Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files. =================================================================== RCS file: /ftp/cvs/cvsroot/src/sys/netinet/raw_ip.c,v rcsdiff: /ftp/cvs/cvsroot/src/sys/netinet/raw_ip.c,v: warning: Unknown phrases like `commitid ...;' are present. retrieving revision 1.25 retrieving revision 1.46.8.1 diff -u -p -r1.25 -r1.46.8.1 --- src/sys/netinet/raw_ip.c 1996/02/18 18:58:33 1.25 +++ src/sys/netinet/raw_ip.c 1999/12/27 18:36:19 1.46.8.1 @@ -1,4 +1,33 @@ -/* $NetBSD: raw_ip.c,v 1.25 1996/02/18 18:58:33 christos Exp $ */ +/* $NetBSD: raw_ip.c,v 1.46.8.1 1999/12/27 18:36:19 wrstuden Exp $ */ + +/* + * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. Neither the name of the project nor the names of its contributors + * may be used to endorse or promote products derived from this software + * without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ /* * Copyright (c) 1982, 1986, 1988, 1993 @@ -32,9 +61,12 @@ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. * - * @(#)raw_ip.c 8.2 (Berkeley) 1/4/94 + * @(#)raw_ip.c 8.7 (Berkeley) 5/15/95 */ +#include "opt_ipsec.h" +#include "opt_mrouting.h" + #include #include #include @@ -43,6 +75,7 @@ #include #include #include +#include #include #include @@ -52,13 +85,24 @@ #include #include #include +#include #include #include #include +#ifdef IPSEC +#include +#endif /*IPSEC*/ + +extern u_char ip_protox[]; +extern struct protosw inetsw[]; struct inpcbtable rawcbtable; +int rip_bind __P((struct inpcb *, struct mbuf *)); +int rip_connect __P((struct inpcb *, struct mbuf *)); +void rip_disconnect __P((struct inpcb *)); + /* * Nominal space allocated to a raw ip socket. */ @@ -76,10 +120,11 @@ void rip_init() { - in_pcbinit(&rawcbtable, 1); + in_pcbinit(&rawcbtable, 1, 1); } -struct sockaddr_in ripsrc = { sizeof(ripsrc), AF_INET }; +static struct sockaddr_in ripsrc = { sizeof(ripsrc), AF_INET }; + /* * Setup generic address and protocol structures * for raw_input routine, then pass them along with @@ -94,47 +139,82 @@ rip_input(m, va_alist) va_dcl #endif { + int off, proto; register struct ip *ip = mtod(m, struct ip *); register struct inpcb *inp; - struct socket *last = 0; + struct inpcb *last = 0; + struct mbuf *opts = 0; + struct sockaddr_in ripsrc; + va_list ap; + + va_start(ap, m); + off = va_arg(ap, int); + proto = va_arg(ap, int); + va_end(ap); + ripsrc.sin_family = AF_INET; + ripsrc.sin_len = sizeof(struct sockaddr_in); ripsrc.sin_addr = ip->ip_src; + ripsrc.sin_port = 0; + bzero((caddr_t)ripsrc.sin_zero, sizeof(ripsrc.sin_zero)); + + /* + * XXX Compatibility: programs using raw IP expect ip_len + * XXX to have the header length subtracted. + */ + ip->ip_len -= ip->ip_hl << 2; + for (inp = rawcbtable.inpt_queue.cqh_first; inp != (struct inpcb *)&rawcbtable.inpt_queue; inp = inp->inp_queue.cqe_next) { - if (inp->inp_ip.ip_p && inp->inp_ip.ip_p != ip->ip_p) + if (inp->inp_ip.ip_p && inp->inp_ip.ip_p != proto) continue; - if (inp->inp_laddr.s_addr && - inp->inp_laddr.s_addr != ip->ip_dst.s_addr) + if (!in_nullhost(inp->inp_laddr) && + !in_hosteq(inp->inp_laddr, ip->ip_dst)) continue; - if (inp->inp_faddr.s_addr && - inp->inp_faddr.s_addr != ip->ip_src.s_addr) + if (!in_nullhost(inp->inp_faddr) && + !in_hosteq(inp->inp_faddr, ip->ip_src)) continue; if (last) { struct mbuf *n; if ((n = m_copy(m, 0, (int)M_COPYALL)) != NULL) { - if (sbappendaddr(&last->so_rcv, - sintosa(&ripsrc), n, - (struct mbuf *)0) == 0) + if (last->inp_flags & INP_CONTROLOPTS || + last->inp_socket->so_options & SO_TIMESTAMP) + ip_savecontrol(last, &opts, ip, n); + if (sbappendaddr(&last->inp_socket->so_rcv, + sintosa(&ripsrc), n, opts) == 0) { /* should notify about lost packet */ m_freem(n); - else - sorwakeup(last); + if (opts) + m_freem(opts); + } else + sorwakeup(last->inp_socket); + opts = NULL; } } - last = inp->inp_socket; + last = inp; } if (last) { - if (sbappendaddr(&last->so_rcv, sintosa(&ripsrc), m, - (struct mbuf *)0) == 0) + if (last->inp_flags & INP_CONTROLOPTS || + last->inp_socket->so_options & SO_TIMESTAMP) + ip_savecontrol(last, &opts, ip, m); + if (sbappendaddr(&last->inp_socket->so_rcv, + sintosa(&ripsrc), m, opts) == 0) { m_freem(m); - else - sorwakeup(last); + if (opts) + m_freem(opts); + } else + sorwakeup(last->inp_socket); } else { - m_freem(m); - ipstat.ips_noproto++; - ipstat.ips_delivered--; + if (inetsw[ip_protox[ip->ip_p]].pr_input == rip_input) { + icmp_error(m, ICMP_UNREACH, ICMP_UNREACH_PROTOCOL, + 0, 0); + ipstat.ips_noproto++; + ipstat.ips_delivered--; + } else + m_freem(m); } + return; } /* @@ -150,27 +230,29 @@ rip_output(m, va_alist) va_dcl #endif { - struct socket *so; - u_long dst; - register struct ip *ip; register struct inpcb *inp; + register struct ip *ip; struct mbuf *opts; int flags; va_list ap; va_start(ap, m); - so = va_arg(ap, struct socket *); - dst = va_arg(ap, u_long); + inp = va_arg(ap, struct inpcb *); va_end(ap); - inp = sotoinpcb(so); - flags = (so->so_options & SO_DONTROUTE) | IP_ALLOWBROADCAST; + flags = + (inp->inp_socket->so_options & SO_DONTROUTE) | IP_ALLOWBROADCAST + | IP_RETURNMTU; /* * If the user handed us a complete IP packet, use it. * Otherwise, allocate an mbuf for a header and fill it in. */ if ((inp->inp_flags & INP_HDRINCL) == 0) { + if ((m->m_pkthdr.len + sizeof(struct ip)) > IP_MAXPACKET) { + m_freem(m); + return (EMSGSIZE); + } M_PREPEND(m, sizeof(struct ip), M_WAIT); ip = mtod(m, struct ip *); ip->ip_tos = 0; @@ -178,11 +260,19 @@ rip_output(m, va_alist) ip->ip_p = inp->inp_ip.ip_p; ip->ip_len = m->m_pkthdr.len; ip->ip_src = inp->inp_laddr; - ip->ip_dst.s_addr = dst; + ip->ip_dst = inp->inp_faddr; ip->ip_ttl = MAXTTL; opts = inp->inp_options; } else { + if (m->m_pkthdr.len > IP_MAXPACKET) { + m_freem(m); + return (EMSGSIZE); + } ip = mtod(m, struct ip *); + if (m->m_pkthdr.len != ip->ip_len) { + m_freem(m); + return (EINVAL); + } if (ip->ip_id == 0) ip->ip_id = htons(ip_id++); opts = NULL; @@ -190,7 +280,10 @@ rip_output(m, va_alist) flags |= IP_RAWOUTPUT; ipstat.ips_rawout++; } - return (ip_output(m, opts, &inp->inp_route, flags, inp->inp_moptions)); +#ifdef IPSEC + m->m_pkthdr.rcvif = (struct ifnet *)inp->inp_socket; /*XXX*/ +#endif /*IPSEC*/ + return (ip_output(m, opts, &inp->inp_route, flags, inp->inp_moptions, &inp->inp_errormtu)); } /* @@ -204,64 +297,116 @@ rip_ctloutput(op, so, level, optname, m) struct mbuf **m; { register struct inpcb *inp = sotoinpcb(so); -#ifdef MROUTING - int error; -#endif + int error = 0; if (level != IPPROTO_IP) { - if (m != 0 && *m != 0) - (void)m_free(*m); - return (EINVAL); - } - - switch (optname) { - - case IP_HDRINCL: - if (op == PRCO_SETOPT || op == PRCO_GETOPT) { - if (m == 0 || *m == 0 || (*m)->m_len < sizeof (int)) - return (EINVAL); - if (op == PRCO_SETOPT) { + error = ENOPROTOOPT; + if (op == PRCO_SETOPT && *m != 0) + (void) m_free(*m); + } else switch (op) { + + case PRCO_SETOPT: + switch (optname) { + case IP_HDRINCL: + if (*m == 0 || (*m)->m_len < sizeof (int)) + error = EINVAL; + else { if (*mtod(*m, int *)) inp->inp_flags |= INP_HDRINCL; else inp->inp_flags &= ~INP_HDRINCL; - (void)m_free(*m); - } else { - (*m)->m_len = sizeof (int); - *mtod(*m, int *) = inp->inp_flags & INP_HDRINCL; } - return (0); + if (*m != 0) + (void) m_free(*m); + break; + +#ifdef MROUTING + case MRT_INIT: + case MRT_DONE: + case MRT_ADD_VIF: + case MRT_DEL_VIF: + case MRT_ADD_MFC: + case MRT_DEL_MFC: + case MRT_ASSERT: + error = ip_mrouter_set(so, optname, m); + break; +#endif + + default: + error = ip_ctloutput(op, so, level, optname, m); + break; } break; - case MRT_INIT: - case MRT_DONE: - case MRT_ADD_VIF: - case MRT_DEL_VIF: - case MRT_ADD_MFC: - case MRT_DEL_MFC: - case MRT_VERSION: - case MRT_ASSERT: -#ifdef MROUTING - switch (op) { - case PRCO_SETOPT: - error = ip_mrouter_set(optname, so, m); + case PRCO_GETOPT: + switch (optname) { + case IP_HDRINCL: + *m = m_get(M_WAIT, M_SOOPTS); + (*m)->m_len = sizeof (int); + *mtod(*m, int *) = inp->inp_flags & INP_HDRINCL ? 1 : 0; break; - case PRCO_GETOPT: - error = ip_mrouter_get(optname, so, m); + +#ifdef MROUTING + case MRT_VERSION: + case MRT_ASSERT: + error = ip_mrouter_get(so, optname, m); break; +#endif + default: - error = EINVAL; + error = ip_ctloutput(op, so, level, optname, m); break; } - return (error); -#else - if (op == PRCO_SETOPT && *m) - m_free(*m); - return (EOPNOTSUPP); -#endif + break; } - return (ip_ctloutput(op, so, level, optname, m)); + return (error); +} + +int +rip_bind(inp, nam) + struct inpcb *inp; + struct mbuf *nam; +{ + struct sockaddr_in *addr = mtod(nam, struct sockaddr_in *); + + if (nam->m_len != sizeof(*addr)) + return (EINVAL); + if (ifnet.tqh_first == 0) + return (EADDRNOTAVAIL); + if (addr->sin_family != AF_INET && + addr->sin_family != AF_IMPLINK) + return (EAFNOSUPPORT); + if (!in_nullhost(addr->sin_addr) && + ifa_ifwithaddr(sintosa(addr)) == 0) + return (EADDRNOTAVAIL); + inp->inp_laddr = addr->sin_addr; + return (0); +} + +int +rip_connect(inp, nam) + struct inpcb *inp; + struct mbuf *nam; +{ + struct sockaddr_in *addr = mtod(nam, struct sockaddr_in *); + + if (nam->m_len != sizeof(*addr)) + return (EINVAL); + if (ifnet.tqh_first == 0) + return (EADDRNOTAVAIL); + if (addr->sin_family != AF_INET && + addr->sin_family != AF_IMPLINK) + return (EAFNOSUPPORT); + inp->inp_faddr = addr->sin_addr; + return (0); +} + +void +rip_disconnect(inp) + struct inpcb *inp; +{ + + inp->inp_faddr = zeroin_addr; } u_long rip_sendspace = RIPSNDQ; @@ -269,21 +414,30 @@ u_long rip_recvspace = RIPRCVQ; /*ARGSUSED*/ int -rip_usrreq(so, req, m, nam, control) +rip_usrreq(so, req, m, nam, control, p) register struct socket *so; int req; struct mbuf *m, *nam, *control; + struct proc *p; { + register struct inpcb *inp; + int s; register int error = 0; - register struct inpcb *inp = sotoinpcb(so); #ifdef MROUTING extern struct socket *ip_mrouter; #endif + if (req == PRU_CONTROL) return (in_control(so, (long)m, (caddr_t)nam, - (struct ifnet *)control)); + (struct ifnet *)control, p)); - if (inp == NULL && req != PRU_ATTACH) { + s = splsoftnet(); + inp = sotoinpcb(so); +#ifdef DIAGNOSTIC + if (req != PRU_SEND && req != PRU_SENDOOB && control) + panic("rip_usrreq: unexpected control mbuf"); +#endif + if (inp == 0 && req != PRU_ATTACH) { error = EINVAL; goto release; } @@ -291,31 +445,34 @@ rip_usrreq(so, req, m, nam, control) switch (req) { case PRU_ATTACH: - if (inp) - panic("rip_attach"); - if ((so->so_state & SS_PRIV) == 0) { + if (inp != 0) { + error = EISCONN; + break; + } + if (p == 0 || (error = suser(p->p_ucred, &p->p_acflag))) { error = EACCES; break; } - if ((error = soreserve(so, rip_sendspace, rip_recvspace)) || - (error = in_pcballoc(so, &rawcbtable))) + if (so->so_snd.sb_hiwat == 0 || so->so_rcv.sb_hiwat == 0) { + error = soreserve(so, rip_sendspace, rip_recvspace); + if (error) + break; + } + error = in_pcballoc(so, &rawcbtable); + if (error) break; - inp = (struct inpcb *)so->so_pcb; + inp = sotoinpcb(so); inp->inp_ip.ip_p = (long)nam; - break; - - case PRU_DISCONNECT: - if ((so->so_state & SS_ISCONNECTED) == 0) { - error = ENOTCONN; +#ifdef IPSEC + error = ipsec_init_policy(&inp->inp_sp); + if (error != 0) { + in_pcbdetach(inp); break; } - /* FALLTHROUGH */ - case PRU_ABORT: - soisdisconnected(so); - /* FALLTHROUGH */ +#endif /*IPSEC*/ + break; + case PRU_DETACH: - if (inp == 0) - panic("rip_detach"); #ifdef MROUTING if (so == ip_mrouter) ip_mrouter_done(); @@ -324,50 +481,29 @@ rip_usrreq(so, req, m, nam, control) break; case PRU_BIND: - { - struct sockaddr_in *addr = mtod(nam, struct sockaddr_in *); + error = rip_bind(inp, nam); + break; - if (nam->m_len != sizeof(*addr)) { - error = EINVAL; - break; - } - if ((ifnet.tqh_first == 0) || - ((addr->sin_family != AF_INET) && - (addr->sin_family != AF_IMPLINK)) || - (addr->sin_addr.s_addr && - ifa_ifwithaddr(sintosa(addr)) == 0)) { - error = EADDRNOTAVAIL; - break; - } - inp->inp_laddr = addr->sin_addr; + case PRU_LISTEN: + error = EOPNOTSUPP; break; - } - case PRU_CONNECT: - { - struct sockaddr_in *addr = mtod(nam, struct sockaddr_in *); - if (nam->m_len != sizeof(*addr)) { - error = EINVAL; - break; - } - if (ifnet.tqh_first == 0) { - error = EADDRNOTAVAIL; - break; - } - if ((addr->sin_family != AF_INET) && - (addr->sin_family != AF_IMPLINK)) { - error = EAFNOSUPPORT; + case PRU_CONNECT: + error = rip_connect(inp, nam); + if (error) break; - } - inp->inp_faddr = addr->sin_addr; soisconnected(so); break; - } case PRU_CONNECT2: error = EOPNOTSUPP; break; + case PRU_DISCONNECT: + soisdisconnected(so); + rip_disconnect(inp); + break; + /* * Mark the connection as being incapable of further input. */ @@ -375,46 +511,59 @@ rip_usrreq(so, req, m, nam, control) socantsendmore(so); break; + case PRU_RCVD: + error = EOPNOTSUPP; + break; + /* * Ship a packet out. The appropriate raw output * routine handles any massaging necessary. */ case PRU_SEND: - { - register u_int32_t dst; - - if (so->so_state & SS_ISCONNECTED) { - if (nam) { + if (control && control->m_len) { + m_freem(control); + m_freem(m); + error = EINVAL; + break; + } + { + if (nam) { + if ((so->so_state & SS_ISCONNECTED) != 0) { error = EISCONN; + goto die; + } + error = rip_connect(inp, nam); + if (error) { + die: + m_freem(m); break; } - dst = inp->inp_faddr.s_addr; } else { - if (nam == NULL) { + if ((so->so_state & SS_ISCONNECTED) == 0) { error = ENOTCONN; - break; + goto die; } - dst = mtod(nam, struct sockaddr_in *)->sin_addr.s_addr; } - error = rip_output(m, so, dst); - m = NULL; + error = rip_output(m, inp); + if (nam) + rip_disconnect(inp); + } break; - } case PRU_SENSE: /* * stat: don't bother with a blocksize. */ + splx(s); return (0); - /* - * Not supported. - */ case PRU_RCVOOB: - case PRU_RCVD: - case PRU_LISTEN: - case PRU_ACCEPT: + error = EOPNOTSUPP; + break; + case PRU_SENDOOB: + m_freem(control); + m_freem(m); error = EOPNOTSUPP; break; @@ -429,8 +578,8 @@ rip_usrreq(so, req, m, nam, control) default: panic("rip_usrreq"); } + release: - if (m != NULL) - m_freem(m); + splx(s); return (error); }