diff options
author | Ansis Atteka <aatteka@nicira.com> | 2013-09-19 00:29:53 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2013-09-19 20:11:15 +0200 |
commit | 703133de331a7a7df47f31fb9de51dc6f68a9de8 (patch) | |
tree | 0c6c49e15c9461cd3a563d17062a866d2fafd6fa /net/ipv4/xfrm4_mode_tunnel.c | |
parent | ip: use ip_hdr() in __ip_make_skb() to retrieve IP header (diff) | |
download | linux-703133de331a7a7df47f31fb9de51dc6f68a9de8.tar.xz linux-703133de331a7a7df47f31fb9de51dc6f68a9de8.zip |
ip: generate unique IP identificator if local fragmentation is allowed
If local fragmentation is allowed, then ip_select_ident() and
ip_select_ident_more() need to generate unique IDs to ensure
correct defragmentation on the peer.
For example, if IPsec (tunnel mode) has to encrypt large skbs
that have local_df bit set, then all IP fragments that belonged
to different ESP datagrams would have used the same identificator.
If one of these IP fragments would get lost or reordered, then
peer could possibly stitch together wrong IP fragments that did
not belong to the same datagram. This would lead to a packet loss
or data corruption.
Signed-off-by: Ansis Atteka <aatteka@nicira.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv4/xfrm4_mode_tunnel.c')
-rw-r--r-- | net/ipv4/xfrm4_mode_tunnel.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/net/ipv4/xfrm4_mode_tunnel.c b/net/ipv4/xfrm4_mode_tunnel.c index eb1dd4d643f2..b5663c37f089 100644 --- a/net/ipv4/xfrm4_mode_tunnel.c +++ b/net/ipv4/xfrm4_mode_tunnel.c @@ -117,7 +117,7 @@ static int xfrm4_mode_tunnel_output(struct xfrm_state *x, struct sk_buff *skb) top_iph->frag_off = (flags & XFRM_STATE_NOPMTUDISC) ? 0 : (XFRM_MODE_SKB_CB(skb)->frag_off & htons(IP_DF)); - ip_select_ident(top_iph, dst->child, NULL); + ip_select_ident(skb, dst->child, NULL); top_iph->ttl = ip4_dst_hoplimit(dst->child); |