route.h 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409
  1. /* SPDX-License-Identifier: GPL-2.0-or-later */
  2. /*
  3. * INET An implementation of the TCP/IP protocol suite for the LINUX
  4. * operating system. INET is implemented using the BSD Socket
  5. * interface as the means of communication with the user level.
  6. *
  7. * Definitions for the IP router.
  8. *
  9. * Version: @(#)route.h 1.0.4 05/27/93
  10. *
  11. * Authors: Ross Biro
  12. * Fred N. van Kempen, <waltje@uWalt.NL.Mugnet.ORG>
  13. * Fixes:
  14. * Alan Cox : Reformatted. Added ip_rt_local()
  15. * Alan Cox : Support for TCP parameters.
  16. * Alexey Kuznetsov: Major changes for new routing code.
  17. * Mike McLagan : Routing by source
  18. * Robert Olsson : Added rt_cache statistics
  19. */
  20. #ifndef _ROUTE_H
  21. #define _ROUTE_H
  22. #include <net/dst.h>
  23. #include <net/inetpeer.h>
  24. #include <net/flow.h>
  25. #include <net/inet_sock.h>
  26. #include <net/ip_fib.h>
  27. #include <net/arp.h>
  28. #include <net/ndisc.h>
  29. #include <net/inet_dscp.h>
  30. #include <linux/in_route.h>
  31. #include <linux/rtnetlink.h>
  32. #include <linux/rcupdate.h>
  33. #include <linux/route.h>
  34. #include <linux/ip.h>
  35. #include <linux/cache.h>
  36. #include <linux/security.h>
  37. static inline __u8 ip_sock_rt_scope(const struct sock *sk)
  38. {
  39. if (sock_flag(sk, SOCK_LOCALROUTE))
  40. return RT_SCOPE_LINK;
  41. return RT_SCOPE_UNIVERSE;
  42. }
  43. static inline __u8 ip_sock_rt_tos(const struct sock *sk)
  44. {
  45. return READ_ONCE(inet_sk(sk)->tos) & INET_DSCP_MASK;
  46. }
  47. struct ip_tunnel_info;
  48. struct fib_nh;
  49. struct fib_info;
  50. struct uncached_list;
  51. struct rtable {
  52. struct dst_entry dst;
  53. int rt_genid;
  54. unsigned int rt_flags;
  55. __u16 rt_type;
  56. __u8 rt_is_input;
  57. __u8 rt_uses_gateway;
  58. int rt_iif;
  59. u8 rt_gw_family;
  60. /* Info on neighbour */
  61. union {
  62. __be32 rt_gw4;
  63. struct in6_addr rt_gw6;
  64. };
  65. /* Miscellaneous cached information */
  66. u32 rt_mtu_locked:1,
  67. rt_pmtu:31;
  68. };
  69. #define dst_rtable(_ptr) container_of_const(_ptr, struct rtable, dst)
  70. /**
  71. * skb_rtable - Returns the skb &rtable
  72. * @skb: buffer
  73. */
  74. static inline struct rtable *skb_rtable(const struct sk_buff *skb)
  75. {
  76. return dst_rtable(skb_dst(skb));
  77. }
  78. static inline bool rt_is_input_route(const struct rtable *rt)
  79. {
  80. return rt->rt_is_input != 0;
  81. }
  82. static inline bool rt_is_output_route(const struct rtable *rt)
  83. {
  84. return rt->rt_is_input == 0;
  85. }
  86. static inline __be32 rt_nexthop(const struct rtable *rt, __be32 daddr)
  87. {
  88. if (rt->rt_gw_family == AF_INET)
  89. return rt->rt_gw4;
  90. return daddr;
  91. }
  92. struct ip_rt_acct {
  93. __u32 o_bytes;
  94. __u32 o_packets;
  95. __u32 i_bytes;
  96. __u32 i_packets;
  97. };
  98. struct rt_cache_stat {
  99. unsigned int in_slow_tot;
  100. unsigned int in_slow_mc;
  101. unsigned int in_no_route;
  102. unsigned int in_brd;
  103. unsigned int in_martian_dst;
  104. unsigned int in_martian_src;
  105. unsigned int out_slow_tot;
  106. unsigned int out_slow_mc;
  107. };
  108. extern struct ip_rt_acct __percpu *ip_rt_acct;
  109. struct in_device;
  110. int ip_rt_init(void);
  111. void rt_cache_flush(struct net *net);
  112. void rt_flush_dev(struct net_device *dev);
  113. struct rtable *ip_route_output_key_hash(struct net *net, struct flowi4 *flp,
  114. const struct sk_buff *skb);
  115. struct rtable *ip_route_output_key_hash_rcu(struct net *net, struct flowi4 *flp,
  116. struct fib_result *res,
  117. const struct sk_buff *skb);
  118. static inline struct rtable *__ip_route_output_key(struct net *net,
  119. struct flowi4 *flp)
  120. {
  121. return ip_route_output_key_hash(net, flp, NULL);
  122. }
  123. struct rtable *ip_route_output_flow(struct net *, struct flowi4 *flp,
  124. const struct sock *sk);
  125. struct dst_entry *ipv4_blackhole_route(struct net *net,
  126. struct dst_entry *dst_orig);
  127. static inline struct rtable *ip_route_output_key(struct net *net, struct flowi4 *flp)
  128. {
  129. return ip_route_output_flow(net, flp, NULL);
  130. }
  131. /* Simplistic IPv4 route lookup function.
  132. * This is only suitable for some particular use cases: since the flowi4
  133. * structure is only partially set, it may bypass some fib-rules.
  134. */
  135. static inline struct rtable *ip_route_output(struct net *net, __be32 daddr,
  136. __be32 saddr, u8 tos, int oif,
  137. __u8 scope)
  138. {
  139. struct flowi4 fl4 = {
  140. .flowi4_oif = oif,
  141. .flowi4_tos = tos,
  142. .flowi4_scope = scope,
  143. .daddr = daddr,
  144. .saddr = saddr,
  145. };
  146. return ip_route_output_key(net, &fl4);
  147. }
  148. static inline struct rtable *ip_route_output_ports(struct net *net, struct flowi4 *fl4,
  149. const struct sock *sk,
  150. __be32 daddr, __be32 saddr,
  151. __be16 dport, __be16 sport,
  152. __u8 proto, __u8 tos, int oif)
  153. {
  154. flowi4_init_output(fl4, oif, sk ? READ_ONCE(sk->sk_mark) : 0, tos,
  155. sk ? ip_sock_rt_scope(sk) : RT_SCOPE_UNIVERSE,
  156. proto, sk ? inet_sk_flowi_flags(sk) : 0,
  157. daddr, saddr, dport, sport, sock_net_uid(net, sk));
  158. if (sk)
  159. security_sk_classify_flow(sk, flowi4_to_flowi_common(fl4));
  160. return ip_route_output_flow(net, fl4, sk);
  161. }
  162. static inline struct rtable *ip_route_output_gre(struct net *net, struct flowi4 *fl4,
  163. __be32 daddr, __be32 saddr,
  164. __be32 gre_key, __u8 tos, int oif)
  165. {
  166. memset(fl4, 0, sizeof(*fl4));
  167. fl4->flowi4_oif = oif;
  168. fl4->daddr = daddr;
  169. fl4->saddr = saddr;
  170. fl4->flowi4_tos = tos;
  171. fl4->flowi4_proto = IPPROTO_GRE;
  172. fl4->fl4_gre_key = gre_key;
  173. return ip_route_output_key(net, fl4);
  174. }
  175. int ip_mc_validate_source(struct sk_buff *skb, __be32 daddr, __be32 saddr,
  176. u8 tos, struct net_device *dev,
  177. struct in_device *in_dev, u32 *itag);
  178. int ip_route_input_noref(struct sk_buff *skb, __be32 dst, __be32 src,
  179. u8 tos, struct net_device *devin);
  180. int ip_route_use_hint(struct sk_buff *skb, __be32 dst, __be32 src,
  181. u8 tos, struct net_device *devin,
  182. const struct sk_buff *hint);
  183. static inline int ip_route_input(struct sk_buff *skb, __be32 dst, __be32 src,
  184. dscp_t dscp, struct net_device *devin)
  185. {
  186. int err;
  187. rcu_read_lock();
  188. err = ip_route_input_noref(skb, dst, src, inet_dscp_to_dsfield(dscp),
  189. devin);
  190. if (!err) {
  191. skb_dst_force(skb);
  192. if (!skb_dst(skb))
  193. err = -EINVAL;
  194. }
  195. rcu_read_unlock();
  196. return err;
  197. }
  198. void ipv4_update_pmtu(struct sk_buff *skb, struct net *net, u32 mtu, int oif,
  199. u8 protocol);
  200. void ipv4_sk_update_pmtu(struct sk_buff *skb, struct sock *sk, u32 mtu);
  201. void ipv4_redirect(struct sk_buff *skb, struct net *net, int oif, u8 protocol);
  202. void ipv4_sk_redirect(struct sk_buff *skb, struct sock *sk);
  203. void ip_rt_send_redirect(struct sk_buff *skb);
  204. unsigned int inet_addr_type(struct net *net, __be32 addr);
  205. unsigned int inet_addr_type_table(struct net *net, __be32 addr, u32 tb_id);
  206. unsigned int inet_dev_addr_type(struct net *net, const struct net_device *dev,
  207. __be32 addr);
  208. unsigned int inet_addr_type_dev_table(struct net *net,
  209. const struct net_device *dev,
  210. __be32 addr);
  211. void ip_rt_multicast_event(struct in_device *);
  212. int ip_rt_ioctl(struct net *, unsigned int cmd, struct rtentry *rt);
  213. void ip_rt_get_source(u8 *src, struct sk_buff *skb, struct rtable *rt);
  214. struct rtable *rt_dst_alloc(struct net_device *dev,
  215. unsigned int flags, u16 type, bool noxfrm);
  216. struct rtable *rt_dst_clone(struct net_device *dev, struct rtable *rt);
  217. struct in_ifaddr;
  218. void fib_add_ifaddr(struct in_ifaddr *);
  219. void fib_del_ifaddr(struct in_ifaddr *, struct in_ifaddr *);
  220. void fib_modify_prefix_metric(struct in_ifaddr *ifa, u32 new_metric);
  221. void rt_add_uncached_list(struct rtable *rt);
  222. void rt_del_uncached_list(struct rtable *rt);
  223. int fib_dump_info_fnhe(struct sk_buff *skb, struct netlink_callback *cb,
  224. u32 table_id, struct fib_info *fi,
  225. int *fa_index, int fa_start, unsigned int flags);
  226. static inline void ip_rt_put(struct rtable *rt)
  227. {
  228. /* dst_release() accepts a NULL parameter.
  229. * We rely on dst being first structure in struct rtable
  230. */
  231. BUILD_BUG_ON(offsetof(struct rtable, dst) != 0);
  232. dst_release(&rt->dst);
  233. }
  234. extern const __u8 ip_tos2prio[16];
  235. static inline char rt_tos2priority(u8 tos)
  236. {
  237. return ip_tos2prio[IPTOS_TOS(tos)>>1];
  238. }
  239. /* ip_route_connect() and ip_route_newports() work in tandem whilst
  240. * binding a socket for a new outgoing connection.
  241. *
  242. * In order to use IPSEC properly, we must, in the end, have a
  243. * route that was looked up using all available keys including source
  244. * and destination ports.
  245. *
  246. * However, if a source port needs to be allocated (the user specified
  247. * a wildcard source port) we need to obtain addressing information
  248. * in order to perform that allocation.
  249. *
  250. * So ip_route_connect() looks up a route using wildcarded source and
  251. * destination ports in the key, simply so that we can get a pair of
  252. * addresses to use for port allocation.
  253. *
  254. * Later, once the ports are allocated, ip_route_newports() will make
  255. * another route lookup if needed to make sure we catch any IPSEC
  256. * rules keyed on the port information.
  257. *
  258. * The callers allocate the flow key on their stack, and must pass in
  259. * the same flowi4 object to both the ip_route_connect() and the
  260. * ip_route_newports() calls.
  261. */
  262. static inline void ip_route_connect_init(struct flowi4 *fl4, __be32 dst,
  263. __be32 src, int oif, u8 protocol,
  264. __be16 sport, __be16 dport,
  265. const struct sock *sk)
  266. {
  267. __u8 flow_flags = 0;
  268. if (inet_test_bit(TRANSPARENT, sk))
  269. flow_flags |= FLOWI_FLAG_ANYSRC;
  270. flowi4_init_output(fl4, oif, READ_ONCE(sk->sk_mark), ip_sock_rt_tos(sk),
  271. ip_sock_rt_scope(sk), protocol, flow_flags, dst,
  272. src, dport, sport, sk->sk_uid);
  273. }
  274. static inline struct rtable *ip_route_connect(struct flowi4 *fl4, __be32 dst,
  275. __be32 src, int oif, u8 protocol,
  276. __be16 sport, __be16 dport,
  277. const struct sock *sk)
  278. {
  279. struct net *net = sock_net(sk);
  280. struct rtable *rt;
  281. ip_route_connect_init(fl4, dst, src, oif, protocol, sport, dport, sk);
  282. if (!dst || !src) {
  283. rt = __ip_route_output_key(net, fl4);
  284. if (IS_ERR(rt))
  285. return rt;
  286. ip_rt_put(rt);
  287. flowi4_update_output(fl4, oif, fl4->daddr, fl4->saddr);
  288. }
  289. security_sk_classify_flow(sk, flowi4_to_flowi_common(fl4));
  290. return ip_route_output_flow(net, fl4, sk);
  291. }
  292. static inline struct rtable *ip_route_newports(struct flowi4 *fl4, struct rtable *rt,
  293. __be16 orig_sport, __be16 orig_dport,
  294. __be16 sport, __be16 dport,
  295. const struct sock *sk)
  296. {
  297. if (sport != orig_sport || dport != orig_dport) {
  298. fl4->fl4_dport = dport;
  299. fl4->fl4_sport = sport;
  300. ip_rt_put(rt);
  301. flowi4_update_output(fl4, sk->sk_bound_dev_if, fl4->daddr,
  302. fl4->saddr);
  303. security_sk_classify_flow(sk, flowi4_to_flowi_common(fl4));
  304. return ip_route_output_flow(sock_net(sk), fl4, sk);
  305. }
  306. return rt;
  307. }
  308. static inline int inet_iif(const struct sk_buff *skb)
  309. {
  310. struct rtable *rt = skb_rtable(skb);
  311. if (rt && rt->rt_iif)
  312. return rt->rt_iif;
  313. return skb->skb_iif;
  314. }
  315. static inline int ip4_dst_hoplimit(const struct dst_entry *dst)
  316. {
  317. int hoplimit = dst_metric_raw(dst, RTAX_HOPLIMIT);
  318. if (hoplimit == 0) {
  319. const struct net *net;
  320. rcu_read_lock();
  321. net = dev_net_rcu(dst_dev(dst));
  322. hoplimit = READ_ONCE(net->ipv4.sysctl_ip_default_ttl);
  323. rcu_read_unlock();
  324. }
  325. return hoplimit;
  326. }
  327. static inline struct neighbour *ip_neigh_gw4(struct net_device *dev,
  328. __be32 daddr)
  329. {
  330. struct neighbour *neigh;
  331. neigh = __ipv4_neigh_lookup_noref(dev, (__force u32)daddr);
  332. if (unlikely(!neigh))
  333. neigh = __neigh_create(&arp_tbl, &daddr, dev, false);
  334. return neigh;
  335. }
  336. static inline struct neighbour *ip_neigh_for_gw(struct rtable *rt,
  337. struct sk_buff *skb,
  338. bool *is_v6gw)
  339. {
  340. struct net_device *dev = rt->dst.dev;
  341. struct neighbour *neigh;
  342. if (likely(rt->rt_gw_family == AF_INET)) {
  343. neigh = ip_neigh_gw4(dev, rt->rt_gw4);
  344. } else if (rt->rt_gw_family == AF_INET6) {
  345. neigh = ip_neigh_gw6(dev, &rt->rt_gw6);
  346. *is_v6gw = true;
  347. } else {
  348. neigh = ip_neigh_gw4(dev, ip_hdr(skb)->daddr);
  349. }
  350. return neigh;
  351. }
  352. #endif /* _ROUTE_H */