1e3e4712eSRoopa Prabhu /* 2e3e4712eSRoopa Prabhu * mpls tunnels An implementation mpls tunnels using the light weight tunnel 3e3e4712eSRoopa Prabhu * infrastructure 4e3e4712eSRoopa Prabhu * 5e3e4712eSRoopa Prabhu * Authors: Roopa Prabhu, <roopa@cumulusnetworks.com> 6e3e4712eSRoopa Prabhu * 7e3e4712eSRoopa Prabhu * This program is free software; you can redistribute it and/or 8e3e4712eSRoopa Prabhu * modify it under the terms of the GNU General Public License 9e3e4712eSRoopa Prabhu * as published by the Free Software Foundation; either version 10e3e4712eSRoopa Prabhu * 2 of the License, or (at your option) any later version. 11e3e4712eSRoopa Prabhu * 12e3e4712eSRoopa Prabhu */ 13e3e4712eSRoopa Prabhu #include <linux/types.h> 14e3e4712eSRoopa Prabhu #include <linux/skbuff.h> 15e3e4712eSRoopa Prabhu #include <linux/net.h> 16e3e4712eSRoopa Prabhu #include <linux/module.h> 17e3e4712eSRoopa Prabhu #include <linux/mpls.h> 18e3e4712eSRoopa Prabhu #include <linux/vmalloc.h> 19e3e4712eSRoopa Prabhu #include <net/ip.h> 20e3e4712eSRoopa Prabhu #include <net/dst.h> 21e3e4712eSRoopa Prabhu #include <net/lwtunnel.h> 22e3e4712eSRoopa Prabhu #include <net/netevent.h> 23e3e4712eSRoopa Prabhu #include <net/netns/generic.h> 24e3e4712eSRoopa Prabhu #include <net/ip6_fib.h> 25e3e4712eSRoopa Prabhu #include <net/route.h> 26e3e4712eSRoopa Prabhu #include <net/mpls_iptunnel.h> 27e3e4712eSRoopa Prabhu #include <linux/mpls_iptunnel.h> 28e3e4712eSRoopa Prabhu #include "internal.h" 29e3e4712eSRoopa Prabhu 30e3e4712eSRoopa Prabhu static const struct nla_policy mpls_iptunnel_policy[MPLS_IPTUNNEL_MAX + 1] = { 31e3e4712eSRoopa Prabhu [MPLS_IPTUNNEL_DST] = { .type = NLA_U32 }, 32a59166e4SRobert Shearman [MPLS_IPTUNNEL_TTL] = { .type = NLA_U8 }, 33e3e4712eSRoopa Prabhu }; 34e3e4712eSRoopa Prabhu 35e3e4712eSRoopa Prabhu static unsigned int mpls_encap_size(struct mpls_iptunnel_encap *en) 36e3e4712eSRoopa Prabhu { 37e3e4712eSRoopa Prabhu /* The size of the layer 2.5 labels to be added for this route */ 38e3e4712eSRoopa Prabhu return en->labels * sizeof(struct mpls_shim_hdr); 39e3e4712eSRoopa Prabhu } 40e3e4712eSRoopa Prabhu 4114972cbdSRoopa Prabhu static int mpls_xmit(struct sk_buff *skb) 42e3e4712eSRoopa Prabhu { 43e3e4712eSRoopa Prabhu struct mpls_iptunnel_encap *tun_encap_info; 44e3e4712eSRoopa Prabhu struct mpls_shim_hdr *hdr; 45e3e4712eSRoopa Prabhu struct net_device *out_dev; 46e3e4712eSRoopa Prabhu unsigned int hh_len; 47e3e4712eSRoopa Prabhu unsigned int new_header_size; 48e3e4712eSRoopa Prabhu unsigned int mtu; 49e3e4712eSRoopa Prabhu struct dst_entry *dst = skb_dst(skb); 50e3e4712eSRoopa Prabhu struct rtable *rt = NULL; 51e3e4712eSRoopa Prabhu struct rt6_info *rt6 = NULL; 5227d69105SRobert Shearman struct mpls_dev *out_mdev; 53a59166e4SRobert Shearman struct net *net; 54e3e4712eSRoopa Prabhu int err = 0; 55e3e4712eSRoopa Prabhu bool bos; 56e3e4712eSRoopa Prabhu int i; 57e3e4712eSRoopa Prabhu unsigned int ttl; 58e3e4712eSRoopa Prabhu 5927d69105SRobert Shearman /* Find the output device */ 6027d69105SRobert Shearman out_dev = dst->dev; 61a59166e4SRobert Shearman net = dev_net(out_dev); 62e3e4712eSRoopa Prabhu 63e3e4712eSRoopa Prabhu skb_orphan(skb); 64e3e4712eSRoopa Prabhu 65e3e4712eSRoopa Prabhu if (!mpls_output_possible(out_dev) || 6661adedf3SJiri Benc !dst->lwtstate || skb_warn_if_lro(skb)) 67e3e4712eSRoopa Prabhu goto drop; 68e3e4712eSRoopa Prabhu 69e3e4712eSRoopa Prabhu skb_forward_csum(skb); 70e3e4712eSRoopa Prabhu 7161adedf3SJiri Benc tun_encap_info = mpls_lwtunnel_encap(dst->lwtstate); 72e3e4712eSRoopa Prabhu 73a59166e4SRobert Shearman /* Obtain the ttl using the following set of rules. 74a59166e4SRobert Shearman * 75a59166e4SRobert Shearman * LWT ttl propagation setting: 76a59166e4SRobert Shearman * - disabled => use default TTL value from LWT 77a59166e4SRobert Shearman * - enabled => use TTL value from IPv4/IPv6 header 78a59166e4SRobert Shearman * - default => 79a59166e4SRobert Shearman * Global ttl propagation setting: 80a59166e4SRobert Shearman * - disabled => use default TTL value from global setting 81a59166e4SRobert Shearman * - enabled => use TTL value from IPv4/IPv6 header 82a59166e4SRobert Shearman */ 83a59166e4SRobert Shearman if (dst->ops->family == AF_INET) { 84a59166e4SRobert Shearman if (tun_encap_info->ttl_propagate == MPLS_TTL_PROP_DISABLED) 85a59166e4SRobert Shearman ttl = tun_encap_info->default_ttl; 86a59166e4SRobert Shearman else if (tun_encap_info->ttl_propagate == MPLS_TTL_PROP_DEFAULT && 87a59166e4SRobert Shearman !net->mpls.ip_ttl_propagate) 88a59166e4SRobert Shearman ttl = net->mpls.default_ttl; 89a59166e4SRobert Shearman else 90a59166e4SRobert Shearman ttl = ip_hdr(skb)->ttl; 91a59166e4SRobert Shearman rt = (struct rtable *)dst; 92a59166e4SRobert Shearman } else if (dst->ops->family == AF_INET6) { 93a59166e4SRobert Shearman if (tun_encap_info->ttl_propagate == MPLS_TTL_PROP_DISABLED) 94a59166e4SRobert Shearman ttl = tun_encap_info->default_ttl; 95a59166e4SRobert Shearman else if (tun_encap_info->ttl_propagate == MPLS_TTL_PROP_DEFAULT && 96a59166e4SRobert Shearman !net->mpls.ip_ttl_propagate) 97a59166e4SRobert Shearman ttl = net->mpls.default_ttl; 98a59166e4SRobert Shearman else 99a59166e4SRobert Shearman ttl = ipv6_hdr(skb)->hop_limit; 100a59166e4SRobert Shearman rt6 = (struct rt6_info *)dst; 101a59166e4SRobert Shearman } else { 102a59166e4SRobert Shearman goto drop; 103a59166e4SRobert Shearman } 104a59166e4SRobert Shearman 105e3e4712eSRoopa Prabhu /* Verify the destination can hold the packet */ 106e3e4712eSRoopa Prabhu new_header_size = mpls_encap_size(tun_encap_info); 107e3e4712eSRoopa Prabhu mtu = mpls_dev_mtu(out_dev); 108e3e4712eSRoopa Prabhu if (mpls_pkt_too_big(skb, mtu - new_header_size)) 109e3e4712eSRoopa Prabhu goto drop; 110e3e4712eSRoopa Prabhu 111e3e4712eSRoopa Prabhu hh_len = LL_RESERVED_SPACE(out_dev); 112e3e4712eSRoopa Prabhu if (!out_dev->header_ops) 113e3e4712eSRoopa Prabhu hh_len = 0; 114e3e4712eSRoopa Prabhu 115e3e4712eSRoopa Prabhu /* Ensure there is enough space for the headers in the skb */ 116e3e4712eSRoopa Prabhu if (skb_cow(skb, hh_len + new_header_size)) 117e3e4712eSRoopa Prabhu goto drop; 118e3e4712eSRoopa Prabhu 11948d2ab60SDavid Ahern skb_set_inner_protocol(skb, skb->protocol); 12048d2ab60SDavid Ahern skb_reset_inner_network_header(skb); 12148d2ab60SDavid Ahern 122e3e4712eSRoopa Prabhu skb_push(skb, new_header_size); 12348d2ab60SDavid Ahern 124e3e4712eSRoopa Prabhu skb_reset_network_header(skb); 125e3e4712eSRoopa Prabhu 126e3e4712eSRoopa Prabhu skb->dev = out_dev; 127e3e4712eSRoopa Prabhu skb->protocol = htons(ETH_P_MPLS_UC); 128e3e4712eSRoopa Prabhu 129e3e4712eSRoopa Prabhu /* Push the new labels */ 130e3e4712eSRoopa Prabhu hdr = mpls_hdr(skb); 131e3e4712eSRoopa Prabhu bos = true; 132e3e4712eSRoopa Prabhu for (i = tun_encap_info->labels - 1; i >= 0; i--) { 133e3e4712eSRoopa Prabhu hdr[i] = mpls_entry_encode(tun_encap_info->label[i], 134e3e4712eSRoopa Prabhu ttl, 0, bos); 135e3e4712eSRoopa Prabhu bos = false; 136e3e4712eSRoopa Prabhu } 137e3e4712eSRoopa Prabhu 13827d69105SRobert Shearman mpls_stats_inc_outucastpkts(out_dev, skb); 13927d69105SRobert Shearman 140e3e4712eSRoopa Prabhu if (rt) 141e3e4712eSRoopa Prabhu err = neigh_xmit(NEIGH_ARP_TABLE, out_dev, &rt->rt_gateway, 142e3e4712eSRoopa Prabhu skb); 143*f84532ceSVinay K Nallamothu else if (rt6) { 144*f84532ceSVinay K Nallamothu if (ipv6_addr_v4mapped(&rt6->rt6i_gateway)) { 145*f84532ceSVinay K Nallamothu /* 6PE (RFC 4798) */ 146*f84532ceSVinay K Nallamothu err = neigh_xmit(NEIGH_ARP_TABLE, out_dev, &rt6->rt6i_gateway.s6_addr32[3], 147*f84532ceSVinay K Nallamothu skb); 148*f84532ceSVinay K Nallamothu } else 149e3e4712eSRoopa Prabhu err = neigh_xmit(NEIGH_ND_TABLE, out_dev, &rt6->rt6i_gateway, 150e3e4712eSRoopa Prabhu skb); 151*f84532ceSVinay K Nallamothu } 152e3e4712eSRoopa Prabhu if (err) 153e3e4712eSRoopa Prabhu net_dbg_ratelimited("%s: packet transmission failed: %d\n", 154e3e4712eSRoopa Prabhu __func__, err); 155e3e4712eSRoopa Prabhu 15614972cbdSRoopa Prabhu return LWTUNNEL_XMIT_DONE; 157e3e4712eSRoopa Prabhu 158e3e4712eSRoopa Prabhu drop: 15927d69105SRobert Shearman out_mdev = out_dev ? mpls_dev_get(out_dev) : NULL; 16027d69105SRobert Shearman if (out_mdev) 16127d69105SRobert Shearman MPLS_INC_STATS(out_mdev, tx_errors); 162e3e4712eSRoopa Prabhu kfree_skb(skb); 163e3e4712eSRoopa Prabhu return -EINVAL; 164e3e4712eSRoopa Prabhu } 165e3e4712eSRoopa Prabhu 16630357d7dSDavid Ahern static int mpls_build_state(struct nlattr *nla, 167127eb7cdSTom Herbert unsigned int family, const void *cfg, 1689ae28727SDavid Ahern struct lwtunnel_state **ts, 1699ae28727SDavid Ahern struct netlink_ext_ack *extack) 170e3e4712eSRoopa Prabhu { 171e3e4712eSRoopa Prabhu struct mpls_iptunnel_encap *tun_encap_info; 172e3e4712eSRoopa Prabhu struct nlattr *tb[MPLS_IPTUNNEL_MAX + 1]; 173e3e4712eSRoopa Prabhu struct lwtunnel_state *newts; 1741511009cSDavid Ahern u8 n_labels; 175e3e4712eSRoopa Prabhu int ret; 176e3e4712eSRoopa Prabhu 177e3e4712eSRoopa Prabhu ret = nla_parse_nested(tb, MPLS_IPTUNNEL_MAX, nla, 1789ae28727SDavid Ahern mpls_iptunnel_policy, extack); 179e3e4712eSRoopa Prabhu if (ret < 0) 180e3e4712eSRoopa Prabhu return ret; 181e3e4712eSRoopa Prabhu 182a1f10abeSDavid Ahern if (!tb[MPLS_IPTUNNEL_DST]) { 183a1f10abeSDavid Ahern NL_SET_ERR_MSG(extack, "MPLS_IPTUNNEL_DST attribute is missing"); 184e3e4712eSRoopa Prabhu return -EINVAL; 185a1f10abeSDavid Ahern } 186e3e4712eSRoopa Prabhu 1871511009cSDavid Ahern /* determine number of labels */ 188a1f10abeSDavid Ahern if (nla_get_labels(tb[MPLS_IPTUNNEL_DST], MAX_NEW_LABELS, 189a1f10abeSDavid Ahern &n_labels, NULL, extack)) 1901511009cSDavid Ahern return -EINVAL; 1911511009cSDavid Ahern 192b4ba9354SGustavo A. R. Silva newts = lwtunnel_state_alloc(struct_size(tun_encap_info, label, 193b4ba9354SGustavo A. R. Silva n_labels)); 194e3e4712eSRoopa Prabhu if (!newts) 195e3e4712eSRoopa Prabhu return -ENOMEM; 196e3e4712eSRoopa Prabhu 197e3e4712eSRoopa Prabhu tun_encap_info = mpls_lwtunnel_encap(newts); 1981511009cSDavid Ahern ret = nla_get_labels(tb[MPLS_IPTUNNEL_DST], n_labels, 199a1f10abeSDavid Ahern &tun_encap_info->labels, tun_encap_info->label, 200a1f10abeSDavid Ahern extack); 201e3e4712eSRoopa Prabhu if (ret) 202e3e4712eSRoopa Prabhu goto errout; 203a59166e4SRobert Shearman 204a59166e4SRobert Shearman tun_encap_info->ttl_propagate = MPLS_TTL_PROP_DEFAULT; 205a59166e4SRobert Shearman 206a59166e4SRobert Shearman if (tb[MPLS_IPTUNNEL_TTL]) { 207a59166e4SRobert Shearman tun_encap_info->default_ttl = nla_get_u8(tb[MPLS_IPTUNNEL_TTL]); 208a59166e4SRobert Shearman /* TTL 0 implies propagate from IP header */ 209a59166e4SRobert Shearman tun_encap_info->ttl_propagate = tun_encap_info->default_ttl ? 210a59166e4SRobert Shearman MPLS_TTL_PROP_DISABLED : 211a59166e4SRobert Shearman MPLS_TTL_PROP_ENABLED; 212a59166e4SRobert Shearman } 213a59166e4SRobert Shearman 214e3e4712eSRoopa Prabhu newts->type = LWTUNNEL_ENCAP_MPLS; 21514972cbdSRoopa Prabhu newts->flags |= LWTUNNEL_STATE_XMIT_REDIRECT; 21614972cbdSRoopa Prabhu newts->headroom = mpls_encap_size(tun_encap_info); 217e3e4712eSRoopa Prabhu 218e3e4712eSRoopa Prabhu *ts = newts; 219e3e4712eSRoopa Prabhu 220e3e4712eSRoopa Prabhu return 0; 221e3e4712eSRoopa Prabhu 222e3e4712eSRoopa Prabhu errout: 223e3e4712eSRoopa Prabhu kfree(newts); 224e3e4712eSRoopa Prabhu *ts = NULL; 225e3e4712eSRoopa Prabhu 226e3e4712eSRoopa Prabhu return ret; 227e3e4712eSRoopa Prabhu } 228e3e4712eSRoopa Prabhu 229e3e4712eSRoopa Prabhu static int mpls_fill_encap_info(struct sk_buff *skb, 230e3e4712eSRoopa Prabhu struct lwtunnel_state *lwtstate) 231e3e4712eSRoopa Prabhu { 232e3e4712eSRoopa Prabhu struct mpls_iptunnel_encap *tun_encap_info; 233e3e4712eSRoopa Prabhu 234e3e4712eSRoopa Prabhu tun_encap_info = mpls_lwtunnel_encap(lwtstate); 235e3e4712eSRoopa Prabhu 236e3e4712eSRoopa Prabhu if (nla_put_labels(skb, MPLS_IPTUNNEL_DST, tun_encap_info->labels, 237e3e4712eSRoopa Prabhu tun_encap_info->label)) 238e3e4712eSRoopa Prabhu goto nla_put_failure; 239e3e4712eSRoopa Prabhu 240a59166e4SRobert Shearman if (tun_encap_info->ttl_propagate != MPLS_TTL_PROP_DEFAULT && 241a59166e4SRobert Shearman nla_put_u8(skb, MPLS_IPTUNNEL_TTL, tun_encap_info->default_ttl)) 242a59166e4SRobert Shearman goto nla_put_failure; 243a59166e4SRobert Shearman 244e3e4712eSRoopa Prabhu return 0; 245e3e4712eSRoopa Prabhu 246e3e4712eSRoopa Prabhu nla_put_failure: 247e3e4712eSRoopa Prabhu return -EMSGSIZE; 248e3e4712eSRoopa Prabhu } 249e3e4712eSRoopa Prabhu 250e3e4712eSRoopa Prabhu static int mpls_encap_nlsize(struct lwtunnel_state *lwtstate) 251e3e4712eSRoopa Prabhu { 252e3e4712eSRoopa Prabhu struct mpls_iptunnel_encap *tun_encap_info; 253a59166e4SRobert Shearman int nlsize; 254e3e4712eSRoopa Prabhu 255e3e4712eSRoopa Prabhu tun_encap_info = mpls_lwtunnel_encap(lwtstate); 256e3e4712eSRoopa Prabhu 257a59166e4SRobert Shearman nlsize = nla_total_size(tun_encap_info->labels * 4); 258a59166e4SRobert Shearman 259a59166e4SRobert Shearman if (tun_encap_info->ttl_propagate != MPLS_TTL_PROP_DEFAULT) 260a59166e4SRobert Shearman nlsize += nla_total_size(1); 261a59166e4SRobert Shearman 262a59166e4SRobert Shearman return nlsize; 263e3e4712eSRoopa Prabhu } 264e3e4712eSRoopa Prabhu 265e3e4712eSRoopa Prabhu static int mpls_encap_cmp(struct lwtunnel_state *a, struct lwtunnel_state *b) 266e3e4712eSRoopa Prabhu { 267e3e4712eSRoopa Prabhu struct mpls_iptunnel_encap *a_hdr = mpls_lwtunnel_encap(a); 268e3e4712eSRoopa Prabhu struct mpls_iptunnel_encap *b_hdr = mpls_lwtunnel_encap(b); 269e3e4712eSRoopa Prabhu int l; 270e3e4712eSRoopa Prabhu 271a59166e4SRobert Shearman if (a_hdr->labels != b_hdr->labels || 272a59166e4SRobert Shearman a_hdr->ttl_propagate != b_hdr->ttl_propagate || 273a59166e4SRobert Shearman a_hdr->default_ttl != b_hdr->default_ttl) 274e3e4712eSRoopa Prabhu return 1; 275e3e4712eSRoopa Prabhu 2761511009cSDavid Ahern for (l = 0; l < a_hdr->labels; l++) 277e3e4712eSRoopa Prabhu if (a_hdr->label[l] != b_hdr->label[l]) 278e3e4712eSRoopa Prabhu return 1; 279e3e4712eSRoopa Prabhu return 0; 280e3e4712eSRoopa Prabhu } 281e3e4712eSRoopa Prabhu 282e3e4712eSRoopa Prabhu static const struct lwtunnel_encap_ops mpls_iptun_ops = { 283e3e4712eSRoopa Prabhu .build_state = mpls_build_state, 28414972cbdSRoopa Prabhu .xmit = mpls_xmit, 285e3e4712eSRoopa Prabhu .fill_encap = mpls_fill_encap_info, 286e3e4712eSRoopa Prabhu .get_encap_size = mpls_encap_nlsize, 287e3e4712eSRoopa Prabhu .cmp_encap = mpls_encap_cmp, 28888ff7334SRobert Shearman .owner = THIS_MODULE, 289e3e4712eSRoopa Prabhu }; 290e3e4712eSRoopa Prabhu 291e3e4712eSRoopa Prabhu static int __init mpls_iptunnel_init(void) 292e3e4712eSRoopa Prabhu { 293e3e4712eSRoopa Prabhu return lwtunnel_encap_add_ops(&mpls_iptun_ops, LWTUNNEL_ENCAP_MPLS); 294e3e4712eSRoopa Prabhu } 295e3e4712eSRoopa Prabhu module_init(mpls_iptunnel_init); 296e3e4712eSRoopa Prabhu 297e3e4712eSRoopa Prabhu static void __exit mpls_iptunnel_exit(void) 298e3e4712eSRoopa Prabhu { 299e3e4712eSRoopa Prabhu lwtunnel_encap_del_ops(&mpls_iptun_ops, LWTUNNEL_ENCAP_MPLS); 300e3e4712eSRoopa Prabhu } 301e3e4712eSRoopa Prabhu module_exit(mpls_iptunnel_exit); 302e3e4712eSRoopa Prabhu 303b2b04edcSRobert Shearman MODULE_ALIAS_RTNL_LWT(MPLS); 304e3e4712eSRoopa Prabhu MODULE_DESCRIPTION("MultiProtocol Label Switching IP Tunnels"); 305e3e4712eSRoopa Prabhu MODULE_LICENSE("GPL v2"); 306