11da177e4SLinus Torvalds /* 21da177e4SLinus Torvalds * INET An implementation of the TCP/IP protocol suite for the LINUX 31da177e4SLinus Torvalds * operating system. INET is implemented using the BSD Socket 41da177e4SLinus Torvalds * interface as the means of communication with the user level. 51da177e4SLinus Torvalds * 61da177e4SLinus Torvalds * The IP to API glue. 71da177e4SLinus Torvalds * 81da177e4SLinus Torvalds * Authors: see ip.c 91da177e4SLinus Torvalds * 101da177e4SLinus Torvalds * Fixes: 111da177e4SLinus Torvalds * Many : Split from ip.c , see ip.c for history. 121da177e4SLinus Torvalds * Martin Mares : TOS setting fixed. 131da177e4SLinus Torvalds * Alan Cox : Fixed a couple of oopses in Martin's 141da177e4SLinus Torvalds * TOS tweaks. 151da177e4SLinus Torvalds * Mike McLagan : Routing by source 161da177e4SLinus Torvalds */ 171da177e4SLinus Torvalds 181da177e4SLinus Torvalds #include <linux/module.h> 191da177e4SLinus Torvalds #include <linux/types.h> 201da177e4SLinus Torvalds #include <linux/mm.h> 211da177e4SLinus Torvalds #include <linux/skbuff.h> 221da177e4SLinus Torvalds #include <linux/ip.h> 231da177e4SLinus Torvalds #include <linux/icmp.h> 2414c85021SArnaldo Carvalho de Melo #include <linux/inetdevice.h> 251da177e4SLinus Torvalds #include <linux/netdevice.h> 265a0e3ad6STejun Heo #include <linux/slab.h> 271da177e4SLinus Torvalds #include <net/sock.h> 281da177e4SLinus Torvalds #include <net/ip.h> 291da177e4SLinus Torvalds #include <net/icmp.h> 30d83d8461SArnaldo Carvalho de Melo #include <net/tcp_states.h> 311da177e4SLinus Torvalds #include <linux/udp.h> 321da177e4SLinus Torvalds #include <linux/igmp.h> 331da177e4SLinus Torvalds #include <linux/netfilter.h> 341da177e4SLinus Torvalds #include <linux/route.h> 351da177e4SLinus Torvalds #include <linux/mroute.h> 362c67e9acSMaciej Żenczykowski #include <net/inet_ecn.h> 371da177e4SLinus Torvalds #include <net/route.h> 381da177e4SLinus Torvalds #include <net/xfrm.h> 39dae50295SDavid L Stevens #include <net/compat.h> 40dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6) 411da177e4SLinus Torvalds #include <net/transp_v6.h> 421da177e4SLinus Torvalds #endif 4335ebf65eSDavid S. Miller #include <net/ip_fib.h> 441da177e4SLinus Torvalds 451da177e4SLinus Torvalds #include <linux/errqueue.h> 461da177e4SLinus Torvalds #include <asm/uaccess.h> 471da177e4SLinus Torvalds 481da177e4SLinus Torvalds #define IP_CMSG_PKTINFO 1 491da177e4SLinus Torvalds #define IP_CMSG_TTL 2 501da177e4SLinus Torvalds #define IP_CMSG_TOS 4 511da177e4SLinus Torvalds #define IP_CMSG_RECVOPTS 8 521da177e4SLinus Torvalds #define IP_CMSG_RETOPTS 16 532c7946a7SCatherine Zhang #define IP_CMSG_PASSSEC 32 54e8b2dfe9SBalazs Scheidler #define IP_CMSG_ORIGDSTADDR 64 551da177e4SLinus Torvalds 561da177e4SLinus Torvalds /* 571da177e4SLinus Torvalds * SOL_IP control messages. 581da177e4SLinus Torvalds */ 59d826eb14SEric Dumazet #define PKTINFO_SKB_CB(__skb) ((struct in_pktinfo *)((__skb)->cb)) 601da177e4SLinus Torvalds 611da177e4SLinus Torvalds static void ip_cmsg_recv_pktinfo(struct msghdr *msg, struct sk_buff *skb) 621da177e4SLinus Torvalds { 63d826eb14SEric Dumazet struct in_pktinfo info = *PKTINFO_SKB_CB(skb); 641da177e4SLinus Torvalds 65eddc9ec5SArnaldo Carvalho de Melo info.ipi_addr.s_addr = ip_hdr(skb)->daddr; 661da177e4SLinus Torvalds 671da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_PKTINFO, sizeof(info), &info); 681da177e4SLinus Torvalds } 691da177e4SLinus Torvalds 701da177e4SLinus Torvalds static void ip_cmsg_recv_ttl(struct msghdr *msg, struct sk_buff *skb) 711da177e4SLinus Torvalds { 72eddc9ec5SArnaldo Carvalho de Melo int ttl = ip_hdr(skb)->ttl; 731da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_TTL, sizeof(int), &ttl); 741da177e4SLinus Torvalds } 751da177e4SLinus Torvalds 761da177e4SLinus Torvalds static void ip_cmsg_recv_tos(struct msghdr *msg, struct sk_buff *skb) 771da177e4SLinus Torvalds { 78eddc9ec5SArnaldo Carvalho de Melo put_cmsg(msg, SOL_IP, IP_TOS, 1, &ip_hdr(skb)->tos); 791da177e4SLinus Torvalds } 801da177e4SLinus Torvalds 811da177e4SLinus Torvalds static void ip_cmsg_recv_opts(struct msghdr *msg, struct sk_buff *skb) 821da177e4SLinus Torvalds { 831da177e4SLinus Torvalds if (IPCB(skb)->opt.optlen == 0) 841da177e4SLinus Torvalds return; 851da177e4SLinus Torvalds 86eddc9ec5SArnaldo Carvalho de Melo put_cmsg(msg, SOL_IP, IP_RECVOPTS, IPCB(skb)->opt.optlen, 87eddc9ec5SArnaldo Carvalho de Melo ip_hdr(skb) + 1); 881da177e4SLinus Torvalds } 891da177e4SLinus Torvalds 901da177e4SLinus Torvalds 911da177e4SLinus Torvalds static void ip_cmsg_recv_retopts(struct msghdr *msg, struct sk_buff *skb) 921da177e4SLinus Torvalds { 931da177e4SLinus Torvalds unsigned char optbuf[sizeof(struct ip_options) + 40]; 941da177e4SLinus Torvalds struct ip_options *opt = (struct ip_options *)optbuf; 951da177e4SLinus Torvalds 961da177e4SLinus Torvalds if (IPCB(skb)->opt.optlen == 0) 971da177e4SLinus Torvalds return; 981da177e4SLinus Torvalds 991da177e4SLinus Torvalds if (ip_options_echo(opt, skb)) { 1001da177e4SLinus Torvalds msg->msg_flags |= MSG_CTRUNC; 1011da177e4SLinus Torvalds return; 1021da177e4SLinus Torvalds } 1031da177e4SLinus Torvalds ip_options_undo(opt); 1041da177e4SLinus Torvalds 1051da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_RETOPTS, opt->optlen, opt->__data); 1061da177e4SLinus Torvalds } 1071da177e4SLinus Torvalds 1082c7946a7SCatherine Zhang static void ip_cmsg_recv_security(struct msghdr *msg, struct sk_buff *skb) 1092c7946a7SCatherine Zhang { 1102c7946a7SCatherine Zhang char *secdata; 111dc49c1f9SCatherine Zhang u32 seclen, secid; 1122c7946a7SCatherine Zhang int err; 1132c7946a7SCatherine Zhang 114dc49c1f9SCatherine Zhang err = security_socket_getpeersec_dgram(NULL, skb, &secid); 115dc49c1f9SCatherine Zhang if (err) 116dc49c1f9SCatherine Zhang return; 117dc49c1f9SCatherine Zhang 118dc49c1f9SCatherine Zhang err = security_secid_to_secctx(secid, &secdata, &seclen); 1192c7946a7SCatherine Zhang if (err) 1202c7946a7SCatherine Zhang return; 1212c7946a7SCatherine Zhang 1222c7946a7SCatherine Zhang put_cmsg(msg, SOL_IP, SCM_SECURITY, seclen, secdata); 123dc49c1f9SCatherine Zhang security_release_secctx(secdata, seclen); 1242c7946a7SCatherine Zhang } 1252c7946a7SCatherine Zhang 12621d1a161SHarvey Harrison static void ip_cmsg_recv_dstaddr(struct msghdr *msg, struct sk_buff *skb) 127e8b2dfe9SBalazs Scheidler { 128e8b2dfe9SBalazs Scheidler struct sockaddr_in sin; 129b71d1d42SEric Dumazet const struct iphdr *iph = ip_hdr(skb); 13021d1a161SHarvey Harrison __be16 *ports = (__be16 *)skb_transport_header(skb); 131e8b2dfe9SBalazs Scheidler 132e8b2dfe9SBalazs Scheidler if (skb_transport_offset(skb) + 4 > skb->len) 133e8b2dfe9SBalazs Scheidler return; 134e8b2dfe9SBalazs Scheidler 135e8b2dfe9SBalazs Scheidler /* All current transport protocols have the port numbers in the 136e8b2dfe9SBalazs Scheidler * first four bytes of the transport header and this function is 137e8b2dfe9SBalazs Scheidler * written with this assumption in mind. 138e8b2dfe9SBalazs Scheidler */ 139e8b2dfe9SBalazs Scheidler 140e8b2dfe9SBalazs Scheidler sin.sin_family = AF_INET; 141e8b2dfe9SBalazs Scheidler sin.sin_addr.s_addr = iph->daddr; 142e8b2dfe9SBalazs Scheidler sin.sin_port = ports[1]; 143e8b2dfe9SBalazs Scheidler memset(sin.sin_zero, 0, sizeof(sin.sin_zero)); 144e8b2dfe9SBalazs Scheidler 145e8b2dfe9SBalazs Scheidler put_cmsg(msg, SOL_IP, IP_ORIGDSTADDR, sizeof(sin), &sin); 146e8b2dfe9SBalazs Scheidler } 1471da177e4SLinus Torvalds 1481da177e4SLinus Torvalds void ip_cmsg_recv(struct msghdr *msg, struct sk_buff *skb) 1491da177e4SLinus Torvalds { 1501da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(skb->sk); 15195c96174SEric Dumazet unsigned int flags = inet->cmsg_flags; 1521da177e4SLinus Torvalds 1531da177e4SLinus Torvalds /* Ordered by supposed usage frequency */ 1541da177e4SLinus Torvalds if (flags & 1) 1551da177e4SLinus Torvalds ip_cmsg_recv_pktinfo(msg, skb); 1561da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1571da177e4SLinus Torvalds return; 1581da177e4SLinus Torvalds 1591da177e4SLinus Torvalds if (flags & 1) 1601da177e4SLinus Torvalds ip_cmsg_recv_ttl(msg, skb); 1611da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1621da177e4SLinus Torvalds return; 1631da177e4SLinus Torvalds 1641da177e4SLinus Torvalds if (flags & 1) 1651da177e4SLinus Torvalds ip_cmsg_recv_tos(msg, skb); 1661da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1671da177e4SLinus Torvalds return; 1681da177e4SLinus Torvalds 1691da177e4SLinus Torvalds if (flags & 1) 1701da177e4SLinus Torvalds ip_cmsg_recv_opts(msg, skb); 1711da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1721da177e4SLinus Torvalds return; 1731da177e4SLinus Torvalds 1741da177e4SLinus Torvalds if (flags & 1) 1751da177e4SLinus Torvalds ip_cmsg_recv_retopts(msg, skb); 1762c7946a7SCatherine Zhang if ((flags >>= 1) == 0) 1772c7946a7SCatherine Zhang return; 1782c7946a7SCatherine Zhang 1792c7946a7SCatherine Zhang if (flags & 1) 1802c7946a7SCatherine Zhang ip_cmsg_recv_security(msg, skb); 181e8b2dfe9SBalazs Scheidler 182e8b2dfe9SBalazs Scheidler if ((flags >>= 1) == 0) 183e8b2dfe9SBalazs Scheidler return; 184e8b2dfe9SBalazs Scheidler if (flags & 1) 185e8b2dfe9SBalazs Scheidler ip_cmsg_recv_dstaddr(msg, skb); 186e8b2dfe9SBalazs Scheidler 1871da177e4SLinus Torvalds } 1884d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_cmsg_recv); 1891da177e4SLinus Torvalds 1907a6adb92SDenis V. Lunev int ip_cmsg_send(struct net *net, struct msghdr *msg, struct ipcm_cookie *ipc) 1911da177e4SLinus Torvalds { 1921da177e4SLinus Torvalds int err; 1931da177e4SLinus Torvalds struct cmsghdr *cmsg; 1941da177e4SLinus Torvalds 1951da177e4SLinus Torvalds for (cmsg = CMSG_FIRSTHDR(msg); cmsg; cmsg = CMSG_NXTHDR(msg, cmsg)) { 1961da177e4SLinus Torvalds if (!CMSG_OK(msg, cmsg)) 1971da177e4SLinus Torvalds return -EINVAL; 1981da177e4SLinus Torvalds if (cmsg->cmsg_level != SOL_IP) 1991da177e4SLinus Torvalds continue; 2001da177e4SLinus Torvalds switch (cmsg->cmsg_type) { 2011da177e4SLinus Torvalds case IP_RETOPTS: 2021da177e4SLinus Torvalds err = cmsg->cmsg_len - CMSG_ALIGN(sizeof(struct cmsghdr)); 2034d52cfbeSEric Dumazet err = ip_options_get(net, &ipc->opt, CMSG_DATA(cmsg), 2044d52cfbeSEric Dumazet err < 40 ? err : 40); 2051da177e4SLinus Torvalds if (err) 2061da177e4SLinus Torvalds return err; 2071da177e4SLinus Torvalds break; 2081da177e4SLinus Torvalds case IP_PKTINFO: 2091da177e4SLinus Torvalds { 2101da177e4SLinus Torvalds struct in_pktinfo *info; 2111da177e4SLinus Torvalds if (cmsg->cmsg_len != CMSG_LEN(sizeof(struct in_pktinfo))) 2121da177e4SLinus Torvalds return -EINVAL; 2131da177e4SLinus Torvalds info = (struct in_pktinfo *)CMSG_DATA(cmsg); 2141da177e4SLinus Torvalds ipc->oif = info->ipi_ifindex; 2151da177e4SLinus Torvalds ipc->addr = info->ipi_spec_dst.s_addr; 2161da177e4SLinus Torvalds break; 2171da177e4SLinus Torvalds } 2181da177e4SLinus Torvalds default: 2191da177e4SLinus Torvalds return -EINVAL; 2201da177e4SLinus Torvalds } 2211da177e4SLinus Torvalds } 2221da177e4SLinus Torvalds return 0; 2231da177e4SLinus Torvalds } 2241da177e4SLinus Torvalds 2251da177e4SLinus Torvalds 2261da177e4SLinus Torvalds /* Special input handler for packets caught by router alert option. 2271da177e4SLinus Torvalds They are selected only by protocol field, and then processed likely 2281da177e4SLinus Torvalds local ones; but only if someone wants them! Otherwise, router 2291da177e4SLinus Torvalds not running rsvpd will kill RSVP. 2301da177e4SLinus Torvalds 2311da177e4SLinus Torvalds It is user level problem, what it will make with them. 2321da177e4SLinus Torvalds I have no idea, how it will masquearde or NAT them (it is joke, joke :-)), 2331da177e4SLinus Torvalds but receiver should be enough clever f.e. to forward mtrace requests, 2341da177e4SLinus Torvalds sent to multicast group to reach destination designated router. 2351da177e4SLinus Torvalds */ 23643a951e9SEric Dumazet struct ip_ra_chain __rcu *ip_ra_chain; 23766018506SEric Dumazet static DEFINE_SPINLOCK(ip_ra_lock); 23866018506SEric Dumazet 239592fcb9dSEric Dumazet 240592fcb9dSEric Dumazet static void ip_ra_destroy_rcu(struct rcu_head *head) 24166018506SEric Dumazet { 242592fcb9dSEric Dumazet struct ip_ra_chain *ra = container_of(head, struct ip_ra_chain, rcu); 243592fcb9dSEric Dumazet 244592fcb9dSEric Dumazet sock_put(ra->saved_sk); 245592fcb9dSEric Dumazet kfree(ra); 24666018506SEric Dumazet } 2471da177e4SLinus Torvalds 2484d52cfbeSEric Dumazet int ip_ra_control(struct sock *sk, unsigned char on, 2494d52cfbeSEric Dumazet void (*destructor)(struct sock *)) 2501da177e4SLinus Torvalds { 25143a951e9SEric Dumazet struct ip_ra_chain *ra, *new_ra; 25243a951e9SEric Dumazet struct ip_ra_chain __rcu **rap; 2531da177e4SLinus Torvalds 254c720c7e8SEric Dumazet if (sk->sk_type != SOCK_RAW || inet_sk(sk)->inet_num == IPPROTO_RAW) 2551da177e4SLinus Torvalds return -EINVAL; 2561da177e4SLinus Torvalds 2571da177e4SLinus Torvalds new_ra = on ? kmalloc(sizeof(*new_ra), GFP_KERNEL) : NULL; 2581da177e4SLinus Torvalds 25966018506SEric Dumazet spin_lock_bh(&ip_ra_lock); 26043a951e9SEric Dumazet for (rap = &ip_ra_chain; 26143a951e9SEric Dumazet (ra = rcu_dereference_protected(*rap, 26243a951e9SEric Dumazet lockdep_is_held(&ip_ra_lock))) != NULL; 26343a951e9SEric Dumazet rap = &ra->next) { 2641da177e4SLinus Torvalds if (ra->sk == sk) { 2651da177e4SLinus Torvalds if (on) { 26666018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 2671da177e4SLinus Torvalds kfree(new_ra); 2681da177e4SLinus Torvalds return -EADDRINUSE; 2691da177e4SLinus Torvalds } 270592fcb9dSEric Dumazet /* dont let ip_call_ra_chain() use sk again */ 271592fcb9dSEric Dumazet ra->sk = NULL; 27266018506SEric Dumazet rcu_assign_pointer(*rap, ra->next); 27366018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 2741da177e4SLinus Torvalds 2751da177e4SLinus Torvalds if (ra->destructor) 2761da177e4SLinus Torvalds ra->destructor(sk); 277592fcb9dSEric Dumazet /* 278592fcb9dSEric Dumazet * Delay sock_put(sk) and kfree(ra) after one rcu grace 279592fcb9dSEric Dumazet * period. This guarantee ip_call_ra_chain() dont need 280592fcb9dSEric Dumazet * to mess with socket refcounts. 281592fcb9dSEric Dumazet */ 282592fcb9dSEric Dumazet ra->saved_sk = sk; 283592fcb9dSEric Dumazet call_rcu(&ra->rcu, ip_ra_destroy_rcu); 2841da177e4SLinus Torvalds return 0; 2851da177e4SLinus Torvalds } 2861da177e4SLinus Torvalds } 2871da177e4SLinus Torvalds if (new_ra == NULL) { 28866018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 2891da177e4SLinus Torvalds return -ENOBUFS; 2901da177e4SLinus Torvalds } 2911da177e4SLinus Torvalds new_ra->sk = sk; 2921da177e4SLinus Torvalds new_ra->destructor = destructor; 2931da177e4SLinus Torvalds 2941da177e4SLinus Torvalds new_ra->next = ra; 29566018506SEric Dumazet rcu_assign_pointer(*rap, new_ra); 2961da177e4SLinus Torvalds sock_hold(sk); 29766018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 2981da177e4SLinus Torvalds 2991da177e4SLinus Torvalds return 0; 3001da177e4SLinus Torvalds } 3011da177e4SLinus Torvalds 3021da177e4SLinus Torvalds void ip_icmp_error(struct sock *sk, struct sk_buff *skb, int err, 30335986b32SAl Viro __be16 port, u32 info, u8 *payload) 3041da177e4SLinus Torvalds { 3051da177e4SLinus Torvalds struct sock_exterr_skb *serr; 3061da177e4SLinus Torvalds 3071da177e4SLinus Torvalds skb = skb_clone(skb, GFP_ATOMIC); 3081da177e4SLinus Torvalds if (!skb) 3091da177e4SLinus Torvalds return; 3101da177e4SLinus Torvalds 3111da177e4SLinus Torvalds serr = SKB_EXT_ERR(skb); 3121da177e4SLinus Torvalds serr->ee.ee_errno = err; 3131da177e4SLinus Torvalds serr->ee.ee_origin = SO_EE_ORIGIN_ICMP; 31488c7664fSArnaldo Carvalho de Melo serr->ee.ee_type = icmp_hdr(skb)->type; 31588c7664fSArnaldo Carvalho de Melo serr->ee.ee_code = icmp_hdr(skb)->code; 3161da177e4SLinus Torvalds serr->ee.ee_pad = 0; 3171da177e4SLinus Torvalds serr->ee.ee_info = info; 3181da177e4SLinus Torvalds serr->ee.ee_data = 0; 31988c7664fSArnaldo Carvalho de Melo serr->addr_offset = (u8 *)&(((struct iphdr *)(icmp_hdr(skb) + 1))->daddr) - 320d56f90a7SArnaldo Carvalho de Melo skb_network_header(skb); 3211da177e4SLinus Torvalds serr->port = port; 3221da177e4SLinus Torvalds 323bd82393cSArnaldo Carvalho de Melo if (skb_pull(skb, payload - skb->data) != NULL) { 324bd82393cSArnaldo Carvalho de Melo skb_reset_transport_header(skb); 325bd82393cSArnaldo Carvalho de Melo if (sock_queue_err_skb(sk, skb) == 0) 326bd82393cSArnaldo Carvalho de Melo return; 327bd82393cSArnaldo Carvalho de Melo } 3281da177e4SLinus Torvalds kfree_skb(skb); 3291da177e4SLinus Torvalds } 3301da177e4SLinus Torvalds 3310579016eSAl Viro void ip_local_error(struct sock *sk, int err, __be32 daddr, __be16 port, u32 info) 3321da177e4SLinus Torvalds { 3331da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 3341da177e4SLinus Torvalds struct sock_exterr_skb *serr; 3351da177e4SLinus Torvalds struct iphdr *iph; 3361da177e4SLinus Torvalds struct sk_buff *skb; 3371da177e4SLinus Torvalds 3381da177e4SLinus Torvalds if (!inet->recverr) 3391da177e4SLinus Torvalds return; 3401da177e4SLinus Torvalds 3411da177e4SLinus Torvalds skb = alloc_skb(sizeof(struct iphdr), GFP_ATOMIC); 3421da177e4SLinus Torvalds if (!skb) 3431da177e4SLinus Torvalds return; 3441da177e4SLinus Torvalds 3452ca9e6f2SArnaldo Carvalho de Melo skb_put(skb, sizeof(struct iphdr)); 3462ca9e6f2SArnaldo Carvalho de Melo skb_reset_network_header(skb); 347eddc9ec5SArnaldo Carvalho de Melo iph = ip_hdr(skb); 3481da177e4SLinus Torvalds iph->daddr = daddr; 3491da177e4SLinus Torvalds 3501da177e4SLinus Torvalds serr = SKB_EXT_ERR(skb); 3511da177e4SLinus Torvalds serr->ee.ee_errno = err; 3521da177e4SLinus Torvalds serr->ee.ee_origin = SO_EE_ORIGIN_LOCAL; 3531da177e4SLinus Torvalds serr->ee.ee_type = 0; 3541da177e4SLinus Torvalds serr->ee.ee_code = 0; 3551da177e4SLinus Torvalds serr->ee.ee_pad = 0; 3561da177e4SLinus Torvalds serr->ee.ee_info = info; 3571da177e4SLinus Torvalds serr->ee.ee_data = 0; 358d56f90a7SArnaldo Carvalho de Melo serr->addr_offset = (u8 *)&iph->daddr - skb_network_header(skb); 3591da177e4SLinus Torvalds serr->port = port; 3601da177e4SLinus Torvalds 36127a884dcSArnaldo Carvalho de Melo __skb_pull(skb, skb_tail_pointer(skb) - skb->data); 362bd82393cSArnaldo Carvalho de Melo skb_reset_transport_header(skb); 3631da177e4SLinus Torvalds 3641da177e4SLinus Torvalds if (sock_queue_err_skb(sk, skb)) 3651da177e4SLinus Torvalds kfree_skb(skb); 3661da177e4SLinus Torvalds } 3671da177e4SLinus Torvalds 3681da177e4SLinus Torvalds /* 3691da177e4SLinus Torvalds * Handle MSG_ERRQUEUE 3701da177e4SLinus Torvalds */ 3711da177e4SLinus Torvalds int ip_recv_error(struct sock *sk, struct msghdr *msg, int len) 3721da177e4SLinus Torvalds { 3731da177e4SLinus Torvalds struct sock_exterr_skb *serr; 3741da177e4SLinus Torvalds struct sk_buff *skb, *skb2; 3751da177e4SLinus Torvalds struct sockaddr_in *sin; 3761da177e4SLinus Torvalds struct { 3771da177e4SLinus Torvalds struct sock_extended_err ee; 3781da177e4SLinus Torvalds struct sockaddr_in offender; 3791da177e4SLinus Torvalds } errhdr; 3801da177e4SLinus Torvalds int err; 3811da177e4SLinus Torvalds int copied; 3821da177e4SLinus Torvalds 3831da177e4SLinus Torvalds err = -EAGAIN; 3841da177e4SLinus Torvalds skb = skb_dequeue(&sk->sk_error_queue); 3851da177e4SLinus Torvalds if (skb == NULL) 3861da177e4SLinus Torvalds goto out; 3871da177e4SLinus Torvalds 3881da177e4SLinus Torvalds copied = skb->len; 3891da177e4SLinus Torvalds if (copied > len) { 3901da177e4SLinus Torvalds msg->msg_flags |= MSG_TRUNC; 3911da177e4SLinus Torvalds copied = len; 3921da177e4SLinus Torvalds } 3931da177e4SLinus Torvalds err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied); 3941da177e4SLinus Torvalds if (err) 3951da177e4SLinus Torvalds goto out_free_skb; 3961da177e4SLinus Torvalds 3971da177e4SLinus Torvalds sock_recv_timestamp(msg, sk, skb); 3981da177e4SLinus Torvalds 3991da177e4SLinus Torvalds serr = SKB_EXT_ERR(skb); 4001da177e4SLinus Torvalds 4011da177e4SLinus Torvalds sin = (struct sockaddr_in *)msg->msg_name; 4021da177e4SLinus Torvalds if (sin) { 4031da177e4SLinus Torvalds sin->sin_family = AF_INET; 404d56f90a7SArnaldo Carvalho de Melo sin->sin_addr.s_addr = *(__be32 *)(skb_network_header(skb) + 405d56f90a7SArnaldo Carvalho de Melo serr->addr_offset); 4061da177e4SLinus Torvalds sin->sin_port = serr->port; 4071da177e4SLinus Torvalds memset(&sin->sin_zero, 0, sizeof(sin->sin_zero)); 4081da177e4SLinus Torvalds } 4091da177e4SLinus Torvalds 4101da177e4SLinus Torvalds memcpy(&errhdr.ee, &serr->ee, sizeof(struct sock_extended_err)); 4111da177e4SLinus Torvalds sin = &errhdr.offender; 4121da177e4SLinus Torvalds sin->sin_family = AF_UNSPEC; 4131da177e4SLinus Torvalds if (serr->ee.ee_origin == SO_EE_ORIGIN_ICMP) { 4141da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 4151da177e4SLinus Torvalds 4161da177e4SLinus Torvalds sin->sin_family = AF_INET; 417eddc9ec5SArnaldo Carvalho de Melo sin->sin_addr.s_addr = ip_hdr(skb)->saddr; 4181da177e4SLinus Torvalds sin->sin_port = 0; 4191da177e4SLinus Torvalds memset(&sin->sin_zero, 0, sizeof(sin->sin_zero)); 4201da177e4SLinus Torvalds if (inet->cmsg_flags) 4211da177e4SLinus Torvalds ip_cmsg_recv(msg, skb); 4221da177e4SLinus Torvalds } 4231da177e4SLinus Torvalds 4241da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_RECVERR, sizeof(errhdr), &errhdr); 4251da177e4SLinus Torvalds 4261da177e4SLinus Torvalds /* Now we could try to dump offended packet options */ 4271da177e4SLinus Torvalds 4281da177e4SLinus Torvalds msg->msg_flags |= MSG_ERRQUEUE; 4291da177e4SLinus Torvalds err = copied; 4301da177e4SLinus Torvalds 4311da177e4SLinus Torvalds /* Reset and regenerate socket error */ 432e0f9f858SHerbert Xu spin_lock_bh(&sk->sk_error_queue.lock); 4331da177e4SLinus Torvalds sk->sk_err = 0; 4344d52cfbeSEric Dumazet skb2 = skb_peek(&sk->sk_error_queue); 4354d52cfbeSEric Dumazet if (skb2 != NULL) { 4361da177e4SLinus Torvalds sk->sk_err = SKB_EXT_ERR(skb2)->ee.ee_errno; 437e0f9f858SHerbert Xu spin_unlock_bh(&sk->sk_error_queue.lock); 4381da177e4SLinus Torvalds sk->sk_error_report(sk); 4391da177e4SLinus Torvalds } else 440e0f9f858SHerbert Xu spin_unlock_bh(&sk->sk_error_queue.lock); 4411da177e4SLinus Torvalds 4421da177e4SLinus Torvalds out_free_skb: 4431da177e4SLinus Torvalds kfree_skb(skb); 4441da177e4SLinus Torvalds out: 4451da177e4SLinus Torvalds return err; 4461da177e4SLinus Torvalds } 4471da177e4SLinus Torvalds 4481da177e4SLinus Torvalds 4491da177e4SLinus Torvalds /* 4504d52cfbeSEric Dumazet * Socket option code for IP. This is the end of the line after any 4514d52cfbeSEric Dumazet * TCP,UDP etc options on an IP socket. 4521da177e4SLinus Torvalds */ 4531da177e4SLinus Torvalds 4543fdadf7dSDmitry Mishin static int do_ip_setsockopt(struct sock *sk, int level, 455b7058842SDavid S. Miller int optname, char __user *optval, unsigned int optlen) 4561da177e4SLinus Torvalds { 4571da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 4581da177e4SLinus Torvalds int val = 0, err; 4591da177e4SLinus Torvalds 4600c9f79beSXi Wang switch (optname) { 4610c9f79beSXi Wang case IP_PKTINFO: 4620c9f79beSXi Wang case IP_RECVTTL: 4630c9f79beSXi Wang case IP_RECVOPTS: 4640c9f79beSXi Wang case IP_RECVTOS: 4650c9f79beSXi Wang case IP_RETOPTS: 4660c9f79beSXi Wang case IP_TOS: 4670c9f79beSXi Wang case IP_TTL: 4680c9f79beSXi Wang case IP_HDRINCL: 4690c9f79beSXi Wang case IP_MTU_DISCOVER: 4700c9f79beSXi Wang case IP_RECVERR: 4710c9f79beSXi Wang case IP_ROUTER_ALERT: 4720c9f79beSXi Wang case IP_FREEBIND: 4730c9f79beSXi Wang case IP_PASSSEC: 4740c9f79beSXi Wang case IP_TRANSPARENT: 4750c9f79beSXi Wang case IP_MINTTL: 4760c9f79beSXi Wang case IP_NODEFRAG: 4770c9f79beSXi Wang case IP_UNICAST_IF: 4780c9f79beSXi Wang case IP_MULTICAST_TTL: 4790c9f79beSXi Wang case IP_MULTICAST_ALL: 4800c9f79beSXi Wang case IP_MULTICAST_LOOP: 4810c9f79beSXi Wang case IP_RECVORIGDSTADDR: 4821da177e4SLinus Torvalds if (optlen >= sizeof(int)) { 4831da177e4SLinus Torvalds if (get_user(val, (int __user *) optval)) 4841da177e4SLinus Torvalds return -EFAULT; 4851da177e4SLinus Torvalds } else if (optlen >= sizeof(char)) { 4861da177e4SLinus Torvalds unsigned char ucval; 4871da177e4SLinus Torvalds 4881da177e4SLinus Torvalds if (get_user(ucval, (unsigned char __user *) optval)) 4891da177e4SLinus Torvalds return -EFAULT; 4901da177e4SLinus Torvalds val = (int) ucval; 4911da177e4SLinus Torvalds } 4921da177e4SLinus Torvalds } 4931da177e4SLinus Torvalds 4941da177e4SLinus Torvalds /* If optlen==0, it is equivalent to val == 0 */ 4951da177e4SLinus Torvalds 4966a9fb947SPavel Emelyanov if (ip_mroute_opt(optname)) 4971da177e4SLinus Torvalds return ip_mroute_setsockopt(sk, optname, optval, optlen); 4981da177e4SLinus Torvalds 4991da177e4SLinus Torvalds err = 0; 5001da177e4SLinus Torvalds lock_sock(sk); 5011da177e4SLinus Torvalds 5021da177e4SLinus Torvalds switch (optname) { 5031da177e4SLinus Torvalds case IP_OPTIONS: 5041da177e4SLinus Torvalds { 505f6d8bd05SEric Dumazet struct ip_options_rcu *old, *opt = NULL; 506f6d8bd05SEric Dumazet 50765a1c4ffSroel kluin if (optlen > 40) 5081da177e4SLinus Torvalds goto e_inval; 5093b1e0a65SYOSHIFUJI Hideaki err = ip_options_get_from_user(sock_net(sk), &opt, 510cb84663eSDenis V. Lunev optval, optlen); 5111da177e4SLinus Torvalds if (err) 5121da177e4SLinus Torvalds break; 513f6d8bd05SEric Dumazet old = rcu_dereference_protected(inet->inet_opt, 514f6d8bd05SEric Dumazet sock_owned_by_user(sk)); 515d83d8461SArnaldo Carvalho de Melo if (inet->is_icsk) { 516d83d8461SArnaldo Carvalho de Melo struct inet_connection_sock *icsk = inet_csk(sk); 517dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6) 5181da177e4SLinus Torvalds if (sk->sk_family == PF_INET || 5191da177e4SLinus Torvalds (!((1 << sk->sk_state) & 5201da177e4SLinus Torvalds (TCPF_LISTEN | TCPF_CLOSE)) && 521c720c7e8SEric Dumazet inet->inet_daddr != LOOPBACK4_IPV6)) { 5221da177e4SLinus Torvalds #endif 523f6d8bd05SEric Dumazet if (old) 524f6d8bd05SEric Dumazet icsk->icsk_ext_hdr_len -= old->opt.optlen; 5251da177e4SLinus Torvalds if (opt) 526f6d8bd05SEric Dumazet icsk->icsk_ext_hdr_len += opt->opt.optlen; 527d83d8461SArnaldo Carvalho de Melo icsk->icsk_sync_mss(sk, icsk->icsk_pmtu_cookie); 528dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6) 5291da177e4SLinus Torvalds } 5301da177e4SLinus Torvalds #endif 5311da177e4SLinus Torvalds } 532f6d8bd05SEric Dumazet rcu_assign_pointer(inet->inet_opt, opt); 533f6d8bd05SEric Dumazet if (old) 534605b4afeSPaul E. McKenney kfree_rcu(old, rcu); 5351da177e4SLinus Torvalds break; 5361da177e4SLinus Torvalds } 5371da177e4SLinus Torvalds case IP_PKTINFO: 5381da177e4SLinus Torvalds if (val) 5391da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_PKTINFO; 5401da177e4SLinus Torvalds else 5411da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_PKTINFO; 5421da177e4SLinus Torvalds break; 5431da177e4SLinus Torvalds case IP_RECVTTL: 5441da177e4SLinus Torvalds if (val) 5451da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_TTL; 5461da177e4SLinus Torvalds else 5471da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_TTL; 5481da177e4SLinus Torvalds break; 5491da177e4SLinus Torvalds case IP_RECVTOS: 5501da177e4SLinus Torvalds if (val) 5511da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_TOS; 5521da177e4SLinus Torvalds else 5531da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_TOS; 5541da177e4SLinus Torvalds break; 5551da177e4SLinus Torvalds case IP_RECVOPTS: 5561da177e4SLinus Torvalds if (val) 5571da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_RECVOPTS; 5581da177e4SLinus Torvalds else 5591da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_RECVOPTS; 5601da177e4SLinus Torvalds break; 5611da177e4SLinus Torvalds case IP_RETOPTS: 5621da177e4SLinus Torvalds if (val) 5631da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_RETOPTS; 5641da177e4SLinus Torvalds else 5651da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_RETOPTS; 5661da177e4SLinus Torvalds break; 5672c7946a7SCatherine Zhang case IP_PASSSEC: 5682c7946a7SCatherine Zhang if (val) 5692c7946a7SCatherine Zhang inet->cmsg_flags |= IP_CMSG_PASSSEC; 5702c7946a7SCatherine Zhang else 5712c7946a7SCatherine Zhang inet->cmsg_flags &= ~IP_CMSG_PASSSEC; 5722c7946a7SCatherine Zhang break; 573e8b2dfe9SBalazs Scheidler case IP_RECVORIGDSTADDR: 574e8b2dfe9SBalazs Scheidler if (val) 575e8b2dfe9SBalazs Scheidler inet->cmsg_flags |= IP_CMSG_ORIGDSTADDR; 576e8b2dfe9SBalazs Scheidler else 577e8b2dfe9SBalazs Scheidler inet->cmsg_flags &= ~IP_CMSG_ORIGDSTADDR; 578e8b2dfe9SBalazs Scheidler break; 5791da177e4SLinus Torvalds case IP_TOS: /* This sets both TOS and Precedence */ 5801da177e4SLinus Torvalds if (sk->sk_type == SOCK_STREAM) { 5812c67e9acSMaciej Żenczykowski val &= ~INET_ECN_MASK; 5822c67e9acSMaciej Żenczykowski val |= inet->tos & INET_ECN_MASK; 5831da177e4SLinus Torvalds } 5841da177e4SLinus Torvalds if (inet->tos != val) { 5851da177e4SLinus Torvalds inet->tos = val; 5861da177e4SLinus Torvalds sk->sk_priority = rt_tos2priority(val); 5871da177e4SLinus Torvalds sk_dst_reset(sk); 5881da177e4SLinus Torvalds } 5891da177e4SLinus Torvalds break; 5901da177e4SLinus Torvalds case IP_TTL: 5911da177e4SLinus Torvalds if (optlen < 1) 5921da177e4SLinus Torvalds goto e_inval; 5934d52cfbeSEric Dumazet if (val != -1 && (val < 0 || val > 255)) 5941da177e4SLinus Torvalds goto e_inval; 5951da177e4SLinus Torvalds inet->uc_ttl = val; 5961da177e4SLinus Torvalds break; 5971da177e4SLinus Torvalds case IP_HDRINCL: 5981da177e4SLinus Torvalds if (sk->sk_type != SOCK_RAW) { 5991da177e4SLinus Torvalds err = -ENOPROTOOPT; 6001da177e4SLinus Torvalds break; 6011da177e4SLinus Torvalds } 6021da177e4SLinus Torvalds inet->hdrincl = val ? 1 : 0; 6031da177e4SLinus Torvalds break; 6047b2ff18eSJiri Olsa case IP_NODEFRAG: 6057b2ff18eSJiri Olsa if (sk->sk_type != SOCK_RAW) { 6067b2ff18eSJiri Olsa err = -ENOPROTOOPT; 6077b2ff18eSJiri Olsa break; 6087b2ff18eSJiri Olsa } 6097b2ff18eSJiri Olsa inet->nodefrag = val ? 1 : 0; 6107b2ff18eSJiri Olsa break; 6111da177e4SLinus Torvalds case IP_MTU_DISCOVER: 6120eae750eSJohn Dykstra if (val < IP_PMTUDISC_DONT || val > IP_PMTUDISC_PROBE) 6131da177e4SLinus Torvalds goto e_inval; 6141da177e4SLinus Torvalds inet->pmtudisc = val; 6151da177e4SLinus Torvalds break; 6161da177e4SLinus Torvalds case IP_RECVERR: 6171da177e4SLinus Torvalds inet->recverr = !!val; 6181da177e4SLinus Torvalds if (!val) 6191da177e4SLinus Torvalds skb_queue_purge(&sk->sk_error_queue); 6201da177e4SLinus Torvalds break; 6211da177e4SLinus Torvalds case IP_MULTICAST_TTL: 6221da177e4SLinus Torvalds if (sk->sk_type == SOCK_STREAM) 6231da177e4SLinus Torvalds goto e_inval; 6241da177e4SLinus Torvalds if (optlen < 1) 6251da177e4SLinus Torvalds goto e_inval; 6261da177e4SLinus Torvalds if (val == -1) 6271da177e4SLinus Torvalds val = 1; 6281da177e4SLinus Torvalds if (val < 0 || val > 255) 6291da177e4SLinus Torvalds goto e_inval; 6301da177e4SLinus Torvalds inet->mc_ttl = val; 6311da177e4SLinus Torvalds break; 6321da177e4SLinus Torvalds case IP_MULTICAST_LOOP: 6331da177e4SLinus Torvalds if (optlen < 1) 6341da177e4SLinus Torvalds goto e_inval; 6351da177e4SLinus Torvalds inet->mc_loop = !!val; 6361da177e4SLinus Torvalds break; 63776e21053SErich E. Hoover case IP_UNICAST_IF: 63876e21053SErich E. Hoover { 63976e21053SErich E. Hoover struct net_device *dev = NULL; 64076e21053SErich E. Hoover int ifindex; 64176e21053SErich E. Hoover 64276e21053SErich E. Hoover if (optlen != sizeof(int)) 64376e21053SErich E. Hoover goto e_inval; 64476e21053SErich E. Hoover 64576e21053SErich E. Hoover ifindex = (__force int)ntohl((__force __be32)val); 64676e21053SErich E. Hoover if (ifindex == 0) { 64776e21053SErich E. Hoover inet->uc_index = 0; 64876e21053SErich E. Hoover err = 0; 64976e21053SErich E. Hoover break; 65076e21053SErich E. Hoover } 65176e21053SErich E. Hoover 65276e21053SErich E. Hoover dev = dev_get_by_index(sock_net(sk), ifindex); 65376e21053SErich E. Hoover err = -EADDRNOTAVAIL; 65476e21053SErich E. Hoover if (!dev) 65576e21053SErich E. Hoover break; 65676e21053SErich E. Hoover dev_put(dev); 65776e21053SErich E. Hoover 65876e21053SErich E. Hoover err = -EINVAL; 65976e21053SErich E. Hoover if (sk->sk_bound_dev_if) 66076e21053SErich E. Hoover break; 66176e21053SErich E. Hoover 66276e21053SErich E. Hoover inet->uc_index = ifindex; 66376e21053SErich E. Hoover err = 0; 66476e21053SErich E. Hoover break; 66576e21053SErich E. Hoover } 6661da177e4SLinus Torvalds case IP_MULTICAST_IF: 6671da177e4SLinus Torvalds { 6681da177e4SLinus Torvalds struct ip_mreqn mreq; 6691da177e4SLinus Torvalds struct net_device *dev = NULL; 6701da177e4SLinus Torvalds 6711da177e4SLinus Torvalds if (sk->sk_type == SOCK_STREAM) 6721da177e4SLinus Torvalds goto e_inval; 6731da177e4SLinus Torvalds /* 6741da177e4SLinus Torvalds * Check the arguments are allowable 6751da177e4SLinus Torvalds */ 6761da177e4SLinus Torvalds 6770915921bSShan Wei if (optlen < sizeof(struct in_addr)) 6780915921bSShan Wei goto e_inval; 6790915921bSShan Wei 6801da177e4SLinus Torvalds err = -EFAULT; 6811da177e4SLinus Torvalds if (optlen >= sizeof(struct ip_mreqn)) { 6821da177e4SLinus Torvalds if (copy_from_user(&mreq, optval, sizeof(mreq))) 6831da177e4SLinus Torvalds break; 6841da177e4SLinus Torvalds } else { 6851da177e4SLinus Torvalds memset(&mreq, 0, sizeof(mreq)); 6863a084ddbSJiri Pirko if (optlen >= sizeof(struct ip_mreq)) { 6873a084ddbSJiri Pirko if (copy_from_user(&mreq, optval, 6883a084ddbSJiri Pirko sizeof(struct ip_mreq))) 6893a084ddbSJiri Pirko break; 6903a084ddbSJiri Pirko } else if (optlen >= sizeof(struct in_addr)) { 6913a084ddbSJiri Pirko if (copy_from_user(&mreq.imr_address, optval, 6924d52cfbeSEric Dumazet sizeof(struct in_addr))) 6931da177e4SLinus Torvalds break; 6941da177e4SLinus Torvalds } 6953a084ddbSJiri Pirko } 6961da177e4SLinus Torvalds 6971da177e4SLinus Torvalds if (!mreq.imr_ifindex) { 698e6f1cebfSAl Viro if (mreq.imr_address.s_addr == htonl(INADDR_ANY)) { 6991da177e4SLinus Torvalds inet->mc_index = 0; 7001da177e4SLinus Torvalds inet->mc_addr = 0; 7011da177e4SLinus Torvalds err = 0; 7021da177e4SLinus Torvalds break; 7031da177e4SLinus Torvalds } 7043b1e0a65SYOSHIFUJI Hideaki dev = ip_dev_find(sock_net(sk), mreq.imr_address.s_addr); 70555b80503SEric Dumazet if (dev) 7061da177e4SLinus Torvalds mreq.imr_ifindex = dev->ifindex; 7071da177e4SLinus Torvalds } else 70855b80503SEric Dumazet dev = dev_get_by_index(sock_net(sk), mreq.imr_ifindex); 7091da177e4SLinus Torvalds 7101da177e4SLinus Torvalds 7111da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 7121da177e4SLinus Torvalds if (!dev) 7131da177e4SLinus Torvalds break; 71455b80503SEric Dumazet dev_put(dev); 7151da177e4SLinus Torvalds 7161da177e4SLinus Torvalds err = -EINVAL; 7171da177e4SLinus Torvalds if (sk->sk_bound_dev_if && 7181da177e4SLinus Torvalds mreq.imr_ifindex != sk->sk_bound_dev_if) 7191da177e4SLinus Torvalds break; 7201da177e4SLinus Torvalds 7211da177e4SLinus Torvalds inet->mc_index = mreq.imr_ifindex; 7221da177e4SLinus Torvalds inet->mc_addr = mreq.imr_address.s_addr; 7231da177e4SLinus Torvalds err = 0; 7241da177e4SLinus Torvalds break; 7251da177e4SLinus Torvalds } 7261da177e4SLinus Torvalds 7271da177e4SLinus Torvalds case IP_ADD_MEMBERSHIP: 7281da177e4SLinus Torvalds case IP_DROP_MEMBERSHIP: 7291da177e4SLinus Torvalds { 7301da177e4SLinus Torvalds struct ip_mreqn mreq; 7311da177e4SLinus Torvalds 732a96fb49bSFlavio Leitner err = -EPROTO; 733a96fb49bSFlavio Leitner if (inet_sk(sk)->is_icsk) 734a96fb49bSFlavio Leitner break; 735a96fb49bSFlavio Leitner 7361da177e4SLinus Torvalds if (optlen < sizeof(struct ip_mreq)) 7371da177e4SLinus Torvalds goto e_inval; 7381da177e4SLinus Torvalds err = -EFAULT; 7391da177e4SLinus Torvalds if (optlen >= sizeof(struct ip_mreqn)) { 7401da177e4SLinus Torvalds if (copy_from_user(&mreq, optval, sizeof(mreq))) 7411da177e4SLinus Torvalds break; 7421da177e4SLinus Torvalds } else { 7431da177e4SLinus Torvalds memset(&mreq, 0, sizeof(mreq)); 7441da177e4SLinus Torvalds if (copy_from_user(&mreq, optval, sizeof(struct ip_mreq))) 7451da177e4SLinus Torvalds break; 7461da177e4SLinus Torvalds } 7471da177e4SLinus Torvalds 7481da177e4SLinus Torvalds if (optname == IP_ADD_MEMBERSHIP) 7491da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 7501da177e4SLinus Torvalds else 7511da177e4SLinus Torvalds err = ip_mc_leave_group(sk, &mreq); 7521da177e4SLinus Torvalds break; 7531da177e4SLinus Torvalds } 7541da177e4SLinus Torvalds case IP_MSFILTER: 7551da177e4SLinus Torvalds { 7561da177e4SLinus Torvalds struct ip_msfilter *msf; 7571da177e4SLinus Torvalds 7581da177e4SLinus Torvalds if (optlen < IP_MSFILTER_SIZE(0)) 7591da177e4SLinus Torvalds goto e_inval; 7601da177e4SLinus Torvalds if (optlen > sysctl_optmem_max) { 7611da177e4SLinus Torvalds err = -ENOBUFS; 7621da177e4SLinus Torvalds break; 7631da177e4SLinus Torvalds } 7648b3a7005SKris Katterjohn msf = kmalloc(optlen, GFP_KERNEL); 765cfcabdccSStephen Hemminger if (!msf) { 7661da177e4SLinus Torvalds err = -ENOBUFS; 7671da177e4SLinus Torvalds break; 7681da177e4SLinus Torvalds } 7691da177e4SLinus Torvalds err = -EFAULT; 7701da177e4SLinus Torvalds if (copy_from_user(msf, optval, optlen)) { 7711da177e4SLinus Torvalds kfree(msf); 7721da177e4SLinus Torvalds break; 7731da177e4SLinus Torvalds } 7741da177e4SLinus Torvalds /* numsrc >= (1G-4) overflow in 32 bits */ 7751da177e4SLinus Torvalds if (msf->imsf_numsrc >= 0x3ffffffcU || 7761da177e4SLinus Torvalds msf->imsf_numsrc > sysctl_igmp_max_msf) { 7771da177e4SLinus Torvalds kfree(msf); 7781da177e4SLinus Torvalds err = -ENOBUFS; 7791da177e4SLinus Torvalds break; 7801da177e4SLinus Torvalds } 7811da177e4SLinus Torvalds if (IP_MSFILTER_SIZE(msf->imsf_numsrc) > optlen) { 7821da177e4SLinus Torvalds kfree(msf); 7831da177e4SLinus Torvalds err = -EINVAL; 7841da177e4SLinus Torvalds break; 7851da177e4SLinus Torvalds } 7861da177e4SLinus Torvalds err = ip_mc_msfilter(sk, msf, 0); 7871da177e4SLinus Torvalds kfree(msf); 7881da177e4SLinus Torvalds break; 7891da177e4SLinus Torvalds } 7901da177e4SLinus Torvalds case IP_BLOCK_SOURCE: 7911da177e4SLinus Torvalds case IP_UNBLOCK_SOURCE: 7921da177e4SLinus Torvalds case IP_ADD_SOURCE_MEMBERSHIP: 7931da177e4SLinus Torvalds case IP_DROP_SOURCE_MEMBERSHIP: 7941da177e4SLinus Torvalds { 7951da177e4SLinus Torvalds struct ip_mreq_source mreqs; 7961da177e4SLinus Torvalds int omode, add; 7971da177e4SLinus Torvalds 7981da177e4SLinus Torvalds if (optlen != sizeof(struct ip_mreq_source)) 7991da177e4SLinus Torvalds goto e_inval; 8001da177e4SLinus Torvalds if (copy_from_user(&mreqs, optval, sizeof(mreqs))) { 8011da177e4SLinus Torvalds err = -EFAULT; 8021da177e4SLinus Torvalds break; 8031da177e4SLinus Torvalds } 8041da177e4SLinus Torvalds if (optname == IP_BLOCK_SOURCE) { 8051da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 8061da177e4SLinus Torvalds add = 1; 8071da177e4SLinus Torvalds } else if (optname == IP_UNBLOCK_SOURCE) { 8081da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 8091da177e4SLinus Torvalds add = 0; 8101da177e4SLinus Torvalds } else if (optname == IP_ADD_SOURCE_MEMBERSHIP) { 8111da177e4SLinus Torvalds struct ip_mreqn mreq; 8121da177e4SLinus Torvalds 8131da177e4SLinus Torvalds mreq.imr_multiaddr.s_addr = mreqs.imr_multiaddr; 8141da177e4SLinus Torvalds mreq.imr_address.s_addr = mreqs.imr_interface; 8151da177e4SLinus Torvalds mreq.imr_ifindex = 0; 8161da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 8178cdaaa15SDavid L Stevens if (err && err != -EADDRINUSE) 8181da177e4SLinus Torvalds break; 8191da177e4SLinus Torvalds omode = MCAST_INCLUDE; 8201da177e4SLinus Torvalds add = 1; 8211da177e4SLinus Torvalds } else /* IP_DROP_SOURCE_MEMBERSHIP */ { 8221da177e4SLinus Torvalds omode = MCAST_INCLUDE; 8231da177e4SLinus Torvalds add = 0; 8241da177e4SLinus Torvalds } 8251da177e4SLinus Torvalds err = ip_mc_source(add, omode, sk, &mreqs, 0); 8261da177e4SLinus Torvalds break; 8271da177e4SLinus Torvalds } 8281da177e4SLinus Torvalds case MCAST_JOIN_GROUP: 8291da177e4SLinus Torvalds case MCAST_LEAVE_GROUP: 8301da177e4SLinus Torvalds { 8311da177e4SLinus Torvalds struct group_req greq; 8321da177e4SLinus Torvalds struct sockaddr_in *psin; 8331da177e4SLinus Torvalds struct ip_mreqn mreq; 8341da177e4SLinus Torvalds 8351da177e4SLinus Torvalds if (optlen < sizeof(struct group_req)) 8361da177e4SLinus Torvalds goto e_inval; 8371da177e4SLinus Torvalds err = -EFAULT; 8381da177e4SLinus Torvalds if (copy_from_user(&greq, optval, sizeof(greq))) 8391da177e4SLinus Torvalds break; 8401da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greq.gr_group; 8411da177e4SLinus Torvalds if (psin->sin_family != AF_INET) 8421da177e4SLinus Torvalds goto e_inval; 8431da177e4SLinus Torvalds memset(&mreq, 0, sizeof(mreq)); 8441da177e4SLinus Torvalds mreq.imr_multiaddr = psin->sin_addr; 8451da177e4SLinus Torvalds mreq.imr_ifindex = greq.gr_interface; 8461da177e4SLinus Torvalds 8471da177e4SLinus Torvalds if (optname == MCAST_JOIN_GROUP) 8481da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 8491da177e4SLinus Torvalds else 8501da177e4SLinus Torvalds err = ip_mc_leave_group(sk, &mreq); 8511da177e4SLinus Torvalds break; 8521da177e4SLinus Torvalds } 8531da177e4SLinus Torvalds case MCAST_JOIN_SOURCE_GROUP: 8541da177e4SLinus Torvalds case MCAST_LEAVE_SOURCE_GROUP: 8551da177e4SLinus Torvalds case MCAST_BLOCK_SOURCE: 8561da177e4SLinus Torvalds case MCAST_UNBLOCK_SOURCE: 8571da177e4SLinus Torvalds { 8581da177e4SLinus Torvalds struct group_source_req greqs; 8591da177e4SLinus Torvalds struct ip_mreq_source mreqs; 8601da177e4SLinus Torvalds struct sockaddr_in *psin; 8611da177e4SLinus Torvalds int omode, add; 8621da177e4SLinus Torvalds 8631da177e4SLinus Torvalds if (optlen != sizeof(struct group_source_req)) 8641da177e4SLinus Torvalds goto e_inval; 8651da177e4SLinus Torvalds if (copy_from_user(&greqs, optval, sizeof(greqs))) { 8661da177e4SLinus Torvalds err = -EFAULT; 8671da177e4SLinus Torvalds break; 8681da177e4SLinus Torvalds } 8691da177e4SLinus Torvalds if (greqs.gsr_group.ss_family != AF_INET || 8701da177e4SLinus Torvalds greqs.gsr_source.ss_family != AF_INET) { 8711da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 8721da177e4SLinus Torvalds break; 8731da177e4SLinus Torvalds } 8741da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greqs.gsr_group; 8751da177e4SLinus Torvalds mreqs.imr_multiaddr = psin->sin_addr.s_addr; 8761da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greqs.gsr_source; 8771da177e4SLinus Torvalds mreqs.imr_sourceaddr = psin->sin_addr.s_addr; 8781da177e4SLinus Torvalds mreqs.imr_interface = 0; /* use index for mc_source */ 8791da177e4SLinus Torvalds 8801da177e4SLinus Torvalds if (optname == MCAST_BLOCK_SOURCE) { 8811da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 8821da177e4SLinus Torvalds add = 1; 8831da177e4SLinus Torvalds } else if (optname == MCAST_UNBLOCK_SOURCE) { 8841da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 8851da177e4SLinus Torvalds add = 0; 8861da177e4SLinus Torvalds } else if (optname == MCAST_JOIN_SOURCE_GROUP) { 8871da177e4SLinus Torvalds struct ip_mreqn mreq; 8881da177e4SLinus Torvalds 8891da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greqs.gsr_group; 8901da177e4SLinus Torvalds mreq.imr_multiaddr = psin->sin_addr; 8911da177e4SLinus Torvalds mreq.imr_address.s_addr = 0; 8921da177e4SLinus Torvalds mreq.imr_ifindex = greqs.gsr_interface; 8931da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 8948cdaaa15SDavid L Stevens if (err && err != -EADDRINUSE) 8951da177e4SLinus Torvalds break; 8961da177e4SLinus Torvalds greqs.gsr_interface = mreq.imr_ifindex; 8971da177e4SLinus Torvalds omode = MCAST_INCLUDE; 8981da177e4SLinus Torvalds add = 1; 8991da177e4SLinus Torvalds } else /* MCAST_LEAVE_SOURCE_GROUP */ { 9001da177e4SLinus Torvalds omode = MCAST_INCLUDE; 9011da177e4SLinus Torvalds add = 0; 9021da177e4SLinus Torvalds } 9031da177e4SLinus Torvalds err = ip_mc_source(add, omode, sk, &mreqs, 9041da177e4SLinus Torvalds greqs.gsr_interface); 9051da177e4SLinus Torvalds break; 9061da177e4SLinus Torvalds } 9071da177e4SLinus Torvalds case MCAST_MSFILTER: 9081da177e4SLinus Torvalds { 9091da177e4SLinus Torvalds struct sockaddr_in *psin; 9101da177e4SLinus Torvalds struct ip_msfilter *msf = NULL; 9111da177e4SLinus Torvalds struct group_filter *gsf = NULL; 9121da177e4SLinus Torvalds int msize, i, ifindex; 9131da177e4SLinus Torvalds 9141da177e4SLinus Torvalds if (optlen < GROUP_FILTER_SIZE(0)) 9151da177e4SLinus Torvalds goto e_inval; 9161da177e4SLinus Torvalds if (optlen > sysctl_optmem_max) { 9171da177e4SLinus Torvalds err = -ENOBUFS; 9181da177e4SLinus Torvalds break; 9191da177e4SLinus Torvalds } 9208b3a7005SKris Katterjohn gsf = kmalloc(optlen, GFP_KERNEL); 921cfcabdccSStephen Hemminger if (!gsf) { 9221da177e4SLinus Torvalds err = -ENOBUFS; 9231da177e4SLinus Torvalds break; 9241da177e4SLinus Torvalds } 9251da177e4SLinus Torvalds err = -EFAULT; 9264d52cfbeSEric Dumazet if (copy_from_user(gsf, optval, optlen)) 9271da177e4SLinus Torvalds goto mc_msf_out; 9284d52cfbeSEric Dumazet 9291da177e4SLinus Torvalds /* numsrc >= (4G-140)/128 overflow in 32 bits */ 9301da177e4SLinus Torvalds if (gsf->gf_numsrc >= 0x1ffffff || 9311da177e4SLinus Torvalds gsf->gf_numsrc > sysctl_igmp_max_msf) { 9321da177e4SLinus Torvalds err = -ENOBUFS; 9331da177e4SLinus Torvalds goto mc_msf_out; 9341da177e4SLinus Torvalds } 9351da177e4SLinus Torvalds if (GROUP_FILTER_SIZE(gsf->gf_numsrc) > optlen) { 9361da177e4SLinus Torvalds err = -EINVAL; 9371da177e4SLinus Torvalds goto mc_msf_out; 9381da177e4SLinus Torvalds } 9391da177e4SLinus Torvalds msize = IP_MSFILTER_SIZE(gsf->gf_numsrc); 9408b3a7005SKris Katterjohn msf = kmalloc(msize, GFP_KERNEL); 941cfcabdccSStephen Hemminger if (!msf) { 9421da177e4SLinus Torvalds err = -ENOBUFS; 9431da177e4SLinus Torvalds goto mc_msf_out; 9441da177e4SLinus Torvalds } 9451da177e4SLinus Torvalds ifindex = gsf->gf_interface; 9461da177e4SLinus Torvalds psin = (struct sockaddr_in *)&gsf->gf_group; 9471da177e4SLinus Torvalds if (psin->sin_family != AF_INET) { 9481da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 9491da177e4SLinus Torvalds goto mc_msf_out; 9501da177e4SLinus Torvalds } 9511da177e4SLinus Torvalds msf->imsf_multiaddr = psin->sin_addr.s_addr; 9521da177e4SLinus Torvalds msf->imsf_interface = 0; 9531da177e4SLinus Torvalds msf->imsf_fmode = gsf->gf_fmode; 9541da177e4SLinus Torvalds msf->imsf_numsrc = gsf->gf_numsrc; 9551da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 9561da177e4SLinus Torvalds for (i = 0; i < gsf->gf_numsrc; ++i) { 9571da177e4SLinus Torvalds psin = (struct sockaddr_in *)&gsf->gf_slist[i]; 9581da177e4SLinus Torvalds 9591da177e4SLinus Torvalds if (psin->sin_family != AF_INET) 9601da177e4SLinus Torvalds goto mc_msf_out; 9611da177e4SLinus Torvalds msf->imsf_slist[i] = psin->sin_addr.s_addr; 9621da177e4SLinus Torvalds } 9631da177e4SLinus Torvalds kfree(gsf); 9641da177e4SLinus Torvalds gsf = NULL; 9651da177e4SLinus Torvalds 9661da177e4SLinus Torvalds err = ip_mc_msfilter(sk, msf, ifindex); 9671da177e4SLinus Torvalds mc_msf_out: 9681da177e4SLinus Torvalds kfree(msf); 9691da177e4SLinus Torvalds kfree(gsf); 9701da177e4SLinus Torvalds break; 9711da177e4SLinus Torvalds } 972f771bef9SNivedita Singhvi case IP_MULTICAST_ALL: 973f771bef9SNivedita Singhvi if (optlen < 1) 974f771bef9SNivedita Singhvi goto e_inval; 975f771bef9SNivedita Singhvi if (val != 0 && val != 1) 976f771bef9SNivedita Singhvi goto e_inval; 977f771bef9SNivedita Singhvi inet->mc_all = val; 978f771bef9SNivedita Singhvi break; 9791da177e4SLinus Torvalds case IP_ROUTER_ALERT: 9801da177e4SLinus Torvalds err = ip_ra_control(sk, val ? 1 : 0, NULL); 9811da177e4SLinus Torvalds break; 9821da177e4SLinus Torvalds 9831da177e4SLinus Torvalds case IP_FREEBIND: 9841da177e4SLinus Torvalds if (optlen < 1) 9851da177e4SLinus Torvalds goto e_inval; 9861da177e4SLinus Torvalds inet->freebind = !!val; 9871da177e4SLinus Torvalds break; 9881da177e4SLinus Torvalds 9891da177e4SLinus Torvalds case IP_IPSEC_POLICY: 9901da177e4SLinus Torvalds case IP_XFRM_POLICY: 9916fc0b4a7SHerbert Xu err = -EPERM; 992*52e804c6SEric W. Biederman if (!ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN)) 9936fc0b4a7SHerbert Xu break; 9941da177e4SLinus Torvalds err = xfrm_user_policy(sk, optname, optval, optlen); 9951da177e4SLinus Torvalds break; 9961da177e4SLinus Torvalds 997f5715aeaSKOVACS Krisztian case IP_TRANSPARENT: 998*52e804c6SEric W. Biederman if (!!val && !ns_capable(sock_net(sk)->user_ns, CAP_NET_RAW) && 999*52e804c6SEric W. Biederman !ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN)) { 1000f5715aeaSKOVACS Krisztian err = -EPERM; 1001f5715aeaSKOVACS Krisztian break; 1002f5715aeaSKOVACS Krisztian } 1003f5715aeaSKOVACS Krisztian if (optlen < 1) 1004f5715aeaSKOVACS Krisztian goto e_inval; 1005f5715aeaSKOVACS Krisztian inet->transparent = !!val; 1006f5715aeaSKOVACS Krisztian break; 1007f5715aeaSKOVACS Krisztian 1008d218d111SStephen Hemminger case IP_MINTTL: 1009d218d111SStephen Hemminger if (optlen < 1) 1010d218d111SStephen Hemminger goto e_inval; 1011d218d111SStephen Hemminger if (val < 0 || val > 255) 1012d218d111SStephen Hemminger goto e_inval; 1013d218d111SStephen Hemminger inet->min_ttl = val; 1014d218d111SStephen Hemminger break; 1015d218d111SStephen Hemminger 10161da177e4SLinus Torvalds default: 10171da177e4SLinus Torvalds err = -ENOPROTOOPT; 10181da177e4SLinus Torvalds break; 10191da177e4SLinus Torvalds } 10201da177e4SLinus Torvalds release_sock(sk); 10211da177e4SLinus Torvalds return err; 10221da177e4SLinus Torvalds 10231da177e4SLinus Torvalds e_inval: 10241da177e4SLinus Torvalds release_sock(sk); 10251da177e4SLinus Torvalds return -EINVAL; 10261da177e4SLinus Torvalds } 10271da177e4SLinus Torvalds 1028f84af32cSEric Dumazet /** 1029d826eb14SEric Dumazet * ipv4_pktinfo_prepare - transfert some info from rtable to skb 1030f84af32cSEric Dumazet * @sk: socket 1031f84af32cSEric Dumazet * @skb: buffer 1032f84af32cSEric Dumazet * 103335ebf65eSDavid S. Miller * To support IP_CMSG_PKTINFO option, we store rt_iif and specific 103435ebf65eSDavid S. Miller * destination in skb->cb[] before dst drop. 1035d826eb14SEric Dumazet * This way, receiver doesnt make cache line misses to read rtable. 1036f84af32cSEric Dumazet */ 1037d826eb14SEric Dumazet void ipv4_pktinfo_prepare(struct sk_buff *skb) 1038f84af32cSEric Dumazet { 1039d826eb14SEric Dumazet struct in_pktinfo *pktinfo = PKTINFO_SKB_CB(skb); 1040d826eb14SEric Dumazet 104192101b3bSDavid S. Miller if (skb_rtable(skb)) { 104292101b3bSDavid S. Miller pktinfo->ipi_ifindex = inet_iif(skb); 104335ebf65eSDavid S. Miller pktinfo->ipi_spec_dst.s_addr = fib_compute_spec_dst(skb); 1044d826eb14SEric Dumazet } else { 1045d826eb14SEric Dumazet pktinfo->ipi_ifindex = 0; 1046d826eb14SEric Dumazet pktinfo->ipi_spec_dst.s_addr = 0; 1047f84af32cSEric Dumazet } 1048d826eb14SEric Dumazet skb_dst_drop(skb); 1049d826eb14SEric Dumazet } 1050f84af32cSEric Dumazet 10513fdadf7dSDmitry Mishin int ip_setsockopt(struct sock *sk, int level, 1052b7058842SDavid S. Miller int optname, char __user *optval, unsigned int optlen) 10533fdadf7dSDmitry Mishin { 10543fdadf7dSDmitry Mishin int err; 10553fdadf7dSDmitry Mishin 10563fdadf7dSDmitry Mishin if (level != SOL_IP) 10573fdadf7dSDmitry Mishin return -ENOPROTOOPT; 10583fdadf7dSDmitry Mishin 10593fdadf7dSDmitry Mishin err = do_ip_setsockopt(sk, level, optname, optval, optlen); 10603fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 10613fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 10623fdadf7dSDmitry Mishin if (err == -ENOPROTOOPT && optname != IP_HDRINCL && 10636a9fb947SPavel Emelyanov optname != IP_IPSEC_POLICY && 10646a9fb947SPavel Emelyanov optname != IP_XFRM_POLICY && 10656a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 10663fdadf7dSDmitry Mishin lock_sock(sk); 10673fdadf7dSDmitry Mishin err = nf_setsockopt(sk, PF_INET, optname, optval, optlen); 10683fdadf7dSDmitry Mishin release_sock(sk); 10693fdadf7dSDmitry Mishin } 10703fdadf7dSDmitry Mishin #endif 10713fdadf7dSDmitry Mishin return err; 10723fdadf7dSDmitry Mishin } 10734d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_setsockopt); 10743fdadf7dSDmitry Mishin 10753fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT 1076543d9cfeSArnaldo Carvalho de Melo int compat_ip_setsockopt(struct sock *sk, int level, int optname, 1077b7058842SDavid S. Miller char __user *optval, unsigned int optlen) 10783fdadf7dSDmitry Mishin { 10793fdadf7dSDmitry Mishin int err; 10803fdadf7dSDmitry Mishin 10813fdadf7dSDmitry Mishin if (level != SOL_IP) 10823fdadf7dSDmitry Mishin return -ENOPROTOOPT; 10833fdadf7dSDmitry Mishin 1084dae50295SDavid L Stevens if (optname >= MCAST_JOIN_GROUP && optname <= MCAST_MSFILTER) 1085dae50295SDavid L Stevens return compat_mc_setsockopt(sk, level, optname, optval, optlen, 1086dae50295SDavid L Stevens ip_setsockopt); 1087dae50295SDavid L Stevens 10883fdadf7dSDmitry Mishin err = do_ip_setsockopt(sk, level, optname, optval, optlen); 10893fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 10903fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 10913fdadf7dSDmitry Mishin if (err == -ENOPROTOOPT && optname != IP_HDRINCL && 10926a9fb947SPavel Emelyanov optname != IP_IPSEC_POLICY && 10936a9fb947SPavel Emelyanov optname != IP_XFRM_POLICY && 10946a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 10953fdadf7dSDmitry Mishin lock_sock(sk); 1096543d9cfeSArnaldo Carvalho de Melo err = compat_nf_setsockopt(sk, PF_INET, optname, 1097543d9cfeSArnaldo Carvalho de Melo optval, optlen); 10983fdadf7dSDmitry Mishin release_sock(sk); 10993fdadf7dSDmitry Mishin } 11003fdadf7dSDmitry Mishin #endif 11013fdadf7dSDmitry Mishin return err; 11023fdadf7dSDmitry Mishin } 1103543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_setsockopt); 11043fdadf7dSDmitry Mishin #endif 11053fdadf7dSDmitry Mishin 11061da177e4SLinus Torvalds /* 11074d52cfbeSEric Dumazet * Get the options. Note for future reference. The GET of IP options gets 11084d52cfbeSEric Dumazet * the _received_ ones. The set sets the _sent_ ones. 11091da177e4SLinus Torvalds */ 11101da177e4SLinus Torvalds 11113fdadf7dSDmitry Mishin static int do_ip_getsockopt(struct sock *sk, int level, int optname, 111295c96174SEric Dumazet char __user *optval, int __user *optlen, unsigned int flags) 11131da177e4SLinus Torvalds { 11141da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 11151da177e4SLinus Torvalds int val; 11161da177e4SLinus Torvalds int len; 11171da177e4SLinus Torvalds 11181da177e4SLinus Torvalds if (level != SOL_IP) 11191da177e4SLinus Torvalds return -EOPNOTSUPP; 11201da177e4SLinus Torvalds 11216a9fb947SPavel Emelyanov if (ip_mroute_opt(optname)) 11221da177e4SLinus Torvalds return ip_mroute_getsockopt(sk, optname, optval, optlen); 11231da177e4SLinus Torvalds 11241da177e4SLinus Torvalds if (get_user(len, optlen)) 11251da177e4SLinus Torvalds return -EFAULT; 11261da177e4SLinus Torvalds if (len < 0) 11271da177e4SLinus Torvalds return -EINVAL; 11281da177e4SLinus Torvalds 11291da177e4SLinus Torvalds lock_sock(sk); 11301da177e4SLinus Torvalds 11311da177e4SLinus Torvalds switch (optname) { 11321da177e4SLinus Torvalds case IP_OPTIONS: 11331da177e4SLinus Torvalds { 11341da177e4SLinus Torvalds unsigned char optbuf[sizeof(struct ip_options)+40]; 11351da177e4SLinus Torvalds struct ip_options *opt = (struct ip_options *)optbuf; 1136f6d8bd05SEric Dumazet struct ip_options_rcu *inet_opt; 1137f6d8bd05SEric Dumazet 1138f6d8bd05SEric Dumazet inet_opt = rcu_dereference_protected(inet->inet_opt, 1139f6d8bd05SEric Dumazet sock_owned_by_user(sk)); 11401da177e4SLinus Torvalds opt->optlen = 0; 1141f6d8bd05SEric Dumazet if (inet_opt) 1142f6d8bd05SEric Dumazet memcpy(optbuf, &inet_opt->opt, 11431da177e4SLinus Torvalds sizeof(struct ip_options) + 1144f6d8bd05SEric Dumazet inet_opt->opt.optlen); 11451da177e4SLinus Torvalds release_sock(sk); 11461da177e4SLinus Torvalds 11471da177e4SLinus Torvalds if (opt->optlen == 0) 11481da177e4SLinus Torvalds return put_user(0, optlen); 11491da177e4SLinus Torvalds 11501da177e4SLinus Torvalds ip_options_undo(opt); 11511da177e4SLinus Torvalds 11521da177e4SLinus Torvalds len = min_t(unsigned int, len, opt->optlen); 11531da177e4SLinus Torvalds if (put_user(len, optlen)) 11541da177e4SLinus Torvalds return -EFAULT; 11551da177e4SLinus Torvalds if (copy_to_user(optval, opt->__data, len)) 11561da177e4SLinus Torvalds return -EFAULT; 11571da177e4SLinus Torvalds return 0; 11581da177e4SLinus Torvalds } 11591da177e4SLinus Torvalds case IP_PKTINFO: 11601da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_PKTINFO) != 0; 11611da177e4SLinus Torvalds break; 11621da177e4SLinus Torvalds case IP_RECVTTL: 11631da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_TTL) != 0; 11641da177e4SLinus Torvalds break; 11651da177e4SLinus Torvalds case IP_RECVTOS: 11661da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_TOS) != 0; 11671da177e4SLinus Torvalds break; 11681da177e4SLinus Torvalds case IP_RECVOPTS: 11691da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_RECVOPTS) != 0; 11701da177e4SLinus Torvalds break; 11711da177e4SLinus Torvalds case IP_RETOPTS: 11721da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_RETOPTS) != 0; 11731da177e4SLinus Torvalds break; 11742c7946a7SCatherine Zhang case IP_PASSSEC: 11752c7946a7SCatherine Zhang val = (inet->cmsg_flags & IP_CMSG_PASSSEC) != 0; 11762c7946a7SCatherine Zhang break; 1177e8b2dfe9SBalazs Scheidler case IP_RECVORIGDSTADDR: 1178e8b2dfe9SBalazs Scheidler val = (inet->cmsg_flags & IP_CMSG_ORIGDSTADDR) != 0; 1179e8b2dfe9SBalazs Scheidler break; 11801da177e4SLinus Torvalds case IP_TOS: 11811da177e4SLinus Torvalds val = inet->tos; 11821da177e4SLinus Torvalds break; 11831da177e4SLinus Torvalds case IP_TTL: 11841da177e4SLinus Torvalds val = (inet->uc_ttl == -1 ? 11851da177e4SLinus Torvalds sysctl_ip_default_ttl : 11861da177e4SLinus Torvalds inet->uc_ttl); 11871da177e4SLinus Torvalds break; 11881da177e4SLinus Torvalds case IP_HDRINCL: 11891da177e4SLinus Torvalds val = inet->hdrincl; 11901da177e4SLinus Torvalds break; 1191a89b4763SMichael Kerrisk case IP_NODEFRAG: 1192a89b4763SMichael Kerrisk val = inet->nodefrag; 1193a89b4763SMichael Kerrisk break; 11941da177e4SLinus Torvalds case IP_MTU_DISCOVER: 11951da177e4SLinus Torvalds val = inet->pmtudisc; 11961da177e4SLinus Torvalds break; 11971da177e4SLinus Torvalds case IP_MTU: 11981da177e4SLinus Torvalds { 11991da177e4SLinus Torvalds struct dst_entry *dst; 12001da177e4SLinus Torvalds val = 0; 12011da177e4SLinus Torvalds dst = sk_dst_get(sk); 12021da177e4SLinus Torvalds if (dst) { 12031da177e4SLinus Torvalds val = dst_mtu(dst); 12041da177e4SLinus Torvalds dst_release(dst); 12051da177e4SLinus Torvalds } 12061da177e4SLinus Torvalds if (!val) { 12071da177e4SLinus Torvalds release_sock(sk); 12081da177e4SLinus Torvalds return -ENOTCONN; 12091da177e4SLinus Torvalds } 12101da177e4SLinus Torvalds break; 12111da177e4SLinus Torvalds } 12121da177e4SLinus Torvalds case IP_RECVERR: 12131da177e4SLinus Torvalds val = inet->recverr; 12141da177e4SLinus Torvalds break; 12151da177e4SLinus Torvalds case IP_MULTICAST_TTL: 12161da177e4SLinus Torvalds val = inet->mc_ttl; 12171da177e4SLinus Torvalds break; 12181da177e4SLinus Torvalds case IP_MULTICAST_LOOP: 12191da177e4SLinus Torvalds val = inet->mc_loop; 12201da177e4SLinus Torvalds break; 122176e21053SErich E. Hoover case IP_UNICAST_IF: 122276e21053SErich E. Hoover val = (__force int)htonl((__u32) inet->uc_index); 122376e21053SErich E. Hoover break; 12241da177e4SLinus Torvalds case IP_MULTICAST_IF: 12251da177e4SLinus Torvalds { 12261da177e4SLinus Torvalds struct in_addr addr; 12271da177e4SLinus Torvalds len = min_t(unsigned int, len, sizeof(struct in_addr)); 12281da177e4SLinus Torvalds addr.s_addr = inet->mc_addr; 12291da177e4SLinus Torvalds release_sock(sk); 12301da177e4SLinus Torvalds 12311da177e4SLinus Torvalds if (put_user(len, optlen)) 12321da177e4SLinus Torvalds return -EFAULT; 12331da177e4SLinus Torvalds if (copy_to_user(optval, &addr, len)) 12341da177e4SLinus Torvalds return -EFAULT; 12351da177e4SLinus Torvalds return 0; 12361da177e4SLinus Torvalds } 12371da177e4SLinus Torvalds case IP_MSFILTER: 12381da177e4SLinus Torvalds { 12391da177e4SLinus Torvalds struct ip_msfilter msf; 12401da177e4SLinus Torvalds int err; 12411da177e4SLinus Torvalds 12421da177e4SLinus Torvalds if (len < IP_MSFILTER_SIZE(0)) { 12431da177e4SLinus Torvalds release_sock(sk); 12441da177e4SLinus Torvalds return -EINVAL; 12451da177e4SLinus Torvalds } 12461da177e4SLinus Torvalds if (copy_from_user(&msf, optval, IP_MSFILTER_SIZE(0))) { 12471da177e4SLinus Torvalds release_sock(sk); 12481da177e4SLinus Torvalds return -EFAULT; 12491da177e4SLinus Torvalds } 12501da177e4SLinus Torvalds err = ip_mc_msfget(sk, &msf, 12511da177e4SLinus Torvalds (struct ip_msfilter __user *)optval, optlen); 12521da177e4SLinus Torvalds release_sock(sk); 12531da177e4SLinus Torvalds return err; 12541da177e4SLinus Torvalds } 12551da177e4SLinus Torvalds case MCAST_MSFILTER: 12561da177e4SLinus Torvalds { 12571da177e4SLinus Torvalds struct group_filter gsf; 12581da177e4SLinus Torvalds int err; 12591da177e4SLinus Torvalds 12601da177e4SLinus Torvalds if (len < GROUP_FILTER_SIZE(0)) { 12611da177e4SLinus Torvalds release_sock(sk); 12621da177e4SLinus Torvalds return -EINVAL; 12631da177e4SLinus Torvalds } 12641da177e4SLinus Torvalds if (copy_from_user(&gsf, optval, GROUP_FILTER_SIZE(0))) { 12651da177e4SLinus Torvalds release_sock(sk); 12661da177e4SLinus Torvalds return -EFAULT; 12671da177e4SLinus Torvalds } 12681da177e4SLinus Torvalds err = ip_mc_gsfget(sk, &gsf, 12694d52cfbeSEric Dumazet (struct group_filter __user *)optval, 12704d52cfbeSEric Dumazet optlen); 12711da177e4SLinus Torvalds release_sock(sk); 12721da177e4SLinus Torvalds return err; 12731da177e4SLinus Torvalds } 1274f771bef9SNivedita Singhvi case IP_MULTICAST_ALL: 1275f771bef9SNivedita Singhvi val = inet->mc_all; 1276f771bef9SNivedita Singhvi break; 12771da177e4SLinus Torvalds case IP_PKTOPTIONS: 12781da177e4SLinus Torvalds { 12791da177e4SLinus Torvalds struct msghdr msg; 12801da177e4SLinus Torvalds 12811da177e4SLinus Torvalds release_sock(sk); 12821da177e4SLinus Torvalds 12831da177e4SLinus Torvalds if (sk->sk_type != SOCK_STREAM) 12841da177e4SLinus Torvalds return -ENOPROTOOPT; 12851da177e4SLinus Torvalds 12861da177e4SLinus Torvalds msg.msg_control = optval; 12871da177e4SLinus Torvalds msg.msg_controllen = len; 1288dd23198eSDaniel Baluta msg.msg_flags = flags; 12891da177e4SLinus Torvalds 12901da177e4SLinus Torvalds if (inet->cmsg_flags & IP_CMSG_PKTINFO) { 12911da177e4SLinus Torvalds struct in_pktinfo info; 12921da177e4SLinus Torvalds 1293c720c7e8SEric Dumazet info.ipi_addr.s_addr = inet->inet_rcv_saddr; 1294c720c7e8SEric Dumazet info.ipi_spec_dst.s_addr = inet->inet_rcv_saddr; 12951da177e4SLinus Torvalds info.ipi_ifindex = inet->mc_index; 12961da177e4SLinus Torvalds put_cmsg(&msg, SOL_IP, IP_PKTINFO, sizeof(info), &info); 12971da177e4SLinus Torvalds } 12981da177e4SLinus Torvalds if (inet->cmsg_flags & IP_CMSG_TTL) { 12991da177e4SLinus Torvalds int hlim = inet->mc_ttl; 13001da177e4SLinus Torvalds put_cmsg(&msg, SOL_IP, IP_TTL, sizeof(hlim), &hlim); 13011da177e4SLinus Torvalds } 13024c507d28SJiri Benc if (inet->cmsg_flags & IP_CMSG_TOS) { 13034c507d28SJiri Benc int tos = inet->rcv_tos; 13044c507d28SJiri Benc put_cmsg(&msg, SOL_IP, IP_TOS, sizeof(tos), &tos); 13054c507d28SJiri Benc } 13061da177e4SLinus Torvalds len -= msg.msg_controllen; 13071da177e4SLinus Torvalds return put_user(len, optlen); 13081da177e4SLinus Torvalds } 13091da177e4SLinus Torvalds case IP_FREEBIND: 13101da177e4SLinus Torvalds val = inet->freebind; 13111da177e4SLinus Torvalds break; 1312f5715aeaSKOVACS Krisztian case IP_TRANSPARENT: 1313f5715aeaSKOVACS Krisztian val = inet->transparent; 1314f5715aeaSKOVACS Krisztian break; 1315d218d111SStephen Hemminger case IP_MINTTL: 1316d218d111SStephen Hemminger val = inet->min_ttl; 1317d218d111SStephen Hemminger break; 13181da177e4SLinus Torvalds default: 13191da177e4SLinus Torvalds release_sock(sk); 13201da177e4SLinus Torvalds return -ENOPROTOOPT; 13211da177e4SLinus Torvalds } 13221da177e4SLinus Torvalds release_sock(sk); 13231da177e4SLinus Torvalds 1324951e07c9SDavid S. Miller if (len < sizeof(int) && len > 0 && val >= 0 && val <= 255) { 13251da177e4SLinus Torvalds unsigned char ucval = (unsigned char)val; 13261da177e4SLinus Torvalds len = 1; 13271da177e4SLinus Torvalds if (put_user(len, optlen)) 13281da177e4SLinus Torvalds return -EFAULT; 13291da177e4SLinus Torvalds if (copy_to_user(optval, &ucval, 1)) 13301da177e4SLinus Torvalds return -EFAULT; 13311da177e4SLinus Torvalds } else { 13321da177e4SLinus Torvalds len = min_t(unsigned int, sizeof(int), len); 13331da177e4SLinus Torvalds if (put_user(len, optlen)) 13341da177e4SLinus Torvalds return -EFAULT; 13351da177e4SLinus Torvalds if (copy_to_user(optval, &val, len)) 13361da177e4SLinus Torvalds return -EFAULT; 13371da177e4SLinus Torvalds } 13381da177e4SLinus Torvalds return 0; 13391da177e4SLinus Torvalds } 13401da177e4SLinus Torvalds 13413fdadf7dSDmitry Mishin int ip_getsockopt(struct sock *sk, int level, 13423fdadf7dSDmitry Mishin int optname, char __user *optval, int __user *optlen) 13433fdadf7dSDmitry Mishin { 13443fdadf7dSDmitry Mishin int err; 13453fdadf7dSDmitry Mishin 1346dd23198eSDaniel Baluta err = do_ip_getsockopt(sk, level, optname, optval, optlen, 0); 13473fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 13483fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 13496a9fb947SPavel Emelyanov if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS && 13506a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 13513fdadf7dSDmitry Mishin int len; 13523fdadf7dSDmitry Mishin 13533fdadf7dSDmitry Mishin if (get_user(len, optlen)) 13543fdadf7dSDmitry Mishin return -EFAULT; 13553fdadf7dSDmitry Mishin 13563fdadf7dSDmitry Mishin lock_sock(sk); 13573fdadf7dSDmitry Mishin err = nf_getsockopt(sk, PF_INET, optname, optval, 13583fdadf7dSDmitry Mishin &len); 13593fdadf7dSDmitry Mishin release_sock(sk); 13603fdadf7dSDmitry Mishin if (err >= 0) 13613fdadf7dSDmitry Mishin err = put_user(len, optlen); 13623fdadf7dSDmitry Mishin return err; 13633fdadf7dSDmitry Mishin } 13643fdadf7dSDmitry Mishin #endif 13653fdadf7dSDmitry Mishin return err; 13663fdadf7dSDmitry Mishin } 13674d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_getsockopt); 13683fdadf7dSDmitry Mishin 13693fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT 1370543d9cfeSArnaldo Carvalho de Melo int compat_ip_getsockopt(struct sock *sk, int level, int optname, 1371543d9cfeSArnaldo Carvalho de Melo char __user *optval, int __user *optlen) 13723fdadf7dSDmitry Mishin { 137342908c69SDavid L Stevens int err; 137442908c69SDavid L Stevens 137542908c69SDavid L Stevens if (optname == MCAST_MSFILTER) 137642908c69SDavid L Stevens return compat_mc_getsockopt(sk, level, optname, optval, optlen, 137742908c69SDavid L Stevens ip_getsockopt); 137842908c69SDavid L Stevens 1379dd23198eSDaniel Baluta err = do_ip_getsockopt(sk, level, optname, optval, optlen, 1380dd23198eSDaniel Baluta MSG_CMSG_COMPAT); 138142908c69SDavid L Stevens 13823fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 13833fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 13846a9fb947SPavel Emelyanov if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS && 13856a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 13863fdadf7dSDmitry Mishin int len; 13873fdadf7dSDmitry Mishin 13883fdadf7dSDmitry Mishin if (get_user(len, optlen)) 13893fdadf7dSDmitry Mishin return -EFAULT; 13903fdadf7dSDmitry Mishin 13913fdadf7dSDmitry Mishin lock_sock(sk); 1392543d9cfeSArnaldo Carvalho de Melo err = compat_nf_getsockopt(sk, PF_INET, optname, optval, &len); 13933fdadf7dSDmitry Mishin release_sock(sk); 13943fdadf7dSDmitry Mishin if (err >= 0) 13953fdadf7dSDmitry Mishin err = put_user(len, optlen); 13963fdadf7dSDmitry Mishin return err; 13973fdadf7dSDmitry Mishin } 13983fdadf7dSDmitry Mishin #endif 13993fdadf7dSDmitry Mishin return err; 14003fdadf7dSDmitry Mishin } 1401543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_getsockopt); 14023fdadf7dSDmitry Mishin #endif 1403