blob: 8d7b113958b1332be11545069fafa8072a64e6a2 [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * Internet Control Message Protocol (ICMPv6)
3 * Linux INET6 implementation
4 *
5 * Authors:
6 * Pedro Roque <roque@di.fc.ul.pt>
7 *
Linus Torvalds1da177e2005-04-16 15:20:36 -07008 * Based on net/ipv4/icmp.c
9 *
10 * RFC 1885
11 *
12 * This program is free software; you can redistribute it and/or
13 * modify it under the terms of the GNU General Public License
14 * as published by the Free Software Foundation; either version
15 * 2 of the License, or (at your option) any later version.
16 */
17
18/*
19 * Changes:
20 *
21 * Andi Kleen : exception handling
22 * Andi Kleen add rate limits. never reply to a icmp.
23 * add more length checks and other fixes.
24 * yoshfuji : ensure to sent parameter problem for
25 * fragments.
26 * YOSHIFUJI Hideaki @USAGI: added sysctl for icmp rate limit.
27 * Randy Dunlap and
28 * YOSHIFUJI Hideaki @USAGI: Per-interface statistics support
29 * Kazunori MIYAZAWA @USAGI: change output process to use ip6_append_data
30 */
31
Joe Perchesf3213832012-05-15 14:11:53 +000032#define pr_fmt(fmt) "IPv6: " fmt
33
Linus Torvalds1da177e2005-04-16 15:20:36 -070034#include <linux/module.h>
35#include <linux/errno.h>
36#include <linux/types.h>
37#include <linux/socket.h>
38#include <linux/in.h>
39#include <linux/kernel.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070040#include <linux/sockios.h>
41#include <linux/net.h>
42#include <linux/skbuff.h>
43#include <linux/init.h>
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -080044#include <linux/netfilter.h>
Tejun Heo5a0e3ad2010-03-24 17:04:11 +090045#include <linux/slab.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070046
47#ifdef CONFIG_SYSCTL
48#include <linux/sysctl.h>
49#endif
50
51#include <linux/inet.h>
52#include <linux/netdevice.h>
53#include <linux/icmpv6.h>
54
55#include <net/ip.h>
56#include <net/sock.h>
57
58#include <net/ipv6.h>
59#include <net/ip6_checksum.h>
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000060#include <net/ping.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070061#include <net/protocol.h>
62#include <net/raw.h>
63#include <net/rawv6.h>
64#include <net/transp_v6.h>
65#include <net/ip6_route.h>
66#include <net/addrconf.h>
67#include <net/icmp.h>
Herbert Xu8b7817f2007-12-12 10:44:43 -080068#include <net/xfrm.h>
Denis V. Lunev1ed85162008-04-03 14:31:03 -070069#include <net/inet_common.h>
Hannes Frederic Sowa825edac2014-01-11 11:55:46 +010070#include <net/dsfield.h>
David Ahernca254492015-10-12 11:47:10 -070071#include <net/l3mdev.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070072
Linus Torvalds7c0f6ba2016-12-24 11:46:01 -080073#include <linux/uaccess.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070074
Linus Torvalds1da177e2005-04-16 15:20:36 -070075/*
76 * The ICMP socket(s). This is the most convenient way to flow control
77 * our ICMP output as well as maintain a clean interface throughout
78 * all layers. All Socketless IP sends will soon be gone.
79 *
80 * On SMP we have one ICMP socket per-cpu.
81 */
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -080082static inline struct sock *icmpv6_sk(struct net *net)
83{
84 return net->ipv6.icmp_sk[smp_processor_id()];
85}
Linus Torvalds1da177e2005-04-16 15:20:36 -070086
Steffen Klassert6f809da2013-01-16 22:09:49 +000087static void icmpv6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
88 u8 type, u8 code, int offset, __be32 info)
89{
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000090 /* icmpv6_notify checks 8 bytes can be pulled, icmp6hdr is 8 bytes */
91 struct icmp6hdr *icmp6 = (struct icmp6hdr *) (skb->data + offset);
Steffen Klassert6f809da2013-01-16 22:09:49 +000092 struct net *net = dev_net(skb->dev);
93
94 if (type == ICMPV6_PKT_TOOBIG)
Lorenzo Colittie2d118a2016-11-04 02:23:43 +090095 ip6_update_pmtu(skb, net, info, 0, 0, sock_net_uid(net, NULL));
Steffen Klassert6f809da2013-01-16 22:09:49 +000096 else if (type == NDISC_REDIRECT)
Lorenzo Colittie2d118a2016-11-04 02:23:43 +090097 ip6_redirect(skb, net, skb->dev->ifindex, 0,
98 sock_net_uid(net, NULL));
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000099
100 if (!(type & ICMPV6_INFOMSG_MASK))
101 if (icmp6->icmp6_type == ICMPV6_ECHO_REQUEST)
Hannes Frederic Sowadcb94b82016-06-11 20:32:06 +0200102 ping_err(skb, offset, ntohl(info));
Steffen Klassert6f809da2013-01-16 22:09:49 +0000103}
104
Herbert Xue5bbef22007-10-15 12:50:28 -0700105static int icmpv6_rcv(struct sk_buff *skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700106
Alexey Dobriyan41135cc2009-09-14 12:22:28 +0000107static const struct inet6_protocol icmpv6_protocol = {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700108 .handler = icmpv6_rcv,
Steffen Klassert6f809da2013-01-16 22:09:49 +0000109 .err_handler = icmpv6_err,
Herbert Xu8b7817f2007-12-12 10:44:43 -0800110 .flags = INET6_PROTO_NOPOLICY|INET6_PROTO_FINAL,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700111};
112
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100113/* Called with BH disabled */
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700114static __inline__ struct sock *icmpv6_xmit_lock(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700115{
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700116 struct sock *sk;
117
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700118 sk = icmpv6_sk(net);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800119 if (unlikely(!spin_trylock(&sk->sk_lock.slock))) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700120 /* This can happen if the output path (f.e. SIT or
121 * ip6ip6 tunnel) signals dst_link_failure() for an
122 * outgoing ICMP6 packet.
123 */
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700124 return NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700125 }
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700126 return sk;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700127}
128
Denis V. Lunev405666d2008-02-29 11:16:46 -0800129static __inline__ void icmpv6_xmit_unlock(struct sock *sk)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700130{
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100131 spin_unlock(&sk->sk_lock.slock);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700132}
133
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900134/*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700135 * Figure out, may we reply to this packet with icmp error.
136 *
137 * We do not reply, if:
138 * - it was icmp error message.
139 * - it is truncated, so that it is known, that protocol is ICMPV6
140 * (i.e. in the middle of some exthdr)
141 *
142 * --ANK (980726)
143 */
144
Eric Dumazeta50feda2012-05-18 18:57:34 +0000145static bool is_ineligible(const struct sk_buff *skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700146{
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700147 int ptr = (u8 *)(ipv6_hdr(skb) + 1) - skb->data;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700148 int len = skb->len - ptr;
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700149 __u8 nexthdr = ipv6_hdr(skb)->nexthdr;
Jesse Gross75f28112011-11-30 17:05:51 -0800150 __be16 frag_off;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700151
152 if (len < 0)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000153 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700154
Jesse Gross75f28112011-11-30 17:05:51 -0800155 ptr = ipv6_skip_exthdr(skb, ptr, &nexthdr, &frag_off);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700156 if (ptr < 0)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000157 return false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700158 if (nexthdr == IPPROTO_ICMPV6) {
159 u8 _type, *tp;
160 tp = skb_header_pointer(skb,
161 ptr+offsetof(struct icmp6hdr, icmp6_type),
162 sizeof(_type), &_type);
Ian Morris63159f22015-03-29 14:00:04 +0100163 if (!tp || !(*tp & ICMPV6_INFOMSG_MASK))
Eric Dumazeta50feda2012-05-18 18:57:34 +0000164 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700165 }
Eric Dumazeta50feda2012-05-18 18:57:34 +0000166 return false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700167}
168
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100169static bool icmpv6_mask_allow(int type)
170{
171 /* Informational messages are not limited. */
172 if (type & ICMPV6_INFOMSG_MASK)
173 return true;
174
175 /* Do not limit pmtu discovery, it would break it. */
176 if (type == ICMPV6_PKT_TOOBIG)
177 return true;
178
179 return false;
180}
181
182static bool icmpv6_global_allow(int type)
183{
184 if (icmpv6_mask_allow(type))
185 return true;
186
187 if (icmp_global_allow())
188 return true;
189
190 return false;
191}
192
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900193/*
194 * Check the ICMP output rate limit
Linus Torvalds1da177e2005-04-16 15:20:36 -0700195 */
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700196static bool icmpv6_xrlim_allow(struct sock *sk, u8 type,
197 struct flowi6 *fl6)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700198{
YOSHIFUJI Hideaki3b1e0a62008-03-26 02:26:21 +0900199 struct net *net = sock_net(sk);
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700200 struct dst_entry *dst;
David S. Miller92d86822011-02-04 15:55:25 -0800201 bool res = false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700202
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100203 if (icmpv6_mask_allow(type))
David S. Miller92d86822011-02-04 15:55:25 -0800204 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700205
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900206 /*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700207 * Look up the output route.
208 * XXX: perhaps the expire for routing entries cloned by
209 * this lookup should be more aggressive (not longer than timeout).
210 */
David S. Miller4c9483b2011-03-12 16:22:43 -0500211 dst = ip6_route_output(net, sk, fl6);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700212 if (dst->error) {
Denis V. Lunev3bd653c2008-10-08 10:54:51 -0700213 IP6_INC_STATS(net, ip6_dst_idev(dst),
YOSHIFUJI Hideakia11d2062006-11-04 20:11:37 +0900214 IPSTATS_MIB_OUTNOROUTES);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700215 } else if (dst->dev && (dst->dev->flags&IFF_LOOPBACK)) {
David S. Miller92d86822011-02-04 15:55:25 -0800216 res = true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700217 } else {
218 struct rt6_info *rt = (struct rt6_info *)dst;
Benjamin Thery9a43b702008-03-05 10:49:18 -0800219 int tmo = net->ipv6.sysctl.icmpv6_time;
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100220 struct inet_peer *peer;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700221
222 /* Give more bandwidth to wider prefixes. */
223 if (rt->rt6i_dst.plen < 128)
224 tmo >>= ((128 - rt->rt6i_dst.plen)>>5);
225
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100226 peer = inet_getpeer_v6(net->ipv6.peers, &fl6->daddr, 1);
227 res = inet_peer_xrlim_allow(peer, tmo);
228 if (peer)
229 inet_putpeer(peer);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700230 }
231 dst_release(dst);
232 return res;
233}
234
235/*
236 * an inline helper for the "simple" if statement below
237 * checks if parameter problem report is caused by an
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900238 * unrecognized IPv6 option that has the Option Type
Linus Torvalds1da177e2005-04-16 15:20:36 -0700239 * highest-order two bits set to 10
240 */
241
Eric Dumazeta50feda2012-05-18 18:57:34 +0000242static bool opt_unrec(struct sk_buff *skb, __u32 offset)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700243{
244 u8 _optval, *op;
245
Arnaldo Carvalho de Melobbe735e2007-03-10 22:16:10 -0300246 offset += skb_network_offset(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700247 op = skb_header_pointer(skb, offset, sizeof(_optval), &_optval);
Ian Morris63159f22015-03-29 14:00:04 +0100248 if (!op)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000249 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700250 return (*op & 0xC0) == 0x80;
251}
252
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +0000253int icmpv6_push_pending_frames(struct sock *sk, struct flowi6 *fl6,
254 struct icmp6hdr *thdr, int len)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700255{
256 struct sk_buff *skb;
257 struct icmp6hdr *icmp6h;
258 int err = 0;
259
Ian Morrise5d08d72014-11-23 21:28:43 +0000260 skb = skb_peek(&sk->sk_write_queue);
Ian Morris63159f22015-03-29 14:00:04 +0100261 if (!skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700262 goto out;
263
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300264 icmp6h = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700265 memcpy(icmp6h, thdr, sizeof(struct icmp6hdr));
266 icmp6h->icmp6_cksum = 0;
267
268 if (skb_queue_len(&sk->sk_write_queue) == 1) {
Joe Perches07f07572008-11-19 15:44:53 -0800269 skb->csum = csum_partial(icmp6h,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700270 sizeof(struct icmp6hdr), skb->csum);
David S. Miller4c9483b2011-03-12 16:22:43 -0500271 icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
272 &fl6->daddr,
273 len, fl6->flowi6_proto,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700274 skb->csum);
275 } else {
Al Viro868c86b2006-11-14 21:35:48 -0800276 __wsum tmp_csum = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700277
278 skb_queue_walk(&sk->sk_write_queue, skb) {
279 tmp_csum = csum_add(tmp_csum, skb->csum);
280 }
281
Joe Perches07f07572008-11-19 15:44:53 -0800282 tmp_csum = csum_partial(icmp6h,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700283 sizeof(struct icmp6hdr), tmp_csum);
David S. Miller4c9483b2011-03-12 16:22:43 -0500284 icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
285 &fl6->daddr,
286 len, fl6->flowi6_proto,
Al Viro868c86b2006-11-14 21:35:48 -0800287 tmp_csum);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700288 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700289 ip6_push_pending_frames(sk);
290out:
291 return err;
292}
293
294struct icmpv6_msg {
295 struct sk_buff *skb;
296 int offset;
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800297 uint8_t type;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700298};
299
300static int icmpv6_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
301{
302 struct icmpv6_msg *msg = (struct icmpv6_msg *) from;
303 struct sk_buff *org_skb = msg->skb;
Al Viro5f92a732006-11-14 21:36:54 -0800304 __wsum csum = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700305
306 csum = skb_copy_and_csum_bits(org_skb, msg->offset + offset,
307 to, len, csum);
308 skb->csum = csum_block_add(skb->csum, csum, odd);
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800309 if (!(msg->type & ICMPV6_INFOMSG_MASK))
310 nf_ct_attach(skb, org_skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700311 return 0;
312}
313
Amerigo Wang07a93622012-10-29 16:23:10 +0000314#if IS_ENABLED(CONFIG_IPV6_MIP6)
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700315static void mip6_addr_swap(struct sk_buff *skb)
316{
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700317 struct ipv6hdr *iph = ipv6_hdr(skb);
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700318 struct inet6_skb_parm *opt = IP6CB(skb);
319 struct ipv6_destopt_hao *hao;
320 struct in6_addr tmp;
321 int off;
322
323 if (opt->dsthao) {
324 off = ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO);
325 if (likely(off >= 0)) {
Arnaldo Carvalho de Melod56f90a2007-04-10 20:50:43 -0700326 hao = (struct ipv6_destopt_hao *)
327 (skb_network_header(skb) + off);
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000328 tmp = iph->saddr;
329 iph->saddr = hao->addr;
330 hao->addr = tmp;
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700331 }
332 }
333}
334#else
335static inline void mip6_addr_swap(struct sk_buff *skb) {}
336#endif
337
stephen hemmingere8243532013-12-29 14:03:31 -0800338static struct dst_entry *icmpv6_route_lookup(struct net *net,
339 struct sk_buff *skb,
340 struct sock *sk,
341 struct flowi6 *fl6)
David S. Millerb42835d2011-03-01 22:06:22 -0800342{
343 struct dst_entry *dst, *dst2;
David S. Miller4c9483b2011-03-12 16:22:43 -0500344 struct flowi6 fl2;
David S. Millerb42835d2011-03-01 22:06:22 -0800345 int err;
346
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700347 err = ip6_dst_lookup(net, sk, &dst, fl6);
David S. Millerb42835d2011-03-01 22:06:22 -0800348 if (err)
349 return ERR_PTR(err);
350
351 /*
352 * We won't send icmp if the destination is known
353 * anycast.
354 */
Martin KaFai Lau2647a9b2015-05-22 20:55:58 -0700355 if (ipv6_anycast_destination(dst, &fl6->daddr)) {
Joe Perchesba7a46f2014-11-11 10:59:17 -0800356 net_dbg_ratelimited("icmp6_send: acast source\n");
David S. Millerb42835d2011-03-01 22:06:22 -0800357 dst_release(dst);
358 return ERR_PTR(-EINVAL);
359 }
360
361 /* No need to clone since we're just using its address. */
362 dst2 = dst;
363
David S. Miller4c9483b2011-03-12 16:22:43 -0500364 dst = xfrm_lookup(net, dst, flowi6_to_flowi(fl6), sk, 0);
David S. Miller452edd52011-03-02 13:27:41 -0800365 if (!IS_ERR(dst)) {
David S. Millerb42835d2011-03-01 22:06:22 -0800366 if (dst != dst2)
367 return dst;
David S. Miller452edd52011-03-02 13:27:41 -0800368 } else {
369 if (PTR_ERR(dst) == -EPERM)
370 dst = NULL;
371 else
372 return dst;
David S. Millerb42835d2011-03-01 22:06:22 -0800373 }
374
David S. Miller4c9483b2011-03-12 16:22:43 -0500375 err = xfrm_decode_session_reverse(skb, flowi6_to_flowi(&fl2), AF_INET6);
David S. Millerb42835d2011-03-01 22:06:22 -0800376 if (err)
377 goto relookup_failed;
378
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700379 err = ip6_dst_lookup(net, sk, &dst2, &fl2);
David S. Millerb42835d2011-03-01 22:06:22 -0800380 if (err)
381 goto relookup_failed;
382
David S. Miller4c9483b2011-03-12 16:22:43 -0500383 dst2 = xfrm_lookup(net, dst2, flowi6_to_flowi(&fl2), sk, XFRM_LOOKUP_ICMP);
David S. Miller452edd52011-03-02 13:27:41 -0800384 if (!IS_ERR(dst2)) {
David S. Millerb42835d2011-03-01 22:06:22 -0800385 dst_release(dst);
386 dst = dst2;
David S. Miller452edd52011-03-02 13:27:41 -0800387 } else {
388 err = PTR_ERR(dst2);
389 if (err == -EPERM) {
390 dst_release(dst);
391 return dst2;
392 } else
393 goto relookup_failed;
David S. Millerb42835d2011-03-01 22:06:22 -0800394 }
395
396relookup_failed:
397 if (dst)
398 return dst;
399 return ERR_PTR(err);
400}
401
Linus Torvalds1da177e2005-04-16 15:20:36 -0700402/*
403 * Send an ICMP message in response to a packet in error
404 */
Eric Dumazetb1cadc12016-06-18 21:52:02 -0700405static void icmp6_send(struct sk_buff *skb, u8 type, u8 code, __u32 info,
406 const struct in6_addr *force_saddr)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700407{
YOSHIFUJI Hideakic346dca2008-03-25 21:47:49 +0900408 struct net *net = dev_net(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700409 struct inet6_dev *idev = NULL;
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700410 struct ipv6hdr *hdr = ipv6_hdr(skb);
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700411 struct sock *sk;
412 struct ipv6_pinfo *np;
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000413 const struct in6_addr *saddr = NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700414 struct dst_entry *dst;
415 struct icmp6hdr tmp_hdr;
David S. Miller4c9483b2011-03-12 16:22:43 -0500416 struct flowi6 fl6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700417 struct icmpv6_msg msg;
Soheil Hassas Yeganehc14ac942016-04-02 23:08:12 -0400418 struct sockcm_cookie sockc_unused = {0};
Wei Wang26879da2016-05-02 21:40:07 -0700419 struct ipcm6_cookie ipc6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700420 int iif = 0;
421 int addr_type = 0;
422 int len;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700423 int err = 0;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700424 u32 mark = IP6_REPLY_MARK(net, skb->mark);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700425
Arnaldo Carvalho de Melo27a884d2007-04-19 20:29:13 -0700426 if ((u8 *)hdr < skb->head ||
Simon Horman29a3cad2013-05-28 20:34:26 +0000427 (skb_network_header(skb) + sizeof(*hdr)) > skb_tail_pointer(skb))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700428 return;
429
430 /*
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900431 * Make sure we respect the rules
Linus Torvalds1da177e2005-04-16 15:20:36 -0700432 * i.e. RFC 1885 2.4(e)
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000433 * Rule (e.1) is enforced by not using icmp6_send
Linus Torvalds1da177e2005-04-16 15:20:36 -0700434 * in any code that processes icmp errors.
435 */
436 addr_type = ipv6_addr_type(&hdr->daddr);
437
FX Le Bail446fab52014-01-19 17:00:36 +0100438 if (ipv6_chk_addr(net, &hdr->daddr, skb->dev, 0) ||
FX Le Baild94c1f92014-02-07 11:22:37 +0100439 ipv6_chk_acast_addr_src(net, skb->dev, &hdr->daddr))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700440 saddr = &hdr->daddr;
441
442 /*
443 * Dest addr check
444 */
445
zhuyj9a6b4b32015-01-14 17:23:59 +0800446 if (addr_type & IPV6_ADDR_MULTICAST || skb->pkt_type != PACKET_HOST) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700447 if (type != ICMPV6_PKT_TOOBIG &&
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900448 !(type == ICMPV6_PARAMPROB &&
449 code == ICMPV6_UNK_OPTION &&
Linus Torvalds1da177e2005-04-16 15:20:36 -0700450 (opt_unrec(skb, info))))
451 return;
452
453 saddr = NULL;
454 }
455
456 addr_type = ipv6_addr_type(&hdr->saddr);
457
458 /*
459 * Source addr check
460 */
461
Hannes Frederic Sowa842df072013-03-08 02:07:19 +0000462 if (__ipv6_addr_needs_scope_id(addr_type))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700463 iif = skb->dev->ifindex;
David Ahern79dc7e32016-11-27 18:52:53 -0800464 else {
465 dst = skb_dst(skb);
466 iif = l3mdev_master_ifindex(dst ? dst->dev : skb->dev);
467 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700468
469 /*
YOSHIFUJI Hideaki8de33512005-12-21 22:57:06 +0900470 * Must not send error if the source does not uniquely
471 * identify a single node (RFC2463 Section 2.4).
472 * We check unspecified / multicast addresses here,
473 * and anycast addresses will be checked later.
Linus Torvalds1da177e2005-04-16 15:20:36 -0700474 */
475 if ((addr_type == IPV6_ADDR_ANY) || (addr_type & IPV6_ADDR_MULTICAST)) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200476 net_dbg_ratelimited("icmp6_send: addr_any/mcast source [%pI6c > %pI6c]\n",
477 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700478 return;
479 }
480
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900481 /*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700482 * Never answer to a ICMP packet.
483 */
484 if (is_ineligible(skb)) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200485 net_dbg_ratelimited("icmp6_send: no reply to icmp error [%pI6c > %pI6c]\n",
486 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700487 return;
488 }
489
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100490 /* Needed by both icmp_global_allow and icmpv6_xmit_lock */
491 local_bh_disable();
492
493 /* Check global sysctl_icmp_msgs_per_sec ratelimit */
Jesper Dangaard Brouer849a44d2017-06-14 13:27:37 +0200494 if (!(skb->dev->flags&IFF_LOOPBACK) && !icmpv6_global_allow(type))
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100495 goto out_bh_enable;
496
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700497 mip6_addr_swap(skb);
498
David S. Miller4c9483b2011-03-12 16:22:43 -0500499 memset(&fl6, 0, sizeof(fl6));
500 fl6.flowi6_proto = IPPROTO_ICMPV6;
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000501 fl6.daddr = hdr->saddr;
Eric Dumazetb1cadc12016-06-18 21:52:02 -0700502 if (force_saddr)
503 saddr = force_saddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700504 if (saddr)
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000505 fl6.saddr = *saddr;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700506 fl6.flowi6_mark = mark;
David S. Miller4c9483b2011-03-12 16:22:43 -0500507 fl6.flowi6_oif = iif;
David S. Miller1958b852011-03-12 16:36:19 -0500508 fl6.fl6_icmp_type = type;
509 fl6.fl6_icmp_code = code;
Lorenzo Colittie2d118a2016-11-04 02:23:43 +0900510 fl6.flowi6_uid = sock_net_uid(net, NULL);
David S. Miller4c9483b2011-03-12 16:22:43 -0500511 security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700512
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700513 sk = icmpv6_xmit_lock(net);
Ian Morris63159f22015-03-29 14:00:04 +0100514 if (!sk)
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100515 goto out_bh_enable;
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100516
Lorenzo Colittie1108612014-05-13 10:17:33 -0700517 sk->sk_mark = mark;
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700518 np = inet6_sk(sk);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800519
David S. Miller4c9483b2011-03-12 16:22:43 -0500520 if (!icmpv6_xrlim_allow(sk, type, &fl6))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700521 goto out;
522
523 tmp_hdr.icmp6_type = type;
524 tmp_hdr.icmp6_code = code;
525 tmp_hdr.icmp6_cksum = 0;
526 tmp_hdr.icmp6_pointer = htonl(info);
527
David S. Miller4c9483b2011-03-12 16:22:43 -0500528 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
529 fl6.flowi6_oif = np->mcast_oif;
Erich E. Hooverc4062df2012-02-08 09:11:08 +0000530 else if (!fl6.flowi6_oif)
531 fl6.flowi6_oif = np->ucast_oif;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700532
Hannes Frederic Sowa38b70972016-06-11 20:08:19 +0200533 ipc6.tclass = np->tclass;
534 fl6.flowlabel = ip6_make_flowinfo(ipc6.tclass, fl6.flowlabel);
535
David S. Miller4c9483b2011-03-12 16:22:43 -0500536 dst = icmpv6_route_lookup(net, skb, sk, &fl6);
David S. Millerb42835d2011-03-01 22:06:22 -0800537 if (IS_ERR(dst))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700538 goto out;
YOSHIFUJI Hideaki8de33512005-12-21 22:57:06 +0900539
Wei Wang26879da2016-05-02 21:40:07 -0700540 ipc6.hlimit = ip6_sk_dst_hoplimit(np, &fl6, dst);
Wei Wang26879da2016-05-02 21:40:07 -0700541 ipc6.dontfrag = np->dontfrag;
542 ipc6.opt = NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700543
544 msg.skb = skb;
Arnaldo Carvalho de Melobbe735e2007-03-10 22:16:10 -0300545 msg.offset = skb_network_offset(skb);
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800546 msg.type = type;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700547
548 len = skb->len - msg.offset;
Ian Morris67ba4152014-08-24 21:53:10 +0100549 len = min_t(unsigned int, len, IPV6_MIN_MTU - sizeof(struct ipv6hdr) - sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700550 if (len < 0) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200551 net_dbg_ratelimited("icmp: len problem [%pI6c > %pI6c]\n",
552 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700553 goto out_dst_release;
554 }
555
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000556 rcu_read_lock();
557 idev = __in6_dev_get(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700558
559 err = ip6_append_data(sk, icmpv6_getfrag, &msg,
560 len + sizeof(struct icmp6hdr),
Wei Wang26879da2016-05-02 21:40:07 -0700561 sizeof(struct icmp6hdr),
562 &ipc6, &fl6, (struct rt6_info *)dst,
563 MSG_DONTWAIT, &sockc_unused);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700564 if (err) {
Hannes Frederic Sowa43a43b62014-03-31 20:14:10 +0200565 ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700566 ip6_flush_pending_frames(sk);
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000567 } else {
568 err = icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
569 len + sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700570 }
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000571 rcu_read_unlock();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700572out_dst_release:
573 dst_release(dst);
574out:
Denis V. Lunev405666d2008-02-29 11:16:46 -0800575 icmpv6_xmit_unlock(sk);
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100576out_bh_enable:
577 local_bh_enable();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700578}
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000579
580/* Slightly more convenient version of icmp6_send.
581 */
582void icmpv6_param_prob(struct sk_buff *skb, u8 code, int pos)
583{
Eric Dumazetb1cadc12016-06-18 21:52:02 -0700584 icmp6_send(skb, ICMPV6_PARAMPROB, code, pos, NULL);
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000585 kfree_skb(skb);
586}
YOSHIFUJI Hideaki71590392007-02-22 22:05:40 +0900587
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700588/* Generate icmpv6 with type/code ICMPV6_DEST_UNREACH/ICMPV6_ADDR_UNREACH
589 * if sufficient data bytes are available
590 * @nhs is the size of the tunnel header(s) :
591 * Either an IPv4 header for SIT encap
592 * an IPv4 header + GRE header for GRE encap
593 */
Eric Dumazet20e19542016-06-18 21:52:06 -0700594int ip6_err_gen_icmpv6_unreach(struct sk_buff *skb, int nhs, int type,
595 unsigned int data_len)
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700596{
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700597 struct in6_addr temp_saddr;
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700598 struct rt6_info *rt;
599 struct sk_buff *skb2;
Eric Dumazet20e19542016-06-18 21:52:06 -0700600 u32 info = 0;
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700601
602 if (!pskb_may_pull(skb, nhs + sizeof(struct ipv6hdr) + 8))
603 return 1;
604
Eric Dumazet20e19542016-06-18 21:52:06 -0700605 /* RFC 4884 (partial) support for ICMP extensions */
606 if (data_len < 128 || (data_len & 7) || skb->len < data_len)
607 data_len = 0;
608
609 skb2 = data_len ? skb_copy(skb, GFP_ATOMIC) : skb_clone(skb, GFP_ATOMIC);
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700610
611 if (!skb2)
612 return 1;
613
614 skb_dst_drop(skb2);
615 skb_pull(skb2, nhs);
616 skb_reset_network_header(skb2);
617
618 rt = rt6_lookup(dev_net(skb->dev), &ipv6_hdr(skb2)->saddr, NULL, 0, 0);
619
620 if (rt && rt->dst.dev)
621 skb2->dev = rt->dst.dev;
622
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700623 ipv6_addr_set_v4mapped(ip_hdr(skb)->saddr, &temp_saddr);
Eric Dumazet20e19542016-06-18 21:52:06 -0700624
625 if (data_len) {
626 /* RFC 4884 (partial) support :
627 * insert 0 padding at the end, before the extensions
628 */
629 __skb_push(skb2, nhs);
630 skb_reset_network_header(skb2);
631 memmove(skb2->data, skb2->data + nhs, data_len - nhs);
632 memset(skb2->data + data_len - nhs, 0, nhs);
633 /* RFC 4884 4.5 : Length is measured in 64-bit words,
634 * and stored in reserved[0]
635 */
636 info = (data_len/8) << 24;
637 }
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700638 if (type == ICMP_TIME_EXCEEDED)
639 icmp6_send(skb2, ICMPV6_TIME_EXCEED, ICMPV6_EXC_HOPLIMIT,
Eric Dumazet20e19542016-06-18 21:52:06 -0700640 info, &temp_saddr);
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700641 else
642 icmp6_send(skb2, ICMPV6_DEST_UNREACH, ICMPV6_ADDR_UNREACH,
Eric Dumazet20e19542016-06-18 21:52:06 -0700643 info, &temp_saddr);
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700644 if (rt)
645 ip6_rt_put(rt);
646
647 kfree_skb(skb2);
648
649 return 0;
650}
651EXPORT_SYMBOL(ip6_err_gen_icmpv6_unreach);
652
Linus Torvalds1da177e2005-04-16 15:20:36 -0700653static void icmpv6_echo_reply(struct sk_buff *skb)
654{
YOSHIFUJI Hideakic346dca2008-03-25 21:47:49 +0900655 struct net *net = dev_net(skb->dev);
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700656 struct sock *sk;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700657 struct inet6_dev *idev;
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700658 struct ipv6_pinfo *np;
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000659 const struct in6_addr *saddr = NULL;
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300660 struct icmp6hdr *icmph = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700661 struct icmp6hdr tmp_hdr;
David S. Miller4c9483b2011-03-12 16:22:43 -0500662 struct flowi6 fl6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700663 struct icmpv6_msg msg;
664 struct dst_entry *dst;
Wei Wang26879da2016-05-02 21:40:07 -0700665 struct ipcm6_cookie ipc6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700666 int err = 0;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700667 u32 mark = IP6_REPLY_MARK(net, skb->mark);
Soheil Hassas Yeganehc14ac942016-04-02 23:08:12 -0400668 struct sockcm_cookie sockc_unused = {0};
Linus Torvalds1da177e2005-04-16 15:20:36 -0700669
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700670 saddr = &ipv6_hdr(skb)->daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700671
FX Le Bail509aba32014-01-07 14:57:27 +0100672 if (!ipv6_unicast_destination(skb) &&
FX Le Bailec35b612014-01-13 15:59:01 +0100673 !(net->ipv6.sysctl.anycast_src_echo_reply &&
Martin KaFai Lau2647a9b2015-05-22 20:55:58 -0700674 ipv6_anycast_destination(skb_dst(skb), saddr)))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700675 saddr = NULL;
676
677 memcpy(&tmp_hdr, icmph, sizeof(tmp_hdr));
678 tmp_hdr.icmp6_type = ICMPV6_ECHO_REPLY;
679
David S. Miller4c9483b2011-03-12 16:22:43 -0500680 memset(&fl6, 0, sizeof(fl6));
681 fl6.flowi6_proto = IPPROTO_ICMPV6;
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000682 fl6.daddr = ipv6_hdr(skb)->saddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700683 if (saddr)
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000684 fl6.saddr = *saddr;
David Ahern9ff74382016-06-13 13:44:19 -0700685 fl6.flowi6_oif = skb->dev->ifindex;
David S. Miller1958b852011-03-12 16:36:19 -0500686 fl6.fl6_icmp_type = ICMPV6_ECHO_REPLY;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700687 fl6.flowi6_mark = mark;
Lorenzo Colittie2d118a2016-11-04 02:23:43 +0900688 fl6.flowi6_uid = sock_net_uid(net, NULL);
David S. Miller4c9483b2011-03-12 16:22:43 -0500689 security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700690
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100691 local_bh_disable();
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700692 sk = icmpv6_xmit_lock(net);
Ian Morris63159f22015-03-29 14:00:04 +0100693 if (!sk)
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100694 goto out_bh_enable;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700695 sk->sk_mark = mark;
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700696 np = inet6_sk(sk);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800697
David S. Miller4c9483b2011-03-12 16:22:43 -0500698 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
699 fl6.flowi6_oif = np->mcast_oif;
Erich E. Hooverc4062df2012-02-08 09:11:08 +0000700 else if (!fl6.flowi6_oif)
701 fl6.flowi6_oif = np->ucast_oif;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700702
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700703 err = ip6_dst_lookup(net, sk, &dst, &fl6);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700704 if (err)
705 goto out;
David S. Miller4c9483b2011-03-12 16:22:43 -0500706 dst = xfrm_lookup(net, dst, flowi6_to_flowi(&fl6), sk, 0);
David S. Miller452edd52011-03-02 13:27:41 -0800707 if (IS_ERR(dst))
Patrick McHardye104411b2005-09-08 15:11:55 -0700708 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700709
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000710 idev = __in6_dev_get(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700711
712 msg.skb = skb;
713 msg.offset = 0;
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800714 msg.type = ICMPV6_ECHO_REPLY;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700715
Wei Wang26879da2016-05-02 21:40:07 -0700716 ipc6.hlimit = ip6_sk_dst_hoplimit(np, &fl6, dst);
717 ipc6.tclass = ipv6_get_dsfield(ipv6_hdr(skb));
718 ipc6.dontfrag = np->dontfrag;
719 ipc6.opt = NULL;
720
Linus Torvalds1da177e2005-04-16 15:20:36 -0700721 err = ip6_append_data(sk, icmpv6_getfrag, &msg, skb->len + sizeof(struct icmp6hdr),
Wei Wang26879da2016-05-02 21:40:07 -0700722 sizeof(struct icmp6hdr), &ipc6, &fl6,
Eldad Zacka2d91a02012-04-01 07:49:07 +0000723 (struct rt6_info *)dst, MSG_DONTWAIT,
Wei Wang26879da2016-05-02 21:40:07 -0700724 &sockc_unused);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700725
726 if (err) {
Eric Dumazeta16292a2016-04-27 16:44:36 -0700727 __ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700728 ip6_flush_pending_frames(sk);
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000729 } else {
730 err = icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
731 skb->len + sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700732 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700733 dst_release(dst);
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900734out:
Denis V. Lunev405666d2008-02-29 11:16:46 -0800735 icmpv6_xmit_unlock(sk);
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100736out_bh_enable:
737 local_bh_enable();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700738}
739
David S. Millerb94f1c02012-07-12 00:33:37 -0700740void icmpv6_notify(struct sk_buff *skb, u8 type, u8 code, __be32 info)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700741{
Alexey Dobriyan41135cc2009-09-14 12:22:28 +0000742 const struct inet6_protocol *ipprot;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700743 int inner_offset;
Jesse Gross75f28112011-11-30 17:05:51 -0800744 __be16 frag_off;
David S. Millerf9242b62012-06-19 18:56:21 -0700745 u8 nexthdr;
Duan Jiong7304fe42014-07-31 17:54:32 +0800746 struct net *net = dev_net(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700747
748 if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
Duan Jiong7304fe42014-07-31 17:54:32 +0800749 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700750
751 nexthdr = ((struct ipv6hdr *)skb->data)->nexthdr;
752 if (ipv6_ext_hdr(nexthdr)) {
753 /* now skip over extension headers */
Jesse Gross75f28112011-11-30 17:05:51 -0800754 inner_offset = ipv6_skip_exthdr(skb, sizeof(struct ipv6hdr),
755 &nexthdr, &frag_off);
Ian Morris67ba4152014-08-24 21:53:10 +0100756 if (inner_offset < 0)
Duan Jiong7304fe42014-07-31 17:54:32 +0800757 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700758 } else {
759 inner_offset = sizeof(struct ipv6hdr);
760 }
761
762 /* Checkin header including 8 bytes of inner protocol header. */
763 if (!pskb_may_pull(skb, inner_offset+8))
Duan Jiong7304fe42014-07-31 17:54:32 +0800764 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700765
Linus Torvalds1da177e2005-04-16 15:20:36 -0700766 /* BUGGG_FUTURE: we should try to parse exthdrs in this packet.
767 Without this we will not able f.e. to make source routed
768 pmtu discovery.
769 Corresponding argument (opt) to notifiers is already added.
770 --ANK (980726)
771 */
772
David S. Millerf9242b62012-06-19 18:56:21 -0700773 ipprot = rcu_dereference(inet6_protos[nexthdr]);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700774 if (ipprot && ipprot->err_handler)
775 ipprot->err_handler(skb, NULL, type, code, inner_offset, info);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700776
Pavel Emelyanov69d6da02007-11-19 22:35:57 -0800777 raw6_icmp_error(skb, nexthdr, type, code, inner_offset, info);
Duan Jiong7304fe42014-07-31 17:54:32 +0800778 return;
779
780out:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700781 __ICMP6_INC_STATS(net, __in6_dev_get(skb->dev), ICMP6_MIB_INERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700782}
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900783
Linus Torvalds1da177e2005-04-16 15:20:36 -0700784/*
785 * Handle icmp messages
786 */
787
Herbert Xue5bbef22007-10-15 12:50:28 -0700788static int icmpv6_rcv(struct sk_buff *skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700789{
Linus Torvalds1da177e2005-04-16 15:20:36 -0700790 struct net_device *dev = skb->dev;
791 struct inet6_dev *idev = __in6_dev_get(dev);
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000792 const struct in6_addr *saddr, *daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700793 struct icmp6hdr *hdr;
Brian Haleyd5fdd6b2009-06-23 04:31:07 -0700794 u8 type;
Rick Jonese3e32172014-11-17 14:04:29 -0800795 bool success = false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700796
Herbert Xuaebcf822007-12-12 18:54:16 -0800797 if (!xfrm6_policy_check(NULL, XFRM_POLICY_IN, skb)) {
Alexey Dobriyandef8b4f2008-10-28 13:24:06 -0700798 struct sec_path *sp = skb_sec_path(skb);
Herbert Xu8b7817f2007-12-12 10:44:43 -0800799 int nh;
800
Alexey Dobriyandef8b4f2008-10-28 13:24:06 -0700801 if (!(sp && sp->xvec[sp->len - 1]->props.flags &
Herbert Xuaebcf822007-12-12 18:54:16 -0800802 XFRM_STATE_ICMP))
803 goto drop_no_count;
804
David S. Miller81aded22012-06-15 14:54:11 -0700805 if (!pskb_may_pull(skb, sizeof(*hdr) + sizeof(struct ipv6hdr)))
Herbert Xu8b7817f2007-12-12 10:44:43 -0800806 goto drop_no_count;
807
808 nh = skb_network_offset(skb);
809 skb_set_network_header(skb, sizeof(*hdr));
810
811 if (!xfrm6_policy_check_reverse(NULL, XFRM_POLICY_IN, skb))
812 goto drop_no_count;
813
814 skb_set_network_header(skb, nh);
815 }
816
Eric Dumazeta16292a2016-04-27 16:44:36 -0700817 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_INMSGS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700818
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700819 saddr = &ipv6_hdr(skb)->saddr;
820 daddr = &ipv6_hdr(skb)->daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700821
Tom Herbert39471ac2014-05-07 16:52:29 -0700822 if (skb_checksum_validate(skb, IPPROTO_ICMPV6, ip6_compute_pseudo)) {
Joe Perchesba7a46f2014-11-11 10:59:17 -0800823 net_dbg_ratelimited("ICMPv6 checksum failed [%pI6c > %pI6c]\n",
824 saddr, daddr);
Tom Herbert39471ac2014-05-07 16:52:29 -0700825 goto csum_error;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700826 }
827
Herbert Xu8cf22942008-02-05 03:15:50 -0800828 if (!pskb_pull(skb, sizeof(*hdr)))
829 goto discard_it;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700830
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300831 hdr = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700832
833 type = hdr->icmp6_type;
834
Eric Dumazetf3832ed2016-04-27 16:44:42 -0700835 ICMP6MSGIN_INC_STATS(dev_net(dev), idev, type);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700836
837 switch (type) {
838 case ICMPV6_ECHO_REQUEST:
839 icmpv6_echo_reply(skb);
840 break;
841
842 case ICMPV6_ECHO_REPLY:
Rick Jonese3e32172014-11-17 14:04:29 -0800843 success = ping_rcv(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700844 break;
845
846 case ICMPV6_PKT_TOOBIG:
847 /* BUGGG_FUTURE: if packet contains rthdr, we cannot update
848 standard destination cache. Seems, only "advanced"
849 destination cache will allow to solve this problem
850 --ANK (980726)
851 */
852 if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
853 goto discard_it;
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300854 hdr = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700855
856 /*
857 * Drop through to notify
858 */
859
860 case ICMPV6_DEST_UNREACH:
861 case ICMPV6_TIME_EXCEED:
862 case ICMPV6_PARAMPROB:
863 icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
864 break;
865
866 case NDISC_ROUTER_SOLICITATION:
867 case NDISC_ROUTER_ADVERTISEMENT:
868 case NDISC_NEIGHBOUR_SOLICITATION:
869 case NDISC_NEIGHBOUR_ADVERTISEMENT:
870 case NDISC_REDIRECT:
871 ndisc_rcv(skb);
872 break;
873
874 case ICMPV6_MGM_QUERY:
875 igmp6_event_query(skb);
876 break;
877
878 case ICMPV6_MGM_REPORT:
879 igmp6_event_report(skb);
880 break;
881
882 case ICMPV6_MGM_REDUCTION:
883 case ICMPV6_NI_QUERY:
884 case ICMPV6_NI_REPLY:
885 case ICMPV6_MLD2_REPORT:
886 case ICMPV6_DHAAD_REQUEST:
887 case ICMPV6_DHAAD_REPLY:
888 case ICMPV6_MOBILE_PREFIX_SOL:
889 case ICMPV6_MOBILE_PREFIX_ADV:
890 break;
891
892 default:
Linus Torvalds1da177e2005-04-16 15:20:36 -0700893 /* informational */
894 if (type & ICMPV6_INFOMSG_MASK)
895 break;
896
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200897 net_dbg_ratelimited("icmpv6: msg of unknown type [%pI6c > %pI6c]\n",
898 saddr, daddr);
David S. Millerea85a0a2014-10-07 16:33:53 -0400899
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900900 /*
901 * error of unknown type.
902 * must pass to upper level
Linus Torvalds1da177e2005-04-16 15:20:36 -0700903 */
904
905 icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
Stephen Hemminger3ff50b72007-04-20 17:09:22 -0700906 }
907
Rick Jonese3e32172014-11-17 14:04:29 -0800908 /* until the v6 path can be better sorted assume failure and
909 * preserve the status quo behaviour for the rest of the paths to here
910 */
911 if (success)
912 consume_skb(skb);
913 else
914 kfree_skb(skb);
915
Linus Torvalds1da177e2005-04-16 15:20:36 -0700916 return 0;
917
Eric Dumazet6a5dc9e2013-04-29 08:39:56 +0000918csum_error:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700919 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_CSUMERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700920discard_it:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700921 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_INERRORS);
Herbert Xu8b7817f2007-12-12 10:44:43 -0800922drop_no_count:
Linus Torvalds1da177e2005-04-16 15:20:36 -0700923 kfree_skb(skb);
924 return 0;
925}
926
David S. Miller4c9483b2011-03-12 16:22:43 -0500927void icmpv6_flow_init(struct sock *sk, struct flowi6 *fl6,
YOSHIFUJI Hideaki95e41e92007-12-06 15:43:30 -0800928 u8 type,
929 const struct in6_addr *saddr,
930 const struct in6_addr *daddr,
931 int oif)
932{
David S. Miller4c9483b2011-03-12 16:22:43 -0500933 memset(fl6, 0, sizeof(*fl6));
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000934 fl6->saddr = *saddr;
935 fl6->daddr = *daddr;
Ian Morris67ba4152014-08-24 21:53:10 +0100936 fl6->flowi6_proto = IPPROTO_ICMPV6;
David S. Miller1958b852011-03-12 16:36:19 -0500937 fl6->fl6_icmp_type = type;
938 fl6->fl6_icmp_code = 0;
David S. Miller4c9483b2011-03-12 16:22:43 -0500939 fl6->flowi6_oif = oif;
940 security_sk_classify_flow(sk, flowi6_to_flowi(fl6));
YOSHIFUJI Hideaki95e41e92007-12-06 15:43:30 -0800941}
942
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800943static int __net_init icmpv6_sk_init(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700944{
945 struct sock *sk;
946 int err, i, j;
947
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800948 net->ipv6.icmp_sk =
949 kzalloc(nr_cpu_ids * sizeof(struct sock *), GFP_KERNEL);
Ian Morris63159f22015-03-29 14:00:04 +0100950 if (!net->ipv6.icmp_sk)
Denis V. Lunev79c91152008-02-29 11:17:11 -0800951 return -ENOMEM;
952
KAMEZAWA Hiroyuki6f912042006-04-10 22:52:50 -0700953 for_each_possible_cpu(i) {
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700954 err = inet_ctl_sock_create(&sk, PF_INET6,
955 SOCK_RAW, IPPROTO_ICMPV6, net);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700956 if (err < 0) {
Joe Perchesf3213832012-05-15 14:11:53 +0000957 pr_err("Failed to initialize the ICMP6 control socket (err %d)\n",
Linus Torvalds1da177e2005-04-16 15:20:36 -0700958 err);
959 goto fail;
960 }
961
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700962 net->ipv6.icmp_sk[i] = sk;
Denis V. Lunev5c8cafd2008-02-29 11:19:22 -0800963
Linus Torvalds1da177e2005-04-16 15:20:36 -0700964 /* Enough space for 2 64K ICMP packets, including
965 * sk_buff struct overhead.
966 */
Eric Dumazet87fb4b72011-10-13 07:28:54 +0000967 sk->sk_sndbuf = 2 * SKB_TRUESIZE(64 * 1024);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700968 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700969 return 0;
970
971 fail:
Denis V. Lunev5c8cafd2008-02-29 11:19:22 -0800972 for (j = 0; j < i; j++)
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700973 inet_ctl_sock_destroy(net->ipv6.icmp_sk[j]);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800974 kfree(net->ipv6.icmp_sk);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700975 return err;
976}
977
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800978static void __net_exit icmpv6_sk_exit(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700979{
980 int i;
981
KAMEZAWA Hiroyuki6f912042006-04-10 22:52:50 -0700982 for_each_possible_cpu(i) {
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700983 inet_ctl_sock_destroy(net->ipv6.icmp_sk[i]);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700984 }
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800985 kfree(net->ipv6.icmp_sk);
986}
987
Alexey Dobriyan8ed7edc2008-03-03 12:02:54 -0800988static struct pernet_operations icmpv6_sk_ops = {
Ian Morris67ba4152014-08-24 21:53:10 +0100989 .init = icmpv6_sk_init,
990 .exit = icmpv6_sk_exit,
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800991};
992
993int __init icmpv6_init(void)
994{
995 int err;
996
997 err = register_pernet_subsys(&icmpv6_sk_ops);
998 if (err < 0)
999 return err;
1000
1001 err = -EAGAIN;
1002 if (inet6_add_protocol(&icmpv6_protocol, IPPROTO_ICMPV6) < 0)
1003 goto fail;
Pravin B Shelar5f5624c2013-04-25 11:08:30 +00001004
1005 err = inet6_register_icmp_sender(icmp6_send);
1006 if (err)
1007 goto sender_reg_err;
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001008 return 0;
1009
Pravin B Shelar5f5624c2013-04-25 11:08:30 +00001010sender_reg_err:
1011 inet6_del_protocol(&icmpv6_protocol, IPPROTO_ICMPV6);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001012fail:
Joe Perchesf3213832012-05-15 14:11:53 +00001013 pr_err("Failed to register ICMP6 protocol\n");
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001014 unregister_pernet_subsys(&icmpv6_sk_ops);
1015 return err;
1016}
1017
Alexey Dobriyan8ed7edc2008-03-03 12:02:54 -08001018void icmpv6_cleanup(void)
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001019{
Pravin B Shelar5f5624c2013-04-25 11:08:30 +00001020 inet6_unregister_icmp_sender(icmp6_send);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001021 unregister_pernet_subsys(&icmpv6_sk_ops);
Linus Torvalds1da177e2005-04-16 15:20:36 -07001022 inet6_del_protocol(&icmpv6_protocol, IPPROTO_ICMPV6);
1023}
1024
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001025
Arjan van de Ven9b5b5cf2005-11-29 16:21:38 -08001026static const struct icmp6_err {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001027 int err;
1028 int fatal;
1029} tab_unreach[] = {
1030 { /* NOROUTE */
1031 .err = ENETUNREACH,
1032 .fatal = 0,
1033 },
1034 { /* ADM_PROHIBITED */
1035 .err = EACCES,
1036 .fatal = 1,
1037 },
1038 { /* Was NOT_NEIGHBOUR, now reserved */
1039 .err = EHOSTUNREACH,
1040 .fatal = 0,
1041 },
1042 { /* ADDR_UNREACH */
1043 .err = EHOSTUNREACH,
1044 .fatal = 0,
1045 },
1046 { /* PORT_UNREACH */
1047 .err = ECONNREFUSED,
1048 .fatal = 1,
1049 },
Jiri Bohac61e76b12013-08-30 11:18:45 +02001050 { /* POLICY_FAIL */
1051 .err = EACCES,
1052 .fatal = 1,
1053 },
1054 { /* REJECT_ROUTE */
1055 .err = EACCES,
1056 .fatal = 1,
1057 },
Linus Torvalds1da177e2005-04-16 15:20:36 -07001058};
1059
Brian Haleyd5fdd6b2009-06-23 04:31:07 -07001060int icmpv6_err_convert(u8 type, u8 code, int *err)
Linus Torvalds1da177e2005-04-16 15:20:36 -07001061{
1062 int fatal = 0;
1063
1064 *err = EPROTO;
1065
1066 switch (type) {
1067 case ICMPV6_DEST_UNREACH:
1068 fatal = 1;
Jiri Bohac61e76b12013-08-30 11:18:45 +02001069 if (code < ARRAY_SIZE(tab_unreach)) {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001070 *err = tab_unreach[code].err;
1071 fatal = tab_unreach[code].fatal;
1072 }
1073 break;
1074
1075 case ICMPV6_PKT_TOOBIG:
1076 *err = EMSGSIZE;
1077 break;
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +09001078
Linus Torvalds1da177e2005-04-16 15:20:36 -07001079 case ICMPV6_PARAMPROB:
1080 *err = EPROTO;
1081 fatal = 1;
1082 break;
1083
1084 case ICMPV6_TIME_EXCEED:
1085 *err = EHOSTUNREACH;
1086 break;
Stephen Hemminger3ff50b72007-04-20 17:09:22 -07001087 }
Linus Torvalds1da177e2005-04-16 15:20:36 -07001088
1089 return fatal;
1090}
YOSHIFUJI Hideaki71590392007-02-22 22:05:40 +09001091EXPORT_SYMBOL(icmpv6_err_convert);
1092
Linus Torvalds1da177e2005-04-16 15:20:36 -07001093#ifdef CONFIG_SYSCTL
stephen hemmingere8243532013-12-29 14:03:31 -08001094static struct ctl_table ipv6_icmp_table_template[] = {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001095 {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001096 .procname = "ratelimit",
Daniel Lezcano41a76902008-01-10 03:02:40 -08001097 .data = &init_net.ipv6.sysctl.icmpv6_time,
Linus Torvalds1da177e2005-04-16 15:20:36 -07001098 .maxlen = sizeof(int),
1099 .mode = 0644,
Alexey Dobriyan6d9f2392008-11-03 18:21:05 -08001100 .proc_handler = proc_dointvec_ms_jiffies,
Linus Torvalds1da177e2005-04-16 15:20:36 -07001101 },
Eric W. Biedermanf8572d82009-11-05 13:32:03 -08001102 { },
Linus Torvalds1da177e2005-04-16 15:20:36 -07001103};
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001104
Alexey Dobriyan2c8c1e72010-01-17 03:35:32 +00001105struct ctl_table * __net_init ipv6_icmp_sysctl_init(struct net *net)
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001106{
1107 struct ctl_table *table;
1108
1109 table = kmemdup(ipv6_icmp_table_template,
1110 sizeof(ipv6_icmp_table_template),
1111 GFP_KERNEL);
YOSHIFUJI Hideaki5ee09102008-02-28 00:24:28 +09001112
Eric W. Biedermanc027aab2012-11-16 03:03:10 +00001113 if (table)
YOSHIFUJI Hideaki5ee09102008-02-28 00:24:28 +09001114 table[0].data = &net->ipv6.sysctl.icmpv6_time;
1115
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001116 return table;
1117}
Linus Torvalds1da177e2005-04-16 15:20:36 -07001118#endif