Commit 83ba4645 authored by Vincent Bernat's avatar Vincent Bernat Committed by David S. Miller

net: add helpers checking if socket can be bound to nonlocal address

The construction "net->ipv4.sysctl_ip_nonlocal_bind || inet->freebind
|| inet->transparent" is present three times and its IPv6 counterpart
is also present three times. We introduce two small helpers to
characterize these tests uniformly.
Signed-off-by: default avatarVincent Bernat <vincent@bernat.im>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent d39db3b4
...@@ -359,4 +359,12 @@ static inline bool inet_get_convert_csum(struct sock *sk) ...@@ -359,4 +359,12 @@ static inline bool inet_get_convert_csum(struct sock *sk)
return !!inet_sk(sk)->convert_csum; return !!inet_sk(sk)->convert_csum;
} }
static inline bool inet_can_nonlocal_bind(struct net *net,
struct inet_sock *inet)
{
return net->ipv4.sysctl_ip_nonlocal_bind ||
inet->freebind || inet->transparent;
}
#endif /* _INET_SOCK_H */ #endif /* _INET_SOCK_H */
...@@ -766,6 +766,13 @@ static inline int ip6_sk_dst_hoplimit(struct ipv6_pinfo *np, struct flowi6 *fl6, ...@@ -766,6 +766,13 @@ static inline int ip6_sk_dst_hoplimit(struct ipv6_pinfo *np, struct flowi6 *fl6,
return hlimit; return hlimit;
} }
static inline bool ipv6_can_nonlocal_bind(struct net *net,
struct inet_sock *inet)
{
return net->ipv6.sysctl.ip_nonlocal_bind ||
inet->freebind || inet->transparent;
}
/* copy IPv6 saddr & daddr to flow_keys, possibly using 64bit load/store /* copy IPv6 saddr & daddr to flow_keys, possibly using 64bit load/store
* Equivalent to : flow->v6addrs.src = iph->saddr; * Equivalent to : flow->v6addrs.src = iph->saddr;
* flow->v6addrs.dst = iph->daddr; * flow->v6addrs.dst = iph->daddr;
......
...@@ -486,8 +486,7 @@ int __inet_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len, ...@@ -486,8 +486,7 @@ int __inet_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len,
* is temporarily down) * is temporarily down)
*/ */
err = -EADDRNOTAVAIL; err = -EADDRNOTAVAIL;
if (!net->ipv4.sysctl_ip_nonlocal_bind && if (!inet_can_nonlocal_bind(net, inet) &&
!(inet->freebind || inet->transparent) &&
addr->sin_addr.s_addr != htonl(INADDR_ANY) && addr->sin_addr.s_addr != htonl(INADDR_ANY) &&
chk_addr_ret != RTN_LOCAL && chk_addr_ret != RTN_LOCAL &&
chk_addr_ret != RTN_MULTICAST && chk_addr_ret != RTN_MULTICAST &&
......
...@@ -320,8 +320,7 @@ static int ping_check_bind_addr(struct sock *sk, struct inet_sock *isk, ...@@ -320,8 +320,7 @@ static int ping_check_bind_addr(struct sock *sk, struct inet_sock *isk,
if (addr->sin_addr.s_addr == htonl(INADDR_ANY)) if (addr->sin_addr.s_addr == htonl(INADDR_ANY))
chk_addr_ret = RTN_LOCAL; chk_addr_ret = RTN_LOCAL;
if ((net->ipv4.sysctl_ip_nonlocal_bind == 0 && if ((!inet_can_nonlocal_bind(net, isk) &&
isk->freebind == 0 && isk->transparent == 0 &&
chk_addr_ret != RTN_LOCAL) || chk_addr_ret != RTN_LOCAL) ||
chk_addr_ret == RTN_MULTICAST || chk_addr_ret == RTN_MULTICAST ||
chk_addr_ret == RTN_BROADCAST) chk_addr_ret == RTN_BROADCAST)
...@@ -361,8 +360,7 @@ static int ping_check_bind_addr(struct sock *sk, struct inet_sock *isk, ...@@ -361,8 +360,7 @@ static int ping_check_bind_addr(struct sock *sk, struct inet_sock *isk,
scoped); scoped);
rcu_read_unlock(); rcu_read_unlock();
if (!(net->ipv6.sysctl.ip_nonlocal_bind || if (!(ipv6_can_nonlocal_bind(net, isk) || has_addr ||
isk->freebind || isk->transparent || has_addr ||
addr_type == IPV6_ADDR_ANY)) addr_type == IPV6_ADDR_ANY))
return -EADDRNOTAVAIL; return -EADDRNOTAVAIL;
......
...@@ -322,8 +322,7 @@ static int __inet6_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len, ...@@ -322,8 +322,7 @@ static int __inet6_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len,
/* Reproduce AF_INET checks to make the bindings consistent */ /* Reproduce AF_INET checks to make the bindings consistent */
v4addr = addr->sin6_addr.s6_addr32[3]; v4addr = addr->sin6_addr.s6_addr32[3];
chk_addr_ret = inet_addr_type(net, v4addr); chk_addr_ret = inet_addr_type(net, v4addr);
if (!net->ipv4.sysctl_ip_nonlocal_bind && if (!inet_can_nonlocal_bind(net, inet) &&
!(inet->freebind || inet->transparent) &&
v4addr != htonl(INADDR_ANY) && v4addr != htonl(INADDR_ANY) &&
chk_addr_ret != RTN_LOCAL && chk_addr_ret != RTN_LOCAL &&
chk_addr_ret != RTN_MULTICAST && chk_addr_ret != RTN_MULTICAST &&
...@@ -362,8 +361,7 @@ static int __inet6_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len, ...@@ -362,8 +361,7 @@ static int __inet6_bind(struct sock *sk, struct sockaddr *uaddr, int addr_len,
*/ */
v4addr = LOOPBACK4_IPV6; v4addr = LOOPBACK4_IPV6;
if (!(addr_type & IPV6_ADDR_MULTICAST)) { if (!(addr_type & IPV6_ADDR_MULTICAST)) {
if (!net->ipv6.sysctl.ip_nonlocal_bind && if (!ipv6_can_nonlocal_bind(net, inet) &&
!(inet->freebind || inet->transparent) &&
!ipv6_chk_addr(net, &addr->sin6_addr, !ipv6_chk_addr(net, &addr->sin6_addr,
dev, 0)) { dev, 0)) {
err = -EADDRNOTAVAIL; err = -EADDRNOTAVAIL;
......
...@@ -803,8 +803,7 @@ int ip6_datagram_send_ctl(struct net *net, struct sock *sk, ...@@ -803,8 +803,7 @@ int ip6_datagram_send_ctl(struct net *net, struct sock *sk,
if (addr_type != IPV6_ADDR_ANY) { if (addr_type != IPV6_ADDR_ANY) {
int strict = __ipv6_addr_src_scope(addr_type) <= IPV6_ADDR_SCOPE_LINKLOCAL; int strict = __ipv6_addr_src_scope(addr_type) <= IPV6_ADDR_SCOPE_LINKLOCAL;
if (!(net->ipv6.sysctl.ip_nonlocal_bind || if (!ipv6_can_nonlocal_bind(net, inet_sk(sk)) &&
inet_sk(sk)->freebind || inet_sk(sk)->transparent) &&
!ipv6_chk_addr_and_flags(net, &src_info->ipi6_addr, !ipv6_chk_addr_and_flags(net, &src_info->ipi6_addr,
dev, !strict, 0, dev, !strict, 0,
IFA_F_TENTATIVE) && IFA_F_TENTATIVE) &&
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment