]> git.ipfire.org Git - thirdparty/kernel/stable.git/blame - net/ipv6/route.c
vhost_net: batch used ring update in rx
[thirdparty/kernel/stable.git] / net / ipv6 / route.c
CommitLineData
1da177e4
LT
1/*
2 * Linux INET6 implementation
3 * FIB front-end.
4 *
5 * Authors:
1ab1457c 6 * Pedro Roque <roque@di.fc.ul.pt>
1da177e4 7 *
1da177e4
LT
8 * This program is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU General Public License
10 * as published by the Free Software Foundation; either version
11 * 2 of the License, or (at your option) any later version.
12 */
13
14/* Changes:
15 *
16 * YOSHIFUJI Hideaki @USAGI
17 * reworked default router selection.
18 * - respect outgoing interface
19 * - select from (probably) reachable routers (i.e.
20 * routers in REACHABLE, STALE, DELAY or PROBE states).
21 * - always select the same router if it is (probably)
22 * reachable. otherwise, round-robin the list.
c0bece9f
YH
23 * Ville Nuorvala
24 * Fixed routing subtrees.
1da177e4
LT
25 */
26
f3213831
JP
27#define pr_fmt(fmt) "IPv6: " fmt
28
4fc268d2 29#include <linux/capability.h>
1da177e4 30#include <linux/errno.h>
bc3b2d7f 31#include <linux/export.h>
1da177e4
LT
32#include <linux/types.h>
33#include <linux/times.h>
34#include <linux/socket.h>
35#include <linux/sockios.h>
36#include <linux/net.h>
37#include <linux/route.h>
38#include <linux/netdevice.h>
39#include <linux/in6.h>
7bc570c8 40#include <linux/mroute6.h>
1da177e4 41#include <linux/init.h>
1da177e4 42#include <linux/if_arp.h>
1da177e4
LT
43#include <linux/proc_fs.h>
44#include <linux/seq_file.h>
5b7c931d 45#include <linux/nsproxy.h>
5a0e3ad6 46#include <linux/slab.h>
35732d01 47#include <linux/jhash.h>
457c4cbc 48#include <net/net_namespace.h>
1da177e4
LT
49#include <net/snmp.h>
50#include <net/ipv6.h>
51#include <net/ip6_fib.h>
52#include <net/ip6_route.h>
53#include <net/ndisc.h>
54#include <net/addrconf.h>
55#include <net/tcp.h>
56#include <linux/rtnetlink.h>
57#include <net/dst.h>
904af04d 58#include <net/dst_metadata.h>
1da177e4 59#include <net/xfrm.h>
8d71740c 60#include <net/netevent.h>
21713ebc 61#include <net/netlink.h>
51ebd318 62#include <net/nexthop.h>
19e42e45 63#include <net/lwtunnel.h>
904af04d 64#include <net/ip_tunnels.h>
ca254490 65#include <net/l3mdev.h>
b811580d 66#include <trace/events/fib6.h>
1da177e4 67
7c0f6ba6 68#include <linux/uaccess.h>
1da177e4
LT
69
70#ifdef CONFIG_SYSCTL
71#include <linux/sysctl.h>
72#endif
73
afc154e9 74enum rt6_nud_state {
7e980569
JB
75 RT6_NUD_FAIL_HARD = -3,
76 RT6_NUD_FAIL_PROBE = -2,
77 RT6_NUD_FAIL_DO_RR = -1,
afc154e9
HFS
78 RT6_NUD_SUCCEED = 1
79};
80
83a09abd 81static void ip6_rt_copy_init(struct rt6_info *rt, struct rt6_info *ort);
1da177e4 82static struct dst_entry *ip6_dst_check(struct dst_entry *dst, u32 cookie);
0dbaee3b 83static unsigned int ip6_default_advmss(const struct dst_entry *dst);
ebb762f2 84static unsigned int ip6_mtu(const struct dst_entry *dst);
1da177e4
LT
85static struct dst_entry *ip6_negative_advice(struct dst_entry *);
86static void ip6_dst_destroy(struct dst_entry *);
87static void ip6_dst_ifdown(struct dst_entry *,
88 struct net_device *dev, int how);
569d3645 89static int ip6_dst_gc(struct dst_ops *ops);
1da177e4
LT
90
91static int ip6_pkt_discard(struct sk_buff *skb);
ede2059d 92static int ip6_pkt_discard_out(struct net *net, struct sock *sk, struct sk_buff *skb);
7150aede 93static int ip6_pkt_prohibit(struct sk_buff *skb);
ede2059d 94static int ip6_pkt_prohibit_out(struct net *net, struct sock *sk, struct sk_buff *skb);
1da177e4 95static void ip6_link_failure(struct sk_buff *skb);
6700c270
DM
96static void ip6_rt_update_pmtu(struct dst_entry *dst, struct sock *sk,
97 struct sk_buff *skb, u32 mtu);
98static void rt6_do_redirect(struct dst_entry *dst, struct sock *sk,
99 struct sk_buff *skb);
4b32b5ad 100static void rt6_dst_from_metrics_check(struct rt6_info *rt);
52bd4c0c 101static int rt6_score_route(struct rt6_info *rt, int oif, int strict);
16a16cd3
DA
102static size_t rt6_nlmsg_size(struct rt6_info *rt);
103static int rt6_fill_node(struct net *net,
104 struct sk_buff *skb, struct rt6_info *rt,
105 struct in6_addr *dst, struct in6_addr *src,
106 int iif, int type, u32 portid, u32 seq,
107 unsigned int flags);
35732d01
WW
108static struct rt6_info *rt6_find_cached_rt(struct rt6_info *rt,
109 struct in6_addr *daddr,
110 struct in6_addr *saddr);
1da177e4 111
70ceb4f5 112#ifdef CONFIG_IPV6_ROUTE_INFO
efa2cea0 113static struct rt6_info *rt6_add_route_info(struct net *net,
b71d1d42 114 const struct in6_addr *prefix, int prefixlen,
830218c1
DA
115 const struct in6_addr *gwaddr,
116 struct net_device *dev,
95c96174 117 unsigned int pref);
efa2cea0 118static struct rt6_info *rt6_get_route_info(struct net *net,
b71d1d42 119 const struct in6_addr *prefix, int prefixlen,
830218c1
DA
120 const struct in6_addr *gwaddr,
121 struct net_device *dev);
70ceb4f5
YH
122#endif
123
8d0b94af
MKL
124struct uncached_list {
125 spinlock_t lock;
126 struct list_head head;
127};
128
129static DEFINE_PER_CPU_ALIGNED(struct uncached_list, rt6_uncached_list);
130
131static void rt6_uncached_list_add(struct rt6_info *rt)
132{
133 struct uncached_list *ul = raw_cpu_ptr(&rt6_uncached_list);
134
8d0b94af
MKL
135 rt->rt6i_uncached_list = ul;
136
137 spin_lock_bh(&ul->lock);
138 list_add_tail(&rt->rt6i_uncached, &ul->head);
139 spin_unlock_bh(&ul->lock);
140}
141
142static void rt6_uncached_list_del(struct rt6_info *rt)
143{
144 if (!list_empty(&rt->rt6i_uncached)) {
145 struct uncached_list *ul = rt->rt6i_uncached_list;
81eb8447 146 struct net *net = dev_net(rt->dst.dev);
8d0b94af
MKL
147
148 spin_lock_bh(&ul->lock);
149 list_del(&rt->rt6i_uncached);
81eb8447 150 atomic_dec(&net->ipv6.rt6_stats->fib_rt_uncache);
8d0b94af
MKL
151 spin_unlock_bh(&ul->lock);
152 }
153}
154
155static void rt6_uncached_list_flush_dev(struct net *net, struct net_device *dev)
156{
157 struct net_device *loopback_dev = net->loopback_dev;
158 int cpu;
159
e332bc67
EB
160 if (dev == loopback_dev)
161 return;
162
8d0b94af
MKL
163 for_each_possible_cpu(cpu) {
164 struct uncached_list *ul = per_cpu_ptr(&rt6_uncached_list, cpu);
165 struct rt6_info *rt;
166
167 spin_lock_bh(&ul->lock);
168 list_for_each_entry(rt, &ul->head, rt6i_uncached) {
169 struct inet6_dev *rt_idev = rt->rt6i_idev;
170 struct net_device *rt_dev = rt->dst.dev;
171
e332bc67 172 if (rt_idev->dev == dev) {
8d0b94af
MKL
173 rt->rt6i_idev = in6_dev_get(loopback_dev);
174 in6_dev_put(rt_idev);
175 }
176
e332bc67 177 if (rt_dev == dev) {
8d0b94af
MKL
178 rt->dst.dev = loopback_dev;
179 dev_hold(rt->dst.dev);
180 dev_put(rt_dev);
181 }
182 }
183 spin_unlock_bh(&ul->lock);
184 }
185}
186
d52d3997
MKL
187static u32 *rt6_pcpu_cow_metrics(struct rt6_info *rt)
188{
3a2232e9 189 return dst_metrics_write_ptr(&rt->from->dst);
d52d3997
MKL
190}
191
06582540
DM
192static u32 *ipv6_cow_metrics(struct dst_entry *dst, unsigned long old)
193{
4b32b5ad 194 struct rt6_info *rt = (struct rt6_info *)dst;
06582540 195
d52d3997
MKL
196 if (rt->rt6i_flags & RTF_PCPU)
197 return rt6_pcpu_cow_metrics(rt);
198 else if (rt->rt6i_flags & RTF_CACHE)
4b32b5ad
MKL
199 return NULL;
200 else
3b471175 201 return dst_cow_metrics_generic(dst, old);
06582540
DM
202}
203
f894cbf8
DM
204static inline const void *choose_neigh_daddr(struct rt6_info *rt,
205 struct sk_buff *skb,
206 const void *daddr)
39232973
DM
207{
208 struct in6_addr *p = &rt->rt6i_gateway;
209
a7563f34 210 if (!ipv6_addr_any(p))
39232973 211 return (const void *) p;
f894cbf8
DM
212 else if (skb)
213 return &ipv6_hdr(skb)->daddr;
39232973
DM
214 return daddr;
215}
216
f894cbf8
DM
217static struct neighbour *ip6_neigh_lookup(const struct dst_entry *dst,
218 struct sk_buff *skb,
219 const void *daddr)
d3aaeb38 220{
39232973
DM
221 struct rt6_info *rt = (struct rt6_info *) dst;
222 struct neighbour *n;
223
f894cbf8 224 daddr = choose_neigh_daddr(rt, skb, daddr);
8e022ee6 225 n = __ipv6_neigh_lookup(dst->dev, daddr);
f83c7790
DM
226 if (n)
227 return n;
228 return neigh_create(&nd_tbl, daddr, dst->dev);
229}
230
63fca65d
JA
231static void ip6_confirm_neigh(const struct dst_entry *dst, const void *daddr)
232{
233 struct net_device *dev = dst->dev;
234 struct rt6_info *rt = (struct rt6_info *)dst;
235
236 daddr = choose_neigh_daddr(rt, NULL, daddr);
237 if (!daddr)
238 return;
239 if (dev->flags & (IFF_NOARP | IFF_LOOPBACK))
240 return;
241 if (ipv6_addr_is_multicast((const struct in6_addr *)daddr))
242 return;
243 __ipv6_confirm_neigh(dev, daddr);
244}
245
9a7ec3a9 246static struct dst_ops ip6_dst_ops_template = {
1da177e4 247 .family = AF_INET6,
1da177e4
LT
248 .gc = ip6_dst_gc,
249 .gc_thresh = 1024,
250 .check = ip6_dst_check,
0dbaee3b 251 .default_advmss = ip6_default_advmss,
ebb762f2 252 .mtu = ip6_mtu,
06582540 253 .cow_metrics = ipv6_cow_metrics,
1da177e4
LT
254 .destroy = ip6_dst_destroy,
255 .ifdown = ip6_dst_ifdown,
256 .negative_advice = ip6_negative_advice,
257 .link_failure = ip6_link_failure,
258 .update_pmtu = ip6_rt_update_pmtu,
6e157b6a 259 .redirect = rt6_do_redirect,
9f8955cc 260 .local_out = __ip6_local_out,
d3aaeb38 261 .neigh_lookup = ip6_neigh_lookup,
63fca65d 262 .confirm_neigh = ip6_confirm_neigh,
1da177e4
LT
263};
264
ebb762f2 265static unsigned int ip6_blackhole_mtu(const struct dst_entry *dst)
ec831ea7 266{
618f9bc7
SK
267 unsigned int mtu = dst_metric_raw(dst, RTAX_MTU);
268
269 return mtu ? : dst->dev->mtu;
ec831ea7
RD
270}
271
6700c270
DM
272static void ip6_rt_blackhole_update_pmtu(struct dst_entry *dst, struct sock *sk,
273 struct sk_buff *skb, u32 mtu)
14e50e57
DM
274{
275}
276
6700c270
DM
277static void ip6_rt_blackhole_redirect(struct dst_entry *dst, struct sock *sk,
278 struct sk_buff *skb)
b587ee3b
DM
279{
280}
281
14e50e57
DM
282static struct dst_ops ip6_dst_blackhole_ops = {
283 .family = AF_INET6,
14e50e57
DM
284 .destroy = ip6_dst_destroy,
285 .check = ip6_dst_check,
ebb762f2 286 .mtu = ip6_blackhole_mtu,
214f45c9 287 .default_advmss = ip6_default_advmss,
14e50e57 288 .update_pmtu = ip6_rt_blackhole_update_pmtu,
b587ee3b 289 .redirect = ip6_rt_blackhole_redirect,
0a1f5962 290 .cow_metrics = dst_cow_metrics_generic,
d3aaeb38 291 .neigh_lookup = ip6_neigh_lookup,
14e50e57
DM
292};
293
62fa8a84 294static const u32 ip6_template_metrics[RTAX_MAX] = {
14edd87d 295 [RTAX_HOPLIMIT - 1] = 0,
62fa8a84
DM
296};
297
fb0af4c7 298static const struct rt6_info ip6_null_entry_template = {
d8d1f30b
CG
299 .dst = {
300 .__refcnt = ATOMIC_INIT(1),
301 .__use = 1,
2c20cbd7 302 .obsolete = DST_OBSOLETE_FORCE_CHK,
d8d1f30b 303 .error = -ENETUNREACH,
d8d1f30b
CG
304 .input = ip6_pkt_discard,
305 .output = ip6_pkt_discard_out,
1da177e4
LT
306 },
307 .rt6i_flags = (RTF_REJECT | RTF_NONEXTHOP),
4f724279 308 .rt6i_protocol = RTPROT_KERNEL,
1da177e4
LT
309 .rt6i_metric = ~(u32) 0,
310 .rt6i_ref = ATOMIC_INIT(1),
311};
312
101367c2
TG
313#ifdef CONFIG_IPV6_MULTIPLE_TABLES
314
fb0af4c7 315static const struct rt6_info ip6_prohibit_entry_template = {
d8d1f30b
CG
316 .dst = {
317 .__refcnt = ATOMIC_INIT(1),
318 .__use = 1,
2c20cbd7 319 .obsolete = DST_OBSOLETE_FORCE_CHK,
d8d1f30b 320 .error = -EACCES,
d8d1f30b
CG
321 .input = ip6_pkt_prohibit,
322 .output = ip6_pkt_prohibit_out,
101367c2
TG
323 },
324 .rt6i_flags = (RTF_REJECT | RTF_NONEXTHOP),
4f724279 325 .rt6i_protocol = RTPROT_KERNEL,
101367c2
TG
326 .rt6i_metric = ~(u32) 0,
327 .rt6i_ref = ATOMIC_INIT(1),
328};
329
fb0af4c7 330static const struct rt6_info ip6_blk_hole_entry_template = {
d8d1f30b
CG
331 .dst = {
332 .__refcnt = ATOMIC_INIT(1),
333 .__use = 1,
2c20cbd7 334 .obsolete = DST_OBSOLETE_FORCE_CHK,
d8d1f30b 335 .error = -EINVAL,
d8d1f30b 336 .input = dst_discard,
ede2059d 337 .output = dst_discard_out,
101367c2
TG
338 },
339 .rt6i_flags = (RTF_REJECT | RTF_NONEXTHOP),
4f724279 340 .rt6i_protocol = RTPROT_KERNEL,
101367c2
TG
341 .rt6i_metric = ~(u32) 0,
342 .rt6i_ref = ATOMIC_INIT(1),
343};
344
345#endif
346
ebfa45f0
MKL
347static void rt6_info_init(struct rt6_info *rt)
348{
349 struct dst_entry *dst = &rt->dst;
350
351 memset(dst + 1, 0, sizeof(*rt) - sizeof(*dst));
352 INIT_LIST_HEAD(&rt->rt6i_siblings);
353 INIT_LIST_HEAD(&rt->rt6i_uncached);
354}
355
1da177e4 356/* allocate dst with ip6_dst_ops */
d52d3997
MKL
357static struct rt6_info *__ip6_dst_alloc(struct net *net,
358 struct net_device *dev,
ad706862 359 int flags)
1da177e4 360{
97bab73f 361 struct rt6_info *rt = dst_alloc(&net->ipv6.ip6_dst_ops, dev,
b2a9c0ed 362 1, DST_OBSOLETE_FORCE_CHK, flags);
cf911662 363
81eb8447 364 if (rt) {
ebfa45f0 365 rt6_info_init(rt);
81eb8447
WW
366 atomic_inc(&net->ipv6.rt6_stats->fib_rt_alloc);
367 }
8104891b 368
cf911662 369 return rt;
1da177e4
LT
370}
371
9ab179d8
DA
372struct rt6_info *ip6_dst_alloc(struct net *net,
373 struct net_device *dev,
374 int flags)
d52d3997 375{
ad706862 376 struct rt6_info *rt = __ip6_dst_alloc(net, dev, flags);
d52d3997
MKL
377
378 if (rt) {
379 rt->rt6i_pcpu = alloc_percpu_gfp(struct rt6_info *, GFP_ATOMIC);
bfd8e5a4 380 if (!rt->rt6i_pcpu) {
587fea74 381 dst_release_immediate(&rt->dst);
d52d3997
MKL
382 return NULL;
383 }
384 }
385
386 return rt;
387}
9ab179d8 388EXPORT_SYMBOL(ip6_dst_alloc);
d52d3997 389
1da177e4
LT
390static void ip6_dst_destroy(struct dst_entry *dst)
391{
392 struct rt6_info *rt = (struct rt6_info *)dst;
35732d01 393 struct rt6_exception_bucket *bucket;
3a2232e9 394 struct rt6_info *from = rt->from;
8d0b94af 395 struct inet6_dev *idev;
1da177e4 396
4b32b5ad 397 dst_destroy_metrics_generic(dst);
87775312 398 free_percpu(rt->rt6i_pcpu);
8d0b94af
MKL
399 rt6_uncached_list_del(rt);
400
401 idev = rt->rt6i_idev;
38308473 402 if (idev) {
1da177e4
LT
403 rt->rt6i_idev = NULL;
404 in6_dev_put(idev);
1ab1457c 405 }
35732d01
WW
406 bucket = rcu_dereference_protected(rt->rt6i_exception_bucket, 1);
407 if (bucket) {
408 rt->rt6i_exception_bucket = NULL;
409 kfree(bucket);
410 }
1716a961 411
3a2232e9
DM
412 rt->from = NULL;
413 dst_release(&from->dst);
b3419363
DM
414}
415
1da177e4
LT
416static void ip6_dst_ifdown(struct dst_entry *dst, struct net_device *dev,
417 int how)
418{
419 struct rt6_info *rt = (struct rt6_info *)dst;
420 struct inet6_dev *idev = rt->rt6i_idev;
5a3e55d6 421 struct net_device *loopback_dev =
c346dca1 422 dev_net(dev)->loopback_dev;
1da177e4 423
e5645f51
WW
424 if (idev && idev->dev != loopback_dev) {
425 struct inet6_dev *loopback_idev = in6_dev_get(loopback_dev);
426 if (loopback_idev) {
427 rt->rt6i_idev = loopback_idev;
428 in6_dev_put(idev);
97cac082 429 }
1da177e4
LT
430 }
431}
432
5973fb1e
MKL
433static bool __rt6_check_expired(const struct rt6_info *rt)
434{
435 if (rt->rt6i_flags & RTF_EXPIRES)
436 return time_after(jiffies, rt->dst.expires);
437 else
438 return false;
439}
440
a50feda5 441static bool rt6_check_expired(const struct rt6_info *rt)
1da177e4 442{
1716a961
G
443 if (rt->rt6i_flags & RTF_EXPIRES) {
444 if (time_after(jiffies, rt->dst.expires))
a50feda5 445 return true;
3a2232e9 446 } else if (rt->from) {
1e2ea8ad 447 return rt->dst.obsolete != DST_OBSOLETE_FORCE_CHK ||
3a2232e9 448 rt6_check_expired(rt->from);
1716a961 449 }
a50feda5 450 return false;
1da177e4
LT
451}
452
51ebd318 453static struct rt6_info *rt6_multipath_select(struct rt6_info *match,
52bd4c0c
ND
454 struct flowi6 *fl6, int oif,
455 int strict)
51ebd318
ND
456{
457 struct rt6_info *sibling, *next_sibling;
458 int route_choosen;
459
b673d6cc
JS
460 /* We might have already computed the hash for ICMPv6 errors. In such
461 * case it will always be non-zero. Otherwise now is the time to do it.
462 */
463 if (!fl6->mp_hash)
464 fl6->mp_hash = rt6_multipath_hash(fl6, NULL);
465
466 route_choosen = fl6->mp_hash % (match->rt6i_nsiblings + 1);
51ebd318
ND
467 /* Don't change the route, if route_choosen == 0
468 * (siblings does not include ourself)
469 */
470 if (route_choosen)
471 list_for_each_entry_safe(sibling, next_sibling,
472 &match->rt6i_siblings, rt6i_siblings) {
473 route_choosen--;
474 if (route_choosen == 0) {
bbfcd776
IS
475 struct inet6_dev *idev = sibling->rt6i_idev;
476
8067bb8c
IS
477 if (sibling->rt6i_nh_flags & RTNH_F_DEAD)
478 break;
14c5206c 479 if (sibling->rt6i_nh_flags & RTNH_F_LINKDOWN &&
bbfcd776
IS
480 idev->cnf.ignore_routes_with_linkdown)
481 break;
52bd4c0c
ND
482 if (rt6_score_route(sibling, oif, strict) < 0)
483 break;
51ebd318
ND
484 match = sibling;
485 break;
486 }
487 }
488 return match;
489}
490
1da177e4 491/*
66f5d6ce 492 * Route lookup. rcu_read_lock() should be held.
1da177e4
LT
493 */
494
8ed67789
DL
495static inline struct rt6_info *rt6_device_match(struct net *net,
496 struct rt6_info *rt,
b71d1d42 497 const struct in6_addr *saddr,
1da177e4 498 int oif,
d420895e 499 int flags)
1da177e4
LT
500{
501 struct rt6_info *local = NULL;
502 struct rt6_info *sprt;
503
8067bb8c
IS
504 if (!oif && ipv6_addr_any(saddr) && !(rt->rt6i_nh_flags & RTNH_F_DEAD))
505 return rt;
dd3abc4e 506
071fb37e 507 for (sprt = rt; sprt; sprt = rcu_dereference(sprt->rt6_next)) {
d1918542 508 struct net_device *dev = sprt->dst.dev;
dd3abc4e 509
8067bb8c
IS
510 if (sprt->rt6i_nh_flags & RTNH_F_DEAD)
511 continue;
512
dd3abc4e 513 if (oif) {
1da177e4
LT
514 if (dev->ifindex == oif)
515 return sprt;
516 if (dev->flags & IFF_LOOPBACK) {
38308473 517 if (!sprt->rt6i_idev ||
1da177e4 518 sprt->rt6i_idev->dev->ifindex != oif) {
17fb0b2b 519 if (flags & RT6_LOOKUP_F_IFACE)
1da177e4 520 continue;
17fb0b2b
DA
521 if (local &&
522 local->rt6i_idev->dev->ifindex == oif)
1da177e4
LT
523 continue;
524 }
525 local = sprt;
526 }
dd3abc4e
YH
527 } else {
528 if (ipv6_chk_addr(net, saddr, dev,
529 flags & RT6_LOOKUP_F_IFACE))
530 return sprt;
1da177e4 531 }
dd3abc4e 532 }
1da177e4 533
dd3abc4e 534 if (oif) {
1da177e4
LT
535 if (local)
536 return local;
537
d420895e 538 if (flags & RT6_LOOKUP_F_IFACE)
8ed67789 539 return net->ipv6.ip6_null_entry;
1da177e4 540 }
8067bb8c
IS
541
542 return rt->rt6i_nh_flags & RTNH_F_DEAD ? net->ipv6.ip6_null_entry : rt;
1da177e4
LT
543}
544
27097255 545#ifdef CONFIG_IPV6_ROUTER_PREF
c2f17e82
HFS
546struct __rt6_probe_work {
547 struct work_struct work;
548 struct in6_addr target;
549 struct net_device *dev;
550};
551
552static void rt6_probe_deferred(struct work_struct *w)
553{
554 struct in6_addr mcaddr;
555 struct __rt6_probe_work *work =
556 container_of(w, struct __rt6_probe_work, work);
557
558 addrconf_addr_solict_mult(&work->target, &mcaddr);
adc176c5 559 ndisc_send_ns(work->dev, &work->target, &mcaddr, NULL, 0);
c2f17e82 560 dev_put(work->dev);
662f5533 561 kfree(work);
c2f17e82
HFS
562}
563
27097255
YH
564static void rt6_probe(struct rt6_info *rt)
565{
990edb42 566 struct __rt6_probe_work *work;
f2c31e32 567 struct neighbour *neigh;
27097255
YH
568 /*
569 * Okay, this does not seem to be appropriate
570 * for now, however, we need to check if it
571 * is really so; aka Router Reachability Probing.
572 *
573 * Router Reachability Probe MUST be rate-limited
574 * to no more than one per minute.
575 */
2152caea 576 if (!rt || !(rt->rt6i_flags & RTF_GATEWAY))
7ff74a59 577 return;
2152caea
YH
578 rcu_read_lock_bh();
579 neigh = __ipv6_neigh_lookup_noref(rt->dst.dev, &rt->rt6i_gateway);
580 if (neigh) {
8d6c31bf
MKL
581 if (neigh->nud_state & NUD_VALID)
582 goto out;
583
990edb42 584 work = NULL;
2152caea 585 write_lock(&neigh->lock);
990edb42
MKL
586 if (!(neigh->nud_state & NUD_VALID) &&
587 time_after(jiffies,
588 neigh->updated +
589 rt->rt6i_idev->cnf.rtr_probe_interval)) {
590 work = kmalloc(sizeof(*work), GFP_ATOMIC);
591 if (work)
592 __neigh_set_probe_once(neigh);
c2f17e82 593 }
2152caea 594 write_unlock(&neigh->lock);
990edb42
MKL
595 } else {
596 work = kmalloc(sizeof(*work), GFP_ATOMIC);
f2c31e32 597 }
990edb42
MKL
598
599 if (work) {
600 INIT_WORK(&work->work, rt6_probe_deferred);
601 work->target = rt->rt6i_gateway;
602 dev_hold(rt->dst.dev);
603 work->dev = rt->dst.dev;
604 schedule_work(&work->work);
605 }
606
8d6c31bf 607out:
2152caea 608 rcu_read_unlock_bh();
27097255
YH
609}
610#else
611static inline void rt6_probe(struct rt6_info *rt)
612{
27097255
YH
613}
614#endif
615
1da177e4 616/*
554cfb7e 617 * Default Router Selection (RFC 2461 6.3.6)
1da177e4 618 */
b6f99a21 619static inline int rt6_check_dev(struct rt6_info *rt, int oif)
554cfb7e 620{
d1918542 621 struct net_device *dev = rt->dst.dev;
161980f4 622 if (!oif || dev->ifindex == oif)
554cfb7e 623 return 2;
161980f4
DM
624 if ((dev->flags & IFF_LOOPBACK) &&
625 rt->rt6i_idev && rt->rt6i_idev->dev->ifindex == oif)
626 return 1;
627 return 0;
554cfb7e 628}
1da177e4 629
afc154e9 630static inline enum rt6_nud_state rt6_check_neigh(struct rt6_info *rt)
1da177e4 631{
f2c31e32 632 struct neighbour *neigh;
afc154e9 633 enum rt6_nud_state ret = RT6_NUD_FAIL_HARD;
f2c31e32 634
4d0c5911
YH
635 if (rt->rt6i_flags & RTF_NONEXTHOP ||
636 !(rt->rt6i_flags & RTF_GATEWAY))
afc154e9 637 return RT6_NUD_SUCCEED;
145a3621
YH
638
639 rcu_read_lock_bh();
640 neigh = __ipv6_neigh_lookup_noref(rt->dst.dev, &rt->rt6i_gateway);
641 if (neigh) {
642 read_lock(&neigh->lock);
554cfb7e 643 if (neigh->nud_state & NUD_VALID)
afc154e9 644 ret = RT6_NUD_SUCCEED;
398bcbeb 645#ifdef CONFIG_IPV6_ROUTER_PREF
a5a81f0b 646 else if (!(neigh->nud_state & NUD_FAILED))
afc154e9 647 ret = RT6_NUD_SUCCEED;
7e980569
JB
648 else
649 ret = RT6_NUD_FAIL_PROBE;
398bcbeb 650#endif
145a3621 651 read_unlock(&neigh->lock);
afc154e9
HFS
652 } else {
653 ret = IS_ENABLED(CONFIG_IPV6_ROUTER_PREF) ?
7e980569 654 RT6_NUD_SUCCEED : RT6_NUD_FAIL_DO_RR;
a5a81f0b 655 }
145a3621
YH
656 rcu_read_unlock_bh();
657
a5a81f0b 658 return ret;
1da177e4
LT
659}
660
554cfb7e
YH
661static int rt6_score_route(struct rt6_info *rt, int oif,
662 int strict)
1da177e4 663{
a5a81f0b 664 int m;
1ab1457c 665
4d0c5911 666 m = rt6_check_dev(rt, oif);
77d16f45 667 if (!m && (strict & RT6_LOOKUP_F_IFACE))
afc154e9 668 return RT6_NUD_FAIL_HARD;
ebacaaa0
YH
669#ifdef CONFIG_IPV6_ROUTER_PREF
670 m |= IPV6_DECODE_PREF(IPV6_EXTRACT_PREF(rt->rt6i_flags)) << 2;
671#endif
afc154e9
HFS
672 if (strict & RT6_LOOKUP_F_REACHABLE) {
673 int n = rt6_check_neigh(rt);
674 if (n < 0)
675 return n;
676 }
554cfb7e
YH
677 return m;
678}
679
f11e6659 680static struct rt6_info *find_match(struct rt6_info *rt, int oif, int strict,
afc154e9
HFS
681 int *mpri, struct rt6_info *match,
682 bool *do_rr)
554cfb7e 683{
f11e6659 684 int m;
afc154e9 685 bool match_do_rr = false;
35103d11 686 struct inet6_dev *idev = rt->rt6i_idev;
35103d11 687
8067bb8c
IS
688 if (rt->rt6i_nh_flags & RTNH_F_DEAD)
689 goto out;
690
14c5206c
IS
691 if (idev->cnf.ignore_routes_with_linkdown &&
692 rt->rt6i_nh_flags & RTNH_F_LINKDOWN &&
d5d32e4b 693 !(strict & RT6_LOOKUP_F_IGNORE_LINKSTATE))
35103d11 694 goto out;
f11e6659
DM
695
696 if (rt6_check_expired(rt))
697 goto out;
698
699 m = rt6_score_route(rt, oif, strict);
7e980569 700 if (m == RT6_NUD_FAIL_DO_RR) {
afc154e9
HFS
701 match_do_rr = true;
702 m = 0; /* lowest valid score */
7e980569 703 } else if (m == RT6_NUD_FAIL_HARD) {
f11e6659 704 goto out;
afc154e9
HFS
705 }
706
707 if (strict & RT6_LOOKUP_F_REACHABLE)
708 rt6_probe(rt);
f11e6659 709
7e980569 710 /* note that m can be RT6_NUD_FAIL_PROBE at this point */
f11e6659 711 if (m > *mpri) {
afc154e9 712 *do_rr = match_do_rr;
f11e6659
DM
713 *mpri = m;
714 match = rt;
f11e6659 715 }
f11e6659
DM
716out:
717 return match;
718}
719
720static struct rt6_info *find_rr_leaf(struct fib6_node *fn,
8d1040e8 721 struct rt6_info *leaf,
f11e6659 722 struct rt6_info *rr_head,
afc154e9
HFS
723 u32 metric, int oif, int strict,
724 bool *do_rr)
f11e6659 725{
9fbdcfaf 726 struct rt6_info *rt, *match, *cont;
554cfb7e 727 int mpri = -1;
1da177e4 728
f11e6659 729 match = NULL;
9fbdcfaf 730 cont = NULL;
071fb37e 731 for (rt = rr_head; rt; rt = rcu_dereference(rt->rt6_next)) {
9fbdcfaf
SK
732 if (rt->rt6i_metric != metric) {
733 cont = rt;
734 break;
735 }
736
737 match = find_match(rt, oif, strict, &mpri, match, do_rr);
738 }
739
66f5d6ce 740 for (rt = leaf; rt && rt != rr_head;
071fb37e 741 rt = rcu_dereference(rt->rt6_next)) {
9fbdcfaf
SK
742 if (rt->rt6i_metric != metric) {
743 cont = rt;
744 break;
745 }
746
afc154e9 747 match = find_match(rt, oif, strict, &mpri, match, do_rr);
9fbdcfaf
SK
748 }
749
750 if (match || !cont)
751 return match;
752
071fb37e 753 for (rt = cont; rt; rt = rcu_dereference(rt->rt6_next))
afc154e9 754 match = find_match(rt, oif, strict, &mpri, match, do_rr);
1da177e4 755
f11e6659
DM
756 return match;
757}
1da177e4 758
8d1040e8
WW
759static struct rt6_info *rt6_select(struct net *net, struct fib6_node *fn,
760 int oif, int strict)
f11e6659 761{
66f5d6ce 762 struct rt6_info *leaf = rcu_dereference(fn->leaf);
f11e6659 763 struct rt6_info *match, *rt0;
afc154e9 764 bool do_rr = false;
17ecf590 765 int key_plen;
1da177e4 766
87b1af8d 767 if (!leaf || leaf == net->ipv6.ip6_null_entry)
8d1040e8
WW
768 return net->ipv6.ip6_null_entry;
769
66f5d6ce 770 rt0 = rcu_dereference(fn->rr_ptr);
f11e6659 771 if (!rt0)
66f5d6ce 772 rt0 = leaf;
1da177e4 773
17ecf590
WW
774 /* Double check to make sure fn is not an intermediate node
775 * and fn->leaf does not points to its child's leaf
776 * (This might happen if all routes under fn are deleted from
777 * the tree and fib6_repair_tree() is called on the node.)
778 */
779 key_plen = rt0->rt6i_dst.plen;
780#ifdef CONFIG_IPV6_SUBTREES
781 if (rt0->rt6i_src.plen)
782 key_plen = rt0->rt6i_src.plen;
783#endif
784 if (fn->fn_bit != key_plen)
785 return net->ipv6.ip6_null_entry;
786
8d1040e8 787 match = find_rr_leaf(fn, leaf, rt0, rt0->rt6i_metric, oif, strict,
afc154e9 788 &do_rr);
1da177e4 789
afc154e9 790 if (do_rr) {
071fb37e 791 struct rt6_info *next = rcu_dereference(rt0->rt6_next);
f11e6659 792
554cfb7e 793 /* no entries matched; do round-robin */
f11e6659 794 if (!next || next->rt6i_metric != rt0->rt6i_metric)
8d1040e8 795 next = leaf;
f11e6659 796
66f5d6ce
WW
797 if (next != rt0) {
798 spin_lock_bh(&leaf->rt6i_table->tb6_lock);
799 /* make sure next is not being deleted from the tree */
800 if (next->rt6i_node)
801 rcu_assign_pointer(fn->rr_ptr, next);
802 spin_unlock_bh(&leaf->rt6i_table->tb6_lock);
803 }
1da177e4 804 }
1da177e4 805
a02cec21 806 return match ? match : net->ipv6.ip6_null_entry;
1da177e4
LT
807}
808
8b9df265
MKL
809static bool rt6_is_gw_or_nonexthop(const struct rt6_info *rt)
810{
811 return (rt->rt6i_flags & (RTF_NONEXTHOP | RTF_GATEWAY));
812}
813
70ceb4f5
YH
814#ifdef CONFIG_IPV6_ROUTE_INFO
815int rt6_route_rcv(struct net_device *dev, u8 *opt, int len,
b71d1d42 816 const struct in6_addr *gwaddr)
70ceb4f5 817{
c346dca1 818 struct net *net = dev_net(dev);
70ceb4f5
YH
819 struct route_info *rinfo = (struct route_info *) opt;
820 struct in6_addr prefix_buf, *prefix;
821 unsigned int pref;
4bed72e4 822 unsigned long lifetime;
70ceb4f5
YH
823 struct rt6_info *rt;
824
825 if (len < sizeof(struct route_info)) {
826 return -EINVAL;
827 }
828
829 /* Sanity check for prefix_len and length */
830 if (rinfo->length > 3) {
831 return -EINVAL;
832 } else if (rinfo->prefix_len > 128) {
833 return -EINVAL;
834 } else if (rinfo->prefix_len > 64) {
835 if (rinfo->length < 2) {
836 return -EINVAL;
837 }
838 } else if (rinfo->prefix_len > 0) {
839 if (rinfo->length < 1) {
840 return -EINVAL;
841 }
842 }
843
844 pref = rinfo->route_pref;
845 if (pref == ICMPV6_ROUTER_PREF_INVALID)
3933fc95 846 return -EINVAL;
70ceb4f5 847
4bed72e4 848 lifetime = addrconf_timeout_fixup(ntohl(rinfo->lifetime), HZ);
70ceb4f5
YH
849
850 if (rinfo->length == 3)
851 prefix = (struct in6_addr *)rinfo->prefix;
852 else {
853 /* this function is safe */
854 ipv6_addr_prefix(&prefix_buf,
855 (struct in6_addr *)rinfo->prefix,
856 rinfo->prefix_len);
857 prefix = &prefix_buf;
858 }
859
f104a567
DJ
860 if (rinfo->prefix_len == 0)
861 rt = rt6_get_dflt_router(gwaddr, dev);
862 else
863 rt = rt6_get_route_info(net, prefix, rinfo->prefix_len,
830218c1 864 gwaddr, dev);
70ceb4f5
YH
865
866 if (rt && !lifetime) {
e0a1ad73 867 ip6_del_rt(rt);
70ceb4f5
YH
868 rt = NULL;
869 }
870
871 if (!rt && lifetime)
830218c1
DA
872 rt = rt6_add_route_info(net, prefix, rinfo->prefix_len, gwaddr,
873 dev, pref);
70ceb4f5
YH
874 else if (rt)
875 rt->rt6i_flags = RTF_ROUTEINFO |
876 (rt->rt6i_flags & ~RTF_PREF_MASK) | RTF_PREF(pref);
877
878 if (rt) {
1716a961
G
879 if (!addrconf_finite_timeout(lifetime))
880 rt6_clean_expires(rt);
881 else
882 rt6_set_expires(rt, jiffies + HZ * lifetime);
883
94e187c0 884 ip6_rt_put(rt);
70ceb4f5
YH
885 }
886 return 0;
887}
888#endif
889
a3c00e46
MKL
890static struct fib6_node* fib6_backtrack(struct fib6_node *fn,
891 struct in6_addr *saddr)
892{
66f5d6ce 893 struct fib6_node *pn, *sn;
a3c00e46
MKL
894 while (1) {
895 if (fn->fn_flags & RTN_TL_ROOT)
896 return NULL;
66f5d6ce
WW
897 pn = rcu_dereference(fn->parent);
898 sn = FIB6_SUBTREE(pn);
899 if (sn && sn != fn)
900 fn = fib6_lookup(sn, NULL, saddr);
a3c00e46
MKL
901 else
902 fn = pn;
903 if (fn->fn_flags & RTN_RTINFO)
904 return fn;
905 }
906}
c71099ac 907
d3843fe5
WW
908static bool ip6_hold_safe(struct net *net, struct rt6_info **prt,
909 bool null_fallback)
910{
911 struct rt6_info *rt = *prt;
912
913 if (dst_hold_safe(&rt->dst))
914 return true;
915 if (null_fallback) {
916 rt = net->ipv6.ip6_null_entry;
917 dst_hold(&rt->dst);
918 } else {
919 rt = NULL;
920 }
921 *prt = rt;
922 return false;
923}
924
8ed67789
DL
925static struct rt6_info *ip6_pol_route_lookup(struct net *net,
926 struct fib6_table *table,
4c9483b2 927 struct flowi6 *fl6, int flags)
1da177e4 928{
2b760fcf 929 struct rt6_info *rt, *rt_cache;
1da177e4 930 struct fib6_node *fn;
1da177e4 931
66f5d6ce 932 rcu_read_lock();
4c9483b2 933 fn = fib6_lookup(&table->tb6_root, &fl6->daddr, &fl6->saddr);
c71099ac 934restart:
66f5d6ce
WW
935 rt = rcu_dereference(fn->leaf);
936 if (!rt) {
937 rt = net->ipv6.ip6_null_entry;
938 } else {
939 rt = rt6_device_match(net, rt, &fl6->saddr,
940 fl6->flowi6_oif, flags);
941 if (rt->rt6i_nsiblings && fl6->flowi6_oif == 0)
942 rt = rt6_multipath_select(rt, fl6,
943 fl6->flowi6_oif, flags);
944 }
a3c00e46
MKL
945 if (rt == net->ipv6.ip6_null_entry) {
946 fn = fib6_backtrack(fn, &fl6->saddr);
947 if (fn)
948 goto restart;
949 }
2b760fcf
WW
950 /* Search through exception table */
951 rt_cache = rt6_find_cached_rt(rt, &fl6->daddr, &fl6->saddr);
952 if (rt_cache)
953 rt = rt_cache;
954
d3843fe5
WW
955 if (ip6_hold_safe(net, &rt, true))
956 dst_use_noref(&rt->dst, jiffies);
957
66f5d6ce 958 rcu_read_unlock();
b811580d 959
b65f164d 960 trace_fib6_table_lookup(net, rt, table, fl6);
b811580d 961
c71099ac
TG
962 return rt;
963
964}
965
67ba4152 966struct dst_entry *ip6_route_lookup(struct net *net, struct flowi6 *fl6,
ea6e574e
FW
967 int flags)
968{
969 return fib6_rule_lookup(net, fl6, flags, ip6_pol_route_lookup);
970}
971EXPORT_SYMBOL_GPL(ip6_route_lookup);
972
9acd9f3a
YH
973struct rt6_info *rt6_lookup(struct net *net, const struct in6_addr *daddr,
974 const struct in6_addr *saddr, int oif, int strict)
c71099ac 975{
4c9483b2
DM
976 struct flowi6 fl6 = {
977 .flowi6_oif = oif,
978 .daddr = *daddr,
c71099ac
TG
979 };
980 struct dst_entry *dst;
77d16f45 981 int flags = strict ? RT6_LOOKUP_F_IFACE : 0;
c71099ac 982
adaa70bb 983 if (saddr) {
4c9483b2 984 memcpy(&fl6.saddr, saddr, sizeof(*saddr));
adaa70bb
TG
985 flags |= RT6_LOOKUP_F_HAS_SADDR;
986 }
987
4c9483b2 988 dst = fib6_rule_lookup(net, &fl6, flags, ip6_pol_route_lookup);
c71099ac
TG
989 if (dst->error == 0)
990 return (struct rt6_info *) dst;
991
992 dst_release(dst);
993
1da177e4
LT
994 return NULL;
995}
7159039a
YH
996EXPORT_SYMBOL(rt6_lookup);
997
c71099ac 998/* ip6_ins_rt is called with FREE table->tb6_lock.
1cfb71ee
WW
999 * It takes new route entry, the addition fails by any reason the
1000 * route is released.
1001 * Caller must hold dst before calling it.
1da177e4
LT
1002 */
1003
e5fd387a 1004static int __ip6_ins_rt(struct rt6_info *rt, struct nl_info *info,
333c4301
DA
1005 struct mx6_config *mxc,
1006 struct netlink_ext_ack *extack)
1da177e4
LT
1007{
1008 int err;
c71099ac 1009 struct fib6_table *table;
1da177e4 1010
c71099ac 1011 table = rt->rt6i_table;
66f5d6ce 1012 spin_lock_bh(&table->tb6_lock);
333c4301 1013 err = fib6_add(&table->tb6_root, rt, info, mxc, extack);
66f5d6ce 1014 spin_unlock_bh(&table->tb6_lock);
1da177e4
LT
1015
1016 return err;
1017}
1018
40e22e8f
TG
1019int ip6_ins_rt(struct rt6_info *rt)
1020{
e715b6d3
FW
1021 struct nl_info info = { .nl_net = dev_net(rt->dst.dev), };
1022 struct mx6_config mxc = { .mx = NULL, };
1023
1cfb71ee
WW
1024 /* Hold dst to account for the reference from the fib6 tree */
1025 dst_hold(&rt->dst);
333c4301 1026 return __ip6_ins_rt(rt, &info, &mxc, NULL);
40e22e8f
TG
1027}
1028
4832c30d
DA
1029/* called with rcu_lock held */
1030static struct net_device *ip6_rt_get_dev_rcu(struct rt6_info *rt)
1031{
1032 struct net_device *dev = rt->dst.dev;
1033
98d11291 1034 if (rt->rt6i_flags & (RTF_LOCAL | RTF_ANYCAST)) {
4832c30d
DA
1035 /* for copies of local routes, dst->dev needs to be the
1036 * device if it is a master device, the master device if
1037 * device is enslaved, and the loopback as the default
1038 */
1039 if (netif_is_l3_slave(dev) &&
1040 !rt6_need_strict(&rt->rt6i_dst.addr))
1041 dev = l3mdev_master_dev_rcu(dev);
1042 else if (!netif_is_l3_master(dev))
1043 dev = dev_net(dev)->loopback_dev;
1044 /* last case is netif_is_l3_master(dev) is true in which
1045 * case we want dev returned to be dev
1046 */
1047 }
1048
1049 return dev;
1050}
1051
8b9df265
MKL
1052static struct rt6_info *ip6_rt_cache_alloc(struct rt6_info *ort,
1053 const struct in6_addr *daddr,
1054 const struct in6_addr *saddr)
1da177e4 1055{
4832c30d 1056 struct net_device *dev;
1da177e4
LT
1057 struct rt6_info *rt;
1058
1059 /*
1060 * Clone the route.
1061 */
1062
d52d3997 1063 if (ort->rt6i_flags & (RTF_CACHE | RTF_PCPU))
3a2232e9 1064 ort = ort->from;
1da177e4 1065
4832c30d
DA
1066 rcu_read_lock();
1067 dev = ip6_rt_get_dev_rcu(ort);
1068 rt = __ip6_dst_alloc(dev_net(dev), dev, 0);
1069 rcu_read_unlock();
83a09abd
MKL
1070 if (!rt)
1071 return NULL;
1072
1073 ip6_rt_copy_init(rt, ort);
1074 rt->rt6i_flags |= RTF_CACHE;
1075 rt->rt6i_metric = 0;
1076 rt->dst.flags |= DST_HOST;
1077 rt->rt6i_dst.addr = *daddr;
1078 rt->rt6i_dst.plen = 128;
1da177e4 1079
83a09abd
MKL
1080 if (!rt6_is_gw_or_nonexthop(ort)) {
1081 if (ort->rt6i_dst.plen != 128 &&
1082 ipv6_addr_equal(&ort->rt6i_dst.addr, daddr))
1083 rt->rt6i_flags |= RTF_ANYCAST;
1da177e4 1084#ifdef CONFIG_IPV6_SUBTREES
83a09abd
MKL
1085 if (rt->rt6i_src.plen && saddr) {
1086 rt->rt6i_src.addr = *saddr;
1087 rt->rt6i_src.plen = 128;
8b9df265 1088 }
83a09abd 1089#endif
95a9a5ba 1090 }
1da177e4 1091
95a9a5ba
YH
1092 return rt;
1093}
1da177e4 1094
d52d3997
MKL
1095static struct rt6_info *ip6_rt_pcpu_alloc(struct rt6_info *rt)
1096{
4832c30d 1097 struct net_device *dev;
d52d3997
MKL
1098 struct rt6_info *pcpu_rt;
1099
4832c30d
DA
1100 rcu_read_lock();
1101 dev = ip6_rt_get_dev_rcu(rt);
1102 pcpu_rt = __ip6_dst_alloc(dev_net(dev), dev, rt->dst.flags);
1103 rcu_read_unlock();
d52d3997
MKL
1104 if (!pcpu_rt)
1105 return NULL;
1106 ip6_rt_copy_init(pcpu_rt, rt);
1107 pcpu_rt->rt6i_protocol = rt->rt6i_protocol;
1108 pcpu_rt->rt6i_flags |= RTF_PCPU;
1109 return pcpu_rt;
1110}
1111
66f5d6ce 1112/* It should be called with rcu_read_lock() acquired */
d52d3997
MKL
1113static struct rt6_info *rt6_get_pcpu_route(struct rt6_info *rt)
1114{
a73e4195 1115 struct rt6_info *pcpu_rt, **p;
d52d3997
MKL
1116
1117 p = this_cpu_ptr(rt->rt6i_pcpu);
1118 pcpu_rt = *p;
1119
d3843fe5 1120 if (pcpu_rt && ip6_hold_safe(NULL, &pcpu_rt, false))
a73e4195 1121 rt6_dst_from_metrics_check(pcpu_rt);
d3843fe5 1122
a73e4195
MKL
1123 return pcpu_rt;
1124}
1125
1126static struct rt6_info *rt6_make_pcpu_route(struct rt6_info *rt)
1127{
1128 struct rt6_info *pcpu_rt, *prev, **p;
d52d3997
MKL
1129
1130 pcpu_rt = ip6_rt_pcpu_alloc(rt);
1131 if (!pcpu_rt) {
1132 struct net *net = dev_net(rt->dst.dev);
1133
9c7370a1
MKL
1134 dst_hold(&net->ipv6.ip6_null_entry->dst);
1135 return net->ipv6.ip6_null_entry;
d52d3997
MKL
1136 }
1137
a94b9367
WW
1138 dst_hold(&pcpu_rt->dst);
1139 p = this_cpu_ptr(rt->rt6i_pcpu);
1140 prev = cmpxchg(p, NULL, pcpu_rt);
951f788a 1141 BUG_ON(prev);
a94b9367 1142
d52d3997
MKL
1143 rt6_dst_from_metrics_check(pcpu_rt);
1144 return pcpu_rt;
1145}
1146
35732d01
WW
1147/* exception hash table implementation
1148 */
1149static DEFINE_SPINLOCK(rt6_exception_lock);
1150
1151/* Remove rt6_ex from hash table and free the memory
1152 * Caller must hold rt6_exception_lock
1153 */
1154static void rt6_remove_exception(struct rt6_exception_bucket *bucket,
1155 struct rt6_exception *rt6_ex)
1156{
b2427e67 1157 struct net *net;
81eb8447 1158
35732d01
WW
1159 if (!bucket || !rt6_ex)
1160 return;
b2427e67
CIK
1161
1162 net = dev_net(rt6_ex->rt6i->dst.dev);
35732d01
WW
1163 rt6_ex->rt6i->rt6i_node = NULL;
1164 hlist_del_rcu(&rt6_ex->hlist);
1165 rt6_release(rt6_ex->rt6i);
1166 kfree_rcu(rt6_ex, rcu);
1167 WARN_ON_ONCE(!bucket->depth);
1168 bucket->depth--;
81eb8447 1169 net->ipv6.rt6_stats->fib_rt_cache--;
35732d01
WW
1170}
1171
1172/* Remove oldest rt6_ex in bucket and free the memory
1173 * Caller must hold rt6_exception_lock
1174 */
1175static void rt6_exception_remove_oldest(struct rt6_exception_bucket *bucket)
1176{
1177 struct rt6_exception *rt6_ex, *oldest = NULL;
1178
1179 if (!bucket)
1180 return;
1181
1182 hlist_for_each_entry(rt6_ex, &bucket->chain, hlist) {
1183 if (!oldest || time_before(rt6_ex->stamp, oldest->stamp))
1184 oldest = rt6_ex;
1185 }
1186 rt6_remove_exception(bucket, oldest);
1187}
1188
1189static u32 rt6_exception_hash(const struct in6_addr *dst,
1190 const struct in6_addr *src)
1191{
1192 static u32 seed __read_mostly;
1193 u32 val;
1194
1195 net_get_random_once(&seed, sizeof(seed));
1196 val = jhash(dst, sizeof(*dst), seed);
1197
1198#ifdef CONFIG_IPV6_SUBTREES
1199 if (src)
1200 val = jhash(src, sizeof(*src), val);
1201#endif
1202 return hash_32(val, FIB6_EXCEPTION_BUCKET_SIZE_SHIFT);
1203}
1204
1205/* Helper function to find the cached rt in the hash table
1206 * and update bucket pointer to point to the bucket for this
1207 * (daddr, saddr) pair
1208 * Caller must hold rt6_exception_lock
1209 */
1210static struct rt6_exception *
1211__rt6_find_exception_spinlock(struct rt6_exception_bucket **bucket,
1212 const struct in6_addr *daddr,
1213 const struct in6_addr *saddr)
1214{
1215 struct rt6_exception *rt6_ex;
1216 u32 hval;
1217
1218 if (!(*bucket) || !daddr)
1219 return NULL;
1220
1221 hval = rt6_exception_hash(daddr, saddr);
1222 *bucket += hval;
1223
1224 hlist_for_each_entry(rt6_ex, &(*bucket)->chain, hlist) {
1225 struct rt6_info *rt6 = rt6_ex->rt6i;
1226 bool matched = ipv6_addr_equal(daddr, &rt6->rt6i_dst.addr);
1227
1228#ifdef CONFIG_IPV6_SUBTREES
1229 if (matched && saddr)
1230 matched = ipv6_addr_equal(saddr, &rt6->rt6i_src.addr);
1231#endif
1232 if (matched)
1233 return rt6_ex;
1234 }
1235 return NULL;
1236}
1237
1238/* Helper function to find the cached rt in the hash table
1239 * and update bucket pointer to point to the bucket for this
1240 * (daddr, saddr) pair
1241 * Caller must hold rcu_read_lock()
1242 */
1243static struct rt6_exception *
1244__rt6_find_exception_rcu(struct rt6_exception_bucket **bucket,
1245 const struct in6_addr *daddr,
1246 const struct in6_addr *saddr)
1247{
1248 struct rt6_exception *rt6_ex;
1249 u32 hval;
1250
1251 WARN_ON_ONCE(!rcu_read_lock_held());
1252
1253 if (!(*bucket) || !daddr)
1254 return NULL;
1255
1256 hval = rt6_exception_hash(daddr, saddr);
1257 *bucket += hval;
1258
1259 hlist_for_each_entry_rcu(rt6_ex, &(*bucket)->chain, hlist) {
1260 struct rt6_info *rt6 = rt6_ex->rt6i;
1261 bool matched = ipv6_addr_equal(daddr, &rt6->rt6i_dst.addr);
1262
1263#ifdef CONFIG_IPV6_SUBTREES
1264 if (matched && saddr)
1265 matched = ipv6_addr_equal(saddr, &rt6->rt6i_src.addr);
1266#endif
1267 if (matched)
1268 return rt6_ex;
1269 }
1270 return NULL;
1271}
1272
1273static int rt6_insert_exception(struct rt6_info *nrt,
1274 struct rt6_info *ort)
1275{
81eb8447 1276 struct net *net = dev_net(ort->dst.dev);
35732d01
WW
1277 struct rt6_exception_bucket *bucket;
1278 struct in6_addr *src_key = NULL;
1279 struct rt6_exception *rt6_ex;
1280 int err = 0;
1281
1282 /* ort can't be a cache or pcpu route */
1283 if (ort->rt6i_flags & (RTF_CACHE | RTF_PCPU))
3a2232e9 1284 ort = ort->from;
35732d01
WW
1285 WARN_ON_ONCE(ort->rt6i_flags & (RTF_CACHE | RTF_PCPU));
1286
1287 spin_lock_bh(&rt6_exception_lock);
1288
1289 if (ort->exception_bucket_flushed) {
1290 err = -EINVAL;
1291 goto out;
1292 }
1293
1294 bucket = rcu_dereference_protected(ort->rt6i_exception_bucket,
1295 lockdep_is_held(&rt6_exception_lock));
1296 if (!bucket) {
1297 bucket = kcalloc(FIB6_EXCEPTION_BUCKET_SIZE, sizeof(*bucket),
1298 GFP_ATOMIC);
1299 if (!bucket) {
1300 err = -ENOMEM;
1301 goto out;
1302 }
1303 rcu_assign_pointer(ort->rt6i_exception_bucket, bucket);
1304 }
1305
1306#ifdef CONFIG_IPV6_SUBTREES
1307 /* rt6i_src.plen != 0 indicates ort is in subtree
1308 * and exception table is indexed by a hash of
1309 * both rt6i_dst and rt6i_src.
1310 * Otherwise, the exception table is indexed by
1311 * a hash of only rt6i_dst.
1312 */
1313 if (ort->rt6i_src.plen)
1314 src_key = &nrt->rt6i_src.addr;
1315#endif
60006a48
WW
1316
1317 /* Update rt6i_prefsrc as it could be changed
1318 * in rt6_remove_prefsrc()
1319 */
1320 nrt->rt6i_prefsrc = ort->rt6i_prefsrc;
f5bbe7ee
WW
1321 /* rt6_mtu_change() might lower mtu on ort.
1322 * Only insert this exception route if its mtu
1323 * is less than ort's mtu value.
1324 */
1325 if (nrt->rt6i_pmtu >= dst_mtu(&ort->dst)) {
1326 err = -EINVAL;
1327 goto out;
1328 }
60006a48 1329
35732d01
WW
1330 rt6_ex = __rt6_find_exception_spinlock(&bucket, &nrt->rt6i_dst.addr,
1331 src_key);
1332 if (rt6_ex)
1333 rt6_remove_exception(bucket, rt6_ex);
1334
1335 rt6_ex = kzalloc(sizeof(*rt6_ex), GFP_ATOMIC);
1336 if (!rt6_ex) {
1337 err = -ENOMEM;
1338 goto out;
1339 }
1340 rt6_ex->rt6i = nrt;
1341 rt6_ex->stamp = jiffies;
1342 atomic_inc(&nrt->rt6i_ref);
1343 nrt->rt6i_node = ort->rt6i_node;
1344 hlist_add_head_rcu(&rt6_ex->hlist, &bucket->chain);
1345 bucket->depth++;
81eb8447 1346 net->ipv6.rt6_stats->fib_rt_cache++;
35732d01
WW
1347
1348 if (bucket->depth > FIB6_MAX_DEPTH)
1349 rt6_exception_remove_oldest(bucket);
1350
1351out:
1352 spin_unlock_bh(&rt6_exception_lock);
1353
1354 /* Update fn->fn_sernum to invalidate all cached dst */
b886d5f2 1355 if (!err) {
922c2ac8 1356 spin_lock_bh(&ort->rt6i_table->tb6_lock);
35732d01 1357 fib6_update_sernum(ort);
922c2ac8 1358 spin_unlock_bh(&ort->rt6i_table->tb6_lock);
b886d5f2
PA
1359 fib6_force_start_gc(net);
1360 }
35732d01
WW
1361
1362 return err;
1363}
1364
1365void rt6_flush_exceptions(struct rt6_info *rt)
1366{
1367 struct rt6_exception_bucket *bucket;
1368 struct rt6_exception *rt6_ex;
1369 struct hlist_node *tmp;
1370 int i;
1371
1372 spin_lock_bh(&rt6_exception_lock);
1373 /* Prevent rt6_insert_exception() to recreate the bucket list */
1374 rt->exception_bucket_flushed = 1;
1375
1376 bucket = rcu_dereference_protected(rt->rt6i_exception_bucket,
1377 lockdep_is_held(&rt6_exception_lock));
1378 if (!bucket)
1379 goto out;
1380
1381 for (i = 0; i < FIB6_EXCEPTION_BUCKET_SIZE; i++) {
1382 hlist_for_each_entry_safe(rt6_ex, tmp, &bucket->chain, hlist)
1383 rt6_remove_exception(bucket, rt6_ex);
1384 WARN_ON_ONCE(bucket->depth);
1385 bucket++;
1386 }
1387
1388out:
1389 spin_unlock_bh(&rt6_exception_lock);
1390}
1391
1392/* Find cached rt in the hash table inside passed in rt
1393 * Caller has to hold rcu_read_lock()
1394 */
1395static struct rt6_info *rt6_find_cached_rt(struct rt6_info *rt,
1396 struct in6_addr *daddr,
1397 struct in6_addr *saddr)
1398{
1399 struct rt6_exception_bucket *bucket;
1400 struct in6_addr *src_key = NULL;
1401 struct rt6_exception *rt6_ex;
1402 struct rt6_info *res = NULL;
1403
1404 bucket = rcu_dereference(rt->rt6i_exception_bucket);
1405
1406#ifdef CONFIG_IPV6_SUBTREES
1407 /* rt6i_src.plen != 0 indicates rt is in subtree
1408 * and exception table is indexed by a hash of
1409 * both rt6i_dst and rt6i_src.
1410 * Otherwise, the exception table is indexed by
1411 * a hash of only rt6i_dst.
1412 */
1413 if (rt->rt6i_src.plen)
1414 src_key = saddr;
1415#endif
1416 rt6_ex = __rt6_find_exception_rcu(&bucket, daddr, src_key);
1417
1418 if (rt6_ex && !rt6_check_expired(rt6_ex->rt6i))
1419 res = rt6_ex->rt6i;
1420
1421 return res;
1422}
1423
1424/* Remove the passed in cached rt from the hash table that contains it */
1425int rt6_remove_exception_rt(struct rt6_info *rt)
1426{
35732d01 1427 struct rt6_exception_bucket *bucket;
3a2232e9 1428 struct rt6_info *from = rt->from;
35732d01
WW
1429 struct in6_addr *src_key = NULL;
1430 struct rt6_exception *rt6_ex;
1431 int err;
1432
1433 if (!from ||
442d713b 1434 !(rt->rt6i_flags & RTF_CACHE))
35732d01
WW
1435 return -EINVAL;
1436
1437 if (!rcu_access_pointer(from->rt6i_exception_bucket))
1438 return -ENOENT;
1439
1440 spin_lock_bh(&rt6_exception_lock);
1441 bucket = rcu_dereference_protected(from->rt6i_exception_bucket,
1442 lockdep_is_held(&rt6_exception_lock));
1443#ifdef CONFIG_IPV6_SUBTREES
1444 /* rt6i_src.plen != 0 indicates 'from' is in subtree
1445 * and exception table is indexed by a hash of
1446 * both rt6i_dst and rt6i_src.
1447 * Otherwise, the exception table is indexed by
1448 * a hash of only rt6i_dst.
1449 */
1450 if (from->rt6i_src.plen)
1451 src_key = &rt->rt6i_src.addr;
1452#endif
1453 rt6_ex = __rt6_find_exception_spinlock(&bucket,
1454 &rt->rt6i_dst.addr,
1455 src_key);
1456 if (rt6_ex) {
1457 rt6_remove_exception(bucket, rt6_ex);
1458 err = 0;
1459 } else {
1460 err = -ENOENT;
1461 }
1462
1463 spin_unlock_bh(&rt6_exception_lock);
1464 return err;
1465}
1466
1467/* Find rt6_ex which contains the passed in rt cache and
1468 * refresh its stamp
1469 */
1470static void rt6_update_exception_stamp_rt(struct rt6_info *rt)
1471{
35732d01 1472 struct rt6_exception_bucket *bucket;
3a2232e9 1473 struct rt6_info *from = rt->from;
35732d01
WW
1474 struct in6_addr *src_key = NULL;
1475 struct rt6_exception *rt6_ex;
1476
1477 if (!from ||
442d713b 1478 !(rt->rt6i_flags & RTF_CACHE))
35732d01
WW
1479 return;
1480
1481 rcu_read_lock();
1482 bucket = rcu_dereference(from->rt6i_exception_bucket);
1483
1484#ifdef CONFIG_IPV6_SUBTREES
1485 /* rt6i_src.plen != 0 indicates 'from' is in subtree
1486 * and exception table is indexed by a hash of
1487 * both rt6i_dst and rt6i_src.
1488 * Otherwise, the exception table is indexed by
1489 * a hash of only rt6i_dst.
1490 */
1491 if (from->rt6i_src.plen)
1492 src_key = &rt->rt6i_src.addr;
1493#endif
1494 rt6_ex = __rt6_find_exception_rcu(&bucket,
1495 &rt->rt6i_dst.addr,
1496 src_key);
1497 if (rt6_ex)
1498 rt6_ex->stamp = jiffies;
1499
1500 rcu_read_unlock();
1501}
1502
60006a48
WW
1503static void rt6_exceptions_remove_prefsrc(struct rt6_info *rt)
1504{
1505 struct rt6_exception_bucket *bucket;
1506 struct rt6_exception *rt6_ex;
1507 int i;
1508
1509 bucket = rcu_dereference_protected(rt->rt6i_exception_bucket,
1510 lockdep_is_held(&rt6_exception_lock));
1511
1512 if (bucket) {
1513 for (i = 0; i < FIB6_EXCEPTION_BUCKET_SIZE; i++) {
1514 hlist_for_each_entry(rt6_ex, &bucket->chain, hlist) {
1515 rt6_ex->rt6i->rt6i_prefsrc.plen = 0;
1516 }
1517 bucket++;
1518 }
1519 }
1520}
1521
f5bbe7ee
WW
1522static void rt6_exceptions_update_pmtu(struct rt6_info *rt, int mtu)
1523{
1524 struct rt6_exception_bucket *bucket;
1525 struct rt6_exception *rt6_ex;
1526 int i;
1527
1528 bucket = rcu_dereference_protected(rt->rt6i_exception_bucket,
1529 lockdep_is_held(&rt6_exception_lock));
1530
1531 if (bucket) {
1532 for (i = 0; i < FIB6_EXCEPTION_BUCKET_SIZE; i++) {
1533 hlist_for_each_entry(rt6_ex, &bucket->chain, hlist) {
1534 struct rt6_info *entry = rt6_ex->rt6i;
1535 /* For RTF_CACHE with rt6i_pmtu == 0
1536 * (i.e. a redirected route),
1537 * the metrics of its rt->dst.from has already
1538 * been updated.
1539 */
1540 if (entry->rt6i_pmtu && entry->rt6i_pmtu > mtu)
1541 entry->rt6i_pmtu = mtu;
1542 }
1543 bucket++;
1544 }
1545 }
1546}
1547
b16cb459
WW
1548#define RTF_CACHE_GATEWAY (RTF_GATEWAY | RTF_CACHE)
1549
1550static void rt6_exceptions_clean_tohost(struct rt6_info *rt,
1551 struct in6_addr *gateway)
1552{
1553 struct rt6_exception_bucket *bucket;
1554 struct rt6_exception *rt6_ex;
1555 struct hlist_node *tmp;
1556 int i;
1557
1558 if (!rcu_access_pointer(rt->rt6i_exception_bucket))
1559 return;
1560
1561 spin_lock_bh(&rt6_exception_lock);
1562 bucket = rcu_dereference_protected(rt->rt6i_exception_bucket,
1563 lockdep_is_held(&rt6_exception_lock));
1564
1565 if (bucket) {
1566 for (i = 0; i < FIB6_EXCEPTION_BUCKET_SIZE; i++) {
1567 hlist_for_each_entry_safe(rt6_ex, tmp,
1568 &bucket->chain, hlist) {
1569 struct rt6_info *entry = rt6_ex->rt6i;
1570
1571 if ((entry->rt6i_flags & RTF_CACHE_GATEWAY) ==
1572 RTF_CACHE_GATEWAY &&
1573 ipv6_addr_equal(gateway,
1574 &entry->rt6i_gateway)) {
1575 rt6_remove_exception(bucket, rt6_ex);
1576 }
1577 }
1578 bucket++;
1579 }
1580 }
1581
1582 spin_unlock_bh(&rt6_exception_lock);
1583}
1584
c757faa8
WW
1585static void rt6_age_examine_exception(struct rt6_exception_bucket *bucket,
1586 struct rt6_exception *rt6_ex,
1587 struct fib6_gc_args *gc_args,
1588 unsigned long now)
1589{
1590 struct rt6_info *rt = rt6_ex->rt6i;
1591
1859bac0
PA
1592 /* we are pruning and obsoleting aged-out and non gateway exceptions
1593 * even if others have still references to them, so that on next
1594 * dst_check() such references can be dropped.
1595 * EXPIRES exceptions - e.g. pmtu-generated ones are pruned when
1596 * expired, independently from their aging, as per RFC 8201 section 4
1597 */
1598 if (!(rt->rt6i_flags & RTF_EXPIRES) &&
c757faa8
WW
1599 time_after_eq(now, rt->dst.lastuse + gc_args->timeout)) {
1600 RT6_TRACE("aging clone %p\n", rt);
1601 rt6_remove_exception(bucket, rt6_ex);
1602 return;
1603 } else if (rt->rt6i_flags & RTF_GATEWAY) {
1604 struct neighbour *neigh;
1605 __u8 neigh_flags = 0;
1606
1607 neigh = dst_neigh_lookup(&rt->dst, &rt->rt6i_gateway);
1608 if (neigh) {
1609 neigh_flags = neigh->flags;
1610 neigh_release(neigh);
1611 }
1612 if (!(neigh_flags & NTF_ROUTER)) {
1613 RT6_TRACE("purging route %p via non-router but gateway\n",
1614 rt);
1615 rt6_remove_exception(bucket, rt6_ex);
1616 return;
1617 }
1859bac0
PA
1618 } else if (__rt6_check_expired(rt)) {
1619 RT6_TRACE("purging expired route %p\n", rt);
1620 rt6_remove_exception(bucket, rt6_ex);
1621 return;
c757faa8
WW
1622 }
1623 gc_args->more++;
1624}
1625
1626void rt6_age_exceptions(struct rt6_info *rt,
1627 struct fib6_gc_args *gc_args,
1628 unsigned long now)
1629{
1630 struct rt6_exception_bucket *bucket;
1631 struct rt6_exception *rt6_ex;
1632 struct hlist_node *tmp;
1633 int i;
1634
1635 if (!rcu_access_pointer(rt->rt6i_exception_bucket))
1636 return;
1637
1638 spin_lock_bh(&rt6_exception_lock);
1639 bucket = rcu_dereference_protected(rt->rt6i_exception_bucket,
1640 lockdep_is_held(&rt6_exception_lock));
1641
1642 if (bucket) {
1643 for (i = 0; i < FIB6_EXCEPTION_BUCKET_SIZE; i++) {
1644 hlist_for_each_entry_safe(rt6_ex, tmp,
1645 &bucket->chain, hlist) {
1646 rt6_age_examine_exception(bucket, rt6_ex,
1647 gc_args, now);
1648 }
1649 bucket++;
1650 }
1651 }
1652 spin_unlock_bh(&rt6_exception_lock);
1653}
1654
9ff74384
DA
1655struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table,
1656 int oif, struct flowi6 *fl6, int flags)
1da177e4 1657{
367efcb9 1658 struct fib6_node *fn, *saved_fn;
2b760fcf 1659 struct rt6_info *rt, *rt_cache;
c71099ac 1660 int strict = 0;
1da177e4 1661
77d16f45 1662 strict |= flags & RT6_LOOKUP_F_IFACE;
d5d32e4b 1663 strict |= flags & RT6_LOOKUP_F_IGNORE_LINKSTATE;
367efcb9
MKL
1664 if (net->ipv6.devconf_all->forwarding == 0)
1665 strict |= RT6_LOOKUP_F_REACHABLE;
1da177e4 1666
66f5d6ce 1667 rcu_read_lock();
1da177e4 1668
4c9483b2 1669 fn = fib6_lookup(&table->tb6_root, &fl6->daddr, &fl6->saddr);
367efcb9 1670 saved_fn = fn;
1da177e4 1671
ca254490
DA
1672 if (fl6->flowi6_flags & FLOWI_FLAG_SKIP_NH_OIF)
1673 oif = 0;
1674
a3c00e46 1675redo_rt6_select:
8d1040e8 1676 rt = rt6_select(net, fn, oif, strict);
52bd4c0c 1677 if (rt->rt6i_nsiblings)
367efcb9 1678 rt = rt6_multipath_select(rt, fl6, oif, strict);
a3c00e46
MKL
1679 if (rt == net->ipv6.ip6_null_entry) {
1680 fn = fib6_backtrack(fn, &fl6->saddr);
1681 if (fn)
1682 goto redo_rt6_select;
367efcb9
MKL
1683 else if (strict & RT6_LOOKUP_F_REACHABLE) {
1684 /* also consider unreachable route */
1685 strict &= ~RT6_LOOKUP_F_REACHABLE;
1686 fn = saved_fn;
1687 goto redo_rt6_select;
367efcb9 1688 }
a3c00e46
MKL
1689 }
1690
2b760fcf
WW
1691 /*Search through exception table */
1692 rt_cache = rt6_find_cached_rt(rt, &fl6->daddr, &fl6->saddr);
1693 if (rt_cache)
1694 rt = rt_cache;
fb9de91e 1695
d3843fe5 1696 if (rt == net->ipv6.ip6_null_entry) {
66f5d6ce 1697 rcu_read_unlock();
d3843fe5 1698 dst_hold(&rt->dst);
b65f164d 1699 trace_fib6_table_lookup(net, rt, table, fl6);
d3843fe5
WW
1700 return rt;
1701 } else if (rt->rt6i_flags & RTF_CACHE) {
1702 if (ip6_hold_safe(net, &rt, true)) {
1703 dst_use_noref(&rt->dst, jiffies);
1704 rt6_dst_from_metrics_check(rt);
1705 }
66f5d6ce 1706 rcu_read_unlock();
b65f164d 1707 trace_fib6_table_lookup(net, rt, table, fl6);
d52d3997 1708 return rt;
3da59bd9
MKL
1709 } else if (unlikely((fl6->flowi6_flags & FLOWI_FLAG_KNOWN_NH) &&
1710 !(rt->rt6i_flags & RTF_GATEWAY))) {
1711 /* Create a RTF_CACHE clone which will not be
1712 * owned by the fib6 tree. It is for the special case where
1713 * the daddr in the skb during the neighbor look-up is different
1714 * from the fl6->daddr used to look-up route here.
1715 */
1716
1717 struct rt6_info *uncached_rt;
1718
d3843fe5
WW
1719 if (ip6_hold_safe(net, &rt, true)) {
1720 dst_use_noref(&rt->dst, jiffies);
1721 } else {
66f5d6ce 1722 rcu_read_unlock();
d3843fe5
WW
1723 uncached_rt = rt;
1724 goto uncached_rt_out;
1725 }
66f5d6ce 1726 rcu_read_unlock();
d52d3997 1727
3da59bd9
MKL
1728 uncached_rt = ip6_rt_cache_alloc(rt, &fl6->daddr, NULL);
1729 dst_release(&rt->dst);
c71099ac 1730
1cfb71ee
WW
1731 if (uncached_rt) {
1732 /* Uncached_rt's refcnt is taken during ip6_rt_cache_alloc()
1733 * No need for another dst_hold()
1734 */
8d0b94af 1735 rt6_uncached_list_add(uncached_rt);
81eb8447 1736 atomic_inc(&net->ipv6.rt6_stats->fib_rt_uncache);
1cfb71ee 1737 } else {
3da59bd9 1738 uncached_rt = net->ipv6.ip6_null_entry;
1cfb71ee
WW
1739 dst_hold(&uncached_rt->dst);
1740 }
b811580d 1741
d3843fe5 1742uncached_rt_out:
b65f164d 1743 trace_fib6_table_lookup(net, uncached_rt, table, fl6);
3da59bd9 1744 return uncached_rt;
3da59bd9 1745
d52d3997
MKL
1746 } else {
1747 /* Get a percpu copy */
1748
1749 struct rt6_info *pcpu_rt;
1750
d3843fe5 1751 dst_use_noref(&rt->dst, jiffies);
951f788a 1752 local_bh_disable();
d52d3997 1753 pcpu_rt = rt6_get_pcpu_route(rt);
d52d3997 1754
951f788a 1755 if (!pcpu_rt) {
a94b9367
WW
1756 /* atomic_inc_not_zero() is needed when using rcu */
1757 if (atomic_inc_not_zero(&rt->rt6i_ref)) {
951f788a 1758 /* No dst_hold() on rt is needed because grabbing
a94b9367
WW
1759 * rt->rt6i_ref makes sure rt can't be released.
1760 */
a94b9367
WW
1761 pcpu_rt = rt6_make_pcpu_route(rt);
1762 rt6_release(rt);
1763 } else {
1764 /* rt is already removed from tree */
a94b9367
WW
1765 pcpu_rt = net->ipv6.ip6_null_entry;
1766 dst_hold(&pcpu_rt->dst);
1767 }
9c7370a1 1768 }
951f788a
ED
1769 local_bh_enable();
1770 rcu_read_unlock();
b65f164d 1771 trace_fib6_table_lookup(net, pcpu_rt, table, fl6);
d52d3997
MKL
1772 return pcpu_rt;
1773 }
1da177e4 1774}
9ff74384 1775EXPORT_SYMBOL_GPL(ip6_pol_route);
1da177e4 1776
8ed67789 1777static struct rt6_info *ip6_pol_route_input(struct net *net, struct fib6_table *table,
4c9483b2 1778 struct flowi6 *fl6, int flags)
4acad72d 1779{
4c9483b2 1780 return ip6_pol_route(net, table, fl6->flowi6_iif, fl6, flags);
4acad72d
PE
1781}
1782
d409b847
MB
1783struct dst_entry *ip6_route_input_lookup(struct net *net,
1784 struct net_device *dev,
1785 struct flowi6 *fl6, int flags)
72331bc0
SL
1786{
1787 if (rt6_need_strict(&fl6->daddr) && dev->type != ARPHRD_PIMREG)
1788 flags |= RT6_LOOKUP_F_IFACE;
1789
1790 return fib6_rule_lookup(net, fl6, flags, ip6_pol_route_input);
1791}
d409b847 1792EXPORT_SYMBOL_GPL(ip6_route_input_lookup);
72331bc0 1793
23aebdac
JS
1794static void ip6_multipath_l3_keys(const struct sk_buff *skb,
1795 struct flow_keys *keys)
1796{
1797 const struct ipv6hdr *outer_iph = ipv6_hdr(skb);
1798 const struct ipv6hdr *key_iph = outer_iph;
1799 const struct ipv6hdr *inner_iph;
1800 const struct icmp6hdr *icmph;
1801 struct ipv6hdr _inner_iph;
1802
1803 if (likely(outer_iph->nexthdr != IPPROTO_ICMPV6))
1804 goto out;
1805
1806 icmph = icmp6_hdr(skb);
1807 if (icmph->icmp6_type != ICMPV6_DEST_UNREACH &&
1808 icmph->icmp6_type != ICMPV6_PKT_TOOBIG &&
1809 icmph->icmp6_type != ICMPV6_TIME_EXCEED &&
1810 icmph->icmp6_type != ICMPV6_PARAMPROB)
1811 goto out;
1812
1813 inner_iph = skb_header_pointer(skb,
1814 skb_transport_offset(skb) + sizeof(*icmph),
1815 sizeof(_inner_iph), &_inner_iph);
1816 if (!inner_iph)
1817 goto out;
1818
1819 key_iph = inner_iph;
1820out:
1821 memset(keys, 0, sizeof(*keys));
1822 keys->control.addr_type = FLOW_DISSECTOR_KEY_IPV6_ADDRS;
1823 keys->addrs.v6addrs.src = key_iph->saddr;
1824 keys->addrs.v6addrs.dst = key_iph->daddr;
1825 keys->tags.flow_label = ip6_flowinfo(key_iph);
1826 keys->basic.ip_proto = key_iph->nexthdr;
1827}
1828
1829/* if skb is set it will be used and fl6 can be NULL */
1830u32 rt6_multipath_hash(const struct flowi6 *fl6, const struct sk_buff *skb)
1831{
1832 struct flow_keys hash_keys;
1833
1834 if (skb) {
1835 ip6_multipath_l3_keys(skb, &hash_keys);
1836 return flow_hash_from_keys(&hash_keys);
1837 }
1838
1839 return get_hash_from_flowi6(fl6);
1840}
1841
c71099ac
TG
1842void ip6_route_input(struct sk_buff *skb)
1843{
b71d1d42 1844 const struct ipv6hdr *iph = ipv6_hdr(skb);
c346dca1 1845 struct net *net = dev_net(skb->dev);
adaa70bb 1846 int flags = RT6_LOOKUP_F_HAS_SADDR;
904af04d 1847 struct ip_tunnel_info *tun_info;
4c9483b2 1848 struct flowi6 fl6 = {
e0d56fdd 1849 .flowi6_iif = skb->dev->ifindex,
4c9483b2
DM
1850 .daddr = iph->daddr,
1851 .saddr = iph->saddr,
6502ca52 1852 .flowlabel = ip6_flowinfo(iph),
4c9483b2
DM
1853 .flowi6_mark = skb->mark,
1854 .flowi6_proto = iph->nexthdr,
c71099ac 1855 };
adaa70bb 1856
904af04d 1857 tun_info = skb_tunnel_info(skb);
46fa062a 1858 if (tun_info && !(tun_info->mode & IP_TUNNEL_INFO_TX))
904af04d 1859 fl6.flowi6_tun_key.tun_id = tun_info->key.tun_id;
23aebdac
JS
1860 if (unlikely(fl6.flowi6_proto == IPPROTO_ICMPV6))
1861 fl6.mp_hash = rt6_multipath_hash(&fl6, skb);
06e9d040 1862 skb_dst_drop(skb);
72331bc0 1863 skb_dst_set(skb, ip6_route_input_lookup(net, skb->dev, &fl6, flags));
c71099ac
TG
1864}
1865
8ed67789 1866static struct rt6_info *ip6_pol_route_output(struct net *net, struct fib6_table *table,
4c9483b2 1867 struct flowi6 *fl6, int flags)
1da177e4 1868{
4c9483b2 1869 return ip6_pol_route(net, table, fl6->flowi6_oif, fl6, flags);
c71099ac
TG
1870}
1871
6f21c96a
PA
1872struct dst_entry *ip6_route_output_flags(struct net *net, const struct sock *sk,
1873 struct flowi6 *fl6, int flags)
c71099ac 1874{
d46a9d67 1875 bool any_src;
c71099ac 1876
4c1feac5
DA
1877 if (rt6_need_strict(&fl6->daddr)) {
1878 struct dst_entry *dst;
1879
1880 dst = l3mdev_link_scope_lookup(net, fl6);
1881 if (dst)
1882 return dst;
1883 }
ca254490 1884
1fb9489b 1885 fl6->flowi6_iif = LOOPBACK_IFINDEX;
4dc27d1c 1886
d46a9d67 1887 any_src = ipv6_addr_any(&fl6->saddr);
741a11d9 1888 if ((sk && sk->sk_bound_dev_if) || rt6_need_strict(&fl6->daddr) ||
d46a9d67 1889 (fl6->flowi6_oif && any_src))
77d16f45 1890 flags |= RT6_LOOKUP_F_IFACE;
c71099ac 1891
d46a9d67 1892 if (!any_src)
adaa70bb 1893 flags |= RT6_LOOKUP_F_HAS_SADDR;
0c9a2ac1
YH
1894 else if (sk)
1895 flags |= rt6_srcprefs2flags(inet6_sk(sk)->srcprefs);
adaa70bb 1896
4c9483b2 1897 return fib6_rule_lookup(net, fl6, flags, ip6_pol_route_output);
1da177e4 1898}
6f21c96a 1899EXPORT_SYMBOL_GPL(ip6_route_output_flags);
1da177e4 1900
2774c131 1901struct dst_entry *ip6_blackhole_route(struct net *net, struct dst_entry *dst_orig)
14e50e57 1902{
5c1e6aa3 1903 struct rt6_info *rt, *ort = (struct rt6_info *) dst_orig;
1dbe3252 1904 struct net_device *loopback_dev = net->loopback_dev;
14e50e57
DM
1905 struct dst_entry *new = NULL;
1906
1dbe3252 1907 rt = dst_alloc(&ip6_dst_blackhole_ops, loopback_dev, 1,
62cf27e5 1908 DST_OBSOLETE_DEAD, 0);
14e50e57 1909 if (rt) {
0a1f5962 1910 rt6_info_init(rt);
81eb8447 1911 atomic_inc(&net->ipv6.rt6_stats->fib_rt_alloc);
8104891b 1912
0a1f5962 1913 new = &rt->dst;
14e50e57 1914 new->__use = 1;
352e512c 1915 new->input = dst_discard;
ede2059d 1916 new->output = dst_discard_out;
14e50e57 1917
0a1f5962 1918 dst_copy_metrics(new, &ort->dst);
14e50e57 1919
1dbe3252 1920 rt->rt6i_idev = in6_dev_get(loopback_dev);
4e3fd7a0 1921 rt->rt6i_gateway = ort->rt6i_gateway;
0a1f5962 1922 rt->rt6i_flags = ort->rt6i_flags & ~RTF_PCPU;
14e50e57
DM
1923 rt->rt6i_metric = 0;
1924
1925 memcpy(&rt->rt6i_dst, &ort->rt6i_dst, sizeof(struct rt6key));
1926#ifdef CONFIG_IPV6_SUBTREES
1927 memcpy(&rt->rt6i_src, &ort->rt6i_src, sizeof(struct rt6key));
1928#endif
14e50e57
DM
1929 }
1930
69ead7af
DM
1931 dst_release(dst_orig);
1932 return new ? new : ERR_PTR(-ENOMEM);
14e50e57 1933}
14e50e57 1934
1da177e4
LT
1935/*
1936 * Destination cache support functions
1937 */
1938
4b32b5ad
MKL
1939static void rt6_dst_from_metrics_check(struct rt6_info *rt)
1940{
3a2232e9
DM
1941 if (rt->from &&
1942 dst_metrics_ptr(&rt->dst) != dst_metrics_ptr(&rt->from->dst))
1943 dst_init_metrics(&rt->dst, dst_metrics_ptr(&rt->from->dst), true);
4b32b5ad
MKL
1944}
1945
3da59bd9
MKL
1946static struct dst_entry *rt6_check(struct rt6_info *rt, u32 cookie)
1947{
36143645 1948 u32 rt_cookie = 0;
c5cff856
WW
1949
1950 if (!rt6_get_cookie_safe(rt, &rt_cookie) || rt_cookie != cookie)
3da59bd9
MKL
1951 return NULL;
1952
1953 if (rt6_check_expired(rt))
1954 return NULL;
1955
1956 return &rt->dst;
1957}
1958
1959static struct dst_entry *rt6_dst_from_check(struct rt6_info *rt, u32 cookie)
1960{
5973fb1e
MKL
1961 if (!__rt6_check_expired(rt) &&
1962 rt->dst.obsolete == DST_OBSOLETE_FORCE_CHK &&
3a2232e9 1963 rt6_check(rt->from, cookie))
3da59bd9
MKL
1964 return &rt->dst;
1965 else
1966 return NULL;
1967}
1968
1da177e4
LT
1969static struct dst_entry *ip6_dst_check(struct dst_entry *dst, u32 cookie)
1970{
1971 struct rt6_info *rt;
1972
1973 rt = (struct rt6_info *) dst;
1974
6f3118b5
ND
1975 /* All IPV6 dsts are created with ->obsolete set to the value
1976 * DST_OBSOLETE_FORCE_CHK which forces validation calls down
1977 * into this function always.
1978 */
e3bc10bd 1979
4b32b5ad
MKL
1980 rt6_dst_from_metrics_check(rt);
1981
02bcf4e0 1982 if (rt->rt6i_flags & RTF_PCPU ||
3a2232e9 1983 (unlikely(!list_empty(&rt->rt6i_uncached)) && rt->from))
3da59bd9
MKL
1984 return rt6_dst_from_check(rt, cookie);
1985 else
1986 return rt6_check(rt, cookie);
1da177e4
LT
1987}
1988
1989static struct dst_entry *ip6_negative_advice(struct dst_entry *dst)
1990{
1991 struct rt6_info *rt = (struct rt6_info *) dst;
1992
1993 if (rt) {
54c1a859
YH
1994 if (rt->rt6i_flags & RTF_CACHE) {
1995 if (rt6_check_expired(rt)) {
1996 ip6_del_rt(rt);
1997 dst = NULL;
1998 }
1999 } else {
1da177e4 2000 dst_release(dst);
54c1a859
YH
2001 dst = NULL;
2002 }
1da177e4 2003 }
54c1a859 2004 return dst;
1da177e4
LT
2005}
2006
2007static void ip6_link_failure(struct sk_buff *skb)
2008{
2009 struct rt6_info *rt;
2010
3ffe533c 2011 icmpv6_send(skb, ICMPV6_DEST_UNREACH, ICMPV6_ADDR_UNREACH, 0);
1da177e4 2012
adf30907 2013 rt = (struct rt6_info *) skb_dst(skb);
1da177e4 2014 if (rt) {
1eb4f758 2015 if (rt->rt6i_flags & RTF_CACHE) {
ad65a2f0
WW
2016 if (dst_hold_safe(&rt->dst))
2017 ip6_del_rt(rt);
c5cff856
WW
2018 } else {
2019 struct fib6_node *fn;
2020
2021 rcu_read_lock();
2022 fn = rcu_dereference(rt->rt6i_node);
2023 if (fn && (rt->rt6i_flags & RTF_DEFAULT))
2024 fn->fn_sernum = -1;
2025 rcu_read_unlock();
1eb4f758 2026 }
1da177e4
LT
2027 }
2028}
2029
45e4fd26
MKL
2030static void rt6_do_update_pmtu(struct rt6_info *rt, u32 mtu)
2031{
2032 struct net *net = dev_net(rt->dst.dev);
2033
2034 rt->rt6i_flags |= RTF_MODIFIED;
2035 rt->rt6i_pmtu = mtu;
2036 rt6_update_expires(rt, net->ipv6.sysctl.ip6_rt_mtu_expires);
2037}
2038
0d3f6d29
MKL
2039static bool rt6_cache_allowed_for_pmtu(const struct rt6_info *rt)
2040{
2041 return !(rt->rt6i_flags & RTF_CACHE) &&
4e587ea7
WW
2042 (rt->rt6i_flags & RTF_PCPU ||
2043 rcu_access_pointer(rt->rt6i_node));
0d3f6d29
MKL
2044}
2045
45e4fd26
MKL
2046static void __ip6_rt_update_pmtu(struct dst_entry *dst, const struct sock *sk,
2047 const struct ipv6hdr *iph, u32 mtu)
1da177e4 2048{
0dec879f 2049 const struct in6_addr *daddr, *saddr;
67ba4152 2050 struct rt6_info *rt6 = (struct rt6_info *)dst;
1da177e4 2051
45e4fd26
MKL
2052 if (rt6->rt6i_flags & RTF_LOCAL)
2053 return;
81aded24 2054
19bda36c
XL
2055 if (dst_metric_locked(dst, RTAX_MTU))
2056 return;
2057
0dec879f
JA
2058 if (iph) {
2059 daddr = &iph->daddr;
2060 saddr = &iph->saddr;
2061 } else if (sk) {
2062 daddr = &sk->sk_v6_daddr;
2063 saddr = &inet6_sk(sk)->saddr;
2064 } else {
2065 daddr = NULL;
2066 saddr = NULL;
2067 }
2068 dst_confirm_neigh(dst, daddr);
45e4fd26
MKL
2069 mtu = max_t(u32, mtu, IPV6_MIN_MTU);
2070 if (mtu >= dst_mtu(dst))
2071 return;
9d289715 2072
0d3f6d29 2073 if (!rt6_cache_allowed_for_pmtu(rt6)) {
45e4fd26 2074 rt6_do_update_pmtu(rt6, mtu);
2b760fcf
WW
2075 /* update rt6_ex->stamp for cache */
2076 if (rt6->rt6i_flags & RTF_CACHE)
2077 rt6_update_exception_stamp_rt(rt6);
0dec879f 2078 } else if (daddr) {
45e4fd26
MKL
2079 struct rt6_info *nrt6;
2080
45e4fd26
MKL
2081 nrt6 = ip6_rt_cache_alloc(rt6, daddr, saddr);
2082 if (nrt6) {
2083 rt6_do_update_pmtu(nrt6, mtu);
2b760fcf
WW
2084 if (rt6_insert_exception(nrt6, rt6))
2085 dst_release_immediate(&nrt6->dst);
45e4fd26 2086 }
1da177e4
LT
2087 }
2088}
2089
45e4fd26
MKL
2090static void ip6_rt_update_pmtu(struct dst_entry *dst, struct sock *sk,
2091 struct sk_buff *skb, u32 mtu)
2092{
2093 __ip6_rt_update_pmtu(dst, sk, skb ? ipv6_hdr(skb) : NULL, mtu);
2094}
2095
42ae66c8 2096void ip6_update_pmtu(struct sk_buff *skb, struct net *net, __be32 mtu,
e2d118a1 2097 int oif, u32 mark, kuid_t uid)
81aded24
DM
2098{
2099 const struct ipv6hdr *iph = (struct ipv6hdr *) skb->data;
2100 struct dst_entry *dst;
2101 struct flowi6 fl6;
2102
2103 memset(&fl6, 0, sizeof(fl6));
2104 fl6.flowi6_oif = oif;
1b3c61dc 2105 fl6.flowi6_mark = mark ? mark : IP6_REPLY_MARK(net, skb->mark);
81aded24
DM
2106 fl6.daddr = iph->daddr;
2107 fl6.saddr = iph->saddr;
6502ca52 2108 fl6.flowlabel = ip6_flowinfo(iph);
e2d118a1 2109 fl6.flowi6_uid = uid;
81aded24
DM
2110
2111 dst = ip6_route_output(net, NULL, &fl6);
2112 if (!dst->error)
45e4fd26 2113 __ip6_rt_update_pmtu(dst, NULL, iph, ntohl(mtu));
81aded24
DM
2114 dst_release(dst);
2115}
2116EXPORT_SYMBOL_GPL(ip6_update_pmtu);
2117
2118void ip6_sk_update_pmtu(struct sk_buff *skb, struct sock *sk, __be32 mtu)
2119{
33c162a9
MKL
2120 struct dst_entry *dst;
2121
81aded24 2122 ip6_update_pmtu(skb, sock_net(sk), mtu,
e2d118a1 2123 sk->sk_bound_dev_if, sk->sk_mark, sk->sk_uid);
33c162a9
MKL
2124
2125 dst = __sk_dst_get(sk);
2126 if (!dst || !dst->obsolete ||
2127 dst->ops->check(dst, inet6_sk(sk)->dst_cookie))
2128 return;
2129
2130 bh_lock_sock(sk);
2131 if (!sock_owned_by_user(sk) && !ipv6_addr_v4mapped(&sk->sk_v6_daddr))
2132 ip6_datagram_dst_update(sk, false);
2133 bh_unlock_sock(sk);
81aded24
DM
2134}
2135EXPORT_SYMBOL_GPL(ip6_sk_update_pmtu);
2136
b55b76b2
DJ
2137/* Handle redirects */
2138struct ip6rd_flowi {
2139 struct flowi6 fl6;
2140 struct in6_addr gateway;
2141};
2142
2143static struct rt6_info *__ip6_route_redirect(struct net *net,
2144 struct fib6_table *table,
2145 struct flowi6 *fl6,
2146 int flags)
2147{
2148 struct ip6rd_flowi *rdfl = (struct ip6rd_flowi *)fl6;
2b760fcf 2149 struct rt6_info *rt, *rt_cache;
b55b76b2
DJ
2150 struct fib6_node *fn;
2151
2152 /* Get the "current" route for this destination and
67c408cf 2153 * check if the redirect has come from appropriate router.
b55b76b2
DJ
2154 *
2155 * RFC 4861 specifies that redirects should only be
2156 * accepted if they come from the nexthop to the target.
2157 * Due to the way the routes are chosen, this notion
2158 * is a bit fuzzy and one might need to check all possible
2159 * routes.
2160 */
2161
66f5d6ce 2162 rcu_read_lock();
b55b76b2
DJ
2163 fn = fib6_lookup(&table->tb6_root, &fl6->daddr, &fl6->saddr);
2164restart:
66f5d6ce 2165 for_each_fib6_node_rt_rcu(fn) {
8067bb8c
IS
2166 if (rt->rt6i_nh_flags & RTNH_F_DEAD)
2167 continue;
b55b76b2
DJ
2168 if (rt6_check_expired(rt))
2169 continue;
2170 if (rt->dst.error)
2171 break;
2172 if (!(rt->rt6i_flags & RTF_GATEWAY))
2173 continue;
2174 if (fl6->flowi6_oif != rt->dst.dev->ifindex)
2175 continue;
2b760fcf
WW
2176 /* rt_cache's gateway might be different from its 'parent'
2177 * in the case of an ip redirect.
2178 * So we keep searching in the exception table if the gateway
2179 * is different.
2180 */
2181 if (!ipv6_addr_equal(&rdfl->gateway, &rt->rt6i_gateway)) {
2182 rt_cache = rt6_find_cached_rt(rt,
2183 &fl6->daddr,
2184 &fl6->saddr);
2185 if (rt_cache &&
2186 ipv6_addr_equal(&rdfl->gateway,
2187 &rt_cache->rt6i_gateway)) {
2188 rt = rt_cache;
2189 break;
2190 }
b55b76b2 2191 continue;
2b760fcf 2192 }
b55b76b2
DJ
2193 break;
2194 }
2195
2196 if (!rt)
2197 rt = net->ipv6.ip6_null_entry;
2198 else if (rt->dst.error) {
2199 rt = net->ipv6.ip6_null_entry;
b0a1ba59
MKL
2200 goto out;
2201 }
2202
2203 if (rt == net->ipv6.ip6_null_entry) {
a3c00e46
MKL
2204 fn = fib6_backtrack(fn, &fl6->saddr);
2205 if (fn)
2206 goto restart;
b55b76b2 2207 }
a3c00e46 2208
b0a1ba59 2209out:
d3843fe5 2210 ip6_hold_safe(net, &rt, true);
b55b76b2 2211
66f5d6ce 2212 rcu_read_unlock();
b55b76b2 2213
b65f164d 2214 trace_fib6_table_lookup(net, rt, table, fl6);
b55b76b2
DJ
2215 return rt;
2216};
2217
2218static struct dst_entry *ip6_route_redirect(struct net *net,
2219 const struct flowi6 *fl6,
2220 const struct in6_addr *gateway)
2221{
2222 int flags = RT6_LOOKUP_F_HAS_SADDR;
2223 struct ip6rd_flowi rdfl;
2224
2225 rdfl.fl6 = *fl6;
2226 rdfl.gateway = *gateway;
2227
2228 return fib6_rule_lookup(net, &rdfl.fl6,
2229 flags, __ip6_route_redirect);
2230}
2231
e2d118a1
LC
2232void ip6_redirect(struct sk_buff *skb, struct net *net, int oif, u32 mark,
2233 kuid_t uid)
3a5ad2ee
DM
2234{
2235 const struct ipv6hdr *iph = (struct ipv6hdr *) skb->data;
2236 struct dst_entry *dst;
2237 struct flowi6 fl6;
2238
2239 memset(&fl6, 0, sizeof(fl6));
e374c618 2240 fl6.flowi6_iif = LOOPBACK_IFINDEX;
3a5ad2ee
DM
2241 fl6.flowi6_oif = oif;
2242 fl6.flowi6_mark = mark;
3a5ad2ee
DM
2243 fl6.daddr = iph->daddr;
2244 fl6.saddr = iph->saddr;
6502ca52 2245 fl6.flowlabel = ip6_flowinfo(iph);
e2d118a1 2246 fl6.flowi6_uid = uid;
3a5ad2ee 2247
b55b76b2
DJ
2248 dst = ip6_route_redirect(net, &fl6, &ipv6_hdr(skb)->saddr);
2249 rt6_do_redirect(dst, NULL, skb);
3a5ad2ee
DM
2250 dst_release(dst);
2251}
2252EXPORT_SYMBOL_GPL(ip6_redirect);
2253
c92a59ec
DJ
2254void ip6_redirect_no_header(struct sk_buff *skb, struct net *net, int oif,
2255 u32 mark)
2256{
2257 const struct ipv6hdr *iph = ipv6_hdr(skb);
2258 const struct rd_msg *msg = (struct rd_msg *)icmp6_hdr(skb);
2259 struct dst_entry *dst;
2260 struct flowi6 fl6;
2261
2262 memset(&fl6, 0, sizeof(fl6));
e374c618 2263 fl6.flowi6_iif = LOOPBACK_IFINDEX;
c92a59ec
DJ
2264 fl6.flowi6_oif = oif;
2265 fl6.flowi6_mark = mark;
c92a59ec
DJ
2266 fl6.daddr = msg->dest;
2267 fl6.saddr = iph->daddr;
e2d118a1 2268 fl6.flowi6_uid = sock_net_uid(net, NULL);
c92a59ec 2269
b55b76b2
DJ
2270 dst = ip6_route_redirect(net, &fl6, &iph->saddr);
2271 rt6_do_redirect(dst, NULL, skb);
c92a59ec
DJ
2272 dst_release(dst);
2273}
2274
3a5ad2ee
DM
2275void ip6_sk_redirect(struct sk_buff *skb, struct sock *sk)
2276{
e2d118a1
LC
2277 ip6_redirect(skb, sock_net(sk), sk->sk_bound_dev_if, sk->sk_mark,
2278 sk->sk_uid);
3a5ad2ee
DM
2279}
2280EXPORT_SYMBOL_GPL(ip6_sk_redirect);
2281
0dbaee3b 2282static unsigned int ip6_default_advmss(const struct dst_entry *dst)
1da177e4 2283{
0dbaee3b
DM
2284 struct net_device *dev = dst->dev;
2285 unsigned int mtu = dst_mtu(dst);
2286 struct net *net = dev_net(dev);
2287
1da177e4
LT
2288 mtu -= sizeof(struct ipv6hdr) + sizeof(struct tcphdr);
2289
5578689a
DL
2290 if (mtu < net->ipv6.sysctl.ip6_rt_min_advmss)
2291 mtu = net->ipv6.sysctl.ip6_rt_min_advmss;
1da177e4
LT
2292
2293 /*
1ab1457c
YH
2294 * Maximal non-jumbo IPv6 payload is IPV6_MAXPLEN and
2295 * corresponding MSS is IPV6_MAXPLEN - tcp_header_size.
2296 * IPV6_MAXPLEN is also valid and means: "any MSS,
1da177e4
LT
2297 * rely only on pmtu discovery"
2298 */
2299 if (mtu > IPV6_MAXPLEN - sizeof(struct tcphdr))
2300 mtu = IPV6_MAXPLEN;
2301 return mtu;
2302}
2303
ebb762f2 2304static unsigned int ip6_mtu(const struct dst_entry *dst)
d33e4553 2305{
4b32b5ad
MKL
2306 const struct rt6_info *rt = (const struct rt6_info *)dst;
2307 unsigned int mtu = rt->rt6i_pmtu;
d33e4553 2308 struct inet6_dev *idev;
618f9bc7 2309
4b32b5ad
MKL
2310 if (mtu)
2311 goto out;
2312
2313 mtu = dst_metric_raw(dst, RTAX_MTU);
618f9bc7 2314 if (mtu)
30f78d8e 2315 goto out;
618f9bc7
SK
2316
2317 mtu = IPV6_MIN_MTU;
d33e4553
DM
2318
2319 rcu_read_lock();
2320 idev = __in6_dev_get(dst->dev);
2321 if (idev)
2322 mtu = idev->cnf.mtu6;
2323 rcu_read_unlock();
2324
30f78d8e 2325out:
14972cbd
RP
2326 mtu = min_t(unsigned int, mtu, IP6_MAX_MTU);
2327
2328 return mtu - lwtunnel_headroom(dst->lwtstate, mtu);
d33e4553
DM
2329}
2330
3b00944c 2331struct dst_entry *icmp6_dst_alloc(struct net_device *dev,
87a11578 2332 struct flowi6 *fl6)
1da177e4 2333{
87a11578 2334 struct dst_entry *dst;
1da177e4
LT
2335 struct rt6_info *rt;
2336 struct inet6_dev *idev = in6_dev_get(dev);
c346dca1 2337 struct net *net = dev_net(dev);
1da177e4 2338
38308473 2339 if (unlikely(!idev))
122bdf67 2340 return ERR_PTR(-ENODEV);
1da177e4 2341
ad706862 2342 rt = ip6_dst_alloc(net, dev, 0);
38308473 2343 if (unlikely(!rt)) {
1da177e4 2344 in6_dev_put(idev);
87a11578 2345 dst = ERR_PTR(-ENOMEM);
1da177e4
LT
2346 goto out;
2347 }
2348
8e2ec639 2349 rt->dst.flags |= DST_HOST;
588753f1 2350 rt->dst.input = ip6_input;
8e2ec639 2351 rt->dst.output = ip6_output;
550bab42 2352 rt->rt6i_gateway = fl6->daddr;
87a11578 2353 rt->rt6i_dst.addr = fl6->daddr;
8e2ec639
YZ
2354 rt->rt6i_dst.plen = 128;
2355 rt->rt6i_idev = idev;
14edd87d 2356 dst_metric_set(&rt->dst, RTAX_HOPLIMIT, 0);
1da177e4 2357
4c981e28 2358 /* Add this dst into uncached_list so that rt6_disable_ip() can
587fea74
WW
2359 * do proper release of the net_device
2360 */
2361 rt6_uncached_list_add(rt);
81eb8447 2362 atomic_inc(&net->ipv6.rt6_stats->fib_rt_uncache);
1da177e4 2363
87a11578
DM
2364 dst = xfrm_lookup(net, &rt->dst, flowi6_to_flowi(fl6), NULL, 0);
2365
1da177e4 2366out:
87a11578 2367 return dst;
1da177e4
LT
2368}
2369
569d3645 2370static int ip6_dst_gc(struct dst_ops *ops)
1da177e4 2371{
86393e52 2372 struct net *net = container_of(ops, struct net, ipv6.ip6_dst_ops);
7019b78e
DL
2373 int rt_min_interval = net->ipv6.sysctl.ip6_rt_gc_min_interval;
2374 int rt_max_size = net->ipv6.sysctl.ip6_rt_max_size;
2375 int rt_elasticity = net->ipv6.sysctl.ip6_rt_gc_elasticity;
2376 int rt_gc_timeout = net->ipv6.sysctl.ip6_rt_gc_timeout;
2377 unsigned long rt_last_gc = net->ipv6.ip6_rt_last_gc;
fc66f95c 2378 int entries;
7019b78e 2379
fc66f95c 2380 entries = dst_entries_get_fast(ops);
49a18d86 2381 if (time_after(rt_last_gc + rt_min_interval, jiffies) &&
fc66f95c 2382 entries <= rt_max_size)
1da177e4
LT
2383 goto out;
2384
6891a346 2385 net->ipv6.ip6_rt_gc_expire++;
14956643 2386 fib6_run_gc(net->ipv6.ip6_rt_gc_expire, net, true);
fc66f95c
ED
2387 entries = dst_entries_get_slow(ops);
2388 if (entries < ops->gc_thresh)
7019b78e 2389 net->ipv6.ip6_rt_gc_expire = rt_gc_timeout>>1;
1da177e4 2390out:
7019b78e 2391 net->ipv6.ip6_rt_gc_expire -= net->ipv6.ip6_rt_gc_expire>>rt_elasticity;
fc66f95c 2392 return entries > rt_max_size;
1da177e4
LT
2393}
2394
e715b6d3
FW
2395static int ip6_convert_metrics(struct mx6_config *mxc,
2396 const struct fib6_config *cfg)
2397{
6670e152 2398 struct net *net = cfg->fc_nlinfo.nl_net;
c3a8d947 2399 bool ecn_ca = false;
e715b6d3
FW
2400 struct nlattr *nla;
2401 int remaining;
2402 u32 *mp;
2403
63159f29 2404 if (!cfg->fc_mx)
e715b6d3
FW
2405 return 0;
2406
2407 mp = kzalloc(sizeof(u32) * RTAX_MAX, GFP_KERNEL);
2408 if (unlikely(!mp))
2409 return -ENOMEM;
2410
2411 nla_for_each_attr(nla, cfg->fc_mx, cfg->fc_mx_len, remaining) {
2412 int type = nla_type(nla);
1bb14807 2413 u32 val;
e715b6d3 2414
1bb14807
DB
2415 if (!type)
2416 continue;
2417 if (unlikely(type > RTAX_MAX))
2418 goto err;
ea697639 2419
1bb14807
DB
2420 if (type == RTAX_CC_ALGO) {
2421 char tmp[TCP_CA_NAME_MAX];
e715b6d3 2422
1bb14807 2423 nla_strlcpy(tmp, nla, sizeof(tmp));
6670e152 2424 val = tcp_ca_get_key_by_name(net, tmp, &ecn_ca);
1bb14807
DB
2425 if (val == TCP_CA_UNSPEC)
2426 goto err;
2427 } else {
2428 val = nla_get_u32(nla);
e715b6d3 2429 }
626abd59
PA
2430 if (type == RTAX_HOPLIMIT && val > 255)
2431 val = 255;
b8d3e416
DB
2432 if (type == RTAX_FEATURES && (val & ~RTAX_FEATURE_MASK))
2433 goto err;
1bb14807
DB
2434
2435 mp[type - 1] = val;
2436 __set_bit(type - 1, mxc->mx_valid);
e715b6d3
FW
2437 }
2438
c3a8d947
DB
2439 if (ecn_ca) {
2440 __set_bit(RTAX_FEATURES - 1, mxc->mx_valid);
2441 mp[RTAX_FEATURES - 1] |= DST_FEATURE_ECN_CA;
2442 }
e715b6d3 2443
c3a8d947 2444 mxc->mx = mp;
e715b6d3
FW
2445 return 0;
2446 err:
2447 kfree(mp);
2448 return -EINVAL;
2449}
1da177e4 2450
8c14586f
DA
2451static struct rt6_info *ip6_nh_lookup_table(struct net *net,
2452 struct fib6_config *cfg,
2453 const struct in6_addr *gw_addr)
2454{
2455 struct flowi6 fl6 = {
2456 .flowi6_oif = cfg->fc_ifindex,
2457 .daddr = *gw_addr,
2458 .saddr = cfg->fc_prefsrc,
2459 };
2460 struct fib6_table *table;
2461 struct rt6_info *rt;
d5d32e4b 2462 int flags = RT6_LOOKUP_F_IFACE | RT6_LOOKUP_F_IGNORE_LINKSTATE;
8c14586f
DA
2463
2464 table = fib6_get_table(net, cfg->fc_table);
2465 if (!table)
2466 return NULL;
2467
2468 if (!ipv6_addr_any(&cfg->fc_prefsrc))
2469 flags |= RT6_LOOKUP_F_HAS_SADDR;
2470
2471 rt = ip6_pol_route(net, table, cfg->fc_ifindex, &fl6, flags);
2472
2473 /* if table lookup failed, fall back to full lookup */
2474 if (rt == net->ipv6.ip6_null_entry) {
2475 ip6_rt_put(rt);
2476 rt = NULL;
2477 }
2478
2479 return rt;
2480}
2481
333c4301
DA
2482static struct rt6_info *ip6_route_info_create(struct fib6_config *cfg,
2483 struct netlink_ext_ack *extack)
1da177e4 2484{
5578689a 2485 struct net *net = cfg->fc_nlinfo.nl_net;
1da177e4
LT
2486 struct rt6_info *rt = NULL;
2487 struct net_device *dev = NULL;
2488 struct inet6_dev *idev = NULL;
c71099ac 2489 struct fib6_table *table;
1da177e4 2490 int addr_type;
8c5b83f0 2491 int err = -EINVAL;
1da177e4 2492
557c44be 2493 /* RTF_PCPU is an internal flag; can not be set by userspace */
d5d531cb
DA
2494 if (cfg->fc_flags & RTF_PCPU) {
2495 NL_SET_ERR_MSG(extack, "Userspace can not set RTF_PCPU");
557c44be 2496 goto out;
d5d531cb 2497 }
557c44be 2498
2ea2352e
WW
2499 /* RTF_CACHE is an internal flag; can not be set by userspace */
2500 if (cfg->fc_flags & RTF_CACHE) {
2501 NL_SET_ERR_MSG(extack, "Userspace can not set RTF_CACHE");
2502 goto out;
2503 }
2504
d5d531cb
DA
2505 if (cfg->fc_dst_len > 128) {
2506 NL_SET_ERR_MSG(extack, "Invalid prefix length");
2507 goto out;
2508 }
2509 if (cfg->fc_src_len > 128) {
2510 NL_SET_ERR_MSG(extack, "Invalid source address length");
8c5b83f0 2511 goto out;
d5d531cb 2512 }
1da177e4 2513#ifndef CONFIG_IPV6_SUBTREES
d5d531cb
DA
2514 if (cfg->fc_src_len) {
2515 NL_SET_ERR_MSG(extack,
2516 "Specifying source address requires IPV6_SUBTREES to be enabled");
8c5b83f0 2517 goto out;
d5d531cb 2518 }
1da177e4 2519#endif
86872cb5 2520 if (cfg->fc_ifindex) {
1da177e4 2521 err = -ENODEV;
5578689a 2522 dev = dev_get_by_index(net, cfg->fc_ifindex);
1da177e4
LT
2523 if (!dev)
2524 goto out;
2525 idev = in6_dev_get(dev);
2526 if (!idev)
2527 goto out;
2528 }
2529
86872cb5
TG
2530 if (cfg->fc_metric == 0)
2531 cfg->fc_metric = IP6_RT_PRIO_USER;
1da177e4 2532
d71314b4 2533 err = -ENOBUFS;
38308473
DM
2534 if (cfg->fc_nlinfo.nlh &&
2535 !(cfg->fc_nlinfo.nlh->nlmsg_flags & NLM_F_CREATE)) {
d71314b4 2536 table = fib6_get_table(net, cfg->fc_table);
38308473 2537 if (!table) {
f3213831 2538 pr_warn("NLM_F_CREATE should be specified when creating new route\n");
d71314b4
MV
2539 table = fib6_new_table(net, cfg->fc_table);
2540 }
2541 } else {
2542 table = fib6_new_table(net, cfg->fc_table);
2543 }
38308473
DM
2544
2545 if (!table)
c71099ac 2546 goto out;
c71099ac 2547
ad706862
MKL
2548 rt = ip6_dst_alloc(net, NULL,
2549 (cfg->fc_flags & RTF_ADDRCONF) ? 0 : DST_NOCOUNT);
1da177e4 2550
38308473 2551 if (!rt) {
1da177e4
LT
2552 err = -ENOMEM;
2553 goto out;
2554 }
2555
1716a961
G
2556 if (cfg->fc_flags & RTF_EXPIRES)
2557 rt6_set_expires(rt, jiffies +
2558 clock_t_to_jiffies(cfg->fc_expires));
2559 else
2560 rt6_clean_expires(rt);
1da177e4 2561
86872cb5
TG
2562 if (cfg->fc_protocol == RTPROT_UNSPEC)
2563 cfg->fc_protocol = RTPROT_BOOT;
2564 rt->rt6i_protocol = cfg->fc_protocol;
2565
2566 addr_type = ipv6_addr_type(&cfg->fc_dst);
1da177e4
LT
2567
2568 if (addr_type & IPV6_ADDR_MULTICAST)
d8d1f30b 2569 rt->dst.input = ip6_mc_input;
ab79ad14
2570 else if (cfg->fc_flags & RTF_LOCAL)
2571 rt->dst.input = ip6_input;
1da177e4 2572 else
d8d1f30b 2573 rt->dst.input = ip6_forward;
1da177e4 2574
d8d1f30b 2575 rt->dst.output = ip6_output;
1da177e4 2576
19e42e45
RP
2577 if (cfg->fc_encap) {
2578 struct lwtunnel_state *lwtstate;
2579
30357d7d 2580 err = lwtunnel_build_state(cfg->fc_encap_type,
127eb7cd 2581 cfg->fc_encap, AF_INET6, cfg,
9ae28727 2582 &lwtstate, extack);
19e42e45
RP
2583 if (err)
2584 goto out;
61adedf3
JB
2585 rt->dst.lwtstate = lwtstate_get(lwtstate);
2586 if (lwtunnel_output_redirect(rt->dst.lwtstate)) {
2587 rt->dst.lwtstate->orig_output = rt->dst.output;
2588 rt->dst.output = lwtunnel_output;
25368623 2589 }
61adedf3
JB
2590 if (lwtunnel_input_redirect(rt->dst.lwtstate)) {
2591 rt->dst.lwtstate->orig_input = rt->dst.input;
2592 rt->dst.input = lwtunnel_input;
25368623 2593 }
19e42e45
RP
2594 }
2595
86872cb5
TG
2596 ipv6_addr_prefix(&rt->rt6i_dst.addr, &cfg->fc_dst, cfg->fc_dst_len);
2597 rt->rt6i_dst.plen = cfg->fc_dst_len;
afc4eef8 2598 if (rt->rt6i_dst.plen == 128)
e5fd387a 2599 rt->dst.flags |= DST_HOST;
e5fd387a 2600
1da177e4 2601#ifdef CONFIG_IPV6_SUBTREES
86872cb5
TG
2602 ipv6_addr_prefix(&rt->rt6i_src.addr, &cfg->fc_src, cfg->fc_src_len);
2603 rt->rt6i_src.plen = cfg->fc_src_len;
1da177e4
LT
2604#endif
2605
86872cb5 2606 rt->rt6i_metric = cfg->fc_metric;
1da177e4
LT
2607
2608 /* We cannot add true routes via loopback here,
2609 they would result in kernel looping; promote them to reject routes
2610 */
86872cb5 2611 if ((cfg->fc_flags & RTF_REJECT) ||
38308473
DM
2612 (dev && (dev->flags & IFF_LOOPBACK) &&
2613 !(addr_type & IPV6_ADDR_LOOPBACK) &&
2614 !(cfg->fc_flags & RTF_LOCAL))) {
1da177e4 2615 /* hold loopback dev/idev if we haven't done so. */
5578689a 2616 if (dev != net->loopback_dev) {
1da177e4
LT
2617 if (dev) {
2618 dev_put(dev);
2619 in6_dev_put(idev);
2620 }
5578689a 2621 dev = net->loopback_dev;
1da177e4
LT
2622 dev_hold(dev);
2623 idev = in6_dev_get(dev);
2624 if (!idev) {
2625 err = -ENODEV;
2626 goto out;
2627 }
2628 }
1da177e4 2629 rt->rt6i_flags = RTF_REJECT|RTF_NONEXTHOP;
ef2c7d7b
ND
2630 switch (cfg->fc_type) {
2631 case RTN_BLACKHOLE:
2632 rt->dst.error = -EINVAL;
ede2059d 2633 rt->dst.output = dst_discard_out;
7150aede 2634 rt->dst.input = dst_discard;
ef2c7d7b
ND
2635 break;
2636 case RTN_PROHIBIT:
2637 rt->dst.error = -EACCES;
7150aede
K
2638 rt->dst.output = ip6_pkt_prohibit_out;
2639 rt->dst.input = ip6_pkt_prohibit;
ef2c7d7b 2640 break;
b4949ab2 2641 case RTN_THROW:
0315e382 2642 case RTN_UNREACHABLE:
ef2c7d7b 2643 default:
7150aede 2644 rt->dst.error = (cfg->fc_type == RTN_THROW) ? -EAGAIN
0315e382
NF
2645 : (cfg->fc_type == RTN_UNREACHABLE)
2646 ? -EHOSTUNREACH : -ENETUNREACH;
7150aede
K
2647 rt->dst.output = ip6_pkt_discard_out;
2648 rt->dst.input = ip6_pkt_discard;
ef2c7d7b
ND
2649 break;
2650 }
1da177e4
LT
2651 goto install_route;
2652 }
2653
86872cb5 2654 if (cfg->fc_flags & RTF_GATEWAY) {
b71d1d42 2655 const struct in6_addr *gw_addr;
1da177e4
LT
2656 int gwa_type;
2657
86872cb5 2658 gw_addr = &cfg->fc_gateway;
330567b7 2659 gwa_type = ipv6_addr_type(gw_addr);
48ed7b26
FW
2660
2661 /* if gw_addr is local we will fail to detect this in case
2662 * address is still TENTATIVE (DAD in progress). rt6_lookup()
2663 * will return already-added prefix route via interface that
2664 * prefix route was assigned to, which might be non-loopback.
2665 */
2666 err = -EINVAL;
330567b7
FW
2667 if (ipv6_chk_addr_and_flags(net, gw_addr,
2668 gwa_type & IPV6_ADDR_LINKLOCAL ?
d5d531cb
DA
2669 dev : NULL, 0, 0)) {
2670 NL_SET_ERR_MSG(extack, "Invalid gateway address");
48ed7b26 2671 goto out;
d5d531cb 2672 }
4e3fd7a0 2673 rt->rt6i_gateway = *gw_addr;
1da177e4
LT
2674
2675 if (gwa_type != (IPV6_ADDR_LINKLOCAL|IPV6_ADDR_UNICAST)) {
8c14586f 2676 struct rt6_info *grt = NULL;
1da177e4
LT
2677
2678 /* IPv6 strictly inhibits using not link-local
2679 addresses as nexthop address.
2680 Otherwise, router will not able to send redirects.
2681 It is very good, but in some (rare!) circumstances
2682 (SIT, PtP, NBMA NOARP links) it is handy to allow
2683 some exceptions. --ANK
96d5822c
EN
2684 We allow IPv4-mapped nexthops to support RFC4798-type
2685 addressing
1da177e4 2686 */
96d5822c 2687 if (!(gwa_type & (IPV6_ADDR_UNICAST |
d5d531cb
DA
2688 IPV6_ADDR_MAPPED))) {
2689 NL_SET_ERR_MSG(extack,
2690 "Invalid gateway address");
1da177e4 2691 goto out;
d5d531cb 2692 }
1da177e4 2693
a435a07f 2694 if (cfg->fc_table) {
8c14586f
DA
2695 grt = ip6_nh_lookup_table(net, cfg, gw_addr);
2696
a435a07f
VB
2697 if (grt) {
2698 if (grt->rt6i_flags & RTF_GATEWAY ||
2699 (dev && dev != grt->dst.dev)) {
2700 ip6_rt_put(grt);
2701 grt = NULL;
2702 }
2703 }
2704 }
2705
8c14586f
DA
2706 if (!grt)
2707 grt = rt6_lookup(net, gw_addr, NULL,
2708 cfg->fc_ifindex, 1);
1da177e4
LT
2709
2710 err = -EHOSTUNREACH;
38308473 2711 if (!grt)
1da177e4
LT
2712 goto out;
2713 if (dev) {
d1918542 2714 if (dev != grt->dst.dev) {
94e187c0 2715 ip6_rt_put(grt);
1da177e4
LT
2716 goto out;
2717 }
2718 } else {
d1918542 2719 dev = grt->dst.dev;
1da177e4
LT
2720 idev = grt->rt6i_idev;
2721 dev_hold(dev);
2722 in6_dev_hold(grt->rt6i_idev);
2723 }
38308473 2724 if (!(grt->rt6i_flags & RTF_GATEWAY))
1da177e4 2725 err = 0;
94e187c0 2726 ip6_rt_put(grt);
1da177e4
LT
2727
2728 if (err)
2729 goto out;
2730 }
2731 err = -EINVAL;
d5d531cb
DA
2732 if (!dev) {
2733 NL_SET_ERR_MSG(extack, "Egress device not specified");
2734 goto out;
2735 } else if (dev->flags & IFF_LOOPBACK) {
2736 NL_SET_ERR_MSG(extack,
2737 "Egress device can not be loopback device for this route");
1da177e4 2738 goto out;
d5d531cb 2739 }
1da177e4
LT
2740 }
2741
2742 err = -ENODEV;
38308473 2743 if (!dev)
1da177e4
LT
2744 goto out;
2745
c3968a85
DW
2746 if (!ipv6_addr_any(&cfg->fc_prefsrc)) {
2747 if (!ipv6_chk_addr(net, &cfg->fc_prefsrc, dev, 0)) {
d5d531cb 2748 NL_SET_ERR_MSG(extack, "Invalid source address");
c3968a85
DW
2749 err = -EINVAL;
2750 goto out;
2751 }
4e3fd7a0 2752 rt->rt6i_prefsrc.addr = cfg->fc_prefsrc;
c3968a85
DW
2753 rt->rt6i_prefsrc.plen = 128;
2754 } else
2755 rt->rt6i_prefsrc.plen = 0;
2756
86872cb5 2757 rt->rt6i_flags = cfg->fc_flags;
1da177e4
LT
2758
2759install_route:
5609b80a
IS
2760 if (!(rt->rt6i_flags & (RTF_LOCAL | RTF_ANYCAST)) &&
2761 !netif_carrier_ok(dev))
2762 rt->rt6i_nh_flags |= RTNH_F_LINKDOWN;
d8d1f30b 2763 rt->dst.dev = dev;
1da177e4 2764 rt->rt6i_idev = idev;
c71099ac 2765 rt->rt6i_table = table;
63152fc0 2766
c346dca1 2767 cfg->fc_nlinfo.nl_net = dev_net(dev);
63152fc0 2768
8c5b83f0 2769 return rt;
6b9ea5a6
RP
2770out:
2771 if (dev)
2772 dev_put(dev);
2773 if (idev)
2774 in6_dev_put(idev);
587fea74
WW
2775 if (rt)
2776 dst_release_immediate(&rt->dst);
6b9ea5a6 2777
8c5b83f0 2778 return ERR_PTR(err);
6b9ea5a6
RP
2779}
2780
333c4301
DA
2781int ip6_route_add(struct fib6_config *cfg,
2782 struct netlink_ext_ack *extack)
6b9ea5a6
RP
2783{
2784 struct mx6_config mxc = { .mx = NULL, };
8c5b83f0 2785 struct rt6_info *rt;
6b9ea5a6
RP
2786 int err;
2787
333c4301 2788 rt = ip6_route_info_create(cfg, extack);
8c5b83f0
RP
2789 if (IS_ERR(rt)) {
2790 err = PTR_ERR(rt);
2791 rt = NULL;
6b9ea5a6 2792 goto out;
8c5b83f0 2793 }
6b9ea5a6 2794
e715b6d3
FW
2795 err = ip6_convert_metrics(&mxc, cfg);
2796 if (err)
2797 goto out;
1da177e4 2798
333c4301 2799 err = __ip6_ins_rt(rt, &cfg->fc_nlinfo, &mxc, extack);
e715b6d3
FW
2800
2801 kfree(mxc.mx);
6b9ea5a6 2802
e715b6d3 2803 return err;
1da177e4 2804out:
587fea74
WW
2805 if (rt)
2806 dst_release_immediate(&rt->dst);
6b9ea5a6 2807
1da177e4
LT
2808 return err;
2809}
2810
86872cb5 2811static int __ip6_del_rt(struct rt6_info *rt, struct nl_info *info)
1da177e4
LT
2812{
2813 int err;
c71099ac 2814 struct fib6_table *table;
d1918542 2815 struct net *net = dev_net(rt->dst.dev);
1da177e4 2816
a4c2fd7f 2817 if (rt == net->ipv6.ip6_null_entry) {
6825a26c
G
2818 err = -ENOENT;
2819 goto out;
2820 }
6c813a72 2821
c71099ac 2822 table = rt->rt6i_table;
66f5d6ce 2823 spin_lock_bh(&table->tb6_lock);
86872cb5 2824 err = fib6_del(rt, info);
66f5d6ce 2825 spin_unlock_bh(&table->tb6_lock);
1da177e4 2826
6825a26c 2827out:
94e187c0 2828 ip6_rt_put(rt);
1da177e4
LT
2829 return err;
2830}
2831
e0a1ad73
TG
2832int ip6_del_rt(struct rt6_info *rt)
2833{
4d1169c1 2834 struct nl_info info = {
d1918542 2835 .nl_net = dev_net(rt->dst.dev),
4d1169c1 2836 };
528c4ceb 2837 return __ip6_del_rt(rt, &info);
e0a1ad73
TG
2838}
2839
0ae81335
DA
2840static int __ip6_del_rt_siblings(struct rt6_info *rt, struct fib6_config *cfg)
2841{
2842 struct nl_info *info = &cfg->fc_nlinfo;
e3330039 2843 struct net *net = info->nl_net;
16a16cd3 2844 struct sk_buff *skb = NULL;
0ae81335 2845 struct fib6_table *table;
e3330039 2846 int err = -ENOENT;
0ae81335 2847
e3330039
WC
2848 if (rt == net->ipv6.ip6_null_entry)
2849 goto out_put;
0ae81335 2850 table = rt->rt6i_table;
66f5d6ce 2851 spin_lock_bh(&table->tb6_lock);
0ae81335
DA
2852
2853 if (rt->rt6i_nsiblings && cfg->fc_delete_all_nh) {
2854 struct rt6_info *sibling, *next_sibling;
2855
16a16cd3
DA
2856 /* prefer to send a single notification with all hops */
2857 skb = nlmsg_new(rt6_nlmsg_size(rt), gfp_any());
2858 if (skb) {
2859 u32 seq = info->nlh ? info->nlh->nlmsg_seq : 0;
2860
e3330039 2861 if (rt6_fill_node(net, skb, rt,
16a16cd3
DA
2862 NULL, NULL, 0, RTM_DELROUTE,
2863 info->portid, seq, 0) < 0) {
2864 kfree_skb(skb);
2865 skb = NULL;
2866 } else
2867 info->skip_notify = 1;
2868 }
2869
0ae81335
DA
2870 list_for_each_entry_safe(sibling, next_sibling,
2871 &rt->rt6i_siblings,
2872 rt6i_siblings) {
2873 err = fib6_del(sibling, info);
2874 if (err)
e3330039 2875 goto out_unlock;
0ae81335
DA
2876 }
2877 }
2878
2879 err = fib6_del(rt, info);
e3330039 2880out_unlock:
66f5d6ce 2881 spin_unlock_bh(&table->tb6_lock);
e3330039 2882out_put:
0ae81335 2883 ip6_rt_put(rt);
16a16cd3
DA
2884
2885 if (skb) {
e3330039 2886 rtnl_notify(skb, net, info->portid, RTNLGRP_IPV6_ROUTE,
16a16cd3
DA
2887 info->nlh, gfp_any());
2888 }
0ae81335
DA
2889 return err;
2890}
2891
333c4301
DA
2892static int ip6_route_del(struct fib6_config *cfg,
2893 struct netlink_ext_ack *extack)
1da177e4 2894{
2b760fcf 2895 struct rt6_info *rt, *rt_cache;
c71099ac 2896 struct fib6_table *table;
1da177e4 2897 struct fib6_node *fn;
1da177e4
LT
2898 int err = -ESRCH;
2899
5578689a 2900 table = fib6_get_table(cfg->fc_nlinfo.nl_net, cfg->fc_table);
d5d531cb
DA
2901 if (!table) {
2902 NL_SET_ERR_MSG(extack, "FIB table does not exist");
c71099ac 2903 return err;
d5d531cb 2904 }
c71099ac 2905
66f5d6ce 2906 rcu_read_lock();
1da177e4 2907
c71099ac 2908 fn = fib6_locate(&table->tb6_root,
86872cb5 2909 &cfg->fc_dst, cfg->fc_dst_len,
38fbeeee 2910 &cfg->fc_src, cfg->fc_src_len,
2b760fcf 2911 !(cfg->fc_flags & RTF_CACHE));
1ab1457c 2912
1da177e4 2913 if (fn) {
66f5d6ce 2914 for_each_fib6_node_rt_rcu(fn) {
2b760fcf
WW
2915 if (cfg->fc_flags & RTF_CACHE) {
2916 rt_cache = rt6_find_cached_rt(rt, &cfg->fc_dst,
2917 &cfg->fc_src);
2918 if (!rt_cache)
2919 continue;
2920 rt = rt_cache;
2921 }
86872cb5 2922 if (cfg->fc_ifindex &&
d1918542
DM
2923 (!rt->dst.dev ||
2924 rt->dst.dev->ifindex != cfg->fc_ifindex))
1da177e4 2925 continue;
86872cb5
TG
2926 if (cfg->fc_flags & RTF_GATEWAY &&
2927 !ipv6_addr_equal(&cfg->fc_gateway, &rt->rt6i_gateway))
1da177e4 2928 continue;
86872cb5 2929 if (cfg->fc_metric && cfg->fc_metric != rt->rt6i_metric)
1da177e4 2930 continue;
c2ed1880
M
2931 if (cfg->fc_protocol && cfg->fc_protocol != rt->rt6i_protocol)
2932 continue;
d3843fe5
WW
2933 if (!dst_hold_safe(&rt->dst))
2934 break;
66f5d6ce 2935 rcu_read_unlock();
1da177e4 2936
0ae81335
DA
2937 /* if gateway was specified only delete the one hop */
2938 if (cfg->fc_flags & RTF_GATEWAY)
2939 return __ip6_del_rt(rt, &cfg->fc_nlinfo);
2940
2941 return __ip6_del_rt_siblings(rt, cfg);
1da177e4
LT
2942 }
2943 }
66f5d6ce 2944 rcu_read_unlock();
1da177e4
LT
2945
2946 return err;
2947}
2948
6700c270 2949static void rt6_do_redirect(struct dst_entry *dst, struct sock *sk, struct sk_buff *skb)
a6279458 2950{
a6279458 2951 struct netevent_redirect netevent;
e8599ff4 2952 struct rt6_info *rt, *nrt = NULL;
e8599ff4
DM
2953 struct ndisc_options ndopts;
2954 struct inet6_dev *in6_dev;
2955 struct neighbour *neigh;
71bcdba0 2956 struct rd_msg *msg;
6e157b6a
DM
2957 int optlen, on_link;
2958 u8 *lladdr;
e8599ff4 2959
29a3cad5 2960 optlen = skb_tail_pointer(skb) - skb_transport_header(skb);
71bcdba0 2961 optlen -= sizeof(*msg);
e8599ff4
DM
2962
2963 if (optlen < 0) {
6e157b6a 2964 net_dbg_ratelimited("rt6_do_redirect: packet too short\n");
e8599ff4
DM
2965 return;
2966 }
2967
71bcdba0 2968 msg = (struct rd_msg *)icmp6_hdr(skb);
e8599ff4 2969
71bcdba0 2970 if (ipv6_addr_is_multicast(&msg->dest)) {
6e157b6a 2971 net_dbg_ratelimited("rt6_do_redirect: destination address is multicast\n");
e8599ff4
DM
2972 return;
2973 }
2974
6e157b6a 2975 on_link = 0;
71bcdba0 2976 if (ipv6_addr_equal(&msg->dest, &msg->target)) {
e8599ff4 2977 on_link = 1;
71bcdba0 2978 } else if (ipv6_addr_type(&msg->target) !=
e8599ff4 2979 (IPV6_ADDR_UNICAST|IPV6_ADDR_LINKLOCAL)) {
6e157b6a 2980 net_dbg_ratelimited("rt6_do_redirect: target address is not link-local unicast\n");
e8599ff4
DM
2981 return;
2982 }
2983
2984 in6_dev = __in6_dev_get(skb->dev);
2985 if (!in6_dev)
2986 return;
2987 if (in6_dev->cnf.forwarding || !in6_dev->cnf.accept_redirects)
2988 return;
2989
2990 /* RFC2461 8.1:
2991 * The IP source address of the Redirect MUST be the same as the current
2992 * first-hop router for the specified ICMP Destination Address.
2993 */
2994
f997c55c 2995 if (!ndisc_parse_options(skb->dev, msg->opt, optlen, &ndopts)) {
e8599ff4
DM
2996 net_dbg_ratelimited("rt6_redirect: invalid ND options\n");
2997 return;
2998 }
6e157b6a
DM
2999
3000 lladdr = NULL;
e8599ff4
DM
3001 if (ndopts.nd_opts_tgt_lladdr) {
3002 lladdr = ndisc_opt_addr_data(ndopts.nd_opts_tgt_lladdr,
3003 skb->dev);
3004 if (!lladdr) {
3005 net_dbg_ratelimited("rt6_redirect: invalid link-layer address length\n");
3006 return;
3007 }
3008 }
3009
6e157b6a 3010 rt = (struct rt6_info *) dst;
ec13ad1d 3011 if (rt->rt6i_flags & RTF_REJECT) {
6e157b6a 3012 net_dbg_ratelimited("rt6_redirect: source isn't a valid nexthop for redirect target\n");
e8599ff4 3013 return;
6e157b6a 3014 }
e8599ff4 3015
6e157b6a
DM
3016 /* Redirect received -> path was valid.
3017 * Look, redirects are sent only in response to data packets,
3018 * so that this nexthop apparently is reachable. --ANK
3019 */
0dec879f 3020 dst_confirm_neigh(&rt->dst, &ipv6_hdr(skb)->saddr);
a6279458 3021
71bcdba0 3022 neigh = __neigh_lookup(&nd_tbl, &msg->target, skb->dev, 1);
6e157b6a
DM
3023 if (!neigh)
3024 return;
a6279458 3025
1da177e4
LT
3026 /*
3027 * We have finally decided to accept it.
3028 */
3029
f997c55c 3030 ndisc_update(skb->dev, neigh, lladdr, NUD_STALE,
1da177e4
LT
3031 NEIGH_UPDATE_F_WEAK_OVERRIDE|
3032 NEIGH_UPDATE_F_OVERRIDE|
3033 (on_link ? 0 : (NEIGH_UPDATE_F_OVERRIDE_ISROUTER|
f997c55c
AA
3034 NEIGH_UPDATE_F_ISROUTER)),
3035 NDISC_REDIRECT, &ndopts);
1da177e4 3036
83a09abd 3037 nrt = ip6_rt_cache_alloc(rt, &msg->dest, NULL);
38308473 3038 if (!nrt)
1da177e4
LT
3039 goto out;
3040
3041 nrt->rt6i_flags = RTF_GATEWAY|RTF_UP|RTF_DYNAMIC|RTF_CACHE;
3042 if (on_link)
3043 nrt->rt6i_flags &= ~RTF_GATEWAY;
3044
b91d5329 3045 nrt->rt6i_protocol = RTPROT_REDIRECT;
4e3fd7a0 3046 nrt->rt6i_gateway = *(struct in6_addr *)neigh->primary_key;
1da177e4 3047
2b760fcf
WW
3048 /* No need to remove rt from the exception table if rt is
3049 * a cached route because rt6_insert_exception() will
3050 * takes care of it
3051 */
3052 if (rt6_insert_exception(nrt, rt)) {
3053 dst_release_immediate(&nrt->dst);
3054 goto out;
3055 }
1da177e4 3056
d8d1f30b
CG
3057 netevent.old = &rt->dst;
3058 netevent.new = &nrt->dst;
71bcdba0 3059 netevent.daddr = &msg->dest;
60592833 3060 netevent.neigh = neigh;
8d71740c
TT
3061 call_netevent_notifiers(NETEVENT_REDIRECT, &netevent);
3062
1da177e4 3063out:
e8599ff4 3064 neigh_release(neigh);
6e157b6a
DM
3065}
3066
1da177e4
LT
3067/*
3068 * Misc support functions
3069 */
3070
4b32b5ad
MKL
3071static void rt6_set_from(struct rt6_info *rt, struct rt6_info *from)
3072{
3a2232e9 3073 BUG_ON(from->from);
4b32b5ad
MKL
3074
3075 rt->rt6i_flags &= ~RTF_EXPIRES;
3076 dst_hold(&from->dst);
3a2232e9 3077 rt->from = from;
4b32b5ad
MKL
3078 dst_init_metrics(&rt->dst, dst_metrics_ptr(&from->dst), true);
3079}
3080
83a09abd
MKL
3081static void ip6_rt_copy_init(struct rt6_info *rt, struct rt6_info *ort)
3082{
3083 rt->dst.input = ort->dst.input;
3084 rt->dst.output = ort->dst.output;
3085 rt->rt6i_dst = ort->rt6i_dst;
3086 rt->dst.error = ort->dst.error;
3087 rt->rt6i_idev = ort->rt6i_idev;
3088 if (rt->rt6i_idev)
3089 in6_dev_hold(rt->rt6i_idev);
3090 rt->dst.lastuse = jiffies;
3091 rt->rt6i_gateway = ort->rt6i_gateway;
3092 rt->rt6i_flags = ort->rt6i_flags;
3093 rt6_set_from(rt, ort);
3094 rt->rt6i_metric = ort->rt6i_metric;
1da177e4 3095#ifdef CONFIG_IPV6_SUBTREES
83a09abd 3096 rt->rt6i_src = ort->rt6i_src;
1da177e4 3097#endif
83a09abd
MKL
3098 rt->rt6i_prefsrc = ort->rt6i_prefsrc;
3099 rt->rt6i_table = ort->rt6i_table;
61adedf3 3100 rt->dst.lwtstate = lwtstate_get(ort->dst.lwtstate);
1da177e4
LT
3101}
3102
70ceb4f5 3103#ifdef CONFIG_IPV6_ROUTE_INFO
efa2cea0 3104static struct rt6_info *rt6_get_route_info(struct net *net,
b71d1d42 3105 const struct in6_addr *prefix, int prefixlen,
830218c1
DA
3106 const struct in6_addr *gwaddr,
3107 struct net_device *dev)
70ceb4f5 3108{
830218c1
DA
3109 u32 tb_id = l3mdev_fib_table(dev) ? : RT6_TABLE_INFO;
3110 int ifindex = dev->ifindex;
70ceb4f5
YH
3111 struct fib6_node *fn;
3112 struct rt6_info *rt = NULL;
c71099ac
TG
3113 struct fib6_table *table;
3114
830218c1 3115 table = fib6_get_table(net, tb_id);
38308473 3116 if (!table)
c71099ac 3117 return NULL;
70ceb4f5 3118
66f5d6ce 3119 rcu_read_lock();
38fbeeee 3120 fn = fib6_locate(&table->tb6_root, prefix, prefixlen, NULL, 0, true);
70ceb4f5
YH
3121 if (!fn)
3122 goto out;
3123
66f5d6ce 3124 for_each_fib6_node_rt_rcu(fn) {
d1918542 3125 if (rt->dst.dev->ifindex != ifindex)
70ceb4f5
YH
3126 continue;
3127 if ((rt->rt6i_flags & (RTF_ROUTEINFO|RTF_GATEWAY)) != (RTF_ROUTEINFO|RTF_GATEWAY))
3128 continue;
3129 if (!ipv6_addr_equal(&rt->rt6i_gateway, gwaddr))
3130 continue;
d3843fe5 3131 ip6_hold_safe(NULL, &rt, false);
70ceb4f5
YH
3132 break;
3133 }
3134out:
66f5d6ce 3135 rcu_read_unlock();
70ceb4f5
YH
3136 return rt;
3137}
3138
efa2cea0 3139static struct rt6_info *rt6_add_route_info(struct net *net,
b71d1d42 3140 const struct in6_addr *prefix, int prefixlen,
830218c1
DA
3141 const struct in6_addr *gwaddr,
3142 struct net_device *dev,
95c96174 3143 unsigned int pref)
70ceb4f5 3144{
86872cb5 3145 struct fib6_config cfg = {
238fc7ea 3146 .fc_metric = IP6_RT_PRIO_USER,
830218c1 3147 .fc_ifindex = dev->ifindex,
86872cb5
TG
3148 .fc_dst_len = prefixlen,
3149 .fc_flags = RTF_GATEWAY | RTF_ADDRCONF | RTF_ROUTEINFO |
3150 RTF_UP | RTF_PREF(pref),
b91d5329 3151 .fc_protocol = RTPROT_RA,
15e47304 3152 .fc_nlinfo.portid = 0,
efa2cea0
DL
3153 .fc_nlinfo.nlh = NULL,
3154 .fc_nlinfo.nl_net = net,
86872cb5
TG
3155 };
3156
830218c1 3157 cfg.fc_table = l3mdev_fib_table(dev) ? : RT6_TABLE_INFO,
4e3fd7a0
AD
3158 cfg.fc_dst = *prefix;
3159 cfg.fc_gateway = *gwaddr;
70ceb4f5 3160
e317da96
YH
3161 /* We should treat it as a default route if prefix length is 0. */
3162 if (!prefixlen)
86872cb5 3163 cfg.fc_flags |= RTF_DEFAULT;
70ceb4f5 3164
333c4301 3165 ip6_route_add(&cfg, NULL);
70ceb4f5 3166
830218c1 3167 return rt6_get_route_info(net, prefix, prefixlen, gwaddr, dev);
70ceb4f5
YH
3168}
3169#endif
3170
b71d1d42 3171struct rt6_info *rt6_get_dflt_router(const struct in6_addr *addr, struct net_device *dev)
1ab1457c 3172{
830218c1 3173 u32 tb_id = l3mdev_fib_table(dev) ? : RT6_TABLE_DFLT;
1da177e4 3174 struct rt6_info *rt;
c71099ac 3175 struct fib6_table *table;
1da177e4 3176
830218c1 3177 table = fib6_get_table(dev_net(dev), tb_id);
38308473 3178 if (!table)
c71099ac 3179 return NULL;
1da177e4 3180
66f5d6ce
WW
3181 rcu_read_lock();
3182 for_each_fib6_node_rt_rcu(&table->tb6_root) {
d1918542 3183 if (dev == rt->dst.dev &&
045927ff 3184 ((rt->rt6i_flags & (RTF_ADDRCONF | RTF_DEFAULT)) == (RTF_ADDRCONF | RTF_DEFAULT)) &&
1da177e4
LT
3185 ipv6_addr_equal(&rt->rt6i_gateway, addr))
3186 break;
3187 }
3188 if (rt)
d3843fe5 3189 ip6_hold_safe(NULL, &rt, false);
66f5d6ce 3190 rcu_read_unlock();
1da177e4
LT
3191 return rt;
3192}
3193
b71d1d42 3194struct rt6_info *rt6_add_dflt_router(const struct in6_addr *gwaddr,
ebacaaa0
YH
3195 struct net_device *dev,
3196 unsigned int pref)
1da177e4 3197{
86872cb5 3198 struct fib6_config cfg = {
ca254490 3199 .fc_table = l3mdev_fib_table(dev) ? : RT6_TABLE_DFLT,
238fc7ea 3200 .fc_metric = IP6_RT_PRIO_USER,
86872cb5
TG
3201 .fc_ifindex = dev->ifindex,
3202 .fc_flags = RTF_GATEWAY | RTF_ADDRCONF | RTF_DEFAULT |
3203 RTF_UP | RTF_EXPIRES | RTF_PREF(pref),
b91d5329 3204 .fc_protocol = RTPROT_RA,
15e47304 3205 .fc_nlinfo.portid = 0,
5578689a 3206 .fc_nlinfo.nlh = NULL,
c346dca1 3207 .fc_nlinfo.nl_net = dev_net(dev),
86872cb5 3208 };
1da177e4 3209
4e3fd7a0 3210 cfg.fc_gateway = *gwaddr;
1da177e4 3211
333c4301 3212 if (!ip6_route_add(&cfg, NULL)) {
830218c1
DA
3213 struct fib6_table *table;
3214
3215 table = fib6_get_table(dev_net(dev), cfg.fc_table);
3216 if (table)
3217 table->flags |= RT6_TABLE_HAS_DFLT_ROUTER;
3218 }
1da177e4 3219
1da177e4
LT
3220 return rt6_get_dflt_router(gwaddr, dev);
3221}
3222
830218c1 3223static void __rt6_purge_dflt_routers(struct fib6_table *table)
1da177e4
LT
3224{
3225 struct rt6_info *rt;
3226
3227restart:
66f5d6ce
WW
3228 rcu_read_lock();
3229 for_each_fib6_node_rt_rcu(&table->tb6_root) {
3e8b0ac3
LC
3230 if (rt->rt6i_flags & (RTF_DEFAULT | RTF_ADDRCONF) &&
3231 (!rt->rt6i_idev || rt->rt6i_idev->cnf.accept_ra != 2)) {
d3843fe5 3232 if (dst_hold_safe(&rt->dst)) {
66f5d6ce 3233 rcu_read_unlock();
d3843fe5
WW
3234 ip6_del_rt(rt);
3235 } else {
66f5d6ce 3236 rcu_read_unlock();
d3843fe5 3237 }
1da177e4
LT
3238 goto restart;
3239 }
3240 }
66f5d6ce 3241 rcu_read_unlock();
830218c1
DA
3242
3243 table->flags &= ~RT6_TABLE_HAS_DFLT_ROUTER;
3244}
3245
3246void rt6_purge_dflt_routers(struct net *net)
3247{
3248 struct fib6_table *table;
3249 struct hlist_head *head;
3250 unsigned int h;
3251
3252 rcu_read_lock();
3253
3254 for (h = 0; h < FIB6_TABLE_HASHSZ; h++) {
3255 head = &net->ipv6.fib_table_hash[h];
3256 hlist_for_each_entry_rcu(table, head, tb6_hlist) {
3257 if (table->flags & RT6_TABLE_HAS_DFLT_ROUTER)
3258 __rt6_purge_dflt_routers(table);
3259 }
3260 }
3261
3262 rcu_read_unlock();
1da177e4
LT
3263}
3264
5578689a
DL
3265static void rtmsg_to_fib6_config(struct net *net,
3266 struct in6_rtmsg *rtmsg,
86872cb5
TG
3267 struct fib6_config *cfg)
3268{
3269 memset(cfg, 0, sizeof(*cfg));
3270
ca254490
DA
3271 cfg->fc_table = l3mdev_fib_table_by_index(net, rtmsg->rtmsg_ifindex) ?
3272 : RT6_TABLE_MAIN;
86872cb5
TG
3273 cfg->fc_ifindex = rtmsg->rtmsg_ifindex;
3274 cfg->fc_metric = rtmsg->rtmsg_metric;
3275 cfg->fc_expires = rtmsg->rtmsg_info;
3276 cfg->fc_dst_len = rtmsg->rtmsg_dst_len;
3277 cfg->fc_src_len = rtmsg->rtmsg_src_len;
3278 cfg->fc_flags = rtmsg->rtmsg_flags;
3279
5578689a 3280 cfg->fc_nlinfo.nl_net = net;
f1243c2d 3281
4e3fd7a0
AD
3282 cfg->fc_dst = rtmsg->rtmsg_dst;
3283 cfg->fc_src = rtmsg->rtmsg_src;
3284 cfg->fc_gateway = rtmsg->rtmsg_gateway;
86872cb5
TG
3285}
3286
5578689a 3287int ipv6_route_ioctl(struct net *net, unsigned int cmd, void __user *arg)
1da177e4 3288{
86872cb5 3289 struct fib6_config cfg;
1da177e4
LT
3290 struct in6_rtmsg rtmsg;
3291 int err;
3292
67ba4152 3293 switch (cmd) {
1da177e4
LT
3294 case SIOCADDRT: /* Add a route */
3295 case SIOCDELRT: /* Delete a route */
af31f412 3296 if (!ns_capable(net->user_ns, CAP_NET_ADMIN))
1da177e4
LT
3297 return -EPERM;
3298 err = copy_from_user(&rtmsg, arg,
3299 sizeof(struct in6_rtmsg));
3300 if (err)
3301 return -EFAULT;
86872cb5 3302
5578689a 3303 rtmsg_to_fib6_config(net, &rtmsg, &cfg);
86872cb5 3304
1da177e4
LT
3305 rtnl_lock();
3306 switch (cmd) {
3307 case SIOCADDRT:
333c4301 3308 err = ip6_route_add(&cfg, NULL);
1da177e4
LT
3309 break;
3310 case SIOCDELRT:
333c4301 3311 err = ip6_route_del(&cfg, NULL);
1da177e4
LT
3312 break;
3313 default:
3314 err = -EINVAL;
3315 }
3316 rtnl_unlock();
3317
3318 return err;
3ff50b79 3319 }
1da177e4
LT
3320
3321 return -EINVAL;
3322}
3323
3324/*
3325 * Drop the packet on the floor
3326 */
3327
d5fdd6ba 3328static int ip6_pkt_drop(struct sk_buff *skb, u8 code, int ipstats_mib_noroutes)
1da177e4 3329{
612f09e8 3330 int type;
adf30907 3331 struct dst_entry *dst = skb_dst(skb);
612f09e8
YH
3332 switch (ipstats_mib_noroutes) {
3333 case IPSTATS_MIB_INNOROUTES:
0660e03f 3334 type = ipv6_addr_type(&ipv6_hdr(skb)->daddr);
45bb0060 3335 if (type == IPV6_ADDR_ANY) {
3bd653c8
DL
3336 IP6_INC_STATS(dev_net(dst->dev), ip6_dst_idev(dst),
3337 IPSTATS_MIB_INADDRERRORS);
612f09e8
YH
3338 break;
3339 }
3340 /* FALLTHROUGH */
3341 case IPSTATS_MIB_OUTNOROUTES:
3bd653c8
DL
3342 IP6_INC_STATS(dev_net(dst->dev), ip6_dst_idev(dst),
3343 ipstats_mib_noroutes);
612f09e8
YH
3344 break;
3345 }
3ffe533c 3346 icmpv6_send(skb, ICMPV6_DEST_UNREACH, code, 0);
1da177e4
LT
3347 kfree_skb(skb);
3348 return 0;
3349}
3350
9ce8ade0
TG
3351static int ip6_pkt_discard(struct sk_buff *skb)
3352{
612f09e8 3353 return ip6_pkt_drop(skb, ICMPV6_NOROUTE, IPSTATS_MIB_INNOROUTES);
9ce8ade0
TG
3354}
3355
ede2059d 3356static int ip6_pkt_discard_out(struct net *net, struct sock *sk, struct sk_buff *skb)
1da177e4 3357{
adf30907 3358 skb->dev = skb_dst(skb)->dev;
612f09e8 3359 return ip6_pkt_drop(skb, ICMPV6_NOROUTE, IPSTATS_MIB_OUTNOROUTES);
1da177e4
LT
3360}
3361
9ce8ade0
TG
3362static int ip6_pkt_prohibit(struct sk_buff *skb)
3363{
612f09e8 3364 return ip6_pkt_drop(skb, ICMPV6_ADM_PROHIBITED, IPSTATS_MIB_INNOROUTES);
9ce8ade0
TG
3365}
3366
ede2059d 3367static int ip6_pkt_prohibit_out(struct net *net, struct sock *sk, struct sk_buff *skb)
9ce8ade0 3368{
adf30907 3369 skb->dev = skb_dst(skb)->dev;
612f09e8 3370 return ip6_pkt_drop(skb, ICMPV6_ADM_PROHIBITED, IPSTATS_MIB_OUTNOROUTES);
9ce8ade0
TG
3371}
3372
1da177e4
LT
3373/*
3374 * Allocate a dst for local (unicast / anycast) address.
3375 */
3376
3377struct rt6_info *addrconf_dst_alloc(struct inet6_dev *idev,
3378 const struct in6_addr *addr,
8f031519 3379 bool anycast)
1da177e4 3380{
ca254490 3381 u32 tb_id;
c346dca1 3382 struct net *net = dev_net(idev->dev);
4832c30d 3383 struct net_device *dev = idev->dev;
5f02ce24
DA
3384 struct rt6_info *rt;
3385
5f02ce24 3386 rt = ip6_dst_alloc(net, dev, DST_NOCOUNT);
a3300ef4 3387 if (!rt)
1da177e4
LT
3388 return ERR_PTR(-ENOMEM);
3389
1da177e4
LT
3390 in6_dev_hold(idev);
3391
11d53b49 3392 rt->dst.flags |= DST_HOST;
d8d1f30b
CG
3393 rt->dst.input = ip6_input;
3394 rt->dst.output = ip6_output;
1da177e4 3395 rt->rt6i_idev = idev;
1da177e4 3396
94b5e0f9 3397 rt->rt6i_protocol = RTPROT_KERNEL;
1da177e4 3398 rt->rt6i_flags = RTF_UP | RTF_NONEXTHOP;
58c4fb86
YH
3399 if (anycast)
3400 rt->rt6i_flags |= RTF_ANYCAST;
3401 else
1da177e4 3402 rt->rt6i_flags |= RTF_LOCAL;
1da177e4 3403
550bab42 3404 rt->rt6i_gateway = *addr;
4e3fd7a0 3405 rt->rt6i_dst.addr = *addr;
1da177e4 3406 rt->rt6i_dst.plen = 128;
ca254490
DA
3407 tb_id = l3mdev_fib_table(idev->dev) ? : RT6_TABLE_LOCAL;
3408 rt->rt6i_table = fib6_get_table(net, tb_id);
1da177e4 3409
1da177e4
LT
3410 return rt;
3411}
3412
c3968a85
DW
3413/* remove deleted ip from prefsrc entries */
3414struct arg_dev_net_ip {
3415 struct net_device *dev;
3416 struct net *net;
3417 struct in6_addr *addr;
3418};
3419
3420static int fib6_remove_prefsrc(struct rt6_info *rt, void *arg)
3421{
3422 struct net_device *dev = ((struct arg_dev_net_ip *)arg)->dev;
3423 struct net *net = ((struct arg_dev_net_ip *)arg)->net;
3424 struct in6_addr *addr = ((struct arg_dev_net_ip *)arg)->addr;
3425
d1918542 3426 if (((void *)rt->dst.dev == dev || !dev) &&
c3968a85
DW
3427 rt != net->ipv6.ip6_null_entry &&
3428 ipv6_addr_equal(addr, &rt->rt6i_prefsrc.addr)) {
60006a48 3429 spin_lock_bh(&rt6_exception_lock);
c3968a85
DW
3430 /* remove prefsrc entry */
3431 rt->rt6i_prefsrc.plen = 0;
60006a48
WW
3432 /* need to update cache as well */
3433 rt6_exceptions_remove_prefsrc(rt);
3434 spin_unlock_bh(&rt6_exception_lock);
c3968a85
DW
3435 }
3436 return 0;
3437}
3438
3439void rt6_remove_prefsrc(struct inet6_ifaddr *ifp)
3440{
3441 struct net *net = dev_net(ifp->idev->dev);
3442 struct arg_dev_net_ip adni = {
3443 .dev = ifp->idev->dev,
3444 .net = net,
3445 .addr = &ifp->addr,
3446 };
0c3584d5 3447 fib6_clean_all(net, fib6_remove_prefsrc, &adni);
c3968a85
DW
3448}
3449
be7a010d 3450#define RTF_RA_ROUTER (RTF_ADDRCONF | RTF_DEFAULT | RTF_GATEWAY)
be7a010d
DJ
3451
3452/* Remove routers and update dst entries when gateway turn into host. */
3453static int fib6_clean_tohost(struct rt6_info *rt, void *arg)
3454{
3455 struct in6_addr *gateway = (struct in6_addr *)arg;
3456
2b760fcf
WW
3457 if (((rt->rt6i_flags & RTF_RA_ROUTER) == RTF_RA_ROUTER) &&
3458 ipv6_addr_equal(gateway, &rt->rt6i_gateway)) {
be7a010d
DJ
3459 return -1;
3460 }
b16cb459
WW
3461
3462 /* Further clean up cached routes in exception table.
3463 * This is needed because cached route may have a different
3464 * gateway than its 'parent' in the case of an ip redirect.
3465 */
3466 rt6_exceptions_clean_tohost(rt, gateway);
3467
be7a010d
DJ
3468 return 0;
3469}
3470
3471void rt6_clean_tohost(struct net *net, struct in6_addr *gateway)
3472{
3473 fib6_clean_all(net, fib6_clean_tohost, gateway);
3474}
3475
2127d95a
IS
3476struct arg_netdev_event {
3477 const struct net_device *dev;
4c981e28
IS
3478 union {
3479 unsigned int nh_flags;
3480 unsigned long event;
3481 };
2127d95a
IS
3482};
3483
3484static int fib6_ifup(struct rt6_info *rt, void *p_arg)
3485{
3486 const struct arg_netdev_event *arg = p_arg;
3487 const struct net *net = dev_net(arg->dev);
3488
1de178ed 3489 if (rt != net->ipv6.ip6_null_entry && rt->dst.dev == arg->dev) {
2127d95a 3490 rt->rt6i_nh_flags &= ~arg->nh_flags;
1de178ed
IS
3491 fib6_update_sernum_upto_root(dev_net(rt->dst.dev), rt);
3492 }
2127d95a
IS
3493
3494 return 0;
3495}
3496
3497void rt6_sync_up(struct net_device *dev, unsigned int nh_flags)
3498{
3499 struct arg_netdev_event arg = {
3500 .dev = dev,
3501 .nh_flags = nh_flags,
3502 };
3503
3504 if (nh_flags & RTNH_F_DEAD && netif_carrier_ok(dev))
3505 arg.nh_flags |= RTNH_F_LINKDOWN;
3506
3507 fib6_clean_all(dev_net(dev), fib6_ifup, &arg);
3508}
3509
1de178ed
IS
3510static bool rt6_multipath_uses_dev(const struct rt6_info *rt,
3511 const struct net_device *dev)
3512{
3513 struct rt6_info *iter;
3514
3515 if (rt->dst.dev == dev)
3516 return true;
3517 list_for_each_entry(iter, &rt->rt6i_siblings, rt6i_siblings)
3518 if (iter->dst.dev == dev)
3519 return true;
3520
3521 return false;
3522}
3523
3524static void rt6_multipath_flush(struct rt6_info *rt)
3525{
3526 struct rt6_info *iter;
3527
3528 rt->should_flush = 1;
3529 list_for_each_entry(iter, &rt->rt6i_siblings, rt6i_siblings)
3530 iter->should_flush = 1;
3531}
3532
3533static unsigned int rt6_multipath_dead_count(const struct rt6_info *rt,
3534 const struct net_device *down_dev)
3535{
3536 struct rt6_info *iter;
3537 unsigned int dead = 0;
3538
3539 if (rt->dst.dev == down_dev || rt->rt6i_nh_flags & RTNH_F_DEAD)
3540 dead++;
3541 list_for_each_entry(iter, &rt->rt6i_siblings, rt6i_siblings)
3542 if (iter->dst.dev == down_dev ||
3543 iter->rt6i_nh_flags & RTNH_F_DEAD)
3544 dead++;
3545
3546 return dead;
3547}
3548
3549static void rt6_multipath_nh_flags_set(struct rt6_info *rt,
3550 const struct net_device *dev,
3551 unsigned int nh_flags)
3552{
3553 struct rt6_info *iter;
3554
3555 if (rt->dst.dev == dev)
3556 rt->rt6i_nh_flags |= nh_flags;
3557 list_for_each_entry(iter, &rt->rt6i_siblings, rt6i_siblings)
3558 if (iter->dst.dev == dev)
3559 iter->rt6i_nh_flags |= nh_flags;
3560}
3561
a1a22c12 3562/* called with write lock held for table with rt */
4c981e28 3563static int fib6_ifdown(struct rt6_info *rt, void *p_arg)
1da177e4 3564{
4c981e28
IS
3565 const struct arg_netdev_event *arg = p_arg;
3566 const struct net_device *dev = arg->dev;
3567 const struct net *net = dev_net(dev);
8ed67789 3568
1de178ed 3569 if (rt == net->ipv6.ip6_null_entry)
27c6fa73
IS
3570 return 0;
3571
3572 switch (arg->event) {
3573 case NETDEV_UNREGISTER:
1de178ed 3574 return rt->dst.dev == dev ? -1 : 0;
27c6fa73 3575 case NETDEV_DOWN:
1de178ed 3576 if (rt->should_flush)
27c6fa73 3577 return -1;
1de178ed
IS
3578 if (!rt->rt6i_nsiblings)
3579 return rt->dst.dev == dev ? -1 : 0;
3580 if (rt6_multipath_uses_dev(rt, dev)) {
3581 unsigned int count;
3582
3583 count = rt6_multipath_dead_count(rt, dev);
3584 if (rt->rt6i_nsiblings + 1 == count) {
3585 rt6_multipath_flush(rt);
3586 return -1;
3587 }
3588 rt6_multipath_nh_flags_set(rt, dev, RTNH_F_DEAD |
3589 RTNH_F_LINKDOWN);
3590 fib6_update_sernum(rt);
3591 }
3592 return -2;
27c6fa73 3593 case NETDEV_CHANGE:
1de178ed
IS
3594 if (rt->dst.dev != dev ||
3595 rt->rt6i_flags & (RTF_LOCAL | RTF_ANYCAST))
27c6fa73
IS
3596 break;
3597 rt->rt6i_nh_flags |= RTNH_F_LINKDOWN;
3598 break;
2b241361 3599 }
c159d30c 3600
1da177e4
LT
3601 return 0;
3602}
3603
27c6fa73 3604void rt6_sync_down_dev(struct net_device *dev, unsigned long event)
1da177e4 3605{
4c981e28 3606 struct arg_netdev_event arg = {
8ed67789 3607 .dev = dev,
4c981e28 3608 .event = event,
8ed67789
DL
3609 };
3610
4c981e28
IS
3611 fib6_clean_all(dev_net(dev), fib6_ifdown, &arg);
3612}
3613
3614void rt6_disable_ip(struct net_device *dev, unsigned long event)
3615{
3616 rt6_sync_down_dev(dev, event);
3617 rt6_uncached_list_flush_dev(dev_net(dev), dev);
3618 neigh_ifdown(&nd_tbl, dev);
1da177e4
LT
3619}
3620
95c96174 3621struct rt6_mtu_change_arg {
1da177e4 3622 struct net_device *dev;
95c96174 3623 unsigned int mtu;
1da177e4
LT
3624};
3625
3626static int rt6_mtu_change_route(struct rt6_info *rt, void *p_arg)
3627{
3628 struct rt6_mtu_change_arg *arg = (struct rt6_mtu_change_arg *) p_arg;
3629 struct inet6_dev *idev;
3630
3631 /* In IPv6 pmtu discovery is not optional,
3632 so that RTAX_MTU lock cannot disable it.
3633 We still use this lock to block changes
3634 caused by addrconf/ndisc.
3635 */
3636
3637 idev = __in6_dev_get(arg->dev);
38308473 3638 if (!idev)
1da177e4
LT
3639 return 0;
3640
3641 /* For administrative MTU increase, there is no way to discover
3642 IPv6 PMTU increase, so PMTU increase should be updated here.
3643 Since RFC 1981 doesn't include administrative MTU increase
3644 update PMTU increase is a MUST. (i.e. jumbo frame)
3645 */
3646 /*
3647 If new MTU is less than route PMTU, this new MTU will be the
3648 lowest MTU in the path, update the route PMTU to reflect PMTU
3649 decreases; if new MTU is greater than route PMTU, and the
3650 old MTU is the lowest MTU in the path, update the route PMTU
3651 to reflect the increase. In this case if the other nodes' MTU
3652 also have the lowest MTU, TOO BIG MESSAGE will be lead to
67c408cf 3653 PMTU discovery.
1da177e4 3654 */
d1918542 3655 if (rt->dst.dev == arg->dev &&
fb56be83 3656 dst_metric_raw(&rt->dst, RTAX_MTU) &&
4b32b5ad 3657 !dst_metric_locked(&rt->dst, RTAX_MTU)) {
f5bbe7ee 3658 spin_lock_bh(&rt6_exception_lock);
2b760fcf
WW
3659 if (dst_mtu(&rt->dst) >= arg->mtu ||
3660 (dst_mtu(&rt->dst) < arg->mtu &&
3661 dst_mtu(&rt->dst) == idev->cnf.mtu6)) {
4b32b5ad
MKL
3662 dst_metric_set(&rt->dst, RTAX_MTU, arg->mtu);
3663 }
f5bbe7ee
WW
3664 rt6_exceptions_update_pmtu(rt, arg->mtu);
3665 spin_unlock_bh(&rt6_exception_lock);
566cfd8f 3666 }
1da177e4
LT
3667 return 0;
3668}
3669
95c96174 3670void rt6_mtu_change(struct net_device *dev, unsigned int mtu)
1da177e4 3671{
c71099ac
TG
3672 struct rt6_mtu_change_arg arg = {
3673 .dev = dev,
3674 .mtu = mtu,
3675 };
1da177e4 3676
0c3584d5 3677 fib6_clean_all(dev_net(dev), rt6_mtu_change_route, &arg);
1da177e4
LT
3678}
3679
ef7c79ed 3680static const struct nla_policy rtm_ipv6_policy[RTA_MAX+1] = {
5176f91e 3681 [RTA_GATEWAY] = { .len = sizeof(struct in6_addr) },
86872cb5 3682 [RTA_OIF] = { .type = NLA_U32 },
ab364a6f 3683 [RTA_IIF] = { .type = NLA_U32 },
86872cb5
TG
3684 [RTA_PRIORITY] = { .type = NLA_U32 },
3685 [RTA_METRICS] = { .type = NLA_NESTED },
51ebd318 3686 [RTA_MULTIPATH] = { .len = sizeof(struct rtnexthop) },
c78ba6d6 3687 [RTA_PREF] = { .type = NLA_U8 },
19e42e45
RP
3688 [RTA_ENCAP_TYPE] = { .type = NLA_U16 },
3689 [RTA_ENCAP] = { .type = NLA_NESTED },
32bc201e 3690 [RTA_EXPIRES] = { .type = NLA_U32 },
622ec2c9 3691 [RTA_UID] = { .type = NLA_U32 },
3b45a410 3692 [RTA_MARK] = { .type = NLA_U32 },
86872cb5
TG
3693};
3694
3695static int rtm_to_fib6_config(struct sk_buff *skb, struct nlmsghdr *nlh,
333c4301
DA
3696 struct fib6_config *cfg,
3697 struct netlink_ext_ack *extack)
1da177e4 3698{
86872cb5
TG
3699 struct rtmsg *rtm;
3700 struct nlattr *tb[RTA_MAX+1];
c78ba6d6 3701 unsigned int pref;
86872cb5 3702 int err;
1da177e4 3703
fceb6435
JB
3704 err = nlmsg_parse(nlh, sizeof(*rtm), tb, RTA_MAX, rtm_ipv6_policy,
3705 NULL);
86872cb5
TG
3706 if (err < 0)
3707 goto errout;
1da177e4 3708
86872cb5
TG
3709 err = -EINVAL;
3710 rtm = nlmsg_data(nlh);
3711 memset(cfg, 0, sizeof(*cfg));
3712
3713 cfg->fc_table = rtm->rtm_table;
3714 cfg->fc_dst_len = rtm->rtm_dst_len;
3715 cfg->fc_src_len = rtm->rtm_src_len;
3716 cfg->fc_flags = RTF_UP;
3717 cfg->fc_protocol = rtm->rtm_protocol;
ef2c7d7b 3718 cfg->fc_type = rtm->rtm_type;
86872cb5 3719
ef2c7d7b
ND
3720 if (rtm->rtm_type == RTN_UNREACHABLE ||
3721 rtm->rtm_type == RTN_BLACKHOLE ||
b4949ab2
ND
3722 rtm->rtm_type == RTN_PROHIBIT ||
3723 rtm->rtm_type == RTN_THROW)
86872cb5
TG
3724 cfg->fc_flags |= RTF_REJECT;
3725
ab79ad14
3726 if (rtm->rtm_type == RTN_LOCAL)
3727 cfg->fc_flags |= RTF_LOCAL;
3728
1f56a01f
MKL
3729 if (rtm->rtm_flags & RTM_F_CLONED)
3730 cfg->fc_flags |= RTF_CACHE;
3731
15e47304 3732 cfg->fc_nlinfo.portid = NETLINK_CB(skb).portid;
86872cb5 3733 cfg->fc_nlinfo.nlh = nlh;
3b1e0a65 3734 cfg->fc_nlinfo.nl_net = sock_net(skb->sk);
86872cb5
TG
3735
3736 if (tb[RTA_GATEWAY]) {
67b61f6c 3737 cfg->fc_gateway = nla_get_in6_addr(tb[RTA_GATEWAY]);
86872cb5 3738 cfg->fc_flags |= RTF_GATEWAY;
1da177e4 3739 }
86872cb5
TG
3740
3741 if (tb[RTA_DST]) {
3742 int plen = (rtm->rtm_dst_len + 7) >> 3;
3743
3744 if (nla_len(tb[RTA_DST]) < plen)
3745 goto errout;
3746
3747 nla_memcpy(&cfg->fc_dst, tb[RTA_DST], plen);
1da177e4 3748 }
86872cb5
TG
3749
3750 if (tb[RTA_SRC]) {
3751 int plen = (rtm->rtm_src_len + 7) >> 3;
3752
3753 if (nla_len(tb[RTA_SRC]) < plen)
3754 goto errout;
3755
3756 nla_memcpy(&cfg->fc_src, tb[RTA_SRC], plen);
1da177e4 3757 }
86872cb5 3758
c3968a85 3759 if (tb[RTA_PREFSRC])
67b61f6c 3760 cfg->fc_prefsrc = nla_get_in6_addr(tb[RTA_PREFSRC]);
c3968a85 3761
86872cb5
TG
3762 if (tb[RTA_OIF])
3763 cfg->fc_ifindex = nla_get_u32(tb[RTA_OIF]);
3764
3765 if (tb[RTA_PRIORITY])
3766 cfg->fc_metric = nla_get_u32(tb[RTA_PRIORITY]);
3767
3768 if (tb[RTA_METRICS]) {
3769 cfg->fc_mx = nla_data(tb[RTA_METRICS]);
3770 cfg->fc_mx_len = nla_len(tb[RTA_METRICS]);
1da177e4 3771 }
86872cb5
TG
3772
3773 if (tb[RTA_TABLE])
3774 cfg->fc_table = nla_get_u32(tb[RTA_TABLE]);
3775
51ebd318
ND
3776 if (tb[RTA_MULTIPATH]) {
3777 cfg->fc_mp = nla_data(tb[RTA_MULTIPATH]);
3778 cfg->fc_mp_len = nla_len(tb[RTA_MULTIPATH]);
9ed59592
DA
3779
3780 err = lwtunnel_valid_encap_type_attr(cfg->fc_mp,
c255bd68 3781 cfg->fc_mp_len, extack);
9ed59592
DA
3782 if (err < 0)
3783 goto errout;
51ebd318
ND
3784 }
3785
c78ba6d6
LR
3786 if (tb[RTA_PREF]) {
3787 pref = nla_get_u8(tb[RTA_PREF]);
3788 if (pref != ICMPV6_ROUTER_PREF_LOW &&
3789 pref != ICMPV6_ROUTER_PREF_HIGH)
3790 pref = ICMPV6_ROUTER_PREF_MEDIUM;
3791 cfg->fc_flags |= RTF_PREF(pref);
3792 }
3793
19e42e45
RP
3794 if (tb[RTA_ENCAP])
3795 cfg->fc_encap = tb[RTA_ENCAP];
3796
9ed59592 3797 if (tb[RTA_ENCAP_TYPE]) {
19e42e45
RP
3798 cfg->fc_encap_type = nla_get_u16(tb[RTA_ENCAP_TYPE]);
3799
c255bd68 3800 err = lwtunnel_valid_encap_type(cfg->fc_encap_type, extack);
9ed59592
DA
3801 if (err < 0)
3802 goto errout;
3803 }
3804
32bc201e
XL
3805 if (tb[RTA_EXPIRES]) {
3806 unsigned long timeout = addrconf_timeout_fixup(nla_get_u32(tb[RTA_EXPIRES]), HZ);
3807
3808 if (addrconf_finite_timeout(timeout)) {
3809 cfg->fc_expires = jiffies_to_clock_t(timeout * HZ);
3810 cfg->fc_flags |= RTF_EXPIRES;
3811 }
3812 }
3813
86872cb5
TG
3814 err = 0;
3815errout:
3816 return err;
1da177e4
LT
3817}
3818
6b9ea5a6
RP
3819struct rt6_nh {
3820 struct rt6_info *rt6_info;
3821 struct fib6_config r_cfg;
3822 struct mx6_config mxc;
3823 struct list_head next;
3824};
3825
3826static void ip6_print_replace_route_err(struct list_head *rt6_nh_list)
3827{
3828 struct rt6_nh *nh;
3829
3830 list_for_each_entry(nh, rt6_nh_list, next) {
7d4d5065 3831 pr_warn("IPV6: multipath route replace failed (check consistency of installed routes): %pI6c nexthop %pI6c ifi %d\n",
6b9ea5a6
RP
3832 &nh->r_cfg.fc_dst, &nh->r_cfg.fc_gateway,
3833 nh->r_cfg.fc_ifindex);
3834 }
3835}
3836
3837static int ip6_route_info_append(struct list_head *rt6_nh_list,
3838 struct rt6_info *rt, struct fib6_config *r_cfg)
3839{
3840 struct rt6_nh *nh;
6b9ea5a6
RP
3841 int err = -EEXIST;
3842
3843 list_for_each_entry(nh, rt6_nh_list, next) {
3844 /* check if rt6_info already exists */
f06b7549 3845 if (rt6_duplicate_nexthop(nh->rt6_info, rt))
6b9ea5a6
RP
3846 return err;
3847 }
3848
3849 nh = kzalloc(sizeof(*nh), GFP_KERNEL);
3850 if (!nh)
3851 return -ENOMEM;
3852 nh->rt6_info = rt;
3853 err = ip6_convert_metrics(&nh->mxc, r_cfg);
3854 if (err) {
3855 kfree(nh);
3856 return err;
3857 }
3858 memcpy(&nh->r_cfg, r_cfg, sizeof(*r_cfg));
3859 list_add_tail(&nh->next, rt6_nh_list);
3860
3861 return 0;
3862}
3863
3b1137fe
DA
3864static void ip6_route_mpath_notify(struct rt6_info *rt,
3865 struct rt6_info *rt_last,
3866 struct nl_info *info,
3867 __u16 nlflags)
3868{
3869 /* if this is an APPEND route, then rt points to the first route
3870 * inserted and rt_last points to last route inserted. Userspace
3871 * wants a consistent dump of the route which starts at the first
3872 * nexthop. Since sibling routes are always added at the end of
3873 * the list, find the first sibling of the last route appended
3874 */
3875 if ((nlflags & NLM_F_APPEND) && rt_last && rt_last->rt6i_nsiblings) {
3876 rt = list_first_entry(&rt_last->rt6i_siblings,
3877 struct rt6_info,
3878 rt6i_siblings);
3879 }
3880
3881 if (rt)
3882 inet6_rt_notify(RTM_NEWROUTE, rt, info, nlflags);
3883}
3884
333c4301
DA
3885static int ip6_route_multipath_add(struct fib6_config *cfg,
3886 struct netlink_ext_ack *extack)
51ebd318 3887{
3b1137fe
DA
3888 struct rt6_info *rt_notif = NULL, *rt_last = NULL;
3889 struct nl_info *info = &cfg->fc_nlinfo;
51ebd318
ND
3890 struct fib6_config r_cfg;
3891 struct rtnexthop *rtnh;
6b9ea5a6
RP
3892 struct rt6_info *rt;
3893 struct rt6_nh *err_nh;
3894 struct rt6_nh *nh, *nh_safe;
3b1137fe 3895 __u16 nlflags;
51ebd318
ND
3896 int remaining;
3897 int attrlen;
6b9ea5a6
RP
3898 int err = 1;
3899 int nhn = 0;
3900 int replace = (cfg->fc_nlinfo.nlh &&
3901 (cfg->fc_nlinfo.nlh->nlmsg_flags & NLM_F_REPLACE));
3902 LIST_HEAD(rt6_nh_list);
51ebd318 3903
3b1137fe
DA
3904 nlflags = replace ? NLM_F_REPLACE : NLM_F_CREATE;
3905 if (info->nlh && info->nlh->nlmsg_flags & NLM_F_APPEND)
3906 nlflags |= NLM_F_APPEND;
3907
35f1b4e9 3908 remaining = cfg->fc_mp_len;
51ebd318 3909 rtnh = (struct rtnexthop *)cfg->fc_mp;
51ebd318 3910
6b9ea5a6
RP
3911 /* Parse a Multipath Entry and build a list (rt6_nh_list) of
3912 * rt6_info structs per nexthop
3913 */
51ebd318
ND
3914 while (rtnh_ok(rtnh, remaining)) {
3915 memcpy(&r_cfg, cfg, sizeof(*cfg));
3916 if (rtnh->rtnh_ifindex)
3917 r_cfg.fc_ifindex = rtnh->rtnh_ifindex;
3918
3919 attrlen = rtnh_attrlen(rtnh);
3920 if (attrlen > 0) {
3921 struct nlattr *nla, *attrs = rtnh_attrs(rtnh);
3922
3923 nla = nla_find(attrs, attrlen, RTA_GATEWAY);
3924 if (nla) {
67b61f6c 3925 r_cfg.fc_gateway = nla_get_in6_addr(nla);
51ebd318
ND
3926 r_cfg.fc_flags |= RTF_GATEWAY;
3927 }
19e42e45
RP
3928 r_cfg.fc_encap = nla_find(attrs, attrlen, RTA_ENCAP);
3929 nla = nla_find(attrs, attrlen, RTA_ENCAP_TYPE);
3930 if (nla)
3931 r_cfg.fc_encap_type = nla_get_u16(nla);
51ebd318 3932 }
6b9ea5a6 3933
333c4301 3934 rt = ip6_route_info_create(&r_cfg, extack);
8c5b83f0
RP
3935 if (IS_ERR(rt)) {
3936 err = PTR_ERR(rt);
3937 rt = NULL;
6b9ea5a6 3938 goto cleanup;
8c5b83f0 3939 }
6b9ea5a6
RP
3940
3941 err = ip6_route_info_append(&rt6_nh_list, rt, &r_cfg);
51ebd318 3942 if (err) {
587fea74 3943 dst_release_immediate(&rt->dst);
6b9ea5a6
RP
3944 goto cleanup;
3945 }
3946
3947 rtnh = rtnh_next(rtnh, &remaining);
3948 }
3949
3b1137fe
DA
3950 /* for add and replace send one notification with all nexthops.
3951 * Skip the notification in fib6_add_rt2node and send one with
3952 * the full route when done
3953 */
3954 info->skip_notify = 1;
3955
6b9ea5a6
RP
3956 err_nh = NULL;
3957 list_for_each_entry(nh, &rt6_nh_list, next) {
3b1137fe 3958 rt_last = nh->rt6_info;
333c4301 3959 err = __ip6_ins_rt(nh->rt6_info, info, &nh->mxc, extack);
3b1137fe
DA
3960 /* save reference to first route for notification */
3961 if (!rt_notif && !err)
3962 rt_notif = nh->rt6_info;
3963
6b9ea5a6
RP
3964 /* nh->rt6_info is used or freed at this point, reset to NULL*/
3965 nh->rt6_info = NULL;
3966 if (err) {
3967 if (replace && nhn)
3968 ip6_print_replace_route_err(&rt6_nh_list);
3969 err_nh = nh;
3970 goto add_errout;
51ebd318 3971 }
6b9ea5a6 3972
1a72418b 3973 /* Because each route is added like a single route we remove
27596472
MK
3974 * these flags after the first nexthop: if there is a collision,
3975 * we have already failed to add the first nexthop:
3976 * fib6_add_rt2node() has rejected it; when replacing, old
3977 * nexthops have been replaced by first new, the rest should
3978 * be added to it.
1a72418b 3979 */
27596472
MK
3980 cfg->fc_nlinfo.nlh->nlmsg_flags &= ~(NLM_F_EXCL |
3981 NLM_F_REPLACE);
6b9ea5a6
RP
3982 nhn++;
3983 }
3984
3b1137fe
DA
3985 /* success ... tell user about new route */
3986 ip6_route_mpath_notify(rt_notif, rt_last, info, nlflags);
6b9ea5a6
RP
3987 goto cleanup;
3988
3989add_errout:
3b1137fe
DA
3990 /* send notification for routes that were added so that
3991 * the delete notifications sent by ip6_route_del are
3992 * coherent
3993 */
3994 if (rt_notif)
3995 ip6_route_mpath_notify(rt_notif, rt_last, info, nlflags);
3996
6b9ea5a6
RP
3997 /* Delete routes that were already added */
3998 list_for_each_entry(nh, &rt6_nh_list, next) {
3999 if (err_nh == nh)
4000 break;
333c4301 4001 ip6_route_del(&nh->r_cfg, extack);
6b9ea5a6
RP
4002 }
4003
4004cleanup:
4005 list_for_each_entry_safe(nh, nh_safe, &rt6_nh_list, next) {
587fea74
WW
4006 if (nh->rt6_info)
4007 dst_release_immediate(&nh->rt6_info->dst);
52fe51f8 4008 kfree(nh->mxc.mx);
6b9ea5a6
RP
4009 list_del(&nh->next);
4010 kfree(nh);
4011 }
4012
4013 return err;
4014}
4015
333c4301
DA
4016static int ip6_route_multipath_del(struct fib6_config *cfg,
4017 struct netlink_ext_ack *extack)
6b9ea5a6
RP
4018{
4019 struct fib6_config r_cfg;
4020 struct rtnexthop *rtnh;
4021 int remaining;
4022 int attrlen;
4023 int err = 1, last_err = 0;
4024
4025 remaining = cfg->fc_mp_len;
4026 rtnh = (struct rtnexthop *)cfg->fc_mp;
4027
4028 /* Parse a Multipath Entry */
4029 while (rtnh_ok(rtnh, remaining)) {
4030 memcpy(&r_cfg, cfg, sizeof(*cfg));
4031 if (rtnh->rtnh_ifindex)
4032 r_cfg.fc_ifindex = rtnh->rtnh_ifindex;
4033
4034 attrlen = rtnh_attrlen(rtnh);
4035 if (attrlen > 0) {
4036 struct nlattr *nla, *attrs = rtnh_attrs(rtnh);
4037
4038 nla = nla_find(attrs, attrlen, RTA_GATEWAY);
4039 if (nla) {
4040 nla_memcpy(&r_cfg.fc_gateway, nla, 16);
4041 r_cfg.fc_flags |= RTF_GATEWAY;
4042 }
4043 }
333c4301 4044 err = ip6_route_del(&r_cfg, extack);
6b9ea5a6
RP
4045 if (err)
4046 last_err = err;
4047
51ebd318
ND
4048 rtnh = rtnh_next(rtnh, &remaining);
4049 }
4050
4051 return last_err;
4052}
4053
c21ef3e3
DA
4054static int inet6_rtm_delroute(struct sk_buff *skb, struct nlmsghdr *nlh,
4055 struct netlink_ext_ack *extack)
1da177e4 4056{
86872cb5
TG
4057 struct fib6_config cfg;
4058 int err;
1da177e4 4059
333c4301 4060 err = rtm_to_fib6_config(skb, nlh, &cfg, extack);
86872cb5
TG
4061 if (err < 0)
4062 return err;
4063
51ebd318 4064 if (cfg.fc_mp)
333c4301 4065 return ip6_route_multipath_del(&cfg, extack);
0ae81335
DA
4066 else {
4067 cfg.fc_delete_all_nh = 1;
333c4301 4068 return ip6_route_del(&cfg, extack);
0ae81335 4069 }
1da177e4
LT
4070}
4071
c21ef3e3
DA
4072static int inet6_rtm_newroute(struct sk_buff *skb, struct nlmsghdr *nlh,
4073 struct netlink_ext_ack *extack)
1da177e4 4074{
86872cb5
TG
4075 struct fib6_config cfg;
4076 int err;
1da177e4 4077
333c4301 4078 err = rtm_to_fib6_config(skb, nlh, &cfg, extack);
86872cb5
TG
4079 if (err < 0)
4080 return err;
4081
51ebd318 4082 if (cfg.fc_mp)
333c4301 4083 return ip6_route_multipath_add(&cfg, extack);
51ebd318 4084 else
333c4301 4085 return ip6_route_add(&cfg, extack);
1da177e4
LT
4086}
4087
beb1afac 4088static size_t rt6_nlmsg_size(struct rt6_info *rt)
339bf98f 4089{
beb1afac
DA
4090 int nexthop_len = 0;
4091
4092 if (rt->rt6i_nsiblings) {
4093 nexthop_len = nla_total_size(0) /* RTA_MULTIPATH */
4094 + NLA_ALIGN(sizeof(struct rtnexthop))
4095 + nla_total_size(16) /* RTA_GATEWAY */
beb1afac
DA
4096 + lwtunnel_get_encap_size(rt->dst.lwtstate);
4097
4098 nexthop_len *= rt->rt6i_nsiblings;
4099 }
4100
339bf98f
TG
4101 return NLMSG_ALIGN(sizeof(struct rtmsg))
4102 + nla_total_size(16) /* RTA_SRC */
4103 + nla_total_size(16) /* RTA_DST */
4104 + nla_total_size(16) /* RTA_GATEWAY */
4105 + nla_total_size(16) /* RTA_PREFSRC */
4106 + nla_total_size(4) /* RTA_TABLE */
4107 + nla_total_size(4) /* RTA_IIF */
4108 + nla_total_size(4) /* RTA_OIF */
4109 + nla_total_size(4) /* RTA_PRIORITY */
6a2b9ce0 4110 + RTAX_MAX * nla_total_size(4) /* RTA_METRICS */
ea697639 4111 + nla_total_size(sizeof(struct rta_cacheinfo))
c78ba6d6 4112 + nla_total_size(TCP_CA_NAME_MAX) /* RTAX_CC_ALGO */
19e42e45 4113 + nla_total_size(1) /* RTA_PREF */
beb1afac
DA
4114 + lwtunnel_get_encap_size(rt->dst.lwtstate)
4115 + nexthop_len;
4116}
4117
4118static int rt6_nexthop_info(struct sk_buff *skb, struct rt6_info *rt,
5be083ce 4119 unsigned int *flags, bool skip_oif)
beb1afac 4120{
f9d882ea
IS
4121 if (rt->rt6i_nh_flags & RTNH_F_DEAD)
4122 *flags |= RTNH_F_DEAD;
4123
44c9f2f2 4124 if (rt->rt6i_nh_flags & RTNH_F_LINKDOWN) {
beb1afac
DA
4125 *flags |= RTNH_F_LINKDOWN;
4126 if (rt->rt6i_idev->cnf.ignore_routes_with_linkdown)
4127 *flags |= RTNH_F_DEAD;
4128 }
4129
4130 if (rt->rt6i_flags & RTF_GATEWAY) {
4131 if (nla_put_in6_addr(skb, RTA_GATEWAY, &rt->rt6i_gateway) < 0)
4132 goto nla_put_failure;
4133 }
4134
fe400799 4135 if (rt->rt6i_nh_flags & RTNH_F_OFFLOAD)
61e4d01e
IS
4136 *flags |= RTNH_F_OFFLOAD;
4137
5be083ce
DA
4138 /* not needed for multipath encoding b/c it has a rtnexthop struct */
4139 if (!skip_oif && rt->dst.dev &&
beb1afac
DA
4140 nla_put_u32(skb, RTA_OIF, rt->dst.dev->ifindex))
4141 goto nla_put_failure;
4142
4143 if (rt->dst.lwtstate &&
4144 lwtunnel_fill_encap(skb, rt->dst.lwtstate) < 0)
4145 goto nla_put_failure;
4146
4147 return 0;
4148
4149nla_put_failure:
4150 return -EMSGSIZE;
4151}
4152
5be083ce 4153/* add multipath next hop */
beb1afac
DA
4154static int rt6_add_nexthop(struct sk_buff *skb, struct rt6_info *rt)
4155{
4156 struct rtnexthop *rtnh;
4157 unsigned int flags = 0;
4158
4159 rtnh = nla_reserve_nohdr(skb, sizeof(*rtnh));
4160 if (!rtnh)
4161 goto nla_put_failure;
4162
4163 rtnh->rtnh_hops = 0;
4164 rtnh->rtnh_ifindex = rt->dst.dev ? rt->dst.dev->ifindex : 0;
4165
5be083ce 4166 if (rt6_nexthop_info(skb, rt, &flags, true) < 0)
beb1afac
DA
4167 goto nla_put_failure;
4168
4169 rtnh->rtnh_flags = flags;
4170
4171 /* length of rtnetlink header + attributes */
4172 rtnh->rtnh_len = nlmsg_get_pos(skb) - (void *)rtnh;
4173
4174 return 0;
4175
4176nla_put_failure:
4177 return -EMSGSIZE;
339bf98f
TG
4178}
4179
191cd582
BH
4180static int rt6_fill_node(struct net *net,
4181 struct sk_buff *skb, struct rt6_info *rt,
0d51aa80 4182 struct in6_addr *dst, struct in6_addr *src,
15e47304 4183 int iif, int type, u32 portid, u32 seq,
f8cfe2ce 4184 unsigned int flags)
1da177e4 4185{
4b32b5ad 4186 u32 metrics[RTAX_MAX];
1da177e4 4187 struct rtmsg *rtm;
2d7202bf 4188 struct nlmsghdr *nlh;
e3703b3d 4189 long expires;
9e762a4a 4190 u32 table;
1da177e4 4191
15e47304 4192 nlh = nlmsg_put(skb, portid, seq, type, sizeof(*rtm), flags);
38308473 4193 if (!nlh)
26932566 4194 return -EMSGSIZE;
2d7202bf
TG
4195
4196 rtm = nlmsg_data(nlh);
1da177e4
LT
4197 rtm->rtm_family = AF_INET6;
4198 rtm->rtm_dst_len = rt->rt6i_dst.plen;
4199 rtm->rtm_src_len = rt->rt6i_src.plen;
4200 rtm->rtm_tos = 0;
c71099ac 4201 if (rt->rt6i_table)
9e762a4a 4202 table = rt->rt6i_table->tb6_id;
c71099ac 4203 else
9e762a4a
PM
4204 table = RT6_TABLE_UNSPEC;
4205 rtm->rtm_table = table;
c78679e8
DM
4206 if (nla_put_u32(skb, RTA_TABLE, table))
4207 goto nla_put_failure;
ef2c7d7b
ND
4208 if (rt->rt6i_flags & RTF_REJECT) {
4209 switch (rt->dst.error) {
4210 case -EINVAL:
4211 rtm->rtm_type = RTN_BLACKHOLE;
4212 break;
4213 case -EACCES:
4214 rtm->rtm_type = RTN_PROHIBIT;
4215 break;
b4949ab2
ND
4216 case -EAGAIN:
4217 rtm->rtm_type = RTN_THROW;
4218 break;
ef2c7d7b
ND
4219 default:
4220 rtm->rtm_type = RTN_UNREACHABLE;
4221 break;
4222 }
4223 }
38308473 4224 else if (rt->rt6i_flags & RTF_LOCAL)
ab79ad14 4225 rtm->rtm_type = RTN_LOCAL;
4ee39733
DA
4226 else if (rt->rt6i_flags & RTF_ANYCAST)
4227 rtm->rtm_type = RTN_ANYCAST;
d1918542 4228 else if (rt->dst.dev && (rt->dst.dev->flags & IFF_LOOPBACK))
1da177e4
LT
4229 rtm->rtm_type = RTN_LOCAL;
4230 else
4231 rtm->rtm_type = RTN_UNICAST;
4232 rtm->rtm_flags = 0;
4233 rtm->rtm_scope = RT_SCOPE_UNIVERSE;
4234 rtm->rtm_protocol = rt->rt6i_protocol;
1da177e4 4235
38308473 4236 if (rt->rt6i_flags & RTF_CACHE)
1da177e4
LT
4237 rtm->rtm_flags |= RTM_F_CLONED;
4238
4239 if (dst) {
930345ea 4240 if (nla_put_in6_addr(skb, RTA_DST, dst))
c78679e8 4241 goto nla_put_failure;
1ab1457c 4242 rtm->rtm_dst_len = 128;
1da177e4 4243 } else if (rtm->rtm_dst_len)
930345ea 4244 if (nla_put_in6_addr(skb, RTA_DST, &rt->rt6i_dst.addr))
c78679e8 4245 goto nla_put_failure;
1da177e4
LT
4246#ifdef CONFIG_IPV6_SUBTREES
4247 if (src) {
930345ea 4248 if (nla_put_in6_addr(skb, RTA_SRC, src))
c78679e8 4249 goto nla_put_failure;
1ab1457c 4250 rtm->rtm_src_len = 128;
c78679e8 4251 } else if (rtm->rtm_src_len &&
930345ea 4252 nla_put_in6_addr(skb, RTA_SRC, &rt->rt6i_src.addr))
c78679e8 4253 goto nla_put_failure;
1da177e4 4254#endif
7bc570c8
YH
4255 if (iif) {
4256#ifdef CONFIG_IPV6_MROUTE
4257 if (ipv6_addr_is_multicast(&rt->rt6i_dst.addr)) {
fd61c6ba
DA
4258 int err = ip6mr_get_route(net, skb, rtm, portid);
4259
4260 if (err == 0)
4261 return 0;
4262 if (err < 0)
4263 goto nla_put_failure;
7bc570c8
YH
4264 } else
4265#endif
c78679e8
DM
4266 if (nla_put_u32(skb, RTA_IIF, iif))
4267 goto nla_put_failure;
7bc570c8 4268 } else if (dst) {
1da177e4 4269 struct in6_addr saddr_buf;
c78679e8 4270 if (ip6_route_get_saddr(net, rt, dst, 0, &saddr_buf) == 0 &&
930345ea 4271 nla_put_in6_addr(skb, RTA_PREFSRC, &saddr_buf))
c78679e8 4272 goto nla_put_failure;
1da177e4 4273 }
2d7202bf 4274
c3968a85
DW
4275 if (rt->rt6i_prefsrc.plen) {
4276 struct in6_addr saddr_buf;
4e3fd7a0 4277 saddr_buf = rt->rt6i_prefsrc.addr;
930345ea 4278 if (nla_put_in6_addr(skb, RTA_PREFSRC, &saddr_buf))
c78679e8 4279 goto nla_put_failure;
c3968a85
DW
4280 }
4281
4b32b5ad
MKL
4282 memcpy(metrics, dst_metrics_ptr(&rt->dst), sizeof(metrics));
4283 if (rt->rt6i_pmtu)
4284 metrics[RTAX_MTU - 1] = rt->rt6i_pmtu;
4285 if (rtnetlink_put_metrics(skb, metrics) < 0)
2d7202bf
TG
4286 goto nla_put_failure;
4287
c78679e8
DM
4288 if (nla_put_u32(skb, RTA_PRIORITY, rt->rt6i_metric))
4289 goto nla_put_failure;
8253947e 4290
beb1afac
DA
4291 /* For multipath routes, walk the siblings list and add
4292 * each as a nexthop within RTA_MULTIPATH.
4293 */
4294 if (rt->rt6i_nsiblings) {
4295 struct rt6_info *sibling, *next_sibling;
4296 struct nlattr *mp;
4297
4298 mp = nla_nest_start(skb, RTA_MULTIPATH);
4299 if (!mp)
4300 goto nla_put_failure;
4301
4302 if (rt6_add_nexthop(skb, rt) < 0)
4303 goto nla_put_failure;
4304
4305 list_for_each_entry_safe(sibling, next_sibling,
4306 &rt->rt6i_siblings, rt6i_siblings) {
4307 if (rt6_add_nexthop(skb, sibling) < 0)
4308 goto nla_put_failure;
4309 }
4310
4311 nla_nest_end(skb, mp);
4312 } else {
5be083ce 4313 if (rt6_nexthop_info(skb, rt, &rtm->rtm_flags, false) < 0)
beb1afac
DA
4314 goto nla_put_failure;
4315 }
4316
8253947e 4317 expires = (rt->rt6i_flags & RTF_EXPIRES) ? rt->dst.expires - jiffies : 0;
69cdf8f9 4318
87a50699 4319 if (rtnl_put_cacheinfo(skb, &rt->dst, 0, expires, rt->dst.error) < 0)
e3703b3d 4320 goto nla_put_failure;
2d7202bf 4321
c78ba6d6
LR
4322 if (nla_put_u8(skb, RTA_PREF, IPV6_EXTRACT_PREF(rt->rt6i_flags)))
4323 goto nla_put_failure;
4324
19e42e45 4325
053c095a
JB
4326 nlmsg_end(skb, nlh);
4327 return 0;
2d7202bf
TG
4328
4329nla_put_failure:
26932566
PM
4330 nlmsg_cancel(skb, nlh);
4331 return -EMSGSIZE;
1da177e4
LT
4332}
4333
1b43af54 4334int rt6_dump_route(struct rt6_info *rt, void *p_arg)
1da177e4
LT
4335{
4336 struct rt6_rtnl_dump_arg *arg = (struct rt6_rtnl_dump_arg *) p_arg;
1f17e2f2
DA
4337 struct net *net = arg->net;
4338
4339 if (rt == net->ipv6.ip6_null_entry)
4340 return 0;
1da177e4 4341
2d7202bf
TG
4342 if (nlmsg_len(arg->cb->nlh) >= sizeof(struct rtmsg)) {
4343 struct rtmsg *rtm = nlmsg_data(arg->cb->nlh);
f8cfe2ce
DA
4344
4345 /* user wants prefix routes only */
4346 if (rtm->rtm_flags & RTM_F_PREFIX &&
4347 !(rt->rt6i_flags & RTF_PREFIX_RT)) {
4348 /* success since this is not a prefix route */
4349 return 1;
4350 }
4351 }
1da177e4 4352
1f17e2f2 4353 return rt6_fill_node(net,
191cd582 4354 arg->skb, rt, NULL, NULL, 0, RTM_NEWROUTE,
15e47304 4355 NETLINK_CB(arg->cb->skb).portid, arg->cb->nlh->nlmsg_seq,
f8cfe2ce 4356 NLM_F_MULTI);
1da177e4
LT
4357}
4358
c21ef3e3
DA
4359static int inet6_rtm_getroute(struct sk_buff *in_skb, struct nlmsghdr *nlh,
4360 struct netlink_ext_ack *extack)
1da177e4 4361{
3b1e0a65 4362 struct net *net = sock_net(in_skb->sk);
ab364a6f 4363 struct nlattr *tb[RTA_MAX+1];
18c3a61c
RP
4364 int err, iif = 0, oif = 0;
4365 struct dst_entry *dst;
ab364a6f 4366 struct rt6_info *rt;
1da177e4 4367 struct sk_buff *skb;
ab364a6f 4368 struct rtmsg *rtm;
4c9483b2 4369 struct flowi6 fl6;
18c3a61c 4370 bool fibmatch;
1da177e4 4371
fceb6435 4372 err = nlmsg_parse(nlh, sizeof(*rtm), tb, RTA_MAX, rtm_ipv6_policy,
c21ef3e3 4373 extack);
ab364a6f
TG
4374 if (err < 0)
4375 goto errout;
1da177e4 4376
ab364a6f 4377 err = -EINVAL;
4c9483b2 4378 memset(&fl6, 0, sizeof(fl6));
38b7097b
HFS
4379 rtm = nlmsg_data(nlh);
4380 fl6.flowlabel = ip6_make_flowinfo(rtm->rtm_tos, 0);
18c3a61c 4381 fibmatch = !!(rtm->rtm_flags & RTM_F_FIB_MATCH);
1da177e4 4382
ab364a6f
TG
4383 if (tb[RTA_SRC]) {
4384 if (nla_len(tb[RTA_SRC]) < sizeof(struct in6_addr))
4385 goto errout;
4386
4e3fd7a0 4387 fl6.saddr = *(struct in6_addr *)nla_data(tb[RTA_SRC]);
ab364a6f
TG
4388 }
4389
4390 if (tb[RTA_DST]) {
4391 if (nla_len(tb[RTA_DST]) < sizeof(struct in6_addr))
4392 goto errout;
4393
4e3fd7a0 4394 fl6.daddr = *(struct in6_addr *)nla_data(tb[RTA_DST]);
ab364a6f
TG
4395 }
4396
4397 if (tb[RTA_IIF])
4398 iif = nla_get_u32(tb[RTA_IIF]);
4399
4400 if (tb[RTA_OIF])
72331bc0 4401 oif = nla_get_u32(tb[RTA_OIF]);
1da177e4 4402
2e47b291
LC
4403 if (tb[RTA_MARK])
4404 fl6.flowi6_mark = nla_get_u32(tb[RTA_MARK]);
4405
622ec2c9
LC
4406 if (tb[RTA_UID])
4407 fl6.flowi6_uid = make_kuid(current_user_ns(),
4408 nla_get_u32(tb[RTA_UID]));
4409 else
4410 fl6.flowi6_uid = iif ? INVALID_UID : current_uid();
4411
1da177e4
LT
4412 if (iif) {
4413 struct net_device *dev;
72331bc0
SL
4414 int flags = 0;
4415
121622db
FW
4416 rcu_read_lock();
4417
4418 dev = dev_get_by_index_rcu(net, iif);
1da177e4 4419 if (!dev) {
121622db 4420 rcu_read_unlock();
1da177e4 4421 err = -ENODEV;
ab364a6f 4422 goto errout;
1da177e4 4423 }
72331bc0
SL
4424
4425 fl6.flowi6_iif = iif;
4426
4427 if (!ipv6_addr_any(&fl6.saddr))
4428 flags |= RT6_LOOKUP_F_HAS_SADDR;
4429
58acfd71 4430 dst = ip6_route_input_lookup(net, dev, &fl6, flags);
121622db
FW
4431
4432 rcu_read_unlock();
72331bc0
SL
4433 } else {
4434 fl6.flowi6_oif = oif;
4435
58acfd71 4436 dst = ip6_route_output(net, NULL, &fl6);
18c3a61c
RP
4437 }
4438
18c3a61c
RP
4439
4440 rt = container_of(dst, struct rt6_info, dst);
4441 if (rt->dst.error) {
4442 err = rt->dst.error;
4443 ip6_rt_put(rt);
4444 goto errout;
1da177e4
LT
4445 }
4446
9d6acb3b
WC
4447 if (rt == net->ipv6.ip6_null_entry) {
4448 err = rt->dst.error;
4449 ip6_rt_put(rt);
4450 goto errout;
4451 }
4452
fba961ab
DM
4453 if (fibmatch && rt->from) {
4454 struct rt6_info *ort = rt->from;
58acfd71
IS
4455
4456 dst_hold(&ort->dst);
4457 ip6_rt_put(rt);
4458 rt = ort;
4459 }
4460
ab364a6f 4461 skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
38308473 4462 if (!skb) {
94e187c0 4463 ip6_rt_put(rt);
ab364a6f
TG
4464 err = -ENOBUFS;
4465 goto errout;
4466 }
1da177e4 4467
d8d1f30b 4468 skb_dst_set(skb, &rt->dst);
18c3a61c
RP
4469 if (fibmatch)
4470 err = rt6_fill_node(net, skb, rt, NULL, NULL, iif,
4471 RTM_NEWROUTE, NETLINK_CB(in_skb).portid,
4472 nlh->nlmsg_seq, 0);
4473 else
4474 err = rt6_fill_node(net, skb, rt, &fl6.daddr, &fl6.saddr, iif,
4475 RTM_NEWROUTE, NETLINK_CB(in_skb).portid,
4476 nlh->nlmsg_seq, 0);
1da177e4 4477 if (err < 0) {
ab364a6f
TG
4478 kfree_skb(skb);
4479 goto errout;
1da177e4
LT
4480 }
4481
15e47304 4482 err = rtnl_unicast(skb, net, NETLINK_CB(in_skb).portid);
ab364a6f 4483errout:
1da177e4 4484 return err;
1da177e4
LT
4485}
4486
37a1d361
RP
4487void inet6_rt_notify(int event, struct rt6_info *rt, struct nl_info *info,
4488 unsigned int nlm_flags)
1da177e4
LT
4489{
4490 struct sk_buff *skb;
5578689a 4491 struct net *net = info->nl_net;
528c4ceb
DL
4492 u32 seq;
4493 int err;
4494
4495 err = -ENOBUFS;
38308473 4496 seq = info->nlh ? info->nlh->nlmsg_seq : 0;
86872cb5 4497
19e42e45 4498 skb = nlmsg_new(rt6_nlmsg_size(rt), gfp_any());
38308473 4499 if (!skb)
21713ebc
TG
4500 goto errout;
4501
191cd582 4502 err = rt6_fill_node(net, skb, rt, NULL, NULL, 0,
f8cfe2ce 4503 event, info->portid, seq, nlm_flags);
26932566
PM
4504 if (err < 0) {
4505 /* -EMSGSIZE implies BUG in rt6_nlmsg_size() */
4506 WARN_ON(err == -EMSGSIZE);
4507 kfree_skb(skb);
4508 goto errout;
4509 }
15e47304 4510 rtnl_notify(skb, net, info->portid, RTNLGRP_IPV6_ROUTE,
1ce85fe4
PNA
4511 info->nlh, gfp_any());
4512 return;
21713ebc
TG
4513errout:
4514 if (err < 0)
5578689a 4515 rtnl_set_sk_err(net, RTNLGRP_IPV6_ROUTE, err);
1da177e4
LT
4516}
4517
8ed67789 4518static int ip6_route_dev_notify(struct notifier_block *this,
351638e7 4519 unsigned long event, void *ptr)
8ed67789 4520{
351638e7 4521 struct net_device *dev = netdev_notifier_info_to_dev(ptr);
c346dca1 4522 struct net *net = dev_net(dev);
8ed67789 4523
242d3a49
WC
4524 if (!(dev->flags & IFF_LOOPBACK))
4525 return NOTIFY_OK;
4526
4527 if (event == NETDEV_REGISTER) {
d8d1f30b 4528 net->ipv6.ip6_null_entry->dst.dev = dev;
8ed67789
DL
4529 net->ipv6.ip6_null_entry->rt6i_idev = in6_dev_get(dev);
4530#ifdef CONFIG_IPV6_MULTIPLE_TABLES
d8d1f30b 4531 net->ipv6.ip6_prohibit_entry->dst.dev = dev;
8ed67789 4532 net->ipv6.ip6_prohibit_entry->rt6i_idev = in6_dev_get(dev);
d8d1f30b 4533 net->ipv6.ip6_blk_hole_entry->dst.dev = dev;
8ed67789 4534 net->ipv6.ip6_blk_hole_entry->rt6i_idev = in6_dev_get(dev);
242d3a49 4535#endif
76da0704
WC
4536 } else if (event == NETDEV_UNREGISTER &&
4537 dev->reg_state != NETREG_UNREGISTERED) {
4538 /* NETDEV_UNREGISTER could be fired for multiple times by
4539 * netdev_wait_allrefs(). Make sure we only call this once.
4540 */
12d94a80 4541 in6_dev_put_clear(&net->ipv6.ip6_null_entry->rt6i_idev);
242d3a49 4542#ifdef CONFIG_IPV6_MULTIPLE_TABLES
12d94a80
ED
4543 in6_dev_put_clear(&net->ipv6.ip6_prohibit_entry->rt6i_idev);
4544 in6_dev_put_clear(&net->ipv6.ip6_blk_hole_entry->rt6i_idev);
8ed67789
DL
4545#endif
4546 }
4547
4548 return NOTIFY_OK;
4549}
4550
1da177e4
LT
4551/*
4552 * /proc
4553 */
4554
4555#ifdef CONFIG_PROC_FS
4556
33120b30
AD
4557static const struct file_operations ipv6_route_proc_fops = {
4558 .owner = THIS_MODULE,
4559 .open = ipv6_route_open,
4560 .read = seq_read,
4561 .llseek = seq_lseek,
8d2ca1d7 4562 .release = seq_release_net,
33120b30
AD
4563};
4564
1da177e4
LT
4565static int rt6_stats_seq_show(struct seq_file *seq, void *v)
4566{
69ddb805 4567 struct net *net = (struct net *)seq->private;
1da177e4 4568 seq_printf(seq, "%04x %04x %04x %04x %04x %04x %04x\n",
69ddb805
DL
4569 net->ipv6.rt6_stats->fib_nodes,
4570 net->ipv6.rt6_stats->fib_route_nodes,
81eb8447 4571 atomic_read(&net->ipv6.rt6_stats->fib_rt_alloc),
69ddb805
DL
4572 net->ipv6.rt6_stats->fib_rt_entries,
4573 net->ipv6.rt6_stats->fib_rt_cache,
fc66f95c 4574 dst_entries_get_slow(&net->ipv6.ip6_dst_ops),
69ddb805 4575 net->ipv6.rt6_stats->fib_discarded_routes);
1da177e4
LT
4576
4577 return 0;
4578}
4579
4580static int rt6_stats_seq_open(struct inode *inode, struct file *file)
4581{
de05c557 4582 return single_open_net(inode, file, rt6_stats_seq_show);
69ddb805
DL
4583}
4584
9a32144e 4585static const struct file_operations rt6_stats_seq_fops = {
1da177e4
LT
4586 .owner = THIS_MODULE,
4587 .open = rt6_stats_seq_open,
4588 .read = seq_read,
4589 .llseek = seq_lseek,
b6fcbdb4 4590 .release = single_release_net,
1da177e4
LT
4591};
4592#endif /* CONFIG_PROC_FS */
4593
4594#ifdef CONFIG_SYSCTL
4595
1da177e4 4596static
fe2c6338 4597int ipv6_sysctl_rtcache_flush(struct ctl_table *ctl, int write,
1da177e4
LT
4598 void __user *buffer, size_t *lenp, loff_t *ppos)
4599{
c486da34
LAG
4600 struct net *net;
4601 int delay;
4602 if (!write)
1da177e4 4603 return -EINVAL;
c486da34
LAG
4604
4605 net = (struct net *)ctl->extra1;
4606 delay = net->ipv6.sysctl.flush_delay;
4607 proc_dointvec(ctl, write, buffer, lenp, ppos);
2ac3ac8f 4608 fib6_run_gc(delay <= 0 ? 0 : (unsigned long)delay, net, delay > 0);
c486da34 4609 return 0;
1da177e4
LT
4610}
4611
fe2c6338 4612struct ctl_table ipv6_route_table_template[] = {
1ab1457c 4613 {
1da177e4 4614 .procname = "flush",
4990509f 4615 .data = &init_net.ipv6.sysctl.flush_delay,
1da177e4 4616 .maxlen = sizeof(int),
89c8b3a1 4617 .mode = 0200,
6d9f239a 4618 .proc_handler = ipv6_sysctl_rtcache_flush
1da177e4
LT
4619 },
4620 {
1da177e4 4621 .procname = "gc_thresh",
9a7ec3a9 4622 .data = &ip6_dst_ops_template.gc_thresh,
1da177e4
LT
4623 .maxlen = sizeof(int),
4624 .mode = 0644,
6d9f239a 4625 .proc_handler = proc_dointvec,
1da177e4
LT
4626 },
4627 {
1da177e4 4628 .procname = "max_size",
4990509f 4629 .data = &init_net.ipv6.sysctl.ip6_rt_max_size,
1da177e4
LT
4630 .maxlen = sizeof(int),
4631 .mode = 0644,
6d9f239a 4632 .proc_handler = proc_dointvec,
1da177e4
LT
4633 },
4634 {
1da177e4 4635 .procname = "gc_min_interval",
4990509f 4636 .data = &init_net.ipv6.sysctl.ip6_rt_gc_min_interval,
1da177e4
LT
4637 .maxlen = sizeof(int),
4638 .mode = 0644,
6d9f239a 4639 .proc_handler = proc_dointvec_jiffies,
1da177e4
LT
4640 },
4641 {
1da177e4 4642 .procname = "gc_timeout",
4990509f 4643 .data = &init_net.ipv6.sysctl.ip6_rt_gc_timeout,
1da177e4
LT
4644 .maxlen = sizeof(int),
4645 .mode = 0644,
6d9f239a 4646 .proc_handler = proc_dointvec_jiffies,
1da177e4
LT
4647 },
4648 {
1da177e4 4649 .procname = "gc_interval",
4990509f 4650 .data = &init_net.ipv6.sysctl.ip6_rt_gc_interval,
1da177e4
LT
4651 .maxlen = sizeof(int),
4652 .mode = 0644,
6d9f239a 4653 .proc_handler = proc_dointvec_jiffies,
1da177e4
LT
4654 },
4655 {
1da177e4 4656 .procname = "gc_elasticity",
4990509f 4657 .data = &init_net.ipv6.sysctl.ip6_rt_gc_elasticity,
1da177e4
LT
4658 .maxlen = sizeof(int),
4659 .mode = 0644,
f3d3f616 4660 .proc_handler = proc_dointvec,
1da177e4
LT
4661 },
4662 {
1da177e4 4663 .procname = "mtu_expires",
4990509f 4664 .data = &init_net.ipv6.sysctl.ip6_rt_mtu_expires,
1da177e4
LT
4665 .maxlen = sizeof(int),
4666 .mode = 0644,
6d9f239a 4667 .proc_handler = proc_dointvec_jiffies,
1da177e4
LT
4668 },
4669 {
1da177e4 4670 .procname = "min_adv_mss",
4990509f 4671 .data = &init_net.ipv6.sysctl.ip6_rt_min_advmss,
1da177e4
LT
4672 .maxlen = sizeof(int),
4673 .mode = 0644,
f3d3f616 4674 .proc_handler = proc_dointvec,
1da177e4
LT
4675 },
4676 {
1da177e4 4677 .procname = "gc_min_interval_ms",
4990509f 4678 .data = &init_net.ipv6.sysctl.ip6_rt_gc_min_interval,
1da177e4
LT
4679 .maxlen = sizeof(int),
4680 .mode = 0644,
6d9f239a 4681 .proc_handler = proc_dointvec_ms_jiffies,
1da177e4 4682 },
f8572d8f 4683 { }
1da177e4
LT
4684};
4685
2c8c1e72 4686struct ctl_table * __net_init ipv6_route_sysctl_init(struct net *net)
760f2d01
DL
4687{
4688 struct ctl_table *table;
4689
4690 table = kmemdup(ipv6_route_table_template,
4691 sizeof(ipv6_route_table_template),
4692 GFP_KERNEL);
5ee09105
YH
4693
4694 if (table) {
4695 table[0].data = &net->ipv6.sysctl.flush_delay;
c486da34 4696 table[0].extra1 = net;
86393e52 4697 table[1].data = &net->ipv6.ip6_dst_ops.gc_thresh;
5ee09105
YH
4698 table[2].data = &net->ipv6.sysctl.ip6_rt_max_size;
4699 table[3].data = &net->ipv6.sysctl.ip6_rt_gc_min_interval;
4700 table[4].data = &net->ipv6.sysctl.ip6_rt_gc_timeout;
4701 table[5].data = &net->ipv6.sysctl.ip6_rt_gc_interval;
4702 table[6].data = &net->ipv6.sysctl.ip6_rt_gc_elasticity;
4703 table[7].data = &net->ipv6.sysctl.ip6_rt_mtu_expires;
4704 table[8].data = &net->ipv6.sysctl.ip6_rt_min_advmss;
9c69fabe 4705 table[9].data = &net->ipv6.sysctl.ip6_rt_gc_min_interval;
464dc801
EB
4706
4707 /* Don't export sysctls to unprivileged users */
4708 if (net->user_ns != &init_user_ns)
4709 table[0].procname = NULL;
5ee09105
YH
4710 }
4711
760f2d01
DL
4712 return table;
4713}
1da177e4
LT
4714#endif
4715
2c8c1e72 4716static int __net_init ip6_route_net_init(struct net *net)
cdb18761 4717{
633d424b 4718 int ret = -ENOMEM;
8ed67789 4719
86393e52
AD
4720 memcpy(&net->ipv6.ip6_dst_ops, &ip6_dst_ops_template,
4721 sizeof(net->ipv6.ip6_dst_ops));
f2fc6a54 4722
fc66f95c
ED
4723 if (dst_entries_init(&net->ipv6.ip6_dst_ops) < 0)
4724 goto out_ip6_dst_ops;
4725
8ed67789
DL
4726 net->ipv6.ip6_null_entry = kmemdup(&ip6_null_entry_template,
4727 sizeof(*net->ipv6.ip6_null_entry),
4728 GFP_KERNEL);
4729 if (!net->ipv6.ip6_null_entry)
fc66f95c 4730 goto out_ip6_dst_entries;
d8d1f30b 4731 net->ipv6.ip6_null_entry->dst.ops = &net->ipv6.ip6_dst_ops;
62fa8a84
DM
4732 dst_init_metrics(&net->ipv6.ip6_null_entry->dst,
4733 ip6_template_metrics, true);
8ed67789
DL
4734
4735#ifdef CONFIG_IPV6_MULTIPLE_TABLES
feca7d8c 4736 net->ipv6.fib6_has_custom_rules = false;
8ed67789
DL
4737 net->ipv6.ip6_prohibit_entry = kmemdup(&ip6_prohibit_entry_template,
4738 sizeof(*net->ipv6.ip6_prohibit_entry),
4739 GFP_KERNEL);
68fffc67
PZ
4740 if (!net->ipv6.ip6_prohibit_entry)
4741 goto out_ip6_null_entry;
d8d1f30b 4742 net->ipv6.ip6_prohibit_entry->dst.ops = &net->ipv6.ip6_dst_ops;
62fa8a84
DM
4743 dst_init_metrics(&net->ipv6.ip6_prohibit_entry->dst,
4744 ip6_template_metrics, true);
8ed67789
DL
4745
4746 net->ipv6.ip6_blk_hole_entry = kmemdup(&ip6_blk_hole_entry_template,
4747 sizeof(*net->ipv6.ip6_blk_hole_entry),
4748 GFP_KERNEL);
68fffc67
PZ
4749 if (!net->ipv6.ip6_blk_hole_entry)
4750 goto out_ip6_prohibit_entry;
d8d1f30b 4751 net->ipv6.ip6_blk_hole_entry->dst.ops = &net->ipv6.ip6_dst_ops;
62fa8a84
DM
4752 dst_init_metrics(&net->ipv6.ip6_blk_hole_entry->dst,
4753 ip6_template_metrics, true);
8ed67789
DL
4754#endif
4755
b339a47c
PZ
4756 net->ipv6.sysctl.flush_delay = 0;
4757 net->ipv6.sysctl.ip6_rt_max_size = 4096;
4758 net->ipv6.sysctl.ip6_rt_gc_min_interval = HZ / 2;
4759 net->ipv6.sysctl.ip6_rt_gc_timeout = 60*HZ;
4760 net->ipv6.sysctl.ip6_rt_gc_interval = 30*HZ;
4761 net->ipv6.sysctl.ip6_rt_gc_elasticity = 9;
4762 net->ipv6.sysctl.ip6_rt_mtu_expires = 10*60*HZ;
4763 net->ipv6.sysctl.ip6_rt_min_advmss = IPV6_MIN_MTU - 20 - 40;
4764
6891a346
BT
4765 net->ipv6.ip6_rt_gc_expire = 30*HZ;
4766
8ed67789
DL
4767 ret = 0;
4768out:
4769 return ret;
f2fc6a54 4770
68fffc67
PZ
4771#ifdef CONFIG_IPV6_MULTIPLE_TABLES
4772out_ip6_prohibit_entry:
4773 kfree(net->ipv6.ip6_prohibit_entry);
4774out_ip6_null_entry:
4775 kfree(net->ipv6.ip6_null_entry);
4776#endif
fc66f95c
ED
4777out_ip6_dst_entries:
4778 dst_entries_destroy(&net->ipv6.ip6_dst_ops);
f2fc6a54 4779out_ip6_dst_ops:
f2fc6a54 4780 goto out;
cdb18761
DL
4781}
4782
2c8c1e72 4783static void __net_exit ip6_route_net_exit(struct net *net)
cdb18761 4784{
8ed67789
DL
4785 kfree(net->ipv6.ip6_null_entry);
4786#ifdef CONFIG_IPV6_MULTIPLE_TABLES
4787 kfree(net->ipv6.ip6_prohibit_entry);
4788 kfree(net->ipv6.ip6_blk_hole_entry);
4789#endif
41bb78b4 4790 dst_entries_destroy(&net->ipv6.ip6_dst_ops);
cdb18761
DL
4791}
4792
d189634e
TG
4793static int __net_init ip6_route_net_init_late(struct net *net)
4794{
4795#ifdef CONFIG_PROC_FS
d4beaa66
G
4796 proc_create("ipv6_route", 0, net->proc_net, &ipv6_route_proc_fops);
4797 proc_create("rt6_stats", S_IRUGO, net->proc_net, &rt6_stats_seq_fops);
d189634e
TG
4798#endif
4799 return 0;
4800}
4801
4802static void __net_exit ip6_route_net_exit_late(struct net *net)
4803{
4804#ifdef CONFIG_PROC_FS
ece31ffd
G
4805 remove_proc_entry("ipv6_route", net->proc_net);
4806 remove_proc_entry("rt6_stats", net->proc_net);
d189634e
TG
4807#endif
4808}
4809
cdb18761
DL
4810static struct pernet_operations ip6_route_net_ops = {
4811 .init = ip6_route_net_init,
4812 .exit = ip6_route_net_exit,
4813};
4814
c3426b47
DM
4815static int __net_init ipv6_inetpeer_init(struct net *net)
4816{
4817 struct inet_peer_base *bp = kmalloc(sizeof(*bp), GFP_KERNEL);
4818
4819 if (!bp)
4820 return -ENOMEM;
4821 inet_peer_base_init(bp);
4822 net->ipv6.peers = bp;
4823 return 0;
4824}
4825
4826static void __net_exit ipv6_inetpeer_exit(struct net *net)
4827{
4828 struct inet_peer_base *bp = net->ipv6.peers;
4829
4830 net->ipv6.peers = NULL;
56a6b248 4831 inetpeer_invalidate_tree(bp);
c3426b47
DM
4832 kfree(bp);
4833}
4834
2b823f72 4835static struct pernet_operations ipv6_inetpeer_ops = {
c3426b47
DM
4836 .init = ipv6_inetpeer_init,
4837 .exit = ipv6_inetpeer_exit,
4838};
4839
d189634e
TG
4840static struct pernet_operations ip6_route_net_late_ops = {
4841 .init = ip6_route_net_init_late,
4842 .exit = ip6_route_net_exit_late,
4843};
4844
8ed67789
DL
4845static struct notifier_block ip6_route_dev_notifier = {
4846 .notifier_call = ip6_route_dev_notify,
242d3a49 4847 .priority = ADDRCONF_NOTIFY_PRIORITY - 10,
8ed67789
DL
4848};
4849
2f460933
WC
4850void __init ip6_route_init_special_entries(void)
4851{
4852 /* Registering of the loopback is done before this portion of code,
4853 * the loopback reference in rt6_info will not be taken, do it
4854 * manually for init_net */
4855 init_net.ipv6.ip6_null_entry->dst.dev = init_net.loopback_dev;
4856 init_net.ipv6.ip6_null_entry->rt6i_idev = in6_dev_get(init_net.loopback_dev);
4857 #ifdef CONFIG_IPV6_MULTIPLE_TABLES
4858 init_net.ipv6.ip6_prohibit_entry->dst.dev = init_net.loopback_dev;
4859 init_net.ipv6.ip6_prohibit_entry->rt6i_idev = in6_dev_get(init_net.loopback_dev);
4860 init_net.ipv6.ip6_blk_hole_entry->dst.dev = init_net.loopback_dev;
4861 init_net.ipv6.ip6_blk_hole_entry->rt6i_idev = in6_dev_get(init_net.loopback_dev);
4862 #endif
4863}
4864
433d49c3 4865int __init ip6_route_init(void)
1da177e4 4866{
433d49c3 4867 int ret;
8d0b94af 4868 int cpu;
433d49c3 4869
9a7ec3a9
DL
4870 ret = -ENOMEM;
4871 ip6_dst_ops_template.kmem_cachep =
e5d679f3 4872 kmem_cache_create("ip6_dst_cache", sizeof(struct rt6_info), 0,
f845ab6b 4873 SLAB_HWCACHE_ALIGN, NULL);
9a7ec3a9 4874 if (!ip6_dst_ops_template.kmem_cachep)
c19a28e1 4875 goto out;
14e50e57 4876
fc66f95c 4877 ret = dst_entries_init(&ip6_dst_blackhole_ops);
8ed67789 4878 if (ret)
bdb3289f 4879 goto out_kmem_cache;
bdb3289f 4880
c3426b47
DM
4881 ret = register_pernet_subsys(&ipv6_inetpeer_ops);
4882 if (ret)
e8803b6c 4883 goto out_dst_entries;
2a0c451a 4884
7e52b33b
DM
4885 ret = register_pernet_subsys(&ip6_route_net_ops);
4886 if (ret)
4887 goto out_register_inetpeer;
c3426b47 4888
5dc121e9
AE
4889 ip6_dst_blackhole_ops.kmem_cachep = ip6_dst_ops_template.kmem_cachep;
4890
e8803b6c 4891 ret = fib6_init();
433d49c3 4892 if (ret)
8ed67789 4893 goto out_register_subsys;
433d49c3 4894
433d49c3
DL
4895 ret = xfrm6_init();
4896 if (ret)
e8803b6c 4897 goto out_fib6_init;
c35b7e72 4898
433d49c3
DL
4899 ret = fib6_rules_init();
4900 if (ret)
4901 goto xfrm6_init;
7e5449c2 4902
d189634e
TG
4903 ret = register_pernet_subsys(&ip6_route_net_late_ops);
4904 if (ret)
4905 goto fib6_rules_init;
4906
16feebcf
FW
4907 ret = rtnl_register_module(THIS_MODULE, PF_INET6, RTM_NEWROUTE,
4908 inet6_rtm_newroute, NULL, 0);
4909 if (ret < 0)
4910 goto out_register_late_subsys;
4911
4912 ret = rtnl_register_module(THIS_MODULE, PF_INET6, RTM_DELROUTE,
4913 inet6_rtm_delroute, NULL, 0);
4914 if (ret < 0)
4915 goto out_register_late_subsys;
4916
4917 ret = rtnl_register_module(THIS_MODULE, PF_INET6, RTM_GETROUTE,
4918 inet6_rtm_getroute, NULL,
4919 RTNL_FLAG_DOIT_UNLOCKED);
4920 if (ret < 0)
d189634e 4921 goto out_register_late_subsys;
c127ea2c 4922
8ed67789 4923 ret = register_netdevice_notifier(&ip6_route_dev_notifier);
cdb18761 4924 if (ret)
d189634e 4925 goto out_register_late_subsys;
8ed67789 4926
8d0b94af
MKL
4927 for_each_possible_cpu(cpu) {
4928 struct uncached_list *ul = per_cpu_ptr(&rt6_uncached_list, cpu);
4929
4930 INIT_LIST_HEAD(&ul->head);
4931 spin_lock_init(&ul->lock);
4932 }
4933
433d49c3
DL
4934out:
4935 return ret;
4936
d189634e 4937out_register_late_subsys:
16feebcf 4938 rtnl_unregister_all(PF_INET6);
d189634e 4939 unregister_pernet_subsys(&ip6_route_net_late_ops);
433d49c3 4940fib6_rules_init:
433d49c3
DL
4941 fib6_rules_cleanup();
4942xfrm6_init:
433d49c3 4943 xfrm6_fini();
2a0c451a
TG
4944out_fib6_init:
4945 fib6_gc_cleanup();
8ed67789
DL
4946out_register_subsys:
4947 unregister_pernet_subsys(&ip6_route_net_ops);
7e52b33b
DM
4948out_register_inetpeer:
4949 unregister_pernet_subsys(&ipv6_inetpeer_ops);
fc66f95c
ED
4950out_dst_entries:
4951 dst_entries_destroy(&ip6_dst_blackhole_ops);
433d49c3 4952out_kmem_cache:
f2fc6a54 4953 kmem_cache_destroy(ip6_dst_ops_template.kmem_cachep);
433d49c3 4954 goto out;
1da177e4
LT
4955}
4956
4957void ip6_route_cleanup(void)
4958{
8ed67789 4959 unregister_netdevice_notifier(&ip6_route_dev_notifier);
d189634e 4960 unregister_pernet_subsys(&ip6_route_net_late_ops);
101367c2 4961 fib6_rules_cleanup();
1da177e4 4962 xfrm6_fini();
1da177e4 4963 fib6_gc_cleanup();
c3426b47 4964 unregister_pernet_subsys(&ipv6_inetpeer_ops);
8ed67789 4965 unregister_pernet_subsys(&ip6_route_net_ops);
41bb78b4 4966 dst_entries_destroy(&ip6_dst_blackhole_ops);
f2fc6a54 4967 kmem_cache_destroy(ip6_dst_ops_template.kmem_cachep);
1da177e4 4968}