xref: /linux/net/ipv4/ip_gre.c (revision cf85f810f911234a06a4ef2439e8694b93b717fc)
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  *	Linux NET3:	GRE over IP protocol decoder.
4  *
5  *	Authors: Alexey Kuznetsov (kuznet@ms2.inr.ac.ru)
6  */
7 
8 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
9 
10 #include <linux/capability.h>
11 #include <linux/module.h>
12 #include <linux/types.h>
13 #include <linux/kernel.h>
14 #include <linux/slab.h>
15 #include <linux/uaccess.h>
16 #include <linux/skbuff.h>
17 #include <linux/netdevice.h>
18 #include <linux/in.h>
19 #include <linux/tcp.h>
20 #include <linux/udp.h>
21 #include <linux/if_arp.h>
22 #include <linux/if_vlan.h>
23 #include <linux/init.h>
24 #include <linux/in6.h>
25 #include <linux/inetdevice.h>
26 #include <linux/igmp.h>
27 #include <linux/netfilter_ipv4.h>
28 #include <linux/etherdevice.h>
29 #include <linux/if_ether.h>
30 
31 #include <net/flow.h>
32 #include <net/sock.h>
33 #include <net/ip.h>
34 #include <net/icmp.h>
35 #include <net/protocol.h>
36 #include <net/ip_tunnels.h>
37 #include <net/arp.h>
38 #include <net/checksum.h>
39 #include <net/dsfield.h>
40 #include <net/inet_ecn.h>
41 #include <net/xfrm.h>
42 #include <net/net_namespace.h>
43 #include <net/netns/generic.h>
44 #include <net/rtnetlink.h>
45 #include <net/gre.h>
46 #include <net/dst_metadata.h>
47 #include <net/erspan.h>
48 
49 /*
50    Problems & solutions
51    --------------------
52 
53    1. The most important issue is detecting local dead loops.
54    They would cause complete host lockup in transmit, which
55    would be "resolved" by stack overflow or, if queueing is enabled,
56    with infinite looping in net_bh.
57 
58    We cannot track such dead loops during route installation,
59    it is infeasible task. The most general solutions would be
60    to keep skb->encapsulation counter (sort of local ttl),
61    and silently drop packet when it expires. It is a good
62    solution, but it supposes maintaining new variable in ALL
63    skb, even if no tunneling is used.
64 
65    Current solution: xmit_recursion breaks dead loops. This is a percpu
66    counter, since when we enter the first ndo_xmit(), cpu migration is
67    forbidden. We force an exit if this counter reaches RECURSION_LIMIT
68 
69    2. Networking dead loops would not kill routers, but would really
70    kill network. IP hop limit plays role of "t->recursion" in this case,
71    if we copy it from packet being encapsulated to upper header.
72    It is very good solution, but it introduces two problems:
73 
74    - Routing protocols, using packets with ttl=1 (OSPF, RIP2),
75      do not work over tunnels.
76    - traceroute does not work. I planned to relay ICMP from tunnel,
77      so that this problem would be solved and traceroute output
78      would even more informative. This idea appeared to be wrong:
79      only Linux complies to rfc1812 now (yes, guys, Linux is the only
80      true router now :-)), all routers (at least, in neighbourhood of mine)
81      return only 8 bytes of payload. It is the end.
82 
83    Hence, if we want that OSPF worked or traceroute said something reasonable,
84    we should search for another solution.
85 
86    One of them is to parse packet trying to detect inner encapsulation
87    made by our node. It is difficult or even impossible, especially,
88    taking into account fragmentation. TO be short, ttl is not solution at all.
89 
90    Current solution: The solution was UNEXPECTEDLY SIMPLE.
91    We force DF flag on tunnels with preconfigured hop limit,
92    that is ALL. :-) Well, it does not remove the problem completely,
93    but exponential growth of network traffic is changed to linear
94    (branches, that exceed pmtu are pruned) and tunnel mtu
95    rapidly degrades to value <68, where looping stops.
96    Yes, it is not good if there exists a router in the loop,
97    which does not force DF, even when encapsulating packets have DF set.
98    But it is not our problem! Nobody could accuse us, we made
99    all that we could make. Even if it is your gated who injected
100    fatal route to network, even if it were you who configured
101    fatal static route: you are innocent. :-)
102 
103    Alexey Kuznetsov.
104  */
105 
106 static bool log_ecn_error = true;
107 module_param(log_ecn_error, bool, 0644);
108 MODULE_PARM_DESC(log_ecn_error, "Log packets received with corrupted ECN");
109 
110 static struct rtnl_link_ops ipgre_link_ops __read_mostly;
111 static const struct header_ops ipgre_header_ops;
112 
113 static int ipgre_tunnel_init(struct net_device *dev);
114 static void erspan_build_header(struct sk_buff *skb,
115 				u32 id, u32 index,
116 				bool truncate, bool is_ipv4);
117 
118 static unsigned int ipgre_net_id __read_mostly;
119 static unsigned int gre_tap_net_id __read_mostly;
120 static unsigned int erspan_net_id __read_mostly;
121 
122 static int ipgre_err(struct sk_buff *skb, u32 info,
123 		     const struct tnl_ptk_info *tpi)
124 {
125 
126 	/* All the routers (except for Linux) return only
127 	   8 bytes of packet payload. It means, that precise relaying of
128 	   ICMP in the real Internet is absolutely infeasible.
129 
130 	   Moreover, Cisco "wise men" put GRE key to the third word
131 	   in GRE header. It makes impossible maintaining even soft
132 	   state for keyed GRE tunnels with enabled checksum. Tell
133 	   them "thank you".
134 
135 	   Well, I wonder, rfc1812 was written by Cisco employee,
136 	   what the hell these idiots break standards established
137 	   by themselves???
138 	   */
139 	struct net *net = dev_net(skb->dev);
140 	struct ip_tunnel_net *itn;
141 	const struct iphdr *iph;
142 	const int type = icmp_hdr(skb)->type;
143 	const int code = icmp_hdr(skb)->code;
144 	struct ip_tunnel *t;
145 
146 	if (tpi->proto == htons(ETH_P_TEB))
147 		itn = net_generic(net, gre_tap_net_id);
148 	else if (tpi->proto == htons(ETH_P_ERSPAN) ||
149 		 tpi->proto == htons(ETH_P_ERSPAN2))
150 		itn = net_generic(net, erspan_net_id);
151 	else
152 		itn = net_generic(net, ipgre_net_id);
153 
154 	iph = (const struct iphdr *)(icmp_hdr(skb) + 1);
155 	t = ip_tunnel_lookup(itn, skb->dev->ifindex, tpi->flags,
156 			     iph->daddr, iph->saddr, tpi->key);
157 
158 	if (!t)
159 		return -ENOENT;
160 
161 	switch (type) {
162 	default:
163 	case ICMP_PARAMETERPROB:
164 		return 0;
165 
166 	case ICMP_DEST_UNREACH:
167 		switch (code) {
168 		case ICMP_SR_FAILED:
169 		case ICMP_PORT_UNREACH:
170 			/* Impossible event. */
171 			return 0;
172 		default:
173 			/* All others are translated to HOST_UNREACH.
174 			   rfc2003 contains "deep thoughts" about NET_UNREACH,
175 			   I believe they are just ether pollution. --ANK
176 			 */
177 			break;
178 		}
179 		break;
180 
181 	case ICMP_TIME_EXCEEDED:
182 		if (code != ICMP_EXC_TTL)
183 			return 0;
184 		break;
185 
186 	case ICMP_REDIRECT:
187 		break;
188 	}
189 
190 #if IS_ENABLED(CONFIG_IPV6)
191 	if (tpi->proto == htons(ETH_P_IPV6)) {
192 		unsigned int data_len = 0;
193 
194 		if (type == ICMP_TIME_EXCEEDED)
195 			data_len = icmp_hdr(skb)->un.reserved[1] * 4; /* RFC 4884 4.1 */
196 
197 		if (!ip6_err_gen_icmpv6_unreach(skb, iph->ihl * 4 + tpi->hdr_len,
198 						type, data_len))
199 			return 0;
200 	}
201 #endif
202 
203 	if (t->parms.iph.daddr == 0 ||
204 	    ipv4_is_multicast(t->parms.iph.daddr))
205 		return 0;
206 
207 	if (t->parms.iph.ttl == 0 && type == ICMP_TIME_EXCEEDED)
208 		return 0;
209 
210 	if (time_before(jiffies, READ_ONCE(t->err_time) + IPTUNNEL_ERR_TIMEO))
211 		WRITE_ONCE(t->err_count, READ_ONCE(t->err_count) + 1);
212 	else
213 		WRITE_ONCE(t->err_count, 1);
214 	WRITE_ONCE(t->err_time, jiffies);
215 
216 	return 0;
217 }
218 
219 static void gre_err(struct sk_buff *skb, u32 info)
220 {
221 	/* All the routers (except for Linux) return only
222 	 * 8 bytes of packet payload. It means, that precise relaying of
223 	 * ICMP in the real Internet is absolutely infeasible.
224 	 *
225 	 * Moreover, Cisco "wise men" put GRE key to the third word
226 	 * in GRE header. It makes impossible maintaining even soft
227 	 * state for keyed
228 	 * GRE tunnels with enabled checksum. Tell them "thank you".
229 	 *
230 	 * Well, I wonder, rfc1812 was written by Cisco employee,
231 	 * what the hell these idiots break standards established
232 	 * by themselves???
233 	 */
234 
235 	const struct iphdr *iph = (struct iphdr *)skb->data;
236 	const int type = icmp_hdr(skb)->type;
237 	const int code = icmp_hdr(skb)->code;
238 	struct tnl_ptk_info tpi;
239 
240 	if (gre_parse_header(skb, &tpi, NULL, htons(ETH_P_IP),
241 			     iph->ihl * 4) < 0)
242 		return;
243 
244 	if (type == ICMP_DEST_UNREACH && code == ICMP_FRAG_NEEDED) {
245 		ipv4_update_pmtu(skb, dev_net(skb->dev), info,
246 				 skb->dev->ifindex, IPPROTO_GRE);
247 		return;
248 	}
249 	if (type == ICMP_REDIRECT) {
250 		ipv4_redirect(skb, dev_net(skb->dev), skb->dev->ifindex,
251 			      IPPROTO_GRE);
252 		return;
253 	}
254 
255 	ipgre_err(skb, info, &tpi);
256 }
257 
258 static bool is_erspan_type1(int gre_hdr_len)
259 {
260 	/* Both ERSPAN type I (version 0) and type II (version 1) use
261 	 * protocol 0x88BE, but the type I has only 4-byte GRE header,
262 	 * while type II has 8-byte.
263 	 */
264 	return gre_hdr_len == 4;
265 }
266 
267 static int erspan_rcv(struct sk_buff *skb, struct tnl_ptk_info *tpi,
268 		      int gre_hdr_len)
269 {
270 	struct net *net = dev_net(skb->dev);
271 	struct metadata_dst *tun_dst = NULL;
272 	struct erspan_base_hdr *ershdr;
273 	IP_TUNNEL_DECLARE_FLAGS(flags);
274 	struct ip_tunnel_net *itn;
275 	struct ip_tunnel *tunnel;
276 	const struct iphdr *iph;
277 	struct erspan_md2 *md2;
278 	int ver;
279 	int len;
280 
281 	ip_tunnel_flags_copy(flags, tpi->flags);
282 
283 	itn = net_generic(net, erspan_net_id);
284 	iph = ip_hdr(skb);
285 	if (is_erspan_type1(gre_hdr_len)) {
286 		ver = 0;
287 		__set_bit(IP_TUNNEL_NO_KEY_BIT, flags);
288 		tunnel = ip_tunnel_lookup(itn, skb->dev->ifindex, flags,
289 					  iph->saddr, iph->daddr, 0);
290 	} else {
291 		if (unlikely(!pskb_may_pull(skb,
292 					    gre_hdr_len + sizeof(*ershdr))))
293 			return PACKET_REJECT;
294 
295 		ershdr = (struct erspan_base_hdr *)(skb->data + gre_hdr_len);
296 		ver = ershdr->ver;
297 		iph = ip_hdr(skb);
298 		__set_bit(IP_TUNNEL_KEY_BIT, flags);
299 		tunnel = ip_tunnel_lookup(itn, skb->dev->ifindex, flags,
300 					  iph->saddr, iph->daddr, tpi->key);
301 	}
302 
303 	if (tunnel) {
304 		if (is_erspan_type1(gre_hdr_len))
305 			len = gre_hdr_len;
306 		else
307 			len = gre_hdr_len + erspan_hdr_len(ver);
308 
309 		if (unlikely(!pskb_may_pull(skb, len)))
310 			return PACKET_REJECT;
311 
312 		if (__iptunnel_pull_header(skb,
313 					   len,
314 					   htons(ETH_P_TEB),
315 					   false, false) < 0)
316 			goto drop;
317 
318 		if (tunnel->collect_md) {
319 			struct erspan_metadata *pkt_md, *md;
320 			struct ip_tunnel_info *info;
321 			unsigned char *gh;
322 			__be64 tun_id;
323 
324 			__set_bit(IP_TUNNEL_KEY_BIT, tpi->flags);
325 			ip_tunnel_flags_copy(flags, tpi->flags);
326 			tun_id = key32_to_tunnel_id(tpi->key);
327 
328 			tun_dst = ip_tun_rx_dst(skb, flags,
329 						tun_id, sizeof(*md));
330 			if (!tun_dst)
331 				return PACKET_REJECT;
332 
333 			/* MUST set options_len before referencing options */
334 			info = &tun_dst->u.tun_info;
335 			info->options_len = sizeof(*md);
336 
337 			/* skb can be uncloned in __iptunnel_pull_header, so
338 			 * old pkt_md is no longer valid and we need to reset
339 			 * it
340 			 */
341 			gh = skb_network_header(skb) +
342 			     skb_network_header_len(skb);
343 			pkt_md = (struct erspan_metadata *)(gh + gre_hdr_len +
344 							    sizeof(*ershdr));
345 			md = ip_tunnel_info_opts(&tun_dst->u.tun_info);
346 			md->version = ver;
347 			md2 = &md->u.md2;
348 			memcpy(md2, pkt_md, ver == 1 ? ERSPAN_V1_MDSIZE :
349 						       ERSPAN_V2_MDSIZE);
350 
351 			__set_bit(IP_TUNNEL_ERSPAN_OPT_BIT,
352 				  info->key.tun_flags);
353 		}
354 
355 		skb_reset_mac_header(skb);
356 		ip_tunnel_rcv(tunnel, skb, tpi, tun_dst, log_ecn_error);
357 		return PACKET_RCVD;
358 	}
359 	return PACKET_REJECT;
360 
361 drop:
362 	kfree_skb(skb);
363 	return PACKET_RCVD;
364 }
365 
366 static int __ipgre_rcv(struct sk_buff *skb, const struct tnl_ptk_info *tpi,
367 		       struct ip_tunnel_net *itn, int hdr_len, bool raw_proto)
368 {
369 	struct metadata_dst *tun_dst = NULL;
370 	const struct iphdr *iph;
371 	struct ip_tunnel *tunnel;
372 
373 	iph = ip_hdr(skb);
374 	tunnel = ip_tunnel_lookup(itn, skb->dev->ifindex, tpi->flags,
375 				  iph->saddr, iph->daddr, tpi->key);
376 
377 	if (tunnel) {
378 		const struct iphdr *tnl_params;
379 
380 		if (__iptunnel_pull_header(skb, hdr_len, tpi->proto,
381 					   raw_proto, false) < 0)
382 			goto drop;
383 
384 		/* Special case for ipgre_header_parse(), which expects the
385 		 * mac_header to point to the outer IP header.
386 		 */
387 		if (tunnel->dev->header_ops == &ipgre_header_ops)
388 			skb_pop_mac_header(skb);
389 		else
390 			skb_reset_mac_header(skb);
391 
392 		tnl_params = &tunnel->parms.iph;
393 		if (tunnel->collect_md || tnl_params->daddr == 0) {
394 			IP_TUNNEL_DECLARE_FLAGS(flags) = { };
395 			__be64 tun_id;
396 
397 			__set_bit(IP_TUNNEL_CSUM_BIT, flags);
398 			__set_bit(IP_TUNNEL_KEY_BIT, flags);
399 			ip_tunnel_flags_and(flags, tpi->flags, flags);
400 
401 			tun_id = key32_to_tunnel_id(tpi->key);
402 			tun_dst = ip_tun_rx_dst(skb, flags, tun_id, 0);
403 			if (!tun_dst)
404 				return PACKET_REJECT;
405 		}
406 
407 		ip_tunnel_rcv(tunnel, skb, tpi, tun_dst, log_ecn_error);
408 		return PACKET_RCVD;
409 	}
410 	return PACKET_NEXT;
411 
412 drop:
413 	kfree_skb(skb);
414 	return PACKET_RCVD;
415 }
416 
417 static int ipgre_rcv(struct sk_buff *skb, const struct tnl_ptk_info *tpi,
418 		     int hdr_len)
419 {
420 	struct net *net = dev_net(skb->dev);
421 	struct ip_tunnel_net *itn;
422 	int res;
423 
424 	if (tpi->proto == htons(ETH_P_TEB))
425 		itn = net_generic(net, gre_tap_net_id);
426 	else
427 		itn = net_generic(net, ipgre_net_id);
428 
429 	res = __ipgre_rcv(skb, tpi, itn, hdr_len, false);
430 	if (res == PACKET_NEXT && tpi->proto == htons(ETH_P_TEB)) {
431 		/* ipgre tunnels in collect metadata mode should receive
432 		 * also ETH_P_TEB traffic.
433 		 */
434 		itn = net_generic(net, ipgre_net_id);
435 		res = __ipgre_rcv(skb, tpi, itn, hdr_len, true);
436 	}
437 	return res;
438 }
439 
440 static int gre_rcv(struct sk_buff *skb)
441 {
442 	struct tnl_ptk_info tpi;
443 	bool csum_err = false;
444 	int hdr_len;
445 
446 #ifdef CONFIG_NET_IPGRE_BROADCAST
447 	if (ipv4_is_multicast(ip_hdr(skb)->daddr)) {
448 		/* Looped back packet, drop it! */
449 		if (rt_is_output_route(skb_rtable(skb)))
450 			goto drop;
451 	}
452 #endif
453 
454 	hdr_len = gre_parse_header(skb, &tpi, &csum_err, htons(ETH_P_IP), 0);
455 	if (hdr_len < 0)
456 		goto drop;
457 
458 	if (unlikely(tpi.proto == htons(ETH_P_ERSPAN) ||
459 		     tpi.proto == htons(ETH_P_ERSPAN2))) {
460 		if (erspan_rcv(skb, &tpi, hdr_len) == PACKET_RCVD)
461 			return 0;
462 		goto out;
463 	}
464 
465 	if (ipgre_rcv(skb, &tpi, hdr_len) == PACKET_RCVD)
466 		return 0;
467 
468 out:
469 	icmp_send(skb, ICMP_DEST_UNREACH, ICMP_PORT_UNREACH, 0);
470 drop:
471 	dev_core_stats_rx_dropped_inc(skb->dev);
472 	kfree_skb(skb);
473 	return 0;
474 }
475 
476 static void __gre_xmit(struct sk_buff *skb, struct net_device *dev,
477 		       const struct iphdr *tnl_params,
478 		       __be16 proto, const unsigned long *flags)
479 {
480 	struct ip_tunnel *tunnel = netdev_priv(dev);
481 
482 	/* Push GRE header. */
483 	gre_build_header(skb, tunnel->tun_hlen,
484 			 flags, proto, tunnel->parms.o_key,
485 			 test_bit(IP_TUNNEL_SEQ_BIT, flags) ?
486 			 htonl(atomic_fetch_inc(&tunnel->o_seqno)) : 0);
487 
488 	ip_tunnel_xmit(skb, dev, tnl_params, tnl_params->protocol);
489 }
490 
491 static int gre_handle_offloads(struct sk_buff *skb, bool csum)
492 {
493 	return iptunnel_handle_offloads(skb, csum ? SKB_GSO_GRE_CSUM : SKB_GSO_GRE);
494 }
495 
496 static void gre_fb_xmit(struct sk_buff *skb, struct net_device *dev,
497 			__be16 proto)
498 {
499 	struct ip_tunnel *tunnel = netdev_priv(dev);
500 	IP_TUNNEL_DECLARE_FLAGS(flags) = { };
501 	struct ip_tunnel_info *tun_info;
502 	const struct ip_tunnel_key *key;
503 	int tunnel_hlen;
504 
505 	tun_info = skb_tunnel_info(skb);
506 	if (unlikely(!tun_info || !(tun_info->mode & IP_TUNNEL_INFO_TX) ||
507 		     ip_tunnel_info_af(tun_info) != AF_INET))
508 		goto err_free_skb;
509 
510 	key = &tun_info->key;
511 	tunnel_hlen = gre_calc_hlen(key->tun_flags);
512 
513 	if (skb_cow_head(skb, dev->needed_headroom))
514 		goto err_free_skb;
515 
516 	/* Push Tunnel header. */
517 	if (gre_handle_offloads(skb, test_bit(IP_TUNNEL_CSUM_BIT,
518 					      tunnel->parms.o_flags)))
519 		goto err_free_skb;
520 
521 	__set_bit(IP_TUNNEL_CSUM_BIT, flags);
522 	__set_bit(IP_TUNNEL_KEY_BIT, flags);
523 	__set_bit(IP_TUNNEL_SEQ_BIT, flags);
524 	ip_tunnel_flags_and(flags, tun_info->key.tun_flags, flags);
525 
526 	gre_build_header(skb, tunnel_hlen, flags, proto,
527 			 tunnel_id_to_key32(tun_info->key.tun_id),
528 			 test_bit(IP_TUNNEL_SEQ_BIT, flags) ?
529 			 htonl(atomic_fetch_inc(&tunnel->o_seqno)) : 0);
530 
531 	ip_md_tunnel_xmit(skb, dev, IPPROTO_GRE, tunnel_hlen);
532 
533 	return;
534 
535 err_free_skb:
536 	kfree_skb(skb);
537 	DEV_STATS_INC(dev, tx_dropped);
538 }
539 
540 static void erspan_fb_xmit(struct sk_buff *skb, struct net_device *dev)
541 {
542 	struct ip_tunnel *tunnel = netdev_priv(dev);
543 	IP_TUNNEL_DECLARE_FLAGS(flags) = { };
544 	struct ip_tunnel_info *tun_info;
545 	const struct ip_tunnel_key *key;
546 	struct erspan_metadata *md;
547 	bool truncate = false;
548 	__be16 proto;
549 	int tunnel_hlen;
550 	int version;
551 	int nhoff;
552 
553 	tun_info = skb_tunnel_info(skb);
554 	if (unlikely(!tun_info || !(tun_info->mode & IP_TUNNEL_INFO_TX) ||
555 		     ip_tunnel_info_af(tun_info) != AF_INET))
556 		goto err_free_skb;
557 
558 	key = &tun_info->key;
559 	if (!test_bit(IP_TUNNEL_ERSPAN_OPT_BIT, tun_info->key.tun_flags))
560 		goto err_free_skb;
561 	if (tun_info->options_len < sizeof(*md))
562 		goto err_free_skb;
563 	md = ip_tunnel_info_opts(tun_info);
564 
565 	/* ERSPAN has fixed 8 byte GRE header */
566 	version = md->version;
567 	tunnel_hlen = 8 + erspan_hdr_len(version);
568 
569 	if (skb_cow_head(skb, dev->needed_headroom))
570 		goto err_free_skb;
571 
572 	if (gre_handle_offloads(skb, false))
573 		goto err_free_skb;
574 
575 	if (skb->len > dev->mtu + dev->hard_header_len) {
576 		if (pskb_trim(skb, dev->mtu + dev->hard_header_len))
577 			goto err_free_skb;
578 		truncate = true;
579 	}
580 
581 	nhoff = skb_network_offset(skb);
582 	if (skb->protocol == htons(ETH_P_IP) &&
583 	    (ntohs(ip_hdr(skb)->tot_len) > skb->len - nhoff))
584 		truncate = true;
585 
586 	if (skb->protocol == htons(ETH_P_IPV6)) {
587 		int thoff;
588 
589 		if (skb_transport_header_was_set(skb))
590 			thoff = skb_transport_offset(skb);
591 		else
592 			thoff = nhoff + sizeof(struct ipv6hdr);
593 		if (ntohs(ipv6_hdr(skb)->payload_len) > skb->len - thoff)
594 			truncate = true;
595 	}
596 
597 	if (version == 1) {
598 		erspan_build_header(skb, ntohl(tunnel_id_to_key32(key->tun_id)),
599 				    ntohl(md->u.index), truncate, true);
600 		proto = htons(ETH_P_ERSPAN);
601 	} else if (version == 2) {
602 		erspan_build_header_v2(skb,
603 				       ntohl(tunnel_id_to_key32(key->tun_id)),
604 				       md->u.md2.dir,
605 				       get_hwid(&md->u.md2),
606 				       truncate, true);
607 		proto = htons(ETH_P_ERSPAN2);
608 	} else {
609 		goto err_free_skb;
610 	}
611 
612 	__set_bit(IP_TUNNEL_SEQ_BIT, flags);
613 	gre_build_header(skb, 8, flags, proto, 0,
614 			 htonl(atomic_fetch_inc(&tunnel->o_seqno)));
615 
616 	ip_md_tunnel_xmit(skb, dev, IPPROTO_GRE, tunnel_hlen);
617 
618 	return;
619 
620 err_free_skb:
621 	kfree_skb(skb);
622 	DEV_STATS_INC(dev, tx_dropped);
623 }
624 
625 static int gre_fill_metadata_dst(struct net_device *dev, struct sk_buff *skb)
626 {
627 	struct ip_tunnel_info *info = skb_tunnel_info(skb);
628 	const struct ip_tunnel_key *key;
629 	struct rtable *rt;
630 	struct flowi4 fl4;
631 
632 	if (ip_tunnel_info_af(info) != AF_INET)
633 		return -EINVAL;
634 
635 	key = &info->key;
636 	ip_tunnel_init_flow(&fl4, IPPROTO_GRE, key->u.ipv4.dst, key->u.ipv4.src,
637 			    tunnel_id_to_key32(key->tun_id),
638 			    key->tos & ~INET_ECN_MASK, dev_net(dev), 0,
639 			    skb->mark, skb_get_hash(skb), key->flow_flags);
640 	rt = ip_route_output_key(dev_net(dev), &fl4);
641 	if (IS_ERR(rt))
642 		return PTR_ERR(rt);
643 
644 	ip_rt_put(rt);
645 	info->key.u.ipv4.src = fl4.saddr;
646 	return 0;
647 }
648 
649 static netdev_tx_t ipgre_xmit(struct sk_buff *skb,
650 			      struct net_device *dev)
651 {
652 	struct ip_tunnel *tunnel = netdev_priv(dev);
653 	IP_TUNNEL_DECLARE_FLAGS(flags);
654 	const struct iphdr *tnl_params;
655 
656 	if (!pskb_inet_may_pull(skb))
657 		goto free_skb;
658 
659 	if (tunnel->collect_md) {
660 		gre_fb_xmit(skb, dev, skb->protocol);
661 		return NETDEV_TX_OK;
662 	}
663 
664 	if (dev->header_ops) {
665 		int pull_len = tunnel->hlen + sizeof(struct iphdr);
666 
667 		if (skb_cow_head(skb, 0))
668 			goto free_skb;
669 
670 		if (!pskb_may_pull(skb, pull_len))
671 			goto free_skb;
672 
673 		tnl_params = (const struct iphdr *)skb->data;
674 
675 		/* ip_tunnel_xmit() needs skb->data pointing to gre header. */
676 		skb_pull(skb, pull_len);
677 		skb_reset_mac_header(skb);
678 
679 		if (skb->ip_summed == CHECKSUM_PARTIAL &&
680 		    skb_checksum_start(skb) < skb->data)
681 			goto free_skb;
682 	} else {
683 		if (skb_cow_head(skb, dev->needed_headroom))
684 			goto free_skb;
685 
686 		tnl_params = &tunnel->parms.iph;
687 	}
688 
689 	ip_tunnel_flags_copy(flags, tunnel->parms.o_flags);
690 
691 	if (gre_handle_offloads(skb, test_bit(IP_TUNNEL_CSUM_BIT, flags)))
692 		goto free_skb;
693 
694 	__gre_xmit(skb, dev, tnl_params, skb->protocol, flags);
695 	return NETDEV_TX_OK;
696 
697 free_skb:
698 	kfree_skb(skb);
699 	DEV_STATS_INC(dev, tx_dropped);
700 	return NETDEV_TX_OK;
701 }
702 
703 static netdev_tx_t erspan_xmit(struct sk_buff *skb,
704 			       struct net_device *dev)
705 {
706 	struct ip_tunnel *tunnel = netdev_priv(dev);
707 	IP_TUNNEL_DECLARE_FLAGS(flags);
708 	bool truncate = false;
709 	__be16 proto;
710 
711 	if (!pskb_inet_may_pull(skb))
712 		goto free_skb;
713 
714 	if (tunnel->collect_md) {
715 		erspan_fb_xmit(skb, dev);
716 		return NETDEV_TX_OK;
717 	}
718 
719 	if (gre_handle_offloads(skb, false))
720 		goto free_skb;
721 
722 	if (skb_cow_head(skb, dev->needed_headroom))
723 		goto free_skb;
724 
725 	if (skb->len > dev->mtu + dev->hard_header_len) {
726 		if (pskb_trim(skb, dev->mtu + dev->hard_header_len))
727 			goto free_skb;
728 		truncate = true;
729 	}
730 
731 	ip_tunnel_flags_copy(flags, tunnel->parms.o_flags);
732 
733 	/* Push ERSPAN header */
734 	if (tunnel->erspan_ver == 0) {
735 		proto = htons(ETH_P_ERSPAN);
736 		__clear_bit(IP_TUNNEL_SEQ_BIT, flags);
737 	} else if (tunnel->erspan_ver == 1) {
738 		erspan_build_header(skb, ntohl(tunnel->parms.o_key),
739 				    tunnel->index,
740 				    truncate, true);
741 		proto = htons(ETH_P_ERSPAN);
742 	} else if (tunnel->erspan_ver == 2) {
743 		erspan_build_header_v2(skb, ntohl(tunnel->parms.o_key),
744 				       tunnel->dir, tunnel->hwid,
745 				       truncate, true);
746 		proto = htons(ETH_P_ERSPAN2);
747 	} else {
748 		goto free_skb;
749 	}
750 
751 	__clear_bit(IP_TUNNEL_KEY_BIT, flags);
752 	__gre_xmit(skb, dev, &tunnel->parms.iph, proto, flags);
753 	return NETDEV_TX_OK;
754 
755 free_skb:
756 	kfree_skb(skb);
757 	DEV_STATS_INC(dev, tx_dropped);
758 	return NETDEV_TX_OK;
759 }
760 
761 static netdev_tx_t gre_tap_xmit(struct sk_buff *skb,
762 				struct net_device *dev)
763 {
764 	struct ip_tunnel *tunnel = netdev_priv(dev);
765 	IP_TUNNEL_DECLARE_FLAGS(flags);
766 
767 	if (!pskb_inet_may_pull(skb))
768 		goto free_skb;
769 
770 	if (tunnel->collect_md) {
771 		gre_fb_xmit(skb, dev, htons(ETH_P_TEB));
772 		return NETDEV_TX_OK;
773 	}
774 
775 	ip_tunnel_flags_copy(flags, tunnel->parms.o_flags);
776 
777 	if (gre_handle_offloads(skb, test_bit(IP_TUNNEL_CSUM_BIT, flags)))
778 		goto free_skb;
779 
780 	if (skb_cow_head(skb, dev->needed_headroom))
781 		goto free_skb;
782 
783 	__gre_xmit(skb, dev, &tunnel->parms.iph, htons(ETH_P_TEB), flags);
784 	return NETDEV_TX_OK;
785 
786 free_skb:
787 	kfree_skb(skb);
788 	DEV_STATS_INC(dev, tx_dropped);
789 	return NETDEV_TX_OK;
790 }
791 
792 static void ipgre_link_update(struct net_device *dev, bool set_mtu)
793 {
794 	struct ip_tunnel *tunnel = netdev_priv(dev);
795 	int len;
796 
797 	len = tunnel->tun_hlen;
798 	tunnel->tun_hlen = gre_calc_hlen(tunnel->parms.o_flags);
799 	len = tunnel->tun_hlen - len;
800 	tunnel->hlen = tunnel->hlen + len;
801 
802 	if (dev->header_ops)
803 		dev->hard_header_len += len;
804 	else
805 		dev->needed_headroom += len;
806 
807 	if (set_mtu)
808 		WRITE_ONCE(dev->mtu, max_t(int, dev->mtu - len, 68));
809 
810 	if (test_bit(IP_TUNNEL_SEQ_BIT, tunnel->parms.o_flags) ||
811 	    (test_bit(IP_TUNNEL_CSUM_BIT, tunnel->parms.o_flags) &&
812 	     tunnel->encap.type != TUNNEL_ENCAP_NONE)) {
813 		dev->features &= ~NETIF_F_GSO_SOFTWARE;
814 		dev->hw_features &= ~NETIF_F_GSO_SOFTWARE;
815 	} else {
816 		dev->features |= NETIF_F_GSO_SOFTWARE;
817 		dev->hw_features |= NETIF_F_GSO_SOFTWARE;
818 	}
819 }
820 
821 static int ipgre_tunnel_ctl(struct net_device *dev,
822 			    struct ip_tunnel_parm_kern *p,
823 			    int cmd)
824 {
825 	__be16 i_flags, o_flags;
826 	int err;
827 
828 	if (!ip_tunnel_flags_is_be16_compat(p->i_flags) ||
829 	    !ip_tunnel_flags_is_be16_compat(p->o_flags))
830 		return -EOVERFLOW;
831 
832 	i_flags = ip_tunnel_flags_to_be16(p->i_flags);
833 	o_flags = ip_tunnel_flags_to_be16(p->o_flags);
834 
835 	if (cmd == SIOCADDTUNNEL || cmd == SIOCCHGTUNNEL) {
836 		if (p->iph.version != 4 || p->iph.protocol != IPPROTO_GRE ||
837 		    p->iph.ihl != 5 || (p->iph.frag_off & htons(~IP_DF)) ||
838 		    ((i_flags | o_flags) & (GRE_VERSION | GRE_ROUTING)))
839 			return -EINVAL;
840 	}
841 
842 	gre_flags_to_tnl_flags(p->i_flags, i_flags);
843 	gre_flags_to_tnl_flags(p->o_flags, o_flags);
844 
845 	err = ip_tunnel_ctl(dev, p, cmd);
846 	if (err)
847 		return err;
848 
849 	if (cmd == SIOCCHGTUNNEL) {
850 		struct ip_tunnel *t = netdev_priv(dev);
851 
852 		ip_tunnel_flags_copy(t->parms.i_flags, p->i_flags);
853 		ip_tunnel_flags_copy(t->parms.o_flags, p->o_flags);
854 
855 		if (strcmp(dev->rtnl_link_ops->kind, "erspan"))
856 			ipgre_link_update(dev, true);
857 	}
858 
859 	i_flags = gre_tnl_flags_to_gre_flags(p->i_flags);
860 	ip_tunnel_flags_from_be16(p->i_flags, i_flags);
861 	o_flags = gre_tnl_flags_to_gre_flags(p->o_flags);
862 	ip_tunnel_flags_from_be16(p->o_flags, o_flags);
863 
864 	return 0;
865 }
866 
867 /* Nice toy. Unfortunately, useless in real life :-)
868    It allows to construct virtual multiprotocol broadcast "LAN"
869    over the Internet, provided multicast routing is tuned.
870 
871 
872    I have no idea was this bicycle invented before me,
873    so that I had to set ARPHRD_IPGRE to a random value.
874    I have an impression, that Cisco could make something similar,
875    but this feature is apparently missing in IOS<=11.2(8).
876 
877    I set up 10.66.66/24 and fec0:6666:6666::0/96 as virtual networks
878    with broadcast 224.66.66.66. If you have access to mbone, play with me :-)
879 
880    ping -t 255 224.66.66.66
881 
882    If nobody answers, mbone does not work.
883 
884    ip tunnel add Universe mode gre remote 224.66.66.66 local <Your_real_addr> ttl 255
885    ip addr add 10.66.66.<somewhat>/24 dev Universe
886    ifconfig Universe up
887    ifconfig Universe add fe80::<Your_real_addr>/10
888    ifconfig Universe add fec0:6666:6666::<Your_real_addr>/96
889    ftp 10.66.66.66
890    ...
891    ftp fec0:6666:6666::193.233.7.65
892    ...
893  */
894 static int ipgre_header(struct sk_buff *skb, struct net_device *dev,
895 			unsigned short type,
896 			const void *daddr, const void *saddr, unsigned int len)
897 {
898 	struct ip_tunnel *t = netdev_priv(dev);
899 	struct gre_base_hdr *greh;
900 	struct iphdr *iph;
901 	int needed;
902 
903 	needed = t->hlen + sizeof(*iph);
904 	if (skb_headroom(skb) < needed &&
905 	    pskb_expand_head(skb, HH_DATA_ALIGN(needed - skb_headroom(skb)),
906 			     0, GFP_ATOMIC))
907 		return -needed;
908 
909 	iph = skb_push(skb, needed);
910 	greh = (struct gre_base_hdr *)(iph+1);
911 	greh->flags = gre_tnl_flags_to_gre_flags(t->parms.o_flags);
912 	greh->protocol = htons(type);
913 
914 	memcpy(iph, &t->parms.iph, sizeof(struct iphdr));
915 
916 	/* Set the source hardware address. */
917 	if (saddr)
918 		memcpy(&iph->saddr, saddr, 4);
919 	if (daddr)
920 		memcpy(&iph->daddr, daddr, 4);
921 	if (iph->daddr)
922 		return t->hlen + sizeof(*iph);
923 
924 	return -(t->hlen + sizeof(*iph));
925 }
926 
927 static int ipgre_header_parse(const struct sk_buff *skb, const struct net_device *dev,
928 			      unsigned char *haddr)
929 {
930 	const struct iphdr *iph = (const struct iphdr *) skb_mac_header(skb);
931 	memcpy(haddr, &iph->saddr, 4);
932 	return 4;
933 }
934 
935 static const struct header_ops ipgre_header_ops = {
936 	.create	= ipgre_header,
937 	.parse	= ipgre_header_parse,
938 };
939 
940 #ifdef CONFIG_NET_IPGRE_BROADCAST
941 static int ipgre_open(struct net_device *dev)
942 {
943 	struct ip_tunnel *t = netdev_priv(dev);
944 
945 	if (ipv4_is_multicast(t->parms.iph.daddr)) {
946 		struct flowi4 fl4 = {
947 			.flowi4_oif = t->parms.link,
948 			.flowi4_dscp = ip4h_dscp(&t->parms.iph),
949 			.flowi4_scope = RT_SCOPE_UNIVERSE,
950 			.flowi4_proto = IPPROTO_GRE,
951 			.saddr = t->parms.iph.saddr,
952 			.daddr = t->parms.iph.daddr,
953 			.fl4_gre_key = t->parms.o_key,
954 		};
955 		struct rtable *rt;
956 
957 		rt = ip_route_output_key(t->net, &fl4);
958 		if (IS_ERR(rt))
959 			return -EADDRNOTAVAIL;
960 		dev = rt->dst.dev;
961 		ip_rt_put(rt);
962 		if (!__in_dev_get_rtnl(dev))
963 			return -EADDRNOTAVAIL;
964 		t->mlink = dev->ifindex;
965 		ip_mc_inc_group(__in_dev_get_rtnl(dev), t->parms.iph.daddr);
966 	}
967 	return 0;
968 }
969 
970 static int ipgre_close(struct net_device *dev)
971 {
972 	struct ip_tunnel *t = netdev_priv(dev);
973 
974 	if (ipv4_is_multicast(t->parms.iph.daddr) && t->mlink) {
975 		struct in_device *in_dev;
976 		in_dev = inetdev_by_index(t->net, t->mlink);
977 		if (in_dev)
978 			ip_mc_dec_group(in_dev, t->parms.iph.daddr);
979 	}
980 	return 0;
981 }
982 #endif
983 
984 static const struct net_device_ops ipgre_netdev_ops = {
985 	.ndo_init		= ipgre_tunnel_init,
986 	.ndo_uninit		= ip_tunnel_uninit,
987 #ifdef CONFIG_NET_IPGRE_BROADCAST
988 	.ndo_open		= ipgre_open,
989 	.ndo_stop		= ipgre_close,
990 #endif
991 	.ndo_start_xmit		= ipgre_xmit,
992 	.ndo_siocdevprivate	= ip_tunnel_siocdevprivate,
993 	.ndo_change_mtu		= ip_tunnel_change_mtu,
994 	.ndo_get_stats64	= dev_get_tstats64,
995 	.ndo_get_iflink		= ip_tunnel_get_iflink,
996 	.ndo_tunnel_ctl		= ipgre_tunnel_ctl,
997 };
998 
999 #define GRE_FEATURES (NETIF_F_SG |		\
1000 		      NETIF_F_FRAGLIST |	\
1001 		      NETIF_F_HIGHDMA |		\
1002 		      NETIF_F_HW_CSUM)
1003 
1004 static void ipgre_tunnel_setup(struct net_device *dev)
1005 {
1006 	dev->netdev_ops		= &ipgre_netdev_ops;
1007 	dev->type		= ARPHRD_IPGRE;
1008 	ip_tunnel_setup(dev, ipgre_net_id);
1009 }
1010 
1011 static void __gre_tunnel_init(struct net_device *dev)
1012 {
1013 	struct ip_tunnel *tunnel;
1014 
1015 	tunnel = netdev_priv(dev);
1016 	tunnel->tun_hlen = gre_calc_hlen(tunnel->parms.o_flags);
1017 	tunnel->parms.iph.protocol = IPPROTO_GRE;
1018 
1019 	tunnel->hlen = tunnel->tun_hlen + tunnel->encap_hlen;
1020 	dev->needed_headroom = tunnel->hlen + sizeof(tunnel->parms.iph);
1021 
1022 	dev->features		|= GRE_FEATURES;
1023 	dev->hw_features	|= GRE_FEATURES;
1024 
1025 	dev->lltx = true;
1026 
1027 	/* TCP offload with GRE SEQ is not supported, nor can we support 2
1028 	 * levels of outer headers requiring an update.
1029 	 */
1030 	if (test_bit(IP_TUNNEL_SEQ_BIT, tunnel->parms.o_flags))
1031 		return;
1032 	if (test_bit(IP_TUNNEL_CSUM_BIT, tunnel->parms.o_flags) &&
1033 	    tunnel->encap.type != TUNNEL_ENCAP_NONE)
1034 		return;
1035 
1036 	dev->features |= NETIF_F_GSO_SOFTWARE;
1037 	dev->hw_features |= NETIF_F_GSO_SOFTWARE;
1038 }
1039 
1040 static int ipgre_tunnel_init(struct net_device *dev)
1041 {
1042 	struct ip_tunnel *tunnel = netdev_priv(dev);
1043 	struct iphdr *iph = &tunnel->parms.iph;
1044 
1045 	__gre_tunnel_init(dev);
1046 
1047 	__dev_addr_set(dev, &iph->saddr, 4);
1048 	memcpy(dev->broadcast, &iph->daddr, 4);
1049 
1050 	dev->flags		= IFF_NOARP;
1051 	netif_keep_dst(dev);
1052 	dev->addr_len		= 4;
1053 
1054 	if (iph->daddr && !tunnel->collect_md) {
1055 #ifdef CONFIG_NET_IPGRE_BROADCAST
1056 		if (ipv4_is_multicast(iph->daddr)) {
1057 			if (!iph->saddr)
1058 				return -EINVAL;
1059 			dev->flags = IFF_BROADCAST;
1060 			dev->header_ops = &ipgre_header_ops;
1061 			dev->hard_header_len = tunnel->hlen + sizeof(*iph);
1062 			dev->needed_headroom = 0;
1063 		}
1064 #endif
1065 	} else if (!tunnel->collect_md) {
1066 		dev->header_ops = &ipgre_header_ops;
1067 		dev->hard_header_len = tunnel->hlen + sizeof(*iph);
1068 		dev->needed_headroom = 0;
1069 	}
1070 
1071 	return ip_tunnel_init(dev);
1072 }
1073 
1074 static const struct gre_protocol ipgre_protocol = {
1075 	.handler     = gre_rcv,
1076 	.err_handler = gre_err,
1077 };
1078 
1079 static int __net_init ipgre_init_net(struct net *net)
1080 {
1081 	return ip_tunnel_init_net(net, ipgre_net_id, &ipgre_link_ops, NULL);
1082 }
1083 
1084 static void __net_exit ipgre_exit_rtnl(struct net *net,
1085 				       struct list_head *dev_to_kill)
1086 {
1087 	ip_tunnel_delete_net(net, ipgre_net_id, &ipgre_link_ops, dev_to_kill);
1088 }
1089 
1090 static struct pernet_operations ipgre_net_ops = {
1091 	.init = ipgre_init_net,
1092 	.exit_rtnl = ipgre_exit_rtnl,
1093 	.id   = &ipgre_net_id,
1094 	.size = sizeof(struct ip_tunnel_net),
1095 };
1096 
1097 static int ipgre_tunnel_validate(struct nlattr *tb[], struct nlattr *data[],
1098 				 struct netlink_ext_ack *extack)
1099 {
1100 	__be16 flags;
1101 
1102 	if (!data)
1103 		return 0;
1104 
1105 	flags = 0;
1106 	if (data[IFLA_GRE_IFLAGS])
1107 		flags |= nla_get_be16(data[IFLA_GRE_IFLAGS]);
1108 	if (data[IFLA_GRE_OFLAGS])
1109 		flags |= nla_get_be16(data[IFLA_GRE_OFLAGS]);
1110 	if (flags & (GRE_VERSION|GRE_ROUTING))
1111 		return -EINVAL;
1112 
1113 	if (data[IFLA_GRE_COLLECT_METADATA] &&
1114 	    data[IFLA_GRE_ENCAP_TYPE] &&
1115 	    nla_get_u16(data[IFLA_GRE_ENCAP_TYPE]) != TUNNEL_ENCAP_NONE)
1116 		return -EINVAL;
1117 
1118 	return 0;
1119 }
1120 
1121 static int ipgre_tap_validate(struct nlattr *tb[], struct nlattr *data[],
1122 			      struct netlink_ext_ack *extack)
1123 {
1124 	__be32 daddr;
1125 
1126 	if (tb[IFLA_ADDRESS]) {
1127 		if (nla_len(tb[IFLA_ADDRESS]) != ETH_ALEN)
1128 			return -EINVAL;
1129 		if (!is_valid_ether_addr(nla_data(tb[IFLA_ADDRESS])))
1130 			return -EADDRNOTAVAIL;
1131 	}
1132 
1133 	if (!data)
1134 		goto out;
1135 
1136 	if (data[IFLA_GRE_REMOTE]) {
1137 		memcpy(&daddr, nla_data(data[IFLA_GRE_REMOTE]), 4);
1138 		if (!daddr)
1139 			return -EINVAL;
1140 	}
1141 
1142 out:
1143 	return ipgre_tunnel_validate(tb, data, extack);
1144 }
1145 
1146 static int erspan_validate(struct nlattr *tb[], struct nlattr *data[],
1147 			   struct netlink_ext_ack *extack)
1148 {
1149 	__be16 flags = 0;
1150 	int ret;
1151 
1152 	if (!data)
1153 		return 0;
1154 
1155 	ret = ipgre_tap_validate(tb, data, extack);
1156 	if (ret)
1157 		return ret;
1158 
1159 	if (data[IFLA_GRE_ERSPAN_VER] &&
1160 	    nla_get_u8(data[IFLA_GRE_ERSPAN_VER]) == 0)
1161 		return 0;
1162 
1163 	/* ERSPAN type II/III should only have GRE sequence and key flag */
1164 	if (data[IFLA_GRE_OFLAGS])
1165 		flags |= nla_get_be16(data[IFLA_GRE_OFLAGS]);
1166 	if (data[IFLA_GRE_IFLAGS])
1167 		flags |= nla_get_be16(data[IFLA_GRE_IFLAGS]);
1168 	if (!data[IFLA_GRE_COLLECT_METADATA] &&
1169 	    flags != (GRE_SEQ | GRE_KEY))
1170 		return -EINVAL;
1171 
1172 	/* ERSPAN Session ID only has 10-bit. Since we reuse
1173 	 * 32-bit key field as ID, check it's range.
1174 	 */
1175 	if (data[IFLA_GRE_IKEY] &&
1176 	    (ntohl(nla_get_be32(data[IFLA_GRE_IKEY])) & ~ID_MASK))
1177 		return -EINVAL;
1178 
1179 	if (data[IFLA_GRE_OKEY] &&
1180 	    (ntohl(nla_get_be32(data[IFLA_GRE_OKEY])) & ~ID_MASK))
1181 		return -EINVAL;
1182 
1183 	return 0;
1184 }
1185 
1186 static int ipgre_netlink_parms(struct net_device *dev,
1187 				struct nlattr *data[],
1188 				struct nlattr *tb[],
1189 				struct ip_tunnel_parm_kern *parms,
1190 				__u32 *fwmark)
1191 {
1192 	struct ip_tunnel *t = netdev_priv(dev);
1193 
1194 	memset(parms, 0, sizeof(*parms));
1195 
1196 	parms->iph.protocol = IPPROTO_GRE;
1197 
1198 	if (!data)
1199 		return 0;
1200 
1201 	if (data[IFLA_GRE_LINK])
1202 		parms->link = nla_get_u32(data[IFLA_GRE_LINK]);
1203 
1204 	if (data[IFLA_GRE_IFLAGS])
1205 		gre_flags_to_tnl_flags(parms->i_flags,
1206 				       nla_get_be16(data[IFLA_GRE_IFLAGS]));
1207 
1208 	if (data[IFLA_GRE_OFLAGS])
1209 		gre_flags_to_tnl_flags(parms->o_flags,
1210 				       nla_get_be16(data[IFLA_GRE_OFLAGS]));
1211 
1212 	if (data[IFLA_GRE_IKEY])
1213 		parms->i_key = nla_get_be32(data[IFLA_GRE_IKEY]);
1214 
1215 	if (data[IFLA_GRE_OKEY])
1216 		parms->o_key = nla_get_be32(data[IFLA_GRE_OKEY]);
1217 
1218 	if (data[IFLA_GRE_LOCAL])
1219 		parms->iph.saddr = nla_get_in_addr(data[IFLA_GRE_LOCAL]);
1220 
1221 	if (data[IFLA_GRE_REMOTE])
1222 		parms->iph.daddr = nla_get_in_addr(data[IFLA_GRE_REMOTE]);
1223 
1224 	if (data[IFLA_GRE_TTL])
1225 		parms->iph.ttl = nla_get_u8(data[IFLA_GRE_TTL]);
1226 
1227 	if (data[IFLA_GRE_TOS])
1228 		parms->iph.tos = nla_get_u8(data[IFLA_GRE_TOS]);
1229 
1230 	if (!data[IFLA_GRE_PMTUDISC] || nla_get_u8(data[IFLA_GRE_PMTUDISC])) {
1231 		if (t->ignore_df)
1232 			return -EINVAL;
1233 		parms->iph.frag_off = htons(IP_DF);
1234 	}
1235 
1236 	if (data[IFLA_GRE_COLLECT_METADATA]) {
1237 		t->collect_md = true;
1238 		if (dev->type == ARPHRD_IPGRE)
1239 			dev->type = ARPHRD_NONE;
1240 	}
1241 
1242 	if (data[IFLA_GRE_IGNORE_DF]) {
1243 		if (nla_get_u8(data[IFLA_GRE_IGNORE_DF])
1244 		  && (parms->iph.frag_off & htons(IP_DF)))
1245 			return -EINVAL;
1246 		t->ignore_df = !!nla_get_u8(data[IFLA_GRE_IGNORE_DF]);
1247 	}
1248 
1249 	if (data[IFLA_GRE_FWMARK])
1250 		*fwmark = nla_get_u32(data[IFLA_GRE_FWMARK]);
1251 
1252 	return 0;
1253 }
1254 
1255 static int erspan_netlink_parms(struct net_device *dev,
1256 				struct nlattr *data[],
1257 				struct nlattr *tb[],
1258 				struct ip_tunnel_parm_kern *parms,
1259 				__u32 *fwmark)
1260 {
1261 	struct ip_tunnel *t = netdev_priv(dev);
1262 	int err;
1263 
1264 	err = ipgre_netlink_parms(dev, data, tb, parms, fwmark);
1265 	if (err)
1266 		return err;
1267 	if (!data)
1268 		return 0;
1269 
1270 	if (data[IFLA_GRE_ERSPAN_VER]) {
1271 		t->erspan_ver = nla_get_u8(data[IFLA_GRE_ERSPAN_VER]);
1272 
1273 		if (t->erspan_ver > 2)
1274 			return -EINVAL;
1275 	}
1276 
1277 	if (t->erspan_ver == 1) {
1278 		if (data[IFLA_GRE_ERSPAN_INDEX]) {
1279 			t->index = nla_get_u32(data[IFLA_GRE_ERSPAN_INDEX]);
1280 			if (t->index & ~INDEX_MASK)
1281 				return -EINVAL;
1282 		}
1283 	} else if (t->erspan_ver == 2) {
1284 		if (data[IFLA_GRE_ERSPAN_DIR]) {
1285 			t->dir = nla_get_u8(data[IFLA_GRE_ERSPAN_DIR]);
1286 			if (t->dir & ~(DIR_MASK >> DIR_OFFSET))
1287 				return -EINVAL;
1288 		}
1289 		if (data[IFLA_GRE_ERSPAN_HWID]) {
1290 			t->hwid = nla_get_u16(data[IFLA_GRE_ERSPAN_HWID]);
1291 			if (t->hwid & ~(HWID_MASK >> HWID_OFFSET))
1292 				return -EINVAL;
1293 		}
1294 	}
1295 
1296 	return 0;
1297 }
1298 
1299 /* This function returns true when ENCAP attributes are present in the nl msg */
1300 static bool ipgre_netlink_encap_parms(struct nlattr *data[],
1301 				      struct ip_tunnel_encap *ipencap)
1302 {
1303 	bool ret = false;
1304 
1305 	memset(ipencap, 0, sizeof(*ipencap));
1306 
1307 	if (!data)
1308 		return ret;
1309 
1310 	if (data[IFLA_GRE_ENCAP_TYPE]) {
1311 		ret = true;
1312 		ipencap->type = nla_get_u16(data[IFLA_GRE_ENCAP_TYPE]);
1313 	}
1314 
1315 	if (data[IFLA_GRE_ENCAP_FLAGS]) {
1316 		ret = true;
1317 		ipencap->flags = nla_get_u16(data[IFLA_GRE_ENCAP_FLAGS]);
1318 	}
1319 
1320 	if (data[IFLA_GRE_ENCAP_SPORT]) {
1321 		ret = true;
1322 		ipencap->sport = nla_get_be16(data[IFLA_GRE_ENCAP_SPORT]);
1323 	}
1324 
1325 	if (data[IFLA_GRE_ENCAP_DPORT]) {
1326 		ret = true;
1327 		ipencap->dport = nla_get_be16(data[IFLA_GRE_ENCAP_DPORT]);
1328 	}
1329 
1330 	return ret;
1331 }
1332 
1333 static int gre_tap_init(struct net_device *dev)
1334 {
1335 	__gre_tunnel_init(dev);
1336 	dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
1337 	netif_keep_dst(dev);
1338 
1339 	return ip_tunnel_init(dev);
1340 }
1341 
1342 static const struct net_device_ops gre_tap_netdev_ops = {
1343 	.ndo_init		= gre_tap_init,
1344 	.ndo_uninit		= ip_tunnel_uninit,
1345 	.ndo_start_xmit		= gre_tap_xmit,
1346 	.ndo_set_mac_address 	= eth_mac_addr,
1347 	.ndo_validate_addr	= eth_validate_addr,
1348 	.ndo_change_mtu		= ip_tunnel_change_mtu,
1349 	.ndo_get_stats64	= dev_get_tstats64,
1350 	.ndo_get_iflink		= ip_tunnel_get_iflink,
1351 	.ndo_fill_metadata_dst	= gre_fill_metadata_dst,
1352 };
1353 
1354 static int erspan_tunnel_init(struct net_device *dev)
1355 {
1356 	struct ip_tunnel *tunnel = netdev_priv(dev);
1357 
1358 	if (tunnel->erspan_ver == 0)
1359 		tunnel->tun_hlen = 4; /* 4-byte GRE hdr. */
1360 	else
1361 		tunnel->tun_hlen = 8; /* 8-byte GRE hdr. */
1362 
1363 	tunnel->parms.iph.protocol = IPPROTO_GRE;
1364 	tunnel->hlen = tunnel->tun_hlen + tunnel->encap_hlen +
1365 		       erspan_hdr_len(tunnel->erspan_ver);
1366 
1367 	dev->features		|= GRE_FEATURES;
1368 	dev->hw_features	|= GRE_FEATURES;
1369 	dev->priv_flags		|= IFF_LIVE_ADDR_CHANGE;
1370 	netif_keep_dst(dev);
1371 
1372 	return ip_tunnel_init(dev);
1373 }
1374 
1375 static const struct net_device_ops erspan_netdev_ops = {
1376 	.ndo_init		= erspan_tunnel_init,
1377 	.ndo_uninit		= ip_tunnel_uninit,
1378 	.ndo_start_xmit		= erspan_xmit,
1379 	.ndo_set_mac_address	= eth_mac_addr,
1380 	.ndo_validate_addr	= eth_validate_addr,
1381 	.ndo_change_mtu		= ip_tunnel_change_mtu,
1382 	.ndo_get_stats64	= dev_get_tstats64,
1383 	.ndo_get_iflink		= ip_tunnel_get_iflink,
1384 	.ndo_fill_metadata_dst	= gre_fill_metadata_dst,
1385 };
1386 
1387 static void ipgre_tap_setup(struct net_device *dev)
1388 {
1389 	ether_setup(dev);
1390 	dev->max_mtu = 0;
1391 	dev->netdev_ops	= &gre_tap_netdev_ops;
1392 	dev->priv_flags &= ~IFF_TX_SKB_SHARING;
1393 	dev->priv_flags	|= IFF_LIVE_ADDR_CHANGE;
1394 	ip_tunnel_setup(dev, gre_tap_net_id);
1395 }
1396 
1397 static int
1398 ipgre_newlink_encap_setup(struct net_device *dev, struct nlattr *data[])
1399 {
1400 	struct ip_tunnel_encap ipencap;
1401 
1402 	if (ipgre_netlink_encap_parms(data, &ipencap)) {
1403 		struct ip_tunnel *t = netdev_priv(dev);
1404 		int err = ip_tunnel_encap_setup(t, &ipencap);
1405 
1406 		if (err < 0)
1407 			return err;
1408 	}
1409 
1410 	return 0;
1411 }
1412 
1413 static int ipgre_newlink(struct net_device *dev,
1414 			 struct rtnl_newlink_params *params,
1415 			 struct netlink_ext_ack *extack)
1416 {
1417 	struct nlattr **data = params->data;
1418 	struct nlattr **tb = params->tb;
1419 	struct ip_tunnel_parm_kern p;
1420 	__u32 fwmark = 0;
1421 	int err;
1422 
1423 	err = ipgre_newlink_encap_setup(dev, data);
1424 	if (err)
1425 		return err;
1426 
1427 	err = ipgre_netlink_parms(dev, data, tb, &p, &fwmark);
1428 	if (err < 0)
1429 		return err;
1430 	return ip_tunnel_newlink(params->link_net ? : dev_net(dev), dev, tb, &p,
1431 				 fwmark);
1432 }
1433 
1434 static int erspan_newlink(struct net_device *dev,
1435 			  struct rtnl_newlink_params *params,
1436 			  struct netlink_ext_ack *extack)
1437 {
1438 	struct nlattr **data = params->data;
1439 	struct nlattr **tb = params->tb;
1440 	struct ip_tunnel_parm_kern p;
1441 	__u32 fwmark = 0;
1442 	int err;
1443 
1444 	err = ipgre_newlink_encap_setup(dev, data);
1445 	if (err)
1446 		return err;
1447 
1448 	err = erspan_netlink_parms(dev, data, tb, &p, &fwmark);
1449 	if (err)
1450 		return err;
1451 	return ip_tunnel_newlink(params->link_net ? : dev_net(dev), dev, tb, &p,
1452 				 fwmark);
1453 }
1454 
1455 static int ipgre_changelink(struct net_device *dev, struct nlattr *tb[],
1456 			    struct nlattr *data[],
1457 			    struct netlink_ext_ack *extack)
1458 {
1459 	struct ip_tunnel *t = netdev_priv(dev);
1460 	struct ip_tunnel_parm_kern p;
1461 	__u32 fwmark = t->fwmark;
1462 	int err;
1463 
1464 	if (!rtnl_dev_link_net_capable(dev, t->net))
1465 		return -EPERM;
1466 
1467 	err = ipgre_newlink_encap_setup(dev, data);
1468 	if (err)
1469 		return err;
1470 
1471 	err = ipgre_netlink_parms(dev, data, tb, &p, &fwmark);
1472 	if (err < 0)
1473 		return err;
1474 
1475 	err = ip_tunnel_changelink(dev, tb, &p, fwmark);
1476 	if (err < 0)
1477 		return err;
1478 
1479 	ip_tunnel_flags_copy(t->parms.i_flags, p.i_flags);
1480 	ip_tunnel_flags_copy(t->parms.o_flags, p.o_flags);
1481 
1482 	ipgre_link_update(dev, !tb[IFLA_MTU]);
1483 
1484 	return 0;
1485 }
1486 
1487 static int erspan_changelink(struct net_device *dev, struct nlattr *tb[],
1488 			     struct nlattr *data[],
1489 			     struct netlink_ext_ack *extack)
1490 {
1491 	struct ip_tunnel *t = netdev_priv(dev);
1492 	struct ip_tunnel_parm_kern p;
1493 	__u32 fwmark = t->fwmark;
1494 	int err;
1495 
1496 	if (!rtnl_dev_link_net_capable(dev, t->net))
1497 		return -EPERM;
1498 
1499 	err = ipgre_newlink_encap_setup(dev, data);
1500 	if (err)
1501 		return err;
1502 
1503 	err = erspan_netlink_parms(dev, data, tb, &p, &fwmark);
1504 	if (err < 0)
1505 		return err;
1506 
1507 	err = ip_tunnel_changelink(dev, tb, &p, fwmark);
1508 	if (err < 0)
1509 		return err;
1510 
1511 	ip_tunnel_flags_copy(t->parms.i_flags, p.i_flags);
1512 	ip_tunnel_flags_copy(t->parms.o_flags, p.o_flags);
1513 
1514 	return 0;
1515 }
1516 
1517 static size_t ipgre_get_size(const struct net_device *dev)
1518 {
1519 	return
1520 		/* IFLA_GRE_LINK */
1521 		nla_total_size(4) +
1522 		/* IFLA_GRE_IFLAGS */
1523 		nla_total_size(2) +
1524 		/* IFLA_GRE_OFLAGS */
1525 		nla_total_size(2) +
1526 		/* IFLA_GRE_IKEY */
1527 		nla_total_size(4) +
1528 		/* IFLA_GRE_OKEY */
1529 		nla_total_size(4) +
1530 		/* IFLA_GRE_LOCAL */
1531 		nla_total_size(4) +
1532 		/* IFLA_GRE_REMOTE */
1533 		nla_total_size(4) +
1534 		/* IFLA_GRE_TTL */
1535 		nla_total_size(1) +
1536 		/* IFLA_GRE_TOS */
1537 		nla_total_size(1) +
1538 		/* IFLA_GRE_PMTUDISC */
1539 		nla_total_size(1) +
1540 		/* IFLA_GRE_ENCAP_TYPE */
1541 		nla_total_size(2) +
1542 		/* IFLA_GRE_ENCAP_FLAGS */
1543 		nla_total_size(2) +
1544 		/* IFLA_GRE_ENCAP_SPORT */
1545 		nla_total_size(2) +
1546 		/* IFLA_GRE_ENCAP_DPORT */
1547 		nla_total_size(2) +
1548 		/* IFLA_GRE_COLLECT_METADATA */
1549 		nla_total_size(0) +
1550 		/* IFLA_GRE_IGNORE_DF */
1551 		nla_total_size(1) +
1552 		/* IFLA_GRE_FWMARK */
1553 		nla_total_size(4) +
1554 		/* IFLA_GRE_ERSPAN_INDEX */
1555 		nla_total_size(4) +
1556 		/* IFLA_GRE_ERSPAN_VER */
1557 		nla_total_size(1) +
1558 		/* IFLA_GRE_ERSPAN_DIR */
1559 		nla_total_size(1) +
1560 		/* IFLA_GRE_ERSPAN_HWID */
1561 		nla_total_size(2) +
1562 		0;
1563 }
1564 
1565 static int ipgre_fill_info(struct sk_buff *skb, const struct net_device *dev)
1566 {
1567 	const struct ip_tunnel *t = netdev_priv(dev);
1568 	const struct ip_tunnel_parm_kern *p = &t->parms;
1569 	IP_TUNNEL_DECLARE_FLAGS(o_flags);
1570 
1571 	ip_tunnel_flags_copy(o_flags, p->o_flags);
1572 
1573 	if (t->erspan_ver != 0 && !t->collect_md)
1574 		__set_bit(IP_TUNNEL_KEY_BIT, o_flags);
1575 
1576 	if (nla_put_u32(skb, IFLA_GRE_LINK, p->link) ||
1577 	    nla_put_be16(skb, IFLA_GRE_IFLAGS,
1578 			 gre_tnl_flags_to_gre_flags(p->i_flags)) ||
1579 	    nla_put_be16(skb, IFLA_GRE_OFLAGS,
1580 			 gre_tnl_flags_to_gre_flags(o_flags)) ||
1581 	    nla_put_be32(skb, IFLA_GRE_IKEY, p->i_key) ||
1582 	    nla_put_be32(skb, IFLA_GRE_OKEY, p->o_key) ||
1583 	    nla_put_in_addr(skb, IFLA_GRE_LOCAL, p->iph.saddr) ||
1584 	    nla_put_in_addr(skb, IFLA_GRE_REMOTE, p->iph.daddr) ||
1585 	    nla_put_u8(skb, IFLA_GRE_TTL, p->iph.ttl) ||
1586 	    nla_put_u8(skb, IFLA_GRE_TOS, p->iph.tos) ||
1587 	    nla_put_u8(skb, IFLA_GRE_PMTUDISC,
1588 		       !!(p->iph.frag_off & htons(IP_DF))) ||
1589 	    nla_put_u32(skb, IFLA_GRE_FWMARK, t->fwmark))
1590 		goto nla_put_failure;
1591 
1592 	if (nla_put_u16(skb, IFLA_GRE_ENCAP_TYPE,
1593 			t->encap.type) ||
1594 	    nla_put_be16(skb, IFLA_GRE_ENCAP_SPORT,
1595 			 t->encap.sport) ||
1596 	    nla_put_be16(skb, IFLA_GRE_ENCAP_DPORT,
1597 			 t->encap.dport) ||
1598 	    nla_put_u16(skb, IFLA_GRE_ENCAP_FLAGS,
1599 			t->encap.flags))
1600 		goto nla_put_failure;
1601 
1602 	if (nla_put_u8(skb, IFLA_GRE_IGNORE_DF, t->ignore_df))
1603 		goto nla_put_failure;
1604 
1605 	if (t->collect_md) {
1606 		if (nla_put_flag(skb, IFLA_GRE_COLLECT_METADATA))
1607 			goto nla_put_failure;
1608 	}
1609 
1610 	return 0;
1611 
1612 nla_put_failure:
1613 	return -EMSGSIZE;
1614 }
1615 
1616 static int erspan_fill_info(struct sk_buff *skb, const struct net_device *dev)
1617 {
1618 	const struct ip_tunnel *t = netdev_priv(dev);
1619 
1620 	if (t->erspan_ver <= 2) {
1621 		if (nla_put_u8(skb, IFLA_GRE_ERSPAN_VER, t->erspan_ver))
1622 			goto nla_put_failure;
1623 
1624 		if (t->erspan_ver == 1) {
1625 			if (nla_put_u32(skb, IFLA_GRE_ERSPAN_INDEX, t->index))
1626 				goto nla_put_failure;
1627 		} else if (t->erspan_ver == 2) {
1628 			if (nla_put_u8(skb, IFLA_GRE_ERSPAN_DIR, t->dir))
1629 				goto nla_put_failure;
1630 			if (nla_put_u16(skb, IFLA_GRE_ERSPAN_HWID, t->hwid))
1631 				goto nla_put_failure;
1632 		}
1633 	}
1634 
1635 	return ipgre_fill_info(skb, dev);
1636 
1637 nla_put_failure:
1638 	return -EMSGSIZE;
1639 }
1640 
1641 static void erspan_setup(struct net_device *dev)
1642 {
1643 	struct ip_tunnel *t = netdev_priv(dev);
1644 
1645 	ether_setup(dev);
1646 	dev->max_mtu = 0;
1647 	dev->netdev_ops = &erspan_netdev_ops;
1648 	dev->priv_flags &= ~IFF_TX_SKB_SHARING;
1649 	dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
1650 	ip_tunnel_setup(dev, erspan_net_id);
1651 	t->erspan_ver = 1;
1652 }
1653 
1654 static const struct nla_policy ipgre_policy[IFLA_GRE_MAX + 1] = {
1655 	[IFLA_GRE_LINK]		= { .type = NLA_U32 },
1656 	[IFLA_GRE_IFLAGS]	= { .type = NLA_U16 },
1657 	[IFLA_GRE_OFLAGS]	= { .type = NLA_U16 },
1658 	[IFLA_GRE_IKEY]		= { .type = NLA_U32 },
1659 	[IFLA_GRE_OKEY]		= { .type = NLA_U32 },
1660 	[IFLA_GRE_LOCAL]	= { .len = sizeof_field(struct iphdr, saddr) },
1661 	[IFLA_GRE_REMOTE]	= { .len = sizeof_field(struct iphdr, daddr) },
1662 	[IFLA_GRE_TTL]		= { .type = NLA_U8 },
1663 	[IFLA_GRE_TOS]		= { .type = NLA_U8 },
1664 	[IFLA_GRE_PMTUDISC]	= { .type = NLA_U8 },
1665 	[IFLA_GRE_ENCAP_TYPE]	= { .type = NLA_U16 },
1666 	[IFLA_GRE_ENCAP_FLAGS]	= { .type = NLA_U16 },
1667 	[IFLA_GRE_ENCAP_SPORT]	= { .type = NLA_U16 },
1668 	[IFLA_GRE_ENCAP_DPORT]	= { .type = NLA_U16 },
1669 	[IFLA_GRE_COLLECT_METADATA]	= { .type = NLA_FLAG },
1670 	[IFLA_GRE_IGNORE_DF]	= { .type = NLA_U8 },
1671 	[IFLA_GRE_FWMARK]	= { .type = NLA_U32 },
1672 	[IFLA_GRE_ERSPAN_INDEX]	= { .type = NLA_U32 },
1673 	[IFLA_GRE_ERSPAN_VER]	= { .type = NLA_U8 },
1674 	[IFLA_GRE_ERSPAN_DIR]	= { .type = NLA_U8 },
1675 	[IFLA_GRE_ERSPAN_HWID]	= { .type = NLA_U16 },
1676 };
1677 
1678 static struct rtnl_link_ops ipgre_link_ops __read_mostly = {
1679 	.kind		= "gre",
1680 	.maxtype	= IFLA_GRE_MAX,
1681 	.policy		= ipgre_policy,
1682 	.priv_size	= sizeof(struct ip_tunnel),
1683 	.setup		= ipgre_tunnel_setup,
1684 	.validate	= ipgre_tunnel_validate,
1685 	.newlink	= ipgre_newlink,
1686 	.changelink	= ipgre_changelink,
1687 	.dellink	= ip_tunnel_dellink,
1688 	.get_size	= ipgre_get_size,
1689 	.fill_info	= ipgre_fill_info,
1690 	.get_link_net	= ip_tunnel_get_link_net,
1691 };
1692 
1693 static struct rtnl_link_ops ipgre_tap_ops __read_mostly = {
1694 	.kind		= "gretap",
1695 	.maxtype	= IFLA_GRE_MAX,
1696 	.policy		= ipgre_policy,
1697 	.priv_size	= sizeof(struct ip_tunnel),
1698 	.setup		= ipgre_tap_setup,
1699 	.validate	= ipgre_tap_validate,
1700 	.newlink	= ipgre_newlink,
1701 	.changelink	= ipgre_changelink,
1702 	.dellink	= ip_tunnel_dellink,
1703 	.get_size	= ipgre_get_size,
1704 	.fill_info	= ipgre_fill_info,
1705 	.get_link_net	= ip_tunnel_get_link_net,
1706 };
1707 
1708 static struct rtnl_link_ops erspan_link_ops __read_mostly = {
1709 	.kind		= "erspan",
1710 	.maxtype	= IFLA_GRE_MAX,
1711 	.policy		= ipgre_policy,
1712 	.priv_size	= sizeof(struct ip_tunnel),
1713 	.setup		= erspan_setup,
1714 	.validate	= erspan_validate,
1715 	.newlink	= erspan_newlink,
1716 	.changelink	= erspan_changelink,
1717 	.dellink	= ip_tunnel_dellink,
1718 	.get_size	= ipgre_get_size,
1719 	.fill_info	= erspan_fill_info,
1720 	.get_link_net	= ip_tunnel_get_link_net,
1721 };
1722 
1723 static int __net_init ipgre_tap_init_net(struct net *net)
1724 {
1725 	return ip_tunnel_init_net(net, gre_tap_net_id, &ipgre_tap_ops, "gretap0");
1726 }
1727 
1728 static void __net_exit ipgre_tap_exit_rtnl(struct net *net,
1729 					   struct list_head *dev_to_kill)
1730 {
1731 	ip_tunnel_delete_net(net, gre_tap_net_id, &ipgre_tap_ops, dev_to_kill);
1732 }
1733 
1734 static struct pernet_operations ipgre_tap_net_ops = {
1735 	.init = ipgre_tap_init_net,
1736 	.exit_rtnl = ipgre_tap_exit_rtnl,
1737 	.id   = &gre_tap_net_id,
1738 	.size = sizeof(struct ip_tunnel_net),
1739 };
1740 
1741 static int __net_init erspan_init_net(struct net *net)
1742 {
1743 	return ip_tunnel_init_net(net, erspan_net_id,
1744 				  &erspan_link_ops, "erspan0");
1745 }
1746 
1747 static void __net_exit erspan_exit_rtnl(struct net *net,
1748 					struct list_head *dev_to_kill)
1749 {
1750 	ip_tunnel_delete_net(net, erspan_net_id, &erspan_link_ops, dev_to_kill);
1751 }
1752 
1753 static struct pernet_operations erspan_net_ops = {
1754 	.init = erspan_init_net,
1755 	.exit_rtnl = erspan_exit_rtnl,
1756 	.id   = &erspan_net_id,
1757 	.size = sizeof(struct ip_tunnel_net),
1758 };
1759 
1760 static int __init ipgre_init(void)
1761 {
1762 	int err;
1763 
1764 	pr_info("GRE over IPv4 tunneling driver\n");
1765 
1766 	err = register_pernet_device(&ipgre_net_ops);
1767 	if (err < 0)
1768 		return err;
1769 
1770 	err = register_pernet_device(&ipgre_tap_net_ops);
1771 	if (err < 0)
1772 		goto pnet_tap_failed;
1773 
1774 	err = register_pernet_device(&erspan_net_ops);
1775 	if (err < 0)
1776 		goto pnet_erspan_failed;
1777 
1778 	err = gre_add_protocol(&ipgre_protocol, GREPROTO_CISCO);
1779 	if (err < 0) {
1780 		pr_info("%s: can't add protocol\n", __func__);
1781 		goto add_proto_failed;
1782 	}
1783 
1784 	err = rtnl_link_register(&ipgre_link_ops);
1785 	if (err < 0)
1786 		goto rtnl_link_failed;
1787 
1788 	err = rtnl_link_register(&ipgre_tap_ops);
1789 	if (err < 0)
1790 		goto tap_ops_failed;
1791 
1792 	err = rtnl_link_register(&erspan_link_ops);
1793 	if (err < 0)
1794 		goto erspan_link_failed;
1795 
1796 	return 0;
1797 
1798 erspan_link_failed:
1799 	rtnl_link_unregister(&ipgre_tap_ops);
1800 tap_ops_failed:
1801 	rtnl_link_unregister(&ipgre_link_ops);
1802 rtnl_link_failed:
1803 	gre_del_protocol(&ipgre_protocol, GREPROTO_CISCO);
1804 add_proto_failed:
1805 	unregister_pernet_device(&erspan_net_ops);
1806 pnet_erspan_failed:
1807 	unregister_pernet_device(&ipgre_tap_net_ops);
1808 pnet_tap_failed:
1809 	unregister_pernet_device(&ipgre_net_ops);
1810 	return err;
1811 }
1812 
1813 static void __exit ipgre_fini(void)
1814 {
1815 	rtnl_link_unregister(&ipgre_tap_ops);
1816 	rtnl_link_unregister(&ipgre_link_ops);
1817 	rtnl_link_unregister(&erspan_link_ops);
1818 	gre_del_protocol(&ipgre_protocol, GREPROTO_CISCO);
1819 	unregister_pernet_device(&ipgre_tap_net_ops);
1820 	unregister_pernet_device(&ipgre_net_ops);
1821 	unregister_pernet_device(&erspan_net_ops);
1822 }
1823 
1824 module_init(ipgre_init);
1825 module_exit(ipgre_fini);
1826 MODULE_DESCRIPTION("IPv4 GRE tunnels over IP library");
1827 MODULE_LICENSE("GPL");
1828 MODULE_ALIAS_RTNL_LINK("gre");
1829 MODULE_ALIAS_RTNL_LINK("gretap");
1830 MODULE_ALIAS_RTNL_LINK("erspan");
1831 MODULE_ALIAS_NETDEV("gre0");
1832 MODULE_ALIAS_NETDEV("gretap0");
1833 MODULE_ALIAS_NETDEV("erspan0");
1834