1 // SPDX-License-Identifier: GPL-2.0-or-later
3 * Anycast support for IPv6
4 * Linux INET6 implementation
7 * David L Stevens (dlstevens@us.ibm.com)
9 * based heavily on net/ipv6/mcast.c
12 #include <linux/capability.h>
13 #include <linux/module.h>
14 #include <linux/errno.h>
15 #include <linux/types.h>
16 #include <linux/random.h>
17 #include <linux/string.h>
18 #include <linux/socket.h>
19 #include <linux/sockios.h>
20 #include <linux/net.h>
21 #include <linux/in6.h>
22 #include <linux/netdevice.h>
23 #include <linux/if_arp.h>
24 #include <linux/route.h>
25 #include <linux/init.h>
26 #include <linux/proc_fs.h>
27 #include <linux/seq_file.h>
28 #include <linux/slab.h>
30 #include <net/net_namespace.h>
35 #include <net/protocol.h>
36 #include <net/if_inet6.h>
37 #include <net/ndisc.h>
38 #include <net/addrconf.h>
39 #include <net/ip6_route.h>
41 #include <net/checksum.h>
43 #define IN6_ADDR_HSIZE_SHIFT 8
44 #define IN6_ADDR_HSIZE BIT(IN6_ADDR_HSIZE_SHIFT)
45 /* anycast address hash table
47 static struct hlist_head inet6_acaddr_lst
[IN6_ADDR_HSIZE
];
48 static DEFINE_SPINLOCK(acaddr_hash_lock
);
50 static int ipv6_dev_ac_dec(struct net_device
*dev
, const struct in6_addr
*addr
);
52 static u32
inet6_acaddr_hash(struct net
*net
, const struct in6_addr
*addr
)
54 u32 val
= ipv6_addr_hash(addr
) ^ net_hash_mix(net
);
56 return hash_32(val
, IN6_ADDR_HSIZE_SHIFT
);
60 * socket join an anycast group
63 int ipv6_sock_ac_join(struct sock
*sk
, int ifindex
, const struct in6_addr
*addr
)
65 struct ipv6_pinfo
*np
= inet6_sk(sk
);
66 struct net_device
*dev
= NULL
;
67 struct inet6_dev
*idev
;
68 struct ipv6_ac_socklist
*pac
;
69 struct net
*net
= sock_net(sk
);
70 int ishost
= !net
->ipv6
.devconf_all
->forwarding
;
75 if (!ns_capable(net
->user_ns
, CAP_NET_ADMIN
))
77 if (ipv6_addr_is_multicast(addr
))
81 dev
= __dev_get_by_index(net
, ifindex
);
83 if (ipv6_chk_addr_and_flags(net
, addr
, dev
, true, 0, IFA_F_TENTATIVE
))
86 pac
= sock_kmalloc(sk
, sizeof(struct ipv6_ac_socklist
), GFP_KERNEL
);
90 pac
->acl_addr
= *addr
;
95 rt
= rt6_lookup(net
, addr
, NULL
, 0, NULL
, 0);
100 err
= -EADDRNOTAVAIL
;
103 /* router, no matching interface: just pick one */
104 dev
= __dev_get_by_flags(net
, IFF_UP
,
105 IFF_UP
| IFF_LOOPBACK
);
114 idev
= __in6_dev_get(dev
);
119 err
= -EADDRNOTAVAIL
;
122 /* reset ishost, now that we have a specific device */
123 ishost
= !idev
->cnf
.forwarding
;
125 pac
->acl_ifindex
= dev
->ifindex
;
128 * For hosts, allow link-local or matching prefix anycasts.
129 * This obviates the need for propagating anycast routes while
130 * still allowing some non-router anycast participation.
132 if (!ipv6_chk_prefix(addr
, dev
)) {
134 err
= -EADDRNOTAVAIL
;
139 err
= __ipv6_dev_ac_inc(idev
, addr
);
141 pac
->acl_next
= np
->ipv6_ac_list
;
142 np
->ipv6_ac_list
= pac
;
148 sock_kfree_s(sk
, pac
, sizeof(*pac
));
153 * socket leave an anycast group
155 int ipv6_sock_ac_drop(struct sock
*sk
, int ifindex
, const struct in6_addr
*addr
)
157 struct ipv6_pinfo
*np
= inet6_sk(sk
);
158 struct net_device
*dev
;
159 struct ipv6_ac_socklist
*pac
, *prev_pac
;
160 struct net
*net
= sock_net(sk
);
165 for (pac
= np
->ipv6_ac_list
; pac
; pac
= pac
->acl_next
) {
166 if ((ifindex
== 0 || pac
->acl_ifindex
== ifindex
) &&
167 ipv6_addr_equal(&pac
->acl_addr
, addr
))
174 prev_pac
->acl_next
= pac
->acl_next
;
176 np
->ipv6_ac_list
= pac
->acl_next
;
178 dev
= __dev_get_by_index(net
, pac
->acl_ifindex
);
180 ipv6_dev_ac_dec(dev
, &pac
->acl_addr
);
182 sock_kfree_s(sk
, pac
, sizeof(*pac
));
186 void __ipv6_sock_ac_close(struct sock
*sk
)
188 struct ipv6_pinfo
*np
= inet6_sk(sk
);
189 struct net_device
*dev
= NULL
;
190 struct ipv6_ac_socklist
*pac
;
191 struct net
*net
= sock_net(sk
);
195 pac
= np
->ipv6_ac_list
;
196 np
->ipv6_ac_list
= NULL
;
200 struct ipv6_ac_socklist
*next
= pac
->acl_next
;
202 if (pac
->acl_ifindex
!= prev_index
) {
203 dev
= __dev_get_by_index(net
, pac
->acl_ifindex
);
204 prev_index
= pac
->acl_ifindex
;
207 ipv6_dev_ac_dec(dev
, &pac
->acl_addr
);
208 sock_kfree_s(sk
, pac
, sizeof(*pac
));
213 void ipv6_sock_ac_close(struct sock
*sk
)
215 struct ipv6_pinfo
*np
= inet6_sk(sk
);
217 if (!np
->ipv6_ac_list
)
220 __ipv6_sock_ac_close(sk
);
224 static void ipv6_add_acaddr_hash(struct net
*net
, struct ifacaddr6
*aca
)
226 unsigned int hash
= inet6_acaddr_hash(net
, &aca
->aca_addr
);
228 spin_lock(&acaddr_hash_lock
);
229 hlist_add_head_rcu(&aca
->aca_addr_lst
, &inet6_acaddr_lst
[hash
]);
230 spin_unlock(&acaddr_hash_lock
);
233 static void ipv6_del_acaddr_hash(struct ifacaddr6
*aca
)
235 spin_lock(&acaddr_hash_lock
);
236 hlist_del_init_rcu(&aca
->aca_addr_lst
);
237 spin_unlock(&acaddr_hash_lock
);
240 static void aca_get(struct ifacaddr6
*aca
)
242 refcount_inc(&aca
->aca_refcnt
);
245 static void aca_free_rcu(struct rcu_head
*h
)
247 struct ifacaddr6
*aca
= container_of(h
, struct ifacaddr6
, rcu
);
249 fib6_info_release(aca
->aca_rt
);
253 static void aca_put(struct ifacaddr6
*ac
)
255 if (refcount_dec_and_test(&ac
->aca_refcnt
)) {
256 call_rcu(&ac
->rcu
, aca_free_rcu
);
260 static struct ifacaddr6
*aca_alloc(struct fib6_info
*f6i
,
261 const struct in6_addr
*addr
)
263 struct ifacaddr6
*aca
;
265 aca
= kzalloc(sizeof(*aca
), GFP_ATOMIC
);
269 aca
->aca_addr
= *addr
;
272 INIT_HLIST_NODE(&aca
->aca_addr_lst
);
274 /* aca_tstamp should be updated upon changes */
275 aca
->aca_cstamp
= aca
->aca_tstamp
= jiffies
;
276 refcount_set(&aca
->aca_refcnt
, 1);
282 * device anycast group inc (add if not found)
284 int __ipv6_dev_ac_inc(struct inet6_dev
*idev
, const struct in6_addr
*addr
)
286 struct ifacaddr6
*aca
;
287 struct fib6_info
*f6i
;
293 write_lock_bh(&idev
->lock
);
299 for (aca
= idev
->ac_list
; aca
; aca
= aca
->aca_next
) {
300 if (ipv6_addr_equal(&aca
->aca_addr
, addr
)) {
307 net
= dev_net(idev
->dev
);
308 f6i
= addrconf_f6i_alloc(net
, idev
, addr
, true, GFP_ATOMIC
);
313 aca
= aca_alloc(f6i
, addr
);
315 fib6_info_release(f6i
);
320 aca
->aca_next
= idev
->ac_list
;
323 /* Hold this for addrconf_join_solict() below before we unlock,
324 * it is already exposed via idev->ac_list.
327 write_unlock_bh(&idev
->lock
);
329 ipv6_add_acaddr_hash(net
, aca
);
331 ip6_ins_rt(net
, f6i
);
333 addrconf_join_solict(idev
->dev
, &aca
->aca_addr
);
338 write_unlock_bh(&idev
->lock
);
343 * device anycast group decrement
345 int __ipv6_dev_ac_dec(struct inet6_dev
*idev
, const struct in6_addr
*addr
)
347 struct ifacaddr6
*aca
, *prev_aca
;
351 write_lock_bh(&idev
->lock
);
353 for (aca
= idev
->ac_list
; aca
; aca
= aca
->aca_next
) {
354 if (ipv6_addr_equal(&aca
->aca_addr
, addr
))
359 write_unlock_bh(&idev
->lock
);
362 if (--aca
->aca_users
> 0) {
363 write_unlock_bh(&idev
->lock
);
367 prev_aca
->aca_next
= aca
->aca_next
;
369 idev
->ac_list
= aca
->aca_next
;
370 write_unlock_bh(&idev
->lock
);
371 ipv6_del_acaddr_hash(aca
);
372 addrconf_leave_solict(idev
, &aca
->aca_addr
);
374 ip6_del_rt(dev_net(idev
->dev
), aca
->aca_rt
, false);
380 /* called with rtnl_lock() */
381 static int ipv6_dev_ac_dec(struct net_device
*dev
, const struct in6_addr
*addr
)
383 struct inet6_dev
*idev
= __in6_dev_get(dev
);
387 return __ipv6_dev_ac_dec(idev
, addr
);
390 void ipv6_ac_destroy_dev(struct inet6_dev
*idev
)
392 struct ifacaddr6
*aca
;
394 write_lock_bh(&idev
->lock
);
395 while ((aca
= idev
->ac_list
) != NULL
) {
396 idev
->ac_list
= aca
->aca_next
;
397 write_unlock_bh(&idev
->lock
);
399 ipv6_del_acaddr_hash(aca
);
401 addrconf_leave_solict(idev
, &aca
->aca_addr
);
403 ip6_del_rt(dev_net(idev
->dev
), aca
->aca_rt
, false);
407 write_lock_bh(&idev
->lock
);
409 write_unlock_bh(&idev
->lock
);
413 * check if the interface has this anycast address
414 * called with rcu_read_lock()
416 static bool ipv6_chk_acast_dev(struct net_device
*dev
, const struct in6_addr
*addr
)
418 struct inet6_dev
*idev
;
419 struct ifacaddr6
*aca
;
421 idev
= __in6_dev_get(dev
);
423 read_lock_bh(&idev
->lock
);
424 for (aca
= idev
->ac_list
; aca
; aca
= aca
->aca_next
)
425 if (ipv6_addr_equal(&aca
->aca_addr
, addr
))
427 read_unlock_bh(&idev
->lock
);
434 * check if given interface (or any, if dev==0) has this anycast address
436 bool ipv6_chk_acast_addr(struct net
*net
, struct net_device
*dev
,
437 const struct in6_addr
*addr
)
439 struct net_device
*nh_dev
;
440 struct ifacaddr6
*aca
;
445 found
= ipv6_chk_acast_dev(dev
, addr
);
447 unsigned int hash
= inet6_acaddr_hash(net
, addr
);
449 hlist_for_each_entry_rcu(aca
, &inet6_acaddr_lst
[hash
],
451 nh_dev
= fib6_info_nh_dev(aca
->aca_rt
);
452 if (!nh_dev
|| !net_eq(dev_net(nh_dev
), net
))
454 if (ipv6_addr_equal(&aca
->aca_addr
, addr
)) {
464 /* check if this anycast address is link-local on given interface or
467 bool ipv6_chk_acast_addr_src(struct net
*net
, struct net_device
*dev
,
468 const struct in6_addr
*addr
)
470 return ipv6_chk_acast_addr(net
,
471 (ipv6_addr_type(addr
) & IPV6_ADDR_LINKLOCAL
?
476 #ifdef CONFIG_PROC_FS
477 struct ac6_iter_state
{
478 struct seq_net_private p
;
479 struct net_device
*dev
;
480 struct inet6_dev
*idev
;
483 #define ac6_seq_private(seq) ((struct ac6_iter_state *)(seq)->private)
485 static inline struct ifacaddr6
*ac6_get_first(struct seq_file
*seq
)
487 struct ifacaddr6
*im
= NULL
;
488 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
489 struct net
*net
= seq_file_net(seq
);
492 for_each_netdev_rcu(net
, state
->dev
) {
493 struct inet6_dev
*idev
;
494 idev
= __in6_dev_get(state
->dev
);
497 read_lock_bh(&idev
->lock
);
503 read_unlock_bh(&idev
->lock
);
508 static struct ifacaddr6
*ac6_get_next(struct seq_file
*seq
, struct ifacaddr6
*im
)
510 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
514 if (likely(state
->idev
!= NULL
))
515 read_unlock_bh(&state
->idev
->lock
);
517 state
->dev
= next_net_device_rcu(state
->dev
);
522 state
->idev
= __in6_dev_get(state
->dev
);
525 read_lock_bh(&state
->idev
->lock
);
526 im
= state
->idev
->ac_list
;
531 static struct ifacaddr6
*ac6_get_idx(struct seq_file
*seq
, loff_t pos
)
533 struct ifacaddr6
*im
= ac6_get_first(seq
);
535 while (pos
&& (im
= ac6_get_next(seq
, im
)) != NULL
)
537 return pos
? NULL
: im
;
540 static void *ac6_seq_start(struct seq_file
*seq
, loff_t
*pos
)
544 return ac6_get_idx(seq
, *pos
);
547 static void *ac6_seq_next(struct seq_file
*seq
, void *v
, loff_t
*pos
)
549 struct ifacaddr6
*im
= ac6_get_next(seq
, v
);
555 static void ac6_seq_stop(struct seq_file
*seq
, void *v
)
558 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
560 if (likely(state
->idev
!= NULL
)) {
561 read_unlock_bh(&state
->idev
->lock
);
567 static int ac6_seq_show(struct seq_file
*seq
, void *v
)
569 struct ifacaddr6
*im
= (struct ifacaddr6
*)v
;
570 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
572 seq_printf(seq
, "%-4d %-15s %pi6 %5d\n",
573 state
->dev
->ifindex
, state
->dev
->name
,
574 &im
->aca_addr
, im
->aca_users
);
578 static const struct seq_operations ac6_seq_ops
= {
579 .start
= ac6_seq_start
,
580 .next
= ac6_seq_next
,
581 .stop
= ac6_seq_stop
,
582 .show
= ac6_seq_show
,
585 int __net_init
ac6_proc_init(struct net
*net
)
587 if (!proc_create_net("anycast6", 0444, net
->proc_net
, &ac6_seq_ops
,
588 sizeof(struct ac6_iter_state
)))
594 void ac6_proc_exit(struct net
*net
)
596 remove_proc_entry("anycast6", net
->proc_net
);
600 /* Init / cleanup code
602 int __init
ipv6_anycast_init(void)
606 for (i
= 0; i
< IN6_ADDR_HSIZE
; i
++)
607 INIT_HLIST_HEAD(&inet6_acaddr_lst
[i
]);
611 void ipv6_anycast_cleanup(void)
615 spin_lock(&acaddr_hash_lock
);
616 for (i
= 0; i
< IN6_ADDR_HSIZE
; i
++)
617 WARN_ON(!hlist_empty(&inet6_acaddr_lst
[i
]));
618 spin_unlock(&acaddr_hash_lock
);