1 // SoftEther VPN Source Code - Stable Edition Repository
2 // Cedar Communication Module
3 //
4 // SoftEther VPN Server, Client and Bridge are free software under the Apache License, Version 2.0.
5 //
6 // Copyright (c) Daiyuu Nobori.
7 // Copyright (c) SoftEther VPN Project, University of Tsukuba, Japan.
8 // Copyright (c) SoftEther Corporation.
9 // Copyright (c) all contributors on SoftEther VPN project in GitHub.
10 //
11 // All Rights Reserved.
12 //
13 // http://www.softether.org/
14 //
15 // This stable branch is officially managed by Daiyuu Nobori, the owner of SoftEther VPN Project.
16 // Pull requests should be sent to the Developer Edition Master Repository on https://github.com/SoftEtherVPN/SoftEtherVPN
17 //
18 // License: The Apache License, Version 2.0
19 // https://www.apache.org/licenses/LICENSE-2.0
20 //
21 // DISCLAIMER
22 // ==========
23 //
24 // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
25 // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
26 // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
27 // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
28 // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
29 // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
30 // SOFTWARE.
31 //
32 // THIS SOFTWARE IS DEVELOPED IN JAPAN, AND DISTRIBUTED FROM JAPAN, UNDER
33 // JAPANESE LAWS. YOU MUST AGREE IN ADVANCE TO USE, COPY, MODIFY, MERGE, PUBLISH,
34 // DISTRIBUTE, SUBLICENSE, AND/OR SELL COPIES OF THIS SOFTWARE, THAT ANY
35 // JURIDICAL DISPUTES WHICH ARE CONCERNED TO THIS SOFTWARE OR ITS CONTENTS,
36 // AGAINST US (SOFTETHER PROJECT, SOFTETHER CORPORATION, DAIYUU NOBORI OR OTHER
37 // SUPPLIERS), OR ANY JURIDICAL DISPUTES AGAINST US WHICH ARE CAUSED BY ANY KIND
38 // OF USING, COPYING, MODIFYING, MERGING, PUBLISHING, DISTRIBUTING, SUBLICENSING,
39 // AND/OR SELLING COPIES OF THIS SOFTWARE SHALL BE REGARDED AS BE CONSTRUED AND
40 // CONTROLLED BY JAPANESE LAWS, AND YOU MUST FURTHER CONSENT TO EXCLUSIVE
41 // JURISDICTION AND VENUE IN THE COURTS SITTING IN TOKYO, JAPAN. YOU MUST WAIVE
42 // ALL DEFENSES OF LACK OF PERSONAL JURISDICTION AND FORUM NON CONVENIENS.
43 // PROCESS MAY BE SERVED ON EITHER PARTY IN THE MANNER AUTHORIZED BY APPLICABLE
44 // LAW OR COURT RULE.
45 //
46 // USE ONLY IN JAPAN. DO NOT USE THIS SOFTWARE IN ANOTHER COUNTRY UNLESS YOU HAVE
47 // A CONFIRMATION THAT THIS SOFTWARE DOES NOT VIOLATE ANY CRIMINAL LAWS OR CIVIL
48 // RIGHTS IN THAT PARTICULAR COUNTRY. USING THIS SOFTWARE IN OTHER COUNTRIES IS
49 // COMPLETELY AT YOUR OWN RISK. THE SOFTETHER VPN PROJECT HAS DEVELOPED AND
50 // DISTRIBUTED THIS SOFTWARE TO COMPLY ONLY WITH THE JAPANESE LAWS AND EXISTING
51 // CIVIL RIGHTS INCLUDING PATENTS WHICH ARE SUBJECTS APPLY IN JAPAN. OTHER
52 // COUNTRIES' LAWS OR CIVIL RIGHTS ARE NONE OF OUR CONCERNS NOR RESPONSIBILITIES.
53 // WE HAVE NEVER INVESTIGATED ANY CRIMINAL REGULATIONS, CIVIL LAWS OR
54 // INTELLECTUAL PROPERTY RIGHTS INCLUDING PATENTS IN ANY OF OTHER 200+ COUNTRIES
55 // AND TERRITORIES. BY NATURE, THERE ARE 200+ REGIONS IN THE WORLD, WITH
56 // DIFFERENT LAWS. IT IS IMPOSSIBLE TO VERIFY EVERY COUNTRIES' LAWS, REGULATIONS
57 // AND CIVIL RIGHTS TO MAKE THE SOFTWARE COMPLY WITH ALL COUNTRIES' LAWS BY THE
58 // PROJECT. EVEN IF YOU WILL BE SUED BY A PRIVATE ENTITY OR BE DAMAGED BY A
59 // PUBLIC SERVANT IN YOUR COUNTRY, THE DEVELOPERS OF THIS SOFTWARE WILL NEVER BE
60 // LIABLE TO RECOVER OR COMPENSATE SUCH DAMAGES, CRIMINAL OR CIVIL
61 // RESPONSIBILITIES. NOTE THAT THIS LINE IS NOT LICENSE RESTRICTION BUT JUST A
62 // STATEMENT FOR WARNING AND DISCLAIMER.
63 //
64 // READ AND UNDERSTAND THE 'WARNING.TXT' FILE BEFORE USING THIS SOFTWARE.
65 // SOME SOFTWARE PROGRAMS FROM THIRD PARTIES ARE INCLUDED ON THIS SOFTWARE WITH
66 // LICENSE CONDITIONS WHICH ARE DESCRIBED ON THE 'THIRD_PARTY.TXT' FILE.
67 //
68 //
69 // SOURCE CODE CONTRIBUTION
70 // ------------------------
71 //
72 // Your contribution to SoftEther VPN Project is much appreciated.
73 // Please send patches to us through GitHub.
74 // Read the SoftEther VPN Patch Acceptance Policy in advance:
75 // http://www.softether.org/5-download/src/9.patch
76 //
77 //
78 // DEAR SECURITY EXPERTS
79 // ---------------------
80 //
81 // If you find a bug or a security vulnerability please kindly inform us
82 // about the problem immediately so that we can fix the security problem
83 // to protect a lot of users around the world as soon as possible.
84 //
85 // Our e-mail address for security reports is:
86 // softether-vpn-security [at] softether.org
87 //
88 // Please note that the above e-mail address is not a technical support
89 // inquiry address. If you need technical assistance, please visit
90 // http://www.softether.org/ and ask your question on the users forum.
91 //
92 // Thank you for your cooperation.
93 //
94 //
95 // NO MEMORY OR RESOURCE LEAKS
96 // ---------------------------
97 //
98 // The memory-leaks and resource-leaks verification under the stress
99 // test has been passed before release this source code.
100 
101 
102 // NativeStack.h
103 // Header of NativeStack.c
104 
105 #ifndef	NATIVESTACK_H
106 #define	NATIVESTACK_H
107 
108 //// Constants
109 #define	NS_MAC_ADDRESS_BYTE_1		0xDA		// First byte of the MAC address
110 
111 #define	NS_CHECK_IPTABLES_INTERVAL_INIT	(1 * 1000)
112 
113 #define	NS_CHECK_IPTABLES_INTERVAL_MAX	(5 * 60 * 1000)
114 
115 //// Type
116 struct NATIVE_STACK
117 {
118 	CEDAR *Cedar;
119 	IPC *Ipc;						// IPC object
120 	char DeviceName[MAX_SIZE];		// Ethernet device name
121 	THREAD *MainThread;				// Main thread
122 	bool Halt;						// Halting flag
123 	CANCEL *Cancel;					// Cancel
124 	UCHAR MacAddress[6];			// MAC address of the virtual host
125 	ETH *Eth;						// Eth device
126 	SOCK *Sock1;					// Sock1 (To be used in the bridge side)
127 	SOCK *Sock2;					// Sock2 (Used in the IPC side)
128 	DHCP_OPTION_LIST CurrentDhcpOptionList;	// Current DHCP options list
129 	IP DnsServerIP;					// IP address of the DNS server
130 	IP DnsServerIP2;				// IP address of the DNS server #2
131 	bool IsIpRawMode;
132 	IP MyIP_InCaseOfIpRawMode;		// My IP
133 
134 	THREAD *IpTablesThread;
135 	EVENT *IpTablesHaltEvent;
136 	bool IpTablesHalt;
137 	bool IpTablesInitOk;
138 };
139 
140 struct IPTABLES_ENTRY
141 {
142 	char Chain[64];
143 	UINT LineNumber;
144 	char ConditionAndArgs[MAX_SIZE];
145 	IP DummySrcIp, DummyDestIP;
146 	UINT DummyMark;
147 };
148 
149 struct IPTABLES_STATE
150 {
151 	UCHAR SeedHash[SHA1_SIZE];
152 	LIST *EntryList;
153 	bool HasError;
154 };
155 
156 
157 //// Function prototype
158 NATIVE_STACK *NewNativeStack(CEDAR *cedar, char *device_name, char *mac_address_seed);
159 void FreeNativeStack(NATIVE_STACK *a);
160 
161 void NsGenMacAddress(void *dest, char *mac_address_seed, char *device_name);
162 void NsMainThread(THREAD *thread, void *param);
163 void NsGenMacAddressSignatureForMachine(UCHAR *dst_last_2, UCHAR *src_mac_addr_4);
164 bool NsIsMacAddressOnLocalhost(UCHAR *mac);
165 
166 bool NsStartIpTablesTracking(NATIVE_STACK *a);
167 void NsStopIpTablesTracking(NATIVE_STACK *a);
168 void NsIpTablesThread(THREAD *thread, void *param);
169 
170 IPTABLES_STATE *GetCurrentIpTables();
171 void FreeIpTablesState(IPTABLES_STATE *s);
172 bool IsIpTablesSupported();
173 IPTABLES_ENTRY *SearchIpTables(IPTABLES_STATE *s, char *chain, IP *src_ip, IP *dest_ip, UINT mark);
174 UINT GetCurrentIpTableLineNumber(char *chain, IP *src_ip, IP *dest_ip, UINT mark);
175 
176 IPTABLES_STATE *StartAddIpTablesEntryForNativeStack(void *seed, UINT seed_size);
177 void EndAddIpTablesEntryForNativeStack(IPTABLES_STATE *s);
178 bool MaintainAddIpTablesEntryForNativeStack(IPTABLES_STATE *s);
179 
180 void GenerateDummyIpAndMark(void *hash_seed, IPTABLES_ENTRY *e, UINT id);
181 UINT GenerateDummyMark(PRAND *p);
182 void GenerateDummyIp(PRAND *p, IP *ip);
183 
184 #endif	// NATIVESTACK_H
185 
186 
187