fib_semantics.c 38.4 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
/*
 * INET		An implementation of the TCP/IP protocol suite for the LINUX
 *		operating system.  INET is implemented using the  BSD Socket
 *		interface as the means of communication with the user level.
 *
 *		IPv4 Forwarding Information Base: semantics.
 *
 * Authors:	Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 */

16
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
17 18 19 20 21 22 23 24 25 26 27
#include <linux/bitops.h>
#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/jiffies.h>
#include <linux/mm.h>
#include <linux/string.h>
#include <linux/socket.h>
#include <linux/sockios.h>
#include <linux/errno.h>
#include <linux/in.h>
#include <linux/inet.h>
28
#include <linux/inetdevice.h>
L
Linus Torvalds 已提交
29 30 31 32 33
#include <linux/netdevice.h>
#include <linux/if_arp.h>
#include <linux/proc_fs.h>
#include <linux/skbuff.h>
#include <linux/init.h>
34
#include <linux/slab.h>
L
Linus Torvalds 已提交
35

36
#include <net/arp.h>
L
Linus Torvalds 已提交
37 38 39 40 41 42
#include <net/ip.h>
#include <net/protocol.h>
#include <net/route.h>
#include <net/tcp.h>
#include <net/sock.h>
#include <net/ip_fib.h>
43
#include <net/netlink.h>
44
#include <net/nexthop.h>
45
#include <net/lwtunnel.h>
L
Linus Torvalds 已提交
46 47 48

#include "fib_lookup.h"

49
static DEFINE_SPINLOCK(fib_info_lock);
L
Linus Torvalds 已提交
50 51
static struct hlist_head *fib_info_hash;
static struct hlist_head *fib_info_laddrhash;
52
static unsigned int fib_info_hash_size;
L
Linus Torvalds 已提交
53 54 55 56 57 58 59
static unsigned int fib_info_cnt;

#define DEVINDEX_HASHBITS 8
#define DEVINDEX_HASHSIZE (1U << DEVINDEX_HASHBITS)
static struct hlist_head fib_info_devhash[DEVINDEX_HASHSIZE];

#ifdef CONFIG_IP_ROUTE_MULTIPATH
P
Peter Nørlund 已提交
60
u32 fib_multipath_secret __read_mostly;
L
Linus Torvalds 已提交
61

E
Eric Dumazet 已提交
62 63 64 65 66 67 68 69 70 71 72
#define for_nexthops(fi) {						\
	int nhsel; const struct fib_nh *nh;				\
	for (nhsel = 0, nh = (fi)->fib_nh;				\
	     nhsel < (fi)->fib_nhs;					\
	     nh++, nhsel++)

#define change_nexthops(fi) {						\
	int nhsel; struct fib_nh *nexthop_nh;				\
	for (nhsel = 0,	nexthop_nh = (struct fib_nh *)((fi)->fib_nh);	\
	     nhsel < (fi)->fib_nhs;					\
	     nexthop_nh++, nhsel++)
L
Linus Torvalds 已提交
73 74 75 76 77

#else /* CONFIG_IP_ROUTE_MULTIPATH */

/* Hope, that gcc will optimize it to get rid of dummy loop */

E
Eric Dumazet 已提交
78 79 80
#define for_nexthops(fi) {						\
	int nhsel; const struct fib_nh *nh = (fi)->fib_nh;		\
	for (nhsel = 0; nhsel < 1; nhsel++)
L
Linus Torvalds 已提交
81

E
Eric Dumazet 已提交
82 83 84 85
#define change_nexthops(fi) {						\
	int nhsel;							\
	struct fib_nh *nexthop_nh = (struct fib_nh *)((fi)->fib_nh);	\
	for (nhsel = 0; nhsel < 1; nhsel++)
L
Linus Torvalds 已提交
86 87 88 89 90 91

#endif /* CONFIG_IP_ROUTE_MULTIPATH */

#define endfor_nexthops(fi) }


92
const struct fib_prop fib_props[RTN_MAX + 1] = {
E
Eric Dumazet 已提交
93
	[RTN_UNSPEC] = {
L
Linus Torvalds 已提交
94 95
		.error	= 0,
		.scope	= RT_SCOPE_NOWHERE,
E
Eric Dumazet 已提交
96 97
	},
	[RTN_UNICAST] = {
L
Linus Torvalds 已提交
98 99
		.error	= 0,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
100 101
	},
	[RTN_LOCAL] = {
L
Linus Torvalds 已提交
102 103
		.error	= 0,
		.scope	= RT_SCOPE_HOST,
E
Eric Dumazet 已提交
104 105
	},
	[RTN_BROADCAST] = {
L
Linus Torvalds 已提交
106 107
		.error	= 0,
		.scope	= RT_SCOPE_LINK,
E
Eric Dumazet 已提交
108 109
	},
	[RTN_ANYCAST] = {
L
Linus Torvalds 已提交
110 111
		.error	= 0,
		.scope	= RT_SCOPE_LINK,
E
Eric Dumazet 已提交
112 113
	},
	[RTN_MULTICAST] = {
L
Linus Torvalds 已提交
114 115
		.error	= 0,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
116 117
	},
	[RTN_BLACKHOLE] = {
L
Linus Torvalds 已提交
118 119
		.error	= -EINVAL,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
120 121
	},
	[RTN_UNREACHABLE] = {
L
Linus Torvalds 已提交
122 123
		.error	= -EHOSTUNREACH,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
124 125
	},
	[RTN_PROHIBIT] = {
L
Linus Torvalds 已提交
126 127
		.error	= -EACCES,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
128 129
	},
	[RTN_THROW] = {
L
Linus Torvalds 已提交
130 131
		.error	= -EAGAIN,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
132 133
	},
	[RTN_NAT] = {
L
Linus Torvalds 已提交
134 135
		.error	= -EINVAL,
		.scope	= RT_SCOPE_NOWHERE,
E
Eric Dumazet 已提交
136 137
	},
	[RTN_XRESOLVE] = {
L
Linus Torvalds 已提交
138 139
		.error	= -EINVAL,
		.scope	= RT_SCOPE_NOWHERE,
E
Eric Dumazet 已提交
140
	},
L
Linus Torvalds 已提交
141 142
};

143 144 145 146 147 148 149 150 151 152 153 154 155 156 157
static void rt_fibinfo_free(struct rtable __rcu **rtp)
{
	struct rtable *rt = rcu_dereference_protected(*rtp, 1);

	if (!rt)
		return;

	/* Not even needed : RCU_INIT_POINTER(*rtp, NULL);
	 * because we waited an RCU grace period before calling
	 * free_fib_info_rcu()
	 */

	dst_free(&rt->dst);
}

158 159
static void free_nh_exceptions(struct fib_nh *nh)
{
160
	struct fnhe_hash_bucket *hash;
161 162
	int i;

163 164 165
	hash = rcu_dereference_protected(nh->nh_exceptions, 1);
	if (!hash)
		return;
166 167 168
	for (i = 0; i < FNHE_HASH_SIZE; i++) {
		struct fib_nh_exception *fnhe;

E
Eric Dumazet 已提交
169
		fnhe = rcu_dereference_protected(hash[i].chain, 1);
170 171 172
		while (fnhe) {
			struct fib_nh_exception *next;
			
E
Eric Dumazet 已提交
173
			next = rcu_dereference_protected(fnhe->fnhe_next, 1);
174

175 176
			rt_fibinfo_free(&fnhe->fnhe_rth_input);
			rt_fibinfo_free(&fnhe->fnhe_rth_output);
177

178 179 180 181 182 183 184 185
			kfree(fnhe);

			fnhe = next;
		}
	}
	kfree(hash);
}

186
static void rt_fibinfo_free_cpus(struct rtable __rcu * __percpu *rtp)
E
Eric Dumazet 已提交
187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202
{
	int cpu;

	if (!rtp)
		return;

	for_each_possible_cpu(cpu) {
		struct rtable *rt;

		rt = rcu_dereference_protected(*per_cpu_ptr(rtp, cpu), 1);
		if (rt)
			dst_free(&rt->dst);
	}
	free_percpu(rtp);
}

L
Linus Torvalds 已提交
203
/* Release a nexthop info record */
204 205 206 207
static void free_fib_info_rcu(struct rcu_head *head)
{
	struct fib_info *fi = container_of(head, struct fib_info, rcu);

208 209 210
	change_nexthops(fi) {
		if (nexthop_nh->nh_dev)
			dev_put(nexthop_nh->nh_dev);
211
		lwtstate_put(nexthop_nh->nh_lwtstate);
212
		free_nh_exceptions(nexthop_nh);
213 214
		rt_fibinfo_free_cpus(nexthop_nh->nh_pcpu_rth_output);
		rt_fibinfo_free(&nexthop_nh->nh_rth_input);
215 216
	} endfor_nexthops(fi);

217 218 219 220
	if (fi->fib_metrics != (u32 *) dst_default_metrics)
		kfree(fi->fib_metrics);
	kfree(fi);
}
L
Linus Torvalds 已提交
221 222 223 224

void free_fib_info(struct fib_info *fi)
{
	if (fi->fib_dead == 0) {
J
Joe Perches 已提交
225
		pr_warn("Freeing alive fib_info %p\n", fi);
L
Linus Torvalds 已提交
226 227 228
		return;
	}
	fib_info_cnt--;
229 230 231
#ifdef CONFIG_IP_ROUTE_CLASSID
	change_nexthops(fi) {
		if (nexthop_nh->nh_tclassid)
232
			fi->fib_net->ipv4.fib_num_tclassid_users--;
233 234
	} endfor_nexthops(fi);
#endif
235
	call_rcu(&fi->rcu, free_fib_info_rcu);
L
Linus Torvalds 已提交
236
}
I
Ido Schimmel 已提交
237
EXPORT_SYMBOL_GPL(free_fib_info);
L
Linus Torvalds 已提交
238 239 240

void fib_release_info(struct fib_info *fi)
{
241
	spin_lock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
242 243 244 245 246
	if (fi && --fi->fib_treeref == 0) {
		hlist_del(&fi->fib_hash);
		if (fi->fib_prefsrc)
			hlist_del(&fi->fib_lhash);
		change_nexthops(fi) {
247
			if (!nexthop_nh->nh_dev)
L
Linus Torvalds 已提交
248
				continue;
249
			hlist_del(&nexthop_nh->nh_hash);
L
Linus Torvalds 已提交
250 251 252 253
		} endfor_nexthops(fi)
		fi->fib_dead = 1;
		fib_info_put(fi);
	}
254
	spin_unlock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
255 256
}

E
Eric Dumazet 已提交
257
static inline int nh_comp(const struct fib_info *fi, const struct fib_info *ofi)
L
Linus Torvalds 已提交
258 259 260 261 262 263 264 265 266 267
{
	const struct fib_nh *onh = ofi->fib_nh;

	for_nexthops(fi) {
		if (nh->nh_oif != onh->nh_oif ||
		    nh->nh_gw  != onh->nh_gw ||
		    nh->nh_scope != onh->nh_scope ||
#ifdef CONFIG_IP_ROUTE_MULTIPATH
		    nh->nh_weight != onh->nh_weight ||
#endif
268
#ifdef CONFIG_IP_ROUTE_CLASSID
L
Linus Torvalds 已提交
269 270
		    nh->nh_tclassid != onh->nh_tclassid ||
#endif
271
		    lwtunnel_cmp_encap(nh->nh_lwtstate, onh->nh_lwtstate) ||
272
		    ((nh->nh_flags ^ onh->nh_flags) & ~RTNH_COMPARE_MASK))
L
Linus Torvalds 已提交
273 274 275 276 277 278
			return -1;
		onh++;
	} endfor_nexthops(fi);
	return 0;
}

279 280 281 282 283 284 285 286 287
static inline unsigned int fib_devindex_hashfn(unsigned int val)
{
	unsigned int mask = DEVINDEX_HASHSIZE - 1;

	return (val ^
		(val >> DEVINDEX_HASHBITS) ^
		(val >> (DEVINDEX_HASHBITS * 2))) & mask;
}

L
Linus Torvalds 已提交
288 289
static inline unsigned int fib_info_hashfn(const struct fib_info *fi)
{
290
	unsigned int mask = (fib_info_hash_size - 1);
L
Linus Torvalds 已提交
291 292
	unsigned int val = fi->fib_nhs;

293
	val ^= (fi->fib_protocol << 8) | fi->fib_scope;
A
Al Viro 已提交
294
	val ^= (__force u32)fi->fib_prefsrc;
L
Linus Torvalds 已提交
295
	val ^= fi->fib_priority;
296 297 298
	for_nexthops(fi) {
		val ^= fib_devindex_hashfn(nh->nh_oif);
	} endfor_nexthops(fi)
L
Linus Torvalds 已提交
299 300 301 302 303 304 305 306 307 308 309 310 311

	return (val ^ (val >> 7) ^ (val >> 12)) & mask;
}

static struct fib_info *fib_find_info(const struct fib_info *nfi)
{
	struct hlist_head *head;
	struct fib_info *fi;
	unsigned int hash;

	hash = fib_info_hashfn(nfi);
	head = &fib_info_hash[hash];

312
	hlist_for_each_entry(fi, head, fib_hash) {
O
Octavian Purdila 已提交
313
		if (!net_eq(fi->fib_net, nfi->fib_net))
314
			continue;
L
Linus Torvalds 已提交
315 316 317
		if (fi->fib_nhs != nfi->fib_nhs)
			continue;
		if (nfi->fib_protocol == fi->fib_protocol &&
318
		    nfi->fib_scope == fi->fib_scope &&
L
Linus Torvalds 已提交
319 320
		    nfi->fib_prefsrc == fi->fib_prefsrc &&
		    nfi->fib_priority == fi->fib_priority &&
E
Eric Dumazet 已提交
321
		    nfi->fib_type == fi->fib_type &&
L
Linus Torvalds 已提交
322
		    memcmp(nfi->fib_metrics, fi->fib_metrics,
E
Eric Dumazet 已提交
323
			   sizeof(u32) * RTAX_MAX) == 0 &&
324
		    !((nfi->fib_flags ^ fi->fib_flags) & ~RTNH_COMPARE_MASK) &&
L
Linus Torvalds 已提交
325 326 327 328 329 330 331 332
		    (nfi->fib_nhs == 0 || nh_comp(fi, nfi) == 0))
			return fi;
	}

	return NULL;
}

/* Check, that the gateway is already configured.
E
Eric Dumazet 已提交
333
 * Used only by redirect accept routine.
L
Linus Torvalds 已提交
334
 */
335
int ip_fib_check_default(__be32 gw, struct net_device *dev)
L
Linus Torvalds 已提交
336 337 338 339 340
{
	struct hlist_head *head;
	struct fib_nh *nh;
	unsigned int hash;

341
	spin_lock(&fib_info_lock);
L
Linus Torvalds 已提交
342 343 344

	hash = fib_devindex_hashfn(dev->ifindex);
	head = &fib_info_devhash[hash];
345
	hlist_for_each_entry(nh, head, nh_hash) {
L
Linus Torvalds 已提交
346 347
		if (nh->nh_dev == dev &&
		    nh->nh_gw == gw &&
E
Eric Dumazet 已提交
348
		    !(nh->nh_flags & RTNH_F_DEAD)) {
349
			spin_unlock(&fib_info_lock);
L
Linus Torvalds 已提交
350 351 352 353
			return 0;
		}
	}

354
	spin_unlock(&fib_info_lock);
L
Linus Torvalds 已提交
355 356 357 358

	return -1;
}

359 360 361 362 363 364
static inline size_t fib_nlmsg_size(struct fib_info *fi)
{
	size_t payload = NLMSG_ALIGN(sizeof(struct rtmsg))
			 + nla_total_size(4) /* RTA_TABLE */
			 + nla_total_size(4) /* RTA_DST */
			 + nla_total_size(4) /* RTA_PRIORITY */
365 366
			 + nla_total_size(4) /* RTA_PREFSRC */
			 + nla_total_size(TCP_CA_NAME_MAX); /* RTAX_CC_ALGO */
367 368 369 370 371

	/* space for nested metrics */
	payload += nla_total_size((RTAX_MAX * nla_total_size(4)));

	if (fi->fib_nhs) {
372
		size_t nh_encapsize = 0;
373 374 375 376 377 378 379 380
		/* Also handles the special case fib_nhs == 1 */

		/* each nexthop is packed in an attribute */
		size_t nhsize = nla_total_size(sizeof(struct rtnexthop));

		/* may contain flow and gateway attribute */
		nhsize += 2 * nla_total_size(4);

381 382 383 384 385 386 387 388 389 390 391
		/* grab encap info */
		for_nexthops(fi) {
			if (nh->nh_lwtstate) {
				/* RTA_ENCAP_TYPE */
				nh_encapsize += lwtunnel_get_encap_size(
						nh->nh_lwtstate);
				/* RTA_ENCAP */
				nh_encapsize +=  nla_total_size(2);
			}
		} endfor_nexthops(fi);

392
		/* all nexthops are packed in a nested attribute */
393 394 395
		payload += nla_total_size((fi->fib_nhs * nhsize) +
					  nh_encapsize);

396 397 398 399 400
	}

	return payload;
}

A
Al Viro 已提交
401
void rtmsg_fib(int event, __be32 key, struct fib_alias *fa,
402
	       int dst_len, u32 tb_id, const struct nl_info *info,
403
	       unsigned int nlm_flags)
L
Linus Torvalds 已提交
404 405
{
	struct sk_buff *skb;
406
	u32 seq = info->nlh ? info->nlh->nlmsg_seq : 0;
407
	int err = -ENOBUFS;
L
Linus Torvalds 已提交
408

409
	skb = nlmsg_new(fib_nlmsg_size(fa->fa_info), GFP_KERNEL);
410
	if (!skb)
411
		goto errout;
L
Linus Torvalds 已提交
412

413
	err = fib_dump_info(skb, info->portid, seq, event, tb_id,
414
			    fa->fa_type, key, dst_len,
415
			    fa->fa_tos, fa->fa_info, nlm_flags);
416 417 418 419 420 421
	if (err < 0) {
		/* -EMSGSIZE implies BUG in fib_nlmsg_size() */
		WARN_ON(err == -EMSGSIZE);
		kfree_skb(skb);
		goto errout;
	}
422
	rtnl_notify(skb, info->nl_net, info->portid, RTNLGRP_IPV4_ROUTE,
423 424
		    info->nlh, GFP_KERNEL);
	return;
425 426
errout:
	if (err < 0)
427
		rtnl_set_sk_err(info->nl_net, RTNLGRP_IPV4_ROUTE, err);
L
Linus Torvalds 已提交
428 429
}

430 431 432
static int fib_detect_death(struct fib_info *fi, int order,
			    struct fib_info **last_resort, int *last_idx,
			    int dflt)
L
Linus Torvalds 已提交
433 434 435 436 437 438 439 440
{
	struct neighbour *n;
	int state = NUD_NONE;

	n = neigh_lookup(&arp_tbl, &fi->fib_nh[0].nh_gw, fi->fib_dev);
	if (n) {
		state = n->nud_state;
		neigh_release(n);
441 442
	} else {
		return 0;
L
Linus Torvalds 已提交
443
	}
444
	if (state == NUD_REACHABLE)
L
Linus Torvalds 已提交
445
		return 0;
E
Eric Dumazet 已提交
446
	if ((state & NUD_VALID) && order != dflt)
L
Linus Torvalds 已提交
447
		return 0;
E
Eric Dumazet 已提交
448
	if ((state & NUD_VALID) ||
449
	    (*last_idx < 0 && order > dflt && state != NUD_INCOMPLETE)) {
L
Linus Torvalds 已提交
450 451 452 453 454 455 456 457
		*last_resort = fi;
		*last_idx = order;
	}
	return 1;
}

#ifdef CONFIG_IP_ROUTE_MULTIPATH

458
static int fib_count_nexthops(struct rtnexthop *rtnh, int remaining)
L
Linus Torvalds 已提交
459 460 461
{
	int nhs = 0;

462
	while (rtnh_ok(rtnh, remaining)) {
L
Linus Torvalds 已提交
463
		nhs++;
464 465 466 467 468
		rtnh = rtnh_next(rtnh, &remaining);
	}

	/* leftover implies invalid nexthop configuration, discard it */
	return remaining > 0 ? 0 : nhs;
L
Linus Torvalds 已提交
469 470
}

471 472
static int fib_get_nhs(struct fib_info *fi, struct rtnexthop *rtnh,
		       int remaining, struct fib_config *cfg)
L
Linus Torvalds 已提交
473
{
474 475 476
	struct net *net = cfg->fc_nlinfo.nl_net;
	int ret;

L
Linus Torvalds 已提交
477
	change_nexthops(fi) {
478 479 480
		int attrlen;

		if (!rtnh_ok(rtnh, remaining))
L
Linus Torvalds 已提交
481
			return -EINVAL;
482

483 484 485
		if (rtnh->rtnh_flags & (RTNH_F_DEAD | RTNH_F_LINKDOWN))
			return -EINVAL;

486 487 488 489
		nexthop_nh->nh_flags =
			(cfg->fc_flags & ~0xFF) | rtnh->rtnh_flags;
		nexthop_nh->nh_oif = rtnh->rtnh_ifindex;
		nexthop_nh->nh_weight = rtnh->rtnh_hops + 1;
490 491 492 493 494 495

		attrlen = rtnh_attrlen(rtnh);
		if (attrlen > 0) {
			struct nlattr *nla, *attrs = rtnh_attrs(rtnh);

			nla = nla_find(attrs, attrlen, RTA_GATEWAY);
496
			nexthop_nh->nh_gw = nla ? nla_get_in_addr(nla) : 0;
497
#ifdef CONFIG_IP_ROUTE_CLASSID
498
			nla = nla_find(attrs, attrlen, RTA_FLOW);
499
			nexthop_nh->nh_tclassid = nla ? nla_get_u32(nla) : 0;
500
			if (nexthop_nh->nh_tclassid)
501
				fi->fib_net->ipv4.fib_num_tclassid_users++;
L
Linus Torvalds 已提交
502
#endif
503 504 505 506 507 508 509 510 511 512 513 514 515 516
			nla = nla_find(attrs, attrlen, RTA_ENCAP);
			if (nla) {
				struct lwtunnel_state *lwtstate;
				struct net_device *dev = NULL;
				struct nlattr *nla_entype;

				nla_entype = nla_find(attrs, attrlen,
						      RTA_ENCAP_TYPE);
				if (!nla_entype)
					goto err_inval;
				if (cfg->fc_oif)
					dev = __dev_get_by_index(net, cfg->fc_oif);
				ret = lwtunnel_build_state(dev, nla_get_u16(
							   nla_entype),
517 518
							   nla,  AF_INET, cfg,
							   &lwtstate);
519 520
				if (ret)
					goto errout;
521 522
				nexthop_nh->nh_lwtstate =
					lwtstate_get(lwtstate);
523
			}
L
Linus Torvalds 已提交
524
		}
525 526

		rtnh = rtnh_next(rtnh, &remaining);
L
Linus Torvalds 已提交
527
	} endfor_nexthops(fi);
528

L
Linus Torvalds 已提交
529
	return 0;
530 531 532 533 534 535

err_inval:
	ret = -EINVAL;

errout:
	return ret;
L
Linus Torvalds 已提交
536 537
}

P
Peter Nørlund 已提交
538 539 540 541 542 543 544 545 546 547 548 549 550 551
static void fib_rebalance(struct fib_info *fi)
{
	int total;
	int w;
	struct in_device *in_dev;

	if (fi->fib_nhs < 2)
		return;

	total = 0;
	for_nexthops(fi) {
		if (nh->nh_flags & RTNH_F_DEAD)
			continue;

552
		in_dev = __in_dev_get_rtnl(nh->nh_dev);
P
Peter Nørlund 已提交
553 554 555 556 557 558 559 560 561 562 563 564 565

		if (in_dev &&
		    IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev) &&
		    nh->nh_flags & RTNH_F_LINKDOWN)
			continue;

		total += nh->nh_weight;
	} endfor_nexthops(fi);

	w = 0;
	change_nexthops(fi) {
		int upper_bound;

566
		in_dev = __in_dev_get_rtnl(nexthop_nh->nh_dev);
P
Peter Nørlund 已提交
567 568 569 570 571 572 573 574 575

		if (nexthop_nh->nh_flags & RTNH_F_DEAD) {
			upper_bound = -1;
		} else if (in_dev &&
			   IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev) &&
			   nexthop_nh->nh_flags & RTNH_F_LINKDOWN) {
			upper_bound = -1;
		} else {
			w += nexthop_nh->nh_weight;
576 577
			upper_bound = DIV_ROUND_CLOSEST_ULL((u64)w << 31,
							    total) - 1;
P
Peter Nørlund 已提交
578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598
		}

		atomic_set(&nexthop_nh->nh_upper_bound, upper_bound);
	} endfor_nexthops(fi);

	net_get_random_once(&fib_multipath_secret,
			    sizeof(fib_multipath_secret));
}

static inline void fib_add_weight(struct fib_info *fi,
				  const struct fib_nh *nh)
{
	fi->fib_weight += nh->nh_weight;
}

#else /* CONFIG_IP_ROUTE_MULTIPATH */

#define fib_rebalance(fi) do { } while (0)
#define fib_add_weight(fi, nh) do { } while (0)

#endif /* CONFIG_IP_ROUTE_MULTIPATH */
L
Linus Torvalds 已提交
599

Y
Ying Xue 已提交
600 601
static int fib_encap_match(struct net *net, u16 encap_type,
			   struct nlattr *encap,
602 603
			   int oif, const struct fib_nh *nh,
			   const struct fib_config *cfg)
604 605 606
{
	struct lwtunnel_state *lwtstate;
	struct net_device *dev = NULL;
J
Jiri Benc 已提交
607
	int ret, result = 0;
608 609 610 611 612 613

	if (encap_type == LWTUNNEL_ENCAP_NONE)
		return 0;

	if (oif)
		dev = __dev_get_by_index(net, oif);
614 615
	ret = lwtunnel_build_state(dev, encap_type, encap,
				   AF_INET, cfg, &lwtstate);
J
Jiri Benc 已提交
616 617 618 619
	if (!ret) {
		result = lwtunnel_cmp_encap(lwtstate, nh->nh_lwtstate);
		lwtstate_free(lwtstate);
	}
620

J
Jiri Benc 已提交
621
	return result;
622 623
}

624
int fib_nh_match(struct fib_config *cfg, struct fib_info *fi)
L
Linus Torvalds 已提交
625
{
626
	struct net *net = cfg->fc_nlinfo.nl_net;
L
Linus Torvalds 已提交
627
#ifdef CONFIG_IP_ROUTE_MULTIPATH
628 629
	struct rtnexthop *rtnh;
	int remaining;
L
Linus Torvalds 已提交
630 631
#endif

632
	if (cfg->fc_priority && cfg->fc_priority != fi->fib_priority)
L
Linus Torvalds 已提交
633 634
		return 1;

635
	if (cfg->fc_oif || cfg->fc_gw) {
636 637 638
		if (cfg->fc_encap) {
			if (fib_encap_match(net, cfg->fc_encap_type,
					    cfg->fc_encap, cfg->fc_oif,
639
					    fi->fib_nh, cfg))
640 641
			    return 1;
		}
642 643
		if ((!cfg->fc_oif || cfg->fc_oif == fi->fib_nh->nh_oif) &&
		    (!cfg->fc_gw  || cfg->fc_gw == fi->fib_nh->nh_gw))
L
Linus Torvalds 已提交
644 645 646 647 648
			return 0;
		return 1;
	}

#ifdef CONFIG_IP_ROUTE_MULTIPATH
649
	if (!cfg->fc_mp)
L
Linus Torvalds 已提交
650
		return 0;
651 652 653

	rtnh = cfg->fc_mp;
	remaining = cfg->fc_mp_len;
654

L
Linus Torvalds 已提交
655
	for_nexthops(fi) {
656
		int attrlen;
L
Linus Torvalds 已提交
657

658
		if (!rtnh_ok(rtnh, remaining))
L
Linus Torvalds 已提交
659
			return -EINVAL;
660 661

		if (rtnh->rtnh_ifindex && rtnh->rtnh_ifindex != nh->nh_oif)
L
Linus Torvalds 已提交
662
			return 1;
663 664

		attrlen = rtnh_attrlen(rtnh);
665
		if (attrlen > 0) {
666 667 668
			struct nlattr *nla, *attrs = rtnh_attrs(rtnh);

			nla = nla_find(attrs, attrlen, RTA_GATEWAY);
669
			if (nla && nla_get_in_addr(nla) != nh->nh_gw)
L
Linus Torvalds 已提交
670
				return 1;
671
#ifdef CONFIG_IP_ROUTE_CLASSID
672 673
			nla = nla_find(attrs, attrlen, RTA_FLOW);
			if (nla && nla_get_u32(nla) != nh->nh_tclassid)
L
Linus Torvalds 已提交
674 675 676
				return 1;
#endif
		}
677 678

		rtnh = rtnh_next(rtnh, &remaining);
L
Linus Torvalds 已提交
679 680 681 682 683 684 685
	} endfor_nexthops(fi);
#endif
	return 0;
}


/*
E
Eric Dumazet 已提交
686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726
 * Picture
 * -------
 *
 * Semantics of nexthop is very messy by historical reasons.
 * We have to take into account, that:
 * a) gateway can be actually local interface address,
 *    so that gatewayed route is direct.
 * b) gateway must be on-link address, possibly
 *    described not by an ifaddr, but also by a direct route.
 * c) If both gateway and interface are specified, they should not
 *    contradict.
 * d) If we use tunnel routes, gateway could be not on-link.
 *
 * Attempt to reconcile all of these (alas, self-contradictory) conditions
 * results in pretty ugly and hairy code with obscure logic.
 *
 * I chose to generalized it instead, so that the size
 * of code does not increase practically, but it becomes
 * much more general.
 * Every prefix is assigned a "scope" value: "host" is local address,
 * "link" is direct route,
 * [ ... "site" ... "interior" ... ]
 * and "universe" is true gateway route with global meaning.
 *
 * Every prefix refers to a set of "nexthop"s (gw, oif),
 * where gw must have narrower scope. This recursion stops
 * when gw has LOCAL scope or if "nexthop" is declared ONLINK,
 * which means that gw is forced to be on link.
 *
 * Code is still hairy, but now it is apparently logically
 * consistent and very flexible. F.e. as by-product it allows
 * to co-exists in peace independent exterior and interior
 * routing processes.
 *
 * Normally it looks as following.
 *
 * {universe prefix}  -> (gw, oif) [scope link]
 *		  |
 *		  |-> {link prefix} -> (gw, oif) [scope local]
 *					|
 *					|-> {local prefix} (terminal node)
L
Linus Torvalds 已提交
727
 */
728 729
static int fib_check_nh(struct fib_config *cfg, struct fib_info *fi,
			struct fib_nh *nh)
L
Linus Torvalds 已提交
730
{
731
	int err = 0;
732
	struct net *net;
E
Eric Dumazet 已提交
733
	struct net_device *dev;
L
Linus Torvalds 已提交
734

735
	net = cfg->fc_nlinfo.nl_net;
L
Linus Torvalds 已提交
736 737 738
	if (nh->nh_gw) {
		struct fib_result res;

E
Eric Dumazet 已提交
739
		if (nh->nh_flags & RTNH_F_ONLINK) {
D
David Ahern 已提交
740
			unsigned int addr_type;
L
Linus Torvalds 已提交
741

742
			if (cfg->fc_scope >= RT_SCOPE_LINK)
L
Linus Torvalds 已提交
743
				return -EINVAL;
E
Eric Dumazet 已提交
744 745
			dev = __dev_get_by_index(net, nh->nh_oif);
			if (!dev)
L
Linus Torvalds 已提交
746
				return -ENODEV;
E
Eric Dumazet 已提交
747
			if (!(dev->flags & IFF_UP))
L
Linus Torvalds 已提交
748
				return -ENETDOWN;
D
David Ahern 已提交
749 750 751
			addr_type = inet_addr_type_dev_table(net, dev, nh->nh_gw);
			if (addr_type != RTN_UNICAST)
				return -EINVAL;
752 753
			if (!netif_carrier_ok(dev))
				nh->nh_flags |= RTNH_F_LINKDOWN;
L
Linus Torvalds 已提交
754 755 756 757 758
			nh->nh_dev = dev;
			dev_hold(dev);
			nh->nh_scope = RT_SCOPE_LINK;
			return 0;
		}
E
Eric Dumazet 已提交
759
		rcu_read_lock();
L
Linus Torvalds 已提交
760
		{
761
			struct fib_table *tbl = NULL;
D
David S. Miller 已提交
762 763 764 765
			struct flowi4 fl4 = {
				.daddr = nh->nh_gw,
				.flowi4_scope = cfg->fc_scope + 1,
				.flowi4_oif = nh->nh_oif,
766
				.flowi4_iif = LOOPBACK_IFINDEX,
767
			};
L
Linus Torvalds 已提交
768 769

			/* It is not necessary, but requires a bit of thinking */
D
David S. Miller 已提交
770 771
			if (fl4.flowi4_scope < RT_SCOPE_LINK)
				fl4.flowi4_scope = RT_SCOPE_LINK;
772 773 774 775 776 777

			if (cfg->fc_table)
				tbl = fib_get_table(net, cfg->fc_table);

			if (tbl)
				err = fib_table_lookup(tbl, &fl4, &res,
778 779
						       FIB_LOOKUP_IGNORE_LINKSTATE |
						       FIB_LOOKUP_NOREF);
D
David Ahern 已提交
780 781 782 783 784 785

			/* on error or if no table given do full lookup. This
			 * is needed for example when nexthops are in the local
			 * table rather than the given table
			 */
			if (!tbl || err) {
786 787
				err = fib_lookup(net, &fl4, &res,
						 FIB_LOOKUP_IGNORE_LINKSTATE);
D
David Ahern 已提交
788 789
			}

E
Eric Dumazet 已提交
790 791
			if (err) {
				rcu_read_unlock();
L
Linus Torvalds 已提交
792
				return err;
E
Eric Dumazet 已提交
793
			}
L
Linus Torvalds 已提交
794 795 796 797 798 799
		}
		err = -EINVAL;
		if (res.type != RTN_UNICAST && res.type != RTN_LOCAL)
			goto out;
		nh->nh_scope = res.scope;
		nh->nh_oif = FIB_RES_OIF(res);
E
Eric Dumazet 已提交
800 801
		nh->nh_dev = dev = FIB_RES_DEV(res);
		if (!dev)
L
Linus Torvalds 已提交
802
			goto out;
E
Eric Dumazet 已提交
803
		dev_hold(dev);
804 805
		if (!netif_carrier_ok(dev))
			nh->nh_flags |= RTNH_F_LINKDOWN;
806
		err = (dev->flags & IFF_UP) ? 0 : -ENETDOWN;
L
Linus Torvalds 已提交
807 808 809
	} else {
		struct in_device *in_dev;

E
Eric Dumazet 已提交
810
		if (nh->nh_flags & (RTNH_F_PERVASIVE | RTNH_F_ONLINK))
L
Linus Torvalds 已提交
811 812
			return -EINVAL;

813 814
		rcu_read_lock();
		err = -ENODEV;
815
		in_dev = inetdev_by_index(net, nh->nh_oif);
816
		if (!in_dev)
817 818 819 820
			goto out;
		err = -ENETDOWN;
		if (!(in_dev->dev->flags & IFF_UP))
			goto out;
L
Linus Torvalds 已提交
821 822 823
		nh->nh_dev = in_dev->dev;
		dev_hold(nh->nh_dev);
		nh->nh_scope = RT_SCOPE_HOST;
824 825
		if (!netif_carrier_ok(nh->nh_dev))
			nh->nh_flags |= RTNH_F_LINKDOWN;
826
		err = 0;
L
Linus Torvalds 已提交
827
	}
828 829 830
out:
	rcu_read_unlock();
	return err;
L
Linus Torvalds 已提交
831 832
}

A
Al Viro 已提交
833
static inline unsigned int fib_laddr_hashfn(__be32 val)
L
Linus Torvalds 已提交
834
{
835
	unsigned int mask = (fib_info_hash_size - 1);
L
Linus Torvalds 已提交
836

E
Eric Dumazet 已提交
837 838 839
	return ((__force u32)val ^
		((__force u32)val >> 7) ^
		((__force u32)val >> 14)) & mask;
L
Linus Torvalds 已提交
840 841
}

842
static struct hlist_head *fib_info_hash_alloc(int bytes)
L
Linus Torvalds 已提交
843 844
{
	if (bytes <= PAGE_SIZE)
845
		return kzalloc(bytes, GFP_KERNEL);
L
Linus Torvalds 已提交
846 847
	else
		return (struct hlist_head *)
E
Eric Dumazet 已提交
848 849
			__get_free_pages(GFP_KERNEL | __GFP_ZERO,
					 get_order(bytes));
L
Linus Torvalds 已提交
850 851
}

852
static void fib_info_hash_free(struct hlist_head *hash, int bytes)
L
Linus Torvalds 已提交
853 854 855 856 857 858 859 860 861 862
{
	if (!hash)
		return;

	if (bytes <= PAGE_SIZE)
		kfree(hash);
	else
		free_pages((unsigned long) hash, get_order(bytes));
}

863 864 865
static void fib_info_hash_move(struct hlist_head *new_info_hash,
			       struct hlist_head *new_laddrhash,
			       unsigned int new_size)
L
Linus Torvalds 已提交
866
{
867
	struct hlist_head *old_info_hash, *old_laddrhash;
868
	unsigned int old_size = fib_info_hash_size;
869
	unsigned int i, bytes;
L
Linus Torvalds 已提交
870

871
	spin_lock_bh(&fib_info_lock);
872 873
	old_info_hash = fib_info_hash;
	old_laddrhash = fib_info_laddrhash;
874
	fib_info_hash_size = new_size;
L
Linus Torvalds 已提交
875 876 877

	for (i = 0; i < old_size; i++) {
		struct hlist_head *head = &fib_info_hash[i];
878
		struct hlist_node *n;
L
Linus Torvalds 已提交
879 880
		struct fib_info *fi;

881
		hlist_for_each_entry_safe(fi, n, head, fib_hash) {
L
Linus Torvalds 已提交
882 883 884 885 886 887 888 889 890 891 892 893
			struct hlist_head *dest;
			unsigned int new_hash;

			new_hash = fib_info_hashfn(fi);
			dest = &new_info_hash[new_hash];
			hlist_add_head(&fi->fib_hash, dest);
		}
	}
	fib_info_hash = new_info_hash;

	for (i = 0; i < old_size; i++) {
		struct hlist_head *lhead = &fib_info_laddrhash[i];
894
		struct hlist_node *n;
L
Linus Torvalds 已提交
895 896
		struct fib_info *fi;

897
		hlist_for_each_entry_safe(fi, n, lhead, fib_lhash) {
L
Linus Torvalds 已提交
898 899 900 901 902 903 904 905 906 907
			struct hlist_head *ldest;
			unsigned int new_hash;

			new_hash = fib_laddr_hashfn(fi->fib_prefsrc);
			ldest = &new_laddrhash[new_hash];
			hlist_add_head(&fi->fib_lhash, ldest);
		}
	}
	fib_info_laddrhash = new_laddrhash;

908
	spin_unlock_bh(&fib_info_lock);
909 910

	bytes = old_size * sizeof(struct hlist_head *);
911 912
	fib_info_hash_free(old_info_hash, bytes);
	fib_info_hash_free(old_laddrhash, bytes);
L
Linus Torvalds 已提交
913 914
}

915 916 917 918
__be32 fib_info_update_nh_saddr(struct net *net, struct fib_nh *nh)
{
	nh->nh_saddr = inet_select_addr(nh->nh_dev,
					nh->nh_gw,
919
					nh->nh_parent->fib_scope);
920 921 922 923 924
	nh->nh_saddr_genid = atomic_read(&net->ipv4.dev_addr_genid);

	return nh->nh_saddr;
}

925 926 927 928
static bool fib_valid_prefsrc(struct fib_config *cfg, __be32 fib_prefsrc)
{
	if (cfg->fc_type != RTN_LOCAL || !cfg->fc_dst ||
	    fib_prefsrc != cfg->fc_dst) {
D
David Ahern 已提交
929
		u32 tb_id = cfg->fc_table;
D
David Ahern 已提交
930
		int rc;
931 932 933 934

		if (tb_id == RT_TABLE_MAIN)
			tb_id = RT_TABLE_LOCAL;

D
David Ahern 已提交
935 936 937 938 939 940
		rc = inet_addr_type_table(cfg->fc_nlinfo.nl_net,
					  fib_prefsrc, tb_id);

		if (rc != RTN_LOCAL && tb_id != RT_TABLE_LOCAL) {
			rc = inet_addr_type_table(cfg->fc_nlinfo.nl_net,
						  fib_prefsrc, RT_TABLE_LOCAL);
941
		}
D
David Ahern 已提交
942 943 944

		if (rc != RTN_LOCAL)
			return false;
945 946 947 948
	}
	return true;
}

949 950 951
static int
fib_convert_metrics(struct fib_info *fi, const struct fib_config *cfg)
{
952
	bool ecn_ca = false;
953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971
	struct nlattr *nla;
	int remaining;

	if (!cfg->fc_mx)
		return 0;

	nla_for_each_attr(nla, cfg->fc_mx, cfg->fc_mx_len, remaining) {
		int type = nla_type(nla);
		u32 val;

		if (!type)
			continue;
		if (type > RTAX_MAX)
			return -EINVAL;

		if (type == RTAX_CC_ALGO) {
			char tmp[TCP_CA_NAME_MAX];

			nla_strlcpy(tmp, nla, sizeof(tmp));
972
			val = tcp_ca_get_key_by_name(tmp, &ecn_ca);
973 974 975 976 977 978 979 980 981
			if (val == TCP_CA_UNSPEC)
				return -EINVAL;
		} else {
			val = nla_get_u32(nla);
		}
		if (type == RTAX_ADVMSS && val > 65535 - 40)
			val = 65535 - 40;
		if (type == RTAX_MTU && val > 65535 - 15)
			val = 65535 - 15;
982 983
		if (type == RTAX_HOPLIMIT && val > 255)
			val = 255;
984 985
		if (type == RTAX_FEATURES && (val & ~RTAX_FEATURE_MASK))
			return -EINVAL;
986 987 988
		fi->fib_metrics[type - 1] = val;
	}

989 990 991
	if (ecn_ca)
		fi->fib_metrics[RTAX_FEATURES - 1] |= DST_FEATURE_ECN_CA;

992 993 994
	return 0;
}

995
struct fib_info *fib_create_info(struct fib_config *cfg)
L
Linus Torvalds 已提交
996 997 998 999 1000
{
	int err;
	struct fib_info *fi = NULL;
	struct fib_info *ofi;
	int nhs = 1;
1001
	struct net *net = cfg->fc_nlinfo.nl_net;
L
Linus Torvalds 已提交
1002

1003 1004 1005
	if (cfg->fc_type > RTN_MAX)
		goto err_inval;

L
Linus Torvalds 已提交
1006
	/* Fast check to catch the most weird cases */
1007
	if (fib_props[cfg->fc_type].scope > cfg->fc_scope)
L
Linus Torvalds 已提交
1008 1009
		goto err_inval;

1010 1011 1012
	if (cfg->fc_flags & (RTNH_F_DEAD | RTNH_F_LINKDOWN))
		goto err_inval;

L
Linus Torvalds 已提交
1013
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1014 1015
	if (cfg->fc_mp) {
		nhs = fib_count_nexthops(cfg->fc_mp, cfg->fc_mp_len);
L
Linus Torvalds 已提交
1016 1017 1018 1019 1020 1021
		if (nhs == 0)
			goto err_inval;
	}
#endif

	err = -ENOBUFS;
1022 1023
	if (fib_info_cnt >= fib_info_hash_size) {
		unsigned int new_size = fib_info_hash_size << 1;
L
Linus Torvalds 已提交
1024 1025 1026 1027 1028
		struct hlist_head *new_info_hash;
		struct hlist_head *new_laddrhash;
		unsigned int bytes;

		if (!new_size)
1029
			new_size = 16;
L
Linus Torvalds 已提交
1030
		bytes = new_size * sizeof(struct hlist_head *);
1031 1032
		new_info_hash = fib_info_hash_alloc(bytes);
		new_laddrhash = fib_info_hash_alloc(bytes);
L
Linus Torvalds 已提交
1033
		if (!new_info_hash || !new_laddrhash) {
1034 1035
			fib_info_hash_free(new_info_hash, bytes);
			fib_info_hash_free(new_laddrhash, bytes);
1036
		} else
1037
			fib_info_hash_move(new_info_hash, new_laddrhash, new_size);
L
Linus Torvalds 已提交
1038

1039
		if (!fib_info_hash_size)
L
Linus Torvalds 已提交
1040 1041 1042
			goto failure;
	}

1043
	fi = kzalloc(sizeof(*fi)+nhs*sizeof(struct fib_nh), GFP_KERNEL);
1044
	if (!fi)
L
Linus Torvalds 已提交
1045
		goto failure;
1046
	fib_info_cnt++;
1047 1048 1049 1050 1051 1052
	if (cfg->fc_mx) {
		fi->fib_metrics = kzalloc(sizeof(u32) * RTAX_MAX, GFP_KERNEL);
		if (!fi->fib_metrics)
			goto failure;
	} else
		fi->fib_metrics = (u32 *) dst_default_metrics;
L
Linus Torvalds 已提交
1053

1054
	fi->fib_net = net;
1055
	fi->fib_protocol = cfg->fc_protocol;
1056
	fi->fib_scope = cfg->fc_scope;
1057 1058 1059
	fi->fib_flags = cfg->fc_flags;
	fi->fib_priority = cfg->fc_priority;
	fi->fib_prefsrc = cfg->fc_prefsrc;
E
Eric Dumazet 已提交
1060
	fi->fib_type = cfg->fc_type;
1061
	fi->fib_tb_id = cfg->fc_table;
L
Linus Torvalds 已提交
1062 1063 1064

	fi->fib_nhs = nhs;
	change_nexthops(fi) {
1065
		nexthop_nh->nh_parent = fi;
E
Eric Dumazet 已提交
1066
		nexthop_nh->nh_pcpu_rth_output = alloc_percpu(struct rtable __rcu *);
1067 1068
		if (!nexthop_nh->nh_pcpu_rth_output)
			goto failure;
L
Linus Torvalds 已提交
1069 1070
	} endfor_nexthops(fi)

1071 1072 1073
	err = fib_convert_metrics(fi, cfg);
	if (err)
		goto failure;
L
Linus Torvalds 已提交
1074

1075
	if (cfg->fc_mp) {
L
Linus Torvalds 已提交
1076
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1077 1078
		err = fib_get_nhs(fi, cfg->fc_mp, cfg->fc_mp_len, cfg);
		if (err != 0)
L
Linus Torvalds 已提交
1079
			goto failure;
1080
		if (cfg->fc_oif && fi->fib_nh->nh_oif != cfg->fc_oif)
L
Linus Torvalds 已提交
1081
			goto err_inval;
1082
		if (cfg->fc_gw && fi->fib_nh->nh_gw != cfg->fc_gw)
L
Linus Torvalds 已提交
1083
			goto err_inval;
1084
#ifdef CONFIG_IP_ROUTE_CLASSID
1085
		if (cfg->fc_flow && fi->fib_nh->nh_tclassid != cfg->fc_flow)
L
Linus Torvalds 已提交
1086 1087 1088 1089 1090 1091 1092
			goto err_inval;
#endif
#else
		goto err_inval;
#endif
	} else {
		struct fib_nh *nh = fi->fib_nh;
1093

1094 1095 1096 1097 1098 1099 1100 1101 1102
		if (cfg->fc_encap) {
			struct lwtunnel_state *lwtstate;
			struct net_device *dev = NULL;

			if (cfg->fc_encap_type == LWTUNNEL_ENCAP_NONE)
				goto err_inval;
			if (cfg->fc_oif)
				dev = __dev_get_by_index(net, cfg->fc_oif);
			err = lwtunnel_build_state(dev, cfg->fc_encap_type,
1103 1104
						   cfg->fc_encap, AF_INET, cfg,
						   &lwtstate);
1105 1106 1107
			if (err)
				goto failure;

1108
			nh->nh_lwtstate = lwtstate_get(lwtstate);
1109
		}
1110 1111 1112
		nh->nh_oif = cfg->fc_oif;
		nh->nh_gw = cfg->fc_gw;
		nh->nh_flags = cfg->fc_flags;
1113
#ifdef CONFIG_IP_ROUTE_CLASSID
1114
		nh->nh_tclassid = cfg->fc_flow;
1115
		if (nh->nh_tclassid)
1116
			fi->fib_net->ipv4.fib_num_tclassid_users++;
L
Linus Torvalds 已提交
1117 1118 1119 1120 1121 1122
#endif
#ifdef CONFIG_IP_ROUTE_MULTIPATH
		nh->nh_weight = 1;
#endif
	}

1123 1124
	if (fib_props[cfg->fc_type].error) {
		if (cfg->fc_gw || cfg->fc_oif || cfg->fc_mp)
L
Linus Torvalds 已提交
1125 1126
			goto err_inval;
		goto link_it;
1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137
	} else {
		switch (cfg->fc_type) {
		case RTN_UNICAST:
		case RTN_LOCAL:
		case RTN_BROADCAST:
		case RTN_ANYCAST:
		case RTN_MULTICAST:
			break;
		default:
			goto err_inval;
		}
L
Linus Torvalds 已提交
1138 1139
	}

1140
	if (cfg->fc_scope > RT_SCOPE_HOST)
L
Linus Torvalds 已提交
1141 1142
		goto err_inval;

1143
	if (cfg->fc_scope == RT_SCOPE_HOST) {
L
Linus Torvalds 已提交
1144 1145 1146 1147 1148 1149
		struct fib_nh *nh = fi->fib_nh;

		/* Local address is added. */
		if (nhs != 1 || nh->nh_gw)
			goto err_inval;
		nh->nh_scope = RT_SCOPE_NOWHERE;
1150
		nh->nh_dev = dev_get_by_index(net, fi->fib_nh->nh_oif);
L
Linus Torvalds 已提交
1151
		err = -ENODEV;
1152
		if (!nh->nh_dev)
L
Linus Torvalds 已提交
1153 1154
			goto failure;
	} else {
1155 1156
		int linkdown = 0;

L
Linus Torvalds 已提交
1157
		change_nexthops(fi) {
E
Eric Dumazet 已提交
1158 1159
			err = fib_check_nh(cfg, fi, nexthop_nh);
			if (err != 0)
L
Linus Torvalds 已提交
1160
				goto failure;
1161 1162
			if (nexthop_nh->nh_flags & RTNH_F_LINKDOWN)
				linkdown++;
L
Linus Torvalds 已提交
1163
		} endfor_nexthops(fi)
1164 1165
		if (linkdown == fi->fib_nhs)
			fi->fib_flags |= RTNH_F_LINKDOWN;
L
Linus Torvalds 已提交
1166 1167
	}

1168 1169
	if (fi->fib_prefsrc && !fib_valid_prefsrc(cfg, fi->fib_prefsrc))
		goto err_inval;
L
Linus Torvalds 已提交
1170

1171
	change_nexthops(fi) {
1172
		fib_info_update_nh_saddr(net, nexthop_nh);
P
Peter Nørlund 已提交
1173
		fib_add_weight(fi, nexthop_nh);
1174 1175
	} endfor_nexthops(fi)

P
Peter Nørlund 已提交
1176 1177
	fib_rebalance(fi);

L
Linus Torvalds 已提交
1178
link_it:
E
Eric Dumazet 已提交
1179 1180
	ofi = fib_find_info(fi);
	if (ofi) {
L
Linus Torvalds 已提交
1181 1182 1183 1184 1185 1186 1187 1188
		fi->fib_dead = 1;
		free_fib_info(fi);
		ofi->fib_treeref++;
		return ofi;
	}

	fi->fib_treeref++;
	atomic_inc(&fi->fib_clntref);
1189
	spin_lock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201
	hlist_add_head(&fi->fib_hash,
		       &fib_info_hash[fib_info_hashfn(fi)]);
	if (fi->fib_prefsrc) {
		struct hlist_head *head;

		head = &fib_info_laddrhash[fib_laddr_hashfn(fi->fib_prefsrc)];
		hlist_add_head(&fi->fib_lhash, head);
	}
	change_nexthops(fi) {
		struct hlist_head *head;
		unsigned int hash;

1202
		if (!nexthop_nh->nh_dev)
L
Linus Torvalds 已提交
1203
			continue;
1204
		hash = fib_devindex_hashfn(nexthop_nh->nh_dev->ifindex);
L
Linus Torvalds 已提交
1205
		head = &fib_info_devhash[hash];
1206
		hlist_add_head(&nexthop_nh->nh_hash, head);
L
Linus Torvalds 已提交
1207
	} endfor_nexthops(fi)
1208
	spin_unlock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
1209 1210 1211 1212 1213 1214
	return fi;

err_inval:
	err = -EINVAL;

failure:
1215
	if (fi) {
L
Linus Torvalds 已提交
1216 1217 1218
		fi->fib_dead = 1;
		free_fib_info(fi);
	}
1219 1220

	return ERR_PTR(err);
L
Linus Torvalds 已提交
1221 1222
}

1223
int fib_dump_info(struct sk_buff *skb, u32 portid, u32 seq, int event,
1224
		  u32 tb_id, u8 type, __be32 dst, int dst_len, u8 tos,
1225
		  struct fib_info *fi, unsigned int flags)
L
Linus Torvalds 已提交
1226
{
1227
	struct nlmsghdr *nlh;
L
Linus Torvalds 已提交
1228 1229
	struct rtmsg *rtm;

1230
	nlh = nlmsg_put(skb, portid, seq, event, sizeof(*rtm), flags);
1231
	if (!nlh)
1232
		return -EMSGSIZE;
1233 1234

	rtm = nlmsg_data(nlh);
L
Linus Torvalds 已提交
1235 1236 1237 1238
	rtm->rtm_family = AF_INET;
	rtm->rtm_dst_len = dst_len;
	rtm->rtm_src_len = 0;
	rtm->rtm_tos = tos;
1239 1240 1241 1242
	if (tb_id < 256)
		rtm->rtm_table = tb_id;
	else
		rtm->rtm_table = RT_TABLE_COMPAT;
D
David S. Miller 已提交
1243 1244
	if (nla_put_u32(skb, RTA_TABLE, tb_id))
		goto nla_put_failure;
L
Linus Torvalds 已提交
1245 1246
	rtm->rtm_type = type;
	rtm->rtm_flags = fi->fib_flags;
1247
	rtm->rtm_scope = fi->fib_scope;
L
Linus Torvalds 已提交
1248
	rtm->rtm_protocol = fi->fib_protocol;
1249

D
David S. Miller 已提交
1250
	if (rtm->rtm_dst_len &&
1251
	    nla_put_in_addr(skb, RTA_DST, dst))
D
David S. Miller 已提交
1252 1253 1254 1255
		goto nla_put_failure;
	if (fi->fib_priority &&
	    nla_put_u32(skb, RTA_PRIORITY, fi->fib_priority))
		goto nla_put_failure;
L
Linus Torvalds 已提交
1256
	if (rtnetlink_put_metrics(skb, fi->fib_metrics) < 0)
1257 1258
		goto nla_put_failure;

D
David S. Miller 已提交
1259
	if (fi->fib_prefsrc &&
1260
	    nla_put_in_addr(skb, RTA_PREFSRC, fi->fib_prefsrc))
D
David S. Miller 已提交
1261
		goto nla_put_failure;
L
Linus Torvalds 已提交
1262
	if (fi->fib_nhs == 1) {
1263 1264
		struct in_device *in_dev;

D
David S. Miller 已提交
1265
		if (fi->fib_nh->nh_gw &&
1266
		    nla_put_in_addr(skb, RTA_GATEWAY, fi->fib_nh->nh_gw))
D
David S. Miller 已提交
1267 1268 1269 1270
			goto nla_put_failure;
		if (fi->fib_nh->nh_oif &&
		    nla_put_u32(skb, RTA_OIF, fi->fib_nh->nh_oif))
			goto nla_put_failure;
1271
		if (fi->fib_nh->nh_flags & RTNH_F_LINKDOWN) {
1272
			in_dev = __in_dev_get_rtnl(fi->fib_nh->nh_dev);
1273 1274 1275 1276
			if (in_dev &&
			    IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev))
				rtm->rtm_flags |= RTNH_F_DEAD;
		}
1277
#ifdef CONFIG_IP_ROUTE_CLASSID
D
David S. Miller 已提交
1278 1279 1280
		if (fi->fib_nh[0].nh_tclassid &&
		    nla_put_u32(skb, RTA_FLOW, fi->fib_nh[0].nh_tclassid))
			goto nla_put_failure;
1281
#endif
1282 1283 1284
		if (fi->fib_nh->nh_lwtstate &&
		    lwtunnel_fill_encap(skb, fi->fib_nh->nh_lwtstate) < 0)
			goto nla_put_failure;
L
Linus Torvalds 已提交
1285 1286 1287
	}
#ifdef CONFIG_IP_ROUTE_MULTIPATH
	if (fi->fib_nhs > 1) {
1288 1289 1290 1291
		struct rtnexthop *rtnh;
		struct nlattr *mp;

		mp = nla_nest_start(skb, RTA_MULTIPATH);
1292
		if (!mp)
1293
			goto nla_put_failure;
L
Linus Torvalds 已提交
1294 1295

		for_nexthops(fi) {
1296 1297
			struct in_device *in_dev;

1298
			rtnh = nla_reserve_nohdr(skb, sizeof(*rtnh));
1299
			if (!rtnh)
1300 1301 1302
				goto nla_put_failure;

			rtnh->rtnh_flags = nh->nh_flags & 0xFF;
1303
			if (nh->nh_flags & RTNH_F_LINKDOWN) {
1304
				in_dev = __in_dev_get_rtnl(nh->nh_dev);
1305 1306 1307 1308
				if (in_dev &&
				    IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev))
					rtnh->rtnh_flags |= RTNH_F_DEAD;
			}
1309 1310 1311
			rtnh->rtnh_hops = nh->nh_weight - 1;
			rtnh->rtnh_ifindex = nh->nh_oif;

D
David S. Miller 已提交
1312
			if (nh->nh_gw &&
1313
			    nla_put_in_addr(skb, RTA_GATEWAY, nh->nh_gw))
D
David S. Miller 已提交
1314
				goto nla_put_failure;
1315
#ifdef CONFIG_IP_ROUTE_CLASSID
D
David S. Miller 已提交
1316 1317 1318
			if (nh->nh_tclassid &&
			    nla_put_u32(skb, RTA_FLOW, nh->nh_tclassid))
				goto nla_put_failure;
1319
#endif
1320 1321 1322 1323
			if (nh->nh_lwtstate &&
			    lwtunnel_fill_encap(skb, nh->nh_lwtstate) < 0)
				goto nla_put_failure;

1324 1325
			/* length of rtnetlink header + attributes */
			rtnh->rtnh_len = nlmsg_get_pos(skb) - (void *) rtnh;
L
Linus Torvalds 已提交
1326
		} endfor_nexthops(fi);
1327 1328

		nla_nest_end(skb, mp);
L
Linus Torvalds 已提交
1329 1330
	}
#endif
1331 1332
	nlmsg_end(skb, nlh);
	return 0;
L
Linus Torvalds 已提交
1333

1334
nla_put_failure:
1335 1336
	nlmsg_cancel(skb, nlh);
	return -EMSGSIZE;
L
Linus Torvalds 已提交
1337 1338 1339
}

/*
E
Eric Dumazet 已提交
1340 1341 1342 1343
 * Update FIB if:
 * - local address disappeared -> we must delete all the entries
 *   referring to it.
 * - device went down -> we must shutdown all nexthops going via it.
L
Linus Torvalds 已提交
1344
 */
1345
int fib_sync_down_addr(struct net_device *dev, __be32 local)
L
Linus Torvalds 已提交
1346 1347
{
	int ret = 0;
D
Denis V. Lunev 已提交
1348 1349
	unsigned int hash = fib_laddr_hashfn(local);
	struct hlist_head *head = &fib_info_laddrhash[hash];
1350 1351
	struct net *net = dev_net(dev);
	int tb_id = l3mdev_fib_table(dev);
D
Denis V. Lunev 已提交
1352
	struct fib_info *fi;
L
Linus Torvalds 已提交
1353

1354
	if (!fib_info_laddrhash || local == 0)
D
Denis V. Lunev 已提交
1355
		return 0;
L
Linus Torvalds 已提交
1356

1357
	hlist_for_each_entry(fi, head, fib_lhash) {
1358 1359
		if (!net_eq(fi->fib_net, net) ||
		    fi->fib_tb_id != tb_id)
1360
			continue;
D
Denis V. Lunev 已提交
1361 1362 1363
		if (fi->fib_prefsrc == local) {
			fi->fib_flags |= RTNH_F_DEAD;
			ret++;
L
Linus Torvalds 已提交
1364 1365
		}
	}
D
Denis V. Lunev 已提交
1366 1367 1368
	return ret;
}

1369 1370 1371 1372 1373 1374 1375
/* Event              force Flags           Description
 * NETDEV_CHANGE      0     LINKDOWN        Carrier OFF, not for scope host
 * NETDEV_DOWN        0     LINKDOWN|DEAD   Link down, not for scope host
 * NETDEV_DOWN        1     LINKDOWN|DEAD   Last address removed
 * NETDEV_UNREGISTER  1     LINKDOWN|DEAD   Device removed
 */
int fib_sync_down_dev(struct net_device *dev, unsigned long event, bool force)
D
Denis V. Lunev 已提交
1376 1377 1378 1379 1380 1381 1382
{
	int ret = 0;
	int scope = RT_SCOPE_NOWHERE;
	struct fib_info *prev_fi = NULL;
	unsigned int hash = fib_devindex_hashfn(dev->ifindex);
	struct hlist_head *head = &fib_info_devhash[hash];
	struct fib_nh *nh;
L
Linus Torvalds 已提交
1383

1384
	if (force)
D
Denis V. Lunev 已提交
1385
		scope = -1;
L
Linus Torvalds 已提交
1386

1387
	hlist_for_each_entry(nh, head, nh_hash) {
D
Denis V. Lunev 已提交
1388 1389
		struct fib_info *fi = nh->nh_parent;
		int dead;
L
Linus Torvalds 已提交
1390

D
Denis V. Lunev 已提交
1391 1392 1393 1394 1395 1396
		BUG_ON(!fi->fib_nhs);
		if (nh->nh_dev != dev || fi == prev_fi)
			continue;
		prev_fi = fi;
		dead = 0;
		change_nexthops(fi) {
E
Eric Dumazet 已提交
1397
			if (nexthop_nh->nh_flags & RTNH_F_DEAD)
D
Denis V. Lunev 已提交
1398
				dead++;
1399 1400
			else if (nexthop_nh->nh_dev == dev &&
				 nexthop_nh->nh_scope != scope) {
1401 1402 1403 1404 1405 1406 1407 1408 1409
				switch (event) {
				case NETDEV_DOWN:
				case NETDEV_UNREGISTER:
					nexthop_nh->nh_flags |= RTNH_F_DEAD;
					/* fall through */
				case NETDEV_CHANGE:
					nexthop_nh->nh_flags |= RTNH_F_LINKDOWN;
					break;
				}
D
Denis V. Lunev 已提交
1410 1411
				dead++;
			}
L
Linus Torvalds 已提交
1412
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1413 1414
			if (event == NETDEV_UNREGISTER &&
			    nexthop_nh->nh_dev == dev) {
D
Denis V. Lunev 已提交
1415 1416
				dead = fi->fib_nhs;
				break;
L
Linus Torvalds 已提交
1417
			}
D
Denis V. Lunev 已提交
1418 1419 1420
#endif
		} endfor_nexthops(fi)
		if (dead == fi->fib_nhs) {
1421 1422 1423 1424 1425 1426 1427 1428 1429
			switch (event) {
			case NETDEV_DOWN:
			case NETDEV_UNREGISTER:
				fi->fib_flags |= RTNH_F_DEAD;
				/* fall through */
			case NETDEV_CHANGE:
				fi->fib_flags |= RTNH_F_LINKDOWN;
				break;
			}
D
Denis V. Lunev 已提交
1430
			ret++;
L
Linus Torvalds 已提交
1431
		}
P
Peter Nørlund 已提交
1432 1433

		fib_rebalance(fi);
L
Linus Torvalds 已提交
1434 1435 1436 1437 1438
	}

	return ret;
}

1439
/* Must be invoked inside of an RCU protected region.  */
1440
static void fib_select_default(const struct flowi4 *flp, struct fib_result *res)
1441 1442
{
	struct fib_info *fi = NULL, *last_resort = NULL;
1443
	struct hlist_head *fa_head = res->fa_head;
1444
	struct fib_table *tb = res->table;
1445
	u8 slen = 32 - res->prefixlen;
1446
	int order = -1, last_idx = -1;
1447 1448 1449
	struct fib_alias *fa, *fa1 = NULL;
	u32 last_prio = res->fi->fib_priority;
	u8 last_tos = 0;
1450

1451
	hlist_for_each_entry_rcu(fa, fa_head, fa_list) {
1452 1453
		struct fib_info *next_fi = fa->fa_info;

1454 1455
		if (fa->fa_slen != slen)
			continue;
1456 1457
		if (fa->fa_tos && fa->fa_tos != flp->flowi4_tos)
			continue;
1458 1459
		if (fa->tb_id != tb->tb_id)
			continue;
1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470
		if (next_fi->fib_priority > last_prio &&
		    fa->fa_tos == last_tos) {
			if (last_tos)
				continue;
			break;
		}
		if (next_fi->fib_flags & RTNH_F_DEAD)
			continue;
		last_tos = fa->fa_tos;
		last_prio = next_fi->fib_priority;

1471
		if (next_fi->fib_scope != res->scope ||
1472 1473 1474 1475 1476 1477 1478 1479
		    fa->fa_type != RTN_UNICAST)
			continue;
		if (!next_fi->fib_nh[0].nh_gw ||
		    next_fi->fib_nh[0].nh_scope != RT_SCOPE_LINK)
			continue;

		fib_alias_accessed(fa);

1480
		if (!fi) {
1481 1482
			if (next_fi != res->fi)
				break;
1483
			fa1 = fa;
1484
		} else if (!fib_detect_death(fi, order, &last_resort,
1485
					     &last_idx, fa1->fa_default)) {
1486
			fib_result_assign(res, fi);
1487
			fa1->fa_default = order;
1488 1489 1490 1491 1492 1493
			goto out;
		}
		fi = next_fi;
		order++;
	}

1494
	if (order <= 0 || !fi) {
1495 1496
		if (fa1)
			fa1->fa_default = -1;
1497 1498 1499 1500
		goto out;
	}

	if (!fib_detect_death(fi, order, &last_resort, &last_idx,
1501
			      fa1->fa_default)) {
1502
		fib_result_assign(res, fi);
1503
		fa1->fa_default = order;
1504 1505 1506 1507 1508
		goto out;
	}

	if (last_idx >= 0)
		fib_result_assign(res, last_resort);
1509
	fa1->fa_default = last_idx;
1510
out:
1511
	return;
1512 1513
}

L
Linus Torvalds 已提交
1514
/*
E
Eric Dumazet 已提交
1515 1516
 * Dead device goes up. We wake up dead nexthops.
 * It takes sense only on multipath routes.
L
Linus Torvalds 已提交
1517
 */
1518
int fib_sync_up(struct net_device *dev, unsigned int nh_flags)
L
Linus Torvalds 已提交
1519 1520 1521 1522 1523 1524 1525
{
	struct fib_info *prev_fi;
	unsigned int hash;
	struct hlist_head *head;
	struct fib_nh *nh;
	int ret;

E
Eric Dumazet 已提交
1526
	if (!(dev->flags & IFF_UP))
L
Linus Torvalds 已提交
1527 1528
		return 0;

1529 1530 1531 1532 1533 1534 1535
	if (nh_flags & RTNH_F_DEAD) {
		unsigned int flags = dev_get_flags(dev);

		if (flags & (IFF_RUNNING | IFF_LOWER_UP))
			nh_flags |= RTNH_F_LINKDOWN;
	}

L
Linus Torvalds 已提交
1536 1537 1538 1539 1540
	prev_fi = NULL;
	hash = fib_devindex_hashfn(dev->ifindex);
	head = &fib_info_devhash[hash];
	ret = 0;

1541
	hlist_for_each_entry(nh, head, nh_hash) {
L
Linus Torvalds 已提交
1542 1543 1544 1545 1546 1547 1548 1549 1550 1551
		struct fib_info *fi = nh->nh_parent;
		int alive;

		BUG_ON(!fi->fib_nhs);
		if (nh->nh_dev != dev || fi == prev_fi)
			continue;

		prev_fi = fi;
		alive = 0;
		change_nexthops(fi) {
1552
			if (!(nexthop_nh->nh_flags & nh_flags)) {
L
Linus Torvalds 已提交
1553 1554 1555
				alive++;
				continue;
			}
1556
			if (!nexthop_nh->nh_dev ||
E
Eric Dumazet 已提交
1557
			    !(nexthop_nh->nh_dev->flags & IFF_UP))
L
Linus Torvalds 已提交
1558
				continue;
1559 1560
			if (nexthop_nh->nh_dev != dev ||
			    !__in_dev_get_rtnl(dev))
L
Linus Torvalds 已提交
1561 1562
				continue;
			alive++;
1563
			nexthop_nh->nh_flags &= ~nh_flags;
L
Linus Torvalds 已提交
1564 1565 1566
		} endfor_nexthops(fi)

		if (alive > 0) {
1567
			fi->fib_flags &= ~nh_flags;
L
Linus Torvalds 已提交
1568 1569
			ret++;
		}
P
Peter Nørlund 已提交
1570 1571

		fib_rebalance(fi);
L
Linus Torvalds 已提交
1572 1573 1574 1575 1576
	}

	return ret;
}

1577
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1578 1579 1580 1581 1582 1583 1584 1585 1586
static bool fib_good_nh(const struct fib_nh *nh)
{
	int state = NUD_REACHABLE;

	if (nh->nh_scope == RT_SCOPE_LINK) {
		struct neighbour *n;

		rcu_read_lock_bh();

1587 1588
		n = __ipv4_neigh_lookup_noref(nh->nh_dev,
					      (__force u32)nh->nh_gw);
1589 1590 1591 1592 1593 1594 1595 1596
		if (n)
			state = n->nud_state;

		rcu_read_unlock_bh();
	}

	return !!(state & NUD_VALID);
}
1597

P
Peter Nørlund 已提交
1598
void fib_select_multipath(struct fib_result *res, int hash)
L
Linus Torvalds 已提交
1599 1600
{
	struct fib_info *fi = res->fi;
1601 1602
	struct net *net = fi->fib_net;
	bool first = false;
L
Linus Torvalds 已提交
1603

P
Peter Nørlund 已提交
1604 1605 1606
	for_nexthops(fi) {
		if (hash > atomic_read(&nh->nh_upper_bound))
			continue;
L
Linus Torvalds 已提交
1607

1608 1609 1610 1611 1612 1613 1614 1615 1616
		if (!net->ipv4.sysctl_fib_multipath_use_neigh ||
		    fib_good_nh(nh)) {
			res->nh_sel = nhsel;
			return;
		}
		if (!first) {
			res->nh_sel = nhsel;
			first = true;
		}
L
Linus Torvalds 已提交
1617 1618 1619
	} endfor_nexthops(fi);
}
#endif
1620 1621 1622 1623

void fib_select_path(struct net *net, struct fib_result *res,
		     struct flowi4 *fl4, int mp_hash)
{
1624 1625 1626 1627 1628
	bool oif_check;

	oif_check = (fl4->flowi4_oif == 0 ||
		     fl4->flowi4_flags & FLOWI_FLAG_SKIP_NH_OIF);

1629
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1630
	if (res->fi->fib_nhs > 1 && oif_check) {
1631
		if (mp_hash < 0)
1632 1633
			mp_hash = get_hash_from_flowi4(fl4) >> 1;

1634 1635 1636 1637 1638 1639
		fib_select_multipath(res, mp_hash);
	}
	else
#endif
	if (!res->prefixlen &&
	    res->table->tb_num_default > 1 &&
1640
	    res->type == RTN_UNICAST && oif_check)
1641 1642 1643 1644 1645 1646
		fib_select_default(fl4, res);

	if (!fl4->saddr)
		fl4->saddr = FIB_RES_PREFSRC(net, *res);
}
EXPORT_SYMBOL_GPL(fib_select_path);