[NETLINK]: Make use of NLA_STRING/NLA_NUL_STRING attribute validation
[safe/jmp/linux-2.6] / net / core / rtnetlink.c
1 /*
2  * INET         An implementation of the TCP/IP protocol suite for the LINUX
3  *              operating system.  INET is implemented using the  BSD Socket
4  *              interface as the means of communication with the user level.
5  *
6  *              Routing netlink socket interface: protocol independent part.
7  *
8  * Authors:     Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
9  *
10  *              This program is free software; you can redistribute it and/or
11  *              modify it under the terms of the GNU General Public License
12  *              as published by the Free Software Foundation; either version
13  *              2 of the License, or (at your option) any later version.
14  *
15  *      Fixes:
16  *      Vitaly E. Lavrov                RTA_OK arithmetics was wrong.
17  */
18
19 #include <linux/errno.h>
20 #include <linux/module.h>
21 #include <linux/types.h>
22 #include <linux/socket.h>
23 #include <linux/kernel.h>
24 #include <linux/sched.h>
25 #include <linux/timer.h>
26 #include <linux/string.h>
27 #include <linux/sockios.h>
28 #include <linux/net.h>
29 #include <linux/fcntl.h>
30 #include <linux/mm.h>
31 #include <linux/slab.h>
32 #include <linux/interrupt.h>
33 #include <linux/capability.h>
34 #include <linux/skbuff.h>
35 #include <linux/init.h>
36 #include <linux/security.h>
37 #include <linux/mutex.h>
38 #include <linux/if_addr.h>
39
40 #include <asm/uaccess.h>
41 #include <asm/system.h>
42 #include <asm/string.h>
43
44 #include <linux/inet.h>
45 #include <linux/netdevice.h>
46 #include <net/ip.h>
47 #include <net/protocol.h>
48 #include <net/arp.h>
49 #include <net/route.h>
50 #include <net/udp.h>
51 #include <net/sock.h>
52 #include <net/pkt_sched.h>
53 #include <net/fib_rules.h>
54 #include <net/netlink.h>
55 #ifdef CONFIG_NET_WIRELESS_RTNETLINK
56 #include <linux/wireless.h>
57 #include <net/iw_handler.h>
58 #endif  /* CONFIG_NET_WIRELESS_RTNETLINK */
59
60 static DEFINE_MUTEX(rtnl_mutex);
61 static struct sock *rtnl;
62
63 void rtnl_lock(void)
64 {
65         mutex_lock(&rtnl_mutex);
66 }
67
68 void __rtnl_unlock(void)
69 {
70         mutex_unlock(&rtnl_mutex);
71 }
72
73 void rtnl_unlock(void)
74 {
75         mutex_unlock(&rtnl_mutex);
76         if (rtnl && rtnl->sk_receive_queue.qlen)
77                 rtnl->sk_data_ready(rtnl, 0);
78         netdev_run_todo();
79 }
80
81 int rtnl_trylock(void)
82 {
83         return mutex_trylock(&rtnl_mutex);
84 }
85
86 int rtattr_parse(struct rtattr *tb[], int maxattr, struct rtattr *rta, int len)
87 {
88         memset(tb, 0, sizeof(struct rtattr*)*maxattr);
89
90         while (RTA_OK(rta, len)) {
91                 unsigned flavor = rta->rta_type;
92                 if (flavor && flavor <= maxattr)
93                         tb[flavor-1] = rta;
94                 rta = RTA_NEXT(rta, len);
95         }
96         return 0;
97 }
98
99 struct rtnetlink_link * rtnetlink_links[NPROTO];
100
101 static const int rtm_min[RTM_NR_FAMILIES] =
102 {
103         [RTM_FAM(RTM_NEWLINK)]      = NLMSG_LENGTH(sizeof(struct ifinfomsg)),
104         [RTM_FAM(RTM_NEWADDR)]      = NLMSG_LENGTH(sizeof(struct ifaddrmsg)),
105         [RTM_FAM(RTM_NEWROUTE)]     = NLMSG_LENGTH(sizeof(struct rtmsg)),
106         [RTM_FAM(RTM_NEWRULE)]      = NLMSG_LENGTH(sizeof(struct fib_rule_hdr)),
107         [RTM_FAM(RTM_NEWQDISC)]     = NLMSG_LENGTH(sizeof(struct tcmsg)),
108         [RTM_FAM(RTM_NEWTCLASS)]    = NLMSG_LENGTH(sizeof(struct tcmsg)),
109         [RTM_FAM(RTM_NEWTFILTER)]   = NLMSG_LENGTH(sizeof(struct tcmsg)),
110         [RTM_FAM(RTM_NEWACTION)]    = NLMSG_LENGTH(sizeof(struct tcamsg)),
111         [RTM_FAM(RTM_NEWPREFIX)]    = NLMSG_LENGTH(sizeof(struct rtgenmsg)),
112         [RTM_FAM(RTM_GETMULTICAST)] = NLMSG_LENGTH(sizeof(struct rtgenmsg)),
113         [RTM_FAM(RTM_GETANYCAST)]   = NLMSG_LENGTH(sizeof(struct rtgenmsg)),
114 };
115
116 static const int rta_max[RTM_NR_FAMILIES] =
117 {
118         [RTM_FAM(RTM_NEWLINK)]      = IFLA_MAX,
119         [RTM_FAM(RTM_NEWADDR)]      = IFA_MAX,
120         [RTM_FAM(RTM_NEWROUTE)]     = RTA_MAX,
121         [RTM_FAM(RTM_NEWRULE)]      = FRA_MAX,
122         [RTM_FAM(RTM_NEWQDISC)]     = TCA_MAX,
123         [RTM_FAM(RTM_NEWTCLASS)]    = TCA_MAX,
124         [RTM_FAM(RTM_NEWTFILTER)]   = TCA_MAX,
125         [RTM_FAM(RTM_NEWACTION)]    = TCAA_MAX,
126 };
127
128 void __rta_fill(struct sk_buff *skb, int attrtype, int attrlen, const void *data)
129 {
130         struct rtattr *rta;
131         int size = RTA_LENGTH(attrlen);
132
133         rta = (struct rtattr*)skb_put(skb, RTA_ALIGN(size));
134         rta->rta_type = attrtype;
135         rta->rta_len = size;
136         memcpy(RTA_DATA(rta), data, attrlen);
137         memset(RTA_DATA(rta) + attrlen, 0, RTA_ALIGN(size) - size);
138 }
139
140 size_t rtattr_strlcpy(char *dest, const struct rtattr *rta, size_t size)
141 {
142         size_t ret = RTA_PAYLOAD(rta);
143         char *src = RTA_DATA(rta);
144
145         if (ret > 0 && src[ret - 1] == '\0')
146                 ret--;
147         if (size > 0) {
148                 size_t len = (ret >= size) ? size - 1 : ret;
149                 memset(dest, 0, size);
150                 memcpy(dest, src, len);
151         }
152         return ret;
153 }
154
155 int rtnetlink_send(struct sk_buff *skb, u32 pid, unsigned group, int echo)
156 {
157         int err = 0;
158
159         NETLINK_CB(skb).dst_group = group;
160         if (echo)
161                 atomic_inc(&skb->users);
162         netlink_broadcast(rtnl, skb, pid, group, GFP_KERNEL);
163         if (echo)
164                 err = netlink_unicast(rtnl, skb, pid, MSG_DONTWAIT);
165         return err;
166 }
167
168 int rtnl_unicast(struct sk_buff *skb, u32 pid)
169 {
170         return nlmsg_unicast(rtnl, skb, pid);
171 }
172
173 int rtnl_notify(struct sk_buff *skb, u32 pid, u32 group,
174                 struct nlmsghdr *nlh, gfp_t flags)
175 {
176         int report = 0;
177
178         if (nlh)
179                 report = nlmsg_report(nlh);
180
181         return nlmsg_notify(rtnl, skb, pid, group, report, flags);
182 }
183
184 void rtnl_set_sk_err(u32 group, int error)
185 {
186         netlink_set_err(rtnl, 0, group, error);
187 }
188
189 int rtnetlink_put_metrics(struct sk_buff *skb, u32 *metrics)
190 {
191         struct nlattr *mx;
192         int i, valid = 0;
193
194         mx = nla_nest_start(skb, RTA_METRICS);
195         if (mx == NULL)
196                 return -ENOBUFS;
197
198         for (i = 0; i < RTAX_MAX; i++) {
199                 if (metrics[i]) {
200                         valid++;
201                         NLA_PUT_U32(skb, i+1, metrics[i]);
202                 }
203         }
204
205         if (!valid) {
206                 nla_nest_cancel(skb, mx);
207                 return 0;
208         }
209
210         return nla_nest_end(skb, mx);
211
212 nla_put_failure:
213         return nla_nest_cancel(skb, mx);
214 }
215
216
217 static void set_operstate(struct net_device *dev, unsigned char transition)
218 {
219         unsigned char operstate = dev->operstate;
220
221         switch(transition) {
222         case IF_OPER_UP:
223                 if ((operstate == IF_OPER_DORMANT ||
224                      operstate == IF_OPER_UNKNOWN) &&
225                     !netif_dormant(dev))
226                         operstate = IF_OPER_UP;
227                 break;
228
229         case IF_OPER_DORMANT:
230                 if (operstate == IF_OPER_UP ||
231                     operstate == IF_OPER_UNKNOWN)
232                         operstate = IF_OPER_DORMANT;
233                 break;
234         };
235
236         if (dev->operstate != operstate) {
237                 write_lock_bh(&dev_base_lock);
238                 dev->operstate = operstate;
239                 write_unlock_bh(&dev_base_lock);
240                 netdev_state_change(dev);
241         }
242 }
243
244 static void copy_rtnl_link_stats(struct rtnl_link_stats *a,
245                                  struct net_device_stats *b)
246 {
247         a->rx_packets = b->rx_packets;
248         a->tx_packets = b->tx_packets;
249         a->rx_bytes = b->rx_bytes;
250         a->tx_bytes = b->tx_bytes;
251         a->rx_errors = b->rx_errors;
252         a->tx_errors = b->tx_errors;
253         a->rx_dropped = b->rx_dropped;
254         a->tx_dropped = b->tx_dropped;
255
256         a->multicast = b->multicast;
257         a->collisions = b->collisions;
258
259         a->rx_length_errors = b->rx_length_errors;
260         a->rx_over_errors = b->rx_over_errors;
261         a->rx_crc_errors = b->rx_crc_errors;
262         a->rx_frame_errors = b->rx_frame_errors;
263         a->rx_fifo_errors = b->rx_fifo_errors;
264         a->rx_missed_errors = b->rx_missed_errors;
265
266         a->tx_aborted_errors = b->tx_aborted_errors;
267         a->tx_carrier_errors = b->tx_carrier_errors;
268         a->tx_fifo_errors = b->tx_fifo_errors;
269         a->tx_heartbeat_errors = b->tx_heartbeat_errors;
270         a->tx_window_errors = b->tx_window_errors;
271
272         a->rx_compressed = b->rx_compressed;
273         a->tx_compressed = b->tx_compressed;
274 };
275
276 static int rtnl_fill_ifinfo(struct sk_buff *skb, struct net_device *dev,
277                             void *iwbuf, int iwbuflen, int type, u32 pid,
278                             u32 seq, u32 change, unsigned int flags)
279 {
280         struct ifinfomsg *ifm;
281         struct nlmsghdr *nlh;
282
283         nlh = nlmsg_put(skb, pid, seq, type, sizeof(*ifm), flags);
284         if (nlh == NULL)
285                 return -ENOBUFS;
286
287         ifm = nlmsg_data(nlh);
288         ifm->ifi_family = AF_UNSPEC;
289         ifm->__ifi_pad = 0;
290         ifm->ifi_type = dev->type;
291         ifm->ifi_index = dev->ifindex;
292         ifm->ifi_flags = dev_get_flags(dev);
293         ifm->ifi_change = change;
294
295         NLA_PUT_STRING(skb, IFLA_IFNAME, dev->name);
296         NLA_PUT_U32(skb, IFLA_TXQLEN, dev->tx_queue_len);
297         NLA_PUT_U32(skb, IFLA_WEIGHT, dev->weight);
298         NLA_PUT_U8(skb, IFLA_OPERSTATE,
299                    netif_running(dev) ? dev->operstate : IF_OPER_DOWN);
300         NLA_PUT_U8(skb, IFLA_LINKMODE, dev->link_mode);
301         NLA_PUT_U32(skb, IFLA_MTU, dev->mtu);
302
303         if (dev->ifindex != dev->iflink)
304                 NLA_PUT_U32(skb, IFLA_LINK, dev->iflink);
305
306         if (dev->master)
307                 NLA_PUT_U32(skb, IFLA_MASTER, dev->master->ifindex);
308
309         if (dev->qdisc_sleeping)
310                 NLA_PUT_STRING(skb, IFLA_QDISC, dev->qdisc_sleeping->ops->id);
311
312         if (1) {
313                 struct rtnl_link_ifmap map = {
314                         .mem_start   = dev->mem_start,
315                         .mem_end     = dev->mem_end,
316                         .base_addr   = dev->base_addr,
317                         .irq         = dev->irq,
318                         .dma         = dev->dma,
319                         .port        = dev->if_port,
320                 };
321                 NLA_PUT(skb, IFLA_MAP, sizeof(map), &map);
322         }
323
324         if (dev->addr_len) {
325                 NLA_PUT(skb, IFLA_ADDRESS, dev->addr_len, dev->dev_addr);
326                 NLA_PUT(skb, IFLA_BROADCAST, dev->addr_len, dev->broadcast);
327         }
328
329         if (dev->get_stats) {
330                 struct net_device_stats *stats = dev->get_stats(dev);
331                 if (stats) {
332                         struct nlattr *attr;
333
334                         attr = nla_reserve(skb, IFLA_STATS,
335                                            sizeof(struct rtnl_link_stats));
336                         if (attr == NULL)
337                                 goto nla_put_failure;
338
339                         copy_rtnl_link_stats(nla_data(attr), stats);
340                 }
341         }
342
343         if (iwbuf)
344                 NLA_PUT(skb, IFLA_WIRELESS, iwbuflen, iwbuf);
345
346         return nlmsg_end(skb, nlh);
347
348 nla_put_failure:
349         return nlmsg_cancel(skb, nlh);
350 }
351
352 static int rtnl_dump_ifinfo(struct sk_buff *skb, struct netlink_callback *cb)
353 {
354         int idx;
355         int s_idx = cb->args[0];
356         struct net_device *dev;
357
358         read_lock(&dev_base_lock);
359         for (dev=dev_base, idx=0; dev; dev = dev->next, idx++) {
360                 if (idx < s_idx)
361                         continue;
362                 if (rtnl_fill_ifinfo(skb, dev, NULL, 0, RTM_NEWLINK,
363                                      NETLINK_CB(cb->skb).pid,
364                                      cb->nlh->nlmsg_seq, 0, NLM_F_MULTI) <= 0)
365                         break;
366         }
367         read_unlock(&dev_base_lock);
368         cb->args[0] = idx;
369
370         return skb->len;
371 }
372
373 static struct nla_policy ifla_policy[IFLA_MAX+1] __read_mostly = {
374         [IFLA_IFNAME]           = { .type = NLA_STRING, .len = IFNAMSIZ-1 },
375         [IFLA_MAP]              = { .len = sizeof(struct rtnl_link_ifmap) },
376         [IFLA_MTU]              = { .type = NLA_U32 },
377         [IFLA_TXQLEN]           = { .type = NLA_U32 },
378         [IFLA_WEIGHT]           = { .type = NLA_U32 },
379         [IFLA_OPERSTATE]        = { .type = NLA_U8 },
380         [IFLA_LINKMODE]         = { .type = NLA_U8 },
381 };
382
383 static int rtnl_setlink(struct sk_buff *skb, struct nlmsghdr *nlh, void *arg)
384 {
385         struct ifinfomsg *ifm;
386         struct net_device *dev;
387         int err, send_addr_notify = 0, modified = 0;
388         struct nlattr *tb[IFLA_MAX+1];
389         char ifname[IFNAMSIZ];
390
391         err = nlmsg_parse(nlh, sizeof(*ifm), tb, IFLA_MAX, ifla_policy);
392         if (err < 0)
393                 goto errout;
394
395         if (tb[IFLA_IFNAME])
396                 nla_strlcpy(ifname, tb[IFLA_IFNAME], IFNAMSIZ);
397
398         err = -EINVAL;
399         ifm = nlmsg_data(nlh);
400         if (ifm->ifi_index >= 0)
401                 dev = dev_get_by_index(ifm->ifi_index);
402         else if (tb[IFLA_IFNAME])
403                 dev = dev_get_by_name(ifname);
404         else
405                 goto errout;
406
407         if (dev == NULL) {
408                 err = -ENODEV;
409                 goto errout;
410         }
411
412         if (tb[IFLA_ADDRESS] &&
413             nla_len(tb[IFLA_ADDRESS]) < dev->addr_len)
414                 goto errout_dev;
415
416         if (tb[IFLA_BROADCAST] &&
417             nla_len(tb[IFLA_BROADCAST]) < dev->addr_len)
418                 goto errout_dev;
419
420         if (tb[IFLA_MAP]) {
421                 struct rtnl_link_ifmap *u_map;
422                 struct ifmap k_map;
423
424                 if (!dev->set_config) {
425                         err = -EOPNOTSUPP;
426                         goto errout_dev;
427                 }
428
429                 if (!netif_device_present(dev)) {
430                         err = -ENODEV;
431                         goto errout_dev;
432                 }
433
434                 u_map = nla_data(tb[IFLA_MAP]);
435                 k_map.mem_start = (unsigned long) u_map->mem_start;
436                 k_map.mem_end = (unsigned long) u_map->mem_end;
437                 k_map.base_addr = (unsigned short) u_map->base_addr;
438                 k_map.irq = (unsigned char) u_map->irq;
439                 k_map.dma = (unsigned char) u_map->dma;
440                 k_map.port = (unsigned char) u_map->port;
441
442                 err = dev->set_config(dev, &k_map);
443                 if (err < 0)
444                         goto errout_dev;
445
446                 modified = 1;
447         }
448
449         if (tb[IFLA_ADDRESS]) {
450                 struct sockaddr *sa;
451                 int len;
452
453                 if (!dev->set_mac_address) {
454                         err = -EOPNOTSUPP;
455                         goto errout_dev;
456                 }
457
458                 if (!netif_device_present(dev)) {
459                         err = -ENODEV;
460                         goto errout_dev;
461                 }
462
463                 len = sizeof(sa_family_t) + dev->addr_len;
464                 sa = kmalloc(len, GFP_KERNEL);
465                 if (!sa) {
466                         err = -ENOMEM;
467                         goto errout_dev;
468                 }
469                 sa->sa_family = dev->type;
470                 memcpy(sa->sa_data, nla_data(tb[IFLA_ADDRESS]),
471                        dev->addr_len);
472                 err = dev->set_mac_address(dev, sa);
473                 kfree(sa);
474                 if (err)
475                         goto errout_dev;
476                 send_addr_notify = 1;
477                 modified = 1;
478         }
479
480         if (tb[IFLA_MTU]) {
481                 err = dev_set_mtu(dev, nla_get_u32(tb[IFLA_MTU]));
482                 if (err < 0)
483                         goto errout_dev;
484                 modified = 1;
485         }
486
487         /*
488          * Interface selected by interface index but interface
489          * name provided implies that a name change has been
490          * requested.
491          */
492         if (ifm->ifi_index >= 0 && ifname[0]) {
493                 err = dev_change_name(dev, ifname);
494                 if (err < 0)
495                         goto errout_dev;
496                 modified = 1;
497         }
498
499 #ifdef CONFIG_NET_WIRELESS_RTNETLINK
500         if (tb[IFLA_WIRELESS]) {
501                 /* Call Wireless Extensions.
502                  * Various stuff checked in there... */
503                 err = wireless_rtnetlink_set(dev, nla_data(tb[IFLA_WIRELESS]),
504                                              nla_len(tb[IFLA_WIRELESS]));
505                 if (err < 0)
506                         goto errout_dev;
507         }
508 #endif  /* CONFIG_NET_WIRELESS_RTNETLINK */
509
510         if (tb[IFLA_BROADCAST]) {
511                 nla_memcpy(dev->broadcast, tb[IFLA_BROADCAST], dev->addr_len);
512                 send_addr_notify = 1;
513         }
514
515
516         if (ifm->ifi_flags)
517                 dev_change_flags(dev, ifm->ifi_flags);
518
519         if (tb[IFLA_TXQLEN])
520                 dev->tx_queue_len = nla_get_u32(tb[IFLA_TXQLEN]);
521
522         if (tb[IFLA_WEIGHT])
523                 dev->weight = nla_get_u32(tb[IFLA_WEIGHT]);
524
525         if (tb[IFLA_OPERSTATE])
526                 set_operstate(dev, nla_get_u8(tb[IFLA_OPERSTATE]));
527
528         if (tb[IFLA_LINKMODE]) {
529                 write_lock_bh(&dev_base_lock);
530                 dev->link_mode = nla_get_u8(tb[IFLA_LINKMODE]);
531                 write_unlock_bh(&dev_base_lock);
532         }
533
534         err = 0;
535
536 errout_dev:
537         if (err < 0 && modified && net_ratelimit())
538                 printk(KERN_WARNING "A link change request failed with "
539                        "some changes comitted already. Interface %s may "
540                        "have been left with an inconsistent configuration, "
541                        "please check.\n", dev->name);
542
543         if (send_addr_notify)
544                 call_netdevice_notifiers(NETDEV_CHANGEADDR, dev);
545
546         dev_put(dev);
547 errout:
548         return err;
549 }
550
551 static int rtnl_getlink(struct sk_buff *skb, struct nlmsghdr* nlh, void *arg)
552 {
553         struct ifinfomsg *ifm;
554         struct nlattr *tb[IFLA_MAX+1];
555         struct net_device *dev = NULL;
556         struct sk_buff *nskb;
557         char *iw_buf = NULL, *iw = NULL;
558         int iw_buf_len = 0;
559         int err, payload;
560
561         err = nlmsg_parse(nlh, sizeof(*ifm), tb, IFLA_MAX, ifla_policy);
562         if (err < 0)
563                 goto errout;
564
565         ifm = nlmsg_data(nlh);
566         if (ifm->ifi_index >= 0) {
567                 dev = dev_get_by_index(ifm->ifi_index);
568                 if (dev == NULL)
569                         return -ENODEV;
570         } else
571                 return -EINVAL;
572
573
574 #ifdef CONFIG_NET_WIRELESS_RTNETLINK
575         if (tb[IFLA_WIRELESS]) {
576                 /* Call Wireless Extensions. We need to know the size before
577                  * we can alloc. Various stuff checked in there... */
578                 err = wireless_rtnetlink_get(dev, nla_data(tb[IFLA_WIRELESS]),
579                                              nla_len(tb[IFLA_WIRELESS]),
580                                              &iw_buf, &iw_buf_len);
581                 if (err < 0)
582                         goto errout;
583
584                 iw += IW_EV_POINT_OFF;
585         }
586 #endif  /* CONFIG_NET_WIRELESS_RTNETLINK */
587
588         payload = NLMSG_ALIGN(sizeof(struct ifinfomsg) +
589                               nla_total_size(iw_buf_len));
590         nskb = nlmsg_new(nlmsg_total_size(payload), GFP_KERNEL);
591         if (nskb == NULL) {
592                 err = -ENOBUFS;
593                 goto errout;
594         }
595
596         err = rtnl_fill_ifinfo(nskb, dev, iw, iw_buf_len, RTM_NEWLINK,
597                                NETLINK_CB(skb).pid, nlh->nlmsg_seq, 0, 0);
598         if (err <= 0) {
599                 kfree_skb(skb);
600                 goto errout;
601         }
602
603         err = rtnl_unicast(skb, NETLINK_CB(skb).pid);
604 errout:
605         kfree(iw_buf);
606         dev_put(dev);
607
608         return err;
609 }
610
611 static int rtnl_dump_all(struct sk_buff *skb, struct netlink_callback *cb)
612 {
613         int idx;
614         int s_idx = cb->family;
615
616         if (s_idx == 0)
617                 s_idx = 1;
618         for (idx=1; idx<NPROTO; idx++) {
619                 int type = cb->nlh->nlmsg_type-RTM_BASE;
620                 if (idx < s_idx || idx == PF_PACKET)
621                         continue;
622                 if (rtnetlink_links[idx] == NULL ||
623                     rtnetlink_links[idx][type].dumpit == NULL)
624                         continue;
625                 if (idx > s_idx)
626                         memset(&cb->args[0], 0, sizeof(cb->args));
627                 if (rtnetlink_links[idx][type].dumpit(skb, cb))
628                         break;
629         }
630         cb->family = idx;
631
632         return skb->len;
633 }
634
635 void rtmsg_ifinfo(int type, struct net_device *dev, unsigned change)
636 {
637         struct sk_buff *skb;
638         int err = -ENOBUFS;
639
640         skb = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
641         if (skb == NULL)
642                 goto errout;
643
644         err = rtnl_fill_ifinfo(skb, dev, NULL, 0, type, 0, 0, change, 0);
645         if (err < 0) {
646                 kfree_skb(skb);
647                 goto errout;
648         }
649
650         err = rtnl_notify(skb, 0, RTNLGRP_LINK, NULL, GFP_KERNEL);
651 errout:
652         if (err < 0)
653                 rtnl_set_sk_err(RTNLGRP_LINK, err);
654 }
655
656 /* Protected by RTNL sempahore.  */
657 static struct rtattr **rta_buf;
658 static int rtattr_max;
659
660 /* Process one rtnetlink message. */
661
662 static __inline__ int
663 rtnetlink_rcv_msg(struct sk_buff *skb, struct nlmsghdr *nlh, int *errp)
664 {
665         struct rtnetlink_link *link;
666         struct rtnetlink_link *link_tab;
667         int sz_idx, kind;
668         int min_len;
669         int family;
670         int type;
671         int err;
672
673         /* Only requests are handled by kernel now */
674         if (!(nlh->nlmsg_flags&NLM_F_REQUEST))
675                 return 0;
676
677         type = nlh->nlmsg_type;
678
679         /* A control message: ignore them */
680         if (type < RTM_BASE)
681                 return 0;
682
683         /* Unknown message: reply with EINVAL */
684         if (type > RTM_MAX)
685                 goto err_inval;
686
687         type -= RTM_BASE;
688
689         /* All the messages must have at least 1 byte length */
690         if (nlh->nlmsg_len < NLMSG_LENGTH(sizeof(struct rtgenmsg)))
691                 return 0;
692
693         family = ((struct rtgenmsg*)NLMSG_DATA(nlh))->rtgen_family;
694         if (family >= NPROTO) {
695                 *errp = -EAFNOSUPPORT;
696                 return -1;
697         }
698
699         link_tab = rtnetlink_links[family];
700         if (link_tab == NULL)
701                 link_tab = rtnetlink_links[PF_UNSPEC];
702         link = &link_tab[type];
703
704         sz_idx = type>>2;
705         kind = type&3;
706
707         if (kind != 2 && security_netlink_recv(skb, CAP_NET_ADMIN)) {
708                 *errp = -EPERM;
709                 return -1;
710         }
711
712         if (kind == 2 && nlh->nlmsg_flags&NLM_F_DUMP) {
713                 if (link->dumpit == NULL)
714                         link = &(rtnetlink_links[PF_UNSPEC][type]);
715
716                 if (link->dumpit == NULL)
717                         goto err_inval;
718
719                 if ((*errp = netlink_dump_start(rtnl, skb, nlh,
720                                                 link->dumpit, NULL)) != 0) {
721                         return -1;
722                 }
723
724                 netlink_queue_skip(nlh, skb);
725                 return -1;
726         }
727
728         memset(rta_buf, 0, (rtattr_max * sizeof(struct rtattr *)));
729
730         min_len = rtm_min[sz_idx];
731         if (nlh->nlmsg_len < min_len)
732                 goto err_inval;
733
734         if (nlh->nlmsg_len > min_len) {
735                 int attrlen = nlh->nlmsg_len - NLMSG_ALIGN(min_len);
736                 struct rtattr *attr = (void*)nlh + NLMSG_ALIGN(min_len);
737
738                 while (RTA_OK(attr, attrlen)) {
739                         unsigned flavor = attr->rta_type;
740                         if (flavor) {
741                                 if (flavor > rta_max[sz_idx])
742                                         goto err_inval;
743                                 rta_buf[flavor-1] = attr;
744                         }
745                         attr = RTA_NEXT(attr, attrlen);
746                 }
747         }
748
749         if (link->doit == NULL)
750                 link = &(rtnetlink_links[PF_UNSPEC][type]);
751         if (link->doit == NULL)
752                 goto err_inval;
753         err = link->doit(skb, nlh, (void *)&rta_buf[0]);
754
755         *errp = err;
756         return err;
757
758 err_inval:
759         *errp = -EINVAL;
760         return -1;
761 }
762
763 static void rtnetlink_rcv(struct sock *sk, int len)
764 {
765         unsigned int qlen = 0;
766
767         do {
768                 mutex_lock(&rtnl_mutex);
769                 netlink_run_queue(sk, &qlen, &rtnetlink_rcv_msg);
770                 mutex_unlock(&rtnl_mutex);
771
772                 netdev_run_todo();
773         } while (qlen);
774 }
775
776 static struct rtnetlink_link link_rtnetlink_table[RTM_NR_MSGTYPES] =
777 {
778         [RTM_GETLINK     - RTM_BASE] = { .doit   = rtnl_getlink,
779                                          .dumpit = rtnl_dump_ifinfo      },
780         [RTM_SETLINK     - RTM_BASE] = { .doit   = rtnl_setlink          },
781         [RTM_GETADDR     - RTM_BASE] = { .dumpit = rtnl_dump_all         },
782         [RTM_GETROUTE    - RTM_BASE] = { .dumpit = rtnl_dump_all         },
783         [RTM_NEWNEIGH    - RTM_BASE] = { .doit   = neigh_add             },
784         [RTM_DELNEIGH    - RTM_BASE] = { .doit   = neigh_delete          },
785         [RTM_GETNEIGH    - RTM_BASE] = { .dumpit = neigh_dump_info       },
786 #ifdef CONFIG_FIB_RULES
787         [RTM_NEWRULE     - RTM_BASE] = { .doit   = fib_nl_newrule        },
788         [RTM_DELRULE     - RTM_BASE] = { .doit   = fib_nl_delrule        },
789 #endif
790         [RTM_GETRULE     - RTM_BASE] = { .dumpit = rtnl_dump_all         },
791         [RTM_GETNEIGHTBL - RTM_BASE] = { .dumpit = neightbl_dump_info    },
792         [RTM_SETNEIGHTBL - RTM_BASE] = { .doit   = neightbl_set          },
793 };
794
795 static int rtnetlink_event(struct notifier_block *this, unsigned long event, void *ptr)
796 {
797         struct net_device *dev = ptr;
798         switch (event) {
799         case NETDEV_UNREGISTER:
800                 rtmsg_ifinfo(RTM_DELLINK, dev, ~0U);
801                 break;
802         case NETDEV_REGISTER:
803                 rtmsg_ifinfo(RTM_NEWLINK, dev, ~0U);
804                 break;
805         case NETDEV_UP:
806         case NETDEV_DOWN:
807                 rtmsg_ifinfo(RTM_NEWLINK, dev, IFF_UP|IFF_RUNNING);
808                 break;
809         case NETDEV_CHANGE:
810         case NETDEV_GOING_DOWN:
811                 break;
812         default:
813                 rtmsg_ifinfo(RTM_NEWLINK, dev, 0);
814                 break;
815         }
816         return NOTIFY_DONE;
817 }
818
819 static struct notifier_block rtnetlink_dev_notifier = {
820         .notifier_call  = rtnetlink_event,
821 };
822
823 void __init rtnetlink_init(void)
824 {
825         int i;
826
827         rtattr_max = 0;
828         for (i = 0; i < ARRAY_SIZE(rta_max); i++)
829                 if (rta_max[i] > rtattr_max)
830                         rtattr_max = rta_max[i];
831         rta_buf = kmalloc(rtattr_max * sizeof(struct rtattr *), GFP_KERNEL);
832         if (!rta_buf)
833                 panic("rtnetlink_init: cannot allocate rta_buf\n");
834
835         rtnl = netlink_kernel_create(NETLINK_ROUTE, RTNLGRP_MAX, rtnetlink_rcv,
836                                      THIS_MODULE);
837         if (rtnl == NULL)
838                 panic("rtnetlink_init: cannot initialize rtnetlink\n");
839         netlink_set_nonroot(NETLINK_ROUTE, NL_NONROOT_RECV);
840         register_netdevice_notifier(&rtnetlink_dev_notifier);
841         rtnetlink_links[PF_UNSPEC] = link_rtnetlink_table;
842         rtnetlink_links[PF_PACKET] = link_rtnetlink_table;
843 }
844
845 EXPORT_SYMBOL(__rta_fill);
846 EXPORT_SYMBOL(rtattr_strlcpy);
847 EXPORT_SYMBOL(rtattr_parse);
848 EXPORT_SYMBOL(rtnetlink_links);
849 EXPORT_SYMBOL(rtnetlink_put_metrics);
850 EXPORT_SYMBOL(rtnl_lock);
851 EXPORT_SYMBOL(rtnl_trylock);
852 EXPORT_SYMBOL(rtnl_unlock);
853 EXPORT_SYMBOL(rtnl_unicast);
854 EXPORT_SYMBOL(rtnl_notify);
855 EXPORT_SYMBOL(rtnl_set_sk_err);