xref: /freebsd/sys/netlink/route/rt.c (revision cdacb12065e4d85416655743da5bc6b17a9d9119)
1 /*-
2  * SPDX-License-Identifier: BSD-2-Clause
3  *
4  * Copyright (c) 2021 Ng Peng Nam Sean
5  * Copyright (c) 2022 Alexander V. Chernikov <melifaro@FreeBSD.org>
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include <sys/cdefs.h>
30 #include "opt_inet.h"
31 #include "opt_inet6.h"
32 #include "opt_route.h"
33 #include <sys/types.h>
34 #include <sys/malloc.h>
35 #include <sys/rmlock.h>
36 #include <sys/socket.h>
37 
38 #include <net/if.h>
39 #include <net/route.h>
40 #include <net/route/nhop.h>
41 #include <net/route/route_ctl.h>
42 #include <net/route/route_var.h>
43 #include <netinet6/scope6_var.h>
44 #include <netlink/netlink.h>
45 #include <netlink/netlink_ctl.h>
46 #include <netlink/netlink_route.h>
47 #include <netlink/route/route_var.h>
48 
49 #define	DEBUG_MOD_NAME	nl_route
50 #define	DEBUG_MAX_LEVEL	LOG_DEBUG3
51 #include <netlink/netlink_debug.h>
52 _DECLARE_DEBUG(LOG_INFO);
53 
54 static unsigned char
55 get_rtm_type(const struct nhop_object *nh)
56 {
57 	int nh_flags = nh->nh_flags;
58 
59 	/* Use the fact that nhg runtime flags are only NHF_MULTIPATH */
60 	if (nh_flags & NHF_BLACKHOLE)
61 		return (RTN_BLACKHOLE);
62 	else if (nh_flags & NHF_REJECT)
63 		return (RTN_PROHIBIT);
64 	return (RTN_UNICAST);
65 }
66 
67 static uint8_t
68 nl_get_rtm_protocol(const struct nhop_object *nh)
69 {
70 #ifdef ROUTE_MPATH
71 	if (NH_IS_NHGRP(nh)) {
72 		const struct nhgrp_object *nhg = (const struct nhgrp_object *)nh;
73 		uint8_t origin = nhgrp_get_origin(nhg);
74 		if (origin != RTPROT_UNSPEC)
75 			return (origin);
76 		nh = nhg->nhops[0];
77 	}
78 #endif
79 	uint8_t origin = nhop_get_origin(nh);
80 	if (origin != RTPROT_UNSPEC)
81 		return (origin);
82 	/* TODO: remove guesswork once all kernel users fill in origin */
83 	int rt_flags = nhop_get_rtflags(nh);
84 	if (rt_flags & RTF_PROTO1)
85 		return (RTPROT_ZEBRA);
86 	if (rt_flags & RTF_STATIC)
87 		return (RTPROT_STATIC);
88 	return (RTPROT_KERNEL);
89 }
90 
91 static int
92 get_rtmsg_type_from_rtsock(int cmd)
93 {
94 	switch (cmd) {
95 	case RTM_ADD:
96 	case RTM_CHANGE:
97 	case RTM_GET:
98 		return NL_RTM_NEWROUTE;
99 	case RTM_DELETE:
100 		return NL_RTM_DELROUTE;
101 	}
102 
103 	return (0);
104 }
105 
106 /*
107  * fibnum heuristics
108  *
109  * if (dump && rtm_table == 0 && !rta_table) RT_ALL_FIBS
110  * msg                rtm_table     RTA_TABLE            result
111  * RTM_GETROUTE/dump          0             -       RT_ALL_FIBS
112  * RTM_GETROUTE/dump          1             -                 1
113  * RTM_GETROUTE/get           0             -                 0
114  *
115  */
116 
117 static struct nhop_object *
118 rc_get_nhop(const struct rib_cmd_info *rc)
119 {
120 	return ((rc->rc_cmd == RTM_DELETE) ? rc->rc_nh_old : rc->rc_nh_new);
121 }
122 
123 static void
124 dump_rc_nhop_gw(struct nl_writer *nw, const struct nhop_object *nh)
125 {
126 #ifdef INET6
127 	int upper_family;
128 #endif
129 
130 	switch (nhop_get_neigh_family(nh)) {
131 	case AF_LINK:
132 		/* onlink prefix, skip */
133 		break;
134 	case AF_INET:
135 		nlattr_add(nw, NL_RTA_GATEWAY, 4, &nh->gw4_sa.sin_addr);
136 		break;
137 #ifdef INET6
138 	case AF_INET6:
139 		upper_family = nhop_get_upper_family(nh);
140 		if (upper_family == AF_INET6) {
141 			struct in6_addr gw6 = nh->gw6_sa.sin6_addr;
142 			in6_clearscope(&gw6);
143 
144 			nlattr_add(nw, NL_RTA_GATEWAY, 16, &gw6);
145 		} else if (upper_family == AF_INET) {
146 			/* IPv4 over IPv6 */
147 			struct in6_addr gw6 = nh->gw6_sa.sin6_addr;
148 			in6_clearscope(&gw6);
149 
150 			char buf[20];
151 			struct rtvia *via = (struct rtvia *)&buf[0];
152 			via->rtvia_family = AF_INET6;
153 			memcpy(via->rtvia_addr, &gw6, 16);
154 			nlattr_add(nw, NL_RTA_VIA, 17, via);
155 		}
156 		break;
157 #endif
158 	}
159 }
160 
161 static void
162 dump_rc_nhop_mtu(struct nl_writer *nw, const struct nhop_object *nh)
163 {
164 	int nla_len = sizeof(struct nlattr) * 2 + sizeof(uint32_t);
165 	struct nlattr *nla = nlmsg_reserve_data(nw, nla_len, struct nlattr);
166 
167 	if (nla == NULL)
168 		return;
169 	nla->nla_type = NL_RTA_METRICS;
170 	nla->nla_len = nla_len;
171 	nla++;
172 	nla->nla_type = NL_RTAX_MTU;
173 	nla->nla_len = sizeof(struct nlattr) + sizeof(uint32_t);
174 	*((uint32_t *)(nla + 1)) = nh->nh_mtu;
175 }
176 
177 #ifdef ROUTE_MPATH
178 static void
179 dump_rc_nhg(struct nl_writer *nw, const struct nhgrp_object *nhg, struct rtmsg *rtm)
180 {
181 	uint32_t uidx = nhgrp_get_uidx(nhg);
182 	uint32_t num_nhops;
183 	const struct weightened_nhop *wn = nhgrp_get_nhops(nhg, &num_nhops);
184 	uint32_t base_rtflags = nhop_get_rtflags(wn[0].nh);
185 
186 	if (uidx != 0)
187 		nlattr_add_u32(nw, NL_RTA_NH_ID, uidx);
188 	nlattr_add_u32(nw, NL_RTA_KNH_ID, nhgrp_get_idx(nhg));
189 
190 	nlattr_add_u32(nw, NL_RTA_RTFLAGS, base_rtflags);
191 	int off = nlattr_add_nested(nw, NL_RTA_MULTIPATH);
192 	if (off == 0)
193 		return;
194 
195 	for (int i = 0; i < num_nhops; i++) {
196 		int nh_off = nlattr_save_offset(nw);
197 		struct rtnexthop *rtnh = nlmsg_reserve_object(nw, struct rtnexthop);
198 		if (rtnh == NULL)
199 			return;
200 		rtnh->rtnh_flags = 0;
201 		rtnh->rtnh_ifindex = if_getindex(wn[i].nh->nh_ifp);
202 		rtnh->rtnh_hops = wn[i].weight;
203 		dump_rc_nhop_gw(nw, wn[i].nh);
204 		uint32_t rtflags = nhop_get_rtflags(wn[i].nh);
205 		if (rtflags != base_rtflags)
206 			nlattr_add_u32(nw, NL_RTA_RTFLAGS, rtflags);
207 		if (rtflags & RTF_FIXEDMTU)
208 			dump_rc_nhop_mtu(nw, wn[i].nh);
209 		rtnh = nlattr_restore_offset(nw, nh_off, struct rtnexthop);
210 		/*
211 		 * nlattr_add() allocates 4-byte aligned storage, no need to aligh
212 		 * length here
213 		 * */
214 		rtnh->rtnh_len = nlattr_save_offset(nw) - nh_off;
215 	}
216 	nlattr_set_len(nw, off);
217 }
218 #endif
219 
220 static void
221 dump_rc_nhop(struct nl_writer *nw, const struct route_nhop_data *rnd, struct rtmsg *rtm)
222 {
223 #ifdef ROUTE_MPATH
224 	if (NH_IS_NHGRP(rnd->rnd_nhop)) {
225 		dump_rc_nhg(nw, rnd->rnd_nhgrp, rtm);
226 		return;
227 	}
228 #endif
229 	const struct nhop_object *nh = rnd->rnd_nhop;
230 	uint32_t rtflags = nhop_get_rtflags(nh);
231 
232 	/*
233 	 * IPv4 over IPv6
234 	 *    ('RTA_VIA', {'family': 10, 'addr': 'fe80::20c:29ff:fe67:2dd'}), ('RTA_OIF', 2),
235 	 * IPv4 w/ gw
236 	 *    ('RTA_GATEWAY', '172.16.107.131'), ('RTA_OIF', 2)],
237 	 * Direct route:
238 	 *    ('RTA_OIF', 2)
239 	 */
240 	if (nh->nh_flags & NHF_GATEWAY)
241 		dump_rc_nhop_gw(nw, nh);
242 
243 	uint32_t uidx = nhop_get_uidx(nh);
244 	if (uidx != 0)
245 		nlattr_add_u32(nw, NL_RTA_NH_ID, uidx);
246 	nlattr_add_u32(nw, NL_RTA_KNH_ID, nhop_get_idx(nh));
247 	nlattr_add_u32(nw, NL_RTA_RTFLAGS, rtflags);
248 
249 	if (rtflags & RTF_FIXEDMTU)
250 		dump_rc_nhop_mtu(nw, nh);
251 	uint32_t nh_expire = nhop_get_expire(nh);
252 	if (nh_expire > 0)
253 		nlattr_add_u32(nw, NL_RTA_EXPIRES, nh_expire - time_uptime);
254 
255 	/* In any case, fill outgoing interface */
256 	nlattr_add_u32(nw, NL_RTA_OIF, if_getindex(nh->nh_ifp));
257 
258 	if (rnd->rnd_weight != RT_DEFAULT_WEIGHT)
259 		nlattr_add_u32(nw, NL_RTA_WEIGHT, rnd->rnd_weight);
260 }
261 
262 /*
263  * Dumps output from a rib command into an rtmsg
264  */
265 
266 static int
267 dump_px(uint32_t fibnum, const struct nlmsghdr *hdr,
268     const struct rtentry *rt, struct route_nhop_data *rnd,
269     struct nl_writer *nw)
270 {
271 	struct rtmsg *rtm;
272 	int error = 0;
273 
274 	NET_EPOCH_ASSERT();
275 
276 	if (!nlmsg_reply(nw, hdr, sizeof(struct rtmsg)))
277 		goto enomem;
278 
279 	int family = rt_get_family(rt);
280 	int rtm_off = nlattr_save_offset(nw);
281 	rtm = nlmsg_reserve_object(nw, struct rtmsg);
282 	rtm->rtm_family = family;
283 	rtm->rtm_dst_len = 0;
284 	rtm->rtm_src_len = 0;
285 	rtm->rtm_tos = 0;
286 	if (fibnum < 255)
287 		rtm->rtm_table = (unsigned char)fibnum;
288 	rtm->rtm_scope = RT_SCOPE_UNIVERSE;
289 	rtm->rtm_protocol = nl_get_rtm_protocol(rnd->rnd_nhop);
290 	rtm->rtm_type = get_rtm_type(rnd->rnd_nhop);
291 
292 	nlattr_add_u32(nw, NL_RTA_TABLE, fibnum);
293 
294 	int plen = 0;
295 #if defined(INET) || defined(INET6)
296 	uint32_t scopeid;
297 #endif
298 	switch (family) {
299 #ifdef INET
300 	case AF_INET:
301 		{
302 			struct in_addr addr;
303 			rt_get_inet_prefix_plen(rt, &addr, &plen, &scopeid);
304 			nlattr_add(nw, NL_RTA_DST, 4, &addr);
305 			break;
306 		}
307 #endif
308 #ifdef INET6
309 	case AF_INET6:
310 		{
311 			struct in6_addr addr;
312 			rt_get_inet6_prefix_plen(rt, &addr, &plen, &scopeid);
313 			nlattr_add(nw, NL_RTA_DST, 16, &addr);
314 			break;
315 		}
316 #endif
317 	default:
318 		FIB_LOG(LOG_NOTICE, fibnum, family, "unsupported rt family: %d", family);
319 		error = EAFNOSUPPORT;
320 		goto flush;
321 	}
322 
323 	rtm = nlattr_restore_offset(nw, rtm_off, struct rtmsg);
324 	if (plen > 0)
325 		rtm->rtm_dst_len = plen;
326 	dump_rc_nhop(nw, rnd, rtm);
327 
328 	if (nlmsg_end(nw))
329 		return (0);
330 enomem:
331 	error = ENOMEM;
332 flush:
333 	nlmsg_abort(nw);
334 	return (error);
335 }
336 
337 static int
338 family_to_group(int family)
339 {
340 	switch (family) {
341 	case AF_INET:
342 		return (RTNLGRP_IPV4_ROUTE);
343 	case AF_INET6:
344 		return (RTNLGRP_IPV6_ROUTE);
345 	}
346 	return (0);
347 }
348 
349 static void
350 report_operation(uint32_t fibnum, struct rib_cmd_info *rc,
351     struct nlpcb *nlp, struct nlmsghdr *hdr)
352 {
353 	struct nl_writer nw;
354 	uint32_t group_id = family_to_group(rt_get_family(rc->rc_rt));
355 
356 	if (nl_writer_group(&nw, NLMSG_SMALL, NETLINK_ROUTE, group_id, 0,
357 	    false)) {
358 		struct route_nhop_data rnd = {
359 			.rnd_nhop = rc_get_nhop(rc),
360 			.rnd_weight = rc->rc_nh_weight,
361 		};
362 		hdr->nlmsg_flags &= ~(NLM_F_REPLACE | NLM_F_CREATE);
363 		hdr->nlmsg_flags &= ~(NLM_F_EXCL | NLM_F_APPEND);
364 		switch (rc->rc_cmd) {
365 		case RTM_ADD:
366 			hdr->nlmsg_type = NL_RTM_NEWROUTE;
367 			hdr->nlmsg_flags |= NLM_F_CREATE | NLM_F_EXCL;
368 			break;
369 		case RTM_CHANGE:
370 			hdr->nlmsg_type = NL_RTM_NEWROUTE;
371 			hdr->nlmsg_flags |= NLM_F_REPLACE;
372 			break;
373 		case RTM_DELETE:
374 			hdr->nlmsg_type = NL_RTM_DELROUTE;
375 			break;
376 		}
377 		dump_px(fibnum, hdr, rc->rc_rt, &rnd, &nw);
378 		nlmsg_flush(&nw);
379 	}
380 
381 	rtsock_callback_p->route_f(fibnum, rc);
382 }
383 
384 static void
385 set_scope6(struct sockaddr *sa, struct ifnet *ifp)
386 {
387 #ifdef INET6
388 	if (sa != NULL && sa->sa_family == AF_INET6 && ifp != NULL) {
389 		struct sockaddr_in6 *sa6 = (struct sockaddr_in6 *)sa;
390 
391 		if (IN6_IS_ADDR_LINKLOCAL(&sa6->sin6_addr))
392 			in6_set_unicast_scopeid(&sa6->sin6_addr, if_getindex(ifp));
393 	}
394 #endif
395 }
396 
397 struct rta_mpath_nh {
398 	struct sockaddr	*gw;
399 	struct ifnet	*ifp;
400 	uint8_t		rtnh_flags;
401 	uint8_t		rtnh_weight;
402 };
403 
404 #define	_IN(_field)	offsetof(struct rtnexthop, _field)
405 #define	_OUT(_field)	offsetof(struct rta_mpath_nh, _field)
406 const static struct nlattr_parser nla_p_rtnh[] = {
407 	{ .type = NL_RTA_GATEWAY, .off = _OUT(gw), .cb = nlattr_get_ip },
408 	{ .type = NL_RTA_VIA, .off = _OUT(gw), .cb = nlattr_get_ipvia },
409 };
410 const static struct nlfield_parser nlf_p_rtnh[] = {
411 	{ .off_in = _IN(rtnh_flags), .off_out = _OUT(rtnh_flags), .cb = nlf_get_u8 },
412 	{ .off_in = _IN(rtnh_hops), .off_out = _OUT(rtnh_weight), .cb = nlf_get_u8 },
413 	{ .off_in = _IN(rtnh_ifindex), .off_out = _OUT(ifp), .cb = nlf_get_ifpz },
414 };
415 #undef _IN
416 #undef _OUT
417 
418 static bool
419 post_p_rtnh(void *_attrs, struct nl_pstate *npt __unused)
420 {
421 	struct rta_mpath_nh *attrs = (struct rta_mpath_nh *)_attrs;
422 
423 	set_scope6(attrs->gw, attrs->ifp);
424 	return (true);
425 }
426 NL_DECLARE_PARSER_EXT(mpath_parser, struct rtnexthop, NULL, nlf_p_rtnh, nla_p_rtnh, post_p_rtnh);
427 
428 struct rta_mpath {
429 	u_int num_nhops;
430 	struct rta_mpath_nh nhops[0];
431 };
432 
433 static int
434 nlattr_get_multipath(struct nlattr *nla, struct nl_pstate *npt,
435     const void *arg, void *target)
436 {
437 	struct rta_mpath *mp;
438 	struct rtnexthop *rtnh;
439 	uint16_t data_len, len;
440 	u_int max_nhops;
441 	int error;
442 
443 	data_len = nla->nla_len - sizeof(struct nlattr);
444 	max_nhops = data_len / sizeof(struct rtnexthop);
445 
446 	mp = npt_alloc(npt, (max_nhops + 2) * sizeof(struct rta_mpath_nh));
447 	mp->num_nhops = 0;
448 
449 	for (rtnh = (struct rtnexthop *)(nla + 1); data_len > 0; ) {
450 		struct rta_mpath_nh *mpnh;
451 
452 		if (__predict_false(rtnh->rtnh_len <= sizeof(*rtnh) ||
453 		    rtnh->rtnh_len > data_len)) {
454 			NLMSG_REPORT_ERR_MSG(npt, "%s: bad length %u",
455 			    __func__, rtnh->rtnh_len);
456 			return (EINVAL);
457 		}
458 		mpnh = &mp->nhops[mp->num_nhops++];
459 		error = nl_parse_header(rtnh, rtnh->rtnh_len, &mpath_parser,
460 		    npt, mpnh);
461 		if (error != 0) {
462 			NLMSG_REPORT_ERR_MSG(npt,
463 			    "RTA_MULTIPATH: nexthop %u: parse failed",
464 			    mp->num_nhops - 1);
465 			return (error);
466 		}
467 		len = NL_ITEM_ALIGN(rtnh->rtnh_len);
468 		data_len -= len;
469 		rtnh = (struct rtnexthop *)((char *)rtnh + len);
470 	}
471 	if (data_len != 0 || mp->num_nhops == 0) {
472 		NLMSG_REPORT_ERR_MSG(npt, "invalid RTA_MULTIPATH attr");
473 		return (EINVAL);
474 	}
475 
476 	*((struct rta_mpath **)target) = mp;
477 	return (0);
478 }
479 
480 
481 struct nl_parsed_route {
482 	struct sockaddr		*rta_dst;
483 	struct sockaddr		*rta_gw;
484 	struct ifnet		*rta_oif;
485 	struct rta_mpath	*rta_multipath;
486 	uint32_t		rta_table;
487 	uint32_t		rta_rtflags;
488 	uint32_t		rta_nh_id;
489 	uint32_t		rta_weight;
490 	uint32_t		rtax_mtu;
491 	uint8_t			rtm_table;
492 	uint8_t			rtm_family;
493 	uint8_t			rtm_dst_len;
494 	uint8_t			rtm_protocol;
495 	uint8_t			rtm_type;
496 	uint32_t		rtm_flags;
497 };
498 
499 #define	_IN(_field)	offsetof(struct rtmsg, _field)
500 #define	_OUT(_field)	offsetof(struct nl_parsed_route, _field)
501 static struct nlattr_parser nla_p_rtmetrics[] = {
502 	{ .type = NL_RTAX_MTU, .off = _OUT(rtax_mtu), .cb = nlattr_get_uint32 },
503 };
504 NL_DECLARE_ATTR_PARSER(metrics_parser, nla_p_rtmetrics);
505 
506 static const struct nlattr_parser nla_p_rtmsg[] = {
507 	{ .type = NL_RTA_DST, .off = _OUT(rta_dst), .cb = nlattr_get_ip },
508 	{ .type = NL_RTA_OIF, .off = _OUT(rta_oif), .cb = nlattr_get_ifp },
509 	{ .type = NL_RTA_GATEWAY, .off = _OUT(rta_gw), .cb = nlattr_get_ip },
510 	{ .type = NL_RTA_METRICS, .arg = &metrics_parser, .cb = nlattr_get_nested },
511 	{ .type = NL_RTA_MULTIPATH, .off = _OUT(rta_multipath), .cb = nlattr_get_multipath },
512 	{ .type = NL_RTA_WEIGHT, .off = _OUT(rta_weight), .cb = nlattr_get_uint32 },
513 	{ .type = NL_RTA_RTFLAGS, .off = _OUT(rta_rtflags), .cb = nlattr_get_uint32 },
514 	{ .type = NL_RTA_TABLE, .off = _OUT(rta_table), .cb = nlattr_get_uint32 },
515 	{ .type = NL_RTA_VIA, .off = _OUT(rta_gw), .cb = nlattr_get_ipvia },
516 	{ .type = NL_RTA_NH_ID, .off = _OUT(rta_nh_id), .cb = nlattr_get_uint32 },
517 };
518 
519 static const struct nlfield_parser nlf_p_rtmsg[] = {
520 	{ .off_in = _IN(rtm_family), .off_out = _OUT(rtm_family), .cb = nlf_get_u8 },
521 	{ .off_in = _IN(rtm_dst_len), .off_out = _OUT(rtm_dst_len), .cb = nlf_get_u8 },
522 	{ .off_in = _IN(rtm_protocol), .off_out = _OUT(rtm_protocol), .cb = nlf_get_u8 },
523 	{ .off_in = _IN(rtm_type), .off_out = _OUT(rtm_type), .cb = nlf_get_u8 },
524 	{ .off_in = _IN(rtm_table), .off_out = _OUT(rtm_table), .cb = nlf_get_u8 },
525 	{ .off_in = _IN(rtm_flags), .off_out = _OUT(rtm_flags), .cb = nlf_get_u32 },
526 };
527 #undef _IN
528 #undef _OUT
529 
530 static bool
531 post_p_rtmsg(void *_attrs, struct nl_pstate *npt __unused)
532 {
533 	struct nl_parsed_route *attrs = (struct nl_parsed_route *)_attrs;
534 
535 	set_scope6(attrs->rta_dst, attrs->rta_oif);
536 	set_scope6(attrs->rta_gw, attrs->rta_oif);
537 	return (true);
538 }
539 NL_DECLARE_PARSER_EXT(rtm_parser, struct rtmsg, NULL, nlf_p_rtmsg, nla_p_rtmsg, post_p_rtmsg);
540 
541 struct netlink_walkargs {
542 	struct nl_writer *nw;
543 	struct route_nhop_data rnd;
544 	struct nlmsghdr hdr;
545 	struct nlpcb *nlp;
546 	uint32_t fibnum;
547 	int family;
548 	int error;
549 	int count;
550 	int dumped;
551 	int dumped_tables;
552 };
553 
554 static int
555 dump_rtentry(struct rtentry *rt, void *_arg)
556 {
557 	struct netlink_walkargs *wa = (struct netlink_walkargs *)_arg;
558 	int error;
559 
560 	wa->count++;
561 	if (wa->error != 0)
562 		return (0);
563 	if (!rt_is_exportable(rt, nlp_get_cred(wa->nlp)))
564 		return (0);
565 	wa->dumped++;
566 
567 	rt_get_rnd(rt, &wa->rnd);
568 
569 	error = dump_px(wa->fibnum, &wa->hdr, rt, &wa->rnd, wa->nw);
570 
571 	IF_DEBUG_LEVEL(LOG_DEBUG3) {
572 		char rtbuf[INET6_ADDRSTRLEN + 5];
573 		FIB_LOG(LOG_DEBUG3, wa->fibnum, wa->family,
574 		    "Dump %s, error %d",
575 		    rt_print_buf(rt, rtbuf, sizeof(rtbuf)), error);
576 	}
577 	wa->error = error;
578 
579 	return (0);
580 }
581 
582 static void
583 dump_rtable_one(struct netlink_walkargs *wa, uint32_t fibnum, int family)
584 {
585 	FIB_LOG(LOG_DEBUG2, fibnum, family, "Start dump");
586 	wa->count = 0;
587 	wa->dumped = 0;
588 
589 	rib_walk(fibnum, family, false, dump_rtentry, wa);
590 
591 	wa->dumped_tables++;
592 
593 	FIB_LOG(LOG_DEBUG2, fibnum, family, "End dump, iterated %d dumped %d",
594 	    wa->count, wa->dumped);
595 }
596 
597 static int
598 dump_rtable_fib(struct netlink_walkargs *wa, uint32_t fibnum, int family)
599 {
600 	wa->fibnum = fibnum;
601 
602 	if (family == AF_UNSPEC) {
603 		for (int i = 0; i < AF_MAX; i++) {
604 			if (rt_tables_get_rnh(fibnum, i) != 0) {
605 				wa->family = i;
606 				dump_rtable_one(wa, fibnum, i);
607 				if (wa->error != 0)
608 					break;
609 			}
610 		}
611 	} else {
612 		if (rt_tables_get_rnh(fibnum, family) != 0) {
613 			wa->family = family;
614 			dump_rtable_one(wa, fibnum, family);
615 		}
616 	}
617 
618 	return (wa->error);
619 }
620 
621 static int
622 handle_rtm_getroute(struct nlpcb *nlp, struct nl_parsed_route *attrs,
623     struct nlmsghdr *hdr, struct nl_pstate *npt)
624 {
625 	RIB_RLOCK_TRACKER;
626 	struct rib_head *rnh;
627 	const struct rtentry *rt;
628 	struct route_nhop_data rnd;
629 	uint32_t fibnum = attrs->rta_table;
630 	sa_family_t family = attrs->rtm_family;
631 
632 	if (attrs->rta_dst == NULL) {
633 		NLMSG_REPORT_ERR_MSG(npt, "No RTA_DST supplied");
634 			return (EINVAL);
635 	}
636 
637 	rnh = rt_tables_get_rnh(fibnum, family);
638 	if (rnh == NULL)
639 		return (EAFNOSUPPORT);
640 
641 	RIB_RLOCK(rnh);
642 
643 	struct sockaddr *dst = attrs->rta_dst;
644 
645 	if (attrs->rtm_flags & RTM_F_PREFIX)
646 		rt = rib_lookup_prefix_plen(rnh, dst, attrs->rtm_dst_len, &rnd);
647 	else
648 		rt = (const struct rtentry *)rnh->rnh_matchaddr(dst, &rnh->head);
649 	if (rt == NULL) {
650 		RIB_RUNLOCK(rnh);
651 		return (ESRCH);
652 	}
653 
654 	rt_get_rnd(rt, &rnd);
655 	rnd.rnd_nhop = nhop_select_func(rnd.rnd_nhop, 0);
656 
657 	RIB_RUNLOCK(rnh);
658 
659 	if (!rt_is_exportable(rt, nlp_get_cred(nlp)))
660 		return (ESRCH);
661 
662 	IF_DEBUG_LEVEL(LOG_DEBUG2) {
663 		char rtbuf[NHOP_PRINT_BUFSIZE] __unused, nhbuf[NHOP_PRINT_BUFSIZE] __unused;
664 		FIB_LOG(LOG_DEBUG2, fibnum, family, "getroute completed: got %s for %s",
665 		    nhop_print_buf_any(rnd.rnd_nhop, nhbuf, sizeof(nhbuf)),
666 		    rt_print_buf(rt, rtbuf, sizeof(rtbuf)));
667 	}
668 
669 	hdr->nlmsg_type = NL_RTM_NEWROUTE;
670 	dump_px(fibnum, hdr, rt, &rnd, npt->nw);
671 
672 	return (0);
673 }
674 
675 static int
676 handle_rtm_dump(struct nlpcb *nlp, uint32_t fibnum, int family,
677     struct nlmsghdr *hdr, struct nl_writer *nw)
678 {
679 	struct netlink_walkargs wa = {
680 		.nlp = nlp,
681 		.nw = nw,
682 		.hdr.nlmsg_pid = hdr->nlmsg_pid,
683 		.hdr.nlmsg_seq = hdr->nlmsg_seq,
684 		.hdr.nlmsg_type = NL_RTM_NEWROUTE,
685 		.hdr.nlmsg_flags = hdr->nlmsg_flags | NLM_F_MULTI,
686 	};
687 
688 	if (fibnum == RT_TABLE_UNSPEC) {
689 		for (int i = 0; i < V_rt_numfibs; i++) {
690 			dump_rtable_fib(&wa, fibnum, family);
691 			if (wa.error != 0)
692 				break;
693 		}
694 	} else
695 		dump_rtable_fib(&wa, fibnum, family);
696 
697 	if (wa.error == 0 && wa.dumped_tables == 0) {
698 		FIB_LOG(LOG_DEBUG, fibnum, family, "incorrect fibnum/family");
699 		wa.error = ESRCH;
700 		// How do we propagate it?
701 	}
702 
703 	if (!nlmsg_end_dump(wa.nw, wa.error, &wa.hdr)) {
704                 NL_LOG(LOG_DEBUG, "Unable to finalize the dump");
705                 return (ENOMEM);
706         }
707 
708 	return (wa.error);
709 }
710 
711 static struct nhop_object *
712 finalize_nhop(struct nhop_object *nh, const struct sockaddr *dst, int *perror)
713 {
714 	/*
715 	 * The following MUST be filled:
716 	 *  nh_ifp, nh_ifa, nh_gw
717 	 */
718 	if (nh->gw_sa.sa_family == 0) {
719 		/*
720 		 * Empty gateway. Can be direct route with RTA_OIF set.
721 		 */
722 		if (nh->nh_ifp != NULL)
723 			nhop_set_direct_gw(nh, nh->nh_ifp);
724 		else {
725 			NL_LOG(LOG_DEBUG, "empty gateway and interface, skipping");
726 			*perror = EINVAL;
727 			return (NULL);
728 		}
729 		/* Both nh_ifp and gateway are set */
730 	} else {
731 		/* Gateway is set up, we can derive ifp if not set */
732 		if (nh->nh_ifp == NULL) {
733 			uint32_t fibnum = nhop_get_fibnum(nh);
734 			uint32_t flags = 0;
735 
736 			if (nh->nh_flags & NHF_GATEWAY)
737 				flags = RTF_GATEWAY;
738 			else if (nh->nh_flags & NHF_HOST)
739 				flags = RTF_HOST;
740 
741 			struct ifaddr *ifa = ifa_ifwithroute(flags, dst, &nh->gw_sa, fibnum);
742 			if (ifa == NULL) {
743 				NL_LOG(LOG_DEBUG, "Unable to determine ifp, skipping");
744 				*perror = EINVAL;
745 				return (NULL);
746 			}
747 			nhop_set_transmit_ifp(nh, ifa->ifa_ifp);
748 		}
749 	}
750 	/* Both nh_ifp and gateway are set */
751 	if (nh->nh_ifa == NULL) {
752 		const struct sockaddr *gw_sa = &nh->gw_sa;
753 
754 		if (gw_sa->sa_family != dst->sa_family) {
755 			/*
756 			 * Use dst as the target for determining the default
757 			 * preferred ifa IF
758 			 * 1) the gateway is link-level (e.g. direct route)
759 			 * 2) the gateway family is different (e.g. IPv4 over IPv6).
760 			 */
761 			gw_sa = dst;
762 		}
763 
764 		struct ifaddr *ifa = ifaof_ifpforaddr(gw_sa, nh->nh_ifp);
765 		if (ifa == NULL) {
766 			/* Try link-level ifa. */
767 			gw_sa = &nh->gw_sa;
768 			ifa = ifaof_ifpforaddr(gw_sa, nh->nh_ifp);
769 			if (ifa == NULL) {
770 				NL_LOG(LOG_DEBUG, "Unable to determine ifa, skipping");
771 				*perror = EINVAL;
772 				return (NULL);
773 			}
774 		}
775 		nhop_set_src(nh, ifa);
776 	}
777 
778 	return (nhop_get_nhop(nh, perror));
779 }
780 
781 static int
782 get_pxflag(const struct nl_parsed_route *attrs)
783 {
784 	int pxflag = 0;
785 	switch (attrs->rtm_family) {
786 	case AF_INET:
787 		if (attrs->rtm_dst_len == 32)
788 			pxflag = NHF_HOST;
789 		else if (attrs->rtm_dst_len == 0)
790 			pxflag = NHF_DEFAULT;
791 		break;
792 	case AF_INET6:
793 		if (attrs->rtm_dst_len == 128)
794 			pxflag = NHF_HOST;
795 		else if (attrs->rtm_dst_len == 0)
796 			pxflag = NHF_DEFAULT;
797 		break;
798 	}
799 
800 	return (pxflag);
801 }
802 
803 static int
804 get_op_flags(int nlm_flags)
805 {
806 	int op_flags = 0;
807 
808 	op_flags |= (nlm_flags & NLM_F_REPLACE) ? RTM_F_REPLACE : 0;
809 	op_flags |= (nlm_flags & NLM_F_EXCL) ? RTM_F_EXCL : 0;
810 	op_flags |= (nlm_flags & NLM_F_CREATE) ? RTM_F_CREATE : 0;
811 	op_flags |= (nlm_flags & NLM_F_APPEND) ? RTM_F_APPEND : 0;
812 
813 	return (op_flags);
814 }
815 
816 #ifdef ROUTE_MPATH
817 static int
818 create_nexthop_one(struct nl_parsed_route *attrs, struct rta_mpath_nh *mpnh,
819     struct nl_pstate *npt, struct nhop_object **pnh)
820 {
821 	int error;
822 
823 	if (mpnh->gw == NULL)
824 		return (EINVAL);
825 
826 	struct nhop_object *nh = nhop_alloc(attrs->rta_table, attrs->rtm_family);
827 	if (nh == NULL)
828 		return (ENOMEM);
829 
830 	error = nl_set_nexthop_gw(nh, mpnh->gw, mpnh->ifp, npt);
831 	if (error != 0) {
832 		nhop_free(nh);
833 		return (error);
834 	}
835 	if (mpnh->ifp != NULL)
836 		nhop_set_transmit_ifp(nh, mpnh->ifp);
837 	nhop_set_pxtype_flag(nh, get_pxflag(attrs));
838 	nhop_set_rtflags(nh, attrs->rta_rtflags);
839 	if (attrs->rtm_protocol > RTPROT_STATIC)
840 		nhop_set_origin(nh, attrs->rtm_protocol);
841 
842 	*pnh = finalize_nhop(nh, attrs->rta_dst, &error);
843 
844 	return (error);
845 }
846 #endif
847 
848 static struct nhop_object *
849 create_nexthop_from_attrs(struct nl_parsed_route *attrs,
850     struct nl_pstate *npt, int *perror)
851 {
852 	struct nhop_object *nh = NULL;
853 	int error = 0;
854 
855 	if (attrs->rta_multipath != NULL) {
856 #ifdef ROUTE_MPATH
857 		/* Multipath w/o explicit nexthops */
858 		int num_nhops = attrs->rta_multipath->num_nhops;
859 		struct weightened_nhop *wn = npt_alloc(npt, sizeof(*wn) * num_nhops);
860 
861 		for (int i = 0; i < num_nhops; i++) {
862 			struct rta_mpath_nh *mpnh = &attrs->rta_multipath->nhops[i];
863 
864 			error = create_nexthop_one(attrs, mpnh, npt, &wn[i].nh);
865 			if (error != 0) {
866 				for (int j = 0; j < i; j++)
867 					nhop_free(wn[j].nh);
868 				break;
869 			}
870 			wn[i].weight = mpnh->rtnh_weight > 0 ? mpnh->rtnh_weight : 1;
871 		}
872 		if (error == 0) {
873 			struct rib_head *rh = nhop_get_rh(wn[0].nh);
874 			struct nhgrp_object *nhg;
875 
876 			nhg = nhgrp_alloc(rh->rib_fibnum, rh->rib_family,
877 			    wn, num_nhops, perror);
878 			if (nhg != NULL) {
879 				if (attrs->rtm_protocol > RTPROT_STATIC)
880 					nhgrp_set_origin(nhg, attrs->rtm_protocol);
881 				nhg = nhgrp_get_nhgrp(nhg, perror);
882 			}
883 			for (int i = 0; i < num_nhops; i++)
884 				nhop_free(wn[i].nh);
885 			if (nhg != NULL)
886 				return ((struct nhop_object *)nhg);
887 			error = *perror;
888 		}
889 #else
890 		error = ENOTSUP;
891 #endif
892 		*perror = error;
893 	} else {
894 		nh = nhop_alloc(attrs->rta_table, attrs->rtm_family);
895 		if (nh == NULL) {
896 			*perror = ENOMEM;
897 			return (NULL);
898 		}
899 		if (attrs->rta_gw != NULL) {
900 			*perror = nl_set_nexthop_gw(nh, attrs->rta_gw, attrs->rta_oif, npt);
901 			if (*perror != 0) {
902 				nhop_free(nh);
903 				return (NULL);
904 			}
905 		}
906 		if (attrs->rta_oif != NULL)
907 			nhop_set_transmit_ifp(nh, attrs->rta_oif);
908 		if (attrs->rtax_mtu != 0)
909 			nhop_set_mtu(nh, attrs->rtax_mtu, true);
910 		if (attrs->rta_rtflags & RTF_BROADCAST)
911 			nhop_set_broadcast(nh, true);
912 		if (attrs->rtm_protocol > RTPROT_STATIC)
913 			nhop_set_origin(nh, attrs->rtm_protocol);
914 		nhop_set_pxtype_flag(nh, get_pxflag(attrs));
915 		nhop_set_rtflags(nh, attrs->rta_rtflags);
916 
917 		switch (attrs->rtm_type) {
918 		case RTN_UNICAST:
919 			break;
920 		case RTN_BLACKHOLE:
921 			nhop_set_blackhole(nh, RTF_BLACKHOLE);
922 			break;
923 		case RTN_PROHIBIT:
924 		case RTN_UNREACHABLE:
925 			nhop_set_blackhole(nh, RTF_REJECT);
926 			break;
927 		/* TODO: return ENOTSUP for other types if strict option is set */
928 		}
929 
930 		nh = finalize_nhop(nh, attrs->rta_dst, perror);
931 	}
932 
933 	return (nh);
934 }
935 
936 static int
937 rtnl_handle_newroute(struct nlmsghdr *hdr, struct nlpcb *nlp,
938     struct nl_pstate *npt)
939 {
940 	struct rib_cmd_info rc = {};
941 	struct nhop_object *nh = NULL;
942 	int error;
943 
944 	struct nl_parsed_route attrs = {};
945 	error = nl_parse_nlmsg(hdr, &rtm_parser, npt, &attrs);
946 	if (error != 0)
947 		return (error);
948 
949 	/* Check if we have enough data */
950 	if (attrs.rta_dst == NULL) {
951 		NL_LOG(LOG_DEBUG, "missing RTA_DST");
952 		return (EINVAL);
953 	}
954 
955 	/* pre-2.6.19 Linux API compatibility */
956 	if (attrs.rtm_table > 0 && attrs.rta_table == 0)
957 		attrs.rta_table = attrs.rtm_table;
958 	if (attrs.rta_table >= V_rt_numfibs || attrs.rtm_family > AF_MAX) {
959 		NLMSG_REPORT_ERR_MSG(npt, "invalid fib");
960 		return (EINVAL);
961 	}
962 
963 	if (attrs.rta_nh_id != 0) {
964 		/* Referenced uindex */
965 		int pxflag = get_pxflag(&attrs);
966 		nh = nl_find_nhop(attrs.rta_table, attrs.rtm_family, attrs.rta_nh_id,
967 		    pxflag, &error);
968 		if (error != 0)
969 			return (error);
970 	} else {
971 		nh = create_nexthop_from_attrs(&attrs, npt, &error);
972 		if (error != 0) {
973 			NL_LOG(LOG_DEBUG, "Error creating nexthop");
974 			return (error);
975 		}
976 	}
977 
978 	if (!NH_IS_NHGRP(nh) && attrs.rta_weight == 0)
979 		attrs.rta_weight = RT_DEFAULT_WEIGHT;
980 	struct route_nhop_data rnd = { .rnd_nhop = nh, .rnd_weight = attrs.rta_weight };
981 	int op_flags = get_op_flags(hdr->nlmsg_flags);
982 
983 	error = rib_add_route_px(attrs.rta_table, attrs.rta_dst, attrs.rtm_dst_len,
984 	    &rnd, op_flags, &rc);
985 	if (error == 0)
986 		report_operation(attrs.rta_table, &rc, nlp, hdr);
987 	return (error);
988 }
989 
990 static int
991 path_match_func(const struct rtentry *rt, const struct nhop_object *nh, void *_data)
992 {
993 	struct nl_parsed_route *attrs = (struct nl_parsed_route *)_data;
994 
995 	if ((attrs->rta_gw != NULL) && !rib_match_gw(rt, nh, attrs->rta_gw))
996 		return (0);
997 
998 	if ((attrs->rta_oif != NULL) && (attrs->rta_oif != nh->nh_ifp))
999 		return (0);
1000 
1001 	return (1);
1002 }
1003 
1004 static int
1005 rtnl_handle_delroute(struct nlmsghdr *hdr, struct nlpcb *nlp,
1006     struct nl_pstate *npt)
1007 {
1008 	struct rib_cmd_info rc;
1009 	int error;
1010 
1011 	struct nl_parsed_route attrs = {};
1012 	error = nl_parse_nlmsg(hdr, &rtm_parser, npt, &attrs);
1013 	if (error != 0)
1014 		return (error);
1015 
1016 	if (attrs.rta_dst == NULL) {
1017 		NLMSG_REPORT_ERR_MSG(npt, "RTA_DST is not set");
1018 		return (ESRCH);
1019 	}
1020 
1021 	if (attrs.rta_table >= V_rt_numfibs || attrs.rtm_family > AF_MAX) {
1022 		NLMSG_REPORT_ERR_MSG(npt, "invalid fib");
1023 		return (EINVAL);
1024 	}
1025 
1026 	error = rib_del_route_px(attrs.rta_table, attrs.rta_dst,
1027 	    attrs.rtm_dst_len, path_match_func, &attrs,
1028 	    (attrs.rta_rtflags & RTF_PINNED) ? RTM_F_FORCE : 0, &rc);
1029 	if (error == 0)
1030 		report_operation(attrs.rta_table, &rc, nlp, hdr);
1031 	return (error);
1032 }
1033 
1034 static int
1035 rtnl_handle_getroute(struct nlmsghdr *hdr, struct nlpcb *nlp, struct nl_pstate *npt)
1036 {
1037 	int error;
1038 
1039 	struct nl_parsed_route attrs = {};
1040 	error = nl_parse_nlmsg(hdr, &rtm_parser, npt, &attrs);
1041 	if (error != 0)
1042 		return (error);
1043 
1044 	if (attrs.rta_table >= V_rt_numfibs || attrs.rtm_family > AF_MAX) {
1045 		NLMSG_REPORT_ERR_MSG(npt, "invalid fib");
1046 		return (EINVAL);
1047 	}
1048 
1049 	if (hdr->nlmsg_flags & NLM_F_DUMP)
1050 		error = handle_rtm_dump(nlp, attrs.rta_table, attrs.rtm_family, hdr, npt->nw);
1051 	else
1052 		error = handle_rtm_getroute(nlp, &attrs, hdr, npt);
1053 
1054 	return (error);
1055 }
1056 
1057 void
1058 rtnl_handle_route_event(uint32_t fibnum, const struct rib_cmd_info *rc)
1059 {
1060 	struct nl_writer nw;
1061 	int family, nlm_flags = 0;
1062 
1063 	family = rt_get_family(rc->rc_rt);
1064 
1065 	/* XXX: check if there are active listeners first */
1066 
1067 	/* TODO: consider passing PID/type/seq */
1068 	switch (rc->rc_cmd) {
1069 	case RTM_ADD:
1070 		nlm_flags = NLM_F_EXCL | NLM_F_CREATE;
1071 		break;
1072 	case RTM_CHANGE:
1073 		nlm_flags = NLM_F_REPLACE;
1074 		break;
1075 	case RTM_DELETE:
1076 		nlm_flags = 0;
1077 		break;
1078 	}
1079 	IF_DEBUG_LEVEL(LOG_DEBUG2) {
1080 		char rtbuf[NHOP_PRINT_BUFSIZE] __unused;
1081 		FIB_LOG(LOG_DEBUG2, fibnum, family,
1082 		    "received event %s for %s / nlm_flags=%X",
1083 		    rib_print_cmd(rc->rc_cmd),
1084 		    rt_print_buf(rc->rc_rt, rtbuf, sizeof(rtbuf)),
1085 		    nlm_flags);
1086 	}
1087 
1088 	struct nlmsghdr hdr = {
1089 		.nlmsg_flags = nlm_flags,
1090 		.nlmsg_type = get_rtmsg_type_from_rtsock(rc->rc_cmd),
1091 	};
1092 
1093 	struct route_nhop_data rnd = {
1094 		.rnd_nhop = rc_get_nhop(rc),
1095 		.rnd_weight = rc->rc_nh_weight,
1096 	};
1097 
1098 	uint32_t group_id = family_to_group(family);
1099 	if (!nl_writer_group(&nw, NLMSG_SMALL, NETLINK_ROUTE, group_id, 0,
1100 	    false)) {
1101 		NL_LOG(LOG_DEBUG, "error allocating event buffer");
1102 		return;
1103 	}
1104 
1105 	dump_px(fibnum, &hdr, rc->rc_rt, &rnd, &nw);
1106 	nlmsg_flush(&nw);
1107 }
1108 
1109 static const struct rtnl_cmd_handler cmd_handlers[] = {
1110 	{
1111 		.cmd = NL_RTM_GETROUTE,
1112 		.name = "RTM_GETROUTE",
1113 		.cb = &rtnl_handle_getroute,
1114 		.flags = RTNL_F_ALLOW_NONVNET_JAIL,
1115 	},
1116 	{
1117 		.cmd = NL_RTM_DELROUTE,
1118 		.name = "RTM_DELROUTE",
1119 		.cb = &rtnl_handle_delroute,
1120 		.priv = PRIV_NET_ROUTE,
1121 	},
1122 	{
1123 		.cmd = NL_RTM_NEWROUTE,
1124 		.name = "RTM_NEWROUTE",
1125 		.cb = &rtnl_handle_newroute,
1126 		.priv = PRIV_NET_ROUTE,
1127 	}
1128 };
1129 
1130 static const struct nlhdr_parser *all_parsers[] = {&mpath_parser, &metrics_parser, &rtm_parser};
1131 
1132 void
1133 rtnl_routes_init(void)
1134 {
1135 	NL_VERIFY_PARSERS(all_parsers);
1136 	rtnl_register_messages(cmd_handlers, nitems(cmd_handlers));
1137 }
1138