9546SAutomerger Merge Worker
_init(void)192*a71a9546SAutomerger Merge Worker void _init(void)
193*a71a9546SAutomerger Merge Worker {
194*a71a9546SAutomerger Merge Worker xtables_register_target(&tcpoptstrip_tg_reg);
195*a71a9546SAutomerger Merge Worker }
196