diff --git a/doc/windivert.html b/doc/windivert.html index d465251..4a9320e 100644 --- a/doc/windivert.html +++ b/doc/windivert.html @@ -1,10 +1,10 @@
--sc stop WinDivert1.1 -sc delete WinDivert1.1 +sc stop WinDivert1.2 +sc delete WinDivert1.2Note that this is not recommended as it will interfere with other applications that depend on WinDivert. @@ -546,15 +548,6 @@ This is useful for implementing simple packet filters using the WinDivert filter language. -
+6.11 WinDivertHelperCheckFilter
+
++BOOL WinDivertHelperCheckFilter( + __in const char *filter, + __in WINDIVERT_LAYER layer, + __out_opt const char **errorStr, + __out_opt UINT *errorPos +); ++ |
+Parameters
+
+Return Value
+TRUE if the packet filter string is valid, FALSE otherwise.
+
+Remarks
+Checks if the given packet filter string is valid with respect to the
+filter language.
+If the filter is invalid, then a human readable description of the error is
+returned by errorStr (if non-NULL), and the error's
+position is returned by errorPos (if non-NULL).
+
+Note that all strings returned through errorStr are global static +objects, and therefore do not need to be deallocated. +
+
++BOOL WinDivertHelperEvalFilter( + __in const char *filter, + __in WINDIVERT_LAYER layer, + __in PVOID pPacket, + __in UINT packetLen, + __in PWINDIVERT_ADDRESS pAddr +); ++ |
+Parameters
+
+Return Value
+TRUE if the packet matches the filter string,
+ FALSE otherwise.
+
+Remarks
+Evaluates the given packet against the given packet filter string.
+This function returns TRUE if the packet matches, and
+returns FALSE otherwise.
+
+This function also returns FALSE if an error occurs, in which +case GetLastError() can be used to get the reason for the error. +Otherwise, if no error occurred, GetLastError() will return +0. +
+Note that this function is relatively slow since the packet filter string +will be (re)compiled for each call. +This function is mainly intended for debugging or testing purposes. +
+
A filter is a Boolean expression of the form:
- FILTER := true | false | FILTER and FILTER | FILTER or FILTER | (FILTER) | TEST + FILTER := true | false | FILTER and FILTER | FILTER or FILTER | (FILTER) | (FILTER? FILTER: FILTER) | TESTC-style syntax &&, ||, and ! may also be used instead of and, or, and not, respectively. +C-style conditional operators are also supported, +where the expression (A? B: C) evaluates to: +
TEST := TEST0 | not TEST0
@@ -1327,8 +1406,8 @@ The possible fields are:
Field Description
-outbound Is outbound?
-inbound Is inbound?
+outbound Is outbound? (only valid for WINDIVERT_LAYER_NETWORK)
+inbound Is inbound? (only valid for WINDIVERT_LAYER_NETWORK)
ifIdx Interface index
subIfIdx Sub-interface index
ip Is IPv4?