fib_rules.c 30.1 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0-only
2 3 4 5 6 7 8 9
/*
 * net/core/fib_rules.c		Generic Routing Rules
 *
 * Authors:	Thomas Graf <tgraf@suug.ch>
 */

#include <linux/types.h>
#include <linux/kernel.h>
10
#include <linux/slab.h>
11
#include <linux/list.h>
12
#include <linux/module.h>
13
#include <net/net_namespace.h>
14
#include <net/sock.h>
15
#include <net/fib_rules.h>
16
#include <net/ip_tunnels.h>
17
#include <linux/indirect_call_wrapper.h>
18

19
#if defined(CONFIG_IPV6) && defined(CONFIG_IPV6_MULTIPLE_TABLES)
20
#ifdef CONFIG_IP_MULTIPLE_TABLES
21 22 23
#define INDIRECT_CALL_MT(f, f2, f1, ...) \
	INDIRECT_CALL_INET(f, f2, f1, __VA_ARGS__)
#else
24 25
#define INDIRECT_CALL_MT(f, f2, f1, ...) INDIRECT_CALL_1(f, f2, __VA_ARGS__)
#endif
Y
YueHaibing 已提交
26
#elif defined(CONFIG_IP_MULTIPLE_TABLES)
27
#define INDIRECT_CALL_MT(f, f2, f1, ...) INDIRECT_CALL_1(f, f1, __VA_ARGS__)
28 29
#else
#define INDIRECT_CALL_MT(f, f2, f1, ...) f(__VA_ARGS__)
30 31
#endif

32 33 34 35 36
static const struct fib_kuid_range fib_kuid_range_unset = {
	KUIDT_INIT(0),
	KUIDT_INIT(~0),
};

37 38 39 40 41 42 43 44 45 46
bool fib_rule_matchall(const struct fib_rule *rule)
{
	if (rule->iifindex || rule->oifindex || rule->mark || rule->tun_id ||
	    rule->flags)
		return false;
	if (rule->suppress_ifgroup != -1 || rule->suppress_prefixlen != -1)
		return false;
	if (!uid_eq(rule->uid_range.start, fib_kuid_range_unset.start) ||
	    !uid_eq(rule->uid_range.end, fib_kuid_range_unset.end))
		return false;
47 48 49 50
	if (fib_rule_port_range_set(&rule->sport_range))
		return false;
	if (fib_rule_port_range_set(&rule->dport_range))
		return false;
51 52 53 54
	return true;
}
EXPORT_SYMBOL_GPL(fib_rule_matchall);

55 56 57 58 59
int fib_default_rule_add(struct fib_rules_ops *ops,
			 u32 pref, u32 table, u32 flags)
{
	struct fib_rule *r;

60
	r = kzalloc(ops->rule_size, GFP_KERNEL_ACCOUNT);
61 62 63
	if (r == NULL)
		return -ENOMEM;

64
	refcount_set(&r->refcnt, 1);
65 66 67 68
	r->action = FR_ACT_TO_TBL;
	r->pref = pref;
	r->table = table;
	r->flags = flags;
69
	r->proto = RTPROT_KERNEL;
70
	r->fr_net = ops->fro_net;
71
	r->uid_range = fib_kuid_range_unset;
72

73 74 75
	r->suppress_prefixlen = -1;
	r->suppress_ifgroup = -1;

76 77 78 79 80 81 82
	/* The lock is not required here, the list in unreacheable
	 * at the moment this function is called */
	list_add_tail(&r->list, &ops->rules_list);
	return 0;
}
EXPORT_SYMBOL(fib_default_rule_add);

83
static u32 fib_default_rule_pref(struct fib_rules_ops *ops)
84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99
{
	struct list_head *pos;
	struct fib_rule *rule;

	if (!list_empty(&ops->rules_list)) {
		pos = ops->rules_list.next;
		if (pos->next != &ops->rules_list) {
			rule = list_entry(pos->next, struct fib_rule, list);
			if (rule->pref)
				return rule->pref - 1;
		}
	}

	return 0;
}

D
Denis V. Lunev 已提交
100
static void notify_rule_change(int event, struct fib_rule *rule,
101 102
			       struct fib_rules_ops *ops, struct nlmsghdr *nlh,
			       u32 pid);
103

104
static struct fib_rules_ops *lookup_rules_ops(struct net *net, int family)
105 106 107 108
{
	struct fib_rules_ops *ops;

	rcu_read_lock();
109
	list_for_each_entry_rcu(ops, &net->rules_ops, list) {
110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127
		if (ops->family == family) {
			if (!try_module_get(ops->owner))
				ops = NULL;
			rcu_read_unlock();
			return ops;
		}
	}
	rcu_read_unlock();

	return NULL;
}

static void rules_ops_put(struct fib_rules_ops *ops)
{
	if (ops)
		module_put(ops->owner);
}

128 129 130
static void flush_route_cache(struct fib_rules_ops *ops)
{
	if (ops->flush_cache)
131
		ops->flush_cache(ops);
132 133
}

134
static int __fib_rules_register(struct fib_rules_ops *ops)
135 136 137
{
	int err = -EEXIST;
	struct fib_rules_ops *o;
D
Denis V. Lunev 已提交
138 139 140
	struct net *net;

	net = ops->fro_net;
141 142 143 144 145 146 147 148 149

	if (ops->rule_size < sizeof(struct fib_rule))
		return -EINVAL;

	if (ops->match == NULL || ops->configure == NULL ||
	    ops->compare == NULL || ops->fill == NULL ||
	    ops->action == NULL)
		return -EINVAL;

150 151
	spin_lock(&net->rules_mod_lock);
	list_for_each_entry(o, &net->rules_ops, list)
152 153 154
		if (ops->family == o->family)
			goto errout;

155
	list_add_tail_rcu(&ops->list, &net->rules_ops);
156 157
	err = 0;
errout:
158
	spin_unlock(&net->rules_mod_lock);
159 160 161 162

	return err;
}

163
struct fib_rules_ops *
164
fib_rules_register(const struct fib_rules_ops *tmpl, struct net *net)
165 166 167 168
{
	struct fib_rules_ops *ops;
	int err;

169
	ops = kmemdup(tmpl, sizeof(*ops), GFP_KERNEL);
170 171 172 173 174 175 176 177 178 179 180 181 182 183
	if (ops == NULL)
		return ERR_PTR(-ENOMEM);

	INIT_LIST_HEAD(&ops->rules_list);
	ops->fro_net = net;

	err = __fib_rules_register(ops);
	if (err) {
		kfree(ops);
		ops = ERR_PTR(err);
	}

	return ops;
}
184 185
EXPORT_SYMBOL_GPL(fib_rules_register);

186
static void fib_rules_cleanup_ops(struct fib_rules_ops *ops)
187 188 189
{
	struct fib_rule *rule, *tmp;

190
	list_for_each_entry_safe(rule, tmp, &ops->rules_list, list) {
191
		list_del_rcu(&rule->list);
192 193
		if (ops->delete)
			ops->delete(rule);
194 195 196 197
		fib_rule_put(rule);
	}
}

D
Denis V. Lunev 已提交
198
void fib_rules_unregister(struct fib_rules_ops *ops)
199
{
D
Denis V. Lunev 已提交
200
	struct net *net = ops->fro_net;
201

202
	spin_lock(&net->rules_mod_lock);
203
	list_del_rcu(&ops->list);
204
	spin_unlock(&net->rules_mod_lock);
205

206
	fib_rules_cleanup_ops(ops);
207
	kfree_rcu(ops, rcu);
208 209 210
}
EXPORT_SYMBOL_GPL(fib_rules_unregister);

211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238
static int uid_range_set(struct fib_kuid_range *range)
{
	return uid_valid(range->start) && uid_valid(range->end);
}

static struct fib_kuid_range nla_get_kuid_range(struct nlattr **tb)
{
	struct fib_rule_uid_range *in;
	struct fib_kuid_range out;

	in = (struct fib_rule_uid_range *)nla_data(tb[FRA_UID_RANGE]);

	out.start = make_kuid(current_user_ns(), in->start);
	out.end = make_kuid(current_user_ns(), in->end);

	return out;
}

static int nla_put_uid_range(struct sk_buff *skb, struct fib_kuid_range *range)
{
	struct fib_rule_uid_range out = {
		from_kuid_munged(current_user_ns(), range->start),
		from_kuid_munged(current_user_ns(), range->end)
	};

	return nla_put(skb, FRA_UID_RANGE, sizeof(out), &out);
}

239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258
static int nla_get_port_range(struct nlattr *pattr,
			      struct fib_rule_port_range *port_range)
{
	const struct fib_rule_port_range *pr = nla_data(pattr);

	if (!fib_rule_port_range_valid(pr))
		return -EINVAL;

	port_range->start = pr->start;
	port_range->end = pr->end;

	return 0;
}

static int nla_put_port_range(struct sk_buff *skb, int attrtype,
			      struct fib_rule_port_range *range)
{
	return nla_put(skb, attrtype, sizeof(*range), range);
}

259
static int fib_rule_match(struct fib_rule *rule, struct fib_rules_ops *ops,
D
David Ahern 已提交
260 261
			  struct flowi *fl, int flags,
			  struct fib_lookup_arg *arg)
262 263 264
{
	int ret = 0;

265
	if (rule->iifindex && (rule->iifindex != fl->flowi_iif))
266 267
		goto out;

268
	if (rule->oifindex && (rule->oifindex != fl->flowi_oif))
269 270
		goto out;

271
	if ((rule->mark ^ fl->flowi_mark) & rule->mark_mask)
272 273
		goto out;

274 275 276
	if (rule->tun_id && (rule->tun_id != fl->flowi_tun_key.tun_id))
		goto out;

D
David Ahern 已提交
277 278 279
	if (rule->l3mdev && !l3mdev_fib_rule_match(rule->fr_net, fl, arg))
		goto out;

280 281 282 283
	if (uid_lt(fl->flowi_uid, rule->uid_range.start) ||
	    uid_gt(fl->flowi_uid, rule->uid_range.end))
		goto out;

284 285 286 287
	ret = INDIRECT_CALL_MT(ops->match,
			       fib6_rule_match,
			       fib4_rule_match,
			       rule, fl, flags);
288 289 290 291
out:
	return (rule->flags & FIB_RULE_INVERT) ? !ret : ret;
}

292 293 294 295 296 297 298 299
int fib_rules_lookup(struct fib_rules_ops *ops, struct flowi *fl,
		     int flags, struct fib_lookup_arg *arg)
{
	struct fib_rule *rule;
	int err;

	rcu_read_lock();

300
	list_for_each_entry_rcu(rule, &ops->rules_list, list) {
T
Thomas Graf 已提交
301
jumped:
D
David Ahern 已提交
302
		if (!fib_rule_match(rule, ops, fl, flags, arg))
303 304
			continue;

T
Thomas Graf 已提交
305 306 307 308 309 310 311 312 313 314
		if (rule->action == FR_ACT_GOTO) {
			struct fib_rule *target;

			target = rcu_dereference(rule->ctarget);
			if (target == NULL) {
				continue;
			} else {
				rule = target;
				goto jumped;
			}
315 316 317
		} else if (rule->action == FR_ACT_NOP)
			continue;
		else
318 319 320 321 322 323 324 325 326
			err = INDIRECT_CALL_MT(ops->action,
					       fib6_rule_action,
					       fib4_rule_action,
					       rule, fl, flags, arg);

		if (!err && ops->suppress && INDIRECT_CALL_MT(ops->suppress,
							      fib6_rule_suppress,
							      fib4_rule_suppress,
							      rule, arg))
327 328
			continue;

329
		if (err != -EAGAIN) {
E
Eric Dumazet 已提交
330
			if ((arg->flags & FIB_LOOKUP_NOREF) ||
331
			    likely(refcount_inc_not_zero(&rule->refcnt))) {
332 333 334 335
				arg->rule = rule;
				goto out;
			}
			break;
336 337 338
		}
	}

339
	err = -ESRCH;
340 341 342 343 344 345 346
out:
	rcu_read_unlock();

	return err;
}
EXPORT_SYMBOL_GPL(fib_rules_lookup);

347
static int call_fib_rule_notifier(struct notifier_block *nb,
348
				  enum fib_event_type event_type,
349 350
				  struct fib_rule *rule, int family,
				  struct netlink_ext_ack *extack)
351 352 353
{
	struct fib_rule_notifier_info info = {
		.info.family = family,
354
		.info.extack = extack,
355 356 357
		.rule = rule,
	};

358
	return call_fib_notifier(nb, event_type, &info.info);
359 360 361 362 363
}

static int call_fib_rule_notifiers(struct net *net,
				   enum fib_event_type event_type,
				   struct fib_rule *rule,
D
David Ahern 已提交
364 365
				   struct fib_rules_ops *ops,
				   struct netlink_ext_ack *extack)
366 367 368
{
	struct fib_rule_notifier_info info = {
		.info.family = ops->family,
D
David Ahern 已提交
369
		.info.extack = extack,
370 371 372 373 374 375 376 377
		.rule = rule,
	};

	ops->fib_rules_seq++;
	return call_fib_notifiers(net, event_type, &info.info);
}

/* Called with rcu_read_lock() */
378 379
int fib_rules_dump(struct net *net, struct notifier_block *nb, int family,
		   struct netlink_ext_ack *extack)
380 381 382
{
	struct fib_rules_ops *ops;
	struct fib_rule *rule;
383
	int err = 0;
384 385 386 387

	ops = lookup_rules_ops(net, family);
	if (!ops)
		return -EAFNOSUPPORT;
388 389
	list_for_each_entry_rcu(rule, &ops->rules_list, list) {
		err = call_fib_rule_notifier(nb, FIB_EVENT_RULE_ADD,
390
					     rule, family, extack);
391 392 393
		if (err)
			break;
	}
394 395
	rules_ops_put(ops);

396
	return err;
397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416
}
EXPORT_SYMBOL_GPL(fib_rules_dump);

unsigned int fib_rules_seq_read(struct net *net, int family)
{
	unsigned int fib_rules_seq;
	struct fib_rules_ops *ops;

	ASSERT_RTNL();

	ops = lookup_rules_ops(net, family);
	if (!ops)
		return 0;
	fib_rules_seq = ops->fib_rules_seq;
	rules_ops_put(ops);

	return fib_rules_seq;
}
EXPORT_SYMBOL_GPL(fib_rules_seq_read);

417 418 419 420 421
static struct fib_rule *rule_find(struct fib_rules_ops *ops,
				  struct fib_rule_hdr *frh,
				  struct nlattr **tb,
				  struct fib_rule *rule,
				  bool user_priority)
422 423 424 425
{
	struct fib_rule *r;

	list_for_each_entry(r, &ops->rules_list, list) {
426
		if (rule->action && r->action != rule->action)
427 428
			continue;

429
		if (rule->table && r->table != rule->table)
430 431
			continue;

432
		if (user_priority && r->pref != rule->pref)
433 434
			continue;

435 436
		if (rule->iifname[0] &&
		    memcmp(r->iifname, rule->iifname, IFNAMSIZ))
437 438
			continue;

439 440
		if (rule->oifname[0] &&
		    memcmp(r->oifname, rule->oifname, IFNAMSIZ))
441 442
			continue;

443
		if (rule->mark && r->mark != rule->mark)
444 445
			continue;

446 447 448 449 450 451 452 453
		if (rule->suppress_ifgroup != -1 &&
		    r->suppress_ifgroup != rule->suppress_ifgroup)
			continue;

		if (rule->suppress_prefixlen != -1 &&
		    r->suppress_prefixlen != rule->suppress_prefixlen)
			continue;

454
		if (rule->mark_mask && r->mark_mask != rule->mark_mask)
455 456
			continue;

457
		if (rule->tun_id && r->tun_id != rule->tun_id)
458 459 460 461 462
			continue;

		if (r->fr_net != rule->fr_net)
			continue;

463
		if (rule->l3mdev && r->l3mdev != rule->l3mdev)
464 465
			continue;

466 467 468
		if (uid_range_set(&rule->uid_range) &&
		    (!uid_eq(r->uid_range.start, rule->uid_range.start) ||
		    !uid_eq(r->uid_range.end, rule->uid_range.end)))
469 470
			continue;

471
		if (rule->ip_proto && r->ip_proto != rule->ip_proto)
472 473
			continue;

474 475 476
		if (rule->proto && r->proto != rule->proto)
			continue;

477 478
		if (fib_rule_port_range_set(&rule->sport_range) &&
		    !fib_rule_port_range_compare(&r->sport_range,
479 480 481
						 &rule->sport_range))
			continue;

482 483
		if (fib_rule_port_range_set(&rule->dport_range) &&
		    !fib_rule_port_range_compare(&r->dport_range,
484 485 486
						 &rule->dport_range))
			continue;

487 488
		if (!ops->compare(r, frh, tb))
			continue;
489
		return r;
490
	}
491 492

	return NULL;
493 494
}

495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515
#ifdef CONFIG_NET_L3_MASTER_DEV
static int fib_nl2rule_l3mdev(struct nlattr *nla, struct fib_rule *nlrule,
			      struct netlink_ext_ack *extack)
{
	nlrule->l3mdev = nla_get_u8(nla);
	if (nlrule->l3mdev != 1) {
		NL_SET_ERR_MSG(extack, "Invalid l3mdev attribute");
		return -1;
	}

	return 0;
}
#else
static int fib_nl2rule_l3mdev(struct nlattr *nla, struct fib_rule *nlrule,
			      struct netlink_ext_ack *extack)
{
	NL_SET_ERR_MSG(extack, "l3mdev support is not enabled in kernel");
	return -1;
}
#endif

516 517 518 519 520 521
static int fib_nl2rule(struct sk_buff *skb, struct nlmsghdr *nlh,
		       struct netlink_ext_ack *extack,
		       struct fib_rules_ops *ops,
		       struct nlattr *tb[],
		       struct fib_rule **rule,
		       bool *user_priority)
522
{
523
	struct net *net = sock_net(skb->sk);
524
	struct fib_rule_hdr *frh = nlmsg_data(nlh);
525 526
	struct fib_rule *nlrule = NULL;
	int err = -EINVAL;
527

528 529 530
	if (frh->src_len)
		if (!tb[FRA_SRC] ||
		    frh->src_len > (ops->addr_size * 8) ||
531 532
		    nla_len(tb[FRA_SRC]) != ops->addr_size) {
			NL_SET_ERR_MSG(extack, "Invalid source address");
533
			goto errout;
534
	}
535

536 537 538
	if (frh->dst_len)
		if (!tb[FRA_DST] ||
		    frh->dst_len > (ops->addr_size * 8) ||
539 540
		    nla_len(tb[FRA_DST]) != ops->addr_size) {
			NL_SET_ERR_MSG(extack, "Invalid dst address");
541
			goto errout;
542
	}
543

544
	nlrule = kzalloc(ops->rule_size, GFP_KERNEL_ACCOUNT);
545
	if (!nlrule) {
546 547 548
		err = -ENOMEM;
		goto errout;
	}
549 550
	refcount_set(&nlrule->refcnt, 1);
	nlrule->fr_net = net;
551

552 553 554 555 556 557
	if (tb[FRA_PRIORITY]) {
		nlrule->pref = nla_get_u32(tb[FRA_PRIORITY]);
		*user_priority = true;
	} else {
		nlrule->pref = fib_default_rule_pref(ops);
	}
558

559
	nlrule->proto = tb[FRA_PROTOCOL] ?
560 561
		nla_get_u8(tb[FRA_PROTOCOL]) : RTPROT_UNSPEC;

562
	if (tb[FRA_IIFNAME]) {
563 564
		struct net_device *dev;

565
		nlrule->iifindex = -1;
566
		nla_strscpy(nlrule->iifname, tb[FRA_IIFNAME], IFNAMSIZ);
567
		dev = __dev_get_by_name(net, nlrule->iifname);
568
		if (dev)
569
			nlrule->iifindex = dev->ifindex;
570 571
	}

572 573 574
	if (tb[FRA_OIFNAME]) {
		struct net_device *dev;

575
		nlrule->oifindex = -1;
576
		nla_strscpy(nlrule->oifname, tb[FRA_OIFNAME], IFNAMSIZ);
577
		dev = __dev_get_by_name(net, nlrule->oifname);
578
		if (dev)
579
			nlrule->oifindex = dev->ifindex;
580 581
	}

582
	if (tb[FRA_FWMARK]) {
583 584
		nlrule->mark = nla_get_u32(tb[FRA_FWMARK]);
		if (nlrule->mark)
585 586 587
			/* compatibility: if the mark value is non-zero all bits
			 * are compared unless a mask is explicitly specified.
			 */
588
			nlrule->mark_mask = 0xFFFFFFFF;
589 590 591
	}

	if (tb[FRA_FWMASK])
592
		nlrule->mark_mask = nla_get_u32(tb[FRA_FWMASK]);
593

594
	if (tb[FRA_TUN_ID])
595
		nlrule->tun_id = nla_get_be64(tb[FRA_TUN_ID]);
596

W
Wei Yongjun 已提交
597
	err = -EINVAL;
598 599 600
	if (tb[FRA_L3MDEV] &&
	    fib_nl2rule_l3mdev(tb[FRA_L3MDEV], nlrule, extack) < 0)
		goto errout_free;
D
David Ahern 已提交
601

602 603 604
	nlrule->action = frh->action;
	nlrule->flags = frh->flags;
	nlrule->table = frh_get_table(frh, tb);
605
	if (tb[FRA_SUPPRESS_PREFIXLEN])
606
		nlrule->suppress_prefixlen = nla_get_u32(tb[FRA_SUPPRESS_PREFIXLEN]);
607
	else
608
		nlrule->suppress_prefixlen = -1;
609

610
	if (tb[FRA_SUPPRESS_IFGROUP])
611
		nlrule->suppress_ifgroup = nla_get_u32(tb[FRA_SUPPRESS_IFGROUP]);
612
	else
613
		nlrule->suppress_ifgroup = -1;
614

T
Thomas Graf 已提交
615
	if (tb[FRA_GOTO]) {
616 617
		if (nlrule->action != FR_ACT_GOTO) {
			NL_SET_ERR_MSG(extack, "Unexpected goto");
T
Thomas Graf 已提交
618
			goto errout_free;
619
		}
T
Thomas Graf 已提交
620

621
		nlrule->target = nla_get_u32(tb[FRA_GOTO]);
T
Thomas Graf 已提交
622
		/* Backward jumps are prohibited to avoid endless loops */
623 624
		if (nlrule->target <= nlrule->pref) {
			NL_SET_ERR_MSG(extack, "Backward goto not supported");
T
Thomas Graf 已提交
625
			goto errout_free;
626
		}
627
	} else if (nlrule->action == FR_ACT_GOTO) {
628
		NL_SET_ERR_MSG(extack, "Missing goto target for action goto");
T
Thomas Graf 已提交
629
		goto errout_free;
630
	}
T
Thomas Graf 已提交
631

632 633
	if (nlrule->l3mdev && nlrule->table) {
		NL_SET_ERR_MSG(extack, "l3mdev and table are mutually exclusive");
D
David Ahern 已提交
634
		goto errout_free;
635
	}
D
David Ahern 已提交
636

637 638 639
	if (tb[FRA_UID_RANGE]) {
		if (current_user_ns() != net->user_ns) {
			err = -EPERM;
640
			NL_SET_ERR_MSG(extack, "No permission to set uid");
641 642 643
			goto errout_free;
		}

644
		nlrule->uid_range = nla_get_kuid_range(tb);
645

646
		if (!uid_range_set(&nlrule->uid_range) ||
647 648
		    !uid_lte(nlrule->uid_range.start, nlrule->uid_range.end)) {
			NL_SET_ERR_MSG(extack, "Invalid uid range");
649
			goto errout_free;
650
		}
651
	} else {
652
		nlrule->uid_range = fib_kuid_range_unset;
653 654
	}

655
	if (tb[FRA_IP_PROTO])
656
		nlrule->ip_proto = nla_get_u8(tb[FRA_IP_PROTO]);
657 658 659

	if (tb[FRA_SPORT_RANGE]) {
		err = nla_get_port_range(tb[FRA_SPORT_RANGE],
660
					 &nlrule->sport_range);
661 662
		if (err) {
			NL_SET_ERR_MSG(extack, "Invalid sport range");
663
			goto errout_free;
664
		}
665 666 667 668
	}

	if (tb[FRA_DPORT_RANGE]) {
		err = nla_get_port_range(tb[FRA_DPORT_RANGE],
669
					 &nlrule->dport_range);
670 671
		if (err) {
			NL_SET_ERR_MSG(extack, "Invalid dport range");
672
			goto errout_free;
673
		}
674 675
	}

676 677 678 679 680 681 682 683 684 685
	*rule = nlrule;

	return 0;

errout_free:
	kfree(nlrule);
errout:
	return err;
}

686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752
static int rule_exists(struct fib_rules_ops *ops, struct fib_rule_hdr *frh,
		       struct nlattr **tb, struct fib_rule *rule)
{
	struct fib_rule *r;

	list_for_each_entry(r, &ops->rules_list, list) {
		if (r->action != rule->action)
			continue;

		if (r->table != rule->table)
			continue;

		if (r->pref != rule->pref)
			continue;

		if (memcmp(r->iifname, rule->iifname, IFNAMSIZ))
			continue;

		if (memcmp(r->oifname, rule->oifname, IFNAMSIZ))
			continue;

		if (r->mark != rule->mark)
			continue;

		if (r->suppress_ifgroup != rule->suppress_ifgroup)
			continue;

		if (r->suppress_prefixlen != rule->suppress_prefixlen)
			continue;

		if (r->mark_mask != rule->mark_mask)
			continue;

		if (r->tun_id != rule->tun_id)
			continue;

		if (r->fr_net != rule->fr_net)
			continue;

		if (r->l3mdev != rule->l3mdev)
			continue;

		if (!uid_eq(r->uid_range.start, rule->uid_range.start) ||
		    !uid_eq(r->uid_range.end, rule->uid_range.end))
			continue;

		if (r->ip_proto != rule->ip_proto)
			continue;

		if (r->proto != rule->proto)
			continue;

		if (!fib_rule_port_range_compare(&r->sport_range,
						 &rule->sport_range))
			continue;

		if (!fib_rule_port_range_compare(&r->dport_range,
						 &rule->dport_range))
			continue;

		if (!ops->compare(r, frh, tb))
			continue;
		return 1;
	}
	return 0;
}

753 754 755 756 757 758 759 760 761 762 763
int fib_nl_newrule(struct sk_buff *skb, struct nlmsghdr *nlh,
		   struct netlink_ext_ack *extack)
{
	struct net *net = sock_net(skb->sk);
	struct fib_rule_hdr *frh = nlmsg_data(nlh);
	struct fib_rules_ops *ops = NULL;
	struct fib_rule *rule = NULL, *r, *last = NULL;
	struct nlattr *tb[FRA_MAX + 1];
	int err = -EINVAL, unresolved = 0;
	bool user_priority = false;

764 765
	if (nlh->nlmsg_len < nlmsg_msg_size(sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid msg length");
766
		goto errout;
767
	}
768 769 770 771

	ops = lookup_rules_ops(net, frh->family);
	if (!ops) {
		err = -EAFNOSUPPORT;
772
		NL_SET_ERR_MSG(extack, "Rule family not supported");
773 774 775
		goto errout;
	}

776 777
	err = nlmsg_parse_deprecated(nlh, sizeof(*frh), tb, FRA_MAX,
				     ops->policy, extack);
778 779
	if (err < 0) {
		NL_SET_ERR_MSG(extack, "Error parsing msg");
780
		goto errout;
781
	}
782 783 784 785 786

	err = fib_nl2rule(skb, nlh, extack, ops, tb, &rule, &user_priority);
	if (err)
		goto errout;

787 788 789
	if ((nlh->nlmsg_flags & NLM_F_EXCL) &&
	    rule_exists(ops, frh, tb, rule)) {
		err = -EEXIST;
790 791 792
		goto errout_free;
	}

793
	err = ops->configure(rule, skb, frh, tb, extack);
794 795 796
	if (err < 0)
		goto errout_free;

797 798 799 800 801
	err = call_fib_rule_notifiers(net, FIB_EVENT_RULE_ADD, rule, ops,
				      extack);
	if (err < 0)
		goto errout_free;

802 803 804 805 806 807 808 809 810 811
	list_for_each_entry(r, &ops->rules_list, list) {
		if (r->pref == rule->target) {
			RCU_INIT_POINTER(rule->ctarget, r);
			break;
		}
	}

	if (rcu_dereference_protected(rule->ctarget, 1) == NULL)
		unresolved = 1;

812
	list_for_each_entry(r, &ops->rules_list, list) {
813 814 815 816 817
		if (r->pref > rule->pref)
			break;
		last = r;
	}

E
Eric Dumazet 已提交
818 819 820 821 822
	if (last)
		list_add_rcu(&rule->list, &last->list);
	else
		list_add_rcu(&rule->list, &ops->rules_list);

T
Thomas Graf 已提交
823 824 825 826 827
	if (ops->unresolved_rules) {
		/*
		 * There are unresolved goto rules in the list, check if
		 * any of them are pointing to this new rule.
		 */
828
		list_for_each_entry(r, &ops->rules_list, list) {
T
Thomas Graf 已提交
829
			if (r->action == FR_ACT_GOTO &&
830 831
			    r->target == rule->pref &&
			    rtnl_dereference(r->ctarget) == NULL) {
T
Thomas Graf 已提交
832 833 834 835 836 837 838 839 840 841 842 843 844
				rcu_assign_pointer(r->ctarget, rule);
				if (--ops->unresolved_rules == 0)
					break;
			}
		}
	}

	if (rule->action == FR_ACT_GOTO)
		ops->nr_goto_rules++;

	if (unresolved)
		ops->unresolved_rules++;

845 846 847
	if (rule->tun_id)
		ip_tunnel_need_metadata();

848
	notify_rule_change(RTM_NEWRULE, rule, ops, nlh, NETLINK_CB(skb).portid);
849
	flush_route_cache(ops);
850 851 852 853 854 855 856 857 858
	rules_ops_put(ops);
	return 0;

errout_free:
	kfree(rule);
errout:
	rules_ops_put(ops);
	return err;
}
D
David Ahern 已提交
859
EXPORT_SYMBOL_GPL(fib_nl_newrule);
860

861 862
int fib_nl_delrule(struct sk_buff *skb, struct nlmsghdr *nlh,
		   struct netlink_ext_ack *extack)
863
{
864
	struct net *net = sock_net(skb->sk);
865 866
	struct fib_rule_hdr *frh = nlmsg_data(nlh);
	struct fib_rules_ops *ops = NULL;
867
	struct fib_rule *rule = NULL, *r, *nlrule = NULL;
868 869
	struct nlattr *tb[FRA_MAX+1];
	int err = -EINVAL;
870
	bool user_priority = false;
871

872 873
	if (nlh->nlmsg_len < nlmsg_msg_size(sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid msg length");
874
		goto errout;
875
	}
876

877
	ops = lookup_rules_ops(net, frh->family);
878
	if (ops == NULL) {
879
		err = -EAFNOSUPPORT;
880
		NL_SET_ERR_MSG(extack, "Rule family not supported");
881 882 883
		goto errout;
	}

884 885
	err = nlmsg_parse_deprecated(nlh, sizeof(*frh), tb, FRA_MAX,
				     ops->policy, extack);
886 887
	if (err < 0) {
		NL_SET_ERR_MSG(extack, "Error parsing msg");
888
		goto errout;
889
	}
890

891 892
	err = fib_nl2rule(skb, nlh, extack, ops, tb, &nlrule, &user_priority);
	if (err)
893 894
		goto errout;

895 896 897 898
	rule = rule_find(ops, frh, tb, nlrule, user_priority);
	if (!rule) {
		err = -ENOENT;
		goto errout;
899 900
	}

901 902 903
	if (rule->flags & FIB_RULE_PERMANENT) {
		err = -EPERM;
		goto errout;
904 905
	}

906 907
	if (ops->delete) {
		err = ops->delete(rule);
908 909 910 911
		if (err)
			goto errout;
	}

912 913
	if (rule->tun_id)
		ip_tunnel_unneed_metadata();
914

915
	list_del_rcu(&rule->list);
916

917 918 919 920 921
	if (rule->action == FR_ACT_GOTO) {
		ops->nr_goto_rules--;
		if (rtnl_dereference(rule->ctarget) == NULL)
			ops->unresolved_rules--;
	}
T
Thomas Graf 已提交
922

923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941
	/*
	 * Check if this rule is a target to any of them. If so,
	 * adjust to the next one with the same preference or
	 * disable them. As this operation is eventually very
	 * expensive, it is only performed if goto rules, except
	 * current if it is goto rule, have actually been added.
	 */
	if (ops->nr_goto_rules > 0) {
		struct fib_rule *n;

		n = list_next_entry(rule, list);
		if (&n->list == &ops->rules_list || n->pref != rule->pref)
			n = NULL;
		list_for_each_entry(r, &ops->rules_list, list) {
			if (rtnl_dereference(r->ctarget) != rule)
				continue;
			rcu_assign_pointer(r->ctarget, n);
			if (!n)
				ops->unresolved_rules++;
T
Thomas Graf 已提交
942
		}
943 944
	}

945 946 947 948 949 950 951 952 953 954
	call_fib_rule_notifiers(net, FIB_EVENT_RULE_DEL, rule, ops,
				NULL);
	notify_rule_change(RTM_DELRULE, rule, ops, nlh,
			   NETLINK_CB(skb).portid);
	fib_rule_put(rule);
	flush_route_cache(ops);
	rules_ops_put(ops);
	kfree(nlrule);
	return 0;

955
errout:
956
	kfree(nlrule);
957 958 959
	rules_ops_put(ops);
	return err;
}
D
David Ahern 已提交
960
EXPORT_SYMBOL_GPL(fib_nl_delrule);
961

962 963 964 965
static inline size_t fib_rule_nlmsg_size(struct fib_rules_ops *ops,
					 struct fib_rule *rule)
{
	size_t payload = NLMSG_ALIGN(sizeof(struct fib_rule_hdr))
966
			 + nla_total_size(IFNAMSIZ) /* FRA_IIFNAME */
967
			 + nla_total_size(IFNAMSIZ) /* FRA_OIFNAME */
968 969
			 + nla_total_size(4) /* FRA_PRIORITY */
			 + nla_total_size(4) /* FRA_TABLE */
970
			 + nla_total_size(4) /* FRA_SUPPRESS_PREFIXLEN */
971
			 + nla_total_size(4) /* FRA_SUPPRESS_IFGROUP */
972
			 + nla_total_size(4) /* FRA_FWMARK */
973
			 + nla_total_size(4) /* FRA_FWMASK */
974
			 + nla_total_size_64bit(8) /* FRA_TUN_ID */
975
			 + nla_total_size(sizeof(struct fib_kuid_range))
976 977 978 979
			 + nla_total_size(1) /* FRA_PROTOCOL */
			 + nla_total_size(1) /* FRA_IP_PROTO */
			 + nla_total_size(sizeof(struct fib_rule_port_range)) /* FRA_SPORT_RANGE */
			 + nla_total_size(sizeof(struct fib_rule_port_range)); /* FRA_DPORT_RANGE */
980 981 982 983 984 985 986

	if (ops->nlmsg_payload)
		payload += ops->nlmsg_payload(rule);

	return payload;
}

987 988 989 990 991 992 993 994 995
static int fib_nl_fill_rule(struct sk_buff *skb, struct fib_rule *rule,
			    u32 pid, u32 seq, int type, int flags,
			    struct fib_rules_ops *ops)
{
	struct nlmsghdr *nlh;
	struct fib_rule_hdr *frh;

	nlh = nlmsg_put(skb, pid, seq, type, sizeof(*frh), flags);
	if (nlh == NULL)
996
		return -EMSGSIZE;
997 998

	frh = nlmsg_data(nlh);
999
	frh->family = ops->family;
1000
	frh->table = rule->table < 256 ? rule->table : RT_TABLE_COMPAT;
1001 1002
	if (nla_put_u32(skb, FRA_TABLE, rule->table))
		goto nla_put_failure;
1003
	if (nla_put_u32(skb, FRA_SUPPRESS_PREFIXLEN, rule->suppress_prefixlen))
1004
		goto nla_put_failure;
1005
	frh->res1 = 0;
1006
	frh->res2 = 0;
1007 1008
	frh->action = rule->action;
	frh->flags = rule->flags;
1009 1010 1011

	if (nla_put_u8(skb, FRA_PROTOCOL, rule->proto))
		goto nla_put_failure;
1012

E
Eric Dumazet 已提交
1013
	if (rule->action == FR_ACT_GOTO &&
1014
	    rcu_access_pointer(rule->ctarget) == NULL)
T
Thomas Graf 已提交
1015 1016
		frh->flags |= FIB_RULE_UNRESOLVED;

1017
	if (rule->iifname[0]) {
1018 1019
		if (nla_put_string(skb, FRA_IIFNAME, rule->iifname))
			goto nla_put_failure;
1020 1021
		if (rule->iifindex == -1)
			frh->flags |= FIB_RULE_IIF_DETACHED;
1022 1023
	}

1024
	if (rule->oifname[0]) {
1025 1026
		if (nla_put_string(skb, FRA_OIFNAME, rule->oifname))
			goto nla_put_failure;
1027 1028 1029 1030
		if (rule->oifindex == -1)
			frh->flags |= FIB_RULE_OIF_DETACHED;
	}

1031 1032 1033 1034 1035 1036 1037
	if ((rule->pref &&
	     nla_put_u32(skb, FRA_PRIORITY, rule->pref)) ||
	    (rule->mark &&
	     nla_put_u32(skb, FRA_FWMARK, rule->mark)) ||
	    ((rule->mark_mask || rule->mark) &&
	     nla_put_u32(skb, FRA_FWMASK, rule->mark_mask)) ||
	    (rule->target &&
1038 1039
	     nla_put_u32(skb, FRA_GOTO, rule->target)) ||
	    (rule->tun_id &&
D
David Ahern 已提交
1040 1041
	     nla_put_be64(skb, FRA_TUN_ID, rule->tun_id, FRA_PAD)) ||
	    (rule->l3mdev &&
1042 1043
	     nla_put_u8(skb, FRA_L3MDEV, rule->l3mdev)) ||
	    (uid_range_set(&rule->uid_range) &&
1044 1045 1046 1047 1048 1049
	     nla_put_uid_range(skb, &rule->uid_range)) ||
	    (fib_rule_port_range_set(&rule->sport_range) &&
	     nla_put_port_range(skb, FRA_SPORT_RANGE, &rule->sport_range)) ||
	    (fib_rule_port_range_set(&rule->dport_range) &&
	     nla_put_port_range(skb, FRA_DPORT_RANGE, &rule->dport_range)) ||
	    (rule->ip_proto && nla_put_u8(skb, FRA_IP_PROTO, rule->ip_proto)))
1050
		goto nla_put_failure;
1051 1052 1053 1054 1055 1056

	if (rule->suppress_ifgroup != -1) {
		if (nla_put_u32(skb, FRA_SUPPRESS_IFGROUP, rule->suppress_ifgroup))
			goto nla_put_failure;
	}

1057
	if (ops->fill(rule, skb, frh) < 0)
1058 1059
		goto nla_put_failure;

1060 1061
	nlmsg_end(skb, nlh);
	return 0;
1062 1063

nla_put_failure:
1064 1065
	nlmsg_cancel(skb, nlh);
	return -EMSGSIZE;
1066 1067
}

T
Thomas Graf 已提交
1068 1069
static int dump_rules(struct sk_buff *skb, struct netlink_callback *cb,
		      struct fib_rules_ops *ops)
1070 1071 1072
{
	int idx = 0;
	struct fib_rule *rule;
1073
	int err = 0;
1074

1075 1076
	rcu_read_lock();
	list_for_each_entry_rcu(rule, &ops->rules_list, list) {
T
Thomas Graf 已提交
1077
		if (idx < cb->args[1])
1078 1079
			goto skip;

1080 1081 1082 1083
		err = fib_nl_fill_rule(skb, rule, NETLINK_CB(cb->skb).portid,
				       cb->nlh->nlmsg_seq, RTM_NEWRULE,
				       NLM_F_MULTI, ops);
		if (err)
1084 1085 1086 1087
			break;
skip:
		idx++;
	}
1088
	rcu_read_unlock();
T
Thomas Graf 已提交
1089
	cb->args[1] = idx;
1090 1091
	rules_ops_put(ops);

1092
	return err;
1093 1094
}

1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120
static int fib_valid_dumprule_req(const struct nlmsghdr *nlh,
				   struct netlink_ext_ack *extack)
{
	struct fib_rule_hdr *frh;

	if (nlh->nlmsg_len < nlmsg_msg_size(sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid header for fib rule dump request");
		return -EINVAL;
	}

	frh = nlmsg_data(nlh);
	if (frh->dst_len || frh->src_len || frh->tos || frh->table ||
	    frh->res1 || frh->res2 || frh->action || frh->flags) {
		NL_SET_ERR_MSG(extack,
			       "Invalid values in header for fib rule dump request");
		return -EINVAL;
	}

	if (nlmsg_attrlen(nlh, sizeof(*frh))) {
		NL_SET_ERR_MSG(extack, "Invalid data after header in fib rule dump request");
		return -EINVAL;
	}

	return 0;
}

T
Thomas Graf 已提交
1121 1122
static int fib_nl_dumprule(struct sk_buff *skb, struct netlink_callback *cb)
{
1123
	const struct nlmsghdr *nlh = cb->nlh;
1124
	struct net *net = sock_net(skb->sk);
T
Thomas Graf 已提交
1125 1126 1127
	struct fib_rules_ops *ops;
	int idx = 0, family;

1128 1129 1130 1131 1132 1133 1134 1135
	if (cb->strict_check) {
		int err = fib_valid_dumprule_req(nlh, cb->extack);

		if (err < 0)
			return err;
	}

	family = rtnl_msg_family(nlh);
T
Thomas Graf 已提交
1136 1137
	if (family != AF_UNSPEC) {
		/* Protocol specific dump request */
1138
		ops = lookup_rules_ops(net, family);
T
Thomas Graf 已提交
1139 1140 1141
		if (ops == NULL)
			return -EAFNOSUPPORT;

1142 1143 1144
		dump_rules(skb, cb, ops);

		return skb->len;
T
Thomas Graf 已提交
1145 1146 1147
	}

	rcu_read_lock();
1148
	list_for_each_entry_rcu(ops, &net->rules_ops, list) {
T
Thomas Graf 已提交
1149 1150 1151 1152 1153 1154 1155
		if (idx < cb->args[0] || !try_module_get(ops->owner))
			goto skip;

		if (dump_rules(skb, cb, ops) < 0)
			break;

		cb->args[1] = 0;
1156
skip:
T
Thomas Graf 已提交
1157 1158 1159 1160 1161 1162 1163
		idx++;
	}
	rcu_read_unlock();
	cb->args[0] = idx;

	return skb->len;
}
1164

D
Denis V. Lunev 已提交
1165
static void notify_rule_change(int event, struct fib_rule *rule,
1166 1167
			       struct fib_rules_ops *ops, struct nlmsghdr *nlh,
			       u32 pid)
1168
{
D
Denis V. Lunev 已提交
1169
	struct net *net;
1170
	struct sk_buff *skb;
1171
	int err = -ENOMEM;
1172

D
Denis V. Lunev 已提交
1173
	net = ops->fro_net;
1174
	skb = nlmsg_new(fib_rule_nlmsg_size(ops, rule), GFP_KERNEL);
1175
	if (skb == NULL)
1176 1177 1178
		goto errout;

	err = fib_nl_fill_rule(skb, rule, pid, nlh->nlmsg_seq, event, 0, ops);
1179 1180 1181 1182 1183 1184
	if (err < 0) {
		/* -EMSGSIZE implies BUG in fib_rule_nlmsg_size() */
		WARN_ON(err == -EMSGSIZE);
		kfree_skb(skb);
		goto errout;
	}
D
Denis V. Lunev 已提交
1185

1186 1187
	rtnl_notify(skb, net, pid, ops->nlgroup, nlh, GFP_KERNEL);
	return;
1188 1189
errout:
	if (err < 0)
1190
		rtnl_set_sk_err(net, ops->nlgroup, err);
1191 1192 1193 1194 1195 1196 1197
}

static void attach_rules(struct list_head *rules, struct net_device *dev)
{
	struct fib_rule *rule;

	list_for_each_entry(rule, rules, list) {
1198 1199 1200
		if (rule->iifindex == -1 &&
		    strcmp(dev->name, rule->iifname) == 0)
			rule->iifindex = dev->ifindex;
1201 1202 1203
		if (rule->oifindex == -1 &&
		    strcmp(dev->name, rule->oifname) == 0)
			rule->oifindex = dev->ifindex;
1204 1205 1206 1207 1208 1209 1210
	}
}

static void detach_rules(struct list_head *rules, struct net_device *dev)
{
	struct fib_rule *rule;

1211
	list_for_each_entry(rule, rules, list) {
1212 1213
		if (rule->iifindex == dev->ifindex)
			rule->iifindex = -1;
1214 1215 1216
		if (rule->oifindex == dev->ifindex)
			rule->oifindex = -1;
	}
1217 1218 1219 1220
}


static int fib_rules_event(struct notifier_block *this, unsigned long event,
1221
			   void *ptr)
1222
{
1223
	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
1224
	struct net *net = dev_net(dev);
1225 1226
	struct fib_rules_ops *ops;

1227
	ASSERT_RTNL();
1228 1229 1230

	switch (event) {
	case NETDEV_REGISTER:
1231
		list_for_each_entry(ops, &net->rules_ops, list)
1232
			attach_rules(&ops->rules_list, dev);
1233 1234
		break;

1235 1236 1237 1238 1239 1240 1241
	case NETDEV_CHANGENAME:
		list_for_each_entry(ops, &net->rules_ops, list) {
			detach_rules(&ops->rules_list, dev);
			attach_rules(&ops->rules_list, dev);
		}
		break;

1242
	case NETDEV_UNREGISTER:
1243
		list_for_each_entry(ops, &net->rules_ops, list)
1244
			detach_rules(&ops->rules_list, dev);
1245 1246 1247 1248 1249 1250 1251 1252 1253 1254
		break;
	}

	return NOTIFY_DONE;
}

static struct notifier_block fib_rules_notifier = {
	.notifier_call = fib_rules_event,
};

1255
static int __net_init fib_rules_net_init(struct net *net)
1256 1257 1258 1259 1260 1261
{
	INIT_LIST_HEAD(&net->rules_ops);
	spin_lock_init(&net->rules_mod_lock);
	return 0;
}

1262 1263 1264 1265 1266
static void __net_exit fib_rules_net_exit(struct net *net)
{
	WARN_ON_ONCE(!list_empty(&net->rules_ops));
}

1267 1268
static struct pernet_operations fib_rules_net_ops = {
	.init = fib_rules_net_init,
1269
	.exit = fib_rules_net_exit,
1270 1271
};

1272 1273
static int __init fib_rules_init(void)
{
1274
	int err;
1275 1276 1277
	rtnl_register(PF_UNSPEC, RTM_NEWRULE, fib_nl_newrule, NULL, 0);
	rtnl_register(PF_UNSPEC, RTM_DELRULE, fib_nl_delrule, NULL, 0);
	rtnl_register(PF_UNSPEC, RTM_GETRULE, NULL, fib_nl_dumprule, 0);
1278

E
Eric W. Biederman 已提交
1279
	err = register_pernet_subsys(&fib_rules_net_ops);
1280 1281 1282
	if (err < 0)
		goto fail;

E
Eric W. Biederman 已提交
1283
	err = register_netdevice_notifier(&fib_rules_notifier);
1284 1285
	if (err < 0)
		goto fail_unregister;
E
Eric W. Biederman 已提交
1286

1287 1288 1289
	return 0;

fail_unregister:
E
Eric W. Biederman 已提交
1290
	unregister_pernet_subsys(&fib_rules_net_ops);
1291 1292 1293 1294 1295
fail:
	rtnl_unregister(PF_UNSPEC, RTM_NEWRULE);
	rtnl_unregister(PF_UNSPEC, RTM_DELRULE);
	rtnl_unregister(PF_UNSPEC, RTM_GETRULE);
	return err;
1296 1297 1298
}

subsys_initcall(fib_rules_init);