VirtualBox

source: vbox/trunk/src/VBox/Runtime/common/checksum/ipv4.cpp

Last change on this file was 98103, checked in by vboxsync, 16 months ago

Copyright year updates by scm.

  • Property svn:eol-style set to native
  • Property svn:keywords set to Author Date Id Revision
File size: 30.0 KB
Line 
1/* $Id: ipv4.cpp 98103 2023-01-17 14:15:46Z vboxsync $ */
2/** @file
3 * IPRT - IPv4 Checksum calculation and validation.
4 */
5
6/*
7 * Copyright (C) 2008-2023 Oracle and/or its affiliates.
8 *
9 * This file is part of VirtualBox base platform packages, as
10 * available from https://www.virtualbox.org.
11 *
12 * This program is free software; you can redistribute it and/or
13 * modify it under the terms of the GNU General Public License
14 * as published by the Free Software Foundation, in version 3 of the
15 * License.
16 *
17 * This program is distributed in the hope that it will be useful, but
18 * WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
20 * General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License
23 * along with this program; if not, see <https://www.gnu.org/licenses>.
24 *
25 * The contents of this file may alternatively be used under the terms
26 * of the Common Development and Distribution License Version 1.0
27 * (CDDL), a copy of it is provided in the "COPYING.CDDL" file included
28 * in the VirtualBox distribution, in which case the provisions of the
29 * CDDL are applicable instead of those of the GPL.
30 *
31 * You may elect to license modified versions of this file under the
32 * terms and conditions of either the GPL or the CDDL or both.
33 *
34 * SPDX-License-Identifier: GPL-3.0-only OR CDDL-1.0
35 */
36
37
38/*********************************************************************************************************************************
39* Header Files *
40*********************************************************************************************************************************/
41#include <iprt/net.h>
42#include "internal/iprt.h"
43
44#include <iprt/asm.h>
45#include <iprt/assert.h>
46
47
48/**
49 * Calculates the checksum of the IPv4 header.
50 *
51 * @returns Checksum (network endian).
52 * @param pIpHdr Pointer to the IPv4 header to checksum, network endian (big).
53 * Assumes the caller already checked the minimum size requirement.
54 */
55RTDECL(uint16_t) RTNetIPv4HdrChecksum(PCRTNETIPV4 pIpHdr)
56{
57 uint16_t const *paw = (uint16_t const *)pIpHdr;
58 uint32_t u32Sum = paw[0] /* ip_hl */
59 + paw[1] /* ip_len */
60 + paw[2] /* ip_id */
61 + paw[3] /* ip_off */
62 + paw[4] /* ip_ttl */
63 /*+ paw[5] == 0 */ /* ip_sum */
64 + paw[6] /* ip_src */
65 + paw[7] /* ip_src:16 */
66 + paw[8] /* ip_dst */
67 + paw[9]; /* ip_dst:16 */
68 /* any options */
69 if (pIpHdr->ip_hl > 20 / 4)
70 {
71 /* this is a bit insane... (identical to the TCP header) */
72 switch (pIpHdr->ip_hl)
73 {
74 case 6: u32Sum += paw[10] + paw[11]; break;
75 case 7: u32Sum += paw[10] + paw[11] + paw[12] + paw[13]; break;
76 case 8: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15]; break;
77 case 9: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17]; break;
78 case 10: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19]; break;
79 case 11: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21]; break;
80 case 12: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23]; break;
81 case 13: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23] + paw[24] + paw[25]; break;
82 case 14: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23] + paw[24] + paw[25] + paw[26] + paw[27]; break;
83 case 15: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23] + paw[24] + paw[25] + paw[26] + paw[27] + paw[28] + paw[29]; break;
84 default:
85 AssertFailed();
86 }
87 }
88
89 /* 16-bit one complement fun */
90 u32Sum = (u32Sum >> 16) + (u32Sum & 0xffff); /* hi + low words */
91 u32Sum += u32Sum >> 16; /* carry */
92 return (uint16_t)~u32Sum;
93}
94RT_EXPORT_SYMBOL(RTNetIPv4HdrChecksum);
95
96
97/**
98 * Verifies the header version, header size, packet size, and header checksum
99 * of the specified IPv4 header.
100 *
101 * @returns true if valid, false if invalid.
102 * @param pIpHdr Pointer to the IPv4 header to validate. Network endian (big).
103 * @param cbHdrMax The max header size, or the max size of what pIpHdr points
104 * to if you like. Note that an IPv4 header can be up to 60 bytes.
105 * @param cbPktMax The max IP packet size, IP header and payload. This doesn't have
106 * to be mapped following pIpHdr.
107 * @param fChecksum Whether to validate the checksum (GSO).
108 */
109RTDECL(bool) RTNetIPv4IsHdrValid(PCRTNETIPV4 pIpHdr, size_t cbHdrMax, size_t cbPktMax, bool fChecksum)
110{
111 /*
112 * The header fields.
113 */
114 Assert(cbPktMax >= cbHdrMax);
115 if (RT_UNLIKELY(cbHdrMax < RTNETIPV4_MIN_LEN))
116 return false;
117 if (RT_UNLIKELY(pIpHdr->ip_hl * 4 < RTNETIPV4_MIN_LEN))
118 return false;
119 if (RT_UNLIKELY((size_t)pIpHdr->ip_hl * 4 > cbHdrMax))
120 {
121 Assert((size_t)pIpHdr->ip_hl * 4 > cbPktMax); /* You'll hit this if you mapped/copy too little of the header! */
122 return false;
123 }
124 if (RT_UNLIKELY(pIpHdr->ip_v != 4))
125 return false;
126 if (RT_UNLIKELY(RT_BE2H_U16(pIpHdr->ip_len) > cbPktMax))
127 return false;
128
129 /*
130 * The header checksum if requested.
131 */
132 if (fChecksum)
133 {
134 uint16_t u16Sum = RTNetIPv4HdrChecksum(pIpHdr);
135 if (RT_UNLIKELY(pIpHdr->ip_sum != u16Sum))
136 return false;
137 }
138 return true;
139}
140RT_EXPORT_SYMBOL(RTNetIPv4IsHdrValid);
141
142
143/**
144 * Calculates the checksum of a pseudo header given an IPv4 header [inlined].
145 *
146 * @returns 32-bit intermediary checksum value.
147 * @param pIpHdr The IP header (network endian (big)).
148 */
149DECLINLINE(uint32_t) rtNetIPv4PseudoChecksum(PCRTNETIPV4 pIpHdr)
150{
151 uint16_t cbPayload = RT_BE2H_U16(pIpHdr->ip_len) - pIpHdr->ip_hl * 4;
152 uint32_t u32Sum = pIpHdr->ip_src.au16[0]
153 + pIpHdr->ip_src.au16[1]
154 + pIpHdr->ip_dst.au16[0]
155 + pIpHdr->ip_dst.au16[1]
156#ifdef RT_BIG_ENDIAN
157 + pIpHdr->ip_p
158#else
159 + ((uint32_t)pIpHdr->ip_p << 8)
160#endif
161 + RT_H2BE_U16(cbPayload);
162 return u32Sum;
163}
164
165
166/**
167 * Calculates the checksum of a pseudo header given an IPv4 header.
168 *
169 * @returns 32-bit intermediary checksum value.
170 * @param pIpHdr The IP header (network endian (big)).
171 */
172RTDECL(uint32_t) RTNetIPv4PseudoChecksum(PCRTNETIPV4 pIpHdr)
173{
174 return rtNetIPv4PseudoChecksum(pIpHdr);
175}
176RT_EXPORT_SYMBOL(RTNetIPv4PseudoChecksum);
177
178
179/**
180 * Calculates the checksum of a pseudo header given the individual components.
181 *
182 * @returns 32-bit intermediary checksum value.
183 * @param SrcAddr The source address in host endian.
184 * @param DstAddr The destination address in host endian.
185 * @param bProtocol The protocol number.
186 * @param cbPkt The packet size (host endian of course) (no IPv4 header).
187 */
188RTDECL(uint32_t) RTNetIPv4PseudoChecksumBits(RTNETADDRIPV4 SrcAddr, RTNETADDRIPV4 DstAddr, uint8_t bProtocol, uint16_t cbPkt)
189{
190 uint32_t u32Sum = RT_H2BE_U16(SrcAddr.au16[0])
191 + RT_H2BE_U16(SrcAddr.au16[1])
192 + RT_H2BE_U16(DstAddr.au16[0])
193 + RT_H2BE_U16(DstAddr.au16[1])
194#ifdef RT_BIG_ENDIAN
195 + bProtocol
196#else
197 + ((uint32_t)bProtocol << 8)
198#endif
199 + RT_H2BE_U16(cbPkt);
200 return u32Sum;
201}
202RT_EXPORT_SYMBOL(RTNetIPv4PseudoChecksumBits);
203
204
205/**
206 * Adds the checksum of the UDP header to the intermediate checksum value [inlined].
207 *
208 * @returns 32-bit intermediary checksum value.
209 * @param pUdpHdr Pointer to the UDP header to checksum, network endian (big).
210 * @param u32Sum The 32-bit intermediate checksum value.
211 */
212DECLINLINE(uint32_t) rtNetIPv4AddUDPChecksum(PCRTNETUDP pUdpHdr, uint32_t u32Sum)
213{
214 u32Sum += pUdpHdr->uh_sport
215 + pUdpHdr->uh_dport
216 /*+ pUdpHdr->uh_sum = 0 */
217 + pUdpHdr->uh_ulen;
218 return u32Sum;
219}
220
221
222/**
223 * Adds the checksum of the UDP header to the intermediate checksum value.
224 *
225 * @returns 32-bit intermediary checksum value.
226 * @param pUdpHdr Pointer to the UDP header to checksum, network endian (big).
227 * @param u32Sum The 32-bit intermediate checksum value.
228 */
229RTDECL(uint32_t) RTNetIPv4AddUDPChecksum(PCRTNETUDP pUdpHdr, uint32_t u32Sum)
230{
231 return rtNetIPv4AddUDPChecksum(pUdpHdr, u32Sum);
232}
233RT_EXPORT_SYMBOL(RTNetIPv4AddUDPChecksum);
234
235
236/**
237 * Adds the checksum of the TCP header to the intermediate checksum value [inlined].
238 *
239 * @returns 32-bit intermediary checksum value.
240 * @param pTcpHdr Pointer to the TCP header to checksum, network
241 * endian (big). Assumes the caller has already validate
242 * it and made sure the entire header is present.
243 * @param u32Sum The 32-bit intermediate checksum value.
244 */
245DECLINLINE(uint32_t) rtNetIPv4AddTCPChecksum(PCRTNETTCP pTcpHdr, uint32_t u32Sum)
246{
247 uint16_t const *paw = (uint16_t const *)pTcpHdr;
248 u32Sum += paw[0] /* th_sport */
249 + paw[1] /* th_dport */
250 + paw[2] /* th_seq */
251 + paw[3] /* th_seq:16 */
252 + paw[4] /* th_ack */
253 + paw[5] /* th_ack:16 */
254 + paw[6] /* th_off, th_x2, th_flags */
255 + paw[7] /* th_win */
256 /*+ paw[8] == 0 */ /* th_sum */
257 + paw[9]; /* th_urp */
258 if (pTcpHdr->th_off > RTNETTCP_MIN_LEN / 4)
259 {
260 /* this is a bit insane... (identical to the IPv4 header) */
261 switch (pTcpHdr->th_off)
262 {
263 case 6: u32Sum += paw[10] + paw[11]; break;
264 case 7: u32Sum += paw[10] + paw[11] + paw[12] + paw[13]; break;
265 case 8: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15]; break;
266 case 9: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17]; break;
267 case 10: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19]; break;
268 case 11: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21]; break;
269 case 12: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23]; break;
270 case 13: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23] + paw[24] + paw[25]; break;
271 case 14: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23] + paw[24] + paw[25] + paw[26] + paw[27]; break;
272 case 15: u32Sum += paw[10] + paw[11] + paw[12] + paw[13] + paw[14] + paw[15] + paw[16] + paw[17] + paw[18] + paw[19] + paw[20] + paw[21] + paw[22] + paw[23] + paw[24] + paw[25] + paw[26] + paw[27] + paw[28] + paw[29]; break;
273 default:
274 AssertFailed();
275 }
276 }
277
278 return u32Sum;
279}
280
281
282/**
283 * Adds the checksum of the TCP header to the intermediate checksum value.
284 *
285 * @returns 32-bit intermediary checksum value.
286 * @param pTcpHdr Pointer to the TCP header to checksum, network
287 * endian (big). Assumes the caller has already validate
288 * it and made sure the entire header is present.
289 * @param u32Sum The 32-bit intermediate checksum value.
290 */
291RTDECL(uint32_t) RTNetIPv4AddTCPChecksum(PCRTNETTCP pTcpHdr, uint32_t u32Sum)
292{
293 return rtNetIPv4AddTCPChecksum(pTcpHdr, u32Sum);
294}
295RT_EXPORT_SYMBOL(RTNetIPv4AddTCPChecksum);
296
297
298/**
299 * Adds the checksum of the specified data segment to the intermediate checksum value [inlined].
300 *
301 * @returns 32-bit intermediary checksum value.
302 * @param pvData Pointer to the data that should be checksummed.
303 * @param cbData The number of bytes to checksum.
304 * @param u32Sum The 32-bit intermediate checksum value.
305 * @param pfOdd This is used to keep track of odd bits, initialize to false
306 * when starting to checksum the data (aka text) after a TCP
307 * or UDP header (data never start at an odd offset).
308 */
309DECLINLINE(uint32_t) rtNetIPv4AddDataChecksum(void const *pvData, size_t cbData, uint32_t u32Sum, bool *pfOdd)
310{
311 if (*pfOdd)
312 {
313#ifdef RT_BIG_ENDIAN
314 /* there was an odd byte in the previous chunk, add the lower byte. */
315 u32Sum += *(uint8_t *)pvData;
316#else
317 /* there was an odd byte in the previous chunk, add the upper byte. */
318 u32Sum += (uint32_t)*(uint8_t *)pvData << 8;
319#endif
320 /* skip the byte. */
321 cbData--;
322 if (!cbData)
323 return u32Sum;
324 pvData = (uint8_t const *)pvData + 1;
325 }
326
327 /* iterate the data. */
328 uint16_t const *pw = (uint16_t const *)pvData;
329 while (cbData > 1)
330 {
331 u32Sum += *pw;
332 pw++;
333 cbData -= 2;
334 }
335
336 /* handle odd byte. */
337 if (cbData)
338 {
339#ifdef RT_BIG_ENDIAN
340 u32Sum += (uint32_t)*(uint8_t *)pw << 8;
341#else
342 u32Sum += *(uint8_t *)pw;
343#endif
344 *pfOdd = true;
345 }
346 else
347 *pfOdd = false;
348 return u32Sum;
349}
350
351/**
352 * Adds the checksum of the specified data segment to the intermediate checksum value.
353 *
354 * @returns 32-bit intermediary checksum value.
355 * @param pvData The data bits to checksum.
356 * @param cbData The number of bytes to checksum.
357 * @param u32Sum The 32-bit intermediate checksum value.
358 * @param pfOdd This is used to keep track of odd bits, initialize to false
359 * when starting to checksum the data (aka text) after a TCP
360 * or UDP header (data never start at an odd offset).
361 */
362RTDECL(uint32_t) RTNetIPv4AddDataChecksum(void const *pvData, size_t cbData, uint32_t u32Sum, bool *pfOdd)
363{
364 return rtNetIPv4AddDataChecksum(pvData, cbData, u32Sum, pfOdd);
365}
366RT_EXPORT_SYMBOL(RTNetIPv4AddDataChecksum);
367
368
369/**
370 * Finalizes a IPv4 checksum [inlined].
371 *
372 * @returns The checksum (network endian).
373 * @param u32Sum The 32-bit intermediate checksum value.
374 */
375DECLINLINE(uint16_t) rtNetIPv4FinalizeChecksum(uint32_t u32Sum)
376{
377 /* 16-bit one complement fun */
378 u32Sum = (u32Sum >> 16) + (u32Sum & 0xffff); /* hi + low words */
379 u32Sum += u32Sum >> 16; /* carry */
380 return (uint16_t)~u32Sum;
381}
382
383
384/**
385 * Finalizes a IPv4 checksum.
386 *
387 * @returns The checksum (network endian).
388 * @param u32Sum The 32-bit intermediate checksum value.
389 */
390RTDECL(uint16_t) RTNetIPv4FinalizeChecksum(uint32_t u32Sum)
391{
392 return rtNetIPv4FinalizeChecksum(u32Sum);
393}
394RT_EXPORT_SYMBOL(RTNetIPv4FinalizeChecksum);
395
396
397/**
398 * Calculates the checksum for the UDP header given the UDP header w/ payload
399 * and the checksum of the pseudo header.
400 *
401 * @returns The checksum (network endian).
402 * @param u32Sum The checksum of the pseudo header. See
403 * RTNetIPv4PseudoChecksum and RTNetIPv6PseudoChecksum.
404 * @param pUdpHdr Pointer to the UDP header and the payload, in
405 * network endian (big). We use the uh_ulen field to
406 * figure out how much to checksum.
407 */
408RTDECL(uint16_t) RTNetUDPChecksum(uint32_t u32Sum, PCRTNETUDP pUdpHdr)
409{
410 bool fOdd;
411 u32Sum = rtNetIPv4AddUDPChecksum(pUdpHdr, u32Sum);
412 fOdd = false;
413 u32Sum = rtNetIPv4AddDataChecksum(pUdpHdr + 1, RT_BE2H_U16(pUdpHdr->uh_ulen) - sizeof(*pUdpHdr), u32Sum, &fOdd);
414 return rtNetIPv4FinalizeChecksum(u32Sum);
415}
416RT_EXPORT_SYMBOL(RTNetUDPChecksum);
417
418
419/**
420 * Calculates the checksum for the UDP header given the IP header,
421 * UDP header and payload.
422 *
423 * @returns The checksum (network endian).
424 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
425 * @param pUdpHdr Pointer to the UDP header, in network endian (big).
426 * @param pvData Pointer to the UDP payload. The size is taken from the
427 * UDP header and the caller is supposed to have validated
428 * this before calling.
429 */
430RTDECL(uint16_t) RTNetIPv4UDPChecksum(PCRTNETIPV4 pIpHdr, PCRTNETUDP pUdpHdr, void const *pvData)
431{
432 bool fOdd;
433 uint32_t u32Sum = rtNetIPv4PseudoChecksum(pIpHdr);
434 u32Sum = rtNetIPv4AddUDPChecksum(pUdpHdr, u32Sum);
435 fOdd = false;
436 u32Sum = rtNetIPv4AddDataChecksum(pvData, RT_BE2H_U16(pUdpHdr->uh_ulen) - sizeof(*pUdpHdr), u32Sum, &fOdd);
437 return rtNetIPv4FinalizeChecksum(u32Sum);
438}
439RT_EXPORT_SYMBOL(RTNetIPv4UDPChecksum);
440
441
442/**
443 * Simple verification of an UDP packet size.
444 *
445 * @returns true if valid, false if invalid.
446 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
447 * This is assumed to be valid and the minimum size being mapped.
448 * @param pUdpHdr Pointer to the UDP header, in network endian (big).
449 * @param cbPktMax The max UDP packet size, UDP header and payload (data).
450 */
451DECLINLINE(bool) rtNetIPv4IsUDPSizeValid(PCRTNETIPV4 pIpHdr, PCRTNETUDP pUdpHdr, size_t cbPktMax)
452{
453 /*
454 * Size validation.
455 */
456 size_t cb;
457 if (RT_UNLIKELY(cbPktMax < RTNETUDP_MIN_LEN))
458 return false;
459 cb = RT_BE2H_U16(pUdpHdr->uh_ulen);
460 if (RT_UNLIKELY(cb > cbPktMax))
461 return false;
462 if (RT_UNLIKELY(cb > (size_t)(RT_BE2H_U16(pIpHdr->ip_len) - pIpHdr->ip_hl * 4)))
463 return false;
464 return true;
465}
466
467
468/**
469 * Simple verification of an UDP packet size.
470 *
471 * @returns true if valid, false if invalid.
472 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
473 * This is assumed to be valid and the minimum size being mapped.
474 * @param pUdpHdr Pointer to the UDP header, in network endian (big).
475 * @param cbPktMax The max UDP packet size, UDP header and payload (data).
476 */
477RTDECL(bool) RTNetIPv4IsUDPSizeValid(PCRTNETIPV4 pIpHdr, PCRTNETUDP pUdpHdr, size_t cbPktMax)
478{
479 return rtNetIPv4IsUDPSizeValid(pIpHdr, pUdpHdr, cbPktMax);
480}
481RT_EXPORT_SYMBOL(RTNetIPv4IsUDPSizeValid);
482
483
484/**
485 * Simple verification of an UDP packet (size + checksum).
486 *
487 * @returns true if valid, false if invalid.
488 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
489 * This is assumed to be valid and the minimum size being mapped.
490 * @param pUdpHdr Pointer to the UDP header, in network endian (big).
491 * @param pvData Pointer to the data, assuming it's one single segment
492 * and that cbPktMax - sizeof(RTNETUDP) is mapped here.
493 * @param cbPktMax The max UDP packet size, UDP header and payload (data).
494 * @param fChecksum Whether to validate the checksum (GSO).
495 */
496RTDECL(bool) RTNetIPv4IsUDPValid(PCRTNETIPV4 pIpHdr, PCRTNETUDP pUdpHdr, void const *pvData, size_t cbPktMax, bool fChecksum)
497{
498 if (RT_UNLIKELY(!rtNetIPv4IsUDPSizeValid(pIpHdr, pUdpHdr, cbPktMax)))
499 return false;
500 if (fChecksum && pUdpHdr->uh_sum)
501 {
502 uint16_t u16Sum = RTNetIPv4UDPChecksum(pIpHdr, pUdpHdr, pvData);
503 if (RT_UNLIKELY(pUdpHdr->uh_sum != u16Sum))
504 return false;
505 }
506 return true;
507}
508RT_EXPORT_SYMBOL(RTNetIPv4IsUDPValid);
509
510
511/**
512 * Calculates the checksum for the TCP header given the IP header,
513 * TCP header and payload.
514 *
515 * @returns The checksum (network endian).
516 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
517 * @param pTcpHdr Pointer to the TCP header, in network endian (big).
518 * @param pvData Pointer to the TCP payload. The size is derived from
519 * the two headers and the caller is supposed to have
520 * validated this before calling. If NULL, we assume
521 * the data follows immediately after the TCP header.
522 */
523RTDECL(uint16_t) RTNetIPv4TCPChecksum(PCRTNETIPV4 pIpHdr, PCRTNETTCP pTcpHdr, void const *pvData)
524{
525 bool fOdd;
526 size_t cbData;
527 uint32_t u32Sum = rtNetIPv4PseudoChecksum(pIpHdr);
528 u32Sum = rtNetIPv4AddTCPChecksum(pTcpHdr, u32Sum);
529 fOdd = false;
530 cbData = RT_BE2H_U16(pIpHdr->ip_len) - pIpHdr->ip_hl * 4 - pTcpHdr->th_off * 4;
531 u32Sum = rtNetIPv4AddDataChecksum(pvData ? pvData : (uint8_t const *)pTcpHdr + pTcpHdr->th_off * 4,
532 cbData, u32Sum, &fOdd);
533 return rtNetIPv4FinalizeChecksum(u32Sum);
534}
535RT_EXPORT_SYMBOL(RTNetIPv4TCPChecksum);
536
537
538/**
539 * Calculates the checksum for the TCP header given the TCP header, payload and
540 * the checksum of the pseudo header.
541 *
542 * This is not specific to IPv4.
543 *
544 * @returns The checksum (network endian).
545 * @param u32Sum The checksum of the pseudo header. See
546 * RTNetIPv4PseudoChecksum and RTNetIPv6PseudoChecksum.
547 * @param pTcpHdr Pointer to the TCP header, in network endian (big).
548 * @param pvData Pointer to the TCP payload.
549 * @param cbData The size of the TCP payload.
550 */
551RTDECL(uint16_t) RTNetTCPChecksum(uint32_t u32Sum, PCRTNETTCP pTcpHdr, void const *pvData, size_t cbData)
552{
553 bool fOdd;
554 u32Sum = rtNetIPv4AddTCPChecksum(pTcpHdr, u32Sum);
555 fOdd = false;
556 u32Sum = rtNetIPv4AddDataChecksum(pvData, cbData, u32Sum, &fOdd);
557 return rtNetIPv4FinalizeChecksum(u32Sum);
558}
559RT_EXPORT_SYMBOL(RTNetTCPChecksum);
560
561
562/**
563 * Verification of a TCP header.
564 *
565 * @returns true if valid, false if invalid.
566 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
567 * This is assumed to be valid and the minimum size being mapped.
568 * @param pTcpHdr Pointer to the TCP header, in network endian (big).
569 * @param cbHdrMax The max TCP header size (what pTcpHdr points to).
570 * @param cbPktMax The max TCP packet size, TCP header and payload (data).
571 */
572DECLINLINE(bool) rtNetIPv4IsTCPSizeValid(PCRTNETIPV4 pIpHdr, PCRTNETTCP pTcpHdr, size_t cbHdrMax, size_t cbPktMax)
573{
574 size_t cbTcpHdr;
575 size_t cbTcp;
576
577 Assert(cbPktMax >= cbHdrMax);
578
579 /*
580 * Size validations.
581 */
582 if (RT_UNLIKELY(cbPktMax < RTNETTCP_MIN_LEN))
583 return false;
584 cbTcpHdr = pTcpHdr->th_off * 4;
585 if (RT_UNLIKELY(cbTcpHdr > cbHdrMax))
586 return false;
587 cbTcp = RT_BE2H_U16(pIpHdr->ip_len) - pIpHdr->ip_hl * 4;
588 if (RT_UNLIKELY(cbTcp > cbPktMax))
589 return false;
590 return true;
591}
592
593
594/**
595 * Simple verification of an TCP packet size.
596 *
597 * @returns true if valid, false if invalid.
598 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
599 * This is assumed to be valid and the minimum size being mapped.
600 * @param pTcpHdr Pointer to the TCP header, in network endian (big).
601 * @param cbHdrMax The max TCP header size (what pTcpHdr points to).
602 * @param cbPktMax The max TCP packet size, TCP header and payload (data).
603 */
604RTDECL(bool) RTNetIPv4IsTCPSizeValid(PCRTNETIPV4 pIpHdr, PCRTNETTCP pTcpHdr, size_t cbHdrMax, size_t cbPktMax)
605{
606 return rtNetIPv4IsTCPSizeValid(pIpHdr, pTcpHdr, cbHdrMax, cbPktMax);
607}
608RT_EXPORT_SYMBOL(RTNetIPv4IsTCPSizeValid);
609
610
611/**
612 * Simple verification of an TCP packet (size + checksum).
613 *
614 * @returns true if valid, false if invalid.
615 * @param pIpHdr Pointer to the IPv4 header, in network endian (big).
616 * This is assumed to be valid and the minimum size being mapped.
617 * @param pTcpHdr Pointer to the TCP header, in network endian (big).
618 * @param cbHdrMax The max TCP header size (what pTcpHdr points to).
619 * @param pvData Pointer to the data, assuming it's one single segment
620 * and that cbPktMax - sizeof(RTNETTCP) is mapped here.
621 * If NULL then we assume the data follows immediately after
622 * the TCP header.
623 * @param cbPktMax The max TCP packet size, TCP header and payload (data).
624 * @param fChecksum Whether to validate the checksum (GSO).
625 */
626RTDECL(bool) RTNetIPv4IsTCPValid(PCRTNETIPV4 pIpHdr, PCRTNETTCP pTcpHdr, size_t cbHdrMax, void const *pvData, size_t cbPktMax,
627 bool fChecksum)
628{
629 if (RT_UNLIKELY(!rtNetIPv4IsTCPSizeValid(pIpHdr, pTcpHdr, cbHdrMax, cbPktMax)))
630 return false;
631 if (fChecksum)
632 {
633 uint16_t u16Sum = RTNetIPv4TCPChecksum(pIpHdr, pTcpHdr, pvData);
634 if (RT_UNLIKELY(pTcpHdr->th_sum != u16Sum))
635 return false;
636 }
637 return true;
638}
639RT_EXPORT_SYMBOL(RTNetIPv4IsTCPValid);
640
641
642/**
643 * Minimal validation of a DHCP packet.
644 *
645 * This will fail on BOOTP packets (if sufficient data is supplied).
646 * It will not verify the source and destination ports, that's the
647 * caller's responsibility.
648 *
649 * This function will ASSUME that the hardware type is ethernet
650 * and use that for htype/hlen validation.
651 *
652 * @returns true if valid, false if invalid.
653 * @param pUdpHdr Pointer to the UDP header, in network endian (big).
654 * This is assumed to be valid and fully mapped.
655 * @param pDhcp Pointer to the DHCP packet.
656 * This might not be the entire thing, see cbDhcp.
657 * @param cbDhcp The number of valid bytes that pDhcp points to.
658 * @param pMsgType Where to store the message type (if found).
659 * This will be set to 0 if not found and on failure.
660 */
661RTDECL(bool) RTNetIPv4IsDHCPValid(PCRTNETUDP pUdpHdr, PCRTNETBOOTP pDhcp, size_t cbDhcp, uint8_t *pMsgType)
662{
663 ssize_t cbLeft;
664 uint8_t MsgType;
665 PCRTNETDHCPOPT pOpt;
666 NOREF(pUdpHdr); /** @todo rainy-day: Why isn't the UDP header used? */
667
668 AssertPtrNull(pMsgType);
669 if (pMsgType)
670 *pMsgType = 0;
671
672 /*
673 * Validate all the header fields we're able to...
674 */
675 if (cbDhcp < RT_UOFFSETOF(RTNETBOOTP, bp_op) + sizeof(pDhcp->bp_op))
676 return true;
677 if (RT_UNLIKELY( pDhcp->bp_op != RTNETBOOTP_OP_REQUEST
678 && pDhcp->bp_op != RTNETBOOTP_OP_REPLY))
679 return false;
680
681 if (cbDhcp < RT_UOFFSETOF(RTNETBOOTP, bp_htype) + sizeof(pDhcp->bp_htype))
682 return true;
683 if (RT_UNLIKELY(pDhcp->bp_htype != RTNET_ARP_ETHER))
684 return false;
685
686 if (cbDhcp < RT_UOFFSETOF(RTNETBOOTP, bp_hlen) + sizeof(pDhcp->bp_hlen))
687 return true;
688 if (RT_UNLIKELY(pDhcp->bp_hlen != sizeof(RTMAC)))
689 return false;
690
691 if (cbDhcp < RT_UOFFSETOF(RTNETBOOTP, bp_flags) + sizeof(pDhcp->bp_flags))
692 return true;
693 if (RT_UNLIKELY(RT_BE2H_U16(pDhcp->bp_flags) & ~(RTNET_DHCP_FLAGS_NO_BROADCAST)))
694 return false;
695
696 /*
697 * Check the DHCP cookie and make sure it isn't followed by an END option
698 * (because that seems to be indicating that it's BOOTP and not DHCP).
699 */
700 cbLeft = (ssize_t)cbDhcp - RT_UOFFSETOF(RTNETBOOTP, bp_vend.Dhcp.dhcp_cookie) + sizeof(pDhcp->bp_vend.Dhcp.dhcp_cookie);
701 if (cbLeft < 0)
702 return true;
703 if (RT_UNLIKELY(RT_BE2H_U32(pDhcp->bp_vend.Dhcp.dhcp_cookie) != RTNET_DHCP_COOKIE))
704 return false;
705 if (cbLeft < 1)
706 return true;
707 pOpt = (PCRTNETDHCPOPT)&pDhcp->bp_vend.Dhcp.dhcp_opts[0];
708 if (pOpt->dhcp_opt == RTNET_DHCP_OPT_END)
709 return false;
710
711 /*
712 * Scan the options until we find the message type or run out of message.
713 *
714 * We're not strict about termination (END) for many reasons, however,
715 * we don't accept END without MSG_TYPE.
716 */
717 MsgType = 0;
718 while (cbLeft > 0)
719 {
720 if (pOpt->dhcp_opt == RTNET_DHCP_OPT_END)
721 {
722 /* Fail if no MSG_TYPE. */
723 if (!MsgType)
724 return false;
725 break;
726 }
727 if (pOpt->dhcp_opt == RTNET_DHCP_OPT_PAD)
728 {
729 pOpt = (PCRTNETDHCPOPT)((uint8_t const *)pOpt + 1);
730 cbLeft--;
731 }
732 else
733 {
734 switch (pOpt->dhcp_opt)
735 {
736 case RTNET_DHCP_OPT_MSG_TYPE:
737 {
738 if (cbLeft < 3)
739 return true;
740 MsgType = *(const uint8_t *)(pOpt + 1);
741 switch (MsgType)
742 {
743 case RTNET_DHCP_MT_DISCOVER:
744 case RTNET_DHCP_MT_OFFER:
745 case RTNET_DHCP_MT_REQUEST:
746 case RTNET_DHCP_MT_DECLINE:
747 case RTNET_DHCP_MT_ACK:
748 case RTNET_DHCP_MT_NAC:
749 case RTNET_DHCP_MT_RELEASE:
750 case RTNET_DHCP_MT_INFORM:
751 break;
752
753 default:
754 /* we don't know this message type, fail. */
755 return false;
756 }
757
758 /* Found a known message type, consider the job done. */
759 if (pMsgType)
760 *pMsgType = MsgType;
761 return true;
762 }
763 }
764
765 /* Skip the option. */
766 cbLeft -= pOpt->dhcp_len + sizeof(*pOpt);
767 pOpt = (PCRTNETDHCPOPT)((uint8_t const *)pOpt + pOpt->dhcp_len + sizeof(*pOpt));
768 }
769 }
770
771 return true;
772}
773RT_EXPORT_SYMBOL(RTNetIPv4IsDHCPValid);
774
Note: See TracBrowser for help on using the repository browser.

© 2023 Oracle
ContactPrivacy policyTerms of Use