VirtualBox

source: vbox/trunk/src/VBox/Devices/Network/slirp/slirp.c@ 22452

最後變更 在這個檔案從22452是 22449,由 vboxsync 提交於 16 年 前

NAT: re-counters

  • 屬性 svn:eol-style 設為 native
檔案大小: 55.6 KB
 
1#include "slirp.h"
2#ifdef RT_OS_OS2
3# include <paths.h>
4#endif
5
6#include <VBox/err.h>
7#include <VBox/pdmdrv.h>
8#include <iprt/assert.h>
9#ifndef RT_OS_WINDOWS
10# include <sys/ioctl.h>
11# include <poll.h>
12#else
13# include <Winnls.h>
14# define _WINSOCK2API_
15# include <IPHlpApi.h>
16#endif
17#include <alias.h>
18
19#if !defined(RT_OS_WINDOWS)
20
21# define DO_ENGAGE_EVENT1(so, fdset, label) \
22 do { \
23 if( so->so_poll_index != -1 \
24 && so->s == polls[so->so_poll_index].fd) { \
25 polls[so->so_poll_index].events |= N_(fdset ## _poll); \
26 break; /* out of this loop */ \
27 } \
28 AssertRelease(poll_index < (nfds)); \
29 AssertRelease(poll_index >= 0 && poll_index < (nfds)); \
30 polls[poll_index].fd = (so)->s; \
31 (so)->so_poll_index = poll_index; \
32 polls[poll_index].events = N_(fdset ## _poll); \
33 polls[poll_index].revents = 0; \
34 poll_index++; \
35 } while(0)
36
37
38# define DO_ENGAGE_EVENT2(so, fdset1, fdset2, label) \
39 do { \
40 if( so->so_poll_index != -1 \
41 && so->s == polls[so->so_poll_index].fd) { \
42 polls[so->so_poll_index].events |= \
43 N_(fdset1 ## _poll) | N_(fdset1 ## _poll); \
44 break; /* out of this loop */ \
45 } \
46 AssertRelease(poll_index < (nfds)); \
47 polls[poll_index].fd = (so)->s; \
48 (so)->so_poll_index = poll_index; \
49 polls[poll_index].events = \
50 N_(fdset1 ## _poll) | N_(fdset1 ## _poll); \
51 poll_index++; \
52 } while(0)
53
54# define DO_POLL_EVENTS(rc, error, so, events, label) do {} while (0)
55
56# define DO_CHECK_FD_SET(so, events, fdset) ( ((so)->so_poll_index != -1) \
57 && ((so)->so_poll_index <= ndfs) \
58 && ((so)->s == polls[so->so_poll_index].fd) \
59 && (polls[(so)->so_poll_index].revents & N_(fdset ## _poll)))
60# define DO_UNIX_CHECK_FD_SET(so, events, fdset ) DO_CHECK_FD_SET((so), (events), fdset) /*specific for Unix API */
61# define DO_WIN_CHECK_FD_SET(so, events, fdset ) 0 /* specific for Windows Winsock API */
62
63# ifndef RT_OS_WINDOWS
64
65# ifndef RT_OS_LINUX
66# define readfds_poll (POLLRDNORM)
67# define writefds_poll (POLLWRNORM)
68# define xfds_poll (POLLRDBAND|POLLWRBAND|POLLPRI)
69# else
70# define readfds_poll (POLLIN)
71# define writefds_poll (POLLOUT)
72# define xfds_poll (POLLPRI)
73# endif
74# define rderr_poll (POLLERR)
75# define rdhup_poll (POLLHUP)
76# define nval_poll (POLLNVAL)
77
78# define ICMP_ENGAGE_EVENT(so, fdset) \
79 do { \
80 if (pData->icmp_socket.s != -1) \
81 DO_ENGAGE_EVENT1((so), fdset, ICMP); \
82 } while (0)
83# else /* !RT_OS_WINDOWS */
84# define DO_WIN_CHECK_FD_SET(so, events, fdset ) DO_CHECK_FD_SET((so), (events), fdset)
85# define ICMP_ENGAGE_EVENT(so, fdset) do {} while(0)
86#endif /* RT_OS_WINDOWS */
87
88#else /* defined(RT_OS_WINDOWS) */
89
90/*
91 * On Windows, we will be notified by IcmpSendEcho2() when the response arrives.
92 * So no call to WSAEventSelect necessary.
93 */
94# define ICMP_ENGAGE_EVENT(so, fdset) do {} while(0)
95
96# define DO_ENGAGE_EVENT1(so, fdset1, label) \
97 do { \
98 rc = WSAEventSelect((so)->s, VBOX_SOCKET_EVENT, FD_ALL_EVENTS); \
99 if (rc == SOCKET_ERROR) \
100 { \
101 /* This should not happen */ \
102 error = WSAGetLastError(); \
103 LogRel(("WSAEventSelect (" #label ") error %d (so=%x, socket=%s, event=%x)\n", \
104 error, (so), (so)->s, VBOX_SOCKET_EVENT)); \
105 } \
106 } while(0); \
107 CONTINUE(label)
108
109# define DO_ENGAGE_EVENT2(so, fdset1, fdset2, label) \
110 DO_ENGAGE_EVENT1((so), (fdset1), label)
111
112# define DO_POLL_EVENTS(rc, error, so, events, label) \
113 (rc) = WSAEnumNetworkEvents((so)->s, VBOX_SOCKET_EVENT, (events)); \
114 if ((rc) == SOCKET_ERROR) \
115 { \
116 (error) = WSAGetLastError(); \
117 LogRel(("WSAEnumNetworkEvents " #label " error %d\n", (error))); \
118 CONTINUE(label); \
119 }
120
121# define acceptds_win FD_ACCEPT
122# define acceptds_win_bit FD_ACCEPT_BIT
123
124# define readfds_win FD_READ
125# define readfds_win_bit FD_READ_BIT
126
127# define writefds_win FD_WRITE
128# define writefds_win_bit FD_WRITE_BIT
129
130# define xfds_win FD_OOB
131# define xfds_win_bit FD_OOB_BIT
132
133# define DO_CHECK_FD_SET(so, events, fdset) \
134 (((events).lNetworkEvents & fdset ## _win) && ((events).iErrorCode[fdset ## _win_bit] == 0))
135
136# define DO_WIN_CHECK_FD_SET(so, events, fdset ) DO_CHECK_FD_SET((so), (events), fdset)
137# define DO_UNIX_CHECK_FD_SET(so, events, fdset ) 1 /*specific for Unix API */
138
139#endif /* defined(RT_OS_WINDOWS) */
140
141#define TCP_ENGAGE_EVENT1(so, fdset) \
142 DO_ENGAGE_EVENT1((so), fdset, tcp)
143
144#define TCP_ENGAGE_EVENT2(so, fdset1, fdset2) \
145 DO_ENGAGE_EVENT2((so), fdset1, fdset2, tcp)
146
147#define UDP_ENGAGE_EVENT(so, fdset) \
148 DO_ENGAGE_EVENT1((so), fdset, udp)
149
150#define POLL_TCP_EVENTS(rc, error, so, events) \
151 DO_POLL_EVENTS((rc), (error), (so), (events), tcp)
152
153#define POLL_UDP_EVENTS(rc, error, so, events) \
154 DO_POLL_EVENTS((rc), (error), (so), (events), udp)
155
156#define CHECK_FD_SET(so, events, set) \
157 (DO_CHECK_FD_SET((so), (events), set))
158
159#define WIN_CHECK_FD_SET(so, events, set) \
160 (DO_WIN_CHECK_FD_SET((so), (events), set))
161#define UNIX_CHECK_FD_SET(so, events, set) \
162 (DO_UNIX_CHECK_FD_SET(so, events, set))
163
164/*
165 * Loging macros
166 */
167#if VBOX_WITH_DEBUG_NAT_SOCKETS
168# if defined(RT_OS_WINDOWS)
169# define DO_LOG_NAT_SOCK(so, proto, winevent, r_fdset, w_fdset, x_fdset) \
170 do { \
171 LogRel((" " #proto " %R[natsock] %R[natwinnetevents]\n", (so), (winevent))); \
172 } while (0)
173# else /* RT_OS_WINDOWS */
174# define DO_LOG_NAT_SOCK(so, proto, winevent, r_fdset, w_fdset, x_fdset) \
175 do { \
176 LogRel((" " #proto " %R[natsock] %s %s %s er: %s, %s, %s\n", (so), \
177 CHECK_FD_SET(so, ign ,r_fdset) ? "READ":"", \
178 CHECK_FD_SET(so, ign, w_fdset) ? "WRITE":"", \
179 CHECK_FD_SET(so, ign, x_fdset) ? "OOB":"", \
180 CHECK_FD_SET(so, ign, rderr) ? "RDERR":"", \
181 CHECK_FD_SET(so, ign, rdhup) ? "RDHUP":"", \
182 CHECK_FD_SET(so, ign, nval) ? "RDNVAL":"")); \
183 } while (0)
184# endif /* !RT_OS_WINDOWS */
185#else /* VBOX_WITH_DEBUG_NAT_SOCKETS */
186# define DO_LOG_NAT_SOCK(so, proto, winevent, r_fdset, w_fdset, x_fdset) do {} while (0)
187#endif /* !VBOX_WITH_DEBUG_NAT_SOCKETS */
188
189#define LOG_NAT_SOCK(so, proto, winevent, r_fdset, w_fdset, x_fdset) DO_LOG_NAT_SOCK((so), proto, (winevent), r_fdset, w_fdset, x_fdset)
190
191static void acivate_port_forwarding(PNATState, struct ethhdr *);
192static uint32_t find_guest_ip(PNATState, uint8_t *);
193
194static const uint8_t special_ethaddr[6] =
195{
196 0x52, 0x54, 0x00, 0x12, 0x35, 0x00
197};
198
199static const uint8_t broadcast_ethaddr[6] =
200{
201 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
202};
203
204const uint8_t zerro_ethaddr[6] =
205{
206 0x0, 0x0, 0x0, 0x0, 0x0, 0x0
207};
208
209#ifdef RT_OS_WINDOWS
210static int get_dns_addr_domain(PNATState pData, bool fVerbose,
211 struct in_addr *pdns_addr,
212 const char **ppszDomain)
213{
214 /* Get amount of memory required for operation */
215 ULONG flags = GAA_FLAG_INCLUDE_PREFIX; /*GAA_FLAG_INCLUDE_ALL_INTERFACES;*/ /* all interfaces registered in NDIS */
216 PIP_ADAPTER_ADDRESSES addresses = NULL;
217 PIP_ADAPTER_ADDRESSES addr = NULL;
218 PIP_ADAPTER_DNS_SERVER_ADDRESS dns = NULL;
219 ULONG size = 0;
220 int wlen = 0;
221 char *suffix;
222 struct dns_entry *da = NULL;
223 struct dns_domain_entry *dd = NULL;
224 ULONG ret = ERROR_SUCCESS;
225
226 /* @todo add SKIPing flags to get only required information */
227
228 ret = pData->pfGetAdaptersAddresses(AF_INET, 0, NULL /* reserved */, addresses, &size);
229 if (ret != ERROR_BUFFER_OVERFLOW)
230 {
231 LogRel(("NAT: error %lu occurred on capacity detection operation\n", ret));
232 return -1;
233 }
234
235 if (size == 0)
236 {
237 LogRel(("NAT: Win socket API returns non capacity\n"));
238 return -1;
239 }
240
241 addresses = RTMemAllocZ(size);
242 if (addresses == NULL)
243 {
244 LogRel(("NAT: No memory available \n"));
245 return -1;
246 }
247
248 ret = pData->pfGetAdaptersAddresses(AF_INET, 0, NULL /* reserved */, addresses, &size);
249 if (ret != ERROR_SUCCESS)
250 {
251 LogRel(("NAT: error %lu occurred on fetching adapters info\n", ret));
252 RTMemFree(addresses);
253 return -1;
254 }
255 addr = addresses;
256 while(addr != NULL)
257 {
258 int found;
259 if (addr->OperStatus != IfOperStatusUp)
260 goto next;
261 dns = addr->FirstDnsServerAddress;
262 while (dns != NULL)
263 {
264 struct sockaddr *saddr = dns->Address.lpSockaddr;
265 if (saddr->sa_family != AF_INET)
266 goto next_dns;
267 /* add dns server to list */
268 da = RTMemAllocZ(sizeof(struct dns_entry));
269 if (da == NULL)
270 {
271 LogRel(("NAT: Can't allocate buffer for DNS entry\n"));
272 RTMemFree(addresses);
273 return VERR_NO_MEMORY;
274 }
275 LogRel(("NAT: adding %R[IP4] to DNS server list\n", &((struct sockaddr_in *)saddr)->sin_addr));
276 if ((((struct sockaddr_in *)saddr)->sin_addr.s_addr & htonl(IN_CLASSA_NET)) == ntohl(INADDR_LOOPBACK & IN_CLASSA_NET)) {
277 da->de_addr.s_addr = htonl(ntohl(special_addr.s_addr) | CTL_ALIAS);
278 }
279 else
280 {
281 da->de_addr.s_addr = ((struct sockaddr_in *)saddr)->sin_addr.s_addr;
282 }
283 TAILQ_INSERT_HEAD(&pData->dns_list_head, da, de_list);
284
285 if (addr->DnsSuffix == NULL)
286 goto next_dns;
287
288 /*uniq*/
289 RTUtf16ToUtf8(addr->DnsSuffix, &suffix);
290
291 if (!suffix || strlen(suffix) == 0) {
292 RTStrFree(suffix);
293 goto next_dns;
294 }
295
296 found = 0;
297 LIST_FOREACH(dd, &pData->dns_domain_list_head, dd_list)
298 {
299 if ( dd->dd_pszDomain != NULL
300 && strcmp(dd->dd_pszDomain, suffix) == 0)
301 {
302 found = 1;
303 RTStrFree(suffix);
304 break;
305 }
306 }
307 if (found == 0)
308 {
309 dd = RTMemAllocZ(sizeof(struct dns_domain_entry));
310 if (dd == NULL)
311 {
312 LogRel(("NAT: not enough memory\n"));
313 RTStrFree(suffix);
314 RTMemFree(addresses);
315 return VERR_NO_MEMORY;
316 }
317 dd->dd_pszDomain = suffix;
318 LogRel(("NAT: adding domain name %s to search list\n", dd->dd_pszDomain));
319 LIST_INSERT_HEAD(&pData->dns_domain_list_head, dd, dd_list);
320 }
321 next_dns:
322 dns = dns->Next;
323 }
324 next:
325 addr = addr->Next;
326 }
327 RTMemFree(addresses);
328 return 0;
329}
330
331#else /* !RT_OS_WINDOWS */
332
333static int get_dns_addr_domain(PNATState pData, bool fVerbose,
334 struct in_addr *pdns_addr,
335 const char **ppszDomain)
336{
337 char buff[512];
338 char buff2[256];
339 FILE *f = NULL;
340 int found = 0;
341 struct in_addr tmp_addr;
342
343#ifdef RT_OS_OS2
344 /* Try various locations. */
345 char *etc = getenv("ETC");
346 if (etc)
347 {
348 snprintf(buff, sizeof(buff), "%s/RESOLV2", etc);
349 f = fopen(buff, "rt");
350 }
351 if (!f)
352 {
353 snprintf(buff, sizeof(buff), "%s/RESOLV2", _PATH_ETC);
354 f = fopen(buff, "rt");
355 }
356 if (!f)
357 {
358 snprintf(buff, sizeof(buff), "%s/resolv.conf", _PATH_ETC);
359 f = fopen(buff, "rt");
360 }
361#else
362#ifndef DEBUG_vvl
363 f = fopen("/etc/resolv.conf", "r");
364#else
365 char *home = getenv("HOME");
366 snprintf(buff, sizeof(buff), "%s/resolv.conf", home);
367 f = fopen(buff, "r");
368 if (f != NULL)
369 {
370 Log(("NAT: DNS we're using %s\n", buff));
371 }
372 else
373 {
374 f = fopen("/etc/resolv.conf", "r");
375 Log(("NAT: DNS we're using %s\n", buff));
376 }
377#endif
378#endif
379 if (!f)
380 return -1;
381
382 if (ppszDomain)
383 *ppszDomain = NULL;
384 Log(("nat: DNS Servers:\n"));
385 while (fgets(buff, 512, f) != NULL)
386 {
387 struct dns_entry *da = NULL;
388 if (sscanf(buff, "nameserver%*[ \t]%256s", buff2) == 1)
389 {
390 if (!inet_aton(buff2, &tmp_addr))
391 continue;
392 /*localhost mask */
393 da = RTMemAllocZ(sizeof (struct dns_entry));
394 if (da == NULL)
395 {
396 LogRel(("can't alloc memory for DNS entry\n"));
397 return -1;
398 }
399 /*check */
400 da->de_addr.s_addr = tmp_addr.s_addr;
401 if ((da->de_addr.s_addr & htonl(IN_CLASSA_NET)) == ntohl(INADDR_LOOPBACK & IN_CLASSA_NET)) {
402 da->de_addr.s_addr = htonl(ntohl(special_addr.s_addr) | CTL_ALIAS);
403 }
404 TAILQ_INSERT_HEAD(&pData->dns_list_head, da, de_list);
405 found++;
406 }
407 if ((!strncmp(buff, "domain", 6) || !strncmp(buff, "search", 6)))
408 {
409 char *tok;
410 char *saveptr;
411 struct dns_domain_entry *dd = NULL;
412 int found = 0;
413 tok = strtok_r(&buff[6], " \t\n", &saveptr);
414 LIST_FOREACH(dd, &pData->dns_domain_list_head, dd_list)
415 {
416 if( tok != NULL
417 && strcmp(tok, dd->dd_pszDomain) == 0)
418 {
419 found = 1;
420 break;
421 }
422 }
423 if (tok != NULL && found == 0) {
424 dd = RTMemAllocZ(sizeof(struct dns_domain_entry));
425 if (dd == NULL)
426 {
427 LogRel(("NAT: not enought memory to add domain list\n"));
428 return VERR_NO_MEMORY;
429 }
430 dd->dd_pszDomain = RTStrDup(tok);
431 LogRel(("NAT: adding domain name %s to search list\n", dd->dd_pszDomain));
432 LIST_INSERT_HEAD(&pData->dns_domain_list_head, dd, dd_list);
433 }
434 }
435 }
436 fclose(f);
437 if (!found)
438 return -1;
439 return 0;
440}
441
442#endif
443
444static int slirp_init_dns_list(PNATState pData)
445{
446 TAILQ_INIT(&pData->dns_list_head);
447 LIST_INIT(&pData->dns_domain_list_head);
448 return get_dns_addr_domain(pData, true, NULL, NULL);
449}
450
451static void slirp_release_dns_list(PNATState pData)
452{
453 struct dns_entry *de = NULL;
454 struct dns_domain_entry *dd = NULL;
455 while(!TAILQ_EMPTY(&pData->dns_list_head)) {
456 de = TAILQ_FIRST(&pData->dns_list_head);
457 TAILQ_REMOVE(&pData->dns_list_head, de, de_list);
458 RTMemFree(de);
459 }
460 while(!LIST_EMPTY(&pData->dns_domain_list_head)) {
461 dd = LIST_FIRST(&pData->dns_domain_list_head);
462 LIST_REMOVE(dd, dd_list);
463 if (dd->dd_pszDomain != NULL)
464 RTStrFree(dd->dd_pszDomain);
465 RTMemFree(dd);
466 }
467}
468
469int get_dns_addr(PNATState pData, struct in_addr *pdns_addr)
470{
471 return get_dns_addr_domain(pData, false, pdns_addr, NULL);
472}
473
474#ifndef VBOX_WITH_NAT_SERVICE
475int slirp_init(PNATState *ppData, const char *pszNetAddr, uint32_t u32Netmask,
476 bool fPassDomain, void *pvUser)
477#else
478int slirp_init(PNATState *ppData, uint32_t u32NetAddr, uint32_t u32Netmask,
479 bool fPassDomain, void *pvUser)
480#endif
481{
482 int fNATfailed = 0;
483 int rc;
484 PNATState pData = RTMemAllocZ(sizeof(NATState));
485 *ppData = pData;
486 if (!pData)
487 return VERR_NO_MEMORY;
488 if (u32Netmask & 0x1f)
489 /* CTL is x.x.x.15, bootp passes up to 16 IPs (15..31) */
490 return VERR_INVALID_PARAMETER;
491 pData->fPassDomain = fPassDomain;
492 pData->pvUser = pvUser;
493 pData->netmask = u32Netmask;
494
495 /* sockets & TCP defaults */
496 pData->socket_rcv = 64 * _1K;
497 pData->socket_snd = 64 * _1K;
498 tcp_sndspace = 64 * _1K;
499 tcp_rcvspace = 64 * _1K;
500
501#ifdef RT_OS_WINDOWS
502 {
503 WSADATA Data;
504 WSAStartup(MAKEWORD(2, 0), &Data);
505 }
506 pData->phEvents[VBOX_SOCKET_EVENT_INDEX] = CreateEvent(NULL, FALSE, FALSE, NULL);
507#endif
508#ifdef VBOX_WITH_SLIRP_MT
509 QSOCKET_LOCK_CREATE(tcb);
510 QSOCKET_LOCK_CREATE(udb);
511 rc = RTReqCreateQueue(&pData->pReqQueue);
512 AssertReleaseRC(rc);
513#endif
514
515 link_up = 1;
516
517 debug_init();
518 if_init(pData);
519 ip_init(pData);
520 icmp_init(pData);
521
522 /* Initialise mbufs *after* setting the MTU */
523 m_init(pData);
524
525#ifndef VBOX_WITH_NAT_SERVICE
526 inet_aton(pszNetAddr, &special_addr);
527#else
528 special_addr.s_addr = u32NetAddr;
529#endif
530 pData->slirp_ethaddr = &special_ethaddr[0];
531 alias_addr.s_addr = special_addr.s_addr | htonl(CTL_ALIAS);
532 /* @todo: add ability to configure this staff */
533
534 /* set default addresses */
535 inet_aton("127.0.0.1", &loopback_addr);
536 if (slirp_init_dns_list(pData) < 0)
537 fNATfailed = 1;
538
539 dnsproxy_init(pData);
540
541 getouraddr(pData);
542 {
543 int flags = 0;
544 struct in_addr proxy_addr;
545 pData->proxy_alias = LibAliasInit(pData, NULL);
546 if (pData->proxy_alias == NULL)
547 {
548 LogRel(("NAT: LibAlias default rule wasn't initialized\n"));
549 AssertMsgFailed(("NAT: LibAlias default rule wasn't initialized\n"));
550 }
551 flags = LibAliasSetMode(pData->proxy_alias, 0, 0);
552 flags |= PKT_ALIAS_LOG; /* set logging */
553 flags = LibAliasSetMode(pData->proxy_alias, flags, ~0);
554 proxy_addr.s_addr = htonl(ntohl(special_addr.s_addr) | CTL_ALIAS);
555 LibAliasSetAddress(pData->proxy_alias, proxy_addr);
556 ftp_alias_load(pData);
557 nbt_alias_load(pData);
558 }
559 return fNATfailed ? VINF_NAT_DNS : VINF_SUCCESS;
560}
561
562/**
563 * Register statistics.
564 */
565void slirp_register_statistics(PNATState pData, PPDMDRVINS pDrvIns)
566{
567#ifdef VBOX_WITH_STATISTICS
568# define PROFILE_COUNTER(name, dsc) REGISTER_COUNTER(name, pData, STAMTYPE_PROFILE, STAMUNIT_TICKS_PER_CALL, dsc)
569# define COUNTING_COUNTER(name, dsc) REGISTER_COUNTER(name, pData, STAMTYPE_COUNTER, STAMUNIT_COUNT, dsc)
570# include "counters.h"
571# undef COUNTER
572/** @todo register statistics for the variables dumped by:
573 * ipstats(pData); tcpstats(pData); udpstats(pData); icmpstats(pData);
574 * mbufstats(pData); sockstats(pData); */
575#endif /* VBOX_WITH_STATISTICS */
576}
577
578/**
579 * Deregister statistics.
580 */
581void slirp_deregister_statistics(PNATState pData, PPDMDRVINS pDrvIns)
582{
583#ifdef VBOX_WITH_STATISTICS
584# define PROFILE_COUNTER(name, dsc) DEREGISTER_COUNTER(name, pData)
585# define COUNTING_COUNTER(name, dsc) DEREGISTER_COUNTER(name, pData)
586# include "counters.h"
587#endif /* VBOX_WITH_STATISTICS */
588}
589
590/**
591 * Marks the link as up, making it possible to establish new connections.
592 */
593void slirp_link_up(PNATState pData)
594{
595 link_up = 1;
596}
597
598/**
599 * Marks the link as down and cleans up the current connections.
600 */
601void slirp_link_down(PNATState pData)
602{
603 struct socket *so;
604
605 while ((so = tcb.so_next) != &tcb)
606 {
607 if (so->so_state & SS_NOFDREF || so->s == -1)
608 sofree(pData, so);
609 else
610 tcp_drop(pData, sototcpcb(so), 0);
611 }
612
613 while ((so = udb.so_next) != &udb)
614 udp_detach(pData, so);
615
616 link_up = 0;
617}
618
619/**
620 * Terminates the slirp component.
621 */
622void slirp_term(PNATState pData)
623{
624#ifdef RT_OS_WINDOWS
625 pData->pfIcmpCloseHandle(pData->icmp_socket.sh);
626 FreeLibrary(pData->hmIcmpLibrary);
627 RTMemFree(pData->pvIcmpBuffer);
628#else
629 closesocket(pData->icmp_socket.s);
630#endif
631
632 slirp_link_down(pData);
633 slirp_release_dns_list(pData);
634 ftp_alias_unload(pData);
635 nbt_alias_unload(pData);
636 while(!LIST_EMPTY(&instancehead)) {
637 struct libalias *la = LIST_FIRST(&instancehead);
638 /* libalias do all clean up */
639 LibAliasUninit(la);
640 }
641#ifdef RT_OS_WINDOWS
642 WSACleanup();
643#endif
644#ifdef LOG_ENABLED
645 Log(("\n"
646 "NAT statistics\n"
647 "--------------\n"
648 "\n"));
649 ipstats(pData);
650 tcpstats(pData);
651 udpstats(pData);
652 icmpstats(pData);
653 mbufstats(pData);
654 sockstats(pData);
655 Log(("\n"
656 "\n"
657 "\n"));
658#endif
659 RTMemFree(pData);
660}
661
662
663#define CONN_CANFSEND(so) (((so)->so_state & (SS_FCANTSENDMORE|SS_ISFCONNECTED)) == SS_ISFCONNECTED)
664#define CONN_CANFRCV(so) (((so)->so_state & (SS_FCANTRCVMORE|SS_ISFCONNECTED)) == SS_ISFCONNECTED)
665
666/*
667 * curtime kept to an accuracy of 1ms
668 */
669static void updtime(PNATState pData)
670{
671#ifdef RT_OS_WINDOWS
672 struct _timeb tb;
673
674 _ftime(&tb);
675 curtime = (u_int)tb.time * (u_int)1000;
676 curtime += (u_int)tb.millitm;
677#else
678 gettimeofday(&tt, 0);
679
680 curtime = (u_int)tt.tv_sec * (u_int)1000;
681 curtime += (u_int)tt.tv_usec / (u_int)1000;
682
683 if ((tt.tv_usec % 1000) >= 500)
684 curtime++;
685#endif
686}
687
688#ifdef RT_OS_WINDOWS
689void slirp_select_fill(PNATState pData, int *pnfds)
690#else /* RT_OS_WINDOWS */
691void slirp_select_fill(PNATState pData, int *pnfds, struct pollfd *polls)
692#endif /* !RT_OS_WINDOWS */
693{
694 struct socket *so, *so_next;
695 int nfds;
696#if defined(RT_OS_WINDOWS)
697 int rc;
698 int error;
699#else
700 int poll_index = 0;
701#endif
702 int i;
703
704 STAM_PROFILE_START(&pData->StatFill, a);
705
706 nfds = *pnfds;
707
708 /*
709 * First, TCP sockets
710 */
711 do_slowtimo = 0;
712 if (!link_up)
713 goto done;
714 /*
715 * *_slowtimo needs calling if there are IP fragments
716 * in the fragment queue, or there are TCP connections active
717 */
718 /* XXX:
719 * triggering of fragment expiration should be the same but use new macroses
720 */
721 do_slowtimo = (tcb.so_next != &tcb);
722 if (!do_slowtimo)
723 {
724 for (i = 0; i < IPREASS_NHASH; i++)
725 {
726 if (!TAILQ_EMPTY(&ipq[i]))
727 {
728 do_slowtimo = 1;
729 break;
730 }
731 }
732 }
733 ICMP_ENGAGE_EVENT(&pData->icmp_socket, readfds);
734
735 STAM_COUNTER_RESET(&pData->StatTCP);
736 STAM_COUNTER_RESET(&pData->StatTCPHot);
737
738 QSOCKET_FOREACH(so, so_next, tcp)
739 /* { */
740#if !defined(RT_OS_WINDOWS)
741 so->so_poll_index = -1;
742#endif
743 STAM_COUNTER_INC(&pData->StatTCP);
744
745 /*
746 * See if we need a tcp_fasttimo
747 */
748 if ( time_fasttimo == 0
749 && so->so_tcpcb != NULL
750 && so->so_tcpcb->t_flags & TF_DELACK)
751 time_fasttimo = curtime; /* Flag when we want a fasttimo */
752
753 /*
754 * NOFDREF can include still connecting to local-host,
755 * newly socreated() sockets etc. Don't want to select these.
756 */
757 if (so->so_state & SS_NOFDREF || so->s == -1)
758 CONTINUE(tcp);
759
760 /*
761 * Set for reading sockets which are accepting
762 */
763 if (so->so_state & SS_FACCEPTCONN)
764 {
765 STAM_COUNTER_INC(&pData->StatTCPHot);
766 TCP_ENGAGE_EVENT1(so, readfds);
767 CONTINUE(tcp);
768 }
769
770 /*
771 * Set for writing sockets which are connecting
772 */
773 if (so->so_state & SS_ISFCONNECTING)
774 {
775 Log2(("connecting %R[natsock] engaged\n",so));
776 STAM_COUNTER_INC(&pData->StatTCPHot);
777 TCP_ENGAGE_EVENT1(so, writefds);
778 }
779
780 /*
781 * Set for writing if we are connected, can send more, and
782 * we have something to send
783 */
784 if (CONN_CANFSEND(so) && so->so_rcv.sb_cc)
785 {
786 STAM_COUNTER_INC(&pData->StatTCPHot);
787 TCP_ENGAGE_EVENT1(so, writefds);
788 }
789
790 /*
791 * Set for reading (and urgent data) if we are connected, can
792 * receive more, and we have room for it XXX /2 ?
793 */
794 if (CONN_CANFRCV(so) && (so->so_snd.sb_cc < (so->so_snd.sb_datalen/2)))
795 {
796 STAM_COUNTER_INC(&pData->StatTCPHot);
797 TCP_ENGAGE_EVENT2(so, readfds, xfds);
798 }
799 LOOP_LABEL(tcp, so, so_next);
800 }
801
802 /*
803 * UDP sockets
804 */
805 STAM_COUNTER_RESET(&pData->StatUDP);
806 STAM_COUNTER_RESET(&pData->StatUDPHot);
807
808 QSOCKET_FOREACH(so, so_next, udp)
809 /* { */
810
811 STAM_COUNTER_INC(&pData->StatUDP);
812#if !defined(RT_OS_WINDOWS)
813 so->so_poll_index = -1;
814#endif
815
816 /*
817 * See if it's timed out
818 */
819 if (so->so_expire)
820 {
821 if (so->so_expire <= curtime)
822 {
823 Log2(("NAT: %R[natsock] expired\n", so));
824 if (so->so_timeout != NULL)
825 {
826 so->so_timeout(pData, so, so->so_timeout_arg);
827 }
828#ifdef VBOX_WITH_SLIRP_MT
829 /* we need so_next for continue our cycle*/
830 so_next = so->so_next;
831#endif
832 UDP_DETACH(pData, so, so_next);
833 CONTINUE_NO_UNLOCK(udp);
834 }
835 else
836 do_slowtimo = 1; /* Let socket expire */
837 }
838
839 /*
840 * When UDP packets are received from over the link, they're
841 * sendto()'d straight away, so no need for setting for writing
842 * Limit the number of packets queued by this session to 4.
843 * Note that even though we try and limit this to 4 packets,
844 * the session could have more queued if the packets needed
845 * to be fragmented.
846 *
847 * (XXX <= 4 ?)
848 */
849 if ((so->so_state & SS_ISFCONNECTED) && so->so_queued <= 4)
850 {
851 STAM_COUNTER_INC(&pData->StatUDPHot);
852 UDP_ENGAGE_EVENT(so, readfds);
853 }
854 LOOP_LABEL(udp, so, so_next);
855 }
856done:
857
858#if defined(RT_OS_WINDOWS)
859 *pnfds = VBOX_EVENT_COUNT;
860#else /* RT_OS_WINDOWS */
861 AssertRelease(poll_index <= *pnfds);
862 *pnfds = poll_index;
863#endif /* !RT_OS_WINDOWS */
864
865 STAM_PROFILE_STOP(&pData->StatFill, a);
866}
867
868#if defined(RT_OS_WINDOWS)
869void slirp_select_poll(PNATState pData, int fTimeout, int fIcmp)
870#else /* RT_OS_WINDOWS */
871void slirp_select_poll(PNATState pData, struct pollfd *polls, int ndfs)
872#endif /* !RT_OS_WINDOWS */
873{
874 struct socket *so, *so_next;
875 int ret;
876#if defined(RT_OS_WINDOWS)
877 WSANETWORKEVENTS NetworkEvents;
878 int rc;
879 int error;
880#else
881 int poll_index = 0;
882#endif
883
884 STAM_PROFILE_START(&pData->StatPoll, a);
885
886 /* Update time */
887 updtime(pData);
888
889 /*
890 * See if anything has timed out
891 */
892 if (link_up)
893 {
894 if (time_fasttimo && ((curtime - time_fasttimo) >= 2))
895 {
896 STAM_PROFILE_START(&pData->StatFastTimer, a);
897 tcp_fasttimo(pData);
898 time_fasttimo = 0;
899 STAM_PROFILE_STOP(&pData->StatFastTimer, a);
900 }
901 if (do_slowtimo && ((curtime - last_slowtimo) >= 499))
902 {
903 STAM_PROFILE_START(&pData->StatSlowTimer, a);
904 ip_slowtimo(pData);
905 tcp_slowtimo(pData);
906 last_slowtimo = curtime;
907 STAM_PROFILE_STOP(&pData->StatSlowTimer, a);
908 }
909 }
910#if defined(RT_OS_WINDOWS)
911 if (fTimeout)
912 return; /* only timer update */
913#endif
914
915 /*
916 * Check sockets
917 */
918 if (!link_up)
919 goto done;
920#if defined(RT_OS_WINDOWS)
921 /*XXX: before renaming please make see define
922 * fIcmp in slirp_state.h
923 */
924 if (fIcmp)
925 sorecvfrom(pData, &pData->icmp_socket);
926#else
927 if ( (pData->icmp_socket.s != -1)
928 && CHECK_FD_SET(&pData->icmp_socket, ignored, readfds))
929 sorecvfrom(pData, &pData->icmp_socket);
930#endif
931 /*
932 * Check TCP sockets
933 */
934 QSOCKET_FOREACH(so, so_next, tcp)
935 /* { */
936
937#ifdef VBOX_WITH_SLIRP_MT
938 if ( so->so_state & SS_NOFDREF
939 && so->so_deleted == 1)
940 {
941 struct socket *son, *sop = NULL;
942 QSOCKET_LOCK(tcb);
943 if (so->so_next != NULL)
944 {
945 if (so->so_next != &tcb)
946 SOCKET_LOCK(so->so_next);
947 son = so->so_next;
948 }
949 if ( so->so_prev != &tcb
950 && so->so_prev != NULL)
951 {
952 SOCKET_LOCK(so->so_prev);
953 sop = so->so_prev;
954 }
955 QSOCKET_UNLOCK(tcb);
956 remque(pData, so);
957 NSOCK_DEC();
958 SOCKET_UNLOCK(so);
959 SOCKET_LOCK_DESTROY(so);
960 RTMemFree(so);
961 so_next = son;
962 if (sop != NULL)
963 SOCKET_UNLOCK(sop);
964 CONTINUE_NO_UNLOCK(tcp);
965 }
966#endif
967 /*
968 * FD_ISSET is meaningless on these sockets
969 * (and they can crash the program)
970 */
971 if (so->so_state & SS_NOFDREF || so->s == -1)
972 CONTINUE(tcp);
973
974 POLL_TCP_EVENTS(rc, error, so, &NetworkEvents);
975
976 LOG_NAT_SOCK(so, TCP, &NetworkEvents, readfds, writefds, xfds);
977
978
979 /*
980 * Check for URG data
981 * This will soread as well, so no need to
982 * test for readfds below if this succeeds
983 */
984
985 /* out-of-band data */
986 if (CHECK_FD_SET(so, NetworkEvents, xfds))
987 {
988 sorecvoob(pData, so);
989 }
990
991 /*
992 * Check sockets for reading
993 */
994 else if ( CHECK_FD_SET(so, NetworkEvents, readfds)
995 || WIN_CHECK_FD_SET(so, NetworkEvents, acceptds))
996 {
997 /*
998 * Check for incoming connections
999 */
1000 if (so->so_state & SS_FACCEPTCONN)
1001 {
1002 TCP_CONNECT(pData, so);
1003#if defined(RT_OS_WINDOWS)
1004 if (!(NetworkEvents.lNetworkEvents & FD_CLOSE))
1005#endif
1006 CONTINUE(tcp);
1007 }
1008
1009 ret = soread(pData, so);
1010 /* Output it if we read something */
1011 if (RT_LIKELY(ret > 0))
1012 TCP_OUTPUT(pData, sototcpcb(so));
1013 }
1014
1015#if defined(RT_OS_WINDOWS)
1016 /*
1017 * Check for FD_CLOSE events.
1018 * in some cases once FD_CLOSE engaged on socket it could be flashed latter (for some reasons)
1019 */
1020 if ( (NetworkEvents.lNetworkEvents & FD_CLOSE)
1021 || (so->so_close == 1))
1022 {
1023 so->so_close = 1; /* mark it */
1024 /*
1025 * drain the socket
1026 */
1027 for (;;)
1028 {
1029 ret = soread(pData, so);
1030 if (ret > 0)
1031 TCP_OUTPUT(pData, sototcpcb(so));
1032 else
1033 break;
1034 }
1035 CONTINUE(tcp);
1036 }
1037#endif
1038
1039 /*
1040 * Check sockets for writing
1041 */
1042 if (CHECK_FD_SET(so, NetworkEvents, writefds))
1043 {
1044 /*
1045 * Check for non-blocking, still-connecting sockets
1046 */
1047 if (so->so_state & SS_ISFCONNECTING)
1048 {
1049 Log2(("connecting %R[natsock] catched\n", so));
1050 /* Connected */
1051 so->so_state &= ~SS_ISFCONNECTING;
1052
1053 /*
1054 * This should be probably guarded by PROBE_CONN too. Anyway,
1055 * we disable it on OS/2 because the below send call returns
1056 * EFAULT which causes the opened TCP socket to close right
1057 * after it has been opened and connected.
1058 */
1059#ifndef RT_OS_OS2
1060 ret = send(so->s, (const char *)&ret, 0, 0);
1061 if (ret < 0)
1062 {
1063 /* XXXXX Must fix, zero bytes is a NOP */
1064 if ( errno == EAGAIN
1065 || errno == EWOULDBLOCK
1066 || errno == EINPROGRESS
1067 || errno == ENOTCONN)
1068 CONTINUE(tcp);
1069
1070 /* else failed */
1071 so->so_state = SS_NOFDREF;
1072 }
1073 /* else so->so_state &= ~SS_ISFCONNECTING; */
1074#endif
1075
1076 /*
1077 * Continue tcp_input
1078 */
1079 TCP_INPUT(pData, (struct mbuf *)NULL, sizeof(struct ip), so);
1080 /* continue; */
1081 }
1082 else
1083 SOWRITE(ret, pData, so);
1084 /*
1085 * XXX If we wrote something (a lot), there could be the need
1086 * for a window update. In the worst case, the remote will send
1087 * a window probe to get things going again.
1088 */
1089 }
1090
1091 /*
1092 * Probe a still-connecting, non-blocking socket
1093 * to check if it's still alive
1094 */
1095#ifdef PROBE_CONN
1096 if (so->so_state & SS_ISFCONNECTING)
1097 {
1098 ret = recv(so->s, (char *)&ret, 0, 0);
1099
1100 if (ret < 0)
1101 {
1102 /* XXX */
1103 if ( errno == EAGAIN
1104 || errno == EWOULDBLOCK
1105 || errno == EINPROGRESS
1106 || errno == ENOTCONN)
1107 {
1108 CONTINUE(tcp); /* Still connecting, continue */
1109 }
1110
1111 /* else failed */
1112 so->so_state = SS_NOFDREF;
1113
1114 /* tcp_input will take care of it */
1115 }
1116 else
1117 {
1118 ret = send(so->s, &ret, 0, 0);
1119 if (ret < 0)
1120 {
1121 /* XXX */
1122 if ( errno == EAGAIN
1123 || errno == EWOULDBLOCK
1124 || errno == EINPROGRESS
1125 || errno == ENOTCONN)
1126 {
1127 CONTINUE(tcp);
1128 }
1129 /* else failed */
1130 so->so_state = SS_NOFDREF;
1131 }
1132 else
1133 so->so_state &= ~SS_ISFCONNECTING;
1134
1135 }
1136 TCP_INPUT((struct mbuf *)NULL, sizeof(struct ip),so);
1137 } /* SS_ISFCONNECTING */
1138#endif
1139#ifndef RT_OS_WINDOWS
1140 if ( UNIX_CHECK_FD_SET(so, NetworkEvents, rdhup)
1141 || UNIX_CHECK_FD_SET(so, NetworkEvents, rderr))
1142 {
1143 int err;
1144 int inq, outq;
1145 int status;
1146 socklen_t optlen = sizeof(int);
1147 inq = outq = 0;
1148 status = getsockopt(so->s, SOL_SOCKET, SO_ERROR, &err, &optlen);
1149 if (status != 0)
1150 Log(("NAT: can't get error status from %R[natsock]\n", so));
1151#ifndef RT_OS_SOLARIS
1152 status = ioctl(so->s, FIONREAD, &inq); /* tcp(7) recommends SIOCINQ which is Linux specific */
1153 if (status != 0 || status != EINVAL)
1154 {
1155 /* EINVAL returned if socket in listen state tcp(7)*/
1156 Log(("NAT: can't get depth of IN queue status from %R[natsock]\n", so));
1157 }
1158 status = ioctl(so->s, TIOCOUTQ, &outq); /* SIOCOUTQ see previous comment */
1159 if (status != 0)
1160 Log(("NAT: can't get depth of OUT queue from %R[natsock]\n", so));
1161#else
1162 /*
1163 * Solaris has bit different ioctl commands and its handlings
1164 * hint: streamio(7) I_NREAD
1165 */
1166#endif
1167 if ( so->so_state & SS_ISFCONNECTING
1168 || UNIX_CHECK_FD_SET(so, NetworkEvents, readfds))
1169 {
1170 /**
1171 * Check if we need here take care about gracefull connection
1172 * @todo try with proxy server
1173 */
1174 if (UNIX_CHECK_FD_SET(so, NetworkEvents, readfds))
1175 {
1176 /*
1177 * Never meet inq != 0 or outq != 0, anyway let it stay for a while
1178 * in case it happens we'll able to detect it.
1179 * Give TCP/IP stack wait or expire the socket.
1180 */
1181 Log(("NAT: %R[natsock] err(%d:%s) s(in:%d,out:%d)happens on read I/O, "
1182 "other side close connection \n", so, err, strerror(err), inq, outq));
1183 CONTINUE(tcp);
1184 }
1185 goto tcp_input_close;
1186 }
1187 if ( !UNIX_CHECK_FD_SET(so, NetworkEvents, readfds)
1188 && !UNIX_CHECK_FD_SET(so, NetworkEvents, writefds)
1189 && !UNIX_CHECK_FD_SET(so, NetworkEvents, xfds))
1190 {
1191 Log(("NAT: system expires the socket %R[natsock] err(%d:%s) s(in:%d,out:%d) happens on non-I/O. ",
1192 so, err, strerror(err), inq, outq));
1193 goto tcp_input_close;
1194 }
1195 Log(("NAT: %R[natsock] we've met(%d:%s) s(in:%d, out:%d) unhandled combination hup (%d) "
1196 "rederr(%d) on (r:%d, w:%d, x:%d)\n",
1197 so, err, strerror(err),
1198 inq, outq,
1199 UNIX_CHECK_FD_SET(so, ign, rdhup),
1200 UNIX_CHECK_FD_SET(so, ign, rderr),
1201 UNIX_CHECK_FD_SET(so, ign, readfds),
1202 UNIX_CHECK_FD_SET(so, ign, writefds),
1203 UNIX_CHECK_FD_SET(so, ign, xfds)));
1204 /*
1205 * Give OS's TCP/IP stack a chance to resolve an issue or expire the socket.
1206 */
1207 CONTINUE(tcp);
1208tcp_input_close:
1209 so->so_state = SS_NOFDREF; /*cause connection valid tcp connection termination and socket closing */
1210 TCP_INPUT(pData, (struct mbuf *)NULL, sizeof(struct ip), so);
1211 CONTINUE(tcp);
1212 }
1213#endif
1214 LOOP_LABEL(tcp, so, so_next);
1215 }
1216
1217 /*
1218 * Now UDP sockets.
1219 * Incoming packets are sent straight away, they're not buffered.
1220 * Incoming UDP data isn't buffered either.
1221 */
1222 QSOCKET_FOREACH(so, so_next, udp)
1223 /* { */
1224#ifdef VBOX_WITH_SLIRP_MT
1225 if ( so->so_state & SS_NOFDREF
1226 && so->so_deleted == 1)
1227 {
1228 struct socket *son, *sop = NULL;
1229 QSOCKET_LOCK(udb);
1230 if (so->so_next != NULL)
1231 {
1232 if (so->so_next != &udb)
1233 SOCKET_LOCK(so->so_next);
1234 son = so->so_next;
1235 }
1236 if ( so->so_prev != &udb
1237 && so->so_prev != NULL)
1238 {
1239 SOCKET_LOCK(so->so_prev);
1240 sop = so->so_prev;
1241 }
1242 QSOCKET_UNLOCK(udb);
1243 remque(pData, so);
1244 NSOCK_DEC();
1245 SOCKET_UNLOCK(so);
1246 SOCKET_LOCK_DESTROY(so);
1247 RTMemFree(so);
1248 so_next = son;
1249 if (sop != NULL)
1250 SOCKET_UNLOCK(sop);
1251 CONTINUE_NO_UNLOCK(udp);
1252 }
1253#endif
1254 POLL_UDP_EVENTS(rc, error, so, &NetworkEvents);
1255
1256 LOG_NAT_SOCK(so, UDP, &NetworkEvents, readfds, writefds, xfds);
1257
1258 if (so->s != -1 && CHECK_FD_SET(so, NetworkEvents, readfds))
1259 {
1260 SORECVFROM(pData, so);
1261 }
1262 LOOP_LABEL(udp, so, so_next);
1263 }
1264
1265done:
1266#ifndef VBOX_WITH_SLIRP_MT
1267 /*
1268 * See if we can start outputting
1269 */
1270 if (if_queued && link_up)
1271 if_start(pData);
1272#endif
1273
1274 STAM_PROFILE_STOP(&pData->StatPoll, a);
1275}
1276
1277
1278struct arphdr
1279{
1280 unsigned short ar_hrd; /* format of hardware address */
1281 unsigned short ar_pro; /* format of protocol address */
1282 unsigned char ar_hln; /* length of hardware address */
1283 unsigned char ar_pln; /* length of protocol address */
1284 unsigned short ar_op; /* ARP opcode (command) */
1285
1286 /*
1287 * Ethernet looks like this : This bit is variable sized however...
1288 */
1289 unsigned char ar_sha[ETH_ALEN]; /* sender hardware address */
1290 unsigned char ar_sip[4]; /* sender IP address */
1291 unsigned char ar_tha[ETH_ALEN]; /* target hardware address */
1292 unsigned char ar_tip[4]; /* target IP address */
1293};
1294AssertCompileSize(struct arphdr, 28);
1295
1296static void arp_input(PNATState pData, struct mbuf *m)
1297{
1298 struct ethhdr *eh;
1299 struct ethhdr *reh;
1300 struct arphdr *ah;
1301 struct arphdr *rah;
1302 int ar_op;
1303 struct ex_list *ex_ptr;
1304 uint32_t htip;
1305 uint32_t tip;
1306 struct mbuf *mr;
1307 eh = mtod(m, struct ethhdr *);
1308 ah = (struct arphdr *)&eh[1];
1309 htip = ntohl(*(uint32_t*)ah->ar_tip);
1310 tip = *(uint32_t*)ah->ar_tip;
1311
1312 mr = m_get(pData);
1313
1314 reh = mtod(mr, struct ethhdr *);
1315 memcpy(reh->h_source, eh->h_source, ETH_ALEN); /* XXX: if_encap will swap src and dst*/
1316 Log4(("NAT: arp:%R[ether]->%R[ether]\n",
1317 reh->h_source, reh->h_dest));
1318 Log4(("NAT: arp: %R[IP4]\n", &tip));
1319
1320 mr->m_data += if_maxlinkhdr;
1321 mr->m_len = sizeof(struct arphdr);
1322 rah = mtod(mr, struct arphdr *);
1323
1324 ar_op = ntohs(ah->ar_op);
1325 switch(ar_op)
1326 {
1327 case ARPOP_REQUEST:
1328#ifdef VBOX_WITH_NAT_SERVICE
1329 if (tip == special_addr.s_addr) goto arp_ok;
1330#endif
1331 if ((htip & pData->netmask) == ntohl(special_addr.s_addr))
1332 {
1333 if ( CTL_CHECK(htip, CTL_DNS)
1334 || CTL_CHECK(htip, CTL_ALIAS)
1335 || CTL_CHECK(htip, CTL_TFTP))
1336 goto arp_ok;
1337 for (ex_ptr = exec_list; ex_ptr; ex_ptr = ex_ptr->ex_next)
1338 {
1339 if ((htip & ~pData->netmask) == ex_ptr->ex_addr)
1340 {
1341 goto arp_ok;
1342 }
1343 }
1344 return;
1345 arp_ok:
1346 rah->ar_hrd = htons(1);
1347 rah->ar_pro = htons(ETH_P_IP);
1348 rah->ar_hln = ETH_ALEN;
1349 rah->ar_pln = 4;
1350 rah->ar_op = htons(ARPOP_REPLY);
1351 memcpy(rah->ar_sha, special_ethaddr, ETH_ALEN);
1352
1353 switch (htip & ~pData->netmask)
1354 {
1355 case CTL_DNS:
1356 case CTL_ALIAS:
1357 rah->ar_sha[5] = (uint8_t)(htip & ~pData->netmask);
1358 break;
1359 default:;
1360 }
1361
1362 memcpy(rah->ar_sip, ah->ar_tip, 4);
1363 memcpy(rah->ar_tha, ah->ar_sha, ETH_ALEN);
1364 memcpy(rah->ar_tip, ah->ar_sip, 4);
1365 if_encap(pData, ETH_P_ARP, mr);
1366 m_free(pData, m);
1367 }
1368 break;
1369 default:
1370 break;
1371 }
1372}
1373
1374void slirp_input(PNATState pData, const uint8_t *pkt, int pkt_len)
1375{
1376 struct mbuf *m;
1377 int proto;
1378 static bool fWarnedIpv6;
1379 struct ethhdr *eh = (struct ethhdr*)pkt;
1380
1381 Log2(("NAT: slirp_input %d\n", pkt_len));
1382 if (pkt_len < ETH_HLEN)
1383 {
1384 LogRel(("NAT: packet having size %d has been ingnored\n", pkt_len));
1385 return;
1386 }
1387 Log4(("NAT: in:%R[ether]->%R[ether]\n", &eh->h_source, &eh->h_dest));
1388
1389 if (memcmp(eh->h_source, special_ethaddr, ETH_ALEN) == 0)
1390 {
1391 /* @todo vasily: add ether logging routine in debug.c */
1392 Log(("NAT: packet was addressed to other MAC\n"));
1393 RTMemFree((void *)pkt);
1394 return;
1395 }
1396
1397 m = m_get(pData);
1398 if (!m)
1399 {
1400 LogRel(("NAT: can't allocate new mbuf\n"));
1401 return;
1402 }
1403
1404 /* Note: we add to align the IP header */
1405
1406 if (M_FREEROOM(m) < pkt_len)
1407 m_inc(m, pkt_len);
1408
1409 m->m_len = pkt_len ;
1410 memcpy(m->m_data, pkt, pkt_len);
1411
1412 if (pData->port_forwarding_activated == 0)
1413 acivate_port_forwarding(pData, mtod(m, struct ethhdr *));
1414
1415 proto = ntohs(*(uint16_t *)(pkt + 12));
1416 switch(proto)
1417 {
1418 case ETH_P_ARP:
1419 arp_input(pData, m);
1420 break;
1421 case ETH_P_IP:
1422 /* Update time. Important if the network is very quiet, as otherwise
1423 * the first outgoing connection gets an incorrect timestamp. */
1424 updtime(pData);
1425 m_adj(m, ETH_HLEN);
1426 ip_input(pData, m);
1427 break;
1428 case ETH_P_IPV6:
1429 m_free(pData, m);
1430 if (!fWarnedIpv6)
1431 {
1432 LogRel(("NAT: IPv6 not supported\n"));
1433 fWarnedIpv6 = true;
1434 }
1435 break;
1436 default:
1437 Log(("NAT: Unsupported protocol %x\n", proto));
1438 m_free(pData, m);
1439 break;
1440 }
1441 RTMemFree((void *)pkt);
1442}
1443
1444/* output the IP packet to the ethernet device */
1445void if_encap(PNATState pData, uint16_t eth_proto, struct mbuf *m)
1446{
1447 struct ethhdr *eh;
1448 uint8_t *buf = NULL;
1449 STAM_PROFILE_START(&pData->StatIF_encap, a);
1450
1451 m->m_data -= if_maxlinkhdr;
1452 m->m_len += ETH_HLEN;
1453 eh = mtod(m, struct ethhdr *);
1454
1455 if(MBUF_HEAD(m) != m->m_data)
1456 {
1457 LogRel(("NAT: ethernet detects corruption of the packet"));
1458 AssertMsgFailed(("!!Ethernet frame corrupted!!"));
1459 }
1460
1461 if (memcmp(eh->h_source, special_ethaddr, ETH_ALEN) != 0)
1462 {
1463 memcpy(eh->h_dest, eh->h_source, ETH_ALEN);
1464 memcpy(eh->h_source, special_ethaddr, ETH_ALEN);
1465 Assert(memcmp(eh->h_dest, special_ethaddr, ETH_ALEN) != 0);
1466 if (memcmp(eh->h_dest, zerro_ethaddr, ETH_ALEN) == 0)
1467 {
1468 /* don't do anything */
1469 goto done;
1470 }
1471 }
1472 buf = RTMemAlloc(1600);
1473 if (buf == NULL)
1474 {
1475 LogRel(("NAT: Can't alloc memory for outgoing buffer\n"));
1476 goto done;
1477 }
1478 eh->h_proto = htons(eth_proto);
1479 memcpy(buf, mtod(m, uint8_t *), m->m_len);
1480 slirp_output(pData->pvUser, NULL, buf, m->m_len);
1481done:
1482 STAM_PROFILE_STOP(&pData->StatIF_encap, a);
1483 m_free(pData, m);
1484}
1485
1486/**
1487 * Still we're using dhcp server leasing to map ether to IP
1488 * @todo see rt_lookup_in_cache
1489 */
1490static uint32_t find_guest_ip(PNATState pData, uint8_t *eth_addr)
1491{
1492 int i;
1493 if (memcmp(eth_addr, zerro_ethaddr, ETH_ALEN) == 0
1494 || memcmp(eth_addr, broadcast_ethaddr, ETH_ALEN) == 0)
1495 goto done;
1496 for (i = 0; i < NB_ADDR; i++)
1497 {
1498 if ( bootp_clients[i].allocated
1499 && memcmp(bootp_clients[i].macaddr, eth_addr, ETH_ALEN) == 0)
1500 return bootp_clients[i].addr.s_addr;
1501 }
1502done:
1503 return INADDR_ANY;
1504}
1505
1506/**
1507 * We need check if we've activated port forwarding
1508 * for specific machine ... that of course relates to
1509 * service mode
1510 * @todo finish this for service case
1511 */
1512static void acivate_port_forwarding(PNATState pData, struct ethhdr *ethdr)
1513{
1514 struct port_forward_rule *rule = NULL;
1515
1516 pData->port_forwarding_activated = 1;
1517 /* check mac here */
1518 LIST_FOREACH(rule, &pData->port_forward_rule_head, list)
1519 {
1520 struct socket *so;
1521 struct alias_link *link;
1522 struct libalias *lib;
1523 int flags;
1524 struct sockaddr sa;
1525 struct sockaddr_in *psin;
1526 socklen_t socketlen;
1527 struct in_addr alias;
1528 int rc;
1529 uint32_t guest_addr; /* need to understand if we already give address to guest */
1530
1531 if (rule->activated)
1532 continue; /*already activated */
1533#ifdef VBOX_WITH_NAT_SERVICE
1534 if (memcmp(rule->mac_address, ethdr->h_source, ETH_ALEN) != 0)
1535 continue; /*not right mac, @todo: it'd be better do the list port forwarding per mac */
1536 guest_addr = find_guest_ip(pData, ethdr->h_source);
1537#else
1538 if (memcmp(client_ethaddr, ethdr->h_source, ETH_ALEN) != 0)
1539 continue;
1540 guest_addr = find_guest_ip(pData, ethdr->h_source);
1541#endif
1542 if (guest_addr == INADDR_ANY)
1543 {
1544 /* the address wasn't granted */
1545 pData->port_forwarding_activated = 0;
1546 return;
1547 }
1548#if defined(DEBUG_vvl) && !defined(VBOX_WITH_NAT_SERVICE)
1549 Assert(rule->guest_addr.s_addr == guest_addr);
1550#endif
1551
1552 LogRel(("NAT: set redirect %s hp:%d gp:%d\n", (rule->proto == IPPROTO_UDP?"UDP":"TCP"),
1553 rule->host_port, rule->guest_port));
1554 if (rule->proto == IPPROTO_UDP)
1555 {
1556 so = udp_listen(pData, rule->bind_ip.s_addr, htons(rule->host_port), guest_addr,
1557 htons(rule->guest_port), 0);
1558 }
1559 else
1560 {
1561 so = solisten(pData, rule->bind_ip.s_addr, htons(rule->host_port), guest_addr,
1562 htons(rule->guest_port), 0);
1563 }
1564 if (so == NULL)
1565 {
1566 LogRel(("NAT: failed redirect %s hp:%d gp:%d\n", (rule->proto == IPPROTO_UDP?"UDP":"TCP"),
1567 rule->host_port, rule->guest_port));
1568 goto remove_port_forwarding;
1569 }
1570
1571 psin = (struct sockaddr_in *)&sa;
1572 psin->sin_family = AF_INET;
1573 psin->sin_port = 0;
1574 psin->sin_addr.s_addr = INADDR_ANY;
1575 socketlen = sizeof(struct sockaddr);
1576
1577 rc = getsockname(so->s, &sa, &socketlen);
1578 if (rc < 0 || sa.sa_family != AF_INET)
1579 {
1580 LogRel(("NAT: failed redirect %s hp:%d gp:%d\n", (rule->proto == IPPROTO_UDP?"UDP":"TCP"),
1581 rule->host_port, rule->guest_port));
1582 goto remove_port_forwarding;
1583 }
1584
1585 psin = (struct sockaddr_in *)&sa;
1586
1587 lib = LibAliasInit(pData, NULL);
1588 flags = LibAliasSetMode(lib, 0, 0);
1589 flags |= PKT_ALIAS_LOG; /* set logging */
1590 flags |= PKT_ALIAS_REVERSE; /* set logging */
1591 flags = LibAliasSetMode(lib, flags, ~0);
1592
1593 alias.s_addr = htonl(ntohl(guest_addr) | CTL_ALIAS);
1594 link = LibAliasRedirectPort(lib, psin->sin_addr, htons(rule->host_port),
1595 alias, htons(rule->guest_port),
1596 special_addr, -1, /* not very clear for now*/
1597 rule->proto);
1598 if (link == NULL)
1599 {
1600 LogRel(("NAT: failed redirect %s hp:%d gp:%d\n", (rule->proto == IPPROTO_UDP?"UDP":"TCP"),
1601 rule->host_port, rule->guest_port));
1602 goto remove_port_forwarding;
1603 }
1604 so->so_la = lib;
1605 rule->activated = 1;
1606 continue;
1607 remove_port_forwarding:
1608 LIST_REMOVE(rule, list);
1609 RTMemFree(rule);
1610 }
1611}
1612
1613/**
1614 * Changes in 3.1 instead of opening new socket do the following:
1615 * gain more information:
1616 * 1. bind IP
1617 * 2. host port
1618 * 3. guest port
1619 * 4. proto
1620 * 5. guest MAC address
1621 * the guest's MAC address is rather important for service, but we easily
1622 * could get it from VM configuration in DrvNAT or Service, the idea is activating
1623 * corresponding port-forwarding
1624 */
1625int slirp_redir(PNATState pData, int is_udp, struct in_addr host_addr, int host_port,
1626 struct in_addr guest_addr, int guest_port, const uint8_t *ethaddr)
1627{
1628 struct port_forward_rule *rule = NULL;
1629 Assert(memcmp(ethaddr, zerro_ethaddr, ETH_ALEN) == 0);
1630 rule = RTMemAllocZ(sizeof(struct port_forward_rule));
1631 if (rule == NULL)
1632 return 1;
1633 rule->proto = (is_udp ? IPPROTO_UDP : IPPROTO_TCP);
1634 rule->host_port = host_port;
1635 rule->guest_port = guest_port;
1636#ifndef VBOX_WITH_NAT_SERVICE
1637 rule->guest_addr.s_addr = guest_addr.s_addr;
1638#endif
1639 rule->bind_ip.s_addr = host_addr.s_addr;
1640 memcpy(rule->mac_address, ethaddr, ETH_ALEN);
1641 /* @todo add mac address */
1642 LIST_INSERT_HEAD(&pData->port_forward_rule_head, rule, list);
1643 return 0;
1644}
1645
1646int slirp_add_exec(PNATState pData, int do_pty, const char *args, int addr_low_byte,
1647 int guest_port)
1648{
1649 return add_exec(&exec_list, do_pty, (char *)args,
1650 addr_low_byte, htons(guest_port));
1651}
1652
1653void slirp_set_ethaddr(PNATState pData, const uint8_t *ethaddr)
1654{
1655#ifndef VBOX_WITH_NAT_SERVICE
1656 memcpy(client_ethaddr, ethaddr, ETH_ALEN);
1657#endif
1658}
1659
1660#if defined(RT_OS_WINDOWS)
1661HANDLE *slirp_get_events(PNATState pData)
1662{
1663 return pData->phEvents;
1664}
1665void slirp_register_external_event(PNATState pData, HANDLE hEvent, int index)
1666{
1667 pData->phEvents[index] = hEvent;
1668}
1669#endif
1670
1671unsigned int slirp_get_timeout_ms(PNATState pData)
1672{
1673 if (link_up)
1674 {
1675 if (time_fasttimo)
1676 return 2;
1677 if (do_slowtimo)
1678 return 500; /* see PR_SLOWHZ */
1679 }
1680 return 0;
1681}
1682
1683#ifndef RT_OS_WINDOWS
1684int slirp_get_nsock(PNATState pData)
1685{
1686 return pData->nsock;
1687}
1688#endif
1689
1690/*
1691 * this function called from NAT thread
1692 */
1693void slirp_post_sent(PNATState pData, void *pvArg)
1694{
1695 struct socket *so = 0;
1696 struct tcpcb *tp = 0;
1697 struct mbuf *m = (struct mbuf *)pvArg;
1698 m_free(pData, m);
1699}
1700#ifdef VBOX_WITH_SLIRP_MT
1701void slirp_process_queue(PNATState pData)
1702{
1703 RTReqProcess(pData->pReqQueue, RT_INDEFINITE_WAIT);
1704}
1705void *slirp_get_queue(PNATState pData)
1706{
1707 return pData->pReqQueue;
1708}
1709#endif
1710
1711void slirp_set_dhcp_TFTP_prefix(PNATState pData, const char *tftpPrefix)
1712{
1713 Log2(("tftp_prefix:%s\n", tftpPrefix));
1714 tftp_prefix = tftpPrefix;
1715}
1716
1717void slirp_set_dhcp_TFTP_bootfile(PNATState pData, const char *bootFile)
1718{
1719 Log2(("bootFile:%s\n", bootFile));
1720 bootp_filename = bootFile;
1721}
1722
1723void slirp_set_dhcp_next_server(PNATState pData, const char *next_server)
1724{
1725 Log2(("next_server:%s\n", next_server));
1726 if (next_server == NULL)
1727 pData->tftp_server.s_addr = htonl(ntohl(special_addr.s_addr) | CTL_TFTP);
1728 else
1729 inet_aton(next_server, &pData->tftp_server);
1730}
1731
1732int slirp_set_binding_address(PNATState pData, char *addr)
1733{
1734 if (addr == NULL || (inet_aton(addr, &pData->bindIP) == 0))
1735 {
1736 pData->bindIP.s_addr = INADDR_ANY;
1737 return 1;
1738 }
1739 return 0;
1740}
1741
1742void slirp_set_dhcp_dns_proxy(PNATState pData, bool fDNSProxy)
1743{
1744 Log2(("NAT: DNS proxy switched %s\n", (fDNSProxy ? "on" : "off")));
1745 pData->use_dns_proxy = fDNSProxy;
1746}
1747
1748#define CHECK_ARG(name, val, lim_min, lim_max) \
1749do { \
1750 if ((val) < (lim_min) || (val) > (lim_max)) \
1751 { \
1752 LogRel(("NAT: (" #name ":%d) has been ignored, " \
1753 "because out of range (%d, %d)\n", (val), (lim_min), (lim_max))); \
1754 return; \
1755 } \
1756 else \
1757 { \
1758 LogRel(("NAT: (" #name ":%d)\n", (val))); \
1759 } \
1760} while (0)
1761
1762/* don't allow user set less 8kB and more than 1M values */
1763#define _8K_1M_CHECK_ARG(name, val) CHECK_ARG(name, (val), 8, 1024)
1764void slirp_set_rcvbuf(PNATState pData, int kilobytes)
1765{
1766 _8K_1M_CHECK_ARG("SOCKET_RCVBUF", kilobytes);
1767 pData->socket_rcv = kilobytes;
1768}
1769void slirp_set_sndbuf(PNATState pData, int kilobytes)
1770{
1771 _8K_1M_CHECK_ARG("SOCKET_SNDBUF", kilobytes);
1772 pData->socket_snd = kilobytes * _1K;
1773}
1774void slirp_set_tcp_rcvspace(PNATState pData, int kilobytes)
1775{
1776 _8K_1M_CHECK_ARG("TCP_RCVSPACE", kilobytes);
1777 tcp_rcvspace = kilobytes * _1K;
1778}
1779void slirp_set_tcp_sndspace(PNATState pData, int kilobytes)
1780{
1781 _8K_1M_CHECK_ARG("TCP_SNDSPACE", kilobytes);
1782 tcp_sndspace = kilobytes * _1K;
1783}
1784
注意: 瀏覽 TracBrowser 來幫助您使用儲存庫瀏覽器

© 2025 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette