123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132 |
- #ifndef RTC_BASE_FIREWALL_SOCKET_SERVER_H_
- #define RTC_BASE_FIREWALL_SOCKET_SERVER_H_
- #include <vector>
- #include "rtc_base/async_socket.h"
- #include "rtc_base/ip_address.h"
- #include "rtc_base/socket.h"
- #include "rtc_base/socket_address.h"
- #include "rtc_base/socket_server.h"
- #include "rtc_base/synchronization/mutex.h"
- namespace rtc {
- class FirewallManager;
- enum FirewallProtocol { FP_UDP, FP_TCP, FP_ANY };
- enum FirewallDirection { FD_IN, FD_OUT, FD_ANY };
- class FirewallSocketServer : public SocketServer {
- public:
- FirewallSocketServer(SocketServer* server,
- FirewallManager* manager = nullptr,
- bool should_delete_server = false);
- ~FirewallSocketServer() override;
- SocketServer* socketserver() const { return server_; }
- void set_socketserver(SocketServer* server) {
- if (server_ && should_delete_server_) {
- delete server_;
- server_ = nullptr;
- should_delete_server_ = false;
- }
- server_ = server;
- }
-
- void set_udp_sockets_enabled(bool enabled) { udp_sockets_enabled_ = enabled; }
- void set_tcp_sockets_enabled(bool enabled) { tcp_sockets_enabled_ = enabled; }
- bool tcp_listen_enabled() const { return tcp_listen_enabled_; }
- void set_tcp_listen_enabled(bool enabled) { tcp_listen_enabled_ = enabled; }
-
- void AddRule(bool allow,
- FirewallProtocol p = FP_ANY,
- FirewallDirection d = FD_ANY,
- const SocketAddress& addr = SocketAddress());
- void AddRule(bool allow,
- FirewallProtocol p,
- const SocketAddress& src,
- const SocketAddress& dst);
- void ClearRules();
- bool Check(FirewallProtocol p,
- const SocketAddress& src,
- const SocketAddress& dst);
-
-
-
-
-
-
-
- void SetUnbindableIps(const std::vector<rtc::IPAddress>& unbindable_ips);
- bool IsBindableIp(const rtc::IPAddress& ip);
- Socket* CreateSocket(int family, int type) override;
- AsyncSocket* CreateAsyncSocket(int family, int type) override;
- void SetMessageQueue(Thread* queue) override;
- bool Wait(int cms, bool process_io) override;
- void WakeUp() override;
- Socket* WrapSocket(Socket* sock, int type);
- AsyncSocket* WrapSocket(AsyncSocket* sock, int type);
- private:
- SocketServer* server_;
- FirewallManager* manager_;
- webrtc::Mutex mutex_;
- struct Rule {
- bool allow;
- FirewallProtocol p;
- FirewallDirection d;
- SocketAddress src;
- SocketAddress dst;
- };
- std::vector<Rule> rules_;
- std::vector<rtc::IPAddress> unbindable_ips_;
- bool should_delete_server_;
- bool udp_sockets_enabled_;
- bool tcp_sockets_enabled_;
- bool tcp_listen_enabled_;
- };
- class FirewallManager {
- public:
- FirewallManager();
- ~FirewallManager();
- void AddServer(FirewallSocketServer* server);
- void RemoveServer(FirewallSocketServer* server);
- void AddRule(bool allow,
- FirewallProtocol p = FP_ANY,
- FirewallDirection d = FD_ANY,
- const SocketAddress& addr = SocketAddress());
- void ClearRules();
- private:
- webrtc::Mutex mutex_;
- std::vector<FirewallSocketServer*> servers_;
- };
- }
- #endif
|