1c398230bSWarner Losh /*- 251369649SPedro F. Giffuni * SPDX-License-Identifier: BSD-3-Clause 351369649SPedro F. Giffuni * 4df8bae1dSRodney W. Grimes * Copyright (c) 1982, 1986, 1991, 1993 5df8bae1dSRodney W. Grimes * The Regents of the University of California. All rights reserved. 681d96ce8SMax Laier * Copyright (C) 2001 WIDE Project. All rights reserved. 7df8bae1dSRodney W. Grimes * 8df8bae1dSRodney W. Grimes * Redistribution and use in source and binary forms, with or without 9df8bae1dSRodney W. Grimes * modification, are permitted provided that the following conditions 10df8bae1dSRodney W. Grimes * are met: 11df8bae1dSRodney W. Grimes * 1. Redistributions of source code must retain the above copyright 12df8bae1dSRodney W. Grimes * notice, this list of conditions and the following disclaimer. 13df8bae1dSRodney W. Grimes * 2. Redistributions in binary form must reproduce the above copyright 14df8bae1dSRodney W. Grimes * notice, this list of conditions and the following disclaimer in the 15df8bae1dSRodney W. Grimes * documentation and/or other materials provided with the distribution. 16fbbd9655SWarner Losh * 3. Neither the name of the University nor the names of its contributors 17df8bae1dSRodney W. Grimes * may be used to endorse or promote products derived from this software 18df8bae1dSRodney W. Grimes * without specific prior written permission. 19df8bae1dSRodney W. Grimes * 20df8bae1dSRodney W. Grimes * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 21df8bae1dSRodney W. Grimes * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 22df8bae1dSRodney W. Grimes * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 23df8bae1dSRodney W. Grimes * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 24df8bae1dSRodney W. Grimes * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 25df8bae1dSRodney W. Grimes * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 26df8bae1dSRodney W. Grimes * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 27df8bae1dSRodney W. Grimes * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 28df8bae1dSRodney W. Grimes * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 29df8bae1dSRodney W. Grimes * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 30df8bae1dSRodney W. Grimes * SUCH DAMAGE. 31df8bae1dSRodney W. Grimes * 322180b925SGarrett Wollman * @(#)in.c 8.4 (Berkeley) 1/9/95 33df8bae1dSRodney W. Grimes */ 34df8bae1dSRodney W. Grimes 354b421e2dSMike Silbersack #include <sys/cdefs.h> 364b421e2dSMike Silbersack __FBSDID("$FreeBSD$"); 374b421e2dSMike Silbersack 38df8bae1dSRodney W. Grimes #include <sys/param.h> 39c3322cb9SGleb Smirnoff #include <sys/eventhandler.h> 4026f9a767SRodney W. Grimes #include <sys/systm.h> 4151a53488SBruce Evans #include <sys/sockio.h> 42df8bae1dSRodney W. Grimes #include <sys/malloc.h> 43acd3428bSRobert Watson #include <sys/priv.h> 44df8bae1dSRodney W. Grimes #include <sys/socket.h> 455ce0eb7fSBjoern A. Zeeb #include <sys/jail.h> 46f6d24a78SPoul-Henning Kamp #include <sys/kernel.h> 47cc0a3c8cSAndrey V. Elsukov #include <sys/lock.h> 485ce0eb7fSBjoern A. Zeeb #include <sys/proc.h> 49cc0a3c8cSAndrey V. Elsukov #include <sys/rmlock.h> 50f6d24a78SPoul-Henning Kamp #include <sys/sysctl.h> 51ebc90701SQing Li #include <sys/syslog.h> 52f7a39160SGleb Smirnoff #include <sys/sx.h> 53df8bae1dSRodney W. Grimes 54df8bae1dSRodney W. Grimes #include <net/if.h> 55df813b7eSQing Li #include <net/if_var.h> 56e162ea60SGeorge V. Neville-Neil #include <net/if_arp.h> 57ebc90701SQing Li #include <net/if_dl.h> 586e6b3f7cSQing Li #include <net/if_llatbl.h> 596a800098SYoshinobu Inoue #include <net/if_types.h> 60df8bae1dSRodney W. Grimes #include <net/route.h> 6181728a53SAlexander V. Chernikov #include <net/route/nhop.h> 6281728a53SAlexander V. Chernikov #include <net/route/route_ctl.h> 63ebc90701SQing Li #include <net/vnet.h> 64df8bae1dSRodney W. Grimes 6508b68b0eSGleb Smirnoff #include <netinet/if_ether.h> 66df8bae1dSRodney W. Grimes #include <netinet/in.h> 67*936f4a42SAlexander V. Chernikov #include <netinet/in_fib.h> 68df8bae1dSRodney W. Grimes #include <netinet/in_var.h> 69e43cc4aeSHajimu UMEMOTO #include <netinet/in_pcb.h> 7071498f30SBruce M Simpson #include <netinet/ip_var.h> 7108b68b0eSGleb Smirnoff #include <netinet/ip_carp.h> 72d10910e6SBruce M Simpson #include <netinet/igmp_var.h> 73eddfbb76SRobert Watson #include <netinet/udp.h> 74eddfbb76SRobert Watson #include <netinet/udp_var.h> 7555166637SPoul-Henning Kamp 7677b89ad8SGleb Smirnoff static int in_aifaddr_ioctl(u_long, caddr_t, struct ifnet *, struct thread *); 77338e227aSLuiz Otavio O Souza static int in_difaddr_ioctl(u_long, caddr_t, struct ifnet *, struct thread *); 786952c3e1SAndrey V. Elsukov static int in_gifaddr_ioctl(u_long, caddr_t, struct ifnet *, struct thread *); 796a800098SYoshinobu Inoue 804d77a549SAlfred Perlstein static void in_socktrim(struct sockaddr_in *); 81ec002feeSBruce M Simpson static void in_purgemaddrs(struct ifnet *); 82df8bae1dSRodney W. Grimes 83130aebbaSAlexander V. Chernikov static bool ia_need_loopback_route(const struct in_ifaddr *); 84130aebbaSAlexander V. Chernikov 855f901c92SAndrew Turner VNET_DEFINE_STATIC(int, nosameprefix); 8608b68b0eSGleb Smirnoff #define V_nosameprefix VNET(nosameprefix) 876df8a710SGleb Smirnoff SYSCTL_INT(_net_inet_ip, OID_AUTO, no_same_prefix, CTLFLAG_VNET | CTLFLAG_RW, 8808b68b0eSGleb Smirnoff &VNET_NAME(nosameprefix), 0, 891ae95409SGleb Smirnoff "Refuse to create same prefixes on different interfaces"); 90477180fbSGarrett Wollman 9182cea7e6SBjoern A. Zeeb VNET_DECLARE(struct inpcbinfo, ripcbinfo); 9282cea7e6SBjoern A. Zeeb #define V_ripcbinfo VNET(ripcbinfo) 9382cea7e6SBjoern A. Zeeb 94f7a39160SGleb Smirnoff static struct sx in_control_sx; 95f7a39160SGleb Smirnoff SX_SYSINIT(in_control_sx, &in_control_sx, "in_control"); 96f7a39160SGleb Smirnoff 97df8bae1dSRodney W. Grimes /* 98df8bae1dSRodney W. Grimes * Return 1 if an internet address is for a ``local'' host 99b365d954SGleb Smirnoff * (one to which we have a connection). 100df8bae1dSRodney W. Grimes */ 10126f9a767SRodney W. Grimes int 102f2565d68SRobert Watson in_localaddr(struct in_addr in) 103df8bae1dSRodney W. Grimes { 104cc0a3c8cSAndrey V. Elsukov struct rm_priotracker in_ifa_tracker; 1053e85b721SEd Maste u_long i = ntohl(in.s_addr); 1063e85b721SEd Maste struct in_ifaddr *ia; 107df8bae1dSRodney W. Grimes 108cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RLOCK(&in_ifa_tracker); 109d7c5a620SMatt Macy CK_STAILQ_FOREACH(ia, &V_in_ifaddrhead, ia_link) { 1102d9cfabaSRobert Watson if ((i & ia->ia_subnetmask) == ia->ia_subnet) { 111cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 1122d9cfabaSRobert Watson return (1); 1132d9cfabaSRobert Watson } 1142d9cfabaSRobert Watson } 115cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 116df8bae1dSRodney W. Grimes return (0); 117df8bae1dSRodney W. Grimes } 118df8bae1dSRodney W. Grimes 119df8bae1dSRodney W. Grimes /* 1202eccc90bSAndre Oppermann * Return 1 if an internet address is for the local host and configured 1212eccc90bSAndre Oppermann * on one of its interfaces. 1222eccc90bSAndre Oppermann */ 1232eccc90bSAndre Oppermann int 124f2565d68SRobert Watson in_localip(struct in_addr in) 1252eccc90bSAndre Oppermann { 126cc0a3c8cSAndrey V. Elsukov struct rm_priotracker in_ifa_tracker; 1272eccc90bSAndre Oppermann struct in_ifaddr *ia; 1282eccc90bSAndre Oppermann 129cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RLOCK(&in_ifa_tracker); 1302eccc90bSAndre Oppermann LIST_FOREACH(ia, INADDR_HASH(in.s_addr), ia_hash) { 1312d9cfabaSRobert Watson if (IA_SIN(ia)->sin_addr.s_addr == in.s_addr) { 132cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 133460473a0SBjoern A. Zeeb return (1); 1342eccc90bSAndre Oppermann } 1352d9cfabaSRobert Watson } 136cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 137460473a0SBjoern A. Zeeb return (0); 1382eccc90bSAndre Oppermann } 1392eccc90bSAndre Oppermann 1402eccc90bSAndre Oppermann /* 14128ebe80cSGleb Smirnoff * Return 1 if an internet address is configured on an interface. 14228ebe80cSGleb Smirnoff */ 14328ebe80cSGleb Smirnoff int 14428ebe80cSGleb Smirnoff in_ifhasaddr(struct ifnet *ifp, struct in_addr in) 14528ebe80cSGleb Smirnoff { 14628ebe80cSGleb Smirnoff struct ifaddr *ifa; 14728ebe80cSGleb Smirnoff struct in_ifaddr *ia; 14828ebe80cSGleb Smirnoff 149b8a6e03fSGleb Smirnoff NET_EPOCH_ASSERT(); 150b8a6e03fSGleb Smirnoff 151d7c5a620SMatt Macy CK_STAILQ_FOREACH(ifa, &ifp->if_addrhead, ifa_link) { 15228ebe80cSGleb Smirnoff if (ifa->ifa_addr->sa_family != AF_INET) 15328ebe80cSGleb Smirnoff continue; 15428ebe80cSGleb Smirnoff ia = (struct in_ifaddr *)ifa; 155b8a6e03fSGleb Smirnoff if (ia->ia_addr.sin_addr.s_addr == in.s_addr) 15628ebe80cSGleb Smirnoff return (1); 15728ebe80cSGleb Smirnoff } 15828ebe80cSGleb Smirnoff 15928ebe80cSGleb Smirnoff return (0); 16028ebe80cSGleb Smirnoff } 16128ebe80cSGleb Smirnoff 16228ebe80cSGleb Smirnoff /* 163f7a39160SGleb Smirnoff * Return a reference to the interface address which is different to 164f7a39160SGleb Smirnoff * the supplied one but with same IP address value. 165f7a39160SGleb Smirnoff */ 166f7a39160SGleb Smirnoff static struct in_ifaddr * 1679fdbf7eeSAlexander V. Chernikov in_localip_more(struct in_ifaddr *original_ia) 168f7a39160SGleb Smirnoff { 169cc0a3c8cSAndrey V. Elsukov struct rm_priotracker in_ifa_tracker; 1709fdbf7eeSAlexander V. Chernikov in_addr_t original_addr = IA_SIN(original_ia)->sin_addr.s_addr; 1719fdbf7eeSAlexander V. Chernikov uint32_t original_fib = original_ia->ia_ifa.ifa_ifp->if_fib; 1729fdbf7eeSAlexander V. Chernikov struct in_ifaddr *ia; 173f7a39160SGleb Smirnoff 174cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RLOCK(&in_ifa_tracker); 1759fdbf7eeSAlexander V. Chernikov LIST_FOREACH(ia, INADDR_HASH(original_addr), ia_hash) { 1769fdbf7eeSAlexander V. Chernikov in_addr_t addr = IA_SIN(ia)->sin_addr.s_addr; 1779fdbf7eeSAlexander V. Chernikov uint32_t fib = ia->ia_ifa.ifa_ifp->if_fib; 1789fdbf7eeSAlexander V. Chernikov if (!V_rt_add_addr_allfibs && (original_fib != fib)) 1799fdbf7eeSAlexander V. Chernikov continue; 1809fdbf7eeSAlexander V. Chernikov if ((original_ia != ia) && (original_addr == addr)) { 1819fdbf7eeSAlexander V. Chernikov ifa_ref(&ia->ia_ifa); 182cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 1839fdbf7eeSAlexander V. Chernikov return (ia); 184f7a39160SGleb Smirnoff } 185f7a39160SGleb Smirnoff } 186cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 187f7a39160SGleb Smirnoff 188f7a39160SGleb Smirnoff return (NULL); 189f7a39160SGleb Smirnoff } 190f7a39160SGleb Smirnoff 191f7a39160SGleb Smirnoff /* 192df8bae1dSRodney W. Grimes * Determine whether an IP address is in a reserved set of addresses 193df8bae1dSRodney W. Grimes * that may not be forwarded, or whether datagrams to that destination 194df8bae1dSRodney W. Grimes * may be forwarded. 195df8bae1dSRodney W. Grimes */ 19626f9a767SRodney W. Grimes int 197f2565d68SRobert Watson in_canforward(struct in_addr in) 198df8bae1dSRodney W. Grimes { 1993e85b721SEd Maste u_long i = ntohl(in.s_addr); 200df8bae1dSRodney W. Grimes 2016c1c6ae5SRodney W. Grimes if (IN_EXPERIMENTAL(i) || IN_MULTICAST(i) || IN_LINKLOCAL(i) || 2026c1c6ae5SRodney W. Grimes IN_ZERONET(i) || IN_LOOPBACK(i)) 203df8bae1dSRodney W. Grimes return (0); 204df8bae1dSRodney W. Grimes return (1); 205df8bae1dSRodney W. Grimes } 206df8bae1dSRodney W. Grimes 207df8bae1dSRodney W. Grimes /* 208df8bae1dSRodney W. Grimes * Trim a mask in a sockaddr 209df8bae1dSRodney W. Grimes */ 2100312fbe9SPoul-Henning Kamp static void 211f2565d68SRobert Watson in_socktrim(struct sockaddr_in *ap) 212df8bae1dSRodney W. Grimes { 2133e85b721SEd Maste char *cplim = (char *) &ap->sin_addr; 2143e85b721SEd Maste char *cp = (char *) (&ap->sin_addr + 1); 215df8bae1dSRodney W. Grimes 216df8bae1dSRodney W. Grimes ap->sin_len = 0; 217df00058dSGarrett Wollman while (--cp >= cplim) 218df8bae1dSRodney W. Grimes if (*cp) { 219df8bae1dSRodney W. Grimes (ap)->sin_len = cp - (char *) (ap) + 1; 220df8bae1dSRodney W. Grimes break; 221df8bae1dSRodney W. Grimes } 222df8bae1dSRodney W. Grimes } 223df8bae1dSRodney W. Grimes 224df8bae1dSRodney W. Grimes /* 225df8bae1dSRodney W. Grimes * Generic internet control operations (ioctl's). 226df8bae1dSRodney W. Grimes */ 22726f9a767SRodney W. Grimes int 228f2565d68SRobert Watson in_control(struct socket *so, u_long cmd, caddr_t data, struct ifnet *ifp, 229f2565d68SRobert Watson struct thread *td) 230df8bae1dSRodney W. Grimes { 231f7a39160SGleb Smirnoff struct ifreq *ifr = (struct ifreq *)data; 232f7a39160SGleb Smirnoff struct sockaddr_in *addr = (struct sockaddr_in *)&ifr->ifr_addr; 233a68cc388SGleb Smirnoff struct epoch_tracker et; 234821b5cafSGleb Smirnoff struct ifaddr *ifa; 235f7a39160SGleb Smirnoff struct in_ifaddr *ia; 236f7a39160SGleb Smirnoff int error; 237f7a39160SGleb Smirnoff 238f7a39160SGleb Smirnoff if (ifp == NULL) 239f7a39160SGleb Smirnoff return (EADDRNOTAVAIL); 24071212473SGleb Smirnoff 24171212473SGleb Smirnoff /* 242f7a39160SGleb Smirnoff * Filter out 4 ioctls we implement directly. Forward the rest 243f7a39160SGleb Smirnoff * to specific functions and ifp->if_ioctl(). 244bbb3fb61SRobert Watson */ 2456a800098SYoshinobu Inoue switch (cmd) { 246bbb3fb61SRobert Watson case SIOCGIFADDR: 247bbb3fb61SRobert Watson case SIOCGIFBRDADDR: 248bbb3fb61SRobert Watson case SIOCGIFDSTADDR: 249bbb3fb61SRobert Watson case SIOCGIFNETMASK: 250f7a39160SGleb Smirnoff break; 2516952c3e1SAndrey V. Elsukov case SIOCGIFALIAS: 2526952c3e1SAndrey V. Elsukov sx_xlock(&in_control_sx); 2536952c3e1SAndrey V. Elsukov error = in_gifaddr_ioctl(cmd, data, ifp, td); 2546952c3e1SAndrey V. Elsukov sx_xunlock(&in_control_sx); 2556952c3e1SAndrey V. Elsukov return (error); 2566d00fd9cSGleb Smirnoff case SIOCDIFADDR: 257f7a39160SGleb Smirnoff sx_xlock(&in_control_sx); 258338e227aSLuiz Otavio O Souza error = in_difaddr_ioctl(cmd, data, ifp, td); 259f7a39160SGleb Smirnoff sx_xunlock(&in_control_sx); 260f7a39160SGleb Smirnoff return (error); 26177b89ad8SGleb Smirnoff case OSIOCAIFADDR: /* 9.x compat */ 2626d00fd9cSGleb Smirnoff case SIOCAIFADDR: 263f7a39160SGleb Smirnoff sx_xlock(&in_control_sx); 26477b89ad8SGleb Smirnoff error = in_aifaddr_ioctl(cmd, data, ifp, td); 265f7a39160SGleb Smirnoff sx_xunlock(&in_control_sx); 266f7a39160SGleb Smirnoff return (error); 267bbb3fb61SRobert Watson case SIOCSIFADDR: 268bbb3fb61SRobert Watson case SIOCSIFBRDADDR: 269bbb3fb61SRobert Watson case SIOCSIFDSTADDR: 270bbb3fb61SRobert Watson case SIOCSIFNETMASK: 27156cf9dc1SGleb Smirnoff /* We no longer support that old commands. */ 2726d00fd9cSGleb Smirnoff return (EINVAL); 273bbb3fb61SRobert Watson default: 274f7a39160SGleb Smirnoff if (ifp->if_ioctl == NULL) 275bbb3fb61SRobert Watson return (EOPNOTSUPP); 276bbb3fb61SRobert Watson return ((*ifp->if_ioctl)(ifp, cmd, data)); 2776a800098SYoshinobu Inoue } 2786a800098SYoshinobu Inoue 279821b5cafSGleb Smirnoff if (addr->sin_addr.s_addr != INADDR_ANY && 280821b5cafSGleb Smirnoff prison_check_ip4(td->td_ucred, &addr->sin_addr) != 0) 281821b5cafSGleb Smirnoff return (EADDRNOTAVAIL); 282821b5cafSGleb Smirnoff 283cf7b18f1SRobert Watson /* 284a7f77a39SXin LI * Find address for this interface, if it exists. If an 285a7f77a39SXin LI * address was specified, find that one instead of the 286a7f77a39SXin LI * first one on the interface, if possible. 287df8bae1dSRodney W. Grimes */ 288a68cc388SGleb Smirnoff NET_EPOCH_ENTER(et); 289d7c5a620SMatt Macy CK_STAILQ_FOREACH(ifa, &ifp->if_addrhead, ifa_link) { 2909706c950SGleb Smirnoff if (ifa->ifa_addr->sa_family != AF_INET) 2919706c950SGleb Smirnoff continue; 292821b5cafSGleb Smirnoff ia = (struct in_ifaddr *)ifa; 293821b5cafSGleb Smirnoff if (ia->ia_addr.sin_addr.s_addr == addr->sin_addr.s_addr) 294df8bae1dSRodney W. Grimes break; 295ca925d9cSJonathan Lemon } 296a7f77a39SXin LI if (ifa == NULL) 297d7c5a620SMatt Macy CK_STAILQ_FOREACH(ifa, &ifp->if_addrhead, ifa_link) 298a7f77a39SXin LI if (ifa->ifa_addr->sa_family == AF_INET) { 299a7f77a39SXin LI ia = (struct in_ifaddr *)ifa; 300a7f77a39SXin LI if (prison_check_ip4(td->td_ucred, 301a7f77a39SXin LI &ia->ia_addr.sin_addr) == 0) 302a7f77a39SXin LI break; 303a7f77a39SXin LI } 304f7a39160SGleb Smirnoff 305821b5cafSGleb Smirnoff if (ifa == NULL) { 306a68cc388SGleb Smirnoff NET_EPOCH_EXIT(et); 307f7a39160SGleb Smirnoff return (EADDRNOTAVAIL); 308ac0aa473SBill Fenner } 309df8bae1dSRodney W. Grimes 310588885f2SRobert Watson error = 0; 311df8bae1dSRodney W. Grimes switch (cmd) { 312f7a39160SGleb Smirnoff case SIOCGIFADDR: 313f7a39160SGleb Smirnoff *addr = ia->ia_addr; 314f7a39160SGleb Smirnoff break; 3158c0fec80SRobert Watson 316f7a39160SGleb Smirnoff case SIOCGIFBRDADDR: 317f7a39160SGleb Smirnoff if ((ifp->if_flags & IFF_BROADCAST) == 0) { 318f7a39160SGleb Smirnoff error = EINVAL; 319df8bae1dSRodney W. Grimes break; 320df8bae1dSRodney W. Grimes } 321f7a39160SGleb Smirnoff *addr = ia->ia_broadaddr; 322f7a39160SGleb Smirnoff break; 323f7a39160SGleb Smirnoff 324f7a39160SGleb Smirnoff case SIOCGIFDSTADDR: 325f7a39160SGleb Smirnoff if ((ifp->if_flags & IFF_POINTOPOINT) == 0) { 326f7a39160SGleb Smirnoff error = EINVAL; 327f7a39160SGleb Smirnoff break; 328f7a39160SGleb Smirnoff } 329f7a39160SGleb Smirnoff *addr = ia->ia_dstaddr; 330f7a39160SGleb Smirnoff break; 331f7a39160SGleb Smirnoff 332f7a39160SGleb Smirnoff case SIOCGIFNETMASK: 333f7a39160SGleb Smirnoff *addr = ia->ia_sockmask; 334f7a39160SGleb Smirnoff break; 335f7a39160SGleb Smirnoff } 336f7a39160SGleb Smirnoff 337a68cc388SGleb Smirnoff NET_EPOCH_EXIT(et); 338f7a39160SGleb Smirnoff 339f7a39160SGleb Smirnoff return (error); 3401067217dSGarrett Wollman } 341f7a39160SGleb Smirnoff 342f7a39160SGleb Smirnoff static int 34377b89ad8SGleb Smirnoff in_aifaddr_ioctl(u_long cmd, caddr_t data, struct ifnet *ifp, struct thread *td) 344f7a39160SGleb Smirnoff { 345f7a39160SGleb Smirnoff const struct in_aliasreq *ifra = (struct in_aliasreq *)data; 346f7a39160SGleb Smirnoff const struct sockaddr_in *addr = &ifra->ifra_addr; 347f7a39160SGleb Smirnoff const struct sockaddr_in *broadaddr = &ifra->ifra_broadaddr; 348f7a39160SGleb Smirnoff const struct sockaddr_in *mask = &ifra->ifra_mask; 349f7a39160SGleb Smirnoff const struct sockaddr_in *dstaddr = &ifra->ifra_dstaddr; 35077b89ad8SGleb Smirnoff const int vhid = (cmd == SIOCAIFADDR) ? ifra->ifra_vhid : 0; 351a68cc388SGleb Smirnoff struct epoch_tracker et; 352f7a39160SGleb Smirnoff struct ifaddr *ifa; 353f7a39160SGleb Smirnoff struct in_ifaddr *ia; 354f7a39160SGleb Smirnoff bool iaIsFirst; 355f7a39160SGleb Smirnoff int error = 0; 356f7a39160SGleb Smirnoff 357f7a39160SGleb Smirnoff error = priv_check(td, PRIV_NET_ADDIFADDR); 358f7a39160SGleb Smirnoff if (error) 359f7a39160SGleb Smirnoff return (error); 360f7a39160SGleb Smirnoff 361f7a39160SGleb Smirnoff /* 362f7a39160SGleb Smirnoff * ifra_addr must be present and be of INET family. 363f7a39160SGleb Smirnoff * ifra_broadaddr/ifra_dstaddr and ifra_mask are optional. 364f7a39160SGleb Smirnoff */ 365f7a39160SGleb Smirnoff if (addr->sin_len != sizeof(struct sockaddr_in) || 366f7a39160SGleb Smirnoff addr->sin_family != AF_INET) 367f7a39160SGleb Smirnoff return (EINVAL); 368f7a39160SGleb Smirnoff if (broadaddr->sin_len != 0 && 369f7a39160SGleb Smirnoff (broadaddr->sin_len != sizeof(struct sockaddr_in) || 370f7a39160SGleb Smirnoff broadaddr->sin_family != AF_INET)) 371f7a39160SGleb Smirnoff return (EINVAL); 372f7a39160SGleb Smirnoff if (mask->sin_len != 0 && 373f7a39160SGleb Smirnoff (mask->sin_len != sizeof(struct sockaddr_in) || 374f7a39160SGleb Smirnoff mask->sin_family != AF_INET)) 375f7a39160SGleb Smirnoff return (EINVAL); 376f7a39160SGleb Smirnoff if ((ifp->if_flags & IFF_POINTOPOINT) && 377f7a39160SGleb Smirnoff (dstaddr->sin_len != sizeof(struct sockaddr_in) || 378f7a39160SGleb Smirnoff dstaddr->sin_addr.s_addr == INADDR_ANY)) 379f7a39160SGleb Smirnoff return (EDESTADDRREQ); 380620cf65cSArtem Khramov if (vhid != 0 && carp_attach_p == NULL) 381f7a39160SGleb Smirnoff return (EPROTONOSUPPORT); 382f7a39160SGleb Smirnoff 383f7a39160SGleb Smirnoff /* 384f7a39160SGleb Smirnoff * See whether address already exist. 385f7a39160SGleb Smirnoff */ 386f7a39160SGleb Smirnoff iaIsFirst = true; 387f7a39160SGleb Smirnoff ia = NULL; 388a68cc388SGleb Smirnoff NET_EPOCH_ENTER(et); 389d7c5a620SMatt Macy CK_STAILQ_FOREACH(ifa, &ifp->if_addrhead, ifa_link) { 3909706c950SGleb Smirnoff struct in_ifaddr *it; 391f7a39160SGleb Smirnoff 3929706c950SGleb Smirnoff if (ifa->ifa_addr->sa_family != AF_INET) 393f7a39160SGleb Smirnoff continue; 394f7a39160SGleb Smirnoff 3959706c950SGleb Smirnoff it = (struct in_ifaddr *)ifa; 396f7a39160SGleb Smirnoff if (it->ia_addr.sin_addr.s_addr == addr->sin_addr.s_addr && 397f7a39160SGleb Smirnoff prison_check_ip4(td->td_ucred, &addr->sin_addr) == 0) 398f7a39160SGleb Smirnoff ia = it; 3993f740d43SAndrey V. Elsukov else 4003f740d43SAndrey V. Elsukov iaIsFirst = false; 4011067217dSGarrett Wollman } 402a68cc388SGleb Smirnoff NET_EPOCH_EXIT(et); 403f7a39160SGleb Smirnoff 404f7a39160SGleb Smirnoff if (ia != NULL) 405338e227aSLuiz Otavio O Souza (void )in_difaddr_ioctl(cmd, data, ifp, td); 406f7a39160SGleb Smirnoff 40746758960SGleb Smirnoff ifa = ifa_alloc(sizeof(struct in_ifaddr), M_WAITOK); 40846758960SGleb Smirnoff ia = (struct in_ifaddr *)ifa; 40959562606SGarrett Wollman ifa->ifa_addr = (struct sockaddr *)&ia->ia_addr; 41059562606SGarrett Wollman ifa->ifa_dstaddr = (struct sockaddr *)&ia->ia_dstaddr; 41159562606SGarrett Wollman ifa->ifa_netmask = (struct sockaddr *)&ia->ia_sockmask; 4122d9db0bcSEric van Gyzen callout_init_rw(&ia->ia_garp_timer, &ifp->if_addr_lock, 4132d9db0bcSEric van Gyzen CALLOUT_RETURNUNLOCKED); 41419fc74fbSJeffrey Hsu 415f7a39160SGleb Smirnoff ia->ia_ifp = ifp; 416f7a39160SGleb Smirnoff ia->ia_addr = *addr; 417f7a39160SGleb Smirnoff if (mask->sin_len != 0) { 418f7a39160SGleb Smirnoff ia->ia_sockmask = *mask; 419f7a39160SGleb Smirnoff ia->ia_subnetmask = ntohl(ia->ia_sockmask.sin_addr.s_addr); 420f7a39160SGleb Smirnoff } else { 421f7a39160SGleb Smirnoff in_addr_t i = ntohl(addr->sin_addr.s_addr); 422f7a39160SGleb Smirnoff 423f7a39160SGleb Smirnoff /* 424f7a39160SGleb Smirnoff * Be compatible with network classes, if netmask isn't 425f7a39160SGleb Smirnoff * supplied, guess it based on classes. 426f7a39160SGleb Smirnoff */ 427f7a39160SGleb Smirnoff if (IN_CLASSA(i)) 428f7a39160SGleb Smirnoff ia->ia_subnetmask = IN_CLASSA_NET; 429f7a39160SGleb Smirnoff else if (IN_CLASSB(i)) 430f7a39160SGleb Smirnoff ia->ia_subnetmask = IN_CLASSB_NET; 431f7a39160SGleb Smirnoff else 432f7a39160SGleb Smirnoff ia->ia_subnetmask = IN_CLASSC_NET; 433f7a39160SGleb Smirnoff ia->ia_sockmask.sin_addr.s_addr = htonl(ia->ia_subnetmask); 434f7a39160SGleb Smirnoff } 435f7a39160SGleb Smirnoff ia->ia_subnet = ntohl(addr->sin_addr.s_addr) & ia->ia_subnetmask; 436f7a39160SGleb Smirnoff in_socktrim(&ia->ia_sockmask); 437f7a39160SGleb Smirnoff 438df8bae1dSRodney W. Grimes if (ifp->if_flags & IFF_BROADCAST) { 439f7a39160SGleb Smirnoff if (broadaddr->sin_len != 0) { 440f7a39160SGleb Smirnoff ia->ia_broadaddr = *broadaddr; 441f7a39160SGleb Smirnoff } else if (ia->ia_subnetmask == IN_RFC3021_MASK) { 442f7a39160SGleb Smirnoff ia->ia_broadaddr.sin_addr.s_addr = INADDR_BROADCAST; 443f7a39160SGleb Smirnoff ia->ia_broadaddr.sin_len = sizeof(struct sockaddr_in); 444f7a39160SGleb Smirnoff ia->ia_broadaddr.sin_family = AF_INET; 445f7a39160SGleb Smirnoff } else { 446f7a39160SGleb Smirnoff ia->ia_broadaddr.sin_addr.s_addr = 447f7a39160SGleb Smirnoff htonl(ia->ia_subnet | ~ia->ia_subnetmask); 448f7a39160SGleb Smirnoff ia->ia_broadaddr.sin_len = sizeof(struct sockaddr_in); 449df8bae1dSRodney W. Grimes ia->ia_broadaddr.sin_family = AF_INET; 450df8bae1dSRodney W. Grimes } 451f7a39160SGleb Smirnoff } 452f7a39160SGleb Smirnoff 453f7a39160SGleb Smirnoff if (ifp->if_flags & IFF_POINTOPOINT) 454f7a39160SGleb Smirnoff ia->ia_dstaddr = *dstaddr; 455f7a39160SGleb Smirnoff 4565af464bbSSteven Hartland if (vhid != 0) { 4575af464bbSSteven Hartland error = (*carp_attach_p)(&ia->ia_ifa, vhid); 4585af464bbSSteven Hartland if (error) 4595af464bbSSteven Hartland return (error); 4605af464bbSSteven Hartland } 4615af464bbSSteven Hartland 462a49b317cSAlexander V. Chernikov /* if_addrhead is already referenced by ifa_alloc() */ 463137f91e8SJohn Baldwin IF_ADDR_WLOCK(ifp); 464d7c5a620SMatt Macy CK_STAILQ_INSERT_TAIL(&ifp->if_addrhead, ifa, ifa_link); 465137f91e8SJohn Baldwin IF_ADDR_WUNLOCK(ifp); 466f7a39160SGleb Smirnoff 4678c0fec80SRobert Watson ifa_ref(ifa); /* in_ifaddrhead */ 4682d9cfabaSRobert Watson IN_IFADDR_WLOCK(); 469d7c5a620SMatt Macy CK_STAILQ_INSERT_TAIL(&V_in_ifaddrhead, ia, ia_link); 470f7a39160SGleb Smirnoff LIST_INSERT_HEAD(INADDR_HASH(ia->ia_addr.sin_addr.s_addr), ia, ia_hash); 4712d9cfabaSRobert Watson IN_IFADDR_WUNLOCK(); 472df8bae1dSRodney W. Grimes 473f7a39160SGleb Smirnoff /* 474f7a39160SGleb Smirnoff * Give the interface a chance to initialize 475f7a39160SGleb Smirnoff * if this is its first address, 476f7a39160SGleb Smirnoff * and to validate the address if necessary. 477f7a39160SGleb Smirnoff */ 478d34165f7SSteven Hartland if (ifp->if_ioctl != NULL) { 479f7a39160SGleb Smirnoff error = (*ifp->if_ioctl)(ifp, SIOCSIFADDR, (caddr_t)ia); 480f7a39160SGleb Smirnoff if (error) 4815af464bbSSteven Hartland goto fail1; 482d34165f7SSteven Hartland } 483f7a39160SGleb Smirnoff 484f7a39160SGleb Smirnoff /* 485f7a39160SGleb Smirnoff * Add route for the network. 486f7a39160SGleb Smirnoff */ 487f7a39160SGleb Smirnoff if (vhid == 0) { 488130aebbaSAlexander V. Chernikov error = in_addprefix(ia); 489f7a39160SGleb Smirnoff if (error) 4905af464bbSSteven Hartland goto fail1; 491df8bae1dSRodney W. Grimes } 492df8bae1dSRodney W. Grimes 493588885f2SRobert Watson /* 494f7a39160SGleb Smirnoff * Add a loopback route to self. 495588885f2SRobert Watson */ 496130aebbaSAlexander V. Chernikov if (vhid == 0 && ia_need_loopback_route(ia)) { 497f7a39160SGleb Smirnoff struct in_ifaddr *eia; 498df8bae1dSRodney W. Grimes 499f7a39160SGleb Smirnoff eia = in_localip_more(ia); 500f7a39160SGleb Smirnoff 501f7a39160SGleb Smirnoff if (eia == NULL) { 502f7a39160SGleb Smirnoff error = ifa_add_loopback_route((struct ifaddr *)ia, 503f7a39160SGleb Smirnoff (struct sockaddr *)&ia->ia_addr); 504f7a39160SGleb Smirnoff if (error) 5055af464bbSSteven Hartland goto fail2; 506f7a39160SGleb Smirnoff } else 507f7a39160SGleb Smirnoff ifa_free(&eia->ia_ifa); 508588885f2SRobert Watson } 509df8bae1dSRodney W. Grimes 510f7a39160SGleb Smirnoff if (iaIsFirst && (ifp->if_flags & IFF_MULTICAST)) { 511f7a39160SGleb Smirnoff struct in_addr allhosts_addr; 512f7a39160SGleb Smirnoff struct in_ifinfo *ii; 513df8bae1dSRodney W. Grimes 514c75aa354SBruce M Simpson ii = ((struct in_ifinfo *)ifp->if_afdata[AF_INET]); 515f7a39160SGleb Smirnoff allhosts_addr.s_addr = htonl(INADDR_ALLHOSTS_GROUP); 516df8bae1dSRodney W. Grimes 517f7a39160SGleb Smirnoff error = in_joingroup(ifp, &allhosts_addr, NULL, 518f7a39160SGleb Smirnoff &ii->ii_allhosts); 519f7a39160SGleb Smirnoff } 520f7a39160SGleb Smirnoff 52164d63b1eSAndrey V. Elsukov /* 52264d63b1eSAndrey V. Elsukov * Note: we don't need extra reference for ifa, since we called 52364d63b1eSAndrey V. Elsukov * with sx lock held, and ifaddr can not be deleted in concurrent 52464d63b1eSAndrey V. Elsukov * thread. 52564d63b1eSAndrey V. Elsukov */ 52664d63b1eSAndrey V. Elsukov EVENTHANDLER_INVOKE(ifaddr_event_ext, ifp, ifa, IFADDR_EVENT_ADD); 527f7a39160SGleb Smirnoff 528f7a39160SGleb Smirnoff return (error); 529f7a39160SGleb Smirnoff 5305af464bbSSteven Hartland fail2: 531f7a39160SGleb Smirnoff if (vhid == 0) 532f7a39160SGleb Smirnoff (void )in_scrubprefix(ia, LLE_STATIC); 533f7a39160SGleb Smirnoff 5345af464bbSSteven Hartland fail1: 535f7a39160SGleb Smirnoff if (ia->ia_ifa.ifa_carp) 536338e227aSLuiz Otavio O Souza (*carp_detach_p)(&ia->ia_ifa, false); 537f7a39160SGleb Smirnoff 538f7a39160SGleb Smirnoff IF_ADDR_WLOCK(ifp); 539d7c5a620SMatt Macy CK_STAILQ_REMOVE(&ifp->if_addrhead, &ia->ia_ifa, ifaddr, ifa_link); 540f7a39160SGleb Smirnoff IF_ADDR_WUNLOCK(ifp); 541a49b317cSAlexander V. Chernikov ifa_free(&ia->ia_ifa); /* if_addrhead */ 542f7a39160SGleb Smirnoff 543f7a39160SGleb Smirnoff IN_IFADDR_WLOCK(); 544d7c5a620SMatt Macy CK_STAILQ_REMOVE(&V_in_ifaddrhead, ia, in_ifaddr, ia_link); 545f7a39160SGleb Smirnoff LIST_REMOVE(ia, ia_hash); 546f7a39160SGleb Smirnoff IN_IFADDR_WUNLOCK(); 547a49b317cSAlexander V. Chernikov ifa_free(&ia->ia_ifa); /* in_ifaddrhead */ 548f7a39160SGleb Smirnoff 549f7a39160SGleb Smirnoff return (error); 550f7a39160SGleb Smirnoff } 551f7a39160SGleb Smirnoff 552f7a39160SGleb Smirnoff static int 553338e227aSLuiz Otavio O Souza in_difaddr_ioctl(u_long cmd, caddr_t data, struct ifnet *ifp, struct thread *td) 554f7a39160SGleb Smirnoff { 555f7a39160SGleb Smirnoff const struct ifreq *ifr = (struct ifreq *)data; 5566224cd89SNathan Whitehorn const struct sockaddr_in *addr = (const struct sockaddr_in *) 5576224cd89SNathan Whitehorn &ifr->ifr_addr; 558f7a39160SGleb Smirnoff struct ifaddr *ifa; 559f7a39160SGleb Smirnoff struct in_ifaddr *ia; 560f7a39160SGleb Smirnoff bool deleteAny, iaIsLast; 561f7a39160SGleb Smirnoff int error; 562f7a39160SGleb Smirnoff 563f7a39160SGleb Smirnoff if (td != NULL) { 564f7a39160SGleb Smirnoff error = priv_check(td, PRIV_NET_DELIFADDR); 565f7a39160SGleb Smirnoff if (error) 566f7a39160SGleb Smirnoff return (error); 567f7a39160SGleb Smirnoff } 568f7a39160SGleb Smirnoff 569f7a39160SGleb Smirnoff if (addr->sin_len != sizeof(struct sockaddr_in) || 570f7a39160SGleb Smirnoff addr->sin_family != AF_INET) 571f7a39160SGleb Smirnoff deleteAny = true; 572f7a39160SGleb Smirnoff else 573f7a39160SGleb Smirnoff deleteAny = false; 574f7a39160SGleb Smirnoff 575f7a39160SGleb Smirnoff iaIsLast = true; 576f7a39160SGleb Smirnoff ia = NULL; 577f7a39160SGleb Smirnoff IF_ADDR_WLOCK(ifp); 578d7c5a620SMatt Macy CK_STAILQ_FOREACH(ifa, &ifp->if_addrhead, ifa_link) { 5799706c950SGleb Smirnoff struct in_ifaddr *it; 580f7a39160SGleb Smirnoff 5819706c950SGleb Smirnoff if (ifa->ifa_addr->sa_family != AF_INET) 582f7a39160SGleb Smirnoff continue; 583f7a39160SGleb Smirnoff 5849706c950SGleb Smirnoff it = (struct in_ifaddr *)ifa; 585f7a39160SGleb Smirnoff if (deleteAny && ia == NULL && (td == NULL || 586f7a39160SGleb Smirnoff prison_check_ip4(td->td_ucred, &it->ia_addr.sin_addr) == 0)) 587f7a39160SGleb Smirnoff ia = it; 588f7a39160SGleb Smirnoff 589f7a39160SGleb Smirnoff if (it->ia_addr.sin_addr.s_addr == addr->sin_addr.s_addr && 590f7a39160SGleb Smirnoff (td == NULL || prison_check_ip4(td->td_ucred, 591f7a39160SGleb Smirnoff &addr->sin_addr) == 0)) 592f7a39160SGleb Smirnoff ia = it; 593f7a39160SGleb Smirnoff 594f7a39160SGleb Smirnoff if (it != ia) 595f7a39160SGleb Smirnoff iaIsLast = false; 596f7a39160SGleb Smirnoff } 597f7a39160SGleb Smirnoff 598f7a39160SGleb Smirnoff if (ia == NULL) { 599f7a39160SGleb Smirnoff IF_ADDR_WUNLOCK(ifp); 600f7a39160SGleb Smirnoff return (EADDRNOTAVAIL); 601f7a39160SGleb Smirnoff } 602f7a39160SGleb Smirnoff 603d7c5a620SMatt Macy CK_STAILQ_REMOVE(&ifp->if_addrhead, &ia->ia_ifa, ifaddr, ifa_link); 604f7a39160SGleb Smirnoff IF_ADDR_WUNLOCK(ifp); 605f7a39160SGleb Smirnoff ifa_free(&ia->ia_ifa); /* if_addrhead */ 606f7a39160SGleb Smirnoff 607f7a39160SGleb Smirnoff IN_IFADDR_WLOCK(); 608d7c5a620SMatt Macy CK_STAILQ_REMOVE(&V_in_ifaddrhead, ia, in_ifaddr, ia_link); 609f7a39160SGleb Smirnoff LIST_REMOVE(ia, ia_hash); 610f7a39160SGleb Smirnoff IN_IFADDR_WUNLOCK(); 611f7a39160SGleb Smirnoff 612089cdfadSRuslan Ermilov /* 613237bf7f7SGleb Smirnoff * in_scrubprefix() kills the interface route. 614089cdfadSRuslan Ermilov */ 615237bf7f7SGleb Smirnoff in_scrubprefix(ia, LLE_STATIC); 616588885f2SRobert Watson 617c655b7c4SDavid Greenman /* 618089cdfadSRuslan Ermilov * in_ifadown gets rid of all the rest of 619089cdfadSRuslan Ermilov * the routes. This is not quite the right 620089cdfadSRuslan Ermilov * thing to do, but at least if we are running 621089cdfadSRuslan Ermilov * a routing process they will come back. 622089cdfadSRuslan Ermilov */ 62391854268SRuslan Ermilov in_ifadown(&ia->ia_ifa, 1); 6240f02fdacSBrian Somers 62508b68b0eSGleb Smirnoff if (ia->ia_ifa.ifa_carp) 62659b2022fSLuiz Otavio O Souza (*carp_detach_p)(&ia->ia_ifa, cmd == SIOCAIFADDR); 62708b68b0eSGleb Smirnoff 628f7e083afSBruce M Simpson /* 629f7e083afSBruce M Simpson * If this is the last IPv4 address configured on this 630f7e083afSBruce M Simpson * interface, leave the all-hosts group. 631d10910e6SBruce M Simpson * No state-change report need be transmitted. 632f7e083afSBruce M Simpson */ 633f7a39160SGleb Smirnoff if (iaIsLast && (ifp->if_flags & IFF_MULTICAST)) { 634f7a39160SGleb Smirnoff struct in_ifinfo *ii; 635f7a39160SGleb Smirnoff 636c75aa354SBruce M Simpson ii = ((struct in_ifinfo *)ifp->if_afdata[AF_INET]); 637d10910e6SBruce M Simpson if (ii->ii_allhosts) { 638f3e1324bSStephen Hurd (void)in_leavegroup(ii->ii_allhosts, NULL); 639d10910e6SBruce M Simpson ii->ii_allhosts = NULL; 640d10910e6SBruce M Simpson } 641f7a39160SGleb Smirnoff } 6426d00fd9cSGleb Smirnoff 6432d9db0bcSEric van Gyzen IF_ADDR_WLOCK(ifp); 6442d9db0bcSEric van Gyzen if (callout_stop(&ia->ia_garp_timer) == 1) { 6452d9db0bcSEric van Gyzen ifa_free(&ia->ia_ifa); 6462d9db0bcSEric van Gyzen } 6472d9db0bcSEric van Gyzen IF_ADDR_WUNLOCK(ifp); 6482d9db0bcSEric van Gyzen 64964d63b1eSAndrey V. Elsukov EVENTHANDLER_INVOKE(ifaddr_event_ext, ifp, &ia->ia_ifa, 65064d63b1eSAndrey V. Elsukov IFADDR_EVENT_DEL); 651a49b317cSAlexander V. Chernikov ifa_free(&ia->ia_ifa); /* in_ifaddrhead */ 652f7a39160SGleb Smirnoff 653f7a39160SGleb Smirnoff return (0); 654df8bae1dSRodney W. Grimes } 655df8bae1dSRodney W. Grimes 6566952c3e1SAndrey V. Elsukov static int 6576952c3e1SAndrey V. Elsukov in_gifaddr_ioctl(u_long cmd, caddr_t data, struct ifnet *ifp, struct thread *td) 6586952c3e1SAndrey V. Elsukov { 6596952c3e1SAndrey V. Elsukov struct in_aliasreq *ifra = (struct in_aliasreq *)data; 6606952c3e1SAndrey V. Elsukov const struct sockaddr_in *addr = &ifra->ifra_addr; 6616952c3e1SAndrey V. Elsukov struct epoch_tracker et; 6626952c3e1SAndrey V. Elsukov struct ifaddr *ifa; 6636952c3e1SAndrey V. Elsukov struct in_ifaddr *ia; 6646952c3e1SAndrey V. Elsukov 6656952c3e1SAndrey V. Elsukov /* 6666952c3e1SAndrey V. Elsukov * ifra_addr must be present and be of INET family. 6676952c3e1SAndrey V. Elsukov */ 6686952c3e1SAndrey V. Elsukov if (addr->sin_len != sizeof(struct sockaddr_in) || 6696952c3e1SAndrey V. Elsukov addr->sin_family != AF_INET) 6706952c3e1SAndrey V. Elsukov return (EINVAL); 6716952c3e1SAndrey V. Elsukov 6726952c3e1SAndrey V. Elsukov /* 6736952c3e1SAndrey V. Elsukov * See whether address exist. 6746952c3e1SAndrey V. Elsukov */ 6756952c3e1SAndrey V. Elsukov ia = NULL; 6766952c3e1SAndrey V. Elsukov NET_EPOCH_ENTER(et); 6776952c3e1SAndrey V. Elsukov CK_STAILQ_FOREACH(ifa, &ifp->if_addrhead, ifa_link) { 6786952c3e1SAndrey V. Elsukov struct in_ifaddr *it; 6796952c3e1SAndrey V. Elsukov 6806952c3e1SAndrey V. Elsukov if (ifa->ifa_addr->sa_family != AF_INET) 6816952c3e1SAndrey V. Elsukov continue; 6826952c3e1SAndrey V. Elsukov 6836952c3e1SAndrey V. Elsukov it = (struct in_ifaddr *)ifa; 6846952c3e1SAndrey V. Elsukov if (it->ia_addr.sin_addr.s_addr == addr->sin_addr.s_addr && 6856952c3e1SAndrey V. Elsukov prison_check_ip4(td->td_ucred, &addr->sin_addr) == 0) { 6866952c3e1SAndrey V. Elsukov ia = it; 6876952c3e1SAndrey V. Elsukov break; 6886952c3e1SAndrey V. Elsukov } 6896952c3e1SAndrey V. Elsukov } 6906952c3e1SAndrey V. Elsukov if (ia == NULL) { 6916952c3e1SAndrey V. Elsukov NET_EPOCH_EXIT(et); 6926952c3e1SAndrey V. Elsukov return (EADDRNOTAVAIL); 6936952c3e1SAndrey V. Elsukov } 6946952c3e1SAndrey V. Elsukov 6956952c3e1SAndrey V. Elsukov ifra->ifra_mask = ia->ia_sockmask; 6966952c3e1SAndrey V. Elsukov if ((ifp->if_flags & IFF_POINTOPOINT) && 6976952c3e1SAndrey V. Elsukov ia->ia_dstaddr.sin_family == AF_INET) 6986952c3e1SAndrey V. Elsukov ifra->ifra_dstaddr = ia->ia_dstaddr; 6996952c3e1SAndrey V. Elsukov else if ((ifp->if_flags & IFF_BROADCAST) && 7006952c3e1SAndrey V. Elsukov ia->ia_broadaddr.sin_family == AF_INET) 7016952c3e1SAndrey V. Elsukov ifra->ifra_broadaddr = ia->ia_broadaddr; 7026952c3e1SAndrey V. Elsukov else 7036952c3e1SAndrey V. Elsukov memset(&ifra->ifra_broadaddr, 0, 7046952c3e1SAndrey V. Elsukov sizeof(ifra->ifra_broadaddr)); 7056952c3e1SAndrey V. Elsukov 7066952c3e1SAndrey V. Elsukov NET_EPOCH_EXIT(et); 7076952c3e1SAndrey V. Elsukov return (0); 7086952c3e1SAndrey V. Elsukov } 7096952c3e1SAndrey V. Elsukov 71081728a53SAlexander V. Chernikov static int 71181728a53SAlexander V. Chernikov in_match_ifaddr(const struct rtentry *rt, const struct nhop_object *nh, void *arg) 71281728a53SAlexander V. Chernikov { 71381728a53SAlexander V. Chernikov 71481728a53SAlexander V. Chernikov if (nh->nh_ifa == (struct ifaddr *)arg) 71581728a53SAlexander V. Chernikov return (1); 71681728a53SAlexander V. Chernikov 71781728a53SAlexander V. Chernikov return (0); 71881728a53SAlexander V. Chernikov } 71981728a53SAlexander V. Chernikov 72081728a53SAlexander V. Chernikov static int 72181728a53SAlexander V. Chernikov in_handle_prefix_route(uint32_t fibnum, int cmd, 722130aebbaSAlexander V. Chernikov struct sockaddr_in *dst, struct sockaddr_in *netmask, struct ifaddr *ifa, 723130aebbaSAlexander V. Chernikov struct ifnet *ifp) 72481728a53SAlexander V. Chernikov { 72581728a53SAlexander V. Chernikov 72681728a53SAlexander V. Chernikov NET_EPOCH_ASSERT(); 72781728a53SAlexander V. Chernikov 72881728a53SAlexander V. Chernikov /* Prepare gateway */ 72981728a53SAlexander V. Chernikov struct sockaddr_dl_short sdl = { 73081728a53SAlexander V. Chernikov .sdl_family = AF_LINK, 73181728a53SAlexander V. Chernikov .sdl_len = sizeof(struct sockaddr_dl_short), 73281728a53SAlexander V. Chernikov .sdl_type = ifa->ifa_ifp->if_type, 73381728a53SAlexander V. Chernikov .sdl_index = ifa->ifa_ifp->if_index, 73481728a53SAlexander V. Chernikov }; 73581728a53SAlexander V. Chernikov 73681728a53SAlexander V. Chernikov struct rt_addrinfo info = { 73781728a53SAlexander V. Chernikov .rti_ifa = ifa, 738130aebbaSAlexander V. Chernikov .rti_ifp = ifp, 73981728a53SAlexander V. Chernikov .rti_flags = RTF_PINNED | ((netmask != NULL) ? 0 : RTF_HOST), 74081728a53SAlexander V. Chernikov .rti_info = { 74181728a53SAlexander V. Chernikov [RTAX_DST] = (struct sockaddr *)dst, 74281728a53SAlexander V. Chernikov [RTAX_NETMASK] = (struct sockaddr *)netmask, 74381728a53SAlexander V. Chernikov [RTAX_GATEWAY] = (struct sockaddr *)&sdl, 74481728a53SAlexander V. Chernikov }, 74581728a53SAlexander V. Chernikov /* Ensure we delete the prefix IFF prefix ifa matches */ 74681728a53SAlexander V. Chernikov .rti_filter = in_match_ifaddr, 74781728a53SAlexander V. Chernikov .rti_filterdata = ifa, 74881728a53SAlexander V. Chernikov }; 74981728a53SAlexander V. Chernikov 75081728a53SAlexander V. Chernikov return (rib_handle_ifaddr_info(fibnum, cmd, &info)); 75181728a53SAlexander V. Chernikov } 75281728a53SAlexander V. Chernikov 75381728a53SAlexander V. Chernikov /* 754130aebbaSAlexander V. Chernikov * Routing table interaction with interface addresses. 755130aebbaSAlexander V. Chernikov * 756130aebbaSAlexander V. Chernikov * In general, two types of routes needs to be installed: 757130aebbaSAlexander V. Chernikov * a) "interface" or "prefix" route, telling user that the addresses 758130aebbaSAlexander V. Chernikov * behind the ifa prefix are reached directly. 759130aebbaSAlexander V. Chernikov * b) "loopback" route installed for the ifa address, telling user that 760130aebbaSAlexander V. Chernikov * the address belongs to local system. 761130aebbaSAlexander V. Chernikov * 762130aebbaSAlexander V. Chernikov * Handling for (a) and (b) differs in multi-fib aspects, hence they 763130aebbaSAlexander V. Chernikov * are implemented in different functions below. 764130aebbaSAlexander V. Chernikov * 765130aebbaSAlexander V. Chernikov * The cases above may intersect - /32 interface aliases results in 766130aebbaSAlexander V. Chernikov * the same prefix produced by (a) and (b). This blurs the definition 767130aebbaSAlexander V. Chernikov * of the "loopback" route and complicate interactions. The interaction 768130aebbaSAlexander V. Chernikov * table is defined below. The case numbers are used in the multiple 769130aebbaSAlexander V. Chernikov * functions below to refer to the particular test case. 770130aebbaSAlexander V. Chernikov * 77181728a53SAlexander V. Chernikov * There can be multiple options: 772130aebbaSAlexander V. Chernikov * 1) Adding address with prefix on non-p2p/non-loopback interface. 773130aebbaSAlexander V. Chernikov * Example: 192.0.2.1/24. Action: 774130aebbaSAlexander V. Chernikov * * add "prefix" route towards 192.0.2.0/24 via @ia interface, 775130aebbaSAlexander V. Chernikov * using @ia as an address source. 776130aebbaSAlexander V. Chernikov * * add "loopback" route towards 192.0.2.1 via V_loif, saving 777130aebbaSAlexander V. Chernikov * @ia ifp in the gateway and using @ia as an address source. 778130aebbaSAlexander V. Chernikov * 779130aebbaSAlexander V. Chernikov * 2) Adding address with /32 mask to non-p2p/non-loopback interface. 780130aebbaSAlexander V. Chernikov * Example: 192.0.2.2/32. Action: 781130aebbaSAlexander V. Chernikov * * add "prefix" host route via V_loif, using @ia as an address source. 782130aebbaSAlexander V. Chernikov * 78381728a53SAlexander V. Chernikov * 3) Adding address with or without prefix to p2p interface. 784130aebbaSAlexander V. Chernikov * Example: 10.0.0.1/24->10.0.0.2. Action: 785130aebbaSAlexander V. Chernikov * * add "prefix" host route towards 10.0.0.2 via this interface, using @ia 786130aebbaSAlexander V. Chernikov * as an address source. Note: no sense in installing full /24 as the interface 787130aebbaSAlexander V. Chernikov * is point-to-point. 788130aebbaSAlexander V. Chernikov * * add "loopback" route towards 10.0.9.1 via V_loif, saving 789130aebbaSAlexander V. Chernikov * @ia ifp in the gateway and using @ia as an address source. 790130aebbaSAlexander V. Chernikov * 79181728a53SAlexander V. Chernikov * 4) Adding address with or without prefix to loopback interface. 792130aebbaSAlexander V. Chernikov * Example: 192.0.2.1/24. Action: 793130aebbaSAlexander V. Chernikov * * add "prefix" host route via @ia interface, using @ia as an address source. 794130aebbaSAlexander V. Chernikov * Note: Skip installing /24 prefix as it would introduce TTL loop 795130aebbaSAlexander V. Chernikov * for the traffic destined to these addresses. 796130aebbaSAlexander V. Chernikov */ 797130aebbaSAlexander V. Chernikov 798130aebbaSAlexander V. Chernikov /* 799130aebbaSAlexander V. Chernikov * Checks if @ia needs to install loopback route to @ia address via 800130aebbaSAlexander V. Chernikov * ifa_maintain_loopback_route(). 801130aebbaSAlexander V. Chernikov * 802130aebbaSAlexander V. Chernikov * Return true on success. 803130aebbaSAlexander V. Chernikov */ 804130aebbaSAlexander V. Chernikov static bool 805130aebbaSAlexander V. Chernikov ia_need_loopback_route(const struct in_ifaddr *ia) 806130aebbaSAlexander V. Chernikov { 807130aebbaSAlexander V. Chernikov struct ifnet *ifp = ia->ia_ifp; 808130aebbaSAlexander V. Chernikov 809130aebbaSAlexander V. Chernikov /* Case 4: Skip loopback interfaces */ 810130aebbaSAlexander V. Chernikov if ((ifp->if_flags & IFF_LOOPBACK) || 811130aebbaSAlexander V. Chernikov (ia->ia_addr.sin_addr.s_addr == INADDR_ANY)) 812130aebbaSAlexander V. Chernikov return (false); 813130aebbaSAlexander V. Chernikov 814130aebbaSAlexander V. Chernikov /* Clash avoidance: Skip p2p interfaces with both addresses are equal */ 815130aebbaSAlexander V. Chernikov if ((ifp->if_flags & IFF_POINTOPOINT) && 816130aebbaSAlexander V. Chernikov ia->ia_dstaddr.sin_addr.s_addr == ia->ia_addr.sin_addr.s_addr) 817130aebbaSAlexander V. Chernikov return (false); 818130aebbaSAlexander V. Chernikov 819130aebbaSAlexander V. Chernikov /* Case 2: skip /32 prefixes */ 820130aebbaSAlexander V. Chernikov if (!(ifp->if_flags & IFF_POINTOPOINT) && 821130aebbaSAlexander V. Chernikov (ia->ia_sockmask.sin_addr.s_addr == INADDR_BROADCAST)) 822130aebbaSAlexander V. Chernikov return (false); 823130aebbaSAlexander V. Chernikov 824130aebbaSAlexander V. Chernikov return (true); 825130aebbaSAlexander V. Chernikov } 826130aebbaSAlexander V. Chernikov 827130aebbaSAlexander V. Chernikov /* 828130aebbaSAlexander V. Chernikov * Calculate "prefix" route corresponding to @ia. 829130aebbaSAlexander V. Chernikov */ 830130aebbaSAlexander V. Chernikov static void 831130aebbaSAlexander V. Chernikov ia_getrtprefix(const struct in_ifaddr *ia, struct in_addr *prefix, struct in_addr *mask) 832130aebbaSAlexander V. Chernikov { 833130aebbaSAlexander V. Chernikov 834130aebbaSAlexander V. Chernikov if (ia->ia_ifp->if_flags & IFF_POINTOPOINT) { 835130aebbaSAlexander V. Chernikov /* Case 3: return host route for dstaddr */ 836130aebbaSAlexander V. Chernikov *prefix = ia->ia_dstaddr.sin_addr; 837130aebbaSAlexander V. Chernikov mask->s_addr = INADDR_BROADCAST; 838130aebbaSAlexander V. Chernikov } else if (ia->ia_ifp->if_flags & IFF_LOOPBACK) { 839130aebbaSAlexander V. Chernikov /* Case 4: return host route for ifaddr */ 840130aebbaSAlexander V. Chernikov *prefix = ia->ia_addr.sin_addr; 841130aebbaSAlexander V. Chernikov mask->s_addr = INADDR_BROADCAST; 842130aebbaSAlexander V. Chernikov } else { 843130aebbaSAlexander V. Chernikov /* Cases 1,2: return actual ia prefix */ 844130aebbaSAlexander V. Chernikov *prefix = ia->ia_addr.sin_addr; 845130aebbaSAlexander V. Chernikov *mask = ia->ia_sockmask.sin_addr; 846130aebbaSAlexander V. Chernikov prefix->s_addr &= mask->s_addr; 847130aebbaSAlexander V. Chernikov } 848130aebbaSAlexander V. Chernikov } 849130aebbaSAlexander V. Chernikov 850130aebbaSAlexander V. Chernikov /* 851130aebbaSAlexander V. Chernikov * Adds or delete interface "prefix" route corresponding to @ifa. 852130aebbaSAlexander V. Chernikov * Returns 0 on success or errno. 85381728a53SAlexander V. Chernikov */ 85481728a53SAlexander V. Chernikov int 85581728a53SAlexander V. Chernikov in_handle_ifaddr_route(int cmd, struct in_ifaddr *ia) 85681728a53SAlexander V. Chernikov { 85781728a53SAlexander V. Chernikov struct ifaddr *ifa = &ia->ia_ifa; 85881728a53SAlexander V. Chernikov struct in_addr daddr, maddr; 85981728a53SAlexander V. Chernikov struct sockaddr_in *pmask; 86081728a53SAlexander V. Chernikov struct epoch_tracker et; 86181728a53SAlexander V. Chernikov int error; 86281728a53SAlexander V. Chernikov 863130aebbaSAlexander V. Chernikov ia_getrtprefix(ia, &daddr, &maddr); 86481728a53SAlexander V. Chernikov 86581728a53SAlexander V. Chernikov struct sockaddr_in mask = { 86681728a53SAlexander V. Chernikov .sin_family = AF_INET, 86781728a53SAlexander V. Chernikov .sin_len = sizeof(struct sockaddr_in), 86881728a53SAlexander V. Chernikov .sin_addr = maddr, 86981728a53SAlexander V. Chernikov }; 87081728a53SAlexander V. Chernikov 871130aebbaSAlexander V. Chernikov pmask = (maddr.s_addr != INADDR_BROADCAST) ? &mask : NULL; 87281728a53SAlexander V. Chernikov 87381728a53SAlexander V. Chernikov struct sockaddr_in dst = { 87481728a53SAlexander V. Chernikov .sin_family = AF_INET, 87581728a53SAlexander V. Chernikov .sin_len = sizeof(struct sockaddr_in), 87681728a53SAlexander V. Chernikov .sin_addr.s_addr = daddr.s_addr & maddr.s_addr, 87781728a53SAlexander V. Chernikov }; 87881728a53SAlexander V. Chernikov 879130aebbaSAlexander V. Chernikov struct ifnet *ifp = ia->ia_ifp; 880130aebbaSAlexander V. Chernikov 881130aebbaSAlexander V. Chernikov if ((maddr.s_addr == INADDR_BROADCAST) && 882130aebbaSAlexander V. Chernikov (!(ia->ia_ifp->if_flags & (IFF_POINTOPOINT|IFF_LOOPBACK)))) { 883130aebbaSAlexander V. Chernikov /* Case 2: host route on broadcast interface */ 884130aebbaSAlexander V. Chernikov ifp = V_loif; 885130aebbaSAlexander V. Chernikov } 886130aebbaSAlexander V. Chernikov 88781728a53SAlexander V. Chernikov uint32_t fibnum = ifa->ifa_ifp->if_fib; 88881728a53SAlexander V. Chernikov NET_EPOCH_ENTER(et); 889130aebbaSAlexander V. Chernikov error = in_handle_prefix_route(fibnum, cmd, &dst, pmask, ifa, ifp); 89081728a53SAlexander V. Chernikov NET_EPOCH_EXIT(et); 89181728a53SAlexander V. Chernikov 89281728a53SAlexander V. Chernikov return (error); 89381728a53SAlexander V. Chernikov } 89481728a53SAlexander V. Chernikov 895ccbb9c35SQing Li /* 896d68cf57bSAlexander V. Chernikov * Check if we have a route for the given prefix already. 89748321abeSMax Laier */ 898d68cf57bSAlexander V. Chernikov static bool 899130aebbaSAlexander V. Chernikov in_hasrtprefix(struct in_ifaddr *target) 90048321abeSMax Laier { 901cc0a3c8cSAndrey V. Elsukov struct rm_priotracker in_ifa_tracker; 90248321abeSMax Laier struct in_ifaddr *ia; 903bfb26eecSGleb Smirnoff struct in_addr prefix, mask, p, m; 904d68cf57bSAlexander V. Chernikov bool result = false; 90548321abeSMax Laier 906130aebbaSAlexander V. Chernikov ia_getrtprefix(target, &prefix, &mask); 90748321abeSMax Laier 908cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RLOCK(&in_ifa_tracker); 9090cfee0c2SAlan Somers /* Look for an existing address with the same prefix, mask, and fib */ 910d7c5a620SMatt Macy CK_STAILQ_FOREACH(ia, &V_in_ifaddrhead, ia_link) { 911130aebbaSAlexander V. Chernikov ia_getrtprefix(ia, &p, &m); 912bfb26eecSGleb Smirnoff 913bfb26eecSGleb Smirnoff if (prefix.s_addr != p.s_addr || 914bfb26eecSGleb Smirnoff mask.s_addr != m.s_addr) 915bfb26eecSGleb Smirnoff continue; 916130aebbaSAlexander V. Chernikov 9170cfee0c2SAlan Somers if (target->ia_ifp->if_fib != ia->ia_ifp->if_fib) 9180cfee0c2SAlan Somers continue; 91948321abeSMax Laier 92048321abeSMax Laier /* 92148321abeSMax Laier * If we got a matching prefix route inserted by other 92248321abeSMax Laier * interface address, we are done here. 92348321abeSMax Laier */ 9241ae95409SGleb Smirnoff if (ia->ia_flags & IFA_ROUTE) { 925d68cf57bSAlexander V. Chernikov result = true; 926d68cf57bSAlexander V. Chernikov break; 927d68cf57bSAlexander V. Chernikov } 928d68cf57bSAlexander V. Chernikov } 929cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 9300cfee0c2SAlan Somers 931d68cf57bSAlexander V. Chernikov return (result); 932d68cf57bSAlexander V. Chernikov } 933d68cf57bSAlexander V. Chernikov 934d68cf57bSAlexander V. Chernikov int 935130aebbaSAlexander V. Chernikov in_addprefix(struct in_ifaddr *target) 936d68cf57bSAlexander V. Chernikov { 937d68cf57bSAlexander V. Chernikov int error; 938d68cf57bSAlexander V. Chernikov 939130aebbaSAlexander V. Chernikov if (in_hasrtprefix(target)) { 940d68cf57bSAlexander V. Chernikov if (V_nosameprefix) 941d68cf57bSAlexander V. Chernikov return (EEXIST); 942d68cf57bSAlexander V. Chernikov else { 943d68cf57bSAlexander V. Chernikov rt_addrmsg(RTM_ADD, &target->ia_ifa, 944d68cf57bSAlexander V. Chernikov target->ia_ifp->if_fib); 9451ae95409SGleb Smirnoff return (0); 9461ae95409SGleb Smirnoff } 94748321abeSMax Laier } 94848321abeSMax Laier 94948321abeSMax Laier /* 95048321abeSMax Laier * No-one seem to have this prefix route, so we try to insert it. 95148321abeSMax Laier */ 95281728a53SAlexander V. Chernikov rt_addrmsg(RTM_ADD, &target->ia_ifa, target->ia_ifp->if_fib); 95381728a53SAlexander V. Chernikov error = in_handle_ifaddr_route(RTM_ADD, target); 95448321abeSMax Laier if (!error) 95548321abeSMax Laier target->ia_flags |= IFA_ROUTE; 956460473a0SBjoern A. Zeeb return (error); 95748321abeSMax Laier } 95848321abeSMax Laier 95948321abeSMax Laier /* 9603e7a2321SAlexander V. Chernikov * Removes either all lle entries for given @ia, or lle 9613e7a2321SAlexander V. Chernikov * corresponding to @ia address. 9623e7a2321SAlexander V. Chernikov */ 9633e7a2321SAlexander V. Chernikov static void 9643e7a2321SAlexander V. Chernikov in_scrubprefixlle(struct in_ifaddr *ia, int all, u_int flags) 9653e7a2321SAlexander V. Chernikov { 9663e7a2321SAlexander V. Chernikov struct sockaddr_in addr, mask; 9673e7a2321SAlexander V. Chernikov struct sockaddr *saddr, *smask; 9683e7a2321SAlexander V. Chernikov struct ifnet *ifp; 9693e7a2321SAlexander V. Chernikov 9703e7a2321SAlexander V. Chernikov saddr = (struct sockaddr *)&addr; 9713e7a2321SAlexander V. Chernikov bzero(&addr, sizeof(addr)); 9723e7a2321SAlexander V. Chernikov addr.sin_len = sizeof(addr); 9733e7a2321SAlexander V. Chernikov addr.sin_family = AF_INET; 9743e7a2321SAlexander V. Chernikov smask = (struct sockaddr *)&mask; 9753e7a2321SAlexander V. Chernikov bzero(&mask, sizeof(mask)); 9763e7a2321SAlexander V. Chernikov mask.sin_len = sizeof(mask); 9773e7a2321SAlexander V. Chernikov mask.sin_family = AF_INET; 9783e7a2321SAlexander V. Chernikov mask.sin_addr.s_addr = ia->ia_subnetmask; 9793e7a2321SAlexander V. Chernikov ifp = ia->ia_ifp; 9803e7a2321SAlexander V. Chernikov 98126a60575SAlexander V. Chernikov if (all) { 98226a60575SAlexander V. Chernikov /* 98326a60575SAlexander V. Chernikov * Remove all L2 entries matching given prefix. 98426a60575SAlexander V. Chernikov * Convert address to host representation to avoid 98526a60575SAlexander V. Chernikov * doing this on every callback. ia_subnetmask is already 98626a60575SAlexander V. Chernikov * stored in host representation. 98726a60575SAlexander V. Chernikov */ 98826a60575SAlexander V. Chernikov addr.sin_addr.s_addr = ntohl(ia->ia_addr.sin_addr.s_addr); 9893e7a2321SAlexander V. Chernikov lltable_prefix_free(AF_INET, saddr, smask, flags); 99026a60575SAlexander V. Chernikov } else { 99126a60575SAlexander V. Chernikov /* Remove interface address only */ 99226a60575SAlexander V. Chernikov addr.sin_addr.s_addr = ia->ia_addr.sin_addr.s_addr; 9933e7a2321SAlexander V. Chernikov lltable_delete_addr(LLTABLE(ifp), LLE_IFADDR, saddr); 9943e7a2321SAlexander V. Chernikov } 99526a60575SAlexander V. Chernikov } 9963e7a2321SAlexander V. Chernikov 9973e7a2321SAlexander V. Chernikov /* 99848321abeSMax Laier * If there is no other address in the system that can serve a route to the 99948321abeSMax Laier * same prefix, remove the route. Hand over the route to the new address 100048321abeSMax Laier * otherwise. 100148321abeSMax Laier */ 100208b68b0eSGleb Smirnoff int 10035b84dc78SQing Li in_scrubprefix(struct in_ifaddr *target, u_int flags) 100448321abeSMax Laier { 1005cc0a3c8cSAndrey V. Elsukov struct rm_priotracker in_ifa_tracker; 100648321abeSMax Laier struct in_ifaddr *ia; 100755174c34SGleb Smirnoff struct in_addr prefix, mask, p, m; 10087278b62aSAlan Somers int error = 0; 100948321abeSMax Laier 1010df813b7eSQing Li /* 1011df813b7eSQing Li * Remove the loopback route to the interface address. 1012df813b7eSQing Li */ 1013130aebbaSAlexander V. Chernikov if (ia_need_loopback_route(target) && (flags & LLE_STATIC)) { 1014f7a39160SGleb Smirnoff struct in_ifaddr *eia; 1015c7ab6602SQing Li 1016f7a39160SGleb Smirnoff eia = in_localip_more(target); 1017f7a39160SGleb Smirnoff 1018f7a39160SGleb Smirnoff if (eia != NULL) { 1019f7a39160SGleb Smirnoff error = ifa_switch_loopback_route((struct ifaddr *)eia, 102059c180c3SAlexander V. Chernikov (struct sockaddr *)&target->ia_addr); 1021f7a39160SGleb Smirnoff ifa_free(&eia->ia_ifa); 1022f7a39160SGleb Smirnoff } else { 10239bb7d0f4SQing Li error = ifa_del_loopback_route((struct ifaddr *)target, 10249bb7d0f4SQing Li (struct sockaddr *)&target->ia_addr); 10255b84dc78SQing Li } 1026ebc90701SQing Li } 1027ebc90701SQing Li 1028130aebbaSAlexander V. Chernikov ia_getrtprefix(target, &prefix, &mask); 102948321abeSMax Laier 1030ccbb9c35SQing Li if ((target->ia_flags & IFA_ROUTE) == 0) { 1031d68cf57bSAlexander V. Chernikov rt_addrmsg(RTM_DELETE, &target->ia_ifa, target->ia_ifp->if_fib); 103226a60575SAlexander V. Chernikov 103326a60575SAlexander V. Chernikov /* 103426a60575SAlexander V. Chernikov * Removing address from !IFF_UP interface or 103526a60575SAlexander V. Chernikov * prefix which exists on other interface (along with route). 103626a60575SAlexander V. Chernikov * No entries should exist here except target addr. 103726a60575SAlexander V. Chernikov * Given that, delete this entry only. 103826a60575SAlexander V. Chernikov */ 103926a60575SAlexander V. Chernikov in_scrubprefixlle(target, 0, flags); 1040ccbb9c35SQing Li return (0); 1041ccbb9c35SQing Li } 1042ccbb9c35SQing Li 1043cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RLOCK(&in_ifa_tracker); 1044d7c5a620SMatt Macy CK_STAILQ_FOREACH(ia, &V_in_ifaddrhead, ia_link) { 1045130aebbaSAlexander V. Chernikov ia_getrtprefix(ia, &p, &m); 104655174c34SGleb Smirnoff 104755174c34SGleb Smirnoff if (prefix.s_addr != p.s_addr || 104855174c34SGleb Smirnoff mask.s_addr != m.s_addr) 104955174c34SGleb Smirnoff continue; 105048321abeSMax Laier 105155174c34SGleb Smirnoff if ((ia->ia_ifp->if_flags & IFF_UP) == 0) 105248321abeSMax Laier continue; 105348321abeSMax Laier 105448321abeSMax Laier /* 105548321abeSMax Laier * If we got a matching prefix address, move IFA_ROUTE and 105648321abeSMax Laier * the route itself to it. Make sure that routing daemons 105748321abeSMax Laier * get a heads-up. 105848321abeSMax Laier */ 105908b68b0eSGleb Smirnoff if ((ia->ia_flags & IFA_ROUTE) == 0) { 106079d51435SSergey Kandaurov ifa_ref(&ia->ia_ifa); 1061cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 106281728a53SAlexander V. Chernikov error = in_handle_ifaddr_route(RTM_DELETE, target); 106392322284SQing Li if (error == 0) 106448321abeSMax Laier target->ia_flags &= ~IFA_ROUTE; 106592322284SQing Li else 106692322284SQing Li log(LOG_INFO, "in_scrubprefix: err=%d, old prefix delete failed\n", 106792322284SQing Li error); 10683e7a2321SAlexander V. Chernikov /* Scrub all entries IFF interface is different */ 10693e7a2321SAlexander V. Chernikov in_scrubprefixlle(target, target->ia_ifp != ia->ia_ifp, 10703e7a2321SAlexander V. Chernikov flags); 107181728a53SAlexander V. Chernikov error = in_handle_ifaddr_route(RTM_ADD, ia); 107248321abeSMax Laier if (error == 0) 107348321abeSMax Laier ia->ia_flags |= IFA_ROUTE; 107492322284SQing Li else 107592322284SQing Li log(LOG_INFO, "in_scrubprefix: err=%d, new prefix add failed\n", 107692322284SQing Li error); 107779d51435SSergey Kandaurov ifa_free(&ia->ia_ifa); 1078460473a0SBjoern A. Zeeb return (error); 107948321abeSMax Laier } 108048321abeSMax Laier } 1081cc0a3c8cSAndrey V. Elsukov IN_IFADDR_RUNLOCK(&in_ifa_tracker); 108248321abeSMax Laier 108348321abeSMax Laier /* 1084c9d763bfSQing Li * remove all L2 entries on the given prefix 1085c9d763bfSQing Li */ 10863e7a2321SAlexander V. Chernikov in_scrubprefixlle(target, 1, flags); 1087c9d763bfSQing Li 1088c9d763bfSQing Li /* 108948321abeSMax Laier * As no-one seem to have this prefix, we can remove the route. 109048321abeSMax Laier */ 109181728a53SAlexander V. Chernikov rt_addrmsg(RTM_DELETE, &target->ia_ifa, target->ia_ifp->if_fib); 109281728a53SAlexander V. Chernikov error = in_handle_ifaddr_route(RTM_DELETE, target); 109392322284SQing Li if (error == 0) 109448321abeSMax Laier target->ia_flags &= ~IFA_ROUTE; 109592322284SQing Li else 109692322284SQing Li log(LOG_INFO, "in_scrubprefix: err=%d, prefix delete failed\n", error); 109792322284SQing Li return (error); 109848321abeSMax Laier } 109948321abeSMax Laier 110089856f7eSBjoern A. Zeeb void 110189856f7eSBjoern A. Zeeb in_ifscrub_all(void) 110289856f7eSBjoern A. Zeeb { 110389856f7eSBjoern A. Zeeb struct ifnet *ifp; 110489856f7eSBjoern A. Zeeb struct ifaddr *ifa, *nifa; 110589856f7eSBjoern A. Zeeb struct ifaliasreq ifr; 110689856f7eSBjoern A. Zeeb 110789856f7eSBjoern A. Zeeb IFNET_RLOCK(); 11084f6c66ccSMatt Macy CK_STAILQ_FOREACH(ifp, &V_ifnet, if_link) { 110989856f7eSBjoern A. Zeeb /* Cannot lock here - lock recursion. */ 1110a68cc388SGleb Smirnoff /* NET_EPOCH_ENTER(et); */ 1111d7c5a620SMatt Macy CK_STAILQ_FOREACH_SAFE(ifa, &ifp->if_addrhead, ifa_link, nifa) { 111289856f7eSBjoern A. Zeeb if (ifa->ifa_addr->sa_family != AF_INET) 111389856f7eSBjoern A. Zeeb continue; 111489856f7eSBjoern A. Zeeb 111589856f7eSBjoern A. Zeeb /* 111689856f7eSBjoern A. Zeeb * This is ugly but the only way for legacy IP to 111789856f7eSBjoern A. Zeeb * cleanly remove addresses and everything attached. 111889856f7eSBjoern A. Zeeb */ 111989856f7eSBjoern A. Zeeb bzero(&ifr, sizeof(ifr)); 112089856f7eSBjoern A. Zeeb ifr.ifra_addr = *ifa->ifa_addr; 112189856f7eSBjoern A. Zeeb if (ifa->ifa_dstaddr) 112289856f7eSBjoern A. Zeeb ifr.ifra_broadaddr = *ifa->ifa_dstaddr; 112389856f7eSBjoern A. Zeeb (void)in_control(NULL, SIOCDIFADDR, (caddr_t)&ifr, 112489856f7eSBjoern A. Zeeb ifp, NULL); 112589856f7eSBjoern A. Zeeb } 1126a68cc388SGleb Smirnoff /* NET_EPOCH_EXIT(et); */ 112789856f7eSBjoern A. Zeeb in_purgemaddrs(ifp); 112889856f7eSBjoern A. Zeeb igmp_domifdetach(ifp); 112989856f7eSBjoern A. Zeeb } 113089856f7eSBjoern A. Zeeb IFNET_RUNLOCK(); 113189856f7eSBjoern A. Zeeb } 113289856f7eSBjoern A. Zeeb 113390cc51a1SRyan Stone int 113490cc51a1SRyan Stone in_ifaddr_broadcast(struct in_addr in, struct in_ifaddr *ia) 113590cc51a1SRyan Stone { 113690cc51a1SRyan Stone 113790cc51a1SRyan Stone return ((in.s_addr == ia->ia_broadaddr.sin_addr.s_addr || 113890cc51a1SRyan Stone /* 113990cc51a1SRyan Stone * Check for old-style (host 0) broadcast, but 114090cc51a1SRyan Stone * taking into account that RFC 3021 obsoletes it. 114190cc51a1SRyan Stone */ 114290cc51a1SRyan Stone (ia->ia_subnetmask != IN_RFC3021_MASK && 114390cc51a1SRyan Stone ntohl(in.s_addr) == ia->ia_subnet)) && 114490cc51a1SRyan Stone /* 114590cc51a1SRyan Stone * Check for an all one subnetmask. These 114690cc51a1SRyan Stone * only exist when an interface gets a secondary 114790cc51a1SRyan Stone * address. 114890cc51a1SRyan Stone */ 114990cc51a1SRyan Stone ia->ia_subnetmask != (u_long)0xffffffff); 115090cc51a1SRyan Stone } 115190cc51a1SRyan Stone 1152df8bae1dSRodney W. Grimes /* 1153df8bae1dSRodney W. Grimes * Return 1 if the address might be a local broadcast address. 1154df8bae1dSRodney W. Grimes */ 115526f9a767SRodney W. Grimes int 1156f2565d68SRobert Watson in_broadcast(struct in_addr in, struct ifnet *ifp) 1157df8bae1dSRodney W. Grimes { 11583e85b721SEd Maste struct ifaddr *ifa; 115911f2a7cdSRyan Stone int found; 1160df8bae1dSRodney W. Grimes 1161b8a6e03fSGleb Smirnoff NET_EPOCH_ASSERT(); 1162b8a6e03fSGleb Smirnoff 1163df8bae1dSRodney W. Grimes if (in.s_addr == INADDR_BROADCAST || 1164df8bae1dSRodney W. Grimes in.s_addr == INADDR_ANY) 1165460473a0SBjoern A. Zeeb return (1); 1166df8bae1dSRodney W. Grimes if ((ifp->if_flags & IFF_BROADCAST) == 0) 1167460473a0SBjoern A. Zeeb return (0); 116811f2a7cdSRyan Stone found = 0; 1169df8bae1dSRodney W. Grimes /* 1170df8bae1dSRodney W. Grimes * Look through the list of addresses for a match 1171df8bae1dSRodney W. Grimes * with a broadcast address. 1172df8bae1dSRodney W. Grimes */ 1173d7c5a620SMatt Macy CK_STAILQ_FOREACH(ifa, &ifp->if_addrhead, ifa_link) 1174df8bae1dSRodney W. Grimes if (ifa->ifa_addr->sa_family == AF_INET && 117511f2a7cdSRyan Stone in_ifaddr_broadcast(in, (struct in_ifaddr *)ifa)) { 117611f2a7cdSRyan Stone found = 1; 117711f2a7cdSRyan Stone break; 117811f2a7cdSRyan Stone } 117911f2a7cdSRyan Stone return (found); 1180df8bae1dSRodney W. Grimes } 1181ec002feeSBruce M Simpson 1182df8bae1dSRodney W. Grimes /* 1183b1c53bc9SRobert Watson * On interface removal, clean up IPv4 data structures hung off of the ifnet. 1184b1c53bc9SRobert Watson */ 1185b1c53bc9SRobert Watson void 1186f2565d68SRobert Watson in_ifdetach(struct ifnet *ifp) 1187b1c53bc9SRobert Watson { 1188f3e1324bSStephen Hurd IN_MULTI_LOCK(); 1189603724d3SBjoern A. Zeeb in_pcbpurgeif0(&V_ripcbinfo, ifp); 1190603724d3SBjoern A. Zeeb in_pcbpurgeif0(&V_udbinfo, ifp); 1191e06e816fSKevin Lo in_pcbpurgeif0(&V_ulitecbinfo, ifp); 1192ec002feeSBruce M Simpson in_purgemaddrs(ifp); 1193f3e1324bSStephen Hurd IN_MULTI_UNLOCK(); 11943689652cSHans Petter Selasky 11953689652cSHans Petter Selasky /* 11963689652cSHans Petter Selasky * Make sure all multicast deletions invoking if_ioctl() are 11973689652cSHans Petter Selasky * completed before returning. Else we risk accessing a freed 11983689652cSHans Petter Selasky * ifnet structure pointer. 11993689652cSHans Petter Selasky */ 12003689652cSHans Petter Selasky inm_release_wait(NULL); 1201b1c53bc9SRobert Watson } 12026e6b3f7cSQing Li 1203d10910e6SBruce M Simpson /* 1204d10910e6SBruce M Simpson * Delete all IPv4 multicast address records, and associated link-layer 1205d10910e6SBruce M Simpson * multicast address records, associated with ifp. 1206d10910e6SBruce M Simpson * XXX It looks like domifdetach runs AFTER the link layer cleanup. 120756663a40SBruce M Simpson * XXX This should not race with ifma_protospec being set during 120856663a40SBruce M Simpson * a new allocation, if it does, we have bigger problems. 1209d10910e6SBruce M Simpson */ 1210d10910e6SBruce M Simpson static void 1211d10910e6SBruce M Simpson in_purgemaddrs(struct ifnet *ifp) 1212d10910e6SBruce M Simpson { 1213f3e1324bSStephen Hurd struct in_multi_head purgeinms; 1214f3e1324bSStephen Hurd struct in_multi *inm; 1215b6f6f880SMatt Macy struct ifmultiaddr *ifma, *next; 1216d10910e6SBruce M Simpson 1217f3e1324bSStephen Hurd SLIST_INIT(&purgeinms); 1218f3e1324bSStephen Hurd IN_MULTI_LIST_LOCK(); 1219d10910e6SBruce M Simpson 1220d10910e6SBruce M Simpson /* 1221d10910e6SBruce M Simpson * Extract list of in_multi associated with the detaching ifp 1222d10910e6SBruce M Simpson * which the PF_INET layer is about to release. 1223d10910e6SBruce M Simpson * We need to do this as IF_ADDR_LOCK() may be re-acquired 1224d10910e6SBruce M Simpson * by code further down. 1225d10910e6SBruce M Simpson */ 1226b6f6f880SMatt Macy IF_ADDR_WLOCK(ifp); 1227b6f6f880SMatt Macy restart: 1228d7c5a620SMatt Macy CK_STAILQ_FOREACH_SAFE(ifma, &ifp->if_multiaddrs, ifma_link, next) { 122956663a40SBruce M Simpson if (ifma->ifma_addr->sa_family != AF_INET || 123056663a40SBruce M Simpson ifma->ifma_protospec == NULL) 1231d10910e6SBruce M Simpson continue; 1232d10910e6SBruce M Simpson inm = (struct in_multi *)ifma->ifma_protospec; 1233f3e1324bSStephen Hurd inm_rele_locked(&purgeinms, inm); 1234b6f6f880SMatt Macy if (__predict_false(ifma_restart)) { 1235b6f6f880SMatt Macy ifma_restart = true; 1236b6f6f880SMatt Macy goto restart; 1237d10910e6SBruce M Simpson } 1238b6f6f880SMatt Macy } 1239b6f6f880SMatt Macy IF_ADDR_WUNLOCK(ifp); 1240d10910e6SBruce M Simpson 1241f3e1324bSStephen Hurd inm_release_list_deferred(&purgeinms); 1242d10910e6SBruce M Simpson igmp_ifdetach(ifp); 1243f3e1324bSStephen Hurd IN_MULTI_LIST_UNLOCK(); 1244d10910e6SBruce M Simpson } 1245d10910e6SBruce M Simpson 12466e6b3f7cSQing Li struct in_llentry { 12476e6b3f7cSQing Li struct llentry base; 12486e6b3f7cSQing Li }; 12496e6b3f7cSQing Li 125011cdad98SAlexander V. Chernikov #define IN_LLTBL_DEFAULT_HSIZE 32 125111cdad98SAlexander V. Chernikov #define IN_LLTBL_HASH(k, h) \ 125211cdad98SAlexander V. Chernikov (((((((k >> 8) ^ k) >> 8) ^ k) >> 8) ^ k) & ((h) - 1)) 125311cdad98SAlexander V. Chernikov 1254a93cda78SKip Macy /* 125511cdad98SAlexander V. Chernikov * Do actual deallocation of @lle. 12562769d062SConrad Meyer */ 12572769d062SConrad Meyer static void 12584f6c66ccSMatt Macy in_lltable_destroy_lle_unlocked(epoch_context_t ctx) 12592769d062SConrad Meyer { 12604f6c66ccSMatt Macy struct llentry *lle; 12612769d062SConrad Meyer 12624f6c66ccSMatt Macy lle = __containerof(ctx, struct llentry, lle_epoch_ctx); 12632769d062SConrad Meyer LLE_LOCK_DESTROY(lle); 12642769d062SConrad Meyer LLE_REQ_DESTROY(lle); 12652769d062SConrad Meyer free(lle, M_LLTABLE); 12662769d062SConrad Meyer } 12672769d062SConrad Meyer 12682769d062SConrad Meyer /* 126911cdad98SAlexander V. Chernikov * Called by LLE_FREE_LOCKED when number of references 127011cdad98SAlexander V. Chernikov * drops to zero. 1271a93cda78SKip Macy */ 1272a93cda78SKip Macy static void 127311cdad98SAlexander V. Chernikov in_lltable_destroy_lle(struct llentry *lle) 1274a93cda78SKip Macy { 127511cdad98SAlexander V. Chernikov 1276a93cda78SKip Macy LLE_WUNLOCK(lle); 12772a4bd982SGleb Smirnoff NET_EPOCH_CALL(in_lltable_destroy_lle_unlocked, &lle->lle_epoch_ctx); 1278a93cda78SKip Macy } 1279a93cda78SKip Macy 12806e6b3f7cSQing Li static struct llentry * 1281314294deSAlexander V. Chernikov in_lltable_new(struct in_addr addr4, u_int flags) 12826e6b3f7cSQing Li { 12836e6b3f7cSQing Li struct in_llentry *lle; 12846e6b3f7cSQing Li 128590b357f6SGleb Smirnoff lle = malloc(sizeof(struct in_llentry), M_LLTABLE, M_NOWAIT | M_ZERO); 12866e6b3f7cSQing Li if (lle == NULL) /* NB: caller generates msg */ 12876e6b3f7cSQing Li return NULL; 12886e6b3f7cSQing Li 12896e6b3f7cSQing Li /* 12906e6b3f7cSQing Li * For IPv4 this will trigger "arpresolve" to generate 12916e6b3f7cSQing Li * an ARP request. 12926e6b3f7cSQing Li */ 1293a98c06f1SGleb Smirnoff lle->base.la_expire = time_uptime; /* mark expired */ 1294314294deSAlexander V. Chernikov lle->base.r_l3addr.addr4 = addr4; 12956e6b3f7cSQing Li lle->base.lle_refcnt = 1; 129611cdad98SAlexander V. Chernikov lle->base.lle_free = in_lltable_destroy_lle; 12976e6b3f7cSQing Li LLE_LOCK_INIT(&lle->base); 1298f8aee88fSAlexander V. Chernikov LLE_REQ_INIT(&lle->base); 12990447c136SAlexander V. Chernikov callout_init(&lle->base.lle_timer, 1); 1300ea537929SGleb Smirnoff 1301ea537929SGleb Smirnoff return (&lle->base); 13026e6b3f7cSQing Li } 13036e6b3f7cSQing Li 1304c9d763bfSQing Li #define IN_ARE_MASKED_ADDR_EQUAL(d, a, m) ( \ 13053e7a2321SAlexander V. Chernikov ((((d).s_addr ^ (a).s_addr) & (m).s_addr)) == 0 ) 1306c9d763bfSQing Li 130711cdad98SAlexander V. Chernikov static int 13083e7a2321SAlexander V. Chernikov in_lltable_match_prefix(const struct sockaddr *saddr, 13093e7a2321SAlexander V. Chernikov const struct sockaddr *smask, u_int flags, struct llentry *lle) 1310c9d763bfSQing Li { 13113e7a2321SAlexander V. Chernikov struct in_addr addr, mask, lle_addr; 13123e7a2321SAlexander V. Chernikov 13133e7a2321SAlexander V. Chernikov addr = ((const struct sockaddr_in *)saddr)->sin_addr; 13143e7a2321SAlexander V. Chernikov mask = ((const struct sockaddr_in *)smask)->sin_addr; 13153e7a2321SAlexander V. Chernikov lle_addr.s_addr = ntohl(lle->r_l3addr.addr4.s_addr); 13163e7a2321SAlexander V. Chernikov 13173e7a2321SAlexander V. Chernikov if (IN_ARE_MASKED_ADDR_EQUAL(lle_addr, addr, mask) == 0) 13183e7a2321SAlexander V. Chernikov return (0); 13193e7a2321SAlexander V. Chernikov 13203e7a2321SAlexander V. Chernikov if (lle->la_flags & LLE_IFADDR) { 13215b84dc78SQing Li /* 13223e7a2321SAlexander V. Chernikov * Delete LLE_IFADDR records IFF address & flag matches. 13233e7a2321SAlexander V. Chernikov * Note that addr is the interface address within prefix 13243e7a2321SAlexander V. Chernikov * being matched. 13253e7a2321SAlexander V. Chernikov * Note also we should handle 'ifdown' cases without removing 13263e7a2321SAlexander V. Chernikov * ifaddr macs. 13275b84dc78SQing Li */ 13283e7a2321SAlexander V. Chernikov if (addr.s_addr == lle_addr.s_addr && (flags & LLE_STATIC) != 0) 13293e7a2321SAlexander V. Chernikov return (1); 13303e7a2321SAlexander V. Chernikov return (0); 13313e7a2321SAlexander V. Chernikov } 13323e7a2321SAlexander V. Chernikov 13333e7a2321SAlexander V. Chernikov /* flags & LLE_STATIC means deleting both dynamic and static entries */ 13343e7a2321SAlexander V. Chernikov if ((flags & LLE_STATIC) || !(lle->la_flags & LLE_STATIC)) 133511cdad98SAlexander V. Chernikov return (1); 133611cdad98SAlexander V. Chernikov 133711cdad98SAlexander V. Chernikov return (0); 133811cdad98SAlexander V. Chernikov } 133911cdad98SAlexander V. Chernikov 134011cdad98SAlexander V. Chernikov static void 134111cdad98SAlexander V. Chernikov in_lltable_free_entry(struct lltable *llt, struct llentry *lle) 134211cdad98SAlexander V. Chernikov { 134311cdad98SAlexander V. Chernikov size_t pkts_dropped; 134411cdad98SAlexander V. Chernikov 134511cdad98SAlexander V. Chernikov LLE_WLOCK_ASSERT(lle); 134611cdad98SAlexander V. Chernikov KASSERT(llt != NULL, ("lltable is NULL")); 134711cdad98SAlexander V. Chernikov 134811cdad98SAlexander V. Chernikov /* Unlink entry from table if not already */ 134911cdad98SAlexander V. Chernikov if ((lle->la_flags & LLE_LINKED) != 0) { 1350f6960e20SMatt Macy IF_AFDATA_WLOCK_ASSERT(llt->llt_ifp); 135111cdad98SAlexander V. Chernikov lltable_unlink_entry(llt, lle); 135211cdad98SAlexander V. Chernikov } 135311cdad98SAlexander V. Chernikov 135411cdad98SAlexander V. Chernikov /* Drop hold queue */ 1355e162ea60SGeorge V. Neville-Neil pkts_dropped = llentry_free(lle); 1356e162ea60SGeorge V. Neville-Neil ARPSTAT_ADD(dropped, pkts_dropped); 1357c9d763bfSQing Li } 1358c9d763bfSQing Li 13596e6b3f7cSQing Li static int 1360c7ab6602SQing Li in_lltable_rtcheck(struct ifnet *ifp, u_int flags, const struct sockaddr *l3addr) 13616e6b3f7cSQing Li { 1362*936f4a42SAlexander V. Chernikov struct nhop_object *nh; 1363*936f4a42SAlexander V. Chernikov struct in_addr addr; 13646e6b3f7cSQing Li 13656e6b3f7cSQing Li KASSERT(l3addr->sa_family == AF_INET, 13666e6b3f7cSQing Li ("sin_family %d", l3addr->sa_family)); 13676e6b3f7cSQing Li 1368*936f4a42SAlexander V. Chernikov addr = ((const struct sockaddr_in *)l3addr)->sin_addr; 136913e255faSMarko Zec 1370*936f4a42SAlexander V. Chernikov nh = fib4_lookup(ifp->if_fib, addr, 0, NHR_NONE, 0); 1371*936f4a42SAlexander V. Chernikov if (nh == NULL) 13726cf8e330SQing Li return (EINVAL); 13736cf8e330SQing Li 137413e255faSMarko Zec /* 137513e255faSMarko Zec * If the gateway for an existing host route matches the target L3 13766cf8e330SQing Li * address, which is a special route inserted by some implementation 13776cf8e330SQing Li * such as MANET, and the interface is of the correct type, then 13786cf8e330SQing Li * allow for ARP to proceed. 137913e255faSMarko Zec */ 1380*936f4a42SAlexander V. Chernikov if (nh->nh_flags & NHF_GATEWAY) { 1381*936f4a42SAlexander V. Chernikov if (!(nh->nh_flags & NHF_HOST) || nh->nh_ifp->if_type != IFT_ETHER || 1382*936f4a42SAlexander V. Chernikov (nh->nh_ifp->if_flags & (IFF_NOARP | IFF_STATICARP)) != 0 || 1383*936f4a42SAlexander V. Chernikov memcmp(nh->gw_sa.sa_data, l3addr->sa_data, 138415d25219SQing Li sizeof(in_addr_t)) != 0) { 1385db92413eSQing Li return (EINVAL); 1386db92413eSQing Li } 138715d25219SQing Li } 1388db92413eSQing Li 1389db92413eSQing Li /* 1390db92413eSQing Li * Make sure that at least the destination address is covered 1391db92413eSQing Li * by the route. This is for handling the case where 2 or more 1392db92413eSQing Li * interfaces have the same prefix. An incoming packet arrives 1393db92413eSQing Li * on one interface and the corresponding outgoing packet leaves 1394db92413eSQing Li * another interface. 1395db92413eSQing Li */ 1396*936f4a42SAlexander V. Chernikov if ((nh->nh_ifp != ifp) && (nh->nh_flags & NHF_HOST) == 0) { 1397*936f4a42SAlexander V. Chernikov struct in_ifaddr *ia = (struct in_ifaddr *)ifaof_ifpforaddr(l3addr, ifp); 1398*936f4a42SAlexander V. Chernikov struct in_addr dst_addr, mask_addr; 1399db92413eSQing Li 1400*936f4a42SAlexander V. Chernikov if (ia == NULL) 1401*936f4a42SAlexander V. Chernikov return (EINVAL); 1402*936f4a42SAlexander V. Chernikov 1403b3664a14SQing Li /* 1404*936f4a42SAlexander V. Chernikov * ifaof_ifpforaddr() returns _best matching_ IFA. 1405*936f4a42SAlexander V. Chernikov * It is possible that ifa prefix does not cover our address. 1406*936f4a42SAlexander V. Chernikov * Explicitly verify and fail if that's the case. 1407b3664a14SQing Li */ 1408*936f4a42SAlexander V. Chernikov dst_addr = IA_SIN(ia)->sin_addr; 1409*936f4a42SAlexander V. Chernikov mask_addr.s_addr = htonl(ia->ia_subnetmask); 1410*936f4a42SAlexander V. Chernikov 1411*936f4a42SAlexander V. Chernikov if (!IN_ARE_MASKED_ADDR_EQUAL(dst_addr, addr, mask_addr)) 1412b3664a14SQing Li return (EINVAL); 1413db92413eSQing Li } 1414db92413eSQing Li 141515d25219SQing Li return (0); 14166e6b3f7cSQing Li } 14176e6b3f7cSQing Li 141811cdad98SAlexander V. Chernikov static inline uint32_t 141911cdad98SAlexander V. Chernikov in_lltable_hash_dst(const struct in_addr dst, uint32_t hsize) 142011cdad98SAlexander V. Chernikov { 142111cdad98SAlexander V. Chernikov 142211cdad98SAlexander V. Chernikov return (IN_LLTBL_HASH(dst.s_addr, hsize)); 142311cdad98SAlexander V. Chernikov } 142411cdad98SAlexander V. Chernikov 142511cdad98SAlexander V. Chernikov static uint32_t 142611cdad98SAlexander V. Chernikov in_lltable_hash(const struct llentry *lle, uint32_t hsize) 142711cdad98SAlexander V. Chernikov { 142811cdad98SAlexander V. Chernikov 1429314294deSAlexander V. Chernikov return (in_lltable_hash_dst(lle->r_l3addr.addr4, hsize)); 143011cdad98SAlexander V. Chernikov } 143111cdad98SAlexander V. Chernikov 143211cdad98SAlexander V. Chernikov static void 143311cdad98SAlexander V. Chernikov in_lltable_fill_sa_entry(const struct llentry *lle, struct sockaddr *sa) 143411cdad98SAlexander V. Chernikov { 143511cdad98SAlexander V. Chernikov struct sockaddr_in *sin; 143611cdad98SAlexander V. Chernikov 143711cdad98SAlexander V. Chernikov sin = (struct sockaddr_in *)sa; 143811cdad98SAlexander V. Chernikov bzero(sin, sizeof(*sin)); 143911cdad98SAlexander V. Chernikov sin->sin_family = AF_INET; 144011cdad98SAlexander V. Chernikov sin->sin_len = sizeof(*sin); 1441314294deSAlexander V. Chernikov sin->sin_addr = lle->r_l3addr.addr4; 144211cdad98SAlexander V. Chernikov } 144311cdad98SAlexander V. Chernikov 1444b4b1367aSAlexander V. Chernikov static inline struct llentry * 1445b4b1367aSAlexander V. Chernikov in_lltable_find_dst(struct lltable *llt, struct in_addr dst) 1446b4b1367aSAlexander V. Chernikov { 1447b4b1367aSAlexander V. Chernikov struct llentry *lle; 1448b4b1367aSAlexander V. Chernikov struct llentries *lleh; 144911cdad98SAlexander V. Chernikov u_int hashidx; 1450b4b1367aSAlexander V. Chernikov 14513a749863SAlexander V. Chernikov hashidx = in_lltable_hash_dst(dst, llt->llt_hsize); 145211cdad98SAlexander V. Chernikov lleh = &llt->lle_head[hashidx]; 14534f6c66ccSMatt Macy CK_LIST_FOREACH(lle, lleh, lle_next) { 1454b4b1367aSAlexander V. Chernikov if (lle->la_flags & LLE_DELETED) 1455b4b1367aSAlexander V. Chernikov continue; 1456314294deSAlexander V. Chernikov if (lle->r_l3addr.addr4.s_addr == dst.s_addr) 1457b4b1367aSAlexander V. Chernikov break; 1458b4b1367aSAlexander V. Chernikov } 1459b4b1367aSAlexander V. Chernikov 1460b4b1367aSAlexander V. Chernikov return (lle); 1461b4b1367aSAlexander V. Chernikov } 1462b4b1367aSAlexander V. Chernikov 14633e7a2321SAlexander V. Chernikov static void 14643e7a2321SAlexander V. Chernikov in_lltable_delete_entry(struct lltable *llt, struct llentry *lle) 1465b4b1367aSAlexander V. Chernikov { 1466b4b1367aSAlexander V. Chernikov 1467b4b1367aSAlexander V. Chernikov lle->la_flags |= LLE_DELETED; 1468b4b1367aSAlexander V. Chernikov EVENTHANDLER_INVOKE(lle_event, lle, LLENTRY_DELETED); 1469b4b1367aSAlexander V. Chernikov #ifdef DIAGNOSTIC 1470b4b1367aSAlexander V. Chernikov log(LOG_INFO, "ifaddr cache = %p is deleted\n", lle); 1471b4b1367aSAlexander V. Chernikov #endif 1472b4b1367aSAlexander V. Chernikov llentry_free(lle); 1473b4b1367aSAlexander V. Chernikov } 1474b4b1367aSAlexander V. Chernikov 1475b4b1367aSAlexander V. Chernikov static struct llentry * 14765a255516SAlexander V. Chernikov in_lltable_alloc(struct lltable *llt, u_int flags, const struct sockaddr *l3addr) 1477b4b1367aSAlexander V. Chernikov { 1478b4b1367aSAlexander V. Chernikov const struct sockaddr_in *sin = (const struct sockaddr_in *)l3addr; 1479b4b1367aSAlexander V. Chernikov struct ifnet *ifp = llt->llt_ifp; 1480b4b1367aSAlexander V. Chernikov struct llentry *lle; 14814fb3a820SAlexander V. Chernikov char linkhdr[LLE_MAX_LINKHDR]; 14824fb3a820SAlexander V. Chernikov size_t linkhdrsize; 14834fb3a820SAlexander V. Chernikov int lladdr_off; 1484b4b1367aSAlexander V. Chernikov 1485b4b1367aSAlexander V. Chernikov KASSERT(l3addr->sa_family == AF_INET, 1486b4b1367aSAlexander V. Chernikov ("sin_family %d", l3addr->sa_family)); 1487b4b1367aSAlexander V. Chernikov 1488b4b1367aSAlexander V. Chernikov /* 1489b4b1367aSAlexander V. Chernikov * A route that covers the given address must have 1490b4b1367aSAlexander V. Chernikov * been installed 1st because we are doing a resolution, 1491b4b1367aSAlexander V. Chernikov * verify this. 1492b4b1367aSAlexander V. Chernikov */ 1493b4b1367aSAlexander V. Chernikov if (!(flags & LLE_IFADDR) && 1494b4b1367aSAlexander V. Chernikov in_lltable_rtcheck(ifp, flags, l3addr) != 0) 1495b4b1367aSAlexander V. Chernikov return (NULL); 1496b4b1367aSAlexander V. Chernikov 1497314294deSAlexander V. Chernikov lle = in_lltable_new(sin->sin_addr, flags); 1498b4b1367aSAlexander V. Chernikov if (lle == NULL) { 1499b4b1367aSAlexander V. Chernikov log(LOG_INFO, "lla_lookup: new lle malloc failed\n"); 1500b4b1367aSAlexander V. Chernikov return (NULL); 1501b4b1367aSAlexander V. Chernikov } 1502b4b1367aSAlexander V. Chernikov lle->la_flags = flags; 1503f8aee88fSAlexander V. Chernikov if (flags & LLE_STATIC) 1504f8aee88fSAlexander V. Chernikov lle->r_flags |= RLLE_VALID; 1505b4b1367aSAlexander V. Chernikov if ((flags & LLE_IFADDR) == LLE_IFADDR) { 15064fb3a820SAlexander V. Chernikov linkhdrsize = LLE_MAX_LINKHDR; 15074fb3a820SAlexander V. Chernikov if (lltable_calc_llheader(ifp, AF_INET, IF_LLADDR(ifp), 15082769d062SConrad Meyer linkhdr, &linkhdrsize, &lladdr_off) != 0) { 15092a4bd982SGleb Smirnoff NET_EPOCH_CALL(in_lltable_destroy_lle_unlocked, &lle->lle_epoch_ctx); 15104fb3a820SAlexander V. Chernikov return (NULL); 15112769d062SConrad Meyer } 15124fb3a820SAlexander V. Chernikov lltable_set_entry_addr(ifp, lle, linkhdr, linkhdrsize, 15134fb3a820SAlexander V. Chernikov lladdr_off); 1514ddd208f7SAlexander V. Chernikov lle->la_flags |= LLE_STATIC; 1515f8aee88fSAlexander V. Chernikov lle->r_flags |= (RLLE_VALID | RLLE_IFADDR); 1516b4b1367aSAlexander V. Chernikov } 1517b4b1367aSAlexander V. Chernikov 1518b4b1367aSAlexander V. Chernikov return (lle); 1519b4b1367aSAlexander V. Chernikov } 1520b4b1367aSAlexander V. Chernikov 15216e6b3f7cSQing Li /* 15226e6b3f7cSQing Li * Return NULL if not found or marked for deletion. 15236e6b3f7cSQing Li * If found return lle read locked. 15246e6b3f7cSQing Li */ 15256e6b3f7cSQing Li static struct llentry * 15266e6b3f7cSQing Li in_lltable_lookup(struct lltable *llt, u_int flags, const struct sockaddr *l3addr) 15276e6b3f7cSQing Li { 15286e6b3f7cSQing Li const struct sockaddr_in *sin = (const struct sockaddr_in *)l3addr; 15296e6b3f7cSQing Li struct llentry *lle; 15306e6b3f7cSQing Li 15316e4cd746SMarius Strobl IF_AFDATA_LOCK_ASSERT(llt->llt_ifp); 15326e6b3f7cSQing Li KASSERT(l3addr->sa_family == AF_INET, 15336e6b3f7cSQing Li ("sin_family %d", l3addr->sa_family)); 153449cf58e5SMark Johnston KASSERT((flags & (LLE_UNLOCKED | LLE_EXCLUSIVE)) != 153549cf58e5SMark Johnston (LLE_UNLOCKED | LLE_EXCLUSIVE), 153649cf58e5SMark Johnston ("wrong lle request flags: %#x", flags)); 1537b4b1367aSAlexander V. Chernikov 153849cf58e5SMark Johnston lle = in_lltable_find_dst(llt, sin->sin_addr); 1539b4b1367aSAlexander V. Chernikov if (lle == NULL) 15406e6b3f7cSQing Li return (NULL); 1541f8aee88fSAlexander V. Chernikov if (flags & LLE_UNLOCKED) 1542f8aee88fSAlexander V. Chernikov return (lle); 1543f8aee88fSAlexander V. Chernikov 15446e6b3f7cSQing Li if (flags & LLE_EXCLUSIVE) 15456e6b3f7cSQing Li LLE_WLOCK(lle); 15466e6b3f7cSQing Li else 15476e6b3f7cSQing Li LLE_RLOCK(lle); 1548b4b1367aSAlexander V. Chernikov 1549c06cc56eSMark Johnston /* 1550c06cc56eSMark Johnston * If the afdata lock is not held, the LLE may have been unlinked while 1551c06cc56eSMark Johnston * we were blocked on the LLE lock. Check for this case. 1552c06cc56eSMark Johnston */ 1553c06cc56eSMark Johnston if (__predict_false((lle->la_flags & LLE_LINKED) == 0)) { 1554c06cc56eSMark Johnston if (flags & LLE_EXCLUSIVE) 1555c06cc56eSMark Johnston LLE_WUNLOCK(lle); 1556c06cc56eSMark Johnston else 1557c06cc56eSMark Johnston LLE_RUNLOCK(lle); 1558c06cc56eSMark Johnston return (NULL); 1559c06cc56eSMark Johnston } 15606e6b3f7cSQing Li return (lle); 15616e6b3f7cSQing Li } 15626e6b3f7cSQing Li 15636e6b3f7cSQing Li static int 156411cdad98SAlexander V. Chernikov in_lltable_dump_entry(struct lltable *llt, struct llentry *lle, 156511cdad98SAlexander V. Chernikov struct sysctl_req *wr) 15666e6b3f7cSQing Li { 15676e6b3f7cSQing Li struct ifnet *ifp = llt->llt_ifp; 15686e6b3f7cSQing Li /* XXX stack use */ 15696e6b3f7cSQing Li struct { 15706e6b3f7cSQing Li struct rt_msghdr rtm; 15719711a168SGleb Smirnoff struct sockaddr_in sin; 15726e6b3f7cSQing Li struct sockaddr_dl sdl; 15736e6b3f7cSQing Li } arpc; 15746e6b3f7cSQing Li struct sockaddr_dl *sdl; 157511cdad98SAlexander V. Chernikov int error; 15766e6b3f7cSQing Li 157711cdad98SAlexander V. Chernikov bzero(&arpc, sizeof(arpc)); 15786e6b3f7cSQing Li /* skip deleted entries */ 157993704ac5SQing Li if ((lle->la_flags & LLE_DELETED) == LLE_DELETED) 158011cdad98SAlexander V. Chernikov return (0); 1581813dd6aeSBjoern A. Zeeb /* Skip if jailed and not a valid IP of the prison. */ 158211cdad98SAlexander V. Chernikov lltable_fill_sa_entry(lle,(struct sockaddr *)&arpc.sin); 1583514ef08cSBrooks Davis if (prison_if(wr->td->td_ucred, (struct sockaddr *)&arpc.sin) != 0) 158411cdad98SAlexander V. Chernikov return (0); 15856e6b3f7cSQing Li /* 15866e6b3f7cSQing Li * produce a msg made of: 15876e6b3f7cSQing Li * struct rt_msghdr; 15889711a168SGleb Smirnoff * struct sockaddr_in; (IPv4) 15896e6b3f7cSQing Li * struct sockaddr_dl; 15906e6b3f7cSQing Li */ 15916e6b3f7cSQing Li arpc.rtm.rtm_msglen = sizeof(arpc); 1592c0e9a8a1SHartmut Brandt arpc.rtm.rtm_version = RTM_VERSION; 1593c0e9a8a1SHartmut Brandt arpc.rtm.rtm_type = RTM_GET; 1594c0e9a8a1SHartmut Brandt arpc.rtm.rtm_flags = RTF_UP; 1595c0e9a8a1SHartmut Brandt arpc.rtm.rtm_addrs = RTA_DST | RTA_GATEWAY; 15966e6b3f7cSQing Li 15976e6b3f7cSQing Li /* publish */ 15989711a168SGleb Smirnoff if (lle->la_flags & LLE_PUB) 15996e6b3f7cSQing Li arpc.rtm.rtm_flags |= RTF_ANNOUNCE; 16006e6b3f7cSQing Li 16016e6b3f7cSQing Li sdl = &arpc.sdl; 16026e6b3f7cSQing Li sdl->sdl_family = AF_LINK; 16036e6b3f7cSQing Li sdl->sdl_len = sizeof(*sdl); 16046e6b3f7cSQing Li sdl->sdl_index = ifp->if_index; 16056e6b3f7cSQing Li sdl->sdl_type = ifp->if_type; 160693704ac5SQing Li if ((lle->la_flags & LLE_VALID) == LLE_VALID) { 160793704ac5SQing Li sdl->sdl_alen = ifp->if_addrlen; 16084fb3a820SAlexander V. Chernikov bcopy(lle->ll_addr, LLADDR(sdl), ifp->if_addrlen); 160993704ac5SQing Li } else { 161093704ac5SQing Li sdl->sdl_alen = 0; 161193704ac5SQing Li bzero(LLADDR(sdl), ifp->if_addrlen); 161293704ac5SQing Li } 16136e6b3f7cSQing Li 16146e6b3f7cSQing Li arpc.rtm.rtm_rmx.rmx_expire = 16156e6b3f7cSQing Li lle->la_flags & LLE_STATIC ? 0 : lle->la_expire; 16168eca593cSQing Li arpc.rtm.rtm_flags |= (RTF_HOST | RTF_LLDATA); 16176e6b3f7cSQing Li if (lle->la_flags & LLE_STATIC) 16186e6b3f7cSQing Li arpc.rtm.rtm_flags |= RTF_STATIC; 16194a336ef4SAlexander V. Chernikov if (lle->la_flags & LLE_IFADDR) 16204a336ef4SAlexander V. Chernikov arpc.rtm.rtm_flags |= RTF_PINNED; 16216e6b3f7cSQing Li arpc.rtm.rtm_index = ifp->if_index; 16226e6b3f7cSQing Li error = SYSCTL_OUT(wr, &arpc, sizeof(arpc)); 162311cdad98SAlexander V. Chernikov 162411cdad98SAlexander V. Chernikov return (error); 16256e6b3f7cSQing Li } 16266e6b3f7cSQing Li 16273a749863SAlexander V. Chernikov static struct lltable * 16283a749863SAlexander V. Chernikov in_lltattach(struct ifnet *ifp) 16296e6b3f7cSQing Li { 1630d10910e6SBruce M Simpson struct lltable *llt; 16316e6b3f7cSQing Li 16323a749863SAlexander V. Chernikov llt = lltable_allocate_htbl(IN_LLTBL_DEFAULT_HSIZE); 1633721cd2e0SAlexander V. Chernikov llt->llt_af = AF_INET; 1634721cd2e0SAlexander V. Chernikov llt->llt_ifp = ifp; 1635d10910e6SBruce M Simpson 16366e6b3f7cSQing Li llt->llt_lookup = in_lltable_lookup; 16375a255516SAlexander V. Chernikov llt->llt_alloc_entry = in_lltable_alloc; 16383e7a2321SAlexander V. Chernikov llt->llt_delete_entry = in_lltable_delete_entry; 163911cdad98SAlexander V. Chernikov llt->llt_dump_entry = in_lltable_dump_entry; 164011cdad98SAlexander V. Chernikov llt->llt_hash = in_lltable_hash; 164111cdad98SAlexander V. Chernikov llt->llt_fill_sa_entry = in_lltable_fill_sa_entry; 164211cdad98SAlexander V. Chernikov llt->llt_free_entry = in_lltable_free_entry; 164311cdad98SAlexander V. Chernikov llt->llt_match_prefix = in_lltable_match_prefix; 1644f3a3b061SAlexander V. Chernikov llt->llt_mark_used = llentry_mark_used; 1645721cd2e0SAlexander V. Chernikov lltable_link(llt); 1646d10910e6SBruce M Simpson 16473a749863SAlexander V. Chernikov return (llt); 16483a749863SAlexander V. Chernikov } 16493a749863SAlexander V. Chernikov 16503a749863SAlexander V. Chernikov void * 16513a749863SAlexander V. Chernikov in_domifattach(struct ifnet *ifp) 16523a749863SAlexander V. Chernikov { 16533a749863SAlexander V. Chernikov struct in_ifinfo *ii; 16543a749863SAlexander V. Chernikov 1655721cd2e0SAlexander V. Chernikov ii = malloc(sizeof(struct in_ifinfo), M_IFADDR, M_WAITOK|M_ZERO); 165641cb42a6SAlexander V. Chernikov 16573a749863SAlexander V. Chernikov ii->ii_llt = in_lltattach(ifp); 1658d10910e6SBruce M Simpson ii->ii_igmp = igmp_domifattach(ifp); 1659d10910e6SBruce M Simpson 166041cb42a6SAlexander V. Chernikov return (ii); 16616e6b3f7cSQing Li } 16626e6b3f7cSQing Li 16636e6b3f7cSQing Li void 1664d10910e6SBruce M Simpson in_domifdetach(struct ifnet *ifp, void *aux) 16656e6b3f7cSQing Li { 1666d10910e6SBruce M Simpson struct in_ifinfo *ii = (struct in_ifinfo *)aux; 16676e6b3f7cSQing Li 1668d10910e6SBruce M Simpson igmp_domifdetach(ifp); 1669d10910e6SBruce M Simpson lltable_free(ii->ii_llt); 1670d10910e6SBruce M Simpson free(ii, M_IFADDR); 16716e6b3f7cSQing Li } 1672