net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1 | /* $USAGI: $ */ |
| 2 | |
| 3 | /* |
| 4 | * Copyright (C)2004 USAGI/WIDE Project |
Stephen Hemminger | ae665a5 | 2006-12-05 10:10:22 -0800 | [diff] [blame] | 5 | * |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 6 | * This program is free software; you can redistribute it and/or modify |
| 7 | * it under the terms of the GNU General Public License as published by |
| 8 | * the Free Software Foundation; either version 2 of the License, or |
| 9 | * (at your option) any later version. |
Stephen Hemminger | ae665a5 | 2006-12-05 10:10:22 -0800 | [diff] [blame] | 10 | * |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 11 | * This program is distributed in the hope that it will be useful, |
| 12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
| 14 | * GNU General Public License for more details. |
Stephen Hemminger | ae665a5 | 2006-12-05 10:10:22 -0800 | [diff] [blame] | 15 | * |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 16 | * You should have received a copy of the GNU General Public License |
Stephen Hemminger | 4d98ab0 | 2013-12-06 15:05:07 -0800 | [diff] [blame] | 17 | * along with this program; if not, see <http://www.gnu.org/licenses>. |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 18 | */ |
| 19 | /* |
| 20 | * based on iproute.c |
| 21 | */ |
| 22 | /* |
| 23 | * Authors: |
| 24 | * Masahide NAKAMURA @USAGI |
| 25 | */ |
| 26 | |
| 27 | #include <stdio.h> |
| 28 | #include <stdlib.h> |
| 29 | #include <string.h> |
| 30 | #include <netdb.h> |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 31 | #include "utils.h" |
| 32 | #include "xfrm.h" |
| 33 | #include "ip_common.h" |
| 34 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 35 | /* #define NLMSG_DELETEALL_BUF_SIZE (4096-512) */ |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 36 | #define NLMSG_DELETEALL_BUF_SIZE 8192 |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 37 | |
| 38 | /* |
| 39 | * Receiving buffer defines: |
| 40 | * nlmsg |
| 41 | * data = struct xfrm_usersa_info |
| 42 | * rtattr |
| 43 | * rtattr |
12!tgraf | 2534613 | 2005-01-18 22:11:58 +0000 | [diff] [blame] | 44 | * ... (max count of rtattr is XFRM_MAX+1 |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 45 | * |
| 46 | * each rtattr data = struct xfrm_algo(dynamic size) or xfrm_address_t |
| 47 | */ |
| 48 | #define NLMSG_BUF_SIZE 4096 |
| 49 | #define RTA_BUF_SIZE 2048 |
| 50 | #define XFRM_ALGO_KEY_BUF_SIZE 512 |
Joy Latten | 0c7a594 | 2011-02-02 17:32:59 -0600 | [diff] [blame] | 51 | #define CTX_BUF_SIZE 256 |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 52 | |
| 53 | static void usage(void) __attribute__((noreturn)); |
| 54 | |
| 55 | static void usage(void) |
| 56 | { |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 57 | fprintf(stderr, "Usage: ip xfrm state { add | update } ID [ ALGO-LIST ] [ mode MODE ]\n"); |
| 58 | fprintf(stderr, " [ mark MARK [ mask MASK ] ] [ reqid REQID ] [ seq SEQ ]\n"); |
| 59 | fprintf(stderr, " [ replay-window SIZE ] [ replay-seq SEQ ] [ replay-oseq SEQ ]\n"); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 60 | fprintf(stderr, " [ replay-seq-hi SEQ ] [ replay-oseq-hi SEQ ]\n"); |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 61 | fprintf(stderr, " [ flag FLAG-LIST ] [ sel SELECTOR ] [ LIMIT-LIST ] [ encap ENCAP ]\n"); |
Nicolas Dichtel | dc8867d | 2013-05-17 01:36:38 -0700 | [diff] [blame] | 62 | fprintf(stderr, " [ coa ADDR[/PLEN] ] [ ctx CTX ] [ extra-flag EXTRA-FLAG-LIST ]\n"); |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 63 | fprintf(stderr, "Usage: ip xfrm state allocspi ID [ mode MODE ] [ mark MARK [ mask MASK ] ]\n"); |
| 64 | fprintf(stderr, " [ reqid REQID ] [ seq SEQ ] [ min SPI max SPI ]\n"); |
| 65 | fprintf(stderr, "Usage: ip xfrm state { delete | get } ID [ mark MARK [ mask MASK ] ]\n"); |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 66 | fprintf(stderr, "Usage: ip xfrm state { deleteall | list } [ ID ] [ mode MODE ] [ reqid REQID ]\n"); |
Masahide NAKAMURA | c1fa225 | 2007-08-24 11:05:18 +0900 | [diff] [blame] | 67 | fprintf(stderr, " [ flag FLAG-LIST ]\n"); |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 68 | fprintf(stderr, "Usage: ip xfrm state flush [ proto XFRM-PROTO ]\n"); |
| 69 | fprintf(stderr, "Usage: ip xfrm state count\n"); |
| 70 | fprintf(stderr, "ID := [ src ADDR ] [ dst ADDR ] [ proto XFRM-PROTO ] [ spi SPI ]\n"); |
| 71 | fprintf(stderr, "XFRM-PROTO := "); |
org[shemminger]!nakam | 29aa4dd | 2004-09-28 18:40:49 +0000 | [diff] [blame] | 72 | fprintf(stderr, "%s | ", strxf_xfrmproto(IPPROTO_ESP)); |
| 73 | fprintf(stderr, "%s | ", strxf_xfrmproto(IPPROTO_AH)); |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 74 | fprintf(stderr, "%s | ", strxf_xfrmproto(IPPROTO_COMP)); |
| 75 | fprintf(stderr, "%s | ", strxf_xfrmproto(IPPROTO_ROUTING)); |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 76 | fprintf(stderr, "%s\n", strxf_xfrmproto(IPPROTO_DSTOPTS)); |
| 77 | fprintf(stderr, "ALGO-LIST := [ ALGO-LIST ] ALGO\n"); |
| 78 | fprintf(stderr, "ALGO := { "); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 79 | fprintf(stderr, "%s | ", strxf_algotype(XFRMA_ALG_CRYPT)); |
David Ward | f3b9aa3 | 2013-03-25 04:23:17 +0000 | [diff] [blame] | 80 | fprintf(stderr, "%s", strxf_algotype(XFRMA_ALG_AUTH)); |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 81 | fprintf(stderr, " } ALGO-NAME ALGO-KEYMAT |\n"); |
David Ward | f3b9aa3 | 2013-03-25 04:23:17 +0000 | [diff] [blame] | 82 | fprintf(stderr, " %s", strxf_algotype(XFRMA_ALG_AUTH_TRUNC)); |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 83 | fprintf(stderr, " ALGO-NAME ALGO-KEYMAT ALGO-TRUNC-LEN |\n"); |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 84 | fprintf(stderr, " %s", strxf_algotype(XFRMA_ALG_AEAD)); |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 85 | fprintf(stderr, " ALGO-NAME ALGO-KEYMAT ALGO-ICV-LEN |\n"); |
David Ward | f3b9aa3 | 2013-03-25 04:23:17 +0000 | [diff] [blame] | 86 | fprintf(stderr, " %s", strxf_algotype(XFRMA_ALG_COMP)); |
| 87 | fprintf(stderr, " ALGO-NAME\n"); |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 88 | fprintf(stderr, "MODE := transport | tunnel | beet | ro | in_trigger\n"); |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 89 | fprintf(stderr, "FLAG-LIST := [ FLAG-LIST ] FLAG\n"); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 90 | fprintf(stderr, "FLAG := noecn | decap-dscp | nopmtudisc | wildrecv | icmp | af-unspec | align4 | esn\n"); |
Nicolas Dichtel | dc8867d | 2013-05-17 01:36:38 -0700 | [diff] [blame] | 91 | fprintf(stderr, "EXTRA-FLAG-LIST := [ EXTRA-FLAG-LIST ] EXTRA-FLAG\n"); |
| 92 | fprintf(stderr, "EXTRA-FLAG := dont-encap-dscp\n"); |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 93 | fprintf(stderr, "SELECTOR := [ src ADDR[/PLEN] ] [ dst ADDR[/PLEN] ] [ dev DEV ] [ UPSPEC ]\n"); |
| 94 | fprintf(stderr, "UPSPEC := proto { { "); |
| 95 | fprintf(stderr, "%s | ", strxf_proto(IPPROTO_TCP)); |
| 96 | fprintf(stderr, "%s | ", strxf_proto(IPPROTO_UDP)); |
| 97 | fprintf(stderr, "%s | ", strxf_proto(IPPROTO_SCTP)); |
| 98 | fprintf(stderr, "%s", strxf_proto(IPPROTO_DCCP)); |
| 99 | fprintf(stderr, " } [ sport PORT ] [ dport PORT ] |\n"); |
| 100 | fprintf(stderr, " { "); |
| 101 | fprintf(stderr, "%s | ", strxf_proto(IPPROTO_ICMP)); |
| 102 | fprintf(stderr, "%s | ", strxf_proto(IPPROTO_ICMPV6)); |
| 103 | fprintf(stderr, "%s", strxf_proto(IPPROTO_MH)); |
| 104 | fprintf(stderr, " } [ type NUMBER ] [ code NUMBER ] |\n"); |
| 105 | fprintf(stderr, " %s", strxf_proto(IPPROTO_GRE)); |
| 106 | fprintf(stderr, " [ key { DOTTED-QUAD | NUMBER } ] | PROTO }\n"); |
| 107 | fprintf(stderr, "LIMIT-LIST := [ LIMIT-LIST ] limit LIMIT\n"); |
| 108 | fprintf(stderr, "LIMIT := { time-soft | time-hard | time-use-soft | time-use-hard } SECONDS |\n"); |
| 109 | fprintf(stderr, " { byte-soft | byte-hard } SIZE | { packet-soft | packet-hard } COUNT\n"); |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 110 | fprintf(stderr, "ENCAP := { espinudp | espinudp-nonike } SPORT DPORT OADDR\n"); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 111 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 112 | exit(-1); |
| 113 | } |
| 114 | |
| 115 | static int xfrm_algo_parse(struct xfrm_algo *alg, enum xfrm_attr_type_t type, |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 116 | char *name, char *key, char *buf, int max) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 117 | { |
| 118 | int len; |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 119 | int slen = strlen(key); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 120 | |
net[shemminger]!shemminger | eaa34ee | 2005-01-17 23:29:39 +0000 | [diff] [blame] | 121 | #if 0 |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 122 | /* XXX: verifying both name and key is required! */ |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 123 | fprintf(stderr, "warning: ALGO-NAME/ALGO-KEYMAT values will be sent to the kernel promiscuously! (verifying them isn't implemented yet)\n"); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 124 | #endif |
| 125 | |
| 126 | strncpy(alg->alg_name, name, sizeof(alg->alg_name)); |
| 127 | |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 128 | if (slen > 2 && strncmp(key, "0x", 2) == 0) { |
org[shemminger]!nakam | 54f7328 | 2004-09-28 18:36:52 +0000 | [diff] [blame] | 129 | /* split two chars "0x" from the top */ |
| 130 | char *p = key + 2; |
| 131 | int plen = slen - 2; |
| 132 | int i; |
| 133 | int j; |
| 134 | |
| 135 | /* Converting hexadecimal numbered string into real key; |
| 136 | * Convert each two chars into one char(value). If number |
| 137 | * of the length is odd, add zero on the top for rounding. |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 138 | */ |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 139 | |
org[shemminger]!nakam | 54f7328 | 2004-09-28 18:36:52 +0000 | [diff] [blame] | 140 | /* calculate length of the converted values(real key) */ |
| 141 | len = (plen + 1) / 2; |
| 142 | if (len > max) |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 143 | invarg("ALGO-KEYMAT value makes buffer overflow\n", key); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 144 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 145 | for (i = -(plen % 2), j = 0; j < len; i += 2, j++) { |
org[shemminger]!nakam | 54f7328 | 2004-09-28 18:36:52 +0000 | [diff] [blame] | 146 | char vbuf[3]; |
shemminger | 737f15f | 2005-07-08 22:08:47 +0000 | [diff] [blame] | 147 | __u8 val; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 148 | |
org[shemminger]!nakam | 54f7328 | 2004-09-28 18:36:52 +0000 | [diff] [blame] | 149 | vbuf[0] = i >= 0 ? p[i] : '0'; |
| 150 | vbuf[1] = p[i + 1]; |
| 151 | vbuf[2] = '\0'; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 152 | |
org[shemminger]!nakam | 54f7328 | 2004-09-28 18:36:52 +0000 | [diff] [blame] | 153 | if (get_u8(&val, vbuf, 16)) |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 154 | invarg("ALGO-KEYMAT value is invalid", key); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 155 | |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 156 | buf[j] = val; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 157 | } |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 158 | } else { |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 159 | len = slen; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 160 | if (len > 0) { |
| 161 | if (len > max) |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 162 | invarg("ALGO-KEYMAT value makes buffer overflow\n", key); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 163 | |
Fan Du | 99500b5 | 2013-09-30 21:09:05 -0700 | [diff] [blame] | 164 | memcpy(buf, key, len); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 165 | } |
| 166 | } |
| 167 | |
| 168 | alg->alg_key_len = len * 8; |
| 169 | |
| 170 | return 0; |
| 171 | } |
| 172 | |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 173 | static int xfrm_seq_parse(__u32 *seq, int *argcp, char ***argvp) |
| 174 | { |
| 175 | int argc = *argcp; |
| 176 | char **argv = *argvp; |
| 177 | |
Sabrina Dubroca | 9f7401f | 2016-06-03 16:45:46 +0200 | [diff] [blame] | 178 | if (get_be32(seq, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 179 | invarg("SEQ value is invalid", *argv); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 180 | |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 181 | *argcp = argc; |
| 182 | *argvp = argv; |
| 183 | |
| 184 | return 0; |
| 185 | } |
| 186 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 187 | static int xfrm_state_flag_parse(__u8 *flags, int *argcp, char ***argvp) |
| 188 | { |
| 189 | int argc = *argcp; |
| 190 | char **argv = *argvp; |
net[shemminger]!shemminger | 9e566a4 | 2004-07-30 20:26:15 +0000 | [diff] [blame] | 191 | int len = strlen(*argv); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 192 | |
net[shemminger]!shemminger | 9e566a4 | 2004-07-30 20:26:15 +0000 | [diff] [blame] | 193 | if (len > 2 && strncmp(*argv, "0x", 2) == 0) { |
| 194 | __u8 val = 0; |
| 195 | |
| 196 | if (get_u8(&val, *argv, 16)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 197 | invarg("FLAG value is invalid", *argv); |
net[shemminger]!shemminger | 9e566a4 | 2004-07-30 20:26:15 +0000 | [diff] [blame] | 198 | *flags = val; |
| 199 | } else { |
net[shemminger]!shemminger | eaa34ee | 2005-01-17 23:29:39 +0000 | [diff] [blame] | 200 | while (1) { |
| 201 | if (strcmp(*argv, "noecn") == 0) |
| 202 | *flags |= XFRM_STATE_NOECN; |
| 203 | else if (strcmp(*argv, "decap-dscp") == 0) |
| 204 | *flags |= XFRM_STATE_DECAP_DSCP; |
Masahide NAKAMURA | c1fa225 | 2007-08-24 11:05:18 +0900 | [diff] [blame] | 205 | else if (strcmp(*argv, "nopmtudisc") == 0) |
| 206 | *flags |= XFRM_STATE_NOPMTUDISC; |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 207 | else if (strcmp(*argv, "wildrecv") == 0) |
| 208 | *flags |= XFRM_STATE_WILDRECV; |
Alex Badea | 15bb82c | 2010-01-11 17:23:41 +0200 | [diff] [blame] | 209 | else if (strcmp(*argv, "icmp") == 0) |
| 210 | *flags |= XFRM_STATE_ICMP; |
| 211 | else if (strcmp(*argv, "af-unspec") == 0) |
| 212 | *flags |= XFRM_STATE_AF_UNSPEC; |
Nicolas Dichtel | 98f5519 | 2011-02-01 07:29:54 -0500 | [diff] [blame] | 213 | else if (strcmp(*argv, "align4") == 0) |
| 214 | *flags |= XFRM_STATE_ALIGN4; |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 215 | else if (strcmp(*argv, "esn") == 0) |
| 216 | *flags |= XFRM_STATE_ESN; |
net[shemminger]!shemminger | eaa34ee | 2005-01-17 23:29:39 +0000 | [diff] [blame] | 217 | else { |
| 218 | PREV_ARG(); /* back track */ |
| 219 | break; |
| 220 | } |
| 221 | |
| 222 | if (!NEXT_ARG_OK()) |
| 223 | break; |
| 224 | NEXT_ARG(); |
| 225 | } |
net[shemminger]!shemminger | 9e566a4 | 2004-07-30 20:26:15 +0000 | [diff] [blame] | 226 | } |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 227 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 228 | *argcp = argc; |
| 229 | *argvp = argv; |
| 230 | |
| 231 | return 0; |
| 232 | } |
| 233 | |
Nicolas Dichtel | dc8867d | 2013-05-17 01:36:38 -0700 | [diff] [blame] | 234 | static int xfrm_state_extra_flag_parse(__u32 *extra_flags, int *argcp, char ***argvp) |
| 235 | { |
| 236 | int argc = *argcp; |
| 237 | char **argv = *argvp; |
| 238 | int len = strlen(*argv); |
| 239 | |
| 240 | if (len > 2 && strncmp(*argv, "0x", 2) == 0) { |
| 241 | __u32 val = 0; |
| 242 | |
| 243 | if (get_u32(&val, *argv, 16)) |
| 244 | invarg("\"EXTRA-FLAG\" is invalid", *argv); |
| 245 | *extra_flags = val; |
| 246 | } else { |
| 247 | while (1) { |
| 248 | if (strcmp(*argv, "dont-encap-dscp") == 0) |
| 249 | *extra_flags |= XFRM_SA_XFLAG_DONT_ENCAP_DSCP; |
| 250 | else { |
| 251 | PREV_ARG(); /* back track */ |
| 252 | break; |
| 253 | } |
| 254 | |
| 255 | if (!NEXT_ARG_OK()) |
| 256 | break; |
| 257 | NEXT_ARG(); |
| 258 | } |
| 259 | } |
| 260 | |
| 261 | *argcp = argc; |
| 262 | *argvp = argv; |
| 263 | |
| 264 | return 0; |
| 265 | } |
| 266 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 267 | static int xfrm_state_modify(int cmd, unsigned int flags, int argc, char **argv) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 268 | { |
| 269 | struct rtnl_handle rth; |
| 270 | struct { |
Stephen Hemminger | 4806867 | 2014-02-17 10:56:31 -0800 | [diff] [blame] | 271 | struct nlmsghdr n; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 272 | struct xfrm_usersa_info xsinfo; |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 273 | char buf[RTA_BUF_SIZE]; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 274 | } req; |
Herbert Xu | de95ae7 | 2008-04-23 15:42:32 +0800 | [diff] [blame] | 275 | struct xfrm_replay_state replay; |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 276 | struct xfrm_replay_state_esn replay_esn; |
| 277 | __u32 replay_window = 0; |
| 278 | __u32 seq = 0, oseq = 0, seq_hi = 0, oseq_hi = 0; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 279 | char *idp = NULL; |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 280 | char *aeadop = NULL; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 281 | char *ealgop = NULL; |
| 282 | char *aalgop = NULL; |
| 283 | char *calgop = NULL; |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 284 | char *coap = NULL; |
Joy Latten | 0c7a594 | 2011-02-02 17:32:59 -0600 | [diff] [blame] | 285 | char *sctxp = NULL; |
Nicolas Dichtel | dc8867d | 2013-05-17 01:36:38 -0700 | [diff] [blame] | 286 | __u32 extra_flags = 0; |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 287 | struct xfrm_mark mark = {0, 0}; |
Joy Latten | 0c7a594 | 2011-02-02 17:32:59 -0600 | [diff] [blame] | 288 | struct { |
| 289 | struct xfrm_user_sec_ctx sctx; |
| 290 | char str[CTX_BUF_SIZE]; |
| 291 | } ctx; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 292 | |
| 293 | memset(&req, 0, sizeof(req)); |
Herbert Xu | de95ae7 | 2008-04-23 15:42:32 +0800 | [diff] [blame] | 294 | memset(&replay, 0, sizeof(replay)); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 295 | memset(&replay_esn, 0, sizeof(replay_esn)); |
Joy Latten | 0c7a594 | 2011-02-02 17:32:59 -0600 | [diff] [blame] | 296 | memset(&ctx, 0, sizeof(ctx)); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 297 | |
| 298 | req.n.nlmsg_len = NLMSG_LENGTH(sizeof(req.xsinfo)); |
| 299 | req.n.nlmsg_flags = NLM_F_REQUEST|flags; |
| 300 | req.n.nlmsg_type = cmd; |
| 301 | req.xsinfo.family = preferred_family; |
| 302 | |
| 303 | req.xsinfo.lft.soft_byte_limit = XFRM_INF; |
| 304 | req.xsinfo.lft.hard_byte_limit = XFRM_INF; |
| 305 | req.xsinfo.lft.soft_packet_limit = XFRM_INF; |
| 306 | req.xsinfo.lft.hard_packet_limit = XFRM_INF; |
| 307 | |
| 308 | while (argc > 0) { |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 309 | if (strcmp(*argv, "mode") == 0) { |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 310 | NEXT_ARG(); |
| 311 | xfrm_mode_parse(&req.xsinfo.mode, &argc, &argv); |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 312 | } else if (strcmp(*argv, "mark") == 0) { |
| 313 | xfrm_parse_mark(&mark, &argc, &argv); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 314 | } else if (strcmp(*argv, "reqid") == 0) { |
| 315 | NEXT_ARG(); |
| 316 | xfrm_reqid_parse(&req.xsinfo.reqid, &argc, &argv); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 317 | } else if (strcmp(*argv, "seq") == 0) { |
| 318 | NEXT_ARG(); |
| 319 | xfrm_seq_parse(&req.xsinfo.seq, &argc, &argv); |
net[shemminger]!shemminger | eaa34ee | 2005-01-17 23:29:39 +0000 | [diff] [blame] | 320 | } else if (strcmp(*argv, "replay-window") == 0) { |
| 321 | NEXT_ARG(); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 322 | if (get_u32(&replay_window, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 323 | invarg("value after \"replay-window\" is invalid", *argv); |
Herbert Xu | de95ae7 | 2008-04-23 15:42:32 +0800 | [diff] [blame] | 324 | } else if (strcmp(*argv, "replay-seq") == 0) { |
| 325 | NEXT_ARG(); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 326 | if (get_u32(&seq, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 327 | invarg("value after \"replay-seq\" is invalid", *argv); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 328 | } else if (strcmp(*argv, "replay-seq-hi") == 0) { |
| 329 | NEXT_ARG(); |
| 330 | if (get_u32(&seq_hi, *argv, 0)) |
| 331 | invarg("value after \"replay-seq-hi\" is invalid", *argv); |
Herbert Xu | de95ae7 | 2008-04-23 15:42:32 +0800 | [diff] [blame] | 332 | } else if (strcmp(*argv, "replay-oseq") == 0) { |
| 333 | NEXT_ARG(); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 334 | if (get_u32(&oseq, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 335 | invarg("value after \"replay-oseq\" is invalid", *argv); |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 336 | } else if (strcmp(*argv, "replay-oseq-hi") == 0) { |
| 337 | NEXT_ARG(); |
| 338 | if (get_u32(&oseq_hi, *argv, 0)) |
| 339 | invarg("value after \"replay-oseq-hi\" is invalid", *argv); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 340 | } else if (strcmp(*argv, "flag") == 0) { |
| 341 | NEXT_ARG(); |
| 342 | xfrm_state_flag_parse(&req.xsinfo.flags, &argc, &argv); |
Nicolas Dichtel | dc8867d | 2013-05-17 01:36:38 -0700 | [diff] [blame] | 343 | } else if (strcmp(*argv, "extra-flag") == 0) { |
| 344 | NEXT_ARG(); |
| 345 | xfrm_state_extra_flag_parse(&extra_flags, &argc, &argv); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 346 | } else if (strcmp(*argv, "sel") == 0) { |
| 347 | NEXT_ARG(); |
Thomas Egerer | 23d5b0d | 2013-03-17 00:56:01 +0000 | [diff] [blame] | 348 | preferred_family = AF_UNSPEC; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 349 | xfrm_selector_parse(&req.xsinfo.sel, &argc, &argv); |
Thomas Egerer | 0c5982f | 2013-03-20 02:18:43 -0700 | [diff] [blame] | 350 | preferred_family = req.xsinfo.sel.family; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 351 | } else if (strcmp(*argv, "limit") == 0) { |
| 352 | NEXT_ARG(); |
| 353 | xfrm_lifetime_cfg_parse(&req.xsinfo.lft, &argc, &argv); |
osdl.net!shemminger | 5cf576d | 2005-03-10 19:04:00 +0000 | [diff] [blame] | 354 | } else if (strcmp(*argv, "encap") == 0) { |
| 355 | struct xfrm_encap_tmpl encap; |
| 356 | inet_prefix oa; |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 357 | NEXT_ARG(); |
osdl.net!shemminger | 5cf576d | 2005-03-10 19:04:00 +0000 | [diff] [blame] | 358 | xfrm_encap_type_parse(&encap.encap_type, &argc, &argv); |
| 359 | NEXT_ARG(); |
Sabrina Dubroca | 9f7401f | 2016-06-03 16:45:46 +0200 | [diff] [blame] | 360 | if (get_be16(&encap.encap_sport, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 361 | invarg("SPORT value after \"encap\" is invalid", *argv); |
osdl.net!shemminger | 5cf576d | 2005-03-10 19:04:00 +0000 | [diff] [blame] | 362 | NEXT_ARG(); |
Sabrina Dubroca | 9f7401f | 2016-06-03 16:45:46 +0200 | [diff] [blame] | 363 | if (get_be16(&encap.encap_dport, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 364 | invarg("DPORT value after \"encap\" is invalid", *argv); |
osdl.net!shemminger | 5cf576d | 2005-03-10 19:04:00 +0000 | [diff] [blame] | 365 | NEXT_ARG(); |
| 366 | get_addr(&oa, *argv, AF_UNSPEC); |
| 367 | memcpy(&encap.encap_oa, &oa.data, sizeof(encap.encap_oa)); |
| 368 | addattr_l(&req.n, sizeof(req.buf), XFRMA_ENCAP, |
| 369 | (void *)&encap, sizeof(encap)); |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 370 | } else if (strcmp(*argv, "coa") == 0) { |
| 371 | inet_prefix coa; |
| 372 | xfrm_address_t xcoa; |
| 373 | |
| 374 | if (coap) |
| 375 | duparg("coa", *argv); |
| 376 | coap = *argv; |
| 377 | |
| 378 | NEXT_ARG(); |
| 379 | |
| 380 | get_prefix(&coa, *argv, preferred_family); |
| 381 | if (coa.family == AF_UNSPEC) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 382 | invarg("value after \"coa\" has an unrecognized address family", *argv); |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 383 | if (coa.bytelen > sizeof(xcoa)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 384 | invarg("value after \"coa\" is too large", *argv); |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 385 | |
| 386 | memset(&xcoa, 0, sizeof(xcoa)); |
| 387 | memcpy(&xcoa, &coa.data, coa.bytelen); |
| 388 | |
| 389 | addattr_l(&req.n, sizeof(req.buf), XFRMA_COADDR, |
| 390 | (void *)&xcoa, sizeof(xcoa)); |
Joy Latten | 0c7a594 | 2011-02-02 17:32:59 -0600 | [diff] [blame] | 391 | } else if (strcmp(*argv, "ctx") == 0) { |
| 392 | char *context; |
| 393 | |
| 394 | if (sctxp) |
| 395 | duparg("ctx", *argv); |
| 396 | sctxp = *argv; |
| 397 | |
| 398 | NEXT_ARG(); |
| 399 | context = *argv; |
| 400 | |
| 401 | xfrm_sctx_parse((char *)&ctx.str, context, &ctx.sctx); |
| 402 | addattr_l(&req.n, sizeof(req.buf), XFRMA_SEC_CTX, |
| 403 | (void *)&ctx, ctx.sctx.len); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 404 | } else { |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 405 | /* try to assume ALGO */ |
| 406 | int type = xfrm_algotype_getbyname(*argv); |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 407 | |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 408 | switch (type) { |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 409 | case XFRMA_ALG_AEAD: |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 410 | case XFRMA_ALG_CRYPT: |
| 411 | case XFRMA_ALG_AUTH: |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 412 | case XFRMA_ALG_AUTH_TRUNC: |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 413 | case XFRMA_ALG_COMP: |
| 414 | { |
| 415 | /* ALGO */ |
| 416 | struct { |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 417 | union { |
| 418 | struct xfrm_algo alg; |
| 419 | struct xfrm_algo_aead aead; |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 420 | struct xfrm_algo_auth auth; |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 421 | } u; |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 422 | char buf[XFRM_ALGO_KEY_BUF_SIZE]; |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 423 | } alg = {}; |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 424 | int len; |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 425 | __u32 icvlen, trunclen; |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 426 | char *name; |
David Ward | f3b9aa3 | 2013-03-25 04:23:17 +0000 | [diff] [blame] | 427 | char *key = ""; |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 428 | char *buf; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 429 | |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 430 | switch (type) { |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 431 | case XFRMA_ALG_AEAD: |
David Ward | ec83952 | 2013-03-25 04:23:14 +0000 | [diff] [blame] | 432 | if (ealgop || aalgop || aeadop) |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 433 | duparg("ALGO-TYPE", *argv); |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 434 | aeadop = *argv; |
| 435 | break; |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 436 | case XFRMA_ALG_CRYPT: |
David Ward | ec83952 | 2013-03-25 04:23:14 +0000 | [diff] [blame] | 437 | if (ealgop || aeadop) |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 438 | duparg("ALGO-TYPE", *argv); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 439 | ealgop = *argv; |
| 440 | break; |
| 441 | case XFRMA_ALG_AUTH: |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 442 | case XFRMA_ALG_AUTH_TRUNC: |
David Ward | ec83952 | 2013-03-25 04:23:14 +0000 | [diff] [blame] | 443 | if (aalgop || aeadop) |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 444 | duparg("ALGO-TYPE", *argv); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 445 | aalgop = *argv; |
| 446 | break; |
| 447 | case XFRMA_ALG_COMP: |
| 448 | if (calgop) |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 449 | duparg("ALGO-TYPE", *argv); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 450 | calgop = *argv; |
| 451 | break; |
| 452 | default: |
| 453 | /* not reached */ |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 454 | invarg("ALGO-TYPE value is invalid\n", *argv); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 455 | } |
| 456 | |
| 457 | if (!NEXT_ARG_OK()) |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 458 | missarg("ALGO-NAME"); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 459 | NEXT_ARG(); |
| 460 | name = *argv; |
| 461 | |
David Ward | f3b9aa3 | 2013-03-25 04:23:17 +0000 | [diff] [blame] | 462 | switch (type) { |
| 463 | case XFRMA_ALG_AEAD: |
| 464 | case XFRMA_ALG_CRYPT: |
| 465 | case XFRMA_ALG_AUTH: |
| 466 | case XFRMA_ALG_AUTH_TRUNC: |
| 467 | if (!NEXT_ARG_OK()) |
David Ward | 29665f9 | 2013-03-25 04:23:18 +0000 | [diff] [blame] | 468 | missarg("ALGO-KEYMAT"); |
David Ward | f3b9aa3 | 2013-03-25 04:23:17 +0000 | [diff] [blame] | 469 | NEXT_ARG(); |
| 470 | key = *argv; |
| 471 | break; |
| 472 | } |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 473 | |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 474 | buf = alg.u.alg.alg_key; |
| 475 | len = sizeof(alg.u.alg); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 476 | |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 477 | switch (type) { |
| 478 | case XFRMA_ALG_AEAD: |
| 479 | if (!NEXT_ARG_OK()) |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 480 | missarg("ALGO-ICV-LEN"); |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 481 | NEXT_ARG(); |
| 482 | if (get_u32(&icvlen, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 483 | invarg("ALGO-ICV-LEN value is invalid", |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 484 | *argv); |
| 485 | alg.u.aead.alg_icv_len = icvlen; |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 486 | |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 487 | buf = alg.u.aead.alg_key; |
| 488 | len = sizeof(alg.u.aead); |
| 489 | break; |
| 490 | case XFRMA_ALG_AUTH_TRUNC: |
| 491 | if (!NEXT_ARG_OK()) |
David Ward | cbec021 | 2011-06-11 16:13:30 +0000 | [diff] [blame] | 492 | missarg("ALGO-TRUNC-LEN"); |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 493 | NEXT_ARG(); |
| 494 | if (get_u32(&trunclen, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 495 | invarg("ALGO-TRUNC-LEN value is invalid", |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 496 | *argv); |
| 497 | alg.u.auth.alg_trunc_len = trunclen; |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 498 | |
Nicolas Dichtel | f323f2a | 2011-01-11 06:32:46 +0000 | [diff] [blame] | 499 | buf = alg.u.auth.alg_key; |
| 500 | len = sizeof(alg.u.auth); |
| 501 | break; |
| 502 | } |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 503 | |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 504 | xfrm_algo_parse((void *)&alg, type, name, key, |
Herbert Xu | 1758a81 | 2008-09-17 22:09:01 -0700 | [diff] [blame] | 505 | buf, sizeof(alg.buf)); |
| 506 | len += alg.u.alg.alg_key_len; |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 507 | |
| 508 | addattr_l(&req.n, sizeof(req.buf), type, |
| 509 | (void *)&alg, len); |
| 510 | break; |
| 511 | } |
| 512 | default: |
| 513 | /* try to assume ID */ |
| 514 | if (idp) |
| 515 | invarg("unknown", *argv); |
| 516 | idp = *argv; |
| 517 | |
| 518 | /* ID */ |
| 519 | xfrm_id_parse(&req.xsinfo.saddr, &req.xsinfo.id, |
| 520 | &req.xsinfo.family, 0, &argc, &argv); |
| 521 | if (preferred_family == AF_UNSPEC) |
| 522 | preferred_family = req.xsinfo.family; |
| 523 | } |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 524 | } |
| 525 | argc--; argv++; |
| 526 | } |
| 527 | |
dingzhi | 0151b56 | 2014-10-20 11:23:04 +0200 | [diff] [blame] | 528 | if (req.xsinfo.flags & XFRM_STATE_ESN && |
| 529 | replay_window == 0) { |
| 530 | fprintf(stderr, "Error: esn flag set without replay-window.\n"); |
| 531 | exit(-1); |
| 532 | } |
| 533 | |
| 534 | if (replay_window > XFRMA_REPLAY_ESN_MAX) { |
| 535 | fprintf(stderr, |
| 536 | "Error: replay-window (%u) > XFRMA_REPLAY_ESN_MAX (%u).\n", |
| 537 | replay_window, XFRMA_REPLAY_ESN_MAX); |
| 538 | exit(-1); |
| 539 | } |
| 540 | |
| 541 | if (req.xsinfo.flags & XFRM_STATE_ESN || |
| 542 | replay_window > (sizeof(replay.bitmap) * 8)) { |
| 543 | replay_esn.seq = seq; |
| 544 | replay_esn.oseq = oseq; |
| 545 | replay_esn.seq_hi = seq_hi; |
| 546 | replay_esn.oseq_hi = oseq_hi; |
| 547 | replay_esn.replay_window = replay_window; |
| 548 | replay_esn.bmp_len = (replay_window + sizeof(__u32) * 8 - 1) / |
| 549 | (sizeof(__u32) * 8); |
| 550 | addattr_l(&req.n, sizeof(req.buf), XFRMA_REPLAY_ESN_VAL, |
| 551 | &replay_esn, sizeof(replay_esn)); |
| 552 | } else { |
| 553 | if (seq || oseq) { |
| 554 | replay.seq = seq; |
| 555 | replay.oseq = oseq; |
| 556 | addattr_l(&req.n, sizeof(req.buf), XFRMA_REPLAY_VAL, |
| 557 | &replay, sizeof(replay)); |
| 558 | } |
| 559 | req.xsinfo.replay_window = replay_window; |
| 560 | } |
Herbert Xu | de95ae7 | 2008-04-23 15:42:32 +0800 | [diff] [blame] | 561 | |
Nicolas Dichtel | dc8867d | 2013-05-17 01:36:38 -0700 | [diff] [blame] | 562 | if (extra_flags) |
| 563 | addattr32(&req.n, sizeof(req.buf), XFRMA_SA_EXTRA_FLAGS, |
| 564 | extra_flags); |
| 565 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 566 | if (!idp) { |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 567 | fprintf(stderr, "Not enough information: ID is required\n"); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 568 | exit(1); |
| 569 | } |
| 570 | |
Christophe Gouault | b557416 | 2013-10-08 05:56:54 -0700 | [diff] [blame] | 571 | if (mark.m) { |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 572 | int r = addattr_l(&req.n, sizeof(req.buf), XFRMA_MARK, |
| 573 | (void *)&mark, sizeof(mark)); |
| 574 | if (r < 0) { |
| 575 | fprintf(stderr, "XFRMA_MARK failed\n"); |
| 576 | exit(1); |
| 577 | } |
| 578 | } |
| 579 | |
David Ward | 6128fdf | 2013-03-25 04:23:15 +0000 | [diff] [blame] | 580 | if (xfrm_xfrmproto_is_ipsec(req.xsinfo.id.proto)) { |
| 581 | switch (req.xsinfo.mode) { |
| 582 | case XFRM_MODE_TRANSPORT: |
| 583 | case XFRM_MODE_TUNNEL: |
| 584 | break; |
| 585 | case XFRM_MODE_BEET: |
| 586 | if (req.xsinfo.id.proto == IPPROTO_ESP) |
| 587 | break; |
| 588 | default: |
| 589 | fprintf(stderr, "MODE value is invalid with XFRM-PROTO value \"%s\"\n", |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 590 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 591 | exit(1); |
| 592 | } |
David Ward | 6128fdf | 2013-03-25 04:23:15 +0000 | [diff] [blame] | 593 | |
| 594 | switch (req.xsinfo.id.proto) { |
| 595 | case IPPROTO_ESP: |
| 596 | if (calgop) { |
| 597 | fprintf(stderr, "ALGO-TYPE value \"%s\" is invalid with XFRM-PROTO value \"%s\"\n", |
| 598 | strxf_algotype(XFRMA_ALG_COMP), |
| 599 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 600 | exit(1); |
| 601 | } |
| 602 | if (!ealgop && !aeadop) { |
| 603 | fprintf(stderr, "ALGO-TYPE value \"%s\" or \"%s\" is required with XFRM-PROTO value \"%s\"\n", |
| 604 | strxf_algotype(XFRMA_ALG_CRYPT), |
| 605 | strxf_algotype(XFRMA_ALG_AEAD), |
| 606 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 607 | exit(1); |
| 608 | } |
| 609 | break; |
| 610 | case IPPROTO_AH: |
| 611 | if (ealgop || aeadop || calgop) { |
| 612 | fprintf(stderr, "ALGO-TYPE values \"%s\", \"%s\", and \"%s\" are invalid with XFRM-PROTO value \"%s\"\n", |
| 613 | strxf_algotype(XFRMA_ALG_CRYPT), |
| 614 | strxf_algotype(XFRMA_ALG_AEAD), |
| 615 | strxf_algotype(XFRMA_ALG_COMP), |
| 616 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 617 | exit(1); |
| 618 | } |
| 619 | if (!aalgop) { |
| 620 | fprintf(stderr, "ALGO-TYPE value \"%s\" or \"%s\" is required with XFRM-PROTO value \"%s\"\n", |
| 621 | strxf_algotype(XFRMA_ALG_AUTH), |
| 622 | strxf_algotype(XFRMA_ALG_AUTH_TRUNC), |
| 623 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 624 | exit(1); |
| 625 | } |
| 626 | break; |
| 627 | case IPPROTO_COMP: |
| 628 | if (ealgop || aalgop || aeadop) { |
| 629 | fprintf(stderr, "ALGO-TYPE values \"%s\", \"%s\", \"%s\", and \"%s\" are invalid with XFRM-PROTO value \"%s\"\n", |
| 630 | strxf_algotype(XFRMA_ALG_CRYPT), |
| 631 | strxf_algotype(XFRMA_ALG_AUTH), |
| 632 | strxf_algotype(XFRMA_ALG_AUTH_TRUNC), |
| 633 | strxf_algotype(XFRMA_ALG_AEAD), |
| 634 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 635 | exit(1); |
| 636 | } |
| 637 | if (!calgop) { |
| 638 | fprintf(stderr, "ALGO-TYPE value \"%s\" is required with XFRM-PROTO value \"%s\"\n", |
| 639 | strxf_algotype(XFRMA_ALG_COMP), |
| 640 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 641 | exit(1); |
| 642 | } |
| 643 | break; |
| 644 | } |
| 645 | } else { |
| 646 | if (ealgop || aalgop || aeadop || calgop) { |
| 647 | fprintf(stderr, "ALGO is invalid with XFRM-PROTO value \"%s\"\n", |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 648 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 649 | exit(1); |
| 650 | } |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 651 | } |
| 652 | |
David Ward | 6128fdf | 2013-03-25 04:23:15 +0000 | [diff] [blame] | 653 | if (xfrm_xfrmproto_is_ro(req.xsinfo.id.proto)) { |
| 654 | switch (req.xsinfo.mode) { |
| 655 | case XFRM_MODE_ROUTEOPTIMIZATION: |
| 656 | case XFRM_MODE_IN_TRIGGER: |
| 657 | break; |
| 658 | case 0: |
| 659 | fprintf(stderr, "\"mode\" is required with XFRM-PROTO value \"%s\"\n", |
| 660 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 661 | exit(1); |
| 662 | default: |
| 663 | fprintf(stderr, "MODE value is invalid with XFRM-PROTO value \"%s\"\n", |
| 664 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 665 | exit(1); |
| 666 | } |
| 667 | |
| 668 | if (!coap) { |
| 669 | fprintf(stderr, "\"coa\" is required with XFRM-PROTO value \"%s\"\n", |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 670 | strxf_xfrmproto(req.xsinfo.id.proto)); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 671 | exit(1); |
| 672 | } |
| 673 | } else { |
David Ward | 6128fdf | 2013-03-25 04:23:15 +0000 | [diff] [blame] | 674 | if (coap) { |
| 675 | fprintf(stderr, "\"coa\" is invalid with XFRM-PROTO value \"%s\"\n", |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 676 | strxf_xfrmproto(req.xsinfo.id.proto)); |
| 677 | exit(1); |
| 678 | } |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 679 | } |
| 680 | |
| 681 | if (rtnl_open_byproto(&rth, 0, NETLINK_XFRM) < 0) |
| 682 | exit(1); |
| 683 | |
| 684 | if (req.xsinfo.family == AF_UNSPEC) |
| 685 | req.xsinfo.family = AF_INET; |
| 686 | |
Stephen Hemminger | c079e12 | 2015-05-27 12:26:14 -0700 | [diff] [blame] | 687 | if (rtnl_talk(&rth, &req.n, NULL, 0) < 0) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 688 | exit(2); |
| 689 | |
| 690 | rtnl_close(&rth); |
| 691 | |
| 692 | return 0; |
| 693 | } |
| 694 | |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 695 | static int xfrm_state_allocspi(int argc, char **argv) |
| 696 | { |
| 697 | struct rtnl_handle rth; |
| 698 | struct { |
Stephen Hemminger | 4806867 | 2014-02-17 10:56:31 -0800 | [diff] [blame] | 699 | struct nlmsghdr n; |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 700 | struct xfrm_userspi_info xspi; |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 701 | char buf[RTA_BUF_SIZE]; |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 702 | } req; |
| 703 | char *idp = NULL; |
| 704 | char *minp = NULL; |
| 705 | char *maxp = NULL; |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 706 | struct xfrm_mark mark = {0, 0}; |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 707 | char res_buf[NLMSG_BUF_SIZE]; |
| 708 | struct nlmsghdr *res_n = (struct nlmsghdr *)res_buf; |
| 709 | |
| 710 | memset(res_buf, 0, sizeof(res_buf)); |
| 711 | |
| 712 | memset(&req, 0, sizeof(req)); |
| 713 | |
| 714 | req.n.nlmsg_len = NLMSG_LENGTH(sizeof(req.xspi)); |
| 715 | req.n.nlmsg_flags = NLM_F_REQUEST; |
| 716 | req.n.nlmsg_type = XFRM_MSG_ALLOCSPI; |
| 717 | req.xspi.info.family = preferred_family; |
| 718 | |
| 719 | #if 0 |
| 720 | req.xsinfo.lft.soft_byte_limit = XFRM_INF; |
| 721 | req.xsinfo.lft.hard_byte_limit = XFRM_INF; |
| 722 | req.xsinfo.lft.soft_packet_limit = XFRM_INF; |
| 723 | req.xsinfo.lft.hard_packet_limit = XFRM_INF; |
| 724 | #endif |
| 725 | |
| 726 | while (argc > 0) { |
| 727 | if (strcmp(*argv, "mode") == 0) { |
| 728 | NEXT_ARG(); |
| 729 | xfrm_mode_parse(&req.xspi.info.mode, &argc, &argv); |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 730 | } else if (strcmp(*argv, "mark") == 0) { |
| 731 | xfrm_parse_mark(&mark, &argc, &argv); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 732 | } else if (strcmp(*argv, "reqid") == 0) { |
| 733 | NEXT_ARG(); |
| 734 | xfrm_reqid_parse(&req.xspi.info.reqid, &argc, &argv); |
| 735 | } else if (strcmp(*argv, "seq") == 0) { |
| 736 | NEXT_ARG(); |
| 737 | xfrm_seq_parse(&req.xspi.info.seq, &argc, &argv); |
| 738 | } else if (strcmp(*argv, "min") == 0) { |
| 739 | if (minp) |
| 740 | duparg("min", *argv); |
| 741 | minp = *argv; |
| 742 | |
| 743 | NEXT_ARG(); |
| 744 | |
| 745 | if (get_u32(&req.xspi.min, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 746 | invarg("value after \"min\" is invalid", *argv); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 747 | } else if (strcmp(*argv, "max") == 0) { |
| 748 | if (maxp) |
| 749 | duparg("max", *argv); |
| 750 | maxp = *argv; |
| 751 | |
| 752 | NEXT_ARG(); |
| 753 | |
| 754 | if (get_u32(&req.xspi.max, *argv, 0)) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 755 | invarg("value after \"max\" is invalid", *argv); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 756 | } else { |
| 757 | /* try to assume ID */ |
| 758 | if (idp) |
| 759 | invarg("unknown", *argv); |
| 760 | idp = *argv; |
| 761 | |
| 762 | /* ID */ |
| 763 | xfrm_id_parse(&req.xspi.info.saddr, &req.xspi.info.id, |
| 764 | &req.xspi.info.family, 0, &argc, &argv); |
| 765 | if (req.xspi.info.id.spi) { |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 766 | fprintf(stderr, "\"spi\" is invalid\n"); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 767 | exit(1); |
| 768 | } |
| 769 | if (preferred_family == AF_UNSPEC) |
| 770 | preferred_family = req.xspi.info.family; |
| 771 | } |
| 772 | argc--; argv++; |
| 773 | } |
| 774 | |
| 775 | if (!idp) { |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 776 | fprintf(stderr, "Not enough information: ID is required\n"); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 777 | exit(1); |
| 778 | } |
| 779 | |
| 780 | if (minp) { |
| 781 | if (!maxp) { |
| 782 | fprintf(stderr, "\"max\" is missing\n"); |
| 783 | exit(1); |
| 784 | } |
| 785 | if (req.xspi.min > req.xspi.max) { |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 786 | fprintf(stderr, "value after \"min\" is larger than value after \"max\"\n"); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 787 | exit(1); |
| 788 | } |
| 789 | } else { |
| 790 | if (maxp) { |
| 791 | fprintf(stderr, "\"min\" is missing\n"); |
| 792 | exit(1); |
| 793 | } |
| 794 | |
| 795 | /* XXX: Default value defined in PF_KEY; |
| 796 | * See kernel's net/key/af_key.c(pfkey_getspi). |
| 797 | */ |
| 798 | req.xspi.min = 0x100; |
| 799 | req.xspi.max = 0x0fffffff; |
| 800 | |
| 801 | /* XXX: IPCOMP spi is 16-bits; |
| 802 | * See kernel's net/xfrm/xfrm_user(verify_userspi_info). |
| 803 | */ |
| 804 | if (req.xspi.info.id.proto == IPPROTO_COMP) |
| 805 | req.xspi.max = 0xffff; |
| 806 | } |
| 807 | |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 808 | if (mark.m & mark.v) { |
| 809 | int r = addattr_l(&req.n, sizeof(req.buf), XFRMA_MARK, |
| 810 | (void *)&mark, sizeof(mark)); |
| 811 | if (r < 0) { |
| 812 | fprintf(stderr, "XFRMA_MARK failed\n"); |
| 813 | exit(1); |
| 814 | } |
| 815 | } |
| 816 | |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 817 | if (rtnl_open_byproto(&rth, 0, NETLINK_XFRM) < 0) |
| 818 | exit(1); |
| 819 | |
| 820 | if (req.xspi.info.family == AF_UNSPEC) |
| 821 | req.xspi.info.family = AF_INET; |
| 822 | |
| 823 | |
Stephen Hemminger | c079e12 | 2015-05-27 12:26:14 -0700 | [diff] [blame] | 824 | if (rtnl_talk(&rth, &req.n, res_n, sizeof(res_buf)) < 0) |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 825 | exit(2); |
| 826 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 827 | if (xfrm_state_print(NULL, res_n, (void *)stdout) < 0) { |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 828 | fprintf(stderr, "An error :-)\n"); |
| 829 | exit(1); |
| 830 | } |
| 831 | |
| 832 | rtnl_close(&rth); |
| 833 | |
| 834 | return 0; |
| 835 | } |
| 836 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 837 | static int xfrm_state_filter_match(struct xfrm_usersa_info *xsinfo) |
| 838 | { |
| 839 | if (!filter.use) |
| 840 | return 1; |
| 841 | |
| 842 | if (filter.id_src_mask) |
net[shemminger]!shemminger | eaa34ee | 2005-01-17 23:29:39 +0000 | [diff] [blame] | 843 | if (xfrm_addr_match(&xsinfo->saddr, &filter.xsinfo.saddr, |
| 844 | filter.id_src_mask)) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 845 | return 0; |
| 846 | if (filter.id_dst_mask) |
net[shemminger]!shemminger | eaa34ee | 2005-01-17 23:29:39 +0000 | [diff] [blame] | 847 | if (xfrm_addr_match(&xsinfo->id.daddr, &filter.xsinfo.id.daddr, |
| 848 | filter.id_dst_mask)) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 849 | return 0; |
| 850 | if ((xsinfo->id.proto^filter.xsinfo.id.proto)&filter.id_proto_mask) |
| 851 | return 0; |
| 852 | if ((xsinfo->id.spi^filter.xsinfo.id.spi)&filter.id_spi_mask) |
| 853 | return 0; |
| 854 | if ((xsinfo->mode^filter.xsinfo.mode)&filter.mode_mask) |
| 855 | return 0; |
| 856 | if ((xsinfo->reqid^filter.xsinfo.reqid)&filter.reqid_mask) |
| 857 | return 0; |
| 858 | if (filter.state_flags_mask) |
| 859 | if ((xsinfo->flags & filter.xsinfo.flags) == 0) |
| 860 | return 0; |
| 861 | |
| 862 | return 1; |
| 863 | } |
| 864 | |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 865 | int xfrm_state_print(const struct sockaddr_nl *who, struct nlmsghdr *n, |
| 866 | void *arg) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 867 | { |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 868 | FILE *fp = (FILE *)arg; |
| 869 | struct rtattr *tb[XFRMA_MAX+1]; |
| 870 | struct rtattr *rta; |
shemminger | c595c79 | 2005-11-01 23:03:03 +0000 | [diff] [blame] | 871 | struct xfrm_usersa_info *xsinfo = NULL; |
| 872 | struct xfrm_user_expire *xexp = NULL; |
| 873 | struct xfrm_usersa_id *xsid = NULL; |
| 874 | int len = n->nlmsg_len; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 875 | |
| 876 | if (n->nlmsg_type != XFRM_MSG_NEWSA && |
shemminger | 90f9302 | 2005-06-07 21:55:55 +0000 | [diff] [blame] | 877 | n->nlmsg_type != XFRM_MSG_DELSA && |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 878 | n->nlmsg_type != XFRM_MSG_UPDSA && |
shemminger | 90f9302 | 2005-06-07 21:55:55 +0000 | [diff] [blame] | 879 | n->nlmsg_type != XFRM_MSG_EXPIRE) { |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 880 | fprintf(stderr, "Not a state: %08x %08x %08x\n", |
| 881 | n->nlmsg_len, n->nlmsg_type, n->nlmsg_flags); |
| 882 | return 0; |
| 883 | } |
| 884 | |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 885 | if (n->nlmsg_type == XFRM_MSG_DELSA) { |
shemminger | c595c79 | 2005-11-01 23:03:03 +0000 | [diff] [blame] | 886 | /* Dont blame me for this .. Herbert made me do it */ |
| 887 | xsid = NLMSG_DATA(n); |
Andy Gay | af1b6a4 | 2006-08-10 20:25:40 -0400 | [diff] [blame] | 888 | len -= NLMSG_SPACE(sizeof(*xsid)); |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 889 | } else if (n->nlmsg_type == XFRM_MSG_EXPIRE) { |
| 890 | xexp = NLMSG_DATA(n); |
| 891 | xsinfo = &xexp->state; |
Andy Gay | af1b6a4 | 2006-08-10 20:25:40 -0400 | [diff] [blame] | 892 | len -= NLMSG_SPACE(sizeof(*xexp)); |
shemminger | 90f9302 | 2005-06-07 21:55:55 +0000 | [diff] [blame] | 893 | } else { |
| 894 | xexp = NULL; |
| 895 | xsinfo = NLMSG_DATA(n); |
Andy Gay | af1b6a4 | 2006-08-10 20:25:40 -0400 | [diff] [blame] | 896 | len -= NLMSG_SPACE(sizeof(*xsinfo)); |
shemminger | 90f9302 | 2005-06-07 21:55:55 +0000 | [diff] [blame] | 897 | } |
| 898 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 899 | if (len < 0) { |
| 900 | fprintf(stderr, "BUG: wrong nlmsg len %d\n", len); |
| 901 | return -1; |
| 902 | } |
| 903 | |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 904 | if (xsinfo && !xfrm_state_filter_match(xsinfo)) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 905 | return 0; |
| 906 | |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 907 | if (n->nlmsg_type == XFRM_MSG_DELSA) |
shemminger | c595c79 | 2005-11-01 23:03:03 +0000 | [diff] [blame] | 908 | fprintf(fp, "Deleted "); |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 909 | else if (n->nlmsg_type == XFRM_MSG_UPDSA) |
| 910 | fprintf(fp, "Updated "); |
shemminger | c595c79 | 2005-11-01 23:03:03 +0000 | [diff] [blame] | 911 | else if (n->nlmsg_type == XFRM_MSG_EXPIRE) |
| 912 | fprintf(fp, "Expired "); |
| 913 | |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 914 | if (n->nlmsg_type == XFRM_MSG_DELSA) |
| 915 | rta = XFRMSID_RTA(xsid); |
| 916 | else if (n->nlmsg_type == XFRM_MSG_EXPIRE) |
shemminger | 90f9302 | 2005-06-07 21:55:55 +0000 | [diff] [blame] | 917 | rta = XFRMEXP_RTA(xexp); |
Stephen Hemminger | ae665a5 | 2006-12-05 10:10:22 -0800 | [diff] [blame] | 918 | else |
shemminger | 90f9302 | 2005-06-07 21:55:55 +0000 | [diff] [blame] | 919 | rta = XFRMS_RTA(xsinfo); |
| 920 | |
| 921 | parse_rtattr(tb, XFRMA_MAX, rta, len); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 922 | |
shemminger | c595c79 | 2005-11-01 23:03:03 +0000 | [diff] [blame] | 923 | if (n->nlmsg_type == XFRM_MSG_DELSA) { |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 924 | /* xfrm_policy_id_print(); */ |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 925 | |
| 926 | if (!tb[XFRMA_SA]) { |
| 927 | fprintf(stderr, "Buggy XFRM_MSG_DELSA: no XFRMA_SA\n"); |
| 928 | return -1; |
shemminger | c595c79 | 2005-11-01 23:03:03 +0000 | [diff] [blame] | 929 | } |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 930 | if (RTA_PAYLOAD(tb[XFRMA_SA]) < sizeof(*xsinfo)) { |
| 931 | fprintf(stderr, "Buggy XFRM_MSG_DELPOLICY: too short XFRMA_POLICY len\n"); |
| 932 | return -1; |
| 933 | } |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 934 | xsinfo = RTA_DATA(tb[XFRMA_SA]); |
shemminger | c595c79 | 2005-11-01 23:03:03 +0000 | [diff] [blame] | 935 | } |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 936 | |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 937 | xfrm_state_info_print(xsinfo, tb, fp, NULL, NULL); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 938 | |
shemminger | 90f9302 | 2005-06-07 21:55:55 +0000 | [diff] [blame] | 939 | if (n->nlmsg_type == XFRM_MSG_EXPIRE) { |
| 940 | fprintf(fp, "\t"); |
| 941 | fprintf(fp, "hard %u", xexp->hard); |
| 942 | fprintf(fp, "%s", _SL_); |
| 943 | } |
| 944 | |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 945 | if (oneline) |
| 946 | fprintf(fp, "\n"); |
shemminger | 669ae74 | 2005-11-07 18:39:30 +0000 | [diff] [blame] | 947 | fflush(fp); |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 948 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 949 | return 0; |
| 950 | } |
| 951 | |
| 952 | static int xfrm_state_get_or_delete(int argc, char **argv, int delete) |
| 953 | { |
| 954 | struct rtnl_handle rth; |
| 955 | struct { |
Stephen Hemminger | 4806867 | 2014-02-17 10:56:31 -0800 | [diff] [blame] | 956 | struct nlmsghdr n; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 957 | struct xfrm_usersa_id xsid; |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 958 | char buf[RTA_BUF_SIZE]; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 959 | } req; |
| 960 | struct xfrm_id id; |
| 961 | char *idp = NULL; |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 962 | struct xfrm_mark mark = {0, 0}; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 963 | |
| 964 | memset(&req, 0, sizeof(req)); |
| 965 | |
| 966 | req.n.nlmsg_len = NLMSG_LENGTH(sizeof(req.xsid)); |
| 967 | req.n.nlmsg_flags = NLM_F_REQUEST; |
| 968 | req.n.nlmsg_type = delete ? XFRM_MSG_DELSA : XFRM_MSG_GETSA; |
| 969 | req.xsid.family = preferred_family; |
| 970 | |
| 971 | while (argc > 0) { |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 972 | xfrm_address_t saddr; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 973 | |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 974 | if (strcmp(*argv, "mark") == 0) { |
| 975 | xfrm_parse_mark(&mark, &argc, &argv); |
| 976 | } else { |
| 977 | if (idp) |
| 978 | invarg("unknown", *argv); |
| 979 | idp = *argv; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 980 | |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 981 | /* ID */ |
| 982 | memset(&id, 0, sizeof(id)); |
| 983 | memset(&saddr, 0, sizeof(saddr)); |
| 984 | xfrm_id_parse(&saddr, &id, &req.xsid.family, 0, |
| 985 | &argc, &argv); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 986 | |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 987 | memcpy(&req.xsid.daddr, &id.daddr, sizeof(req.xsid.daddr)); |
| 988 | req.xsid.spi = id.spi; |
| 989 | req.xsid.proto = id.proto; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 990 | |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 991 | addattr_l(&req.n, sizeof(req.buf), XFRMA_SRCADDR, |
| 992 | (void *)&saddr, sizeof(saddr)); |
| 993 | } |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 994 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 995 | argc--; argv++; |
| 996 | } |
| 997 | |
Jamal Hadi Salim | c90cda9 | 2010-02-23 03:15:12 +0000 | [diff] [blame] | 998 | if (mark.m & mark.v) { |
| 999 | int r = addattr_l(&req.n, sizeof(req.buf), XFRMA_MARK, |
| 1000 | (void *)&mark, sizeof(mark)); |
| 1001 | if (r < 0) { |
| 1002 | fprintf(stderr, "XFRMA_MARK failed\n"); |
| 1003 | exit(1); |
| 1004 | } |
| 1005 | } |
| 1006 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1007 | if (rtnl_open_byproto(&rth, 0, NETLINK_XFRM) < 0) |
| 1008 | exit(1); |
| 1009 | |
| 1010 | if (req.xsid.family == AF_UNSPEC) |
| 1011 | req.xsid.family = AF_INET; |
| 1012 | |
| 1013 | if (delete) { |
Stephen Hemminger | c079e12 | 2015-05-27 12:26:14 -0700 | [diff] [blame] | 1014 | if (rtnl_talk(&rth, &req.n, NULL, 0) < 0) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1015 | exit(2); |
| 1016 | } else { |
| 1017 | char buf[NLMSG_BUF_SIZE]; |
| 1018 | struct nlmsghdr *res_n = (struct nlmsghdr *)buf; |
| 1019 | |
| 1020 | memset(buf, 0, sizeof(buf)); |
| 1021 | |
Stephen Hemminger | c079e12 | 2015-05-27 12:26:14 -0700 | [diff] [blame] | 1022 | if (rtnl_talk(&rth, &req.n, res_n, sizeof(req)) < 0) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1023 | exit(2); |
| 1024 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1025 | if (xfrm_state_print(NULL, res_n, (void *)stdout) < 0) { |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1026 | fprintf(stderr, "An error :-)\n"); |
| 1027 | exit(1); |
| 1028 | } |
| 1029 | } |
| 1030 | |
| 1031 | rtnl_close(&rth); |
| 1032 | |
| 1033 | return 0; |
| 1034 | } |
| 1035 | |
| 1036 | /* |
| 1037 | * With an existing state of nlmsg, make new nlmsg for deleting the state |
| 1038 | * and store it to buffer. |
| 1039 | */ |
osdl.net!shemminger | 6dc9f01 | 2004-08-31 17:45:21 +0000 | [diff] [blame] | 1040 | static int xfrm_state_keep(const struct sockaddr_nl *who, |
osdl.net!shemminger | 50772dc | 2004-12-07 21:48:29 +0000 | [diff] [blame] | 1041 | struct nlmsghdr *n, |
osdl.net!shemminger | 6dc9f01 | 2004-08-31 17:45:21 +0000 | [diff] [blame] | 1042 | void *arg) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1043 | { |
| 1044 | struct xfrm_buffer *xb = (struct xfrm_buffer *)arg; |
| 1045 | struct rtnl_handle *rth = xb->rth; |
| 1046 | struct xfrm_usersa_info *xsinfo = NLMSG_DATA(n); |
| 1047 | int len = n->nlmsg_len; |
| 1048 | struct nlmsghdr *new_n; |
| 1049 | struct xfrm_usersa_id *xsid; |
| 1050 | |
| 1051 | if (n->nlmsg_type != XFRM_MSG_NEWSA) { |
| 1052 | fprintf(stderr, "Not a state: %08x %08x %08x\n", |
| 1053 | n->nlmsg_len, n->nlmsg_type, n->nlmsg_flags); |
| 1054 | return 0; |
| 1055 | } |
| 1056 | |
| 1057 | len -= NLMSG_LENGTH(sizeof(*xsinfo)); |
| 1058 | if (len < 0) { |
| 1059 | fprintf(stderr, "BUG: wrong nlmsg len %d\n", len); |
| 1060 | return -1; |
| 1061 | } |
| 1062 | |
| 1063 | if (!xfrm_state_filter_match(xsinfo)) |
| 1064 | return 0; |
| 1065 | |
| 1066 | if (xb->offset > xb->size) { |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1067 | fprintf(stderr, "State buffer overflow\n"); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1068 | return -1; |
| 1069 | } |
| 1070 | |
| 1071 | new_n = (struct nlmsghdr *)(xb->buf + xb->offset); |
| 1072 | new_n->nlmsg_len = NLMSG_LENGTH(sizeof(*xsid)); |
| 1073 | new_n->nlmsg_flags = NLM_F_REQUEST; |
| 1074 | new_n->nlmsg_type = XFRM_MSG_DELSA; |
| 1075 | new_n->nlmsg_seq = ++rth->seq; |
| 1076 | |
| 1077 | xsid = NLMSG_DATA(new_n); |
| 1078 | xsid->family = xsinfo->family; |
| 1079 | memcpy(&xsid->daddr, &xsinfo->id.daddr, sizeof(xsid->daddr)); |
| 1080 | xsid->spi = xsinfo->id.spi; |
| 1081 | xsid->proto = xsinfo->id.proto; |
| 1082 | |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 1083 | addattr_l(new_n, xb->size, XFRMA_SRCADDR, &xsinfo->saddr, |
| 1084 | sizeof(xsid->daddr)); |
| 1085 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1086 | xb->offset += new_n->nlmsg_len; |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1087 | xb->nlmsg_count++; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1088 | |
| 1089 | return 0; |
| 1090 | } |
| 1091 | |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1092 | static int xfrm_state_list_or_deleteall(int argc, char **argv, int deleteall) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1093 | { |
| 1094 | char *idp = NULL; |
| 1095 | struct rtnl_handle rth; |
| 1096 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1097 | if (argc > 0) |
org[shemminger]!nakam | bd641cd | 2004-09-28 18:38:35 +0000 | [diff] [blame] | 1098 | filter.use = 1; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1099 | filter.xsinfo.family = preferred_family; |
| 1100 | |
| 1101 | while (argc > 0) { |
| 1102 | if (strcmp(*argv, "mode") == 0) { |
| 1103 | NEXT_ARG(); |
| 1104 | xfrm_mode_parse(&filter.xsinfo.mode, &argc, &argv); |
| 1105 | |
| 1106 | filter.mode_mask = XFRM_FILTER_MASK_FULL; |
| 1107 | |
| 1108 | } else if (strcmp(*argv, "reqid") == 0) { |
| 1109 | NEXT_ARG(); |
| 1110 | xfrm_reqid_parse(&filter.xsinfo.reqid, &argc, &argv); |
| 1111 | |
| 1112 | filter.reqid_mask = XFRM_FILTER_MASK_FULL; |
| 1113 | |
| 1114 | } else if (strcmp(*argv, "flag") == 0) { |
| 1115 | NEXT_ARG(); |
| 1116 | xfrm_state_flag_parse(&filter.xsinfo.flags, &argc, &argv); |
| 1117 | |
| 1118 | filter.state_flags_mask = XFRM_FILTER_MASK_FULL; |
| 1119 | |
| 1120 | } else { |
| 1121 | if (idp) |
| 1122 | invarg("unknown", *argv); |
| 1123 | idp = *argv; |
| 1124 | |
| 1125 | /* ID */ |
net[shemminger]!shemminger | 7809c61 | 2004-08-11 23:41:38 +0000 | [diff] [blame] | 1126 | xfrm_id_parse(&filter.xsinfo.saddr, &filter.xsinfo.id, |
| 1127 | &filter.xsinfo.family, 1, &argc, &argv); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1128 | if (preferred_family == AF_UNSPEC) |
| 1129 | preferred_family = filter.xsinfo.family; |
| 1130 | } |
| 1131 | argc--; argv++; |
| 1132 | } |
| 1133 | |
| 1134 | if (rtnl_open_byproto(&rth, 0, NETLINK_XFRM) < 0) |
| 1135 | exit(1); |
| 1136 | |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1137 | if (deleteall) { |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1138 | struct xfrm_buffer xb; |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1139 | char buf[NLMSG_DELETEALL_BUF_SIZE]; |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1140 | int i; |
| 1141 | |
| 1142 | xb.buf = buf; |
| 1143 | xb.size = sizeof(buf); |
| 1144 | xb.rth = &rth; |
| 1145 | |
| 1146 | for (i = 0; ; i++) { |
Nicolas Dichtel | 782cf01 | 2015-04-15 14:00:53 +0200 | [diff] [blame] | 1147 | struct { |
| 1148 | struct nlmsghdr n; |
| 1149 | char buf[NLMSG_BUF_SIZE]; |
| 1150 | } req = { |
| 1151 | .n.nlmsg_len = NLMSG_HDRLEN, |
| 1152 | .n.nlmsg_flags = NLM_F_DUMP | NLM_F_REQUEST, |
| 1153 | .n.nlmsg_type = XFRM_MSG_GETSA, |
| 1154 | .n.nlmsg_seq = rth.dump = ++rth.seq, |
| 1155 | }; |
| 1156 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1157 | xb.offset = 0; |
| 1158 | xb.nlmsg_count = 0; |
| 1159 | |
| 1160 | if (show_stats > 1) |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1161 | fprintf(stderr, "Delete-all round = %d\n", i); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1162 | |
Nicolas Dichtel | 782cf01 | 2015-04-15 14:00:53 +0200 | [diff] [blame] | 1163 | if (rtnl_send(&rth, (void *)&req, req.n.nlmsg_len) < 0) { |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1164 | perror("Cannot send dump request"); |
| 1165 | exit(1); |
| 1166 | } |
| 1167 | |
Stephen Hemminger | cd70f3f | 2011-12-28 10:37:12 -0800 | [diff] [blame] | 1168 | if (rtnl_dump_filter(&rth, xfrm_state_keep, &xb) < 0) { |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1169 | fprintf(stderr, "Delete-all terminated\n"); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1170 | exit(1); |
| 1171 | } |
| 1172 | if (xb.nlmsg_count == 0) { |
| 1173 | if (show_stats > 1) |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1174 | fprintf(stderr, "Delete-all completed\n"); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1175 | break; |
| 1176 | } |
| 1177 | |
Stephen Hemminger | f31a37f | 2008-01-31 21:38:58 -0800 | [diff] [blame] | 1178 | if (rtnl_send_check(&rth, xb.buf, xb.offset) < 0) { |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1179 | perror("Failed to send delete-all request\n"); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1180 | exit(1); |
| 1181 | } |
| 1182 | if (show_stats > 1) |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1183 | fprintf(stderr, "Delete-all nlmsg count = %d\n", xb.nlmsg_count); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1184 | |
| 1185 | xb.offset = 0; |
| 1186 | xb.nlmsg_count = 0; |
| 1187 | } |
| 1188 | |
| 1189 | } else { |
Nicolas Dichtel | f687d73 | 2014-03-21 11:02:43 +0100 | [diff] [blame] | 1190 | struct xfrm_address_filter addrfilter = { |
| 1191 | .saddr = filter.xsinfo.saddr, |
| 1192 | .daddr = filter.xsinfo.id.daddr, |
| 1193 | .family = filter.xsinfo.family, |
| 1194 | .splen = filter.id_src_mask, |
| 1195 | .dplen = filter.id_dst_mask, |
| 1196 | }; |
| 1197 | struct { |
| 1198 | struct nlmsghdr n; |
| 1199 | char buf[NLMSG_BUF_SIZE]; |
| 1200 | } req = { |
| 1201 | .n.nlmsg_len = NLMSG_HDRLEN, |
| 1202 | .n.nlmsg_flags = NLM_F_DUMP | NLM_F_REQUEST, |
| 1203 | .n.nlmsg_type = XFRM_MSG_GETSA, |
| 1204 | .n.nlmsg_seq = rth.dump = ++rth.seq, |
| 1205 | }; |
| 1206 | |
| 1207 | if (filter.xsinfo.id.proto) |
| 1208 | addattr8(&req.n, sizeof(req), XFRMA_PROTO, |
| 1209 | filter.xsinfo.id.proto); |
| 1210 | addattr_l(&req.n, sizeof(req), XFRMA_ADDRESS_FILTER, |
| 1211 | &addrfilter, sizeof(addrfilter)); |
| 1212 | |
| 1213 | if (rtnl_send(&rth, (void *)&req, req.n.nlmsg_len) < 0) { |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1214 | perror("Cannot send dump request"); |
| 1215 | exit(1); |
| 1216 | } |
| 1217 | |
Stephen Hemminger | cd70f3f | 2011-12-28 10:37:12 -0800 | [diff] [blame] | 1218 | if (rtnl_dump_filter(&rth, xfrm_state_print, stdout) < 0) { |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1219 | fprintf(stderr, "Dump terminated\n"); |
| 1220 | exit(1); |
| 1221 | } |
| 1222 | } |
| 1223 | |
| 1224 | rtnl_close(&rth); |
| 1225 | |
| 1226 | exit(0); |
| 1227 | } |
| 1228 | |
Stephen Hemminger | d1f28cf | 2013-02-12 11:09:03 -0800 | [diff] [blame] | 1229 | static int print_sadinfo(struct nlmsghdr *n, void *arg) |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1230 | { |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1231 | FILE *fp = (FILE *)arg; |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1232 | __u32 *f = NLMSG_DATA(n); |
| 1233 | struct rtattr *tb[XFRMA_SAD_MAX+1]; |
| 1234 | struct rtattr *rta; |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1235 | __u32 *cnt; |
| 1236 | |
| 1237 | int len = n->nlmsg_len; |
| 1238 | |
| 1239 | len -= NLMSG_LENGTH(sizeof(__u32)); |
| 1240 | if (len < 0) { |
| 1241 | fprintf(stderr, "SADinfo: Wrong len %d\n", len); |
| 1242 | return -1; |
| 1243 | } |
| 1244 | |
| 1245 | rta = XFRMSAPD_RTA(f); |
| 1246 | parse_rtattr(tb, XFRMA_SAD_MAX, rta, len); |
| 1247 | |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 1248 | if (tb[XFRMA_SAD_CNT]) { |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1249 | fprintf(fp, "\t SAD"); |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 1250 | cnt = (__u32 *)RTA_DATA(tb[XFRMA_SAD_CNT]); |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1251 | fprintf(fp, " count %d", *cnt); |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1252 | } else { |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1253 | fprintf(fp, "BAD SAD info returned\n"); |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1254 | return -1; |
| 1255 | } |
| 1256 | |
| 1257 | if (show_stats) { |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 1258 | if (tb[XFRMA_SAD_HINFO]) { |
| 1259 | struct xfrmu_sadhinfo *si; |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1260 | |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 1261 | if (RTA_PAYLOAD(tb[XFRMA_SAD_HINFO]) < sizeof(*si)) { |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1262 | fprintf(fp, "BAD SAD length returned\n"); |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 1263 | return -1; |
| 1264 | } |
Stephen Hemminger | 0612519 | 2014-02-17 10:55:31 -0800 | [diff] [blame] | 1265 | |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 1266 | si = RTA_DATA(tb[XFRMA_SAD_HINFO]); |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1267 | fprintf(fp, " (buckets "); |
| 1268 | fprintf(fp, "count %d", si->sadhcnt); |
| 1269 | fprintf(fp, " Max %d", si->sadhmcnt); |
| 1270 | fprintf(fp, ")"); |
Stephen Hemminger | bdf9e86 | 2007-06-19 16:24:08 -0700 | [diff] [blame] | 1271 | } |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1272 | } |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1273 | fprintf(fp, "\n"); |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1274 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1275 | return 0; |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1276 | } |
| 1277 | |
| 1278 | static int xfrm_sad_getinfo(int argc, char **argv) |
| 1279 | { |
| 1280 | struct rtnl_handle rth; |
| 1281 | struct { |
| 1282 | struct nlmsghdr n; |
| 1283 | __u32 flags; |
| 1284 | char ans[64]; |
| 1285 | } req; |
| 1286 | |
| 1287 | memset(&req, 0, sizeof(req)); |
| 1288 | req.n.nlmsg_len = NLMSG_LENGTH(sizeof(req.flags)); |
| 1289 | req.n.nlmsg_flags = NLM_F_REQUEST; |
| 1290 | req.n.nlmsg_type = XFRM_MSG_GETSADINFO; |
| 1291 | req.flags = 0XFFFFFFFF; |
| 1292 | |
| 1293 | if (rtnl_open_byproto(&rth, 0, NETLINK_XFRM) < 0) |
| 1294 | exit(1); |
| 1295 | |
Stephen Hemminger | c079e12 | 2015-05-27 12:26:14 -0700 | [diff] [blame] | 1296 | if (rtnl_talk(&rth, &req.n, &req.n, sizeof(req)) < 0) |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1297 | exit(2); |
| 1298 | |
Stephen Hemminger | 56f5daa | 2016-03-21 11:52:19 -0700 | [diff] [blame] | 1299 | print_sadinfo(&req.n, (void *)stdout); |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1300 | |
| 1301 | rtnl_close(&rth); |
| 1302 | |
| 1303 | return 0; |
| 1304 | } |
| 1305 | |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1306 | static int xfrm_state_flush(int argc, char **argv) |
org[shemminger]!nakam | bd641cd | 2004-09-28 18:38:35 +0000 | [diff] [blame] | 1307 | { |
| 1308 | struct rtnl_handle rth; |
| 1309 | struct { |
| 1310 | struct nlmsghdr n; |
| 1311 | struct xfrm_usersa_flush xsf; |
| 1312 | } req; |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1313 | char *protop = NULL; |
org[shemminger]!nakam | bd641cd | 2004-09-28 18:38:35 +0000 | [diff] [blame] | 1314 | |
| 1315 | memset(&req, 0, sizeof(req)); |
| 1316 | |
| 1317 | req.n.nlmsg_len = NLMSG_LENGTH(sizeof(req.xsf)); |
| 1318 | req.n.nlmsg_flags = NLM_F_REQUEST; |
| 1319 | req.n.nlmsg_type = XFRM_MSG_FLUSHSA; |
Masahide NAKAMURA | 7ea4f5d | 2006-12-05 19:15:47 +0900 | [diff] [blame] | 1320 | req.xsf.proto = 0; |
org[shemminger]!nakam | bd641cd | 2004-09-28 18:38:35 +0000 | [diff] [blame] | 1321 | |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1322 | while (argc > 0) { |
| 1323 | if (strcmp(*argv, "proto") == 0) { |
| 1324 | int ret; |
| 1325 | |
| 1326 | if (protop) |
| 1327 | duparg("proto", *argv); |
| 1328 | protop = *argv; |
| 1329 | |
| 1330 | NEXT_ARG(); |
| 1331 | |
| 1332 | ret = xfrm_xfrmproto_getbyname(*argv); |
| 1333 | if (ret < 0) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 1334 | invarg("XFRM-PROTO value is invalid", *argv); |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1335 | |
| 1336 | req.xsf.proto = (__u8)ret; |
| 1337 | } else |
| 1338 | invarg("unknown", *argv); |
| 1339 | |
| 1340 | argc--; argv++; |
| 1341 | } |
| 1342 | |
org[shemminger]!nakam | bd641cd | 2004-09-28 18:38:35 +0000 | [diff] [blame] | 1343 | if (rtnl_open_byproto(&rth, 0, NETLINK_XFRM) < 0) |
| 1344 | exit(1); |
| 1345 | |
| 1346 | if (show_stats > 1) |
David Ward | e8740e4 | 2013-03-25 04:23:19 +0000 | [diff] [blame] | 1347 | fprintf(stderr, "Flush state with XFRM-PROTO value \"%s\"\n", |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1348 | strxf_xfrmproto(req.xsf.proto)); |
org[shemminger]!nakam | bd641cd | 2004-09-28 18:38:35 +0000 | [diff] [blame] | 1349 | |
Stephen Hemminger | c079e12 | 2015-05-27 12:26:14 -0700 | [diff] [blame] | 1350 | if (rtnl_talk(&rth, &req.n, NULL, 0) < 0) |
org[shemminger]!nakam | bd641cd | 2004-09-28 18:38:35 +0000 | [diff] [blame] | 1351 | exit(2); |
| 1352 | |
| 1353 | rtnl_close(&rth); |
| 1354 | |
| 1355 | return 0; |
| 1356 | } |
| 1357 | |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1358 | int do_xfrm_state(int argc, char **argv) |
| 1359 | { |
| 1360 | if (argc < 1) |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1361 | return xfrm_state_list_or_deleteall(0, NULL, 0); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1362 | |
| 1363 | if (matches(*argv, "add") == 0) |
| 1364 | return xfrm_state_modify(XFRM_MSG_NEWSA, 0, |
| 1365 | argc-1, argv+1); |
| 1366 | if (matches(*argv, "update") == 0) |
| 1367 | return xfrm_state_modify(XFRM_MSG_UPDSA, 0, |
| 1368 | argc-1, argv+1); |
linux-ipv6.org!nakam | fb7399b | 2005-03-22 16:13:21 +0000 | [diff] [blame] | 1369 | if (matches(*argv, "allocspi") == 0) |
| 1370 | return xfrm_state_allocspi(argc-1, argv+1); |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1371 | if (matches(*argv, "delete") == 0) |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1372 | return xfrm_state_get_or_delete(argc-1, argv+1, 1); |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1373 | if (matches(*argv, "deleteall") == 0 || matches(*argv, "delall") == 0) |
| 1374 | return xfrm_state_list_or_deleteall(argc-1, argv+1, 1); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1375 | if (matches(*argv, "list") == 0 || matches(*argv, "show") == 0 |
| 1376 | || matches(*argv, "lst") == 0) |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1377 | return xfrm_state_list_or_deleteall(argc-1, argv+1, 0); |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1378 | if (matches(*argv, "get") == 0) |
| 1379 | return xfrm_state_get_or_delete(argc-1, argv+1, 0); |
shemminger | 9bec1a4 | 2005-06-07 21:58:25 +0000 | [diff] [blame] | 1380 | if (matches(*argv, "flush") == 0) |
| 1381 | return xfrm_state_flush(argc-1, argv+1); |
jamal | 0bb4a4c | 2007-05-03 19:09:41 -0400 | [diff] [blame] | 1382 | if (matches(*argv, "count") == 0) { |
| 1383 | return xfrm_sad_getinfo(argc, argv); |
| 1384 | } |
net[shemminger]!shemminger | c769987 | 2004-07-07 17:05:56 +0000 | [diff] [blame] | 1385 | if (matches(*argv, "help") == 0) |
| 1386 | usage(); |
| 1387 | fprintf(stderr, "Command \"%s\" is unknown, try \"ip xfrm state help\".\n", *argv); |
| 1388 | exit(-1); |
| 1389 | } |