1
10
13
14
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
113
114
115
116
117
118
119
120
124
125
126
127
128
129
130
131
132
133
135
136
137
142
143
144
151
152
153
157
158
161
162
163
164
165
166
167
168
169
170
171
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
203
204
205
206
207
208
209
210
211
212
213
218
219
220
221
222
223
224
229
230
231
232
233
234
235
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
299
300
301
306
307
308
309
310
311
312
313
314
316
317
318
319
320
321
322
323
324
329
330
331
332
333
334
335
336
337
338
...
...
...
#define NX_SOURCE_CODE
#include "nx_api.h"
#include "nx_packet.h"
#include "nx_ip.h"
#include "nx_icmp.h"
#ifdef NX_IPSEC_ENABLE
#include "nx_ipsec.h"
#endif
#if !defined(NX_DISABLE_IPV4) && !defined(NX_DISABLE_ICMPV4_ERROR_MESSAGE)...
...
VOID _nx_icmpv4_send_error_message(NX_IP *ip_ptr, NX_PACKET *offending_packet,
ULONG word1, ULONG error_pointer)
{
NX_PACKET *pkt_ptr;
USHORT checksum;
#if defined(NX_DISABLE_ICMPV4_TX_CHECKSUM) || defined(NX_ENABLE_INTERFACE_CAPABILITY) || defined(NX_IPSEC_ENABLE)
UINT compute_checksum = 1;
#endif
NX_ICMPV4_ERROR *icmpv4_error;
NX_IPV4_HEADER *ip_header_ptr;
UINT ip_header_size;
UINT bytes_to_copy, i;
ULONG src_ip;
ULONG next_hop_address = NX_NULL;
ULONG *src_packet, *dest_packet;
NX_INTERFACE *if_ptr;
#ifdef NX_IPSEC_ENABLE
VOID *sa = NX_NULL;
UINT ret = 0;
ULONG data_offset;
NXD_ADDRESS src_addr;
NXD_ADDRESS dest_addr;/* ... */
#endif
NX_PACKET_DEBUG(__FILE__, __LINE__, offending_packet);
if (ip_ptr -> nx_ip_icmpv4_packet_process == NX_NULL)
{
return;
}if (ip_ptr -> nx_ip_icmpv4_packet_process == NX_NULL) { ... }
ip_header_ptr = (NX_IPV4_HEADER *)(offending_packet -> nx_packet_ip_header);
src_ip = ip_header_ptr -> nx_ip_header_source_ip;
if_ptr = offending_packet -> nx_packet_address.nx_packet_interface_ptr;
/* ... */
if ((ip_header_ptr -> nx_ip_header_destination_ip == NX_IP_LIMITED_BROADCAST) ||
((ip_header_ptr -> nx_ip_header_destination_ip & NX_IP_CLASS_D_MASK) == NX_IP_CLASS_D_TYPE))
{
return;
}if ((ip_header_ptr -> nx_ip_header_destination_ip == NX_IP_LIMITED_BROADCAST) || ((ip_header_ptr -> nx_ip_header_destination_ip & NX_IP_CLASS_D_MASK) == NX_IP_CLASS_D_TYPE)) { ... }
if (((ip_header_ptr -> nx_ip_header_destination_ip & if_ptr -> nx_interface_ip_network_mask) ==
if_ptr -> nx_interface_ip_network) &&
((ip_header_ptr -> nx_ip_header_destination_ip & ~(if_ptr -> nx_interface_ip_network_mask)) ==
~(if_ptr -> nx_interface_ip_network_mask)))
{
return;
}if (((ip_header_ptr -> nx_ip_header_destination_ip & if_ptr -> nx_interface_ip_network_mask) == if_ptr -> nx_interface_ip_network) && ((ip_header_ptr -> nx_ip_header_destination_ip & ~(if_ptr -> nx_interface_ip_network_mask)) == ~(if_ptr -> nx_interface_ip_network_mask))) { ... }
if (ip_header_ptr -> nx_ip_header_word_1 & NX_IP_OFFSET_MASK)
{
return;
}if (ip_header_ptr -> nx_ip_header_word_1 & NX_IP_OFFSET_MASK) { ... }
/* ... */
if ((ip_header_ptr -> nx_ip_header_source_ip == 0) ||
((ip_header_ptr -> nx_ip_header_source_ip >= NX_IP_LOOPBACK_FIRST) &&
(ip_header_ptr -> nx_ip_header_source_ip <= NX_IP_LOOPBACK_LAST)) ||
(ip_header_ptr -> nx_ip_header_source_ip == NX_IP_LIMITED_BROADCAST) ||
((ip_header_ptr -> nx_ip_header_source_ip & NX_IP_CLASS_D_MASK) == NX_IP_CLASS_D_TYPE))
{
return;
}if ((ip_header_ptr -> nx_ip_header_source_ip == 0) || ((ip_header_ptr -> nx_ip_header_source_ip >= NX_IP_LOOPBACK_FIRST) && (ip_header_ptr -> nx_ip_header_source_ip <= NX_IP_LOOPBACK_LAST)) || (ip_header_ptr -> nx_ip_header_source_ip == NX_IP_LIMITED_BROADCAST) || ((ip_header_ptr -> nx_ip_header_source_ip & NX_IP_CLASS_D_MASK) == NX_IP_CLASS_D_TYPE)) { ... }
if (_nx_packet_allocate(ip_ptr -> nx_ip_default_packet_pool, &pkt_ptr, NX_IPv4_ICMP_PACKET, NX_NO_WAIT))
{
return;
}if (_nx_packet_allocate(ip_ptr -> nx_ip_default_packet_pool, &pkt_ptr, NX_IPv4_ICMP_PACKET, NX_NO_WAIT)) { ... }
NX_PACKET_DEBUG(__FILE__, __LINE__, pkt_ptr);
pkt_ptr -> nx_packet_ip_version = NX_IP_VERSION_V4;
icmpv4_error = (NX_ICMPV4_ERROR *)(pkt_ptr -> nx_packet_prepend_ptr);
icmpv4_error -> nx_icmpv4_error_header.nx_icmpv4_header_type = (UCHAR)((word1 >> 24) & 0xFF);
icmpv4_error -> nx_icmpv4_error_header.nx_icmpv4_header_code = (UCHAR)((word1 >> 16) & 0xFF);
icmpv4_error -> nx_icmpv4_error_header.nx_icmpv4_header_checksum = 0;
icmpv4_error -> nx_icmpv4_error_pointer = (error_pointer << 24);
NX_CHANGE_ULONG_ENDIAN(icmpv4_error -> nx_icmpv4_error_pointer);
ip_header_size = ((ip_header_ptr -> nx_ip_header_word_0 & 0x0F000000) >> 24);
bytes_to_copy = (UINT)((ip_header_size + 2) * sizeof(ULONG));
/* ... */
pkt_ptr -> nx_packet_length = bytes_to_copy + (ULONG)sizeof(NX_ICMPV4_ERROR);
pkt_ptr -> nx_packet_append_ptr = pkt_ptr -> nx_packet_prepend_ptr + pkt_ptr -> nx_packet_length;
src_packet = (ULONG *)(offending_packet -> nx_packet_ip_header);
dest_packet = (ULONG *)NX_UCHAR_POINTER_ADD(icmpv4_error, sizeof(NX_ICMPV4_ERROR));
for (i = 0; i < NX_IP_NORMAL_LENGTH; i++)
{
NX_CHANGE_ULONG_ENDIAN(*src_packet);
src_packet++;
}for (i = 0; i < NX_IP_NORMAL_LENGTH; i++) { ... }
src_packet = (ULONG *)(offending_packet -> nx_packet_ip_header);
for (; bytes_to_copy > 0; bytes_to_copy -= 4)
{
*dest_packet++ = *src_packet++;
}for (; bytes_to_copy > 0; bytes_to_copy -= 4) { ... }
src_packet = (ULONG *)(offending_packet -> nx_packet_ip_header);
for (i = 0; i < NX_IP_NORMAL_LENGTH; i++)
{
NX_CHANGE_ULONG_ENDIAN(*src_packet);
src_packet++;
}for (i = 0; i < NX_IP_NORMAL_LENGTH; i++) { ... }
pkt_ptr -> nx_packet_address.nx_packet_interface_ptr = offending_packet -> nx_packet_address.nx_packet_interface_ptr;
_nx_ip_route_find(ip_ptr, src_ip,
&pkt_ptr -> nx_packet_address.nx_packet_interface_ptr,
&next_hop_address);
#ifdef NX_IPSEC_ENABLE
if (ip_ptr -> nx_ip_packet_egress_sa_lookup != NX_NULL)
{
src_addr.nxd_ip_version = NX_IP_VERSION_V4;
src_addr.nxd_ip_address.v4 = pkt_ptr -> nx_packet_address.nx_packet_interface_ptr -> nx_interface_ip_address;
dest_addr.nxd_ip_version = NX_IP_VERSION_V4;
dest_addr.nxd_ip_address.v4 = src_ip;
ret = ip_ptr -> nx_ip_packet_egress_sa_lookup(ip_ptr,
&src_addr,
&dest_addr,
NX_PROTOCOL_ICMP,
0,
0,
&data_offset, &sa,
((word1 >> 16) & 0xFFFF));
if (ret == NX_IPSEC_TRAFFIC_BYPASS)
{
sa = NX_NULL;
data_offset = 0;
}if (ret == NX_IPSEC_TRAFFIC_BYPASS) { ... }
else if (ret == NX_IPSEC_TRAFFIC_DROP || ret == NX_IPSEC_TRAFFIC_PENDING_IKEV2)
{
_nx_packet_release(pkt_ptr);
return;
}else if (ret == NX_IPSEC_TRAFFIC_DROP || ret == NX_IPSEC_TRAFFIC_PENDING_IKEV2) { ... }
...}
pkt_ptr -> nx_packet_ipsec_sa_ptr = sa;
/* ... */
#endif
#ifdef NX_DISABLE_ICMPV4_TX_CHECKSUM
compute_checksum = 0;
#endif
#ifdef NX_ENABLE_INTERFACE_CAPABILITY
if (pkt_ptr -> nx_packet_address.nx_packet_interface_ptr -> nx_interface_capability_flag & NX_INTERFACE_CAPABILITY_ICMPV4_TX_CHECKSUM)
{
compute_checksum = 0;
}if (pkt_ptr -> nx_packet_address.nx_packet_interface_ptr -> nx_interface_capability_flag & NX_INTERFACE_CAPABILITY_ICMPV4_TX_CHECKSUM) { ... }
/* ... */#endif
#ifdef NX_IPSEC_ENABLE
if ((sa != NX_NULL) && (((NX_IPSEC_SA *)sa) -> nx_ipsec_sa_encryption_method != NX_CRYPTO_NONE))
{
compute_checksum = 1;
}if ((sa != NX_NULL) && (((NX_IPSEC_SA *)sa) -> nx_ipsec_sa_encryption_method != NX_CRYPTO_NONE)) { ... }
/* ... */#endif
#if defined(NX_DISABLE_ICMPV4_TX_CHECKSUM) || defined(NX_ENABLE_INTERFACE_CAPABILITY) || defined(NX_IPSEC_ENABLE)
if (compute_checksum)
#endif
{
checksum = _nx_ip_checksum_compute(pkt_ptr, NX_IP_ICMP,
(UINT)pkt_ptr -> nx_packet_length,
/* ... */
NX_NULL, NX_NULL);
icmpv4_error -> nx_icmpv4_error_header.nx_icmpv4_header_checksum = (USHORT)(~checksum);
NX_CHANGE_USHORT_ENDIAN(icmpv4_error -> nx_icmpv4_error_header.nx_icmpv4_header_checksum);
...}
#ifdef NX_ENABLE_INTERFACE_CAPABILITY
else
{
pkt_ptr -> nx_packet_interface_capability_flag |= NX_INTERFACE_CAPABILITY_ICMPV4_TX_CHECKSUM;
}else { ... }
/* ... */#endif
_nx_ip_packet_send(ip_ptr, pkt_ptr, src_ip,
NX_IP_NORMAL, 255, NX_IP_ICMP, NX_FRAGMENT_OKAY, next_hop_address);
return;
}{ ... }
#endif/* ... */