reassembly: prevent long chain attack
[vpp.git] / src / vnet / ip / ip4_error.h
1 /*
2  * Copyright (c) 2015 Cisco and/or its affiliates.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at:
6  *
7  *     http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 /*
16  * ip/ip4_error.h: ip4 fast path errors
17  *
18  * Copyright (c) 2008 Eliot Dresselhaus
19  *
20  * Permission is hereby granted, free of charge, to any person obtaining
21  * a copy of this software and associated documentation files (the
22  * "Software"), to deal in the Software without restriction, including
23  * without limitation the rights to use, copy, modify, merge, publish,
24  * distribute, sublicense, and/or sell copies of the Software, and to
25  * permit persons to whom the Software is furnished to do so, subject to
26  * the following conditions:
27  *
28  * The above copyright notice and this permission notice shall be
29  * included in all copies or substantial portions of the Software.
30  *
31  *  THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
32  *  EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
33  *  MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
34  *  NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
35  *  LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
36  *  OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
37  *  WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
38  */
39
40 #ifndef included_ip_ip4_error_h
41 #define included_ip_ip4_error_h
42
43 #define foreach_ip4_error                                               \
44   /* Must be first. */                                                  \
45   _ (NONE, "valid ip4 packets")                                         \
46                                                                         \
47   /* Errors signalled by ip4-input */                                   \
48   _ (TOO_SHORT, "ip4 length < 20 bytes")                                \
49   _ (BAD_LENGTH, "ip4 length > l2 length")                              \
50   _ (BAD_CHECKSUM, "bad ip4 checksum")                                  \
51   _ (VERSION, "ip4 version != 4")                                       \
52   _ (OPTIONS, "ip4 options present")                                    \
53   _ (FRAGMENT_OFFSET_ONE, "ip4 fragment offset == 1")                   \
54   _ (TIME_EXPIRED, "ip4 ttl <= 1")                                      \
55                                                                         \
56   /* Errors signalled by ip4-rewrite. */                                \
57   _ (MTU_EXCEEDED, "ip4 MTU exceeded and DF set")                       \
58   _ (DST_LOOKUP_MISS, "ip4 destination lookup miss")                    \
59   _ (SRC_LOOKUP_MISS, "ip4 source lookup miss")                         \
60   _ (DROP, "ip4 drop")                                                  \
61   _ (PUNT, "ip4 punt")                                                  \
62   _ (SAME_INTERFACE, "ip4 egress interface same as ingress")            \
63                                                                         \
64   /* Errors signalled by ip4-local. */                                  \
65   _ (UNKNOWN_PROTOCOL, "unknown ip protocol")                           \
66   _ (TCP_CHECKSUM, "bad tcp checksum")                                  \
67   _ (UDP_CHECKSUM, "bad udp checksum")                                  \
68   _ (UDP_LENGTH, "inconsistent udp/ip lengths")                         \
69                                                                         \
70   /* Errors signalled by ip4-source-check. */                           \
71   _ (UNICAST_SOURCE_CHECK_FAILS, "ip4 unicast source check fails")      \
72                                                                         \
73   /* Spoofed packets in ip4-rewrite-local */                            \
74   _ (SPOOFED_LOCAL_PACKETS, "ip4 spoofed local-address packet drops")   \
75                                                                         \
76   /* Errors singalled by ip4-inacl */                                   \
77   _ (INACL_TABLE_MISS, "input ACL table-miss drops")                    \
78   _ (INACL_SESSION_DENY, "input ACL session deny drops")                \
79   /* Errors singalled by ip4-outacl */                                  \
80   _ (OUTACL_TABLE_MISS, "output ACL table-miss drops")                  \
81   _ (OUTACL_SESSION_DENY, "output ACL session deny drops")              \
82                                                                         \
83   /* Erros from mfib-forward */                                         \
84   _ (RPF_FAILURE, "Multicast RPF check failed")                         \
85                                                                         \
86   /* Errors signalled by ip4-reassembly */                              \
87   _ (REASS_DUPLICATE_FRAGMENT, "duplicate/overlapping fragments")       \
88   _ (REASS_LIMIT_REACHED, "drops due to concurrent reassemblies limit") \
89   _ (REASS_FRAGMENT_CHAIN_TOO_LONG, "fragment chain too long (drop)")   \
90   _ (REASS_NO_BUF, "out of buffers (drop)")                             \
91   _ (REASS_MALFORMED_PACKET, "malformed packets")                       \
92   _ (REASS_INTERNAL_ERROR, "drops due to internal reassembly error")
93
94 typedef enum
95 {
96 #define _(sym,str) IP4_ERROR_##sym,
97   foreach_ip4_error
98 #undef _
99     IP4_N_ERROR,
100 } ip4_error_t;
101
102 #endif /* included_ip_ip4_error_h */
103
104 /*
105  * fd.io coding-style-patch-verification: ON
106  *
107  * Local Variables:
108  * eval: (c-set-style "gnu")
109  * End:
110  */