raw.c 30.3 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 *	RAW sockets for IPv6
3
 *	Linux INET6 implementation
L
Linus Torvalds 已提交
4 5
 *
 *	Authors:
6
 *	Pedro Roque		<roque@di.fc.ul.pt>
L
Linus Torvalds 已提交
7 8 9 10 11
 *
 *	Adapted from linux/net/ipv4/raw.c
 *
 *	Fixes:
 *	Hideaki YOSHIFUJI	:	sin6_scope_id support
12
 *	YOSHIFUJI,H.@USAGI	:	raw checksum (RFC2292(bis) compliance)
L
Linus Torvalds 已提交
13 14 15 16 17 18 19 20 21 22 23
 *	Kazunori MIYAZAWA @USAGI:	change process style to use ip6_append_data
 *
 *	This program is free software; you can redistribute it and/or
 *      modify it under the terms of the GNU General Public License
 *      as published by the Free Software Foundation; either version
 *      2 of the License, or (at your option) any later version.
 */

#include <linux/errno.h>
#include <linux/types.h>
#include <linux/socket.h>
24
#include <linux/slab.h>
L
Linus Torvalds 已提交
25 26 27 28 29 30 31 32
#include <linux/sockios.h>
#include <linux/net.h>
#include <linux/in6.h>
#include <linux/netdevice.h>
#include <linux/if_arp.h>
#include <linux/icmpv6.h>
#include <linux/netfilter.h>
#include <linux/netfilter_ipv6.h>
33
#include <linux/skbuff.h>
34
#include <linux/compat.h>
L
Linus Torvalds 已提交
35 36 37
#include <asm/uaccess.h>
#include <asm/ioctls.h>

38
#include <net/net_namespace.h>
L
Linus Torvalds 已提交
39 40 41 42 43 44 45 46 47 48 49 50 51
#include <net/ip.h>
#include <net/sock.h>
#include <net/snmp.h>

#include <net/ipv6.h>
#include <net/ndisc.h>
#include <net/protocol.h>
#include <net/ip6_route.h>
#include <net/ip6_checksum.h>
#include <net/addrconf.h>
#include <net/transp_v6.h>
#include <net/udp.h>
#include <net/inet_common.h>
52
#include <net/tcp_states.h>
A
Amerigo Wang 已提交
53
#if IS_ENABLED(CONFIG_IPV6_MIP6)
54 55
#include <net/mip6.h>
#endif
56
#include <linux/mroute6.h>
L
Linus Torvalds 已提交
57

58
#include <net/raw.h>
L
Linus Torvalds 已提交
59 60 61 62 63
#include <net/rawv6.h>
#include <net/xfrm.h>

#include <linux/proc_fs.h>
#include <linux/seq_file.h>
64
#include <linux/export.h>
L
Linus Torvalds 已提交
65

66 67
#define	ICMPV6_HDRLEN	4	/* ICMPv6 header, RFC 4443 Section 2.1 */

68
static struct raw_hashinfo raw_v6_hashinfo = {
69
	.lock = __RW_LOCK_UNLOCKED(raw_v6_hashinfo.lock),
70
};
L
Linus Torvalds 已提交
71

72
static struct sock *__raw_v6_lookup(struct net *net, struct sock *sk,
73 74
		unsigned short num, const struct in6_addr *loc_addr,
		const struct in6_addr *rmt_addr, int dif)
L
Linus Torvalds 已提交
75
{
76
	bool is_multicast = ipv6_addr_is_multicast(loc_addr);
L
Linus Torvalds 已提交
77

78
	sk_for_each_from(sk)
E
Eric Dumazet 已提交
79
		if (inet_sk(sk)->inet_num == num) {
L
Linus Torvalds 已提交
80 81
			struct ipv6_pinfo *np = inet6_sk(sk);

82
			if (!net_eq(sock_net(sk), net))
83 84
				continue;

L
Linus Torvalds 已提交
85 86 87 88
			if (!ipv6_addr_any(&np->daddr) &&
			    !ipv6_addr_equal(&np->daddr, rmt_addr))
				continue;

89 90 91
			if (sk->sk_bound_dev_if && sk->sk_bound_dev_if != dif)
				continue;

L
Linus Torvalds 已提交
92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110
			if (!ipv6_addr_any(&np->rcv_saddr)) {
				if (ipv6_addr_equal(&np->rcv_saddr, loc_addr))
					goto found;
				if (is_multicast &&
				    inet6_mc_check(sk, loc_addr, rmt_addr))
					goto found;
				continue;
			}
			goto found;
		}
	sk = NULL;
found:
	return sk;
}

/*
 *	0 - deliver
 *	1 - block
 */
E
Eric Dumazet 已提交
111
static int icmpv6_filter(const struct sock *sk, const struct sk_buff *skb)
L
Linus Torvalds 已提交
112
{
113
	struct icmp6hdr _hdr;
E
Eric Dumazet 已提交
114
	const struct icmp6hdr *hdr;
L
Linus Torvalds 已提交
115

116 117 118
	/* We require only the four bytes of the ICMPv6 header, not any
	 * additional bytes of message body in "struct icmp6hdr".
	 */
E
Eric Dumazet 已提交
119
	hdr = skb_header_pointer(skb, skb_transport_offset(skb),
120
				 ICMPV6_HDRLEN, &_hdr);
E
Eric Dumazet 已提交
121 122 123
	if (hdr) {
		const __u32 *data = &raw6_sk(sk)->filter.data[0];
		unsigned int type = hdr->icmp6_type;
L
Linus Torvalds 已提交
124

E
Eric Dumazet 已提交
125
		return (data[type >> 5] & (1U << (type & 31))) != 0;
L
Linus Torvalds 已提交
126
	}
E
Eric Dumazet 已提交
127
	return 1;
L
Linus Torvalds 已提交
128 129
}

A
Amerigo Wang 已提交
130
#if IS_ENABLED(CONFIG_IPV6_MIP6)
E
Eric Dumazet 已提交
131
typedef int mh_filter_t(struct sock *sock, struct sk_buff *skb);
132

E
Eric Dumazet 已提交
133 134 135
static mh_filter_t __rcu *mh_filter __read_mostly;

int rawv6_mh_filter_register(mh_filter_t filter)
136
{
137
	rcu_assign_pointer(mh_filter, filter);
138 139 140 141
	return 0;
}
EXPORT_SYMBOL(rawv6_mh_filter_register);

E
Eric Dumazet 已提交
142
int rawv6_mh_filter_unregister(mh_filter_t filter)
143
{
144
	RCU_INIT_POINTER(mh_filter, NULL);
145 146 147 148 149 150 151
	synchronize_rcu();
	return 0;
}
EXPORT_SYMBOL(rawv6_mh_filter_unregister);

#endif

L
Linus Torvalds 已提交
152 153 154 155 156 157 158
/*
 *	demultiplex raw sockets.
 *	(should consider queueing the skb in the sock receive_queue
 *	without calling rawv6.c)
 *
 *	Caller owns SKB so we must make clones.
 */
159
static bool ipv6_raw_deliver(struct sk_buff *skb, int nexthdr)
L
Linus Torvalds 已提交
160
{
161 162
	const struct in6_addr *saddr;
	const struct in6_addr *daddr;
L
Linus Torvalds 已提交
163
	struct sock *sk;
164
	bool delivered = false;
L
Linus Torvalds 已提交
165
	__u8 hash;
166
	struct net *net;
L
Linus Torvalds 已提交
167

168
	saddr = &ipv6_hdr(skb)->saddr;
L
Linus Torvalds 已提交
169 170
	daddr = saddr + 1;

171
	hash = nexthdr & (RAW_HTABLE_SIZE - 1);
L
Linus Torvalds 已提交
172

173 174
	read_lock(&raw_v6_hashinfo.lock);
	sk = sk_head(&raw_v6_hashinfo.ht[hash]);
L
Linus Torvalds 已提交
175 176 177 178

	if (sk == NULL)
		goto out;

179
	net = dev_net(skb->dev);
180
	sk = __raw_v6_lookup(net, sk, nexthdr, daddr, saddr, IP6CB(skb)->iif);
L
Linus Torvalds 已提交
181 182

	while (sk) {
183 184
		int filtered;

185
		delivered = true;
186 187 188 189
		switch (nexthdr) {
		case IPPROTO_ICMPV6:
			filtered = icmpv6_filter(sk, skb);
			break;
190

A
Amerigo Wang 已提交
191
#if IS_ENABLED(CONFIG_IPV6_MIP6)
192
		case IPPROTO_MH:
193
		{
194 195 196 197 198 199
			/* XXX: To validate MH only once for each packet,
			 * this is placed here. It should be after checking
			 * xfrm policy, however it doesn't. The checking xfrm
			 * policy is placed in rawv6_rcv() because it is
			 * required for each socket.
			 */
E
Eric Dumazet 已提交
200
			mh_filter_t *filter;
201 202

			filter = rcu_dereference(mh_filter);
E
Eric Dumazet 已提交
203
			filtered = filter ? (*filter)(sk, skb) : 0;
204
			break;
205
		}
206 207 208 209 210 211 212 213 214
#endif
		default:
			filtered = 0;
			break;
		}

		if (filtered < 0)
			break;
		if (filtered == 0) {
L
Linus Torvalds 已提交
215 216 217
			struct sk_buff *clone = skb_clone(skb, GFP_ATOMIC);

			/* Not releasing hash table! */
218 219
			if (clone) {
				nf_reset(clone);
L
Linus Torvalds 已提交
220
				rawv6_rcv(sk, clone);
221
			}
L
Linus Torvalds 已提交
222
		}
223
		sk = __raw_v6_lookup(net, sk_next(sk), nexthdr, daddr, saddr,
224
				     IP6CB(skb)->iif);
L
Linus Torvalds 已提交
225 226
	}
out:
227
	read_unlock(&raw_v6_hashinfo.lock);
228
	return delivered;
L
Linus Torvalds 已提交
229 230
}

231
bool raw6_local_deliver(struct sk_buff *skb, int nexthdr)
232 233 234
{
	struct sock *raw_sk;

235
	raw_sk = sk_head(&raw_v6_hashinfo.ht[nexthdr & (RAW_HTABLE_SIZE - 1)]);
236 237 238 239 240 241
	if (raw_sk && !ipv6_raw_deliver(skb, nexthdr))
		raw_sk = NULL;

	return raw_sk != NULL;
}

L
Linus Torvalds 已提交
242 243 244 245 246 247
/* This cleans up af_inet6 a bit. -DaveM */
static int rawv6_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len)
{
	struct inet_sock *inet = inet_sk(sk);
	struct ipv6_pinfo *np = inet6_sk(sk);
	struct sockaddr_in6 *addr = (struct sockaddr_in6 *) uaddr;
A
Al Viro 已提交
248
	__be32 v4addr = 0;
L
Linus Torvalds 已提交
249 250 251 252 253 254 255 256 257
	int addr_type;
	int err;

	if (addr_len < SIN6_LEN_RFC2133)
		return -EINVAL;
	addr_type = ipv6_addr_type(&addr->sin6_addr);

	/* Raw sockets are IPv6 only */
	if (addr_type == IPV6_ADDR_MAPPED)
258
		return -EADDRNOTAVAIL;
L
Linus Torvalds 已提交
259 260 261 262 263 264 265

	lock_sock(sk);

	err = -EINVAL;
	if (sk->sk_state != TCP_CLOSE)
		goto out;

266
	rcu_read_lock();
L
Linus Torvalds 已提交
267 268 269 270
	/* Check if the address belongs to the host. */
	if (addr_type != IPV6_ADDR_ANY) {
		struct net_device *dev = NULL;

271
		if (__ipv6_addr_needs_scope_id(addr_type)) {
L
Linus Torvalds 已提交
272 273 274 275 276 277 278
			if (addr_len >= sizeof(struct sockaddr_in6) &&
			    addr->sin6_scope_id) {
				/* Override any existing binding, if another
				 * one is supplied by user.
				 */
				sk->sk_bound_dev_if = addr->sin6_scope_id;
			}
279

L
Linus Torvalds 已提交
280 281
			/* Binding to link-local address requires an interface */
			if (!sk->sk_bound_dev_if)
282
				goto out_unlock;
L
Linus Torvalds 已提交
283

284 285 286 287 288
			err = -ENODEV;
			dev = dev_get_by_index_rcu(sock_net(sk),
						   sk->sk_bound_dev_if);
			if (!dev)
				goto out_unlock;
L
Linus Torvalds 已提交
289
		}
290

L
Linus Torvalds 已提交
291 292 293 294 295 296
		/* ipv4 addr of the socket is invalid.  Only the
		 * unspecified and mapped address have a v4 equivalent.
		 */
		v4addr = LOOPBACK4_IPV6;
		if (!(addr_type & IPV6_ADDR_MULTICAST))	{
			err = -EADDRNOTAVAIL;
297
			if (!ipv6_chk_addr(sock_net(sk), &addr->sin6_addr,
298
					   dev, 0)) {
299
				goto out_unlock;
L
Linus Torvalds 已提交
300 301 302 303
			}
		}
	}

E
Eric Dumazet 已提交
304
	inet->inet_rcv_saddr = inet->inet_saddr = v4addr;
A
Alexey Dobriyan 已提交
305
	np->rcv_saddr = addr->sin6_addr;
L
Linus Torvalds 已提交
306
	if (!(addr_type & IPV6_ADDR_MULTICAST))
A
Alexey Dobriyan 已提交
307
		np->saddr = addr->sin6_addr;
L
Linus Torvalds 已提交
308
	err = 0;
309 310
out_unlock:
	rcu_read_unlock();
L
Linus Torvalds 已提交
311 312 313 314 315
out:
	release_sock(sk);
	return err;
}

316
static void rawv6_err(struct sock *sk, struct sk_buff *skb,
L
Linus Torvalds 已提交
317
	       struct inet6_skb_parm *opt,
318
	       u8 type, u8 code, int offset, __be32 info)
L
Linus Torvalds 已提交
319 320 321 322 323 324 325 326 327 328 329 330 331 332 333
{
	struct inet_sock *inet = inet_sk(sk);
	struct ipv6_pinfo *np = inet6_sk(sk);
	int err;
	int harderr;

	/* Report error on raw socket, if:
	   1. User requested recverr.
	   2. Socket is connected (otherwise the error indication
	      is useless without recverr and error is hard.
	 */
	if (!np->recverr && sk->sk_state != TCP_ESTABLISHED)
		return;

	harderr = icmpv6_err_convert(type, code, &err);
334 335
	if (type == ICMPV6_PKT_TOOBIG) {
		ip6_sk_update_pmtu(skb, sk, info);
L
Linus Torvalds 已提交
336
		harderr = (np->pmtudisc == IPV6_PMTUDISC_DO);
337
	}
338
	if (type == NDISC_REDIRECT) {
339
		ip6_sk_redirect(skb, sk);
340 341
		return;
	}
L
Linus Torvalds 已提交
342 343 344 345 346 347 348 349 350 351 352 353 354
	if (np->recverr) {
		u8 *payload = skb->data;
		if (!inet->hdrincl)
			payload += offset;
		ipv6_icmp_error(sk, skb, err, 0, ntohl(info), payload);
	}

	if (np->recverr || harderr) {
		sk->sk_err = err;
		sk->sk_error_report(sk);
	}
}

355
void raw6_icmp_error(struct sk_buff *skb, int nexthdr,
356
		u8 type, u8 code, int inner_offset, __be32 info)
357 358 359
{
	struct sock *sk;
	int hash;
360
	const struct in6_addr *saddr, *daddr;
361
	struct net *net;
362

363
	hash = nexthdr & (RAW_HTABLE_SIZE - 1);
364

365 366
	read_lock(&raw_v6_hashinfo.lock);
	sk = sk_head(&raw_v6_hashinfo.ht[hash]);
367
	if (sk != NULL) {
368
		/* Note: ipv6_hdr(skb) != skb->data */
369
		const struct ipv6hdr *ip6h = (const struct ipv6hdr *)skb->data;
370 371
		saddr = &ip6h->saddr;
		daddr = &ip6h->daddr;
372
		net = dev_net(skb->dev);
373

374
		while ((sk = __raw_v6_lookup(net, sk, nexthdr, saddr, daddr,
375 376 377 378 379 380
						IP6CB(skb)->iif))) {
			rawv6_err(sk, skb, NULL, type, code,
					inner_offset, info);
			sk = sk_next(sk);
		}
	}
381
	read_unlock(&raw_v6_hashinfo.lock);
382 383
}

384
static inline int rawv6_rcv_skb(struct sock *sk, struct sk_buff *skb)
L
Linus Torvalds 已提交
385
{
386
	if ((raw6_sk(sk)->checksum || rcu_access_pointer(sk->sk_filter)) &&
387
	    skb_checksum_complete(skb)) {
W
Wang Chen 已提交
388
		atomic_inc(&sk->sk_drops);
389
		kfree_skb(skb);
390
		return NET_RX_DROP;
L
Linus Torvalds 已提交
391 392 393
	}

	/* Charge it to the socket. */
394 395
	skb_dst_drop(skb);
	if (sock_queue_rcv_skb(sk, skb) < 0) {
L
Linus Torvalds 已提交
396
		kfree_skb(skb);
397
		return NET_RX_DROP;
L
Linus Torvalds 已提交
398 399 400 401 402 403
	}

	return 0;
}

/*
404
 *	This is next to useless...
L
Linus Torvalds 已提交
405
 *	if we demultiplex in network layer we don't need the extra call
406 407
 *	just to queue the skb...
 *	maybe we could have the network decide upon a hint if it
L
Linus Torvalds 已提交
408 409 410 411 412 413 414
 *	should call raw_rcv for demultiplexing
 */
int rawv6_rcv(struct sock *sk, struct sk_buff *skb)
{
	struct inet_sock *inet = inet_sk(sk);
	struct raw6_sock *rp = raw6_sk(sk);

415
	if (!xfrm6_policy_check(sk, XFRM_POLICY_IN, skb)) {
W
Wang Chen 已提交
416
		atomic_inc(&sk->sk_drops);
417 418 419
		kfree_skb(skb);
		return NET_RX_DROP;
	}
L
Linus Torvalds 已提交
420 421 422 423

	if (!rp->checksum)
		skb->ip_summed = CHECKSUM_UNNECESSARY;

424
	if (skb->ip_summed == CHECKSUM_COMPLETE) {
425
		skb_postpull_rcsum(skb, skb_network_header(skb),
426
				   skb_network_header_len(skb));
427 428
		if (!csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
				     &ipv6_hdr(skb)->daddr,
E
Eric Dumazet 已提交
429
				     skb->len, inet->inet_num, skb->csum))
L
Linus Torvalds 已提交
430 431
			skb->ip_summed = CHECKSUM_UNNECESSARY;
	}
432
	if (!skb_csum_unnecessary(skb))
433 434 435
		skb->csum = ~csum_unfold(csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
							 &ipv6_hdr(skb)->daddr,
							 skb->len,
E
Eric Dumazet 已提交
436
							 inet->inet_num, 0));
L
Linus Torvalds 已提交
437 438

	if (inet->hdrincl) {
439
		if (skb_checksum_complete(skb)) {
W
Wang Chen 已提交
440
			atomic_inc(&sk->sk_drops);
L
Linus Torvalds 已提交
441
			kfree_skb(skb);
442
			return NET_RX_DROP;
L
Linus Torvalds 已提交
443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467
		}
	}

	rawv6_rcv_skb(sk, skb);
	return 0;
}


/*
 *	This should be easy, if there is something there
 *	we return it, otherwise we block.
 */

static int rawv6_recvmsg(struct kiocb *iocb, struct sock *sk,
		  struct msghdr *msg, size_t len,
		  int noblock, int flags, int *addr_len)
{
	struct ipv6_pinfo *np = inet6_sk(sk);
	struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)msg->msg_name;
	struct sk_buff *skb;
	size_t copied;
	int err;

	if (flags & MSG_OOB)
		return -EOPNOTSUPP;
468 469

	if (addr_len)
L
Linus Torvalds 已提交
470 471 472 473 474
		*addr_len=sizeof(*sin6);

	if (flags & MSG_ERRQUEUE)
		return ipv6_recv_error(sk, msg, len);

475 476 477
	if (np->rxpmtu && np->rxopt.bits.rxpmtu)
		return ipv6_recv_rxpmtu(sk, msg, len);

L
Linus Torvalds 已提交
478 479 480 481 482
	skb = skb_recv_datagram(sk, flags, noblock, &err);
	if (!skb)
		goto out;

	copied = skb->len;
483 484 485 486
	if (copied > len) {
		copied = len;
		msg->msg_flags |= MSG_TRUNC;
	}
L
Linus Torvalds 已提交
487

488
	if (skb_csum_unnecessary(skb)) {
L
Linus Torvalds 已提交
489 490
		err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
	} else if (msg->msg_flags&MSG_TRUNC) {
491
		if (__skb_checksum_complete(skb))
L
Linus Torvalds 已提交
492 493 494 495 496 497 498 499 500 501 502 503 504
			goto csum_copy_err;
		err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
	} else {
		err = skb_copy_and_csum_datagram_iovec(skb, 0, msg->msg_iov);
		if (err == -EINVAL)
			goto csum_copy_err;
	}
	if (err)
		goto out_free;

	/* Copy the address. */
	if (sin6) {
		sin6->sin6_family = AF_INET6;
505
		sin6->sin6_port = 0;
A
Alexey Dobriyan 已提交
506
		sin6->sin6_addr = ipv6_hdr(skb)->saddr;
L
Linus Torvalds 已提交
507
		sin6->sin6_flowinfo = 0;
508 509
		sin6->sin6_scope_id = ipv6_iface_scope_id(&sin6->sin6_addr,
							  IP6CB(skb)->iif);
L
Linus Torvalds 已提交
510 511
	}

512
	sock_recv_ts_and_drops(msg, sk, skb);
L
Linus Torvalds 已提交
513 514

	if (np->rxopt.all)
515
		ip6_datagram_recv_ctl(sk, msg, skb);
L
Linus Torvalds 已提交
516 517 518 519 520 521 522 523 524 525 526

	err = copied;
	if (flags & MSG_TRUNC)
		err = skb->len;

out_free:
	skb_free_datagram(sk, skb);
out:
	return err;

csum_copy_err:
527
	skb_kill_datagram(sk, skb, flags);
L
Linus Torvalds 已提交
528 529 530 531 532

	/* Error for blocking case is chosen to masquerade
	   as some normal condition.
	 */
	err = (flags&MSG_DONTWAIT) ? -EAGAIN : -EHOSTUNREACH;
533
	goto out;
L
Linus Torvalds 已提交
534 535
}

536
static int rawv6_push_pending_frames(struct sock *sk, struct flowi6 *fl6,
537
				     struct raw6_sock *rp)
L
Linus Torvalds 已提交
538 539 540
{
	struct sk_buff *skb;
	int err = 0;
541 542
	int offset;
	int len;
543
	int total_len;
544 545
	__wsum tmp_csum;
	__sum16 csum;
L
Linus Torvalds 已提交
546 547 548 549 550 551 552

	if (!rp->checksum)
		goto send;

	if ((skb = skb_peek(&sk->sk_write_queue)) == NULL)
		goto out;

553
	offset = rp->offset;
554
	total_len = inet_sk(sk)->cork.base.length;
555
	if (offset >= total_len - 1) {
L
Linus Torvalds 已提交
556
		err = -EINVAL;
557
		ip6_flush_pending_frames(sk);
L
Linus Torvalds 已提交
558 559 560 561 562 563 564 565 566 567
		goto out;
	}

	/* should be check HW csum miyazawa */
	if (skb_queue_len(&sk->sk_write_queue) == 1) {
		/*
		 * Only one fragment on the socket.
		 */
		tmp_csum = skb->csum;
	} else {
568
		struct sk_buff *csum_skb = NULL;
L
Linus Torvalds 已提交
569 570 571 572
		tmp_csum = 0;

		skb_queue_walk(&sk->sk_write_queue, skb) {
			tmp_csum = csum_add(tmp_csum, skb->csum);
573 574 575 576

			if (csum_skb)
				continue;

577
			len = skb->len - skb_transport_offset(skb);
578 579 580 581 582 583
			if (offset >= len) {
				offset -= len;
				continue;
			}

			csum_skb = skb;
L
Linus Torvalds 已提交
584
		}
585 586

		skb = csum_skb;
L
Linus Torvalds 已提交
587 588
	}

589
	offset += skb_transport_offset(skb);
590 591 592
	if (skb_copy_bits(skb, offset, &csum, 2))
		BUG();

L
Linus Torvalds 已提交
593
	/* in case cksum was not initialized */
594
	if (unlikely(csum))
595
		tmp_csum = csum_sub(tmp_csum, csum_unfold(csum));
596

597 598
	csum = csum_ipv6_magic(&fl6->saddr, &fl6->daddr,
			       total_len, fl6->flowi6_proto, tmp_csum);
599

600
	if (csum == 0 && fl6->flowi6_proto == IPPROTO_UDP)
601
		csum = CSUM_MANGLED_0;
L
Linus Torvalds 已提交
602

603 604
	if (skb_store_bits(skb, offset, &csum, 2))
		BUG();
L
Linus Torvalds 已提交
605 606 607 608 609 610 611 612

send:
	err = ip6_push_pending_frames(sk);
out:
	return err;
}

static int rawv6_send_hdrinc(struct sock *sk, void *from, int length,
613
			struct flowi6 *fl6, struct dst_entry **dstp,
L
Linus Torvalds 已提交
614 615
			unsigned int flags)
{
616
	struct ipv6_pinfo *np = inet6_sk(sk);
L
Linus Torvalds 已提交
617 618 619
	struct ipv6hdr *iph;
	struct sk_buff *skb;
	int err;
E
Eric Dumazet 已提交
620
	struct rt6_info *rt = (struct rt6_info *)*dstp;
621 622
	int hlen = LL_RESERVED_SPACE(rt->dst.dev);
	int tlen = rt->dst.dev->needed_tailroom;
L
Linus Torvalds 已提交
623

624
	if (length > rt->dst.dev->mtu) {
625
		ipv6_local_error(sk, EMSGSIZE, fl6, rt->dst.dev->mtu);
L
Linus Torvalds 已提交
626 627 628 629 630
		return -EMSGSIZE;
	}
	if (flags&MSG_PROBE)
		goto out;

631
	skb = sock_alloc_send_skb(sk,
632
				  length + hlen + tlen + 15,
633
				  flags & MSG_DONTWAIT, &err);
L
Linus Torvalds 已提交
634
	if (skb == NULL)
635
		goto error;
636
	skb_reserve(skb, hlen);
L
Linus Torvalds 已提交
637

638
	skb->protocol = htons(ETH_P_IPV6);
L
Linus Torvalds 已提交
639
	skb->priority = sk->sk_priority;
640
	skb->mark = sk->sk_mark;
641
	skb_dst_set(skb, &rt->dst);
E
Eric Dumazet 已提交
642
	*dstp = NULL;
L
Linus Torvalds 已提交
643

644 645
	skb_put(skb, length);
	skb_reset_network_header(skb);
646
	iph = ipv6_hdr(skb);
L
Linus Torvalds 已提交
647 648 649

	skb->ip_summed = CHECKSUM_NONE;

650
	skb->transport_header = skb->network_header;
L
Linus Torvalds 已提交
651 652 653 654
	err = memcpy_fromiovecend((void *)iph, from, 0, length);
	if (err)
		goto error_fault;

655
	IP6_UPD_PO_STATS(sock_net(sk), rt->rt6i_idev, IPSTATS_MIB_OUT, skb->len);
656
	err = NF_HOOK(NFPROTO_IPV6, NF_INET_LOCAL_OUT, skb, NULL,
657
		      rt->dst.dev, dst_output);
L
Linus Torvalds 已提交
658
	if (err > 0)
E
Eric Dumazet 已提交
659
		err = net_xmit_errno(err);
L
Linus Torvalds 已提交
660 661 662 663 664 665 666 667 668
	if (err)
		goto error;
out:
	return 0;

error_fault:
	err = -EFAULT;
	kfree_skb(skb);
error:
669
	IP6_INC_STATS(sock_net(sk), rt->rt6i_idev, IPSTATS_MIB_OUTDISCARDS);
E
Eric Dumazet 已提交
670 671
	if (err == -ENOBUFS && !np->recverr)
		err = 0;
672
	return err;
L
Linus Torvalds 已提交
673 674
}

675
static int rawv6_probe_proto_opt(struct flowi6 *fl6, struct msghdr *msg)
L
Linus Torvalds 已提交
676 677 678 679
{
	struct iovec *iov;
	u8 __user *type = NULL;
	u8 __user *code = NULL;
680
	u8 len = 0;
L
Linus Torvalds 已提交
681 682 683 684
	int probed = 0;
	int i;

	if (!msg->msg_iov)
H
Heiko Carstens 已提交
685
		return 0;
L
Linus Torvalds 已提交
686 687 688 689 690 691

	for (i = 0; i < msg->msg_iovlen; i++) {
		iov = &msg->msg_iov[i];
		if (!iov)
			continue;

692
		switch (fl6->flowi6_proto) {
L
Linus Torvalds 已提交
693 694 695 696 697 698 699 700 701 702 703 704 705 706
		case IPPROTO_ICMPV6:
			/* check if one-byte field is readable or not. */
			if (iov->iov_base && iov->iov_len < 1)
				break;

			if (!type) {
				type = iov->iov_base;
				/* check if code field is readable or not. */
				if (iov->iov_len > 1)
					code = type + 1;
			} else if (!code)
				code = iov->iov_base;

			if (type && code) {
707 708
				if (get_user(fl6->fl6_icmp_type, type) ||
				    get_user(fl6->fl6_icmp_code, code))
H
Heiko Carstens 已提交
709
					return -EFAULT;
L
Linus Torvalds 已提交
710 711 712
				probed = 1;
			}
			break;
713 714 715 716 717 718
		case IPPROTO_MH:
			if (iov->iov_base && iov->iov_len < 1)
				break;
			/* check if type field is readable or not. */
			if (iov->iov_len > 2 - len) {
				u8 __user *p = iov->iov_base;
719
				if (get_user(fl6->fl6_mh_type, &p[2 - len]))
H
Heiko Carstens 已提交
720
					return -EFAULT;
721 722 723 724 725
				probed = 1;
			} else
				len += iov->iov_len;

			break;
L
Linus Torvalds 已提交
726 727 728 729 730 731 732
		default:
			probed = 1;
			break;
		}
		if (probed)
			break;
	}
H
Heiko Carstens 已提交
733
	return 0;
L
Linus Torvalds 已提交
734 735 736 737 738 739 740
}

static int rawv6_sendmsg(struct kiocb *iocb, struct sock *sk,
		   struct msghdr *msg, size_t len)
{
	struct ipv6_txoptions opt_space;
	struct sockaddr_in6 * sin6 = (struct sockaddr_in6 *) msg->msg_name;
741
	struct in6_addr *daddr, *final_p, final;
L
Linus Torvalds 已提交
742 743 744 745 746 747
	struct inet_sock *inet = inet_sk(sk);
	struct ipv6_pinfo *np = inet6_sk(sk);
	struct raw6_sock *rp = raw6_sk(sk);
	struct ipv6_txoptions *opt = NULL;
	struct ip6_flowlabel *flowlabel = NULL;
	struct dst_entry *dst = NULL;
748
	struct flowi6 fl6;
L
Linus Torvalds 已提交
749 750
	int addr_len = msg->msg_namelen;
	int hlimit = -1;
751
	int tclass = -1;
752
	int dontfrag = -1;
L
Linus Torvalds 已提交
753 754 755 756
	u16 proto;
	int err;

	/* Rough check on arithmetic overflow,
757
	   better check is made in ip6_append_data().
L
Linus Torvalds 已提交
758
	 */
759
	if (len > INT_MAX)
L
Linus Torvalds 已提交
760 761 762
		return -EMSGSIZE;

	/* Mirror BSD error message compatibility */
763
	if (msg->msg_flags & MSG_OOB)
L
Linus Torvalds 已提交
764 765 766
		return -EOPNOTSUPP;

	/*
767
	 *	Get and verify the address.
L
Linus Torvalds 已提交
768
	 */
769
	memset(&fl6, 0, sizeof(fl6));
L
Linus Torvalds 已提交
770

771
	fl6.flowi6_mark = sk->sk_mark;
772

L
Linus Torvalds 已提交
773
	if (sin6) {
774
		if (addr_len < SIN6_LEN_RFC2133)
L
Linus Torvalds 已提交
775 776
			return -EINVAL;

777
		if (sin6->sin6_family && sin6->sin6_family != AF_INET6)
E
Eric Dumazet 已提交
778
			return -EAFNOSUPPORT;
L
Linus Torvalds 已提交
779 780 781 782 783

		/* port is the proto value [0..255] carried in nexthdr */
		proto = ntohs(sin6->sin6_port);

		if (!proto)
E
Eric Dumazet 已提交
784 785
			proto = inet->inet_num;
		else if (proto != inet->inet_num)
E
Eric Dumazet 已提交
786
			return -EINVAL;
L
Linus Torvalds 已提交
787 788

		if (proto > 255)
E
Eric Dumazet 已提交
789
			return -EINVAL;
L
Linus Torvalds 已提交
790 791 792

		daddr = &sin6->sin6_addr;
		if (np->sndflow) {
793 794 795
			fl6.flowlabel = sin6->sin6_flowinfo&IPV6_FLOWINFO_MASK;
			if (fl6.flowlabel&IPV6_FLOWLABEL_MASK) {
				flowlabel = fl6_sock_lookup(sk, fl6.flowlabel);
L
Linus Torvalds 已提交
796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811
				if (flowlabel == NULL)
					return -EINVAL;
				daddr = &flowlabel->dst;
			}
		}

		/*
		 * Otherwise it will be difficult to maintain
		 * sk->sk_dst_cache.
		 */
		if (sk->sk_state == TCP_ESTABLISHED &&
		    ipv6_addr_equal(daddr, &np->daddr))
			daddr = &np->daddr;

		if (addr_len >= sizeof(struct sockaddr_in6) &&
		    sin6->sin6_scope_id &&
812
		    __ipv6_addr_needs_scope_id(__ipv6_addr_type(daddr)))
813
			fl6.flowi6_oif = sin6->sin6_scope_id;
L
Linus Torvalds 已提交
814
	} else {
815
		if (sk->sk_state != TCP_ESTABLISHED)
L
Linus Torvalds 已提交
816
			return -EDESTADDRREQ;
817

E
Eric Dumazet 已提交
818
		proto = inet->inet_num;
L
Linus Torvalds 已提交
819
		daddr = &np->daddr;
820
		fl6.flowlabel = np->flow_label;
L
Linus Torvalds 已提交
821 822
	}

823 824
	if (fl6.flowi6_oif == 0)
		fl6.flowi6_oif = sk->sk_bound_dev_if;
L
Linus Torvalds 已提交
825 826 827 828 829 830

	if (msg->msg_controllen) {
		opt = &opt_space;
		memset(opt, 0, sizeof(struct ipv6_txoptions));
		opt->tot_len = sizeof(struct ipv6_txoptions);

831 832
		err = ip6_datagram_send_ctl(sock_net(sk), sk, msg, &fl6, opt,
					    &hlimit, &tclass, &dontfrag);
L
Linus Torvalds 已提交
833 834 835 836
		if (err < 0) {
			fl6_sock_release(flowlabel);
			return err;
		}
837 838
		if ((fl6.flowlabel&IPV6_FLOWLABEL_MASK) && !flowlabel) {
			flowlabel = fl6_sock_lookup(sk, fl6.flowlabel);
L
Linus Torvalds 已提交
839 840 841 842 843 844 845 846
			if (flowlabel == NULL)
				return -EINVAL;
		}
		if (!(opt->opt_nflen|opt->opt_flen))
			opt = NULL;
	}
	if (opt == NULL)
		opt = np->opt;
847 848 849
	if (flowlabel)
		opt = fl6_merge_options(&opt_space, flowlabel, opt);
	opt = ipv6_fixup_options(&opt_space, opt);
L
Linus Torvalds 已提交
850

851 852
	fl6.flowi6_proto = proto;
	err = rawv6_probe_proto_opt(&fl6, msg);
H
Heiko Carstens 已提交
853 854
	if (err)
		goto out;
855

856
	if (!ipv6_addr_any(daddr))
A
Alexey Dobriyan 已提交
857
		fl6.daddr = *daddr;
858
	else
859 860
		fl6.daddr.s6_addr[15] = 0x1; /* :: means loopback (BSD'ism) */
	if (ipv6_addr_any(&fl6.saddr) && !ipv6_addr_any(&np->saddr))
A
Alexey Dobriyan 已提交
861
		fl6.saddr = np->saddr;
L
Linus Torvalds 已提交
862

863
	final_p = fl6_update_dst(&fl6, opt, &final);
L
Linus Torvalds 已提交
864

865 866
	if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
		fl6.flowi6_oif = np->mcast_oif;
867 868
	else if (!fl6.flowi6_oif)
		fl6.flowi6_oif = np->ucast_oif;
869
	security_sk_classify_flow(sk, flowi6_to_flowi(&fl6));
L
Linus Torvalds 已提交
870

871
	dst = ip6_dst_lookup_flow(sk, &fl6, final_p, true);
872 873
	if (IS_ERR(dst)) {
		err = PTR_ERR(dst);
L
Linus Torvalds 已提交
874
		goto out;
875
	}
L
Linus Torvalds 已提交
876
	if (hlimit < 0) {
877
		if (ipv6_addr_is_multicast(&fl6.daddr))
L
Linus Torvalds 已提交
878 879 880 881
			hlimit = np->mcast_hops;
		else
			hlimit = np->hop_limit;
		if (hlimit < 0)
882
			hlimit = ip6_dst_hoplimit(dst);
L
Linus Torvalds 已提交
883 884
	}

G
Gerrit Renker 已提交
885
	if (tclass < 0)
886
		tclass = np->tclass;
887

888 889 890
	if (dontfrag < 0)
		dontfrag = np->dontfrag;

L
Linus Torvalds 已提交
891 892 893 894
	if (msg->msg_flags&MSG_CONFIRM)
		goto do_confirm;

back_from_confirm:
E
Eric Dumazet 已提交
895
	if (inet->hdrincl)
896
		err = rawv6_send_hdrinc(sk, msg->msg_iov, len, &fl6, &dst, msg->msg_flags);
E
Eric Dumazet 已提交
897
	else {
L
Linus Torvalds 已提交
898
		lock_sock(sk);
899
		err = ip6_append_data(sk, ip_generic_getfrag, msg->msg_iov,
900
			len, 0, hlimit, tclass, opt, &fl6, (struct rt6_info*)dst,
901
			msg->msg_flags, dontfrag);
L
Linus Torvalds 已提交
902 903 904 905

		if (err)
			ip6_flush_pending_frames(sk);
		else if (!(msg->msg_flags & MSG_MORE))
906
			err = rawv6_push_pending_frames(sk, &fl6, rp);
907
		release_sock(sk);
L
Linus Torvalds 已提交
908 909
	}
done:
910
	dst_release(dst);
911
out:
L
Linus Torvalds 已提交
912 913 914 915 916 917 918 919 920 921
	fl6_sock_release(flowlabel);
	return err<0?err:len;
do_confirm:
	dst_confirm(dst);
	if (!(msg->msg_flags & MSG_PROBE) || len)
		goto back_from_confirm;
	err = 0;
	goto done;
}

922
static int rawv6_seticmpfilter(struct sock *sk, int level, int optname,
L
Linus Torvalds 已提交
923 924 925 926 927 928 929 930 931 932 933
			       char __user *optval, int optlen)
{
	switch (optname) {
	case ICMPV6_FILTER:
		if (optlen > sizeof(struct icmp6_filter))
			optlen = sizeof(struct icmp6_filter);
		if (copy_from_user(&raw6_sk(sk)->filter, optval, optlen))
			return -EFAULT;
		return 0;
	default:
		return -ENOPROTOOPT;
934
	}
L
Linus Torvalds 已提交
935 936 937 938

	return 0;
}

939
static int rawv6_geticmpfilter(struct sock *sk, int level, int optname,
L
Linus Torvalds 已提交
940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958
			       char __user *optval, int __user *optlen)
{
	int len;

	switch (optname) {
	case ICMPV6_FILTER:
		if (get_user(len, optlen))
			return -EFAULT;
		if (len < 0)
			return -EINVAL;
		if (len > sizeof(struct icmp6_filter))
			len = sizeof(struct icmp6_filter);
		if (put_user(len, optlen))
			return -EFAULT;
		if (copy_to_user(optval, &raw6_sk(sk)->filter, len))
			return -EFAULT;
		return 0;
	default:
		return -ENOPROTOOPT;
959
	}
L
Linus Torvalds 已提交
960 961 962 963 964

	return 0;
}


965
static int do_rawv6_setsockopt(struct sock *sk, int level, int optname,
966
			    char __user *optval, unsigned int optlen)
L
Linus Torvalds 已提交
967 968 969 970
{
	struct raw6_sock *rp = raw6_sk(sk);
	int val;

971
	if (get_user(val, (int __user *)optval))
L
Linus Torvalds 已提交
972 973 974
		return -EFAULT;

	switch (optname) {
J
Joe Perches 已提交
975 976 977 978 979 980 981 982 983 984 985 986 987
	case IPV6_CHECKSUM:
		if (inet_sk(sk)->inet_num == IPPROTO_ICMPV6 &&
		    level == IPPROTO_IPV6) {
			/*
			 * RFC3542 tells that IPV6_CHECKSUM socket
			 * option in the IPPROTO_IPV6 level is not
			 * allowed on ICMPv6 sockets.
			 * If you want to set it, use IPPROTO_RAW
			 * level IPV6_CHECKSUM socket option
			 * (Linux extension).
			 */
			return -EINVAL;
		}
988

J
Joe Perches 已提交
989 990 991 992 993 994 995 996 997 998
		/* You may get strange result with a positive odd offset;
		   RFC2292bis agrees with me. */
		if (val > 0 && (val&1))
			return -EINVAL;
		if (val < 0) {
			rp->checksum = 0;
		} else {
			rp->checksum = 1;
			rp->offset = val;
		}
L
Linus Torvalds 已提交
999

J
Joe Perches 已提交
1000
		return 0;
L
Linus Torvalds 已提交
1001

J
Joe Perches 已提交
1002 1003
	default:
		return -ENOPROTOOPT;
L
Linus Torvalds 已提交
1004 1005 1006
	}
}

1007
static int rawv6_setsockopt(struct sock *sk, int level, int optname,
1008
			  char __user *optval, unsigned int optlen)
L
Linus Torvalds 已提交
1009
{
J
Joe Perches 已提交
1010 1011 1012
	switch (level) {
	case SOL_RAW:
		break;
L
Linus Torvalds 已提交
1013

J
Joe Perches 已提交
1014 1015 1016 1017 1018 1019 1020 1021 1022
	case SOL_ICMPV6:
		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
			return -EOPNOTSUPP;
		return rawv6_seticmpfilter(sk, level, optname, optval, optlen);
	case SOL_IPV6:
		if (optname == IPV6_CHECKSUM)
			break;
	default:
		return ipv6_setsockopt(sk, level, optname, optval, optlen);
1023 1024
	}

1025 1026 1027 1028 1029
	return do_rawv6_setsockopt(sk, level, optname, optval, optlen);
}

#ifdef CONFIG_COMPAT
static int compat_rawv6_setsockopt(struct sock *sk, int level, int optname,
1030
				   char __user *optval, unsigned int optlen)
1031
{
1032 1033 1034 1035
	switch (level) {
	case SOL_RAW:
		break;
	case SOL_ICMPV6:
E
Eric Dumazet 已提交
1036
		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
1037 1038 1039 1040
			return -EOPNOTSUPP;
		return rawv6_seticmpfilter(sk, level, optname, optval, optlen);
	case SOL_IPV6:
		if (optname == IPV6_CHECKSUM)
1041
			break;
1042 1043 1044
	default:
		return compat_ipv6_setsockopt(sk, level, optname,
					      optval, optlen);
1045
	}
1046 1047 1048 1049 1050 1051 1052 1053 1054
	return do_rawv6_setsockopt(sk, level, optname, optval, optlen);
}
#endif

static int do_rawv6_getsockopt(struct sock *sk, int level, int optname,
			    char __user *optval, int __user *optlen)
{
	struct raw6_sock *rp = raw6_sk(sk);
	int val, len;
L
Linus Torvalds 已提交
1055 1056 1057 1058 1059 1060

	if (get_user(len,optlen))
		return -EFAULT;

	switch (optname) {
	case IPV6_CHECKSUM:
1061 1062 1063 1064 1065
		/*
		 * We allow getsockopt() for IPPROTO_IPV6-level
		 * IPV6_CHECKSUM socket option on ICMPv6 sockets
		 * since RFC3542 is silent about it.
		 */
L
Linus Torvalds 已提交
1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084
		if (rp->checksum == 0)
			val = -1;
		else
			val = rp->offset;
		break;

	default:
		return -ENOPROTOOPT;
	}

	len = min_t(unsigned int, sizeof(int), len);

	if (put_user(len, optlen))
		return -EFAULT;
	if (copy_to_user(optval,&val,len))
		return -EFAULT;
	return 0;
}

1085 1086 1087
static int rawv6_getsockopt(struct sock *sk, int level, int optname,
			  char __user *optval, int __user *optlen)
{
J
Joe Perches 已提交
1088 1089 1090
	switch (level) {
	case SOL_RAW:
		break;
1091

J
Joe Perches 已提交
1092 1093 1094 1095 1096 1097 1098 1099 1100
	case SOL_ICMPV6:
		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
			return -EOPNOTSUPP;
		return rawv6_geticmpfilter(sk, level, optname, optval, optlen);
	case SOL_IPV6:
		if (optname == IPV6_CHECKSUM)
			break;
	default:
		return ipv6_getsockopt(sk, level, optname, optval, optlen);
1101 1102
	}

1103 1104 1105 1106 1107
	return do_rawv6_getsockopt(sk, level, optname, optval, optlen);
}

#ifdef CONFIG_COMPAT
static int compat_rawv6_getsockopt(struct sock *sk, int level, int optname,
1108
				   char __user *optval, int __user *optlen)
1109
{
1110 1111 1112 1113
	switch (level) {
	case SOL_RAW:
		break;
	case SOL_ICMPV6:
E
Eric Dumazet 已提交
1114
		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
1115 1116 1117 1118
			return -EOPNOTSUPP;
		return rawv6_geticmpfilter(sk, level, optname, optval, optlen);
	case SOL_IPV6:
		if (optname == IPV6_CHECKSUM)
1119
			break;
1120 1121 1122
	default:
		return compat_ipv6_getsockopt(sk, level, optname,
					      optval, optlen);
1123
	}
1124 1125 1126 1127
	return do_rawv6_getsockopt(sk, level, optname, optval, optlen);
}
#endif

L
Linus Torvalds 已提交
1128 1129
static int rawv6_ioctl(struct sock *sk, int cmd, unsigned long arg)
{
J
Joe Perches 已提交
1130 1131 1132
	switch (cmd) {
	case SIOCOUTQ: {
		int amount = sk_wmem_alloc_get(sk);
1133

J
Joe Perches 已提交
1134 1135 1136 1137 1138 1139 1140 1141 1142
		return put_user(amount, (int __user *)arg);
	}
	case SIOCINQ: {
		struct sk_buff *skb;
		int amount = 0;

		spin_lock_bh(&sk->sk_receive_queue.lock);
		skb = skb_peek(&sk->sk_receive_queue);
		if (skb != NULL)
1143 1144
			amount = skb_tail_pointer(skb) -
				skb_transport_header(skb);
J
Joe Perches 已提交
1145 1146 1147
		spin_unlock_bh(&sk->sk_receive_queue.lock);
		return put_user(amount, (int __user *)arg);
	}
L
Linus Torvalds 已提交
1148

J
Joe Perches 已提交
1149
	default:
1150
#ifdef CONFIG_IPV6_MROUTE
J
Joe Perches 已提交
1151
		return ip6mr_ioctl(sk, cmd, (void __user *)arg);
1152
#else
J
Joe Perches 已提交
1153
		return -ENOIOCTLCMD;
1154
#endif
L
Linus Torvalds 已提交
1155 1156 1157
	}
}

1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174
#ifdef CONFIG_COMPAT
static int compat_rawv6_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
{
	switch (cmd) {
	case SIOCOUTQ:
	case SIOCINQ:
		return -ENOIOCTLCMD;
	default:
#ifdef CONFIG_IPV6_MROUTE
		return ip6mr_compat_ioctl(sk, cmd, compat_ptr(arg));
#else
		return -ENOIOCTLCMD;
#endif
	}
}
#endif

L
Linus Torvalds 已提交
1175 1176
static void rawv6_close(struct sock *sk, long timeout)
{
E
Eric Dumazet 已提交
1177
	if (inet_sk(sk)->inet_num == IPPROTO_RAW)
1178
		ip6_ra_control(sk, -1);
1179
	ip6mr_sk_done(sk);
L
Linus Torvalds 已提交
1180 1181 1182
	sk_common_release(sk);
}

1183
static void raw6_destroy(struct sock *sk)
D
Denis V. Lunev 已提交
1184 1185 1186 1187
{
	lock_sock(sk);
	ip6_flush_pending_frames(sk);
	release_sock(sk);
1188

1189
	inet6_destroy_sock(sk);
D
Denis V. Lunev 已提交
1190 1191
}

L
Linus Torvalds 已提交
1192 1193
static int rawv6_init_sk(struct sock *sk)
{
1194 1195
	struct raw6_sock *rp = raw6_sk(sk);

E
Eric Dumazet 已提交
1196
	switch (inet_sk(sk)->inet_num) {
1197
	case IPPROTO_ICMPV6:
L
Linus Torvalds 已提交
1198 1199
		rp->checksum = 1;
		rp->offset   = 2;
1200 1201 1202 1203 1204 1205 1206
		break;
	case IPPROTO_MH:
		rp->checksum = 1;
		rp->offset   = 4;
		break;
	default:
		break;
L
Linus Torvalds 已提交
1207
	}
E
Eric Dumazet 已提交
1208
	return 0;
L
Linus Torvalds 已提交
1209 1210 1211
}

struct proto rawv6_prot = {
1212 1213 1214
	.name		   = "RAWv6",
	.owner		   = THIS_MODULE,
	.close		   = rawv6_close,
D
Denis V. Lunev 已提交
1215
	.destroy	   = raw6_destroy,
1216 1217 1218 1219 1220 1221 1222 1223 1224 1225
	.connect	   = ip6_datagram_connect,
	.disconnect	   = udp_disconnect,
	.ioctl		   = rawv6_ioctl,
	.init		   = rawv6_init_sk,
	.setsockopt	   = rawv6_setsockopt,
	.getsockopt	   = rawv6_getsockopt,
	.sendmsg	   = rawv6_sendmsg,
	.recvmsg	   = rawv6_recvmsg,
	.bind		   = rawv6_bind,
	.backlog_rcv	   = rawv6_rcv_skb,
1226 1227
	.hash		   = raw_hash_sk,
	.unhash		   = raw_unhash_sk,
1228
	.obj_size	   = sizeof(struct raw6_sock),
1229
	.h.raw_hash	   = &raw_v6_hashinfo,
1230
#ifdef CONFIG_COMPAT
1231 1232
	.compat_setsockopt = compat_rawv6_setsockopt,
	.compat_getsockopt = compat_rawv6_getsockopt,
1233
	.compat_ioctl	   = compat_rawv6_ioctl,
1234
#endif
L
Linus Torvalds 已提交
1235 1236 1237 1238 1239
};

#ifdef CONFIG_PROC_FS
static int raw6_seq_show(struct seq_file *seq, void *v)
{
1240 1241 1242 1243 1244 1245 1246 1247
	if (v == SEQ_START_TOKEN) {
		seq_puts(seq, IPV6_SEQ_DGRAM_HEADER);
	} else {
		struct sock *sp = v;
		__u16 srcp  = inet_sk(sp)->inet_num;
		ip6_dgram_sock_seq_show(seq, v, srcp, 0,
					raw_seq_private(seq)->bucket);
	}
L
Linus Torvalds 已提交
1248 1249 1250
	return 0;
}

1251
static const struct seq_operations raw6_seq_ops = {
1252 1253 1254
	.start =	raw_seq_start,
	.next =		raw_seq_next,
	.stop =		raw_seq_stop,
L
Linus Torvalds 已提交
1255 1256 1257 1258 1259
	.show =		raw6_seq_show,
};

static int raw6_seq_open(struct inode *inode, struct file *file)
{
1260
	return raw_seq_open(inode, file, &raw_v6_hashinfo, &raw6_seq_ops);
L
Linus Torvalds 已提交
1261 1262
}

1263
static const struct file_operations raw6_seq_fops = {
L
Linus Torvalds 已提交
1264 1265 1266 1267
	.owner =	THIS_MODULE,
	.open =		raw6_seq_open,
	.read =		seq_read,
	.llseek =	seq_lseek,
1268
	.release =	seq_release_net,
L
Linus Torvalds 已提交
1269 1270
};

1271
static int __net_init raw6_init_net(struct net *net)
L
Linus Torvalds 已提交
1272
{
1273
	if (!proc_create("raw6", S_IRUGO, net->proc_net, &raw6_seq_fops))
L
Linus Torvalds 已提交
1274
		return -ENOMEM;
1275

L
Linus Torvalds 已提交
1276 1277 1278
	return 0;
}

1279
static void __net_exit raw6_exit_net(struct net *net)
1280
{
1281
	remove_proc_entry("raw6", net->proc_net);
1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293
}

static struct pernet_operations raw6_net_ops = {
	.init = raw6_init_net,
	.exit = raw6_exit_net,
};

int __init raw6_proc_init(void)
{
	return register_pernet_subsys(&raw6_net_ops);
}

L
Linus Torvalds 已提交
1294 1295
void raw6_proc_exit(void)
{
1296
	unregister_pernet_subsys(&raw6_net_ops);
L
Linus Torvalds 已提交
1297 1298
}
#endif	/* CONFIG_PROC_FS */
1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345

/* Same as inet6_dgram_ops, sans udp_poll.  */
static const struct proto_ops inet6_sockraw_ops = {
	.family		   = PF_INET6,
	.owner		   = THIS_MODULE,
	.release	   = inet6_release,
	.bind		   = inet6_bind,
	.connect	   = inet_dgram_connect,	/* ok		*/
	.socketpair	   = sock_no_socketpair,	/* a do nothing	*/
	.accept		   = sock_no_accept,		/* a do nothing	*/
	.getname	   = inet6_getname,
	.poll		   = datagram_poll,		/* ok		*/
	.ioctl		   = inet6_ioctl,		/* must change  */
	.listen		   = sock_no_listen,		/* ok		*/
	.shutdown	   = inet_shutdown,		/* ok		*/
	.setsockopt	   = sock_common_setsockopt,	/* ok		*/
	.getsockopt	   = sock_common_getsockopt,	/* ok		*/
	.sendmsg	   = inet_sendmsg,		/* ok		*/
	.recvmsg	   = sock_common_recvmsg,	/* ok		*/
	.mmap		   = sock_no_mmap,
	.sendpage	   = sock_no_sendpage,
#ifdef CONFIG_COMPAT
	.compat_setsockopt = compat_sock_common_setsockopt,
	.compat_getsockopt = compat_sock_common_getsockopt,
#endif
};

static struct inet_protosw rawv6_protosw = {
	.type		= SOCK_RAW,
	.protocol	= IPPROTO_IP,	/* wild card */
	.prot		= &rawv6_prot,
	.ops		= &inet6_sockraw_ops,
	.no_check	= UDP_CSUM_DEFAULT,
	.flags		= INET_PROTOSW_REUSE,
};

int __init rawv6_init(void)
{
	int ret;

	ret = inet6_register_protosw(&rawv6_protosw);
	if (ret)
		goto out;
out:
	return ret;
}

1346
void rawv6_exit(void)
1347 1348 1349
{
	inet6_unregister_protosw(&rawv6_protosw);
}