esp4.c 11.4 KB
Newer Older
1
#include <linux/err.h>
L
Linus Torvalds 已提交
2 3 4 5 6 7
#include <linux/module.h>
#include <net/ip.h>
#include <net/xfrm.h>
#include <net/esp.h>
#include <asm/scatterlist.h>
#include <linux/crypto.h>
H
Herbert Xu 已提交
8
#include <linux/kernel.h>
L
Linus Torvalds 已提交
9 10
#include <linux/pfkeyv2.h>
#include <linux/random.h>
11
#include <linux/spinlock.h>
L
Linus Torvalds 已提交
12
#include <net/icmp.h>
13
#include <net/protocol.h>
L
Linus Torvalds 已提交
14 15 16 17 18 19 20
#include <net/udp.h>

static int esp_output(struct xfrm_state *x, struct sk_buff *skb)
{
	int err;
	struct iphdr *top_iph;
	struct ip_esp_hdr *esph;
21 22
	struct crypto_blkcipher *tfm;
	struct blkcipher_desc desc;
L
Linus Torvalds 已提交
23 24
	struct esp_data *esp;
	struct sk_buff *trailer;
25
	u8 *tail;
L
Linus Torvalds 已提交
26 27 28 29 30
	int blksize;
	int clen;
	int alen;
	int nfrags;

31
	/* skb is pure payload to encrypt */
L
Linus Torvalds 已提交
32 33 34 35 36 37 38 39 40

	err = -ENOMEM;

	/* Round to block size */
	clen = skb->len;

	esp = x->data;
	alen = esp->auth.icv_trunc_len;
	tfm = esp->conf.tfm;
41 42 43
	desc.tfm = tfm;
	desc.flags = 0;
	blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
H
Herbert Xu 已提交
44
	clen = ALIGN(clen + 2, blksize);
L
Linus Torvalds 已提交
45
	if (esp->conf.padlen)
H
Herbert Xu 已提交
46
		clen = ALIGN(clen, esp->conf.padlen);
L
Linus Torvalds 已提交
47 48 49 50 51

	if ((nfrags = skb_cow_data(skb, clen-skb->len+alen, &trailer)) < 0)
		goto error;

	/* Fill padding... */
52
	tail = skb_tail_pointer(trailer);
L
Linus Torvalds 已提交
53 54 55
	do {
		int i;
		for (i=0; i<clen-skb->len - 2; i++)
56
			tail[i] = i + 1;
L
Linus Torvalds 已提交
57
	} while (0);
58
	tail[clen - skb->len - 2] = (clen - skb->len) - 2;
L
Linus Torvalds 已提交
59 60
	pskb_put(skb, trailer, clen - skb->len);

61
	skb_push(skb, -skb_network_offset(skb));
62
	top_iph = ip_hdr(skb);
63
	esph = ip_esp_hdr(skb);
L
Linus Torvalds 已提交
64
	top_iph->tot_len = htons(skb->len + alen);
65 66
	*(skb_tail_pointer(trailer) - 1) = *skb_mac_header(skb);
	*skb_mac_header(skb) = IPPROTO_ESP;
L
Linus Torvalds 已提交
67

68 69
	spin_lock_bh(&x->lock);

L
Linus Torvalds 已提交
70 71 72 73
	/* this is non-NULL only with UDP Encapsulation */
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
		struct udphdr *uh;
A
Al Viro 已提交
74
		__be32 *udpdata32;
L
Linus Torvalds 已提交
75 76 77 78 79 80 81 82 83 84 85 86 87

		uh = (struct udphdr *)esph;
		uh->source = encap->encap_sport;
		uh->dest = encap->encap_dport;
		uh->len = htons(skb->len + alen - top_iph->ihl*4);
		uh->check = 0;

		switch (encap->encap_type) {
		default:
		case UDP_ENCAP_ESPINUDP:
			esph = (struct ip_esp_hdr *)(uh + 1);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
A
Al Viro 已提交
88
			udpdata32 = (__be32 *)(uh + 1);
L
Linus Torvalds 已提交
89 90 91 92 93
			udpdata32[0] = udpdata32[1] = 0;
			esph = (struct ip_esp_hdr *)(udpdata32 + 2);
			break;
		}

94 95
		*skb_mac_header(skb) = IPPROTO_UDP;
	}
L
Linus Torvalds 已提交
96 97

	esph->spi = x->id.spi;
98
	esph->seq_no = htonl(XFRM_SKB_CB(skb)->seq);
L
Linus Torvalds 已提交
99

100 101 102 103 104
	if (esp->conf.ivlen) {
		if (unlikely(!esp->conf.ivinitted)) {
			get_random_bytes(esp->conf.ivec, esp->conf.ivlen);
			esp->conf.ivinitted = 1;
		}
105
		crypto_blkcipher_set_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
106
	}
L
Linus Torvalds 已提交
107 108 109 110 111 112 113

	do {
		struct scatterlist *sg = &esp->sgbuf[0];

		if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
			sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
			if (!sg)
114
				goto unlock;
L
Linus Torvalds 已提交
115 116
		}
		skb_to_sgvec(skb, sg, esph->enc_data+esp->conf.ivlen-skb->data, clen);
117
		err = crypto_blkcipher_encrypt(&desc, sg, sg, clen);
L
Linus Torvalds 已提交
118 119 120 121
		if (unlikely(sg != &esp->sgbuf[0]))
			kfree(sg);
	} while (0);

122
	if (unlikely(err))
123
		goto unlock;
124

L
Linus Torvalds 已提交
125
	if (esp->conf.ivlen) {
126 127
		memcpy(esph->enc_data, esp->conf.ivec, esp->conf.ivlen);
		crypto_blkcipher_get_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
L
Linus Torvalds 已提交
128 129 130
	}

	if (esp->auth.icv_full_len) {
131 132 133
		err = esp_mac_digest(esp, skb, (u8 *)esph - skb->data,
				     sizeof(*esph) + esp->conf.ivlen + clen);
		memcpy(pskb_put(skb, trailer, alen), esp->auth.work_icv, alen);
L
Linus Torvalds 已提交
134 135
	}

136 137 138
unlock:
	spin_unlock_bh(&x->lock);

L
Linus Torvalds 已提交
139 140 141 142 143 144 145 146 147 148 149
	ip_send_check(top_iph);

error:
	return err;
}

/*
 * Note: detecting truncated vs. non-truncated authentication data is very
 * expensive, so we only support truncated data, which is the recommended
 * and common case.
 */
150
static int esp_input(struct xfrm_state *x, struct sk_buff *skb)
L
Linus Torvalds 已提交
151 152 153 154
{
	struct iphdr *iph;
	struct ip_esp_hdr *esph;
	struct esp_data *esp = x->data;
155 156
	struct crypto_blkcipher *tfm = esp->conf.tfm;
	struct blkcipher_desc desc = { .tfm = tfm };
L
Linus Torvalds 已提交
157
	struct sk_buff *trailer;
158
	int blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
L
Linus Torvalds 已提交
159
	int alen = esp->auth.icv_trunc_len;
160
	int elen = skb->len - sizeof(*esph) - esp->conf.ivlen - alen;
L
Linus Torvalds 已提交
161
	int nfrags;
162
	int ihl;
163 164 165
	u8 nexthdr[2];
	struct scatterlist *sg;
	int padlen;
166
	int err;
L
Linus Torvalds 已提交
167

168
	if (!pskb_may_pull(skb, sizeof(*esph)))
L
Linus Torvalds 已提交
169 170 171 172 173 174 175
		goto out;

	if (elen <= 0 || (elen & (blksize-1)))
		goto out;

	/* If integrity check is required, do this. */
	if (esp->auth.icv_full_len) {
176
		u8 sum[alen];
L
Linus Torvalds 已提交
177

178 179 180 181 182
		err = esp_mac_digest(esp, skb, 0, skb->len - alen);
		if (err)
			goto out;

		if (skb_copy_bits(skb, skb->len - alen, sum, alen))
L
Linus Torvalds 已提交
183 184
			BUG();

185
		if (unlikely(memcmp(esp->auth.work_icv, sum, alen))) {
L
Linus Torvalds 已提交
186 187 188 189 190 191 192 193 194 195
			x->stats.integrity_failed++;
			goto out;
		}
	}

	if ((nfrags = skb_cow_data(skb, 0, &trailer)) < 0)
		goto out;

	skb->ip_summed = CHECKSUM_NONE;

196
	esph = (struct ip_esp_hdr *)skb->data;
L
Linus Torvalds 已提交
197 198 199

	/* Get ivec. This can be wrong, check against another impls. */
	if (esp->conf.ivlen)
200
		crypto_blkcipher_set_iv(tfm, esph->enc_data, esp->conf.ivlen);
L
Linus Torvalds 已提交
201

202
	sg = &esp->sgbuf[0];
L
Linus Torvalds 已提交
203

204 205 206 207 208
	if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
		sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
		if (!sg)
			goto out;
	}
209
	skb_to_sgvec(skb, sg, sizeof(*esph) + esp->conf.ivlen, elen);
210
	err = crypto_blkcipher_decrypt(&desc, sg, sg, elen);
211 212
	if (unlikely(sg != &esp->sgbuf[0]))
		kfree(sg);
213 214
	if (unlikely(err))
		return err;
L
Linus Torvalds 已提交
215

216 217
	if (skb_copy_bits(skb, skb->len-alen-2, nexthdr, 2))
		BUG();
L
Linus Torvalds 已提交
218

219 220 221
	padlen = nexthdr[0];
	if (padlen+2 >= elen)
		goto out;
L
Linus Torvalds 已提交
222

223
	/* ... check padding bits here. Silly. :-) */
L
Linus Torvalds 已提交
224

225
	iph = ip_hdr(skb);
226 227
	ihl = iph->ihl * 4;

228 229
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
230
		struct udphdr *uh = (void *)(skb_network_header(skb) + ihl);
231 232 233 234 235 236 237 238 239 240 241 242 243

		/*
		 * 1) if the NAT-T peer's IP or port changed then
		 *    advertize the change to the keying daemon.
		 *    This is an inbound SA, so just compare
		 *    SRC ports.
		 */
		if (iph->saddr != x->props.saddr.a4 ||
		    uh->source != encap->encap_sport) {
			xfrm_address_t ipaddr;

			ipaddr.a4 = iph->saddr;
			km_new_mapping(x, &ipaddr, uh->source);
244

245 246 247 248 249 250 251
			/* XXX: perhaps add an extra
			 * policy check here, to see
			 * if we should allow or
			 * reject a packet from a
			 * different source
			 * address/port.
			 */
L
Linus Torvalds 已提交
252
		}
253

254 255 256 257 258 259 260
		/*
		 * 2) ignore UDP/TCP checksums in case
		 *    of NAT-T in Transport Mode, or
		 *    perform other post-processing fixes
		 *    as per draft-ietf-ipsec-udp-encaps-06,
		 *    section 3.1.2
		 */
261
		if (x->props.mode == XFRM_MODE_TRANSPORT)
262
			skb->ip_summed = CHECKSUM_UNNECESSARY;
L
Linus Torvalds 已提交
263 264
	}

265 266
	iph->protocol = nexthdr[1];
	pskb_trim(skb, skb->len - alen - padlen - 2);
267 268
	__skb_pull(skb, sizeof(*esph) + esp->conf.ivlen);
	skb_set_transport_header(skb, -ihl);
269

L
Linus Torvalds 已提交
270 271 272 273 274 275
	return 0;

out:
	return -EINVAL;
}

276
static u32 esp4_get_mtu(struct xfrm_state *x, int mtu)
L
Linus Torvalds 已提交
277 278
{
	struct esp_data *esp = x->data;
279
	u32 blksize = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
280 281 282 283 284 285
	u32 align = max_t(u32, blksize, esp->conf.padlen);
	u32 rem;

	mtu -= x->props.header_len + esp->auth.icv_trunc_len;
	rem = mtu & (align - 1);
	mtu &= ~(align - 1);
D
Diego Beltrami 已提交
286 287 288 289 290 291 292

	switch (x->props.mode) {
	case XFRM_MODE_TUNNEL:
		break;
	default:
	case XFRM_MODE_TRANSPORT:
		/* The worst case */
293 294
		mtu -= blksize - 4;
		mtu += min_t(u32, blksize - 4, rem);
D
Diego Beltrami 已提交
295 296
		break;
	case XFRM_MODE_BEET:
297
		/* The worst case. */
298
		mtu += min_t(u32, IPV4_BEET_PHMAXLEN, rem);
D
Diego Beltrami 已提交
299
		break;
L
Linus Torvalds 已提交
300
	}
D
Diego Beltrami 已提交
301

302
	return mtu - 2;
L
Linus Torvalds 已提交
303 304 305 306 307 308 309 310
}

static void esp4_err(struct sk_buff *skb, u32 info)
{
	struct iphdr *iph = (struct iphdr*)skb->data;
	struct ip_esp_hdr *esph = (struct ip_esp_hdr*)(skb->data+(iph->ihl<<2));
	struct xfrm_state *x;

311 312
	if (icmp_hdr(skb)->type != ICMP_DEST_UNREACH ||
	    icmp_hdr(skb)->code != ICMP_FRAG_NEEDED)
L
Linus Torvalds 已提交
313 314 315 316 317
		return;

	x = xfrm_state_lookup((xfrm_address_t *)&iph->daddr, esph->spi, IPPROTO_ESP, AF_INET);
	if (!x)
		return;
318 319
	NETDEBUG(KERN_DEBUG "pmtu discovery on SA ESP/%08x/%08x\n",
		 ntohl(esph->spi), ntohl(iph->daddr));
L
Linus Torvalds 已提交
320 321 322 323 324 325 326 327 328 329
	xfrm_state_put(x);
}

static void esp_destroy(struct xfrm_state *x)
{
	struct esp_data *esp = x->data;

	if (!esp)
		return;

330
	crypto_free_blkcipher(esp->conf.tfm);
331 332 333
	esp->conf.tfm = NULL;
	kfree(esp->conf.ivec);
	esp->conf.ivec = NULL;
334
	crypto_free_hash(esp->auth.tfm);
335 336 337
	esp->auth.tfm = NULL;
	kfree(esp->auth.work_icv);
	esp->auth.work_icv = NULL;
L
Linus Torvalds 已提交
338 339 340
	kfree(esp);
}

H
Herbert Xu 已提交
341
static int esp_init_state(struct xfrm_state *x)
L
Linus Torvalds 已提交
342 343
{
	struct esp_data *esp = NULL;
344
	struct crypto_blkcipher *tfm;
345
	u32 align;
L
Linus Torvalds 已提交
346 347 348 349

	if (x->ealg == NULL)
		goto error;

350
	esp = kzalloc(sizeof(*esp), GFP_KERNEL);
L
Linus Torvalds 已提交
351 352 353 354 355
	if (esp == NULL)
		return -ENOMEM;

	if (x->aalg) {
		struct xfrm_algo_desc *aalg_desc;
356
		struct crypto_hash *hash;
L
Linus Torvalds 已提交
357

358 359 360 361 362 363
		hash = crypto_alloc_hash(x->aalg->alg_name, 0,
					 CRYPTO_ALG_ASYNC);
		if (IS_ERR(hash))
			goto error;

		esp->auth.tfm = hash;
364 365
		if (crypto_hash_setkey(hash, x->aalg->alg_key,
				       (x->aalg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
366 367 368 369 370 371
			goto error;

		aalg_desc = xfrm_aalg_get_byname(x->aalg->alg_name, 0);
		BUG_ON(!aalg_desc);

		if (aalg_desc->uinfo.auth.icv_fullbits/8 !=
372
		    crypto_hash_digestsize(hash)) {
373 374
			NETDEBUG(KERN_INFO "ESP: %s digestsize %u != %hu\n",
				 x->aalg->alg_name,
375
				 crypto_hash_digestsize(hash),
376
				 aalg_desc->uinfo.auth.icv_fullbits/8);
L
Linus Torvalds 已提交
377 378 379 380 381 382 383 384 385 386
			goto error;
		}

		esp->auth.icv_full_len = aalg_desc->uinfo.auth.icv_fullbits/8;
		esp->auth.icv_trunc_len = aalg_desc->uinfo.auth.icv_truncbits/8;

		esp->auth.work_icv = kmalloc(esp->auth.icv_full_len, GFP_KERNEL);
		if (!esp->auth.work_icv)
			goto error;
	}
387

388 389
	tfm = crypto_alloc_blkcipher(x->ealg->alg_name, 0, CRYPTO_ALG_ASYNC);
	if (IS_ERR(tfm))
L
Linus Torvalds 已提交
390
		goto error;
391 392
	esp->conf.tfm = tfm;
	esp->conf.ivlen = crypto_blkcipher_ivsize(tfm);
L
Linus Torvalds 已提交
393 394 395 396 397
	esp->conf.padlen = 0;
	if (esp->conf.ivlen) {
		esp->conf.ivec = kmalloc(esp->conf.ivlen, GFP_KERNEL);
		if (unlikely(esp->conf.ivec == NULL))
			goto error;
398
		esp->conf.ivinitted = 0;
L
Linus Torvalds 已提交
399
	}
400 401
	if (crypto_blkcipher_setkey(tfm, x->ealg->alg_key,
				    (x->ealg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
402 403
		goto error;
	x->props.header_len = sizeof(struct ip_esp_hdr) + esp->conf.ivlen;
404
	if (x->props.mode == XFRM_MODE_TUNNEL)
L
Linus Torvalds 已提交
405
		x->props.header_len += sizeof(struct iphdr);
406 407
	else if (x->props.mode == XFRM_MODE_BEET)
		x->props.header_len += IPV4_BEET_PHMAXLEN;
L
Linus Torvalds 已提交
408 409 410 411 412 413 414 415 416 417 418 419 420 421 422
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;

		switch (encap->encap_type) {
		default:
			goto error;
		case UDP_ENCAP_ESPINUDP:
			x->props.header_len += sizeof(struct udphdr);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
			x->props.header_len += sizeof(struct udphdr) + 2 * sizeof(u32);
			break;
		}
	}
	x->data = esp;
423 424 425 426
	align = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
	if (esp->conf.padlen)
		align = max_t(u32, align, esp->conf.padlen);
	x->props.trailer_len = align + 1 + esp->auth.icv_trunc_len;
L
Linus Torvalds 已提交
427 428 429 430 431 432 433 434 435 436 437 438 439 440
	return 0;

error:
	x->data = esp;
	esp_destroy(x);
	x->data = NULL;
	return -EINVAL;
}

static struct xfrm_type esp_type =
{
	.description	= "ESP4",
	.owner		= THIS_MODULE,
	.proto	     	= IPPROTO_ESP,
441
	.flags		= XFRM_TYPE_REPLAY_PROT,
L
Linus Torvalds 已提交
442 443
	.init_state	= esp_init_state,
	.destructor	= esp_destroy,
444
	.get_mtu	= esp4_get_mtu,
L
Linus Torvalds 已提交
445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479
	.input		= esp_input,
	.output		= esp_output
};

static struct net_protocol esp4_protocol = {
	.handler	=	xfrm4_rcv,
	.err_handler	=	esp4_err,
	.no_policy	=	1,
};

static int __init esp4_init(void)
{
	if (xfrm_register_type(&esp_type, AF_INET) < 0) {
		printk(KERN_INFO "ip esp init: can't add xfrm type\n");
		return -EAGAIN;
	}
	if (inet_add_protocol(&esp4_protocol, IPPROTO_ESP) < 0) {
		printk(KERN_INFO "ip esp init: can't add protocol\n");
		xfrm_unregister_type(&esp_type, AF_INET);
		return -EAGAIN;
	}
	return 0;
}

static void __exit esp4_fini(void)
{
	if (inet_del_protocol(&esp4_protocol, IPPROTO_ESP) < 0)
		printk(KERN_INFO "ip esp close: can't remove protocol\n");
	if (xfrm_unregister_type(&esp_type, AF_INET) < 0)
		printk(KERN_INFO "ip esp close: can't remove xfrm type\n");
}

module_init(esp4_init);
module_exit(esp4_fini);
MODULE_LICENSE("GPL");
480
MODULE_ALIAS_XFRM_TYPE(AF_INET, XFRM_PROTO_ESP);