2005-04-16 15:20:36 -07:00
/*
* xfrm6_input . c : based on net / ipv4 / xfrm4_input . c
*
* Authors :
* Mitsuru KANDA @ USAGI
* Kazunori MIYAZAWA @ USAGI
* Kunihiro Ishiguro < kunihiro @ ipinfusion . com >
* YOSHIFUJI Hideaki @ USAGI
* IPv6 support
*/
# include <linux/module.h>
# include <linux/string.h>
2006-01-06 23:03:34 -08:00
# include <linux/netfilter.h>
# include <linux/netfilter_ipv6.h>
2005-04-16 15:20:36 -07:00
# include <net/ipv6.h>
# include <net/xfrm.h>
2007-11-13 21:41:28 -08:00
int xfrm6_extract_input ( struct xfrm_state * x , struct sk_buff * skb )
{
return xfrm6_extract_header ( skb ) ;
}
2007-10-17 21:29:25 -07:00
int xfrm6_rcv_spi ( struct sk_buff * skb , int nexthdr , __be32 spi )
2005-04-16 15:20:36 -07:00
{
2007-12-03 22:54:12 -08:00
XFRM_SPI_SKB_CB ( skb ) - > family = AF_INET6 ;
2007-11-13 21:44:23 -08:00
XFRM_SPI_SKB_CB ( skb ) - > daddroff = offsetof ( struct ipv6hdr , daddr ) ;
return xfrm_input ( skb , nexthdr , spi , 0 ) ;
}
EXPORT_SYMBOL ( xfrm6_rcv_spi ) ;
2006-01-06 23:03:34 -08:00
2007-11-13 21:44:23 -08:00
int xfrm6_transport_finish ( struct sk_buff * skb , int async )
{
2007-11-19 18:47:58 -08:00
skb_network_header ( skb ) [ IP6CB ( skb ) - > nhoff ] =
XFRM_MODE_SKB_CB ( skb ) - > protocol ;
2007-12-30 21:10:14 -08:00
# ifndef CONFIG_NETFILTER
if ( ! async )
return 1 ;
# endif
2007-11-13 21:44:23 -08:00
ipv6_hdr ( skb ) - > payload_len = htons ( skb - > len ) ;
__skb_push ( skb , skb - > data - skb_network_header ( skb ) ) ;
2006-01-06 23:03:34 -08:00
2010-03-23 04:09:07 +01:00
NF_HOOK ( NFPROTO_IPV6 , NF_INET_PRE_ROUTING , skb , skb - > dev , NULL ,
2007-11-13 21:44:23 -08:00
ip6_rcv_finish ) ;
return - 1 ;
2005-04-16 15:20:36 -07:00
}
2007-10-15 12:50:28 -07:00
int xfrm6_rcv ( struct sk_buff * skb )
2005-04-16 15:20:36 -07:00
{
2007-10-17 21:29:25 -07:00
return xfrm6_rcv_spi ( skb , skb_network_header ( skb ) [ IP6CB ( skb ) - > nhoff ] ,
0 ) ;
2005-04-16 15:20:36 -07:00
}
2006-08-23 18:08:21 -07:00
2007-02-22 22:05:40 +09:00
EXPORT_SYMBOL ( xfrm6_rcv ) ;
2006-08-23 18:08:21 -07:00
int xfrm6_input_addr ( struct sk_buff * skb , xfrm_address_t * daddr ,
xfrm_address_t * saddr , u8 proto )
{
2008-11-25 17:59:52 -08:00
struct net * net = dev_net ( skb - > dev ) ;
2007-02-09 23:24:49 +09:00
struct xfrm_state * x = NULL ;
2006-08-23 18:08:21 -07:00
int i = 0 ;
2007-12-20 20:41:57 -08:00
/* Allocate new secpath or COW existing one. */
if ( ! skb - > sp | | atomic_read ( & skb - > sp - > refcnt ) ! = 1 ) {
struct sec_path * sp ;
sp = secpath_dup ( skb - > sp ) ;
if ( ! sp ) {
2008-11-25 17:59:52 -08:00
XFRM_INC_STATS ( net , LINUX_MIB_XFRMINERROR ) ;
2007-12-20 20:41:57 -08:00
goto drop ;
}
if ( skb - > sp )
secpath_put ( skb - > sp ) ;
skb - > sp = sp ;
}
if ( 1 + skb - > sp - > len = = XFRM_MAX_DEPTH ) {
2008-11-25 17:59:52 -08:00
XFRM_INC_STATS ( net , LINUX_MIB_XFRMINBUFFERERROR ) ;
2007-12-20 20:41:57 -08:00
goto drop ;
}
2006-08-23 18:08:21 -07:00
for ( i = 0 ; i < 3 ; i + + ) {
xfrm_address_t * dst , * src ;
2008-02-19 17:24:33 +09:00
2006-08-23 18:08:21 -07:00
switch ( i ) {
case 0 :
dst = daddr ;
src = saddr ;
break ;
case 1 :
/* lookup state with wild-card source address */
dst = daddr ;
2008-02-19 17:24:33 +09:00
src = ( xfrm_address_t * ) & in6addr_any ;
2006-08-23 18:08:21 -07:00
break ;
default :
2007-02-09 23:24:49 +09:00
/* lookup state with wild-card addresses */
2008-02-19 17:24:33 +09:00
dst = ( xfrm_address_t * ) & in6addr_any ;
src = ( xfrm_address_t * ) & in6addr_any ;
2006-08-23 18:08:21 -07:00
break ;
2007-02-09 23:24:49 +09:00
}
2006-08-23 18:08:21 -07:00
2010-02-22 16:20:22 -08:00
x = xfrm_state_lookup_byaddr ( net , skb - > mark , dst , src , proto , AF_INET6 ) ;
2006-08-23 18:08:21 -07:00
if ( ! x )
continue ;
spin_lock ( & x - > lock ) ;
2008-02-19 17:24:33 +09:00
if ( ( ! i | | ( x - > props . flags & XFRM_STATE_WILDRECV ) ) & &
likely ( x - > km . state = = XFRM_STATE_VALID ) & &
! xfrm_state_check_expire ( x ) ) {
2006-08-23 18:08:21 -07:00
spin_unlock ( & x - > lock ) ;
2008-02-19 17:24:33 +09:00
if ( x - > type - > input ( x , skb ) > 0 ) {
/* found a valid state */
break ;
}
} else
2006-08-23 18:08:21 -07:00
spin_unlock ( & x - > lock ) ;
2008-02-19 17:24:33 +09:00
xfrm_state_put ( x ) ;
x = NULL ;
2006-08-23 18:08:21 -07:00
}
2007-12-20 20:41:57 -08:00
if ( ! x ) {
2008-11-25 17:59:52 -08:00
XFRM_INC_STATS ( net , LINUX_MIB_XFRMINNOSTATES ) ;
2007-12-21 14:58:11 -08:00
xfrm_audit_state_notfound_simple ( skb , AF_INET6 ) ;
2006-08-23 18:08:21 -07:00
goto drop ;
}
2007-12-20 20:41:57 -08:00
skb - > sp - > xvec [ skb - > sp - > len + + ] = x ;
spin_lock ( & x - > lock ) ;
2006-08-23 18:08:21 -07:00
2007-12-20 20:41:57 -08:00
x - > curlft . bytes + = skb - > len ;
x - > curlft . packets + + ;
spin_unlock ( & x - > lock ) ;
2006-08-23 18:08:21 -07:00
return 1 ;
2007-12-20 20:41:57 -08:00
2006-08-23 18:08:21 -07:00
drop :
return - 1 ;
}
2007-02-22 22:05:40 +09:00
EXPORT_SYMBOL ( xfrm6_input_addr ) ;