ipv4: fix a deadlock in ip_ra_control
[linux-block.git] / net / ipv6 / datagram.c
CommitLineData
1da177e4
LT
1/*
2 * common UDP/RAW code
1ab1457c 3 * Linux INET6 implementation
1da177e4
LT
4 *
5 * Authors:
1ab1457c 6 * Pedro Roque <roque@di.fc.ul.pt>
1da177e4 7 *
1da177e4
LT
8 * This program is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU General Public License
10 * as published by the Free Software Foundation; either version
11 * 2 of the License, or (at your option) any later version.
12 */
13
4fc268d2 14#include <linux/capability.h>
1da177e4
LT
15#include <linux/errno.h>
16#include <linux/types.h>
17#include <linux/kernel.h>
1da177e4
LT
18#include <linux/interrupt.h>
19#include <linux/socket.h>
20#include <linux/sockios.h>
21#include <linux/in6.h>
22#include <linux/ipv6.h>
23#include <linux/route.h>
5a0e3ad6 24#include <linux/slab.h>
a495f836 25#include <linux/export.h>
1da177e4
LT
26
27#include <net/ipv6.h>
28#include <net/ndisc.h>
29#include <net/addrconf.h>
30#include <net/transp_v6.h>
31#include <net/ip6_route.h>
c752f073 32#include <net/tcp_states.h>
e7219858 33#include <net/dsfield.h>
1da177e4
LT
34
35#include <linux/errqueue.h>
7c0f6ba6 36#include <linux/uaccess.h>
1da177e4 37
a50feda5 38static bool ipv6_mapped_addr_any(const struct in6_addr *a)
c15fea2d 39{
a50feda5 40 return ipv6_addr_v4mapped(a) && (a->s6_addr32[3] == 0);
c15fea2d
MM
41}
42
80fbdb20
MKL
43static void ip6_datagram_flow_key_init(struct flowi6 *fl6, struct sock *sk)
44{
45 struct inet_sock *inet = inet_sk(sk);
46 struct ipv6_pinfo *np = inet6_sk(sk);
47
48 memset(fl6, 0, sizeof(*fl6));
49 fl6->flowi6_proto = sk->sk_protocol;
50 fl6->daddr = sk->sk_v6_daddr;
51 fl6->saddr = np->saddr;
52 fl6->flowi6_oif = sk->sk_bound_dev_if;
53 fl6->flowi6_mark = sk->sk_mark;
54 fl6->fl6_dport = inet->inet_dport;
55 fl6->fl6_sport = inet->inet_sport;
56 fl6->flowlabel = np->flow_label;
e2d118a1 57 fl6->flowi6_uid = sk->sk_uid;
80fbdb20
MKL
58
59 if (!fl6->flowi6_oif)
60 fl6->flowi6_oif = np->sticky_pktinfo.ipi6_ifindex;
61
62 if (!fl6->flowi6_oif && ipv6_addr_is_multicast(&fl6->daddr))
63 fl6->flowi6_oif = np->mcast_oif;
64
65 security_sk_classify_flow(sk, flowi6_to_flowi(fl6));
66}
67
33c162a9 68int ip6_datagram_dst_update(struct sock *sk, bool fix_sk_saddr)
7e2040db
MKL
69{
70 struct ip6_flowlabel *flowlabel = NULL;
71 struct in6_addr *final_p, final;
72 struct ipv6_txoptions *opt;
73 struct dst_entry *dst;
74 struct inet_sock *inet = inet_sk(sk);
75 struct ipv6_pinfo *np = inet6_sk(sk);
76 struct flowi6 fl6;
77 int err = 0;
78
79 if (np->sndflow && (np->flow_label & IPV6_FLOWLABEL_MASK)) {
80 flowlabel = fl6_sock_lookup(sk, np->flow_label);
81 if (!flowlabel)
82 return -EINVAL;
83 }
84 ip6_datagram_flow_key_init(&fl6, sk);
85
86 rcu_read_lock();
87 opt = flowlabel ? flowlabel->opt : rcu_dereference(np->opt);
88 final_p = fl6_update_dst(&fl6, opt, &final);
89 rcu_read_unlock();
90
91 dst = ip6_dst_lookup_flow(sk, &fl6, final_p);
92 if (IS_ERR(dst)) {
93 err = PTR_ERR(dst);
94 goto out;
95 }
96
33c162a9
MKL
97 if (fix_sk_saddr) {
98 if (ipv6_addr_any(&np->saddr))
99 np->saddr = fl6.saddr;
7e2040db 100
33c162a9
MKL
101 if (ipv6_addr_any(&sk->sk_v6_rcv_saddr)) {
102 sk->sk_v6_rcv_saddr = fl6.saddr;
103 inet->inet_rcv_saddr = LOOPBACK4_IPV6;
104 if (sk->sk_prot->rehash)
105 sk->sk_prot->rehash(sk);
106 }
7e2040db
MKL
107 }
108
109 ip6_dst_store(sk, dst,
110 ipv6_addr_equal(&fl6.daddr, &sk->sk_v6_daddr) ?
111 &sk->sk_v6_daddr : NULL,
112#ifdef CONFIG_IPV6_SUBTREES
113 ipv6_addr_equal(&fl6.saddr, &np->saddr) ?
114 &np->saddr :
115#endif
116 NULL);
117
118out:
119 fl6_sock_release(flowlabel);
120 return err;
121}
122
e646b657
MKL
123void ip6_datagram_release_cb(struct sock *sk)
124{
125 struct dst_entry *dst;
126
127 if (ipv6_addr_v4mapped(&sk->sk_v6_daddr))
128 return;
129
130 rcu_read_lock();
131 dst = __sk_dst_get(sk);
132 if (!dst || !dst->obsolete ||
133 dst->ops->check(dst, inet6_sk(sk)->dst_cookie)) {
134 rcu_read_unlock();
135 return;
136 }
137 rcu_read_unlock();
138
139 ip6_datagram_dst_update(sk, false);
140}
141EXPORT_SYMBOL_GPL(ip6_datagram_release_cb);
142
0382a25a
GN
143int __ip6_datagram_connect(struct sock *sk, struct sockaddr *uaddr,
144 int addr_len)
1da177e4
LT
145{
146 struct sockaddr_in6 *usin = (struct sockaddr_in6 *) uaddr;
67ba4152
IM
147 struct inet_sock *inet = inet_sk(sk);
148 struct ipv6_pinfo *np = inet6_sk(sk);
7e2040db 149 struct in6_addr *daddr;
1da177e4
LT
150 int addr_type;
151 int err;
80fbdb20 152 __be32 fl6_flowlabel = 0;
1da177e4
LT
153
154 if (usin->sin6_family == AF_INET) {
155 if (__ipv6_only_sock(sk))
156 return -EAFNOSUPPORT;
03645a11 157 err = __ip4_datagram_connect(sk, uaddr, addr_len);
1da177e4
LT
158 goto ipv4_connected;
159 }
160
161 if (addr_len < SIN6_LEN_RFC2133)
1ab1457c 162 return -EINVAL;
1da177e4 163
1ab1457c
YH
164 if (usin->sin6_family != AF_INET6)
165 return -EAFNOSUPPORT;
1da177e4 166
7e2040db 167 if (np->sndflow)
80fbdb20 168 fl6_flowlabel = usin->sin6_flowinfo & IPV6_FLOWINFO_MASK;
1da177e4 169
052d2369 170 if (ipv6_addr_any(&usin->sin6_addr)) {
1da177e4
LT
171 /*
172 * connect to self
173 */
052d2369
JL
174 if (ipv6_addr_v4mapped(&sk->sk_v6_rcv_saddr))
175 ipv6_addr_set_v4mapped(htonl(INADDR_LOOPBACK),
176 &usin->sin6_addr);
177 else
178 usin->sin6_addr = in6addr_loopback;
1da177e4
LT
179 }
180
052d2369
JL
181 addr_type = ipv6_addr_type(&usin->sin6_addr);
182
1da177e4
LT
183 daddr = &usin->sin6_addr;
184
052d2369 185 if (addr_type & IPV6_ADDR_MAPPED) {
1da177e4
LT
186 struct sockaddr_in sin;
187
188 if (__ipv6_only_sock(sk)) {
189 err = -ENETUNREACH;
190 goto out;
191 }
192 sin.sin_family = AF_INET;
193 sin.sin_addr.s_addr = daddr->s6_addr32[3];
194 sin.sin_port = usin->sin6_port;
195
03645a11
ED
196 err = __ip4_datagram_connect(sk,
197 (struct sockaddr *) &sin,
198 sizeof(sin));
1da177e4
LT
199
200ipv4_connected:
201 if (err)
202 goto out;
1ab1457c 203
efe4208f 204 ipv6_addr_set_v4mapped(inet->inet_daddr, &sk->sk_v6_daddr);
1da177e4 205
c15fea2d
MM
206 if (ipv6_addr_any(&np->saddr) ||
207 ipv6_mapped_addr_any(&np->saddr))
c720c7e8 208 ipv6_addr_set_v4mapped(inet->inet_saddr, &np->saddr);
b301e82c 209
efe4208f
ED
210 if (ipv6_addr_any(&sk->sk_v6_rcv_saddr) ||
211 ipv6_mapped_addr_any(&sk->sk_v6_rcv_saddr)) {
c720c7e8 212 ipv6_addr_set_v4mapped(inet->inet_rcv_saddr,
efe4208f 213 &sk->sk_v6_rcv_saddr);
719f8358
ED
214 if (sk->sk_prot->rehash)
215 sk->sk_prot->rehash(sk);
216 }
1da177e4 217
1da177e4
LT
218 goto out;
219 }
220
842df073 221 if (__ipv6_addr_needs_scope_id(addr_type)) {
1da177e4
LT
222 if (addr_len >= sizeof(struct sockaddr_in6) &&
223 usin->sin6_scope_id) {
224 if (sk->sk_bound_dev_if &&
225 sk->sk_bound_dev_if != usin->sin6_scope_id) {
226 err = -EINVAL;
227 goto out;
228 }
229 sk->sk_bound_dev_if = usin->sin6_scope_id;
1da177e4
LT
230 }
231
1ac4f008
BH
232 if (!sk->sk_bound_dev_if && (addr_type & IPV6_ADDR_MULTICAST))
233 sk->sk_bound_dev_if = np->mcast_oif;
234
1da177e4
LT
235 /* Connect to link-local address requires an interface */
236 if (!sk->sk_bound_dev_if) {
237 err = -EINVAL;
238 goto out;
239 }
240 }
241
efe4208f 242 sk->sk_v6_daddr = *daddr;
80fbdb20 243 np->flow_label = fl6_flowlabel;
1da177e4 244
c720c7e8 245 inet->inet_dport = usin->sin6_port;
1da177e4
LT
246
247 /*
248 * Check for a route to destination an obtain the
249 * destination cache for it.
250 */
251
33c162a9 252 err = ip6_datagram_dst_update(sk, true);
7e2040db 253 if (err)
1da177e4 254 goto out;
1da177e4
LT
255
256 sk->sk_state = TCP_ESTABLISHED;
877d1f62 257 sk_set_txhash(sk);
1da177e4 258out:
1da177e4
LT
259 return err;
260}
0382a25a 261EXPORT_SYMBOL_GPL(__ip6_datagram_connect);
03645a11
ED
262
263int ip6_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
264{
265 int res;
266
267 lock_sock(sk);
268 res = __ip6_datagram_connect(sk, uaddr, addr_len);
269 release_sock(sk);
270 return res;
271}
a495f836 272EXPORT_SYMBOL_GPL(ip6_datagram_connect);
1da177e4 273
82b276cd
HFS
274int ip6_datagram_connect_v6_only(struct sock *sk, struct sockaddr *uaddr,
275 int addr_len)
276{
277 DECLARE_SOCKADDR(struct sockaddr_in6 *, sin6, uaddr);
278 if (sin6->sin6_family != AF_INET6)
279 return -EAFNOSUPPORT;
280 return ip6_datagram_connect(sk, uaddr, addr_len);
281}
282EXPORT_SYMBOL_GPL(ip6_datagram_connect_v6_only);
283
1ab1457c 284void ipv6_icmp_error(struct sock *sk, struct sk_buff *skb, int err,
e69a4adc 285 __be16 port, u32 info, u8 *payload)
1da177e4
LT
286{
287 struct ipv6_pinfo *np = inet6_sk(sk);
cc70ab26 288 struct icmp6hdr *icmph = icmp6_hdr(skb);
1da177e4
LT
289 struct sock_exterr_skb *serr;
290
291 if (!np->recverr)
292 return;
293
294 skb = skb_clone(skb, GFP_ATOMIC);
295 if (!skb)
296 return;
297
d40a4de0
BH
298 skb->protocol = htons(ETH_P_IPV6);
299
1da177e4
LT
300 serr = SKB_EXT_ERR(skb);
301 serr->ee.ee_errno = err;
302 serr->ee.ee_origin = SO_EE_ORIGIN_ICMP6;
1ab1457c 303 serr->ee.ee_type = icmph->icmp6_type;
1da177e4
LT
304 serr->ee.ee_code = icmph->icmp6_code;
305 serr->ee.ee_pad = 0;
306 serr->ee.ee_info = info;
307 serr->ee.ee_data = 0;
d56f90a7
ACM
308 serr->addr_offset = (u8 *)&(((struct ipv6hdr *)(icmph + 1))->daddr) -
309 skb_network_header(skb);
1da177e4
LT
310 serr->port = port;
311
1da177e4 312 __skb_pull(skb, payload - skb->data);
bd82393c 313 skb_reset_transport_header(skb);
1da177e4
LT
314
315 if (sock_queue_err_skb(sk, skb))
316 kfree_skb(skb);
317}
318
4c9483b2 319void ipv6_local_error(struct sock *sk, int err, struct flowi6 *fl6, u32 info)
1da177e4 320{
1c1e9d2b 321 const struct ipv6_pinfo *np = inet6_sk(sk);
1da177e4
LT
322 struct sock_exterr_skb *serr;
323 struct ipv6hdr *iph;
324 struct sk_buff *skb;
325
326 if (!np->recverr)
327 return;
328
329 skb = alloc_skb(sizeof(struct ipv6hdr), GFP_ATOMIC);
330 if (!skb)
331 return;
332
d40a4de0
BH
333 skb->protocol = htons(ETH_P_IPV6);
334
1ced98e8
ACM
335 skb_put(skb, sizeof(struct ipv6hdr));
336 skb_reset_network_header(skb);
0660e03f 337 iph = ipv6_hdr(skb);
4e3fd7a0 338 iph->daddr = fl6->daddr;
1da177e4
LT
339
340 serr = SKB_EXT_ERR(skb);
341 serr->ee.ee_errno = err;
342 serr->ee.ee_origin = SO_EE_ORIGIN_LOCAL;
1ab1457c 343 serr->ee.ee_type = 0;
1da177e4
LT
344 serr->ee.ee_code = 0;
345 serr->ee.ee_pad = 0;
346 serr->ee.ee_info = info;
347 serr->ee.ee_data = 0;
d56f90a7 348 serr->addr_offset = (u8 *)&iph->daddr - skb_network_header(skb);
1958b856 349 serr->port = fl6->fl6_dport;
1da177e4 350
27a884dc 351 __skb_pull(skb, skb_tail_pointer(skb) - skb->data);
bd82393c 352 skb_reset_transport_header(skb);
1da177e4
LT
353
354 if (sock_queue_err_skb(sk, skb))
355 kfree_skb(skb);
356}
357
4c9483b2 358void ipv6_local_rxpmtu(struct sock *sk, struct flowi6 *fl6, u32 mtu)
4b340ae2
BH
359{
360 struct ipv6_pinfo *np = inet6_sk(sk);
361 struct ipv6hdr *iph;
362 struct sk_buff *skb;
363 struct ip6_mtuinfo *mtu_info;
364
365 if (!np->rxopt.bits.rxpmtu)
366 return;
367
368 skb = alloc_skb(sizeof(struct ipv6hdr), GFP_ATOMIC);
369 if (!skb)
370 return;
371
372 skb_put(skb, sizeof(struct ipv6hdr));
373 skb_reset_network_header(skb);
374 iph = ipv6_hdr(skb);
4e3fd7a0 375 iph->daddr = fl6->daddr;
4b340ae2
BH
376
377 mtu_info = IP6CBMTU(skb);
4b340ae2
BH
378
379 mtu_info->ip6m_mtu = mtu;
380 mtu_info->ip6m_addr.sin6_family = AF_INET6;
381 mtu_info->ip6m_addr.sin6_port = 0;
382 mtu_info->ip6m_addr.sin6_flowinfo = 0;
4c9483b2 383 mtu_info->ip6m_addr.sin6_scope_id = fl6->flowi6_oif;
4e3fd7a0 384 mtu_info->ip6m_addr.sin6_addr = ipv6_hdr(skb)->daddr;
4b340ae2
BH
385
386 __skb_pull(skb, skb_tail_pointer(skb) - skb->data);
387 skb_reset_transport_header(skb);
388
389 skb = xchg(&np->rxpmtu, skb);
390 kfree_skb(skb);
391}
392
34b99df4
JA
393/* For some errors we have valid addr_offset even with zero payload and
394 * zero port. Also, addr_offset should be supported if port is set.
395 */
396static inline bool ipv6_datagram_support_addr(struct sock_exterr_skb *serr)
397{
398 return serr->ee.ee_origin == SO_EE_ORIGIN_ICMP6 ||
399 serr->ee.ee_origin == SO_EE_ORIGIN_ICMP ||
400 serr->ee.ee_origin == SO_EE_ORIGIN_LOCAL || serr->port;
401}
402
c247f053
WB
403/* IPv6 supports cmsg on all origins aside from SO_EE_ORIGIN_LOCAL.
404 *
405 * At one point, excluding local errors was a quick test to identify icmp/icmp6
406 * errors. This is no longer true, but the test remained, so the v6 stack,
407 * unlike v4, also honors cmsg requests on all wifi and timestamp errors.
408 *
409 * Timestamp code paths do not initialize the fields expected by cmsg:
410 * the PKTINFO fields in skb->cb[]. Fill those in here.
411 */
412static bool ip6_datagram_support_cmsg(struct sk_buff *skb,
413 struct sock_exterr_skb *serr)
829ae9d6 414{
c247f053
WB
415 if (serr->ee.ee_origin == SO_EE_ORIGIN_ICMP ||
416 serr->ee.ee_origin == SO_EE_ORIGIN_ICMP6)
417 return true;
418
419 if (serr->ee.ee_origin == SO_EE_ORIGIN_LOCAL)
420 return false;
421
422 if (!skb->dev)
423 return false;
829ae9d6
WB
424
425 if (skb->protocol == htons(ETH_P_IPV6))
c247f053 426 IP6CB(skb)->iif = skb->dev->ifindex;
829ae9d6 427 else
c247f053
WB
428 PKTINFO_SKB_CB(skb)->ipi_ifindex = skb->dev->ifindex;
429
430 return true;
829ae9d6
WB
431}
432
1ab1457c 433/*
1da177e4
LT
434 * Handle MSG_ERRQUEUE
435 */
85fbaa75 436int ipv6_recv_error(struct sock *sk, struct msghdr *msg, int len, int *addr_len)
1da177e4
LT
437{
438 struct ipv6_pinfo *np = inet6_sk(sk);
439 struct sock_exterr_skb *serr;
364a9e93 440 struct sk_buff *skb;
342dfc30 441 DECLARE_SOCKADDR(struct sockaddr_in6 *, sin, msg->msg_name);
1da177e4
LT
442 struct {
443 struct sock_extended_err ee;
444 struct sockaddr_in6 offender;
445 } errhdr;
446 int err;
447 int copied;
448
449 err = -EAGAIN;
364a9e93 450 skb = sock_dequeue_err_skb(sk);
63159f29 451 if (!skb)
1da177e4
LT
452 goto out;
453
454 copied = skb->len;
455 if (copied > len) {
456 msg->msg_flags |= MSG_TRUNC;
457 copied = len;
458 }
51f3d02b 459 err = skb_copy_datagram_msg(skb, 0, msg, copied);
960a2628
ED
460 if (unlikely(err)) {
461 kfree_skb(skb);
462 return err;
463 }
1da177e4
LT
464 sock_recv_timestamp(msg, sk, skb);
465
466 serr = SKB_EXT_ERR(skb);
467
34b99df4 468 if (sin && ipv6_datagram_support_addr(serr)) {
d56f90a7 469 const unsigned char *nh = skb_network_header(skb);
1da177e4
LT
470 sin->sin6_family = AF_INET6;
471 sin->sin6_flowinfo = 0;
1ab1457c 472 sin->sin6_port = serr->port;
d40a4de0 473 if (skb->protocol == htons(ETH_P_IPV6)) {
6c40d100
YH
474 const struct ipv6hdr *ip6h = container_of((struct in6_addr *)(nh + serr->addr_offset),
475 struct ipv6hdr, daddr);
476 sin->sin6_addr = ip6h->daddr;
1da177e4 477 if (np->sndflow)
6502ca52 478 sin->sin6_flowinfo = ip6_flowinfo(ip6h);
842df073
HFS
479 sin->sin6_scope_id =
480 ipv6_iface_scope_id(&sin->sin6_addr,
481 IP6CB(skb)->iif);
1da177e4 482 } else {
b301e82c
BH
483 ipv6_addr_set_v4mapped(*(__be32 *)(nh + serr->addr_offset),
484 &sin->sin6_addr);
842df073 485 sin->sin6_scope_id = 0;
1da177e4 486 }
85fbaa75 487 *addr_len = sizeof(*sin);
1da177e4
LT
488 }
489
490 memcpy(&errhdr.ee, &serr->ee, sizeof(struct sock_extended_err));
491 sin = &errhdr.offender;
f812116b 492 memset(sin, 0, sizeof(*sin));
c247f053
WB
493
494 if (ip6_datagram_support_cmsg(skb, serr)) {
1da177e4 495 sin->sin6_family = AF_INET6;
c247f053 496 if (np->rxopt.all)
4b261c75 497 ip6_datagram_recv_common_ctl(sk, msg, skb);
d40a4de0 498 if (skb->protocol == htons(ETH_P_IPV6)) {
4e3fd7a0 499 sin->sin6_addr = ipv6_hdr(skb)->saddr;
1da177e4 500 if (np->rxopt.all)
4b261c75 501 ip6_datagram_recv_specific_ctl(sk, msg, skb);
842df073
HFS
502 sin->sin6_scope_id =
503 ipv6_iface_scope_id(&sin->sin6_addr,
504 IP6CB(skb)->iif);
1da177e4 505 } else {
b301e82c
BH
506 ipv6_addr_set_v4mapped(ip_hdr(skb)->saddr,
507 &sin->sin6_addr);
f812116b 508 if (inet_sk(sk)->cmsg_flags)
1da177e4
LT
509 ip_cmsg_recv(msg, skb);
510 }
511 }
512
513 put_cmsg(msg, SOL_IPV6, IPV6_RECVERR, sizeof(errhdr), &errhdr);
514
515 /* Now we could try to dump offended packet options */
516
517 msg->msg_flags |= MSG_ERRQUEUE;
518 err = copied;
519
960a2628 520 consume_skb(skb);
1da177e4
LT
521out:
522 return err;
523}
a495f836 524EXPORT_SYMBOL_GPL(ipv6_recv_error);
1da177e4 525
4b340ae2
BH
526/*
527 * Handle IPV6_RECVPATHMTU
528 */
85fbaa75
HFS
529int ipv6_recv_rxpmtu(struct sock *sk, struct msghdr *msg, int len,
530 int *addr_len)
4b340ae2
BH
531{
532 struct ipv6_pinfo *np = inet6_sk(sk);
533 struct sk_buff *skb;
4b340ae2 534 struct ip6_mtuinfo mtu_info;
342dfc30 535 DECLARE_SOCKADDR(struct sockaddr_in6 *, sin, msg->msg_name);
4b340ae2
BH
536 int err;
537 int copied;
538
539 err = -EAGAIN;
540 skb = xchg(&np->rxpmtu, NULL);
63159f29 541 if (!skb)
4b340ae2
BH
542 goto out;
543
544 copied = skb->len;
545 if (copied > len) {
546 msg->msg_flags |= MSG_TRUNC;
547 copied = len;
548 }
51f3d02b 549 err = skb_copy_datagram_msg(skb, 0, msg, copied);
4b340ae2
BH
550 if (err)
551 goto out_free_skb;
552
553 sock_recv_timestamp(msg, sk, skb);
554
555 memcpy(&mtu_info, IP6CBMTU(skb), sizeof(mtu_info));
556
4b340ae2
BH
557 if (sin) {
558 sin->sin6_family = AF_INET6;
559 sin->sin6_flowinfo = 0;
560 sin->sin6_port = 0;
561 sin->sin6_scope_id = mtu_info.ip6m_addr.sin6_scope_id;
4e3fd7a0 562 sin->sin6_addr = mtu_info.ip6m_addr.sin6_addr;
85fbaa75 563 *addr_len = sizeof(*sin);
4b340ae2
BH
564 }
565
566 put_cmsg(msg, SOL_IPV6, IPV6_PATHMTU, sizeof(mtu_info), &mtu_info);
567
568 err = copied;
569
570out_free_skb:
571 kfree_skb(skb);
572out:
573 return err;
574}
1da177e4
LT
575
576
4b261c75
HFS
577void ip6_datagram_recv_common_ctl(struct sock *sk, struct msghdr *msg,
578 struct sk_buff *skb)
1da177e4
LT
579{
580 struct ipv6_pinfo *np = inet6_sk(sk);
4b261c75 581 bool is_ipv6 = skb->protocol == htons(ETH_P_IPV6);
1da177e4
LT
582
583 if (np->rxopt.bits.rxinfo) {
584 struct in6_pktinfo src_info;
585
4b261c75
HFS
586 if (is_ipv6) {
587 src_info.ipi6_ifindex = IP6CB(skb)->iif;
588 src_info.ipi6_addr = ipv6_hdr(skb)->daddr;
589 } else {
590 src_info.ipi6_ifindex =
591 PKTINFO_SKB_CB(skb)->ipi_ifindex;
592 ipv6_addr_set_v4mapped(ip_hdr(skb)->daddr,
593 &src_info.ipi6_addr);
594 }
829ae9d6
WB
595
596 if (src_info.ipi6_ifindex >= 0)
597 put_cmsg(msg, SOL_IPV6, IPV6_PKTINFO,
598 sizeof(src_info), &src_info);
1da177e4 599 }
4b261c75
HFS
600}
601
602void ip6_datagram_recv_specific_ctl(struct sock *sk, struct msghdr *msg,
603 struct sk_buff *skb)
604{
605 struct ipv6_pinfo *np = inet6_sk(sk);
606 struct inet6_skb_parm *opt = IP6CB(skb);
607 unsigned char *nh = skb_network_header(skb);
1da177e4
LT
608
609 if (np->rxopt.bits.rxhlim) {
0660e03f 610 int hlim = ipv6_hdr(skb)->hop_limit;
1da177e4
LT
611 put_cmsg(msg, SOL_IPV6, IPV6_HOPLIMIT, sizeof(hlim), &hlim);
612 }
613
41a1f8ea 614 if (np->rxopt.bits.rxtclass) {
e7219858 615 int tclass = ipv6_get_dsfield(ipv6_hdr(skb));
41a1f8ea
YH
616 put_cmsg(msg, SOL_IPV6, IPV6_TCLASS, sizeof(tclass), &tclass);
617 }
618
6502ca52
YH
619 if (np->rxopt.bits.rxflow) {
620 __be32 flowinfo = ip6_flowinfo((struct ipv6hdr *)nh);
621 if (flowinfo)
622 put_cmsg(msg, SOL_IPV6, IPV6_FLOWINFO, sizeof(flowinfo), &flowinfo);
1da177e4 623 }
333fad53
YH
624
625 /* HbH is allowed only once */
8b58a398
FW
626 if (np->rxopt.bits.hopopts && (opt->flags & IP6SKB_HOPBYHOP)) {
627 u8 *ptr = nh + sizeof(struct ipv6hdr);
1da177e4
LT
628 put_cmsg(msg, SOL_IPV6, IPV6_HOPOPTS, (ptr[1]+1)<<3, ptr);
629 }
333fad53
YH
630
631 if (opt->lastopt &&
632 (np->rxopt.bits.dstopts || np->rxopt.bits.srcrt)) {
633 /*
634 * Silly enough, but we need to reparse in order to
635 * report extension headers (except for HbH)
636 * in order.
637 *
1ab1457c 638 * Also note that IPV6_RECVRTHDRDSTOPTS is NOT
333fad53
YH
639 * (and WILL NOT be) defined because
640 * IPV6_RECVDSTOPTS is more generic. --yoshfuji
641 */
642 unsigned int off = sizeof(struct ipv6hdr);
0660e03f 643 u8 nexthdr = ipv6_hdr(skb)->nexthdr;
333fad53
YH
644
645 while (off <= opt->lastopt) {
95c96174 646 unsigned int len;
d56f90a7 647 u8 *ptr = nh + off;
333fad53 648
b5a4257c 649 switch (nexthdr) {
333fad53
YH
650 case IPPROTO_DSTOPTS:
651 nexthdr = ptr[0];
652 len = (ptr[1] + 1) << 3;
653 if (np->rxopt.bits.dstopts)
654 put_cmsg(msg, SOL_IPV6, IPV6_DSTOPTS, len, ptr);
655 break;
656 case IPPROTO_ROUTING:
657 nexthdr = ptr[0];
658 len = (ptr[1] + 1) << 3;
659 if (np->rxopt.bits.srcrt)
660 put_cmsg(msg, SOL_IPV6, IPV6_RTHDR, len, ptr);
661 break;
662 case IPPROTO_AH:
663 nexthdr = ptr[0];
a3059893 664 len = (ptr[1] + 2) << 2;
333fad53
YH
665 break;
666 default:
667 nexthdr = ptr[0];
668 len = (ptr[1] + 1) << 3;
669 break;
670 }
671
672 off += len;
673 }
674 }
675
676 /* socket options in old style */
677 if (np->rxopt.bits.rxoinfo) {
678 struct in6_pktinfo src_info;
679
680 src_info.ipi6_ifindex = opt->iif;
4e3fd7a0 681 src_info.ipi6_addr = ipv6_hdr(skb)->daddr;
333fad53
YH
682 put_cmsg(msg, SOL_IPV6, IPV6_2292PKTINFO, sizeof(src_info), &src_info);
683 }
684 if (np->rxopt.bits.rxohlim) {
0660e03f 685 int hlim = ipv6_hdr(skb)->hop_limit;
333fad53
YH
686 put_cmsg(msg, SOL_IPV6, IPV6_2292HOPLIMIT, sizeof(hlim), &hlim);
687 }
8b58a398
FW
688 if (np->rxopt.bits.ohopopts && (opt->flags & IP6SKB_HOPBYHOP)) {
689 u8 *ptr = nh + sizeof(struct ipv6hdr);
333fad53
YH
690 put_cmsg(msg, SOL_IPV6, IPV6_2292HOPOPTS, (ptr[1]+1)<<3, ptr);
691 }
692 if (np->rxopt.bits.odstopts && opt->dst0) {
d56f90a7 693 u8 *ptr = nh + opt->dst0;
333fad53 694 put_cmsg(msg, SOL_IPV6, IPV6_2292DSTOPTS, (ptr[1]+1)<<3, ptr);
1da177e4 695 }
333fad53 696 if (np->rxopt.bits.osrcrt && opt->srcrt) {
d56f90a7 697 struct ipv6_rt_hdr *rthdr = (struct ipv6_rt_hdr *)(nh + opt->srcrt);
333fad53 698 put_cmsg(msg, SOL_IPV6, IPV6_2292RTHDR, (rthdr->hdrlen+1) << 3, rthdr);
1da177e4 699 }
333fad53 700 if (np->rxopt.bits.odstopts && opt->dst1) {
d56f90a7 701 u8 *ptr = nh + opt->dst1;
333fad53 702 put_cmsg(msg, SOL_IPV6, IPV6_2292DSTOPTS, (ptr[1]+1)<<3, ptr);
1da177e4 703 }
6c468622
BS
704 if (np->rxopt.bits.rxorigdstaddr) {
705 struct sockaddr_in6 sin6;
747465ef 706 __be16 *ports = (__be16 *) skb_transport_header(skb);
6c468622 707
39b2dd76 708 if (skb_transport_offset(skb) + 4 <= (int)skb->len) {
6c468622
BS
709 /* All current transport protocols have the port numbers in the
710 * first four bytes of the transport header and this function is
711 * written with this assumption in mind.
712 */
713
714 sin6.sin6_family = AF_INET6;
4e3fd7a0 715 sin6.sin6_addr = ipv6_hdr(skb)->daddr;
6c468622
BS
716 sin6.sin6_port = ports[1];
717 sin6.sin6_flowinfo = 0;
3868b7aa
HFS
718 sin6.sin6_scope_id =
719 ipv6_iface_scope_id(&ipv6_hdr(skb)->daddr,
720 opt->iif);
6c468622
BS
721
722 put_cmsg(msg, SOL_IPV6, IPV6_ORIGDSTADDR, sizeof(sin6), &sin6);
723 }
724 }
0cc0aa61
WB
725 if (np->rxopt.bits.recvfragsize && opt->frag_max_size) {
726 int val = opt->frag_max_size;
727
728 put_cmsg(msg, SOL_IPV6, IPV6_RECVFRAGSIZE, sizeof(val), &val);
729 }
4b261c75
HFS
730}
731
732void ip6_datagram_recv_ctl(struct sock *sk, struct msghdr *msg,
733 struct sk_buff *skb)
734{
735 ip6_datagram_recv_common_ctl(sk, msg, skb);
736 ip6_datagram_recv_specific_ctl(sk, msg, skb);
1da177e4 737}
8e72d37e 738EXPORT_SYMBOL_GPL(ip6_datagram_recv_ctl);
1da177e4 739
73df66f8
TP
740int ip6_datagram_send_ctl(struct net *net, struct sock *sk,
741 struct msghdr *msg, struct flowi6 *fl6,
26879da5 742 struct ipcm6_cookie *ipc6, struct sockcm_cookie *sockc)
1da177e4
LT
743{
744 struct in6_pktinfo *src_info;
745 struct cmsghdr *cmsg;
746 struct ipv6_rt_hdr *rthdr;
747 struct ipv6_opt_hdr *hdr;
26879da5 748 struct ipv6_txoptions *opt = ipc6->opt;
1da177e4
LT
749 int len;
750 int err = 0;
751
f95b414e 752 for_each_cmsghdr(cmsg, msg) {
1da177e4 753 int addr_type;
1da177e4
LT
754
755 if (!CMSG_OK(msg, cmsg)) {
756 err = -EINVAL;
757 goto exit_f;
758 }
759
ad1e46a8 760 if (cmsg->cmsg_level == SOL_SOCKET) {
2632616b
ED
761 err = __sock_cmsg_send(sk, msg, cmsg, sockc);
762 if (err)
763 return err;
ad1e46a8
SHY
764 continue;
765 }
766
1da177e4
LT
767 if (cmsg->cmsg_level != SOL_IPV6)
768 continue;
769
770 switch (cmsg->cmsg_type) {
1ab1457c
YH
771 case IPV6_PKTINFO:
772 case IPV6_2292PKTINFO:
187e3838
YH
773 {
774 struct net_device *dev = NULL;
775
1ab1457c 776 if (cmsg->cmsg_len < CMSG_LEN(sizeof(struct in6_pktinfo))) {
1da177e4
LT
777 err = -EINVAL;
778 goto exit_f;
779 }
780
781 src_info = (struct in6_pktinfo *)CMSG_DATA(cmsg);
1ab1457c 782
1da177e4 783 if (src_info->ipi6_ifindex) {
4c9483b2
DM
784 if (fl6->flowi6_oif &&
785 src_info->ipi6_ifindex != fl6->flowi6_oif)
1da177e4 786 return -EINVAL;
4c9483b2 787 fl6->flowi6_oif = src_info->ipi6_ifindex;
1da177e4
LT
788 }
789
187e3838 790 addr_type = __ipv6_addr_type(&src_info->ipi6_addr);
1da177e4 791
536b2e92 792 rcu_read_lock();
4c9483b2
DM
793 if (fl6->flowi6_oif) {
794 dev = dev_get_by_index_rcu(net, fl6->flowi6_oif);
536b2e92
ED
795 if (!dev) {
796 rcu_read_unlock();
187e3838 797 return -ENODEV;
536b2e92
ED
798 }
799 } else if (addr_type & IPV6_ADDR_LINKLOCAL) {
800 rcu_read_unlock();
187e3838 801 return -EINVAL;
536b2e92 802 }
1ab1457c 803
187e3838
YH
804 if (addr_type != IPV6_ADDR_ANY) {
805 int strict = __ipv6_addr_src_scope(addr_type) <= IPV6_ADDR_SCOPE_LINKLOCAL;
2563fa59 806 if (!(inet_sk(sk)->freebind || inet_sk(sk)->transparent) &&
ec0506db 807 !ipv6_chk_addr(net, &src_info->ipi6_addr,
7c90cc2d
FLB
808 strict ? dev : NULL, 0) &&
809 !ipv6_chk_acast_addr_src(net, dev,
810 &src_info->ipi6_addr))
187e3838
YH
811 err = -EINVAL;
812 else
4e3fd7a0 813 fl6->saddr = src_info->ipi6_addr;
1da177e4 814 }
187e3838 815
536b2e92 816 rcu_read_unlock();
1da177e4 817
187e3838
YH
818 if (err)
819 goto exit_f;
820
1da177e4 821 break;
187e3838 822 }
1da177e4
LT
823
824 case IPV6_FLOWINFO:
1ab1457c 825 if (cmsg->cmsg_len < CMSG_LEN(4)) {
1da177e4
LT
826 err = -EINVAL;
827 goto exit_f;
828 }
829
4c9483b2
DM
830 if (fl6->flowlabel&IPV6_FLOWINFO_MASK) {
831 if ((fl6->flowlabel^*(__be32 *)CMSG_DATA(cmsg))&~IPV6_FLOWINFO_MASK) {
1da177e4
LT
832 err = -EINVAL;
833 goto exit_f;
834 }
835 }
4c9483b2 836 fl6->flowlabel = IPV6_FLOWINFO_MASK & *(__be32 *)CMSG_DATA(cmsg);
1da177e4
LT
837 break;
838
333fad53 839 case IPV6_2292HOPOPTS:
1da177e4 840 case IPV6_HOPOPTS:
1ab1457c 841 if (opt->hopopt || cmsg->cmsg_len < CMSG_LEN(sizeof(struct ipv6_opt_hdr))) {
1da177e4
LT
842 err = -EINVAL;
843 goto exit_f;
844 }
845
846 hdr = (struct ipv6_opt_hdr *)CMSG_DATA(cmsg);
847 len = ((hdr->hdrlen + 1) << 3);
848 if (cmsg->cmsg_len < CMSG_LEN(len)) {
849 err = -EINVAL;
850 goto exit_f;
851 }
af31f412 852 if (!ns_capable(net->user_ns, CAP_NET_RAW)) {
1da177e4
LT
853 err = -EPERM;
854 goto exit_f;
855 }
856 opt->opt_nflen += len;
857 opt->hopopt = hdr;
858 break;
859
333fad53 860 case IPV6_2292DSTOPTS:
1ab1457c 861 if (cmsg->cmsg_len < CMSG_LEN(sizeof(struct ipv6_opt_hdr))) {
1da177e4
LT
862 err = -EINVAL;
863 goto exit_f;
864 }
865
866 hdr = (struct ipv6_opt_hdr *)CMSG_DATA(cmsg);
867 len = ((hdr->hdrlen + 1) << 3);
868 if (cmsg->cmsg_len < CMSG_LEN(len)) {
869 err = -EINVAL;
870 goto exit_f;
871 }
af31f412 872 if (!ns_capable(net->user_ns, CAP_NET_RAW)) {
1da177e4
LT
873 err = -EPERM;
874 goto exit_f;
875 }
876 if (opt->dst1opt) {
877 err = -EINVAL;
878 goto exit_f;
879 }
880 opt->opt_flen += len;
881 opt->dst1opt = hdr;
882 break;
883
333fad53
YH
884 case IPV6_DSTOPTS:
885 case IPV6_RTHDRDSTOPTS:
886 if (cmsg->cmsg_len < CMSG_LEN(sizeof(struct ipv6_opt_hdr))) {
887 err = -EINVAL;
888 goto exit_f;
889 }
890
891 hdr = (struct ipv6_opt_hdr *)CMSG_DATA(cmsg);
892 len = ((hdr->hdrlen + 1) << 3);
893 if (cmsg->cmsg_len < CMSG_LEN(len)) {
894 err = -EINVAL;
895 goto exit_f;
896 }
af31f412 897 if (!ns_capable(net->user_ns, CAP_NET_RAW)) {
333fad53
YH
898 err = -EPERM;
899 goto exit_f;
900 }
901 if (cmsg->cmsg_type == IPV6_DSTOPTS) {
902 opt->opt_flen += len;
903 opt->dst1opt = hdr;
904 } else {
905 opt->opt_nflen += len;
906 opt->dst0opt = hdr;
907 }
908 break;
909
910 case IPV6_2292RTHDR:
1da177e4 911 case IPV6_RTHDR:
1ab1457c 912 if (cmsg->cmsg_len < CMSG_LEN(sizeof(struct ipv6_rt_hdr))) {
1da177e4
LT
913 err = -EINVAL;
914 goto exit_f;
915 }
916
917 rthdr = (struct ipv6_rt_hdr *)CMSG_DATA(cmsg);
918
280a9d34 919 switch (rthdr->type) {
07a93626 920#if IS_ENABLED(CONFIG_IPV6_MIP6)
280a9d34 921 case IPV6_SRCRT_TYPE_2:
6e093d9d
BH
922 if (rthdr->hdrlen != 2 ||
923 rthdr->segments_left != 1) {
924 err = -EINVAL;
925 goto exit_f;
926 }
280a9d34 927 break;
bb4dbf9e 928#endif
280a9d34 929 default:
1da177e4
LT
930 err = -EINVAL;
931 goto exit_f;
932 }
933
934 len = ((rthdr->hdrlen + 1) << 3);
935
1ab1457c 936 if (cmsg->cmsg_len < CMSG_LEN(len)) {
1da177e4
LT
937 err = -EINVAL;
938 goto exit_f;
939 }
940
941 /* segments left must also match */
942 if ((rthdr->hdrlen >> 1) != rthdr->segments_left) {
943 err = -EINVAL;
944 goto exit_f;
945 }
946
947 opt->opt_nflen += len;
948 opt->srcrt = rthdr;
949
333fad53 950 if (cmsg->cmsg_type == IPV6_2292RTHDR && opt->dst1opt) {
1da177e4
LT
951 int dsthdrlen = ((opt->dst1opt->hdrlen+1)<<3);
952
953 opt->opt_nflen += dsthdrlen;
954 opt->dst0opt = opt->dst1opt;
955 opt->dst1opt = NULL;
956 opt->opt_flen -= dsthdrlen;
957 }
958
959 break;
960
333fad53 961 case IPV6_2292HOPLIMIT:
1da177e4
LT
962 case IPV6_HOPLIMIT:
963 if (cmsg->cmsg_len != CMSG_LEN(sizeof(int))) {
964 err = -EINVAL;
965 goto exit_f;
966 }
967
26879da5
WW
968 ipc6->hlimit = *(int *)CMSG_DATA(cmsg);
969 if (ipc6->hlimit < -1 || ipc6->hlimit > 0xff) {
e8766fc8
SW
970 err = -EINVAL;
971 goto exit_f;
972 }
973
1da177e4
LT
974 break;
975
41a1f8ea
YH
976 case IPV6_TCLASS:
977 {
978 int tc;
979
980 err = -EINVAL;
b5a4257c 981 if (cmsg->cmsg_len != CMSG_LEN(sizeof(int)))
41a1f8ea 982 goto exit_f;
41a1f8ea
YH
983
984 tc = *(int *)CMSG_DATA(cmsg);
d0ee011f 985 if (tc < -1 || tc > 0xff)
41a1f8ea
YH
986 goto exit_f;
987
988 err = 0;
26879da5 989 ipc6->tclass = tc;
41a1f8ea 990
13b52cd4
BH
991 break;
992 }
993
994 case IPV6_DONTFRAG:
995 {
996 int df;
997
998 err = -EINVAL;
b5a4257c 999 if (cmsg->cmsg_len != CMSG_LEN(sizeof(int)))
13b52cd4 1000 goto exit_f;
13b52cd4
BH
1001
1002 df = *(int *)CMSG_DATA(cmsg);
1003 if (df < 0 || df > 1)
1004 goto exit_f;
1005
1006 err = 0;
26879da5 1007 ipc6->dontfrag = df;
13b52cd4 1008
41a1f8ea
YH
1009 break;
1010 }
1da177e4 1011 default:
ba7a46f1
JP
1012 net_dbg_ratelimited("invalid cmsg type: %d\n",
1013 cmsg->cmsg_type);
1da177e4 1014 err = -EINVAL;
4a36702e 1015 goto exit_f;
3ff50b79 1016 }
1da177e4
LT
1017 }
1018
1019exit_f:
1020 return err;
1021}
73df66f8 1022EXPORT_SYMBOL_GPL(ip6_datagram_send_ctl);
17ef66af
LC
1023
1024void ip6_dgram_sock_seq_show(struct seq_file *seq, struct sock *sp,
1025 __u16 srcp, __u16 destp, int bucket)
1026{
17ef66af
LC
1027 const struct in6_addr *dest, *src;
1028
efe4208f
ED
1029 dest = &sp->sk_v6_daddr;
1030 src = &sp->sk_v6_rcv_saddr;
17ef66af
LC
1031 seq_printf(seq,
1032 "%5d: %08X%08X%08X%08X:%04X %08X%08X%08X%08X:%04X "
d14c5ab6 1033 "%02X %08X:%08X %02X:%08lX %08X %5u %8d %lu %d %pK %d\n",
17ef66af
LC
1034 bucket,
1035 src->s6_addr32[0], src->s6_addr32[1],
1036 src->s6_addr32[2], src->s6_addr32[3], srcp,
1037 dest->s6_addr32[0], dest->s6_addr32[1],
1038 dest->s6_addr32[2], dest->s6_addr32[3], destp,
1039 sp->sk_state,
1040 sk_wmem_alloc_get(sp),
1041 sk_rmem_alloc_get(sp),
1042 0, 0L, 0,
1043 from_kuid_munged(seq_user_ns(seq), sock_i_uid(sp)),
1044 0,
1045 sock_i_ino(sp),
1046 atomic_read(&sp->sk_refcnt), sp,
1047 atomic_read(&sp->sk_drops));
1048}