https://source.android.com/docs/security/bulletin/2023-07-01 CVE-2022-42703 CVE-2023-21255 CVE-2023-25012 * tag 'ASB-2023-07-05_4.19-stable' of https://android.googlesource.com/kernel/common: Linux 4.19.288 i2c: imx-lpi2c: fix type char overflow issue when calculating the clock cycle x86/apic: Fix kernel panic when booting with intremap=off and x2apic_phys drm/radeon: fix race condition UAF in radeon_gem_set_domain_ioctl drm/exynos: fix race condition UAF in exynos_g2d_exec_ioctl drm/exynos: vidi: fix a wrong error return ASoC: nau8824: Add quirk to active-high jack-detect s390/cio: unregister device when the only path is gone usb: gadget: udc: fix NULL dereference in remove() nfcsim.c: Fix error checking for debugfs_create_dir media: cec: core: don't set last_initiator if tx in progress arm64: Add missing Set/Way CMO encodings HID: wacom: Add error check to wacom_parse_and_register() scsi: target: iscsi: Prevent login threads from racing between each other sch_netem: acquire qdisc lock in netem_change() netfilter: nfnetlink_osf: fix module autoload netfilter: nf_tables: disallow element updates of bound anonymous sets be2net: Extend xmit workaround to BE3 chip mmc: usdhi60rol0: fix deferred probing mmc: sdhci-acpi: fix deferred probing mmc: omap_hsmmc: fix deferred probing mmc: omap: fix deferred probing mmc: mvsdio: fix deferred probing mmc: mvsdio: convert to devm_platform_ioremap_resource mmc: mtk-sd: fix deferred probing net: qca_spi: Avoid high load if QCA7000 is not available xfrm: Linearize the skb after offloading if needed. ieee802154: hwsim: Fix possible memory leaks rcu: Upgrade rcu_swap_protected() to rcu_replace_pointer() nilfs2: prevent general protection fault in nilfs_clear_dirty_page() cgroup: Do not corrupt task iteration when rebinding subsystem PCI: hv: Fix a race condition bug in hv_pci_query_relations() Drivers: hv: vmbus: Fix vmbus_wait_for_unload() to scan present CPUs nilfs2: fix buffer corruption due to concurrent device reads ipmi: move message error checking to avoid deadlock ipmi: Make the smi watcher be disabled immediately when not needed x86/purgatory: remove PGO flags nilfs2: reject devices with insufficient block count serial: lantiq: add missing interrupt ack serial: lantiq: Do not swap register read/writes serial: lantiq: Use readl/writel instead of ltq_r32/ltq_w32 serial: lantiq: Change ltq_w32_mask to asc_update_bits Linux 4.19.287 mmc: block: ensure error propagation for non-blk powerpc: Fix defconfig choice logic when cross compiling drm/nouveau/kms: Fix NULL pointer dereference in nouveau_connector_detect_depth neighbour: delete neigh_lookup_nodev as not used net: Remove unused inline function dst_hold_and_use() neighbour: Remove unused inline function neigh_key_eq16() selftests/ptp: Fix timestamp printf format for PTP_SYS_OFFSET net: tipc: resize nlattr array to correct size net: lapbether: only support ethernet devices drm/nouveau: add nv_encoder pointer check for NULL drm/nouveau/kms: Don't change EDID when it hasn't actually changed drm/nouveau/dp: check for NULL nv_connector->native_mode igb: fix nvm.ops.read() error handling sctp: fix an error code in sctp_sf_eat_auth() IB/isert: Fix incorrect release of isert connection IB/isert: Fix possible list corruption in CMA handler IB/isert: Fix dead lock in ib_isert IB/uverbs: Fix to consider event queue closing also upon non-blocking mode RDMA/rxe: Fix the use-before-initialization error of resp_pkts RDMA/rxe: Removed unused name from rxe_task struct RDMA/rxe: Remove the unused variable obj ping6: Fix send to link-local addresses with VRF. netfilter: nfnetlink: skip error delivery on batch in case of ENOMEM usb: gadget: f_ncm: Fix NTP-32 support usb: gadget: f_ncm: Add OS descriptor support usb: dwc3: gadget: Reset num TRBs before giving back the request USB: serial: option: add Quectel EM061KGL series Remove DECnet support from kernel net: usb: qmi_wwan: add support for Compal RXM-G1 RDMA/uverbs: Restrict usage of privileged QKEYs nouveau: fix client work fence deletion race powerpc/purgatory: remove PGO flags kexec: support purgatories with .text.hot sections nilfs2: fix possible out-of-bounds segment allocation in resize ioctl nilfs2: fix incomplete buffer cleanup in nilfs_btnode_abort_change_key() nios2: dts: Fix tse_mac "max-frame-size" property ocfs2: check new file size on fallocate call ocfs2: fix use-after-free when unmounting read-only filesystem xen/blkfront: Only check REQ_FUA for writes mips: Move initrd_start check after initrd address sanitisation. MIPS: Alchemy: fix dbdma2 parisc: Improve cache flushing for PCXL in arch_sync_dma_for_cpu() power: supply: Fix logic checking if system is running from battery irqchip/meson-gpio: Mark OF related data as maybe unused regulator: Fix error checking for debugfs_create_dir power: supply: Ratelimit no data debug output ARM: dts: vexpress: add missing cache properties power: supply: bq27xxx: Use mod_delayed_work() instead of cancel() + schedule() power: supply: ab8500: Fix external_power_changed race Revert "tcp: deny tcp_disconnect() when threads are waiting" Revert "tcp: deny tcp_disconnect() when threads are waiting" ANDROID: GKI: update ABI xml for incrementalfs.ko Linux 4.19.286 Revert "staging: rtl8192e: Replace macro RTL_PCI_DEVICE with PCI_DEVICE" btrfs: unset reloc control if transaction commit fails in prepare_to_relocate() btrfs: check return value of btrfs_commit_transaction in relocation ext4: only check dquot_initialize_needed() when debugging i2c: sprd: Delete i2c adapter in .remove's error path pinctrl: meson-axg: add missing GPIOA_18 gpio group Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk ceph: fix use-after-free bug for inodes when flushing capsnaps drm/amdgpu: fix xclk freq on CHIP_STONEY Input: psmouse - fix OOB access in Elantech protocol Input: xpad - delete a Razer DeathAdder mouse VID/PID entry batman-adv: Broken sync while rescheduling delayed work lib: cpu_rmap: Fix potential use-after-free in irq_cpu_rmap_release() net: sched: fix possible refcount leak in tc_chain_tmplt_add() net: sched: move rtm_tca_policy declaration to include file rfs: annotate lockless accesses to RFS sock flow table rfs: annotate lockless accesses to sk->sk_rxhash Bluetooth: L2CAP: Add missing checks for invalid DCID Bluetooth: Fix l2cap_disconnect_req deadlock net: dsa: lan9303: allow vid != 0 in port_fdb_{add|del} methods spi: qup: Request DMA before enabling clocks i40e: fix build warnings in i40e_alloc.h i40iw: fix build warning in i40iw_manage_apbvt() UPSTREAM: net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize UPSTREAM: cdc_ncm: Fix the build warning UPSTREAM: cdc_ncm: Implement the 32-bit version of NCM Transfer Block Revert "tcp: reduce POLLOUT events caused by TCP_NOTSENT_LOWAT" Revert "tcp: return EPOLLOUT from tcp_poll only when notsent_bytes is half the limit" Revert "tcp: factor out __tcp_close() helper" Revert "tcp: add annotations around sk->sk_shutdown accesses" ANDROID: fix abi break in 4.19.284 for cpuhotplug.h UPSTREAM: mailbox: mailbox-test: fix a locking issue in mbox_test_message_write() UPSTREAM: mailbox: mailbox-test: Fix potential double-free in mbox_test_message_write() Linux 4.19.285 wifi: rtlwifi: 8192de: correct checking of IQK reload scsi: dpt_i2o: Do not process completions with invalid addresses scsi: dpt_i2o: Remove broken pass-through ioctl (I2OUSERCMD) regmap: Account for register length when chunking fbcon: Fix null-ptr-deref in soft_cursor ext4: add lockdep annotations for i_data_sem for ea_inode's selinux: don't use make's grouped targets feature yet tty: serial: fsl_lpuart: use UARTCTRL_TXINV to send break instead of UARTCTRL_SBK mmc: vub300: fix invalid response handling rsi: Remove unnecessary boolean condition regulator: da905{2,5}: Remove unnecessary array check hwmon: (scmi) Remove redundant pointer check wifi: rtlwifi: remove always-true condition pointed out by GCC 12 lib/dynamic_debug.c: use address-of operator on section symbols kernel/extable.c: use address-of operator on section symbols eth: sun: cassini: remove dead code gcc-12: disable '-Wdangling-pointer' warning for now ACPI: thermal: drop an always true check x86/boot: Wrap literal addresses in absolute_pointer() ata: libata-scsi: Use correct device no in ata_find_dev() scsi: stex: Fix gcc 13 warnings usb: gadget: f_fs: Add unbind event before functionfs_unbind net: usb: qmi_wwan: Set DTR quirk for BroadMobi BM818 iio: dac: build ad5758 driver when AD5758 is selected iio: dac: mcp4725: Fix i2c_master_send() return value handling HID: wacom: avoid integer overflow in wacom_intuos_inout() HID: google: add jewel USB id iio: adc: mxs-lradc: fix the order of two cleanup operations mailbox: mailbox-test: fix a locking issue in mbox_test_message_write() atm: hide unused procfs functions ALSA: oss: avoid missing-prototype warnings netfilter: conntrack: define variables exp_nat_nla_policy and any_addr with CONFIG_NF_NAT wifi: b43: fix incorrect __packed annotation scsi: core: Decrease scsi_device's iorequest_cnt if dispatch failed arm64/mm: mark private VM_FAULT_X defines as vm_fault_t ARM: dts: stm32: add pin map for CAN controller on stm32f7 wifi: rtl8xxxu: fix authentication timeout due to incorrect RCR value media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*() media: dvb-core: Fix use-after-free due on race condition at dvb_net media: mn88443x: fix !CONFIG_OF error by drop of_match_ptr from ID table media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb() media: dvb_ca_en50221: fix a size write bug media: netup_unidvb: fix irq init by register it at the end of probe media: dvb-usb: dw2102: fix uninit-value in su3000_read_mac_address media: dvb-usb: digitv: fix null-ptr-deref in digitv_i2c_xfer() media: dvb-usb-v2: rtl28xxu: fix null-ptr-deref in rtl28xxu_i2c_xfer media: dvb-usb-v2: ce6230: fix null-ptr-deref in ce6230_i2c_master_xfer() media: dvb-usb-v2: ec168: fix null-ptr-deref in ec168_i2c_xfer() media: dvb-usb: az6027: fix three null-ptr-deref in az6027_i2c_xfer() media: dvb_demux: fix a bug for the continuity counter ASoC: ssm2602: Add workaround for playback distortions xfrm: Check if_id in inbound policy/secpath match ASoC: dwc: limit the number of overrun messages nbd: Fix debugfs_create_dir error checking fbdev: stifb: Fix info entry in sti_struct on error path fbdev: modedb: Add 1920x1080 at 60 Hz video mode media: rcar-vin: Select correct interrupt mode for V4L2_FIELD_ALTERNATE ARM: 9295/1: unwind:fix unwind abort for uleb128 case mailbox: mailbox-test: Fix potential double-free in mbox_test_message_write() watchdog: menz069_wdt: fix watchdog initialisation net: dsa: mv88e6xxx: Increase wait after reset deactivation net/sched: flower: fix possible OOB write in fl_set_geneve_opt() udp6: Fix race condition in udp6_sendmsg & connect net/netlink: fix NETLINK_LIST_MEMBERSHIPS length report ocfs2/dlm: move BITS_TO_BYTES() to bitops.h for wider use net: sched: fix NULL pointer dereference in mq_attach net/sched: Prohibit regrafting ingress or clsact Qdiscs net/sched: Reserve TC_H_INGRESS (TC_H_CLSACT) for ingress (clsact) Qdiscs net/sched: sch_clsact: Only create under TC_H_CLSACT net/sched: sch_ingress: Only create under TC_H_INGRESS tcp: Return user_mss for TCP_MAXSEG in CLOSE/LISTEN state if user_mss set tcp: deny tcp_disconnect() when threads are waiting af_packet: do not use READ_ONCE() in packet_bind() amd-xgbe: fix the false linkup in xgbe_phy_status af_packet: Fix data-races of pkt_sk(sk)->num. netrom: fix info-leak in nr_write_internal() net/mlx5: fw_tracer, Fix event handling dmaengine: pl330: rename _start to prevent build error netfilter: ctnetlink: Support offloaded conntrack entry deletion ipv{4,6}/raw: fix output xfrm lookup wrt protocol bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() cdc_ncm: Fix the build warning power: supply: bq24190: Call power_supply_changed() after updating input current power: supply: core: Refactor power_supply_set_input_current_limit_from_supplier() power: supply: bq27xxx: After charger plug in/out wait 0.5s for things to stabilize net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize cdc_ncm: Implement the 32-bit version of NCM Transfer Block UPSTREAM: efi: rt-wrapper: Add missing include BACKPORT: arm64: efi: Execute runtime services from a dedicated stack Revert "uapi/linux/const.h: prefer ISO-friendly __typeof__" Linux 4.19.284 drivers: depend on HAS_IOMEM for devm_platform_ioremap_resource() 3c589_cs: Fix an error handling path in tc589_probe() forcedeth: Fix an error handling path in nv_probe() ASoC: Intel: Skylake: Fix declaration of enum skl_ch_cfg x86/show_trace_log_lvl: Ensure stack pointer is aligned, again xen/pvcalls-back: fix double frees with pvcalls_new_active_socket() coresight: Fix signedness bug in tmc_etr_buf_insert_barrier_packet() power: supply: sbs-charger: Fix INHIBITED bit for Status reg power: supply: bq27xxx: Fix poll_interval handling and races on remove power: supply: bq27xxx: Fix I2C IRQ race on remove power: supply: bq27xxx: Fix bq27xxx_battery_update() race condition power: supply: leds: Fix blink to LED on transition ipv6: Fix out-of-bounds access in ipv6_find_tlv() bpf: Fix mask generation for 32-bit narrow loads of 64-bit fields net: fix skb leak in __skb_tstamp_tx() media: radio-shark: Add endpoint checks USB: sisusbvga: Add endpoint checks USB: core: Add routines for endpoint checks in old drivers udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). ALSA: hda/realtek - Fix inverted bass GPIO pin on Acer 8951G ALSA: hda/realtek - Fixed one of HP ALC671 platform Headset Mic supported parisc: Fix flush_dcache_page() for usage from irq context selftests/memfd: Fix unknown type name build failure x86/mm: Avoid incomplete Global INVLPG flushes btrfs: use nofs when cleaning up aborted transactions parisc: Allow to reboot machine after system halt m68k: Move signal frame following exception on 68020/030 ALSA: hda/ca0132: add quirk for EVGA X299 DARK spi: fsl-cpm: Use 16 bit mode for large transfers with even size spi: fsl-spi: Re-organise transfer bits_per_word adaptation spi: spi-fsl-spi: automatically adapt bits-per-word in cpu mode s390/qdio: fix do_sqbs() inline assembly constraint s390/qdio: get rid of register asm vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF vc_screen: rewrite vcs_size to accept vc, not inode usb: gadget: u_ether: Fix host MAC address case usb: gadget: u_ether: Convert prints to device prints lib/string_helpers: Introduce string_upper() and string_lower() helpers ALSA: hda/realtek: Add a quirk for HP EliteDesk 805 ALSA: hda/realtek - ALC897 headset MIC no sound ALSA: hda/realtek - Add headset Mic support for Lenovo ALC897 platform ALSA: hda/realtek: Fix the mic type detection issue for ASUS G551JW ALSA: hda/realtek - The front Mic on a HP machine doesn't work ALSA: hda/realtek - Enable the headset of Acer N50-600 with ALC662 ALSA: hda/realtek - Enable headset mic of Acer X2660G with ALC662 ALSA: hda/realtek - Add Headset Mic supported for HP cPC ALSA: hda/realtek - More constifications Add Acer Aspire Ethos 8951G model quirk HID: wacom: Force pen out of prox if no events have been received in a while netfilter: nf_tables: do not allow RULE_ID to refer to another chain netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag netfilter: nf_tables: stricter validation of element data netfilter: nf_tables: allow up to 64 bytes in the set element data area netfilter: nf_tables: add nft_setelem_parse_key() netfilter: nf_tables: validate registers coming from userspace. netfilter: nftables: statify nft_parse_register() netfilter: nftables: add nft_parse_register_store() and use it netfilter: nftables: add nft_parse_register_load() and use it nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode() tpm/tpm_tis: Disable interrupts for more Lenovo devices ceph: force updating the msg pointer in non-split case serial: Add support for Advantech PCI-1611U card statfs: enforce statfs[64] structure initialization ALSA: hda: Add NVIDIA codec IDs a3 through a7 to patch table ALSA: hda: Fix Oops by 9.1 surround channel names usb: typec: altmodes/displayport: fix pin_assignment_show usb-storage: fix deadlock when a scsi command timeouts more than once vlan: fix a potential uninit-value in vlan_dev_hard_start_xmit() igb: fix bit_shift to be in [1..8] range cassini: Fix a memory leak in the error handling path of cas_init_one() net: bcmgenet: Restore phy_stop() depending upon suspend/close net: bcmgenet: Remove phy_stop() from bcmgenet_netif_stop() net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() drm/exynos: fix g2d_open/close helper function definitions media: netup_unidvb: fix use-after-free at del_timer() erspan: get the proto with the md version for collect_md ip_gre, ip6_gre: Fix race condition on o_seqno in collect_md mode ip6_gre: Make o_seqno start from 0 in native mode ip6_gre: Fix skb_under_panic in __gre6_xmit() serial: arc_uart: fix of_iomap leak in `arc_serial_probe` drivers: provide devm_platform_ioremap_resource() vsock: avoid to close connected socket after the timeout net: fec: Better handle pm_runtime_get() failing in .remove() af_key: Reject optional tunnel/BEET mode templates in outbound policies cpupower: Make TSC read per CPU for Mperf monitor btrfs: fix space cache inconsistency after error loading it from disk btrfs: replace calls to btrfs_find_free_ino with btrfs_find_free_objectid mfd: dln2: Fix memory leak in dln2_probe() phy: st: miphy28lp: use _poll_timeout functions for waits Input: xpad - add constants for GIP interface numbers clk: tegra20: fix gcc-7 constant overflow warning recordmcount: Fix memory leaks in the uwrite function sched: Fix KCSAN noinstr violation mcb-pci: Reallocate memory region to avoid memory overlapping serial: 8250: Reinit port->pm on port specific driver unbind usb: typec: tcpm: fix multiple times discover svids error HID: wacom: generic: Set battery quirk only when we see battery data spi: spi-imx: fix MX51_ECSPI_* macros when cs > 3 HID: logitech-hidpp: Reconcile USB and Unifying serials HID: logitech-hidpp: Don't use the USB serial for USB devices staging: rtl8192e: Replace macro RTL_PCI_DEVICE with PCI_DEVICE Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace f2fs: fix to drop all dirty pages during umount() if cp_error is set ext4: Fix best extent lstart adjustment logic in ext4_mb_new_inode_pa() ext4: set goal start correctly in ext4_mb_normalize_request gfs2: Fix inode height consistency check scsi: message: mptlan: Fix use after free bug in mptlan_remove() due to race condition lib: cpu_rmap: Avoid use after free on rmap->obj array entries net: Catch invalid index in XPS mapping net: pasemi: Fix return type of pasemi_mac_start_tx() ext2: Check block size validity during mount wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex ACPICA: ACPICA: check null return of ACPI_ALLOCATE_ZEROED in acpi_db_display_objects ACPICA: Avoid undefined behavior: applying zero offset to null pointer drm/tegra: Avoid potential 32-bit integer overflow ACPI: EC: Fix oops when removing custom query handlers firmware: arm_sdei: Fix sleep from invalid context BUG memstick: r592: Fix UAF bug in r592_remove due to race condition regmap: cache: Return error in cache sync operations for REGCACHE_NONE drm/amd/display: Use DC_LOG_DC in the trasform pixel function fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() af_unix: Fix data races around sk->sk_shutdown. af_unix: Fix a data race of sk->sk_receive_queue->qlen. net: datagram: fix data-races in datagram_poll() ipvlan:Fix out-of-bounds caused by unclear skb->cb tcp: add annotations around sk->sk_shutdown accesses tcp: factor out __tcp_close() helper tcp: return EPOLLOUT from tcp_poll only when notsent_bytes is half the limit tcp: reduce POLLOUT events caused by TCP_NOTSENT_LOWAT net: annotate sk->sk_err write from do_recvmmsg() netlink: annotate accesses to nlk->cb_running net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). Linux 4.19.283 mm/page_alloc: fix potential deadlock on zonelist_update_seq seqlock printk: declare printk_deferred_{enter,safe}() in include/linux/printk.h PCI: pciehp: Fix AB-BA deadlock between reset_lock and device_lock PCI: pciehp: Use down_read/write_nested(reset_lock) to fix lockdep errors drbd: correctly submit flush bio on barrier serial: 8250: Fix serial8250_tx_empty() race with DMA Tx tty: Prevent writing chars during tcsetattr TCSADRAIN/FLUSH ext4: fix invalid free tracking in ext4_xattr_move_to_block() ext4: remove a BUG_ON in ext4_mb_release_group_pa() ext4: bail out of ext4_xattr_ibody_get() fails for any reason ext4: add bounds checking in get_max_inline_xattr_value_size() ext4: improve error recovery code paths in __ext4_remount() ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum ext4: fix WARNING in mb_find_extent HID: wacom: Set a default resolution for older tablets drm/panel: otm8009a: Set backlight parent to panel device ARM: dts: s5pv210: correct MIPI CSIS clock name ARM: dts: exynos: fix WM8960 clock name in Itop Elite sh: nmi_debug: fix return value of __setup handler sh: init: use OF_EARLY_FLATTREE for early init sh: math-emu: fix macro redefined warning platform/x86: touchscreen_dmi: Add info for the Dexp Ursus KX210i cifs: fix pcchunk length type in smb2_copychunk_range btrfs: print-tree: parent bytenr must be aligned to sector size btrfs: fix btrfs_prev_leaf() to not return the same key twice perf symbols: Fix return incorrect build_id size in elf_read_build_id() perf map: Delete two variable initialisations before null pointer checks in sort__sym_from_cmp() perf vendor events power9: Remove UTF-8 characters from JSON files virtio_net: suppress cpu stall when free_unused_bufs virtio_net: split free_unused_bufs() ALSA: caiaq: input: Add error handling for unsupported input methods in `snd_usb_caiaq_input_init` drm/amdgpu: add a missing lock for AMDGPU_SCHED drm/amdgpu: Add command to override the context priority. drm/amdgpu: Put enable gfx off feature to a delay thread drm/amdgpu: Add amdgpu_gfx_off_ctrl function af_packet: Don't send zero-byte data in packet_sendmsg_spkt(). rxrpc: Fix hard call timeout units net/sched: act_mirred: Add carrier check writeback: fix call of incorrect macro net: dsa: mv88e6xxx: add mv88e6321 rsvd2cpu net: dsa: mv88e6xxx: Add missing watchdog ops for 6320 family sit: update dev->needed_headroom in ipip6_tunnel_bind_dev() relayfs: fix out-of-bounds access in relay_file_read kernel/relay.c: fix read_pos error when multiple readers dm verity: fix error handling for check_at_most_once on FEC dm verity: skip redundant verity_handle_err() on I/O errors ipmi: fix SSIF not responding under certain cond. ipmi_ssif: Rename idle state and check ipmi: Fix how the lower layers are told to watch for messages ipmi: Fix SSIF flag requests tick/nohz: Fix cpu_is_hotpluggable() by checking with nohz subsystem nohz: Add TICK_DEP_BIT_RCU netfilter: nf_tables: deactivate anonymous set from preparation phase debugobject: Ensure pool refill (again) perf auxtrace: Fix address filter entire kernel size dm ioctl: fix nested locking in table_clear() to remove deadlock concern dm flakey: fix a crash with invalid table line dm integrity: call kmem_cache_destroy() in dm_integrity_init() error path s390/dasd: fix hanging blockdevice after request requeue btrfs: scrub: reject unsupported scrub flags clk: rockchip: rk3399: allow clk_cifout to force clk_cifout_src to reparent wifi: rtl8xxxu: RTL8192EU always needs full init md/raid10: fix null-ptr-deref in raid10_sync_request nilfs2: fix infinite loop in nilfs_mdt_get_block() nilfs2: do not write dirty data after degenerating to read-only parisc: Fix argument pointer in real64_call_asm() dmaengine: at_xdmac: do not enable all cyclic channels phy: tegra: xusb: Add missing tegra_xusb_port_unregister for usb2_port and ulpi_port pwm: mtk-disp: Disable shadow registers before setting backlight values pwm: mtk-disp: Adjust the clocks to avoid them mismatch pwm: mtk-disp: Don't check the return code of pwmchip_remove() openrisc: Properly store r31 to pt_regs on unhandled exceptions RDMA/mlx5: Use correct device num_ports when modify DC SUNRPC: remove the maximum number of retries in call_bind_status NFSv4.1: Always send a RECLAIM_COMPLETE after establishing lease IB/hfi1: Fix SDMA mmu_rb_node not being evicted in LRU order clk: add missing of_node_put() in "assigned-clocks" property parsing power: supply: generic-adc-battery: fix unit scaling RDMA/mlx4: Prevent shift wrapping in set_user_sq_size() RDMA/rdmavt: Delete unnecessary NULL check perf/core: Fix hardlockup failure caused by perf throttle powerpc/rtas: use memmove for potentially overlapping buffer copy macintosh: via-pmu-led: requires ATA to be set powerpc/sysdev/tsi108: fix resource printk format warnings powerpc/wii: fix resource printk format warnings powerpc/mpc512x: fix resource printk format warning macintosh/windfarm_smu_sat: Add missing of_node_put() spmi: Add a check for remove callback when removing a SPMI driver staging: rtl8192e: Fix W_DISABLE# does not work after stop/start serial: 8250: Add missing wakeup event reporting tty: serial: fsl_lpuart: adjust buffer length to the intended size usb: chipidea: fix missing goto in `ci_hdrc_probe` sh: sq: Fix incorrect element size for allocating bitmap buffer uapi/linux/const.h: prefer ISO-friendly __typeof__ spi: cadence-quadspi: fix suspend-resume implementations mtd: spi-nor: cadence-quadspi: Handle probe deferral while requesting DMA channel mtd: spi-nor: cadence-quadspi: Don't initialize rx_dma_complete on failure mtd: spi-nor: cadence-quadspi: Make driver independent of flash geometry ia64: salinfo: placate defined-but-not-used warning ia64: mm/contig: fix section mismatch warning/error of: Fix modalias string generation vmci_host: fix a race condition in vmci_host_poll() causing GPF spi: fsl-spi: Fix CPM/QE mode Litte Endian spi: qup: Don't skip cleanup in remove's error path spi: qup: fix PM reference leak in spi_qup_remove() linux/vt_buffer.h: allow either builtin or modular for macros usb: gadget: udc: renesas_usb3: Fix use after free bug in renesas_usb3_remove due to race condition fpga: bridge: fix kernel-doc parameter description usb: host: xhci-rcar: remove leftover quirk handling pstore: Revert pmsg_lock back to a normal mutex tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp. net: amd: Fix link leak when verifying config failed netlink: Use copy_to_user() for optval in netlink_getsockopt(). Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" ipv4: Fix potential uninit variable access bug in __ip_make_skb() netfilter: nf_tables: don't write table validation state without mutex ixgbe: Enable setting RSS table to default values ixgbe: Allow flow hash to be set via ethtool wifi: iwlwifi: mvm: check firmware response size wifi: iwlwifi: make the loop for card preparation effective md/raid10: fix memleak of md thread md: update the optimal I/O size on reshape md/raid10: fix memleak for 'conf->bio_split' md/raid10: fix leak of 'r10bio->remaining' for recovery crypto: drbg - Only fail when jent is unavailable in FIPS mode crypto: drbg - make drbg_prepare_hrng() handle jent instantiation errors bpftool: Fix bug for long instructions in program CFG dumps wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_reg() wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_rfreg() rtlwifi: Replace RT_TRACE with rtl_dbg rtlwifi: Start changing RT_TRACE into rtl_dbg rtlwifi: rtl_pci: Fix memory leak when hardware init fails scsi: megaraid: Fix mega_cmd_done() CMDID_INT_CMDS scsi: target: iscsit: Fix TAS handling during conn cleanup net/packet: convert po->auxdata to an atomic flag net/packet: convert po->origdev to an atomic flag vlan: partially enable SIOCSHWTSTAMP in container scm: fix MSG_CTRUNC setting condition for SO_PASSSEC tools: bpftool: Remove invalid \' json escape wifi: ath6kl: reduce WARN to dev_dbg() in callback wifi: ath5k: fix an off by one check in ath5k_eeprom_read_freq_list() wifi: ath9k: hif_usb: fix memory leak of remain_skbs wifi: ath6kl: minor fix for allocation size debugobject: Prevent init race with static objects debugobjects: Move printk out of db->lock critical sections debugobjects: Add percpu free pools arm64: kgdb: Set PSTATE.SS to 1 to re-enable single-step x86/ioapic: Don't return 0 from arch_dynirq_lower_bound() media: rc: gpio-ir-recv: Fix support for wake-up media: rcar_fdp1: Fix refcount leak in probe and remove function media: rcar_fdp1: Fix the correct variable assignments media: saa7134: fix use after free bug in saa7134_finidev due to race condition media: dm1105: Fix use after free bug in dm1105_remove due to race condition x86/apic: Fix atomic update of offset in reserve_eilvt_offset() drm/msm/adreno: drop bogus pm_runtime_set_active() drm/msm/adreno: Defer enabling runpm until hw_init() firmware: qcom_scm: Clear download bit during reboot media: av7110: prevent underflow in write_ts_to_decoder() media: uapi: add MEDIA_BUS_FMT_METADATA_FIXED media bus format. media: bdisp: Add missing check for create_workqueue ARM: dts: qcom: ipq4019: Fix the PCI I/O port range EDAC/skx: Fix overflows on the DRAM row address mapping arrays EDAC, skx: Move debugfs node under EDAC's hierarchy drm/probe-helper: Cancel previous job before starting new one drm/vgem: add missing mutex_destroy drm/rockchip: Drop unbalanced obj unref selinux: ensure av_permissions.h is built when needed selinux: fix Makefile dependencies of flask.h ubifs: Free memory for tmpfile name ubi: Fix return value overwrite issue in try_write_vid_and_data() ubifs: Fix memleak when insert_old_idx() failed Revert "ubifs: dirty_cow_znode: Fix memleak in error handling path" i2c: omap: Fix standard mode false ACK readings KVM: nVMX: Emulate NOPs in L2, and PAUSE if it's not intercepted reiserfs: Add security prefix to xattr name in reiserfs_security_write() ring-buffer: Sync IRQ works before buffer destruction pwm: meson: Fix axg ao mux parents MIPS: fw: Allow firmware to pass a empty env xhci: fix debugfs register accesses while suspended debugfs: regset32: Add Runtime PM support staging: iio: resolver: ads1210: fix config mode perf sched: Cast PTHREAD_STACK_MIN to int as it may turn into sysconf(__SC_THREAD_STACK_MIN_VALUE) USB: dwc3: fix runtime pm imbalance on unbind stmmac: debugfs entry name is not be changed when udev rename device name. ASoC: Intel: bytcr_rt5640: Add quirk for the Acer Iconia One 7 B1-750 iio: adc: palmas_gpadc: fix NULL dereference on rmmod USB: serial: option: add UNISOC vendor and TOZED LT70C product bluetooth: Perform careful capability checks in hci_sock_ioctl() wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Conflicts: drivers/media/dvb-core/dvb_demux.c drivers/usb/dwc3/core.c drivers/usb/gadget/function/f_fs.c drivers/usb/gadget/function/f_ncm.c include/net/pkt_sched.h Change-Id: I5081b8f3529f4df573736bf7d69201f777754b74
717 lines
20 KiB
C
717 lines
20 KiB
C
/*
|
|
* INET An implementation of the TCP/IP protocol suite for the LINUX
|
|
* operating system. INET is implemented using the BSD Socket
|
|
* interface as the means of communication with the user level.
|
|
*
|
|
* Definitions for the IP module.
|
|
*
|
|
* Version: @(#)ip.h 1.0.2 05/07/93
|
|
*
|
|
* Authors: Ross Biro
|
|
* Fred N. van Kempen, <waltje@uWalt.NL.Mugnet.ORG>
|
|
* Alan Cox, <gw4pts@gw4pts.ampr.org>
|
|
*
|
|
* Changes:
|
|
* Mike McLagan : Routing by source
|
|
*
|
|
* This program is free software; you can redistribute it and/or
|
|
* modify it under the terms of the GNU General Public License
|
|
* as published by the Free Software Foundation; either version
|
|
* 2 of the License, or (at your option) any later version.
|
|
*/
|
|
#ifndef _IP_H
|
|
#define _IP_H
|
|
|
|
#include <linux/types.h>
|
|
#include <linux/ip.h>
|
|
#include <linux/in.h>
|
|
#include <linux/skbuff.h>
|
|
#include <linux/jhash.h>
|
|
|
|
#include <net/inet_sock.h>
|
|
#include <net/route.h>
|
|
#include <net/snmp.h>
|
|
#include <net/flow.h>
|
|
#include <net/flow_dissector.h>
|
|
#include <net/netns/hash.h>
|
|
#ifndef __GENKSYMS__
|
|
#include <net/lwtunnel.h>
|
|
#endif
|
|
|
|
#define IPV4_MAX_PMTU 65535U /* RFC 2675, Section 5.1 */
|
|
#define IPV4_MIN_MTU 68 /* RFC 791 */
|
|
|
|
struct sock;
|
|
|
|
struct inet_skb_parm {
|
|
int iif;
|
|
struct ip_options opt; /* Compiled IP options */
|
|
u16 flags;
|
|
|
|
#define IPSKB_FORWARDED BIT(0)
|
|
#define IPSKB_XFRM_TUNNEL_SIZE BIT(1)
|
|
#define IPSKB_XFRM_TRANSFORMED BIT(2)
|
|
#define IPSKB_FRAG_COMPLETE BIT(3)
|
|
#define IPSKB_REROUTED BIT(4)
|
|
#define IPSKB_DOREDIRECT BIT(5)
|
|
#define IPSKB_FRAG_PMTU BIT(6)
|
|
#define IPSKB_L3SLAVE BIT(7)
|
|
|
|
u16 frag_max_size;
|
|
};
|
|
|
|
static inline bool ipv4_l3mdev_skb(u16 flags)
|
|
{
|
|
return !!(flags & IPSKB_L3SLAVE);
|
|
}
|
|
|
|
static inline unsigned int ip_hdrlen(const struct sk_buff *skb)
|
|
{
|
|
return ip_hdr(skb)->ihl * 4;
|
|
}
|
|
|
|
struct ipcm_cookie {
|
|
struct sockcm_cookie sockc;
|
|
__be32 addr;
|
|
int oif;
|
|
struct ip_options_rcu *opt;
|
|
__u8 protocol;
|
|
__u8 ttl;
|
|
__s16 tos;
|
|
char priority;
|
|
__u16 gso_size;
|
|
};
|
|
|
|
static inline void ipcm_init(struct ipcm_cookie *ipcm)
|
|
{
|
|
*ipcm = (struct ipcm_cookie) { .tos = -1 };
|
|
}
|
|
|
|
static inline void ipcm_init_sk(struct ipcm_cookie *ipcm,
|
|
const struct inet_sock *inet)
|
|
{
|
|
ipcm_init(ipcm);
|
|
|
|
ipcm->sockc.tsflags = inet->sk.sk_tsflags;
|
|
ipcm->oif = inet->sk.sk_bound_dev_if;
|
|
ipcm->addr = inet->inet_saddr;
|
|
ipcm->protocol = inet->inet_num;
|
|
}
|
|
|
|
#define IPCB(skb) ((struct inet_skb_parm*)((skb)->cb))
|
|
#define PKTINFO_SKB_CB(skb) ((struct in_pktinfo *)((skb)->cb))
|
|
|
|
/* return enslaved device index if relevant */
|
|
static inline int inet_sdif(struct sk_buff *skb)
|
|
{
|
|
#if IS_ENABLED(CONFIG_NET_L3_MASTER_DEV)
|
|
if (skb && ipv4_l3mdev_skb(IPCB(skb)->flags))
|
|
return IPCB(skb)->iif;
|
|
#endif
|
|
return 0;
|
|
}
|
|
|
|
/* Special input handler for packets caught by router alert option.
|
|
They are selected only by protocol field, and then processed likely
|
|
local ones; but only if someone wants them! Otherwise, router
|
|
not running rsvpd will kill RSVP.
|
|
|
|
It is user level problem, what it will make with them.
|
|
I have no idea, how it will masquearde or NAT them (it is joke, joke :-)),
|
|
but receiver should be enough clever f.e. to forward mtrace requests,
|
|
sent to multicast group to reach destination designated router.
|
|
*/
|
|
|
|
struct ip_ra_chain {
|
|
struct ip_ra_chain __rcu *next;
|
|
struct sock *sk;
|
|
union {
|
|
void (*destructor)(struct sock *);
|
|
struct sock *saved_sk;
|
|
};
|
|
struct rcu_head rcu;
|
|
};
|
|
|
|
/* IP flags. */
|
|
#define IP_CE 0x8000 /* Flag: "Congestion" */
|
|
#define IP_DF 0x4000 /* Flag: "Don't Fragment" */
|
|
#define IP_MF 0x2000 /* Flag: "More Fragments" */
|
|
#define IP_OFFSET 0x1FFF /* "Fragment Offset" part */
|
|
|
|
#define IP_FRAG_TIME (30 * HZ) /* fragment lifetime */
|
|
|
|
struct msghdr;
|
|
struct net_device;
|
|
struct packet_type;
|
|
struct rtable;
|
|
struct sockaddr;
|
|
|
|
int igmp_mc_init(void);
|
|
|
|
/*
|
|
* Functions provided by ip.c
|
|
*/
|
|
|
|
int ip_build_and_send_pkt(struct sk_buff *skb, const struct sock *sk,
|
|
__be32 saddr, __be32 daddr,
|
|
struct ip_options_rcu *opt);
|
|
int ip_rcv(struct sk_buff *skb, struct net_device *dev, struct packet_type *pt,
|
|
struct net_device *orig_dev);
|
|
void ip_list_rcv(struct list_head *head, struct packet_type *pt,
|
|
struct net_device *orig_dev);
|
|
int ip_local_deliver(struct sk_buff *skb);
|
|
void ip_protocol_deliver_rcu(struct net *net, struct sk_buff *skb, int proto);
|
|
int ip_mr_input(struct sk_buff *skb);
|
|
int ip_output(struct net *net, struct sock *sk, struct sk_buff *skb);
|
|
int ip_mc_output(struct net *net, struct sock *sk, struct sk_buff *skb);
|
|
int ip_do_fragment(struct net *net, struct sock *sk, struct sk_buff *skb,
|
|
int (*output)(struct net *, struct sock *, struct sk_buff *));
|
|
void ip_send_check(struct iphdr *ip);
|
|
int __ip_local_out(struct net *net, struct sock *sk, struct sk_buff *skb);
|
|
int ip_local_out(struct net *net, struct sock *sk, struct sk_buff *skb);
|
|
|
|
int __ip_queue_xmit(struct sock *sk, struct sk_buff *skb, struct flowi *fl,
|
|
__u8 tos);
|
|
void ip_init(void);
|
|
int ip_append_data(struct sock *sk, struct flowi4 *fl4,
|
|
int getfrag(void *from, char *to, int offset, int len,
|
|
int odd, struct sk_buff *skb),
|
|
void *from, int len, int protolen,
|
|
struct ipcm_cookie *ipc,
|
|
struct rtable **rt,
|
|
unsigned int flags);
|
|
int ip_generic_getfrag(void *from, char *to, int offset, int len, int odd,
|
|
struct sk_buff *skb);
|
|
ssize_t ip_append_page(struct sock *sk, struct flowi4 *fl4, struct page *page,
|
|
int offset, size_t size, int flags);
|
|
struct sk_buff *__ip_make_skb(struct sock *sk, struct flowi4 *fl4,
|
|
struct sk_buff_head *queue,
|
|
struct inet_cork *cork);
|
|
int ip_send_skb(struct net *net, struct sk_buff *skb);
|
|
int ip_push_pending_frames(struct sock *sk, struct flowi4 *fl4);
|
|
void ip_flush_pending_frames(struct sock *sk);
|
|
struct sk_buff *ip_make_skb(struct sock *sk, struct flowi4 *fl4,
|
|
int getfrag(void *from, char *to, int offset,
|
|
int len, int odd, struct sk_buff *skb),
|
|
void *from, int length, int transhdrlen,
|
|
struct ipcm_cookie *ipc, struct rtable **rtp,
|
|
struct inet_cork *cork, unsigned int flags);
|
|
|
|
static inline int ip_queue_xmit(struct sock *sk, struct sk_buff *skb,
|
|
struct flowi *fl)
|
|
{
|
|
return __ip_queue_xmit(sk, skb, fl, inet_sk(sk)->tos);
|
|
}
|
|
|
|
static inline struct sk_buff *ip_finish_skb(struct sock *sk, struct flowi4 *fl4)
|
|
{
|
|
return __ip_make_skb(sk, fl4, &sk->sk_write_queue, &inet_sk(sk)->cork.base);
|
|
}
|
|
|
|
static inline __u8 get_rttos(struct ipcm_cookie* ipc, struct inet_sock *inet)
|
|
{
|
|
return (ipc->tos != -1) ? RT_TOS(ipc->tos) : RT_TOS(inet->tos);
|
|
}
|
|
|
|
static inline __u8 get_rtconn_flags(struct ipcm_cookie* ipc, struct sock* sk)
|
|
{
|
|
return (ipc->tos != -1) ? RT_CONN_FLAGS_TOS(sk, ipc->tos) : RT_CONN_FLAGS(sk);
|
|
}
|
|
|
|
/* datagram.c */
|
|
int __ip4_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len);
|
|
int ip4_datagram_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len);
|
|
|
|
void ip4_datagram_release_cb(struct sock *sk);
|
|
|
|
struct ip_reply_arg {
|
|
struct kvec iov[1];
|
|
int flags;
|
|
__wsum csum;
|
|
int csumoffset; /* u16 offset of csum in iov[0].iov_base */
|
|
/* -1 if not needed */
|
|
int bound_dev_if;
|
|
u8 tos;
|
|
kuid_t uid;
|
|
};
|
|
|
|
#define IP_REPLY_ARG_NOSRCCHECK 1
|
|
|
|
static inline __u8 ip_reply_arg_flowi_flags(const struct ip_reply_arg *arg)
|
|
{
|
|
return (arg->flags & IP_REPLY_ARG_NOSRCCHECK) ? FLOWI_FLAG_ANYSRC : 0;
|
|
}
|
|
|
|
void ip_send_unicast_reply(struct sock *sk, struct sk_buff *skb,
|
|
const struct ip_options *sopt,
|
|
__be32 daddr, __be32 saddr,
|
|
const struct ip_reply_arg *arg,
|
|
unsigned int len);
|
|
|
|
#define IP_INC_STATS(net, field) SNMP_INC_STATS64((net)->mib.ip_statistics, field)
|
|
#define __IP_INC_STATS(net, field) __SNMP_INC_STATS64((net)->mib.ip_statistics, field)
|
|
#define IP_ADD_STATS(net, field, val) SNMP_ADD_STATS64((net)->mib.ip_statistics, field, val)
|
|
#define __IP_ADD_STATS(net, field, val) __SNMP_ADD_STATS64((net)->mib.ip_statistics, field, val)
|
|
#define IP_UPD_PO_STATS(net, field, val) SNMP_UPD_PO_STATS64((net)->mib.ip_statistics, field, val)
|
|
#define __IP_UPD_PO_STATS(net, field, val) __SNMP_UPD_PO_STATS64((net)->mib.ip_statistics, field, val)
|
|
#define NET_INC_STATS(net, field) SNMP_INC_STATS((net)->mib.net_statistics, field)
|
|
#define __NET_INC_STATS(net, field) __SNMP_INC_STATS((net)->mib.net_statistics, field)
|
|
#define NET_ADD_STATS(net, field, adnd) SNMP_ADD_STATS((net)->mib.net_statistics, field, adnd)
|
|
#define __NET_ADD_STATS(net, field, adnd) __SNMP_ADD_STATS((net)->mib.net_statistics, field, adnd)
|
|
|
|
u64 snmp_get_cpu_field(void __percpu *mib, int cpu, int offct);
|
|
unsigned long snmp_fold_field(void __percpu *mib, int offt);
|
|
#if BITS_PER_LONG==32
|
|
u64 snmp_get_cpu_field64(void __percpu *mib, int cpu, int offct,
|
|
size_t syncp_offset);
|
|
u64 snmp_fold_field64(void __percpu *mib, int offt, size_t sync_off);
|
|
#else
|
|
static inline u64 snmp_get_cpu_field64(void __percpu *mib, int cpu, int offct,
|
|
size_t syncp_offset)
|
|
{
|
|
return snmp_get_cpu_field(mib, cpu, offct);
|
|
|
|
}
|
|
|
|
static inline u64 snmp_fold_field64(void __percpu *mib, int offt, size_t syncp_off)
|
|
{
|
|
return snmp_fold_field(mib, offt);
|
|
}
|
|
#endif
|
|
|
|
#define snmp_get_cpu_field64_batch(buff64, stats_list, mib_statistic, offset) \
|
|
{ \
|
|
int i, c; \
|
|
for_each_possible_cpu(c) { \
|
|
for (i = 0; stats_list[i].name; i++) \
|
|
buff64[i] += snmp_get_cpu_field64( \
|
|
mib_statistic, \
|
|
c, stats_list[i].entry, \
|
|
offset); \
|
|
} \
|
|
}
|
|
|
|
#define snmp_get_cpu_field_batch(buff, stats_list, mib_statistic) \
|
|
{ \
|
|
int i, c; \
|
|
for_each_possible_cpu(c) { \
|
|
for (i = 0; stats_list[i].name; i++) \
|
|
buff[i] += snmp_get_cpu_field( \
|
|
mib_statistic, \
|
|
c, stats_list[i].entry); \
|
|
} \
|
|
}
|
|
|
|
void inet_get_local_port_range(struct net *net, int *low, int *high);
|
|
|
|
#ifdef CONFIG_SYSCTL
|
|
static inline int inet_is_local_reserved_port(struct net *net, int port)
|
|
{
|
|
if (!net->ipv4.sysctl_local_reserved_ports)
|
|
return 0;
|
|
return test_bit(port, net->ipv4.sysctl_local_reserved_ports);
|
|
}
|
|
|
|
static inline bool sysctl_dev_name_is_allowed(const char *name)
|
|
{
|
|
return strcmp(name, "default") != 0 && strcmp(name, "all") != 0;
|
|
}
|
|
|
|
static inline int inet_prot_sock(struct net *net)
|
|
{
|
|
return net->ipv4.sysctl_ip_prot_sock;
|
|
}
|
|
|
|
#else
|
|
static inline int inet_is_local_reserved_port(struct net *net, int port)
|
|
{
|
|
return 0;
|
|
}
|
|
|
|
static inline int inet_prot_sock(struct net *net)
|
|
{
|
|
return PROT_SOCK;
|
|
}
|
|
#endif
|
|
|
|
__be32 inet_current_timestamp(void);
|
|
|
|
extern int sysctl_reserved_port_bind;
|
|
|
|
/* From inetpeer.c */
|
|
extern int inet_peer_threshold;
|
|
extern int inet_peer_minttl;
|
|
extern int inet_peer_maxttl;
|
|
|
|
void ipfrag_init(void);
|
|
|
|
void ip_static_sysctl_init(void);
|
|
|
|
#define IP4_REPLY_MARK(net, mark) \
|
|
(READ_ONCE((net)->ipv4.sysctl_fwmark_reflect) ? (mark) : 0)
|
|
|
|
static inline bool ip_is_fragment(const struct iphdr *iph)
|
|
{
|
|
return (iph->frag_off & htons(IP_MF | IP_OFFSET)) != 0;
|
|
}
|
|
|
|
#ifdef CONFIG_INET
|
|
#include <net/dst.h>
|
|
|
|
/* The function in 2.2 was invalid, producing wrong result for
|
|
* check=0xFEFF. It was noticed by Arthur Skawina _year_ ago. --ANK(000625) */
|
|
static inline
|
|
int ip_decrease_ttl(struct iphdr *iph)
|
|
{
|
|
u32 check = (__force u32)iph->check;
|
|
check += (__force u32)htons(0x0100);
|
|
iph->check = (__force __sum16)(check + (check>=0xFFFF));
|
|
return --iph->ttl;
|
|
}
|
|
|
|
static inline int ip_mtu_locked(const struct dst_entry *dst)
|
|
{
|
|
const struct rtable *rt = (const struct rtable *)dst;
|
|
|
|
return rt->rt_mtu_locked || dst_metric_locked(dst, RTAX_MTU);
|
|
}
|
|
|
|
static inline
|
|
int ip_dont_fragment(const struct sock *sk, const struct dst_entry *dst)
|
|
{
|
|
u8 pmtudisc = READ_ONCE(inet_sk(sk)->pmtudisc);
|
|
|
|
return pmtudisc == IP_PMTUDISC_DO ||
|
|
(pmtudisc == IP_PMTUDISC_WANT &&
|
|
!ip_mtu_locked(dst));
|
|
}
|
|
|
|
static inline bool ip_sk_accept_pmtu(const struct sock *sk)
|
|
{
|
|
return inet_sk(sk)->pmtudisc != IP_PMTUDISC_INTERFACE &&
|
|
inet_sk(sk)->pmtudisc != IP_PMTUDISC_OMIT;
|
|
}
|
|
|
|
static inline bool ip_sk_use_pmtu(const struct sock *sk)
|
|
{
|
|
return inet_sk(sk)->pmtudisc < IP_PMTUDISC_PROBE;
|
|
}
|
|
|
|
static inline bool ip_sk_ignore_df(const struct sock *sk)
|
|
{
|
|
return inet_sk(sk)->pmtudisc < IP_PMTUDISC_DO ||
|
|
inet_sk(sk)->pmtudisc == IP_PMTUDISC_OMIT;
|
|
}
|
|
|
|
static inline unsigned int ip_dst_mtu_maybe_forward(const struct dst_entry *dst,
|
|
bool forwarding)
|
|
{
|
|
struct net *net = dev_net(dst->dev);
|
|
unsigned int mtu;
|
|
|
|
if (READ_ONCE(net->ipv4.sysctl_ip_fwd_use_pmtu) ||
|
|
ip_mtu_locked(dst) ||
|
|
!forwarding)
|
|
return dst_mtu(dst);
|
|
|
|
/* 'forwarding = true' case should always honour route mtu */
|
|
mtu = dst_metric_raw(dst, RTAX_MTU);
|
|
if (!mtu)
|
|
mtu = min(READ_ONCE(dst->dev->mtu), IP_MAX_MTU);
|
|
|
|
return mtu - lwtunnel_headroom(dst->lwtstate, mtu);
|
|
}
|
|
|
|
static inline unsigned int ip_skb_dst_mtu(struct sock *sk,
|
|
const struct sk_buff *skb)
|
|
{
|
|
unsigned int mtu;
|
|
|
|
if (!sk || !sk_fullsock(sk) || ip_sk_use_pmtu(sk)) {
|
|
bool forwarding = IPCB(skb)->flags & IPSKB_FORWARDED;
|
|
|
|
return ip_dst_mtu_maybe_forward(skb_dst(skb), forwarding);
|
|
}
|
|
|
|
mtu = min(READ_ONCE(skb_dst(skb)->dev->mtu), IP_MAX_MTU);
|
|
return mtu - lwtunnel_headroom(skb_dst(skb)->lwtstate, mtu);
|
|
}
|
|
|
|
int ip_metrics_convert(struct net *net, struct nlattr *fc_mx, int fc_mx_len,
|
|
u32 *metrics);
|
|
|
|
u32 ip_idents_reserve(u32 hash, int segs);
|
|
void __ip_select_ident(struct net *net, struct iphdr *iph, int segs);
|
|
|
|
static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
|
|
struct sock *sk, int segs)
|
|
{
|
|
struct iphdr *iph = ip_hdr(skb);
|
|
|
|
/* We had many attacks based on IPID, use the private
|
|
* generator as much as we can.
|
|
*/
|
|
if (sk && inet_sk(sk)->inet_daddr) {
|
|
iph->id = htons(inet_sk(sk)->inet_id);
|
|
inet_sk(sk)->inet_id += segs;
|
|
return;
|
|
}
|
|
if ((iph->frag_off & htons(IP_DF)) && !skb->ignore_df) {
|
|
iph->id = 0;
|
|
} else {
|
|
/* Unfortunately we need the big hammer to get a suitable IPID */
|
|
__ip_select_ident(net, iph, segs);
|
|
}
|
|
}
|
|
|
|
static inline void ip_select_ident(struct net *net, struct sk_buff *skb,
|
|
struct sock *sk)
|
|
{
|
|
ip_select_ident_segs(net, skb, sk, 1);
|
|
}
|
|
|
|
static inline __wsum inet_compute_pseudo(struct sk_buff *skb, int proto)
|
|
{
|
|
return csum_tcpudp_nofold(ip_hdr(skb)->saddr, ip_hdr(skb)->daddr,
|
|
skb->len, proto, 0);
|
|
}
|
|
|
|
/* copy IPv4 saddr & daddr to flow_keys, possibly using 64bit load/store
|
|
* Equivalent to : flow->v4addrs.src = iph->saddr;
|
|
* flow->v4addrs.dst = iph->daddr;
|
|
*/
|
|
static inline void iph_to_flow_copy_v4addrs(struct flow_keys *flow,
|
|
const struct iphdr *iph)
|
|
{
|
|
BUILD_BUG_ON(offsetof(typeof(flow->addrs), v4addrs.dst) !=
|
|
offsetof(typeof(flow->addrs), v4addrs.src) +
|
|
sizeof(flow->addrs.v4addrs.src));
|
|
memcpy(&flow->addrs.v4addrs, &iph->saddr, sizeof(flow->addrs.v4addrs));
|
|
flow->control.addr_type = FLOW_DISSECTOR_KEY_IPV4_ADDRS;
|
|
}
|
|
|
|
static inline __wsum inet_gro_compute_pseudo(struct sk_buff *skb, int proto)
|
|
{
|
|
const struct iphdr *iph = skb_gro_network_header(skb);
|
|
|
|
return csum_tcpudp_nofold(iph->saddr, iph->daddr,
|
|
skb_gro_len(skb), proto, 0);
|
|
}
|
|
|
|
/*
|
|
* Map a multicast IP onto multicast MAC for type ethernet.
|
|
*/
|
|
|
|
static inline void ip_eth_mc_map(__be32 naddr, char *buf)
|
|
{
|
|
__u32 addr=ntohl(naddr);
|
|
buf[0]=0x01;
|
|
buf[1]=0x00;
|
|
buf[2]=0x5e;
|
|
buf[5]=addr&0xFF;
|
|
addr>>=8;
|
|
buf[4]=addr&0xFF;
|
|
addr>>=8;
|
|
buf[3]=addr&0x7F;
|
|
}
|
|
|
|
/*
|
|
* Map a multicast IP onto multicast MAC for type IP-over-InfiniBand.
|
|
* Leave P_Key as 0 to be filled in by driver.
|
|
*/
|
|
|
|
static inline void ip_ib_mc_map(__be32 naddr, const unsigned char *broadcast, char *buf)
|
|
{
|
|
__u32 addr;
|
|
unsigned char scope = broadcast[5] & 0xF;
|
|
|
|
buf[0] = 0; /* Reserved */
|
|
buf[1] = 0xff; /* Multicast QPN */
|
|
buf[2] = 0xff;
|
|
buf[3] = 0xff;
|
|
addr = ntohl(naddr);
|
|
buf[4] = 0xff;
|
|
buf[5] = 0x10 | scope; /* scope from broadcast address */
|
|
buf[6] = 0x40; /* IPv4 signature */
|
|
buf[7] = 0x1b;
|
|
buf[8] = broadcast[8]; /* P_Key */
|
|
buf[9] = broadcast[9];
|
|
buf[10] = 0;
|
|
buf[11] = 0;
|
|
buf[12] = 0;
|
|
buf[13] = 0;
|
|
buf[14] = 0;
|
|
buf[15] = 0;
|
|
buf[19] = addr & 0xff;
|
|
addr >>= 8;
|
|
buf[18] = addr & 0xff;
|
|
addr >>= 8;
|
|
buf[17] = addr & 0xff;
|
|
addr >>= 8;
|
|
buf[16] = addr & 0x0f;
|
|
}
|
|
|
|
static inline void ip_ipgre_mc_map(__be32 naddr, const unsigned char *broadcast, char *buf)
|
|
{
|
|
if ((broadcast[0] | broadcast[1] | broadcast[2] | broadcast[3]) != 0)
|
|
memcpy(buf, broadcast, 4);
|
|
else
|
|
memcpy(buf, &naddr, sizeof(naddr));
|
|
}
|
|
|
|
#if IS_ENABLED(CONFIG_IPV6)
|
|
#include <linux/ipv6.h>
|
|
#endif
|
|
|
|
static __inline__ void inet_reset_saddr(struct sock *sk)
|
|
{
|
|
inet_sk(sk)->inet_rcv_saddr = inet_sk(sk)->inet_saddr = 0;
|
|
#if IS_ENABLED(CONFIG_IPV6)
|
|
if (sk->sk_family == PF_INET6) {
|
|
struct ipv6_pinfo *np = inet6_sk(sk);
|
|
|
|
memset(&np->saddr, 0, sizeof(np->saddr));
|
|
memset(&sk->sk_v6_rcv_saddr, 0, sizeof(sk->sk_v6_rcv_saddr));
|
|
}
|
|
#endif
|
|
}
|
|
|
|
#endif
|
|
|
|
static inline unsigned int ipv4_addr_hash(__be32 ip)
|
|
{
|
|
return (__force unsigned int) ip;
|
|
}
|
|
|
|
static inline u32 ipv4_portaddr_hash(const struct net *net,
|
|
__be32 saddr,
|
|
unsigned int port)
|
|
{
|
|
return jhash_1word((__force u32)saddr, net_hash_mix(net)) ^ port;
|
|
}
|
|
|
|
bool ip_call_ra_chain(struct sk_buff *skb);
|
|
|
|
/*
|
|
* Functions provided by ip_fragment.c
|
|
*/
|
|
|
|
enum ip_defrag_users {
|
|
IP_DEFRAG_LOCAL_DELIVER,
|
|
IP_DEFRAG_CALL_RA_CHAIN,
|
|
IP_DEFRAG_CONNTRACK_IN,
|
|
__IP_DEFRAG_CONNTRACK_IN_END = IP_DEFRAG_CONNTRACK_IN + USHRT_MAX,
|
|
IP_DEFRAG_CONNTRACK_OUT,
|
|
__IP_DEFRAG_CONNTRACK_OUT_END = IP_DEFRAG_CONNTRACK_OUT + USHRT_MAX,
|
|
IP_DEFRAG_CONNTRACK_BRIDGE_IN,
|
|
__IP_DEFRAG_CONNTRACK_BRIDGE_IN = IP_DEFRAG_CONNTRACK_BRIDGE_IN + USHRT_MAX,
|
|
IP_DEFRAG_VS_IN,
|
|
IP_DEFRAG_VS_OUT,
|
|
IP_DEFRAG_VS_FWD,
|
|
IP_DEFRAG_AF_PACKET,
|
|
IP_DEFRAG_MACVLAN,
|
|
};
|
|
|
|
/* Return true if the value of 'user' is between 'lower_bond'
|
|
* and 'upper_bond' inclusively.
|
|
*/
|
|
static inline bool ip_defrag_user_in_between(u32 user,
|
|
enum ip_defrag_users lower_bond,
|
|
enum ip_defrag_users upper_bond)
|
|
{
|
|
return user >= lower_bond && user <= upper_bond;
|
|
}
|
|
|
|
int ip_defrag(struct net *net, struct sk_buff *skb, u32 user);
|
|
#ifdef CONFIG_INET
|
|
struct sk_buff *ip_check_defrag(struct net *net, struct sk_buff *skb, u32 user);
|
|
#else
|
|
static inline struct sk_buff *ip_check_defrag(struct net *net, struct sk_buff *skb, u32 user)
|
|
{
|
|
return skb;
|
|
}
|
|
#endif
|
|
|
|
/*
|
|
* Functions provided by ip_forward.c
|
|
*/
|
|
|
|
int ip_forward(struct sk_buff *skb);
|
|
|
|
/*
|
|
* Functions provided by ip_options.c
|
|
*/
|
|
|
|
void ip_options_build(struct sk_buff *skb, struct ip_options *opt,
|
|
__be32 daddr, struct rtable *rt, int is_frag);
|
|
|
|
int __ip_options_echo(struct net *net, struct ip_options *dopt,
|
|
struct sk_buff *skb, const struct ip_options *sopt);
|
|
static inline int ip_options_echo(struct net *net, struct ip_options *dopt,
|
|
struct sk_buff *skb)
|
|
{
|
|
return __ip_options_echo(net, dopt, skb, &IPCB(skb)->opt);
|
|
}
|
|
|
|
void ip_options_fragment(struct sk_buff *skb);
|
|
int __ip_options_compile(struct net *net, struct ip_options *opt,
|
|
struct sk_buff *skb, __be32 *info);
|
|
int ip_options_compile(struct net *net, struct ip_options *opt,
|
|
struct sk_buff *skb);
|
|
int ip_options_get(struct net *net, struct ip_options_rcu **optp,
|
|
unsigned char *data, int optlen);
|
|
int ip_options_get_from_user(struct net *net, struct ip_options_rcu **optp,
|
|
unsigned char __user *data, int optlen);
|
|
void ip_options_undo(struct ip_options *opt);
|
|
void ip_forward_options(struct sk_buff *skb);
|
|
int ip_options_rcv_srr(struct sk_buff *skb, struct net_device *dev);
|
|
|
|
/*
|
|
* Functions provided by ip_sockglue.c
|
|
*/
|
|
|
|
void ipv4_pktinfo_prepare(const struct sock *sk, struct sk_buff *skb);
|
|
void ip_cmsg_recv_offset(struct msghdr *msg, struct sock *sk,
|
|
struct sk_buff *skb, int tlen, int offset);
|
|
int ip_cmsg_send(struct sock *sk, struct msghdr *msg,
|
|
struct ipcm_cookie *ipc, bool allow_ipv6);
|
|
int ip_setsockopt(struct sock *sk, int level, int optname, char __user *optval,
|
|
unsigned int optlen);
|
|
int ip_getsockopt(struct sock *sk, int level, int optname, char __user *optval,
|
|
int __user *optlen);
|
|
int compat_ip_setsockopt(struct sock *sk, int level, int optname,
|
|
char __user *optval, unsigned int optlen);
|
|
int compat_ip_getsockopt(struct sock *sk, int level, int optname,
|
|
char __user *optval, int __user *optlen);
|
|
int ip_ra_control(struct sock *sk, unsigned char on,
|
|
void (*destructor)(struct sock *));
|
|
|
|
int ip_recv_error(struct sock *sk, struct msghdr *msg, int len, int *addr_len);
|
|
void ip_icmp_error(struct sock *sk, struct sk_buff *skb, int err, __be16 port,
|
|
u32 info, u8 *payload);
|
|
void ip_local_error(struct sock *sk, int err, __be32 daddr, __be16 dport,
|
|
u32 info);
|
|
|
|
static inline void ip_cmsg_recv(struct msghdr *msg, struct sk_buff *skb)
|
|
{
|
|
ip_cmsg_recv_offset(msg, skb->sk, skb, 0, 0);
|
|
}
|
|
|
|
bool icmp_global_allow(void);
|
|
extern int sysctl_icmp_msgs_per_sec;
|
|
extern int sysctl_icmp_msgs_burst;
|
|
|
|
#ifdef CONFIG_PROC_FS
|
|
int ip_misc_proc_init(void);
|
|
#endif
|
|
|
|
int rtm_getroute_parse_ip_proto(struct nlattr *attr, u8 *ip_proto, u8 family,
|
|
struct netlink_ext_ack *extack);
|
|
|
|
static inline bool inetdev_valid_mtu(unsigned int mtu)
|
|
{
|
|
return likely(mtu >= IPV4_MIN_MTU);
|
|
}
|
|
|
|
#endif /* _IP_H */
|