Merge pull request #62 from painless-security/jennifer/report_incoming_ipaddr
[trust_router.git] / include / tr_filter.h
1 /*
2  * Copyright (c) 2012, 2013, JANET(UK)
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer.
11  *
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * 3. Neither the name of JANET(UK) nor the names of its contributors
17  *    may be used to endorse or promote products derived from this software
18  *    without specific prior written permission.
19  *
20  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
21  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
22  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
23  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
24  * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
25  * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
26  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
27  * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
29  * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
30  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
31  * OF THE POSSIBILITY OF SUCH DAMAGE.
32  *
33  */
34
35 #ifndef TR_FILTER_H
36 #define TR_FILTER_H
37
38 #include <talloc.h>
39 #include <jansson.h>
40 #include <glib.h>
41
42 #include <tr_list.h>
43 #include <tr_name_internal.h>
44 #include <trust_router/tr_constraint.h>
45 #include <trust_router/tid.h>
46 #include <trust_router/trp.h>
47
48 /* Filter actions */
49 typedef enum tr_filter_action {
50   TR_FILTER_ACTION_REJECT = 0,
51   TR_FILTER_ACTION_ACCEPT,
52   TR_FILTER_ACTION_UNKNOWN
53 } TR_FILTER_ACTION;
54
55 /* Match codes */
56 #define TR_FILTER_MATCH 0
57 #define TR_FILTER_NO_MATCH 1
58
59 /* Filter types */
60 typedef enum {
61   TR_FILTER_TYPE_TID_INBOUND = 0,
62   TR_FILTER_TYPE_TRP_INBOUND,
63   TR_FILTER_TYPE_TRP_OUTBOUND,
64   TR_FILTER_TYPE_UNKNOWN
65 } TR_FILTER_TYPE;
66
67 typedef struct tr_fspec {
68   TR_NAME *field;
69   TR_LIST *match;
70 } TR_FSPEC;
71
72 typedef struct tr_fline {
73   TR_FILTER_ACTION action;
74   TR_LIST *specs;
75   TR_CONSTRAINT *realm_cons;
76   TR_CONSTRAINT *domain_cons;
77 } TR_FLINE;
78
79 typedef struct tr_filter {
80   TR_FILTER_TYPE type;
81   TR_LIST *lines;
82 } TR_FILTER;
83
84 typedef struct tr_filter_set TR_FILTER_SET;
85 struct tr_filter_set {
86   TR_FILTER *this;
87   TR_FILTER_SET *next;
88 };
89
90 /**
91  * Structure to hold information needed to filter different targets.
92  */
93 typedef struct tr_filter_target {
94   /* An inforec also needs realm and community information */
95   TRP_INFOREC *trp_inforec;
96   TRP_UPD *trp_upd;
97
98   /* a TID request has all the data it needs to be filtered */
99   TID_REQ *tid_req;
100 } TR_FILTER_TARGET;
101
102 TR_FILTER_SET *tr_filter_set_new(TALLOC_CTX *mem_ctx);
103 void tr_filter_set_free(TR_FILTER_SET *fs);
104 int tr_filter_set_add(TR_FILTER_SET *set, TR_FILTER *new);
105 TR_FILTER *tr_filter_set_get(TR_FILTER_SET *set, TR_FILTER_TYPE type);
106
107 TR_FILTER *tr_filter_new(TALLOC_CTX *mem_ctx);
108 void tr_filter_free(TR_FILTER *filt);
109
110 void tr_filter_set_type(TR_FILTER *filt, TR_FILTER_TYPE type);
111 TR_FILTER_TYPE tr_filter_get_type(TR_FILTER *filt);
112 TR_FLINE *tr_filter_add_line(TR_FILTER *filt, TR_FLINE *line);
113
114 TR_FLINE *tr_fline_new(TALLOC_CTX *mem_ctx);
115 void tr_fline_free(TR_FLINE *fline);
116 TR_FSPEC *tr_fline_add_spec(TR_FLINE *fline, TR_FSPEC *spec);
117
118 TR_FSPEC *tr_fspec_new(TALLOC_CTX *mem_ctx);
119 void tr_fspec_free(TR_FSPEC *fspec);
120 TR_NAME *tr_fspec_add_match(TR_FSPEC *fspec, TR_NAME *match);
121
122 int tr_fspec_matches(TR_FSPEC *fspec, TR_FILTER_TYPE ftype, TR_FILTER_TARGET *target);
123
124 /* Iterator for TR_FILTER lines */
125 typedef TR_LIST_ITER TR_FILTER_ITER;
126 #define tr_filter_iter_new(CTX) (tr_list_iter_new(CTX))
127 #define tr_filter_iter_free(ITER) (tr_list_iter_free(ITER))
128 #define tr_filter_iter_first(ITER, FILT) ((TR_FLINE *) tr_list_iter_first((ITER), (FILT)->lines))
129 #define tr_filter_iter_next(ITER) ((TR_FLINE *) tr_list_iter_next(ITER))
130 #define tr_filter_add_line(FILT, LINE) ((TR_FLINE *) tr_list_add((FILT)->lines, (LINE), 1))
131
132 /* Iterator for TR_FSPEC matches */
133 typedef TR_LIST_ITER TR_FSPEC_ITER;
134 #define tr_fspec_iter_new(CTX) (tr_list_iter_new(CTX))
135 #define tr_fspec_iter_free(ITER) (tr_list_iter_free(ITER))
136 #define tr_fspec_iter_first(ITER, SPEC) (tr_list_iter_first((ITER), (SPEC)->match))
137 #define tr_fspec_iter_next(ITER) (tr_list_iter_next(ITER))
138 #define tr_fspec_add_match(SPEC, MATCH) ((TR_NAME *) tr_list_add((SPEC)->match, (MATCH), 0))
139
140 /* Iterator for TR_FLINE specs */
141 typedef TR_LIST_ITER TR_FLINE_ITER;
142 #define tr_fline_iter_new(CTX) (tr_list_iter_new(CTX))
143 #define tr_fline_iter_free(ITER) (tr_list_iter_free(ITER))
144 #define tr_fline_iter_first(ITER, LINE) (tr_list_iter_first((ITER), (LINE)->specs))
145 #define tr_fline_iter_next(ITER) (tr_list_iter_next(ITER))
146 #define tr_fline_add_spec(LINE, SPEC) ((TR_NAME *) tr_list_add((LINE)->specs, (SPEC), 1))
147
148 /*In tr_constraint.c and exported, but not really a public symbol; needed by tr_filter.c and by tr_constraint.c*/
149 int TR_EXPORT tr_prefix_wildcard_match(const char *str, const char *wc_str);
150
151 int tr_filter_apply(TR_FILTER_TARGET *target, TR_FILTER *filt, TR_CONSTRAINT_SET **constraints, TR_FILTER_ACTION *out_action);
152 void tr_filter_target_free(TR_FILTER_TARGET *target);
153 TR_FILTER_TARGET *tr_filter_target_tid_req(TALLOC_CTX *mem_ctx, TID_REQ *req);
154 TR_FILTER_TARGET *tr_filter_target_trp_inforec(TALLOC_CTX *mem_ctx, TRP_UPD *upd, TRP_INFOREC *inforec);
155
156 TR_CONSTRAINT_SET *tr_constraint_set_from_fline(TR_FLINE *fline);
157
158 int tr_filter_validate(TR_FILTER *filt);
159 int tr_filter_validate_spec_field(TR_FILTER_TYPE ftype, TR_FSPEC *fspec);
160 const char *tr_filter_type_to_string(TR_FILTER_TYPE ftype);
161 TR_FILTER_TYPE tr_filter_type_from_string(const char *s);
162
163 /* tr_filter_encoders.c */
164 json_t *tr_filter_set_to_json(TR_FILTER_SET *filter_set);
165
166 #endif