1 /*
2  *	RAW sockets for IPv6
3  *	Linux INET6 implementation
4  *
5  *	Authors:
6  *	Pedro Roque		<roque@di.fc.ul.pt>
7  *
8  *	Adapted from linux/net/ipv4/raw.c
9  *
10  *	Fixes:
11  *	Hideaki YOSHIFUJI	:	sin6_scope_id support
12  *	YOSHIFUJI,H.@USAGI	:	raw checksum (RFC2292(bis) compliance)
13  *	Kazunori MIYAZAWA @USAGI:	change process style to use ip6_append_data
14  *
15  *	This program is free software; you can redistribute it and/or
16  *      modify it under the terms of the GNU General Public License
17  *      as published by the Free Software Foundation; either version
18  *      2 of the License, or (at your option) any later version.
19  */
20 
21 #include <linux/errno.h>
22 #include <linux/types.h>
23 #include <linux/socket.h>
24 #include <linux/slab.h>
25 #include <linux/sockios.h>
26 #include <linux/net.h>
27 #include <linux/in6.h>
28 #include <linux/netdevice.h>
29 #include <linux/if_arp.h>
30 #include <linux/icmpv6.h>
31 #include <linux/netfilter.h>
32 #include <linux/netfilter_ipv6.h>
33 #include <linux/skbuff.h>
34 #include <linux/compat.h>
35 #include <asm/uaccess.h>
36 #include <asm/ioctls.h>
37 
38 #include <net/net_namespace.h>
39 #include <net/ip.h>
40 #include <net/sock.h>
41 #include <net/snmp.h>
42 
43 #include <net/ipv6.h>
44 #include <net/ndisc.h>
45 #include <net/protocol.h>
46 #include <net/ip6_route.h>
47 #include <net/ip6_checksum.h>
48 #include <net/addrconf.h>
49 #include <net/transp_v6.h>
50 #include <net/udp.h>
51 #include <net/inet_common.h>
52 #include <net/tcp_states.h>
53 #if defined(CONFIG_IPV6_MIP6) || defined(CONFIG_IPV6_MIP6_MODULE)
54 #include <net/mip6.h>
55 #endif
56 #include <linux/mroute6.h>
57 
58 #include <net/raw.h>
59 #include <net/rawv6.h>
60 #include <net/xfrm.h>
61 
62 #include <linux/proc_fs.h>
63 #include <linux/seq_file.h>
64 #include <linux/export.h>
65 
66 static struct raw_hashinfo raw_v6_hashinfo = {
67 	.lock = __RW_LOCK_UNLOCKED(raw_v6_hashinfo.lock),
68 };
69 
__raw_v6_lookup(struct net * net,struct sock * sk,unsigned short num,const struct in6_addr * loc_addr,const struct in6_addr * rmt_addr,int dif)70 static struct sock *__raw_v6_lookup(struct net *net, struct sock *sk,
71 		unsigned short num, const struct in6_addr *loc_addr,
72 		const struct in6_addr *rmt_addr, int dif)
73 {
74 	struct hlist_node *node;
75 	int is_multicast = ipv6_addr_is_multicast(loc_addr);
76 
77 	sk_for_each_from(sk, node)
78 		if (inet_sk(sk)->inet_num == num) {
79 			struct ipv6_pinfo *np = inet6_sk(sk);
80 
81 			if (!net_eq(sock_net(sk), net))
82 				continue;
83 
84 			if (!ipv6_addr_any(&np->daddr) &&
85 			    !ipv6_addr_equal(&np->daddr, rmt_addr))
86 				continue;
87 
88 			if (sk->sk_bound_dev_if && sk->sk_bound_dev_if != dif)
89 				continue;
90 
91 			if (!ipv6_addr_any(&np->rcv_saddr)) {
92 				if (ipv6_addr_equal(&np->rcv_saddr, loc_addr))
93 					goto found;
94 				if (is_multicast &&
95 				    inet6_mc_check(sk, loc_addr, rmt_addr))
96 					goto found;
97 				continue;
98 			}
99 			goto found;
100 		}
101 	sk = NULL;
102 found:
103 	return sk;
104 }
105 
106 /*
107  *	0 - deliver
108  *	1 - block
109  */
icmpv6_filter(const struct sock * sk,const struct sk_buff * skb)110 static int icmpv6_filter(const struct sock *sk, const struct sk_buff *skb)
111 {
112 	struct icmp6hdr *_hdr;
113 	const struct icmp6hdr *hdr;
114 
115 	hdr = skb_header_pointer(skb, skb_transport_offset(skb),
116 				 sizeof(_hdr), &_hdr);
117 	if (hdr) {
118 		const __u32 *data = &raw6_sk(sk)->filter.data[0];
119 		unsigned int type = hdr->icmp6_type;
120 
121 		return (data[type >> 5] & (1U << (type & 31))) != 0;
122 	}
123 	return 1;
124 }
125 
126 #if defined(CONFIG_IPV6_MIP6) || defined(CONFIG_IPV6_MIP6_MODULE)
127 typedef int mh_filter_t(struct sock *sock, struct sk_buff *skb);
128 
129 static mh_filter_t __rcu *mh_filter __read_mostly;
130 
rawv6_mh_filter_register(mh_filter_t filter)131 int rawv6_mh_filter_register(mh_filter_t filter)
132 {
133 	rcu_assign_pointer(mh_filter, filter);
134 	return 0;
135 }
136 EXPORT_SYMBOL(rawv6_mh_filter_register);
137 
rawv6_mh_filter_unregister(mh_filter_t filter)138 int rawv6_mh_filter_unregister(mh_filter_t filter)
139 {
140 	RCU_INIT_POINTER(mh_filter, NULL);
141 	synchronize_rcu();
142 	return 0;
143 }
144 EXPORT_SYMBOL(rawv6_mh_filter_unregister);
145 
146 #endif
147 
148 /*
149  *	demultiplex raw sockets.
150  *	(should consider queueing the skb in the sock receive_queue
151  *	without calling rawv6.c)
152  *
153  *	Caller owns SKB so we must make clones.
154  */
ipv6_raw_deliver(struct sk_buff * skb,int nexthdr)155 static int ipv6_raw_deliver(struct sk_buff *skb, int nexthdr)
156 {
157 	const struct in6_addr *saddr;
158 	const struct in6_addr *daddr;
159 	struct sock *sk;
160 	int delivered = 0;
161 	__u8 hash;
162 	struct net *net;
163 
164 	saddr = &ipv6_hdr(skb)->saddr;
165 	daddr = saddr + 1;
166 
167 	hash = nexthdr & (MAX_INET_PROTOS - 1);
168 
169 	read_lock(&raw_v6_hashinfo.lock);
170 	sk = sk_head(&raw_v6_hashinfo.ht[hash]);
171 
172 	if (sk == NULL)
173 		goto out;
174 
175 	net = dev_net(skb->dev);
176 	sk = __raw_v6_lookup(net, sk, nexthdr, daddr, saddr, IP6CB(skb)->iif);
177 
178 	while (sk) {
179 		int filtered;
180 
181 		delivered = 1;
182 		switch (nexthdr) {
183 		case IPPROTO_ICMPV6:
184 			filtered = icmpv6_filter(sk, skb);
185 			break;
186 
187 #if defined(CONFIG_IPV6_MIP6) || defined(CONFIG_IPV6_MIP6_MODULE)
188 		case IPPROTO_MH:
189 		{
190 			/* XXX: To validate MH only once for each packet,
191 			 * this is placed here. It should be after checking
192 			 * xfrm policy, however it doesn't. The checking xfrm
193 			 * policy is placed in rawv6_rcv() because it is
194 			 * required for each socket.
195 			 */
196 			mh_filter_t *filter;
197 
198 			filter = rcu_dereference(mh_filter);
199 			filtered = filter ? (*filter)(sk, skb) : 0;
200 			break;
201 		}
202 #endif
203 		default:
204 			filtered = 0;
205 			break;
206 		}
207 
208 		if (filtered < 0)
209 			break;
210 		if (filtered == 0) {
211 			struct sk_buff *clone = skb_clone(skb, GFP_ATOMIC);
212 
213 			/* Not releasing hash table! */
214 			if (clone) {
215 				nf_reset(clone);
216 				rawv6_rcv(sk, clone);
217 			}
218 		}
219 		sk = __raw_v6_lookup(net, sk_next(sk), nexthdr, daddr, saddr,
220 				     IP6CB(skb)->iif);
221 	}
222 out:
223 	read_unlock(&raw_v6_hashinfo.lock);
224 	return delivered;
225 }
226 
raw6_local_deliver(struct sk_buff * skb,int nexthdr)227 int raw6_local_deliver(struct sk_buff *skb, int nexthdr)
228 {
229 	struct sock *raw_sk;
230 
231 	raw_sk = sk_head(&raw_v6_hashinfo.ht[nexthdr & (MAX_INET_PROTOS - 1)]);
232 	if (raw_sk && !ipv6_raw_deliver(skb, nexthdr))
233 		raw_sk = NULL;
234 
235 	return raw_sk != NULL;
236 }
237 
238 /* This cleans up af_inet6 a bit. -DaveM */
rawv6_bind(struct sock * sk,struct sockaddr * uaddr,int addr_len)239 static int rawv6_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len)
240 {
241 	struct inet_sock *inet = inet_sk(sk);
242 	struct ipv6_pinfo *np = inet6_sk(sk);
243 	struct sockaddr_in6 *addr = (struct sockaddr_in6 *) uaddr;
244 	__be32 v4addr = 0;
245 	int addr_type;
246 	int err;
247 
248 	if (addr_len < SIN6_LEN_RFC2133)
249 		return -EINVAL;
250 	addr_type = ipv6_addr_type(&addr->sin6_addr);
251 
252 	/* Raw sockets are IPv6 only */
253 	if (addr_type == IPV6_ADDR_MAPPED)
254 		return -EADDRNOTAVAIL;
255 
256 	lock_sock(sk);
257 
258 	err = -EINVAL;
259 	if (sk->sk_state != TCP_CLOSE)
260 		goto out;
261 
262 	rcu_read_lock();
263 	/* Check if the address belongs to the host. */
264 	if (addr_type != IPV6_ADDR_ANY) {
265 		struct net_device *dev = NULL;
266 
267 		if (addr_type & IPV6_ADDR_LINKLOCAL) {
268 			if (addr_len >= sizeof(struct sockaddr_in6) &&
269 			    addr->sin6_scope_id) {
270 				/* Override any existing binding, if another
271 				 * one is supplied by user.
272 				 */
273 				sk->sk_bound_dev_if = addr->sin6_scope_id;
274 			}
275 
276 			/* Binding to link-local address requires an interface */
277 			if (!sk->sk_bound_dev_if)
278 				goto out_unlock;
279 
280 			err = -ENODEV;
281 			dev = dev_get_by_index_rcu(sock_net(sk),
282 						   sk->sk_bound_dev_if);
283 			if (!dev)
284 				goto out_unlock;
285 		}
286 
287 		/* ipv4 addr of the socket is invalid.  Only the
288 		 * unspecified and mapped address have a v4 equivalent.
289 		 */
290 		v4addr = LOOPBACK4_IPV6;
291 		if (!(addr_type & IPV6_ADDR_MULTICAST))	{
292 			err = -EADDRNOTAVAIL;
293 			if (!ipv6_chk_addr(sock_net(sk), &addr->sin6_addr,
294 					   dev, 0)) {
295 				goto out_unlock;
296 			}
297 		}
298 	}
299 
300 	inet->inet_rcv_saddr = inet->inet_saddr = v4addr;
301 	np->rcv_saddr = addr->sin6_addr;
302 	if (!(addr_type & IPV6_ADDR_MULTICAST))
303 		np->saddr = addr->sin6_addr;
304 	err = 0;
305 out_unlock:
306 	rcu_read_unlock();
307 out:
308 	release_sock(sk);
309 	return err;
310 }
311 
rawv6_err(struct sock * sk,struct sk_buff * skb,struct inet6_skb_parm * opt,u8 type,u8 code,int offset,__be32 info)312 static void rawv6_err(struct sock *sk, struct sk_buff *skb,
313 	       struct inet6_skb_parm *opt,
314 	       u8 type, u8 code, int offset, __be32 info)
315 {
316 	struct inet_sock *inet = inet_sk(sk);
317 	struct ipv6_pinfo *np = inet6_sk(sk);
318 	int err;
319 	int harderr;
320 
321 	/* Report error on raw socket, if:
322 	   1. User requested recverr.
323 	   2. Socket is connected (otherwise the error indication
324 	      is useless without recverr and error is hard.
325 	 */
326 	if (!np->recverr && sk->sk_state != TCP_ESTABLISHED)
327 		return;
328 
329 	harderr = icmpv6_err_convert(type, code, &err);
330 	if (type == ICMPV6_PKT_TOOBIG)
331 		harderr = (np->pmtudisc == IPV6_PMTUDISC_DO);
332 
333 	if (np->recverr) {
334 		u8 *payload = skb->data;
335 		if (!inet->hdrincl)
336 			payload += offset;
337 		ipv6_icmp_error(sk, skb, err, 0, ntohl(info), payload);
338 	}
339 
340 	if (np->recverr || harderr) {
341 		sk->sk_err = err;
342 		sk->sk_error_report(sk);
343 	}
344 }
345 
raw6_icmp_error(struct sk_buff * skb,int nexthdr,u8 type,u8 code,int inner_offset,__be32 info)346 void raw6_icmp_error(struct sk_buff *skb, int nexthdr,
347 		u8 type, u8 code, int inner_offset, __be32 info)
348 {
349 	struct sock *sk;
350 	int hash;
351 	const struct in6_addr *saddr, *daddr;
352 	struct net *net;
353 
354 	hash = nexthdr & (RAW_HTABLE_SIZE - 1);
355 
356 	read_lock(&raw_v6_hashinfo.lock);
357 	sk = sk_head(&raw_v6_hashinfo.ht[hash]);
358 	if (sk != NULL) {
359 		/* Note: ipv6_hdr(skb) != skb->data */
360 		const struct ipv6hdr *ip6h = (const struct ipv6hdr *)skb->data;
361 		saddr = &ip6h->saddr;
362 		daddr = &ip6h->daddr;
363 		net = dev_net(skb->dev);
364 
365 		while ((sk = __raw_v6_lookup(net, sk, nexthdr, saddr, daddr,
366 						IP6CB(skb)->iif))) {
367 			rawv6_err(sk, skb, NULL, type, code,
368 					inner_offset, info);
369 			sk = sk_next(sk);
370 		}
371 	}
372 	read_unlock(&raw_v6_hashinfo.lock);
373 }
374 
rawv6_rcv_skb(struct sock * sk,struct sk_buff * skb)375 static inline int rawv6_rcv_skb(struct sock *sk, struct sk_buff *skb)
376 {
377 	if ((raw6_sk(sk)->checksum || rcu_access_pointer(sk->sk_filter)) &&
378 	    skb_checksum_complete(skb)) {
379 		atomic_inc(&sk->sk_drops);
380 		kfree_skb(skb);
381 		return NET_RX_DROP;
382 	}
383 
384 	/* Charge it to the socket. */
385 	skb_dst_drop(skb);
386 	if (sock_queue_rcv_skb(sk, skb) < 0) {
387 		kfree_skb(skb);
388 		return NET_RX_DROP;
389 	}
390 
391 	return 0;
392 }
393 
394 /*
395  *	This is next to useless...
396  *	if we demultiplex in network layer we don't need the extra call
397  *	just to queue the skb...
398  *	maybe we could have the network decide upon a hint if it
399  *	should call raw_rcv for demultiplexing
400  */
rawv6_rcv(struct sock * sk,struct sk_buff * skb)401 int rawv6_rcv(struct sock *sk, struct sk_buff *skb)
402 {
403 	struct inet_sock *inet = inet_sk(sk);
404 	struct raw6_sock *rp = raw6_sk(sk);
405 
406 	if (!xfrm6_policy_check(sk, XFRM_POLICY_IN, skb)) {
407 		atomic_inc(&sk->sk_drops);
408 		kfree_skb(skb);
409 		return NET_RX_DROP;
410 	}
411 
412 	if (!rp->checksum)
413 		skb->ip_summed = CHECKSUM_UNNECESSARY;
414 
415 	if (skb->ip_summed == CHECKSUM_COMPLETE) {
416 		skb_postpull_rcsum(skb, skb_network_header(skb),
417 				   skb_network_header_len(skb));
418 		if (!csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
419 				     &ipv6_hdr(skb)->daddr,
420 				     skb->len, inet->inet_num, skb->csum))
421 			skb->ip_summed = CHECKSUM_UNNECESSARY;
422 	}
423 	if (!skb_csum_unnecessary(skb))
424 		skb->csum = ~csum_unfold(csum_ipv6_magic(&ipv6_hdr(skb)->saddr,
425 							 &ipv6_hdr(skb)->daddr,
426 							 skb->len,
427 							 inet->inet_num, 0));
428 
429 	if (inet->hdrincl) {
430 		if (skb_checksum_complete(skb)) {
431 			atomic_inc(&sk->sk_drops);
432 			kfree_skb(skb);
433 			return NET_RX_DROP;
434 		}
435 	}
436 
437 	rawv6_rcv_skb(sk, skb);
438 	return 0;
439 }
440 
441 
442 /*
443  *	This should be easy, if there is something there
444  *	we return it, otherwise we block.
445  */
446 
rawv6_recvmsg(struct kiocb * iocb,struct sock * sk,struct msghdr * msg,size_t len,int noblock,int flags,int * addr_len)447 static int rawv6_recvmsg(struct kiocb *iocb, struct sock *sk,
448 		  struct msghdr *msg, size_t len,
449 		  int noblock, int flags, int *addr_len)
450 {
451 	struct ipv6_pinfo *np = inet6_sk(sk);
452 	struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)msg->msg_name;
453 	struct sk_buff *skb;
454 	size_t copied;
455 	int err;
456 
457 	if (flags & MSG_OOB)
458 		return -EOPNOTSUPP;
459 
460 	if (flags & MSG_ERRQUEUE)
461 		return ipv6_recv_error(sk, msg, len, addr_len);
462 
463 	if (np->rxpmtu && np->rxopt.bits.rxpmtu)
464 		return ipv6_recv_rxpmtu(sk, msg, len, addr_len);
465 
466 	skb = skb_recv_datagram(sk, flags, noblock, &err);
467 	if (!skb)
468 		goto out;
469 
470 	copied = skb->len;
471 	if (copied > len) {
472 		copied = len;
473 		msg->msg_flags |= MSG_TRUNC;
474 	}
475 
476 	if (skb_csum_unnecessary(skb)) {
477 		err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
478 	} else if (msg->msg_flags&MSG_TRUNC) {
479 		if (__skb_checksum_complete(skb))
480 			goto csum_copy_err;
481 		err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
482 	} else {
483 		err = skb_copy_and_csum_datagram_iovec(skb, 0, msg->msg_iov);
484 		if (err == -EINVAL)
485 			goto csum_copy_err;
486 	}
487 	if (err)
488 		goto out_free;
489 
490 	/* Copy the address. */
491 	if (sin6) {
492 		sin6->sin6_family = AF_INET6;
493 		sin6->sin6_port = 0;
494 		sin6->sin6_addr = ipv6_hdr(skb)->saddr;
495 		sin6->sin6_flowinfo = 0;
496 		sin6->sin6_scope_id = 0;
497 		if (ipv6_addr_type(&sin6->sin6_addr) & IPV6_ADDR_LINKLOCAL)
498 			sin6->sin6_scope_id = IP6CB(skb)->iif;
499 		*addr_len = sizeof(*sin6);
500 	}
501 
502 	sock_recv_ts_and_drops(msg, sk, skb);
503 
504 	if (np->rxopt.all)
505 		datagram_recv_ctl(sk, msg, skb);
506 
507 	err = copied;
508 	if (flags & MSG_TRUNC)
509 		err = skb->len;
510 
511 out_free:
512 	skb_free_datagram(sk, skb);
513 out:
514 	return err;
515 
516 csum_copy_err:
517 	skb_kill_datagram(sk, skb, flags);
518 
519 	/* Error for blocking case is chosen to masquerade
520 	   as some normal condition.
521 	 */
522 	err = (flags&MSG_DONTWAIT) ? -EAGAIN : -EHOSTUNREACH;
523 	goto out;
524 }
525 
rawv6_push_pending_frames(struct sock * sk,struct flowi6 * fl6,struct raw6_sock * rp)526 static int rawv6_push_pending_frames(struct sock *sk, struct flowi6 *fl6,
527 				     struct raw6_sock *rp)
528 {
529 	struct sk_buff *skb;
530 	int err = 0;
531 	int offset;
532 	int len;
533 	int total_len;
534 	__wsum tmp_csum;
535 	__sum16 csum;
536 
537 	if (!rp->checksum)
538 		goto send;
539 
540 	if ((skb = skb_peek(&sk->sk_write_queue)) == NULL)
541 		goto out;
542 
543 	offset = rp->offset;
544 	total_len = inet_sk(sk)->cork.base.length;
545 	if (offset >= total_len - 1) {
546 		err = -EINVAL;
547 		ip6_flush_pending_frames(sk);
548 		goto out;
549 	}
550 
551 	/* should be check HW csum miyazawa */
552 	if (skb_queue_len(&sk->sk_write_queue) == 1) {
553 		/*
554 		 * Only one fragment on the socket.
555 		 */
556 		tmp_csum = skb->csum;
557 	} else {
558 		struct sk_buff *csum_skb = NULL;
559 		tmp_csum = 0;
560 
561 		skb_queue_walk(&sk->sk_write_queue, skb) {
562 			tmp_csum = csum_add(tmp_csum, skb->csum);
563 
564 			if (csum_skb)
565 				continue;
566 
567 			len = skb->len - skb_transport_offset(skb);
568 			if (offset >= len) {
569 				offset -= len;
570 				continue;
571 			}
572 
573 			csum_skb = skb;
574 		}
575 
576 		skb = csum_skb;
577 	}
578 
579 	offset += skb_transport_offset(skb);
580 	if (skb_copy_bits(skb, offset, &csum, 2))
581 		BUG();
582 
583 	/* in case cksum was not initialized */
584 	if (unlikely(csum))
585 		tmp_csum = csum_sub(tmp_csum, csum_unfold(csum));
586 
587 	csum = csum_ipv6_magic(&fl6->saddr, &fl6->daddr,
588 			       total_len, fl6->flowi6_proto, tmp_csum);
589 
590 	if (csum == 0 && fl6->flowi6_proto == IPPROTO_UDP)
591 		csum = CSUM_MANGLED_0;
592 
593 	if (skb_store_bits(skb, offset, &csum, 2))
594 		BUG();
595 
596 send:
597 	err = ip6_push_pending_frames(sk);
598 out:
599 	return err;
600 }
601 
rawv6_send_hdrinc(struct sock * sk,void * from,int length,struct flowi6 * fl6,struct dst_entry ** dstp,unsigned int flags)602 static int rawv6_send_hdrinc(struct sock *sk, void *from, int length,
603 			struct flowi6 *fl6, struct dst_entry **dstp,
604 			unsigned int flags)
605 {
606 	struct ipv6_pinfo *np = inet6_sk(sk);
607 	struct ipv6hdr *iph;
608 	struct sk_buff *skb;
609 	int err;
610 	struct rt6_info *rt = (struct rt6_info *)*dstp;
611 	int hlen = LL_RESERVED_SPACE(rt->dst.dev);
612 	int tlen = rt->dst.dev->needed_tailroom;
613 
614 	if (length > rt->dst.dev->mtu) {
615 		ipv6_local_error(sk, EMSGSIZE, fl6, rt->dst.dev->mtu);
616 		return -EMSGSIZE;
617 	}
618 	if (flags&MSG_PROBE)
619 		goto out;
620 
621 	skb = sock_alloc_send_skb(sk,
622 				  length + hlen + tlen + 15,
623 				  flags & MSG_DONTWAIT, &err);
624 	if (skb == NULL)
625 		goto error;
626 	skb_reserve(skb, hlen);
627 
628 	skb->priority = sk->sk_priority;
629 	skb->mark = sk->sk_mark;
630 	skb_dst_set(skb, &rt->dst);
631 	*dstp = NULL;
632 
633 	skb_put(skb, length);
634 	skb_reset_network_header(skb);
635 	iph = ipv6_hdr(skb);
636 
637 	skb->ip_summed = CHECKSUM_NONE;
638 
639 	skb->transport_header = skb->network_header;
640 	err = memcpy_fromiovecend((void *)iph, from, 0, length);
641 	if (err)
642 		goto error_fault;
643 
644 	IP6_UPD_PO_STATS(sock_net(sk), rt->rt6i_idev, IPSTATS_MIB_OUT, skb->len);
645 	err = NF_HOOK(NFPROTO_IPV6, NF_INET_LOCAL_OUT, skb, NULL,
646 		      rt->dst.dev, dst_output);
647 	if (err > 0)
648 		err = net_xmit_errno(err);
649 	if (err)
650 		goto error;
651 out:
652 	return 0;
653 
654 error_fault:
655 	err = -EFAULT;
656 	kfree_skb(skb);
657 error:
658 	IP6_INC_STATS(sock_net(sk), rt->rt6i_idev, IPSTATS_MIB_OUTDISCARDS);
659 	if (err == -ENOBUFS && !np->recverr)
660 		err = 0;
661 	return err;
662 }
663 
rawv6_probe_proto_opt(struct flowi6 * fl6,struct msghdr * msg)664 static int rawv6_probe_proto_opt(struct flowi6 *fl6, struct msghdr *msg)
665 {
666 	struct iovec *iov;
667 	u8 __user *type = NULL;
668 	u8 __user *code = NULL;
669 	u8 len = 0;
670 	int probed = 0;
671 	int i;
672 
673 	if (!msg->msg_iov)
674 		return 0;
675 
676 	for (i = 0; i < msg->msg_iovlen; i++) {
677 		iov = &msg->msg_iov[i];
678 		if (!iov)
679 			continue;
680 
681 		switch (fl6->flowi6_proto) {
682 		case IPPROTO_ICMPV6:
683 			/* check if one-byte field is readable or not. */
684 			if (iov->iov_base && iov->iov_len < 1)
685 				break;
686 
687 			if (!type) {
688 				type = iov->iov_base;
689 				/* check if code field is readable or not. */
690 				if (iov->iov_len > 1)
691 					code = type + 1;
692 			} else if (!code)
693 				code = iov->iov_base;
694 
695 			if (type && code) {
696 				if (get_user(fl6->fl6_icmp_type, type) ||
697 				    get_user(fl6->fl6_icmp_code, code))
698 					return -EFAULT;
699 				probed = 1;
700 			}
701 			break;
702 		case IPPROTO_MH:
703 			if (iov->iov_base && iov->iov_len < 1)
704 				break;
705 			/* check if type field is readable or not. */
706 			if (iov->iov_len > 2 - len) {
707 				u8 __user *p = iov->iov_base;
708 				if (get_user(fl6->fl6_mh_type, &p[2 - len]))
709 					return -EFAULT;
710 				probed = 1;
711 			} else
712 				len += iov->iov_len;
713 
714 			break;
715 		default:
716 			probed = 1;
717 			break;
718 		}
719 		if (probed)
720 			break;
721 	}
722 	return 0;
723 }
724 
rawv6_sendmsg(struct kiocb * iocb,struct sock * sk,struct msghdr * msg,size_t len)725 static int rawv6_sendmsg(struct kiocb *iocb, struct sock *sk,
726 		   struct msghdr *msg, size_t len)
727 {
728 	struct ipv6_txoptions opt_space;
729 	struct sockaddr_in6 * sin6 = (struct sockaddr_in6 *) msg->msg_name;
730 	struct in6_addr *daddr, *final_p, final;
731 	struct inet_sock *inet = inet_sk(sk);
732 	struct ipv6_pinfo *np = inet6_sk(sk);
733 	struct raw6_sock *rp = raw6_sk(sk);
734 	struct ipv6_txoptions *opt = NULL;
735 	struct ip6_flowlabel *flowlabel = NULL;
736 	struct dst_entry *dst = NULL;
737 	struct flowi6 fl6;
738 	int addr_len = msg->msg_namelen;
739 	int hlimit = -1;
740 	int tclass = -1;
741 	int dontfrag = -1;
742 	u16 proto;
743 	int err;
744 
745 	/* Rough check on arithmetic overflow,
746 	   better check is made in ip6_append_data().
747 	 */
748 	if (len > INT_MAX)
749 		return -EMSGSIZE;
750 
751 	/* Mirror BSD error message compatibility */
752 	if (msg->msg_flags & MSG_OOB)
753 		return -EOPNOTSUPP;
754 
755 	/*
756 	 *	Get and verify the address.
757 	 */
758 	memset(&fl6, 0, sizeof(fl6));
759 
760 	fl6.flowi6_mark = sk->sk_mark;
761 
762 	if (sin6) {
763 		if (addr_len < SIN6_LEN_RFC2133)
764 			return -EINVAL;
765 
766 		if (sin6->sin6_family && sin6->sin6_family != AF_INET6)
767 			return -EAFNOSUPPORT;
768 
769 		/* port is the proto value [0..255] carried in nexthdr */
770 		proto = ntohs(sin6->sin6_port);
771 
772 		if (!proto)
773 			proto = inet->inet_num;
774 		else if (proto != inet->inet_num)
775 			return -EINVAL;
776 
777 		if (proto > 255)
778 			return -EINVAL;
779 
780 		daddr = &sin6->sin6_addr;
781 		if (np->sndflow) {
782 			fl6.flowlabel = sin6->sin6_flowinfo&IPV6_FLOWINFO_MASK;
783 			if (fl6.flowlabel&IPV6_FLOWLABEL_MASK) {
784 				flowlabel = fl6_sock_lookup(sk, fl6.flowlabel);
785 				if (flowlabel == NULL)
786 					return -EINVAL;
787 				daddr = &flowlabel->dst;
788 			}
789 		}
790 
791 		/*
792 		 * Otherwise it will be difficult to maintain
793 		 * sk->sk_dst_cache.
794 		 */
795 		if (sk->sk_state == TCP_ESTABLISHED &&
796 		    ipv6_addr_equal(daddr, &np->daddr))
797 			daddr = &np->daddr;
798 
799 		if (addr_len >= sizeof(struct sockaddr_in6) &&
800 		    sin6->sin6_scope_id &&
801 		    ipv6_addr_type(daddr)&IPV6_ADDR_LINKLOCAL)
802 			fl6.flowi6_oif = sin6->sin6_scope_id;
803 	} else {
804 		if (sk->sk_state != TCP_ESTABLISHED)
805 			return -EDESTADDRREQ;
806 
807 		proto = inet->inet_num;
808 		daddr = &np->daddr;
809 		fl6.flowlabel = np->flow_label;
810 	}
811 
812 	if (fl6.flowi6_oif == 0)
813 		fl6.flowi6_oif = sk->sk_bound_dev_if;
814 
815 	if (msg->msg_controllen) {
816 		opt = &opt_space;
817 		memset(opt, 0, sizeof(struct ipv6_txoptions));
818 		opt->tot_len = sizeof(struct ipv6_txoptions);
819 
820 		err = datagram_send_ctl(sock_net(sk), sk, msg, &fl6, opt,
821 					&hlimit, &tclass, &dontfrag);
822 		if (err < 0) {
823 			fl6_sock_release(flowlabel);
824 			return err;
825 		}
826 		if ((fl6.flowlabel&IPV6_FLOWLABEL_MASK) && !flowlabel) {
827 			flowlabel = fl6_sock_lookup(sk, fl6.flowlabel);
828 			if (flowlabel == NULL)
829 				return -EINVAL;
830 		}
831 		if (!(opt->opt_nflen|opt->opt_flen))
832 			opt = NULL;
833 	}
834 	if (opt == NULL)
835 		opt = np->opt;
836 	if (flowlabel)
837 		opt = fl6_merge_options(&opt_space, flowlabel, opt);
838 	opt = ipv6_fixup_options(&opt_space, opt);
839 
840 	fl6.flowi6_proto = proto;
841 	err = rawv6_probe_proto_opt(&fl6, msg);
842 	if (err)
843 		goto out;
844 
845 	if (!ipv6_addr_any(daddr))
846 		fl6.daddr = *daddr;
847 	else
848 		fl6.daddr.s6_addr[15] = 0x1; /* :: means loopback (BSD'ism) */
849 	if (ipv6_addr_any(&fl6.saddr) && !ipv6_addr_any(&np->saddr))
850 		fl6.saddr = np->saddr;
851 
852 	final_p = fl6_update_dst(&fl6, opt, &final);
853 
854 	if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
855 		fl6.flowi6_oif = np->mcast_oif;
856 	else if (!fl6.flowi6_oif)
857 		fl6.flowi6_oif = np->ucast_oif;
858 	security_sk_classify_flow(sk, flowi6_to_flowi(&fl6));
859 
860 	dst = ip6_dst_lookup_flow(sk, &fl6, final_p, true);
861 	if (IS_ERR(dst)) {
862 		err = PTR_ERR(dst);
863 		goto out;
864 	}
865 	if (hlimit < 0) {
866 		if (ipv6_addr_is_multicast(&fl6.daddr))
867 			hlimit = np->mcast_hops;
868 		else
869 			hlimit = np->hop_limit;
870 		if (hlimit < 0)
871 			hlimit = ip6_dst_hoplimit(dst);
872 	}
873 
874 	if (tclass < 0)
875 		tclass = np->tclass;
876 
877 	if (dontfrag < 0)
878 		dontfrag = np->dontfrag;
879 
880 	if (msg->msg_flags&MSG_CONFIRM)
881 		goto do_confirm;
882 
883 back_from_confirm:
884 	if (inet->hdrincl)
885 		err = rawv6_send_hdrinc(sk, msg->msg_iov, len, &fl6, &dst, msg->msg_flags);
886 	else {
887 		lock_sock(sk);
888 		err = ip6_append_data(sk, ip_generic_getfrag, msg->msg_iov,
889 			len, 0, hlimit, tclass, opt, &fl6, (struct rt6_info*)dst,
890 			msg->msg_flags, dontfrag);
891 
892 		if (err)
893 			ip6_flush_pending_frames(sk);
894 		else if (!(msg->msg_flags & MSG_MORE))
895 			err = rawv6_push_pending_frames(sk, &fl6, rp);
896 		release_sock(sk);
897 	}
898 done:
899 	dst_release(dst);
900 out:
901 	fl6_sock_release(flowlabel);
902 	return err<0?err:len;
903 do_confirm:
904 	dst_confirm(dst);
905 	if (!(msg->msg_flags & MSG_PROBE) || len)
906 		goto back_from_confirm;
907 	err = 0;
908 	goto done;
909 }
910 
rawv6_seticmpfilter(struct sock * sk,int level,int optname,char __user * optval,int optlen)911 static int rawv6_seticmpfilter(struct sock *sk, int level, int optname,
912 			       char __user *optval, int optlen)
913 {
914 	switch (optname) {
915 	case ICMPV6_FILTER:
916 		if (optlen > sizeof(struct icmp6_filter))
917 			optlen = sizeof(struct icmp6_filter);
918 		if (copy_from_user(&raw6_sk(sk)->filter, optval, optlen))
919 			return -EFAULT;
920 		return 0;
921 	default:
922 		return -ENOPROTOOPT;
923 	}
924 
925 	return 0;
926 }
927 
rawv6_geticmpfilter(struct sock * sk,int level,int optname,char __user * optval,int __user * optlen)928 static int rawv6_geticmpfilter(struct sock *sk, int level, int optname,
929 			       char __user *optval, int __user *optlen)
930 {
931 	int len;
932 
933 	switch (optname) {
934 	case ICMPV6_FILTER:
935 		if (get_user(len, optlen))
936 			return -EFAULT;
937 		if (len < 0)
938 			return -EINVAL;
939 		if (len > sizeof(struct icmp6_filter))
940 			len = sizeof(struct icmp6_filter);
941 		if (put_user(len, optlen))
942 			return -EFAULT;
943 		if (copy_to_user(optval, &raw6_sk(sk)->filter, len))
944 			return -EFAULT;
945 		return 0;
946 	default:
947 		return -ENOPROTOOPT;
948 	}
949 
950 	return 0;
951 }
952 
953 
do_rawv6_setsockopt(struct sock * sk,int level,int optname,char __user * optval,unsigned int optlen)954 static int do_rawv6_setsockopt(struct sock *sk, int level, int optname,
955 			    char __user *optval, unsigned int optlen)
956 {
957 	struct raw6_sock *rp = raw6_sk(sk);
958 	int val;
959 
960 	if (get_user(val, (int __user *)optval))
961 		return -EFAULT;
962 
963 	switch (optname) {
964 	case IPV6_CHECKSUM:
965 		if (inet_sk(sk)->inet_num == IPPROTO_ICMPV6 &&
966 		    level == IPPROTO_IPV6) {
967 			/*
968 			 * RFC3542 tells that IPV6_CHECKSUM socket
969 			 * option in the IPPROTO_IPV6 level is not
970 			 * allowed on ICMPv6 sockets.
971 			 * If you want to set it, use IPPROTO_RAW
972 			 * level IPV6_CHECKSUM socket option
973 			 * (Linux extension).
974 			 */
975 			return -EINVAL;
976 		}
977 
978 		/* You may get strange result with a positive odd offset;
979 		   RFC2292bis agrees with me. */
980 		if (val > 0 && (val&1))
981 			return -EINVAL;
982 		if (val < 0) {
983 			rp->checksum = 0;
984 		} else {
985 			rp->checksum = 1;
986 			rp->offset = val;
987 		}
988 
989 		return 0;
990 
991 	default:
992 		return -ENOPROTOOPT;
993 	}
994 }
995 
rawv6_setsockopt(struct sock * sk,int level,int optname,char __user * optval,unsigned int optlen)996 static int rawv6_setsockopt(struct sock *sk, int level, int optname,
997 			  char __user *optval, unsigned int optlen)
998 {
999 	switch (level) {
1000 	case SOL_RAW:
1001 		break;
1002 
1003 	case SOL_ICMPV6:
1004 		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
1005 			return -EOPNOTSUPP;
1006 		return rawv6_seticmpfilter(sk, level, optname, optval, optlen);
1007 	case SOL_IPV6:
1008 		if (optname == IPV6_CHECKSUM)
1009 			break;
1010 	default:
1011 		return ipv6_setsockopt(sk, level, optname, optval, optlen);
1012 	}
1013 
1014 	return do_rawv6_setsockopt(sk, level, optname, optval, optlen);
1015 }
1016 
1017 #ifdef CONFIG_COMPAT
compat_rawv6_setsockopt(struct sock * sk,int level,int optname,char __user * optval,unsigned int optlen)1018 static int compat_rawv6_setsockopt(struct sock *sk, int level, int optname,
1019 				   char __user *optval, unsigned int optlen)
1020 {
1021 	switch (level) {
1022 	case SOL_RAW:
1023 		break;
1024 	case SOL_ICMPV6:
1025 		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
1026 			return -EOPNOTSUPP;
1027 		return rawv6_seticmpfilter(sk, level, optname, optval, optlen);
1028 	case SOL_IPV6:
1029 		if (optname == IPV6_CHECKSUM)
1030 			break;
1031 	default:
1032 		return compat_ipv6_setsockopt(sk, level, optname,
1033 					      optval, optlen);
1034 	}
1035 	return do_rawv6_setsockopt(sk, level, optname, optval, optlen);
1036 }
1037 #endif
1038 
do_rawv6_getsockopt(struct sock * sk,int level,int optname,char __user * optval,int __user * optlen)1039 static int do_rawv6_getsockopt(struct sock *sk, int level, int optname,
1040 			    char __user *optval, int __user *optlen)
1041 {
1042 	struct raw6_sock *rp = raw6_sk(sk);
1043 	int val, len;
1044 
1045 	if (get_user(len,optlen))
1046 		return -EFAULT;
1047 
1048 	switch (optname) {
1049 	case IPV6_CHECKSUM:
1050 		/*
1051 		 * We allow getsockopt() for IPPROTO_IPV6-level
1052 		 * IPV6_CHECKSUM socket option on ICMPv6 sockets
1053 		 * since RFC3542 is silent about it.
1054 		 */
1055 		if (rp->checksum == 0)
1056 			val = -1;
1057 		else
1058 			val = rp->offset;
1059 		break;
1060 
1061 	default:
1062 		return -ENOPROTOOPT;
1063 	}
1064 
1065 	len = min_t(unsigned int, sizeof(int), len);
1066 
1067 	if (put_user(len, optlen))
1068 		return -EFAULT;
1069 	if (copy_to_user(optval,&val,len))
1070 		return -EFAULT;
1071 	return 0;
1072 }
1073 
rawv6_getsockopt(struct sock * sk,int level,int optname,char __user * optval,int __user * optlen)1074 static int rawv6_getsockopt(struct sock *sk, int level, int optname,
1075 			  char __user *optval, int __user *optlen)
1076 {
1077 	switch (level) {
1078 	case SOL_RAW:
1079 		break;
1080 
1081 	case SOL_ICMPV6:
1082 		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
1083 			return -EOPNOTSUPP;
1084 		return rawv6_geticmpfilter(sk, level, optname, optval, optlen);
1085 	case SOL_IPV6:
1086 		if (optname == IPV6_CHECKSUM)
1087 			break;
1088 	default:
1089 		return ipv6_getsockopt(sk, level, optname, optval, optlen);
1090 	}
1091 
1092 	return do_rawv6_getsockopt(sk, level, optname, optval, optlen);
1093 }
1094 
1095 #ifdef CONFIG_COMPAT
compat_rawv6_getsockopt(struct sock * sk,int level,int optname,char __user * optval,int __user * optlen)1096 static int compat_rawv6_getsockopt(struct sock *sk, int level, int optname,
1097 				   char __user *optval, int __user *optlen)
1098 {
1099 	switch (level) {
1100 	case SOL_RAW:
1101 		break;
1102 	case SOL_ICMPV6:
1103 		if (inet_sk(sk)->inet_num != IPPROTO_ICMPV6)
1104 			return -EOPNOTSUPP;
1105 		return rawv6_geticmpfilter(sk, level, optname, optval, optlen);
1106 	case SOL_IPV6:
1107 		if (optname == IPV6_CHECKSUM)
1108 			break;
1109 	default:
1110 		return compat_ipv6_getsockopt(sk, level, optname,
1111 					      optval, optlen);
1112 	}
1113 	return do_rawv6_getsockopt(sk, level, optname, optval, optlen);
1114 }
1115 #endif
1116 
rawv6_ioctl(struct sock * sk,int cmd,unsigned long arg)1117 static int rawv6_ioctl(struct sock *sk, int cmd, unsigned long arg)
1118 {
1119 	switch (cmd) {
1120 	case SIOCOUTQ: {
1121 		int amount = sk_wmem_alloc_get(sk);
1122 
1123 		return put_user(amount, (int __user *)arg);
1124 	}
1125 	case SIOCINQ: {
1126 		struct sk_buff *skb;
1127 		int amount = 0;
1128 
1129 		spin_lock_bh(&sk->sk_receive_queue.lock);
1130 		skb = skb_peek(&sk->sk_receive_queue);
1131 		if (skb != NULL)
1132 			amount = skb->tail - skb->transport_header;
1133 		spin_unlock_bh(&sk->sk_receive_queue.lock);
1134 		return put_user(amount, (int __user *)arg);
1135 	}
1136 
1137 	default:
1138 #ifdef CONFIG_IPV6_MROUTE
1139 		return ip6mr_ioctl(sk, cmd, (void __user *)arg);
1140 #else
1141 		return -ENOIOCTLCMD;
1142 #endif
1143 	}
1144 }
1145 
1146 #ifdef CONFIG_COMPAT
compat_rawv6_ioctl(struct sock * sk,unsigned int cmd,unsigned long arg)1147 static int compat_rawv6_ioctl(struct sock *sk, unsigned int cmd, unsigned long arg)
1148 {
1149 	switch (cmd) {
1150 	case SIOCOUTQ:
1151 	case SIOCINQ:
1152 		return -ENOIOCTLCMD;
1153 	default:
1154 #ifdef CONFIG_IPV6_MROUTE
1155 		return ip6mr_compat_ioctl(sk, cmd, compat_ptr(arg));
1156 #else
1157 		return -ENOIOCTLCMD;
1158 #endif
1159 	}
1160 }
1161 #endif
1162 
rawv6_close(struct sock * sk,long timeout)1163 static void rawv6_close(struct sock *sk, long timeout)
1164 {
1165 	if (inet_sk(sk)->inet_num == IPPROTO_RAW)
1166 		ip6_ra_control(sk, -1);
1167 	ip6mr_sk_done(sk);
1168 	sk_common_release(sk);
1169 }
1170 
raw6_destroy(struct sock * sk)1171 static void raw6_destroy(struct sock *sk)
1172 {
1173 	lock_sock(sk);
1174 	ip6_flush_pending_frames(sk);
1175 	release_sock(sk);
1176 
1177 	inet6_destroy_sock(sk);
1178 }
1179 
rawv6_init_sk(struct sock * sk)1180 static int rawv6_init_sk(struct sock *sk)
1181 {
1182 	struct raw6_sock *rp = raw6_sk(sk);
1183 
1184 	switch (inet_sk(sk)->inet_num) {
1185 	case IPPROTO_ICMPV6:
1186 		rp->checksum = 1;
1187 		rp->offset   = 2;
1188 		break;
1189 	case IPPROTO_MH:
1190 		rp->checksum = 1;
1191 		rp->offset   = 4;
1192 		break;
1193 	default:
1194 		break;
1195 	}
1196 	return 0;
1197 }
1198 
1199 struct proto rawv6_prot = {
1200 	.name		   = "RAWv6",
1201 	.owner		   = THIS_MODULE,
1202 	.close		   = rawv6_close,
1203 	.destroy	   = raw6_destroy,
1204 	.connect	   = ip6_datagram_connect,
1205 	.disconnect	   = udp_disconnect,
1206 	.ioctl		   = rawv6_ioctl,
1207 	.init		   = rawv6_init_sk,
1208 	.setsockopt	   = rawv6_setsockopt,
1209 	.getsockopt	   = rawv6_getsockopt,
1210 	.sendmsg	   = rawv6_sendmsg,
1211 	.recvmsg	   = rawv6_recvmsg,
1212 	.bind		   = rawv6_bind,
1213 	.backlog_rcv	   = rawv6_rcv_skb,
1214 	.hash		   = raw_hash_sk,
1215 	.unhash		   = raw_unhash_sk,
1216 	.obj_size	   = sizeof(struct raw6_sock),
1217 	.h.raw_hash	   = &raw_v6_hashinfo,
1218 #ifdef CONFIG_COMPAT
1219 	.compat_setsockopt = compat_rawv6_setsockopt,
1220 	.compat_getsockopt = compat_rawv6_getsockopt,
1221 	.compat_ioctl	   = compat_rawv6_ioctl,
1222 #endif
1223 };
1224 
1225 #ifdef CONFIG_PROC_FS
raw6_sock_seq_show(struct seq_file * seq,struct sock * sp,int i)1226 static void raw6_sock_seq_show(struct seq_file *seq, struct sock *sp, int i)
1227 {
1228 	struct ipv6_pinfo *np = inet6_sk(sp);
1229 	const struct in6_addr *dest, *src;
1230 	__u16 destp, srcp;
1231 
1232 	dest  = &np->daddr;
1233 	src   = &np->rcv_saddr;
1234 	destp = 0;
1235 	srcp  = inet_sk(sp)->inet_num;
1236 	seq_printf(seq,
1237 		   "%4d: %08X%08X%08X%08X:%04X %08X%08X%08X%08X:%04X "
1238 		   "%02X %08X:%08X %02X:%08lX %08X %5d %8d %lu %d %pK %d\n",
1239 		   i,
1240 		   src->s6_addr32[0], src->s6_addr32[1],
1241 		   src->s6_addr32[2], src->s6_addr32[3], srcp,
1242 		   dest->s6_addr32[0], dest->s6_addr32[1],
1243 		   dest->s6_addr32[2], dest->s6_addr32[3], destp,
1244 		   sp->sk_state,
1245 		   sk_wmem_alloc_get(sp),
1246 		   sk_rmem_alloc_get(sp),
1247 		   0, 0L, 0,
1248 		   sock_i_uid(sp), 0,
1249 		   sock_i_ino(sp),
1250 		   atomic_read(&sp->sk_refcnt), sp, atomic_read(&sp->sk_drops));
1251 }
1252 
raw6_seq_show(struct seq_file * seq,void * v)1253 static int raw6_seq_show(struct seq_file *seq, void *v)
1254 {
1255 	if (v == SEQ_START_TOKEN)
1256 		seq_printf(seq,
1257 			   "  sl  "
1258 			   "local_address                         "
1259 			   "remote_address                        "
1260 			   "st tx_queue rx_queue tr tm->when retrnsmt"
1261 			   "   uid  timeout inode ref pointer drops\n");
1262 	else
1263 		raw6_sock_seq_show(seq, v, raw_seq_private(seq)->bucket);
1264 	return 0;
1265 }
1266 
1267 static const struct seq_operations raw6_seq_ops = {
1268 	.start =	raw_seq_start,
1269 	.next =		raw_seq_next,
1270 	.stop =		raw_seq_stop,
1271 	.show =		raw6_seq_show,
1272 };
1273 
raw6_seq_open(struct inode * inode,struct file * file)1274 static int raw6_seq_open(struct inode *inode, struct file *file)
1275 {
1276 	return raw_seq_open(inode, file, &raw_v6_hashinfo, &raw6_seq_ops);
1277 }
1278 
1279 static const struct file_operations raw6_seq_fops = {
1280 	.owner =	THIS_MODULE,
1281 	.open =		raw6_seq_open,
1282 	.read =		seq_read,
1283 	.llseek =	seq_lseek,
1284 	.release =	seq_release_net,
1285 };
1286 
raw6_init_net(struct net * net)1287 static int __net_init raw6_init_net(struct net *net)
1288 {
1289 	if (!proc_net_fops_create(net, "raw6", S_IRUGO, &raw6_seq_fops))
1290 		return -ENOMEM;
1291 
1292 	return 0;
1293 }
1294 
raw6_exit_net(struct net * net)1295 static void __net_exit raw6_exit_net(struct net *net)
1296 {
1297 	proc_net_remove(net, "raw6");
1298 }
1299 
1300 static struct pernet_operations raw6_net_ops = {
1301 	.init = raw6_init_net,
1302 	.exit = raw6_exit_net,
1303 };
1304 
raw6_proc_init(void)1305 int __init raw6_proc_init(void)
1306 {
1307 	return register_pernet_subsys(&raw6_net_ops);
1308 }
1309 
raw6_proc_exit(void)1310 void raw6_proc_exit(void)
1311 {
1312 	unregister_pernet_subsys(&raw6_net_ops);
1313 }
1314 #endif	/* CONFIG_PROC_FS */
1315 
1316 /* Same as inet6_dgram_ops, sans udp_poll.  */
1317 static const struct proto_ops inet6_sockraw_ops = {
1318 	.family		   = PF_INET6,
1319 	.owner		   = THIS_MODULE,
1320 	.release	   = inet6_release,
1321 	.bind		   = inet6_bind,
1322 	.connect	   = inet_dgram_connect,	/* ok		*/
1323 	.socketpair	   = sock_no_socketpair,	/* a do nothing	*/
1324 	.accept		   = sock_no_accept,		/* a do nothing	*/
1325 	.getname	   = inet6_getname,
1326 	.poll		   = datagram_poll,		/* ok		*/
1327 	.ioctl		   = inet6_ioctl,		/* must change  */
1328 	.listen		   = sock_no_listen,		/* ok		*/
1329 	.shutdown	   = inet_shutdown,		/* ok		*/
1330 	.setsockopt	   = sock_common_setsockopt,	/* ok		*/
1331 	.getsockopt	   = sock_common_getsockopt,	/* ok		*/
1332 	.sendmsg	   = inet_sendmsg,		/* ok		*/
1333 	.recvmsg	   = sock_common_recvmsg,	/* ok		*/
1334 	.mmap		   = sock_no_mmap,
1335 	.sendpage	   = sock_no_sendpage,
1336 #ifdef CONFIG_COMPAT
1337 	.compat_setsockopt = compat_sock_common_setsockopt,
1338 	.compat_getsockopt = compat_sock_common_getsockopt,
1339 #endif
1340 };
1341 
1342 static struct inet_protosw rawv6_protosw = {
1343 	.type		= SOCK_RAW,
1344 	.protocol	= IPPROTO_IP,	/* wild card */
1345 	.prot		= &rawv6_prot,
1346 	.ops		= &inet6_sockraw_ops,
1347 	.no_check	= UDP_CSUM_DEFAULT,
1348 	.flags		= INET_PROTOSW_REUSE,
1349 };
1350 
rawv6_init(void)1351 int __init rawv6_init(void)
1352 {
1353 	int ret;
1354 
1355 	ret = inet6_register_protosw(&rawv6_protosw);
1356 	if (ret)
1357 		goto out;
1358 out:
1359 	return ret;
1360 }
1361 
rawv6_exit(void)1362 void rawv6_exit(void)
1363 {
1364 	inet6_unregister_protosw(&rawv6_protosw);
1365 }
1366