2 * (C)opyright 1992-1998 Darren Reed. (from tcplog)
4 * See the IPFILTER.LICENCE file for details on licencing.
14 #include <sys/types.h>
16 #include <sys/timeb.h>
17 #include <sys/socket.h>
19 #include <sys/ioctl.h>
20 #include <sys/stropts.h>
22 #include <sys/pfmod.h>
23 #include <sys/bufmod.h>
27 #include <netinet/in.h>
28 #include <netinet/in_systm.h>
29 #include <netinet/ip.h>
30 #include <netinet/if_ether.h>
31 #include <netinet/ip_var.h>
32 #include <netinet/udp.h>
33 #include <netinet/udp_var.h>
34 #include <netinet/tcp.h>
35 #include <netinet/tcpip.h>
37 #include "ip_compat.h"
40 static char snitid[] = "%W% %G% (C)1995 Darren Reed";
43 #define BUFSPACE 32768
48 * Be careful to only include those defined in the flags option for the
49 * interface are included in the header size.
68 tcp = (tcphdr_t *)(ip + 1);
69 bcopy(ep, (char *)ip, sizeof(*ip));
70 bcopy(ep + (ip->ip_hl << 2), (char *)tcp, sizeof(*tcp));
72 if (ip->ip_off & 0x1fff != 0)
74 if (0 == detect(ip, tcp))
80 int readloop(fd, port, dst)
84 static u_char buf[BUFSPACE];
85 register u_char *bp, *cp, *bufend;
86 register struct sb_hdr *hp;
90 time_t now = time(NULL);
91 int flags = 0, i, done = 0;
96 dbuf.maxlen = sizeof(buf);
98 * no control data buffer...
101 (void) signal(SIGALRM, nullbell);
103 i = getmsg(fd, NULL, &dbuf, &flags);
105 (void) signal(SIGALRM, nullbell);
108 if ((time(NULL) - now) > timeout)
118 * loop through each snapshot in the chunk
120 while (bp < bufend) {
122 * get past bufmod header
124 hp = (struct sb_hdr *)bp;
125 cp = (u_char *)((char *)bp + sizeof(*hp));
126 bcopy(cp, (char *)&eh, sizeof(eh));
130 bp += hp->sbh_totlen;
131 cc -= hp->sbh_totlen;
133 if (eh.ether_type != ETHERTYPE_IP)
137 done += ack_recv(cp);
145 int initdevice(device, tout)
152 struct packetfilt pfil;
154 u_short *fwp = pfil.Pf_Filter;
155 char devname[16], *s, buf[256];
156 int i, offset, fd, snaplen= 58, chunksize = BUFSPACE;
158 (void) sprintf(devname, "/dev/%s", device);
161 while (*s && !ISDIGIT(*s))
165 fprintf(stderr, "bad device name %s\n", devname);
173 if ((fd = open(devname, O_RDWR)) < 0)
175 fprintf(stderr, "O_RDWR(0) ");
179 if (dlattachreq(fd, i) == -1 || dlokack(fd, buf) == -1)
181 fprintf(stderr, "DLPI error\n");
184 dlbindreq(fd, ETHERTYPE_IP, 0, DL_CLDLS, 0, 0);
189 if (strioctl(fd, DLIOCRAW, -1, 0, NULL) == -1)
191 fprintf(stderr, "DLIOCRAW error\n");
195 * Create some filter rules for our TCP watcher. We only want ethernet
196 * pacets which are IP protocol and only the TCP packets from IP.
199 *fwp++ = ENF_PUSHWORD + offset;
200 *fwp++ = ENF_PUSHLIT | ENF_CAND;
201 *fwp++ = htons(ETHERTYPE_IP);
202 *fwp++ = ENF_PUSHWORD + sizeof(struct ether_header)/sizeof(short)+4;
203 *fwp++ = ENF_PUSHLIT | ENF_AND;
204 *fwp++ = htons(0x00ff);
205 *fwp++ = ENF_PUSHLIT | ENF_COR;
206 *fwp++ = htons(IPPROTO_TCP);
207 *fwp++ = ENF_PUSHWORD + sizeof(struct ether_header)/sizeof(short)+4;
208 *fwp++ = ENF_PUSHLIT | ENF_AND;
209 *fwp++ = htons(0x00ff);
210 *fwp++ = ENF_PUSHLIT | ENF_CAND;
211 *fwp++ = htons(IPPROTO_UDP);
212 pfil.Pf_FilterLen = (fwp - &pfil.Pf_Filter[0]);
214 * put filter in place.
217 if (ioctl(fd, I_PUSH, "pfmod") == -1)
219 perror("ioctl: I_PUSH pf");
222 if (strioctl(fd, PFIOCSETF, -1, sizeof(pfil), (char *)&pfil) == -1)
224 perror("ioctl: PFIOCSETF");
229 * arrange to get messages from the NIT STREAM and use NIT_BUF option
231 if (ioctl(fd, I_PUSH, "bufmod") == -1)
233 perror("ioctl: I_PUSH bufmod");
237 strioctl(fd, SBIOCSSNAP, -1, sizeof(i), (char *)&i);
243 if (strioctl(fd, SBIOCSTIME, -1, sizeof(to), (char *)&to) == -1)
245 perror("strioctl(SBIOCSTIME)");
251 if (ioctl(fd, I_FLUSH, FLUSHR) == -1)