Release 4.11 net/ipv4/xfrm4_input.c
/*
* xfrm4_input.c
*
* Changes:
* YOSHIFUJI Hideaki @USAGI
* Split up af-specific portion
* Derek Atkins <derek@ihtfp.com>
* Add Encapsulation support
*
*/
#include <linux/slab.h>
#include <linux/module.h>
#include <linux/string.h>
#include <linux/netfilter.h>
#include <linux/netfilter_ipv4.h>
#include <net/ip.h>
#include <net/xfrm.h>
int xfrm4_extract_input(struct xfrm_state *x, struct sk_buff *skb)
{
return xfrm4_extract_header(skb);
}
Contributors
Person | Tokens | Prop | Commits | CommitProp |
Herbert Xu | 21 | 100.00% | 1 | 100.00% |
Total | 21 | 100.00% | 1 | 100.00% |
static inline int xfrm4_rcv_encap_finish(struct net *net, struct sock *sk,
struct sk_buff *skb)
{
if (!skb_dst(skb)) {
const struct iphdr *iph = ip_hdr(skb);
if (ip_route_input_noref(skb, iph->daddr, iph->saddr,
iph->tos, skb->dev))
goto drop;
}
return dst_input(skb);
drop:
kfree_skb(skb);
return NET_RX_DROP;
}
Contributors
Person | Tokens | Prop | Commits | CommitProp |
Patrick McHardy | 59 | 69.41% | 1 | 14.29% |
Arnaldo Carvalho de Melo | 11 | 12.94% | 1 | 14.29% |
David S. Miller | 6 | 7.06% | 2 | 28.57% |
Eric W. Biedermann | 5 | 5.88% | 1 | 14.29% |
Eric Dumazet | 3 | 3.53% | 1 | 14.29% |
Ian Morris | 1 | 1.18% | 1 | 14.29% |
Total | 85 | 100.00% | 7 | 100.00% |
int xfrm4_transport_finish(struct sk_buff *skb, int async)
{
struct xfrm_offload *xo = xfrm_offload(skb);
struct iphdr *iph = ip_hdr(skb);
iph->protocol = XFRM_MODE_SKB_CB(skb)->protocol;
#ifndef CONFIG_NETFILTER
if (!async)
return -iph->protocol;
#endif
__skb_push(skb, skb->data - skb_network_header(skb));
iph->tot_len = htons(skb->len);
ip_send_check(iph);
if (xo && (xo->flags & XFRM_GRO)) {
skb_mac_header_rebuild(skb);
return 0;
}
NF_HOOK(NFPROTO_IPV4, NF_INET_PRE_ROUTING,
dev_net(skb->dev), NULL, skb, skb->dev, NULL,
xfrm4_rcv_encap_finish);
return 0;
}
Contributors
Person | Tokens | Prop | Commits | CommitProp |
Herbert Xu | 46 | 32.62% | 3 | 27.27% |
Patrick McHardy | 45 | 31.91% | 2 | 18.18% |
Steffen Klassert | 32 | 22.70% | 1 | 9.09% |
Eric W. Biedermann | 7 | 4.96% | 1 | 9.09% |
Hideaki Yoshifuji / 吉藤英明 | 5 | 3.55% | 1 | 9.09% |
Arnaldo Carvalho de Melo | 3 | 2.13% | 1 | 9.09% |
David S. Miller | 2 | 1.42% | 1 | 9.09% |
Jan Engelhardt | 1 | 0.71% | 1 | 9.09% |
Total | 141 | 100.00% | 11 | 100.00% |
/* If it's a keepalive packet, then just eat it.
* If it's an encapsulated packet, then pass it to the
* IPsec xfrm input.
* Returns 0 if skb passed to xfrm or was dropped.
* Returns >0 if skb should be passed to UDP.
* Returns <0 if skb should be resubmitted (-ret is protocol)
*/
int xfrm4_udp_encap_rcv(struct sock *sk, struct sk_buff *skb)
{
struct udp_sock *up = udp_sk(sk);
struct udphdr *uh;
struct iphdr *iph;
int iphlen, len;
__u8 *udpdata;
__be32 *udpdata32;
__u16 encap_type = up->encap_type;
/* if this is not encapsulated socket, then just return now */
if (!encap_type)
return 1;
/* If this is a paged skb, make sure we pull up
* whatever data we need to look at. */
len = skb->len - sizeof(struct udphdr);
if (!pskb_may_pull(skb, sizeof(struct udphdr) + min(len, 8)))
return 1;
/* Now we can get the pointers */
uh = udp_hdr(skb);
udpdata = (__u8 *)uh + sizeof(struct udphdr);
udpdata32 = (__be32 *)udpdata;
switch (encap_type) {
default:
case UDP_ENCAP_ESPINUDP:
/* Check if this is a keepalive packet. If so, eat it. */
if (len == 1 && udpdata[0] == 0xff) {
goto drop;
} else if (len > sizeof(struct ip_esp_hdr) && udpdata32[0] != 0) {
/* ESP Packet without Non-ESP header */
len = sizeof(struct udphdr);
} else
/* Must be an IKE packet.. pass it through */
return 1;
break;
case UDP_ENCAP_ESPINUDP_NON_IKE:
/* Check if this is a keepalive packet. If so, eat it. */
if (len == 1 && udpdata[0] == 0xff) {
goto drop;
} else if (len > 2 * sizeof(u32) + sizeof(struct ip_esp_hdr) &&
udpdata32[0] == 0 && udpdata32[1] == 0) {
/* ESP Packet with Non-IKE marker */
len = sizeof(struct udphdr) + 2 * sizeof(u32);
} else
/* Must be an IKE packet.. pass it through */
return 1;
break;
}
/* At this point we are sure that this is an ESPinUDP packet,
* so we need to remove 'len' bytes from the packet (the UDP
* header and optional ESP marker bytes) and then modify the
* protocol to ESP, and then call into the transform receiver.
*/
if (skb_unclone(skb, GFP_ATOMIC))
goto drop;
/* Now we can update and verify the packet length... */
iph = ip_hdr(skb);
iphlen = iph->ihl << 2;
iph->tot_len = htons(ntohs(iph->tot_len) - len);
if (skb->len < iphlen + len) {
/* packet is too small!?! */
goto drop;
}
/* pull the data buffer up to the ESP header and set the
* transport header to point to ESP. Keep UDP on the stack
* for later.
*/
__skb_pull(skb, len);
skb_reset_transport_header(skb);
/* process ESP */
return xfrm4_rcv_encap(skb, IPPROTO_ESP, 0, encap_type);
drop:
kfree_skb(skb);
return 0;
}
Contributors
Person | Tokens | Prop | Commits | CommitProp |
James Chapman | 364 | 98.38% | 1 | 25.00% |
Herbert Xu | 5 | 1.35% | 2 | 50.00% |
Pravin B Shelar | 1 | 0.27% | 1 | 25.00% |
Total | 370 | 100.00% | 4 | 100.00% |
int xfrm4_rcv(struct sk_buff *skb)
{
return xfrm4_rcv_spi(skb, ip_hdr(skb)->protocol, 0);
}
Contributors
Person | Tokens | Prop | Commits | CommitProp |
James Chapman | 17 | 68.00% | 1 | 50.00% |
Herbert Xu | 8 | 32.00% | 1 | 50.00% |
Total | 25 | 100.00% | 2 | 100.00% |
EXPORT_SYMBOL(xfrm4_rcv);
Overall Contributors
Person | Tokens | Prop | Commits | CommitProp |
James Chapman | 387 | 57.76% | 1 | 4.00% |
Patrick McHardy | 110 | 16.42% | 2 | 8.00% |
Herbert Xu | 86 | 12.84% | 8 | 32.00% |
Steffen Klassert | 32 | 4.78% | 1 | 4.00% |
Arnaldo Carvalho de Melo | 14 | 2.09% | 2 | 8.00% |
Hideaki Yoshifuji / 吉藤英明 | 12 | 1.79% | 2 | 8.00% |
Eric W. Biedermann | 12 | 1.79% | 2 | 8.00% |
David S. Miller | 8 | 1.19% | 2 | 8.00% |
Tejun Heo | 3 | 0.45% | 1 | 4.00% |
Eric Dumazet | 3 | 0.45% | 1 | 4.00% |
Jan Engelhardt | 1 | 0.15% | 1 | 4.00% |
Pravin B Shelar | 1 | 0.15% | 1 | 4.00% |
Ian Morris | 1 | 0.15% | 1 | 4.00% |
Total | 670 | 100.00% | 25 | 100.00% |
Information contained on this website is for historical information purposes only and does not indicate or represent copyright ownership.