pep.c 25 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106
  1. /*
  2. * File: pep.c
  3. *
  4. * Phonet pipe protocol end point socket
  5. *
  6. * Copyright (C) 2008 Nokia Corporation.
  7. *
  8. * Author: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
  9. *
  10. * This program is free software; you can redistribute it and/or
  11. * modify it under the terms of the GNU General Public License
  12. * version 2 as published by the Free Software Foundation.
  13. *
  14. * This program is distributed in the hope that it will be useful, but
  15. * WITHOUT ANY WARRANTY; without even the implied warranty of
  16. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  17. * General Public License for more details.
  18. *
  19. * You should have received a copy of the GNU General Public License
  20. * along with this program; if not, write to the Free Software
  21. * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
  22. * 02110-1301 USA
  23. */
  24. #include <linux/kernel.h>
  25. #include <linux/slab.h>
  26. #include <linux/socket.h>
  27. #include <net/sock.h>
  28. #include <net/tcp_states.h>
  29. #include <asm/ioctls.h>
  30. #include <linux/phonet.h>
  31. #include <net/phonet/phonet.h>
  32. #include <net/phonet/pep.h>
  33. #include <net/phonet/gprs.h>
  34. /* sk_state values:
  35. * TCP_CLOSE sock not in use yet
  36. * TCP_CLOSE_WAIT disconnected pipe
  37. * TCP_LISTEN listening pipe endpoint
  38. * TCP_SYN_RECV connected pipe in disabled state
  39. * TCP_ESTABLISHED connected pipe in enabled state
  40. *
  41. * pep_sock locking:
  42. * - sk_state, ackq, hlist: sock lock needed
  43. * - listener: read only
  44. * - pipe_handle: read only
  45. */
  46. #define CREDITS_MAX 10
  47. #define CREDITS_THR 7
  48. static const struct sockaddr_pn pipe_srv = {
  49. .spn_family = AF_PHONET,
  50. .spn_resource = 0xD9, /* pipe service */
  51. };
  52. #define pep_sb_size(s) (((s) + 5) & ~3) /* 2-bytes head, 32-bits aligned */
  53. /* Get the next TLV sub-block. */
  54. static unsigned char *pep_get_sb(struct sk_buff *skb, u8 *ptype, u8 *plen,
  55. void *buf)
  56. {
  57. void *data = NULL;
  58. struct {
  59. u8 sb_type;
  60. u8 sb_len;
  61. } *ph, h;
  62. int buflen = *plen;
  63. ph = skb_header_pointer(skb, 0, 2, &h);
  64. if (ph == NULL || ph->sb_len < 2 || !pskb_may_pull(skb, ph->sb_len))
  65. return NULL;
  66. ph->sb_len -= 2;
  67. *ptype = ph->sb_type;
  68. *plen = ph->sb_len;
  69. if (buflen > ph->sb_len)
  70. buflen = ph->sb_len;
  71. data = skb_header_pointer(skb, 2, buflen, buf);
  72. __skb_pull(skb, 2 + ph->sb_len);
  73. return data;
  74. }
  75. static int pep_reply(struct sock *sk, struct sk_buff *oskb,
  76. u8 code, const void *data, int len, gfp_t priority)
  77. {
  78. const struct pnpipehdr *oph = pnp_hdr(oskb);
  79. struct pnpipehdr *ph;
  80. struct sk_buff *skb;
  81. skb = alloc_skb(MAX_PNPIPE_HEADER + len, priority);
  82. if (!skb)
  83. return -ENOMEM;
  84. skb_set_owner_w(skb, sk);
  85. skb_reserve(skb, MAX_PNPIPE_HEADER);
  86. __skb_put(skb, len);
  87. skb_copy_to_linear_data(skb, data, len);
  88. __skb_push(skb, sizeof(*ph));
  89. skb_reset_transport_header(skb);
  90. ph = pnp_hdr(skb);
  91. ph->utid = oph->utid;
  92. ph->message_id = oph->message_id + 1; /* REQ -> RESP */
  93. ph->pipe_handle = oph->pipe_handle;
  94. ph->error_code = code;
  95. return pn_skb_send(sk, skb, &pipe_srv);
  96. }
  97. #define PAD 0x00
  98. static int pep_accept_conn(struct sock *sk, struct sk_buff *skb)
  99. {
  100. static const u8 data[20] = {
  101. PAD, PAD, PAD, 2 /* sub-blocks */,
  102. PN_PIPE_SB_REQUIRED_FC_TX, pep_sb_size(5), 3, PAD,
  103. PN_MULTI_CREDIT_FLOW_CONTROL,
  104. PN_ONE_CREDIT_FLOW_CONTROL,
  105. PN_LEGACY_FLOW_CONTROL,
  106. PAD,
  107. PN_PIPE_SB_PREFERRED_FC_RX, pep_sb_size(5), 3, PAD,
  108. PN_MULTI_CREDIT_FLOW_CONTROL,
  109. PN_ONE_CREDIT_FLOW_CONTROL,
  110. PN_LEGACY_FLOW_CONTROL,
  111. PAD,
  112. };
  113. might_sleep();
  114. return pep_reply(sk, skb, PN_PIPE_NO_ERROR, data, sizeof(data),
  115. GFP_KERNEL);
  116. }
  117. static int pep_reject_conn(struct sock *sk, struct sk_buff *skb, u8 code)
  118. {
  119. static const u8 data[4] = { PAD, PAD, PAD, 0 /* sub-blocks */ };
  120. WARN_ON(code == PN_PIPE_NO_ERROR);
  121. return pep_reply(sk, skb, code, data, sizeof(data), GFP_ATOMIC);
  122. }
  123. /* Control requests are not sent by the pipe service and have a specific
  124. * message format. */
  125. static int pep_ctrlreq_error(struct sock *sk, struct sk_buff *oskb, u8 code,
  126. gfp_t priority)
  127. {
  128. const struct pnpipehdr *oph = pnp_hdr(oskb);
  129. struct sk_buff *skb;
  130. struct pnpipehdr *ph;
  131. struct sockaddr_pn dst;
  132. skb = alloc_skb(MAX_PNPIPE_HEADER + 4, priority);
  133. if (!skb)
  134. return -ENOMEM;
  135. skb_set_owner_w(skb, sk);
  136. skb_reserve(skb, MAX_PHONET_HEADER);
  137. ph = (struct pnpipehdr *)skb_put(skb, sizeof(*ph) + 4);
  138. ph->utid = oph->utid;
  139. ph->message_id = PNS_PEP_CTRL_RESP;
  140. ph->pipe_handle = oph->pipe_handle;
  141. ph->data[0] = oph->data[1]; /* CTRL id */
  142. ph->data[1] = oph->data[0]; /* PEP type */
  143. ph->data[2] = code; /* error code, at an usual offset */
  144. ph->data[3] = PAD;
  145. ph->data[4] = PAD;
  146. pn_skb_get_src_sockaddr(oskb, &dst);
  147. return pn_skb_send(sk, skb, &dst);
  148. }
  149. static int pipe_snd_status(struct sock *sk, u8 type, u8 status, gfp_t priority)
  150. {
  151. struct pep_sock *pn = pep_sk(sk);
  152. struct pnpipehdr *ph;
  153. struct sk_buff *skb;
  154. skb = alloc_skb(MAX_PNPIPE_HEADER + 4, priority);
  155. if (!skb)
  156. return -ENOMEM;
  157. skb_set_owner_w(skb, sk);
  158. skb_reserve(skb, MAX_PNPIPE_HEADER + 4);
  159. __skb_push(skb, sizeof(*ph) + 4);
  160. skb_reset_transport_header(skb);
  161. ph = pnp_hdr(skb);
  162. ph->utid = 0;
  163. ph->message_id = PNS_PEP_STATUS_IND;
  164. ph->pipe_handle = pn->pipe_handle;
  165. ph->pep_type = PN_PEP_TYPE_COMMON;
  166. ph->data[1] = type;
  167. ph->data[2] = PAD;
  168. ph->data[3] = PAD;
  169. ph->data[4] = status;
  170. return pn_skb_send(sk, skb, &pipe_srv);
  171. }
  172. /* Send our RX flow control information to the sender.
  173. * Socket must be locked. */
  174. static void pipe_grant_credits(struct sock *sk)
  175. {
  176. struct pep_sock *pn = pep_sk(sk);
  177. BUG_ON(sk->sk_state != TCP_ESTABLISHED);
  178. switch (pn->rx_fc) {
  179. case PN_LEGACY_FLOW_CONTROL: /* TODO */
  180. break;
  181. case PN_ONE_CREDIT_FLOW_CONTROL:
  182. pipe_snd_status(sk, PN_PEP_IND_FLOW_CONTROL,
  183. PEP_IND_READY, GFP_ATOMIC);
  184. pn->rx_credits = 1;
  185. break;
  186. case PN_MULTI_CREDIT_FLOW_CONTROL:
  187. if ((pn->rx_credits + CREDITS_THR) > CREDITS_MAX)
  188. break;
  189. if (pipe_snd_status(sk, PN_PEP_IND_ID_MCFC_GRANT_CREDITS,
  190. CREDITS_MAX - pn->rx_credits,
  191. GFP_ATOMIC) == 0)
  192. pn->rx_credits = CREDITS_MAX;
  193. break;
  194. }
  195. }
  196. static int pipe_rcv_status(struct sock *sk, struct sk_buff *skb)
  197. {
  198. struct pep_sock *pn = pep_sk(sk);
  199. struct pnpipehdr *hdr;
  200. int wake = 0;
  201. if (!pskb_may_pull(skb, sizeof(*hdr) + 4))
  202. return -EINVAL;
  203. hdr = pnp_hdr(skb);
  204. if (hdr->data[0] != PN_PEP_TYPE_COMMON) {
  205. LIMIT_NETDEBUG(KERN_DEBUG"Phonet unknown PEP type: %u\n",
  206. (unsigned)hdr->data[0]);
  207. return -EOPNOTSUPP;
  208. }
  209. switch (hdr->data[1]) {
  210. case PN_PEP_IND_FLOW_CONTROL:
  211. switch (pn->tx_fc) {
  212. case PN_LEGACY_FLOW_CONTROL:
  213. switch (hdr->data[4]) {
  214. case PEP_IND_BUSY:
  215. atomic_set(&pn->tx_credits, 0);
  216. break;
  217. case PEP_IND_READY:
  218. atomic_set(&pn->tx_credits, wake = 1);
  219. break;
  220. }
  221. break;
  222. case PN_ONE_CREDIT_FLOW_CONTROL:
  223. if (hdr->data[4] == PEP_IND_READY)
  224. atomic_set(&pn->tx_credits, wake = 1);
  225. break;
  226. }
  227. break;
  228. case PN_PEP_IND_ID_MCFC_GRANT_CREDITS:
  229. if (pn->tx_fc != PN_MULTI_CREDIT_FLOW_CONTROL)
  230. break;
  231. atomic_add(wake = hdr->data[4], &pn->tx_credits);
  232. break;
  233. default:
  234. LIMIT_NETDEBUG(KERN_DEBUG"Phonet unknown PEP indication: %u\n",
  235. (unsigned)hdr->data[1]);
  236. return -EOPNOTSUPP;
  237. }
  238. if (wake)
  239. sk->sk_write_space(sk);
  240. return 0;
  241. }
  242. static int pipe_rcv_created(struct sock *sk, struct sk_buff *skb)
  243. {
  244. struct pep_sock *pn = pep_sk(sk);
  245. struct pnpipehdr *hdr = pnp_hdr(skb);
  246. u8 n_sb = hdr->data[0];
  247. pn->rx_fc = pn->tx_fc = PN_LEGACY_FLOW_CONTROL;
  248. __skb_pull(skb, sizeof(*hdr));
  249. while (n_sb > 0) {
  250. u8 type, buf[2], len = sizeof(buf);
  251. u8 *data = pep_get_sb(skb, &type, &len, buf);
  252. if (data == NULL)
  253. return -EINVAL;
  254. switch (type) {
  255. case PN_PIPE_SB_NEGOTIATED_FC:
  256. if (len < 2 || (data[0] | data[1]) > 3)
  257. break;
  258. pn->tx_fc = data[0] & 3;
  259. pn->rx_fc = data[1] & 3;
  260. break;
  261. }
  262. n_sb--;
  263. }
  264. return 0;
  265. }
  266. /* Queue an skb to a connected sock.
  267. * Socket lock must be held. */
  268. static int pipe_do_rcv(struct sock *sk, struct sk_buff *skb)
  269. {
  270. struct pep_sock *pn = pep_sk(sk);
  271. struct pnpipehdr *hdr = pnp_hdr(skb);
  272. struct sk_buff_head *queue;
  273. int err = 0;
  274. BUG_ON(sk->sk_state == TCP_CLOSE_WAIT);
  275. switch (hdr->message_id) {
  276. case PNS_PEP_CONNECT_REQ:
  277. pep_reject_conn(sk, skb, PN_PIPE_ERR_PEP_IN_USE);
  278. break;
  279. case PNS_PEP_DISCONNECT_REQ:
  280. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  281. sk->sk_state = TCP_CLOSE_WAIT;
  282. if (!sock_flag(sk, SOCK_DEAD))
  283. sk->sk_state_change(sk);
  284. break;
  285. case PNS_PEP_ENABLE_REQ:
  286. /* Wait for PNS_PIPE_(ENABLED|REDIRECTED)_IND */
  287. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  288. break;
  289. case PNS_PEP_RESET_REQ:
  290. switch (hdr->state_after_reset) {
  291. case PN_PIPE_DISABLE:
  292. pn->init_enable = 0;
  293. break;
  294. case PN_PIPE_ENABLE:
  295. pn->init_enable = 1;
  296. break;
  297. default: /* not allowed to send an error here!? */
  298. err = -EINVAL;
  299. goto out;
  300. }
  301. /* fall through */
  302. case PNS_PEP_DISABLE_REQ:
  303. atomic_set(&pn->tx_credits, 0);
  304. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  305. break;
  306. case PNS_PEP_CTRL_REQ:
  307. if (skb_queue_len(&pn->ctrlreq_queue) >= PNPIPE_CTRLREQ_MAX) {
  308. atomic_inc(&sk->sk_drops);
  309. break;
  310. }
  311. __skb_pull(skb, 4);
  312. queue = &pn->ctrlreq_queue;
  313. goto queue;
  314. case PNS_PIPE_ALIGNED_DATA:
  315. __skb_pull(skb, 1);
  316. /* fall through */
  317. case PNS_PIPE_DATA:
  318. __skb_pull(skb, 3); /* Pipe data header */
  319. if (!pn_flow_safe(pn->rx_fc)) {
  320. err = sock_queue_rcv_skb(sk, skb);
  321. if (!err)
  322. return 0;
  323. break;
  324. }
  325. if (pn->rx_credits == 0) {
  326. atomic_inc(&sk->sk_drops);
  327. err = -ENOBUFS;
  328. break;
  329. }
  330. pn->rx_credits--;
  331. queue = &sk->sk_receive_queue;
  332. goto queue;
  333. case PNS_PEP_STATUS_IND:
  334. pipe_rcv_status(sk, skb);
  335. break;
  336. case PNS_PIPE_REDIRECTED_IND:
  337. err = pipe_rcv_created(sk, skb);
  338. break;
  339. case PNS_PIPE_CREATED_IND:
  340. err = pipe_rcv_created(sk, skb);
  341. if (err)
  342. break;
  343. /* fall through */
  344. case PNS_PIPE_RESET_IND:
  345. if (!pn->init_enable)
  346. break;
  347. /* fall through */
  348. case PNS_PIPE_ENABLED_IND:
  349. if (!pn_flow_safe(pn->tx_fc)) {
  350. atomic_set(&pn->tx_credits, 1);
  351. sk->sk_write_space(sk);
  352. }
  353. if (sk->sk_state == TCP_ESTABLISHED)
  354. break; /* Nothing to do */
  355. sk->sk_state = TCP_ESTABLISHED;
  356. pipe_grant_credits(sk);
  357. break;
  358. case PNS_PIPE_DISABLED_IND:
  359. sk->sk_state = TCP_SYN_RECV;
  360. pn->rx_credits = 0;
  361. break;
  362. default:
  363. LIMIT_NETDEBUG(KERN_DEBUG"Phonet unknown PEP message: %u\n",
  364. hdr->message_id);
  365. err = -EINVAL;
  366. }
  367. out:
  368. kfree_skb(skb);
  369. return err;
  370. queue:
  371. skb->dev = NULL;
  372. skb_set_owner_r(skb, sk);
  373. err = skb->len;
  374. skb_queue_tail(queue, skb);
  375. if (!sock_flag(sk, SOCK_DEAD))
  376. sk->sk_data_ready(sk, err);
  377. return 0;
  378. }
  379. /* Destroy connected sock. */
  380. static void pipe_destruct(struct sock *sk)
  381. {
  382. struct pep_sock *pn = pep_sk(sk);
  383. skb_queue_purge(&sk->sk_receive_queue);
  384. skb_queue_purge(&pn->ctrlreq_queue);
  385. }
  386. static int pep_connreq_rcv(struct sock *sk, struct sk_buff *skb)
  387. {
  388. struct sock *newsk;
  389. struct pep_sock *newpn, *pn = pep_sk(sk);
  390. struct pnpipehdr *hdr;
  391. struct sockaddr_pn dst;
  392. u16 peer_type;
  393. u8 pipe_handle, enabled, n_sb;
  394. u8 aligned = 0;
  395. if (!pskb_pull(skb, sizeof(*hdr) + 4))
  396. return -EINVAL;
  397. hdr = pnp_hdr(skb);
  398. pipe_handle = hdr->pipe_handle;
  399. switch (hdr->state_after_connect) {
  400. case PN_PIPE_DISABLE:
  401. enabled = 0;
  402. break;
  403. case PN_PIPE_ENABLE:
  404. enabled = 1;
  405. break;
  406. default:
  407. pep_reject_conn(sk, skb, PN_PIPE_ERR_INVALID_PARAM);
  408. return -EINVAL;
  409. }
  410. peer_type = hdr->other_pep_type << 8;
  411. if (unlikely(sk->sk_state != TCP_LISTEN) || sk_acceptq_is_full(sk)) {
  412. pep_reject_conn(sk, skb, PN_PIPE_ERR_PEP_IN_USE);
  413. return -ENOBUFS;
  414. }
  415. /* Parse sub-blocks (options) */
  416. n_sb = hdr->data[4];
  417. while (n_sb > 0) {
  418. u8 type, buf[1], len = sizeof(buf);
  419. const u8 *data = pep_get_sb(skb, &type, &len, buf);
  420. if (data == NULL)
  421. return -EINVAL;
  422. switch (type) {
  423. case PN_PIPE_SB_CONNECT_REQ_PEP_SUB_TYPE:
  424. if (len < 1)
  425. return -EINVAL;
  426. peer_type = (peer_type & 0xff00) | data[0];
  427. break;
  428. case PN_PIPE_SB_ALIGNED_DATA:
  429. aligned = data[0] != 0;
  430. break;
  431. }
  432. n_sb--;
  433. }
  434. skb = skb_clone(skb, GFP_ATOMIC);
  435. if (!skb)
  436. return -ENOMEM;
  437. /* Create a new to-be-accepted sock */
  438. newsk = sk_alloc(sock_net(sk), PF_PHONET, GFP_ATOMIC, sk->sk_prot);
  439. if (!newsk) {
  440. kfree_skb(skb);
  441. return -ENOMEM;
  442. }
  443. sock_init_data(NULL, newsk);
  444. newsk->sk_state = TCP_SYN_RECV;
  445. newsk->sk_backlog_rcv = pipe_do_rcv;
  446. newsk->sk_protocol = sk->sk_protocol;
  447. newsk->sk_destruct = pipe_destruct;
  448. newpn = pep_sk(newsk);
  449. pn_skb_get_dst_sockaddr(skb, &dst);
  450. newpn->pn_sk.sobject = pn_sockaddr_get_object(&dst);
  451. newpn->pn_sk.resource = pn->pn_sk.resource;
  452. skb_queue_head_init(&newpn->ctrlreq_queue);
  453. newpn->pipe_handle = pipe_handle;
  454. atomic_set(&newpn->tx_credits, 0);
  455. newpn->peer_type = peer_type;
  456. newpn->rx_credits = 0;
  457. newpn->rx_fc = newpn->tx_fc = PN_LEGACY_FLOW_CONTROL;
  458. newpn->init_enable = enabled;
  459. newpn->aligned = aligned;
  460. BUG_ON(!skb_queue_empty(&newsk->sk_receive_queue));
  461. skb_queue_head(&newsk->sk_receive_queue, skb);
  462. if (!sock_flag(sk, SOCK_DEAD))
  463. sk->sk_data_ready(sk, 0);
  464. sk_acceptq_added(sk);
  465. sk_add_node(newsk, &pn->ackq);
  466. return 0;
  467. }
  468. /* Listening sock must be locked */
  469. static struct sock *pep_find_pipe(const struct hlist_head *hlist,
  470. const struct sockaddr_pn *dst,
  471. u8 pipe_handle)
  472. {
  473. struct hlist_node *node;
  474. struct sock *sknode;
  475. u16 dobj = pn_sockaddr_get_object(dst);
  476. sk_for_each(sknode, node, hlist) {
  477. struct pep_sock *pnnode = pep_sk(sknode);
  478. /* Ports match, but addresses might not: */
  479. if (pnnode->pn_sk.sobject != dobj)
  480. continue;
  481. if (pnnode->pipe_handle != pipe_handle)
  482. continue;
  483. if (sknode->sk_state == TCP_CLOSE_WAIT)
  484. continue;
  485. sock_hold(sknode);
  486. return sknode;
  487. }
  488. return NULL;
  489. }
  490. /*
  491. * Deliver an skb to a listening sock.
  492. * Socket lock must be held.
  493. * We then queue the skb to the right connected sock (if any).
  494. */
  495. static int pep_do_rcv(struct sock *sk, struct sk_buff *skb)
  496. {
  497. struct pep_sock *pn = pep_sk(sk);
  498. struct sock *sknode;
  499. struct pnpipehdr *hdr;
  500. struct sockaddr_pn dst;
  501. int err = NET_RX_SUCCESS;
  502. u8 pipe_handle;
  503. if (!pskb_may_pull(skb, sizeof(*hdr)))
  504. goto drop;
  505. hdr = pnp_hdr(skb);
  506. pipe_handle = hdr->pipe_handle;
  507. if (pipe_handle == PN_PIPE_INVALID_HANDLE)
  508. goto drop;
  509. pn_skb_get_dst_sockaddr(skb, &dst);
  510. /* Look for an existing pipe handle */
  511. sknode = pep_find_pipe(&pn->hlist, &dst, pipe_handle);
  512. if (sknode)
  513. return sk_receive_skb(sknode, skb, 1);
  514. /* Look for a pipe handle pending accept */
  515. sknode = pep_find_pipe(&pn->ackq, &dst, pipe_handle);
  516. if (sknode) {
  517. sock_put(sknode);
  518. if (net_ratelimit())
  519. printk(KERN_WARNING"Phonet unconnected PEP ignored");
  520. err = NET_RX_DROP;
  521. goto drop;
  522. }
  523. switch (hdr->message_id) {
  524. case PNS_PEP_CONNECT_REQ:
  525. err = pep_connreq_rcv(sk, skb);
  526. break;
  527. case PNS_PEP_DISCONNECT_REQ:
  528. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  529. break;
  530. case PNS_PEP_CTRL_REQ:
  531. pep_ctrlreq_error(sk, skb, PN_PIPE_INVALID_HANDLE, GFP_ATOMIC);
  532. break;
  533. case PNS_PEP_RESET_REQ:
  534. case PNS_PEP_ENABLE_REQ:
  535. case PNS_PEP_DISABLE_REQ:
  536. /* invalid handle is not even allowed here! */
  537. default:
  538. err = NET_RX_DROP;
  539. }
  540. drop:
  541. kfree_skb(skb);
  542. return err;
  543. }
  544. /* associated socket ceases to exist */
  545. static void pep_sock_close(struct sock *sk, long timeout)
  546. {
  547. struct pep_sock *pn = pep_sk(sk);
  548. int ifindex = 0;
  549. sock_hold(sk); /* keep a reference after sk_common_release() */
  550. sk_common_release(sk);
  551. lock_sock(sk);
  552. if (sk->sk_state == TCP_LISTEN) {
  553. /* Destroy the listen queue */
  554. struct sock *sknode;
  555. struct hlist_node *p, *n;
  556. sk_for_each_safe(sknode, p, n, &pn->ackq)
  557. sk_del_node_init(sknode);
  558. sk->sk_state = TCP_CLOSE;
  559. }
  560. ifindex = pn->ifindex;
  561. pn->ifindex = 0;
  562. release_sock(sk);
  563. if (ifindex)
  564. gprs_detach(sk);
  565. sock_put(sk);
  566. }
  567. static int pep_wait_connreq(struct sock *sk, int noblock)
  568. {
  569. struct task_struct *tsk = current;
  570. struct pep_sock *pn = pep_sk(sk);
  571. long timeo = sock_rcvtimeo(sk, noblock);
  572. for (;;) {
  573. DEFINE_WAIT(wait);
  574. if (sk->sk_state != TCP_LISTEN)
  575. return -EINVAL;
  576. if (!hlist_empty(&pn->ackq))
  577. break;
  578. if (!timeo)
  579. return -EWOULDBLOCK;
  580. if (signal_pending(tsk))
  581. return sock_intr_errno(timeo);
  582. prepare_to_wait_exclusive(sk_sleep(sk), &wait,
  583. TASK_INTERRUPTIBLE);
  584. release_sock(sk);
  585. timeo = schedule_timeout(timeo);
  586. lock_sock(sk);
  587. finish_wait(sk_sleep(sk), &wait);
  588. }
  589. return 0;
  590. }
  591. static struct sock *pep_sock_accept(struct sock *sk, int flags, int *errp)
  592. {
  593. struct pep_sock *pn = pep_sk(sk);
  594. struct sock *newsk = NULL;
  595. struct sk_buff *oskb;
  596. int err;
  597. lock_sock(sk);
  598. err = pep_wait_connreq(sk, flags & O_NONBLOCK);
  599. if (err)
  600. goto out;
  601. newsk = __sk_head(&pn->ackq);
  602. oskb = skb_dequeue(&newsk->sk_receive_queue);
  603. err = pep_accept_conn(newsk, oskb);
  604. if (err) {
  605. skb_queue_head(&newsk->sk_receive_queue, oskb);
  606. newsk = NULL;
  607. goto out;
  608. }
  609. kfree_skb(oskb);
  610. sock_hold(sk);
  611. pep_sk(newsk)->listener = sk;
  612. sock_hold(newsk);
  613. sk_del_node_init(newsk);
  614. sk_acceptq_removed(sk);
  615. sk_add_node(newsk, &pn->hlist);
  616. __sock_put(newsk);
  617. out:
  618. release_sock(sk);
  619. *errp = err;
  620. return newsk;
  621. }
  622. static int pep_ioctl(struct sock *sk, int cmd, unsigned long arg)
  623. {
  624. struct pep_sock *pn = pep_sk(sk);
  625. int answ;
  626. switch (cmd) {
  627. case SIOCINQ:
  628. if (sk->sk_state == TCP_LISTEN)
  629. return -EINVAL;
  630. lock_sock(sk);
  631. if (sock_flag(sk, SOCK_URGINLINE) &&
  632. !skb_queue_empty(&pn->ctrlreq_queue))
  633. answ = skb_peek(&pn->ctrlreq_queue)->len;
  634. else if (!skb_queue_empty(&sk->sk_receive_queue))
  635. answ = skb_peek(&sk->sk_receive_queue)->len;
  636. else
  637. answ = 0;
  638. release_sock(sk);
  639. return put_user(answ, (int __user *)arg);
  640. }
  641. return -ENOIOCTLCMD;
  642. }
  643. static int pep_init(struct sock *sk)
  644. {
  645. struct pep_sock *pn = pep_sk(sk);
  646. INIT_HLIST_HEAD(&pn->ackq);
  647. INIT_HLIST_HEAD(&pn->hlist);
  648. skb_queue_head_init(&pn->ctrlreq_queue);
  649. pn->pipe_handle = PN_PIPE_INVALID_HANDLE;
  650. return 0;
  651. }
  652. static int pep_setsockopt(struct sock *sk, int level, int optname,
  653. char __user *optval, unsigned int optlen)
  654. {
  655. struct pep_sock *pn = pep_sk(sk);
  656. int val = 0, err = 0;
  657. if (level != SOL_PNPIPE)
  658. return -ENOPROTOOPT;
  659. if (optlen >= sizeof(int)) {
  660. if (get_user(val, (int __user *) optval))
  661. return -EFAULT;
  662. }
  663. lock_sock(sk);
  664. switch (optname) {
  665. case PNPIPE_ENCAP:
  666. if (val && val != PNPIPE_ENCAP_IP) {
  667. err = -EINVAL;
  668. break;
  669. }
  670. if (!pn->ifindex == !val)
  671. break; /* Nothing to do! */
  672. if (!capable(CAP_NET_ADMIN)) {
  673. err = -EPERM;
  674. break;
  675. }
  676. if (val) {
  677. release_sock(sk);
  678. err = gprs_attach(sk);
  679. if (err > 0) {
  680. pn->ifindex = err;
  681. err = 0;
  682. }
  683. } else {
  684. pn->ifindex = 0;
  685. release_sock(sk);
  686. gprs_detach(sk);
  687. err = 0;
  688. }
  689. goto out_norel;
  690. default:
  691. err = -ENOPROTOOPT;
  692. }
  693. release_sock(sk);
  694. out_norel:
  695. return err;
  696. }
  697. static int pep_getsockopt(struct sock *sk, int level, int optname,
  698. char __user *optval, int __user *optlen)
  699. {
  700. struct pep_sock *pn = pep_sk(sk);
  701. int len, val;
  702. if (level != SOL_PNPIPE)
  703. return -ENOPROTOOPT;
  704. if (get_user(len, optlen))
  705. return -EFAULT;
  706. switch (optname) {
  707. case PNPIPE_ENCAP:
  708. val = pn->ifindex ? PNPIPE_ENCAP_IP : PNPIPE_ENCAP_NONE;
  709. break;
  710. case PNPIPE_IFINDEX:
  711. val = pn->ifindex;
  712. break;
  713. default:
  714. return -ENOPROTOOPT;
  715. }
  716. len = min_t(unsigned int, sizeof(int), len);
  717. if (put_user(len, optlen))
  718. return -EFAULT;
  719. if (put_user(val, (int __user *) optval))
  720. return -EFAULT;
  721. return 0;
  722. }
  723. static int pipe_skb_send(struct sock *sk, struct sk_buff *skb)
  724. {
  725. struct pep_sock *pn = pep_sk(sk);
  726. struct pnpipehdr *ph;
  727. if (pn_flow_safe(pn->tx_fc) &&
  728. !atomic_add_unless(&pn->tx_credits, -1, 0)) {
  729. kfree_skb(skb);
  730. return -ENOBUFS;
  731. }
  732. skb_push(skb, 3 + pn->aligned);
  733. skb_reset_transport_header(skb);
  734. ph = pnp_hdr(skb);
  735. ph->utid = 0;
  736. if (pn->aligned) {
  737. ph->message_id = PNS_PIPE_ALIGNED_DATA;
  738. ph->data[0] = 0; /* padding */
  739. } else
  740. ph->message_id = PNS_PIPE_DATA;
  741. ph->pipe_handle = pn->pipe_handle;
  742. return pn_skb_send(sk, skb, &pipe_srv);
  743. }
  744. static int pep_sendmsg(struct kiocb *iocb, struct sock *sk,
  745. struct msghdr *msg, size_t len)
  746. {
  747. struct pep_sock *pn = pep_sk(sk);
  748. struct sk_buff *skb;
  749. long timeo;
  750. int flags = msg->msg_flags;
  751. int err, done;
  752. if ((msg->msg_flags & ~(MSG_DONTWAIT|MSG_EOR|MSG_NOSIGNAL|
  753. MSG_CMSG_COMPAT)) ||
  754. !(msg->msg_flags & MSG_EOR))
  755. return -EOPNOTSUPP;
  756. skb = sock_alloc_send_skb(sk, MAX_PNPIPE_HEADER + len,
  757. flags & MSG_DONTWAIT, &err);
  758. if (!skb)
  759. return -ENOBUFS;
  760. skb_reserve(skb, MAX_PHONET_HEADER + 3);
  761. err = memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len);
  762. if (err < 0)
  763. goto outfree;
  764. lock_sock(sk);
  765. timeo = sock_sndtimeo(sk, flags & MSG_DONTWAIT);
  766. if ((1 << sk->sk_state) & (TCPF_LISTEN|TCPF_CLOSE)) {
  767. err = -ENOTCONN;
  768. goto out;
  769. }
  770. if (sk->sk_state != TCP_ESTABLISHED) {
  771. /* Wait until the pipe gets to enabled state */
  772. disabled:
  773. err = sk_stream_wait_connect(sk, &timeo);
  774. if (err)
  775. goto out;
  776. if (sk->sk_state == TCP_CLOSE_WAIT) {
  777. err = -ECONNRESET;
  778. goto out;
  779. }
  780. }
  781. BUG_ON(sk->sk_state != TCP_ESTABLISHED);
  782. /* Wait until flow control allows TX */
  783. done = atomic_read(&pn->tx_credits);
  784. while (!done) {
  785. DEFINE_WAIT(wait);
  786. if (!timeo) {
  787. err = -EAGAIN;
  788. goto out;
  789. }
  790. if (signal_pending(current)) {
  791. err = sock_intr_errno(timeo);
  792. goto out;
  793. }
  794. prepare_to_wait(sk_sleep(sk), &wait,
  795. TASK_INTERRUPTIBLE);
  796. done = sk_wait_event(sk, &timeo, atomic_read(&pn->tx_credits));
  797. finish_wait(sk_sleep(sk), &wait);
  798. if (sk->sk_state != TCP_ESTABLISHED)
  799. goto disabled;
  800. }
  801. err = pipe_skb_send(sk, skb);
  802. if (err >= 0)
  803. err = len; /* success! */
  804. skb = NULL;
  805. out:
  806. release_sock(sk);
  807. outfree:
  808. kfree_skb(skb);
  809. return err;
  810. }
  811. int pep_writeable(struct sock *sk)
  812. {
  813. struct pep_sock *pn = pep_sk(sk);
  814. return atomic_read(&pn->tx_credits);
  815. }
  816. int pep_write(struct sock *sk, struct sk_buff *skb)
  817. {
  818. struct sk_buff *rskb, *fs;
  819. int flen = 0;
  820. if (pep_sk(sk)->aligned)
  821. return pipe_skb_send(sk, skb);
  822. rskb = alloc_skb(MAX_PNPIPE_HEADER, GFP_ATOMIC);
  823. if (!rskb) {
  824. kfree_skb(skb);
  825. return -ENOMEM;
  826. }
  827. skb_shinfo(rskb)->frag_list = skb;
  828. rskb->len += skb->len;
  829. rskb->data_len += rskb->len;
  830. rskb->truesize += rskb->len;
  831. /* Avoid nested fragments */
  832. skb_walk_frags(skb, fs)
  833. flen += fs->len;
  834. skb->next = skb_shinfo(skb)->frag_list;
  835. skb_frag_list_init(skb);
  836. skb->len -= flen;
  837. skb->data_len -= flen;
  838. skb->truesize -= flen;
  839. skb_reserve(rskb, MAX_PHONET_HEADER + 3);
  840. return pipe_skb_send(sk, rskb);
  841. }
  842. struct sk_buff *pep_read(struct sock *sk)
  843. {
  844. struct sk_buff *skb = skb_dequeue(&sk->sk_receive_queue);
  845. if (sk->sk_state == TCP_ESTABLISHED)
  846. pipe_grant_credits(sk);
  847. return skb;
  848. }
  849. static int pep_recvmsg(struct kiocb *iocb, struct sock *sk,
  850. struct msghdr *msg, size_t len, int noblock,
  851. int flags, int *addr_len)
  852. {
  853. struct sk_buff *skb;
  854. int err;
  855. if (flags & ~(MSG_OOB|MSG_PEEK|MSG_TRUNC|MSG_DONTWAIT|MSG_WAITALL|
  856. MSG_NOSIGNAL|MSG_CMSG_COMPAT))
  857. return -EOPNOTSUPP;
  858. if (unlikely(1 << sk->sk_state & (TCPF_LISTEN | TCPF_CLOSE)))
  859. return -ENOTCONN;
  860. if ((flags & MSG_OOB) || sock_flag(sk, SOCK_URGINLINE)) {
  861. /* Dequeue and acknowledge control request */
  862. struct pep_sock *pn = pep_sk(sk);
  863. if (flags & MSG_PEEK)
  864. return -EOPNOTSUPP;
  865. skb = skb_dequeue(&pn->ctrlreq_queue);
  866. if (skb) {
  867. pep_ctrlreq_error(sk, skb, PN_PIPE_NO_ERROR,
  868. GFP_KERNEL);
  869. msg->msg_flags |= MSG_OOB;
  870. goto copy;
  871. }
  872. if (flags & MSG_OOB)
  873. return -EINVAL;
  874. }
  875. skb = skb_recv_datagram(sk, flags, noblock, &err);
  876. lock_sock(sk);
  877. if (skb == NULL) {
  878. if (err == -ENOTCONN && sk->sk_state == TCP_CLOSE_WAIT)
  879. err = -ECONNRESET;
  880. release_sock(sk);
  881. return err;
  882. }
  883. if (sk->sk_state == TCP_ESTABLISHED)
  884. pipe_grant_credits(sk);
  885. release_sock(sk);
  886. copy:
  887. msg->msg_flags |= MSG_EOR;
  888. if (skb->len > len)
  889. msg->msg_flags |= MSG_TRUNC;
  890. else
  891. len = skb->len;
  892. err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, len);
  893. if (!err)
  894. err = (flags & MSG_TRUNC) ? skb->len : len;
  895. skb_free_datagram(sk, skb);
  896. return err;
  897. }
  898. static void pep_sock_unhash(struct sock *sk)
  899. {
  900. struct pep_sock *pn = pep_sk(sk);
  901. struct sock *skparent = NULL;
  902. lock_sock(sk);
  903. if ((1 << sk->sk_state) & ~(TCPF_CLOSE|TCPF_LISTEN)) {
  904. skparent = pn->listener;
  905. release_sock(sk);
  906. pn = pep_sk(skparent);
  907. lock_sock(skparent);
  908. sk_del_node_init(sk);
  909. sk = skparent;
  910. }
  911. /* Unhash a listening sock only when it is closed
  912. * and all of its active connected pipes are closed. */
  913. if (hlist_empty(&pn->hlist))
  914. pn_sock_unhash(&pn->pn_sk.sk);
  915. release_sock(sk);
  916. if (skparent)
  917. sock_put(skparent);
  918. }
  919. static struct proto pep_proto = {
  920. .close = pep_sock_close,
  921. .accept = pep_sock_accept,
  922. .ioctl = pep_ioctl,
  923. .init = pep_init,
  924. .setsockopt = pep_setsockopt,
  925. .getsockopt = pep_getsockopt,
  926. .sendmsg = pep_sendmsg,
  927. .recvmsg = pep_recvmsg,
  928. .backlog_rcv = pep_do_rcv,
  929. .hash = pn_sock_hash,
  930. .unhash = pep_sock_unhash,
  931. .get_port = pn_sock_get_port,
  932. .obj_size = sizeof(struct pep_sock),
  933. .owner = THIS_MODULE,
  934. .name = "PNPIPE",
  935. };
  936. static struct phonet_protocol pep_pn_proto = {
  937. .ops = &phonet_stream_ops,
  938. .prot = &pep_proto,
  939. .sock_type = SOCK_SEQPACKET,
  940. };
  941. static int __init pep_register(void)
  942. {
  943. return phonet_proto_register(PN_PROTO_PIPE, &pep_pn_proto);
  944. }
  945. static void __exit pep_unregister(void)
  946. {
  947. phonet_proto_unregister(PN_PROTO_PIPE, &pep_pn_proto);
  948. }
  949. module_init(pep_register);
  950. module_exit(pep_unregister);
  951. MODULE_AUTHOR("Remi Denis-Courmont, Nokia");
  952. MODULE_DESCRIPTION("Phonet pipe protocol");
  953. MODULE_LICENSE("GPL");
  954. MODULE_ALIAS_NET_PF_PROTO(PF_PHONET, PN_PROTO_PIPE);