[NETNS]: Drop packets in the non-initial namespace on the per/protocol basis.
[linux-2.6/openmoko-kernel/knife-kernel.git] / net / ipv4 / tunnel4.c
blob978b3fd61e65533f3cf01f26521fc6f406288fac
1 /* tunnel4.c: Generic IP tunnel transformer.
3 * Copyright (C) 2003 David S. Miller (davem@redhat.com)
4 */
6 #include <linux/init.h>
7 #include <linux/module.h>
8 #include <linux/mutex.h>
9 #include <linux/netdevice.h>
10 #include <linux/skbuff.h>
11 #include <net/icmp.h>
12 #include <net/ip.h>
13 #include <net/protocol.h>
14 #include <net/xfrm.h>
16 static struct xfrm_tunnel *tunnel4_handlers;
17 static struct xfrm_tunnel *tunnel64_handlers;
18 static DEFINE_MUTEX(tunnel4_mutex);
20 static inline struct xfrm_tunnel **fam_handlers(unsigned short family)
22 return (family == AF_INET) ? &tunnel4_handlers : &tunnel64_handlers;
25 int xfrm4_tunnel_register(struct xfrm_tunnel *handler, unsigned short family)
27 struct xfrm_tunnel **pprev;
28 int ret = -EEXIST;
29 int priority = handler->priority;
31 mutex_lock(&tunnel4_mutex);
33 for (pprev = fam_handlers(family); *pprev; pprev = &(*pprev)->next) {
34 if ((*pprev)->priority > priority)
35 break;
36 if ((*pprev)->priority == priority)
37 goto err;
40 handler->next = *pprev;
41 *pprev = handler;
43 ret = 0;
45 err:
46 mutex_unlock(&tunnel4_mutex);
48 return ret;
51 EXPORT_SYMBOL(xfrm4_tunnel_register);
53 int xfrm4_tunnel_deregister(struct xfrm_tunnel *handler, unsigned short family)
55 struct xfrm_tunnel **pprev;
56 int ret = -ENOENT;
58 mutex_lock(&tunnel4_mutex);
60 for (pprev = fam_handlers(family); *pprev; pprev = &(*pprev)->next) {
61 if (*pprev == handler) {
62 *pprev = handler->next;
63 ret = 0;
64 break;
68 mutex_unlock(&tunnel4_mutex);
70 synchronize_net();
72 return ret;
75 EXPORT_SYMBOL(xfrm4_tunnel_deregister);
77 static int tunnel4_rcv(struct sk_buff *skb)
79 struct xfrm_tunnel *handler;
81 if (!pskb_may_pull(skb, sizeof(struct iphdr)))
82 goto drop;
84 for (handler = tunnel4_handlers; handler; handler = handler->next)
85 if (!handler->handler(skb))
86 return 0;
88 icmp_send(skb, ICMP_DEST_UNREACH, ICMP_PORT_UNREACH, 0);
90 drop:
91 kfree_skb(skb);
92 return 0;
95 #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
96 static int tunnel64_rcv(struct sk_buff *skb)
98 struct xfrm_tunnel *handler;
100 if (!pskb_may_pull(skb, sizeof(struct iphdr)))
101 goto drop;
103 for (handler = tunnel64_handlers; handler; handler = handler->next)
104 if (!handler->handler(skb))
105 return 0;
107 icmp_send(skb, ICMP_DEST_UNREACH, ICMP_PORT_UNREACH, 0);
109 drop:
110 kfree_skb(skb);
111 return 0;
113 #endif
115 static void tunnel4_err(struct sk_buff *skb, u32 info)
117 struct xfrm_tunnel *handler;
119 for (handler = tunnel4_handlers; handler; handler = handler->next)
120 if (!handler->err_handler(skb, info))
121 break;
124 #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
125 static void tunnel64_err(struct sk_buff *skb, u32 info)
127 struct xfrm_tunnel *handler;
129 for (handler = tunnel64_handlers; handler; handler = handler->next)
130 if (!handler->err_handler(skb, info))
131 break;
133 #endif
135 static struct net_protocol tunnel4_protocol = {
136 .handler = tunnel4_rcv,
137 .err_handler = tunnel4_err,
138 .no_policy = 1,
141 #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
142 static struct net_protocol tunnel64_protocol = {
143 .handler = tunnel64_rcv,
144 .err_handler = tunnel64_err,
145 .no_policy = 1,
147 #endif
149 static int __init tunnel4_init(void)
151 if (inet_add_protocol(&tunnel4_protocol, IPPROTO_IPIP)) {
152 printk(KERN_ERR "tunnel4 init: can't add protocol\n");
153 return -EAGAIN;
155 #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
156 if (inet_add_protocol(&tunnel64_protocol, IPPROTO_IPV6)) {
157 printk(KERN_ERR "tunnel64 init: can't add protocol\n");
158 inet_del_protocol(&tunnel4_protocol, IPPROTO_IPIP);
159 return -EAGAIN;
161 #endif
162 return 0;
165 static void __exit tunnel4_fini(void)
167 #if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE)
168 if (inet_del_protocol(&tunnel64_protocol, IPPROTO_IPV6))
169 printk(KERN_ERR "tunnel64 close: can't remove protocol\n");
170 #endif
171 if (inet_del_protocol(&tunnel4_protocol, IPPROTO_IPIP))
172 printk(KERN_ERR "tunnel4 close: can't remove protocol\n");
175 module_init(tunnel4_init);
176 module_exit(tunnel4_fini);
177 MODULE_LICENSE("GPL");