11da177e4SLinus Torvalds /* 21da177e4SLinus Torvalds * INET An implementation of the TCP/IP protocol suite for the LINUX 31da177e4SLinus Torvalds * operating system. INET is implemented using the BSD Socket 41da177e4SLinus Torvalds * interface as the means of communication with the user level. 51da177e4SLinus Torvalds * 61da177e4SLinus Torvalds * The IP to API glue. 71da177e4SLinus Torvalds * 81da177e4SLinus Torvalds * Authors: see ip.c 91da177e4SLinus Torvalds * 101da177e4SLinus Torvalds * Fixes: 111da177e4SLinus Torvalds * Many : Split from ip.c , see ip.c for history. 121da177e4SLinus Torvalds * Martin Mares : TOS setting fixed. 131da177e4SLinus Torvalds * Alan Cox : Fixed a couple of oopses in Martin's 141da177e4SLinus Torvalds * TOS tweaks. 151da177e4SLinus Torvalds * Mike McLagan : Routing by source 161da177e4SLinus Torvalds */ 171da177e4SLinus Torvalds 181da177e4SLinus Torvalds #include <linux/module.h> 191da177e4SLinus Torvalds #include <linux/types.h> 201da177e4SLinus Torvalds #include <linux/mm.h> 211da177e4SLinus Torvalds #include <linux/skbuff.h> 221da177e4SLinus Torvalds #include <linux/ip.h> 231da177e4SLinus Torvalds #include <linux/icmp.h> 2414c85021SArnaldo Carvalho de Melo #include <linux/inetdevice.h> 251da177e4SLinus Torvalds #include <linux/netdevice.h> 265a0e3ad6STejun Heo #include <linux/slab.h> 271da177e4SLinus Torvalds #include <net/sock.h> 281da177e4SLinus Torvalds #include <net/ip.h> 291da177e4SLinus Torvalds #include <net/icmp.h> 30d83d8461SArnaldo Carvalho de Melo #include <net/tcp_states.h> 311da177e4SLinus Torvalds #include <linux/udp.h> 321da177e4SLinus Torvalds #include <linux/igmp.h> 331da177e4SLinus Torvalds #include <linux/netfilter.h> 341da177e4SLinus Torvalds #include <linux/route.h> 351da177e4SLinus Torvalds #include <linux/mroute.h> 362c67e9acSMaciej Żenczykowski #include <net/inet_ecn.h> 371da177e4SLinus Torvalds #include <net/route.h> 381da177e4SLinus Torvalds #include <net/xfrm.h> 39dae50295SDavid L Stevens #include <net/compat.h> 40dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6) 411da177e4SLinus Torvalds #include <net/transp_v6.h> 421da177e4SLinus Torvalds #endif 4335ebf65eSDavid S. Miller #include <net/ip_fib.h> 441da177e4SLinus Torvalds 451da177e4SLinus Torvalds #include <linux/errqueue.h> 461da177e4SLinus Torvalds #include <asm/uaccess.h> 471da177e4SLinus Torvalds 481da177e4SLinus Torvalds #define IP_CMSG_PKTINFO 1 491da177e4SLinus Torvalds #define IP_CMSG_TTL 2 501da177e4SLinus Torvalds #define IP_CMSG_TOS 4 511da177e4SLinus Torvalds #define IP_CMSG_RECVOPTS 8 521da177e4SLinus Torvalds #define IP_CMSG_RETOPTS 16 532c7946a7SCatherine Zhang #define IP_CMSG_PASSSEC 32 54e8b2dfe9SBalazs Scheidler #define IP_CMSG_ORIGDSTADDR 64 551da177e4SLinus Torvalds 561da177e4SLinus Torvalds /* 571da177e4SLinus Torvalds * SOL_IP control messages. 581da177e4SLinus Torvalds */ 59d826eb14SEric Dumazet #define PKTINFO_SKB_CB(__skb) ((struct in_pktinfo *)((__skb)->cb)) 601da177e4SLinus Torvalds 611da177e4SLinus Torvalds static void ip_cmsg_recv_pktinfo(struct msghdr *msg, struct sk_buff *skb) 621da177e4SLinus Torvalds { 63d826eb14SEric Dumazet struct in_pktinfo info = *PKTINFO_SKB_CB(skb); 641da177e4SLinus Torvalds 65eddc9ec5SArnaldo Carvalho de Melo info.ipi_addr.s_addr = ip_hdr(skb)->daddr; 661da177e4SLinus Torvalds 671da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_PKTINFO, sizeof(info), &info); 681da177e4SLinus Torvalds } 691da177e4SLinus Torvalds 701da177e4SLinus Torvalds static void ip_cmsg_recv_ttl(struct msghdr *msg, struct sk_buff *skb) 711da177e4SLinus Torvalds { 72eddc9ec5SArnaldo Carvalho de Melo int ttl = ip_hdr(skb)->ttl; 731da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_TTL, sizeof(int), &ttl); 741da177e4SLinus Torvalds } 751da177e4SLinus Torvalds 761da177e4SLinus Torvalds static void ip_cmsg_recv_tos(struct msghdr *msg, struct sk_buff *skb) 771da177e4SLinus Torvalds { 78eddc9ec5SArnaldo Carvalho de Melo put_cmsg(msg, SOL_IP, IP_TOS, 1, &ip_hdr(skb)->tos); 791da177e4SLinus Torvalds } 801da177e4SLinus Torvalds 811da177e4SLinus Torvalds static void ip_cmsg_recv_opts(struct msghdr *msg, struct sk_buff *skb) 821da177e4SLinus Torvalds { 831da177e4SLinus Torvalds if (IPCB(skb)->opt.optlen == 0) 841da177e4SLinus Torvalds return; 851da177e4SLinus Torvalds 86eddc9ec5SArnaldo Carvalho de Melo put_cmsg(msg, SOL_IP, IP_RECVOPTS, IPCB(skb)->opt.optlen, 87eddc9ec5SArnaldo Carvalho de Melo ip_hdr(skb) + 1); 881da177e4SLinus Torvalds } 891da177e4SLinus Torvalds 901da177e4SLinus Torvalds 911da177e4SLinus Torvalds static void ip_cmsg_recv_retopts(struct msghdr *msg, struct sk_buff *skb) 921da177e4SLinus Torvalds { 931da177e4SLinus Torvalds unsigned char optbuf[sizeof(struct ip_options) + 40]; 941da177e4SLinus Torvalds struct ip_options *opt = (struct ip_options *)optbuf; 951da177e4SLinus Torvalds 961da177e4SLinus Torvalds if (IPCB(skb)->opt.optlen == 0) 971da177e4SLinus Torvalds return; 981da177e4SLinus Torvalds 991da177e4SLinus Torvalds if (ip_options_echo(opt, skb)) { 1001da177e4SLinus Torvalds msg->msg_flags |= MSG_CTRUNC; 1011da177e4SLinus Torvalds return; 1021da177e4SLinus Torvalds } 1031da177e4SLinus Torvalds ip_options_undo(opt); 1041da177e4SLinus Torvalds 1051da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_RETOPTS, opt->optlen, opt->__data); 1061da177e4SLinus Torvalds } 1071da177e4SLinus Torvalds 1082c7946a7SCatherine Zhang static void ip_cmsg_recv_security(struct msghdr *msg, struct sk_buff *skb) 1092c7946a7SCatherine Zhang { 1102c7946a7SCatherine Zhang char *secdata; 111dc49c1f9SCatherine Zhang u32 seclen, secid; 1122c7946a7SCatherine Zhang int err; 1132c7946a7SCatherine Zhang 114dc49c1f9SCatherine Zhang err = security_socket_getpeersec_dgram(NULL, skb, &secid); 115dc49c1f9SCatherine Zhang if (err) 116dc49c1f9SCatherine Zhang return; 117dc49c1f9SCatherine Zhang 118dc49c1f9SCatherine Zhang err = security_secid_to_secctx(secid, &secdata, &seclen); 1192c7946a7SCatherine Zhang if (err) 1202c7946a7SCatherine Zhang return; 1212c7946a7SCatherine Zhang 1222c7946a7SCatherine Zhang put_cmsg(msg, SOL_IP, SCM_SECURITY, seclen, secdata); 123dc49c1f9SCatherine Zhang security_release_secctx(secdata, seclen); 1242c7946a7SCatherine Zhang } 1252c7946a7SCatherine Zhang 12621d1a161SHarvey Harrison static void ip_cmsg_recv_dstaddr(struct msghdr *msg, struct sk_buff *skb) 127e8b2dfe9SBalazs Scheidler { 128e8b2dfe9SBalazs Scheidler struct sockaddr_in sin; 129b71d1d42SEric Dumazet const struct iphdr *iph = ip_hdr(skb); 13021d1a161SHarvey Harrison __be16 *ports = (__be16 *)skb_transport_header(skb); 131e8b2dfe9SBalazs Scheidler 132e8b2dfe9SBalazs Scheidler if (skb_transport_offset(skb) + 4 > skb->len) 133e8b2dfe9SBalazs Scheidler return; 134e8b2dfe9SBalazs Scheidler 135e8b2dfe9SBalazs Scheidler /* All current transport protocols have the port numbers in the 136e8b2dfe9SBalazs Scheidler * first four bytes of the transport header and this function is 137e8b2dfe9SBalazs Scheidler * written with this assumption in mind. 138e8b2dfe9SBalazs Scheidler */ 139e8b2dfe9SBalazs Scheidler 140e8b2dfe9SBalazs Scheidler sin.sin_family = AF_INET; 141e8b2dfe9SBalazs Scheidler sin.sin_addr.s_addr = iph->daddr; 142e8b2dfe9SBalazs Scheidler sin.sin_port = ports[1]; 143e8b2dfe9SBalazs Scheidler memset(sin.sin_zero, 0, sizeof(sin.sin_zero)); 144e8b2dfe9SBalazs Scheidler 145e8b2dfe9SBalazs Scheidler put_cmsg(msg, SOL_IP, IP_ORIGDSTADDR, sizeof(sin), &sin); 146e8b2dfe9SBalazs Scheidler } 1471da177e4SLinus Torvalds 1481da177e4SLinus Torvalds void ip_cmsg_recv(struct msghdr *msg, struct sk_buff *skb) 1491da177e4SLinus Torvalds { 1501da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(skb->sk); 15195c96174SEric Dumazet unsigned int flags = inet->cmsg_flags; 1521da177e4SLinus Torvalds 1531da177e4SLinus Torvalds /* Ordered by supposed usage frequency */ 1541da177e4SLinus Torvalds if (flags & 1) 1551da177e4SLinus Torvalds ip_cmsg_recv_pktinfo(msg, skb); 1561da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1571da177e4SLinus Torvalds return; 1581da177e4SLinus Torvalds 1591da177e4SLinus Torvalds if (flags & 1) 1601da177e4SLinus Torvalds ip_cmsg_recv_ttl(msg, skb); 1611da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1621da177e4SLinus Torvalds return; 1631da177e4SLinus Torvalds 1641da177e4SLinus Torvalds if (flags & 1) 1651da177e4SLinus Torvalds ip_cmsg_recv_tos(msg, skb); 1661da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1671da177e4SLinus Torvalds return; 1681da177e4SLinus Torvalds 1691da177e4SLinus Torvalds if (flags & 1) 1701da177e4SLinus Torvalds ip_cmsg_recv_opts(msg, skb); 1711da177e4SLinus Torvalds if ((flags >>= 1) == 0) 1721da177e4SLinus Torvalds return; 1731da177e4SLinus Torvalds 1741da177e4SLinus Torvalds if (flags & 1) 1751da177e4SLinus Torvalds ip_cmsg_recv_retopts(msg, skb); 1762c7946a7SCatherine Zhang if ((flags >>= 1) == 0) 1772c7946a7SCatherine Zhang return; 1782c7946a7SCatherine Zhang 1792c7946a7SCatherine Zhang if (flags & 1) 1802c7946a7SCatherine Zhang ip_cmsg_recv_security(msg, skb); 181e8b2dfe9SBalazs Scheidler 182e8b2dfe9SBalazs Scheidler if ((flags >>= 1) == 0) 183e8b2dfe9SBalazs Scheidler return; 184e8b2dfe9SBalazs Scheidler if (flags & 1) 185e8b2dfe9SBalazs Scheidler ip_cmsg_recv_dstaddr(msg, skb); 186e8b2dfe9SBalazs Scheidler 1871da177e4SLinus Torvalds } 1884d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_cmsg_recv); 1891da177e4SLinus Torvalds 1907a6adb92SDenis V. Lunev int ip_cmsg_send(struct net *net, struct msghdr *msg, struct ipcm_cookie *ipc) 1911da177e4SLinus Torvalds { 192f02db315SFrancesco Fusco int err, val; 1931da177e4SLinus Torvalds struct cmsghdr *cmsg; 1941da177e4SLinus Torvalds 1951da177e4SLinus Torvalds for (cmsg = CMSG_FIRSTHDR(msg); cmsg; cmsg = CMSG_NXTHDR(msg, cmsg)) { 1961da177e4SLinus Torvalds if (!CMSG_OK(msg, cmsg)) 1971da177e4SLinus Torvalds return -EINVAL; 1981da177e4SLinus Torvalds if (cmsg->cmsg_level != SOL_IP) 1991da177e4SLinus Torvalds continue; 2001da177e4SLinus Torvalds switch (cmsg->cmsg_type) { 2011da177e4SLinus Torvalds case IP_RETOPTS: 2021da177e4SLinus Torvalds err = cmsg->cmsg_len - CMSG_ALIGN(sizeof(struct cmsghdr)); 2034d52cfbeSEric Dumazet err = ip_options_get(net, &ipc->opt, CMSG_DATA(cmsg), 2044d52cfbeSEric Dumazet err < 40 ? err : 40); 2051da177e4SLinus Torvalds if (err) 2061da177e4SLinus Torvalds return err; 2071da177e4SLinus Torvalds break; 2081da177e4SLinus Torvalds case IP_PKTINFO: 2091da177e4SLinus Torvalds { 2101da177e4SLinus Torvalds struct in_pktinfo *info; 2111da177e4SLinus Torvalds if (cmsg->cmsg_len != CMSG_LEN(sizeof(struct in_pktinfo))) 2121da177e4SLinus Torvalds return -EINVAL; 2131da177e4SLinus Torvalds info = (struct in_pktinfo *)CMSG_DATA(cmsg); 2141da177e4SLinus Torvalds ipc->oif = info->ipi_ifindex; 2151da177e4SLinus Torvalds ipc->addr = info->ipi_spec_dst.s_addr; 2161da177e4SLinus Torvalds break; 2171da177e4SLinus Torvalds } 218f02db315SFrancesco Fusco case IP_TTL: 219f02db315SFrancesco Fusco if (cmsg->cmsg_len != CMSG_LEN(sizeof(int))) 220f02db315SFrancesco Fusco return -EINVAL; 221f02db315SFrancesco Fusco val = *(int *)CMSG_DATA(cmsg); 222f02db315SFrancesco Fusco if (val < 1 || val > 255) 223f02db315SFrancesco Fusco return -EINVAL; 224f02db315SFrancesco Fusco ipc->ttl = val; 225f02db315SFrancesco Fusco break; 226f02db315SFrancesco Fusco case IP_TOS: 227f02db315SFrancesco Fusco if (cmsg->cmsg_len != CMSG_LEN(sizeof(int))) 228f02db315SFrancesco Fusco return -EINVAL; 229f02db315SFrancesco Fusco val = *(int *)CMSG_DATA(cmsg); 230f02db315SFrancesco Fusco if (val < 0 || val > 255) 231f02db315SFrancesco Fusco return -EINVAL; 232f02db315SFrancesco Fusco ipc->tos = val; 233f02db315SFrancesco Fusco ipc->priority = rt_tos2priority(ipc->tos); 234f02db315SFrancesco Fusco break; 235f02db315SFrancesco Fusco 2361da177e4SLinus Torvalds default: 2371da177e4SLinus Torvalds return -EINVAL; 2381da177e4SLinus Torvalds } 2391da177e4SLinus Torvalds } 2401da177e4SLinus Torvalds return 0; 2411da177e4SLinus Torvalds } 2421da177e4SLinus Torvalds 2431da177e4SLinus Torvalds 2441da177e4SLinus Torvalds /* Special input handler for packets caught by router alert option. 2451da177e4SLinus Torvalds They are selected only by protocol field, and then processed likely 2461da177e4SLinus Torvalds local ones; but only if someone wants them! Otherwise, router 2471da177e4SLinus Torvalds not running rsvpd will kill RSVP. 2481da177e4SLinus Torvalds 2491da177e4SLinus Torvalds It is user level problem, what it will make with them. 2501da177e4SLinus Torvalds I have no idea, how it will masquearde or NAT them (it is joke, joke :-)), 2511da177e4SLinus Torvalds but receiver should be enough clever f.e. to forward mtrace requests, 2521da177e4SLinus Torvalds sent to multicast group to reach destination designated router. 2531da177e4SLinus Torvalds */ 25443a951e9SEric Dumazet struct ip_ra_chain __rcu *ip_ra_chain; 25566018506SEric Dumazet static DEFINE_SPINLOCK(ip_ra_lock); 25666018506SEric Dumazet 257592fcb9dSEric Dumazet 258592fcb9dSEric Dumazet static void ip_ra_destroy_rcu(struct rcu_head *head) 25966018506SEric Dumazet { 260592fcb9dSEric Dumazet struct ip_ra_chain *ra = container_of(head, struct ip_ra_chain, rcu); 261592fcb9dSEric Dumazet 262592fcb9dSEric Dumazet sock_put(ra->saved_sk); 263592fcb9dSEric Dumazet kfree(ra); 26466018506SEric Dumazet } 2651da177e4SLinus Torvalds 2664d52cfbeSEric Dumazet int ip_ra_control(struct sock *sk, unsigned char on, 2674d52cfbeSEric Dumazet void (*destructor)(struct sock *)) 2681da177e4SLinus Torvalds { 26943a951e9SEric Dumazet struct ip_ra_chain *ra, *new_ra; 27043a951e9SEric Dumazet struct ip_ra_chain __rcu **rap; 2711da177e4SLinus Torvalds 272c720c7e8SEric Dumazet if (sk->sk_type != SOCK_RAW || inet_sk(sk)->inet_num == IPPROTO_RAW) 2731da177e4SLinus Torvalds return -EINVAL; 2741da177e4SLinus Torvalds 2751da177e4SLinus Torvalds new_ra = on ? kmalloc(sizeof(*new_ra), GFP_KERNEL) : NULL; 2761da177e4SLinus Torvalds 27766018506SEric Dumazet spin_lock_bh(&ip_ra_lock); 27843a951e9SEric Dumazet for (rap = &ip_ra_chain; 27943a951e9SEric Dumazet (ra = rcu_dereference_protected(*rap, 28043a951e9SEric Dumazet lockdep_is_held(&ip_ra_lock))) != NULL; 28143a951e9SEric Dumazet rap = &ra->next) { 2821da177e4SLinus Torvalds if (ra->sk == sk) { 2831da177e4SLinus Torvalds if (on) { 28466018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 2851da177e4SLinus Torvalds kfree(new_ra); 2861da177e4SLinus Torvalds return -EADDRINUSE; 2871da177e4SLinus Torvalds } 288592fcb9dSEric Dumazet /* dont let ip_call_ra_chain() use sk again */ 289592fcb9dSEric Dumazet ra->sk = NULL; 29066018506SEric Dumazet rcu_assign_pointer(*rap, ra->next); 29166018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 2921da177e4SLinus Torvalds 2931da177e4SLinus Torvalds if (ra->destructor) 2941da177e4SLinus Torvalds ra->destructor(sk); 295592fcb9dSEric Dumazet /* 296592fcb9dSEric Dumazet * Delay sock_put(sk) and kfree(ra) after one rcu grace 297592fcb9dSEric Dumazet * period. This guarantee ip_call_ra_chain() dont need 298592fcb9dSEric Dumazet * to mess with socket refcounts. 299592fcb9dSEric Dumazet */ 300592fcb9dSEric Dumazet ra->saved_sk = sk; 301592fcb9dSEric Dumazet call_rcu(&ra->rcu, ip_ra_destroy_rcu); 3021da177e4SLinus Torvalds return 0; 3031da177e4SLinus Torvalds } 3041da177e4SLinus Torvalds } 3051da177e4SLinus Torvalds if (new_ra == NULL) { 30666018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 3071da177e4SLinus Torvalds return -ENOBUFS; 3081da177e4SLinus Torvalds } 3091da177e4SLinus Torvalds new_ra->sk = sk; 3101da177e4SLinus Torvalds new_ra->destructor = destructor; 3111da177e4SLinus Torvalds 3121da177e4SLinus Torvalds new_ra->next = ra; 31366018506SEric Dumazet rcu_assign_pointer(*rap, new_ra); 3141da177e4SLinus Torvalds sock_hold(sk); 31566018506SEric Dumazet spin_unlock_bh(&ip_ra_lock); 3161da177e4SLinus Torvalds 3171da177e4SLinus Torvalds return 0; 3181da177e4SLinus Torvalds } 3191da177e4SLinus Torvalds 3201da177e4SLinus Torvalds void ip_icmp_error(struct sock *sk, struct sk_buff *skb, int err, 32135986b32SAl Viro __be16 port, u32 info, u8 *payload) 3221da177e4SLinus Torvalds { 3231da177e4SLinus Torvalds struct sock_exterr_skb *serr; 3241da177e4SLinus Torvalds 3251da177e4SLinus Torvalds skb = skb_clone(skb, GFP_ATOMIC); 3261da177e4SLinus Torvalds if (!skb) 3271da177e4SLinus Torvalds return; 3281da177e4SLinus Torvalds 3291da177e4SLinus Torvalds serr = SKB_EXT_ERR(skb); 3301da177e4SLinus Torvalds serr->ee.ee_errno = err; 3311da177e4SLinus Torvalds serr->ee.ee_origin = SO_EE_ORIGIN_ICMP; 33288c7664fSArnaldo Carvalho de Melo serr->ee.ee_type = icmp_hdr(skb)->type; 33388c7664fSArnaldo Carvalho de Melo serr->ee.ee_code = icmp_hdr(skb)->code; 3341da177e4SLinus Torvalds serr->ee.ee_pad = 0; 3351da177e4SLinus Torvalds serr->ee.ee_info = info; 3361da177e4SLinus Torvalds serr->ee.ee_data = 0; 33788c7664fSArnaldo Carvalho de Melo serr->addr_offset = (u8 *)&(((struct iphdr *)(icmp_hdr(skb) + 1))->daddr) - 338d56f90a7SArnaldo Carvalho de Melo skb_network_header(skb); 3391da177e4SLinus Torvalds serr->port = port; 3401da177e4SLinus Torvalds 341bd82393cSArnaldo Carvalho de Melo if (skb_pull(skb, payload - skb->data) != NULL) { 342bd82393cSArnaldo Carvalho de Melo skb_reset_transport_header(skb); 343bd82393cSArnaldo Carvalho de Melo if (sock_queue_err_skb(sk, skb) == 0) 344bd82393cSArnaldo Carvalho de Melo return; 345bd82393cSArnaldo Carvalho de Melo } 3461da177e4SLinus Torvalds kfree_skb(skb); 3471da177e4SLinus Torvalds } 3481da177e4SLinus Torvalds 3490579016eSAl Viro void ip_local_error(struct sock *sk, int err, __be32 daddr, __be16 port, u32 info) 3501da177e4SLinus Torvalds { 3511da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 3521da177e4SLinus Torvalds struct sock_exterr_skb *serr; 3531da177e4SLinus Torvalds struct iphdr *iph; 3541da177e4SLinus Torvalds struct sk_buff *skb; 3551da177e4SLinus Torvalds 3561da177e4SLinus Torvalds if (!inet->recverr) 3571da177e4SLinus Torvalds return; 3581da177e4SLinus Torvalds 3591da177e4SLinus Torvalds skb = alloc_skb(sizeof(struct iphdr), GFP_ATOMIC); 3601da177e4SLinus Torvalds if (!skb) 3611da177e4SLinus Torvalds return; 3621da177e4SLinus Torvalds 3632ca9e6f2SArnaldo Carvalho de Melo skb_put(skb, sizeof(struct iphdr)); 3642ca9e6f2SArnaldo Carvalho de Melo skb_reset_network_header(skb); 365eddc9ec5SArnaldo Carvalho de Melo iph = ip_hdr(skb); 3661da177e4SLinus Torvalds iph->daddr = daddr; 3671da177e4SLinus Torvalds 3681da177e4SLinus Torvalds serr = SKB_EXT_ERR(skb); 3691da177e4SLinus Torvalds serr->ee.ee_errno = err; 3701da177e4SLinus Torvalds serr->ee.ee_origin = SO_EE_ORIGIN_LOCAL; 3711da177e4SLinus Torvalds serr->ee.ee_type = 0; 3721da177e4SLinus Torvalds serr->ee.ee_code = 0; 3731da177e4SLinus Torvalds serr->ee.ee_pad = 0; 3741da177e4SLinus Torvalds serr->ee.ee_info = info; 3751da177e4SLinus Torvalds serr->ee.ee_data = 0; 376d56f90a7SArnaldo Carvalho de Melo serr->addr_offset = (u8 *)&iph->daddr - skb_network_header(skb); 3771da177e4SLinus Torvalds serr->port = port; 3781da177e4SLinus Torvalds 37927a884dcSArnaldo Carvalho de Melo __skb_pull(skb, skb_tail_pointer(skb) - skb->data); 380bd82393cSArnaldo Carvalho de Melo skb_reset_transport_header(skb); 3811da177e4SLinus Torvalds 3821da177e4SLinus Torvalds if (sock_queue_err_skb(sk, skb)) 3831da177e4SLinus Torvalds kfree_skb(skb); 3841da177e4SLinus Torvalds } 3851da177e4SLinus Torvalds 3861da177e4SLinus Torvalds /* 3871da177e4SLinus Torvalds * Handle MSG_ERRQUEUE 3881da177e4SLinus Torvalds */ 38985fbaa75SHannes Frederic Sowa int ip_recv_error(struct sock *sk, struct msghdr *msg, int len, int *addr_len) 3901da177e4SLinus Torvalds { 3911da177e4SLinus Torvalds struct sock_exterr_skb *serr; 3921da177e4SLinus Torvalds struct sk_buff *skb, *skb2; 3931da177e4SLinus Torvalds struct sockaddr_in *sin; 3941da177e4SLinus Torvalds struct { 3951da177e4SLinus Torvalds struct sock_extended_err ee; 3961da177e4SLinus Torvalds struct sockaddr_in offender; 3971da177e4SLinus Torvalds } errhdr; 3981da177e4SLinus Torvalds int err; 3991da177e4SLinus Torvalds int copied; 4001da177e4SLinus Torvalds 4011da177e4SLinus Torvalds err = -EAGAIN; 4021da177e4SLinus Torvalds skb = skb_dequeue(&sk->sk_error_queue); 4031da177e4SLinus Torvalds if (skb == NULL) 4041da177e4SLinus Torvalds goto out; 4051da177e4SLinus Torvalds 4061da177e4SLinus Torvalds copied = skb->len; 4071da177e4SLinus Torvalds if (copied > len) { 4081da177e4SLinus Torvalds msg->msg_flags |= MSG_TRUNC; 4091da177e4SLinus Torvalds copied = len; 4101da177e4SLinus Torvalds } 4111da177e4SLinus Torvalds err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied); 4121da177e4SLinus Torvalds if (err) 4131da177e4SLinus Torvalds goto out_free_skb; 4141da177e4SLinus Torvalds 4151da177e4SLinus Torvalds sock_recv_timestamp(msg, sk, skb); 4161da177e4SLinus Torvalds 4171da177e4SLinus Torvalds serr = SKB_EXT_ERR(skb); 4181da177e4SLinus Torvalds 4191da177e4SLinus Torvalds sin = (struct sockaddr_in *)msg->msg_name; 4201da177e4SLinus Torvalds if (sin) { 4211da177e4SLinus Torvalds sin->sin_family = AF_INET; 422d56f90a7SArnaldo Carvalho de Melo sin->sin_addr.s_addr = *(__be32 *)(skb_network_header(skb) + 423d56f90a7SArnaldo Carvalho de Melo serr->addr_offset); 4241da177e4SLinus Torvalds sin->sin_port = serr->port; 4251da177e4SLinus Torvalds memset(&sin->sin_zero, 0, sizeof(sin->sin_zero)); 42685fbaa75SHannes Frederic Sowa *addr_len = sizeof(*sin); 4271da177e4SLinus Torvalds } 4281da177e4SLinus Torvalds 4291da177e4SLinus Torvalds memcpy(&errhdr.ee, &serr->ee, sizeof(struct sock_extended_err)); 4301da177e4SLinus Torvalds sin = &errhdr.offender; 4311da177e4SLinus Torvalds sin->sin_family = AF_UNSPEC; 4321da177e4SLinus Torvalds if (serr->ee.ee_origin == SO_EE_ORIGIN_ICMP) { 4331da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 4341da177e4SLinus Torvalds 4351da177e4SLinus Torvalds sin->sin_family = AF_INET; 436eddc9ec5SArnaldo Carvalho de Melo sin->sin_addr.s_addr = ip_hdr(skb)->saddr; 4371da177e4SLinus Torvalds sin->sin_port = 0; 4381da177e4SLinus Torvalds memset(&sin->sin_zero, 0, sizeof(sin->sin_zero)); 4391da177e4SLinus Torvalds if (inet->cmsg_flags) 4401da177e4SLinus Torvalds ip_cmsg_recv(msg, skb); 4411da177e4SLinus Torvalds } 4421da177e4SLinus Torvalds 4431da177e4SLinus Torvalds put_cmsg(msg, SOL_IP, IP_RECVERR, sizeof(errhdr), &errhdr); 4441da177e4SLinus Torvalds 4451da177e4SLinus Torvalds /* Now we could try to dump offended packet options */ 4461da177e4SLinus Torvalds 4471da177e4SLinus Torvalds msg->msg_flags |= MSG_ERRQUEUE; 4481da177e4SLinus Torvalds err = copied; 4491da177e4SLinus Torvalds 4501da177e4SLinus Torvalds /* Reset and regenerate socket error */ 451e0f9f858SHerbert Xu spin_lock_bh(&sk->sk_error_queue.lock); 4521da177e4SLinus Torvalds sk->sk_err = 0; 4534d52cfbeSEric Dumazet skb2 = skb_peek(&sk->sk_error_queue); 4544d52cfbeSEric Dumazet if (skb2 != NULL) { 4551da177e4SLinus Torvalds sk->sk_err = SKB_EXT_ERR(skb2)->ee.ee_errno; 456e0f9f858SHerbert Xu spin_unlock_bh(&sk->sk_error_queue.lock); 4571da177e4SLinus Torvalds sk->sk_error_report(sk); 4581da177e4SLinus Torvalds } else 459e0f9f858SHerbert Xu spin_unlock_bh(&sk->sk_error_queue.lock); 4601da177e4SLinus Torvalds 4611da177e4SLinus Torvalds out_free_skb: 4621da177e4SLinus Torvalds kfree_skb(skb); 4631da177e4SLinus Torvalds out: 4641da177e4SLinus Torvalds return err; 4651da177e4SLinus Torvalds } 4661da177e4SLinus Torvalds 4671da177e4SLinus Torvalds 4681da177e4SLinus Torvalds /* 4694d52cfbeSEric Dumazet * Socket option code for IP. This is the end of the line after any 4704d52cfbeSEric Dumazet * TCP,UDP etc options on an IP socket. 4711da177e4SLinus Torvalds */ 4721da177e4SLinus Torvalds 4733fdadf7dSDmitry Mishin static int do_ip_setsockopt(struct sock *sk, int level, 474b7058842SDavid S. Miller int optname, char __user *optval, unsigned int optlen) 4751da177e4SLinus Torvalds { 4761da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 4771da177e4SLinus Torvalds int val = 0, err; 4781da177e4SLinus Torvalds 4790c9f79beSXi Wang switch (optname) { 4800c9f79beSXi Wang case IP_PKTINFO: 4810c9f79beSXi Wang case IP_RECVTTL: 4820c9f79beSXi Wang case IP_RECVOPTS: 4830c9f79beSXi Wang case IP_RECVTOS: 4840c9f79beSXi Wang case IP_RETOPTS: 4850c9f79beSXi Wang case IP_TOS: 4860c9f79beSXi Wang case IP_TTL: 4870c9f79beSXi Wang case IP_HDRINCL: 4880c9f79beSXi Wang case IP_MTU_DISCOVER: 4890c9f79beSXi Wang case IP_RECVERR: 4900c9f79beSXi Wang case IP_ROUTER_ALERT: 4910c9f79beSXi Wang case IP_FREEBIND: 4920c9f79beSXi Wang case IP_PASSSEC: 4930c9f79beSXi Wang case IP_TRANSPARENT: 4940c9f79beSXi Wang case IP_MINTTL: 4950c9f79beSXi Wang case IP_NODEFRAG: 4960c9f79beSXi Wang case IP_UNICAST_IF: 4970c9f79beSXi Wang case IP_MULTICAST_TTL: 4980c9f79beSXi Wang case IP_MULTICAST_ALL: 4990c9f79beSXi Wang case IP_MULTICAST_LOOP: 5000c9f79beSXi Wang case IP_RECVORIGDSTADDR: 5011da177e4SLinus Torvalds if (optlen >= sizeof(int)) { 5021da177e4SLinus Torvalds if (get_user(val, (int __user *) optval)) 5031da177e4SLinus Torvalds return -EFAULT; 5041da177e4SLinus Torvalds } else if (optlen >= sizeof(char)) { 5051da177e4SLinus Torvalds unsigned char ucval; 5061da177e4SLinus Torvalds 5071da177e4SLinus Torvalds if (get_user(ucval, (unsigned char __user *) optval)) 5081da177e4SLinus Torvalds return -EFAULT; 5091da177e4SLinus Torvalds val = (int) ucval; 5101da177e4SLinus Torvalds } 5111da177e4SLinus Torvalds } 5121da177e4SLinus Torvalds 5131da177e4SLinus Torvalds /* If optlen==0, it is equivalent to val == 0 */ 5141da177e4SLinus Torvalds 5156a9fb947SPavel Emelyanov if (ip_mroute_opt(optname)) 5161da177e4SLinus Torvalds return ip_mroute_setsockopt(sk, optname, optval, optlen); 5171da177e4SLinus Torvalds 5181da177e4SLinus Torvalds err = 0; 5191da177e4SLinus Torvalds lock_sock(sk); 5201da177e4SLinus Torvalds 5211da177e4SLinus Torvalds switch (optname) { 5221da177e4SLinus Torvalds case IP_OPTIONS: 5231da177e4SLinus Torvalds { 524f6d8bd05SEric Dumazet struct ip_options_rcu *old, *opt = NULL; 525f6d8bd05SEric Dumazet 52665a1c4ffSroel kluin if (optlen > 40) 5271da177e4SLinus Torvalds goto e_inval; 5283b1e0a65SYOSHIFUJI Hideaki err = ip_options_get_from_user(sock_net(sk), &opt, 529cb84663eSDenis V. Lunev optval, optlen); 5301da177e4SLinus Torvalds if (err) 5311da177e4SLinus Torvalds break; 532f6d8bd05SEric Dumazet old = rcu_dereference_protected(inet->inet_opt, 533f6d8bd05SEric Dumazet sock_owned_by_user(sk)); 534d83d8461SArnaldo Carvalho de Melo if (inet->is_icsk) { 535d83d8461SArnaldo Carvalho de Melo struct inet_connection_sock *icsk = inet_csk(sk); 536dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6) 5371da177e4SLinus Torvalds if (sk->sk_family == PF_INET || 5381da177e4SLinus Torvalds (!((1 << sk->sk_state) & 5391da177e4SLinus Torvalds (TCPF_LISTEN | TCPF_CLOSE)) && 540c720c7e8SEric Dumazet inet->inet_daddr != LOOPBACK4_IPV6)) { 5411da177e4SLinus Torvalds #endif 542f6d8bd05SEric Dumazet if (old) 543f6d8bd05SEric Dumazet icsk->icsk_ext_hdr_len -= old->opt.optlen; 5441da177e4SLinus Torvalds if (opt) 545f6d8bd05SEric Dumazet icsk->icsk_ext_hdr_len += opt->opt.optlen; 546d83d8461SArnaldo Carvalho de Melo icsk->icsk_sync_mss(sk, icsk->icsk_pmtu_cookie); 547dfd56b8bSEric Dumazet #if IS_ENABLED(CONFIG_IPV6) 5481da177e4SLinus Torvalds } 5491da177e4SLinus Torvalds #endif 5501da177e4SLinus Torvalds } 551f6d8bd05SEric Dumazet rcu_assign_pointer(inet->inet_opt, opt); 552f6d8bd05SEric Dumazet if (old) 553605b4afeSPaul E. McKenney kfree_rcu(old, rcu); 5541da177e4SLinus Torvalds break; 5551da177e4SLinus Torvalds } 5561da177e4SLinus Torvalds case IP_PKTINFO: 5571da177e4SLinus Torvalds if (val) 5581da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_PKTINFO; 5591da177e4SLinus Torvalds else 5601da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_PKTINFO; 5611da177e4SLinus Torvalds break; 5621da177e4SLinus Torvalds case IP_RECVTTL: 5631da177e4SLinus Torvalds if (val) 5641da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_TTL; 5651da177e4SLinus Torvalds else 5661da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_TTL; 5671da177e4SLinus Torvalds break; 5681da177e4SLinus Torvalds case IP_RECVTOS: 5691da177e4SLinus Torvalds if (val) 5701da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_TOS; 5711da177e4SLinus Torvalds else 5721da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_TOS; 5731da177e4SLinus Torvalds break; 5741da177e4SLinus Torvalds case IP_RECVOPTS: 5751da177e4SLinus Torvalds if (val) 5761da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_RECVOPTS; 5771da177e4SLinus Torvalds else 5781da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_RECVOPTS; 5791da177e4SLinus Torvalds break; 5801da177e4SLinus Torvalds case IP_RETOPTS: 5811da177e4SLinus Torvalds if (val) 5821da177e4SLinus Torvalds inet->cmsg_flags |= IP_CMSG_RETOPTS; 5831da177e4SLinus Torvalds else 5841da177e4SLinus Torvalds inet->cmsg_flags &= ~IP_CMSG_RETOPTS; 5851da177e4SLinus Torvalds break; 5862c7946a7SCatherine Zhang case IP_PASSSEC: 5872c7946a7SCatherine Zhang if (val) 5882c7946a7SCatherine Zhang inet->cmsg_flags |= IP_CMSG_PASSSEC; 5892c7946a7SCatherine Zhang else 5902c7946a7SCatherine Zhang inet->cmsg_flags &= ~IP_CMSG_PASSSEC; 5912c7946a7SCatherine Zhang break; 592e8b2dfe9SBalazs Scheidler case IP_RECVORIGDSTADDR: 593e8b2dfe9SBalazs Scheidler if (val) 594e8b2dfe9SBalazs Scheidler inet->cmsg_flags |= IP_CMSG_ORIGDSTADDR; 595e8b2dfe9SBalazs Scheidler else 596e8b2dfe9SBalazs Scheidler inet->cmsg_flags &= ~IP_CMSG_ORIGDSTADDR; 597e8b2dfe9SBalazs Scheidler break; 5981da177e4SLinus Torvalds case IP_TOS: /* This sets both TOS and Precedence */ 5991da177e4SLinus Torvalds if (sk->sk_type == SOCK_STREAM) { 6002c67e9acSMaciej Żenczykowski val &= ~INET_ECN_MASK; 6012c67e9acSMaciej Żenczykowski val |= inet->tos & INET_ECN_MASK; 6021da177e4SLinus Torvalds } 6031da177e4SLinus Torvalds if (inet->tos != val) { 6041da177e4SLinus Torvalds inet->tos = val; 6051da177e4SLinus Torvalds sk->sk_priority = rt_tos2priority(val); 6061da177e4SLinus Torvalds sk_dst_reset(sk); 6071da177e4SLinus Torvalds } 6081da177e4SLinus Torvalds break; 6091da177e4SLinus Torvalds case IP_TTL: 6101da177e4SLinus Torvalds if (optlen < 1) 6111da177e4SLinus Torvalds goto e_inval; 612c9be4a5cSCong Wang if (val != -1 && (val < 1 || val > 255)) 6131da177e4SLinus Torvalds goto e_inval; 6141da177e4SLinus Torvalds inet->uc_ttl = val; 6151da177e4SLinus Torvalds break; 6161da177e4SLinus Torvalds case IP_HDRINCL: 6171da177e4SLinus Torvalds if (sk->sk_type != SOCK_RAW) { 6181da177e4SLinus Torvalds err = -ENOPROTOOPT; 6191da177e4SLinus Torvalds break; 6201da177e4SLinus Torvalds } 6211da177e4SLinus Torvalds inet->hdrincl = val ? 1 : 0; 6221da177e4SLinus Torvalds break; 6237b2ff18eSJiri Olsa case IP_NODEFRAG: 6247b2ff18eSJiri Olsa if (sk->sk_type != SOCK_RAW) { 6257b2ff18eSJiri Olsa err = -ENOPROTOOPT; 6267b2ff18eSJiri Olsa break; 6277b2ff18eSJiri Olsa } 6287b2ff18eSJiri Olsa inet->nodefrag = val ? 1 : 0; 6297b2ff18eSJiri Olsa break; 6301da177e4SLinus Torvalds case IP_MTU_DISCOVER: 631482fc609SHannes Frederic Sowa if (val < IP_PMTUDISC_DONT || val > IP_PMTUDISC_INTERFACE) 6321da177e4SLinus Torvalds goto e_inval; 6331da177e4SLinus Torvalds inet->pmtudisc = val; 6341da177e4SLinus Torvalds break; 6351da177e4SLinus Torvalds case IP_RECVERR: 6361da177e4SLinus Torvalds inet->recverr = !!val; 6371da177e4SLinus Torvalds if (!val) 6381da177e4SLinus Torvalds skb_queue_purge(&sk->sk_error_queue); 6391da177e4SLinus Torvalds break; 6401da177e4SLinus Torvalds case IP_MULTICAST_TTL: 6411da177e4SLinus Torvalds if (sk->sk_type == SOCK_STREAM) 6421da177e4SLinus Torvalds goto e_inval; 6431da177e4SLinus Torvalds if (optlen < 1) 6441da177e4SLinus Torvalds goto e_inval; 6451da177e4SLinus Torvalds if (val == -1) 6461da177e4SLinus Torvalds val = 1; 6471da177e4SLinus Torvalds if (val < 0 || val > 255) 6481da177e4SLinus Torvalds goto e_inval; 6491da177e4SLinus Torvalds inet->mc_ttl = val; 6501da177e4SLinus Torvalds break; 6511da177e4SLinus Torvalds case IP_MULTICAST_LOOP: 6521da177e4SLinus Torvalds if (optlen < 1) 6531da177e4SLinus Torvalds goto e_inval; 6541da177e4SLinus Torvalds inet->mc_loop = !!val; 6551da177e4SLinus Torvalds break; 65676e21053SErich E. Hoover case IP_UNICAST_IF: 65776e21053SErich E. Hoover { 65876e21053SErich E. Hoover struct net_device *dev = NULL; 65976e21053SErich E. Hoover int ifindex; 66076e21053SErich E. Hoover 66176e21053SErich E. Hoover if (optlen != sizeof(int)) 66276e21053SErich E. Hoover goto e_inval; 66376e21053SErich E. Hoover 66476e21053SErich E. Hoover ifindex = (__force int)ntohl((__force __be32)val); 66576e21053SErich E. Hoover if (ifindex == 0) { 66676e21053SErich E. Hoover inet->uc_index = 0; 66776e21053SErich E. Hoover err = 0; 66876e21053SErich E. Hoover break; 66976e21053SErich E. Hoover } 67076e21053SErich E. Hoover 67176e21053SErich E. Hoover dev = dev_get_by_index(sock_net(sk), ifindex); 67276e21053SErich E. Hoover err = -EADDRNOTAVAIL; 67376e21053SErich E. Hoover if (!dev) 67476e21053SErich E. Hoover break; 67576e21053SErich E. Hoover dev_put(dev); 67676e21053SErich E. Hoover 67776e21053SErich E. Hoover err = -EINVAL; 67876e21053SErich E. Hoover if (sk->sk_bound_dev_if) 67976e21053SErich E. Hoover break; 68076e21053SErich E. Hoover 68176e21053SErich E. Hoover inet->uc_index = ifindex; 68276e21053SErich E. Hoover err = 0; 68376e21053SErich E. Hoover break; 68476e21053SErich E. Hoover } 6851da177e4SLinus Torvalds case IP_MULTICAST_IF: 6861da177e4SLinus Torvalds { 6871da177e4SLinus Torvalds struct ip_mreqn mreq; 6881da177e4SLinus Torvalds struct net_device *dev = NULL; 6891da177e4SLinus Torvalds 6901da177e4SLinus Torvalds if (sk->sk_type == SOCK_STREAM) 6911da177e4SLinus Torvalds goto e_inval; 6921da177e4SLinus Torvalds /* 6931da177e4SLinus Torvalds * Check the arguments are allowable 6941da177e4SLinus Torvalds */ 6951da177e4SLinus Torvalds 6960915921bSShan Wei if (optlen < sizeof(struct in_addr)) 6970915921bSShan Wei goto e_inval; 6980915921bSShan Wei 6991da177e4SLinus Torvalds err = -EFAULT; 7001da177e4SLinus Torvalds if (optlen >= sizeof(struct ip_mreqn)) { 7011da177e4SLinus Torvalds if (copy_from_user(&mreq, optval, sizeof(mreq))) 7021da177e4SLinus Torvalds break; 7031da177e4SLinus Torvalds } else { 7041da177e4SLinus Torvalds memset(&mreq, 0, sizeof(mreq)); 7053a084ddbSJiri Pirko if (optlen >= sizeof(struct ip_mreq)) { 7063a084ddbSJiri Pirko if (copy_from_user(&mreq, optval, 7073a084ddbSJiri Pirko sizeof(struct ip_mreq))) 7083a084ddbSJiri Pirko break; 7093a084ddbSJiri Pirko } else if (optlen >= sizeof(struct in_addr)) { 7103a084ddbSJiri Pirko if (copy_from_user(&mreq.imr_address, optval, 7114d52cfbeSEric Dumazet sizeof(struct in_addr))) 7121da177e4SLinus Torvalds break; 7131da177e4SLinus Torvalds } 7143a084ddbSJiri Pirko } 7151da177e4SLinus Torvalds 7161da177e4SLinus Torvalds if (!mreq.imr_ifindex) { 717e6f1cebfSAl Viro if (mreq.imr_address.s_addr == htonl(INADDR_ANY)) { 7181da177e4SLinus Torvalds inet->mc_index = 0; 7191da177e4SLinus Torvalds inet->mc_addr = 0; 7201da177e4SLinus Torvalds err = 0; 7211da177e4SLinus Torvalds break; 7221da177e4SLinus Torvalds } 7233b1e0a65SYOSHIFUJI Hideaki dev = ip_dev_find(sock_net(sk), mreq.imr_address.s_addr); 72455b80503SEric Dumazet if (dev) 7251da177e4SLinus Torvalds mreq.imr_ifindex = dev->ifindex; 7261da177e4SLinus Torvalds } else 72755b80503SEric Dumazet dev = dev_get_by_index(sock_net(sk), mreq.imr_ifindex); 7281da177e4SLinus Torvalds 7291da177e4SLinus Torvalds 7301da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 7311da177e4SLinus Torvalds if (!dev) 7321da177e4SLinus Torvalds break; 73355b80503SEric Dumazet dev_put(dev); 7341da177e4SLinus Torvalds 7351da177e4SLinus Torvalds err = -EINVAL; 7361da177e4SLinus Torvalds if (sk->sk_bound_dev_if && 7371da177e4SLinus Torvalds mreq.imr_ifindex != sk->sk_bound_dev_if) 7381da177e4SLinus Torvalds break; 7391da177e4SLinus Torvalds 7401da177e4SLinus Torvalds inet->mc_index = mreq.imr_ifindex; 7411da177e4SLinus Torvalds inet->mc_addr = mreq.imr_address.s_addr; 7421da177e4SLinus Torvalds err = 0; 7431da177e4SLinus Torvalds break; 7441da177e4SLinus Torvalds } 7451da177e4SLinus Torvalds 7461da177e4SLinus Torvalds case IP_ADD_MEMBERSHIP: 7471da177e4SLinus Torvalds case IP_DROP_MEMBERSHIP: 7481da177e4SLinus Torvalds { 7491da177e4SLinus Torvalds struct ip_mreqn mreq; 7501da177e4SLinus Torvalds 751a96fb49bSFlavio Leitner err = -EPROTO; 752a96fb49bSFlavio Leitner if (inet_sk(sk)->is_icsk) 753a96fb49bSFlavio Leitner break; 754a96fb49bSFlavio Leitner 7551da177e4SLinus Torvalds if (optlen < sizeof(struct ip_mreq)) 7561da177e4SLinus Torvalds goto e_inval; 7571da177e4SLinus Torvalds err = -EFAULT; 7581da177e4SLinus Torvalds if (optlen >= sizeof(struct ip_mreqn)) { 7591da177e4SLinus Torvalds if (copy_from_user(&mreq, optval, sizeof(mreq))) 7601da177e4SLinus Torvalds break; 7611da177e4SLinus Torvalds } else { 7621da177e4SLinus Torvalds memset(&mreq, 0, sizeof(mreq)); 7631da177e4SLinus Torvalds if (copy_from_user(&mreq, optval, sizeof(struct ip_mreq))) 7641da177e4SLinus Torvalds break; 7651da177e4SLinus Torvalds } 7661da177e4SLinus Torvalds 7671da177e4SLinus Torvalds if (optname == IP_ADD_MEMBERSHIP) 7681da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 7691da177e4SLinus Torvalds else 7701da177e4SLinus Torvalds err = ip_mc_leave_group(sk, &mreq); 7711da177e4SLinus Torvalds break; 7721da177e4SLinus Torvalds } 7731da177e4SLinus Torvalds case IP_MSFILTER: 7741da177e4SLinus Torvalds { 7751da177e4SLinus Torvalds struct ip_msfilter *msf; 7761da177e4SLinus Torvalds 7771da177e4SLinus Torvalds if (optlen < IP_MSFILTER_SIZE(0)) 7781da177e4SLinus Torvalds goto e_inval; 7791da177e4SLinus Torvalds if (optlen > sysctl_optmem_max) { 7801da177e4SLinus Torvalds err = -ENOBUFS; 7811da177e4SLinus Torvalds break; 7821da177e4SLinus Torvalds } 7838b3a7005SKris Katterjohn msf = kmalloc(optlen, GFP_KERNEL); 784cfcabdccSStephen Hemminger if (!msf) { 7851da177e4SLinus Torvalds err = -ENOBUFS; 7861da177e4SLinus Torvalds break; 7871da177e4SLinus Torvalds } 7881da177e4SLinus Torvalds err = -EFAULT; 7891da177e4SLinus Torvalds if (copy_from_user(msf, optval, optlen)) { 7901da177e4SLinus Torvalds kfree(msf); 7911da177e4SLinus Torvalds break; 7921da177e4SLinus Torvalds } 7931da177e4SLinus Torvalds /* numsrc >= (1G-4) overflow in 32 bits */ 7941da177e4SLinus Torvalds if (msf->imsf_numsrc >= 0x3ffffffcU || 7951da177e4SLinus Torvalds msf->imsf_numsrc > sysctl_igmp_max_msf) { 7961da177e4SLinus Torvalds kfree(msf); 7971da177e4SLinus Torvalds err = -ENOBUFS; 7981da177e4SLinus Torvalds break; 7991da177e4SLinus Torvalds } 8001da177e4SLinus Torvalds if (IP_MSFILTER_SIZE(msf->imsf_numsrc) > optlen) { 8011da177e4SLinus Torvalds kfree(msf); 8021da177e4SLinus Torvalds err = -EINVAL; 8031da177e4SLinus Torvalds break; 8041da177e4SLinus Torvalds } 8051da177e4SLinus Torvalds err = ip_mc_msfilter(sk, msf, 0); 8061da177e4SLinus Torvalds kfree(msf); 8071da177e4SLinus Torvalds break; 8081da177e4SLinus Torvalds } 8091da177e4SLinus Torvalds case IP_BLOCK_SOURCE: 8101da177e4SLinus Torvalds case IP_UNBLOCK_SOURCE: 8111da177e4SLinus Torvalds case IP_ADD_SOURCE_MEMBERSHIP: 8121da177e4SLinus Torvalds case IP_DROP_SOURCE_MEMBERSHIP: 8131da177e4SLinus Torvalds { 8141da177e4SLinus Torvalds struct ip_mreq_source mreqs; 8151da177e4SLinus Torvalds int omode, add; 8161da177e4SLinus Torvalds 8171da177e4SLinus Torvalds if (optlen != sizeof(struct ip_mreq_source)) 8181da177e4SLinus Torvalds goto e_inval; 8191da177e4SLinus Torvalds if (copy_from_user(&mreqs, optval, sizeof(mreqs))) { 8201da177e4SLinus Torvalds err = -EFAULT; 8211da177e4SLinus Torvalds break; 8221da177e4SLinus Torvalds } 8231da177e4SLinus Torvalds if (optname == IP_BLOCK_SOURCE) { 8241da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 8251da177e4SLinus Torvalds add = 1; 8261da177e4SLinus Torvalds } else if (optname == IP_UNBLOCK_SOURCE) { 8271da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 8281da177e4SLinus Torvalds add = 0; 8291da177e4SLinus Torvalds } else if (optname == IP_ADD_SOURCE_MEMBERSHIP) { 8301da177e4SLinus Torvalds struct ip_mreqn mreq; 8311da177e4SLinus Torvalds 8321da177e4SLinus Torvalds mreq.imr_multiaddr.s_addr = mreqs.imr_multiaddr; 8331da177e4SLinus Torvalds mreq.imr_address.s_addr = mreqs.imr_interface; 8341da177e4SLinus Torvalds mreq.imr_ifindex = 0; 8351da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 8368cdaaa15SDavid L Stevens if (err && err != -EADDRINUSE) 8371da177e4SLinus Torvalds break; 8381da177e4SLinus Torvalds omode = MCAST_INCLUDE; 8391da177e4SLinus Torvalds add = 1; 8401da177e4SLinus Torvalds } else /* IP_DROP_SOURCE_MEMBERSHIP */ { 8411da177e4SLinus Torvalds omode = MCAST_INCLUDE; 8421da177e4SLinus Torvalds add = 0; 8431da177e4SLinus Torvalds } 8441da177e4SLinus Torvalds err = ip_mc_source(add, omode, sk, &mreqs, 0); 8451da177e4SLinus Torvalds break; 8461da177e4SLinus Torvalds } 8471da177e4SLinus Torvalds case MCAST_JOIN_GROUP: 8481da177e4SLinus Torvalds case MCAST_LEAVE_GROUP: 8491da177e4SLinus Torvalds { 8501da177e4SLinus Torvalds struct group_req greq; 8511da177e4SLinus Torvalds struct sockaddr_in *psin; 8521da177e4SLinus Torvalds struct ip_mreqn mreq; 8531da177e4SLinus Torvalds 8541da177e4SLinus Torvalds if (optlen < sizeof(struct group_req)) 8551da177e4SLinus Torvalds goto e_inval; 8561da177e4SLinus Torvalds err = -EFAULT; 8571da177e4SLinus Torvalds if (copy_from_user(&greq, optval, sizeof(greq))) 8581da177e4SLinus Torvalds break; 8591da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greq.gr_group; 8601da177e4SLinus Torvalds if (psin->sin_family != AF_INET) 8611da177e4SLinus Torvalds goto e_inval; 8621da177e4SLinus Torvalds memset(&mreq, 0, sizeof(mreq)); 8631da177e4SLinus Torvalds mreq.imr_multiaddr = psin->sin_addr; 8641da177e4SLinus Torvalds mreq.imr_ifindex = greq.gr_interface; 8651da177e4SLinus Torvalds 8661da177e4SLinus Torvalds if (optname == MCAST_JOIN_GROUP) 8671da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 8681da177e4SLinus Torvalds else 8691da177e4SLinus Torvalds err = ip_mc_leave_group(sk, &mreq); 8701da177e4SLinus Torvalds break; 8711da177e4SLinus Torvalds } 8721da177e4SLinus Torvalds case MCAST_JOIN_SOURCE_GROUP: 8731da177e4SLinus Torvalds case MCAST_LEAVE_SOURCE_GROUP: 8741da177e4SLinus Torvalds case MCAST_BLOCK_SOURCE: 8751da177e4SLinus Torvalds case MCAST_UNBLOCK_SOURCE: 8761da177e4SLinus Torvalds { 8771da177e4SLinus Torvalds struct group_source_req greqs; 8781da177e4SLinus Torvalds struct ip_mreq_source mreqs; 8791da177e4SLinus Torvalds struct sockaddr_in *psin; 8801da177e4SLinus Torvalds int omode, add; 8811da177e4SLinus Torvalds 8821da177e4SLinus Torvalds if (optlen != sizeof(struct group_source_req)) 8831da177e4SLinus Torvalds goto e_inval; 8841da177e4SLinus Torvalds if (copy_from_user(&greqs, optval, sizeof(greqs))) { 8851da177e4SLinus Torvalds err = -EFAULT; 8861da177e4SLinus Torvalds break; 8871da177e4SLinus Torvalds } 8881da177e4SLinus Torvalds if (greqs.gsr_group.ss_family != AF_INET || 8891da177e4SLinus Torvalds greqs.gsr_source.ss_family != AF_INET) { 8901da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 8911da177e4SLinus Torvalds break; 8921da177e4SLinus Torvalds } 8931da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greqs.gsr_group; 8941da177e4SLinus Torvalds mreqs.imr_multiaddr = psin->sin_addr.s_addr; 8951da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greqs.gsr_source; 8961da177e4SLinus Torvalds mreqs.imr_sourceaddr = psin->sin_addr.s_addr; 8971da177e4SLinus Torvalds mreqs.imr_interface = 0; /* use index for mc_source */ 8981da177e4SLinus Torvalds 8991da177e4SLinus Torvalds if (optname == MCAST_BLOCK_SOURCE) { 9001da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 9011da177e4SLinus Torvalds add = 1; 9021da177e4SLinus Torvalds } else if (optname == MCAST_UNBLOCK_SOURCE) { 9031da177e4SLinus Torvalds omode = MCAST_EXCLUDE; 9041da177e4SLinus Torvalds add = 0; 9051da177e4SLinus Torvalds } else if (optname == MCAST_JOIN_SOURCE_GROUP) { 9061da177e4SLinus Torvalds struct ip_mreqn mreq; 9071da177e4SLinus Torvalds 9081da177e4SLinus Torvalds psin = (struct sockaddr_in *)&greqs.gsr_group; 9091da177e4SLinus Torvalds mreq.imr_multiaddr = psin->sin_addr; 9101da177e4SLinus Torvalds mreq.imr_address.s_addr = 0; 9111da177e4SLinus Torvalds mreq.imr_ifindex = greqs.gsr_interface; 9121da177e4SLinus Torvalds err = ip_mc_join_group(sk, &mreq); 9138cdaaa15SDavid L Stevens if (err && err != -EADDRINUSE) 9141da177e4SLinus Torvalds break; 9151da177e4SLinus Torvalds greqs.gsr_interface = mreq.imr_ifindex; 9161da177e4SLinus Torvalds omode = MCAST_INCLUDE; 9171da177e4SLinus Torvalds add = 1; 9181da177e4SLinus Torvalds } else /* MCAST_LEAVE_SOURCE_GROUP */ { 9191da177e4SLinus Torvalds omode = MCAST_INCLUDE; 9201da177e4SLinus Torvalds add = 0; 9211da177e4SLinus Torvalds } 9221da177e4SLinus Torvalds err = ip_mc_source(add, omode, sk, &mreqs, 9231da177e4SLinus Torvalds greqs.gsr_interface); 9241da177e4SLinus Torvalds break; 9251da177e4SLinus Torvalds } 9261da177e4SLinus Torvalds case MCAST_MSFILTER: 9271da177e4SLinus Torvalds { 9281da177e4SLinus Torvalds struct sockaddr_in *psin; 9291da177e4SLinus Torvalds struct ip_msfilter *msf = NULL; 9301da177e4SLinus Torvalds struct group_filter *gsf = NULL; 9311da177e4SLinus Torvalds int msize, i, ifindex; 9321da177e4SLinus Torvalds 9331da177e4SLinus Torvalds if (optlen < GROUP_FILTER_SIZE(0)) 9341da177e4SLinus Torvalds goto e_inval; 9351da177e4SLinus Torvalds if (optlen > sysctl_optmem_max) { 9361da177e4SLinus Torvalds err = -ENOBUFS; 9371da177e4SLinus Torvalds break; 9381da177e4SLinus Torvalds } 9398b3a7005SKris Katterjohn gsf = kmalloc(optlen, GFP_KERNEL); 940cfcabdccSStephen Hemminger if (!gsf) { 9411da177e4SLinus Torvalds err = -ENOBUFS; 9421da177e4SLinus Torvalds break; 9431da177e4SLinus Torvalds } 9441da177e4SLinus Torvalds err = -EFAULT; 9454d52cfbeSEric Dumazet if (copy_from_user(gsf, optval, optlen)) 9461da177e4SLinus Torvalds goto mc_msf_out; 9474d52cfbeSEric Dumazet 9481da177e4SLinus Torvalds /* numsrc >= (4G-140)/128 overflow in 32 bits */ 9491da177e4SLinus Torvalds if (gsf->gf_numsrc >= 0x1ffffff || 9501da177e4SLinus Torvalds gsf->gf_numsrc > sysctl_igmp_max_msf) { 9511da177e4SLinus Torvalds err = -ENOBUFS; 9521da177e4SLinus Torvalds goto mc_msf_out; 9531da177e4SLinus Torvalds } 9541da177e4SLinus Torvalds if (GROUP_FILTER_SIZE(gsf->gf_numsrc) > optlen) { 9551da177e4SLinus Torvalds err = -EINVAL; 9561da177e4SLinus Torvalds goto mc_msf_out; 9571da177e4SLinus Torvalds } 9581da177e4SLinus Torvalds msize = IP_MSFILTER_SIZE(gsf->gf_numsrc); 9598b3a7005SKris Katterjohn msf = kmalloc(msize, GFP_KERNEL); 960cfcabdccSStephen Hemminger if (!msf) { 9611da177e4SLinus Torvalds err = -ENOBUFS; 9621da177e4SLinus Torvalds goto mc_msf_out; 9631da177e4SLinus Torvalds } 9641da177e4SLinus Torvalds ifindex = gsf->gf_interface; 9651da177e4SLinus Torvalds psin = (struct sockaddr_in *)&gsf->gf_group; 9661da177e4SLinus Torvalds if (psin->sin_family != AF_INET) { 9671da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 9681da177e4SLinus Torvalds goto mc_msf_out; 9691da177e4SLinus Torvalds } 9701da177e4SLinus Torvalds msf->imsf_multiaddr = psin->sin_addr.s_addr; 9711da177e4SLinus Torvalds msf->imsf_interface = 0; 9721da177e4SLinus Torvalds msf->imsf_fmode = gsf->gf_fmode; 9731da177e4SLinus Torvalds msf->imsf_numsrc = gsf->gf_numsrc; 9741da177e4SLinus Torvalds err = -EADDRNOTAVAIL; 9751da177e4SLinus Torvalds for (i = 0; i < gsf->gf_numsrc; ++i) { 9761da177e4SLinus Torvalds psin = (struct sockaddr_in *)&gsf->gf_slist[i]; 9771da177e4SLinus Torvalds 9781da177e4SLinus Torvalds if (psin->sin_family != AF_INET) 9791da177e4SLinus Torvalds goto mc_msf_out; 9801da177e4SLinus Torvalds msf->imsf_slist[i] = psin->sin_addr.s_addr; 9811da177e4SLinus Torvalds } 9821da177e4SLinus Torvalds kfree(gsf); 9831da177e4SLinus Torvalds gsf = NULL; 9841da177e4SLinus Torvalds 9851da177e4SLinus Torvalds err = ip_mc_msfilter(sk, msf, ifindex); 9861da177e4SLinus Torvalds mc_msf_out: 9871da177e4SLinus Torvalds kfree(msf); 9881da177e4SLinus Torvalds kfree(gsf); 9891da177e4SLinus Torvalds break; 9901da177e4SLinus Torvalds } 991f771bef9SNivedita Singhvi case IP_MULTICAST_ALL: 992f771bef9SNivedita Singhvi if (optlen < 1) 993f771bef9SNivedita Singhvi goto e_inval; 994f771bef9SNivedita Singhvi if (val != 0 && val != 1) 995f771bef9SNivedita Singhvi goto e_inval; 996f771bef9SNivedita Singhvi inet->mc_all = val; 997f771bef9SNivedita Singhvi break; 9981da177e4SLinus Torvalds case IP_ROUTER_ALERT: 9991da177e4SLinus Torvalds err = ip_ra_control(sk, val ? 1 : 0, NULL); 10001da177e4SLinus Torvalds break; 10011da177e4SLinus Torvalds 10021da177e4SLinus Torvalds case IP_FREEBIND: 10031da177e4SLinus Torvalds if (optlen < 1) 10041da177e4SLinus Torvalds goto e_inval; 10051da177e4SLinus Torvalds inet->freebind = !!val; 10061da177e4SLinus Torvalds break; 10071da177e4SLinus Torvalds 10081da177e4SLinus Torvalds case IP_IPSEC_POLICY: 10091da177e4SLinus Torvalds case IP_XFRM_POLICY: 10106fc0b4a7SHerbert Xu err = -EPERM; 101152e804c6SEric W. Biederman if (!ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN)) 10126fc0b4a7SHerbert Xu break; 10131da177e4SLinus Torvalds err = xfrm_user_policy(sk, optname, optval, optlen); 10141da177e4SLinus Torvalds break; 10151da177e4SLinus Torvalds 1016f5715aeaSKOVACS Krisztian case IP_TRANSPARENT: 101752e804c6SEric W. Biederman if (!!val && !ns_capable(sock_net(sk)->user_ns, CAP_NET_RAW) && 101852e804c6SEric W. Biederman !ns_capable(sock_net(sk)->user_ns, CAP_NET_ADMIN)) { 1019f5715aeaSKOVACS Krisztian err = -EPERM; 1020f5715aeaSKOVACS Krisztian break; 1021f5715aeaSKOVACS Krisztian } 1022f5715aeaSKOVACS Krisztian if (optlen < 1) 1023f5715aeaSKOVACS Krisztian goto e_inval; 1024f5715aeaSKOVACS Krisztian inet->transparent = !!val; 1025f5715aeaSKOVACS Krisztian break; 1026f5715aeaSKOVACS Krisztian 1027d218d111SStephen Hemminger case IP_MINTTL: 1028d218d111SStephen Hemminger if (optlen < 1) 1029d218d111SStephen Hemminger goto e_inval; 1030d218d111SStephen Hemminger if (val < 0 || val > 255) 1031d218d111SStephen Hemminger goto e_inval; 1032d218d111SStephen Hemminger inet->min_ttl = val; 1033d218d111SStephen Hemminger break; 1034d218d111SStephen Hemminger 10351da177e4SLinus Torvalds default: 10361da177e4SLinus Torvalds err = -ENOPROTOOPT; 10371da177e4SLinus Torvalds break; 10381da177e4SLinus Torvalds } 10391da177e4SLinus Torvalds release_sock(sk); 10401da177e4SLinus Torvalds return err; 10411da177e4SLinus Torvalds 10421da177e4SLinus Torvalds e_inval: 10431da177e4SLinus Torvalds release_sock(sk); 10441da177e4SLinus Torvalds return -EINVAL; 10451da177e4SLinus Torvalds } 10461da177e4SLinus Torvalds 1047f84af32cSEric Dumazet /** 1048d826eb14SEric Dumazet * ipv4_pktinfo_prepare - transfert some info from rtable to skb 1049f84af32cSEric Dumazet * @sk: socket 1050f84af32cSEric Dumazet * @skb: buffer 1051f84af32cSEric Dumazet * 105235ebf65eSDavid S. Miller * To support IP_CMSG_PKTINFO option, we store rt_iif and specific 105335ebf65eSDavid S. Miller * destination in skb->cb[] before dst drop. 1054*8e3bff96Sstephen hemminger * This way, receiver doesn't make cache line misses to read rtable. 1055f84af32cSEric Dumazet */ 1056fbf8866dSShawn Bohrer void ipv4_pktinfo_prepare(const struct sock *sk, struct sk_buff *skb) 1057f84af32cSEric Dumazet { 1058d826eb14SEric Dumazet struct in_pktinfo *pktinfo = PKTINFO_SKB_CB(skb); 1059d826eb14SEric Dumazet 1060fbf8866dSShawn Bohrer if ((inet_sk(sk)->cmsg_flags & IP_CMSG_PKTINFO) && 1061fbf8866dSShawn Bohrer skb_rtable(skb)) { 106292101b3bSDavid S. Miller pktinfo->ipi_ifindex = inet_iif(skb); 106335ebf65eSDavid S. Miller pktinfo->ipi_spec_dst.s_addr = fib_compute_spec_dst(skb); 1064d826eb14SEric Dumazet } else { 1065d826eb14SEric Dumazet pktinfo->ipi_ifindex = 0; 1066d826eb14SEric Dumazet pktinfo->ipi_spec_dst.s_addr = 0; 1067f84af32cSEric Dumazet } 1068d826eb14SEric Dumazet skb_dst_drop(skb); 1069d826eb14SEric Dumazet } 1070f84af32cSEric Dumazet 10713fdadf7dSDmitry Mishin int ip_setsockopt(struct sock *sk, int level, 1072b7058842SDavid S. Miller int optname, char __user *optval, unsigned int optlen) 10733fdadf7dSDmitry Mishin { 10743fdadf7dSDmitry Mishin int err; 10753fdadf7dSDmitry Mishin 10763fdadf7dSDmitry Mishin if (level != SOL_IP) 10773fdadf7dSDmitry Mishin return -ENOPROTOOPT; 10783fdadf7dSDmitry Mishin 10793fdadf7dSDmitry Mishin err = do_ip_setsockopt(sk, level, optname, optval, optlen); 10803fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 10813fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 10823fdadf7dSDmitry Mishin if (err == -ENOPROTOOPT && optname != IP_HDRINCL && 10836a9fb947SPavel Emelyanov optname != IP_IPSEC_POLICY && 10846a9fb947SPavel Emelyanov optname != IP_XFRM_POLICY && 10856a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 10863fdadf7dSDmitry Mishin lock_sock(sk); 10873fdadf7dSDmitry Mishin err = nf_setsockopt(sk, PF_INET, optname, optval, optlen); 10883fdadf7dSDmitry Mishin release_sock(sk); 10893fdadf7dSDmitry Mishin } 10903fdadf7dSDmitry Mishin #endif 10913fdadf7dSDmitry Mishin return err; 10923fdadf7dSDmitry Mishin } 10934d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_setsockopt); 10943fdadf7dSDmitry Mishin 10953fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT 1096543d9cfeSArnaldo Carvalho de Melo int compat_ip_setsockopt(struct sock *sk, int level, int optname, 1097b7058842SDavid S. Miller char __user *optval, unsigned int optlen) 10983fdadf7dSDmitry Mishin { 10993fdadf7dSDmitry Mishin int err; 11003fdadf7dSDmitry Mishin 11013fdadf7dSDmitry Mishin if (level != SOL_IP) 11023fdadf7dSDmitry Mishin return -ENOPROTOOPT; 11033fdadf7dSDmitry Mishin 1104dae50295SDavid L Stevens if (optname >= MCAST_JOIN_GROUP && optname <= MCAST_MSFILTER) 1105dae50295SDavid L Stevens return compat_mc_setsockopt(sk, level, optname, optval, optlen, 1106dae50295SDavid L Stevens ip_setsockopt); 1107dae50295SDavid L Stevens 11083fdadf7dSDmitry Mishin err = do_ip_setsockopt(sk, level, optname, optval, optlen); 11093fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 11103fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 11113fdadf7dSDmitry Mishin if (err == -ENOPROTOOPT && optname != IP_HDRINCL && 11126a9fb947SPavel Emelyanov optname != IP_IPSEC_POLICY && 11136a9fb947SPavel Emelyanov optname != IP_XFRM_POLICY && 11146a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 11153fdadf7dSDmitry Mishin lock_sock(sk); 1116543d9cfeSArnaldo Carvalho de Melo err = compat_nf_setsockopt(sk, PF_INET, optname, 1117543d9cfeSArnaldo Carvalho de Melo optval, optlen); 11183fdadf7dSDmitry Mishin release_sock(sk); 11193fdadf7dSDmitry Mishin } 11203fdadf7dSDmitry Mishin #endif 11213fdadf7dSDmitry Mishin return err; 11223fdadf7dSDmitry Mishin } 1123543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_setsockopt); 11243fdadf7dSDmitry Mishin #endif 11253fdadf7dSDmitry Mishin 11261da177e4SLinus Torvalds /* 11274d52cfbeSEric Dumazet * Get the options. Note for future reference. The GET of IP options gets 11284d52cfbeSEric Dumazet * the _received_ ones. The set sets the _sent_ ones. 11291da177e4SLinus Torvalds */ 11301da177e4SLinus Torvalds 11313fdadf7dSDmitry Mishin static int do_ip_getsockopt(struct sock *sk, int level, int optname, 113295c96174SEric Dumazet char __user *optval, int __user *optlen, unsigned int flags) 11331da177e4SLinus Torvalds { 11341da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 11351da177e4SLinus Torvalds int val; 11361da177e4SLinus Torvalds int len; 11371da177e4SLinus Torvalds 11381da177e4SLinus Torvalds if (level != SOL_IP) 11391da177e4SLinus Torvalds return -EOPNOTSUPP; 11401da177e4SLinus Torvalds 11416a9fb947SPavel Emelyanov if (ip_mroute_opt(optname)) 11421da177e4SLinus Torvalds return ip_mroute_getsockopt(sk, optname, optval, optlen); 11431da177e4SLinus Torvalds 11441da177e4SLinus Torvalds if (get_user(len, optlen)) 11451da177e4SLinus Torvalds return -EFAULT; 11461da177e4SLinus Torvalds if (len < 0) 11471da177e4SLinus Torvalds return -EINVAL; 11481da177e4SLinus Torvalds 11491da177e4SLinus Torvalds lock_sock(sk); 11501da177e4SLinus Torvalds 11511da177e4SLinus Torvalds switch (optname) { 11521da177e4SLinus Torvalds case IP_OPTIONS: 11531da177e4SLinus Torvalds { 11541da177e4SLinus Torvalds unsigned char optbuf[sizeof(struct ip_options)+40]; 11551da177e4SLinus Torvalds struct ip_options *opt = (struct ip_options *)optbuf; 1156f6d8bd05SEric Dumazet struct ip_options_rcu *inet_opt; 1157f6d8bd05SEric Dumazet 1158f6d8bd05SEric Dumazet inet_opt = rcu_dereference_protected(inet->inet_opt, 1159f6d8bd05SEric Dumazet sock_owned_by_user(sk)); 11601da177e4SLinus Torvalds opt->optlen = 0; 1161f6d8bd05SEric Dumazet if (inet_opt) 1162f6d8bd05SEric Dumazet memcpy(optbuf, &inet_opt->opt, 11631da177e4SLinus Torvalds sizeof(struct ip_options) + 1164f6d8bd05SEric Dumazet inet_opt->opt.optlen); 11651da177e4SLinus Torvalds release_sock(sk); 11661da177e4SLinus Torvalds 11671da177e4SLinus Torvalds if (opt->optlen == 0) 11681da177e4SLinus Torvalds return put_user(0, optlen); 11691da177e4SLinus Torvalds 11701da177e4SLinus Torvalds ip_options_undo(opt); 11711da177e4SLinus Torvalds 11721da177e4SLinus Torvalds len = min_t(unsigned int, len, opt->optlen); 11731da177e4SLinus Torvalds if (put_user(len, optlen)) 11741da177e4SLinus Torvalds return -EFAULT; 11751da177e4SLinus Torvalds if (copy_to_user(optval, opt->__data, len)) 11761da177e4SLinus Torvalds return -EFAULT; 11771da177e4SLinus Torvalds return 0; 11781da177e4SLinus Torvalds } 11791da177e4SLinus Torvalds case IP_PKTINFO: 11801da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_PKTINFO) != 0; 11811da177e4SLinus Torvalds break; 11821da177e4SLinus Torvalds case IP_RECVTTL: 11831da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_TTL) != 0; 11841da177e4SLinus Torvalds break; 11851da177e4SLinus Torvalds case IP_RECVTOS: 11861da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_TOS) != 0; 11871da177e4SLinus Torvalds break; 11881da177e4SLinus Torvalds case IP_RECVOPTS: 11891da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_RECVOPTS) != 0; 11901da177e4SLinus Torvalds break; 11911da177e4SLinus Torvalds case IP_RETOPTS: 11921da177e4SLinus Torvalds val = (inet->cmsg_flags & IP_CMSG_RETOPTS) != 0; 11931da177e4SLinus Torvalds break; 11942c7946a7SCatherine Zhang case IP_PASSSEC: 11952c7946a7SCatherine Zhang val = (inet->cmsg_flags & IP_CMSG_PASSSEC) != 0; 11962c7946a7SCatherine Zhang break; 1197e8b2dfe9SBalazs Scheidler case IP_RECVORIGDSTADDR: 1198e8b2dfe9SBalazs Scheidler val = (inet->cmsg_flags & IP_CMSG_ORIGDSTADDR) != 0; 1199e8b2dfe9SBalazs Scheidler break; 12001da177e4SLinus Torvalds case IP_TOS: 12011da177e4SLinus Torvalds val = inet->tos; 12021da177e4SLinus Torvalds break; 12031da177e4SLinus Torvalds case IP_TTL: 12041da177e4SLinus Torvalds val = (inet->uc_ttl == -1 ? 12051da177e4SLinus Torvalds sysctl_ip_default_ttl : 12061da177e4SLinus Torvalds inet->uc_ttl); 12071da177e4SLinus Torvalds break; 12081da177e4SLinus Torvalds case IP_HDRINCL: 12091da177e4SLinus Torvalds val = inet->hdrincl; 12101da177e4SLinus Torvalds break; 1211a89b4763SMichael Kerrisk case IP_NODEFRAG: 1212a89b4763SMichael Kerrisk val = inet->nodefrag; 1213a89b4763SMichael Kerrisk break; 12141da177e4SLinus Torvalds case IP_MTU_DISCOVER: 12151da177e4SLinus Torvalds val = inet->pmtudisc; 12161da177e4SLinus Torvalds break; 12171da177e4SLinus Torvalds case IP_MTU: 12181da177e4SLinus Torvalds { 12191da177e4SLinus Torvalds struct dst_entry *dst; 12201da177e4SLinus Torvalds val = 0; 12211da177e4SLinus Torvalds dst = sk_dst_get(sk); 12221da177e4SLinus Torvalds if (dst) { 12231da177e4SLinus Torvalds val = dst_mtu(dst); 12241da177e4SLinus Torvalds dst_release(dst); 12251da177e4SLinus Torvalds } 12261da177e4SLinus Torvalds if (!val) { 12271da177e4SLinus Torvalds release_sock(sk); 12281da177e4SLinus Torvalds return -ENOTCONN; 12291da177e4SLinus Torvalds } 12301da177e4SLinus Torvalds break; 12311da177e4SLinus Torvalds } 12321da177e4SLinus Torvalds case IP_RECVERR: 12331da177e4SLinus Torvalds val = inet->recverr; 12341da177e4SLinus Torvalds break; 12351da177e4SLinus Torvalds case IP_MULTICAST_TTL: 12361da177e4SLinus Torvalds val = inet->mc_ttl; 12371da177e4SLinus Torvalds break; 12381da177e4SLinus Torvalds case IP_MULTICAST_LOOP: 12391da177e4SLinus Torvalds val = inet->mc_loop; 12401da177e4SLinus Torvalds break; 124176e21053SErich E. Hoover case IP_UNICAST_IF: 124276e21053SErich E. Hoover val = (__force int)htonl((__u32) inet->uc_index); 124376e21053SErich E. Hoover break; 12441da177e4SLinus Torvalds case IP_MULTICAST_IF: 12451da177e4SLinus Torvalds { 12461da177e4SLinus Torvalds struct in_addr addr; 12471da177e4SLinus Torvalds len = min_t(unsigned int, len, sizeof(struct in_addr)); 12481da177e4SLinus Torvalds addr.s_addr = inet->mc_addr; 12491da177e4SLinus Torvalds release_sock(sk); 12501da177e4SLinus Torvalds 12511da177e4SLinus Torvalds if (put_user(len, optlen)) 12521da177e4SLinus Torvalds return -EFAULT; 12531da177e4SLinus Torvalds if (copy_to_user(optval, &addr, len)) 12541da177e4SLinus Torvalds return -EFAULT; 12551da177e4SLinus Torvalds return 0; 12561da177e4SLinus Torvalds } 12571da177e4SLinus Torvalds case IP_MSFILTER: 12581da177e4SLinus Torvalds { 12591da177e4SLinus Torvalds struct ip_msfilter msf; 12601da177e4SLinus Torvalds int err; 12611da177e4SLinus Torvalds 12621da177e4SLinus Torvalds if (len < IP_MSFILTER_SIZE(0)) { 12631da177e4SLinus Torvalds release_sock(sk); 12641da177e4SLinus Torvalds return -EINVAL; 12651da177e4SLinus Torvalds } 12661da177e4SLinus Torvalds if (copy_from_user(&msf, optval, IP_MSFILTER_SIZE(0))) { 12671da177e4SLinus Torvalds release_sock(sk); 12681da177e4SLinus Torvalds return -EFAULT; 12691da177e4SLinus Torvalds } 12701da177e4SLinus Torvalds err = ip_mc_msfget(sk, &msf, 12711da177e4SLinus Torvalds (struct ip_msfilter __user *)optval, optlen); 12721da177e4SLinus Torvalds release_sock(sk); 12731da177e4SLinus Torvalds return err; 12741da177e4SLinus Torvalds } 12751da177e4SLinus Torvalds case MCAST_MSFILTER: 12761da177e4SLinus Torvalds { 12771da177e4SLinus Torvalds struct group_filter gsf; 12781da177e4SLinus Torvalds int err; 12791da177e4SLinus Torvalds 12801da177e4SLinus Torvalds if (len < GROUP_FILTER_SIZE(0)) { 12811da177e4SLinus Torvalds release_sock(sk); 12821da177e4SLinus Torvalds return -EINVAL; 12831da177e4SLinus Torvalds } 12841da177e4SLinus Torvalds if (copy_from_user(&gsf, optval, GROUP_FILTER_SIZE(0))) { 12851da177e4SLinus Torvalds release_sock(sk); 12861da177e4SLinus Torvalds return -EFAULT; 12871da177e4SLinus Torvalds } 12881da177e4SLinus Torvalds err = ip_mc_gsfget(sk, &gsf, 12894d52cfbeSEric Dumazet (struct group_filter __user *)optval, 12904d52cfbeSEric Dumazet optlen); 12911da177e4SLinus Torvalds release_sock(sk); 12921da177e4SLinus Torvalds return err; 12931da177e4SLinus Torvalds } 1294f771bef9SNivedita Singhvi case IP_MULTICAST_ALL: 1295f771bef9SNivedita Singhvi val = inet->mc_all; 1296f771bef9SNivedita Singhvi break; 12971da177e4SLinus Torvalds case IP_PKTOPTIONS: 12981da177e4SLinus Torvalds { 12991da177e4SLinus Torvalds struct msghdr msg; 13001da177e4SLinus Torvalds 13011da177e4SLinus Torvalds release_sock(sk); 13021da177e4SLinus Torvalds 13031da177e4SLinus Torvalds if (sk->sk_type != SOCK_STREAM) 13041da177e4SLinus Torvalds return -ENOPROTOOPT; 13051da177e4SLinus Torvalds 13061da177e4SLinus Torvalds msg.msg_control = optval; 13071da177e4SLinus Torvalds msg.msg_controllen = len; 1308dd23198eSDaniel Baluta msg.msg_flags = flags; 13091da177e4SLinus Torvalds 13101da177e4SLinus Torvalds if (inet->cmsg_flags & IP_CMSG_PKTINFO) { 13111da177e4SLinus Torvalds struct in_pktinfo info; 13121da177e4SLinus Torvalds 1313c720c7e8SEric Dumazet info.ipi_addr.s_addr = inet->inet_rcv_saddr; 1314c720c7e8SEric Dumazet info.ipi_spec_dst.s_addr = inet->inet_rcv_saddr; 13151da177e4SLinus Torvalds info.ipi_ifindex = inet->mc_index; 13161da177e4SLinus Torvalds put_cmsg(&msg, SOL_IP, IP_PKTINFO, sizeof(info), &info); 13171da177e4SLinus Torvalds } 13181da177e4SLinus Torvalds if (inet->cmsg_flags & IP_CMSG_TTL) { 13191da177e4SLinus Torvalds int hlim = inet->mc_ttl; 13201da177e4SLinus Torvalds put_cmsg(&msg, SOL_IP, IP_TTL, sizeof(hlim), &hlim); 13211da177e4SLinus Torvalds } 13224c507d28SJiri Benc if (inet->cmsg_flags & IP_CMSG_TOS) { 13234c507d28SJiri Benc int tos = inet->rcv_tos; 13244c507d28SJiri Benc put_cmsg(&msg, SOL_IP, IP_TOS, sizeof(tos), &tos); 13254c507d28SJiri Benc } 13261da177e4SLinus Torvalds len -= msg.msg_controllen; 13271da177e4SLinus Torvalds return put_user(len, optlen); 13281da177e4SLinus Torvalds } 13291da177e4SLinus Torvalds case IP_FREEBIND: 13301da177e4SLinus Torvalds val = inet->freebind; 13311da177e4SLinus Torvalds break; 1332f5715aeaSKOVACS Krisztian case IP_TRANSPARENT: 1333f5715aeaSKOVACS Krisztian val = inet->transparent; 1334f5715aeaSKOVACS Krisztian break; 1335d218d111SStephen Hemminger case IP_MINTTL: 1336d218d111SStephen Hemminger val = inet->min_ttl; 1337d218d111SStephen Hemminger break; 13381da177e4SLinus Torvalds default: 13391da177e4SLinus Torvalds release_sock(sk); 13401da177e4SLinus Torvalds return -ENOPROTOOPT; 13411da177e4SLinus Torvalds } 13421da177e4SLinus Torvalds release_sock(sk); 13431da177e4SLinus Torvalds 1344951e07c9SDavid S. Miller if (len < sizeof(int) && len > 0 && val >= 0 && val <= 255) { 13451da177e4SLinus Torvalds unsigned char ucval = (unsigned char)val; 13461da177e4SLinus Torvalds len = 1; 13471da177e4SLinus Torvalds if (put_user(len, optlen)) 13481da177e4SLinus Torvalds return -EFAULT; 13491da177e4SLinus Torvalds if (copy_to_user(optval, &ucval, 1)) 13501da177e4SLinus Torvalds return -EFAULT; 13511da177e4SLinus Torvalds } else { 13521da177e4SLinus Torvalds len = min_t(unsigned int, sizeof(int), len); 13531da177e4SLinus Torvalds if (put_user(len, optlen)) 13541da177e4SLinus Torvalds return -EFAULT; 13551da177e4SLinus Torvalds if (copy_to_user(optval, &val, len)) 13561da177e4SLinus Torvalds return -EFAULT; 13571da177e4SLinus Torvalds } 13581da177e4SLinus Torvalds return 0; 13591da177e4SLinus Torvalds } 13601da177e4SLinus Torvalds 13613fdadf7dSDmitry Mishin int ip_getsockopt(struct sock *sk, int level, 13623fdadf7dSDmitry Mishin int optname, char __user *optval, int __user *optlen) 13633fdadf7dSDmitry Mishin { 13643fdadf7dSDmitry Mishin int err; 13653fdadf7dSDmitry Mishin 1366dd23198eSDaniel Baluta err = do_ip_getsockopt(sk, level, optname, optval, optlen, 0); 13673fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 13683fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 13696a9fb947SPavel Emelyanov if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS && 13706a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 13713fdadf7dSDmitry Mishin int len; 13723fdadf7dSDmitry Mishin 13733fdadf7dSDmitry Mishin if (get_user(len, optlen)) 13743fdadf7dSDmitry Mishin return -EFAULT; 13753fdadf7dSDmitry Mishin 13763fdadf7dSDmitry Mishin lock_sock(sk); 13773fdadf7dSDmitry Mishin err = nf_getsockopt(sk, PF_INET, optname, optval, 13783fdadf7dSDmitry Mishin &len); 13793fdadf7dSDmitry Mishin release_sock(sk); 13803fdadf7dSDmitry Mishin if (err >= 0) 13813fdadf7dSDmitry Mishin err = put_user(len, optlen); 13823fdadf7dSDmitry Mishin return err; 13833fdadf7dSDmitry Mishin } 13843fdadf7dSDmitry Mishin #endif 13853fdadf7dSDmitry Mishin return err; 13863fdadf7dSDmitry Mishin } 13874d52cfbeSEric Dumazet EXPORT_SYMBOL(ip_getsockopt); 13883fdadf7dSDmitry Mishin 13893fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT 1390543d9cfeSArnaldo Carvalho de Melo int compat_ip_getsockopt(struct sock *sk, int level, int optname, 1391543d9cfeSArnaldo Carvalho de Melo char __user *optval, int __user *optlen) 13923fdadf7dSDmitry Mishin { 139342908c69SDavid L Stevens int err; 139442908c69SDavid L Stevens 139542908c69SDavid L Stevens if (optname == MCAST_MSFILTER) 139642908c69SDavid L Stevens return compat_mc_getsockopt(sk, level, optname, optval, optlen, 139742908c69SDavid L Stevens ip_getsockopt); 139842908c69SDavid L Stevens 1399dd23198eSDaniel Baluta err = do_ip_getsockopt(sk, level, optname, optval, optlen, 1400dd23198eSDaniel Baluta MSG_CMSG_COMPAT); 140142908c69SDavid L Stevens 14023fdadf7dSDmitry Mishin #ifdef CONFIG_NETFILTER 14033fdadf7dSDmitry Mishin /* we need to exclude all possible ENOPROTOOPTs except default case */ 14046a9fb947SPavel Emelyanov if (err == -ENOPROTOOPT && optname != IP_PKTOPTIONS && 14056a9fb947SPavel Emelyanov !ip_mroute_opt(optname)) { 14063fdadf7dSDmitry Mishin int len; 14073fdadf7dSDmitry Mishin 14083fdadf7dSDmitry Mishin if (get_user(len, optlen)) 14093fdadf7dSDmitry Mishin return -EFAULT; 14103fdadf7dSDmitry Mishin 14113fdadf7dSDmitry Mishin lock_sock(sk); 1412543d9cfeSArnaldo Carvalho de Melo err = compat_nf_getsockopt(sk, PF_INET, optname, optval, &len); 14133fdadf7dSDmitry Mishin release_sock(sk); 14143fdadf7dSDmitry Mishin if (err >= 0) 14153fdadf7dSDmitry Mishin err = put_user(len, optlen); 14163fdadf7dSDmitry Mishin return err; 14173fdadf7dSDmitry Mishin } 14183fdadf7dSDmitry Mishin #endif 14193fdadf7dSDmitry Mishin return err; 14203fdadf7dSDmitry Mishin } 1421543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_ip_getsockopt); 14223fdadf7dSDmitry Mishin #endif 1423