2 * Copyright (c) 2002 Michael Shalayeff. All rights reserved.
3 * Copyright (c) 2003 Ryan McBride. All rights reserved.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
15 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
16 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
17 * IN NO EVENT SHALL THE AUTHOR OR HIS RELATIVES BE LIABLE FOR ANY DIRECT,
18 * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
19 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
20 * SERVICES; LOSS OF MIND, USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
22 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING
23 * IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
24 * THE POSSIBILITY OF SUCH DAMAGE.
27 * $FreeBSD: src/sys/netinet/ip_carp.c,v 1.48 2007/02/02 09:39:09 glebius Exp $
32 #include "opt_inet6.h"
34 #include <sys/param.h>
35 #include <sys/systm.h>
36 #include <sys/kernel.h>
37 #include <sys/in_cksum.h>
38 #include <sys/limits.h>
39 #include <sys/malloc.h>
41 #include <sys/msgport2.h>
45 #include <sys/sockio.h>
46 #include <sys/socket.h>
47 #include <sys/sysctl.h>
48 #include <sys/syslog.h>
49 #include <sys/thread.h>
51 #include <machine/stdarg.h>
52 #include <crypto/sha1.h>
55 #include <net/ethernet.h>
57 #include <net/if_dl.h>
58 #include <net/if_types.h>
59 #include <net/route.h>
60 #include <net/if_clone.h>
61 #include <net/if_var.h>
62 #include <net/ifq_var.h>
63 #include <net/netmsg2.h>
66 #include <netinet/in.h>
67 #include <netinet/in_var.h>
68 #include <netinet/in_systm.h>
69 #include <netinet/ip.h>
70 #include <netinet/ip_var.h>
71 #include <netinet/if_ether.h>
75 #include <netinet/icmp6.h>
76 #include <netinet/ip6.h>
77 #include <netinet6/ip6_var.h>
78 #include <netinet6/scope6_var.h>
79 #include <netinet6/nd6.h>
82 #include <netinet/ip_carp.h>
84 #define CARP_IFNAME "carp"
85 #define CARP_IS_RUNNING(ifp) \
86 (((ifp)->if_flags & (IFF_UP | IFF_RUNNING)) == (IFF_UP | IFF_RUNNING))
89 uint32_t vha_flags
; /* CARP_VHAF_ */
90 struct in_ifaddr
*vha_ia
; /* carp address */
91 struct in_ifaddr
*vha_iaback
; /* backing address */
92 TAILQ_ENTRY(carp_vhaddr
) vha_link
;
94 TAILQ_HEAD(carp_vhaddr_list
, carp_vhaddr
);
98 struct ifnet
*sc_carpdev
; /* parent interface */
99 struct carp_vhaddr_list sc_vha_list
; /* virtual addr list */
101 const struct in_ifaddr
*sc_ia
; /* primary iface address v4 */
102 struct ip_moptions sc_imo
;
105 struct in6_ifaddr
*sc_ia6
; /* primary iface address v6 */
106 struct ip6_moptions sc_im6o
;
108 TAILQ_ENTRY(carp_softc
) sc_list
;
110 enum { INIT
= 0, BACKUP
, MASTER
}
116 int sc_sendad_errors
;
117 #define CARP_SENDAD_MAX_ERRORS 3
118 int sc_sendad_success
;
119 #define CARP_SENDAD_MIN_SUCCESS 3
123 int sc_naddrs
; /* actually used IPv4 vha */
125 int sc_advbase
; /* seconds */
130 #define CARP_HMAC_PAD 64
131 unsigned char sc_key
[CARP_KEY_LEN
];
132 unsigned char sc_pad
[CARP_HMAC_PAD
];
135 struct callout sc_ad_tmo
; /* advertisement timeout */
136 struct callout sc_md_tmo
; /* master down timeout */
137 struct callout sc_md6_tmo
; /* master down timeout */
139 LIST_ENTRY(carp_softc
) sc_next
; /* Interface clue */
142 #define sc_if arpcom.ac_if
145 TAILQ_HEAD(, carp_softc
) vhif_vrs
;
149 struct netmsg_base base
;
150 struct ifnet
*nc_carpdev
;
151 struct carp_softc
*nc_softc
;
156 SYSCTL_DECL(_net_inet_carp
);
158 static int carp_opts
[CARPCTL_MAXID
] = { 0, 1, 0, 1, 0, 0 }; /* XXX for now */
159 SYSCTL_INT(_net_inet_carp
, CARPCTL_ALLOW
, allow
, CTLFLAG_RW
,
160 &carp_opts
[CARPCTL_ALLOW
], 0, "Accept incoming CARP packets");
161 SYSCTL_INT(_net_inet_carp
, CARPCTL_PREEMPT
, preempt
, CTLFLAG_RW
,
162 &carp_opts
[CARPCTL_PREEMPT
], 0, "high-priority backup preemption mode");
163 SYSCTL_INT(_net_inet_carp
, CARPCTL_LOG
, log
, CTLFLAG_RW
,
164 &carp_opts
[CARPCTL_LOG
], 0, "log bad carp packets");
165 SYSCTL_INT(_net_inet_carp
, CARPCTL_ARPBALANCE
, arpbalance
, CTLFLAG_RW
,
166 &carp_opts
[CARPCTL_ARPBALANCE
], 0, "balance arp responses");
168 static int carp_suppress_preempt
= 0;
169 SYSCTL_INT(_net_inet_carp
, OID_AUTO
, suppress_preempt
, CTLFLAG_RD
,
170 &carp_suppress_preempt
, 0, "Preemption is suppressed");
172 static struct carpstats carpstats
;
173 SYSCTL_STRUCT(_net_inet_carp
, CARPCTL_STATS
, stats
, CTLFLAG_RW
,
174 &carpstats
, carpstats
,
175 "CARP statistics (struct carpstats, netinet/ip_carp.h)");
177 #define CARP_LOG(...) do { \
178 if (carp_opts[CARPCTL_LOG] > 0) \
179 log(LOG_INFO, __VA_ARGS__); \
182 #define CARP_DEBUG(...) do { \
183 if (carp_opts[CARPCTL_LOG] > 1) \
184 log(LOG_DEBUG, __VA_ARGS__); \
187 static struct lwkt_token carp_tok
= LWKT_TOKEN_INITIALIZER(carp_token
);
189 static void carp_hmac_prepare(struct carp_softc
*);
190 static void carp_hmac_generate(struct carp_softc
*, uint32_t *,
192 static int carp_hmac_verify(struct carp_softc
*, uint32_t *,
194 static void carp_setroute(struct carp_softc
*, int);
195 static void carp_proto_input_c(struct carp_softc
*, struct mbuf
*,
196 struct carp_header
*, sa_family_t
);
197 static int carp_clone_create(struct if_clone
*, int, caddr_t
);
198 static int carp_clone_destroy(struct ifnet
*);
199 static void carp_detach(struct carp_softc
*, int, boolean_t
);
200 static void carp_prepare_ad(struct carp_softc
*, struct carp_header
*);
201 static void carp_send_ad_all(void);
202 static void carp_send_ad_timeout(void *);
203 static void carp_send_ad(struct carp_softc
*);
204 static void carp_send_arp(struct carp_softc
*);
205 static void carp_master_down_timeout(void *);
206 static void carp_master_down(struct carp_softc
*);
207 static void carp_setrun(struct carp_softc
*, sa_family_t
);
208 static void carp_set_state(struct carp_softc
*, int);
209 static struct ifnet
*carp_forus(struct carp_if
*, const uint8_t *);
211 static void carp_init(void *);
212 static int carp_ioctl(struct ifnet
*, u_long
, caddr_t
, struct ucred
*);
213 static int carp_output(struct ifnet
*, struct mbuf
*, struct sockaddr
*,
215 static void carp_start(struct ifnet
*);
216 static void carp_serialize(struct ifnet
*, enum ifnet_serialize
);
217 static void carp_deserialize(struct ifnet
*, enum ifnet_serialize
);
218 static int carp_tryserialize(struct ifnet
*, enum ifnet_serialize
);
220 static void carp_serialize_assert(struct ifnet
*, enum ifnet_serialize
,
224 static void carp_multicast_cleanup(struct carp_softc
*);
225 static void carp_add_addr(struct carp_softc
*, struct ifaddr
*);
226 static void carp_del_addr(struct carp_softc
*, struct ifaddr
*);
227 static void carp_config_addr(struct carp_softc
*, struct ifaddr
*);
228 static void carp_link_addrs(struct carp_softc
*, struct ifnet
*,
230 static void carp_unlink_addrs(struct carp_softc
*, struct ifnet
*,
232 static void carp_update_addrs(struct carp_softc
*, struct ifaddr
*);
234 static int carp_config_vhaddr(struct carp_softc
*, struct carp_vhaddr
*,
236 static int carp_activate_vhaddr(struct carp_softc
*, struct carp_vhaddr
*,
237 struct ifnet
*, struct in_ifaddr
*, int);
238 static void carp_deactivate_vhaddr(struct carp_softc
*,
239 struct carp_vhaddr
*, boolean_t
);
240 static int carp_addroute_vhaddr(struct carp_softc
*, struct carp_vhaddr
*);
241 static void carp_delroute_vhaddr(struct carp_softc
*, struct carp_vhaddr
*,
244 static void carp_sc_state(struct carp_softc
*);
246 static void carp_send_na(struct carp_softc
*);
248 static int carp_set_addr6(struct carp_softc
*, struct sockaddr_in6
*);
249 static int carp_del_addr6(struct carp_softc
*, struct sockaddr_in6
*);
251 static void carp_multicast6_cleanup(struct carp_softc
*);
253 static void carp_stop(struct carp_softc
*, int);
254 static void carp_suspend(struct carp_softc
*, int);
255 static void carp_ioctl_stop(struct carp_softc
*);
256 static int carp_ioctl_setvh(struct carp_softc
*, void *, struct ucred
*);
257 static int carp_ioctl_getvh(struct carp_softc
*, void *, struct ucred
*);
258 static int carp_ioctl_getdevname(struct carp_softc
*, struct ifdrv
*);
259 static int carp_ioctl_getvhaddr(struct carp_softc
*, struct ifdrv
*);
261 static void carp_ifaddr(void *, struct ifnet
*, enum ifaddr_event
,
263 static void carp_ifdetach(void *, struct ifnet
*);
265 static void carp_ifdetach_dispatch(netmsg_t
);
266 static void carp_clone_destroy_dispatch(netmsg_t
);
267 static void carp_init_dispatch(netmsg_t
);
268 static void carp_ioctl_stop_dispatch(netmsg_t
);
269 static void carp_ioctl_setvh_dispatch(netmsg_t
);
270 static void carp_ioctl_getvh_dispatch(netmsg_t
);
271 static void carp_ioctl_getdevname_dispatch(netmsg_t
);
272 static void carp_ioctl_getvhaddr_dispatch(netmsg_t
);
274 static MALLOC_DEFINE(M_CARP
, "CARP", "CARP interfaces");
276 static LIST_HEAD(, carp_softc
) carpif_list
;
278 static struct if_clone carp_cloner
=
279 IF_CLONE_INITIALIZER(CARP_IFNAME
, carp_clone_create
, carp_clone_destroy
,
282 static uint8_t carp_etheraddr
[ETHER_ADDR_LEN
] = { 0, 0, 0x5e, 0, 1, 0 };
284 static eventhandler_tag carp_ifdetach_event
;
285 static eventhandler_tag carp_ifaddr_event
;
288 carp_insert_vhaddr(struct carp_softc
*sc
, struct carp_vhaddr
*vha_new
)
290 struct carp_vhaddr
*vha
;
291 u_long new_addr
, addr
;
293 KKASSERT((vha_new
->vha_flags
& CARP_VHAF_ONLIST
) == 0);
296 * Virtual address list is sorted; smaller one first
298 new_addr
= ntohl(vha_new
->vha_ia
->ia_addr
.sin_addr
.s_addr
);
300 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
301 addr
= ntohl(vha
->vha_ia
->ia_addr
.sin_addr
.s_addr
);
307 TAILQ_INSERT_TAIL(&sc
->sc_vha_list
, vha_new
, vha_link
);
309 TAILQ_INSERT_BEFORE(vha
, vha_new
, vha_link
);
310 vha_new
->vha_flags
|= CARP_VHAF_ONLIST
;
314 carp_remove_vhaddr(struct carp_softc
*sc
, struct carp_vhaddr
*vha
)
316 KKASSERT(vha
->vha_flags
& CARP_VHAF_ONLIST
);
317 vha
->vha_flags
&= ~CARP_VHAF_ONLIST
;
318 TAILQ_REMOVE(&sc
->sc_vha_list
, vha
, vha_link
);
322 carp_hmac_prepare(struct carp_softc
*sc
)
324 uint8_t version
= CARP_VERSION
, type
= CARP_ADVERTISEMENT
;
325 uint8_t vhid
= sc
->sc_vhid
& 0xff;
328 struct ifaddr_container
*ifac
;
332 struct carp_vhaddr
*vha
;
335 /* XXX: possible race here */
337 /* compute ipad from key */
338 bzero(sc
->sc_pad
, sizeof(sc
->sc_pad
));
339 bcopy(sc
->sc_key
, sc
->sc_pad
, sizeof(sc
->sc_key
));
340 for (i
= 0; i
< sizeof(sc
->sc_pad
); i
++)
341 sc
->sc_pad
[i
] ^= 0x36;
343 /* precompute first part of inner hash */
344 SHA1Init(&sc
->sc_sha1
);
345 SHA1Update(&sc
->sc_sha1
, sc
->sc_pad
, sizeof(sc
->sc_pad
));
346 SHA1Update(&sc
->sc_sha1
, (void *)&version
, sizeof(version
));
347 SHA1Update(&sc
->sc_sha1
, (void *)&type
, sizeof(type
));
348 SHA1Update(&sc
->sc_sha1
, (void *)&vhid
, sizeof(vhid
));
350 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
351 SHA1Update(&sc
->sc_sha1
,
352 (const uint8_t *)&vha
->vha_ia
->ia_addr
.sin_addr
,
353 sizeof(struct in_addr
));
357 TAILQ_FOREACH(ifac
, &sc
->sc_if
.if_addrheads
[mycpuid
], ifa_link
) {
358 struct ifaddr
*ifa
= ifac
->ifa
;
360 if (ifa
->ifa_addr
->sa_family
== AF_INET6
) {
361 in6
= ifatoia6(ifa
)->ia_addr
.sin6_addr
;
362 in6_clearscope(&in6
);
363 SHA1Update(&sc
->sc_sha1
, (void *)&in6
, sizeof(in6
));
368 /* convert ipad to opad */
369 for (i
= 0; i
< sizeof(sc
->sc_pad
); i
++)
370 sc
->sc_pad
[i
] ^= 0x36 ^ 0x5c;
374 carp_hmac_generate(struct carp_softc
*sc
, uint32_t counter
[2],
375 unsigned char md
[20])
379 /* fetch first half of inner hash */
380 bcopy(&sc
->sc_sha1
, &sha1ctx
, sizeof(sha1ctx
));
382 SHA1Update(&sha1ctx
, (void *)counter
, sizeof(sc
->sc_counter
));
383 SHA1Final(md
, &sha1ctx
);
387 SHA1Update(&sha1ctx
, sc
->sc_pad
, sizeof(sc
->sc_pad
));
388 SHA1Update(&sha1ctx
, md
, 20);
389 SHA1Final(md
, &sha1ctx
);
393 carp_hmac_verify(struct carp_softc
*sc
, uint32_t counter
[2],
394 unsigned char md
[20])
396 unsigned char md2
[20];
398 carp_hmac_generate(sc
, counter
, md2
);
399 return (bcmp(md
, md2
, sizeof(md2
)));
403 carp_setroute(struct carp_softc
*sc
, int cmd
)
406 struct ifaddr_container
*ifac
;
408 struct carp_vhaddr
*vha
;
410 KKASSERT(cmd
== RTM_DELETE
|| cmd
== RTM_ADD
);
412 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
413 if (vha
->vha_iaback
== NULL
)
415 if (cmd
== RTM_DELETE
)
416 carp_delroute_vhaddr(sc
, vha
, FALSE
);
418 carp_addroute_vhaddr(sc
, vha
);
422 TAILQ_FOREACH(ifac
, &sc
->sc_if
.if_addrheads
[mycpuid
], ifa_link
) {
423 struct ifaddr
*ifa
= ifac
->ifa
;
425 if (ifa
->ifa_addr
->sa_family
== AF_INET6
) {
436 carp_clone_create(struct if_clone
*ifc
, int unit
, caddr_t param __unused
)
438 struct carp_softc
*sc
;
441 sc
= kmalloc(sizeof(*sc
), M_CARP
, M_WAITOK
| M_ZERO
);
445 sc
->sc_advbase
= CARP_DFLTINTV
;
446 sc
->sc_vhid
= -1; /* required setting */
448 sc
->sc_init_counter
= 1;
452 TAILQ_INIT(&sc
->sc_vha_list
);
455 sc
->sc_im6o
.im6o_multicast_hlim
= CARP_DFLTTL
;
458 callout_init_mp(&sc
->sc_ad_tmo
);
459 callout_init_mp(&sc
->sc_md_tmo
);
460 callout_init_mp(&sc
->sc_md6_tmo
);
462 if_initname(ifp
, CARP_IFNAME
, unit
);
464 ifp
->if_flags
= IFF_BROADCAST
| IFF_SIMPLEX
| IFF_MULTICAST
;
465 ifp
->if_init
= carp_init
;
466 ifp
->if_ioctl
= carp_ioctl
;
467 ifp
->if_start
= carp_start
;
468 ifp
->if_serialize
= carp_serialize
;
469 ifp
->if_deserialize
= carp_deserialize
;
470 ifp
->if_tryserialize
= carp_tryserialize
;
472 ifp
->if_serialize_assert
= carp_serialize_assert
;
474 ifq_set_maxlen(&ifp
->if_snd
, ifqmaxlen
);
475 ifq_set_ready(&ifp
->if_snd
);
477 ether_ifattach(ifp
, carp_etheraddr
, NULL
);
479 ifp
->if_type
= IFT_CARP
;
480 ifp
->if_output
= carp_output
;
483 LIST_INSERT_HEAD(&carpif_list
, sc
, sc_next
);
490 carp_clone_destroy_dispatch(netmsg_t msg
)
492 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
493 struct carp_softc
*sc
= cmsg
->nc_softc
;
498 carp_detach(sc
, 1, FALSE
);
502 lwkt_replymsg(&cmsg
->base
.lmsg
, 0);
506 carp_clone_destroy(struct ifnet
*ifp
)
508 struct carp_softc
*sc
= ifp
->if_softc
;
509 struct netmsg_carp cmsg
;
511 bzero(&cmsg
, sizeof(cmsg
));
512 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
513 carp_clone_destroy_dispatch
);
516 lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
519 LIST_REMOVE(sc
, sc_next
);
525 KASSERT(sc
->sc_naddrs
== 0, ("certain inet address is still active\n"));
532 carp_detach(struct carp_softc
*sc
, int detach
, boolean_t del_iaback
)
536 carp_suspend(sc
, detach
);
538 carp_multicast_cleanup(sc
);
540 carp_multicast6_cleanup(sc
);
543 if (!sc
->sc_dead
&& detach
) {
544 struct carp_vhaddr
*vha
;
546 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
)
547 carp_deactivate_vhaddr(sc
, vha
, del_iaback
);
548 KKASSERT(sc
->sc_naddrs
== 0);
551 if (sc
->sc_carpdev
!= NULL
) {
552 cif
= sc
->sc_carpdev
->if_carp
;
553 TAILQ_REMOVE(&cif
->vhif_vrs
, sc
, sc_list
);
554 if (TAILQ_EMPTY(&cif
->vhif_vrs
)) {
555 ifpromisc(sc
->sc_carpdev
, 0);
556 sc
->sc_carpdev
->if_carp
= NULL
;
559 sc
->sc_carpdev
= NULL
;
565 carp_ifdetach_dispatch(netmsg_t msg
)
567 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
568 struct ifnet
*ifp
= cmsg
->nc_carpdev
;
569 struct carp_if
*cif
= ifp
->if_carp
;
570 struct carp_softc
*sc
;
574 while (ifp
->if_carp
&&
575 (sc
= TAILQ_FIRST(&cif
->vhif_vrs
)) != NULL
)
576 carp_detach(sc
, 1, TRUE
);
580 lwkt_replymsg(&cmsg
->base
.lmsg
, 0);
583 /* Detach an interface from the carp. */
585 carp_ifdetach(void *arg __unused
, struct ifnet
*ifp
)
587 struct netmsg_carp cmsg
;
589 ASSERT_IFNET_NOT_SERIALIZED_ALL(ifp
);
591 bzero(&cmsg
, sizeof(cmsg
));
592 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
593 carp_ifdetach_dispatch
);
594 cmsg
.nc_carpdev
= ifp
;
596 lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
600 * process input packet.
601 * we have rearranged checks order compared to the rfc,
602 * but it seems more efficient this way or not possible otherwise.
605 carp_proto_input(struct mbuf
**mp
, int *offp
, int proto
)
607 struct mbuf
*m
= *mp
;
608 struct ip
*ip
= mtod(m
, struct ip
*);
609 struct ifnet
*ifp
= m
->m_pkthdr
.rcvif
;
610 struct carp_header
*ch
;
611 struct carp_softc
*sc
;
619 carpstats
.carps_ipackets
++;
621 if (!carp_opts
[CARPCTL_ALLOW
]) {
626 /* Check if received on a valid carp interface */
627 if (ifp
->if_type
!= IFT_CARP
) {
628 carpstats
.carps_badif
++;
629 CARP_LOG("carp_proto_input: packet received on non-carp "
630 "interface: %s\n", ifp
->if_xname
);
635 if (!CARP_IS_RUNNING(ifp
)) {
636 carpstats
.carps_badif
++;
637 CARP_LOG("carp_proto_input: packet received on stopped carp "
638 "interface: %s\n", ifp
->if_xname
);
644 if (sc
->sc_carpdev
== NULL
) {
645 carpstats
.carps_badif
++;
646 CARP_LOG("carp_proto_input: packet received on defunc carp "
647 "interface: %s\n", ifp
->if_xname
);
652 if (!IN_MULTICAST(ntohl(ip
->ip_dst
.s_addr
))) {
653 carpstats
.carps_badif
++;
654 CARP_LOG("carp_proto_input: non-mcast packet on "
655 "interface: %s\n", ifp
->if_xname
);
660 /* Verify that the IP TTL is CARP_DFLTTL. */
661 if (ip
->ip_ttl
!= CARP_DFLTTL
) {
662 carpstats
.carps_badttl
++;
663 CARP_LOG("carp_proto_input: received ttl %d != %d on %s\n",
664 ip
->ip_ttl
, CARP_DFLTTL
, ifp
->if_xname
);
669 /* Minimal CARP packet size */
670 len
= iphlen
+ sizeof(*ch
);
673 * Verify that the received packet length is
674 * not less than the CARP header
676 if (m
->m_pkthdr
.len
< len
) {
677 carpstats
.carps_badlen
++;
678 CARP_LOG("packet too short %d on %s\n", m
->m_pkthdr
.len
,
684 /* Make sure that CARP header is contiguous */
685 if (len
> m
->m_len
) {
686 m
= m_pullup(m
, len
);
688 carpstats
.carps_hdrops
++;
689 CARP_LOG("carp_proto_input: m_pullup failed\n");
692 ip
= mtod(m
, struct ip
*);
694 ch
= (struct carp_header
*)((uint8_t *)ip
+ iphlen
);
696 /* Verify the CARP checksum */
697 if (in_cksum_skip(m
, len
, iphlen
)) {
698 carpstats
.carps_badsum
++;
699 CARP_LOG("carp_proto_input: checksum failed on %s\n",
704 carp_proto_input_c(sc
, m
, ch
, AF_INET
);
707 return(IPPROTO_DONE
);
712 carp6_proto_input(struct mbuf
**mp
, int *offp
, int proto
)
714 struct mbuf
*m
= *mp
;
715 struct ip6_hdr
*ip6
= mtod(m
, struct ip6_hdr
*);
716 struct ifnet
*ifp
= m
->m_pkthdr
.rcvif
;
717 struct carp_header
*ch
;
718 struct carp_softc
*sc
;
723 carpstats
.carps_ipackets6
++;
725 if (!carp_opts
[CARPCTL_ALLOW
]) {
730 /* check if received on a valid carp interface */
731 if (ifp
->if_type
!= IFT_CARP
) {
732 carpstats
.carps_badif
++;
733 CARP_LOG("carp6_proto_input: packet received on non-carp "
734 "interface: %s\n", ifp
->if_xname
);
739 if (!CARP_IS_RUNNING(ifp
)) {
740 carpstats
.carps_badif
++;
741 CARP_LOG("carp_proto_input: packet received on stopped carp "
742 "interface: %s\n", ifp
->if_xname
);
748 if (sc
->sc_carpdev
== NULL
) {
749 carpstats
.carps_badif
++;
750 CARP_LOG("carp6_proto_input: packet received on defunc-carp "
751 "interface: %s\n", ifp
->if_xname
);
756 /* verify that the IP TTL is 255 */
757 if (ip6
->ip6_hlim
!= CARP_DFLTTL
) {
758 carpstats
.carps_badttl
++;
759 CARP_LOG("carp6_proto_input: received ttl %d != 255 on %s\n",
760 ip6
->ip6_hlim
, ifp
->if_xname
);
765 /* verify that we have a complete carp packet */
767 IP6_EXTHDR_GET(ch
, struct carp_header
*, m
, *offp
, sizeof(*ch
));
769 carpstats
.carps_badlen
++;
770 CARP_LOG("carp6_proto_input: packet size %u too small\n", len
);
774 /* verify the CARP checksum */
775 if (in_cksum_range(m
, 0, *offp
, sizeof(*ch
))) {
776 carpstats
.carps_badsum
++;
777 CARP_LOG("carp6_proto_input: checksum failed, on %s\n",
783 carp_proto_input_c(sc
, m
, ch
, AF_INET6
);
786 return (IPPROTO_DONE
);
791 carp_proto_input_c(struct carp_softc
*sc
, struct mbuf
*m
,
792 struct carp_header
*ch
, sa_family_t af
)
795 uint64_t tmp_counter
;
796 struct timeval sc_tv
, ch_tv
;
798 if (sc
->sc_vhid
!= ch
->carp_vhid
) {
800 * CARP uses multicast, however, multicast packets
801 * are tapped to all CARP interfaces on the physical
802 * interface receiving the CARP packets, so we don't
803 * update any stats here.
810 /* verify the CARP version. */
811 if (ch
->carp_version
!= CARP_VERSION
) {
812 carpstats
.carps_badver
++;
813 CARP_LOG("%s; invalid version %d\n", cifp
->if_xname
,
819 /* verify the hash */
820 if (carp_hmac_verify(sc
, ch
->carp_counter
, ch
->carp_md
)) {
821 carpstats
.carps_badauth
++;
822 CARP_LOG("%s: incorrect hash\n", cifp
->if_xname
);
827 tmp_counter
= ntohl(ch
->carp_counter
[0]);
828 tmp_counter
= tmp_counter
<<32;
829 tmp_counter
+= ntohl(ch
->carp_counter
[1]);
831 /* XXX Replay protection goes here */
833 sc
->sc_init_counter
= 0;
834 sc
->sc_counter
= tmp_counter
;
836 sc_tv
.tv_sec
= sc
->sc_advbase
;
837 if (carp_suppress_preempt
&& sc
->sc_advskew
< 240)
838 sc_tv
.tv_usec
= 240 * 1000000 / 256;
840 sc_tv
.tv_usec
= sc
->sc_advskew
* 1000000 / 256;
841 ch_tv
.tv_sec
= ch
->carp_advbase
;
842 ch_tv
.tv_usec
= ch
->carp_advskew
* 1000000 / 256;
844 switch (sc
->sc_state
) {
850 * If we receive an advertisement from a master who's going to
851 * be more frequent than us, go into BACKUP state.
853 if (timevalcmp(&sc_tv
, &ch_tv
, >) ||
854 timevalcmp(&sc_tv
, &ch_tv
, ==)) {
855 callout_stop(&sc
->sc_ad_tmo
);
856 CARP_DEBUG("%s: MASTER -> BACKUP "
857 "(more frequent advertisement received)\n",
859 carp_set_state(sc
, BACKUP
);
861 carp_setroute(sc
, RTM_DELETE
);
867 * If we're pre-empting masters who advertise slower than us,
868 * and this one claims to be slower, treat him as down.
870 if (carp_opts
[CARPCTL_PREEMPT
] &&
871 timevalcmp(&sc_tv
, &ch_tv
, <)) {
872 CARP_DEBUG("%s: BACKUP -> MASTER "
873 "(preempting a slower master)\n", cifp
->if_xname
);
874 carp_master_down(sc
);
879 * If the master is going to advertise at such a low frequency
880 * that he's guaranteed to time out, we'd might as well just
881 * treat him as timed out now.
883 sc_tv
.tv_sec
= sc
->sc_advbase
* 3;
884 if (timevalcmp(&sc_tv
, &ch_tv
, <)) {
885 CARP_DEBUG("%s: BACKUP -> MASTER (master timed out)\n",
887 carp_master_down(sc
);
892 * Otherwise, we reset the counter and wait for the next
902 carp_input(void *v
, struct mbuf
*m
)
904 struct carp_if
*cif
= v
;
905 struct ether_header
*eh
;
906 struct carp_softc
*sc
;
909 ASSERT_LWKT_TOKEN_HELD(&carp_tok
);
911 eh
= mtod(m
, struct ether_header
*);
913 ifp
= carp_forus(cif
, eh
->ether_dhost
);
915 ether_reinput_oncpu(ifp
, m
, REINPUT_RUNBPF
);
919 if ((m
->m_flags
& (M_BCAST
| M_MCAST
)) == 0)
923 * XXX Should really check the list of multicast addresses
924 * for each CARP interface _before_ copying.
926 TAILQ_FOREACH(sc
, &cif
->vhif_vrs
, sc_list
) {
929 if ((sc
->sc_if
.if_flags
& IFF_UP
) == 0)
932 m0
= m_dup(m
, MB_DONTWAIT
);
936 ether_reinput_oncpu(&sc
->sc_if
, m0
, REINPUT_RUNBPF
);
942 carp_prepare_ad(struct carp_softc
*sc
, struct carp_header
*ch
)
944 if (sc
->sc_init_counter
) {
945 /* this could also be seconds since unix epoch */
946 sc
->sc_counter
= karc4random();
947 sc
->sc_counter
= sc
->sc_counter
<< 32;
948 sc
->sc_counter
+= karc4random();
953 ch
->carp_counter
[0] = htonl((sc
->sc_counter
>> 32) & 0xffffffff);
954 ch
->carp_counter
[1] = htonl(sc
->sc_counter
& 0xffffffff);
956 carp_hmac_generate(sc
, ch
->carp_counter
, ch
->carp_md
);
960 carp_send_ad_all(void)
962 struct carp_softc
*sc
;
964 LIST_FOREACH(sc
, &carpif_list
, sc_next
) {
965 if (sc
->sc_carpdev
== NULL
)
968 if (CARP_IS_RUNNING(&sc
->sc_if
) && sc
->sc_state
== MASTER
)
974 carp_send_ad_timeout(void *xsc
)
982 carp_send_ad(struct carp_softc
*sc
)
984 struct ifnet
*cifp
= &sc
->sc_if
;
985 struct carp_header ch
;
987 struct carp_header
*ch_ptr
;
989 int len
, advbase
, advskew
;
991 if (!CARP_IS_RUNNING(cifp
)) {
996 advbase
= sc
->sc_advbase
;
997 if (!carp_suppress_preempt
|| sc
->sc_advskew
> 240)
998 advskew
= sc
->sc_advskew
;
1001 tv
.tv_sec
= advbase
;
1002 tv
.tv_usec
= advskew
* 1000000 / 256;
1005 ch
.carp_version
= CARP_VERSION
;
1006 ch
.carp_type
= CARP_ADVERTISEMENT
;
1007 ch
.carp_vhid
= sc
->sc_vhid
;
1008 ch
.carp_advbase
= advbase
;
1009 ch
.carp_advskew
= advskew
;
1010 ch
.carp_authlen
= 7; /* XXX DEFINE */
1011 ch
.carp_pad1
= 0; /* must be zero */
1015 if (sc
->sc_ia
!= NULL
) {
1018 MGETHDR(m
, MB_DONTWAIT
, MT_HEADER
);
1021 carpstats
.carps_onomem
++;
1022 /* XXX maybe less ? */
1023 if (advbase
!= 255 || advskew
!= 255)
1024 callout_reset(&sc
->sc_ad_tmo
, tvtohz_high(&tv
),
1025 carp_send_ad_timeout
, sc
);
1028 len
= sizeof(*ip
) + sizeof(ch
);
1029 m
->m_pkthdr
.len
= len
;
1030 m
->m_pkthdr
.rcvif
= NULL
;
1032 MH_ALIGN(m
, m
->m_len
);
1033 m
->m_flags
|= M_MCAST
;
1034 ip
= mtod(m
, struct ip
*);
1035 ip
->ip_v
= IPVERSION
;
1036 ip
->ip_hl
= sizeof(*ip
) >> 2;
1037 ip
->ip_tos
= IPTOS_LOWDELAY
;
1039 ip
->ip_id
= ip_newid();
1041 ip
->ip_ttl
= CARP_DFLTTL
;
1042 ip
->ip_p
= IPPROTO_CARP
;
1044 ip
->ip_src
= sc
->sc_ia
->ia_addr
.sin_addr
;
1045 ip
->ip_dst
.s_addr
= htonl(INADDR_CARP_GROUP
);
1047 ch_ptr
= (struct carp_header
*)(&ip
[1]);
1048 bcopy(&ch
, ch_ptr
, sizeof(ch
));
1049 carp_prepare_ad(sc
, ch_ptr
);
1050 ch_ptr
->carp_cksum
= in_cksum_skip(m
, len
, sizeof(*ip
));
1052 getmicrotime(&cifp
->if_lastchange
);
1053 cifp
->if_opackets
++;
1054 cifp
->if_obytes
+= len
;
1055 carpstats
.carps_opackets
++;
1057 if (ip_output(m
, NULL
, NULL
, IP_RAWOUTPUT
, &sc
->sc_imo
, NULL
)) {
1059 if (sc
->sc_sendad_errors
< INT_MAX
)
1060 sc
->sc_sendad_errors
++;
1061 if (sc
->sc_sendad_errors
== CARP_SENDAD_MAX_ERRORS
) {
1062 carp_suppress_preempt
++;
1063 if (carp_suppress_preempt
== 1) {
1067 sc
->sc_sendad_success
= 0;
1069 if (sc
->sc_sendad_errors
>= CARP_SENDAD_MAX_ERRORS
) {
1070 if (++sc
->sc_sendad_success
>=
1071 CARP_SENDAD_MIN_SUCCESS
) {
1072 carp_suppress_preempt
--;
1073 sc
->sc_sendad_errors
= 0;
1076 sc
->sc_sendad_errors
= 0;
1083 struct ip6_hdr
*ip6
;
1085 MGETHDR(m
, MB_DONTWAIT
, MT_HEADER
);
1088 carpstats
.carps_onomem
++;
1089 /* XXX maybe less ? */
1090 if (advbase
!= 255 || advskew
!= 255)
1091 callout_reset(&sc
->sc_ad_tmo
, tvtohz_high(&tv
),
1092 carp_send_ad_timeout
, sc
);
1095 len
= sizeof(*ip6
) + sizeof(ch
);
1096 m
->m_pkthdr
.len
= len
;
1097 m
->m_pkthdr
.rcvif
= NULL
;
1099 MH_ALIGN(m
, m
->m_len
);
1100 m
->m_flags
|= M_MCAST
;
1101 ip6
= mtod(m
, struct ip6_hdr
*);
1102 bzero(ip6
, sizeof(*ip6
));
1103 ip6
->ip6_vfc
|= IPV6_VERSION
;
1104 ip6
->ip6_hlim
= CARP_DFLTTL
;
1105 ip6
->ip6_nxt
= IPPROTO_CARP
;
1106 bcopy(&sc
->sc_ia6
->ia_addr
.sin6_addr
, &ip6
->ip6_src
,
1107 sizeof(struct in6_addr
));
1108 /* set the multicast destination */
1110 ip6
->ip6_dst
.s6_addr16
[0] = htons(0xff02);
1111 ip6
->ip6_dst
.s6_addr8
[15] = 0x12;
1112 if (in6_setscope(&ip6
->ip6_dst
, sc
->sc_carpdev
, NULL
) != 0) {
1115 CARP_LOG("%s: in6_setscope failed\n", __func__
);
1119 ch_ptr
= (struct carp_header
*)(&ip6
[1]);
1120 bcopy(&ch
, ch_ptr
, sizeof(ch
));
1121 carp_prepare_ad(sc
, ch_ptr
);
1122 ch_ptr
->carp_cksum
= in_cksum_skip(m
, len
, sizeof(*ip6
));
1124 getmicrotime(&cifp
->if_lastchange
);
1125 cifp
->if_opackets
++;
1126 cifp
->if_obytes
+= len
;
1127 carpstats
.carps_opackets6
++;
1129 if (ip6_output(m
, NULL
, NULL
, 0, &sc
->sc_im6o
, NULL
, NULL
)) {
1131 if (sc
->sc_sendad_errors
< INT_MAX
)
1132 sc
->sc_sendad_errors
++;
1133 if (sc
->sc_sendad_errors
== CARP_SENDAD_MAX_ERRORS
) {
1134 carp_suppress_preempt
++;
1135 if (carp_suppress_preempt
== 1) {
1139 sc
->sc_sendad_success
= 0;
1141 if (sc
->sc_sendad_errors
>= CARP_SENDAD_MAX_ERRORS
) {
1142 if (++sc
->sc_sendad_success
>=
1143 CARP_SENDAD_MIN_SUCCESS
) {
1144 carp_suppress_preempt
--;
1145 sc
->sc_sendad_errors
= 0;
1148 sc
->sc_sendad_errors
= 0;
1154 if (advbase
!= 255 || advskew
!= 255)
1155 callout_reset(&sc
->sc_ad_tmo
, tvtohz_high(&tv
),
1156 carp_send_ad_timeout
, sc
);
1160 * Broadcast a gratuitous ARP request containing
1161 * the virtual router MAC address for each IP address
1162 * associated with the virtual router.
1165 carp_send_arp(struct carp_softc
*sc
)
1167 const struct carp_vhaddr
*vha
;
1169 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
1170 if (vha
->vha_iaback
== NULL
)
1172 arp_gratuitous(&sc
->sc_if
, &vha
->vha_ia
->ia_ifa
);
1178 carp_send_na(struct carp_softc
*sc
)
1180 struct ifaddr_container
*ifac
;
1181 struct in6_addr
*in6
;
1182 static struct in6_addr mcast
= IN6ADDR_LINKLOCAL_ALLNODES_INIT
;
1184 TAILQ_FOREACH(ifac
, &sc
->sc_if
.if_addrheads
[mycpuid
], ifa_link
) {
1185 struct ifaddr
*ifa
= ifac
->ifa
;
1187 if (ifa
->ifa_addr
->sa_family
!= AF_INET6
)
1190 in6
= &ifatoia6(ifa
)->ia_addr
.sin6_addr
;
1191 nd6_na_output(sc
->sc_carpdev
, &mcast
, in6
,
1192 ND_NA_FLAG_OVERRIDE
, 1, NULL
);
1193 DELAY(1000); /* XXX */
1198 static __inline
const struct carp_vhaddr
*
1199 carp_find_addr(const struct carp_softc
*sc
, const struct in_addr
*addr
)
1201 struct carp_vhaddr
*vha
;
1203 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
1204 if (vha
->vha_iaback
== NULL
)
1207 if (vha
->vha_ia
->ia_addr
.sin_addr
.s_addr
== addr
->s_addr
)
1215 carp_iamatch_balance(const struct carp_if
*cif
, const struct in_addr
*itaddr
,
1216 const struct in_addr
*isaddr
, uint8_t **enaddr
)
1218 const struct carp_softc
*vh
;
1219 int index
, count
= 0;
1222 * XXX proof of concept implementation.
1223 * We use the source ip to decide which virtual host should
1224 * handle the request. If we're master of that virtual host,
1225 * then we respond, otherwise, just drop the arp packet on
1229 TAILQ_FOREACH(vh
, &cif
->vhif_vrs
, sc_list
) {
1230 if (!CARP_IS_RUNNING(&vh
->sc_if
))
1233 if (carp_find_addr(vh
, itaddr
) != NULL
)
1239 /* this should be a hash, like pf_hash() */
1240 index
= ntohl(isaddr
->s_addr
) % count
;
1243 TAILQ_FOREACH(vh
, &cif
->vhif_vrs
, sc_list
) {
1244 if (!CARP_IS_RUNNING(&vh
->sc_if
))
1247 if (carp_find_addr(vh
, itaddr
) == NULL
)
1250 if (count
== index
) {
1251 if (vh
->sc_state
== MASTER
) {
1252 *enaddr
= IF_LLADDR(&vh
->sc_if
);
1265 carp_iamatch(const struct in_ifaddr
*ia
)
1267 const struct carp_softc
*sc
= ia
->ia_ifp
->if_softc
;
1269 ASSERT_LWKT_TOKEN_HELD(&carp_tok
);
1272 if (carp_opts
[CARPCTL_ARPBALANCE
])
1273 return carp_iamatch_balance(cif
, itaddr
, isaddr
, enaddr
);
1276 if (!CARP_IS_RUNNING(&sc
->sc_if
) || sc
->sc_state
!= MASTER
)
1284 carp_iamatch6(void *v
, struct in6_addr
*taddr
)
1286 struct carp_if
*cif
= v
;
1287 struct carp_softc
*vh
;
1289 ASSERT_LWKT_TOKEN_HELD(&carp_tok
);
1291 TAILQ_FOREACH(vh
, &cif
->vhif_vrs
, sc_list
) {
1292 struct ifaddr_container
*ifac
;
1294 TAILQ_FOREACH(ifac
, &vh
->sc_if
.if_addrheads
[mycpuid
],
1296 struct ifaddr
*ifa
= ifac
->ifa
;
1298 if (IN6_ARE_ADDR_EQUAL(taddr
,
1299 &ifatoia6(ifa
)->ia_addr
.sin6_addr
) &&
1300 CARP_IS_RUNNING(&vh
->sc_if
) &&
1301 vh
->sc_state
== MASTER
) {
1310 carp_macmatch6(void *v
, struct mbuf
*m
, const struct in6_addr
*taddr
)
1313 struct carp_if
*cif
= v
;
1314 struct carp_softc
*sc
;
1316 ASSERT_LWKT_TOKEN_HELD(&carp_tok
);
1318 TAILQ_FOREACH(sc
, &cif
->vhif_vrs
, sc_list
) {
1319 struct ifaddr_container
*ifac
;
1321 TAILQ_FOREACH(ifac
, &sc
->sc_if
.if_addrheads
[mycpuid
],
1323 struct ifaddr
*ifa
= ifac
->ifa
;
1325 if (IN6_ARE_ADDR_EQUAL(taddr
,
1326 &ifatoia6(ifa
)->ia_addr
.sin6_addr
) &&
1327 CARP_IS_RUNNING(&sc
->sc_if
)) {
1328 struct ifnet
*ifp
= &sc
->sc_if
;
1330 mtag
= m_tag_get(PACKET_TAG_CARP
,
1331 sizeof(struct ifnet
*), MB_DONTWAIT
);
1333 /* better a bit than nothing */
1334 return (IF_LLADDR(ifp
));
1336 bcopy(&ifp
, (caddr_t
)(mtag
+ 1),
1337 sizeof(struct ifnet
*));
1338 m_tag_prepend(m
, mtag
);
1340 return (IF_LLADDR(ifp
));
1348 static struct ifnet
*
1349 carp_forus(struct carp_if
*cif
, const uint8_t *dhost
)
1351 struct carp_softc
*sc
;
1353 ASSERT_LWKT_TOKEN_HELD(&carp_tok
);
1355 if (memcmp(dhost
, carp_etheraddr
, ETHER_ADDR_LEN
- 1) != 0)
1358 TAILQ_FOREACH(sc
, &cif
->vhif_vrs
, sc_list
) {
1359 struct ifnet
*ifp
= &sc
->sc_if
;
1361 if (CARP_IS_RUNNING(ifp
) && sc
->sc_state
== MASTER
&&
1362 !bcmp(dhost
, IF_LLADDR(ifp
), ETHER_ADDR_LEN
))
1369 carp_master_down_timeout(void *xsc
)
1371 struct carp_softc
*sc
= xsc
;
1373 CARP_DEBUG("%s: BACKUP -> MASTER (master timed out)\n",
1374 sc
->sc_if
.if_xname
);
1376 carp_master_down(sc
);
1381 carp_master_down(struct carp_softc
*sc
)
1383 switch (sc
->sc_state
) {
1385 kprintf("%s: master_down event in INIT state\n",
1386 sc
->sc_if
.if_xname
);
1393 carp_set_state(sc
, MASTER
);
1400 carp_setroute(sc
, RTM_ADD
);
1406 * When in backup state, af indicates whether to reset the master down timer
1407 * for v4 or v6. If it's set to zero, reset the ones which are already pending.
1410 carp_setrun(struct carp_softc
*sc
, sa_family_t af
)
1412 struct ifnet
*cifp
= &sc
->sc_if
;
1415 if (sc
->sc_carpdev
== NULL
) {
1416 carp_set_state(sc
, INIT
);
1420 if ((cifp
->if_flags
& IFF_RUNNING
) && sc
->sc_vhid
> 0 &&
1421 (sc
->sc_naddrs
|| sc
->sc_naddrs6
)) {
1424 carp_setroute(sc
, RTM_DELETE
);
1428 switch (sc
->sc_state
) {
1430 if (carp_opts
[CARPCTL_PREEMPT
] && !carp_suppress_preempt
) {
1436 CARP_DEBUG("%s: INIT -> MASTER (preempting)\n",
1438 carp_set_state(sc
, MASTER
);
1439 carp_setroute(sc
, RTM_ADD
);
1441 CARP_DEBUG("%s: INIT -> BACKUP\n", cifp
->if_xname
);
1442 carp_set_state(sc
, BACKUP
);
1443 carp_setroute(sc
, RTM_DELETE
);
1449 callout_stop(&sc
->sc_ad_tmo
);
1450 tv
.tv_sec
= 3 * sc
->sc_advbase
;
1451 tv
.tv_usec
= sc
->sc_advskew
* 1000000 / 256;
1455 callout_reset(&sc
->sc_md_tmo
, tvtohz_high(&tv
),
1456 carp_master_down_timeout
, sc
);
1461 callout_reset(&sc
->sc_md6_tmo
, tvtohz_high(&tv
),
1462 carp_master_down_timeout
, sc
);
1467 callout_reset(&sc
->sc_md_tmo
, tvtohz_high(&tv
),
1468 carp_master_down_timeout
, sc
);
1470 callout_reset(&sc
->sc_md6_tmo
, tvtohz_high(&tv
),
1471 carp_master_down_timeout
, sc
);
1477 tv
.tv_sec
= sc
->sc_advbase
;
1478 tv
.tv_usec
= sc
->sc_advskew
* 1000000 / 256;
1479 callout_reset(&sc
->sc_ad_tmo
, tvtohz_high(&tv
),
1480 carp_send_ad_timeout
, sc
);
1486 carp_multicast_cleanup(struct carp_softc
*sc
)
1488 struct ip_moptions
*imo
= &sc
->sc_imo
;
1490 if (imo
->imo_num_memberships
== 0)
1492 KKASSERT(imo
->imo_num_memberships
== 1);
1494 in_delmulti(imo
->imo_membership
[0]);
1495 imo
->imo_membership
[0] = NULL
;
1496 imo
->imo_num_memberships
= 0;
1497 imo
->imo_multicast_ifp
= NULL
;
1502 carp_multicast6_cleanup(struct carp_softc
*sc
)
1504 struct ip6_moptions
*im6o
= &sc
->sc_im6o
;
1506 while (!LIST_EMPTY(&im6o
->im6o_memberships
)) {
1507 struct in6_multi_mship
*imm
=
1508 LIST_FIRST(&im6o
->im6o_memberships
);
1510 LIST_REMOVE(imm
, i6mm_chain
);
1511 in6_leavegroup(imm
);
1513 im6o
->im6o_multicast_ifp
= NULL
;
1518 carp_ioctl_getvhaddr_dispatch(netmsg_t msg
)
1520 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
1521 struct carp_softc
*sc
= cmsg
->nc_softc
;
1522 const struct carp_vhaddr
*vha
;
1523 struct ifcarpvhaddr
*carpa
, *carpa0
;
1524 int count
, len
, error
= 0;
1529 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
)
1532 if (cmsg
->nc_datalen
== 0) {
1533 cmsg
->nc_datalen
= count
* sizeof(*carpa
);
1535 } else if (count
== 0 || cmsg
->nc_datalen
< sizeof(*carpa
)) {
1536 cmsg
->nc_datalen
= 0;
1539 len
= min(cmsg
->nc_datalen
, sizeof(*carpa
) * count
);
1540 KKASSERT(len
>= sizeof(*carpa
));
1542 carpa0
= carpa
= kmalloc(len
, M_TEMP
, M_WAITOK
| M_NULLOK
| M_ZERO
);
1543 if (carpa
== NULL
) {
1549 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
1550 if (len
< sizeof(*carpa
))
1553 carpa
->carpa_flags
= vha
->vha_flags
;
1554 carpa
->carpa_addr
.sin_family
= AF_INET
;
1555 carpa
->carpa_addr
.sin_addr
= vha
->vha_ia
->ia_addr
.sin_addr
;
1557 carpa
->carpa_baddr
.sin_family
= AF_INET
;
1558 if (vha
->vha_iaback
== NULL
) {
1559 carpa
->carpa_baddr
.sin_addr
.s_addr
= INADDR_ANY
;
1561 carpa
->carpa_baddr
.sin_addr
=
1562 vha
->vha_iaback
->ia_addr
.sin_addr
;
1567 len
-= sizeof(*carpa
);
1569 cmsg
->nc_datalen
= sizeof(*carpa
) * count
;
1570 KKASSERT(cmsg
->nc_datalen
> 0);
1572 cmsg
->nc_data
= carpa0
;
1576 lwkt_replymsg(&cmsg
->base
.lmsg
, error
);
1580 carp_ioctl_getvhaddr(struct carp_softc
*sc
, struct ifdrv
*ifd
)
1582 struct ifnet
*ifp
= &sc
->arpcom
.ac_if
;
1583 struct netmsg_carp cmsg
;
1586 ASSERT_IFNET_SERIALIZED_ALL(ifp
);
1587 ifnet_deserialize_all(ifp
);
1589 bzero(&cmsg
, sizeof(cmsg
));
1590 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
1591 carp_ioctl_getvhaddr_dispatch
);
1593 cmsg
.nc_datalen
= ifd
->ifd_len
;
1595 error
= lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
1598 if (cmsg
.nc_data
!= NULL
) {
1599 error
= copyout(cmsg
.nc_data
, ifd
->ifd_data
,
1601 kfree(cmsg
.nc_data
, M_TEMP
);
1603 ifd
->ifd_len
= cmsg
.nc_datalen
;
1605 KASSERT(cmsg
.nc_data
== NULL
,
1606 ("%s temp vhaddr is alloc upon error\n", __func__
));
1609 ifnet_serialize_all(ifp
);
1614 carp_config_vhaddr(struct carp_softc
*sc
, struct carp_vhaddr
*vha
,
1615 struct in_ifaddr
*ia_del
)
1618 struct in_ifaddr
*ia_if
;
1619 struct in_ifaddr_container
*iac
;
1620 const struct sockaddr_in
*sin
;
1624 KKASSERT(vha
->vha_ia
!= NULL
);
1626 sin
= &vha
->vha_ia
->ia_addr
;
1627 iaddr
= ntohl(sin
->sin_addr
.s_addr
);
1631 TAILQ_FOREACH(iac
, &in_ifaddrheads
[mycpuid
], ia_link
) {
1632 struct in_ifaddr
*ia
= iac
->ia
;
1637 if (ia
->ia_ifp
->if_type
== IFT_CARP
)
1640 if ((ia
->ia_ifp
->if_flags
& IFF_UP
) == 0)
1643 /* and, yeah, we need a multicast-capable iface too */
1644 if ((ia
->ia_ifp
->if_flags
& IFF_MULTICAST
) == 0)
1647 if ((iaddr
& ia
->ia_subnetmask
) == ia
->ia_subnet
) {
1648 if (sin
->sin_addr
.s_addr
==
1649 ia
->ia_addr
.sin_addr
.s_addr
)
1653 else if (sc
->sc_carpdev
!= NULL
&&
1654 sc
->sc_carpdev
== ia
->ia_ifp
)
1659 carp_deactivate_vhaddr(sc
, vha
, FALSE
);
1663 ifp
= ia_if
->ia_ifp
;
1665 /* XXX Don't allow parent iface to be changed */
1666 if (sc
->sc_carpdev
!= NULL
&& sc
->sc_carpdev
!= ifp
)
1669 return carp_activate_vhaddr(sc
, vha
, ifp
, ia_if
, own
);
1673 carp_add_addr(struct carp_softc
*sc
, struct ifaddr
*carp_ifa
)
1675 struct carp_vhaddr
*vha_new
;
1676 struct in_ifaddr
*carp_ia
;
1678 struct carp_vhaddr
*vha
;
1681 KKASSERT(carp_ifa
->ifa_addr
->sa_family
== AF_INET
);
1682 carp_ia
= ifatoia(carp_ifa
);
1685 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
)
1686 KKASSERT(vha
->vha_ia
!= NULL
&& vha
->vha_ia
!= carp_ia
);
1689 vha_new
= kmalloc(sizeof(*vha_new
), M_CARP
, M_WAITOK
| M_ZERO
);
1690 vha_new
->vha_ia
= carp_ia
;
1691 carp_insert_vhaddr(sc
, vha_new
);
1693 if (carp_config_vhaddr(sc
, vha_new
, NULL
) != 0) {
1695 * If the above configuration fails, it may only mean
1696 * that the new address is problematic. However, the
1697 * carp(4) interface may already have several working
1698 * addresses. Since the expected behaviour of
1699 * SIOC[AS]IFADDR is to put the NIC into working state,
1700 * we try starting the state machine manually here with
1701 * the hope that the carp(4)'s previously working
1702 * addresses still could be brought up.
1704 carp_hmac_prepare(sc
);
1705 carp_set_state(sc
, INIT
);
1711 carp_del_addr(struct carp_softc
*sc
, struct ifaddr
*carp_ifa
)
1713 struct carp_vhaddr
*vha
;
1714 struct in_ifaddr
*carp_ia
;
1716 KKASSERT(carp_ifa
->ifa_addr
->sa_family
== AF_INET
);
1717 carp_ia
= ifatoia(carp_ifa
);
1719 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
1720 KKASSERT(vha
->vha_ia
!= NULL
);
1721 if (vha
->vha_ia
== carp_ia
)
1724 KASSERT(vha
!= NULL
, ("no corresponding vhaddr %p\n", carp_ifa
));
1727 * Remove the vhaddr from the list before deactivating
1728 * the vhaddr, so that the HMAC could be correctly
1729 * updated in carp_deactivate_vhaddr()
1731 carp_remove_vhaddr(sc
, vha
);
1733 carp_deactivate_vhaddr(sc
, vha
, FALSE
);
1738 carp_config_addr(struct carp_softc
*sc
, struct ifaddr
*carp_ifa
)
1740 struct carp_vhaddr
*vha
;
1741 struct in_ifaddr
*carp_ia
;
1743 KKASSERT(carp_ifa
->ifa_addr
->sa_family
== AF_INET
);
1744 carp_ia
= ifatoia(carp_ifa
);
1746 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
1747 KKASSERT(vha
->vha_ia
!= NULL
);
1748 if (vha
->vha_ia
== carp_ia
)
1751 KASSERT(vha
!= NULL
, ("no corresponding vhaddr %p\n", carp_ifa
));
1753 /* Remove then reinsert, to keep the vhaddr list sorted */
1754 carp_remove_vhaddr(sc
, vha
);
1755 carp_insert_vhaddr(sc
, vha
);
1757 if (carp_config_vhaddr(sc
, vha
, NULL
) != 0) {
1758 /* See the comment in carp_add_addr() */
1759 carp_hmac_prepare(sc
);
1760 carp_set_state(sc
, INIT
);
1769 carp_set_addr6(struct carp_softc
*sc
, struct sockaddr_in6
*sin6
)
1772 struct carp_if
*cif
;
1773 struct in6_ifaddr
*ia
, *ia_if
;
1774 struct ip6_moptions
*im6o
= &sc
->sc_im6o
;
1775 struct in6_multi_mship
*imm
;
1776 struct in6_addr in6
;
1779 if (IN6_IS_ADDR_UNSPECIFIED(&sin6
->sin6_addr
)) {
1784 /* we have to do it by hands to check we won't match on us */
1785 ia_if
= NULL
; own
= 0;
1786 for (ia
= in6_ifaddr
; ia
; ia
= ia
->ia_next
) {
1789 for (i
= 0; i
< 4; i
++) {
1790 if ((sin6
->sin6_addr
.s6_addr32
[i
] &
1791 ia
->ia_prefixmask
.sin6_addr
.s6_addr32
[i
]) !=
1792 (ia
->ia_addr
.sin6_addr
.s6_addr32
[i
] &
1793 ia
->ia_prefixmask
.sin6_addr
.s6_addr32
[i
]))
1796 /* and, yeah, we need a multicast-capable iface too */
1797 if (ia
->ia_ifp
!= &sc
->sc_if
&&
1798 (ia
->ia_ifp
->if_flags
& IFF_MULTICAST
) &&
1802 if (IN6_ARE_ADDR_EQUAL(&sin6
->sin6_addr
,
1803 &ia
->ia_addr
.sin6_addr
))
1809 return (EADDRNOTAVAIL
);
1813 if (ifp
== NULL
|| (ifp
->if_flags
& IFF_MULTICAST
) == 0 ||
1814 (im6o
->im6o_multicast_ifp
&& im6o
->im6o_multicast_ifp
!= ifp
))
1815 return (EADDRNOTAVAIL
);
1817 if (!sc
->sc_naddrs6
) {
1818 im6o
->im6o_multicast_ifp
= ifp
;
1820 /* join CARP multicast address */
1821 bzero(&in6
, sizeof(in6
));
1822 in6
.s6_addr16
[0] = htons(0xff02);
1823 in6
.s6_addr8
[15] = 0x12;
1824 if (in6_setscope(&in6
, ifp
, NULL
) != 0)
1826 if ((imm
= in6_joingroup(ifp
, &in6
, &error
)) == NULL
)
1828 LIST_INSERT_HEAD(&im6o
->im6o_memberships
, imm
, i6mm_chain
);
1830 /* join solicited multicast address */
1831 bzero(&in6
, sizeof(in6
));
1832 in6
.s6_addr16
[0] = htons(0xff02);
1833 in6
.s6_addr32
[1] = 0;
1834 in6
.s6_addr32
[2] = htonl(1);
1835 in6
.s6_addr32
[3] = sin6
->sin6_addr
.s6_addr32
[3];
1836 in6
.s6_addr8
[12] = 0xff;
1837 if (in6_setscope(&in6
, ifp
, NULL
) != 0)
1839 if ((imm
= in6_joingroup(ifp
, &in6
, &error
)) == NULL
)
1841 LIST_INSERT_HEAD(&im6o
->im6o_memberships
, imm
, i6mm_chain
);
1844 if (!ifp
->if_carp
) {
1845 cif
= kmalloc(sizeof(*cif
), M_CARP
, M_WAITOK
| M_ZERO
);
1847 if ((error
= ifpromisc(ifp
, 1))) {
1852 TAILQ_INIT(&cif
->vhif_vrs
);
1855 struct carp_softc
*vr
;
1858 TAILQ_FOREACH(vr
, &cif
->vhif_vrs
, sc_list
) {
1859 if (vr
!= sc
&& vr
->sc_vhid
== sc
->sc_vhid
) {
1866 sc
->sc_carpdev
= ifp
;
1868 { /* XXX prevent endless loop if already in queue */
1869 struct carp_softc
*vr
, *after
= NULL
;
1873 TAILQ_FOREACH(vr
, &cif
->vhif_vrs
, sc_list
) {
1876 if (vr
->sc_vhid
< sc
->sc_vhid
)
1881 /* We're trying to keep things in order */
1883 TAILQ_INSERT_TAIL(&cif
->vhif_vrs
, sc
, sc_list
);
1885 TAILQ_INSERT_AFTER(&cif
->vhif_vrs
, after
, sc
, sc_list
);
1898 /* clean up multicast memberships */
1899 if (!sc
->sc_naddrs6
) {
1900 while (!LIST_EMPTY(&im6o
->im6o_memberships
)) {
1901 imm
= LIST_FIRST(&im6o
->im6o_memberships
);
1902 LIST_REMOVE(imm
, i6mm_chain
);
1903 in6_leavegroup(imm
);
1910 carp_del_addr6(struct carp_softc
*sc
, struct sockaddr_in6
*sin6
)
1914 if (!--sc
->sc_naddrs6
) {
1915 struct carp_if
*cif
= sc
->sc_carpdev
->if_carp
;
1916 struct ip6_moptions
*im6o
= &sc
->sc_im6o
;
1918 callout_stop(&sc
->sc_ad_tmo
);
1920 while (!LIST_EMPTY(&im6o
->im6o_memberships
)) {
1921 struct in6_multi_mship
*imm
=
1922 LIST_FIRST(&im6o
->im6o_memberships
);
1924 LIST_REMOVE(imm
, i6mm_chain
);
1925 in6_leavegroup(imm
);
1927 im6o
->im6o_multicast_ifp
= NULL
;
1928 TAILQ_REMOVE(&cif
->vhif_vrs
, sc
, sc_list
);
1929 if (TAILQ_EMPTY(&cif
->vhif_vrs
)) {
1930 sc
->sc_carpdev
->if_carp
= NULL
;
1931 kfree(cif
, M_IFADDR
);
1941 carp_ioctl(struct ifnet
*ifp
, u_long cmd
, caddr_t addr
, struct ucred
*cr
)
1943 struct carp_softc
*sc
= ifp
->if_softc
;
1944 struct ifreq
*ifr
= (struct ifreq
*)addr
;
1945 struct ifdrv
*ifd
= (struct ifdrv
*)addr
;
1948 ASSERT_IFNET_SERIALIZED_ALL(ifp
);
1954 if (ifp
->if_flags
& IFF_UP
) {
1955 if ((ifp
->if_flags
& IFF_RUNNING
) == 0)
1957 } else if (ifp
->if_flags
& IFF_RUNNING
) {
1958 carp_ioctl_stop(sc
);
1963 error
= carp_ioctl_setvh(sc
, ifr
->ifr_data
, cr
);
1967 error
= carp_ioctl_getvh(sc
, ifr
->ifr_data
, cr
);
1971 switch (ifd
->ifd_cmd
) {
1973 error
= carp_ioctl_getdevname(sc
, ifd
);
1977 error
= carp_ioctl_getvhaddr(sc
, ifd
);
1987 error
= ether_ioctl(ifp
, cmd
, addr
);
1996 carp_ioctl_stop_dispatch(netmsg_t msg
)
1998 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
1999 struct carp_softc
*sc
= cmsg
->nc_softc
;
2005 lwkt_replymsg(&cmsg
->base
.lmsg
, 0);
2009 carp_ioctl_stop(struct carp_softc
*sc
)
2011 struct ifnet
*ifp
= &sc
->arpcom
.ac_if
;
2012 struct netmsg_carp cmsg
;
2014 ASSERT_IFNET_SERIALIZED_ALL(ifp
);
2016 ifnet_deserialize_all(ifp
);
2018 bzero(&cmsg
, sizeof(cmsg
));
2019 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
2020 carp_ioctl_stop_dispatch
);
2023 lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
2025 ifnet_serialize_all(ifp
);
2029 carp_ioctl_setvh_dispatch(netmsg_t msg
)
2031 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
2032 struct carp_softc
*sc
= cmsg
->nc_softc
, *vr
;
2033 struct ifnet
*ifp
= &sc
->arpcom
.ac_if
;
2034 const struct carpreq
*carpr
= cmsg
->nc_data
;
2040 if ((ifp
->if_flags
& IFF_RUNNING
) &&
2041 sc
->sc_state
!= INIT
&& carpr
->carpr_state
!= sc
->sc_state
) {
2042 switch (carpr
->carpr_state
) {
2044 callout_stop(&sc
->sc_ad_tmo
);
2045 carp_set_state(sc
, BACKUP
);
2047 carp_setroute(sc
, RTM_DELETE
);
2051 carp_master_down(sc
);
2058 if (carpr
->carpr_vhid
> 0) {
2059 if (carpr
->carpr_vhid
> 255) {
2063 if (sc
->sc_carpdev
) {
2064 struct carp_if
*cif
= sc
->sc_carpdev
->if_carp
;
2066 TAILQ_FOREACH(vr
, &cif
->vhif_vrs
, sc_list
) {
2068 vr
->sc_vhid
== carpr
->carpr_vhid
) {
2074 sc
->sc_vhid
= carpr
->carpr_vhid
;
2076 IF_LLADDR(ifp
)[5] = sc
->sc_vhid
;
2077 bcopy(IF_LLADDR(ifp
), sc
->arpcom
.ac_enaddr
,
2082 if (carpr
->carpr_advbase
> 0 || carpr
->carpr_advskew
> 0) {
2083 if (carpr
->carpr_advskew
>= 255) {
2087 if (carpr
->carpr_advbase
> 255) {
2091 sc
->sc_advbase
= carpr
->carpr_advbase
;
2092 sc
->sc_advskew
= carpr
->carpr_advskew
;
2095 bcopy(carpr
->carpr_key
, sc
->sc_key
, sizeof(sc
->sc_key
));
2103 carp_hmac_prepare(sc
);
2106 lwkt_replymsg(&cmsg
->base
.lmsg
, error
);
2110 carp_ioctl_setvh(struct carp_softc
*sc
, void *udata
, struct ucred
*cr
)
2112 struct ifnet
*ifp
= &sc
->arpcom
.ac_if
;
2113 struct netmsg_carp cmsg
;
2114 struct carpreq carpr
;
2117 ASSERT_IFNET_SERIALIZED_ALL(ifp
);
2118 ifnet_deserialize_all(ifp
);
2120 error
= priv_check_cred(cr
, PRIV_ROOT
, NULL_CRED_OKAY
);
2124 error
= copyin(udata
, &carpr
, sizeof(carpr
));
2128 bzero(&cmsg
, sizeof(cmsg
));
2129 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
2130 carp_ioctl_setvh_dispatch
);
2132 cmsg
.nc_data
= &carpr
;
2134 error
= lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
2137 ifnet_serialize_all(ifp
);
2142 carp_ioctl_getvh_dispatch(netmsg_t msg
)
2144 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
2145 struct carp_softc
*sc
= cmsg
->nc_softc
;
2146 struct carpreq
*carpr
= cmsg
->nc_data
;
2150 carpr
->carpr_state
= sc
->sc_state
;
2151 carpr
->carpr_vhid
= sc
->sc_vhid
;
2152 carpr
->carpr_advbase
= sc
->sc_advbase
;
2153 carpr
->carpr_advskew
= sc
->sc_advskew
;
2154 bcopy(sc
->sc_key
, carpr
->carpr_key
, sizeof(carpr
->carpr_key
));
2158 lwkt_replymsg(&cmsg
->base
.lmsg
, 0);
2162 carp_ioctl_getvh(struct carp_softc
*sc
, void *udata
, struct ucred
*cr
)
2164 struct ifnet
*ifp
= &sc
->arpcom
.ac_if
;
2165 struct netmsg_carp cmsg
;
2166 struct carpreq carpr
;
2169 ASSERT_IFNET_SERIALIZED_ALL(ifp
);
2170 ifnet_deserialize_all(ifp
);
2172 bzero(&cmsg
, sizeof(cmsg
));
2173 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
2174 carp_ioctl_getvh_dispatch
);
2176 cmsg
.nc_data
= &carpr
;
2178 lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
2180 error
= priv_check_cred(cr
, PRIV_ROOT
, NULL_CRED_OKAY
);
2182 bzero(carpr
.carpr_key
, sizeof(carpr
.carpr_key
));
2184 error
= copyout(&carpr
, udata
, sizeof(carpr
));
2186 ifnet_serialize_all(ifp
);
2191 carp_ioctl_getdevname_dispatch(netmsg_t msg
)
2193 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
2194 struct carp_softc
*sc
= cmsg
->nc_softc
;
2195 char *devname
= cmsg
->nc_data
;
2197 bzero(devname
, sizeof(devname
));
2200 if (sc
->sc_carpdev
!= NULL
)
2201 strlcpy(devname
, sc
->sc_carpdev
->if_xname
, sizeof(devname
));
2204 lwkt_replymsg(&cmsg
->base
.lmsg
, 0);
2208 carp_ioctl_getdevname(struct carp_softc
*sc
, struct ifdrv
*ifd
)
2210 struct ifnet
*ifp
= &sc
->arpcom
.ac_if
;
2211 struct netmsg_carp cmsg
;
2212 char devname
[IFNAMSIZ
];
2215 ASSERT_IFNET_SERIALIZED_ALL(ifp
);
2217 if (ifd
->ifd_len
!= sizeof(devname
))
2220 ifnet_deserialize_all(ifp
);
2222 bzero(&cmsg
, sizeof(cmsg
));
2223 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
2224 carp_ioctl_getdevname_dispatch
);
2226 cmsg
.nc_data
= devname
;
2228 lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
2230 error
= copyout(devname
, ifd
->ifd_data
, sizeof(devname
));
2232 ifnet_serialize_all(ifp
);
2237 carp_init_dispatch(netmsg_t msg
)
2239 struct netmsg_carp
*cmsg
= (struct netmsg_carp
*)msg
;
2240 struct carp_softc
*sc
= cmsg
->nc_softc
;
2244 sc
->sc_if
.if_flags
|= IFF_RUNNING
;
2245 carp_hmac_prepare(sc
);
2246 carp_set_state(sc
, INIT
);
2251 lwkt_replymsg(&cmsg
->base
.lmsg
, 0);
2255 carp_init(void *xsc
)
2257 struct carp_softc
*sc
= xsc
;
2258 struct ifnet
*ifp
= &sc
->arpcom
.ac_if
;
2259 struct netmsg_carp cmsg
;
2261 ASSERT_IFNET_SERIALIZED_ALL(ifp
);
2263 ifnet_deserialize_all(ifp
);
2265 bzero(&cmsg
, sizeof(cmsg
));
2266 netmsg_init(&cmsg
.base
, NULL
, &curthread
->td_msgport
, 0,
2267 carp_init_dispatch
);
2270 lwkt_domsg(cpu_portfn(0), &cmsg
.base
.lmsg
, 0);
2272 ifnet_serialize_all(ifp
);
2276 carp_output(struct ifnet
*ifp
, struct mbuf
*m
, struct sockaddr
*dst
,
2279 struct carp_softc
*sc
= ifp
->if_softc
;
2283 if (sc
->sc_carpdev
) {
2286 * CARP's ifp is passed to backing device's
2289 sc
->sc_carpdev
->if_output(ifp
, m
, dst
, rt
);
2292 error
= ENETUNREACH
;
2300 * Start output on carp interface. This function should never be called.
2303 carp_start(struct ifnet
*ifp
)
2305 panic("%s: start called\n", ifp
->if_xname
);
2309 carp_serialize(struct ifnet
*ifp __unused
,
2310 enum ifnet_serialize slz __unused
)
2315 carp_deserialize(struct ifnet
*ifp __unused
,
2316 enum ifnet_serialize slz __unused
)
2321 carp_tryserialize(struct ifnet
*ifp __unused
,
2322 enum ifnet_serialize slz __unused
)
2330 carp_serialize_assert(struct ifnet
*ifp __unused
,
2331 enum ifnet_serialize slz __unused
, boolean_t serialized __unused
)
2335 #endif /* INVARIANTS */
2338 carp_set_state(struct carp_softc
*sc
, int state
)
2340 struct ifnet
*cifp
= &sc
->sc_if
;
2342 if (sc
->sc_state
== state
)
2344 sc
->sc_state
= state
;
2346 switch (sc
->sc_state
) {
2348 cifp
->if_link_state
= LINK_STATE_DOWN
;
2352 cifp
->if_link_state
= LINK_STATE_UP
;
2356 cifp
->if_link_state
= LINK_STATE_UNKNOWN
;
2363 carp_group_demote_adj(struct ifnet
*ifp
, int adj
)
2365 struct ifg_list
*ifgl
;
2370 TAILQ_FOREACH(ifgl
, &ifp
->if_groups
, ifgl_next
) {
2371 if (!strcmp(ifgl
->ifgl_group
->ifg_group
, IFG_ALL
))
2373 dm
= &ifgl
->ifgl_group
->ifg_carp_demoted
;
2380 if (adj
> 0 && *dm
== 1)
2382 CARP_LOG("%s demoted group %s to %d", ifp
->if_xname
,
2383 ifgl
->ifgl_group
->ifg_group
, *dm
);
2390 carp_carpdev_state(void *v
)
2392 struct carp_if
*cif
= v
;
2393 struct carp_softc
*sc
;
2397 TAILQ_FOREACH(sc
, &cif
->vhif_vrs
, sc_list
)
2404 carp_sc_state(struct carp_softc
*sc
)
2406 if (!(sc
->sc_carpdev
->if_flags
& IFF_UP
)) {
2407 callout_stop(&sc
->sc_ad_tmo
);
2408 callout_stop(&sc
->sc_md_tmo
);
2409 callout_stop(&sc
->sc_md6_tmo
);
2410 carp_set_state(sc
, INIT
);
2412 if (!sc
->sc_suppress
) {
2413 carp_suppress_preempt
++;
2414 if (carp_suppress_preempt
== 1)
2417 sc
->sc_suppress
= 1;
2419 carp_set_state(sc
, INIT
);
2421 if (sc
->sc_suppress
)
2422 carp_suppress_preempt
--;
2423 sc
->sc_suppress
= 0;
2428 carp_stop(struct carp_softc
*sc
, int detach
)
2430 sc
->sc_if
.if_flags
&= ~IFF_RUNNING
;
2432 callout_stop(&sc
->sc_ad_tmo
);
2433 callout_stop(&sc
->sc_md_tmo
);
2434 callout_stop(&sc
->sc_md6_tmo
);
2436 if (!detach
&& sc
->sc_state
== MASTER
)
2439 if (sc
->sc_suppress
)
2440 carp_suppress_preempt
--;
2441 sc
->sc_suppress
= 0;
2443 if (sc
->sc_sendad_errors
>= CARP_SENDAD_MAX_ERRORS
)
2444 carp_suppress_preempt
--;
2445 sc
->sc_sendad_errors
= 0;
2446 sc
->sc_sendad_success
= 0;
2448 carp_set_state(sc
, INIT
);
2453 carp_suspend(struct carp_softc
*sc
, int detach
)
2455 struct ifnet
*cifp
= &sc
->sc_if
;
2457 carp_stop(sc
, detach
);
2459 /* Retain the running state, if we are not dead yet */
2460 if (!sc
->sc_dead
&& (cifp
->if_flags
& IFF_UP
))
2461 cifp
->if_flags
|= IFF_RUNNING
;
2465 carp_activate_vhaddr(struct carp_softc
*sc
, struct carp_vhaddr
*vha
,
2466 struct ifnet
*ifp
, struct in_ifaddr
*ia_if
, int own
)
2468 struct ip_moptions
*imo
= &sc
->sc_imo
;
2469 struct carp_if
*cif
;
2470 struct carp_softc
*vr
, *after
= NULL
;
2476 KKASSERT(vha
->vha_ia
!= NULL
);
2478 KASSERT(ia_if
!= NULL
, ("NULL backing address\n"));
2479 KASSERT(vha
->vha_iaback
== NULL
, ("%p is already activated\n", vha
));
2480 KASSERT((vha
->vha_flags
& CARP_VHAF_OWNER
) == 0,
2481 ("inactive vhaddr %p is the address owner\n", vha
));
2483 KASSERT(sc
->sc_carpdev
== NULL
|| sc
->sc_carpdev
== ifp
,
2484 ("%s is already on %s\n", sc
->sc_if
.if_xname
,
2485 sc
->sc_carpdev
->if_xname
));
2487 if (!ifp
->if_carp
) {
2488 KASSERT(sc
->sc_carpdev
== NULL
,
2489 ("%s is already on %s\n", sc
->sc_if
.if_xname
,
2490 sc
->sc_carpdev
->if_xname
));
2492 cif
= kmalloc(sizeof(*cif
), M_CARP
, M_WAITOK
| M_ZERO
);
2494 error
= ifpromisc(ifp
, 1);
2500 TAILQ_INIT(&cif
->vhif_vrs
);
2504 TAILQ_FOREACH(vr
, &cif
->vhif_vrs
, sc_list
) {
2505 if (vr
!= sc
&& vr
->sc_vhid
== sc
->sc_vhid
)
2511 if (sc
->sc_carpdev
!= NULL
)
2517 sc
->sc_carpdev
= ifp
;
2521 TAILQ_FOREACH(vr
, &cif
->vhif_vrs
, sc_list
) {
2524 if (vr
->sc_vhid
< sc
->sc_vhid
)
2529 if (assert_onlist
) {
2530 KASSERT(onlist
, ("%s is not on %s carp list\n",
2531 sc
->sc_if
.if_xname
, ifp
->if_xname
));
2533 KASSERT(!onlist
, ("%s is already on %s carp list\n",
2534 sc
->sc_if
.if_xname
, ifp
->if_xname
));
2539 /* We're trying to keep things in order */
2541 TAILQ_INSERT_TAIL(&cif
->vhif_vrs
, sc
, sc_list
);
2543 TAILQ_INSERT_AFTER(&cif
->vhif_vrs
, after
, sc
, sc_list
);
2546 vha
->vha_iaback
= ia_if
;
2550 vha
->vha_flags
|= CARP_VHAF_OWNER
;
2552 /* XXX save user configured advskew? */
2556 carp_addroute_vhaddr(sc
, vha
);
2559 * Join the multicast group only after the backing interface
2560 * has been hooked with the CARP interface.
2562 KASSERT(imo
->imo_multicast_ifp
== NULL
||
2563 imo
->imo_multicast_ifp
== &sc
->sc_if
,
2564 ("%s didn't leave mcast group on %s\n",
2565 sc
->sc_if
.if_xname
, imo
->imo_multicast_ifp
->if_xname
));
2567 if (imo
->imo_num_memberships
== 0) {
2568 struct in_addr addr
;
2570 addr
.s_addr
= htonl(INADDR_CARP_GROUP
);
2571 imo
->imo_membership
[0] = in_addmulti(&addr
, &sc
->sc_if
);
2572 if (imo
->imo_membership
[0] == NULL
) {
2573 carp_deactivate_vhaddr(sc
, vha
, FALSE
);
2577 imo
->imo_num_memberships
++;
2578 imo
->imo_multicast_ifp
= &sc
->sc_if
;
2579 imo
->imo_multicast_ttl
= CARP_DFLTTL
;
2580 imo
->imo_multicast_loop
= 0;
2583 carp_hmac_prepare(sc
);
2584 carp_set_state(sc
, INIT
);
2590 carp_deactivate_vhaddr(struct carp_softc
*sc
, struct carp_vhaddr
*vha
,
2591 boolean_t del_iaback
)
2593 KKASSERT(vha
->vha_ia
!= NULL
);
2595 carp_hmac_prepare(sc
);
2597 if (vha
->vha_iaback
== NULL
) {
2598 KASSERT((vha
->vha_flags
& CARP_VHAF_OWNER
) == 0,
2599 ("inactive vhaddr %p is the address owner\n", vha
));
2603 vha
->vha_flags
&= ~CARP_VHAF_OWNER
;
2604 carp_delroute_vhaddr(sc
, vha
, del_iaback
);
2606 KKASSERT(sc
->sc_naddrs
> 0);
2607 vha
->vha_iaback
= NULL
;
2609 if (!sc
->sc_naddrs
) {
2610 if (sc
->sc_naddrs6
) {
2611 carp_multicast_cleanup(sc
);
2614 carp_detach(sc
, 0, del_iaback
);
2620 carp_link_addrs(struct carp_softc
*sc
, struct ifnet
*ifp
, struct ifaddr
*ifa_if
)
2622 struct carp_vhaddr
*vha
;
2623 struct in_ifaddr
*ia_if
;
2625 KKASSERT(ifa_if
->ifa_addr
->sa_family
== AF_INET
);
2626 ia_if
= ifatoia(ifa_if
);
2629 * Test each inactive vhaddr against the newly added address.
2630 * If the newly added address could be the backing address,
2631 * then activate the matching vhaddr.
2633 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
2634 const struct in_ifaddr
*ia
;
2638 if (vha
->vha_iaback
!= NULL
)
2642 iaddr
= ntohl(ia
->ia_addr
.sin_addr
.s_addr
);
2644 if ((iaddr
& ia_if
->ia_subnetmask
) != ia_if
->ia_subnet
)
2648 if (ia
->ia_addr
.sin_addr
.s_addr
==
2649 ia_if
->ia_addr
.sin_addr
.s_addr
)
2652 carp_activate_vhaddr(sc
, vha
, ifp
, ia_if
, own
);
2657 carp_unlink_addrs(struct carp_softc
*sc
, struct ifnet
*ifp
,
2658 struct ifaddr
*ifa_if
)
2660 struct carp_vhaddr
*vha
;
2661 struct in_ifaddr
*ia_if
;
2663 KKASSERT(ifa_if
->ifa_addr
->sa_family
== AF_INET
);
2664 ia_if
= ifatoia(ifa_if
);
2667 * Ad src address is deleted; set it to NULL.
2668 * Following loop will try pick up a new ad src address
2669 * if one of the vhaddr could retain its backing address.
2671 if (sc
->sc_ia
== ia_if
)
2675 * Test each active vhaddr against the deleted address.
2676 * If the deleted address is vhaddr address's backing
2677 * address, then deactivate the vhaddr.
2679 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
) {
2680 if (vha
->vha_iaback
== NULL
)
2683 if (vha
->vha_iaback
== ia_if
)
2684 carp_deactivate_vhaddr(sc
, vha
, TRUE
);
2685 else if (sc
->sc_ia
== NULL
)
2686 sc
->sc_ia
= vha
->vha_iaback
;
2691 carp_update_addrs(struct carp_softc
*sc
, struct ifaddr
*ifa_del
)
2693 struct carp_vhaddr
*vha
;
2695 KKASSERT(sc
->sc_carpdev
== NULL
);
2697 TAILQ_FOREACH(vha
, &sc
->sc_vha_list
, vha_link
)
2698 carp_config_vhaddr(sc
, vha
, ifatoia(ifa_del
));
2702 carp_ifaddr(void *arg __unused
, struct ifnet
*ifp
,
2703 enum ifaddr_event event
, struct ifaddr
*ifa
)
2705 struct carp_softc
*sc
;
2709 if (ifa
->ifa_addr
->sa_family
!= AF_INET
)
2712 KASSERT(&curthread
->td_msgport
== cpu_portfn(0),
2713 ("not in netisr0"));
2715 if (ifp
->if_type
== IFT_CARP
) {
2717 * Address is changed on carp(4) interface
2720 case IFADDR_EVENT_ADD
:
2721 carp_add_addr(ifp
->if_softc
, ifa
);
2724 case IFADDR_EVENT_CHANGE
:
2725 carp_config_addr(ifp
->if_softc
, ifa
);
2728 case IFADDR_EVENT_DELETE
:
2729 carp_del_addr(ifp
->if_softc
, ifa
);
2736 * Address is changed on non-carp(4) interface
2738 if ((ifp
->if_flags
& IFF_MULTICAST
) == 0)
2741 LIST_FOREACH(sc
, &carpif_list
, sc_next
) {
2742 if (sc
->sc_carpdev
!= NULL
&& sc
->sc_carpdev
!= ifp
) {
2743 /* Not the parent iface; skip */
2748 case IFADDR_EVENT_ADD
:
2749 carp_link_addrs(sc
, ifp
, ifa
);
2752 case IFADDR_EVENT_DELETE
:
2753 if (sc
->sc_carpdev
!= NULL
) {
2754 carp_unlink_addrs(sc
, ifp
, ifa
);
2755 if (sc
->sc_carpdev
== NULL
) {
2757 * We no longer have the parent
2758 * interface, however, certain
2759 * virtual addresses, which are
2760 * not used because they can't
2761 * match the previous parent
2762 * interface's addresses, may now
2763 * match different interface's
2766 carp_update_addrs(sc
, ifa
);
2770 * The carp(4) interface didn't have a
2771 * parent iface, so it is not possible
2772 * that it will contain any address to
2778 case IFADDR_EVENT_CHANGE
:
2779 if (sc
->sc_carpdev
== NULL
) {
2781 * The carp(4) interface didn't have a
2782 * parent iface, so it is not possible
2783 * that it will contain any address to
2786 carp_link_addrs(sc
, ifp
, ifa
);
2789 * First try breaking tie with the old
2790 * address. Then see whether we could
2791 * link certain vhaddr to the new address.
2792 * If that fails, i.e. carpdev is NULL,
2793 * we try a global update.
2795 * NOTE: The above order is critical.
2797 carp_unlink_addrs(sc
, ifp
, ifa
);
2798 carp_link_addrs(sc
, ifp
, ifa
);
2799 if (sc
->sc_carpdev
== NULL
) {
2801 * See the comment in the above
2802 * IFADDR_EVENT_DELETE block.
2804 carp_update_addrs(sc
, NULL
);
2816 carp_proto_ctlinput(netmsg_t msg
)
2818 int cmd
= msg
->ctlinput
.nm_cmd
;
2819 struct sockaddr
*sa
= msg
->ctlinput
.nm_arg
;
2820 struct in_ifaddr_container
*iac
;
2824 TAILQ_FOREACH(iac
, &in_ifaddrheads
[mycpuid
], ia_link
) {
2825 struct in_ifaddr
*ia
= iac
->ia
;
2826 struct ifnet
*ifp
= ia
->ia_ifp
;
2828 if (ifp
->if_type
== IFT_CARP
)
2831 if (ia
->ia_ifa
.ifa_addr
== sa
) {
2832 if (cmd
== PRC_IFDOWN
) {
2833 carp_ifaddr(NULL
, ifp
, IFADDR_EVENT_DELETE
,
2835 } else if (cmd
== PRC_IFUP
) {
2836 carp_ifaddr(NULL
, ifp
, IFADDR_EVENT_ADD
,
2844 lwkt_replymsg(&msg
->lmsg
, 0);
2850 lwkt_gettoken(&carp_tok
);
2856 lwkt_reltoken(&carp_tok
);
2860 carp_parent(struct ifnet
*cifp
)
2862 struct carp_softc
*sc
;
2864 ASSERT_LWKT_TOKEN_HELD(&carp_tok
);
2866 KKASSERT(cifp
->if_type
== IFT_CARP
);
2867 sc
= cifp
->if_softc
;
2869 return sc
->sc_carpdev
;
2872 #define rtinitflags(x) \
2873 (((x)->ia_ifp->if_flags & (IFF_LOOPBACK | IFF_POINTOPOINT)) \
2877 carp_addroute_vhaddr(struct carp_softc
*sc
, struct carp_vhaddr
*vha
)
2879 struct in_ifaddr
*ia
, *iaback
;
2882 if (sc
->sc_state
!= MASTER
)
2886 KKASSERT(ia
!= NULL
);
2888 iaback
= vha
->vha_iaback
;
2889 KKASSERT(iaback
!= NULL
);
2891 rtinit(&iaback
->ia_ifa
, RTM_DELETE
, rtinitflags(iaback
));
2892 in_ifadown(&iaback
->ia_ifa
, 1);
2893 iaback
->ia_flags
&= ~IFA_ROUTE
;
2895 error
= rtinit(&ia
->ia_ifa
, RTM_ADD
, rtinitflags(ia
) | RTF_UP
);
2897 ia
->ia_flags
|= IFA_ROUTE
;
2902 carp_delroute_vhaddr(struct carp_softc
*sc
, struct carp_vhaddr
*vha
,
2903 boolean_t del_iaback
)
2905 struct in_ifaddr
*ia
, *iaback
;
2908 KKASSERT(ia
!= NULL
);
2910 iaback
= vha
->vha_iaback
;
2911 KKASSERT(iaback
!= NULL
);
2913 rtinit(&ia
->ia_ifa
, RTM_DELETE
, rtinitflags(ia
));
2914 in_ifadown(&ia
->ia_ifa
, 1);
2915 ia
->ia_flags
&= ~IFA_ROUTE
;
2917 if (!del_iaback
&& (iaback
->ia_ifp
->if_flags
& IFF_UP
)) {
2920 error
= rtinit(&iaback
->ia_ifa
, RTM_ADD
,
2921 rtinitflags(iaback
) | RTF_UP
);
2923 iaback
->ia_flags
|= IFA_ROUTE
;
2928 carp_modevent(module_t mod
, int type
, void *data
)
2932 LIST_INIT(&carpif_list
);
2933 carp_ifdetach_event
=
2934 EVENTHANDLER_REGISTER(ifnet_detach_event
, carp_ifdetach
, NULL
,
2935 EVENTHANDLER_PRI_ANY
);
2937 EVENTHANDLER_REGISTER(ifaddr_event
, carp_ifaddr
, NULL
,
2938 EVENTHANDLER_PRI_FIRST
);
2939 if_clone_attach(&carp_cloner
);
2943 EVENTHANDLER_DEREGISTER(ifnet_detach_event
,
2944 carp_ifdetach_event
);
2945 EVENTHANDLER_DEREGISTER(ifaddr_event
,
2947 if_clone_detach(&carp_cloner
);
2956 static moduledata_t carp_mod
= {
2961 DECLARE_MODULE(carp
, carp_mod
, SI_SUB_PSEUDO
, SI_ORDER_ANY
);