forked from go-freebsd/pf
-
Notifications
You must be signed in to change notification settings - Fork 0
/
address.go
287 lines (250 loc) · 7.44 KB
/
address.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
package pf
import (
"bytes"
"fmt"
"net"
"strings"
"unsafe"
)
// #include <net/if.h>
// #include <net/pfvar.h>
/*
int addr_type(struct pf_addr_wrap* addr) { return addr->type; }
void set_addr_type(struct pf_addr_wrap* addr, int type) { addr->type = type; }
int addr_cnt(struct pf_addr_wrap* addr) { return addr->p.tblcnt; }
char* addr_name(struct pf_addr_wrap* addr) { return &addr->v.ifname[0]; }
*/
import "C"
// Address wraps the pf address (cgo)
type Address struct {
wrap *C.struct_pf_addr_wrap
af C.sa_family_t
}
func newAddress() *Address {
var wrap C.struct_pf_addr_wrap
a := Address{wrap: &wrap}
return &a
}
// any is the pf represnetation of the any address
var any = net.IPNet{
IP: net.IPv6zero,
Mask: net.IPMask(net.IPv6zero),
}
var singleIPv4 = net.CIDRMask(32, 128)
var singleIPv6 = net.CIDRMask(128, 128)
// DynamicFlag can be set on an address that is derived from
// an interface
type DynamicFlag uint8
const (
// DynamicFlagNetwork translates to the network(s) attached to the interface
DynamicFlagNetwork DynamicFlag = C.PFI_AFLAG_NETWORK
// DynamicFlagBroadcast translates to the interface's broadcast address(es).
DynamicFlagBroadcast DynamicFlag = C.PFI_AFLAG_BROADCAST
// DynamicFlagPeer translates to the point-to-point interface's peer address(es).
DynamicFlagPeer DynamicFlag = C.PFI_AFLAG_PEER
// DynamicFlagNoAlias do not include interface aliases.
DynamicFlagNoAlias DynamicFlag = C.PFI_AFLAG_NOALIAS
)
func (f DynamicFlag) String() string {
switch f {
case DynamicFlagNetwork:
return "network"
case DynamicFlagBroadcast:
return "broadcast"
case DynamicFlagPeer:
return "peer"
case DynamicFlagNoAlias:
return "0"
default:
return fmt.Sprintf("DynamicFlag(%d)", int(f))
}
}
// AllDynamicFlags contains all danymic flags in usual order
var AllDynamicFlags = []DynamicFlag{
DynamicFlagNetwork,
DynamicFlagBroadcast,
DynamicFlagPeer,
DynamicFlagNoAlias,
}
// Dynamic returns true if the address is dynamic
// based of the interface
func (a Address) Dynamic() bool {
return C.addr_type(a.wrap) == C.PF_ADDR_DYNIFTL
}
// Interface the name of the interface (e..g. used for dynamic address),
// returns an empty string if no interface is set
func (a Address) Interface() string {
return C.GoString(C.addr_name(a.wrap)) // ifname union
}
// SetInterface turns address into dynamic interface reference,
// type of interface reference can be changed with flags
func (a *Address) SetInterface(itf string) error {
err := cStringCopy(unsafe.Pointer(&a.wrap.v), itf, C.IFNAMSIZ)
if err != nil {
return err
}
C.set_addr_type(a.wrap, C.PF_ADDR_DYNIFTL)
return nil
}
// Table returns true if the address references a table
func (a Address) Table() bool {
return C.addr_type(a.wrap) == C.PF_ADDR_TABLE
}
// DynamicFlag returns true if the flag is set for the address
func (a Address) DynamicFlag(flag DynamicFlag) bool {
return uint8(a.wrap.iflags)&uint8(flag) == uint8(flag)
}
// SetDynamicFlag sets the dynamic interface flag
func (a *Address) SetDynamicFlag(flag DynamicFlag) {
a.wrap.iflags = C.u_int8_t(flag)
}
// DynamicCount returns the dynamic count
func (a Address) DynamicCount() int {
return int(C.addr_cnt(a.wrap)) // dyncnt union
}
// TableName returns the name of the table or an empty string if not set
func (a Address) TableName() string {
return C.GoString(C.addr_name(a.wrap)) // tblname union
}
// SetTableName turns address into table reference, using given name
func (a *Address) SetTableName(name string) error {
err := cStringCopy(unsafe.Pointer(&a.wrap.v), name, C.PF_TABLE_NAME_SIZE)
if err != nil {
return err
}
C.set_addr_type(a.wrap, C.PF_ADDR_TABLE)
return nil
}
// TableCount returns the table count
func (a Address) TableCount() int {
return int(C.addr_cnt(a.wrap)) // tblcnt union
}
// NoRoute any address which is not currently routable
func (a Address) NoRoute() bool {
return C.addr_type(a.wrap) == C.PF_ADDR_NOROUTE
}
// SetNoRoute turns address into no routeable address
func (a *Address) SetNoRoute() {
C.set_addr_type(a.wrap, C.PF_ADDR_NOROUTE)
}
// URPFFailed any source address that fails a unicast reverse
// path forwarding (URPF) check, i.e. packets coming
// in on an interface other than that which holds the
// route back to the packet's source address
func (a Address) URPFFailed() bool {
return C.addr_type(a.wrap) == C.PF_ADDR_URPFFAILED
}
// SetURPFFailed see URPFFailed for details
func (a *Address) SetURPFFailed() {
C.set_addr_type(a.wrap, C.PF_ADDR_URPFFAILED)
}
// Mask returns true if address is an ip address with mask
func (a Address) Mask() bool {
return C.addr_type(a.wrap) == C.PF_ADDR_ADDRMASK
}
// Range returns true if is an address range with start
// and end ip addr
func (a Address) Range() bool {
return C.addr_type(a.wrap) == C.PF_ADDR_RANGE
}
// Any returns true if address represents any address
func (a Address) Any() bool {
if !a.Mask() {
return false
}
return bytes.Compare(any.IP, a.wrap.v[0:16]) == 0 &&
bytes.Compare(any.Mask, a.wrap.v[16:32]) == 0
}
// SetAny will turn the address into an any IP address
func (a *Address) SetAny() {
a.SetIPNet(&any)
}
// IPNet returns the IPNetwork (IPv4/IPv6) of the address with mask
func (a Address) IPNet() *net.IPNet {
var ipn net.IPNet
if a.af == C.AF_INET {
ipn.IP = a.wrap.v[0:4] // addr union
ipn.Mask = a.wrap.v[16:20] // mask union
} else {
ipn.IP = a.wrap.v[0:16] // addr union
ipn.Mask = a.wrap.v[16:32] // mask union
}
return &ipn
}
// IPRange returns the start and end ip address of the range
func (a Address) IPRange() (net.IP, net.IP) {
start := net.IP(a.wrap.v[0:16])
end := net.IP(a.wrap.v[16:32])
return start, end
}
// SetIPRange sets start and end address and turns object
// into ip range
func (a *Address) SetIPRange(start, end net.IP) {
copy(a.wrap.v[0:16], start)
copy(a.wrap.v[16:32], end)
C.set_addr_type(a.wrap, C.PF_ADDR_RANGE)
}
// SetIPNet updates the ip address and mask and changes
// the type to AddressMask
func (a *Address) SetIPNet(ipn *net.IPNet) {
if ipv4 := ipn.IP.To4(); ipv4 != nil {
copy(a.wrap.v[0:4], ipv4)
copy(a.wrap.v[16:20], ipn.Mask)
a.af = C.AF_INET
} else {
copy(a.wrap.v[0:16], ipn.IP)
copy(a.wrap.v[16:32], ipn.Mask)
a.af = C.AF_INET6
}
C.set_addr_type(a.wrap, C.PF_ADDR_ADDRMASK)
}
func (a Address) String() string {
if a.Dynamic() {
str := []string{a.Interface()}
for _, flag := range AllDynamicFlags {
if a.DynamicFlag(flag) {
str = append(str, flag.String())
}
}
return fmt.Sprintf("(%s)", strings.Join(str, ":"))
} else if a.Table() {
return fmt.Sprintf("<%s>", a.TableName())
} else if a.NoRoute() {
return "no-route"
} else if a.URPFFailed() {
return "urpf-failed"
} else if a.Any() {
return "any"
} else if a.Mask() {
return a.IPNet().String()
} else if a.Range() {
s, e := a.IPRange()
return fmt.Sprintf("%s - %s", s, e)
} else {
return fmt.Sprintf("Address(%d)", C.addr_type(a.wrap))
}
}
// ParseCIDR parses the passed address in CIDR notation
// and sets the extracted addess, mask and af. Id mask is missing
// IP address is assumed and mask is set to 32 IPv4 or 128 IPv6.
// May return a parse error if the address is invalid CIDR or
// IP address
func (a *Address) ParseCIDR(address string) error {
if strings.ContainsRune(address, '/') {
_, n, err := net.ParseCIDR(address)
if err != nil {
return err
}
a.SetIPNet(n)
} else {
var ipn net.IPNet
ipn.IP = net.ParseIP(address)
if ipn.IP.To4() != nil {
ipn.Mask = singleIPv4
} else {
ipn.Mask = singleIPv6
}
a.SetIPNet(&ipn)
}
return nil
}