iptunnel: scrub packet in iptunnel_pull_header
[deliverable/linux.git] / include / net / ip_tunnels.h
1 #ifndef __NET_IP_TUNNELS_H
2 #define __NET_IP_TUNNELS_H 1
3
4 #include <linux/if_tunnel.h>
5 #include <linux/netdevice.h>
6 #include <linux/skbuff.h>
7 #include <linux/socket.h>
8 #include <linux/types.h>
9 #include <linux/u64_stats_sync.h>
10 #include <net/dsfield.h>
11 #include <net/gro_cells.h>
12 #include <net/inet_ecn.h>
13 #include <net/netns/generic.h>
14 #include <net/rtnetlink.h>
15 #include <net/lwtunnel.h>
16 #include <net/dst_cache.h>
17
18 #if IS_ENABLED(CONFIG_IPV6)
19 #include <net/ipv6.h>
20 #include <net/ip6_fib.h>
21 #include <net/ip6_route.h>
22 #endif
23
24 /* Keep error state on tunnel for 30 sec */
25 #define IPTUNNEL_ERR_TIMEO (30*HZ)
26
27 /* Used to memset ip_tunnel padding. */
28 #define IP_TUNNEL_KEY_SIZE offsetofend(struct ip_tunnel_key, tp_dst)
29
30 /* Used to memset ipv4 address padding. */
31 #define IP_TUNNEL_KEY_IPV4_PAD offsetofend(struct ip_tunnel_key, u.ipv4.dst)
32 #define IP_TUNNEL_KEY_IPV4_PAD_LEN \
33 (FIELD_SIZEOF(struct ip_tunnel_key, u) - \
34 FIELD_SIZEOF(struct ip_tunnel_key, u.ipv4))
35
36 struct ip_tunnel_key {
37 __be64 tun_id;
38 union {
39 struct {
40 __be32 src;
41 __be32 dst;
42 } ipv4;
43 struct {
44 struct in6_addr src;
45 struct in6_addr dst;
46 } ipv6;
47 } u;
48 __be16 tun_flags;
49 u8 tos; /* TOS for IPv4, TC for IPv6 */
50 u8 ttl; /* TTL for IPv4, HL for IPv6 */
51 __be16 tp_src;
52 __be16 tp_dst;
53 };
54
55 /* Flags for ip_tunnel_info mode. */
56 #define IP_TUNNEL_INFO_TX 0x01 /* represents tx tunnel parameters */
57 #define IP_TUNNEL_INFO_IPV6 0x02 /* key contains IPv6 addresses */
58
59 struct ip_tunnel_info {
60 struct ip_tunnel_key key;
61 #ifdef CONFIG_DST_CACHE
62 struct dst_cache dst_cache;
63 #endif
64 u8 options_len;
65 u8 mode;
66 };
67
68 /* 6rd prefix/relay information */
69 #ifdef CONFIG_IPV6_SIT_6RD
70 struct ip_tunnel_6rd_parm {
71 struct in6_addr prefix;
72 __be32 relay_prefix;
73 u16 prefixlen;
74 u16 relay_prefixlen;
75 };
76 #endif
77
78 struct ip_tunnel_encap {
79 u16 type;
80 u16 flags;
81 __be16 sport;
82 __be16 dport;
83 };
84
85 struct ip_tunnel_prl_entry {
86 struct ip_tunnel_prl_entry __rcu *next;
87 __be32 addr;
88 u16 flags;
89 struct rcu_head rcu_head;
90 };
91
92 struct metadata_dst;
93
94 struct ip_tunnel {
95 struct ip_tunnel __rcu *next;
96 struct hlist_node hash_node;
97 struct net_device *dev;
98 struct net *net; /* netns for packet i/o */
99
100 int err_count; /* Number of arrived ICMP errors */
101 unsigned long err_time; /* Time when the last ICMP error
102 * arrived */
103
104 /* These four fields used only by GRE */
105 u32 i_seqno; /* The last seen seqno */
106 u32 o_seqno; /* The last output seqno */
107 int tun_hlen; /* Precalculated header length */
108 int mlink;
109
110 struct dst_cache dst_cache;
111
112 struct ip_tunnel_parm parms;
113
114 int encap_hlen; /* Encap header length (FOU,GUE) */
115 struct ip_tunnel_encap encap;
116
117 int hlen; /* tun_hlen + encap_hlen */
118
119 /* for SIT */
120 #ifdef CONFIG_IPV6_SIT_6RD
121 struct ip_tunnel_6rd_parm ip6rd;
122 #endif
123 struct ip_tunnel_prl_entry __rcu *prl; /* potential router list */
124 unsigned int prl_count; /* # of entries in PRL */
125 int ip_tnl_net_id;
126 struct gro_cells gro_cells;
127 bool collect_md;
128 };
129
130 #define TUNNEL_CSUM __cpu_to_be16(0x01)
131 #define TUNNEL_ROUTING __cpu_to_be16(0x02)
132 #define TUNNEL_KEY __cpu_to_be16(0x04)
133 #define TUNNEL_SEQ __cpu_to_be16(0x08)
134 #define TUNNEL_STRICT __cpu_to_be16(0x10)
135 #define TUNNEL_REC __cpu_to_be16(0x20)
136 #define TUNNEL_VERSION __cpu_to_be16(0x40)
137 #define TUNNEL_NO_KEY __cpu_to_be16(0x80)
138 #define TUNNEL_DONT_FRAGMENT __cpu_to_be16(0x0100)
139 #define TUNNEL_OAM __cpu_to_be16(0x0200)
140 #define TUNNEL_CRIT_OPT __cpu_to_be16(0x0400)
141 #define TUNNEL_GENEVE_OPT __cpu_to_be16(0x0800)
142 #define TUNNEL_VXLAN_OPT __cpu_to_be16(0x1000)
143
144 #define TUNNEL_OPTIONS_PRESENT (TUNNEL_GENEVE_OPT | TUNNEL_VXLAN_OPT)
145
146 struct tnl_ptk_info {
147 __be16 flags;
148 __be16 proto;
149 __be32 key;
150 __be32 seq;
151 };
152
153 #define PACKET_RCVD 0
154 #define PACKET_REJECT 1
155
156 #define IP_TNL_HASH_BITS 7
157 #define IP_TNL_HASH_SIZE (1 << IP_TNL_HASH_BITS)
158
159 struct ip_tunnel_net {
160 struct net_device *fb_tunnel_dev;
161 struct hlist_head tunnels[IP_TNL_HASH_SIZE];
162 struct ip_tunnel __rcu *collect_md_tun;
163 };
164
165 struct ip_tunnel_encap_ops {
166 size_t (*encap_hlen)(struct ip_tunnel_encap *e);
167 int (*build_header)(struct sk_buff *skb, struct ip_tunnel_encap *e,
168 u8 *protocol, struct flowi4 *fl4);
169 };
170
171 #define MAX_IPTUN_ENCAP_OPS 8
172
173 extern const struct ip_tunnel_encap_ops __rcu *
174 iptun_encaps[MAX_IPTUN_ENCAP_OPS];
175
176 int ip_tunnel_encap_add_ops(const struct ip_tunnel_encap_ops *op,
177 unsigned int num);
178 int ip_tunnel_encap_del_ops(const struct ip_tunnel_encap_ops *op,
179 unsigned int num);
180
181 static inline void ip_tunnel_key_init(struct ip_tunnel_key *key,
182 __be32 saddr, __be32 daddr,
183 u8 tos, u8 ttl,
184 __be16 tp_src, __be16 tp_dst,
185 __be64 tun_id, __be16 tun_flags)
186 {
187 key->tun_id = tun_id;
188 key->u.ipv4.src = saddr;
189 key->u.ipv4.dst = daddr;
190 memset((unsigned char *)key + IP_TUNNEL_KEY_IPV4_PAD,
191 0, IP_TUNNEL_KEY_IPV4_PAD_LEN);
192 key->tos = tos;
193 key->ttl = ttl;
194 key->tun_flags = tun_flags;
195
196 /* For the tunnel types on the top of IPsec, the tp_src and tp_dst of
197 * the upper tunnel are used.
198 * E.g: GRE over IPSEC, the tp_src and tp_port are zero.
199 */
200 key->tp_src = tp_src;
201 key->tp_dst = tp_dst;
202
203 /* Clear struct padding. */
204 if (sizeof(*key) != IP_TUNNEL_KEY_SIZE)
205 memset((unsigned char *)key + IP_TUNNEL_KEY_SIZE,
206 0, sizeof(*key) - IP_TUNNEL_KEY_SIZE);
207 }
208
209 static inline unsigned short ip_tunnel_info_af(const struct ip_tunnel_info
210 *tun_info)
211 {
212 return tun_info->mode & IP_TUNNEL_INFO_IPV6 ? AF_INET6 : AF_INET;
213 }
214
215 #ifdef CONFIG_INET
216
217 int ip_tunnel_init(struct net_device *dev);
218 void ip_tunnel_uninit(struct net_device *dev);
219 void ip_tunnel_dellink(struct net_device *dev, struct list_head *head);
220 struct net *ip_tunnel_get_link_net(const struct net_device *dev);
221 int ip_tunnel_get_iflink(const struct net_device *dev);
222 int ip_tunnel_init_net(struct net *net, int ip_tnl_net_id,
223 struct rtnl_link_ops *ops, char *devname);
224
225 void ip_tunnel_delete_net(struct ip_tunnel_net *itn, struct rtnl_link_ops *ops);
226
227 void ip_tunnel_xmit(struct sk_buff *skb, struct net_device *dev,
228 const struct iphdr *tnl_params, const u8 protocol);
229 int ip_tunnel_ioctl(struct net_device *dev, struct ip_tunnel_parm *p, int cmd);
230 int ip_tunnel_encap(struct sk_buff *skb, struct ip_tunnel *t,
231 u8 *protocol, struct flowi4 *fl4);
232 int ip_tunnel_change_mtu(struct net_device *dev, int new_mtu);
233
234 struct rtnl_link_stats64 *ip_tunnel_get_stats64(struct net_device *dev,
235 struct rtnl_link_stats64 *tot);
236 struct ip_tunnel *ip_tunnel_lookup(struct ip_tunnel_net *itn,
237 int link, __be16 flags,
238 __be32 remote, __be32 local,
239 __be32 key);
240
241 int ip_tunnel_rcv(struct ip_tunnel *tunnel, struct sk_buff *skb,
242 const struct tnl_ptk_info *tpi, struct metadata_dst *tun_dst,
243 bool log_ecn_error);
244 int ip_tunnel_changelink(struct net_device *dev, struct nlattr *tb[],
245 struct ip_tunnel_parm *p);
246 int ip_tunnel_newlink(struct net_device *dev, struct nlattr *tb[],
247 struct ip_tunnel_parm *p);
248 void ip_tunnel_setup(struct net_device *dev, int net_id);
249 int ip_tunnel_encap_setup(struct ip_tunnel *t,
250 struct ip_tunnel_encap *ipencap);
251
252 /* Extract dsfield from inner protocol */
253 static inline u8 ip_tunnel_get_dsfield(const struct iphdr *iph,
254 const struct sk_buff *skb)
255 {
256 if (skb->protocol == htons(ETH_P_IP))
257 return iph->tos;
258 else if (skb->protocol == htons(ETH_P_IPV6))
259 return ipv6_get_dsfield((const struct ipv6hdr *)iph);
260 else
261 return 0;
262 }
263
264 /* Propogate ECN bits out */
265 static inline u8 ip_tunnel_ecn_encap(u8 tos, const struct iphdr *iph,
266 const struct sk_buff *skb)
267 {
268 u8 inner = ip_tunnel_get_dsfield(iph, skb);
269
270 return INET_ECN_encapsulate(tos, inner);
271 }
272
273 int iptunnel_pull_header(struct sk_buff *skb, int hdr_len, __be16 inner_proto,
274 bool xnet);
275 void iptunnel_xmit(struct sock *sk, struct rtable *rt, struct sk_buff *skb,
276 __be32 src, __be32 dst, u8 proto,
277 u8 tos, u8 ttl, __be16 df, bool xnet);
278 struct metadata_dst *iptunnel_metadata_reply(struct metadata_dst *md,
279 gfp_t flags);
280
281 struct sk_buff *iptunnel_handle_offloads(struct sk_buff *skb, int gso_type_mask);
282
283 static inline void iptunnel_xmit_stats(struct net_device *dev, int pkt_len)
284 {
285 if (pkt_len > 0) {
286 struct pcpu_sw_netstats *tstats = get_cpu_ptr(dev->tstats);
287
288 u64_stats_update_begin(&tstats->syncp);
289 tstats->tx_bytes += pkt_len;
290 tstats->tx_packets++;
291 u64_stats_update_end(&tstats->syncp);
292 put_cpu_ptr(tstats);
293 } else {
294 struct net_device_stats *err_stats = &dev->stats;
295
296 if (pkt_len < 0) {
297 err_stats->tx_errors++;
298 err_stats->tx_aborted_errors++;
299 } else {
300 err_stats->tx_dropped++;
301 }
302 }
303 }
304
305 static inline void *ip_tunnel_info_opts(struct ip_tunnel_info *info)
306 {
307 return info + 1;
308 }
309
310 static inline void ip_tunnel_info_opts_get(void *to,
311 const struct ip_tunnel_info *info)
312 {
313 memcpy(to, info + 1, info->options_len);
314 }
315
316 static inline void ip_tunnel_info_opts_set(struct ip_tunnel_info *info,
317 const void *from, int len)
318 {
319 memcpy(ip_tunnel_info_opts(info), from, len);
320 info->options_len = len;
321 }
322
323 static inline struct ip_tunnel_info *lwt_tun_info(struct lwtunnel_state *lwtstate)
324 {
325 return (struct ip_tunnel_info *)lwtstate->data;
326 }
327
328 extern struct static_key ip_tunnel_metadata_cnt;
329
330 /* Returns > 0 if metadata should be collected */
331 static inline int ip_tunnel_collect_metadata(void)
332 {
333 return static_key_false(&ip_tunnel_metadata_cnt);
334 }
335
336 void __init ip_tunnel_core_init(void);
337
338 void ip_tunnel_need_metadata(void);
339 void ip_tunnel_unneed_metadata(void);
340
341 #else /* CONFIG_INET */
342
343 static inline struct ip_tunnel_info *lwt_tun_info(struct lwtunnel_state *lwtstate)
344 {
345 return NULL;
346 }
347
348 static inline void ip_tunnel_need_metadata(void)
349 {
350 }
351
352 static inline void ip_tunnel_unneed_metadata(void)
353 {
354 }
355
356 #endif /* CONFIG_INET */
357
358 #endif /* __NET_IP_TUNNELS_H */
This page took 0.104725 seconds and 5 git commands to generate.