18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later 28c2ecf20Sopenharmony_ci/* 38c2ecf20Sopenharmony_ci * IP Payload Compression Protocol (IPComp) for IPv6 - RFC3173 48c2ecf20Sopenharmony_ci * 58c2ecf20Sopenharmony_ci * Copyright (C)2003 USAGI/WIDE Project 68c2ecf20Sopenharmony_ci * 78c2ecf20Sopenharmony_ci * Author Mitsuru KANDA <mk@linux-ipv6.org> 88c2ecf20Sopenharmony_ci */ 98c2ecf20Sopenharmony_ci/* 108c2ecf20Sopenharmony_ci * [Memo] 118c2ecf20Sopenharmony_ci * 128c2ecf20Sopenharmony_ci * Outbound: 138c2ecf20Sopenharmony_ci * The compression of IP datagram MUST be done before AH/ESP processing, 148c2ecf20Sopenharmony_ci * fragmentation, and the addition of Hop-by-Hop/Routing header. 158c2ecf20Sopenharmony_ci * 168c2ecf20Sopenharmony_ci * Inbound: 178c2ecf20Sopenharmony_ci * The decompression of IP datagram MUST be done after the reassembly, 188c2ecf20Sopenharmony_ci * AH/ESP processing. 198c2ecf20Sopenharmony_ci */ 208c2ecf20Sopenharmony_ci 218c2ecf20Sopenharmony_ci#define pr_fmt(fmt) "IPv6: " fmt 228c2ecf20Sopenharmony_ci 238c2ecf20Sopenharmony_ci#include <linux/module.h> 248c2ecf20Sopenharmony_ci#include <net/ip.h> 258c2ecf20Sopenharmony_ci#include <net/xfrm.h> 268c2ecf20Sopenharmony_ci#include <net/ipcomp.h> 278c2ecf20Sopenharmony_ci#include <linux/crypto.h> 288c2ecf20Sopenharmony_ci#include <linux/err.h> 298c2ecf20Sopenharmony_ci#include <linux/pfkeyv2.h> 308c2ecf20Sopenharmony_ci#include <linux/random.h> 318c2ecf20Sopenharmony_ci#include <linux/percpu.h> 328c2ecf20Sopenharmony_ci#include <linux/smp.h> 338c2ecf20Sopenharmony_ci#include <linux/list.h> 348c2ecf20Sopenharmony_ci#include <linux/vmalloc.h> 358c2ecf20Sopenharmony_ci#include <linux/rtnetlink.h> 368c2ecf20Sopenharmony_ci#include <net/ip6_route.h> 378c2ecf20Sopenharmony_ci#include <net/icmp.h> 388c2ecf20Sopenharmony_ci#include <net/ipv6.h> 398c2ecf20Sopenharmony_ci#include <net/protocol.h> 408c2ecf20Sopenharmony_ci#include <linux/ipv6.h> 418c2ecf20Sopenharmony_ci#include <linux/icmpv6.h> 428c2ecf20Sopenharmony_ci#include <linux/mutex.h> 438c2ecf20Sopenharmony_ci 448c2ecf20Sopenharmony_cistatic int ipcomp6_err(struct sk_buff *skb, struct inet6_skb_parm *opt, 458c2ecf20Sopenharmony_ci u8 type, u8 code, int offset, __be32 info) 468c2ecf20Sopenharmony_ci{ 478c2ecf20Sopenharmony_ci struct net *net = dev_net(skb->dev); 488c2ecf20Sopenharmony_ci __be32 spi; 498c2ecf20Sopenharmony_ci const struct ipv6hdr *iph = (const struct ipv6hdr *)skb->data; 508c2ecf20Sopenharmony_ci struct ip_comp_hdr *ipcomph = 518c2ecf20Sopenharmony_ci (struct ip_comp_hdr *)(skb->data + offset); 528c2ecf20Sopenharmony_ci struct xfrm_state *x; 538c2ecf20Sopenharmony_ci 548c2ecf20Sopenharmony_ci if (type != ICMPV6_PKT_TOOBIG && 558c2ecf20Sopenharmony_ci type != NDISC_REDIRECT) 568c2ecf20Sopenharmony_ci return 0; 578c2ecf20Sopenharmony_ci 588c2ecf20Sopenharmony_ci spi = htonl(ntohs(ipcomph->cpi)); 598c2ecf20Sopenharmony_ci x = xfrm_state_lookup(net, skb->mark, (const xfrm_address_t *)&iph->daddr, 608c2ecf20Sopenharmony_ci spi, IPPROTO_COMP, AF_INET6); 618c2ecf20Sopenharmony_ci if (!x) 628c2ecf20Sopenharmony_ci return 0; 638c2ecf20Sopenharmony_ci 648c2ecf20Sopenharmony_ci if (type == NDISC_REDIRECT) 658c2ecf20Sopenharmony_ci ip6_redirect(skb, net, skb->dev->ifindex, 0, 668c2ecf20Sopenharmony_ci sock_net_uid(net, NULL)); 678c2ecf20Sopenharmony_ci else 688c2ecf20Sopenharmony_ci ip6_update_pmtu(skb, net, info, 0, 0, sock_net_uid(net, NULL)); 698c2ecf20Sopenharmony_ci xfrm_state_put(x); 708c2ecf20Sopenharmony_ci 718c2ecf20Sopenharmony_ci return 0; 728c2ecf20Sopenharmony_ci} 738c2ecf20Sopenharmony_ci 748c2ecf20Sopenharmony_cistatic struct xfrm_state *ipcomp6_tunnel_create(struct xfrm_state *x) 758c2ecf20Sopenharmony_ci{ 768c2ecf20Sopenharmony_ci struct net *net = xs_net(x); 778c2ecf20Sopenharmony_ci struct xfrm_state *t = NULL; 788c2ecf20Sopenharmony_ci 798c2ecf20Sopenharmony_ci t = xfrm_state_alloc(net); 808c2ecf20Sopenharmony_ci if (!t) 818c2ecf20Sopenharmony_ci goto out; 828c2ecf20Sopenharmony_ci 838c2ecf20Sopenharmony_ci t->id.proto = IPPROTO_IPV6; 848c2ecf20Sopenharmony_ci t->id.spi = xfrm6_tunnel_alloc_spi(net, (xfrm_address_t *)&x->props.saddr); 858c2ecf20Sopenharmony_ci if (!t->id.spi) 868c2ecf20Sopenharmony_ci goto error; 878c2ecf20Sopenharmony_ci 888c2ecf20Sopenharmony_ci memcpy(t->id.daddr.a6, x->id.daddr.a6, sizeof(struct in6_addr)); 898c2ecf20Sopenharmony_ci memcpy(&t->sel, &x->sel, sizeof(t->sel)); 908c2ecf20Sopenharmony_ci t->props.family = AF_INET6; 918c2ecf20Sopenharmony_ci t->props.mode = x->props.mode; 928c2ecf20Sopenharmony_ci memcpy(t->props.saddr.a6, x->props.saddr.a6, sizeof(struct in6_addr)); 938c2ecf20Sopenharmony_ci memcpy(&t->mark, &x->mark, sizeof(t->mark)); 948c2ecf20Sopenharmony_ci t->if_id = x->if_id; 958c2ecf20Sopenharmony_ci 968c2ecf20Sopenharmony_ci if (xfrm_init_state(t)) 978c2ecf20Sopenharmony_ci goto error; 988c2ecf20Sopenharmony_ci 998c2ecf20Sopenharmony_ci atomic_set(&t->tunnel_users, 1); 1008c2ecf20Sopenharmony_ci 1018c2ecf20Sopenharmony_ciout: 1028c2ecf20Sopenharmony_ci return t; 1038c2ecf20Sopenharmony_ci 1048c2ecf20Sopenharmony_cierror: 1058c2ecf20Sopenharmony_ci t->km.state = XFRM_STATE_DEAD; 1068c2ecf20Sopenharmony_ci xfrm_state_put(t); 1078c2ecf20Sopenharmony_ci t = NULL; 1088c2ecf20Sopenharmony_ci goto out; 1098c2ecf20Sopenharmony_ci} 1108c2ecf20Sopenharmony_ci 1118c2ecf20Sopenharmony_cistatic int ipcomp6_tunnel_attach(struct xfrm_state *x) 1128c2ecf20Sopenharmony_ci{ 1138c2ecf20Sopenharmony_ci struct net *net = xs_net(x); 1148c2ecf20Sopenharmony_ci int err = 0; 1158c2ecf20Sopenharmony_ci struct xfrm_state *t = NULL; 1168c2ecf20Sopenharmony_ci __be32 spi; 1178c2ecf20Sopenharmony_ci u32 mark = x->mark.m & x->mark.v; 1188c2ecf20Sopenharmony_ci 1198c2ecf20Sopenharmony_ci spi = xfrm6_tunnel_spi_lookup(net, (xfrm_address_t *)&x->props.saddr); 1208c2ecf20Sopenharmony_ci if (spi) 1218c2ecf20Sopenharmony_ci t = xfrm_state_lookup(net, mark, (xfrm_address_t *)&x->id.daddr, 1228c2ecf20Sopenharmony_ci spi, IPPROTO_IPV6, AF_INET6); 1238c2ecf20Sopenharmony_ci if (!t) { 1248c2ecf20Sopenharmony_ci t = ipcomp6_tunnel_create(x); 1258c2ecf20Sopenharmony_ci if (!t) { 1268c2ecf20Sopenharmony_ci err = -EINVAL; 1278c2ecf20Sopenharmony_ci goto out; 1288c2ecf20Sopenharmony_ci } 1298c2ecf20Sopenharmony_ci xfrm_state_insert(t); 1308c2ecf20Sopenharmony_ci xfrm_state_hold(t); 1318c2ecf20Sopenharmony_ci } 1328c2ecf20Sopenharmony_ci x->tunnel = t; 1338c2ecf20Sopenharmony_ci atomic_inc(&t->tunnel_users); 1348c2ecf20Sopenharmony_ci 1358c2ecf20Sopenharmony_ciout: 1368c2ecf20Sopenharmony_ci return err; 1378c2ecf20Sopenharmony_ci} 1388c2ecf20Sopenharmony_ci 1398c2ecf20Sopenharmony_cistatic int ipcomp6_init_state(struct xfrm_state *x) 1408c2ecf20Sopenharmony_ci{ 1418c2ecf20Sopenharmony_ci int err = -EINVAL; 1428c2ecf20Sopenharmony_ci 1438c2ecf20Sopenharmony_ci x->props.header_len = 0; 1448c2ecf20Sopenharmony_ci switch (x->props.mode) { 1458c2ecf20Sopenharmony_ci case XFRM_MODE_TRANSPORT: 1468c2ecf20Sopenharmony_ci break; 1478c2ecf20Sopenharmony_ci case XFRM_MODE_TUNNEL: 1488c2ecf20Sopenharmony_ci x->props.header_len += sizeof(struct ipv6hdr); 1498c2ecf20Sopenharmony_ci break; 1508c2ecf20Sopenharmony_ci default: 1518c2ecf20Sopenharmony_ci goto out; 1528c2ecf20Sopenharmony_ci } 1538c2ecf20Sopenharmony_ci 1548c2ecf20Sopenharmony_ci err = ipcomp_init_state(x); 1558c2ecf20Sopenharmony_ci if (err) 1568c2ecf20Sopenharmony_ci goto out; 1578c2ecf20Sopenharmony_ci 1588c2ecf20Sopenharmony_ci if (x->props.mode == XFRM_MODE_TUNNEL) { 1598c2ecf20Sopenharmony_ci err = ipcomp6_tunnel_attach(x); 1608c2ecf20Sopenharmony_ci if (err) 1618c2ecf20Sopenharmony_ci goto out; 1628c2ecf20Sopenharmony_ci } 1638c2ecf20Sopenharmony_ci 1648c2ecf20Sopenharmony_ci err = 0; 1658c2ecf20Sopenharmony_ciout: 1668c2ecf20Sopenharmony_ci return err; 1678c2ecf20Sopenharmony_ci} 1688c2ecf20Sopenharmony_ci 1698c2ecf20Sopenharmony_cistatic int ipcomp6_rcv_cb(struct sk_buff *skb, int err) 1708c2ecf20Sopenharmony_ci{ 1718c2ecf20Sopenharmony_ci return 0; 1728c2ecf20Sopenharmony_ci} 1738c2ecf20Sopenharmony_ci 1748c2ecf20Sopenharmony_cistatic const struct xfrm_type ipcomp6_type = { 1758c2ecf20Sopenharmony_ci .description = "IPCOMP6", 1768c2ecf20Sopenharmony_ci .owner = THIS_MODULE, 1778c2ecf20Sopenharmony_ci .proto = IPPROTO_COMP, 1788c2ecf20Sopenharmony_ci .init_state = ipcomp6_init_state, 1798c2ecf20Sopenharmony_ci .destructor = ipcomp_destroy, 1808c2ecf20Sopenharmony_ci .input = ipcomp_input, 1818c2ecf20Sopenharmony_ci .output = ipcomp_output, 1828c2ecf20Sopenharmony_ci .hdr_offset = xfrm6_find_1stfragopt, 1838c2ecf20Sopenharmony_ci}; 1848c2ecf20Sopenharmony_ci 1858c2ecf20Sopenharmony_cistatic struct xfrm6_protocol ipcomp6_protocol = { 1868c2ecf20Sopenharmony_ci .handler = xfrm6_rcv, 1878c2ecf20Sopenharmony_ci .input_handler = xfrm_input, 1888c2ecf20Sopenharmony_ci .cb_handler = ipcomp6_rcv_cb, 1898c2ecf20Sopenharmony_ci .err_handler = ipcomp6_err, 1908c2ecf20Sopenharmony_ci .priority = 0, 1918c2ecf20Sopenharmony_ci}; 1928c2ecf20Sopenharmony_ci 1938c2ecf20Sopenharmony_cistatic int __init ipcomp6_init(void) 1948c2ecf20Sopenharmony_ci{ 1958c2ecf20Sopenharmony_ci if (xfrm_register_type(&ipcomp6_type, AF_INET6) < 0) { 1968c2ecf20Sopenharmony_ci pr_info("%s: can't add xfrm type\n", __func__); 1978c2ecf20Sopenharmony_ci return -EAGAIN; 1988c2ecf20Sopenharmony_ci } 1998c2ecf20Sopenharmony_ci if (xfrm6_protocol_register(&ipcomp6_protocol, IPPROTO_COMP) < 0) { 2008c2ecf20Sopenharmony_ci pr_info("%s: can't add protocol\n", __func__); 2018c2ecf20Sopenharmony_ci xfrm_unregister_type(&ipcomp6_type, AF_INET6); 2028c2ecf20Sopenharmony_ci return -EAGAIN; 2038c2ecf20Sopenharmony_ci } 2048c2ecf20Sopenharmony_ci return 0; 2058c2ecf20Sopenharmony_ci} 2068c2ecf20Sopenharmony_ci 2078c2ecf20Sopenharmony_cistatic void __exit ipcomp6_fini(void) 2088c2ecf20Sopenharmony_ci{ 2098c2ecf20Sopenharmony_ci if (xfrm6_protocol_deregister(&ipcomp6_protocol, IPPROTO_COMP) < 0) 2108c2ecf20Sopenharmony_ci pr_info("%s: can't remove protocol\n", __func__); 2118c2ecf20Sopenharmony_ci xfrm_unregister_type(&ipcomp6_type, AF_INET6); 2128c2ecf20Sopenharmony_ci} 2138c2ecf20Sopenharmony_ci 2148c2ecf20Sopenharmony_cimodule_init(ipcomp6_init); 2158c2ecf20Sopenharmony_cimodule_exit(ipcomp6_fini); 2168c2ecf20Sopenharmony_ciMODULE_LICENSE("GPL"); 2178c2ecf20Sopenharmony_ciMODULE_DESCRIPTION("IP Payload Compression Protocol (IPComp) for IPv6 - RFC3173"); 2188c2ecf20Sopenharmony_ciMODULE_AUTHOR("Mitsuru KANDA <mk@linux-ipv6.org>"); 2198c2ecf20Sopenharmony_ci 2208c2ecf20Sopenharmony_ciMODULE_ALIAS_XFRM_TYPE(AF_INET6, XFRM_PROTO_COMP); 221