fib_semantics.c 38.2 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
/*
 * INET		An implementation of the TCP/IP protocol suite for the LINUX
 *		operating system.  INET is implemented using the  BSD Socket
 *		interface as the means of communication with the user level.
 *
 *		IPv4 Forwarding Information Base: semantics.
 *
 * Authors:	Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 */

16
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
17 18 19 20 21 22 23 24 25 26 27
#include <linux/bitops.h>
#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/jiffies.h>
#include <linux/mm.h>
#include <linux/string.h>
#include <linux/socket.h>
#include <linux/sockios.h>
#include <linux/errno.h>
#include <linux/in.h>
#include <linux/inet.h>
28
#include <linux/inetdevice.h>
L
Linus Torvalds 已提交
29 30 31 32 33
#include <linux/netdevice.h>
#include <linux/if_arp.h>
#include <linux/proc_fs.h>
#include <linux/skbuff.h>
#include <linux/init.h>
34
#include <linux/slab.h>
L
Linus Torvalds 已提交
35

36
#include <net/arp.h>
L
Linus Torvalds 已提交
37 38 39 40 41 42
#include <net/ip.h>
#include <net/protocol.h>
#include <net/route.h>
#include <net/tcp.h>
#include <net/sock.h>
#include <net/ip_fib.h>
43
#include <net/netlink.h>
44
#include <net/nexthop.h>
45
#include <net/lwtunnel.h>
L
Linus Torvalds 已提交
46 47 48

#include "fib_lookup.h"

49
static DEFINE_SPINLOCK(fib_info_lock);
L
Linus Torvalds 已提交
50 51
static struct hlist_head *fib_info_hash;
static struct hlist_head *fib_info_laddrhash;
52
static unsigned int fib_info_hash_size;
L
Linus Torvalds 已提交
53 54 55 56 57 58 59
static unsigned int fib_info_cnt;

#define DEVINDEX_HASHBITS 8
#define DEVINDEX_HASHSIZE (1U << DEVINDEX_HASHBITS)
static struct hlist_head fib_info_devhash[DEVINDEX_HASHSIZE];

#ifdef CONFIG_IP_ROUTE_MULTIPATH
P
Peter Nørlund 已提交
60
u32 fib_multipath_secret __read_mostly;
L
Linus Torvalds 已提交
61

E
Eric Dumazet 已提交
62 63 64 65 66 67 68 69 70 71 72
#define for_nexthops(fi) {						\
	int nhsel; const struct fib_nh *nh;				\
	for (nhsel = 0, nh = (fi)->fib_nh;				\
	     nhsel < (fi)->fib_nhs;					\
	     nh++, nhsel++)

#define change_nexthops(fi) {						\
	int nhsel; struct fib_nh *nexthop_nh;				\
	for (nhsel = 0,	nexthop_nh = (struct fib_nh *)((fi)->fib_nh);	\
	     nhsel < (fi)->fib_nhs;					\
	     nexthop_nh++, nhsel++)
L
Linus Torvalds 已提交
73 74 75 76 77

#else /* CONFIG_IP_ROUTE_MULTIPATH */

/* Hope, that gcc will optimize it to get rid of dummy loop */

E
Eric Dumazet 已提交
78 79 80
#define for_nexthops(fi) {						\
	int nhsel; const struct fib_nh *nh = (fi)->fib_nh;		\
	for (nhsel = 0; nhsel < 1; nhsel++)
L
Linus Torvalds 已提交
81

E
Eric Dumazet 已提交
82 83 84 85
#define change_nexthops(fi) {						\
	int nhsel;							\
	struct fib_nh *nexthop_nh = (struct fib_nh *)((fi)->fib_nh);	\
	for (nhsel = 0; nhsel < 1; nhsel++)
L
Linus Torvalds 已提交
86 87 88 89 90 91

#endif /* CONFIG_IP_ROUTE_MULTIPATH */

#define endfor_nexthops(fi) }


92
const struct fib_prop fib_props[RTN_MAX + 1] = {
E
Eric Dumazet 已提交
93
	[RTN_UNSPEC] = {
L
Linus Torvalds 已提交
94 95
		.error	= 0,
		.scope	= RT_SCOPE_NOWHERE,
E
Eric Dumazet 已提交
96 97
	},
	[RTN_UNICAST] = {
L
Linus Torvalds 已提交
98 99
		.error	= 0,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
100 101
	},
	[RTN_LOCAL] = {
L
Linus Torvalds 已提交
102 103
		.error	= 0,
		.scope	= RT_SCOPE_HOST,
E
Eric Dumazet 已提交
104 105
	},
	[RTN_BROADCAST] = {
L
Linus Torvalds 已提交
106 107
		.error	= 0,
		.scope	= RT_SCOPE_LINK,
E
Eric Dumazet 已提交
108 109
	},
	[RTN_ANYCAST] = {
L
Linus Torvalds 已提交
110 111
		.error	= 0,
		.scope	= RT_SCOPE_LINK,
E
Eric Dumazet 已提交
112 113
	},
	[RTN_MULTICAST] = {
L
Linus Torvalds 已提交
114 115
		.error	= 0,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
116 117
	},
	[RTN_BLACKHOLE] = {
L
Linus Torvalds 已提交
118 119
		.error	= -EINVAL,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
120 121
	},
	[RTN_UNREACHABLE] = {
L
Linus Torvalds 已提交
122 123
		.error	= -EHOSTUNREACH,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
124 125
	},
	[RTN_PROHIBIT] = {
L
Linus Torvalds 已提交
126 127
		.error	= -EACCES,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
128 129
	},
	[RTN_THROW] = {
L
Linus Torvalds 已提交
130 131
		.error	= -EAGAIN,
		.scope	= RT_SCOPE_UNIVERSE,
E
Eric Dumazet 已提交
132 133
	},
	[RTN_NAT] = {
L
Linus Torvalds 已提交
134 135
		.error	= -EINVAL,
		.scope	= RT_SCOPE_NOWHERE,
E
Eric Dumazet 已提交
136 137
	},
	[RTN_XRESOLVE] = {
L
Linus Torvalds 已提交
138 139
		.error	= -EINVAL,
		.scope	= RT_SCOPE_NOWHERE,
E
Eric Dumazet 已提交
140
	},
L
Linus Torvalds 已提交
141 142
};

143 144 145 146 147 148 149 150 151 152 153 154 155 156 157
static void rt_fibinfo_free(struct rtable __rcu **rtp)
{
	struct rtable *rt = rcu_dereference_protected(*rtp, 1);

	if (!rt)
		return;

	/* Not even needed : RCU_INIT_POINTER(*rtp, NULL);
	 * because we waited an RCU grace period before calling
	 * free_fib_info_rcu()
	 */

	dst_free(&rt->dst);
}

158 159
static void free_nh_exceptions(struct fib_nh *nh)
{
160
	struct fnhe_hash_bucket *hash;
161 162
	int i;

163 164 165
	hash = rcu_dereference_protected(nh->nh_exceptions, 1);
	if (!hash)
		return;
166 167 168
	for (i = 0; i < FNHE_HASH_SIZE; i++) {
		struct fib_nh_exception *fnhe;

E
Eric Dumazet 已提交
169
		fnhe = rcu_dereference_protected(hash[i].chain, 1);
170 171 172
		while (fnhe) {
			struct fib_nh_exception *next;
			
E
Eric Dumazet 已提交
173
			next = rcu_dereference_protected(fnhe->fnhe_next, 1);
174

175 176
			rt_fibinfo_free(&fnhe->fnhe_rth_input);
			rt_fibinfo_free(&fnhe->fnhe_rth_output);
177

178 179 180 181 182 183 184 185
			kfree(fnhe);

			fnhe = next;
		}
	}
	kfree(hash);
}

186
static void rt_fibinfo_free_cpus(struct rtable __rcu * __percpu *rtp)
E
Eric Dumazet 已提交
187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202
{
	int cpu;

	if (!rtp)
		return;

	for_each_possible_cpu(cpu) {
		struct rtable *rt;

		rt = rcu_dereference_protected(*per_cpu_ptr(rtp, cpu), 1);
		if (rt)
			dst_free(&rt->dst);
	}
	free_percpu(rtp);
}

L
Linus Torvalds 已提交
203
/* Release a nexthop info record */
204 205 206 207
static void free_fib_info_rcu(struct rcu_head *head)
{
	struct fib_info *fi = container_of(head, struct fib_info, rcu);

208 209 210
	change_nexthops(fi) {
		if (nexthop_nh->nh_dev)
			dev_put(nexthop_nh->nh_dev);
211
		lwtstate_put(nexthop_nh->nh_lwtstate);
212
		free_nh_exceptions(nexthop_nh);
213 214
		rt_fibinfo_free_cpus(nexthop_nh->nh_pcpu_rth_output);
		rt_fibinfo_free(&nexthop_nh->nh_rth_input);
215 216
	} endfor_nexthops(fi);

217 218 219 220
	if (fi->fib_metrics != (u32 *) dst_default_metrics)
		kfree(fi->fib_metrics);
	kfree(fi);
}
L
Linus Torvalds 已提交
221 222 223 224

void free_fib_info(struct fib_info *fi)
{
	if (fi->fib_dead == 0) {
J
Joe Perches 已提交
225
		pr_warn("Freeing alive fib_info %p\n", fi);
L
Linus Torvalds 已提交
226 227 228
		return;
	}
	fib_info_cnt--;
229 230 231
#ifdef CONFIG_IP_ROUTE_CLASSID
	change_nexthops(fi) {
		if (nexthop_nh->nh_tclassid)
232
			fi->fib_net->ipv4.fib_num_tclassid_users--;
233 234
	} endfor_nexthops(fi);
#endif
235
	call_rcu(&fi->rcu, free_fib_info_rcu);
L
Linus Torvalds 已提交
236
}
I
Ido Schimmel 已提交
237
EXPORT_SYMBOL_GPL(free_fib_info);
L
Linus Torvalds 已提交
238 239 240

void fib_release_info(struct fib_info *fi)
{
241
	spin_lock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
242 243 244 245 246
	if (fi && --fi->fib_treeref == 0) {
		hlist_del(&fi->fib_hash);
		if (fi->fib_prefsrc)
			hlist_del(&fi->fib_lhash);
		change_nexthops(fi) {
247
			if (!nexthop_nh->nh_dev)
L
Linus Torvalds 已提交
248
				continue;
249
			hlist_del(&nexthop_nh->nh_hash);
L
Linus Torvalds 已提交
250 251 252 253
		} endfor_nexthops(fi)
		fi->fib_dead = 1;
		fib_info_put(fi);
	}
254
	spin_unlock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
255 256
}

E
Eric Dumazet 已提交
257
static inline int nh_comp(const struct fib_info *fi, const struct fib_info *ofi)
L
Linus Torvalds 已提交
258 259 260 261 262 263 264 265 266 267
{
	const struct fib_nh *onh = ofi->fib_nh;

	for_nexthops(fi) {
		if (nh->nh_oif != onh->nh_oif ||
		    nh->nh_gw  != onh->nh_gw ||
		    nh->nh_scope != onh->nh_scope ||
#ifdef CONFIG_IP_ROUTE_MULTIPATH
		    nh->nh_weight != onh->nh_weight ||
#endif
268
#ifdef CONFIG_IP_ROUTE_CLASSID
L
Linus Torvalds 已提交
269 270
		    nh->nh_tclassid != onh->nh_tclassid ||
#endif
271
		    lwtunnel_cmp_encap(nh->nh_lwtstate, onh->nh_lwtstate) ||
272
		    ((nh->nh_flags ^ onh->nh_flags) & ~RTNH_COMPARE_MASK))
L
Linus Torvalds 已提交
273 274 275 276 277 278
			return -1;
		onh++;
	} endfor_nexthops(fi);
	return 0;
}

279 280 281 282 283 284 285 286 287
static inline unsigned int fib_devindex_hashfn(unsigned int val)
{
	unsigned int mask = DEVINDEX_HASHSIZE - 1;

	return (val ^
		(val >> DEVINDEX_HASHBITS) ^
		(val >> (DEVINDEX_HASHBITS * 2))) & mask;
}

L
Linus Torvalds 已提交
288 289
static inline unsigned int fib_info_hashfn(const struct fib_info *fi)
{
290
	unsigned int mask = (fib_info_hash_size - 1);
L
Linus Torvalds 已提交
291 292
	unsigned int val = fi->fib_nhs;

293
	val ^= (fi->fib_protocol << 8) | fi->fib_scope;
A
Al Viro 已提交
294
	val ^= (__force u32)fi->fib_prefsrc;
L
Linus Torvalds 已提交
295
	val ^= fi->fib_priority;
296 297 298
	for_nexthops(fi) {
		val ^= fib_devindex_hashfn(nh->nh_oif);
	} endfor_nexthops(fi)
L
Linus Torvalds 已提交
299 300 301 302 303 304 305 306 307 308 309 310 311

	return (val ^ (val >> 7) ^ (val >> 12)) & mask;
}

static struct fib_info *fib_find_info(const struct fib_info *nfi)
{
	struct hlist_head *head;
	struct fib_info *fi;
	unsigned int hash;

	hash = fib_info_hashfn(nfi);
	head = &fib_info_hash[hash];

312
	hlist_for_each_entry(fi, head, fib_hash) {
O
Octavian Purdila 已提交
313
		if (!net_eq(fi->fib_net, nfi->fib_net))
314
			continue;
L
Linus Torvalds 已提交
315 316 317
		if (fi->fib_nhs != nfi->fib_nhs)
			continue;
		if (nfi->fib_protocol == fi->fib_protocol &&
318
		    nfi->fib_scope == fi->fib_scope &&
L
Linus Torvalds 已提交
319 320
		    nfi->fib_prefsrc == fi->fib_prefsrc &&
		    nfi->fib_priority == fi->fib_priority &&
E
Eric Dumazet 已提交
321
		    nfi->fib_type == fi->fib_type &&
L
Linus Torvalds 已提交
322
		    memcmp(nfi->fib_metrics, fi->fib_metrics,
E
Eric Dumazet 已提交
323
			   sizeof(u32) * RTAX_MAX) == 0 &&
324
		    !((nfi->fib_flags ^ fi->fib_flags) & ~RTNH_COMPARE_MASK) &&
L
Linus Torvalds 已提交
325 326 327 328 329 330 331 332
		    (nfi->fib_nhs == 0 || nh_comp(fi, nfi) == 0))
			return fi;
	}

	return NULL;
}

/* Check, that the gateway is already configured.
E
Eric Dumazet 已提交
333
 * Used only by redirect accept routine.
L
Linus Torvalds 已提交
334
 */
335
int ip_fib_check_default(__be32 gw, struct net_device *dev)
L
Linus Torvalds 已提交
336 337 338 339 340
{
	struct hlist_head *head;
	struct fib_nh *nh;
	unsigned int hash;

341
	spin_lock(&fib_info_lock);
L
Linus Torvalds 已提交
342 343 344

	hash = fib_devindex_hashfn(dev->ifindex);
	head = &fib_info_devhash[hash];
345
	hlist_for_each_entry(nh, head, nh_hash) {
L
Linus Torvalds 已提交
346 347
		if (nh->nh_dev == dev &&
		    nh->nh_gw == gw &&
E
Eric Dumazet 已提交
348
		    !(nh->nh_flags & RTNH_F_DEAD)) {
349
			spin_unlock(&fib_info_lock);
L
Linus Torvalds 已提交
350 351 352 353
			return 0;
		}
	}

354
	spin_unlock(&fib_info_lock);
L
Linus Torvalds 已提交
355 356 357 358

	return -1;
}

359 360 361 362 363 364
static inline size_t fib_nlmsg_size(struct fib_info *fi)
{
	size_t payload = NLMSG_ALIGN(sizeof(struct rtmsg))
			 + nla_total_size(4) /* RTA_TABLE */
			 + nla_total_size(4) /* RTA_DST */
			 + nla_total_size(4) /* RTA_PRIORITY */
365 366
			 + nla_total_size(4) /* RTA_PREFSRC */
			 + nla_total_size(TCP_CA_NAME_MAX); /* RTAX_CC_ALGO */
367 368 369 370 371

	/* space for nested metrics */
	payload += nla_total_size((RTAX_MAX * nla_total_size(4)));

	if (fi->fib_nhs) {
372
		size_t nh_encapsize = 0;
373 374 375 376 377 378 379 380
		/* Also handles the special case fib_nhs == 1 */

		/* each nexthop is packed in an attribute */
		size_t nhsize = nla_total_size(sizeof(struct rtnexthop));

		/* may contain flow and gateway attribute */
		nhsize += 2 * nla_total_size(4);

381 382 383 384 385 386 387 388 389 390 391
		/* grab encap info */
		for_nexthops(fi) {
			if (nh->nh_lwtstate) {
				/* RTA_ENCAP_TYPE */
				nh_encapsize += lwtunnel_get_encap_size(
						nh->nh_lwtstate);
				/* RTA_ENCAP */
				nh_encapsize +=  nla_total_size(2);
			}
		} endfor_nexthops(fi);

392
		/* all nexthops are packed in a nested attribute */
393 394 395
		payload += nla_total_size((fi->fib_nhs * nhsize) +
					  nh_encapsize);

396 397 398 399 400
	}

	return payload;
}

A
Al Viro 已提交
401
void rtmsg_fib(int event, __be32 key, struct fib_alias *fa,
402
	       int dst_len, u32 tb_id, const struct nl_info *info,
403
	       unsigned int nlm_flags)
L
Linus Torvalds 已提交
404 405
{
	struct sk_buff *skb;
406
	u32 seq = info->nlh ? info->nlh->nlmsg_seq : 0;
407
	int err = -ENOBUFS;
L
Linus Torvalds 已提交
408

409
	skb = nlmsg_new(fib_nlmsg_size(fa->fa_info), GFP_KERNEL);
410
	if (!skb)
411
		goto errout;
L
Linus Torvalds 已提交
412

413
	err = fib_dump_info(skb, info->portid, seq, event, tb_id,
414
			    fa->fa_type, key, dst_len,
415
			    fa->fa_tos, fa->fa_info, nlm_flags);
416 417 418 419 420 421
	if (err < 0) {
		/* -EMSGSIZE implies BUG in fib_nlmsg_size() */
		WARN_ON(err == -EMSGSIZE);
		kfree_skb(skb);
		goto errout;
	}
422
	rtnl_notify(skb, info->nl_net, info->portid, RTNLGRP_IPV4_ROUTE,
423 424
		    info->nlh, GFP_KERNEL);
	return;
425 426
errout:
	if (err < 0)
427
		rtnl_set_sk_err(info->nl_net, RTNLGRP_IPV4_ROUTE, err);
L
Linus Torvalds 已提交
428 429
}

430 431 432
static int fib_detect_death(struct fib_info *fi, int order,
			    struct fib_info **last_resort, int *last_idx,
			    int dflt)
L
Linus Torvalds 已提交
433 434 435 436 437 438 439 440
{
	struct neighbour *n;
	int state = NUD_NONE;

	n = neigh_lookup(&arp_tbl, &fi->fib_nh[0].nh_gw, fi->fib_dev);
	if (n) {
		state = n->nud_state;
		neigh_release(n);
441 442
	} else {
		return 0;
L
Linus Torvalds 已提交
443
	}
444
	if (state == NUD_REACHABLE)
L
Linus Torvalds 已提交
445
		return 0;
E
Eric Dumazet 已提交
446
	if ((state & NUD_VALID) && order != dflt)
L
Linus Torvalds 已提交
447
		return 0;
E
Eric Dumazet 已提交
448
	if ((state & NUD_VALID) ||
449
	    (*last_idx < 0 && order > dflt && state != NUD_INCOMPLETE)) {
L
Linus Torvalds 已提交
450 451 452 453 454 455 456 457
		*last_resort = fi;
		*last_idx = order;
	}
	return 1;
}

#ifdef CONFIG_IP_ROUTE_MULTIPATH

458
static int fib_count_nexthops(struct rtnexthop *rtnh, int remaining)
L
Linus Torvalds 已提交
459 460 461
{
	int nhs = 0;

462
	while (rtnh_ok(rtnh, remaining)) {
L
Linus Torvalds 已提交
463
		nhs++;
464 465 466 467 468
		rtnh = rtnh_next(rtnh, &remaining);
	}

	/* leftover implies invalid nexthop configuration, discard it */
	return remaining > 0 ? 0 : nhs;
L
Linus Torvalds 已提交
469 470
}

471 472
static int fib_get_nhs(struct fib_info *fi, struct rtnexthop *rtnh,
		       int remaining, struct fib_config *cfg)
L
Linus Torvalds 已提交
473
{
474 475 476
	struct net *net = cfg->fc_nlinfo.nl_net;
	int ret;

L
Linus Torvalds 已提交
477
	change_nexthops(fi) {
478 479 480
		int attrlen;

		if (!rtnh_ok(rtnh, remaining))
L
Linus Torvalds 已提交
481
			return -EINVAL;
482

483 484 485
		if (rtnh->rtnh_flags & (RTNH_F_DEAD | RTNH_F_LINKDOWN))
			return -EINVAL;

486 487 488 489
		nexthop_nh->nh_flags =
			(cfg->fc_flags & ~0xFF) | rtnh->rtnh_flags;
		nexthop_nh->nh_oif = rtnh->rtnh_ifindex;
		nexthop_nh->nh_weight = rtnh->rtnh_hops + 1;
490 491 492 493 494 495

		attrlen = rtnh_attrlen(rtnh);
		if (attrlen > 0) {
			struct nlattr *nla, *attrs = rtnh_attrs(rtnh);

			nla = nla_find(attrs, attrlen, RTA_GATEWAY);
496
			nexthop_nh->nh_gw = nla ? nla_get_in_addr(nla) : 0;
497
#ifdef CONFIG_IP_ROUTE_CLASSID
498
			nla = nla_find(attrs, attrlen, RTA_FLOW);
499
			nexthop_nh->nh_tclassid = nla ? nla_get_u32(nla) : 0;
500
			if (nexthop_nh->nh_tclassid)
501
				fi->fib_net->ipv4.fib_num_tclassid_users++;
L
Linus Torvalds 已提交
502
#endif
503 504 505 506 507 508 509 510 511 512 513 514 515 516
			nla = nla_find(attrs, attrlen, RTA_ENCAP);
			if (nla) {
				struct lwtunnel_state *lwtstate;
				struct net_device *dev = NULL;
				struct nlattr *nla_entype;

				nla_entype = nla_find(attrs, attrlen,
						      RTA_ENCAP_TYPE);
				if (!nla_entype)
					goto err_inval;
				if (cfg->fc_oif)
					dev = __dev_get_by_index(net, cfg->fc_oif);
				ret = lwtunnel_build_state(dev, nla_get_u16(
							   nla_entype),
517 518
							   nla,  AF_INET, cfg,
							   &lwtstate);
519 520
				if (ret)
					goto errout;
521 522
				nexthop_nh->nh_lwtstate =
					lwtstate_get(lwtstate);
523
			}
L
Linus Torvalds 已提交
524
		}
525 526

		rtnh = rtnh_next(rtnh, &remaining);
L
Linus Torvalds 已提交
527
	} endfor_nexthops(fi);
528

L
Linus Torvalds 已提交
529
	return 0;
530 531 532 533 534 535

err_inval:
	ret = -EINVAL;

errout:
	return ret;
L
Linus Torvalds 已提交
536 537
}

P
Peter Nørlund 已提交
538 539 540 541 542 543 544 545 546 547 548 549 550 551
static void fib_rebalance(struct fib_info *fi)
{
	int total;
	int w;
	struct in_device *in_dev;

	if (fi->fib_nhs < 2)
		return;

	total = 0;
	for_nexthops(fi) {
		if (nh->nh_flags & RTNH_F_DEAD)
			continue;

552
		in_dev = __in_dev_get_rtnl(nh->nh_dev);
P
Peter Nørlund 已提交
553 554 555 556 557 558 559 560 561 562 563 564 565

		if (in_dev &&
		    IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev) &&
		    nh->nh_flags & RTNH_F_LINKDOWN)
			continue;

		total += nh->nh_weight;
	} endfor_nexthops(fi);

	w = 0;
	change_nexthops(fi) {
		int upper_bound;

566
		in_dev = __in_dev_get_rtnl(nexthop_nh->nh_dev);
P
Peter Nørlund 已提交
567 568 569 570 571 572 573 574 575

		if (nexthop_nh->nh_flags & RTNH_F_DEAD) {
			upper_bound = -1;
		} else if (in_dev &&
			   IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev) &&
			   nexthop_nh->nh_flags & RTNH_F_LINKDOWN) {
			upper_bound = -1;
		} else {
			w += nexthop_nh->nh_weight;
576 577
			upper_bound = DIV_ROUND_CLOSEST_ULL((u64)w << 31,
							    total) - 1;
P
Peter Nørlund 已提交
578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598
		}

		atomic_set(&nexthop_nh->nh_upper_bound, upper_bound);
	} endfor_nexthops(fi);

	net_get_random_once(&fib_multipath_secret,
			    sizeof(fib_multipath_secret));
}

static inline void fib_add_weight(struct fib_info *fi,
				  const struct fib_nh *nh)
{
	fi->fib_weight += nh->nh_weight;
}

#else /* CONFIG_IP_ROUTE_MULTIPATH */

#define fib_rebalance(fi) do { } while (0)
#define fib_add_weight(fi, nh) do { } while (0)

#endif /* CONFIG_IP_ROUTE_MULTIPATH */
L
Linus Torvalds 已提交
599

Y
Ying Xue 已提交
600 601
static int fib_encap_match(struct net *net, u16 encap_type,
			   struct nlattr *encap,
602 603
			   int oif, const struct fib_nh *nh,
			   const struct fib_config *cfg)
604 605 606
{
	struct lwtunnel_state *lwtstate;
	struct net_device *dev = NULL;
J
Jiri Benc 已提交
607
	int ret, result = 0;
608 609 610 611 612 613

	if (encap_type == LWTUNNEL_ENCAP_NONE)
		return 0;

	if (oif)
		dev = __dev_get_by_index(net, oif);
614 615
	ret = lwtunnel_build_state(dev, encap_type, encap,
				   AF_INET, cfg, &lwtstate);
J
Jiri Benc 已提交
616 617 618 619
	if (!ret) {
		result = lwtunnel_cmp_encap(lwtstate, nh->nh_lwtstate);
		lwtstate_free(lwtstate);
	}
620

J
Jiri Benc 已提交
621
	return result;
622 623
}

624
int fib_nh_match(struct fib_config *cfg, struct fib_info *fi)
L
Linus Torvalds 已提交
625
{
626
	struct net *net = cfg->fc_nlinfo.nl_net;
L
Linus Torvalds 已提交
627
#ifdef CONFIG_IP_ROUTE_MULTIPATH
628 629
	struct rtnexthop *rtnh;
	int remaining;
L
Linus Torvalds 已提交
630 631
#endif

632
	if (cfg->fc_priority && cfg->fc_priority != fi->fib_priority)
L
Linus Torvalds 已提交
633 634
		return 1;

635
	if (cfg->fc_oif || cfg->fc_gw) {
636 637 638
		if (cfg->fc_encap) {
			if (fib_encap_match(net, cfg->fc_encap_type,
					    cfg->fc_encap, cfg->fc_oif,
639
					    fi->fib_nh, cfg))
640 641
			    return 1;
		}
642 643
		if ((!cfg->fc_oif || cfg->fc_oif == fi->fib_nh->nh_oif) &&
		    (!cfg->fc_gw  || cfg->fc_gw == fi->fib_nh->nh_gw))
L
Linus Torvalds 已提交
644 645 646 647 648
			return 0;
		return 1;
	}

#ifdef CONFIG_IP_ROUTE_MULTIPATH
649
	if (!cfg->fc_mp)
L
Linus Torvalds 已提交
650
		return 0;
651 652 653

	rtnh = cfg->fc_mp;
	remaining = cfg->fc_mp_len;
654

L
Linus Torvalds 已提交
655
	for_nexthops(fi) {
656
		int attrlen;
L
Linus Torvalds 已提交
657

658
		if (!rtnh_ok(rtnh, remaining))
L
Linus Torvalds 已提交
659
			return -EINVAL;
660 661

		if (rtnh->rtnh_ifindex && rtnh->rtnh_ifindex != nh->nh_oif)
L
Linus Torvalds 已提交
662
			return 1;
663 664

		attrlen = rtnh_attrlen(rtnh);
665
		if (attrlen > 0) {
666 667 668
			struct nlattr *nla, *attrs = rtnh_attrs(rtnh);

			nla = nla_find(attrs, attrlen, RTA_GATEWAY);
669
			if (nla && nla_get_in_addr(nla) != nh->nh_gw)
L
Linus Torvalds 已提交
670
				return 1;
671
#ifdef CONFIG_IP_ROUTE_CLASSID
672 673
			nla = nla_find(attrs, attrlen, RTA_FLOW);
			if (nla && nla_get_u32(nla) != nh->nh_tclassid)
L
Linus Torvalds 已提交
674 675 676
				return 1;
#endif
		}
677 678

		rtnh = rtnh_next(rtnh, &remaining);
L
Linus Torvalds 已提交
679 680 681 682 683 684 685
	} endfor_nexthops(fi);
#endif
	return 0;
}


/*
E
Eric Dumazet 已提交
686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726
 * Picture
 * -------
 *
 * Semantics of nexthop is very messy by historical reasons.
 * We have to take into account, that:
 * a) gateway can be actually local interface address,
 *    so that gatewayed route is direct.
 * b) gateway must be on-link address, possibly
 *    described not by an ifaddr, but also by a direct route.
 * c) If both gateway and interface are specified, they should not
 *    contradict.
 * d) If we use tunnel routes, gateway could be not on-link.
 *
 * Attempt to reconcile all of these (alas, self-contradictory) conditions
 * results in pretty ugly and hairy code with obscure logic.
 *
 * I chose to generalized it instead, so that the size
 * of code does not increase practically, but it becomes
 * much more general.
 * Every prefix is assigned a "scope" value: "host" is local address,
 * "link" is direct route,
 * [ ... "site" ... "interior" ... ]
 * and "universe" is true gateway route with global meaning.
 *
 * Every prefix refers to a set of "nexthop"s (gw, oif),
 * where gw must have narrower scope. This recursion stops
 * when gw has LOCAL scope or if "nexthop" is declared ONLINK,
 * which means that gw is forced to be on link.
 *
 * Code is still hairy, but now it is apparently logically
 * consistent and very flexible. F.e. as by-product it allows
 * to co-exists in peace independent exterior and interior
 * routing processes.
 *
 * Normally it looks as following.
 *
 * {universe prefix}  -> (gw, oif) [scope link]
 *		  |
 *		  |-> {link prefix} -> (gw, oif) [scope local]
 *					|
 *					|-> {local prefix} (terminal node)
L
Linus Torvalds 已提交
727
 */
728 729
static int fib_check_nh(struct fib_config *cfg, struct fib_info *fi,
			struct fib_nh *nh)
L
Linus Torvalds 已提交
730
{
731
	int err = 0;
732
	struct net *net;
E
Eric Dumazet 已提交
733
	struct net_device *dev;
L
Linus Torvalds 已提交
734

735
	net = cfg->fc_nlinfo.nl_net;
L
Linus Torvalds 已提交
736 737 738
	if (nh->nh_gw) {
		struct fib_result res;

E
Eric Dumazet 已提交
739
		if (nh->nh_flags & RTNH_F_ONLINK) {
D
David Ahern 已提交
740
			unsigned int addr_type;
L
Linus Torvalds 已提交
741

742
			if (cfg->fc_scope >= RT_SCOPE_LINK)
L
Linus Torvalds 已提交
743
				return -EINVAL;
E
Eric Dumazet 已提交
744 745
			dev = __dev_get_by_index(net, nh->nh_oif);
			if (!dev)
L
Linus Torvalds 已提交
746
				return -ENODEV;
E
Eric Dumazet 已提交
747
			if (!(dev->flags & IFF_UP))
L
Linus Torvalds 已提交
748
				return -ENETDOWN;
D
David Ahern 已提交
749 750 751
			addr_type = inet_addr_type_dev_table(net, dev, nh->nh_gw);
			if (addr_type != RTN_UNICAST)
				return -EINVAL;
752 753
			if (!netif_carrier_ok(dev))
				nh->nh_flags |= RTNH_F_LINKDOWN;
L
Linus Torvalds 已提交
754 755 756 757 758
			nh->nh_dev = dev;
			dev_hold(dev);
			nh->nh_scope = RT_SCOPE_LINK;
			return 0;
		}
E
Eric Dumazet 已提交
759
		rcu_read_lock();
L
Linus Torvalds 已提交
760
		{
761
			struct fib_table *tbl = NULL;
D
David S. Miller 已提交
762 763 764 765
			struct flowi4 fl4 = {
				.daddr = nh->nh_gw,
				.flowi4_scope = cfg->fc_scope + 1,
				.flowi4_oif = nh->nh_oif,
766
				.flowi4_iif = LOOPBACK_IFINDEX,
767
			};
L
Linus Torvalds 已提交
768 769

			/* It is not necessary, but requires a bit of thinking */
D
David S. Miller 已提交
770 771
			if (fl4.flowi4_scope < RT_SCOPE_LINK)
				fl4.flowi4_scope = RT_SCOPE_LINK;
772 773 774 775 776 777

			if (cfg->fc_table)
				tbl = fib_get_table(net, cfg->fc_table);

			if (tbl)
				err = fib_table_lookup(tbl, &fl4, &res,
778 779
						       FIB_LOOKUP_IGNORE_LINKSTATE |
						       FIB_LOOKUP_NOREF);
D
David Ahern 已提交
780 781 782 783 784 785

			/* on error or if no table given do full lookup. This
			 * is needed for example when nexthops are in the local
			 * table rather than the given table
			 */
			if (!tbl || err) {
786 787
				err = fib_lookup(net, &fl4, &res,
						 FIB_LOOKUP_IGNORE_LINKSTATE);
D
David Ahern 已提交
788 789
			}

E
Eric Dumazet 已提交
790 791
			if (err) {
				rcu_read_unlock();
L
Linus Torvalds 已提交
792
				return err;
E
Eric Dumazet 已提交
793
			}
L
Linus Torvalds 已提交
794 795 796 797 798 799
		}
		err = -EINVAL;
		if (res.type != RTN_UNICAST && res.type != RTN_LOCAL)
			goto out;
		nh->nh_scope = res.scope;
		nh->nh_oif = FIB_RES_OIF(res);
E
Eric Dumazet 已提交
800 801
		nh->nh_dev = dev = FIB_RES_DEV(res);
		if (!dev)
L
Linus Torvalds 已提交
802
			goto out;
E
Eric Dumazet 已提交
803
		dev_hold(dev);
804 805
		if (!netif_carrier_ok(dev))
			nh->nh_flags |= RTNH_F_LINKDOWN;
806
		err = (dev->flags & IFF_UP) ? 0 : -ENETDOWN;
L
Linus Torvalds 已提交
807 808 809
	} else {
		struct in_device *in_dev;

E
Eric Dumazet 已提交
810
		if (nh->nh_flags & (RTNH_F_PERVASIVE | RTNH_F_ONLINK))
L
Linus Torvalds 已提交
811 812
			return -EINVAL;

813 814
		rcu_read_lock();
		err = -ENODEV;
815
		in_dev = inetdev_by_index(net, nh->nh_oif);
816
		if (!in_dev)
817 818 819 820
			goto out;
		err = -ENETDOWN;
		if (!(in_dev->dev->flags & IFF_UP))
			goto out;
L
Linus Torvalds 已提交
821 822 823
		nh->nh_dev = in_dev->dev;
		dev_hold(nh->nh_dev);
		nh->nh_scope = RT_SCOPE_HOST;
824 825
		if (!netif_carrier_ok(nh->nh_dev))
			nh->nh_flags |= RTNH_F_LINKDOWN;
826
		err = 0;
L
Linus Torvalds 已提交
827
	}
828 829 830
out:
	rcu_read_unlock();
	return err;
L
Linus Torvalds 已提交
831 832
}

A
Al Viro 已提交
833
static inline unsigned int fib_laddr_hashfn(__be32 val)
L
Linus Torvalds 已提交
834
{
835
	unsigned int mask = (fib_info_hash_size - 1);
L
Linus Torvalds 已提交
836

E
Eric Dumazet 已提交
837 838 839
	return ((__force u32)val ^
		((__force u32)val >> 7) ^
		((__force u32)val >> 14)) & mask;
L
Linus Torvalds 已提交
840 841
}

842
static struct hlist_head *fib_info_hash_alloc(int bytes)
L
Linus Torvalds 已提交
843 844
{
	if (bytes <= PAGE_SIZE)
845
		return kzalloc(bytes, GFP_KERNEL);
L
Linus Torvalds 已提交
846 847
	else
		return (struct hlist_head *)
E
Eric Dumazet 已提交
848 849
			__get_free_pages(GFP_KERNEL | __GFP_ZERO,
					 get_order(bytes));
L
Linus Torvalds 已提交
850 851
}

852
static void fib_info_hash_free(struct hlist_head *hash, int bytes)
L
Linus Torvalds 已提交
853 854 855 856 857 858 859 860 861 862
{
	if (!hash)
		return;

	if (bytes <= PAGE_SIZE)
		kfree(hash);
	else
		free_pages((unsigned long) hash, get_order(bytes));
}

863 864 865
static void fib_info_hash_move(struct hlist_head *new_info_hash,
			       struct hlist_head *new_laddrhash,
			       unsigned int new_size)
L
Linus Torvalds 已提交
866
{
867
	struct hlist_head *old_info_hash, *old_laddrhash;
868
	unsigned int old_size = fib_info_hash_size;
869
	unsigned int i, bytes;
L
Linus Torvalds 已提交
870

871
	spin_lock_bh(&fib_info_lock);
872 873
	old_info_hash = fib_info_hash;
	old_laddrhash = fib_info_laddrhash;
874
	fib_info_hash_size = new_size;
L
Linus Torvalds 已提交
875 876 877

	for (i = 0; i < old_size; i++) {
		struct hlist_head *head = &fib_info_hash[i];
878
		struct hlist_node *n;
L
Linus Torvalds 已提交
879 880
		struct fib_info *fi;

881
		hlist_for_each_entry_safe(fi, n, head, fib_hash) {
L
Linus Torvalds 已提交
882 883 884 885 886 887 888 889 890 891 892 893
			struct hlist_head *dest;
			unsigned int new_hash;

			new_hash = fib_info_hashfn(fi);
			dest = &new_info_hash[new_hash];
			hlist_add_head(&fi->fib_hash, dest);
		}
	}
	fib_info_hash = new_info_hash;

	for (i = 0; i < old_size; i++) {
		struct hlist_head *lhead = &fib_info_laddrhash[i];
894
		struct hlist_node *n;
L
Linus Torvalds 已提交
895 896
		struct fib_info *fi;

897
		hlist_for_each_entry_safe(fi, n, lhead, fib_lhash) {
L
Linus Torvalds 已提交
898 899 900 901 902 903 904 905 906 907
			struct hlist_head *ldest;
			unsigned int new_hash;

			new_hash = fib_laddr_hashfn(fi->fib_prefsrc);
			ldest = &new_laddrhash[new_hash];
			hlist_add_head(&fi->fib_lhash, ldest);
		}
	}
	fib_info_laddrhash = new_laddrhash;

908
	spin_unlock_bh(&fib_info_lock);
909 910

	bytes = old_size * sizeof(struct hlist_head *);
911 912
	fib_info_hash_free(old_info_hash, bytes);
	fib_info_hash_free(old_laddrhash, bytes);
L
Linus Torvalds 已提交
913 914
}

915 916 917 918
__be32 fib_info_update_nh_saddr(struct net *net, struct fib_nh *nh)
{
	nh->nh_saddr = inet_select_addr(nh->nh_dev,
					nh->nh_gw,
919
					nh->nh_parent->fib_scope);
920 921 922 923 924
	nh->nh_saddr_genid = atomic_read(&net->ipv4.dev_addr_genid);

	return nh->nh_saddr;
}

925 926 927 928
static bool fib_valid_prefsrc(struct fib_config *cfg, __be32 fib_prefsrc)
{
	if (cfg->fc_type != RTN_LOCAL || !cfg->fc_dst ||
	    fib_prefsrc != cfg->fc_dst) {
D
David Ahern 已提交
929
		u32 tb_id = cfg->fc_table;
D
David Ahern 已提交
930
		int rc;
931 932 933 934

		if (tb_id == RT_TABLE_MAIN)
			tb_id = RT_TABLE_LOCAL;

D
David Ahern 已提交
935 936 937 938 939 940
		rc = inet_addr_type_table(cfg->fc_nlinfo.nl_net,
					  fib_prefsrc, tb_id);

		if (rc != RTN_LOCAL && tb_id != RT_TABLE_LOCAL) {
			rc = inet_addr_type_table(cfg->fc_nlinfo.nl_net,
						  fib_prefsrc, RT_TABLE_LOCAL);
941
		}
D
David Ahern 已提交
942 943 944

		if (rc != RTN_LOCAL)
			return false;
945 946 947 948
	}
	return true;
}

949 950 951
static int
fib_convert_metrics(struct fib_info *fi, const struct fib_config *cfg)
{
952
	bool ecn_ca = false;
953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971
	struct nlattr *nla;
	int remaining;

	if (!cfg->fc_mx)
		return 0;

	nla_for_each_attr(nla, cfg->fc_mx, cfg->fc_mx_len, remaining) {
		int type = nla_type(nla);
		u32 val;

		if (!type)
			continue;
		if (type > RTAX_MAX)
			return -EINVAL;

		if (type == RTAX_CC_ALGO) {
			char tmp[TCP_CA_NAME_MAX];

			nla_strlcpy(tmp, nla, sizeof(tmp));
972
			val = tcp_ca_get_key_by_name(tmp, &ecn_ca);
973 974 975 976 977 978 979 980 981
			if (val == TCP_CA_UNSPEC)
				return -EINVAL;
		} else {
			val = nla_get_u32(nla);
		}
		if (type == RTAX_ADVMSS && val > 65535 - 40)
			val = 65535 - 40;
		if (type == RTAX_MTU && val > 65535 - 15)
			val = 65535 - 15;
982 983
		if (type == RTAX_HOPLIMIT && val > 255)
			val = 255;
984 985
		if (type == RTAX_FEATURES && (val & ~RTAX_FEATURE_MASK))
			return -EINVAL;
986 987 988
		fi->fib_metrics[type - 1] = val;
	}

989 990 991
	if (ecn_ca)
		fi->fib_metrics[RTAX_FEATURES - 1] |= DST_FEATURE_ECN_CA;

992 993 994
	return 0;
}

995
struct fib_info *fib_create_info(struct fib_config *cfg)
L
Linus Torvalds 已提交
996 997 998 999 1000
{
	int err;
	struct fib_info *fi = NULL;
	struct fib_info *ofi;
	int nhs = 1;
1001
	struct net *net = cfg->fc_nlinfo.nl_net;
L
Linus Torvalds 已提交
1002

1003 1004 1005
	if (cfg->fc_type > RTN_MAX)
		goto err_inval;

L
Linus Torvalds 已提交
1006
	/* Fast check to catch the most weird cases */
1007
	if (fib_props[cfg->fc_type].scope > cfg->fc_scope)
L
Linus Torvalds 已提交
1008 1009
		goto err_inval;

1010 1011 1012
	if (cfg->fc_flags & (RTNH_F_DEAD | RTNH_F_LINKDOWN))
		goto err_inval;

L
Linus Torvalds 已提交
1013
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1014 1015
	if (cfg->fc_mp) {
		nhs = fib_count_nexthops(cfg->fc_mp, cfg->fc_mp_len);
L
Linus Torvalds 已提交
1016 1017 1018 1019 1020 1021
		if (nhs == 0)
			goto err_inval;
	}
#endif

	err = -ENOBUFS;
1022 1023
	if (fib_info_cnt >= fib_info_hash_size) {
		unsigned int new_size = fib_info_hash_size << 1;
L
Linus Torvalds 已提交
1024 1025 1026 1027 1028
		struct hlist_head *new_info_hash;
		struct hlist_head *new_laddrhash;
		unsigned int bytes;

		if (!new_size)
1029
			new_size = 16;
L
Linus Torvalds 已提交
1030
		bytes = new_size * sizeof(struct hlist_head *);
1031 1032
		new_info_hash = fib_info_hash_alloc(bytes);
		new_laddrhash = fib_info_hash_alloc(bytes);
L
Linus Torvalds 已提交
1033
		if (!new_info_hash || !new_laddrhash) {
1034 1035
			fib_info_hash_free(new_info_hash, bytes);
			fib_info_hash_free(new_laddrhash, bytes);
1036
		} else
1037
			fib_info_hash_move(new_info_hash, new_laddrhash, new_size);
L
Linus Torvalds 已提交
1038

1039
		if (!fib_info_hash_size)
L
Linus Torvalds 已提交
1040 1041 1042
			goto failure;
	}

1043
	fi = kzalloc(sizeof(*fi)+nhs*sizeof(struct fib_nh), GFP_KERNEL);
1044
	if (!fi)
L
Linus Torvalds 已提交
1045
		goto failure;
1046
	fib_info_cnt++;
1047 1048 1049 1050 1051 1052
	if (cfg->fc_mx) {
		fi->fib_metrics = kzalloc(sizeof(u32) * RTAX_MAX, GFP_KERNEL);
		if (!fi->fib_metrics)
			goto failure;
	} else
		fi->fib_metrics = (u32 *) dst_default_metrics;
L
Linus Torvalds 已提交
1053

1054
	fi->fib_net = net;
1055
	fi->fib_protocol = cfg->fc_protocol;
1056
	fi->fib_scope = cfg->fc_scope;
1057 1058 1059
	fi->fib_flags = cfg->fc_flags;
	fi->fib_priority = cfg->fc_priority;
	fi->fib_prefsrc = cfg->fc_prefsrc;
E
Eric Dumazet 已提交
1060
	fi->fib_type = cfg->fc_type;
1061
	fi->fib_tb_id = cfg->fc_table;
L
Linus Torvalds 已提交
1062 1063 1064

	fi->fib_nhs = nhs;
	change_nexthops(fi) {
1065
		nexthop_nh->nh_parent = fi;
E
Eric Dumazet 已提交
1066
		nexthop_nh->nh_pcpu_rth_output = alloc_percpu(struct rtable __rcu *);
1067 1068
		if (!nexthop_nh->nh_pcpu_rth_output)
			goto failure;
L
Linus Torvalds 已提交
1069 1070
	} endfor_nexthops(fi)

1071 1072 1073
	err = fib_convert_metrics(fi, cfg);
	if (err)
		goto failure;
L
Linus Torvalds 已提交
1074

1075
	if (cfg->fc_mp) {
L
Linus Torvalds 已提交
1076
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1077 1078
		err = fib_get_nhs(fi, cfg->fc_mp, cfg->fc_mp_len, cfg);
		if (err != 0)
L
Linus Torvalds 已提交
1079
			goto failure;
1080
		if (cfg->fc_oif && fi->fib_nh->nh_oif != cfg->fc_oif)
L
Linus Torvalds 已提交
1081
			goto err_inval;
1082
		if (cfg->fc_gw && fi->fib_nh->nh_gw != cfg->fc_gw)
L
Linus Torvalds 已提交
1083
			goto err_inval;
1084
#ifdef CONFIG_IP_ROUTE_CLASSID
1085
		if (cfg->fc_flow && fi->fib_nh->nh_tclassid != cfg->fc_flow)
L
Linus Torvalds 已提交
1086 1087 1088 1089 1090 1091 1092
			goto err_inval;
#endif
#else
		goto err_inval;
#endif
	} else {
		struct fib_nh *nh = fi->fib_nh;
1093

1094 1095 1096 1097 1098 1099 1100 1101 1102
		if (cfg->fc_encap) {
			struct lwtunnel_state *lwtstate;
			struct net_device *dev = NULL;

			if (cfg->fc_encap_type == LWTUNNEL_ENCAP_NONE)
				goto err_inval;
			if (cfg->fc_oif)
				dev = __dev_get_by_index(net, cfg->fc_oif);
			err = lwtunnel_build_state(dev, cfg->fc_encap_type,
1103 1104
						   cfg->fc_encap, AF_INET, cfg,
						   &lwtstate);
1105 1106 1107
			if (err)
				goto failure;

1108
			nh->nh_lwtstate = lwtstate_get(lwtstate);
1109
		}
1110 1111 1112
		nh->nh_oif = cfg->fc_oif;
		nh->nh_gw = cfg->fc_gw;
		nh->nh_flags = cfg->fc_flags;
1113
#ifdef CONFIG_IP_ROUTE_CLASSID
1114
		nh->nh_tclassid = cfg->fc_flow;
1115
		if (nh->nh_tclassid)
1116
			fi->fib_net->ipv4.fib_num_tclassid_users++;
L
Linus Torvalds 已提交
1117 1118 1119 1120 1121 1122
#endif
#ifdef CONFIG_IP_ROUTE_MULTIPATH
		nh->nh_weight = 1;
#endif
	}

1123 1124
	if (fib_props[cfg->fc_type].error) {
		if (cfg->fc_gw || cfg->fc_oif || cfg->fc_mp)
L
Linus Torvalds 已提交
1125 1126
			goto err_inval;
		goto link_it;
1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137
	} else {
		switch (cfg->fc_type) {
		case RTN_UNICAST:
		case RTN_LOCAL:
		case RTN_BROADCAST:
		case RTN_ANYCAST:
		case RTN_MULTICAST:
			break;
		default:
			goto err_inval;
		}
L
Linus Torvalds 已提交
1138 1139
	}

1140
	if (cfg->fc_scope > RT_SCOPE_HOST)
L
Linus Torvalds 已提交
1141 1142
		goto err_inval;

1143
	if (cfg->fc_scope == RT_SCOPE_HOST) {
L
Linus Torvalds 已提交
1144 1145 1146 1147 1148 1149
		struct fib_nh *nh = fi->fib_nh;

		/* Local address is added. */
		if (nhs != 1 || nh->nh_gw)
			goto err_inval;
		nh->nh_scope = RT_SCOPE_NOWHERE;
1150
		nh->nh_dev = dev_get_by_index(net, fi->fib_nh->nh_oif);
L
Linus Torvalds 已提交
1151
		err = -ENODEV;
1152
		if (!nh->nh_dev)
L
Linus Torvalds 已提交
1153 1154
			goto failure;
	} else {
1155 1156
		int linkdown = 0;

L
Linus Torvalds 已提交
1157
		change_nexthops(fi) {
E
Eric Dumazet 已提交
1158 1159
			err = fib_check_nh(cfg, fi, nexthop_nh);
			if (err != 0)
L
Linus Torvalds 已提交
1160
				goto failure;
1161 1162
			if (nexthop_nh->nh_flags & RTNH_F_LINKDOWN)
				linkdown++;
L
Linus Torvalds 已提交
1163
		} endfor_nexthops(fi)
1164 1165
		if (linkdown == fi->fib_nhs)
			fi->fib_flags |= RTNH_F_LINKDOWN;
L
Linus Torvalds 已提交
1166 1167
	}

1168 1169
	if (fi->fib_prefsrc && !fib_valid_prefsrc(cfg, fi->fib_prefsrc))
		goto err_inval;
L
Linus Torvalds 已提交
1170

1171
	change_nexthops(fi) {
1172
		fib_info_update_nh_saddr(net, nexthop_nh);
P
Peter Nørlund 已提交
1173
		fib_add_weight(fi, nexthop_nh);
1174 1175
	} endfor_nexthops(fi)

P
Peter Nørlund 已提交
1176 1177
	fib_rebalance(fi);

L
Linus Torvalds 已提交
1178
link_it:
E
Eric Dumazet 已提交
1179 1180
	ofi = fib_find_info(fi);
	if (ofi) {
L
Linus Torvalds 已提交
1181 1182 1183 1184 1185 1186 1187 1188
		fi->fib_dead = 1;
		free_fib_info(fi);
		ofi->fib_treeref++;
		return ofi;
	}

	fi->fib_treeref++;
	atomic_inc(&fi->fib_clntref);
1189
	spin_lock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201
	hlist_add_head(&fi->fib_hash,
		       &fib_info_hash[fib_info_hashfn(fi)]);
	if (fi->fib_prefsrc) {
		struct hlist_head *head;

		head = &fib_info_laddrhash[fib_laddr_hashfn(fi->fib_prefsrc)];
		hlist_add_head(&fi->fib_lhash, head);
	}
	change_nexthops(fi) {
		struct hlist_head *head;
		unsigned int hash;

1202
		if (!nexthop_nh->nh_dev)
L
Linus Torvalds 已提交
1203
			continue;
1204
		hash = fib_devindex_hashfn(nexthop_nh->nh_dev->ifindex);
L
Linus Torvalds 已提交
1205
		head = &fib_info_devhash[hash];
1206
		hlist_add_head(&nexthop_nh->nh_hash, head);
L
Linus Torvalds 已提交
1207
	} endfor_nexthops(fi)
1208
	spin_unlock_bh(&fib_info_lock);
L
Linus Torvalds 已提交
1209 1210 1211 1212 1213 1214
	return fi;

err_inval:
	err = -EINVAL;

failure:
1215
	if (fi) {
L
Linus Torvalds 已提交
1216 1217 1218
		fi->fib_dead = 1;
		free_fib_info(fi);
	}
1219 1220

	return ERR_PTR(err);
L
Linus Torvalds 已提交
1221 1222
}

1223
int fib_dump_info(struct sk_buff *skb, u32 portid, u32 seq, int event,
1224
		  u32 tb_id, u8 type, __be32 dst, int dst_len, u8 tos,
1225
		  struct fib_info *fi, unsigned int flags)
L
Linus Torvalds 已提交
1226
{
1227
	struct nlmsghdr *nlh;
L
Linus Torvalds 已提交
1228 1229
	struct rtmsg *rtm;

1230
	nlh = nlmsg_put(skb, portid, seq, event, sizeof(*rtm), flags);
1231
	if (!nlh)
1232
		return -EMSGSIZE;
1233 1234

	rtm = nlmsg_data(nlh);
L
Linus Torvalds 已提交
1235 1236 1237 1238
	rtm->rtm_family = AF_INET;
	rtm->rtm_dst_len = dst_len;
	rtm->rtm_src_len = 0;
	rtm->rtm_tos = tos;
1239 1240 1241 1242
	if (tb_id < 256)
		rtm->rtm_table = tb_id;
	else
		rtm->rtm_table = RT_TABLE_COMPAT;
D
David S. Miller 已提交
1243 1244
	if (nla_put_u32(skb, RTA_TABLE, tb_id))
		goto nla_put_failure;
L
Linus Torvalds 已提交
1245 1246
	rtm->rtm_type = type;
	rtm->rtm_flags = fi->fib_flags;
1247
	rtm->rtm_scope = fi->fib_scope;
L
Linus Torvalds 已提交
1248
	rtm->rtm_protocol = fi->fib_protocol;
1249

D
David S. Miller 已提交
1250
	if (rtm->rtm_dst_len &&
1251
	    nla_put_in_addr(skb, RTA_DST, dst))
D
David S. Miller 已提交
1252 1253 1254 1255
		goto nla_put_failure;
	if (fi->fib_priority &&
	    nla_put_u32(skb, RTA_PRIORITY, fi->fib_priority))
		goto nla_put_failure;
L
Linus Torvalds 已提交
1256
	if (rtnetlink_put_metrics(skb, fi->fib_metrics) < 0)
1257 1258
		goto nla_put_failure;

D
David S. Miller 已提交
1259
	if (fi->fib_prefsrc &&
1260
	    nla_put_in_addr(skb, RTA_PREFSRC, fi->fib_prefsrc))
D
David S. Miller 已提交
1261
		goto nla_put_failure;
L
Linus Torvalds 已提交
1262
	if (fi->fib_nhs == 1) {
1263 1264
		struct in_device *in_dev;

D
David S. Miller 已提交
1265
		if (fi->fib_nh->nh_gw &&
1266
		    nla_put_in_addr(skb, RTA_GATEWAY, fi->fib_nh->nh_gw))
D
David S. Miller 已提交
1267 1268 1269 1270
			goto nla_put_failure;
		if (fi->fib_nh->nh_oif &&
		    nla_put_u32(skb, RTA_OIF, fi->fib_nh->nh_oif))
			goto nla_put_failure;
1271
		if (fi->fib_nh->nh_flags & RTNH_F_LINKDOWN) {
1272
			in_dev = __in_dev_get_rtnl(fi->fib_nh->nh_dev);
1273 1274 1275 1276
			if (in_dev &&
			    IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev))
				rtm->rtm_flags |= RTNH_F_DEAD;
		}
1277
#ifdef CONFIG_IP_ROUTE_CLASSID
D
David S. Miller 已提交
1278 1279 1280
		if (fi->fib_nh[0].nh_tclassid &&
		    nla_put_u32(skb, RTA_FLOW, fi->fib_nh[0].nh_tclassid))
			goto nla_put_failure;
1281
#endif
1282 1283
		if (fi->fib_nh->nh_lwtstate)
			lwtunnel_fill_encap(skb, fi->fib_nh->nh_lwtstate);
L
Linus Torvalds 已提交
1284 1285 1286
	}
#ifdef CONFIG_IP_ROUTE_MULTIPATH
	if (fi->fib_nhs > 1) {
1287 1288 1289 1290
		struct rtnexthop *rtnh;
		struct nlattr *mp;

		mp = nla_nest_start(skb, RTA_MULTIPATH);
1291
		if (!mp)
1292
			goto nla_put_failure;
L
Linus Torvalds 已提交
1293 1294

		for_nexthops(fi) {
1295 1296
			struct in_device *in_dev;

1297
			rtnh = nla_reserve_nohdr(skb, sizeof(*rtnh));
1298
			if (!rtnh)
1299 1300 1301
				goto nla_put_failure;

			rtnh->rtnh_flags = nh->nh_flags & 0xFF;
1302
			if (nh->nh_flags & RTNH_F_LINKDOWN) {
1303
				in_dev = __in_dev_get_rtnl(nh->nh_dev);
1304 1305 1306 1307
				if (in_dev &&
				    IN_DEV_IGNORE_ROUTES_WITH_LINKDOWN(in_dev))
					rtnh->rtnh_flags |= RTNH_F_DEAD;
			}
1308 1309 1310
			rtnh->rtnh_hops = nh->nh_weight - 1;
			rtnh->rtnh_ifindex = nh->nh_oif;

D
David S. Miller 已提交
1311
			if (nh->nh_gw &&
1312
			    nla_put_in_addr(skb, RTA_GATEWAY, nh->nh_gw))
D
David S. Miller 已提交
1313
				goto nla_put_failure;
1314
#ifdef CONFIG_IP_ROUTE_CLASSID
D
David S. Miller 已提交
1315 1316 1317
			if (nh->nh_tclassid &&
			    nla_put_u32(skb, RTA_FLOW, nh->nh_tclassid))
				goto nla_put_failure;
1318
#endif
1319 1320
			if (nh->nh_lwtstate)
				lwtunnel_fill_encap(skb, nh->nh_lwtstate);
1321 1322
			/* length of rtnetlink header + attributes */
			rtnh->rtnh_len = nlmsg_get_pos(skb) - (void *) rtnh;
L
Linus Torvalds 已提交
1323
		} endfor_nexthops(fi);
1324 1325

		nla_nest_end(skb, mp);
L
Linus Torvalds 已提交
1326 1327
	}
#endif
1328 1329
	nlmsg_end(skb, nlh);
	return 0;
L
Linus Torvalds 已提交
1330

1331
nla_put_failure:
1332 1333
	nlmsg_cancel(skb, nlh);
	return -EMSGSIZE;
L
Linus Torvalds 已提交
1334 1335 1336
}

/*
E
Eric Dumazet 已提交
1337 1338 1339 1340
 * Update FIB if:
 * - local address disappeared -> we must delete all the entries
 *   referring to it.
 * - device went down -> we must shutdown all nexthops going via it.
L
Linus Torvalds 已提交
1341
 */
1342
int fib_sync_down_addr(struct net_device *dev, __be32 local)
L
Linus Torvalds 已提交
1343 1344
{
	int ret = 0;
D
Denis V. Lunev 已提交
1345 1346
	unsigned int hash = fib_laddr_hashfn(local);
	struct hlist_head *head = &fib_info_laddrhash[hash];
1347 1348
	struct net *net = dev_net(dev);
	int tb_id = l3mdev_fib_table(dev);
D
Denis V. Lunev 已提交
1349
	struct fib_info *fi;
L
Linus Torvalds 已提交
1350

1351
	if (!fib_info_laddrhash || local == 0)
D
Denis V. Lunev 已提交
1352
		return 0;
L
Linus Torvalds 已提交
1353

1354
	hlist_for_each_entry(fi, head, fib_lhash) {
1355 1356
		if (!net_eq(fi->fib_net, net) ||
		    fi->fib_tb_id != tb_id)
1357
			continue;
D
Denis V. Lunev 已提交
1358 1359 1360
		if (fi->fib_prefsrc == local) {
			fi->fib_flags |= RTNH_F_DEAD;
			ret++;
L
Linus Torvalds 已提交
1361 1362
		}
	}
D
Denis V. Lunev 已提交
1363 1364 1365
	return ret;
}

1366 1367 1368 1369 1370 1371 1372
/* Event              force Flags           Description
 * NETDEV_CHANGE      0     LINKDOWN        Carrier OFF, not for scope host
 * NETDEV_DOWN        0     LINKDOWN|DEAD   Link down, not for scope host
 * NETDEV_DOWN        1     LINKDOWN|DEAD   Last address removed
 * NETDEV_UNREGISTER  1     LINKDOWN|DEAD   Device removed
 */
int fib_sync_down_dev(struct net_device *dev, unsigned long event, bool force)
D
Denis V. Lunev 已提交
1373 1374 1375 1376 1377 1378 1379
{
	int ret = 0;
	int scope = RT_SCOPE_NOWHERE;
	struct fib_info *prev_fi = NULL;
	unsigned int hash = fib_devindex_hashfn(dev->ifindex);
	struct hlist_head *head = &fib_info_devhash[hash];
	struct fib_nh *nh;
L
Linus Torvalds 已提交
1380

1381
	if (force)
D
Denis V. Lunev 已提交
1382
		scope = -1;
L
Linus Torvalds 已提交
1383

1384
	hlist_for_each_entry(nh, head, nh_hash) {
D
Denis V. Lunev 已提交
1385 1386
		struct fib_info *fi = nh->nh_parent;
		int dead;
L
Linus Torvalds 已提交
1387

D
Denis V. Lunev 已提交
1388 1389 1390 1391 1392 1393
		BUG_ON(!fi->fib_nhs);
		if (nh->nh_dev != dev || fi == prev_fi)
			continue;
		prev_fi = fi;
		dead = 0;
		change_nexthops(fi) {
E
Eric Dumazet 已提交
1394
			if (nexthop_nh->nh_flags & RTNH_F_DEAD)
D
Denis V. Lunev 已提交
1395
				dead++;
1396 1397
			else if (nexthop_nh->nh_dev == dev &&
				 nexthop_nh->nh_scope != scope) {
1398 1399 1400 1401 1402 1403 1404 1405 1406
				switch (event) {
				case NETDEV_DOWN:
				case NETDEV_UNREGISTER:
					nexthop_nh->nh_flags |= RTNH_F_DEAD;
					/* fall through */
				case NETDEV_CHANGE:
					nexthop_nh->nh_flags |= RTNH_F_LINKDOWN;
					break;
				}
D
Denis V. Lunev 已提交
1407 1408
				dead++;
			}
L
Linus Torvalds 已提交
1409
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1410 1411
			if (event == NETDEV_UNREGISTER &&
			    nexthop_nh->nh_dev == dev) {
D
Denis V. Lunev 已提交
1412 1413
				dead = fi->fib_nhs;
				break;
L
Linus Torvalds 已提交
1414
			}
D
Denis V. Lunev 已提交
1415 1416 1417
#endif
		} endfor_nexthops(fi)
		if (dead == fi->fib_nhs) {
1418 1419 1420 1421 1422 1423 1424 1425 1426
			switch (event) {
			case NETDEV_DOWN:
			case NETDEV_UNREGISTER:
				fi->fib_flags |= RTNH_F_DEAD;
				/* fall through */
			case NETDEV_CHANGE:
				fi->fib_flags |= RTNH_F_LINKDOWN;
				break;
			}
D
Denis V. Lunev 已提交
1427
			ret++;
L
Linus Torvalds 已提交
1428
		}
P
Peter Nørlund 已提交
1429 1430

		fib_rebalance(fi);
L
Linus Torvalds 已提交
1431 1432 1433 1434 1435
	}

	return ret;
}

1436
/* Must be invoked inside of an RCU protected region.  */
1437
void fib_select_default(const struct flowi4 *flp, struct fib_result *res)
1438 1439
{
	struct fib_info *fi = NULL, *last_resort = NULL;
1440
	struct hlist_head *fa_head = res->fa_head;
1441
	struct fib_table *tb = res->table;
1442
	u8 slen = 32 - res->prefixlen;
1443
	int order = -1, last_idx = -1;
1444 1445 1446
	struct fib_alias *fa, *fa1 = NULL;
	u32 last_prio = res->fi->fib_priority;
	u8 last_tos = 0;
1447

1448
	hlist_for_each_entry_rcu(fa, fa_head, fa_list) {
1449 1450
		struct fib_info *next_fi = fa->fa_info;

1451 1452
		if (fa->fa_slen != slen)
			continue;
1453 1454
		if (fa->fa_tos && fa->fa_tos != flp->flowi4_tos)
			continue;
1455 1456
		if (fa->tb_id != tb->tb_id)
			continue;
1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467
		if (next_fi->fib_priority > last_prio &&
		    fa->fa_tos == last_tos) {
			if (last_tos)
				continue;
			break;
		}
		if (next_fi->fib_flags & RTNH_F_DEAD)
			continue;
		last_tos = fa->fa_tos;
		last_prio = next_fi->fib_priority;

1468
		if (next_fi->fib_scope != res->scope ||
1469 1470 1471 1472 1473 1474 1475 1476
		    fa->fa_type != RTN_UNICAST)
			continue;
		if (!next_fi->fib_nh[0].nh_gw ||
		    next_fi->fib_nh[0].nh_scope != RT_SCOPE_LINK)
			continue;

		fib_alias_accessed(fa);

1477
		if (!fi) {
1478 1479
			if (next_fi != res->fi)
				break;
1480
			fa1 = fa;
1481
		} else if (!fib_detect_death(fi, order, &last_resort,
1482
					     &last_idx, fa1->fa_default)) {
1483
			fib_result_assign(res, fi);
1484
			fa1->fa_default = order;
1485 1486 1487 1488 1489 1490
			goto out;
		}
		fi = next_fi;
		order++;
	}

1491
	if (order <= 0 || !fi) {
1492 1493
		if (fa1)
			fa1->fa_default = -1;
1494 1495 1496 1497
		goto out;
	}

	if (!fib_detect_death(fi, order, &last_resort, &last_idx,
1498
			      fa1->fa_default)) {
1499
		fib_result_assign(res, fi);
1500
		fa1->fa_default = order;
1501 1502 1503 1504 1505
		goto out;
	}

	if (last_idx >= 0)
		fib_result_assign(res, last_resort);
1506
	fa1->fa_default = last_idx;
1507
out:
1508
	return;
1509 1510
}

L
Linus Torvalds 已提交
1511
/*
E
Eric Dumazet 已提交
1512 1513
 * Dead device goes up. We wake up dead nexthops.
 * It takes sense only on multipath routes.
L
Linus Torvalds 已提交
1514
 */
1515
int fib_sync_up(struct net_device *dev, unsigned int nh_flags)
L
Linus Torvalds 已提交
1516 1517 1518 1519 1520 1521 1522
{
	struct fib_info *prev_fi;
	unsigned int hash;
	struct hlist_head *head;
	struct fib_nh *nh;
	int ret;

E
Eric Dumazet 已提交
1523
	if (!(dev->flags & IFF_UP))
L
Linus Torvalds 已提交
1524 1525
		return 0;

1526 1527 1528 1529 1530 1531 1532
	if (nh_flags & RTNH_F_DEAD) {
		unsigned int flags = dev_get_flags(dev);

		if (flags & (IFF_RUNNING | IFF_LOWER_UP))
			nh_flags |= RTNH_F_LINKDOWN;
	}

L
Linus Torvalds 已提交
1533 1534 1535 1536 1537
	prev_fi = NULL;
	hash = fib_devindex_hashfn(dev->ifindex);
	head = &fib_info_devhash[hash];
	ret = 0;

1538
	hlist_for_each_entry(nh, head, nh_hash) {
L
Linus Torvalds 已提交
1539 1540 1541 1542 1543 1544 1545 1546 1547 1548
		struct fib_info *fi = nh->nh_parent;
		int alive;

		BUG_ON(!fi->fib_nhs);
		if (nh->nh_dev != dev || fi == prev_fi)
			continue;

		prev_fi = fi;
		alive = 0;
		change_nexthops(fi) {
1549
			if (!(nexthop_nh->nh_flags & nh_flags)) {
L
Linus Torvalds 已提交
1550 1551 1552
				alive++;
				continue;
			}
1553
			if (!nexthop_nh->nh_dev ||
E
Eric Dumazet 已提交
1554
			    !(nexthop_nh->nh_dev->flags & IFF_UP))
L
Linus Torvalds 已提交
1555
				continue;
1556 1557
			if (nexthop_nh->nh_dev != dev ||
			    !__in_dev_get_rtnl(dev))
L
Linus Torvalds 已提交
1558 1559
				continue;
			alive++;
1560
			nexthop_nh->nh_flags &= ~nh_flags;
L
Linus Torvalds 已提交
1561 1562 1563
		} endfor_nexthops(fi)

		if (alive > 0) {
1564
			fi->fib_flags &= ~nh_flags;
L
Linus Torvalds 已提交
1565 1566
			ret++;
		}
P
Peter Nørlund 已提交
1567 1568

		fib_rebalance(fi);
L
Linus Torvalds 已提交
1569 1570 1571 1572 1573
	}

	return ret;
}

1574
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1575 1576 1577 1578 1579 1580 1581 1582 1583
static bool fib_good_nh(const struct fib_nh *nh)
{
	int state = NUD_REACHABLE;

	if (nh->nh_scope == RT_SCOPE_LINK) {
		struct neighbour *n;

		rcu_read_lock_bh();

1584 1585
		n = __ipv4_neigh_lookup_noref(nh->nh_dev,
					      (__force u32)nh->nh_gw);
1586 1587 1588 1589 1590 1591 1592 1593
		if (n)
			state = n->nud_state;

		rcu_read_unlock_bh();
	}

	return !!(state & NUD_VALID);
}
1594

P
Peter Nørlund 已提交
1595
void fib_select_multipath(struct fib_result *res, int hash)
L
Linus Torvalds 已提交
1596 1597
{
	struct fib_info *fi = res->fi;
1598 1599
	struct net *net = fi->fib_net;
	bool first = false;
L
Linus Torvalds 已提交
1600

P
Peter Nørlund 已提交
1601 1602 1603
	for_nexthops(fi) {
		if (hash > atomic_read(&nh->nh_upper_bound))
			continue;
L
Linus Torvalds 已提交
1604

1605 1606 1607 1608 1609 1610 1611 1612 1613
		if (!net->ipv4.sysctl_fib_multipath_use_neigh ||
		    fib_good_nh(nh)) {
			res->nh_sel = nhsel;
			return;
		}
		if (!first) {
			res->nh_sel = nhsel;
			first = true;
		}
L
Linus Torvalds 已提交
1614 1615 1616
	} endfor_nexthops(fi);
}
#endif
1617 1618 1619 1620 1621 1622 1623

void fib_select_path(struct net *net, struct fib_result *res,
		     struct flowi4 *fl4, int mp_hash)
{
#ifdef CONFIG_IP_ROUTE_MULTIPATH
	if (res->fi->fib_nhs > 1 && fl4->flowi4_oif == 0) {
		if (mp_hash < 0)
1624 1625
			mp_hash = get_hash_from_flowi4(fl4) >> 1;

1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638
		fib_select_multipath(res, mp_hash);
	}
	else
#endif
	if (!res->prefixlen &&
	    res->table->tb_num_default > 1 &&
	    res->type == RTN_UNICAST && !fl4->flowi4_oif)
		fib_select_default(fl4, res);

	if (!fl4->saddr)
		fl4->saddr = FIB_RES_PREFSRC(net, *res);
}
EXPORT_SYMBOL_GPL(fib_select_path);