1/* $OpenBSD: if_pflog.h,v 1.13 2006/10/23 12:46:09 henning Exp $ */
2/*-
3 * SPDX-License-Identifier: BSD-2-Clause
4 *
5 * Copyright 2001 Niels Provos <provos@citi.umich.edu>
6 * All rights reserved.
7 *
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
10 * are met:
11 * 1. Redistributions of source code must retain the above copyright
12 *    notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 *    notice, this list of conditions and the following disclaimer in the
15 *    documentation and/or other materials provided with the distribution.
16 *
17 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
18 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
19 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
20 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
21 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
22 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
23 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
24 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
25 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
26 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27 */
28
29#ifndef _NET_IF_PFLOG_H_
30#define	_NET_IF_PFLOG_H_
31
32#include <sys/types.h>
33
34#include <net/if.h>
35
36#define	PFLOGIFS_MAX	16
37
38#define	PFLOG_RULESET_NAME_SIZE	16
39
40struct pfloghdr {
41	u_int8_t	length;
42	sa_family_t	af;
43	u_int8_t	action;
44	u_int8_t	reason;
45	char		ifname[IFNAMSIZ];
46	char		ruleset[PFLOG_RULESET_NAME_SIZE];
47	u_int32_t	rulenr;
48	u_int32_t	subrulenr;
49	uid_t		uid;
50	pid_t		pid;
51	uid_t		rule_uid;
52	pid_t		rule_pid;
53	u_int8_t	dir;
54	u_int8_t	pad[3];
55	u_int32_t	ridentifier;
56	u_int8_t	reserve;	/* Appease broken software like Wireshark. */
57	u_int8_t	pad2[3];
58};
59
60#define PFLOG_ALIGNMENT		sizeof(uint32_t)
61#define PFLOG_ALIGN(x)		(((x) + PFLOG_ALIGNMENT - 1) & ~(PFLOG_ALIGNMENT - 1))
62#define	PFLOG_HDRLEN		PFLOG_ALIGN(offsetof(struct pfloghdr, pad2))
63/* minus pad, also used as a signature */
64#define	PFLOG_REAL_HDRLEN	offsetof(struct pfloghdr, pad2)
65
66#ifdef _KERNEL
67struct pf_rule;
68struct pf_ruleset;
69struct pfi_kif;
70struct pf_pdesc;
71
72#define	PFLOG_PACKET(i,a,b,t,c,d,e,f,g,di) do {		\
73	if (pflog_packet_ptr != NULL)			\
74		pflog_packet_ptr(i,a,b,t,c,d,e,f,g,di);	\
75} while (0)
76#endif /* _KERNEL */
77#endif /* _NET_IF_PFLOG_H_ */
78