* [PATCH v2 net 0/5] icmp: account for NAT when sending icmps from ndo layer
@ 2020-02-10 14:14 Jason A. Donenfeld
0 siblings, 0 replies; only message in thread
From: Jason A. Donenfeld @ 2020-02-10 14:14 UTC (permalink / raw)
To: netdev, davem; +Cc: Jason A. Donenfeld, netfilter-devel
The ICMP routines use the source address for two reasons:
1. Rate-limiting ICMP transmissions based on source address, so
that one source address cannot provoke a flood of replies. If
the source address is wrong, the rate limiting will be
2. Choosing the interface and hence new source address of the
generated ICMP packet. If the original packet source address
is wrong, ICMP replies will be sent from the wrong source
address, resulting in either a misdelivery, infoleak, or just
general network admin confusion.
Most of the time, the icmp_send and icmpv6_send routines can just reach
down into the skb's IP header to determine the saddr. However, if
icmp_send or icmpv6_send is being called from a network device driver --
there are a few in the tree -- then it's possible that by the time
icmp_send or icmpv6_send looks at the packet, the packet's source
address has already been transformed by SNAT or MASQUERADE or some other
transformation that CONNTRACK knows about. In this case, the packet's
source address is most certainly the *wrong* source address to be used
for the purpose of ICMP replies.
Rather, the source address we want to use for ICMP replies is the
original one, from before the transformation occurred.
Fortunately, it's very easy to just ask CONNTRACK if it knows about this
packet, and if so, how to fix it up. The saddr is the only field in the
header we need to fix up, for the purposes of the subsequent processing
in the icmp_send and icmpv6_send functions, so we do the lookup very
early on, so that the rest of the ICMP machinery can progress as usual.
- icmpv6 takes subtly different types than icmpv4, like u32 instead of be32,
u8 instead of int.
- Since we're technically writing to the skb, we need to make sure it's not
a shared one [Dave, 2017].
- Restore the original skb data after icmp_send returns. All current users
are freeing the packet right after, so it doesn't matter, but future users
- Remove superfluous route lookup in sunvnet [Dave].
- Use NF_NAT instead of NF_CONNTRACK for condition [Florian].
- Include this cover letter [Dave].
Jason A. Donenfeld (5):
icmp: introduce helper for NAT'd source address in network device
gtp: use icmp_ndo_send helper
sunvnet: use icmp_ndo_send helper
wireguard: use icmp_ndo_send helper
xfrm: interface: use icmp_ndo_send helper
drivers/net/ethernet/sun/sunvnet_common.c | 23 +++--------------
drivers/net/gtp.c | 4 +--
drivers/net/wireguard/device.c | 4 +--
include/linux/icmpv6.h | 6 +++++
include/net/icmp.h | 6 +++++
net/ipv4/icmp.c | 29 ++++++++++++++++++++++
net/ipv6/ip6_icmp.c | 30 +++++++++++++++++++++++
net/xfrm/xfrm_interface.c | 6 ++---
8 files changed, 82 insertions(+), 26 deletions(-)
^ permalink raw reply [flat|nested] only message in thread
only message in thread, back to index
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-02-10 14:14 [PATCH v2 net 0/5] icmp: account for NAT when sending icmps from ndo layer Jason A. Donenfeld
Netfilter-Devel Archive on lore.kernel.org
Archives are clonable:
git clone --mirror https://lore.kernel.org/netfilter-devel/0 netfilter-devel/git/0.git
# If you have public-inbox 1.1+ installed, you may
# initialize and index your mirror using the following commands:
public-inbox-init -V2 netfilter-devel netfilter-devel/ https://lore.kernel.org/netfilter-devel \
Example config snippet for mirrors
Newsgroup available over NNTP:
AGPL code for this site: git clone https://public-inbox.org/public-inbox.git