]> bbs.cooldavid.org Git - net-next-2.6.git/blame - net/ipv4/udp.c
udp: add a counter into udp_hslot
[net-next-2.6.git] / net / ipv4 / udp.c
CommitLineData
1da177e4
LT
1/*
2 * INET An implementation of the TCP/IP protocol suite for the LINUX
3 * operating system. INET is implemented using the BSD Socket
4 * interface as the means of communication with the user level.
5 *
6 * The User Datagram Protocol (UDP).
7 *
02c30a84 8 * Authors: Ross Biro
1da177e4
LT
9 * Fred N. van Kempen, <waltje@uWalt.NL.Mugnet.ORG>
10 * Arnt Gulbrandsen, <agulbra@nvg.unit.no>
113aa838 11 * Alan Cox, <alan@lxorguk.ukuu.org.uk>
1da177e4
LT
12 * Hirokazu Takahashi, <taka@valinux.co.jp>
13 *
14 * Fixes:
15 * Alan Cox : verify_area() calls
16 * Alan Cox : stopped close while in use off icmp
17 * messages. Not a fix but a botch that
18 * for udp at least is 'valid'.
19 * Alan Cox : Fixed icmp handling properly
20 * Alan Cox : Correct error for oversized datagrams
e905a9ed
YH
21 * Alan Cox : Tidied select() semantics.
22 * Alan Cox : udp_err() fixed properly, also now
1da177e4
LT
23 * select and read wake correctly on errors
24 * Alan Cox : udp_send verify_area moved to avoid mem leak
25 * Alan Cox : UDP can count its memory
26 * Alan Cox : send to an unknown connection causes
27 * an ECONNREFUSED off the icmp, but
28 * does NOT close.
29 * Alan Cox : Switched to new sk_buff handlers. No more backlog!
30 * Alan Cox : Using generic datagram code. Even smaller and the PEEK
31 * bug no longer crashes it.
32 * Fred Van Kempen : Net2e support for sk->broadcast.
33 * Alan Cox : Uses skb_free_datagram
34 * Alan Cox : Added get/set sockopt support.
35 * Alan Cox : Broadcasting without option set returns EACCES.
36 * Alan Cox : No wakeup calls. Instead we now use the callbacks.
37 * Alan Cox : Use ip_tos and ip_ttl
38 * Alan Cox : SNMP Mibs
39 * Alan Cox : MSG_DONTROUTE, and 0.0.0.0 support.
40 * Matt Dillon : UDP length checks.
41 * Alan Cox : Smarter af_inet used properly.
42 * Alan Cox : Use new kernel side addressing.
43 * Alan Cox : Incorrect return on truncated datagram receive.
44 * Arnt Gulbrandsen : New udp_send and stuff
45 * Alan Cox : Cache last socket
46 * Alan Cox : Route cache
47 * Jon Peatfield : Minor efficiency fix to sendto().
48 * Mike Shaver : RFC1122 checks.
49 * Alan Cox : Nonblocking error fix.
50 * Willy Konynenberg : Transparent proxying support.
51 * Mike McLagan : Routing by source
52 * David S. Miller : New socket lookup architecture.
53 * Last socket cache retained as it
54 * does have a high hit rate.
55 * Olaf Kirch : Don't linearise iovec on sendmsg.
56 * Andi Kleen : Some cleanups, cache destination entry
e905a9ed 57 * for connect.
1da177e4
LT
58 * Vitaly E. Lavrov : Transparent proxy revived after year coma.
59 * Melvin Smith : Check msg_name not msg_namelen in sendto(),
60 * return ENOTCONN for unconnected sockets (POSIX)
61 * Janos Farkas : don't deliver multi/broadcasts to a different
62 * bound-to-device socket
63 * Hirokazu Takahashi : HW checksumming for outgoing UDP
64 * datagrams.
65 * Hirokazu Takahashi : sendfile() on UDP works now.
66 * Arnaldo C. Melo : convert /proc/net/udp to seq_file
67 * YOSHIFUJI Hideaki @USAGI and: Support IPV6_V6ONLY socket option, which
68 * Alexey Kuznetsov: allow both IPv4 and IPv6 sockets to bind
69 * a single port at the same time.
70 * Derek Atkins <derek@ihtfp.com>: Add Encapulation Support
342f0234 71 * James Chapman : Add L2TP encapsulation type.
1da177e4
LT
72 *
73 *
74 * This program is free software; you can redistribute it and/or
75 * modify it under the terms of the GNU General Public License
76 * as published by the Free Software Foundation; either version
77 * 2 of the License, or (at your option) any later version.
78 */
e905a9ed 79
1da177e4
LT
80#include <asm/system.h>
81#include <asm/uaccess.h>
82#include <asm/ioctls.h>
95766fff 83#include <linux/bootmem.h>
8203efb3
ED
84#include <linux/highmem.h>
85#include <linux/swap.h>
1da177e4
LT
86#include <linux/types.h>
87#include <linux/fcntl.h>
88#include <linux/module.h>
89#include <linux/socket.h>
90#include <linux/sockios.h>
14c85021 91#include <linux/igmp.h>
1da177e4
LT
92#include <linux/in.h>
93#include <linux/errno.h>
94#include <linux/timer.h>
95#include <linux/mm.h>
1da177e4 96#include <linux/inet.h>
1da177e4 97#include <linux/netdevice.h>
c752f073 98#include <net/tcp_states.h>
1da177e4
LT
99#include <linux/skbuff.h>
100#include <linux/proc_fs.h>
101#include <linux/seq_file.h>
457c4cbc 102#include <net/net_namespace.h>
1da177e4
LT
103#include <net/icmp.h>
104#include <net/route.h>
1da177e4
LT
105#include <net/checksum.h>
106#include <net/xfrm.h>
ba4e58ec 107#include "udp_impl.h"
1da177e4 108
f86dcc5a 109struct udp_table udp_table __read_mostly;
645ca708 110EXPORT_SYMBOL(udp_table);
1da177e4 111
95766fff 112int sysctl_udp_mem[3] __read_mostly;
95766fff 113EXPORT_SYMBOL(sysctl_udp_mem);
c482c568
ED
114
115int sysctl_udp_rmem_min __read_mostly;
95766fff 116EXPORT_SYMBOL(sysctl_udp_rmem_min);
c482c568
ED
117
118int sysctl_udp_wmem_min __read_mostly;
95766fff
HA
119EXPORT_SYMBOL(sysctl_udp_wmem_min);
120
121atomic_t udp_memory_allocated;
122EXPORT_SYMBOL(udp_memory_allocated);
123
f86dcc5a
ED
124#define MAX_UDP_PORTS 65536
125#define PORTS_PER_CHAIN (MAX_UDP_PORTS / UDP_HTABLE_SIZE_MIN)
98322f22 126
f24d43c0 127static int udp_lib_lport_inuse(struct net *net, __u16 num,
645ca708 128 const struct udp_hslot *hslot,
98322f22 129 unsigned long *bitmap,
f24d43c0
ED
130 struct sock *sk,
131 int (*saddr_comp)(const struct sock *sk1,
f86dcc5a
ED
132 const struct sock *sk2),
133 unsigned int log)
1da177e4 134{
f24d43c0 135 struct sock *sk2;
88ab1932 136 struct hlist_nulls_node *node;
25030a7f 137
88ab1932 138 sk_nulls_for_each(sk2, node, &hslot->head)
f24d43c0
ED
139 if (net_eq(sock_net(sk2), net) &&
140 sk2 != sk &&
98322f22 141 (bitmap || sk2->sk_hash == num) &&
f24d43c0
ED
142 (!sk2->sk_reuse || !sk->sk_reuse) &&
143 (!sk2->sk_bound_dev_if || !sk->sk_bound_dev_if
144 || sk2->sk_bound_dev_if == sk->sk_bound_dev_if) &&
98322f22
ED
145 (*saddr_comp)(sk, sk2)) {
146 if (bitmap)
f86dcc5a 147 __set_bit(sk2->sk_hash >> log, bitmap);
98322f22
ED
148 else
149 return 1;
150 }
25030a7f
GR
151 return 0;
152}
153
154/**
6ba5a3c5 155 * udp_lib_get_port - UDP/-Lite port lookup for IPv4 and IPv6
25030a7f
GR
156 *
157 * @sk: socket struct in question
158 * @snum: port number to look up
df2bc459 159 * @saddr_comp: AF-dependent comparison of bound local IP addresses
25030a7f 160 */
6ba5a3c5 161int udp_lib_get_port(struct sock *sk, unsigned short snum,
df2bc459 162 int (*saddr_comp)(const struct sock *sk1,
c482c568 163 const struct sock *sk2))
25030a7f 164{
645ca708
ED
165 struct udp_hslot *hslot;
166 struct udp_table *udptable = sk->sk_prot->h.udp_table;
25030a7f 167 int error = 1;
3b1e0a65 168 struct net *net = sock_net(sk);
1da177e4 169
32c1da70 170 if (!snum) {
9088c560
ED
171 int low, high, remaining;
172 unsigned rand;
98322f22
ED
173 unsigned short first, last;
174 DECLARE_BITMAP(bitmap, PORTS_PER_CHAIN);
32c1da70 175
227b60f5 176 inet_get_local_port_range(&low, &high);
a25de534 177 remaining = (high - low) + 1;
227b60f5 178
9088c560 179 rand = net_random();
98322f22
ED
180 first = (((u64)rand * remaining) >> 32) + low;
181 /*
182 * force rand to be an odd multiple of UDP_HTABLE_SIZE
183 */
f86dcc5a
ED
184 rand = (rand | 1) * (udptable->mask + 1);
185 for (last = first + udptable->mask + 1;
186 first != last;
187 first++) {
188 hslot = udp_hashslot(udptable, net, first);
98322f22 189 bitmap_zero(bitmap, PORTS_PER_CHAIN);
645ca708 190 spin_lock_bh(&hslot->lock);
98322f22 191 udp_lib_lport_inuse(net, snum, hslot, bitmap, sk,
f86dcc5a 192 saddr_comp, udptable->log);
98322f22
ED
193
194 snum = first;
195 /*
196 * Iterate on all possible values of snum for this hash.
197 * Using steps of an odd multiple of UDP_HTABLE_SIZE
198 * give us randomization and full range coverage.
199 */
9088c560 200 do {
98322f22 201 if (low <= snum && snum <= high &&
f86dcc5a 202 !test_bit(snum >> udptable->log, bitmap))
98322f22
ED
203 goto found;
204 snum += rand;
205 } while (snum != first);
206 spin_unlock_bh(&hslot->lock);
1da177e4 207 }
98322f22 208 goto fail;
645ca708 209 } else {
f86dcc5a 210 hslot = udp_hashslot(udptable, net, snum);
645ca708 211 spin_lock_bh(&hslot->lock);
f86dcc5a
ED
212 if (udp_lib_lport_inuse(net, snum, hslot, NULL, sk,
213 saddr_comp, 0))
645ca708
ED
214 goto fail_unlock;
215 }
98322f22 216found:
c720c7e8 217 inet_sk(sk)->inet_num = snum;
df2bc459 218 sk->sk_hash = snum;
1da177e4 219 if (sk_unhashed(sk)) {
88ab1932 220 sk_nulls_add_node_rcu(sk, &hslot->head);
fdcc8aa9 221 hslot->count++;
c29a0bc4 222 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, 1);
1da177e4 223 }
25030a7f 224 error = 0;
645ca708
ED
225fail_unlock:
226 spin_unlock_bh(&hslot->lock);
1da177e4 227fail:
25030a7f
GR
228 return error;
229}
c482c568 230EXPORT_SYMBOL(udp_lib_get_port);
25030a7f 231
499923c7 232static int ipv4_rcv_saddr_equal(const struct sock *sk1, const struct sock *sk2)
db8dac20
DM
233{
234 struct inet_sock *inet1 = inet_sk(sk1), *inet2 = inet_sk(sk2);
235
c482c568 236 return (!ipv6_only_sock(sk2) &&
c720c7e8
ED
237 (!inet1->inet_rcv_saddr || !inet2->inet_rcv_saddr ||
238 inet1->inet_rcv_saddr == inet2->inet_rcv_saddr));
db8dac20
DM
239}
240
6ba5a3c5 241int udp_v4_get_port(struct sock *sk, unsigned short snum)
db8dac20 242{
6ba5a3c5 243 return udp_lib_get_port(sk, snum, ipv4_rcv_saddr_equal);
db8dac20
DM
244}
245
645ca708
ED
246static inline int compute_score(struct sock *sk, struct net *net, __be32 saddr,
247 unsigned short hnum,
248 __be16 sport, __be32 daddr, __be16 dport, int dif)
249{
250 int score = -1;
251
252 if (net_eq(sock_net(sk), net) && sk->sk_hash == hnum &&
253 !ipv6_only_sock(sk)) {
254 struct inet_sock *inet = inet_sk(sk);
255
256 score = (sk->sk_family == PF_INET ? 1 : 0);
c720c7e8
ED
257 if (inet->inet_rcv_saddr) {
258 if (inet->inet_rcv_saddr != daddr)
645ca708
ED
259 return -1;
260 score += 2;
261 }
c720c7e8
ED
262 if (inet->inet_daddr) {
263 if (inet->inet_daddr != saddr)
645ca708
ED
264 return -1;
265 score += 2;
266 }
c720c7e8
ED
267 if (inet->inet_dport) {
268 if (inet->inet_dport != sport)
645ca708
ED
269 return -1;
270 score += 2;
271 }
272 if (sk->sk_bound_dev_if) {
273 if (sk->sk_bound_dev_if != dif)
274 return -1;
275 score += 2;
276 }
277 }
278 return score;
279}
280
db8dac20
DM
281/* UDP is nearly always wildcards out the wazoo, it makes no sense to try
282 * harder than this. -DaveM
283 */
284static struct sock *__udp4_lib_lookup(struct net *net, __be32 saddr,
285 __be16 sport, __be32 daddr, __be16 dport,
645ca708 286 int dif, struct udp_table *udptable)
db8dac20 287{
271b72c7 288 struct sock *sk, *result;
88ab1932 289 struct hlist_nulls_node *node;
db8dac20 290 unsigned short hnum = ntohs(dport);
f86dcc5a 291 unsigned int hash = udp_hashfn(net, hnum, udptable->mask);
645ca708 292 struct udp_hslot *hslot = &udptable->hash[hash];
271b72c7 293 int score, badness;
645ca708 294
271b72c7
ED
295 rcu_read_lock();
296begin:
297 result = NULL;
298 badness = -1;
88ab1932 299 sk_nulls_for_each_rcu(sk, node, &hslot->head) {
645ca708
ED
300 score = compute_score(sk, net, saddr, hnum, sport,
301 daddr, dport, dif);
302 if (score > badness) {
303 result = sk;
304 badness = score;
db8dac20
DM
305 }
306 }
88ab1932
ED
307 /*
308 * if the nulls value we got at the end of this lookup is
309 * not the expected one, we must restart lookup.
310 * We probably met an item that was moved to another chain.
311 */
312 if (get_nulls_value(node) != hash)
313 goto begin;
314
271b72c7
ED
315 if (result) {
316 if (unlikely(!atomic_inc_not_zero(&result->sk_refcnt)))
317 result = NULL;
318 else if (unlikely(compute_score(result, net, saddr, hnum, sport,
319 daddr, dport, dif) < badness)) {
320 sock_put(result);
321 goto begin;
322 }
323 }
324 rcu_read_unlock();
db8dac20
DM
325 return result;
326}
327
607c4aaf
KK
328static inline struct sock *__udp4_lib_lookup_skb(struct sk_buff *skb,
329 __be16 sport, __be16 dport,
645ca708 330 struct udp_table *udptable)
607c4aaf 331{
23542618 332 struct sock *sk;
607c4aaf
KK
333 const struct iphdr *iph = ip_hdr(skb);
334
23542618
KK
335 if (unlikely(sk = skb_steal_sock(skb)))
336 return sk;
337 else
adf30907 338 return __udp4_lib_lookup(dev_net(skb_dst(skb)->dev), iph->saddr, sport,
23542618
KK
339 iph->daddr, dport, inet_iif(skb),
340 udptable);
607c4aaf
KK
341}
342
bcd41303
KK
343struct sock *udp4_lib_lookup(struct net *net, __be32 saddr, __be16 sport,
344 __be32 daddr, __be16 dport, int dif)
345{
645ca708 346 return __udp4_lib_lookup(net, saddr, sport, daddr, dport, dif, &udp_table);
bcd41303
KK
347}
348EXPORT_SYMBOL_GPL(udp4_lib_lookup);
349
920a4611 350static inline struct sock *udp_v4_mcast_next(struct net *net, struct sock *sk,
db8dac20
DM
351 __be16 loc_port, __be32 loc_addr,
352 __be16 rmt_port, __be32 rmt_addr,
353 int dif)
354{
88ab1932 355 struct hlist_nulls_node *node;
db8dac20
DM
356 struct sock *s = sk;
357 unsigned short hnum = ntohs(loc_port);
358
88ab1932 359 sk_nulls_for_each_from(s, node) {
db8dac20
DM
360 struct inet_sock *inet = inet_sk(s);
361
920a4611
ED
362 if (!net_eq(sock_net(s), net) ||
363 s->sk_hash != hnum ||
c720c7e8
ED
364 (inet->inet_daddr && inet->inet_daddr != rmt_addr) ||
365 (inet->inet_dport != rmt_port && inet->inet_dport) ||
366 (inet->inet_rcv_saddr &&
367 inet->inet_rcv_saddr != loc_addr) ||
db8dac20
DM
368 ipv6_only_sock(s) ||
369 (s->sk_bound_dev_if && s->sk_bound_dev_if != dif))
370 continue;
371 if (!ip_mc_sf_allow(s, loc_addr, rmt_addr, dif))
372 continue;
373 goto found;
374 }
375 s = NULL;
376found:
377 return s;
378}
379
380/*
381 * This routine is called by the ICMP module when it gets some
382 * sort of error condition. If err < 0 then the socket should
383 * be closed and the error returned to the user. If err > 0
384 * it's just the icmp type << 8 | icmp code.
385 * Header points to the ip header of the error packet. We move
386 * on past this. Then (as it used to claim before adjustment)
387 * header points to the first 8 bytes of the udp header. We need
388 * to find the appropriate port.
389 */
390
645ca708 391void __udp4_lib_err(struct sk_buff *skb, u32 info, struct udp_table *udptable)
db8dac20
DM
392{
393 struct inet_sock *inet;
c482c568
ED
394 struct iphdr *iph = (struct iphdr *)skb->data;
395 struct udphdr *uh = (struct udphdr *)(skb->data+(iph->ihl<<2));
db8dac20
DM
396 const int type = icmp_hdr(skb)->type;
397 const int code = icmp_hdr(skb)->code;
398 struct sock *sk;
399 int harderr;
400 int err;
fd54d716 401 struct net *net = dev_net(skb->dev);
db8dac20 402
fd54d716 403 sk = __udp4_lib_lookup(net, iph->daddr, uh->dest,
db8dac20
DM
404 iph->saddr, uh->source, skb->dev->ifindex, udptable);
405 if (sk == NULL) {
dcfc23ca 406 ICMP_INC_STATS_BH(net, ICMP_MIB_INERRORS);
db8dac20
DM
407 return; /* No socket for error */
408 }
409
410 err = 0;
411 harderr = 0;
412 inet = inet_sk(sk);
413
414 switch (type) {
415 default:
416 case ICMP_TIME_EXCEEDED:
417 err = EHOSTUNREACH;
418 break;
419 case ICMP_SOURCE_QUENCH:
420 goto out;
421 case ICMP_PARAMETERPROB:
422 err = EPROTO;
423 harderr = 1;
424 break;
425 case ICMP_DEST_UNREACH:
426 if (code == ICMP_FRAG_NEEDED) { /* Path MTU discovery */
427 if (inet->pmtudisc != IP_PMTUDISC_DONT) {
428 err = EMSGSIZE;
429 harderr = 1;
430 break;
431 }
432 goto out;
433 }
434 err = EHOSTUNREACH;
435 if (code <= NR_ICMP_UNREACH) {
436 harderr = icmp_err_convert[code].fatal;
437 err = icmp_err_convert[code].errno;
438 }
439 break;
440 }
441
442 /*
443 * RFC1122: OK. Passes ICMP errors back to application, as per
444 * 4.1.3.3.
445 */
446 if (!inet->recverr) {
447 if (!harderr || sk->sk_state != TCP_ESTABLISHED)
448 goto out;
449 } else {
c482c568 450 ip_icmp_error(sk, skb, err, uh->dest, info, (u8 *)(uh+1));
db8dac20
DM
451 }
452 sk->sk_err = err;
453 sk->sk_error_report(sk);
454out:
455 sock_put(sk);
456}
457
458void udp_err(struct sk_buff *skb, u32 info)
459{
645ca708 460 __udp4_lib_err(skb, info, &udp_table);
db8dac20
DM
461}
462
463/*
464 * Throw away all pending data and cancel the corking. Socket is locked.
465 */
36d926b9 466void udp_flush_pending_frames(struct sock *sk)
db8dac20
DM
467{
468 struct udp_sock *up = udp_sk(sk);
469
470 if (up->pending) {
471 up->len = 0;
472 up->pending = 0;
473 ip_flush_pending_frames(sk);
474 }
475}
36d926b9 476EXPORT_SYMBOL(udp_flush_pending_frames);
db8dac20
DM
477
478/**
479 * udp4_hwcsum_outgoing - handle outgoing HW checksumming
480 * @sk: socket we are sending on
481 * @skb: sk_buff containing the filled-in UDP header
482 * (checksum field must be zeroed out)
483 */
484static void udp4_hwcsum_outgoing(struct sock *sk, struct sk_buff *skb,
c482c568 485 __be32 src, __be32 dst, int len)
db8dac20
DM
486{
487 unsigned int offset;
488 struct udphdr *uh = udp_hdr(skb);
489 __wsum csum = 0;
490
491 if (skb_queue_len(&sk->sk_write_queue) == 1) {
492 /*
493 * Only one fragment on the socket.
494 */
495 skb->csum_start = skb_transport_header(skb) - skb->head;
496 skb->csum_offset = offsetof(struct udphdr, check);
497 uh->check = ~csum_tcpudp_magic(src, dst, len, IPPROTO_UDP, 0);
498 } else {
499 /*
500 * HW-checksum won't work as there are two or more
501 * fragments on the socket so that all csums of sk_buffs
502 * should be together
503 */
504 offset = skb_transport_offset(skb);
505 skb->csum = skb_checksum(skb, offset, skb->len - offset, 0);
506
507 skb->ip_summed = CHECKSUM_NONE;
508
509 skb_queue_walk(&sk->sk_write_queue, skb) {
510 csum = csum_add(csum, skb->csum);
511 }
512
513 uh->check = csum_tcpudp_magic(src, dst, len, IPPROTO_UDP, csum);
514 if (uh->check == 0)
515 uh->check = CSUM_MANGLED_0;
516 }
517}
518
519/*
520 * Push out all pending data as one UDP datagram. Socket is locked.
521 */
522static int udp_push_pending_frames(struct sock *sk)
523{
524 struct udp_sock *up = udp_sk(sk);
525 struct inet_sock *inet = inet_sk(sk);
526 struct flowi *fl = &inet->cork.fl;
527 struct sk_buff *skb;
528 struct udphdr *uh;
529 int err = 0;
530 int is_udplite = IS_UDPLITE(sk);
531 __wsum csum = 0;
532
533 /* Grab the skbuff where UDP header space exists. */
534 if ((skb = skb_peek(&sk->sk_write_queue)) == NULL)
535 goto out;
536
537 /*
538 * Create a UDP header
539 */
540 uh = udp_hdr(skb);
541 uh->source = fl->fl_ip_sport;
542 uh->dest = fl->fl_ip_dport;
543 uh->len = htons(up->len);
544 uh->check = 0;
545
546 if (is_udplite) /* UDP-Lite */
547 csum = udplite_csum_outgoing(sk, skb);
548
549 else if (sk->sk_no_check == UDP_CSUM_NOXMIT) { /* UDP csum disabled */
550
551 skb->ip_summed = CHECKSUM_NONE;
552 goto send;
553
554 } else if (skb->ip_summed == CHECKSUM_PARTIAL) { /* UDP hardware csum */
555
c482c568 556 udp4_hwcsum_outgoing(sk, skb, fl->fl4_src, fl->fl4_dst, up->len);
db8dac20
DM
557 goto send;
558
559 } else /* `normal' UDP */
560 csum = udp_csum_outgoing(sk, skb);
561
562 /* add protocol-dependent pseudo-header */
563 uh->check = csum_tcpudp_magic(fl->fl4_src, fl->fl4_dst, up->len,
c482c568 564 sk->sk_protocol, csum);
db8dac20
DM
565 if (uh->check == 0)
566 uh->check = CSUM_MANGLED_0;
567
568send:
569 err = ip_push_pending_frames(sk);
6ce9e7b5
ED
570 if (err) {
571 if (err == -ENOBUFS && !inet->recverr) {
572 UDP_INC_STATS_USER(sock_net(sk),
573 UDP_MIB_SNDBUFERRORS, is_udplite);
574 err = 0;
575 }
576 } else
577 UDP_INC_STATS_USER(sock_net(sk),
578 UDP_MIB_OUTDATAGRAMS, is_udplite);
db8dac20
DM
579out:
580 up->len = 0;
581 up->pending = 0;
db8dac20
DM
582 return err;
583}
584
585int udp_sendmsg(struct kiocb *iocb, struct sock *sk, struct msghdr *msg,
586 size_t len)
587{
588 struct inet_sock *inet = inet_sk(sk);
589 struct udp_sock *up = udp_sk(sk);
590 int ulen = len;
591 struct ipcm_cookie ipc;
592 struct rtable *rt = NULL;
593 int free = 0;
594 int connected = 0;
595 __be32 daddr, faddr, saddr;
596 __be16 dport;
597 u8 tos;
598 int err, is_udplite = IS_UDPLITE(sk);
599 int corkreq = up->corkflag || msg->msg_flags&MSG_MORE;
600 int (*getfrag)(void *, char *, int, int, int, struct sk_buff *);
601
602 if (len > 0xFFFF)
603 return -EMSGSIZE;
604
605 /*
606 * Check the flags.
607 */
608
c482c568 609 if (msg->msg_flags & MSG_OOB) /* Mirror BSD error message compatibility */
db8dac20
DM
610 return -EOPNOTSUPP;
611
612 ipc.opt = NULL;
51f31cab 613 ipc.shtx.flags = 0;
db8dac20
DM
614
615 if (up->pending) {
616 /*
617 * There are pending frames.
618 * The socket lock must be held while it's corked.
619 */
620 lock_sock(sk);
621 if (likely(up->pending)) {
622 if (unlikely(up->pending != AF_INET)) {
623 release_sock(sk);
624 return -EINVAL;
625 }
626 goto do_append_data;
627 }
628 release_sock(sk);
629 }
630 ulen += sizeof(struct udphdr);
631
632 /*
633 * Get and verify the address.
634 */
635 if (msg->msg_name) {
c482c568 636 struct sockaddr_in * usin = (struct sockaddr_in *)msg->msg_name;
db8dac20
DM
637 if (msg->msg_namelen < sizeof(*usin))
638 return -EINVAL;
639 if (usin->sin_family != AF_INET) {
640 if (usin->sin_family != AF_UNSPEC)
641 return -EAFNOSUPPORT;
642 }
643
644 daddr = usin->sin_addr.s_addr;
645 dport = usin->sin_port;
646 if (dport == 0)
647 return -EINVAL;
648 } else {
649 if (sk->sk_state != TCP_ESTABLISHED)
650 return -EDESTADDRREQ;
c720c7e8
ED
651 daddr = inet->inet_daddr;
652 dport = inet->inet_dport;
db8dac20
DM
653 /* Open fast path for connected socket.
654 Route will not be used, if at least one option is set.
655 */
656 connected = 1;
657 }
c720c7e8 658 ipc.addr = inet->inet_saddr;
db8dac20
DM
659
660 ipc.oif = sk->sk_bound_dev_if;
51f31cab
PO
661 err = sock_tx_timestamp(msg, sk, &ipc.shtx);
662 if (err)
663 return err;
db8dac20 664 if (msg->msg_controllen) {
3b1e0a65 665 err = ip_cmsg_send(sock_net(sk), msg, &ipc);
db8dac20
DM
666 if (err)
667 return err;
668 if (ipc.opt)
669 free = 1;
670 connected = 0;
671 }
672 if (!ipc.opt)
673 ipc.opt = inet->opt;
674
675 saddr = ipc.addr;
676 ipc.addr = faddr = daddr;
677
678 if (ipc.opt && ipc.opt->srr) {
679 if (!daddr)
680 return -EINVAL;
681 faddr = ipc.opt->faddr;
682 connected = 0;
683 }
684 tos = RT_TOS(inet->tos);
685 if (sock_flag(sk, SOCK_LOCALROUTE) ||
686 (msg->msg_flags & MSG_DONTROUTE) ||
687 (ipc.opt && ipc.opt->is_strictroute)) {
688 tos |= RTO_ONLINK;
689 connected = 0;
690 }
691
692 if (ipv4_is_multicast(daddr)) {
693 if (!ipc.oif)
694 ipc.oif = inet->mc_index;
695 if (!saddr)
696 saddr = inet->mc_addr;
697 connected = 0;
698 }
699
700 if (connected)
c482c568 701 rt = (struct rtable *)sk_dst_check(sk, 0);
db8dac20
DM
702
703 if (rt == NULL) {
704 struct flowi fl = { .oif = ipc.oif,
914a9ab3 705 .mark = sk->sk_mark,
db8dac20
DM
706 .nl_u = { .ip4_u =
707 { .daddr = faddr,
708 .saddr = saddr,
709 .tos = tos } },
710 .proto = sk->sk_protocol,
a134f85c 711 .flags = inet_sk_flowi_flags(sk),
db8dac20 712 .uli_u = { .ports =
c720c7e8 713 { .sport = inet->inet_sport,
db8dac20 714 .dport = dport } } };
84a3aa00
PE
715 struct net *net = sock_net(sk);
716
db8dac20 717 security_sk_classify_flow(sk, &fl);
84a3aa00 718 err = ip_route_output_flow(net, &rt, &fl, sk, 1);
db8dac20
DM
719 if (err) {
720 if (err == -ENETUNREACH)
7c73a6fa 721 IP_INC_STATS_BH(net, IPSTATS_MIB_OUTNOROUTES);
db8dac20
DM
722 goto out;
723 }
724
725 err = -EACCES;
726 if ((rt->rt_flags & RTCF_BROADCAST) &&
727 !sock_flag(sk, SOCK_BROADCAST))
728 goto out;
729 if (connected)
730 sk_dst_set(sk, dst_clone(&rt->u.dst));
731 }
732
733 if (msg->msg_flags&MSG_CONFIRM)
734 goto do_confirm;
735back_from_confirm:
736
737 saddr = rt->rt_src;
738 if (!ipc.addr)
739 daddr = ipc.addr = rt->rt_dst;
740
741 lock_sock(sk);
742 if (unlikely(up->pending)) {
743 /* The socket is already corked while preparing it. */
744 /* ... which is an evident application bug. --ANK */
745 release_sock(sk);
746
747 LIMIT_NETDEBUG(KERN_DEBUG "udp cork app bug 2\n");
748 err = -EINVAL;
749 goto out;
750 }
751 /*
752 * Now cork the socket to pend data.
753 */
754 inet->cork.fl.fl4_dst = daddr;
755 inet->cork.fl.fl_ip_dport = dport;
756 inet->cork.fl.fl4_src = saddr;
c720c7e8 757 inet->cork.fl.fl_ip_sport = inet->inet_sport;
db8dac20
DM
758 up->pending = AF_INET;
759
760do_append_data:
761 up->len += ulen;
762 getfrag = is_udplite ? udplite_getfrag : ip_generic_getfrag;
763 err = ip_append_data(sk, getfrag, msg->msg_iov, ulen,
2e77d89b 764 sizeof(struct udphdr), &ipc, &rt,
db8dac20
DM
765 corkreq ? msg->msg_flags|MSG_MORE : msg->msg_flags);
766 if (err)
767 udp_flush_pending_frames(sk);
768 else if (!corkreq)
769 err = udp_push_pending_frames(sk);
770 else if (unlikely(skb_queue_empty(&sk->sk_write_queue)))
771 up->pending = 0;
772 release_sock(sk);
773
774out:
775 ip_rt_put(rt);
776 if (free)
777 kfree(ipc.opt);
778 if (!err)
779 return len;
780 /*
781 * ENOBUFS = no kernel mem, SOCK_NOSPACE = no sndbuf space. Reporting
782 * ENOBUFS might not be good (it's not tunable per se), but otherwise
783 * we don't have a good statistic (IpOutDiscards but it can be too many
784 * things). We could add another new stat but at least for now that
785 * seems like overkill.
786 */
787 if (err == -ENOBUFS || test_bit(SOCK_NOSPACE, &sk->sk_socket->flags)) {
629ca23c
PE
788 UDP_INC_STATS_USER(sock_net(sk),
789 UDP_MIB_SNDBUFERRORS, is_udplite);
db8dac20
DM
790 }
791 return err;
792
793do_confirm:
794 dst_confirm(&rt->u.dst);
795 if (!(msg->msg_flags&MSG_PROBE) || len)
796 goto back_from_confirm;
797 err = 0;
798 goto out;
799}
c482c568 800EXPORT_SYMBOL(udp_sendmsg);
db8dac20
DM
801
802int udp_sendpage(struct sock *sk, struct page *page, int offset,
803 size_t size, int flags)
804{
805 struct udp_sock *up = udp_sk(sk);
806 int ret;
807
808 if (!up->pending) {
809 struct msghdr msg = { .msg_flags = flags|MSG_MORE };
810
811 /* Call udp_sendmsg to specify destination address which
812 * sendpage interface can't pass.
813 * This will succeed only when the socket is connected.
814 */
815 ret = udp_sendmsg(NULL, sk, &msg, 0);
816 if (ret < 0)
817 return ret;
818 }
819
820 lock_sock(sk);
821
822 if (unlikely(!up->pending)) {
823 release_sock(sk);
824
825 LIMIT_NETDEBUG(KERN_DEBUG "udp cork app bug 3\n");
826 return -EINVAL;
827 }
828
829 ret = ip_append_page(sk, page, offset, size, flags);
830 if (ret == -EOPNOTSUPP) {
831 release_sock(sk);
832 return sock_no_sendpage(sk->sk_socket, page, offset,
833 size, flags);
834 }
835 if (ret < 0) {
836 udp_flush_pending_frames(sk);
837 goto out;
838 }
839
840 up->len += size;
841 if (!(up->corkflag || (flags&MSG_MORE)))
842 ret = udp_push_pending_frames(sk);
843 if (!ret)
844 ret = size;
845out:
846 release_sock(sk);
847 return ret;
848}
849
85584672
ED
850
851/**
852 * first_packet_length - return length of first packet in receive queue
853 * @sk: socket
854 *
855 * Drops all bad checksum frames, until a valid one is found.
856 * Returns the length of found skb, or 0 if none is found.
857 */
858static unsigned int first_packet_length(struct sock *sk)
859{
860 struct sk_buff_head list_kill, *rcvq = &sk->sk_receive_queue;
861 struct sk_buff *skb;
862 unsigned int res;
863
864 __skb_queue_head_init(&list_kill);
865
866 spin_lock_bh(&rcvq->lock);
867 while ((skb = skb_peek(rcvq)) != NULL &&
868 udp_lib_checksum_complete(skb)) {
869 UDP_INC_STATS_BH(sock_net(sk), UDP_MIB_INERRORS,
870 IS_UDPLITE(sk));
8edf19c2 871 atomic_inc(&sk->sk_drops);
85584672
ED
872 __skb_unlink(skb, rcvq);
873 __skb_queue_tail(&list_kill, skb);
874 }
875 res = skb ? skb->len : 0;
876 spin_unlock_bh(&rcvq->lock);
877
878 if (!skb_queue_empty(&list_kill)) {
879 lock_sock(sk);
880 __skb_queue_purge(&list_kill);
881 sk_mem_reclaim_partial(sk);
882 release_sock(sk);
883 }
884 return res;
885}
886
1da177e4
LT
887/*
888 * IOCTL requests applicable to the UDP protocol
889 */
e905a9ed 890
1da177e4
LT
891int udp_ioctl(struct sock *sk, int cmd, unsigned long arg)
892{
6516c655
SH
893 switch (cmd) {
894 case SIOCOUTQ:
1da177e4 895 {
31e6d363
ED
896 int amount = sk_wmem_alloc_get(sk);
897
6516c655
SH
898 return put_user(amount, (int __user *)arg);
899 }
1da177e4 900
6516c655
SH
901 case SIOCINQ:
902 {
85584672 903 unsigned int amount = first_packet_length(sk);
6516c655 904
85584672 905 if (amount)
6516c655
SH
906 /*
907 * We will only return the amount
908 * of this packet since that is all
909 * that will be read.
910 */
85584672
ED
911 amount -= sizeof(struct udphdr);
912
6516c655
SH
913 return put_user(amount, (int __user *)arg);
914 }
1da177e4 915
6516c655
SH
916 default:
917 return -ENOIOCTLCMD;
1da177e4 918 }
6516c655
SH
919
920 return 0;
1da177e4 921}
c482c568 922EXPORT_SYMBOL(udp_ioctl);
1da177e4 923
db8dac20
DM
924/*
925 * This should be easy, if there is something there we
926 * return it, otherwise we block.
927 */
928
929int udp_recvmsg(struct kiocb *iocb, struct sock *sk, struct msghdr *msg,
930 size_t len, int noblock, int flags, int *addr_len)
931{
932 struct inet_sock *inet = inet_sk(sk);
933 struct sockaddr_in *sin = (struct sockaddr_in *)msg->msg_name;
934 struct sk_buff *skb;
935 unsigned int ulen, copied;
936 int peeked;
937 int err;
938 int is_udplite = IS_UDPLITE(sk);
939
940 /*
941 * Check any passed addresses
942 */
943 if (addr_len)
c482c568 944 *addr_len = sizeof(*sin);
db8dac20
DM
945
946 if (flags & MSG_ERRQUEUE)
947 return ip_recv_error(sk, msg, len);
948
949try_again:
950 skb = __skb_recv_datagram(sk, flags | (noblock ? MSG_DONTWAIT : 0),
951 &peeked, &err);
952 if (!skb)
953 goto out;
954
955 ulen = skb->len - sizeof(struct udphdr);
956 copied = len;
957 if (copied > ulen)
958 copied = ulen;
959 else if (copied < ulen)
960 msg->msg_flags |= MSG_TRUNC;
961
962 /*
963 * If checksum is needed at all, try to do it while copying the
964 * data. If the data is truncated, or if we only want a partial
965 * coverage checksum (UDP-Lite), do it before the copy.
966 */
967
968 if (copied < ulen || UDP_SKB_CB(skb)->partial_cov) {
969 if (udp_lib_checksum_complete(skb))
970 goto csum_copy_err;
971 }
972
973 if (skb_csum_unnecessary(skb))
974 err = skb_copy_datagram_iovec(skb, sizeof(struct udphdr),
c482c568 975 msg->msg_iov, copied);
db8dac20 976 else {
c482c568
ED
977 err = skb_copy_and_csum_datagram_iovec(skb,
978 sizeof(struct udphdr),
979 msg->msg_iov);
db8dac20
DM
980
981 if (err == -EINVAL)
982 goto csum_copy_err;
983 }
984
985 if (err)
986 goto out_free;
987
988 if (!peeked)
629ca23c
PE
989 UDP_INC_STATS_USER(sock_net(sk),
990 UDP_MIB_INDATAGRAMS, is_udplite);
db8dac20 991
3b885787 992 sock_recv_ts_and_drops(msg, sk, skb);
db8dac20
DM
993
994 /* Copy the address. */
c482c568 995 if (sin) {
db8dac20
DM
996 sin->sin_family = AF_INET;
997 sin->sin_port = udp_hdr(skb)->source;
998 sin->sin_addr.s_addr = ip_hdr(skb)->saddr;
999 memset(sin->sin_zero, 0, sizeof(sin->sin_zero));
1000 }
1001 if (inet->cmsg_flags)
1002 ip_cmsg_recv(msg, skb);
1003
1004 err = copied;
1005 if (flags & MSG_TRUNC)
1006 err = ulen;
1007
1008out_free:
9d410c79 1009 skb_free_datagram_locked(sk, skb);
db8dac20
DM
1010out:
1011 return err;
1012
1013csum_copy_err:
1014 lock_sock(sk);
1015 if (!skb_kill_datagram(sk, skb, flags))
629ca23c 1016 UDP_INC_STATS_USER(sock_net(sk), UDP_MIB_INERRORS, is_udplite);
db8dac20
DM
1017 release_sock(sk);
1018
1019 if (noblock)
1020 return -EAGAIN;
1021 goto try_again;
1022}
1023
1024
1da177e4
LT
1025int udp_disconnect(struct sock *sk, int flags)
1026{
1027 struct inet_sock *inet = inet_sk(sk);
1028 /*
1029 * 1003.1g - break association.
1030 */
e905a9ed 1031
1da177e4 1032 sk->sk_state = TCP_CLOSE;
c720c7e8
ED
1033 inet->inet_daddr = 0;
1034 inet->inet_dport = 0;
1da177e4
LT
1035 sk->sk_bound_dev_if = 0;
1036 if (!(sk->sk_userlocks & SOCK_BINDADDR_LOCK))
1037 inet_reset_saddr(sk);
1038
1039 if (!(sk->sk_userlocks & SOCK_BINDPORT_LOCK)) {
1040 sk->sk_prot->unhash(sk);
c720c7e8 1041 inet->inet_sport = 0;
1da177e4
LT
1042 }
1043 sk_dst_reset(sk);
1044 return 0;
1045}
c482c568 1046EXPORT_SYMBOL(udp_disconnect);
1da177e4 1047
645ca708
ED
1048void udp_lib_unhash(struct sock *sk)
1049{
723b4610
ED
1050 if (sk_hashed(sk)) {
1051 struct udp_table *udptable = sk->sk_prot->h.udp_table;
f86dcc5a
ED
1052 struct udp_hslot *hslot = udp_hashslot(udptable, sock_net(sk),
1053 sk->sk_hash);
645ca708 1054
723b4610
ED
1055 spin_lock_bh(&hslot->lock);
1056 if (sk_nulls_del_node_init_rcu(sk)) {
fdcc8aa9 1057 hslot->count--;
c720c7e8 1058 inet_sk(sk)->inet_num = 0;
723b4610
ED
1059 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, -1);
1060 }
1061 spin_unlock_bh(&hslot->lock);
645ca708 1062 }
645ca708
ED
1063}
1064EXPORT_SYMBOL(udp_lib_unhash);
1065
93821778
HX
1066static int __udp_queue_rcv_skb(struct sock *sk, struct sk_buff *skb)
1067{
766e9037
ED
1068 int rc = sock_queue_rcv_skb(sk, skb);
1069
1070 if (rc < 0) {
1071 int is_udplite = IS_UDPLITE(sk);
93821778 1072
93821778 1073 /* Note that an ENOMEM error is charged twice */
766e9037 1074 if (rc == -ENOMEM)
93821778
HX
1075 UDP_INC_STATS_BH(sock_net(sk), UDP_MIB_RCVBUFERRORS,
1076 is_udplite);
766e9037
ED
1077 UDP_INC_STATS_BH(sock_net(sk), UDP_MIB_INERRORS, is_udplite);
1078 kfree_skb(skb);
1079 return -1;
93821778
HX
1080 }
1081
1082 return 0;
1083
93821778
HX
1084}
1085
db8dac20
DM
1086/* returns:
1087 * -1: error
1088 * 0: success
1089 * >0: "udp encap" protocol resubmission
1090 *
1091 * Note that in the success and error cases, the skb is assumed to
1092 * have either been requeued or freed.
1093 */
c482c568 1094int udp_queue_rcv_skb(struct sock *sk, struct sk_buff *skb)
db8dac20
DM
1095{
1096 struct udp_sock *up = udp_sk(sk);
1097 int rc;
1098 int is_udplite = IS_UDPLITE(sk);
1099
1100 /*
1101 * Charge it to the socket, dropping if the queue is full.
1102 */
1103 if (!xfrm4_policy_check(sk, XFRM_POLICY_IN, skb))
1104 goto drop;
1105 nf_reset(skb);
1106
1107 if (up->encap_type) {
1108 /*
1109 * This is an encapsulation socket so pass the skb to
1110 * the socket's udp_encap_rcv() hook. Otherwise, just
1111 * fall through and pass this up the UDP socket.
1112 * up->encap_rcv() returns the following value:
1113 * =0 if skb was successfully passed to the encap
1114 * handler or was discarded by it.
1115 * >0 if skb should be passed on to UDP.
1116 * <0 if skb should be resubmitted as proto -N
1117 */
1118
1119 /* if we're overly short, let UDP handle it */
1120 if (skb->len > sizeof(struct udphdr) &&
1121 up->encap_rcv != NULL) {
1122 int ret;
1123
1124 ret = (*up->encap_rcv)(sk, skb);
1125 if (ret <= 0) {
0283328e
PE
1126 UDP_INC_STATS_BH(sock_net(sk),
1127 UDP_MIB_INDATAGRAMS,
db8dac20
DM
1128 is_udplite);
1129 return -ret;
1130 }
1131 }
1132
1133 /* FALLTHROUGH -- it's a UDP Packet */
1134 }
1135
1136 /*
1137 * UDP-Lite specific tests, ignored on UDP sockets
1138 */
1139 if ((is_udplite & UDPLITE_RECV_CC) && UDP_SKB_CB(skb)->partial_cov) {
1140
1141 /*
1142 * MIB statistics other than incrementing the error count are
1143 * disabled for the following two types of errors: these depend
1144 * on the application settings, not on the functioning of the
1145 * protocol stack as such.
1146 *
1147 * RFC 3828 here recommends (sec 3.3): "There should also be a
1148 * way ... to ... at least let the receiving application block
1149 * delivery of packets with coverage values less than a value
1150 * provided by the application."
1151 */
1152 if (up->pcrlen == 0) { /* full coverage was set */
1153 LIMIT_NETDEBUG(KERN_WARNING "UDPLITE: partial coverage "
1154 "%d while full coverage %d requested\n",
1155 UDP_SKB_CB(skb)->cscov, skb->len);
1156 goto drop;
1157 }
1158 /* The next case involves violating the min. coverage requested
1159 * by the receiver. This is subtle: if receiver wants x and x is
1160 * greater than the buffersize/MTU then receiver will complain
1161 * that it wants x while sender emits packets of smaller size y.
1162 * Therefore the above ...()->partial_cov statement is essential.
1163 */
1164 if (UDP_SKB_CB(skb)->cscov < up->pcrlen) {
1165 LIMIT_NETDEBUG(KERN_WARNING
1166 "UDPLITE: coverage %d too small, need min %d\n",
1167 UDP_SKB_CB(skb)->cscov, up->pcrlen);
1168 goto drop;
1169 }
1170 }
1171
1172 if (sk->sk_filter) {
1173 if (udp_lib_checksum_complete(skb))
1174 goto drop;
1175 }
1176
93821778 1177 rc = 0;
db8dac20 1178
93821778
HX
1179 bh_lock_sock(sk);
1180 if (!sock_owned_by_user(sk))
1181 rc = __udp_queue_rcv_skb(sk, skb);
1182 else
1183 sk_add_backlog(sk, skb);
1184 bh_unlock_sock(sk);
1185
1186 return rc;
db8dac20
DM
1187
1188drop:
0283328e 1189 UDP_INC_STATS_BH(sock_net(sk), UDP_MIB_INERRORS, is_udplite);
8edf19c2 1190 atomic_inc(&sk->sk_drops);
db8dac20
DM
1191 kfree_skb(skb);
1192 return -1;
1193}
1194
1195/*
1196 * Multicasts and broadcasts go to each listener.
1197 *
1198 * Note: called only from the BH handler context,
1199 * so we don't need to lock the hashes.
1200 */
e3163493 1201static int __udp4_lib_mcast_deliver(struct net *net, struct sk_buff *skb,
db8dac20
DM
1202 struct udphdr *uh,
1203 __be32 saddr, __be32 daddr,
645ca708 1204 struct udp_table *udptable)
db8dac20
DM
1205{
1206 struct sock *sk;
f86dcc5a 1207 struct udp_hslot *hslot = udp_hashslot(udptable, net, ntohs(uh->dest));
db8dac20
DM
1208 int dif;
1209
645ca708 1210 spin_lock(&hslot->lock);
88ab1932 1211 sk = sk_nulls_head(&hslot->head);
db8dac20 1212 dif = skb->dev->ifindex;
920a4611 1213 sk = udp_v4_mcast_next(net, sk, uh->dest, daddr, uh->source, saddr, dif);
db8dac20
DM
1214 if (sk) {
1215 struct sock *sknext = NULL;
1216
1217 do {
1218 struct sk_buff *skb1 = skb;
1219
88ab1932 1220 sknext = udp_v4_mcast_next(net, sk_nulls_next(sk), uh->dest,
920a4611
ED
1221 daddr, uh->source, saddr,
1222 dif);
db8dac20
DM
1223 if (sknext)
1224 skb1 = skb_clone(skb, GFP_ATOMIC);
1225
1226 if (skb1) {
93821778 1227 int ret = udp_queue_rcv_skb(sk, skb1);
db8dac20
DM
1228 if (ret > 0)
1229 /* we should probably re-process instead
1230 * of dropping packets here. */
1231 kfree_skb(skb1);
1232 }
1233 sk = sknext;
1234 } while (sknext);
1235 } else
ead2ceb0 1236 consume_skb(skb);
645ca708 1237 spin_unlock(&hslot->lock);
db8dac20
DM
1238 return 0;
1239}
1240
1241/* Initialize UDP checksum. If exited with zero value (success),
1242 * CHECKSUM_UNNECESSARY means, that no more checks are required.
1243 * Otherwise, csum completion requires chacksumming packet body,
1244 * including udp header and folding it to skb->csum.
1245 */
1246static inline int udp4_csum_init(struct sk_buff *skb, struct udphdr *uh,
1247 int proto)
1248{
1249 const struct iphdr *iph;
1250 int err;
1251
1252 UDP_SKB_CB(skb)->partial_cov = 0;
1253 UDP_SKB_CB(skb)->cscov = skb->len;
1254
1255 if (proto == IPPROTO_UDPLITE) {
1256 err = udplite_checksum_init(skb, uh);
1257 if (err)
1258 return err;
1259 }
1260
1261 iph = ip_hdr(skb);
1262 if (uh->check == 0) {
1263 skb->ip_summed = CHECKSUM_UNNECESSARY;
1264 } else if (skb->ip_summed == CHECKSUM_COMPLETE) {
c482c568 1265 if (!csum_tcpudp_magic(iph->saddr, iph->daddr, skb->len,
db8dac20
DM
1266 proto, skb->csum))
1267 skb->ip_summed = CHECKSUM_UNNECESSARY;
1268 }
1269 if (!skb_csum_unnecessary(skb))
1270 skb->csum = csum_tcpudp_nofold(iph->saddr, iph->daddr,
1271 skb->len, proto, 0);
1272 /* Probably, we should checksum udp header (it should be in cache
1273 * in any case) and data in tiny packets (< rx copybreak).
1274 */
1275
1276 return 0;
1277}
1278
1279/*
1280 * All we need to do is get the socket, and then do a checksum.
1281 */
1282
645ca708 1283int __udp4_lib_rcv(struct sk_buff *skb, struct udp_table *udptable,
db8dac20
DM
1284 int proto)
1285{
1286 struct sock *sk;
7b5e56f9 1287 struct udphdr *uh;
db8dac20 1288 unsigned short ulen;
adf30907 1289 struct rtable *rt = skb_rtable(skb);
2783ef23 1290 __be32 saddr, daddr;
0283328e 1291 struct net *net = dev_net(skb->dev);
db8dac20
DM
1292
1293 /*
1294 * Validate the packet.
1295 */
1296 if (!pskb_may_pull(skb, sizeof(struct udphdr)))
1297 goto drop; /* No space for header. */
1298
7b5e56f9 1299 uh = udp_hdr(skb);
db8dac20
DM
1300 ulen = ntohs(uh->len);
1301 if (ulen > skb->len)
1302 goto short_packet;
1303
1304 if (proto == IPPROTO_UDP) {
1305 /* UDP validates ulen. */
1306 if (ulen < sizeof(*uh) || pskb_trim_rcsum(skb, ulen))
1307 goto short_packet;
1308 uh = udp_hdr(skb);
1309 }
1310
1311 if (udp4_csum_init(skb, uh, proto))
1312 goto csum_error;
1313
2783ef23
JDB
1314 saddr = ip_hdr(skb)->saddr;
1315 daddr = ip_hdr(skb)->daddr;
1316
db8dac20 1317 if (rt->rt_flags & (RTCF_BROADCAST|RTCF_MULTICAST))
e3163493
PE
1318 return __udp4_lib_mcast_deliver(net, skb, uh,
1319 saddr, daddr, udptable);
db8dac20 1320
607c4aaf 1321 sk = __udp4_lib_lookup_skb(skb, uh->source, uh->dest, udptable);
db8dac20
DM
1322
1323 if (sk != NULL) {
93821778 1324 int ret = udp_queue_rcv_skb(sk, skb);
db8dac20
DM
1325 sock_put(sk);
1326
1327 /* a return value > 0 means to resubmit the input, but
1328 * it wants the return to be -protocol, or 0
1329 */
1330 if (ret > 0)
1331 return -ret;
1332 return 0;
1333 }
1334
1335 if (!xfrm4_policy_check(NULL, XFRM_POLICY_IN, skb))
1336 goto drop;
1337 nf_reset(skb);
1338
1339 /* No socket. Drop packet silently, if checksum is wrong */
1340 if (udp_lib_checksum_complete(skb))
1341 goto csum_error;
1342
0283328e 1343 UDP_INC_STATS_BH(net, UDP_MIB_NOPORTS, proto == IPPROTO_UDPLITE);
db8dac20
DM
1344 icmp_send(skb, ICMP_DEST_UNREACH, ICMP_PORT_UNREACH, 0);
1345
1346 /*
1347 * Hmm. We got an UDP packet to a port to which we
1348 * don't wanna listen. Ignore it.
1349 */
1350 kfree_skb(skb);
1351 return 0;
1352
1353short_packet:
673d57e7 1354 LIMIT_NETDEBUG(KERN_DEBUG "UDP%s: short packet: From %pI4:%u %d/%d to %pI4:%u\n",
db8dac20 1355 proto == IPPROTO_UDPLITE ? "-Lite" : "",
673d57e7 1356 &saddr,
db8dac20
DM
1357 ntohs(uh->source),
1358 ulen,
1359 skb->len,
673d57e7 1360 &daddr,
db8dac20
DM
1361 ntohs(uh->dest));
1362 goto drop;
1363
1364csum_error:
1365 /*
1366 * RFC1122: OK. Discards the bad packet silently (as far as
1367 * the network is concerned, anyway) as per 4.1.3.4 (MUST).
1368 */
673d57e7 1369 LIMIT_NETDEBUG(KERN_DEBUG "UDP%s: bad checksum. From %pI4:%u to %pI4:%u ulen %d\n",
db8dac20 1370 proto == IPPROTO_UDPLITE ? "-Lite" : "",
673d57e7 1371 &saddr,
db8dac20 1372 ntohs(uh->source),
673d57e7 1373 &daddr,
db8dac20
DM
1374 ntohs(uh->dest),
1375 ulen);
1376drop:
0283328e 1377 UDP_INC_STATS_BH(net, UDP_MIB_INERRORS, proto == IPPROTO_UDPLITE);
db8dac20
DM
1378 kfree_skb(skb);
1379 return 0;
1380}
1381
1382int udp_rcv(struct sk_buff *skb)
1383{
645ca708 1384 return __udp4_lib_rcv(skb, &udp_table, IPPROTO_UDP);
db8dac20
DM
1385}
1386
7d06b2e0 1387void udp_destroy_sock(struct sock *sk)
db8dac20
DM
1388{
1389 lock_sock(sk);
1390 udp_flush_pending_frames(sk);
1391 release_sock(sk);
db8dac20
DM
1392}
1393
1da177e4
LT
1394/*
1395 * Socket option code for UDP
1396 */
4c0a6cb0 1397int udp_lib_setsockopt(struct sock *sk, int level, int optname,
b7058842 1398 char __user *optval, unsigned int optlen,
4c0a6cb0 1399 int (*push_pending_frames)(struct sock *))
1da177e4
LT
1400{
1401 struct udp_sock *up = udp_sk(sk);
1402 int val;
1403 int err = 0;
b2bf1e26 1404 int is_udplite = IS_UDPLITE(sk);
1da177e4 1405
c482c568 1406 if (optlen < sizeof(int))
1da177e4
LT
1407 return -EINVAL;
1408
1409 if (get_user(val, (int __user *)optval))
1410 return -EFAULT;
1411
6516c655 1412 switch (optname) {
1da177e4
LT
1413 case UDP_CORK:
1414 if (val != 0) {
1415 up->corkflag = 1;
1416 } else {
1417 up->corkflag = 0;
1418 lock_sock(sk);
4c0a6cb0 1419 (*push_pending_frames)(sk);
1da177e4
LT
1420 release_sock(sk);
1421 }
1422 break;
e905a9ed 1423
1da177e4
LT
1424 case UDP_ENCAP:
1425 switch (val) {
1426 case 0:
1427 case UDP_ENCAP_ESPINUDP:
1428 case UDP_ENCAP_ESPINUDP_NON_IKE:
067b207b
JC
1429 up->encap_rcv = xfrm4_udp_encap_rcv;
1430 /* FALLTHROUGH */
342f0234 1431 case UDP_ENCAP_L2TPINUDP:
1da177e4
LT
1432 up->encap_type = val;
1433 break;
1434 default:
1435 err = -ENOPROTOOPT;
1436 break;
1437 }
1438 break;
1439
ba4e58ec
GR
1440 /*
1441 * UDP-Lite's partial checksum coverage (RFC 3828).
1442 */
1443 /* The sender sets actual checksum coverage length via this option.
1444 * The case coverage > packet length is handled by send module. */
1445 case UDPLITE_SEND_CSCOV:
b2bf1e26 1446 if (!is_udplite) /* Disable the option on UDP sockets */
ba4e58ec
GR
1447 return -ENOPROTOOPT;
1448 if (val != 0 && val < 8) /* Illegal coverage: use default (8) */
1449 val = 8;
47112e25
GR
1450 else if (val > USHORT_MAX)
1451 val = USHORT_MAX;
ba4e58ec
GR
1452 up->pcslen = val;
1453 up->pcflag |= UDPLITE_SEND_CC;
1454 break;
1455
e905a9ed
YH
1456 /* The receiver specifies a minimum checksum coverage value. To make
1457 * sense, this should be set to at least 8 (as done below). If zero is
ba4e58ec
GR
1458 * used, this again means full checksum coverage. */
1459 case UDPLITE_RECV_CSCOV:
b2bf1e26 1460 if (!is_udplite) /* Disable the option on UDP sockets */
ba4e58ec
GR
1461 return -ENOPROTOOPT;
1462 if (val != 0 && val < 8) /* Avoid silly minimal values. */
1463 val = 8;
47112e25
GR
1464 else if (val > USHORT_MAX)
1465 val = USHORT_MAX;
ba4e58ec
GR
1466 up->pcrlen = val;
1467 up->pcflag |= UDPLITE_RECV_CC;
1468 break;
1469
1da177e4
LT
1470 default:
1471 err = -ENOPROTOOPT;
1472 break;
6516c655 1473 }
1da177e4
LT
1474
1475 return err;
1476}
c482c568 1477EXPORT_SYMBOL(udp_lib_setsockopt);
1da177e4 1478
db8dac20 1479int udp_setsockopt(struct sock *sk, int level, int optname,
b7058842 1480 char __user *optval, unsigned int optlen)
db8dac20
DM
1481{
1482 if (level == SOL_UDP || level == SOL_UDPLITE)
1483 return udp_lib_setsockopt(sk, level, optname, optval, optlen,
1484 udp_push_pending_frames);
1485 return ip_setsockopt(sk, level, optname, optval, optlen);
1486}
1487
1488#ifdef CONFIG_COMPAT
1489int compat_udp_setsockopt(struct sock *sk, int level, int optname,
b7058842 1490 char __user *optval, unsigned int optlen)
db8dac20
DM
1491{
1492 if (level == SOL_UDP || level == SOL_UDPLITE)
1493 return udp_lib_setsockopt(sk, level, optname, optval, optlen,
1494 udp_push_pending_frames);
1495 return compat_ip_setsockopt(sk, level, optname, optval, optlen);
1496}
1497#endif
1498
4c0a6cb0
GR
1499int udp_lib_getsockopt(struct sock *sk, int level, int optname,
1500 char __user *optval, int __user *optlen)
1da177e4
LT
1501{
1502 struct udp_sock *up = udp_sk(sk);
1503 int val, len;
1504
c482c568 1505 if (get_user(len, optlen))
1da177e4
LT
1506 return -EFAULT;
1507
1508 len = min_t(unsigned int, len, sizeof(int));
e905a9ed 1509
6516c655 1510 if (len < 0)
1da177e4
LT
1511 return -EINVAL;
1512
6516c655 1513 switch (optname) {
1da177e4
LT
1514 case UDP_CORK:
1515 val = up->corkflag;
1516 break;
1517
1518 case UDP_ENCAP:
1519 val = up->encap_type;
1520 break;
1521
ba4e58ec
GR
1522 /* The following two cannot be changed on UDP sockets, the return is
1523 * always 0 (which corresponds to the full checksum coverage of UDP). */
1524 case UDPLITE_SEND_CSCOV:
1525 val = up->pcslen;
1526 break;
1527
1528 case UDPLITE_RECV_CSCOV:
1529 val = up->pcrlen;
1530 break;
1531
1da177e4
LT
1532 default:
1533 return -ENOPROTOOPT;
6516c655 1534 }
1da177e4 1535
6516c655 1536 if (put_user(len, optlen))
e905a9ed 1537 return -EFAULT;
c482c568 1538 if (copy_to_user(optval, &val, len))
1da177e4 1539 return -EFAULT;
e905a9ed 1540 return 0;
1da177e4 1541}
c482c568 1542EXPORT_SYMBOL(udp_lib_getsockopt);
1da177e4 1543
db8dac20
DM
1544int udp_getsockopt(struct sock *sk, int level, int optname,
1545 char __user *optval, int __user *optlen)
1546{
1547 if (level == SOL_UDP || level == SOL_UDPLITE)
1548 return udp_lib_getsockopt(sk, level, optname, optval, optlen);
1549 return ip_getsockopt(sk, level, optname, optval, optlen);
1550}
1551
1552#ifdef CONFIG_COMPAT
1553int compat_udp_getsockopt(struct sock *sk, int level, int optname,
1554 char __user *optval, int __user *optlen)
1555{
1556 if (level == SOL_UDP || level == SOL_UDPLITE)
1557 return udp_lib_getsockopt(sk, level, optname, optval, optlen);
1558 return compat_ip_getsockopt(sk, level, optname, optval, optlen);
1559}
1560#endif
1da177e4
LT
1561/**
1562 * udp_poll - wait for a UDP event.
1563 * @file - file struct
1564 * @sock - socket
1565 * @wait - poll table
1566 *
e905a9ed 1567 * This is same as datagram poll, except for the special case of
1da177e4
LT
1568 * blocking sockets. If application is using a blocking fd
1569 * and a packet with checksum error is in the queue;
1570 * then it could get return from select indicating data available
1571 * but then block when reading it. Add special case code
1572 * to work around these arguably broken applications.
1573 */
1574unsigned int udp_poll(struct file *file, struct socket *sock, poll_table *wait)
1575{
1576 unsigned int mask = datagram_poll(file, sock, wait);
1577 struct sock *sk = sock->sk;
ba4e58ec 1578
1da177e4 1579 /* Check for false positives due to checksum errors */
85584672
ED
1580 if ((mask & POLLRDNORM) && !(file->f_flags & O_NONBLOCK) &&
1581 !(sk->sk_shutdown & RCV_SHUTDOWN) && !first_packet_length(sk))
1582 mask &= ~(POLLIN | POLLRDNORM);
1da177e4
LT
1583
1584 return mask;
e905a9ed 1585
1da177e4 1586}
c482c568 1587EXPORT_SYMBOL(udp_poll);
1da177e4 1588
db8dac20
DM
1589struct proto udp_prot = {
1590 .name = "UDP",
1591 .owner = THIS_MODULE,
1592 .close = udp_lib_close,
1593 .connect = ip4_datagram_connect,
1594 .disconnect = udp_disconnect,
1595 .ioctl = udp_ioctl,
1596 .destroy = udp_destroy_sock,
1597 .setsockopt = udp_setsockopt,
1598 .getsockopt = udp_getsockopt,
1599 .sendmsg = udp_sendmsg,
1600 .recvmsg = udp_recvmsg,
1601 .sendpage = udp_sendpage,
93821778 1602 .backlog_rcv = __udp_queue_rcv_skb,
db8dac20
DM
1603 .hash = udp_lib_hash,
1604 .unhash = udp_lib_unhash,
1605 .get_port = udp_v4_get_port,
1606 .memory_allocated = &udp_memory_allocated,
1607 .sysctl_mem = sysctl_udp_mem,
1608 .sysctl_wmem = &sysctl_udp_wmem_min,
1609 .sysctl_rmem = &sysctl_udp_rmem_min,
1610 .obj_size = sizeof(struct udp_sock),
271b72c7 1611 .slab_flags = SLAB_DESTROY_BY_RCU,
645ca708 1612 .h.udp_table = &udp_table,
db8dac20
DM
1613#ifdef CONFIG_COMPAT
1614 .compat_setsockopt = compat_udp_setsockopt,
1615 .compat_getsockopt = compat_udp_getsockopt,
1616#endif
db8dac20 1617};
c482c568 1618EXPORT_SYMBOL(udp_prot);
1da177e4
LT
1619
1620/* ------------------------------------------------------------------------ */
1621#ifdef CONFIG_PROC_FS
1622
645ca708 1623static struct sock *udp_get_first(struct seq_file *seq, int start)
1da177e4
LT
1624{
1625 struct sock *sk;
1626 struct udp_iter_state *state = seq->private;
6f191efe 1627 struct net *net = seq_file_net(seq);
1da177e4 1628
f86dcc5a
ED
1629 for (state->bucket = start; state->bucket <= state->udp_table->mask;
1630 ++state->bucket) {
88ab1932 1631 struct hlist_nulls_node *node;
645ca708 1632 struct udp_hslot *hslot = &state->udp_table->hash[state->bucket];
f86dcc5a
ED
1633
1634 if (hlist_nulls_empty(&hslot->head))
1635 continue;
1636
645ca708 1637 spin_lock_bh(&hslot->lock);
88ab1932 1638 sk_nulls_for_each(sk, node, &hslot->head) {
878628fb 1639 if (!net_eq(sock_net(sk), net))
a91275ef 1640 continue;
1da177e4
LT
1641 if (sk->sk_family == state->family)
1642 goto found;
1643 }
645ca708 1644 spin_unlock_bh(&hslot->lock);
1da177e4
LT
1645 }
1646 sk = NULL;
1647found:
1648 return sk;
1649}
1650
1651static struct sock *udp_get_next(struct seq_file *seq, struct sock *sk)
1652{
1653 struct udp_iter_state *state = seq->private;
6f191efe 1654 struct net *net = seq_file_net(seq);
1da177e4
LT
1655
1656 do {
88ab1932 1657 sk = sk_nulls_next(sk);
878628fb 1658 } while (sk && (!net_eq(sock_net(sk), net) || sk->sk_family != state->family));
1da177e4 1659
645ca708 1660 if (!sk) {
f86dcc5a 1661 if (state->bucket <= state->udp_table->mask)
30842f29 1662 spin_unlock_bh(&state->udp_table->hash[state->bucket].lock);
645ca708 1663 return udp_get_first(seq, state->bucket + 1);
1da177e4
LT
1664 }
1665 return sk;
1666}
1667
1668static struct sock *udp_get_idx(struct seq_file *seq, loff_t pos)
1669{
645ca708 1670 struct sock *sk = udp_get_first(seq, 0);
1da177e4
LT
1671
1672 if (sk)
6516c655 1673 while (pos && (sk = udp_get_next(seq, sk)) != NULL)
1da177e4
LT
1674 --pos;
1675 return pos ? NULL : sk;
1676}
1677
1678static void *udp_seq_start(struct seq_file *seq, loff_t *pos)
1679{
30842f29 1680 struct udp_iter_state *state = seq->private;
f86dcc5a 1681 state->bucket = MAX_UDP_PORTS;
30842f29 1682
b50660f1 1683 return *pos ? udp_get_idx(seq, *pos-1) : SEQ_START_TOKEN;
1da177e4
LT
1684}
1685
1686static void *udp_seq_next(struct seq_file *seq, void *v, loff_t *pos)
1687{
1688 struct sock *sk;
1689
b50660f1 1690 if (v == SEQ_START_TOKEN)
1da177e4
LT
1691 sk = udp_get_idx(seq, 0);
1692 else
1693 sk = udp_get_next(seq, v);
1694
1695 ++*pos;
1696 return sk;
1697}
1698
1699static void udp_seq_stop(struct seq_file *seq, void *v)
1700{
645ca708
ED
1701 struct udp_iter_state *state = seq->private;
1702
f86dcc5a 1703 if (state->bucket <= state->udp_table->mask)
645ca708 1704 spin_unlock_bh(&state->udp_table->hash[state->bucket].lock);
1da177e4
LT
1705}
1706
1707static int udp_seq_open(struct inode *inode, struct file *file)
1708{
1709 struct udp_seq_afinfo *afinfo = PDE(inode)->data;
a2be75c1
DL
1710 struct udp_iter_state *s;
1711 int err;
a91275ef 1712
a2be75c1
DL
1713 err = seq_open_net(inode, file, &afinfo->seq_ops,
1714 sizeof(struct udp_iter_state));
1715 if (err < 0)
1716 return err;
a91275ef 1717
a2be75c1 1718 s = ((struct seq_file *)file->private_data)->private;
1da177e4 1719 s->family = afinfo->family;
645ca708 1720 s->udp_table = afinfo->udp_table;
a2be75c1 1721 return err;
a91275ef
DL
1722}
1723
1da177e4 1724/* ------------------------------------------------------------------------ */
0c96d8c5 1725int udp_proc_register(struct net *net, struct udp_seq_afinfo *afinfo)
1da177e4
LT
1726{
1727 struct proc_dir_entry *p;
1728 int rc = 0;
1729
3ba9441b
DL
1730 afinfo->seq_fops.open = udp_seq_open;
1731 afinfo->seq_fops.read = seq_read;
1732 afinfo->seq_fops.llseek = seq_lseek;
1733 afinfo->seq_fops.release = seq_release_net;
1da177e4 1734
dda61925
DL
1735 afinfo->seq_ops.start = udp_seq_start;
1736 afinfo->seq_ops.next = udp_seq_next;
1737 afinfo->seq_ops.stop = udp_seq_stop;
1738
84841c3c
DL
1739 p = proc_create_data(afinfo->name, S_IRUGO, net->proc_net,
1740 &afinfo->seq_fops, afinfo);
1741 if (!p)
1da177e4
LT
1742 rc = -ENOMEM;
1743 return rc;
1744}
c482c568 1745EXPORT_SYMBOL(udp_proc_register);
1da177e4 1746
0c96d8c5 1747void udp_proc_unregister(struct net *net, struct udp_seq_afinfo *afinfo)
1da177e4 1748{
0c96d8c5 1749 proc_net_remove(net, afinfo->name);
1da177e4 1750}
c482c568 1751EXPORT_SYMBOL(udp_proc_unregister);
db8dac20
DM
1752
1753/* ------------------------------------------------------------------------ */
5e659e4c
PE
1754static void udp4_format_sock(struct sock *sp, struct seq_file *f,
1755 int bucket, int *len)
db8dac20
DM
1756{
1757 struct inet_sock *inet = inet_sk(sp);
c720c7e8
ED
1758 __be32 dest = inet->inet_daddr;
1759 __be32 src = inet->inet_rcv_saddr;
1760 __u16 destp = ntohs(inet->inet_dport);
1761 __u16 srcp = ntohs(inet->inet_sport);
db8dac20 1762
f86dcc5a 1763 seq_printf(f, "%5d: %08X:%04X %08X:%04X"
cb61cb9b 1764 " %02X %08X:%08X %02X:%08lX %08X %5d %8d %lu %d %p %d%n",
db8dac20 1765 bucket, src, srcp, dest, destp, sp->sk_state,
31e6d363
ED
1766 sk_wmem_alloc_get(sp),
1767 sk_rmem_alloc_get(sp),
db8dac20 1768 0, 0L, 0, sock_i_uid(sp), 0, sock_i_ino(sp),
cb61cb9b
ED
1769 atomic_read(&sp->sk_refcnt), sp,
1770 atomic_read(&sp->sk_drops), len);
db8dac20
DM
1771}
1772
1773int udp4_seq_show(struct seq_file *seq, void *v)
1774{
1775 if (v == SEQ_START_TOKEN)
1776 seq_printf(seq, "%-127s\n",
1777 " sl local_address rem_address st tx_queue "
1778 "rx_queue tr tm->when retrnsmt uid timeout "
cb61cb9b 1779 "inode ref pointer drops");
db8dac20 1780 else {
db8dac20 1781 struct udp_iter_state *state = seq->private;
5e659e4c 1782 int len;
db8dac20 1783
5e659e4c 1784 udp4_format_sock(v, seq, state->bucket, &len);
c482c568 1785 seq_printf(seq, "%*s\n", 127 - len, "");
db8dac20
DM
1786 }
1787 return 0;
1788}
1789
1790/* ------------------------------------------------------------------------ */
db8dac20 1791static struct udp_seq_afinfo udp4_seq_afinfo = {
db8dac20
DM
1792 .name = "udp",
1793 .family = AF_INET,
645ca708 1794 .udp_table = &udp_table,
4ad96d39
DL
1795 .seq_fops = {
1796 .owner = THIS_MODULE,
1797 },
dda61925
DL
1798 .seq_ops = {
1799 .show = udp4_seq_show,
1800 },
db8dac20
DM
1801};
1802
15439feb
PE
1803static int udp4_proc_init_net(struct net *net)
1804{
1805 return udp_proc_register(net, &udp4_seq_afinfo);
1806}
1807
1808static void udp4_proc_exit_net(struct net *net)
1809{
1810 udp_proc_unregister(net, &udp4_seq_afinfo);
1811}
1812
1813static struct pernet_operations udp4_net_ops = {
1814 .init = udp4_proc_init_net,
1815 .exit = udp4_proc_exit_net,
1816};
1817
db8dac20
DM
1818int __init udp4_proc_init(void)
1819{
15439feb 1820 return register_pernet_subsys(&udp4_net_ops);
db8dac20
DM
1821}
1822
1823void udp4_proc_exit(void)
1824{
15439feb 1825 unregister_pernet_subsys(&udp4_net_ops);
db8dac20 1826}
1da177e4
LT
1827#endif /* CONFIG_PROC_FS */
1828
f86dcc5a
ED
1829static __initdata unsigned long uhash_entries;
1830static int __init set_uhash_entries(char *str)
645ca708 1831{
f86dcc5a
ED
1832 if (!str)
1833 return 0;
1834 uhash_entries = simple_strtoul(str, &str, 0);
1835 if (uhash_entries && uhash_entries < UDP_HTABLE_SIZE_MIN)
1836 uhash_entries = UDP_HTABLE_SIZE_MIN;
1837 return 1;
1838}
1839__setup("uhash_entries=", set_uhash_entries);
645ca708 1840
f86dcc5a
ED
1841void __init udp_table_init(struct udp_table *table, const char *name)
1842{
1843 unsigned int i;
1844
1845 if (!CONFIG_BASE_SMALL)
1846 table->hash = alloc_large_system_hash(name,
1847 sizeof(struct udp_hslot),
1848 uhash_entries,
1849 21, /* one slot per 2 MB */
1850 0,
1851 &table->log,
1852 &table->mask,
1853 64 * 1024);
1854 /*
1855 * Make sure hash table has the minimum size
1856 */
1857 if (CONFIG_BASE_SMALL || table->mask < UDP_HTABLE_SIZE_MIN - 1) {
1858 table->hash = kmalloc(UDP_HTABLE_SIZE_MIN *
1859 sizeof(struct udp_hslot), GFP_KERNEL);
1860 if (!table->hash)
1861 panic(name);
1862 table->log = ilog2(UDP_HTABLE_SIZE_MIN);
1863 table->mask = UDP_HTABLE_SIZE_MIN - 1;
1864 }
1865 for (i = 0; i <= table->mask; i++) {
88ab1932 1866 INIT_HLIST_NULLS_HEAD(&table->hash[i].head, i);
fdcc8aa9 1867 table->hash[i].count = 0;
645ca708
ED
1868 spin_lock_init(&table->hash[i].lock);
1869 }
1870}
1871
95766fff
HA
1872void __init udp_init(void)
1873{
8203efb3 1874 unsigned long nr_pages, limit;
95766fff 1875
f86dcc5a 1876 udp_table_init(&udp_table, "UDP");
95766fff
HA
1877 /* Set the pressure threshold up by the same strategy of TCP. It is a
1878 * fraction of global memory that is up to 1/2 at 256 MB, decreasing
1879 * toward zero with the amount of memory, with a floor of 128 pages.
1880 */
8203efb3
ED
1881 nr_pages = totalram_pages - totalhigh_pages;
1882 limit = min(nr_pages, 1UL<<(28-PAGE_SHIFT)) >> (20-PAGE_SHIFT);
1883 limit = (limit * (nr_pages >> (20-PAGE_SHIFT))) >> (PAGE_SHIFT-11);
95766fff
HA
1884 limit = max(limit, 128UL);
1885 sysctl_udp_mem[0] = limit / 4 * 3;
1886 sysctl_udp_mem[1] = limit;
1887 sysctl_udp_mem[2] = sysctl_udp_mem[0] * 2;
1888
1889 sysctl_udp_rmem_min = SK_MEM_QUANTUM;
1890 sysctl_udp_wmem_min = SK_MEM_QUANTUM;
1891}
1892
d7ca4cc0
SS
1893int udp4_ufo_send_check(struct sk_buff *skb)
1894{
1895 const struct iphdr *iph;
1896 struct udphdr *uh;
1897
1898 if (!pskb_may_pull(skb, sizeof(*uh)))
1899 return -EINVAL;
1900
1901 iph = ip_hdr(skb);
1902 uh = udp_hdr(skb);
1903
1904 uh->check = ~csum_tcpudp_magic(iph->saddr, iph->daddr, skb->len,
1905 IPPROTO_UDP, 0);
1906 skb->csum_start = skb_transport_header(skb) - skb->head;
1907 skb->csum_offset = offsetof(struct udphdr, check);
1908 skb->ip_summed = CHECKSUM_PARTIAL;
1909 return 0;
1910}
1911
1912struct sk_buff *udp4_ufo_fragment(struct sk_buff *skb, int features)
1913{
1914 struct sk_buff *segs = ERR_PTR(-EINVAL);
1915 unsigned int mss;
1916 int offset;
1917 __wsum csum;
1918
1919 mss = skb_shinfo(skb)->gso_size;
1920 if (unlikely(skb->len <= mss))
1921 goto out;
1922
1923 if (skb_gso_ok(skb, features | NETIF_F_GSO_ROBUST)) {
1924 /* Packet is from an untrusted source, reset gso_segs. */
1925 int type = skb_shinfo(skb)->gso_type;
1926
1927 if (unlikely(type & ~(SKB_GSO_UDP | SKB_GSO_DODGY) ||
1928 !(type & (SKB_GSO_UDP))))
1929 goto out;
1930
1931 skb_shinfo(skb)->gso_segs = DIV_ROUND_UP(skb->len, mss);
1932
1933 segs = NULL;
1934 goto out;
1935 }
1936
1937 /* Do software UFO. Complete and fill in the UDP checksum as HW cannot
1938 * do checksum of UDP packets sent as multiple IP fragments.
1939 */
1940 offset = skb->csum_start - skb_headroom(skb);
c482c568 1941 csum = skb_checksum(skb, offset, skb->len - offset, 0);
d7ca4cc0
SS
1942 offset += skb->csum_offset;
1943 *(__sum16 *)(skb->data + offset) = csum_fold(csum);
1944 skb->ip_summed = CHECKSUM_NONE;
1945
1946 /* Fragment the skb. IP headers of the fragments are updated in
1947 * inet_gso_segment()
1948 */
1949 segs = skb_segment(skb, features);
1950out:
1951 return segs;
1952}
1953