xfrm4_output.c 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140
  1. /*
  2. * xfrm4_output.c - Common IPsec encapsulation code for IPv4.
  3. * Copyright (c) 2004 Herbert Xu <herbert@gondor.apana.org.au>
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License
  7. * as published by the Free Software Foundation; either version
  8. * 2 of the License, or (at your option) any later version.
  9. */
  10. #include <linux/compiler.h>
  11. #include <linux/if_ether.h>
  12. #include <linux/kernel.h>
  13. #include <linux/skbuff.h>
  14. #include <linux/netfilter_ipv4.h>
  15. #include <net/ip.h>
  16. #include <net/xfrm.h>
  17. #include <net/icmp.h>
  18. static int xfrm4_tunnel_check_size(struct sk_buff *skb)
  19. {
  20. int mtu, ret = 0;
  21. struct dst_entry *dst;
  22. if (IPCB(skb)->flags & IPSKB_XFRM_TUNNEL_SIZE)
  23. goto out;
  24. IPCB(skb)->flags |= IPSKB_XFRM_TUNNEL_SIZE;
  25. if (!(ip_hdr(skb)->frag_off & htons(IP_DF)) || skb->local_df)
  26. goto out;
  27. dst = skb->dst;
  28. mtu = dst_mtu(dst);
  29. if (skb->len > mtu) {
  30. icmp_send(skb, ICMP_DEST_UNREACH, ICMP_FRAG_NEEDED, htonl(mtu));
  31. ret = -EMSGSIZE;
  32. }
  33. out:
  34. return ret;
  35. }
  36. static inline int xfrm4_output_one(struct sk_buff *skb)
  37. {
  38. struct dst_entry *dst = skb->dst;
  39. struct xfrm_state *x = dst->xfrm;
  40. int err;
  41. if (x->props.mode == XFRM_MODE_TUNNEL) {
  42. err = xfrm4_tunnel_check_size(skb);
  43. if (err)
  44. goto error_nolock;
  45. }
  46. err = xfrm_output(skb);
  47. if (err)
  48. goto error_nolock;
  49. IPCB(skb)->flags |= IPSKB_XFRM_TRANSFORMED;
  50. err = 0;
  51. out_exit:
  52. return err;
  53. error_nolock:
  54. kfree_skb(skb);
  55. goto out_exit;
  56. }
  57. static int xfrm4_output_finish2(struct sk_buff *skb)
  58. {
  59. int err;
  60. while (likely((err = xfrm4_output_one(skb)) == 0)) {
  61. nf_reset(skb);
  62. err = nf_hook(PF_INET, NF_IP_LOCAL_OUT, &skb, NULL,
  63. skb->dst->dev, dst_output);
  64. if (unlikely(err != 1))
  65. break;
  66. if (!skb->dst->xfrm)
  67. return dst_output(skb);
  68. err = nf_hook(PF_INET, NF_IP_POST_ROUTING, &skb, NULL,
  69. skb->dst->dev, xfrm4_output_finish2);
  70. if (unlikely(err != 1))
  71. break;
  72. }
  73. return err;
  74. }
  75. static int xfrm4_output_finish(struct sk_buff *skb)
  76. {
  77. struct sk_buff *segs;
  78. #ifdef CONFIG_NETFILTER
  79. if (!skb->dst->xfrm) {
  80. IPCB(skb)->flags |= IPSKB_REROUTED;
  81. return dst_output(skb);
  82. }
  83. #endif
  84. if (!skb_is_gso(skb))
  85. return xfrm4_output_finish2(skb);
  86. skb->protocol = htons(ETH_P_IP);
  87. segs = skb_gso_segment(skb, 0);
  88. kfree_skb(skb);
  89. if (unlikely(IS_ERR(segs)))
  90. return PTR_ERR(segs);
  91. do {
  92. struct sk_buff *nskb = segs->next;
  93. int err;
  94. segs->next = NULL;
  95. err = xfrm4_output_finish2(segs);
  96. if (unlikely(err)) {
  97. while ((segs = nskb)) {
  98. nskb = segs->next;
  99. segs->next = NULL;
  100. kfree_skb(segs);
  101. }
  102. return err;
  103. }
  104. segs = nskb;
  105. } while (segs);
  106. return 0;
  107. }
  108. int xfrm4_output(struct sk_buff *skb)
  109. {
  110. return NF_HOOK_COND(PF_INET, NF_IP_POST_ROUTING, skb, NULL, skb->dst->dev,
  111. xfrm4_output_finish,
  112. !(IPCB(skb)->flags & IPSKB_REROUTED));
  113. }