11da177e4SLinus Torvalds /* 21da177e4SLinus Torvalds * INET An implementation of the TCP/IP protocol suite for the LINUX 31da177e4SLinus Torvalds * operating system. INET is implemented using the BSD Socket 41da177e4SLinus Torvalds * interface as the means of communication with the user level. 51da177e4SLinus Torvalds * 61da177e4SLinus Torvalds * Definitions for the IP router. 71da177e4SLinus Torvalds * 81da177e4SLinus Torvalds * Version: @(#)route.h 1.0.4 05/27/93 91da177e4SLinus Torvalds * 1002c30a84SJesper Juhl * Authors: Ross Biro 111da177e4SLinus Torvalds * Fred N. van Kempen, <waltje@uWalt.NL.Mugnet.ORG> 121da177e4SLinus Torvalds * Fixes: 131da177e4SLinus Torvalds * Alan Cox : Reformatted. Added ip_rt_local() 141da177e4SLinus Torvalds * Alan Cox : Support for TCP parameters. 151da177e4SLinus Torvalds * Alexey Kuznetsov: Major changes for new routing code. 161da177e4SLinus Torvalds * Mike McLagan : Routing by source 171da177e4SLinus Torvalds * Robert Olsson : Added rt_cache statistics 181da177e4SLinus Torvalds * 191da177e4SLinus Torvalds * This program is free software; you can redistribute it and/or 201da177e4SLinus Torvalds * modify it under the terms of the GNU General Public License 211da177e4SLinus Torvalds * as published by the Free Software Foundation; either version 221da177e4SLinus Torvalds * 2 of the License, or (at your option) any later version. 231da177e4SLinus Torvalds */ 241da177e4SLinus Torvalds #ifndef _ROUTE_H 251da177e4SLinus Torvalds #define _ROUTE_H 261da177e4SLinus Torvalds 271da177e4SLinus Torvalds #include <net/dst.h> 281da177e4SLinus Torvalds #include <net/inetpeer.h> 291da177e4SLinus Torvalds #include <net/flow.h> 3079876874SKOVACS Krisztian #include <net/inet_sock.h> 3179a13159SPeter Nørlund #include <net/ip_fib.h> 321da177e4SLinus Torvalds #include <linux/in_route.h> 331da177e4SLinus Torvalds #include <linux/rtnetlink.h> 34c6cffba4SDavid S. Miller #include <linux/rcupdate.h> 351da177e4SLinus Torvalds #include <linux/route.h> 361da177e4SLinus Torvalds #include <linux/ip.h> 371da177e4SLinus Torvalds #include <linux/cache.h> 38beb8d13bSVenkat Yekkirala #include <linux/security.h> 391da177e4SLinus Torvalds 40f87c10a8SHannes Frederic Sowa /* IPv4 datagram length is stored into 16bit field (tot_len) */ 41f87c10a8SHannes Frederic Sowa #define IP_MAX_MTU 0xFFFFU 42f87c10a8SHannes Frederic Sowa 431da177e4SLinus Torvalds #define RTO_ONLINK 0x01 441da177e4SLinus Torvalds 451da177e4SLinus Torvalds #define RT_CONN_FLAGS(sk) (RT_TOS(inet_sk(sk)->tos) | sock_flag(sk, SOCK_LOCALROUTE)) 46aa661581SFrancesco Fusco #define RT_CONN_FLAGS_TOS(sk,tos) (RT_TOS(tos) | sock_flag(sk, SOCK_LOCALROUTE)) 471da177e4SLinus Torvalds 481da177e4SLinus Torvalds struct fib_nh; 4962fa8a84SDavid S. Miller struct fib_info; 505055c371SEric Dumazet struct uncached_list; 51fd2c3ef7SEric Dumazet struct rtable { 521da177e4SLinus Torvalds struct dst_entry dst; 531da177e4SLinus Torvalds 5429e75252SEric Dumazet int rt_genid; 5595c96174SEric Dumazet unsigned int rt_flags; 561da177e4SLinus Torvalds __u16 rt_type; 57155e8336SJulian Anastasov __u8 rt_is_input; 58155e8336SJulian Anastasov __u8 rt_uses_gateway; 591da177e4SLinus Torvalds 601da177e4SLinus Torvalds int rt_iif; 611da177e4SLinus Torvalds 621da177e4SLinus Torvalds /* Info on neighbour */ 63f2c3fe24SAl Viro __be32 rt_gateway; 641da177e4SLinus Torvalds 651da177e4SLinus Torvalds /* Miscellaneous cached information */ 66d52e5a7eSSabrina Dubroca u32 rt_mtu_locked:1, 67d52e5a7eSSabrina Dubroca rt_pmtu:31; 68caacf05eSDavid S. Miller 69caacf05eSDavid S. Miller struct list_head rt_uncached; 705055c371SEric Dumazet struct uncached_list *rt_uncached_list; 711da177e4SLinus Torvalds }; 721da177e4SLinus Torvalds 73b8400f37SSteffen Klassert static inline bool rt_is_input_route(const struct rtable *rt) 74c7537967SDavid S. Miller { 759917e1e8SDavid S. Miller return rt->rt_is_input != 0; 76c7537967SDavid S. Miller } 77c7537967SDavid S. Miller 78b8400f37SSteffen Klassert static inline bool rt_is_output_route(const struct rtable *rt) 79c7537967SDavid S. Miller { 809917e1e8SDavid S. Miller return rt->rt_is_input == 0; 81c7537967SDavid S. Miller } 82c7537967SDavid S. Miller 83f8126f1dSDavid S. Miller static inline __be32 rt_nexthop(const struct rtable *rt, __be32 daddr) 84f8126f1dSDavid S. Miller { 85f8126f1dSDavid S. Miller if (rt->rt_gateway) 86f8126f1dSDavid S. Miller return rt->rt_gateway; 87f8126f1dSDavid S. Miller return daddr; 88f8126f1dSDavid S. Miller } 89f8126f1dSDavid S. Miller 90fd2c3ef7SEric Dumazet struct ip_rt_acct { 911da177e4SLinus Torvalds __u32 o_bytes; 921da177e4SLinus Torvalds __u32 o_packets; 931da177e4SLinus Torvalds __u32 i_bytes; 941da177e4SLinus Torvalds __u32 i_packets; 951da177e4SLinus Torvalds }; 961da177e4SLinus Torvalds 97fd2c3ef7SEric Dumazet struct rt_cache_stat { 981da177e4SLinus Torvalds unsigned int in_slow_tot; 991da177e4SLinus Torvalds unsigned int in_slow_mc; 1001da177e4SLinus Torvalds unsigned int in_no_route; 1011da177e4SLinus Torvalds unsigned int in_brd; 1021da177e4SLinus Torvalds unsigned int in_martian_dst; 1031da177e4SLinus Torvalds unsigned int in_martian_src; 1041da177e4SLinus Torvalds unsigned int out_slow_tot; 1051da177e4SLinus Torvalds unsigned int out_slow_mc; 1061da177e4SLinus Torvalds }; 1071da177e4SLinus Torvalds 1087d720c3eSTejun Heo extern struct ip_rt_acct __percpu *ip_rt_acct; 1091da177e4SLinus Torvalds 1101da177e4SLinus Torvalds struct in_device; 1112702c4bbSJoe Perches 1122702c4bbSJoe Perches int ip_rt_init(void); 1132702c4bbSJoe Perches void rt_cache_flush(struct net *net); 1142702c4bbSJoe Perches void rt_flush_dev(struct net_device *dev); 1153abd1adeSDavid Ahern struct rtable *ip_route_output_key_hash(struct net *net, struct flowi4 *flp, 1163abd1adeSDavid Ahern const struct sk_buff *skb); 1173abd1adeSDavid Ahern struct rtable *ip_route_output_key_hash_rcu(struct net *net, struct flowi4 *flp, 1183abd1adeSDavid Ahern struct fib_result *res, 119bf4e0a3dSNikolay Aleksandrov const struct sk_buff *skb); 12079a13159SPeter Nørlund 12179a13159SPeter Nørlund static inline struct rtable *__ip_route_output_key(struct net *net, 12279a13159SPeter Nørlund struct flowi4 *flp) 12379a13159SPeter Nørlund { 1243abd1adeSDavid Ahern return ip_route_output_key_hash(net, flp, NULL); 12579a13159SPeter Nørlund } 12679a13159SPeter Nørlund 1272702c4bbSJoe Perches struct rtable *ip_route_output_flow(struct net *, struct flowi4 *flp, 1286f9c9615SEric Dumazet const struct sock *sk); 1292702c4bbSJoe Perches struct dst_entry *ipv4_blackhole_route(struct net *net, 1302702c4bbSJoe Perches struct dst_entry *dst_orig); 131407eadd9SEric Dumazet 1329d6ec938SDavid S. Miller static inline struct rtable *ip_route_output_key(struct net *net, struct flowi4 *flp) 1335bfa787fSDavid S. Miller { 1345bfa787fSDavid S. Miller return ip_route_output_flow(net, flp, NULL); 1355bfa787fSDavid S. Miller } 1365bfa787fSDavid S. Miller 13778fbfd8aSDavid S. Miller static inline struct rtable *ip_route_output(struct net *net, __be32 daddr, 13878fbfd8aSDavid S. Miller __be32 saddr, u8 tos, int oif) 13978fbfd8aSDavid S. Miller { 1409d6ec938SDavid S. Miller struct flowi4 fl4 = { 1419d6ec938SDavid S. Miller .flowi4_oif = oif, 142c5d21c4bSRoland Dreier .flowi4_tos = tos, 1439d6ec938SDavid S. Miller .daddr = daddr, 1449d6ec938SDavid S. Miller .saddr = saddr, 14578fbfd8aSDavid S. Miller }; 1469d6ec938SDavid S. Miller return ip_route_output_key(net, &fl4); 14778fbfd8aSDavid S. Miller } 14878fbfd8aSDavid S. Miller 14931e4543dSDavid S. Miller static inline struct rtable *ip_route_output_ports(struct net *net, struct flowi4 *fl4, 15031e4543dSDavid S. Miller struct sock *sk, 15178fbfd8aSDavid S. Miller __be32 daddr, __be32 saddr, 15278fbfd8aSDavid S. Miller __be16 dport, __be16 sport, 15378fbfd8aSDavid S. Miller __u8 proto, __u8 tos, int oif) 15478fbfd8aSDavid S. Miller { 15531e4543dSDavid S. Miller flowi4_init_output(fl4, oif, sk ? sk->sk_mark : 0, tos, 15694b92b88SDavid S. Miller RT_SCOPE_UNIVERSE, proto, 15794b92b88SDavid S. Miller sk ? inet_sk_flowi_flags(sk) : 0, 158e2d118a1SLorenzo Colitti daddr, saddr, dport, sport, sock_net_uid(net, sk)); 15978fbfd8aSDavid S. Miller if (sk) 16031e4543dSDavid S. Miller security_sk_classify_flow(sk, flowi4_to_flowi(fl4)); 16131e4543dSDavid S. Miller return ip_route_output_flow(net, fl4, sk); 16278fbfd8aSDavid S. Miller } 16378fbfd8aSDavid S. Miller 164cbb1e85fSDavid S. Miller static inline struct rtable *ip_route_output_gre(struct net *net, struct flowi4 *fl4, 16578fbfd8aSDavid S. Miller __be32 daddr, __be32 saddr, 16678fbfd8aSDavid S. Miller __be32 gre_key, __u8 tos, int oif) 16778fbfd8aSDavid S. Miller { 168cbb1e85fSDavid S. Miller memset(fl4, 0, sizeof(*fl4)); 169cbb1e85fSDavid S. Miller fl4->flowi4_oif = oif; 170cbb1e85fSDavid S. Miller fl4->daddr = daddr; 171cbb1e85fSDavid S. Miller fl4->saddr = saddr; 172cbb1e85fSDavid S. Miller fl4->flowi4_tos = tos; 173cbb1e85fSDavid S. Miller fl4->flowi4_proto = IPPROTO_GRE; 174cbb1e85fSDavid S. Miller fl4->fl4_gre_key = gre_key; 175cbb1e85fSDavid S. Miller return ip_route_output_key(net, fl4); 17678fbfd8aSDavid S. Miller } 177bc044e8dSPaolo Abeni int ip_mc_validate_source(struct sk_buff *skb, __be32 daddr, __be32 saddr, 178bc044e8dSPaolo Abeni u8 tos, struct net_device *dev, 179bc044e8dSPaolo Abeni struct in_device *in_dev, u32 *itag); 1802702c4bbSJoe Perches int ip_route_input_noref(struct sk_buff *skb, __be32 dst, __be32 src, 18138a424e4SDavid Miller u8 tos, struct net_device *devin); 1825510cdf7SDavid Ahern int ip_route_input_rcu(struct sk_buff *skb, __be32 dst, __be32 src, 1835510cdf7SDavid Ahern u8 tos, struct net_device *devin, 1845510cdf7SDavid Ahern struct fib_result *res); 185407eadd9SEric Dumazet 186c6cffba4SDavid S. Miller static inline int ip_route_input(struct sk_buff *skb, __be32 dst, __be32 src, 187c6cffba4SDavid S. Miller u8 tos, struct net_device *devin) 188c6cffba4SDavid S. Miller { 189c6cffba4SDavid S. Miller int err; 190c6cffba4SDavid S. Miller 191c6cffba4SDavid S. Miller rcu_read_lock(); 192c6cffba4SDavid S. Miller err = ip_route_input_noref(skb, dst, src, tos, devin); 19364327fc8SStefano Brivio if (!err) { 194222d7dbdSEric Dumazet skb_dst_force(skb); 1959df16efaSWei Wang if (!skb_dst(skb)) 1969df16efaSWei Wang err = -EINVAL; 19764327fc8SStefano Brivio } 198c6cffba4SDavid S. Miller rcu_read_unlock(); 199c6cffba4SDavid S. Miller 200c6cffba4SDavid S. Miller return err; 201c6cffba4SDavid S. Miller } 202c6cffba4SDavid S. Miller 2032702c4bbSJoe Perches void ipv4_update_pmtu(struct sk_buff *skb, struct net *net, u32 mtu, int oif, 204d888f396SMaciej Żenczykowski u8 protocol); 2052702c4bbSJoe Perches void ipv4_sk_update_pmtu(struct sk_buff *skb, struct sock *sk, u32 mtu); 2062702c4bbSJoe Perches void ipv4_redirect(struct sk_buff *skb, struct net *net, int oif, u32 mark, 2072702c4bbSJoe Perches u8 protocol, int flow_flags); 2082702c4bbSJoe Perches void ipv4_sk_redirect(struct sk_buff *skb, struct sock *sk); 2092702c4bbSJoe Perches void ip_rt_send_redirect(struct sk_buff *skb); 2101da177e4SLinus Torvalds 2112702c4bbSJoe Perches unsigned int inet_addr_type(struct net *net, __be32 addr); 2129b8ff518SDavid Ahern unsigned int inet_addr_type_table(struct net *net, __be32 addr, u32 tb_id); 2132702c4bbSJoe Perches unsigned int inet_dev_addr_type(struct net *net, const struct net_device *dev, 2142702c4bbSJoe Perches __be32 addr); 21530bbaa19SDavid Ahern unsigned int inet_addr_type_dev_table(struct net *net, 21630bbaa19SDavid Ahern const struct net_device *dev, 21730bbaa19SDavid Ahern __be32 addr); 2182702c4bbSJoe Perches void ip_rt_multicast_event(struct in_device *); 219ca25c300SAl Viro int ip_rt_ioctl(struct net *, unsigned int cmd, struct rtentry *rt); 2202702c4bbSJoe Perches void ip_rt_get_source(u8 *src, struct sk_buff *skb, struct rtable *rt); 2219ab179d8SDavid Ahern struct rtable *rt_dst_alloc(struct net_device *dev, 2229ab179d8SDavid Ahern unsigned int flags, u16 type, 2239ab179d8SDavid Ahern bool nopolicy, bool noxfrm, bool will_cache); 2241da177e4SLinus Torvalds 2250ff60a45SJamal Hadi Salim struct in_ifaddr; 2262702c4bbSJoe Perches void fib_add_ifaddr(struct in_ifaddr *); 2272702c4bbSJoe Perches void fib_del_ifaddr(struct in_ifaddr *, struct in_ifaddr *); 228af4d768aSDavid Ahern void fib_modify_prefix_metric(struct in_ifaddr *ifa, u32 new_metric); 2290ff60a45SJamal Hadi Salim 230510c321bSXin Long void rt_add_uncached_list(struct rtable *rt); 231510c321bSXin Long void rt_del_uncached_list(struct rtable *rt); 232510c321bSXin Long 2331da177e4SLinus Torvalds static inline void ip_rt_put(struct rtable *rt) 2341da177e4SLinus Torvalds { 2356da025faSEric Dumazet /* dst_release() accepts a NULL parameter. 2366da025faSEric Dumazet * We rely on dst being first structure in struct rtable 2376da025faSEric Dumazet */ 2386da025faSEric Dumazet BUILD_BUG_ON(offsetof(struct rtable, dst) != 0); 239d8d1f30bSChangli Gao dst_release(&rt->dst); 2401da177e4SLinus Torvalds } 2411da177e4SLinus Torvalds 2421da177e4SLinus Torvalds #define IPTOS_RT_MASK (IPTOS_TOS_MASK & ~3) 2431da177e4SLinus Torvalds 2444839c52bSPhilippe De Muyter extern const __u8 ip_tos2prio[16]; 2451da177e4SLinus Torvalds 2461da177e4SLinus Torvalds static inline char rt_tos2priority(u8 tos) 2471da177e4SLinus Torvalds { 2481da177e4SLinus Torvalds return ip_tos2prio[IPTOS_TOS(tos)>>1]; 2491da177e4SLinus Torvalds } 2501da177e4SLinus Torvalds 2512d7192d6SDavid S. Miller /* ip_route_connect() and ip_route_newports() work in tandem whilst 2522d7192d6SDavid S. Miller * binding a socket for a new outgoing connection. 2532d7192d6SDavid S. Miller * 2542d7192d6SDavid S. Miller * In order to use IPSEC properly, we must, in the end, have a 2552d7192d6SDavid S. Miller * route that was looked up using all available keys including source 2562d7192d6SDavid S. Miller * and destination ports. 2572d7192d6SDavid S. Miller * 2582d7192d6SDavid S. Miller * However, if a source port needs to be allocated (the user specified 2592d7192d6SDavid S. Miller * a wildcard source port) we need to obtain addressing information 2602d7192d6SDavid S. Miller * in order to perform that allocation. 2612d7192d6SDavid S. Miller * 2622d7192d6SDavid S. Miller * So ip_route_connect() looks up a route using wildcarded source and 2632d7192d6SDavid S. Miller * destination ports in the key, simply so that we can get a pair of 2642d7192d6SDavid S. Miller * addresses to use for port allocation. 2652d7192d6SDavid S. Miller * 2662d7192d6SDavid S. Miller * Later, once the ports are allocated, ip_route_newports() will make 2672d7192d6SDavid S. Miller * another route lookup if needed to make sure we catch any IPSEC 2682d7192d6SDavid S. Miller * rules keyed on the port information. 2692d7192d6SDavid S. Miller * 2702d7192d6SDavid S. Miller * The callers allocate the flow key on their stack, and must pass in 2712d7192d6SDavid S. Miller * the same flowi4 object to both the ip_route_connect() and the 2722d7192d6SDavid S. Miller * ip_route_newports() calls. 2732d7192d6SDavid S. Miller */ 2742d7192d6SDavid S. Miller 2752d7192d6SDavid S. Miller static inline void ip_route_connect_init(struct flowi4 *fl4, __be32 dst, __be32 src, 2762d7192d6SDavid S. Miller u32 tos, int oif, u8 protocol, 277b23dd4feSDavid S. Miller __be16 sport, __be16 dport, 2780e0d44abSSteffen Klassert struct sock *sk) 2791da177e4SLinus Torvalds { 2802d7192d6SDavid S. Miller __u8 flow_flags = 0; 28179876874SKOVACS Krisztian 28279876874SKOVACS Krisztian if (inet_sk(sk)->transparent) 28394b92b88SDavid S. Miller flow_flags |= FLOWI_FLAG_ANYSRC; 28494b92b88SDavid S. Miller 2852d7192d6SDavid S. Miller flowi4_init_output(fl4, oif, sk->sk_mark, tos, RT_SCOPE_UNIVERSE, 286e2d118a1SLorenzo Colitti protocol, flow_flags, dst, src, dport, sport, 287e2d118a1SLorenzo Colitti sk->sk_uid); 2882d7192d6SDavid S. Miller } 2892d7192d6SDavid S. Miller 2902d7192d6SDavid S. Miller static inline struct rtable *ip_route_connect(struct flowi4 *fl4, 2912d7192d6SDavid S. Miller __be32 dst, __be32 src, u32 tos, 2922d7192d6SDavid S. Miller int oif, u8 protocol, 2932d7192d6SDavid S. Miller __be16 sport, __be16 dport, 2940e0d44abSSteffen Klassert struct sock *sk) 2952d7192d6SDavid S. Miller { 2962d7192d6SDavid S. Miller struct net *net = sock_net(sk); 2972d7192d6SDavid S. Miller struct rtable *rt; 2982d7192d6SDavid S. Miller 2992d7192d6SDavid S. Miller ip_route_connect_init(fl4, dst, src, tos, oif, protocol, 3000e0d44abSSteffen Klassert sport, dport, sk); 30179876874SKOVACS Krisztian 3021da177e4SLinus Torvalds if (!dst || !src) { 3032d7192d6SDavid S. Miller rt = __ip_route_output_key(net, fl4); 304b23dd4feSDavid S. Miller if (IS_ERR(rt)) 305b23dd4feSDavid S. Miller return rt; 306b23dd4feSDavid S. Miller ip_rt_put(rt); 307e6b45241SJulian Anastasov flowi4_update_output(fl4, oif, tos, fl4->daddr, fl4->saddr); 3081da177e4SLinus Torvalds } 3092d7192d6SDavid S. Miller security_sk_classify_flow(sk, flowi4_to_flowi(fl4)); 3102d7192d6SDavid S. Miller return ip_route_output_flow(net, fl4, sk); 3111da177e4SLinus Torvalds } 3121da177e4SLinus Torvalds 3132d7192d6SDavid S. Miller static inline struct rtable *ip_route_newports(struct flowi4 *fl4, struct rtable *rt, 3142d7192d6SDavid S. Miller __be16 orig_sport, __be16 orig_dport, 3152d7192d6SDavid S. Miller __be16 sport, __be16 dport, 3162d7192d6SDavid S. Miller struct sock *sk) 3171da177e4SLinus Torvalds { 318dca8b089SDavid S. Miller if (sport != orig_sport || dport != orig_dport) { 3192d7192d6SDavid S. Miller fl4->fl4_dport = dport; 3202d7192d6SDavid S. Miller fl4->fl4_sport = sport; 321b23dd4feSDavid S. Miller ip_rt_put(rt); 322e6b45241SJulian Anastasov flowi4_update_output(fl4, sk->sk_bound_dev_if, 323e6b45241SJulian Anastasov RT_CONN_FLAGS(sk), fl4->daddr, 324e6b45241SJulian Anastasov fl4->saddr); 3252d7192d6SDavid S. Miller security_sk_classify_flow(sk, flowi4_to_flowi(fl4)); 3262d7192d6SDavid S. Miller return ip_route_output_flow(sock_net(sk), fl4, sk); 3271da177e4SLinus Torvalds } 328b23dd4feSDavid S. Miller return rt; 3291da177e4SLinus Torvalds } 3301da177e4SLinus Torvalds 3311668e010SKOVACS Krisztian static inline int inet_iif(const struct sk_buff *skb) 3321668e010SKOVACS Krisztian { 3330340d0b9STom Herbert struct rtable *rt = skb_rtable(skb); 33413378cadSDavid S. Miller 3350340d0b9STom Herbert if (rt && rt->rt_iif) 3360340d0b9STom Herbert return rt->rt_iif; 3370340d0b9STom Herbert 33813378cadSDavid S. Miller return skb->skb_iif; 3391668e010SKOVACS Krisztian } 3401668e010SKOVACS Krisztian 341323e126fSDavid S. Miller static inline int ip4_dst_hoplimit(const struct dst_entry *dst) 342323e126fSDavid S. Miller { 343323e126fSDavid S. Miller int hoplimit = dst_metric_raw(dst, RTAX_HOPLIMIT); 344fa50d974SNikolay Borisov struct net *net = dev_net(dst->dev); 345323e126fSDavid S. Miller 346323e126fSDavid S. Miller if (hoplimit == 0) 347fa50d974SNikolay Borisov hoplimit = net->ipv4.sysctl_ip_default_ttl; 348323e126fSDavid S. Miller return hoplimit; 349323e126fSDavid S. Miller } 350323e126fSDavid S. Miller 3511da177e4SLinus Torvalds #endif /* _ROUTE_H */ 352