1 // SPDX-License-Identifier: GPL-2.0-or-later
3 * Anycast support for IPv6
4 * Linux INET6 implementation
7 * David L Stevens (dlstevens@us.ibm.com)
9 * based heavily on net/ipv6/mcast.c
12 #include <linux/capability.h>
13 #include <linux/module.h>
14 #include <linux/errno.h>
15 #include <linux/types.h>
16 #include <linux/random.h>
17 #include <linux/string.h>
18 #include <linux/socket.h>
19 #include <linux/sockios.h>
20 #include <linux/net.h>
21 #include <linux/in6.h>
22 #include <linux/netdevice.h>
23 #include <linux/if_arp.h>
24 #include <linux/route.h>
25 #include <linux/init.h>
26 #include <linux/proc_fs.h>
27 #include <linux/seq_file.h>
28 #include <linux/slab.h>
30 #include <net/net_namespace.h>
35 #include <net/protocol.h>
36 #include <net/if_inet6.h>
37 #include <net/ndisc.h>
38 #include <net/addrconf.h>
39 #include <net/ip6_route.h>
41 #include <net/checksum.h>
43 #define IN6_ADDR_HSIZE_SHIFT 8
44 #define IN6_ADDR_HSIZE BIT(IN6_ADDR_HSIZE_SHIFT)
45 /* anycast address hash table
47 static struct hlist_head inet6_acaddr_lst
[IN6_ADDR_HSIZE
];
48 static DEFINE_SPINLOCK(acaddr_hash_lock
);
50 static int ipv6_dev_ac_dec(struct net_device
*dev
, const struct in6_addr
*addr
);
52 static u32
inet6_acaddr_hash(struct net
*net
, const struct in6_addr
*addr
)
54 u32 val
= ipv6_addr_hash(addr
) ^ net_hash_mix(net
);
56 return hash_32(val
, IN6_ADDR_HSIZE_SHIFT
);
60 * socket join an anycast group
63 int ipv6_sock_ac_join(struct sock
*sk
, int ifindex
, const struct in6_addr
*addr
)
65 struct ipv6_pinfo
*np
= inet6_sk(sk
);
66 struct net_device
*dev
= NULL
;
67 struct inet6_dev
*idev
;
68 struct ipv6_ac_socklist
*pac
;
69 struct net
*net
= sock_net(sk
);
70 int ishost
= !net
->ipv6
.devconf_all
->forwarding
;
75 if (!ns_capable(net
->user_ns
, CAP_NET_ADMIN
))
77 if (ipv6_addr_is_multicast(addr
))
81 dev
= __dev_get_by_index(net
, ifindex
);
83 if (ipv6_chk_addr_and_flags(net
, addr
, dev
, true, 0, IFA_F_TENTATIVE
))
86 pac
= sock_kmalloc(sk
, sizeof(struct ipv6_ac_socklist
), GFP_KERNEL
);
90 pac
->acl_addr
= *addr
;
95 rt
= rt6_lookup(net
, addr
, NULL
, 0, NULL
, 0);
100 err
= -EADDRNOTAVAIL
;
103 /* router, no matching interface: just pick one */
104 dev
= __dev_get_by_flags(net
, IFF_UP
,
105 IFF_UP
| IFF_LOOPBACK
);
114 idev
= __in6_dev_get(dev
);
119 err
= -EADDRNOTAVAIL
;
122 /* reset ishost, now that we have a specific device */
123 ishost
= !idev
->cnf
.forwarding
;
125 pac
->acl_ifindex
= dev
->ifindex
;
128 * For hosts, allow link-local or matching prefix anycasts.
129 * This obviates the need for propagating anycast routes while
130 * still allowing some non-router anycast participation.
132 if (!ipv6_chk_prefix(addr
, dev
)) {
134 err
= -EADDRNOTAVAIL
;
139 err
= __ipv6_dev_ac_inc(idev
, addr
);
141 pac
->acl_next
= np
->ipv6_ac_list
;
142 np
->ipv6_ac_list
= pac
;
148 sock_kfree_s(sk
, pac
, sizeof(*pac
));
153 * socket leave an anycast group
155 int ipv6_sock_ac_drop(struct sock
*sk
, int ifindex
, const struct in6_addr
*addr
)
157 struct ipv6_pinfo
*np
= inet6_sk(sk
);
158 struct net_device
*dev
;
159 struct ipv6_ac_socklist
*pac
, *prev_pac
;
160 struct net
*net
= sock_net(sk
);
165 for (pac
= np
->ipv6_ac_list
; pac
; pac
= pac
->acl_next
) {
166 if ((ifindex
== 0 || pac
->acl_ifindex
== ifindex
) &&
167 ipv6_addr_equal(&pac
->acl_addr
, addr
))
174 prev_pac
->acl_next
= pac
->acl_next
;
176 np
->ipv6_ac_list
= pac
->acl_next
;
178 dev
= __dev_get_by_index(net
, pac
->acl_ifindex
);
180 ipv6_dev_ac_dec(dev
, &pac
->acl_addr
);
182 sock_kfree_s(sk
, pac
, sizeof(*pac
));
186 void ipv6_sock_ac_close(struct sock
*sk
)
188 struct ipv6_pinfo
*np
= inet6_sk(sk
);
189 struct net_device
*dev
= NULL
;
190 struct ipv6_ac_socklist
*pac
;
191 struct net
*net
= sock_net(sk
);
194 if (!np
->ipv6_ac_list
)
198 pac
= np
->ipv6_ac_list
;
199 np
->ipv6_ac_list
= NULL
;
203 struct ipv6_ac_socklist
*next
= pac
->acl_next
;
205 if (pac
->acl_ifindex
!= prev_index
) {
206 dev
= __dev_get_by_index(net
, pac
->acl_ifindex
);
207 prev_index
= pac
->acl_ifindex
;
210 ipv6_dev_ac_dec(dev
, &pac
->acl_addr
);
211 sock_kfree_s(sk
, pac
, sizeof(*pac
));
217 static void ipv6_add_acaddr_hash(struct net
*net
, struct ifacaddr6
*aca
)
219 unsigned int hash
= inet6_acaddr_hash(net
, &aca
->aca_addr
);
221 spin_lock(&acaddr_hash_lock
);
222 hlist_add_head_rcu(&aca
->aca_addr_lst
, &inet6_acaddr_lst
[hash
]);
223 spin_unlock(&acaddr_hash_lock
);
226 static void ipv6_del_acaddr_hash(struct ifacaddr6
*aca
)
228 spin_lock(&acaddr_hash_lock
);
229 hlist_del_init_rcu(&aca
->aca_addr_lst
);
230 spin_unlock(&acaddr_hash_lock
);
233 static void aca_get(struct ifacaddr6
*aca
)
235 refcount_inc(&aca
->aca_refcnt
);
238 static void aca_free_rcu(struct rcu_head
*h
)
240 struct ifacaddr6
*aca
= container_of(h
, struct ifacaddr6
, rcu
);
242 fib6_info_release(aca
->aca_rt
);
246 static void aca_put(struct ifacaddr6
*ac
)
248 if (refcount_dec_and_test(&ac
->aca_refcnt
)) {
249 call_rcu(&ac
->rcu
, aca_free_rcu
);
253 static struct ifacaddr6
*aca_alloc(struct fib6_info
*f6i
,
254 const struct in6_addr
*addr
)
256 struct ifacaddr6
*aca
;
258 aca
= kzalloc(sizeof(*aca
), GFP_ATOMIC
);
262 aca
->aca_addr
= *addr
;
265 INIT_HLIST_NODE(&aca
->aca_addr_lst
);
267 /* aca_tstamp should be updated upon changes */
268 aca
->aca_cstamp
= aca
->aca_tstamp
= jiffies
;
269 refcount_set(&aca
->aca_refcnt
, 1);
275 * device anycast group inc (add if not found)
277 int __ipv6_dev_ac_inc(struct inet6_dev
*idev
, const struct in6_addr
*addr
)
279 struct ifacaddr6
*aca
;
280 struct fib6_info
*f6i
;
286 write_lock_bh(&idev
->lock
);
292 for (aca
= idev
->ac_list
; aca
; aca
= aca
->aca_next
) {
293 if (ipv6_addr_equal(&aca
->aca_addr
, addr
)) {
300 net
= dev_net(idev
->dev
);
301 f6i
= addrconf_f6i_alloc(net
, idev
, addr
, true, GFP_ATOMIC
);
306 aca
= aca_alloc(f6i
, addr
);
308 fib6_info_release(f6i
);
313 aca
->aca_next
= idev
->ac_list
;
316 /* Hold this for addrconf_join_solict() below before we unlock,
317 * it is already exposed via idev->ac_list.
320 write_unlock_bh(&idev
->lock
);
322 ipv6_add_acaddr_hash(net
, aca
);
324 ip6_ins_rt(net
, f6i
);
326 addrconf_join_solict(idev
->dev
, &aca
->aca_addr
);
331 write_unlock_bh(&idev
->lock
);
336 * device anycast group decrement
338 int __ipv6_dev_ac_dec(struct inet6_dev
*idev
, const struct in6_addr
*addr
)
340 struct ifacaddr6
*aca
, *prev_aca
;
344 write_lock_bh(&idev
->lock
);
346 for (aca
= idev
->ac_list
; aca
; aca
= aca
->aca_next
) {
347 if (ipv6_addr_equal(&aca
->aca_addr
, addr
))
352 write_unlock_bh(&idev
->lock
);
355 if (--aca
->aca_users
> 0) {
356 write_unlock_bh(&idev
->lock
);
360 prev_aca
->aca_next
= aca
->aca_next
;
362 idev
->ac_list
= aca
->aca_next
;
363 write_unlock_bh(&idev
->lock
);
364 ipv6_del_acaddr_hash(aca
);
365 addrconf_leave_solict(idev
, &aca
->aca_addr
);
367 ip6_del_rt(dev_net(idev
->dev
), aca
->aca_rt
, false);
373 /* called with rtnl_lock() */
374 static int ipv6_dev_ac_dec(struct net_device
*dev
, const struct in6_addr
*addr
)
376 struct inet6_dev
*idev
= __in6_dev_get(dev
);
380 return __ipv6_dev_ac_dec(idev
, addr
);
383 void ipv6_ac_destroy_dev(struct inet6_dev
*idev
)
385 struct ifacaddr6
*aca
;
387 write_lock_bh(&idev
->lock
);
388 while ((aca
= idev
->ac_list
) != NULL
) {
389 idev
->ac_list
= aca
->aca_next
;
390 write_unlock_bh(&idev
->lock
);
392 ipv6_del_acaddr_hash(aca
);
394 addrconf_leave_solict(idev
, &aca
->aca_addr
);
396 ip6_del_rt(dev_net(idev
->dev
), aca
->aca_rt
, false);
400 write_lock_bh(&idev
->lock
);
402 write_unlock_bh(&idev
->lock
);
406 * check if the interface has this anycast address
407 * called with rcu_read_lock()
409 static bool ipv6_chk_acast_dev(struct net_device
*dev
, const struct in6_addr
*addr
)
411 struct inet6_dev
*idev
;
412 struct ifacaddr6
*aca
;
414 idev
= __in6_dev_get(dev
);
416 read_lock_bh(&idev
->lock
);
417 for (aca
= idev
->ac_list
; aca
; aca
= aca
->aca_next
)
418 if (ipv6_addr_equal(&aca
->aca_addr
, addr
))
420 read_unlock_bh(&idev
->lock
);
427 * check if given interface (or any, if dev==0) has this anycast address
429 bool ipv6_chk_acast_addr(struct net
*net
, struct net_device
*dev
,
430 const struct in6_addr
*addr
)
432 struct net_device
*nh_dev
;
433 struct ifacaddr6
*aca
;
438 found
= ipv6_chk_acast_dev(dev
, addr
);
440 unsigned int hash
= inet6_acaddr_hash(net
, addr
);
442 hlist_for_each_entry_rcu(aca
, &inet6_acaddr_lst
[hash
],
444 nh_dev
= fib6_info_nh_dev(aca
->aca_rt
);
445 if (!nh_dev
|| !net_eq(dev_net(nh_dev
), net
))
447 if (ipv6_addr_equal(&aca
->aca_addr
, addr
)) {
457 /* check if this anycast address is link-local on given interface or
460 bool ipv6_chk_acast_addr_src(struct net
*net
, struct net_device
*dev
,
461 const struct in6_addr
*addr
)
463 return ipv6_chk_acast_addr(net
,
464 (ipv6_addr_type(addr
) & IPV6_ADDR_LINKLOCAL
?
469 #ifdef CONFIG_PROC_FS
470 struct ac6_iter_state
{
471 struct seq_net_private p
;
472 struct net_device
*dev
;
473 struct inet6_dev
*idev
;
476 #define ac6_seq_private(seq) ((struct ac6_iter_state *)(seq)->private)
478 static inline struct ifacaddr6
*ac6_get_first(struct seq_file
*seq
)
480 struct ifacaddr6
*im
= NULL
;
481 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
482 struct net
*net
= seq_file_net(seq
);
485 for_each_netdev_rcu(net
, state
->dev
) {
486 struct inet6_dev
*idev
;
487 idev
= __in6_dev_get(state
->dev
);
490 read_lock_bh(&idev
->lock
);
496 read_unlock_bh(&idev
->lock
);
501 static struct ifacaddr6
*ac6_get_next(struct seq_file
*seq
, struct ifacaddr6
*im
)
503 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
507 if (likely(state
->idev
!= NULL
))
508 read_unlock_bh(&state
->idev
->lock
);
510 state
->dev
= next_net_device_rcu(state
->dev
);
515 state
->idev
= __in6_dev_get(state
->dev
);
518 read_lock_bh(&state
->idev
->lock
);
519 im
= state
->idev
->ac_list
;
524 static struct ifacaddr6
*ac6_get_idx(struct seq_file
*seq
, loff_t pos
)
526 struct ifacaddr6
*im
= ac6_get_first(seq
);
528 while (pos
&& (im
= ac6_get_next(seq
, im
)) != NULL
)
530 return pos
? NULL
: im
;
533 static void *ac6_seq_start(struct seq_file
*seq
, loff_t
*pos
)
537 return ac6_get_idx(seq
, *pos
);
540 static void *ac6_seq_next(struct seq_file
*seq
, void *v
, loff_t
*pos
)
542 struct ifacaddr6
*im
= ac6_get_next(seq
, v
);
548 static void ac6_seq_stop(struct seq_file
*seq
, void *v
)
551 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
553 if (likely(state
->idev
!= NULL
)) {
554 read_unlock_bh(&state
->idev
->lock
);
560 static int ac6_seq_show(struct seq_file
*seq
, void *v
)
562 struct ifacaddr6
*im
= (struct ifacaddr6
*)v
;
563 struct ac6_iter_state
*state
= ac6_seq_private(seq
);
565 seq_printf(seq
, "%-4d %-15s %pi6 %5d\n",
566 state
->dev
->ifindex
, state
->dev
->name
,
567 &im
->aca_addr
, im
->aca_users
);
571 static const struct seq_operations ac6_seq_ops
= {
572 .start
= ac6_seq_start
,
573 .next
= ac6_seq_next
,
574 .stop
= ac6_seq_stop
,
575 .show
= ac6_seq_show
,
578 int __net_init
ac6_proc_init(struct net
*net
)
580 if (!proc_create_net("anycast6", 0444, net
->proc_net
, &ac6_seq_ops
,
581 sizeof(struct ac6_iter_state
)))
587 void ac6_proc_exit(struct net
*net
)
589 remove_proc_entry("anycast6", net
->proc_net
);
593 /* Init / cleanup code
595 int __init
ipv6_anycast_init(void)
599 for (i
= 0; i
< IN6_ADDR_HSIZE
; i
++)
600 INIT_HLIST_HEAD(&inet6_acaddr_lst
[i
]);
604 void ipv6_anycast_cleanup(void)
608 spin_lock(&acaddr_hash_lock
);
609 for (i
= 0; i
< IN6_ADDR_HSIZE
; i
++)
610 WARN_ON(!hlist_empty(&inet6_acaddr_lst
[i
]));
611 spin_unlock(&acaddr_hash_lock
);