1/*	$NetBSD: ip6_var.h,v 1.93 2022/10/28 05:18:39 ozaki-r Exp $	*/
  2/*	$KAME: ip6_var.h,v 1.33 2000/06/11 14:59:20 jinmei Exp $	*/
  3
  4/*
  5 * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
  6 * All rights reserved.
  7 *
  8 * Redistribution and use in source and binary forms, with or without
  9 * modification, are permitted provided that the following conditions
 10 * are met:
 11 * 1. Redistributions of source code must retain the above copyright
 12 *    notice, this list of conditions and the following disclaimer.
 13 * 2. Redistributions in binary form must reproduce the above copyright
 14 *    notice, this list of conditions and the following disclaimer in the
 15 *    documentation and/or other materials provided with the distribution.
 16 * 3. Neither the name of the project nor the names of its contributors
 17 *    may be used to endorse or promote products derived from this software
 18 *    without specific prior written permission.
 19 *
 20 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
 21 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 23 * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
 24 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
 25 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
 26 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 27 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
 28 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 29 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 30 * SUCH DAMAGE.
 31 */
 32
 33/*
 34 * Copyright (c) 1982, 1986, 1993
 35 *	The Regents of the University of California.  All rights reserved.
 36 *
 37 * Redistribution and use in source and binary forms, with or without
 38 * modification, are permitted provided that the following conditions
 39 * are met:
 40 * 1. Redistributions of source code must retain the above copyright
 41 *    notice, this list of conditions and the following disclaimer.
 42 * 2. Redistributions in binary form must reproduce the above copyright
 43 *    notice, this list of conditions and the following disclaimer in the
 44 *    documentation and/or other materials provided with the distribution.
 45 * 3. Neither the name of the University nor the names of its contributors
 46 *    may be used to endorse or promote products derived from this software
 47 *    without specific prior written permission.
 48 *
 49 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
 50 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 51 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 52 * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
 53 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
 54 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
 55 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 56 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
 57 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 58 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 59 * SUCH DAMAGE.
 60 *
 61 *	@(#)ip_var.h	8.1 (Berkeley) 6/10/93
 62 */
 63
 64#ifndef _NETINET6_IP6_VAR_H_
 65#define _NETINET6_IP6_VAR_H_
 66
 67#include <sys/types.h>
 68#include <sys/queue.h>
 69#include <sys/socketvar.h>
 70
 71#include <net/if.h>
 72#include <net/route.h>
 73
 74#include <netinet/in.h>
 75#include <netinet/ip6.h>
 76
 77struct	ip6_moptions {
 78	if_index_t im6o_multicast_if_index; /* I/F for outgoing multicasts */
 79	u_char	im6o_multicast_hlim;	/* hoplimit for outgoing multicasts */
 80	u_char	im6o_multicast_loop;	/* 1 >= hear sends if a member */
 81	LIST_HEAD(, in6_multi_mship) im6o_memberships;
 82};
 83
 84/*
 85 * Control options for outgoing packets
 86 */
 87
 88/* Routing header related info */
 89struct	ip6po_rhinfo {
 90	struct	ip6_rthdr *ip6po_rhi_rthdr; /* Routing header */
 91	struct	route ip6po_rhi_route; /* Route to the 1st hop */
 92};
 93#define ip6po_rthdr	ip6po_rhinfo.ip6po_rhi_rthdr
 94#define ip6po_route	ip6po_rhinfo.ip6po_rhi_route
 95
 96/* Nexthop related info */
 97struct	ip6po_nhinfo {
 98	struct	sockaddr *ip6po_nhi_nexthop;
 99	struct	route ip6po_nhi_route; /* Route to the nexthop */
100};
101#define ip6po_nexthop	ip6po_nhinfo.ip6po_nhi_nexthop
102#define ip6po_nextroute	ip6po_nhinfo.ip6po_nhi_route
103
104struct	ip6_pktopts {
105	int	ip6po_hlim;		/* Hoplimit for outgoing packets */
106	struct	in6_pktinfo *ip6po_pktinfo; /* Outgoing IF/address information */
107	struct	ip6po_nhinfo ip6po_nhinfo; /* Next-hop address information */
108	struct	ip6_hbh *ip6po_hbh; /* Hop-by-Hop options header */
109	struct	ip6_dest *ip6po_dest1; /* Destination options header(1st part) */
110	struct	ip6po_rhinfo ip6po_rhinfo; /* Routing header related info. */
111	struct	ip6_dest *ip6po_dest2; /* Destination options header(2nd part) */
112	int	ip6po_tclass;	/* traffic class */
113	int	ip6po_minmtu;  /* fragment vs PMTU discovery policy */
114#define IP6PO_MINMTU_MCASTONLY	-1 /* default; send at min MTU for multicast*/
115#define IP6PO_MINMTU_DISABLE	 0 /* always perform pmtu disc */
116#define IP6PO_MINMTU_ALL	 1 /* always send at min MTU */
117	int	ip6po_prefer_tempaddr;	/* whether temporary addresses are
118					 * preferred as source address */
119#define IP6PO_TEMPADDR_SYSTEM	-1 /* follow the system default */
120#define IP6PO_TEMPADDR_NOTPREFER 0 /* not prefer temporary address */
121#define IP6PO_TEMPADDR_PREFER	 1 /* prefer temporary address */
122	int ip6po_flags;
123#if 0	/* parameters in this block is obsolete. do not reuse the values. */
124#define IP6PO_REACHCONF	0x01	/* upper-layer reachability confirmation. */
125#define IP6PO_MINMTU	0x02	/* use minimum MTU (IPV6_USE_MIN_MTU) */
126#endif
127#define IP6PO_DONTFRAG	0x04	/* disable fragmentation (IPV6_DONTFRAG) */
128};
129
130/*
131 * IPv6 statistics.
132 * Each counter is an unsigned 64-bit value.
133 */
134#define	IP6_STAT_TOTAL		0	/* total packets received */
135#define	IP6_STAT_TOOSHORT	1	/* packet too short */
136#define	IP6_STAT_TOOSMALL	2	/* not enough data */
137#define	IP6_STAT_FRAGMENTS	3	/* fragments received */
138#define	IP6_STAT_FRAGDROPPED	4	/* frags dropped (dups, out of space) */
139#define	IP6_STAT_FRAGTIMEOUT	5	/* fragments timed out */
140#define	IP6_STAT_FRAGOVERFLOW	6	/* fragments that exceed limit */
141#define IP6_STAT_FORWARD	7	/* packets forwarded */
142#define	IP6_STAT_CANTFORWARD	8	/* packets rcvd for uncreachable dst */
143#define	IP6_STAT_REDIRECTSENT	9	/* packets forwarded on same net */
144#define	IP6_STAT_DELIVERED	10	/* datagrams delivered to upper level */
145#define	IP6_STAT_LOCALOUT	11	/* total IP packets generated here */
146#define	IP6_STAT_ODROPPED	12	/* lost packets due to nobufs, etc. */
147#define	IP6_STAT_REASSEMBLED	13	/* total packets reassembled ok */
148#define	IP6_STAT_FRAGMENTED	14	/* datagrams successfully fragmented */
149#define	IP6_STAT_OFRAGMENTS	15	/* output fragments created */
150#define	IP6_STAT_CANTFRAG	16	/* don't fragment flag was set, etc. */
151#define	IP6_STAT_BADOPTIONS	17	/* error in option processing */
152#define	IP6_STAT_NOROUTE	18	/* packets discarded due to no route */
153#define	IP6_STAT_BADVERS	19	/* ip6 version != 6 */
154#define	IP6_STAT_RAWOUT		20	/* total raw ip packets generated */
155#define	IP6_STAT_BADSCOPE	21	/* scope error */
156#define	IP6_STAT_NOTMEMBER	22	/* don't join this multicast group */
157#define	IP6_STAT_NXTHIST	23	/* next header histogram */
158		/* space for 256 counters */
159#define	IP6_STAT_M1		279	/* one mbuf */
160#define	IP6_STAT_M2M		280	/* two or more mbuf */
161		/* space for 32 counters */
162#define	IP6_STAT_MEXT1		312	/* one ext mbuf */
163#define	IP6_STAT_MEXT2M		313	/* two or more ext mbuf */
164#define	IP6_STAT_EXTHDRTOOLONG	314	/* ext hdr are not contiguous */
165#define	IP6_STAT_NOGIF		315	/* no match gif found */
166#define	IP6_STAT_TOOMANYHDR	316	/* discarded due to too many headers */
167	/*
168	 * statistics for improvement of the source address selection
169	 * algorithm:
170	 * XXX: hardcoded 16 = # of ip6 multicast scope types + 1
171	 */
172#define	IP6_STAT_SOURCES_NONE	317	/* number of times that address
173					   selection fails */
174#define	IP6_STAT_SOURCES_SAMEIF	318	/* number of times that an address
175					   on the outgoing I/F is chosen */
176		/* space for 16 counters */
177#define	IP6_STAT_SOURCES_OTHERIF 334	/* number of times that an address on
178					   a non-outgoing I/F is chosen */
179		/* space for 16 counters */
180#define	IP6_STAT_SOURCES_SAMESCOPE 350	/* number of times that an address that
181					   has the same scope from the dest.
182					   is chosen */
183		/* space for 16 counters */
184#define	IP6_STAT_SOURCES_OTHERSCOPE 366	/* number of times that an address that
185					   has a different scope from the dest.
186					   is chosen */
187		/* space for 16 counters */
188#define	IP6_STAT_SOURCES_DEPRECATED 382	/* number of times that a deprecated
189					   address is chosen */
190		/* space for 16 counters */
191#define	IP6_STAT_FORWARD_CACHEHIT 398
192#define	IP6_STAT_FORWARD_CACHEMISS 399
193#define	IP6_STAT_FASTFORWARD	400	/* packets fast forwarded */
194#define	IP6_STAT_FASTFORWARDFLOWS 401	/* number of fast forward flows */
195#define	IP6_STAT_NOIPSEC	402	/* no match ipsec(4) found */
196#define	IP6_STAT_PFILDROP_IN	403	/* dropped by pfil (PFIL_IN) */
197#define	IP6_STAT_PFILDROP_OUT	404	/* dropped by pfil (PFIL_OUT) */
198#define	IP6_STAT_IPSECDROP_IN	405	/* dropped by IPsec SP check */
199#define	IP6_STAT_IPSECDROP_OUT	406	/* dropped by IPsec SP check */
200#define	IP6_STAT_IFDROP		407	/* dropped due to interface state */
201#define	IP6_STAT_IDROPPED	408	/* lost packets due to nobufs, etc. */
202#define	IP6_STAT_TIMXCEED	409	/* hop limit exceeded */
203#define	IP6_STAT_TOOBIG		410	/* packet bigger than MTU */
204#define	IP6_STAT_RTREJECT	411	/* rejected by route */
205
206#define	IP6_NSTATS		412
207
208#define IP6FLOW_HASHBITS         6 /* should not be a multiple of 8 */
209
210/* 
211 * Structure for an IPv6 flow (ip6_fastforward).
212 */
213struct ip6flow {
214	TAILQ_ENTRY(ip6flow) ip6f_list;  /* next in active list */
215	TAILQ_ENTRY(ip6flow) ip6f_hash;  /* next ip6flow in bucket */
216	size_t ip6f_hashidx;             /* own hash index of ipflowtable[] */
217	struct in6_addr ip6f_dst;       /* destination address */
218	struct in6_addr ip6f_src;       /* source address */
219	struct route ip6f_ro;       /* associated route entry */
220	u_int32_t ip6f_flow;		/* flow (tos) */
221	u_quad_t ip6f_uses;               /* number of uses in this period */
222	u_quad_t ip6f_last_uses;          /* number of uses in last period */
223	u_quad_t ip6f_dropped;            /* ENOBUFS returned by if_output */
224	u_quad_t ip6f_forwarded;          /* packets forwarded */
225	u_int ip6f_timer;               /* lifetime timer */
226};
227
228#ifdef _KERNEL
229
230#include <sys/protosw.h>
231#include <sys/cprng.h>
232
233/*
234 * Auxiliary attributes of incoming IPv6 packets, which is initialized when we
235 * come into ip6_input().
236 * XXX do not make it a kitchen sink!
237 */
238struct ip6aux {
239	/* ip6.ip6_dst */
240	struct in6_addr	ip6a_src;
241	uint32_t	ip6a_scope_id;
242	int		ip6a_flags;
243};
244
245/* flags passed to ip6_output as last parameter */
246#define	IPV6_UNSPECSRC		0x01	/* allow :: as the source address */
247#define	IPV6_FORWARDING		0x02	/* most of IPv6 header exists */
248#define	IPV6_MINMTU		0x04	/* use minimum MTU (IPV6_USE_MIN_MTU) */
249
250extern u_int32_t ip6_id;		/* fragment identifier */
251extern int	ip6_defhlim;		/* default hop limit */
252extern int	ip6_defmcasthlim;	/* default multicast hop limit */
253extern int	ip6_forwarding;		/* act as router? */
254extern int	ip6_sendredirect;	/* send ICMPv6 redirect? */
255extern int	ip6_use_deprecated;	/* allow deprecated addr as source */
256extern int	ip6_mcast_pmtu;		/* enable pMTU discovery for multicast? */
257extern int	ip6_v6only;
258extern int	ip6_neighborgcthresh;	/* Threshold # of NDP entries for GC */
259extern int	ip6_maxdynroutes; /* Max # of routes created via redirect */
260extern int	ip6_param_rt_msg;  /* How to send parmeter changing rtm */
261
262
263extern struct socket *ip6_mrouter; 	/* multicast routing daemon */
264extern int	ip6_sendredirects;	/* send IP redirects when forwarding? */
265extern int	ip6_maxfragpackets; /* Maximum packets in reassembly queue */
266extern int	ip6_maxfrags;	/* Maximum fragments in reassembly queue */
267extern int	ip6_keepfaith;		/* Firewall Aided Internet Translator */
268extern int	ip6_log_interval;
269extern time_t	ip6_log_time;
270extern int	ip6_hdrnestlimit; /* upper limit of # of extension headers */
271extern int	ip6_dad_count;		/* DupAddrDetectionTransmits */
272
273extern int ip6_auto_flowlabel;
274extern int ip6_auto_linklocal;
275
276extern int   ip6_anonportmin;		/* minimum ephemeral port */
277extern int   ip6_anonportmax;		/* maximum ephemeral port */
278extern int   ip6_lowportmin;		/* minimum reserved port */
279extern int   ip6_lowportmax;		/* maximum reserved port */
280
281extern int	ip6_prefer_tempaddr; /* whether to prefer temporary addresses
282					in the source address selection */
283extern int	ip6_use_defzone; /* whether to use the default scope zone
284				    when unspecified */
285
286#ifdef GATEWAY
287extern int      ip6_maxflows;           /* maximum amount of flows for ip6ff */
288extern int	ip6_hashsize;		/* size of hash table */
289#endif
290
291struct inpcb;
292extern const struct pr_usrreqs rip6_usrreqs;
293
294int	icmp6_ctloutput(int, struct socket *, struct sockopt *);
295
296struct mbuf;
297void	ip6_init(void);
298const struct ip6aux *ip6_getdstifaddr(struct mbuf *);
299void	ip6_freepcbopts(struct ip6_pktopts *);
300void	ip6_freemoptions(struct ip6_moptions *);
301int	ip6_unknown_opt(u_int8_t *, struct mbuf *, int);
302int	ip6_get_prevhdr(struct mbuf *, int);
303int	ip6_nexthdr(struct mbuf *, int, int, int *);
304int	ip6_lasthdr(struct mbuf *, int, int, int *);
305
306struct ip6_hdr;
307int	ip6_mforward(struct ip6_hdr *, struct ifnet *, struct mbuf *);
308int	ip6_hopopts_input(u_int32_t *, u_int32_t *, struct mbuf **, int *);
309void	ip6_savecontrol(struct inpcb *, struct mbuf **, struct ip6_hdr *,
310		struct mbuf *);
311void	ip6_notify_pmtu(struct inpcb *, const struct sockaddr_in6 *,
312		u_int32_t *);
313int	ip6_sysctl(int *, u_int, void *, size_t *, void *, size_t);
314
315void	ip6_forward(struct mbuf *, int, struct ifnet *);
316
317void	ip6_mloopback(struct ifnet *, struct mbuf *,
318	              const struct sockaddr_in6 *);
319int	ip6_output(struct mbuf *, struct ip6_pktopts *, struct route *, int,
320	    struct ip6_moptions *, struct inpcb *, struct ifnet **);
321int	ip6_if_output(struct ifnet * const, struct ifnet * const,
322	    struct mbuf * const,
323	    const struct sockaddr_in6 * const, const struct rtentry *);
324int	ip6_ctloutput(int, struct socket *, struct sockopt *);
325int	ip6_raw_ctloutput(int, struct socket *, struct sockopt *);
326void	ip6_initpktopts(struct ip6_pktopts *);
327int	ip6_setpktopts(struct mbuf *, struct ip6_pktopts *,
328			    struct ip6_pktopts *, kauth_cred_t, int);
329void	ip6_clearpktopts(struct ip6_pktopts *, int);
330struct ip6_pktopts *ip6_copypktopts(struct ip6_pktopts *, int);
331int	ip6_optlen(struct inpcb *);
332
333void	ip6_statinc(u_int);
334
335int	route6_input(struct mbuf **, int *, int);
336
337void	frag6_init(void);
338int	frag6_input(struct mbuf **, int *, int);
339int	ip6_reass_packet(struct mbuf **, int);
340void	frag6_slowtimo(void);
341void	frag6_fasttimo(void);
342void	frag6_drain(void);
343void	frag6_drainstub(void);
344
345int	ip6flow_init(int);
346void	ip6flow_poolinit(void);
347struct  ip6flow *ip6flow_reap(int);
348void    ip6flow_create(struct route *, struct mbuf *);
349void    ip6flow_slowtimo(void);
350int	ip6flow_invalidate_all(int);
351
352void	rip6_init(void);
353int	rip6_input(struct mbuf **, int *, int);
354void	*rip6_ctlinput(int, const struct sockaddr *, void *);
355int	rip6_ctloutput(int, struct socket *, struct sockopt *);
356int	rip6_output(struct mbuf *, struct socket *, struct sockaddr_in6 *,
357			 struct mbuf *);
358int	rip6_attach(struct socket *, int);
359int	rip6_usrreq(struct socket *,
360	    int, struct mbuf *, struct mbuf *, struct mbuf *, struct lwp *);
361
362int	dest6_input(struct mbuf **, int *, int);
363int	none_input(struct mbuf **, int *, int);
364
365struct route;
366
367int	in6_selectsrc(struct sockaddr_in6 *, struct ip6_pktopts *,
368	   struct ip6_moptions *, struct route *, struct in6_addr *,
369	   struct ifnet **, struct psref *, struct in6_addr *);
370int in6_selectroute(struct sockaddr_in6 *, struct ip6_pktopts *,
371	struct route **, struct rtentry **, bool);
372int	ip6_get_membership(const struct sockopt *, struct ifnet **,
373	    struct psref *, void *, size_t);
374
375static __inline uint32_t
376ip6_randomid(void)
377{
378
379	return cprng_fast32();
380}
381
382static __inline uint32_t
383ip6_randomflowlabel(void)
384{
385
386	return cprng_fast32() & 0xfffff;
387}
388
389static __inline bool
390ip6_dad_enabled(void)
391{
392
393	return ip6_dad_count > 0;
394}
395#endif /* _KERNEL */
396
397#endif /* !_NETINET6_IP6_VAR_H_ */