mirror of
https://git.hardenedbsd.org/hardenedbsd/HardenedBSD.git
synced 2024-12-21 16:32:25 +01:00
33b3ac0633
systems (my last change did not mix well with some firewall configurations). As much as I dislike firewalls, this is one thing I I was not prepared to break by default.. :-) Allow the user to nominate one of three ranges of port numbers as candidates for selecting a local address to replace a zero port number. The ranges are selected via a setsockopt(s, IPPROTO_IP, IP_PORTRANGE, &arg) call. The three ranges are: default, high (to bypass firewalls) and low (to get a port below 1024). The default and high port ranges are sysctl settable under sysctl net.inet.ip.portrange.* This code also fixes a potential deadlock if the system accidently ran out of local port addresses. It'd drop into an infinite while loop. The secure port selection (for root) should reduce overheads and increase reliability of rlogin/rlogind/rsh/rshd if they are modified to take advantage of it. Partly suggested by: pst Reviewed by: wollman
111 lines
4.6 KiB
C
111 lines
4.6 KiB
C
/*
|
|
* Copyright (c) 1982, 1986, 1990, 1993
|
|
* The Regents of the University of California. All rights reserved.
|
|
*
|
|
* Redistribution and use in source and binary forms, with or without
|
|
* modification, are permitted provided that the following conditions
|
|
* are met:
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
* notice, this list of conditions and the following disclaimer.
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
* documentation and/or other materials provided with the distribution.
|
|
* 3. All advertising materials mentioning features or use of this software
|
|
* must display the following acknowledgement:
|
|
* This product includes software developed by the University of
|
|
* California, Berkeley and its contributors.
|
|
* 4. Neither the name of the University nor the names of its contributors
|
|
* may be used to endorse or promote products derived from this software
|
|
* without specific prior written permission.
|
|
*
|
|
* THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
|
|
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
* ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
|
|
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
* SUCH DAMAGE.
|
|
*
|
|
* @(#)in_pcb.h 8.1 (Berkeley) 6/10/93
|
|
* $Id: in_pcb.h,v 1.10 1995/12/05 21:26:34 bde Exp $
|
|
*/
|
|
|
|
#ifndef _NETINET_IN_PCB_H_
|
|
#define _NETINET_IN_PCB_H_
|
|
|
|
#include <sys/queue.h>
|
|
|
|
/*
|
|
* Common structure pcb for internet protocol implementation.
|
|
* Here are stored pointers to local and foreign host table
|
|
* entries, local and foreign socket numbers, and pointers
|
|
* up (to a socket structure) and down (to a protocol-specific)
|
|
* control block.
|
|
*/
|
|
LIST_HEAD(inpcbhead, inpcb);
|
|
|
|
struct inpcb {
|
|
LIST_ENTRY(inpcb) inp_list; /* list for all PCBs of this proto */
|
|
LIST_ENTRY(inpcb) inp_hash; /* hash list */
|
|
struct inpcbinfo *inp_pcbinfo;
|
|
struct in_addr inp_faddr; /* foreign host table entry */
|
|
u_short inp_fport; /* foreign port */
|
|
struct in_addr inp_laddr; /* local host table entry */
|
|
u_short inp_lport; /* local port */
|
|
struct socket *inp_socket; /* back pointer to socket */
|
|
caddr_t inp_ppcb; /* pointer to per-protocol pcb */
|
|
struct route inp_route; /* placeholder for routing entry */
|
|
int inp_flags; /* generic IP/datagram flags */
|
|
struct ip inp_ip; /* header prototype; should have more */
|
|
struct mbuf *inp_options; /* IP options */
|
|
struct ip_moptions *inp_moptions; /* IP multicast options */
|
|
};
|
|
|
|
struct inpcbinfo {
|
|
struct inpcbhead *listhead;
|
|
struct inpcbhead *hashbase;
|
|
unsigned long hashsize;
|
|
unsigned short lastport;
|
|
};
|
|
|
|
/* flags in inp_flags: */
|
|
#define INP_RECVOPTS 0x01 /* receive incoming IP options */
|
|
#define INP_RECVRETOPTS 0x02 /* receive IP options for reply */
|
|
#define INP_RECVDSTADDR 0x04 /* receive IP dst address */
|
|
#define INP_CONTROLOPTS (INP_RECVOPTS|INP_RECVRETOPTS|INP_RECVDSTADDR)
|
|
#define INP_HDRINCL 0x08 /* user supplies entire IP header */
|
|
#define INP_HIGHPORT 0x10 /* user wants "high" port binding */
|
|
#define INP_LOWPORT 0x20 /* user wants "low" port binding */
|
|
|
|
#define INPLOOKUP_WILDCARD 1
|
|
|
|
#define sotoinpcb(so) ((struct inpcb *)(so)->so_pcb)
|
|
|
|
#ifdef KERNEL
|
|
void in_losing __P((struct inpcb *));
|
|
int in_pcballoc __P((struct socket *, struct inpcbinfo *));
|
|
int in_pcbbind __P((struct inpcb *, struct mbuf *));
|
|
int in_pcbconnect __P((struct inpcb *, struct mbuf *));
|
|
void in_pcbdetach __P((struct inpcb *));
|
|
void in_pcbdisconnect __P((struct inpcb *));
|
|
int in_pcbladdr __P((struct inpcb *, struct mbuf *,
|
|
struct sockaddr_in **));
|
|
struct inpcb *
|
|
in_pcblookup __P((struct inpcbhead *,
|
|
struct in_addr, u_int, struct in_addr, u_int, int));
|
|
struct inpcb *
|
|
in_pcblookuphash __P((struct inpcbinfo *,
|
|
struct in_addr, u_int, struct in_addr, u_int));
|
|
void in_pcbnotify __P((struct inpcbhead *, struct sockaddr *,
|
|
u_int, struct in_addr, u_int, int, void (*)(struct inpcb *, int)));
|
|
void in_pcbrehash __P((struct inpcb *));
|
|
void in_setpeeraddr __P((struct inpcb *, struct mbuf *));
|
|
void in_setsockaddr __P((struct inpcb *, struct mbuf *));
|
|
#endif
|
|
|
|
#endif
|