mirror of
git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2025-08-05 16:54:27 +00:00
xfrm: Provide private skb extensions for segmented and hw offloaded ESP packets
Commit94579ac3f6
("xfrm: Fix double ESP trailer insertion in IPsec crypto offload.") added a XFRM_XMIT flag to avoid duplicate ESP trailer insertion on HW offload. This flag is set on the secpath that is shared amongst segments. This lead to a situation where some segments are not transformed correctly when segmentation happens at layer 3. Fix this by using private skb extensions for segmented and hw offloaded ESP packets. Fixes:94579ac3f6
("xfrm: Fix double ESP trailer insertion in IPsec crypto offload.") Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
This commit is contained in:
parent
b1e3a56070
commit
c7dbf4c088
3 changed files with 20 additions and 4 deletions
|
@ -314,8 +314,17 @@ static int esp_xmit(struct xfrm_state *x, struct sk_buff *skb, netdev_features_
|
||||||
ip_hdr(skb)->tot_len = htons(skb->len);
|
ip_hdr(skb)->tot_len = htons(skb->len);
|
||||||
ip_send_check(ip_hdr(skb));
|
ip_send_check(ip_hdr(skb));
|
||||||
|
|
||||||
if (hw_offload)
|
if (hw_offload) {
|
||||||
|
if (!skb_ext_add(skb, SKB_EXT_SEC_PATH))
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
xo = xfrm_offload(skb);
|
||||||
|
if (!xo)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
xo->flags |= XFRM_XMIT;
|
||||||
return 0;
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
err = esp_output_tail(x, skb, &esp);
|
err = esp_output_tail(x, skb, &esp);
|
||||||
if (err)
|
if (err)
|
||||||
|
|
|
@ -348,8 +348,17 @@ static int esp6_xmit(struct xfrm_state *x, struct sk_buff *skb, netdev_features
|
||||||
|
|
||||||
ipv6_hdr(skb)->payload_len = htons(len);
|
ipv6_hdr(skb)->payload_len = htons(len);
|
||||||
|
|
||||||
if (hw_offload)
|
if (hw_offload) {
|
||||||
|
if (!skb_ext_add(skb, SKB_EXT_SEC_PATH))
|
||||||
|
return -ENOMEM;
|
||||||
|
|
||||||
|
xo = xfrm_offload(skb);
|
||||||
|
if (!xo)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
xo->flags |= XFRM_XMIT;
|
||||||
return 0;
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
err = esp6_output_tail(x, skb, &esp);
|
err = esp6_output_tail(x, skb, &esp);
|
||||||
if (err)
|
if (err)
|
||||||
|
|
|
@ -134,8 +134,6 @@ struct sk_buff *validate_xmit_xfrm(struct sk_buff *skb, netdev_features_t featur
|
||||||
return skb;
|
return skb;
|
||||||
}
|
}
|
||||||
|
|
||||||
xo->flags |= XFRM_XMIT;
|
|
||||||
|
|
||||||
if (skb_is_gso(skb) && unlikely(x->xso.dev != dev)) {
|
if (skb_is_gso(skb) && unlikely(x->xso.dev != dev)) {
|
||||||
struct sk_buff *segs;
|
struct sk_buff *segs;
|
||||||
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue