]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/ipv4/inet_hashtables.c
tcp/dccp: fix possible race __inet_lookup_established()
[mirror_ubuntu-bionic-kernel.git] / net / ipv4 / inet_hashtables.c
CommitLineData
77d8bf9c
ACM
1/*
2 * INET An implementation of the TCP/IP protocol suite for the LINUX
3 * operating system. INET is implemented using the BSD Socket
4 * interface as the means of communication with the user level.
5 *
6 * Generic INET transport hashtables
7 *
8 * Authors: Lotsa people, from code originally in tcp
9 *
10 * This program is free software; you can redistribute it and/or
11 * modify it under the terms of the GNU General Public License
12 * as published by the Free Software Foundation; either version
13 * 2 of the License, or (at your option) any later version.
14 */
15
2d8c4ce5 16#include <linux/module.h>
a7f5e7f1 17#include <linux/random.h>
f3f05f70 18#include <linux/sched.h>
77d8bf9c 19#include <linux/slab.h>
f3f05f70 20#include <linux/wait.h>
095dc8e0 21#include <linux/vmalloc.h>
77d8bf9c 22
c125e80b 23#include <net/addrconf.h>
463c84b9 24#include <net/inet_connection_sock.h>
77d8bf9c 25#include <net/inet_hashtables.h>
6e5714ea 26#include <net/secure_seq.h>
a7f5e7f1 27#include <net/ip.h>
a04a480d 28#include <net/tcp.h>
c125e80b 29#include <net/sock_reuseport.h>
77d8bf9c 30
6eada011
ED
31static u32 inet_ehashfn(const struct net *net, const __be32 laddr,
32 const __u16 lport, const __be32 faddr,
33 const __be16 fport)
65cd8033 34{
1bbdceef
HFS
35 static u32 inet_ehash_secret __read_mostly;
36
37 net_get_random_once(&inet_ehash_secret, sizeof(inet_ehash_secret));
38
65cd8033
HFS
39 return __inet_ehashfn(laddr, lport, faddr, fport,
40 inet_ehash_secret + net_hash_mix(net));
41}
42
d1e559d0
ED
43/* This function handles inet_sock, but also timewait and request sockets
44 * for IPv4/IPv6.
45 */
784c372a 46static u32 sk_ehashfn(const struct sock *sk)
65cd8033 47{
d1e559d0
ED
48#if IS_ENABLED(CONFIG_IPV6)
49 if (sk->sk_family == AF_INET6 &&
50 !ipv6_addr_v4mapped(&sk->sk_v6_daddr))
51 return inet6_ehashfn(sock_net(sk),
52 &sk->sk_v6_rcv_saddr, sk->sk_num,
53 &sk->sk_v6_daddr, sk->sk_dport);
54#endif
5b441f76
ED
55 return inet_ehashfn(sock_net(sk),
56 sk->sk_rcv_saddr, sk->sk_num,
57 sk->sk_daddr, sk->sk_dport);
65cd8033
HFS
58}
59
77d8bf9c
ACM
60/*
61 * Allocate and initialize a new local port bind bucket.
62 * The bindhash mutex for snum's hash chain must be held here.
63 */
e18b890b 64struct inet_bind_bucket *inet_bind_bucket_create(struct kmem_cache *cachep,
941b1d22 65 struct net *net,
77d8bf9c
ACM
66 struct inet_bind_hashbucket *head,
67 const unsigned short snum)
68{
54e6ecb2 69 struct inet_bind_bucket *tb = kmem_cache_alloc(cachep, GFP_ATOMIC);
77d8bf9c 70
00db4124 71 if (tb) {
efd7ef1c 72 write_pnet(&tb->ib_net, net);
77d8bf9c
ACM
73 tb->port = snum;
74 tb->fastreuse = 0;
da5e3630 75 tb->fastreuseport = 0;
77d8bf9c
ACM
76 INIT_HLIST_HEAD(&tb->owners);
77 hlist_add_head(&tb->node, &head->chain);
78 }
79 return tb;
80}
81
77d8bf9c
ACM
82/*
83 * Caller must hold hashbucket lock for this tb with local BH disabled
84 */
e18b890b 85void inet_bind_bucket_destroy(struct kmem_cache *cachep, struct inet_bind_bucket *tb)
77d8bf9c
ACM
86{
87 if (hlist_empty(&tb->owners)) {
88 __hlist_del(&tb->node);
89 kmem_cache_free(cachep, tb);
90 }
91}
2d8c4ce5
ACM
92
93void inet_bind_hash(struct sock *sk, struct inet_bind_bucket *tb,
94 const unsigned short snum)
95{
c720c7e8 96 inet_sk(sk)->inet_num = snum;
2d8c4ce5 97 sk_add_bind_node(sk, &tb->owners);
463c84b9 98 inet_csk(sk)->icsk_bind_hash = tb;
2d8c4ce5
ACM
99}
100
2d8c4ce5
ACM
101/*
102 * Get rid of any references to a local port held by the given sock.
103 */
ab1e0a13 104static void __inet_put_port(struct sock *sk)
2d8c4ce5 105{
39d8cda7 106 struct inet_hashinfo *hashinfo = sk->sk_prot->h.hashinfo;
c720c7e8 107 const int bhash = inet_bhashfn(sock_net(sk), inet_sk(sk)->inet_num,
7f635ab7 108 hashinfo->bhash_size);
2d8c4ce5
ACM
109 struct inet_bind_hashbucket *head = &hashinfo->bhash[bhash];
110 struct inet_bind_bucket *tb;
111
112 spin_lock(&head->lock);
463c84b9 113 tb = inet_csk(sk)->icsk_bind_hash;
2d8c4ce5 114 __sk_del_bind_node(sk);
463c84b9 115 inet_csk(sk)->icsk_bind_hash = NULL;
c720c7e8 116 inet_sk(sk)->inet_num = 0;
2d8c4ce5
ACM
117 inet_bind_bucket_destroy(hashinfo->bind_bucket_cachep, tb);
118 spin_unlock(&head->lock);
119}
120
ab1e0a13 121void inet_put_port(struct sock *sk)
2d8c4ce5
ACM
122{
123 local_bh_disable();
ab1e0a13 124 __inet_put_port(sk);
2d8c4ce5
ACM
125 local_bh_enable();
126}
2d8c4ce5 127EXPORT_SYMBOL(inet_put_port);
f3f05f70 128
1ce31c9e 129int __inet_inherit_port(const struct sock *sk, struct sock *child)
53083773
PE
130{
131 struct inet_hashinfo *table = sk->sk_prot->h.hashinfo;
093d2823
BS
132 unsigned short port = inet_sk(child)->inet_num;
133 const int bhash = inet_bhashfn(sock_net(sk), port,
7f635ab7 134 table->bhash_size);
53083773
PE
135 struct inet_bind_hashbucket *head = &table->bhash[bhash];
136 struct inet_bind_bucket *tb;
137
138 spin_lock(&head->lock);
139 tb = inet_csk(sk)->icsk_bind_hash;
c2f34a65
ED
140 if (unlikely(!tb)) {
141 spin_unlock(&head->lock);
142 return -ENOENT;
143 }
093d2823
BS
144 if (tb->port != port) {
145 /* NOTE: using tproxy and redirecting skbs to a proxy
146 * on a different listener port breaks the assumption
147 * that the listener socket's icsk_bind_hash is the same
148 * as that of the child socket. We have to look up or
149 * create a new bind bucket for the child here. */
b67bfe0d 150 inet_bind_bucket_for_each(tb, &head->chain) {
093d2823
BS
151 if (net_eq(ib_net(tb), sock_net(sk)) &&
152 tb->port == port)
153 break;
154 }
b67bfe0d 155 if (!tb) {
093d2823
BS
156 tb = inet_bind_bucket_create(table->bind_bucket_cachep,
157 sock_net(sk), head, port);
158 if (!tb) {
159 spin_unlock(&head->lock);
160 return -ENOMEM;
161 }
162 }
163 }
b4ff3c90 164 inet_bind_hash(child, tb, port);
53083773 165 spin_unlock(&head->lock);
093d2823
BS
166
167 return 0;
53083773 168}
53083773
PE
169EXPORT_SYMBOL_GPL(__inet_inherit_port);
170
c25eb3bf
ED
171static inline int compute_score(struct sock *sk, struct net *net,
172 const unsigned short hnum, const __be32 daddr,
3fa6f616 173 const int dif, const int sdif, bool exact_dif)
c25eb3bf
ED
174{
175 int score = -1;
176 struct inet_sock *inet = inet_sk(sk);
177
c720c7e8 178 if (net_eq(sock_net(sk), net) && inet->inet_num == hnum &&
c25eb3bf 179 !ipv6_only_sock(sk)) {
c720c7e8 180 __be32 rcv_saddr = inet->inet_rcv_saddr;
da5e3630 181 score = sk->sk_family == PF_INET ? 2 : 1;
c25eb3bf
ED
182 if (rcv_saddr) {
183 if (rcv_saddr != daddr)
184 return -1;
da5e3630 185 score += 4;
c25eb3bf 186 }
a04a480d 187 if (sk->sk_bound_dev_if || exact_dif) {
3fa6f616
DA
188 bool dev_match = (sk->sk_bound_dev_if == dif ||
189 sk->sk_bound_dev_if == sdif);
190
83ea7a1b 191 if (!dev_match)
c25eb3bf 192 return -1;
83ea7a1b 193 if (sk->sk_bound_dev_if)
3fa6f616 194 score += 4;
c25eb3bf 195 }
f5f96dc2 196 if (READ_ONCE(sk->sk_incoming_cpu) == raw_smp_processor_id())
70da268b 197 score++;
c25eb3bf
ED
198 }
199 return score;
200}
201
33b62231 202/*
3b24d854
ED
203 * Here are some nice properties to exploit here. The BSD API
204 * does not allow a listening sock to specify the remote port nor the
33b62231
ACM
205 * remote address for the connection. So always assume those are both
206 * wildcarded during the search since they can never be otherwise.
207 */
e48c414e 208
3b24d854 209/* called with rcu_read_lock() : No refcount taken on the socket */
c67499c0
PE
210struct sock *__inet_lookup_listener(struct net *net,
211 struct inet_hashinfo *hashinfo,
a583636a 212 struct sk_buff *skb, int doff,
da5e3630 213 const __be32 saddr, __be16 sport,
fb99c848 214 const __be32 daddr, const unsigned short hnum,
3fa6f616 215 const int dif, const int sdif)
99a92ff5 216{
c25eb3bf
ED
217 unsigned int hash = inet_lhashfn(net, hnum);
218 struct inet_listen_hashbucket *ilb = &hashinfo->listening_hash[hash];
3b24d854 219 int score, hiscore = 0, matches = 0, reuseport = 0;
a04a480d 220 bool exact_dif = inet_exact_dif_match(net, skb);
3b24d854 221 struct sock *sk, *result = NULL;
6cb8e266 222 struct hlist_nulls_node *node;
da5e3630 223 u32 phash = 0;
99a92ff5 224
6cb8e266 225 sk_nulls_for_each_rcu(sk, node, &ilb->nulls_head) {
3fa6f616
DA
226 score = compute_score(sk, net, hnum, daddr,
227 dif, sdif, exact_dif);
c25eb3bf 228 if (score > hiscore) {
da5e3630
TH
229 reuseport = sk->sk_reuseport;
230 if (reuseport) {
231 phash = inet_ehashfn(net, daddr, hnum,
232 saddr, sport);
3b24d854
ED
233 result = reuseport_select_sock(sk, phash,
234 skb, doff);
235 if (result)
236 return result;
da5e3630
TH
237 matches = 1;
238 }
3b24d854
ED
239 result = sk;
240 hiscore = score;
da5e3630
TH
241 } else if (score == hiscore && reuseport) {
242 matches++;
8fc54f68 243 if (reciprocal_scale(phash, matches) == 0)
da5e3630
TH
244 result = sk;
245 phash = next_pseudo_random32(phash);
c25eb3bf 246 }
99a92ff5 247 }
c25eb3bf 248 return result;
99a92ff5 249}
8f491069 250EXPORT_SYMBOL_GPL(__inet_lookup_listener);
a7f5e7f1 251
05dbc7b5
ED
252/* All sockets share common refcount, but have different destructors */
253void sock_gen_put(struct sock *sk)
254{
41c6d650 255 if (!refcount_dec_and_test(&sk->sk_refcnt))
05dbc7b5
ED
256 return;
257
258 if (sk->sk_state == TCP_TIME_WAIT)
259 inet_twsk_free(inet_twsk(sk));
41b822c5
ED
260 else if (sk->sk_state == TCP_NEW_SYN_RECV)
261 reqsk_free(inet_reqsk(sk));
05dbc7b5
ED
262 else
263 sk_free(sk);
264}
265EXPORT_SYMBOL_GPL(sock_gen_put);
266
2c13270b
ED
267void sock_edemux(struct sk_buff *skb)
268{
269 sock_gen_put(skb->sk);
270}
271EXPORT_SYMBOL(sock_edemux);
272
5e73ea1a 273struct sock *__inet_lookup_established(struct net *net,
c67499c0 274 struct inet_hashinfo *hashinfo,
77a5ba55
PE
275 const __be32 saddr, const __be16 sport,
276 const __be32 daddr, const u16 hnum,
3fa6f616 277 const int dif, const int sdif)
77a5ba55 278{
c7228317 279 INET_ADDR_COOKIE(acookie, saddr, daddr);
77a5ba55
PE
280 const __portpair ports = INET_COMBINED_PORTS(sport, hnum);
281 struct sock *sk;
3ab5aee7 282 const struct hlist_nulls_node *node;
77a5ba55
PE
283 /* Optimize here for direct hit, only listening connections can
284 * have wildcards anyways.
285 */
9f26b3ad 286 unsigned int hash = inet_ehashfn(net, daddr, hnum, saddr, sport);
f373b53b 287 unsigned int slot = hash & hashinfo->ehash_mask;
3ab5aee7 288 struct inet_ehash_bucket *head = &hashinfo->ehash[slot];
77a5ba55 289
3ab5aee7
ED
290begin:
291 sk_nulls_for_each_rcu(sk, node, &head->chain) {
ce43b03e
ED
292 if (sk->sk_hash != hash)
293 continue;
294 if (likely(INET_MATCH(sk, net, acookie,
3fa6f616 295 saddr, daddr, ports, dif, sdif))) {
41c6d650 296 if (unlikely(!refcount_inc_not_zero(&sk->sk_refcnt)))
05dbc7b5 297 goto out;
ce43b03e 298 if (unlikely(!INET_MATCH(sk, net, acookie,
3fa6f616
DA
299 saddr, daddr, ports,
300 dif, sdif))) {
05dbc7b5 301 sock_gen_put(sk);
3ab5aee7
ED
302 goto begin;
303 }
05dbc7b5 304 goto found;
3ab5aee7 305 }
77a5ba55 306 }
3ab5aee7
ED
307 /*
308 * if the nulls value we got at the end of this lookup is
309 * not the expected one, we must restart lookup.
310 * We probably met an item that was moved to another chain.
311 */
312 if (get_nulls_value(node) != slot)
313 goto begin;
77a5ba55 314out:
05dbc7b5
ED
315 sk = NULL;
316found:
77a5ba55 317 return sk;
77a5ba55
PE
318}
319EXPORT_SYMBOL_GPL(__inet_lookup_established);
320
a7f5e7f1
ACM
321/* called with local bh disabled */
322static int __inet_check_established(struct inet_timewait_death_row *death_row,
323 struct sock *sk, __u16 lport,
324 struct inet_timewait_sock **twp)
325{
326 struct inet_hashinfo *hinfo = death_row->hashinfo;
327 struct inet_sock *inet = inet_sk(sk);
c720c7e8
ED
328 __be32 daddr = inet->inet_rcv_saddr;
329 __be32 saddr = inet->inet_daddr;
a7f5e7f1 330 int dif = sk->sk_bound_dev_if;
3fa6f616
DA
331 struct net *net = sock_net(sk);
332 int sdif = l3mdev_master_ifindex_by_index(net, dif);
c7228317 333 INET_ADDR_COOKIE(acookie, saddr, daddr);
c720c7e8 334 const __portpair ports = INET_COMBINED_PORTS(inet->inet_dport, lport);
c720c7e8
ED
335 unsigned int hash = inet_ehashfn(net, daddr, lport,
336 saddr, inet->inet_dport);
a7f5e7f1 337 struct inet_ehash_bucket *head = inet_ehash_bucket(hinfo, hash);
9db66bdc 338 spinlock_t *lock = inet_ehash_lockp(hinfo, hash);
a7f5e7f1 339 struct sock *sk2;
3ab5aee7 340 const struct hlist_nulls_node *node;
05dbc7b5 341 struct inet_timewait_sock *tw = NULL;
a7f5e7f1 342
9db66bdc 343 spin_lock(lock);
a7f5e7f1 344
3ab5aee7 345 sk_nulls_for_each(sk2, node, &head->chain) {
ce43b03e
ED
346 if (sk2->sk_hash != hash)
347 continue;
05dbc7b5 348
ce43b03e 349 if (likely(INET_MATCH(sk2, net, acookie,
3fa6f616 350 saddr, daddr, ports, dif, sdif))) {
05dbc7b5
ED
351 if (sk2->sk_state == TCP_TIME_WAIT) {
352 tw = inet_twsk(sk2);
353 if (twsk_unique(sk, sk2, twp))
354 break;
355 }
a7f5e7f1 356 goto not_unique;
05dbc7b5 357 }
a7f5e7f1
ACM
358 }
359
a7f5e7f1 360 /* Must record num and sport now. Otherwise we will see
05dbc7b5
ED
361 * in hash table socket with a funny identity.
362 */
c720c7e8
ED
363 inet->inet_num = lport;
364 inet->inet_sport = htons(lport);
a7f5e7f1 365 sk->sk_hash = hash;
547b792c 366 WARN_ON(!sk_unhashed(sk));
3ab5aee7 367 __sk_nulls_add_node_rcu(sk, &head->chain);
13475a30 368 if (tw) {
fc01538f 369 sk_nulls_del_node_init_rcu((struct sock *)tw);
02a1d6e7 370 __NET_INC_STATS(net, LINUX_MIB_TIMEWAITRECYCLED);
13475a30 371 }
9db66bdc 372 spin_unlock(lock);
c29a0bc4 373 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, 1);
a7f5e7f1
ACM
374
375 if (twp) {
376 *twp = tw;
a7f5e7f1
ACM
377 } else if (tw) {
378 /* Silly. Should hash-dance instead... */
dbe7faa4 379 inet_twsk_deschedule_put(tw);
a7f5e7f1 380 }
a7f5e7f1
ACM
381 return 0;
382
383not_unique:
9db66bdc 384 spin_unlock(lock);
a7f5e7f1
ACM
385 return -EADDRNOTAVAIL;
386}
387
e2baad9e 388static u32 inet_sk_port_offset(const struct sock *sk)
a7f5e7f1
ACM
389{
390 const struct inet_sock *inet = inet_sk(sk);
e2baad9e 391
c720c7e8
ED
392 return secure_ipv4_port_ephemeral(inet->inet_rcv_saddr,
393 inet->inet_daddr,
394 inet->inet_dport);
a7f5e7f1
ACM
395}
396
079096f1
ED
397/* insert a socket into ehash, and eventually remove another one
398 * (The another one can be a SYN_RECV or TIMEWAIT
399 */
5e0724d0 400bool inet_ehash_insert(struct sock *sk, struct sock *osk)
152da81d 401{
39d8cda7 402 struct inet_hashinfo *hashinfo = sk->sk_prot->h.hashinfo;
3ab5aee7 403 struct hlist_nulls_head *list;
152da81d 404 struct inet_ehash_bucket *head;
5b441f76 405 spinlock_t *lock;
5e0724d0 406 bool ret = true;
152da81d 407
079096f1 408 WARN_ON_ONCE(!sk_unhashed(sk));
152da81d 409
5b441f76 410 sk->sk_hash = sk_ehashfn(sk);
152da81d
PE
411 head = inet_ehash_bucket(hashinfo, sk->sk_hash);
412 list = &head->chain;
413 lock = inet_ehash_lockp(hashinfo, sk->sk_hash);
414
9db66bdc 415 spin_lock(lock);
fc01538f 416 if (osk) {
5e0724d0
ED
417 WARN_ON_ONCE(sk->sk_hash != osk->sk_hash);
418 ret = sk_nulls_del_node_init_rcu(osk);
9327f705 419 }
5e0724d0
ED
420 if (ret)
421 __sk_nulls_add_node_rcu(sk, list);
9db66bdc 422 spin_unlock(lock);
079096f1
ED
423 return ret;
424}
425
5e0724d0 426bool inet_ehash_nolisten(struct sock *sk, struct sock *osk)
079096f1 427{
5e0724d0
ED
428 bool ok = inet_ehash_insert(sk, osk);
429
430 if (ok) {
431 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, 1);
432 } else {
433 percpu_counter_inc(sk->sk_prot->orphan_count);
434 sk->sk_state = TCP_CLOSE;
435 sock_set_flag(sk, SOCK_DEAD);
436 inet_csk_destroy_sock(sk);
437 }
438 return ok;
152da81d 439}
5e0724d0 440EXPORT_SYMBOL_GPL(inet_ehash_nolisten);
152da81d 441
c125e80b 442static int inet_reuseport_add_sock(struct sock *sk,
fe38d2a1 443 struct inet_listen_hashbucket *ilb)
c125e80b 444{
90e5d0db 445 struct inet_bind_bucket *tb = inet_csk(sk)->icsk_bind_hash;
6cb8e266 446 const struct hlist_nulls_node *node;
c125e80b 447 struct sock *sk2;
c125e80b
CG
448 kuid_t uid = sock_i_uid(sk);
449
6cb8e266 450 sk_nulls_for_each_rcu(sk2, node, &ilb->nulls_head) {
c125e80b
CG
451 if (sk2 != sk &&
452 sk2->sk_family == sk->sk_family &&
453 ipv6_only_sock(sk2) == ipv6_only_sock(sk) &&
454 sk2->sk_bound_dev_if == sk->sk_bound_dev_if &&
90e5d0db 455 inet_csk(sk2)->icsk_bind_hash == tb &&
c125e80b 456 sk2->sk_reuseport && uid_eq(uid, sock_i_uid(sk2)) &&
fe38d2a1 457 inet_rcv_saddr_equal(sk, sk2, false))
c125e80b
CG
458 return reuseport_add_sock(sk, sk2);
459 }
460
1b5f962e 461 return reuseport_alloc(sk);
c125e80b
CG
462}
463
fe38d2a1 464int __inet_hash(struct sock *sk, struct sock *osk)
152da81d 465{
39d8cda7 466 struct inet_hashinfo *hashinfo = sk->sk_prot->h.hashinfo;
5caea4ea 467 struct inet_listen_hashbucket *ilb;
c125e80b 468 int err = 0;
152da81d 469
5e0724d0
ED
470 if (sk->sk_state != TCP_LISTEN) {
471 inet_ehash_nolisten(sk, osk);
c125e80b 472 return 0;
5e0724d0 473 }
547b792c 474 WARN_ON(!sk_unhashed(sk));
5caea4ea 475 ilb = &hashinfo->listening_hash[inet_sk_listen_hashfn(sk)];
152da81d 476
5caea4ea 477 spin_lock(&ilb->lock);
c125e80b 478 if (sk->sk_reuseport) {
fe38d2a1 479 err = inet_reuseport_add_sock(sk, ilb);
c125e80b
CG
480 if (err)
481 goto unlock;
482 }
d296ba60
CG
483 if (IS_ENABLED(CONFIG_IPV6) && sk->sk_reuseport &&
484 sk->sk_family == AF_INET6)
6cb8e266 485 __sk_nulls_add_node_tail_rcu(sk, &ilb->nulls_head);
d296ba60 486 else
6cb8e266 487 __sk_nulls_add_node_rcu(sk, &ilb->nulls_head);
3b24d854 488 sock_set_flag(sk, SOCK_RCU_FREE);
c29a0bc4 489 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, 1);
c125e80b 490unlock:
5caea4ea 491 spin_unlock(&ilb->lock);
c125e80b
CG
492
493 return err;
152da81d 494}
77a6a471 495EXPORT_SYMBOL(__inet_hash);
ab1e0a13 496
086c653f 497int inet_hash(struct sock *sk)
ab1e0a13 498{
c125e80b
CG
499 int err = 0;
500
ab1e0a13
ACM
501 if (sk->sk_state != TCP_CLOSE) {
502 local_bh_disable();
fe38d2a1 503 err = __inet_hash(sk, NULL);
ab1e0a13
ACM
504 local_bh_enable();
505 }
086c653f 506
c125e80b 507 return err;
ab1e0a13
ACM
508}
509EXPORT_SYMBOL_GPL(inet_hash);
510
511void inet_unhash(struct sock *sk)
512{
39d8cda7 513 struct inet_hashinfo *hashinfo = sk->sk_prot->h.hashinfo;
c25eb3bf 514 spinlock_t *lock;
3b24d854 515 bool listener = false;
c25eb3bf 516 int done;
ab1e0a13
ACM
517
518 if (sk_unhashed(sk))
5caea4ea 519 return;
ab1e0a13 520
3b24d854 521 if (sk->sk_state == TCP_LISTEN) {
c25eb3bf 522 lock = &hashinfo->listening_hash[inet_sk_listen_hashfn(sk)].lock;
3b24d854
ED
523 listener = true;
524 } else {
c25eb3bf 525 lock = inet_ehash_lockp(hashinfo, sk->sk_hash);
3b24d854 526 }
c25eb3bf 527 spin_lock_bh(lock);
c125e80b
CG
528 if (rcu_access_pointer(sk->sk_reuseport_cb))
529 reuseport_detach_sock(sk);
6cb8e266 530 done = __sk_nulls_del_node_init_rcu(sk);
c25eb3bf
ED
531 if (done)
532 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, -1);
920de804 533 spin_unlock_bh(lock);
ab1e0a13
ACM
534}
535EXPORT_SYMBOL_GPL(inet_unhash);
152da81d 536
5ee31fc1 537int __inet_hash_connect(struct inet_timewait_death_row *death_row,
5d8c0aa9 538 struct sock *sk, u32 port_offset,
5ee31fc1 539 int (*check_established)(struct inet_timewait_death_row *,
b4d6444e 540 struct sock *, __u16, struct inet_timewait_sock **))
a7f5e7f1
ACM
541{
542 struct inet_hashinfo *hinfo = death_row->hashinfo;
1580ab63 543 struct inet_timewait_sock *tw = NULL;
e905a9ed 544 struct inet_bind_hashbucket *head;
1580ab63 545 int port = inet_sk(sk)->inet_num;
3b1e0a65 546 struct net *net = sock_net(sk);
1580ab63
ED
547 struct inet_bind_bucket *tb;
548 u32 remaining, offset;
549 int ret, i, low, high;
550 static u32 hint;
551
552 if (port) {
553 head = &hinfo->bhash[inet_bhashfn(net, port,
554 hinfo->bhash_size)];
555 tb = inet_csk(sk)->icsk_bind_hash;
556 spin_lock_bh(&head->lock);
557 if (sk_head(&tb->owners) == sk && !sk->sk_bind_node.next) {
558 inet_ehash_nolisten(sk, NULL);
559 spin_unlock_bh(&head->lock);
560 return 0;
561 }
562 spin_unlock(&head->lock);
563 /* No definite answer... Walk to established hash table */
564 ret = check_established(death_row, sk, port, NULL);
565 local_bh_enable();
566 return ret;
567 }
a7f5e7f1 568
1580ab63
ED
569 inet_get_local_port_range(net, &low, &high);
570 high++; /* [32768, 60999] -> [32768, 61000[ */
571 remaining = high - low;
572 if (likely(remaining > 1))
573 remaining &= ~1U;
a7f5e7f1 574
1580ab63
ED
575 offset = (hint + port_offset) % remaining;
576 /* In first pass we try ports of @low parity.
577 * inet_csk_get_port() does the opposite choice.
578 */
579 offset &= ~1U;
580other_parity_scan:
581 port = low + offset;
582 for (i = 0; i < remaining; i += 2, port += 2) {
583 if (unlikely(port >= high))
584 port -= remaining;
585 if (inet_is_local_reserved_port(net, port))
586 continue;
587 head = &hinfo->bhash[inet_bhashfn(net, port,
588 hinfo->bhash_size)];
589 spin_lock_bh(&head->lock);
227b60f5 590
1580ab63
ED
591 /* Does not bother with rcv_saddr checks, because
592 * the established check is already unique enough.
07f4c900 593 */
1580ab63
ED
594 inet_bind_bucket_for_each(tb, &head->chain) {
595 if (net_eq(ib_net(tb), net) && tb->port == port) {
596 if (tb->fastreuse >= 0 ||
597 tb->fastreuseport >= 0)
e905a9ed 598 goto next_port;
1580ab63
ED
599 WARN_ON(hlist_empty(&tb->owners));
600 if (!check_established(death_row, sk,
601 port, &tw))
602 goto ok;
603 goto next_port;
e905a9ed 604 }
e905a9ed 605 }
a7f5e7f1 606
1580ab63
ED
607 tb = inet_bind_bucket_create(hinfo->bind_bucket_cachep,
608 net, head, port);
609 if (!tb) {
610 spin_unlock_bh(&head->lock);
611 return -ENOMEM;
e905a9ed 612 }
1580ab63
ED
613 tb->fastreuse = -1;
614 tb->fastreuseport = -1;
615 goto ok;
616next_port:
617 spin_unlock_bh(&head->lock);
618 cond_resched();
619 }
a7f5e7f1 620
1580ab63
ED
621 offset++;
622 if ((offset & 1) && remaining > 1)
623 goto other_parity_scan;
a7f5e7f1 624
1580ab63 625 return -EADDRNOTAVAIL;
a7f5e7f1 626
1580ab63
ED
627ok:
628 hint += i + 2;
629
630 /* Head lock still held and bh's disabled */
631 inet_bind_hash(sk, tb, port);
632 if (sk_unhashed(sk)) {
633 inet_sk(sk)->inet_sport = htons(port);
634 inet_ehash_nolisten(sk, (struct sock *)tw);
a7f5e7f1 635 }
1580ab63
ED
636 if (tw)
637 inet_twsk_bind_unhash(tw, hinfo);
638 spin_unlock(&head->lock);
639 if (tw)
640 inet_twsk_deschedule_put(tw);
641 local_bh_enable();
642 return 0;
a7f5e7f1 643}
5ee31fc1
PE
644
645/*
646 * Bind a port for a connect operation and hash it.
647 */
648int inet_hash_connect(struct inet_timewait_death_row *death_row,
649 struct sock *sk)
650{
e2baad9e
ED
651 u32 port_offset = 0;
652
653 if (!inet_sk(sk)->inet_num)
654 port_offset = inet_sk_port_offset(sk);
655 return __inet_hash_connect(death_row, sk, port_offset,
b4d6444e 656 __inet_check_established);
5ee31fc1 657}
a7f5e7f1 658EXPORT_SYMBOL_GPL(inet_hash_connect);
5caea4ea
ED
659
660void inet_hashinfo_init(struct inet_hashinfo *h)
661{
662 int i;
663
c25eb3bf 664 for (i = 0; i < INET_LHTABLE_SIZE; i++) {
5caea4ea 665 spin_lock_init(&h->listening_hash[i].lock);
6cb8e266
ED
666 INIT_HLIST_NULLS_HEAD(&h->listening_hash[i].nulls_head,
667 i + LISTENING_NULLS_BASE);
3b24d854 668 }
5caea4ea 669}
5caea4ea 670EXPORT_SYMBOL_GPL(inet_hashinfo_init);
095dc8e0
ED
671
672int inet_ehash_locks_alloc(struct inet_hashinfo *hashinfo)
673{
89e478a2 674 unsigned int locksz = sizeof(spinlock_t);
095dc8e0
ED
675 unsigned int i, nblocks = 1;
676
89e478a2 677 if (locksz != 0) {
095dc8e0 678 /* allocate 2 cache lines or at least one spinlock per cpu */
89e478a2 679 nblocks = max(2U * L1_CACHE_BYTES / locksz, 1U);
095dc8e0
ED
680 nblocks = roundup_pow_of_two(nblocks * num_possible_cpus());
681
682 /* no more locks than number of hash buckets */
683 nblocks = min(nblocks, hashinfo->ehash_mask + 1);
684
752ade68 685 hashinfo->ehash_locks = kvmalloc_array(nblocks, locksz, GFP_KERNEL);
095dc8e0
ED
686 if (!hashinfo->ehash_locks)
687 return -ENOMEM;
688
689 for (i = 0; i < nblocks; i++)
690 spin_lock_init(&hashinfo->ehash_locks[i]);
691 }
692 hashinfo->ehash_locks_mask = nblocks - 1;
693 return 0;
694}
695EXPORT_SYMBOL_GPL(inet_ehash_locks_alloc);