1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
|
#ifndef _ULOGD_H
#define _ULOGD_H
/* ulogd, Version $Revision$
*
* userspace logging daemon for netfilter ULOG target
* of the linux 2.4/2.6 netfilter subsystem.
*
* (C) 2000-2005 by Harald Welte <laforge@gnumonks.org>
*
* this code is released under the terms of GNU GPL
*
* $Id$
*/
#include <ulogd/linuxlist.h>
#include <ulogd/conffile.h>
#include <ulogd/ipfix_protocol.h>
#include <stdio.h>
#include <signal.h> /* need this because of extension-sighandler */
#include <sys/types.h>
#include <string.h>
#include <config.h>
#define ARRAY_SIZE(x) (sizeof(x) / sizeof((x)[0]))
#define ULOGD_VERSION "2.0.0beta"
/* All types with MSB = 1 make use of value.ptr
* other types use one of the union's member */
/* types without length */
#define ULOGD_RET_NONE 0x0000
#define ULOGD_RET_INT8 0x0001
#define ULOGD_RET_INT16 0x0002
#define ULOGD_RET_INT32 0x0003
#define ULOGD_RET_INT64 0x0004
#define ULOGD_RET_UINT8 0x0011
#define ULOGD_RET_UINT16 0x0012
#define ULOGD_RET_UINT32 0x0013
#define ULOGD_RET_UINT64 0x0014
#define ULOGD_RET_BOOL 0x0050
#define ULOGD_RET_IPADDR 0x0100
#define ULOGD_RET_IP6ADDR 0x0200
/* types with length field */
#define ULOGD_RET_STRING 0x8020
#define ULOGD_RET_RAW 0x8030
#define ULOGD_RET_RAWSTR 0x8040
/* FLAGS */
#define ULOGD_RETF_NONE 0x0000
#define ULOGD_RETF_VALID 0x0001 /* contains a valid result */
#define ULOGD_RETF_FREE 0x0002 /* ptr needs to be free()d */
#define ULOGD_RETF_NEEDED 0x0004 /* this parameter is actually needed
* by some downstream plugin */
#define ULOGD_KEYF_OPTIONAL 0x0100 /* this key is optional */
#define ULOGD_KEYF_INACTIVE 0x0200 /* marked as inactive (i.e. totally
to be ignored by everyone */
/* maximum length of ulogd key */
#define ULOGD_MAX_KEYLEN 31
#define ULOGD_DEBUG 1 /* debugging information */
#define ULOGD_INFO 3
#define ULOGD_NOTICE 5 /* abnormal/unexpected condition */
#define ULOGD_ERROR 7 /* error condition, requires user action */
#define ULOGD_FATAL 8 /* fatal, program aborted */
/* ulogd data type */
enum ulogd_dtype {
ULOGD_DTYPE_NULL = 0x0000,
ULOGD_DTYPE_SOURCE = 0x0001, /* source of data, no input keys */
ULOGD_DTYPE_RAW = 0x0002, /* raw packet data */
ULOGD_DTYPE_PACKET = 0x0004, /* packet metadata */
ULOGD_DTYPE_FLOW = 0x0008, /* flow metadata */
ULOGD_DTYPE_SINK = 0x0010, /* sink of data, no output keys */
};
/* structure describing an input / output parameter of a plugin */
struct ulogd_key {
/* length of the returned value (only for lengthed types */
u_int32_t len;
/* type of the returned value (ULOGD_DTYPE_...) */
u_int16_t type;
/* flags (i.e. free, ...) */
u_int16_t flags;
/* name of this key */
char name[ULOGD_MAX_KEYLEN+1];
/* IETF IPFIX attribute ID */
struct {
u_int32_t vendor;
u_int16_t field_id;
} ipfix;
union {
/* and finally the returned value */
union {
u_int8_t b;
u_int8_t ui8;
u_int16_t ui16;
u_int32_t ui32;
u_int64_t ui64;
u_int32_t ui128[4];
int8_t i8;
int16_t i16;
int32_t i32;
int64_t i64;
int32_t i128[4];
void *ptr;
} value;
struct ulogd_key *source;
} u;
};
struct ulogd_keyset {
/* possible input keys of this interpreter */
struct ulogd_key *keys;
/* number of input keys */
unsigned int num_keys;
/* bitmask of possible types */
unsigned int type;
};
static inline void okey_set_b(struct ulogd_key *key, u_int8_t value)
{
key->u.value.b = value;
key->flags |= ULOGD_RETF_VALID;
}
static inline void okey_set_u8(struct ulogd_key *key, u_int8_t value)
{
key->u.value.ui8 = value;
key->flags |= ULOGD_RETF_VALID;
}
static inline void okey_set_u16(struct ulogd_key *key, u_int16_t value)
{
key->u.value.ui16 = value;
key->flags |= ULOGD_RETF_VALID;
}
static inline void okey_set_u32(struct ulogd_key *key, u_int32_t value)
{
key->u.value.ui32 = value;
key->flags |= ULOGD_RETF_VALID;
}
static inline void okey_set_u128(struct ulogd_key *key, const void *value)
{
memcpy(key->u.value.ui128, value, 16);
key->flags |= ULOGD_RETF_VALID;
}
static inline void okey_set_ptr(struct ulogd_key *key, void *value)
{
key->u.value.ptr = value;
key->flags |= ULOGD_RETF_VALID;
}
static inline u_int8_t ikey_get_u8(struct ulogd_key *key)
{
return key->u.source->u.value.ui8;
}
static inline u_int16_t ikey_get_u16(struct ulogd_key *key)
{
return key->u.source->u.value.ui16;
}
static inline u_int32_t ikey_get_u32(struct ulogd_key *key)
{
return key->u.source->u.value.ui32;
}
static inline void *ikey_get_u128(struct ulogd_key *key)
{
return &key->u.source->u.value.ui128;
}
static inline void *ikey_get_ptr(struct ulogd_key *key)
{
return key->u.source->u.value.ptr;
}
struct ulogd_pluginstance_stack;
struct ulogd_pluginstance;
struct ulogd_plugin_handle {
/* global list of plugins */
struct llist_head list;
void *handle;
};
struct ulogd_plugin {
/* global list of plugins */
struct llist_head list;
/* version */
char *version;
/* name of this plugin (predefined by plugin) */
char name[ULOGD_MAX_KEYLEN+1];
/* ID for this plugin (dynamically assigned) */
unsigned int id;
struct ulogd_keyset input;
struct ulogd_keyset output;
/* function to call for each packet */
int (*interp)(struct ulogd_pluginstance *instance);
int (*configure)(struct ulogd_pluginstance *instance,
struct ulogd_pluginstance_stack *stack);
/* function to construct a new pluginstance */
int (*start)(struct ulogd_pluginstance *pi);
/* function to destruct an existing pluginstance */
int (*stop)(struct ulogd_pluginstance *pi);
/* function to receive a signal */
void (*signal)(struct ulogd_pluginstance *pi, int signal);
/* configuration parameters */
struct config_keyset *config_kset;
/* size of instance->priv */
unsigned int priv_size;
};
#define ULOGD_IRET_ERR -1
#define ULOGD_IRET_STOP -2
#define ULOGD_IRET_OK 0
/* an instance of a plugin, element in a stack */
struct ulogd_pluginstance {
/* local list of plugins in this stack */
struct llist_head list;
/* local list of plugininstance in other stacks */
struct llist_head plist;
/* plugin */
struct ulogd_plugin *plugin;
/* stack that we're part of */
struct ulogd_pluginstance_stack *stack;
/* name / id of this instance*/
char id[ULOGD_MAX_KEYLEN+1];
/* per-instance input keys */
struct ulogd_keyset input;
/* per-instance output keys */
struct ulogd_keyset output;
/* per-instance config parameters (array) */
struct config_keyset *config_kset;
/* private data */
char private[0];
};
struct ulogd_pluginstance_stack {
/* global list of pluginstance stacks */
struct llist_head stack_list;
/* list of plugins in this stack */
struct llist_head list;
char *name;
};
/***********************************************************************
* PUBLIC INTERFACE
***********************************************************************/
void ulogd_propagate_results(struct ulogd_pluginstance *pi);
/* register a new interpreter plugin */
void ulogd_register_plugin(struct ulogd_plugin *me);
/* allocate a new ulogd_key */
struct ulogd_key *alloc_ret(const u_int16_t type, const char*);
/* write a message to the daemons' logfile */
void __ulogd_log(int level, char *file, int line, const char *message, ...);
/* macro for logging including filename and line number */
#define ulogd_log(level, format, args...) \
__ulogd_log(level, __FILE__, __LINE__, format, ## args)
/* backwards compatibility */
#define ulogd_error(format, args...) ulogd_log(ULOGD_ERROR, format, ## args)
#define IS_VALID(x) ((x).flags & ULOGD_RETF_VALID)
#define SET_VALID(x) (x.flags |= ULOGD_RETF_VALID)
#define IS_NEEDED(x) (x.flags & ULOGD_RETF_NEEDED)
#define SET_NEEDED(x) (x.flags |= ULOGD_RETF_NEEDED)
#define GET_FLAGS(res, x) (res[x].u.source->flags)
#define pp_is_valid(res, x) \
(res[x].u.source && (GET_FLAGS(res, x) & ULOGD_RETF_VALID))
int ulogd_key_size(struct ulogd_key *key);
int ulogd_wildcard_inputkeys(struct ulogd_pluginstance *upi);
/***********************************************************************
* file descriptor handling
***********************************************************************/
#define ULOGD_FD_READ 0x0001
#define ULOGD_FD_WRITE 0x0002
#define ULOGD_FD_EXCEPT 0x0004
struct ulogd_fd {
struct llist_head list;
int fd; /* file descriptor */
unsigned int when;
int (*cb)(int fd, unsigned int what, void *data);
void *data; /* void * to pass to callback */
};
int ulogd_register_fd(struct ulogd_fd *ufd);
void ulogd_unregister_fd(struct ulogd_fd *ufd);
int ulogd_select_main(struct timeval *tv);
/***********************************************************************
* timer handling
***********************************************************************/
#include <ulogd/timer.h>
/***********************************************************************
* other declarations
***********************************************************************/
#ifndef IPPROTO_DCCP
#define IPPROTO_DCCP 33
#endif
#ifndef IPPROTO_UDPLITE
#define IPPROTO_UDPLITE 136
#endif
#endif /* _ULOGD_H */
|