Commit | Line | Data |
---|---|---|
2874c5fd | 1 | // SPDX-License-Identifier: GPL-2.0-or-later |
1da177e4 LT |
2 | /* |
3 | * RAW sockets for IPv6 | |
1ab1457c | 4 | * Linux INET6 implementation |
1da177e4 LT |
5 | * |
6 | * Authors: | |
1ab1457c | 7 | * Pedro Roque <roque@di.fc.ul.pt> |
1da177e4 LT |
8 | * |
9 | * Adapted from linux/net/ipv4/raw.c | |
10 | * | |
1da177e4 LT |
11 | * Fixes: |
12 | * Hideaki YOSHIFUJI : sin6_scope_id support | |
1ab1457c | 13 | * YOSHIFUJI,H.@USAGI : raw checksum (RFC2292(bis) compliance) |
1da177e4 | 14 | * Kazunori MIYAZAWA @USAGI: change process style to use ip6_append_data |
1da177e4 LT |
15 | */ |
16 | ||
17 | #include <linux/errno.h> | |
18 | #include <linux/types.h> | |
19 | #include <linux/socket.h> | |
5a0e3ad6 | 20 | #include <linux/slab.h> |
1da177e4 | 21 | #include <linux/sockios.h> |
1da177e4 LT |
22 | #include <linux/net.h> |
23 | #include <linux/in6.h> | |
24 | #include <linux/netdevice.h> | |
25 | #include <linux/if_arp.h> | |
26 | #include <linux/icmpv6.h> | |
27 | #include <linux/netfilter.h> | |
28 | #include <linux/netfilter_ipv6.h> | |
3305b80c | 29 | #include <linux/skbuff.h> |
e2d57766 | 30 | #include <linux/compat.h> |
29778bec | 31 | #include <linux/uaccess.h> |
1da177e4 LT |
32 | #include <asm/ioctls.h> |
33 | ||
457c4cbc | 34 | #include <net/net_namespace.h> |
1da177e4 LT |
35 | #include <net/ip.h> |
36 | #include <net/sock.h> | |
37 | #include <net/snmp.h> | |
38 | ||
39 | #include <net/ipv6.h> | |
40 | #include <net/ndisc.h> | |
41 | #include <net/protocol.h> | |
42 | #include <net/ip6_route.h> | |
43 | #include <net/ip6_checksum.h> | |
44 | #include <net/addrconf.h> | |
45 | #include <net/transp_v6.h> | |
46 | #include <net/udp.h> | |
47 | #include <net/inet_common.h> | |
c752f073 | 48 | #include <net/tcp_states.h> |
07a93626 | 49 | #if IS_ENABLED(CONFIG_IPV6_MIP6) |
7be96f76 MN |
50 | #include <net/mip6.h> |
51 | #endif | |
7bc570c8 | 52 | #include <linux/mroute6.h> |
1da177e4 | 53 | |
b673e4df | 54 | #include <net/raw.h> |
1da177e4 LT |
55 | #include <net/rawv6.h> |
56 | #include <net/xfrm.h> | |
57 | ||
58 | #include <linux/proc_fs.h> | |
59 | #include <linux/seq_file.h> | |
bc3b2d7f | 60 | #include <linux/export.h> |
1da177e4 | 61 | |
d1c53c8e WA |
62 | #define ICMPV6_HDRLEN 4 /* ICMPv6 header, RFC 4443 Section 2.1 */ |
63 | ||
0daf07e5 | 64 | struct raw_hashinfo raw_v6_hashinfo; |
432490f9 | 65 | EXPORT_SYMBOL_GPL(raw_v6_hashinfo); |
1da177e4 | 66 | |
db6af4fd | 67 | bool raw_v6_match(struct net *net, const struct sock *sk, unsigned short num, |
ba44f818 ED |
68 | const struct in6_addr *loc_addr, |
69 | const struct in6_addr *rmt_addr, int dif, int sdif) | |
1da177e4 | 70 | { |
ba44f818 ED |
71 | if (inet_sk(sk)->inet_num != num || |
72 | !net_eq(sock_net(sk), net) || | |
73 | (!ipv6_addr_any(&sk->sk_v6_daddr) && | |
74 | !ipv6_addr_equal(&sk->sk_v6_daddr, rmt_addr)) || | |
75 | !raw_sk_bound_dev_eq(net, sk->sk_bound_dev_if, | |
76 | dif, sdif)) | |
77 | return false; | |
78 | ||
79 | if (ipv6_addr_any(&sk->sk_v6_rcv_saddr) || | |
80 | ipv6_addr_equal(&sk->sk_v6_rcv_saddr, loc_addr) || | |
81 | (ipv6_addr_is_multicast(loc_addr) && | |
82 | inet6_mc_check(sk, loc_addr, rmt_addr))) | |
83 | return true; | |
84 | ||
85 | return false; | |
1da177e4 | 86 | } |
ba44f818 | 87 | EXPORT_SYMBOL_GPL(raw_v6_match); |
1da177e4 LT |
88 | |
89 | /* | |
90 | * 0 - deliver | |
91 | * 1 - block | |
92 | */ | |
1b05c4b5 | 93 | static int icmpv6_filter(const struct sock *sk, const struct sk_buff *skb) |
1da177e4 | 94 | { |
9cc08af3 | 95 | struct icmp6hdr _hdr; |
1b05c4b5 | 96 | const struct icmp6hdr *hdr; |
1da177e4 | 97 | |
d1c53c8e WA |
98 | /* We require only the four bytes of the ICMPv6 header, not any |
99 | * additional bytes of message body in "struct icmp6hdr". | |
100 | */ | |
1b05c4b5 | 101 | hdr = skb_header_pointer(skb, skb_transport_offset(skb), |
d1c53c8e | 102 | ICMPV6_HDRLEN, &_hdr); |
1b05c4b5 ED |
103 | if (hdr) { |
104 | const __u32 *data = &raw6_sk(sk)->filter.data[0]; | |
105 | unsigned int type = hdr->icmp6_type; | |
1da177e4 | 106 | |
1b05c4b5 | 107 | return (data[type >> 5] & (1U << (type & 31))) != 0; |
1da177e4 | 108 | } |
1b05c4b5 | 109 | return 1; |
1da177e4 LT |
110 | } |
111 | ||
07a93626 | 112 | #if IS_ENABLED(CONFIG_IPV6_MIP6) |
f2eda47d | 113 | typedef int mh_filter_t(struct sock *sock, struct sk_buff *skb); |
59fbb3a6 | 114 | |
f2eda47d ED |
115 | static mh_filter_t __rcu *mh_filter __read_mostly; |
116 | ||
117 | int rawv6_mh_filter_register(mh_filter_t filter) | |
59fbb3a6 | 118 | { |
cf778b00 | 119 | rcu_assign_pointer(mh_filter, filter); |
59fbb3a6 MN |
120 | return 0; |
121 | } | |
122 | EXPORT_SYMBOL(rawv6_mh_filter_register); | |
123 | ||
f2eda47d | 124 | int rawv6_mh_filter_unregister(mh_filter_t filter) |
59fbb3a6 | 125 | { |
a9b3cd7f | 126 | RCU_INIT_POINTER(mh_filter, NULL); |
59fbb3a6 MN |
127 | synchronize_rcu(); |
128 | return 0; | |
129 | } | |
130 | EXPORT_SYMBOL(rawv6_mh_filter_unregister); | |
131 | ||
132 | #endif | |
133 | ||
1da177e4 LT |
134 | /* |
135 | * demultiplex raw sockets. | |
136 | * (should consider queueing the skb in the sock receive_queue | |
137 | * without calling rawv6.c) | |
138 | * | |
139 | * Caller owns SKB so we must make clones. | |
140 | */ | |
a50feda5 | 141 | static bool ipv6_raw_deliver(struct sk_buff *skb, int nexthdr) |
1da177e4 | 142 | { |
ba44f818 | 143 | struct net *net = dev_net(skb->dev); |
b71d1d42 ED |
144 | const struct in6_addr *saddr; |
145 | const struct in6_addr *daddr; | |
0a78cf72 | 146 | struct hlist_head *hlist; |
1da177e4 | 147 | struct sock *sk; |
a50feda5 | 148 | bool delivered = false; |
1da177e4 LT |
149 | __u8 hash; |
150 | ||
0660e03f | 151 | saddr = &ipv6_hdr(skb)->saddr; |
1da177e4 LT |
152 | daddr = saddr + 1; |
153 | ||
6579f5ba | 154 | hash = raw_hashfunc(net, nexthdr); |
0daf07e5 ED |
155 | hlist = &raw_v6_hashinfo.ht[hash]; |
156 | rcu_read_lock(); | |
0a78cf72 | 157 | sk_for_each_rcu(sk, hlist) { |
7be96f76 MN |
158 | int filtered; |
159 | ||
ba44f818 ED |
160 | if (!raw_v6_match(net, sk, nexthdr, daddr, saddr, |
161 | inet6_iif(skb), inet6_sdif(skb))) | |
162 | continue; | |
a50feda5 | 163 | delivered = true; |
7be96f76 MN |
164 | switch (nexthdr) { |
165 | case IPPROTO_ICMPV6: | |
166 | filtered = icmpv6_filter(sk, skb); | |
167 | break; | |
59fbb3a6 | 168 | |
07a93626 | 169 | #if IS_ENABLED(CONFIG_IPV6_MIP6) |
7be96f76 | 170 | case IPPROTO_MH: |
59fbb3a6 | 171 | { |
7be96f76 MN |
172 | /* XXX: To validate MH only once for each packet, |
173 | * this is placed here. It should be after checking | |
174 | * xfrm policy, however it doesn't. The checking xfrm | |
175 | * policy is placed in rawv6_rcv() because it is | |
176 | * required for each socket. | |
177 | */ | |
f2eda47d | 178 | mh_filter_t *filter; |
59fbb3a6 MN |
179 | |
180 | filter = rcu_dereference(mh_filter); | |
f2eda47d | 181 | filtered = filter ? (*filter)(sk, skb) : 0; |
7be96f76 | 182 | break; |
59fbb3a6 | 183 | } |
7be96f76 MN |
184 | #endif |
185 | default: | |
186 | filtered = 0; | |
187 | break; | |
188 | } | |
189 | ||
190 | if (filtered < 0) | |
191 | break; | |
192 | if (filtered == 0) { | |
1da177e4 LT |
193 | struct sk_buff *clone = skb_clone(skb, GFP_ATOMIC); |
194 | ||
195 | /* Not releasing hash table! */ | |
b0e214d2 | 196 | if (clone) |
1da177e4 LT |
197 | rawv6_rcv(sk, clone); |
198 | } | |
1da177e4 | 199 | } |
0daf07e5 | 200 | rcu_read_unlock(); |
d13964f4 | 201 | return delivered; |
1da177e4 LT |
202 | } |
203 | ||
a50feda5 | 204 | bool raw6_local_deliver(struct sk_buff *skb, int nexthdr) |
69d6da0b | 205 | { |
ba44f818 | 206 | return ipv6_raw_deliver(skb, nexthdr); |
69d6da0b PE |
207 | } |
208 | ||
1da177e4 LT |
209 | /* This cleans up af_inet6 a bit. -DaveM */ |
210 | static int rawv6_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len) | |
211 | { | |
212 | struct inet_sock *inet = inet_sk(sk); | |
213 | struct ipv6_pinfo *np = inet6_sk(sk); | |
214 | struct sockaddr_in6 *addr = (struct sockaddr_in6 *) uaddr; | |
e69a4adc | 215 | __be32 v4addr = 0; |
1da177e4 LT |
216 | int addr_type; |
217 | int err; | |
218 | ||
219 | if (addr_len < SIN6_LEN_RFC2133) | |
220 | return -EINVAL; | |
82b276cd HFS |
221 | |
222 | if (addr->sin6_family != AF_INET6) | |
223 | return -EINVAL; | |
224 | ||
1da177e4 LT |
225 | addr_type = ipv6_addr_type(&addr->sin6_addr); |
226 | ||
227 | /* Raw sockets are IPv6 only */ | |
228 | if (addr_type == IPV6_ADDR_MAPPED) | |
fd5c0027 | 229 | return -EADDRNOTAVAIL; |
1da177e4 LT |
230 | |
231 | lock_sock(sk); | |
232 | ||
233 | err = -EINVAL; | |
234 | if (sk->sk_state != TCP_CLOSE) | |
235 | goto out; | |
236 | ||
fd5c0027 | 237 | rcu_read_lock(); |
1da177e4 LT |
238 | /* Check if the address belongs to the host. */ |
239 | if (addr_type != IPV6_ADDR_ANY) { | |
240 | struct net_device *dev = NULL; | |
241 | ||
842df073 | 242 | if (__ipv6_addr_needs_scope_id(addr_type)) { |
1da177e4 LT |
243 | if (addr_len >= sizeof(struct sockaddr_in6) && |
244 | addr->sin6_scope_id) { | |
245 | /* Override any existing binding, if another | |
246 | * one is supplied by user. | |
247 | */ | |
248 | sk->sk_bound_dev_if = addr->sin6_scope_id; | |
249 | } | |
1ab1457c | 250 | |
1da177e4 LT |
251 | /* Binding to link-local address requires an interface */ |
252 | if (!sk->sk_bound_dev_if) | |
fd5c0027 | 253 | goto out_unlock; |
72f7cfab | 254 | } |
1da177e4 | 255 | |
72f7cfab | 256 | if (sk->sk_bound_dev_if) { |
fd5c0027 ED |
257 | err = -ENODEV; |
258 | dev = dev_get_by_index_rcu(sock_net(sk), | |
259 | sk->sk_bound_dev_if); | |
260 | if (!dev) | |
261 | goto out_unlock; | |
1da177e4 | 262 | } |
1ab1457c | 263 | |
1da177e4 LT |
264 | /* ipv4 addr of the socket is invalid. Only the |
265 | * unspecified and mapped address have a v4 equivalent. | |
266 | */ | |
267 | v4addr = LOOPBACK4_IPV6; | |
35a256fe | 268 | if (!(addr_type & IPV6_ADDR_MULTICAST) && |
630e4576 | 269 | !ipv6_can_nonlocal_bind(sock_net(sk), inet)) { |
1da177e4 | 270 | err = -EADDRNOTAVAIL; |
3b1e0a65 | 271 | if (!ipv6_chk_addr(sock_net(sk), &addr->sin6_addr, |
bfeade08 | 272 | dev, 0)) { |
fd5c0027 | 273 | goto out_unlock; |
1da177e4 LT |
274 | } |
275 | } | |
1da177e4 LT |
276 | } |
277 | ||
c720c7e8 | 278 | inet->inet_rcv_saddr = inet->inet_saddr = v4addr; |
efe4208f | 279 | sk->sk_v6_rcv_saddr = addr->sin6_addr; |
1da177e4 | 280 | if (!(addr_type & IPV6_ADDR_MULTICAST)) |
4e3fd7a0 | 281 | np->saddr = addr->sin6_addr; |
1da177e4 | 282 | err = 0; |
fd5c0027 ED |
283 | out_unlock: |
284 | rcu_read_unlock(); | |
1da177e4 LT |
285 | out: |
286 | release_sock(sk); | |
287 | return err; | |
288 | } | |
289 | ||
69d6da0b | 290 | static void rawv6_err(struct sock *sk, struct sk_buff *skb, |
1da177e4 | 291 | struct inet6_skb_parm *opt, |
d5fdd6ba | 292 | u8 type, u8 code, int offset, __be32 info) |
1da177e4 LT |
293 | { |
294 | struct inet_sock *inet = inet_sk(sk); | |
295 | struct ipv6_pinfo *np = inet6_sk(sk); | |
296 | int err; | |
297 | int harderr; | |
298 | ||
299 | /* Report error on raw socket, if: | |
300 | 1. User requested recverr. | |
301 | 2. Socket is connected (otherwise the error indication | |
302 | is useless without recverr and error is hard. | |
303 | */ | |
304 | if (!np->recverr && sk->sk_state != TCP_ESTABLISHED) | |
305 | return; | |
306 | ||
307 | harderr = icmpv6_err_convert(type, code, &err); | |
81aded24 DM |
308 | if (type == ICMPV6_PKT_TOOBIG) { |
309 | ip6_sk_update_pmtu(skb, sk, info); | |
1da177e4 | 310 | harderr = (np->pmtudisc == IPV6_PMTUDISC_DO); |
81aded24 | 311 | } |
8d65b119 | 312 | if (type == NDISC_REDIRECT) { |
ec18d9a2 | 313 | ip6_sk_redirect(skb, sk); |
8d65b119 DJ |
314 | return; |
315 | } | |
1da177e4 LT |
316 | if (np->recverr) { |
317 | u8 *payload = skb->data; | |
318 | if (!inet->hdrincl) | |
319 | payload += offset; | |
320 | ipv6_icmp_error(sk, skb, err, 0, ntohl(info), payload); | |
321 | } | |
322 | ||
323 | if (np->recverr || harderr) { | |
324 | sk->sk_err = err; | |
e3ae2365 | 325 | sk_error_report(sk); |
1da177e4 LT |
326 | } |
327 | } | |
328 | ||
69d6da0b | 329 | void raw6_icmp_error(struct sk_buff *skb, int nexthdr, |
d5fdd6ba | 330 | u8 type, u8 code, int inner_offset, __be32 info) |
69d6da0b | 331 | { |
ba44f818 | 332 | struct net *net = dev_net(skb->dev); |
0a78cf72 | 333 | struct hlist_head *hlist; |
69d6da0b PE |
334 | struct sock *sk; |
335 | int hash; | |
69d6da0b | 336 | |
6579f5ba | 337 | hash = raw_hashfunc(net, nexthdr); |
0daf07e5 ED |
338 | hlist = &raw_v6_hashinfo.ht[hash]; |
339 | rcu_read_lock(); | |
0a78cf72 | 340 | sk_for_each_rcu(sk, hlist) { |
05f175cd | 341 | /* Note: ipv6_hdr(skb) != skb->data */ |
b71d1d42 | 342 | const struct ipv6hdr *ip6h = (const struct ipv6hdr *)skb->data; |
69d6da0b | 343 | |
ba44f818 ED |
344 | if (!raw_v6_match(net, sk, nexthdr, &ip6h->saddr, &ip6h->daddr, |
345 | inet6_iif(skb), inet6_iif(skb))) | |
346 | continue; | |
347 | rawv6_err(sk, skb, NULL, type, code, inner_offset, info); | |
69d6da0b | 348 | } |
0daf07e5 | 349 | rcu_read_unlock(); |
69d6da0b PE |
350 | } |
351 | ||
33d480ce | 352 | static inline int rawv6_rcv_skb(struct sock *sk, struct sk_buff *skb) |
1da177e4 | 353 | { |
8d8ebd77 ED |
354 | enum skb_drop_reason reason; |
355 | ||
33d480ce | 356 | if ((raw6_sk(sk)->checksum || rcu_access_pointer(sk->sk_filter)) && |
fb286bb2 | 357 | skb_checksum_complete(skb)) { |
a92aa318 | 358 | atomic_inc(&sk->sk_drops); |
8d8ebd77 | 359 | kfree_skb_reason(skb, SKB_DROP_REASON_SKB_CSUM); |
3cc76caa | 360 | return NET_RX_DROP; |
1da177e4 LT |
361 | } |
362 | ||
363 | /* Charge it to the socket. */ | |
d826eb14 | 364 | skb_dst_drop(skb); |
8d8ebd77 ED |
365 | if (sock_queue_rcv_skb_reason(sk, skb, &reason) < 0) { |
366 | kfree_skb_reason(skb, reason); | |
3cc76caa | 367 | return NET_RX_DROP; |
1da177e4 LT |
368 | } |
369 | ||
370 | return 0; | |
371 | } | |
372 | ||
373 | /* | |
1ab1457c | 374 | * This is next to useless... |
1da177e4 | 375 | * if we demultiplex in network layer we don't need the extra call |
1ab1457c YH |
376 | * just to queue the skb... |
377 | * maybe we could have the network decide upon a hint if it | |
1da177e4 LT |
378 | * should call raw_rcv for demultiplexing |
379 | */ | |
380 | int rawv6_rcv(struct sock *sk, struct sk_buff *skb) | |
381 | { | |
382 | struct inet_sock *inet = inet_sk(sk); | |
383 | struct raw6_sock *rp = raw6_sk(sk); | |
384 | ||
1ab1457c | 385 | if (!xfrm6_policy_check(sk, XFRM_POLICY_IN, skb)) { |
a92aa318 | 386 | atomic_inc(&sk->sk_drops); |
8d8ebd77 | 387 | kfree_skb_reason(skb, SKB_DROP_REASON_XFRM_POLICY); |
1ab1457c YH |
388 | return NET_RX_DROP; |
389 | } | |
b0e214d2 | 390 | nf_reset_ct(skb); |
1da177e4 LT |
391 | |
392 | if (!rp->checksum) | |
393 | skb->ip_summed = CHECKSUM_UNNECESSARY; | |
394 | ||
84fa7933 | 395 | if (skb->ip_summed == CHECKSUM_COMPLETE) { |
d56f90a7 | 396 | skb_postpull_rcsum(skb, skb_network_header(skb), |
cfe1fc77 | 397 | skb_network_header_len(skb)); |
0660e03f ACM |
398 | if (!csum_ipv6_magic(&ipv6_hdr(skb)->saddr, |
399 | &ipv6_hdr(skb)->daddr, | |
c720c7e8 | 400 | skb->len, inet->inet_num, skb->csum)) |
1da177e4 | 401 | skb->ip_summed = CHECKSUM_UNNECESSARY; |
1da177e4 | 402 | } |
60476372 | 403 | if (!skb_csum_unnecessary(skb)) |
0660e03f ACM |
404 | skb->csum = ~csum_unfold(csum_ipv6_magic(&ipv6_hdr(skb)->saddr, |
405 | &ipv6_hdr(skb)->daddr, | |
406 | skb->len, | |
c720c7e8 | 407 | inet->inet_num, 0)); |
1da177e4 LT |
408 | |
409 | if (inet->hdrincl) { | |
fb286bb2 | 410 | if (skb_checksum_complete(skb)) { |
a92aa318 | 411 | atomic_inc(&sk->sk_drops); |
8d8ebd77 | 412 | kfree_skb_reason(skb, SKB_DROP_REASON_SKB_CSUM); |
3cc76caa | 413 | return NET_RX_DROP; |
1da177e4 | 414 | } |
1da177e4 LT |
415 | } |
416 | ||
417 | rawv6_rcv_skb(sk, skb); | |
418 | return 0; | |
419 | } | |
420 | ||
421 | ||
422 | /* | |
423 | * This should be easy, if there is something there | |
424 | * we return it, otherwise we block. | |
425 | */ | |
426 | ||
1b784140 | 427 | static int rawv6_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, |
ec095263 | 428 | int flags, int *addr_len) |
1da177e4 LT |
429 | { |
430 | struct ipv6_pinfo *np = inet6_sk(sk); | |
342dfc30 | 431 | DECLARE_SOCKADDR(struct sockaddr_in6 *, sin6, msg->msg_name); |
1da177e4 LT |
432 | struct sk_buff *skb; |
433 | size_t copied; | |
434 | int err; | |
435 | ||
436 | if (flags & MSG_OOB) | |
437 | return -EOPNOTSUPP; | |
1ab1457c | 438 | |
1da177e4 | 439 | if (flags & MSG_ERRQUEUE) |
85fbaa75 | 440 | return ipv6_recv_error(sk, msg, len, addr_len); |
1da177e4 | 441 | |
4b340ae2 | 442 | if (np->rxpmtu && np->rxopt.bits.rxpmtu) |
85fbaa75 | 443 | return ipv6_recv_rxpmtu(sk, msg, len, addr_len); |
4b340ae2 | 444 | |
f4b41f06 | 445 | skb = skb_recv_datagram(sk, flags, &err); |
1da177e4 LT |
446 | if (!skb) |
447 | goto out; | |
448 | ||
449 | copied = skb->len; | |
1ab1457c YH |
450 | if (copied > len) { |
451 | copied = len; | |
452 | msg->msg_flags |= MSG_TRUNC; | |
453 | } | |
1da177e4 | 454 | |
60476372 | 455 | if (skb_csum_unnecessary(skb)) { |
51f3d02b | 456 | err = skb_copy_datagram_msg(skb, 0, msg, copied); |
1da177e4 | 457 | } else if (msg->msg_flags&MSG_TRUNC) { |
fb286bb2 | 458 | if (__skb_checksum_complete(skb)) |
1da177e4 | 459 | goto csum_copy_err; |
51f3d02b | 460 | err = skb_copy_datagram_msg(skb, 0, msg, copied); |
1da177e4 | 461 | } else { |
227158db | 462 | err = skb_copy_and_csum_datagram_msg(skb, 0, msg); |
1da177e4 LT |
463 | if (err == -EINVAL) |
464 | goto csum_copy_err; | |
465 | } | |
466 | if (err) | |
467 | goto out_free; | |
468 | ||
469 | /* Copy the address. */ | |
470 | if (sin6) { | |
471 | sin6->sin6_family = AF_INET6; | |
f59fc7f3 | 472 | sin6->sin6_port = 0; |
4e3fd7a0 | 473 | sin6->sin6_addr = ipv6_hdr(skb)->saddr; |
1da177e4 | 474 | sin6->sin6_flowinfo = 0; |
842df073 | 475 | sin6->sin6_scope_id = ipv6_iface_scope_id(&sin6->sin6_addr, |
4330487a | 476 | inet6_iif(skb)); |
bceaa902 | 477 | *addr_len = sizeof(*sin6); |
1da177e4 LT |
478 | } |
479 | ||
6fd1d51c | 480 | sock_recv_cmsgs(msg, sk, skb); |
1da177e4 LT |
481 | |
482 | if (np->rxopt.all) | |
73df66f8 | 483 | ip6_datagram_recv_ctl(sk, msg, skb); |
1da177e4 LT |
484 | |
485 | err = copied; | |
486 | if (flags & MSG_TRUNC) | |
487 | err = skb->len; | |
488 | ||
489 | out_free: | |
490 | skb_free_datagram(sk, skb); | |
491 | out: | |
492 | return err; | |
493 | ||
494 | csum_copy_err: | |
3305b80c | 495 | skb_kill_datagram(sk, skb, flags); |
1da177e4 LT |
496 | |
497 | /* Error for blocking case is chosen to masquerade | |
498 | as some normal condition. | |
499 | */ | |
500 | err = (flags&MSG_DONTWAIT) ? -EAGAIN : -EHOSTUNREACH; | |
3305b80c | 501 | goto out; |
1da177e4 LT |
502 | } |
503 | ||
4c9483b2 | 504 | static int rawv6_push_pending_frames(struct sock *sk, struct flowi6 *fl6, |
357b40a1 | 505 | struct raw6_sock *rp) |
1da177e4 | 506 | { |
cb3e9864 | 507 | struct ipv6_txoptions *opt; |
1da177e4 LT |
508 | struct sk_buff *skb; |
509 | int err = 0; | |
357b40a1 HX |
510 | int offset; |
511 | int len; | |
679a8738 | 512 | int total_len; |
868c86bc AV |
513 | __wsum tmp_csum; |
514 | __sum16 csum; | |
1da177e4 LT |
515 | |
516 | if (!rp->checksum) | |
517 | goto send; | |
518 | ||
43728fa5 FF |
519 | skb = skb_peek(&sk->sk_write_queue); |
520 | if (!skb) | |
1da177e4 LT |
521 | goto out; |
522 | ||
357b40a1 | 523 | offset = rp->offset; |
299b0767 | 524 | total_len = inet_sk(sk)->cork.base.length; |
cb3e9864 HX |
525 | opt = inet6_sk(sk)->cork.opt; |
526 | total_len -= opt ? opt->opt_flen : 0; | |
527 | ||
679a8738 | 528 | if (offset >= total_len - 1) { |
1da177e4 | 529 | err = -EINVAL; |
357b40a1 | 530 | ip6_flush_pending_frames(sk); |
1da177e4 LT |
531 | goto out; |
532 | } | |
533 | ||
534 | /* should be check HW csum miyazawa */ | |
535 | if (skb_queue_len(&sk->sk_write_queue) == 1) { | |
536 | /* | |
537 | * Only one fragment on the socket. | |
538 | */ | |
539 | tmp_csum = skb->csum; | |
540 | } else { | |
357b40a1 | 541 | struct sk_buff *csum_skb = NULL; |
1da177e4 LT |
542 | tmp_csum = 0; |
543 | ||
544 | skb_queue_walk(&sk->sk_write_queue, skb) { | |
545 | tmp_csum = csum_add(tmp_csum, skb->csum); | |
357b40a1 HX |
546 | |
547 | if (csum_skb) | |
548 | continue; | |
549 | ||
ea2ae17d | 550 | len = skb->len - skb_transport_offset(skb); |
357b40a1 HX |
551 | if (offset >= len) { |
552 | offset -= len; | |
553 | continue; | |
554 | } | |
555 | ||
556 | csum_skb = skb; | |
1da177e4 | 557 | } |
357b40a1 HX |
558 | |
559 | skb = csum_skb; | |
1da177e4 LT |
560 | } |
561 | ||
ea2ae17d | 562 | offset += skb_transport_offset(skb); |
a98f9175 DJ |
563 | err = skb_copy_bits(skb, offset, &csum, 2); |
564 | if (err < 0) { | |
565 | ip6_flush_pending_frames(sk); | |
566 | goto out; | |
567 | } | |
357b40a1 | 568 | |
1da177e4 | 569 | /* in case cksum was not initialized */ |
357b40a1 | 570 | if (unlikely(csum)) |
5f92a738 | 571 | tmp_csum = csum_sub(tmp_csum, csum_unfold(csum)); |
357b40a1 | 572 | |
4c9483b2 DM |
573 | csum = csum_ipv6_magic(&fl6->saddr, &fl6->daddr, |
574 | total_len, fl6->flowi6_proto, tmp_csum); | |
357b40a1 | 575 | |
4c9483b2 | 576 | if (csum == 0 && fl6->flowi6_proto == IPPROTO_UDP) |
f6ab0288 | 577 | csum = CSUM_MANGLED_0; |
1da177e4 | 578 | |
8242fc33 | 579 | BUG_ON(skb_store_bits(skb, offset, &csum, 2)); |
1da177e4 | 580 | |
1da177e4 LT |
581 | send: |
582 | err = ip6_push_pending_frames(sk); | |
583 | out: | |
584 | return err; | |
585 | } | |
586 | ||
c3c1a7db | 587 | static int rawv6_send_hdrinc(struct sock *sk, struct msghdr *msg, int length, |
4c9483b2 | 588 | struct flowi6 *fl6, struct dst_entry **dstp, |
a818f75e | 589 | unsigned int flags, const struct sockcm_cookie *sockc) |
1da177e4 | 590 | { |
3320da89 | 591 | struct ipv6_pinfo *np = inet6_sk(sk); |
adb28c9d | 592 | struct net *net = sock_net(sk); |
1da177e4 LT |
593 | struct ipv6hdr *iph; |
594 | struct sk_buff *skb; | |
1da177e4 | 595 | int err; |
1789a640 | 596 | struct rt6_info *rt = (struct rt6_info *)*dstp; |
a7ae1992 HX |
597 | int hlen = LL_RESERVED_SPACE(rt->dst.dev); |
598 | int tlen = rt->dst.dev->needed_tailroom; | |
1da177e4 | 599 | |
d8d1f30b | 600 | if (length > rt->dst.dev->mtu) { |
4c9483b2 | 601 | ipv6_local_error(sk, EMSGSIZE, fl6, rt->dst.dev->mtu); |
1da177e4 LT |
602 | return -EMSGSIZE; |
603 | } | |
86f4c90a AP |
604 | if (length < sizeof(struct ipv6hdr)) |
605 | return -EINVAL; | |
1da177e4 LT |
606 | if (flags&MSG_PROBE) |
607 | goto out; | |
608 | ||
f5184d26 | 609 | skb = sock_alloc_send_skb(sk, |
a7ae1992 | 610 | length + hlen + tlen + 15, |
f5184d26 | 611 | flags & MSG_DONTWAIT, &err); |
63159f29 | 612 | if (!skb) |
1ab1457c | 613 | goto error; |
a7ae1992 | 614 | skb_reserve(skb, hlen); |
1da177e4 | 615 | |
9c9c9ad5 | 616 | skb->protocol = htons(ETH_P_IPV6); |
8bf43be7 | 617 | skb->priority = READ_ONCE(sk->sk_priority); |
c6af0c22 | 618 | skb->mark = sockc->mark; |
a818f75e | 619 | skb->tstamp = sockc->transmit_time; |
1da177e4 | 620 | |
1ced98e8 ACM |
621 | skb_put(skb, length); |
622 | skb_reset_network_header(skb); | |
0660e03f | 623 | iph = ipv6_hdr(skb); |
1da177e4 LT |
624 | |
625 | skb->ip_summed = CHECKSUM_NONE; | |
626 | ||
8f932f76 | 627 | skb_setup_tx_timestamp(skb, sockc->tsflags); |
fbfb2321 | 628 | |
0dec879f JA |
629 | if (flags & MSG_CONFIRM) |
630 | skb_set_dst_pending_confirm(skb, 1); | |
631 | ||
b0e380b1 | 632 | skb->transport_header = skb->network_header; |
21226abb | 633 | err = memcpy_from_msg(iph, msg, length); |
a688caa3 WW |
634 | if (err) { |
635 | err = -EFAULT; | |
636 | kfree_skb(skb); | |
637 | goto error; | |
638 | } | |
639 | ||
640 | skb_dst_set(skb, &rt->dst); | |
641 | *dstp = NULL; | |
1da177e4 | 642 | |
a8e3e1a9 DA |
643 | /* if egress device is enslaved to an L3 master device pass the |
644 | * skb to its handler for processing | |
645 | */ | |
646 | skb = l3mdev_ip6_out(sk, skb); | |
647 | if (unlikely(!skb)) | |
648 | return 0; | |
649 | ||
a688caa3 WW |
650 | /* Acquire rcu_read_lock() in case we need to use rt->rt6i_idev |
651 | * in the error path. Since skb has been freed, the dst could | |
652 | * have been queued for deletion. | |
653 | */ | |
654 | rcu_read_lock(); | |
adb28c9d | 655 | IP6_UPD_PO_STATS(net, rt->rt6i_idev, IPSTATS_MIB_OUT, skb->len); |
29a26a56 | 656 | err = NF_HOOK(NFPROTO_IPV6, NF_INET_LOCAL_OUT, net, sk, skb, |
13206b6b | 657 | NULL, rt->dst.dev, dst_output); |
1da177e4 | 658 | if (err > 0) |
6ce9e7b5 | 659 | err = net_xmit_errno(err); |
a688caa3 WW |
660 | if (err) { |
661 | IP6_INC_STATS(net, rt->rt6i_idev, IPSTATS_MIB_OUTDISCARDS); | |
662 | rcu_read_unlock(); | |
663 | goto error_check; | |
664 | } | |
665 | rcu_read_unlock(); | |
1da177e4 LT |
666 | out: |
667 | return 0; | |
668 | ||
1da177e4 | 669 | error: |
adb28c9d | 670 | IP6_INC_STATS(net, rt->rt6i_idev, IPSTATS_MIB_OUTDISCARDS); |
a688caa3 | 671 | error_check: |
6ce9e7b5 ED |
672 | if (err == -ENOBUFS && !np->recverr) |
673 | err = 0; | |
1ab1457c | 674 | return err; |
1da177e4 LT |
675 | } |
676 | ||
19e3c66b AV |
677 | struct raw6_frag_vec { |
678 | struct msghdr *msg; | |
679 | int hlen; | |
680 | char c[4]; | |
681 | }; | |
682 | ||
683 | static int rawv6_probe_proto_opt(struct raw6_frag_vec *rfv, struct flowi6 *fl6) | |
1da177e4 | 684 | { |
19e3c66b AV |
685 | int err = 0; |
686 | switch (fl6->flowi6_proto) { | |
687 | case IPPROTO_ICMPV6: | |
688 | rfv->hlen = 2; | |
689 | err = memcpy_from_msg(rfv->c, rfv->msg, rfv->hlen); | |
690 | if (!err) { | |
691 | fl6->fl6_icmp_type = rfv->c[0]; | |
692 | fl6->fl6_icmp_code = rfv->c[1]; | |
693 | } | |
694 | break; | |
695 | case IPPROTO_MH: | |
696 | rfv->hlen = 4; | |
697 | err = memcpy_from_msg(rfv->c, rfv->msg, rfv->hlen); | |
698 | if (!err) | |
699 | fl6->fl6_mh_type = rfv->c[2]; | |
700 | } | |
701 | return err; | |
702 | } | |
1da177e4 | 703 | |
19e3c66b AV |
704 | static int raw6_getfrag(void *from, char *to, int offset, int len, int odd, |
705 | struct sk_buff *skb) | |
706 | { | |
707 | struct raw6_frag_vec *rfv = from; | |
708 | ||
709 | if (offset < rfv->hlen) { | |
710 | int copy = min(rfv->hlen - offset, len); | |
711 | ||
712 | if (skb->ip_summed == CHECKSUM_PARTIAL) | |
713 | memcpy(to, rfv->c + offset, copy); | |
714 | else | |
715 | skb->csum = csum_block_add( | |
716 | skb->csum, | |
717 | csum_partial_copy_nocheck(rfv->c + offset, | |
cc44c17b | 718 | to, copy), |
19e3c66b AV |
719 | odd); |
720 | ||
721 | odd = 0; | |
722 | offset += copy; | |
723 | to += copy; | |
724 | len -= copy; | |
725 | ||
726 | if (!len) | |
727 | return 0; | |
728 | } | |
1da177e4 | 729 | |
19e3c66b | 730 | offset -= rfv->hlen; |
6e8f4d48 | 731 | |
f69e6d13 | 732 | return ip_generic_getfrag(rfv->msg, to, offset, len, odd, skb); |
1da177e4 LT |
733 | } |
734 | ||
1b784140 | 735 | static int rawv6_sendmsg(struct sock *sk, struct msghdr *msg, size_t len) |
1da177e4 | 736 | { |
45f6fad8 | 737 | struct ipv6_txoptions *opt_to_free = NULL; |
1da177e4 | 738 | struct ipv6_txoptions opt_space; |
342dfc30 | 739 | DECLARE_SOCKADDR(struct sockaddr_in6 *, sin6, msg->msg_name); |
20c59de2 | 740 | struct in6_addr *daddr, *final_p, final; |
1da177e4 LT |
741 | struct inet_sock *inet = inet_sk(sk); |
742 | struct ipv6_pinfo *np = inet6_sk(sk); | |
743 | struct raw6_sock *rp = raw6_sk(sk); | |
744 | struct ipv6_txoptions *opt = NULL; | |
745 | struct ip6_flowlabel *flowlabel = NULL; | |
746 | struct dst_entry *dst = NULL; | |
19e3c66b | 747 | struct raw6_frag_vec rfv; |
4c9483b2 | 748 | struct flowi6 fl6; |
26879da5 | 749 | struct ipcm6_cookie ipc6; |
1da177e4 | 750 | int addr_len = msg->msg_namelen; |
59e3e4b5 | 751 | int hdrincl; |
1da177e4 LT |
752 | u16 proto; |
753 | int err; | |
754 | ||
755 | /* Rough check on arithmetic overflow, | |
b59e139b | 756 | better check is made in ip6_append_data(). |
1da177e4 | 757 | */ |
b59e139b | 758 | if (len > INT_MAX) |
1da177e4 LT |
759 | return -EMSGSIZE; |
760 | ||
761 | /* Mirror BSD error message compatibility */ | |
1ab1457c | 762 | if (msg->msg_flags & MSG_OOB) |
1da177e4 LT |
763 | return -EOPNOTSUPP; |
764 | ||
59e3e4b5 OM |
765 | /* hdrincl should be READ_ONCE(inet->hdrincl) |
766 | * but READ_ONCE() doesn't work with bit fields. | |
767 | * Doing this indirectly yields the same result. | |
768 | */ | |
769 | hdrincl = inet->hdrincl; | |
770 | hdrincl = READ_ONCE(hdrincl); | |
771 | ||
1da177e4 | 772 | /* |
1ab1457c | 773 | * Get and verify the address. |
1da177e4 | 774 | */ |
4c9483b2 | 775 | memset(&fl6, 0, sizeof(fl6)); |
1da177e4 | 776 | |
3c5b4d69 | 777 | fl6.flowi6_mark = READ_ONCE(sk->sk_mark); |
e2d118a1 | 778 | fl6.flowi6_uid = sk->sk_uid; |
4a19ec58 | 779 | |
b515430a | 780 | ipcm6_init(&ipc6); |
5fdaa88d | 781 | ipc6.sockc.tsflags = sk->sk_tsflags; |
3c5b4d69 | 782 | ipc6.sockc.mark = fl6.flowi6_mark; |
26879da5 | 783 | |
1da177e4 | 784 | if (sin6) { |
1ab1457c | 785 | if (addr_len < SIN6_LEN_RFC2133) |
1da177e4 LT |
786 | return -EINVAL; |
787 | ||
1ab1457c | 788 | if (sin6->sin6_family && sin6->sin6_family != AF_INET6) |
a02cec21 | 789 | return -EAFNOSUPPORT; |
1da177e4 LT |
790 | |
791 | /* port is the proto value [0..255] carried in nexthdr */ | |
792 | proto = ntohs(sin6->sin6_port); | |
793 | ||
794 | if (!proto) | |
c720c7e8 | 795 | proto = inet->inet_num; |
3632679d ND |
796 | else if (proto != inet->inet_num && |
797 | inet->inet_num != IPPROTO_RAW) | |
a02cec21 | 798 | return -EINVAL; |
1da177e4 LT |
799 | |
800 | if (proto > 255) | |
a02cec21 | 801 | return -EINVAL; |
1da177e4 LT |
802 | |
803 | daddr = &sin6->sin6_addr; | |
804 | if (np->sndflow) { | |
4c9483b2 DM |
805 | fl6.flowlabel = sin6->sin6_flowinfo&IPV6_FLOWINFO_MASK; |
806 | if (fl6.flowlabel&IPV6_FLOWLABEL_MASK) { | |
807 | flowlabel = fl6_sock_lookup(sk, fl6.flowlabel); | |
59c820b2 | 808 | if (IS_ERR(flowlabel)) |
1da177e4 | 809 | return -EINVAL; |
1da177e4 LT |
810 | } |
811 | } | |
812 | ||
813 | /* | |
814 | * Otherwise it will be difficult to maintain | |
815 | * sk->sk_dst_cache. | |
816 | */ | |
817 | if (sk->sk_state == TCP_ESTABLISHED && | |
efe4208f ED |
818 | ipv6_addr_equal(daddr, &sk->sk_v6_daddr)) |
819 | daddr = &sk->sk_v6_daddr; | |
1da177e4 LT |
820 | |
821 | if (addr_len >= sizeof(struct sockaddr_in6) && | |
822 | sin6->sin6_scope_id && | |
842df073 | 823 | __ipv6_addr_needs_scope_id(__ipv6_addr_type(daddr))) |
4c9483b2 | 824 | fl6.flowi6_oif = sin6->sin6_scope_id; |
1da177e4 | 825 | } else { |
1ab1457c | 826 | if (sk->sk_state != TCP_ESTABLISHED) |
1da177e4 | 827 | return -EDESTADDRREQ; |
1ab1457c | 828 | |
c720c7e8 | 829 | proto = inet->inet_num; |
efe4208f | 830 | daddr = &sk->sk_v6_daddr; |
4c9483b2 | 831 | fl6.flowlabel = np->flow_label; |
1da177e4 LT |
832 | } |
833 | ||
4c9483b2 DM |
834 | if (fl6.flowi6_oif == 0) |
835 | fl6.flowi6_oif = sk->sk_bound_dev_if; | |
1da177e4 LT |
836 | |
837 | if (msg->msg_controllen) { | |
838 | opt = &opt_space; | |
839 | memset(opt, 0, sizeof(struct ipv6_txoptions)); | |
840 | opt->tot_len = sizeof(struct ipv6_txoptions); | |
26879da5 | 841 | ipc6.opt = opt; |
1da177e4 | 842 | |
5fdaa88d | 843 | err = ip6_datagram_send_ctl(sock_net(sk), sk, msg, &fl6, &ipc6); |
1da177e4 LT |
844 | if (err < 0) { |
845 | fl6_sock_release(flowlabel); | |
846 | return err; | |
847 | } | |
4c9483b2 DM |
848 | if ((fl6.flowlabel&IPV6_FLOWLABEL_MASK) && !flowlabel) { |
849 | flowlabel = fl6_sock_lookup(sk, fl6.flowlabel); | |
59c820b2 | 850 | if (IS_ERR(flowlabel)) |
1da177e4 LT |
851 | return -EINVAL; |
852 | } | |
853 | if (!(opt->opt_nflen|opt->opt_flen)) | |
854 | opt = NULL; | |
855 | } | |
45f6fad8 ED |
856 | if (!opt) { |
857 | opt = txopt_get(np); | |
858 | opt_to_free = opt; | |
26879da5 | 859 | } |
df9890c3 YH |
860 | if (flowlabel) |
861 | opt = fl6_merge_options(&opt_space, flowlabel, opt); | |
862 | opt = ipv6_fixup_options(&opt_space, opt); | |
1da177e4 | 863 | |
4c9483b2 | 864 | fl6.flowi6_proto = proto; |
c6af0c22 | 865 | fl6.flowi6_mark = ipc6.sockc.mark; |
b9aa52c4 OM |
866 | |
867 | if (!hdrincl) { | |
868 | rfv.msg = msg; | |
869 | rfv.hlen = 0; | |
870 | err = rawv6_probe_proto_opt(&rfv, &fl6); | |
871 | if (err) | |
872 | goto out; | |
873 | } | |
1ab1457c | 874 | |
876c7f41 | 875 | if (!ipv6_addr_any(daddr)) |
4e3fd7a0 | 876 | fl6.daddr = *daddr; |
876c7f41 | 877 | else |
4c9483b2 DM |
878 | fl6.daddr.s6_addr[15] = 0x1; /* :: means loopback (BSD'ism) */ |
879 | if (ipv6_addr_any(&fl6.saddr) && !ipv6_addr_any(&np->saddr)) | |
4e3fd7a0 | 880 | fl6.saddr = np->saddr; |
1da177e4 | 881 | |
4c9483b2 | 882 | final_p = fl6_update_dst(&fl6, opt, &final); |
1da177e4 | 883 | |
4c9483b2 DM |
884 | if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr)) |
885 | fl6.flowi6_oif = np->mcast_oif; | |
c4062dfc EH |
886 | else if (!fl6.flowi6_oif) |
887 | fl6.flowi6_oif = np->ucast_oif; | |
3df98d79 | 888 | security_sk_classify_flow(sk, flowi6_to_flowi_common(&fl6)); |
1da177e4 | 889 | |
59e3e4b5 | 890 | if (hdrincl) |
48e8aa6e MKL |
891 | fl6.flowi6_flags |= FLOWI_FLAG_KNOWN_NH; |
892 | ||
38b7097b HFS |
893 | if (ipc6.tclass < 0) |
894 | ipc6.tclass = np->tclass; | |
895 | ||
896 | fl6.flowlabel = ip6_make_flowinfo(ipc6.tclass, fl6.flowlabel); | |
897 | ||
c4e85f73 | 898 | dst = ip6_dst_lookup_flow(sock_net(sk), sk, &fl6, final_p); |
68d0c6d3 DM |
899 | if (IS_ERR(dst)) { |
900 | err = PTR_ERR(dst); | |
1da177e4 | 901 | goto out; |
14e50e57 | 902 | } |
26879da5 WW |
903 | if (ipc6.hlimit < 0) |
904 | ipc6.hlimit = ip6_sk_dst_hoplimit(np, &fl6, dst); | |
1da177e4 | 905 | |
26879da5 WW |
906 | if (ipc6.dontfrag < 0) |
907 | ipc6.dontfrag = np->dontfrag; | |
13b52cd4 | 908 | |
1da177e4 LT |
909 | if (msg->msg_flags&MSG_CONFIRM) |
910 | goto do_confirm; | |
911 | ||
912 | back_from_confirm: | |
59e3e4b5 | 913 | if (hdrincl) |
a818f75e | 914 | err = rawv6_send_hdrinc(sk, msg, len, &fl6, &dst, |
5fdaa88d | 915 | msg->msg_flags, &ipc6.sockc); |
1789a640 | 916 | else { |
26879da5 | 917 | ipc6.opt = opt; |
1da177e4 | 918 | lock_sock(sk); |
19e3c66b | 919 | err = ip6_append_data(sk, raw6_getfrag, &rfv, |
26879da5 | 920 | len, 0, &ipc6, &fl6, (struct rt6_info *)dst, |
5fdaa88d | 921 | msg->msg_flags); |
1da177e4 LT |
922 | |
923 | if (err) | |
924 | ip6_flush_pending_frames(sk); | |
925 | else if (!(msg->msg_flags & MSG_MORE)) | |
4c9483b2 | 926 | err = rawv6_push_pending_frames(sk, &fl6, rp); |
3ef9d943 | 927 | release_sock(sk); |
1da177e4 LT |
928 | } |
929 | done: | |
6d3e85ec | 930 | dst_release(dst); |
1ab1457c | 931 | out: |
1da177e4 | 932 | fl6_sock_release(flowlabel); |
45f6fad8 | 933 | txopt_put(opt_to_free); |
67ba4152 | 934 | return err < 0 ? err : len; |
1da177e4 | 935 | do_confirm: |
0dec879f JA |
936 | if (msg->msg_flags & MSG_PROBE) |
937 | dst_confirm_neigh(dst, &fl6.daddr); | |
1da177e4 LT |
938 | if (!(msg->msg_flags & MSG_PROBE) || len) |
939 | goto back_from_confirm; | |
940 | err = 0; | |
941 | goto done; | |
942 | } | |
943 | ||
1ab1457c | 944 | static int rawv6_seticmpfilter(struct sock *sk, int level, int optname, |
a7b75c5a | 945 | sockptr_t optval, int optlen) |
1da177e4 LT |
946 | { |
947 | switch (optname) { | |
948 | case ICMPV6_FILTER: | |
949 | if (optlen > sizeof(struct icmp6_filter)) | |
950 | optlen = sizeof(struct icmp6_filter); | |
a7b75c5a | 951 | if (copy_from_sockptr(&raw6_sk(sk)->filter, optval, optlen)) |
1da177e4 LT |
952 | return -EFAULT; |
953 | return 0; | |
954 | default: | |
955 | return -ENOPROTOOPT; | |
3ff50b79 | 956 | } |
1da177e4 LT |
957 | |
958 | return 0; | |
959 | } | |
960 | ||
1ab1457c | 961 | static int rawv6_geticmpfilter(struct sock *sk, int level, int optname, |
1da177e4 LT |
962 | char __user *optval, int __user *optlen) |
963 | { | |
964 | int len; | |
965 | ||
966 | switch (optname) { | |
967 | case ICMPV6_FILTER: | |
968 | if (get_user(len, optlen)) | |
969 | return -EFAULT; | |
970 | if (len < 0) | |
971 | return -EINVAL; | |
972 | if (len > sizeof(struct icmp6_filter)) | |
973 | len = sizeof(struct icmp6_filter); | |
974 | if (put_user(len, optlen)) | |
975 | return -EFAULT; | |
976 | if (copy_to_user(optval, &raw6_sk(sk)->filter, len)) | |
977 | return -EFAULT; | |
978 | return 0; | |
979 | default: | |
980 | return -ENOPROTOOPT; | |
3ff50b79 | 981 | } |
1da177e4 LT |
982 | |
983 | return 0; | |
984 | } | |
985 | ||
986 | ||
3fdadf7d | 987 | static int do_rawv6_setsockopt(struct sock *sk, int level, int optname, |
a7b75c5a | 988 | sockptr_t optval, unsigned int optlen) |
1da177e4 LT |
989 | { |
990 | struct raw6_sock *rp = raw6_sk(sk); | |
991 | int val; | |
992 | ||
fb7bc920 TD |
993 | if (optlen < sizeof(val)) |
994 | return -EINVAL; | |
995 | ||
a7b75c5a | 996 | if (copy_from_sockptr(&val, optval, sizeof(val))) |
1da177e4 LT |
997 | return -EFAULT; |
998 | ||
999 | switch (optname) { | |
715f504b HFS |
1000 | case IPV6_HDRINCL: |
1001 | if (sk->sk_type != SOCK_RAW) | |
1002 | return -EINVAL; | |
1003 | inet_sk(sk)->hdrincl = !!val; | |
1004 | return 0; | |
207ec0ab JP |
1005 | case IPV6_CHECKSUM: |
1006 | if (inet_sk(sk)->inet_num == IPPROTO_ICMPV6 && | |
1007 | level == IPPROTO_IPV6) { | |
1008 | /* | |
1009 | * RFC3542 tells that IPV6_CHECKSUM socket | |
1010 | * option in the IPPROTO_IPV6 level is not | |
1011 | * allowed on ICMPv6 sockets. | |
1012 | * If you want to set it, use IPPROTO_RAW | |
1013 | * level IPV6_CHECKSUM socket option | |
1014 | * (Linux extension). | |
1015 | */ | |
1016 | return -EINVAL; | |
1017 | } | |
1a98d05f | 1018 | |
207ec0ab JP |
1019 | /* You may get strange result with a positive odd offset; |
1020 | RFC2292bis agrees with me. */ | |
1021 | if (val > 0 && (val&1)) | |
1022 | return -EINVAL; | |
1023 | if (val < 0) { | |
1024 | rp->checksum = 0; | |
1025 | } else { | |
1026 | rp->checksum = 1; | |
1027 | rp->offset = val; | |
1028 | } | |
1da177e4 | 1029 | |
207ec0ab | 1030 | return 0; |
1da177e4 | 1031 | |
207ec0ab JP |
1032 | default: |
1033 | return -ENOPROTOOPT; | |
1da177e4 LT |
1034 | } |
1035 | } | |
1036 | ||
3fdadf7d | 1037 | static int rawv6_setsockopt(struct sock *sk, int level, int optname, |
a7b75c5a | 1038 | sockptr_t optval, unsigned int optlen) |
1da177e4 | 1039 | { |
207ec0ab JP |
1040 | switch (level) { |
1041 | case SOL_RAW: | |
1042 | break; | |
1da177e4 | 1043 | |
207ec0ab JP |
1044 | case SOL_ICMPV6: |
1045 | if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6) | |
1046 | return -EOPNOTSUPP; | |
1047 | return rawv6_seticmpfilter(sk, level, optname, optval, optlen); | |
1048 | case SOL_IPV6: | |
715f504b HFS |
1049 | if (optname == IPV6_CHECKSUM || |
1050 | optname == IPV6_HDRINCL) | |
207ec0ab | 1051 | break; |
a8eceea8 | 1052 | fallthrough; |
207ec0ab JP |
1053 | default: |
1054 | return ipv6_setsockopt(sk, level, optname, optval, optlen); | |
3ff50b79 SH |
1055 | } |
1056 | ||
3fdadf7d DM |
1057 | return do_rawv6_setsockopt(sk, level, optname, optval, optlen); |
1058 | } | |
1059 | ||
3fdadf7d DM |
1060 | static int do_rawv6_getsockopt(struct sock *sk, int level, int optname, |
1061 | char __user *optval, int __user *optlen) | |
1062 | { | |
1063 | struct raw6_sock *rp = raw6_sk(sk); | |
1064 | int val, len; | |
1da177e4 | 1065 | |
67ba4152 | 1066 | if (get_user(len, optlen)) |
1da177e4 LT |
1067 | return -EFAULT; |
1068 | ||
1069 | switch (optname) { | |
715f504b HFS |
1070 | case IPV6_HDRINCL: |
1071 | val = inet_sk(sk)->hdrincl; | |
1072 | break; | |
1da177e4 | 1073 | case IPV6_CHECKSUM: |
1a98d05f YH |
1074 | /* |
1075 | * We allow getsockopt() for IPPROTO_IPV6-level | |
1076 | * IPV6_CHECKSUM socket option on ICMPv6 sockets | |
1077 | * since RFC3542 is silent about it. | |
1078 | */ | |
1da177e4 LT |
1079 | if (rp->checksum == 0) |
1080 | val = -1; | |
1081 | else | |
1082 | val = rp->offset; | |
1083 | break; | |
1084 | ||
1085 | default: | |
1086 | return -ENOPROTOOPT; | |
1087 | } | |
1088 | ||
1089 | len = min_t(unsigned int, sizeof(int), len); | |
1090 | ||
1091 | if (put_user(len, optlen)) | |
1092 | return -EFAULT; | |
67ba4152 | 1093 | if (copy_to_user(optval, &val, len)) |
1da177e4 LT |
1094 | return -EFAULT; |
1095 | return 0; | |
1096 | } | |
1097 | ||
3fdadf7d DM |
1098 | static int rawv6_getsockopt(struct sock *sk, int level, int optname, |
1099 | char __user *optval, int __user *optlen) | |
1100 | { | |
207ec0ab JP |
1101 | switch (level) { |
1102 | case SOL_RAW: | |
1103 | break; | |
3fdadf7d | 1104 | |
207ec0ab JP |
1105 | case SOL_ICMPV6: |
1106 | if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6) | |
1107 | return -EOPNOTSUPP; | |
1108 | return rawv6_geticmpfilter(sk, level, optname, optval, optlen); | |
1109 | case SOL_IPV6: | |
715f504b HFS |
1110 | if (optname == IPV6_CHECKSUM || |
1111 | optname == IPV6_HDRINCL) | |
207ec0ab | 1112 | break; |
a8eceea8 | 1113 | fallthrough; |
207ec0ab JP |
1114 | default: |
1115 | return ipv6_getsockopt(sk, level, optname, optval, optlen); | |
3ff50b79 SH |
1116 | } |
1117 | ||
3fdadf7d DM |
1118 | return do_rawv6_getsockopt(sk, level, optname, optval, optlen); |
1119 | } | |
1120 | ||
e1d001fa | 1121 | static int rawv6_ioctl(struct sock *sk, int cmd, int *karg) |
1da177e4 | 1122 | { |
207ec0ab JP |
1123 | switch (cmd) { |
1124 | case SIOCOUTQ: { | |
e1d001fa BL |
1125 | *karg = sk_wmem_alloc_get(sk); |
1126 | return 0; | |
207ec0ab JP |
1127 | } |
1128 | case SIOCINQ: { | |
1129 | struct sk_buff *skb; | |
207ec0ab JP |
1130 | |
1131 | spin_lock_bh(&sk->sk_receive_queue.lock); | |
1132 | skb = skb_peek(&sk->sk_receive_queue); | |
53b24b8f | 1133 | if (skb) |
e1d001fa BL |
1134 | *karg = skb->len; |
1135 | else | |
1136 | *karg = 0; | |
207ec0ab | 1137 | spin_unlock_bh(&sk->sk_receive_queue.lock); |
e1d001fa | 1138 | return 0; |
207ec0ab | 1139 | } |
1da177e4 | 1140 | |
207ec0ab | 1141 | default: |
7bc570c8 | 1142 | #ifdef CONFIG_IPV6_MROUTE |
e1d001fa | 1143 | return ip6mr_ioctl(sk, cmd, karg); |
7bc570c8 | 1144 | #else |
207ec0ab | 1145 | return -ENOIOCTLCMD; |
7bc570c8 | 1146 | #endif |
1da177e4 LT |
1147 | } |
1148 | } | |
1149 | ||
e2d57766 DM |
1150 | #ifdef CONFIG_COMPAT |
1151 | static int compat_rawv6_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg) | |
1152 | { | |
1153 | switch (cmd) { | |
1154 | case SIOCOUTQ: | |
1155 | case SIOCINQ: | |
1156 | return -ENOIOCTLCMD; | |
1157 | default: | |
1158 | #ifdef CONFIG_IPV6_MROUTE | |
1159 | return ip6mr_compat_ioctl(sk, cmd, compat_ptr(arg)); | |
1160 | #else | |
1161 | return -ENOIOCTLCMD; | |
1162 | #endif | |
1163 | } | |
1164 | } | |
1165 | #endif | |
1166 | ||
1da177e4 LT |
1167 | static void rawv6_close(struct sock *sk, long timeout) |
1168 | { | |
c720c7e8 | 1169 | if (inet_sk(sk)->inet_num == IPPROTO_RAW) |
725a8ff0 | 1170 | ip6_ra_control(sk, -1); |
7bc570c8 | 1171 | ip6mr_sk_done(sk); |
1da177e4 LT |
1172 | sk_common_release(sk); |
1173 | } | |
1174 | ||
7d06b2e0 | 1175 | static void raw6_destroy(struct sock *sk) |
22dd4850 DL |
1176 | { |
1177 | lock_sock(sk); | |
1178 | ip6_flush_pending_frames(sk); | |
1179 | release_sock(sk); | |
22dd4850 DL |
1180 | } |
1181 | ||
1da177e4 LT |
1182 | static int rawv6_init_sk(struct sock *sk) |
1183 | { | |
f48d5ff1 MN |
1184 | struct raw6_sock *rp = raw6_sk(sk); |
1185 | ||
c720c7e8 | 1186 | switch (inet_sk(sk)->inet_num) { |
f48d5ff1 | 1187 | case IPPROTO_ICMPV6: |
1da177e4 LT |
1188 | rp->checksum = 1; |
1189 | rp->offset = 2; | |
f48d5ff1 MN |
1190 | break; |
1191 | case IPPROTO_MH: | |
1192 | rp->checksum = 1; | |
1193 | rp->offset = 4; | |
1194 | break; | |
1195 | default: | |
1196 | break; | |
1da177e4 | 1197 | } |
a02cec21 | 1198 | return 0; |
1da177e4 LT |
1199 | } |
1200 | ||
1201 | struct proto rawv6_prot = { | |
543d9cfe ACM |
1202 | .name = "RAWv6", |
1203 | .owner = THIS_MODULE, | |
1204 | .close = rawv6_close, | |
22dd4850 | 1205 | .destroy = raw6_destroy, |
82b276cd | 1206 | .connect = ip6_datagram_connect_v6_only, |
286c72de | 1207 | .disconnect = __udp_disconnect, |
543d9cfe ACM |
1208 | .ioctl = rawv6_ioctl, |
1209 | .init = rawv6_init_sk, | |
543d9cfe ACM |
1210 | .setsockopt = rawv6_setsockopt, |
1211 | .getsockopt = rawv6_getsockopt, | |
1212 | .sendmsg = rawv6_sendmsg, | |
1213 | .recvmsg = rawv6_recvmsg, | |
1214 | .bind = rawv6_bind, | |
1215 | .backlog_rcv = rawv6_rcv_skb, | |
fc8717ba PE |
1216 | .hash = raw_hash_sk, |
1217 | .unhash = raw_unhash_sk, | |
543d9cfe | 1218 | .obj_size = sizeof(struct raw6_sock), |
8c2bc895 DW |
1219 | .useroffset = offsetof(struct raw6_sock, filter), |
1220 | .usersize = sizeof_field(struct raw6_sock, filter), | |
fc8717ba | 1221 | .h.raw_hash = &raw_v6_hashinfo, |
3fdadf7d | 1222 | #ifdef CONFIG_COMPAT |
e2d57766 | 1223 | .compat_ioctl = compat_rawv6_ioctl, |
3fdadf7d | 1224 | #endif |
432490f9 | 1225 | .diag_destroy = raw_abort, |
1da177e4 LT |
1226 | }; |
1227 | ||
1228 | #ifdef CONFIG_PROC_FS | |
1da177e4 LT |
1229 | static int raw6_seq_show(struct seq_file *seq, void *v) |
1230 | { | |
17ef66af LC |
1231 | if (v == SEQ_START_TOKEN) { |
1232 | seq_puts(seq, IPV6_SEQ_DGRAM_HEADER); | |
1233 | } else { | |
1234 | struct sock *sp = v; | |
1235 | __u16 srcp = inet_sk(sp)->inet_num; | |
1236 | ip6_dgram_sock_seq_show(seq, v, srcp, 0, | |
1237 | raw_seq_private(seq)->bucket); | |
1238 | } | |
1da177e4 LT |
1239 | return 0; |
1240 | } | |
1241 | ||
56b3d975 | 1242 | static const struct seq_operations raw6_seq_ops = { |
42a73808 PE |
1243 | .start = raw_seq_start, |
1244 | .next = raw_seq_next, | |
1245 | .stop = raw_seq_stop, | |
1da177e4 LT |
1246 | .show = raw6_seq_show, |
1247 | }; | |
1248 | ||
2c8c1e72 | 1249 | static int __net_init raw6_init_net(struct net *net) |
1da177e4 | 1250 | { |
c3506372 CH |
1251 | if (!proc_create_net_data("raw6", 0444, net->proc_net, &raw6_seq_ops, |
1252 | sizeof(struct raw_iter_state), &raw_v6_hashinfo)) | |
1da177e4 | 1253 | return -ENOMEM; |
a308da16 | 1254 | |
1da177e4 LT |
1255 | return 0; |
1256 | } | |
1257 | ||
2c8c1e72 | 1258 | static void __net_exit raw6_exit_net(struct net *net) |
a308da16 | 1259 | { |
ece31ffd | 1260 | remove_proc_entry("raw6", net->proc_net); |
a308da16 PE |
1261 | } |
1262 | ||
1263 | static struct pernet_operations raw6_net_ops = { | |
1264 | .init = raw6_init_net, | |
1265 | .exit = raw6_exit_net, | |
1266 | }; | |
1267 | ||
1268 | int __init raw6_proc_init(void) | |
1269 | { | |
1270 | return register_pernet_subsys(&raw6_net_ops); | |
1271 | } | |
1272 | ||
1da177e4 LT |
1273 | void raw6_proc_exit(void) |
1274 | { | |
a308da16 | 1275 | unregister_pernet_subsys(&raw6_net_ops); |
1da177e4 LT |
1276 | } |
1277 | #endif /* CONFIG_PROC_FS */ | |
7f4e4868 | 1278 | |
a11e1d43 | 1279 | /* Same as inet6_dgram_ops, sans udp_poll. */ |
77d4b1d3 | 1280 | const struct proto_ops inet6_sockraw_ops = { |
7f4e4868 DL |
1281 | .family = PF_INET6, |
1282 | .owner = THIS_MODULE, | |
1283 | .release = inet6_release, | |
1284 | .bind = inet6_bind, | |
1285 | .connect = inet_dgram_connect, /* ok */ | |
1286 | .socketpair = sock_no_socketpair, /* a do nothing */ | |
1287 | .accept = sock_no_accept, /* a do nothing */ | |
1288 | .getname = inet6_getname, | |
a11e1d43 | 1289 | .poll = datagram_poll, /* ok */ |
7f4e4868 | 1290 | .ioctl = inet6_ioctl, /* must change */ |
c7cbdbf2 | 1291 | .gettstamp = sock_gettstamp, |
7f4e4868 DL |
1292 | .listen = sock_no_listen, /* ok */ |
1293 | .shutdown = inet_shutdown, /* ok */ | |
1294 | .setsockopt = sock_common_setsockopt, /* ok */ | |
1295 | .getsockopt = sock_common_getsockopt, /* ok */ | |
1296 | .sendmsg = inet_sendmsg, /* ok */ | |
1297 | .recvmsg = sock_common_recvmsg, /* ok */ | |
1298 | .mmap = sock_no_mmap, | |
7f4e4868 | 1299 | #ifdef CONFIG_COMPAT |
3986912f | 1300 | .compat_ioctl = inet6_compat_ioctl, |
7f4e4868 DL |
1301 | #endif |
1302 | }; | |
1303 | ||
1304 | static struct inet_protosw rawv6_protosw = { | |
1305 | .type = SOCK_RAW, | |
1306 | .protocol = IPPROTO_IP, /* wild card */ | |
1307 | .prot = &rawv6_prot, | |
1308 | .ops = &inet6_sockraw_ops, | |
7f4e4868 DL |
1309 | .flags = INET_PROTOSW_REUSE, |
1310 | }; | |
1311 | ||
1312 | int __init rawv6_init(void) | |
1313 | { | |
3d2f6d41 | 1314 | return inet6_register_protosw(&rawv6_protosw); |
7f4e4868 DL |
1315 | } |
1316 | ||
09f7709f | 1317 | void rawv6_exit(void) |
7f4e4868 DL |
1318 | { |
1319 | inet6_unregister_protosw(&rawv6_protosw); | |
1320 | } |