icmp.c 23 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010
  1. /*
  2. * Internet Control Message Protocol (ICMPv6)
  3. * Linux INET6 implementation
  4. *
  5. * Authors:
  6. * Pedro Roque <roque@di.fc.ul.pt>
  7. *
  8. * Based on net/ipv4/icmp.c
  9. *
  10. * RFC 1885
  11. *
  12. * This program is free software; you can redistribute it and/or
  13. * modify it under the terms of the GNU General Public License
  14. * as published by the Free Software Foundation; either version
  15. * 2 of the License, or (at your option) any later version.
  16. */
  17. /*
  18. * Changes:
  19. *
  20. * Andi Kleen : exception handling
  21. * Andi Kleen add rate limits. never reply to a icmp.
  22. * add more length checks and other fixes.
  23. * yoshfuji : ensure to sent parameter problem for
  24. * fragments.
  25. * YOSHIFUJI Hideaki @USAGI: added sysctl for icmp rate limit.
  26. * Randy Dunlap and
  27. * YOSHIFUJI Hideaki @USAGI: Per-interface statistics support
  28. * Kazunori MIYAZAWA @USAGI: change output process to use ip6_append_data
  29. */
  30. #define pr_fmt(fmt) "IPv6: " fmt
  31. #include <linux/module.h>
  32. #include <linux/errno.h>
  33. #include <linux/types.h>
  34. #include <linux/socket.h>
  35. #include <linux/in.h>
  36. #include <linux/kernel.h>
  37. #include <linux/sockios.h>
  38. #include <linux/net.h>
  39. #include <linux/skbuff.h>
  40. #include <linux/init.h>
  41. #include <linux/netfilter.h>
  42. #include <linux/slab.h>
  43. #ifdef CONFIG_SYSCTL
  44. #include <linux/sysctl.h>
  45. #endif
  46. #include <linux/inet.h>
  47. #include <linux/netdevice.h>
  48. #include <linux/icmpv6.h>
  49. #include <net/ip.h>
  50. #include <net/sock.h>
  51. #include <net/ipv6.h>
  52. #include <net/ip6_checksum.h>
  53. #include <net/ping.h>
  54. #include <net/protocol.h>
  55. #include <net/raw.h>
  56. #include <net/rawv6.h>
  57. #include <net/transp_v6.h>
  58. #include <net/ip6_route.h>
  59. #include <net/addrconf.h>
  60. #include <net/icmp.h>
  61. #include <net/xfrm.h>
  62. #include <net/inet_common.h>
  63. #include <asm/uaccess.h>
  64. /*
  65. * The ICMP socket(s). This is the most convenient way to flow control
  66. * our ICMP output as well as maintain a clean interface throughout
  67. * all layers. All Socketless IP sends will soon be gone.
  68. *
  69. * On SMP we have one ICMP socket per-cpu.
  70. */
  71. static inline struct sock *icmpv6_sk(struct net *net)
  72. {
  73. return net->ipv6.icmp_sk[smp_processor_id()];
  74. }
  75. static void icmpv6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
  76. u8 type, u8 code, int offset, __be32 info)
  77. {
  78. /* icmpv6_notify checks 8 bytes can be pulled, icmp6hdr is 8 bytes */
  79. struct icmp6hdr *icmp6 = (struct icmp6hdr *) (skb->data + offset);
  80. if (!(type & ICMPV6_INFOMSG_MASK))
  81. if (icmp6->icmp6_type == ICMPV6_ECHO_REQUEST)
  82. ping_err(skb, offset, ntohl(info));
  83. }
  84. static int icmpv6_rcv(struct sk_buff *skb);
  85. static const struct inet6_protocol icmpv6_protocol = {
  86. .handler = icmpv6_rcv,
  87. .err_handler = icmpv6_err,
  88. .flags = INET6_PROTO_NOPOLICY|INET6_PROTO_FINAL,
  89. };
  90. static __inline__ struct sock *icmpv6_xmit_lock(struct net *net)
  91. {
  92. struct sock *sk;
  93. local_bh_disable();
  94. sk = icmpv6_sk(net);
  95. if (unlikely(!spin_trylock(&sk->sk_lock.slock))) {
  96. /* This can happen if the output path (f.e. SIT or
  97. * ip6ip6 tunnel) signals dst_link_failure() for an
  98. * outgoing ICMP6 packet.
  99. */
  100. local_bh_enable();
  101. return NULL;
  102. }
  103. return sk;
  104. }
  105. static __inline__ void icmpv6_xmit_unlock(struct sock *sk)
  106. {
  107. spin_unlock_bh(&sk->sk_lock.slock);
  108. }
  109. /*
  110. * Slightly more convenient version of icmpv6_send.
  111. */
  112. void icmpv6_param_prob(struct sk_buff *skb, u8 code, int pos)
  113. {
  114. icmpv6_send(skb, ICMPV6_PARAMPROB, code, pos);
  115. kfree_skb(skb);
  116. }
  117. /*
  118. * Figure out, may we reply to this packet with icmp error.
  119. *
  120. * We do not reply, if:
  121. * - it was icmp error message.
  122. * - it is truncated, so that it is known, that protocol is ICMPV6
  123. * (i.e. in the middle of some exthdr)
  124. *
  125. * --ANK (980726)
  126. */
  127. static int is_ineligible(struct sk_buff *skb)
  128. {
  129. int ptr = (u8 *)(ipv6_hdr(skb) + 1) - skb->data;
  130. int len = skb->len - ptr;
  131. __u8 nexthdr = ipv6_hdr(skb)->nexthdr;
  132. __be16 frag_off;
  133. if (len < 0)
  134. return 1;
  135. ptr = ipv6_skip_exthdr(skb, ptr, &nexthdr, &frag_off);
  136. if (ptr < 0)
  137. return 0;
  138. if (nexthdr == IPPROTO_ICMPV6) {
  139. u8 _type, *tp;
  140. tp = skb_header_pointer(skb,
  141. ptr+offsetof(struct icmp6hdr, icmp6_type),
  142. sizeof(_type), &_type);
  143. if (tp == NULL ||
  144. !(*tp & ICMPV6_INFOMSG_MASK))
  145. return 1;
  146. }
  147. return 0;
  148. }
  149. /*
  150. * Check the ICMP output rate limit
  151. */
  152. static inline bool icmpv6_xrlim_allow(struct sock *sk, u8 type,
  153. struct flowi6 *fl6)
  154. {
  155. struct dst_entry *dst;
  156. struct net *net = sock_net(sk);
  157. bool res = false;
  158. /* Informational messages are not limited. */
  159. if (type & ICMPV6_INFOMSG_MASK)
  160. return true;
  161. /* Do not limit pmtu discovery, it would break it. */
  162. if (type == ICMPV6_PKT_TOOBIG)
  163. return true;
  164. /*
  165. * Look up the output route.
  166. * XXX: perhaps the expire for routing entries cloned by
  167. * this lookup should be more aggressive (not longer than timeout).
  168. */
  169. dst = ip6_route_output(net, sk, fl6);
  170. if (dst->error) {
  171. IP6_INC_STATS(net, ip6_dst_idev(dst),
  172. IPSTATS_MIB_OUTNOROUTES);
  173. } else if (dst->dev && (dst->dev->flags&IFF_LOOPBACK)) {
  174. res = true;
  175. } else {
  176. struct rt6_info *rt = (struct rt6_info *)dst;
  177. int tmo = net->ipv6.sysctl.icmpv6_time;
  178. /* Give more bandwidth to wider prefixes. */
  179. if (rt->rt6i_dst.plen < 128)
  180. tmo >>= ((128 - rt->rt6i_dst.plen)>>5);
  181. if (!rt->rt6i_peer)
  182. rt6_bind_peer(rt, 1);
  183. res = inet_peer_xrlim_allow(rt->rt6i_peer, tmo);
  184. }
  185. dst_release(dst);
  186. return res;
  187. }
  188. /*
  189. * an inline helper for the "simple" if statement below
  190. * checks if parameter problem report is caused by an
  191. * unrecognized IPv6 option that has the Option Type
  192. * highest-order two bits set to 10
  193. */
  194. static __inline__ int opt_unrec(struct sk_buff *skb, __u32 offset)
  195. {
  196. u8 _optval, *op;
  197. offset += skb_network_offset(skb);
  198. op = skb_header_pointer(skb, offset, sizeof(_optval), &_optval);
  199. if (op == NULL)
  200. return 1;
  201. return (*op & 0xC0) == 0x80;
  202. }
  203. int icmpv6_push_pending_frames(struct sock *sk, struct flowi6 *fl6,
  204. struct icmp6hdr *thdr, int len)
  205. {
  206. struct sk_buff *skb;
  207. struct icmp6hdr *icmp6h;
  208. int err = 0;
  209. if ((skb = skb_peek(&sk->sk_write_queue)) == NULL)
  210. goto out;
  211. icmp6h = icmp6_hdr(skb);
  212. memcpy(icmp6h, thdr, sizeof(struct icmp6hdr));
  213. icmp6h->icmp6_cksum = 0;
  214. if (skb_queue_len(&sk->sk_write_queue) == 1) {
  215. skb->csum = csum_partial(icmp6h,
  216. sizeof(struct icmp6hdr), skb->csum);
  217. icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
  218. &fl6->daddr,
  219. len, fl6->flowi6_proto,
  220. skb->csum);
  221. } else {
  222. __wsum tmp_csum = 0;
  223. skb_queue_walk(&sk->sk_write_queue, skb) {
  224. tmp_csum = csum_add(tmp_csum, skb->csum);
  225. }
  226. tmp_csum = csum_partial(icmp6h,
  227. sizeof(struct icmp6hdr), tmp_csum);
  228. icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
  229. &fl6->daddr,
  230. len, fl6->flowi6_proto,
  231. tmp_csum);
  232. }
  233. ip6_push_pending_frames(sk);
  234. out:
  235. return err;
  236. }
  237. struct icmpv6_msg {
  238. struct sk_buff *skb;
  239. int offset;
  240. uint8_t type;
  241. };
  242. static int icmpv6_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
  243. {
  244. struct icmpv6_msg *msg = (struct icmpv6_msg *) from;
  245. struct sk_buff *org_skb = msg->skb;
  246. __wsum csum = 0;
  247. csum = skb_copy_and_csum_bits(org_skb, msg->offset + offset,
  248. to, len, csum);
  249. skb->csum = csum_block_add(skb->csum, csum, odd);
  250. if (!(msg->type & ICMPV6_INFOMSG_MASK))
  251. nf_ct_attach(skb, org_skb);
  252. return 0;
  253. }
  254. #if defined(CONFIG_IPV6_MIP6) || defined(CONFIG_IPV6_MIP6_MODULE)
  255. static void mip6_addr_swap(struct sk_buff *skb)
  256. {
  257. struct ipv6hdr *iph = ipv6_hdr(skb);
  258. struct inet6_skb_parm *opt = IP6CB(skb);
  259. struct ipv6_destopt_hao *hao;
  260. struct in6_addr tmp;
  261. int off;
  262. if (opt->dsthao) {
  263. off = ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO);
  264. if (likely(off >= 0)) {
  265. hao = (struct ipv6_destopt_hao *)
  266. (skb_network_header(skb) + off);
  267. tmp = iph->saddr;
  268. iph->saddr = hao->addr;
  269. hao->addr = tmp;
  270. }
  271. }
  272. }
  273. #else
  274. static inline void mip6_addr_swap(struct sk_buff *skb) {}
  275. #endif
  276. struct dst_entry *icmpv6_route_lookup(struct net *net, struct sk_buff *skb,
  277. struct sock *sk, struct flowi6 *fl6)
  278. {
  279. struct dst_entry *dst, *dst2;
  280. struct flowi6 fl2;
  281. int err;
  282. err = ip6_dst_lookup(sk, &dst, fl6);
  283. if (err)
  284. return ERR_PTR(err);
  285. /*
  286. * We won't send icmp if the destination is known
  287. * anycast.
  288. */
  289. if (((struct rt6_info *)dst)->rt6i_flags & RTF_ANYCAST) {
  290. LIMIT_NETDEBUG(KERN_DEBUG "icmpv6_send: acast source\n");
  291. dst_release(dst);
  292. return ERR_PTR(-EINVAL);
  293. }
  294. /* No need to clone since we're just using its address. */
  295. dst2 = dst;
  296. dst = xfrm_lookup(net, dst, flowi6_to_flowi(fl6), sk, 0);
  297. if (!IS_ERR(dst)) {
  298. if (dst != dst2)
  299. return dst;
  300. } else {
  301. if (PTR_ERR(dst) == -EPERM)
  302. dst = NULL;
  303. else
  304. return dst;
  305. }
  306. err = xfrm_decode_session_reverse(skb, flowi6_to_flowi(&fl2), AF_INET6);
  307. if (err)
  308. goto relookup_failed;
  309. err = ip6_dst_lookup(sk, &dst2, &fl2);
  310. if (err)
  311. goto relookup_failed;
  312. dst2 = xfrm_lookup(net, dst2, flowi6_to_flowi(&fl2), sk, XFRM_LOOKUP_ICMP);
  313. if (!IS_ERR(dst2)) {
  314. dst_release(dst);
  315. dst = dst2;
  316. } else {
  317. err = PTR_ERR(dst2);
  318. if (err == -EPERM) {
  319. dst_release(dst);
  320. return dst2;
  321. } else
  322. goto relookup_failed;
  323. }
  324. relookup_failed:
  325. if (dst)
  326. return dst;
  327. return ERR_PTR(err);
  328. }
  329. /*
  330. * Send an ICMP message in response to a packet in error
  331. */
  332. void icmpv6_send(struct sk_buff *skb, u8 type, u8 code, __u32 info)
  333. {
  334. struct net *net = dev_net(skb->dev);
  335. struct inet6_dev *idev = NULL;
  336. struct ipv6hdr *hdr = ipv6_hdr(skb);
  337. struct sock *sk;
  338. struct ipv6_pinfo *np;
  339. const struct in6_addr *saddr = NULL;
  340. struct dst_entry *dst;
  341. struct icmp6hdr tmp_hdr;
  342. struct flowi6 fl6;
  343. struct icmpv6_msg msg;
  344. int iif = 0;
  345. int addr_type = 0;
  346. int len;
  347. int hlimit;
  348. int err = 0;
  349. u32 mark = IP6_REPLY_MARK(net, skb->mark);
  350. if ((u8 *)hdr < skb->head ||
  351. (skb->network_header + sizeof(*hdr)) > skb->tail)
  352. return;
  353. /*
  354. * Make sure we respect the rules
  355. * i.e. RFC 1885 2.4(e)
  356. * Rule (e.1) is enforced by not using icmpv6_send
  357. * in any code that processes icmp errors.
  358. */
  359. addr_type = ipv6_addr_type(&hdr->daddr);
  360. if (ipv6_chk_addr(net, &hdr->daddr, skb->dev, 0))
  361. saddr = &hdr->daddr;
  362. /*
  363. * Dest addr check
  364. */
  365. if ((addr_type & IPV6_ADDR_MULTICAST || skb->pkt_type != PACKET_HOST)) {
  366. if (type != ICMPV6_PKT_TOOBIG &&
  367. !(type == ICMPV6_PARAMPROB &&
  368. code == ICMPV6_UNK_OPTION &&
  369. (opt_unrec(skb, info))))
  370. return;
  371. saddr = NULL;
  372. }
  373. addr_type = ipv6_addr_type(&hdr->saddr);
  374. /*
  375. * Source addr check
  376. */
  377. if (__ipv6_addr_needs_scope_id(addr_type))
  378. iif = skb->dev->ifindex;
  379. /*
  380. * Must not send error if the source does not uniquely
  381. * identify a single node (RFC2463 Section 2.4).
  382. * We check unspecified / multicast addresses here,
  383. * and anycast addresses will be checked later.
  384. */
  385. if ((addr_type == IPV6_ADDR_ANY) || (addr_type & IPV6_ADDR_MULTICAST)) {
  386. LIMIT_NETDEBUG(KERN_DEBUG "icmpv6_send: addr_any/mcast source\n");
  387. return;
  388. }
  389. /*
  390. * Never answer to a ICMP packet.
  391. */
  392. if (is_ineligible(skb)) {
  393. LIMIT_NETDEBUG(KERN_DEBUG "icmpv6_send: no reply to icmp error\n");
  394. return;
  395. }
  396. mip6_addr_swap(skb);
  397. memset(&fl6, 0, sizeof(fl6));
  398. fl6.flowi6_proto = IPPROTO_ICMPV6;
  399. fl6.daddr = hdr->saddr;
  400. if (saddr)
  401. fl6.saddr = *saddr;
  402. fl6.flowi6_mark = mark;
  403. fl6.flowi6_oif = iif;
  404. fl6.fl6_icmp_type = type;
  405. fl6.fl6_icmp_code = code;
  406. fl6.flowi6_uid = sock_net_uid(net, NULL);
  407. security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
  408. sk = icmpv6_xmit_lock(net);
  409. if (sk == NULL)
  410. return;
  411. sk->sk_mark = mark;
  412. np = inet6_sk(sk);
  413. if (!icmpv6_xrlim_allow(sk, type, &fl6))
  414. goto out;
  415. tmp_hdr.icmp6_type = type;
  416. tmp_hdr.icmp6_code = code;
  417. tmp_hdr.icmp6_cksum = 0;
  418. tmp_hdr.icmp6_pointer = htonl(info);
  419. if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
  420. fl6.flowi6_oif = np->mcast_oif;
  421. else if (!fl6.flowi6_oif)
  422. fl6.flowi6_oif = np->ucast_oif;
  423. dst = icmpv6_route_lookup(net, skb, sk, &fl6);
  424. if (IS_ERR(dst))
  425. goto out;
  426. if (ipv6_addr_is_multicast(&fl6.daddr))
  427. hlimit = np->mcast_hops;
  428. else
  429. hlimit = np->hop_limit;
  430. if (hlimit < 0)
  431. hlimit = ip6_dst_hoplimit(dst);
  432. msg.skb = skb;
  433. msg.offset = skb_network_offset(skb);
  434. msg.type = type;
  435. len = skb->len - msg.offset;
  436. len = min_t(unsigned int, len, IPV6_MIN_MTU - sizeof(struct ipv6hdr) -sizeof(struct icmp6hdr));
  437. if (len < 0) {
  438. LIMIT_NETDEBUG(KERN_DEBUG "icmp: len problem\n");
  439. goto out_dst_release;
  440. }
  441. rcu_read_lock();
  442. idev = __in6_dev_get(skb->dev);
  443. err = ip6_append_data(sk, icmpv6_getfrag, &msg,
  444. len + sizeof(struct icmp6hdr),
  445. sizeof(struct icmp6hdr), hlimit,
  446. np->tclass, NULL, &fl6, (struct rt6_info*)dst,
  447. MSG_DONTWAIT, np->dontfrag);
  448. if (err) {
  449. ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
  450. ip6_flush_pending_frames(sk);
  451. } else {
  452. err = icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
  453. len + sizeof(struct icmp6hdr));
  454. }
  455. rcu_read_unlock();
  456. out_dst_release:
  457. dst_release(dst);
  458. out:
  459. icmpv6_xmit_unlock(sk);
  460. }
  461. EXPORT_SYMBOL(icmpv6_send);
  462. static void icmpv6_echo_reply(struct sk_buff *skb)
  463. {
  464. struct net *net = dev_net(skb->dev);
  465. struct sock *sk;
  466. struct inet6_dev *idev;
  467. struct ipv6_pinfo *np;
  468. const struct in6_addr *saddr = NULL;
  469. struct icmp6hdr *icmph = icmp6_hdr(skb);
  470. struct icmp6hdr tmp_hdr;
  471. struct flowi6 fl6;
  472. struct icmpv6_msg msg;
  473. struct dst_entry *dst;
  474. int err = 0;
  475. int hlimit;
  476. u32 mark = IP6_REPLY_MARK(net, skb->mark);
  477. saddr = &ipv6_hdr(skb)->daddr;
  478. if (!ipv6_unicast_destination(skb))
  479. saddr = NULL;
  480. memcpy(&tmp_hdr, icmph, sizeof(tmp_hdr));
  481. tmp_hdr.icmp6_type = ICMPV6_ECHO_REPLY;
  482. memset(&fl6, 0, sizeof(fl6));
  483. fl6.flowi6_proto = IPPROTO_ICMPV6;
  484. fl6.daddr = ipv6_hdr(skb)->saddr;
  485. if (saddr)
  486. fl6.saddr = *saddr;
  487. fl6.flowi6_oif = skb->dev->ifindex;
  488. fl6.fl6_icmp_type = ICMPV6_ECHO_REPLY;
  489. fl6.flowi6_mark = mark;
  490. fl6.flowi6_uid = sock_net_uid(net, NULL);
  491. security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
  492. sk = icmpv6_xmit_lock(net);
  493. if (sk == NULL)
  494. return;
  495. sk->sk_mark = mark;
  496. np = inet6_sk(sk);
  497. if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
  498. fl6.flowi6_oif = np->mcast_oif;
  499. else if (!fl6.flowi6_oif)
  500. fl6.flowi6_oif = np->ucast_oif;
  501. err = ip6_dst_lookup(sk, &dst, &fl6);
  502. if (err)
  503. goto out;
  504. dst = xfrm_lookup(net, dst, flowi6_to_flowi(&fl6), sk, 0);
  505. if (IS_ERR(dst))
  506. goto out;
  507. if (ipv6_addr_is_multicast(&fl6.daddr))
  508. hlimit = np->mcast_hops;
  509. else
  510. hlimit = np->hop_limit;
  511. if (hlimit < 0)
  512. hlimit = ip6_dst_hoplimit(dst);
  513. idev = __in6_dev_get(skb->dev);
  514. msg.skb = skb;
  515. msg.offset = 0;
  516. msg.type = ICMPV6_ECHO_REPLY;
  517. err = ip6_append_data(sk, icmpv6_getfrag, &msg, skb->len + sizeof(struct icmp6hdr),
  518. sizeof(struct icmp6hdr), hlimit, np->tclass, NULL, &fl6,
  519. (struct rt6_info*)dst, MSG_DONTWAIT,
  520. np->dontfrag);
  521. if (err) {
  522. ICMP6_INC_STATS_BH(net, idev, ICMP6_MIB_OUTERRORS);
  523. ip6_flush_pending_frames(sk);
  524. } else {
  525. err = icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
  526. skb->len + sizeof(struct icmp6hdr));
  527. }
  528. dst_release(dst);
  529. out:
  530. icmpv6_xmit_unlock(sk);
  531. }
  532. void icmpv6_notify(struct sk_buff *skb, u8 type, u8 code, __be32 info)
  533. {
  534. const struct inet6_protocol *ipprot;
  535. int inner_offset;
  536. int hash;
  537. u8 nexthdr;
  538. __be16 frag_off;
  539. if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
  540. return;
  541. nexthdr = ((struct ipv6hdr *)skb->data)->nexthdr;
  542. if (ipv6_ext_hdr(nexthdr)) {
  543. /* now skip over extension headers */
  544. inner_offset = ipv6_skip_exthdr(skb, sizeof(struct ipv6hdr),
  545. &nexthdr, &frag_off);
  546. if (inner_offset<0)
  547. return;
  548. } else {
  549. inner_offset = sizeof(struct ipv6hdr);
  550. }
  551. /* Checkin header including 8 bytes of inner protocol header. */
  552. if (!pskb_may_pull(skb, inner_offset+8))
  553. return;
  554. /* BUGGG_FUTURE: we should try to parse exthdrs in this packet.
  555. Without this we will not able f.e. to make source routed
  556. pmtu discovery.
  557. Corresponding argument (opt) to notifiers is already added.
  558. --ANK (980726)
  559. */
  560. hash = nexthdr & (MAX_INET_PROTOS - 1);
  561. rcu_read_lock();
  562. ipprot = rcu_dereference(inet6_protos[hash]);
  563. if (ipprot && ipprot->err_handler)
  564. ipprot->err_handler(skb, NULL, type, code, inner_offset, info);
  565. rcu_read_unlock();
  566. raw6_icmp_error(skb, nexthdr, type, code, inner_offset, info);
  567. }
  568. /*
  569. * Handle icmp messages
  570. */
  571. static int icmpv6_rcv(struct sk_buff *skb)
  572. {
  573. struct net_device *dev = skb->dev;
  574. struct inet6_dev *idev = __in6_dev_get(dev);
  575. const struct in6_addr *saddr, *daddr;
  576. struct icmp6hdr *hdr;
  577. u8 type;
  578. if (!xfrm6_policy_check(NULL, XFRM_POLICY_IN, skb)) {
  579. struct sec_path *sp = skb_sec_path(skb);
  580. int nh;
  581. if (!(sp && sp->xvec[sp->len - 1]->props.flags &
  582. XFRM_STATE_ICMP))
  583. goto drop_no_count;
  584. if (!pskb_may_pull(skb, sizeof(*hdr) + sizeof(struct ipv6hdr)))
  585. goto drop_no_count;
  586. nh = skb_network_offset(skb);
  587. skb_set_network_header(skb, sizeof(*hdr));
  588. if (!xfrm6_policy_check_reverse(NULL, XFRM_POLICY_IN, skb))
  589. goto drop_no_count;
  590. skb_set_network_header(skb, nh);
  591. }
  592. ICMP6_INC_STATS_BH(dev_net(dev), idev, ICMP6_MIB_INMSGS);
  593. saddr = &ipv6_hdr(skb)->saddr;
  594. daddr = &ipv6_hdr(skb)->daddr;
  595. /* Perform checksum. */
  596. switch (skb->ip_summed) {
  597. case CHECKSUM_COMPLETE:
  598. if (!csum_ipv6_magic(saddr, daddr, skb->len, IPPROTO_ICMPV6,
  599. skb->csum))
  600. break;
  601. /* fall through */
  602. case CHECKSUM_NONE:
  603. skb->csum = ~csum_unfold(csum_ipv6_magic(saddr, daddr, skb->len,
  604. IPPROTO_ICMPV6, 0));
  605. if (__skb_checksum_complete(skb)) {
  606. LIMIT_NETDEBUG(KERN_DEBUG
  607. "ICMPv6 checksum failed [%pI6c > %pI6c]\n",
  608. saddr, daddr);
  609. goto discard_it;
  610. }
  611. }
  612. if (!pskb_pull(skb, sizeof(*hdr)))
  613. goto discard_it;
  614. hdr = icmp6_hdr(skb);
  615. type = hdr->icmp6_type;
  616. ICMP6MSGIN_INC_STATS_BH(dev_net(dev), idev, type);
  617. switch (type) {
  618. case ICMPV6_ECHO_REQUEST:
  619. icmpv6_echo_reply(skb);
  620. break;
  621. case ICMPV6_ECHO_REPLY:
  622. ping_rcv(skb);
  623. break;
  624. case ICMPV6_PKT_TOOBIG:
  625. /* BUGGG_FUTURE: if packet contains rthdr, we cannot update
  626. standard destination cache. Seems, only "advanced"
  627. destination cache will allow to solve this problem
  628. --ANK (980726)
  629. */
  630. if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
  631. goto discard_it;
  632. hdr = icmp6_hdr(skb);
  633. /*
  634. * Drop through to notify
  635. */
  636. case ICMPV6_DEST_UNREACH:
  637. case ICMPV6_TIME_EXCEED:
  638. case ICMPV6_PARAMPROB:
  639. icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
  640. break;
  641. case NDISC_ROUTER_SOLICITATION:
  642. case NDISC_ROUTER_ADVERTISEMENT:
  643. case NDISC_NEIGHBOUR_SOLICITATION:
  644. case NDISC_NEIGHBOUR_ADVERTISEMENT:
  645. case NDISC_REDIRECT:
  646. ndisc_rcv(skb);
  647. break;
  648. case ICMPV6_MGM_QUERY:
  649. igmp6_event_query(skb);
  650. break;
  651. case ICMPV6_MGM_REPORT:
  652. igmp6_event_report(skb);
  653. break;
  654. case ICMPV6_MGM_REDUCTION:
  655. case ICMPV6_NI_QUERY:
  656. case ICMPV6_NI_REPLY:
  657. case ICMPV6_MLD2_REPORT:
  658. case ICMPV6_DHAAD_REQUEST:
  659. case ICMPV6_DHAAD_REPLY:
  660. case ICMPV6_MOBILE_PREFIX_SOL:
  661. case ICMPV6_MOBILE_PREFIX_ADV:
  662. break;
  663. default:
  664. LIMIT_NETDEBUG(KERN_DEBUG "icmpv6: msg of unknown type\n");
  665. /* informational */
  666. if (type & ICMPV6_INFOMSG_MASK)
  667. break;
  668. /*
  669. * error of unknown type.
  670. * must pass to upper level
  671. */
  672. icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
  673. }
  674. kfree_skb(skb);
  675. return 0;
  676. discard_it:
  677. ICMP6_INC_STATS_BH(dev_net(dev), idev, ICMP6_MIB_INERRORS);
  678. drop_no_count:
  679. kfree_skb(skb);
  680. return 0;
  681. }
  682. void icmpv6_flow_init(struct sock *sk, struct flowi6 *fl6,
  683. u8 type,
  684. const struct in6_addr *saddr,
  685. const struct in6_addr *daddr,
  686. int oif)
  687. {
  688. memset(fl6, 0, sizeof(*fl6));
  689. fl6->saddr = *saddr;
  690. fl6->daddr = *daddr;
  691. fl6->flowi6_proto = IPPROTO_ICMPV6;
  692. fl6->fl6_icmp_type = type;
  693. fl6->fl6_icmp_code = 0;
  694. fl6->flowi6_oif = oif;
  695. security_sk_classify_flow(sk, flowi6_to_flowi(fl6));
  696. }
  697. /*
  698. * Special lock-class for __icmpv6_sk:
  699. */
  700. static struct lock_class_key icmpv6_socket_sk_dst_lock_key;
  701. static int __net_init icmpv6_sk_init(struct net *net)
  702. {
  703. struct sock *sk;
  704. int err, i, j;
  705. net->ipv6.icmp_sk =
  706. kzalloc(nr_cpu_ids * sizeof(struct sock *), GFP_KERNEL);
  707. if (net->ipv6.icmp_sk == NULL)
  708. return -ENOMEM;
  709. for_each_possible_cpu(i) {
  710. err = inet_ctl_sock_create(&sk, PF_INET6,
  711. SOCK_RAW, IPPROTO_ICMPV6, net);
  712. if (err < 0) {
  713. pr_err("Failed to initialize the ICMP6 control socket (err %d)\n",
  714. err);
  715. goto fail;
  716. }
  717. net->ipv6.icmp_sk[i] = sk;
  718. /*
  719. * Split off their lock-class, because sk->sk_dst_lock
  720. * gets used from softirqs, which is safe for
  721. * __icmpv6_sk (because those never get directly used
  722. * via userspace syscalls), but unsafe for normal sockets.
  723. */
  724. lockdep_set_class(&sk->sk_dst_lock,
  725. &icmpv6_socket_sk_dst_lock_key);
  726. /* Enough space for 2 64K ICMP packets, including
  727. * sk_buff struct overhead.
  728. */
  729. sk->sk_sndbuf = 2 * SKB_TRUESIZE(64 * 1024);
  730. }
  731. return 0;
  732. fail:
  733. for (j = 0; j < i; j++)
  734. inet_ctl_sock_destroy(net->ipv6.icmp_sk[j]);
  735. kfree(net->ipv6.icmp_sk);
  736. return err;
  737. }
  738. static void __net_exit icmpv6_sk_exit(struct net *net)
  739. {
  740. int i;
  741. for_each_possible_cpu(i) {
  742. inet_ctl_sock_destroy(net->ipv6.icmp_sk[i]);
  743. }
  744. kfree(net->ipv6.icmp_sk);
  745. }
  746. static struct pernet_operations icmpv6_sk_ops = {
  747. .init = icmpv6_sk_init,
  748. .exit = icmpv6_sk_exit,
  749. };
  750. int __init icmpv6_init(void)
  751. {
  752. int err;
  753. err = register_pernet_subsys(&icmpv6_sk_ops);
  754. if (err < 0)
  755. return err;
  756. err = -EAGAIN;
  757. if (inet6_add_protocol(&icmpv6_protocol, IPPROTO_ICMPV6) < 0)
  758. goto fail;
  759. return 0;
  760. fail:
  761. pr_err("Failed to register ICMP6 protocol\n");
  762. unregister_pernet_subsys(&icmpv6_sk_ops);
  763. return err;
  764. }
  765. void icmpv6_cleanup(void)
  766. {
  767. unregister_pernet_subsys(&icmpv6_sk_ops);
  768. inet6_del_protocol(&icmpv6_protocol, IPPROTO_ICMPV6);
  769. }
  770. static const struct icmp6_err {
  771. int err;
  772. int fatal;
  773. } tab_unreach[] = {
  774. { /* NOROUTE */
  775. .err = ENETUNREACH,
  776. .fatal = 0,
  777. },
  778. { /* ADM_PROHIBITED */
  779. .err = EACCES,
  780. .fatal = 1,
  781. },
  782. { /* Was NOT_NEIGHBOUR, now reserved */
  783. .err = EHOSTUNREACH,
  784. .fatal = 0,
  785. },
  786. { /* ADDR_UNREACH */
  787. .err = EHOSTUNREACH,
  788. .fatal = 0,
  789. },
  790. { /* PORT_UNREACH */
  791. .err = ECONNREFUSED,
  792. .fatal = 1,
  793. },
  794. { /* POLICY_FAIL */
  795. .err = EACCES,
  796. .fatal = 1,
  797. },
  798. { /* REJECT_ROUTE */
  799. .err = EACCES,
  800. .fatal = 1,
  801. },
  802. };
  803. int icmpv6_err_convert(u8 type, u8 code, int *err)
  804. {
  805. int fatal = 0;
  806. *err = EPROTO;
  807. switch (type) {
  808. case ICMPV6_DEST_UNREACH:
  809. fatal = 1;
  810. if (code < ARRAY_SIZE(tab_unreach)) {
  811. *err = tab_unreach[code].err;
  812. fatal = tab_unreach[code].fatal;
  813. }
  814. break;
  815. case ICMPV6_PKT_TOOBIG:
  816. *err = EMSGSIZE;
  817. break;
  818. case ICMPV6_PARAMPROB:
  819. *err = EPROTO;
  820. fatal = 1;
  821. break;
  822. case ICMPV6_TIME_EXCEED:
  823. *err = EHOSTUNREACH;
  824. break;
  825. }
  826. return fatal;
  827. }
  828. EXPORT_SYMBOL(icmpv6_err_convert);
  829. #ifdef CONFIG_SYSCTL
  830. ctl_table ipv6_icmp_table_template[] = {
  831. {
  832. .procname = "ratelimit",
  833. .data = &init_net.ipv6.sysctl.icmpv6_time,
  834. .maxlen = sizeof(int),
  835. .mode = 0644,
  836. .proc_handler = proc_dointvec_ms_jiffies,
  837. },
  838. { },
  839. };
  840. struct ctl_table * __net_init ipv6_icmp_sysctl_init(struct net *net)
  841. {
  842. struct ctl_table *table;
  843. table = kmemdup(ipv6_icmp_table_template,
  844. sizeof(ipv6_icmp_table_template),
  845. GFP_KERNEL);
  846. if (table)
  847. table[0].data = &net->ipv6.sysctl.icmpv6_time;
  848. return table;
  849. }
  850. #endif