162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * ipsec.c - Check xfrm on veth inside a net-ns. 462306a36Sopenharmony_ci * Copyright (c) 2018 Dmitry Safonov 562306a36Sopenharmony_ci */ 662306a36Sopenharmony_ci 762306a36Sopenharmony_ci#define _GNU_SOURCE 862306a36Sopenharmony_ci 962306a36Sopenharmony_ci#include <arpa/inet.h> 1062306a36Sopenharmony_ci#include <asm/types.h> 1162306a36Sopenharmony_ci#include <errno.h> 1262306a36Sopenharmony_ci#include <fcntl.h> 1362306a36Sopenharmony_ci#include <limits.h> 1462306a36Sopenharmony_ci#include <linux/limits.h> 1562306a36Sopenharmony_ci#include <linux/netlink.h> 1662306a36Sopenharmony_ci#include <linux/random.h> 1762306a36Sopenharmony_ci#include <linux/rtnetlink.h> 1862306a36Sopenharmony_ci#include <linux/veth.h> 1962306a36Sopenharmony_ci#include <linux/xfrm.h> 2062306a36Sopenharmony_ci#include <netinet/in.h> 2162306a36Sopenharmony_ci#include <net/if.h> 2262306a36Sopenharmony_ci#include <sched.h> 2362306a36Sopenharmony_ci#include <stdbool.h> 2462306a36Sopenharmony_ci#include <stdint.h> 2562306a36Sopenharmony_ci#include <stdio.h> 2662306a36Sopenharmony_ci#include <stdlib.h> 2762306a36Sopenharmony_ci#include <string.h> 2862306a36Sopenharmony_ci#include <sys/mman.h> 2962306a36Sopenharmony_ci#include <sys/socket.h> 3062306a36Sopenharmony_ci#include <sys/stat.h> 3162306a36Sopenharmony_ci#include <sys/syscall.h> 3262306a36Sopenharmony_ci#include <sys/types.h> 3362306a36Sopenharmony_ci#include <sys/wait.h> 3462306a36Sopenharmony_ci#include <time.h> 3562306a36Sopenharmony_ci#include <unistd.h> 3662306a36Sopenharmony_ci 3762306a36Sopenharmony_ci#include "../kselftest.h" 3862306a36Sopenharmony_ci 3962306a36Sopenharmony_ci#define printk(fmt, ...) \ 4062306a36Sopenharmony_ci ksft_print_msg("%d[%u] " fmt "\n", getpid(), __LINE__, ##__VA_ARGS__) 4162306a36Sopenharmony_ci 4262306a36Sopenharmony_ci#define pr_err(fmt, ...) printk(fmt ": %m", ##__VA_ARGS__) 4362306a36Sopenharmony_ci 4462306a36Sopenharmony_ci#define BUILD_BUG_ON(condition) ((void)sizeof(char[1 - 2*!!(condition)])) 4562306a36Sopenharmony_ci 4662306a36Sopenharmony_ci#define IPV4_STR_SZ 16 /* xxx.xxx.xxx.xxx is longest + \0 */ 4762306a36Sopenharmony_ci#define MAX_PAYLOAD 2048 4862306a36Sopenharmony_ci#define XFRM_ALGO_KEY_BUF_SIZE 512 4962306a36Sopenharmony_ci#define MAX_PROCESSES (1 << 14) /* /16 mask divided by /30 subnets */ 5062306a36Sopenharmony_ci#define INADDR_A ((in_addr_t) 0x0a000000) /* 10.0.0.0 */ 5162306a36Sopenharmony_ci#define INADDR_B ((in_addr_t) 0xc0a80000) /* 192.168.0.0 */ 5262306a36Sopenharmony_ci 5362306a36Sopenharmony_ci/* /30 mask for one veth connection */ 5462306a36Sopenharmony_ci#define PREFIX_LEN 30 5562306a36Sopenharmony_ci#define child_ip(nr) (4*nr + 1) 5662306a36Sopenharmony_ci#define grchild_ip(nr) (4*nr + 2) 5762306a36Sopenharmony_ci 5862306a36Sopenharmony_ci#define VETH_FMT "ktst-%d" 5962306a36Sopenharmony_ci#define VETH_LEN 12 6062306a36Sopenharmony_ci 6162306a36Sopenharmony_ci#define XFRM_ALGO_NR_KEYS 29 6262306a36Sopenharmony_ci 6362306a36Sopenharmony_cistatic int nsfd_parent = -1; 6462306a36Sopenharmony_cistatic int nsfd_childa = -1; 6562306a36Sopenharmony_cistatic int nsfd_childb = -1; 6662306a36Sopenharmony_cistatic long page_size; 6762306a36Sopenharmony_ci 6862306a36Sopenharmony_ci/* 6962306a36Sopenharmony_ci * ksft_cnt is static in kselftest, so isn't shared with children. 7062306a36Sopenharmony_ci * We have to send a test result back to parent and count there. 7162306a36Sopenharmony_ci * results_fd is a pipe with test feedback from children. 7262306a36Sopenharmony_ci */ 7362306a36Sopenharmony_cistatic int results_fd[2]; 7462306a36Sopenharmony_ci 7562306a36Sopenharmony_ciconst unsigned int ping_delay_nsec = 50 * 1000 * 1000; 7662306a36Sopenharmony_ciconst unsigned int ping_timeout = 300; 7762306a36Sopenharmony_ciconst unsigned int ping_count = 100; 7862306a36Sopenharmony_ciconst unsigned int ping_success = 80; 7962306a36Sopenharmony_ci 8062306a36Sopenharmony_cistruct xfrm_key_entry { 8162306a36Sopenharmony_ci char algo_name[35]; 8262306a36Sopenharmony_ci int key_len; 8362306a36Sopenharmony_ci}; 8462306a36Sopenharmony_ci 8562306a36Sopenharmony_cistruct xfrm_key_entry xfrm_key_entries[] = { 8662306a36Sopenharmony_ci {"digest_null", 0}, 8762306a36Sopenharmony_ci {"ecb(cipher_null)", 0}, 8862306a36Sopenharmony_ci {"cbc(des)", 64}, 8962306a36Sopenharmony_ci {"hmac(md5)", 128}, 9062306a36Sopenharmony_ci {"cmac(aes)", 128}, 9162306a36Sopenharmony_ci {"xcbc(aes)", 128}, 9262306a36Sopenharmony_ci {"cbc(cast5)", 128}, 9362306a36Sopenharmony_ci {"cbc(serpent)", 128}, 9462306a36Sopenharmony_ci {"hmac(sha1)", 160}, 9562306a36Sopenharmony_ci {"hmac(rmd160)", 160}, 9662306a36Sopenharmony_ci {"cbc(des3_ede)", 192}, 9762306a36Sopenharmony_ci {"hmac(sha256)", 256}, 9862306a36Sopenharmony_ci {"cbc(aes)", 256}, 9962306a36Sopenharmony_ci {"cbc(camellia)", 256}, 10062306a36Sopenharmony_ci {"cbc(twofish)", 256}, 10162306a36Sopenharmony_ci {"rfc3686(ctr(aes))", 288}, 10262306a36Sopenharmony_ci {"hmac(sha384)", 384}, 10362306a36Sopenharmony_ci {"cbc(blowfish)", 448}, 10462306a36Sopenharmony_ci {"hmac(sha512)", 512}, 10562306a36Sopenharmony_ci {"rfc4106(gcm(aes))-128", 160}, 10662306a36Sopenharmony_ci {"rfc4543(gcm(aes))-128", 160}, 10762306a36Sopenharmony_ci {"rfc4309(ccm(aes))-128", 152}, 10862306a36Sopenharmony_ci {"rfc4106(gcm(aes))-192", 224}, 10962306a36Sopenharmony_ci {"rfc4543(gcm(aes))-192", 224}, 11062306a36Sopenharmony_ci {"rfc4309(ccm(aes))-192", 216}, 11162306a36Sopenharmony_ci {"rfc4106(gcm(aes))-256", 288}, 11262306a36Sopenharmony_ci {"rfc4543(gcm(aes))-256", 288}, 11362306a36Sopenharmony_ci {"rfc4309(ccm(aes))-256", 280}, 11462306a36Sopenharmony_ci {"rfc7539(chacha20,poly1305)-128", 0} 11562306a36Sopenharmony_ci}; 11662306a36Sopenharmony_ci 11762306a36Sopenharmony_cistatic void randomize_buffer(void *buf, size_t buflen) 11862306a36Sopenharmony_ci{ 11962306a36Sopenharmony_ci int *p = (int *)buf; 12062306a36Sopenharmony_ci size_t words = buflen / sizeof(int); 12162306a36Sopenharmony_ci size_t leftover = buflen % sizeof(int); 12262306a36Sopenharmony_ci 12362306a36Sopenharmony_ci if (!buflen) 12462306a36Sopenharmony_ci return; 12562306a36Sopenharmony_ci 12662306a36Sopenharmony_ci while (words--) 12762306a36Sopenharmony_ci *p++ = rand(); 12862306a36Sopenharmony_ci 12962306a36Sopenharmony_ci if (leftover) { 13062306a36Sopenharmony_ci int tmp = rand(); 13162306a36Sopenharmony_ci 13262306a36Sopenharmony_ci memcpy(buf + buflen - leftover, &tmp, leftover); 13362306a36Sopenharmony_ci } 13462306a36Sopenharmony_ci 13562306a36Sopenharmony_ci return; 13662306a36Sopenharmony_ci} 13762306a36Sopenharmony_ci 13862306a36Sopenharmony_cistatic int unshare_open(void) 13962306a36Sopenharmony_ci{ 14062306a36Sopenharmony_ci const char *netns_path = "/proc/self/ns/net"; 14162306a36Sopenharmony_ci int fd; 14262306a36Sopenharmony_ci 14362306a36Sopenharmony_ci if (unshare(CLONE_NEWNET) != 0) { 14462306a36Sopenharmony_ci pr_err("unshare()"); 14562306a36Sopenharmony_ci return -1; 14662306a36Sopenharmony_ci } 14762306a36Sopenharmony_ci 14862306a36Sopenharmony_ci fd = open(netns_path, O_RDONLY); 14962306a36Sopenharmony_ci if (fd <= 0) { 15062306a36Sopenharmony_ci pr_err("open(%s)", netns_path); 15162306a36Sopenharmony_ci return -1; 15262306a36Sopenharmony_ci } 15362306a36Sopenharmony_ci 15462306a36Sopenharmony_ci return fd; 15562306a36Sopenharmony_ci} 15662306a36Sopenharmony_ci 15762306a36Sopenharmony_cistatic int switch_ns(int fd) 15862306a36Sopenharmony_ci{ 15962306a36Sopenharmony_ci if (setns(fd, CLONE_NEWNET)) { 16062306a36Sopenharmony_ci pr_err("setns()"); 16162306a36Sopenharmony_ci return -1; 16262306a36Sopenharmony_ci } 16362306a36Sopenharmony_ci return 0; 16462306a36Sopenharmony_ci} 16562306a36Sopenharmony_ci 16662306a36Sopenharmony_ci/* 16762306a36Sopenharmony_ci * Running the test inside a new parent net namespace to bother less 16862306a36Sopenharmony_ci * about cleanup on error-path. 16962306a36Sopenharmony_ci */ 17062306a36Sopenharmony_cistatic int init_namespaces(void) 17162306a36Sopenharmony_ci{ 17262306a36Sopenharmony_ci nsfd_parent = unshare_open(); 17362306a36Sopenharmony_ci if (nsfd_parent <= 0) 17462306a36Sopenharmony_ci return -1; 17562306a36Sopenharmony_ci 17662306a36Sopenharmony_ci nsfd_childa = unshare_open(); 17762306a36Sopenharmony_ci if (nsfd_childa <= 0) 17862306a36Sopenharmony_ci return -1; 17962306a36Sopenharmony_ci 18062306a36Sopenharmony_ci if (switch_ns(nsfd_parent)) 18162306a36Sopenharmony_ci return -1; 18262306a36Sopenharmony_ci 18362306a36Sopenharmony_ci nsfd_childb = unshare_open(); 18462306a36Sopenharmony_ci if (nsfd_childb <= 0) 18562306a36Sopenharmony_ci return -1; 18662306a36Sopenharmony_ci 18762306a36Sopenharmony_ci if (switch_ns(nsfd_parent)) 18862306a36Sopenharmony_ci return -1; 18962306a36Sopenharmony_ci return 0; 19062306a36Sopenharmony_ci} 19162306a36Sopenharmony_ci 19262306a36Sopenharmony_cistatic int netlink_sock(int *sock, uint32_t *seq_nr, int proto) 19362306a36Sopenharmony_ci{ 19462306a36Sopenharmony_ci if (*sock > 0) { 19562306a36Sopenharmony_ci seq_nr++; 19662306a36Sopenharmony_ci return 0; 19762306a36Sopenharmony_ci } 19862306a36Sopenharmony_ci 19962306a36Sopenharmony_ci *sock = socket(AF_NETLINK, SOCK_RAW | SOCK_CLOEXEC, proto); 20062306a36Sopenharmony_ci if (*sock <= 0) { 20162306a36Sopenharmony_ci pr_err("socket(AF_NETLINK)"); 20262306a36Sopenharmony_ci return -1; 20362306a36Sopenharmony_ci } 20462306a36Sopenharmony_ci 20562306a36Sopenharmony_ci randomize_buffer(seq_nr, sizeof(*seq_nr)); 20662306a36Sopenharmony_ci 20762306a36Sopenharmony_ci return 0; 20862306a36Sopenharmony_ci} 20962306a36Sopenharmony_ci 21062306a36Sopenharmony_cistatic inline struct rtattr *rtattr_hdr(struct nlmsghdr *nh) 21162306a36Sopenharmony_ci{ 21262306a36Sopenharmony_ci return (struct rtattr *)((char *)(nh) + RTA_ALIGN((nh)->nlmsg_len)); 21362306a36Sopenharmony_ci} 21462306a36Sopenharmony_ci 21562306a36Sopenharmony_cistatic int rtattr_pack(struct nlmsghdr *nh, size_t req_sz, 21662306a36Sopenharmony_ci unsigned short rta_type, const void *payload, size_t size) 21762306a36Sopenharmony_ci{ 21862306a36Sopenharmony_ci /* NLMSG_ALIGNTO == RTA_ALIGNTO, nlmsg_len already aligned */ 21962306a36Sopenharmony_ci struct rtattr *attr = rtattr_hdr(nh); 22062306a36Sopenharmony_ci size_t nl_size = RTA_ALIGN(nh->nlmsg_len) + RTA_LENGTH(size); 22162306a36Sopenharmony_ci 22262306a36Sopenharmony_ci if (req_sz < nl_size) { 22362306a36Sopenharmony_ci printk("req buf is too small: %zu < %zu", req_sz, nl_size); 22462306a36Sopenharmony_ci return -1; 22562306a36Sopenharmony_ci } 22662306a36Sopenharmony_ci nh->nlmsg_len = nl_size; 22762306a36Sopenharmony_ci 22862306a36Sopenharmony_ci attr->rta_len = RTA_LENGTH(size); 22962306a36Sopenharmony_ci attr->rta_type = rta_type; 23062306a36Sopenharmony_ci memcpy(RTA_DATA(attr), payload, size); 23162306a36Sopenharmony_ci 23262306a36Sopenharmony_ci return 0; 23362306a36Sopenharmony_ci} 23462306a36Sopenharmony_ci 23562306a36Sopenharmony_cistatic struct rtattr *_rtattr_begin(struct nlmsghdr *nh, size_t req_sz, 23662306a36Sopenharmony_ci unsigned short rta_type, const void *payload, size_t size) 23762306a36Sopenharmony_ci{ 23862306a36Sopenharmony_ci struct rtattr *ret = rtattr_hdr(nh); 23962306a36Sopenharmony_ci 24062306a36Sopenharmony_ci if (rtattr_pack(nh, req_sz, rta_type, payload, size)) 24162306a36Sopenharmony_ci return 0; 24262306a36Sopenharmony_ci 24362306a36Sopenharmony_ci return ret; 24462306a36Sopenharmony_ci} 24562306a36Sopenharmony_ci 24662306a36Sopenharmony_cistatic inline struct rtattr *rtattr_begin(struct nlmsghdr *nh, size_t req_sz, 24762306a36Sopenharmony_ci unsigned short rta_type) 24862306a36Sopenharmony_ci{ 24962306a36Sopenharmony_ci return _rtattr_begin(nh, req_sz, rta_type, 0, 0); 25062306a36Sopenharmony_ci} 25162306a36Sopenharmony_ci 25262306a36Sopenharmony_cistatic inline void rtattr_end(struct nlmsghdr *nh, struct rtattr *attr) 25362306a36Sopenharmony_ci{ 25462306a36Sopenharmony_ci char *nlmsg_end = (char *)nh + nh->nlmsg_len; 25562306a36Sopenharmony_ci 25662306a36Sopenharmony_ci attr->rta_len = nlmsg_end - (char *)attr; 25762306a36Sopenharmony_ci} 25862306a36Sopenharmony_ci 25962306a36Sopenharmony_cistatic int veth_pack_peerb(struct nlmsghdr *nh, size_t req_sz, 26062306a36Sopenharmony_ci const char *peer, int ns) 26162306a36Sopenharmony_ci{ 26262306a36Sopenharmony_ci struct ifinfomsg pi; 26362306a36Sopenharmony_ci struct rtattr *peer_attr; 26462306a36Sopenharmony_ci 26562306a36Sopenharmony_ci memset(&pi, 0, sizeof(pi)); 26662306a36Sopenharmony_ci pi.ifi_family = AF_UNSPEC; 26762306a36Sopenharmony_ci pi.ifi_change = 0xFFFFFFFF; 26862306a36Sopenharmony_ci 26962306a36Sopenharmony_ci peer_attr = _rtattr_begin(nh, req_sz, VETH_INFO_PEER, &pi, sizeof(pi)); 27062306a36Sopenharmony_ci if (!peer_attr) 27162306a36Sopenharmony_ci return -1; 27262306a36Sopenharmony_ci 27362306a36Sopenharmony_ci if (rtattr_pack(nh, req_sz, IFLA_IFNAME, peer, strlen(peer))) 27462306a36Sopenharmony_ci return -1; 27562306a36Sopenharmony_ci 27662306a36Sopenharmony_ci if (rtattr_pack(nh, req_sz, IFLA_NET_NS_FD, &ns, sizeof(ns))) 27762306a36Sopenharmony_ci return -1; 27862306a36Sopenharmony_ci 27962306a36Sopenharmony_ci rtattr_end(nh, peer_attr); 28062306a36Sopenharmony_ci 28162306a36Sopenharmony_ci return 0; 28262306a36Sopenharmony_ci} 28362306a36Sopenharmony_ci 28462306a36Sopenharmony_cistatic int netlink_check_answer(int sock) 28562306a36Sopenharmony_ci{ 28662306a36Sopenharmony_ci struct nlmsgerror { 28762306a36Sopenharmony_ci struct nlmsghdr hdr; 28862306a36Sopenharmony_ci int error; 28962306a36Sopenharmony_ci struct nlmsghdr orig_msg; 29062306a36Sopenharmony_ci } answer; 29162306a36Sopenharmony_ci 29262306a36Sopenharmony_ci if (recv(sock, &answer, sizeof(answer), 0) < 0) { 29362306a36Sopenharmony_ci pr_err("recv()"); 29462306a36Sopenharmony_ci return -1; 29562306a36Sopenharmony_ci } else if (answer.hdr.nlmsg_type != NLMSG_ERROR) { 29662306a36Sopenharmony_ci printk("expected NLMSG_ERROR, got %d", (int)answer.hdr.nlmsg_type); 29762306a36Sopenharmony_ci return -1; 29862306a36Sopenharmony_ci } else if (answer.error) { 29962306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", 30062306a36Sopenharmony_ci answer.error, strerror(-answer.error)); 30162306a36Sopenharmony_ci return answer.error; 30262306a36Sopenharmony_ci } 30362306a36Sopenharmony_ci 30462306a36Sopenharmony_ci return 0; 30562306a36Sopenharmony_ci} 30662306a36Sopenharmony_ci 30762306a36Sopenharmony_cistatic int veth_add(int sock, uint32_t seq, const char *peera, int ns_a, 30862306a36Sopenharmony_ci const char *peerb, int ns_b) 30962306a36Sopenharmony_ci{ 31062306a36Sopenharmony_ci uint16_t flags = NLM_F_REQUEST | NLM_F_ACK | NLM_F_EXCL | NLM_F_CREATE; 31162306a36Sopenharmony_ci struct { 31262306a36Sopenharmony_ci struct nlmsghdr nh; 31362306a36Sopenharmony_ci struct ifinfomsg info; 31462306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 31562306a36Sopenharmony_ci } req; 31662306a36Sopenharmony_ci const char veth_type[] = "veth"; 31762306a36Sopenharmony_ci struct rtattr *link_info, *info_data; 31862306a36Sopenharmony_ci 31962306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 32062306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.info)); 32162306a36Sopenharmony_ci req.nh.nlmsg_type = RTM_NEWLINK; 32262306a36Sopenharmony_ci req.nh.nlmsg_flags = flags; 32362306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 32462306a36Sopenharmony_ci req.info.ifi_family = AF_UNSPEC; 32562306a36Sopenharmony_ci req.info.ifi_change = 0xFFFFFFFF; 32662306a36Sopenharmony_ci 32762306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), IFLA_IFNAME, peera, strlen(peera))) 32862306a36Sopenharmony_ci return -1; 32962306a36Sopenharmony_ci 33062306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), IFLA_NET_NS_FD, &ns_a, sizeof(ns_a))) 33162306a36Sopenharmony_ci return -1; 33262306a36Sopenharmony_ci 33362306a36Sopenharmony_ci link_info = rtattr_begin(&req.nh, sizeof(req), IFLA_LINKINFO); 33462306a36Sopenharmony_ci if (!link_info) 33562306a36Sopenharmony_ci return -1; 33662306a36Sopenharmony_ci 33762306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), IFLA_INFO_KIND, veth_type, sizeof(veth_type))) 33862306a36Sopenharmony_ci return -1; 33962306a36Sopenharmony_ci 34062306a36Sopenharmony_ci info_data = rtattr_begin(&req.nh, sizeof(req), IFLA_INFO_DATA); 34162306a36Sopenharmony_ci if (!info_data) 34262306a36Sopenharmony_ci return -1; 34362306a36Sopenharmony_ci 34462306a36Sopenharmony_ci if (veth_pack_peerb(&req.nh, sizeof(req), peerb, ns_b)) 34562306a36Sopenharmony_ci return -1; 34662306a36Sopenharmony_ci 34762306a36Sopenharmony_ci rtattr_end(&req.nh, info_data); 34862306a36Sopenharmony_ci rtattr_end(&req.nh, link_info); 34962306a36Sopenharmony_ci 35062306a36Sopenharmony_ci if (send(sock, &req, req.nh.nlmsg_len, 0) < 0) { 35162306a36Sopenharmony_ci pr_err("send()"); 35262306a36Sopenharmony_ci return -1; 35362306a36Sopenharmony_ci } 35462306a36Sopenharmony_ci return netlink_check_answer(sock); 35562306a36Sopenharmony_ci} 35662306a36Sopenharmony_ci 35762306a36Sopenharmony_cistatic int ip4_addr_set(int sock, uint32_t seq, const char *intf, 35862306a36Sopenharmony_ci struct in_addr addr, uint8_t prefix) 35962306a36Sopenharmony_ci{ 36062306a36Sopenharmony_ci uint16_t flags = NLM_F_REQUEST | NLM_F_ACK | NLM_F_EXCL | NLM_F_CREATE; 36162306a36Sopenharmony_ci struct { 36262306a36Sopenharmony_ci struct nlmsghdr nh; 36362306a36Sopenharmony_ci struct ifaddrmsg info; 36462306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 36562306a36Sopenharmony_ci } req; 36662306a36Sopenharmony_ci 36762306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 36862306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.info)); 36962306a36Sopenharmony_ci req.nh.nlmsg_type = RTM_NEWADDR; 37062306a36Sopenharmony_ci req.nh.nlmsg_flags = flags; 37162306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 37262306a36Sopenharmony_ci req.info.ifa_family = AF_INET; 37362306a36Sopenharmony_ci req.info.ifa_prefixlen = prefix; 37462306a36Sopenharmony_ci req.info.ifa_index = if_nametoindex(intf); 37562306a36Sopenharmony_ci 37662306a36Sopenharmony_ci#ifdef DEBUG 37762306a36Sopenharmony_ci { 37862306a36Sopenharmony_ci char addr_str[IPV4_STR_SZ] = {}; 37962306a36Sopenharmony_ci 38062306a36Sopenharmony_ci strncpy(addr_str, inet_ntoa(addr), IPV4_STR_SZ - 1); 38162306a36Sopenharmony_ci 38262306a36Sopenharmony_ci printk("ip addr set %s", addr_str); 38362306a36Sopenharmony_ci } 38462306a36Sopenharmony_ci#endif 38562306a36Sopenharmony_ci 38662306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), IFA_LOCAL, &addr, sizeof(addr))) 38762306a36Sopenharmony_ci return -1; 38862306a36Sopenharmony_ci 38962306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), IFA_ADDRESS, &addr, sizeof(addr))) 39062306a36Sopenharmony_ci return -1; 39162306a36Sopenharmony_ci 39262306a36Sopenharmony_ci if (send(sock, &req, req.nh.nlmsg_len, 0) < 0) { 39362306a36Sopenharmony_ci pr_err("send()"); 39462306a36Sopenharmony_ci return -1; 39562306a36Sopenharmony_ci } 39662306a36Sopenharmony_ci return netlink_check_answer(sock); 39762306a36Sopenharmony_ci} 39862306a36Sopenharmony_ci 39962306a36Sopenharmony_cistatic int link_set_up(int sock, uint32_t seq, const char *intf) 40062306a36Sopenharmony_ci{ 40162306a36Sopenharmony_ci struct { 40262306a36Sopenharmony_ci struct nlmsghdr nh; 40362306a36Sopenharmony_ci struct ifinfomsg info; 40462306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 40562306a36Sopenharmony_ci } req; 40662306a36Sopenharmony_ci 40762306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 40862306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.info)); 40962306a36Sopenharmony_ci req.nh.nlmsg_type = RTM_NEWLINK; 41062306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 41162306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 41262306a36Sopenharmony_ci req.info.ifi_family = AF_UNSPEC; 41362306a36Sopenharmony_ci req.info.ifi_change = 0xFFFFFFFF; 41462306a36Sopenharmony_ci req.info.ifi_index = if_nametoindex(intf); 41562306a36Sopenharmony_ci req.info.ifi_flags = IFF_UP; 41662306a36Sopenharmony_ci req.info.ifi_change = IFF_UP; 41762306a36Sopenharmony_ci 41862306a36Sopenharmony_ci if (send(sock, &req, req.nh.nlmsg_len, 0) < 0) { 41962306a36Sopenharmony_ci pr_err("send()"); 42062306a36Sopenharmony_ci return -1; 42162306a36Sopenharmony_ci } 42262306a36Sopenharmony_ci return netlink_check_answer(sock); 42362306a36Sopenharmony_ci} 42462306a36Sopenharmony_ci 42562306a36Sopenharmony_cistatic int ip4_route_set(int sock, uint32_t seq, const char *intf, 42662306a36Sopenharmony_ci struct in_addr src, struct in_addr dst) 42762306a36Sopenharmony_ci{ 42862306a36Sopenharmony_ci struct { 42962306a36Sopenharmony_ci struct nlmsghdr nh; 43062306a36Sopenharmony_ci struct rtmsg rt; 43162306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 43262306a36Sopenharmony_ci } req; 43362306a36Sopenharmony_ci unsigned int index = if_nametoindex(intf); 43462306a36Sopenharmony_ci 43562306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 43662306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.rt)); 43762306a36Sopenharmony_ci req.nh.nlmsg_type = RTM_NEWROUTE; 43862306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | NLM_F_CREATE; 43962306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 44062306a36Sopenharmony_ci req.rt.rtm_family = AF_INET; 44162306a36Sopenharmony_ci req.rt.rtm_dst_len = 32; 44262306a36Sopenharmony_ci req.rt.rtm_table = RT_TABLE_MAIN; 44362306a36Sopenharmony_ci req.rt.rtm_protocol = RTPROT_BOOT; 44462306a36Sopenharmony_ci req.rt.rtm_scope = RT_SCOPE_LINK; 44562306a36Sopenharmony_ci req.rt.rtm_type = RTN_UNICAST; 44662306a36Sopenharmony_ci 44762306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), RTA_DST, &dst, sizeof(dst))) 44862306a36Sopenharmony_ci return -1; 44962306a36Sopenharmony_ci 45062306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), RTA_PREFSRC, &src, sizeof(src))) 45162306a36Sopenharmony_ci return -1; 45262306a36Sopenharmony_ci 45362306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), RTA_OIF, &index, sizeof(index))) 45462306a36Sopenharmony_ci return -1; 45562306a36Sopenharmony_ci 45662306a36Sopenharmony_ci if (send(sock, &req, req.nh.nlmsg_len, 0) < 0) { 45762306a36Sopenharmony_ci pr_err("send()"); 45862306a36Sopenharmony_ci return -1; 45962306a36Sopenharmony_ci } 46062306a36Sopenharmony_ci 46162306a36Sopenharmony_ci return netlink_check_answer(sock); 46262306a36Sopenharmony_ci} 46362306a36Sopenharmony_ci 46462306a36Sopenharmony_cistatic int tunnel_set_route(int route_sock, uint32_t *route_seq, char *veth, 46562306a36Sopenharmony_ci struct in_addr tunsrc, struct in_addr tundst) 46662306a36Sopenharmony_ci{ 46762306a36Sopenharmony_ci if (ip4_addr_set(route_sock, (*route_seq)++, "lo", 46862306a36Sopenharmony_ci tunsrc, PREFIX_LEN)) { 46962306a36Sopenharmony_ci printk("Failed to set ipv4 addr"); 47062306a36Sopenharmony_ci return -1; 47162306a36Sopenharmony_ci } 47262306a36Sopenharmony_ci 47362306a36Sopenharmony_ci if (ip4_route_set(route_sock, (*route_seq)++, veth, tunsrc, tundst)) { 47462306a36Sopenharmony_ci printk("Failed to set ipv4 route"); 47562306a36Sopenharmony_ci return -1; 47662306a36Sopenharmony_ci } 47762306a36Sopenharmony_ci 47862306a36Sopenharmony_ci return 0; 47962306a36Sopenharmony_ci} 48062306a36Sopenharmony_ci 48162306a36Sopenharmony_cistatic int init_child(int nsfd, char *veth, unsigned int src, unsigned int dst) 48262306a36Sopenharmony_ci{ 48362306a36Sopenharmony_ci struct in_addr intsrc = inet_makeaddr(INADDR_B, src); 48462306a36Sopenharmony_ci struct in_addr tunsrc = inet_makeaddr(INADDR_A, src); 48562306a36Sopenharmony_ci struct in_addr tundst = inet_makeaddr(INADDR_A, dst); 48662306a36Sopenharmony_ci int route_sock = -1, ret = -1; 48762306a36Sopenharmony_ci uint32_t route_seq; 48862306a36Sopenharmony_ci 48962306a36Sopenharmony_ci if (switch_ns(nsfd)) 49062306a36Sopenharmony_ci return -1; 49162306a36Sopenharmony_ci 49262306a36Sopenharmony_ci if (netlink_sock(&route_sock, &route_seq, NETLINK_ROUTE)) { 49362306a36Sopenharmony_ci printk("Failed to open netlink route socket in child"); 49462306a36Sopenharmony_ci return -1; 49562306a36Sopenharmony_ci } 49662306a36Sopenharmony_ci 49762306a36Sopenharmony_ci if (ip4_addr_set(route_sock, route_seq++, veth, intsrc, PREFIX_LEN)) { 49862306a36Sopenharmony_ci printk("Failed to set ipv4 addr"); 49962306a36Sopenharmony_ci goto err; 50062306a36Sopenharmony_ci } 50162306a36Sopenharmony_ci 50262306a36Sopenharmony_ci if (link_set_up(route_sock, route_seq++, veth)) { 50362306a36Sopenharmony_ci printk("Failed to bring up %s", veth); 50462306a36Sopenharmony_ci goto err; 50562306a36Sopenharmony_ci } 50662306a36Sopenharmony_ci 50762306a36Sopenharmony_ci if (tunnel_set_route(route_sock, &route_seq, veth, tunsrc, tundst)) { 50862306a36Sopenharmony_ci printk("Failed to add tunnel route on %s", veth); 50962306a36Sopenharmony_ci goto err; 51062306a36Sopenharmony_ci } 51162306a36Sopenharmony_ci ret = 0; 51262306a36Sopenharmony_ci 51362306a36Sopenharmony_cierr: 51462306a36Sopenharmony_ci close(route_sock); 51562306a36Sopenharmony_ci return ret; 51662306a36Sopenharmony_ci} 51762306a36Sopenharmony_ci 51862306a36Sopenharmony_ci#define ALGO_LEN 64 51962306a36Sopenharmony_cienum desc_type { 52062306a36Sopenharmony_ci CREATE_TUNNEL = 0, 52162306a36Sopenharmony_ci ALLOCATE_SPI, 52262306a36Sopenharmony_ci MONITOR_ACQUIRE, 52362306a36Sopenharmony_ci EXPIRE_STATE, 52462306a36Sopenharmony_ci EXPIRE_POLICY, 52562306a36Sopenharmony_ci SPDINFO_ATTRS, 52662306a36Sopenharmony_ci}; 52762306a36Sopenharmony_ciconst char *desc_name[] = { 52862306a36Sopenharmony_ci "create tunnel", 52962306a36Sopenharmony_ci "alloc spi", 53062306a36Sopenharmony_ci "monitor acquire", 53162306a36Sopenharmony_ci "expire state", 53262306a36Sopenharmony_ci "expire policy", 53362306a36Sopenharmony_ci "spdinfo attributes", 53462306a36Sopenharmony_ci "" 53562306a36Sopenharmony_ci}; 53662306a36Sopenharmony_cistruct xfrm_desc { 53762306a36Sopenharmony_ci enum desc_type type; 53862306a36Sopenharmony_ci uint8_t proto; 53962306a36Sopenharmony_ci char a_algo[ALGO_LEN]; 54062306a36Sopenharmony_ci char e_algo[ALGO_LEN]; 54162306a36Sopenharmony_ci char c_algo[ALGO_LEN]; 54262306a36Sopenharmony_ci char ae_algo[ALGO_LEN]; 54362306a36Sopenharmony_ci unsigned int icv_len; 54462306a36Sopenharmony_ci /* unsigned key_len; */ 54562306a36Sopenharmony_ci}; 54662306a36Sopenharmony_ci 54762306a36Sopenharmony_cienum msg_type { 54862306a36Sopenharmony_ci MSG_ACK = 0, 54962306a36Sopenharmony_ci MSG_EXIT, 55062306a36Sopenharmony_ci MSG_PING, 55162306a36Sopenharmony_ci MSG_XFRM_PREPARE, 55262306a36Sopenharmony_ci MSG_XFRM_ADD, 55362306a36Sopenharmony_ci MSG_XFRM_DEL, 55462306a36Sopenharmony_ci MSG_XFRM_CLEANUP, 55562306a36Sopenharmony_ci}; 55662306a36Sopenharmony_ci 55762306a36Sopenharmony_cistruct test_desc { 55862306a36Sopenharmony_ci enum msg_type type; 55962306a36Sopenharmony_ci union { 56062306a36Sopenharmony_ci struct { 56162306a36Sopenharmony_ci in_addr_t reply_ip; 56262306a36Sopenharmony_ci unsigned int port; 56362306a36Sopenharmony_ci } ping; 56462306a36Sopenharmony_ci struct xfrm_desc xfrm_desc; 56562306a36Sopenharmony_ci } body; 56662306a36Sopenharmony_ci}; 56762306a36Sopenharmony_ci 56862306a36Sopenharmony_cistruct test_result { 56962306a36Sopenharmony_ci struct xfrm_desc desc; 57062306a36Sopenharmony_ci unsigned int res; 57162306a36Sopenharmony_ci}; 57262306a36Sopenharmony_ci 57362306a36Sopenharmony_cistatic void write_test_result(unsigned int res, struct xfrm_desc *d) 57462306a36Sopenharmony_ci{ 57562306a36Sopenharmony_ci struct test_result tr = {}; 57662306a36Sopenharmony_ci ssize_t ret; 57762306a36Sopenharmony_ci 57862306a36Sopenharmony_ci tr.desc = *d; 57962306a36Sopenharmony_ci tr.res = res; 58062306a36Sopenharmony_ci 58162306a36Sopenharmony_ci ret = write(results_fd[1], &tr, sizeof(tr)); 58262306a36Sopenharmony_ci if (ret != sizeof(tr)) 58362306a36Sopenharmony_ci pr_err("Failed to write the result in pipe %zd", ret); 58462306a36Sopenharmony_ci} 58562306a36Sopenharmony_ci 58662306a36Sopenharmony_cistatic void write_msg(int fd, struct test_desc *msg, bool exit_of_fail) 58762306a36Sopenharmony_ci{ 58862306a36Sopenharmony_ci ssize_t bytes = write(fd, msg, sizeof(*msg)); 58962306a36Sopenharmony_ci 59062306a36Sopenharmony_ci /* Make sure that write/read is atomic to a pipe */ 59162306a36Sopenharmony_ci BUILD_BUG_ON(sizeof(struct test_desc) > PIPE_BUF); 59262306a36Sopenharmony_ci 59362306a36Sopenharmony_ci if (bytes < 0) { 59462306a36Sopenharmony_ci pr_err("write()"); 59562306a36Sopenharmony_ci if (exit_of_fail) 59662306a36Sopenharmony_ci exit(KSFT_FAIL); 59762306a36Sopenharmony_ci } 59862306a36Sopenharmony_ci if (bytes != sizeof(*msg)) { 59962306a36Sopenharmony_ci pr_err("sent part of the message %zd/%zu", bytes, sizeof(*msg)); 60062306a36Sopenharmony_ci if (exit_of_fail) 60162306a36Sopenharmony_ci exit(KSFT_FAIL); 60262306a36Sopenharmony_ci } 60362306a36Sopenharmony_ci} 60462306a36Sopenharmony_ci 60562306a36Sopenharmony_cistatic void read_msg(int fd, struct test_desc *msg, bool exit_of_fail) 60662306a36Sopenharmony_ci{ 60762306a36Sopenharmony_ci ssize_t bytes = read(fd, msg, sizeof(*msg)); 60862306a36Sopenharmony_ci 60962306a36Sopenharmony_ci if (bytes < 0) { 61062306a36Sopenharmony_ci pr_err("read()"); 61162306a36Sopenharmony_ci if (exit_of_fail) 61262306a36Sopenharmony_ci exit(KSFT_FAIL); 61362306a36Sopenharmony_ci } 61462306a36Sopenharmony_ci if (bytes != sizeof(*msg)) { 61562306a36Sopenharmony_ci pr_err("got incomplete message %zd/%zu", bytes, sizeof(*msg)); 61662306a36Sopenharmony_ci if (exit_of_fail) 61762306a36Sopenharmony_ci exit(KSFT_FAIL); 61862306a36Sopenharmony_ci } 61962306a36Sopenharmony_ci} 62062306a36Sopenharmony_ci 62162306a36Sopenharmony_cistatic int udp_ping_init(struct in_addr listen_ip, unsigned int u_timeout, 62262306a36Sopenharmony_ci unsigned int *server_port, int sock[2]) 62362306a36Sopenharmony_ci{ 62462306a36Sopenharmony_ci struct sockaddr_in server; 62562306a36Sopenharmony_ci struct timeval t = { .tv_sec = 0, .tv_usec = u_timeout }; 62662306a36Sopenharmony_ci socklen_t s_len = sizeof(server); 62762306a36Sopenharmony_ci 62862306a36Sopenharmony_ci sock[0] = socket(AF_INET, SOCK_DGRAM, 0); 62962306a36Sopenharmony_ci if (sock[0] < 0) { 63062306a36Sopenharmony_ci pr_err("socket()"); 63162306a36Sopenharmony_ci return -1; 63262306a36Sopenharmony_ci } 63362306a36Sopenharmony_ci 63462306a36Sopenharmony_ci server.sin_family = AF_INET; 63562306a36Sopenharmony_ci server.sin_port = 0; 63662306a36Sopenharmony_ci memcpy(&server.sin_addr.s_addr, &listen_ip, sizeof(struct in_addr)); 63762306a36Sopenharmony_ci 63862306a36Sopenharmony_ci if (bind(sock[0], (struct sockaddr *)&server, s_len)) { 63962306a36Sopenharmony_ci pr_err("bind()"); 64062306a36Sopenharmony_ci goto err_close_server; 64162306a36Sopenharmony_ci } 64262306a36Sopenharmony_ci 64362306a36Sopenharmony_ci if (getsockname(sock[0], (struct sockaddr *)&server, &s_len)) { 64462306a36Sopenharmony_ci pr_err("getsockname()"); 64562306a36Sopenharmony_ci goto err_close_server; 64662306a36Sopenharmony_ci } 64762306a36Sopenharmony_ci 64862306a36Sopenharmony_ci *server_port = ntohs(server.sin_port); 64962306a36Sopenharmony_ci 65062306a36Sopenharmony_ci if (setsockopt(sock[0], SOL_SOCKET, SO_RCVTIMEO, (const char *)&t, sizeof t)) { 65162306a36Sopenharmony_ci pr_err("setsockopt()"); 65262306a36Sopenharmony_ci goto err_close_server; 65362306a36Sopenharmony_ci } 65462306a36Sopenharmony_ci 65562306a36Sopenharmony_ci sock[1] = socket(AF_INET, SOCK_DGRAM, 0); 65662306a36Sopenharmony_ci if (sock[1] < 0) { 65762306a36Sopenharmony_ci pr_err("socket()"); 65862306a36Sopenharmony_ci goto err_close_server; 65962306a36Sopenharmony_ci } 66062306a36Sopenharmony_ci 66162306a36Sopenharmony_ci return 0; 66262306a36Sopenharmony_ci 66362306a36Sopenharmony_cierr_close_server: 66462306a36Sopenharmony_ci close(sock[0]); 66562306a36Sopenharmony_ci return -1; 66662306a36Sopenharmony_ci} 66762306a36Sopenharmony_ci 66862306a36Sopenharmony_cistatic int udp_ping_send(int sock[2], in_addr_t dest_ip, unsigned int port, 66962306a36Sopenharmony_ci char *buf, size_t buf_len) 67062306a36Sopenharmony_ci{ 67162306a36Sopenharmony_ci struct sockaddr_in server; 67262306a36Sopenharmony_ci const struct sockaddr *dest_addr = (struct sockaddr *)&server; 67362306a36Sopenharmony_ci char *sock_buf[buf_len]; 67462306a36Sopenharmony_ci ssize_t r_bytes, s_bytes; 67562306a36Sopenharmony_ci 67662306a36Sopenharmony_ci server.sin_family = AF_INET; 67762306a36Sopenharmony_ci server.sin_port = htons(port); 67862306a36Sopenharmony_ci server.sin_addr.s_addr = dest_ip; 67962306a36Sopenharmony_ci 68062306a36Sopenharmony_ci s_bytes = sendto(sock[1], buf, buf_len, 0, dest_addr, sizeof(server)); 68162306a36Sopenharmony_ci if (s_bytes < 0) { 68262306a36Sopenharmony_ci pr_err("sendto()"); 68362306a36Sopenharmony_ci return -1; 68462306a36Sopenharmony_ci } else if (s_bytes != buf_len) { 68562306a36Sopenharmony_ci printk("send part of the message: %zd/%zu", s_bytes, sizeof(server)); 68662306a36Sopenharmony_ci return -1; 68762306a36Sopenharmony_ci } 68862306a36Sopenharmony_ci 68962306a36Sopenharmony_ci r_bytes = recv(sock[0], sock_buf, buf_len, 0); 69062306a36Sopenharmony_ci if (r_bytes < 0) { 69162306a36Sopenharmony_ci if (errno != EAGAIN) 69262306a36Sopenharmony_ci pr_err("recv()"); 69362306a36Sopenharmony_ci return -1; 69462306a36Sopenharmony_ci } else if (r_bytes == 0) { /* EOF */ 69562306a36Sopenharmony_ci printk("EOF on reply to ping"); 69662306a36Sopenharmony_ci return -1; 69762306a36Sopenharmony_ci } else if (r_bytes != buf_len || memcmp(buf, sock_buf, buf_len)) { 69862306a36Sopenharmony_ci printk("ping reply packet is corrupted %zd/%zu", r_bytes, buf_len); 69962306a36Sopenharmony_ci return -1; 70062306a36Sopenharmony_ci } 70162306a36Sopenharmony_ci 70262306a36Sopenharmony_ci return 0; 70362306a36Sopenharmony_ci} 70462306a36Sopenharmony_ci 70562306a36Sopenharmony_cistatic int udp_ping_reply(int sock[2], in_addr_t dest_ip, unsigned int port, 70662306a36Sopenharmony_ci char *buf, size_t buf_len) 70762306a36Sopenharmony_ci{ 70862306a36Sopenharmony_ci struct sockaddr_in server; 70962306a36Sopenharmony_ci const struct sockaddr *dest_addr = (struct sockaddr *)&server; 71062306a36Sopenharmony_ci char *sock_buf[buf_len]; 71162306a36Sopenharmony_ci ssize_t r_bytes, s_bytes; 71262306a36Sopenharmony_ci 71362306a36Sopenharmony_ci server.sin_family = AF_INET; 71462306a36Sopenharmony_ci server.sin_port = htons(port); 71562306a36Sopenharmony_ci server.sin_addr.s_addr = dest_ip; 71662306a36Sopenharmony_ci 71762306a36Sopenharmony_ci r_bytes = recv(sock[0], sock_buf, buf_len, 0); 71862306a36Sopenharmony_ci if (r_bytes < 0) { 71962306a36Sopenharmony_ci if (errno != EAGAIN) 72062306a36Sopenharmony_ci pr_err("recv()"); 72162306a36Sopenharmony_ci return -1; 72262306a36Sopenharmony_ci } 72362306a36Sopenharmony_ci if (r_bytes == 0) { /* EOF */ 72462306a36Sopenharmony_ci printk("EOF on reply to ping"); 72562306a36Sopenharmony_ci return -1; 72662306a36Sopenharmony_ci } 72762306a36Sopenharmony_ci if (r_bytes != buf_len || memcmp(buf, sock_buf, buf_len)) { 72862306a36Sopenharmony_ci printk("ping reply packet is corrupted %zd/%zu", r_bytes, buf_len); 72962306a36Sopenharmony_ci return -1; 73062306a36Sopenharmony_ci } 73162306a36Sopenharmony_ci 73262306a36Sopenharmony_ci s_bytes = sendto(sock[1], buf, buf_len, 0, dest_addr, sizeof(server)); 73362306a36Sopenharmony_ci if (s_bytes < 0) { 73462306a36Sopenharmony_ci pr_err("sendto()"); 73562306a36Sopenharmony_ci return -1; 73662306a36Sopenharmony_ci } else if (s_bytes != buf_len) { 73762306a36Sopenharmony_ci printk("send part of the message: %zd/%zu", s_bytes, sizeof(server)); 73862306a36Sopenharmony_ci return -1; 73962306a36Sopenharmony_ci } 74062306a36Sopenharmony_ci 74162306a36Sopenharmony_ci return 0; 74262306a36Sopenharmony_ci} 74362306a36Sopenharmony_ci 74462306a36Sopenharmony_citypedef int (*ping_f)(int sock[2], in_addr_t dest_ip, unsigned int port, 74562306a36Sopenharmony_ci char *buf, size_t buf_len); 74662306a36Sopenharmony_cistatic int do_ping(int cmd_fd, char *buf, size_t buf_len, struct in_addr from, 74762306a36Sopenharmony_ci bool init_side, int d_port, in_addr_t to, ping_f func) 74862306a36Sopenharmony_ci{ 74962306a36Sopenharmony_ci struct test_desc msg; 75062306a36Sopenharmony_ci unsigned int s_port, i, ping_succeeded = 0; 75162306a36Sopenharmony_ci int ping_sock[2]; 75262306a36Sopenharmony_ci char to_str[IPV4_STR_SZ] = {}, from_str[IPV4_STR_SZ] = {}; 75362306a36Sopenharmony_ci 75462306a36Sopenharmony_ci if (udp_ping_init(from, ping_timeout, &s_port, ping_sock)) { 75562306a36Sopenharmony_ci printk("Failed to init ping"); 75662306a36Sopenharmony_ci return -1; 75762306a36Sopenharmony_ci } 75862306a36Sopenharmony_ci 75962306a36Sopenharmony_ci memset(&msg, 0, sizeof(msg)); 76062306a36Sopenharmony_ci msg.type = MSG_PING; 76162306a36Sopenharmony_ci msg.body.ping.port = s_port; 76262306a36Sopenharmony_ci memcpy(&msg.body.ping.reply_ip, &from, sizeof(from)); 76362306a36Sopenharmony_ci 76462306a36Sopenharmony_ci write_msg(cmd_fd, &msg, 0); 76562306a36Sopenharmony_ci if (init_side) { 76662306a36Sopenharmony_ci /* The other end sends ip to ping */ 76762306a36Sopenharmony_ci read_msg(cmd_fd, &msg, 0); 76862306a36Sopenharmony_ci if (msg.type != MSG_PING) 76962306a36Sopenharmony_ci return -1; 77062306a36Sopenharmony_ci to = msg.body.ping.reply_ip; 77162306a36Sopenharmony_ci d_port = msg.body.ping.port; 77262306a36Sopenharmony_ci } 77362306a36Sopenharmony_ci 77462306a36Sopenharmony_ci for (i = 0; i < ping_count ; i++) { 77562306a36Sopenharmony_ci struct timespec sleep_time = { 77662306a36Sopenharmony_ci .tv_sec = 0, 77762306a36Sopenharmony_ci .tv_nsec = ping_delay_nsec, 77862306a36Sopenharmony_ci }; 77962306a36Sopenharmony_ci 78062306a36Sopenharmony_ci ping_succeeded += !func(ping_sock, to, d_port, buf, page_size); 78162306a36Sopenharmony_ci nanosleep(&sleep_time, 0); 78262306a36Sopenharmony_ci } 78362306a36Sopenharmony_ci 78462306a36Sopenharmony_ci close(ping_sock[0]); 78562306a36Sopenharmony_ci close(ping_sock[1]); 78662306a36Sopenharmony_ci 78762306a36Sopenharmony_ci strncpy(to_str, inet_ntoa(*(struct in_addr *)&to), IPV4_STR_SZ - 1); 78862306a36Sopenharmony_ci strncpy(from_str, inet_ntoa(from), IPV4_STR_SZ - 1); 78962306a36Sopenharmony_ci 79062306a36Sopenharmony_ci if (ping_succeeded < ping_success) { 79162306a36Sopenharmony_ci printk("ping (%s) %s->%s failed %u/%u times", 79262306a36Sopenharmony_ci init_side ? "send" : "reply", from_str, to_str, 79362306a36Sopenharmony_ci ping_count - ping_succeeded, ping_count); 79462306a36Sopenharmony_ci return -1; 79562306a36Sopenharmony_ci } 79662306a36Sopenharmony_ci 79762306a36Sopenharmony_ci#ifdef DEBUG 79862306a36Sopenharmony_ci printk("ping (%s) %s->%s succeeded %u/%u times", 79962306a36Sopenharmony_ci init_side ? "send" : "reply", from_str, to_str, 80062306a36Sopenharmony_ci ping_succeeded, ping_count); 80162306a36Sopenharmony_ci#endif 80262306a36Sopenharmony_ci 80362306a36Sopenharmony_ci return 0; 80462306a36Sopenharmony_ci} 80562306a36Sopenharmony_ci 80662306a36Sopenharmony_cistatic int xfrm_fill_key(char *name, char *buf, 80762306a36Sopenharmony_ci size_t buf_len, unsigned int *key_len) 80862306a36Sopenharmony_ci{ 80962306a36Sopenharmony_ci int i; 81062306a36Sopenharmony_ci 81162306a36Sopenharmony_ci for (i = 0; i < XFRM_ALGO_NR_KEYS; i++) { 81262306a36Sopenharmony_ci if (strncmp(name, xfrm_key_entries[i].algo_name, ALGO_LEN) == 0) 81362306a36Sopenharmony_ci *key_len = xfrm_key_entries[i].key_len; 81462306a36Sopenharmony_ci } 81562306a36Sopenharmony_ci 81662306a36Sopenharmony_ci if (*key_len > buf_len) { 81762306a36Sopenharmony_ci printk("Can't pack a key - too big for buffer"); 81862306a36Sopenharmony_ci return -1; 81962306a36Sopenharmony_ci } 82062306a36Sopenharmony_ci 82162306a36Sopenharmony_ci randomize_buffer(buf, *key_len); 82262306a36Sopenharmony_ci 82362306a36Sopenharmony_ci return 0; 82462306a36Sopenharmony_ci} 82562306a36Sopenharmony_ci 82662306a36Sopenharmony_cistatic int xfrm_state_pack_algo(struct nlmsghdr *nh, size_t req_sz, 82762306a36Sopenharmony_ci struct xfrm_desc *desc) 82862306a36Sopenharmony_ci{ 82962306a36Sopenharmony_ci struct { 83062306a36Sopenharmony_ci union { 83162306a36Sopenharmony_ci struct xfrm_algo alg; 83262306a36Sopenharmony_ci struct xfrm_algo_aead aead; 83362306a36Sopenharmony_ci struct xfrm_algo_auth auth; 83462306a36Sopenharmony_ci } u; 83562306a36Sopenharmony_ci char buf[XFRM_ALGO_KEY_BUF_SIZE]; 83662306a36Sopenharmony_ci } alg = {}; 83762306a36Sopenharmony_ci size_t alen, elen, clen, aelen; 83862306a36Sopenharmony_ci unsigned short type; 83962306a36Sopenharmony_ci 84062306a36Sopenharmony_ci alen = strlen(desc->a_algo); 84162306a36Sopenharmony_ci elen = strlen(desc->e_algo); 84262306a36Sopenharmony_ci clen = strlen(desc->c_algo); 84362306a36Sopenharmony_ci aelen = strlen(desc->ae_algo); 84462306a36Sopenharmony_ci 84562306a36Sopenharmony_ci /* Verify desc */ 84662306a36Sopenharmony_ci switch (desc->proto) { 84762306a36Sopenharmony_ci case IPPROTO_AH: 84862306a36Sopenharmony_ci if (!alen || elen || clen || aelen) { 84962306a36Sopenharmony_ci printk("BUG: buggy ah desc"); 85062306a36Sopenharmony_ci return -1; 85162306a36Sopenharmony_ci } 85262306a36Sopenharmony_ci strncpy(alg.u.alg.alg_name, desc->a_algo, ALGO_LEN - 1); 85362306a36Sopenharmony_ci if (xfrm_fill_key(desc->a_algo, alg.u.alg.alg_key, 85462306a36Sopenharmony_ci sizeof(alg.buf), &alg.u.alg.alg_key_len)) 85562306a36Sopenharmony_ci return -1; 85662306a36Sopenharmony_ci type = XFRMA_ALG_AUTH; 85762306a36Sopenharmony_ci break; 85862306a36Sopenharmony_ci case IPPROTO_COMP: 85962306a36Sopenharmony_ci if (!clen || elen || alen || aelen) { 86062306a36Sopenharmony_ci printk("BUG: buggy comp desc"); 86162306a36Sopenharmony_ci return -1; 86262306a36Sopenharmony_ci } 86362306a36Sopenharmony_ci strncpy(alg.u.alg.alg_name, desc->c_algo, ALGO_LEN - 1); 86462306a36Sopenharmony_ci if (xfrm_fill_key(desc->c_algo, alg.u.alg.alg_key, 86562306a36Sopenharmony_ci sizeof(alg.buf), &alg.u.alg.alg_key_len)) 86662306a36Sopenharmony_ci return -1; 86762306a36Sopenharmony_ci type = XFRMA_ALG_COMP; 86862306a36Sopenharmony_ci break; 86962306a36Sopenharmony_ci case IPPROTO_ESP: 87062306a36Sopenharmony_ci if (!((alen && elen) ^ aelen) || clen) { 87162306a36Sopenharmony_ci printk("BUG: buggy esp desc"); 87262306a36Sopenharmony_ci return -1; 87362306a36Sopenharmony_ci } 87462306a36Sopenharmony_ci if (aelen) { 87562306a36Sopenharmony_ci alg.u.aead.alg_icv_len = desc->icv_len; 87662306a36Sopenharmony_ci strncpy(alg.u.aead.alg_name, desc->ae_algo, ALGO_LEN - 1); 87762306a36Sopenharmony_ci if (xfrm_fill_key(desc->ae_algo, alg.u.aead.alg_key, 87862306a36Sopenharmony_ci sizeof(alg.buf), &alg.u.aead.alg_key_len)) 87962306a36Sopenharmony_ci return -1; 88062306a36Sopenharmony_ci type = XFRMA_ALG_AEAD; 88162306a36Sopenharmony_ci } else { 88262306a36Sopenharmony_ci 88362306a36Sopenharmony_ci strncpy(alg.u.alg.alg_name, desc->e_algo, ALGO_LEN - 1); 88462306a36Sopenharmony_ci type = XFRMA_ALG_CRYPT; 88562306a36Sopenharmony_ci if (xfrm_fill_key(desc->e_algo, alg.u.alg.alg_key, 88662306a36Sopenharmony_ci sizeof(alg.buf), &alg.u.alg.alg_key_len)) 88762306a36Sopenharmony_ci return -1; 88862306a36Sopenharmony_ci if (rtattr_pack(nh, req_sz, type, &alg, sizeof(alg))) 88962306a36Sopenharmony_ci return -1; 89062306a36Sopenharmony_ci 89162306a36Sopenharmony_ci strncpy(alg.u.alg.alg_name, desc->a_algo, ALGO_LEN); 89262306a36Sopenharmony_ci type = XFRMA_ALG_AUTH; 89362306a36Sopenharmony_ci if (xfrm_fill_key(desc->a_algo, alg.u.alg.alg_key, 89462306a36Sopenharmony_ci sizeof(alg.buf), &alg.u.alg.alg_key_len)) 89562306a36Sopenharmony_ci return -1; 89662306a36Sopenharmony_ci } 89762306a36Sopenharmony_ci break; 89862306a36Sopenharmony_ci default: 89962306a36Sopenharmony_ci printk("BUG: unknown proto in desc"); 90062306a36Sopenharmony_ci return -1; 90162306a36Sopenharmony_ci } 90262306a36Sopenharmony_ci 90362306a36Sopenharmony_ci if (rtattr_pack(nh, req_sz, type, &alg, sizeof(alg))) 90462306a36Sopenharmony_ci return -1; 90562306a36Sopenharmony_ci 90662306a36Sopenharmony_ci return 0; 90762306a36Sopenharmony_ci} 90862306a36Sopenharmony_ci 90962306a36Sopenharmony_cistatic inline uint32_t gen_spi(struct in_addr src) 91062306a36Sopenharmony_ci{ 91162306a36Sopenharmony_ci return htonl(inet_lnaof(src)); 91262306a36Sopenharmony_ci} 91362306a36Sopenharmony_ci 91462306a36Sopenharmony_cistatic int xfrm_state_add(int xfrm_sock, uint32_t seq, uint32_t spi, 91562306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, 91662306a36Sopenharmony_ci struct xfrm_desc *desc) 91762306a36Sopenharmony_ci{ 91862306a36Sopenharmony_ci struct { 91962306a36Sopenharmony_ci struct nlmsghdr nh; 92062306a36Sopenharmony_ci struct xfrm_usersa_info info; 92162306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 92262306a36Sopenharmony_ci } req; 92362306a36Sopenharmony_ci 92462306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 92562306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.info)); 92662306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_NEWSA; 92762306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 92862306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 92962306a36Sopenharmony_ci 93062306a36Sopenharmony_ci /* Fill selector. */ 93162306a36Sopenharmony_ci memcpy(&req.info.sel.daddr, &dst, sizeof(dst)); 93262306a36Sopenharmony_ci memcpy(&req.info.sel.saddr, &src, sizeof(src)); 93362306a36Sopenharmony_ci req.info.sel.family = AF_INET; 93462306a36Sopenharmony_ci req.info.sel.prefixlen_d = PREFIX_LEN; 93562306a36Sopenharmony_ci req.info.sel.prefixlen_s = PREFIX_LEN; 93662306a36Sopenharmony_ci 93762306a36Sopenharmony_ci /* Fill id */ 93862306a36Sopenharmony_ci memcpy(&req.info.id.daddr, &dst, sizeof(dst)); 93962306a36Sopenharmony_ci /* Note: zero-spi cannot be deleted */ 94062306a36Sopenharmony_ci req.info.id.spi = spi; 94162306a36Sopenharmony_ci req.info.id.proto = desc->proto; 94262306a36Sopenharmony_ci 94362306a36Sopenharmony_ci memcpy(&req.info.saddr, &src, sizeof(src)); 94462306a36Sopenharmony_ci 94562306a36Sopenharmony_ci /* Fill lifteme_cfg */ 94662306a36Sopenharmony_ci req.info.lft.soft_byte_limit = XFRM_INF; 94762306a36Sopenharmony_ci req.info.lft.hard_byte_limit = XFRM_INF; 94862306a36Sopenharmony_ci req.info.lft.soft_packet_limit = XFRM_INF; 94962306a36Sopenharmony_ci req.info.lft.hard_packet_limit = XFRM_INF; 95062306a36Sopenharmony_ci 95162306a36Sopenharmony_ci req.info.family = AF_INET; 95262306a36Sopenharmony_ci req.info.mode = XFRM_MODE_TUNNEL; 95362306a36Sopenharmony_ci 95462306a36Sopenharmony_ci if (xfrm_state_pack_algo(&req.nh, sizeof(req), desc)) 95562306a36Sopenharmony_ci return -1; 95662306a36Sopenharmony_ci 95762306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 95862306a36Sopenharmony_ci pr_err("send()"); 95962306a36Sopenharmony_ci return -1; 96062306a36Sopenharmony_ci } 96162306a36Sopenharmony_ci 96262306a36Sopenharmony_ci return netlink_check_answer(xfrm_sock); 96362306a36Sopenharmony_ci} 96462306a36Sopenharmony_ci 96562306a36Sopenharmony_cistatic bool xfrm_usersa_found(struct xfrm_usersa_info *info, uint32_t spi, 96662306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, 96762306a36Sopenharmony_ci struct xfrm_desc *desc) 96862306a36Sopenharmony_ci{ 96962306a36Sopenharmony_ci if (memcmp(&info->sel.daddr, &dst, sizeof(dst))) 97062306a36Sopenharmony_ci return false; 97162306a36Sopenharmony_ci 97262306a36Sopenharmony_ci if (memcmp(&info->sel.saddr, &src, sizeof(src))) 97362306a36Sopenharmony_ci return false; 97462306a36Sopenharmony_ci 97562306a36Sopenharmony_ci if (info->sel.family != AF_INET || 97662306a36Sopenharmony_ci info->sel.prefixlen_d != PREFIX_LEN || 97762306a36Sopenharmony_ci info->sel.prefixlen_s != PREFIX_LEN) 97862306a36Sopenharmony_ci return false; 97962306a36Sopenharmony_ci 98062306a36Sopenharmony_ci if (info->id.spi != spi || info->id.proto != desc->proto) 98162306a36Sopenharmony_ci return false; 98262306a36Sopenharmony_ci 98362306a36Sopenharmony_ci if (memcmp(&info->id.daddr, &dst, sizeof(dst))) 98462306a36Sopenharmony_ci return false; 98562306a36Sopenharmony_ci 98662306a36Sopenharmony_ci if (memcmp(&info->saddr, &src, sizeof(src))) 98762306a36Sopenharmony_ci return false; 98862306a36Sopenharmony_ci 98962306a36Sopenharmony_ci if (info->lft.soft_byte_limit != XFRM_INF || 99062306a36Sopenharmony_ci info->lft.hard_byte_limit != XFRM_INF || 99162306a36Sopenharmony_ci info->lft.soft_packet_limit != XFRM_INF || 99262306a36Sopenharmony_ci info->lft.hard_packet_limit != XFRM_INF) 99362306a36Sopenharmony_ci return false; 99462306a36Sopenharmony_ci 99562306a36Sopenharmony_ci if (info->family != AF_INET || info->mode != XFRM_MODE_TUNNEL) 99662306a36Sopenharmony_ci return false; 99762306a36Sopenharmony_ci 99862306a36Sopenharmony_ci /* XXX: check xfrm algo, see xfrm_state_pack_algo(). */ 99962306a36Sopenharmony_ci 100062306a36Sopenharmony_ci return true; 100162306a36Sopenharmony_ci} 100262306a36Sopenharmony_ci 100362306a36Sopenharmony_cistatic int xfrm_state_check(int xfrm_sock, uint32_t seq, uint32_t spi, 100462306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, 100562306a36Sopenharmony_ci struct xfrm_desc *desc) 100662306a36Sopenharmony_ci{ 100762306a36Sopenharmony_ci struct { 100862306a36Sopenharmony_ci struct nlmsghdr nh; 100962306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 101062306a36Sopenharmony_ci } req; 101162306a36Sopenharmony_ci struct { 101262306a36Sopenharmony_ci struct nlmsghdr nh; 101362306a36Sopenharmony_ci union { 101462306a36Sopenharmony_ci struct xfrm_usersa_info info; 101562306a36Sopenharmony_ci int error; 101662306a36Sopenharmony_ci }; 101762306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 101862306a36Sopenharmony_ci } answer; 101962306a36Sopenharmony_ci struct xfrm_address_filter filter = {}; 102062306a36Sopenharmony_ci bool found = false; 102162306a36Sopenharmony_ci 102262306a36Sopenharmony_ci 102362306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 102462306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(0); 102562306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_GETSA; 102662306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_DUMP; 102762306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 102862306a36Sopenharmony_ci 102962306a36Sopenharmony_ci /* 103062306a36Sopenharmony_ci * Add dump filter by source address as there may be other tunnels 103162306a36Sopenharmony_ci * in this netns (if tests run in parallel). 103262306a36Sopenharmony_ci */ 103362306a36Sopenharmony_ci filter.family = AF_INET; 103462306a36Sopenharmony_ci filter.splen = 0x1f; /* 0xffffffff mask see addr_match() */ 103562306a36Sopenharmony_ci memcpy(&filter.saddr, &src, sizeof(src)); 103662306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), XFRMA_ADDRESS_FILTER, 103762306a36Sopenharmony_ci &filter, sizeof(filter))) 103862306a36Sopenharmony_ci return -1; 103962306a36Sopenharmony_ci 104062306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 104162306a36Sopenharmony_ci pr_err("send()"); 104262306a36Sopenharmony_ci return -1; 104362306a36Sopenharmony_ci } 104462306a36Sopenharmony_ci 104562306a36Sopenharmony_ci while (1) { 104662306a36Sopenharmony_ci if (recv(xfrm_sock, &answer, sizeof(answer), 0) < 0) { 104762306a36Sopenharmony_ci pr_err("recv()"); 104862306a36Sopenharmony_ci return -1; 104962306a36Sopenharmony_ci } 105062306a36Sopenharmony_ci if (answer.nh.nlmsg_type == NLMSG_ERROR) { 105162306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", 105262306a36Sopenharmony_ci answer.error, strerror(-answer.error)); 105362306a36Sopenharmony_ci return -1; 105462306a36Sopenharmony_ci } else if (answer.nh.nlmsg_type == NLMSG_DONE) { 105562306a36Sopenharmony_ci if (found) 105662306a36Sopenharmony_ci return 0; 105762306a36Sopenharmony_ci printk("didn't find allocated xfrm state in dump"); 105862306a36Sopenharmony_ci return -1; 105962306a36Sopenharmony_ci } else if (answer.nh.nlmsg_type == XFRM_MSG_NEWSA) { 106062306a36Sopenharmony_ci if (xfrm_usersa_found(&answer.info, spi, src, dst, desc)) 106162306a36Sopenharmony_ci found = true; 106262306a36Sopenharmony_ci } 106362306a36Sopenharmony_ci } 106462306a36Sopenharmony_ci} 106562306a36Sopenharmony_ci 106662306a36Sopenharmony_cistatic int xfrm_set(int xfrm_sock, uint32_t *seq, 106762306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, 106862306a36Sopenharmony_ci struct in_addr tunsrc, struct in_addr tundst, 106962306a36Sopenharmony_ci struct xfrm_desc *desc) 107062306a36Sopenharmony_ci{ 107162306a36Sopenharmony_ci int err; 107262306a36Sopenharmony_ci 107362306a36Sopenharmony_ci err = xfrm_state_add(xfrm_sock, (*seq)++, gen_spi(src), src, dst, desc); 107462306a36Sopenharmony_ci if (err) { 107562306a36Sopenharmony_ci printk("Failed to add xfrm state"); 107662306a36Sopenharmony_ci return -1; 107762306a36Sopenharmony_ci } 107862306a36Sopenharmony_ci 107962306a36Sopenharmony_ci err = xfrm_state_add(xfrm_sock, (*seq)++, gen_spi(src), dst, src, desc); 108062306a36Sopenharmony_ci if (err) { 108162306a36Sopenharmony_ci printk("Failed to add xfrm state"); 108262306a36Sopenharmony_ci return -1; 108362306a36Sopenharmony_ci } 108462306a36Sopenharmony_ci 108562306a36Sopenharmony_ci /* Check dumps for XFRM_MSG_GETSA */ 108662306a36Sopenharmony_ci err = xfrm_state_check(xfrm_sock, (*seq)++, gen_spi(src), src, dst, desc); 108762306a36Sopenharmony_ci err |= xfrm_state_check(xfrm_sock, (*seq)++, gen_spi(src), dst, src, desc); 108862306a36Sopenharmony_ci if (err) { 108962306a36Sopenharmony_ci printk("Failed to check xfrm state"); 109062306a36Sopenharmony_ci return -1; 109162306a36Sopenharmony_ci } 109262306a36Sopenharmony_ci 109362306a36Sopenharmony_ci return 0; 109462306a36Sopenharmony_ci} 109562306a36Sopenharmony_ci 109662306a36Sopenharmony_cistatic int xfrm_policy_add(int xfrm_sock, uint32_t seq, uint32_t spi, 109762306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, uint8_t dir, 109862306a36Sopenharmony_ci struct in_addr tunsrc, struct in_addr tundst, uint8_t proto) 109962306a36Sopenharmony_ci{ 110062306a36Sopenharmony_ci struct { 110162306a36Sopenharmony_ci struct nlmsghdr nh; 110262306a36Sopenharmony_ci struct xfrm_userpolicy_info info; 110362306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 110462306a36Sopenharmony_ci } req; 110562306a36Sopenharmony_ci struct xfrm_user_tmpl tmpl; 110662306a36Sopenharmony_ci 110762306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 110862306a36Sopenharmony_ci memset(&tmpl, 0, sizeof(tmpl)); 110962306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.info)); 111062306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_NEWPOLICY; 111162306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 111262306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 111362306a36Sopenharmony_ci 111462306a36Sopenharmony_ci /* Fill selector. */ 111562306a36Sopenharmony_ci memcpy(&req.info.sel.daddr, &dst, sizeof(tundst)); 111662306a36Sopenharmony_ci memcpy(&req.info.sel.saddr, &src, sizeof(tunsrc)); 111762306a36Sopenharmony_ci req.info.sel.family = AF_INET; 111862306a36Sopenharmony_ci req.info.sel.prefixlen_d = PREFIX_LEN; 111962306a36Sopenharmony_ci req.info.sel.prefixlen_s = PREFIX_LEN; 112062306a36Sopenharmony_ci 112162306a36Sopenharmony_ci /* Fill lifteme_cfg */ 112262306a36Sopenharmony_ci req.info.lft.soft_byte_limit = XFRM_INF; 112362306a36Sopenharmony_ci req.info.lft.hard_byte_limit = XFRM_INF; 112462306a36Sopenharmony_ci req.info.lft.soft_packet_limit = XFRM_INF; 112562306a36Sopenharmony_ci req.info.lft.hard_packet_limit = XFRM_INF; 112662306a36Sopenharmony_ci 112762306a36Sopenharmony_ci req.info.dir = dir; 112862306a36Sopenharmony_ci 112962306a36Sopenharmony_ci /* Fill tmpl */ 113062306a36Sopenharmony_ci memcpy(&tmpl.id.daddr, &dst, sizeof(dst)); 113162306a36Sopenharmony_ci /* Note: zero-spi cannot be deleted */ 113262306a36Sopenharmony_ci tmpl.id.spi = spi; 113362306a36Sopenharmony_ci tmpl.id.proto = proto; 113462306a36Sopenharmony_ci tmpl.family = AF_INET; 113562306a36Sopenharmony_ci memcpy(&tmpl.saddr, &src, sizeof(src)); 113662306a36Sopenharmony_ci tmpl.mode = XFRM_MODE_TUNNEL; 113762306a36Sopenharmony_ci tmpl.aalgos = (~(uint32_t)0); 113862306a36Sopenharmony_ci tmpl.ealgos = (~(uint32_t)0); 113962306a36Sopenharmony_ci tmpl.calgos = (~(uint32_t)0); 114062306a36Sopenharmony_ci 114162306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), XFRMA_TMPL, &tmpl, sizeof(tmpl))) 114262306a36Sopenharmony_ci return -1; 114362306a36Sopenharmony_ci 114462306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 114562306a36Sopenharmony_ci pr_err("send()"); 114662306a36Sopenharmony_ci return -1; 114762306a36Sopenharmony_ci } 114862306a36Sopenharmony_ci 114962306a36Sopenharmony_ci return netlink_check_answer(xfrm_sock); 115062306a36Sopenharmony_ci} 115162306a36Sopenharmony_ci 115262306a36Sopenharmony_cistatic int xfrm_prepare(int xfrm_sock, uint32_t *seq, 115362306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, 115462306a36Sopenharmony_ci struct in_addr tunsrc, struct in_addr tundst, uint8_t proto) 115562306a36Sopenharmony_ci{ 115662306a36Sopenharmony_ci if (xfrm_policy_add(xfrm_sock, (*seq)++, gen_spi(src), src, dst, 115762306a36Sopenharmony_ci XFRM_POLICY_OUT, tunsrc, tundst, proto)) { 115862306a36Sopenharmony_ci printk("Failed to add xfrm policy"); 115962306a36Sopenharmony_ci return -1; 116062306a36Sopenharmony_ci } 116162306a36Sopenharmony_ci 116262306a36Sopenharmony_ci if (xfrm_policy_add(xfrm_sock, (*seq)++, gen_spi(src), dst, src, 116362306a36Sopenharmony_ci XFRM_POLICY_IN, tunsrc, tundst, proto)) { 116462306a36Sopenharmony_ci printk("Failed to add xfrm policy"); 116562306a36Sopenharmony_ci return -1; 116662306a36Sopenharmony_ci } 116762306a36Sopenharmony_ci 116862306a36Sopenharmony_ci return 0; 116962306a36Sopenharmony_ci} 117062306a36Sopenharmony_ci 117162306a36Sopenharmony_cistatic int xfrm_policy_del(int xfrm_sock, uint32_t seq, 117262306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, uint8_t dir, 117362306a36Sopenharmony_ci struct in_addr tunsrc, struct in_addr tundst) 117462306a36Sopenharmony_ci{ 117562306a36Sopenharmony_ci struct { 117662306a36Sopenharmony_ci struct nlmsghdr nh; 117762306a36Sopenharmony_ci struct xfrm_userpolicy_id id; 117862306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 117962306a36Sopenharmony_ci } req; 118062306a36Sopenharmony_ci 118162306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 118262306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.id)); 118362306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_DELPOLICY; 118462306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 118562306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 118662306a36Sopenharmony_ci 118762306a36Sopenharmony_ci /* Fill id */ 118862306a36Sopenharmony_ci memcpy(&req.id.sel.daddr, &dst, sizeof(tundst)); 118962306a36Sopenharmony_ci memcpy(&req.id.sel.saddr, &src, sizeof(tunsrc)); 119062306a36Sopenharmony_ci req.id.sel.family = AF_INET; 119162306a36Sopenharmony_ci req.id.sel.prefixlen_d = PREFIX_LEN; 119262306a36Sopenharmony_ci req.id.sel.prefixlen_s = PREFIX_LEN; 119362306a36Sopenharmony_ci req.id.dir = dir; 119462306a36Sopenharmony_ci 119562306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 119662306a36Sopenharmony_ci pr_err("send()"); 119762306a36Sopenharmony_ci return -1; 119862306a36Sopenharmony_ci } 119962306a36Sopenharmony_ci 120062306a36Sopenharmony_ci return netlink_check_answer(xfrm_sock); 120162306a36Sopenharmony_ci} 120262306a36Sopenharmony_ci 120362306a36Sopenharmony_cistatic int xfrm_cleanup(int xfrm_sock, uint32_t *seq, 120462306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, 120562306a36Sopenharmony_ci struct in_addr tunsrc, struct in_addr tundst) 120662306a36Sopenharmony_ci{ 120762306a36Sopenharmony_ci if (xfrm_policy_del(xfrm_sock, (*seq)++, src, dst, 120862306a36Sopenharmony_ci XFRM_POLICY_OUT, tunsrc, tundst)) { 120962306a36Sopenharmony_ci printk("Failed to add xfrm policy"); 121062306a36Sopenharmony_ci return -1; 121162306a36Sopenharmony_ci } 121262306a36Sopenharmony_ci 121362306a36Sopenharmony_ci if (xfrm_policy_del(xfrm_sock, (*seq)++, dst, src, 121462306a36Sopenharmony_ci XFRM_POLICY_IN, tunsrc, tundst)) { 121562306a36Sopenharmony_ci printk("Failed to add xfrm policy"); 121662306a36Sopenharmony_ci return -1; 121762306a36Sopenharmony_ci } 121862306a36Sopenharmony_ci 121962306a36Sopenharmony_ci return 0; 122062306a36Sopenharmony_ci} 122162306a36Sopenharmony_ci 122262306a36Sopenharmony_cistatic int xfrm_state_del(int xfrm_sock, uint32_t seq, uint32_t spi, 122362306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, uint8_t proto) 122462306a36Sopenharmony_ci{ 122562306a36Sopenharmony_ci struct { 122662306a36Sopenharmony_ci struct nlmsghdr nh; 122762306a36Sopenharmony_ci struct xfrm_usersa_id id; 122862306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 122962306a36Sopenharmony_ci } req; 123062306a36Sopenharmony_ci xfrm_address_t saddr = {}; 123162306a36Sopenharmony_ci 123262306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 123362306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.id)); 123462306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_DELSA; 123562306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 123662306a36Sopenharmony_ci req.nh.nlmsg_seq = seq; 123762306a36Sopenharmony_ci 123862306a36Sopenharmony_ci memcpy(&req.id.daddr, &dst, sizeof(dst)); 123962306a36Sopenharmony_ci req.id.family = AF_INET; 124062306a36Sopenharmony_ci req.id.proto = proto; 124162306a36Sopenharmony_ci /* Note: zero-spi cannot be deleted */ 124262306a36Sopenharmony_ci req.id.spi = spi; 124362306a36Sopenharmony_ci 124462306a36Sopenharmony_ci memcpy(&saddr, &src, sizeof(src)); 124562306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), XFRMA_SRCADDR, &saddr, sizeof(saddr))) 124662306a36Sopenharmony_ci return -1; 124762306a36Sopenharmony_ci 124862306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 124962306a36Sopenharmony_ci pr_err("send()"); 125062306a36Sopenharmony_ci return -1; 125162306a36Sopenharmony_ci } 125262306a36Sopenharmony_ci 125362306a36Sopenharmony_ci return netlink_check_answer(xfrm_sock); 125462306a36Sopenharmony_ci} 125562306a36Sopenharmony_ci 125662306a36Sopenharmony_cistatic int xfrm_delete(int xfrm_sock, uint32_t *seq, 125762306a36Sopenharmony_ci struct in_addr src, struct in_addr dst, 125862306a36Sopenharmony_ci struct in_addr tunsrc, struct in_addr tundst, uint8_t proto) 125962306a36Sopenharmony_ci{ 126062306a36Sopenharmony_ci if (xfrm_state_del(xfrm_sock, (*seq)++, gen_spi(src), src, dst, proto)) { 126162306a36Sopenharmony_ci printk("Failed to remove xfrm state"); 126262306a36Sopenharmony_ci return -1; 126362306a36Sopenharmony_ci } 126462306a36Sopenharmony_ci 126562306a36Sopenharmony_ci if (xfrm_state_del(xfrm_sock, (*seq)++, gen_spi(src), dst, src, proto)) { 126662306a36Sopenharmony_ci printk("Failed to remove xfrm state"); 126762306a36Sopenharmony_ci return -1; 126862306a36Sopenharmony_ci } 126962306a36Sopenharmony_ci 127062306a36Sopenharmony_ci return 0; 127162306a36Sopenharmony_ci} 127262306a36Sopenharmony_ci 127362306a36Sopenharmony_cistatic int xfrm_state_allocspi(int xfrm_sock, uint32_t *seq, 127462306a36Sopenharmony_ci uint32_t spi, uint8_t proto) 127562306a36Sopenharmony_ci{ 127662306a36Sopenharmony_ci struct { 127762306a36Sopenharmony_ci struct nlmsghdr nh; 127862306a36Sopenharmony_ci struct xfrm_userspi_info spi; 127962306a36Sopenharmony_ci } req; 128062306a36Sopenharmony_ci struct { 128162306a36Sopenharmony_ci struct nlmsghdr nh; 128262306a36Sopenharmony_ci union { 128362306a36Sopenharmony_ci struct xfrm_usersa_info info; 128462306a36Sopenharmony_ci int error; 128562306a36Sopenharmony_ci }; 128662306a36Sopenharmony_ci } answer; 128762306a36Sopenharmony_ci 128862306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 128962306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.spi)); 129062306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_ALLOCSPI; 129162306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST; 129262306a36Sopenharmony_ci req.nh.nlmsg_seq = (*seq)++; 129362306a36Sopenharmony_ci 129462306a36Sopenharmony_ci req.spi.info.family = AF_INET; 129562306a36Sopenharmony_ci req.spi.min = spi; 129662306a36Sopenharmony_ci req.spi.max = spi; 129762306a36Sopenharmony_ci req.spi.info.id.proto = proto; 129862306a36Sopenharmony_ci 129962306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 130062306a36Sopenharmony_ci pr_err("send()"); 130162306a36Sopenharmony_ci return KSFT_FAIL; 130262306a36Sopenharmony_ci } 130362306a36Sopenharmony_ci 130462306a36Sopenharmony_ci if (recv(xfrm_sock, &answer, sizeof(answer), 0) < 0) { 130562306a36Sopenharmony_ci pr_err("recv()"); 130662306a36Sopenharmony_ci return KSFT_FAIL; 130762306a36Sopenharmony_ci } else if (answer.nh.nlmsg_type == XFRM_MSG_NEWSA) { 130862306a36Sopenharmony_ci uint32_t new_spi = htonl(answer.info.id.spi); 130962306a36Sopenharmony_ci 131062306a36Sopenharmony_ci if (new_spi != spi) { 131162306a36Sopenharmony_ci printk("allocated spi is different from requested: %#x != %#x", 131262306a36Sopenharmony_ci new_spi, spi); 131362306a36Sopenharmony_ci return KSFT_FAIL; 131462306a36Sopenharmony_ci } 131562306a36Sopenharmony_ci return KSFT_PASS; 131662306a36Sopenharmony_ci } else if (answer.nh.nlmsg_type != NLMSG_ERROR) { 131762306a36Sopenharmony_ci printk("expected NLMSG_ERROR, got %d", (int)answer.nh.nlmsg_type); 131862306a36Sopenharmony_ci return KSFT_FAIL; 131962306a36Sopenharmony_ci } 132062306a36Sopenharmony_ci 132162306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", answer.error, strerror(-answer.error)); 132262306a36Sopenharmony_ci return (answer.error) ? KSFT_FAIL : KSFT_PASS; 132362306a36Sopenharmony_ci} 132462306a36Sopenharmony_ci 132562306a36Sopenharmony_cistatic int netlink_sock_bind(int *sock, uint32_t *seq, int proto, uint32_t groups) 132662306a36Sopenharmony_ci{ 132762306a36Sopenharmony_ci struct sockaddr_nl snl = {}; 132862306a36Sopenharmony_ci socklen_t addr_len; 132962306a36Sopenharmony_ci int ret = -1; 133062306a36Sopenharmony_ci 133162306a36Sopenharmony_ci snl.nl_family = AF_NETLINK; 133262306a36Sopenharmony_ci snl.nl_groups = groups; 133362306a36Sopenharmony_ci 133462306a36Sopenharmony_ci if (netlink_sock(sock, seq, proto)) { 133562306a36Sopenharmony_ci printk("Failed to open xfrm netlink socket"); 133662306a36Sopenharmony_ci return -1; 133762306a36Sopenharmony_ci } 133862306a36Sopenharmony_ci 133962306a36Sopenharmony_ci if (bind(*sock, (struct sockaddr *)&snl, sizeof(snl)) < 0) { 134062306a36Sopenharmony_ci pr_err("bind()"); 134162306a36Sopenharmony_ci goto out_close; 134262306a36Sopenharmony_ci } 134362306a36Sopenharmony_ci 134462306a36Sopenharmony_ci addr_len = sizeof(snl); 134562306a36Sopenharmony_ci if (getsockname(*sock, (struct sockaddr *)&snl, &addr_len) < 0) { 134662306a36Sopenharmony_ci pr_err("getsockname()"); 134762306a36Sopenharmony_ci goto out_close; 134862306a36Sopenharmony_ci } 134962306a36Sopenharmony_ci if (addr_len != sizeof(snl)) { 135062306a36Sopenharmony_ci printk("Wrong address length %d", addr_len); 135162306a36Sopenharmony_ci goto out_close; 135262306a36Sopenharmony_ci } 135362306a36Sopenharmony_ci if (snl.nl_family != AF_NETLINK) { 135462306a36Sopenharmony_ci printk("Wrong address family %d", snl.nl_family); 135562306a36Sopenharmony_ci goto out_close; 135662306a36Sopenharmony_ci } 135762306a36Sopenharmony_ci return 0; 135862306a36Sopenharmony_ci 135962306a36Sopenharmony_ciout_close: 136062306a36Sopenharmony_ci close(*sock); 136162306a36Sopenharmony_ci return ret; 136262306a36Sopenharmony_ci} 136362306a36Sopenharmony_ci 136462306a36Sopenharmony_cistatic int xfrm_monitor_acquire(int xfrm_sock, uint32_t *seq, unsigned int nr) 136562306a36Sopenharmony_ci{ 136662306a36Sopenharmony_ci struct { 136762306a36Sopenharmony_ci struct nlmsghdr nh; 136862306a36Sopenharmony_ci union { 136962306a36Sopenharmony_ci struct xfrm_user_acquire acq; 137062306a36Sopenharmony_ci int error; 137162306a36Sopenharmony_ci }; 137262306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 137362306a36Sopenharmony_ci } req; 137462306a36Sopenharmony_ci struct xfrm_user_tmpl xfrm_tmpl = {}; 137562306a36Sopenharmony_ci int xfrm_listen = -1, ret = KSFT_FAIL; 137662306a36Sopenharmony_ci uint32_t seq_listen; 137762306a36Sopenharmony_ci 137862306a36Sopenharmony_ci if (netlink_sock_bind(&xfrm_listen, &seq_listen, NETLINK_XFRM, XFRMNLGRP_ACQUIRE)) 137962306a36Sopenharmony_ci return KSFT_FAIL; 138062306a36Sopenharmony_ci 138162306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 138262306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.acq)); 138362306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_ACQUIRE; 138462306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 138562306a36Sopenharmony_ci req.nh.nlmsg_seq = (*seq)++; 138662306a36Sopenharmony_ci 138762306a36Sopenharmony_ci req.acq.policy.sel.family = AF_INET; 138862306a36Sopenharmony_ci req.acq.aalgos = 0xfeed; 138962306a36Sopenharmony_ci req.acq.ealgos = 0xbaad; 139062306a36Sopenharmony_ci req.acq.calgos = 0xbabe; 139162306a36Sopenharmony_ci 139262306a36Sopenharmony_ci xfrm_tmpl.family = AF_INET; 139362306a36Sopenharmony_ci xfrm_tmpl.id.proto = IPPROTO_ESP; 139462306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), XFRMA_TMPL, &xfrm_tmpl, sizeof(xfrm_tmpl))) 139562306a36Sopenharmony_ci goto out_close; 139662306a36Sopenharmony_ci 139762306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 139862306a36Sopenharmony_ci pr_err("send()"); 139962306a36Sopenharmony_ci goto out_close; 140062306a36Sopenharmony_ci } 140162306a36Sopenharmony_ci 140262306a36Sopenharmony_ci if (recv(xfrm_sock, &req, sizeof(req), 0) < 0) { 140362306a36Sopenharmony_ci pr_err("recv()"); 140462306a36Sopenharmony_ci goto out_close; 140562306a36Sopenharmony_ci } else if (req.nh.nlmsg_type != NLMSG_ERROR) { 140662306a36Sopenharmony_ci printk("expected NLMSG_ERROR, got %d", (int)req.nh.nlmsg_type); 140762306a36Sopenharmony_ci goto out_close; 140862306a36Sopenharmony_ci } 140962306a36Sopenharmony_ci 141062306a36Sopenharmony_ci if (req.error) { 141162306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", req.error, strerror(-req.error)); 141262306a36Sopenharmony_ci ret = req.error; 141362306a36Sopenharmony_ci goto out_close; 141462306a36Sopenharmony_ci } 141562306a36Sopenharmony_ci 141662306a36Sopenharmony_ci if (recv(xfrm_listen, &req, sizeof(req), 0) < 0) { 141762306a36Sopenharmony_ci pr_err("recv()"); 141862306a36Sopenharmony_ci goto out_close; 141962306a36Sopenharmony_ci } 142062306a36Sopenharmony_ci 142162306a36Sopenharmony_ci if (req.acq.aalgos != 0xfeed || req.acq.ealgos != 0xbaad 142262306a36Sopenharmony_ci || req.acq.calgos != 0xbabe) { 142362306a36Sopenharmony_ci printk("xfrm_user_acquire has changed %x %x %x", 142462306a36Sopenharmony_ci req.acq.aalgos, req.acq.ealgos, req.acq.calgos); 142562306a36Sopenharmony_ci goto out_close; 142662306a36Sopenharmony_ci } 142762306a36Sopenharmony_ci 142862306a36Sopenharmony_ci ret = KSFT_PASS; 142962306a36Sopenharmony_ciout_close: 143062306a36Sopenharmony_ci close(xfrm_listen); 143162306a36Sopenharmony_ci return ret; 143262306a36Sopenharmony_ci} 143362306a36Sopenharmony_ci 143462306a36Sopenharmony_cistatic int xfrm_expire_state(int xfrm_sock, uint32_t *seq, 143562306a36Sopenharmony_ci unsigned int nr, struct xfrm_desc *desc) 143662306a36Sopenharmony_ci{ 143762306a36Sopenharmony_ci struct { 143862306a36Sopenharmony_ci struct nlmsghdr nh; 143962306a36Sopenharmony_ci union { 144062306a36Sopenharmony_ci struct xfrm_user_expire expire; 144162306a36Sopenharmony_ci int error; 144262306a36Sopenharmony_ci }; 144362306a36Sopenharmony_ci } req; 144462306a36Sopenharmony_ci struct in_addr src, dst; 144562306a36Sopenharmony_ci int xfrm_listen = -1, ret = KSFT_FAIL; 144662306a36Sopenharmony_ci uint32_t seq_listen; 144762306a36Sopenharmony_ci 144862306a36Sopenharmony_ci src = inet_makeaddr(INADDR_B, child_ip(nr)); 144962306a36Sopenharmony_ci dst = inet_makeaddr(INADDR_B, grchild_ip(nr)); 145062306a36Sopenharmony_ci 145162306a36Sopenharmony_ci if (xfrm_state_add(xfrm_sock, (*seq)++, gen_spi(src), src, dst, desc)) { 145262306a36Sopenharmony_ci printk("Failed to add xfrm state"); 145362306a36Sopenharmony_ci return KSFT_FAIL; 145462306a36Sopenharmony_ci } 145562306a36Sopenharmony_ci 145662306a36Sopenharmony_ci if (netlink_sock_bind(&xfrm_listen, &seq_listen, NETLINK_XFRM, XFRMNLGRP_EXPIRE)) 145762306a36Sopenharmony_ci return KSFT_FAIL; 145862306a36Sopenharmony_ci 145962306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 146062306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.expire)); 146162306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_EXPIRE; 146262306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 146362306a36Sopenharmony_ci req.nh.nlmsg_seq = (*seq)++; 146462306a36Sopenharmony_ci 146562306a36Sopenharmony_ci memcpy(&req.expire.state.id.daddr, &dst, sizeof(dst)); 146662306a36Sopenharmony_ci req.expire.state.id.spi = gen_spi(src); 146762306a36Sopenharmony_ci req.expire.state.id.proto = desc->proto; 146862306a36Sopenharmony_ci req.expire.state.family = AF_INET; 146962306a36Sopenharmony_ci req.expire.hard = 0xff; 147062306a36Sopenharmony_ci 147162306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 147262306a36Sopenharmony_ci pr_err("send()"); 147362306a36Sopenharmony_ci goto out_close; 147462306a36Sopenharmony_ci } 147562306a36Sopenharmony_ci 147662306a36Sopenharmony_ci if (recv(xfrm_sock, &req, sizeof(req), 0) < 0) { 147762306a36Sopenharmony_ci pr_err("recv()"); 147862306a36Sopenharmony_ci goto out_close; 147962306a36Sopenharmony_ci } else if (req.nh.nlmsg_type != NLMSG_ERROR) { 148062306a36Sopenharmony_ci printk("expected NLMSG_ERROR, got %d", (int)req.nh.nlmsg_type); 148162306a36Sopenharmony_ci goto out_close; 148262306a36Sopenharmony_ci } 148362306a36Sopenharmony_ci 148462306a36Sopenharmony_ci if (req.error) { 148562306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", req.error, strerror(-req.error)); 148662306a36Sopenharmony_ci ret = req.error; 148762306a36Sopenharmony_ci goto out_close; 148862306a36Sopenharmony_ci } 148962306a36Sopenharmony_ci 149062306a36Sopenharmony_ci if (recv(xfrm_listen, &req, sizeof(req), 0) < 0) { 149162306a36Sopenharmony_ci pr_err("recv()"); 149262306a36Sopenharmony_ci goto out_close; 149362306a36Sopenharmony_ci } 149462306a36Sopenharmony_ci 149562306a36Sopenharmony_ci if (req.expire.hard != 0x1) { 149662306a36Sopenharmony_ci printk("expire.hard is not set: %x", req.expire.hard); 149762306a36Sopenharmony_ci goto out_close; 149862306a36Sopenharmony_ci } 149962306a36Sopenharmony_ci 150062306a36Sopenharmony_ci ret = KSFT_PASS; 150162306a36Sopenharmony_ciout_close: 150262306a36Sopenharmony_ci close(xfrm_listen); 150362306a36Sopenharmony_ci return ret; 150462306a36Sopenharmony_ci} 150562306a36Sopenharmony_ci 150662306a36Sopenharmony_cistatic int xfrm_expire_policy(int xfrm_sock, uint32_t *seq, 150762306a36Sopenharmony_ci unsigned int nr, struct xfrm_desc *desc) 150862306a36Sopenharmony_ci{ 150962306a36Sopenharmony_ci struct { 151062306a36Sopenharmony_ci struct nlmsghdr nh; 151162306a36Sopenharmony_ci union { 151262306a36Sopenharmony_ci struct xfrm_user_polexpire expire; 151362306a36Sopenharmony_ci int error; 151462306a36Sopenharmony_ci }; 151562306a36Sopenharmony_ci } req; 151662306a36Sopenharmony_ci struct in_addr src, dst, tunsrc, tundst; 151762306a36Sopenharmony_ci int xfrm_listen = -1, ret = KSFT_FAIL; 151862306a36Sopenharmony_ci uint32_t seq_listen; 151962306a36Sopenharmony_ci 152062306a36Sopenharmony_ci src = inet_makeaddr(INADDR_B, child_ip(nr)); 152162306a36Sopenharmony_ci dst = inet_makeaddr(INADDR_B, grchild_ip(nr)); 152262306a36Sopenharmony_ci tunsrc = inet_makeaddr(INADDR_A, child_ip(nr)); 152362306a36Sopenharmony_ci tundst = inet_makeaddr(INADDR_A, grchild_ip(nr)); 152462306a36Sopenharmony_ci 152562306a36Sopenharmony_ci if (xfrm_policy_add(xfrm_sock, (*seq)++, gen_spi(src), src, dst, 152662306a36Sopenharmony_ci XFRM_POLICY_OUT, tunsrc, tundst, desc->proto)) { 152762306a36Sopenharmony_ci printk("Failed to add xfrm policy"); 152862306a36Sopenharmony_ci return KSFT_FAIL; 152962306a36Sopenharmony_ci } 153062306a36Sopenharmony_ci 153162306a36Sopenharmony_ci if (netlink_sock_bind(&xfrm_listen, &seq_listen, NETLINK_XFRM, XFRMNLGRP_EXPIRE)) 153262306a36Sopenharmony_ci return KSFT_FAIL; 153362306a36Sopenharmony_ci 153462306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 153562306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.expire)); 153662306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_POLEXPIRE; 153762306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 153862306a36Sopenharmony_ci req.nh.nlmsg_seq = (*seq)++; 153962306a36Sopenharmony_ci 154062306a36Sopenharmony_ci /* Fill selector. */ 154162306a36Sopenharmony_ci memcpy(&req.expire.pol.sel.daddr, &dst, sizeof(tundst)); 154262306a36Sopenharmony_ci memcpy(&req.expire.pol.sel.saddr, &src, sizeof(tunsrc)); 154362306a36Sopenharmony_ci req.expire.pol.sel.family = AF_INET; 154462306a36Sopenharmony_ci req.expire.pol.sel.prefixlen_d = PREFIX_LEN; 154562306a36Sopenharmony_ci req.expire.pol.sel.prefixlen_s = PREFIX_LEN; 154662306a36Sopenharmony_ci req.expire.pol.dir = XFRM_POLICY_OUT; 154762306a36Sopenharmony_ci req.expire.hard = 0xff; 154862306a36Sopenharmony_ci 154962306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 155062306a36Sopenharmony_ci pr_err("send()"); 155162306a36Sopenharmony_ci goto out_close; 155262306a36Sopenharmony_ci } 155362306a36Sopenharmony_ci 155462306a36Sopenharmony_ci if (recv(xfrm_sock, &req, sizeof(req), 0) < 0) { 155562306a36Sopenharmony_ci pr_err("recv()"); 155662306a36Sopenharmony_ci goto out_close; 155762306a36Sopenharmony_ci } else if (req.nh.nlmsg_type != NLMSG_ERROR) { 155862306a36Sopenharmony_ci printk("expected NLMSG_ERROR, got %d", (int)req.nh.nlmsg_type); 155962306a36Sopenharmony_ci goto out_close; 156062306a36Sopenharmony_ci } 156162306a36Sopenharmony_ci 156262306a36Sopenharmony_ci if (req.error) { 156362306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", req.error, strerror(-req.error)); 156462306a36Sopenharmony_ci ret = req.error; 156562306a36Sopenharmony_ci goto out_close; 156662306a36Sopenharmony_ci } 156762306a36Sopenharmony_ci 156862306a36Sopenharmony_ci if (recv(xfrm_listen, &req, sizeof(req), 0) < 0) { 156962306a36Sopenharmony_ci pr_err("recv()"); 157062306a36Sopenharmony_ci goto out_close; 157162306a36Sopenharmony_ci } 157262306a36Sopenharmony_ci 157362306a36Sopenharmony_ci if (req.expire.hard != 0x1) { 157462306a36Sopenharmony_ci printk("expire.hard is not set: %x", req.expire.hard); 157562306a36Sopenharmony_ci goto out_close; 157662306a36Sopenharmony_ci } 157762306a36Sopenharmony_ci 157862306a36Sopenharmony_ci ret = KSFT_PASS; 157962306a36Sopenharmony_ciout_close: 158062306a36Sopenharmony_ci close(xfrm_listen); 158162306a36Sopenharmony_ci return ret; 158262306a36Sopenharmony_ci} 158362306a36Sopenharmony_ci 158462306a36Sopenharmony_cistatic int xfrm_spdinfo_set_thresh(int xfrm_sock, uint32_t *seq, 158562306a36Sopenharmony_ci unsigned thresh4_l, unsigned thresh4_r, 158662306a36Sopenharmony_ci unsigned thresh6_l, unsigned thresh6_r, 158762306a36Sopenharmony_ci bool add_bad_attr) 158862306a36Sopenharmony_ci 158962306a36Sopenharmony_ci{ 159062306a36Sopenharmony_ci struct { 159162306a36Sopenharmony_ci struct nlmsghdr nh; 159262306a36Sopenharmony_ci union { 159362306a36Sopenharmony_ci uint32_t unused; 159462306a36Sopenharmony_ci int error; 159562306a36Sopenharmony_ci }; 159662306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 159762306a36Sopenharmony_ci } req; 159862306a36Sopenharmony_ci struct xfrmu_spdhthresh thresh; 159962306a36Sopenharmony_ci 160062306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 160162306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.unused)); 160262306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_NEWSPDINFO; 160362306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; 160462306a36Sopenharmony_ci req.nh.nlmsg_seq = (*seq)++; 160562306a36Sopenharmony_ci 160662306a36Sopenharmony_ci thresh.lbits = thresh4_l; 160762306a36Sopenharmony_ci thresh.rbits = thresh4_r; 160862306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), XFRMA_SPD_IPV4_HTHRESH, &thresh, sizeof(thresh))) 160962306a36Sopenharmony_ci return -1; 161062306a36Sopenharmony_ci 161162306a36Sopenharmony_ci thresh.lbits = thresh6_l; 161262306a36Sopenharmony_ci thresh.rbits = thresh6_r; 161362306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), XFRMA_SPD_IPV6_HTHRESH, &thresh, sizeof(thresh))) 161462306a36Sopenharmony_ci return -1; 161562306a36Sopenharmony_ci 161662306a36Sopenharmony_ci if (add_bad_attr) { 161762306a36Sopenharmony_ci BUILD_BUG_ON(XFRMA_IF_ID <= XFRMA_SPD_MAX + 1); 161862306a36Sopenharmony_ci if (rtattr_pack(&req.nh, sizeof(req), XFRMA_IF_ID, NULL, 0)) { 161962306a36Sopenharmony_ci pr_err("adding attribute failed: no space"); 162062306a36Sopenharmony_ci return -1; 162162306a36Sopenharmony_ci } 162262306a36Sopenharmony_ci } 162362306a36Sopenharmony_ci 162462306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 162562306a36Sopenharmony_ci pr_err("send()"); 162662306a36Sopenharmony_ci return -1; 162762306a36Sopenharmony_ci } 162862306a36Sopenharmony_ci 162962306a36Sopenharmony_ci if (recv(xfrm_sock, &req, sizeof(req), 0) < 0) { 163062306a36Sopenharmony_ci pr_err("recv()"); 163162306a36Sopenharmony_ci return -1; 163262306a36Sopenharmony_ci } else if (req.nh.nlmsg_type != NLMSG_ERROR) { 163362306a36Sopenharmony_ci printk("expected NLMSG_ERROR, got %d", (int)req.nh.nlmsg_type); 163462306a36Sopenharmony_ci return -1; 163562306a36Sopenharmony_ci } 163662306a36Sopenharmony_ci 163762306a36Sopenharmony_ci if (req.error) { 163862306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", req.error, strerror(-req.error)); 163962306a36Sopenharmony_ci return -1; 164062306a36Sopenharmony_ci } 164162306a36Sopenharmony_ci 164262306a36Sopenharmony_ci return 0; 164362306a36Sopenharmony_ci} 164462306a36Sopenharmony_ci 164562306a36Sopenharmony_cistatic int xfrm_spdinfo_attrs(int xfrm_sock, uint32_t *seq) 164662306a36Sopenharmony_ci{ 164762306a36Sopenharmony_ci struct { 164862306a36Sopenharmony_ci struct nlmsghdr nh; 164962306a36Sopenharmony_ci union { 165062306a36Sopenharmony_ci uint32_t unused; 165162306a36Sopenharmony_ci int error; 165262306a36Sopenharmony_ci }; 165362306a36Sopenharmony_ci char attrbuf[MAX_PAYLOAD]; 165462306a36Sopenharmony_ci } req; 165562306a36Sopenharmony_ci 165662306a36Sopenharmony_ci if (xfrm_spdinfo_set_thresh(xfrm_sock, seq, 32, 31, 120, 16, false)) { 165762306a36Sopenharmony_ci pr_err("Can't set SPD HTHRESH"); 165862306a36Sopenharmony_ci return KSFT_FAIL; 165962306a36Sopenharmony_ci } 166062306a36Sopenharmony_ci 166162306a36Sopenharmony_ci memset(&req, 0, sizeof(req)); 166262306a36Sopenharmony_ci 166362306a36Sopenharmony_ci req.nh.nlmsg_len = NLMSG_LENGTH(sizeof(req.unused)); 166462306a36Sopenharmony_ci req.nh.nlmsg_type = XFRM_MSG_GETSPDINFO; 166562306a36Sopenharmony_ci req.nh.nlmsg_flags = NLM_F_REQUEST; 166662306a36Sopenharmony_ci req.nh.nlmsg_seq = (*seq)++; 166762306a36Sopenharmony_ci if (send(xfrm_sock, &req, req.nh.nlmsg_len, 0) < 0) { 166862306a36Sopenharmony_ci pr_err("send()"); 166962306a36Sopenharmony_ci return KSFT_FAIL; 167062306a36Sopenharmony_ci } 167162306a36Sopenharmony_ci 167262306a36Sopenharmony_ci if (recv(xfrm_sock, &req, sizeof(req), 0) < 0) { 167362306a36Sopenharmony_ci pr_err("recv()"); 167462306a36Sopenharmony_ci return KSFT_FAIL; 167562306a36Sopenharmony_ci } else if (req.nh.nlmsg_type == XFRM_MSG_NEWSPDINFO) { 167662306a36Sopenharmony_ci size_t len = NLMSG_PAYLOAD(&req.nh, sizeof(req.unused)); 167762306a36Sopenharmony_ci struct rtattr *attr = (void *)req.attrbuf; 167862306a36Sopenharmony_ci int got_thresh = 0; 167962306a36Sopenharmony_ci 168062306a36Sopenharmony_ci for (; RTA_OK(attr, len); attr = RTA_NEXT(attr, len)) { 168162306a36Sopenharmony_ci if (attr->rta_type == XFRMA_SPD_IPV4_HTHRESH) { 168262306a36Sopenharmony_ci struct xfrmu_spdhthresh *t = RTA_DATA(attr); 168362306a36Sopenharmony_ci 168462306a36Sopenharmony_ci got_thresh++; 168562306a36Sopenharmony_ci if (t->lbits != 32 || t->rbits != 31) { 168662306a36Sopenharmony_ci pr_err("thresh differ: %u, %u", 168762306a36Sopenharmony_ci t->lbits, t->rbits); 168862306a36Sopenharmony_ci return KSFT_FAIL; 168962306a36Sopenharmony_ci } 169062306a36Sopenharmony_ci } 169162306a36Sopenharmony_ci if (attr->rta_type == XFRMA_SPD_IPV6_HTHRESH) { 169262306a36Sopenharmony_ci struct xfrmu_spdhthresh *t = RTA_DATA(attr); 169362306a36Sopenharmony_ci 169462306a36Sopenharmony_ci got_thresh++; 169562306a36Sopenharmony_ci if (t->lbits != 120 || t->rbits != 16) { 169662306a36Sopenharmony_ci pr_err("thresh differ: %u, %u", 169762306a36Sopenharmony_ci t->lbits, t->rbits); 169862306a36Sopenharmony_ci return KSFT_FAIL; 169962306a36Sopenharmony_ci } 170062306a36Sopenharmony_ci } 170162306a36Sopenharmony_ci } 170262306a36Sopenharmony_ci if (got_thresh != 2) { 170362306a36Sopenharmony_ci pr_err("only %d thresh returned by XFRM_MSG_GETSPDINFO", got_thresh); 170462306a36Sopenharmony_ci return KSFT_FAIL; 170562306a36Sopenharmony_ci } 170662306a36Sopenharmony_ci } else if (req.nh.nlmsg_type != NLMSG_ERROR) { 170762306a36Sopenharmony_ci printk("expected NLMSG_ERROR, got %d", (int)req.nh.nlmsg_type); 170862306a36Sopenharmony_ci return KSFT_FAIL; 170962306a36Sopenharmony_ci } else { 171062306a36Sopenharmony_ci printk("NLMSG_ERROR: %d: %s", req.error, strerror(-req.error)); 171162306a36Sopenharmony_ci return -1; 171262306a36Sopenharmony_ci } 171362306a36Sopenharmony_ci 171462306a36Sopenharmony_ci /* Restore the default */ 171562306a36Sopenharmony_ci if (xfrm_spdinfo_set_thresh(xfrm_sock, seq, 32, 32, 128, 128, false)) { 171662306a36Sopenharmony_ci pr_err("Can't restore SPD HTHRESH"); 171762306a36Sopenharmony_ci return KSFT_FAIL; 171862306a36Sopenharmony_ci } 171962306a36Sopenharmony_ci 172062306a36Sopenharmony_ci /* 172162306a36Sopenharmony_ci * At this moment xfrm uses nlmsg_parse_deprecated(), which 172262306a36Sopenharmony_ci * implies NL_VALIDATE_LIBERAL - ignoring attributes with 172362306a36Sopenharmony_ci * (type > maxtype). nla_parse_depricated_strict() would enforce 172462306a36Sopenharmony_ci * it. Or even stricter nla_parse(). 172562306a36Sopenharmony_ci * Right now it's not expected to fail, but to be ignored. 172662306a36Sopenharmony_ci */ 172762306a36Sopenharmony_ci if (xfrm_spdinfo_set_thresh(xfrm_sock, seq, 32, 32, 128, 128, true)) 172862306a36Sopenharmony_ci return KSFT_PASS; 172962306a36Sopenharmony_ci 173062306a36Sopenharmony_ci return KSFT_PASS; 173162306a36Sopenharmony_ci} 173262306a36Sopenharmony_ci 173362306a36Sopenharmony_cistatic int child_serv(int xfrm_sock, uint32_t *seq, 173462306a36Sopenharmony_ci unsigned int nr, int cmd_fd, void *buf, struct xfrm_desc *desc) 173562306a36Sopenharmony_ci{ 173662306a36Sopenharmony_ci struct in_addr src, dst, tunsrc, tundst; 173762306a36Sopenharmony_ci struct test_desc msg; 173862306a36Sopenharmony_ci int ret = KSFT_FAIL; 173962306a36Sopenharmony_ci 174062306a36Sopenharmony_ci src = inet_makeaddr(INADDR_B, child_ip(nr)); 174162306a36Sopenharmony_ci dst = inet_makeaddr(INADDR_B, grchild_ip(nr)); 174262306a36Sopenharmony_ci tunsrc = inet_makeaddr(INADDR_A, child_ip(nr)); 174362306a36Sopenharmony_ci tundst = inet_makeaddr(INADDR_A, grchild_ip(nr)); 174462306a36Sopenharmony_ci 174562306a36Sopenharmony_ci /* UDP pinging without xfrm */ 174662306a36Sopenharmony_ci if (do_ping(cmd_fd, buf, page_size, src, true, 0, 0, udp_ping_send)) { 174762306a36Sopenharmony_ci printk("ping failed before setting xfrm"); 174862306a36Sopenharmony_ci return KSFT_FAIL; 174962306a36Sopenharmony_ci } 175062306a36Sopenharmony_ci 175162306a36Sopenharmony_ci memset(&msg, 0, sizeof(msg)); 175262306a36Sopenharmony_ci msg.type = MSG_XFRM_PREPARE; 175362306a36Sopenharmony_ci memcpy(&msg.body.xfrm_desc, desc, sizeof(*desc)); 175462306a36Sopenharmony_ci write_msg(cmd_fd, &msg, 1); 175562306a36Sopenharmony_ci 175662306a36Sopenharmony_ci if (xfrm_prepare(xfrm_sock, seq, src, dst, tunsrc, tundst, desc->proto)) { 175762306a36Sopenharmony_ci printk("failed to prepare xfrm"); 175862306a36Sopenharmony_ci goto cleanup; 175962306a36Sopenharmony_ci } 176062306a36Sopenharmony_ci 176162306a36Sopenharmony_ci memset(&msg, 0, sizeof(msg)); 176262306a36Sopenharmony_ci msg.type = MSG_XFRM_ADD; 176362306a36Sopenharmony_ci memcpy(&msg.body.xfrm_desc, desc, sizeof(*desc)); 176462306a36Sopenharmony_ci write_msg(cmd_fd, &msg, 1); 176562306a36Sopenharmony_ci if (xfrm_set(xfrm_sock, seq, src, dst, tunsrc, tundst, desc)) { 176662306a36Sopenharmony_ci printk("failed to set xfrm"); 176762306a36Sopenharmony_ci goto delete; 176862306a36Sopenharmony_ci } 176962306a36Sopenharmony_ci 177062306a36Sopenharmony_ci /* UDP pinging with xfrm tunnel */ 177162306a36Sopenharmony_ci if (do_ping(cmd_fd, buf, page_size, tunsrc, 177262306a36Sopenharmony_ci true, 0, 0, udp_ping_send)) { 177362306a36Sopenharmony_ci printk("ping failed for xfrm"); 177462306a36Sopenharmony_ci goto delete; 177562306a36Sopenharmony_ci } 177662306a36Sopenharmony_ci 177762306a36Sopenharmony_ci ret = KSFT_PASS; 177862306a36Sopenharmony_cidelete: 177962306a36Sopenharmony_ci /* xfrm delete */ 178062306a36Sopenharmony_ci memset(&msg, 0, sizeof(msg)); 178162306a36Sopenharmony_ci msg.type = MSG_XFRM_DEL; 178262306a36Sopenharmony_ci memcpy(&msg.body.xfrm_desc, desc, sizeof(*desc)); 178362306a36Sopenharmony_ci write_msg(cmd_fd, &msg, 1); 178462306a36Sopenharmony_ci 178562306a36Sopenharmony_ci if (xfrm_delete(xfrm_sock, seq, src, dst, tunsrc, tundst, desc->proto)) { 178662306a36Sopenharmony_ci printk("failed ping to remove xfrm"); 178762306a36Sopenharmony_ci ret = KSFT_FAIL; 178862306a36Sopenharmony_ci } 178962306a36Sopenharmony_ci 179062306a36Sopenharmony_cicleanup: 179162306a36Sopenharmony_ci memset(&msg, 0, sizeof(msg)); 179262306a36Sopenharmony_ci msg.type = MSG_XFRM_CLEANUP; 179362306a36Sopenharmony_ci memcpy(&msg.body.xfrm_desc, desc, sizeof(*desc)); 179462306a36Sopenharmony_ci write_msg(cmd_fd, &msg, 1); 179562306a36Sopenharmony_ci if (xfrm_cleanup(xfrm_sock, seq, src, dst, tunsrc, tundst)) { 179662306a36Sopenharmony_ci printk("failed ping to cleanup xfrm"); 179762306a36Sopenharmony_ci ret = KSFT_FAIL; 179862306a36Sopenharmony_ci } 179962306a36Sopenharmony_ci return ret; 180062306a36Sopenharmony_ci} 180162306a36Sopenharmony_ci 180262306a36Sopenharmony_cistatic int child_f(unsigned int nr, int test_desc_fd, int cmd_fd, void *buf) 180362306a36Sopenharmony_ci{ 180462306a36Sopenharmony_ci struct xfrm_desc desc; 180562306a36Sopenharmony_ci struct test_desc msg; 180662306a36Sopenharmony_ci int xfrm_sock = -1; 180762306a36Sopenharmony_ci uint32_t seq; 180862306a36Sopenharmony_ci 180962306a36Sopenharmony_ci if (switch_ns(nsfd_childa)) 181062306a36Sopenharmony_ci exit(KSFT_FAIL); 181162306a36Sopenharmony_ci 181262306a36Sopenharmony_ci if (netlink_sock(&xfrm_sock, &seq, NETLINK_XFRM)) { 181362306a36Sopenharmony_ci printk("Failed to open xfrm netlink socket"); 181462306a36Sopenharmony_ci exit(KSFT_FAIL); 181562306a36Sopenharmony_ci } 181662306a36Sopenharmony_ci 181762306a36Sopenharmony_ci /* Check that seq sock is ready, just for sure. */ 181862306a36Sopenharmony_ci memset(&msg, 0, sizeof(msg)); 181962306a36Sopenharmony_ci msg.type = MSG_ACK; 182062306a36Sopenharmony_ci write_msg(cmd_fd, &msg, 1); 182162306a36Sopenharmony_ci read_msg(cmd_fd, &msg, 1); 182262306a36Sopenharmony_ci if (msg.type != MSG_ACK) { 182362306a36Sopenharmony_ci printk("Ack failed"); 182462306a36Sopenharmony_ci exit(KSFT_FAIL); 182562306a36Sopenharmony_ci } 182662306a36Sopenharmony_ci 182762306a36Sopenharmony_ci for (;;) { 182862306a36Sopenharmony_ci ssize_t received = read(test_desc_fd, &desc, sizeof(desc)); 182962306a36Sopenharmony_ci int ret; 183062306a36Sopenharmony_ci 183162306a36Sopenharmony_ci if (received == 0) /* EOF */ 183262306a36Sopenharmony_ci break; 183362306a36Sopenharmony_ci 183462306a36Sopenharmony_ci if (received != sizeof(desc)) { 183562306a36Sopenharmony_ci pr_err("read() returned %zd", received); 183662306a36Sopenharmony_ci exit(KSFT_FAIL); 183762306a36Sopenharmony_ci } 183862306a36Sopenharmony_ci 183962306a36Sopenharmony_ci switch (desc.type) { 184062306a36Sopenharmony_ci case CREATE_TUNNEL: 184162306a36Sopenharmony_ci ret = child_serv(xfrm_sock, &seq, nr, 184262306a36Sopenharmony_ci cmd_fd, buf, &desc); 184362306a36Sopenharmony_ci break; 184462306a36Sopenharmony_ci case ALLOCATE_SPI: 184562306a36Sopenharmony_ci ret = xfrm_state_allocspi(xfrm_sock, &seq, 184662306a36Sopenharmony_ci -1, desc.proto); 184762306a36Sopenharmony_ci break; 184862306a36Sopenharmony_ci case MONITOR_ACQUIRE: 184962306a36Sopenharmony_ci ret = xfrm_monitor_acquire(xfrm_sock, &seq, nr); 185062306a36Sopenharmony_ci break; 185162306a36Sopenharmony_ci case EXPIRE_STATE: 185262306a36Sopenharmony_ci ret = xfrm_expire_state(xfrm_sock, &seq, nr, &desc); 185362306a36Sopenharmony_ci break; 185462306a36Sopenharmony_ci case EXPIRE_POLICY: 185562306a36Sopenharmony_ci ret = xfrm_expire_policy(xfrm_sock, &seq, nr, &desc); 185662306a36Sopenharmony_ci break; 185762306a36Sopenharmony_ci case SPDINFO_ATTRS: 185862306a36Sopenharmony_ci ret = xfrm_spdinfo_attrs(xfrm_sock, &seq); 185962306a36Sopenharmony_ci break; 186062306a36Sopenharmony_ci default: 186162306a36Sopenharmony_ci printk("Unknown desc type %d", desc.type); 186262306a36Sopenharmony_ci exit(KSFT_FAIL); 186362306a36Sopenharmony_ci } 186462306a36Sopenharmony_ci write_test_result(ret, &desc); 186562306a36Sopenharmony_ci } 186662306a36Sopenharmony_ci 186762306a36Sopenharmony_ci close(xfrm_sock); 186862306a36Sopenharmony_ci 186962306a36Sopenharmony_ci msg.type = MSG_EXIT; 187062306a36Sopenharmony_ci write_msg(cmd_fd, &msg, 1); 187162306a36Sopenharmony_ci exit(KSFT_PASS); 187262306a36Sopenharmony_ci} 187362306a36Sopenharmony_ci 187462306a36Sopenharmony_cistatic void grand_child_serv(unsigned int nr, int cmd_fd, void *buf, 187562306a36Sopenharmony_ci struct test_desc *msg, int xfrm_sock, uint32_t *seq) 187662306a36Sopenharmony_ci{ 187762306a36Sopenharmony_ci struct in_addr src, dst, tunsrc, tundst; 187862306a36Sopenharmony_ci bool tun_reply; 187962306a36Sopenharmony_ci struct xfrm_desc *desc = &msg->body.xfrm_desc; 188062306a36Sopenharmony_ci 188162306a36Sopenharmony_ci src = inet_makeaddr(INADDR_B, grchild_ip(nr)); 188262306a36Sopenharmony_ci dst = inet_makeaddr(INADDR_B, child_ip(nr)); 188362306a36Sopenharmony_ci tunsrc = inet_makeaddr(INADDR_A, grchild_ip(nr)); 188462306a36Sopenharmony_ci tundst = inet_makeaddr(INADDR_A, child_ip(nr)); 188562306a36Sopenharmony_ci 188662306a36Sopenharmony_ci switch (msg->type) { 188762306a36Sopenharmony_ci case MSG_EXIT: 188862306a36Sopenharmony_ci exit(KSFT_PASS); 188962306a36Sopenharmony_ci case MSG_ACK: 189062306a36Sopenharmony_ci write_msg(cmd_fd, msg, 1); 189162306a36Sopenharmony_ci break; 189262306a36Sopenharmony_ci case MSG_PING: 189362306a36Sopenharmony_ci tun_reply = memcmp(&dst, &msg->body.ping.reply_ip, sizeof(in_addr_t)); 189462306a36Sopenharmony_ci /* UDP pinging without xfrm */ 189562306a36Sopenharmony_ci if (do_ping(cmd_fd, buf, page_size, tun_reply ? tunsrc : src, 189662306a36Sopenharmony_ci false, msg->body.ping.port, 189762306a36Sopenharmony_ci msg->body.ping.reply_ip, udp_ping_reply)) { 189862306a36Sopenharmony_ci printk("ping failed before setting xfrm"); 189962306a36Sopenharmony_ci } 190062306a36Sopenharmony_ci break; 190162306a36Sopenharmony_ci case MSG_XFRM_PREPARE: 190262306a36Sopenharmony_ci if (xfrm_prepare(xfrm_sock, seq, src, dst, tunsrc, tundst, 190362306a36Sopenharmony_ci desc->proto)) { 190462306a36Sopenharmony_ci xfrm_cleanup(xfrm_sock, seq, src, dst, tunsrc, tundst); 190562306a36Sopenharmony_ci printk("failed to prepare xfrm"); 190662306a36Sopenharmony_ci } 190762306a36Sopenharmony_ci break; 190862306a36Sopenharmony_ci case MSG_XFRM_ADD: 190962306a36Sopenharmony_ci if (xfrm_set(xfrm_sock, seq, src, dst, tunsrc, tundst, desc)) { 191062306a36Sopenharmony_ci xfrm_cleanup(xfrm_sock, seq, src, dst, tunsrc, tundst); 191162306a36Sopenharmony_ci printk("failed to set xfrm"); 191262306a36Sopenharmony_ci } 191362306a36Sopenharmony_ci break; 191462306a36Sopenharmony_ci case MSG_XFRM_DEL: 191562306a36Sopenharmony_ci if (xfrm_delete(xfrm_sock, seq, src, dst, tunsrc, tundst, 191662306a36Sopenharmony_ci desc->proto)) { 191762306a36Sopenharmony_ci xfrm_cleanup(xfrm_sock, seq, src, dst, tunsrc, tundst); 191862306a36Sopenharmony_ci printk("failed to remove xfrm"); 191962306a36Sopenharmony_ci } 192062306a36Sopenharmony_ci break; 192162306a36Sopenharmony_ci case MSG_XFRM_CLEANUP: 192262306a36Sopenharmony_ci if (xfrm_cleanup(xfrm_sock, seq, src, dst, tunsrc, tundst)) { 192362306a36Sopenharmony_ci printk("failed to cleanup xfrm"); 192462306a36Sopenharmony_ci } 192562306a36Sopenharmony_ci break; 192662306a36Sopenharmony_ci default: 192762306a36Sopenharmony_ci printk("got unknown msg type %d", msg->type); 192862306a36Sopenharmony_ci } 192962306a36Sopenharmony_ci} 193062306a36Sopenharmony_ci 193162306a36Sopenharmony_cistatic int grand_child_f(unsigned int nr, int cmd_fd, void *buf) 193262306a36Sopenharmony_ci{ 193362306a36Sopenharmony_ci struct test_desc msg; 193462306a36Sopenharmony_ci int xfrm_sock = -1; 193562306a36Sopenharmony_ci uint32_t seq; 193662306a36Sopenharmony_ci 193762306a36Sopenharmony_ci if (switch_ns(nsfd_childb)) 193862306a36Sopenharmony_ci exit(KSFT_FAIL); 193962306a36Sopenharmony_ci 194062306a36Sopenharmony_ci if (netlink_sock(&xfrm_sock, &seq, NETLINK_XFRM)) { 194162306a36Sopenharmony_ci printk("Failed to open xfrm netlink socket"); 194262306a36Sopenharmony_ci exit(KSFT_FAIL); 194362306a36Sopenharmony_ci } 194462306a36Sopenharmony_ci 194562306a36Sopenharmony_ci do { 194662306a36Sopenharmony_ci read_msg(cmd_fd, &msg, 1); 194762306a36Sopenharmony_ci grand_child_serv(nr, cmd_fd, buf, &msg, xfrm_sock, &seq); 194862306a36Sopenharmony_ci } while (1); 194962306a36Sopenharmony_ci 195062306a36Sopenharmony_ci close(xfrm_sock); 195162306a36Sopenharmony_ci exit(KSFT_FAIL); 195262306a36Sopenharmony_ci} 195362306a36Sopenharmony_ci 195462306a36Sopenharmony_cistatic int start_child(unsigned int nr, char *veth, int test_desc_fd[2]) 195562306a36Sopenharmony_ci{ 195662306a36Sopenharmony_ci int cmd_sock[2]; 195762306a36Sopenharmony_ci void *data_map; 195862306a36Sopenharmony_ci pid_t child; 195962306a36Sopenharmony_ci 196062306a36Sopenharmony_ci if (init_child(nsfd_childa, veth, child_ip(nr), grchild_ip(nr))) 196162306a36Sopenharmony_ci return -1; 196262306a36Sopenharmony_ci 196362306a36Sopenharmony_ci if (init_child(nsfd_childb, veth, grchild_ip(nr), child_ip(nr))) 196462306a36Sopenharmony_ci return -1; 196562306a36Sopenharmony_ci 196662306a36Sopenharmony_ci child = fork(); 196762306a36Sopenharmony_ci if (child < 0) { 196862306a36Sopenharmony_ci pr_err("fork()"); 196962306a36Sopenharmony_ci return -1; 197062306a36Sopenharmony_ci } else if (child) { 197162306a36Sopenharmony_ci /* in parent - selftest */ 197262306a36Sopenharmony_ci return switch_ns(nsfd_parent); 197362306a36Sopenharmony_ci } 197462306a36Sopenharmony_ci 197562306a36Sopenharmony_ci if (close(test_desc_fd[1])) { 197662306a36Sopenharmony_ci pr_err("close()"); 197762306a36Sopenharmony_ci return -1; 197862306a36Sopenharmony_ci } 197962306a36Sopenharmony_ci 198062306a36Sopenharmony_ci /* child */ 198162306a36Sopenharmony_ci data_map = mmap(0, page_size, PROT_READ | PROT_WRITE, 198262306a36Sopenharmony_ci MAP_SHARED | MAP_ANONYMOUS, -1, 0); 198362306a36Sopenharmony_ci if (data_map == MAP_FAILED) { 198462306a36Sopenharmony_ci pr_err("mmap()"); 198562306a36Sopenharmony_ci return -1; 198662306a36Sopenharmony_ci } 198762306a36Sopenharmony_ci 198862306a36Sopenharmony_ci randomize_buffer(data_map, page_size); 198962306a36Sopenharmony_ci 199062306a36Sopenharmony_ci if (socketpair(PF_LOCAL, SOCK_SEQPACKET, 0, cmd_sock)) { 199162306a36Sopenharmony_ci pr_err("socketpair()"); 199262306a36Sopenharmony_ci return -1; 199362306a36Sopenharmony_ci } 199462306a36Sopenharmony_ci 199562306a36Sopenharmony_ci child = fork(); 199662306a36Sopenharmony_ci if (child < 0) { 199762306a36Sopenharmony_ci pr_err("fork()"); 199862306a36Sopenharmony_ci return -1; 199962306a36Sopenharmony_ci } else if (child) { 200062306a36Sopenharmony_ci if (close(cmd_sock[0])) { 200162306a36Sopenharmony_ci pr_err("close()"); 200262306a36Sopenharmony_ci return -1; 200362306a36Sopenharmony_ci } 200462306a36Sopenharmony_ci return child_f(nr, test_desc_fd[0], cmd_sock[1], data_map); 200562306a36Sopenharmony_ci } 200662306a36Sopenharmony_ci if (close(cmd_sock[1])) { 200762306a36Sopenharmony_ci pr_err("close()"); 200862306a36Sopenharmony_ci return -1; 200962306a36Sopenharmony_ci } 201062306a36Sopenharmony_ci return grand_child_f(nr, cmd_sock[0], data_map); 201162306a36Sopenharmony_ci} 201262306a36Sopenharmony_ci 201362306a36Sopenharmony_cistatic void exit_usage(char **argv) 201462306a36Sopenharmony_ci{ 201562306a36Sopenharmony_ci printk("Usage: %s [nr_process]", argv[0]); 201662306a36Sopenharmony_ci exit(KSFT_FAIL); 201762306a36Sopenharmony_ci} 201862306a36Sopenharmony_ci 201962306a36Sopenharmony_cistatic int __write_desc(int test_desc_fd, struct xfrm_desc *desc) 202062306a36Sopenharmony_ci{ 202162306a36Sopenharmony_ci ssize_t ret; 202262306a36Sopenharmony_ci 202362306a36Sopenharmony_ci ret = write(test_desc_fd, desc, sizeof(*desc)); 202462306a36Sopenharmony_ci 202562306a36Sopenharmony_ci if (ret == sizeof(*desc)) 202662306a36Sopenharmony_ci return 0; 202762306a36Sopenharmony_ci 202862306a36Sopenharmony_ci pr_err("Writing test's desc failed %ld", ret); 202962306a36Sopenharmony_ci 203062306a36Sopenharmony_ci return -1; 203162306a36Sopenharmony_ci} 203262306a36Sopenharmony_ci 203362306a36Sopenharmony_cistatic int write_desc(int proto, int test_desc_fd, 203462306a36Sopenharmony_ci char *a, char *e, char *c, char *ae) 203562306a36Sopenharmony_ci{ 203662306a36Sopenharmony_ci struct xfrm_desc desc = {}; 203762306a36Sopenharmony_ci 203862306a36Sopenharmony_ci desc.type = CREATE_TUNNEL; 203962306a36Sopenharmony_ci desc.proto = proto; 204062306a36Sopenharmony_ci 204162306a36Sopenharmony_ci if (a) 204262306a36Sopenharmony_ci strncpy(desc.a_algo, a, ALGO_LEN - 1); 204362306a36Sopenharmony_ci if (e) 204462306a36Sopenharmony_ci strncpy(desc.e_algo, e, ALGO_LEN - 1); 204562306a36Sopenharmony_ci if (c) 204662306a36Sopenharmony_ci strncpy(desc.c_algo, c, ALGO_LEN - 1); 204762306a36Sopenharmony_ci if (ae) 204862306a36Sopenharmony_ci strncpy(desc.ae_algo, ae, ALGO_LEN - 1); 204962306a36Sopenharmony_ci 205062306a36Sopenharmony_ci return __write_desc(test_desc_fd, &desc); 205162306a36Sopenharmony_ci} 205262306a36Sopenharmony_ci 205362306a36Sopenharmony_ciint proto_list[] = { IPPROTO_AH, IPPROTO_COMP, IPPROTO_ESP }; 205462306a36Sopenharmony_cichar *ah_list[] = { 205562306a36Sopenharmony_ci "digest_null", "hmac(md5)", "hmac(sha1)", "hmac(sha256)", 205662306a36Sopenharmony_ci "hmac(sha384)", "hmac(sha512)", "hmac(rmd160)", 205762306a36Sopenharmony_ci "xcbc(aes)", "cmac(aes)" 205862306a36Sopenharmony_ci}; 205962306a36Sopenharmony_cichar *comp_list[] = { 206062306a36Sopenharmony_ci "deflate", 206162306a36Sopenharmony_ci#if 0 206262306a36Sopenharmony_ci /* No compression backend realization */ 206362306a36Sopenharmony_ci "lzs", "lzjh" 206462306a36Sopenharmony_ci#endif 206562306a36Sopenharmony_ci}; 206662306a36Sopenharmony_cichar *e_list[] = { 206762306a36Sopenharmony_ci "ecb(cipher_null)", "cbc(des)", "cbc(des3_ede)", "cbc(cast5)", 206862306a36Sopenharmony_ci "cbc(blowfish)", "cbc(aes)", "cbc(serpent)", "cbc(camellia)", 206962306a36Sopenharmony_ci "cbc(twofish)", "rfc3686(ctr(aes))" 207062306a36Sopenharmony_ci}; 207162306a36Sopenharmony_cichar *ae_list[] = { 207262306a36Sopenharmony_ci#if 0 207362306a36Sopenharmony_ci /* not implemented */ 207462306a36Sopenharmony_ci "rfc4106(gcm(aes))", "rfc4309(ccm(aes))", "rfc4543(gcm(aes))", 207562306a36Sopenharmony_ci "rfc7539esp(chacha20,poly1305)" 207662306a36Sopenharmony_ci#endif 207762306a36Sopenharmony_ci}; 207862306a36Sopenharmony_ci 207962306a36Sopenharmony_ciconst unsigned int proto_plan = ARRAY_SIZE(ah_list) + ARRAY_SIZE(comp_list) \ 208062306a36Sopenharmony_ci + (ARRAY_SIZE(ah_list) * ARRAY_SIZE(e_list)) \ 208162306a36Sopenharmony_ci + ARRAY_SIZE(ae_list); 208262306a36Sopenharmony_ci 208362306a36Sopenharmony_cistatic int write_proto_plan(int fd, int proto) 208462306a36Sopenharmony_ci{ 208562306a36Sopenharmony_ci unsigned int i; 208662306a36Sopenharmony_ci 208762306a36Sopenharmony_ci switch (proto) { 208862306a36Sopenharmony_ci case IPPROTO_AH: 208962306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(ah_list); i++) { 209062306a36Sopenharmony_ci if (write_desc(proto, fd, ah_list[i], 0, 0, 0)) 209162306a36Sopenharmony_ci return -1; 209262306a36Sopenharmony_ci } 209362306a36Sopenharmony_ci break; 209462306a36Sopenharmony_ci case IPPROTO_COMP: 209562306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(comp_list); i++) { 209662306a36Sopenharmony_ci if (write_desc(proto, fd, 0, 0, comp_list[i], 0)) 209762306a36Sopenharmony_ci return -1; 209862306a36Sopenharmony_ci } 209962306a36Sopenharmony_ci break; 210062306a36Sopenharmony_ci case IPPROTO_ESP: 210162306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(ah_list); i++) { 210262306a36Sopenharmony_ci int j; 210362306a36Sopenharmony_ci 210462306a36Sopenharmony_ci for (j = 0; j < ARRAY_SIZE(e_list); j++) { 210562306a36Sopenharmony_ci if (write_desc(proto, fd, ah_list[i], 210662306a36Sopenharmony_ci e_list[j], 0, 0)) 210762306a36Sopenharmony_ci return -1; 210862306a36Sopenharmony_ci } 210962306a36Sopenharmony_ci } 211062306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(ae_list); i++) { 211162306a36Sopenharmony_ci if (write_desc(proto, fd, 0, 0, 0, ae_list[i])) 211262306a36Sopenharmony_ci return -1; 211362306a36Sopenharmony_ci } 211462306a36Sopenharmony_ci break; 211562306a36Sopenharmony_ci default: 211662306a36Sopenharmony_ci printk("BUG: Specified unknown proto %d", proto); 211762306a36Sopenharmony_ci return -1; 211862306a36Sopenharmony_ci } 211962306a36Sopenharmony_ci 212062306a36Sopenharmony_ci return 0; 212162306a36Sopenharmony_ci} 212262306a36Sopenharmony_ci 212362306a36Sopenharmony_ci/* 212462306a36Sopenharmony_ci * Some structures in xfrm uapi header differ in size between 212562306a36Sopenharmony_ci * 64-bit and 32-bit ABI: 212662306a36Sopenharmony_ci * 212762306a36Sopenharmony_ci * 32-bit UABI | 64-bit UABI 212862306a36Sopenharmony_ci * -------------------------------------|------------------------------------- 212962306a36Sopenharmony_ci * sizeof(xfrm_usersa_info) = 220 | sizeof(xfrm_usersa_info) = 224 213062306a36Sopenharmony_ci * sizeof(xfrm_userpolicy_info) = 164 | sizeof(xfrm_userpolicy_info) = 168 213162306a36Sopenharmony_ci * sizeof(xfrm_userspi_info) = 228 | sizeof(xfrm_userspi_info) = 232 213262306a36Sopenharmony_ci * sizeof(xfrm_user_acquire) = 276 | sizeof(xfrm_user_acquire) = 280 213362306a36Sopenharmony_ci * sizeof(xfrm_user_expire) = 224 | sizeof(xfrm_user_expire) = 232 213462306a36Sopenharmony_ci * sizeof(xfrm_user_polexpire) = 168 | sizeof(xfrm_user_polexpire) = 176 213562306a36Sopenharmony_ci * 213662306a36Sopenharmony_ci * Check the affected by the UABI difference structures. 213762306a36Sopenharmony_ci * Also, check translation for xfrm_set_spdinfo: it has it's own attributes 213862306a36Sopenharmony_ci * which needs to be correctly copied, but not translated. 213962306a36Sopenharmony_ci */ 214062306a36Sopenharmony_ciconst unsigned int compat_plan = 5; 214162306a36Sopenharmony_cistatic int write_compat_struct_tests(int test_desc_fd) 214262306a36Sopenharmony_ci{ 214362306a36Sopenharmony_ci struct xfrm_desc desc = {}; 214462306a36Sopenharmony_ci 214562306a36Sopenharmony_ci desc.type = ALLOCATE_SPI; 214662306a36Sopenharmony_ci desc.proto = IPPROTO_AH; 214762306a36Sopenharmony_ci strncpy(desc.a_algo, ah_list[0], ALGO_LEN - 1); 214862306a36Sopenharmony_ci 214962306a36Sopenharmony_ci if (__write_desc(test_desc_fd, &desc)) 215062306a36Sopenharmony_ci return -1; 215162306a36Sopenharmony_ci 215262306a36Sopenharmony_ci desc.type = MONITOR_ACQUIRE; 215362306a36Sopenharmony_ci if (__write_desc(test_desc_fd, &desc)) 215462306a36Sopenharmony_ci return -1; 215562306a36Sopenharmony_ci 215662306a36Sopenharmony_ci desc.type = EXPIRE_STATE; 215762306a36Sopenharmony_ci if (__write_desc(test_desc_fd, &desc)) 215862306a36Sopenharmony_ci return -1; 215962306a36Sopenharmony_ci 216062306a36Sopenharmony_ci desc.type = EXPIRE_POLICY; 216162306a36Sopenharmony_ci if (__write_desc(test_desc_fd, &desc)) 216262306a36Sopenharmony_ci return -1; 216362306a36Sopenharmony_ci 216462306a36Sopenharmony_ci desc.type = SPDINFO_ATTRS; 216562306a36Sopenharmony_ci if (__write_desc(test_desc_fd, &desc)) 216662306a36Sopenharmony_ci return -1; 216762306a36Sopenharmony_ci 216862306a36Sopenharmony_ci return 0; 216962306a36Sopenharmony_ci} 217062306a36Sopenharmony_ci 217162306a36Sopenharmony_cistatic int write_test_plan(int test_desc_fd) 217262306a36Sopenharmony_ci{ 217362306a36Sopenharmony_ci unsigned int i; 217462306a36Sopenharmony_ci pid_t child; 217562306a36Sopenharmony_ci 217662306a36Sopenharmony_ci child = fork(); 217762306a36Sopenharmony_ci if (child < 0) { 217862306a36Sopenharmony_ci pr_err("fork()"); 217962306a36Sopenharmony_ci return -1; 218062306a36Sopenharmony_ci } 218162306a36Sopenharmony_ci if (child) { 218262306a36Sopenharmony_ci if (close(test_desc_fd)) 218362306a36Sopenharmony_ci printk("close(): %m"); 218462306a36Sopenharmony_ci return 0; 218562306a36Sopenharmony_ci } 218662306a36Sopenharmony_ci 218762306a36Sopenharmony_ci if (write_compat_struct_tests(test_desc_fd)) 218862306a36Sopenharmony_ci exit(KSFT_FAIL); 218962306a36Sopenharmony_ci 219062306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(proto_list); i++) { 219162306a36Sopenharmony_ci if (write_proto_plan(test_desc_fd, proto_list[i])) 219262306a36Sopenharmony_ci exit(KSFT_FAIL); 219362306a36Sopenharmony_ci } 219462306a36Sopenharmony_ci 219562306a36Sopenharmony_ci exit(KSFT_PASS); 219662306a36Sopenharmony_ci} 219762306a36Sopenharmony_ci 219862306a36Sopenharmony_cistatic int children_cleanup(void) 219962306a36Sopenharmony_ci{ 220062306a36Sopenharmony_ci unsigned ret = KSFT_PASS; 220162306a36Sopenharmony_ci 220262306a36Sopenharmony_ci while (1) { 220362306a36Sopenharmony_ci int status; 220462306a36Sopenharmony_ci pid_t p = wait(&status); 220562306a36Sopenharmony_ci 220662306a36Sopenharmony_ci if ((p < 0) && errno == ECHILD) 220762306a36Sopenharmony_ci break; 220862306a36Sopenharmony_ci 220962306a36Sopenharmony_ci if (p < 0) { 221062306a36Sopenharmony_ci pr_err("wait()"); 221162306a36Sopenharmony_ci return KSFT_FAIL; 221262306a36Sopenharmony_ci } 221362306a36Sopenharmony_ci 221462306a36Sopenharmony_ci if (!WIFEXITED(status)) { 221562306a36Sopenharmony_ci ret = KSFT_FAIL; 221662306a36Sopenharmony_ci continue; 221762306a36Sopenharmony_ci } 221862306a36Sopenharmony_ci 221962306a36Sopenharmony_ci if (WEXITSTATUS(status) == KSFT_FAIL) 222062306a36Sopenharmony_ci ret = KSFT_FAIL; 222162306a36Sopenharmony_ci } 222262306a36Sopenharmony_ci 222362306a36Sopenharmony_ci return ret; 222462306a36Sopenharmony_ci} 222562306a36Sopenharmony_ci 222662306a36Sopenharmony_citypedef void (*print_res)(const char *, ...); 222762306a36Sopenharmony_ci 222862306a36Sopenharmony_cistatic int check_results(void) 222962306a36Sopenharmony_ci{ 223062306a36Sopenharmony_ci struct test_result tr = {}; 223162306a36Sopenharmony_ci struct xfrm_desc *d = &tr.desc; 223262306a36Sopenharmony_ci int ret = KSFT_PASS; 223362306a36Sopenharmony_ci 223462306a36Sopenharmony_ci while (1) { 223562306a36Sopenharmony_ci ssize_t received = read(results_fd[0], &tr, sizeof(tr)); 223662306a36Sopenharmony_ci print_res result; 223762306a36Sopenharmony_ci 223862306a36Sopenharmony_ci if (received == 0) /* EOF */ 223962306a36Sopenharmony_ci break; 224062306a36Sopenharmony_ci 224162306a36Sopenharmony_ci if (received != sizeof(tr)) { 224262306a36Sopenharmony_ci pr_err("read() returned %zd", received); 224362306a36Sopenharmony_ci return KSFT_FAIL; 224462306a36Sopenharmony_ci } 224562306a36Sopenharmony_ci 224662306a36Sopenharmony_ci switch (tr.res) { 224762306a36Sopenharmony_ci case KSFT_PASS: 224862306a36Sopenharmony_ci result = ksft_test_result_pass; 224962306a36Sopenharmony_ci break; 225062306a36Sopenharmony_ci case KSFT_FAIL: 225162306a36Sopenharmony_ci default: 225262306a36Sopenharmony_ci result = ksft_test_result_fail; 225362306a36Sopenharmony_ci ret = KSFT_FAIL; 225462306a36Sopenharmony_ci } 225562306a36Sopenharmony_ci 225662306a36Sopenharmony_ci result(" %s: [%u, '%s', '%s', '%s', '%s', %u]\n", 225762306a36Sopenharmony_ci desc_name[d->type], (unsigned int)d->proto, d->a_algo, 225862306a36Sopenharmony_ci d->e_algo, d->c_algo, d->ae_algo, d->icv_len); 225962306a36Sopenharmony_ci } 226062306a36Sopenharmony_ci 226162306a36Sopenharmony_ci return ret; 226262306a36Sopenharmony_ci} 226362306a36Sopenharmony_ci 226462306a36Sopenharmony_ciint main(int argc, char **argv) 226562306a36Sopenharmony_ci{ 226662306a36Sopenharmony_ci long nr_process = 1; 226762306a36Sopenharmony_ci int route_sock = -1, ret = KSFT_SKIP; 226862306a36Sopenharmony_ci int test_desc_fd[2]; 226962306a36Sopenharmony_ci uint32_t route_seq; 227062306a36Sopenharmony_ci unsigned int i; 227162306a36Sopenharmony_ci 227262306a36Sopenharmony_ci if (argc > 2) 227362306a36Sopenharmony_ci exit_usage(argv); 227462306a36Sopenharmony_ci 227562306a36Sopenharmony_ci if (argc > 1) { 227662306a36Sopenharmony_ci char *endptr; 227762306a36Sopenharmony_ci 227862306a36Sopenharmony_ci errno = 0; 227962306a36Sopenharmony_ci nr_process = strtol(argv[1], &endptr, 10); 228062306a36Sopenharmony_ci if ((errno == ERANGE && (nr_process == LONG_MAX || nr_process == LONG_MIN)) 228162306a36Sopenharmony_ci || (errno != 0 && nr_process == 0) 228262306a36Sopenharmony_ci || (endptr == argv[1]) || (*endptr != '\0')) { 228362306a36Sopenharmony_ci printk("Failed to parse [nr_process]"); 228462306a36Sopenharmony_ci exit_usage(argv); 228562306a36Sopenharmony_ci } 228662306a36Sopenharmony_ci 228762306a36Sopenharmony_ci if (nr_process > MAX_PROCESSES || nr_process < 1) { 228862306a36Sopenharmony_ci printk("nr_process should be between [1; %u]", 228962306a36Sopenharmony_ci MAX_PROCESSES); 229062306a36Sopenharmony_ci exit_usage(argv); 229162306a36Sopenharmony_ci } 229262306a36Sopenharmony_ci } 229362306a36Sopenharmony_ci 229462306a36Sopenharmony_ci srand(time(NULL)); 229562306a36Sopenharmony_ci page_size = sysconf(_SC_PAGESIZE); 229662306a36Sopenharmony_ci if (page_size < 1) 229762306a36Sopenharmony_ci ksft_exit_skip("sysconf(): %m\n"); 229862306a36Sopenharmony_ci 229962306a36Sopenharmony_ci if (pipe2(test_desc_fd, O_DIRECT) < 0) 230062306a36Sopenharmony_ci ksft_exit_skip("pipe(): %m\n"); 230162306a36Sopenharmony_ci 230262306a36Sopenharmony_ci if (pipe2(results_fd, O_DIRECT) < 0) 230362306a36Sopenharmony_ci ksft_exit_skip("pipe(): %m\n"); 230462306a36Sopenharmony_ci 230562306a36Sopenharmony_ci if (init_namespaces()) 230662306a36Sopenharmony_ci ksft_exit_skip("Failed to create namespaces\n"); 230762306a36Sopenharmony_ci 230862306a36Sopenharmony_ci if (netlink_sock(&route_sock, &route_seq, NETLINK_ROUTE)) 230962306a36Sopenharmony_ci ksft_exit_skip("Failed to open netlink route socket\n"); 231062306a36Sopenharmony_ci 231162306a36Sopenharmony_ci for (i = 0; i < nr_process; i++) { 231262306a36Sopenharmony_ci char veth[VETH_LEN]; 231362306a36Sopenharmony_ci 231462306a36Sopenharmony_ci snprintf(veth, VETH_LEN, VETH_FMT, i); 231562306a36Sopenharmony_ci 231662306a36Sopenharmony_ci if (veth_add(route_sock, route_seq++, veth, nsfd_childa, veth, nsfd_childb)) { 231762306a36Sopenharmony_ci close(route_sock); 231862306a36Sopenharmony_ci ksft_exit_fail_msg("Failed to create veth device"); 231962306a36Sopenharmony_ci } 232062306a36Sopenharmony_ci 232162306a36Sopenharmony_ci if (start_child(i, veth, test_desc_fd)) { 232262306a36Sopenharmony_ci close(route_sock); 232362306a36Sopenharmony_ci ksft_exit_fail_msg("Child %u failed to start", i); 232462306a36Sopenharmony_ci } 232562306a36Sopenharmony_ci } 232662306a36Sopenharmony_ci 232762306a36Sopenharmony_ci if (close(route_sock) || close(test_desc_fd[0]) || close(results_fd[1])) 232862306a36Sopenharmony_ci ksft_exit_fail_msg("close(): %m"); 232962306a36Sopenharmony_ci 233062306a36Sopenharmony_ci ksft_set_plan(proto_plan + compat_plan); 233162306a36Sopenharmony_ci 233262306a36Sopenharmony_ci if (write_test_plan(test_desc_fd[1])) 233362306a36Sopenharmony_ci ksft_exit_fail_msg("Failed to write test plan to pipe"); 233462306a36Sopenharmony_ci 233562306a36Sopenharmony_ci ret = check_results(); 233662306a36Sopenharmony_ci 233762306a36Sopenharmony_ci if (children_cleanup() == KSFT_FAIL) 233862306a36Sopenharmony_ci exit(KSFT_FAIL); 233962306a36Sopenharmony_ci 234062306a36Sopenharmony_ci exit(ret); 234162306a36Sopenharmony_ci} 2342