The WINDIVERT_HELPER_NO_REPLACE flag tells WinDivertHelperCalcChecksums not to
recalculate and replace non-zero checksum fields. This is useful for
reconstructing the checksums for packets returned by WinDivertRecv(), where
all non-zero checksum fields are already valid. This allows WinDivert1.2
to achieve similar efficiency as WinDivert1.1, where checksums were calculated
by the driver.
Note that for modified packets, the WINDIVERT_HELPER_NO_REPLACE flag should
not be used, as all checksums need to be recalculated from scratch anyway.
- As discussed in #37, the WINDIVERT_FLAG_NO_CHECKSUM behavior has become the
default. This means that outbound packets returned by WinDivertRecv() are
no longer guaranteed to have valid checksums, thanks to TCP checksum
offloading by the Windows TCP/IP stack. The checksums can still be
recovered by calling WinDivertHelperCalcChecksums() manually.
- Remove the old WinDivert1.0 legacy API, as nobody should still be using it.
Replaces the old filter compiler with a new version that:
- Is a cleaner, more extensible, implementation.
- Can report specific error messages (e.g. bad token vs parse error).
- Supports the new C-style if-then-else expression "(A? B: C)" syntax.
Two new WinDivert helper API functions have been implemented:
- WinDivertHelperCheckFilter() can be used to check a filter string for
errors.
- WinDivertHelperEvalFilter() evaluates a filter on a given packet. Will be
useful for testing.
* WinDivert sublayers are created and inserted when the driver is loaded.
* All WinDivert callouts are installed at the same sublayer.
- Clean-up the implementation of priorities.
- Re-introduce deep copying for SNIFF mode. This avoids referencing the
sniffed packets.
- Fix-up the netfilter example:
* Don't send RSTs to RST/FINs, this can start a RST war.
* Don't inject ICMP outbound - this may not be a problem despite 1233 errors.
1) Remove the dependency on the WdfCoInstaller*.dll file. This file appears
to be unnecessary for Windows 7 and up, and for patched Vista+2008.
2) Remove the WinDivert.inf file (only used by the co-installer).
3) 32/64-bit versions of the driver are now explicitly named, meaning that
the two can co-exist in the same directory.
4) The 32-bit WinDivert.dll can now automatically load the 64-bit driver on
64-bit Windows. This means it is possible to write 32-bit WinDivert
applications that automatically work on 64-bit windows.
5) WinDivert.dll now schedules the WinDivert service to be deleted right
away. This should fix some cases where the service is never deleted,
even during reboot.
6) Updated build scripts to reflect the changes.
* Re-brand "DIVERT" to "WINDIVERT" throughout the code-base.
* New flags:
> WINDIVERT_FLAG_PASSTHRU: Do not drop nor capture packets. Useful
for injection-only handles.
> WINDIVERT_FLAG_NO_CHECKSUM: Do not guarantee that diverted packets
have a correct checksum.
NOTE: Not yet tested!
* New default values and limits for various WinDivert parameters,
including WINDIVERT_PARAM_QUEUE_LEN, WINDIVERT_PARAM_QUEUE_TIME, and
the maximum filter length.
* New extended WinDivert functions that support asynchronous I/O:
> WinDivertRecvEx(..)
> WinDivertSendEx(..)
NOTE: Not yet tested!
* The WinDivert driver now services reads (receives) out-of-band.
The motivation is because WFP callouts are run at DISPATCH_LEVEL, so
we should not be doing expensive work in the ClassifyFn. This is also
the same reason why the filter length has been restricted.
- VS2010 support added via msvc-build.bat and *.vcxproj files
- MinGW now also builds example programs
- Documentation and examples are now included in the binary packages
Name and version:
* Now officially called 'WinDivert'
* Now officially working towards a version 1.0 release
New features:
* WinDivert now supports a packet-sniffing mode. This mode merely
copies packets, and does not drop the original.
* WinDivert now also supports a packet-dropping mode.
* WinDivert now supports filter priorities.
* WinDivert now supports a forwarded packet layer (WARNING: untested).
* WinDivert now supports get/set parameters such as packet queue length and
time.
* WinDivert now supports larger filters (but use at own risk).
* WinDivert now uninstalls the driver on program exit/library unload
* Different versions of WinDivert can co-exist on the same machine
(WARNING: untested, as there is currently only one version).
New License:
* WinDivert is now LGPL. This is less restrictive than the GPL so WinDivert
can be linked to by commercial software (under the terms of the LGPL
license).
Technical:
* Cleaner IOCTL interface.
* Cleaner driver implementation.
* Thread local events in WinDivert.dll
* Many minor tweaks and fixes.
includes making the driver handle I/O requests in parallel, and changing
the library such that it uses overlapped I/O. Overall the package is
now significantly faster.
- The divert driver now only adds WFP callouts when a filter is set,
instead of when a handle is created.
- The divert driver now attempts to avoid adding WFP callouts that are
superfluous with respect to the filter.
- The divert driver now explicitly deletes filters and callouts during
cleanup. This appears to resolve a bug where network connectivity is
sometimes lost.
- Added a new sample program: passthru.exe. This example doesn't do anything
interesting but is useful for speed testing.
- Rename build.sh to mingw-build.sh to avoid confusion.
- Make the pAddr arg for DivertRecv() optional
- Make the i386 user binaries compatible with an amd64 driver.
(useful for projects not yet ported to amd64)
data itself. This makes for a much cleaner interface.
sys/divert.c
dll/divert.c
include/*.h
DivertRecv and DivertSend now use IOCTLs instead of reads/writes.
The 'address' parameter is passed by pointer to the driver, which
writes directly to it (after sanity checks).
This means that the data buffer now only contains the packet, which
help to avoid some messy code.
examples/*/*.c
Update the examples to reflect the new API.
doc/divert.html
Update the documentation to reflect the new API.