Local Delivery
Chapter 35 explains how the forwarding (routing)
engine knows that the local host is the packet's destination. We saw at the end of the
section "The ip_rcv_finish Function"
in Chapter 19 that the call to ip_route_input, at the top of ip_rcv_finish, initializes skb->dst->input to ip_local_deliver
when the packet has reached its destination host (as opposed to ip_forward, when it needs to be forwarded). Furthermore, Netfilter is given
the final right to decide whether the generic do_something function (such as ip_local_deliver) is allowed to call the corresponding
do_something
_finish function (in this case, ip_local_deliver_finish) to complete the job.
int ip_local_deliver(struct sk_buff *skb)
{
if (skb->nh.iph->frag_off & htons(IP_MF|IP_OFFSET)) {
skb = ip_defrag(skb, IP_DEFRAG_LOCAL_DELIVER);
if (!skb)
return 0;
}
return NF_HOOK(PF_INET, NF_IP_LOCAL_IN, skb, skb->dev, NULL,
ip_local_deliver_finish);
}In contrast to forwarding, where defragmentation can mostly be ignored, local delivery has to do a lot of work to handle defragmentation. Except for special cases (such as when Netfilter must defragment a packet to examine its contents), forwarding can be performed on each fragment without trying to recombine them. In contrast, the original IP packet must always be defragmented and passed as a whole for local delivery, because that higher L4 layer is supposed to be blissfully ignorant of the need for fragmentation at the IP layer.
Defragmentation is performed within the ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access