esp4.c 11.5 KB
Newer Older
1
#include <linux/err.h>
L
Linus Torvalds 已提交
2 3 4 5 6 7
#include <linux/module.h>
#include <net/ip.h>
#include <net/xfrm.h>
#include <net/esp.h>
#include <asm/scatterlist.h>
#include <linux/crypto.h>
H
Herbert Xu 已提交
8
#include <linux/kernel.h>
L
Linus Torvalds 已提交
9 10
#include <linux/pfkeyv2.h>
#include <linux/random.h>
11
#include <linux/spinlock.h>
L
Linus Torvalds 已提交
12
#include <net/icmp.h>
13
#include <net/protocol.h>
L
Linus Torvalds 已提交
14 15 16 17 18 19 20
#include <net/udp.h>

static int esp_output(struct xfrm_state *x, struct sk_buff *skb)
{
	int err;
	struct iphdr *top_iph;
	struct ip_esp_hdr *esph;
21 22
	struct crypto_blkcipher *tfm;
	struct blkcipher_desc desc;
L
Linus Torvalds 已提交
23 24
	struct esp_data *esp;
	struct sk_buff *trailer;
25
	u8 *tail;
L
Linus Torvalds 已提交
26 27 28 29 30
	int blksize;
	int clen;
	int alen;
	int nfrags;

31
	/* skb is pure payload to encrypt */
L
Linus Torvalds 已提交
32 33 34 35 36 37 38 39 40

	err = -ENOMEM;

	/* Round to block size */
	clen = skb->len;

	esp = x->data;
	alen = esp->auth.icv_trunc_len;
	tfm = esp->conf.tfm;
41 42 43
	desc.tfm = tfm;
	desc.flags = 0;
	blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
H
Herbert Xu 已提交
44
	clen = ALIGN(clen + 2, blksize);
L
Linus Torvalds 已提交
45
	if (esp->conf.padlen)
H
Herbert Xu 已提交
46
		clen = ALIGN(clen, esp->conf.padlen);
L
Linus Torvalds 已提交
47 48 49 50 51

	if ((nfrags = skb_cow_data(skb, clen-skb->len+alen, &trailer)) < 0)
		goto error;

	/* Fill padding... */
52
	tail = skb_tail_pointer(trailer);
L
Linus Torvalds 已提交
53 54 55
	do {
		int i;
		for (i=0; i<clen-skb->len - 2; i++)
56
			tail[i] = i + 1;
L
Linus Torvalds 已提交
57
	} while (0);
58
	tail[clen - skb->len - 2] = (clen - skb->len) - 2;
L
Linus Torvalds 已提交
59 60
	pskb_put(skb, trailer, clen - skb->len);

61
	skb_push(skb, -skb_network_offset(skb));
62
	top_iph = ip_hdr(skb);
63 64
	esph = (struct ip_esp_hdr *)(skb_network_header(skb) +
				     top_iph->ihl * 4);
L
Linus Torvalds 已提交
65
	top_iph->tot_len = htons(skb->len + alen);
66
	*(skb_tail_pointer(trailer) - 1) = top_iph->protocol;
L
Linus Torvalds 已提交
67

68 69
	spin_lock_bh(&x->lock);

L
Linus Torvalds 已提交
70 71 72 73
	/* this is non-NULL only with UDP Encapsulation */
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
		struct udphdr *uh;
A
Al Viro 已提交
74
		__be32 *udpdata32;
L
Linus Torvalds 已提交
75 76 77 78 79 80 81 82 83 84 85 86 87

		uh = (struct udphdr *)esph;
		uh->source = encap->encap_sport;
		uh->dest = encap->encap_dport;
		uh->len = htons(skb->len + alen - top_iph->ihl*4);
		uh->check = 0;

		switch (encap->encap_type) {
		default:
		case UDP_ENCAP_ESPINUDP:
			esph = (struct ip_esp_hdr *)(uh + 1);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
A
Al Viro 已提交
88
			udpdata32 = (__be32 *)(uh + 1);
L
Linus Torvalds 已提交
89 90 91 92 93 94 95 96 97 98
			udpdata32[0] = udpdata32[1] = 0;
			esph = (struct ip_esp_hdr *)(udpdata32 + 2);
			break;
		}

		top_iph->protocol = IPPROTO_UDP;
	} else
		top_iph->protocol = IPPROTO_ESP;

	esph->spi = x->id.spi;
99
	esph->seq_no = htonl(XFRM_SKB_CB(skb)->seq);
L
Linus Torvalds 已提交
100

101 102 103 104 105
	if (esp->conf.ivlen) {
		if (unlikely(!esp->conf.ivinitted)) {
			get_random_bytes(esp->conf.ivec, esp->conf.ivlen);
			esp->conf.ivinitted = 1;
		}
106
		crypto_blkcipher_set_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
107
	}
L
Linus Torvalds 已提交
108 109 110 111 112 113 114

	do {
		struct scatterlist *sg = &esp->sgbuf[0];

		if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
			sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
			if (!sg)
115
				goto unlock;
L
Linus Torvalds 已提交
116 117
		}
		skb_to_sgvec(skb, sg, esph->enc_data+esp->conf.ivlen-skb->data, clen);
118
		err = crypto_blkcipher_encrypt(&desc, sg, sg, clen);
L
Linus Torvalds 已提交
119 120 121 122
		if (unlikely(sg != &esp->sgbuf[0]))
			kfree(sg);
	} while (0);

123
	if (unlikely(err))
124
		goto unlock;
125

L
Linus Torvalds 已提交
126
	if (esp->conf.ivlen) {
127 128
		memcpy(esph->enc_data, esp->conf.ivec, esp->conf.ivlen);
		crypto_blkcipher_get_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
L
Linus Torvalds 已提交
129 130 131
	}

	if (esp->auth.icv_full_len) {
132 133 134
		err = esp_mac_digest(esp, skb, (u8 *)esph - skb->data,
				     sizeof(*esph) + esp->conf.ivlen + clen);
		memcpy(pskb_put(skb, trailer, alen), esp->auth.work_icv, alen);
L
Linus Torvalds 已提交
135 136
	}

137 138 139
unlock:
	spin_unlock_bh(&x->lock);

L
Linus Torvalds 已提交
140 141 142 143 144 145 146 147 148 149 150
	ip_send_check(top_iph);

error:
	return err;
}

/*
 * Note: detecting truncated vs. non-truncated authentication data is very
 * expensive, so we only support truncated data, which is the recommended
 * and common case.
 */
151
static int esp_input(struct xfrm_state *x, struct sk_buff *skb)
L
Linus Torvalds 已提交
152 153 154 155
{
	struct iphdr *iph;
	struct ip_esp_hdr *esph;
	struct esp_data *esp = x->data;
156 157
	struct crypto_blkcipher *tfm = esp->conf.tfm;
	struct blkcipher_desc desc = { .tfm = tfm };
L
Linus Torvalds 已提交
158
	struct sk_buff *trailer;
159
	int blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
L
Linus Torvalds 已提交
160 161 162
	int alen = esp->auth.icv_trunc_len;
	int elen = skb->len - sizeof(struct ip_esp_hdr) - esp->conf.ivlen - alen;
	int nfrags;
163
	int ihl;
164 165 166
	u8 nexthdr[2];
	struct scatterlist *sg;
	int padlen;
167
	int err;
L
Linus Torvalds 已提交
168 169 170 171 172 173 174 175 176

	if (!pskb_may_pull(skb, sizeof(struct ip_esp_hdr)))
		goto out;

	if (elen <= 0 || (elen & (blksize-1)))
		goto out;

	/* If integrity check is required, do this. */
	if (esp->auth.icv_full_len) {
177
		u8 sum[alen];
L
Linus Torvalds 已提交
178

179 180 181 182 183
		err = esp_mac_digest(esp, skb, 0, skb->len - alen);
		if (err)
			goto out;

		if (skb_copy_bits(skb, skb->len - alen, sum, alen))
L
Linus Torvalds 已提交
184 185
			BUG();

186
		if (unlikely(memcmp(esp->auth.work_icv, sum, alen))) {
L
Linus Torvalds 已提交
187 188 189 190 191 192 193 194 195 196 197 198 199 200
			x->stats.integrity_failed++;
			goto out;
		}
	}

	if ((nfrags = skb_cow_data(skb, 0, &trailer)) < 0)
		goto out;

	skb->ip_summed = CHECKSUM_NONE;

	esph = (struct ip_esp_hdr*)skb->data;

	/* Get ivec. This can be wrong, check against another impls. */
	if (esp->conf.ivlen)
201
		crypto_blkcipher_set_iv(tfm, esph->enc_data, esp->conf.ivlen);
L
Linus Torvalds 已提交
202

203
	sg = &esp->sgbuf[0];
L
Linus Torvalds 已提交
204

205 206 207 208 209 210
	if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
		sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
		if (!sg)
			goto out;
	}
	skb_to_sgvec(skb, sg, sizeof(struct ip_esp_hdr) + esp->conf.ivlen, elen);
211
	err = crypto_blkcipher_decrypt(&desc, sg, sg, elen);
212 213
	if (unlikely(sg != &esp->sgbuf[0]))
		kfree(sg);
214 215
	if (unlikely(err))
		return err;
L
Linus Torvalds 已提交
216

217 218
	if (skb_copy_bits(skb, skb->len-alen-2, nexthdr, 2))
		BUG();
L
Linus Torvalds 已提交
219

220 221 222
	padlen = nexthdr[0];
	if (padlen+2 >= elen)
		goto out;
L
Linus Torvalds 已提交
223

224
	/* ... check padding bits here. Silly. :-) */
L
Linus Torvalds 已提交
225

226
	iph = ip_hdr(skb);
227 228
	ihl = iph->ihl * 4;

229 230
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
231
		struct udphdr *uh = (void *)(skb_network_header(skb) + ihl);
232 233 234 235 236 237 238 239 240 241 242 243 244

		/*
		 * 1) if the NAT-T peer's IP or port changed then
		 *    advertize the change to the keying daemon.
		 *    This is an inbound SA, so just compare
		 *    SRC ports.
		 */
		if (iph->saddr != x->props.saddr.a4 ||
		    uh->source != encap->encap_sport) {
			xfrm_address_t ipaddr;

			ipaddr.a4 = iph->saddr;
			km_new_mapping(x, &ipaddr, uh->source);
245

246 247 248 249 250 251 252
			/* XXX: perhaps add an extra
			 * policy check here, to see
			 * if we should allow or
			 * reject a packet from a
			 * different source
			 * address/port.
			 */
L
Linus Torvalds 已提交
253
		}
254

255 256 257 258 259 260 261
		/*
		 * 2) ignore UDP/TCP checksums in case
		 *    of NAT-T in Transport Mode, or
		 *    perform other post-processing fixes
		 *    as per draft-ietf-ipsec-udp-encaps-06,
		 *    section 3.1.2
		 */
262
		if (x->props.mode == XFRM_MODE_TRANSPORT)
263
			skb->ip_summed = CHECKSUM_UNNECESSARY;
L
Linus Torvalds 已提交
264 265
	}

266 267
	iph->protocol = nexthdr[1];
	pskb_trim(skb, skb->len - alen - padlen - 2);
268 269
	__skb_pull(skb, sizeof(*esph) + esp->conf.ivlen);
	skb_set_transport_header(skb, -ihl);
270

L
Linus Torvalds 已提交
271 272 273 274 275 276
	return 0;

out:
	return -EINVAL;
}

277
static u32 esp4_get_mtu(struct xfrm_state *x, int mtu)
L
Linus Torvalds 已提交
278 279
{
	struct esp_data *esp = x->data;
280
	u32 blksize = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
281 282 283 284 285 286
	u32 align = max_t(u32, blksize, esp->conf.padlen);
	u32 rem;

	mtu -= x->props.header_len + esp->auth.icv_trunc_len;
	rem = mtu & (align - 1);
	mtu &= ~(align - 1);
D
Diego Beltrami 已提交
287 288 289 290 291 292 293

	switch (x->props.mode) {
	case XFRM_MODE_TUNNEL:
		break;
	default:
	case XFRM_MODE_TRANSPORT:
		/* The worst case */
294 295
		mtu -= blksize - 4;
		mtu += min_t(u32, blksize - 4, rem);
D
Diego Beltrami 已提交
296 297
		break;
	case XFRM_MODE_BEET:
298
		/* The worst case. */
299
		mtu += min_t(u32, IPV4_BEET_PHMAXLEN, rem);
D
Diego Beltrami 已提交
300
		break;
L
Linus Torvalds 已提交
301
	}
D
Diego Beltrami 已提交
302

303
	return mtu - 2;
L
Linus Torvalds 已提交
304 305 306 307 308 309 310 311
}

static void esp4_err(struct sk_buff *skb, u32 info)
{
	struct iphdr *iph = (struct iphdr*)skb->data;
	struct ip_esp_hdr *esph = (struct ip_esp_hdr*)(skb->data+(iph->ihl<<2));
	struct xfrm_state *x;

312 313
	if (icmp_hdr(skb)->type != ICMP_DEST_UNREACH ||
	    icmp_hdr(skb)->code != ICMP_FRAG_NEEDED)
L
Linus Torvalds 已提交
314 315 316 317 318
		return;

	x = xfrm_state_lookup((xfrm_address_t *)&iph->daddr, esph->spi, IPPROTO_ESP, AF_INET);
	if (!x)
		return;
319 320
	NETDEBUG(KERN_DEBUG "pmtu discovery on SA ESP/%08x/%08x\n",
		 ntohl(esph->spi), ntohl(iph->daddr));
L
Linus Torvalds 已提交
321 322 323 324 325 326 327 328 329 330
	xfrm_state_put(x);
}

static void esp_destroy(struct xfrm_state *x)
{
	struct esp_data *esp = x->data;

	if (!esp)
		return;

331
	crypto_free_blkcipher(esp->conf.tfm);
332 333 334
	esp->conf.tfm = NULL;
	kfree(esp->conf.ivec);
	esp->conf.ivec = NULL;
335
	crypto_free_hash(esp->auth.tfm);
336 337 338
	esp->auth.tfm = NULL;
	kfree(esp->auth.work_icv);
	esp->auth.work_icv = NULL;
L
Linus Torvalds 已提交
339 340 341
	kfree(esp);
}

H
Herbert Xu 已提交
342
static int esp_init_state(struct xfrm_state *x)
L
Linus Torvalds 已提交
343 344
{
	struct esp_data *esp = NULL;
345
	struct crypto_blkcipher *tfm;
346
	u32 align;
L
Linus Torvalds 已提交
347 348 349 350

	if (x->ealg == NULL)
		goto error;

351
	esp = kzalloc(sizeof(*esp), GFP_KERNEL);
L
Linus Torvalds 已提交
352 353 354 355 356
	if (esp == NULL)
		return -ENOMEM;

	if (x->aalg) {
		struct xfrm_algo_desc *aalg_desc;
357
		struct crypto_hash *hash;
L
Linus Torvalds 已提交
358

359 360 361 362 363 364
		hash = crypto_alloc_hash(x->aalg->alg_name, 0,
					 CRYPTO_ALG_ASYNC);
		if (IS_ERR(hash))
			goto error;

		esp->auth.tfm = hash;
365 366
		if (crypto_hash_setkey(hash, x->aalg->alg_key,
				       (x->aalg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
367 368 369 370 371 372
			goto error;

		aalg_desc = xfrm_aalg_get_byname(x->aalg->alg_name, 0);
		BUG_ON(!aalg_desc);

		if (aalg_desc->uinfo.auth.icv_fullbits/8 !=
373
		    crypto_hash_digestsize(hash)) {
374 375
			NETDEBUG(KERN_INFO "ESP: %s digestsize %u != %hu\n",
				 x->aalg->alg_name,
376
				 crypto_hash_digestsize(hash),
377
				 aalg_desc->uinfo.auth.icv_fullbits/8);
L
Linus Torvalds 已提交
378 379 380 381 382 383 384 385 386 387
			goto error;
		}

		esp->auth.icv_full_len = aalg_desc->uinfo.auth.icv_fullbits/8;
		esp->auth.icv_trunc_len = aalg_desc->uinfo.auth.icv_truncbits/8;

		esp->auth.work_icv = kmalloc(esp->auth.icv_full_len, GFP_KERNEL);
		if (!esp->auth.work_icv)
			goto error;
	}
388

389 390
	tfm = crypto_alloc_blkcipher(x->ealg->alg_name, 0, CRYPTO_ALG_ASYNC);
	if (IS_ERR(tfm))
L
Linus Torvalds 已提交
391
		goto error;
392 393
	esp->conf.tfm = tfm;
	esp->conf.ivlen = crypto_blkcipher_ivsize(tfm);
L
Linus Torvalds 已提交
394 395 396 397 398
	esp->conf.padlen = 0;
	if (esp->conf.ivlen) {
		esp->conf.ivec = kmalloc(esp->conf.ivlen, GFP_KERNEL);
		if (unlikely(esp->conf.ivec == NULL))
			goto error;
399
		esp->conf.ivinitted = 0;
L
Linus Torvalds 已提交
400
	}
401 402
	if (crypto_blkcipher_setkey(tfm, x->ealg->alg_key,
				    (x->ealg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
403 404
		goto error;
	x->props.header_len = sizeof(struct ip_esp_hdr) + esp->conf.ivlen;
405
	if (x->props.mode == XFRM_MODE_TUNNEL)
L
Linus Torvalds 已提交
406
		x->props.header_len += sizeof(struct iphdr);
407 408
	else if (x->props.mode == XFRM_MODE_BEET)
		x->props.header_len += IPV4_BEET_PHMAXLEN;
L
Linus Torvalds 已提交
409 410 411 412 413 414 415 416 417 418 419 420 421 422 423
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;

		switch (encap->encap_type) {
		default:
			goto error;
		case UDP_ENCAP_ESPINUDP:
			x->props.header_len += sizeof(struct udphdr);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
			x->props.header_len += sizeof(struct udphdr) + 2 * sizeof(u32);
			break;
		}
	}
	x->data = esp;
424 425 426 427
	align = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
	if (esp->conf.padlen)
		align = max_t(u32, align, esp->conf.padlen);
	x->props.trailer_len = align + 1 + esp->auth.icv_trunc_len;
L
Linus Torvalds 已提交
428 429 430 431 432 433 434 435 436 437 438 439 440 441
	return 0;

error:
	x->data = esp;
	esp_destroy(x);
	x->data = NULL;
	return -EINVAL;
}

static struct xfrm_type esp_type =
{
	.description	= "ESP4",
	.owner		= THIS_MODULE,
	.proto	     	= IPPROTO_ESP,
442
	.flags		= XFRM_TYPE_REPLAY_PROT,
L
Linus Torvalds 已提交
443 444
	.init_state	= esp_init_state,
	.destructor	= esp_destroy,
445
	.get_mtu	= esp4_get_mtu,
L
Linus Torvalds 已提交
446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480
	.input		= esp_input,
	.output		= esp_output
};

static struct net_protocol esp4_protocol = {
	.handler	=	xfrm4_rcv,
	.err_handler	=	esp4_err,
	.no_policy	=	1,
};

static int __init esp4_init(void)
{
	if (xfrm_register_type(&esp_type, AF_INET) < 0) {
		printk(KERN_INFO "ip esp init: can't add xfrm type\n");
		return -EAGAIN;
	}
	if (inet_add_protocol(&esp4_protocol, IPPROTO_ESP) < 0) {
		printk(KERN_INFO "ip esp init: can't add protocol\n");
		xfrm_unregister_type(&esp_type, AF_INET);
		return -EAGAIN;
	}
	return 0;
}

static void __exit esp4_fini(void)
{
	if (inet_del_protocol(&esp4_protocol, IPPROTO_ESP) < 0)
		printk(KERN_INFO "ip esp close: can't remove protocol\n");
	if (xfrm_unregister_type(&esp_type, AF_INET) < 0)
		printk(KERN_INFO "ip esp close: can't remove xfrm type\n");
}

module_init(esp4_init);
module_exit(esp4_fini);
MODULE_LICENSE("GPL");
481
MODULE_ALIAS_XFRM_TYPE(AF_INET, XFRM_PROTO_ESP);