version 1.128, 2001/03/01 16:31:39 |
version 1.134, 2001/05/21 03:31:36 |
Line 211 struct pfil_head inet_pfil_hook; |
|
Line 211 struct pfil_head inet_pfil_hook; |
|
|
|
struct ipqhead ipq; |
struct ipqhead ipq; |
int ipq_locked; |
int ipq_locked; |
|
int ip_nfragpackets = 0; |
|
int ip_maxfragpackets = 200; |
|
|
static __inline int ipq_lock_try __P((void)); |
static __inline int ipq_lock_try __P((void)); |
static __inline void ipq_unlock __P((void)); |
static __inline void ipq_unlock __P((void)); |
|
|
{ |
{ |
int s; |
int s; |
|
|
s = splimp(); |
/* |
|
* Use splvm() -- we're bloking things that would cause |
|
* mbuf allocation. |
|
*/ |
|
s = splvm(); |
if (ipq_locked) { |
if (ipq_locked) { |
splx(s); |
splx(s); |
return (0); |
return (0); |
|
|
{ |
{ |
int s; |
int s; |
|
|
s = splimp(); |
s = splvm(); |
ipq_locked = 0; |
ipq_locked = 0; |
splx(s); |
splx(s); |
} |
} |
|
|
struct mbuf *m; |
struct mbuf *m; |
|
|
while (1) { |
while (1) { |
s = splimp(); |
s = splnet(); |
IF_DEQUEUE(&ipintrq, m); |
IF_DEQUEUE(&ipintrq, m); |
splx(s); |
splx(s); |
if (m == 0) |
if (m == 0) |
Line 414 ip_input(struct mbuf *m) |
|
Line 420 ip_input(struct mbuf *m) |
|
* not allowed. |
* not allowed. |
*/ |
*/ |
if (IN_MULTICAST(ip->ip_src.s_addr)) { |
if (IN_MULTICAST(ip->ip_src.s_addr)) { |
/* XXX stat */ |
ipstat.ips_badaddr++; |
goto bad; |
goto bad; |
} |
} |
|
|
|
/* 127/8 must not appear on wire - RFC1122 */ |
|
if ((ntohl(ip->ip_dst.s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET || |
|
(ntohl(ip->ip_src.s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET) { |
|
if ((m->m_pkthdr.rcvif->if_flags & IFF_LOOPBACK) == 0) { |
|
ipstat.ips_badaddr++; |
|
goto bad; |
|
} |
|
} |
|
|
if (in_cksum(m, hlen) != 0) { |
if (in_cksum(m, hlen) != 0) { |
ipstat.ips_badsum++; |
ipstat.ips_badsum++; |
goto bad; |
goto bad; |
Line 772 ip_reass(ipqe, fp) |
|
Line 787 ip_reass(ipqe, fp) |
|
* If first fragment to arrive, create a reassembly queue. |
* If first fragment to arrive, create a reassembly queue. |
*/ |
*/ |
if (fp == 0) { |
if (fp == 0) { |
|
/* |
|
* Enforce upper bound on number of fragmented packets |
|
* for which we attempt reassembly; |
|
* If maxfrag is 0, never accept fragments. |
|
* If maxfrag is -1, accept all fragments without limitation. |
|
*/ |
|
if (ip_maxfragpackets < 0) |
|
; |
|
else if (ip_nfragpackets >= ip_maxfragpackets) |
|
goto dropfrag; |
|
ip_nfragpackets++; |
MALLOC(fp, struct ipq *, sizeof (struct ipq), |
MALLOC(fp, struct ipq *, sizeof (struct ipq), |
M_FTABLE, M_NOWAIT); |
M_FTABLE, M_NOWAIT); |
if (fp == NULL) |
if (fp == NULL) |
|
|
ip->ip_dst = fp->ipq_dst; |
ip->ip_dst = fp->ipq_dst; |
LIST_REMOVE(fp, ipq_q); |
LIST_REMOVE(fp, ipq_q); |
FREE(fp, M_FTABLE); |
FREE(fp, M_FTABLE); |
|
ip_nfragpackets--; |
m->m_len += (ip->ip_hl << 2); |
m->m_len += (ip->ip_hl << 2); |
m->m_data -= (ip->ip_hl << 2); |
m->m_data -= (ip->ip_hl << 2); |
/* some debugging cruft by sklower, below, will go away soon */ |
/* some debugging cruft by sklower, below, will go away soon */ |
|
|
} |
} |
LIST_REMOVE(fp, ipq_q); |
LIST_REMOVE(fp, ipq_q); |
FREE(fp, M_FTABLE); |
FREE(fp, M_FTABLE); |
|
ip_nfragpackets--; |
} |
} |
|
|
/* |
/* |
|
|
ip_freef(fp); |
ip_freef(fp); |
} |
} |
} |
} |
|
/* |
|
* If we are over the maximum number of fragments |
|
* (due to the limit being lowered), drain off |
|
* enough to get down to the new limit. |
|
*/ |
|
if (ip_maxfragpackets < 0) |
|
; |
|
else { |
|
while (ip_nfragpackets > ip_maxfragpackets && ipq.lh_first) |
|
ip_freef(ipq.lh_first); |
|
} |
IPQ_UNLOCK(); |
IPQ_UNLOCK(); |
#ifdef GATEWAY |
#ifdef GATEWAY |
ipflow_slowtimo(); |
ipflow_slowtimo(); |
Line 1475 ip_forward(m, srcrt) |
|
Line 1514 ip_forward(m, srcrt) |
|
} |
} |
|
|
#ifdef IPSEC |
#ifdef IPSEC |
/* Don't lookup socket in forwading case */ |
/* Don't lookup socket in forwarding case */ |
(void)ipsec_setsocket(m, NULL); |
(void)ipsec_setsocket(m, NULL); |
#endif |
#endif |
error = ip_output(m, (struct mbuf *)0, &ipforward_rt, |
error = ip_output(m, (struct mbuf *)0, &ipforward_rt, |
Line 1782 ip_sysctl(name, namelen, oldp, oldlenp, |
|
Line 1821 ip_sysctl(name, namelen, oldp, oldlenp, |
|
return (error); |
return (error); |
#endif |
#endif |
|
|
|
case IPCTL_MAXFRAGPACKETS: |
|
return (sysctl_int(oldp, oldlenp, newp, newlen, |
|
&ip_maxfragpackets)); |
|
|
default: |
default: |
return (EOPNOTSUPP); |
return (EOPNOTSUPP); |
} |
} |