#include "opt_inet.h"
#include "opt_inet6.h"
#include "opt_ipsec.h"
#include <sys/param.h>
#include <sys/systm.h>
#include <sys/kernel.h>
#include <sys/lock.h>
#include <sys/malloc.h>
#include <sys/mbuf.h>
#include <sys/module.h>
#include <sys/priv.h>
#include <sys/rmlock.h>
#include <sys/socket.h>
#include <sys/sockopt.h>
#include <sys/syslog.h>
#include <sys/proc.h>
#include <netinet/in.h>
#include <netinet/in_pcb.h>
#include <netipsec/ipsec.h>
#include <netipsec/ipsec6.h>
#include <netipsec/key.h>
#include <netipsec/key_debug.h>
#include <netipsec/ipsec_support.h>
#ifdef INET
static const struct ipsec_methods ipv4_methods = {
.input = ipsec4_input,
.forward = ipsec4_forward,
.output = ipsec4_output,
.pcbctl = ipsec4_pcbctl,
.capability = ipsec4_capability,
.check_policy = ipsec4_in_reject,
.ctlinput = ipsec4_ctlinput,
.hdrsize = ipsec_hdrsiz_inpcb,
.udp_input = udp_ipsec_input,
.udp_pcbctl = udp_ipsec_pcbctl,
};
#ifndef KLD_MODULE
static const struct ipsec_support ipv4_ipsec = {
.enabled = IPSEC_MODULE_ENABLED,
.methods = &ipv4_methods
};
const struct ipsec_support * const ipv4_ipsec_support = &ipv4_ipsec;
#endif
#endif
#ifdef INET6
static const struct ipsec_methods ipv6_methods = {
.input = ipsec6_input,
.forward = ipsec6_forward,
.output = ipsec6_output,
.pcbctl = ipsec6_pcbctl,
.capability = ipsec6_capability,
.check_policy = ipsec6_in_reject,
.ctlinput = ipsec6_ctlinput,
.hdrsize = ipsec_hdrsiz_inpcb,
.udp_input = udp_ipsec_input,
.udp_pcbctl = udp_ipsec_pcbctl,
};
#ifndef KLD_MODULE
static const struct ipsec_support ipv6_ipsec = {
.enabled = IPSEC_MODULE_ENABLED,
.methods = &ipv6_methods
};
const struct ipsec_support * const ipv6_ipsec_support = &ipv6_ipsec;
#endif
#endif
static int
ipsec_modevent(module_t mod, int type, void *data)
{
switch (type) {
case MOD_LOAD:
if (!ipsec_initialized())
return (ENOMEM);
#ifdef KLD_MODULE
#ifdef INET
ipsec_support_enable(ipv4_ipsec_support, &ipv4_methods);
#endif
#ifdef INET6
ipsec_support_enable(ipv6_ipsec_support, &ipv6_methods);
#endif
#endif
break;
case MOD_UNLOAD:
#ifdef KLD_MODULE
#ifdef INET
ipsec_support_disable(ipv4_ipsec_support);
#endif
#ifdef INET6
ipsec_support_disable(ipv6_ipsec_support);
#endif
#endif
break;
default:
return (EOPNOTSUPP);
}
return (0);
}
static moduledata_t ipsec_mod = {
"ipsec",
ipsec_modevent,
0
};
DECLARE_MODULE(ipsec, ipsec_mod, SI_SUB_PROTO_DOMAIN, SI_ORDER_ANY);
MODULE_VERSION(ipsec, 1);
#ifdef KLD_MODULE
MODULE_DEPEND(ipsec, ipsec_support, 1, 1, 1);
#endif