|
48 | 48 | #ifdef CONFIG_IPV6_SEG6_HMAC
|
49 | 49 | #include <net/seg6_hmac.h>
|
50 | 50 | #endif
|
| 51 | +#include <net/rpl.h> |
51 | 52 |
|
52 | 53 | #include <linux/uaccess.h>
|
53 | 54 |
|
@@ -468,6 +469,195 @@ static int ipv6_srh_rcv(struct sk_buff *skb)
|
468 | 469 | return -1;
|
469 | 470 | }
|
470 | 471 |
|
| 472 | +static int ipv6_rpl_srh_rcv(struct sk_buff *skb) |
| 473 | +{ |
| 474 | + struct ipv6_rpl_sr_hdr *hdr, *ohdr, *chdr; |
| 475 | + struct inet6_skb_parm *opt = IP6CB(skb); |
| 476 | + struct net *net = dev_net(skb->dev); |
| 477 | + struct inet6_dev *idev; |
| 478 | + struct ipv6hdr *oldhdr; |
| 479 | + struct in6_addr addr; |
| 480 | + unsigned char *buf; |
| 481 | + int accept_rpl_seg; |
| 482 | + int i, err; |
| 483 | + u64 n = 0; |
| 484 | + u32 r; |
| 485 | + |
| 486 | + idev = __in6_dev_get(skb->dev); |
| 487 | + |
| 488 | + accept_rpl_seg = net->ipv6.devconf_all->rpl_seg_enabled; |
| 489 | + if (accept_rpl_seg > idev->cnf.rpl_seg_enabled) |
| 490 | + accept_rpl_seg = idev->cnf.rpl_seg_enabled; |
| 491 | + |
| 492 | + if (!accept_rpl_seg) { |
| 493 | + kfree_skb(skb); |
| 494 | + return -1; |
| 495 | + } |
| 496 | + |
| 497 | +looped_back: |
| 498 | + hdr = (struct ipv6_rpl_sr_hdr *)skb_transport_header(skb); |
| 499 | + |
| 500 | + if (hdr->segments_left == 0) { |
| 501 | + if (hdr->nexthdr == NEXTHDR_IPV6) { |
| 502 | + int offset = (hdr->hdrlen + 1) << 3; |
| 503 | + |
| 504 | + skb_postpull_rcsum(skb, skb_network_header(skb), |
| 505 | + skb_network_header_len(skb)); |
| 506 | + |
| 507 | + if (!pskb_pull(skb, offset)) { |
| 508 | + kfree_skb(skb); |
| 509 | + return -1; |
| 510 | + } |
| 511 | + skb_postpull_rcsum(skb, skb_transport_header(skb), |
| 512 | + offset); |
| 513 | + |
| 514 | + skb_reset_network_header(skb); |
| 515 | + skb_reset_transport_header(skb); |
| 516 | + skb->encapsulation = 0; |
| 517 | + |
| 518 | + __skb_tunnel_rx(skb, skb->dev, net); |
| 519 | + |
| 520 | + netif_rx(skb); |
| 521 | + return -1; |
| 522 | + } |
| 523 | + |
| 524 | + opt->srcrt = skb_network_header_len(skb); |
| 525 | + opt->lastopt = opt->srcrt; |
| 526 | + skb->transport_header += (hdr->hdrlen + 1) << 3; |
| 527 | + opt->nhoff = (&hdr->nexthdr) - skb_network_header(skb); |
| 528 | + |
| 529 | + return 1; |
| 530 | + } |
| 531 | + |
| 532 | + if (!pskb_may_pull(skb, sizeof(*hdr))) { |
| 533 | + kfree_skb(skb); |
| 534 | + return -1; |
| 535 | + } |
| 536 | + |
| 537 | + n = (hdr->hdrlen << 3) - hdr->pad - (16 - hdr->cmpre); |
| 538 | + r = do_div(n, (16 - hdr->cmpri)); |
| 539 | + /* checks if calculation was without remainder and n fits into |
| 540 | + * unsigned char which is segments_left field. Should not be |
| 541 | + * higher than that. |
| 542 | + */ |
| 543 | + if (r || (n + 1) > 255) { |
| 544 | + kfree_skb(skb); |
| 545 | + return -1; |
| 546 | + } |
| 547 | + |
| 548 | + if (hdr->segments_left > n + 1) { |
| 549 | + __IP6_INC_STATS(net, idev, IPSTATS_MIB_INHDRERRORS); |
| 550 | + icmpv6_param_prob(skb, ICMPV6_HDR_FIELD, |
| 551 | + ((&hdr->segments_left) - |
| 552 | + skb_network_header(skb))); |
| 553 | + return -1; |
| 554 | + } |
| 555 | + |
| 556 | + if (skb_cloned(skb)) { |
| 557 | + if (pskb_expand_head(skb, IPV6_RPL_SRH_WORST_SWAP_SIZE, 0, |
| 558 | + GFP_ATOMIC)) { |
| 559 | + __IP6_INC_STATS(net, ip6_dst_idev(skb_dst(skb)), |
| 560 | + IPSTATS_MIB_OUTDISCARDS); |
| 561 | + kfree_skb(skb); |
| 562 | + return -1; |
| 563 | + } |
| 564 | + } else { |
| 565 | + err = skb_cow_head(skb, IPV6_RPL_SRH_WORST_SWAP_SIZE); |
| 566 | + if (unlikely(err)) { |
| 567 | + kfree_skb(skb); |
| 568 | + return -1; |
| 569 | + } |
| 570 | + } |
| 571 | + |
| 572 | + hdr = (struct ipv6_rpl_sr_hdr *)skb_transport_header(skb); |
| 573 | + |
| 574 | + if (!pskb_may_pull(skb, ipv6_rpl_srh_size(n, hdr->cmpri, |
| 575 | + hdr->cmpre))) { |
| 576 | + kfree_skb(skb); |
| 577 | + return -1; |
| 578 | + } |
| 579 | + |
| 580 | + hdr->segments_left--; |
| 581 | + i = n - hdr->segments_left; |
| 582 | + |
| 583 | + buf = kzalloc(ipv6_rpl_srh_alloc_size(n + 1) * 2, GFP_ATOMIC); |
| 584 | + if (unlikely(!buf)) { |
| 585 | + kfree_skb(skb); |
| 586 | + return -1; |
| 587 | + } |
| 588 | + |
| 589 | + ohdr = (struct ipv6_rpl_sr_hdr *)buf; |
| 590 | + ipv6_rpl_srh_decompress(ohdr, hdr, &ipv6_hdr(skb)->daddr, n); |
| 591 | + chdr = (struct ipv6_rpl_sr_hdr *)(buf + ((ohdr->hdrlen + 1) << 3)); |
| 592 | + |
| 593 | + if ((ipv6_addr_type(&ipv6_hdr(skb)->daddr) & IPV6_ADDR_MULTICAST) || |
| 594 | + (ipv6_addr_type(&ohdr->rpl_segaddr[i]) & IPV6_ADDR_MULTICAST)) { |
| 595 | + kfree_skb(skb); |
| 596 | + kfree(buf); |
| 597 | + return -1; |
| 598 | + } |
| 599 | + |
| 600 | + err = ipv6_chk_rpl_srh_loop(net, ohdr->rpl_segaddr, n + 1); |
| 601 | + if (err) { |
| 602 | + icmpv6_send(skb, ICMPV6_PARAMPROB, 0, 0); |
| 603 | + kfree_skb(skb); |
| 604 | + kfree(buf); |
| 605 | + return -1; |
| 606 | + } |
| 607 | + |
| 608 | + addr = ipv6_hdr(skb)->daddr; |
| 609 | + ipv6_hdr(skb)->daddr = ohdr->rpl_segaddr[i]; |
| 610 | + ohdr->rpl_segaddr[i] = addr; |
| 611 | + |
| 612 | + ipv6_rpl_srh_compress(chdr, ohdr, &ipv6_hdr(skb)->daddr, n); |
| 613 | + |
| 614 | + oldhdr = ipv6_hdr(skb); |
| 615 | + |
| 616 | + skb_pull(skb, ((hdr->hdrlen + 1) << 3)); |
| 617 | + skb_postpull_rcsum(skb, oldhdr, |
| 618 | + sizeof(struct ipv6hdr) + ((hdr->hdrlen + 1) << 3)); |
| 619 | + skb_push(skb, ((chdr->hdrlen + 1) << 3) + sizeof(struct ipv6hdr)); |
| 620 | + skb_reset_network_header(skb); |
| 621 | + skb_mac_header_rebuild(skb); |
| 622 | + skb_set_transport_header(skb, sizeof(struct ipv6hdr)); |
| 623 | + |
| 624 | + memmove(ipv6_hdr(skb), oldhdr, sizeof(struct ipv6hdr)); |
| 625 | + memcpy(skb_transport_header(skb), chdr, (chdr->hdrlen + 1) << 3); |
| 626 | + |
| 627 | + ipv6_hdr(skb)->payload_len = htons(skb->len - sizeof(struct ipv6hdr)); |
| 628 | + skb_postpush_rcsum(skb, ipv6_hdr(skb), |
| 629 | + sizeof(struct ipv6hdr) + ((chdr->hdrlen + 1) << 3)); |
| 630 | + |
| 631 | + kfree(buf); |
| 632 | + |
| 633 | + skb_dst_drop(skb); |
| 634 | + |
| 635 | + ip6_route_input(skb); |
| 636 | + |
| 637 | + if (skb_dst(skb)->error) { |
| 638 | + dst_input(skb); |
| 639 | + return -1; |
| 640 | + } |
| 641 | + |
| 642 | + if (skb_dst(skb)->dev->flags & IFF_LOOPBACK) { |
| 643 | + if (ipv6_hdr(skb)->hop_limit <= 1) { |
| 644 | + __IP6_INC_STATS(net, idev, IPSTATS_MIB_INHDRERRORS); |
| 645 | + icmpv6_send(skb, ICMPV6_TIME_EXCEED, |
| 646 | + ICMPV6_EXC_HOPLIMIT, 0); |
| 647 | + kfree_skb(skb); |
| 648 | + return -1; |
| 649 | + } |
| 650 | + ipv6_hdr(skb)->hop_limit--; |
| 651 | + |
| 652 | + skb_pull(skb, sizeof(struct ipv6hdr)); |
| 653 | + goto looped_back; |
| 654 | + } |
| 655 | + |
| 656 | + dst_input(skb); |
| 657 | + |
| 658 | + return -1; |
| 659 | +} |
| 660 | + |
471 | 661 | /********************************
|
472 | 662 | Routing header.
|
473 | 663 | ********************************/
|
@@ -506,9 +696,16 @@ static int ipv6_rthdr_rcv(struct sk_buff *skb)
|
506 | 696 | return -1;
|
507 | 697 | }
|
508 | 698 |
|
509 |
| - /* segment routing */ |
510 |
| - if (hdr->type == IPV6_SRCRT_TYPE_4) |
| 699 | + switch (hdr->type) { |
| 700 | + case IPV6_SRCRT_TYPE_4: |
| 701 | + /* segment routing */ |
511 | 702 | return ipv6_srh_rcv(skb);
|
| 703 | + case IPV6_SRCRT_TYPE_3: |
| 704 | + /* rpl segment routing */ |
| 705 | + return ipv6_rpl_srh_rcv(skb); |
| 706 | + default: |
| 707 | + break; |
| 708 | + } |
512 | 709 |
|
513 | 710 | looped_back:
|
514 | 711 | if (hdr->segments_left == 0) {
|
|
0 commit comments