1*aca3beaaSApple OSS Distributions /* 2*aca3beaaSApple OSS Distributions * Copyright (c) 2012-2021 Apple Inc. All rights reserved. 3*aca3beaaSApple OSS Distributions * 4*aca3beaaSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@ 5*aca3beaaSApple OSS Distributions * 6*aca3beaaSApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code 7*aca3beaaSApple OSS Distributions * as defined in and that are subject to the Apple Public Source License 8*aca3beaaSApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in 9*aca3beaaSApple OSS Distributions * compliance with the License. The rights granted to you under the License 10*aca3beaaSApple OSS Distributions * may not be used to create, or enable the creation or redistribution of, 11*aca3beaaSApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to 12*aca3beaaSApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any 13*aca3beaaSApple OSS Distributions * terms of an Apple operating system software license agreement. 14*aca3beaaSApple OSS Distributions * 15*aca3beaaSApple OSS Distributions * Please obtain a copy of the License at 16*aca3beaaSApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file. 17*aca3beaaSApple OSS Distributions * 18*aca3beaaSApple OSS Distributions * The Original Code and all software distributed under the License are 19*aca3beaaSApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER 20*aca3beaaSApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, 21*aca3beaaSApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, 22*aca3beaaSApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. 23*aca3beaaSApple OSS Distributions * Please see the License for the specific language governing rights and 24*aca3beaaSApple OSS Distributions * limitations under the License. 25*aca3beaaSApple OSS Distributions * 26*aca3beaaSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@ 27*aca3beaaSApple OSS Distributions */ 28*aca3beaaSApple OSS Distributions 29*aca3beaaSApple OSS Distributions 30*aca3beaaSApple OSS Distributions #ifndef _NET_IF_IPSEC_H_ 31*aca3beaaSApple OSS Distributions #define _NET_IF_IPSEC_H_ 32*aca3beaaSApple OSS Distributions 33*aca3beaaSApple OSS Distributions #ifdef BSD_KERNEL_PRIVATE 34*aca3beaaSApple OSS Distributions 35*aca3beaaSApple OSS Distributions #include <sys/kern_control.h> 36*aca3beaaSApple OSS Distributions #include <netinet/ip_var.h> 37*aca3beaaSApple OSS Distributions 38*aca3beaaSApple OSS Distributions 39*aca3beaaSApple OSS Distributions errno_t ipsec_register_control(void); 40*aca3beaaSApple OSS Distributions 41*aca3beaaSApple OSS Distributions /* Helpers */ 42*aca3beaaSApple OSS Distributions int ipsec_interface_isvalid(ifnet_t interface); 43*aca3beaaSApple OSS Distributions #if SKYWALK 44*aca3beaaSApple OSS Distributions boolean_t ipsec_interface_needs_netagent(ifnet_t interface); 45*aca3beaaSApple OSS Distributions #endif /* SKYWALK */ 46*aca3beaaSApple OSS Distributions 47*aca3beaaSApple OSS Distributions errno_t ipsec_inject_inbound_packet(ifnet_t interface, mbuf_t packet); 48*aca3beaaSApple OSS Distributions 49*aca3beaaSApple OSS Distributions void ipsec_set_pkthdr_for_interface(ifnet_t interface, mbuf_t packet, int family, 50*aca3beaaSApple OSS Distributions uint32_t flowid); 51*aca3beaaSApple OSS Distributions 52*aca3beaaSApple OSS Distributions void ipsec_set_ipoa_for_interface(ifnet_t interface, struct ip_out_args *ipoa); 53*aca3beaaSApple OSS Distributions 54*aca3beaaSApple OSS Distributions struct ip6_out_args; 55*aca3beaaSApple OSS Distributions void ipsec_set_ip6oa_for_interface(ifnet_t interface, struct ip6_out_args *ip6oa); 56*aca3beaaSApple OSS Distributions 57*aca3beaaSApple OSS Distributions #endif 58*aca3beaaSApple OSS Distributions 59*aca3beaaSApple OSS Distributions /* 60*aca3beaaSApple OSS Distributions * Name registered by the ipsec kernel control 61*aca3beaaSApple OSS Distributions */ 62*aca3beaaSApple OSS Distributions #define IPSEC_CONTROL_NAME "com.apple.net.ipsec_control" 63*aca3beaaSApple OSS Distributions 64*aca3beaaSApple OSS Distributions /* 65*aca3beaaSApple OSS Distributions * Socket option names to manage ipsec 66*aca3beaaSApple OSS Distributions */ 67*aca3beaaSApple OSS Distributions #define IPSEC_OPT_FLAGS 1 68*aca3beaaSApple OSS Distributions #define IPSEC_OPT_IFNAME 2 69*aca3beaaSApple OSS Distributions #define IPSEC_OPT_EXT_IFDATA_STATS 3 /* get|set (type int) */ 70*aca3beaaSApple OSS Distributions #define IPSEC_OPT_INC_IFDATA_STATS_IN 4 /* set to increment stat counters (type struct ipsec_stats_param) */ 71*aca3beaaSApple OSS Distributions #define IPSEC_OPT_INC_IFDATA_STATS_OUT 5 /* set to increment stat counters (type struct ipsec_stats_param) */ 72*aca3beaaSApple OSS Distributions #define IPSEC_OPT_SET_DELEGATE_INTERFACE 6 /* set the delegate interface (char[]) */ 73*aca3beaaSApple OSS Distributions #define IPSEC_OPT_OUTPUT_TRAFFIC_CLASS 7 /* set the traffic class for packets leaving the interface, see sys/socket.h */ 74*aca3beaaSApple OSS Distributions #define IPSEC_OPT_ENABLE_CHANNEL 8 /* enable a kernel pipe nexus that allows the owner to open a channel to act as a driver, 75*aca3beaaSApple OSS Distributions * Must be set before connecting */ 76*aca3beaaSApple OSS Distributions #define IPSEC_OPT_GET_CHANNEL_UUID 9 /* get the uuid of the kernel pipe nexus instance */ 77*aca3beaaSApple OSS Distributions #define IPSEC_OPT_ENABLE_FLOWSWITCH 10 /* enable a flowswitch nexus that clients can use */ 78*aca3beaaSApple OSS Distributions #define IPSEC_OPT_INPUT_FRAG_SIZE 11 /* set the maximum size of input packets before fragmenting as a uint32_t */ 79*aca3beaaSApple OSS Distributions 80*aca3beaaSApple OSS Distributions #define IPSEC_OPT_ENABLE_NETIF 12 /* Must be set before connecting */ 81*aca3beaaSApple OSS Distributions #define IPSEC_OPT_SLOT_SIZE 13 /* Must be set before connecting */ 82*aca3beaaSApple OSS Distributions #define IPSEC_OPT_NETIF_RING_SIZE 14 /* Must be set before connecting */ 83*aca3beaaSApple OSS Distributions #define IPSEC_OPT_TX_FSW_RING_SIZE 15 /* Must be set before connecting */ 84*aca3beaaSApple OSS Distributions #define IPSEC_OPT_RX_FSW_RING_SIZE 16 /* Must be set before connecting */ 85*aca3beaaSApple OSS Distributions #define IPSEC_OPT_CHANNEL_BIND_PID 17 /* Must be set before connecting */ 86*aca3beaaSApple OSS Distributions #define IPSEC_OPT_KPIPE_TX_RING_SIZE 18 /* Must be set before connecting */ 87*aca3beaaSApple OSS Distributions #define IPSEC_OPT_KPIPE_RX_RING_SIZE 19 /* Must be set before connecting */ 88*aca3beaaSApple OSS Distributions #define IPSEC_OPT_CHANNEL_BIND_UUID 20 /* Must be set before connecting */ 89*aca3beaaSApple OSS Distributions 90*aca3beaaSApple OSS Distributions #define IPSEC_OPT_OUTPUT_DSCP_MAPPING 21 /* Must be set before connecting */ 91*aca3beaaSApple OSS Distributions 92*aca3beaaSApple OSS Distributions typedef enum { 93*aca3beaaSApple OSS Distributions IPSEC_DSCP_MAPPING_COPY = 0, /* Copy DSCP bits from inner IP header to outer IP header */ 94*aca3beaaSApple OSS Distributions IPSEC_DSCP_MAPPING_LEGACY = 1, /* Copies bits from the outer IP header that are at TOS offset of the inner IP header, into the DSCP of the outer IP header */ 95*aca3beaaSApple OSS Distributions } ipsec_dscp_mapping_t; 96*aca3beaaSApple OSS Distributions 97*aca3beaaSApple OSS Distributions /* 98*aca3beaaSApple OSS Distributions * ipsec stats parameter structure 99*aca3beaaSApple OSS Distributions */ 100*aca3beaaSApple OSS Distributions struct ipsec_stats_param { 101*aca3beaaSApple OSS Distributions u_int64_t utsp_packets; 102*aca3beaaSApple OSS Distributions u_int64_t utsp_bytes; 103*aca3beaaSApple OSS Distributions u_int64_t utsp_errors; 104*aca3beaaSApple OSS Distributions }; 105*aca3beaaSApple OSS Distributions 106*aca3beaaSApple OSS Distributions #endif 107