xfrm4_output.c 2.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135
  1. /*
  2. * xfrm4_output.c - Common IPsec encapsulation code for IPv4.
  3. * Copyright (c) 2004 Herbert Xu <herbert@gondor.apana.org.au>
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License
  7. * as published by the Free Software Foundation; either version
  8. * 2 of the License, or (at your option) any later version.
  9. */
  10. #include <linux/compiler.h>
  11. #include <linux/skbuff.h>
  12. #include <linux/spinlock.h>
  13. #include <linux/netfilter_ipv4.h>
  14. #include <net/ip.h>
  15. #include <net/xfrm.h>
  16. #include <net/icmp.h>
  17. static int xfrm4_tunnel_check_size(struct sk_buff *skb)
  18. {
  19. int mtu, ret = 0;
  20. struct dst_entry *dst;
  21. struct iphdr *iph = skb->nh.iph;
  22. if (IPCB(skb)->flags & IPSKB_XFRM_TUNNEL_SIZE)
  23. goto out;
  24. IPCB(skb)->flags |= IPSKB_XFRM_TUNNEL_SIZE;
  25. if (!(iph->frag_off & htons(IP_DF)) || skb->local_df)
  26. goto out;
  27. dst = skb->dst;
  28. mtu = dst_mtu(dst);
  29. if (skb->len > mtu) {
  30. icmp_send(skb, ICMP_DEST_UNREACH, ICMP_FRAG_NEEDED, htonl(mtu));
  31. ret = -EMSGSIZE;
  32. }
  33. out:
  34. return ret;
  35. }
  36. static int xfrm4_output_one(struct sk_buff *skb)
  37. {
  38. struct dst_entry *dst = skb->dst;
  39. struct xfrm_state *x = dst->xfrm;
  40. int err;
  41. if (skb->ip_summed == CHECKSUM_HW) {
  42. err = skb_checksum_help(skb, 0);
  43. if (err)
  44. goto error_nolock;
  45. }
  46. if (x->props.mode) {
  47. err = xfrm4_tunnel_check_size(skb);
  48. if (err)
  49. goto error_nolock;
  50. }
  51. do {
  52. spin_lock_bh(&x->lock);
  53. err = xfrm_state_check(x, skb);
  54. if (err)
  55. goto error;
  56. err = x->mode->output(skb);
  57. if (err)
  58. goto error;
  59. err = x->type->output(x, skb);
  60. if (err)
  61. goto error;
  62. x->curlft.bytes += skb->len;
  63. x->curlft.packets++;
  64. spin_unlock_bh(&x->lock);
  65. if (!(skb->dst = dst_pop(dst))) {
  66. err = -EHOSTUNREACH;
  67. goto error_nolock;
  68. }
  69. dst = skb->dst;
  70. x = dst->xfrm;
  71. } while (x && !x->props.mode);
  72. IPCB(skb)->flags |= IPSKB_XFRM_TRANSFORMED;
  73. err = 0;
  74. out_exit:
  75. return err;
  76. error:
  77. spin_unlock_bh(&x->lock);
  78. error_nolock:
  79. kfree_skb(skb);
  80. goto out_exit;
  81. }
  82. static int xfrm4_output_finish(struct sk_buff *skb)
  83. {
  84. int err;
  85. #ifdef CONFIG_NETFILTER
  86. if (!skb->dst->xfrm) {
  87. IPCB(skb)->flags |= IPSKB_REROUTED;
  88. return dst_output(skb);
  89. }
  90. #endif
  91. while (likely((err = xfrm4_output_one(skb)) == 0)) {
  92. nf_reset(skb);
  93. err = nf_hook(PF_INET, NF_IP_LOCAL_OUT, &skb, NULL,
  94. skb->dst->dev, dst_output);
  95. if (unlikely(err != 1))
  96. break;
  97. if (!skb->dst->xfrm)
  98. return dst_output(skb);
  99. err = nf_hook(PF_INET, NF_IP_POST_ROUTING, &skb, NULL,
  100. skb->dst->dev, xfrm4_output_finish);
  101. if (unlikely(err != 1))
  102. break;
  103. }
  104. return err;
  105. }
  106. int xfrm4_output(struct sk_buff *skb)
  107. {
  108. return NF_HOOK_COND(PF_INET, NF_IP_POST_ROUTING, skb, NULL, skb->dst->dev,
  109. xfrm4_output_finish,
  110. !(IPCB(skb)->flags & IPSKB_REROUTED));
  111. }