xref: /openbmc/linux/net/ipv4/xfrm4_output.c (revision ca064bd8)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds  * xfrm4_output.c - Common IPsec encapsulation code for IPv4.
31da177e4SLinus Torvalds  * Copyright (c) 2004 Herbert Xu <herbert@gondor.apana.org.au>
41da177e4SLinus Torvalds  *
51da177e4SLinus Torvalds  * This program is free software; you can redistribute it and/or
61da177e4SLinus Torvalds  * modify it under the terms of the GNU General Public License
71da177e4SLinus Torvalds  * as published by the Free Software Foundation; either version
81da177e4SLinus Torvalds  * 2 of the License, or (at your option) any later version.
91da177e4SLinus Torvalds  */
101da177e4SLinus Torvalds 
1109b8f7a9SHerbert Xu #include <linux/if_ether.h>
1209b8f7a9SHerbert Xu #include <linux/kernel.h>
1336cf9acfSHerbert Xu #include <linux/module.h>
141da177e4SLinus Torvalds #include <linux/skbuff.h>
1516a6677fSPatrick McHardy #include <linux/netfilter_ipv4.h>
1636cf9acfSHerbert Xu #include <net/dst.h>
171da177e4SLinus Torvalds #include <net/ip.h>
181da177e4SLinus Torvalds #include <net/xfrm.h>
191da177e4SLinus Torvalds #include <net/icmp.h>
201da177e4SLinus Torvalds 
211da177e4SLinus Torvalds static int xfrm4_tunnel_check_size(struct sk_buff *skb)
221da177e4SLinus Torvalds {
231da177e4SLinus Torvalds 	int mtu, ret = 0;
241da177e4SLinus Torvalds 
251da177e4SLinus Torvalds 	if (IPCB(skb)->flags & IPSKB_XFRM_TUNNEL_SIZE)
261da177e4SLinus Torvalds 		goto out;
271da177e4SLinus Torvalds 
2860ff7467SWANG Cong 	if (!(ip_hdr(skb)->frag_off & htons(IP_DF)) || skb->ignore_df)
291da177e4SLinus Torvalds 		goto out;
301da177e4SLinus Torvalds 
315a25cf1eSHannes Frederic Sowa 	mtu = dst_mtu(skb_dst(skb));
321da177e4SLinus Torvalds 	if (skb->len > mtu) {
33ca064bd8SSteffen Klassert 		skb->protocol = htons(ETH_P_IP);
34ca064bd8SSteffen Klassert 
35b00897b8SSteffen Klassert 		if (skb->sk)
36628e341fSHannes Frederic Sowa 			xfrm_local_error(skb, mtu);
37b00897b8SSteffen Klassert 		else
38b00897b8SSteffen Klassert 			icmp_send(skb, ICMP_DEST_UNREACH,
39b00897b8SSteffen Klassert 				  ICMP_FRAG_NEEDED, htonl(mtu));
401da177e4SLinus Torvalds 		ret = -EMSGSIZE;
411da177e4SLinus Torvalds 	}
421da177e4SLinus Torvalds out:
431da177e4SLinus Torvalds 	return ret;
441da177e4SLinus Torvalds }
451da177e4SLinus Torvalds 
4636cf9acfSHerbert Xu int xfrm4_extract_output(struct xfrm_state *x, struct sk_buff *skb)
471da177e4SLinus Torvalds {
481da177e4SLinus Torvalds 	int err;
491da177e4SLinus Torvalds 
501da177e4SLinus Torvalds 	err = xfrm4_tunnel_check_size(skb);
511da177e4SLinus Torvalds 	if (err)
5236cf9acfSHerbert Xu 		return err;
5336cf9acfSHerbert Xu 
5460d5fcfbSHerbert Xu 	XFRM_MODE_SKB_CB(skb)->protocol = ip_hdr(skb)->protocol;
5560d5fcfbSHerbert Xu 
5636cf9acfSHerbert Xu 	return xfrm4_extract_header(skb);
571da177e4SLinus Torvalds }
581da177e4SLinus Torvalds 
5936cf9acfSHerbert Xu int xfrm4_prepare_output(struct xfrm_state *x, struct sk_buff *skb)
6036cf9acfSHerbert Xu {
6136cf9acfSHerbert Xu 	int err;
6236cf9acfSHerbert Xu 
63df9dcb45SKazunori MIYAZAWA 	err = xfrm_inner_extract_output(x, skb);
6436cf9acfSHerbert Xu 	if (err)
6536cf9acfSHerbert Xu 		return err;
6636cf9acfSHerbert Xu 
675596732fSSteffen Klassert 	IPCB(skb)->flags |= IPSKB_XFRM_TUNNEL_SIZE;
68044a832aSSteffen Klassert 	skb->protocol = htons(ETH_P_IP);
6936cf9acfSHerbert Xu 
7036cf9acfSHerbert Xu 	return x->outer_mode->output2(x, skb);
7136cf9acfSHerbert Xu }
7236cf9acfSHerbert Xu EXPORT_SYMBOL(xfrm4_prepare_output);
7336cf9acfSHerbert Xu 
747026b1ddSDavid Miller int xfrm4_output_finish(struct sock *sk, struct sk_buff *skb)
7509b8f7a9SHerbert Xu {
765596732fSSteffen Klassert 	memset(IPCB(skb), 0, sizeof(*IPCB(skb)));
77862b82c6SHerbert Xu 
785596732fSSteffen Klassert #ifdef CONFIG_NETFILTER
79862b82c6SHerbert Xu 	IPCB(skb)->flags |= IPSKB_XFRM_TRANSFORMED;
8009b8f7a9SHerbert Xu #endif
8109b8f7a9SHerbert Xu 
827026b1ddSDavid Miller 	return xfrm_output(sk, skb);
8309b8f7a9SHerbert Xu }
8409b8f7a9SHerbert Xu 
857026b1ddSDavid Miller static int __xfrm4_output(struct sock *sk, struct sk_buff *skb)
865596732fSSteffen Klassert {
875596732fSSteffen Klassert 	struct xfrm_state *x = skb_dst(skb)->xfrm;
885596732fSSteffen Klassert 
895596732fSSteffen Klassert #ifdef CONFIG_NETFILTER
905596732fSSteffen Klassert 	if (!x) {
915596732fSSteffen Klassert 		IPCB(skb)->flags |= IPSKB_REROUTED;
927026b1ddSDavid Miller 		return dst_output_sk(sk, skb);
935596732fSSteffen Klassert 	}
945596732fSSteffen Klassert #endif
955596732fSSteffen Klassert 
967026b1ddSDavid Miller 	return x->outer_mode->afinfo->output_finish(sk, skb);
975596732fSSteffen Klassert }
985596732fSSteffen Klassert 
99aad88724SEric Dumazet int xfrm4_output(struct sock *sk, struct sk_buff *skb)
10016a6677fSPatrick McHardy {
1017026b1ddSDavid Miller 	return NF_HOOK_COND(NFPROTO_IPV4, NF_INET_POST_ROUTING, sk, skb,
1025596732fSSteffen Klassert 			    NULL, skb_dst(skb)->dev, __xfrm4_output,
10348d5cad8SPatrick McHardy 			    !(IPCB(skb)->flags & IPSKB_REROUTED));
10416a6677fSPatrick McHardy }
105628e341fSHannes Frederic Sowa 
106628e341fSHannes Frederic Sowa void xfrm4_local_error(struct sk_buff *skb, u32 mtu)
107628e341fSHannes Frederic Sowa {
108628e341fSHannes Frederic Sowa 	struct iphdr *hdr;
109628e341fSHannes Frederic Sowa 
110628e341fSHannes Frederic Sowa 	hdr = skb->encapsulation ? inner_ip_hdr(skb) : ip_hdr(skb);
111628e341fSHannes Frederic Sowa 	ip_local_error(skb->sk, EMSGSIZE, hdr->daddr,
112628e341fSHannes Frederic Sowa 		       inet_sk(skb->sk)->inet_dport, mtu);
113628e341fSHannes Frederic Sowa }
114