[NETFILTER]: don't use nested attributes for conntrack_expect
[linux-2.6/mini2440.git] / net / ipv4 / fib_frontend.c
blobb5e2f1550c91cc08b4b71cdb14d699f188f678b2
1 /*
2 * INET An implementation of the TCP/IP protocol suite for the LINUX
3 * operating system. INET is implemented using the BSD Socket
4 * interface as the means of communication with the user level.
6 * IPv4 Forwarding Information Base: FIB frontend.
8 * Version: $Id: fib_frontend.c,v 1.26 2001/10/31 21:55:54 davem Exp $
10 * Authors: Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
12 * This program is free software; you can redistribute it and/or
13 * modify it under the terms of the GNU General Public License
14 * as published by the Free Software Foundation; either version
15 * 2 of the License, or (at your option) any later version.
18 #include <linux/config.h>
19 #include <linux/module.h>
20 #include <asm/uaccess.h>
21 #include <asm/system.h>
22 #include <linux/bitops.h>
23 #include <linux/types.h>
24 #include <linux/kernel.h>
25 #include <linux/sched.h>
26 #include <linux/mm.h>
27 #include <linux/string.h>
28 #include <linux/socket.h>
29 #include <linux/sockios.h>
30 #include <linux/errno.h>
31 #include <linux/in.h>
32 #include <linux/inet.h>
33 #include <linux/netdevice.h>
34 #include <linux/if_arp.h>
35 #include <linux/skbuff.h>
36 #include <linux/netlink.h>
37 #include <linux/init.h>
39 #include <net/ip.h>
40 #include <net/protocol.h>
41 #include <net/route.h>
42 #include <net/tcp.h>
43 #include <net/sock.h>
44 #include <net/icmp.h>
45 #include <net/arp.h>
46 #include <net/ip_fib.h>
48 #define FFprint(a...) printk(KERN_DEBUG a)
50 #ifndef CONFIG_IP_MULTIPLE_TABLES
52 #define RT_TABLE_MIN RT_TABLE_MAIN
54 struct fib_table *ip_fib_local_table;
55 struct fib_table *ip_fib_main_table;
57 #else
59 #define RT_TABLE_MIN 1
61 struct fib_table *fib_tables[RT_TABLE_MAX+1];
63 struct fib_table *__fib_new_table(int id)
65 struct fib_table *tb;
67 tb = fib_hash_init(id);
68 if (!tb)
69 return NULL;
70 fib_tables[id] = tb;
71 return tb;
75 #endif /* CONFIG_IP_MULTIPLE_TABLES */
78 static void fib_flush(void)
80 int flushed = 0;
81 #ifdef CONFIG_IP_MULTIPLE_TABLES
82 struct fib_table *tb;
83 int id;
85 for (id = RT_TABLE_MAX; id>0; id--) {
86 if ((tb = fib_get_table(id))==NULL)
87 continue;
88 flushed += tb->tb_flush(tb);
90 #else /* CONFIG_IP_MULTIPLE_TABLES */
91 flushed += ip_fib_main_table->tb_flush(ip_fib_main_table);
92 flushed += ip_fib_local_table->tb_flush(ip_fib_local_table);
93 #endif /* CONFIG_IP_MULTIPLE_TABLES */
95 if (flushed)
96 rt_cache_flush(-1);
100 * Find the first device with a given source address.
103 struct net_device * ip_dev_find(u32 addr)
105 struct flowi fl = { .nl_u = { .ip4_u = { .daddr = addr } } };
106 struct fib_result res;
107 struct net_device *dev = NULL;
109 #ifdef CONFIG_IP_MULTIPLE_TABLES
110 res.r = NULL;
111 #endif
113 if (!ip_fib_local_table ||
114 ip_fib_local_table->tb_lookup(ip_fib_local_table, &fl, &res))
115 return NULL;
116 if (res.type != RTN_LOCAL)
117 goto out;
118 dev = FIB_RES_DEV(res);
120 if (dev)
121 dev_hold(dev);
122 out:
123 fib_res_put(&res);
124 return dev;
127 unsigned inet_addr_type(u32 addr)
129 struct flowi fl = { .nl_u = { .ip4_u = { .daddr = addr } } };
130 struct fib_result res;
131 unsigned ret = RTN_BROADCAST;
133 if (ZERONET(addr) || BADCLASS(addr))
134 return RTN_BROADCAST;
135 if (MULTICAST(addr))
136 return RTN_MULTICAST;
138 #ifdef CONFIG_IP_MULTIPLE_TABLES
139 res.r = NULL;
140 #endif
142 if (ip_fib_local_table) {
143 ret = RTN_UNICAST;
144 if (!ip_fib_local_table->tb_lookup(ip_fib_local_table,
145 &fl, &res)) {
146 ret = res.type;
147 fib_res_put(&res);
150 return ret;
153 /* Given (packet source, input interface) and optional (dst, oif, tos):
154 - (main) check, that source is valid i.e. not broadcast or our local
155 address.
156 - figure out what "logical" interface this packet arrived
157 and calculate "specific destination" address.
158 - check, that packet arrived from expected physical interface.
161 int fib_validate_source(u32 src, u32 dst, u8 tos, int oif,
162 struct net_device *dev, u32 *spec_dst, u32 *itag)
164 struct in_device *in_dev;
165 struct flowi fl = { .nl_u = { .ip4_u =
166 { .daddr = src,
167 .saddr = dst,
168 .tos = tos } },
169 .iif = oif };
170 struct fib_result res;
171 int no_addr, rpf;
172 int ret;
174 no_addr = rpf = 0;
175 rcu_read_lock();
176 in_dev = __in_dev_get(dev);
177 if (in_dev) {
178 no_addr = in_dev->ifa_list == NULL;
179 rpf = IN_DEV_RPFILTER(in_dev);
181 rcu_read_unlock();
183 if (in_dev == NULL)
184 goto e_inval;
186 if (fib_lookup(&fl, &res))
187 goto last_resort;
188 if (res.type != RTN_UNICAST)
189 goto e_inval_res;
190 *spec_dst = FIB_RES_PREFSRC(res);
191 fib_combine_itag(itag, &res);
192 #ifdef CONFIG_IP_ROUTE_MULTIPATH
193 if (FIB_RES_DEV(res) == dev || res.fi->fib_nhs > 1)
194 #else
195 if (FIB_RES_DEV(res) == dev)
196 #endif
198 ret = FIB_RES_NH(res).nh_scope >= RT_SCOPE_HOST;
199 fib_res_put(&res);
200 return ret;
202 fib_res_put(&res);
203 if (no_addr)
204 goto last_resort;
205 if (rpf)
206 goto e_inval;
207 fl.oif = dev->ifindex;
209 ret = 0;
210 if (fib_lookup(&fl, &res) == 0) {
211 if (res.type == RTN_UNICAST) {
212 *spec_dst = FIB_RES_PREFSRC(res);
213 ret = FIB_RES_NH(res).nh_scope >= RT_SCOPE_HOST;
215 fib_res_put(&res);
217 return ret;
219 last_resort:
220 if (rpf)
221 goto e_inval;
222 *spec_dst = inet_select_addr(dev, 0, RT_SCOPE_UNIVERSE);
223 *itag = 0;
224 return 0;
226 e_inval_res:
227 fib_res_put(&res);
228 e_inval:
229 return -EINVAL;
232 #ifndef CONFIG_IP_NOSIOCRT
235 * Handle IP routing ioctl calls. These are used to manipulate the routing tables
238 int ip_rt_ioctl(unsigned int cmd, void __user *arg)
240 int err;
241 struct kern_rta rta;
242 struct rtentry r;
243 struct {
244 struct nlmsghdr nlh;
245 struct rtmsg rtm;
246 } req;
248 switch (cmd) {
249 case SIOCADDRT: /* Add a route */
250 case SIOCDELRT: /* Delete a route */
251 if (!capable(CAP_NET_ADMIN))
252 return -EPERM;
253 if (copy_from_user(&r, arg, sizeof(struct rtentry)))
254 return -EFAULT;
255 rtnl_lock();
256 err = fib_convert_rtentry(cmd, &req.nlh, &req.rtm, &rta, &r);
257 if (err == 0) {
258 if (cmd == SIOCDELRT) {
259 struct fib_table *tb = fib_get_table(req.rtm.rtm_table);
260 err = -ESRCH;
261 if (tb)
262 err = tb->tb_delete(tb, &req.rtm, &rta, &req.nlh, NULL);
263 } else {
264 struct fib_table *tb = fib_new_table(req.rtm.rtm_table);
265 err = -ENOBUFS;
266 if (tb)
267 err = tb->tb_insert(tb, &req.rtm, &rta, &req.nlh, NULL);
269 if (rta.rta_mx)
270 kfree(rta.rta_mx);
272 rtnl_unlock();
273 return err;
275 return -EINVAL;
278 #else
280 int ip_rt_ioctl(unsigned int cmd, void *arg)
282 return -EINVAL;
285 #endif
287 static int inet_check_attr(struct rtmsg *r, struct rtattr **rta)
289 int i;
291 for (i=1; i<=RTA_MAX; i++) {
292 struct rtattr *attr = rta[i-1];
293 if (attr) {
294 if (RTA_PAYLOAD(attr) < 4)
295 return -EINVAL;
296 if (i != RTA_MULTIPATH && i != RTA_METRICS)
297 rta[i-1] = (struct rtattr*)RTA_DATA(attr);
300 return 0;
303 int inet_rtm_delroute(struct sk_buff *skb, struct nlmsghdr* nlh, void *arg)
305 struct fib_table * tb;
306 struct rtattr **rta = arg;
307 struct rtmsg *r = NLMSG_DATA(nlh);
309 if (inet_check_attr(r, rta))
310 return -EINVAL;
312 tb = fib_get_table(r->rtm_table);
313 if (tb)
314 return tb->tb_delete(tb, r, (struct kern_rta*)rta, nlh, &NETLINK_CB(skb));
315 return -ESRCH;
318 int inet_rtm_newroute(struct sk_buff *skb, struct nlmsghdr* nlh, void *arg)
320 struct fib_table * tb;
321 struct rtattr **rta = arg;
322 struct rtmsg *r = NLMSG_DATA(nlh);
324 if (inet_check_attr(r, rta))
325 return -EINVAL;
327 tb = fib_new_table(r->rtm_table);
328 if (tb)
329 return tb->tb_insert(tb, r, (struct kern_rta*)rta, nlh, &NETLINK_CB(skb));
330 return -ENOBUFS;
333 int inet_dump_fib(struct sk_buff *skb, struct netlink_callback *cb)
335 int t;
336 int s_t;
337 struct fib_table *tb;
339 if (NLMSG_PAYLOAD(cb->nlh, 0) >= sizeof(struct rtmsg) &&
340 ((struct rtmsg*)NLMSG_DATA(cb->nlh))->rtm_flags&RTM_F_CLONED)
341 return ip_rt_dump(skb, cb);
343 s_t = cb->args[0];
344 if (s_t == 0)
345 s_t = cb->args[0] = RT_TABLE_MIN;
347 for (t=s_t; t<=RT_TABLE_MAX; t++) {
348 if (t < s_t) continue;
349 if (t > s_t)
350 memset(&cb->args[1], 0, sizeof(cb->args)-sizeof(cb->args[0]));
351 if ((tb = fib_get_table(t))==NULL)
352 continue;
353 if (tb->tb_dump(tb, skb, cb) < 0)
354 break;
357 cb->args[0] = t;
359 return skb->len;
362 /* Prepare and feed intra-kernel routing request.
363 Really, it should be netlink message, but :-( netlink
364 can be not configured, so that we feed it directly
365 to fib engine. It is legal, because all events occur
366 only when netlink is already locked.
369 static void fib_magic(int cmd, int type, u32 dst, int dst_len, struct in_ifaddr *ifa)
371 struct fib_table * tb;
372 struct {
373 struct nlmsghdr nlh;
374 struct rtmsg rtm;
375 } req;
376 struct kern_rta rta;
378 memset(&req.rtm, 0, sizeof(req.rtm));
379 memset(&rta, 0, sizeof(rta));
381 if (type == RTN_UNICAST)
382 tb = fib_new_table(RT_TABLE_MAIN);
383 else
384 tb = fib_new_table(RT_TABLE_LOCAL);
386 if (tb == NULL)
387 return;
389 req.nlh.nlmsg_len = sizeof(req);
390 req.nlh.nlmsg_type = cmd;
391 req.nlh.nlmsg_flags = NLM_F_REQUEST|NLM_F_CREATE|NLM_F_APPEND;
392 req.nlh.nlmsg_pid = 0;
393 req.nlh.nlmsg_seq = 0;
395 req.rtm.rtm_dst_len = dst_len;
396 req.rtm.rtm_table = tb->tb_id;
397 req.rtm.rtm_protocol = RTPROT_KERNEL;
398 req.rtm.rtm_scope = (type != RTN_LOCAL ? RT_SCOPE_LINK : RT_SCOPE_HOST);
399 req.rtm.rtm_type = type;
401 rta.rta_dst = &dst;
402 rta.rta_prefsrc = &ifa->ifa_local;
403 rta.rta_oif = &ifa->ifa_dev->dev->ifindex;
405 if (cmd == RTM_NEWROUTE)
406 tb->tb_insert(tb, &req.rtm, &rta, &req.nlh, NULL);
407 else
408 tb->tb_delete(tb, &req.rtm, &rta, &req.nlh, NULL);
411 static void fib_add_ifaddr(struct in_ifaddr *ifa)
413 struct in_device *in_dev = ifa->ifa_dev;
414 struct net_device *dev = in_dev->dev;
415 struct in_ifaddr *prim = ifa;
416 u32 mask = ifa->ifa_mask;
417 u32 addr = ifa->ifa_local;
418 u32 prefix = ifa->ifa_address&mask;
420 if (ifa->ifa_flags&IFA_F_SECONDARY) {
421 prim = inet_ifa_byprefix(in_dev, prefix, mask);
422 if (prim == NULL) {
423 printk(KERN_DEBUG "fib_add_ifaddr: bug: prim == NULL\n");
424 return;
428 fib_magic(RTM_NEWROUTE, RTN_LOCAL, addr, 32, prim);
430 if (!(dev->flags&IFF_UP))
431 return;
433 /* Add broadcast address, if it is explicitly assigned. */
434 if (ifa->ifa_broadcast && ifa->ifa_broadcast != 0xFFFFFFFF)
435 fib_magic(RTM_NEWROUTE, RTN_BROADCAST, ifa->ifa_broadcast, 32, prim);
437 if (!ZERONET(prefix) && !(ifa->ifa_flags&IFA_F_SECONDARY) &&
438 (prefix != addr || ifa->ifa_prefixlen < 32)) {
439 fib_magic(RTM_NEWROUTE, dev->flags&IFF_LOOPBACK ? RTN_LOCAL :
440 RTN_UNICAST, prefix, ifa->ifa_prefixlen, prim);
442 /* Add network specific broadcasts, when it takes a sense */
443 if (ifa->ifa_prefixlen < 31) {
444 fib_magic(RTM_NEWROUTE, RTN_BROADCAST, prefix, 32, prim);
445 fib_magic(RTM_NEWROUTE, RTN_BROADCAST, prefix|~mask, 32, prim);
450 static void fib_del_ifaddr(struct in_ifaddr *ifa)
452 struct in_device *in_dev = ifa->ifa_dev;
453 struct net_device *dev = in_dev->dev;
454 struct in_ifaddr *ifa1;
455 struct in_ifaddr *prim = ifa;
456 u32 brd = ifa->ifa_address|~ifa->ifa_mask;
457 u32 any = ifa->ifa_address&ifa->ifa_mask;
458 #define LOCAL_OK 1
459 #define BRD_OK 2
460 #define BRD0_OK 4
461 #define BRD1_OK 8
462 unsigned ok = 0;
464 if (!(ifa->ifa_flags&IFA_F_SECONDARY))
465 fib_magic(RTM_DELROUTE, dev->flags&IFF_LOOPBACK ? RTN_LOCAL :
466 RTN_UNICAST, any, ifa->ifa_prefixlen, prim);
467 else {
468 prim = inet_ifa_byprefix(in_dev, any, ifa->ifa_mask);
469 if (prim == NULL) {
470 printk(KERN_DEBUG "fib_del_ifaddr: bug: prim == NULL\n");
471 return;
475 /* Deletion is more complicated than add.
476 We should take care of not to delete too much :-)
478 Scan address list to be sure that addresses are really gone.
481 for (ifa1 = in_dev->ifa_list; ifa1; ifa1 = ifa1->ifa_next) {
482 if (ifa->ifa_local == ifa1->ifa_local)
483 ok |= LOCAL_OK;
484 if (ifa->ifa_broadcast == ifa1->ifa_broadcast)
485 ok |= BRD_OK;
486 if (brd == ifa1->ifa_broadcast)
487 ok |= BRD1_OK;
488 if (any == ifa1->ifa_broadcast)
489 ok |= BRD0_OK;
492 if (!(ok&BRD_OK))
493 fib_magic(RTM_DELROUTE, RTN_BROADCAST, ifa->ifa_broadcast, 32, prim);
494 if (!(ok&BRD1_OK))
495 fib_magic(RTM_DELROUTE, RTN_BROADCAST, brd, 32, prim);
496 if (!(ok&BRD0_OK))
497 fib_magic(RTM_DELROUTE, RTN_BROADCAST, any, 32, prim);
498 if (!(ok&LOCAL_OK)) {
499 fib_magic(RTM_DELROUTE, RTN_LOCAL, ifa->ifa_local, 32, prim);
501 /* Check, that this local address finally disappeared. */
502 if (inet_addr_type(ifa->ifa_local) != RTN_LOCAL) {
503 /* And the last, but not the least thing.
504 We must flush stray FIB entries.
506 First of all, we scan fib_info list searching
507 for stray nexthop entries, then ignite fib_flush.
509 if (fib_sync_down(ifa->ifa_local, NULL, 0))
510 fib_flush();
513 #undef LOCAL_OK
514 #undef BRD_OK
515 #undef BRD0_OK
516 #undef BRD1_OK
519 static void nl_fib_lookup(struct fib_result_nl *frn, struct fib_table *tb )
522 struct fib_result res;
523 struct flowi fl = { .nl_u = { .ip4_u = { .daddr = frn->fl_addr,
524 .fwmark = frn->fl_fwmark,
525 .tos = frn->fl_tos,
526 .scope = frn->fl_scope } } };
527 if (tb) {
528 local_bh_disable();
530 frn->tb_id = tb->tb_id;
531 frn->err = tb->tb_lookup(tb, &fl, &res);
533 if (!frn->err) {
534 frn->prefixlen = res.prefixlen;
535 frn->nh_sel = res.nh_sel;
536 frn->type = res.type;
537 frn->scope = res.scope;
539 local_bh_enable();
543 static void nl_fib_input(struct sock *sk, int len)
545 struct sk_buff *skb = NULL;
546 struct nlmsghdr *nlh = NULL;
547 struct fib_result_nl *frn;
548 int err;
549 u32 pid;
550 struct fib_table *tb;
552 skb = skb_recv_datagram(sk, 0, 0, &err);
553 nlh = (struct nlmsghdr *)skb->data;
555 frn = (struct fib_result_nl *) NLMSG_DATA(nlh);
556 tb = fib_get_table(frn->tb_id_in);
558 nl_fib_lookup(frn, tb);
560 pid = nlh->nlmsg_pid; /*pid of sending process */
561 NETLINK_CB(skb).groups = 0; /* not in mcast group */
562 NETLINK_CB(skb).pid = 0; /* from kernel */
563 NETLINK_CB(skb).dst_pid = pid;
564 NETLINK_CB(skb).dst_groups = 0; /* unicast */
565 netlink_unicast(sk, skb, pid, MSG_DONTWAIT);
568 static void nl_fib_lookup_init(void)
570 netlink_kernel_create(NETLINK_FIB_LOOKUP, nl_fib_input, THIS_MODULE);
573 static void fib_disable_ip(struct net_device *dev, int force)
575 if (fib_sync_down(0, dev, force))
576 fib_flush();
577 rt_cache_flush(0);
578 arp_ifdown(dev);
581 static int fib_inetaddr_event(struct notifier_block *this, unsigned long event, void *ptr)
583 struct in_ifaddr *ifa = (struct in_ifaddr*)ptr;
585 switch (event) {
586 case NETDEV_UP:
587 fib_add_ifaddr(ifa);
588 #ifdef CONFIG_IP_ROUTE_MULTIPATH
589 fib_sync_up(ifa->ifa_dev->dev);
590 #endif
591 rt_cache_flush(-1);
592 break;
593 case NETDEV_DOWN:
594 fib_del_ifaddr(ifa);
595 if (ifa->ifa_dev && ifa->ifa_dev->ifa_list == NULL) {
596 /* Last address was deleted from this interface.
597 Disable IP.
599 fib_disable_ip(ifa->ifa_dev->dev, 1);
600 } else {
601 rt_cache_flush(-1);
603 break;
605 return NOTIFY_DONE;
608 static int fib_netdev_event(struct notifier_block *this, unsigned long event, void *ptr)
610 struct net_device *dev = ptr;
611 struct in_device *in_dev = __in_dev_get(dev);
613 if (event == NETDEV_UNREGISTER) {
614 fib_disable_ip(dev, 2);
615 return NOTIFY_DONE;
618 if (!in_dev)
619 return NOTIFY_DONE;
621 switch (event) {
622 case NETDEV_UP:
623 for_ifa(in_dev) {
624 fib_add_ifaddr(ifa);
625 } endfor_ifa(in_dev);
626 #ifdef CONFIG_IP_ROUTE_MULTIPATH
627 fib_sync_up(dev);
628 #endif
629 rt_cache_flush(-1);
630 break;
631 case NETDEV_DOWN:
632 fib_disable_ip(dev, 0);
633 break;
634 case NETDEV_CHANGEMTU:
635 case NETDEV_CHANGE:
636 rt_cache_flush(0);
637 break;
639 return NOTIFY_DONE;
642 static struct notifier_block fib_inetaddr_notifier = {
643 .notifier_call =fib_inetaddr_event,
646 static struct notifier_block fib_netdev_notifier = {
647 .notifier_call =fib_netdev_event,
650 void __init ip_fib_init(void)
652 #ifndef CONFIG_IP_MULTIPLE_TABLES
653 ip_fib_local_table = fib_hash_init(RT_TABLE_LOCAL);
654 ip_fib_main_table = fib_hash_init(RT_TABLE_MAIN);
655 #else
656 fib_rules_init();
657 #endif
659 register_netdevice_notifier(&fib_netdev_notifier);
660 register_inetaddr_notifier(&fib_inetaddr_notifier);
661 nl_fib_lookup_init();
664 EXPORT_SYMBOL(inet_addr_type);
665 EXPORT_SYMBOL(ip_rt_ioctl);