fib_rules.c 30.3 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0-only
2 3 4 5 6 7 8 9
/*
 * net/core/fib_rules.c		Generic Routing Rules
 *
 * Authors:	Thomas Graf <tgraf@suug.ch>
 */

#include <linux/types.h>
#include <linux/kernel.h>
10
#include <linux/slab.h>
11
#include <linux/list.h>
12
#include <linux/module.h>
13
#include <net/net_namespace.h>
14
#include <net/sock.h>
15
#include <net/fib_rules.h>
16
#include <net/ip_tunnels.h>
17
#include <linux/indirect_call_wrapper.h>
18

19
#if defined(CONFIG_IPV6) && defined(CONFIG_IPV6_MULTIPLE_TABLES)
20
#ifdef CONFIG_IP_MULTIPLE_TABLES
21 22 23
#define INDIRECT_CALL_MT(f, f2, f1, ...) \
	INDIRECT_CALL_INET(f, f2, f1, __VA_ARGS__)
#else
24 25
#define INDIRECT_CALL_MT(f, f2, f1, ...) INDIRECT_CALL_1(f, f2, __VA_ARGS__)
#endif
Y
YueHaibing 已提交
26
#elif defined(CONFIG_IP_MULTIPLE_TABLES)
27
#define INDIRECT_CALL_MT(f, f2, f1, ...) INDIRECT_CALL_1(f, f1, __VA_ARGS__)
28 29
#else
#define INDIRECT_CALL_MT(f, f2, f1, ...) f(__VA_ARGS__)
30 31
#endif

32 33 34 35 36
static const struct fib_kuid_range fib_kuid_range_unset = {
	KUIDT_INIT(0),
	KUIDT_INIT(~0),
};

37 38 39 40 41 42 43 44 45 46
bool fib_rule_matchall(const struct fib_rule *rule)
{
	if (rule->iifindex || rule->oifindex || rule->mark || rule->tun_id ||
	    rule->flags)
		return false;
	if (rule->suppress_ifgroup != -1 || rule->suppress_prefixlen != -1)
		return false;
	if (!uid_eq(rule->uid_range.start, fib_kuid_range_unset.start) ||
	    !uid_eq(rule->uid_range.end, fib_kuid_range_unset.end))
		return false;
47 48 49 50
	if (fib_rule_port_range_set(&rule->sport_range))
		return false;
	if (fib_rule_port_range_set(&rule->dport_range))
		return false;
51 52 53 54
	return true;
}
EXPORT_SYMBOL_GPL(fib_rule_matchall);

55 56 57 58 59
int fib_default_rule_add(struct fib_rules_ops *ops,
			 u32 pref, u32 table, u32 flags)
{
	struct fib_rule *r;

60
	r = kzalloc(ops->rule_size, GFP_KERNEL_ACCOUNT);
61 62 63
	if (r == NULL)
		return -ENOMEM;

64
	refcount_set(&r->refcnt, 1);
65 66 67 68
	r->action = FR_ACT_TO_TBL;
	r->pref = pref;
	r->table = table;
	r->flags = flags;
69
	r->proto = RTPROT_KERNEL;
70
	r->fr_net = ops->fro_net;
71
	r->uid_range = fib_kuid_range_unset;
72

73 74 75
	r->suppress_prefixlen = -1;
	r->suppress_ifgroup = -1;

76 77 78 79 80 81 82
	/* The lock is not required here, the list in unreacheable
	 * at the moment this function is called */
	list_add_tail(&r->list, &ops->rules_list);
	return 0;
}
EXPORT_SYMBOL(fib_default_rule_add);

83
static u32 fib_default_rule_pref(struct fib_rules_ops *ops)
84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99
{
	struct list_head *pos;
	struct fib_rule *rule;

	if (!list_empty(&ops->rules_list)) {
		pos = ops->rules_list.next;
		if (pos->next != &ops->rules_list) {
			rule = list_entry(pos->next, struct fib_rule, list);
			if (rule->pref)
				return rule->pref - 1;
		}
	}

	return 0;
}

D
Denis V. Lunev 已提交
100
static void notify_rule_change(int event, struct fib_rule *rule,
101 102
			       struct fib_rules_ops *ops, struct nlmsghdr *nlh,
			       u32 pid);
103

104
static struct fib_rules_ops *lookup_rules_ops(struct net *net, int family)
105 106 107 108
{
	struct fib_rules_ops *ops;

	rcu_read_lock();
109
	list_for_each_entry_rcu(ops, &net->rules_ops, list) {
110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127
		if (ops->family == family) {
			if (!try_module_get(ops->owner))
				ops = NULL;
			rcu_read_unlock();
			return ops;
		}
	}
	rcu_read_unlock();

	return NULL;
}

static void rules_ops_put(struct fib_rules_ops *ops)
{
	if (ops)
		module_put(ops->owner);
}

128 129 130
static void flush_route_cache(struct fib_rules_ops *ops)
{
	if (ops->flush_cache)
131
		ops->flush_cache(ops);
132 133
}

134
static int __fib_rules_register(struct fib_rules_ops *ops)
135 136 137
{
	int err = -EEXIST;
	struct fib_rules_ops *o;
D
Denis V. Lunev 已提交
138 139 140
	struct net *net;

	net = ops->fro_net;
141 142 143 144 145 146 147 148 149

	if (ops->rule_size < sizeof(struct fib_rule))
		return -EINVAL;

	if (ops->match == NULL || ops->configure == NULL ||
	    ops->compare == NULL || ops->fill == NULL ||
	    ops->action == NULL)
		return -EINVAL;

150 151
	spin_lock(&net->rules_mod_lock);
	list_for_each_entry(o, &net->rules_ops, list)
152 153 154
		if (ops->family == o->family)
			goto errout;

155
	list_add_tail_rcu(&ops->list, &net->rules_ops);
156 157
	err = 0;
errout:
158
	spin_unlock(&net->rules_mod_lock);
159 160 161 162

	return err;
}

163
struct fib_rules_ops *
164
fib_rules_register(const struct fib_rules_ops *tmpl, struct net *net)
165 166 167 168
{
	struct fib_rules_ops *ops;
	int err;

169
	ops = kmemdup(tmpl, sizeof(*ops), GFP_KERNEL);
170 171 172 173 174 175 176 177 178 179 180 181 182 183
	if (ops == NULL)
		return ERR_PTR(-ENOMEM);

	INIT_LIST_HEAD(&ops->rules_list);
	ops->fro_net = net;

	err = __fib_rules_register(ops);
	if (err) {
		kfree(ops);
		ops = ERR_PTR(err);
	}

	return ops;
}
184 185
EXPORT_SYMBOL_GPL(fib_rules_register);

186
static void fib_rules_cleanup_ops(struct fib_rules_ops *ops)
187 188 189
{
	struct fib_rule *rule, *tmp;

190
	list_for_each_entry_safe(rule, tmp, &ops->rules_list, list) {
191
		list_del_rcu(&rule->list);
192 193
		if (ops->delete)
			ops->delete(rule);
194 195 196 197
		fib_rule_put(rule);
	}
}

D
Denis V. Lunev 已提交
198
void fib_rules_unregister(struct fib_rules_ops *ops)
199
{
D
Denis V. Lunev 已提交
200
	struct net *net = ops->fro_net;
201

202
	spin_lock(&net->rules_mod_lock);
203
	list_del_rcu(&ops->list);
204
	spin_unlock(&net->rules_mod_lock);
205

206
	fib_rules_cleanup_ops(ops);
207
	kfree_rcu(ops, rcu);
208 209 210
}
EXPORT_SYMBOL_GPL(fib_rules_unregister);

211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238
static int uid_range_set(struct fib_kuid_range *range)
{
	return uid_valid(range->start) && uid_valid(range->end);
}

static struct fib_kuid_range nla_get_kuid_range(struct nlattr **tb)
{
	struct fib_rule_uid_range *in;
	struct fib_kuid_range out;

	in = (struct fib_rule_uid_range *)nla_data(tb[FRA_UID_RANGE]);

	out.start = make_kuid(current_user_ns(), in->start);
	out.end = make_kuid(current_user_ns(), in->end);

	return out;
}

static int nla_put_uid_range(struct sk_buff *skb, struct fib_kuid_range *range)
{
	struct fib_rule_uid_range out = {
		from_kuid_munged(current_user_ns(), range->start),
		from_kuid_munged(current_user_ns(), range->end)
	};

	return nla_put(skb, FRA_UID_RANGE, sizeof(out), &out);
}

239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258
static int nla_get_port_range(struct nlattr *pattr,
			      struct fib_rule_port_range *port_range)
{
	const struct fib_rule_port_range *pr = nla_data(pattr);

	if (!fib_rule_port_range_valid(pr))
		return -EINVAL;

	port_range->start = pr->start;
	port_range->end = pr->end;

	return 0;
}

static int nla_put_port_range(struct sk_buff *skb, int attrtype,
			      struct fib_rule_port_range *range)
{
	return nla_put(skb, attrtype, sizeof(*range), range);
}

259
static int fib_rule_match(struct fib_rule *rule, struct fib_rules_ops *ops,
D
David Ahern 已提交
260 261
			  struct flowi *fl, int flags,
			  struct fib_lookup_arg *arg)
262 263 264
{
	int ret = 0;

265
	if (rule->iifindex && (rule->iifindex != fl->flowi_iif))
266 267
		goto out;

268
	if (rule->oifindex && (rule->oifindex != fl->flowi_oif))
269 270
		goto out;

271
	if ((rule->mark ^ fl->flowi_mark) & rule->mark_mask)
272 273
		goto out;

274 275 276
	if (rule->tun_id && (rule->tun_id != fl->flowi_tun_key.tun_id))
		goto out;

D
David Ahern 已提交
277 278 279
	if (rule->l3mdev && !l3mdev_fib_rule_match(rule->fr_net, fl, arg))
		goto out;

280 281 282 283
	if (uid_lt(fl->flowi_uid, rule->uid_range.start) ||
	    uid_gt(fl->flowi_uid, rule->uid_range.end))
		goto out;

284 285 286 287
	ret = INDIRECT_CALL_MT(ops->match,
			       fib6_rule_match,
			       fib4_rule_match,
			       rule, fl, flags);
288 289 290 291
out:
	return (rule->flags & FIB_RULE_INVERT) ? !ret : ret;
}

292 293 294 295 296 297 298 299
int fib_rules_lookup(struct fib_rules_ops *ops, struct flowi *fl,
		     int flags, struct fib_lookup_arg *arg)
{
	struct fib_rule *rule;
	int err;

	rcu_read_lock();

300
	list_for_each_entry_rcu(rule, &ops->rules_list, list) {
T
Thomas Graf 已提交
301
jumped:
D
David Ahern 已提交
302
		if (!fib_rule_match(rule, ops, fl, flags, arg))
303 304
			continue;

T
Thomas Graf 已提交
305 306 307 308 309 310 311 312 313 314
		if (rule->action == FR_ACT_GOTO) {
			struct fib_rule *target;

			target = rcu_dereference(rule->ctarget);
			if (target == NULL) {
				continue;
			} else {
				rule = target;
				goto jumped;
			}
315 316 317
		} else if (rule->action == FR_ACT_NOP)
			continue;
		else
318 319 320 321 322 323 324 325
			err = INDIRECT_CALL_MT(ops->action,
					       fib6_rule_action,
					       fib4_rule_action,
					       rule, fl, flags, arg);

		if (!err && ops->suppress && INDIRECT_CALL_MT(ops->suppress,
							      fib6_rule_suppress,
							      fib4_rule_suppress,
326
							      rule, flags, arg))
327 328
			continue;

329
		if (err != -EAGAIN) {
E
Eric Dumazet 已提交
330
			if ((arg->flags & FIB_LOOKUP_NOREF) ||
331
			    likely(refcount_inc_not_zero(&rule->refcnt))) {
332 333 334 335
				arg->rule = rule;
				goto out;
			}
			break;
336 337 338
		}
	}

339
	err = -ESRCH;
340 341 342 343 344 345 346
out:
	rcu_read_unlock();

	return err;
}
EXPORT_SYMBOL_GPL(fib_rules_lookup);

347
static int call_fib_rule_notifier(struct notifier_block *nb,
348
				  enum fib_event_type event_type,
349 350
				  struct fib_rule *rule, int family,
				  struct netlink_ext_ack *extack)
351 352 353
{
	struct fib_rule_notifier_info info = {
		.info.family = family,
354
		.info.extack = extack,
355 356 357
		.rule = rule,
	};

358
	return call_fib_notifier(nb, event_type, &info.info);
359 360 361 362 363
}

static int call_fib_rule_notifiers(struct net *net,
				   enum fib_event_type event_type,
				   struct fib_rule *rule,
D
David Ahern 已提交
364 365
				   struct fib_rules_ops *ops,
				   struct netlink_ext_ack *extack)
366 367 368
{
	struct fib_rule_notifier_info info = {
		.info.family = ops->family,
D
David Ahern 已提交
369
		.info.extack = extack,
370 371 372 373 374 375 376 377
		.rule = rule,
	};

	ops->fib_rules_seq++;
	return call_fib_notifiers(net, event_type, &info.info);
}

/* Called with rcu_read_lock() */
378 379
int fib_rules_dump(struct net *net, struct notifier_block *nb, int family,
		   struct netlink_ext_ack *extack)
380 381 382
{
	struct fib_rules_ops *ops;
	struct fib_rule *rule;
383
	int err = 0;
384 385 386 387

	ops = lookup_rules_ops(net, family);
	if (!ops)
		return -EAFNOSUPPORT;
388 389
	list_for_each_entry_rcu(rule, &ops->rules_list, list) {
		err = call_fib_rule_notifier(nb, FIB_EVENT_RULE_ADD,
390
					     rule, family, extack);
391 392 393
		if (err)
			break;
	}
394 395
	rules_ops_put(ops);

396
	return err;
397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416
}
EXPORT_SYMBOL_GPL(fib_rules_dump);

unsigned int fib_rules_seq_read(struct net *net, int family)
{
	unsigned int fib_rules_seq;
	struct fib_rules_ops *ops;

	ASSERT_RTNL();

	ops = lookup_rules_ops(net, family);
	if (!ops)
		return 0;
	fib_rules_seq = ops->fib_rules_seq;
	rules_ops_put(ops);

	return fib_rules_seq;
}
EXPORT_SYMBOL_GPL(fib_rules_seq_read);

417 418 419 420 421
static struct fib_rule *rule_find(struct fib_rules_ops *ops,
				  struct fib_rule_hdr *frh,
				  struct nlattr **tb,
				  struct fib_rule *rule,
				  bool user_priority)
422 423 424 425
{
	struct fib_rule *r;

	list_for_each_entry(r, &ops->rules_list, list) {
426
		if (rule->action && r->action != rule->action)
427 428
			continue;

429
		if (rule->table && r->table != rule->table)
430 431
			continue;

432
		if (user_priority && r->pref != rule->pref)
433 434
			continue;

435 436
		if (rule->iifname[0] &&
		    memcmp(r->iifname, rule->iifname, IFNAMSIZ))
437 438
			continue;

439 440
		if (rule->oifname[0] &&
		    memcmp(r->oifname, rule->oifname, IFNAMSIZ))
441 442
			continue;

443
		if (rule->mark && r->mark != rule->mark)
444 445
			continue;

446 447 448 449 450 451 452 453
		if (rule->suppress_ifgroup != -1 &&
		    r->suppress_ifgroup != rule->suppress_ifgroup)
			continue;

		if (rule->suppress_prefixlen != -1 &&
		    r->suppress_prefixlen != rule->suppress_prefixlen)
			continue;

454
		if (rule->mark_mask && r->mark_mask != rule->mark_mask)
455 456
			continue;

457
		if (rule->tun_id && r->tun_id != rule->tun_id)
458 459 460 461 462
			continue;

		if (r->fr_net != rule->fr_net)
			continue;

463
		if (rule->l3mdev && r->l3mdev != rule->l3mdev)
464 465
			continue;

466 467 468
		if (uid_range_set(&rule->uid_range) &&
		    (!uid_eq(r->uid_range.start, rule->uid_range.start) ||
		    !uid_eq(r->uid_range.end, rule->uid_range.end)))
469 470
			continue;

471
		if (rule->ip_proto && r->ip_proto != rule->ip_proto)
472 473
			continue;

474 475 476
		if (rule->proto && r->proto != rule->proto)
			continue;

477 478
		if (fib_rule_port_range_set(&rule->sport_range) &&
		    !fib_rule_port_range_compare(&r->sport_range,
479 480 481
						 &rule->sport_range))
			continue;

482 483
		if (fib_rule_port_range_set(&rule->dport_range) &&
		    !fib_rule_port_range_compare(&r->dport_range,
484 485 486
						 &rule->dport_range))
			continue;

487 488
		if (!ops->compare(r, frh, tb))
			continue;
489
		return r;
490
	}
491 492

	return NULL;
493 494
}

495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515
#ifdef CONFIG_NET_L3_MASTER_DEV
static int fib_nl2rule_l3mdev(struct nlattr *nla, struct fib_rule *nlrule,
			      struct netlink_ext_ack *extack)
{
	nlrule->l3mdev = nla_get_u8(nla);
	if (nlrule->l3mdev != 1) {
		NL_SET_ERR_MSG(extack, "Invalid l3mdev attribute");
		return -1;
	}

	return 0;
}
#else
static int fib_nl2rule_l3mdev(struct nlattr *nla, struct fib_rule *nlrule,
			      struct netlink_ext_ack *extack)
{
	NL_SET_ERR_MSG(extack, "l3mdev support is not enabled in kernel");
	return -1;
}
#endif

516 517 518 519 520 521
static int fib_nl2rule(struct sk_buff *skb, struct nlmsghdr *nlh,
		       struct netlink_ext_ack *extack,
		       struct fib_rules_ops *ops,
		       struct nlattr *tb[],
		       struct fib_rule **rule,
		       bool *user_priority)
522
{
523
	struct net *net = sock_net(skb->sk);
524
	struct fib_rule_hdr *frh = nlmsg_data(nlh);
525 526
	struct fib_rule *nlrule = NULL;
	int err = -EINVAL;
527

528 529 530
	if (frh->src_len)
		if (!tb[FRA_SRC] ||
		    frh->src_len > (ops->addr_size * 8) ||
531 532
		    nla_len(tb[FRA_SRC]) != ops->addr_size) {
			NL_SET_ERR_MSG(extack, "Invalid source address");
533
			goto errout;
534
	}
535

536 537 538
	if (frh->dst_len)
		if (!tb[FRA_DST] ||
		    frh->dst_len > (ops->addr_size * 8) ||
539 540
		    nla_len(tb[FRA_DST]) != ops->addr_size) {
			NL_SET_ERR_MSG(extack, "Invalid dst address");
541
			goto errout;
542
	}
543

544
	nlrule = kzalloc(ops->rule_size, GFP_KERNEL_ACCOUNT);
545
	if (!nlrule) {
546 547 548
		err = -ENOMEM;
		goto errout;
	}
549 550
	refcount_set(&nlrule->refcnt, 1);
	nlrule->fr_net = net;
551

552 553 554 555 556 557
	if (tb[FRA_PRIORITY]) {
		nlrule->pref = nla_get_u32(tb[FRA_PRIORITY]);
		*user_priority = true;
	} else {
		nlrule->pref = fib_default_rule_pref(ops);
	}
558

559
	nlrule->proto = tb[FRA_PROTOCOL] ?
560 561
		nla_get_u8(tb[FRA_PROTOCOL]) : RTPROT_UNSPEC;

562
	if (tb[FRA_IIFNAME]) {
563 564
		struct net_device *dev;

565
		nlrule->iifindex = -1;
566
		nla_strscpy(nlrule->iifname, tb[FRA_IIFNAME], IFNAMSIZ);
567
		dev = __dev_get_by_name(net, nlrule->iifname);
568
		if (dev)
569
			nlrule->iifindex = dev->ifindex;
570 571
	}

572 573 574
	if (tb[FRA_OIFNAME]) {
		struct net_device *dev;

575
		nlrule->oifindex = -1;
576
		nla_strscpy(nlrule->oifname, tb[FRA_OIFNAME], IFNAMSIZ);
577
		dev = __dev_get_by_name(net, nlrule->oifname);
578
		if (dev)
579
			nlrule->oifindex = dev->ifindex;
580 581
	}

582
	if (tb[FRA_FWMARK]) {
583 584
		nlrule->mark = nla_get_u32(tb[FRA_FWMARK]);
		if (nlrule->mark)
585 586 587
			/* compatibility: if the mark value is non-zero all bits
			 * are compared unless a mask is explicitly specified.
			 */
588
			nlrule->mark_mask = 0xFFFFFFFF;
589 590 591
	}

	if (tb[FRA_FWMASK])
592
		nlrule->mark_mask = nla_get_u32(tb[FRA_FWMASK]);
593

594
	if (tb[FRA_TUN_ID])
595
		nlrule->tun_id = nla_get_be64(tb[FRA_TUN_ID]);
596

W
Wei Yongjun 已提交
597
	err = -EINVAL;
598 599 600
	if (tb[FRA_L3MDEV] &&
	    fib_nl2rule_l3mdev(tb[FRA_L3MDEV], nlrule, extack) < 0)
		goto errout_free;
D
David Ahern 已提交
601

602 603 604
	nlrule->action = frh->action;
	nlrule->flags = frh->flags;
	nlrule->table = frh_get_table(frh, tb);
605
	if (tb[FRA_SUPPRESS_PREFIXLEN])
606
		nlrule->suppress_prefixlen = nla_get_u32(tb[FRA_SUPPRESS_PREFIXLEN]);
607
	else
608
		nlrule->suppress_prefixlen = -1;
609

610
	if (tb[FRA_SUPPRESS_IFGROUP])
611
		nlrule->suppress_ifgroup = nla_get_u32(tb[FRA_SUPPRESS_IFGROUP]);
612
	else
613
		nlrule->suppress_ifgroup = -1;
614

T
Thomas Graf 已提交
615
	if (tb[FRA_GOTO]) {
616 617
		if (nlrule->action != FR_ACT_GOTO) {
			NL_SET_ERR_MSG(extack, "Unexpected goto");
T
Thomas Graf 已提交
618
			goto errout_free;
619
		}
T
Thomas Graf 已提交
620

621
		nlrule->target = nla_get_u32(tb[FRA_GOTO]);
T
Thomas Graf 已提交
622
		/* Backward jumps are prohibited to avoid endless loops */
623 624
		if (nlrule->target <= nlrule->pref) {
			NL_SET_ERR_MSG(extack, "Backward goto not supported");
T
Thomas Graf 已提交
625
			goto errout_free;
626
		}
627
	} else if (nlrule->action == FR_ACT_GOTO) {
628
		NL_SET_ERR_MSG(extack, "Missing goto target for action goto");
T
Thomas Graf 已提交
629
		goto errout_free;
630
	}
T
Thomas Graf 已提交
631

632 633
	if (nlrule->l3mdev && nlrule->table) {
		NL_SET_ERR_MSG(extack, "l3mdev and table are mutually exclusive");
D
David Ahern 已提交
634
		goto errout_free;
635
	}
D
David Ahern 已提交
636

637 638 639
	if (tb[FRA_UID_RANGE]) {
		if (current_user_ns() != net->user_ns) {
			err = -EPERM;
640
			NL_SET_ERR_MSG(extack, "No permission to set uid");
641 642 643
			goto errout_free;
		}

644
		nlrule->uid_range = nla_get_kuid_range(tb);
645

646
		if (!uid_range_set(&nlrule->uid_range) ||
647 648
		    !uid_lte(nlrule->uid_range.start, nlrule->uid_range.end)) {
			NL_SET_ERR_MSG(extack, "Invalid uid range");
649
			goto errout_free;
650
		}
651
	} else {
652
		nlrule->uid_range = fib_kuid_range_unset;
653 654
	}

655
	if (tb[FRA_IP_PROTO])
656
		nlrule->ip_proto = nla_get_u8(tb[FRA_IP_PROTO]);
657 658 659

	if (tb[FRA_SPORT_RANGE]) {
		err = nla_get_port_range(tb[FRA_SPORT_RANGE],
660
					 &nlrule->sport_range);
661 662
		if (err) {
			NL_SET_ERR_MSG(extack, "Invalid sport range");
663
			goto errout_free;
664
		}
665 666 667 668
	}

	if (tb[FRA_DPORT_RANGE]) {
		err = nla_get_port_range(tb[FRA_DPORT_RANGE],
669
					 &nlrule->dport_range);
670 671
		if (err) {
			NL_SET_ERR_MSG(extack, "Invalid dport range");
672
			goto errout_free;
673
		}
674 675
	}

676 677 678 679 680 681 682 683 684 685
	*rule = nlrule;

	return 0;

errout_free:
	kfree(nlrule);
errout:
	return err;
}

686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752
static int rule_exists(struct fib_rules_ops *ops, struct fib_rule_hdr *frh,
		       struct nlattr **tb, struct fib_rule *rule)
{
	struct fib_rule *r;

	list_for_each_entry(r, &ops->rules_list, list) {
		if (r->action != rule->action)
			continue;

		if (r->table != rule->table)
			continue;

		if (r->pref != rule->pref)
			continue;

		if (memcmp(r->iifname, rule->iifname, IFNAMSIZ))
			continue;

		if (memcmp(r->oifname, rule->oifname, IFNAMSIZ))
			continue;

		if (r->mark != rule->mark)
			continue;

		if (r->suppress_ifgroup != rule->suppress_ifgroup)
			continue;

		if (r->suppress_prefixlen != rule->suppress_prefixlen)
			continue;

		if (r->mark_mask != rule->mark_mask)
			continue;

		if (r->tun_id != rule->tun_id)
			continue;

		if (r->fr_net != rule->fr_net)
			continue;

		if (r->l3mdev != rule->l3mdev)
			continue;

		if (!uid_eq(r->uid_range.start, rule->uid_range.start) ||
		    !uid_eq(r->uid_range.end, rule->uid_range.end))
			continue;

		if (r->ip_proto != rule->ip_proto)
			continue;

		if (r->proto != rule->proto)
			continue;

		if (!fib_rule_port_range_compare(&r->sport_range,
						 &rule->sport_range))
			continue;

		if (!fib_rule_port_range_compare(&r->dport_range,
						 &rule->dport_range))
			continue;

		if (!ops->compare(r, frh, tb))
			continue;
		return 1;
	}
	return 0;
}

753 754 755 756 757
static const struct nla_policy fib_rule_policy[FRA_MAX + 1] = {
	FRA_GENERIC_POLICY,
	[FRA_FLOW]	= { .type = NLA_U32 },
};

758 759 760 761 762 763 764 765 766 767 768
int fib_nl_newrule(struct sk_buff *skb, struct nlmsghdr *nlh,
		   struct netlink_ext_ack *extack)
{
	struct net *net = sock_net(skb->sk);
	struct fib_rule_hdr *frh = nlmsg_data(nlh);
	struct fib_rules_ops *ops = NULL;
	struct fib_rule *rule = NULL, *r, *last = NULL;
	struct nlattr *tb[FRA_MAX + 1];
	int err = -EINVAL, unresolved = 0;
	bool user_priority = false;

769 770
	if (nlh->nlmsg_len < nlmsg_msg_size(sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid msg length");
771
		goto errout;
772
	}
773 774 775 776

	ops = lookup_rules_ops(net, frh->family);
	if (!ops) {
		err = -EAFNOSUPPORT;
777
		NL_SET_ERR_MSG(extack, "Rule family not supported");
778 779 780
		goto errout;
	}

781
	err = nlmsg_parse_deprecated(nlh, sizeof(*frh), tb, FRA_MAX,
782
				     fib_rule_policy, extack);
783 784
	if (err < 0) {
		NL_SET_ERR_MSG(extack, "Error parsing msg");
785
		goto errout;
786
	}
787 788 789 790 791

	err = fib_nl2rule(skb, nlh, extack, ops, tb, &rule, &user_priority);
	if (err)
		goto errout;

792 793 794
	if ((nlh->nlmsg_flags & NLM_F_EXCL) &&
	    rule_exists(ops, frh, tb, rule)) {
		err = -EEXIST;
795 796 797
		goto errout_free;
	}

798
	err = ops->configure(rule, skb, frh, tb, extack);
799 800 801
	if (err < 0)
		goto errout_free;

802 803 804 805 806
	err = call_fib_rule_notifiers(net, FIB_EVENT_RULE_ADD, rule, ops,
				      extack);
	if (err < 0)
		goto errout_free;

807 808 809 810 811 812 813 814 815 816
	list_for_each_entry(r, &ops->rules_list, list) {
		if (r->pref == rule->target) {
			RCU_INIT_POINTER(rule->ctarget, r);
			break;
		}
	}

	if (rcu_dereference_protected(rule->ctarget, 1) == NULL)
		unresolved = 1;

817
	list_for_each_entry(r, &ops->rules_list, list) {
818 819 820 821 822
		if (r->pref > rule->pref)
			break;
		last = r;
	}

E
Eric Dumazet 已提交
823 824 825 826 827
	if (last)
		list_add_rcu(&rule->list, &last->list);
	else
		list_add_rcu(&rule->list, &ops->rules_list);

T
Thomas Graf 已提交
828 829 830 831 832
	if (ops->unresolved_rules) {
		/*
		 * There are unresolved goto rules in the list, check if
		 * any of them are pointing to this new rule.
		 */
833
		list_for_each_entry(r, &ops->rules_list, list) {
T
Thomas Graf 已提交
834
			if (r->action == FR_ACT_GOTO &&
835 836
			    r->target == rule->pref &&
			    rtnl_dereference(r->ctarget) == NULL) {
T
Thomas Graf 已提交
837 838 839 840 841 842 843 844 845 846 847 848 849
				rcu_assign_pointer(r->ctarget, rule);
				if (--ops->unresolved_rules == 0)
					break;
			}
		}
	}

	if (rule->action == FR_ACT_GOTO)
		ops->nr_goto_rules++;

	if (unresolved)
		ops->unresolved_rules++;

850 851 852
	if (rule->tun_id)
		ip_tunnel_need_metadata();

853
	notify_rule_change(RTM_NEWRULE, rule, ops, nlh, NETLINK_CB(skb).portid);
854
	flush_route_cache(ops);
855 856 857 858 859 860 861 862 863
	rules_ops_put(ops);
	return 0;

errout_free:
	kfree(rule);
errout:
	rules_ops_put(ops);
	return err;
}
D
David Ahern 已提交
864
EXPORT_SYMBOL_GPL(fib_nl_newrule);
865

866 867
int fib_nl_delrule(struct sk_buff *skb, struct nlmsghdr *nlh,
		   struct netlink_ext_ack *extack)
868
{
869
	struct net *net = sock_net(skb->sk);
870 871
	struct fib_rule_hdr *frh = nlmsg_data(nlh);
	struct fib_rules_ops *ops = NULL;
872
	struct fib_rule *rule = NULL, *r, *nlrule = NULL;
873 874
	struct nlattr *tb[FRA_MAX+1];
	int err = -EINVAL;
875
	bool user_priority = false;
876

877 878
	if (nlh->nlmsg_len < nlmsg_msg_size(sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid msg length");
879
		goto errout;
880
	}
881

882
	ops = lookup_rules_ops(net, frh->family);
883
	if (ops == NULL) {
884
		err = -EAFNOSUPPORT;
885
		NL_SET_ERR_MSG(extack, "Rule family not supported");
886 887 888
		goto errout;
	}

889
	err = nlmsg_parse_deprecated(nlh, sizeof(*frh), tb, FRA_MAX,
890
				     fib_rule_policy, extack);
891 892
	if (err < 0) {
		NL_SET_ERR_MSG(extack, "Error parsing msg");
893
		goto errout;
894
	}
895

896 897
	err = fib_nl2rule(skb, nlh, extack, ops, tb, &nlrule, &user_priority);
	if (err)
898 899
		goto errout;

900 901 902 903
	rule = rule_find(ops, frh, tb, nlrule, user_priority);
	if (!rule) {
		err = -ENOENT;
		goto errout;
904 905
	}

906 907 908
	if (rule->flags & FIB_RULE_PERMANENT) {
		err = -EPERM;
		goto errout;
909 910
	}

911 912
	if (ops->delete) {
		err = ops->delete(rule);
913 914 915 916
		if (err)
			goto errout;
	}

917 918
	if (rule->tun_id)
		ip_tunnel_unneed_metadata();
919

920
	list_del_rcu(&rule->list);
921

922 923 924 925 926
	if (rule->action == FR_ACT_GOTO) {
		ops->nr_goto_rules--;
		if (rtnl_dereference(rule->ctarget) == NULL)
			ops->unresolved_rules--;
	}
T
Thomas Graf 已提交
927

928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946
	/*
	 * Check if this rule is a target to any of them. If so,
	 * adjust to the next one with the same preference or
	 * disable them. As this operation is eventually very
	 * expensive, it is only performed if goto rules, except
	 * current if it is goto rule, have actually been added.
	 */
	if (ops->nr_goto_rules > 0) {
		struct fib_rule *n;

		n = list_next_entry(rule, list);
		if (&n->list == &ops->rules_list || n->pref != rule->pref)
			n = NULL;
		list_for_each_entry(r, &ops->rules_list, list) {
			if (rtnl_dereference(r->ctarget) != rule)
				continue;
			rcu_assign_pointer(r->ctarget, n);
			if (!n)
				ops->unresolved_rules++;
T
Thomas Graf 已提交
947
		}
948 949
	}

950 951 952 953 954 955 956 957 958 959
	call_fib_rule_notifiers(net, FIB_EVENT_RULE_DEL, rule, ops,
				NULL);
	notify_rule_change(RTM_DELRULE, rule, ops, nlh,
			   NETLINK_CB(skb).portid);
	fib_rule_put(rule);
	flush_route_cache(ops);
	rules_ops_put(ops);
	kfree(nlrule);
	return 0;

960
errout:
961
	kfree(nlrule);
962 963 964
	rules_ops_put(ops);
	return err;
}
D
David Ahern 已提交
965
EXPORT_SYMBOL_GPL(fib_nl_delrule);
966

967 968 969 970
static inline size_t fib_rule_nlmsg_size(struct fib_rules_ops *ops,
					 struct fib_rule *rule)
{
	size_t payload = NLMSG_ALIGN(sizeof(struct fib_rule_hdr))
971
			 + nla_total_size(IFNAMSIZ) /* FRA_IIFNAME */
972
			 + nla_total_size(IFNAMSIZ) /* FRA_OIFNAME */
973 974
			 + nla_total_size(4) /* FRA_PRIORITY */
			 + nla_total_size(4) /* FRA_TABLE */
975
			 + nla_total_size(4) /* FRA_SUPPRESS_PREFIXLEN */
976
			 + nla_total_size(4) /* FRA_SUPPRESS_IFGROUP */
977
			 + nla_total_size(4) /* FRA_FWMARK */
978
			 + nla_total_size(4) /* FRA_FWMASK */
979
			 + nla_total_size_64bit(8) /* FRA_TUN_ID */
980
			 + nla_total_size(sizeof(struct fib_kuid_range))
981 982 983 984
			 + nla_total_size(1) /* FRA_PROTOCOL */
			 + nla_total_size(1) /* FRA_IP_PROTO */
			 + nla_total_size(sizeof(struct fib_rule_port_range)) /* FRA_SPORT_RANGE */
			 + nla_total_size(sizeof(struct fib_rule_port_range)); /* FRA_DPORT_RANGE */
985 986 987 988 989 990 991

	if (ops->nlmsg_payload)
		payload += ops->nlmsg_payload(rule);

	return payload;
}

992 993 994 995 996 997 998 999 1000
static int fib_nl_fill_rule(struct sk_buff *skb, struct fib_rule *rule,
			    u32 pid, u32 seq, int type, int flags,
			    struct fib_rules_ops *ops)
{
	struct nlmsghdr *nlh;
	struct fib_rule_hdr *frh;

	nlh = nlmsg_put(skb, pid, seq, type, sizeof(*frh), flags);
	if (nlh == NULL)
1001
		return -EMSGSIZE;
1002 1003

	frh = nlmsg_data(nlh);
1004
	frh->family = ops->family;
1005
	frh->table = rule->table < 256 ? rule->table : RT_TABLE_COMPAT;
1006 1007
	if (nla_put_u32(skb, FRA_TABLE, rule->table))
		goto nla_put_failure;
1008
	if (nla_put_u32(skb, FRA_SUPPRESS_PREFIXLEN, rule->suppress_prefixlen))
1009
		goto nla_put_failure;
1010
	frh->res1 = 0;
1011
	frh->res2 = 0;
1012 1013
	frh->action = rule->action;
	frh->flags = rule->flags;
1014 1015 1016

	if (nla_put_u8(skb, FRA_PROTOCOL, rule->proto))
		goto nla_put_failure;
1017

E
Eric Dumazet 已提交
1018
	if (rule->action == FR_ACT_GOTO &&
1019
	    rcu_access_pointer(rule->ctarget) == NULL)
T
Thomas Graf 已提交
1020 1021
		frh->flags |= FIB_RULE_UNRESOLVED;

1022
	if (rule->iifname[0]) {
1023 1024
		if (nla_put_string(skb, FRA_IIFNAME, rule->iifname))
			goto nla_put_failure;
1025 1026
		if (rule->iifindex == -1)
			frh->flags |= FIB_RULE_IIF_DETACHED;
1027 1028
	}

1029
	if (rule->oifname[0]) {
1030 1031
		if (nla_put_string(skb, FRA_OIFNAME, rule->oifname))
			goto nla_put_failure;
1032 1033 1034 1035
		if (rule->oifindex == -1)
			frh->flags |= FIB_RULE_OIF_DETACHED;
	}

1036 1037 1038 1039 1040 1041 1042
	if ((rule->pref &&
	     nla_put_u32(skb, FRA_PRIORITY, rule->pref)) ||
	    (rule->mark &&
	     nla_put_u32(skb, FRA_FWMARK, rule->mark)) ||
	    ((rule->mark_mask || rule->mark) &&
	     nla_put_u32(skb, FRA_FWMASK, rule->mark_mask)) ||
	    (rule->target &&
1043 1044
	     nla_put_u32(skb, FRA_GOTO, rule->target)) ||
	    (rule->tun_id &&
D
David Ahern 已提交
1045 1046
	     nla_put_be64(skb, FRA_TUN_ID, rule->tun_id, FRA_PAD)) ||
	    (rule->l3mdev &&
1047 1048
	     nla_put_u8(skb, FRA_L3MDEV, rule->l3mdev)) ||
	    (uid_range_set(&rule->uid_range) &&
1049 1050 1051 1052 1053 1054
	     nla_put_uid_range(skb, &rule->uid_range)) ||
	    (fib_rule_port_range_set(&rule->sport_range) &&
	     nla_put_port_range(skb, FRA_SPORT_RANGE, &rule->sport_range)) ||
	    (fib_rule_port_range_set(&rule->dport_range) &&
	     nla_put_port_range(skb, FRA_DPORT_RANGE, &rule->dport_range)) ||
	    (rule->ip_proto && nla_put_u8(skb, FRA_IP_PROTO, rule->ip_proto)))
1055
		goto nla_put_failure;
1056 1057 1058 1059 1060 1061

	if (rule->suppress_ifgroup != -1) {
		if (nla_put_u32(skb, FRA_SUPPRESS_IFGROUP, rule->suppress_ifgroup))
			goto nla_put_failure;
	}

1062
	if (ops->fill(rule, skb, frh) < 0)
1063 1064
		goto nla_put_failure;

1065 1066
	nlmsg_end(skb, nlh);
	return 0;
1067 1068

nla_put_failure:
1069 1070
	nlmsg_cancel(skb, nlh);
	return -EMSGSIZE;
1071 1072
}

T
Thomas Graf 已提交
1073 1074
static int dump_rules(struct sk_buff *skb, struct netlink_callback *cb,
		      struct fib_rules_ops *ops)
1075 1076 1077
{
	int idx = 0;
	struct fib_rule *rule;
1078
	int err = 0;
1079

1080 1081
	rcu_read_lock();
	list_for_each_entry_rcu(rule, &ops->rules_list, list) {
T
Thomas Graf 已提交
1082
		if (idx < cb->args[1])
1083 1084
			goto skip;

1085 1086 1087 1088
		err = fib_nl_fill_rule(skb, rule, NETLINK_CB(cb->skb).portid,
				       cb->nlh->nlmsg_seq, RTM_NEWRULE,
				       NLM_F_MULTI, ops);
		if (err)
1089 1090 1091 1092
			break;
skip:
		idx++;
	}
1093
	rcu_read_unlock();
T
Thomas Graf 已提交
1094
	cb->args[1] = idx;
1095 1096
	rules_ops_put(ops);

1097
	return err;
1098 1099
}

1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125
static int fib_valid_dumprule_req(const struct nlmsghdr *nlh,
				   struct netlink_ext_ack *extack)
{
	struct fib_rule_hdr *frh;

	if (nlh->nlmsg_len < nlmsg_msg_size(sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid header for fib rule dump request");
		return -EINVAL;
	}

	frh = nlmsg_data(nlh);
	if (frh->dst_len || frh->src_len || frh->tos || frh->table ||
	    frh->res1 || frh->res2 || frh->action || frh->flags) {
		NL_SET_ERR_MSG(extack,
			       "Invalid values in header for fib rule dump request");
		return -EINVAL;
	}

	if (nlmsg_attrlen(nlh, sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid data after header in fib rule dump request");
		return -EINVAL;
	}

	return 0;
}

T
Thomas Graf 已提交
1126 1127
static int fib_nl_dumprule(struct sk_buff *skb, struct netlink_callback *cb)
{
1128
	const struct nlmsghdr *nlh = cb->nlh;
1129
	struct net *net = sock_net(skb->sk);
T
Thomas Graf 已提交
1130 1131 1132
	struct fib_rules_ops *ops;
	int idx = 0, family;

1133 1134 1135 1136 1137 1138 1139 1140
	if (cb->strict_check) {
		int err = fib_valid_dumprule_req(nlh, cb->extack);

		if (err < 0)
			return err;
	}

	family = rtnl_msg_family(nlh);
T
Thomas Graf 已提交
1141 1142
	if (family != AF_UNSPEC) {
		/* Protocol specific dump request */
1143
		ops = lookup_rules_ops(net, family);
T
Thomas Graf 已提交
1144 1145 1146
		if (ops == NULL)
			return -EAFNOSUPPORT;

1147 1148 1149
		dump_rules(skb, cb, ops);

		return skb->len;
T
Thomas Graf 已提交
1150 1151 1152
	}

	rcu_read_lock();
1153
	list_for_each_entry_rcu(ops, &net->rules_ops, list) {
T
Thomas Graf 已提交
1154 1155 1156 1157 1158 1159 1160
		if (idx < cb->args[0] || !try_module_get(ops->owner))
			goto skip;

		if (dump_rules(skb, cb, ops) < 0)
			break;

		cb->args[1] = 0;
1161
skip:
T
Thomas Graf 已提交
1162 1163 1164 1165 1166 1167 1168
		idx++;
	}
	rcu_read_unlock();
	cb->args[0] = idx;

	return skb->len;
}
1169

D
Denis V. Lunev 已提交
1170
static void notify_rule_change(int event, struct fib_rule *rule,
1171 1172
			       struct fib_rules_ops *ops, struct nlmsghdr *nlh,
			       u32 pid)
1173
{
D
Denis V. Lunev 已提交
1174
	struct net *net;
1175
	struct sk_buff *skb;
1176
	int err = -ENOMEM;
1177

D
Denis V. Lunev 已提交
1178
	net = ops->fro_net;
1179
	skb = nlmsg_new(fib_rule_nlmsg_size(ops, rule), GFP_KERNEL);
1180
	if (skb == NULL)
1181 1182 1183
		goto errout;

	err = fib_nl_fill_rule(skb, rule, pid, nlh->nlmsg_seq, event, 0, ops);
1184 1185 1186 1187 1188 1189
	if (err < 0) {
		/* -EMSGSIZE implies BUG in fib_rule_nlmsg_size() */
		WARN_ON(err == -EMSGSIZE);
		kfree_skb(skb);
		goto errout;
	}
D
Denis V. Lunev 已提交
1190

1191 1192
	rtnl_notify(skb, net, pid, ops->nlgroup, nlh, GFP_KERNEL);
	return;
1193 1194
errout:
	if (err < 0)
1195
		rtnl_set_sk_err(net, ops->nlgroup, err);
1196 1197 1198 1199 1200 1201 1202
}

static void attach_rules(struct list_head *rules, struct net_device *dev)
{
	struct fib_rule *rule;

	list_for_each_entry(rule, rules, list) {
1203 1204 1205
		if (rule->iifindex == -1 &&
		    strcmp(dev->name, rule->iifname) == 0)
			rule->iifindex = dev->ifindex;
1206 1207 1208
		if (rule->oifindex == -1 &&
		    strcmp(dev->name, rule->oifname) == 0)
			rule->oifindex = dev->ifindex;
1209 1210 1211 1212 1213 1214 1215
	}
}

static void detach_rules(struct list_head *rules, struct net_device *dev)
{
	struct fib_rule *rule;

1216
	list_for_each_entry(rule, rules, list) {
1217 1218
		if (rule->iifindex == dev->ifindex)
			rule->iifindex = -1;
1219 1220 1221
		if (rule->oifindex == dev->ifindex)
			rule->oifindex = -1;
	}
1222 1223 1224 1225
}


static int fib_rules_event(struct notifier_block *this, unsigned long event,
1226
			   void *ptr)
1227
{
1228
	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
1229
	struct net *net = dev_net(dev);
1230 1231
	struct fib_rules_ops *ops;

1232
	ASSERT_RTNL();
1233 1234 1235

	switch (event) {
	case NETDEV_REGISTER:
1236
		list_for_each_entry(ops, &net->rules_ops, list)
1237
			attach_rules(&ops->rules_list, dev);
1238 1239
		break;

1240 1241 1242 1243 1244 1245 1246
	case NETDEV_CHANGENAME:
		list_for_each_entry(ops, &net->rules_ops, list) {
			detach_rules(&ops->rules_list, dev);
			attach_rules(&ops->rules_list, dev);
		}
		break;

1247
	case NETDEV_UNREGISTER:
1248
		list_for_each_entry(ops, &net->rules_ops, list)
1249
			detach_rules(&ops->rules_list, dev);
1250 1251 1252 1253 1254 1255 1256 1257 1258 1259
		break;
	}

	return NOTIFY_DONE;
}

static struct notifier_block fib_rules_notifier = {
	.notifier_call = fib_rules_event,
};

1260
static int __net_init fib_rules_net_init(struct net *net)
1261 1262 1263 1264 1265 1266
{
	INIT_LIST_HEAD(&net->rules_ops);
	spin_lock_init(&net->rules_mod_lock);
	return 0;
}

1267 1268 1269 1270 1271
static void __net_exit fib_rules_net_exit(struct net *net)
{
	WARN_ON_ONCE(!list_empty(&net->rules_ops));
}

1272 1273
static struct pernet_operations fib_rules_net_ops = {
	.init = fib_rules_net_init,
1274
	.exit = fib_rules_net_exit,
1275 1276
};

1277 1278
static int __init fib_rules_init(void)
{
1279
	int err;
1280 1281 1282
	rtnl_register(PF_UNSPEC, RTM_NEWRULE, fib_nl_newrule, NULL, 0);
	rtnl_register(PF_UNSPEC, RTM_DELRULE, fib_nl_delrule, NULL, 0);
	rtnl_register(PF_UNSPEC, RTM_GETRULE, NULL, fib_nl_dumprule, 0);
1283

E
Eric W. Biederman 已提交
1284
	err = register_pernet_subsys(&fib_rules_net_ops);
1285 1286 1287
	if (err < 0)
		goto fail;

E
Eric W. Biederman 已提交
1288
	err = register_netdevice_notifier(&fib_rules_notifier);
1289 1290
	if (err < 0)
		goto fail_unregister;
E
Eric W. Biederman 已提交
1291

1292 1293 1294
	return 0;

fail_unregister:
E
Eric W. Biederman 已提交
1295
	unregister_pernet_subsys(&fib_rules_net_ops);
1296 1297 1298 1299 1300
fail:
	rtnl_unregister(PF_UNSPEC, RTM_NEWRULE);
	rtnl_unregister(PF_UNSPEC, RTM_DELRULE);
	rtnl_unregister(PF_UNSPEC, RTM_GETRULE);
	return err;
1301 1302 1303
}

subsys_initcall(fib_rules_init);