xref: /openbmc/linux/net/ipv4/xfrm4_output.c (revision b59f45d0)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds  * xfrm4_output.c - Common IPsec encapsulation code for IPv4.
31da177e4SLinus Torvalds  * Copyright (c) 2004 Herbert Xu <herbert@gondor.apana.org.au>
41da177e4SLinus Torvalds  *
51da177e4SLinus Torvalds  * This program is free software; you can redistribute it and/or
61da177e4SLinus Torvalds  * modify it under the terms of the GNU General Public License
71da177e4SLinus Torvalds  * as published by the Free Software Foundation; either version
81da177e4SLinus Torvalds  * 2 of the License, or (at your option) any later version.
91da177e4SLinus Torvalds  */
101da177e4SLinus Torvalds 
1116a6677fSPatrick McHardy #include <linux/compiler.h>
121da177e4SLinus Torvalds #include <linux/skbuff.h>
131da177e4SLinus Torvalds #include <linux/spinlock.h>
1416a6677fSPatrick McHardy #include <linux/netfilter_ipv4.h>
151da177e4SLinus Torvalds #include <net/ip.h>
161da177e4SLinus Torvalds #include <net/xfrm.h>
171da177e4SLinus Torvalds #include <net/icmp.h>
181da177e4SLinus Torvalds 
191da177e4SLinus Torvalds static int xfrm4_tunnel_check_size(struct sk_buff *skb)
201da177e4SLinus Torvalds {
211da177e4SLinus Torvalds 	int mtu, ret = 0;
221da177e4SLinus Torvalds 	struct dst_entry *dst;
231da177e4SLinus Torvalds 	struct iphdr *iph = skb->nh.iph;
241da177e4SLinus Torvalds 
251da177e4SLinus Torvalds 	if (IPCB(skb)->flags & IPSKB_XFRM_TUNNEL_SIZE)
261da177e4SLinus Torvalds 		goto out;
271da177e4SLinus Torvalds 
281da177e4SLinus Torvalds 	IPCB(skb)->flags |= IPSKB_XFRM_TUNNEL_SIZE;
291da177e4SLinus Torvalds 
301da177e4SLinus Torvalds 	if (!(iph->frag_off & htons(IP_DF)) || skb->local_df)
311da177e4SLinus Torvalds 		goto out;
321da177e4SLinus Torvalds 
331da177e4SLinus Torvalds 	dst = skb->dst;
341da177e4SLinus Torvalds 	mtu = dst_mtu(dst);
351da177e4SLinus Torvalds 	if (skb->len > mtu) {
361da177e4SLinus Torvalds 		icmp_send(skb, ICMP_DEST_UNREACH, ICMP_FRAG_NEEDED, htonl(mtu));
371da177e4SLinus Torvalds 		ret = -EMSGSIZE;
381da177e4SLinus Torvalds 	}
391da177e4SLinus Torvalds out:
401da177e4SLinus Torvalds 	return ret;
411da177e4SLinus Torvalds }
421da177e4SLinus Torvalds 
4316a6677fSPatrick McHardy static int xfrm4_output_one(struct sk_buff *skb)
441da177e4SLinus Torvalds {
451da177e4SLinus Torvalds 	struct dst_entry *dst = skb->dst;
461da177e4SLinus Torvalds 	struct xfrm_state *x = dst->xfrm;
471da177e4SLinus Torvalds 	int err;
481da177e4SLinus Torvalds 
491da177e4SLinus Torvalds 	if (skb->ip_summed == CHECKSUM_HW) {
501da177e4SLinus Torvalds 		err = skb_checksum_help(skb, 0);
511da177e4SLinus Torvalds 		if (err)
521da177e4SLinus Torvalds 			goto error_nolock;
531da177e4SLinus Torvalds 	}
541da177e4SLinus Torvalds 
551da177e4SLinus Torvalds 	if (x->props.mode) {
561da177e4SLinus Torvalds 		err = xfrm4_tunnel_check_size(skb);
571da177e4SLinus Torvalds 		if (err)
581da177e4SLinus Torvalds 			goto error_nolock;
591da177e4SLinus Torvalds 	}
601da177e4SLinus Torvalds 
6116a6677fSPatrick McHardy 	do {
621da177e4SLinus Torvalds 		spin_lock_bh(&x->lock);
631da177e4SLinus Torvalds 		err = xfrm_state_check(x, skb);
641da177e4SLinus Torvalds 		if (err)
651da177e4SLinus Torvalds 			goto error;
661da177e4SLinus Torvalds 
67b59f45d0SHerbert Xu 		err = x->mode->output(skb);
68b59f45d0SHerbert Xu 		if (err)
69b59f45d0SHerbert Xu 			goto error;
701da177e4SLinus Torvalds 
711da177e4SLinus Torvalds 		err = x->type->output(x, skb);
721da177e4SLinus Torvalds 		if (err)
731da177e4SLinus Torvalds 			goto error;
741da177e4SLinus Torvalds 
751da177e4SLinus Torvalds 		x->curlft.bytes += skb->len;
761da177e4SLinus Torvalds 		x->curlft.packets++;
771da177e4SLinus Torvalds 
781da177e4SLinus Torvalds 		spin_unlock_bh(&x->lock);
791da177e4SLinus Torvalds 
801da177e4SLinus Torvalds 		if (!(skb->dst = dst_pop(dst))) {
811da177e4SLinus Torvalds 			err = -EHOSTUNREACH;
821da177e4SLinus Torvalds 			goto error_nolock;
831da177e4SLinus Torvalds 		}
8416a6677fSPatrick McHardy 		dst = skb->dst;
8516a6677fSPatrick McHardy 		x = dst->xfrm;
8616a6677fSPatrick McHardy 	} while (x && !x->props.mode);
8716a6677fSPatrick McHardy 
883e3850e9SPatrick McHardy 	IPCB(skb)->flags |= IPSKB_XFRM_TRANSFORMED;
8916a6677fSPatrick McHardy 	err = 0;
901da177e4SLinus Torvalds 
911da177e4SLinus Torvalds out_exit:
921da177e4SLinus Torvalds 	return err;
931da177e4SLinus Torvalds error:
941da177e4SLinus Torvalds 	spin_unlock_bh(&x->lock);
951da177e4SLinus Torvalds error_nolock:
961da177e4SLinus Torvalds 	kfree_skb(skb);
971da177e4SLinus Torvalds 	goto out_exit;
981da177e4SLinus Torvalds }
9916a6677fSPatrick McHardy 
10048d5cad8SPatrick McHardy static int xfrm4_output_finish(struct sk_buff *skb)
10116a6677fSPatrick McHardy {
10216a6677fSPatrick McHardy 	int err;
10316a6677fSPatrick McHardy 
10448d5cad8SPatrick McHardy #ifdef CONFIG_NETFILTER
10548d5cad8SPatrick McHardy 	if (!skb->dst->xfrm) {
10648d5cad8SPatrick McHardy 		IPCB(skb)->flags |= IPSKB_REROUTED;
10748d5cad8SPatrick McHardy 		return dst_output(skb);
10848d5cad8SPatrick McHardy 	}
10948d5cad8SPatrick McHardy #endif
11016a6677fSPatrick McHardy 	while (likely((err = xfrm4_output_one(skb)) == 0)) {
11116a6677fSPatrick McHardy 		nf_reset(skb);
11216a6677fSPatrick McHardy 
11316a6677fSPatrick McHardy 		err = nf_hook(PF_INET, NF_IP_LOCAL_OUT, &skb, NULL,
11416a6677fSPatrick McHardy 			      skb->dst->dev, dst_output);
11516a6677fSPatrick McHardy 		if (unlikely(err != 1))
11616a6677fSPatrick McHardy 			break;
11716a6677fSPatrick McHardy 
11816a6677fSPatrick McHardy 		if (!skb->dst->xfrm)
11916a6677fSPatrick McHardy 			return dst_output(skb);
12016a6677fSPatrick McHardy 
12116a6677fSPatrick McHardy 		err = nf_hook(PF_INET, NF_IP_POST_ROUTING, &skb, NULL,
12216a6677fSPatrick McHardy 			      skb->dst->dev, xfrm4_output_finish);
12316a6677fSPatrick McHardy 		if (unlikely(err != 1))
12416a6677fSPatrick McHardy 			break;
12516a6677fSPatrick McHardy 	}
12616a6677fSPatrick McHardy 
12716a6677fSPatrick McHardy 	return err;
12816a6677fSPatrick McHardy }
12916a6677fSPatrick McHardy 
13016a6677fSPatrick McHardy int xfrm4_output(struct sk_buff *skb)
13116a6677fSPatrick McHardy {
13248d5cad8SPatrick McHardy 	return NF_HOOK_COND(PF_INET, NF_IP_POST_ROUTING, skb, NULL, skb->dst->dev,
13348d5cad8SPatrick McHardy 			    xfrm4_output_finish,
13448d5cad8SPatrick McHardy 			    !(IPCB(skb)->flags & IPSKB_REROUTED));
13516a6677fSPatrick McHardy }
136