1 // SPDX-License-Identifier: GPL-2.0-or-later
3 * Anycast support for IPv6
4 * Linux INET6 implementation
7 * David L Stevens (dlstevens@us.ibm.com)
9 * based heavily on net/ipv6/mcast.c
12 #include <linux/capability.h>
13 #include <linux/module.h>
14 #include <linux/errno.h>
15 #include <linux/types.h>
16 #include <linux/random.h>
17 #include <linux/string.h>
18 #include <linux/socket.h>
19 #include <linux/sockios.h>
20 #include <linux/net.h>
21 #include <linux/in6.h>
22 #include <linux/netdevice.h>
23 #include <linux/if_arp.h>
24 #include <linux/route.h>
25 #include <linux/init.h>
26 #include <linux/proc_fs.h>
27 #include <linux/seq_file.h>
28 #include <linux/slab.h>
30 #include <net/net_namespace.h>
35 #include <net/protocol.h>
36 #include <net/if_inet6.h>
37 #include <net/ndisc.h>
38 #include <net/addrconf.h>
39 #include <net/ip6_route.h>
41 #include <net/checksum.h>
43 #define IN6_ADDR_HSIZE_SHIFT 8
44 #define IN6_ADDR_HSIZE BIT(IN6_ADDR_HSIZE_SHIFT)
45 /* anycast address hash table
47 static struct hlist_head inet6_acaddr_lst
[IN6_ADDR_HSIZE
];
48 static DEFINE_SPINLOCK(acaddr_hash_lock
);
50 static int ipv6_dev_ac_dec(struct net_device
*dev
, const struct in6_addr
*addr
);
52 static u32
inet6_acaddr_hash(const struct net
*net
,
53 const struct in6_addr
*addr
)
55 u32 val
= __ipv6_addr_jhash(addr
, net_hash_mix(net
));
57 return hash_32(val
, IN6_ADDR_HSIZE_SHIFT
);
61 * socket join an anycast group
64 int ipv6_sock_ac_join(struct sock
*sk
, int ifindex
, const struct in6_addr
*addr
)
66 struct ipv6_pinfo
*np
= inet6_sk(sk
);
67 struct net_device
*dev
= NULL
;
68 struct inet6_dev
*idev
;
69 struct ipv6_ac_socklist
*pac
;
70 struct net
*net
= sock_net(sk
);
71 int ishost
= !net
->ipv6
.devconf_all
->forwarding
;
76 if (!ns_capable(net
->user_ns
, CAP_NET_ADMIN
))
78 if (ipv6_addr_is_multicast(addr
))
82 dev
= __dev_get_by_index(net
, ifindex
);
84 if (ipv6_chk_addr_and_flags(net
, addr
, dev
, true, 0, IFA_F_TENTATIVE
))
87 pac
= sock_kmalloc(sk
, sizeof(struct ipv6_ac_socklist
), GFP_KERNEL
);
91 pac
->acl_addr
= *addr
;
96 rt
= rt6_lookup(net
, addr
, NULL
, 0, NULL
, 0);
101 err
= -EADDRNOTAVAIL
;
104 /* router, no matching interface: just pick one */
105 dev
= __dev_get_by_flags(net
, IFF_UP
,
106 IFF_UP
| IFF_LOOPBACK
);
115 idev
= __in6_dev_get(dev
);
120 err
= -EADDRNOTAVAIL
;
123 /* reset ishost, now that we have a specific device */
124 ishost
= !idev
->cnf
.forwarding
;
126 pac
->acl_ifindex
= dev
->ifindex
;
129 * For hosts, allow link-local or matching prefix anycasts.
130 * This obviates the need for propagating anycast routes while
131 * still allowing some non-router anycast participation.
133 if (!ipv6_chk_prefix(addr
, dev
)) {
135 err
= -EADDRNOTAVAIL
;
140 err
= __ipv6_dev_ac_inc(idev
, addr
);
142 pac
->acl_next
= np
->ipv6_ac_list
;
143 np
->ipv6_ac_list
= pac
;
149 sock_kfree_s(sk
, pac
, sizeof(*pac
));
154 * socket leave an anycast group
156 int ipv6_sock_ac_drop(struct sock
*sk
, int ifindex
, const struct in6_addr
*addr
)
158 struct ipv6_pinfo
*np
= inet6_sk(sk
);
159 struct net_device
*dev
;
160 struct ipv6_ac_socklist
*pac
, *prev_pac
;
161 struct net
*net
= sock_net(sk
);
166 for (pac
= np
->ipv6_ac_list
; pac
; pac
= pac
->acl_next
) {
167 if ((ifindex
== 0 || pac
->acl_ifindex
== ifindex
) &&
168 ipv6_addr_equal(&pac
->acl_addr
, addr
))
175 prev_pac
->acl_next
= pac
->acl_next
;
177 np
->ipv6_ac_list
= pac
->acl_next
;
179 dev
= __dev_get_by_index(net
, pac
->acl_ifindex
);
181 ipv6_dev_ac_dec(dev
, &pac
->acl_addr
);
183 sock_kfree_s(sk
, pac
, sizeof(*pac
));
187 void __ipv6_sock_ac_close(struct sock
*sk
)
189 struct ipv6_pinfo
*np
= inet6_sk(sk
);
190 struct net_device
*dev
= NULL
;
191 struct ipv6_ac_socklist
*pac
;
192 struct net
*net
= sock_net(sk
);
196 pac
= np
->ipv6_ac_list
;
197 np
->ipv6_ac_list
= NULL
;
201 struct ipv6_ac_socklist
*next
= pac
->acl_next
;
203 if (pac
->acl_ifindex
!= prev_index
) {
204 dev
= __dev_get_by_index(net
, pac
->acl_ifindex
);
205 prev_index
= pac
->acl_ifindex
;
208 ipv6_dev_ac_dec(dev
, &pac
->acl_addr
);
209 sock_kfree_s(sk
, pac
, sizeof(*pac
));
214 void ipv6_sock_ac_close(struct sock
*sk
)
216 struct ipv6_pinfo
*np
= inet6_sk(sk
);
218 if (!np
->ipv6_ac_list
)
221 __ipv6_sock_ac_close(sk
);
225 static void ipv6_add_acaddr_hash(struct net
*net
, struct ifacaddr6
*aca
)
227 unsigned int hash
= inet6_acaddr_hash(net
, &aca
->aca_addr
);
229 spin_lock(&acaddr_hash_lock
);
230 hlist_add_head_rcu(&aca
->aca_addr_lst
, &inet6_acaddr_lst
[hash
]);
231 spin_unlock(&acaddr_hash_lock
);
234 static void ipv6_del_acaddr_hash(struct ifacaddr6
*aca
)
236 spin_lock(&acaddr_hash_lock
);
237 hlist_del_init_rcu(&aca
->aca_addr_lst
);
238 spin_unlock(&acaddr_hash_lock
);
241 static void aca_get(struct ifacaddr6
*aca
)
243 refcount_inc(&aca
->aca_refcnt
);
246 static void aca_free_rcu(struct rcu_head
*h
)
248 struct ifacaddr6
*aca
= container_of(h
, struct ifacaddr6
, rcu
);
250 fib6_info_release(aca
->aca_rt
);
254 static void aca_put(struct ifacaddr6
*ac
)
256 if (refcount_dec_and_test(&ac
->aca_refcnt
))
257 call_rcu_hurry(&ac
->rcu
, aca_free_rcu
);
260 static struct ifacaddr6
*aca_alloc(struct fib6_info
*f6i
,
261 const struct in6_addr
*addr
)
263 struct ifacaddr6
*aca
;
265 aca
= kzalloc(sizeof(*aca
), GFP_ATOMIC
);
269 aca
->aca_addr
= *addr
;
272 INIT_HLIST_NODE(&aca
->aca_addr_lst
);
274 /* aca_tstamp should be updated upon changes */
275 aca
->aca_cstamp
= aca
->aca_tstamp
= jiffies
;
276 refcount_set(&aca
->aca_refcnt
, 1);
282 * device anycast group inc (add if not found)
284 int __ipv6_dev_ac_inc(struct inet6_dev
*idev
, const struct in6_addr
*addr
)
286 struct ifacaddr6
*aca
;
287 struct fib6_info
*f6i
;
293 write_lock_bh(&idev
->lock
);
299 for (aca
= rtnl_dereference(idev
->ac_list
); aca
;
300 aca
= rtnl_dereference(aca
->aca_next
)) {
301 if (ipv6_addr_equal(&aca
->aca_addr
, addr
)) {
308 net
= dev_net(idev
->dev
);
309 f6i
= addrconf_f6i_alloc(net
, idev
, addr
, true, GFP_ATOMIC
, NULL
);
314 aca
= aca_alloc(f6i
, addr
);
316 fib6_info_release(f6i
);
321 /* Hold this for addrconf_join_solict() below before we unlock,
322 * it is already exposed via idev->ac_list.
325 aca
->aca_next
= idev
->ac_list
;
326 rcu_assign_pointer(idev
->ac_list
, aca
);
328 write_unlock_bh(&idev
->lock
);
330 ipv6_add_acaddr_hash(net
, aca
);
332 ip6_ins_rt(net
, f6i
);
334 addrconf_join_solict(idev
->dev
, &aca
->aca_addr
);
339 write_unlock_bh(&idev
->lock
);
344 * device anycast group decrement
346 int __ipv6_dev_ac_dec(struct inet6_dev
*idev
, const struct in6_addr
*addr
)
348 struct ifacaddr6
*aca
, *prev_aca
;
352 write_lock_bh(&idev
->lock
);
354 for (aca
= rtnl_dereference(idev
->ac_list
); aca
;
355 aca
= rtnl_dereference(aca
->aca_next
)) {
356 if (ipv6_addr_equal(&aca
->aca_addr
, addr
))
361 write_unlock_bh(&idev
->lock
);
364 if (--aca
->aca_users
> 0) {
365 write_unlock_bh(&idev
->lock
);
369 rcu_assign_pointer(prev_aca
->aca_next
, aca
->aca_next
);
371 rcu_assign_pointer(idev
->ac_list
, aca
->aca_next
);
372 write_unlock_bh(&idev
->lock
);
373 ipv6_del_acaddr_hash(aca
);
374 addrconf_leave_solict(idev
, &aca
->aca_addr
);
376 ip6_del_rt(dev_net(idev
->dev
), aca
->aca_rt
, false);
382 /* called with rtnl_lock() */
383 static int ipv6_dev_ac_dec(struct net_device
*dev
, const struct in6_addr
*addr
)
385 struct inet6_dev
*idev
= __in6_dev_get(dev
);
389 return __ipv6_dev_ac_dec(idev
, addr
);
392 void ipv6_ac_destroy_dev(struct inet6_dev
*idev
)
394 struct ifacaddr6
*aca
;
396 write_lock_bh(&idev
->lock
);
397 while ((aca
= rtnl_dereference(idev
->ac_list
)) != NULL
) {
398 rcu_assign_pointer(idev
->ac_list
, aca
->aca_next
);
399 write_unlock_bh(&idev
->lock
);
401 ipv6_del_acaddr_hash(aca
);
403 addrconf_leave_solict(idev
, &aca
->aca_addr
);
405 ip6_del_rt(dev_net(idev
->dev
), aca
->aca_rt
, false);
409 write_lock_bh(&idev
->lock
);
411 write_unlock_bh(&idev
->lock
);
415 * check if the interface has this anycast address
416 * called with rcu_read_lock()
418 static bool ipv6_chk_acast_dev(struct net_device
*dev
, const struct in6_addr
*addr
)
420 struct inet6_dev
*idev
;
421 struct ifacaddr6
*aca
;
423 idev
= __in6_dev_get(dev
);
425 for (aca
= rcu_dereference(idev
->ac_list
); aca
;
426 aca
= rcu_dereference(aca
->aca_next
))
427 if (ipv6_addr_equal(&aca
->aca_addr
, addr
))
435 * check if given interface (or any, if dev==0) has this anycast address
437 bool ipv6_chk_acast_addr(struct net
*net
, struct net_device
*dev
,
438 const struct in6_addr
*addr
)
440 struct net_device
*nh_dev
;
441 struct ifacaddr6
*aca
;
446 found
= ipv6_chk_acast_dev(dev
, addr
);
448 unsigned int hash
= inet6_acaddr_hash(net
, addr
);
450 hlist_for_each_entry_rcu(aca
, &inet6_acaddr_lst
[hash
],
452 nh_dev
= fib6_info_nh_dev(aca
->aca_rt
);
453 if (!nh_dev
|| !net_eq(dev_net(nh_dev
), net
))
455 if (ipv6_addr_equal(&aca
->aca_addr
, addr
)) {
465 /* check if this anycast address is link-local on given interface or
468 bool ipv6_chk_acast_addr_src(struct net
*net
, struct net_device
*dev
,
469 const struct in6_addr
*addr
)
471 return ipv6_chk_acast_addr(net
,
472 (ipv6_addr_type(addr
) & IPV6_ADDR_LINKLOCAL
?
477 #ifdef CONFIG_PROC_FS
478 struct ac6_iter_state
{
479 struct seq_net_private p
;
480 struct net_device
*dev
;
483 #define ac6_seq_private(seq) ((struct ac6_iter_state *)(seq)->private)
485 static inline struct ifacaddr6
*ac6_get_first(struct seq_file
*seq
)
487 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
488 struct net
*net
= seq_file_net(seq
);
489 struct ifacaddr6
*im
= NULL
;
491 for_each_netdev_rcu(net
, state
->dev
) {
492 struct inet6_dev
*idev
;
494 idev
= __in6_dev_get(state
->dev
);
497 im
= rcu_dereference(idev
->ac_list
);
504 static struct ifacaddr6
*ac6_get_next(struct seq_file
*seq
, struct ifacaddr6
*im
)
506 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
507 struct inet6_dev
*idev
;
509 im
= rcu_dereference(im
->aca_next
);
511 state
->dev
= next_net_device_rcu(state
->dev
);
514 idev
= __in6_dev_get(state
->dev
);
517 im
= rcu_dereference(idev
->ac_list
);
522 static struct ifacaddr6
*ac6_get_idx(struct seq_file
*seq
, loff_t pos
)
524 struct ifacaddr6
*im
= ac6_get_first(seq
);
526 while (pos
&& (im
= ac6_get_next(seq
, im
)) != NULL
)
528 return pos
? NULL
: im
;
531 static void *ac6_seq_start(struct seq_file
*seq
, loff_t
*pos
)
535 return ac6_get_idx(seq
, *pos
);
538 static void *ac6_seq_next(struct seq_file
*seq
, void *v
, loff_t
*pos
)
540 struct ifacaddr6
*im
= ac6_get_next(seq
, v
);
546 static void ac6_seq_stop(struct seq_file
*seq
, void *v
)
552 static int ac6_seq_show(struct seq_file
*seq
, void *v
)
554 struct ifacaddr6
*im
= (struct ifacaddr6
*)v
;
555 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
557 seq_printf(seq
, "%-4d %-15s %pi6 %5d\n",
558 state
->dev
->ifindex
, state
->dev
->name
,
559 &im
->aca_addr
, im
->aca_users
);
563 static const struct seq_operations ac6_seq_ops
= {
564 .start
= ac6_seq_start
,
565 .next
= ac6_seq_next
,
566 .stop
= ac6_seq_stop
,
567 .show
= ac6_seq_show
,
570 int __net_init
ac6_proc_init(struct net
*net
)
572 if (!proc_create_net("anycast6", 0444, net
->proc_net
, &ac6_seq_ops
,
573 sizeof(struct ac6_iter_state
)))
579 void ac6_proc_exit(struct net
*net
)
581 remove_proc_entry("anycast6", net
->proc_net
);
585 /* Init / cleanup code
587 int __init
ipv6_anycast_init(void)
591 for (i
= 0; i
< IN6_ADDR_HSIZE
; i
++)
592 INIT_HLIST_HEAD(&inet6_acaddr_lst
[i
]);
596 void ipv6_anycast_cleanup(void)
600 spin_lock(&acaddr_hash_lock
);
601 for (i
= 0; i
< IN6_ADDR_HSIZE
; i
++)
602 WARN_ON(!hlist_empty(&inet6_acaddr_lst
[i
]));
603 spin_unlock(&acaddr_hash_lock
);