xfrm4_output.c 2.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145
  1. /*
  2. * xfrm4_output.c - Common IPsec encapsulation code for IPv4.
  3. * Copyright (c) 2004 Herbert Xu <herbert@gondor.apana.org.au>
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License
  7. * as published by the Free Software Foundation; either version
  8. * 2 of the License, or (at your option) any later version.
  9. */
  10. #include <linux/compiler.h>
  11. #include <linux/if_ether.h>
  12. #include <linux/kernel.h>
  13. #include <linux/skbuff.h>
  14. #include <linux/netfilter_ipv4.h>
  15. #include <net/ip.h>
  16. #include <net/xfrm.h>
  17. #include <net/icmp.h>
  18. static int xfrm4_tunnel_check_size(struct sk_buff *skb)
  19. {
  20. int mtu, ret = 0;
  21. struct dst_entry *dst;
  22. if (IPCB(skb)->flags & IPSKB_XFRM_TUNNEL_SIZE)
  23. goto out;
  24. IPCB(skb)->flags |= IPSKB_XFRM_TUNNEL_SIZE;
  25. if (!(ip_hdr(skb)->frag_off & htons(IP_DF)) || skb->local_df)
  26. goto out;
  27. dst = skb->dst;
  28. mtu = dst_mtu(dst);
  29. if (skb->len > mtu) {
  30. icmp_send(skb, ICMP_DEST_UNREACH, ICMP_FRAG_NEEDED, htonl(mtu));
  31. ret = -EMSGSIZE;
  32. }
  33. out:
  34. return ret;
  35. }
  36. static inline int xfrm4_output_one(struct sk_buff *skb)
  37. {
  38. struct dst_entry *dst = skb->dst;
  39. struct xfrm_state *x = dst->xfrm;
  40. struct iphdr *iph;
  41. int err;
  42. if (x->props.mode == XFRM_MODE_TUNNEL) {
  43. err = xfrm4_tunnel_check_size(skb);
  44. if (err)
  45. goto error_nolock;
  46. }
  47. err = xfrm_output(skb);
  48. if (err)
  49. goto error_nolock;
  50. iph = ip_hdr(skb);
  51. iph->tot_len = htons(skb->len);
  52. ip_send_check(iph);
  53. IPCB(skb)->flags |= IPSKB_XFRM_TRANSFORMED;
  54. err = 0;
  55. out_exit:
  56. return err;
  57. error_nolock:
  58. kfree_skb(skb);
  59. goto out_exit;
  60. }
  61. static int xfrm4_output_finish2(struct sk_buff *skb)
  62. {
  63. int err;
  64. while (likely((err = xfrm4_output_one(skb)) == 0)) {
  65. nf_reset(skb);
  66. err = nf_hook(PF_INET, NF_IP_LOCAL_OUT, &skb, NULL,
  67. skb->dst->dev, dst_output);
  68. if (unlikely(err != 1))
  69. break;
  70. if (!skb->dst->xfrm)
  71. return dst_output(skb);
  72. err = nf_hook(PF_INET, NF_IP_POST_ROUTING, &skb, NULL,
  73. skb->dst->dev, xfrm4_output_finish2);
  74. if (unlikely(err != 1))
  75. break;
  76. }
  77. return err;
  78. }
  79. static int xfrm4_output_finish(struct sk_buff *skb)
  80. {
  81. struct sk_buff *segs;
  82. #ifdef CONFIG_NETFILTER
  83. if (!skb->dst->xfrm) {
  84. IPCB(skb)->flags |= IPSKB_REROUTED;
  85. return dst_output(skb);
  86. }
  87. #endif
  88. if (!skb_is_gso(skb))
  89. return xfrm4_output_finish2(skb);
  90. skb->protocol = htons(ETH_P_IP);
  91. segs = skb_gso_segment(skb, 0);
  92. kfree_skb(skb);
  93. if (unlikely(IS_ERR(segs)))
  94. return PTR_ERR(segs);
  95. do {
  96. struct sk_buff *nskb = segs->next;
  97. int err;
  98. segs->next = NULL;
  99. err = xfrm4_output_finish2(segs);
  100. if (unlikely(err)) {
  101. while ((segs = nskb)) {
  102. nskb = segs->next;
  103. segs->next = NULL;
  104. kfree_skb(segs);
  105. }
  106. return err;
  107. }
  108. segs = nskb;
  109. } while (segs);
  110. return 0;
  111. }
  112. int xfrm4_output(struct sk_buff *skb)
  113. {
  114. return NF_HOOK_COND(PF_INET, NF_IP_POST_ROUTING, skb, NULL, skb->dst->dev,
  115. xfrm4_output_finish,
  116. !(IPCB(skb)->flags & IPSKB_REROUTED));
  117. }