162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci *	Vxlan multicast group handling
462306a36Sopenharmony_ci *
562306a36Sopenharmony_ci */
662306a36Sopenharmony_ci#include <linux/kernel.h>
762306a36Sopenharmony_ci#include <net/net_namespace.h>
862306a36Sopenharmony_ci#include <net/sock.h>
962306a36Sopenharmony_ci#include <linux/igmp.h>
1062306a36Sopenharmony_ci#include <net/vxlan.h>
1162306a36Sopenharmony_ci
1262306a36Sopenharmony_ci#include "vxlan_private.h"
1362306a36Sopenharmony_ci
1462306a36Sopenharmony_ci/* Update multicast group membership when first VNI on
1562306a36Sopenharmony_ci * multicast address is brought up
1662306a36Sopenharmony_ci */
1762306a36Sopenharmony_ciint vxlan_igmp_join(struct vxlan_dev *vxlan, union vxlan_addr *rip,
1862306a36Sopenharmony_ci		    int rifindex)
1962306a36Sopenharmony_ci{
2062306a36Sopenharmony_ci	union vxlan_addr *ip = (rip ? : &vxlan->default_dst.remote_ip);
2162306a36Sopenharmony_ci	int ifindex = (rifindex ? : vxlan->default_dst.remote_ifindex);
2262306a36Sopenharmony_ci	int ret = -EINVAL;
2362306a36Sopenharmony_ci	struct sock *sk;
2462306a36Sopenharmony_ci
2562306a36Sopenharmony_ci	if (ip->sa.sa_family == AF_INET) {
2662306a36Sopenharmony_ci		struct vxlan_sock *sock4 = rtnl_dereference(vxlan->vn4_sock);
2762306a36Sopenharmony_ci		struct ip_mreqn mreq = {
2862306a36Sopenharmony_ci			.imr_multiaddr.s_addr	= ip->sin.sin_addr.s_addr,
2962306a36Sopenharmony_ci			.imr_ifindex		= ifindex,
3062306a36Sopenharmony_ci		};
3162306a36Sopenharmony_ci
3262306a36Sopenharmony_ci		sk = sock4->sock->sk;
3362306a36Sopenharmony_ci		lock_sock(sk);
3462306a36Sopenharmony_ci		ret = ip_mc_join_group(sk, &mreq);
3562306a36Sopenharmony_ci		release_sock(sk);
3662306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_IPV6)
3762306a36Sopenharmony_ci	} else {
3862306a36Sopenharmony_ci		struct vxlan_sock *sock6 = rtnl_dereference(vxlan->vn6_sock);
3962306a36Sopenharmony_ci
4062306a36Sopenharmony_ci		sk = sock6->sock->sk;
4162306a36Sopenharmony_ci		lock_sock(sk);
4262306a36Sopenharmony_ci		ret = ipv6_stub->ipv6_sock_mc_join(sk, ifindex,
4362306a36Sopenharmony_ci						   &ip->sin6.sin6_addr);
4462306a36Sopenharmony_ci		release_sock(sk);
4562306a36Sopenharmony_ci#endif
4662306a36Sopenharmony_ci	}
4762306a36Sopenharmony_ci
4862306a36Sopenharmony_ci	return ret;
4962306a36Sopenharmony_ci}
5062306a36Sopenharmony_ci
5162306a36Sopenharmony_ciint vxlan_igmp_leave(struct vxlan_dev *vxlan, union vxlan_addr *rip,
5262306a36Sopenharmony_ci		     int rifindex)
5362306a36Sopenharmony_ci{
5462306a36Sopenharmony_ci	union vxlan_addr *ip = (rip ? : &vxlan->default_dst.remote_ip);
5562306a36Sopenharmony_ci	int ifindex = (rifindex ? : vxlan->default_dst.remote_ifindex);
5662306a36Sopenharmony_ci	int ret = -EINVAL;
5762306a36Sopenharmony_ci	struct sock *sk;
5862306a36Sopenharmony_ci
5962306a36Sopenharmony_ci	if (ip->sa.sa_family == AF_INET) {
6062306a36Sopenharmony_ci		struct vxlan_sock *sock4 = rtnl_dereference(vxlan->vn4_sock);
6162306a36Sopenharmony_ci		struct ip_mreqn mreq = {
6262306a36Sopenharmony_ci			.imr_multiaddr.s_addr	= ip->sin.sin_addr.s_addr,
6362306a36Sopenharmony_ci			.imr_ifindex		= ifindex,
6462306a36Sopenharmony_ci		};
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_ci		sk = sock4->sock->sk;
6762306a36Sopenharmony_ci		lock_sock(sk);
6862306a36Sopenharmony_ci		ret = ip_mc_leave_group(sk, &mreq);
6962306a36Sopenharmony_ci		release_sock(sk);
7062306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_IPV6)
7162306a36Sopenharmony_ci	} else {
7262306a36Sopenharmony_ci		struct vxlan_sock *sock6 = rtnl_dereference(vxlan->vn6_sock);
7362306a36Sopenharmony_ci
7462306a36Sopenharmony_ci		sk = sock6->sock->sk;
7562306a36Sopenharmony_ci		lock_sock(sk);
7662306a36Sopenharmony_ci		ret = ipv6_stub->ipv6_sock_mc_drop(sk, ifindex,
7762306a36Sopenharmony_ci						   &ip->sin6.sin6_addr);
7862306a36Sopenharmony_ci		release_sock(sk);
7962306a36Sopenharmony_ci#endif
8062306a36Sopenharmony_ci	}
8162306a36Sopenharmony_ci
8262306a36Sopenharmony_ci	return ret;
8362306a36Sopenharmony_ci}
8462306a36Sopenharmony_ci
8562306a36Sopenharmony_cistatic bool vxlan_group_used_match(union vxlan_addr *ip, int ifindex,
8662306a36Sopenharmony_ci				   union vxlan_addr *rip, int rifindex)
8762306a36Sopenharmony_ci{
8862306a36Sopenharmony_ci	if (!vxlan_addr_multicast(rip))
8962306a36Sopenharmony_ci		return false;
9062306a36Sopenharmony_ci
9162306a36Sopenharmony_ci	if (!vxlan_addr_equal(rip, ip))
9262306a36Sopenharmony_ci		return false;
9362306a36Sopenharmony_ci
9462306a36Sopenharmony_ci	if (rifindex != ifindex)
9562306a36Sopenharmony_ci		return false;
9662306a36Sopenharmony_ci
9762306a36Sopenharmony_ci	return true;
9862306a36Sopenharmony_ci}
9962306a36Sopenharmony_ci
10062306a36Sopenharmony_cistatic bool vxlan_group_used_by_vnifilter(struct vxlan_dev *vxlan,
10162306a36Sopenharmony_ci					  union vxlan_addr *ip, int ifindex)
10262306a36Sopenharmony_ci{
10362306a36Sopenharmony_ci	struct vxlan_vni_group *vg = rtnl_dereference(vxlan->vnigrp);
10462306a36Sopenharmony_ci	struct vxlan_vni_node *v, *tmp;
10562306a36Sopenharmony_ci
10662306a36Sopenharmony_ci	if (vxlan_group_used_match(ip, ifindex,
10762306a36Sopenharmony_ci				   &vxlan->default_dst.remote_ip,
10862306a36Sopenharmony_ci				   vxlan->default_dst.remote_ifindex))
10962306a36Sopenharmony_ci		return true;
11062306a36Sopenharmony_ci
11162306a36Sopenharmony_ci	list_for_each_entry_safe(v, tmp, &vg->vni_list, vlist) {
11262306a36Sopenharmony_ci		if (!vxlan_addr_multicast(&v->remote_ip))
11362306a36Sopenharmony_ci			continue;
11462306a36Sopenharmony_ci
11562306a36Sopenharmony_ci		if (vxlan_group_used_match(ip, ifindex,
11662306a36Sopenharmony_ci					   &v->remote_ip,
11762306a36Sopenharmony_ci					   vxlan->default_dst.remote_ifindex))
11862306a36Sopenharmony_ci			return true;
11962306a36Sopenharmony_ci	}
12062306a36Sopenharmony_ci
12162306a36Sopenharmony_ci	return false;
12262306a36Sopenharmony_ci}
12362306a36Sopenharmony_ci
12462306a36Sopenharmony_ci/* See if multicast group is already in use by other ID */
12562306a36Sopenharmony_cibool vxlan_group_used(struct vxlan_net *vn, struct vxlan_dev *dev,
12662306a36Sopenharmony_ci		      __be32 vni, union vxlan_addr *rip, int rifindex)
12762306a36Sopenharmony_ci{
12862306a36Sopenharmony_ci	union vxlan_addr *ip = (rip ? : &dev->default_dst.remote_ip);
12962306a36Sopenharmony_ci	int ifindex = (rifindex ? : dev->default_dst.remote_ifindex);
13062306a36Sopenharmony_ci	struct vxlan_dev *vxlan;
13162306a36Sopenharmony_ci	struct vxlan_sock *sock4;
13262306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_IPV6)
13362306a36Sopenharmony_ci	struct vxlan_sock *sock6;
13462306a36Sopenharmony_ci#endif
13562306a36Sopenharmony_ci	unsigned short family = dev->default_dst.remote_ip.sa.sa_family;
13662306a36Sopenharmony_ci
13762306a36Sopenharmony_ci	sock4 = rtnl_dereference(dev->vn4_sock);
13862306a36Sopenharmony_ci
13962306a36Sopenharmony_ci	/* The vxlan_sock is only used by dev, leaving group has
14062306a36Sopenharmony_ci	 * no effect on other vxlan devices.
14162306a36Sopenharmony_ci	 */
14262306a36Sopenharmony_ci	if (family == AF_INET && sock4 && refcount_read(&sock4->refcnt) == 1)
14362306a36Sopenharmony_ci		return false;
14462306a36Sopenharmony_ci
14562306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_IPV6)
14662306a36Sopenharmony_ci	sock6 = rtnl_dereference(dev->vn6_sock);
14762306a36Sopenharmony_ci	if (family == AF_INET6 && sock6 && refcount_read(&sock6->refcnt) == 1)
14862306a36Sopenharmony_ci		return false;
14962306a36Sopenharmony_ci#endif
15062306a36Sopenharmony_ci
15162306a36Sopenharmony_ci	list_for_each_entry(vxlan, &vn->vxlan_list, next) {
15262306a36Sopenharmony_ci		if (!netif_running(vxlan->dev) || vxlan == dev)
15362306a36Sopenharmony_ci			continue;
15462306a36Sopenharmony_ci
15562306a36Sopenharmony_ci		if (family == AF_INET &&
15662306a36Sopenharmony_ci		    rtnl_dereference(vxlan->vn4_sock) != sock4)
15762306a36Sopenharmony_ci			continue;
15862306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_IPV6)
15962306a36Sopenharmony_ci		if (family == AF_INET6 &&
16062306a36Sopenharmony_ci		    rtnl_dereference(vxlan->vn6_sock) != sock6)
16162306a36Sopenharmony_ci			continue;
16262306a36Sopenharmony_ci#endif
16362306a36Sopenharmony_ci		if (vxlan->cfg.flags & VXLAN_F_VNIFILTER) {
16462306a36Sopenharmony_ci			if (!vxlan_group_used_by_vnifilter(vxlan, ip, ifindex))
16562306a36Sopenharmony_ci				continue;
16662306a36Sopenharmony_ci		} else {
16762306a36Sopenharmony_ci			if (!vxlan_group_used_match(ip, ifindex,
16862306a36Sopenharmony_ci						    &vxlan->default_dst.remote_ip,
16962306a36Sopenharmony_ci						    vxlan->default_dst.remote_ifindex))
17062306a36Sopenharmony_ci				continue;
17162306a36Sopenharmony_ci		}
17262306a36Sopenharmony_ci
17362306a36Sopenharmony_ci		return true;
17462306a36Sopenharmony_ci	}
17562306a36Sopenharmony_ci
17662306a36Sopenharmony_ci	return false;
17762306a36Sopenharmony_ci}
17862306a36Sopenharmony_ci
17962306a36Sopenharmony_cistatic int vxlan_multicast_join_vnigrp(struct vxlan_dev *vxlan)
18062306a36Sopenharmony_ci{
18162306a36Sopenharmony_ci	struct vxlan_vni_group *vg = rtnl_dereference(vxlan->vnigrp);
18262306a36Sopenharmony_ci	struct vxlan_vni_node *v, *tmp, *vgood = NULL;
18362306a36Sopenharmony_ci	int ret = 0;
18462306a36Sopenharmony_ci
18562306a36Sopenharmony_ci	list_for_each_entry_safe(v, tmp, &vg->vni_list, vlist) {
18662306a36Sopenharmony_ci		if (!vxlan_addr_multicast(&v->remote_ip))
18762306a36Sopenharmony_ci			continue;
18862306a36Sopenharmony_ci		/* skip if address is same as default address */
18962306a36Sopenharmony_ci		if (vxlan_addr_equal(&v->remote_ip,
19062306a36Sopenharmony_ci				     &vxlan->default_dst.remote_ip))
19162306a36Sopenharmony_ci			continue;
19262306a36Sopenharmony_ci		ret = vxlan_igmp_join(vxlan, &v->remote_ip, 0);
19362306a36Sopenharmony_ci		if (ret == -EADDRINUSE)
19462306a36Sopenharmony_ci			ret = 0;
19562306a36Sopenharmony_ci		if (ret)
19662306a36Sopenharmony_ci			goto out;
19762306a36Sopenharmony_ci		vgood = v;
19862306a36Sopenharmony_ci	}
19962306a36Sopenharmony_ciout:
20062306a36Sopenharmony_ci	if (ret) {
20162306a36Sopenharmony_ci		list_for_each_entry_safe(v, tmp, &vg->vni_list, vlist) {
20262306a36Sopenharmony_ci			if (!vxlan_addr_multicast(&v->remote_ip))
20362306a36Sopenharmony_ci				continue;
20462306a36Sopenharmony_ci			if (vxlan_addr_equal(&v->remote_ip,
20562306a36Sopenharmony_ci					     &vxlan->default_dst.remote_ip))
20662306a36Sopenharmony_ci				continue;
20762306a36Sopenharmony_ci			vxlan_igmp_leave(vxlan, &v->remote_ip, 0);
20862306a36Sopenharmony_ci			if (v == vgood)
20962306a36Sopenharmony_ci				break;
21062306a36Sopenharmony_ci		}
21162306a36Sopenharmony_ci	}
21262306a36Sopenharmony_ci
21362306a36Sopenharmony_ci	return ret;
21462306a36Sopenharmony_ci}
21562306a36Sopenharmony_ci
21662306a36Sopenharmony_cistatic int vxlan_multicast_leave_vnigrp(struct vxlan_dev *vxlan)
21762306a36Sopenharmony_ci{
21862306a36Sopenharmony_ci	struct vxlan_net *vn = net_generic(vxlan->net, vxlan_net_id);
21962306a36Sopenharmony_ci	struct vxlan_vni_group *vg = rtnl_dereference(vxlan->vnigrp);
22062306a36Sopenharmony_ci	struct vxlan_vni_node *v, *tmp;
22162306a36Sopenharmony_ci	int last_err = 0, ret;
22262306a36Sopenharmony_ci
22362306a36Sopenharmony_ci	list_for_each_entry_safe(v, tmp, &vg->vni_list, vlist) {
22462306a36Sopenharmony_ci		if (vxlan_addr_multicast(&v->remote_ip) &&
22562306a36Sopenharmony_ci		    !vxlan_group_used(vn, vxlan, v->vni, &v->remote_ip,
22662306a36Sopenharmony_ci				      0)) {
22762306a36Sopenharmony_ci			ret = vxlan_igmp_leave(vxlan, &v->remote_ip, 0);
22862306a36Sopenharmony_ci			if (ret)
22962306a36Sopenharmony_ci				last_err = ret;
23062306a36Sopenharmony_ci		}
23162306a36Sopenharmony_ci	}
23262306a36Sopenharmony_ci
23362306a36Sopenharmony_ci	return last_err;
23462306a36Sopenharmony_ci}
23562306a36Sopenharmony_ci
23662306a36Sopenharmony_ciint vxlan_multicast_join(struct vxlan_dev *vxlan)
23762306a36Sopenharmony_ci{
23862306a36Sopenharmony_ci	int ret = 0;
23962306a36Sopenharmony_ci
24062306a36Sopenharmony_ci	if (vxlan_addr_multicast(&vxlan->default_dst.remote_ip)) {
24162306a36Sopenharmony_ci		ret = vxlan_igmp_join(vxlan, &vxlan->default_dst.remote_ip,
24262306a36Sopenharmony_ci				      vxlan->default_dst.remote_ifindex);
24362306a36Sopenharmony_ci		if (ret == -EADDRINUSE)
24462306a36Sopenharmony_ci			ret = 0;
24562306a36Sopenharmony_ci		if (ret)
24662306a36Sopenharmony_ci			return ret;
24762306a36Sopenharmony_ci	}
24862306a36Sopenharmony_ci
24962306a36Sopenharmony_ci	if (vxlan->cfg.flags & VXLAN_F_VNIFILTER)
25062306a36Sopenharmony_ci		return vxlan_multicast_join_vnigrp(vxlan);
25162306a36Sopenharmony_ci
25262306a36Sopenharmony_ci	return 0;
25362306a36Sopenharmony_ci}
25462306a36Sopenharmony_ci
25562306a36Sopenharmony_ciint vxlan_multicast_leave(struct vxlan_dev *vxlan)
25662306a36Sopenharmony_ci{
25762306a36Sopenharmony_ci	struct vxlan_net *vn = net_generic(vxlan->net, vxlan_net_id);
25862306a36Sopenharmony_ci	int ret = 0;
25962306a36Sopenharmony_ci
26062306a36Sopenharmony_ci	if (vxlan_addr_multicast(&vxlan->default_dst.remote_ip) &&
26162306a36Sopenharmony_ci	    !vxlan_group_used(vn, vxlan, 0, NULL, 0)) {
26262306a36Sopenharmony_ci		ret = vxlan_igmp_leave(vxlan, &vxlan->default_dst.remote_ip,
26362306a36Sopenharmony_ci				       vxlan->default_dst.remote_ifindex);
26462306a36Sopenharmony_ci		if (ret)
26562306a36Sopenharmony_ci			return ret;
26662306a36Sopenharmony_ci	}
26762306a36Sopenharmony_ci
26862306a36Sopenharmony_ci	if (vxlan->cfg.flags & VXLAN_F_VNIFILTER)
26962306a36Sopenharmony_ci		return vxlan_multicast_leave_vnigrp(vxlan);
27062306a36Sopenharmony_ci
27162306a36Sopenharmony_ci	return 0;
27262306a36Sopenharmony_ci}
273