1 | /* |
2 | * Copyright (c) 2012-2021 Apple Inc. All rights reserved. |
3 | * |
4 | * @APPLE_OSREFERENCE_LICENSE_HEADER_START@ |
5 | * |
6 | * This file contains Original Code and/or Modifications of Original Code |
7 | * as defined in and that are subject to the Apple Public Source License |
8 | * Version 2.0 (the 'License'). You may not use this file except in |
9 | * compliance with the License. The rights granted to you under the License |
10 | * may not be used to create, or enable the creation or redistribution of, |
11 | * unlawful or unlicensed copies of an Apple operating system, or to |
12 | * circumvent, violate, or enable the circumvention or violation of, any |
13 | * terms of an Apple operating system software license agreement. |
14 | * |
15 | * Please obtain a copy of the License at |
16 | * http://www.opensource.apple.com/apsl/ and read it before using this file. |
17 | * |
18 | * The Original Code and all software distributed under the License are |
19 | * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER |
20 | * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, |
21 | * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, |
22 | * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. |
23 | * Please see the License for the specific language governing rights and |
24 | * limitations under the License. |
25 | * |
26 | * @APPLE_OSREFERENCE_LICENSE_HEADER_END@ |
27 | */ |
28 | |
29 | |
30 | #ifndef _NET_IF_IPSEC_H_ |
31 | #define _NET_IF_IPSEC_H_ |
32 | |
33 | #ifdef BSD_KERNEL_PRIVATE |
34 | |
35 | #include <sys/kern_control.h> |
36 | #include <netinet/ip_var.h> |
37 | |
38 | |
39 | errno_t ipsec_register_control(void); |
40 | |
41 | /* Helpers */ |
42 | int ipsec_interface_isvalid(ifnet_t interface); |
43 | #if SKYWALK |
44 | boolean_t ipsec_interface_needs_netagent(ifnet_t interface); |
45 | #endif /* SKYWALK */ |
46 | |
47 | errno_t ipsec_inject_inbound_packet(ifnet_t interface, mbuf_t packet); |
48 | |
49 | void ipsec_set_pkthdr_for_interface(ifnet_t interface, mbuf_t packet, int family, |
50 | uint32_t flowid); |
51 | |
52 | void ipsec_set_ipoa_for_interface(ifnet_t interface, struct ip_out_args *ipoa); |
53 | |
54 | struct ip6_out_args; |
55 | void ipsec_set_ip6oa_for_interface(ifnet_t interface, struct ip6_out_args *ip6oa); |
56 | |
57 | #endif |
58 | |
59 | /* |
60 | * Name registered by the ipsec kernel control |
61 | */ |
62 | #define IPSEC_CONTROL_NAME "com.apple.net.ipsec_control" |
63 | |
64 | /* |
65 | * Socket option names to manage ipsec |
66 | */ |
67 | #define IPSEC_OPT_FLAGS 1 |
68 | #define IPSEC_OPT_IFNAME 2 |
69 | #define IPSEC_OPT_EXT_IFDATA_STATS 3 /* get|set (type int) */ |
70 | #define IPSEC_OPT_INC_IFDATA_STATS_IN 4 /* set to increment stat counters (type struct ipsec_stats_param) */ |
71 | #define IPSEC_OPT_INC_IFDATA_STATS_OUT 5 /* set to increment stat counters (type struct ipsec_stats_param) */ |
72 | #define IPSEC_OPT_SET_DELEGATE_INTERFACE 6 /* set the delegate interface (char[]) */ |
73 | #define IPSEC_OPT_OUTPUT_TRAFFIC_CLASS 7 /* set the traffic class for packets leaving the interface, see sys/socket.h */ |
74 | #define IPSEC_OPT_ENABLE_CHANNEL 8 /* enable a kernel pipe nexus that allows the owner to open a channel to act as a driver, |
75 | * Must be set before connecting */ |
76 | #define IPSEC_OPT_GET_CHANNEL_UUID 9 /* get the uuid of the kernel pipe nexus instance */ |
77 | #define IPSEC_OPT_ENABLE_FLOWSWITCH 10 /* enable a flowswitch nexus that clients can use */ |
78 | #define IPSEC_OPT_INPUT_FRAG_SIZE 11 /* set the maximum size of input packets before fragmenting as a uint32_t */ |
79 | |
80 | #define IPSEC_OPT_ENABLE_NETIF 12 /* Must be set before connecting */ |
81 | #define IPSEC_OPT_SLOT_SIZE 13 /* Must be set before connecting */ |
82 | #define IPSEC_OPT_NETIF_RING_SIZE 14 /* Must be set before connecting */ |
83 | #define IPSEC_OPT_TX_FSW_RING_SIZE 15 /* Must be set before connecting */ |
84 | #define IPSEC_OPT_RX_FSW_RING_SIZE 16 /* Must be set before connecting */ |
85 | #define IPSEC_OPT_CHANNEL_BIND_PID 17 /* Must be set before connecting */ |
86 | #define IPSEC_OPT_KPIPE_TX_RING_SIZE 18 /* Must be set before connecting */ |
87 | #define IPSEC_OPT_KPIPE_RX_RING_SIZE 19 /* Must be set before connecting */ |
88 | #define IPSEC_OPT_CHANNEL_BIND_UUID 20 /* Must be set before connecting */ |
89 | |
90 | #define IPSEC_OPT_OUTPUT_DSCP_MAPPING 21 /* Must be set before connecting */ |
91 | |
92 | typedef enum { |
93 | IPSEC_DSCP_MAPPING_COPY = 0, /* Copy DSCP bits from inner IP header to outer IP header */ |
94 | IPSEC_DSCP_MAPPING_LEGACY = 1, /* Copies bits from the outer IP header that are at TOS offset of the inner IP header, into the DSCP of the outer IP header */ |
95 | } ipsec_dscp_mapping_t; |
96 | |
97 | /* |
98 | * ipsec stats parameter structure |
99 | */ |
100 | struct ipsec_stats_param { |
101 | u_int64_t utsp_packets; |
102 | u_int64_t utsp_bytes; |
103 | u_int64_t utsp_errors; |
104 | }; |
105 | |
106 | #endif |
107 | |