[XFRM] STATE: Add a hook to find offset to be inserted header in outbound.
On current kernel, ip6_find_1stfragopt() is used by IPv6 IPsec to find offset to be inserted header in outbound for transport mode. (BTW, no usage may be needed for IPv4 case.) Mobile IPv6 requires another logic for routing header and destination options header respectively. This patch is common platform for the offset and adopts it to IPsec. Based on MIPL2 kernel patch. Signed-off-by: Masahide NAKAMURA <nakam@linux-ipv6.org> Signed-off-by: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
eb2971b68a
commit
aee5adb430
@ -265,6 +265,7 @@ struct xfrm_type
|
||||
void (*destructor)(struct xfrm_state *);
|
||||
int (*input)(struct xfrm_state *, struct sk_buff *skb);
|
||||
int (*output)(struct xfrm_state *, struct sk_buff *pskb);
|
||||
int (*hdr_offset)(struct xfrm_state *, struct sk_buff *, u8 **);
|
||||
/* Estimate maximal size of result of transformation of a dgram */
|
||||
u32 (*get_max_size)(struct xfrm_state *, int size);
|
||||
};
|
||||
@ -960,6 +961,8 @@ extern u32 xfrm6_tunnel_alloc_spi(xfrm_address_t *saddr);
|
||||
extern void xfrm6_tunnel_free_spi(xfrm_address_t *saddr);
|
||||
extern u32 xfrm6_tunnel_spi_lookup(xfrm_address_t *saddr);
|
||||
extern int xfrm6_output(struct sk_buff *skb);
|
||||
extern int xfrm6_find_1stfragopt(struct xfrm_state *x, struct sk_buff *skb,
|
||||
u8 **prevhdr);
|
||||
|
||||
#ifdef CONFIG_XFRM
|
||||
extern int xfrm4_rcv_encap(struct sk_buff *skb, __u16 encap_type);
|
||||
|
@ -435,7 +435,8 @@ static struct xfrm_type ah6_type =
|
||||
.init_state = ah6_init_state,
|
||||
.destructor = ah6_destroy,
|
||||
.input = ah6_input,
|
||||
.output = ah6_output
|
||||
.output = ah6_output,
|
||||
.hdr_offset = xfrm6_find_1stfragopt,
|
||||
};
|
||||
|
||||
static struct inet6_protocol ah6_protocol = {
|
||||
|
@ -379,7 +379,8 @@ static struct xfrm_type esp6_type =
|
||||
.destructor = esp6_destroy,
|
||||
.get_max_size = esp6_get_max_size,
|
||||
.input = esp6_input,
|
||||
.output = esp6_output
|
||||
.output = esp6_output,
|
||||
.hdr_offset = xfrm6_find_1stfragopt,
|
||||
};
|
||||
|
||||
static struct inet6_protocol esp6_protocol = {
|
||||
|
@ -461,6 +461,7 @@ static struct xfrm_type ipcomp6_type =
|
||||
.destructor = ipcomp6_destroy,
|
||||
.input = ipcomp6_input,
|
||||
.output = ipcomp6_output,
|
||||
.hdr_offset = xfrm6_find_1stfragopt,
|
||||
};
|
||||
|
||||
static struct inet6_protocol ipcomp6_protocol =
|
||||
|
@ -31,6 +31,7 @@ EXPORT_SYMBOL(ipv6_chk_addr);
|
||||
EXPORT_SYMBOL(in6_dev_finish_destroy);
|
||||
#ifdef CONFIG_XFRM
|
||||
EXPORT_SYMBOL(xfrm6_rcv);
|
||||
EXPORT_SYMBOL(xfrm6_find_1stfragopt);
|
||||
#endif
|
||||
EXPORT_SYMBOL(rt6_lookup);
|
||||
EXPORT_SYMBOL(ipv6_push_nfrag_opts);
|
||||
|
@ -35,7 +35,7 @@ static int xfrm6_transport_output(struct sk_buff *skb)
|
||||
skb_push(skb, x->props.header_len);
|
||||
iph = skb->nh.ipv6h;
|
||||
|
||||
hdr_len = ip6_find_1stfragopt(skb, &prevhdr);
|
||||
hdr_len = x->type->hdr_offset(x, skb, &prevhdr);
|
||||
skb->nh.raw = prevhdr - x->props.header_len;
|
||||
skb->h.raw = skb->data + hdr_len;
|
||||
memmove(skb->data, iph, hdr_len);
|
||||
|
@ -17,6 +17,12 @@
|
||||
#include <net/ipv6.h>
|
||||
#include <net/xfrm.h>
|
||||
|
||||
int xfrm6_find_1stfragopt(struct xfrm_state *x, struct sk_buff *skb,
|
||||
u8 **prevhdr)
|
||||
{
|
||||
return ip6_find_1stfragopt(skb, prevhdr);
|
||||
}
|
||||
|
||||
static int xfrm6_tunnel_check_size(struct sk_buff *skb)
|
||||
{
|
||||
int mtu, ret = 0;
|
||||
|
Loading…
Reference in New Issue
Block a user