br_mdb.c 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481
  1. #include <linux/err.h>
  2. #include <linux/igmp.h>
  3. #include <linux/kernel.h>
  4. #include <linux/netdevice.h>
  5. #include <linux/rculist.h>
  6. #include <linux/skbuff.h>
  7. #include <linux/if_ether.h>
  8. #include <net/ip.h>
  9. #include <net/netlink.h>
  10. #if IS_ENABLED(CONFIG_IPV6)
  11. #include <net/ipv6.h>
  12. #endif
  13. #include "br_private.h"
  14. static int br_rports_fill_info(struct sk_buff *skb, struct netlink_callback *cb,
  15. struct net_device *dev)
  16. {
  17. struct net_bridge *br = netdev_priv(dev);
  18. struct net_bridge_port *p;
  19. struct hlist_node *n;
  20. struct nlattr *nest;
  21. if (!br->multicast_router || hlist_empty(&br->router_list))
  22. return 0;
  23. nest = nla_nest_start(skb, MDBA_ROUTER);
  24. if (nest == NULL)
  25. return -EMSGSIZE;
  26. hlist_for_each_entry_rcu(p, n, &br->router_list, rlist) {
  27. if (p && nla_put_u32(skb, MDBA_ROUTER_PORT, p->dev->ifindex))
  28. goto fail;
  29. }
  30. nla_nest_end(skb, nest);
  31. return 0;
  32. fail:
  33. nla_nest_cancel(skb, nest);
  34. return -EMSGSIZE;
  35. }
  36. static int br_mdb_fill_info(struct sk_buff *skb, struct netlink_callback *cb,
  37. struct net_device *dev)
  38. {
  39. struct net_bridge *br = netdev_priv(dev);
  40. struct net_bridge_mdb_htable *mdb;
  41. struct nlattr *nest, *nest2;
  42. int i, err = 0;
  43. int idx = 0, s_idx = cb->args[1];
  44. if (br->multicast_disabled)
  45. return 0;
  46. mdb = rcu_dereference(br->mdb);
  47. if (!mdb)
  48. return 0;
  49. nest = nla_nest_start(skb, MDBA_MDB);
  50. if (nest == NULL)
  51. return -EMSGSIZE;
  52. for (i = 0; i < mdb->max; i++) {
  53. struct hlist_node *h;
  54. struct net_bridge_mdb_entry *mp;
  55. struct net_bridge_port_group *p, **pp;
  56. struct net_bridge_port *port;
  57. hlist_for_each_entry_rcu(mp, h, &mdb->mhash[i], hlist[mdb->ver]) {
  58. if (idx < s_idx)
  59. goto skip;
  60. nest2 = nla_nest_start(skb, MDBA_MDB_ENTRY);
  61. if (nest2 == NULL) {
  62. err = -EMSGSIZE;
  63. goto out;
  64. }
  65. for (pp = &mp->ports;
  66. (p = rcu_dereference(*pp)) != NULL;
  67. pp = &p->next) {
  68. port = p->port;
  69. if (port) {
  70. struct br_mdb_entry e;
  71. e.ifindex = port->dev->ifindex;
  72. e.addr.u.ip4 = p->addr.u.ip4;
  73. #if IS_ENABLED(CONFIG_IPV6)
  74. e.addr.u.ip6 = p->addr.u.ip6;
  75. #endif
  76. e.addr.proto = p->addr.proto;
  77. if (nla_put(skb, MDBA_MDB_ENTRY_INFO, sizeof(e), &e)) {
  78. nla_nest_cancel(skb, nest2);
  79. err = -EMSGSIZE;
  80. goto out;
  81. }
  82. }
  83. }
  84. nla_nest_end(skb, nest2);
  85. skip:
  86. idx++;
  87. }
  88. }
  89. out:
  90. cb->args[1] = idx;
  91. nla_nest_end(skb, nest);
  92. return err;
  93. }
  94. static int br_mdb_dump(struct sk_buff *skb, struct netlink_callback *cb)
  95. {
  96. struct net_device *dev;
  97. struct net *net = sock_net(skb->sk);
  98. struct nlmsghdr *nlh = NULL;
  99. int idx = 0, s_idx;
  100. s_idx = cb->args[0];
  101. rcu_read_lock();
  102. /* In theory this could be wrapped to 0... */
  103. cb->seq = net->dev_base_seq + br_mdb_rehash_seq;
  104. for_each_netdev_rcu(net, dev) {
  105. if (dev->priv_flags & IFF_EBRIDGE) {
  106. struct br_port_msg *bpm;
  107. if (idx < s_idx)
  108. goto skip;
  109. nlh = nlmsg_put(skb, NETLINK_CB(cb->skb).portid,
  110. cb->nlh->nlmsg_seq, RTM_GETMDB,
  111. sizeof(*bpm), NLM_F_MULTI);
  112. if (nlh == NULL)
  113. break;
  114. bpm = nlmsg_data(nlh);
  115. bpm->ifindex = dev->ifindex;
  116. if (br_mdb_fill_info(skb, cb, dev) < 0)
  117. goto out;
  118. if (br_rports_fill_info(skb, cb, dev) < 0)
  119. goto out;
  120. cb->args[1] = 0;
  121. nlmsg_end(skb, nlh);
  122. skip:
  123. idx++;
  124. }
  125. }
  126. out:
  127. if (nlh)
  128. nlmsg_end(skb, nlh);
  129. rcu_read_unlock();
  130. cb->args[0] = idx;
  131. return skb->len;
  132. }
  133. static int nlmsg_populate_mdb_fill(struct sk_buff *skb,
  134. struct net_device *dev,
  135. struct br_mdb_entry *entry, u32 pid,
  136. u32 seq, int type, unsigned int flags)
  137. {
  138. struct nlmsghdr *nlh;
  139. struct br_port_msg *bpm;
  140. struct nlattr *nest, *nest2;
  141. nlh = nlmsg_put(skb, pid, seq, type, sizeof(*bpm), NLM_F_MULTI);
  142. if (!nlh)
  143. return -EMSGSIZE;
  144. bpm = nlmsg_data(nlh);
  145. bpm->family = AF_BRIDGE;
  146. bpm->ifindex = dev->ifindex;
  147. nest = nla_nest_start(skb, MDBA_MDB);
  148. if (nest == NULL)
  149. goto cancel;
  150. nest2 = nla_nest_start(skb, MDBA_MDB_ENTRY);
  151. if (nest2 == NULL)
  152. goto end;
  153. if (nla_put(skb, MDBA_MDB_ENTRY_INFO, sizeof(*entry), entry))
  154. goto end;
  155. nla_nest_end(skb, nest2);
  156. nla_nest_end(skb, nest);
  157. return nlmsg_end(skb, nlh);
  158. end:
  159. nla_nest_end(skb, nest);
  160. cancel:
  161. nlmsg_cancel(skb, nlh);
  162. return -EMSGSIZE;
  163. }
  164. static inline size_t rtnl_mdb_nlmsg_size(void)
  165. {
  166. return NLMSG_ALIGN(sizeof(struct br_port_msg))
  167. + nla_total_size(sizeof(struct br_mdb_entry));
  168. }
  169. static void __br_mdb_notify(struct net_device *dev, struct br_mdb_entry *entry,
  170. int type)
  171. {
  172. struct net *net = dev_net(dev);
  173. struct sk_buff *skb;
  174. int err = -ENOBUFS;
  175. skb = nlmsg_new(rtnl_mdb_nlmsg_size(), GFP_ATOMIC);
  176. if (!skb)
  177. goto errout;
  178. err = nlmsg_populate_mdb_fill(skb, dev, entry, 0, 0, type, NTF_SELF);
  179. if (err < 0) {
  180. kfree_skb(skb);
  181. goto errout;
  182. }
  183. rtnl_notify(skb, net, 0, RTNLGRP_MDB, NULL, GFP_ATOMIC);
  184. return;
  185. errout:
  186. rtnl_set_sk_err(net, RTNLGRP_MDB, err);
  187. }
  188. void br_mdb_notify(struct net_device *dev, struct net_bridge_port *port,
  189. struct br_ip *group, int type)
  190. {
  191. struct br_mdb_entry entry;
  192. entry.ifindex = port->dev->ifindex;
  193. entry.addr.proto = group->proto;
  194. entry.addr.u.ip4 = group->u.ip4;
  195. #if IS_ENABLED(CONFIG_IPV6)
  196. entry.addr.u.ip6 = group->u.ip6;
  197. #endif
  198. __br_mdb_notify(dev, &entry, type);
  199. }
  200. static bool is_valid_mdb_entry(struct br_mdb_entry *entry)
  201. {
  202. if (entry->ifindex == 0)
  203. return false;
  204. if (entry->addr.proto == htons(ETH_P_IP)) {
  205. if (!ipv4_is_multicast(entry->addr.u.ip4))
  206. return false;
  207. if (ipv4_is_local_multicast(entry->addr.u.ip4))
  208. return false;
  209. #if IS_ENABLED(CONFIG_IPV6)
  210. } else if (entry->addr.proto == htons(ETH_P_IPV6)) {
  211. if (!ipv6_is_transient_multicast(&entry->addr.u.ip6))
  212. return false;
  213. #endif
  214. } else
  215. return false;
  216. return true;
  217. }
  218. static int br_mdb_parse(struct sk_buff *skb, struct nlmsghdr *nlh,
  219. struct net_device **pdev, struct br_mdb_entry **pentry)
  220. {
  221. struct net *net = sock_net(skb->sk);
  222. struct br_mdb_entry *entry;
  223. struct br_port_msg *bpm;
  224. struct nlattr *tb[MDBA_SET_ENTRY_MAX+1];
  225. struct net_device *dev;
  226. int err;
  227. if (!capable(CAP_NET_ADMIN))
  228. return -EPERM;
  229. err = nlmsg_parse(nlh, sizeof(*bpm), tb, MDBA_SET_ENTRY, NULL);
  230. if (err < 0)
  231. return err;
  232. bpm = nlmsg_data(nlh);
  233. if (bpm->ifindex == 0) {
  234. pr_info("PF_BRIDGE: br_mdb_parse() with invalid ifindex\n");
  235. return -EINVAL;
  236. }
  237. dev = __dev_get_by_index(net, bpm->ifindex);
  238. if (dev == NULL) {
  239. pr_info("PF_BRIDGE: br_mdb_parse() with unknown ifindex\n");
  240. return -ENODEV;
  241. }
  242. if (!(dev->priv_flags & IFF_EBRIDGE)) {
  243. pr_info("PF_BRIDGE: br_mdb_parse() with non-bridge\n");
  244. return -EOPNOTSUPP;
  245. }
  246. *pdev = dev;
  247. if (!tb[MDBA_SET_ENTRY] ||
  248. nla_len(tb[MDBA_SET_ENTRY]) != sizeof(struct br_mdb_entry)) {
  249. pr_info("PF_BRIDGE: br_mdb_parse() with invalid attr\n");
  250. return -EINVAL;
  251. }
  252. entry = nla_data(tb[MDBA_SET_ENTRY]);
  253. if (!is_valid_mdb_entry(entry)) {
  254. pr_info("PF_BRIDGE: br_mdb_parse() with invalid entry\n");
  255. return -EINVAL;
  256. }
  257. *pentry = entry;
  258. return 0;
  259. }
  260. static int br_mdb_add_group(struct net_bridge *br, struct net_bridge_port *port,
  261. struct br_ip *group)
  262. {
  263. struct net_bridge_mdb_entry *mp;
  264. struct net_bridge_port_group *p;
  265. struct net_bridge_port_group __rcu **pp;
  266. struct net_bridge_mdb_htable *mdb;
  267. int err;
  268. mdb = mlock_dereference(br->mdb, br);
  269. mp = br_mdb_ip_get(mdb, group);
  270. if (!mp) {
  271. mp = br_multicast_new_group(br, port, group);
  272. err = PTR_ERR(mp);
  273. if (IS_ERR(mp))
  274. return err;
  275. }
  276. for (pp = &mp->ports;
  277. (p = mlock_dereference(*pp, br)) != NULL;
  278. pp = &p->next) {
  279. if (p->port == port)
  280. return -EEXIST;
  281. if ((unsigned long)p->port < (unsigned long)port)
  282. break;
  283. }
  284. p = br_multicast_new_port_group(port, group, *pp);
  285. if (unlikely(!p))
  286. return -ENOMEM;
  287. rcu_assign_pointer(*pp, p);
  288. br_mdb_notify(br->dev, port, group, RTM_NEWMDB);
  289. return 0;
  290. }
  291. static int __br_mdb_add(struct net *net, struct net_bridge *br,
  292. struct br_mdb_entry *entry)
  293. {
  294. struct br_ip ip;
  295. struct net_device *dev;
  296. struct net_bridge_port *p;
  297. int ret;
  298. if (!netif_running(br->dev) || br->multicast_disabled)
  299. return -EINVAL;
  300. dev = __dev_get_by_index(net, entry->ifindex);
  301. if (!dev)
  302. return -ENODEV;
  303. p = br_port_get_rtnl(dev);
  304. if (!p || p->br != br || p->state == BR_STATE_DISABLED)
  305. return -EINVAL;
  306. ip.proto = entry->addr.proto;
  307. if (ip.proto == htons(ETH_P_IP))
  308. ip.u.ip4 = entry->addr.u.ip4;
  309. #if IS_ENABLED(CONFIG_IPV6)
  310. else
  311. ip.u.ip6 = entry->addr.u.ip6;
  312. #endif
  313. spin_lock_bh(&br->multicast_lock);
  314. ret = br_mdb_add_group(br, p, &ip);
  315. spin_unlock_bh(&br->multicast_lock);
  316. return ret;
  317. }
  318. static int br_mdb_add(struct sk_buff *skb, struct nlmsghdr *nlh, void *arg)
  319. {
  320. struct net *net = sock_net(skb->sk);
  321. struct br_mdb_entry *entry;
  322. struct net_device *dev;
  323. struct net_bridge *br;
  324. int err;
  325. err = br_mdb_parse(skb, nlh, &dev, &entry);
  326. if (err < 0)
  327. return err;
  328. br = netdev_priv(dev);
  329. err = __br_mdb_add(net, br, entry);
  330. if (!err)
  331. __br_mdb_notify(dev, entry, RTM_NEWMDB);
  332. return err;
  333. }
  334. static int __br_mdb_del(struct net_bridge *br, struct br_mdb_entry *entry)
  335. {
  336. struct net_bridge_mdb_htable *mdb;
  337. struct net_bridge_mdb_entry *mp;
  338. struct net_bridge_port_group *p;
  339. struct net_bridge_port_group __rcu **pp;
  340. struct br_ip ip;
  341. int err = -EINVAL;
  342. if (!netif_running(br->dev) || br->multicast_disabled)
  343. return -EINVAL;
  344. if (timer_pending(&br->multicast_querier_timer))
  345. return -EBUSY;
  346. ip.proto = entry->addr.proto;
  347. if (ip.proto == htons(ETH_P_IP))
  348. ip.u.ip4 = entry->addr.u.ip4;
  349. #if IS_ENABLED(CONFIG_IPV6)
  350. else
  351. ip.u.ip6 = entry->addr.u.ip6;
  352. #endif
  353. spin_lock_bh(&br->multicast_lock);
  354. mdb = mlock_dereference(br->mdb, br);
  355. mp = br_mdb_ip_get(mdb, &ip);
  356. if (!mp)
  357. goto unlock;
  358. for (pp = &mp->ports;
  359. (p = mlock_dereference(*pp, br)) != NULL;
  360. pp = &p->next) {
  361. if (!p->port || p->port->dev->ifindex != entry->ifindex)
  362. continue;
  363. if (p->port->state == BR_STATE_DISABLED)
  364. goto unlock;
  365. rcu_assign_pointer(*pp, p->next);
  366. hlist_del_init(&p->mglist);
  367. del_timer(&p->timer);
  368. call_rcu_bh(&p->rcu, br_multicast_free_pg);
  369. err = 0;
  370. if (!mp->ports && !mp->mglist &&
  371. netif_running(br->dev))
  372. mod_timer(&mp->timer, jiffies);
  373. break;
  374. }
  375. unlock:
  376. spin_unlock_bh(&br->multicast_lock);
  377. return err;
  378. }
  379. static int br_mdb_del(struct sk_buff *skb, struct nlmsghdr *nlh, void *arg)
  380. {
  381. struct net_device *dev;
  382. struct br_mdb_entry *entry;
  383. struct net_bridge *br;
  384. int err;
  385. err = br_mdb_parse(skb, nlh, &dev, &entry);
  386. if (err < 0)
  387. return err;
  388. br = netdev_priv(dev);
  389. err = __br_mdb_del(br, entry);
  390. if (!err)
  391. __br_mdb_notify(dev, entry, RTM_DELMDB);
  392. return err;
  393. }
  394. void br_mdb_init(void)
  395. {
  396. rtnl_register(PF_BRIDGE, RTM_GETMDB, NULL, br_mdb_dump, NULL);
  397. rtnl_register(PF_BRIDGE, RTM_NEWMDB, br_mdb_add, NULL, NULL);
  398. rtnl_register(PF_BRIDGE, RTM_DELMDB, br_mdb_del, NULL, NULL);
  399. }