Skip to main content

retina_core/conntrack/conn/tcp_conn/
mod.rs

1pub(crate) mod reassembly;
2
3use self::reassembly::TcpFlow;
4use crate::conntrack::conn::conn_info::ConnInfo;
5use crate::conntrack::pdu::{L4Context, L4Pdu};
6use crate::protocols::packet::tcp::{FIN, RST};
7use crate::protocols::stream::ParserRegistry;
8use crate::subscription::{Subscription, Trackable};
9
10pub(crate) struct TcpConn {
11    pub(crate) ctos: TcpFlow,
12    pub(crate) stoc: TcpFlow,
13}
14
15impl TcpConn {
16    pub(crate) fn new_on_syn(ctxt: L4Context, max_ooo: usize) -> Self {
17        let flags = ctxt.flags;
18        let next_seq = ctxt.seq_no.wrapping_add(1 + ctxt.length as u32);
19        TcpConn {
20            ctos: TcpFlow::new(max_ooo, next_seq, flags),
21            stoc: TcpFlow::default(max_ooo),
22        }
23    }
24
25    /// Insert TCP segment ordered into ctos or stoc flow
26    #[inline]
27    pub(crate) fn reassemble<T: Trackable>(
28        &mut self,
29        segment: L4Pdu,
30        info: &mut ConnInfo<T>,
31        subscription: &Subscription<T::Subscribed>,
32        registry: &ParserRegistry,
33    ) {
34        if segment.dir {
35            self.ctos
36                .insert_segment::<T>(segment, info, subscription, registry);
37        } else {
38            self.stoc
39                .insert_segment::<T>(segment, info, subscription, registry);
40        }
41    }
42
43    /// Returns `true` if the connection should be terminated
44    #[inline]
45    pub(crate) fn is_terminated(&self) -> bool {
46        // Both sides have sent FIN, or a RST has been sent
47        (self.ctos.consumed_flags & self.stoc.consumed_flags & FIN
48            | self.ctos.consumed_flags & RST
49            | self.stoc.consumed_flags & RST)
50            != 0
51    }
52
53    /// Updates connection termination flags
54    #[inline]
55    pub(super) fn update_term_condition(&mut self, flags: u8, dir: bool) {
56        if dir {
57            self.ctos.consumed_flags |= flags;
58        } else {
59            self.stoc.consumed_flags |= flags;
60        }
61    }
62}