diff options
Diffstat (limited to 'net/xfrm/xfrm_interface.c')
| -rw-r--r-- | net/xfrm/xfrm_interface.c | 136 | 
1 files changed, 117 insertions, 19 deletions
| diff --git a/net/xfrm/xfrm_interface.c b/net/xfrm/xfrm_interface.c index b615729812e5..eb8181987620 100644 --- a/net/xfrm/xfrm_interface.c +++ b/net/xfrm/xfrm_interface.c @@ -48,21 +48,30 @@ static int xfrmi_dev_init(struct net_device *dev);  static void xfrmi_dev_setup(struct net_device *dev);  static struct rtnl_link_ops xfrmi_link_ops __read_mostly;  static unsigned int xfrmi_net_id __read_mostly; +static const struct net_device_ops xfrmi_netdev_ops; + +#define XFRMI_HASH_BITS	8 +#define XFRMI_HASH_SIZE	BIT(XFRMI_HASH_BITS)  struct xfrmi_net {  	/* lists for storing interfaces in use */ -	struct xfrm_if __rcu *xfrmi[1]; +	struct xfrm_if __rcu *xfrmi[XFRMI_HASH_SIZE];  };  #define for_each_xfrmi_rcu(start, xi) \  	for (xi = rcu_dereference(start); xi; xi = rcu_dereference(xi->next)) +static u32 xfrmi_hash(u32 if_id) +{ +	return hash_32(if_id, XFRMI_HASH_BITS); +} +  static struct xfrm_if *xfrmi_lookup(struct net *net, struct xfrm_state *x)  {  	struct xfrmi_net *xfrmn = net_generic(net, xfrmi_net_id);  	struct xfrm_if *xi; -	for_each_xfrmi_rcu(xfrmn->xfrmi[0], xi) { +	for_each_xfrmi_rcu(xfrmn->xfrmi[xfrmi_hash(x->if_id)], xi) {  		if (x->if_id == xi->p.if_id &&  		    (xi->dev->flags & IFF_UP))  			return xi; @@ -74,8 +83,7 @@ static struct xfrm_if *xfrmi_lookup(struct net *net, struct xfrm_state *x)  static struct xfrm_if *xfrmi_decode_session(struct sk_buff *skb,  					    unsigned short family)  { -	struct xfrmi_net *xfrmn; -	struct xfrm_if *xi; +	struct net_device *dev;  	int ifindex = 0;  	if (!secpath_exists(skb) || !skb->dev) @@ -89,23 +97,26 @@ static struct xfrm_if *xfrmi_decode_session(struct sk_buff *skb,  		ifindex = inet_sdif(skb);  		break;  	} -	if (!ifindex) -		ifindex = skb->dev->ifindex; -	xfrmn = net_generic(xs_net(xfrm_input_state(skb)), xfrmi_net_id); +	if (ifindex) { +		struct net *net = xs_net(xfrm_input_state(skb)); -	for_each_xfrmi_rcu(xfrmn->xfrmi[0], xi) { -		if (ifindex == xi->dev->ifindex && -			(xi->dev->flags & IFF_UP)) -				return xi; +		dev = dev_get_by_index_rcu(net, ifindex); +	} else { +		dev = skb->dev;  	} -	return NULL; +	if (!dev || !(dev->flags & IFF_UP)) +		return NULL; +	if (dev->netdev_ops != &xfrmi_netdev_ops) +		return NULL; + +	return netdev_priv(dev);  }  static void xfrmi_link(struct xfrmi_net *xfrmn, struct xfrm_if *xi)  { -	struct xfrm_if __rcu **xip = &xfrmn->xfrmi[0]; +	struct xfrm_if __rcu **xip = &xfrmn->xfrmi[xfrmi_hash(xi->p.if_id)];  	rcu_assign_pointer(xi->next , rtnl_dereference(*xip));  	rcu_assign_pointer(*xip, xi); @@ -116,7 +127,7 @@ static void xfrmi_unlink(struct xfrmi_net *xfrmn, struct xfrm_if *xi)  	struct xfrm_if __rcu **xip;  	struct xfrm_if *iter; -	for (xip = &xfrmn->xfrmi[0]; +	for (xip = &xfrmn->xfrmi[xfrmi_hash(xi->p.if_id)];  	     (iter = rtnl_dereference(*xip)) != NULL;  	     xip = &iter->next) {  		if (xi == iter) { @@ -160,7 +171,7 @@ static struct xfrm_if *xfrmi_locate(struct net *net, struct xfrm_if_parms *p)  	struct xfrm_if *xi;  	struct xfrmi_net *xfrmn = net_generic(net, xfrmi_net_id); -	for (xip = &xfrmn->xfrmi[0]; +	for (xip = &xfrmn->xfrmi[xfrmi_hash(p->if_id)];  	     (xi = rtnl_dereference(*xip)) != NULL;  	     xip = &xi->next)  		if (xi->p.if_id == p->if_id) @@ -760,11 +771,14 @@ static void __net_exit xfrmi_exit_batch_net(struct list_head *net_exit_list)  		struct xfrmi_net *xfrmn = net_generic(net, xfrmi_net_id);  		struct xfrm_if __rcu **xip;  		struct xfrm_if *xi; +		int i; -		for (xip = &xfrmn->xfrmi[0]; -		     (xi = rtnl_dereference(*xip)) != NULL; -		     xip = &xi->next) -			unregister_netdevice_queue(xi->dev, &list); +		for (i = 0; i < XFRMI_HASH_SIZE; i++) { +			for (xip = &xfrmn->xfrmi[i]; +			     (xi = rtnl_dereference(*xip)) != NULL; +			     xip = &xi->next) +				unregister_netdevice_queue(xi->dev, &list); +		}  	}  	unregister_netdevice_many(&list);  	rtnl_unlock(); @@ -800,6 +814,33 @@ static struct xfrm6_protocol xfrmi_ipcomp6_protocol __read_mostly = {  	.priority	=	10,  }; +#if IS_REACHABLE(CONFIG_INET6_XFRM_TUNNEL) +static int xfrmi6_rcv_tunnel(struct sk_buff *skb) +{ +	const xfrm_address_t *saddr; +	__be32 spi; + +	saddr = (const xfrm_address_t *)&ipv6_hdr(skb)->saddr; +	spi = xfrm6_tunnel_spi_lookup(dev_net(skb->dev), saddr); + +	return xfrm6_rcv_spi(skb, IPPROTO_IPV6, spi, NULL); +} + +static struct xfrm6_tunnel xfrmi_ipv6_handler __read_mostly = { +	.handler	=	xfrmi6_rcv_tunnel, +	.cb_handler	=	xfrmi_rcv_cb, +	.err_handler	=	xfrmi6_err, +	.priority	=	-1, +}; + +static struct xfrm6_tunnel xfrmi_ip6ip_handler __read_mostly = { +	.handler	=	xfrmi6_rcv_tunnel, +	.cb_handler	=	xfrmi_rcv_cb, +	.err_handler	=	xfrmi6_err, +	.priority	=	-1, +}; +#endif +  static struct xfrm4_protocol xfrmi_esp4_protocol __read_mostly = {  	.handler	=	xfrm4_rcv,  	.input_handler	=	xfrm_input, @@ -824,6 +865,27 @@ static struct xfrm4_protocol xfrmi_ipcomp4_protocol __read_mostly = {  	.priority	=	10,  }; +#if IS_REACHABLE(CONFIG_INET_XFRM_TUNNEL) +static int xfrmi4_rcv_tunnel(struct sk_buff *skb) +{ +	return xfrm4_rcv_spi(skb, IPPROTO_IPIP, ip_hdr(skb)->saddr); +} + +static struct xfrm_tunnel xfrmi_ipip_handler __read_mostly = { +	.handler	=	xfrmi4_rcv_tunnel, +	.cb_handler	=	xfrmi_rcv_cb, +	.err_handler	=	xfrmi4_err, +	.priority	=	-1, +}; + +static struct xfrm_tunnel xfrmi_ipip6_handler __read_mostly = { +	.handler	=	xfrmi4_rcv_tunnel, +	.cb_handler	=	xfrmi_rcv_cb, +	.err_handler	=	xfrmi4_err, +	.priority	=	-1, +}; +#endif +  static int __init xfrmi4_init(void)  {  	int err; @@ -837,9 +899,23 @@ static int __init xfrmi4_init(void)  	err = xfrm4_protocol_register(&xfrmi_ipcomp4_protocol, IPPROTO_COMP);  	if (err < 0)  		goto xfrm_proto_comp_failed; +#if IS_REACHABLE(CONFIG_INET_XFRM_TUNNEL) +	err = xfrm4_tunnel_register(&xfrmi_ipip_handler, AF_INET); +	if (err < 0) +		goto xfrm_tunnel_ipip_failed; +	err = xfrm4_tunnel_register(&xfrmi_ipip6_handler, AF_INET6); +	if (err < 0) +		goto xfrm_tunnel_ipip6_failed; +#endif  	return 0; +#if IS_REACHABLE(CONFIG_INET_XFRM_TUNNEL) +xfrm_tunnel_ipip6_failed: +	xfrm4_tunnel_deregister(&xfrmi_ipip_handler, AF_INET); +xfrm_tunnel_ipip_failed: +	xfrm4_protocol_deregister(&xfrmi_ipcomp4_protocol, IPPROTO_COMP); +#endif  xfrm_proto_comp_failed:  	xfrm4_protocol_deregister(&xfrmi_ah4_protocol, IPPROTO_AH);  xfrm_proto_ah_failed: @@ -850,6 +926,10 @@ xfrm_proto_esp_failed:  static void xfrmi4_fini(void)  { +#if IS_REACHABLE(CONFIG_INET_XFRM_TUNNEL) +	xfrm4_tunnel_deregister(&xfrmi_ipip6_handler, AF_INET6); +	xfrm4_tunnel_deregister(&xfrmi_ipip_handler, AF_INET); +#endif  	xfrm4_protocol_deregister(&xfrmi_ipcomp4_protocol, IPPROTO_COMP);  	xfrm4_protocol_deregister(&xfrmi_ah4_protocol, IPPROTO_AH);  	xfrm4_protocol_deregister(&xfrmi_esp4_protocol, IPPROTO_ESP); @@ -868,9 +948,23 @@ static int __init xfrmi6_init(void)  	err = xfrm6_protocol_register(&xfrmi_ipcomp6_protocol, IPPROTO_COMP);  	if (err < 0)  		goto xfrm_proto_comp_failed; +#if IS_REACHABLE(CONFIG_INET6_XFRM_TUNNEL) +	err = xfrm6_tunnel_register(&xfrmi_ipv6_handler, AF_INET6); +	if (err < 0) +		goto xfrm_tunnel_ipv6_failed; +	err = xfrm6_tunnel_register(&xfrmi_ip6ip_handler, AF_INET); +	if (err < 0) +		goto xfrm_tunnel_ip6ip_failed; +#endif  	return 0; +#if IS_REACHABLE(CONFIG_INET6_XFRM_TUNNEL) +xfrm_tunnel_ip6ip_failed: +	xfrm6_tunnel_deregister(&xfrmi_ipv6_handler, AF_INET6); +xfrm_tunnel_ipv6_failed: +	xfrm6_protocol_deregister(&xfrmi_ipcomp6_protocol, IPPROTO_COMP); +#endif  xfrm_proto_comp_failed:  	xfrm6_protocol_deregister(&xfrmi_ah6_protocol, IPPROTO_AH);  xfrm_proto_ah_failed: @@ -881,6 +975,10 @@ xfrm_proto_esp_failed:  static void xfrmi6_fini(void)  { +#if IS_REACHABLE(CONFIG_INET6_XFRM_TUNNEL) +	xfrm6_tunnel_deregister(&xfrmi_ip6ip_handler, AF_INET); +	xfrm6_tunnel_deregister(&xfrmi_ipv6_handler, AF_INET6); +#endif  	xfrm6_protocol_deregister(&xfrmi_ipcomp6_protocol, IPPROTO_COMP);  	xfrm6_protocol_deregister(&xfrmi_ah6_protocol, IPPROTO_AH);  	xfrm6_protocol_deregister(&xfrmi_esp6_protocol, IPPROTO_ESP); | 
