WinDivert now treats all offloaded checksum fields as zero:
- WinDivertRecv() will zero all offloaded checksum fields.
- Filter matching will treat offloaded fields as zero.
Bump version and change magic numbers to make the driver incompatible with
older versions. Also cleanup some driver checksum code missed by previous
commit.
- As discussed in #37, the WINDIVERT_FLAG_NO_CHECKSUM behavior has become the
default. This means that outbound packets returned by WinDivertRecv() are
no longer guaranteed to have valid checksums, thanks to TCP checksum
offloading by the Windows TCP/IP stack. The checksums can still be
recovered by calling WinDivertHelperCalcChecksums() manually.
- Remove the old WinDivert1.0 legacy API, as nobody should still be using it.
by the classify function and silently dropped. This can degrade outbound
speed significantly, as it forces the Windows TCP/IP stack to re-send the
missing data. Thanks to GhalemB who found the bug & fix.
* WinDivert sublayers are created and inserted when the driver is loaded.
* All WinDivert callouts are installed at the same sublayer.
- Clean-up the implementation of priorities.
- Re-introduce deep copying for SNIFF mode. This avoids referencing the
sniffed packets.
- Fix-up the netfilter example:
* Don't send RSTs to RST/FINs, this can start a RST war.
* Don't inject ICMP outbound - this may not be a problem despite 1233 errors.
1) Remove the dependency on the WdfCoInstaller*.dll file. This file appears
to be unnecessary for Windows 7 and up, and for patched Vista+2008.
2) Remove the WinDivert.inf file (only used by the co-installer).
3) 32/64-bit versions of the driver are now explicitly named, meaning that
the two can co-exist in the same directory.
4) The 32-bit WinDivert.dll can now automatically load the 64-bit driver on
64-bit Windows. This means it is possible to write 32-bit WinDivert
applications that automatically work on 64-bit windows.
5) WinDivert.dll now schedules the WinDivert service to be deleted right
away. This should fix some cases where the service is never deleted,
even during reboot.
6) Updated build scripts to reflect the changes.
NET_BUFFERs in a single NET_BUFFER_LIST. Apparently this should only
ever occur in the FORWARD layer in certain circumstances, and even then each
fragment should be indicated individually anyway. This change removes a lot
of needless complexity.
the original packet. The former turns out to be problematic, since there is
no guarantee that something else (e.g. another callout driver)
modifies/overwrites the packet data whilst it is in the queue. Copying the
data is not ideal either, but seems to be the only way to ensure the packet
is not changed later.
* Re-brand "DIVERT" to "WINDIVERT" throughout the code-base.
* New flags:
> WINDIVERT_FLAG_PASSTHRU: Do not drop nor capture packets. Useful
for injection-only handles.
> WINDIVERT_FLAG_NO_CHECKSUM: Do not guarantee that diverted packets
have a correct checksum.
NOTE: Not yet tested!
* New default values and limits for various WinDivert parameters,
including WINDIVERT_PARAM_QUEUE_LEN, WINDIVERT_PARAM_QUEUE_TIME, and
the maximum filter length.
* New extended WinDivert functions that support asynchronous I/O:
> WinDivertRecvEx(..)
> WinDivertSendEx(..)
NOTE: Not yet tested!
* The WinDivert driver now services reads (receives) out-of-band.
The motivation is because WFP callouts are run at DISPATCH_LEVEL, so
we should not be doing expensive work in the ClassifyFn. This is also
the same reason why the filter length has been restricted.
* Use type 0 for FwpsInjectionHandleCreate0 for the FORWARD layer.
* Use FWPS_FIELD_IPFORWARD_V{4|6}_DESTINATION_INTERFACE_INDEX to get addr->IfIdx
* Replace FWP_ACTION_CONTINUE with FWP_ACTION_PERMIT.
Name and version:
* Now officially called 'WinDivert'
* Now officially working towards a version 1.0 release
New features:
* WinDivert now supports a packet-sniffing mode. This mode merely
copies packets, and does not drop the original.
* WinDivert now also supports a packet-dropping mode.
* WinDivert now supports filter priorities.
* WinDivert now supports a forwarded packet layer (WARNING: untested).
* WinDivert now supports get/set parameters such as packet queue length and
time.
* WinDivert now supports larger filters (but use at own risk).
* WinDivert now uninstalls the driver on program exit/library unload
* Different versions of WinDivert can co-exist on the same machine
(WARNING: untested, as there is currently only one version).
New License:
* WinDivert is now LGPL. This is less restrictive than the GPL so WinDivert
can be linked to by commercial software (under the terms of the LGPL
license).
Technical:
* Cleaner IOCTL interface.
* Cleaner driver implementation.
* Thread local events in WinDivert.dll
* Many minor tweaks and fixes.