2 * xfrm6_mode_tunnel.c - Tunnel mode encapsulation for IPv6.
4 * Copyright (C) 2002 USAGI/WIDE Project
5 * Copyright (c) 2004-2006 Herbert Xu <herbert@gondor.apana.org.au>
8 #include <linux/init.h>
9 #include <linux/kernel.h>
10 #include <linux/module.h>
11 #include <linux/skbuff.h>
12 #include <linux/stringify.h>
13 #include <net/dsfield.h>
15 #include <net/inet_ecn.h>
19 static inline void ipip6_ecn_decapsulate(struct sk_buff
*skb
)
21 struct ipv6hdr
*outer_iph
= ipv6_hdr(skb
);
22 struct ipv6hdr
*inner_iph
= ipipv6_hdr(skb
);
24 if (INET_ECN_is_ce(ipv6_get_dsfield(outer_iph
)))
25 IP6_ECN_set_ce(inner_iph
);
28 static inline void ip6ip_ecn_decapsulate(struct sk_buff
*skb
)
30 if (INET_ECN_is_ce(ipv6_get_dsfield(ipv6_hdr(skb
))))
31 IP_ECN_set_ce(ipip_hdr(skb
));
34 /* Add encapsulation header.
36 * The top IP header will be constructed per RFC 2401.
38 static int xfrm6_tunnel_output(struct xfrm_state
*x
, struct sk_buff
*skb
)
40 struct dst_entry
*dst
= skb
->dst
;
41 struct xfrm_dst
*xdst
= (struct xfrm_dst
*)dst
;
42 struct ipv6hdr
*iph
, *top_iph
;
47 skb_set_network_header(skb
, -x
->props
.header_len
);
48 skb
->mac_header
= skb
->network_header
+
49 offsetof(struct ipv6hdr
, nexthdr
);
50 skb
->transport_header
= skb
->network_header
+ sizeof(*iph
);
51 top_iph
= ipv6_hdr(skb
);
54 if (xdst
->route
->ops
->family
== AF_INET6
) {
55 top_iph
->priority
= iph
->priority
;
56 top_iph
->flow_lbl
[0] = iph
->flow_lbl
[0];
57 top_iph
->flow_lbl
[1] = iph
->flow_lbl
[1];
58 top_iph
->flow_lbl
[2] = iph
->flow_lbl
[2];
59 top_iph
->nexthdr
= IPPROTO_IPV6
;
61 top_iph
->priority
= 0;
62 top_iph
->flow_lbl
[0] = 0;
63 top_iph
->flow_lbl
[1] = 0;
64 top_iph
->flow_lbl
[2] = 0;
65 top_iph
->nexthdr
= IPPROTO_IPIP
;
67 dsfield
= ipv6_get_dsfield(top_iph
);
68 dsfield
= INET_ECN_encapsulate(dsfield
, dsfield
);
69 if (x
->props
.flags
& XFRM_STATE_NOECN
)
70 dsfield
&= ~INET_ECN_MASK
;
71 ipv6_change_dsfield(top_iph
, 0, dsfield
);
72 top_iph
->hop_limit
= dst_metric(dst
->child
, RTAX_HOPLIMIT
);
73 ipv6_addr_copy(&top_iph
->saddr
, (struct in6_addr
*)&x
->props
.saddr
);
74 ipv6_addr_copy(&top_iph
->daddr
, (struct in6_addr
*)&x
->id
.daddr
);
75 skb
->protocol
= htons(ETH_P_IPV6
);
79 static int xfrm6_tunnel_input(struct xfrm_state
*x
, struct sk_buff
*skb
)
82 const unsigned char *old_mac
;
83 const unsigned char *nh
= skb_network_header(skb
);
85 if (nh
[IP6CB(skb
)->nhoff
] != IPPROTO_IPV6
&&
86 nh
[IP6CB(skb
)->nhoff
] != IPPROTO_IPIP
)
88 if (!pskb_may_pull(skb
, sizeof(struct ipv6hdr
)))
91 if (skb_cloned(skb
) &&
92 (err
= pskb_expand_head(skb
, 0, 0, GFP_ATOMIC
)))
95 nh
= skb_network_header(skb
);
96 if (nh
[IP6CB(skb
)->nhoff
] == IPPROTO_IPV6
) {
97 if (x
->props
.flags
& XFRM_STATE_DECAP_DSCP
)
98 ipv6_copy_dscp(ipv6_hdr(skb
), ipipv6_hdr(skb
));
99 if (!(x
->props
.flags
& XFRM_STATE_NOECN
))
100 ipip6_ecn_decapsulate(skb
);
102 if (!(x
->props
.flags
& XFRM_STATE_NOECN
))
103 ip6ip_ecn_decapsulate(skb
);
104 skb
->protocol
= htons(ETH_P_IP
);
106 old_mac
= skb_mac_header(skb
);
107 skb_set_mac_header(skb
, -skb
->mac_len
);
108 memmove(skb_mac_header(skb
), old_mac
, skb
->mac_len
);
109 skb_reset_network_header(skb
);
116 static struct xfrm_mode xfrm6_tunnel_mode
= {
117 .input
= xfrm6_tunnel_input
,
118 .output
= xfrm6_tunnel_output
,
119 .owner
= THIS_MODULE
,
120 .encap
= XFRM_MODE_TUNNEL
,
121 .flags
= XFRM_MODE_FLAG_TUNNEL
,
124 static int __init
xfrm6_tunnel_init(void)
126 return xfrm_register_mode(&xfrm6_tunnel_mode
, AF_INET6
);
129 static void __exit
xfrm6_tunnel_exit(void)
133 err
= xfrm_unregister_mode(&xfrm6_tunnel_mode
, AF_INET6
);
137 module_init(xfrm6_tunnel_init
);
138 module_exit(xfrm6_tunnel_exit
);
139 MODULE_LICENSE("GPL");
140 MODULE_ALIAS_XFRM_MODE(AF_INET6
, XFRM_MODE_TUNNEL
);