fib_frontend.c 29.1 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
/*
 * INET		An implementation of the TCP/IP protocol suite for the LINUX
 *		operating system.  INET is implemented using the  BSD Socket
 *		interface as the means of communication with the user level.
 *
 *		IPv4 Forwarding Information Base: FIB frontend.
 *
 * Authors:	Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 */

#include <linux/module.h>
#include <asm/uaccess.h>
#include <linux/bitops.h>
19
#include <linux/capability.h>
L
Linus Torvalds 已提交
20 21 22 23 24 25 26 27 28
#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/mm.h>
#include <linux/string.h>
#include <linux/socket.h>
#include <linux/sockios.h>
#include <linux/errno.h>
#include <linux/in.h>
#include <linux/inet.h>
29
#include <linux/inetdevice.h>
L
Linus Torvalds 已提交
30
#include <linux/netdevice.h>
31
#include <linux/if_addr.h>
L
Linus Torvalds 已提交
32 33
#include <linux/if_arp.h>
#include <linux/skbuff.h>
34
#include <linux/cache.h>
L
Linus Torvalds 已提交
35
#include <linux/init.h>
36
#include <linux/list.h>
37
#include <linux/slab.h>
L
Linus Torvalds 已提交
38 39 40 41 42 43 44 45

#include <net/ip.h>
#include <net/protocol.h>
#include <net/route.h>
#include <net/tcp.h>
#include <net/sock.h>
#include <net/arp.h>
#include <net/ip_fib.h>
46
#include <net/rtnetlink.h>
47
#include <net/xfrm.h>
L
Linus Torvalds 已提交
48 49 50

#ifndef CONFIG_IP_MULTIPLE_TABLES

51
static int __net_init fib4_rules_init(struct net *net)
52
{
53 54
	struct fib_table *local_table, *main_table;

55
	main_table  = fib_trie_table(RT_TABLE_MAIN, NULL);
56
	if (!main_table)
57
		return -ENOMEM;
58

59
	local_table = fib_trie_table(RT_TABLE_LOCAL, main_table);
60
	if (!local_table)
61
		goto fail;
62

63
	hlist_add_head_rcu(&local_table->tb_hlist,
64
				&net->ipv4.fib_table_hash[TABLE_LOCAL_INDEX]);
65
	hlist_add_head_rcu(&main_table->tb_hlist,
66
				&net->ipv4.fib_table_hash[TABLE_MAIN_INDEX]);
67 68 69
	return 0;

fail:
70
	fib_free_table(main_table);
71
	return -ENOMEM;
72
}
73
#else
L
Linus Torvalds 已提交
74

75
struct fib_table *fib_new_table(struct net *net, u32 id)
L
Linus Torvalds 已提交
76
{
77
	struct fib_table *tb, *alias = NULL;
78
	unsigned int h;
L
Linus Torvalds 已提交
79

80 81
	if (id == 0)
		id = RT_TABLE_MAIN;
82
	tb = fib_get_table(net, id);
83 84
	if (tb)
		return tb;
85

86 87 88 89
	if (id == RT_TABLE_LOCAL)
		alias = fib_new_table(net, RT_TABLE_MAIN);

	tb = fib_trie_table(id, alias);
L
Linus Torvalds 已提交
90 91
	if (!tb)
		return NULL;
92 93 94

	switch (id) {
	case RT_TABLE_LOCAL:
95
		rcu_assign_pointer(net->ipv4.fib_local, tb);
96 97
		break;
	case RT_TABLE_MAIN:
98
		rcu_assign_pointer(net->ipv4.fib_main, tb);
99 100
		break;
	case RT_TABLE_DEFAULT:
101
		rcu_assign_pointer(net->ipv4.fib_default, tb);
102 103 104 105 106
		break;
	default:
		break;
	}

107
	h = id & (FIB_TABLE_HASHSZ - 1);
108
	hlist_add_head_rcu(&tb->tb_hlist, &net->ipv4.fib_table_hash[h]);
L
Linus Torvalds 已提交
109 110 111
	return tb;
}

112
/* caller must hold either rtnl or rcu read lock */
113
struct fib_table *fib_get_table(struct net *net, u32 id)
114 115
{
	struct fib_table *tb;
116
	struct hlist_head *head;
117
	unsigned int h;
L
Linus Torvalds 已提交
118

119 120 121
	if (id == 0)
		id = RT_TABLE_MAIN;
	h = id & (FIB_TABLE_HASHSZ - 1);
122 123

	head = &net->ipv4.fib_table_hash[h];
124
	hlist_for_each_entry_rcu(tb, head, tb_hlist) {
125
		if (tb->tb_id == id)
126 127 128 129
			return tb;
	}
	return NULL;
}
L
Linus Torvalds 已提交
130 131
#endif /* CONFIG_IP_MULTIPLE_TABLES */

132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158
static void fib_replace_table(struct net *net, struct fib_table *old,
			      struct fib_table *new)
{
#ifdef CONFIG_IP_MULTIPLE_TABLES
	switch (new->tb_id) {
	case RT_TABLE_LOCAL:
		rcu_assign_pointer(net->ipv4.fib_local, new);
		break;
	case RT_TABLE_MAIN:
		rcu_assign_pointer(net->ipv4.fib_main, new);
		break;
	case RT_TABLE_DEFAULT:
		rcu_assign_pointer(net->ipv4.fib_default, new);
		break;
	default:
		break;
	}

#endif
	/* replace the old table in the hlist */
	hlist_replace_rcu(&old->tb_hlist, &new->tb_hlist);
}

int fib_unmerge(struct net *net)
{
	struct fib_table *old, *new;

159
	/* attempt to fetch local table if it has been allocated */
160
	old = fib_get_table(net, RT_TABLE_LOCAL);
161 162
	if (!old)
		return 0;
163

164
	new = fib_trie_unmerge(old);
165 166 167 168 169 170 171 172 173 174 175 176
	if (!new)
		return -ENOMEM;

	/* replace merged table with clean table */
	if (new != old) {
		fib_replace_table(net, old, new);
		fib_free_table(old);
	}

	return 0;
}

177
static void fib_flush(struct net *net)
L
Linus Torvalds 已提交
178 179
{
	int flushed = 0;
180
	unsigned int h;
L
Linus Torvalds 已提交
181

182
	for (h = 0; h < FIB_TABLE_HASHSZ; h++) {
183 184 185 186 187
		struct hlist_head *head = &net->ipv4.fib_table_hash[h];
		struct hlist_node *tmp;
		struct fib_table *tb;

		hlist_for_each_entry_safe(tb, tmp, head, tb_hlist)
188
			flushed += fib_table_flush(tb);
L
Linus Torvalds 已提交
189 190 191
	}

	if (flushed)
192
		rt_cache_flush(net);
L
Linus Torvalds 已提交
193 194
}

195 196 197 198 199 200 201 202 203 204 205 206 207
void fib_flush_external(struct net *net)
{
	struct fib_table *tb;
	struct hlist_head *head;
	unsigned int h;

	for (h = 0; h < FIB_TABLE_HASHSZ; h++) {
		head = &net->ipv4.fib_table_hash[h];
		hlist_for_each_entry(tb, head, tb_hlist)
			fib_table_flush_external(tb);
	}
}

208 209 210 211
/*
 * Find address type as if only "dev" was present in the system. If
 * on_dev is NULL then all interfaces are taken into consideration.
 */
212 213 214
static inline unsigned int __inet_dev_addr_type(struct net *net,
						const struct net_device *dev,
						__be32 addr)
L
Linus Torvalds 已提交
215
{
D
David S. Miller 已提交
216
	struct flowi4		fl4 = { .daddr = addr };
L
Linus Torvalds 已提交
217
	struct fib_result	res;
218
	unsigned int ret = RTN_BROADCAST;
219
	struct fib_table *local_table;
L
Linus Torvalds 已提交
220

221
	if (ipv4_is_zeronet(addr) || ipv4_is_lbcast(addr))
L
Linus Torvalds 已提交
222
		return RTN_BROADCAST;
223
	if (ipv4_is_multicast(addr))
L
Linus Torvalds 已提交
224 225
		return RTN_MULTICAST;

226 227
	rcu_read_lock();

228
	local_table = fib_get_table(net, RT_TABLE_LOCAL);
229
	if (local_table) {
L
Linus Torvalds 已提交
230
		ret = RTN_UNICAST;
D
David S. Miller 已提交
231
		if (!fib_table_lookup(local_table, &fl4, &res, FIB_LOOKUP_NOREF)) {
232 233
			if (!dev || dev == res.fi->fib_dev)
				ret = res.type;
L
Linus Torvalds 已提交
234 235
		}
	}
236 237

	rcu_read_unlock();
L
Linus Torvalds 已提交
238 239 240
	return ret;
}

241
unsigned int inet_addr_type(struct net *net, __be32 addr)
242
{
243
	return __inet_dev_addr_type(net, NULL, addr);
244
}
E
Eric Dumazet 已提交
245
EXPORT_SYMBOL(inet_addr_type);
246

247 248
unsigned int inet_dev_addr_type(struct net *net, const struct net_device *dev,
				__be32 addr)
249
{
E
Eric Dumazet 已提交
250
	return __inet_dev_addr_type(net, dev, addr);
251
}
E
Eric Dumazet 已提交
252
EXPORT_SYMBOL(inet_dev_addr_type);
253

254 255 256 257 258
__be32 fib_compute_spec_dst(struct sk_buff *skb)
{
	struct net_device *dev = skb->dev;
	struct in_device *in_dev;
	struct fib_result res;
259
	struct rtable *rt;
260 261
	struct flowi4 fl4;
	struct net *net;
262
	int scope;
263

264
	rt = skb_rtable(skb);
265 266
	if ((rt->rt_flags & (RTCF_BROADCAST | RTCF_MULTICAST | RTCF_LOCAL)) ==
	    RTCF_LOCAL)
267 268 269 270 271 272
		return ip_hdr(skb)->daddr;

	in_dev = __in_dev_get_rcu(dev);
	BUG_ON(!in_dev);

	net = dev_net(dev);
273 274 275 276

	scope = RT_SCOPE_UNIVERSE;
	if (!ipv4_is_zeronet(ip_hdr(skb)->saddr)) {
		fl4.flowi4_oif = 0;
277
		fl4.flowi4_iif = LOOPBACK_IFINDEX;
278 279 280 281 282
		fl4.daddr = ip_hdr(skb)->saddr;
		fl4.saddr = 0;
		fl4.flowi4_tos = RT_TOS(ip_hdr(skb)->tos);
		fl4.flowi4_scope = scope;
		fl4.flowi4_mark = IN_DEV_SRC_VMARK(in_dev) ? skb->mark : 0;
283
		if (!fib_lookup(net, &fl4, &res, 0))
284 285 286 287 288 289
			return FIB_RES_PREFSRC(net, res);
	} else {
		scope = RT_SCOPE_LINK;
	}

	return inet_select_addr(dev, ip_hdr(skb)->saddr, scope);
290 291
}

L
Linus Torvalds 已提交
292
/* Given (packet source, input interface) and optional (dst, oif, tos):
E
Eric Dumazet 已提交
293 294 295 296 297
 * - (main) check, that source is valid i.e. not broadcast or our local
 *   address.
 * - figure out what "logical" interface this packet arrived
 *   and calculate "specific destination" address.
 * - check, that packet arrived from expected physical interface.
E
Eric Dumazet 已提交
298
 * called with rcu_read_lock()
L
Linus Torvalds 已提交
299
 */
300 301 302
static int __fib_validate_source(struct sk_buff *skb, __be32 src, __be32 dst,
				 u8 tos, int oif, struct net_device *dev,
				 int rpf, struct in_device *idev, u32 *itag)
L
Linus Torvalds 已提交
303
{
304
	int ret, no_addr;
L
Linus Torvalds 已提交
305
	struct fib_result res;
306
	struct flowi4 fl4;
307
	struct net *net;
308
	bool dev_match;
L
Linus Torvalds 已提交
309

D
David S. Miller 已提交
310
	fl4.flowi4_oif = 0;
311
	fl4.flowi4_iif = oif ? : LOOPBACK_IFINDEX;
D
David S. Miller 已提交
312 313 314 315
	fl4.daddr = src;
	fl4.saddr = dst;
	fl4.flowi4_tos = tos;
	fl4.flowi4_scope = RT_SCOPE_UNIVERSE;
316

317
	no_addr = idev->ifa_list == NULL;
318

319
	fl4.flowi4_mark = IN_DEV_SRC_VMARK(idev) ? skb->mark : 0;
L
Linus Torvalds 已提交
320

321
	net = dev_net(dev);
322
	if (fib_lookup(net, &fl4, &res, 0))
L
Linus Torvalds 已提交
323
		goto last_resort;
324 325 326 327 328 329
	if (res.type != RTN_UNICAST &&
	    (res.type != RTN_LOCAL || !IN_DEV_ACCEPT_LOCAL(idev)))
		goto e_inval;
	if (!rpf && !fib_num_tclassid_users(dev_net(dev)) &&
	    (dev->ifindex != oif || !IN_DEV_TX_REDIRECTS(idev)))
		goto last_resort;
L
Linus Torvalds 已提交
330
	fib_combine_itag(itag, &res);
331 332
	dev_match = false;

L
Linus Torvalds 已提交
333
#ifdef CONFIG_IP_ROUTE_MULTIPATH
334 335 336 337 338 339 340 341
	for (ret = 0; ret < res.fi->fib_nhs; ret++) {
		struct fib_nh *nh = &res.fi->fib_nh[ret];

		if (nh->nh_dev == dev) {
			dev_match = true;
			break;
		}
	}
L
Linus Torvalds 已提交
342 343
#else
	if (FIB_RES_DEV(res) == dev)
344
		dev_match = true;
L
Linus Torvalds 已提交
345
#endif
346
	if (dev_match) {
L
Linus Torvalds 已提交
347 348 349 350 351
		ret = FIB_RES_NH(res).nh_scope >= RT_SCOPE_HOST;
		return ret;
	}
	if (no_addr)
		goto last_resort;
352
	if (rpf == 1)
353
		goto e_rpf;
D
David S. Miller 已提交
354
	fl4.flowi4_oif = dev->ifindex;
L
Linus Torvalds 已提交
355 356

	ret = 0;
357
	if (fib_lookup(net, &fl4, &res, FIB_LOOKUP_IGNORE_LINKSTATE) == 0) {
358
		if (res.type == RTN_UNICAST)
L
Linus Torvalds 已提交
359 360 361 362 363 364
			ret = FIB_RES_NH(res).nh_scope >= RT_SCOPE_HOST;
	}
	return ret;

last_resort:
	if (rpf)
365
		goto e_rpf;
L
Linus Torvalds 已提交
366 367 368 369 370
	*itag = 0;
	return 0;

e_inval:
	return -EINVAL;
371 372
e_rpf:
	return -EXDEV;
L
Linus Torvalds 已提交
373 374
}

375 376 377 378 379 380 381
/* Ignore rp_filter for packets protected by IPsec. */
int fib_validate_source(struct sk_buff *skb, __be32 src, __be32 dst,
			u8 tos, int oif, struct net_device *dev,
			struct in_device *idev, u32 *itag)
{
	int r = secpath_exists(skb) ? 0 : IN_DEV_RPFILTER(idev);

J
Julian Anastasov 已提交
382
	if (!r && !fib_num_tclassid_users(dev_net(dev)) &&
383
	    IN_DEV_ACCEPT_LOCAL(idev) &&
J
Julian Anastasov 已提交
384
	    (dev->ifindex != oif || !IN_DEV_TX_REDIRECTS(idev))) {
385 386 387 388 389 390
		*itag = 0;
		return 0;
	}
	return __fib_validate_source(skb, src, dst, tos, oif, dev, r, idev, itag);
}

A
Al Viro 已提交
391
static inline __be32 sk_extract_addr(struct sockaddr *addr)
392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407
{
	return ((struct sockaddr_in *) addr)->sin_addr.s_addr;
}

static int put_rtax(struct nlattr *mx, int len, int type, u32 value)
{
	struct nlattr *nla;

	nla = (struct nlattr *) ((char *) mx + len);
	nla->nla_type = type;
	nla->nla_len = nla_attr_size(4);
	*(u32 *) nla_data(nla) = value;

	return len + nla_total_size(4);
}

408
static int rtentry_to_fib_config(struct net *net, int cmd, struct rtentry *rt,
409 410
				 struct fib_config *cfg)
{
411
	__be32 addr;
412 413 414
	int plen;

	memset(cfg, 0, sizeof(*cfg));
415
	cfg->fc_nlinfo.nl_net = net;
416 417 418 419 420 421 422 423 424 425 426 427 428 429 430

	if (rt->rt_dst.sa_family != AF_INET)
		return -EAFNOSUPPORT;

	/*
	 * Check mask for validity:
	 * a) it must be contiguous.
	 * b) destination must have all host bits clear.
	 * c) if application forgot to set correct family (AF_INET),
	 *    reject request unless it is absolutely clear i.e.
	 *    both family and mask are zero.
	 */
	plen = 32;
	addr = sk_extract_addr(&rt->rt_dst);
	if (!(rt->rt_flags & RTF_HOST)) {
A
Al Viro 已提交
431
		__be32 mask = sk_extract_addr(&rt->rt_genmask);
432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475

		if (rt->rt_genmask.sa_family != AF_INET) {
			if (mask || rt->rt_genmask.sa_family)
				return -EAFNOSUPPORT;
		}

		if (bad_mask(mask, addr))
			return -EINVAL;

		plen = inet_mask_len(mask);
	}

	cfg->fc_dst_len = plen;
	cfg->fc_dst = addr;

	if (cmd != SIOCDELRT) {
		cfg->fc_nlflags = NLM_F_CREATE;
		cfg->fc_protocol = RTPROT_BOOT;
	}

	if (rt->rt_metric)
		cfg->fc_priority = rt->rt_metric - 1;

	if (rt->rt_flags & RTF_REJECT) {
		cfg->fc_scope = RT_SCOPE_HOST;
		cfg->fc_type = RTN_UNREACHABLE;
		return 0;
	}

	cfg->fc_scope = RT_SCOPE_NOWHERE;
	cfg->fc_type = RTN_UNICAST;

	if (rt->rt_dev) {
		char *colon;
		struct net_device *dev;
		char devname[IFNAMSIZ];

		if (copy_from_user(devname, rt->rt_dev, IFNAMSIZ-1))
			return -EFAULT;

		devname[IFNAMSIZ-1] = 0;
		colon = strchr(devname, ':');
		if (colon)
			*colon = 0;
476
		dev = __dev_get_by_name(net, devname);
477 478 479 480 481 482 483 484 485 486 487 488
		if (!dev)
			return -ENODEV;
		cfg->fc_oif = dev->ifindex;
		if (colon) {
			struct in_ifaddr *ifa;
			struct in_device *in_dev = __in_dev_get_rtnl(dev);
			if (!in_dev)
				return -ENODEV;
			*colon = ':';
			for (ifa = in_dev->ifa_list; ifa; ifa = ifa->ifa_next)
				if (strcmp(ifa->ifa_label, devname) == 0)
					break;
489
			if (!ifa)
490 491 492 493 494 495 496 497 498
				return -ENODEV;
			cfg->fc_prefsrc = ifa->ifa_local;
		}
	}

	addr = sk_extract_addr(&rt->rt_gateway);
	if (rt->rt_gateway.sa_family == AF_INET && addr) {
		cfg->fc_gw = addr;
		if (rt->rt_flags & RTF_GATEWAY &&
499
		    inet_addr_type(net, addr) == RTN_UNICAST)
500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516
			cfg->fc_scope = RT_SCOPE_UNIVERSE;
	}

	if (cmd == SIOCDELRT)
		return 0;

	if (rt->rt_flags & RTF_GATEWAY && !cfg->fc_gw)
		return -EINVAL;

	if (cfg->fc_scope == RT_SCOPE_NOWHERE)
		cfg->fc_scope = RT_SCOPE_LINK;

	if (rt->rt_flags & (RTF_MTU | RTF_WINDOW | RTF_IRTT)) {
		struct nlattr *mx;
		int len = 0;

		mx = kzalloc(3 * nla_total_size(4), GFP_KERNEL);
517
		if (!mx)
518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535
			return -ENOMEM;

		if (rt->rt_flags & RTF_MTU)
			len = put_rtax(mx, len, RTAX_ADVMSS, rt->rt_mtu - 40);

		if (rt->rt_flags & RTF_WINDOW)
			len = put_rtax(mx, len, RTAX_WINDOW, rt->rt_window);

		if (rt->rt_flags & RTF_IRTT)
			len = put_rtax(mx, len, RTAX_RTT, rt->rt_irtt << 3);

		cfg->fc_mx = mx;
		cfg->fc_mx_len = len;
	}

	return 0;
}

L
Linus Torvalds 已提交
536
/*
E
Eric Dumazet 已提交
537 538
 * Handle IP routing ioctl calls.
 * These are used to manipulate the routing tables
L
Linus Torvalds 已提交
539
 */
540
int ip_rt_ioctl(struct net *net, unsigned int cmd, void __user *arg)
L
Linus Torvalds 已提交
541
{
542 543
	struct fib_config cfg;
	struct rtentry rt;
L
Linus Torvalds 已提交
544 545 546 547 548
	int err;

	switch (cmd) {
	case SIOCADDRT:		/* Add a route */
	case SIOCDELRT:		/* Delete a route */
549
		if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
L
Linus Torvalds 已提交
550
			return -EPERM;
551 552

		if (copy_from_user(&rt, arg, sizeof(rt)))
L
Linus Torvalds 已提交
553
			return -EFAULT;
554

L
Linus Torvalds 已提交
555
		rtnl_lock();
556
		err = rtentry_to_fib_config(net, cmd, &rt, &cfg);
L
Linus Torvalds 已提交
557
		if (err == 0) {
558 559
			struct fib_table *tb;

L
Linus Torvalds 已提交
560
			if (cmd == SIOCDELRT) {
561
				tb = fib_get_table(net, cfg.fc_table);
L
Linus Torvalds 已提交
562
				if (tb)
563
					err = fib_table_delete(tb, &cfg);
564 565
				else
					err = -ESRCH;
L
Linus Torvalds 已提交
566
			} else {
567
				tb = fib_new_table(net, cfg.fc_table);
L
Linus Torvalds 已提交
568
				if (tb)
569
					err = fib_table_insert(tb, &cfg);
570 571
				else
					err = -ENOBUFS;
L
Linus Torvalds 已提交
572
			}
573 574 575

			/* allocated by rtentry_to_fib_config() */
			kfree(cfg.fc_mx);
L
Linus Torvalds 已提交
576 577 578 579 580 581 582
		}
		rtnl_unlock();
		return err;
	}
	return -EINVAL;
}

E
Eric Dumazet 已提交
583
const struct nla_policy rtm_ipv4_policy[RTA_MAX + 1] = {
584 585 586 587 588 589 590 591
	[RTA_DST]		= { .type = NLA_U32 },
	[RTA_SRC]		= { .type = NLA_U32 },
	[RTA_IIF]		= { .type = NLA_U32 },
	[RTA_OIF]		= { .type = NLA_U32 },
	[RTA_GATEWAY]		= { .type = NLA_U32 },
	[RTA_PRIORITY]		= { .type = NLA_U32 },
	[RTA_PREFSRC]		= { .type = NLA_U32 },
	[RTA_METRICS]		= { .type = NLA_NESTED },
592
	[RTA_MULTIPATH]		= { .len = sizeof(struct rtnexthop) },
593 594 595
	[RTA_FLOW]		= { .type = NLA_U32 },
};

596
static int rtm_to_fib_config(struct net *net, struct sk_buff *skb,
E
Eric Dumazet 已提交
597
			     struct nlmsghdr *nlh, struct fib_config *cfg)
L
Linus Torvalds 已提交
598
{
599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618
	struct nlattr *attr;
	int err, remaining;
	struct rtmsg *rtm;

	err = nlmsg_validate(nlh, sizeof(*rtm), RTA_MAX, rtm_ipv4_policy);
	if (err < 0)
		goto errout;

	memset(cfg, 0, sizeof(*cfg));

	rtm = nlmsg_data(nlh);
	cfg->fc_dst_len = rtm->rtm_dst_len;
	cfg->fc_tos = rtm->rtm_tos;
	cfg->fc_table = rtm->rtm_table;
	cfg->fc_protocol = rtm->rtm_protocol;
	cfg->fc_scope = rtm->rtm_scope;
	cfg->fc_type = rtm->rtm_type;
	cfg->fc_flags = rtm->rtm_flags;
	cfg->fc_nlflags = nlh->nlmsg_flags;

619
	cfg->fc_nlinfo.portid = NETLINK_CB(skb).portid;
620
	cfg->fc_nlinfo.nlh = nlh;
621
	cfg->fc_nlinfo.nl_net = net;
622

623 624 625 626 627
	if (cfg->fc_type > RTN_MAX) {
		err = -EINVAL;
		goto errout;
	}

628
	nlmsg_for_each_attr(attr, nlh, sizeof(struct rtmsg), remaining) {
629
		switch (nla_type(attr)) {
630
		case RTA_DST:
631
			cfg->fc_dst = nla_get_be32(attr);
632 633 634 635 636
			break;
		case RTA_OIF:
			cfg->fc_oif = nla_get_u32(attr);
			break;
		case RTA_GATEWAY:
637
			cfg->fc_gw = nla_get_be32(attr);
638 639 640 641 642
			break;
		case RTA_PRIORITY:
			cfg->fc_priority = nla_get_u32(attr);
			break;
		case RTA_PREFSRC:
643
			cfg->fc_prefsrc = nla_get_be32(attr);
644 645 646 647 648 649 650 651 652 653 654 655 656 657 658
			break;
		case RTA_METRICS:
			cfg->fc_mx = nla_data(attr);
			cfg->fc_mx_len = nla_len(attr);
			break;
		case RTA_MULTIPATH:
			cfg->fc_mp = nla_data(attr);
			cfg->fc_mp_len = nla_len(attr);
			break;
		case RTA_FLOW:
			cfg->fc_flow = nla_get_u32(attr);
			break;
		case RTA_TABLE:
			cfg->fc_table = nla_get_u32(attr);
			break;
L
Linus Torvalds 已提交
659 660
		}
	}
661

L
Linus Torvalds 已提交
662
	return 0;
663 664
errout:
	return err;
L
Linus Torvalds 已提交
665 666
}

667
static int inet_rtm_delroute(struct sk_buff *skb, struct nlmsghdr *nlh)
L
Linus Torvalds 已提交
668
{
669
	struct net *net = sock_net(skb->sk);
670 671 672
	struct fib_config cfg;
	struct fib_table *tb;
	int err;
L
Linus Torvalds 已提交
673

674
	err = rtm_to_fib_config(net, skb, nlh, &cfg);
675 676
	if (err < 0)
		goto errout;
L
Linus Torvalds 已提交
677

678
	tb = fib_get_table(net, cfg.fc_table);
679
	if (!tb) {
680 681 682 683
		err = -ESRCH;
		goto errout;
	}

684
	err = fib_table_delete(tb, &cfg);
685 686
errout:
	return err;
L
Linus Torvalds 已提交
687 688
}

689
static int inet_rtm_newroute(struct sk_buff *skb, struct nlmsghdr *nlh)
L
Linus Torvalds 已提交
690
{
691
	struct net *net = sock_net(skb->sk);
692 693 694
	struct fib_config cfg;
	struct fib_table *tb;
	int err;
L
Linus Torvalds 已提交
695

696
	err = rtm_to_fib_config(net, skb, nlh, &cfg);
697 698
	if (err < 0)
		goto errout;
L
Linus Torvalds 已提交
699

700
	tb = fib_new_table(net, cfg.fc_table);
701
	if (!tb) {
702 703 704 705
		err = -ENOBUFS;
		goto errout;
	}

706
	err = fib_table_insert(tb, &cfg);
707 708
errout:
	return err;
L
Linus Torvalds 已提交
709 710
}

711
static int inet_dump_fib(struct sk_buff *skb, struct netlink_callback *cb)
L
Linus Torvalds 已提交
712
{
713
	struct net *net = sock_net(skb->sk);
714 715
	unsigned int h, s_h;
	unsigned int e = 0, s_e;
L
Linus Torvalds 已提交
716
	struct fib_table *tb;
717
	struct hlist_head *head;
718
	int dumped = 0;
L
Linus Torvalds 已提交
719

720 721
	if (nlmsg_len(cb->nlh) >= sizeof(struct rtmsg) &&
	    ((struct rtmsg *) nlmsg_data(cb->nlh))->rtm_flags & RTM_F_CLONED)
722
		return skb->len;
L
Linus Torvalds 已提交
723

724 725 726
	s_h = cb->args[0];
	s_e = cb->args[1];

727 728
	rcu_read_lock();

729 730
	for (h = s_h; h < FIB_TABLE_HASHSZ; h++, s_e = 0) {
		e = 0;
731
		head = &net->ipv4.fib_table_hash[h];
732
		hlist_for_each_entry_rcu(tb, head, tb_hlist) {
733 734 735 736
			if (e < s_e)
				goto next;
			if (dumped)
				memset(&cb->args[2], 0, sizeof(cb->args) -
737
						 2 * sizeof(cb->args[0]));
738
			if (fib_table_dump(tb, skb, cb) < 0)
739 740 741 742 743
				goto out;
			dumped = 1;
next:
			e++;
		}
L
Linus Torvalds 已提交
744
	}
745
out:
746 747
	rcu_read_unlock();

748 749
	cb->args[1] = e;
	cb->args[0] = h;
L
Linus Torvalds 已提交
750 751 752 753 754

	return skb->len;
}

/* Prepare and feed intra-kernel routing request.
E
Eric Dumazet 已提交
755 756 757 758
 * Really, it should be netlink message, but :-( netlink
 * can be not configured, so that we feed it directly
 * to fib engine. It is legal, because all events occur
 * only when netlink is already locked.
L
Linus Torvalds 已提交
759
 */
A
Al Viro 已提交
760
static void fib_magic(int cmd, int type, __be32 dst, int dst_len, struct in_ifaddr *ifa)
L
Linus Torvalds 已提交
761
{
762
	struct net *net = dev_net(ifa->ifa_dev->dev);
763 764 765 766 767 768 769 770 771
	struct fib_table *tb;
	struct fib_config cfg = {
		.fc_protocol = RTPROT_KERNEL,
		.fc_type = type,
		.fc_dst = dst,
		.fc_dst_len = dst_len,
		.fc_prefsrc = ifa->ifa_local,
		.fc_oif = ifa->ifa_dev->dev->ifindex,
		.fc_nlflags = NLM_F_CREATE | NLM_F_APPEND,
772
		.fc_nlinfo = {
773
			.nl_net = net,
774
		},
775
	};
L
Linus Torvalds 已提交
776 777

	if (type == RTN_UNICAST)
778
		tb = fib_new_table(net, RT_TABLE_MAIN);
L
Linus Torvalds 已提交
779
	else
780
		tb = fib_new_table(net, RT_TABLE_LOCAL);
L
Linus Torvalds 已提交
781

782
	if (!tb)
L
Linus Torvalds 已提交
783 784
		return;

785
	cfg.fc_table = tb->tb_id;
L
Linus Torvalds 已提交
786

787 788 789 790
	if (type != RTN_LOCAL)
		cfg.fc_scope = RT_SCOPE_LINK;
	else
		cfg.fc_scope = RT_SCOPE_HOST;
L
Linus Torvalds 已提交
791 792

	if (cmd == RTM_NEWROUTE)
793
		fib_table_insert(tb, &cfg);
L
Linus Torvalds 已提交
794
	else
795
		fib_table_delete(tb, &cfg);
L
Linus Torvalds 已提交
796 797
}

798
void fib_add_ifaddr(struct in_ifaddr *ifa)
L
Linus Torvalds 已提交
799 800 801 802
{
	struct in_device *in_dev = ifa->ifa_dev;
	struct net_device *dev = in_dev->dev;
	struct in_ifaddr *prim = ifa;
A
Al Viro 已提交
803 804
	__be32 mask = ifa->ifa_mask;
	__be32 addr = ifa->ifa_local;
E
Eric Dumazet 已提交
805
	__be32 prefix = ifa->ifa_address & mask;
L
Linus Torvalds 已提交
806

E
Eric Dumazet 已提交
807
	if (ifa->ifa_flags & IFA_F_SECONDARY) {
L
Linus Torvalds 已提交
808
		prim = inet_ifa_byprefix(in_dev, prefix, mask);
809
		if (!prim) {
J
Joe Perches 已提交
810
			pr_warn("%s: bug: prim == NULL\n", __func__);
L
Linus Torvalds 已提交
811 812 813 814 815 816
			return;
		}
	}

	fib_magic(RTM_NEWROUTE, RTN_LOCAL, addr, 32, prim);

E
Eric Dumazet 已提交
817
	if (!(dev->flags & IFF_UP))
L
Linus Torvalds 已提交
818 819 820
		return;

	/* Add broadcast address, if it is explicitly assigned. */
A
Al Viro 已提交
821
	if (ifa->ifa_broadcast && ifa->ifa_broadcast != htonl(0xFFFFFFFF))
L
Linus Torvalds 已提交
822 823
		fib_magic(RTM_NEWROUTE, RTN_BROADCAST, ifa->ifa_broadcast, 32, prim);

E
Eric Dumazet 已提交
824
	if (!ipv4_is_zeronet(prefix) && !(ifa->ifa_flags & IFA_F_SECONDARY) &&
L
Linus Torvalds 已提交
825
	    (prefix != addr || ifa->ifa_prefixlen < 32)) {
E
Eric Dumazet 已提交
826 827 828
		fib_magic(RTM_NEWROUTE,
			  dev->flags & IFF_LOOPBACK ? RTN_LOCAL : RTN_UNICAST,
			  prefix, ifa->ifa_prefixlen, prim);
L
Linus Torvalds 已提交
829 830 831 832

		/* Add network specific broadcasts, when it takes a sense */
		if (ifa->ifa_prefixlen < 31) {
			fib_magic(RTM_NEWROUTE, RTN_BROADCAST, prefix, 32, prim);
E
Eric Dumazet 已提交
833 834
			fib_magic(RTM_NEWROUTE, RTN_BROADCAST, prefix | ~mask,
				  32, prim);
L
Linus Torvalds 已提交
835 836 837 838
		}
	}
}

839 840 841 842 843 844
/* Delete primary or secondary address.
 * Optionally, on secondary address promotion consider the addresses
 * from subnet iprim as deleted, even if they are in device list.
 * In this case the secondary ifa can be in device list.
 */
void fib_del_ifaddr(struct in_ifaddr *ifa, struct in_ifaddr *iprim)
L
Linus Torvalds 已提交
845 846 847 848
{
	struct in_device *in_dev = ifa->ifa_dev;
	struct net_device *dev = in_dev->dev;
	struct in_ifaddr *ifa1;
849
	struct in_ifaddr *prim = ifa, *prim1 = NULL;
E
Eric Dumazet 已提交
850 851
	__be32 brd = ifa->ifa_address | ~ifa->ifa_mask;
	__be32 any = ifa->ifa_address & ifa->ifa_mask;
L
Linus Torvalds 已提交
852 853 854 855
#define LOCAL_OK	1
#define BRD_OK		2
#define BRD0_OK		4
#define BRD1_OK		8
856
	unsigned int ok = 0;
857 858 859
	int subnet = 0;		/* Primary network */
	int gone = 1;		/* Address is missing */
	int same_prefsrc = 0;	/* Another primary with same IP */
L
Linus Torvalds 已提交
860

861
	if (ifa->ifa_flags & IFA_F_SECONDARY) {
L
Linus Torvalds 已提交
862
		prim = inet_ifa_byprefix(in_dev, any, ifa->ifa_mask);
863
		if (!prim) {
J
Joe Perches 已提交
864
			pr_warn("%s: bug: prim == NULL\n", __func__);
L
Linus Torvalds 已提交
865 866
			return;
		}
867
		if (iprim && iprim != prim) {
J
Joe Perches 已提交
868
			pr_warn("%s: bug: iprim != prim\n", __func__);
869 870 871 872 873 874 875 876
			return;
		}
	} else if (!ipv4_is_zeronet(any) &&
		   (any != ifa->ifa_local || ifa->ifa_prefixlen < 32)) {
		fib_magic(RTM_DELROUTE,
			  dev->flags & IFF_LOOPBACK ? RTN_LOCAL : RTN_UNICAST,
			  any, ifa->ifa_prefixlen, prim);
		subnet = 1;
L
Linus Torvalds 已提交
877 878 879
	}

	/* Deletion is more complicated than add.
E
Eric Dumazet 已提交
880 881 882
	 * We should take care of not to delete too much :-)
	 *
	 * Scan address list to be sure that addresses are really gone.
L
Linus Torvalds 已提交
883 884 885
	 */

	for (ifa1 = in_dev->ifa_list; ifa1; ifa1 = ifa1->ifa_next) {
886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928
		if (ifa1 == ifa) {
			/* promotion, keep the IP */
			gone = 0;
			continue;
		}
		/* Ignore IFAs from our subnet */
		if (iprim && ifa1->ifa_mask == iprim->ifa_mask &&
		    inet_ifa_match(ifa1->ifa_address, iprim))
			continue;

		/* Ignore ifa1 if it uses different primary IP (prefsrc) */
		if (ifa1->ifa_flags & IFA_F_SECONDARY) {
			/* Another address from our subnet? */
			if (ifa1->ifa_mask == prim->ifa_mask &&
			    inet_ifa_match(ifa1->ifa_address, prim))
				prim1 = prim;
			else {
				/* We reached the secondaries, so
				 * same_prefsrc should be determined.
				 */
				if (!same_prefsrc)
					continue;
				/* Search new prim1 if ifa1 is not
				 * using the current prim1
				 */
				if (!prim1 ||
				    ifa1->ifa_mask != prim1->ifa_mask ||
				    !inet_ifa_match(ifa1->ifa_address, prim1))
					prim1 = inet_ifa_byprefix(in_dev,
							ifa1->ifa_address,
							ifa1->ifa_mask);
				if (!prim1)
					continue;
				if (prim1->ifa_local != prim->ifa_local)
					continue;
			}
		} else {
			if (prim->ifa_local != ifa1->ifa_local)
				continue;
			prim1 = ifa1;
			if (prim != prim1)
				same_prefsrc = 1;
		}
L
Linus Torvalds 已提交
929 930 931 932 933 934 935 936
		if (ifa->ifa_local == ifa1->ifa_local)
			ok |= LOCAL_OK;
		if (ifa->ifa_broadcast == ifa1->ifa_broadcast)
			ok |= BRD_OK;
		if (brd == ifa1->ifa_broadcast)
			ok |= BRD1_OK;
		if (any == ifa1->ifa_broadcast)
			ok |= BRD0_OK;
937 938 939 940 941 942 943 944 945 946 947 948 949 950 951
		/* primary has network specific broadcasts */
		if (prim1 == ifa1 && ifa1->ifa_prefixlen < 31) {
			__be32 brd1 = ifa1->ifa_address | ~ifa1->ifa_mask;
			__be32 any1 = ifa1->ifa_address & ifa1->ifa_mask;

			if (!ipv4_is_zeronet(any1)) {
				if (ifa->ifa_broadcast == brd1 ||
				    ifa->ifa_broadcast == any1)
					ok |= BRD_OK;
				if (brd == brd1 || brd == any1)
					ok |= BRD1_OK;
				if (any == brd1 || any == any1)
					ok |= BRD0_OK;
			}
		}
L
Linus Torvalds 已提交
952 953
	}

E
Eric Dumazet 已提交
954
	if (!(ok & BRD_OK))
L
Linus Torvalds 已提交
955
		fib_magic(RTM_DELROUTE, RTN_BROADCAST, ifa->ifa_broadcast, 32, prim);
956 957 958 959 960 961
	if (subnet && ifa->ifa_prefixlen < 31) {
		if (!(ok & BRD1_OK))
			fib_magic(RTM_DELROUTE, RTN_BROADCAST, brd, 32, prim);
		if (!(ok & BRD0_OK))
			fib_magic(RTM_DELROUTE, RTN_BROADCAST, any, 32, prim);
	}
E
Eric Dumazet 已提交
962
	if (!(ok & LOCAL_OK)) {
L
Linus Torvalds 已提交
963 964 965
		fib_magic(RTM_DELROUTE, RTN_LOCAL, ifa->ifa_local, 32, prim);

		/* Check, that this local address finally disappeared. */
966 967
		if (gone &&
		    inet_addr_type(dev_net(dev), ifa->ifa_local) != RTN_LOCAL) {
L
Linus Torvalds 已提交
968
			/* And the last, but not the least thing.
E
Eric Dumazet 已提交
969 970 971 972 973
			 * We must flush stray FIB entries.
			 *
			 * First of all, we scan fib_info list searching
			 * for stray nexthop entries, then ignite fib_flush.
			 */
974 975
			if (fib_sync_down_addr(dev_net(dev), ifa->ifa_local))
				fib_flush(dev_net(dev));
L
Linus Torvalds 已提交
976 977 978 979 980 981 982 983
		}
	}
#undef LOCAL_OK
#undef BRD_OK
#undef BRD0_OK
#undef BRD1_OK
}

984
static void nl_fib_lookup(struct net *net, struct fib_result_nl *frn)
985
{
986

987
	struct fib_result       res;
D
David S. Miller 已提交
988 989 990 991 992
	struct flowi4           fl4 = {
		.flowi4_mark = frn->fl_mark,
		.daddr = frn->fl_addr,
		.flowi4_tos = frn->fl_tos,
		.flowi4_scope = frn->fl_scope,
E
Eric Dumazet 已提交
993
	};
994 995 996 997 998
	struct fib_table *tb;

	rcu_read_lock();

	tb = fib_get_table(net, frn->tb_id_in);
999 1000

	frn->err = -ENOENT;
1001 1002 1003 1004
	if (tb) {
		local_bh_disable();

		frn->tb_id = tb->tb_id;
D
David S. Miller 已提交
1005
		frn->err = fib_table_lookup(tb, &fl4, &res, FIB_LOOKUP_NOREF);
1006 1007 1008 1009 1010 1011 1012 1013 1014

		if (!frn->err) {
			frn->prefixlen = res.prefixlen;
			frn->nh_sel = res.nh_sel;
			frn->type = res.type;
			frn->scope = res.scope;
		}
		local_bh_enable();
	}
1015 1016

	rcu_read_unlock();
1017 1018
}

1019
static void nl_fib_input(struct sk_buff *skb)
1020
{
1021
	struct net *net;
1022
	struct fib_result_nl *frn;
1023
	struct nlmsghdr *nlh;
1024
	u32 portid;
1025

1026
	net = sock_net(skb->sk);
1027
	nlh = nlmsg_hdr(skb);
1028 1029
	if (skb->len < NLMSG_HDRLEN || skb->len < nlh->nlmsg_len ||
	    nlmsg_len(nlh) < sizeof(*frn))
1030
		return;
1031

1032
	skb = netlink_skb_clone(skb, GFP_KERNEL);
1033
	if (!skb)
1034 1035
		return;
	nlh = nlmsg_hdr(skb);
1036

1037
	frn = (struct fib_result_nl *) nlmsg_data(nlh);
1038
	nl_fib_lookup(net, frn);
1039

R
Rami Rosen 已提交
1040
	portid = NETLINK_CB(skb).portid;      /* netlink portid */
1041
	NETLINK_CB(skb).portid = 0;        /* from kernel */
1042
	NETLINK_CB(skb).dst_group = 0;  /* unicast */
1043
	netlink_unicast(net->ipv4.fibnl, skb, portid, MSG_DONTWAIT);
1044
}
1045

1046
static int __net_init nl_fib_lookup_init(struct net *net)
1047
{
1048
	struct sock *sk;
1049 1050 1051 1052
	struct netlink_kernel_cfg cfg = {
		.input	= nl_fib_input,
	};

1053
	sk = netlink_kernel_create(net, NETLINK_FIB_LOOKUP, &cfg);
1054
	if (!sk)
1055
		return -EAFNOSUPPORT;
1056
	net->ipv4.fibnl = sk;
1057 1058 1059 1060 1061
	return 0;
}

static void nl_fib_lookup_exit(struct net *net)
{
1062
	netlink_kernel_release(net->ipv4.fibnl);
1063
	net->ipv4.fibnl = NULL;
1064 1065
}

1066
static void fib_disable_ip(struct net_device *dev, unsigned long event)
L
Linus Torvalds 已提交
1067
{
1068
	if (fib_sync_down_dev(dev, event))
1069
		fib_flush(dev_net(dev));
1070
	rt_cache_flush(dev_net(dev));
L
Linus Torvalds 已提交
1071 1072 1073 1074 1075
	arp_ifdown(dev);
}

static int fib_inetaddr_event(struct notifier_block *this, unsigned long event, void *ptr)
{
1076
	struct in_ifaddr *ifa = (struct in_ifaddr *)ptr;
1077
	struct net_device *dev = ifa->ifa_dev->dev;
1078
	struct net *net = dev_net(dev);
L
Linus Torvalds 已提交
1079 1080 1081 1082 1083

	switch (event) {
	case NETDEV_UP:
		fib_add_ifaddr(ifa);
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1084
		fib_sync_up(dev, RTNH_F_DEAD);
L
Linus Torvalds 已提交
1085
#endif
1086
		atomic_inc(&net->ipv4.dev_addr_genid);
1087
		rt_cache_flush(dev_net(dev));
L
Linus Torvalds 已提交
1088 1089
		break;
	case NETDEV_DOWN:
1090
		fib_del_ifaddr(ifa, NULL);
1091
		atomic_inc(&net->ipv4.dev_addr_genid);
1092
		if (!ifa->ifa_dev->ifa_list) {
L
Linus Torvalds 已提交
1093
			/* Last address was deleted from this interface.
E
Eric Dumazet 已提交
1094
			 * Disable IP.
L
Linus Torvalds 已提交
1095
			 */
1096
			fib_disable_ip(dev, event);
L
Linus Torvalds 已提交
1097
		} else {
1098
			rt_cache_flush(dev_net(dev));
L
Linus Torvalds 已提交
1099 1100 1101 1102 1103 1104 1105 1106
		}
		break;
	}
	return NOTIFY_DONE;
}

static int fib_netdev_event(struct notifier_block *this, unsigned long event, void *ptr)
{
1107
	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
1108
	struct in_device *in_dev;
1109
	struct net *net = dev_net(dev);
1110
	unsigned int flags;
L
Linus Torvalds 已提交
1111 1112

	if (event == NETDEV_UNREGISTER) {
1113
		fib_disable_ip(dev, event);
1114
		rt_flush_dev(dev);
L
Linus Torvalds 已提交
1115 1116 1117
		return NOTIFY_DONE;
	}

1118
	in_dev = __in_dev_get_rtnl(dev);
1119 1120
	if (!in_dev)
		return NOTIFY_DONE;
1121

L
Linus Torvalds 已提交
1122 1123 1124 1125 1126 1127
	switch (event) {
	case NETDEV_UP:
		for_ifa(in_dev) {
			fib_add_ifaddr(ifa);
		} endfor_ifa(in_dev);
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1128
		fib_sync_up(dev, RTNH_F_DEAD);
L
Linus Torvalds 已提交
1129
#endif
1130
		atomic_inc(&net->ipv4.dev_addr_genid);
1131
		rt_cache_flush(net);
L
Linus Torvalds 已提交
1132 1133
		break;
	case NETDEV_DOWN:
1134
		fib_disable_ip(dev, event);
L
Linus Torvalds 已提交
1135 1136
		break;
	case NETDEV_CHANGE:
1137 1138 1139 1140 1141 1142 1143
		flags = dev_get_flags(dev);
		if (flags & (IFF_RUNNING | IFF_LOWER_UP))
			fib_sync_up(dev, RTNH_F_LINKDOWN);
		else
			fib_sync_down_dev(dev, event);
		/* fall through */
	case NETDEV_CHANGEMTU:
1144
		rt_cache_flush(net);
L
Linus Torvalds 已提交
1145 1146 1147 1148 1149 1150
		break;
	}
	return NOTIFY_DONE;
}

static struct notifier_block fib_inetaddr_notifier = {
1151
	.notifier_call = fib_inetaddr_event,
L
Linus Torvalds 已提交
1152 1153 1154
};

static struct notifier_block fib_netdev_notifier = {
1155
	.notifier_call = fib_netdev_event,
L
Linus Torvalds 已提交
1156 1157
};

1158
static int __net_init ip_fib_net_init(struct net *net)
L
Linus Torvalds 已提交
1159
{
1160
	int err;
1161 1162 1163 1164
	size_t size = sizeof(struct hlist_head) * FIB_TABLE_HASHSZ;

	/* Avoid false sharing : Use at least a full cache line */
	size = max_t(size_t, size, L1_CACHE_BYTES);
1165

1166
	net->ipv4.fib_table_hash = kzalloc(size, GFP_KERNEL);
1167
	if (!net->ipv4.fib_table_hash)
1168 1169
		return -ENOMEM;

1170 1171 1172 1173 1174 1175 1176 1177
	err = fib4_rules_init(net);
	if (err < 0)
		goto fail;
	return 0;

fail:
	kfree(net->ipv4.fib_table_hash);
	return err;
1178
}
L
Linus Torvalds 已提交
1179

1180
static void ip_fib_net_exit(struct net *net)
1181 1182 1183
{
	unsigned int i;

1184
	rtnl_lock();
1185 1186 1187 1188 1189
#ifdef CONFIG_IP_MULTIPLE_TABLES
	RCU_INIT_POINTER(net->ipv4.fib_local, NULL);
	RCU_INIT_POINTER(net->ipv4.fib_main, NULL);
	RCU_INIT_POINTER(net->ipv4.fib_default, NULL);
#endif
1190
	for (i = 0; i < FIB_TABLE_HASHSZ; i++) {
1191
		struct hlist_head *head = &net->ipv4.fib_table_hash[i];
1192
		struct hlist_node *tmp;
1193 1194
		struct fib_table *tb;

1195 1196
		hlist_for_each_entry_safe(tb, tmp, head, tb_hlist) {
			hlist_del(&tb->tb_hlist);
1197
			fib_table_flush(tb);
1198
			fib_free_table(tb);
1199 1200
		}
	}
1201 1202 1203 1204

#ifdef CONFIG_IP_MULTIPLE_TABLES
	fib4_rules_exit(net);
#endif
1205
	rtnl_unlock();
1206
	kfree(net->ipv4.fib_table_hash);
1207 1208 1209 1210 1211 1212
}

static int __net_init fib_net_init(struct net *net)
{
	int error;

1213 1214 1215
#ifdef CONFIG_IP_ROUTE_CLASSID
	net->ipv4.fib_num_tclassid_users = 0;
#endif
1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248
	error = ip_fib_net_init(net);
	if (error < 0)
		goto out;
	error = nl_fib_lookup_init(net);
	if (error < 0)
		goto out_nlfl;
	error = fib_proc_init(net);
	if (error < 0)
		goto out_proc;
out:
	return error;

out_proc:
	nl_fib_lookup_exit(net);
out_nlfl:
	ip_fib_net_exit(net);
	goto out;
}

static void __net_exit fib_net_exit(struct net *net)
{
	fib_proc_exit(net);
	nl_fib_lookup_exit(net);
	ip_fib_net_exit(net);
}

static struct pernet_operations fib_net_ops = {
	.init = fib_net_init,
	.exit = fib_net_exit,
};

void __init ip_fib_init(void)
{
1249 1250 1251
	rtnl_register(PF_INET, RTM_NEWROUTE, inet_rtm_newroute, NULL, NULL);
	rtnl_register(PF_INET, RTM_DELROUTE, inet_rtm_delroute, NULL, NULL);
	rtnl_register(PF_INET, RTM_GETROUTE, NULL, inet_dump_fib, NULL);
1252 1253 1254 1255

	register_pernet_subsys(&fib_net_ops);
	register_netdevice_notifier(&fib_netdev_notifier);
	register_inetaddr_notifier(&fib_inetaddr_notifier);
1256

1257
	fib_trie_init();
L
Linus Torvalds 已提交
1258
}