]> bbs.cooldavid.org Git - net-next-2.6.git/blame - net/sctp/ipv6.c
sctp: Prevent uninitialized memory access
[net-next-2.6.git] / net / sctp / ipv6.c
CommitLineData
60c778b2 1/* SCTP kernel implementation
1da177e4
LT
2 * (C) Copyright IBM Corp. 2002, 2004
3 * Copyright (c) 2001 Nokia, Inc.
4 * Copyright (c) 2001 La Monte H.P. Yarroll
5 * Copyright (c) 2002-2003 Intel Corp.
6 *
60c778b2 7 * This file is part of the SCTP kernel implementation
1da177e4
LT
8 *
9 * SCTP over IPv6.
10 *
60c778b2 11 * This SCTP implementation is free software;
1da177e4
LT
12 * you can redistribute it and/or modify it under the terms of
13 * the GNU General Public License as published by
14 * the Free Software Foundation; either version 2, or (at your option)
15 * any later version.
16 *
60c778b2 17 * This SCTP implementation is distributed in the hope that it
1da177e4
LT
18 * will be useful, but WITHOUT ANY WARRANTY; without even the implied
19 * ************************
20 * warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
21 * See the GNU General Public License for more details.
22 *
23 * You should have received a copy of the GNU General Public License
24 * along with GNU CC; see the file COPYING. If not, write to
25 * the Free Software Foundation, 59 Temple Place - Suite 330,
26 * Boston, MA 02111-1307, USA.
27 *
28 * Please send any bug reports or fixes you make to the
29 * email address(es):
30 * lksctp developers <lksctp-developers@lists.sourceforge.net>
31 *
32 * Or submit a bug report through the following website:
33 * http://www.sf.net/projects/lksctp
34 *
35 * Written or modified by:
36 * Le Yanqun <yanqun.le@nokia.com>
37 * Hui Huang <hui.huang@nokia.com>
38 * La Monte H.P. Yarroll <piggy@acm.org>
39 * Sridhar Samudrala <sri@us.ibm.com>
40 * Jon Grimm <jgrimm@us.ibm.com>
41 * Ardelle Fan <ardelle.fan@intel.com>
42 *
43 * Based on:
44 * linux/net/ipv6/tcp_ipv6.c
45 *
46 * Any bugs reported given to us we will try to fix... any fixes shared will
47 * be incorporated into the next SCTP release.
48 */
49
50#include <linux/module.h>
51#include <linux/errno.h>
52#include <linux/types.h>
53#include <linux/socket.h>
54#include <linux/sockios.h>
55#include <linux/net.h>
1da177e4
LT
56#include <linux/in.h>
57#include <linux/in6.h>
58#include <linux/netdevice.h>
59#include <linux/init.h>
60#include <linux/ipsec.h>
61
62#include <linux/ipv6.h>
63#include <linux/icmpv6.h>
64#include <linux/random.h>
65#include <linux/seq_file.h>
66
67#include <net/protocol.h>
1da177e4 68#include <net/ndisc.h>
c752f073 69#include <net/ip.h>
1da177e4
LT
70#include <net/ipv6.h>
71#include <net/transp_v6.h>
72#include <net/addrconf.h>
73#include <net/ip6_route.h>
74#include <net/inet_common.h>
75#include <net/inet_ecn.h>
76#include <net/sctp/sctp.h>
77
78#include <asm/uaccess.h>
79
29303547
VY
80/* Event handler for inet6 address addition/deletion events.
81 * The sctp_local_addr_list needs to be protocted by a spin lock since
82 * multiple notifiers (say IPv4 and IPv6) may be running at the same
83 * time and thus corrupt the list.
84 * The reader side is protected with RCU.
85 */
24123186
AB
86static int sctp_inet6addr_event(struct notifier_block *this, unsigned long ev,
87 void *ptr)
29c7cf96
SS
88{
89 struct inet6_ifaddr *ifa = (struct inet6_ifaddr *)ptr;
29303547
VY
90 struct sctp_sockaddr_entry *addr = NULL;
91 struct sctp_sockaddr_entry *temp;
22626216 92 int found = 0;
29c7cf96
SS
93
94 switch (ev) {
95 case NETDEV_UP:
96 addr = kmalloc(sizeof(struct sctp_sockaddr_entry), GFP_ATOMIC);
97 if (addr) {
98 addr->a.v6.sin6_family = AF_INET6;
99 addr->a.v6.sin6_port = 0;
100 memcpy(&addr->a.v6.sin6_addr, &ifa->addr,
101 sizeof(struct in6_addr));
102 addr->a.v6.sin6_scope_id = ifa->idev->dev->ifindex;
29303547
VY
103 addr->valid = 1;
104 spin_lock_bh(&sctp_local_addr_lock);
105 list_add_tail_rcu(&addr->list, &sctp_local_addr_list);
106 spin_unlock_bh(&sctp_local_addr_lock);
29c7cf96
SS
107 }
108 break;
109 case NETDEV_DOWN:
29303547
VY
110 spin_lock_bh(&sctp_local_addr_lock);
111 list_for_each_entry_safe(addr, temp,
112 &sctp_local_addr_list, list) {
a40a7d15
PE
113 if (addr->a.sa.sa_family == AF_INET6 &&
114 ipv6_addr_equal(&addr->a.v6.sin6_addr,
115 &ifa->addr)) {
22626216 116 found = 1;
29303547
VY
117 addr->valid = 0;
118 list_del_rcu(&addr->list);
29c7cf96
SS
119 break;
120 }
121 }
29303547 122 spin_unlock_bh(&sctp_local_addr_lock);
22626216 123 if (found)
29303547 124 call_rcu(&addr->rcu, sctp_local_addr_free);
29c7cf96
SS
125 break;
126 }
127
128 return NOTIFY_DONE;
129}
130
1da177e4 131static struct notifier_block sctp_inet6addr_notifier = {
29c7cf96 132 .notifier_call = sctp_inet6addr_event,
1da177e4
LT
133};
134
135/* ICMP error handler. */
136SCTP_STATIC void sctp_v6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
04ce6909 137 int type, int code, int offset, __be32 info)
1da177e4
LT
138{
139 struct inet6_dev *idev;
1da177e4 140 struct sock *sk;
1da177e4
LT
141 struct sctp_association *asoc;
142 struct sctp_transport *transport;
143 struct ipv6_pinfo *np;
2e07fa9c 144 sk_buff_data_t saveip, savesctp;
1da177e4
LT
145 int err;
146
147 idev = in6_dev_get(skb->dev);
148
149 /* Fix up skb to look at the embedded net header. */
b0e380b1
ACM
150 saveip = skb->network_header;
151 savesctp = skb->transport_header;
1ced98e8 152 skb_reset_network_header(skb);
a27ef749
ACM
153 skb_set_transport_header(skb, offset);
154 sk = sctp_err_lookup(AF_INET6, skb, sctp_hdr(skb), &asoc, &transport);
1da177e4 155 /* Put back, the original pointers. */
b0e380b1
ACM
156 skb->network_header = saveip;
157 skb->transport_header = savesctp;
1da177e4
LT
158 if (!sk) {
159 ICMP6_INC_STATS_BH(idev, ICMP6_MIB_INERRORS);
160 goto out;
161 }
162
163 /* Warning: The sock lock is held. Remember to call
164 * sctp_err_finish!
165 */
166
167 switch (type) {
168 case ICMPV6_PKT_TOOBIG:
169 sctp_icmp_frag_needed(sk, asoc, transport, ntohl(info));
170 goto out_unlock;
171 case ICMPV6_PARAMPROB:
172 if (ICMPV6_UNK_NEXTHDR == code) {
d1ad1ff2 173 sctp_icmp_proto_unreachable(sk, asoc, transport);
1da177e4
LT
174 goto out_unlock;
175 }
176 break;
177 default:
178 break;
179 }
180
181 np = inet6_sk(sk);
182 icmpv6_err_convert(type, code, &err);
183 if (!sock_owned_by_user(sk) && np->recverr) {
184 sk->sk_err = err;
185 sk->sk_error_report(sk);
186 } else { /* Only an error on timeout */
187 sk->sk_err_soft = err;
188 }
189
190out_unlock:
d1ad1ff2 191 sctp_err_finish(sk, asoc);
1da177e4
LT
192out:
193 if (likely(idev != NULL))
194 in6_dev_put(idev);
195}
196
197/* Based on tcp_v6_xmit() in tcp_ipv6.c. */
198static int sctp_v6_xmit(struct sk_buff *skb, struct sctp_transport *transport,
199 int ipfragok)
200{
201 struct sock *sk = skb->sk;
202 struct ipv6_pinfo *np = inet6_sk(sk);
203 struct flowi fl;
204
205 memset(&fl, 0, sizeof(fl));
206
207 fl.proto = sk->sk_protocol;
208
209 /* Fill in the dest address from the route entry passed with the skb
210 * and the source address from the transport.
211 */
b3f5b3b6 212 ipv6_addr_copy(&fl.fl6_dst, &transport->ipaddr.v6.sin6_addr);
a9266268 213 ipv6_addr_copy(&fl.fl6_src, &transport->saddr.v6.sin6_addr);
1da177e4
LT
214
215 fl.fl6_flowlabel = np->flow_label;
216 IP6_ECN_flow_xmit(sk, fl.fl6_flowlabel);
217 if (ipv6_addr_type(&fl.fl6_src) & IPV6_ADDR_LINKLOCAL)
a9266268 218 fl.oif = transport->saddr.v6.sin6_scope_id;
1da177e4
LT
219 else
220 fl.oif = sk->sk_bound_dev_if;
1da177e4
LT
221
222 if (np->opt && np->opt->srcrt) {
223 struct rt0_hdr *rt0 = (struct rt0_hdr *) np->opt->srcrt;
224 ipv6_addr_copy(&fl.fl6_dst, rt0->addr);
225 }
226
227 SCTP_DEBUG_PRINTK("%s: skb:%p, len:%d, "
46b86a2d 228 "src:" NIP6_FMT " dst:" NIP6_FMT "\n",
0dc47877 229 __func__, skb, skb->len,
1da177e4
LT
230 NIP6(fl.fl6_src), NIP6(fl.fl6_dst));
231
232 SCTP_INC_STATS(SCTP_MIB_OUTSCTPPACKS);
233
234 return ip6_xmit(sk, skb, &fl, np->opt, ipfragok);
235}
236
237/* Returns the dst cache entry for the given source and destination ip
238 * addresses.
239 */
240static struct dst_entry *sctp_v6_get_dst(struct sctp_association *asoc,
241 union sctp_addr *daddr,
242 union sctp_addr *saddr)
243{
244 struct dst_entry *dst;
245 struct flowi fl;
246
247 memset(&fl, 0, sizeof(fl));
248 ipv6_addr_copy(&fl.fl6_dst, &daddr->v6.sin6_addr);
249 if (ipv6_addr_type(&daddr->v6.sin6_addr) & IPV6_ADDR_LINKLOCAL)
250 fl.oif = daddr->v6.sin6_scope_id;
d808ad9a 251
1da177e4 252
46b86a2d 253 SCTP_DEBUG_PRINTK("%s: DST=" NIP6_FMT " ",
0dc47877 254 __func__, NIP6(fl.fl6_dst));
1da177e4
LT
255
256 if (saddr) {
257 ipv6_addr_copy(&fl.fl6_src, &saddr->v6.sin6_addr);
258 SCTP_DEBUG_PRINTK(
46b86a2d 259 "SRC=" NIP6_FMT " - ",
1da177e4
LT
260 NIP6(fl.fl6_src));
261 }
262
4591db4f 263 dst = ip6_route_output(&init_net, NULL, &fl);
4251320f 264 if (!dst->error) {
1da177e4
LT
265 struct rt6_info *rt;
266 rt = (struct rt6_info *)dst;
267 SCTP_DEBUG_PRINTK(
46b86a2d 268 "rt6_dst:" NIP6_FMT " rt6_src:" NIP6_FMT "\n",
1da177e4 269 NIP6(rt->rt6i_dst.addr), NIP6(rt->rt6i_src.addr));
4251320f 270 return dst;
1da177e4 271 }
4251320f
VN
272 SCTP_DEBUG_PRINTK("NO ROUTE\n");
273 dst_release(dst);
274 return NULL;
1da177e4
LT
275}
276
277/* Returns the number of consecutive initial bits that match in the 2 ipv6
278 * addresses.
279 */
280static inline int sctp_v6_addr_match_len(union sctp_addr *s1,
281 union sctp_addr *s2)
282{
283 struct in6_addr *a1 = &s1->v6.sin6_addr;
284 struct in6_addr *a2 = &s2->v6.sin6_addr;
285 int i, j;
286
287 for (i = 0; i < 4 ; i++) {
dbc16db1 288 __be32 a1xora2;
1da177e4
LT
289
290 a1xora2 = a1->s6_addr32[i] ^ a2->s6_addr32[i];
291
292 if ((j = fls(ntohl(a1xora2))))
293 return (i * 32 + 32 - j);
294 }
295
296 return (i*32);
297}
298
299/* Fills in the source address(saddr) based on the destination address(daddr)
300 * and asoc's bind address list.
301 */
e5117101
YH
302static void sctp_v6_get_saddr(struct sctp_sock *sk,
303 struct sctp_association *asoc,
1da177e4
LT
304 struct dst_entry *dst,
305 union sctp_addr *daddr,
306 union sctp_addr *saddr)
307{
308 struct sctp_bind_addr *bp;
1da177e4 309 struct sctp_sockaddr_entry *laddr;
1da177e4
LT
310 sctp_scope_t scope;
311 union sctp_addr *baddr = NULL;
312 __u8 matchlen = 0;
313 __u8 bmatchlen;
314
315 SCTP_DEBUG_PRINTK("%s: asoc:%p dst:%p "
46b86a2d 316 "daddr:" NIP6_FMT " ",
0dc47877 317 __func__, asoc, dst, NIP6(daddr->v6.sin6_addr));
1da177e4
LT
318
319 if (!asoc) {
5e5f3f0f 320 ipv6_dev_get_saddr(dst ? ip6_dst_idev(dst)->dev : NULL,
7cbca67c 321 &daddr->v6.sin6_addr,
e5117101 322 inet6_sk(&sk->inet.sk)->srcprefs,
7cbca67c 323 &saddr->v6.sin6_addr);
46b86a2d 324 SCTP_DEBUG_PRINTK("saddr from ipv6_get_saddr: " NIP6_FMT "\n",
1da177e4
LT
325 NIP6(saddr->v6.sin6_addr));
326 return;
327 }
328
329 scope = sctp_scope(daddr);
330
331 bp = &asoc->base.bind_addr;
1da177e4
LT
332
333 /* Go through the bind address list and find the best source address
334 * that matches the scope of the destination address.
335 */
559cf710
VY
336 rcu_read_lock();
337 list_for_each_entry_rcu(laddr, &bp->address_list, list) {
338 if (!laddr->valid)
339 continue;
f57d96b2 340 if ((laddr->state == SCTP_ADDR_SRC) &&
6244be4e
AV
341 (laddr->a.sa.sa_family == AF_INET6) &&
342 (scope <= sctp_scope(&laddr->a))) {
d3f7a54a 343 bmatchlen = sctp_v6_addr_match_len(daddr, &laddr->a);
1da177e4 344 if (!baddr || (matchlen < bmatchlen)) {
d3f7a54a 345 baddr = &laddr->a;
1da177e4
LT
346 matchlen = bmatchlen;
347 }
348 }
349 }
350
351 if (baddr) {
352 memcpy(saddr, baddr, sizeof(union sctp_addr));
46b86a2d 353 SCTP_DEBUG_PRINTK("saddr: " NIP6_FMT "\n",
1da177e4
LT
354 NIP6(saddr->v6.sin6_addr));
355 } else {
356 printk(KERN_ERR "%s: asoc:%p Could not find a valid source "
46b86a2d 357 "address for the dest:" NIP6_FMT "\n",
0dc47877 358 __func__, asoc, NIP6(daddr->v6.sin6_addr));
1da177e4
LT
359 }
360
559cf710 361 rcu_read_unlock();
1da177e4
LT
362}
363
364/* Make a copy of all potential local addresses. */
365static void sctp_v6_copy_addrlist(struct list_head *addrlist,
366 struct net_device *dev)
367{
368 struct inet6_dev *in6_dev;
369 struct inet6_ifaddr *ifp;
370 struct sctp_sockaddr_entry *addr;
371
8814c4b5 372 rcu_read_lock();
1da177e4 373 if ((in6_dev = __in6_dev_get(dev)) == NULL) {
8814c4b5 374 rcu_read_unlock();
1da177e4
LT
375 return;
376 }
377
e2eb8d45 378 read_lock_bh(&in6_dev->lock);
1da177e4
LT
379 for (ifp = in6_dev->addr_list; ifp; ifp = ifp->if_next) {
380 /* Add the address to the local list. */
381 addr = t_new(struct sctp_sockaddr_entry, GFP_ATOMIC);
382 if (addr) {
2a6fd78a
AV
383 addr->a.v6.sin6_family = AF_INET6;
384 addr->a.v6.sin6_port = 0;
385 addr->a.v6.sin6_addr = ifp->addr;
386 addr->a.v6.sin6_scope_id = dev->ifindex;
29303547 387 addr->valid = 1;
1da177e4 388 INIT_LIST_HEAD(&addr->list);
29303547 389 INIT_RCU_HEAD(&addr->rcu);
1da177e4
LT
390 list_add_tail(&addr->list, addrlist);
391 }
392 }
393
e2eb8d45 394 read_unlock_bh(&in6_dev->lock);
8814c4b5 395 rcu_read_unlock();
1da177e4
LT
396}
397
398/* Initialize a sockaddr_storage from in incoming skb. */
399static void sctp_v6_from_skb(union sctp_addr *addr,struct sk_buff *skb,
400 int is_saddr)
401{
402 void *from;
d55c41b1 403 __be16 *port;
1da177e4
LT
404 struct sctphdr *sh;
405
406 port = &addr->v6.sin6_port;
407 addr->v6.sin6_family = AF_INET6;
408 addr->v6.sin6_flowinfo = 0; /* FIXME */
409 addr->v6.sin6_scope_id = ((struct inet6_skb_parm *)skb->cb)->iif;
410
2c0fd387 411 sh = sctp_hdr(skb);
1da177e4 412 if (is_saddr) {
d55c41b1 413 *port = sh->source;
0660e03f 414 from = &ipv6_hdr(skb)->saddr;
1da177e4 415 } else {
d55c41b1 416 *port = sh->dest;
0660e03f 417 from = &ipv6_hdr(skb)->daddr;
1da177e4
LT
418 }
419 ipv6_addr_copy(&addr->v6.sin6_addr, from);
420}
421
422/* Initialize an sctp_addr from a socket. */
423static void sctp_v6_from_sk(union sctp_addr *addr, struct sock *sk)
424{
425 addr->v6.sin6_family = AF_INET6;
7dcdbd95 426 addr->v6.sin6_port = 0;
1da177e4
LT
427 addr->v6.sin6_addr = inet6_sk(sk)->rcv_saddr;
428}
429
430/* Initialize sk->sk_rcv_saddr from sctp_addr. */
431static void sctp_v6_to_sk_saddr(union sctp_addr *addr, struct sock *sk)
432{
433 if (addr->sa.sa_family == AF_INET && sctp_sk(sk)->v4mapped) {
434 inet6_sk(sk)->rcv_saddr.s6_addr32[0] = 0;
435 inet6_sk(sk)->rcv_saddr.s6_addr32[1] = 0;
436 inet6_sk(sk)->rcv_saddr.s6_addr32[2] = htonl(0x0000ffff);
437 inet6_sk(sk)->rcv_saddr.s6_addr32[3] =
438 addr->v4.sin_addr.s_addr;
439 } else {
440 inet6_sk(sk)->rcv_saddr = addr->v6.sin6_addr;
441 }
442}
443
444/* Initialize sk->sk_daddr from sctp_addr. */
445static void sctp_v6_to_sk_daddr(union sctp_addr *addr, struct sock *sk)
446{
447 if (addr->sa.sa_family == AF_INET && sctp_sk(sk)->v4mapped) {
448 inet6_sk(sk)->daddr.s6_addr32[0] = 0;
449 inet6_sk(sk)->daddr.s6_addr32[1] = 0;
450 inet6_sk(sk)->daddr.s6_addr32[2] = htonl(0x0000ffff);
451 inet6_sk(sk)->daddr.s6_addr32[3] = addr->v4.sin_addr.s_addr;
452 } else {
453 inet6_sk(sk)->daddr = addr->v6.sin6_addr;
454 }
455}
456
457/* Initialize a sctp_addr from an address parameter. */
458static void sctp_v6_from_addr_param(union sctp_addr *addr,
459 union sctp_addr_param *param,
dd86d136 460 __be16 port, int iif)
1da177e4
LT
461{
462 addr->v6.sin6_family = AF_INET6;
463 addr->v6.sin6_port = port;
464 addr->v6.sin6_flowinfo = 0; /* BUG */
465 ipv6_addr_copy(&addr->v6.sin6_addr, &param->v6.addr);
466 addr->v6.sin6_scope_id = iif;
467}
468
469/* Initialize an address parameter from a sctp_addr and return the length
470 * of the address parameter.
471 */
472static int sctp_v6_to_addr_param(const union sctp_addr *addr,
473 union sctp_addr_param *param)
474{
475 int length = sizeof(sctp_ipv6addr_param_t);
476
477 param->v6.param_hdr.type = SCTP_PARAM_IPV6_ADDRESS;
dbc16db1 478 param->v6.param_hdr.length = htons(length);
1da177e4
LT
479 ipv6_addr_copy(&param->v6.addr, &addr->v6.sin6_addr);
480
481 return length;
482}
483
484/* Initialize a sctp_addr from a dst_entry. */
485static void sctp_v6_dst_saddr(union sctp_addr *addr, struct dst_entry *dst,
854d43a4 486 __be16 port)
1da177e4
LT
487{
488 struct rt6_info *rt = (struct rt6_info *)dst;
489 addr->sa.sa_family = AF_INET6;
490 addr->v6.sin6_port = port;
491 ipv6_addr_copy(&addr->v6.sin6_addr, &rt->rt6i_src.addr);
492}
493
494/* Compare addresses exactly.
495 * v4-mapped-v6 is also in consideration.
496 */
497static int sctp_v6_cmp_addr(const union sctp_addr *addr1,
498 const union sctp_addr *addr2)
499{
500 if (addr1->sa.sa_family != addr2->sa.sa_family) {
501 if (addr1->sa.sa_family == AF_INET &&
502 addr2->sa.sa_family == AF_INET6 &&
e773e4fa 503 ipv6_addr_v4mapped(&addr2->v6.sin6_addr)) {
1da177e4
LT
504 if (addr2->v6.sin6_port == addr1->v4.sin_port &&
505 addr2->v6.sin6_addr.s6_addr32[3] ==
506 addr1->v4.sin_addr.s_addr)
507 return 1;
508 }
509 if (addr2->sa.sa_family == AF_INET &&
510 addr1->sa.sa_family == AF_INET6 &&
e773e4fa 511 ipv6_addr_v4mapped(&addr1->v6.sin6_addr)) {
1da177e4
LT
512 if (addr1->v6.sin6_port == addr2->v4.sin_port &&
513 addr1->v6.sin6_addr.s6_addr32[3] ==
514 addr2->v4.sin_addr.s_addr)
515 return 1;
516 }
517 return 0;
518 }
519 if (!ipv6_addr_equal(&addr1->v6.sin6_addr, &addr2->v6.sin6_addr))
520 return 0;
521 /* If this is a linklocal address, compare the scope_id. */
522 if (ipv6_addr_type(&addr1->v6.sin6_addr) & IPV6_ADDR_LINKLOCAL) {
523 if (addr1->v6.sin6_scope_id && addr2->v6.sin6_scope_id &&
524 (addr1->v6.sin6_scope_id != addr2->v6.sin6_scope_id)) {
525 return 0;
526 }
527 }
528
529 return 1;
530}
531
532/* Initialize addr struct to INADDR_ANY. */
6fbfa9f9 533static void sctp_v6_inaddr_any(union sctp_addr *addr, __be16 port)
1da177e4
LT
534{
535 memset(addr, 0x00, sizeof(union sctp_addr));
536 addr->v6.sin6_family = AF_INET6;
537 addr->v6.sin6_port = port;
538}
539
540/* Is this a wildcard address? */
541static int sctp_v6_is_any(const union sctp_addr *addr)
542{
b9b9e10f 543 return ipv6_addr_any(&addr->v6.sin6_addr);
1da177e4
LT
544}
545
546/* Should this be available for binding? */
547static int sctp_v6_available(union sctp_addr *addr, struct sctp_sock *sp)
548{
549 int type;
550 struct in6_addr *in6 = (struct in6_addr *)&addr->v6.sin6_addr;
551
552 type = ipv6_addr_type(in6);
553 if (IPV6_ADDR_ANY == type)
554 return 1;
555 if (type == IPV6_ADDR_MAPPED) {
556 if (sp && !sp->v4mapped)
557 return 0;
558 if (sp && ipv6_only_sock(sctp_opt2sk(sp)))
559 return 0;
560 sctp_v6_map_v4(addr);
561 return sctp_get_af_specific(AF_INET)->available(addr, sp);
562 }
563 if (!(type & IPV6_ADDR_UNICAST))
564 return 0;
565
bfeade08 566 return ipv6_chk_addr(&init_net, in6, NULL, 0);
1da177e4
LT
567}
568
569/* This function checks if the address is a valid address to be used for
570 * SCTP.
571 *
572 * Output:
573 * Return 0 - If the address is a non-unicast or an illegal address.
574 * Return 1 - If the address is a unicast.
575 */
5636bef7
VY
576static int sctp_v6_addr_valid(union sctp_addr *addr,
577 struct sctp_sock *sp,
578 const struct sk_buff *skb)
1da177e4
LT
579{
580 int ret = ipv6_addr_type(&addr->v6.sin6_addr);
581
582 /* Support v4-mapped-v6 address. */
583 if (ret == IPV6_ADDR_MAPPED) {
584 /* Note: This routine is used in input, so v4-mapped-v6
585 * are disallowed here when there is no sctp_sock.
586 */
587 if (!sp || !sp->v4mapped)
588 return 0;
589 if (sp && ipv6_only_sock(sctp_opt2sk(sp)))
590 return 0;
591 sctp_v6_map_v4(addr);
5636bef7 592 return sctp_get_af_specific(AF_INET)->addr_valid(addr, sp, skb);
1da177e4
LT
593 }
594
595 /* Is this a non-unicast address */
596 if (!(ret & IPV6_ADDR_UNICAST))
597 return 0;
598
599 return 1;
600}
601
602/* What is the scope of 'addr'? */
603static sctp_scope_t sctp_v6_scope(union sctp_addr *addr)
604{
605 int v6scope;
606 sctp_scope_t retval;
607
608 /* The IPv6 scope is really a set of bit fields.
609 * See IFA_* in <net/if_inet6.h>. Map to a generic SCTP scope.
610 */
611
612 v6scope = ipv6_addr_scope(&addr->v6.sin6_addr);
613 switch (v6scope) {
614 case IFA_HOST:
615 retval = SCTP_SCOPE_LOOPBACK;
616 break;
617 case IFA_LINK:
618 retval = SCTP_SCOPE_LINK;
619 break;
620 case IFA_SITE:
621 retval = SCTP_SCOPE_PRIVATE;
622 break;
623 default:
624 retval = SCTP_SCOPE_GLOBAL;
625 break;
3ff50b79 626 }
1da177e4
LT
627
628 return retval;
629}
630
631/* Create and initialize a new sk for the socket to be returned by accept(). */
632static struct sock *sctp_v6_create_accept_sk(struct sock *sk,
633 struct sctp_association *asoc)
634{
635 struct inet_sock *inet = inet_sk(sk);
636 struct sock *newsk;
637 struct inet_sock *newinet;
638 struct ipv6_pinfo *newnp, *np = inet6_sk(sk);
639 struct sctp6_sock *newsctp6sk;
640
3b1e0a65 641 newsk = sk_alloc(sock_net(sk), PF_INET6, GFP_KERNEL, sk->sk_prot);
1da177e4
LT
642 if (!newsk)
643 goto out;
644
645 sock_init_data(NULL, newsk);
646
647 newsk->sk_type = SOCK_STREAM;
648
649 newsk->sk_prot = sk->sk_prot;
650 newsk->sk_no_check = sk->sk_no_check;
651 newsk->sk_reuse = sk->sk_reuse;
652
653 newsk->sk_destruct = inet_sock_destruct;
654 newsk->sk_family = PF_INET6;
655 newsk->sk_protocol = IPPROTO_SCTP;
656 newsk->sk_backlog_rcv = sk->sk_prot->backlog_rcv;
657 newsk->sk_shutdown = sk->sk_shutdown;
658 sock_reset_flag(sk, SOCK_ZAPPED);
659
660 newsctp6sk = (struct sctp6_sock *)newsk;
661 inet_sk(newsk)->pinet6 = &newsctp6sk->inet6;
662
b225b884
DJ
663 sctp_sk(newsk)->v4mapped = sctp_sk(sk)->v4mapped;
664
1da177e4
LT
665 newinet = inet_sk(newsk);
666 newnp = inet6_sk(newsk);
667
668 memcpy(newnp, np, sizeof(struct ipv6_pinfo));
669
670 /* Initialize sk's sport, dport, rcv_saddr and daddr for getsockname()
671 * and getpeername().
672 */
673 newinet->sport = inet->sport;
674 newnp->saddr = np->saddr;
675 newnp->rcv_saddr = np->rcv_saddr;
676 newinet->dport = htons(asoc->peer.port);
677 sctp_v6_to_sk_daddr(&asoc->peer.primary_addr, newsk);
678
679 /* Init the ipv4 part of the socket since we can have sockets
680 * using v6 API for ipv4.
681 */
682 newinet->uc_ttl = -1;
683 newinet->mc_loop = 1;
684 newinet->mc_ttl = 1;
685 newinet->mc_index = 0;
686 newinet->mc_list = NULL;
687
688 if (ipv4_config.no_pmtu_disc)
689 newinet->pmtudisc = IP_PMTUDISC_DONT;
690 else
691 newinet->pmtudisc = IP_PMTUDISC_WANT;
692
e6848976 693 sk_refcnt_debug_inc(newsk);
1da177e4
LT
694
695 if (newsk->sk_prot->init(newsk)) {
696 sk_common_release(newsk);
697 newsk = NULL;
698 }
699
700out:
701 return newsk;
702}
703
704/* Map v4 address to mapped v6 address */
705static void sctp_v6_addr_v4map(struct sctp_sock *sp, union sctp_addr *addr)
706{
707 if (sp->v4mapped && AF_INET == addr->sa.sa_family)
708 sctp_v4_map_v6(addr);
709}
710
711/* Where did this skb come from? */
712static int sctp_v6_skb_iif(const struct sk_buff *skb)
713{
714 struct inet6_skb_parm *opt = (struct inet6_skb_parm *) skb->cb;
715 return opt->iif;
716}
717
718/* Was this packet marked by Explicit Congestion Notification? */
719static int sctp_v6_is_ce(const struct sk_buff *skb)
720{
0660e03f 721 return *((__u32 *)(ipv6_hdr(skb))) & htonl(1 << 20);
1da177e4
LT
722}
723
724/* Dump the v6 addr to the seq file. */
725static void sctp_v6_seq_dump_addr(struct seq_file *seq, union sctp_addr *addr)
726{
46b86a2d 727 seq_printf(seq, NIP6_FMT " ", NIP6(addr->v6.sin6_addr));
1da177e4
LT
728}
729
b9031d9d
VY
730static void sctp_v6_ecn_capable(struct sock *sk)
731{
732 inet6_sk(sk)->tclass |= INET_ECN_ECT_0;
733}
734
1da177e4
LT
735/* Initialize a PF_INET6 socket msg_name. */
736static void sctp_inet6_msgname(char *msgname, int *addr_len)
737{
738 struct sockaddr_in6 *sin6;
739
740 sin6 = (struct sockaddr_in6 *)msgname;
741 sin6->sin6_family = AF_INET6;
742 sin6->sin6_flowinfo = 0;
743 sin6->sin6_scope_id = 0; /*FIXME */
744 *addr_len = sizeof(struct sockaddr_in6);
745}
746
747/* Initialize a PF_INET msgname from a ulpevent. */
748static void sctp_inet6_event_msgname(struct sctp_ulpevent *event,
749 char *msgname, int *addrlen)
750{
751 struct sockaddr_in6 *sin6, *sin6from;
752
753 if (msgname) {
754 union sctp_addr *addr;
755 struct sctp_association *asoc;
756
757 asoc = event->asoc;
758 sctp_inet6_msgname(msgname, addrlen);
759 sin6 = (struct sockaddr_in6 *)msgname;
760 sin6->sin6_port = htons(asoc->peer.port);
761 addr = &asoc->peer.primary_addr;
762
763 /* Note: If we go to a common v6 format, this code
764 * will change.
765 */
766
767 /* Map ipv4 address into v4-mapped-on-v6 address. */
768 if (sctp_sk(asoc->base.sk)->v4mapped &&
769 AF_INET == addr->sa.sa_family) {
770 sctp_v4_map_v6((union sctp_addr *)sin6);
771 sin6->sin6_addr.s6_addr32[3] =
772 addr->v4.sin_addr.s_addr;
773 return;
774 }
775
776 sin6from = &asoc->peer.primary_addr.v6;
777 ipv6_addr_copy(&sin6->sin6_addr, &sin6from->sin6_addr);
778 if (ipv6_addr_type(&sin6->sin6_addr) & IPV6_ADDR_LINKLOCAL)
779 sin6->sin6_scope_id = sin6from->sin6_scope_id;
780 }
781}
782
783/* Initialize a msg_name from an inbound skb. */
784static void sctp_inet6_skb_msgname(struct sk_buff *skb, char *msgname,
785 int *addr_len)
786{
787 struct sctphdr *sh;
788 struct sockaddr_in6 *sin6;
789
790 if (msgname) {
791 sctp_inet6_msgname(msgname, addr_len);
792 sin6 = (struct sockaddr_in6 *)msgname;
2c0fd387 793 sh = sctp_hdr(skb);
1da177e4
LT
794 sin6->sin6_port = sh->source;
795
796 /* Map ipv4 address into v4-mapped-on-v6 address. */
797 if (sctp_sk(skb->sk)->v4mapped &&
eddc9ec5 798 ip_hdr(skb)->version == 4) {
1da177e4 799 sctp_v4_map_v6((union sctp_addr *)sin6);
eddc9ec5 800 sin6->sin6_addr.s6_addr32[3] = ip_hdr(skb)->saddr;
1da177e4
LT
801 return;
802 }
803
804 /* Otherwise, just copy the v6 address. */
0660e03f 805 ipv6_addr_copy(&sin6->sin6_addr, &ipv6_hdr(skb)->saddr);
1da177e4
LT
806 if (ipv6_addr_type(&sin6->sin6_addr) & IPV6_ADDR_LINKLOCAL) {
807 struct sctp_ulpevent *ev = sctp_skb2event(skb);
808 sin6->sin6_scope_id = ev->iif;
809 }
810 }
811}
812
813/* Do we support this AF? */
814static int sctp_inet6_af_supported(sa_family_t family, struct sctp_sock *sp)
815{
816 switch (family) {
817 case AF_INET6:
818 return 1;
819 /* v4-mapped-v6 addresses */
820 case AF_INET:
821 if (!__ipv6_only_sock(sctp_opt2sk(sp)) && sp->v4mapped)
822 return 1;
823 default:
824 return 0;
825 }
826}
827
828/* Address matching with wildcards allowed. This extra level
829 * of indirection lets us choose whether a PF_INET6 should
830 * disallow any v4 addresses if we so choose.
831 */
832static int sctp_inet6_cmp_addr(const union sctp_addr *addr1,
833 const union sctp_addr *addr2,
834 struct sctp_sock *opt)
835{
836 struct sctp_af *af1, *af2;
837
838 af1 = sctp_get_af_specific(addr1->sa.sa_family);
839 af2 = sctp_get_af_specific(addr2->sa.sa_family);
840
841 if (!af1 || !af2)
842 return 0;
843 /* Today, wildcard AF_INET/AF_INET6. */
844 if (sctp_is_any(addr1) || sctp_is_any(addr2))
845 return 1;
846
847 if (addr1->sa.sa_family != addr2->sa.sa_family)
848 return 0;
849
850 return af1->cmp_addr(addr1, addr2);
851}
852
853/* Verify that the provided sockaddr looks bindable. Common verification,
854 * has already been taken care of.
855 */
856static int sctp_inet6_bind_verify(struct sctp_sock *opt, union sctp_addr *addr)
857{
858 struct sctp_af *af;
859
860 /* ASSERT: address family has already been verified. */
861 if (addr->sa.sa_family != AF_INET6)
862 af = sctp_get_af_specific(addr->sa.sa_family);
863 else {
1da177e4 864 int type = ipv6_addr_type(&addr->v6.sin6_addr);
6a6ddb2a
SS
865 struct net_device *dev;
866
1da177e4 867 if (type & IPV6_ADDR_LINKLOCAL) {
6a6ddb2a
SS
868 if (!addr->v6.sin6_scope_id)
869 return 0;
881d966b 870 dev = dev_get_by_index(&init_net, addr->v6.sin6_scope_id);
6a6ddb2a 871 if (!dev)
1da177e4 872 return 0;
bfeade08
DL
873 if (!ipv6_chk_addr(&init_net, &addr->v6.sin6_addr,
874 dev, 0)) {
1669d857
VY
875 dev_put(dev);
876 return 0;
877 }
6a6ddb2a 878 dev_put(dev);
1da177e4
LT
879 }
880 af = opt->pf->af;
881 }
882 return af->available(addr, opt);
883}
884
6a6ddb2a 885/* Verify that the provided sockaddr looks sendable. Common verification,
1da177e4
LT
886 * has already been taken care of.
887 */
888static int sctp_inet6_send_verify(struct sctp_sock *opt, union sctp_addr *addr)
889{
890 struct sctp_af *af = NULL;
891
892 /* ASSERT: address family has already been verified. */
893 if (addr->sa.sa_family != AF_INET6)
894 af = sctp_get_af_specific(addr->sa.sa_family);
895 else {
1da177e4 896 int type = ipv6_addr_type(&addr->v6.sin6_addr);
6a6ddb2a
SS
897 struct net_device *dev;
898
1da177e4 899 if (type & IPV6_ADDR_LINKLOCAL) {
6a6ddb2a
SS
900 if (!addr->v6.sin6_scope_id)
901 return 0;
881d966b 902 dev = dev_get_by_index(&init_net, addr->v6.sin6_scope_id);
6a6ddb2a 903 if (!dev)
1da177e4 904 return 0;
6a6ddb2a 905 dev_put(dev);
1da177e4
LT
906 }
907 af = opt->pf->af;
908 }
909
910 return af != NULL;
911}
912
913/* Fill in Supported Address Type information for INIT and INIT-ACK
914 * chunks. Note: In the future, we may want to look at sock options
915 * to determine whether a PF_INET6 socket really wants to have IPV4
916 * addresses.
917 * Returns number of addresses supported.
918 */
919static int sctp_inet6_supported_addrs(const struct sctp_sock *opt,
3dbe8656 920 __be16 *types)
1da177e4
LT
921{
922 types[0] = SCTP_PARAM_IPV4_ADDRESS;
923 types[1] = SCTP_PARAM_IPV6_ADDRESS;
924 return 2;
925}
926
90ddc4f0 927static const struct proto_ops inet6_seqpacket_ops = {
543d9cfe
ACM
928 .family = PF_INET6,
929 .owner = THIS_MODULE,
930 .release = inet6_release,
931 .bind = inet6_bind,
932 .connect = inet_dgram_connect,
933 .socketpair = sock_no_socketpair,
934 .accept = inet_accept,
935 .getname = inet6_getname,
936 .poll = sctp_poll,
937 .ioctl = inet6_ioctl,
938 .listen = sctp_inet_listen,
939 .shutdown = inet_shutdown,
940 .setsockopt = sock_common_setsockopt,
941 .getsockopt = sock_common_getsockopt,
942 .sendmsg = inet_sendmsg,
943 .recvmsg = sock_common_recvmsg,
944 .mmap = sock_no_mmap,
3fdadf7d 945#ifdef CONFIG_COMPAT
543d9cfe
ACM
946 .compat_setsockopt = compat_sock_common_setsockopt,
947 .compat_getsockopt = compat_sock_common_getsockopt,
3fdadf7d 948#endif
1da177e4
LT
949};
950
951static struct inet_protosw sctpv6_seqpacket_protosw = {
952 .type = SOCK_SEQPACKET,
953 .protocol = IPPROTO_SCTP,
954 .prot = &sctpv6_prot,
955 .ops = &inet6_seqpacket_ops,
956 .capability = -1,
957 .no_check = 0,
958 .flags = SCTP_PROTOSW_FLAG
959};
960static struct inet_protosw sctpv6_stream_protosw = {
961 .type = SOCK_STREAM,
962 .protocol = IPPROTO_SCTP,
963 .prot = &sctpv6_prot,
964 .ops = &inet6_seqpacket_ops,
965 .capability = -1,
966 .no_check = 0,
967 .flags = SCTP_PROTOSW_FLAG,
968};
969
e5bbef20 970static int sctp6_rcv(struct sk_buff *skb)
1da177e4 971{
e5bbef20 972 return sctp_rcv(skb) ? -1 : 0;
1da177e4
LT
973}
974
975static struct inet6_protocol sctpv6_protocol = {
976 .handler = sctp6_rcv,
977 .err_handler = sctp_v6_err,
978 .flags = INET6_PROTO_NOPOLICY | INET6_PROTO_FINAL,
979};
980
15efbe76 981static struct sctp_af sctp_af_inet6 = {
543d9cfe
ACM
982 .sa_family = AF_INET6,
983 .sctp_xmit = sctp_v6_xmit,
984 .setsockopt = ipv6_setsockopt,
985 .getsockopt = ipv6_getsockopt,
986 .get_dst = sctp_v6_get_dst,
987 .get_saddr = sctp_v6_get_saddr,
988 .copy_addrlist = sctp_v6_copy_addrlist,
989 .from_skb = sctp_v6_from_skb,
990 .from_sk = sctp_v6_from_sk,
991 .to_sk_saddr = sctp_v6_to_sk_saddr,
992 .to_sk_daddr = sctp_v6_to_sk_daddr,
993 .from_addr_param = sctp_v6_from_addr_param,
994 .to_addr_param = sctp_v6_to_addr_param,
995 .dst_saddr = sctp_v6_dst_saddr,
996 .cmp_addr = sctp_v6_cmp_addr,
997 .scope = sctp_v6_scope,
998 .addr_valid = sctp_v6_addr_valid,
999 .inaddr_any = sctp_v6_inaddr_any,
1000 .is_any = sctp_v6_is_any,
1001 .available = sctp_v6_available,
1002 .skb_iif = sctp_v6_skb_iif,
1003 .is_ce = sctp_v6_is_ce,
1004 .seq_dump_addr = sctp_v6_seq_dump_addr,
b9031d9d 1005 .ecn_capable = sctp_v6_ecn_capable,
543d9cfe
ACM
1006 .net_header_len = sizeof(struct ipv6hdr),
1007 .sockaddr_len = sizeof(struct sockaddr_in6),
3fdadf7d 1008#ifdef CONFIG_COMPAT
543d9cfe
ACM
1009 .compat_setsockopt = compat_ipv6_setsockopt,
1010 .compat_getsockopt = compat_ipv6_getsockopt,
3fdadf7d 1011#endif
1da177e4
LT
1012};
1013
15efbe76 1014static struct sctp_pf sctp_pf_inet6 = {
1da177e4
LT
1015 .event_msgname = sctp_inet6_event_msgname,
1016 .skb_msgname = sctp_inet6_skb_msgname,
1017 .af_supported = sctp_inet6_af_supported,
1018 .cmp_addr = sctp_inet6_cmp_addr,
1019 .bind_verify = sctp_inet6_bind_verify,
1020 .send_verify = sctp_inet6_send_verify,
1021 .supported_addrs = sctp_inet6_supported_addrs,
1022 .create_accept_sk = sctp_v6_create_accept_sk,
1023 .addr_v4map = sctp_v6_addr_v4map,
15efbe76 1024 .af = &sctp_af_inet6,
1da177e4
LT
1025};
1026
827bf122 1027/* Initialize IPv6 support and register with socket layer. */
270637ab 1028void sctp_v6_pf_init(void)
1da177e4 1029{
827bf122 1030 /* Register the SCTP specific PF_INET6 functions. */
15efbe76 1031 sctp_register_pf(&sctp_pf_inet6, PF_INET6);
827bf122
SS
1032
1033 /* Register the SCTP specific AF_INET6 functions. */
15efbe76 1034 sctp_register_af(&sctp_af_inet6);
270637ab
VY
1035}
1036
1037void sctp_v6_pf_exit(void)
1038{
1039 list_del(&sctp_af_inet6.list);
1040}
1041
1042/* Initialize IPv6 support and register with socket layer. */
1043int sctp_v6_protosw_init(void)
1044{
1045 int rc;
827bf122
SS
1046
1047 rc = proto_register(&sctpv6_prot, 1);
1da177e4 1048 if (rc)
827bf122 1049 return rc;
1da177e4
LT
1050
1051 /* Add SCTPv6(UDP and TCP style) to inetsw6 linked list. */
1052 inet6_register_protosw(&sctpv6_seqpacket_protosw);
1053 inet6_register_protosw(&sctpv6_stream_protosw);
1054
827bf122
SS
1055 return 0;
1056}
1da177e4 1057
270637ab
VY
1058void sctp_v6_protosw_exit(void)
1059{
1060 inet6_unregister_protosw(&sctpv6_seqpacket_protosw);
1061 inet6_unregister_protosw(&sctpv6_stream_protosw);
1062 proto_unregister(&sctpv6_prot);
1063}
1064
1065
827bf122
SS
1066/* Register with inet6 layer. */
1067int sctp_v6_add_protocol(void)
1068{
1da177e4
LT
1069 /* Register notifier for inet6 address additions/deletions. */
1070 register_inet6addr_notifier(&sctp_inet6addr_notifier);
827bf122
SS
1071
1072 if (inet6_add_protocol(&sctpv6_protocol, IPPROTO_SCTP) < 0)
1073 return -EAGAIN;
1074
1075 return 0;
1da177e4
LT
1076}
1077
827bf122
SS
1078/* Unregister with inet6 layer. */
1079void sctp_v6_del_protocol(void)
1080{
1081 inet6_del_protocol(&sctpv6_protocol, IPPROTO_SCTP);
1082 unregister_inet6addr_notifier(&sctp_inet6addr_notifier);
1da177e4 1083}