3 * Linux INET6 implementation
6 * Pedro Roque <roque@di.fc.ul.pt>
8 * This program is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU General Public License
10 * as published by the Free Software Foundation; either version
11 * 2 of the License, or (at your option) any later version.
14 #include <linux/capability.h>
15 #include <linux/errno.h>
16 #include <linux/types.h>
17 #include <linux/kernel.h>
18 #include <linux/interrupt.h>
19 #include <linux/socket.h>
20 #include <linux/sockios.h>
21 #include <linux/in6.h>
22 #include <linux/ipv6.h>
23 #include <linux/route.h>
24 #include <linux/slab.h>
27 #include <net/ndisc.h>
28 #include <net/addrconf.h>
29 #include <net/transp_v6.h>
30 #include <net/ip6_route.h>
31 #include <net/tcp_states.h>
33 #include <linux/errqueue.h>
34 #include <asm/uaccess.h>
36 int ip6_datagram_connect(struct sock
*sk
, struct sockaddr
*uaddr
, int addr_len
)
38 struct sockaddr_in6
*usin
= (struct sockaddr_in6
*) uaddr
;
39 struct inet_sock
*inet
= inet_sk(sk
);
40 struct ipv6_pinfo
*np
= inet6_sk(sk
);
41 struct in6_addr
*daddr
, *final_p
= NULL
, final
;
42 struct dst_entry
*dst
;
44 struct ip6_flowlabel
*flowlabel
= NULL
;
48 if (usin
->sin6_family
== AF_INET
) {
49 if (__ipv6_only_sock(sk
))
51 err
= ip4_datagram_connect(sk
, uaddr
, addr_len
);
55 if (addr_len
< SIN6_LEN_RFC2133
)
58 if (usin
->sin6_family
!= AF_INET6
)
61 memset(&fl
, 0, sizeof(fl
));
63 fl
.fl6_flowlabel
= usin
->sin6_flowinfo
&IPV6_FLOWINFO_MASK
;
64 if (fl
.fl6_flowlabel
&IPV6_FLOWLABEL_MASK
) {
65 flowlabel
= fl6_sock_lookup(sk
, fl
.fl6_flowlabel
);
66 if (flowlabel
== NULL
)
68 ipv6_addr_copy(&usin
->sin6_addr
, &flowlabel
->dst
);
72 addr_type
= ipv6_addr_type(&usin
->sin6_addr
);
74 if (addr_type
== IPV6_ADDR_ANY
) {
78 usin
->sin6_addr
.s6_addr
[15] = 0x01;
81 daddr
= &usin
->sin6_addr
;
83 if (addr_type
== IPV6_ADDR_MAPPED
) {
84 struct sockaddr_in sin
;
86 if (__ipv6_only_sock(sk
)) {
90 sin
.sin_family
= AF_INET
;
91 sin
.sin_addr
.s_addr
= daddr
->s6_addr32
[3];
92 sin
.sin_port
= usin
->sin6_port
;
94 err
= ip4_datagram_connect(sk
,
95 (struct sockaddr
*) &sin
,
102 ipv6_addr_set_v4mapped(inet
->inet_daddr
, &np
->daddr
);
104 if (ipv6_addr_any(&np
->saddr
))
105 ipv6_addr_set_v4mapped(inet
->inet_saddr
, &np
->saddr
);
107 if (ipv6_addr_any(&np
->rcv_saddr
))
108 ipv6_addr_set_v4mapped(inet
->inet_rcv_saddr
,
114 if (addr_type
&IPV6_ADDR_LINKLOCAL
) {
115 if (addr_len
>= sizeof(struct sockaddr_in6
) &&
116 usin
->sin6_scope_id
) {
117 if (sk
->sk_bound_dev_if
&&
118 sk
->sk_bound_dev_if
!= usin
->sin6_scope_id
) {
122 sk
->sk_bound_dev_if
= usin
->sin6_scope_id
;
125 if (!sk
->sk_bound_dev_if
&& (addr_type
& IPV6_ADDR_MULTICAST
))
126 sk
->sk_bound_dev_if
= np
->mcast_oif
;
128 /* Connect to link-local address requires an interface */
129 if (!sk
->sk_bound_dev_if
) {
135 ipv6_addr_copy(&np
->daddr
, daddr
);
136 np
->flow_label
= fl
.fl6_flowlabel
;
138 inet
->inet_dport
= usin
->sin6_port
;
141 * Check for a route to destination an obtain the
142 * destination cache for it.
145 fl
.proto
= sk
->sk_protocol
;
146 ipv6_addr_copy(&fl
.fl6_dst
, &np
->daddr
);
147 ipv6_addr_copy(&fl
.fl6_src
, &np
->saddr
);
148 fl
.oif
= sk
->sk_bound_dev_if
;
149 fl
.mark
= sk
->sk_mark
;
150 fl
.fl_ip_dport
= inet
->inet_dport
;
151 fl
.fl_ip_sport
= inet
->inet_sport
;
153 if (!fl
.oif
&& (addr_type
&IPV6_ADDR_MULTICAST
))
154 fl
.oif
= np
->mcast_oif
;
156 security_sk_classify_flow(sk
, &fl
);
159 if (flowlabel
->opt
&& flowlabel
->opt
->srcrt
) {
160 struct rt0_hdr
*rt0
= (struct rt0_hdr
*) flowlabel
->opt
->srcrt
;
161 ipv6_addr_copy(&final
, &fl
.fl6_dst
);
162 ipv6_addr_copy(&fl
.fl6_dst
, rt0
->addr
);
165 } else if (np
->opt
&& np
->opt
->srcrt
) {
166 struct rt0_hdr
*rt0
= (struct rt0_hdr
*)np
->opt
->srcrt
;
167 ipv6_addr_copy(&final
, &fl
.fl6_dst
);
168 ipv6_addr_copy(&fl
.fl6_dst
, rt0
->addr
);
172 err
= ip6_dst_lookup(sk
, &dst
, &fl
);
176 ipv6_addr_copy(&fl
.fl6_dst
, final_p
);
178 err
= __xfrm_lookup(sock_net(sk
), &dst
, &fl
, sk
, XFRM_LOOKUP_WAIT
);
181 err
= ip6_dst_blackhole(sk
, &dst
, &fl
);
186 /* source address lookup done in ip6_dst_lookup */
188 if (ipv6_addr_any(&np
->saddr
))
189 ipv6_addr_copy(&np
->saddr
, &fl
.fl6_src
);
191 if (ipv6_addr_any(&np
->rcv_saddr
)) {
192 ipv6_addr_copy(&np
->rcv_saddr
, &fl
.fl6_src
);
193 inet
->inet_rcv_saddr
= LOOPBACK4_IPV6
;
196 ip6_dst_store(sk
, dst
,
197 ipv6_addr_equal(&fl
.fl6_dst
, &np
->daddr
) ?
199 #ifdef CONFIG_IPV6_SUBTREES
200 ipv6_addr_equal(&fl
.fl6_src
, &np
->saddr
) ?
205 sk
->sk_state
= TCP_ESTABLISHED
;
207 fl6_sock_release(flowlabel
);
211 void ipv6_icmp_error(struct sock
*sk
, struct sk_buff
*skb
, int err
,
212 __be16 port
, u32 info
, u8
*payload
)
214 struct ipv6_pinfo
*np
= inet6_sk(sk
);
215 struct icmp6hdr
*icmph
= icmp6_hdr(skb
);
216 struct sock_exterr_skb
*serr
;
221 skb
= skb_clone(skb
, GFP_ATOMIC
);
225 skb
->protocol
= htons(ETH_P_IPV6
);
227 serr
= SKB_EXT_ERR(skb
);
228 serr
->ee
.ee_errno
= err
;
229 serr
->ee
.ee_origin
= SO_EE_ORIGIN_ICMP6
;
230 serr
->ee
.ee_type
= icmph
->icmp6_type
;
231 serr
->ee
.ee_code
= icmph
->icmp6_code
;
233 serr
->ee
.ee_info
= info
;
234 serr
->ee
.ee_data
= 0;
235 serr
->addr_offset
= (u8
*)&(((struct ipv6hdr
*)(icmph
+ 1))->daddr
) -
236 skb_network_header(skb
);
239 __skb_pull(skb
, payload
- skb
->data
);
240 skb_reset_transport_header(skb
);
242 if (sock_queue_err_skb(sk
, skb
))
246 void ipv6_local_error(struct sock
*sk
, int err
, struct flowi
*fl
, u32 info
)
248 struct ipv6_pinfo
*np
= inet6_sk(sk
);
249 struct sock_exterr_skb
*serr
;
256 skb
= alloc_skb(sizeof(struct ipv6hdr
), GFP_ATOMIC
);
260 skb
->protocol
= htons(ETH_P_IPV6
);
262 skb_put(skb
, sizeof(struct ipv6hdr
));
263 skb_reset_network_header(skb
);
265 ipv6_addr_copy(&iph
->daddr
, &fl
->fl6_dst
);
267 serr
= SKB_EXT_ERR(skb
);
268 serr
->ee
.ee_errno
= err
;
269 serr
->ee
.ee_origin
= SO_EE_ORIGIN_LOCAL
;
270 serr
->ee
.ee_type
= 0;
271 serr
->ee
.ee_code
= 0;
273 serr
->ee
.ee_info
= info
;
274 serr
->ee
.ee_data
= 0;
275 serr
->addr_offset
= (u8
*)&iph
->daddr
- skb_network_header(skb
);
276 serr
->port
= fl
->fl_ip_dport
;
278 __skb_pull(skb
, skb_tail_pointer(skb
) - skb
->data
);
279 skb_reset_transport_header(skb
);
281 if (sock_queue_err_skb(sk
, skb
))
285 void ipv6_local_rxpmtu(struct sock
*sk
, struct flowi
*fl
, u32 mtu
)
287 struct ipv6_pinfo
*np
= inet6_sk(sk
);
290 struct ip6_mtuinfo
*mtu_info
;
292 if (!np
->rxopt
.bits
.rxpmtu
)
295 skb
= alloc_skb(sizeof(struct ipv6hdr
), GFP_ATOMIC
);
299 skb_put(skb
, sizeof(struct ipv6hdr
));
300 skb_reset_network_header(skb
);
302 ipv6_addr_copy(&iph
->daddr
, &fl
->fl6_dst
);
304 mtu_info
= IP6CBMTU(skb
);
310 mtu_info
->ip6m_mtu
= mtu
;
311 mtu_info
->ip6m_addr
.sin6_family
= AF_INET6
;
312 mtu_info
->ip6m_addr
.sin6_port
= 0;
313 mtu_info
->ip6m_addr
.sin6_flowinfo
= 0;
314 mtu_info
->ip6m_addr
.sin6_scope_id
= fl
->oif
;
315 ipv6_addr_copy(&mtu_info
->ip6m_addr
.sin6_addr
, &ipv6_hdr(skb
)->daddr
);
317 __skb_pull(skb
, skb_tail_pointer(skb
) - skb
->data
);
318 skb_reset_transport_header(skb
);
320 skb
= xchg(&np
->rxpmtu
, skb
);
325 * Handle MSG_ERRQUEUE
327 int ipv6_recv_error(struct sock
*sk
, struct msghdr
*msg
, int len
)
329 struct ipv6_pinfo
*np
= inet6_sk(sk
);
330 struct sock_exterr_skb
*serr
;
331 struct sk_buff
*skb
, *skb2
;
332 struct sockaddr_in6
*sin
;
334 struct sock_extended_err ee
;
335 struct sockaddr_in6 offender
;
341 skb
= skb_dequeue(&sk
->sk_error_queue
);
347 msg
->msg_flags
|= MSG_TRUNC
;
350 err
= skb_copy_datagram_iovec(skb
, 0, msg
->msg_iov
, copied
);
354 sock_recv_timestamp(msg
, sk
, skb
);
356 serr
= SKB_EXT_ERR(skb
);
358 sin
= (struct sockaddr_in6
*)msg
->msg_name
;
360 const unsigned char *nh
= skb_network_header(skb
);
361 sin
->sin6_family
= AF_INET6
;
362 sin
->sin6_flowinfo
= 0;
363 sin
->sin6_port
= serr
->port
;
364 sin
->sin6_scope_id
= 0;
365 if (skb
->protocol
== htons(ETH_P_IPV6
)) {
366 ipv6_addr_copy(&sin
->sin6_addr
,
367 (struct in6_addr
*)(nh
+ serr
->addr_offset
));
370 (*(__be32
*)(nh
+ serr
->addr_offset
- 24) &
372 if (ipv6_addr_type(&sin
->sin6_addr
) & IPV6_ADDR_LINKLOCAL
)
373 sin
->sin6_scope_id
= IP6CB(skb
)->iif
;
375 ipv6_addr_set_v4mapped(*(__be32
*)(nh
+ serr
->addr_offset
),
380 memcpy(&errhdr
.ee
, &serr
->ee
, sizeof(struct sock_extended_err
));
381 sin
= &errhdr
.offender
;
382 sin
->sin6_family
= AF_UNSPEC
;
383 if (serr
->ee
.ee_origin
!= SO_EE_ORIGIN_LOCAL
) {
384 sin
->sin6_family
= AF_INET6
;
385 sin
->sin6_flowinfo
= 0;
386 sin
->sin6_scope_id
= 0;
387 if (skb
->protocol
== htons(ETH_P_IPV6
)) {
388 ipv6_addr_copy(&sin
->sin6_addr
, &ipv6_hdr(skb
)->saddr
);
390 datagram_recv_ctl(sk
, msg
, skb
);
391 if (ipv6_addr_type(&sin
->sin6_addr
) & IPV6_ADDR_LINKLOCAL
)
392 sin
->sin6_scope_id
= IP6CB(skb
)->iif
;
394 struct inet_sock
*inet
= inet_sk(sk
);
396 ipv6_addr_set_v4mapped(ip_hdr(skb
)->saddr
,
398 if (inet
->cmsg_flags
)
399 ip_cmsg_recv(msg
, skb
);
403 put_cmsg(msg
, SOL_IPV6
, IPV6_RECVERR
, sizeof(errhdr
), &errhdr
);
405 /* Now we could try to dump offended packet options */
407 msg
->msg_flags
|= MSG_ERRQUEUE
;
410 /* Reset and regenerate socket error */
411 spin_lock_bh(&sk
->sk_error_queue
.lock
);
413 if ((skb2
= skb_peek(&sk
->sk_error_queue
)) != NULL
) {
414 sk
->sk_err
= SKB_EXT_ERR(skb2
)->ee
.ee_errno
;
415 spin_unlock_bh(&sk
->sk_error_queue
.lock
);
416 sk
->sk_error_report(sk
);
418 spin_unlock_bh(&sk
->sk_error_queue
.lock
);
428 * Handle IPV6_RECVPATHMTU
430 int ipv6_recv_rxpmtu(struct sock
*sk
, struct msghdr
*msg
, int len
)
432 struct ipv6_pinfo
*np
= inet6_sk(sk
);
434 struct sockaddr_in6
*sin
;
435 struct ip6_mtuinfo mtu_info
;
440 skb
= xchg(&np
->rxpmtu
, NULL
);
446 msg
->msg_flags
|= MSG_TRUNC
;
449 err
= skb_copy_datagram_iovec(skb
, 0, msg
->msg_iov
, copied
);
453 sock_recv_timestamp(msg
, sk
, skb
);
455 memcpy(&mtu_info
, IP6CBMTU(skb
), sizeof(mtu_info
));
457 sin
= (struct sockaddr_in6
*)msg
->msg_name
;
459 sin
->sin6_family
= AF_INET6
;
460 sin
->sin6_flowinfo
= 0;
462 sin
->sin6_scope_id
= mtu_info
.ip6m_addr
.sin6_scope_id
;
463 ipv6_addr_copy(&sin
->sin6_addr
, &mtu_info
.ip6m_addr
.sin6_addr
);
466 put_cmsg(msg
, SOL_IPV6
, IPV6_PATHMTU
, sizeof(mtu_info
), &mtu_info
);
477 int datagram_recv_ctl(struct sock
*sk
, struct msghdr
*msg
, struct sk_buff
*skb
)
479 struct ipv6_pinfo
*np
= inet6_sk(sk
);
480 struct inet6_skb_parm
*opt
= IP6CB(skb
);
481 unsigned char *nh
= skb_network_header(skb
);
483 if (np
->rxopt
.bits
.rxinfo
) {
484 struct in6_pktinfo src_info
;
486 src_info
.ipi6_ifindex
= opt
->iif
;
487 ipv6_addr_copy(&src_info
.ipi6_addr
, &ipv6_hdr(skb
)->daddr
);
488 put_cmsg(msg
, SOL_IPV6
, IPV6_PKTINFO
, sizeof(src_info
), &src_info
);
491 if (np
->rxopt
.bits
.rxhlim
) {
492 int hlim
= ipv6_hdr(skb
)->hop_limit
;
493 put_cmsg(msg
, SOL_IPV6
, IPV6_HOPLIMIT
, sizeof(hlim
), &hlim
);
496 if (np
->rxopt
.bits
.rxtclass
) {
497 int tclass
= (ntohl(*(__be32
*)ipv6_hdr(skb
)) >> 20) & 0xff;
498 put_cmsg(msg
, SOL_IPV6
, IPV6_TCLASS
, sizeof(tclass
), &tclass
);
501 if (np
->rxopt
.bits
.rxflow
&& (*(__be32
*)nh
& IPV6_FLOWINFO_MASK
)) {
502 __be32 flowinfo
= *(__be32
*)nh
& IPV6_FLOWINFO_MASK
;
503 put_cmsg(msg
, SOL_IPV6
, IPV6_FLOWINFO
, sizeof(flowinfo
), &flowinfo
);
506 /* HbH is allowed only once */
507 if (np
->rxopt
.bits
.hopopts
&& opt
->hop
) {
508 u8
*ptr
= nh
+ opt
->hop
;
509 put_cmsg(msg
, SOL_IPV6
, IPV6_HOPOPTS
, (ptr
[1]+1)<<3, ptr
);
513 (np
->rxopt
.bits
.dstopts
|| np
->rxopt
.bits
.srcrt
)) {
515 * Silly enough, but we need to reparse in order to
516 * report extension headers (except for HbH)
519 * Also note that IPV6_RECVRTHDRDSTOPTS is NOT
520 * (and WILL NOT be) defined because
521 * IPV6_RECVDSTOPTS is more generic. --yoshfuji
523 unsigned int off
= sizeof(struct ipv6hdr
);
524 u8 nexthdr
= ipv6_hdr(skb
)->nexthdr
;
526 while (off
<= opt
->lastopt
) {
531 case IPPROTO_DSTOPTS
:
533 len
= (ptr
[1] + 1) << 3;
534 if (np
->rxopt
.bits
.dstopts
)
535 put_cmsg(msg
, SOL_IPV6
, IPV6_DSTOPTS
, len
, ptr
);
537 case IPPROTO_ROUTING
:
539 len
= (ptr
[1] + 1) << 3;
540 if (np
->rxopt
.bits
.srcrt
)
541 put_cmsg(msg
, SOL_IPV6
, IPV6_RTHDR
, len
, ptr
);
545 len
= (ptr
[1] + 2) << 2;
549 len
= (ptr
[1] + 1) << 3;
557 /* socket options in old style */
558 if (np
->rxopt
.bits
.rxoinfo
) {
559 struct in6_pktinfo src_info
;
561 src_info
.ipi6_ifindex
= opt
->iif
;
562 ipv6_addr_copy(&src_info
.ipi6_addr
, &ipv6_hdr(skb
)->daddr
);
563 put_cmsg(msg
, SOL_IPV6
, IPV6_2292PKTINFO
, sizeof(src_info
), &src_info
);
565 if (np
->rxopt
.bits
.rxohlim
) {
566 int hlim
= ipv6_hdr(skb
)->hop_limit
;
567 put_cmsg(msg
, SOL_IPV6
, IPV6_2292HOPLIMIT
, sizeof(hlim
), &hlim
);
569 if (np
->rxopt
.bits
.ohopopts
&& opt
->hop
) {
570 u8
*ptr
= nh
+ opt
->hop
;
571 put_cmsg(msg
, SOL_IPV6
, IPV6_2292HOPOPTS
, (ptr
[1]+1)<<3, ptr
);
573 if (np
->rxopt
.bits
.odstopts
&& opt
->dst0
) {
574 u8
*ptr
= nh
+ opt
->dst0
;
575 put_cmsg(msg
, SOL_IPV6
, IPV6_2292DSTOPTS
, (ptr
[1]+1)<<3, ptr
);
577 if (np
->rxopt
.bits
.osrcrt
&& opt
->srcrt
) {
578 struct ipv6_rt_hdr
*rthdr
= (struct ipv6_rt_hdr
*)(nh
+ opt
->srcrt
);
579 put_cmsg(msg
, SOL_IPV6
, IPV6_2292RTHDR
, (rthdr
->hdrlen
+1) << 3, rthdr
);
581 if (np
->rxopt
.bits
.odstopts
&& opt
->dst1
) {
582 u8
*ptr
= nh
+ opt
->dst1
;
583 put_cmsg(msg
, SOL_IPV6
, IPV6_2292DSTOPTS
, (ptr
[1]+1)<<3, ptr
);
588 int datagram_send_ctl(struct net
*net
,
589 struct msghdr
*msg
, struct flowi
*fl
,
590 struct ipv6_txoptions
*opt
,
591 int *hlimit
, int *tclass
, int *dontfrag
)
593 struct in6_pktinfo
*src_info
;
594 struct cmsghdr
*cmsg
;
595 struct ipv6_rt_hdr
*rthdr
;
596 struct ipv6_opt_hdr
*hdr
;
600 for (cmsg
= CMSG_FIRSTHDR(msg
); cmsg
; cmsg
= CMSG_NXTHDR(msg
, cmsg
)) {
603 if (!CMSG_OK(msg
, cmsg
)) {
608 if (cmsg
->cmsg_level
!= SOL_IPV6
)
611 switch (cmsg
->cmsg_type
) {
613 case IPV6_2292PKTINFO
:
615 struct net_device
*dev
= NULL
;
617 if (cmsg
->cmsg_len
< CMSG_LEN(sizeof(struct in6_pktinfo
))) {
622 src_info
= (struct in6_pktinfo
*)CMSG_DATA(cmsg
);
624 if (src_info
->ipi6_ifindex
) {
625 if (fl
->oif
&& src_info
->ipi6_ifindex
!= fl
->oif
)
627 fl
->oif
= src_info
->ipi6_ifindex
;
630 addr_type
= __ipv6_addr_type(&src_info
->ipi6_addr
);
634 dev
= dev_get_by_index_rcu(net
, fl
->oif
);
639 } else if (addr_type
& IPV6_ADDR_LINKLOCAL
) {
644 if (addr_type
!= IPV6_ADDR_ANY
) {
645 int strict
= __ipv6_addr_src_scope(addr_type
) <= IPV6_ADDR_SCOPE_LINKLOCAL
;
646 if (!ipv6_chk_addr(net
, &src_info
->ipi6_addr
,
647 strict
? dev
: NULL
, 0))
650 ipv6_addr_copy(&fl
->fl6_src
, &src_info
->ipi6_addr
);
662 if (cmsg
->cmsg_len
< CMSG_LEN(4)) {
667 if (fl
->fl6_flowlabel
&IPV6_FLOWINFO_MASK
) {
668 if ((fl
->fl6_flowlabel
^*(__be32
*)CMSG_DATA(cmsg
))&~IPV6_FLOWINFO_MASK
) {
673 fl
->fl6_flowlabel
= IPV6_FLOWINFO_MASK
& *(__be32
*)CMSG_DATA(cmsg
);
676 case IPV6_2292HOPOPTS
:
678 if (opt
->hopopt
|| cmsg
->cmsg_len
< CMSG_LEN(sizeof(struct ipv6_opt_hdr
))) {
683 hdr
= (struct ipv6_opt_hdr
*)CMSG_DATA(cmsg
);
684 len
= ((hdr
->hdrlen
+ 1) << 3);
685 if (cmsg
->cmsg_len
< CMSG_LEN(len
)) {
689 if (!capable(CAP_NET_RAW
)) {
693 opt
->opt_nflen
+= len
;
697 case IPV6_2292DSTOPTS
:
698 if (cmsg
->cmsg_len
< CMSG_LEN(sizeof(struct ipv6_opt_hdr
))) {
703 hdr
= (struct ipv6_opt_hdr
*)CMSG_DATA(cmsg
);
704 len
= ((hdr
->hdrlen
+ 1) << 3);
705 if (cmsg
->cmsg_len
< CMSG_LEN(len
)) {
709 if (!capable(CAP_NET_RAW
)) {
717 opt
->opt_flen
+= len
;
722 case IPV6_RTHDRDSTOPTS
:
723 if (cmsg
->cmsg_len
< CMSG_LEN(sizeof(struct ipv6_opt_hdr
))) {
728 hdr
= (struct ipv6_opt_hdr
*)CMSG_DATA(cmsg
);
729 len
= ((hdr
->hdrlen
+ 1) << 3);
730 if (cmsg
->cmsg_len
< CMSG_LEN(len
)) {
734 if (!capable(CAP_NET_RAW
)) {
738 if (cmsg
->cmsg_type
== IPV6_DSTOPTS
) {
739 opt
->opt_flen
+= len
;
742 opt
->opt_nflen
+= len
;
749 if (cmsg
->cmsg_len
< CMSG_LEN(sizeof(struct ipv6_rt_hdr
))) {
754 rthdr
= (struct ipv6_rt_hdr
*)CMSG_DATA(cmsg
);
756 switch (rthdr
->type
) {
757 #if defined(CONFIG_IPV6_MIP6) || defined(CONFIG_IPV6_MIP6_MODULE)
758 case IPV6_SRCRT_TYPE_2
:
759 if (rthdr
->hdrlen
!= 2 ||
760 rthdr
->segments_left
!= 1) {
771 len
= ((rthdr
->hdrlen
+ 1) << 3);
773 if (cmsg
->cmsg_len
< CMSG_LEN(len
)) {
778 /* segments left must also match */
779 if ((rthdr
->hdrlen
>> 1) != rthdr
->segments_left
) {
784 opt
->opt_nflen
+= len
;
787 if (cmsg
->cmsg_type
== IPV6_2292RTHDR
&& opt
->dst1opt
) {
788 int dsthdrlen
= ((opt
->dst1opt
->hdrlen
+1)<<3);
790 opt
->opt_nflen
+= dsthdrlen
;
791 opt
->dst0opt
= opt
->dst1opt
;
793 opt
->opt_flen
-= dsthdrlen
;
798 case IPV6_2292HOPLIMIT
:
800 if (cmsg
->cmsg_len
!= CMSG_LEN(sizeof(int))) {
805 *hlimit
= *(int *)CMSG_DATA(cmsg
);
806 if (*hlimit
< -1 || *hlimit
> 0xff) {
818 if (cmsg
->cmsg_len
!= CMSG_LEN(sizeof(int))) {
822 tc
= *(int *)CMSG_DATA(cmsg
);
823 if (tc
< -1 || tc
> 0xff)
837 if (cmsg
->cmsg_len
!= CMSG_LEN(sizeof(int))) {
841 df
= *(int *)CMSG_DATA(cmsg
);
842 if (df
< 0 || df
> 1)
851 LIMIT_NETDEBUG(KERN_DEBUG
"invalid cmsg type: %d\n",