fib_frontend.c 29.5 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
/*
 * INET		An implementation of the TCP/IP protocol suite for the LINUX
 *		operating system.  INET is implemented using the  BSD Socket
 *		interface as the means of communication with the user level.
 *
 *		IPv4 Forwarding Information Base: FIB frontend.
 *
 * Authors:	Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 */

#include <linux/module.h>
#include <asm/uaccess.h>
#include <linux/bitops.h>
19
#include <linux/capability.h>
L
Linus Torvalds 已提交
20 21 22 23 24 25 26 27 28
#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/mm.h>
#include <linux/string.h>
#include <linux/socket.h>
#include <linux/sockios.h>
#include <linux/errno.h>
#include <linux/in.h>
#include <linux/inet.h>
29
#include <linux/inetdevice.h>
L
Linus Torvalds 已提交
30
#include <linux/netdevice.h>
31
#include <linux/if_addr.h>
L
Linus Torvalds 已提交
32 33
#include <linux/if_arp.h>
#include <linux/skbuff.h>
34
#include <linux/cache.h>
L
Linus Torvalds 已提交
35
#include <linux/init.h>
36
#include <linux/list.h>
37
#include <linux/slab.h>
L
Linus Torvalds 已提交
38 39 40 41 42 43 44 45

#include <net/ip.h>
#include <net/protocol.h>
#include <net/route.h>
#include <net/tcp.h>
#include <net/sock.h>
#include <net/arp.h>
#include <net/ip_fib.h>
46
#include <net/rtnetlink.h>
47
#include <net/xfrm.h>
48
#include <net/vrf.h>
L
Linus Torvalds 已提交
49 50 51

#ifndef CONFIG_IP_MULTIPLE_TABLES

52
static int __net_init fib4_rules_init(struct net *net)
53
{
54 55
	struct fib_table *local_table, *main_table;

56
	main_table  = fib_trie_table(RT_TABLE_MAIN, NULL);
57
	if (!main_table)
58
		return -ENOMEM;
59

60
	local_table = fib_trie_table(RT_TABLE_LOCAL, main_table);
61
	if (!local_table)
62
		goto fail;
63

64
	hlist_add_head_rcu(&local_table->tb_hlist,
65
				&net->ipv4.fib_table_hash[TABLE_LOCAL_INDEX]);
66
	hlist_add_head_rcu(&main_table->tb_hlist,
67
				&net->ipv4.fib_table_hash[TABLE_MAIN_INDEX]);
68 69 70
	return 0;

fail:
71
	fib_free_table(main_table);
72
	return -ENOMEM;
73
}
74
#else
L
Linus Torvalds 已提交
75

76
struct fib_table *fib_new_table(struct net *net, u32 id)
L
Linus Torvalds 已提交
77
{
78
	struct fib_table *tb, *alias = NULL;
79
	unsigned int h;
L
Linus Torvalds 已提交
80

81 82
	if (id == 0)
		id = RT_TABLE_MAIN;
83
	tb = fib_get_table(net, id);
84 85
	if (tb)
		return tb;
86

87 88 89 90
	if (id == RT_TABLE_LOCAL)
		alias = fib_new_table(net, RT_TABLE_MAIN);

	tb = fib_trie_table(id, alias);
L
Linus Torvalds 已提交
91 92
	if (!tb)
		return NULL;
93 94 95

	switch (id) {
	case RT_TABLE_LOCAL:
96
		rcu_assign_pointer(net->ipv4.fib_local, tb);
97 98
		break;
	case RT_TABLE_MAIN:
99
		rcu_assign_pointer(net->ipv4.fib_main, tb);
100 101
		break;
	case RT_TABLE_DEFAULT:
102
		rcu_assign_pointer(net->ipv4.fib_default, tb);
103 104 105 106 107
		break;
	default:
		break;
	}

108
	h = id & (FIB_TABLE_HASHSZ - 1);
109
	hlist_add_head_rcu(&tb->tb_hlist, &net->ipv4.fib_table_hash[h]);
L
Linus Torvalds 已提交
110 111 112
	return tb;
}

113
/* caller must hold either rtnl or rcu read lock */
114
struct fib_table *fib_get_table(struct net *net, u32 id)
115 116
{
	struct fib_table *tb;
117
	struct hlist_head *head;
118
	unsigned int h;
L
Linus Torvalds 已提交
119

120 121 122
	if (id == 0)
		id = RT_TABLE_MAIN;
	h = id & (FIB_TABLE_HASHSZ - 1);
123 124

	head = &net->ipv4.fib_table_hash[h];
125
	hlist_for_each_entry_rcu(tb, head, tb_hlist) {
126
		if (tb->tb_id == id)
127 128 129 130
			return tb;
	}
	return NULL;
}
L
Linus Torvalds 已提交
131 132
#endif /* CONFIG_IP_MULTIPLE_TABLES */

133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159
static void fib_replace_table(struct net *net, struct fib_table *old,
			      struct fib_table *new)
{
#ifdef CONFIG_IP_MULTIPLE_TABLES
	switch (new->tb_id) {
	case RT_TABLE_LOCAL:
		rcu_assign_pointer(net->ipv4.fib_local, new);
		break;
	case RT_TABLE_MAIN:
		rcu_assign_pointer(net->ipv4.fib_main, new);
		break;
	case RT_TABLE_DEFAULT:
		rcu_assign_pointer(net->ipv4.fib_default, new);
		break;
	default:
		break;
	}

#endif
	/* replace the old table in the hlist */
	hlist_replace_rcu(&old->tb_hlist, &new->tb_hlist);
}

int fib_unmerge(struct net *net)
{
	struct fib_table *old, *new;

160
	/* attempt to fetch local table if it has been allocated */
161
	old = fib_get_table(net, RT_TABLE_LOCAL);
162 163
	if (!old)
		return 0;
164

165
	new = fib_trie_unmerge(old);
166 167 168 169 170 171 172 173 174 175 176 177
	if (!new)
		return -ENOMEM;

	/* replace merged table with clean table */
	if (new != old) {
		fib_replace_table(net, old, new);
		fib_free_table(old);
	}

	return 0;
}

178
static void fib_flush(struct net *net)
L
Linus Torvalds 已提交
179 180
{
	int flushed = 0;
181
	unsigned int h;
L
Linus Torvalds 已提交
182

183
	for (h = 0; h < FIB_TABLE_HASHSZ; h++) {
184 185 186 187 188
		struct hlist_head *head = &net->ipv4.fib_table_hash[h];
		struct hlist_node *tmp;
		struct fib_table *tb;

		hlist_for_each_entry_safe(tb, tmp, head, tb_hlist)
189
			flushed += fib_table_flush(tb);
L
Linus Torvalds 已提交
190 191 192
	}

	if (flushed)
193
		rt_cache_flush(net);
L
Linus Torvalds 已提交
194 195
}

196 197 198 199 200 201 202 203 204 205 206 207 208
void fib_flush_external(struct net *net)
{
	struct fib_table *tb;
	struct hlist_head *head;
	unsigned int h;

	for (h = 0; h < FIB_TABLE_HASHSZ; h++) {
		head = &net->ipv4.fib_table_hash[h];
		hlist_for_each_entry(tb, head, tb_hlist)
			fib_table_flush_external(tb);
	}
}

209 210 211 212
/*
 * Find address type as if only "dev" was present in the system. If
 * on_dev is NULL then all interfaces are taken into consideration.
 */
213 214 215
static inline unsigned int __inet_dev_addr_type(struct net *net,
						const struct net_device *dev,
						__be32 addr)
L
Linus Torvalds 已提交
216
{
D
David S. Miller 已提交
217
	struct flowi4		fl4 = { .daddr = addr };
L
Linus Torvalds 已提交
218
	struct fib_result	res;
219
	unsigned int ret = RTN_BROADCAST;
220
	struct fib_table *local_table;
L
Linus Torvalds 已提交
221

222
	if (ipv4_is_zeronet(addr) || ipv4_is_lbcast(addr))
L
Linus Torvalds 已提交
223
		return RTN_BROADCAST;
224
	if (ipv4_is_multicast(addr))
L
Linus Torvalds 已提交
225 226
		return RTN_MULTICAST;

227 228
	rcu_read_lock();

229
	local_table = fib_get_table(net, RT_TABLE_LOCAL);
230
	if (local_table) {
L
Linus Torvalds 已提交
231
		ret = RTN_UNICAST;
D
David S. Miller 已提交
232
		if (!fib_table_lookup(local_table, &fl4, &res, FIB_LOOKUP_NOREF)) {
233 234
			if (!dev || dev == res.fi->fib_dev)
				ret = res.type;
L
Linus Torvalds 已提交
235 236
		}
	}
237 238

	rcu_read_unlock();
L
Linus Torvalds 已提交
239 240 241
	return ret;
}

242
unsigned int inet_addr_type(struct net *net, __be32 addr)
243
{
244
	return __inet_dev_addr_type(net, NULL, addr);
245
}
E
Eric Dumazet 已提交
246
EXPORT_SYMBOL(inet_addr_type);
247

248 249
unsigned int inet_dev_addr_type(struct net *net, const struct net_device *dev,
				__be32 addr)
250
{
E
Eric Dumazet 已提交
251
	return __inet_dev_addr_type(net, dev, addr);
252
}
E
Eric Dumazet 已提交
253
EXPORT_SYMBOL(inet_dev_addr_type);
254

255 256 257 258 259
__be32 fib_compute_spec_dst(struct sk_buff *skb)
{
	struct net_device *dev = skb->dev;
	struct in_device *in_dev;
	struct fib_result res;
260
	struct rtable *rt;
261 262
	struct flowi4 fl4;
	struct net *net;
263
	int scope;
264

265
	rt = skb_rtable(skb);
266 267
	if ((rt->rt_flags & (RTCF_BROADCAST | RTCF_MULTICAST | RTCF_LOCAL)) ==
	    RTCF_LOCAL)
268 269 270 271 272 273
		return ip_hdr(skb)->daddr;

	in_dev = __in_dev_get_rcu(dev);
	BUG_ON(!in_dev);

	net = dev_net(dev);
274 275 276 277

	scope = RT_SCOPE_UNIVERSE;
	if (!ipv4_is_zeronet(ip_hdr(skb)->saddr)) {
		fl4.flowi4_oif = 0;
278
		fl4.flowi4_iif = LOOPBACK_IFINDEX;
279 280 281 282 283
		fl4.daddr = ip_hdr(skb)->saddr;
		fl4.saddr = 0;
		fl4.flowi4_tos = RT_TOS(ip_hdr(skb)->tos);
		fl4.flowi4_scope = scope;
		fl4.flowi4_mark = IN_DEV_SRC_VMARK(in_dev) ? skb->mark : 0;
284
		fl4.flowi4_tun_key.tun_id = 0;
285
		if (!fib_lookup(net, &fl4, &res, 0))
286 287 288 289 290 291
			return FIB_RES_PREFSRC(net, res);
	} else {
		scope = RT_SCOPE_LINK;
	}

	return inet_select_addr(dev, ip_hdr(skb)->saddr, scope);
292 293
}

L
Linus Torvalds 已提交
294
/* Given (packet source, input interface) and optional (dst, oif, tos):
E
Eric Dumazet 已提交
295 296 297 298 299
 * - (main) check, that source is valid i.e. not broadcast or our local
 *   address.
 * - figure out what "logical" interface this packet arrived
 *   and calculate "specific destination" address.
 * - check, that packet arrived from expected physical interface.
E
Eric Dumazet 已提交
300
 * called with rcu_read_lock()
L
Linus Torvalds 已提交
301
 */
302 303 304
static int __fib_validate_source(struct sk_buff *skb, __be32 src, __be32 dst,
				 u8 tos, int oif, struct net_device *dev,
				 int rpf, struct in_device *idev, u32 *itag)
L
Linus Torvalds 已提交
305
{
306
	int ret, no_addr;
L
Linus Torvalds 已提交
307
	struct fib_result res;
308
	struct flowi4 fl4;
309
	struct net *net;
310
	bool dev_match;
L
Linus Torvalds 已提交
311

D
David S. Miller 已提交
312
	fl4.flowi4_oif = 0;
313 314 315
	fl4.flowi4_iif = vrf_master_ifindex_rcu(dev);
	if (!fl4.flowi4_iif)
		fl4.flowi4_iif = oif ? : LOOPBACK_IFINDEX;
D
David S. Miller 已提交
316 317 318 319
	fl4.daddr = src;
	fl4.saddr = dst;
	fl4.flowi4_tos = tos;
	fl4.flowi4_scope = RT_SCOPE_UNIVERSE;
320
	fl4.flowi4_tun_key.tun_id = 0;
321

322
	no_addr = idev->ifa_list == NULL;
323

324
	fl4.flowi4_mark = IN_DEV_SRC_VMARK(idev) ? skb->mark : 0;
L
Linus Torvalds 已提交
325

326
	net = dev_net(dev);
327
	if (fib_lookup(net, &fl4, &res, 0))
L
Linus Torvalds 已提交
328
		goto last_resort;
329 330 331 332 333 334
	if (res.type != RTN_UNICAST &&
	    (res.type != RTN_LOCAL || !IN_DEV_ACCEPT_LOCAL(idev)))
		goto e_inval;
	if (!rpf && !fib_num_tclassid_users(dev_net(dev)) &&
	    (dev->ifindex != oif || !IN_DEV_TX_REDIRECTS(idev)))
		goto last_resort;
L
Linus Torvalds 已提交
335
	fib_combine_itag(itag, &res);
336 337
	dev_match = false;

L
Linus Torvalds 已提交
338
#ifdef CONFIG_IP_ROUTE_MULTIPATH
339 340 341 342 343 344
	for (ret = 0; ret < res.fi->fib_nhs; ret++) {
		struct fib_nh *nh = &res.fi->fib_nh[ret];

		if (nh->nh_dev == dev) {
			dev_match = true;
			break;
345 346 347
		} else if (vrf_master_ifindex_rcu(nh->nh_dev) == dev->ifindex) {
			dev_match = true;
			break;
348 349
		}
	}
L
Linus Torvalds 已提交
350 351
#else
	if (FIB_RES_DEV(res) == dev)
352
		dev_match = true;
L
Linus Torvalds 已提交
353
#endif
354
	if (dev_match) {
L
Linus Torvalds 已提交
355 356 357 358 359
		ret = FIB_RES_NH(res).nh_scope >= RT_SCOPE_HOST;
		return ret;
	}
	if (no_addr)
		goto last_resort;
360
	if (rpf == 1)
361
		goto e_rpf;
D
David S. Miller 已提交
362
	fl4.flowi4_oif = dev->ifindex;
L
Linus Torvalds 已提交
363 364

	ret = 0;
365
	if (fib_lookup(net, &fl4, &res, FIB_LOOKUP_IGNORE_LINKSTATE) == 0) {
366
		if (res.type == RTN_UNICAST)
L
Linus Torvalds 已提交
367 368 369 370 371 372
			ret = FIB_RES_NH(res).nh_scope >= RT_SCOPE_HOST;
	}
	return ret;

last_resort:
	if (rpf)
373
		goto e_rpf;
L
Linus Torvalds 已提交
374 375 376 377 378
	*itag = 0;
	return 0;

e_inval:
	return -EINVAL;
379 380
e_rpf:
	return -EXDEV;
L
Linus Torvalds 已提交
381 382
}

383 384 385 386 387 388 389
/* Ignore rp_filter for packets protected by IPsec. */
int fib_validate_source(struct sk_buff *skb, __be32 src, __be32 dst,
			u8 tos, int oif, struct net_device *dev,
			struct in_device *idev, u32 *itag)
{
	int r = secpath_exists(skb) ? 0 : IN_DEV_RPFILTER(idev);

J
Julian Anastasov 已提交
390
	if (!r && !fib_num_tclassid_users(dev_net(dev)) &&
391
	    IN_DEV_ACCEPT_LOCAL(idev) &&
J
Julian Anastasov 已提交
392
	    (dev->ifindex != oif || !IN_DEV_TX_REDIRECTS(idev))) {
393 394 395 396 397 398
		*itag = 0;
		return 0;
	}
	return __fib_validate_source(skb, src, dst, tos, oif, dev, r, idev, itag);
}

A
Al Viro 已提交
399
static inline __be32 sk_extract_addr(struct sockaddr *addr)
400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415
{
	return ((struct sockaddr_in *) addr)->sin_addr.s_addr;
}

static int put_rtax(struct nlattr *mx, int len, int type, u32 value)
{
	struct nlattr *nla;

	nla = (struct nlattr *) ((char *) mx + len);
	nla->nla_type = type;
	nla->nla_len = nla_attr_size(4);
	*(u32 *) nla_data(nla) = value;

	return len + nla_total_size(4);
}

416
static int rtentry_to_fib_config(struct net *net, int cmd, struct rtentry *rt,
417 418
				 struct fib_config *cfg)
{
419
	__be32 addr;
420 421 422
	int plen;

	memset(cfg, 0, sizeof(*cfg));
423
	cfg->fc_nlinfo.nl_net = net;
424 425 426 427 428 429 430 431 432 433 434 435 436 437 438

	if (rt->rt_dst.sa_family != AF_INET)
		return -EAFNOSUPPORT;

	/*
	 * Check mask for validity:
	 * a) it must be contiguous.
	 * b) destination must have all host bits clear.
	 * c) if application forgot to set correct family (AF_INET),
	 *    reject request unless it is absolutely clear i.e.
	 *    both family and mask are zero.
	 */
	plen = 32;
	addr = sk_extract_addr(&rt->rt_dst);
	if (!(rt->rt_flags & RTF_HOST)) {
A
Al Viro 已提交
439
		__be32 mask = sk_extract_addr(&rt->rt_genmask);
440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483

		if (rt->rt_genmask.sa_family != AF_INET) {
			if (mask || rt->rt_genmask.sa_family)
				return -EAFNOSUPPORT;
		}

		if (bad_mask(mask, addr))
			return -EINVAL;

		plen = inet_mask_len(mask);
	}

	cfg->fc_dst_len = plen;
	cfg->fc_dst = addr;

	if (cmd != SIOCDELRT) {
		cfg->fc_nlflags = NLM_F_CREATE;
		cfg->fc_protocol = RTPROT_BOOT;
	}

	if (rt->rt_metric)
		cfg->fc_priority = rt->rt_metric - 1;

	if (rt->rt_flags & RTF_REJECT) {
		cfg->fc_scope = RT_SCOPE_HOST;
		cfg->fc_type = RTN_UNREACHABLE;
		return 0;
	}

	cfg->fc_scope = RT_SCOPE_NOWHERE;
	cfg->fc_type = RTN_UNICAST;

	if (rt->rt_dev) {
		char *colon;
		struct net_device *dev;
		char devname[IFNAMSIZ];

		if (copy_from_user(devname, rt->rt_dev, IFNAMSIZ-1))
			return -EFAULT;

		devname[IFNAMSIZ-1] = 0;
		colon = strchr(devname, ':');
		if (colon)
			*colon = 0;
484
		dev = __dev_get_by_name(net, devname);
485 486 487 488 489 490 491 492 493 494 495 496
		if (!dev)
			return -ENODEV;
		cfg->fc_oif = dev->ifindex;
		if (colon) {
			struct in_ifaddr *ifa;
			struct in_device *in_dev = __in_dev_get_rtnl(dev);
			if (!in_dev)
				return -ENODEV;
			*colon = ':';
			for (ifa = in_dev->ifa_list; ifa; ifa = ifa->ifa_next)
				if (strcmp(ifa->ifa_label, devname) == 0)
					break;
497
			if (!ifa)
498 499 500 501 502 503 504 505 506
				return -ENODEV;
			cfg->fc_prefsrc = ifa->ifa_local;
		}
	}

	addr = sk_extract_addr(&rt->rt_gateway);
	if (rt->rt_gateway.sa_family == AF_INET && addr) {
		cfg->fc_gw = addr;
		if (rt->rt_flags & RTF_GATEWAY &&
507
		    inet_addr_type(net, addr) == RTN_UNICAST)
508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524
			cfg->fc_scope = RT_SCOPE_UNIVERSE;
	}

	if (cmd == SIOCDELRT)
		return 0;

	if (rt->rt_flags & RTF_GATEWAY && !cfg->fc_gw)
		return -EINVAL;

	if (cfg->fc_scope == RT_SCOPE_NOWHERE)
		cfg->fc_scope = RT_SCOPE_LINK;

	if (rt->rt_flags & (RTF_MTU | RTF_WINDOW | RTF_IRTT)) {
		struct nlattr *mx;
		int len = 0;

		mx = kzalloc(3 * nla_total_size(4), GFP_KERNEL);
525
		if (!mx)
526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543
			return -ENOMEM;

		if (rt->rt_flags & RTF_MTU)
			len = put_rtax(mx, len, RTAX_ADVMSS, rt->rt_mtu - 40);

		if (rt->rt_flags & RTF_WINDOW)
			len = put_rtax(mx, len, RTAX_WINDOW, rt->rt_window);

		if (rt->rt_flags & RTF_IRTT)
			len = put_rtax(mx, len, RTAX_RTT, rt->rt_irtt << 3);

		cfg->fc_mx = mx;
		cfg->fc_mx_len = len;
	}

	return 0;
}

L
Linus Torvalds 已提交
544
/*
E
Eric Dumazet 已提交
545 546
 * Handle IP routing ioctl calls.
 * These are used to manipulate the routing tables
L
Linus Torvalds 已提交
547
 */
548
int ip_rt_ioctl(struct net *net, unsigned int cmd, void __user *arg)
L
Linus Torvalds 已提交
549
{
550 551
	struct fib_config cfg;
	struct rtentry rt;
L
Linus Torvalds 已提交
552 553 554 555 556
	int err;

	switch (cmd) {
	case SIOCADDRT:		/* Add a route */
	case SIOCDELRT:		/* Delete a route */
557
		if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
L
Linus Torvalds 已提交
558
			return -EPERM;
559 560

		if (copy_from_user(&rt, arg, sizeof(rt)))
L
Linus Torvalds 已提交
561
			return -EFAULT;
562

L
Linus Torvalds 已提交
563
		rtnl_lock();
564
		err = rtentry_to_fib_config(net, cmd, &rt, &cfg);
L
Linus Torvalds 已提交
565
		if (err == 0) {
566 567
			struct fib_table *tb;

L
Linus Torvalds 已提交
568
			if (cmd == SIOCDELRT) {
569
				tb = fib_get_table(net, cfg.fc_table);
L
Linus Torvalds 已提交
570
				if (tb)
571
					err = fib_table_delete(tb, &cfg);
572 573
				else
					err = -ESRCH;
L
Linus Torvalds 已提交
574
			} else {
575
				tb = fib_new_table(net, cfg.fc_table);
L
Linus Torvalds 已提交
576
				if (tb)
577
					err = fib_table_insert(tb, &cfg);
578 579
				else
					err = -ENOBUFS;
L
Linus Torvalds 已提交
580
			}
581 582 583

			/* allocated by rtentry_to_fib_config() */
			kfree(cfg.fc_mx);
L
Linus Torvalds 已提交
584 585 586 587 588 589 590
		}
		rtnl_unlock();
		return err;
	}
	return -EINVAL;
}

E
Eric Dumazet 已提交
591
const struct nla_policy rtm_ipv4_policy[RTA_MAX + 1] = {
592 593 594 595 596 597 598 599
	[RTA_DST]		= { .type = NLA_U32 },
	[RTA_SRC]		= { .type = NLA_U32 },
	[RTA_IIF]		= { .type = NLA_U32 },
	[RTA_OIF]		= { .type = NLA_U32 },
	[RTA_GATEWAY]		= { .type = NLA_U32 },
	[RTA_PRIORITY]		= { .type = NLA_U32 },
	[RTA_PREFSRC]		= { .type = NLA_U32 },
	[RTA_METRICS]		= { .type = NLA_NESTED },
600
	[RTA_MULTIPATH]		= { .len = sizeof(struct rtnexthop) },
601
	[RTA_FLOW]		= { .type = NLA_U32 },
602 603
	[RTA_ENCAP_TYPE]	= { .type = NLA_U16 },
	[RTA_ENCAP]		= { .type = NLA_NESTED },
604 605
};

606
static int rtm_to_fib_config(struct net *net, struct sk_buff *skb,
E
Eric Dumazet 已提交
607
			     struct nlmsghdr *nlh, struct fib_config *cfg)
L
Linus Torvalds 已提交
608
{
609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628
	struct nlattr *attr;
	int err, remaining;
	struct rtmsg *rtm;

	err = nlmsg_validate(nlh, sizeof(*rtm), RTA_MAX, rtm_ipv4_policy);
	if (err < 0)
		goto errout;

	memset(cfg, 0, sizeof(*cfg));

	rtm = nlmsg_data(nlh);
	cfg->fc_dst_len = rtm->rtm_dst_len;
	cfg->fc_tos = rtm->rtm_tos;
	cfg->fc_table = rtm->rtm_table;
	cfg->fc_protocol = rtm->rtm_protocol;
	cfg->fc_scope = rtm->rtm_scope;
	cfg->fc_type = rtm->rtm_type;
	cfg->fc_flags = rtm->rtm_flags;
	cfg->fc_nlflags = nlh->nlmsg_flags;

629
	cfg->fc_nlinfo.portid = NETLINK_CB(skb).portid;
630
	cfg->fc_nlinfo.nlh = nlh;
631
	cfg->fc_nlinfo.nl_net = net;
632

633 634 635 636 637
	if (cfg->fc_type > RTN_MAX) {
		err = -EINVAL;
		goto errout;
	}

638
	nlmsg_for_each_attr(attr, nlh, sizeof(struct rtmsg), remaining) {
639
		switch (nla_type(attr)) {
640
		case RTA_DST:
641
			cfg->fc_dst = nla_get_be32(attr);
642 643 644 645 646
			break;
		case RTA_OIF:
			cfg->fc_oif = nla_get_u32(attr);
			break;
		case RTA_GATEWAY:
647
			cfg->fc_gw = nla_get_be32(attr);
648 649 650 651 652
			break;
		case RTA_PRIORITY:
			cfg->fc_priority = nla_get_u32(attr);
			break;
		case RTA_PREFSRC:
653
			cfg->fc_prefsrc = nla_get_be32(attr);
654 655 656 657 658 659 660 661 662 663 664 665 666 667 668
			break;
		case RTA_METRICS:
			cfg->fc_mx = nla_data(attr);
			cfg->fc_mx_len = nla_len(attr);
			break;
		case RTA_MULTIPATH:
			cfg->fc_mp = nla_data(attr);
			cfg->fc_mp_len = nla_len(attr);
			break;
		case RTA_FLOW:
			cfg->fc_flow = nla_get_u32(attr);
			break;
		case RTA_TABLE:
			cfg->fc_table = nla_get_u32(attr);
			break;
669 670 671 672 673 674
		case RTA_ENCAP:
			cfg->fc_encap = attr;
			break;
		case RTA_ENCAP_TYPE:
			cfg->fc_encap_type = nla_get_u16(attr);
			break;
L
Linus Torvalds 已提交
675 676
		}
	}
677

L
Linus Torvalds 已提交
678
	return 0;
679 680
errout:
	return err;
L
Linus Torvalds 已提交
681 682
}

683
static int inet_rtm_delroute(struct sk_buff *skb, struct nlmsghdr *nlh)
L
Linus Torvalds 已提交
684
{
685
	struct net *net = sock_net(skb->sk);
686 687 688
	struct fib_config cfg;
	struct fib_table *tb;
	int err;
L
Linus Torvalds 已提交
689

690
	err = rtm_to_fib_config(net, skb, nlh, &cfg);
691 692
	if (err < 0)
		goto errout;
L
Linus Torvalds 已提交
693

694
	tb = fib_get_table(net, cfg.fc_table);
695
	if (!tb) {
696 697 698 699
		err = -ESRCH;
		goto errout;
	}

700
	err = fib_table_delete(tb, &cfg);
701 702
errout:
	return err;
L
Linus Torvalds 已提交
703 704
}

705
static int inet_rtm_newroute(struct sk_buff *skb, struct nlmsghdr *nlh)
L
Linus Torvalds 已提交
706
{
707
	struct net *net = sock_net(skb->sk);
708 709 710
	struct fib_config cfg;
	struct fib_table *tb;
	int err;
L
Linus Torvalds 已提交
711

712
	err = rtm_to_fib_config(net, skb, nlh, &cfg);
713 714
	if (err < 0)
		goto errout;
L
Linus Torvalds 已提交
715

716
	tb = fib_new_table(net, cfg.fc_table);
717
	if (!tb) {
718 719 720 721
		err = -ENOBUFS;
		goto errout;
	}

722
	err = fib_table_insert(tb, &cfg);
723 724
errout:
	return err;
L
Linus Torvalds 已提交
725 726
}

727
static int inet_dump_fib(struct sk_buff *skb, struct netlink_callback *cb)
L
Linus Torvalds 已提交
728
{
729
	struct net *net = sock_net(skb->sk);
730 731
	unsigned int h, s_h;
	unsigned int e = 0, s_e;
L
Linus Torvalds 已提交
732
	struct fib_table *tb;
733
	struct hlist_head *head;
734
	int dumped = 0;
L
Linus Torvalds 已提交
735

736 737
	if (nlmsg_len(cb->nlh) >= sizeof(struct rtmsg) &&
	    ((struct rtmsg *) nlmsg_data(cb->nlh))->rtm_flags & RTM_F_CLONED)
738
		return skb->len;
L
Linus Torvalds 已提交
739

740 741 742
	s_h = cb->args[0];
	s_e = cb->args[1];

743 744
	rcu_read_lock();

745 746
	for (h = s_h; h < FIB_TABLE_HASHSZ; h++, s_e = 0) {
		e = 0;
747
		head = &net->ipv4.fib_table_hash[h];
748
		hlist_for_each_entry_rcu(tb, head, tb_hlist) {
749 750 751 752
			if (e < s_e)
				goto next;
			if (dumped)
				memset(&cb->args[2], 0, sizeof(cb->args) -
753
						 2 * sizeof(cb->args[0]));
754
			if (fib_table_dump(tb, skb, cb) < 0)
755 756 757 758 759
				goto out;
			dumped = 1;
next:
			e++;
		}
L
Linus Torvalds 已提交
760
	}
761
out:
762 763
	rcu_read_unlock();

764 765
	cb->args[1] = e;
	cb->args[0] = h;
L
Linus Torvalds 已提交
766 767 768 769 770

	return skb->len;
}

/* Prepare and feed intra-kernel routing request.
E
Eric Dumazet 已提交
771 772 773 774
 * Really, it should be netlink message, but :-( netlink
 * can be not configured, so that we feed it directly
 * to fib engine. It is legal, because all events occur
 * only when netlink is already locked.
L
Linus Torvalds 已提交
775
 */
A
Al Viro 已提交
776
static void fib_magic(int cmd, int type, __be32 dst, int dst_len, struct in_ifaddr *ifa)
L
Linus Torvalds 已提交
777
{
778
	struct net *net = dev_net(ifa->ifa_dev->dev);
779 780 781 782 783 784 785 786 787
	struct fib_table *tb;
	struct fib_config cfg = {
		.fc_protocol = RTPROT_KERNEL,
		.fc_type = type,
		.fc_dst = dst,
		.fc_dst_len = dst_len,
		.fc_prefsrc = ifa->ifa_local,
		.fc_oif = ifa->ifa_dev->dev->ifindex,
		.fc_nlflags = NLM_F_CREATE | NLM_F_APPEND,
788
		.fc_nlinfo = {
789
			.nl_net = net,
790
		},
791
	};
L
Linus Torvalds 已提交
792 793

	if (type == RTN_UNICAST)
794
		tb = fib_new_table(net, RT_TABLE_MAIN);
L
Linus Torvalds 已提交
795
	else
796
		tb = fib_new_table(net, RT_TABLE_LOCAL);
L
Linus Torvalds 已提交
797

798
	if (!tb)
L
Linus Torvalds 已提交
799 800
		return;

801
	cfg.fc_table = tb->tb_id;
L
Linus Torvalds 已提交
802

803 804 805 806
	if (type != RTN_LOCAL)
		cfg.fc_scope = RT_SCOPE_LINK;
	else
		cfg.fc_scope = RT_SCOPE_HOST;
L
Linus Torvalds 已提交
807 808

	if (cmd == RTM_NEWROUTE)
809
		fib_table_insert(tb, &cfg);
L
Linus Torvalds 已提交
810
	else
811
		fib_table_delete(tb, &cfg);
L
Linus Torvalds 已提交
812 813
}

814
void fib_add_ifaddr(struct in_ifaddr *ifa)
L
Linus Torvalds 已提交
815 816 817 818
{
	struct in_device *in_dev = ifa->ifa_dev;
	struct net_device *dev = in_dev->dev;
	struct in_ifaddr *prim = ifa;
A
Al Viro 已提交
819 820
	__be32 mask = ifa->ifa_mask;
	__be32 addr = ifa->ifa_local;
E
Eric Dumazet 已提交
821
	__be32 prefix = ifa->ifa_address & mask;
L
Linus Torvalds 已提交
822

E
Eric Dumazet 已提交
823
	if (ifa->ifa_flags & IFA_F_SECONDARY) {
L
Linus Torvalds 已提交
824
		prim = inet_ifa_byprefix(in_dev, prefix, mask);
825
		if (!prim) {
J
Joe Perches 已提交
826
			pr_warn("%s: bug: prim == NULL\n", __func__);
L
Linus Torvalds 已提交
827 828 829 830 831 832
			return;
		}
	}

	fib_magic(RTM_NEWROUTE, RTN_LOCAL, addr, 32, prim);

E
Eric Dumazet 已提交
833
	if (!(dev->flags & IFF_UP))
L
Linus Torvalds 已提交
834 835 836
		return;

	/* Add broadcast address, if it is explicitly assigned. */
A
Al Viro 已提交
837
	if (ifa->ifa_broadcast && ifa->ifa_broadcast != htonl(0xFFFFFFFF))
L
Linus Torvalds 已提交
838 839
		fib_magic(RTM_NEWROUTE, RTN_BROADCAST, ifa->ifa_broadcast, 32, prim);

E
Eric Dumazet 已提交
840
	if (!ipv4_is_zeronet(prefix) && !(ifa->ifa_flags & IFA_F_SECONDARY) &&
L
Linus Torvalds 已提交
841
	    (prefix != addr || ifa->ifa_prefixlen < 32)) {
E
Eric Dumazet 已提交
842 843 844
		fib_magic(RTM_NEWROUTE,
			  dev->flags & IFF_LOOPBACK ? RTN_LOCAL : RTN_UNICAST,
			  prefix, ifa->ifa_prefixlen, prim);
L
Linus Torvalds 已提交
845 846 847 848

		/* Add network specific broadcasts, when it takes a sense */
		if (ifa->ifa_prefixlen < 31) {
			fib_magic(RTM_NEWROUTE, RTN_BROADCAST, prefix, 32, prim);
E
Eric Dumazet 已提交
849 850
			fib_magic(RTM_NEWROUTE, RTN_BROADCAST, prefix | ~mask,
				  32, prim);
L
Linus Torvalds 已提交
851 852 853 854
		}
	}
}

855 856 857 858 859 860
/* Delete primary or secondary address.
 * Optionally, on secondary address promotion consider the addresses
 * from subnet iprim as deleted, even if they are in device list.
 * In this case the secondary ifa can be in device list.
 */
void fib_del_ifaddr(struct in_ifaddr *ifa, struct in_ifaddr *iprim)
L
Linus Torvalds 已提交
861 862 863 864
{
	struct in_device *in_dev = ifa->ifa_dev;
	struct net_device *dev = in_dev->dev;
	struct in_ifaddr *ifa1;
865
	struct in_ifaddr *prim = ifa, *prim1 = NULL;
E
Eric Dumazet 已提交
866 867
	__be32 brd = ifa->ifa_address | ~ifa->ifa_mask;
	__be32 any = ifa->ifa_address & ifa->ifa_mask;
L
Linus Torvalds 已提交
868 869 870 871
#define LOCAL_OK	1
#define BRD_OK		2
#define BRD0_OK		4
#define BRD1_OK		8
872
	unsigned int ok = 0;
873 874 875
	int subnet = 0;		/* Primary network */
	int gone = 1;		/* Address is missing */
	int same_prefsrc = 0;	/* Another primary with same IP */
L
Linus Torvalds 已提交
876

877
	if (ifa->ifa_flags & IFA_F_SECONDARY) {
L
Linus Torvalds 已提交
878
		prim = inet_ifa_byprefix(in_dev, any, ifa->ifa_mask);
879
		if (!prim) {
J
Joe Perches 已提交
880
			pr_warn("%s: bug: prim == NULL\n", __func__);
L
Linus Torvalds 已提交
881 882
			return;
		}
883
		if (iprim && iprim != prim) {
J
Joe Perches 已提交
884
			pr_warn("%s: bug: iprim != prim\n", __func__);
885 886 887 888 889 890 891 892
			return;
		}
	} else if (!ipv4_is_zeronet(any) &&
		   (any != ifa->ifa_local || ifa->ifa_prefixlen < 32)) {
		fib_magic(RTM_DELROUTE,
			  dev->flags & IFF_LOOPBACK ? RTN_LOCAL : RTN_UNICAST,
			  any, ifa->ifa_prefixlen, prim);
		subnet = 1;
L
Linus Torvalds 已提交
893 894 895
	}

	/* Deletion is more complicated than add.
E
Eric Dumazet 已提交
896 897 898
	 * We should take care of not to delete too much :-)
	 *
	 * Scan address list to be sure that addresses are really gone.
L
Linus Torvalds 已提交
899 900 901
	 */

	for (ifa1 = in_dev->ifa_list; ifa1; ifa1 = ifa1->ifa_next) {
902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944
		if (ifa1 == ifa) {
			/* promotion, keep the IP */
			gone = 0;
			continue;
		}
		/* Ignore IFAs from our subnet */
		if (iprim && ifa1->ifa_mask == iprim->ifa_mask &&
		    inet_ifa_match(ifa1->ifa_address, iprim))
			continue;

		/* Ignore ifa1 if it uses different primary IP (prefsrc) */
		if (ifa1->ifa_flags & IFA_F_SECONDARY) {
			/* Another address from our subnet? */
			if (ifa1->ifa_mask == prim->ifa_mask &&
			    inet_ifa_match(ifa1->ifa_address, prim))
				prim1 = prim;
			else {
				/* We reached the secondaries, so
				 * same_prefsrc should be determined.
				 */
				if (!same_prefsrc)
					continue;
				/* Search new prim1 if ifa1 is not
				 * using the current prim1
				 */
				if (!prim1 ||
				    ifa1->ifa_mask != prim1->ifa_mask ||
				    !inet_ifa_match(ifa1->ifa_address, prim1))
					prim1 = inet_ifa_byprefix(in_dev,
							ifa1->ifa_address,
							ifa1->ifa_mask);
				if (!prim1)
					continue;
				if (prim1->ifa_local != prim->ifa_local)
					continue;
			}
		} else {
			if (prim->ifa_local != ifa1->ifa_local)
				continue;
			prim1 = ifa1;
			if (prim != prim1)
				same_prefsrc = 1;
		}
L
Linus Torvalds 已提交
945 946 947 948 949 950 951 952
		if (ifa->ifa_local == ifa1->ifa_local)
			ok |= LOCAL_OK;
		if (ifa->ifa_broadcast == ifa1->ifa_broadcast)
			ok |= BRD_OK;
		if (brd == ifa1->ifa_broadcast)
			ok |= BRD1_OK;
		if (any == ifa1->ifa_broadcast)
			ok |= BRD0_OK;
953 954 955 956 957 958 959 960 961 962 963 964 965 966 967
		/* primary has network specific broadcasts */
		if (prim1 == ifa1 && ifa1->ifa_prefixlen < 31) {
			__be32 brd1 = ifa1->ifa_address | ~ifa1->ifa_mask;
			__be32 any1 = ifa1->ifa_address & ifa1->ifa_mask;

			if (!ipv4_is_zeronet(any1)) {
				if (ifa->ifa_broadcast == brd1 ||
				    ifa->ifa_broadcast == any1)
					ok |= BRD_OK;
				if (brd == brd1 || brd == any1)
					ok |= BRD1_OK;
				if (any == brd1 || any == any1)
					ok |= BRD0_OK;
			}
		}
L
Linus Torvalds 已提交
968 969
	}

E
Eric Dumazet 已提交
970
	if (!(ok & BRD_OK))
L
Linus Torvalds 已提交
971
		fib_magic(RTM_DELROUTE, RTN_BROADCAST, ifa->ifa_broadcast, 32, prim);
972 973 974 975 976 977
	if (subnet && ifa->ifa_prefixlen < 31) {
		if (!(ok & BRD1_OK))
			fib_magic(RTM_DELROUTE, RTN_BROADCAST, brd, 32, prim);
		if (!(ok & BRD0_OK))
			fib_magic(RTM_DELROUTE, RTN_BROADCAST, any, 32, prim);
	}
E
Eric Dumazet 已提交
978
	if (!(ok & LOCAL_OK)) {
L
Linus Torvalds 已提交
979 980 981
		fib_magic(RTM_DELROUTE, RTN_LOCAL, ifa->ifa_local, 32, prim);

		/* Check, that this local address finally disappeared. */
982 983
		if (gone &&
		    inet_addr_type(dev_net(dev), ifa->ifa_local) != RTN_LOCAL) {
L
Linus Torvalds 已提交
984
			/* And the last, but not the least thing.
E
Eric Dumazet 已提交
985 986 987 988 989
			 * We must flush stray FIB entries.
			 *
			 * First of all, we scan fib_info list searching
			 * for stray nexthop entries, then ignite fib_flush.
			 */
990 991
			if (fib_sync_down_addr(dev_net(dev), ifa->ifa_local))
				fib_flush(dev_net(dev));
L
Linus Torvalds 已提交
992 993 994 995 996 997 998 999
		}
	}
#undef LOCAL_OK
#undef BRD_OK
#undef BRD0_OK
#undef BRD1_OK
}

1000
static void nl_fib_lookup(struct net *net, struct fib_result_nl *frn)
1001
{
1002

1003
	struct fib_result       res;
D
David S. Miller 已提交
1004 1005 1006 1007 1008
	struct flowi4           fl4 = {
		.flowi4_mark = frn->fl_mark,
		.daddr = frn->fl_addr,
		.flowi4_tos = frn->fl_tos,
		.flowi4_scope = frn->fl_scope,
E
Eric Dumazet 已提交
1009
	};
1010 1011 1012 1013 1014
	struct fib_table *tb;

	rcu_read_lock();

	tb = fib_get_table(net, frn->tb_id_in);
1015 1016

	frn->err = -ENOENT;
1017 1018 1019 1020
	if (tb) {
		local_bh_disable();

		frn->tb_id = tb->tb_id;
D
David S. Miller 已提交
1021
		frn->err = fib_table_lookup(tb, &fl4, &res, FIB_LOOKUP_NOREF);
1022 1023 1024 1025 1026 1027 1028 1029 1030

		if (!frn->err) {
			frn->prefixlen = res.prefixlen;
			frn->nh_sel = res.nh_sel;
			frn->type = res.type;
			frn->scope = res.scope;
		}
		local_bh_enable();
	}
1031 1032

	rcu_read_unlock();
1033 1034
}

1035
static void nl_fib_input(struct sk_buff *skb)
1036
{
1037
	struct net *net;
1038
	struct fib_result_nl *frn;
1039
	struct nlmsghdr *nlh;
1040
	u32 portid;
1041

1042
	net = sock_net(skb->sk);
1043
	nlh = nlmsg_hdr(skb);
1044 1045
	if (skb->len < NLMSG_HDRLEN || skb->len < nlh->nlmsg_len ||
	    nlmsg_len(nlh) < sizeof(*frn))
1046
		return;
1047

1048
	skb = netlink_skb_clone(skb, GFP_KERNEL);
1049
	if (!skb)
1050 1051
		return;
	nlh = nlmsg_hdr(skb);
1052

1053
	frn = (struct fib_result_nl *) nlmsg_data(nlh);
1054
	nl_fib_lookup(net, frn);
1055

R
Rami Rosen 已提交
1056
	portid = NETLINK_CB(skb).portid;      /* netlink portid */
1057
	NETLINK_CB(skb).portid = 0;        /* from kernel */
1058
	NETLINK_CB(skb).dst_group = 0;  /* unicast */
1059
	netlink_unicast(net->ipv4.fibnl, skb, portid, MSG_DONTWAIT);
1060
}
1061

1062
static int __net_init nl_fib_lookup_init(struct net *net)
1063
{
1064
	struct sock *sk;
1065 1066 1067 1068
	struct netlink_kernel_cfg cfg = {
		.input	= nl_fib_input,
	};

1069
	sk = netlink_kernel_create(net, NETLINK_FIB_LOOKUP, &cfg);
1070
	if (!sk)
1071
		return -EAFNOSUPPORT;
1072
	net->ipv4.fibnl = sk;
1073 1074 1075 1076 1077
	return 0;
}

static void nl_fib_lookup_exit(struct net *net)
{
1078
	netlink_kernel_release(net->ipv4.fibnl);
1079
	net->ipv4.fibnl = NULL;
1080 1081
}

1082
static void fib_disable_ip(struct net_device *dev, unsigned long event)
L
Linus Torvalds 已提交
1083
{
1084
	if (fib_sync_down_dev(dev, event))
1085
		fib_flush(dev_net(dev));
1086
	rt_cache_flush(dev_net(dev));
L
Linus Torvalds 已提交
1087 1088 1089 1090 1091
	arp_ifdown(dev);
}

static int fib_inetaddr_event(struct notifier_block *this, unsigned long event, void *ptr)
{
1092
	struct in_ifaddr *ifa = (struct in_ifaddr *)ptr;
1093
	struct net_device *dev = ifa->ifa_dev->dev;
1094
	struct net *net = dev_net(dev);
L
Linus Torvalds 已提交
1095 1096 1097 1098 1099

	switch (event) {
	case NETDEV_UP:
		fib_add_ifaddr(ifa);
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1100
		fib_sync_up(dev, RTNH_F_DEAD);
L
Linus Torvalds 已提交
1101
#endif
1102
		atomic_inc(&net->ipv4.dev_addr_genid);
1103
		rt_cache_flush(dev_net(dev));
L
Linus Torvalds 已提交
1104 1105
		break;
	case NETDEV_DOWN:
1106
		fib_del_ifaddr(ifa, NULL);
1107
		atomic_inc(&net->ipv4.dev_addr_genid);
1108
		if (!ifa->ifa_dev->ifa_list) {
L
Linus Torvalds 已提交
1109
			/* Last address was deleted from this interface.
E
Eric Dumazet 已提交
1110
			 * Disable IP.
L
Linus Torvalds 已提交
1111
			 */
1112
			fib_disable_ip(dev, event);
L
Linus Torvalds 已提交
1113
		} else {
1114
			rt_cache_flush(dev_net(dev));
L
Linus Torvalds 已提交
1115 1116 1117 1118 1119 1120 1121 1122
		}
		break;
	}
	return NOTIFY_DONE;
}

static int fib_netdev_event(struct notifier_block *this, unsigned long event, void *ptr)
{
1123
	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
1124
	struct in_device *in_dev;
1125
	struct net *net = dev_net(dev);
1126
	unsigned int flags;
L
Linus Torvalds 已提交
1127 1128

	if (event == NETDEV_UNREGISTER) {
1129
		fib_disable_ip(dev, event);
1130
		rt_flush_dev(dev);
L
Linus Torvalds 已提交
1131 1132 1133
		return NOTIFY_DONE;
	}

1134
	in_dev = __in_dev_get_rtnl(dev);
1135 1136
	if (!in_dev)
		return NOTIFY_DONE;
1137

L
Linus Torvalds 已提交
1138 1139 1140 1141 1142 1143
	switch (event) {
	case NETDEV_UP:
		for_ifa(in_dev) {
			fib_add_ifaddr(ifa);
		} endfor_ifa(in_dev);
#ifdef CONFIG_IP_ROUTE_MULTIPATH
1144
		fib_sync_up(dev, RTNH_F_DEAD);
L
Linus Torvalds 已提交
1145
#endif
1146
		atomic_inc(&net->ipv4.dev_addr_genid);
1147
		rt_cache_flush(net);
L
Linus Torvalds 已提交
1148 1149
		break;
	case NETDEV_DOWN:
1150
		fib_disable_ip(dev, event);
L
Linus Torvalds 已提交
1151 1152
		break;
	case NETDEV_CHANGE:
1153 1154 1155 1156 1157 1158 1159
		flags = dev_get_flags(dev);
		if (flags & (IFF_RUNNING | IFF_LOWER_UP))
			fib_sync_up(dev, RTNH_F_LINKDOWN);
		else
			fib_sync_down_dev(dev, event);
		/* fall through */
	case NETDEV_CHANGEMTU:
1160
		rt_cache_flush(net);
L
Linus Torvalds 已提交
1161 1162 1163 1164 1165 1166
		break;
	}
	return NOTIFY_DONE;
}

static struct notifier_block fib_inetaddr_notifier = {
1167
	.notifier_call = fib_inetaddr_event,
L
Linus Torvalds 已提交
1168 1169 1170
};

static struct notifier_block fib_netdev_notifier = {
1171
	.notifier_call = fib_netdev_event,
L
Linus Torvalds 已提交
1172 1173
};

1174
static int __net_init ip_fib_net_init(struct net *net)
L
Linus Torvalds 已提交
1175
{
1176
	int err;
1177 1178 1179 1180
	size_t size = sizeof(struct hlist_head) * FIB_TABLE_HASHSZ;

	/* Avoid false sharing : Use at least a full cache line */
	size = max_t(size_t, size, L1_CACHE_BYTES);
1181

1182
	net->ipv4.fib_table_hash = kzalloc(size, GFP_KERNEL);
1183
	if (!net->ipv4.fib_table_hash)
1184 1185
		return -ENOMEM;

1186 1187 1188 1189 1190 1191 1192 1193
	err = fib4_rules_init(net);
	if (err < 0)
		goto fail;
	return 0;

fail:
	kfree(net->ipv4.fib_table_hash);
	return err;
1194
}
L
Linus Torvalds 已提交
1195

1196
static void ip_fib_net_exit(struct net *net)
1197 1198 1199
{
	unsigned int i;

1200
	rtnl_lock();
1201 1202 1203 1204 1205
#ifdef CONFIG_IP_MULTIPLE_TABLES
	RCU_INIT_POINTER(net->ipv4.fib_local, NULL);
	RCU_INIT_POINTER(net->ipv4.fib_main, NULL);
	RCU_INIT_POINTER(net->ipv4.fib_default, NULL);
#endif
1206
	for (i = 0; i < FIB_TABLE_HASHSZ; i++) {
1207
		struct hlist_head *head = &net->ipv4.fib_table_hash[i];
1208
		struct hlist_node *tmp;
1209 1210
		struct fib_table *tb;

1211 1212
		hlist_for_each_entry_safe(tb, tmp, head, tb_hlist) {
			hlist_del(&tb->tb_hlist);
1213
			fib_table_flush(tb);
1214
			fib_free_table(tb);
1215 1216
		}
	}
1217 1218 1219 1220

#ifdef CONFIG_IP_MULTIPLE_TABLES
	fib4_rules_exit(net);
#endif
1221
	rtnl_unlock();
1222
	kfree(net->ipv4.fib_table_hash);
1223 1224 1225 1226 1227 1228
}

static int __net_init fib_net_init(struct net *net)
{
	int error;

1229 1230 1231
#ifdef CONFIG_IP_ROUTE_CLASSID
	net->ipv4.fib_num_tclassid_users = 0;
#endif
1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264
	error = ip_fib_net_init(net);
	if (error < 0)
		goto out;
	error = nl_fib_lookup_init(net);
	if (error < 0)
		goto out_nlfl;
	error = fib_proc_init(net);
	if (error < 0)
		goto out_proc;
out:
	return error;

out_proc:
	nl_fib_lookup_exit(net);
out_nlfl:
	ip_fib_net_exit(net);
	goto out;
}

static void __net_exit fib_net_exit(struct net *net)
{
	fib_proc_exit(net);
	nl_fib_lookup_exit(net);
	ip_fib_net_exit(net);
}

static struct pernet_operations fib_net_ops = {
	.init = fib_net_init,
	.exit = fib_net_exit,
};

void __init ip_fib_init(void)
{
1265 1266 1267
	rtnl_register(PF_INET, RTM_NEWROUTE, inet_rtm_newroute, NULL, NULL);
	rtnl_register(PF_INET, RTM_DELROUTE, inet_rtm_delroute, NULL, NULL);
	rtnl_register(PF_INET, RTM_GETROUTE, NULL, inet_dump_fib, NULL);
1268 1269 1270 1271

	register_pernet_subsys(&fib_net_ops);
	register_netdevice_notifier(&fib_netdev_notifier);
	register_inetaddr_notifier(&fib_inetaddr_notifier);
1272

1273
	fib_trie_init();
L
Linus Torvalds 已提交
1274
}