| version 1.82, 2006/01/23 23:01:40 |
version 1.82.2.3, 2006/09/09 02:58:55 |
|
|
| __KERNEL_RCSID(0, "$NetBSD$"); |
__KERNEL_RCSID(0, "$NetBSD$"); |
| |
|
| #include "opt_inet.h" |
#include "opt_inet.h" |
| |
#include "opt_inet6.h" |
| #include "opt_ipsec.h" |
#include "opt_ipsec.h" |
| #include "opt_pfil_hooks.h" |
#include "opt_pfil_hooks.h" |
| |
|
| Line 94 __KERNEL_RCSID(0, "$NetBSD$"); |
|
| Line 95 __KERNEL_RCSID(0, "$NetBSD$"); |
|
| |
|
| #include <netinet/in.h> |
#include <netinet/in.h> |
| #include <netinet/in_systm.h> |
#include <netinet/in_systm.h> |
| |
#include <netinet/in_pcb.h> |
| #ifdef INET |
#ifdef INET |
| #include <netinet/ip.h> |
#include <netinet/ip.h> |
| #include <netinet/ip_icmp.h> |
#include <netinet/ip_icmp.h> |
| Line 101 __KERNEL_RCSID(0, "$NetBSD$"); |
|
| Line 103 __KERNEL_RCSID(0, "$NetBSD$"); |
|
| #include <netinet/ip6.h> |
#include <netinet/ip6.h> |
| #include <netinet6/in6_var.h> |
#include <netinet6/in6_var.h> |
| #include <netinet6/ip6_var.h> |
#include <netinet6/ip6_var.h> |
| #include <netinet6/in6_pcb.h> |
|
| #include <netinet/icmp6.h> |
#include <netinet/icmp6.h> |
| #include <netinet6/scope6_var.h> |
#include <netinet6/scope6_var.h> |
| #include <netinet6/in6_ifattach.h> |
#include <netinet6/in6_ifattach.h> |
| Line 129 static int ip6qmaxlen = IFQ_MAXLEN; |
|
| Line 130 static int ip6qmaxlen = IFQ_MAXLEN; |
|
| struct in6_ifaddr *in6_ifaddr; |
struct in6_ifaddr *in6_ifaddr; |
| struct ifqueue ip6intrq; |
struct ifqueue ip6intrq; |
| |
|
| |
extern struct callout in6_tmpaddrtimer_ch; |
| |
|
| int ip6_forward_srcrt; /* XXX */ |
int ip6_forward_srcrt; /* XXX */ |
| int ip6_sourcecheck; /* XXX */ |
int ip6_sourcecheck; /* XXX */ |
| int ip6_sourcecheck_interval; /* XXX */ |
int ip6_sourcecheck_interval; /* XXX */ |
|
|
| addrsel_policy_init(); |
addrsel_policy_init(); |
| nd6_init(); |
nd6_init(); |
| frag6_init(); |
frag6_init(); |
| |
ip6_desync_factor = arc4random() % MAX_TEMP_DESYNC_FACTOR; |
| |
|
| ip6_init2((void *)0); |
ip6_init2((void *)0); |
| |
|
| Line 192 ip6_init2(dummy) |
|
| Line 196 ip6_init2(dummy) |
|
| /* nd6_timer_init */ |
/* nd6_timer_init */ |
| callout_init(&nd6_timer_ch); |
callout_init(&nd6_timer_ch); |
| callout_reset(&nd6_timer_ch, hz, nd6_timer, NULL); |
callout_reset(&nd6_timer_ch, hz, nd6_timer, NULL); |
| |
|
| |
/* timer for regeneranation of temporary addresses randomize ID */ |
| |
callout_init(&in6_tmpaddrtimer_ch); |
| |
callout_reset(&in6_tmpaddrtimer_ch, |
| |
(ip6_temp_preferred_lifetime - ip6_desync_factor - |
| |
ip6_temp_regen_advance) * hz, |
| |
in6_tmpaddrtimer, NULL); |
| } |
} |
| |
|
| /* |
/* |
|
|
| splx(s); |
splx(s); |
| if (m == 0) |
if (m == 0) |
| return; |
return; |
| |
/* drop the packet if IPv6 operation is disabled on the IF */ |
| |
if ((ND_IFINFO(m->m_pkthdr.rcvif)->flags & ND6_IFF_IFDISABLED)) { |
| |
m_freem(m); |
| |
return; |
| |
} |
| ip6_input(m); |
ip6_input(m); |
| } |
} |
| } |
} |
|
|
| * dst are the loopback address and the receiving interface |
* dst are the loopback address and the receiving interface |
| * is not loopback. |
* is not loopback. |
| */ |
*/ |
| |
if (__predict_false( |
| |
m_makewritable(&m, 0, sizeof(struct ip6_hdr), M_DONTWAIT))) |
| |
goto bad; |
| |
ip6 = mtod(m, struct ip6_hdr *); |
| if (in6_clearscope(&ip6->ip6_src) || in6_clearscope(&ip6->ip6_dst)) { |
if (in6_clearscope(&ip6->ip6_src) || in6_clearscope(&ip6->ip6_dst)) { |
| ip6stat.ip6s_badscope++; /* XXX */ |
ip6stat.ip6s_badscope++; /* XXX */ |
| goto bad; |
goto bad; |
|
|
| if (ip6->ip6_plen == 0 && plen == 0) { |
if (ip6->ip6_plen == 0 && plen == 0) { |
| /* |
/* |
| * Note that if a valid jumbo payload option is |
* Note that if a valid jumbo payload option is |
| * contained, ip6_hoptops_input() must set a valid |
* contained, ip6_hopopts_input() must set a valid |
| * (non-zero) payload length to the variable plen. |
* (non-zero) payload length to the variable plen. |
| */ |
*/ |
| ip6stat.ip6s_badoptions++; |
ip6stat.ip6s_badoptions++; |
| Line 1009 ip6_unknown_opt(optp, m, off) |
|
| Line 1029 ip6_unknown_opt(optp, m, off) |
|
| * you are using IP6_EXTHDR_CHECK() not m_pulldown()) |
* you are using IP6_EXTHDR_CHECK() not m_pulldown()) |
| */ |
*/ |
| void |
void |
| ip6_savecontrol(in6p, mp, ip6, m) |
ip6_savecontrol(inp, mp, ip6, m) |
| struct in6pcb *in6p; |
struct inpcb *inp; |
| struct mbuf **mp; |
struct mbuf **mp; |
| struct ip6_hdr *ip6; |
struct ip6_hdr *ip6; |
| struct mbuf *m; |
struct mbuf *m; |
| { |
{ |
| |
#ifdef RFC2292 |
| |
#define IS2292(x, y) ((in6p->in6p_flags & IN6P_RFC2292) ? (x) : (y)) |
| |
#else |
| |
#define IS2292(x, y) (y) |
| |
#endif |
| |
|
| #ifdef SO_TIMESTAMP |
#ifdef SO_TIMESTAMP |
| if (in6p->in6p_socket->so_options & SO_TIMESTAMP) { |
if (inp->inp_socket->so_options & SO_TIMESTAMP) { |
| struct timeval tv; |
struct timeval tv; |
| |
|
| microtime(&tv); |
microtime(&tv); |
| Line 1027 ip6_savecontrol(in6p, mp, ip6, m) |
|
| Line 1052 ip6_savecontrol(in6p, mp, ip6, m) |
|
| mp = &(*mp)->m_next; |
mp = &(*mp)->m_next; |
| } |
} |
| #endif |
#endif |
| if (in6p->in6p_flags & IN6P_RECVDSTADDR) { |
|
| *mp = sbcreatecontrol((caddr_t) &ip6->ip6_dst, |
|
| sizeof(struct in6_addr), IPV6_RECVDSTADDR, IPPROTO_IPV6); |
|
| if (*mp) |
|
| mp = &(*mp)->m_next; |
|
| } |
|
| |
|
| #ifdef noyet |
/* some OSes call this logic with IPv4 packet, for SO_TIMESTAMP */ |
| /* options were tossed above */ |
if ((ip6->ip6_vfc & IPV6_VERSION_MASK) != IPV6_VERSION) |
| if (in6p->in6p_flags & IN6P_RECVOPTS) |
return; |
| /* broken */ |
|
| /* ip6_srcroute doesn't do what we want here, need to fix */ |
|
| if (in6p->in6p_flags & IPV6P_RECVRETOPTS) |
|
| /* broken */ |
|
| #endif |
|
| |
|
| /* RFC 2292 sec. 5 */ |
/* RFC 2292 sec. 5 */ |
| if ((in6p->in6p_flags & IN6P_PKTINFO) != 0) { |
if ((inp->inp_flags & IN6P_PKTINFO) != 0) { |
| struct in6_pktinfo pi6; |
struct in6_pktinfo pi6; |
| |
|
| bcopy(&ip6->ip6_dst, &pi6.ipi6_addr, sizeof(struct in6_addr)); |
bcopy(&ip6->ip6_dst, &pi6.ipi6_addr, sizeof(struct in6_addr)); |
| in6_clearscope(&pi6.ipi6_addr); /* XXX */ |
in6_clearscope(&pi6.ipi6_addr); /* XXX */ |
| pi6.ipi6_ifindex = (m && m->m_pkthdr.rcvif) |
pi6.ipi6_ifindex = m->m_pkthdr.rcvif ? |
| ? m->m_pkthdr.rcvif->if_index |
m->m_pkthdr.rcvif->if_index : 0; |
| : 0; |
|
| *mp = sbcreatecontrol((caddr_t) &pi6, |
*mp = sbcreatecontrol((caddr_t) &pi6, |
| sizeof(struct in6_pktinfo), IPV6_PKTINFO, IPPROTO_IPV6); |
sizeof(struct in6_pktinfo), |
| |
IS2292(IPV6_2292PKTINFO, IPV6_PKTINFO), IPPROTO_IPV6); |
| if (*mp) |
if (*mp) |
| mp = &(*mp)->m_next; |
mp = &(*mp)->m_next; |
| } |
} |
| if (in6p->in6p_flags & IN6P_HOPLIMIT) { |
if (inp->inp_flags & IN6P_HOPLIMIT) { |
| int hlim = ip6->ip6_hlim & 0xff; |
int hlim = ip6->ip6_hlim & 0xff; |
| |
|
| *mp = sbcreatecontrol((caddr_t) &hlim, sizeof(int), |
*mp = sbcreatecontrol((caddr_t) &hlim, sizeof(int), |
| IPV6_HOPLIMIT, IPPROTO_IPV6); |
IS2292(IPV6_2292HOPLIMIT, IPV6_HOPLIMIT), IPPROTO_IPV6); |
| |
if (*mp) |
| |
mp = &(*mp)->m_next; |
| |
} |
| |
|
| |
if ((in6p->in6p_flags & IN6P_TCLASS) != 0) { |
| |
u_int32_t flowinfo; |
| |
int tclass; |
| |
|
| |
flowinfo = (u_int32_t)ntohl(ip6->ip6_flow & IPV6_FLOWINFO_MASK); |
| |
flowinfo >>= 20; |
| |
|
| |
tclass = flowinfo & 0xff; |
| |
*mp = sbcreatecontrol((caddr_t)&tclass, sizeof(tclass), |
| |
IPV6_TCLASS, IPPROTO_IPV6); |
| |
|
| if (*mp) |
if (*mp) |
| mp = &(*mp)->m_next; |
mp = &(*mp)->m_next; |
| } |
} |
| /* IN6P_NEXTHOP - for outgoing packet only */ |
|
| |
|
| /* |
/* |
| * IPV6_HOPOPTS socket option. Recall that we required super-user |
* IPV6_HOPOPTS socket option. Recall that we required super-user |
| * privilege for the option (see ip6_ctloutput), but it might be too |
* privilege for the option (see ip6_ctloutput), but it might be too |
| * strict, since there might be some hop-by-hop options which can be |
* strict, since there might be some hop-by-hop options which can be |
| * returned to normal user. |
* returned to normal user. |
| * See also RFC 2292 section 6. |
* See also RFC3542 section 8 (or RFC2292 section 6). |
| */ |
*/ |
| if ((in6p->in6p_flags & IN6P_HOPOPTS) != 0) { |
if ((inp->inp_flags & IN6P_HOPOPTS) != 0) { |
| /* |
/* |
| * Check if a hop-by-hop options header is contatined in the |
* Check if a hop-by-hop options header is contatined in the |
| * received packet, and if so, store the options as ancillary |
* received packet, and if so, store the options as ancillary |
| Line 1104 ip6_savecontrol(in6p, mp, ip6, m) |
|
| Line 1134 ip6_savecontrol(in6p, mp, ip6, m) |
|
| * XXX: We copy whole the header even if a jumbo |
* XXX: We copy whole the header even if a jumbo |
| * payload option is included, which option is to |
* payload option is included, which option is to |
| * be removed before returning in the RFC 2292. |
* be removed before returning in the RFC 2292. |
| * But it's too painful operation... |
* Note: this constraint is removed in RFC3542. |
| */ |
*/ |
| *mp = sbcreatecontrol((caddr_t)hbh, hbhlen, |
*mp = sbcreatecontrol((caddr_t)hbh, hbhlen, |
| IPV6_HOPOPTS, IPPROTO_IPV6); |
IS2292(IPV6_2292HOPOPTS, IPV6_HOPOPTS), |
| |
IPPROTO_IPV6); |
| if (*mp) |
if (*mp) |
| mp = &(*mp)->m_next; |
mp = &(*mp)->m_next; |
| m_freem(ext); |
m_freem(ext); |
| Line 1115 ip6_savecontrol(in6p, mp, ip6, m) |
|
| Line 1146 ip6_savecontrol(in6p, mp, ip6, m) |
|
| } |
} |
| |
|
| /* IPV6_DSTOPTS and IPV6_RTHDR socket options */ |
/* IPV6_DSTOPTS and IPV6_RTHDR socket options */ |
| if (in6p->in6p_flags & (IN6P_DSTOPTS | IN6P_RTHDR)) { |
if (inp->inp_flags & (IN6P_DSTOPTS | IN6P_RTHDR)) { |
| struct ip6_hdr *xip6 = mtod(m, struct ip6_hdr *); |
struct ip6_hdr *xip6 = mtod(m, struct ip6_hdr *); |
| int nxt = xip6->ip6_nxt, off = sizeof(struct ip6_hdr); |
int nxt = xip6->ip6_nxt, off = sizeof(struct ip6_hdr); |
| |
|
| Line 1126 ip6_savecontrol(in6p, mp, ip6, m) |
|
| Line 1157 ip6_savecontrol(in6p, mp, ip6, m) |
|
| * Note that the order of the headers remains in |
* Note that the order of the headers remains in |
| * the chain of ancillary data. |
* the chain of ancillary data. |
| */ |
*/ |
| while (1) { /* is explicit loop prevention necessary? */ |
for (;;) { /* is explicit loop prevention necessary? */ |
| struct ip6_ext *ip6e = NULL; |
struct ip6_ext *ip6e = NULL; |
| int elen; |
int elen; |
| struct mbuf *ext = NULL; |
struct mbuf *ext = NULL; |
| Line 1164 ip6_savecontrol(in6p, mp, ip6, m) |
|
| Line 1195 ip6_savecontrol(in6p, mp, ip6, m) |
|
| |
|
| switch (nxt) { |
switch (nxt) { |
| case IPPROTO_DSTOPTS: |
case IPPROTO_DSTOPTS: |
| if (!in6p->in6p_flags & IN6P_DSTOPTS) |
if (!inp->inp_flags & IN6P_DSTOPTS) |
| break; |
break; |
| |
|
| *mp = sbcreatecontrol((caddr_t)ip6e, elen, |
*mp = sbcreatecontrol((caddr_t)ip6e, elen, |
| IPV6_DSTOPTS, IPPROTO_IPV6); |
IS2292(IPV6_2292DSTOPTS, IPV6_DSTOPTS), |
| |
IPPROTO_IPV6); |
| if (*mp) |
if (*mp) |
| mp = &(*mp)->m_next; |
mp = &(*mp)->m_next; |
| break; |
break; |
| |
|
| case IPPROTO_ROUTING: |
case IPPROTO_ROUTING: |
| if (!in6p->in6p_flags & IN6P_RTHDR) |
if (!inp->inp_flags & IN6P_RTHDR) |
| break; |
break; |
| |
|
| *mp = sbcreatecontrol((caddr_t)ip6e, elen, |
*mp = sbcreatecontrol((caddr_t)ip6e, elen, |
| IPV6_RTHDR, IPPROTO_IPV6); |
IS2292(IPV6_2292RTHDR, IPV6_RTHDR), |
| |
IPPROTO_IPV6); |
| if (*mp) |
if (*mp) |
| mp = &(*mp)->m_next; |
mp = &(*mp)->m_next; |
| break; |
break; |
| Line 1210 ip6_savecontrol(in6p, mp, ip6, m) |
|
| Line 1243 ip6_savecontrol(in6p, mp, ip6, m) |
|
| ; |
; |
| } |
} |
| } |
} |
| |
#undef IS2292 |
| |
|
| |
|
| |
void |
| |
ip6_notify_pmtu(struct in6pcb *in6p, struct sockaddr_in6 *dst, uint32_t *mtu) |
| |
{ |
| |
struct socket *so; |
| |
struct mbuf *m_mtu; |
| |
struct ip6_mtuinfo mtuctl; |
| |
|
| |
so = in6p->in6p_socket; |
| |
|
| |
if (mtu == NULL) |
| |
return; |
| |
|
| |
#ifdef DIAGNOSTIC |
| |
if (so == NULL) /* I believe this is impossible */ |
| |
panic("ip6_notify_pmtu: socket is NULL"); |
| |
#endif |
| |
|
| |
memset(&mtuctl, 0, sizeof(mtuctl)); /* zero-clear for safety */ |
| |
mtuctl.ip6m_mtu = *mtu; |
| |
mtuctl.ip6m_addr = *dst; |
| |
if (sa6_recoverscope(&mtuctl.ip6m_addr)) |
| |
return; |
| |
|
| |
if ((m_mtu = sbcreatecontrol((caddr_t)&mtuctl, sizeof(mtuctl), |
| |
IPV6_PATHMTU, IPPROTO_IPV6)) == NULL) |
| |
return; |
| |
|
| |
if (sbappendaddr(&so->so_rcv, (struct sockaddr *)dst, NULL, m_mtu) |
| |
== 0) { |
| |
m_freem(m_mtu); |
| |
/* XXX: should count statistics */ |
| |
} else |
| |
sorwakeup(so); |
| |
|
| |
return; |
| |
} |
| |
|
| /* |
/* |
| * pull single extension header from mbuf chain. returns single mbuf that |
* pull single extension header from mbuf chain. returns single mbuf that |
| Line 1337 ip6_nexthdr(m, off, proto, nxtp) |
|
| Line 1409 ip6_nexthdr(m, off, proto, nxtp) |
|
| |
|
| switch (proto) { |
switch (proto) { |
| case IPPROTO_IPV6: |
case IPPROTO_IPV6: |
| |
/* do not chase beyond intermediate IPv6 headers */ |
| |
if (off != 0) |
| |
return -1; |
| if (m->m_pkthdr.len < off + sizeof(ip6)) |
if (m->m_pkthdr.len < off + sizeof(ip6)) |
| return -1; |
return -1; |
| m_copydata(m, off, sizeof(ip6), (caddr_t)&ip6); |
m_copydata(m, off, sizeof(ip6), (caddr_t)&ip6); |
| Line 1412 ip6_lasthdr(m, off, proto, nxtp) |
|
| Line 1487 ip6_lasthdr(m, off, proto, nxtp) |
|
| nxt = -1; |
nxt = -1; |
| nxtp = &nxt; |
nxtp = &nxt; |
| } |
} |
| while (1) { |
for (;;) { |
| newoff = ip6_nexthdr(m, off, proto, nxtp); |
newoff = ip6_nexthdr(m, off, proto, nxtp); |
| if (newoff < 0) |
if (newoff < 0) |
| return off; |
return off; |
| Line 1480 u_char inet6ctlerrmap[PRC_NCMDS] = { |
|
| Line 1555 u_char inet6ctlerrmap[PRC_NCMDS] = { |
|
| |
|
| SYSCTL_SETUP(sysctl_net_inet6_ip6_setup, "sysctl net.inet6.ip6 subtree setup") |
SYSCTL_SETUP(sysctl_net_inet6_ip6_setup, "sysctl net.inet6.ip6 subtree setup") |
| { |
{ |
| |
#ifdef RFC2292 |
| |
#define IS2292(x, y) ((in6p->in6p_flags & IN6P_RFC2292) ? (x) : (y)) |
| |
#else |
| |
#define IS2292(x, y) (y) |
| |
#endif |
| |
|
| sysctl_createv(clog, 0, NULL, NULL, |
sysctl_createv(clog, 0, NULL, NULL, |
| CTLFLAG_PERMANENT, |
CTLFLAG_PERMANENT, |
| Line 1696 SYSCTL_SETUP(sysctl_net_inet6_ip6_setup, |
|
| Line 1776 SYSCTL_SETUP(sysctl_net_inet6_ip6_setup, |
|
| #endif /* IPNOPRIVPORTS */ |
#endif /* IPNOPRIVPORTS */ |
| sysctl_createv(clog, 0, NULL, NULL, |
sysctl_createv(clog, 0, NULL, NULL, |
| CTLFLAG_PERMANENT|CTLFLAG_READWRITE, |
CTLFLAG_PERMANENT|CTLFLAG_READWRITE, |
| |
CTLTYPE_INT, "use_tempaddr", |
| |
SYSCTL_DESCR("Use temporary address"), |
| |
NULL, 0, &ip6_use_tempaddr, 0, |
| |
CTL_NET, PF_INET6, IPPROTO_IPV6, |
| |
CTL_CREATE, CTL_EOL); |
| |
sysctl_createv(clog, 0, NULL, NULL, |
| |
CTLFLAG_PERMANENT|CTLFLAG_READWRITE, |
| |
CTLTYPE_INT, "temppltime", |
| |
SYSCTL_DESCR("preferred lifetime of a temporary address"), |
| |
NULL, 0, &ip6_temp_preferred_lifetime, 0, |
| |
CTL_NET, PF_INET6, IPPROTO_IPV6, |
| |
CTL_CREATE, CTL_EOL); |
| |
sysctl_createv(clog, 0, NULL, NULL, |
| |
CTLFLAG_PERMANENT|CTLFLAG_READWRITE, |
| |
CTLTYPE_INT, "tempvltime", |
| |
SYSCTL_DESCR("valid lifetime of a temporary address"), |
| |
NULL, 0, &ip6_temp_valid_lifetime, 0, |
| |
CTL_NET, PF_INET6, IPPROTO_IPV6, |
| |
CTL_CREATE, CTL_EOL); |
| |
sysctl_createv(clog, 0, NULL, NULL, |
| |
CTLFLAG_PERMANENT|CTLFLAG_READWRITE, |
| CTLTYPE_INT, "maxfrags", |
CTLTYPE_INT, "maxfrags", |
| SYSCTL_DESCR("Maximum fragments in reassembly queue"), |
SYSCTL_DESCR("Maximum fragments in reassembly queue"), |
| NULL, 0, &ip6_maxfrags, 0, |
NULL, 0, &ip6_maxfrags, 0, |
| Line 1715 SYSCTL_SETUP(sysctl_net_inet6_ip6_setup, |
|
| Line 1816 SYSCTL_SETUP(sysctl_net_inet6_ip6_setup, |
|
| NULL, 0, &ip6_use_defzone, 0, |
NULL, 0, &ip6_use_defzone, 0, |
| CTL_NET, PF_INET6, IPPROTO_IPV6, |
CTL_NET, PF_INET6, IPPROTO_IPV6, |
| IPV6CTL_USE_DEFAULTZONE, CTL_EOL); |
IPV6CTL_USE_DEFAULTZONE, CTL_EOL); |
| |
sysctl_createv(clog, 0, NULL, NULL, |
| |
CTLFLAG_PERMANENT|CTLFLAG_READWRITE, |
| |
CTLTYPE_INT, "mcast_pmtu", |
| |
SYSCTL_DESCR("Enable pMTU discovery for multicast packet"), |
| |
NULL, 0, &ip6_mcast_pmtu, 0, |
| |
CTL_NET, PF_INET6, IPPROTO_IPV6, |
| |
CTL_CREATE, CTL_EOL); |
| } |
} |