xref: /linux/net/ipv4/ip_sockglue.c (revision 1b346576359c72bee34b1476b4fc63d77d37b314)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds  * INET		An implementation of the TCP/IP protocol suite for the LINUX
31da177e4SLinus Torvalds  *		operating system.  INET is implemented using the  BSD Socket
41da177e4SLinus Torvalds  *		interface as the means of communication with the user level.
51da177e4SLinus Torvalds  *
61da177e4SLinus Torvalds  *		The IP to API glue.
71da177e4SLinus Torvalds  *
81da177e4SLinus Torvalds  * Authors:	see ip.c
91da177e4SLinus Torvalds  *
101da177e4SLinus Torvalds  * Fixes:
111da177e4SLinus Torvalds  *		Many		:	Split from ip.c , see ip.c for history.
121da177e4SLinus Torvalds  *		Martin Mares	:	TOS setting fixed.
131da177e4SLinus Torvalds  *		Alan Cox	:	Fixed a couple of oopses in Martin's
141da177e4SLinus Torvalds  *					TOS tweaks.
151da177e4SLinus Torvalds  *		Mike McLagan	:	Routing by source
161da177e4SLinus Torvalds  */
171da177e4SLinus Torvalds 
181da177e4SLinus Torvalds #include <linux/module.h>
191da177e4SLinus Torvalds #include <linux/types.h>
201da177e4SLinus Torvalds #include <linux/mm.h>
211da177e4SLinus Torvalds #include <linux/skbuff.h>
221da177e4SLinus Torvalds #include <linux/ip.h>
231da177e4SLinus Torvalds #include <linux/icmp.h>
2414c85021SArnaldo Carvalho de Melo #include <linux/inetdevice.h>
251da177e4SLinus Torvalds #include <linux/netdevice.h>
265a0e3ad6STejun Heo #include <linux/slab.h>
271da177e4SLinus Torvalds #include <net/sock.h>
281da177e4SLinus Torvalds #include <net/ip.h>
291da177e4SLinus Torvalds #include <net/icmp.h>
30d83d8461SArnaldo Carvalho de Melo #include <net/tcp_states.h>
311da177e4SLinus Torvalds #include <linux/udp.h>
321da177e4SLinus Torvalds #include <linux/igmp.h>
331da177e4SLinus Torvalds #include <linux/netfilter.h>
341da177e4SLinus Torvalds #include <linux/route.h>
351da177e4SLinus Torvalds #include <linux/mroute.h>
362c67e9acSMaciej Żenczykowski #include <net/inet_ecn.h>
371da177e4SLinus Torvalds #include <net/route.h>
381da177e4SLinus Torvalds #include <net/xfrm.h>
39dae50295SDavid L Stevens #include <net/compat.h>
40dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
411da177e4SLinus Torvalds #include <net/transp_v6.h>
421da177e4SLinus Torvalds #endif
4335ebf65eSDavid S. Miller #include <net/ip_fib.h>
441da177e4SLinus Torvalds 
451da177e4SLinus Torvalds #include <linux/errqueue.h>
461da177e4SLinus Torvalds #include <asm/uaccess.h>
471da177e4SLinus Torvalds 
481da177e4SLinus Torvalds #define IP_CMSG_PKTINFO		1
491da177e4SLinus Torvalds #define IP_CMSG_TTL		2
501da177e4SLinus Torvalds #define IP_CMSG_TOS		4
511da177e4SLinus Torvalds #define IP_CMSG_RECVOPTS	8
521da177e4SLinus Torvalds #define IP_CMSG_RETOPTS		16
532c7946a7SCatherine Zhang #define IP_CMSG_PASSSEC		32
54e8b2dfe9SBalazs Scheidler #define IP_CMSG_ORIGDSTADDR     64
551da177e4SLinus Torvalds 
561da177e4SLinus Torvalds /*
571da177e4SLinus Torvalds  *	SOL_IP control messages.
581da177e4SLinus Torvalds  */
591da177e4SLinus Torvalds 
601da177e4SLinus Torvalds static void ip_cmsg_recv_pktinfo(struct msghdr *msg, struct sk_buff *skb)
611da177e4SLinus Torvalds {
62d826eb14SEric Dumazet 	struct in_pktinfo info = *PKTINFO_SKB_CB(skb);
631da177e4SLinus Torvalds 
64eddc9ec5SArnaldo Carvalho de Melo 	info.ipi_addr.s_addr = ip_hdr(skb)->daddr;
651da177e4SLinus Torvalds 
661da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_PKTINFO, sizeof(info), &info);
671da177e4SLinus Torvalds }
681da177e4SLinus Torvalds 
691da177e4SLinus Torvalds static void ip_cmsg_recv_ttl(struct msghdr *msg, struct sk_buff *skb)
701da177e4SLinus Torvalds {
71eddc9ec5SArnaldo Carvalho de Melo 	int ttl = ip_hdr(skb)->ttl;
721da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_TTL, sizeof(int), &ttl);
731da177e4SLinus Torvalds }
741da177e4SLinus Torvalds 
751da177e4SLinus Torvalds static void ip_cmsg_recv_tos(struct msghdr *msg, struct sk_buff *skb)
761da177e4SLinus Torvalds {
77eddc9ec5SArnaldo Carvalho de Melo 	put_cmsg(msg, SOL_IP, IP_TOS, 1, &ip_hdr(skb)->tos);
781da177e4SLinus Torvalds }
791da177e4SLinus Torvalds 
801da177e4SLinus Torvalds static void ip_cmsg_recv_opts(struct msghdr *msg, struct sk_buff *skb)
811da177e4SLinus Torvalds {
821da177e4SLinus Torvalds 	if (IPCB(skb)->opt.optlen == 0)
831da177e4SLinus Torvalds 		return;
841da177e4SLinus Torvalds 
85eddc9ec5SArnaldo Carvalho de Melo 	put_cmsg(msg, SOL_IP, IP_RECVOPTS, IPCB(skb)->opt.optlen,
86eddc9ec5SArnaldo Carvalho de Melo 		 ip_hdr(skb) + 1);
871da177e4SLinus Torvalds }
881da177e4SLinus Torvalds 
891da177e4SLinus Torvalds 
901da177e4SLinus Torvalds static void ip_cmsg_recv_retopts(struct msghdr *msg, struct sk_buff *skb)
911da177e4SLinus Torvalds {
921da177e4SLinus Torvalds 	unsigned char optbuf[sizeof(struct ip_options) + 40];
931da177e4SLinus Torvalds 	struct ip_options *opt = (struct ip_options *)optbuf;
941da177e4SLinus Torvalds 
951da177e4SLinus Torvalds 	if (IPCB(skb)->opt.optlen == 0)
961da177e4SLinus Torvalds 		return;
971da177e4SLinus Torvalds 
981da177e4SLinus Torvalds 	if (ip_options_echo(opt, skb)) {
991da177e4SLinus Torvalds 		msg->msg_flags |= MSG_CTRUNC;
1001da177e4SLinus Torvalds 		return;
1011da177e4SLinus Torvalds 	}
1021da177e4SLinus Torvalds 	ip_options_undo(opt);
1031da177e4SLinus Torvalds 
1041da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_RETOPTS, opt->optlen, opt->__data);
1051da177e4SLinus Torvalds }
1061da177e4SLinus Torvalds 
1072c7946a7SCatherine Zhang static void ip_cmsg_recv_security(struct msghdr *msg, struct sk_buff *skb)
1082c7946a7SCatherine Zhang {
1092c7946a7SCatherine Zhang 	char *secdata;
110dc49c1f9SCatherine Zhang 	u32 seclen, secid;
1112c7946a7SCatherine Zhang 	int err;
1122c7946a7SCatherine Zhang 
113dc49c1f9SCatherine Zhang 	err = security_socket_getpeersec_dgram(NULL, skb, &secid);
114dc49c1f9SCatherine Zhang 	if (err)
115dc49c1f9SCatherine Zhang 		return;
116dc49c1f9SCatherine Zhang 
117dc49c1f9SCatherine Zhang 	err = security_secid_to_secctx(secid, &secdata, &seclen);
1182c7946a7SCatherine Zhang 	if (err)
1192c7946a7SCatherine Zhang 		return;
1202c7946a7SCatherine Zhang 
1212c7946a7SCatherine Zhang 	put_cmsg(msg, SOL_IP, SCM_SECURITY, seclen, secdata);
122dc49c1f9SCatherine Zhang 	security_release_secctx(secdata, seclen);
1232c7946a7SCatherine Zhang }
1242c7946a7SCatherine Zhang 
12521d1a161SHarvey Harrison static void ip_cmsg_recv_dstaddr(struct msghdr *msg, struct sk_buff *skb)
126e8b2dfe9SBalazs Scheidler {
127e8b2dfe9SBalazs Scheidler 	struct sockaddr_in sin;
128b71d1d42SEric Dumazet 	const struct iphdr *iph = ip_hdr(skb);
12921d1a161SHarvey Harrison 	__be16 *ports = (__be16 *)skb_transport_header(skb);
130e8b2dfe9SBalazs Scheidler 
131e8b2dfe9SBalazs Scheidler 	if (skb_transport_offset(skb) + 4 > skb->len)
132e8b2dfe9SBalazs Scheidler 		return;
133e8b2dfe9SBalazs Scheidler 
134e8b2dfe9SBalazs Scheidler 	/* All current transport protocols have the port numbers in the
135e8b2dfe9SBalazs Scheidler 	 * first four bytes of the transport header and this function is
136e8b2dfe9SBalazs Scheidler 	 * written with this assumption in mind.
137e8b2dfe9SBalazs Scheidler 	 */
138e8b2dfe9SBalazs Scheidler 
139e8b2dfe9SBalazs Scheidler 	sin.sin_family = AF_INET;
140e8b2dfe9SBalazs Scheidler 	sin.sin_addr.s_addr = iph->daddr;
141e8b2dfe9SBalazs Scheidler 	sin.sin_port = ports[1];
142e8b2dfe9SBalazs Scheidler 	memset(sin.sin_zero, 0, sizeof(sin.sin_zero));
143e8b2dfe9SBalazs Scheidler 
144e8b2dfe9SBalazs Scheidler 	put_cmsg(msg, SOL_IP, IP_ORIGDSTADDR, sizeof(sin), &sin);
145e8b2dfe9SBalazs Scheidler }
1461da177e4SLinus Torvalds 
1471da177e4SLinus Torvalds void ip_cmsg_recv(struct msghdr *msg, struct sk_buff *skb)
1481da177e4SLinus Torvalds {
1491da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(skb->sk);
15095c96174SEric Dumazet 	unsigned int flags = inet->cmsg_flags;
1511da177e4SLinus Torvalds 
1521da177e4SLinus Torvalds 	/* Ordered by supposed usage frequency */
1531da177e4SLinus Torvalds 	if (flags & 1)
1541da177e4SLinus Torvalds 		ip_cmsg_recv_pktinfo(msg, skb);
1551da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1561da177e4SLinus Torvalds 		return;
1571da177e4SLinus Torvalds 
1581da177e4SLinus Torvalds 	if (flags & 1)
1591da177e4SLinus Torvalds 		ip_cmsg_recv_ttl(msg, skb);
1601da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1611da177e4SLinus Torvalds 		return;
1621da177e4SLinus Torvalds 
1631da177e4SLinus Torvalds 	if (flags & 1)
1641da177e4SLinus Torvalds 		ip_cmsg_recv_tos(msg, skb);
1651da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1661da177e4SLinus Torvalds 		return;
1671da177e4SLinus Torvalds 
1681da177e4SLinus Torvalds 	if (flags & 1)
1691da177e4SLinus Torvalds 		ip_cmsg_recv_opts(msg, skb);
1701da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1711da177e4SLinus Torvalds 		return;
1721da177e4SLinus Torvalds 
1731da177e4SLinus Torvalds 	if (flags & 1)
1741da177e4SLinus Torvalds 		ip_cmsg_recv_retopts(msg, skb);
1752c7946a7SCatherine Zhang 	if ((flags >>= 1) == 0)
1762c7946a7SCatherine Zhang 		return;
1772c7946a7SCatherine Zhang 
1782c7946a7SCatherine Zhang 	if (flags & 1)
1792c7946a7SCatherine Zhang 		ip_cmsg_recv_security(msg, skb);
180e8b2dfe9SBalazs Scheidler 
181e8b2dfe9SBalazs Scheidler 	if ((flags >>= 1) == 0)
182e8b2dfe9SBalazs Scheidler 		return;
183e8b2dfe9SBalazs Scheidler 	if (flags & 1)
184e8b2dfe9SBalazs Scheidler 		ip_cmsg_recv_dstaddr(msg, skb);
185e8b2dfe9SBalazs Scheidler 
1861da177e4SLinus Torvalds }
1874d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_cmsg_recv);
1881da177e4SLinus Torvalds 
189c8e6ad08SHannes Frederic Sowa int ip_cmsg_send(struct net *net, struct msghdr *msg, struct ipcm_cookie *ipc,
190c8e6ad08SHannes Frederic Sowa 		 bool allow_ipv6)
1911da177e4SLinus Torvalds {
192f02db315SFrancesco Fusco 	int err, val;
1931da177e4SLinus Torvalds 	struct cmsghdr *cmsg;
1941da177e4SLinus Torvalds 
1951da177e4SLinus Torvalds 	for (cmsg = CMSG_FIRSTHDR(msg); cmsg; cmsg = CMSG_NXTHDR(msg, cmsg)) {
1961da177e4SLinus Torvalds 		if (!CMSG_OK(msg, cmsg))
1971da177e4SLinus Torvalds 			return -EINVAL;
198c8e6ad08SHannes Frederic Sowa #if defined(CONFIG_IPV6)
199c8e6ad08SHannes Frederic Sowa 		if (allow_ipv6 &&
200c8e6ad08SHannes Frederic Sowa 		    cmsg->cmsg_level == SOL_IPV6 &&
201c8e6ad08SHannes Frederic Sowa 		    cmsg->cmsg_type == IPV6_PKTINFO) {
202c8e6ad08SHannes Frederic Sowa 			struct in6_pktinfo *src_info;
203c8e6ad08SHannes Frederic Sowa 
204c8e6ad08SHannes Frederic Sowa 			if (cmsg->cmsg_len < CMSG_LEN(sizeof(*src_info)))
205c8e6ad08SHannes Frederic Sowa 				return -EINVAL;
206c8e6ad08SHannes Frederic Sowa 			src_info = (struct in6_pktinfo *)CMSG_DATA(cmsg);
207c8e6ad08SHannes Frederic Sowa 			if (!ipv6_addr_v4mapped(&src_info->ipi6_addr))
208c8e6ad08SHannes Frederic Sowa 				return -EINVAL;
209c8e6ad08SHannes Frederic Sowa 			ipc->oif = src_info->ipi6_ifindex;
210c8e6ad08SHannes Frederic Sowa 			ipc->addr = src_info->ipi6_addr.s6_addr32[3];
211c8e6ad08SHannes Frederic Sowa 			continue;
212c8e6ad08SHannes Frederic Sowa 		}
213c8e6ad08SHannes Frederic Sowa #endif
2141da177e4SLinus Torvalds 		if (cmsg->cmsg_level != SOL_IP)
2151da177e4SLinus Torvalds 			continue;
2161da177e4SLinus Torvalds 		switch (cmsg->cmsg_type) {
2171da177e4SLinus Torvalds 		case IP_RETOPTS:
2181da177e4SLinus Torvalds 			err = cmsg->cmsg_len - CMSG_ALIGN(sizeof(struct cmsghdr));
2194d52cfbeSEric Dumazet 			err = ip_options_get(net, &ipc->opt, CMSG_DATA(cmsg),
2204d52cfbeSEric Dumazet 					     err < 40 ? err : 40);
2211da177e4SLinus Torvalds 			if (err)
2221da177e4SLinus Torvalds 				return err;
2231da177e4SLinus Torvalds 			break;
2241da177e4SLinus Torvalds 		case IP_PKTINFO:
2251da177e4SLinus Torvalds 		{
2261da177e4SLinus Torvalds 			struct in_pktinfo *info;
2271da177e4SLinus Torvalds 			if (cmsg->cmsg_len != CMSG_LEN(sizeof(struct in_pktinfo)))
2281da177e4SLinus Torvalds 				return -EINVAL;
2291da177e4SLinus Torvalds 			info = (struct in_pktinfo *)CMSG_DATA(cmsg);
2301da177e4SLinus Torvalds 			ipc->oif = info->ipi_ifindex;
2311da177e4SLinus Torvalds 			ipc->addr = info->ipi_spec_dst.s_addr;
2321da177e4SLinus Torvalds 			break;
2331da177e4SLinus Torvalds 		}
234f02db315SFrancesco Fusco 		case IP_TTL:
235f02db315SFrancesco Fusco 			if (cmsg->cmsg_len != CMSG_LEN(sizeof(int)))
236f02db315SFrancesco Fusco 				return -EINVAL;
237f02db315SFrancesco Fusco 			val = *(int *)CMSG_DATA(cmsg);
238f02db315SFrancesco Fusco 			if (val < 1 || val > 255)
239f02db315SFrancesco Fusco 				return -EINVAL;
240f02db315SFrancesco Fusco 			ipc->ttl = val;
241f02db315SFrancesco Fusco 			break;
242f02db315SFrancesco Fusco 		case IP_TOS:
243f02db315SFrancesco Fusco 			if (cmsg->cmsg_len != CMSG_LEN(sizeof(int)))
244f02db315SFrancesco Fusco 				return -EINVAL;
245f02db315SFrancesco Fusco 			val = *(int *)CMSG_DATA(cmsg);
246f02db315SFrancesco Fusco 			if (val < 0 || val > 255)
247f02db315SFrancesco Fusco 				return -EINVAL;
248f02db315SFrancesco Fusco 			ipc->tos = val;
249f02db315SFrancesco Fusco 			ipc->priority = rt_tos2priority(ipc->tos);
250f02db315SFrancesco Fusco 			break;
251f02db315SFrancesco Fusco 
2521da177e4SLinus Torvalds 		default:
2531da177e4SLinus Torvalds 			return -EINVAL;
2541da177e4SLinus Torvalds 		}
2551da177e4SLinus Torvalds 	}
2561da177e4SLinus Torvalds 	return 0;
2571da177e4SLinus Torvalds }
2581da177e4SLinus Torvalds 
2591da177e4SLinus Torvalds 
2601da177e4SLinus Torvalds /* Special input handler for packets caught by router alert option.
2611da177e4SLinus Torvalds    They are selected only by protocol field, and then processed likely
2621da177e4SLinus Torvalds    local ones; but only if someone wants them! Otherwise, router
2631da177e4SLinus Torvalds    not running rsvpd will kill RSVP.
2641da177e4SLinus Torvalds 
2651da177e4SLinus Torvalds    It is user level problem, what it will make with them.
2661da177e4SLinus Torvalds    I have no idea, how it will masquearde or NAT them (it is joke, joke :-)),
2671da177e4SLinus Torvalds    but receiver should be enough clever f.e. to forward mtrace requests,
2681da177e4SLinus Torvalds    sent to multicast group to reach destination designated router.
2691da177e4SLinus Torvalds  */
27043a951e9SEric Dumazet struct ip_ra_chain __rcu *ip_ra_chain;
27166018506SEric Dumazet static DEFINE_SPINLOCK(ip_ra_lock);
27266018506SEric Dumazet 
273592fcb9dSEric Dumazet 
274592fcb9dSEric Dumazet static void ip_ra_destroy_rcu(struct rcu_head *head)
27566018506SEric Dumazet {
276592fcb9dSEric Dumazet 	struct ip_ra_chain *ra = container_of(head, struct ip_ra_chain, rcu);
277592fcb9dSEric Dumazet 
278592fcb9dSEric Dumazet 	sock_put(ra->saved_sk);
279592fcb9dSEric Dumazet 	kfree(ra);
28066018506SEric Dumazet }
2811da177e4SLinus Torvalds 
2824d52cfbeSEric Dumazet int ip_ra_control(struct sock *sk, unsigned char on,
2834d52cfbeSEric Dumazet 		  void (*destructor)(struct sock *))
2841da177e4SLinus Torvalds {
28543a951e9SEric Dumazet 	struct ip_ra_chain *ra, *new_ra;
28643a951e9SEric Dumazet 	struct ip_ra_chain __rcu **rap;
2871da177e4SLinus Torvalds 
288c720c7e8SEric Dumazet 	if (sk->sk_type != SOCK_RAW || inet_sk(sk)->inet_num == IPPROTO_RAW)
2891da177e4SLinus Torvalds 		return -EINVAL;
2901da177e4SLinus Torvalds 
2911da177e4SLinus Torvalds 	new_ra = on ? kmalloc(sizeof(*new_ra), GFP_KERNEL) : NULL;
2921da177e4SLinus Torvalds 
29366018506SEric Dumazet 	spin_lock_bh(&ip_ra_lock);
29443a951e9SEric Dumazet 	for (rap = &ip_ra_chain;
29543a951e9SEric Dumazet 	     (ra = rcu_dereference_protected(*rap,
29643a951e9SEric Dumazet 			lockdep_is_held(&ip_ra_lock))) != NULL;
29743a951e9SEric Dumazet 	     rap = &ra->next) {
2981da177e4SLinus Torvalds 		if (ra->sk == sk) {
2991da177e4SLinus Torvalds 			if (on) {
30066018506SEric Dumazet 				spin_unlock_bh(&ip_ra_lock);
3011da177e4SLinus Torvalds 				kfree(new_ra);
3021da177e4SLinus Torvalds 				return -EADDRINUSE;
3031da177e4SLinus Torvalds 			}
304592fcb9dSEric Dumazet 			/* dont let ip_call_ra_chain() use sk again */
305592fcb9dSEric Dumazet 			ra->sk = NULL;
30666018506SEric Dumazet 			rcu_assign_pointer(*rap, ra->next);
30766018506SEric Dumazet 			spin_unlock_bh(&ip_ra_lock);
3081da177e4SLinus Torvalds 
3091da177e4SLinus Torvalds 			if (ra->destructor)
3101da177e4SLinus Torvalds 				ra->destructor(sk);
311592fcb9dSEric Dumazet 			/*
312592fcb9dSEric Dumazet 			 * Delay sock_put(sk) and kfree(ra) after one rcu grace
313592fcb9dSEric Dumazet 			 * period. This guarantee ip_call_ra_chain() dont need
314592fcb9dSEric Dumazet 			 * to mess with socket refcounts.
315592fcb9dSEric Dumazet 			 */
316592fcb9dSEric Dumazet 			ra->saved_sk = sk;
317592fcb9dSEric Dumazet 			call_rcu(&ra->rcu, ip_ra_destroy_rcu);
3181da177e4SLinus Torvalds 			return 0;
3191da177e4SLinus Torvalds 		}
3201da177e4SLinus Torvalds 	}
3211da177e4SLinus Torvalds 	if (new_ra == NULL) {
32266018506SEric Dumazet 		spin_unlock_bh(&ip_ra_lock);
3231da177e4SLinus Torvalds 		return -ENOBUFS;
3241da177e4SLinus Torvalds 	}
3251da177e4SLinus Torvalds 	new_ra->sk = sk;
3261da177e4SLinus Torvalds 	new_ra->destructor = destructor;
3271da177e4SLinus Torvalds 
3281da177e4SLinus Torvalds 	new_ra->next = ra;
32966018506SEric Dumazet 	rcu_assign_pointer(*rap, new_ra);
3301da177e4SLinus Torvalds 	sock_hold(sk);
33166018506SEric Dumazet 	spin_unlock_bh(&ip_ra_lock);
3321da177e4SLinus Torvalds 
3331da177e4SLinus Torvalds 	return 0;
3341da177e4SLinus Torvalds }
3351da177e4SLinus Torvalds 
3361da177e4SLinus Torvalds void ip_icmp_error(struct sock *sk, struct sk_buff *skb, int err,
33735986b32SAl Viro 		   __be16 port, u32 info, u8 *payload)
3381da177e4SLinus Torvalds {
3391da177e4SLinus Torvalds 	struct sock_exterr_skb *serr;
3401da177e4SLinus Torvalds 
3411da177e4SLinus Torvalds 	skb = skb_clone(skb, GFP_ATOMIC);
3421da177e4SLinus Torvalds 	if (!skb)
3431da177e4SLinus Torvalds 		return;
3441da177e4SLinus Torvalds 
3451da177e4SLinus Torvalds 	serr = SKB_EXT_ERR(skb);
3461da177e4SLinus Torvalds 	serr->ee.ee_errno = err;
3471da177e4SLinus Torvalds 	serr->ee.ee_origin = SO_EE_ORIGIN_ICMP;
34888c7664fSArnaldo Carvalho de Melo 	serr->ee.ee_type = icmp_hdr(skb)->type;
34988c7664fSArnaldo Carvalho de Melo 	serr->ee.ee_code = icmp_hdr(skb)->code;
3501da177e4SLinus Torvalds 	serr->ee.ee_pad = 0;
3511da177e4SLinus Torvalds 	serr->ee.ee_info = info;
3521da177e4SLinus Torvalds 	serr->ee.ee_data = 0;
35388c7664fSArnaldo Carvalho de Melo 	serr->addr_offset = (u8 *)&(((struct iphdr *)(icmp_hdr(skb) + 1))->daddr) -
354d56f90a7SArnaldo Carvalho de Melo 				   skb_network_header(skb);
3551da177e4SLinus Torvalds 	serr->port = port;
3561da177e4SLinus Torvalds 
357bd82393cSArnaldo Carvalho de Melo 	if (skb_pull(skb, payload - skb->data) != NULL) {
358bd82393cSArnaldo Carvalho de Melo 		skb_reset_transport_header(skb);
359bd82393cSArnaldo Carvalho de Melo 		if (sock_queue_err_skb(sk, skb) == 0)
360bd82393cSArnaldo Carvalho de Melo 			return;
361bd82393cSArnaldo Carvalho de Melo 	}
3621da177e4SLinus Torvalds 	kfree_skb(skb);
3631da177e4SLinus Torvalds }
3641da177e4SLinus Torvalds 
3650579016eSAl Viro void ip_local_error(struct sock *sk, int err, __be32 daddr, __be16 port, u32 info)
3661da177e4SLinus Torvalds {
3671da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(sk);
3681da177e4SLinus Torvalds 	struct sock_exterr_skb *serr;
3691da177e4SLinus Torvalds 	struct iphdr *iph;
3701da177e4SLinus Torvalds 	struct sk_buff *skb;
3711da177e4SLinus Torvalds 
3721da177e4SLinus Torvalds 	if (!inet->recverr)
3731da177e4SLinus Torvalds 		return;
3741da177e4SLinus Torvalds 
3751da177e4SLinus Torvalds 	skb = alloc_skb(sizeof(struct iphdr), GFP_ATOMIC);
3761da177e4SLinus Torvalds 	if (!skb)
3771da177e4SLinus Torvalds 		return;
3781da177e4SLinus Torvalds 
3792ca9e6f2SArnaldo Carvalho de Melo 	skb_put(skb, sizeof(struct iphdr));
3802ca9e6f2SArnaldo Carvalho de Melo 	skb_reset_network_header(skb);
381eddc9ec5SArnaldo Carvalho de Melo 	iph = ip_hdr(skb);
3821da177e4SLinus Torvalds 	iph->daddr = daddr;
3831da177e4SLinus Torvalds 
3841da177e4SLinus Torvalds 	serr = SKB_EXT_ERR(skb);
3851da177e4SLinus Torvalds 	serr->ee.ee_errno = err;
3861da177e4SLinus Torvalds 	serr->ee.ee_origin = SO_EE_ORIGIN_LOCAL;
3871da177e4SLinus Torvalds 	serr->ee.ee_type = 0;
3881da177e4SLinus Torvalds 	serr->ee.ee_code = 0;
3891da177e4SLinus Torvalds 	serr->ee.ee_pad = 0;
3901da177e4SLinus Torvalds 	serr->ee.ee_info = info;
3911da177e4SLinus Torvalds 	serr->ee.ee_data = 0;
392d56f90a7SArnaldo Carvalho de Melo 	serr->addr_offset = (u8 *)&iph->daddr - skb_network_header(skb);
3931da177e4SLinus Torvalds 	serr->port = port;
3941da177e4SLinus Torvalds 
39527a884dcSArnaldo Carvalho de Melo 	__skb_pull(skb, skb_tail_pointer(skb) - skb->data);
396bd82393cSArnaldo Carvalho de Melo 	skb_reset_transport_header(skb);
3971da177e4SLinus Torvalds 
3981da177e4SLinus Torvalds 	if (sock_queue_err_skb(sk, skb))
3991da177e4SLinus Torvalds 		kfree_skb(skb);
4001da177e4SLinus Torvalds }
4011da177e4SLinus Torvalds 
4021da177e4SLinus Torvalds /*
4031da177e4SLinus Torvalds  *	Handle MSG_ERRQUEUE
4041da177e4SLinus Torvalds  */
40585fbaa75SHannes Frederic Sowa int ip_recv_error(struct sock *sk, struct msghdr *msg, int len, int *addr_len)
4061da177e4SLinus Torvalds {
4071da177e4SLinus Torvalds 	struct sock_exterr_skb *serr;
4081da177e4SLinus Torvalds 	struct sk_buff *skb, *skb2;
409342dfc30SSteffen Hurrle 	DECLARE_SOCKADDR(struct sockaddr_in *, sin, msg->msg_name);
4101da177e4SLinus Torvalds 	struct {
4111da177e4SLinus Torvalds 		struct sock_extended_err ee;
4121da177e4SLinus Torvalds 		struct sockaddr_in	 offender;
4131da177e4SLinus Torvalds 	} errhdr;
4141da177e4SLinus Torvalds 	int err;
4151da177e4SLinus Torvalds 	int copied;
4161da177e4SLinus Torvalds 
4171da177e4SLinus Torvalds 	err = -EAGAIN;
4181da177e4SLinus Torvalds 	skb = skb_dequeue(&sk->sk_error_queue);
4191da177e4SLinus Torvalds 	if (skb == NULL)
4201da177e4SLinus Torvalds 		goto out;
4211da177e4SLinus Torvalds 
4221da177e4SLinus Torvalds 	copied = skb->len;
4231da177e4SLinus Torvalds 	if (copied > len) {
4241da177e4SLinus Torvalds 		msg->msg_flags |= MSG_TRUNC;
4251da177e4SLinus Torvalds 		copied = len;
4261da177e4SLinus Torvalds 	}
4271da177e4SLinus Torvalds 	err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
4281da177e4SLinus Torvalds 	if (err)
4291da177e4SLinus Torvalds 		goto out_free_skb;
4301da177e4SLinus Torvalds 
4311da177e4SLinus Torvalds 	sock_recv_timestamp(msg, sk, skb);
4321da177e4SLinus Torvalds 
4331da177e4SLinus Torvalds 	serr = SKB_EXT_ERR(skb);
4341da177e4SLinus Torvalds 
4351da177e4SLinus Torvalds 	if (sin) {
4361da177e4SLinus Torvalds 		sin->sin_family = AF_INET;
437d56f90a7SArnaldo Carvalho de Melo 		sin->sin_addr.s_addr = *(__be32 *)(skb_network_header(skb) +
438d56f90a7SArnaldo Carvalho de Melo 						   serr->addr_offset);
4391da177e4SLinus Torvalds 		sin->sin_port = serr->port;
4401da177e4SLinus Torvalds 		memset(&sin->sin_zero, 0, sizeof(sin->sin_zero));
44185fbaa75SHannes Frederic Sowa 		*addr_len = sizeof(*sin);
4421da177e4SLinus Torvalds 	}
4431da177e4SLinus Torvalds 
4441da177e4SLinus Torvalds 	memcpy(&errhdr.ee, &serr->ee, sizeof(struct sock_extended_err));
4451da177e4SLinus Torvalds 	sin = &errhdr.offender;
4461da177e4SLinus Torvalds 	sin->sin_family = AF_UNSPEC;
4471da177e4SLinus Torvalds 	if (serr->ee.ee_origin == SO_EE_ORIGIN_ICMP) {
4481da177e4SLinus Torvalds 		struct inet_sock *inet = inet_sk(sk);
4491da177e4SLinus Torvalds 
4501da177e4SLinus Torvalds 		sin->sin_family = AF_INET;
451eddc9ec5SArnaldo Carvalho de Melo 		sin->sin_addr.s_addr = ip_hdr(skb)->saddr;
4521da177e4SLinus Torvalds 		sin->sin_port = 0;
4531da177e4SLinus Torvalds 		memset(&sin->sin_zero, 0, sizeof(sin->sin_zero));
4541da177e4SLinus Torvalds 		if (inet->cmsg_flags)
4551da177e4SLinus Torvalds 			ip_cmsg_recv(msg, skb);
4561da177e4SLinus Torvalds 	}
4571da177e4SLinus Torvalds 
4581da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_RECVERR, sizeof(errhdr), &errhdr);
4591da177e4SLinus Torvalds 
4601da177e4SLinus Torvalds 	/* Now we could try to dump offended packet options */
4611da177e4SLinus Torvalds 
4621da177e4SLinus Torvalds 	msg->msg_flags |= MSG_ERRQUEUE;
4631da177e4SLinus Torvalds 	err = copied;
4641da177e4SLinus Torvalds 
4651da177e4SLinus Torvalds 	/* Reset and regenerate socket error */
466e0f9f858SHerbert Xu 	spin_lock_bh(&sk->sk_error_queue.lock);
4671da177e4SLinus Torvalds 	sk->sk_err = 0;
4684d52cfbeSEric Dumazet 	skb2 = skb_peek(&sk->sk_error_queue);
4694d52cfbeSEric Dumazet 	if (skb2 != NULL) {
4701da177e4SLinus Torvalds 		sk->sk_err = SKB_EXT_ERR(skb2)->ee.ee_errno;
471e0f9f858SHerbert Xu 		spin_unlock_bh(&sk->sk_error_queue.lock);
4721da177e4SLinus Torvalds 		sk->sk_error_report(sk);
4731da177e4SLinus Torvalds 	} else
474e0f9f858SHerbert Xu 		spin_unlock_bh(&sk->sk_error_queue.lock);
4751da177e4SLinus Torvalds 
4761da177e4SLinus Torvalds out_free_skb:
4771da177e4SLinus Torvalds 	kfree_skb(skb);
4781da177e4SLinus Torvalds out:
4791da177e4SLinus Torvalds 	return err;
4801da177e4SLinus Torvalds }
4811da177e4SLinus Torvalds 
4821da177e4SLinus Torvalds 
4831da177e4SLinus Torvalds /*
4844d52cfbeSEric Dumazet  *	Socket option code for IP. This is the end of the line after any
4854d52cfbeSEric Dumazet  *	TCP,UDP etc options on an IP socket.
4861da177e4SLinus Torvalds  */
4871da177e4SLinus Torvalds 
4883fdadf7dSDmitry Mishin static int do_ip_setsockopt(struct sock *sk, int level,
489b7058842SDavid S. Miller 			    int optname, char __user *optval, unsigned int optlen)
4901da177e4SLinus Torvalds {
4911da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(sk);
4921da177e4SLinus Torvalds 	int val = 0, err;
4931da177e4SLinus Torvalds 
4940c9f79beSXi Wang 	switch (optname) {
4950c9f79beSXi Wang 	case IP_PKTINFO:
4960c9f79beSXi Wang 	case IP_RECVTTL:
4970c9f79beSXi Wang 	case IP_RECVOPTS:
4980c9f79beSXi Wang 	case IP_RECVTOS:
4990c9f79beSXi Wang 	case IP_RETOPTS:
5000c9f79beSXi Wang 	case IP_TOS:
5010c9f79beSXi Wang 	case IP_TTL:
5020c9f79beSXi Wang 	case IP_HDRINCL:
5030c9f79beSXi Wang 	case IP_MTU_DISCOVER:
5040c9f79beSXi Wang 	case IP_RECVERR:
5050c9f79beSXi Wang 	case IP_ROUTER_ALERT:
5060c9f79beSXi Wang 	case IP_FREEBIND:
5070c9f79beSXi Wang 	case IP_PASSSEC:
5080c9f79beSXi Wang 	case IP_TRANSPARENT:
5090c9f79beSXi Wang 	case IP_MINTTL:
5100c9f79beSXi Wang 	case IP_NODEFRAG:
5110c9f79beSXi Wang 	case IP_UNICAST_IF:
5120c9f79beSXi Wang 	case IP_MULTICAST_TTL:
5130c9f79beSXi Wang 	case IP_MULTICAST_ALL:
5140c9f79beSXi Wang 	case IP_MULTICAST_LOOP:
5150c9f79beSXi Wang 	case IP_RECVORIGDSTADDR:
5161da177e4SLinus Torvalds 		if (optlen >= sizeof(int)) {
5171da177e4SLinus Torvalds 			if (get_user(val, (int __user *) optval))
5181da177e4SLinus Torvalds 				return -EFAULT;
5191da177e4SLinus Torvalds 		} else if (optlen >= sizeof(char)) {
5201da177e4SLinus Torvalds 			unsigned char ucval;
5211da177e4SLinus Torvalds 
5221da177e4SLinus Torvalds 			if (get_user(ucval, (unsigned char __user *) optval))
5231da177e4SLinus Torvalds 				return -EFAULT;
5241da177e4SLinus Torvalds 			val = (int) ucval;
5251da177e4SLinus Torvalds 		}
5261da177e4SLinus Torvalds 	}
5271da177e4SLinus Torvalds 
5281da177e4SLinus Torvalds 	/* If optlen==0, it is equivalent to val == 0 */
5291da177e4SLinus Torvalds 
5306a9fb947SPavel Emelyanov 	if (ip_mroute_opt(optname))
5311da177e4SLinus Torvalds 		return ip_mroute_setsockopt(sk, optname, optval, optlen);
5321da177e4SLinus Torvalds 
5331da177e4SLinus Torvalds 	err = 0;
5341da177e4SLinus Torvalds 	lock_sock(sk);
5351da177e4SLinus Torvalds 
5361da177e4SLinus Torvalds 	switch (optname) {
5371da177e4SLinus Torvalds 	case IP_OPTIONS:
5381da177e4SLinus Torvalds 	{
539f6d8bd05SEric Dumazet 		struct ip_options_rcu *old, *opt = NULL;
540f6d8bd05SEric Dumazet 
54165a1c4ffSroel kluin 		if (optlen > 40)
5421da177e4SLinus Torvalds 			goto e_inval;
5433b1e0a65SYOSHIFUJI Hideaki 		err = ip_options_get_from_user(sock_net(sk), &opt,
544cb84663eSDenis V. Lunev 					       optval, optlen);
5451da177e4SLinus Torvalds 		if (err)
5461da177e4SLinus Torvalds 			break;
547f6d8bd05SEric Dumazet 		old = rcu_dereference_protected(inet->inet_opt,
548f6d8bd05SEric Dumazet 						sock_owned_by_user(sk));
549d83d8461SArnaldo Carvalho de Melo 		if (inet->is_icsk) {
550d83d8461SArnaldo Carvalho de Melo 			struct inet_connection_sock *icsk = inet_csk(sk);
551dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
5521da177e4SLinus Torvalds 			if (sk->sk_family == PF_INET ||
5531da177e4SLinus Torvalds 			    (!((1 << sk->sk_state) &
5541da177e4SLinus Torvalds 			       (TCPF_LISTEN | TCPF_CLOSE)) &&
555c720c7e8SEric Dumazet 			     inet->inet_daddr != LOOPBACK4_IPV6)) {
5561da177e4SLinus Torvalds #endif
557f6d8bd05SEric Dumazet 				if (old)
558f6d8bd05SEric Dumazet 					icsk->icsk_ext_hdr_len -= old->opt.optlen;
5591da177e4SLinus Torvalds 				if (opt)
560f6d8bd05SEric Dumazet 					icsk->icsk_ext_hdr_len += opt->opt.optlen;
561d83d8461SArnaldo Carvalho de Melo 				icsk->icsk_sync_mss(sk, icsk->icsk_pmtu_cookie);
562dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
5631da177e4SLinus Torvalds 			}
5641da177e4SLinus Torvalds #endif
5651da177e4SLinus Torvalds 		}
566f6d8bd05SEric Dumazet 		rcu_assign_pointer(inet->inet_opt, opt);
567f6d8bd05SEric Dumazet 		if (old)
568605b4afeSPaul E. McKenney 			kfree_rcu(old, rcu);
5691da177e4SLinus Torvalds 		break;
5701da177e4SLinus Torvalds 	}
5711da177e4SLinus Torvalds 	case IP_PKTINFO:
5721da177e4SLinus Torvalds 		if (val)
5731da177e4SLinus Torvalds 			inet->cmsg_flags |= IP_CMSG_PKTINFO;
5741da177e4SLinus Torvalds 		else
5751da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_PKTINFO;
5761da177e4SLinus Torvalds 		break;
5771da177e4SLinus Torvalds 	case IP_RECVTTL:
5781da177e4SLinus Torvalds 		if (val)
5791da177e4SLinus Torvalds 			inet->cmsg_flags |=  IP_CMSG_TTL;
5801da177e4SLinus Torvalds 		else
5811da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_TTL;
5821da177e4SLinus Torvalds 		break;
5831da177e4SLinus Torvalds 	case IP_RECVTOS:
5841da177e4SLinus Torvalds 		if (val)
5851da177e4SLinus Torvalds 			inet->cmsg_flags |=  IP_CMSG_TOS;
5861da177e4SLinus Torvalds 		else
5871da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_TOS;
5881da177e4SLinus Torvalds 		break;
5891da177e4SLinus Torvalds 	case IP_RECVOPTS:
5901da177e4SLinus Torvalds 		if (val)
5911da177e4SLinus Torvalds 			inet->cmsg_flags |=  IP_CMSG_RECVOPTS;
5921da177e4SLinus Torvalds 		else
5931da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_RECVOPTS;
5941da177e4SLinus Torvalds 		break;
5951da177e4SLinus Torvalds 	case IP_RETOPTS:
5961da177e4SLinus Torvalds 		if (val)
5971da177e4SLinus Torvalds 			inet->cmsg_flags |= IP_CMSG_RETOPTS;
5981da177e4SLinus Torvalds 		else
5991da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_RETOPTS;
6001da177e4SLinus Torvalds 		break;
6012c7946a7SCatherine Zhang 	case IP_PASSSEC:
6022c7946a7SCatherine Zhang 		if (val)
6032c7946a7SCatherine Zhang 			inet->cmsg_flags |= IP_CMSG_PASSSEC;
6042c7946a7SCatherine Zhang 		else
6052c7946a7SCatherine Zhang 			inet->cmsg_flags &= ~IP_CMSG_PASSSEC;
6062c7946a7SCatherine Zhang 		break;
607e8b2dfe9SBalazs Scheidler 	case IP_RECVORIGDSTADDR:
608e8b2dfe9SBalazs Scheidler 		if (val)
609e8b2dfe9SBalazs Scheidler 			inet->cmsg_flags |= IP_CMSG_ORIGDSTADDR;
610e8b2dfe9SBalazs Scheidler 		else
611e8b2dfe9SBalazs Scheidler 			inet->cmsg_flags &= ~IP_CMSG_ORIGDSTADDR;
612e8b2dfe9SBalazs Scheidler 		break;
6131da177e4SLinus Torvalds 	case IP_TOS:	/* This sets both TOS and Precedence */
6141da177e4SLinus Torvalds 		if (sk->sk_type == SOCK_STREAM) {
6152c67e9acSMaciej Żenczykowski 			val &= ~INET_ECN_MASK;
6162c67e9acSMaciej Żenczykowski 			val |= inet->tos & INET_ECN_MASK;
6171da177e4SLinus Torvalds 		}
6181da177e4SLinus Torvalds 		if (inet->tos != val) {
6191da177e4SLinus Torvalds 			inet->tos = val;
6201da177e4SLinus Torvalds 			sk->sk_priority = rt_tos2priority(val);
6211da177e4SLinus Torvalds 			sk_dst_reset(sk);
6221da177e4SLinus Torvalds 		}
6231da177e4SLinus Torvalds 		break;
6241da177e4SLinus Torvalds 	case IP_TTL:
6251da177e4SLinus Torvalds 		if (optlen < 1)
6261da177e4SLinus Torvalds 			goto e_inval;
627c9be4a5cSCong Wang 		if (val != -1 && (val < 1 || val > 255))
6281da177e4SLinus Torvalds 			goto e_inval;
6291da177e4SLinus Torvalds 		inet->uc_ttl = val;
6301da177e4SLinus Torvalds 		break;
6311da177e4SLinus Torvalds 	case IP_HDRINCL:
6321da177e4SLinus Torvalds 		if (sk->sk_type != SOCK_RAW) {
6331da177e4SLinus Torvalds 			err = -ENOPROTOOPT;
6341da177e4SLinus Torvalds 			break;
6351da177e4SLinus Torvalds 		}
6361da177e4SLinus Torvalds 		inet->hdrincl = val ? 1 : 0;
6371da177e4SLinus Torvalds 		break;
6387b2ff18eSJiri Olsa 	case IP_NODEFRAG:
6397b2ff18eSJiri Olsa 		if (sk->sk_type != SOCK_RAW) {
6407b2ff18eSJiri Olsa 			err = -ENOPROTOOPT;
6417b2ff18eSJiri Olsa 			break;
6427b2ff18eSJiri Olsa 		}
6437b2ff18eSJiri Olsa 		inet->nodefrag = val ? 1 : 0;
6447b2ff18eSJiri Olsa 		break;
6451da177e4SLinus Torvalds 	case IP_MTU_DISCOVER:
646*1b346576SHannes Frederic Sowa 		if (val < IP_PMTUDISC_DONT || val > IP_PMTUDISC_OMIT)
6471da177e4SLinus Torvalds 			goto e_inval;
6481da177e4SLinus Torvalds 		inet->pmtudisc = val;
6491da177e4SLinus Torvalds 		break;
6501da177e4SLinus Torvalds 	case IP_RECVERR:
6511da177e4SLinus Torvalds 		inet->recverr = !!val;
6521da177e4SLinus Torvalds 		if (!val)
6531da177e4SLinus Torvalds 			skb_queue_purge(&sk->sk_error_queue);
6541da177e4SLinus Torvalds 		break;
6551da177e4SLinus Torvalds 	case IP_MULTICAST_TTL:
6561da177e4SLinus Torvalds 		if (sk->sk_type == SOCK_STREAM)
6571da177e4SLinus Torvalds 			goto e_inval;
6581da177e4SLinus Torvalds 		if (optlen < 1)
6591da177e4SLinus Torvalds 			goto e_inval;
6601da177e4SLinus Torvalds 		if (val == -1)
6611da177e4SLinus Torvalds 			val = 1;
6621da177e4SLinus Torvalds 		if (val < 0 || val > 255)
6631da177e4SLinus Torvalds 			goto e_inval;
6641da177e4SLinus Torvalds 		inet->mc_ttl = val;
6651da177e4SLinus Torvalds 		break;
6661da177e4SLinus Torvalds 	case IP_MULTICAST_LOOP:
6671da177e4SLinus Torvalds 		if (optlen < 1)
6681da177e4SLinus Torvalds 			goto e_inval;
6691da177e4SLinus Torvalds 		inet->mc_loop = !!val;
6701da177e4SLinus Torvalds 		break;
67176e21053SErich E. Hoover 	case IP_UNICAST_IF:
67276e21053SErich E. Hoover 	{
67376e21053SErich E. Hoover 		struct net_device *dev = NULL;
67476e21053SErich E. Hoover 		int ifindex;
67576e21053SErich E. Hoover 
67676e21053SErich E. Hoover 		if (optlen != sizeof(int))
67776e21053SErich E. Hoover 			goto e_inval;
67876e21053SErich E. Hoover 
67976e21053SErich E. Hoover 		ifindex = (__force int)ntohl((__force __be32)val);
68076e21053SErich E. Hoover 		if (ifindex == 0) {
68176e21053SErich E. Hoover 			inet->uc_index = 0;
68276e21053SErich E. Hoover 			err = 0;
68376e21053SErich E. Hoover 			break;
68476e21053SErich E. Hoover 		}
68576e21053SErich E. Hoover 
68676e21053SErich E. Hoover 		dev = dev_get_by_index(sock_net(sk), ifindex);
68776e21053SErich E. Hoover 		err = -EADDRNOTAVAIL;
68876e21053SErich E. Hoover 		if (!dev)
68976e21053SErich E. Hoover 			break;
69076e21053SErich E. Hoover 		dev_put(dev);
69176e21053SErich E. Hoover 
69276e21053SErich E. Hoover 		err = -EINVAL;
69376e21053SErich E. Hoover 		if (sk->sk_bound_dev_if)
69476e21053SErich E. Hoover 			break;
69576e21053SErich E. Hoover 
69676e21053SErich E. Hoover 		inet->uc_index = ifindex;
69776e21053SErich E. Hoover 		err = 0;
69876e21053SErich E. Hoover 		break;
69976e21053SErich E. Hoover 	}
7001da177e4SLinus Torvalds 	case IP_MULTICAST_IF:
7011da177e4SLinus Torvalds 	{
7021da177e4SLinus Torvalds 		struct ip_mreqn mreq;
7031da177e4SLinus Torvalds 		struct net_device *dev = NULL;
7041da177e4SLinus Torvalds 
7051da177e4SLinus Torvalds 		if (sk->sk_type == SOCK_STREAM)
7061da177e4SLinus Torvalds 			goto e_inval;
7071da177e4SLinus Torvalds 		/*
7081da177e4SLinus Torvalds 		 *	Check the arguments are allowable
7091da177e4SLinus Torvalds 		 */
7101da177e4SLinus Torvalds 
7110915921bSShan Wei 		if (optlen < sizeof(struct in_addr))
7120915921bSShan Wei 			goto e_inval;
7130915921bSShan Wei 
7141da177e4SLinus Torvalds 		err = -EFAULT;
7151da177e4SLinus Torvalds 		if (optlen >= sizeof(struct ip_mreqn)) {
7161da177e4SLinus Torvalds 			if (copy_from_user(&mreq, optval, sizeof(mreq)))
7171da177e4SLinus Torvalds 				break;
7181da177e4SLinus Torvalds 		} else {
7191da177e4SLinus Torvalds 			memset(&mreq, 0, sizeof(mreq));
7203a084ddbSJiri Pirko 			if (optlen >= sizeof(struct ip_mreq)) {
7213a084ddbSJiri Pirko 				if (copy_from_user(&mreq, optval,
7223a084ddbSJiri Pirko 						   sizeof(struct ip_mreq)))
7233a084ddbSJiri Pirko 					break;
7243a084ddbSJiri Pirko 			} else if (optlen >= sizeof(struct in_addr)) {
7253a084ddbSJiri Pirko 				if (copy_from_user(&mreq.imr_address, optval,
7264d52cfbeSEric Dumazet 						   sizeof(struct in_addr)))
7271da177e4SLinus Torvalds 					break;
7281da177e4SLinus Torvalds 			}
7293a084ddbSJiri Pirko 		}
7301da177e4SLinus Torvalds 
7311da177e4SLinus Torvalds 		if (!mreq.imr_ifindex) {
732e6f1cebfSAl Viro 			if (mreq.imr_address.s_addr == htonl(INADDR_ANY)) {
7331da177e4SLinus Torvalds 				inet->mc_index = 0;
7341da177e4SLinus Torvalds 				inet->mc_addr  = 0;
7351da177e4SLinus Torvalds 				err = 0;
7361da177e4SLinus Torvalds 				break;
7371da177e4SLinus Torvalds 			}
7383b1e0a65SYOSHIFUJI Hideaki 			dev = ip_dev_find(sock_net(sk), mreq.imr_address.s_addr);
73955b80503SEric Dumazet 			if (dev)
7401da177e4SLinus Torvalds 				mreq.imr_ifindex = dev->ifindex;
7411da177e4SLinus Torvalds 		} else
74255b80503SEric Dumazet 			dev = dev_get_by_index(sock_net(sk), mreq.imr_ifindex);
7431da177e4SLinus Torvalds 
7441da177e4SLinus Torvalds 
7451da177e4SLinus Torvalds 		err = -EADDRNOTAVAIL;
7461da177e4SLinus Torvalds 		if (!dev)
7471da177e4SLinus Torvalds 			break;
74855b80503SEric Dumazet 		dev_put(dev);
7491da177e4SLinus Torvalds 
7501da177e4SLinus Torvalds 		err = -EINVAL;
7511da177e4SLinus Torvalds 		if (sk->sk_bound_dev_if &&
7521da177e4SLinus Torvalds 		    mreq.imr_ifindex != sk->sk_bound_dev_if)
7531da177e4SLinus Torvalds 			break;
7541da177e4SLinus Torvalds 
7551da177e4SLinus Torvalds 		inet->mc_index = mreq.imr_ifindex;
7561da177e4SLinus Torvalds 		inet->mc_addr  = mreq.imr_address.s_addr;
7571da177e4SLinus Torvalds 		err = 0;
7581da177e4SLinus Torvalds 		break;
7591da177e4SLinus Torvalds 	}
7601da177e4SLinus Torvalds 
7611da177e4SLinus Torvalds 	case IP_ADD_MEMBERSHIP:
7621da177e4SLinus Torvalds 	case IP_DROP_MEMBERSHIP:
7631da177e4SLinus Torvalds 	{
7641da177e4SLinus Torvalds 		struct ip_mreqn mreq;
7651da177e4SLinus Torvalds 
766a96fb49bSFlavio Leitner 		err = -EPROTO;
767a96fb49bSFlavio Leitner 		if (inet_sk(sk)->is_icsk)
768a96fb49bSFlavio Leitner 			break;
769a96fb49bSFlavio Leitner 
7701da177e4SLinus Torvalds 		if (optlen < sizeof(struct ip_mreq))
7711da177e4SLinus Torvalds 			goto e_inval;
7721da177e4SLinus Torvalds 		err = -EFAULT;
7731da177e4SLinus Torvalds 		if (optlen >= sizeof(struct ip_mreqn)) {
7741da177e4SLinus Torvalds 			if (copy_from_user(&mreq, optval, sizeof(mreq)))
7751da177e4SLinus Torvalds 				break;
7761da177e4SLinus Torvalds 		} else {
7771da177e4SLinus Torvalds 			memset(&mreq, 0, sizeof(mreq));
7781da177e4SLinus Torvalds 			if (copy_from_user(&mreq, optval, sizeof(struct ip_mreq)))
7791da177e4SLinus Torvalds 				break;
7801da177e4SLinus Torvalds 		}
7811da177e4SLinus Torvalds 
7821da177e4SLinus Torvalds 		if (optname == IP_ADD_MEMBERSHIP)
7831da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
7841da177e4SLinus Torvalds 		else
7851da177e4SLinus Torvalds 			err = ip_mc_leave_group(sk, &mreq);
7861da177e4SLinus Torvalds 		break;
7871da177e4SLinus Torvalds 	}
7881da177e4SLinus Torvalds 	case IP_MSFILTER:
7891da177e4SLinus Torvalds 	{
7901da177e4SLinus Torvalds 		struct ip_msfilter *msf;
7911da177e4SLinus Torvalds 
7921da177e4SLinus Torvalds 		if (optlen < IP_MSFILTER_SIZE(0))
7931da177e4SLinus Torvalds 			goto e_inval;
7941da177e4SLinus Torvalds 		if (optlen > sysctl_optmem_max) {
7951da177e4SLinus Torvalds 			err = -ENOBUFS;
7961da177e4SLinus Torvalds 			break;
7971da177e4SLinus Torvalds 		}
7988b3a7005SKris Katterjohn 		msf = kmalloc(optlen, GFP_KERNEL);
799cfcabdccSStephen Hemminger 		if (!msf) {
8001da177e4SLinus Torvalds 			err = -ENOBUFS;
8011da177e4SLinus Torvalds 			break;
8021da177e4SLinus Torvalds 		}
8031da177e4SLinus Torvalds 		err = -EFAULT;
8041da177e4SLinus Torvalds 		if (copy_from_user(msf, optval, optlen)) {
8051da177e4SLinus Torvalds 			kfree(msf);
8061da177e4SLinus Torvalds 			break;
8071da177e4SLinus Torvalds 		}
8081da177e4SLinus Torvalds 		/* numsrc >= (1G-4) overflow in 32 bits */
8091da177e4SLinus Torvalds 		if (msf->imsf_numsrc >= 0x3ffffffcU ||
8101da177e4SLinus Torvalds 		    msf->imsf_numsrc > sysctl_igmp_max_msf) {
8111da177e4SLinus Torvalds 			kfree(msf);
8121da177e4SLinus Torvalds 			err = -ENOBUFS;
8131da177e4SLinus Torvalds 			break;
8141da177e4SLinus Torvalds 		}
8151da177e4SLinus Torvalds 		if (IP_MSFILTER_SIZE(msf->imsf_numsrc) > optlen) {
8161da177e4SLinus Torvalds 			kfree(msf);
8171da177e4SLinus Torvalds 			err = -EINVAL;
8181da177e4SLinus Torvalds 			break;
8191da177e4SLinus Torvalds 		}
8201da177e4SLinus Torvalds 		err = ip_mc_msfilter(sk, msf, 0);
8211da177e4SLinus Torvalds 		kfree(msf);
8221da177e4SLinus Torvalds 		break;
8231da177e4SLinus Torvalds 	}
8241da177e4SLinus Torvalds 	case IP_BLOCK_SOURCE:
8251da177e4SLinus Torvalds 	case IP_UNBLOCK_SOURCE:
8261da177e4SLinus Torvalds 	case IP_ADD_SOURCE_MEMBERSHIP:
8271da177e4SLinus Torvalds 	case IP_DROP_SOURCE_MEMBERSHIP:
8281da177e4SLinus Torvalds 	{
8291da177e4SLinus Torvalds 		struct ip_mreq_source mreqs;
8301da177e4SLinus Torvalds 		int omode, add;
8311da177e4SLinus Torvalds 
8321da177e4SLinus Torvalds 		if (optlen != sizeof(struct ip_mreq_source))
8331da177e4SLinus Torvalds 			goto e_inval;
8341da177e4SLinus Torvalds 		if (copy_from_user(&mreqs, optval, sizeof(mreqs))) {
8351da177e4SLinus Torvalds 			err = -EFAULT;
8361da177e4SLinus Torvalds 			break;
8371da177e4SLinus Torvalds 		}
8381da177e4SLinus Torvalds 		if (optname == IP_BLOCK_SOURCE) {
8391da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
8401da177e4SLinus Torvalds 			add = 1;
8411da177e4SLinus Torvalds 		} else if (optname == IP_UNBLOCK_SOURCE) {
8421da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
8431da177e4SLinus Torvalds 			add = 0;
8441da177e4SLinus Torvalds 		} else if (optname == IP_ADD_SOURCE_MEMBERSHIP) {
8451da177e4SLinus Torvalds 			struct ip_mreqn mreq;
8461da177e4SLinus Torvalds 
8471da177e4SLinus Torvalds 			mreq.imr_multiaddr.s_addr = mreqs.imr_multiaddr;
8481da177e4SLinus Torvalds 			mreq.imr_address.s_addr = mreqs.imr_interface;
8491da177e4SLinus Torvalds 			mreq.imr_ifindex = 0;
8501da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
8518cdaaa15SDavid L Stevens 			if (err && err != -EADDRINUSE)
8521da177e4SLinus Torvalds 				break;
8531da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
8541da177e4SLinus Torvalds 			add = 1;
8551da177e4SLinus Torvalds 		} else /* IP_DROP_SOURCE_MEMBERSHIP */ {
8561da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
8571da177e4SLinus Torvalds 			add = 0;
8581da177e4SLinus Torvalds 		}
8591da177e4SLinus Torvalds 		err = ip_mc_source(add, omode, sk, &mreqs, 0);
8601da177e4SLinus Torvalds 		break;
8611da177e4SLinus Torvalds 	}
8621da177e4SLinus Torvalds 	case MCAST_JOIN_GROUP:
8631da177e4SLinus Torvalds 	case MCAST_LEAVE_GROUP:
8641da177e4SLinus Torvalds 	{
8651da177e4SLinus Torvalds 		struct group_req greq;
8661da177e4SLinus Torvalds 		struct sockaddr_in *psin;
8671da177e4SLinus Torvalds 		struct ip_mreqn mreq;
8681da177e4SLinus Torvalds 
8691da177e4SLinus Torvalds 		if (optlen < sizeof(struct group_req))
8701da177e4SLinus Torvalds 			goto e_inval;
8711da177e4SLinus Torvalds 		err = -EFAULT;
8721da177e4SLinus Torvalds 		if (copy_from_user(&greq, optval, sizeof(greq)))
8731da177e4SLinus Torvalds 			break;
8741da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&greq.gr_group;
8751da177e4SLinus Torvalds 		if (psin->sin_family != AF_INET)
8761da177e4SLinus Torvalds 			goto e_inval;
8771da177e4SLinus Torvalds 		memset(&mreq, 0, sizeof(mreq));
8781da177e4SLinus Torvalds 		mreq.imr_multiaddr = psin->sin_addr;
8791da177e4SLinus Torvalds 		mreq.imr_ifindex = greq.gr_interface;
8801da177e4SLinus Torvalds 
8811da177e4SLinus Torvalds 		if (optname == MCAST_JOIN_GROUP)
8821da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
8831da177e4SLinus Torvalds 		else
8841da177e4SLinus Torvalds 			err = ip_mc_leave_group(sk, &mreq);
8851da177e4SLinus Torvalds 		break;
8861da177e4SLinus Torvalds 	}
8871da177e4SLinus Torvalds 	case MCAST_JOIN_SOURCE_GROUP:
8881da177e4SLinus Torvalds 	case MCAST_LEAVE_SOURCE_GROUP:
8891da177e4SLinus Torvalds 	case MCAST_BLOCK_SOURCE:
8901da177e4SLinus Torvalds 	case MCAST_UNBLOCK_SOURCE:
8911da177e4SLinus Torvalds 	{
8921da177e4SLinus Torvalds 		struct group_source_req greqs;
8931da177e4SLinus Torvalds 		struct ip_mreq_source mreqs;
8941da177e4SLinus Torvalds 		struct sockaddr_in *psin;
8951da177e4SLinus Torvalds 		int omode, add;
8961da177e4SLinus Torvalds 
8971da177e4SLinus Torvalds 		if (optlen != sizeof(struct group_source_req))
8981da177e4SLinus Torvalds 			goto e_inval;
8991da177e4SLinus Torvalds 		if (copy_from_user(&greqs, optval, sizeof(greqs))) {
9001da177e4SLinus Torvalds 			err = -EFAULT;
9011da177e4SLinus Torvalds 			break;
9021da177e4SLinus Torvalds 		}
9031da177e4SLinus Torvalds 		if (greqs.gsr_group.ss_family != AF_INET ||
9041da177e4SLinus Torvalds 		    greqs.gsr_source.ss_family != AF_INET) {
9051da177e4SLinus Torvalds 			err = -EADDRNOTAVAIL;
9061da177e4SLinus Torvalds 			break;
9071da177e4SLinus Torvalds 		}
9081da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&greqs.gsr_group;
9091da177e4SLinus Torvalds 		mreqs.imr_multiaddr = psin->sin_addr.s_addr;
9101da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&greqs.gsr_source;
9111da177e4SLinus Torvalds 		mreqs.imr_sourceaddr = psin->sin_addr.s_addr;
9121da177e4SLinus Torvalds 		mreqs.imr_interface = 0; /* use index for mc_source */
9131da177e4SLinus Torvalds 
9141da177e4SLinus Torvalds 		if (optname == MCAST_BLOCK_SOURCE) {
9151da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
9161da177e4SLinus Torvalds 			add = 1;
9171da177e4SLinus Torvalds 		} else if (optname == MCAST_UNBLOCK_SOURCE) {
9181da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
9191da177e4SLinus Torvalds 			add = 0;
9201da177e4SLinus Torvalds 		} else if (optname == MCAST_JOIN_SOURCE_GROUP) {
9211da177e4SLinus Torvalds 			struct ip_mreqn mreq;
9221da177e4SLinus Torvalds 
9231da177e4SLinus Torvalds 			psin = (struct sockaddr_in *)&greqs.gsr_group;
9241da177e4SLinus Torvalds 			mreq.imr_multiaddr = psin->sin_addr;
9251da177e4SLinus Torvalds 			mreq.imr_address.s_addr = 0;
9261da177e4SLinus Torvalds 			mreq.imr_ifindex = greqs.gsr_interface;
9271da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
9288cdaaa15SDavid L Stevens 			if (err && err != -EADDRINUSE)
9291da177e4SLinus Torvalds 				break;
9301da177e4SLinus Torvalds 			greqs.gsr_interface = mreq.imr_ifindex;
9311da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
9321da177e4SLinus Torvalds 			add = 1;
9331da177e4SLinus Torvalds 		} else /* MCAST_LEAVE_SOURCE_GROUP */ {
9341da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
9351da177e4SLinus Torvalds 			add = 0;
9361da177e4SLinus Torvalds 		}
9371da177e4SLinus Torvalds 		err = ip_mc_source(add, omode, sk, &mreqs,
9381da177e4SLinus Torvalds 				   greqs.gsr_interface);
9391da177e4SLinus Torvalds 		break;
9401da177e4SLinus Torvalds 	}
9411da177e4SLinus Torvalds 	case MCAST_MSFILTER:
9421da177e4SLinus Torvalds 	{
9431da177e4SLinus Torvalds 		struct sockaddr_in *psin;
9441da177e4SLinus Torvalds 		struct ip_msfilter *msf = NULL;
9451da177e4SLinus Torvalds 		struct group_filter *gsf = NULL;
9461da177e4SLinus Torvalds 		int msize, i, ifindex;
9471da177e4SLinus Torvalds 
9481da177e4SLinus Torvalds 		if (optlen < GROUP_FILTER_SIZE(0))
9491da177e4SLinus Torvalds 			goto e_inval;
9501da177e4SLinus Torvalds 		if (optlen > sysctl_optmem_max) {
9511da177e4SLinus Torvalds 			err = -ENOBUFS;
9521da177e4SLinus Torvalds 			break;
9531da177e4SLinus Torvalds 		}
9548b3a7005SKris Katterjohn 		gsf = kmalloc(optlen, GFP_KERNEL);
955cfcabdccSStephen Hemminger 		if (!gsf) {
9561da177e4SLinus Torvalds 			err = -ENOBUFS;
9571da177e4SLinus Torvalds 			break;
9581da177e4SLinus Torvalds 		}
9591da177e4SLinus Torvalds 		err = -EFAULT;
9604d52cfbeSEric Dumazet 		if (copy_from_user(gsf, optval, optlen))
9611da177e4SLinus Torvalds 			goto mc_msf_out;
9624d52cfbeSEric Dumazet 
9631da177e4SLinus Torvalds 		/* numsrc >= (4G-140)/128 overflow in 32 bits */
9641da177e4SLinus Torvalds 		if (gsf->gf_numsrc >= 0x1ffffff ||
9651da177e4SLinus Torvalds 		    gsf->gf_numsrc > sysctl_igmp_max_msf) {
9661da177e4SLinus Torvalds 			err = -ENOBUFS;
9671da177e4SLinus Torvalds 			goto mc_msf_out;
9681da177e4SLinus Torvalds 		}
9691da177e4SLinus Torvalds 		if (GROUP_FILTER_SIZE(gsf->gf_numsrc) > optlen) {
9701da177e4SLinus Torvalds 			err = -EINVAL;
9711da177e4SLinus Torvalds 			goto mc_msf_out;
9721da177e4SLinus Torvalds 		}
9731da177e4SLinus Torvalds 		msize = IP_MSFILTER_SIZE(gsf->gf_numsrc);
9748b3a7005SKris Katterjohn 		msf = kmalloc(msize, GFP_KERNEL);
975cfcabdccSStephen Hemminger 		if (!msf) {
9761da177e4SLinus Torvalds 			err = -ENOBUFS;
9771da177e4SLinus Torvalds 			goto mc_msf_out;
9781da177e4SLinus Torvalds 		}
9791da177e4SLinus Torvalds 		ifindex = gsf->gf_interface;
9801da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&gsf->gf_group;
9811da177e4SLinus Torvalds 		if (psin->sin_family != AF_INET) {
9821da177e4SLinus Torvalds 			err = -EADDRNOTAVAIL;
9831da177e4SLinus Torvalds 			goto mc_msf_out;
9841da177e4SLinus Torvalds 		}
9851da177e4SLinus Torvalds 		msf->imsf_multiaddr = psin->sin_addr.s_addr;
9861da177e4SLinus Torvalds 		msf->imsf_interface = 0;
9871da177e4SLinus Torvalds 		msf->imsf_fmode = gsf->gf_fmode;
9881da177e4SLinus Torvalds 		msf->imsf_numsrc = gsf->gf_numsrc;
9891da177e4SLinus Torvalds 		err = -EADDRNOTAVAIL;
9901da177e4SLinus Torvalds 		for (i = 0; i < gsf->gf_numsrc; ++i) {
9911da177e4SLinus Torvalds 			psin = (struct sockaddr_in *)&gsf->gf_slist[i];
9921da177e4SLinus Torvalds 
9931da177e4SLinus Torvalds 			if (psin->sin_family != AF_INET)
9941da177e4SLinus Torvalds 				goto mc_msf_out;
9951da177e4SLinus Torvalds 			msf->imsf_slist[i] = psin->sin_addr.s_addr;
9961da177e4SLinus Torvalds 		}
9971da177e4SLinus Torvalds 		kfree(gsf);
9981da177e4SLinus Torvalds 		gsf = NULL;
9991da177e4SLinus Torvalds 
10001da177e4SLinus Torvalds 		err = ip_mc_msfilter(sk, msf, ifindex);
10011da177e4SLinus Torvalds mc_msf_out:
10021da177e4SLinus Torvalds 		kfree(msf);
10031da177e4SLinus Torvalds 		kfree(gsf);
10041da177e4SLinus Torvalds 		break;
10051da177e4SLinus Torvalds 	}
1006f771bef9SNivedita Singhvi 	case IP_MULTICAST_ALL:
1007f771bef9SNivedita Singhvi 		if (optlen < 1)
1008f771bef9SNivedita Singhvi 			goto e_inval;
1009f771bef9SNivedita Singhvi 		if (val != 0 && val != 1)
1010f771bef9SNivedita Singhvi 			goto e_inval;
1011f771bef9SNivedita Singhvi 		inet->mc_all = val;
1012f771bef9SNivedita Singhvi 		break;
10131da177e4SLinus Torvalds 	case IP_ROUTER_ALERT:
10141da177e4SLinus Torvalds 		err = ip_ra_control(sk, val ? 1 : 0, NULL);
10151da177e4SLinus Torvalds 		break;
10161da177e4SLinus Torvalds 
10171da177e4SLinus Torvalds 	case IP_FREEBIND:
10181da177e4SLinus Torvalds 		if (optlen < 1)
10191da177e4SLinus Torvalds 			goto e_inval;
10201da177e4SLinus Torvalds 		inet->freebind = !!val;
10211da177e4SLinus Torvalds 		break;
10221da177e4SLinus Torvalds 
10231da177e4SLinus Torvalds 	case IP_IPSEC_POLICY:
10241da177e4SLinus Torvalds 	case IP_XFRM_POLICY:
10256fc0b4a7SHerbert Xu 		err = -EPERM;
102652e804c6SEric W. Biederman 		if (!ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN))
10276fc0b4a7SHerbert Xu 			break;
10281da177e4SLinus Torvalds 		err = xfrm_user_policy(sk, optname, optval, optlen);
10291da177e4SLinus Torvalds 		break;
10301da177e4SLinus Torvalds 
1031f5715aeaSKOVACS Krisztian 	case IP_TRANSPARENT:
103252e804c6SEric W. Biederman 		if (!!val && !ns_capable(sock_net(sk)->user_ns, CAP_NET_RAW) &&
103352e804c6SEric W. Biederman 		    !ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN)) {
1034f5715aeaSKOVACS Krisztian 			err = -EPERM;
1035f5715aeaSKOVACS Krisztian 			break;
1036f5715aeaSKOVACS Krisztian 		}
1037f5715aeaSKOVACS Krisztian 		if (optlen < 1)
1038f5715aeaSKOVACS Krisztian 			goto e_inval;
1039f5715aeaSKOVACS Krisztian 		inet->transparent = !!val;
1040f5715aeaSKOVACS Krisztian 		break;
1041f5715aeaSKOVACS Krisztian 
1042d218d111SStephen Hemminger 	case IP_MINTTL:
1043d218d111SStephen Hemminger 		if (optlen < 1)
1044d218d111SStephen Hemminger 			goto e_inval;
1045d218d111SStephen Hemminger 		if (val < 0 || val > 255)
1046d218d111SStephen Hemminger 			goto e_inval;
1047d218d111SStephen Hemminger 		inet->min_ttl = val;
1048d218d111SStephen Hemminger 		break;
1049d218d111SStephen Hemminger 
10501da177e4SLinus Torvalds 	default:
10511da177e4SLinus Torvalds 		err = -ENOPROTOOPT;
10521da177e4SLinus Torvalds 		break;
10531da177e4SLinus Torvalds 	}
10541da177e4SLinus Torvalds 	release_sock(sk);
10551da177e4SLinus Torvalds 	return err;
10561da177e4SLinus Torvalds 
10571da177e4SLinus Torvalds e_inval:
10581da177e4SLinus Torvalds 	release_sock(sk);
10591da177e4SLinus Torvalds 	return -EINVAL;
10601da177e4SLinus Torvalds }
10611da177e4SLinus Torvalds 
1062f84af32cSEric Dumazet /**
1063d826eb14SEric Dumazet  * ipv4_pktinfo_prepare - transfert some info from rtable to skb
1064f84af32cSEric Dumazet  * @sk: socket
1065f84af32cSEric Dumazet  * @skb: buffer
1066f84af32cSEric Dumazet  *
106735ebf65eSDavid S. Miller  * To support IP_CMSG_PKTINFO option, we store rt_iif and specific
106835ebf65eSDavid S. Miller  * destination in skb->cb[] before dst drop.
10698e3bff96Sstephen hemminger  * This way, receiver doesn't make cache line misses to read rtable.
1070f84af32cSEric Dumazet  */
1071fbf8866dSShawn Bohrer void ipv4_pktinfo_prepare(const struct sock *sk, struct sk_buff *skb)
1072f84af32cSEric Dumazet {
1073d826eb14SEric Dumazet 	struct in_pktinfo *pktinfo = PKTINFO_SKB_CB(skb);
10744b261c75SHannes Frederic Sowa 	bool prepare = (inet_sk(sk)->cmsg_flags & IP_CMSG_PKTINFO) ||
10754b261c75SHannes Frederic Sowa 		       ipv6_sk_rxinfo(sk);
1076d826eb14SEric Dumazet 
10774b261c75SHannes Frederic Sowa 	if (prepare && skb_rtable(skb)) {
107892101b3bSDavid S. Miller 		pktinfo->ipi_ifindex = inet_iif(skb);
107935ebf65eSDavid S. Miller 		pktinfo->ipi_spec_dst.s_addr = fib_compute_spec_dst(skb);
1080d826eb14SEric Dumazet 	} else {
1081d826eb14SEric Dumazet 		pktinfo->ipi_ifindex = 0;
1082d826eb14SEric Dumazet 		pktinfo->ipi_spec_dst.s_addr = 0;
1083f84af32cSEric Dumazet 	}
1084d826eb14SEric Dumazet 	skb_dst_drop(skb);
1085d826eb14SEric Dumazet }
1086f84af32cSEric Dumazet 
10873fdadf7dSDmitry Mishin int ip_setsockopt(struct sock *sk, int level,
1088b7058842SDavid S. Miller 		int optname, char __user *optval, unsigned int optlen)
10893fdadf7dSDmitry Mishin {
10903fdadf7dSDmitry Mishin 	int err;
10913fdadf7dSDmitry Mishin 
10923fdadf7dSDmitry Mishin 	if (level != SOL_IP)
10933fdadf7dSDmitry Mishin 		return -ENOPROTOOPT;
10943fdadf7dSDmitry Mishin 
10953fdadf7dSDmitry Mishin 	err = do_ip_setsockopt(sk, level, optname, optval, optlen);
10963fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
10973fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
10983fdadf7dSDmitry Mishin 	if (err == -ENOPROTOOPT && optname != IP_HDRINCL &&
10996a9fb947SPavel Emelyanov 			optname != IP_IPSEC_POLICY &&
11006a9fb947SPavel Emelyanov 			optname != IP_XFRM_POLICY &&
11016a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
11023fdadf7dSDmitry Mishin 		lock_sock(sk);
11033fdadf7dSDmitry Mishin 		err = nf_setsockopt(sk, PF_INET, optname, optval, optlen);
11043fdadf7dSDmitry Mishin 		release_sock(sk);
11053fdadf7dSDmitry Mishin 	}
11063fdadf7dSDmitry Mishin #endif
11073fdadf7dSDmitry Mishin 	return err;
11083fdadf7dSDmitry Mishin }
11094d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_setsockopt);
11103fdadf7dSDmitry Mishin 
11113fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT
1112543d9cfeSArnaldo Carvalho de Melo int compat_ip_setsockopt(struct sock *sk, int level, int optname,
1113b7058842SDavid S. Miller 			 char __user *optval, unsigned int optlen)
11143fdadf7dSDmitry Mishin {
11153fdadf7dSDmitry Mishin 	int err;
11163fdadf7dSDmitry Mishin 
11173fdadf7dSDmitry Mishin 	if (level != SOL_IP)
11183fdadf7dSDmitry Mishin 		return -ENOPROTOOPT;
11193fdadf7dSDmitry Mishin 
1120dae50295SDavid L Stevens 	if (optname >= MCAST_JOIN_GROUP && optname <= MCAST_MSFILTER)
1121dae50295SDavid L Stevens 		return compat_mc_setsockopt(sk, level, optname, optval, optlen,
1122dae50295SDavid L Stevens 			ip_setsockopt);
1123dae50295SDavid L Stevens 
11243fdadf7dSDmitry Mishin 	err = do_ip_setsockopt(sk, level, optname, optval, optlen);
11253fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
11263fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
11273fdadf7dSDmitry Mishin 	if (err == -ENOPROTOOPT && optname != IP_HDRINCL &&
11286a9fb947SPavel Emelyanov 			optname != IP_IPSEC_POLICY &&
11296a9fb947SPavel Emelyanov 			optname != IP_XFRM_POLICY &&
11306a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
11313fdadf7dSDmitry Mishin 		lock_sock(sk);
1132543d9cfeSArnaldo Carvalho de Melo 		err = compat_nf_setsockopt(sk, PF_INET, optname,
1133543d9cfeSArnaldo Carvalho de Melo 					   optval, optlen);
11343fdadf7dSDmitry Mishin 		release_sock(sk);
11353fdadf7dSDmitry Mishin 	}
11363fdadf7dSDmitry Mishin #endif
11373fdadf7dSDmitry Mishin 	return err;
11383fdadf7dSDmitry Mishin }
1139543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_setsockopt);
11403fdadf7dSDmitry Mishin #endif
11413fdadf7dSDmitry Mishin 
11421da177e4SLinus Torvalds /*
11434d52cfbeSEric Dumazet  *	Get the options. Note for future reference. The GET of IP options gets
11444d52cfbeSEric Dumazet  *	the _received_ ones. The set sets the _sent_ ones.
11451da177e4SLinus Torvalds  */
11461da177e4SLinus Torvalds 
11473fdadf7dSDmitry Mishin static int do_ip_getsockopt(struct sock *sk, int level, int optname,
114895c96174SEric Dumazet 			    char __user *optval, int __user *optlen, unsigned int flags)
11491da177e4SLinus Torvalds {
11501da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(sk);
11511da177e4SLinus Torvalds 	int val;
11521da177e4SLinus Torvalds 	int len;
11531da177e4SLinus Torvalds 
11541da177e4SLinus Torvalds 	if (level != SOL_IP)
11551da177e4SLinus Torvalds 		return -EOPNOTSUPP;
11561da177e4SLinus Torvalds 
11576a9fb947SPavel Emelyanov 	if (ip_mroute_opt(optname))
11581da177e4SLinus Torvalds 		return ip_mroute_getsockopt(sk, optname, optval, optlen);
11591da177e4SLinus Torvalds 
11601da177e4SLinus Torvalds 	if (get_user(len, optlen))
11611da177e4SLinus Torvalds 		return -EFAULT;
11621da177e4SLinus Torvalds 	if (len < 0)
11631da177e4SLinus Torvalds 		return -EINVAL;
11641da177e4SLinus Torvalds 
11651da177e4SLinus Torvalds 	lock_sock(sk);
11661da177e4SLinus Torvalds 
11671da177e4SLinus Torvalds 	switch (optname) {
11681da177e4SLinus Torvalds 	case IP_OPTIONS:
11691da177e4SLinus Torvalds 	{
11701da177e4SLinus Torvalds 		unsigned char optbuf[sizeof(struct ip_options)+40];
11711da177e4SLinus Torvalds 		struct ip_options *opt = (struct ip_options *)optbuf;
1172f6d8bd05SEric Dumazet 		struct ip_options_rcu *inet_opt;
1173f6d8bd05SEric Dumazet 
1174f6d8bd05SEric Dumazet 		inet_opt = rcu_dereference_protected(inet->inet_opt,
1175f6d8bd05SEric Dumazet 						     sock_owned_by_user(sk));
11761da177e4SLinus Torvalds 		opt->optlen = 0;
1177f6d8bd05SEric Dumazet 		if (inet_opt)
1178f6d8bd05SEric Dumazet 			memcpy(optbuf, &inet_opt->opt,
11791da177e4SLinus Torvalds 			       sizeof(struct ip_options) +
1180f6d8bd05SEric Dumazet 			       inet_opt->opt.optlen);
11811da177e4SLinus Torvalds 		release_sock(sk);
11821da177e4SLinus Torvalds 
11831da177e4SLinus Torvalds 		if (opt->optlen == 0)
11841da177e4SLinus Torvalds 			return put_user(0, optlen);
11851da177e4SLinus Torvalds 
11861da177e4SLinus Torvalds 		ip_options_undo(opt);
11871da177e4SLinus Torvalds 
11881da177e4SLinus Torvalds 		len = min_t(unsigned int, len, opt->optlen);
11891da177e4SLinus Torvalds 		if (put_user(len, optlen))
11901da177e4SLinus Torvalds 			return -EFAULT;
11911da177e4SLinus Torvalds 		if (copy_to_user(optval, opt->__data, len))
11921da177e4SLinus Torvalds 			return -EFAULT;
11931da177e4SLinus Torvalds 		return 0;
11941da177e4SLinus Torvalds 	}
11951da177e4SLinus Torvalds 	case IP_PKTINFO:
11961da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_PKTINFO) != 0;
11971da177e4SLinus Torvalds 		break;
11981da177e4SLinus Torvalds 	case IP_RECVTTL:
11991da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_TTL) != 0;
12001da177e4SLinus Torvalds 		break;
12011da177e4SLinus Torvalds 	case IP_RECVTOS:
12021da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_TOS) != 0;
12031da177e4SLinus Torvalds 		break;
12041da177e4SLinus Torvalds 	case IP_RECVOPTS:
12051da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_RECVOPTS) != 0;
12061da177e4SLinus Torvalds 		break;
12071da177e4SLinus Torvalds 	case IP_RETOPTS:
12081da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_RETOPTS) != 0;
12091da177e4SLinus Torvalds 		break;
12102c7946a7SCatherine Zhang 	case IP_PASSSEC:
12112c7946a7SCatherine Zhang 		val = (inet->cmsg_flags & IP_CMSG_PASSSEC) != 0;
12122c7946a7SCatherine Zhang 		break;
1213e8b2dfe9SBalazs Scheidler 	case IP_RECVORIGDSTADDR:
1214e8b2dfe9SBalazs Scheidler 		val = (inet->cmsg_flags & IP_CMSG_ORIGDSTADDR) != 0;
1215e8b2dfe9SBalazs Scheidler 		break;
12161da177e4SLinus Torvalds 	case IP_TOS:
12171da177e4SLinus Torvalds 		val = inet->tos;
12181da177e4SLinus Torvalds 		break;
12191da177e4SLinus Torvalds 	case IP_TTL:
12201da177e4SLinus Torvalds 		val = (inet->uc_ttl == -1 ?
12211da177e4SLinus Torvalds 		       sysctl_ip_default_ttl :
12221da177e4SLinus Torvalds 		       inet->uc_ttl);
12231da177e4SLinus Torvalds 		break;
12241da177e4SLinus Torvalds 	case IP_HDRINCL:
12251da177e4SLinus Torvalds 		val = inet->hdrincl;
12261da177e4SLinus Torvalds 		break;
1227a89b4763SMichael Kerrisk 	case IP_NODEFRAG:
1228a89b4763SMichael Kerrisk 		val = inet->nodefrag;
1229a89b4763SMichael Kerrisk 		break;
12301da177e4SLinus Torvalds 	case IP_MTU_DISCOVER:
12311da177e4SLinus Torvalds 		val = inet->pmtudisc;
12321da177e4SLinus Torvalds 		break;
12331da177e4SLinus Torvalds 	case IP_MTU:
12341da177e4SLinus Torvalds 	{
12351da177e4SLinus Torvalds 		struct dst_entry *dst;
12361da177e4SLinus Torvalds 		val = 0;
12371da177e4SLinus Torvalds 		dst = sk_dst_get(sk);
12381da177e4SLinus Torvalds 		if (dst) {
12391da177e4SLinus Torvalds 			val = dst_mtu(dst);
12401da177e4SLinus Torvalds 			dst_release(dst);
12411da177e4SLinus Torvalds 		}
12421da177e4SLinus Torvalds 		if (!val) {
12431da177e4SLinus Torvalds 			release_sock(sk);
12441da177e4SLinus Torvalds 			return -ENOTCONN;
12451da177e4SLinus Torvalds 		}
12461da177e4SLinus Torvalds 		break;
12471da177e4SLinus Torvalds 	}
12481da177e4SLinus Torvalds 	case IP_RECVERR:
12491da177e4SLinus Torvalds 		val = inet->recverr;
12501da177e4SLinus Torvalds 		break;
12511da177e4SLinus Torvalds 	case IP_MULTICAST_TTL:
12521da177e4SLinus Torvalds 		val = inet->mc_ttl;
12531da177e4SLinus Torvalds 		break;
12541da177e4SLinus Torvalds 	case IP_MULTICAST_LOOP:
12551da177e4SLinus Torvalds 		val = inet->mc_loop;
12561da177e4SLinus Torvalds 		break;
125776e21053SErich E. Hoover 	case IP_UNICAST_IF:
125876e21053SErich E. Hoover 		val = (__force int)htonl((__u32) inet->uc_index);
125976e21053SErich E. Hoover 		break;
12601da177e4SLinus Torvalds 	case IP_MULTICAST_IF:
12611da177e4SLinus Torvalds 	{
12621da177e4SLinus Torvalds 		struct in_addr addr;
12631da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(struct in_addr));
12641da177e4SLinus Torvalds 		addr.s_addr = inet->mc_addr;
12651da177e4SLinus Torvalds 		release_sock(sk);
12661da177e4SLinus Torvalds 
12671da177e4SLinus Torvalds 		if (put_user(len, optlen))
12681da177e4SLinus Torvalds 			return -EFAULT;
12691da177e4SLinus Torvalds 		if (copy_to_user(optval, &addr, len))
12701da177e4SLinus Torvalds 			return -EFAULT;
12711da177e4SLinus Torvalds 		return 0;
12721da177e4SLinus Torvalds 	}
12731da177e4SLinus Torvalds 	case IP_MSFILTER:
12741da177e4SLinus Torvalds 	{
12751da177e4SLinus Torvalds 		struct ip_msfilter msf;
12761da177e4SLinus Torvalds 		int err;
12771da177e4SLinus Torvalds 
12781da177e4SLinus Torvalds 		if (len < IP_MSFILTER_SIZE(0)) {
12791da177e4SLinus Torvalds 			release_sock(sk);
12801da177e4SLinus Torvalds 			return -EINVAL;
12811da177e4SLinus Torvalds 		}
12821da177e4SLinus Torvalds 		if (copy_from_user(&msf, optval, IP_MSFILTER_SIZE(0))) {
12831da177e4SLinus Torvalds 			release_sock(sk);
12841da177e4SLinus Torvalds 			return -EFAULT;
12851da177e4SLinus Torvalds 		}
12861da177e4SLinus Torvalds 		err = ip_mc_msfget(sk, &msf,
12871da177e4SLinus Torvalds 				   (struct ip_msfilter __user *)optval, optlen);
12881da177e4SLinus Torvalds 		release_sock(sk);
12891da177e4SLinus Torvalds 		return err;
12901da177e4SLinus Torvalds 	}
12911da177e4SLinus Torvalds 	case MCAST_MSFILTER:
12921da177e4SLinus Torvalds 	{
12931da177e4SLinus Torvalds 		struct group_filter gsf;
12941da177e4SLinus Torvalds 		int err;
12951da177e4SLinus Torvalds 
12961da177e4SLinus Torvalds 		if (len < GROUP_FILTER_SIZE(0)) {
12971da177e4SLinus Torvalds 			release_sock(sk);
12981da177e4SLinus Torvalds 			return -EINVAL;
12991da177e4SLinus Torvalds 		}
13001da177e4SLinus Torvalds 		if (copy_from_user(&gsf, optval, GROUP_FILTER_SIZE(0))) {
13011da177e4SLinus Torvalds 			release_sock(sk);
13021da177e4SLinus Torvalds 			return -EFAULT;
13031da177e4SLinus Torvalds 		}
13041da177e4SLinus Torvalds 		err = ip_mc_gsfget(sk, &gsf,
13054d52cfbeSEric Dumazet 				   (struct group_filter __user *)optval,
13064d52cfbeSEric Dumazet 				   optlen);
13071da177e4SLinus Torvalds 		release_sock(sk);
13081da177e4SLinus Torvalds 		return err;
13091da177e4SLinus Torvalds 	}
1310f771bef9SNivedita Singhvi 	case IP_MULTICAST_ALL:
1311f771bef9SNivedita Singhvi 		val = inet->mc_all;
1312f771bef9SNivedita Singhvi 		break;
13131da177e4SLinus Torvalds 	case IP_PKTOPTIONS:
13141da177e4SLinus Torvalds 	{
13151da177e4SLinus Torvalds 		struct msghdr msg;
13161da177e4SLinus Torvalds 
13171da177e4SLinus Torvalds 		release_sock(sk);
13181da177e4SLinus Torvalds 
13191da177e4SLinus Torvalds 		if (sk->sk_type != SOCK_STREAM)
13201da177e4SLinus Torvalds 			return -ENOPROTOOPT;
13211da177e4SLinus Torvalds 
13221da177e4SLinus Torvalds 		msg.msg_control = optval;
13231da177e4SLinus Torvalds 		msg.msg_controllen = len;
1324dd23198eSDaniel Baluta 		msg.msg_flags = flags;
13251da177e4SLinus Torvalds 
13261da177e4SLinus Torvalds 		if (inet->cmsg_flags & IP_CMSG_PKTINFO) {
13271da177e4SLinus Torvalds 			struct in_pktinfo info;
13281da177e4SLinus Torvalds 
1329c720c7e8SEric Dumazet 			info.ipi_addr.s_addr = inet->inet_rcv_saddr;
1330c720c7e8SEric Dumazet 			info.ipi_spec_dst.s_addr = inet->inet_rcv_saddr;
13311da177e4SLinus Torvalds 			info.ipi_ifindex = inet->mc_index;
13321da177e4SLinus Torvalds 			put_cmsg(&msg, SOL_IP, IP_PKTINFO, sizeof(info), &info);
13331da177e4SLinus Torvalds 		}
13341da177e4SLinus Torvalds 		if (inet->cmsg_flags & IP_CMSG_TTL) {
13351da177e4SLinus Torvalds 			int hlim = inet->mc_ttl;
13361da177e4SLinus Torvalds 			put_cmsg(&msg, SOL_IP, IP_TTL, sizeof(hlim), &hlim);
13371da177e4SLinus Torvalds 		}
13384c507d28SJiri Benc 		if (inet->cmsg_flags & IP_CMSG_TOS) {
13394c507d28SJiri Benc 			int tos = inet->rcv_tos;
13404c507d28SJiri Benc 			put_cmsg(&msg, SOL_IP, IP_TOS, sizeof(tos), &tos);
13414c507d28SJiri Benc 		}
13421da177e4SLinus Torvalds 		len -= msg.msg_controllen;
13431da177e4SLinus Torvalds 		return put_user(len, optlen);
13441da177e4SLinus Torvalds 	}
13451da177e4SLinus Torvalds 	case IP_FREEBIND:
13461da177e4SLinus Torvalds 		val = inet->freebind;
13471da177e4SLinus Torvalds 		break;
1348f5715aeaSKOVACS Krisztian 	case IP_TRANSPARENT:
1349f5715aeaSKOVACS Krisztian 		val = inet->transparent;
1350f5715aeaSKOVACS Krisztian 		break;
1351d218d111SStephen Hemminger 	case IP_MINTTL:
1352d218d111SStephen Hemminger 		val = inet->min_ttl;
1353d218d111SStephen Hemminger 		break;
13541da177e4SLinus Torvalds 	default:
13551da177e4SLinus Torvalds 		release_sock(sk);
13561da177e4SLinus Torvalds 		return -ENOPROTOOPT;
13571da177e4SLinus Torvalds 	}
13581da177e4SLinus Torvalds 	release_sock(sk);
13591da177e4SLinus Torvalds 
1360951e07c9SDavid S. Miller 	if (len < sizeof(int) && len > 0 && val >= 0 && val <= 255) {
13611da177e4SLinus Torvalds 		unsigned char ucval = (unsigned char)val;
13621da177e4SLinus Torvalds 		len = 1;
13631da177e4SLinus Torvalds 		if (put_user(len, optlen))
13641da177e4SLinus Torvalds 			return -EFAULT;
13651da177e4SLinus Torvalds 		if (copy_to_user(optval, &ucval, 1))
13661da177e4SLinus Torvalds 			return -EFAULT;
13671da177e4SLinus Torvalds 	} else {
13681da177e4SLinus Torvalds 		len = min_t(unsigned int, sizeof(int), len);
13691da177e4SLinus Torvalds 		if (put_user(len, optlen))
13701da177e4SLinus Torvalds 			return -EFAULT;
13711da177e4SLinus Torvalds 		if (copy_to_user(optval, &val, len))
13721da177e4SLinus Torvalds 			return -EFAULT;
13731da177e4SLinus Torvalds 	}
13741da177e4SLinus Torvalds 	return 0;
13751da177e4SLinus Torvalds }
13761da177e4SLinus Torvalds 
13773fdadf7dSDmitry Mishin int ip_getsockopt(struct sock *sk, int level,
13783fdadf7dSDmitry Mishin 		  int optname, char __user *optval, int __user *optlen)
13793fdadf7dSDmitry Mishin {
13803fdadf7dSDmitry Mishin 	int err;
13813fdadf7dSDmitry Mishin 
1382dd23198eSDaniel Baluta 	err = do_ip_getsockopt(sk, level, optname, optval, optlen, 0);
13833fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
13843fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
13856a9fb947SPavel Emelyanov 	if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS &&
13866a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
13873fdadf7dSDmitry Mishin 		int len;
13883fdadf7dSDmitry Mishin 
13893fdadf7dSDmitry Mishin 		if (get_user(len, optlen))
13903fdadf7dSDmitry Mishin 			return -EFAULT;
13913fdadf7dSDmitry Mishin 
13923fdadf7dSDmitry Mishin 		lock_sock(sk);
13933fdadf7dSDmitry Mishin 		err = nf_getsockopt(sk, PF_INET, optname, optval,
13943fdadf7dSDmitry Mishin 				&len);
13953fdadf7dSDmitry Mishin 		release_sock(sk);
13963fdadf7dSDmitry Mishin 		if (err >= 0)
13973fdadf7dSDmitry Mishin 			err = put_user(len, optlen);
13983fdadf7dSDmitry Mishin 		return err;
13993fdadf7dSDmitry Mishin 	}
14003fdadf7dSDmitry Mishin #endif
14013fdadf7dSDmitry Mishin 	return err;
14023fdadf7dSDmitry Mishin }
14034d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_getsockopt);
14043fdadf7dSDmitry Mishin 
14053fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT
1406543d9cfeSArnaldo Carvalho de Melo int compat_ip_getsockopt(struct sock *sk, int level, int optname,
1407543d9cfeSArnaldo Carvalho de Melo 			 char __user *optval, int __user *optlen)
14083fdadf7dSDmitry Mishin {
140942908c69SDavid L Stevens 	int err;
141042908c69SDavid L Stevens 
141142908c69SDavid L Stevens 	if (optname == MCAST_MSFILTER)
141242908c69SDavid L Stevens 		return compat_mc_getsockopt(sk, level, optname, optval, optlen,
141342908c69SDavid L Stevens 			ip_getsockopt);
141442908c69SDavid L Stevens 
1415dd23198eSDaniel Baluta 	err = do_ip_getsockopt(sk, level, optname, optval, optlen,
1416dd23198eSDaniel Baluta 		MSG_CMSG_COMPAT);
141742908c69SDavid L Stevens 
14183fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
14193fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
14206a9fb947SPavel Emelyanov 	if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS &&
14216a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
14223fdadf7dSDmitry Mishin 		int len;
14233fdadf7dSDmitry Mishin 
14243fdadf7dSDmitry Mishin 		if (get_user(len, optlen))
14253fdadf7dSDmitry Mishin 			return -EFAULT;
14263fdadf7dSDmitry Mishin 
14273fdadf7dSDmitry Mishin 		lock_sock(sk);
1428543d9cfeSArnaldo Carvalho de Melo 		err = compat_nf_getsockopt(sk, PF_INET, optname, optval, &len);
14293fdadf7dSDmitry Mishin 		release_sock(sk);
14303fdadf7dSDmitry Mishin 		if (err >= 0)
14313fdadf7dSDmitry Mishin 			err = put_user(len, optlen);
14323fdadf7dSDmitry Mishin 		return err;
14333fdadf7dSDmitry Mishin 	}
14343fdadf7dSDmitry Mishin #endif
14353fdadf7dSDmitry Mishin 	return err;
14363fdadf7dSDmitry Mishin }
1437543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_getsockopt);
14383fdadf7dSDmitry Mishin #endif
1439