xref: /netbsd-src/sys/net/route.c (revision 3816d47b2c42fcd6e549e3407f842a5b1a1d23ad)
1 /*	$NetBSD: route.c,v 1.121 2009/11/03 00:30:11 dyoung Exp $	*/
2 
3 /*-
4  * Copyright (c) 1998, 2008 The NetBSD Foundation, Inc.
5  * All rights reserved.
6  *
7  * This code is derived from software contributed to The NetBSD Foundation
8  * by Kevin M. Lahey of the Numerical Aerospace Simulation Facility,
9  * NASA Ames Research Center.
10  *
11  * Redistribution and use in source and binary forms, with or without
12  * modification, are permitted provided that the following conditions
13  * are met:
14  * 1. Redistributions of source code must retain the above copyright
15  *    notice, this list of conditions and the following disclaimer.
16  * 2. Redistributions in binary form must reproduce the above copyright
17  *    notice, this list of conditions and the following disclaimer in the
18  *    documentation and/or other materials provided with the distribution.
19  *
20  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
21  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
22  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
23  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
24  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
30  * POSSIBILITY OF SUCH DAMAGE.
31  */
32 
33 /*
34  * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
35  * All rights reserved.
36  *
37  * Redistribution and use in source and binary forms, with or without
38  * modification, are permitted provided that the following conditions
39  * are met:
40  * 1. Redistributions of source code must retain the above copyright
41  *    notice, this list of conditions and the following disclaimer.
42  * 2. Redistributions in binary form must reproduce the above copyright
43  *    notice, this list of conditions and the following disclaimer in the
44  *    documentation and/or other materials provided with the distribution.
45  * 3. Neither the name of the project nor the names of its contributors
46  *    may be used to endorse or promote products derived from this software
47  *    without specific prior written permission.
48  *
49  * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
50  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
51  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
52  * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
53  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
54  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
55  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
56  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
57  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
58  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
59  * SUCH DAMAGE.
60  */
61 
62 /*
63  * Copyright (c) 1980, 1986, 1991, 1993
64  *	The Regents of the University of California.  All rights reserved.
65  *
66  * Redistribution and use in source and binary forms, with or without
67  * modification, are permitted provided that the following conditions
68  * are met:
69  * 1. Redistributions of source code must retain the above copyright
70  *    notice, this list of conditions and the following disclaimer.
71  * 2. Redistributions in binary form must reproduce the above copyright
72  *    notice, this list of conditions and the following disclaimer in the
73  *    documentation and/or other materials provided with the distribution.
74  * 3. Neither the name of the University nor the names of its contributors
75  *    may be used to endorse or promote products derived from this software
76  *    without specific prior written permission.
77  *
78  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
79  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
80  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
81  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
82  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
83  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
84  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
85  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
86  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
87  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
88  * SUCH DAMAGE.
89  *
90  *	@(#)route.c	8.3 (Berkeley) 1/9/95
91  */
92 
93 #include "opt_route.h"
94 
95 #include <sys/cdefs.h>
96 __KERNEL_RCSID(0, "$NetBSD: route.c,v 1.121 2009/11/03 00:30:11 dyoung Exp $");
97 
98 #include <sys/param.h>
99 #include <sys/sysctl.h>
100 #include <sys/systm.h>
101 #include <sys/callout.h>
102 #include <sys/proc.h>
103 #include <sys/mbuf.h>
104 #include <sys/socket.h>
105 #include <sys/socketvar.h>
106 #include <sys/domain.h>
107 #include <sys/protosw.h>
108 #include <sys/kernel.h>
109 #include <sys/ioctl.h>
110 #include <sys/pool.h>
111 #include <sys/kauth.h>
112 
113 #include <net/if.h>
114 #include <net/if_dl.h>
115 #include <net/route.h>
116 #include <net/raw_cb.h>
117 
118 #include <netinet/in.h>
119 #include <netinet/in_var.h>
120 
121 #ifdef RTFLUSH_DEBUG
122 #define	rtcache_debug() __predict_false(_rtcache_debug)
123 #else /* RTFLUSH_DEBUG */
124 #define	rtcache_debug() 0
125 #endif /* RTFLUSH_DEBUG */
126 
127 struct	route_cb route_cb;
128 struct	rtstat	rtstat;
129 struct	radix_node_head *rt_tables[AF_MAX+1];
130 
131 int	rttrash;		/* routes not in table but not freed */
132 
133 struct pool rtentry_pool;
134 struct pool rttimer_pool;
135 
136 struct callout rt_timer_ch; /* callout for rt_timer_timer() */
137 
138 #ifdef RTFLUSH_DEBUG
139 static int _rtcache_debug = 0;
140 #endif /* RTFLUSH_DEBUG */
141 
142 static kauth_listener_t route_listener;
143 
144 static int rtdeletemsg(struct rtentry *);
145 static int rtflushclone1(struct rtentry *, void *);
146 static void rtflushclone(sa_family_t family, struct rtentry *);
147 
148 #ifdef RTFLUSH_DEBUG
149 static void sysctl_net_rtcache_setup(struct sysctllog **);
150 static void
151 sysctl_net_rtcache_setup(struct sysctllog **clog)
152 {
153 	const struct sysctlnode *rnode;
154 
155 	/* XXX do not duplicate */
156 	if (sysctl_createv(clog, 0, NULL, &rnode, CTLFLAG_PERMANENT,
157 	    CTLTYPE_NODE, "net", NULL, NULL, 0, NULL, 0, CTL_NET, CTL_EOL) != 0)
158 		return;
159 	if (sysctl_createv(clog, 0, &rnode, &rnode, CTLFLAG_PERMANENT,
160 	    CTLTYPE_NODE,
161 	    "rtcache", SYSCTL_DESCR("Route cache related settings"),
162 	    NULL, 0, NULL, 0, CTL_CREATE, CTL_EOL) != 0)
163 		return;
164 	if (sysctl_createv(clog, 0, &rnode, &rnode,
165 	    CTLFLAG_PERMANENT|CTLFLAG_READWRITE, CTLTYPE_INT,
166 	    "debug", SYSCTL_DESCR("Debug route caches"),
167 	    NULL, 0, &_rtcache_debug, 0, CTL_CREATE, CTL_EOL) != 0)
168 		return;
169 }
170 #endif /* RTFLUSH_DEBUG */
171 
172 struct ifaddr *
173 rt_get_ifa(struct rtentry *rt)
174 {
175 	struct ifaddr *ifa;
176 
177 	if ((ifa = rt->rt_ifa) == NULL)
178 		return ifa;
179 	else if (ifa->ifa_getifa == NULL)
180 		return ifa;
181 #if 0
182 	else if (ifa->ifa_seqno != NULL && *ifa->ifa_seqno == rt->rt_ifa_seqno)
183 		return ifa;
184 #endif
185 	else {
186 		ifa = (*ifa->ifa_getifa)(ifa, rt_getkey(rt));
187 		rt_replace_ifa(rt, ifa);
188 		return ifa;
189 	}
190 }
191 
192 static void
193 rt_set_ifa1(struct rtentry *rt, struct ifaddr *ifa)
194 {
195 	rt->rt_ifa = ifa;
196 	if (ifa->ifa_seqno != NULL)
197 		rt->rt_ifa_seqno = *ifa->ifa_seqno;
198 }
199 
200 /*
201  * Is this route the connected route for the ifa?
202  */
203 static int
204 rt_ifa_connected(const struct rtentry *rt, const struct ifaddr *ifa)
205 {
206 	const struct sockaddr *key, *dst, *odst;
207 	struct sockaddr_storage maskeddst;
208 
209 	key = rt_getkey(rt);
210 	dst = rt->rt_flags & RTF_HOST ? ifa->ifa_dstaddr : ifa->ifa_addr;
211 	if (dst == NULL ||
212 	    dst->sa_family != key->sa_family ||
213 	    dst->sa_len != key->sa_len)
214 		return 0;
215 	if ((rt->rt_flags & RTF_HOST) == 0 && ifa->ifa_netmask) {
216 		odst = dst;
217 		dst = (struct sockaddr *)&maskeddst;
218 		rt_maskedcopy(odst, (struct sockaddr *)&maskeddst,
219 		    ifa->ifa_netmask);
220 	}
221 	return (memcmp(dst, key, dst->sa_len) == 0);
222 }
223 
224 void
225 rt_replace_ifa(struct rtentry *rt, struct ifaddr *ifa)
226 {
227 	if (rt->rt_ifa &&
228 	    rt->rt_ifa != ifa &&
229 	    rt->rt_ifa->ifa_flags & IFA_ROUTE &&
230 	    rt_ifa_connected(rt, rt->rt_ifa))
231 	{
232 		RT_DPRINTF("rt->_rt_key = %p, ifa = %p, "
233 		    "replace deleted IFA_ROUTE\n",
234 		    (void *)rt->_rt_key, (void *)rt->rt_ifa);
235 		rt->rt_ifa->ifa_flags &= ~IFA_ROUTE;
236 		if (rt_ifa_connected(rt, ifa)) {
237 			RT_DPRINTF("rt->_rt_key = %p, ifa = %p, "
238 			    "replace added IFA_ROUTE\n",
239 			    (void *)rt->_rt_key, (void *)ifa);
240 			ifa->ifa_flags |= IFA_ROUTE;
241 		}
242 	}
243 
244 	IFAREF(ifa);
245 	IFAFREE(rt->rt_ifa);
246 	rt_set_ifa1(rt, ifa);
247 }
248 
249 static void
250 rt_set_ifa(struct rtentry *rt, struct ifaddr *ifa)
251 {
252 	IFAREF(ifa);
253 	rt_set_ifa1(rt, ifa);
254 }
255 
256 void
257 rtable_init(void **table)
258 {
259 	struct domain *dom;
260 	DOMAIN_FOREACH(dom)
261 		if (dom->dom_rtattach)
262 			dom->dom_rtattach(&table[dom->dom_family],
263 			    dom->dom_rtoffset);
264 }
265 
266 static int
267 route_listener_cb(kauth_cred_t cred, kauth_action_t action, void *cookie,
268     void *arg0, void *arg1, void *arg2, void *arg3)
269 {
270 	struct rt_msghdr *rtm;
271 	int result;
272 
273 	result = KAUTH_RESULT_DEFER;
274 	rtm = arg1;
275 
276 	if (action != KAUTH_NETWORK_ROUTE)
277 		return result;
278 
279 	if (rtm->rtm_type == RTM_GET)
280 		result = KAUTH_RESULT_ALLOW;
281 
282 	return result;
283 }
284 
285 void
286 route_init(void)
287 {
288 
289 #ifdef RTFLUSH_DEBUG
290 	sysctl_net_rtcache_setup(NULL);
291 #endif
292 
293 	pool_init(&rtentry_pool, sizeof(struct rtentry), 0, 0, 0, "rtentpl",
294 	    NULL, IPL_SOFTNET);
295 	pool_init(&rttimer_pool, sizeof(struct rttimer), 0, 0, 0, "rttmrpl",
296 	    NULL, IPL_SOFTNET);
297 
298 	rt_init();
299 	rn_init();	/* initialize all zeroes, all ones, mask table */
300 	rtable_init((void **)rt_tables);
301 
302 	route_listener = kauth_listen_scope(KAUTH_SCOPE_NETWORK,
303 	    route_listener_cb, NULL);
304 }
305 
306 void
307 rtflushall(int family)
308 {
309 	struct domain *dom;
310 
311 	if (rtcache_debug())
312 		printf("%s: enter\n", __func__);
313 
314 	if ((dom = pffinddomain(family)) == NULL)
315 		return;
316 
317 	rtcache_invalidate(&dom->dom_rtcache);
318 }
319 
320 void
321 rtcache(struct route *ro)
322 {
323 	struct domain *dom;
324 
325 	rtcache_invariants(ro);
326 	KASSERT(ro->_ro_rt != NULL);
327 	KASSERT(ro->ro_invalid == false);
328 	KASSERT(rtcache_getdst(ro) != NULL);
329 
330 	if ((dom = pffinddomain(rtcache_getdst(ro)->sa_family)) == NULL)
331 		return;
332 
333 	LIST_INSERT_HEAD(&dom->dom_rtcache, ro, ro_rtcache_next);
334 	rtcache_invariants(ro);
335 }
336 
337 /*
338  * Packet routing routines.
339  */
340 struct rtentry *
341 rtalloc1(const struct sockaddr *dst, int report)
342 {
343 	struct radix_node_head *rnh = rt_tables[dst->sa_family];
344 	struct rtentry *rt;
345 	struct radix_node *rn;
346 	struct rtentry *newrt = NULL;
347 	struct rt_addrinfo info;
348 	int  s = splsoftnet(), err = 0, msgtype = RTM_MISS;
349 
350 	if (rnh && (rn = rnh->rnh_matchaddr(dst, rnh)) &&
351 	    ((rn->rn_flags & RNF_ROOT) == 0)) {
352 		newrt = rt = (struct rtentry *)rn;
353 		if (report && (rt->rt_flags & RTF_CLONING)) {
354 			err = rtrequest(RTM_RESOLVE, dst, NULL, NULL, 0,
355 			    &newrt);
356 			if (err) {
357 				newrt = rt;
358 				rt->rt_refcnt++;
359 				goto miss;
360 			}
361 			KASSERT(newrt != NULL);
362 			if ((rt = newrt) && (rt->rt_flags & RTF_XRESOLVE)) {
363 				msgtype = RTM_RESOLVE;
364 				goto miss;
365 			}
366 			/* Inform listeners of the new route */
367 			memset(&info, 0, sizeof(info));
368 			info.rti_info[RTAX_DST] = rt_getkey(rt);
369 			info.rti_info[RTAX_NETMASK] = rt_mask(rt);
370 			info.rti_info[RTAX_GATEWAY] = rt->rt_gateway;
371 			if (rt->rt_ifp != NULL) {
372 				info.rti_info[RTAX_IFP] =
373 				    rt->rt_ifp->if_dl->ifa_addr;
374 				info.rti_info[RTAX_IFA] = rt->rt_ifa->ifa_addr;
375 			}
376 			rt_missmsg(RTM_ADD, &info, rt->rt_flags, 0);
377 		} else
378 			rt->rt_refcnt++;
379 	} else {
380 		rtstat.rts_unreach++;
381 	miss:	if (report) {
382 			memset((void *)&info, 0, sizeof(info));
383 			info.rti_info[RTAX_DST] = dst;
384 			rt_missmsg(msgtype, &info, 0, err);
385 		}
386 	}
387 	splx(s);
388 	return newrt;
389 }
390 
391 void
392 rtfree(struct rtentry *rt)
393 {
394 	struct ifaddr *ifa;
395 
396 	if (rt == NULL)
397 		panic("rtfree");
398 	rt->rt_refcnt--;
399 	if (rt->rt_refcnt <= 0 && (rt->rt_flags & RTF_UP) == 0) {
400 		if (rt->rt_nodes->rn_flags & (RNF_ACTIVE | RNF_ROOT))
401 			panic ("rtfree 2");
402 		rttrash--;
403 		if (rt->rt_refcnt < 0) {
404 			printf("rtfree: %p not freed (neg refs)\n", rt);
405 			return;
406 		}
407 		rt_timer_remove_all(rt, 0);
408 		ifa = rt->rt_ifa;
409 		rt->rt_ifa = NULL;
410 		IFAFREE(ifa);
411 		rt->rt_ifp = NULL;
412 		rt_destroy(rt);
413 		pool_put(&rtentry_pool, rt);
414 	}
415 }
416 
417 void
418 ifafree(struct ifaddr *ifa)
419 {
420 
421 #ifdef DIAGNOSTIC
422 	if (ifa == NULL)
423 		panic("ifafree: null ifa");
424 	if (ifa->ifa_refcnt != 0)
425 		panic("ifafree: ifa_refcnt != 0 (%d)", ifa->ifa_refcnt);
426 #endif
427 #ifdef IFAREF_DEBUG
428 	printf("ifafree: freeing ifaddr %p\n", ifa);
429 #endif
430 	free(ifa, M_IFADDR);
431 }
432 
433 /*
434  * Force a routing table entry to the specified
435  * destination to go through the given gateway.
436  * Normally called as a result of a routing redirect
437  * message from the network layer.
438  *
439  * N.B.: must be called at splsoftnet
440  */
441 void
442 rtredirect(const struct sockaddr *dst, const struct sockaddr *gateway,
443 	const struct sockaddr *netmask, int flags, const struct sockaddr *src,
444 	struct rtentry **rtp)
445 {
446 	struct rtentry *rt;
447 	int error = 0;
448 	uint64_t *stat = NULL;
449 	struct rt_addrinfo info;
450 	struct ifaddr *ifa;
451 
452 	/* verify the gateway is directly reachable */
453 	if ((ifa = ifa_ifwithnet(gateway)) == NULL) {
454 		error = ENETUNREACH;
455 		goto out;
456 	}
457 	rt = rtalloc1(dst, 0);
458 	/*
459 	 * If the redirect isn't from our current router for this dst,
460 	 * it's either old or wrong.  If it redirects us to ourselves,
461 	 * we have a routing loop, perhaps as a result of an interface
462 	 * going down recently.
463 	 */
464 	if (!(flags & RTF_DONE) && rt &&
465 	     (sockaddr_cmp(src, rt->rt_gateway) != 0 || rt->rt_ifa != ifa))
466 		error = EINVAL;
467 	else if (ifa_ifwithaddr(gateway))
468 		error = EHOSTUNREACH;
469 	if (error)
470 		goto done;
471 	/*
472 	 * Create a new entry if we just got back a wildcard entry
473 	 * or the lookup failed.  This is necessary for hosts
474 	 * which use routing redirects generated by smart gateways
475 	 * to dynamically build the routing tables.
476 	 */
477 	if (rt == NULL || (rt_mask(rt) && rt_mask(rt)->sa_len < 2))
478 		goto create;
479 	/*
480 	 * Don't listen to the redirect if it's
481 	 * for a route to an interface.
482 	 */
483 	if (rt->rt_flags & RTF_GATEWAY) {
484 		if (((rt->rt_flags & RTF_HOST) == 0) && (flags & RTF_HOST)) {
485 			/*
486 			 * Changing from route to net => route to host.
487 			 * Create new route, rather than smashing route to net.
488 			 */
489 		create:
490 			if (rt != NULL)
491 				rtfree(rt);
492 			flags |=  RTF_GATEWAY | RTF_DYNAMIC;
493 			info.rti_info[RTAX_DST] = dst;
494 			info.rti_info[RTAX_GATEWAY] = gateway;
495 			info.rti_info[RTAX_NETMASK] = netmask;
496 			info.rti_ifa = ifa;
497 			info.rti_flags = flags;
498 			rt = NULL;
499 			error = rtrequest1(RTM_ADD, &info, &rt);
500 			if (rt != NULL)
501 				flags = rt->rt_flags;
502 			stat = &rtstat.rts_dynamic;
503 		} else {
504 			/*
505 			 * Smash the current notion of the gateway to
506 			 * this destination.  Should check about netmask!!!
507 			 */
508 			rt->rt_flags |= RTF_MODIFIED;
509 			flags |= RTF_MODIFIED;
510 			stat = &rtstat.rts_newgateway;
511 			rt_setgate(rt, gateway);
512 		}
513 	} else
514 		error = EHOSTUNREACH;
515 done:
516 	if (rt) {
517 		if (rtp != NULL && !error)
518 			*rtp = rt;
519 		else
520 			rtfree(rt);
521 	}
522 out:
523 	if (error)
524 		rtstat.rts_badredirect++;
525 	else if (stat != NULL)
526 		(*stat)++;
527 	memset(&info, 0, sizeof(info));
528 	info.rti_info[RTAX_DST] = dst;
529 	info.rti_info[RTAX_GATEWAY] = gateway;
530 	info.rti_info[RTAX_NETMASK] = netmask;
531 	info.rti_info[RTAX_AUTHOR] = src;
532 	rt_missmsg(RTM_REDIRECT, &info, flags, error);
533 }
534 
535 /*
536  * Delete a route and generate a message
537  */
538 static int
539 rtdeletemsg(struct rtentry *rt)
540 {
541 	int error;
542 	struct rt_addrinfo info;
543 
544 	/*
545 	 * Request the new route so that the entry is not actually
546 	 * deleted.  That will allow the information being reported to
547 	 * be accurate (and consistent with route_output()).
548 	 */
549 	memset(&info, 0, sizeof(info));
550 	info.rti_info[RTAX_DST] = rt_getkey(rt);
551 	info.rti_info[RTAX_NETMASK] = rt_mask(rt);
552 	info.rti_info[RTAX_GATEWAY] = rt->rt_gateway;
553 	info.rti_flags = rt->rt_flags;
554 	error = rtrequest1(RTM_DELETE, &info, &rt);
555 
556 	rt_missmsg(RTM_DELETE, &info, info.rti_flags, error);
557 
558 	/* Adjust the refcount */
559 	if (error == 0 && rt->rt_refcnt <= 0) {
560 		rt->rt_refcnt++;
561 		rtfree(rt);
562 	}
563 	return error;
564 }
565 
566 static int
567 rtflushclone1(struct rtentry *rt, void *arg)
568 {
569 	struct rtentry *parent;
570 
571 	parent = (struct rtentry *)arg;
572 	if ((rt->rt_flags & RTF_CLONED) != 0 && rt->rt_parent == parent)
573 		rtdeletemsg(rt);
574 	return 0;
575 }
576 
577 static void
578 rtflushclone(sa_family_t family, struct rtentry *parent)
579 {
580 
581 #ifdef DIAGNOSTIC
582 	if (!parent || (parent->rt_flags & RTF_CLONING) == 0)
583 		panic("rtflushclone: called with a non-cloning route");
584 #endif
585 	rt_walktree(family, rtflushclone1, (void *)parent);
586 }
587 
588 /*
589  * Routing table ioctl interface.
590  */
591 int
592 rtioctl(u_long req, void *data, struct lwp *l)
593 {
594 	return EOPNOTSUPP;
595 }
596 
597 struct ifaddr *
598 ifa_ifwithroute(int flags, const struct sockaddr *dst,
599 	const struct sockaddr *gateway)
600 {
601 	struct ifaddr *ifa;
602 	if ((flags & RTF_GATEWAY) == 0) {
603 		/*
604 		 * If we are adding a route to an interface,
605 		 * and the interface is a pt to pt link
606 		 * we should search for the destination
607 		 * as our clue to the interface.  Otherwise
608 		 * we can use the local address.
609 		 */
610 		ifa = NULL;
611 		if (flags & RTF_HOST)
612 			ifa = ifa_ifwithdstaddr(dst);
613 		if (ifa == NULL)
614 			ifa = ifa_ifwithaddr(gateway);
615 	} else {
616 		/*
617 		 * If we are adding a route to a remote net
618 		 * or host, the gateway may still be on the
619 		 * other end of a pt to pt link.
620 		 */
621 		ifa = ifa_ifwithdstaddr(gateway);
622 	}
623 	if (ifa == NULL)
624 		ifa = ifa_ifwithnet(gateway);
625 	if (ifa == NULL) {
626 		struct rtentry *rt = rtalloc1(dst, 0);
627 		if (rt == NULL)
628 			return NULL;
629 		rt->rt_refcnt--;
630 		if ((ifa = rt->rt_ifa) == NULL)
631 			return NULL;
632 	}
633 	if (ifa->ifa_addr->sa_family != dst->sa_family) {
634 		struct ifaddr *oifa = ifa;
635 		ifa = ifaof_ifpforaddr(dst, ifa->ifa_ifp);
636 		if (ifa == 0)
637 			ifa = oifa;
638 	}
639 	return ifa;
640 }
641 
642 int
643 rtrequest(int req, const struct sockaddr *dst, const struct sockaddr *gateway,
644 	const struct sockaddr *netmask, int flags, struct rtentry **ret_nrt)
645 {
646 	struct rt_addrinfo info;
647 
648 	memset(&info, 0, sizeof(info));
649 	info.rti_flags = flags;
650 	info.rti_info[RTAX_DST] = dst;
651 	info.rti_info[RTAX_GATEWAY] = gateway;
652 	info.rti_info[RTAX_NETMASK] = netmask;
653 	return rtrequest1(req, &info, ret_nrt);
654 }
655 
656 int
657 rt_getifa(struct rt_addrinfo *info)
658 {
659 	struct ifaddr *ifa;
660 	const struct sockaddr *dst = info->rti_info[RTAX_DST];
661 	const struct sockaddr *gateway = info->rti_info[RTAX_GATEWAY];
662 	const struct sockaddr *ifaaddr = info->rti_info[RTAX_IFA];
663 	const struct sockaddr *ifpaddr = info->rti_info[RTAX_IFP];
664 	int flags = info->rti_flags;
665 
666 	/*
667 	 * ifp may be specified by sockaddr_dl when protocol address
668 	 * is ambiguous
669 	 */
670 	if (info->rti_ifp == NULL && ifpaddr != NULL
671 	    && ifpaddr->sa_family == AF_LINK &&
672 	    (ifa = ifa_ifwithnet(ifpaddr)) != NULL)
673 		info->rti_ifp = ifa->ifa_ifp;
674 	if (info->rti_ifa == NULL && ifaaddr != NULL)
675 		info->rti_ifa = ifa_ifwithaddr(ifaaddr);
676 	if (info->rti_ifa == NULL) {
677 		const struct sockaddr *sa;
678 
679 		sa = ifaaddr != NULL ? ifaaddr :
680 		    (gateway != NULL ? gateway : dst);
681 		if (sa != NULL && info->rti_ifp != NULL)
682 			info->rti_ifa = ifaof_ifpforaddr(sa, info->rti_ifp);
683 		else if (dst != NULL && gateway != NULL)
684 			info->rti_ifa = ifa_ifwithroute(flags, dst, gateway);
685 		else if (sa != NULL)
686 			info->rti_ifa = ifa_ifwithroute(flags, sa, sa);
687 	}
688 	if ((ifa = info->rti_ifa) == NULL)
689 		return ENETUNREACH;
690 	if (ifa->ifa_getifa != NULL)
691 		info->rti_ifa = ifa = (*ifa->ifa_getifa)(ifa, dst);
692 	if (info->rti_ifp == NULL)
693 		info->rti_ifp = ifa->ifa_ifp;
694 	return 0;
695 }
696 
697 int
698 rtrequest1(int req, struct rt_addrinfo *info, struct rtentry **ret_nrt)
699 {
700 	int s = splsoftnet();
701 	int error = 0;
702 	struct rtentry *rt, *crt;
703 	struct radix_node *rn;
704 	struct radix_node_head *rnh;
705 	struct ifaddr *ifa;
706 	struct sockaddr_storage maskeddst;
707 	const struct sockaddr *dst = info->rti_info[RTAX_DST];
708 	const struct sockaddr *gateway = info->rti_info[RTAX_GATEWAY];
709 	const struct sockaddr *netmask = info->rti_info[RTAX_NETMASK];
710 	int flags = info->rti_flags;
711 #define senderr(x) { error = x ; goto bad; }
712 
713 	if ((rnh = rt_tables[dst->sa_family]) == NULL)
714 		senderr(ESRCH);
715 	if (flags & RTF_HOST)
716 		netmask = NULL;
717 	switch (req) {
718 	case RTM_DELETE:
719 		if (netmask) {
720 			rt_maskedcopy(dst, (struct sockaddr *)&maskeddst,
721 			    netmask);
722 			dst = (struct sockaddr *)&maskeddst;
723 		}
724 		if ((rn = rnh->rnh_lookup(dst, netmask, rnh)) == NULL)
725 			senderr(ESRCH);
726 		rt = (struct rtentry *)rn;
727 		if ((rt->rt_flags & RTF_CLONING) != 0) {
728 			/* clean up any cloned children */
729 			rtflushclone(dst->sa_family, rt);
730 		}
731 		if ((rn = rnh->rnh_deladdr(dst, netmask, rnh)) == NULL)
732 			senderr(ESRCH);
733 		if (rn->rn_flags & (RNF_ACTIVE | RNF_ROOT))
734 			panic ("rtrequest delete");
735 		rt = (struct rtentry *)rn;
736 		if (rt->rt_gwroute) {
737 			RTFREE(rt->rt_gwroute);
738 			rt->rt_gwroute = NULL;
739 		}
740 		if (rt->rt_parent) {
741 			rt->rt_parent->rt_refcnt--;
742 			rt->rt_parent = NULL;
743 		}
744 		rt->rt_flags &= ~RTF_UP;
745 		if ((ifa = rt->rt_ifa)) {
746 			if (ifa->ifa_flags & IFA_ROUTE &&
747 			    rt_ifa_connected(rt, ifa)) {
748 				RT_DPRINTF("rt->_rt_key = %p, ifa = %p, "
749 				    "deleted IFA_ROUTE\n",
750 				    (void *)rt->_rt_key, (void *)ifa);
751 				ifa->ifa_flags &= ~IFA_ROUTE;
752 			}
753 			if (ifa->ifa_rtrequest)
754 				ifa->ifa_rtrequest(RTM_DELETE, rt, info);
755 		}
756 		rttrash++;
757 		if (ret_nrt)
758 			*ret_nrt = rt;
759 		else if (rt->rt_refcnt <= 0) {
760 			rt->rt_refcnt++;
761 			rtfree(rt);
762 		}
763 		break;
764 
765 	case RTM_RESOLVE:
766 		if (ret_nrt == NULL || (rt = *ret_nrt) == NULL)
767 			senderr(EINVAL);
768 		if ((rt->rt_flags & RTF_CLONING) == 0)
769 			senderr(EINVAL);
770 		ifa = rt->rt_ifa;
771 		flags = rt->rt_flags & ~(RTF_CLONING | RTF_STATIC);
772 		flags |= RTF_CLONED;
773 		gateway = rt->rt_gateway;
774 		flags |= RTF_HOST;
775 		goto makeroute;
776 
777 	case RTM_ADD:
778 		if (info->rti_ifa == NULL && (error = rt_getifa(info)))
779 			senderr(error);
780 		ifa = info->rti_ifa;
781 	makeroute:
782 		/* Already at splsoftnet() so pool_get/pool_put are safe */
783 		rt = pool_get(&rtentry_pool, PR_NOWAIT);
784 		if (rt == NULL)
785 			senderr(ENOBUFS);
786 		memset(rt, 0, sizeof(*rt));
787 		rt->rt_flags = RTF_UP | flags;
788 		LIST_INIT(&rt->rt_timer);
789 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
790 		if (rt_setkey(rt, dst, M_NOWAIT) == NULL ||
791 		    rt_setgate(rt, gateway) != 0) {
792 			pool_put(&rtentry_pool, rt);
793 			senderr(ENOBUFS);
794 		}
795 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
796 		if (netmask) {
797 			rt_maskedcopy(dst, (struct sockaddr *)&maskeddst,
798 			    netmask);
799 			rt_setkey(rt, (struct sockaddr *)&maskeddst, M_NOWAIT);
800 			RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
801 		} else {
802 			rt_setkey(rt, dst, M_NOWAIT);
803 			RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
804 		}
805 		rt_set_ifa(rt, ifa);
806 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
807 		rt->rt_ifp = ifa->ifa_ifp;
808 		if (req == RTM_RESOLVE) {
809 			rt->rt_rmx = (*ret_nrt)->rt_rmx; /* copy metrics */
810 			rt->rt_parent = *ret_nrt;
811 			rt->rt_parent->rt_refcnt++;
812 		}
813 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
814 		rn = rnh->rnh_addaddr(rt_getkey(rt), netmask, rnh,
815 		    rt->rt_nodes);
816 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
817 		if (rn == NULL && (crt = rtalloc1(rt_getkey(rt), 0)) != NULL) {
818 			/* overwrite cloned route */
819 			if ((crt->rt_flags & RTF_CLONED) != 0) {
820 				rtdeletemsg(crt);
821 				rn = rnh->rnh_addaddr(rt_getkey(rt),
822 				    netmask, rnh, rt->rt_nodes);
823 			}
824 			RTFREE(crt);
825 			RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
826 		}
827 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
828 		if (rn == NULL) {
829 			IFAFREE(ifa);
830 			if ((rt->rt_flags & RTF_CLONED) != 0 && rt->rt_parent)
831 				rtfree(rt->rt_parent);
832 			if (rt->rt_gwroute)
833 				rtfree(rt->rt_gwroute);
834 			rt_destroy(rt);
835 			pool_put(&rtentry_pool, rt);
836 			senderr(EEXIST);
837 		}
838 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
839 		if (ifa->ifa_rtrequest)
840 			ifa->ifa_rtrequest(req, rt, info);
841 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
842 		if (ret_nrt) {
843 			*ret_nrt = rt;
844 			rt->rt_refcnt++;
845 		}
846 		if ((rt->rt_flags & RTF_CLONING) != 0) {
847 			/* clean up any cloned children */
848 			rtflushclone(dst->sa_family, rt);
849 		}
850 		rtflushall(dst->sa_family);
851 		break;
852 	case RTM_GET:
853 		if (netmask != NULL) {
854 			rt_maskedcopy(dst, (struct sockaddr *)&maskeddst,
855 			    netmask);
856 			dst = (struct sockaddr *)&maskeddst;
857 		}
858 		rn = rnh->rnh_lookup(dst, netmask, rnh);
859 		if (rn == NULL || (rn->rn_flags & RNF_ROOT) != 0)
860 			senderr(ESRCH);
861 		if (ret_nrt != NULL) {
862 			rt = (struct rtentry *)rn;
863 			*ret_nrt = rt;
864 			rt->rt_refcnt++;
865 		}
866 		break;
867 	}
868 bad:
869 	splx(s);
870 	return error;
871 }
872 
873 int
874 rt_setgate(struct rtentry *rt, const struct sockaddr *gate)
875 {
876 	KASSERT(rt != rt->rt_gwroute);
877 
878 	KASSERT(rt->_rt_key != NULL);
879 	RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
880 
881 	if (rt->rt_gwroute) {
882 		RTFREE(rt->rt_gwroute);
883 		rt->rt_gwroute = NULL;
884 	}
885 	KASSERT(rt->_rt_key != NULL);
886 	RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
887 	if (rt->rt_gateway != NULL)
888 		sockaddr_free(rt->rt_gateway);
889 	KASSERT(rt->_rt_key != NULL);
890 	RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
891 	if ((rt->rt_gateway = sockaddr_dup(gate, M_NOWAIT)) == NULL)
892 		return ENOMEM;
893 	KASSERT(rt->_rt_key != NULL);
894 	RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
895 
896 	if (rt->rt_flags & RTF_GATEWAY) {
897 		KASSERT(rt->_rt_key != NULL);
898 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
899 		rt->rt_gwroute = rtalloc1(gate, 1);
900 		/*
901 		 * If we switched gateways, grab the MTU from the new
902 		 * gateway route if the current MTU, if the current MTU is
903 		 * greater than the MTU of gateway.
904 		 * Note that, if the MTU of gateway is 0, we will reset the
905 		 * MTU of the route to run PMTUD again from scratch. XXX
906 		 */
907 		KASSERT(rt->_rt_key != NULL);
908 		RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
909 		if (rt->rt_gwroute
910 		    && !(rt->rt_rmx.rmx_locks & RTV_MTU)
911 		    && rt->rt_rmx.rmx_mtu
912 		    && rt->rt_rmx.rmx_mtu > rt->rt_gwroute->rt_rmx.rmx_mtu) {
913 			rt->rt_rmx.rmx_mtu = rt->rt_gwroute->rt_rmx.rmx_mtu;
914 		}
915 	}
916 	KASSERT(rt->_rt_key != NULL);
917 	RT_DPRINTF("rt->_rt_key = %p\n", (void *)rt->_rt_key);
918 	return 0;
919 }
920 
921 void
922 rt_maskedcopy(const struct sockaddr *src, struct sockaddr *dst,
923 	const struct sockaddr *netmask)
924 {
925 	const char *netmaskp = &netmask->sa_data[0],
926 	           *srcp = &src->sa_data[0];
927 	char *dstp = &dst->sa_data[0];
928 	const char *maskend = dstp + MIN(netmask->sa_len, src->sa_len);
929 	const char *srcend = dstp + src->sa_len;
930 
931 	dst->sa_len = src->sa_len;
932 	dst->sa_family = src->sa_family;
933 
934 	while (dstp < maskend)
935 		*dstp++ = *srcp++ & *netmaskp++;
936 	if (dstp < srcend)
937 		memset(dstp, 0, (size_t)(srcend - dstp));
938 }
939 
940 /*
941  * Set up or tear down a routing table entry, normally
942  * for an interface.
943  */
944 int
945 rtinit(struct ifaddr *ifa, int cmd, int flags)
946 {
947 	struct rtentry *rt;
948 	struct sockaddr *dst, *odst;
949 	struct sockaddr_storage maskeddst;
950 	struct rtentry *nrt = NULL;
951 	int error;
952 	struct rt_addrinfo info;
953 	struct sockaddr_dl *sdl;
954 	const struct sockaddr_dl *ifsdl;
955 
956 	dst = flags & RTF_HOST ? ifa->ifa_dstaddr : ifa->ifa_addr;
957 	if (cmd == RTM_DELETE) {
958 		if ((flags & RTF_HOST) == 0 && ifa->ifa_netmask) {
959 			/* Delete subnet route for this interface */
960 			odst = dst;
961 			dst = (struct sockaddr *)&maskeddst;
962 			rt_maskedcopy(odst, dst, ifa->ifa_netmask);
963 		}
964 		if ((rt = rtalloc1(dst, 0)) != NULL) {
965 			rt->rt_refcnt--;
966 			if (rt->rt_ifa != ifa)
967 				return (flags & RTF_HOST) ? EHOSTUNREACH
968 							: ENETUNREACH;
969 		}
970 	}
971 	memset(&info, 0, sizeof(info));
972 	info.rti_ifa = ifa;
973 	info.rti_flags = flags | ifa->ifa_flags;
974 	info.rti_info[RTAX_DST] = dst;
975 	info.rti_info[RTAX_GATEWAY] = ifa->ifa_addr;
976 	/*
977 	 * XXX here, it seems that we are assuming that ifa_netmask is NULL
978 	 * for RTF_HOST.  bsdi4 passes NULL explicitly (via intermediate
979 	 * variable) when RTF_HOST is 1.  still not sure if i can safely
980 	 * change it to meet bsdi4 behavior.
981 	 */
982 	if (cmd != RTM_LLINFO_UPD)
983 		info.rti_info[RTAX_NETMASK] = ifa->ifa_netmask;
984 	error = rtrequest1((cmd == RTM_LLINFO_UPD) ? RTM_GET : cmd, &info,
985 	    &nrt);
986 	if (error != 0 || (rt = nrt) == NULL)
987 		;
988 	else switch (cmd) {
989 	case RTM_DELETE:
990 		rt_newaddrmsg(cmd, ifa, error, nrt);
991 		if (rt->rt_refcnt <= 0) {
992 			rt->rt_refcnt++;
993 			rtfree(rt);
994 		}
995 		break;
996 	case RTM_LLINFO_UPD:
997 		rt->rt_refcnt--;
998 		RT_DPRINTF("%s: updating%s\n", __func__,
999 		    ((rt->rt_flags & RTF_LLINFO) == 0) ? " (no llinfo)" : "");
1000 
1001 		ifsdl = ifa->ifa_ifp->if_sadl;
1002 
1003 		if ((rt->rt_flags & RTF_LLINFO) != 0 &&
1004 		    (sdl = satosdl(rt->rt_gateway)) != NULL &&
1005 		    sdl->sdl_family == AF_LINK &&
1006 		    sockaddr_dl_setaddr(sdl, sdl->sdl_len, CLLADDR(ifsdl),
1007 		                        ifa->ifa_ifp->if_addrlen) == NULL) {
1008 			error = EINVAL;
1009 			break;
1010 		}
1011 
1012 		if (cmd == RTM_LLINFO_UPD && ifa->ifa_rtrequest != NULL)
1013 			ifa->ifa_rtrequest(RTM_LLINFO_UPD, rt, &info);
1014 		rt_newaddrmsg(RTM_CHANGE, ifa, error, nrt);
1015 		break;
1016 	case RTM_ADD:
1017 		rt->rt_refcnt--;
1018 		if (rt->rt_ifa != ifa) {
1019 			printf("rtinit: wrong ifa (%p) was (%p)\n", ifa,
1020 				rt->rt_ifa);
1021 			if (rt->rt_ifa->ifa_rtrequest != NULL) {
1022 				rt->rt_ifa->ifa_rtrequest(RTM_DELETE, rt,
1023 				    &info);
1024 			}
1025 			rt_replace_ifa(rt, ifa);
1026 			rt->rt_ifp = ifa->ifa_ifp;
1027 			if (ifa->ifa_rtrequest != NULL)
1028 				ifa->ifa_rtrequest(RTM_ADD, rt, &info);
1029 		}
1030 		rt_newaddrmsg(cmd, ifa, error, nrt);
1031 		break;
1032 	}
1033 	return error;
1034 }
1035 
1036 /*
1037  * Route timer routines.  These routes allow functions to be called
1038  * for various routes at any time.  This is useful in supporting
1039  * path MTU discovery and redirect route deletion.
1040  *
1041  * This is similar to some BSDI internal functions, but it provides
1042  * for multiple queues for efficiency's sake...
1043  */
1044 
1045 LIST_HEAD(, rttimer_queue) rttimer_queue_head;
1046 static int rt_init_done = 0;
1047 
1048 #define RTTIMER_CALLOUT(r)	do {					\
1049 		if (r->rtt_func != NULL) {				\
1050 			(*r->rtt_func)(r->rtt_rt, r);			\
1051 		} else {						\
1052 			rtrequest((int) RTM_DELETE,			\
1053 				  rt_getkey(r->rtt_rt),			\
1054 				  0, 0, 0, 0);				\
1055 		}							\
1056 	} while (/*CONSTCOND*/0)
1057 
1058 /*
1059  * Some subtle order problems with domain initialization mean that
1060  * we cannot count on this being run from rt_init before various
1061  * protocol initializations are done.  Therefore, we make sure
1062  * that this is run when the first queue is added...
1063  */
1064 
1065 void
1066 rt_timer_init(void)
1067 {
1068 	assert(rt_init_done == 0);
1069 
1070 	LIST_INIT(&rttimer_queue_head);
1071 	callout_init(&rt_timer_ch, 0);
1072 	callout_reset(&rt_timer_ch, hz, rt_timer_timer, NULL);
1073 	rt_init_done = 1;
1074 }
1075 
1076 struct rttimer_queue *
1077 rt_timer_queue_create(u_int timeout)
1078 {
1079 	struct rttimer_queue *rtq;
1080 
1081 	if (rt_init_done == 0)
1082 		rt_timer_init();
1083 
1084 	R_Malloc(rtq, struct rttimer_queue *, sizeof *rtq);
1085 	if (rtq == NULL)
1086 		return NULL;
1087 	memset(rtq, 0, sizeof(*rtq));
1088 
1089 	rtq->rtq_timeout = timeout;
1090 	TAILQ_INIT(&rtq->rtq_head);
1091 	LIST_INSERT_HEAD(&rttimer_queue_head, rtq, rtq_link);
1092 
1093 	return rtq;
1094 }
1095 
1096 void
1097 rt_timer_queue_change(struct rttimer_queue *rtq, long timeout)
1098 {
1099 
1100 	rtq->rtq_timeout = timeout;
1101 }
1102 
1103 void
1104 rt_timer_queue_remove_all(struct rttimer_queue *rtq, int destroy)
1105 {
1106 	struct rttimer *r;
1107 
1108 	while ((r = TAILQ_FIRST(&rtq->rtq_head)) != NULL) {
1109 		LIST_REMOVE(r, rtt_link);
1110 		TAILQ_REMOVE(&rtq->rtq_head, r, rtt_next);
1111 		if (destroy)
1112 			RTTIMER_CALLOUT(r);
1113 		/* we are already at splsoftnet */
1114 		pool_put(&rttimer_pool, r);
1115 		if (rtq->rtq_count > 0)
1116 			rtq->rtq_count--;
1117 		else
1118 			printf("rt_timer_queue_remove_all: "
1119 			    "rtq_count reached 0\n");
1120 	}
1121 }
1122 
1123 void
1124 rt_timer_queue_destroy(struct rttimer_queue *rtq, int destroy)
1125 {
1126 
1127 	rt_timer_queue_remove_all(rtq, destroy);
1128 
1129 	LIST_REMOVE(rtq, rtq_link);
1130 
1131 	/*
1132 	 * Caller is responsible for freeing the rttimer_queue structure.
1133 	 */
1134 }
1135 
1136 unsigned long
1137 rt_timer_count(struct rttimer_queue *rtq)
1138 {
1139 	return rtq->rtq_count;
1140 }
1141 
1142 void
1143 rt_timer_remove_all(struct rtentry *rt, int destroy)
1144 {
1145 	struct rttimer *r;
1146 
1147 	while ((r = LIST_FIRST(&rt->rt_timer)) != NULL) {
1148 		LIST_REMOVE(r, rtt_link);
1149 		TAILQ_REMOVE(&r->rtt_queue->rtq_head, r, rtt_next);
1150 		if (destroy)
1151 			RTTIMER_CALLOUT(r);
1152 		if (r->rtt_queue->rtq_count > 0)
1153 			r->rtt_queue->rtq_count--;
1154 		else
1155 			printf("rt_timer_remove_all: rtq_count reached 0\n");
1156 		/* we are already at splsoftnet */
1157 		pool_put(&rttimer_pool, r);
1158 	}
1159 }
1160 
1161 int
1162 rt_timer_add(struct rtentry *rt,
1163 	void (*func)(struct rtentry *, struct rttimer *),
1164 	struct rttimer_queue *queue)
1165 {
1166 	struct rttimer *r;
1167 	int s;
1168 
1169 	/*
1170 	 * If there's already a timer with this action, destroy it before
1171 	 * we add a new one.
1172 	 */
1173 	LIST_FOREACH(r, &rt->rt_timer, rtt_link) {
1174 		if (r->rtt_func == func)
1175 			break;
1176 	}
1177 	if (r != NULL) {
1178 		LIST_REMOVE(r, rtt_link);
1179 		TAILQ_REMOVE(&r->rtt_queue->rtq_head, r, rtt_next);
1180 		if (r->rtt_queue->rtq_count > 0)
1181 			r->rtt_queue->rtq_count--;
1182 		else
1183 			printf("rt_timer_add: rtq_count reached 0\n");
1184 	} else {
1185 		s = splsoftnet();
1186 		r = pool_get(&rttimer_pool, PR_NOWAIT);
1187 		splx(s);
1188 		if (r == NULL)
1189 			return ENOBUFS;
1190 	}
1191 
1192 	memset(r, 0, sizeof(*r));
1193 
1194 	r->rtt_rt = rt;
1195 	r->rtt_time = time_uptime;
1196 	r->rtt_func = func;
1197 	r->rtt_queue = queue;
1198 	LIST_INSERT_HEAD(&rt->rt_timer, r, rtt_link);
1199 	TAILQ_INSERT_TAIL(&queue->rtq_head, r, rtt_next);
1200 	r->rtt_queue->rtq_count++;
1201 
1202 	return 0;
1203 }
1204 
1205 /* ARGSUSED */
1206 void
1207 rt_timer_timer(void *arg)
1208 {
1209 	struct rttimer_queue *rtq;
1210 	struct rttimer *r;
1211 	int s;
1212 
1213 	s = splsoftnet();
1214 	LIST_FOREACH(rtq, &rttimer_queue_head, rtq_link) {
1215 		while ((r = TAILQ_FIRST(&rtq->rtq_head)) != NULL &&
1216 		    (r->rtt_time + rtq->rtq_timeout) < time_uptime) {
1217 			LIST_REMOVE(r, rtt_link);
1218 			TAILQ_REMOVE(&rtq->rtq_head, r, rtt_next);
1219 			RTTIMER_CALLOUT(r);
1220 			pool_put(&rttimer_pool, r);
1221 			if (rtq->rtq_count > 0)
1222 				rtq->rtq_count--;
1223 			else
1224 				printf("rt_timer_timer: rtq_count reached 0\n");
1225 		}
1226 	}
1227 	splx(s);
1228 
1229 	callout_reset(&rt_timer_ch, hz, rt_timer_timer, NULL);
1230 }
1231 
1232 static struct rtentry *
1233 _rtcache_init(struct route *ro, int flag)
1234 {
1235 	rtcache_invariants(ro);
1236 	KASSERT(ro->_ro_rt == NULL);
1237 
1238 	if (rtcache_getdst(ro) == NULL)
1239 		return NULL;
1240 	ro->ro_invalid = false;
1241 	if ((ro->_ro_rt = rtalloc1(rtcache_getdst(ro), flag)) != NULL)
1242 		rtcache(ro);
1243 
1244 	rtcache_invariants(ro);
1245 	return ro->_ro_rt;
1246 }
1247 
1248 struct rtentry *
1249 rtcache_init(struct route *ro)
1250 {
1251 	return _rtcache_init(ro, 1);
1252 }
1253 
1254 struct rtentry *
1255 rtcache_init_noclone(struct route *ro)
1256 {
1257 	return _rtcache_init(ro, 0);
1258 }
1259 
1260 struct rtentry *
1261 rtcache_update(struct route *ro, int clone)
1262 {
1263 	rtcache_clear(ro);
1264 	return _rtcache_init(ro, clone);
1265 }
1266 
1267 void
1268 rtcache_copy(struct route *new_ro, const struct route *old_ro)
1269 {
1270 	struct rtentry *rt;
1271 
1272 	KASSERT(new_ro != old_ro);
1273 	rtcache_invariants(new_ro);
1274 	rtcache_invariants(old_ro);
1275 
1276 	if ((rt = rtcache_validate(old_ro)) != NULL)
1277 		rt->rt_refcnt++;
1278 
1279 	if (rtcache_getdst(old_ro) == NULL ||
1280 	    rtcache_setdst(new_ro, rtcache_getdst(old_ro)) != 0)
1281 		return;
1282 
1283 	new_ro->ro_invalid = false;
1284 	if ((new_ro->_ro_rt = rt) != NULL)
1285 		rtcache(new_ro);
1286 	rtcache_invariants(new_ro);
1287 }
1288 
1289 static struct dom_rtlist invalid_routes = LIST_HEAD_INITIALIZER(dom_rtlist);
1290 
1291 void
1292 rtcache_invalidate(struct dom_rtlist *rtlist)
1293 {
1294 	struct route *ro;
1295 
1296 	while ((ro = LIST_FIRST(rtlist)) != NULL) {
1297 		rtcache_invariants(ro);
1298 		KASSERT(ro->_ro_rt != NULL);
1299 		ro->ro_invalid = true;
1300 		LIST_REMOVE(ro, ro_rtcache_next);
1301 		LIST_INSERT_HEAD(&invalid_routes, ro, ro_rtcache_next);
1302 		rtcache_invariants(ro);
1303 	}
1304 }
1305 
1306 void
1307 rtcache_clear(struct route *ro)
1308 {
1309 	rtcache_invariants(ro);
1310 	if (ro->_ro_rt == NULL)
1311 		return;
1312 
1313 	LIST_REMOVE(ro, ro_rtcache_next);
1314 
1315 	RTFREE(ro->_ro_rt);
1316 	ro->_ro_rt = NULL;
1317 	ro->ro_invalid = false;
1318 	rtcache_invariants(ro);
1319 }
1320 
1321 struct rtentry *
1322 rtcache_lookup2(struct route *ro, const struct sockaddr *dst, int clone,
1323     int *hitp)
1324 {
1325 	const struct sockaddr *odst;
1326 	struct rtentry *rt = NULL;
1327 
1328 	rtcache_invariants(ro);
1329 
1330 	odst = rtcache_getdst(ro);
1331 
1332 	if (odst == NULL)
1333 		;
1334 	else if (sockaddr_cmp(odst, dst) != 0)
1335 		rtcache_free(ro);
1336 	else if ((rt = rtcache_validate(ro)) == NULL)
1337 		rtcache_clear(ro);
1338 
1339 	if (rt == NULL) {
1340 		*hitp = 0;
1341 		if (rtcache_setdst(ro, dst) == 0)
1342 			rt = _rtcache_init(ro, clone);
1343 	} else
1344 		*hitp = 1;
1345 
1346 	rtcache_invariants(ro);
1347 
1348 	return rt;
1349 }
1350 
1351 void
1352 rtcache_free(struct route *ro)
1353 {
1354 	rtcache_clear(ro);
1355 	if (ro->ro_sa != NULL) {
1356 		sockaddr_free(ro->ro_sa);
1357 		ro->ro_sa = NULL;
1358 	}
1359 	rtcache_invariants(ro);
1360 }
1361 
1362 int
1363 rtcache_setdst(struct route *ro, const struct sockaddr *sa)
1364 {
1365 	KASSERT(sa != NULL);
1366 
1367 	rtcache_invariants(ro);
1368 	if (ro->ro_sa != NULL && ro->ro_sa->sa_family == sa->sa_family) {
1369 		rtcache_clear(ro);
1370 		if (sockaddr_copy(ro->ro_sa, ro->ro_sa->sa_len, sa) != NULL) {
1371 			rtcache_invariants(ro);
1372 			return 0;
1373 		}
1374 		sockaddr_free(ro->ro_sa);
1375 	} else if (ro->ro_sa != NULL)
1376 		rtcache_free(ro);	/* free ro_sa, wrong family */
1377 
1378 	KASSERT(ro->_ro_rt == NULL);
1379 
1380 	if ((ro->ro_sa = sockaddr_dup(sa, M_NOWAIT)) == NULL) {
1381 		rtcache_invariants(ro);
1382 		return ENOMEM;
1383 	}
1384 	rtcache_invariants(ro);
1385 	return 0;
1386 }
1387 
1388 static int
1389 rt_walktree_visitor(struct radix_node *rn, void *v)
1390 {
1391 	struct rtwalk *rw = (struct rtwalk *)v;
1392 
1393 	return (*rw->rw_f)((struct rtentry *)rn, rw->rw_v);
1394 }
1395 
1396 int
1397 rt_walktree(sa_family_t family, int (*f)(struct rtentry *, void *), void *v)
1398 {
1399 	struct radix_node_head *rnh = rt_tables[family];
1400 	struct rtwalk rw;
1401 
1402 	if (rnh == NULL)
1403 		return 0;
1404 
1405 	rw.rw_f = f;
1406 	rw.rw_v = v;
1407 
1408 	return rn_walktree(rnh, rt_walktree_visitor, &rw);
1409 }
1410