| version 1.87.2.8, 2008/02/11 15:00:05 |
version 1.88, 2005/12/11 12:24:57 |
| Line 77 __KERNEL_RCSID(0, "$NetBSD$"); |
|
| Line 77 __KERNEL_RCSID(0, "$NetBSD$"); |
|
| #include <sys/errno.h> |
#include <sys/errno.h> |
| #include <sys/systm.h> |
#include <sys/systm.h> |
| #include <sys/proc.h> |
#include <sys/proc.h> |
| #include <sys/kauth.h> |
|
| |
|
| #include <net/if.h> |
#include <net/if.h> |
| #include <net/route.h> |
#include <net/route.h> |
|
|
| in_pcbinit(&rawcbtable, 1, 1); |
in_pcbinit(&rawcbtable, 1, 1); |
| } |
} |
| |
|
| static void |
|
| rip_sbappendaddr(struct inpcb *last, struct ip *ip, const struct sockaddr *sa, |
|
| int hlen, struct mbuf *opts, struct mbuf *n) |
|
| { |
|
| if (last->inp_flags & INP_NOHEADER) |
|
| m_adj(n, hlen); |
|
| if (last->inp_flags & INP_CONTROLOPTS || |
|
| last->inp_socket->so_options & SO_TIMESTAMP) |
|
| ip_savecontrol(last, &opts, ip, n); |
|
| if (sbappendaddr(&last->inp_socket->so_rcv, sa, n, opts) == 0) { |
|
| /* should notify about lost packet */ |
|
| m_freem(n); |
|
| if (opts) |
|
| m_freem(opts); |
|
| } else |
|
| sorwakeup(last->inp_socket); |
|
| } |
|
| |
|
| /* |
/* |
| * Setup generic address and protocol structures |
* Setup generic address and protocol structures |
| * for raw_input routine, then pass them along with |
* for raw_input routine, then pass them along with |
| Line 157 rip_sbappendaddr(struct inpcb *last, str |
|
| Line 138 rip_sbappendaddr(struct inpcb *last, str |
|
| void |
void |
| rip_input(struct mbuf *m, ...) |
rip_input(struct mbuf *m, ...) |
| { |
{ |
| int hlen, proto; |
int proto; |
| struct ip *ip = mtod(m, struct ip *); |
struct ip *ip = mtod(m, struct ip *); |
| struct inpcb_hdr *inph; |
struct inpcb_hdr *inph; |
| struct inpcb *inp; |
struct inpcb *inp; |
| struct inpcb *last = NULL; |
struct inpcb *last = 0; |
| struct mbuf *n, *opts = NULL; |
struct mbuf *opts = 0; |
| struct sockaddr_in ripsrc; |
struct sockaddr_in ripsrc; |
| va_list ap; |
va_list ap; |
| |
|
| Line 171 rip_input(struct mbuf *m, ...) |
|
| Line 152 rip_input(struct mbuf *m, ...) |
|
| proto = va_arg(ap, int); |
proto = va_arg(ap, int); |
| va_end(ap); |
va_end(ap); |
| |
|
| sockaddr_in_init(&ripsrc, &ip->ip_src, 0); |
ripsrc.sin_family = AF_INET; |
| |
ripsrc.sin_len = sizeof(struct sockaddr_in); |
| |
ripsrc.sin_addr = ip->ip_src; |
| |
ripsrc.sin_port = 0; |
| |
bzero((caddr_t)ripsrc.sin_zero, sizeof(ripsrc.sin_zero)); |
| |
|
| /* |
/* |
| * XXX Compatibility: programs using raw IP expect ip_len |
* XXX Compatibility: programs using raw IP expect ip_len |
| * XXX to have the header length subtracted, and in host order. |
* XXX to have the header length subtracted, and in host order. |
| * XXX ip_off is also expected to be host order. |
* XXX ip_off is also expected to be host order. |
| */ |
*/ |
| hlen = ip->ip_hl << 2; |
ip->ip_len = ntohs(ip->ip_len) - (ip->ip_hl << 2); |
| ip->ip_len = ntohs(ip->ip_len) - hlen; |
|
| NTOHS(ip->ip_off); |
NTOHS(ip->ip_off); |
| |
|
| CIRCLEQ_FOREACH(inph, &rawcbtable.inpt_queue, inph_queue) { |
CIRCLEQ_FOREACH(inph, &rawcbtable.inpt_queue, inph_queue) { |
| Line 194 rip_input(struct mbuf *m, ...) |
|
| Line 178 rip_input(struct mbuf *m, ...) |
|
| if (!in_nullhost(inp->inp_faddr) && |
if (!in_nullhost(inp->inp_faddr) && |
| !in_hosteq(inp->inp_faddr, ip->ip_src)) |
!in_hosteq(inp->inp_faddr, ip->ip_src)) |
| continue; |
continue; |
| if (last == NULL) |
if (last) { |
| ; |
struct mbuf *n; |
| |
|
| #if defined(IPSEC) || defined(FAST_IPSEC) |
#if defined(IPSEC) || defined(FAST_IPSEC) |
| /* check AH/ESP integrity. */ |
/* check AH/ESP integrity. */ |
| else if (ipsec4_in_reject_so(m, last->inp_socket)) { |
if (ipsec4_in_reject_so(m, last->inp_socket)) { |
| ipsecstat.in_polvio++; |
ipsecstat.in_polvio++; |
| /* do not inject data to pcb */ |
/* do not inject data to pcb */ |
| } |
} else |
| #endif /*IPSEC*/ |
#endif /*IPSEC*/ |
| else if ((n = m_copypacket(m, M_DONTWAIT)) != NULL) { |
if ((n = m_copy(m, 0, (int)M_COPYALL)) != NULL) { |
| rip_sbappendaddr(last, ip, sintosa(&ripsrc), hlen, opts, |
if (last->inp_flags & INP_CONTROLOPTS || |
| n); |
last->inp_socket->so_options & SO_TIMESTAMP) |
| opts = NULL; |
ip_savecontrol(last, &opts, ip, n); |
| |
if (sbappendaddr(&last->inp_socket->so_rcv, |
| |
sintosa(&ripsrc), n, opts) == 0) { |
| |
/* should notify about lost packet */ |
| |
m_freem(n); |
| |
if (opts) |
| |
m_freem(opts); |
| |
} else |
| |
sorwakeup(last->inp_socket); |
| |
opts = NULL; |
| |
} |
| } |
} |
| last = inp; |
last = inp; |
| } |
} |
| #if defined(IPSEC) || defined(FAST_IPSEC) |
#if defined(IPSEC) || defined(FAST_IPSEC) |
| /* check AH/ESP integrity. */ |
/* check AH/ESP integrity. */ |
| if (last != NULL && ipsec4_in_reject_so(m, last->inp_socket)) { |
if (last && ipsec4_in_reject_so(m, last->inp_socket)) { |
| m_freem(m); |
m_freem(m); |
| ipsecstat.in_polvio++; |
ipsecstat.in_polvio++; |
| ipstat.ips_delivered--; |
ipstat.ips_delivered--; |
| /* do not inject data to pcb */ |
/* do not inject data to pcb */ |
| } else |
} else |
| #endif /*IPSEC*/ |
#endif /*IPSEC*/ |
| if (last != NULL) |
if (last) { |
| rip_sbappendaddr(last, ip, sintosa(&ripsrc), hlen, opts, m); |
if (last->inp_flags & INP_CONTROLOPTS || |
| else if (inetsw[ip_protox[ip->ip_p]].pr_input == rip_input) { |
last->inp_socket->so_options & SO_TIMESTAMP) |
| icmp_error(m, ICMP_UNREACH, ICMP_UNREACH_PROTOCOL, |
ip_savecontrol(last, &opts, ip, m); |
| 0, 0); |
if (sbappendaddr(&last->inp_socket->so_rcv, |
| ipstat.ips_noproto++; |
sintosa(&ripsrc), m, opts) == 0) { |
| ipstat.ips_delivered--; |
m_freem(m); |
| } else |
if (opts) |
| m_freem(m); |
m_freem(opts); |
| |
} else |
| |
sorwakeup(last->inp_socket); |
| |
} else { |
| |
if (inetsw[ip_protox[ip->ip_p]].pr_input == rip_input) { |
| |
icmp_error(m, ICMP_UNREACH, ICMP_UNREACH_PROTOCOL, |
| |
0, 0); |
| |
ipstat.ips_noproto++; |
| |
ipstat.ips_delivered--; |
| |
} else |
| |
m_freem(m); |
| |
} |
| return; |
return; |
| } |
} |
| |
|
| Line 259 rip_pcbnotify(struct inpcbtable *table, |
|
| Line 265 rip_pcbnotify(struct inpcbtable *table, |
|
| } |
} |
| |
|
| void * |
void * |
| rip_ctlinput(int cmd, const struct sockaddr *sa, void *v) |
rip_ctlinput(int cmd, struct sockaddr *sa, void *v) |
| { |
{ |
| struct ip *ip = v; |
struct ip *ip = v; |
| void (*notify)(struct inpcb *, int) = in_rtchange; |
void (*notify)(struct inpcb *, int) = in_rtchange; |
| Line 278 rip_ctlinput(int cmd, const struct socka |
|
| Line 284 rip_ctlinput(int cmd, const struct socka |
|
| else if (errno == 0) |
else if (errno == 0) |
| return NULL; |
return NULL; |
| if (ip) { |
if (ip) { |
| rip_pcbnotify(&rawcbtable, satocsin(sa)->sin_addr, |
rip_pcbnotify(&rawcbtable, satosin(sa)->sin_addr, |
| ip->ip_src, ip->ip_p, errno, notify); |
ip->ip_src, ip->ip_p, errno, notify); |
| |
|
| /* XXX mapped address case */ |
/* XXX mapped address case */ |
| } else |
} else |
| in_pcbnotifyall(&rawcbtable, satocsin(sa)->sin_addr, errno, |
in_pcbnotifyall(&rawcbtable, satosin(sa)->sin_addr, errno, |
| notify); |
notify); |
| return NULL; |
return NULL; |
| } |
} |
| Line 358 rip_output(struct mbuf *m, ...) |
|
| Line 364 rip_output(struct mbuf *m, ...) |
|
| } |
} |
| HTONS(ip->ip_len); |
HTONS(ip->ip_len); |
| HTONS(ip->ip_off); |
HTONS(ip->ip_off); |
| if (ip->ip_id != 0 || m->m_pkthdr.len < IP_MINFRAGSIZE) |
if (ip->ip_id == 0) |
| flags |= IP_NOIPNEWID; |
ip->ip_id = ip_newid(); |
| opts = NULL; |
opts = NULL; |
| /* XXX prevent ip_output from overwriting header fields */ |
/* XXX prevent ip_output from overwriting header fields */ |
| flags |= IP_RAWOUTPUT; |
flags |= IP_RAWOUTPUT; |
| Line 379 rip_ctloutput(int op, struct socket *so, |
|
| Line 385 rip_ctloutput(int op, struct socket *so, |
|
| struct inpcb *inp = sotoinpcb(so); |
struct inpcb *inp = sotoinpcb(so); |
| int error = 0; |
int error = 0; |
| |
|
| if (level == SOL_SOCKET && optname == SO_NOHEADER) { |
if (level != IPPROTO_IP) { |
| if (op == PRCO_GETOPT) { |
error = ENOPROTOOPT; |
| *m = m_intopt(so, |
if (op == PRCO_SETOPT && *m != 0) |
| (inp->inp_flags & INP_NOHEADER) ? 1 : 0); |
(void) m_free(*m); |
| return 0; |
} else switch (op) { |
| } else if (*m == NULL || (*m)->m_len != sizeof(int)) |
|
| error = EINVAL; |
|
| else if (*mtod(*m, int *)) { |
|
| inp->inp_flags &= ~INP_HDRINCL; |
|
| inp->inp_flags |= INP_NOHEADER; |
|
| } else |
|
| inp->inp_flags &= ~INP_NOHEADER; |
|
| goto free_m; |
|
| } else if (level != IPPROTO_IP) |
|
| return ip_ctloutput(op, so, level, optname, m); |
|
| |
|
| switch (op) { |
|
| |
|
| case PRCO_SETOPT: |
case PRCO_SETOPT: |
| switch (optname) { |
switch (optname) { |
| case IP_HDRINCL: |
case IP_HDRINCL: |
| if (*m == NULL || (*m)->m_len != sizeof(int)) |
if (*m == 0 || (*m)->m_len < sizeof (int)) |
| error = EINVAL; |
error = EINVAL; |
| else if (*mtod(*m, int *)) |
else { |
| inp->inp_flags |= INP_HDRINCL; |
if (*mtod(*m, int *)) |
| else |
inp->inp_flags |= INP_HDRINCL; |
| inp->inp_flags &= ~INP_HDRINCL; |
else |
| goto free_m; |
inp->inp_flags &= ~INP_HDRINCL; |
| |
} |
| |
if (*m != 0) |
| |
(void) m_free(*m); |
| |
break; |
| |
|
| #ifdef MROUTING |
#ifdef MROUTING |
| case MRT_INIT: |
case MRT_INIT: |
| Line 432 rip_ctloutput(int op, struct socket *so, |
|
| Line 430 rip_ctloutput(int op, struct socket *so, |
|
| case PRCO_GETOPT: |
case PRCO_GETOPT: |
| switch (optname) { |
switch (optname) { |
| case IP_HDRINCL: |
case IP_HDRINCL: |
| *m = m_intopt(so, inp->inp_flags & INP_HDRINCL ? 1 : 0); |
*m = m_get(M_WAIT, MT_SOOPTS); |
| |
MCLAIM((*m), so->so_mowner); |
| |
(*m)->m_len = sizeof (int); |
| |
*mtod(*m, int *) = inp->inp_flags & INP_HDRINCL ? 1 : 0; |
| break; |
break; |
| |
|
| #ifdef MROUTING |
#ifdef MROUTING |
| Line 450 rip_ctloutput(int op, struct socket *so, |
|
| Line 451 rip_ctloutput(int op, struct socket *so, |
|
| } |
} |
| break; |
break; |
| } |
} |
| return error; |
return (error); |
| free_m: |
|
| if (op == PRCO_SETOPT && *m != NULL) |
|
| (void)m_free(*m); |
|
| return error; |
|
| } |
} |
| |
|
| int |
int |
| Line 508 rip_usrreq(struct socket *so, int req, |
|
| Line 505 rip_usrreq(struct socket *so, int req, |
|
| struct mbuf *m, struct mbuf *nam, struct mbuf *control, struct lwp *l) |
struct mbuf *m, struct mbuf *nam, struct mbuf *control, struct lwp *l) |
| { |
{ |
| struct inpcb *inp; |
struct inpcb *inp; |
| |
struct proc *p; |
| int s; |
int s; |
| int error = 0; |
int error = 0; |
| #ifdef MROUTING |
#ifdef MROUTING |
| extern struct socket *ip_mrouter; |
extern struct socket *ip_mrouter; |
| #endif |
#endif |
| |
|
| |
p = l ? l->l_proc : NULL; |
| if (req == PRU_CONTROL) |
if (req == PRU_CONTROL) |
| return (in_control(so, (long)m, (void *)nam, |
return (in_control(so, (long)m, (caddr_t)nam, |
| (struct ifnet *)control, l)); |
(struct ifnet *)control, p)); |
| |
|
| s = splsoftnet(); |
|
| |
|
| if (req == PRU_PURGEIF) { |
if (req == PRU_PURGEIF) { |
| in_pcbpurgeif0(&rawcbtable, (struct ifnet *)control); |
in_pcbpurgeif0(&rawcbtable, (struct ifnet *)control); |
| in_purgeif((struct ifnet *)control); |
in_purgeif((struct ifnet *)control); |
| in_pcbpurgeif(&rawcbtable, (struct ifnet *)control); |
in_pcbpurgeif(&rawcbtable, (struct ifnet *)control); |
| splx(s); |
|
| return (0); |
return (0); |
| } |
} |
| |
|
| |
s = splsoftnet(); |
| inp = sotoinpcb(so); |
inp = sotoinpcb(so); |
| #ifdef DIAGNOSTIC |
#ifdef DIAGNOSTIC |
| if (req != PRU_SEND && req != PRU_SENDOOB && control) |
if (req != PRU_SEND && req != PRU_SENDOOB && control) |
| Line 545 rip_usrreq(struct socket *so, int req, |
|
| Line 542 rip_usrreq(struct socket *so, int req, |
|
| error = EISCONN; |
error = EISCONN; |
| break; |
break; |
| } |
} |
| |
if (p == 0 || (error = suser(p->p_ucred, &p->p_acflag))) { |
| if (l == NULL) { |
|
| error = EACCES; |
error = EACCES; |
| break; |
break; |
| } |
} |
| |
|
| /* XXX: raw socket permissions are checked in socreate() */ |
|
| |
|
| if (so->so_snd.sb_hiwat == 0 || so->so_rcv.sb_hiwat == 0) { |
if (so->so_snd.sb_hiwat == 0 || so->so_rcv.sb_hiwat == 0) { |
| error = soreserve(so, rip_sendspace, rip_recvspace); |
error = soreserve(so, rip_sendspace, rip_recvspace); |
| if (error) |
if (error) |