net: add build-time checks for msg->msg_name size
[deliverable/linux.git] / net / ipv6 / ping.c
CommitLineData
6d0bfe22
LC
1/*
2 * INET An implementation of the TCP/IP protocol suite for the LINUX
3 * operating system. INET is implemented using the BSD Socket
4 * interface as the means of communication with the user level.
5 *
6 * "Ping" sockets
7 *
8 * This program is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU General Public License
10 * as published by the Free Software Foundation; either version
11 * 2 of the License, or (at your option) any later version.
12 *
13 * Based on ipv4/ping.c code.
14 *
15 * Authors: Lorenzo Colitti (IPv6 support)
16 * Vasiliy Kulikov / Openwall (IPv4 implementation, for Linux 2.6),
17 * Pavel Kankovsky (IPv4 implementation, for Linux 2.4.32)
18 *
19 */
20
21#include <net/addrconf.h>
22#include <net/ipv6.h>
23#include <net/ip6_route.h>
24#include <net/protocol.h>
25#include <net/udp.h>
26#include <net/transp_v6.h>
27#include <net/ping.h>
28
29struct proto pingv6_prot = {
30 .name = "PINGv6",
31 .owner = THIS_MODULE,
32 .init = ping_init_sock,
33 .close = ping_close,
34 .connect = ip6_datagram_connect,
35 .disconnect = udp_disconnect,
36 .setsockopt = ipv6_setsockopt,
37 .getsockopt = ipv6_getsockopt,
38 .sendmsg = ping_v6_sendmsg,
39 .recvmsg = ping_recvmsg,
40 .bind = ping_bind,
41 .backlog_rcv = ping_queue_rcv_skb,
42 .hash = ping_hash,
43 .unhash = ping_unhash,
44 .get_port = ping_get_port,
45 .obj_size = sizeof(struct raw6_sock),
46};
47EXPORT_SYMBOL_GPL(pingv6_prot);
48
49static struct inet_protosw pingv6_protosw = {
50 .type = SOCK_DGRAM,
51 .protocol = IPPROTO_ICMPV6,
52 .prot = &pingv6_prot,
53 .ops = &inet6_dgram_ops,
54 .no_check = UDP_CSUM_DEFAULT,
55 .flags = INET_PROTOSW_REUSE,
56};
57
58
59/* Compatibility glue so we can support IPv6 when it's compiled as a module */
85fbaa75
HFS
60static int dummy_ipv6_recv_error(struct sock *sk, struct msghdr *msg, int len,
61 int *addr_len)
6d0bfe22
LC
62{
63 return -EAFNOSUPPORT;
64}
a06a2d37
WF
65static int dummy_ip6_datagram_recv_ctl(struct sock *sk, struct msghdr *msg,
66 struct sk_buff *skb)
6d0bfe22
LC
67{
68 return -EAFNOSUPPORT;
69}
a06a2d37 70static int dummy_icmpv6_err_convert(u8 type, u8 code, int *err)
6d0bfe22
LC
71{
72 return -EAFNOSUPPORT;
73}
a06a2d37
WF
74static void dummy_ipv6_icmp_error(struct sock *sk, struct sk_buff *skb, int err,
75 __be16 port, u32 info, u8 *payload) {}
76static int dummy_ipv6_chk_addr(struct net *net, const struct in6_addr *addr,
77 const struct net_device *dev, int strict)
6d0bfe22
LC
78{
79 return 0;
80}
81
6d0bfe22
LC
82int ping_v6_sendmsg(struct kiocb *iocb, struct sock *sk, struct msghdr *msg,
83 size_t len)
84{
85 struct inet_sock *inet = inet_sk(sk);
86 struct ipv6_pinfo *np = inet6_sk(sk);
87 struct icmp6hdr user_icmph;
88 int addr_type;
89 struct in6_addr *daddr;
90 int iif = 0;
91 struct flowi6 fl6;
92 int err;
93 int hlimit;
94 struct dst_entry *dst;
95 struct rt6_info *rt;
96 struct pingfakehdr pfh;
97
98 pr_debug("ping_v6_sendmsg(sk=%p,sk->num=%u)\n", inet, inet->inet_num);
99
100 err = ping_common_sendmsg(AF_INET6, msg, len, &user_icmph,
101 sizeof(user_icmph));
102 if (err)
103 return err;
104
105 if (msg->msg_name) {
342dfc30 106 DECLARE_SOCKADDR(struct sockaddr_in6 *, u, msg->msg_name);
6d0bfe22
LC
107 if (msg->msg_namelen < sizeof(struct sockaddr_in6) ||
108 u->sin6_family != AF_INET6) {
109 return -EINVAL;
110 }
111 if (sk->sk_bound_dev_if &&
112 sk->sk_bound_dev_if != u->sin6_scope_id) {
113 return -EINVAL;
114 }
115 daddr = &(u->sin6_addr);
116 iif = u->sin6_scope_id;
117 } else {
118 if (sk->sk_state != TCP_ESTABLISHED)
119 return -EDESTADDRREQ;
efe4208f 120 daddr = &sk->sk_v6_daddr;
6d0bfe22
LC
121 }
122
123 if (!iif)
124 iif = sk->sk_bound_dev_if;
125
126 addr_type = ipv6_addr_type(daddr);
127 if (__ipv6_addr_needs_scope_id(addr_type) && !iif)
128 return -EINVAL;
129 if (addr_type & IPV6_ADDR_MAPPED)
130 return -EINVAL;
131
132 /* TODO: use ip6_datagram_send_ctl to get options from cmsg */
133
134 memset(&fl6, 0, sizeof(fl6));
135
136 fl6.flowi6_proto = IPPROTO_ICMPV6;
137 fl6.saddr = np->saddr;
138 fl6.daddr = *daddr;
139 fl6.fl6_icmp_type = user_icmph.icmp6_type;
140 fl6.fl6_icmp_code = user_icmph.icmp6_code;
141 security_sk_classify_flow(sk, flowi6_to_flowi(&fl6));
142
143 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
144 fl6.flowi6_oif = np->mcast_oif;
145 else if (!fl6.flowi6_oif)
146 fl6.flowi6_oif = np->ucast_oif;
147
0e0d44ab 148 dst = ip6_sk_dst_lookup_flow(sk, &fl6, daddr);
6d0bfe22
LC
149 if (IS_ERR(dst))
150 return PTR_ERR(dst);
151 rt = (struct rt6_info *) dst;
152
153 np = inet6_sk(sk);
154 if (!np)
155 return -EBADF;
156
157 if (!fl6.flowi6_oif && ipv6_addr_is_multicast(&fl6.daddr))
158 fl6.flowi6_oif = np->mcast_oif;
159 else if (!fl6.flowi6_oif)
160 fl6.flowi6_oif = np->ucast_oif;
161
162 pfh.icmph.type = user_icmph.icmp6_type;
163 pfh.icmph.code = user_icmph.icmp6_code;
164 pfh.icmph.checksum = 0;
165 pfh.icmph.un.echo.id = inet->inet_sport;
166 pfh.icmph.un.echo.sequence = user_icmph.icmp6_sequence;
167 pfh.iov = msg->msg_iov;
168 pfh.wcheck = 0;
169 pfh.family = AF_INET6;
170
171 if (ipv6_addr_is_multicast(&fl6.daddr))
172 hlimit = np->mcast_hops;
173 else
174 hlimit = np->hop_limit;
175 if (hlimit < 0)
176 hlimit = ip6_dst_hoplimit(dst);
177
a1bdc455 178 lock_sock(sk);
6d0bfe22
LC
179 err = ip6_append_data(sk, ping_getfrag, &pfh, len,
180 0, hlimit,
181 np->tclass, NULL, &fl6, rt,
182 MSG_DONTWAIT, np->dontfrag);
183
184 if (err) {
185 ICMP6_INC_STATS_BH(sock_net(sk), rt->rt6i_idev,
186 ICMP6_MIB_OUTERRORS);
187 ip6_flush_pending_frames(sk);
188 } else {
189 err = icmpv6_push_pending_frames(sk, &fl6,
190 (struct icmp6hdr *) &pfh.icmph,
191 len);
192 }
a1bdc455 193 release_sock(sk);
6d0bfe22 194
fbfe80c8
LC
195 if (err)
196 return err;
197
198 return len;
6d0bfe22 199}
d862e546
LC
200
201#ifdef CONFIG_PROC_FS
202static void *ping_v6_seq_start(struct seq_file *seq, loff_t *pos)
203{
204 return ping_seq_start(seq, pos, AF_INET6);
205}
206
a06a2d37 207static int ping_v6_seq_show(struct seq_file *seq, void *v)
d862e546
LC
208{
209 if (v == SEQ_START_TOKEN) {
210 seq_puts(seq, IPV6_SEQ_DGRAM_HEADER);
211 } else {
212 int bucket = ((struct ping_iter_state *) seq->private)->bucket;
213 struct inet_sock *inet = inet_sk(v);
214 __u16 srcp = ntohs(inet->inet_sport);
215 __u16 destp = ntohs(inet->inet_dport);
216 ip6_dgram_sock_seq_show(seq, v, srcp, destp, bucket);
217 }
218 return 0;
219}
220
221static struct ping_seq_afinfo ping_v6_seq_afinfo = {
222 .name = "icmp6",
223 .family = AF_INET6,
224 .seq_fops = &ping_seq_fops,
225 .seq_ops = {
226 .start = ping_v6_seq_start,
227 .show = ping_v6_seq_show,
228 .next = ping_seq_next,
229 .stop = ping_seq_stop,
230 },
231};
232
233static int __net_init ping_v6_proc_init_net(struct net *net)
234{
235 return ping_proc_register(net, &ping_v6_seq_afinfo);
236}
237
238static void __net_init ping_v6_proc_exit_net(struct net *net)
239{
240 return ping_proc_unregister(net, &ping_v6_seq_afinfo);
241}
242
243static struct pernet_operations ping_v6_net_ops = {
244 .init = ping_v6_proc_init_net,
245 .exit = ping_v6_proc_exit_net,
246};
247#endif
248
249int __init pingv6_init(void)
250{
251#ifdef CONFIG_PROC_FS
252 int ret = register_pernet_subsys(&ping_v6_net_ops);
253 if (ret)
254 return ret;
255#endif
256 pingv6_ops.ipv6_recv_error = ipv6_recv_error;
257 pingv6_ops.ip6_datagram_recv_ctl = ip6_datagram_recv_ctl;
258 pingv6_ops.icmpv6_err_convert = icmpv6_err_convert;
259 pingv6_ops.ipv6_icmp_error = ipv6_icmp_error;
260 pingv6_ops.ipv6_chk_addr = ipv6_chk_addr;
261 return inet6_register_protosw(&pingv6_protosw);
262}
263
264/* This never gets called because it's not possible to unload the ipv6 module,
265 * but just in case.
266 */
267void pingv6_exit(void)
268{
269 pingv6_ops.ipv6_recv_error = dummy_ipv6_recv_error;
270 pingv6_ops.ip6_datagram_recv_ctl = dummy_ip6_datagram_recv_ctl;
271 pingv6_ops.icmpv6_err_convert = dummy_icmpv6_err_convert;
272 pingv6_ops.ipv6_icmp_error = dummy_ipv6_icmp_error;
273 pingv6_ops.ipv6_chk_addr = dummy_ipv6_chk_addr;
274#ifdef CONFIG_PROC_FS
275 unregister_pernet_subsys(&ping_v6_net_ops);
276#endif
277 inet6_unregister_protosw(&pingv6_protosw);
278}
This page took 0.078972 seconds and 5 git commands to generate.