esp4.c 11.6 KB
Newer Older
1
#include <linux/err.h>
L
Linus Torvalds 已提交
2 3 4 5
#include <linux/module.h>
#include <net/ip.h>
#include <net/xfrm.h>
#include <net/esp.h>
6
#include <linux/scatterlist.h>
L
Linus Torvalds 已提交
7
#include <linux/crypto.h>
H
Herbert Xu 已提交
8
#include <linux/kernel.h>
L
Linus Torvalds 已提交
9 10
#include <linux/pfkeyv2.h>
#include <linux/random.h>
11
#include <linux/spinlock.h>
12
#include <linux/in6.h>
L
Linus Torvalds 已提交
13
#include <net/icmp.h>
14
#include <net/protocol.h>
L
Linus Torvalds 已提交
15 16 17 18 19 20
#include <net/udp.h>

static int esp_output(struct xfrm_state *x, struct sk_buff *skb)
{
	int err;
	struct ip_esp_hdr *esph;
21 22
	struct crypto_blkcipher *tfm;
	struct blkcipher_desc desc;
L
Linus Torvalds 已提交
23 24
	struct esp_data *esp;
	struct sk_buff *trailer;
25
	u8 *tail;
L
Linus Torvalds 已提交
26 27 28 29 30
	int blksize;
	int clen;
	int alen;
	int nfrags;

31
	/* skb is pure payload to encrypt */
L
Linus Torvalds 已提交
32 33 34 35 36 37 38 39 40

	err = -ENOMEM;

	/* Round to block size */
	clen = skb->len;

	esp = x->data;
	alen = esp->auth.icv_trunc_len;
	tfm = esp->conf.tfm;
41 42 43
	desc.tfm = tfm;
	desc.flags = 0;
	blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
H
Herbert Xu 已提交
44
	clen = ALIGN(clen + 2, blksize);
L
Linus Torvalds 已提交
45
	if (esp->conf.padlen)
H
Herbert Xu 已提交
46
		clen = ALIGN(clen, esp->conf.padlen);
L
Linus Torvalds 已提交
47 48 49 50 51

	if ((nfrags = skb_cow_data(skb, clen-skb->len+alen, &trailer)) < 0)
		goto error;

	/* Fill padding... */
52
	tail = skb_tail_pointer(trailer);
L
Linus Torvalds 已提交
53 54 55
	do {
		int i;
		for (i=0; i<clen-skb->len - 2; i++)
56
			tail[i] = i + 1;
L
Linus Torvalds 已提交
57
	} while (0);
58
	tail[clen - skb->len - 2] = (clen - skb->len) - 2;
L
Linus Torvalds 已提交
59 60
	pskb_put(skb, trailer, clen - skb->len);

61
	skb_push(skb, -skb_network_offset(skb));
62
	esph = ip_esp_hdr(skb);
63 64
	*(skb_tail_pointer(trailer) - 1) = *skb_mac_header(skb);
	*skb_mac_header(skb) = IPPROTO_ESP;
L
Linus Torvalds 已提交
65

66 67
	spin_lock_bh(&x->lock);

L
Linus Torvalds 已提交
68 69 70 71
	/* this is non-NULL only with UDP Encapsulation */
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
		struct udphdr *uh;
A
Al Viro 已提交
72
		__be32 *udpdata32;
L
Linus Torvalds 已提交
73 74 75 76

		uh = (struct udphdr *)esph;
		uh->source = encap->encap_sport;
		uh->dest = encap->encap_dport;
77
		uh->len = htons(skb->len + alen - skb_transport_offset(skb));
L
Linus Torvalds 已提交
78 79 80 81 82 83 84 85
		uh->check = 0;

		switch (encap->encap_type) {
		default:
		case UDP_ENCAP_ESPINUDP:
			esph = (struct ip_esp_hdr *)(uh + 1);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
A
Al Viro 已提交
86
			udpdata32 = (__be32 *)(uh + 1);
L
Linus Torvalds 已提交
87 88 89 90 91
			udpdata32[0] = udpdata32[1] = 0;
			esph = (struct ip_esp_hdr *)(udpdata32 + 2);
			break;
		}

92 93
		*skb_mac_header(skb) = IPPROTO_UDP;
	}
L
Linus Torvalds 已提交
94 95

	esph->spi = x->id.spi;
96
	esph->seq_no = htonl(XFRM_SKB_CB(skb)->seq);
L
Linus Torvalds 已提交
97

98 99 100 101 102
	if (esp->conf.ivlen) {
		if (unlikely(!esp->conf.ivinitted)) {
			get_random_bytes(esp->conf.ivec, esp->conf.ivlen);
			esp->conf.ivinitted = 1;
		}
103
		crypto_blkcipher_set_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
104
	}
L
Linus Torvalds 已提交
105 106 107 108 109 110 111

	do {
		struct scatterlist *sg = &esp->sgbuf[0];

		if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
			sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
			if (!sg)
112
				goto unlock;
L
Linus Torvalds 已提交
113
		}
114
		sg_init_table(sg, nfrags);
115 116 117 118
		skb_to_sgvec(skb, sg,
			     esph->enc_data +
			     esp->conf.ivlen -
			     skb->data, clen);
119
		err = crypto_blkcipher_encrypt(&desc, sg, sg, clen);
L
Linus Torvalds 已提交
120 121 122 123
		if (unlikely(sg != &esp->sgbuf[0]))
			kfree(sg);
	} while (0);

124
	if (unlikely(err))
125
		goto unlock;
126

L
Linus Torvalds 已提交
127
	if (esp->conf.ivlen) {
128 129
		memcpy(esph->enc_data, esp->conf.ivec, esp->conf.ivlen);
		crypto_blkcipher_get_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
L
Linus Torvalds 已提交
130 131 132
	}

	if (esp->auth.icv_full_len) {
133 134 135
		err = esp_mac_digest(esp, skb, (u8 *)esph - skb->data,
				     sizeof(*esph) + esp->conf.ivlen + clen);
		memcpy(pskb_put(skb, trailer, alen), esp->auth.work_icv, alen);
L
Linus Torvalds 已提交
136 137
	}

138 139 140
unlock:
	spin_unlock_bh(&x->lock);

L
Linus Torvalds 已提交
141 142 143 144 145 146 147 148 149
error:
	return err;
}

/*
 * Note: detecting truncated vs. non-truncated authentication data is very
 * expensive, so we only support truncated data, which is the recommended
 * and common case.
 */
150
static int esp_input(struct xfrm_state *x, struct sk_buff *skb)
L
Linus Torvalds 已提交
151 152 153 154
{
	struct iphdr *iph;
	struct ip_esp_hdr *esph;
	struct esp_data *esp = x->data;
155 156
	struct crypto_blkcipher *tfm = esp->conf.tfm;
	struct blkcipher_desc desc = { .tfm = tfm };
L
Linus Torvalds 已提交
157
	struct sk_buff *trailer;
158
	int blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
L
Linus Torvalds 已提交
159
	int alen = esp->auth.icv_trunc_len;
160
	int elen = skb->len - sizeof(*esph) - esp->conf.ivlen - alen;
L
Linus Torvalds 已提交
161
	int nfrags;
162
	int ihl;
163 164 165
	u8 nexthdr[2];
	struct scatterlist *sg;
	int padlen;
166
	int err = -EINVAL;
L
Linus Torvalds 已提交
167

168
	if (!pskb_may_pull(skb, sizeof(*esph)))
L
Linus Torvalds 已提交
169 170 171 172 173
		goto out;

	if (elen <= 0 || (elen & (blksize-1)))
		goto out;

174 175 176 177 178 179 180 181
	if ((err = skb_cow_data(skb, 0, &trailer)) < 0)
		goto out;
	nfrags = err;

	skb->ip_summed = CHECKSUM_NONE;

	spin_lock(&x->lock);

L
Linus Torvalds 已提交
182 183
	/* If integrity check is required, do this. */
	if (esp->auth.icv_full_len) {
184
		u8 sum[alen];
L
Linus Torvalds 已提交
185

186 187
		err = esp_mac_digest(esp, skb, 0, skb->len - alen);
		if (err)
188
			goto unlock;
189 190

		if (skb_copy_bits(skb, skb->len - alen, sum, alen))
L
Linus Torvalds 已提交
191 192
			BUG();

193
		if (unlikely(memcmp(esp->auth.work_icv, sum, alen))) {
194
			err = -EBADMSG;
195
			goto unlock;
L
Linus Torvalds 已提交
196 197 198
		}
	}

199
	esph = (struct ip_esp_hdr *)skb->data;
L
Linus Torvalds 已提交
200 201 202

	/* Get ivec. This can be wrong, check against another impls. */
	if (esp->conf.ivlen)
203
		crypto_blkcipher_set_iv(tfm, esph->enc_data, esp->conf.ivlen);
L
Linus Torvalds 已提交
204

205
	sg = &esp->sgbuf[0];
L
Linus Torvalds 已提交
206

207
	if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
208
		err = -ENOMEM;
209 210
		sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
		if (!sg)
211
			goto unlock;
212
	}
213
	sg_init_table(sg, nfrags);
214 215 216
	skb_to_sgvec(skb, sg,
		     sizeof(*esph) + esp->conf.ivlen,
		     elen);
217
	err = crypto_blkcipher_decrypt(&desc, sg, sg, elen);
218 219
	if (unlikely(sg != &esp->sgbuf[0]))
		kfree(sg);
220 221 222 223

unlock:
	spin_unlock(&x->lock);

224
	if (unlikely(err))
225
		goto out;
L
Linus Torvalds 已提交
226

227 228
	if (skb_copy_bits(skb, skb->len-alen-2, nexthdr, 2))
		BUG();
L
Linus Torvalds 已提交
229

230
	err = -EINVAL;
231 232 233
	padlen = nexthdr[0];
	if (padlen+2 >= elen)
		goto out;
L
Linus Torvalds 已提交
234

235
	/* ... check padding bits here. Silly. :-) */
L
Linus Torvalds 已提交
236

237 238 239 240
	/* RFC4303: Drop dummy packets without any error */
	if (nexthdr[1] == IPPROTO_NONE)
		goto out;

241
	iph = ip_hdr(skb);
242 243
	ihl = iph->ihl * 4;

244 245
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
246
		struct udphdr *uh = (void *)(skb_network_header(skb) + ihl);
247 248 249 250 251 252 253 254 255 256 257 258 259

		/*
		 * 1) if the NAT-T peer's IP or port changed then
		 *    advertize the change to the keying daemon.
		 *    This is an inbound SA, so just compare
		 *    SRC ports.
		 */
		if (iph->saddr != x->props.saddr.a4 ||
		    uh->source != encap->encap_sport) {
			xfrm_address_t ipaddr;

			ipaddr.a4 = iph->saddr;
			km_new_mapping(x, &ipaddr, uh->source);
260

261 262 263 264 265 266 267
			/* XXX: perhaps add an extra
			 * policy check here, to see
			 * if we should allow or
			 * reject a packet from a
			 * different source
			 * address/port.
			 */
L
Linus Torvalds 已提交
268
		}
269

270 271 272 273 274 275 276
		/*
		 * 2) ignore UDP/TCP checksums in case
		 *    of NAT-T in Transport Mode, or
		 *    perform other post-processing fixes
		 *    as per draft-ietf-ipsec-udp-encaps-06,
		 *    section 3.1.2
		 */
277
		if (x->props.mode == XFRM_MODE_TRANSPORT)
278
			skb->ip_summed = CHECKSUM_UNNECESSARY;
L
Linus Torvalds 已提交
279 280
	}

281
	pskb_trim(skb, skb->len - alen - padlen - 2);
282 283
	__skb_pull(skb, sizeof(*esph) + esp->conf.ivlen);
	skb_set_transport_header(skb, -ihl);
284

285
	return nexthdr[1];
L
Linus Torvalds 已提交
286 287

out:
288
	return err;
L
Linus Torvalds 已提交
289 290
}

291
static u32 esp4_get_mtu(struct xfrm_state *x, int mtu)
L
Linus Torvalds 已提交
292 293
{
	struct esp_data *esp = x->data;
294
	u32 blksize = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
295 296 297 298 299 300
	u32 align = max_t(u32, blksize, esp->conf.padlen);
	u32 rem;

	mtu -= x->props.header_len + esp->auth.icv_trunc_len;
	rem = mtu & (align - 1);
	mtu &= ~(align - 1);
D
Diego Beltrami 已提交
301 302 303 304 305 306 307

	switch (x->props.mode) {
	case XFRM_MODE_TUNNEL:
		break;
	default:
	case XFRM_MODE_TRANSPORT:
		/* The worst case */
308 309
		mtu -= blksize - 4;
		mtu += min_t(u32, blksize - 4, rem);
D
Diego Beltrami 已提交
310 311
		break;
	case XFRM_MODE_BEET:
312
		/* The worst case. */
313
		mtu += min_t(u32, IPV4_BEET_PHMAXLEN, rem);
D
Diego Beltrami 已提交
314
		break;
L
Linus Torvalds 已提交
315
	}
D
Diego Beltrami 已提交
316

317
	return mtu - 2;
L
Linus Torvalds 已提交
318 319 320 321 322 323 324 325
}

static void esp4_err(struct sk_buff *skb, u32 info)
{
	struct iphdr *iph = (struct iphdr*)skb->data;
	struct ip_esp_hdr *esph = (struct ip_esp_hdr*)(skb->data+(iph->ihl<<2));
	struct xfrm_state *x;

326 327
	if (icmp_hdr(skb)->type != ICMP_DEST_UNREACH ||
	    icmp_hdr(skb)->code != ICMP_FRAG_NEEDED)
L
Linus Torvalds 已提交
328 329 330 331 332
		return;

	x = xfrm_state_lookup((xfrm_address_t *)&iph->daddr, esph->spi, IPPROTO_ESP, AF_INET);
	if (!x)
		return;
333 334
	NETDEBUG(KERN_DEBUG "pmtu discovery on SA ESP/%08x/%08x\n",
		 ntohl(esph->spi), ntohl(iph->daddr));
L
Linus Torvalds 已提交
335 336 337 338 339 340 341 342 343 344
	xfrm_state_put(x);
}

static void esp_destroy(struct xfrm_state *x)
{
	struct esp_data *esp = x->data;

	if (!esp)
		return;

345
	crypto_free_blkcipher(esp->conf.tfm);
346 347 348
	esp->conf.tfm = NULL;
	kfree(esp->conf.ivec);
	esp->conf.ivec = NULL;
349
	crypto_free_hash(esp->auth.tfm);
350 351 352
	esp->auth.tfm = NULL;
	kfree(esp->auth.work_icv);
	esp->auth.work_icv = NULL;
L
Linus Torvalds 已提交
353 354 355
	kfree(esp);
}

H
Herbert Xu 已提交
356
static int esp_init_state(struct xfrm_state *x)
L
Linus Torvalds 已提交
357 358
{
	struct esp_data *esp = NULL;
359
	struct crypto_blkcipher *tfm;
360
	u32 align;
L
Linus Torvalds 已提交
361 362 363 364

	if (x->ealg == NULL)
		goto error;

365
	esp = kzalloc(sizeof(*esp), GFP_KERNEL);
L
Linus Torvalds 已提交
366 367 368 369 370
	if (esp == NULL)
		return -ENOMEM;

	if (x->aalg) {
		struct xfrm_algo_desc *aalg_desc;
371
		struct crypto_hash *hash;
L
Linus Torvalds 已提交
372

373 374 375 376 377 378
		hash = crypto_alloc_hash(x->aalg->alg_name, 0,
					 CRYPTO_ALG_ASYNC);
		if (IS_ERR(hash))
			goto error;

		esp->auth.tfm = hash;
379 380
		if (crypto_hash_setkey(hash, x->aalg->alg_key,
				       (x->aalg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
381 382 383 384 385 386
			goto error;

		aalg_desc = xfrm_aalg_get_byname(x->aalg->alg_name, 0);
		BUG_ON(!aalg_desc);

		if (aalg_desc->uinfo.auth.icv_fullbits/8 !=
387
		    crypto_hash_digestsize(hash)) {
388 389
			NETDEBUG(KERN_INFO "ESP: %s digestsize %u != %hu\n",
				 x->aalg->alg_name,
390
				 crypto_hash_digestsize(hash),
391
				 aalg_desc->uinfo.auth.icv_fullbits/8);
L
Linus Torvalds 已提交
392 393 394 395 396 397 398 399 400 401
			goto error;
		}

		esp->auth.icv_full_len = aalg_desc->uinfo.auth.icv_fullbits/8;
		esp->auth.icv_trunc_len = aalg_desc->uinfo.auth.icv_truncbits/8;

		esp->auth.work_icv = kmalloc(esp->auth.icv_full_len, GFP_KERNEL);
		if (!esp->auth.work_icv)
			goto error;
	}
402

403 404
	tfm = crypto_alloc_blkcipher(x->ealg->alg_name, 0, CRYPTO_ALG_ASYNC);
	if (IS_ERR(tfm))
L
Linus Torvalds 已提交
405
		goto error;
406 407
	esp->conf.tfm = tfm;
	esp->conf.ivlen = crypto_blkcipher_ivsize(tfm);
L
Linus Torvalds 已提交
408 409 410 411 412
	esp->conf.padlen = 0;
	if (esp->conf.ivlen) {
		esp->conf.ivec = kmalloc(esp->conf.ivlen, GFP_KERNEL);
		if (unlikely(esp->conf.ivec == NULL))
			goto error;
413
		esp->conf.ivinitted = 0;
L
Linus Torvalds 已提交
414
	}
415 416
	if (crypto_blkcipher_setkey(tfm, x->ealg->alg_key,
				    (x->ealg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
417 418
		goto error;
	x->props.header_len = sizeof(struct ip_esp_hdr) + esp->conf.ivlen;
419
	if (x->props.mode == XFRM_MODE_TUNNEL)
L
Linus Torvalds 已提交
420
		x->props.header_len += sizeof(struct iphdr);
421 422
	else if (x->props.mode == XFRM_MODE_BEET)
		x->props.header_len += IPV4_BEET_PHMAXLEN;
L
Linus Torvalds 已提交
423 424 425 426 427 428 429 430 431 432 433 434 435 436 437
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;

		switch (encap->encap_type) {
		default:
			goto error;
		case UDP_ENCAP_ESPINUDP:
			x->props.header_len += sizeof(struct udphdr);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
			x->props.header_len += sizeof(struct udphdr) + 2 * sizeof(u32);
			break;
		}
	}
	x->data = esp;
438 439 440 441
	align = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
	if (esp->conf.padlen)
		align = max_t(u32, align, esp->conf.padlen);
	x->props.trailer_len = align + 1 + esp->auth.icv_trunc_len;
L
Linus Torvalds 已提交
442 443 444 445 446 447 448 449 450 451 452 453 454 455
	return 0;

error:
	x->data = esp;
	esp_destroy(x);
	x->data = NULL;
	return -EINVAL;
}

static struct xfrm_type esp_type =
{
	.description	= "ESP4",
	.owner		= THIS_MODULE,
	.proto	     	= IPPROTO_ESP,
456
	.flags		= XFRM_TYPE_REPLAY_PROT,
L
Linus Torvalds 已提交
457 458
	.init_state	= esp_init_state,
	.destructor	= esp_destroy,
459
	.get_mtu	= esp4_get_mtu,
L
Linus Torvalds 已提交
460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494
	.input		= esp_input,
	.output		= esp_output
};

static struct net_protocol esp4_protocol = {
	.handler	=	xfrm4_rcv,
	.err_handler	=	esp4_err,
	.no_policy	=	1,
};

static int __init esp4_init(void)
{
	if (xfrm_register_type(&esp_type, AF_INET) < 0) {
		printk(KERN_INFO "ip esp init: can't add xfrm type\n");
		return -EAGAIN;
	}
	if (inet_add_protocol(&esp4_protocol, IPPROTO_ESP) < 0) {
		printk(KERN_INFO "ip esp init: can't add protocol\n");
		xfrm_unregister_type(&esp_type, AF_INET);
		return -EAGAIN;
	}
	return 0;
}

static void __exit esp4_fini(void)
{
	if (inet_del_protocol(&esp4_protocol, IPPROTO_ESP) < 0)
		printk(KERN_INFO "ip esp close: can't remove protocol\n");
	if (xfrm_unregister_type(&esp_type, AF_INET) < 0)
		printk(KERN_INFO "ip esp close: can't remove xfrm type\n");
}

module_init(esp4_init);
module_exit(esp4_fini);
MODULE_LICENSE("GPL");
495
MODULE_ALIAS_XFRM_TYPE(AF_INET, XFRM_PROTO_ESP);