blob: dc86c70f23d3ee35d1a566711d960a36fd67c79a [file] [log] [blame]
Alexander Afanasyeve4d745d2018-04-08 17:55:56 -04001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2/*
3 * Copyright (c) 2014-2018, Regents of the University of California,
4 * Arizona Board of Regents,
5 * Colorado State University,
6 * University Pierre & Marie Curie, Sorbonne University,
7 * Washington University in St. Louis,
8 * Beijing Institute of Technology,
9 * The University of Memphis.
10 *
11 * This file is part of NFD (Named Data Networking Forwarding Daemon).
12 * See AUTHORS.md for complete list of NFD authors and contributors.
13 *
14 * NFD is free software: you can redistribute it and/or modify it under the terms
15 * of the GNU General Public License as published by the Free Software Foundation,
16 * either version 3 of the License, or (at your option) any later version.
17 *
18 * NFD is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;
19 * without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
20 * PURPOSE. See the GNU General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License along with
23 * NFD, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
24 */
25
26#ifndef NFD_CORE_NETWORK_PREDICATE_HPP
27#define NFD_CORE_NETWORK_PREDICATE_HPP
28
29#include "common.hpp"
30#include <ndn-cxx/net/network-interface.hpp>
31
32namespace nfd {
33
34class NetworkPredicateBase
35{
36public:
37 NetworkPredicateBase();
38
39 virtual
40 ~NetworkPredicateBase();
41
42 /**
43 * \brief Set the whitelist to "*" and clear the blacklist
44 */
45 void
46 clear();
47
48 void
49 parseWhitelist(const boost::property_tree::ptree& list);
50
51 void
52 parseBlacklist(const boost::property_tree::ptree& list);
53
54 void
55 assign(std::initializer_list<std::pair<std::string, std::string>> whitelist,
56 std::initializer_list<std::pair<std::string, std::string>> blacklist);
57
58 bool
59 operator==(const NetworkPredicateBase& other) const;
60
61 bool
62 operator!=(const NetworkPredicateBase& other) const
63 {
64 return !this->operator==(other);
65 }
66
67private:
68 virtual bool
69 isRuleSupported(const std::string& key) = 0;
70
71 virtual bool
72 isRuleValid(const std::string& key, const std::string& value) = 0;
73
74 void
75 parseList(std::set<std::string>& set, const boost::property_tree::ptree& list, const std::string& section);
76
77 void
78 parseList(std::set<std::string>& set, std::initializer_list<std::pair<std::string, std::string>> list);
79
80PUBLIC_WITH_TESTS_ELSE_PROTECTED:
81 std::set<std::string> m_whitelist;
82 std::set<std::string> m_blacklist;
83};
84
85/**
86 * \brief Represents a predicate to accept or reject a ndn::net::NetworkInterface.
87 *
88 * The predicate consists of a whitelist and a blacklist. Whitelist and blacklist can contain,
89 * in no particular order, interface names (e.g., `ifname eth0`), MAC addresses (e.g., `ether
90 * 85:3b:4d:d3:5f:c2`), IPv4 and IPv6 subnets (e.g., `subnet 192.0.2.0/24` or `subnet
91 * 2001:db8:2::/64`), or a wildcard (`*`) that matches all interfaces. A
92 * ndn::net::NetworkInterface is accepted if it matches any entry in the whitelist and none of
93 * the entries in the blacklist.
94 */
95class NetworkInterfacePredicate : public NetworkPredicateBase
96{
97public:
98 bool
99 operator()(const ndn::net::NetworkInterface& netif) const;
100
101private:
102 bool
103 isRuleSupported(const std::string& key) final;
104
105 bool
106 isRuleValid(const std::string& key, const std::string& value) final;
107};
108
109/**
110 * \brief Represents a predicate to accept or reject an IP address.
111 *
112 * The predicate consists of a whitelist and a blacklist. Whitelist and blacklist can contain,
113 * in no particular order, IPv4 and IPv6 subnets (e.g., `subnet 192.0.2.0/24` or `subnet
114 * 2001:db8:2::/64`) or a wildcard (`*`) that matches all IP addresses. An IP address is
115 * accepted if it matches any entry in the whitelist and none of the entries in the blacklist.
116 */
117class IpAddressPredicate : public NetworkPredicateBase
118{
119public:
120 bool
121 operator()(const boost::asio::ip::address& address) const;
122
123private:
124 bool
125 isRuleSupported(const std::string& key) final;
126
127 bool
128 isRuleValid(const std::string& key, const std::string& value) final;
129};
130
131} // namespace nfd
132
133#endif // NFD_CORE_NETWORK_PREDICATE_HPP