|
|
@@ -74,6 +74,33 @@ drop:
|
|
|
return 0;
|
|
|
}
|
|
|
|
|
|
+static int vti_input_ipip(struct sk_buff *skb, int nexthdr, __be32 spi,
|
|
|
+ int encap_type)
|
|
|
+{
|
|
|
+ struct ip_tunnel *tunnel;
|
|
|
+ const struct iphdr *iph = ip_hdr(skb);
|
|
|
+ struct net *net = dev_net(skb->dev);
|
|
|
+ struct ip_tunnel_net *itn = net_generic(net, vti_net_id);
|
|
|
+
|
|
|
+ tunnel = ip_tunnel_lookup(itn, skb->dev->ifindex, TUNNEL_NO_KEY,
|
|
|
+ iph->saddr, iph->daddr, 0);
|
|
|
+ if (tunnel) {
|
|
|
+ if (!xfrm4_policy_check(NULL, XFRM_POLICY_IN, skb))
|
|
|
+ goto drop;
|
|
|
+
|
|
|
+ XFRM_TUNNEL_SKB_CB(skb)->tunnel.ip4 = tunnel;
|
|
|
+
|
|
|
+ skb->dev = tunnel->dev;
|
|
|
+
|
|
|
+ return xfrm_input(skb, nexthdr, spi, encap_type);
|
|
|
+ }
|
|
|
+
|
|
|
+ return -EINVAL;
|
|
|
+drop:
|
|
|
+ kfree_skb(skb);
|
|
|
+ return 0;
|
|
|
+}
|
|
|
+
|
|
|
static int vti_rcv(struct sk_buff *skb)
|
|
|
{
|
|
|
XFRM_SPI_SKB_CB(skb)->family = AF_INET;
|
|
|
@@ -82,6 +109,14 @@ static int vti_rcv(struct sk_buff *skb)
|
|
|
return vti_input(skb, ip_hdr(skb)->protocol, 0, 0);
|
|
|
}
|
|
|
|
|
|
+static int vti_rcv_ipip(struct sk_buff *skb)
|
|
|
+{
|
|
|
+ XFRM_SPI_SKB_CB(skb)->family = AF_INET;
|
|
|
+ XFRM_SPI_SKB_CB(skb)->daddroff = offsetof(struct iphdr, daddr);
|
|
|
+
|
|
|
+ return vti_input_ipip(skb, ip_hdr(skb)->protocol, ip_hdr(skb)->saddr, 0);
|
|
|
+}
|
|
|
+
|
|
|
static int vti_rcv_cb(struct sk_buff *skb, int err)
|
|
|
{
|
|
|
unsigned short family;
|
|
|
@@ -435,6 +470,12 @@ static struct xfrm4_protocol vti_ipcomp4_protocol __read_mostly = {
|
|
|
.priority = 100,
|
|
|
};
|
|
|
|
|
|
+static struct xfrm_tunnel ipip_handler __read_mostly = {
|
|
|
+ .handler = vti_rcv_ipip,
|
|
|
+ .err_handler = vti4_err,
|
|
|
+ .priority = 0,
|
|
|
+};
|
|
|
+
|
|
|
static int __net_init vti_init_net(struct net *net)
|
|
|
{
|
|
|
int err;
|
|
|
@@ -603,6 +644,13 @@ static int __init vti_init(void)
|
|
|
if (err < 0)
|
|
|
goto xfrm_proto_comp_failed;
|
|
|
|
|
|
+ msg = "ipip tunnel";
|
|
|
+ err = xfrm4_tunnel_register(&ipip_handler, AF_INET);
|
|
|
+ if (err < 0) {
|
|
|
+ pr_info("%s: cant't register tunnel\n",__func__);
|
|
|
+ goto xfrm_tunnel_failed;
|
|
|
+ }
|
|
|
+
|
|
|
msg = "netlink interface";
|
|
|
err = rtnl_link_register(&vti_link_ops);
|
|
|
if (err < 0)
|
|
|
@@ -612,6 +660,8 @@ static int __init vti_init(void)
|
|
|
|
|
|
rtnl_link_failed:
|
|
|
xfrm4_protocol_deregister(&vti_ipcomp4_protocol, IPPROTO_COMP);
|
|
|
+xfrm_tunnel_failed:
|
|
|
+ xfrm4_tunnel_deregister(&ipip_handler, AF_INET);
|
|
|
xfrm_proto_comp_failed:
|
|
|
xfrm4_protocol_deregister(&vti_ah4_protocol, IPPROTO_AH);
|
|
|
xfrm_proto_ah_failed:
|