xref: /xnu-12377.81.4/bsd/netinet6/ip6_var.h (revision 043036a2b3718f7f0be807e2870f8f47d3fa0796)
1 /*
2  * Copyright (c) 2000-2024 Apple Inc. All rights reserved.
3  *
4  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5  *
6  * This file contains Original Code and/or Modifications of Original Code
7  * as defined in and that are subject to the Apple Public Source License
8  * Version 2.0 (the 'License'). You may not use this file except in
9  * compliance with the License. The rights granted to you under the License
10  * may not be used to create, or enable the creation or redistribution of,
11  * unlawful or unlicensed copies of an Apple operating system, or to
12  * circumvent, violate, or enable the circumvention or violation of, any
13  * terms of an Apple operating system software license agreement.
14  *
15  * Please obtain a copy of the License at
16  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17  *
18  * The Original Code and all software distributed under the License are
19  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23  * Please see the License for the specific language governing rights and
24  * limitations under the License.
25  *
26  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27  */
28 
29 /*
30  * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
31  * All rights reserved.
32  *
33  * Redistribution and use in source and binary forms, with or without
34  * modification, are permitted provided that the following conditions
35  * are met:
36  * 1. Redistributions of source code must retain the above copyright
37  *    notice, this list of conditions and the following disclaimer.
38  * 2. Redistributions in binary form must reproduce the above copyright
39  *    notice, this list of conditions and the following disclaimer in the
40  *    documentation and/or other materials provided with the distribution.
41  * 3. Neither the name of the project nor the names of its contributors
42  *    may be used to endorse or promote products derived from this software
43  *    without specific prior written permission.
44  *
45  * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
46  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
47  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
48  * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
49  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
50  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
51  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
52  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
53  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
54  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
55  * SUCH DAMAGE.
56  */
57 
58 /*
59  * Copyright (c) 1982, 1986, 1993
60  *	The Regents of the University of California.  All rights reserved.
61  *
62  * Redistribution and use in source and binary forms, with or without
63  * modification, are permitted provided that the following conditions
64  * are met:
65  * 1. Redistributions of source code must retain the above copyright
66  *    notice, this list of conditions and the following disclaimer.
67  * 2. Redistributions in binary form must reproduce the above copyright
68  *    notice, this list of conditions and the following disclaimer in the
69  *    documentation and/or other materials provided with the distribution.
70  * 3. All advertising materials mentioning features or use of this software
71  *    must display the following acknowledgement:
72  *	This product includes software developed by the University of
73  *	California, Berkeley and its contributors.
74  * 4. Neither the name of the University nor the names of its contributors
75  *    may be used to endorse or promote products derived from this software
76  *    without specific prior written permission.
77  *
78  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
79  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
80  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
81  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
82  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
83  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
84  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
85  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
86  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
87  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
88  * SUCH DAMAGE.
89  *
90  *	@(#)ip_var.h	8.1 (Berkeley) 6/10/93
91  */
92 
93 #ifndef _NETINET6_IP6_VAR_H_
94 #define _NETINET6_IP6_VAR_H_
95 #include <sys/appleapiopts.h>
96 
97 #ifdef BSD_KERNEL_PRIVATE
98 #include <kern/zalloc.h>
99 
100 #include <net/ethernet.h>
101 #include <net/if.h>
102 
103 #include <netinet6/in6_var.h>
104 
105 #include <net/if_private.h>
106 
107 #include <netinet6/in6_var.h>
108 
109 struct ip6asfrag;
110 /*
111  * IP6 reassembly queue structure.  Each fragment
112  * being reassembled is attached to one of these structures.
113  */
114 struct  ip6q {
115 	struct ip6asfrag *ip6q_down;
116 	struct ip6asfrag *ip6q_up;
117 	u_int32_t       ip6q_ident;
118 	u_int8_t        ip6q_nxt;
119 	u_int8_t        ip6q_ecn;
120 	u_int8_t        ip6q_ttl;
121 	struct in6_addr ip6q_src, ip6q_dst;
122 	struct ip6q     *ip6q_next;
123 	struct ip6q     *ip6q_prev;
124 	int             ip6q_unfrglen;  /* len of unfragmentable part */
125 	int             ip6q_nfrag;     /* # of fragments */
126 	uint32_t        ip6q_csum_flags; /* checksum flags */
127 	uint32_t        ip6q_csum;      /* partial checksum value */
128 	uint32_t        ip6q_flags;
129 	uint32_t        ip6q_dst_ifscope, ip6q_src_ifscope;
130 #define IP6QF_DIRTY    0x00000001
131 };
132 
133 struct  ip6_moptions {
134 	decl_lck_mtx_data(, im6o_lock);
135 	uint32_t im6o_refcnt;           /* ref count */
136 	uint32_t im6o_debug;            /* see ifa_debug flags */
137 	struct  ifnet *im6o_multicast_ifp; /* ifp for outgoing multicasts */
138 	u_char  im6o_multicast_hlim;    /* hoplimit for outgoing multicasts */
139 	u_char  im6o_multicast_loop;    /* 1 >= hear sends if a member */
140 	u_short im6o_num_memberships;   /* no. memberships this socket */
141 	u_short im6o_max_memberships;   /* max memberships this socket */
142 	u_short im6o_max_filters;       /* max filters this socket */
143 	struct  in6_multi **__counted_by(im6o_max_memberships) im6o_membership;
144 	/* group memberships */
145 	struct  in6_mfilter *__counted_by(im6o_max_filters) im6o_mfilters;
146 	/* source filters */
147 	void (*im6o_trace)              /* callback fn for tracing refs */
148 	(struct ip6_moptions *, int);
149 };
150 
151 #define IM6O_LOCK_ASSERT_HELD(_im6o)                                    \
152 	LCK_MTX_ASSERT(&(_im6o)->im6o_lock, LCK_MTX_ASSERT_OWNED)
153 
154 #define IM6O_LOCK_ASSERT_NOTHELD(_im6o)                                 \
155 	LCK_MTX_ASSERT(&(_im6o)->im6o_lock, LCK_MTX_ASSERT_NOTOWNED)
156 
157 #define IM6O_LOCK(_im6o)                                                \
158 	lck_mtx_lock(&(_im6o)->im6o_lock)
159 
160 #define IM6O_LOCK_SPIN(_im6o)                                           \
161 	lck_mtx_lock_spin(&(_im6o)->im6o_lock)
162 
163 #define IM6O_CONVERT_LOCK(_im6o) do {                                   \
164 	IM6O_LOCK_ASSERT_HELD(_im6o);                                   \
165 	lck_mtx_convert_spin(&(_im6o)->im6o_lock);                      \
166 } while (0)
167 
168 #define IM6O_UNLOCK(_im6o)                                              \
169 	lck_mtx_unlock(&(_im6o)->im6o_lock)
170 
171 #define IM6O_ADDREF(_im6o)                                              \
172 	im6o_addref(_im6o, 0)
173 
174 #define IM6O_ADDREF_LOCKED(_im6o)                                       \
175 	im6o_addref(_im6o, 1)
176 
177 #define IM6O_REMREF(_im6o)                                              \
178 	im6o_remref(_im6o)
179 
180 struct ip6_exthdrs {
181 	struct mbuf *ip6e_ip6;
182 	struct mbuf *ip6e_hbh;
183 	struct mbuf *ip6e_dest1;
184 	struct mbuf *ip6e_rthdr;
185 	struct mbuf *ip6e_dest2;
186 	boolean_t merged;
187 };
188 
189 /*
190  * Control options for outgoing packets
191  */
192 
193 /* Routing header related info */
194 struct  ip6po_rhinfo {
195 	struct  ip6_rthdr *ip6po_rhi_rthdr; /* Routing header */
196 	struct  route_in6 ip6po_rhi_route; /* Route to the 1st hop */
197 };
198 #define ip6po_rthdr     ip6po_rhinfo.ip6po_rhi_rthdr
199 #define ip6po_route     ip6po_rhinfo.ip6po_rhi_route
200 
201 /* Nexthop related info */
202 struct  ip6po_nhinfo {
203 	struct  sockaddr *ip6po_nhi_nexthop;
204 	struct  route_in6 ip6po_nhi_route; /* Route to the nexthop */
205 };
206 #define ip6po_nexthop   ip6po_nhinfo.ip6po_nhi_nexthop
207 #define ip6po_nextroute ip6po_nhinfo.ip6po_nhi_route
208 
209 struct  ip6_pktopts {
210 	int16_t ip6po_hlim;     /* Hoplimit for outgoing packets */
211 
212 	int16_t ip6po_tclass;   /* traffic class */
213 
214 	int8_t  ip6po_minmtu:3,  /* fragment vs PMTU discovery policy */
215 	    ip6po_prefer_tempaddr:3, /* whether temporary addresses are preferred as source address */
216 	    ip6po_flags:2;
217 
218 #define IP6PO_MINMTU_MCASTONLY  -1 /* default; send at min MTU for multicast */
219 #define IP6PO_MINMTU_DISABLE     0 /* always perform pmtu disc */
220 #define IP6PO_MINMTU_ALL         1 /* always send at min MTU */
221 
222 #define IP6PO_TEMPADDR_SYSTEM   -1 /* follow the system default */
223 #define IP6PO_TEMPADDR_NOTPREFER 0 /* not prefer temporary address */
224 #define IP6PO_TEMPADDR_PREFER    1 /* prefer temporary address */
225 
226 #define IP6PO_DONTFRAG          0x01    /* no fragmentation (IPV6_DONTFRAG) */
227 #define IP6PO_USECOA            0x02    /* use care of address */
228 
229 	/* Outgoing IF/address information */
230 	struct  in6_pktinfo *ip6po_pktinfo;
231 
232 	/* Next-hop address information */
233 	struct  ip6po_nhinfo ip6po_nhinfo;
234 
235 	struct  ip6_hbh *ip6po_hbh; /* Hop-by-Hop options header */
236 
237 	/* Destination options header (before a routing header) */
238 	struct  ip6_dest *ip6po_dest1;
239 
240 	/* Routing header related info. */
241 	struct  ip6po_rhinfo ip6po_rhinfo;
242 
243 	/* Destination options header (after a routing header) */
244 	struct  ip6_dest *ip6po_dest2;
245 };
246 
247 /*
248  * Control options for incoming packets
249  */
250 #endif /* BSD_KERNEL_PRIVATE */
251 
252 #define IP6S_SRCRULE_COUNT 16
253 #include <netinet6/scope6_var.h>
254 
255 struct  ip6stat {
256 	u_quad_t ip6s_total;            /* total packets received */
257 	u_quad_t ip6s_tooshort;         /* packet too short */
258 	u_quad_t ip6s_toosmall;         /* not enough data */
259 	u_quad_t ip6s_fragments;        /* fragments received */
260 	u_quad_t ip6s_fragdropped;      /* frags dropped(dups, out of space) */
261 	u_quad_t ip6s_fragtimeout;      /* fragments timed out */
262 	u_quad_t ip6s_fragoverflow;     /* fragments that exceeded limit */
263 	u_quad_t ip6s_forward;          /* packets forwarded */
264 	u_quad_t ip6s_cantforward;      /* packets rcvd for unreachable dest */
265 	u_quad_t ip6s_redirectsent;     /* packets forwarded on same net */
266 	u_quad_t ip6s_delivered;        /* datagrams delivered to upper level */
267 	u_quad_t ip6s_localout;         /* total ip packets generated here */
268 	u_quad_t ip6s_odropped;         /* lost packets due to nobufs, etc. */
269 	u_quad_t ip6s_reassembled;      /* total packets reassembled ok */
270 	u_quad_t ip6s_atmfrag_rcvd;     /* atomic fragments received */
271 	u_quad_t ip6s_fragmented;       /* datagrams successfully fragmented */
272 	u_quad_t ip6s_ofragments;       /* output fragments created */
273 	u_quad_t ip6s_cantfrag;         /* don't fragment flag was set, etc. */
274 	u_quad_t ip6s_badoptions;       /* error in option processing */
275 	u_quad_t ip6s_noroute;          /* packets discarded due to no route */
276 	u_quad_t ip6s_badvers;          /* ip6 version != 6 */
277 	u_quad_t ip6s_rawout;           /* total raw ip packets generated */
278 	u_quad_t ip6s_badscope;         /* scope error */
279 	u_quad_t ip6s_notmember;        /* don't join this multicast group */
280 	u_quad_t ip6s_nxthist[256];     /* next header history */
281 	u_quad_t ip6s_m1;               /* one mbuf */
282 	u_quad_t ip6s_m2m[32];          /* two or more mbuf */
283 	u_quad_t ip6s_mext1;            /* one ext mbuf */
284 	u_quad_t ip6s_mext2m;           /* two or more ext mbuf */
285 	u_quad_t ip6s_exthdrtoolong;    /* ext hdr are not continuous */
286 	u_quad_t ip6s_nogif;            /* no match gif found */
287 	u_quad_t ip6s_toomanyhdr;       /* discarded due to too many headers */
288 
289 	/*
290 	 * statistics for improvement of the source address selection
291 	 * algorithm:
292 	 */
293 	/* number of times that address selection fails */
294 	u_quad_t ip6s_sources_none;
295 	/* number of times that an address on the outgoing I/F is chosen */
296 	u_quad_t ip6s_sources_sameif[SCOPE6_ID_MAX];
297 	/* number of times that an address on a non-outgoing I/F is chosen */
298 	u_quad_t ip6s_sources_otherif[SCOPE6_ID_MAX];
299 	/*
300 	 * number of times that an address that has the same scope
301 	 * from the destination is chosen.
302 	 */
303 	u_quad_t ip6s_sources_samescope[SCOPE6_ID_MAX];
304 	/*
305 	 * number of times that an address that has a different scope
306 	 * from the destination is chosen.
307 	 */
308 	u_quad_t ip6s_sources_otherscope[SCOPE6_ID_MAX];
309 	/* number of times that a deprecated address is chosen */
310 	u_quad_t ip6s_sources_deprecated[SCOPE6_ID_MAX];
311 
312 	u_quad_t ip6s_forward_cachehit;
313 	u_quad_t ip6s_forward_cachemiss;
314 
315 	/* number of times that each rule of source selection is applied. */
316 	u_quad_t ip6s_sources_rule[IP6S_SRCRULE_COUNT];
317 
318 	/* number of times we ignored address on expensive secondary interfaces */
319 	u_quad_t ip6s_sources_skip_expensive_secondary_if;
320 
321 	/* pkt dropped, no mbufs for control data */
322 	u_quad_t ip6s_pktdropcntrl;
323 
324 	/* total packets trimmed/adjusted  */
325 	u_quad_t ip6s_adj;
326 	/* hwcksum info discarded during adjustment */
327 	u_quad_t ip6s_adj_hwcsum_clr;
328 
329 	/* duplicate address detection collisions */
330 	u_quad_t ip6s_dad_collide;
331 
332 	/* DAD NS looped back */
333 	u_quad_t ip6s_dad_loopcount;
334 
335 	/* NECP policy related drop */
336 	u_quad_t ip6s_necp_policy_drop;
337 
338 	/* CLAT46 stats */
339 	u_quad_t ip6s_clat464_in_tooshort_drop;
340 	u_quad_t ip6s_clat464_in_nov6addr_drop;
341 	u_quad_t ip6s_clat464_in_nov4addr_drop;
342 	u_quad_t ip6s_clat464_in_v4synthfail_drop;
343 	u_quad_t ip6s_clat464_in_64transfail_drop;
344 	u_quad_t ip6s_clat464_in_64proto_transfail_drop;
345 	u_quad_t ip6s_clat464_in_64frag_transfail_drop;
346 	u_quad_t ip6s_clat464_in_invalpbuf_drop;
347 	u_quad_t ip6s_clat464_in_success;
348 	u_quad_t ip6s_clat464_in_drop;
349 	u_quad_t ip6s_clat464_in_v4_drop;
350 
351 	u_quad_t ip6s_clat464_out_nov6addr_drop;
352 	u_quad_t ip6s_clat464_out_v6synthfail_drop;
353 	u_quad_t ip6s_clat464_out_46transfail_drop;
354 	u_quad_t ip6s_clat464_out_46proto_transfail_drop;
355 	u_quad_t ip6s_clat464_out_46frag_transfail_drop;
356 	u_quad_t ip6s_clat464_out_invalpbuf_drop;
357 	u_quad_t ip6s_clat464_out_success;
358 	u_quad_t ip6s_clat464_out_drop;
359 
360 	u_quad_t ip6s_clat464_v6addr_conffail;
361 	u_quad_t ip6s_clat464_plat64_pfx_setfail;
362 	u_quad_t ip6s_clat464_plat64_pfx_getfail;
363 
364 	u_quad_t ip6s_overlap_frag_drop;
365 
366 	u_quad_t ip6s_rcv_if_weak_match;
367 	u_quad_t ip6s_rcv_if_no_match;
368 };
369 
370 enum ip6s_sources_rule_index {
371 	IP6S_SRCRULE_0, IP6S_SRCRULE_1, IP6S_SRCRULE_2, IP6S_SRCRULE_3, IP6S_SRCRULE_4,
372 	IP6S_SRCRULE_5, IP6S_SRCRULE_5_5, IP6S_SRCRULE_6, IP6S_SRCRULE_7,
373 	IP6S_SRCRULE_7x, IP6S_SRCRULE_8
374 };
375 
376 #ifdef BSD_KERNEL_PRIVATE
377 /*
378  * IPv6 onion peeling state.
379  *
380  * This is currently allocated for packets destined to the all-nodes
381  * multicast address over Ethernet.  IPv6 destination address information
382  * is now stored in the mbuf itself.
383  */
384 struct ip6aux {
385 	u_int32_t ip6a_flags;
386 #define IP6A_HASEEN     0x01            /* HA was present */
387 
388 #ifdef notyet
389 #define IP6A_SWAP       0x02            /* swapped home/care-of on packet */
390 #define IP6A_BRUID      0x04            /* BR Unique Identifier was present */
391 #define IP6A_RTALERTSEEN 0x08           /* rtalert present */
392 
393 	/* ip6.ip6_src */
394 	struct in6_addr ip6a_careof;    /* care-of address of the peer */
395 	struct in6_addr ip6a_home;      /* home address of the peer */
396 	u_int16_t       ip6a_bruid;     /* BR unique identifier */
397 
398 	/* rtalert */
399 	u_int16_t ip6a_rtalert;         /* rtalert option value */
400 #endif /* notyet */
401 
402 	/* ether source address if all-nodes multicast destination */
403 	u_char ip6a_ehsrc[ETHER_ADDR_LEN];
404 };
405 
406 /* flags passed to ip6_output as last parameter */
407 #define IPV6_UNSPECSRC          0x01    /* allow :: as the source address */
408 #define IPV6_FORWARDING         0x02    /* most of IPv6 header exists */
409 #define IPV6_MINMTU             0x04    /* use minimum MTU (IPV6_USE_MIN_MTU) */
410 #define IPV6_FLAG_NOSRCIFSEL    0x80    /* bypass source address selection */
411 #define IPV6_OUTARGS            0x100   /* has ancillary output info */
412 
413 #ifdef BSD_KERNEL_PRIVATE
414 #define IP6_HDR_ALIGNED_P(_ip6) ((((uintptr_t)(_ip6)) & ((uintptr_t)3)) == 0)
415 
416 /*
417  * On platforms which require strict alignment (currently for anything but
418  * i386 or x86_64 or arm64), this macro checks whether the pointer to the IP header
419  * is 32-bit aligned, and assert otherwise.
420  */
421 #if defined(__i386__) || defined(__x86_64__) || defined(__arm64__)
422 #define IP6_HDR_STRICT_ALIGNMENT_CHECK(_ip6) do { } while (0)
423 #else /* !__i386__ && !__x86_64__ && !__arm64__ */
424 #define IP6_HDR_STRICT_ALIGNMENT_CHECK(_ip6) do {                       \
425 	if (!IP_HDR_ALIGNED_P(_ip6)) {                                  \
426 	        panic_plain("\n%s: Unaligned IPv6 header %p\n",         \
427 	            __func__, _ip6);                                    \
428 	}                                                               \
429 } while (0)
430 #endif /* !__i386__ && !__x86_64__ && !__arm64__ */
431 #endif /* BSD_KERNEL_PRIVATE */
432 
433 #include <net/flowadv.h>
434 
435 /*
436  * Extra information passed to ip6_output when IPV6_OUTARGS is set.
437  */
438 struct ip6_out_args {
439 	unsigned int    ip6oa_boundif;  /* bound outgoing interface */
440 	struct flowadv  ip6oa_flowadv;  /* flow advisory code */
441 	u_int32_t       ip6oa_flags;    /* IP6OAF flags (see below) */
442 #define IP6OAF_SELECT_SRCIF             0x00000001      /* src interface selection */
443 #define IP6OAF_BOUND_IF                 0x00000002      /* boundif value is valid */
444 #define IP6OAF_BOUND_SRCADDR            0x00000004      /* bound to src address */
445 #define IP6OAF_NO_CELLULAR              0x00000010      /* skip IFT_CELLULAR */
446 #define IP6OAF_NO_EXPENSIVE             0x00000020      /* skip IFEF_EXPENSIVE */
447 #define IP6OAF_AWDL_UNRESTRICTED        0x00000040      /* privileged AWDL */
448 #define IP6OAF_QOSMARKING_ALLOWED       0x00000080      /* policy allows Fastlane DSCP marking */
449 #define IP6OAF_INTCOPROC_ALLOWED        0x00000100      /* access to internal coproc interfaces */
450 #define IP6OAF_NO_LOW_POWER             0x00000200      /* skip low power */
451 #define IP6OAF_NO_CONSTRAINED           0x00000400      /* skip IFXF_CONSTRAINED */
452 #define IP6OAF_SKIP_PF                  0x00000800      /* skip PF */
453 #define IP6OAF_DONT_FRAG                0x00001000      /* Don't fragment */
454 #define IP6OAF_REDO_QOSMARKING_POLICY   0x00002000      /* Re-evaluate QOS marking policy */
455 #define IP6OAF_R_IFDENIED               0x00004000      /* return flag: denied access to interface */
456 #define IP6OAF_MANAGEMENT_ALLOWED       0x00008000      /* access to management interfaces */
457 #define IP6OAF_ULTRA_CONSTRAINED_ALLOWED 0x00010000     /* access to ultra constrained interfaces */
458 	int             ip6oa_sotc;             /* traffic class for Fastlane DSCP mapping */
459 	int             ip6oa_netsvctype;
460 	int32_t         qos_marking_gencount;
461 };
462 
463 #define IP6OAF_RET_MASK (IP6OAF_R_IFDENIED)
464 
465 extern struct ip6stat ip6stat;  /* statistics */
466 extern int ip6_defhlim;         /* default hop limit */
467 extern int ip6_defmcasthlim;    /* default multicast hop limit */
468 extern int ip6_forwarding;      /* act as router? */
469 extern int ip6_gif_hlim;        /* Hop limit for gif encap packet */
470 extern int ip6_use_deprecated;  /* allow deprecated addr as source */
471 extern int ip6_rr_prune;        /* router renumbering prefix */
472                                 /*   walk list every 5 sec. */
473 extern int ip6_mcast_pmtu;      /* enable pMTU discovery for multicast? */
474 #define ip6_mapped_addr_on      (!ip6_v6only)
475 extern int ip6_v6only;
476 
477 extern int ip6_neighborgcthresh; /* Threshold # of NDP entries for GC */
478 extern int ip6_maxifprefixes;   /* Max acceptable prefixes via RA per IF */
479 extern int ip6_maxifdefrouters; /* Max acceptable def routers via RA */
480 extern int ip6_maxdynroutes;    /* Max # of routes created via redirect */
481 extern int ip6_sendredirects;   /* send IP redirects when forwarding? */
482 extern int ip6_accept_rtadv;    /* deprecated */
483 extern int ip6_log_interval;
484 extern uint64_t ip6_log_time;
485 extern int ip6_hdrnestlimit;    /* upper limit of # of extension headers */
486 extern int ip6_dad_count;       /* DupAddrDetectionTransmits */
487 
488 /* RFC4193 Unique Local Unicast Prefixes only */
489 extern int ip6_only_allow_rfc4193_prefix;
490 
491 extern int ip6_auto_flowlabel;
492 extern int ip6_auto_linklocal;
493 
494 extern int ip6_anonportmin;             /* minimum ephemeral port */
495 extern int ip6_anonportmax;             /* maximum ephemeral port */
496 extern int ip6_lowportmin;              /* minimum reserved port */
497 extern int ip6_lowportmax;              /* maximum reserved port */
498 
499 extern int ip6_use_tempaddr; /* whether to use temporary addresses. */
500 extern int ip6_ula_use_tempaddr; /* whether to use temporary ULA addresses */
501 
502 /* whether to prefer temporary addresses in the source address selection */
503 extern int ip6_prefer_tempaddr;
504 
505 /* whether to use the default scope zone when unspecified */
506 extern int ip6_use_defzone;
507 
508 /* how many times to try allocating cga address after conflict */
509 extern int ip6_cga_conflict_retries;
510 #define IPV6_CGA_CONFLICT_RETRIES_DEFAULT 3
511 #define IPV6_CGA_CONFLICT_RETRIES_MAX     10
512 
513 extern struct pr_usrreqs rip6_usrreqs;
514 extern struct pr_usrreqs icmp6_dgram_usrreqs;
515 
516 struct sockopt;
517 struct inpcb;
518 struct ip6_hdr;
519 struct in6_ifaddr;
520 struct ip6protosw;
521 struct domain;
522 
523 extern int icmp6_ctloutput(struct socket *, struct sockopt *);
524 extern int icmp6_dgram_ctloutput(struct socket *, struct sockopt *);
525 extern int icmp6_dgram_send(struct socket *, int, struct mbuf *,
526     struct sockaddr *, struct mbuf *, struct proc *);
527 extern int icmp6_dgram_attach(struct socket *, int, struct proc *);
528 
529 extern void ip6_register_m_tag(void);
530 
531 extern void ip6_init(struct protosw *, struct domain *);
532 extern void ip6_input(struct mbuf *);
533 extern void ip6_setsrcifaddr_info(struct mbuf *, uint32_t, struct in6_ifaddr *);
534 extern void ip6_setdstifaddr_info(struct mbuf *, uint32_t, struct in6_ifaddr *);
535 extern int ip6_getsrcifaddr_info(struct mbuf *, uint32_t *, uint32_t *);
536 extern int ip6_getdstifaddr_info(struct mbuf *, uint32_t *, uint32_t *);
537 extern uint32_t ip6_input_getsrcifscope(struct mbuf *);
538 extern uint32_t ip6_input_getdstifscope(struct mbuf *);
539 extern void ip6_output_setsrcifscope(struct mbuf *, uint32_t, struct in6_ifaddr *);
540 extern void ip6_output_setdstifscope(struct mbuf *, uint32_t, struct in6_ifaddr *);
541 extern uint32_t ip6_output_getsrcifscope(struct mbuf *);
542 extern uint32_t ip6_output_getdstifscope(struct mbuf *);
543 
544 extern void ip6_freepcbopts(struct ip6_pktopts *);
545 extern int ip6_unknown_opt(uint8_t * __counted_by(optplen) optp, size_t optplen, struct mbuf *, size_t);
546 extern char *ip6_get_prevhdr(struct mbuf *, int);
547 extern int ip6_nexthdr(struct mbuf *, int, int, int *);
548 extern int ip6_lasthdr(struct mbuf *, int, int, int *);
549 extern boolean_t ip6_pkt_has_ulp(struct mbuf *m);
550 
551 extern void ip6_moptions_init(void);
552 extern struct ip6_moptions *ip6_allocmoptions(zalloc_flags_t);
553 extern void im6o_addref(struct ip6_moptions *, int);
554 extern void im6o_remref(struct ip6_moptions *);
555 
556 extern struct ip6aux *ip6_addaux(struct mbuf *);
557 extern struct ip6aux *ip6_findaux(struct mbuf *);
558 extern void ip6_delaux(struct mbuf *);
559 
560 extern int ip6_process_hopopts(struct mbuf *, u_int8_t *__sized_by(hbhlen) opthead, int hbhlen,
561     u_int32_t *, u_int32_t *);
562 extern struct mbuf **ip6_savecontrol_v4(struct inpcb *, struct mbuf *,
563     struct mbuf **, int *);
564 extern int ip6_savecontrol(struct inpcb *, struct mbuf *, struct mbuf **);
565 extern struct mbuf *ip6_forward(struct mbuf *, struct route_in6 *, int);
566 extern void ip6_notify_pmtu(struct inpcb *, struct sockaddr_in6 *, u_int32_t *);
567 extern void ip6_mloopback(struct ifnet *, struct ifnet *, struct mbuf *,
568     struct sockaddr_in6 *, uint32_t, int32_t);
569 extern int ip6_output(struct mbuf *, struct ip6_pktopts *, struct route_in6 *,
570     int, struct ip6_moptions *, struct ifnet **, struct ip6_out_args *);
571 extern int ip6_output_list(struct mbuf *, int, struct ip6_pktopts *,
572     struct route_in6 *, int, struct ip6_moptions *, struct ifnet **,
573     struct ip6_out_args *);
574 extern int ip6_ctloutput(struct socket *, struct sockopt *);
575 extern int ip6_raw_ctloutput(struct socket *, struct sockopt *);
576 extern void ip6_initpktopts(struct ip6_pktopts *);
577 extern int ip6_setpktoptions(struct mbuf *, struct ip6_pktopts *, int, int);
578 extern void ip6_clearpktopts(struct ip6_pktopts *, int);
579 extern struct ip6_pktopts *ip6_copypktopts(struct ip6_pktopts *, zalloc_flags_t);
580 extern int ip6_optlen(struct inpcb *);
581 extern void ip6_drain(void);
582 extern int ip6_do_fragmentation(struct mbuf **, uint32_t, struct ifnet *, uint32_t,
583     struct ip6_hdr *, uint8_t *, uint32_t, int, uint32_t);
584 
585 extern int route6_input(struct mbuf **, int *, int);
586 
587 extern void frag6_init(void);
588 extern int frag6_input(struct mbuf **, int *, int);
589 extern void frag6_drain(void);
590 
591 extern int rip6_input(struct mbuf **, int *, int);
592 extern void rip6_ctlinput(int, struct sockaddr *, void *, struct ifnet *);
593 extern int rip6_ctloutput(struct socket *so, struct sockopt *sopt);
594 extern int rip6_output(struct mbuf *, struct socket *, struct sockaddr_in6 *,
595     struct mbuf *, int);
596 
597 extern int dest6_input(struct mbuf **, int *, int);
598 /*
599  * IPv6 source address selection hints
600  */
601 #define IPV6_SRCSEL_HINT_PREFER_TMPADDR         0x00000001
602 
603 extern struct ifaddr * in6_selectsrc_core_ifa(struct sockaddr_in6 *, struct ifnet *);
604 extern struct in6_addr * in6_selectsrc_core(struct sockaddr_in6 *,
605     uint32_t, struct ifnet *, int, struct in6_addr *,
606     struct ifnet **, int *, struct ifaddr **, struct route_in6 *, boolean_t);
607 extern struct in6_addr *in6_selectsrc(struct sockaddr_in6 *,
608     struct ip6_pktopts *, struct inpcb *, struct route_in6 *,
609     struct ifnet **, struct in6_addr *, unsigned int, int *);
610 extern struct in6_addrpolicy *in6_addrsel_lookup_policy(struct sockaddr_in6 *);
611 extern int in6_selectroute(struct sockaddr_in6 *, struct sockaddr_in6 *,
612     struct ip6_pktopts *, struct ip6_moptions *, struct in6_ifaddr **,
613     struct route_in6 *, struct ifnet **, struct rtentry **, int,
614     struct ip6_out_args *);
615 extern int ip6_setpktopts(struct mbuf *control, struct ip6_pktopts *opt,
616     struct ip6_pktopts *stickyopt, int uproto);
617 extern uint32_t ip6_randomid(uint64_t);
618 extern uint32_t ip6_randomflowlabel(void);
619 #endif /* BSD_KERNEL_PRIVATE */
620 #endif /* !_NETINET6_IP6_VAR_H_ */
621