4 #include <netinet/ip_fw.h>
7 #define IPFW_NEWTABLES_MAX 256
10 /* Object stored in the hash table */
16 MALLOC_DEFINE(M_IPFW_HTBL, "ipfw_tbl", "IpFw tables");
18 int add_table_entry(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr,
19 uint8_t mlen, uint32_t value);
20 int new_del_table_entry(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr);
21 int del_table_entry(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr,
23 int new_flush_table(struct ip_fw_chain *ch, uint16_t tbl);
24 int flush_table(struct ip_fw_chain *ch, uint16_t tbl);
25 int lookup_table(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr,
27 int new_count_table_entry(struct ip_fw_chain *ch, uint32_t tbl, uint32_t *cnt);
28 int count_table(struct ip_fw_chain *ch, uint32_t tbl, uint32_t *cnt);
29 int new_dump_table_entry(struct ip_fw_chain *ch, ipfw_table *tbl);
30 int dump_table(struct ip_fw_chain *ch, ipfw_table *tbl);
31 int init_tables(struct ip_fw_chain *ch);
33 /* hash and compare functions for 32-bit entries */
35 simple_hash32(const void *key, uint32_t size)
37 uint32_t ret = *(const uint32_t *)key % size;
43 cmp_func32(const void *key1, const void *key2, int sz)
45 int k1 = *(const int *)key1;
46 int k2 = *(const int *)key2;
60 add_table_entry(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr,
61 uint8_t mlen, uint32_t value)
64 * - Search the correct hash table (tbl - IPFW_TABLES_MAX)
65 * - Search if the entry already exists
66 * - Insert the new entry in the table
67 * - Possibly reallocate the table if it is too small
72 int i = tbl - IPFW_TABLES_MAX;
74 int obj_size = sizeof(struct t_o);
76 if (i < 0 || i > size-1) /* wrong table number */
78 if (ch->global_tables[i] == NULL) {
79 ch->global_tables[i] = new_table_init(size, obj_size,
80 simple_hash32, cmp_func32, M_IPFW_HTBL);
87 /* Insert the object in the table */
88 ret = new_table_insert_obj(ch->global_tables[i], &obj);
93 new_del_table_entry(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr)
96 int nr = tbl - IPFW_TABLES_MAX;
98 ret = new_table_delete_obj(ch->global_tables[nr], &addr);
104 del_table_entry(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr,
107 if (tbl >= IPFW_TABLES_MAX && tbl < IPFW_NEWTABLES_MAX) {
108 new_del_table_entry(ch, tbl, addr);
115 new_flush_table(struct ip_fw_chain *ch, uint16_t tbl)
117 new_table_destroy(ch->global_tables[tbl - IPFW_TABLES_MAX]);
122 flush_table(struct ip_fw_chain *ch, uint16_t tbl)
124 if (tbl >= IPFW_TABLES_MAX && tbl < IPFW_NEWTABLES_MAX)
125 return new_flush_table(ch, tbl);
131 lookup_table(struct ip_fw_chain *ch, uint16_t tbl, in_addr_t addr,
134 if (tbl >= IPFW_TABLES_MAX && tbl < IPFW_NEWTABLES_MAX) {
135 struct new_hash_table *h;
136 const struct t_o *obj;
138 h = ch->global_tables[tbl - IPFW_TABLES_MAX];
140 obj = new_table_extract_obj(h, (void *)&addr);
142 return 0; /* no match */
145 return 1; /* match */
151 new_count_table_entry(struct ip_fw_chain *ch, uint32_t tbl, uint32_t *cnt)
153 *cnt = new_table_get_element(ch->global_tables[tbl - IPFW_TABLES_MAX]);
158 count_table(struct ip_fw_chain *ch, uint32_t tbl, uint32_t *cnt)
160 if (tbl >= IPFW_TABLES_MAX && tbl < IPFW_NEWTABLES_MAX) {
161 new_count_table_entry(ch, tbl, cnt);
168 new_dump_table_entry(struct ip_fw_chain *ch, ipfw_table *tbl)
170 /* fill the tbl with all entryes */
171 ipfw_table_entry *ent;
172 const struct t_o *obj;
175 int nr = tbl->tbl - IPFW_TABLES_MAX;
176 struct new_hash_table *t = ch->global_tables[nr];
181 /* XXX determine tbl->size */
182 n_el = new_table_get_element(t);
184 for (; n_el > 0; n_el--) {
185 obj = table_next(t, obj);
188 ent = &tbl->ent[tbl->cnt];
190 ent->addr = obj->addr;
191 ent->value = obj->value;
192 ent->masklen = obj->mask;
199 dump_table(struct ip_fw_chain *ch, ipfw_table *tbl)
201 if (tbl->tbl >= IPFW_TABLES_MAX && tbl->tbl < IPFW_NEWTABLES_MAX) {
202 new_dump_table_entry(ch, tbl);
209 init_tables(struct ip_fw_chain *ch)
213 /* Initialize new tables XXXMPD */
214 for (i = 0; i < IPFW_NEWTABLES_MAX - IPFW_TABLES_MAX; i++) {
215 memset(&ch->global_tables[i], sizeof(struct new_hash_table*), 0);