1fcf59617SAndrey V. Elsukov /*-
2fcf59617SAndrey V. Elsukov * Copyright (c) 2016 Andrey V. Elsukov <ae@FreeBSD.org>
3fcf59617SAndrey V. Elsukov * All rights reserved.
4fcf59617SAndrey V. Elsukov *
5fcf59617SAndrey V. Elsukov * Redistribution and use in source and binary forms, with or without
6fcf59617SAndrey V. Elsukov * modification, are permitted provided that the following conditions
7fcf59617SAndrey V. Elsukov * are met:
8fcf59617SAndrey V. Elsukov *
9fcf59617SAndrey V. Elsukov * 1. Redistributions of source code must retain the above copyright
10fcf59617SAndrey V. Elsukov * notice, this list of conditions and the following disclaimer.
11fcf59617SAndrey V. Elsukov * 2. Redistributions in binary form must reproduce the above copyright
12fcf59617SAndrey V. Elsukov * notice, this list of conditions and the following disclaimer in the
13fcf59617SAndrey V. Elsukov * documentation and/or other materials provided with the distribution.
14fcf59617SAndrey V. Elsukov *
15fcf59617SAndrey V. Elsukov * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16fcf59617SAndrey V. Elsukov * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17fcf59617SAndrey V. Elsukov * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18fcf59617SAndrey V. Elsukov * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19fcf59617SAndrey V. Elsukov * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20fcf59617SAndrey V. Elsukov * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21fcf59617SAndrey V. Elsukov * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22fcf59617SAndrey V. Elsukov * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23fcf59617SAndrey V. Elsukov * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24fcf59617SAndrey V. Elsukov * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25fcf59617SAndrey V. Elsukov */
26fcf59617SAndrey V. Elsukov
27fcf59617SAndrey V. Elsukov #include <sys/cdefs.h>
28fcf59617SAndrey V. Elsukov #include "opt_inet.h"
2980044c78SXavier Beaudouin #include "opt_inet6.h"
30fcf59617SAndrey V. Elsukov #include "opt_ipsec.h"
31fcf59617SAndrey V. Elsukov
32fcf59617SAndrey V. Elsukov #include <sys/param.h>
33fcf59617SAndrey V. Elsukov #include <sys/systm.h>
34fcf59617SAndrey V. Elsukov #include <sys/kernel.h>
35fcf59617SAndrey V. Elsukov #include <sys/lock.h>
36fcf59617SAndrey V. Elsukov #include <sys/mbuf.h>
37fcf59617SAndrey V. Elsukov #include <sys/protosw.h>
38fcf59617SAndrey V. Elsukov #include <sys/socket.h>
39fcf59617SAndrey V. Elsukov #include <sys/sockopt.h>
40fcf59617SAndrey V. Elsukov #include <sys/sysctl.h>
41fcf59617SAndrey V. Elsukov
42fcf59617SAndrey V. Elsukov #include <netinet/in.h>
43fcf59617SAndrey V. Elsukov #include <netinet/in_pcb.h>
44fcf59617SAndrey V. Elsukov #include <netinet/in_systm.h>
45fcf59617SAndrey V. Elsukov #include <netinet/ip.h>
4680044c78SXavier Beaudouin #include <netinet/ip6.h>
47fcf59617SAndrey V. Elsukov #include <netinet/ip_var.h>
48fcf59617SAndrey V. Elsukov #include <netinet/tcp.h>
49fcf59617SAndrey V. Elsukov #include <netinet/udp.h>
50fcf59617SAndrey V. Elsukov #include <netinet/udp_var.h>
51fcf59617SAndrey V. Elsukov
5280044c78SXavier Beaudouin #include <netinet6/ip6_var.h>
5380044c78SXavier Beaudouin
54fcf59617SAndrey V. Elsukov #include <net/vnet.h>
55fcf59617SAndrey V. Elsukov
56fcf59617SAndrey V. Elsukov #include <netipsec/ipsec.h>
57fcf59617SAndrey V. Elsukov #include <netipsec/esp.h>
58fcf59617SAndrey V. Elsukov #include <netipsec/esp_var.h>
59fcf59617SAndrey V. Elsukov #include <netipsec/xform.h>
60fcf59617SAndrey V. Elsukov
61fcf59617SAndrey V. Elsukov #include <netipsec/key.h>
62fcf59617SAndrey V. Elsukov #include <netipsec/key_debug.h>
63fcf59617SAndrey V. Elsukov #include <netipsec/ipsec_support.h>
64fcf59617SAndrey V. Elsukov #include <machine/in_cksum.h>
65fcf59617SAndrey V. Elsukov
66fcf59617SAndrey V. Elsukov /*
67fcf59617SAndrey V. Elsukov * Handle UDP_ENCAP socket option. Always return with released INP_WLOCK.
68fcf59617SAndrey V. Elsukov */
69fcf59617SAndrey V. Elsukov int
udp_ipsec_pcbctl(struct inpcb * inp,struct sockopt * sopt)70fcf59617SAndrey V. Elsukov udp_ipsec_pcbctl(struct inpcb *inp, struct sockopt *sopt)
71fcf59617SAndrey V. Elsukov {
72fcf59617SAndrey V. Elsukov struct udpcb *up;
73fcf59617SAndrey V. Elsukov int error, optval;
74fcf59617SAndrey V. Elsukov
75fcf59617SAndrey V. Elsukov INP_WLOCK_ASSERT(inp);
76fcf59617SAndrey V. Elsukov if (sopt->sopt_name != UDP_ENCAP) {
77fcf59617SAndrey V. Elsukov INP_WUNLOCK(inp);
78fcf59617SAndrey V. Elsukov return (ENOPROTOOPT);
79fcf59617SAndrey V. Elsukov }
80fcf59617SAndrey V. Elsukov
81fcf59617SAndrey V. Elsukov up = intoudpcb(inp);
82fcf59617SAndrey V. Elsukov if (sopt->sopt_dir == SOPT_GET) {
83fcf59617SAndrey V. Elsukov if (up->u_flags & UF_ESPINUDP)
84fcf59617SAndrey V. Elsukov optval = UDP_ENCAP_ESPINUDP;
85fcf59617SAndrey V. Elsukov else
86fcf59617SAndrey V. Elsukov optval = 0;
87fcf59617SAndrey V. Elsukov INP_WUNLOCK(inp);
88fcf59617SAndrey V. Elsukov return (sooptcopyout(sopt, &optval, sizeof(optval)));
89fcf59617SAndrey V. Elsukov }
90fcf59617SAndrey V. Elsukov INP_WUNLOCK(inp);
91fcf59617SAndrey V. Elsukov
92fcf59617SAndrey V. Elsukov error = sooptcopyin(sopt, &optval, sizeof(optval), sizeof(optval));
93fcf59617SAndrey V. Elsukov if (error != 0)
94fcf59617SAndrey V. Elsukov return (error);
95fcf59617SAndrey V. Elsukov
96fcf59617SAndrey V. Elsukov INP_WLOCK(inp);
97fcf59617SAndrey V. Elsukov switch (optval) {
98fcf59617SAndrey V. Elsukov case 0:
99fcf59617SAndrey V. Elsukov up->u_flags &= ~UF_ESPINUDP;
100fcf59617SAndrey V. Elsukov break;
101fcf59617SAndrey V. Elsukov case UDP_ENCAP_ESPINUDP:
102fcf59617SAndrey V. Elsukov up->u_flags |= UF_ESPINUDP;
103fcf59617SAndrey V. Elsukov break;
104fcf59617SAndrey V. Elsukov default:
105fcf59617SAndrey V. Elsukov error = EINVAL;
106fcf59617SAndrey V. Elsukov }
107fcf59617SAndrey V. Elsukov INP_WUNLOCK(inp);
108fcf59617SAndrey V. Elsukov return (error);
109fcf59617SAndrey V. Elsukov }
110fcf59617SAndrey V. Elsukov
111fcf59617SAndrey V. Elsukov /*
112fcf59617SAndrey V. Elsukov * Potentially decap ESP in UDP frame. Check for an ESP header.
113fcf59617SAndrey V. Elsukov * If present, strip the UDP header and push the result through IPSec.
114fcf59617SAndrey V. Elsukov *
115fcf59617SAndrey V. Elsukov * Returns error if mbuf consumed and/or processed, otherwise 0.
116fcf59617SAndrey V. Elsukov */
117fcf59617SAndrey V. Elsukov int
udp_ipsec_input(struct mbuf * m,int off,int af)118fcf59617SAndrey V. Elsukov udp_ipsec_input(struct mbuf *m, int off, int af)
119fcf59617SAndrey V. Elsukov {
120fcf59617SAndrey V. Elsukov union sockaddr_union dst;
121fcf59617SAndrey V. Elsukov struct secasvar *sav;
122fcf59617SAndrey V. Elsukov struct udphdr *udp;
123fcf59617SAndrey V. Elsukov uint32_t spi;
1246f9e437bSAndrey V. Elsukov int hlen;
125fcf59617SAndrey V. Elsukov
126fcf59617SAndrey V. Elsukov /*
127fcf59617SAndrey V. Elsukov * Just return if packet doesn't have enough data.
128fcf59617SAndrey V. Elsukov * We need at least [IP header + UDP header + ESP header].
129fcf59617SAndrey V. Elsukov * NAT-Keepalive packet has only one byte of payload, so it
130fcf59617SAndrey V. Elsukov * by default will not be processed.
131fcf59617SAndrey V. Elsukov */
132fcf59617SAndrey V. Elsukov if (m->m_pkthdr.len < off + sizeof(struct esp))
133fcf59617SAndrey V. Elsukov return (0);
134fcf59617SAndrey V. Elsukov
135fcf59617SAndrey V. Elsukov m_copydata(m, off, sizeof(uint32_t), (caddr_t)&spi);
136fcf59617SAndrey V. Elsukov if (spi == 0) /* Non-ESP marker. */
137fcf59617SAndrey V. Elsukov return (0);
138fcf59617SAndrey V. Elsukov
139fcf59617SAndrey V. Elsukov /*
140fcf59617SAndrey V. Elsukov * Find SA and check that it is configured for UDP
141fcf59617SAndrey V. Elsukov * encapsulation.
142fcf59617SAndrey V. Elsukov */
143fcf59617SAndrey V. Elsukov bzero(&dst, sizeof(dst));
144fcf59617SAndrey V. Elsukov dst.sa.sa_family = af;
145fcf59617SAndrey V. Elsukov switch (af) {
146fcf59617SAndrey V. Elsukov #ifdef INET
14780044c78SXavier Beaudouin case AF_INET: {
14880044c78SXavier Beaudouin struct ip *ip;
14980044c78SXavier Beaudouin
150fcf59617SAndrey V. Elsukov dst.sin.sin_len = sizeof(struct sockaddr_in);
151fcf59617SAndrey V. Elsukov ip = mtod(m, struct ip *);
152fcf59617SAndrey V. Elsukov ip->ip_p = IPPROTO_ESP;
153fcf59617SAndrey V. Elsukov off = offsetof(struct ip, ip_p);
154fcf59617SAndrey V. Elsukov hlen = ip->ip_hl << 2;
155fcf59617SAndrey V. Elsukov dst.sin.sin_addr = ip->ip_dst;
156fcf59617SAndrey V. Elsukov break;
15780044c78SXavier Beaudouin }
158fcf59617SAndrey V. Elsukov #endif
159fcf59617SAndrey V. Elsukov #ifdef INET6
16080044c78SXavier Beaudouin case AF_INET6: {
16180044c78SXavier Beaudouin struct ip6_hdr *ip6;
16280044c78SXavier Beaudouin
16380044c78SXavier Beaudouin dst.sin6.sin6_len = sizeof(struct sockaddr_in6);
16480044c78SXavier Beaudouin ip6 = mtod(m, struct ip6_hdr *);
16580044c78SXavier Beaudouin ip6->ip6_nxt = IPPROTO_ESP;
16680044c78SXavier Beaudouin off = offsetof(struct ip6_hdr, ip6_nxt);
16780044c78SXavier Beaudouin hlen = sizeof(struct ip6_hdr);
16880044c78SXavier Beaudouin dst.sin6.sin6_addr = ip6->ip6_dst;
16980044c78SXavier Beaudouin break;
17080044c78SXavier Beaudouin }
171fcf59617SAndrey V. Elsukov #endif
172fcf59617SAndrey V. Elsukov default:
173fcf59617SAndrey V. Elsukov ESPSTAT_INC(esps_nopf);
174fcf59617SAndrey V. Elsukov m_freem(m);
175fcf59617SAndrey V. Elsukov return (EPFNOSUPPORT);
176fcf59617SAndrey V. Elsukov }
177fcf59617SAndrey V. Elsukov
178fcf59617SAndrey V. Elsukov sav = key_allocsa(&dst, IPPROTO_ESP, spi);
179fcf59617SAndrey V. Elsukov if (sav == NULL) {
180fcf59617SAndrey V. Elsukov ESPSTAT_INC(esps_notdb);
181fcf59617SAndrey V. Elsukov m_freem(m);
182fcf59617SAndrey V. Elsukov return (ENOENT);
183fcf59617SAndrey V. Elsukov }
184fcf59617SAndrey V. Elsukov udp = mtodo(m, hlen);
185fcf59617SAndrey V. Elsukov if (sav->natt == NULL ||
186fcf59617SAndrey V. Elsukov sav->natt->sport != udp->uh_sport ||
187fcf59617SAndrey V. Elsukov sav->natt->dport != udp->uh_dport) {
188fcf59617SAndrey V. Elsukov /* XXXAE: should we check source address? */
189fcf59617SAndrey V. Elsukov ESPSTAT_INC(esps_notdb);
190fcf59617SAndrey V. Elsukov key_freesav(&sav);
191fcf59617SAndrey V. Elsukov m_freem(m);
192fcf59617SAndrey V. Elsukov return (ENOENT);
193fcf59617SAndrey V. Elsukov }
194fcf59617SAndrey V. Elsukov /*
195fcf59617SAndrey V. Elsukov * Remove the UDP header
196fcf59617SAndrey V. Elsukov * Before:
197fcf59617SAndrey V. Elsukov * <--- off --->
198fcf59617SAndrey V. Elsukov * +----+------+-----+
199fcf59617SAndrey V. Elsukov * | IP | UDP | ESP |
200fcf59617SAndrey V. Elsukov * +----+------+-----+
201fcf59617SAndrey V. Elsukov * <-skip->
202fcf59617SAndrey V. Elsukov * After:
203fcf59617SAndrey V. Elsukov * +----+-----+
204fcf59617SAndrey V. Elsukov * | IP | ESP |
205fcf59617SAndrey V. Elsukov * +----+-----+
206fcf59617SAndrey V. Elsukov * <-skip->
207fcf59617SAndrey V. Elsukov */
208fcf59617SAndrey V. Elsukov m_striphdr(m, hlen, sizeof(*udp));
20980044c78SXavier Beaudouin
210fcf59617SAndrey V. Elsukov /*
211fcf59617SAndrey V. Elsukov * We cannot yet update the cksums so clear any h/w cksum flags
212fcf59617SAndrey V. Elsukov * as they are no longer valid.
213fcf59617SAndrey V. Elsukov */
21480044c78SXavier Beaudouin switch (af) {
21580044c78SXavier Beaudouin #ifdef INET
21680044c78SXavier Beaudouin case AF_INET:
217fcf59617SAndrey V. Elsukov if (m->m_pkthdr.csum_flags & CSUM_DATA_VALID)
218fcf59617SAndrey V. Elsukov m->m_pkthdr.csum_flags &= ~(CSUM_DATA_VALID | CSUM_PSEUDO_HDR);
21980044c78SXavier Beaudouin break;
22080044c78SXavier Beaudouin #endif /* INET */
22180044c78SXavier Beaudouin #ifdef INET6
22280044c78SXavier Beaudouin case AF_INET6:
22380044c78SXavier Beaudouin if (m->m_pkthdr.csum_flags & CSUM_DATA_VALID_IPV6)
22480044c78SXavier Beaudouin m->m_pkthdr.csum_flags &= ~(CSUM_DATA_VALID_IPV6 | CSUM_PSEUDO_HDR);
22580044c78SXavier Beaudouin break;
22680044c78SXavier Beaudouin #endif /* INET6 */
22780044c78SXavier Beaudouin default:
22880044c78SXavier Beaudouin ESPSTAT_INC(esps_nopf);
22980044c78SXavier Beaudouin m_freem(m);
23080044c78SXavier Beaudouin return (EPFNOSUPPORT);
23180044c78SXavier Beaudouin }
23280044c78SXavier Beaudouin
233fcf59617SAndrey V. Elsukov /*
234fcf59617SAndrey V. Elsukov * We can update ip_len and ip_sum here, but ipsec4_input_cb()
235fcf59617SAndrey V. Elsukov * will do this anyway, so don't touch them here.
236fcf59617SAndrey V. Elsukov */
237fcf59617SAndrey V. Elsukov ESPSTAT_INC(esps_input);
2386f9e437bSAndrey V. Elsukov (*sav->tdb_xform->xf_input)(m, sav, hlen, off);
239fcf59617SAndrey V. Elsukov return (EINPROGRESS); /* Consumed by IPsec. */
240fcf59617SAndrey V. Elsukov }
241fcf59617SAndrey V. Elsukov
242fcf59617SAndrey V. Elsukov int
udp_ipsec_output(struct mbuf * m,struct secasvar * sav)243fcf59617SAndrey V. Elsukov udp_ipsec_output(struct mbuf *m, struct secasvar *sav)
244fcf59617SAndrey V. Elsukov {
245fcf59617SAndrey V. Elsukov struct udphdr *udp;
246fcf59617SAndrey V. Elsukov struct mbuf *n;
247fcf59617SAndrey V. Elsukov int hlen, off;
248fcf59617SAndrey V. Elsukov
249fcf59617SAndrey V. Elsukov IPSEC_ASSERT(sav->natt != NULL, ("UDP encapsulation isn't required."));
250fcf59617SAndrey V. Elsukov
25180044c78SXavier Beaudouin switch (sav->sah->saidx.dst.sa.sa_family) {
25280044c78SXavier Beaudouin #ifdef INET
25380044c78SXavier Beaudouin case AF_INET: {
25480044c78SXavier Beaudouin struct ip *ip;
255fcf59617SAndrey V. Elsukov ip = mtod(m, struct ip *);
256fcf59617SAndrey V. Elsukov hlen = ip->ip_hl << 2;
25780044c78SXavier Beaudouin break;
25880044c78SXavier Beaudouin }
25980044c78SXavier Beaudouin #endif
26080044c78SXavier Beaudouin #ifdef INET6
26180044c78SXavier Beaudouin case AF_INET6:
26280044c78SXavier Beaudouin hlen = sizeof(struct ip6_hdr);
26380044c78SXavier Beaudouin break;
26480044c78SXavier Beaudouin #endif
26580044c78SXavier Beaudouin default:
26680044c78SXavier Beaudouin ESPSTAT_INC(esps_nopf);
26780044c78SXavier Beaudouin return (EAFNOSUPPORT);
26880044c78SXavier Beaudouin }
26980044c78SXavier Beaudouin
270fcf59617SAndrey V. Elsukov n = m_makespace(m, hlen, sizeof(*udp), &off);
271fcf59617SAndrey V. Elsukov if (n == NULL) {
272fcf59617SAndrey V. Elsukov DPRINTF(("%s: m_makespace for udphdr failed\n", __func__));
273fcf59617SAndrey V. Elsukov return (ENOBUFS);
274fcf59617SAndrey V. Elsukov }
275fcf59617SAndrey V. Elsukov
276fcf59617SAndrey V. Elsukov udp = mtodo(n, off);
277fcf59617SAndrey V. Elsukov udp->uh_dport = sav->natt->dport;
278fcf59617SAndrey V. Elsukov udp->uh_sport = sav->natt->sport;
279fcf59617SAndrey V. Elsukov udp->uh_sum = 0;
280fcf59617SAndrey V. Elsukov udp->uh_ulen = htons(m->m_pkthdr.len - hlen);
281fcf59617SAndrey V. Elsukov
28280044c78SXavier Beaudouin switch (sav->sah->saidx.dst.sa.sa_family) {
28380044c78SXavier Beaudouin #ifdef INET
28480044c78SXavier Beaudouin case AF_INET: {
28580044c78SXavier Beaudouin struct ip *ip;
28680044c78SXavier Beaudouin
287fcf59617SAndrey V. Elsukov ip = mtod(m, struct ip *);
288fcf59617SAndrey V. Elsukov ip->ip_len = htons(m->m_pkthdr.len);
289fcf59617SAndrey V. Elsukov ip->ip_p = IPPROTO_UDP;
29080044c78SXavier Beaudouin break;
29180044c78SXavier Beaudouin }
29280044c78SXavier Beaudouin #endif
29380044c78SXavier Beaudouin #ifdef INET6
29480044c78SXavier Beaudouin case AF_INET6: {
29580044c78SXavier Beaudouin struct ip6_hdr *ip6;
29680044c78SXavier Beaudouin
29780044c78SXavier Beaudouin ip6 = mtod(m, struct ip6_hdr *);
298*dc02374fSAllan Jude KASSERT(ip6->ip6_nxt == IPPROTO_ESP,
299*dc02374fSAllan Jude ("unexpected next header type %d", ip6->ip6_nxt));
30080044c78SXavier Beaudouin ip6->ip6_plen = htons(m->m_pkthdr.len);
30180044c78SXavier Beaudouin ip6->ip6_nxt = IPPROTO_UDP;
30280044c78SXavier Beaudouin udp->uh_sum = in6_cksum_pseudo(ip6,
30380044c78SXavier Beaudouin m->m_pkthdr.len - hlen, ip6->ip6_nxt, 0);
30480044c78SXavier Beaudouin m->m_pkthdr.csum_flags = CSUM_UDP_IPV6;
30580044c78SXavier Beaudouin m->m_pkthdr.csum_data = offsetof(struct udphdr, uh_sum);
30680044c78SXavier Beaudouin break;
30780044c78SXavier Beaudouin }
30880044c78SXavier Beaudouin #endif
30980044c78SXavier Beaudouin default:
31080044c78SXavier Beaudouin ESPSTAT_INC(esps_nopf);
31180044c78SXavier Beaudouin return (EAFNOSUPPORT);
31280044c78SXavier Beaudouin }
31380044c78SXavier Beaudouin
314fcf59617SAndrey V. Elsukov return (0);
315fcf59617SAndrey V. Elsukov }
316fcf59617SAndrey V. Elsukov
317fcf59617SAndrey V. Elsukov void
udp_ipsec_adjust_cksum(struct mbuf * m,struct secasvar * sav,int proto,int skip)318fcf59617SAndrey V. Elsukov udp_ipsec_adjust_cksum(struct mbuf *m, struct secasvar *sav, int proto,
319fcf59617SAndrey V. Elsukov int skip)
320fcf59617SAndrey V. Elsukov {
321fcf59617SAndrey V. Elsukov uint16_t cksum, off;
322fcf59617SAndrey V. Elsukov
323fcf59617SAndrey V. Elsukov IPSEC_ASSERT(sav->natt != NULL, ("NAT-T isn't required"));
324fcf59617SAndrey V. Elsukov IPSEC_ASSERT(proto == IPPROTO_UDP || proto == IPPROTO_TCP,
325fcf59617SAndrey V. Elsukov ("unexpected protocol %u", proto));
326fcf59617SAndrey V. Elsukov
327fcf59617SAndrey V. Elsukov if (proto == IPPROTO_UDP)
328fcf59617SAndrey V. Elsukov off = offsetof(struct udphdr, uh_sum);
329fcf59617SAndrey V. Elsukov else
330fcf59617SAndrey V. Elsukov off = offsetof(struct tcphdr, th_sum);
331fcf59617SAndrey V. Elsukov
332fcf59617SAndrey V. Elsukov if (V_natt_cksum_policy == 0) { /* auto */
333fcf59617SAndrey V. Elsukov if (sav->natt->cksum != 0) {
334fcf59617SAndrey V. Elsukov /* Incrementally recompute. */
335fcf59617SAndrey V. Elsukov m_copydata(m, skip + off, sizeof(cksum),
336fcf59617SAndrey V. Elsukov (caddr_t)&cksum);
337fbed6d60SAndrey V. Elsukov /* Do not adjust UDP checksum if it is zero. */
338fbed6d60SAndrey V. Elsukov if (proto == IPPROTO_UDP && cksum == 0)
339fbed6d60SAndrey V. Elsukov return;
340fcf59617SAndrey V. Elsukov cksum = in_addword(cksum, sav->natt->cksum);
341fcf59617SAndrey V. Elsukov } else {
342fcf59617SAndrey V. Elsukov /* No OA from IKEd. */
343fcf59617SAndrey V. Elsukov if (proto == IPPROTO_TCP) {
344fcf59617SAndrey V. Elsukov /* Ignore for TCP. */
345fcf59617SAndrey V. Elsukov m->m_pkthdr.csum_data = 0xffff;
34680044c78SXavier Beaudouin switch (sav->sah->saidx.dst.sa.sa_family) {
34780044c78SXavier Beaudouin #ifdef INET
34880044c78SXavier Beaudouin case AF_INET:
349fcf59617SAndrey V. Elsukov m->m_pkthdr.csum_flags |= (CSUM_DATA_VALID |
350fcf59617SAndrey V. Elsukov CSUM_PSEUDO_HDR);
35180044c78SXavier Beaudouin break;
35280044c78SXavier Beaudouin #endif
35380044c78SXavier Beaudouin #ifdef INET6
35480044c78SXavier Beaudouin case AF_INET6:
35580044c78SXavier Beaudouin m->m_pkthdr.csum_flags |= (CSUM_DATA_VALID_IPV6 |
35680044c78SXavier Beaudouin CSUM_PSEUDO_HDR);
35780044c78SXavier Beaudouin break;
35880044c78SXavier Beaudouin #endif
35980044c78SXavier Beaudouin default:
36080044c78SXavier Beaudouin break;
36180044c78SXavier Beaudouin }
362fcf59617SAndrey V. Elsukov return;
363fcf59617SAndrey V. Elsukov }
364fcf59617SAndrey V. Elsukov cksum = 0; /* Reset for UDP. */
365fcf59617SAndrey V. Elsukov }
366fcf59617SAndrey V. Elsukov m_copyback(m, skip + off, sizeof(cksum), (caddr_t)&cksum);
367fcf59617SAndrey V. Elsukov } else { /* Fully recompute */
36880044c78SXavier Beaudouin switch (sav->sah->saidx.dst.sa.sa_family) {
36980044c78SXavier Beaudouin #ifdef INET
37080044c78SXavier Beaudouin case AF_INET: {
37180044c78SXavier Beaudouin struct ip *ip;
37280044c78SXavier Beaudouin
373fcf59617SAndrey V. Elsukov ip = mtod(m, struct ip *);
374fcf59617SAndrey V. Elsukov cksum = in_pseudo(ip->ip_src.s_addr, ip->ip_dst.s_addr,
375fcf59617SAndrey V. Elsukov htons(m->m_pkthdr.len - skip + proto));
37680044c78SXavier Beaudouin m_copyback(m, skip + off, sizeof(cksum),
37780044c78SXavier Beaudouin (caddr_t)&cksum);
378fcf59617SAndrey V. Elsukov m->m_pkthdr.csum_flags =
379fcf59617SAndrey V. Elsukov (proto == IPPROTO_UDP) ? CSUM_UDP : CSUM_TCP;
380fcf59617SAndrey V. Elsukov m->m_pkthdr.csum_data = off;
381fcf59617SAndrey V. Elsukov in_delayed_cksum(m);
382fcf59617SAndrey V. Elsukov m->m_pkthdr.csum_flags &= ~CSUM_DELAY_DATA;
38380044c78SXavier Beaudouin break;
38480044c78SXavier Beaudouin }
38580044c78SXavier Beaudouin #endif
38680044c78SXavier Beaudouin #ifdef INET6
38780044c78SXavier Beaudouin case AF_INET6: {
38880044c78SXavier Beaudouin struct ip6_hdr *ip6;
38980044c78SXavier Beaudouin
39080044c78SXavier Beaudouin ip6 = mtod(m, struct ip6_hdr *);
39180044c78SXavier Beaudouin cksum = in6_cksum_pseudo(ip6, m->m_pkthdr.len - skip,
39280044c78SXavier Beaudouin proto, 0);
39380044c78SXavier Beaudouin m_copyback(m, skip + off, sizeof(cksum),
39480044c78SXavier Beaudouin (caddr_t)&cksum);
39580044c78SXavier Beaudouin m->m_pkthdr.csum_flags =
39680044c78SXavier Beaudouin (proto == IPPROTO_UDP) ? CSUM_UDP_IPV6 : CSUM_TCP_IPV6;
39780044c78SXavier Beaudouin m->m_pkthdr.csum_data = off;
39880044c78SXavier Beaudouin in6_delayed_cksum(m,
39980044c78SXavier Beaudouin m->m_pkthdr.len - sizeof(struct ip6_hdr),
40080044c78SXavier Beaudouin sizeof(struct ip6_hdr));
40180044c78SXavier Beaudouin m->m_pkthdr.csum_flags &= ~CSUM_DELAY_DATA_IPV6;
40280044c78SXavier Beaudouin break;
40380044c78SXavier Beaudouin }
40480044c78SXavier Beaudouin #endif
40580044c78SXavier Beaudouin default:
40680044c78SXavier Beaudouin break;
40780044c78SXavier Beaudouin }
408fcf59617SAndrey V. Elsukov }
409fcf59617SAndrey V. Elsukov }
410