route.h 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402
  1. /* SPDX-License-Identifier: GPL-2.0-or-later */
  2. /*
  3. * INET An implementation of the TCP/IP protocol suite for the LINUX
  4. * operating system. INET is implemented using the BSD Socket
  5. * interface as the means of communication with the user level.
  6. *
  7. * Definitions for the IP router.
  8. *
  9. * Version: @(#)route.h 1.0.4 05/27/93
  10. *
  11. * Authors: Ross Biro
  12. * Fred N. van Kempen, <[email protected]>
  13. * Fixes:
  14. * Alan Cox : Reformatted. Added ip_rt_local()
  15. * Alan Cox : Support for TCP parameters.
  16. * Alexey Kuznetsov: Major changes for new routing code.
  17. * Mike McLagan : Routing by source
  18. * Robert Olsson : Added rt_cache statistics
  19. */
  20. #ifndef _ROUTE_H
  21. #define _ROUTE_H
  22. #include <net/dst.h>
  23. #include <net/inetpeer.h>
  24. #include <net/flow.h>
  25. #include <net/inet_sock.h>
  26. #include <net/ip_fib.h>
  27. #include <net/arp.h>
  28. #include <net/ndisc.h>
  29. #include <linux/in_route.h>
  30. #include <linux/rtnetlink.h>
  31. #include <linux/rcupdate.h>
  32. #include <linux/route.h>
  33. #include <linux/ip.h>
  34. #include <linux/cache.h>
  35. #include <linux/security.h>
  36. #define RTO_ONLINK 0x01
  37. #define RT_CONN_FLAGS(sk) (RT_TOS(inet_sk(sk)->tos) | sock_flag(sk, SOCK_LOCALROUTE))
  38. #define RT_CONN_FLAGS_TOS(sk,tos) (RT_TOS(tos) | sock_flag(sk, SOCK_LOCALROUTE))
  39. static inline __u8 ip_sock_rt_scope(const struct sock *sk)
  40. {
  41. if (sock_flag(sk, SOCK_LOCALROUTE))
  42. return RT_SCOPE_LINK;
  43. return RT_SCOPE_UNIVERSE;
  44. }
  45. static inline __u8 ip_sock_rt_tos(const struct sock *sk)
  46. {
  47. return RT_TOS(inet_sk(sk)->tos);
  48. }
  49. struct ip_tunnel_info;
  50. struct fib_nh;
  51. struct fib_info;
  52. struct uncached_list;
  53. struct rtable {
  54. struct dst_entry dst;
  55. int rt_genid;
  56. unsigned int rt_flags;
  57. __u16 rt_type;
  58. __u8 rt_is_input;
  59. __u8 rt_uses_gateway;
  60. int rt_iif;
  61. u8 rt_gw_family;
  62. /* Info on neighbour */
  63. union {
  64. __be32 rt_gw4;
  65. struct in6_addr rt_gw6;
  66. };
  67. /* Miscellaneous cached information */
  68. u32 rt_mtu_locked:1,
  69. rt_pmtu:31;
  70. struct list_head rt_uncached;
  71. struct uncached_list *rt_uncached_list;
  72. };
  73. static inline bool rt_is_input_route(const struct rtable *rt)
  74. {
  75. return rt->rt_is_input != 0;
  76. }
  77. static inline bool rt_is_output_route(const struct rtable *rt)
  78. {
  79. return rt->rt_is_input == 0;
  80. }
  81. static inline __be32 rt_nexthop(const struct rtable *rt, __be32 daddr)
  82. {
  83. if (rt->rt_gw_family == AF_INET)
  84. return rt->rt_gw4;
  85. return daddr;
  86. }
  87. struct ip_rt_acct {
  88. __u32 o_bytes;
  89. __u32 o_packets;
  90. __u32 i_bytes;
  91. __u32 i_packets;
  92. };
  93. struct rt_cache_stat {
  94. unsigned int in_slow_tot;
  95. unsigned int in_slow_mc;
  96. unsigned int in_no_route;
  97. unsigned int in_brd;
  98. unsigned int in_martian_dst;
  99. unsigned int in_martian_src;
  100. unsigned int out_slow_tot;
  101. unsigned int out_slow_mc;
  102. };
  103. extern struct ip_rt_acct __percpu *ip_rt_acct;
  104. struct in_device;
  105. int ip_rt_init(void);
  106. void rt_cache_flush(struct net *net);
  107. void rt_flush_dev(struct net_device *dev);
  108. struct rtable *ip_route_output_key_hash(struct net *net, struct flowi4 *flp,
  109. const struct sk_buff *skb);
  110. struct rtable *ip_route_output_key_hash_rcu(struct net *net, struct flowi4 *flp,
  111. struct fib_result *res,
  112. const struct sk_buff *skb);
  113. static inline struct rtable *__ip_route_output_key(struct net *net,
  114. struct flowi4 *flp)
  115. {
  116. return ip_route_output_key_hash(net, flp, NULL);
  117. }
  118. struct rtable *ip_route_output_flow(struct net *, struct flowi4 *flp,
  119. const struct sock *sk);
  120. struct rtable *ip_route_output_tunnel(struct sk_buff *skb,
  121. struct net_device *dev,
  122. struct net *net, __be32 *saddr,
  123. const struct ip_tunnel_info *info,
  124. u8 protocol, bool use_cache);
  125. struct dst_entry *ipv4_blackhole_route(struct net *net,
  126. struct dst_entry *dst_orig);
  127. static inline struct rtable *ip_route_output_key(struct net *net, struct flowi4 *flp)
  128. {
  129. return ip_route_output_flow(net, flp, NULL);
  130. }
  131. static inline struct rtable *ip_route_output(struct net *net, __be32 daddr,
  132. __be32 saddr, u8 tos, int oif)
  133. {
  134. struct flowi4 fl4 = {
  135. .flowi4_oif = oif,
  136. .flowi4_tos = tos,
  137. .daddr = daddr,
  138. .saddr = saddr,
  139. };
  140. return ip_route_output_key(net, &fl4);
  141. }
  142. static inline struct rtable *ip_route_output_ports(struct net *net, struct flowi4 *fl4,
  143. struct sock *sk,
  144. __be32 daddr, __be32 saddr,
  145. __be16 dport, __be16 sport,
  146. __u8 proto, __u8 tos, int oif)
  147. {
  148. flowi4_init_output(fl4, oif, sk ? READ_ONCE(sk->sk_mark) : 0, tos,
  149. RT_SCOPE_UNIVERSE, proto,
  150. sk ? inet_sk_flowi_flags(sk) : 0,
  151. daddr, saddr, dport, sport, sock_net_uid(net, sk));
  152. if (sk)
  153. security_sk_classify_flow(sk, flowi4_to_flowi_common(fl4));
  154. return ip_route_output_flow(net, fl4, sk);
  155. }
  156. static inline struct rtable *ip_route_output_gre(struct net *net, struct flowi4 *fl4,
  157. __be32 daddr, __be32 saddr,
  158. __be32 gre_key, __u8 tos, int oif)
  159. {
  160. memset(fl4, 0, sizeof(*fl4));
  161. fl4->flowi4_oif = oif;
  162. fl4->daddr = daddr;
  163. fl4->saddr = saddr;
  164. fl4->flowi4_tos = tos;
  165. fl4->flowi4_proto = IPPROTO_GRE;
  166. fl4->fl4_gre_key = gre_key;
  167. return ip_route_output_key(net, fl4);
  168. }
  169. int ip_mc_validate_source(struct sk_buff *skb, __be32 daddr, __be32 saddr,
  170. u8 tos, struct net_device *dev,
  171. struct in_device *in_dev, u32 *itag);
  172. int ip_route_input_noref(struct sk_buff *skb, __be32 dst, __be32 src,
  173. u8 tos, struct net_device *devin);
  174. int ip_route_use_hint(struct sk_buff *skb, __be32 dst, __be32 src,
  175. u8 tos, struct net_device *devin,
  176. const struct sk_buff *hint);
  177. static inline int ip_route_input(struct sk_buff *skb, __be32 dst, __be32 src,
  178. u8 tos, struct net_device *devin)
  179. {
  180. int err;
  181. rcu_read_lock();
  182. err = ip_route_input_noref(skb, dst, src, tos, devin);
  183. if (!err) {
  184. skb_dst_force(skb);
  185. if (!skb_dst(skb))
  186. err = -EINVAL;
  187. }
  188. rcu_read_unlock();
  189. return err;
  190. }
  191. void ipv4_update_pmtu(struct sk_buff *skb, struct net *net, u32 mtu, int oif,
  192. u8 protocol);
  193. void ipv4_sk_update_pmtu(struct sk_buff *skb, struct sock *sk, u32 mtu);
  194. void ipv4_redirect(struct sk_buff *skb, struct net *net, int oif, u8 protocol);
  195. void ipv4_sk_redirect(struct sk_buff *skb, struct sock *sk);
  196. void ip_rt_send_redirect(struct sk_buff *skb);
  197. unsigned int inet_addr_type(struct net *net, __be32 addr);
  198. unsigned int inet_addr_type_table(struct net *net, __be32 addr, u32 tb_id);
  199. unsigned int inet_dev_addr_type(struct net *net, const struct net_device *dev,
  200. __be32 addr);
  201. unsigned int inet_addr_type_dev_table(struct net *net,
  202. const struct net_device *dev,
  203. __be32 addr);
  204. void ip_rt_multicast_event(struct in_device *);
  205. int ip_rt_ioctl(struct net *, unsigned int cmd, struct rtentry *rt);
  206. void ip_rt_get_source(u8 *src, struct sk_buff *skb, struct rtable *rt);
  207. struct rtable *rt_dst_alloc(struct net_device *dev,
  208. unsigned int flags, u16 type, bool noxfrm);
  209. struct rtable *rt_dst_clone(struct net_device *dev, struct rtable *rt);
  210. struct in_ifaddr;
  211. void fib_add_ifaddr(struct in_ifaddr *);
  212. void fib_del_ifaddr(struct in_ifaddr *, struct in_ifaddr *);
  213. void fib_modify_prefix_metric(struct in_ifaddr *ifa, u32 new_metric);
  214. void rt_add_uncached_list(struct rtable *rt);
  215. void rt_del_uncached_list(struct rtable *rt);
  216. int fib_dump_info_fnhe(struct sk_buff *skb, struct netlink_callback *cb,
  217. u32 table_id, struct fib_info *fi,
  218. int *fa_index, int fa_start, unsigned int flags);
  219. static inline void ip_rt_put(struct rtable *rt)
  220. {
  221. /* dst_release() accepts a NULL parameter.
  222. * We rely on dst being first structure in struct rtable
  223. */
  224. BUILD_BUG_ON(offsetof(struct rtable, dst) != 0);
  225. dst_release(&rt->dst);
  226. }
  227. #define IPTOS_RT_MASK (IPTOS_TOS_MASK & ~3)
  228. extern const __u8 ip_tos2prio[16];
  229. static inline char rt_tos2priority(u8 tos)
  230. {
  231. return ip_tos2prio[IPTOS_TOS(tos)>>1];
  232. }
  233. /* ip_route_connect() and ip_route_newports() work in tandem whilst
  234. * binding a socket for a new outgoing connection.
  235. *
  236. * In order to use IPSEC properly, we must, in the end, have a
  237. * route that was looked up using all available keys including source
  238. * and destination ports.
  239. *
  240. * However, if a source port needs to be allocated (the user specified
  241. * a wildcard source port) we need to obtain addressing information
  242. * in order to perform that allocation.
  243. *
  244. * So ip_route_connect() looks up a route using wildcarded source and
  245. * destination ports in the key, simply so that we can get a pair of
  246. * addresses to use for port allocation.
  247. *
  248. * Later, once the ports are allocated, ip_route_newports() will make
  249. * another route lookup if needed to make sure we catch any IPSEC
  250. * rules keyed on the port information.
  251. *
  252. * The callers allocate the flow key on their stack, and must pass in
  253. * the same flowi4 object to both the ip_route_connect() and the
  254. * ip_route_newports() calls.
  255. */
  256. static inline void ip_route_connect_init(struct flowi4 *fl4, __be32 dst,
  257. __be32 src, int oif, u8 protocol,
  258. __be16 sport, __be16 dport,
  259. const struct sock *sk)
  260. {
  261. __u8 flow_flags = 0;
  262. if (inet_sk(sk)->transparent)
  263. flow_flags |= FLOWI_FLAG_ANYSRC;
  264. flowi4_init_output(fl4, oif, READ_ONCE(sk->sk_mark), ip_sock_rt_tos(sk),
  265. ip_sock_rt_scope(sk), protocol, flow_flags, dst,
  266. src, dport, sport, sk->sk_uid);
  267. }
  268. static inline struct rtable *ip_route_connect(struct flowi4 *fl4, __be32 dst,
  269. __be32 src, int oif, u8 protocol,
  270. __be16 sport, __be16 dport,
  271. struct sock *sk)
  272. {
  273. struct net *net = sock_net(sk);
  274. struct rtable *rt;
  275. ip_route_connect_init(fl4, dst, src, oif, protocol, sport, dport, sk);
  276. if (!dst || !src) {
  277. rt = __ip_route_output_key(net, fl4);
  278. if (IS_ERR(rt))
  279. return rt;
  280. ip_rt_put(rt);
  281. flowi4_update_output(fl4, oif, fl4->flowi4_tos, fl4->daddr,
  282. fl4->saddr);
  283. }
  284. security_sk_classify_flow(sk, flowi4_to_flowi_common(fl4));
  285. return ip_route_output_flow(net, fl4, sk);
  286. }
  287. static inline struct rtable *ip_route_newports(struct flowi4 *fl4, struct rtable *rt,
  288. __be16 orig_sport, __be16 orig_dport,
  289. __be16 sport, __be16 dport,
  290. struct sock *sk)
  291. {
  292. if (sport != orig_sport || dport != orig_dport) {
  293. fl4->fl4_dport = dport;
  294. fl4->fl4_sport = sport;
  295. ip_rt_put(rt);
  296. flowi4_update_output(fl4, sk->sk_bound_dev_if,
  297. RT_CONN_FLAGS(sk), fl4->daddr,
  298. fl4->saddr);
  299. security_sk_classify_flow(sk, flowi4_to_flowi_common(fl4));
  300. return ip_route_output_flow(sock_net(sk), fl4, sk);
  301. }
  302. return rt;
  303. }
  304. static inline int inet_iif(const struct sk_buff *skb)
  305. {
  306. struct rtable *rt = skb_rtable(skb);
  307. if (rt && rt->rt_iif)
  308. return rt->rt_iif;
  309. return skb->skb_iif;
  310. }
  311. static inline int ip4_dst_hoplimit(const struct dst_entry *dst)
  312. {
  313. int hoplimit = dst_metric_raw(dst, RTAX_HOPLIMIT);
  314. struct net *net = dev_net(dst->dev);
  315. if (hoplimit == 0)
  316. hoplimit = READ_ONCE(net->ipv4.sysctl_ip_default_ttl);
  317. return hoplimit;
  318. }
  319. static inline struct neighbour *ip_neigh_gw4(struct net_device *dev,
  320. __be32 daddr)
  321. {
  322. struct neighbour *neigh;
  323. neigh = __ipv4_neigh_lookup_noref(dev, (__force u32)daddr);
  324. if (unlikely(!neigh))
  325. neigh = __neigh_create(&arp_tbl, &daddr, dev, false);
  326. return neigh;
  327. }
  328. static inline struct neighbour *ip_neigh_for_gw(struct rtable *rt,
  329. struct sk_buff *skb,
  330. bool *is_v6gw)
  331. {
  332. struct net_device *dev = rt->dst.dev;
  333. struct neighbour *neigh;
  334. if (likely(rt->rt_gw_family == AF_INET)) {
  335. neigh = ip_neigh_gw4(dev, rt->rt_gw4);
  336. } else if (rt->rt_gw_family == AF_INET6) {
  337. neigh = ip_neigh_gw6(dev, &rt->rt_gw6);
  338. *is_v6gw = true;
  339. } else {
  340. neigh = ip_neigh_gw4(dev, ip_hdr(skb)->daddr);
  341. }
  342. return neigh;
  343. }
  344. #endif /* _ROUTE_H */