xref: /linux/net/ipv4/ip_sockglue.c (revision 8e3bff96afa67369008153f3326fa5ce985cabab)
11da177e4SLinus Torvalds /*
21da177e4SLinus Torvalds  * INET		An implementation of the TCP/IP protocol suite for the LINUX
31da177e4SLinus Torvalds  *		operating system.  INET is implemented using the  BSD Socket
41da177e4SLinus Torvalds  *		interface as the means of communication with the user level.
51da177e4SLinus Torvalds  *
61da177e4SLinus Torvalds  *		The IP to API glue.
71da177e4SLinus Torvalds  *
81da177e4SLinus Torvalds  * Authors:	see ip.c
91da177e4SLinus Torvalds  *
101da177e4SLinus Torvalds  * Fixes:
111da177e4SLinus Torvalds  *		Many		:	Split from ip.c , see ip.c for history.
121da177e4SLinus Torvalds  *		Martin Mares	:	TOS setting fixed.
131da177e4SLinus Torvalds  *		Alan Cox	:	Fixed a couple of oopses in Martin's
141da177e4SLinus Torvalds  *					TOS tweaks.
151da177e4SLinus Torvalds  *		Mike McLagan	:	Routing by source
161da177e4SLinus Torvalds  */
171da177e4SLinus Torvalds 
181da177e4SLinus Torvalds #include <linux/module.h>
191da177e4SLinus Torvalds #include <linux/types.h>
201da177e4SLinus Torvalds #include <linux/mm.h>
211da177e4SLinus Torvalds #include <linux/skbuff.h>
221da177e4SLinus Torvalds #include <linux/ip.h>
231da177e4SLinus Torvalds #include <linux/icmp.h>
2414c85021SArnaldo Carvalho de Melo #include <linux/inetdevice.h>
251da177e4SLinus Torvalds #include <linux/netdevice.h>
265a0e3ad6STejun Heo #include <linux/slab.h>
271da177e4SLinus Torvalds #include <net/sock.h>
281da177e4SLinus Torvalds #include <net/ip.h>
291da177e4SLinus Torvalds #include <net/icmp.h>
30d83d8461SArnaldo Carvalho de Melo #include <net/tcp_states.h>
311da177e4SLinus Torvalds #include <linux/udp.h>
321da177e4SLinus Torvalds #include <linux/igmp.h>
331da177e4SLinus Torvalds #include <linux/netfilter.h>
341da177e4SLinus Torvalds #include <linux/route.h>
351da177e4SLinus Torvalds #include <linux/mroute.h>
362c67e9acSMaciej Żenczykowski #include <net/inet_ecn.h>
371da177e4SLinus Torvalds #include <net/route.h>
381da177e4SLinus Torvalds #include <net/xfrm.h>
39dae50295SDavid L Stevens #include <net/compat.h>
40dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
411da177e4SLinus Torvalds #include <net/transp_v6.h>
421da177e4SLinus Torvalds #endif
4335ebf65eSDavid S. Miller #include <net/ip_fib.h>
441da177e4SLinus Torvalds 
451da177e4SLinus Torvalds #include <linux/errqueue.h>
461da177e4SLinus Torvalds #include <asm/uaccess.h>
471da177e4SLinus Torvalds 
481da177e4SLinus Torvalds #define IP_CMSG_PKTINFO		1
491da177e4SLinus Torvalds #define IP_CMSG_TTL		2
501da177e4SLinus Torvalds #define IP_CMSG_TOS		4
511da177e4SLinus Torvalds #define IP_CMSG_RECVOPTS	8
521da177e4SLinus Torvalds #define IP_CMSG_RETOPTS		16
532c7946a7SCatherine Zhang #define IP_CMSG_PASSSEC		32
54e8b2dfe9SBalazs Scheidler #define IP_CMSG_ORIGDSTADDR     64
551da177e4SLinus Torvalds 
561da177e4SLinus Torvalds /*
571da177e4SLinus Torvalds  *	SOL_IP control messages.
581da177e4SLinus Torvalds  */
59d826eb14SEric Dumazet #define PKTINFO_SKB_CB(__skb) ((struct in_pktinfo *)((__skb)->cb))
601da177e4SLinus Torvalds 
611da177e4SLinus Torvalds static void ip_cmsg_recv_pktinfo(struct msghdr *msg, struct sk_buff *skb)
621da177e4SLinus Torvalds {
63d826eb14SEric Dumazet 	struct in_pktinfo info = *PKTINFO_SKB_CB(skb);
641da177e4SLinus Torvalds 
65eddc9ec5SArnaldo Carvalho de Melo 	info.ipi_addr.s_addr = ip_hdr(skb)->daddr;
661da177e4SLinus Torvalds 
671da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_PKTINFO, sizeof(info), &info);
681da177e4SLinus Torvalds }
691da177e4SLinus Torvalds 
701da177e4SLinus Torvalds static void ip_cmsg_recv_ttl(struct msghdr *msg, struct sk_buff *skb)
711da177e4SLinus Torvalds {
72eddc9ec5SArnaldo Carvalho de Melo 	int ttl = ip_hdr(skb)->ttl;
731da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_TTL, sizeof(int), &ttl);
741da177e4SLinus Torvalds }
751da177e4SLinus Torvalds 
761da177e4SLinus Torvalds static void ip_cmsg_recv_tos(struct msghdr *msg, struct sk_buff *skb)
771da177e4SLinus Torvalds {
78eddc9ec5SArnaldo Carvalho de Melo 	put_cmsg(msg, SOL_IP, IP_TOS, 1, &ip_hdr(skb)->tos);
791da177e4SLinus Torvalds }
801da177e4SLinus Torvalds 
811da177e4SLinus Torvalds static void ip_cmsg_recv_opts(struct msghdr *msg, struct sk_buff *skb)
821da177e4SLinus Torvalds {
831da177e4SLinus Torvalds 	if (IPCB(skb)->opt.optlen == 0)
841da177e4SLinus Torvalds 		return;
851da177e4SLinus Torvalds 
86eddc9ec5SArnaldo Carvalho de Melo 	put_cmsg(msg, SOL_IP, IP_RECVOPTS, IPCB(skb)->opt.optlen,
87eddc9ec5SArnaldo Carvalho de Melo 		 ip_hdr(skb) + 1);
881da177e4SLinus Torvalds }
891da177e4SLinus Torvalds 
901da177e4SLinus Torvalds 
911da177e4SLinus Torvalds static void ip_cmsg_recv_retopts(struct msghdr *msg, struct sk_buff *skb)
921da177e4SLinus Torvalds {
931da177e4SLinus Torvalds 	unsigned char optbuf[sizeof(struct ip_options) + 40];
941da177e4SLinus Torvalds 	struct ip_options *opt = (struct ip_options *)optbuf;
951da177e4SLinus Torvalds 
961da177e4SLinus Torvalds 	if (IPCB(skb)->opt.optlen == 0)
971da177e4SLinus Torvalds 		return;
981da177e4SLinus Torvalds 
991da177e4SLinus Torvalds 	if (ip_options_echo(opt, skb)) {
1001da177e4SLinus Torvalds 		msg->msg_flags |= MSG_CTRUNC;
1011da177e4SLinus Torvalds 		return;
1021da177e4SLinus Torvalds 	}
1031da177e4SLinus Torvalds 	ip_options_undo(opt);
1041da177e4SLinus Torvalds 
1051da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_RETOPTS, opt->optlen, opt->__data);
1061da177e4SLinus Torvalds }
1071da177e4SLinus Torvalds 
1082c7946a7SCatherine Zhang static void ip_cmsg_recv_security(struct msghdr *msg, struct sk_buff *skb)
1092c7946a7SCatherine Zhang {
1102c7946a7SCatherine Zhang 	char *secdata;
111dc49c1f9SCatherine Zhang 	u32 seclen, secid;
1122c7946a7SCatherine Zhang 	int err;
1132c7946a7SCatherine Zhang 
114dc49c1f9SCatherine Zhang 	err = security_socket_getpeersec_dgram(NULL, skb, &secid);
115dc49c1f9SCatherine Zhang 	if (err)
116dc49c1f9SCatherine Zhang 		return;
117dc49c1f9SCatherine Zhang 
118dc49c1f9SCatherine Zhang 	err = security_secid_to_secctx(secid, &secdata, &seclen);
1192c7946a7SCatherine Zhang 	if (err)
1202c7946a7SCatherine Zhang 		return;
1212c7946a7SCatherine Zhang 
1222c7946a7SCatherine Zhang 	put_cmsg(msg, SOL_IP, SCM_SECURITY, seclen, secdata);
123dc49c1f9SCatherine Zhang 	security_release_secctx(secdata, seclen);
1242c7946a7SCatherine Zhang }
1252c7946a7SCatherine Zhang 
12621d1a161SHarvey Harrison static void ip_cmsg_recv_dstaddr(struct msghdr *msg, struct sk_buff *skb)
127e8b2dfe9SBalazs Scheidler {
128e8b2dfe9SBalazs Scheidler 	struct sockaddr_in sin;
129b71d1d42SEric Dumazet 	const struct iphdr *iph = ip_hdr(skb);
13021d1a161SHarvey Harrison 	__be16 *ports = (__be16 *)skb_transport_header(skb);
131e8b2dfe9SBalazs Scheidler 
132e8b2dfe9SBalazs Scheidler 	if (skb_transport_offset(skb) + 4 > skb->len)
133e8b2dfe9SBalazs Scheidler 		return;
134e8b2dfe9SBalazs Scheidler 
135e8b2dfe9SBalazs Scheidler 	/* All current transport protocols have the port numbers in the
136e8b2dfe9SBalazs Scheidler 	 * first four bytes of the transport header and this function is
137e8b2dfe9SBalazs Scheidler 	 * written with this assumption in mind.
138e8b2dfe9SBalazs Scheidler 	 */
139e8b2dfe9SBalazs Scheidler 
140e8b2dfe9SBalazs Scheidler 	sin.sin_family = AF_INET;
141e8b2dfe9SBalazs Scheidler 	sin.sin_addr.s_addr = iph->daddr;
142e8b2dfe9SBalazs Scheidler 	sin.sin_port = ports[1];
143e8b2dfe9SBalazs Scheidler 	memset(sin.sin_zero, 0, sizeof(sin.sin_zero));
144e8b2dfe9SBalazs Scheidler 
145e8b2dfe9SBalazs Scheidler 	put_cmsg(msg, SOL_IP, IP_ORIGDSTADDR, sizeof(sin), &sin);
146e8b2dfe9SBalazs Scheidler }
1471da177e4SLinus Torvalds 
1481da177e4SLinus Torvalds void ip_cmsg_recv(struct msghdr *msg, struct sk_buff *skb)
1491da177e4SLinus Torvalds {
1501da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(skb->sk);
15195c96174SEric Dumazet 	unsigned int flags = inet->cmsg_flags;
1521da177e4SLinus Torvalds 
1531da177e4SLinus Torvalds 	/* Ordered by supposed usage frequency */
1541da177e4SLinus Torvalds 	if (flags & 1)
1551da177e4SLinus Torvalds 		ip_cmsg_recv_pktinfo(msg, skb);
1561da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1571da177e4SLinus Torvalds 		return;
1581da177e4SLinus Torvalds 
1591da177e4SLinus Torvalds 	if (flags & 1)
1601da177e4SLinus Torvalds 		ip_cmsg_recv_ttl(msg, skb);
1611da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1621da177e4SLinus Torvalds 		return;
1631da177e4SLinus Torvalds 
1641da177e4SLinus Torvalds 	if (flags & 1)
1651da177e4SLinus Torvalds 		ip_cmsg_recv_tos(msg, skb);
1661da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1671da177e4SLinus Torvalds 		return;
1681da177e4SLinus Torvalds 
1691da177e4SLinus Torvalds 	if (flags & 1)
1701da177e4SLinus Torvalds 		ip_cmsg_recv_opts(msg, skb);
1711da177e4SLinus Torvalds 	if ((flags >>= 1) == 0)
1721da177e4SLinus Torvalds 		return;
1731da177e4SLinus Torvalds 
1741da177e4SLinus Torvalds 	if (flags & 1)
1751da177e4SLinus Torvalds 		ip_cmsg_recv_retopts(msg, skb);
1762c7946a7SCatherine Zhang 	if ((flags >>= 1) == 0)
1772c7946a7SCatherine Zhang 		return;
1782c7946a7SCatherine Zhang 
1792c7946a7SCatherine Zhang 	if (flags & 1)
1802c7946a7SCatherine Zhang 		ip_cmsg_recv_security(msg, skb);
181e8b2dfe9SBalazs Scheidler 
182e8b2dfe9SBalazs Scheidler 	if ((flags >>= 1) == 0)
183e8b2dfe9SBalazs Scheidler 		return;
184e8b2dfe9SBalazs Scheidler 	if (flags & 1)
185e8b2dfe9SBalazs Scheidler 		ip_cmsg_recv_dstaddr(msg, skb);
186e8b2dfe9SBalazs Scheidler 
1871da177e4SLinus Torvalds }
1884d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_cmsg_recv);
1891da177e4SLinus Torvalds 
1907a6adb92SDenis V. Lunev int ip_cmsg_send(struct net *net, struct msghdr *msg, struct ipcm_cookie *ipc)
1911da177e4SLinus Torvalds {
192f02db315SFrancesco Fusco 	int err, val;
1931da177e4SLinus Torvalds 	struct cmsghdr *cmsg;
1941da177e4SLinus Torvalds 
1951da177e4SLinus Torvalds 	for (cmsg = CMSG_FIRSTHDR(msg); cmsg; cmsg = CMSG_NXTHDR(msg, cmsg)) {
1961da177e4SLinus Torvalds 		if (!CMSG_OK(msg, cmsg))
1971da177e4SLinus Torvalds 			return -EINVAL;
1981da177e4SLinus Torvalds 		if (cmsg->cmsg_level != SOL_IP)
1991da177e4SLinus Torvalds 			continue;
2001da177e4SLinus Torvalds 		switch (cmsg->cmsg_type) {
2011da177e4SLinus Torvalds 		case IP_RETOPTS:
2021da177e4SLinus Torvalds 			err = cmsg->cmsg_len - CMSG_ALIGN(sizeof(struct cmsghdr));
2034d52cfbeSEric Dumazet 			err = ip_options_get(net, &ipc->opt, CMSG_DATA(cmsg),
2044d52cfbeSEric Dumazet 					     err < 40 ? err : 40);
2051da177e4SLinus Torvalds 			if (err)
2061da177e4SLinus Torvalds 				return err;
2071da177e4SLinus Torvalds 			break;
2081da177e4SLinus Torvalds 		case IP_PKTINFO:
2091da177e4SLinus Torvalds 		{
2101da177e4SLinus Torvalds 			struct in_pktinfo *info;
2111da177e4SLinus Torvalds 			if (cmsg->cmsg_len != CMSG_LEN(sizeof(struct in_pktinfo)))
2121da177e4SLinus Torvalds 				return -EINVAL;
2131da177e4SLinus Torvalds 			info = (struct in_pktinfo *)CMSG_DATA(cmsg);
2141da177e4SLinus Torvalds 			ipc->oif = info->ipi_ifindex;
2151da177e4SLinus Torvalds 			ipc->addr = info->ipi_spec_dst.s_addr;
2161da177e4SLinus Torvalds 			break;
2171da177e4SLinus Torvalds 		}
218f02db315SFrancesco Fusco 		case IP_TTL:
219f02db315SFrancesco Fusco 			if (cmsg->cmsg_len != CMSG_LEN(sizeof(int)))
220f02db315SFrancesco Fusco 				return -EINVAL;
221f02db315SFrancesco Fusco 			val = *(int *)CMSG_DATA(cmsg);
222f02db315SFrancesco Fusco 			if (val < 1 || val > 255)
223f02db315SFrancesco Fusco 				return -EINVAL;
224f02db315SFrancesco Fusco 			ipc->ttl = val;
225f02db315SFrancesco Fusco 			break;
226f02db315SFrancesco Fusco 		case IP_TOS:
227f02db315SFrancesco Fusco 			if (cmsg->cmsg_len != CMSG_LEN(sizeof(int)))
228f02db315SFrancesco Fusco 				return -EINVAL;
229f02db315SFrancesco Fusco 			val = *(int *)CMSG_DATA(cmsg);
230f02db315SFrancesco Fusco 			if (val < 0 || val > 255)
231f02db315SFrancesco Fusco 				return -EINVAL;
232f02db315SFrancesco Fusco 			ipc->tos = val;
233f02db315SFrancesco Fusco 			ipc->priority = rt_tos2priority(ipc->tos);
234f02db315SFrancesco Fusco 			break;
235f02db315SFrancesco Fusco 
2361da177e4SLinus Torvalds 		default:
2371da177e4SLinus Torvalds 			return -EINVAL;
2381da177e4SLinus Torvalds 		}
2391da177e4SLinus Torvalds 	}
2401da177e4SLinus Torvalds 	return 0;
2411da177e4SLinus Torvalds }
2421da177e4SLinus Torvalds 
2431da177e4SLinus Torvalds 
2441da177e4SLinus Torvalds /* Special input handler for packets caught by router alert option.
2451da177e4SLinus Torvalds    They are selected only by protocol field, and then processed likely
2461da177e4SLinus Torvalds    local ones; but only if someone wants them! Otherwise, router
2471da177e4SLinus Torvalds    not running rsvpd will kill RSVP.
2481da177e4SLinus Torvalds 
2491da177e4SLinus Torvalds    It is user level problem, what it will make with them.
2501da177e4SLinus Torvalds    I have no idea, how it will masquearde or NAT them (it is joke, joke :-)),
2511da177e4SLinus Torvalds    but receiver should be enough clever f.e. to forward mtrace requests,
2521da177e4SLinus Torvalds    sent to multicast group to reach destination designated router.
2531da177e4SLinus Torvalds  */
25443a951e9SEric Dumazet struct ip_ra_chain __rcu *ip_ra_chain;
25566018506SEric Dumazet static DEFINE_SPINLOCK(ip_ra_lock);
25666018506SEric Dumazet 
257592fcb9dSEric Dumazet 
258592fcb9dSEric Dumazet static void ip_ra_destroy_rcu(struct rcu_head *head)
25966018506SEric Dumazet {
260592fcb9dSEric Dumazet 	struct ip_ra_chain *ra = container_of(head, struct ip_ra_chain, rcu);
261592fcb9dSEric Dumazet 
262592fcb9dSEric Dumazet 	sock_put(ra->saved_sk);
263592fcb9dSEric Dumazet 	kfree(ra);
26466018506SEric Dumazet }
2651da177e4SLinus Torvalds 
2664d52cfbeSEric Dumazet int ip_ra_control(struct sock *sk, unsigned char on,
2674d52cfbeSEric Dumazet 		  void (*destructor)(struct sock *))
2681da177e4SLinus Torvalds {
26943a951e9SEric Dumazet 	struct ip_ra_chain *ra, *new_ra;
27043a951e9SEric Dumazet 	struct ip_ra_chain __rcu **rap;
2711da177e4SLinus Torvalds 
272c720c7e8SEric Dumazet 	if (sk->sk_type != SOCK_RAW || inet_sk(sk)->inet_num == IPPROTO_RAW)
2731da177e4SLinus Torvalds 		return -EINVAL;
2741da177e4SLinus Torvalds 
2751da177e4SLinus Torvalds 	new_ra = on ? kmalloc(sizeof(*new_ra), GFP_KERNEL) : NULL;
2761da177e4SLinus Torvalds 
27766018506SEric Dumazet 	spin_lock_bh(&ip_ra_lock);
27843a951e9SEric Dumazet 	for (rap = &ip_ra_chain;
27943a951e9SEric Dumazet 	     (ra = rcu_dereference_protected(*rap,
28043a951e9SEric Dumazet 			lockdep_is_held(&ip_ra_lock))) != NULL;
28143a951e9SEric Dumazet 	     rap = &ra->next) {
2821da177e4SLinus Torvalds 		if (ra->sk == sk) {
2831da177e4SLinus Torvalds 			if (on) {
28466018506SEric Dumazet 				spin_unlock_bh(&ip_ra_lock);
2851da177e4SLinus Torvalds 				kfree(new_ra);
2861da177e4SLinus Torvalds 				return -EADDRINUSE;
2871da177e4SLinus Torvalds 			}
288592fcb9dSEric Dumazet 			/* dont let ip_call_ra_chain() use sk again */
289592fcb9dSEric Dumazet 			ra->sk = NULL;
29066018506SEric Dumazet 			rcu_assign_pointer(*rap, ra->next);
29166018506SEric Dumazet 			spin_unlock_bh(&ip_ra_lock);
2921da177e4SLinus Torvalds 
2931da177e4SLinus Torvalds 			if (ra->destructor)
2941da177e4SLinus Torvalds 				ra->destructor(sk);
295592fcb9dSEric Dumazet 			/*
296592fcb9dSEric Dumazet 			 * Delay sock_put(sk) and kfree(ra) after one rcu grace
297592fcb9dSEric Dumazet 			 * period. This guarantee ip_call_ra_chain() dont need
298592fcb9dSEric Dumazet 			 * to mess with socket refcounts.
299592fcb9dSEric Dumazet 			 */
300592fcb9dSEric Dumazet 			ra->saved_sk = sk;
301592fcb9dSEric Dumazet 			call_rcu(&ra->rcu, ip_ra_destroy_rcu);
3021da177e4SLinus Torvalds 			return 0;
3031da177e4SLinus Torvalds 		}
3041da177e4SLinus Torvalds 	}
3051da177e4SLinus Torvalds 	if (new_ra == NULL) {
30666018506SEric Dumazet 		spin_unlock_bh(&ip_ra_lock);
3071da177e4SLinus Torvalds 		return -ENOBUFS;
3081da177e4SLinus Torvalds 	}
3091da177e4SLinus Torvalds 	new_ra->sk = sk;
3101da177e4SLinus Torvalds 	new_ra->destructor = destructor;
3111da177e4SLinus Torvalds 
3121da177e4SLinus Torvalds 	new_ra->next = ra;
31366018506SEric Dumazet 	rcu_assign_pointer(*rap, new_ra);
3141da177e4SLinus Torvalds 	sock_hold(sk);
31566018506SEric Dumazet 	spin_unlock_bh(&ip_ra_lock);
3161da177e4SLinus Torvalds 
3171da177e4SLinus Torvalds 	return 0;
3181da177e4SLinus Torvalds }
3191da177e4SLinus Torvalds 
3201da177e4SLinus Torvalds void ip_icmp_error(struct sock *sk, struct sk_buff *skb, int err,
32135986b32SAl Viro 		   __be16 port, u32 info, u8 *payload)
3221da177e4SLinus Torvalds {
3231da177e4SLinus Torvalds 	struct sock_exterr_skb *serr;
3241da177e4SLinus Torvalds 
3251da177e4SLinus Torvalds 	skb = skb_clone(skb, GFP_ATOMIC);
3261da177e4SLinus Torvalds 	if (!skb)
3271da177e4SLinus Torvalds 		return;
3281da177e4SLinus Torvalds 
3291da177e4SLinus Torvalds 	serr = SKB_EXT_ERR(skb);
3301da177e4SLinus Torvalds 	serr->ee.ee_errno = err;
3311da177e4SLinus Torvalds 	serr->ee.ee_origin = SO_EE_ORIGIN_ICMP;
33288c7664fSArnaldo Carvalho de Melo 	serr->ee.ee_type = icmp_hdr(skb)->type;
33388c7664fSArnaldo Carvalho de Melo 	serr->ee.ee_code = icmp_hdr(skb)->code;
3341da177e4SLinus Torvalds 	serr->ee.ee_pad = 0;
3351da177e4SLinus Torvalds 	serr->ee.ee_info = info;
3361da177e4SLinus Torvalds 	serr->ee.ee_data = 0;
33788c7664fSArnaldo Carvalho de Melo 	serr->addr_offset = (u8 *)&(((struct iphdr *)(icmp_hdr(skb) + 1))->daddr) -
338d56f90a7SArnaldo Carvalho de Melo 				   skb_network_header(skb);
3391da177e4SLinus Torvalds 	serr->port = port;
3401da177e4SLinus Torvalds 
341bd82393cSArnaldo Carvalho de Melo 	if (skb_pull(skb, payload - skb->data) != NULL) {
342bd82393cSArnaldo Carvalho de Melo 		skb_reset_transport_header(skb);
343bd82393cSArnaldo Carvalho de Melo 		if (sock_queue_err_skb(sk, skb) == 0)
344bd82393cSArnaldo Carvalho de Melo 			return;
345bd82393cSArnaldo Carvalho de Melo 	}
3461da177e4SLinus Torvalds 	kfree_skb(skb);
3471da177e4SLinus Torvalds }
3481da177e4SLinus Torvalds 
3490579016eSAl Viro void ip_local_error(struct sock *sk, int err, __be32 daddr, __be16 port, u32 info)
3501da177e4SLinus Torvalds {
3511da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(sk);
3521da177e4SLinus Torvalds 	struct sock_exterr_skb *serr;
3531da177e4SLinus Torvalds 	struct iphdr *iph;
3541da177e4SLinus Torvalds 	struct sk_buff *skb;
3551da177e4SLinus Torvalds 
3561da177e4SLinus Torvalds 	if (!inet->recverr)
3571da177e4SLinus Torvalds 		return;
3581da177e4SLinus Torvalds 
3591da177e4SLinus Torvalds 	skb = alloc_skb(sizeof(struct iphdr), GFP_ATOMIC);
3601da177e4SLinus Torvalds 	if (!skb)
3611da177e4SLinus Torvalds 		return;
3621da177e4SLinus Torvalds 
3632ca9e6f2SArnaldo Carvalho de Melo 	skb_put(skb, sizeof(struct iphdr));
3642ca9e6f2SArnaldo Carvalho de Melo 	skb_reset_network_header(skb);
365eddc9ec5SArnaldo Carvalho de Melo 	iph = ip_hdr(skb);
3661da177e4SLinus Torvalds 	iph->daddr = daddr;
3671da177e4SLinus Torvalds 
3681da177e4SLinus Torvalds 	serr = SKB_EXT_ERR(skb);
3691da177e4SLinus Torvalds 	serr->ee.ee_errno = err;
3701da177e4SLinus Torvalds 	serr->ee.ee_origin = SO_EE_ORIGIN_LOCAL;
3711da177e4SLinus Torvalds 	serr->ee.ee_type = 0;
3721da177e4SLinus Torvalds 	serr->ee.ee_code = 0;
3731da177e4SLinus Torvalds 	serr->ee.ee_pad = 0;
3741da177e4SLinus Torvalds 	serr->ee.ee_info = info;
3751da177e4SLinus Torvalds 	serr->ee.ee_data = 0;
376d56f90a7SArnaldo Carvalho de Melo 	serr->addr_offset = (u8 *)&iph->daddr - skb_network_header(skb);
3771da177e4SLinus Torvalds 	serr->port = port;
3781da177e4SLinus Torvalds 
37927a884dcSArnaldo Carvalho de Melo 	__skb_pull(skb, skb_tail_pointer(skb) - skb->data);
380bd82393cSArnaldo Carvalho de Melo 	skb_reset_transport_header(skb);
3811da177e4SLinus Torvalds 
3821da177e4SLinus Torvalds 	if (sock_queue_err_skb(sk, skb))
3831da177e4SLinus Torvalds 		kfree_skb(skb);
3841da177e4SLinus Torvalds }
3851da177e4SLinus Torvalds 
3861da177e4SLinus Torvalds /*
3871da177e4SLinus Torvalds  *	Handle MSG_ERRQUEUE
3881da177e4SLinus Torvalds  */
38985fbaa75SHannes Frederic Sowa int ip_recv_error(struct sock *sk, struct msghdr *msg, int len, int *addr_len)
3901da177e4SLinus Torvalds {
3911da177e4SLinus Torvalds 	struct sock_exterr_skb *serr;
3921da177e4SLinus Torvalds 	struct sk_buff *skb, *skb2;
3931da177e4SLinus Torvalds 	struct sockaddr_in *sin;
3941da177e4SLinus Torvalds 	struct {
3951da177e4SLinus Torvalds 		struct sock_extended_err ee;
3961da177e4SLinus Torvalds 		struct sockaddr_in	 offender;
3971da177e4SLinus Torvalds 	} errhdr;
3981da177e4SLinus Torvalds 	int err;
3991da177e4SLinus Torvalds 	int copied;
4001da177e4SLinus Torvalds 
4011da177e4SLinus Torvalds 	err = -EAGAIN;
4021da177e4SLinus Torvalds 	skb = skb_dequeue(&sk->sk_error_queue);
4031da177e4SLinus Torvalds 	if (skb == NULL)
4041da177e4SLinus Torvalds 		goto out;
4051da177e4SLinus Torvalds 
4061da177e4SLinus Torvalds 	copied = skb->len;
4071da177e4SLinus Torvalds 	if (copied > len) {
4081da177e4SLinus Torvalds 		msg->msg_flags |= MSG_TRUNC;
4091da177e4SLinus Torvalds 		copied = len;
4101da177e4SLinus Torvalds 	}
4111da177e4SLinus Torvalds 	err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
4121da177e4SLinus Torvalds 	if (err)
4131da177e4SLinus Torvalds 		goto out_free_skb;
4141da177e4SLinus Torvalds 
4151da177e4SLinus Torvalds 	sock_recv_timestamp(msg, sk, skb);
4161da177e4SLinus Torvalds 
4171da177e4SLinus Torvalds 	serr = SKB_EXT_ERR(skb);
4181da177e4SLinus Torvalds 
4191da177e4SLinus Torvalds 	sin = (struct sockaddr_in *)msg->msg_name;
4201da177e4SLinus Torvalds 	if (sin) {
4211da177e4SLinus Torvalds 		sin->sin_family = AF_INET;
422d56f90a7SArnaldo Carvalho de Melo 		sin->sin_addr.s_addr = *(__be32 *)(skb_network_header(skb) +
423d56f90a7SArnaldo Carvalho de Melo 						   serr->addr_offset);
4241da177e4SLinus Torvalds 		sin->sin_port = serr->port;
4251da177e4SLinus Torvalds 		memset(&sin->sin_zero, 0, sizeof(sin->sin_zero));
42685fbaa75SHannes Frederic Sowa 		*addr_len = sizeof(*sin);
4271da177e4SLinus Torvalds 	}
4281da177e4SLinus Torvalds 
4291da177e4SLinus Torvalds 	memcpy(&errhdr.ee, &serr->ee, sizeof(struct sock_extended_err));
4301da177e4SLinus Torvalds 	sin = &errhdr.offender;
4311da177e4SLinus Torvalds 	sin->sin_family = AF_UNSPEC;
4321da177e4SLinus Torvalds 	if (serr->ee.ee_origin == SO_EE_ORIGIN_ICMP) {
4331da177e4SLinus Torvalds 		struct inet_sock *inet = inet_sk(sk);
4341da177e4SLinus Torvalds 
4351da177e4SLinus Torvalds 		sin->sin_family = AF_INET;
436eddc9ec5SArnaldo Carvalho de Melo 		sin->sin_addr.s_addr = ip_hdr(skb)->saddr;
4371da177e4SLinus Torvalds 		sin->sin_port = 0;
4381da177e4SLinus Torvalds 		memset(&sin->sin_zero, 0, sizeof(sin->sin_zero));
4391da177e4SLinus Torvalds 		if (inet->cmsg_flags)
4401da177e4SLinus Torvalds 			ip_cmsg_recv(msg, skb);
4411da177e4SLinus Torvalds 	}
4421da177e4SLinus Torvalds 
4431da177e4SLinus Torvalds 	put_cmsg(msg, SOL_IP, IP_RECVERR, sizeof(errhdr), &errhdr);
4441da177e4SLinus Torvalds 
4451da177e4SLinus Torvalds 	/* Now we could try to dump offended packet options */
4461da177e4SLinus Torvalds 
4471da177e4SLinus Torvalds 	msg->msg_flags |= MSG_ERRQUEUE;
4481da177e4SLinus Torvalds 	err = copied;
4491da177e4SLinus Torvalds 
4501da177e4SLinus Torvalds 	/* Reset and regenerate socket error */
451e0f9f858SHerbert Xu 	spin_lock_bh(&sk->sk_error_queue.lock);
4521da177e4SLinus Torvalds 	sk->sk_err = 0;
4534d52cfbeSEric Dumazet 	skb2 = skb_peek(&sk->sk_error_queue);
4544d52cfbeSEric Dumazet 	if (skb2 != NULL) {
4551da177e4SLinus Torvalds 		sk->sk_err = SKB_EXT_ERR(skb2)->ee.ee_errno;
456e0f9f858SHerbert Xu 		spin_unlock_bh(&sk->sk_error_queue.lock);
4571da177e4SLinus Torvalds 		sk->sk_error_report(sk);
4581da177e4SLinus Torvalds 	} else
459e0f9f858SHerbert Xu 		spin_unlock_bh(&sk->sk_error_queue.lock);
4601da177e4SLinus Torvalds 
4611da177e4SLinus Torvalds out_free_skb:
4621da177e4SLinus Torvalds 	kfree_skb(skb);
4631da177e4SLinus Torvalds out:
4641da177e4SLinus Torvalds 	return err;
4651da177e4SLinus Torvalds }
4661da177e4SLinus Torvalds 
4671da177e4SLinus Torvalds 
4681da177e4SLinus Torvalds /*
4694d52cfbeSEric Dumazet  *	Socket option code for IP. This is the end of the line after any
4704d52cfbeSEric Dumazet  *	TCP,UDP etc options on an IP socket.
4711da177e4SLinus Torvalds  */
4721da177e4SLinus Torvalds 
4733fdadf7dSDmitry Mishin static int do_ip_setsockopt(struct sock *sk, int level,
474b7058842SDavid S. Miller 			    int optname, char __user *optval, unsigned int optlen)
4751da177e4SLinus Torvalds {
4761da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(sk);
4771da177e4SLinus Torvalds 	int val = 0, err;
4781da177e4SLinus Torvalds 
4790c9f79beSXi Wang 	switch (optname) {
4800c9f79beSXi Wang 	case IP_PKTINFO:
4810c9f79beSXi Wang 	case IP_RECVTTL:
4820c9f79beSXi Wang 	case IP_RECVOPTS:
4830c9f79beSXi Wang 	case IP_RECVTOS:
4840c9f79beSXi Wang 	case IP_RETOPTS:
4850c9f79beSXi Wang 	case IP_TOS:
4860c9f79beSXi Wang 	case IP_TTL:
4870c9f79beSXi Wang 	case IP_HDRINCL:
4880c9f79beSXi Wang 	case IP_MTU_DISCOVER:
4890c9f79beSXi Wang 	case IP_RECVERR:
4900c9f79beSXi Wang 	case IP_ROUTER_ALERT:
4910c9f79beSXi Wang 	case IP_FREEBIND:
4920c9f79beSXi Wang 	case IP_PASSSEC:
4930c9f79beSXi Wang 	case IP_TRANSPARENT:
4940c9f79beSXi Wang 	case IP_MINTTL:
4950c9f79beSXi Wang 	case IP_NODEFRAG:
4960c9f79beSXi Wang 	case IP_UNICAST_IF:
4970c9f79beSXi Wang 	case IP_MULTICAST_TTL:
4980c9f79beSXi Wang 	case IP_MULTICAST_ALL:
4990c9f79beSXi Wang 	case IP_MULTICAST_LOOP:
5000c9f79beSXi Wang 	case IP_RECVORIGDSTADDR:
5011da177e4SLinus Torvalds 		if (optlen >= sizeof(int)) {
5021da177e4SLinus Torvalds 			if (get_user(val, (int __user *) optval))
5031da177e4SLinus Torvalds 				return -EFAULT;
5041da177e4SLinus Torvalds 		} else if (optlen >= sizeof(char)) {
5051da177e4SLinus Torvalds 			unsigned char ucval;
5061da177e4SLinus Torvalds 
5071da177e4SLinus Torvalds 			if (get_user(ucval, (unsigned char __user *) optval))
5081da177e4SLinus Torvalds 				return -EFAULT;
5091da177e4SLinus Torvalds 			val = (int) ucval;
5101da177e4SLinus Torvalds 		}
5111da177e4SLinus Torvalds 	}
5121da177e4SLinus Torvalds 
5131da177e4SLinus Torvalds 	/* If optlen==0, it is equivalent to val == 0 */
5141da177e4SLinus Torvalds 
5156a9fb947SPavel Emelyanov 	if (ip_mroute_opt(optname))
5161da177e4SLinus Torvalds 		return ip_mroute_setsockopt(sk, optname, optval, optlen);
5171da177e4SLinus Torvalds 
5181da177e4SLinus Torvalds 	err = 0;
5191da177e4SLinus Torvalds 	lock_sock(sk);
5201da177e4SLinus Torvalds 
5211da177e4SLinus Torvalds 	switch (optname) {
5221da177e4SLinus Torvalds 	case IP_OPTIONS:
5231da177e4SLinus Torvalds 	{
524f6d8bd05SEric Dumazet 		struct ip_options_rcu *old, *opt = NULL;
525f6d8bd05SEric Dumazet 
52665a1c4ffSroel kluin 		if (optlen > 40)
5271da177e4SLinus Torvalds 			goto e_inval;
5283b1e0a65SYOSHIFUJI Hideaki 		err = ip_options_get_from_user(sock_net(sk), &opt,
529cb84663eSDenis V. Lunev 					       optval, optlen);
5301da177e4SLinus Torvalds 		if (err)
5311da177e4SLinus Torvalds 			break;
532f6d8bd05SEric Dumazet 		old = rcu_dereference_protected(inet->inet_opt,
533f6d8bd05SEric Dumazet 						sock_owned_by_user(sk));
534d83d8461SArnaldo Carvalho de Melo 		if (inet->is_icsk) {
535d83d8461SArnaldo Carvalho de Melo 			struct inet_connection_sock *icsk = inet_csk(sk);
536dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
5371da177e4SLinus Torvalds 			if (sk->sk_family == PF_INET ||
5381da177e4SLinus Torvalds 			    (!((1 << sk->sk_state) &
5391da177e4SLinus Torvalds 			       (TCPF_LISTEN | TCPF_CLOSE)) &&
540c720c7e8SEric Dumazet 			     inet->inet_daddr != LOOPBACK4_IPV6)) {
5411da177e4SLinus Torvalds #endif
542f6d8bd05SEric Dumazet 				if (old)
543f6d8bd05SEric Dumazet 					icsk->icsk_ext_hdr_len -= old->opt.optlen;
5441da177e4SLinus Torvalds 				if (opt)
545f6d8bd05SEric Dumazet 					icsk->icsk_ext_hdr_len += opt->opt.optlen;
546d83d8461SArnaldo Carvalho de Melo 				icsk->icsk_sync_mss(sk, icsk->icsk_pmtu_cookie);
547dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6)
5481da177e4SLinus Torvalds 			}
5491da177e4SLinus Torvalds #endif
5501da177e4SLinus Torvalds 		}
551f6d8bd05SEric Dumazet 		rcu_assign_pointer(inet->inet_opt, opt);
552f6d8bd05SEric Dumazet 		if (old)
553605b4afeSPaul E. McKenney 			kfree_rcu(old, rcu);
5541da177e4SLinus Torvalds 		break;
5551da177e4SLinus Torvalds 	}
5561da177e4SLinus Torvalds 	case IP_PKTINFO:
5571da177e4SLinus Torvalds 		if (val)
5581da177e4SLinus Torvalds 			inet->cmsg_flags |= IP_CMSG_PKTINFO;
5591da177e4SLinus Torvalds 		else
5601da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_PKTINFO;
5611da177e4SLinus Torvalds 		break;
5621da177e4SLinus Torvalds 	case IP_RECVTTL:
5631da177e4SLinus Torvalds 		if (val)
5641da177e4SLinus Torvalds 			inet->cmsg_flags |=  IP_CMSG_TTL;
5651da177e4SLinus Torvalds 		else
5661da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_TTL;
5671da177e4SLinus Torvalds 		break;
5681da177e4SLinus Torvalds 	case IP_RECVTOS:
5691da177e4SLinus Torvalds 		if (val)
5701da177e4SLinus Torvalds 			inet->cmsg_flags |=  IP_CMSG_TOS;
5711da177e4SLinus Torvalds 		else
5721da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_TOS;
5731da177e4SLinus Torvalds 		break;
5741da177e4SLinus Torvalds 	case IP_RECVOPTS:
5751da177e4SLinus Torvalds 		if (val)
5761da177e4SLinus Torvalds 			inet->cmsg_flags |=  IP_CMSG_RECVOPTS;
5771da177e4SLinus Torvalds 		else
5781da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_RECVOPTS;
5791da177e4SLinus Torvalds 		break;
5801da177e4SLinus Torvalds 	case IP_RETOPTS:
5811da177e4SLinus Torvalds 		if (val)
5821da177e4SLinus Torvalds 			inet->cmsg_flags |= IP_CMSG_RETOPTS;
5831da177e4SLinus Torvalds 		else
5841da177e4SLinus Torvalds 			inet->cmsg_flags &= ~IP_CMSG_RETOPTS;
5851da177e4SLinus Torvalds 		break;
5862c7946a7SCatherine Zhang 	case IP_PASSSEC:
5872c7946a7SCatherine Zhang 		if (val)
5882c7946a7SCatherine Zhang 			inet->cmsg_flags |= IP_CMSG_PASSSEC;
5892c7946a7SCatherine Zhang 		else
5902c7946a7SCatherine Zhang 			inet->cmsg_flags &= ~IP_CMSG_PASSSEC;
5912c7946a7SCatherine Zhang 		break;
592e8b2dfe9SBalazs Scheidler 	case IP_RECVORIGDSTADDR:
593e8b2dfe9SBalazs Scheidler 		if (val)
594e8b2dfe9SBalazs Scheidler 			inet->cmsg_flags |= IP_CMSG_ORIGDSTADDR;
595e8b2dfe9SBalazs Scheidler 		else
596e8b2dfe9SBalazs Scheidler 			inet->cmsg_flags &= ~IP_CMSG_ORIGDSTADDR;
597e8b2dfe9SBalazs Scheidler 		break;
5981da177e4SLinus Torvalds 	case IP_TOS:	/* This sets both TOS and Precedence */
5991da177e4SLinus Torvalds 		if (sk->sk_type == SOCK_STREAM) {
6002c67e9acSMaciej Żenczykowski 			val &= ~INET_ECN_MASK;
6012c67e9acSMaciej Żenczykowski 			val |= inet->tos & INET_ECN_MASK;
6021da177e4SLinus Torvalds 		}
6031da177e4SLinus Torvalds 		if (inet->tos != val) {
6041da177e4SLinus Torvalds 			inet->tos = val;
6051da177e4SLinus Torvalds 			sk->sk_priority = rt_tos2priority(val);
6061da177e4SLinus Torvalds 			sk_dst_reset(sk);
6071da177e4SLinus Torvalds 		}
6081da177e4SLinus Torvalds 		break;
6091da177e4SLinus Torvalds 	case IP_TTL:
6101da177e4SLinus Torvalds 		if (optlen < 1)
6111da177e4SLinus Torvalds 			goto e_inval;
612c9be4a5cSCong Wang 		if (val != -1 && (val < 1 || val > 255))
6131da177e4SLinus Torvalds 			goto e_inval;
6141da177e4SLinus Torvalds 		inet->uc_ttl = val;
6151da177e4SLinus Torvalds 		break;
6161da177e4SLinus Torvalds 	case IP_HDRINCL:
6171da177e4SLinus Torvalds 		if (sk->sk_type != SOCK_RAW) {
6181da177e4SLinus Torvalds 			err = -ENOPROTOOPT;
6191da177e4SLinus Torvalds 			break;
6201da177e4SLinus Torvalds 		}
6211da177e4SLinus Torvalds 		inet->hdrincl = val ? 1 : 0;
6221da177e4SLinus Torvalds 		break;
6237b2ff18eSJiri Olsa 	case IP_NODEFRAG:
6247b2ff18eSJiri Olsa 		if (sk->sk_type != SOCK_RAW) {
6257b2ff18eSJiri Olsa 			err = -ENOPROTOOPT;
6267b2ff18eSJiri Olsa 			break;
6277b2ff18eSJiri Olsa 		}
6287b2ff18eSJiri Olsa 		inet->nodefrag = val ? 1 : 0;
6297b2ff18eSJiri Olsa 		break;
6301da177e4SLinus Torvalds 	case IP_MTU_DISCOVER:
631482fc609SHannes Frederic Sowa 		if (val < IP_PMTUDISC_DONT || val > IP_PMTUDISC_INTERFACE)
6321da177e4SLinus Torvalds 			goto e_inval;
6331da177e4SLinus Torvalds 		inet->pmtudisc = val;
6341da177e4SLinus Torvalds 		break;
6351da177e4SLinus Torvalds 	case IP_RECVERR:
6361da177e4SLinus Torvalds 		inet->recverr = !!val;
6371da177e4SLinus Torvalds 		if (!val)
6381da177e4SLinus Torvalds 			skb_queue_purge(&sk->sk_error_queue);
6391da177e4SLinus Torvalds 		break;
6401da177e4SLinus Torvalds 	case IP_MULTICAST_TTL:
6411da177e4SLinus Torvalds 		if (sk->sk_type == SOCK_STREAM)
6421da177e4SLinus Torvalds 			goto e_inval;
6431da177e4SLinus Torvalds 		if (optlen < 1)
6441da177e4SLinus Torvalds 			goto e_inval;
6451da177e4SLinus Torvalds 		if (val == -1)
6461da177e4SLinus Torvalds 			val = 1;
6471da177e4SLinus Torvalds 		if (val < 0 || val > 255)
6481da177e4SLinus Torvalds 			goto e_inval;
6491da177e4SLinus Torvalds 		inet->mc_ttl = val;
6501da177e4SLinus Torvalds 		break;
6511da177e4SLinus Torvalds 	case IP_MULTICAST_LOOP:
6521da177e4SLinus Torvalds 		if (optlen < 1)
6531da177e4SLinus Torvalds 			goto e_inval;
6541da177e4SLinus Torvalds 		inet->mc_loop = !!val;
6551da177e4SLinus Torvalds 		break;
65676e21053SErich E. Hoover 	case IP_UNICAST_IF:
65776e21053SErich E. Hoover 	{
65876e21053SErich E. Hoover 		struct net_device *dev = NULL;
65976e21053SErich E. Hoover 		int ifindex;
66076e21053SErich E. Hoover 
66176e21053SErich E. Hoover 		if (optlen != sizeof(int))
66276e21053SErich E. Hoover 			goto e_inval;
66376e21053SErich E. Hoover 
66476e21053SErich E. Hoover 		ifindex = (__force int)ntohl((__force __be32)val);
66576e21053SErich E. Hoover 		if (ifindex == 0) {
66676e21053SErich E. Hoover 			inet->uc_index = 0;
66776e21053SErich E. Hoover 			err = 0;
66876e21053SErich E. Hoover 			break;
66976e21053SErich E. Hoover 		}
67076e21053SErich E. Hoover 
67176e21053SErich E. Hoover 		dev = dev_get_by_index(sock_net(sk), ifindex);
67276e21053SErich E. Hoover 		err = -EADDRNOTAVAIL;
67376e21053SErich E. Hoover 		if (!dev)
67476e21053SErich E. Hoover 			break;
67576e21053SErich E. Hoover 		dev_put(dev);
67676e21053SErich E. Hoover 
67776e21053SErich E. Hoover 		err = -EINVAL;
67876e21053SErich E. Hoover 		if (sk->sk_bound_dev_if)
67976e21053SErich E. Hoover 			break;
68076e21053SErich E. Hoover 
68176e21053SErich E. Hoover 		inet->uc_index = ifindex;
68276e21053SErich E. Hoover 		err = 0;
68376e21053SErich E. Hoover 		break;
68476e21053SErich E. Hoover 	}
6851da177e4SLinus Torvalds 	case IP_MULTICAST_IF:
6861da177e4SLinus Torvalds 	{
6871da177e4SLinus Torvalds 		struct ip_mreqn mreq;
6881da177e4SLinus Torvalds 		struct net_device *dev = NULL;
6891da177e4SLinus Torvalds 
6901da177e4SLinus Torvalds 		if (sk->sk_type == SOCK_STREAM)
6911da177e4SLinus Torvalds 			goto e_inval;
6921da177e4SLinus Torvalds 		/*
6931da177e4SLinus Torvalds 		 *	Check the arguments are allowable
6941da177e4SLinus Torvalds 		 */
6951da177e4SLinus Torvalds 
6960915921bSShan Wei 		if (optlen < sizeof(struct in_addr))
6970915921bSShan Wei 			goto e_inval;
6980915921bSShan Wei 
6991da177e4SLinus Torvalds 		err = -EFAULT;
7001da177e4SLinus Torvalds 		if (optlen >= sizeof(struct ip_mreqn)) {
7011da177e4SLinus Torvalds 			if (copy_from_user(&mreq, optval, sizeof(mreq)))
7021da177e4SLinus Torvalds 				break;
7031da177e4SLinus Torvalds 		} else {
7041da177e4SLinus Torvalds 			memset(&mreq, 0, sizeof(mreq));
7053a084ddbSJiri Pirko 			if (optlen >= sizeof(struct ip_mreq)) {
7063a084ddbSJiri Pirko 				if (copy_from_user(&mreq, optval,
7073a084ddbSJiri Pirko 						   sizeof(struct ip_mreq)))
7083a084ddbSJiri Pirko 					break;
7093a084ddbSJiri Pirko 			} else if (optlen >= sizeof(struct in_addr)) {
7103a084ddbSJiri Pirko 				if (copy_from_user(&mreq.imr_address, optval,
7114d52cfbeSEric Dumazet 						   sizeof(struct in_addr)))
7121da177e4SLinus Torvalds 					break;
7131da177e4SLinus Torvalds 			}
7143a084ddbSJiri Pirko 		}
7151da177e4SLinus Torvalds 
7161da177e4SLinus Torvalds 		if (!mreq.imr_ifindex) {
717e6f1cebfSAl Viro 			if (mreq.imr_address.s_addr == htonl(INADDR_ANY)) {
7181da177e4SLinus Torvalds 				inet->mc_index = 0;
7191da177e4SLinus Torvalds 				inet->mc_addr  = 0;
7201da177e4SLinus Torvalds 				err = 0;
7211da177e4SLinus Torvalds 				break;
7221da177e4SLinus Torvalds 			}
7233b1e0a65SYOSHIFUJI Hideaki 			dev = ip_dev_find(sock_net(sk), mreq.imr_address.s_addr);
72455b80503SEric Dumazet 			if (dev)
7251da177e4SLinus Torvalds 				mreq.imr_ifindex = dev->ifindex;
7261da177e4SLinus Torvalds 		} else
72755b80503SEric Dumazet 			dev = dev_get_by_index(sock_net(sk), mreq.imr_ifindex);
7281da177e4SLinus Torvalds 
7291da177e4SLinus Torvalds 
7301da177e4SLinus Torvalds 		err = -EADDRNOTAVAIL;
7311da177e4SLinus Torvalds 		if (!dev)
7321da177e4SLinus Torvalds 			break;
73355b80503SEric Dumazet 		dev_put(dev);
7341da177e4SLinus Torvalds 
7351da177e4SLinus Torvalds 		err = -EINVAL;
7361da177e4SLinus Torvalds 		if (sk->sk_bound_dev_if &&
7371da177e4SLinus Torvalds 		    mreq.imr_ifindex != sk->sk_bound_dev_if)
7381da177e4SLinus Torvalds 			break;
7391da177e4SLinus Torvalds 
7401da177e4SLinus Torvalds 		inet->mc_index = mreq.imr_ifindex;
7411da177e4SLinus Torvalds 		inet->mc_addr  = mreq.imr_address.s_addr;
7421da177e4SLinus Torvalds 		err = 0;
7431da177e4SLinus Torvalds 		break;
7441da177e4SLinus Torvalds 	}
7451da177e4SLinus Torvalds 
7461da177e4SLinus Torvalds 	case IP_ADD_MEMBERSHIP:
7471da177e4SLinus Torvalds 	case IP_DROP_MEMBERSHIP:
7481da177e4SLinus Torvalds 	{
7491da177e4SLinus Torvalds 		struct ip_mreqn mreq;
7501da177e4SLinus Torvalds 
751a96fb49bSFlavio Leitner 		err = -EPROTO;
752a96fb49bSFlavio Leitner 		if (inet_sk(sk)->is_icsk)
753a96fb49bSFlavio Leitner 			break;
754a96fb49bSFlavio Leitner 
7551da177e4SLinus Torvalds 		if (optlen < sizeof(struct ip_mreq))
7561da177e4SLinus Torvalds 			goto e_inval;
7571da177e4SLinus Torvalds 		err = -EFAULT;
7581da177e4SLinus Torvalds 		if (optlen >= sizeof(struct ip_mreqn)) {
7591da177e4SLinus Torvalds 			if (copy_from_user(&mreq, optval, sizeof(mreq)))
7601da177e4SLinus Torvalds 				break;
7611da177e4SLinus Torvalds 		} else {
7621da177e4SLinus Torvalds 			memset(&mreq, 0, sizeof(mreq));
7631da177e4SLinus Torvalds 			if (copy_from_user(&mreq, optval, sizeof(struct ip_mreq)))
7641da177e4SLinus Torvalds 				break;
7651da177e4SLinus Torvalds 		}
7661da177e4SLinus Torvalds 
7671da177e4SLinus Torvalds 		if (optname == IP_ADD_MEMBERSHIP)
7681da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
7691da177e4SLinus Torvalds 		else
7701da177e4SLinus Torvalds 			err = ip_mc_leave_group(sk, &mreq);
7711da177e4SLinus Torvalds 		break;
7721da177e4SLinus Torvalds 	}
7731da177e4SLinus Torvalds 	case IP_MSFILTER:
7741da177e4SLinus Torvalds 	{
7751da177e4SLinus Torvalds 		struct ip_msfilter *msf;
7761da177e4SLinus Torvalds 
7771da177e4SLinus Torvalds 		if (optlen < IP_MSFILTER_SIZE(0))
7781da177e4SLinus Torvalds 			goto e_inval;
7791da177e4SLinus Torvalds 		if (optlen > sysctl_optmem_max) {
7801da177e4SLinus Torvalds 			err = -ENOBUFS;
7811da177e4SLinus Torvalds 			break;
7821da177e4SLinus Torvalds 		}
7838b3a7005SKris Katterjohn 		msf = kmalloc(optlen, GFP_KERNEL);
784cfcabdccSStephen Hemminger 		if (!msf) {
7851da177e4SLinus Torvalds 			err = -ENOBUFS;
7861da177e4SLinus Torvalds 			break;
7871da177e4SLinus Torvalds 		}
7881da177e4SLinus Torvalds 		err = -EFAULT;
7891da177e4SLinus Torvalds 		if (copy_from_user(msf, optval, optlen)) {
7901da177e4SLinus Torvalds 			kfree(msf);
7911da177e4SLinus Torvalds 			break;
7921da177e4SLinus Torvalds 		}
7931da177e4SLinus Torvalds 		/* numsrc >= (1G-4) overflow in 32 bits */
7941da177e4SLinus Torvalds 		if (msf->imsf_numsrc >= 0x3ffffffcU ||
7951da177e4SLinus Torvalds 		    msf->imsf_numsrc > sysctl_igmp_max_msf) {
7961da177e4SLinus Torvalds 			kfree(msf);
7971da177e4SLinus Torvalds 			err = -ENOBUFS;
7981da177e4SLinus Torvalds 			break;
7991da177e4SLinus Torvalds 		}
8001da177e4SLinus Torvalds 		if (IP_MSFILTER_SIZE(msf->imsf_numsrc) > optlen) {
8011da177e4SLinus Torvalds 			kfree(msf);
8021da177e4SLinus Torvalds 			err = -EINVAL;
8031da177e4SLinus Torvalds 			break;
8041da177e4SLinus Torvalds 		}
8051da177e4SLinus Torvalds 		err = ip_mc_msfilter(sk, msf, 0);
8061da177e4SLinus Torvalds 		kfree(msf);
8071da177e4SLinus Torvalds 		break;
8081da177e4SLinus Torvalds 	}
8091da177e4SLinus Torvalds 	case IP_BLOCK_SOURCE:
8101da177e4SLinus Torvalds 	case IP_UNBLOCK_SOURCE:
8111da177e4SLinus Torvalds 	case IP_ADD_SOURCE_MEMBERSHIP:
8121da177e4SLinus Torvalds 	case IP_DROP_SOURCE_MEMBERSHIP:
8131da177e4SLinus Torvalds 	{
8141da177e4SLinus Torvalds 		struct ip_mreq_source mreqs;
8151da177e4SLinus Torvalds 		int omode, add;
8161da177e4SLinus Torvalds 
8171da177e4SLinus Torvalds 		if (optlen != sizeof(struct ip_mreq_source))
8181da177e4SLinus Torvalds 			goto e_inval;
8191da177e4SLinus Torvalds 		if (copy_from_user(&mreqs, optval, sizeof(mreqs))) {
8201da177e4SLinus Torvalds 			err = -EFAULT;
8211da177e4SLinus Torvalds 			break;
8221da177e4SLinus Torvalds 		}
8231da177e4SLinus Torvalds 		if (optname == IP_BLOCK_SOURCE) {
8241da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
8251da177e4SLinus Torvalds 			add = 1;
8261da177e4SLinus Torvalds 		} else if (optname == IP_UNBLOCK_SOURCE) {
8271da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
8281da177e4SLinus Torvalds 			add = 0;
8291da177e4SLinus Torvalds 		} else if (optname == IP_ADD_SOURCE_MEMBERSHIP) {
8301da177e4SLinus Torvalds 			struct ip_mreqn mreq;
8311da177e4SLinus Torvalds 
8321da177e4SLinus Torvalds 			mreq.imr_multiaddr.s_addr = mreqs.imr_multiaddr;
8331da177e4SLinus Torvalds 			mreq.imr_address.s_addr = mreqs.imr_interface;
8341da177e4SLinus Torvalds 			mreq.imr_ifindex = 0;
8351da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
8368cdaaa15SDavid L Stevens 			if (err && err != -EADDRINUSE)
8371da177e4SLinus Torvalds 				break;
8381da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
8391da177e4SLinus Torvalds 			add = 1;
8401da177e4SLinus Torvalds 		} else /* IP_DROP_SOURCE_MEMBERSHIP */ {
8411da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
8421da177e4SLinus Torvalds 			add = 0;
8431da177e4SLinus Torvalds 		}
8441da177e4SLinus Torvalds 		err = ip_mc_source(add, omode, sk, &mreqs, 0);
8451da177e4SLinus Torvalds 		break;
8461da177e4SLinus Torvalds 	}
8471da177e4SLinus Torvalds 	case MCAST_JOIN_GROUP:
8481da177e4SLinus Torvalds 	case MCAST_LEAVE_GROUP:
8491da177e4SLinus Torvalds 	{
8501da177e4SLinus Torvalds 		struct group_req greq;
8511da177e4SLinus Torvalds 		struct sockaddr_in *psin;
8521da177e4SLinus Torvalds 		struct ip_mreqn mreq;
8531da177e4SLinus Torvalds 
8541da177e4SLinus Torvalds 		if (optlen < sizeof(struct group_req))
8551da177e4SLinus Torvalds 			goto e_inval;
8561da177e4SLinus Torvalds 		err = -EFAULT;
8571da177e4SLinus Torvalds 		if (copy_from_user(&greq, optval, sizeof(greq)))
8581da177e4SLinus Torvalds 			break;
8591da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&greq.gr_group;
8601da177e4SLinus Torvalds 		if (psin->sin_family != AF_INET)
8611da177e4SLinus Torvalds 			goto e_inval;
8621da177e4SLinus Torvalds 		memset(&mreq, 0, sizeof(mreq));
8631da177e4SLinus Torvalds 		mreq.imr_multiaddr = psin->sin_addr;
8641da177e4SLinus Torvalds 		mreq.imr_ifindex = greq.gr_interface;
8651da177e4SLinus Torvalds 
8661da177e4SLinus Torvalds 		if (optname == MCAST_JOIN_GROUP)
8671da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
8681da177e4SLinus Torvalds 		else
8691da177e4SLinus Torvalds 			err = ip_mc_leave_group(sk, &mreq);
8701da177e4SLinus Torvalds 		break;
8711da177e4SLinus Torvalds 	}
8721da177e4SLinus Torvalds 	case MCAST_JOIN_SOURCE_GROUP:
8731da177e4SLinus Torvalds 	case MCAST_LEAVE_SOURCE_GROUP:
8741da177e4SLinus Torvalds 	case MCAST_BLOCK_SOURCE:
8751da177e4SLinus Torvalds 	case MCAST_UNBLOCK_SOURCE:
8761da177e4SLinus Torvalds 	{
8771da177e4SLinus Torvalds 		struct group_source_req greqs;
8781da177e4SLinus Torvalds 		struct ip_mreq_source mreqs;
8791da177e4SLinus Torvalds 		struct sockaddr_in *psin;
8801da177e4SLinus Torvalds 		int omode, add;
8811da177e4SLinus Torvalds 
8821da177e4SLinus Torvalds 		if (optlen != sizeof(struct group_source_req))
8831da177e4SLinus Torvalds 			goto e_inval;
8841da177e4SLinus Torvalds 		if (copy_from_user(&greqs, optval, sizeof(greqs))) {
8851da177e4SLinus Torvalds 			err = -EFAULT;
8861da177e4SLinus Torvalds 			break;
8871da177e4SLinus Torvalds 		}
8881da177e4SLinus Torvalds 		if (greqs.gsr_group.ss_family != AF_INET ||
8891da177e4SLinus Torvalds 		    greqs.gsr_source.ss_family != AF_INET) {
8901da177e4SLinus Torvalds 			err = -EADDRNOTAVAIL;
8911da177e4SLinus Torvalds 			break;
8921da177e4SLinus Torvalds 		}
8931da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&greqs.gsr_group;
8941da177e4SLinus Torvalds 		mreqs.imr_multiaddr = psin->sin_addr.s_addr;
8951da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&greqs.gsr_source;
8961da177e4SLinus Torvalds 		mreqs.imr_sourceaddr = psin->sin_addr.s_addr;
8971da177e4SLinus Torvalds 		mreqs.imr_interface = 0; /* use index for mc_source */
8981da177e4SLinus Torvalds 
8991da177e4SLinus Torvalds 		if (optname == MCAST_BLOCK_SOURCE) {
9001da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
9011da177e4SLinus Torvalds 			add = 1;
9021da177e4SLinus Torvalds 		} else if (optname == MCAST_UNBLOCK_SOURCE) {
9031da177e4SLinus Torvalds 			omode = MCAST_EXCLUDE;
9041da177e4SLinus Torvalds 			add = 0;
9051da177e4SLinus Torvalds 		} else if (optname == MCAST_JOIN_SOURCE_GROUP) {
9061da177e4SLinus Torvalds 			struct ip_mreqn mreq;
9071da177e4SLinus Torvalds 
9081da177e4SLinus Torvalds 			psin = (struct sockaddr_in *)&greqs.gsr_group;
9091da177e4SLinus Torvalds 			mreq.imr_multiaddr = psin->sin_addr;
9101da177e4SLinus Torvalds 			mreq.imr_address.s_addr = 0;
9111da177e4SLinus Torvalds 			mreq.imr_ifindex = greqs.gsr_interface;
9121da177e4SLinus Torvalds 			err = ip_mc_join_group(sk, &mreq);
9138cdaaa15SDavid L Stevens 			if (err && err != -EADDRINUSE)
9141da177e4SLinus Torvalds 				break;
9151da177e4SLinus Torvalds 			greqs.gsr_interface = mreq.imr_ifindex;
9161da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
9171da177e4SLinus Torvalds 			add = 1;
9181da177e4SLinus Torvalds 		} else /* MCAST_LEAVE_SOURCE_GROUP */ {
9191da177e4SLinus Torvalds 			omode = MCAST_INCLUDE;
9201da177e4SLinus Torvalds 			add = 0;
9211da177e4SLinus Torvalds 		}
9221da177e4SLinus Torvalds 		err = ip_mc_source(add, omode, sk, &mreqs,
9231da177e4SLinus Torvalds 				   greqs.gsr_interface);
9241da177e4SLinus Torvalds 		break;
9251da177e4SLinus Torvalds 	}
9261da177e4SLinus Torvalds 	case MCAST_MSFILTER:
9271da177e4SLinus Torvalds 	{
9281da177e4SLinus Torvalds 		struct sockaddr_in *psin;
9291da177e4SLinus Torvalds 		struct ip_msfilter *msf = NULL;
9301da177e4SLinus Torvalds 		struct group_filter *gsf = NULL;
9311da177e4SLinus Torvalds 		int msize, i, ifindex;
9321da177e4SLinus Torvalds 
9331da177e4SLinus Torvalds 		if (optlen < GROUP_FILTER_SIZE(0))
9341da177e4SLinus Torvalds 			goto e_inval;
9351da177e4SLinus Torvalds 		if (optlen > sysctl_optmem_max) {
9361da177e4SLinus Torvalds 			err = -ENOBUFS;
9371da177e4SLinus Torvalds 			break;
9381da177e4SLinus Torvalds 		}
9398b3a7005SKris Katterjohn 		gsf = kmalloc(optlen, GFP_KERNEL);
940cfcabdccSStephen Hemminger 		if (!gsf) {
9411da177e4SLinus Torvalds 			err = -ENOBUFS;
9421da177e4SLinus Torvalds 			break;
9431da177e4SLinus Torvalds 		}
9441da177e4SLinus Torvalds 		err = -EFAULT;
9454d52cfbeSEric Dumazet 		if (copy_from_user(gsf, optval, optlen))
9461da177e4SLinus Torvalds 			goto mc_msf_out;
9474d52cfbeSEric Dumazet 
9481da177e4SLinus Torvalds 		/* numsrc >= (4G-140)/128 overflow in 32 bits */
9491da177e4SLinus Torvalds 		if (gsf->gf_numsrc >= 0x1ffffff ||
9501da177e4SLinus Torvalds 		    gsf->gf_numsrc > sysctl_igmp_max_msf) {
9511da177e4SLinus Torvalds 			err = -ENOBUFS;
9521da177e4SLinus Torvalds 			goto mc_msf_out;
9531da177e4SLinus Torvalds 		}
9541da177e4SLinus Torvalds 		if (GROUP_FILTER_SIZE(gsf->gf_numsrc) > optlen) {
9551da177e4SLinus Torvalds 			err = -EINVAL;
9561da177e4SLinus Torvalds 			goto mc_msf_out;
9571da177e4SLinus Torvalds 		}
9581da177e4SLinus Torvalds 		msize = IP_MSFILTER_SIZE(gsf->gf_numsrc);
9598b3a7005SKris Katterjohn 		msf = kmalloc(msize, GFP_KERNEL);
960cfcabdccSStephen Hemminger 		if (!msf) {
9611da177e4SLinus Torvalds 			err = -ENOBUFS;
9621da177e4SLinus Torvalds 			goto mc_msf_out;
9631da177e4SLinus Torvalds 		}
9641da177e4SLinus Torvalds 		ifindex = gsf->gf_interface;
9651da177e4SLinus Torvalds 		psin = (struct sockaddr_in *)&gsf->gf_group;
9661da177e4SLinus Torvalds 		if (psin->sin_family != AF_INET) {
9671da177e4SLinus Torvalds 			err = -EADDRNOTAVAIL;
9681da177e4SLinus Torvalds 			goto mc_msf_out;
9691da177e4SLinus Torvalds 		}
9701da177e4SLinus Torvalds 		msf->imsf_multiaddr = psin->sin_addr.s_addr;
9711da177e4SLinus Torvalds 		msf->imsf_interface = 0;
9721da177e4SLinus Torvalds 		msf->imsf_fmode = gsf->gf_fmode;
9731da177e4SLinus Torvalds 		msf->imsf_numsrc = gsf->gf_numsrc;
9741da177e4SLinus Torvalds 		err = -EADDRNOTAVAIL;
9751da177e4SLinus Torvalds 		for (i = 0; i < gsf->gf_numsrc; ++i) {
9761da177e4SLinus Torvalds 			psin = (struct sockaddr_in *)&gsf->gf_slist[i];
9771da177e4SLinus Torvalds 
9781da177e4SLinus Torvalds 			if (psin->sin_family != AF_INET)
9791da177e4SLinus Torvalds 				goto mc_msf_out;
9801da177e4SLinus Torvalds 			msf->imsf_slist[i] = psin->sin_addr.s_addr;
9811da177e4SLinus Torvalds 		}
9821da177e4SLinus Torvalds 		kfree(gsf);
9831da177e4SLinus Torvalds 		gsf = NULL;
9841da177e4SLinus Torvalds 
9851da177e4SLinus Torvalds 		err = ip_mc_msfilter(sk, msf, ifindex);
9861da177e4SLinus Torvalds mc_msf_out:
9871da177e4SLinus Torvalds 		kfree(msf);
9881da177e4SLinus Torvalds 		kfree(gsf);
9891da177e4SLinus Torvalds 		break;
9901da177e4SLinus Torvalds 	}
991f771bef9SNivedita Singhvi 	case IP_MULTICAST_ALL:
992f771bef9SNivedita Singhvi 		if (optlen < 1)
993f771bef9SNivedita Singhvi 			goto e_inval;
994f771bef9SNivedita Singhvi 		if (val != 0 && val != 1)
995f771bef9SNivedita Singhvi 			goto e_inval;
996f771bef9SNivedita Singhvi 		inet->mc_all = val;
997f771bef9SNivedita Singhvi 		break;
9981da177e4SLinus Torvalds 	case IP_ROUTER_ALERT:
9991da177e4SLinus Torvalds 		err = ip_ra_control(sk, val ? 1 : 0, NULL);
10001da177e4SLinus Torvalds 		break;
10011da177e4SLinus Torvalds 
10021da177e4SLinus Torvalds 	case IP_FREEBIND:
10031da177e4SLinus Torvalds 		if (optlen < 1)
10041da177e4SLinus Torvalds 			goto e_inval;
10051da177e4SLinus Torvalds 		inet->freebind = !!val;
10061da177e4SLinus Torvalds 		break;
10071da177e4SLinus Torvalds 
10081da177e4SLinus Torvalds 	case IP_IPSEC_POLICY:
10091da177e4SLinus Torvalds 	case IP_XFRM_POLICY:
10106fc0b4a7SHerbert Xu 		err = -EPERM;
101152e804c6SEric W. Biederman 		if (!ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN))
10126fc0b4a7SHerbert Xu 			break;
10131da177e4SLinus Torvalds 		err = xfrm_user_policy(sk, optname, optval, optlen);
10141da177e4SLinus Torvalds 		break;
10151da177e4SLinus Torvalds 
1016f5715aeaSKOVACS Krisztian 	case IP_TRANSPARENT:
101752e804c6SEric W. Biederman 		if (!!val && !ns_capable(sock_net(sk)->user_ns, CAP_NET_RAW) &&
101852e804c6SEric W. Biederman 		    !ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN)) {
1019f5715aeaSKOVACS Krisztian 			err = -EPERM;
1020f5715aeaSKOVACS Krisztian 			break;
1021f5715aeaSKOVACS Krisztian 		}
1022f5715aeaSKOVACS Krisztian 		if (optlen < 1)
1023f5715aeaSKOVACS Krisztian 			goto e_inval;
1024f5715aeaSKOVACS Krisztian 		inet->transparent = !!val;
1025f5715aeaSKOVACS Krisztian 		break;
1026f5715aeaSKOVACS Krisztian 
1027d218d111SStephen Hemminger 	case IP_MINTTL:
1028d218d111SStephen Hemminger 		if (optlen < 1)
1029d218d111SStephen Hemminger 			goto e_inval;
1030d218d111SStephen Hemminger 		if (val < 0 || val > 255)
1031d218d111SStephen Hemminger 			goto e_inval;
1032d218d111SStephen Hemminger 		inet->min_ttl = val;
1033d218d111SStephen Hemminger 		break;
1034d218d111SStephen Hemminger 
10351da177e4SLinus Torvalds 	default:
10361da177e4SLinus Torvalds 		err = -ENOPROTOOPT;
10371da177e4SLinus Torvalds 		break;
10381da177e4SLinus Torvalds 	}
10391da177e4SLinus Torvalds 	release_sock(sk);
10401da177e4SLinus Torvalds 	return err;
10411da177e4SLinus Torvalds 
10421da177e4SLinus Torvalds e_inval:
10431da177e4SLinus Torvalds 	release_sock(sk);
10441da177e4SLinus Torvalds 	return -EINVAL;
10451da177e4SLinus Torvalds }
10461da177e4SLinus Torvalds 
1047f84af32cSEric Dumazet /**
1048d826eb14SEric Dumazet  * ipv4_pktinfo_prepare - transfert some info from rtable to skb
1049f84af32cSEric Dumazet  * @sk: socket
1050f84af32cSEric Dumazet  * @skb: buffer
1051f84af32cSEric Dumazet  *
105235ebf65eSDavid S. Miller  * To support IP_CMSG_PKTINFO option, we store rt_iif and specific
105335ebf65eSDavid S. Miller  * destination in skb->cb[] before dst drop.
1054*8e3bff96Sstephen hemminger  * This way, receiver doesn't make cache line misses to read rtable.
1055f84af32cSEric Dumazet  */
1056fbf8866dSShawn Bohrer void ipv4_pktinfo_prepare(const struct sock *sk, struct sk_buff *skb)
1057f84af32cSEric Dumazet {
1058d826eb14SEric Dumazet 	struct in_pktinfo *pktinfo = PKTINFO_SKB_CB(skb);
1059d826eb14SEric Dumazet 
1060fbf8866dSShawn Bohrer 	if ((inet_sk(sk)->cmsg_flags & IP_CMSG_PKTINFO) &&
1061fbf8866dSShawn Bohrer 	    skb_rtable(skb)) {
106292101b3bSDavid S. Miller 		pktinfo->ipi_ifindex = inet_iif(skb);
106335ebf65eSDavid S. Miller 		pktinfo->ipi_spec_dst.s_addr = fib_compute_spec_dst(skb);
1064d826eb14SEric Dumazet 	} else {
1065d826eb14SEric Dumazet 		pktinfo->ipi_ifindex = 0;
1066d826eb14SEric Dumazet 		pktinfo->ipi_spec_dst.s_addr = 0;
1067f84af32cSEric Dumazet 	}
1068d826eb14SEric Dumazet 	skb_dst_drop(skb);
1069d826eb14SEric Dumazet }
1070f84af32cSEric Dumazet 
10713fdadf7dSDmitry Mishin int ip_setsockopt(struct sock *sk, int level,
1072b7058842SDavid S. Miller 		int optname, char __user *optval, unsigned int optlen)
10733fdadf7dSDmitry Mishin {
10743fdadf7dSDmitry Mishin 	int err;
10753fdadf7dSDmitry Mishin 
10763fdadf7dSDmitry Mishin 	if (level != SOL_IP)
10773fdadf7dSDmitry Mishin 		return -ENOPROTOOPT;
10783fdadf7dSDmitry Mishin 
10793fdadf7dSDmitry Mishin 	err = do_ip_setsockopt(sk, level, optname, optval, optlen);
10803fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
10813fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
10823fdadf7dSDmitry Mishin 	if (err == -ENOPROTOOPT && optname != IP_HDRINCL &&
10836a9fb947SPavel Emelyanov 			optname != IP_IPSEC_POLICY &&
10846a9fb947SPavel Emelyanov 			optname != IP_XFRM_POLICY &&
10856a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
10863fdadf7dSDmitry Mishin 		lock_sock(sk);
10873fdadf7dSDmitry Mishin 		err = nf_setsockopt(sk, PF_INET, optname, optval, optlen);
10883fdadf7dSDmitry Mishin 		release_sock(sk);
10893fdadf7dSDmitry Mishin 	}
10903fdadf7dSDmitry Mishin #endif
10913fdadf7dSDmitry Mishin 	return err;
10923fdadf7dSDmitry Mishin }
10934d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_setsockopt);
10943fdadf7dSDmitry Mishin 
10953fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT
1096543d9cfeSArnaldo Carvalho de Melo int compat_ip_setsockopt(struct sock *sk, int level, int optname,
1097b7058842SDavid S. Miller 			 char __user *optval, unsigned int optlen)
10983fdadf7dSDmitry Mishin {
10993fdadf7dSDmitry Mishin 	int err;
11003fdadf7dSDmitry Mishin 
11013fdadf7dSDmitry Mishin 	if (level != SOL_IP)
11023fdadf7dSDmitry Mishin 		return -ENOPROTOOPT;
11033fdadf7dSDmitry Mishin 
1104dae50295SDavid L Stevens 	if (optname >= MCAST_JOIN_GROUP && optname <= MCAST_MSFILTER)
1105dae50295SDavid L Stevens 		return compat_mc_setsockopt(sk, level, optname, optval, optlen,
1106dae50295SDavid L Stevens 			ip_setsockopt);
1107dae50295SDavid L Stevens 
11083fdadf7dSDmitry Mishin 	err = do_ip_setsockopt(sk, level, optname, optval, optlen);
11093fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
11103fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
11113fdadf7dSDmitry Mishin 	if (err == -ENOPROTOOPT && optname != IP_HDRINCL &&
11126a9fb947SPavel Emelyanov 			optname != IP_IPSEC_POLICY &&
11136a9fb947SPavel Emelyanov 			optname != IP_XFRM_POLICY &&
11146a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
11153fdadf7dSDmitry Mishin 		lock_sock(sk);
1116543d9cfeSArnaldo Carvalho de Melo 		err = compat_nf_setsockopt(sk, PF_INET, optname,
1117543d9cfeSArnaldo Carvalho de Melo 					   optval, optlen);
11183fdadf7dSDmitry Mishin 		release_sock(sk);
11193fdadf7dSDmitry Mishin 	}
11203fdadf7dSDmitry Mishin #endif
11213fdadf7dSDmitry Mishin 	return err;
11223fdadf7dSDmitry Mishin }
1123543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_setsockopt);
11243fdadf7dSDmitry Mishin #endif
11253fdadf7dSDmitry Mishin 
11261da177e4SLinus Torvalds /*
11274d52cfbeSEric Dumazet  *	Get the options. Note for future reference. The GET of IP options gets
11284d52cfbeSEric Dumazet  *	the _received_ ones. The set sets the _sent_ ones.
11291da177e4SLinus Torvalds  */
11301da177e4SLinus Torvalds 
11313fdadf7dSDmitry Mishin static int do_ip_getsockopt(struct sock *sk, int level, int optname,
113295c96174SEric Dumazet 			    char __user *optval, int __user *optlen, unsigned int flags)
11331da177e4SLinus Torvalds {
11341da177e4SLinus Torvalds 	struct inet_sock *inet = inet_sk(sk);
11351da177e4SLinus Torvalds 	int val;
11361da177e4SLinus Torvalds 	int len;
11371da177e4SLinus Torvalds 
11381da177e4SLinus Torvalds 	if (level != SOL_IP)
11391da177e4SLinus Torvalds 		return -EOPNOTSUPP;
11401da177e4SLinus Torvalds 
11416a9fb947SPavel Emelyanov 	if (ip_mroute_opt(optname))
11421da177e4SLinus Torvalds 		return ip_mroute_getsockopt(sk, optname, optval, optlen);
11431da177e4SLinus Torvalds 
11441da177e4SLinus Torvalds 	if (get_user(len, optlen))
11451da177e4SLinus Torvalds 		return -EFAULT;
11461da177e4SLinus Torvalds 	if (len < 0)
11471da177e4SLinus Torvalds 		return -EINVAL;
11481da177e4SLinus Torvalds 
11491da177e4SLinus Torvalds 	lock_sock(sk);
11501da177e4SLinus Torvalds 
11511da177e4SLinus Torvalds 	switch (optname) {
11521da177e4SLinus Torvalds 	case IP_OPTIONS:
11531da177e4SLinus Torvalds 	{
11541da177e4SLinus Torvalds 		unsigned char optbuf[sizeof(struct ip_options)+40];
11551da177e4SLinus Torvalds 		struct ip_options *opt = (struct ip_options *)optbuf;
1156f6d8bd05SEric Dumazet 		struct ip_options_rcu *inet_opt;
1157f6d8bd05SEric Dumazet 
1158f6d8bd05SEric Dumazet 		inet_opt = rcu_dereference_protected(inet->inet_opt,
1159f6d8bd05SEric Dumazet 						     sock_owned_by_user(sk));
11601da177e4SLinus Torvalds 		opt->optlen = 0;
1161f6d8bd05SEric Dumazet 		if (inet_opt)
1162f6d8bd05SEric Dumazet 			memcpy(optbuf, &inet_opt->opt,
11631da177e4SLinus Torvalds 			       sizeof(struct ip_options) +
1164f6d8bd05SEric Dumazet 			       inet_opt->opt.optlen);
11651da177e4SLinus Torvalds 		release_sock(sk);
11661da177e4SLinus Torvalds 
11671da177e4SLinus Torvalds 		if (opt->optlen == 0)
11681da177e4SLinus Torvalds 			return put_user(0, optlen);
11691da177e4SLinus Torvalds 
11701da177e4SLinus Torvalds 		ip_options_undo(opt);
11711da177e4SLinus Torvalds 
11721da177e4SLinus Torvalds 		len = min_t(unsigned int, len, opt->optlen);
11731da177e4SLinus Torvalds 		if (put_user(len, optlen))
11741da177e4SLinus Torvalds 			return -EFAULT;
11751da177e4SLinus Torvalds 		if (copy_to_user(optval, opt->__data, len))
11761da177e4SLinus Torvalds 			return -EFAULT;
11771da177e4SLinus Torvalds 		return 0;
11781da177e4SLinus Torvalds 	}
11791da177e4SLinus Torvalds 	case IP_PKTINFO:
11801da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_PKTINFO) != 0;
11811da177e4SLinus Torvalds 		break;
11821da177e4SLinus Torvalds 	case IP_RECVTTL:
11831da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_TTL) != 0;
11841da177e4SLinus Torvalds 		break;
11851da177e4SLinus Torvalds 	case IP_RECVTOS:
11861da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_TOS) != 0;
11871da177e4SLinus Torvalds 		break;
11881da177e4SLinus Torvalds 	case IP_RECVOPTS:
11891da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_RECVOPTS) != 0;
11901da177e4SLinus Torvalds 		break;
11911da177e4SLinus Torvalds 	case IP_RETOPTS:
11921da177e4SLinus Torvalds 		val = (inet->cmsg_flags & IP_CMSG_RETOPTS) != 0;
11931da177e4SLinus Torvalds 		break;
11942c7946a7SCatherine Zhang 	case IP_PASSSEC:
11952c7946a7SCatherine Zhang 		val = (inet->cmsg_flags & IP_CMSG_PASSSEC) != 0;
11962c7946a7SCatherine Zhang 		break;
1197e8b2dfe9SBalazs Scheidler 	case IP_RECVORIGDSTADDR:
1198e8b2dfe9SBalazs Scheidler 		val = (inet->cmsg_flags & IP_CMSG_ORIGDSTADDR) != 0;
1199e8b2dfe9SBalazs Scheidler 		break;
12001da177e4SLinus Torvalds 	case IP_TOS:
12011da177e4SLinus Torvalds 		val = inet->tos;
12021da177e4SLinus Torvalds 		break;
12031da177e4SLinus Torvalds 	case IP_TTL:
12041da177e4SLinus Torvalds 		val = (inet->uc_ttl == -1 ?
12051da177e4SLinus Torvalds 		       sysctl_ip_default_ttl :
12061da177e4SLinus Torvalds 		       inet->uc_ttl);
12071da177e4SLinus Torvalds 		break;
12081da177e4SLinus Torvalds 	case IP_HDRINCL:
12091da177e4SLinus Torvalds 		val = inet->hdrincl;
12101da177e4SLinus Torvalds 		break;
1211a89b4763SMichael Kerrisk 	case IP_NODEFRAG:
1212a89b4763SMichael Kerrisk 		val = inet->nodefrag;
1213a89b4763SMichael Kerrisk 		break;
12141da177e4SLinus Torvalds 	case IP_MTU_DISCOVER:
12151da177e4SLinus Torvalds 		val = inet->pmtudisc;
12161da177e4SLinus Torvalds 		break;
12171da177e4SLinus Torvalds 	case IP_MTU:
12181da177e4SLinus Torvalds 	{
12191da177e4SLinus Torvalds 		struct dst_entry *dst;
12201da177e4SLinus Torvalds 		val = 0;
12211da177e4SLinus Torvalds 		dst = sk_dst_get(sk);
12221da177e4SLinus Torvalds 		if (dst) {
12231da177e4SLinus Torvalds 			val = dst_mtu(dst);
12241da177e4SLinus Torvalds 			dst_release(dst);
12251da177e4SLinus Torvalds 		}
12261da177e4SLinus Torvalds 		if (!val) {
12271da177e4SLinus Torvalds 			release_sock(sk);
12281da177e4SLinus Torvalds 			return -ENOTCONN;
12291da177e4SLinus Torvalds 		}
12301da177e4SLinus Torvalds 		break;
12311da177e4SLinus Torvalds 	}
12321da177e4SLinus Torvalds 	case IP_RECVERR:
12331da177e4SLinus Torvalds 		val = inet->recverr;
12341da177e4SLinus Torvalds 		break;
12351da177e4SLinus Torvalds 	case IP_MULTICAST_TTL:
12361da177e4SLinus Torvalds 		val = inet->mc_ttl;
12371da177e4SLinus Torvalds 		break;
12381da177e4SLinus Torvalds 	case IP_MULTICAST_LOOP:
12391da177e4SLinus Torvalds 		val = inet->mc_loop;
12401da177e4SLinus Torvalds 		break;
124176e21053SErich E. Hoover 	case IP_UNICAST_IF:
124276e21053SErich E. Hoover 		val = (__force int)htonl((__u32) inet->uc_index);
124376e21053SErich E. Hoover 		break;
12441da177e4SLinus Torvalds 	case IP_MULTICAST_IF:
12451da177e4SLinus Torvalds 	{
12461da177e4SLinus Torvalds 		struct in_addr addr;
12471da177e4SLinus Torvalds 		len = min_t(unsigned int, len, sizeof(struct in_addr));
12481da177e4SLinus Torvalds 		addr.s_addr = inet->mc_addr;
12491da177e4SLinus Torvalds 		release_sock(sk);
12501da177e4SLinus Torvalds 
12511da177e4SLinus Torvalds 		if (put_user(len, optlen))
12521da177e4SLinus Torvalds 			return -EFAULT;
12531da177e4SLinus Torvalds 		if (copy_to_user(optval, &addr, len))
12541da177e4SLinus Torvalds 			return -EFAULT;
12551da177e4SLinus Torvalds 		return 0;
12561da177e4SLinus Torvalds 	}
12571da177e4SLinus Torvalds 	case IP_MSFILTER:
12581da177e4SLinus Torvalds 	{
12591da177e4SLinus Torvalds 		struct ip_msfilter msf;
12601da177e4SLinus Torvalds 		int err;
12611da177e4SLinus Torvalds 
12621da177e4SLinus Torvalds 		if (len < IP_MSFILTER_SIZE(0)) {
12631da177e4SLinus Torvalds 			release_sock(sk);
12641da177e4SLinus Torvalds 			return -EINVAL;
12651da177e4SLinus Torvalds 		}
12661da177e4SLinus Torvalds 		if (copy_from_user(&msf, optval, IP_MSFILTER_SIZE(0))) {
12671da177e4SLinus Torvalds 			release_sock(sk);
12681da177e4SLinus Torvalds 			return -EFAULT;
12691da177e4SLinus Torvalds 		}
12701da177e4SLinus Torvalds 		err = ip_mc_msfget(sk, &msf,
12711da177e4SLinus Torvalds 				   (struct ip_msfilter __user *)optval, optlen);
12721da177e4SLinus Torvalds 		release_sock(sk);
12731da177e4SLinus Torvalds 		return err;
12741da177e4SLinus Torvalds 	}
12751da177e4SLinus Torvalds 	case MCAST_MSFILTER:
12761da177e4SLinus Torvalds 	{
12771da177e4SLinus Torvalds 		struct group_filter gsf;
12781da177e4SLinus Torvalds 		int err;
12791da177e4SLinus Torvalds 
12801da177e4SLinus Torvalds 		if (len < GROUP_FILTER_SIZE(0)) {
12811da177e4SLinus Torvalds 			release_sock(sk);
12821da177e4SLinus Torvalds 			return -EINVAL;
12831da177e4SLinus Torvalds 		}
12841da177e4SLinus Torvalds 		if (copy_from_user(&gsf, optval, GROUP_FILTER_SIZE(0))) {
12851da177e4SLinus Torvalds 			release_sock(sk);
12861da177e4SLinus Torvalds 			return -EFAULT;
12871da177e4SLinus Torvalds 		}
12881da177e4SLinus Torvalds 		err = ip_mc_gsfget(sk, &gsf,
12894d52cfbeSEric Dumazet 				   (struct group_filter __user *)optval,
12904d52cfbeSEric Dumazet 				   optlen);
12911da177e4SLinus Torvalds 		release_sock(sk);
12921da177e4SLinus Torvalds 		return err;
12931da177e4SLinus Torvalds 	}
1294f771bef9SNivedita Singhvi 	case IP_MULTICAST_ALL:
1295f771bef9SNivedita Singhvi 		val = inet->mc_all;
1296f771bef9SNivedita Singhvi 		break;
12971da177e4SLinus Torvalds 	case IP_PKTOPTIONS:
12981da177e4SLinus Torvalds 	{
12991da177e4SLinus Torvalds 		struct msghdr msg;
13001da177e4SLinus Torvalds 
13011da177e4SLinus Torvalds 		release_sock(sk);
13021da177e4SLinus Torvalds 
13031da177e4SLinus Torvalds 		if (sk->sk_type != SOCK_STREAM)
13041da177e4SLinus Torvalds 			return -ENOPROTOOPT;
13051da177e4SLinus Torvalds 
13061da177e4SLinus Torvalds 		msg.msg_control = optval;
13071da177e4SLinus Torvalds 		msg.msg_controllen = len;
1308dd23198eSDaniel Baluta 		msg.msg_flags = flags;
13091da177e4SLinus Torvalds 
13101da177e4SLinus Torvalds 		if (inet->cmsg_flags & IP_CMSG_PKTINFO) {
13111da177e4SLinus Torvalds 			struct in_pktinfo info;
13121da177e4SLinus Torvalds 
1313c720c7e8SEric Dumazet 			info.ipi_addr.s_addr = inet->inet_rcv_saddr;
1314c720c7e8SEric Dumazet 			info.ipi_spec_dst.s_addr = inet->inet_rcv_saddr;
13151da177e4SLinus Torvalds 			info.ipi_ifindex = inet->mc_index;
13161da177e4SLinus Torvalds 			put_cmsg(&msg, SOL_IP, IP_PKTINFO, sizeof(info), &info);
13171da177e4SLinus Torvalds 		}
13181da177e4SLinus Torvalds 		if (inet->cmsg_flags & IP_CMSG_TTL) {
13191da177e4SLinus Torvalds 			int hlim = inet->mc_ttl;
13201da177e4SLinus Torvalds 			put_cmsg(&msg, SOL_IP, IP_TTL, sizeof(hlim), &hlim);
13211da177e4SLinus Torvalds 		}
13224c507d28SJiri Benc 		if (inet->cmsg_flags & IP_CMSG_TOS) {
13234c507d28SJiri Benc 			int tos = inet->rcv_tos;
13244c507d28SJiri Benc 			put_cmsg(&msg, SOL_IP, IP_TOS, sizeof(tos), &tos);
13254c507d28SJiri Benc 		}
13261da177e4SLinus Torvalds 		len -= msg.msg_controllen;
13271da177e4SLinus Torvalds 		return put_user(len, optlen);
13281da177e4SLinus Torvalds 	}
13291da177e4SLinus Torvalds 	case IP_FREEBIND:
13301da177e4SLinus Torvalds 		val = inet->freebind;
13311da177e4SLinus Torvalds 		break;
1332f5715aeaSKOVACS Krisztian 	case IP_TRANSPARENT:
1333f5715aeaSKOVACS Krisztian 		val = inet->transparent;
1334f5715aeaSKOVACS Krisztian 		break;
1335d218d111SStephen Hemminger 	case IP_MINTTL:
1336d218d111SStephen Hemminger 		val = inet->min_ttl;
1337d218d111SStephen Hemminger 		break;
13381da177e4SLinus Torvalds 	default:
13391da177e4SLinus Torvalds 		release_sock(sk);
13401da177e4SLinus Torvalds 		return -ENOPROTOOPT;
13411da177e4SLinus Torvalds 	}
13421da177e4SLinus Torvalds 	release_sock(sk);
13431da177e4SLinus Torvalds 
1344951e07c9SDavid S. Miller 	if (len < sizeof(int) && len > 0 && val >= 0 && val <= 255) {
13451da177e4SLinus Torvalds 		unsigned char ucval = (unsigned char)val;
13461da177e4SLinus Torvalds 		len = 1;
13471da177e4SLinus Torvalds 		if (put_user(len, optlen))
13481da177e4SLinus Torvalds 			return -EFAULT;
13491da177e4SLinus Torvalds 		if (copy_to_user(optval, &ucval, 1))
13501da177e4SLinus Torvalds 			return -EFAULT;
13511da177e4SLinus Torvalds 	} else {
13521da177e4SLinus Torvalds 		len = min_t(unsigned int, sizeof(int), len);
13531da177e4SLinus Torvalds 		if (put_user(len, optlen))
13541da177e4SLinus Torvalds 			return -EFAULT;
13551da177e4SLinus Torvalds 		if (copy_to_user(optval, &val, len))
13561da177e4SLinus Torvalds 			return -EFAULT;
13571da177e4SLinus Torvalds 	}
13581da177e4SLinus Torvalds 	return 0;
13591da177e4SLinus Torvalds }
13601da177e4SLinus Torvalds 
13613fdadf7dSDmitry Mishin int ip_getsockopt(struct sock *sk, int level,
13623fdadf7dSDmitry Mishin 		  int optname, char __user *optval, int __user *optlen)
13633fdadf7dSDmitry Mishin {
13643fdadf7dSDmitry Mishin 	int err;
13653fdadf7dSDmitry Mishin 
1366dd23198eSDaniel Baluta 	err = do_ip_getsockopt(sk, level, optname, optval, optlen, 0);
13673fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
13683fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
13696a9fb947SPavel Emelyanov 	if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS &&
13706a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
13713fdadf7dSDmitry Mishin 		int len;
13723fdadf7dSDmitry Mishin 
13733fdadf7dSDmitry Mishin 		if (get_user(len, optlen))
13743fdadf7dSDmitry Mishin 			return -EFAULT;
13753fdadf7dSDmitry Mishin 
13763fdadf7dSDmitry Mishin 		lock_sock(sk);
13773fdadf7dSDmitry Mishin 		err = nf_getsockopt(sk, PF_INET, optname, optval,
13783fdadf7dSDmitry Mishin 				&len);
13793fdadf7dSDmitry Mishin 		release_sock(sk);
13803fdadf7dSDmitry Mishin 		if (err >= 0)
13813fdadf7dSDmitry Mishin 			err = put_user(len, optlen);
13823fdadf7dSDmitry Mishin 		return err;
13833fdadf7dSDmitry Mishin 	}
13843fdadf7dSDmitry Mishin #endif
13853fdadf7dSDmitry Mishin 	return err;
13863fdadf7dSDmitry Mishin }
13874d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_getsockopt);
13883fdadf7dSDmitry Mishin 
13893fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT
1390543d9cfeSArnaldo Carvalho de Melo int compat_ip_getsockopt(struct sock *sk, int level, int optname,
1391543d9cfeSArnaldo Carvalho de Melo 			 char __user *optval, int __user *optlen)
13923fdadf7dSDmitry Mishin {
139342908c69SDavid L Stevens 	int err;
139442908c69SDavid L Stevens 
139542908c69SDavid L Stevens 	if (optname == MCAST_MSFILTER)
139642908c69SDavid L Stevens 		return compat_mc_getsockopt(sk, level, optname, optval, optlen,
139742908c69SDavid L Stevens 			ip_getsockopt);
139842908c69SDavid L Stevens 
1399dd23198eSDaniel Baluta 	err = do_ip_getsockopt(sk, level, optname, optval, optlen,
1400dd23198eSDaniel Baluta 		MSG_CMSG_COMPAT);
140142908c69SDavid L Stevens 
14023fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER
14033fdadf7dSDmitry Mishin 	/* we need to exclude all possible ENOPROTOOPTs except default case */
14046a9fb947SPavel Emelyanov 	if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS &&
14056a9fb947SPavel Emelyanov 			!ip_mroute_opt(optname)) {
14063fdadf7dSDmitry Mishin 		int len;
14073fdadf7dSDmitry Mishin 
14083fdadf7dSDmitry Mishin 		if (get_user(len, optlen))
14093fdadf7dSDmitry Mishin 			return -EFAULT;
14103fdadf7dSDmitry Mishin 
14113fdadf7dSDmitry Mishin 		lock_sock(sk);
1412543d9cfeSArnaldo Carvalho de Melo 		err = compat_nf_getsockopt(sk, PF_INET, optname, optval, &len);
14133fdadf7dSDmitry Mishin 		release_sock(sk);
14143fdadf7dSDmitry Mishin 		if (err >= 0)
14153fdadf7dSDmitry Mishin 			err = put_user(len, optlen);
14163fdadf7dSDmitry Mishin 		return err;
14173fdadf7dSDmitry Mishin 	}
14183fdadf7dSDmitry Mishin #endif
14193fdadf7dSDmitry Mishin 	return err;
14203fdadf7dSDmitry Mishin }
1421543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_getsockopt);
14223fdadf7dSDmitry Mishin #endif
1423