mld6.c revision 1.87 1 1.87 ozaki /* $NetBSD: mld6.c,v 1.87 2017/03/02 09:16:46 ozaki-r Exp $ */
2 1.13 itojun /* $KAME: mld6.c,v 1.25 2001/01/16 14:14:18 itojun Exp $ */
3 1.3 thorpej
4 1.2 itojun /*
5 1.2 itojun * Copyright (C) 1998 WIDE Project.
6 1.2 itojun * All rights reserved.
7 1.13 itojun *
8 1.2 itojun * Redistribution and use in source and binary forms, with or without
9 1.2 itojun * modification, are permitted provided that the following conditions
10 1.2 itojun * are met:
11 1.2 itojun * 1. Redistributions of source code must retain the above copyright
12 1.2 itojun * notice, this list of conditions and the following disclaimer.
13 1.2 itojun * 2. Redistributions in binary form must reproduce the above copyright
14 1.2 itojun * notice, this list of conditions and the following disclaimer in the
15 1.2 itojun * documentation and/or other materials provided with the distribution.
16 1.2 itojun * 3. Neither the name of the project nor the names of its contributors
17 1.2 itojun * may be used to endorse or promote products derived from this software
18 1.2 itojun * without specific prior written permission.
19 1.13 itojun *
20 1.2 itojun * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
21 1.2 itojun * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 1.2 itojun * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 1.2 itojun * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
24 1.2 itojun * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25 1.2 itojun * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26 1.2 itojun * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27 1.2 itojun * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28 1.2 itojun * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29 1.2 itojun * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
30 1.2 itojun * SUCH DAMAGE.
31 1.2 itojun */
32 1.2 itojun
33 1.2 itojun /*
34 1.2 itojun * Copyright (c) 1992, 1993
35 1.2 itojun * The Regents of the University of California. All rights reserved.
36 1.2 itojun *
37 1.2 itojun * This code is derived from software contributed to Berkeley by
38 1.2 itojun * Stephen Deering of Stanford University.
39 1.2 itojun *
40 1.2 itojun * Redistribution and use in source and binary forms, with or without
41 1.2 itojun * modification, are permitted provided that the following conditions
42 1.2 itojun * are met:
43 1.2 itojun * 1. Redistributions of source code must retain the above copyright
44 1.2 itojun * notice, this list of conditions and the following disclaimer.
45 1.2 itojun * 2. Redistributions in binary form must reproduce the above copyright
46 1.2 itojun * notice, this list of conditions and the following disclaimer in the
47 1.2 itojun * documentation and/or other materials provided with the distribution.
48 1.23 agc * 3. Neither the name of the University nor the names of its contributors
49 1.23 agc * may be used to endorse or promote products derived from this software
50 1.23 agc * without specific prior written permission.
51 1.23 agc *
52 1.23 agc * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
53 1.23 agc * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
54 1.23 agc * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
55 1.23 agc * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
56 1.23 agc * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
57 1.23 agc * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
58 1.23 agc * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
59 1.23 agc * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
60 1.23 agc * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
61 1.23 agc * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
62 1.23 agc * SUCH DAMAGE.
63 1.23 agc *
64 1.23 agc * @(#)igmp.c 8.1 (Berkeley) 7/19/93
65 1.23 agc */
66 1.23 agc
67 1.23 agc /*
68 1.23 agc * Copyright (c) 1988 Stephen Deering.
69 1.23 agc *
70 1.23 agc * This code is derived from software contributed to Berkeley by
71 1.23 agc * Stephen Deering of Stanford University.
72 1.23 agc *
73 1.23 agc * Redistribution and use in source and binary forms, with or without
74 1.23 agc * modification, are permitted provided that the following conditions
75 1.23 agc * are met:
76 1.23 agc * 1. Redistributions of source code must retain the above copyright
77 1.23 agc * notice, this list of conditions and the following disclaimer.
78 1.23 agc * 2. Redistributions in binary form must reproduce the above copyright
79 1.23 agc * notice, this list of conditions and the following disclaimer in the
80 1.23 agc * documentation and/or other materials provided with the distribution.
81 1.2 itojun * 3. All advertising materials mentioning features or use of this software
82 1.2 itojun * must display the following acknowledgement:
83 1.2 itojun * This product includes software developed by the University of
84 1.2 itojun * California, Berkeley and its contributors.
85 1.2 itojun * 4. Neither the name of the University nor the names of its contributors
86 1.2 itojun * may be used to endorse or promote products derived from this software
87 1.2 itojun * without specific prior written permission.
88 1.2 itojun *
89 1.2 itojun * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
90 1.2 itojun * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
91 1.2 itojun * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
92 1.2 itojun * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
93 1.2 itojun * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
94 1.2 itojun * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
95 1.2 itojun * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
96 1.2 itojun * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
97 1.2 itojun * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
98 1.2 itojun * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
99 1.2 itojun * SUCH DAMAGE.
100 1.2 itojun *
101 1.2 itojun * @(#)igmp.c 8.1 (Berkeley) 7/19/93
102 1.2 itojun */
103 1.16 lukem
104 1.16 lukem #include <sys/cdefs.h>
105 1.87 ozaki __KERNEL_RCSID(0, "$NetBSD: mld6.c,v 1.87 2017/03/02 09:16:46 ozaki-r Exp $");
106 1.2 itojun
107 1.63 pooka #ifdef _KERNEL_OPT
108 1.2 itojun #include "opt_inet.h"
109 1.75 knakahar #include "opt_net_mpsafe.h"
110 1.63 pooka #endif
111 1.2 itojun
112 1.2 itojun #include <sys/param.h>
113 1.2 itojun #include <sys/systm.h>
114 1.2 itojun #include <sys/mbuf.h>
115 1.2 itojun #include <sys/socket.h>
116 1.45 ad #include <sys/socketvar.h>
117 1.2 itojun #include <sys/syslog.h>
118 1.31 rpaulo #include <sys/sysctl.h>
119 1.31 rpaulo #include <sys/kernel.h>
120 1.31 rpaulo #include <sys/callout.h>
121 1.55 tls #include <sys/cprng.h>
122 1.85 ozaki #include <sys/rwlock.h>
123 1.2 itojun
124 1.2 itojun #include <net/if.h>
125 1.2 itojun
126 1.2 itojun #include <netinet/in.h>
127 1.2 itojun #include <netinet/in_var.h>
128 1.31 rpaulo #include <netinet6/in6_var.h>
129 1.10 itojun #include <netinet/ip6.h>
130 1.2 itojun #include <netinet6/ip6_var.h>
131 1.29 rpaulo #include <netinet6/scope6_var.h>
132 1.10 itojun #include <netinet/icmp6.h>
133 1.44 thorpej #include <netinet6/icmp6_private.h>
134 1.2 itojun #include <netinet6/mld6_var.h>
135 1.2 itojun
136 1.7 itojun #include <net/net_osdep.h>
137 1.7 itojun
138 1.31 rpaulo
139 1.85 ozaki static krwlock_t in6_multilock __cacheline_aligned;
140 1.85 ozaki
141 1.31 rpaulo /*
142 1.2 itojun * Protocol constants
143 1.2 itojun */
144 1.2 itojun
145 1.2 itojun /*
146 1.2 itojun * time between repetitions of a node's initial report of interest in a
147 1.2 itojun * multicast address(in seconds)
148 1.2 itojun */
149 1.22 itojun #define MLD_UNSOLICITED_REPORT_INTERVAL 10
150 1.2 itojun
151 1.2 itojun static struct ip6_pktopts ip6_opts;
152 1.2 itojun
153 1.31 rpaulo static void mld_start_listening(struct in6_multi *);
154 1.31 rpaulo static void mld_stop_listening(struct in6_multi *);
155 1.31 rpaulo
156 1.31 rpaulo static struct mld_hdr * mld_allocbuf(struct mbuf **, int, struct in6_multi *,
157 1.31 rpaulo int);
158 1.31 rpaulo static void mld_sendpkt(struct in6_multi *, int, const struct in6_addr *);
159 1.31 rpaulo static void mld_starttimer(struct in6_multi *);
160 1.31 rpaulo static void mld_stoptimer(struct in6_multi *);
161 1.31 rpaulo static u_long mld_timerresid(struct in6_multi *);
162 1.2 itojun
163 1.85 ozaki static void in6m_ref(struct in6_multi *);
164 1.85 ozaki static void in6m_unref(struct in6_multi *);
165 1.85 ozaki static void in6m_destroy(struct in6_multi *);
166 1.85 ozaki
167 1.2 itojun void
168 1.42 matt mld_init(void)
169 1.2 itojun {
170 1.2 itojun static u_int8_t hbh_buf[8];
171 1.2 itojun struct ip6_hbh *hbh = (struct ip6_hbh *)hbh_buf;
172 1.2 itojun u_int16_t rtalert_code = htons((u_int16_t)IP6OPT_RTALERT_MLD);
173 1.2 itojun
174 1.2 itojun /* ip6h_nxt will be fill in later */
175 1.11 itojun hbh->ip6h_len = 0; /* (8 >> 3) - 1 */
176 1.2 itojun
177 1.2 itojun /* XXX: grotty hard coding... */
178 1.2 itojun hbh_buf[2] = IP6OPT_PADN; /* 2 byte padding */
179 1.2 itojun hbh_buf[3] = 0;
180 1.2 itojun hbh_buf[4] = IP6OPT_RTALERT;
181 1.2 itojun hbh_buf[5] = IP6OPT_RTALERT_LEN - 2;
182 1.50 tsutsui memcpy(&hbh_buf[6], (void *)&rtalert_code, sizeof(u_int16_t));
183 1.2 itojun
184 1.2 itojun ip6_opts.ip6po_hbh = hbh;
185 1.2 itojun /* We will specify the hoplimit by a multicast option. */
186 1.2 itojun ip6_opts.ip6po_hlim = -1;
187 1.62 roy ip6_opts.ip6po_prefer_tempaddr = IP6PO_TEMPADDR_NOTPREFER;
188 1.85 ozaki
189 1.85 ozaki rw_init(&in6_multilock);
190 1.2 itojun }
191 1.2 itojun
192 1.31 rpaulo static void
193 1.38 christos mld_starttimer(struct in6_multi *in6m)
194 1.31 rpaulo {
195 1.31 rpaulo struct timeval now;
196 1.31 rpaulo
197 1.85 ozaki KASSERT(rw_write_held(&in6_multilock));
198 1.61 ozaki KASSERT(in6m->in6m_timer != IN6M_TIMER_UNDEF);
199 1.61 ozaki
200 1.31 rpaulo microtime(&now);
201 1.31 rpaulo in6m->in6m_timer_expire.tv_sec = now.tv_sec + in6m->in6m_timer / hz;
202 1.31 rpaulo in6m->in6m_timer_expire.tv_usec = now.tv_usec +
203 1.31 rpaulo (in6m->in6m_timer % hz) * (1000000 / hz);
204 1.31 rpaulo if (in6m->in6m_timer_expire.tv_usec > 1000000) {
205 1.31 rpaulo in6m->in6m_timer_expire.tv_sec++;
206 1.31 rpaulo in6m->in6m_timer_expire.tv_usec -= 1000000;
207 1.31 rpaulo }
208 1.31 rpaulo
209 1.31 rpaulo /* start or restart the timer */
210 1.41 joerg callout_schedule(&in6m->in6m_timer_ch, in6m->in6m_timer);
211 1.31 rpaulo }
212 1.31 rpaulo
213 1.85 ozaki /*
214 1.85 ozaki * mld_stoptimer releases in6_multilock when calling callout_halt.
215 1.85 ozaki * The caller must ensure in6m won't be freed while releasing the lock.
216 1.85 ozaki */
217 1.31 rpaulo static void
218 1.38 christos mld_stoptimer(struct in6_multi *in6m)
219 1.31 rpaulo {
220 1.85 ozaki
221 1.85 ozaki KASSERT(rw_write_held(&in6_multilock));
222 1.85 ozaki
223 1.31 rpaulo if (in6m->in6m_timer == IN6M_TIMER_UNDEF)
224 1.31 rpaulo return;
225 1.31 rpaulo
226 1.85 ozaki rw_exit(&in6_multilock);
227 1.85 ozaki
228 1.85 ozaki if (mutex_owned(softnet_lock))
229 1.85 ozaki callout_halt(&in6m->in6m_timer_ch, softnet_lock);
230 1.85 ozaki else
231 1.85 ozaki callout_halt(&in6m->in6m_timer_ch, NULL);
232 1.85 ozaki
233 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
234 1.31 rpaulo
235 1.31 rpaulo in6m->in6m_timer = IN6M_TIMER_UNDEF;
236 1.31 rpaulo }
237 1.31 rpaulo
238 1.31 rpaulo static void
239 1.41 joerg mld_timeo(void *arg)
240 1.31 rpaulo {
241 1.41 joerg struct in6_multi *in6m = arg;
242 1.45 ad
243 1.85 ozaki KASSERT(in6m->in6m_refcount > 0);
244 1.85 ozaki
245 1.85 ozaki #ifndef NET_MPSAFE
246 1.45 ad mutex_enter(softnet_lock);
247 1.45 ad KERNEL_LOCK(1, NULL);
248 1.85 ozaki #endif
249 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
250 1.61 ozaki if (in6m->in6m_timer == IN6M_TIMER_UNDEF)
251 1.61 ozaki goto out;
252 1.61 ozaki
253 1.31 rpaulo in6m->in6m_timer = IN6M_TIMER_UNDEF;
254 1.31 rpaulo
255 1.31 rpaulo switch (in6m->in6m_state) {
256 1.31 rpaulo case MLD_REPORTPENDING:
257 1.31 rpaulo mld_start_listening(in6m);
258 1.31 rpaulo break;
259 1.31 rpaulo default:
260 1.31 rpaulo mld_sendpkt(in6m, MLD_LISTENER_REPORT, NULL);
261 1.31 rpaulo break;
262 1.31 rpaulo }
263 1.31 rpaulo
264 1.61 ozaki out:
265 1.85 ozaki rw_exit(&in6_multilock);
266 1.85 ozaki #ifndef NET_MPSAFE
267 1.45 ad KERNEL_UNLOCK_ONE(NULL);
268 1.45 ad mutex_exit(softnet_lock);
269 1.85 ozaki #else
270 1.85 ozaki return;
271 1.85 ozaki #endif
272 1.31 rpaulo }
273 1.31 rpaulo
274 1.31 rpaulo static u_long
275 1.38 christos mld_timerresid(struct in6_multi *in6m)
276 1.31 rpaulo {
277 1.31 rpaulo struct timeval now, diff;
278 1.31 rpaulo
279 1.31 rpaulo microtime(&now);
280 1.31 rpaulo
281 1.31 rpaulo if (now.tv_sec > in6m->in6m_timer_expire.tv_sec ||
282 1.31 rpaulo (now.tv_sec == in6m->in6m_timer_expire.tv_sec &&
283 1.31 rpaulo now.tv_usec > in6m->in6m_timer_expire.tv_usec)) {
284 1.31 rpaulo return (0);
285 1.31 rpaulo }
286 1.31 rpaulo diff = in6m->in6m_timer_expire;
287 1.31 rpaulo diff.tv_sec -= now.tv_sec;
288 1.31 rpaulo diff.tv_usec -= now.tv_usec;
289 1.31 rpaulo if (diff.tv_usec < 0) {
290 1.31 rpaulo diff.tv_sec--;
291 1.31 rpaulo diff.tv_usec += 1000000;
292 1.31 rpaulo }
293 1.31 rpaulo
294 1.31 rpaulo /* return the remaining time in milliseconds */
295 1.47 adrianp return diff.tv_sec * 1000 + diff.tv_usec / 1000;
296 1.31 rpaulo }
297 1.31 rpaulo
298 1.31 rpaulo static void
299 1.38 christos mld_start_listening(struct in6_multi *in6m)
300 1.2 itojun {
301 1.29 rpaulo struct in6_addr all_in6;
302 1.29 rpaulo
303 1.85 ozaki KASSERT(rw_write_held(&in6_multilock));
304 1.85 ozaki
305 1.2 itojun /*
306 1.11 itojun * RFC2710 page 10:
307 1.2 itojun * The node never sends a Report or Done for the link-scope all-nodes
308 1.2 itojun * address.
309 1.2 itojun * MLD messages are never sent for multicast addresses whose scope is 0
310 1.2 itojun * (reserved) or 1 (node-local).
311 1.2 itojun */
312 1.29 rpaulo all_in6 = in6addr_linklocal_allnodes;
313 1.29 rpaulo if (in6_setscope(&all_in6, in6m->in6m_ifp, NULL)) {
314 1.29 rpaulo /* XXX: this should not happen! */
315 1.29 rpaulo in6m->in6m_timer = 0;
316 1.29 rpaulo in6m->in6m_state = MLD_OTHERLISTENER;
317 1.29 rpaulo }
318 1.29 rpaulo if (IN6_ARE_ADDR_EQUAL(&in6m->in6m_addr, &all_in6) ||
319 1.2 itojun IPV6_ADDR_MC_SCOPE(&in6m->in6m_addr) < IPV6_ADDR_SCOPE_LINKLOCAL) {
320 1.31 rpaulo in6m->in6m_timer = IN6M_TIMER_UNDEF;
321 1.22 itojun in6m->in6m_state = MLD_OTHERLISTENER;
322 1.2 itojun } else {
323 1.31 rpaulo mld_sendpkt(in6m, MLD_LISTENER_REPORT, NULL);
324 1.55 tls in6m->in6m_timer = cprng_fast32() %
325 1.31 rpaulo (MLD_UNSOLICITED_REPORT_INTERVAL * hz);
326 1.22 itojun in6m->in6m_state = MLD_IREPORTEDLAST;
327 1.31 rpaulo
328 1.31 rpaulo mld_starttimer(in6m);
329 1.2 itojun }
330 1.2 itojun }
331 1.2 itojun
332 1.31 rpaulo static void
333 1.38 christos mld_stop_listening(struct in6_multi *in6m)
334 1.2 itojun {
335 1.29 rpaulo struct in6_addr allnode, allrouter;
336 1.29 rpaulo
337 1.85 ozaki KASSERT(rw_lock_held(&in6_multilock));
338 1.85 ozaki
339 1.29 rpaulo allnode = in6addr_linklocal_allnodes;
340 1.29 rpaulo if (in6_setscope(&allnode, in6m->in6m_ifp, NULL)) {
341 1.29 rpaulo /* XXX: this should not happen! */
342 1.29 rpaulo return;
343 1.29 rpaulo }
344 1.29 rpaulo allrouter = in6addr_linklocal_allrouters;
345 1.29 rpaulo if (in6_setscope(&allrouter, in6m->in6m_ifp, NULL)) {
346 1.29 rpaulo /* XXX impossible */
347 1.29 rpaulo return;
348 1.29 rpaulo }
349 1.2 itojun
350 1.22 itojun if (in6m->in6m_state == MLD_IREPORTEDLAST &&
351 1.29 rpaulo (!IN6_ARE_ADDR_EQUAL(&in6m->in6m_addr, &allnode)) &&
352 1.29 rpaulo IPV6_ADDR_MC_SCOPE(&in6m->in6m_addr) >
353 1.29 rpaulo IPV6_ADDR_SCOPE_INTFACELOCAL) {
354 1.31 rpaulo mld_sendpkt(in6m, MLD_LISTENER_DONE, &allrouter);
355 1.29 rpaulo }
356 1.2 itojun }
357 1.2 itojun
358 1.2 itojun void
359 1.38 christos mld_input(struct mbuf *m, int off)
360 1.2 itojun {
361 1.52 dholland struct ip6_hdr *ip6;
362 1.22 itojun struct mld_hdr *mldh;
363 1.66 ozaki struct ifnet *ifp;
364 1.31 rpaulo struct in6_multi *in6m = NULL;
365 1.29 rpaulo struct in6_addr mld_addr, all_in6;
366 1.47 adrianp u_long timer = 0; /* timer value in the MLD query header */
367 1.83 ozaki struct psref psref;
368 1.2 itojun
369 1.83 ozaki ifp = m_get_rcvif_psref(m, &psref);
370 1.81 ozaki if (__predict_false(ifp == NULL))
371 1.81 ozaki goto out;
372 1.22 itojun IP6_EXTHDR_GET(mldh, struct mld_hdr *, m, off, sizeof(*mldh));
373 1.13 itojun if (mldh == NULL) {
374 1.44 thorpej ICMP6_STATINC(ICMP6_STAT_TOOSHORT);
375 1.66 ozaki goto out_nodrop;
376 1.13 itojun }
377 1.13 itojun
378 1.2 itojun /* source address validation */
379 1.13 itojun ip6 = mtod(m, struct ip6_hdr *);/* in case mpullup */
380 1.2 itojun if (!IN6_IS_ADDR_LINKLOCAL(&ip6->ip6_src)) {
381 1.31 rpaulo /*
382 1.31 rpaulo * RFC3590 allows the IPv6 unspecified address as the source
383 1.31 rpaulo * address of MLD report and done messages. However, as this
384 1.31 rpaulo * same document says, this special rule is for snooping
385 1.31 rpaulo * switches and the RFC requires routers to discard MLD packets
386 1.31 rpaulo * with the unspecified source address. The RFC only talks
387 1.31 rpaulo * about hosts receiving an MLD query or report in Security
388 1.31 rpaulo * Considerations, but this is probably the correct intention.
389 1.31 rpaulo * RFC3590 does not talk about other cases than link-local and
390 1.31 rpaulo * the unspecified source addresses, but we believe the same
391 1.31 rpaulo * rule should be applied.
392 1.31 rpaulo * As a result, we only allow link-local addresses as the
393 1.31 rpaulo * source address; otherwise, simply discard the packet.
394 1.31 rpaulo */
395 1.18 itojun #if 0
396 1.31 rpaulo /*
397 1.31 rpaulo * XXX: do not log in an input path to avoid log flooding,
398 1.31 rpaulo * though RFC3590 says "SHOULD log" if the source of a query
399 1.31 rpaulo * is the unspecified address.
400 1.31 rpaulo */
401 1.78 ryo char ip6bufs[INET6_ADDRSTRLEN];
402 1.78 ryo char ip6bufm[INET6_ADDRSTRLEN];
403 1.31 rpaulo log(LOG_INFO,
404 1.22 itojun "mld_input: src %s is not link-local (grp=%s)\n",
405 1.79 christos IN6_PRINT(ip6bufs,&ip6->ip6_src),
406 1.79 christos IN6_PRINT(ip6bufm, &mldh->mld_addr));
407 1.18 itojun #endif
408 1.66 ozaki goto out;
409 1.2 itojun }
410 1.2 itojun
411 1.2 itojun /*
412 1.29 rpaulo * make a copy for local work (in6_setscope() may modify the 1st arg)
413 1.29 rpaulo */
414 1.29 rpaulo mld_addr = mldh->mld_addr;
415 1.29 rpaulo if (in6_setscope(&mld_addr, ifp, NULL)) {
416 1.29 rpaulo /* XXX: this should not happen! */
417 1.66 ozaki goto out;
418 1.29 rpaulo }
419 1.29 rpaulo
420 1.29 rpaulo /*
421 1.31 rpaulo * In the MLD specification, there are 3 states and a flag.
422 1.2 itojun *
423 1.2 itojun * In Non-Listener state, we simply don't have a membership record.
424 1.2 itojun * In Delaying Listener state, our timer is running (in6m->in6m_timer)
425 1.31 rpaulo * In Idle Listener state, our timer is not running
426 1.31 rpaulo * (in6m->in6m_timer==IN6M_TIMER_UNDEF)
427 1.2 itojun *
428 1.22 itojun * The flag is in6m->in6m_state, it is set to MLD_OTHERLISTENER if
429 1.22 itojun * we have heard a report from another member, or MLD_IREPORTEDLAST
430 1.2 itojun * if we sent the last report.
431 1.2 itojun */
432 1.22 itojun switch (mldh->mld_type) {
433 1.74 ozaki case MLD_LISTENER_QUERY: {
434 1.85 ozaki struct in6_multi *next;
435 1.85 ozaki
436 1.7 itojun if (ifp->if_flags & IFF_LOOPBACK)
437 1.7 itojun break;
438 1.7 itojun
439 1.29 rpaulo if (!IN6_IS_ADDR_UNSPECIFIED(&mld_addr) &&
440 1.29 rpaulo !IN6_IS_ADDR_MULTICAST(&mld_addr))
441 1.7 itojun break; /* print error or log stat? */
442 1.29 rpaulo
443 1.29 rpaulo all_in6 = in6addr_linklocal_allnodes;
444 1.29 rpaulo if (in6_setscope(&all_in6, ifp, NULL)) {
445 1.29 rpaulo /* XXX: this should not happen! */
446 1.29 rpaulo break;
447 1.29 rpaulo }
448 1.2 itojun
449 1.7 itojun /*
450 1.11 itojun * - Start the timers in all of our membership records
451 1.11 itojun * that the query applies to for the interface on
452 1.11 itojun * which the query arrived excl. those that belong
453 1.11 itojun * to the "all-nodes" group (ff02::1).
454 1.11 itojun * - Restart any timer that is already running but has
455 1.30 rpaulo * a value longer than the requested timeout.
456 1.11 itojun * - Use the value specified in the query message as
457 1.11 itojun * the maximum timeout.
458 1.11 itojun */
459 1.31 rpaulo timer = ntohs(mldh->mld_maxdelay);
460 1.31 rpaulo
461 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
462 1.85 ozaki /*
463 1.85 ozaki * mld_stoptimer and mld_sendpkt release in6_multilock
464 1.85 ozaki * temporarily, so we have to prevent in6m from being freed
465 1.85 ozaki * while releasing the lock by having an extra reference to it.
466 1.85 ozaki *
467 1.85 ozaki * Also in6_purge_multi might remove items from the list of the
468 1.85 ozaki * ifp while releasing the lock. Fortunately in6_purge_multi is
469 1.85 ozaki * never executed as long as we have a psref of the ifp.
470 1.85 ozaki */
471 1.85 ozaki LIST_FOREACH_SAFE(in6m, &ifp->if_multiaddrs, in6m_entry, next) {
472 1.29 rpaulo if (IN6_ARE_ADDR_EQUAL(&in6m->in6m_addr, &all_in6) ||
473 1.7 itojun IPV6_ADDR_MC_SCOPE(&in6m->in6m_addr) <
474 1.7 itojun IPV6_ADDR_SCOPE_LINKLOCAL)
475 1.7 itojun continue;
476 1.2 itojun
477 1.31 rpaulo if (in6m->in6m_state == MLD_REPORTPENDING)
478 1.31 rpaulo continue; /* we are not yet ready */
479 1.31 rpaulo
480 1.31 rpaulo if (!IN6_IS_ADDR_UNSPECIFIED(&mld_addr) &&
481 1.31 rpaulo !IN6_ARE_ADDR_EQUAL(&mld_addr, &in6m->in6m_addr))
482 1.31 rpaulo continue;
483 1.31 rpaulo
484 1.31 rpaulo if (timer == 0) {
485 1.85 ozaki in6m_ref(in6m);
486 1.85 ozaki
487 1.31 rpaulo /* send a report immediately */
488 1.31 rpaulo mld_stoptimer(in6m);
489 1.31 rpaulo mld_sendpkt(in6m, MLD_LISTENER_REPORT, NULL);
490 1.31 rpaulo in6m->in6m_state = MLD_IREPORTEDLAST;
491 1.85 ozaki
492 1.85 ozaki in6m_unref(in6m); /* May free in6m */
493 1.31 rpaulo } else if (in6m->in6m_timer == IN6M_TIMER_UNDEF ||
494 1.47 adrianp mld_timerresid(in6m) > timer) {
495 1.47 adrianp in6m->in6m_timer =
496 1.55 tls 1 + (cprng_fast32() % timer) * hz / 1000;
497 1.31 rpaulo mld_starttimer(in6m);
498 1.7 itojun }
499 1.7 itojun }
500 1.85 ozaki rw_exit(&in6_multilock);
501 1.29 rpaulo break;
502 1.74 ozaki }
503 1.2 itojun
504 1.22 itojun case MLD_LISTENER_REPORT:
505 1.2 itojun /*
506 1.11 itojun * For fast leave to work, we have to know that we are the
507 1.11 itojun * last person to send a report for this group. Reports
508 1.11 itojun * can potentially get looped back if we are a multicast
509 1.11 itojun * router, so discard reports sourced by me.
510 1.11 itojun * Note that it is impossible to check IFF_LOOPBACK flag of
511 1.11 itojun * ifp for this purpose, since ip6_mloopback pass the physical
512 1.11 itojun * interface to looutput.
513 1.11 itojun */
514 1.7 itojun if (m->m_flags & M_LOOP) /* XXX: grotty flag, but efficient */
515 1.7 itojun break;
516 1.7 itojun
517 1.22 itojun if (!IN6_IS_ADDR_MULTICAST(&mldh->mld_addr))
518 1.7 itojun break;
519 1.7 itojun
520 1.7 itojun /*
521 1.11 itojun * If we belong to the group being reported, stop
522 1.11 itojun * our timer for that group.
523 1.11 itojun */
524 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
525 1.82 ozaki in6m = in6_lookup_multi(&mld_addr, ifp);
526 1.7 itojun if (in6m) {
527 1.85 ozaki in6m_ref(in6m);
528 1.31 rpaulo mld_stoptimer(in6m); /* transit to idle state */
529 1.22 itojun in6m->in6m_state = MLD_OTHERLISTENER; /* clear flag */
530 1.85 ozaki in6m_unref(in6m);
531 1.85 ozaki in6m = NULL; /* in6m might be freed */
532 1.7 itojun }
533 1.85 ozaki rw_exit(&in6_multilock);
534 1.7 itojun break;
535 1.7 itojun default: /* this is impossible */
536 1.18 itojun #if 0
537 1.19 itojun /*
538 1.19 itojun * this case should be impossible because of filtering in
539 1.19 itojun * icmp6_input(). But we explicitly disabled this part
540 1.19 itojun * just in case.
541 1.19 itojun */
542 1.31 rpaulo log(LOG_ERR, "mld_input: illegal type(%d)", mldh->mld_type);
543 1.18 itojun #endif
544 1.7 itojun break;
545 1.2 itojun }
546 1.11 itojun
547 1.66 ozaki out:
548 1.11 itojun m_freem(m);
549 1.66 ozaki out_nodrop:
550 1.83 ozaki m_put_rcvif_psref(ifp, &psref);
551 1.2 itojun }
552 1.2 itojun
553 1.85 ozaki /*
554 1.85 ozaki * XXX mld_sendpkt must be called with in6_multilock held and
555 1.85 ozaki * will release in6_multilock before calling ip6_output and
556 1.85 ozaki * returning to avoid locking against myself in ip6_output.
557 1.85 ozaki */
558 1.2 itojun static void
559 1.38 christos mld_sendpkt(struct in6_multi *in6m, int type,
560 1.38 christos const struct in6_addr *dst)
561 1.2 itojun {
562 1.31 rpaulo struct mbuf *mh;
563 1.22 itojun struct mld_hdr *mldh;
564 1.31 rpaulo struct ip6_hdr *ip6 = NULL;
565 1.2 itojun struct ip6_moptions im6o;
566 1.31 rpaulo struct in6_ifaddr *ia = NULL;
567 1.2 itojun struct ifnet *ifp = in6m->in6m_ifp;
568 1.19 itojun int ignflags;
569 1.74 ozaki struct psref psref;
570 1.74 ozaki int bound;
571 1.2 itojun
572 1.85 ozaki KASSERT(rw_write_held(&in6_multilock));
573 1.85 ozaki
574 1.2 itojun /*
575 1.2 itojun * At first, find a link local address on the outgoing interface
576 1.2 itojun * to use as the source address of the MLD packet.
577 1.19 itojun * We do not reject tentative addresses for MLD report to deal with
578 1.19 itojun * the case where we first join a link-local address.
579 1.2 itojun */
580 1.19 itojun ignflags = (IN6_IFF_NOTREADY|IN6_IFF_ANYCAST) & ~IN6_IFF_TENTATIVE;
581 1.74 ozaki bound = curlwp_bind();
582 1.74 ozaki ia = in6ifa_ifpforlinklocal_psref(ifp, ignflags, &psref);
583 1.74 ozaki if (ia == NULL) {
584 1.74 ozaki curlwp_bindx(bound);
585 1.2 itojun return;
586 1.74 ozaki }
587 1.74 ozaki if ((ia->ia6_flags & IN6_IFF_TENTATIVE)) {
588 1.74 ozaki ia6_release(ia, &psref);
589 1.19 itojun ia = NULL;
590 1.74 ozaki }
591 1.2 itojun
592 1.31 rpaulo /* Allocate two mbufs to store IPv6 header and MLD header */
593 1.31 rpaulo mldh = mld_allocbuf(&mh, sizeof(struct mld_hdr), in6m, type);
594 1.74 ozaki if (mldh == NULL) {
595 1.74 ozaki ia6_release(ia, &psref);
596 1.74 ozaki curlwp_bindx(bound);
597 1.2 itojun return;
598 1.74 ozaki }
599 1.2 itojun
600 1.31 rpaulo /* fill src/dst here */
601 1.31 rpaulo ip6 = mtod(mh, struct ip6_hdr *);
602 1.31 rpaulo ip6->ip6_src = ia ? ia->ia_addr.sin6_addr : in6addr_any;
603 1.31 rpaulo ip6->ip6_dst = dst ? *dst : in6m->in6m_addr;
604 1.74 ozaki ia6_release(ia, &psref);
605 1.74 ozaki curlwp_bindx(bound);
606 1.2 itojun
607 1.22 itojun mldh->mld_addr = in6m->in6m_addr;
608 1.29 rpaulo in6_clearscope(&mldh->mld_addr); /* XXX */
609 1.22 itojun mldh->mld_cksum = in6_cksum(mh, IPPROTO_ICMPV6, sizeof(struct ip6_hdr),
610 1.22 itojun sizeof(struct mld_hdr));
611 1.2 itojun
612 1.2 itojun /* construct multicast option */
613 1.31 rpaulo memset(&im6o, 0, sizeof(im6o));
614 1.68 ozaki im6o.im6o_multicast_if_index = if_get_index(ifp);
615 1.2 itojun im6o.im6o_multicast_hlim = 1;
616 1.2 itojun
617 1.2 itojun /*
618 1.2 itojun * Request loopback of the report if we are acting as a multicast
619 1.2 itojun * router, so that the process-level routing daemon can hear it.
620 1.2 itojun */
621 1.2 itojun im6o.im6o_multicast_loop = (ip6_mrouter != NULL);
622 1.2 itojun
623 1.2 itojun /* increment output statictics */
624 1.44 thorpej ICMP6_STATINC(ICMP6_STAT_OUTHIST + type);
625 1.15 itojun icmp6_ifstat_inc(ifp, ifs6_out_msg);
626 1.17 itojun switch (type) {
627 1.22 itojun case MLD_LISTENER_QUERY:
628 1.15 itojun icmp6_ifstat_inc(ifp, ifs6_out_mldquery);
629 1.15 itojun break;
630 1.22 itojun case MLD_LISTENER_REPORT:
631 1.15 itojun icmp6_ifstat_inc(ifp, ifs6_out_mldreport);
632 1.15 itojun break;
633 1.22 itojun case MLD_LISTENER_DONE:
634 1.15 itojun icmp6_ifstat_inc(ifp, ifs6_out_mlddone);
635 1.15 itojun break;
636 1.7 itojun }
637 1.19 itojun
638 1.85 ozaki /* XXX we cannot call ip6_output with holding in6_multilock */
639 1.85 ozaki rw_exit(&in6_multilock);
640 1.85 ozaki
641 1.27 perry ip6_output(mh, &ip6_opts, NULL, ia ? 0 : IPV6_UNSPECSRC,
642 1.53 plunky &im6o, NULL, NULL);
643 1.85 ozaki
644 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
645 1.2 itojun }
646 1.31 rpaulo
647 1.31 rpaulo static struct mld_hdr *
648 1.34 christos mld_allocbuf(struct mbuf **mh, int len, struct in6_multi *in6m,
649 1.33 christos int type)
650 1.31 rpaulo {
651 1.31 rpaulo struct mbuf *md;
652 1.31 rpaulo struct mld_hdr *mldh;
653 1.31 rpaulo struct ip6_hdr *ip6;
654 1.31 rpaulo
655 1.31 rpaulo /*
656 1.31 rpaulo * Allocate mbufs to store ip6 header and MLD header.
657 1.31 rpaulo * We allocate 2 mbufs and make chain in advance because
658 1.31 rpaulo * it is more convenient when inserting the hop-by-hop option later.
659 1.31 rpaulo */
660 1.31 rpaulo MGETHDR(*mh, M_DONTWAIT, MT_HEADER);
661 1.31 rpaulo if (*mh == NULL)
662 1.31 rpaulo return NULL;
663 1.31 rpaulo MGET(md, M_DONTWAIT, MT_DATA);
664 1.31 rpaulo if (md == NULL) {
665 1.31 rpaulo m_free(*mh);
666 1.31 rpaulo *mh = NULL;
667 1.31 rpaulo return NULL;
668 1.31 rpaulo }
669 1.31 rpaulo (*mh)->m_next = md;
670 1.31 rpaulo md->m_next = NULL;
671 1.31 rpaulo
672 1.65 ozaki m_reset_rcvif((*mh));
673 1.31 rpaulo (*mh)->m_pkthdr.len = sizeof(struct ip6_hdr) + len;
674 1.31 rpaulo (*mh)->m_len = sizeof(struct ip6_hdr);
675 1.31 rpaulo MH_ALIGN(*mh, sizeof(struct ip6_hdr));
676 1.31 rpaulo
677 1.31 rpaulo /* fill in the ip6 header */
678 1.31 rpaulo ip6 = mtod(*mh, struct ip6_hdr *);
679 1.31 rpaulo memset(ip6, 0, sizeof(*ip6));
680 1.31 rpaulo ip6->ip6_flow = 0;
681 1.31 rpaulo ip6->ip6_vfc &= ~IPV6_VERSION_MASK;
682 1.31 rpaulo ip6->ip6_vfc |= IPV6_VERSION;
683 1.31 rpaulo /* ip6_plen will be set later */
684 1.31 rpaulo ip6->ip6_nxt = IPPROTO_ICMPV6;
685 1.31 rpaulo /* ip6_hlim will be set by im6o.im6o_multicast_hlim */
686 1.31 rpaulo /* ip6_src/dst will be set by mld_sendpkt() or mld_sendbuf() */
687 1.31 rpaulo
688 1.31 rpaulo /* fill in the MLD header as much as possible */
689 1.31 rpaulo md->m_len = len;
690 1.31 rpaulo mldh = mtod(md, struct mld_hdr *);
691 1.31 rpaulo memset(mldh, 0, len);
692 1.31 rpaulo mldh->mld_type = type;
693 1.31 rpaulo return mldh;
694 1.31 rpaulo }
695 1.31 rpaulo
696 1.85 ozaki static void
697 1.85 ozaki in6m_ref(struct in6_multi *in6m)
698 1.85 ozaki {
699 1.85 ozaki
700 1.85 ozaki KASSERT(rw_write_held(&in6_multilock));
701 1.85 ozaki in6m->in6m_refcount++;
702 1.85 ozaki }
703 1.85 ozaki
704 1.85 ozaki static void
705 1.85 ozaki in6m_unref(struct in6_multi *in6m)
706 1.85 ozaki {
707 1.85 ozaki
708 1.85 ozaki KASSERT(rw_write_held(&in6_multilock));
709 1.85 ozaki if (--in6m->in6m_refcount == 0)
710 1.85 ozaki in6m_destroy(in6m);
711 1.85 ozaki }
712 1.85 ozaki
713 1.31 rpaulo /*
714 1.31 rpaulo * Add an address to the list of IP6 multicast addresses for a given interface.
715 1.31 rpaulo */
716 1.31 rpaulo struct in6_multi *
717 1.38 christos in6_addmulti(struct in6_addr *maddr6, struct ifnet *ifp,
718 1.38 christos int *errorp, int timer)
719 1.31 rpaulo {
720 1.54 dyoung struct sockaddr_in6 sin6;
721 1.31 rpaulo struct in6_multi *in6m;
722 1.31 rpaulo
723 1.31 rpaulo *errorp = 0;
724 1.31 rpaulo
725 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
726 1.31 rpaulo /*
727 1.31 rpaulo * See if address already in list.
728 1.31 rpaulo */
729 1.82 ozaki in6m = in6_lookup_multi(maddr6, ifp);
730 1.31 rpaulo if (in6m != NULL) {
731 1.31 rpaulo /*
732 1.31 rpaulo * Found it; just increment the refrence count.
733 1.31 rpaulo */
734 1.31 rpaulo in6m->in6m_refcount++;
735 1.31 rpaulo } else {
736 1.31 rpaulo /*
737 1.31 rpaulo * New address; allocate a new multicast record
738 1.31 rpaulo * and link it into the interface's multicast list.
739 1.31 rpaulo */
740 1.31 rpaulo in6m = (struct in6_multi *)
741 1.51 dyoung malloc(sizeof(*in6m), M_IPMADDR, M_NOWAIT|M_ZERO);
742 1.31 rpaulo if (in6m == NULL) {
743 1.31 rpaulo *errorp = ENOBUFS;
744 1.85 ozaki goto out;
745 1.31 rpaulo }
746 1.31 rpaulo
747 1.31 rpaulo in6m->in6m_addr = *maddr6;
748 1.31 rpaulo in6m->in6m_ifp = ifp;
749 1.31 rpaulo in6m->in6m_refcount = 1;
750 1.31 rpaulo in6m->in6m_timer = IN6M_TIMER_UNDEF;
751 1.64 joerg callout_init(&in6m->in6m_timer_ch, CALLOUT_MPSAFE);
752 1.64 joerg callout_setfunc(&in6m->in6m_timer_ch, mld_timeo, in6m);
753 1.64 joerg
754 1.83 ozaki LIST_INSERT_HEAD(&ifp->if_multiaddrs, in6m, in6m_entry);
755 1.31 rpaulo
756 1.31 rpaulo /*
757 1.31 rpaulo * Ask the network driver to update its multicast reception
758 1.31 rpaulo * filter appropriately for the new address.
759 1.31 rpaulo */
760 1.54 dyoung sockaddr_in6_init(&sin6, maddr6, 0, 0, 0);
761 1.54 dyoung *errorp = if_mcast_op(ifp, SIOCADDMULTI, sin6tosa(&sin6));
762 1.31 rpaulo if (*errorp) {
763 1.64 joerg callout_destroy(&in6m->in6m_timer_ch);
764 1.31 rpaulo LIST_REMOVE(in6m, in6m_entry);
765 1.31 rpaulo free(in6m, M_IPMADDR);
766 1.85 ozaki in6m = NULL;
767 1.85 ozaki goto out;
768 1.31 rpaulo }
769 1.31 rpaulo
770 1.32 rpaulo in6m->in6m_timer = timer;
771 1.31 rpaulo if (in6m->in6m_timer > 0) {
772 1.31 rpaulo in6m->in6m_state = MLD_REPORTPENDING;
773 1.31 rpaulo mld_starttimer(in6m);
774 1.85 ozaki goto out;
775 1.31 rpaulo }
776 1.31 rpaulo
777 1.31 rpaulo /*
778 1.31 rpaulo * Let MLD6 know that we have joined a new IP6 multicast
779 1.31 rpaulo * group.
780 1.31 rpaulo */
781 1.31 rpaulo mld_start_listening(in6m);
782 1.31 rpaulo }
783 1.85 ozaki out:
784 1.85 ozaki rw_exit(&in6_multilock);
785 1.85 ozaki return in6m;
786 1.31 rpaulo }
787 1.31 rpaulo
788 1.85 ozaki static void
789 1.85 ozaki in6m_destroy(struct in6_multi *in6m)
790 1.31 rpaulo {
791 1.85 ozaki struct sockaddr_in6 sin6;
792 1.85 ozaki
793 1.85 ozaki KASSERT(rw_write_held(&in6_multilock));
794 1.85 ozaki KASSERT(in6m->in6m_refcount == 0);
795 1.31 rpaulo
796 1.85 ozaki /*
797 1.85 ozaki * No remaining claims to this record; let MLD6 know
798 1.85 ozaki * that we are leaving the multicast group.
799 1.85 ozaki */
800 1.85 ozaki mld_stop_listening(in6m);
801 1.31 rpaulo
802 1.85 ozaki /*
803 1.85 ozaki * Unlink from list.
804 1.85 ozaki */
805 1.85 ozaki LIST_REMOVE(in6m, in6m_entry);
806 1.73 ozaki
807 1.85 ozaki /*
808 1.85 ozaki * Delete all references of this multicasting group from
809 1.85 ozaki * the membership arrays
810 1.85 ozaki */
811 1.86 ozaki in6_purge_mcast_references(in6m);
812 1.85 ozaki
813 1.85 ozaki /*
814 1.85 ozaki * Notify the network driver to update its multicast
815 1.85 ozaki * reception filter.
816 1.85 ozaki */
817 1.85 ozaki sockaddr_in6_init(&sin6, &in6m->in6m_addr, 0, 0, 0);
818 1.85 ozaki if_mcast_op(in6m->in6m_ifp, SIOCDELMULTI, sin6tosa(&sin6));
819 1.31 rpaulo
820 1.85 ozaki /* Tell mld_timeo we're halting the timer */
821 1.85 ozaki in6m->in6m_timer = IN6M_TIMER_UNDEF;
822 1.85 ozaki if (mutex_owned(softnet_lock))
823 1.85 ozaki callout_halt(&in6m->in6m_timer_ch, softnet_lock);
824 1.85 ozaki else
825 1.85 ozaki callout_halt(&in6m->in6m_timer_ch, NULL);
826 1.85 ozaki callout_destroy(&in6m->in6m_timer_ch);
827 1.31 rpaulo
828 1.85 ozaki free(in6m, M_IPMADDR);
829 1.85 ozaki }
830 1.31 rpaulo
831 1.85 ozaki /*
832 1.85 ozaki * Delete a multicast address record.
833 1.85 ozaki */
834 1.85 ozaki void
835 1.85 ozaki in6_delmulti(struct in6_multi *in6m)
836 1.85 ozaki {
837 1.61 ozaki
838 1.85 ozaki KASSERT(in6m->in6m_refcount > 0);
839 1.61 ozaki
840 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
841 1.85 ozaki /*
842 1.85 ozaki * The caller should have a reference to in6m. So we don't need to care
843 1.85 ozaki * of releasing the lock in mld_stoptimer.
844 1.85 ozaki */
845 1.85 ozaki mld_stoptimer(in6m);
846 1.85 ozaki if (--in6m->in6m_refcount == 0)
847 1.85 ozaki in6m_destroy(in6m);
848 1.85 ozaki rw_exit(&in6_multilock);
849 1.31 rpaulo }
850 1.31 rpaulo
851 1.83 ozaki /*
852 1.83 ozaki * Look up the in6_multi record for a given IP6 multicast address
853 1.83 ozaki * on a given interface. If no matching record is found, "in6m"
854 1.83 ozaki * returns NULL.
855 1.83 ozaki */
856 1.83 ozaki struct in6_multi *
857 1.83 ozaki in6_lookup_multi(const struct in6_addr *addr, const struct ifnet *ifp)
858 1.83 ozaki {
859 1.83 ozaki struct in6_multi *in6m;
860 1.83 ozaki
861 1.85 ozaki KASSERT(rw_lock_held(&in6_multilock));
862 1.85 ozaki
863 1.83 ozaki LIST_FOREACH(in6m, &ifp->if_multiaddrs, in6m_entry) {
864 1.83 ozaki if (IN6_ARE_ADDR_EQUAL(&in6m->in6m_addr, addr))
865 1.83 ozaki break;
866 1.83 ozaki }
867 1.83 ozaki return in6m;
868 1.83 ozaki }
869 1.83 ozaki
870 1.84 ozaki bool
871 1.84 ozaki in6_multi_group(const struct in6_addr *addr, const struct ifnet *ifp)
872 1.84 ozaki {
873 1.84 ozaki bool ingroup;
874 1.84 ozaki
875 1.85 ozaki rw_enter(&in6_multilock, RW_READER);
876 1.84 ozaki ingroup = in6_lookup_multi(addr, ifp) != NULL;
877 1.85 ozaki rw_exit(&in6_multilock);
878 1.84 ozaki
879 1.84 ozaki return ingroup;
880 1.84 ozaki }
881 1.84 ozaki
882 1.83 ozaki /*
883 1.83 ozaki * Purge in6_multi records associated to the interface.
884 1.83 ozaki */
885 1.83 ozaki void
886 1.83 ozaki in6_purge_multi(struct ifnet *ifp)
887 1.83 ozaki {
888 1.83 ozaki struct in6_multi *in6m, *next;
889 1.83 ozaki
890 1.85 ozaki rw_enter(&in6_multilock, RW_WRITER);
891 1.83 ozaki LIST_FOREACH_SAFE(in6m, &ifp->if_multiaddrs, in6m_entry, next) {
892 1.85 ozaki /*
893 1.85 ozaki * Normally multicast addresses are already purged at this
894 1.85 ozaki * point. Remaining references aren't accessible via ifp,
895 1.85 ozaki * so what we can do here is to prevent ifp from being
896 1.85 ozaki * accessed via in6m by removing it from the list of ifp.
897 1.85 ozaki */
898 1.85 ozaki mld_stoptimer(in6m);
899 1.85 ozaki LIST_REMOVE(in6m, in6m_entry);
900 1.83 ozaki }
901 1.85 ozaki rw_exit(&in6_multilock);
902 1.83 ozaki }
903 1.31 rpaulo
904 1.87 ozaki void
905 1.87 ozaki in6_multi_lock(int op)
906 1.87 ozaki {
907 1.87 ozaki
908 1.87 ozaki rw_enter(&in6_multilock, op);
909 1.87 ozaki }
910 1.87 ozaki
911 1.87 ozaki void
912 1.87 ozaki in6_multi_unlock(void)
913 1.87 ozaki {
914 1.87 ozaki
915 1.87 ozaki rw_exit(&in6_multilock);
916 1.87 ozaki }
917 1.87 ozaki
918 1.31 rpaulo struct in6_multi_mship *
919 1.38 christos in6_joingroup(struct ifnet *ifp, struct in6_addr *addr,
920 1.38 christos int *errorp, int timer)
921 1.31 rpaulo {
922 1.31 rpaulo struct in6_multi_mship *imm;
923 1.31 rpaulo
924 1.51 dyoung imm = malloc(sizeof(*imm), M_IPMADDR, M_NOWAIT|M_ZERO);
925 1.51 dyoung if (imm == NULL) {
926 1.31 rpaulo *errorp = ENOBUFS;
927 1.31 rpaulo return NULL;
928 1.31 rpaulo }
929 1.31 rpaulo
930 1.32 rpaulo imm->i6mm_maddr = in6_addmulti(addr, ifp, errorp, timer);
931 1.31 rpaulo if (!imm->i6mm_maddr) {
932 1.36 dyoung /* *errorp is already set */
933 1.31 rpaulo free(imm, M_IPMADDR);
934 1.31 rpaulo return NULL;
935 1.31 rpaulo }
936 1.31 rpaulo return imm;
937 1.31 rpaulo }
938 1.31 rpaulo
939 1.31 rpaulo int
940 1.38 christos in6_leavegroup(struct in6_multi_mship *imm)
941 1.31 rpaulo {
942 1.31 rpaulo
943 1.31 rpaulo if (imm->i6mm_maddr) {
944 1.31 rpaulo in6_delmulti(imm->i6mm_maddr);
945 1.31 rpaulo }
946 1.31 rpaulo free(imm, M_IPMADDR);
947 1.31 rpaulo return 0;
948 1.31 rpaulo }
949 1.31 rpaulo
950 1.31 rpaulo /*
951 1.83 ozaki * DEPRECATED: keep it just to avoid breaking old sysctl users.
952 1.31 rpaulo */
953 1.57 joerg static int
954 1.57 joerg in6_mkludge_sysctl(SYSCTLFN_ARGS)
955 1.57 joerg {
956 1.57 joerg
957 1.57 joerg if (namelen != 1)
958 1.57 joerg return EINVAL;
959 1.83 ozaki *oldlenp = 0;
960 1.83 ozaki return 0;
961 1.57 joerg }
962 1.57 joerg
963 1.57 joerg static int
964 1.57 joerg in6_multicast_sysctl(SYSCTLFN_ARGS)
965 1.57 joerg {
966 1.57 joerg struct ifnet *ifp;
967 1.57 joerg struct ifaddr *ifa;
968 1.83 ozaki struct in6_ifaddr *ia6;
969 1.57 joerg struct in6_multi *in6m;
970 1.57 joerg uint32_t tmp;
971 1.57 joerg int error;
972 1.57 joerg size_t written;
973 1.74 ozaki struct psref psref, psref_ia;
974 1.74 ozaki int bound, s;
975 1.57 joerg
976 1.57 joerg if (namelen != 1)
977 1.57 joerg return EINVAL;
978 1.57 joerg
979 1.85 ozaki rw_enter(&in6_multilock, RW_READER);
980 1.85 ozaki
981 1.67 ozaki bound = curlwp_bind();
982 1.67 ozaki ifp = if_get_byindex(name[0], &psref);
983 1.67 ozaki if (ifp == NULL) {
984 1.67 ozaki curlwp_bindx(bound);
985 1.85 ozaki rw_exit(&in6_multilock);
986 1.57 joerg return ENODEV;
987 1.67 ozaki }
988 1.57 joerg
989 1.57 joerg if (oldp == NULL) {
990 1.57 joerg *oldlenp = 0;
991 1.74 ozaki s = pserialize_read_enter();
992 1.71 ozaki IFADDR_READER_FOREACH(ifa, ifp) {
993 1.83 ozaki LIST_FOREACH(in6m, &ifp->if_multiaddrs, in6m_entry) {
994 1.57 joerg *oldlenp += 2 * sizeof(struct in6_addr) +
995 1.57 joerg sizeof(uint32_t);
996 1.57 joerg }
997 1.57 joerg }
998 1.74 ozaki pserialize_read_exit(s);
999 1.67 ozaki if_put(ifp, &psref);
1000 1.67 ozaki curlwp_bindx(bound);
1001 1.85 ozaki rw_exit(&in6_multilock);
1002 1.57 joerg return 0;
1003 1.57 joerg }
1004 1.57 joerg
1005 1.57 joerg error = 0;
1006 1.57 joerg written = 0;
1007 1.74 ozaki s = pserialize_read_enter();
1008 1.71 ozaki IFADDR_READER_FOREACH(ifa, ifp) {
1009 1.57 joerg if (ifa->ifa_addr->sa_family != AF_INET6)
1010 1.57 joerg continue;
1011 1.74 ozaki
1012 1.74 ozaki ifa_acquire(ifa, &psref_ia);
1013 1.74 ozaki pserialize_read_exit(s);
1014 1.74 ozaki
1015 1.83 ozaki ia6 = ifatoia6(ifa);
1016 1.83 ozaki LIST_FOREACH(in6m, &ifp->if_multiaddrs, in6m_entry) {
1017 1.57 joerg if (written + 2 * sizeof(struct in6_addr) +
1018 1.57 joerg sizeof(uint32_t) > *oldlenp)
1019 1.57 joerg goto done;
1020 1.83 ozaki /*
1021 1.83 ozaki * XXX return the first IPv6 address to keep backward
1022 1.83 ozaki * compatibility, however now multicast addresses
1023 1.83 ozaki * don't belong to any IPv6 addresses so it should be
1024 1.83 ozaki * unnecessary.
1025 1.83 ozaki */
1026 1.83 ozaki error = sysctl_copyout(l, &ia6->ia_addr.sin6_addr,
1027 1.57 joerg oldp, sizeof(struct in6_addr));
1028 1.57 joerg if (error)
1029 1.57 joerg goto done;
1030 1.57 joerg oldp = (char *)oldp + sizeof(struct in6_addr);
1031 1.57 joerg written += sizeof(struct in6_addr);
1032 1.57 joerg error = sysctl_copyout(l, &in6m->in6m_addr,
1033 1.57 joerg oldp, sizeof(struct in6_addr));
1034 1.57 joerg if (error)
1035 1.57 joerg goto done;
1036 1.57 joerg oldp = (char *)oldp + sizeof(struct in6_addr);
1037 1.57 joerg written += sizeof(struct in6_addr);
1038 1.57 joerg tmp = in6m->in6m_refcount;
1039 1.57 joerg error = sysctl_copyout(l, &tmp, oldp, sizeof(tmp));
1040 1.57 joerg if (error)
1041 1.57 joerg goto done;
1042 1.57 joerg oldp = (char *)oldp + sizeof(tmp);
1043 1.57 joerg written += sizeof(tmp);
1044 1.57 joerg }
1045 1.74 ozaki
1046 1.74 ozaki s = pserialize_read_enter();
1047 1.74 ozaki ifa_release(ifa, &psref_ia);
1048 1.83 ozaki
1049 1.83 ozaki break;
1050 1.57 joerg }
1051 1.74 ozaki pserialize_read_exit(s);
1052 1.57 joerg done:
1053 1.74 ozaki ifa_release(ifa, &psref_ia);
1054 1.67 ozaki if_put(ifp, &psref);
1055 1.67 ozaki curlwp_bindx(bound);
1056 1.85 ozaki rw_exit(&in6_multilock);
1057 1.57 joerg *oldlenp = written;
1058 1.57 joerg return error;
1059 1.57 joerg }
1060 1.57 joerg
1061 1.76 ozaki void
1062 1.76 ozaki in6_sysctl_multicast_setup(struct sysctllog **clog)
1063 1.57 joerg {
1064 1.57 joerg
1065 1.57 joerg sysctl_createv(clog, 0, NULL, NULL,
1066 1.57 joerg CTLFLAG_PERMANENT,
1067 1.59 joerg CTLTYPE_NODE, "inet6", NULL,
1068 1.59 joerg NULL, 0, NULL, 0,
1069 1.59 joerg CTL_NET, PF_INET6, CTL_EOL);
1070 1.59 joerg
1071 1.59 joerg sysctl_createv(clog, 0, NULL, NULL,
1072 1.59 joerg CTLFLAG_PERMANENT,
1073 1.57 joerg CTLTYPE_NODE, "multicast",
1074 1.57 joerg SYSCTL_DESCR("Multicast information"),
1075 1.57 joerg in6_multicast_sysctl, 0, NULL, 0,
1076 1.57 joerg CTL_NET, PF_INET6, CTL_CREATE, CTL_EOL);
1077 1.57 joerg
1078 1.57 joerg sysctl_createv(clog, 0, NULL, NULL,
1079 1.57 joerg CTLFLAG_PERMANENT,
1080 1.57 joerg CTLTYPE_NODE, "multicast_kludge",
1081 1.57 joerg SYSCTL_DESCR("multicast kludge information"),
1082 1.57 joerg in6_mkludge_sysctl, 0, NULL, 0,
1083 1.57 joerg CTL_NET, PF_INET6, CTL_CREATE, CTL_EOL);
1084 1.57 joerg }
1085