2005-08-10 02:32:58 +00:00
|
|
|
#ifndef _IPCONNTRACK_NETLINK_H
|
|
|
|
#define _IPCONNTRACK_NETLINK_H
|
|
|
|
#include <linux/netfilter/nfnetlink.h>
|
|
|
|
|
|
|
|
enum cntl_msg_types {
|
|
|
|
IPCTNL_MSG_CT_NEW,
|
|
|
|
IPCTNL_MSG_CT_GET,
|
|
|
|
IPCTNL_MSG_CT_DELETE,
|
|
|
|
IPCTNL_MSG_CT_GET_CTRZERO,
|
|
|
|
|
|
|
|
IPCTNL_MSG_MAX
|
|
|
|
};
|
|
|
|
|
|
|
|
enum ctnl_exp_msg_types {
|
|
|
|
IPCTNL_MSG_EXP_NEW,
|
|
|
|
IPCTNL_MSG_EXP_GET,
|
|
|
|
IPCTNL_MSG_EXP_DELETE,
|
|
|
|
|
|
|
|
IPCTNL_MSG_EXP_MAX
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
enum ctattr_type {
|
|
|
|
CTA_UNSPEC,
|
|
|
|
CTA_TUPLE_ORIG,
|
|
|
|
CTA_TUPLE_REPLY,
|
|
|
|
CTA_STATUS,
|
|
|
|
CTA_PROTOINFO,
|
|
|
|
CTA_HELP,
|
2006-05-30 01:24:39 +00:00
|
|
|
CTA_NAT_SRC,
|
|
|
|
#define CTA_NAT CTA_NAT_SRC /* backwards compatibility */
|
2005-08-10 02:32:58 +00:00
|
|
|
CTA_TIMEOUT,
|
|
|
|
CTA_MARK,
|
|
|
|
CTA_COUNTERS_ORIG,
|
|
|
|
CTA_COUNTERS_REPLY,
|
|
|
|
CTA_USE,
|
|
|
|
CTA_ID,
|
2006-05-30 01:24:39 +00:00
|
|
|
CTA_NAT_DST,
|
2007-09-28 21:43:53 +00:00
|
|
|
CTA_TUPLE_MASTER,
|
2007-12-18 06:28:00 +00:00
|
|
|
CTA_NAT_SEQ_ADJ_ORIG,
|
|
|
|
CTA_NAT_SEQ_ADJ_REPLY,
|
2007-12-18 06:28:41 +00:00
|
|
|
CTA_SECMARK,
|
2005-08-10 02:32:58 +00:00
|
|
|
__CTA_MAX
|
|
|
|
};
|
|
|
|
#define CTA_MAX (__CTA_MAX - 1)
|
|
|
|
|
|
|
|
enum ctattr_tuple {
|
|
|
|
CTA_TUPLE_UNSPEC,
|
|
|
|
CTA_TUPLE_IP,
|
|
|
|
CTA_TUPLE_PROTO,
|
|
|
|
__CTA_TUPLE_MAX
|
|
|
|
};
|
|
|
|
#define CTA_TUPLE_MAX (__CTA_TUPLE_MAX - 1)
|
|
|
|
|
|
|
|
enum ctattr_ip {
|
|
|
|
CTA_IP_UNSPEC,
|
|
|
|
CTA_IP_V4_SRC,
|
|
|
|
CTA_IP_V4_DST,
|
|
|
|
CTA_IP_V6_SRC,
|
|
|
|
CTA_IP_V6_DST,
|
|
|
|
__CTA_IP_MAX
|
|
|
|
};
|
|
|
|
#define CTA_IP_MAX (__CTA_IP_MAX - 1)
|
|
|
|
|
|
|
|
enum ctattr_l4proto {
|
|
|
|
CTA_PROTO_UNSPEC,
|
|
|
|
CTA_PROTO_NUM,
|
|
|
|
CTA_PROTO_SRC_PORT,
|
|
|
|
CTA_PROTO_DST_PORT,
|
|
|
|
CTA_PROTO_ICMP_ID,
|
|
|
|
CTA_PROTO_ICMP_TYPE,
|
|
|
|
CTA_PROTO_ICMP_CODE,
|
2006-01-05 20:19:05 +00:00
|
|
|
CTA_PROTO_ICMPV6_ID,
|
|
|
|
CTA_PROTO_ICMPV6_TYPE,
|
|
|
|
CTA_PROTO_ICMPV6_CODE,
|
2005-08-10 02:32:58 +00:00
|
|
|
__CTA_PROTO_MAX
|
|
|
|
};
|
|
|
|
#define CTA_PROTO_MAX (__CTA_PROTO_MAX - 1)
|
|
|
|
|
|
|
|
enum ctattr_protoinfo {
|
|
|
|
CTA_PROTOINFO_UNSPEC,
|
2005-10-11 03:55:49 +00:00
|
|
|
CTA_PROTOINFO_TCP,
|
2008-03-20 14:15:55 +00:00
|
|
|
CTA_PROTOINFO_DCCP,
|
2008-06-09 22:56:39 +00:00
|
|
|
CTA_PROTOINFO_SCTP,
|
2005-08-10 02:32:58 +00:00
|
|
|
__CTA_PROTOINFO_MAX
|
|
|
|
};
|
|
|
|
#define CTA_PROTOINFO_MAX (__CTA_PROTOINFO_MAX - 1)
|
|
|
|
|
2005-10-11 03:55:49 +00:00
|
|
|
enum ctattr_protoinfo_tcp {
|
|
|
|
CTA_PROTOINFO_TCP_UNSPEC,
|
|
|
|
CTA_PROTOINFO_TCP_STATE,
|
2007-03-14 23:45:19 +00:00
|
|
|
CTA_PROTOINFO_TCP_WSCALE_ORIGINAL,
|
|
|
|
CTA_PROTOINFO_TCP_WSCALE_REPLY,
|
|
|
|
CTA_PROTOINFO_TCP_FLAGS_ORIGINAL,
|
|
|
|
CTA_PROTOINFO_TCP_FLAGS_REPLY,
|
2005-10-11 03:55:49 +00:00
|
|
|
__CTA_PROTOINFO_TCP_MAX
|
|
|
|
};
|
|
|
|
#define CTA_PROTOINFO_TCP_MAX (__CTA_PROTOINFO_TCP_MAX - 1)
|
|
|
|
|
2008-03-20 14:15:55 +00:00
|
|
|
enum ctattr_protoinfo_dccp {
|
|
|
|
CTA_PROTOINFO_DCCP_UNSPEC,
|
|
|
|
CTA_PROTOINFO_DCCP_STATE,
|
|
|
|
__CTA_PROTOINFO_DCCP_MAX,
|
|
|
|
};
|
|
|
|
#define CTA_PROTOINFO_DCCP_MAX (__CTA_PROTOINFO_DCCP_MAX - 1)
|
|
|
|
|
2008-06-09 22:56:39 +00:00
|
|
|
enum ctattr_protoinfo_sctp {
|
|
|
|
CTA_PROTOINFO_SCTP_UNSPEC,
|
|
|
|
CTA_PROTOINFO_SCTP_STATE,
|
|
|
|
CTA_PROTOINFO_SCTP_VTAG_ORIGINAL,
|
|
|
|
CTA_PROTOINFO_SCTP_VTAG_REPLY,
|
|
|
|
__CTA_PROTOINFO_SCTP_MAX
|
|
|
|
};
|
|
|
|
#define CTA_PROTOINFO_SCTP_MAX (__CTA_PROTOINFO_SCTP_MAX - 1)
|
|
|
|
|
2005-08-10 02:32:58 +00:00
|
|
|
enum ctattr_counters {
|
|
|
|
CTA_COUNTERS_UNSPEC,
|
netfilter: accounting rework: ct_extend + 64bit counters (v4)
Initially netfilter has had 64bit counters for conntrack-based accounting, but
it was changed in 2.6.14 to save memory. Unfortunately in-kernel 64bit counters are
still required, for example for "connbytes" extension. However, 64bit counters
waste a lot of memory and it was not possible to enable/disable it runtime.
This patch:
- reimplements accounting with respect to the extension infrastructure,
- makes one global version of seq_print_acct() instead of two seq_print_counters(),
- makes it possible to enable it at boot time (for CONFIG_SYSCTL/CONFIG_SYSFS=n),
- makes it possible to enable/disable it at runtime by sysctl or sysfs,
- extends counters from 32bit to 64bit,
- renames ip_conntrack_counter -> nf_conn_counter,
- enables accounting code unconditionally (no longer depends on CONFIG_NF_CT_ACCT),
- set initial accounting enable state based on CONFIG_NF_CT_ACCT
- removes buggy IPCT_COUNTER_FILLING event handling.
If accounting is enabled newly created connections get additional acct extend.
Old connections are not changed as it is not possible to add a ct_extend area
to confirmed conntrack. Accounting is performed for all connections with
acct extend regardless of a current state of "net.netfilter.nf_conntrack_acct".
Signed-off-by: Krzysztof Piotr Oledzki <ole@ans.pl>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-07-21 17:01:34 +00:00
|
|
|
CTA_COUNTERS_PACKETS, /* 64bit counters */
|
|
|
|
CTA_COUNTERS_BYTES, /* 64bit counters */
|
|
|
|
CTA_COUNTERS32_PACKETS, /* old 32bit counters, unused */
|
|
|
|
CTA_COUNTERS32_BYTES, /* old 32bit counters, unused */
|
2005-08-10 02:32:58 +00:00
|
|
|
__CTA_COUNTERS_MAX
|
|
|
|
};
|
|
|
|
#define CTA_COUNTERS_MAX (__CTA_COUNTERS_MAX - 1)
|
|
|
|
|
|
|
|
enum ctattr_nat {
|
|
|
|
CTA_NAT_UNSPEC,
|
|
|
|
CTA_NAT_MINIP,
|
|
|
|
CTA_NAT_MAXIP,
|
|
|
|
CTA_NAT_PROTO,
|
|
|
|
__CTA_NAT_MAX
|
|
|
|
};
|
|
|
|
#define CTA_NAT_MAX (__CTA_NAT_MAX - 1)
|
|
|
|
|
|
|
|
enum ctattr_protonat {
|
|
|
|
CTA_PROTONAT_UNSPEC,
|
|
|
|
CTA_PROTONAT_PORT_MIN,
|
|
|
|
CTA_PROTONAT_PORT_MAX,
|
|
|
|
__CTA_PROTONAT_MAX
|
|
|
|
};
|
|
|
|
#define CTA_PROTONAT_MAX (__CTA_PROTONAT_MAX - 1)
|
|
|
|
|
2007-12-18 06:28:00 +00:00
|
|
|
enum ctattr_natseq {
|
2008-12-16 09:19:41 +00:00
|
|
|
CTA_NAT_SEQ_UNSPEC,
|
2007-12-18 06:28:00 +00:00
|
|
|
CTA_NAT_SEQ_CORRECTION_POS,
|
|
|
|
CTA_NAT_SEQ_OFFSET_BEFORE,
|
|
|
|
CTA_NAT_SEQ_OFFSET_AFTER,
|
|
|
|
__CTA_NAT_SEQ_MAX
|
|
|
|
};
|
|
|
|
#define CTA_NAT_SEQ_MAX (__CTA_NAT_SEQ_MAX - 1)
|
|
|
|
|
2005-08-10 02:32:58 +00:00
|
|
|
enum ctattr_expect {
|
|
|
|
CTA_EXPECT_UNSPEC,
|
2005-08-10 03:04:07 +00:00
|
|
|
CTA_EXPECT_MASTER,
|
2005-08-10 02:32:58 +00:00
|
|
|
CTA_EXPECT_TUPLE,
|
|
|
|
CTA_EXPECT_MASK,
|
|
|
|
CTA_EXPECT_TIMEOUT,
|
|
|
|
CTA_EXPECT_ID,
|
2005-08-10 03:04:07 +00:00
|
|
|
CTA_EXPECT_HELP_NAME,
|
2005-08-10 02:32:58 +00:00
|
|
|
__CTA_EXPECT_MAX
|
|
|
|
};
|
|
|
|
#define CTA_EXPECT_MAX (__CTA_EXPECT_MAX - 1)
|
|
|
|
|
|
|
|
enum ctattr_help {
|
|
|
|
CTA_HELP_UNSPEC,
|
|
|
|
CTA_HELP_NAME,
|
|
|
|
__CTA_HELP_MAX
|
|
|
|
};
|
|
|
|
#define CTA_HELP_MAX (__CTA_HELP_MAX - 1)
|
|
|
|
|
|
|
|
#endif /* _IPCONNTRACK_NETLINK_H */
|