IP Defragmentation
Defragmentation is needed, obviously, when a packet has
reached its final destination and has to be passed to an upper network layer (in Linux, it
is handled by the ip_local_deliver function). Routers,
by contrast, usually just pass packets through without caring whether they are fragments
of a larger packet. But defragmentation can sometimes be
required on a router: generally speaking, defragmentation is needed whenever a host has to
do some processing on the entire packet. Two such cases on routers are:
The IP header contains the Router Alert option, which forces the router to process the packet (see
ip_call_ra_chain, called fromip_forward, and Figure 18-1 in Chapter 18).Netfilter has to look at the packet to decide what to do with it. Given the scheme in Figure 18-1 in Chapter 18, the hook points where Netfilter may force defragmentation are
NF_IP_PRE_ROUTINGandNF_IP_LOCAL_OUT.
But the way defragmentation works does not depend on the circumstances in which it is triggered, so I will describe the implementation from a high-level standpoint.
Organization of the IP Fragments Hash Table
As IP fragments are received, they are organized into a hash table of struct ipq elements. Figure 22-1 shows an example of how the
data structure is organized and used.
#define IPQ_HASHSZ 64
static struct ipq *ipq_hash[IPQ_HASHSZ];Each IP packet being defragmented is represented by an ipq instance, which consists of a list of fragments. Figure 22-1 shows an example of an IP packet ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access