blob: f6144fe6212e55039b7de82aba226e8fc7aab2e8 [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * Internet Control Message Protocol (ICMPv6)
3 * Linux INET6 implementation
4 *
5 * Authors:
6 * Pedro Roque <roque@di.fc.ul.pt>
7 *
Linus Torvalds1da177e2005-04-16 15:20:36 -07008 * Based on net/ipv4/icmp.c
9 *
10 * RFC 1885
11 *
12 * This program is free software; you can redistribute it and/or
13 * modify it under the terms of the GNU General Public License
14 * as published by the Free Software Foundation; either version
15 * 2 of the License, or (at your option) any later version.
16 */
17
18/*
19 * Changes:
20 *
21 * Andi Kleen : exception handling
22 * Andi Kleen add rate limits. never reply to a icmp.
23 * add more length checks and other fixes.
24 * yoshfuji : ensure to sent parameter problem for
25 * fragments.
26 * YOSHIFUJI Hideaki @USAGI: added sysctl for icmp rate limit.
27 * Randy Dunlap and
28 * YOSHIFUJI Hideaki @USAGI: Per-interface statistics support
29 * Kazunori MIYAZAWA @USAGI: change output process to use ip6_append_data
30 */
31
Joe Perchesf3213832012-05-15 14:11:53 +000032#define pr_fmt(fmt) "IPv6: " fmt
33
Linus Torvalds1da177e2005-04-16 15:20:36 -070034#include <linux/module.h>
35#include <linux/errno.h>
36#include <linux/types.h>
37#include <linux/socket.h>
38#include <linux/in.h>
39#include <linux/kernel.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070040#include <linux/sockios.h>
41#include <linux/net.h>
42#include <linux/skbuff.h>
43#include <linux/init.h>
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -080044#include <linux/netfilter.h>
Tejun Heo5a0e3ad2010-03-24 17:04:11 +090045#include <linux/slab.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070046
47#ifdef CONFIG_SYSCTL
48#include <linux/sysctl.h>
49#endif
50
51#include <linux/inet.h>
52#include <linux/netdevice.h>
53#include <linux/icmpv6.h>
54
55#include <net/ip.h>
56#include <net/sock.h>
57
58#include <net/ipv6.h>
59#include <net/ip6_checksum.h>
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000060#include <net/ping.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070061#include <net/protocol.h>
62#include <net/raw.h>
63#include <net/rawv6.h>
64#include <net/transp_v6.h>
65#include <net/ip6_route.h>
66#include <net/addrconf.h>
67#include <net/icmp.h>
Herbert Xu8b7817f2007-12-12 10:44:43 -080068#include <net/xfrm.h>
Denis V. Lunev1ed85162008-04-03 14:31:03 -070069#include <net/inet_common.h>
Hannes Frederic Sowa825edac2014-01-11 11:55:46 +010070#include <net/dsfield.h>
David Ahernca254492015-10-12 11:47:10 -070071#include <net/l3mdev.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070072
73#include <asm/uaccess.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070074
Linus Torvalds1da177e2005-04-16 15:20:36 -070075/*
76 * The ICMP socket(s). This is the most convenient way to flow control
77 * our ICMP output as well as maintain a clean interface throughout
78 * all layers. All Socketless IP sends will soon be gone.
79 *
80 * On SMP we have one ICMP socket per-cpu.
81 */
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -080082static inline struct sock *icmpv6_sk(struct net *net)
83{
84 return net->ipv6.icmp_sk[smp_processor_id()];
85}
Linus Torvalds1da177e2005-04-16 15:20:36 -070086
Steffen Klassert6f809da2013-01-16 22:09:49 +000087static void icmpv6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
88 u8 type, u8 code, int offset, __be32 info)
89{
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000090 /* icmpv6_notify checks 8 bytes can be pulled, icmp6hdr is 8 bytes */
91 struct icmp6hdr *icmp6 = (struct icmp6hdr *) (skb->data + offset);
Steffen Klassert6f809da2013-01-16 22:09:49 +000092 struct net *net = dev_net(skb->dev);
93
94 if (type == ICMPV6_PKT_TOOBIG)
Lorenzo Colitti50442922016-11-04 02:23:43 +090095 ip6_update_pmtu(skb, net, info, 0, 0, sock_net_uid(net, NULL));
Steffen Klassert6f809da2013-01-16 22:09:49 +000096 else if (type == NDISC_REDIRECT)
Lorenzo Colitti50442922016-11-04 02:23:43 +090097 ip6_redirect(skb, net, skb->dev->ifindex, 0,
98 sock_net_uid(net, NULL));
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000099
100 if (!(type & ICMPV6_INFOMSG_MASK))
101 if (icmp6->icmp6_type == ICMPV6_ECHO_REQUEST)
Hannes Frederic Sowadcb94b82016-06-11 20:32:06 +0200102 ping_err(skb, offset, ntohl(info));
Steffen Klassert6f809da2013-01-16 22:09:49 +0000103}
104
Herbert Xue5bbef22007-10-15 12:50:28 -0700105static int icmpv6_rcv(struct sk_buff *skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700106
Alexey Dobriyan41135cc2009-09-14 12:22:28 +0000107static const struct inet6_protocol icmpv6_protocol = {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700108 .handler = icmpv6_rcv,
Steffen Klassert6f809da2013-01-16 22:09:49 +0000109 .err_handler = icmpv6_err,
Herbert Xu8b7817f2007-12-12 10:44:43 -0800110 .flags = INET6_PROTO_NOPOLICY|INET6_PROTO_FINAL,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700111};
112
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700113static __inline__ struct sock *icmpv6_xmit_lock(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700114{
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700115 struct sock *sk;
116
Linus Torvalds1da177e2005-04-16 15:20:36 -0700117 local_bh_disable();
118
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700119 sk = icmpv6_sk(net);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800120 if (unlikely(!spin_trylock(&sk->sk_lock.slock))) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700121 /* This can happen if the output path (f.e. SIT or
122 * ip6ip6 tunnel) signals dst_link_failure() for an
123 * outgoing ICMP6 packet.
124 */
125 local_bh_enable();
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700126 return NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700127 }
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700128 return sk;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700129}
130
Denis V. Lunev405666d2008-02-29 11:16:46 -0800131static __inline__ void icmpv6_xmit_unlock(struct sock *sk)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700132{
Denis V. Lunev405666d2008-02-29 11:16:46 -0800133 spin_unlock_bh(&sk->sk_lock.slock);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700134}
135
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900136/*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700137 * Figure out, may we reply to this packet with icmp error.
138 *
139 * We do not reply, if:
140 * - it was icmp error message.
141 * - it is truncated, so that it is known, that protocol is ICMPV6
142 * (i.e. in the middle of some exthdr)
143 *
144 * --ANK (980726)
145 */
146
Eric Dumazeta50feda2012-05-18 18:57:34 +0000147static bool is_ineligible(const struct sk_buff *skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700148{
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700149 int ptr = (u8 *)(ipv6_hdr(skb) + 1) - skb->data;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700150 int len = skb->len - ptr;
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700151 __u8 nexthdr = ipv6_hdr(skb)->nexthdr;
Jesse Gross75f28112011-11-30 17:05:51 -0800152 __be16 frag_off;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700153
154 if (len < 0)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000155 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700156
Jesse Gross75f28112011-11-30 17:05:51 -0800157 ptr = ipv6_skip_exthdr(skb, ptr, &nexthdr, &frag_off);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700158 if (ptr < 0)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000159 return false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700160 if (nexthdr == IPPROTO_ICMPV6) {
161 u8 _type, *tp;
162 tp = skb_header_pointer(skb,
163 ptr+offsetof(struct icmp6hdr, icmp6_type),
164 sizeof(_type), &_type);
Ian Morris63159f22015-03-29 14:00:04 +0100165 if (!tp || !(*tp & ICMPV6_INFOMSG_MASK))
Eric Dumazeta50feda2012-05-18 18:57:34 +0000166 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700167 }
Eric Dumazeta50feda2012-05-18 18:57:34 +0000168 return false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700169}
170
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900171/*
172 * Check the ICMP output rate limit
Linus Torvalds1da177e2005-04-16 15:20:36 -0700173 */
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700174static bool icmpv6_xrlim_allow(struct sock *sk, u8 type,
175 struct flowi6 *fl6)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700176{
YOSHIFUJI Hideaki3b1e0a62008-03-26 02:26:21 +0900177 struct net *net = sock_net(sk);
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700178 struct dst_entry *dst;
David S. Miller92d86822011-02-04 15:55:25 -0800179 bool res = false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700180
181 /* Informational messages are not limited. */
182 if (type & ICMPV6_INFOMSG_MASK)
David S. Miller92d86822011-02-04 15:55:25 -0800183 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700184
185 /* Do not limit pmtu discovery, it would break it. */
186 if (type == ICMPV6_PKT_TOOBIG)
David S. Miller92d86822011-02-04 15:55:25 -0800187 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700188
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900189 /*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700190 * Look up the output route.
191 * XXX: perhaps the expire for routing entries cloned by
192 * this lookup should be more aggressive (not longer than timeout).
193 */
David S. Miller4c9483b2011-03-12 16:22:43 -0500194 dst = ip6_route_output(net, sk, fl6);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700195 if (dst->error) {
Denis V. Lunev3bd653c2008-10-08 10:54:51 -0700196 IP6_INC_STATS(net, ip6_dst_idev(dst),
YOSHIFUJI Hideakia11d2062006-11-04 20:11:37 +0900197 IPSTATS_MIB_OUTNOROUTES);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700198 } else if (dst->dev && (dst->dev->flags&IFF_LOOPBACK)) {
David S. Miller92d86822011-02-04 15:55:25 -0800199 res = true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700200 } else {
201 struct rt6_info *rt = (struct rt6_info *)dst;
Benjamin Thery9a43b702008-03-05 10:49:18 -0800202 int tmo = net->ipv6.sysctl.icmpv6_time;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700203
204 /* Give more bandwidth to wider prefixes. */
205 if (rt->rt6i_dst.plen < 128)
206 tmo >>= ((128 - rt->rt6i_dst.plen)>>5);
207
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700208 if (icmp_global_allow()) {
209 struct inet_peer *peer;
210
211 peer = inet_getpeer_v6(net->ipv6.peers,
Martin KaFai Laufd0273d2015-05-22 20:55:57 -0700212 &fl6->daddr, 1);
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700213 res = inet_peer_xrlim_allow(peer, tmo);
214 if (peer)
215 inet_putpeer(peer);
216 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700217 }
218 dst_release(dst);
219 return res;
220}
221
222/*
223 * an inline helper for the "simple" if statement below
224 * checks if parameter problem report is caused by an
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900225 * unrecognized IPv6 option that has the Option Type
Linus Torvalds1da177e2005-04-16 15:20:36 -0700226 * highest-order two bits set to 10
227 */
228
Eric Dumazeta50feda2012-05-18 18:57:34 +0000229static bool opt_unrec(struct sk_buff *skb, __u32 offset)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700230{
231 u8 _optval, *op;
232
Arnaldo Carvalho de Melobbe735e2007-03-10 22:16:10 -0300233 offset += skb_network_offset(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700234 op = skb_header_pointer(skb, offset, sizeof(_optval), &_optval);
Ian Morris63159f22015-03-29 14:00:04 +0100235 if (!op)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000236 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700237 return (*op & 0xC0) == 0x80;
238}
239
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +0000240int icmpv6_push_pending_frames(struct sock *sk, struct flowi6 *fl6,
241 struct icmp6hdr *thdr, int len)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700242{
243 struct sk_buff *skb;
244 struct icmp6hdr *icmp6h;
245 int err = 0;
246
Ian Morrise5d08d72014-11-23 21:28:43 +0000247 skb = skb_peek(&sk->sk_write_queue);
Ian Morris63159f22015-03-29 14:00:04 +0100248 if (!skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700249 goto out;
250
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300251 icmp6h = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700252 memcpy(icmp6h, thdr, sizeof(struct icmp6hdr));
253 icmp6h->icmp6_cksum = 0;
254
255 if (skb_queue_len(&sk->sk_write_queue) == 1) {
Joe Perches07f07572008-11-19 15:44:53 -0800256 skb->csum = csum_partial(icmp6h,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700257 sizeof(struct icmp6hdr), skb->csum);
David S. Miller4c9483b2011-03-12 16:22:43 -0500258 icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
259 &fl6->daddr,
260 len, fl6->flowi6_proto,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700261 skb->csum);
262 } else {
Al Viro868c86b2006-11-14 21:35:48 -0800263 __wsum tmp_csum = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700264
265 skb_queue_walk(&sk->sk_write_queue, skb) {
266 tmp_csum = csum_add(tmp_csum, skb->csum);
267 }
268
Joe Perches07f07572008-11-19 15:44:53 -0800269 tmp_csum = csum_partial(icmp6h,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700270 sizeof(struct icmp6hdr), tmp_csum);
David S. Miller4c9483b2011-03-12 16:22:43 -0500271 icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
272 &fl6->daddr,
273 len, fl6->flowi6_proto,
Al Viro868c86b2006-11-14 21:35:48 -0800274 tmp_csum);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700275 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700276 ip6_push_pending_frames(sk);
277out:
278 return err;
279}
280
281struct icmpv6_msg {
282 struct sk_buff *skb;
283 int offset;
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800284 uint8_t type;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700285};
286
287static int icmpv6_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
288{
289 struct icmpv6_msg *msg = (struct icmpv6_msg *) from;
290 struct sk_buff *org_skb = msg->skb;
Al Viro5f92a732006-11-14 21:36:54 -0800291 __wsum csum = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700292
293 csum = skb_copy_and_csum_bits(org_skb, msg->offset + offset,
294 to, len, csum);
295 skb->csum = csum_block_add(skb->csum, csum, odd);
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800296 if (!(msg->type & ICMPV6_INFOMSG_MASK))
297 nf_ct_attach(skb, org_skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700298 return 0;
299}
300
Amerigo Wang07a93622012-10-29 16:23:10 +0000301#if IS_ENABLED(CONFIG_IPV6_MIP6)
Jason A. Donenfeld0c5bdc22021-02-23 14:18:58 +0100302static void mip6_addr_swap(struct sk_buff *skb, const struct inet6_skb_parm *opt)
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700303{
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700304 struct ipv6hdr *iph = ipv6_hdr(skb);
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700305 struct ipv6_destopt_hao *hao;
306 struct in6_addr tmp;
307 int off;
308
309 if (opt->dsthao) {
310 off = ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO);
311 if (likely(off >= 0)) {
Arnaldo Carvalho de Melod56f90a2007-04-10 20:50:43 -0700312 hao = (struct ipv6_destopt_hao *)
313 (skb_network_header(skb) + off);
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000314 tmp = iph->saddr;
315 iph->saddr = hao->addr;
316 hao->addr = tmp;
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700317 }
318 }
319}
320#else
Jason A. Donenfeld0c5bdc22021-02-23 14:18:58 +0100321static inline void mip6_addr_swap(struct sk_buff *skb, const struct inet6_skb_parm *opt) {}
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700322#endif
323
stephen hemmingere8243532013-12-29 14:03:31 -0800324static struct dst_entry *icmpv6_route_lookup(struct net *net,
325 struct sk_buff *skb,
326 struct sock *sk,
327 struct flowi6 *fl6)
David S. Millerb42835d2011-03-01 22:06:22 -0800328{
329 struct dst_entry *dst, *dst2;
David S. Miller4c9483b2011-03-12 16:22:43 -0500330 struct flowi6 fl2;
David S. Millerb42835d2011-03-01 22:06:22 -0800331 int err;
332
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700333 err = ip6_dst_lookup(net, sk, &dst, fl6);
David S. Millerb42835d2011-03-01 22:06:22 -0800334 if (err)
335 return ERR_PTR(err);
336
337 /*
338 * We won't send icmp if the destination is known
339 * anycast.
340 */
Martin KaFai Lau2647a9b2015-05-22 20:55:58 -0700341 if (ipv6_anycast_destination(dst, &fl6->daddr)) {
Joe Perchesba7a46f2014-11-11 10:59:17 -0800342 net_dbg_ratelimited("icmp6_send: acast source\n");
David S. Millerb42835d2011-03-01 22:06:22 -0800343 dst_release(dst);
344 return ERR_PTR(-EINVAL);
345 }
346
347 /* No need to clone since we're just using its address. */
348 dst2 = dst;
349
David S. Miller4c9483b2011-03-12 16:22:43 -0500350 dst = xfrm_lookup(net, dst, flowi6_to_flowi(fl6), sk, 0);
David S. Miller452edd52011-03-02 13:27:41 -0800351 if (!IS_ERR(dst)) {
David S. Millerb42835d2011-03-01 22:06:22 -0800352 if (dst != dst2)
353 return dst;
David S. Miller452edd52011-03-02 13:27:41 -0800354 } else {
355 if (PTR_ERR(dst) == -EPERM)
356 dst = NULL;
357 else
358 return dst;
David S. Millerb42835d2011-03-01 22:06:22 -0800359 }
360
David S. Miller4c9483b2011-03-12 16:22:43 -0500361 err = xfrm_decode_session_reverse(skb, flowi6_to_flowi(&fl2), AF_INET6);
David S. Millerb42835d2011-03-01 22:06:22 -0800362 if (err)
363 goto relookup_failed;
364
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700365 err = ip6_dst_lookup(net, sk, &dst2, &fl2);
David S. Millerb42835d2011-03-01 22:06:22 -0800366 if (err)
367 goto relookup_failed;
368
David S. Miller4c9483b2011-03-12 16:22:43 -0500369 dst2 = xfrm_lookup(net, dst2, flowi6_to_flowi(&fl2), sk, XFRM_LOOKUP_ICMP);
David S. Miller452edd52011-03-02 13:27:41 -0800370 if (!IS_ERR(dst2)) {
David S. Millerb42835d2011-03-01 22:06:22 -0800371 dst_release(dst);
372 dst = dst2;
David S. Miller452edd52011-03-02 13:27:41 -0800373 } else {
374 err = PTR_ERR(dst2);
375 if (err == -EPERM) {
376 dst_release(dst);
377 return dst2;
378 } else
379 goto relookup_failed;
David S. Millerb42835d2011-03-01 22:06:22 -0800380 }
381
382relookup_failed:
383 if (dst)
384 return dst;
385 return ERR_PTR(err);
386}
387
Linus Torvalds1da177e2005-04-16 15:20:36 -0700388/*
389 * Send an ICMP message in response to a packet in error
390 */
Eric Dumazet8b572a52020-06-19 12:02:59 -0700391void icmp6_send(struct sk_buff *skb, u8 type, u8 code, __u32 info,
Jason A. Donenfeld0c5bdc22021-02-23 14:18:58 +0100392 const struct in6_addr *force_saddr,
393 const struct inet6_skb_parm *parm)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700394{
YOSHIFUJI Hideakic346dca2008-03-25 21:47:49 +0900395 struct net *net = dev_net(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700396 struct inet6_dev *idev = NULL;
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700397 struct ipv6hdr *hdr = ipv6_hdr(skb);
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700398 struct sock *sk;
399 struct ipv6_pinfo *np;
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000400 const struct in6_addr *saddr = NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700401 struct dst_entry *dst;
402 struct icmp6hdr tmp_hdr;
David S. Miller4c9483b2011-03-12 16:22:43 -0500403 struct flowi6 fl6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700404 struct icmpv6_msg msg;
Soheil Hassas Yeganehc14ac942016-04-02 23:08:12 -0400405 struct sockcm_cookie sockc_unused = {0};
Wei Wang26879da2016-05-02 21:40:07 -0700406 struct ipcm6_cookie ipc6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700407 int iif = 0;
408 int addr_type = 0;
409 int len;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700410 int err = 0;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700411 u32 mark = IP6_REPLY_MARK(net, skb->mark);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700412
Arnaldo Carvalho de Melo27a884d2007-04-19 20:29:13 -0700413 if ((u8 *)hdr < skb->head ||
Simon Horman29a3cad2013-05-28 20:34:26 +0000414 (skb_network_header(skb) + sizeof(*hdr)) > skb_tail_pointer(skb))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700415 return;
416
417 /*
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900418 * Make sure we respect the rules
Linus Torvalds1da177e2005-04-16 15:20:36 -0700419 * i.e. RFC 1885 2.4(e)
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000420 * Rule (e.1) is enforced by not using icmp6_send
Linus Torvalds1da177e2005-04-16 15:20:36 -0700421 * in any code that processes icmp errors.
422 */
423 addr_type = ipv6_addr_type(&hdr->daddr);
424
FX Le Bail446fab52014-01-19 17:00:36 +0100425 if (ipv6_chk_addr(net, &hdr->daddr, skb->dev, 0) ||
FX Le Baild94c1f92014-02-07 11:22:37 +0100426 ipv6_chk_acast_addr_src(net, skb->dev, &hdr->daddr))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700427 saddr = &hdr->daddr;
428
429 /*
430 * Dest addr check
431 */
432
zhuyj9a6b4b32015-01-14 17:23:59 +0800433 if (addr_type & IPV6_ADDR_MULTICAST || skb->pkt_type != PACKET_HOST) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700434 if (type != ICMPV6_PKT_TOOBIG &&
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900435 !(type == ICMPV6_PARAMPROB &&
436 code == ICMPV6_UNK_OPTION &&
Linus Torvalds1da177e2005-04-16 15:20:36 -0700437 (opt_unrec(skb, info))))
438 return;
439
440 saddr = NULL;
441 }
442
443 addr_type = ipv6_addr_type(&hdr->saddr);
444
445 /*
446 * Source addr check
447 */
448
Hannes Frederic Sowa842df072013-03-08 02:07:19 +0000449 if (__ipv6_addr_needs_scope_id(addr_type))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700450 iif = skb->dev->ifindex;
David Ahern79dc7e32016-11-27 18:52:53 -0800451 else {
452 dst = skb_dst(skb);
453 iif = l3mdev_master_ifindex(dst ? dst->dev : skb->dev);
454 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700455
456 /*
YOSHIFUJI Hideaki8de33512005-12-21 22:57:06 +0900457 * Must not send error if the source does not uniquely
458 * identify a single node (RFC2463 Section 2.4).
459 * We check unspecified / multicast addresses here,
460 * and anycast addresses will be checked later.
Linus Torvalds1da177e2005-04-16 15:20:36 -0700461 */
462 if ((addr_type == IPV6_ADDR_ANY) || (addr_type & IPV6_ADDR_MULTICAST)) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200463 net_dbg_ratelimited("icmp6_send: addr_any/mcast source [%pI6c > %pI6c]\n",
464 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700465 return;
466 }
467
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900468 /*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700469 * Never answer to a ICMP packet.
470 */
471 if (is_ineligible(skb)) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200472 net_dbg_ratelimited("icmp6_send: no reply to icmp error [%pI6c > %pI6c]\n",
473 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700474 return;
475 }
476
Jason A. Donenfeld0c5bdc22021-02-23 14:18:58 +0100477 mip6_addr_swap(skb, parm);
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700478
David S. Miller4c9483b2011-03-12 16:22:43 -0500479 memset(&fl6, 0, sizeof(fl6));
480 fl6.flowi6_proto = IPPROTO_ICMPV6;
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000481 fl6.daddr = hdr->saddr;
Eric Dumazetb1cadc12016-06-18 21:52:02 -0700482 if (force_saddr)
483 saddr = force_saddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700484 if (saddr)
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000485 fl6.saddr = *saddr;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700486 fl6.flowi6_mark = mark;
David S. Miller4c9483b2011-03-12 16:22:43 -0500487 fl6.flowi6_oif = iif;
David S. Miller1958b852011-03-12 16:36:19 -0500488 fl6.fl6_icmp_type = type;
489 fl6.fl6_icmp_code = code;
Lorenzo Colitti50442922016-11-04 02:23:43 +0900490 fl6.flowi6_uid = sock_net_uid(net, NULL);
David S. Miller4c9483b2011-03-12 16:22:43 -0500491 security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700492
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700493 sk = icmpv6_xmit_lock(net);
Ian Morris63159f22015-03-29 14:00:04 +0100494 if (!sk)
Denis V. Lunev405666d2008-02-29 11:16:46 -0800495 return;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700496 sk->sk_mark = mark;
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700497 np = inet6_sk(sk);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800498
David S. Miller4c9483b2011-03-12 16:22:43 -0500499 if (!icmpv6_xrlim_allow(sk, type, &fl6))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700500 goto out;
501
502 tmp_hdr.icmp6_type = type;
503 tmp_hdr.icmp6_code = code;
504 tmp_hdr.icmp6_cksum = 0;
505 tmp_hdr.icmp6_pointer = htonl(info);
506
David S. Miller4c9483b2011-03-12 16:22:43 -0500507 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
508 fl6.flowi6_oif = np->mcast_oif;
Erich E. Hooverc4062df2012-02-08 09:11:08 +0000509 else if (!fl6.flowi6_oif)
510 fl6.flowi6_oif = np->ucast_oif;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700511
Hannes Frederic Sowa38b70972016-06-11 20:08:19 +0200512 ipc6.tclass = np->tclass;
513 fl6.flowlabel = ip6_make_flowinfo(ipc6.tclass, fl6.flowlabel);
514
David S. Miller4c9483b2011-03-12 16:22:43 -0500515 dst = icmpv6_route_lookup(net, skb, sk, &fl6);
David S. Millerb42835d2011-03-01 22:06:22 -0800516 if (IS_ERR(dst))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700517 goto out;
YOSHIFUJI Hideaki8de33512005-12-21 22:57:06 +0900518
Wei Wang26879da2016-05-02 21:40:07 -0700519 ipc6.hlimit = ip6_sk_dst_hoplimit(np, &fl6, dst);
Wei Wang26879da2016-05-02 21:40:07 -0700520 ipc6.dontfrag = np->dontfrag;
521 ipc6.opt = NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700522
523 msg.skb = skb;
Arnaldo Carvalho de Melobbe735e2007-03-10 22:16:10 -0300524 msg.offset = skb_network_offset(skb);
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800525 msg.type = type;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700526
527 len = skb->len - msg.offset;
Ian Morris67ba4152014-08-24 21:53:10 +0100528 len = min_t(unsigned int, len, IPV6_MIN_MTU - sizeof(struct ipv6hdr) - sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700529 if (len < 0) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200530 net_dbg_ratelimited("icmp: len problem [%pI6c > %pI6c]\n",
531 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700532 goto out_dst_release;
533 }
534
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000535 rcu_read_lock();
536 idev = __in6_dev_get(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700537
538 err = ip6_append_data(sk, icmpv6_getfrag, &msg,
539 len + sizeof(struct icmp6hdr),
Wei Wang26879da2016-05-02 21:40:07 -0700540 sizeof(struct icmp6hdr),
541 &ipc6, &fl6, (struct rt6_info *)dst,
542 MSG_DONTWAIT, &sockc_unused);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700543 if (err) {
Hannes Frederic Sowa43a43b62014-03-31 20:14:10 +0200544 ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700545 ip6_flush_pending_frames(sk);
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000546 } else {
547 err = icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
548 len + sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700549 }
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000550 rcu_read_unlock();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700551out_dst_release:
552 dst_release(dst);
553out:
Denis V. Lunev405666d2008-02-29 11:16:46 -0800554 icmpv6_xmit_unlock(sk);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700555}
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000556
557/* Slightly more convenient version of icmp6_send.
558 */
559void icmpv6_param_prob(struct sk_buff *skb, u8 code, int pos)
560{
Jason A. Donenfeld0c5bdc22021-02-23 14:18:58 +0100561 icmp6_send(skb, ICMPV6_PARAMPROB, code, pos, NULL, IP6CB(skb));
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000562 kfree_skb(skb);
563}
Eric Dumazet8b572a52020-06-19 12:02:59 -0700564EXPORT_SYMBOL(icmp6_send);
YOSHIFUJI Hideaki71590392007-02-22 22:05:40 +0900565
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700566/* Generate icmpv6 with type/code ICMPV6_DEST_UNREACH/ICMPV6_ADDR_UNREACH
567 * if sufficient data bytes are available
568 * @nhs is the size of the tunnel header(s) :
569 * Either an IPv4 header for SIT encap
570 * an IPv4 header + GRE header for GRE encap
571 */
Eric Dumazet20e19542016-06-18 21:52:06 -0700572int ip6_err_gen_icmpv6_unreach(struct sk_buff *skb, int nhs, int type,
573 unsigned int data_len)
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700574{
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700575 struct in6_addr temp_saddr;
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700576 struct rt6_info *rt;
577 struct sk_buff *skb2;
Eric Dumazet20e19542016-06-18 21:52:06 -0700578 u32 info = 0;
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700579
580 if (!pskb_may_pull(skb, nhs + sizeof(struct ipv6hdr) + 8))
581 return 1;
582
Eric Dumazet20e19542016-06-18 21:52:06 -0700583 /* RFC 4884 (partial) support for ICMP extensions */
584 if (data_len < 128 || (data_len & 7) || skb->len < data_len)
585 data_len = 0;
586
587 skb2 = data_len ? skb_copy(skb, GFP_ATOMIC) : skb_clone(skb, GFP_ATOMIC);
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700588
589 if (!skb2)
590 return 1;
591
592 skb_dst_drop(skb2);
593 skb_pull(skb2, nhs);
594 skb_reset_network_header(skb2);
595
596 rt = rt6_lookup(dev_net(skb->dev), &ipv6_hdr(skb2)->saddr, NULL, 0, 0);
597
598 if (rt && rt->dst.dev)
599 skb2->dev = rt->dst.dev;
600
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700601 ipv6_addr_set_v4mapped(ip_hdr(skb)->saddr, &temp_saddr);
Eric Dumazet20e19542016-06-18 21:52:06 -0700602
603 if (data_len) {
604 /* RFC 4884 (partial) support :
605 * insert 0 padding at the end, before the extensions
606 */
607 __skb_push(skb2, nhs);
608 skb_reset_network_header(skb2);
609 memmove(skb2->data, skb2->data + nhs, data_len - nhs);
610 memset(skb2->data + data_len - nhs, 0, nhs);
611 /* RFC 4884 4.5 : Length is measured in 64-bit words,
612 * and stored in reserved[0]
613 */
614 info = (data_len/8) << 24;
615 }
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700616 if (type == ICMP_TIME_EXCEEDED)
617 icmp6_send(skb2, ICMPV6_TIME_EXCEED, ICMPV6_EXC_HOPLIMIT,
Jason A. Donenfeld0c5bdc22021-02-23 14:18:58 +0100618 info, &temp_saddr, IP6CB(skb2));
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700619 else
620 icmp6_send(skb2, ICMPV6_DEST_UNREACH, ICMPV6_ADDR_UNREACH,
Jason A. Donenfeld0c5bdc22021-02-23 14:18:58 +0100621 info, &temp_saddr, IP6CB(skb2));
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700622 if (rt)
623 ip6_rt_put(rt);
624
625 kfree_skb(skb2);
626
627 return 0;
628}
629EXPORT_SYMBOL(ip6_err_gen_icmpv6_unreach);
630
Linus Torvalds1da177e2005-04-16 15:20:36 -0700631static void icmpv6_echo_reply(struct sk_buff *skb)
632{
YOSHIFUJI Hideakic346dca2008-03-25 21:47:49 +0900633 struct net *net = dev_net(skb->dev);
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700634 struct sock *sk;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700635 struct inet6_dev *idev;
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700636 struct ipv6_pinfo *np;
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000637 const struct in6_addr *saddr = NULL;
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300638 struct icmp6hdr *icmph = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700639 struct icmp6hdr tmp_hdr;
David S. Miller4c9483b2011-03-12 16:22:43 -0500640 struct flowi6 fl6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700641 struct icmpv6_msg msg;
642 struct dst_entry *dst;
Wei Wang26879da2016-05-02 21:40:07 -0700643 struct ipcm6_cookie ipc6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700644 int err = 0;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700645 u32 mark = IP6_REPLY_MARK(net, skb->mark);
Soheil Hassas Yeganehc14ac942016-04-02 23:08:12 -0400646 struct sockcm_cookie sockc_unused = {0};
Linus Torvalds1da177e2005-04-16 15:20:36 -0700647
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700648 saddr = &ipv6_hdr(skb)->daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700649
FX Le Bail509aba32014-01-07 14:57:27 +0100650 if (!ipv6_unicast_destination(skb) &&
FX Le Bailec35b612014-01-13 15:59:01 +0100651 !(net->ipv6.sysctl.anycast_src_echo_reply &&
Martin KaFai Lau2647a9b2015-05-22 20:55:58 -0700652 ipv6_anycast_destination(skb_dst(skb), saddr)))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700653 saddr = NULL;
654
655 memcpy(&tmp_hdr, icmph, sizeof(tmp_hdr));
656 tmp_hdr.icmp6_type = ICMPV6_ECHO_REPLY;
657
David S. Miller4c9483b2011-03-12 16:22:43 -0500658 memset(&fl6, 0, sizeof(fl6));
659 fl6.flowi6_proto = IPPROTO_ICMPV6;
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000660 fl6.daddr = ipv6_hdr(skb)->saddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700661 if (saddr)
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000662 fl6.saddr = *saddr;
David Ahern9ff74382016-06-13 13:44:19 -0700663 fl6.flowi6_oif = skb->dev->ifindex;
David S. Miller1958b852011-03-12 16:36:19 -0500664 fl6.fl6_icmp_type = ICMPV6_ECHO_REPLY;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700665 fl6.flowi6_mark = mark;
Lorenzo Colitti50442922016-11-04 02:23:43 +0900666 fl6.flowi6_uid = sock_net_uid(net, NULL);
David S. Miller4c9483b2011-03-12 16:22:43 -0500667 security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700668
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700669 sk = icmpv6_xmit_lock(net);
Ian Morris63159f22015-03-29 14:00:04 +0100670 if (!sk)
Denis V. Lunev405666d2008-02-29 11:16:46 -0800671 return;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700672 sk->sk_mark = mark;
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700673 np = inet6_sk(sk);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800674
David S. Miller4c9483b2011-03-12 16:22:43 -0500675 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
676 fl6.flowi6_oif = np->mcast_oif;
Erich E. Hooverc4062df2012-02-08 09:11:08 +0000677 else if (!fl6.flowi6_oif)
678 fl6.flowi6_oif = np->ucast_oif;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700679
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700680 err = ip6_dst_lookup(net, sk, &dst, &fl6);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700681 if (err)
682 goto out;
David S. Miller4c9483b2011-03-12 16:22:43 -0500683 dst = xfrm_lookup(net, dst, flowi6_to_flowi(&fl6), sk, 0);
David S. Miller452edd52011-03-02 13:27:41 -0800684 if (IS_ERR(dst))
Patrick McHardye104411b2005-09-08 15:11:55 -0700685 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700686
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000687 idev = __in6_dev_get(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700688
689 msg.skb = skb;
690 msg.offset = 0;
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800691 msg.type = ICMPV6_ECHO_REPLY;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700692
Wei Wang26879da2016-05-02 21:40:07 -0700693 ipc6.hlimit = ip6_sk_dst_hoplimit(np, &fl6, dst);
694 ipc6.tclass = ipv6_get_dsfield(ipv6_hdr(skb));
695 ipc6.dontfrag = np->dontfrag;
696 ipc6.opt = NULL;
697
Linus Torvalds1da177e2005-04-16 15:20:36 -0700698 err = ip6_append_data(sk, icmpv6_getfrag, &msg, skb->len + sizeof(struct icmp6hdr),
Wei Wang26879da2016-05-02 21:40:07 -0700699 sizeof(struct icmp6hdr), &ipc6, &fl6,
Eldad Zacka2d91a02012-04-01 07:49:07 +0000700 (struct rt6_info *)dst, MSG_DONTWAIT,
Wei Wang26879da2016-05-02 21:40:07 -0700701 &sockc_unused);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700702
703 if (err) {
Eric Dumazeta16292a2016-04-27 16:44:36 -0700704 __ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700705 ip6_flush_pending_frames(sk);
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000706 } else {
707 err = icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
708 skb->len + sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700709 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700710 dst_release(dst);
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900711out:
Denis V. Lunev405666d2008-02-29 11:16:46 -0800712 icmpv6_xmit_unlock(sk);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700713}
714
David S. Millerb94f1c02012-07-12 00:33:37 -0700715void icmpv6_notify(struct sk_buff *skb, u8 type, u8 code, __be32 info)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700716{
Alexey Dobriyan41135cc2009-09-14 12:22:28 +0000717 const struct inet6_protocol *ipprot;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700718 int inner_offset;
Jesse Gross75f28112011-11-30 17:05:51 -0800719 __be16 frag_off;
David S. Millerf9242b62012-06-19 18:56:21 -0700720 u8 nexthdr;
Duan Jiong7304fe42014-07-31 17:54:32 +0800721 struct net *net = dev_net(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700722
723 if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
Duan Jiong7304fe42014-07-31 17:54:32 +0800724 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700725
726 nexthdr = ((struct ipv6hdr *)skb->data)->nexthdr;
727 if (ipv6_ext_hdr(nexthdr)) {
728 /* now skip over extension headers */
Jesse Gross75f28112011-11-30 17:05:51 -0800729 inner_offset = ipv6_skip_exthdr(skb, sizeof(struct ipv6hdr),
730 &nexthdr, &frag_off);
Ian Morris67ba4152014-08-24 21:53:10 +0100731 if (inner_offset < 0)
Duan Jiong7304fe42014-07-31 17:54:32 +0800732 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700733 } else {
734 inner_offset = sizeof(struct ipv6hdr);
735 }
736
737 /* Checkin header including 8 bytes of inner protocol header. */
738 if (!pskb_may_pull(skb, inner_offset+8))
Duan Jiong7304fe42014-07-31 17:54:32 +0800739 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700740
Linus Torvalds1da177e2005-04-16 15:20:36 -0700741 /* BUGGG_FUTURE: we should try to parse exthdrs in this packet.
742 Without this we will not able f.e. to make source routed
743 pmtu discovery.
744 Corresponding argument (opt) to notifiers is already added.
745 --ANK (980726)
746 */
747
David S. Millerf9242b62012-06-19 18:56:21 -0700748 ipprot = rcu_dereference(inet6_protos[nexthdr]);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700749 if (ipprot && ipprot->err_handler)
750 ipprot->err_handler(skb, NULL, type, code, inner_offset, info);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700751
Pavel Emelyanov69d6da02007-11-19 22:35:57 -0800752 raw6_icmp_error(skb, nexthdr, type, code, inner_offset, info);
Duan Jiong7304fe42014-07-31 17:54:32 +0800753 return;
754
755out:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700756 __ICMP6_INC_STATS(net, __in6_dev_get(skb->dev), ICMP6_MIB_INERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700757}
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900758
Linus Torvalds1da177e2005-04-16 15:20:36 -0700759/*
760 * Handle icmp messages
761 */
762
Herbert Xue5bbef22007-10-15 12:50:28 -0700763static int icmpv6_rcv(struct sk_buff *skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700764{
Linus Torvalds1da177e2005-04-16 15:20:36 -0700765 struct net_device *dev = skb->dev;
766 struct inet6_dev *idev = __in6_dev_get(dev);
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000767 const struct in6_addr *saddr, *daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700768 struct icmp6hdr *hdr;
Brian Haleyd5fdd6b2009-06-23 04:31:07 -0700769 u8 type;
Rick Jonese3e32172014-11-17 14:04:29 -0800770 bool success = false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700771
Herbert Xuaebcf822007-12-12 18:54:16 -0800772 if (!xfrm6_policy_check(NULL, XFRM_POLICY_IN, skb)) {
Alexey Dobriyandef8b4f2008-10-28 13:24:06 -0700773 struct sec_path *sp = skb_sec_path(skb);
Herbert Xu8b7817f2007-12-12 10:44:43 -0800774 int nh;
775
Alexey Dobriyandef8b4f2008-10-28 13:24:06 -0700776 if (!(sp && sp->xvec[sp->len - 1]->props.flags &
Herbert Xuaebcf822007-12-12 18:54:16 -0800777 XFRM_STATE_ICMP))
778 goto drop_no_count;
779
David S. Miller81aded22012-06-15 14:54:11 -0700780 if (!pskb_may_pull(skb, sizeof(*hdr) + sizeof(struct ipv6hdr)))
Herbert Xu8b7817f2007-12-12 10:44:43 -0800781 goto drop_no_count;
782
783 nh = skb_network_offset(skb);
784 skb_set_network_header(skb, sizeof(*hdr));
785
786 if (!xfrm6_policy_check_reverse(NULL, XFRM_POLICY_IN, skb))
787 goto drop_no_count;
788
789 skb_set_network_header(skb, nh);
790 }
791
Eric Dumazeta16292a2016-04-27 16:44:36 -0700792 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_INMSGS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700793
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700794 saddr = &ipv6_hdr(skb)->saddr;
795 daddr = &ipv6_hdr(skb)->daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700796
Tom Herbert39471ac2014-05-07 16:52:29 -0700797 if (skb_checksum_validate(skb, IPPROTO_ICMPV6, ip6_compute_pseudo)) {
Joe Perchesba7a46f2014-11-11 10:59:17 -0800798 net_dbg_ratelimited("ICMPv6 checksum failed [%pI6c > %pI6c]\n",
799 saddr, daddr);
Tom Herbert39471ac2014-05-07 16:52:29 -0700800 goto csum_error;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700801 }
802
Herbert Xu8cf22942008-02-05 03:15:50 -0800803 if (!pskb_pull(skb, sizeof(*hdr)))
804 goto discard_it;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700805
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300806 hdr = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700807
808 type = hdr->icmp6_type;
809
Eric Dumazetf3832ed2016-04-27 16:44:42 -0700810 ICMP6MSGIN_INC_STATS(dev_net(dev), idev, type);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700811
812 switch (type) {
813 case ICMPV6_ECHO_REQUEST:
814 icmpv6_echo_reply(skb);
815 break;
816
817 case ICMPV6_ECHO_REPLY:
Rick Jonese3e32172014-11-17 14:04:29 -0800818 success = ping_rcv(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700819 break;
820
821 case ICMPV6_PKT_TOOBIG:
822 /* BUGGG_FUTURE: if packet contains rthdr, we cannot update
823 standard destination cache. Seems, only "advanced"
824 destination cache will allow to solve this problem
825 --ANK (980726)
826 */
827 if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
828 goto discard_it;
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300829 hdr = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700830
831 /*
832 * Drop through to notify
833 */
834
835 case ICMPV6_DEST_UNREACH:
836 case ICMPV6_TIME_EXCEED:
837 case ICMPV6_PARAMPROB:
838 icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
839 break;
840
841 case NDISC_ROUTER_SOLICITATION:
842 case NDISC_ROUTER_ADVERTISEMENT:
843 case NDISC_NEIGHBOUR_SOLICITATION:
844 case NDISC_NEIGHBOUR_ADVERTISEMENT:
845 case NDISC_REDIRECT:
846 ndisc_rcv(skb);
847 break;
848
849 case ICMPV6_MGM_QUERY:
850 igmp6_event_query(skb);
851 break;
852
853 case ICMPV6_MGM_REPORT:
854 igmp6_event_report(skb);
855 break;
856
857 case ICMPV6_MGM_REDUCTION:
858 case ICMPV6_NI_QUERY:
859 case ICMPV6_NI_REPLY:
860 case ICMPV6_MLD2_REPORT:
861 case ICMPV6_DHAAD_REQUEST:
862 case ICMPV6_DHAAD_REPLY:
863 case ICMPV6_MOBILE_PREFIX_SOL:
864 case ICMPV6_MOBILE_PREFIX_ADV:
865 break;
866
867 default:
Linus Torvalds1da177e2005-04-16 15:20:36 -0700868 /* informational */
869 if (type & ICMPV6_INFOMSG_MASK)
870 break;
871
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200872 net_dbg_ratelimited("icmpv6: msg of unknown type [%pI6c > %pI6c]\n",
873 saddr, daddr);
David S. Millerea85a0a2014-10-07 16:33:53 -0400874
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900875 /*
876 * error of unknown type.
877 * must pass to upper level
Linus Torvalds1da177e2005-04-16 15:20:36 -0700878 */
879
880 icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
Stephen Hemminger3ff50b72007-04-20 17:09:22 -0700881 }
882
Rick Jonese3e32172014-11-17 14:04:29 -0800883 /* until the v6 path can be better sorted assume failure and
884 * preserve the status quo behaviour for the rest of the paths to here
885 */
886 if (success)
887 consume_skb(skb);
888 else
889 kfree_skb(skb);
890
Linus Torvalds1da177e2005-04-16 15:20:36 -0700891 return 0;
892
Eric Dumazet6a5dc9e2013-04-29 08:39:56 +0000893csum_error:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700894 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_CSUMERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700895discard_it:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700896 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_INERRORS);
Herbert Xu8b7817f2007-12-12 10:44:43 -0800897drop_no_count:
Linus Torvalds1da177e2005-04-16 15:20:36 -0700898 kfree_skb(skb);
899 return 0;
900}
901
David S. Miller4c9483b2011-03-12 16:22:43 -0500902void icmpv6_flow_init(struct sock *sk, struct flowi6 *fl6,
YOSHIFUJI Hideaki95e41e92007-12-06 15:43:30 -0800903 u8 type,
904 const struct in6_addr *saddr,
905 const struct in6_addr *daddr,
906 int oif)
907{
David S. Miller4c9483b2011-03-12 16:22:43 -0500908 memset(fl6, 0, sizeof(*fl6));
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000909 fl6->saddr = *saddr;
910 fl6->daddr = *daddr;
Ian Morris67ba4152014-08-24 21:53:10 +0100911 fl6->flowi6_proto = IPPROTO_ICMPV6;
David S. Miller1958b852011-03-12 16:36:19 -0500912 fl6->fl6_icmp_type = type;
913 fl6->fl6_icmp_code = 0;
David S. Miller4c9483b2011-03-12 16:22:43 -0500914 fl6->flowi6_oif = oif;
915 security_sk_classify_flow(sk, flowi6_to_flowi(fl6));
YOSHIFUJI Hideaki95e41e92007-12-06 15:43:30 -0800916}
917
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800918static int __net_init icmpv6_sk_init(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700919{
920 struct sock *sk;
921 int err, i, j;
922
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800923 net->ipv6.icmp_sk =
924 kzalloc(nr_cpu_ids * sizeof(struct sock *), GFP_KERNEL);
Ian Morris63159f22015-03-29 14:00:04 +0100925 if (!net->ipv6.icmp_sk)
Denis V. Lunev79c91152008-02-29 11:17:11 -0800926 return -ENOMEM;
927
KAMEZAWA Hiroyuki6f912042006-04-10 22:52:50 -0700928 for_each_possible_cpu(i) {
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700929 err = inet_ctl_sock_create(&sk, PF_INET6,
930 SOCK_RAW, IPPROTO_ICMPV6, net);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700931 if (err < 0) {
Joe Perchesf3213832012-05-15 14:11:53 +0000932 pr_err("Failed to initialize the ICMP6 control socket (err %d)\n",
Linus Torvalds1da177e2005-04-16 15:20:36 -0700933 err);
934 goto fail;
935 }
936
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700937 net->ipv6.icmp_sk[i] = sk;
Denis V. Lunev5c8cafd2008-02-29 11:19:22 -0800938
Linus Torvalds1da177e2005-04-16 15:20:36 -0700939 /* Enough space for 2 64K ICMP packets, including
940 * sk_buff struct overhead.
941 */
Eric Dumazet87fb4b72011-10-13 07:28:54 +0000942 sk->sk_sndbuf = 2 * SKB_TRUESIZE(64 * 1024);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700943 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700944 return 0;
945
946 fail:
Denis V. Lunev5c8cafd2008-02-29 11:19:22 -0800947 for (j = 0; j < i; j++)
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700948 inet_ctl_sock_destroy(net->ipv6.icmp_sk[j]);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800949 kfree(net->ipv6.icmp_sk);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700950 return err;
951}
952
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800953static void __net_exit icmpv6_sk_exit(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700954{
955 int i;
956
KAMEZAWA Hiroyuki6f912042006-04-10 22:52:50 -0700957 for_each_possible_cpu(i) {
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700958 inet_ctl_sock_destroy(net->ipv6.icmp_sk[i]);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700959 }
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800960 kfree(net->ipv6.icmp_sk);
961}
962
Alexey Dobriyan8ed7edc2008-03-03 12:02:54 -0800963static struct pernet_operations icmpv6_sk_ops = {
Ian Morris67ba4152014-08-24 21:53:10 +0100964 .init = icmpv6_sk_init,
965 .exit = icmpv6_sk_exit,
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800966};
967
968int __init icmpv6_init(void)
969{
970 int err;
971
972 err = register_pernet_subsys(&icmpv6_sk_ops);
973 if (err < 0)
974 return err;
975
976 err = -EAGAIN;
977 if (inet6_add_protocol(&icmpv6_protocol, IPPROTO_ICMPV6) < 0)
978 goto fail;
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000979
980 err = inet6_register_icmp_sender(icmp6_send);
981 if (err)
982 goto sender_reg_err;
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800983 return 0;
984
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000985sender_reg_err:
986 inet6_del_protocol(&icmpv6_protocol, IPPROTO_ICMPV6);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800987fail:
Joe Perchesf3213832012-05-15 14:11:53 +0000988 pr_err("Failed to register ICMP6 protocol\n");
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800989 unregister_pernet_subsys(&icmpv6_sk_ops);
990 return err;
991}
992
Alexey Dobriyan8ed7edc2008-03-03 12:02:54 -0800993void icmpv6_cleanup(void)
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800994{
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000995 inet6_unregister_icmp_sender(icmp6_send);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800996 unregister_pernet_subsys(&icmpv6_sk_ops);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700997 inet6_del_protocol(&icmpv6_protocol, IPPROTO_ICMPV6);
998}
999
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001000
Arjan van de Ven9b5b5cf2005-11-29 16:21:38 -08001001static const struct icmp6_err {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001002 int err;
1003 int fatal;
1004} tab_unreach[] = {
1005 { /* NOROUTE */
1006 .err = ENETUNREACH,
1007 .fatal = 0,
1008 },
1009 { /* ADM_PROHIBITED */
1010 .err = EACCES,
1011 .fatal = 1,
1012 },
1013 { /* Was NOT_NEIGHBOUR, now reserved */
1014 .err = EHOSTUNREACH,
1015 .fatal = 0,
1016 },
1017 { /* ADDR_UNREACH */
1018 .err = EHOSTUNREACH,
1019 .fatal = 0,
1020 },
1021 { /* PORT_UNREACH */
1022 .err = ECONNREFUSED,
1023 .fatal = 1,
1024 },
Jiri Bohac61e76b12013-08-30 11:18:45 +02001025 { /* POLICY_FAIL */
1026 .err = EACCES,
1027 .fatal = 1,
1028 },
1029 { /* REJECT_ROUTE */
1030 .err = EACCES,
1031 .fatal = 1,
1032 },
Linus Torvalds1da177e2005-04-16 15:20:36 -07001033};
1034
Brian Haleyd5fdd6b2009-06-23 04:31:07 -07001035int icmpv6_err_convert(u8 type, u8 code, int *err)
Linus Torvalds1da177e2005-04-16 15:20:36 -07001036{
1037 int fatal = 0;
1038
1039 *err = EPROTO;
1040
1041 switch (type) {
1042 case ICMPV6_DEST_UNREACH:
1043 fatal = 1;
Jiri Bohac61e76b12013-08-30 11:18:45 +02001044 if (code < ARRAY_SIZE(tab_unreach)) {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001045 *err = tab_unreach[code].err;
1046 fatal = tab_unreach[code].fatal;
1047 }
1048 break;
1049
1050 case ICMPV6_PKT_TOOBIG:
1051 *err = EMSGSIZE;
1052 break;
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +09001053
Linus Torvalds1da177e2005-04-16 15:20:36 -07001054 case ICMPV6_PARAMPROB:
1055 *err = EPROTO;
1056 fatal = 1;
1057 break;
1058
1059 case ICMPV6_TIME_EXCEED:
1060 *err = EHOSTUNREACH;
1061 break;
Stephen Hemminger3ff50b72007-04-20 17:09:22 -07001062 }
Linus Torvalds1da177e2005-04-16 15:20:36 -07001063
1064 return fatal;
1065}
YOSHIFUJI Hideaki71590392007-02-22 22:05:40 +09001066EXPORT_SYMBOL(icmpv6_err_convert);
1067
Linus Torvalds1da177e2005-04-16 15:20:36 -07001068#ifdef CONFIG_SYSCTL
stephen hemmingere8243532013-12-29 14:03:31 -08001069static struct ctl_table ipv6_icmp_table_template[] = {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001070 {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001071 .procname = "ratelimit",
Daniel Lezcano41a76902008-01-10 03:02:40 -08001072 .data = &init_net.ipv6.sysctl.icmpv6_time,
Linus Torvalds1da177e2005-04-16 15:20:36 -07001073 .maxlen = sizeof(int),
1074 .mode = 0644,
Alexey Dobriyan6d9f2392008-11-03 18:21:05 -08001075 .proc_handler = proc_dointvec_ms_jiffies,
Linus Torvalds1da177e2005-04-16 15:20:36 -07001076 },
Eric W. Biedermanf8572d82009-11-05 13:32:03 -08001077 { },
Linus Torvalds1da177e2005-04-16 15:20:36 -07001078};
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001079
Alexey Dobriyan2c8c1e72010-01-17 03:35:32 +00001080struct ctl_table * __net_init ipv6_icmp_sysctl_init(struct net *net)
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001081{
1082 struct ctl_table *table;
1083
1084 table = kmemdup(ipv6_icmp_table_template,
1085 sizeof(ipv6_icmp_table_template),
1086 GFP_KERNEL);
YOSHIFUJI Hideaki5ee09102008-02-28 00:24:28 +09001087
Eric W. Biedermanc027aab2012-11-16 03:03:10 +00001088 if (table)
YOSHIFUJI Hideaki5ee09102008-02-28 00:24:28 +09001089 table[0].data = &net->ipv6.sysctl.icmpv6_time;
1090
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001091 return table;
1092}
Linus Torvalds1da177e2005-04-16 15:20:36 -07001093#endif