| 1 | /*- |
| 2 | * SPDX-License-Identifier: BSD-3-Clause |
| 3 | * |
| 4 | * Copyright (c) 1982, 1986, 1993, 1994, 1995 |
| 5 | *	The Regents of the University of California. All rights reserved. |
| 6 | * |
| 7 | * Redistribution and use in source and binary forms, with or without |
| 8 | * modification, are permitted provided that the following conditions |
| 9 | * are met: |
| 10 | * 1. Redistributions of source code must retain the above copyright |
| 11 | * notice, this list of conditions and the following disclaimer. |
| 12 | * 2. Redistributions in binary form must reproduce the above copyright |
| 13 | * notice, this list of conditions and the following disclaimer in the |
| 14 | * documentation and/or other materials provided with the distribution. |
| 15 | * 3. Neither the name of the University nor the names of its contributors |
| 16 | * may be used to endorse or promote products derived from this software |
| 17 | * without specific prior written permission. |
| 18 | * |
| 19 | * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND |
| 20 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
| 21 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
| 22 | * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE |
| 23 | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL |
| 24 | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS |
| 25 | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) |
| 26 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT |
| 27 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
| 28 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
| 29 | * SUCH DAMAGE. |
| 30 | */ |
| 31 | |
| 32 | #ifndef _NETINET_TCP_SYNCACHE_H_ |
| 33 | #define _NETINET_TCP_SYNCACHE_H_ |
| 34 | #ifdef _KERNEL |
| 35 | |
| 36 | void	 syncache_init(void); |
| 37 | #ifdef VIMAGE |
| 38 | void	syncache_destroy(void); |
| 39 | #endif |
| 40 | void	 syncache_unreach(struct in_conninfo *, tcp_seq, uint16_t); |
| 41 | int	 syncache_expand(struct in_conninfo *, struct tcpopt *, |
| 42 | 	 struct tcphdr *, struct socket **, struct mbuf *, uint16_t); |
| 43 | struct socket *	 syncache_add(struct in_conninfo *, struct tcpopt *, |
| 44 | 	 struct tcphdr *, struct inpcb *, struct socket *, struct mbuf *, |
| 45 | 	 void *, void *, uint8_t, uint16_t); |
| 46 | void	 syncache_chkrst(struct in_conninfo *, struct tcphdr *, struct mbuf *, |
| 47 | 	 uint16_t); |
| 48 | int	 syncache_pcblist(struct sysctl_req *); |
| 49 | |
| 50 | struct syncache { |
| 51 | 	TAILQ_ENTRY(syncache)	sc_hash; |
| 52 | 	struct in_conninfo	sc_inc;		/* addresses */ |
| 53 | 	int		sc_rxttime;		/* retransmit time */ |
| 54 | 	u_int16_t	sc_rxmits;		/* retransmit counter */ |
| 55 | 	u_int16_t	sc_port;		/* remote UDP encaps port */ |
| 56 | 	u_int32_t	sc_tsreflect;		/* timestamp to reflect */ |
| 57 | 	u_int32_t	sc_tsoff;		/* ts offset w/ syncookies */ |
| 58 | 	u_int32_t	sc_flowlabel;		/* IPv6 flowlabel */ |
| 59 | 	tcp_seq		sc_irs;			/* seq from peer */ |
| 60 | 	tcp_seq		sc_iss;			/* our ISS */ |
| 61 | 	struct mbuf	*sc_ipopts;		/* source route */ |
| 62 | 	u_int16_t	sc_peer_mss;		/* peer's MSS */ |
| 63 | 	u_int16_t	sc_wnd;			/* advertised window */ |
| 64 | 	u_int8_t	sc_ip_ttl;		/* TTL / Hop Limit */ |
| 65 | 	u_int8_t	sc_ip_tos;		/* TOS / Traffic Class */ |
| 66 | 	u_int8_t	sc_requested_s_scale:4, |
| 67 | 			sc_requested_r_scale:4; |
| 68 | 	u_int16_t	sc_flags; |
| 69 | 	u_int32_t	sc_challenge_ack_cnt;	/* chall. ACKs sent in epoch */ |
| 70 | 	sbintime_t	sc_challenge_ack_end;	/* End of chall. ack epoch */ |
| 71 | #if defined(TCP_OFFLOAD) |
| 72 | 	struct toedev	*sc_tod;		/* entry added by this TOE */ |
| 73 | 	void		*sc_todctx;		/* TOE driver context */ |
| 74 | #endif |
| 75 | 	struct label	*sc_label;		/* MAC label reference */ |
| 76 | 	struct ucred	*sc_cred;		/* cred cache for jail checks */ |
| 77 | 	void		*sc_tfo_cookie;		/* for TCP Fast Open response */ |
| 78 | 	void		*sc_pspare;		/* TCP_SIGNATURE */ |
| 79 | 	u_int32_t	sc_spare[2];		/* UTO */ |
| 80 | }; |
| 81 | |
| 82 | /* |
| 83 | * Flags for the sc_flags field. |
| 84 | */ |
| 85 | #define SCF_NOOPT	0x01			/* no TCP options */ |
| 86 | #define SCF_WINSCALE	0x02			/* negotiated window scaling */ |
| 87 | #define SCF_TIMESTAMP	0x04			/* negotiated timestamps */ |
| 88 | 						/* MSS is implicit */ |
| 89 | #define SCF_UNREACH	0x10			/* icmp unreachable received */ |
| 90 | #define SCF_SIGNATURE	0x20			/* send MD5 digests */ |
| 91 | #define SCF_SACK	0x80			/* send SACK option */ |
| 92 | #define SCF_ECN_MASK	0x700			/* ECN codepoint mask */ |
| 93 | #define SCF_ECN 	0x100			/* send ECN setup packet */ |
| 94 | #define SCF_ACE_N	0x400			/* send ACE non-ECT setup */ |
| 95 | #define SCF_ACE_0	0x500			/* send ACE ECT0 setup */ |
| 96 | #define SCF_ACE_1	0x600			/* send ACE ECT1 setup */ |
| 97 | #define SCF_ACE_CE	0x700			/* send ACE CE setup */ |
| 98 | |
| 99 | struct syncache_head { |
| 100 | 	struct mtx	sch_mtx; |
| 101 | 	TAILQ_HEAD(sch_head, syncache)	sch_bucket; |
| 102 | 	struct callout	sch_timer; |
| 103 | 	int		sch_nextc; |
| 104 | 	u_int		sch_length; |
| 105 | 	struct tcp_syncache *sch_sc; |
| 106 | 	time_t		sch_last_overflow; |
| 107 | }; |
| 108 | |
| 109 | #define	SYNCOOKIE_SECRET_SIZE	16 |
| 110 | #define	SYNCOOKIE_LIFETIME	15		/* seconds */ |
| 111 | |
| 112 | struct syncookie_secret { |
| 113 | 	volatile u_int oddeven; |
| 114 | 	uint8_t key[2][SYNCOOKIE_SECRET_SIZE]; |
| 115 | 	struct callout reseed; |
| 116 | 	u_int lifetime; |
| 117 | }; |
| 118 | |
| 119 | #define	TCP_SYNCACHE_PAUSE_TIME		SYNCOOKIE_LIFETIME |
| 120 | #define	TCP_SYNCACHE_MAX_BACKOFF	6	/* 16 minutes */ |
| 121 | |
| 122 | struct tcp_syncache { |
| 123 | 	struct	syncache_head *hashbase; |
| 124 | 	uma_zone_t zone; |
| 125 | 	u_int	hashsize; |
| 126 | 	u_int	hashmask; |
| 127 | 	u_int	bucket_limit; |
| 128 | 	u_int	cache_limit; |
| 129 | 	u_int	rexmt_limit; |
| 130 | 	uint32_t hash_secret; |
| 131 | #ifdef VIMAGE |
| 132 | 	struct vnet *vnet; |
| 133 | #endif |
| 134 | 	struct syncookie_secret secret; |
| 135 | 	struct mtx pause_mtx; |
| 136 | 	struct callout pause_co; |
| 137 | 	time_t	pause_until; |
| 138 | 	uint8_t pause_backoff; |
| 139 | 	volatile bool paused; |
| 140 | 	bool see_other; |
| 141 | }; |
| 142 | |
| 143 | /* Internal use for the syncookie functions. */ |
| 144 | union syncookie { |
| 145 | 	uint8_t cookie; |
| 146 | 	struct { |
| 147 | 		uint8_t odd_even:1, |
| 148 | 			sack_ok:1, |
| 149 | 			wscale_idx:3, |
| 150 | 			mss_idx:3; |
| 151 | 	} flags; |
| 152 | }; |
| 153 | |
| 154 | #endif /* _KERNEL */ |
| 155 | #endif /* !_NETINET_TCP_SYNCACHE_H_ */ |