blob: c9c53ade55c3cee53ffed639aed8eb0f3e5a0f76 [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * Internet Control Message Protocol (ICMPv6)
3 * Linux INET6 implementation
4 *
5 * Authors:
6 * Pedro Roque <roque@di.fc.ul.pt>
7 *
Linus Torvalds1da177e2005-04-16 15:20:36 -07008 * Based on net/ipv4/icmp.c
9 *
10 * RFC 1885
11 *
12 * This program is free software; you can redistribute it and/or
13 * modify it under the terms of the GNU General Public License
14 * as published by the Free Software Foundation; either version
15 * 2 of the License, or (at your option) any later version.
16 */
17
18/*
19 * Changes:
20 *
21 * Andi Kleen : exception handling
22 * Andi Kleen add rate limits. never reply to a icmp.
23 * add more length checks and other fixes.
24 * yoshfuji : ensure to sent parameter problem for
25 * fragments.
26 * YOSHIFUJI Hideaki @USAGI: added sysctl for icmp rate limit.
27 * Randy Dunlap and
28 * YOSHIFUJI Hideaki @USAGI: Per-interface statistics support
29 * Kazunori MIYAZAWA @USAGI: change output process to use ip6_append_data
30 */
31
Joe Perchesf3213832012-05-15 14:11:53 +000032#define pr_fmt(fmt) "IPv6: " fmt
33
Linus Torvalds1da177e2005-04-16 15:20:36 -070034#include <linux/module.h>
35#include <linux/errno.h>
36#include <linux/types.h>
37#include <linux/socket.h>
38#include <linux/in.h>
39#include <linux/kernel.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070040#include <linux/sockios.h>
41#include <linux/net.h>
42#include <linux/skbuff.h>
43#include <linux/init.h>
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -080044#include <linux/netfilter.h>
Tejun Heo5a0e3ad2010-03-24 17:04:11 +090045#include <linux/slab.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070046
47#ifdef CONFIG_SYSCTL
48#include <linux/sysctl.h>
49#endif
50
51#include <linux/inet.h>
52#include <linux/netdevice.h>
53#include <linux/icmpv6.h>
54
55#include <net/ip.h>
56#include <net/sock.h>
57
58#include <net/ipv6.h>
59#include <net/ip6_checksum.h>
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000060#include <net/ping.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070061#include <net/protocol.h>
62#include <net/raw.h>
63#include <net/rawv6.h>
64#include <net/transp_v6.h>
65#include <net/ip6_route.h>
66#include <net/addrconf.h>
67#include <net/icmp.h>
Herbert Xu8b7817f2007-12-12 10:44:43 -080068#include <net/xfrm.h>
Denis V. Lunev1ed85162008-04-03 14:31:03 -070069#include <net/inet_common.h>
Hannes Frederic Sowa825edac2014-01-11 11:55:46 +010070#include <net/dsfield.h>
David Ahernca254492015-10-12 11:47:10 -070071#include <net/l3mdev.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070072
Linus Torvalds7c0f6ba2016-12-24 11:46:01 -080073#include <linux/uaccess.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070074
Linus Torvalds1da177e2005-04-16 15:20:36 -070075/*
76 * The ICMP socket(s). This is the most convenient way to flow control
77 * our ICMP output as well as maintain a clean interface throughout
78 * all layers. All Socketless IP sends will soon be gone.
79 *
80 * On SMP we have one ICMP socket per-cpu.
81 */
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -080082static inline struct sock *icmpv6_sk(struct net *net)
83{
84 return net->ipv6.icmp_sk[smp_processor_id()];
85}
Linus Torvalds1da177e2005-04-16 15:20:36 -070086
Steffen Klassert6f809da2013-01-16 22:09:49 +000087static void icmpv6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
88 u8 type, u8 code, int offset, __be32 info)
89{
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000090 /* icmpv6_notify checks 8 bytes can be pulled, icmp6hdr is 8 bytes */
91 struct icmp6hdr *icmp6 = (struct icmp6hdr *) (skb->data + offset);
Steffen Klassert6f809da2013-01-16 22:09:49 +000092 struct net *net = dev_net(skb->dev);
93
94 if (type == ICMPV6_PKT_TOOBIG)
Georg Kohmann5f379ef2018-08-02 13:56:58 +020095 ip6_update_pmtu(skb, net, info, skb->dev->ifindex, 0, sock_net_uid(net, NULL));
Steffen Klassert6f809da2013-01-16 22:09:49 +000096 else if (type == NDISC_REDIRECT)
Lorenzo Colittie2d118a2016-11-04 02:23:43 +090097 ip6_redirect(skb, net, skb->dev->ifindex, 0,
98 sock_net_uid(net, NULL));
Lorenzo Colitti6d0bfe22013-05-22 20:17:31 +000099
100 if (!(type & ICMPV6_INFOMSG_MASK))
101 if (icmp6->icmp6_type == ICMPV6_ECHO_REQUEST)
Hannes Frederic Sowadcb94b82016-06-11 20:32:06 +0200102 ping_err(skb, offset, ntohl(info));
Steffen Klassert6f809da2013-01-16 22:09:49 +0000103}
104
Herbert Xue5bbef22007-10-15 12:50:28 -0700105static int icmpv6_rcv(struct sk_buff *skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700106
Alexey Dobriyan41135cc2009-09-14 12:22:28 +0000107static const struct inet6_protocol icmpv6_protocol = {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700108 .handler = icmpv6_rcv,
Steffen Klassert6f809da2013-01-16 22:09:49 +0000109 .err_handler = icmpv6_err,
Herbert Xu8b7817f2007-12-12 10:44:43 -0800110 .flags = INET6_PROTO_NOPOLICY|INET6_PROTO_FINAL,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700111};
112
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100113/* Called with BH disabled */
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700114static __inline__ struct sock *icmpv6_xmit_lock(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700115{
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700116 struct sock *sk;
117
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700118 sk = icmpv6_sk(net);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800119 if (unlikely(!spin_trylock(&sk->sk_lock.slock))) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700120 /* This can happen if the output path (f.e. SIT or
121 * ip6ip6 tunnel) signals dst_link_failure() for an
122 * outgoing ICMP6 packet.
123 */
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700124 return NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700125 }
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700126 return sk;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700127}
128
Denis V. Lunev405666d2008-02-29 11:16:46 -0800129static __inline__ void icmpv6_xmit_unlock(struct sock *sk)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700130{
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100131 spin_unlock(&sk->sk_lock.slock);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700132}
133
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900134/*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700135 * Figure out, may we reply to this packet with icmp error.
136 *
137 * We do not reply, if:
138 * - it was icmp error message.
139 * - it is truncated, so that it is known, that protocol is ICMPV6
140 * (i.e. in the middle of some exthdr)
141 *
142 * --ANK (980726)
143 */
144
Eric Dumazeta50feda2012-05-18 18:57:34 +0000145static bool is_ineligible(const struct sk_buff *skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700146{
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700147 int ptr = (u8 *)(ipv6_hdr(skb) + 1) - skb->data;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700148 int len = skb->len - ptr;
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700149 __u8 nexthdr = ipv6_hdr(skb)->nexthdr;
Jesse Gross75f28112011-11-30 17:05:51 -0800150 __be16 frag_off;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700151
152 if (len < 0)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000153 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700154
Jesse Gross75f28112011-11-30 17:05:51 -0800155 ptr = ipv6_skip_exthdr(skb, ptr, &nexthdr, &frag_off);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700156 if (ptr < 0)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000157 return false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700158 if (nexthdr == IPPROTO_ICMPV6) {
159 u8 _type, *tp;
160 tp = skb_header_pointer(skb,
161 ptr+offsetof(struct icmp6hdr, icmp6_type),
162 sizeof(_type), &_type);
Ian Morris63159f22015-03-29 14:00:04 +0100163 if (!tp || !(*tp & ICMPV6_INFOMSG_MASK))
Eric Dumazeta50feda2012-05-18 18:57:34 +0000164 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700165 }
Eric Dumazeta50feda2012-05-18 18:57:34 +0000166 return false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700167}
168
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100169static bool icmpv6_mask_allow(int type)
170{
171 /* Informational messages are not limited. */
172 if (type & ICMPV6_INFOMSG_MASK)
173 return true;
174
175 /* Do not limit pmtu discovery, it would break it. */
176 if (type == ICMPV6_PKT_TOOBIG)
177 return true;
178
179 return false;
180}
181
182static bool icmpv6_global_allow(int type)
183{
184 if (icmpv6_mask_allow(type))
185 return true;
186
187 if (icmp_global_allow())
188 return true;
189
190 return false;
191}
192
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900193/*
194 * Check the ICMP output rate limit
Linus Torvalds1da177e2005-04-16 15:20:36 -0700195 */
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700196static bool icmpv6_xrlim_allow(struct sock *sk, u8 type,
197 struct flowi6 *fl6)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700198{
YOSHIFUJI Hideaki3b1e0a62008-03-26 02:26:21 +0900199 struct net *net = sock_net(sk);
Eric Dumazet4cdf5072014-09-19 07:38:40 -0700200 struct dst_entry *dst;
David S. Miller92d86822011-02-04 15:55:25 -0800201 bool res = false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700202
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100203 if (icmpv6_mask_allow(type))
David S. Miller92d86822011-02-04 15:55:25 -0800204 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700205
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900206 /*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700207 * Look up the output route.
208 * XXX: perhaps the expire for routing entries cloned by
209 * this lookup should be more aggressive (not longer than timeout).
210 */
David S. Miller4c9483b2011-03-12 16:22:43 -0500211 dst = ip6_route_output(net, sk, fl6);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700212 if (dst->error) {
Denis V. Lunev3bd653c2008-10-08 10:54:51 -0700213 IP6_INC_STATS(net, ip6_dst_idev(dst),
YOSHIFUJI Hideakia11d2062006-11-04 20:11:37 +0900214 IPSTATS_MIB_OUTNOROUTES);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700215 } else if (dst->dev && (dst->dev->flags&IFF_LOOPBACK)) {
David S. Miller92d86822011-02-04 15:55:25 -0800216 res = true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700217 } else {
218 struct rt6_info *rt = (struct rt6_info *)dst;
Benjamin Thery9a43b702008-03-05 10:49:18 -0800219 int tmo = net->ipv6.sysctl.icmpv6_time;
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100220 struct inet_peer *peer;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700221
222 /* Give more bandwidth to wider prefixes. */
223 if (rt->rt6i_dst.plen < 128)
224 tmo >>= ((128 - rt->rt6i_dst.plen)>>5);
225
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100226 peer = inet_getpeer_v6(net->ipv6.peers, &fl6->daddr, 1);
227 res = inet_peer_xrlim_allow(peer, tmo);
228 if (peer)
229 inet_putpeer(peer);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700230 }
231 dst_release(dst);
232 return res;
233}
234
235/*
236 * an inline helper for the "simple" if statement below
237 * checks if parameter problem report is caused by an
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900238 * unrecognized IPv6 option that has the Option Type
Linus Torvalds1da177e2005-04-16 15:20:36 -0700239 * highest-order two bits set to 10
240 */
241
Eric Dumazeta50feda2012-05-18 18:57:34 +0000242static bool opt_unrec(struct sk_buff *skb, __u32 offset)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700243{
244 u8 _optval, *op;
245
Arnaldo Carvalho de Melobbe735e2007-03-10 22:16:10 -0300246 offset += skb_network_offset(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700247 op = skb_header_pointer(skb, offset, sizeof(_optval), &_optval);
Ian Morris63159f22015-03-29 14:00:04 +0100248 if (!op)
Eric Dumazeta50feda2012-05-18 18:57:34 +0000249 return true;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700250 return (*op & 0xC0) == 0x80;
251}
252
Joe Perches4e64b1e2017-10-05 23:46:14 -0700253void icmpv6_push_pending_frames(struct sock *sk, struct flowi6 *fl6,
254 struct icmp6hdr *thdr, int len)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700255{
256 struct sk_buff *skb;
257 struct icmp6hdr *icmp6h;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700258
Ian Morrise5d08d72014-11-23 21:28:43 +0000259 skb = skb_peek(&sk->sk_write_queue);
Ian Morris63159f22015-03-29 14:00:04 +0100260 if (!skb)
Joe Perches4e64b1e2017-10-05 23:46:14 -0700261 return;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700262
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300263 icmp6h = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700264 memcpy(icmp6h, thdr, sizeof(struct icmp6hdr));
265 icmp6h->icmp6_cksum = 0;
266
267 if (skb_queue_len(&sk->sk_write_queue) == 1) {
Joe Perches07f07572008-11-19 15:44:53 -0800268 skb->csum = csum_partial(icmp6h,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700269 sizeof(struct icmp6hdr), skb->csum);
David S. Miller4c9483b2011-03-12 16:22:43 -0500270 icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
271 &fl6->daddr,
272 len, fl6->flowi6_proto,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700273 skb->csum);
274 } else {
Al Viro868c86b2006-11-14 21:35:48 -0800275 __wsum tmp_csum = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700276
277 skb_queue_walk(&sk->sk_write_queue, skb) {
278 tmp_csum = csum_add(tmp_csum, skb->csum);
279 }
280
Joe Perches07f07572008-11-19 15:44:53 -0800281 tmp_csum = csum_partial(icmp6h,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700282 sizeof(struct icmp6hdr), tmp_csum);
David S. Miller4c9483b2011-03-12 16:22:43 -0500283 icmp6h->icmp6_cksum = csum_ipv6_magic(&fl6->saddr,
284 &fl6->daddr,
285 len, fl6->flowi6_proto,
Al Viro868c86b2006-11-14 21:35:48 -0800286 tmp_csum);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700287 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700288 ip6_push_pending_frames(sk);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700289}
290
291struct icmpv6_msg {
292 struct sk_buff *skb;
293 int offset;
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800294 uint8_t type;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700295};
296
297static int icmpv6_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
298{
299 struct icmpv6_msg *msg = (struct icmpv6_msg *) from;
300 struct sk_buff *org_skb = msg->skb;
Al Viro5f92a732006-11-14 21:36:54 -0800301 __wsum csum = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700302
303 csum = skb_copy_and_csum_bits(org_skb, msg->offset + offset,
304 to, len, csum);
305 skb->csum = csum_block_add(skb->csum, csum, odd);
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800306 if (!(msg->type & ICMPV6_INFOMSG_MASK))
307 nf_ct_attach(skb, org_skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700308 return 0;
309}
310
Amerigo Wang07a93622012-10-29 16:23:10 +0000311#if IS_ENABLED(CONFIG_IPV6_MIP6)
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700312static void mip6_addr_swap(struct sk_buff *skb)
313{
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700314 struct ipv6hdr *iph = ipv6_hdr(skb);
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700315 struct inet6_skb_parm *opt = IP6CB(skb);
316 struct ipv6_destopt_hao *hao;
317 struct in6_addr tmp;
318 int off;
319
320 if (opt->dsthao) {
321 off = ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO);
322 if (likely(off >= 0)) {
Arnaldo Carvalho de Melod56f90a2007-04-10 20:50:43 -0700323 hao = (struct ipv6_destopt_hao *)
324 (skb_network_header(skb) + off);
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000325 tmp = iph->saddr;
326 iph->saddr = hao->addr;
327 hao->addr = tmp;
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700328 }
329 }
330}
331#else
332static inline void mip6_addr_swap(struct sk_buff *skb) {}
333#endif
334
stephen hemmingere8243532013-12-29 14:03:31 -0800335static struct dst_entry *icmpv6_route_lookup(struct net *net,
336 struct sk_buff *skb,
337 struct sock *sk,
338 struct flowi6 *fl6)
David S. Millerb42835d2011-03-01 22:06:22 -0800339{
340 struct dst_entry *dst, *dst2;
David S. Miller4c9483b2011-03-12 16:22:43 -0500341 struct flowi6 fl2;
David S. Millerb42835d2011-03-01 22:06:22 -0800342 int err;
343
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700344 err = ip6_dst_lookup(net, sk, &dst, fl6);
David S. Millerb42835d2011-03-01 22:06:22 -0800345 if (err)
346 return ERR_PTR(err);
347
348 /*
349 * We won't send icmp if the destination is known
350 * anycast.
351 */
Martin KaFai Lau2647a9b2015-05-22 20:55:58 -0700352 if (ipv6_anycast_destination(dst, &fl6->daddr)) {
Joe Perchesba7a46f2014-11-11 10:59:17 -0800353 net_dbg_ratelimited("icmp6_send: acast source\n");
David S. Millerb42835d2011-03-01 22:06:22 -0800354 dst_release(dst);
355 return ERR_PTR(-EINVAL);
356 }
357
358 /* No need to clone since we're just using its address. */
359 dst2 = dst;
360
David S. Miller4c9483b2011-03-12 16:22:43 -0500361 dst = xfrm_lookup(net, dst, flowi6_to_flowi(fl6), sk, 0);
David S. Miller452edd52011-03-02 13:27:41 -0800362 if (!IS_ERR(dst)) {
David S. Millerb42835d2011-03-01 22:06:22 -0800363 if (dst != dst2)
364 return dst;
David S. Miller452edd52011-03-02 13:27:41 -0800365 } else {
366 if (PTR_ERR(dst) == -EPERM)
367 dst = NULL;
368 else
369 return dst;
David S. Millerb42835d2011-03-01 22:06:22 -0800370 }
371
David S. Miller4c9483b2011-03-12 16:22:43 -0500372 err = xfrm_decode_session_reverse(skb, flowi6_to_flowi(&fl2), AF_INET6);
David S. Millerb42835d2011-03-01 22:06:22 -0800373 if (err)
374 goto relookup_failed;
375
Roopa Prabhu343d60a2015-07-30 13:34:53 -0700376 err = ip6_dst_lookup(net, sk, &dst2, &fl2);
David S. Millerb42835d2011-03-01 22:06:22 -0800377 if (err)
378 goto relookup_failed;
379
David S. Miller4c9483b2011-03-12 16:22:43 -0500380 dst2 = xfrm_lookup(net, dst2, flowi6_to_flowi(&fl2), sk, XFRM_LOOKUP_ICMP);
David S. Miller452edd52011-03-02 13:27:41 -0800381 if (!IS_ERR(dst2)) {
David S. Millerb42835d2011-03-01 22:06:22 -0800382 dst_release(dst);
383 dst = dst2;
David S. Miller452edd52011-03-02 13:27:41 -0800384 } else {
385 err = PTR_ERR(dst2);
386 if (err == -EPERM) {
387 dst_release(dst);
388 return dst2;
389 } else
390 goto relookup_failed;
David S. Millerb42835d2011-03-01 22:06:22 -0800391 }
392
393relookup_failed:
394 if (dst)
395 return dst;
396 return ERR_PTR(err);
397}
398
David Ahern1b70d7922017-08-28 13:53:34 -0700399static int icmp6_iif(const struct sk_buff *skb)
400{
401 int iif = skb->dev->ifindex;
402
403 /* for local traffic to local address, skb dev is the loopback
404 * device. Check if there is a dst attached to the skb and if so
David Ahern24b711e2018-07-19 12:41:18 -0700405 * get the real device index. Same is needed for replies to a link
406 * local address on a device enslaved to an L3 master device
David Ahern1b70d7922017-08-28 13:53:34 -0700407 */
David Ahern24b711e2018-07-19 12:41:18 -0700408 if (unlikely(iif == LOOPBACK_IFINDEX || netif_is_l3_master(skb->dev))) {
David Ahern1b70d7922017-08-28 13:53:34 -0700409 const struct rt6_info *rt6 = skb_rt6_info(skb);
410
411 if (rt6)
412 iif = rt6->rt6i_idev->dev->ifindex;
413 }
414
415 return iif;
416}
417
Linus Torvalds1da177e2005-04-16 15:20:36 -0700418/*
419 * Send an ICMP message in response to a packet in error
420 */
Eric Dumazetb1cadc12016-06-18 21:52:02 -0700421static void icmp6_send(struct sk_buff *skb, u8 type, u8 code, __u32 info,
422 const struct in6_addr *force_saddr)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700423{
YOSHIFUJI Hideakic346dca2008-03-25 21:47:49 +0900424 struct net *net = dev_net(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700425 struct inet6_dev *idev = NULL;
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700426 struct ipv6hdr *hdr = ipv6_hdr(skb);
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700427 struct sock *sk;
428 struct ipv6_pinfo *np;
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000429 const struct in6_addr *saddr = NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700430 struct dst_entry *dst;
431 struct icmp6hdr tmp_hdr;
David S. Miller4c9483b2011-03-12 16:22:43 -0500432 struct flowi6 fl6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700433 struct icmpv6_msg msg;
Wei Wang26879da2016-05-02 21:40:07 -0700434 struct ipcm6_cookie ipc6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700435 int iif = 0;
436 int addr_type = 0;
437 int len;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700438 u32 mark = IP6_REPLY_MARK(net, skb->mark);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700439
Arnaldo Carvalho de Melo27a884d2007-04-19 20:29:13 -0700440 if ((u8 *)hdr < skb->head ||
Simon Horman29a3cad2013-05-28 20:34:26 +0000441 (skb_network_header(skb) + sizeof(*hdr)) > skb_tail_pointer(skb))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700442 return;
443
444 /*
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900445 * Make sure we respect the rules
Linus Torvalds1da177e2005-04-16 15:20:36 -0700446 * i.e. RFC 1885 2.4(e)
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000447 * Rule (e.1) is enforced by not using icmp6_send
Linus Torvalds1da177e2005-04-16 15:20:36 -0700448 * in any code that processes icmp errors.
449 */
450 addr_type = ipv6_addr_type(&hdr->daddr);
451
FX Le Bail446fab52014-01-19 17:00:36 +0100452 if (ipv6_chk_addr(net, &hdr->daddr, skb->dev, 0) ||
FX Le Baild94c1f92014-02-07 11:22:37 +0100453 ipv6_chk_acast_addr_src(net, skb->dev, &hdr->daddr))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700454 saddr = &hdr->daddr;
455
456 /*
457 * Dest addr check
458 */
459
zhuyj9a6b4b32015-01-14 17:23:59 +0800460 if (addr_type & IPV6_ADDR_MULTICAST || skb->pkt_type != PACKET_HOST) {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700461 if (type != ICMPV6_PKT_TOOBIG &&
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900462 !(type == ICMPV6_PARAMPROB &&
463 code == ICMPV6_UNK_OPTION &&
Linus Torvalds1da177e2005-04-16 15:20:36 -0700464 (opt_unrec(skb, info))))
465 return;
466
467 saddr = NULL;
468 }
469
470 addr_type = ipv6_addr_type(&hdr->saddr);
471
472 /*
473 * Source addr check
474 */
475
David Ahern4832c302017-08-17 12:17:20 -0700476 if (__ipv6_addr_needs_scope_id(addr_type)) {
David Ahern1b70d7922017-08-28 13:53:34 -0700477 iif = icmp6_iif(skb);
David Ahern4832c302017-08-17 12:17:20 -0700478 } else {
David Ahern79dc7e32016-11-27 18:52:53 -0800479 dst = skb_dst(skb);
480 iif = l3mdev_master_ifindex(dst ? dst->dev : skb->dev);
481 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700482
483 /*
YOSHIFUJI Hideaki8de33512005-12-21 22:57:06 +0900484 * Must not send error if the source does not uniquely
485 * identify a single node (RFC2463 Section 2.4).
486 * We check unspecified / multicast addresses here,
487 * and anycast addresses will be checked later.
Linus Torvalds1da177e2005-04-16 15:20:36 -0700488 */
489 if ((addr_type == IPV6_ADDR_ANY) || (addr_type & IPV6_ADDR_MULTICAST)) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200490 net_dbg_ratelimited("icmp6_send: addr_any/mcast source [%pI6c > %pI6c]\n",
491 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700492 return;
493 }
494
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900495 /*
Linus Torvalds1da177e2005-04-16 15:20:36 -0700496 * Never answer to a ICMP packet.
497 */
498 if (is_ineligible(skb)) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200499 net_dbg_ratelimited("icmp6_send: no reply to icmp error [%pI6c > %pI6c]\n",
500 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700501 return;
502 }
503
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100504 /* Needed by both icmp_global_allow and icmpv6_xmit_lock */
505 local_bh_disable();
506
507 /* Check global sysctl_icmp_msgs_per_sec ratelimit */
Jesper Dangaard Brouer849a44d2017-06-14 13:27:37 +0200508 if (!(skb->dev->flags&IFF_LOOPBACK) && !icmpv6_global_allow(type))
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100509 goto out_bh_enable;
510
Masahide NAKAMURA79383232006-08-23 19:27:25 -0700511 mip6_addr_swap(skb);
512
David S. Miller4c9483b2011-03-12 16:22:43 -0500513 memset(&fl6, 0, sizeof(fl6));
514 fl6.flowi6_proto = IPPROTO_ICMPV6;
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000515 fl6.daddr = hdr->saddr;
Eric Dumazetb1cadc12016-06-18 21:52:02 -0700516 if (force_saddr)
517 saddr = force_saddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700518 if (saddr)
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000519 fl6.saddr = *saddr;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700520 fl6.flowi6_mark = mark;
David S. Miller4c9483b2011-03-12 16:22:43 -0500521 fl6.flowi6_oif = iif;
David S. Miller1958b852011-03-12 16:36:19 -0500522 fl6.fl6_icmp_type = type;
523 fl6.fl6_icmp_code = code;
Lorenzo Colittie2d118a2016-11-04 02:23:43 +0900524 fl6.flowi6_uid = sock_net_uid(net, NULL);
David Ahernb4bac172018-03-02 08:32:18 -0800525 fl6.mp_hash = rt6_multipath_hash(net, &fl6, skb, NULL);
David S. Miller4c9483b2011-03-12 16:22:43 -0500526 security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700527
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700528 sk = icmpv6_xmit_lock(net);
Ian Morris63159f22015-03-29 14:00:04 +0100529 if (!sk)
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100530 goto out_bh_enable;
Jesper Dangaard Brouerc0303ef2017-01-09 16:04:09 +0100531
Lorenzo Colittie1108612014-05-13 10:17:33 -0700532 sk->sk_mark = mark;
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700533 np = inet6_sk(sk);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800534
David S. Miller4c9483b2011-03-12 16:22:43 -0500535 if (!icmpv6_xrlim_allow(sk, type, &fl6))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700536 goto out;
537
538 tmp_hdr.icmp6_type = type;
539 tmp_hdr.icmp6_code = code;
540 tmp_hdr.icmp6_cksum = 0;
541 tmp_hdr.icmp6_pointer = htonl(info);
542
David S. Miller4c9483b2011-03-12 16:22:43 -0500543 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
544 fl6.flowi6_oif = np->mcast_oif;
Erich E. Hooverc4062df2012-02-08 09:11:08 +0000545 else if (!fl6.flowi6_oif)
546 fl6.flowi6_oif = np->ucast_oif;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700547
Willem de Bruijnb515430a2018-07-06 10:12:55 -0400548 ipcm6_init_sk(&ipc6, np);
Hannes Frederic Sowa38b70972016-06-11 20:08:19 +0200549 fl6.flowlabel = ip6_make_flowinfo(ipc6.tclass, fl6.flowlabel);
550
David S. Miller4c9483b2011-03-12 16:22:43 -0500551 dst = icmpv6_route_lookup(net, skb, sk, &fl6);
David S. Millerb42835d2011-03-01 22:06:22 -0800552 if (IS_ERR(dst))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700553 goto out;
YOSHIFUJI Hideaki8de33512005-12-21 22:57:06 +0900554
Wei Wang26879da2016-05-02 21:40:07 -0700555 ipc6.hlimit = ip6_sk_dst_hoplimit(np, &fl6, dst);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700556
557 msg.skb = skb;
Arnaldo Carvalho de Melobbe735e2007-03-10 22:16:10 -0300558 msg.offset = skb_network_offset(skb);
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800559 msg.type = type;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700560
561 len = skb->len - msg.offset;
Ian Morris67ba4152014-08-24 21:53:10 +0100562 len = min_t(unsigned int, len, IPV6_MIN_MTU - sizeof(struct ipv6hdr) - sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700563 if (len < 0) {
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200564 net_dbg_ratelimited("icmp: len problem [%pI6c > %pI6c]\n",
565 &hdr->saddr, &hdr->daddr);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700566 goto out_dst_release;
567 }
568
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000569 rcu_read_lock();
570 idev = __in6_dev_get(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700571
Joe Perches4e64b1e2017-10-05 23:46:14 -0700572 if (ip6_append_data(sk, icmpv6_getfrag, &msg,
573 len + sizeof(struct icmp6hdr),
574 sizeof(struct icmp6hdr),
575 &ipc6, &fl6, (struct rt6_info *)dst,
Willem de Bruijn5fdaa882018-07-06 10:12:57 -0400576 MSG_DONTWAIT)) {
Hannes Frederic Sowa43a43b62014-03-31 20:14:10 +0200577 ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700578 ip6_flush_pending_frames(sk);
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000579 } else {
Joe Perches4e64b1e2017-10-05 23:46:14 -0700580 icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
581 len + sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700582 }
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000583 rcu_read_unlock();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700584out_dst_release:
585 dst_release(dst);
586out:
Denis V. Lunev405666d2008-02-29 11:16:46 -0800587 icmpv6_xmit_unlock(sk);
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100588out_bh_enable:
589 local_bh_enable();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700590}
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000591
592/* Slightly more convenient version of icmp6_send.
593 */
594void icmpv6_param_prob(struct sk_buff *skb, u8 code, int pos)
595{
Eric Dumazetb1cadc12016-06-18 21:52:02 -0700596 icmp6_send(skb, ICMPV6_PARAMPROB, code, pos, NULL);
Pravin B Shelar5f5624c2013-04-25 11:08:30 +0000597 kfree_skb(skb);
598}
YOSHIFUJI Hideaki71590392007-02-22 22:05:40 +0900599
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700600/* Generate icmpv6 with type/code ICMPV6_DEST_UNREACH/ICMPV6_ADDR_UNREACH
601 * if sufficient data bytes are available
602 * @nhs is the size of the tunnel header(s) :
603 * Either an IPv4 header for SIT encap
604 * an IPv4 header + GRE header for GRE encap
605 */
Eric Dumazet20e19542016-06-18 21:52:06 -0700606int ip6_err_gen_icmpv6_unreach(struct sk_buff *skb, int nhs, int type,
607 unsigned int data_len)
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700608{
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700609 struct in6_addr temp_saddr;
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700610 struct rt6_info *rt;
611 struct sk_buff *skb2;
Eric Dumazet20e19542016-06-18 21:52:06 -0700612 u32 info = 0;
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700613
614 if (!pskb_may_pull(skb, nhs + sizeof(struct ipv6hdr) + 8))
615 return 1;
616
Eric Dumazet20e19542016-06-18 21:52:06 -0700617 /* RFC 4884 (partial) support for ICMP extensions */
618 if (data_len < 128 || (data_len & 7) || skb->len < data_len)
619 data_len = 0;
620
621 skb2 = data_len ? skb_copy(skb, GFP_ATOMIC) : skb_clone(skb, GFP_ATOMIC);
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700622
623 if (!skb2)
624 return 1;
625
626 skb_dst_drop(skb2);
627 skb_pull(skb2, nhs);
628 skb_reset_network_header(skb2);
629
David Ahernb75cc8f2018-03-02 08:32:17 -0800630 rt = rt6_lookup(dev_net(skb->dev), &ipv6_hdr(skb2)->saddr, NULL, 0,
631 skb, 0);
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700632
633 if (rt && rt->dst.dev)
634 skb2->dev = rt->dst.dev;
635
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700636 ipv6_addr_set_v4mapped(ip_hdr(skb)->saddr, &temp_saddr);
Eric Dumazet20e19542016-06-18 21:52:06 -0700637
638 if (data_len) {
639 /* RFC 4884 (partial) support :
640 * insert 0 padding at the end, before the extensions
641 */
642 __skb_push(skb2, nhs);
643 skb_reset_network_header(skb2);
644 memmove(skb2->data, skb2->data + nhs, data_len - nhs);
645 memset(skb2->data + data_len - nhs, 0, nhs);
646 /* RFC 4884 4.5 : Length is measured in 64-bit words,
647 * and stored in reserved[0]
648 */
649 info = (data_len/8) << 24;
650 }
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700651 if (type == ICMP_TIME_EXCEEDED)
652 icmp6_send(skb2, ICMPV6_TIME_EXCEED, ICMPV6_EXC_HOPLIMIT,
Eric Dumazet20e19542016-06-18 21:52:06 -0700653 info, &temp_saddr);
Eric Dumazet2d7a3b22016-06-18 21:52:04 -0700654 else
655 icmp6_send(skb2, ICMPV6_DEST_UNREACH, ICMPV6_ADDR_UNREACH,
Eric Dumazet20e19542016-06-18 21:52:06 -0700656 info, &temp_saddr);
Eric Dumazet5fbba8a2016-06-18 21:52:03 -0700657 if (rt)
658 ip6_rt_put(rt);
659
660 kfree_skb(skb2);
661
662 return 0;
663}
664EXPORT_SYMBOL(ip6_err_gen_icmpv6_unreach);
665
Linus Torvalds1da177e2005-04-16 15:20:36 -0700666static void icmpv6_echo_reply(struct sk_buff *skb)
667{
YOSHIFUJI Hideakic346dca2008-03-25 21:47:49 +0900668 struct net *net = dev_net(skb->dev);
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700669 struct sock *sk;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700670 struct inet6_dev *idev;
YOSHIFUJI Hideaki84427d52005-06-13 14:59:44 -0700671 struct ipv6_pinfo *np;
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000672 const struct in6_addr *saddr = NULL;
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300673 struct icmp6hdr *icmph = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700674 struct icmp6hdr tmp_hdr;
David S. Miller4c9483b2011-03-12 16:22:43 -0500675 struct flowi6 fl6;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700676 struct icmpv6_msg msg;
677 struct dst_entry *dst;
Wei Wang26879da2016-05-02 21:40:07 -0700678 struct ipcm6_cookie ipc6;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700679 u32 mark = IP6_REPLY_MARK(net, skb->mark);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700680
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700681 saddr = &ipv6_hdr(skb)->daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700682
FX Le Bail509aba32014-01-07 14:57:27 +0100683 if (!ipv6_unicast_destination(skb) &&
FX Le Bailec35b612014-01-13 15:59:01 +0100684 !(net->ipv6.sysctl.anycast_src_echo_reply &&
Martin KaFai Lau2647a9b2015-05-22 20:55:58 -0700685 ipv6_anycast_destination(skb_dst(skb), saddr)))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700686 saddr = NULL;
687
688 memcpy(&tmp_hdr, icmph, sizeof(tmp_hdr));
689 tmp_hdr.icmp6_type = ICMPV6_ECHO_REPLY;
690
David S. Miller4c9483b2011-03-12 16:22:43 -0500691 memset(&fl6, 0, sizeof(fl6));
692 fl6.flowi6_proto = IPPROTO_ICMPV6;
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000693 fl6.daddr = ipv6_hdr(skb)->saddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700694 if (saddr)
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000695 fl6.saddr = *saddr;
David Ahern1b70d7922017-08-28 13:53:34 -0700696 fl6.flowi6_oif = icmp6_iif(skb);
David S. Miller1958b852011-03-12 16:36:19 -0500697 fl6.fl6_icmp_type = ICMPV6_ECHO_REPLY;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700698 fl6.flowi6_mark = mark;
Lorenzo Colittie2d118a2016-11-04 02:23:43 +0900699 fl6.flowi6_uid = sock_net_uid(net, NULL);
David S. Miller4c9483b2011-03-12 16:22:43 -0500700 security_skb_classify_flow(skb, flowi6_to_flowi(&fl6));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700701
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100702 local_bh_disable();
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700703 sk = icmpv6_xmit_lock(net);
Ian Morris63159f22015-03-29 14:00:04 +0100704 if (!sk)
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100705 goto out_bh_enable;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700706 sk->sk_mark = mark;
Denis V. Lunevfdc0bde2008-08-23 04:43:33 -0700707 np = inet6_sk(sk);
Denis V. Lunev405666d2008-02-29 11:16:46 -0800708
David S. Miller4c9483b2011-03-12 16:22:43 -0500709 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
710 fl6.flowi6_oif = np->mcast_oif;
Erich E. Hooverc4062df2012-02-08 09:11:08 +0000711 else if (!fl6.flowi6_oif)
712 fl6.flowi6_oif = np->ucast_oif;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700713
Joe Perches4e64b1e2017-10-05 23:46:14 -0700714 if (ip6_dst_lookup(net, sk, &dst, &fl6))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700715 goto out;
David S. Miller4c9483b2011-03-12 16:22:43 -0500716 dst = xfrm_lookup(net, dst, flowi6_to_flowi(&fl6), sk, 0);
David S. Miller452edd52011-03-02 13:27:41 -0800717 if (IS_ERR(dst))
Patrick McHardye104411b2005-09-08 15:11:55 -0700718 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700719
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000720 idev = __in6_dev_get(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700721
722 msg.skb = skb;
723 msg.offset = 0;
Yasuyuki Kozakai763ecff2006-02-15 15:24:15 -0800724 msg.type = ICMPV6_ECHO_REPLY;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700725
Willem de Bruijnb515430a2018-07-06 10:12:55 -0400726 ipcm6_init_sk(&ipc6, np);
Wei Wang26879da2016-05-02 21:40:07 -0700727 ipc6.hlimit = ip6_sk_dst_hoplimit(np, &fl6, dst);
728 ipc6.tclass = ipv6_get_dsfield(ipv6_hdr(skb));
Wei Wang26879da2016-05-02 21:40:07 -0700729
Joe Perches4e64b1e2017-10-05 23:46:14 -0700730 if (ip6_append_data(sk, icmpv6_getfrag, &msg,
731 skb->len + sizeof(struct icmp6hdr),
732 sizeof(struct icmp6hdr), &ipc6, &fl6,
Willem de Bruijn5fdaa882018-07-06 10:12:57 -0400733 (struct rt6_info *)dst, MSG_DONTWAIT)) {
Eric Dumazeta16292a2016-04-27 16:44:36 -0700734 __ICMP6_INC_STATS(net, idev, ICMP6_MIB_OUTERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700735 ip6_flush_pending_frames(sk);
Eric Dumazetcfdf7642011-07-27 21:13:03 +0000736 } else {
Joe Perches4e64b1e2017-10-05 23:46:14 -0700737 icmpv6_push_pending_frames(sk, &fl6, &tmp_hdr,
738 skb->len + sizeof(struct icmp6hdr));
Linus Torvalds1da177e2005-04-16 15:20:36 -0700739 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700740 dst_release(dst);
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900741out:
Denis V. Lunev405666d2008-02-29 11:16:46 -0800742 icmpv6_xmit_unlock(sk);
Jesper Dangaard Brouer7ba91ec2017-01-09 16:04:14 +0100743out_bh_enable:
744 local_bh_enable();
Linus Torvalds1da177e2005-04-16 15:20:36 -0700745}
746
David S. Millerb94f1c02012-07-12 00:33:37 -0700747void icmpv6_notify(struct sk_buff *skb, u8 type, u8 code, __be32 info)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700748{
Alexey Dobriyan41135cc2009-09-14 12:22:28 +0000749 const struct inet6_protocol *ipprot;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700750 int inner_offset;
Jesse Gross75f28112011-11-30 17:05:51 -0800751 __be16 frag_off;
David S. Millerf9242b62012-06-19 18:56:21 -0700752 u8 nexthdr;
Duan Jiong7304fe42014-07-31 17:54:32 +0800753 struct net *net = dev_net(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700754
755 if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
Duan Jiong7304fe42014-07-31 17:54:32 +0800756 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700757
758 nexthdr = ((struct ipv6hdr *)skb->data)->nexthdr;
759 if (ipv6_ext_hdr(nexthdr)) {
760 /* now skip over extension headers */
Jesse Gross75f28112011-11-30 17:05:51 -0800761 inner_offset = ipv6_skip_exthdr(skb, sizeof(struct ipv6hdr),
762 &nexthdr, &frag_off);
Ian Morris67ba4152014-08-24 21:53:10 +0100763 if (inner_offset < 0)
Duan Jiong7304fe42014-07-31 17:54:32 +0800764 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700765 } else {
766 inner_offset = sizeof(struct ipv6hdr);
767 }
768
769 /* Checkin header including 8 bytes of inner protocol header. */
770 if (!pskb_may_pull(skb, inner_offset+8))
Duan Jiong7304fe42014-07-31 17:54:32 +0800771 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700772
Linus Torvalds1da177e2005-04-16 15:20:36 -0700773 /* BUGGG_FUTURE: we should try to parse exthdrs in this packet.
774 Without this we will not able f.e. to make source routed
775 pmtu discovery.
776 Corresponding argument (opt) to notifiers is already added.
777 --ANK (980726)
778 */
779
David S. Millerf9242b62012-06-19 18:56:21 -0700780 ipprot = rcu_dereference(inet6_protos[nexthdr]);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700781 if (ipprot && ipprot->err_handler)
782 ipprot->err_handler(skb, NULL, type, code, inner_offset, info);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700783
Pavel Emelyanov69d6da02007-11-19 22:35:57 -0800784 raw6_icmp_error(skb, nexthdr, type, code, inner_offset, info);
Duan Jiong7304fe42014-07-31 17:54:32 +0800785 return;
786
787out:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700788 __ICMP6_INC_STATS(net, __in6_dev_get(skb->dev), ICMP6_MIB_INERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700789}
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900790
Linus Torvalds1da177e2005-04-16 15:20:36 -0700791/*
792 * Handle icmp messages
793 */
794
Herbert Xue5bbef22007-10-15 12:50:28 -0700795static int icmpv6_rcv(struct sk_buff *skb)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700796{
Virgile Jarrye6f86b02018-08-10 17:48:15 +0200797 struct net *net = dev_net(skb->dev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700798 struct net_device *dev = skb->dev;
799 struct inet6_dev *idev = __in6_dev_get(dev);
Eric Dumazetb71d1d42011-04-22 04:53:02 +0000800 const struct in6_addr *saddr, *daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700801 struct icmp6hdr *hdr;
Brian Haleyd5fdd6b2009-06-23 04:31:07 -0700802 u8 type;
Rick Jonese3e32172014-11-17 14:04:29 -0800803 bool success = false;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700804
Herbert Xuaebcf822007-12-12 18:54:16 -0800805 if (!xfrm6_policy_check(NULL, XFRM_POLICY_IN, skb)) {
Alexey Dobriyandef8b4f2008-10-28 13:24:06 -0700806 struct sec_path *sp = skb_sec_path(skb);
Herbert Xu8b7817f2007-12-12 10:44:43 -0800807 int nh;
808
Alexey Dobriyandef8b4f2008-10-28 13:24:06 -0700809 if (!(sp && sp->xvec[sp->len - 1]->props.flags &
Herbert Xuaebcf822007-12-12 18:54:16 -0800810 XFRM_STATE_ICMP))
811 goto drop_no_count;
812
David S. Miller81aded22012-06-15 14:54:11 -0700813 if (!pskb_may_pull(skb, sizeof(*hdr) + sizeof(struct ipv6hdr)))
Herbert Xu8b7817f2007-12-12 10:44:43 -0800814 goto drop_no_count;
815
816 nh = skb_network_offset(skb);
817 skb_set_network_header(skb, sizeof(*hdr));
818
819 if (!xfrm6_policy_check_reverse(NULL, XFRM_POLICY_IN, skb))
820 goto drop_no_count;
821
822 skb_set_network_header(skb, nh);
823 }
824
Eric Dumazeta16292a2016-04-27 16:44:36 -0700825 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_INMSGS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700826
Arnaldo Carvalho de Melo0660e032007-04-25 17:54:47 -0700827 saddr = &ipv6_hdr(skb)->saddr;
828 daddr = &ipv6_hdr(skb)->daddr;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700829
Tom Herbert39471ac2014-05-07 16:52:29 -0700830 if (skb_checksum_validate(skb, IPPROTO_ICMPV6, ip6_compute_pseudo)) {
Joe Perchesba7a46f2014-11-11 10:59:17 -0800831 net_dbg_ratelimited("ICMPv6 checksum failed [%pI6c > %pI6c]\n",
832 saddr, daddr);
Tom Herbert39471ac2014-05-07 16:52:29 -0700833 goto csum_error;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700834 }
835
Herbert Xu8cf22942008-02-05 03:15:50 -0800836 if (!pskb_pull(skb, sizeof(*hdr)))
837 goto discard_it;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700838
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300839 hdr = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700840
841 type = hdr->icmp6_type;
842
Eric Dumazetf3832ed2016-04-27 16:44:42 -0700843 ICMP6MSGIN_INC_STATS(dev_net(dev), idev, type);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700844
845 switch (type) {
846 case ICMPV6_ECHO_REQUEST:
Virgile Jarrye6f86b02018-08-10 17:48:15 +0200847 if (!net->ipv6.sysctl.icmpv6_echo_ignore_all)
848 icmpv6_echo_reply(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700849 break;
850
851 case ICMPV6_ECHO_REPLY:
Rick Jonese3e32172014-11-17 14:04:29 -0800852 success = ping_rcv(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700853 break;
854
855 case ICMPV6_PKT_TOOBIG:
856 /* BUGGG_FUTURE: if packet contains rthdr, we cannot update
857 standard destination cache. Seems, only "advanced"
858 destination cache will allow to solve this problem
859 --ANK (980726)
860 */
861 if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
862 goto discard_it;
Arnaldo Carvalho de Melocc70ab22007-03-13 14:03:22 -0300863 hdr = icmp6_hdr(skb);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700864
Gustavo A. R. Silva275757e62017-10-16 16:36:52 -0500865 /* to notify */
866 /* fall through */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700867 case ICMPV6_DEST_UNREACH:
868 case ICMPV6_TIME_EXCEED:
869 case ICMPV6_PARAMPROB:
870 icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
871 break;
872
873 case NDISC_ROUTER_SOLICITATION:
874 case NDISC_ROUTER_ADVERTISEMENT:
875 case NDISC_NEIGHBOUR_SOLICITATION:
876 case NDISC_NEIGHBOUR_ADVERTISEMENT:
877 case NDISC_REDIRECT:
878 ndisc_rcv(skb);
879 break;
880
881 case ICMPV6_MGM_QUERY:
882 igmp6_event_query(skb);
883 break;
884
885 case ICMPV6_MGM_REPORT:
886 igmp6_event_report(skb);
887 break;
888
889 case ICMPV6_MGM_REDUCTION:
890 case ICMPV6_NI_QUERY:
891 case ICMPV6_NI_REPLY:
892 case ICMPV6_MLD2_REPORT:
893 case ICMPV6_DHAAD_REQUEST:
894 case ICMPV6_DHAAD_REPLY:
895 case ICMPV6_MOBILE_PREFIX_SOL:
896 case ICMPV6_MOBILE_PREFIX_ADV:
897 break;
898
899 default:
Linus Torvalds1da177e2005-04-16 15:20:36 -0700900 /* informational */
901 if (type & ICMPV6_INFOMSG_MASK)
902 break;
903
Bjørn Mork4b3418f2015-10-24 14:00:20 +0200904 net_dbg_ratelimited("icmpv6: msg of unknown type [%pI6c > %pI6c]\n",
905 saddr, daddr);
David S. Millerea85a0a2014-10-07 16:33:53 -0400906
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +0900907 /*
908 * error of unknown type.
909 * must pass to upper level
Linus Torvalds1da177e2005-04-16 15:20:36 -0700910 */
911
912 icmpv6_notify(skb, type, hdr->icmp6_code, hdr->icmp6_mtu);
Stephen Hemminger3ff50b72007-04-20 17:09:22 -0700913 }
914
Rick Jonese3e32172014-11-17 14:04:29 -0800915 /* until the v6 path can be better sorted assume failure and
916 * preserve the status quo behaviour for the rest of the paths to here
917 */
918 if (success)
919 consume_skb(skb);
920 else
921 kfree_skb(skb);
922
Linus Torvalds1da177e2005-04-16 15:20:36 -0700923 return 0;
924
Eric Dumazet6a5dc9e2013-04-29 08:39:56 +0000925csum_error:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700926 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_CSUMERRORS);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700927discard_it:
Eric Dumazeta16292a2016-04-27 16:44:36 -0700928 __ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_INERRORS);
Herbert Xu8b7817f2007-12-12 10:44:43 -0800929drop_no_count:
Linus Torvalds1da177e2005-04-16 15:20:36 -0700930 kfree_skb(skb);
931 return 0;
932}
933
David S. Miller4c9483b2011-03-12 16:22:43 -0500934void icmpv6_flow_init(struct sock *sk, struct flowi6 *fl6,
YOSHIFUJI Hideaki95e41e92007-12-06 15:43:30 -0800935 u8 type,
936 const struct in6_addr *saddr,
937 const struct in6_addr *daddr,
938 int oif)
939{
David S. Miller4c9483b2011-03-12 16:22:43 -0500940 memset(fl6, 0, sizeof(*fl6));
Alexey Dobriyan4e3fd7a2011-11-21 03:39:03 +0000941 fl6->saddr = *saddr;
942 fl6->daddr = *daddr;
Ian Morris67ba4152014-08-24 21:53:10 +0100943 fl6->flowi6_proto = IPPROTO_ICMPV6;
David S. Miller1958b852011-03-12 16:36:19 -0500944 fl6->fl6_icmp_type = type;
945 fl6->fl6_icmp_code = 0;
David S. Miller4c9483b2011-03-12 16:22:43 -0500946 fl6->flowi6_oif = oif;
947 security_sk_classify_flow(sk, flowi6_to_flowi(fl6));
YOSHIFUJI Hideaki95e41e92007-12-06 15:43:30 -0800948}
949
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800950static int __net_init icmpv6_sk_init(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700951{
952 struct sock *sk;
953 int err, i, j;
954
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800955 net->ipv6.icmp_sk =
Kees Cook6396bb22018-06-12 14:03:40 -0700956 kcalloc(nr_cpu_ids, sizeof(struct sock *), GFP_KERNEL);
Ian Morris63159f22015-03-29 14:00:04 +0100957 if (!net->ipv6.icmp_sk)
Denis V. Lunev79c91152008-02-29 11:17:11 -0800958 return -ENOMEM;
959
KAMEZAWA Hiroyuki6f912042006-04-10 22:52:50 -0700960 for_each_possible_cpu(i) {
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700961 err = inet_ctl_sock_create(&sk, PF_INET6,
962 SOCK_RAW, IPPROTO_ICMPV6, net);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700963 if (err < 0) {
Joe Perchesf3213832012-05-15 14:11:53 +0000964 pr_err("Failed to initialize the ICMP6 control socket (err %d)\n",
Linus Torvalds1da177e2005-04-16 15:20:36 -0700965 err);
966 goto fail;
967 }
968
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700969 net->ipv6.icmp_sk[i] = sk;
Denis V. Lunev5c8cafd2008-02-29 11:19:22 -0800970
Linus Torvalds1da177e2005-04-16 15:20:36 -0700971 /* Enough space for 2 64K ICMP packets, including
972 * sk_buff struct overhead.
973 */
Eric Dumazet87fb4b72011-10-13 07:28:54 +0000974 sk->sk_sndbuf = 2 * SKB_TRUESIZE(64 * 1024);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700975 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700976 return 0;
977
978 fail:
Denis V. Lunev5c8cafd2008-02-29 11:19:22 -0800979 for (j = 0; j < i; j++)
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700980 inet_ctl_sock_destroy(net->ipv6.icmp_sk[j]);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800981 kfree(net->ipv6.icmp_sk);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700982 return err;
983}
984
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800985static void __net_exit icmpv6_sk_exit(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700986{
987 int i;
988
KAMEZAWA Hiroyuki6f912042006-04-10 22:52:50 -0700989 for_each_possible_cpu(i) {
Denis V. Lunev1ed85162008-04-03 14:31:03 -0700990 inet_ctl_sock_destroy(net->ipv6.icmp_sk[i]);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700991 }
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800992 kfree(net->ipv6.icmp_sk);
993}
994
Alexey Dobriyan8ed7edc2008-03-03 12:02:54 -0800995static struct pernet_operations icmpv6_sk_ops = {
Ian Morris67ba4152014-08-24 21:53:10 +0100996 .init = icmpv6_sk_init,
997 .exit = icmpv6_sk_exit,
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -0800998};
999
1000int __init icmpv6_init(void)
1001{
1002 int err;
1003
1004 err = register_pernet_subsys(&icmpv6_sk_ops);
1005 if (err < 0)
1006 return err;
1007
1008 err = -EAGAIN;
1009 if (inet6_add_protocol(&icmpv6_protocol, IPPROTO_ICMPV6) < 0)
1010 goto fail;
Pravin B Shelar5f5624c2013-04-25 11:08:30 +00001011
1012 err = inet6_register_icmp_sender(icmp6_send);
1013 if (err)
1014 goto sender_reg_err;
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001015 return 0;
1016
Pravin B Shelar5f5624c2013-04-25 11:08:30 +00001017sender_reg_err:
1018 inet6_del_protocol(&icmpv6_protocol, IPPROTO_ICMPV6);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001019fail:
Joe Perchesf3213832012-05-15 14:11:53 +00001020 pr_err("Failed to register ICMP6 protocol\n");
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001021 unregister_pernet_subsys(&icmpv6_sk_ops);
1022 return err;
1023}
1024
Alexey Dobriyan8ed7edc2008-03-03 12:02:54 -08001025void icmpv6_cleanup(void)
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001026{
Pravin B Shelar5f5624c2013-04-25 11:08:30 +00001027 inet6_unregister_icmp_sender(icmp6_send);
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001028 unregister_pernet_subsys(&icmpv6_sk_ops);
Linus Torvalds1da177e2005-04-16 15:20:36 -07001029 inet6_del_protocol(&icmpv6_protocol, IPPROTO_ICMPV6);
1030}
1031
Denis V. Lunev98c6d1b2008-02-29 11:21:22 -08001032
Arjan van de Ven9b5b5cf2005-11-29 16:21:38 -08001033static const struct icmp6_err {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001034 int err;
1035 int fatal;
1036} tab_unreach[] = {
1037 { /* NOROUTE */
1038 .err = ENETUNREACH,
1039 .fatal = 0,
1040 },
1041 { /* ADM_PROHIBITED */
1042 .err = EACCES,
1043 .fatal = 1,
1044 },
1045 { /* Was NOT_NEIGHBOUR, now reserved */
1046 .err = EHOSTUNREACH,
1047 .fatal = 0,
1048 },
1049 { /* ADDR_UNREACH */
1050 .err = EHOSTUNREACH,
1051 .fatal = 0,
1052 },
1053 { /* PORT_UNREACH */
1054 .err = ECONNREFUSED,
1055 .fatal = 1,
1056 },
Jiri Bohac61e76b12013-08-30 11:18:45 +02001057 { /* POLICY_FAIL */
1058 .err = EACCES,
1059 .fatal = 1,
1060 },
1061 { /* REJECT_ROUTE */
1062 .err = EACCES,
1063 .fatal = 1,
1064 },
Linus Torvalds1da177e2005-04-16 15:20:36 -07001065};
1066
Brian Haleyd5fdd6b2009-06-23 04:31:07 -07001067int icmpv6_err_convert(u8 type, u8 code, int *err)
Linus Torvalds1da177e2005-04-16 15:20:36 -07001068{
1069 int fatal = 0;
1070
1071 *err = EPROTO;
1072
1073 switch (type) {
1074 case ICMPV6_DEST_UNREACH:
1075 fatal = 1;
Jiri Bohac61e76b12013-08-30 11:18:45 +02001076 if (code < ARRAY_SIZE(tab_unreach)) {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001077 *err = tab_unreach[code].err;
1078 fatal = tab_unreach[code].fatal;
1079 }
1080 break;
1081
1082 case ICMPV6_PKT_TOOBIG:
1083 *err = EMSGSIZE;
1084 break;
YOSHIFUJI Hideaki1ab14572007-02-09 23:24:49 +09001085
Linus Torvalds1da177e2005-04-16 15:20:36 -07001086 case ICMPV6_PARAMPROB:
1087 *err = EPROTO;
1088 fatal = 1;
1089 break;
1090
1091 case ICMPV6_TIME_EXCEED:
1092 *err = EHOSTUNREACH;
1093 break;
Stephen Hemminger3ff50b72007-04-20 17:09:22 -07001094 }
Linus Torvalds1da177e2005-04-16 15:20:36 -07001095
1096 return fatal;
1097}
YOSHIFUJI Hideaki71590392007-02-22 22:05:40 +09001098EXPORT_SYMBOL(icmpv6_err_convert);
1099
Linus Torvalds1da177e2005-04-16 15:20:36 -07001100#ifdef CONFIG_SYSCTL
stephen hemmingere8243532013-12-29 14:03:31 -08001101static struct ctl_table ipv6_icmp_table_template[] = {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001102 {
Linus Torvalds1da177e2005-04-16 15:20:36 -07001103 .procname = "ratelimit",
Daniel Lezcano41a76902008-01-10 03:02:40 -08001104 .data = &init_net.ipv6.sysctl.icmpv6_time,
Linus Torvalds1da177e2005-04-16 15:20:36 -07001105 .maxlen = sizeof(int),
1106 .mode = 0644,
Alexey Dobriyan6d9f2392008-11-03 18:21:05 -08001107 .proc_handler = proc_dointvec_ms_jiffies,
Linus Torvalds1da177e2005-04-16 15:20:36 -07001108 },
Virgile Jarrye6f86b02018-08-10 17:48:15 +02001109 {
1110 .procname = "echo_ignore_all",
1111 .data = &init_net.ipv6.sysctl.icmpv6_echo_ignore_all,
1112 .maxlen = sizeof(int),
1113 .mode = 0644,
1114 .proc_handler = proc_dointvec,
1115 },
Eric W. Biedermanf8572d82009-11-05 13:32:03 -08001116 { },
Linus Torvalds1da177e2005-04-16 15:20:36 -07001117};
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001118
Alexey Dobriyan2c8c1e72010-01-17 03:35:32 +00001119struct ctl_table * __net_init ipv6_icmp_sysctl_init(struct net *net)
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001120{
1121 struct ctl_table *table;
1122
1123 table = kmemdup(ipv6_icmp_table_template,
1124 sizeof(ipv6_icmp_table_template),
1125 GFP_KERNEL);
YOSHIFUJI Hideaki5ee09102008-02-28 00:24:28 +09001126
Virgile Jarrye6f86b02018-08-10 17:48:15 +02001127 if (table) {
YOSHIFUJI Hideaki5ee09102008-02-28 00:24:28 +09001128 table[0].data = &net->ipv6.sysctl.icmpv6_time;
Virgile Jarrye6f86b02018-08-10 17:48:15 +02001129 table[1].data = &net->ipv6.sysctl.icmpv6_echo_ignore_all;
1130 }
Daniel Lezcano760f2d02008-01-10 02:53:43 -08001131 return table;
1132}
Linus Torvalds1da177e2005-04-16 15:20:36 -07001133#endif