|
47 | 47 | #if IS_ENABLED(CONFIG_IPV6_MIP6) |
48 | 48 | #include <net/xfrm.h> |
49 | 49 | #endif |
| 50 | +#include <linux/seg6.h> |
| 51 | +#include <net/seg6.h> |
50 | 52 |
|
51 | 53 | #include <linux/uaccess.h> |
52 | 54 |
|
@@ -286,6 +288,175 @@ static int ipv6_destopt_rcv(struct sk_buff *skb) |
286 | 288 | return -1; |
287 | 289 | } |
288 | 290 |
|
| 291 | +static void seg6_update_csum(struct sk_buff *skb) |
| 292 | +{ |
| 293 | + struct ipv6_sr_hdr *hdr; |
| 294 | + struct in6_addr *addr; |
| 295 | + __be32 from, to; |
| 296 | + |
| 297 | + /* srh is at transport offset and seg_left is already decremented |
| 298 | + * but daddr is not yet updated with next segment |
| 299 | + */ |
| 300 | + |
| 301 | + hdr = (struct ipv6_sr_hdr *)skb_transport_header(skb); |
| 302 | + addr = hdr->segments + hdr->segments_left; |
| 303 | + |
| 304 | + hdr->segments_left++; |
| 305 | + from = *(__be32 *)hdr; |
| 306 | + |
| 307 | + hdr->segments_left--; |
| 308 | + to = *(__be32 *)hdr; |
| 309 | + |
| 310 | + /* update skb csum with diff resulting from seg_left decrement */ |
| 311 | + |
| 312 | + update_csum_diff4(skb, from, to); |
| 313 | + |
| 314 | + /* compute csum diff between current and next segment and update */ |
| 315 | + |
| 316 | + update_csum_diff16(skb, (__be32 *)(&ipv6_hdr(skb)->daddr), |
| 317 | + (__be32 *)addr); |
| 318 | +} |
| 319 | + |
| 320 | +static int ipv6_srh_rcv(struct sk_buff *skb) |
| 321 | +{ |
| 322 | + struct inet6_skb_parm *opt = IP6CB(skb); |
| 323 | + struct net *net = dev_net(skb->dev); |
| 324 | + struct ipv6_sr_hdr *hdr; |
| 325 | + struct inet6_dev *idev; |
| 326 | + struct in6_addr *addr; |
| 327 | + bool cleanup = false; |
| 328 | + int accept_seg6; |
| 329 | + |
| 330 | + hdr = (struct ipv6_sr_hdr *)skb_transport_header(skb); |
| 331 | + |
| 332 | + idev = __in6_dev_get(skb->dev); |
| 333 | + |
| 334 | + accept_seg6 = net->ipv6.devconf_all->seg6_enabled; |
| 335 | + if (accept_seg6 > idev->cnf.seg6_enabled) |
| 336 | + accept_seg6 = idev->cnf.seg6_enabled; |
| 337 | + |
| 338 | + if (!accept_seg6) { |
| 339 | + kfree_skb(skb); |
| 340 | + return -1; |
| 341 | + } |
| 342 | + |
| 343 | +looped_back: |
| 344 | + if (hdr->segments_left > 0) { |
| 345 | + if (hdr->nexthdr != NEXTHDR_IPV6 && hdr->segments_left == 1 && |
| 346 | + sr_has_cleanup(hdr)) |
| 347 | + cleanup = true; |
| 348 | + } else { |
| 349 | + if (hdr->nexthdr == NEXTHDR_IPV6) { |
| 350 | + int offset = (hdr->hdrlen + 1) << 3; |
| 351 | + |
| 352 | + skb_postpull_rcsum(skb, skb_network_header(skb), |
| 353 | + skb_network_header_len(skb)); |
| 354 | + |
| 355 | + if (!pskb_pull(skb, offset)) { |
| 356 | + kfree_skb(skb); |
| 357 | + return -1; |
| 358 | + } |
| 359 | + skb_postpull_rcsum(skb, skb_transport_header(skb), |
| 360 | + offset); |
| 361 | + |
| 362 | + skb_reset_network_header(skb); |
| 363 | + skb_reset_transport_header(skb); |
| 364 | + skb->encapsulation = 0; |
| 365 | + |
| 366 | + __skb_tunnel_rx(skb, skb->dev, net); |
| 367 | + |
| 368 | + netif_rx(skb); |
| 369 | + return -1; |
| 370 | + } |
| 371 | + |
| 372 | + opt->srcrt = skb_network_header_len(skb); |
| 373 | + opt->lastopt = opt->srcrt; |
| 374 | + skb->transport_header += (hdr->hdrlen + 1) << 3; |
| 375 | + opt->nhoff = (&hdr->nexthdr) - skb_network_header(skb); |
| 376 | + |
| 377 | + return 1; |
| 378 | + } |
| 379 | + |
| 380 | + if (hdr->segments_left >= (hdr->hdrlen >> 1)) { |
| 381 | + __IP6_INC_STATS(net, ip6_dst_idev(skb_dst(skb)), |
| 382 | + IPSTATS_MIB_INHDRERRORS); |
| 383 | + icmpv6_param_prob(skb, ICMPV6_HDR_FIELD, |
| 384 | + ((&hdr->segments_left) - |
| 385 | + skb_network_header(skb))); |
| 386 | + kfree_skb(skb); |
| 387 | + return -1; |
| 388 | + } |
| 389 | + |
| 390 | + if (skb_cloned(skb)) { |
| 391 | + if (pskb_expand_head(skb, 0, 0, GFP_ATOMIC)) { |
| 392 | + __IP6_INC_STATS(net, ip6_dst_idev(skb_dst(skb)), |
| 393 | + IPSTATS_MIB_OUTDISCARDS); |
| 394 | + kfree_skb(skb); |
| 395 | + return -1; |
| 396 | + } |
| 397 | + } |
| 398 | + |
| 399 | + hdr = (struct ipv6_sr_hdr *)skb_transport_header(skb); |
| 400 | + |
| 401 | + hdr->segments_left--; |
| 402 | + addr = hdr->segments + hdr->segments_left; |
| 403 | + |
| 404 | + skb_push(skb, sizeof(struct ipv6hdr)); |
| 405 | + |
| 406 | + if (skb->ip_summed == CHECKSUM_COMPLETE) |
| 407 | + seg6_update_csum(skb); |
| 408 | + |
| 409 | + ipv6_hdr(skb)->daddr = *addr; |
| 410 | + |
| 411 | + if (cleanup) { |
| 412 | + int srhlen = (hdr->hdrlen + 1) << 3; |
| 413 | + int nh = hdr->nexthdr; |
| 414 | + |
| 415 | + skb_pull_rcsum(skb, sizeof(struct ipv6hdr) + srhlen); |
| 416 | + memmove(skb_network_header(skb) + srhlen, |
| 417 | + skb_network_header(skb), |
| 418 | + (unsigned char *)hdr - skb_network_header(skb)); |
| 419 | + skb->network_header += srhlen; |
| 420 | + ipv6_hdr(skb)->nexthdr = nh; |
| 421 | + ipv6_hdr(skb)->payload_len = htons(skb->len - |
| 422 | + sizeof(struct ipv6hdr)); |
| 423 | + skb_push_rcsum(skb, sizeof(struct ipv6hdr)); |
| 424 | + } |
| 425 | + |
| 426 | + skb_dst_drop(skb); |
| 427 | + |
| 428 | + ip6_route_input(skb); |
| 429 | + |
| 430 | + if (skb_dst(skb)->error) { |
| 431 | + dst_input(skb); |
| 432 | + return -1; |
| 433 | + } |
| 434 | + |
| 435 | + if (skb_dst(skb)->dev->flags & IFF_LOOPBACK) { |
| 436 | + if (ipv6_hdr(skb)->hop_limit <= 1) { |
| 437 | + __IP6_INC_STATS(net, ip6_dst_idev(skb_dst(skb)), |
| 438 | + IPSTATS_MIB_INHDRERRORS); |
| 439 | + icmpv6_send(skb, ICMPV6_TIME_EXCEED, |
| 440 | + ICMPV6_EXC_HOPLIMIT, 0); |
| 441 | + kfree_skb(skb); |
| 442 | + return -1; |
| 443 | + } |
| 444 | + ipv6_hdr(skb)->hop_limit--; |
| 445 | + |
| 446 | + /* be sure that srh is still present before reinjecting */ |
| 447 | + if (!cleanup) { |
| 448 | + skb_pull(skb, sizeof(struct ipv6hdr)); |
| 449 | + goto looped_back; |
| 450 | + } |
| 451 | + skb_set_transport_header(skb, sizeof(struct ipv6hdr)); |
| 452 | + IP6CB(skb)->nhoff = offsetof(struct ipv6hdr, nexthdr); |
| 453 | + } |
| 454 | + |
| 455 | + dst_input(skb); |
| 456 | + |
| 457 | + return -1; |
| 458 | +} |
| 459 | + |
289 | 460 | /******************************** |
290 | 461 | Routing header. |
291 | 462 | ********************************/ |
@@ -326,6 +497,10 @@ static int ipv6_rthdr_rcv(struct sk_buff *skb) |
326 | 497 | return -1; |
327 | 498 | } |
328 | 499 |
|
| 500 | + /* segment routing */ |
| 501 | + if (hdr->type == IPV6_SRCRT_TYPE_4) |
| 502 | + return ipv6_srh_rcv(skb); |
| 503 | + |
329 | 504 | looped_back: |
330 | 505 | if (hdr->segments_left == 0) { |
331 | 506 | switch (hdr->type) { |
|
0 commit comments