Provides an interface for filtering network packets as they come in to the system.
Definition at line 34 of file Filter.h.
| bool NetworkFilter::filter |
( |
size_t |
level, |
|
|
uintptr_t |
packet, |
|
|
size_t |
sz |
|
) |
| |
Passes a Level n packet to filter callbacks. Level 1 is the lowest level, handling for example Ethernet frames. Level 2 handles the Level 1 payload. ARP, IP, and other low-level protocols are handled here. Level 3 handles the Level 2 payload. TCP, UDP, ICMP, etc... Level 4 handles the Level 3 payload. Specific application protocols such as FTP, DNS.
- Todo:
- Callbacks should be able to return a code which requests a specific response, such as ICMP Unreachable or something, rather than just dropping the packet.
- Parameters
-
| level | Level of callback to call |
| packet | Packet buffer, can be modified by callbacks |
| size | Size of the packet. Can NOT be modified by callbacks |
- Returns
- False if the packet has been rejected, true otherwise.
Definition at line 60 of file Filter.cc.
References Spinlock::acquire(), ProcessorBase::information(), and Spinlock::release().
| bool NetworkFilter::removeCallback |
( |
size_t |
level, |
|
|
size_t |
id |
|
) |
| |
Closes admission and removes a callback for a specific level.
Outside filter dispatch this waits for admitted calls and returns true once callback-owned state may be destroyed. During dispatch, an active target is disabled but retained and false is returned; the caller must preserve the identifier and callback-owned state, then retry from outside callback context. An already absent valid identifier is complete.
Definition at line 165 of file Filter.cc.
References Spinlock::acquire(), ProcessorBase::information(), and Spinlock::release().
Referenced by ~NetworkFilter().