]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blob - net/ipv4/ip_tunnel_core.c
ipv4: fix a potential use after free in ip_tunnel_core.c
[mirror_ubuntu-bionic-kernel.git] / net / ipv4 / ip_tunnel_core.c
1 /*
2 * Copyright (c) 2013 Nicira, Inc.
3 *
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of version 2 of the GNU General Public
6 * License as published by the Free Software Foundation.
7 *
8 * This program is distributed in the hope that it will be useful, but
9 * WITHOUT ANY WARRANTY; without even the implied warranty of
10 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
11 * General Public License for more details.
12 *
13 * You should have received a copy of the GNU General Public License
14 * along with this program; if not, write to the Free Software
15 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
16 * 02110-1301, USA
17 */
18
19 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
20
21 #include <linux/types.h>
22 #include <linux/kernel.h>
23 #include <linux/skbuff.h>
24 #include <linux/netdevice.h>
25 #include <linux/in.h>
26 #include <linux/if_arp.h>
27 #include <linux/mroute.h>
28 #include <linux/init.h>
29 #include <linux/in6.h>
30 #include <linux/inetdevice.h>
31 #include <linux/netfilter_ipv4.h>
32 #include <linux/etherdevice.h>
33 #include <linux/if_ether.h>
34 #include <linux/if_vlan.h>
35
36 #include <net/ip.h>
37 #include <net/icmp.h>
38 #include <net/protocol.h>
39 #include <net/ip_tunnels.h>
40 #include <net/arp.h>
41 #include <net/checksum.h>
42 #include <net/dsfield.h>
43 #include <net/inet_ecn.h>
44 #include <net/xfrm.h>
45 #include <net/net_namespace.h>
46 #include <net/netns/generic.h>
47 #include <net/rtnetlink.h>
48
49 int iptunnel_xmit(struct sock *sk, struct rtable *rt, struct sk_buff *skb,
50 __be32 src, __be32 dst, __u8 proto,
51 __u8 tos, __u8 ttl, __be16 df, bool xnet)
52 {
53 int pkt_len = skb->len;
54 struct iphdr *iph;
55 int err;
56
57 skb_scrub_packet(skb, xnet);
58
59 skb_clear_hash(skb);
60 skb_dst_set(skb, &rt->dst);
61 memset(IPCB(skb), 0, sizeof(*IPCB(skb)));
62
63 /* Push down and install the IP header. */
64 skb_push(skb, sizeof(struct iphdr));
65 skb_reset_network_header(skb);
66
67 iph = ip_hdr(skb);
68
69 iph->version = 4;
70 iph->ihl = sizeof(struct iphdr) >> 2;
71 iph->frag_off = df;
72 iph->protocol = proto;
73 iph->tos = tos;
74 iph->daddr = dst;
75 iph->saddr = src;
76 iph->ttl = ttl;
77 __ip_select_ident(iph, skb_shinfo(skb)->gso_segs ?: 1);
78
79 err = ip_local_out_sk(sk, skb);
80 if (unlikely(net_xmit_eval(err)))
81 pkt_len = 0;
82 return pkt_len;
83 }
84 EXPORT_SYMBOL_GPL(iptunnel_xmit);
85
86 int iptunnel_pull_header(struct sk_buff *skb, int hdr_len, __be16 inner_proto)
87 {
88 if (unlikely(!pskb_may_pull(skb, hdr_len)))
89 return -ENOMEM;
90
91 skb_pull_rcsum(skb, hdr_len);
92
93 if (inner_proto == htons(ETH_P_TEB)) {
94 struct ethhdr *eh;
95
96 if (unlikely(!pskb_may_pull(skb, ETH_HLEN)))
97 return -ENOMEM;
98
99 eh = (struct ethhdr *)skb->data;
100 if (likely(ntohs(eh->h_proto) >= ETH_P_802_3_MIN))
101 skb->protocol = eh->h_proto;
102 else
103 skb->protocol = htons(ETH_P_802_2);
104
105 } else {
106 skb->protocol = inner_proto;
107 }
108
109 nf_reset(skb);
110 secpath_reset(skb);
111 skb_clear_hash_if_not_l4(skb);
112 skb_dst_drop(skb);
113 skb->vlan_tci = 0;
114 skb_set_queue_mapping(skb, 0);
115 skb->pkt_type = PACKET_HOST;
116 return 0;
117 }
118 EXPORT_SYMBOL_GPL(iptunnel_pull_header);
119
120 struct sk_buff *iptunnel_handle_offloads(struct sk_buff *skb,
121 bool csum_help,
122 int gso_type_mask)
123 {
124 int err;
125
126 if (likely(!skb->encapsulation)) {
127 skb_reset_inner_headers(skb);
128 skb->encapsulation = 1;
129 }
130
131 if (skb_is_gso(skb)) {
132 err = skb_unclone(skb, GFP_ATOMIC);
133 if (unlikely(err))
134 goto error;
135 skb_shinfo(skb)->gso_type |= gso_type_mask;
136 return skb;
137 }
138
139 /* If packet is not gso and we are resolving any partial checksum,
140 * clear encapsulation flag. This allows setting CHECKSUM_PARTIAL
141 * on the outer header without confusing devices that implement
142 * NETIF_F_IP_CSUM with encapsulation.
143 */
144 if (csum_help)
145 skb->encapsulation = 0;
146
147 if (skb->ip_summed == CHECKSUM_PARTIAL && csum_help) {
148 err = skb_checksum_help(skb);
149 if (unlikely(err))
150 goto error;
151 } else if (skb->ip_summed != CHECKSUM_PARTIAL)
152 skb->ip_summed = CHECKSUM_NONE;
153
154 return skb;
155 error:
156 kfree_skb(skb);
157 return ERR_PTR(err);
158 }
159 EXPORT_SYMBOL_GPL(iptunnel_handle_offloads);
160
161 /* Often modified stats are per cpu, other are shared (netdev->stats) */
162 struct rtnl_link_stats64 *ip_tunnel_get_stats64(struct net_device *dev,
163 struct rtnl_link_stats64 *tot)
164 {
165 int i;
166
167 for_each_possible_cpu(i) {
168 const struct pcpu_sw_netstats *tstats =
169 per_cpu_ptr(dev->tstats, i);
170 u64 rx_packets, rx_bytes, tx_packets, tx_bytes;
171 unsigned int start;
172
173 do {
174 start = u64_stats_fetch_begin_irq(&tstats->syncp);
175 rx_packets = tstats->rx_packets;
176 tx_packets = tstats->tx_packets;
177 rx_bytes = tstats->rx_bytes;
178 tx_bytes = tstats->tx_bytes;
179 } while (u64_stats_fetch_retry_irq(&tstats->syncp, start));
180
181 tot->rx_packets += rx_packets;
182 tot->tx_packets += tx_packets;
183 tot->rx_bytes += rx_bytes;
184 tot->tx_bytes += tx_bytes;
185 }
186
187 tot->multicast = dev->stats.multicast;
188
189 tot->rx_crc_errors = dev->stats.rx_crc_errors;
190 tot->rx_fifo_errors = dev->stats.rx_fifo_errors;
191 tot->rx_length_errors = dev->stats.rx_length_errors;
192 tot->rx_frame_errors = dev->stats.rx_frame_errors;
193 tot->rx_errors = dev->stats.rx_errors;
194
195 tot->tx_fifo_errors = dev->stats.tx_fifo_errors;
196 tot->tx_carrier_errors = dev->stats.tx_carrier_errors;
197 tot->tx_dropped = dev->stats.tx_dropped;
198 tot->tx_aborted_errors = dev->stats.tx_aborted_errors;
199 tot->tx_errors = dev->stats.tx_errors;
200
201 tot->collisions = dev->stats.collisions;
202
203 return tot;
204 }
205 EXPORT_SYMBOL_GPL(ip_tunnel_get_stats64);