ALSA: usb-audio: Fix an out-of-bound read in create_composite_quirks
[linux/fpc-iii.git] / net / ipv6 / tunnel6.c
blobdae25cad05cd788146321016597a7badb53ef3d4
1 /*
2 * Copyright (C)2003,2004 USAGI/WIDE Project
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see <http://www.gnu.org/licenses/>.
17 * Authors Mitsuru KANDA <mk@linux-ipv6.org>
18 * YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org>
21 #define pr_fmt(fmt) "IPv6: " fmt
23 #include <linux/icmpv6.h>
24 #include <linux/init.h>
25 #include <linux/module.h>
26 #include <linux/mutex.h>
27 #include <linux/netdevice.h>
28 #include <linux/skbuff.h>
29 #include <linux/slab.h>
30 #include <net/ipv6.h>
31 #include <net/protocol.h>
32 #include <net/xfrm.h>
34 static struct xfrm6_tunnel __rcu *tunnel6_handlers __read_mostly;
35 static struct xfrm6_tunnel __rcu *tunnel46_handlers __read_mostly;
36 static DEFINE_MUTEX(tunnel6_mutex);
38 int xfrm6_tunnel_register(struct xfrm6_tunnel *handler, unsigned short family)
40 struct xfrm6_tunnel __rcu **pprev;
41 struct xfrm6_tunnel *t;
42 int ret = -EEXIST;
43 int priority = handler->priority;
45 mutex_lock(&tunnel6_mutex);
47 for (pprev = (family == AF_INET6) ? &tunnel6_handlers : &tunnel46_handlers;
48 (t = rcu_dereference_protected(*pprev,
49 lockdep_is_held(&tunnel6_mutex))) != NULL;
50 pprev = &t->next) {
51 if (t->priority > priority)
52 break;
53 if (t->priority == priority)
54 goto err;
57 handler->next = *pprev;
58 rcu_assign_pointer(*pprev, handler);
60 ret = 0;
62 err:
63 mutex_unlock(&tunnel6_mutex);
65 return ret;
67 EXPORT_SYMBOL(xfrm6_tunnel_register);
69 int xfrm6_tunnel_deregister(struct xfrm6_tunnel *handler, unsigned short family)
71 struct xfrm6_tunnel __rcu **pprev;
72 struct xfrm6_tunnel *t;
73 int ret = -ENOENT;
75 mutex_lock(&tunnel6_mutex);
77 for (pprev = (family == AF_INET6) ? &tunnel6_handlers : &tunnel46_handlers;
78 (t = rcu_dereference_protected(*pprev,
79 lockdep_is_held(&tunnel6_mutex))) != NULL;
80 pprev = &t->next) {
81 if (t == handler) {
82 *pprev = handler->next;
83 ret = 0;
84 break;
88 mutex_unlock(&tunnel6_mutex);
90 synchronize_net();
92 return ret;
94 EXPORT_SYMBOL(xfrm6_tunnel_deregister);
96 #define for_each_tunnel_rcu(head, handler) \
97 for (handler = rcu_dereference(head); \
98 handler != NULL; \
99 handler = rcu_dereference(handler->next)) \
101 static int tunnel6_rcv(struct sk_buff *skb)
103 struct xfrm6_tunnel *handler;
105 if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
106 goto drop;
108 for_each_tunnel_rcu(tunnel6_handlers, handler)
109 if (!handler->handler(skb))
110 return 0;
112 icmpv6_send(skb, ICMPV6_DEST_UNREACH, ICMPV6_PORT_UNREACH, 0);
114 drop:
115 kfree_skb(skb);
116 return 0;
119 static int tunnel46_rcv(struct sk_buff *skb)
121 struct xfrm6_tunnel *handler;
123 if (!pskb_may_pull(skb, sizeof(struct iphdr)))
124 goto drop;
126 for_each_tunnel_rcu(tunnel46_handlers, handler)
127 if (!handler->handler(skb))
128 return 0;
130 icmpv6_send(skb, ICMPV6_DEST_UNREACH, ICMPV6_PORT_UNREACH, 0);
132 drop:
133 kfree_skb(skb);
134 return 0;
137 static void tunnel6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
138 u8 type, u8 code, int offset, __be32 info)
140 struct xfrm6_tunnel *handler;
142 for_each_tunnel_rcu(tunnel6_handlers, handler)
143 if (!handler->err_handler(skb, opt, type, code, offset, info))
144 break;
147 static void tunnel46_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
148 u8 type, u8 code, int offset, __be32 info)
150 struct xfrm6_tunnel *handler;
152 for_each_tunnel_rcu(tunnel46_handlers, handler)
153 if (!handler->err_handler(skb, opt, type, code, offset, info))
154 break;
157 static const struct inet6_protocol tunnel6_protocol = {
158 .handler = tunnel6_rcv,
159 .err_handler = tunnel6_err,
160 .flags = INET6_PROTO_NOPOLICY|INET6_PROTO_FINAL,
163 static const struct inet6_protocol tunnel46_protocol = {
164 .handler = tunnel46_rcv,
165 .err_handler = tunnel46_err,
166 .flags = INET6_PROTO_NOPOLICY|INET6_PROTO_FINAL,
169 static int __init tunnel6_init(void)
171 if (inet6_add_protocol(&tunnel6_protocol, IPPROTO_IPV6)) {
172 pr_err("%s: can't add protocol\n", __func__);
173 return -EAGAIN;
175 if (inet6_add_protocol(&tunnel46_protocol, IPPROTO_IPIP)) {
176 pr_err("%s: can't add protocol\n", __func__);
177 inet6_del_protocol(&tunnel6_protocol, IPPROTO_IPV6);
178 return -EAGAIN;
180 return 0;
183 static void __exit tunnel6_fini(void)
185 if (inet6_del_protocol(&tunnel46_protocol, IPPROTO_IPIP))
186 pr_err("%s: can't remove protocol\n", __func__);
187 if (inet6_del_protocol(&tunnel6_protocol, IPPROTO_IPV6))
188 pr_err("%s: can't remove protocol\n", __func__);
191 module_init(tunnel6_init);
192 module_exit(tunnel6_fini);
193 MODULE_LICENSE("GPL");