pep.c 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104
  1. /*
  2. * File: pep.c
  3. *
  4. * Phonet pipe protocol end point socket
  5. *
  6. * Copyright (C) 2008 Nokia Corporation.
  7. *
  8. * Author: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
  9. *
  10. * This program is free software; you can redistribute it and/or
  11. * modify it under the terms of the GNU General Public License
  12. * version 2 as published by the Free Software Foundation.
  13. *
  14. * This program is distributed in the hope that it will be useful, but
  15. * WITHOUT ANY WARRANTY; without even the implied warranty of
  16. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  17. * General Public License for more details.
  18. *
  19. * You should have received a copy of the GNU General Public License
  20. * along with this program; if not, write to the Free Software
  21. * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
  22. * 02110-1301 USA
  23. */
  24. #include <linux/kernel.h>
  25. #include <linux/slab.h>
  26. #include <linux/socket.h>
  27. #include <net/sock.h>
  28. #include <net/tcp_states.h>
  29. #include <asm/ioctls.h>
  30. #include <linux/phonet.h>
  31. #include <net/phonet/phonet.h>
  32. #include <net/phonet/pep.h>
  33. #include <net/phonet/gprs.h>
  34. /* sk_state values:
  35. * TCP_CLOSE sock not in use yet
  36. * TCP_CLOSE_WAIT disconnected pipe
  37. * TCP_LISTEN listening pipe endpoint
  38. * TCP_SYN_RECV connected pipe in disabled state
  39. * TCP_ESTABLISHED connected pipe in enabled state
  40. *
  41. * pep_sock locking:
  42. * - sk_state, ackq, hlist: sock lock needed
  43. * - listener: read only
  44. * - pipe_handle: read only
  45. */
  46. #define CREDITS_MAX 10
  47. #define CREDITS_THR 7
  48. static const struct sockaddr_pn pipe_srv = {
  49. .spn_family = AF_PHONET,
  50. .spn_resource = 0xD9, /* pipe service */
  51. };
  52. #define pep_sb_size(s) (((s) + 5) & ~3) /* 2-bytes head, 32-bits aligned */
  53. /* Get the next TLV sub-block. */
  54. static unsigned char *pep_get_sb(struct sk_buff *skb, u8 *ptype, u8 *plen,
  55. void *buf)
  56. {
  57. void *data = NULL;
  58. struct {
  59. u8 sb_type;
  60. u8 sb_len;
  61. } *ph, h;
  62. int buflen = *plen;
  63. ph = skb_header_pointer(skb, 0, 2, &h);
  64. if (ph == NULL || ph->sb_len < 2 || !pskb_may_pull(skb, ph->sb_len))
  65. return NULL;
  66. ph->sb_len -= 2;
  67. *ptype = ph->sb_type;
  68. *plen = ph->sb_len;
  69. if (buflen > ph->sb_len)
  70. buflen = ph->sb_len;
  71. data = skb_header_pointer(skb, 2, buflen, buf);
  72. __skb_pull(skb, 2 + ph->sb_len);
  73. return data;
  74. }
  75. static int pep_reply(struct sock *sk, struct sk_buff *oskb,
  76. u8 code, const void *data, int len, gfp_t priority)
  77. {
  78. const struct pnpipehdr *oph = pnp_hdr(oskb);
  79. struct pnpipehdr *ph;
  80. struct sk_buff *skb;
  81. skb = alloc_skb(MAX_PNPIPE_HEADER + len, priority);
  82. if (!skb)
  83. return -ENOMEM;
  84. skb_set_owner_w(skb, sk);
  85. skb_reserve(skb, MAX_PNPIPE_HEADER);
  86. __skb_put(skb, len);
  87. skb_copy_to_linear_data(skb, data, len);
  88. __skb_push(skb, sizeof(*ph));
  89. skb_reset_transport_header(skb);
  90. ph = pnp_hdr(skb);
  91. ph->utid = oph->utid;
  92. ph->message_id = oph->message_id + 1; /* REQ -> RESP */
  93. ph->pipe_handle = oph->pipe_handle;
  94. ph->error_code = code;
  95. return pn_skb_send(sk, skb, &pipe_srv);
  96. }
  97. #define PAD 0x00
  98. static int pep_accept_conn(struct sock *sk, struct sk_buff *skb)
  99. {
  100. static const u8 data[20] = {
  101. PAD, PAD, PAD, 2 /* sub-blocks */,
  102. PN_PIPE_SB_REQUIRED_FC_TX, pep_sb_size(5), 3, PAD,
  103. PN_MULTI_CREDIT_FLOW_CONTROL,
  104. PN_ONE_CREDIT_FLOW_CONTROL,
  105. PN_LEGACY_FLOW_CONTROL,
  106. PAD,
  107. PN_PIPE_SB_PREFERRED_FC_RX, pep_sb_size(5), 3, PAD,
  108. PN_MULTI_CREDIT_FLOW_CONTROL,
  109. PN_ONE_CREDIT_FLOW_CONTROL,
  110. PN_LEGACY_FLOW_CONTROL,
  111. PAD,
  112. };
  113. might_sleep();
  114. return pep_reply(sk, skb, PN_PIPE_NO_ERROR, data, sizeof(data),
  115. GFP_KERNEL);
  116. }
  117. static int pep_reject_conn(struct sock *sk, struct sk_buff *skb, u8 code)
  118. {
  119. static const u8 data[4] = { PAD, PAD, PAD, 0 /* sub-blocks */ };
  120. WARN_ON(code == PN_PIPE_NO_ERROR);
  121. return pep_reply(sk, skb, code, data, sizeof(data), GFP_ATOMIC);
  122. }
  123. /* Control requests are not sent by the pipe service and have a specific
  124. * message format. */
  125. static int pep_ctrlreq_error(struct sock *sk, struct sk_buff *oskb, u8 code,
  126. gfp_t priority)
  127. {
  128. const struct pnpipehdr *oph = pnp_hdr(oskb);
  129. struct sk_buff *skb;
  130. struct pnpipehdr *ph;
  131. struct sockaddr_pn dst;
  132. skb = alloc_skb(MAX_PNPIPE_HEADER + 4, priority);
  133. if (!skb)
  134. return -ENOMEM;
  135. skb_set_owner_w(skb, sk);
  136. skb_reserve(skb, MAX_PHONET_HEADER);
  137. ph = (struct pnpipehdr *)skb_put(skb, sizeof(*ph) + 4);
  138. ph->utid = oph->utid;
  139. ph->message_id = PNS_PEP_CTRL_RESP;
  140. ph->pipe_handle = oph->pipe_handle;
  141. ph->data[0] = oph->data[1]; /* CTRL id */
  142. ph->data[1] = oph->data[0]; /* PEP type */
  143. ph->data[2] = code; /* error code, at an usual offset */
  144. ph->data[3] = PAD;
  145. ph->data[4] = PAD;
  146. pn_skb_get_src_sockaddr(oskb, &dst);
  147. return pn_skb_send(sk, skb, &dst);
  148. }
  149. static int pipe_snd_status(struct sock *sk, u8 type, u8 status, gfp_t priority)
  150. {
  151. struct pep_sock *pn = pep_sk(sk);
  152. struct pnpipehdr *ph;
  153. struct sk_buff *skb;
  154. skb = alloc_skb(MAX_PNPIPE_HEADER + 4, priority);
  155. if (!skb)
  156. return -ENOMEM;
  157. skb_set_owner_w(skb, sk);
  158. skb_reserve(skb, MAX_PNPIPE_HEADER + 4);
  159. __skb_push(skb, sizeof(*ph) + 4);
  160. skb_reset_transport_header(skb);
  161. ph = pnp_hdr(skb);
  162. ph->utid = 0;
  163. ph->message_id = PNS_PEP_STATUS_IND;
  164. ph->pipe_handle = pn->pipe_handle;
  165. ph->pep_type = PN_PEP_TYPE_COMMON;
  166. ph->data[1] = type;
  167. ph->data[2] = PAD;
  168. ph->data[3] = PAD;
  169. ph->data[4] = status;
  170. return pn_skb_send(sk, skb, &pipe_srv);
  171. }
  172. /* Send our RX flow control information to the sender.
  173. * Socket must be locked. */
  174. static void pipe_grant_credits(struct sock *sk)
  175. {
  176. struct pep_sock *pn = pep_sk(sk);
  177. BUG_ON(sk->sk_state != TCP_ESTABLISHED);
  178. switch (pn->rx_fc) {
  179. case PN_LEGACY_FLOW_CONTROL: /* TODO */
  180. break;
  181. case PN_ONE_CREDIT_FLOW_CONTROL:
  182. pipe_snd_status(sk, PN_PEP_IND_FLOW_CONTROL,
  183. PEP_IND_READY, GFP_ATOMIC);
  184. pn->rx_credits = 1;
  185. break;
  186. case PN_MULTI_CREDIT_FLOW_CONTROL:
  187. if ((pn->rx_credits + CREDITS_THR) > CREDITS_MAX)
  188. break;
  189. if (pipe_snd_status(sk, PN_PEP_IND_ID_MCFC_GRANT_CREDITS,
  190. CREDITS_MAX - pn->rx_credits,
  191. GFP_ATOMIC) == 0)
  192. pn->rx_credits = CREDITS_MAX;
  193. break;
  194. }
  195. }
  196. static int pipe_rcv_status(struct sock *sk, struct sk_buff *skb)
  197. {
  198. struct pep_sock *pn = pep_sk(sk);
  199. struct pnpipehdr *hdr = pnp_hdr(skb);
  200. int wake = 0;
  201. if (!pskb_may_pull(skb, sizeof(*hdr) + 4))
  202. return -EINVAL;
  203. if (hdr->data[0] != PN_PEP_TYPE_COMMON) {
  204. LIMIT_NETDEBUG(KERN_DEBUG"Phonet unknown PEP type: %u\n",
  205. (unsigned)hdr->data[0]);
  206. return -EOPNOTSUPP;
  207. }
  208. switch (hdr->data[1]) {
  209. case PN_PEP_IND_FLOW_CONTROL:
  210. switch (pn->tx_fc) {
  211. case PN_LEGACY_FLOW_CONTROL:
  212. switch (hdr->data[4]) {
  213. case PEP_IND_BUSY:
  214. atomic_set(&pn->tx_credits, 0);
  215. break;
  216. case PEP_IND_READY:
  217. atomic_set(&pn->tx_credits, wake = 1);
  218. break;
  219. }
  220. break;
  221. case PN_ONE_CREDIT_FLOW_CONTROL:
  222. if (hdr->data[4] == PEP_IND_READY)
  223. atomic_set(&pn->tx_credits, wake = 1);
  224. break;
  225. }
  226. break;
  227. case PN_PEP_IND_ID_MCFC_GRANT_CREDITS:
  228. if (pn->tx_fc != PN_MULTI_CREDIT_FLOW_CONTROL)
  229. break;
  230. atomic_add(wake = hdr->data[4], &pn->tx_credits);
  231. break;
  232. default:
  233. LIMIT_NETDEBUG(KERN_DEBUG"Phonet unknown PEP indication: %u\n",
  234. (unsigned)hdr->data[1]);
  235. return -EOPNOTSUPP;
  236. }
  237. if (wake)
  238. sk->sk_write_space(sk);
  239. return 0;
  240. }
  241. static int pipe_rcv_created(struct sock *sk, struct sk_buff *skb)
  242. {
  243. struct pep_sock *pn = pep_sk(sk);
  244. struct pnpipehdr *hdr = pnp_hdr(skb);
  245. u8 n_sb = hdr->data[0];
  246. pn->rx_fc = pn->tx_fc = PN_LEGACY_FLOW_CONTROL;
  247. __skb_pull(skb, sizeof(*hdr));
  248. while (n_sb > 0) {
  249. u8 type, buf[2], len = sizeof(buf);
  250. u8 *data = pep_get_sb(skb, &type, &len, buf);
  251. if (data == NULL)
  252. return -EINVAL;
  253. switch (type) {
  254. case PN_PIPE_SB_NEGOTIATED_FC:
  255. if (len < 2 || (data[0] | data[1]) > 3)
  256. break;
  257. pn->tx_fc = data[0] & 3;
  258. pn->rx_fc = data[1] & 3;
  259. break;
  260. }
  261. n_sb--;
  262. }
  263. return 0;
  264. }
  265. /* Queue an skb to a connected sock.
  266. * Socket lock must be held. */
  267. static int pipe_do_rcv(struct sock *sk, struct sk_buff *skb)
  268. {
  269. struct pep_sock *pn = pep_sk(sk);
  270. struct pnpipehdr *hdr = pnp_hdr(skb);
  271. struct sk_buff_head *queue;
  272. int err = 0;
  273. BUG_ON(sk->sk_state == TCP_CLOSE_WAIT);
  274. switch (hdr->message_id) {
  275. case PNS_PEP_CONNECT_REQ:
  276. pep_reject_conn(sk, skb, PN_PIPE_ERR_PEP_IN_USE);
  277. break;
  278. case PNS_PEP_DISCONNECT_REQ:
  279. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  280. sk->sk_state = TCP_CLOSE_WAIT;
  281. if (!sock_flag(sk, SOCK_DEAD))
  282. sk->sk_state_change(sk);
  283. break;
  284. case PNS_PEP_ENABLE_REQ:
  285. /* Wait for PNS_PIPE_(ENABLED|REDIRECTED)_IND */
  286. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  287. break;
  288. case PNS_PEP_RESET_REQ:
  289. switch (hdr->state_after_reset) {
  290. case PN_PIPE_DISABLE:
  291. pn->init_enable = 0;
  292. break;
  293. case PN_PIPE_ENABLE:
  294. pn->init_enable = 1;
  295. break;
  296. default: /* not allowed to send an error here!? */
  297. err = -EINVAL;
  298. goto out;
  299. }
  300. /* fall through */
  301. case PNS_PEP_DISABLE_REQ:
  302. atomic_set(&pn->tx_credits, 0);
  303. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  304. break;
  305. case PNS_PEP_CTRL_REQ:
  306. if (skb_queue_len(&pn->ctrlreq_queue) >= PNPIPE_CTRLREQ_MAX) {
  307. atomic_inc(&sk->sk_drops);
  308. break;
  309. }
  310. __skb_pull(skb, 4);
  311. queue = &pn->ctrlreq_queue;
  312. goto queue;
  313. case PNS_PIPE_ALIGNED_DATA:
  314. __skb_pull(skb, 1);
  315. /* fall through */
  316. case PNS_PIPE_DATA:
  317. __skb_pull(skb, 3); /* Pipe data header */
  318. if (!pn_flow_safe(pn->rx_fc)) {
  319. err = sock_queue_rcv_skb(sk, skb);
  320. if (!err)
  321. return 0;
  322. break;
  323. }
  324. if (pn->rx_credits == 0) {
  325. atomic_inc(&sk->sk_drops);
  326. err = -ENOBUFS;
  327. break;
  328. }
  329. pn->rx_credits--;
  330. queue = &sk->sk_receive_queue;
  331. goto queue;
  332. case PNS_PEP_STATUS_IND:
  333. pipe_rcv_status(sk, skb);
  334. break;
  335. case PNS_PIPE_REDIRECTED_IND:
  336. err = pipe_rcv_created(sk, skb);
  337. break;
  338. case PNS_PIPE_CREATED_IND:
  339. err = pipe_rcv_created(sk, skb);
  340. if (err)
  341. break;
  342. /* fall through */
  343. case PNS_PIPE_RESET_IND:
  344. if (!pn->init_enable)
  345. break;
  346. /* fall through */
  347. case PNS_PIPE_ENABLED_IND:
  348. if (!pn_flow_safe(pn->tx_fc)) {
  349. atomic_set(&pn->tx_credits, 1);
  350. sk->sk_write_space(sk);
  351. }
  352. if (sk->sk_state == TCP_ESTABLISHED)
  353. break; /* Nothing to do */
  354. sk->sk_state = TCP_ESTABLISHED;
  355. pipe_grant_credits(sk);
  356. break;
  357. case PNS_PIPE_DISABLED_IND:
  358. sk->sk_state = TCP_SYN_RECV;
  359. pn->rx_credits = 0;
  360. break;
  361. default:
  362. LIMIT_NETDEBUG(KERN_DEBUG"Phonet unknown PEP message: %u\n",
  363. hdr->message_id);
  364. err = -EINVAL;
  365. }
  366. out:
  367. kfree_skb(skb);
  368. return err;
  369. queue:
  370. skb->dev = NULL;
  371. skb_set_owner_r(skb, sk);
  372. err = skb->len;
  373. skb_queue_tail(queue, skb);
  374. if (!sock_flag(sk, SOCK_DEAD))
  375. sk->sk_data_ready(sk, err);
  376. return 0;
  377. }
  378. /* Destroy connected sock. */
  379. static void pipe_destruct(struct sock *sk)
  380. {
  381. struct pep_sock *pn = pep_sk(sk);
  382. skb_queue_purge(&sk->sk_receive_queue);
  383. skb_queue_purge(&pn->ctrlreq_queue);
  384. }
  385. static int pep_connreq_rcv(struct sock *sk, struct sk_buff *skb)
  386. {
  387. struct sock *newsk;
  388. struct pep_sock *newpn, *pn = pep_sk(sk);
  389. struct pnpipehdr *hdr;
  390. struct sockaddr_pn dst;
  391. u16 peer_type;
  392. u8 pipe_handle, enabled, n_sb;
  393. u8 aligned = 0;
  394. if (!pskb_pull(skb, sizeof(*hdr) + 4))
  395. return -EINVAL;
  396. hdr = pnp_hdr(skb);
  397. pipe_handle = hdr->pipe_handle;
  398. switch (hdr->state_after_connect) {
  399. case PN_PIPE_DISABLE:
  400. enabled = 0;
  401. break;
  402. case PN_PIPE_ENABLE:
  403. enabled = 1;
  404. break;
  405. default:
  406. pep_reject_conn(sk, skb, PN_PIPE_ERR_INVALID_PARAM);
  407. return -EINVAL;
  408. }
  409. peer_type = hdr->other_pep_type << 8;
  410. if (unlikely(sk->sk_state != TCP_LISTEN) || sk_acceptq_is_full(sk)) {
  411. pep_reject_conn(sk, skb, PN_PIPE_ERR_PEP_IN_USE);
  412. return -ENOBUFS;
  413. }
  414. /* Parse sub-blocks (options) */
  415. n_sb = hdr->data[4];
  416. while (n_sb > 0) {
  417. u8 type, buf[1], len = sizeof(buf);
  418. const u8 *data = pep_get_sb(skb, &type, &len, buf);
  419. if (data == NULL)
  420. return -EINVAL;
  421. switch (type) {
  422. case PN_PIPE_SB_CONNECT_REQ_PEP_SUB_TYPE:
  423. if (len < 1)
  424. return -EINVAL;
  425. peer_type = (peer_type & 0xff00) | data[0];
  426. break;
  427. case PN_PIPE_SB_ALIGNED_DATA:
  428. aligned = data[0] != 0;
  429. break;
  430. }
  431. n_sb--;
  432. }
  433. skb = skb_clone(skb, GFP_ATOMIC);
  434. if (!skb)
  435. return -ENOMEM;
  436. /* Create a new to-be-accepted sock */
  437. newsk = sk_alloc(sock_net(sk), PF_PHONET, GFP_ATOMIC, sk->sk_prot);
  438. if (!newsk) {
  439. kfree_skb(skb);
  440. return -ENOMEM;
  441. }
  442. sock_init_data(NULL, newsk);
  443. newsk->sk_state = TCP_SYN_RECV;
  444. newsk->sk_backlog_rcv = pipe_do_rcv;
  445. newsk->sk_protocol = sk->sk_protocol;
  446. newsk->sk_destruct = pipe_destruct;
  447. newpn = pep_sk(newsk);
  448. pn_skb_get_dst_sockaddr(skb, &dst);
  449. newpn->pn_sk.sobject = pn_sockaddr_get_object(&dst);
  450. newpn->pn_sk.resource = pn->pn_sk.resource;
  451. skb_queue_head_init(&newpn->ctrlreq_queue);
  452. newpn->pipe_handle = pipe_handle;
  453. atomic_set(&newpn->tx_credits, 0);
  454. newpn->peer_type = peer_type;
  455. newpn->rx_credits = 0;
  456. newpn->rx_fc = newpn->tx_fc = PN_LEGACY_FLOW_CONTROL;
  457. newpn->init_enable = enabled;
  458. newpn->aligned = aligned;
  459. BUG_ON(!skb_queue_empty(&newsk->sk_receive_queue));
  460. skb_queue_head(&newsk->sk_receive_queue, skb);
  461. if (!sock_flag(sk, SOCK_DEAD))
  462. sk->sk_data_ready(sk, 0);
  463. sk_acceptq_added(sk);
  464. sk_add_node(newsk, &pn->ackq);
  465. return 0;
  466. }
  467. /* Listening sock must be locked */
  468. static struct sock *pep_find_pipe(const struct hlist_head *hlist,
  469. const struct sockaddr_pn *dst,
  470. u8 pipe_handle)
  471. {
  472. struct hlist_node *node;
  473. struct sock *sknode;
  474. u16 dobj = pn_sockaddr_get_object(dst);
  475. sk_for_each(sknode, node, hlist) {
  476. struct pep_sock *pnnode = pep_sk(sknode);
  477. /* Ports match, but addresses might not: */
  478. if (pnnode->pn_sk.sobject != dobj)
  479. continue;
  480. if (pnnode->pipe_handle != pipe_handle)
  481. continue;
  482. if (sknode->sk_state == TCP_CLOSE_WAIT)
  483. continue;
  484. sock_hold(sknode);
  485. return sknode;
  486. }
  487. return NULL;
  488. }
  489. /*
  490. * Deliver an skb to a listening sock.
  491. * Socket lock must be held.
  492. * We then queue the skb to the right connected sock (if any).
  493. */
  494. static int pep_do_rcv(struct sock *sk, struct sk_buff *skb)
  495. {
  496. struct pep_sock *pn = pep_sk(sk);
  497. struct sock *sknode;
  498. struct pnpipehdr *hdr;
  499. struct sockaddr_pn dst;
  500. int err = NET_RX_SUCCESS;
  501. u8 pipe_handle;
  502. if (!pskb_may_pull(skb, sizeof(*hdr)))
  503. goto drop;
  504. hdr = pnp_hdr(skb);
  505. pipe_handle = hdr->pipe_handle;
  506. if (pipe_handle == PN_PIPE_INVALID_HANDLE)
  507. goto drop;
  508. pn_skb_get_dst_sockaddr(skb, &dst);
  509. /* Look for an existing pipe handle */
  510. sknode = pep_find_pipe(&pn->hlist, &dst, pipe_handle);
  511. if (sknode)
  512. return sk_receive_skb(sknode, skb, 1);
  513. /* Look for a pipe handle pending accept */
  514. sknode = pep_find_pipe(&pn->ackq, &dst, pipe_handle);
  515. if (sknode) {
  516. sock_put(sknode);
  517. if (net_ratelimit())
  518. printk(KERN_WARNING"Phonet unconnected PEP ignored");
  519. err = NET_RX_DROP;
  520. goto drop;
  521. }
  522. switch (hdr->message_id) {
  523. case PNS_PEP_CONNECT_REQ:
  524. err = pep_connreq_rcv(sk, skb);
  525. break;
  526. case PNS_PEP_DISCONNECT_REQ:
  527. pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
  528. break;
  529. case PNS_PEP_CTRL_REQ:
  530. pep_ctrlreq_error(sk, skb, PN_PIPE_INVALID_HANDLE, GFP_ATOMIC);
  531. break;
  532. case PNS_PEP_RESET_REQ:
  533. case PNS_PEP_ENABLE_REQ:
  534. case PNS_PEP_DISABLE_REQ:
  535. /* invalid handle is not even allowed here! */
  536. default:
  537. err = NET_RX_DROP;
  538. }
  539. drop:
  540. kfree_skb(skb);
  541. return err;
  542. }
  543. /* associated socket ceases to exist */
  544. static void pep_sock_close(struct sock *sk, long timeout)
  545. {
  546. struct pep_sock *pn = pep_sk(sk);
  547. int ifindex = 0;
  548. sock_hold(sk); /* keep a reference after sk_common_release() */
  549. sk_common_release(sk);
  550. lock_sock(sk);
  551. if (sk->sk_state == TCP_LISTEN) {
  552. /* Destroy the listen queue */
  553. struct sock *sknode;
  554. struct hlist_node *p, *n;
  555. sk_for_each_safe(sknode, p, n, &pn->ackq)
  556. sk_del_node_init(sknode);
  557. sk->sk_state = TCP_CLOSE;
  558. }
  559. ifindex = pn->ifindex;
  560. pn->ifindex = 0;
  561. release_sock(sk);
  562. if (ifindex)
  563. gprs_detach(sk);
  564. sock_put(sk);
  565. }
  566. static int pep_wait_connreq(struct sock *sk, int noblock)
  567. {
  568. struct task_struct *tsk = current;
  569. struct pep_sock *pn = pep_sk(sk);
  570. long timeo = sock_rcvtimeo(sk, noblock);
  571. for (;;) {
  572. DEFINE_WAIT(wait);
  573. if (sk->sk_state != TCP_LISTEN)
  574. return -EINVAL;
  575. if (!hlist_empty(&pn->ackq))
  576. break;
  577. if (!timeo)
  578. return -EWOULDBLOCK;
  579. if (signal_pending(tsk))
  580. return sock_intr_errno(timeo);
  581. prepare_to_wait_exclusive(sk_sleep(sk), &wait,
  582. TASK_INTERRUPTIBLE);
  583. release_sock(sk);
  584. timeo = schedule_timeout(timeo);
  585. lock_sock(sk);
  586. finish_wait(sk_sleep(sk), &wait);
  587. }
  588. return 0;
  589. }
  590. static struct sock *pep_sock_accept(struct sock *sk, int flags, int *errp)
  591. {
  592. struct pep_sock *pn = pep_sk(sk);
  593. struct sock *newsk = NULL;
  594. struct sk_buff *oskb;
  595. int err;
  596. lock_sock(sk);
  597. err = pep_wait_connreq(sk, flags & O_NONBLOCK);
  598. if (err)
  599. goto out;
  600. newsk = __sk_head(&pn->ackq);
  601. oskb = skb_dequeue(&newsk->sk_receive_queue);
  602. err = pep_accept_conn(newsk, oskb);
  603. if (err) {
  604. skb_queue_head(&newsk->sk_receive_queue, oskb);
  605. newsk = NULL;
  606. goto out;
  607. }
  608. sock_hold(sk);
  609. pep_sk(newsk)->listener = sk;
  610. sock_hold(newsk);
  611. sk_del_node_init(newsk);
  612. sk_acceptq_removed(sk);
  613. sk_add_node(newsk, &pn->hlist);
  614. __sock_put(newsk);
  615. out:
  616. release_sock(sk);
  617. *errp = err;
  618. return newsk;
  619. }
  620. static int pep_ioctl(struct sock *sk, int cmd, unsigned long arg)
  621. {
  622. struct pep_sock *pn = pep_sk(sk);
  623. int answ;
  624. switch (cmd) {
  625. case SIOCINQ:
  626. if (sk->sk_state == TCP_LISTEN)
  627. return -EINVAL;
  628. lock_sock(sk);
  629. if (sock_flag(sk, SOCK_URGINLINE) &&
  630. !skb_queue_empty(&pn->ctrlreq_queue))
  631. answ = skb_peek(&pn->ctrlreq_queue)->len;
  632. else if (!skb_queue_empty(&sk->sk_receive_queue))
  633. answ = skb_peek(&sk->sk_receive_queue)->len;
  634. else
  635. answ = 0;
  636. release_sock(sk);
  637. return put_user(answ, (int __user *)arg);
  638. }
  639. return -ENOIOCTLCMD;
  640. }
  641. static int pep_init(struct sock *sk)
  642. {
  643. struct pep_sock *pn = pep_sk(sk);
  644. INIT_HLIST_HEAD(&pn->ackq);
  645. INIT_HLIST_HEAD(&pn->hlist);
  646. skb_queue_head_init(&pn->ctrlreq_queue);
  647. pn->pipe_handle = PN_PIPE_INVALID_HANDLE;
  648. return 0;
  649. }
  650. static int pep_setsockopt(struct sock *sk, int level, int optname,
  651. char __user *optval, unsigned int optlen)
  652. {
  653. struct pep_sock *pn = pep_sk(sk);
  654. int val = 0, err = 0;
  655. if (level != SOL_PNPIPE)
  656. return -ENOPROTOOPT;
  657. if (optlen >= sizeof(int)) {
  658. if (get_user(val, (int __user *) optval))
  659. return -EFAULT;
  660. }
  661. lock_sock(sk);
  662. switch (optname) {
  663. case PNPIPE_ENCAP:
  664. if (val && val != PNPIPE_ENCAP_IP) {
  665. err = -EINVAL;
  666. break;
  667. }
  668. if (!pn->ifindex == !val)
  669. break; /* Nothing to do! */
  670. if (!capable(CAP_NET_ADMIN)) {
  671. err = -EPERM;
  672. break;
  673. }
  674. if (val) {
  675. release_sock(sk);
  676. err = gprs_attach(sk);
  677. if (err > 0) {
  678. pn->ifindex = err;
  679. err = 0;
  680. }
  681. } else {
  682. pn->ifindex = 0;
  683. release_sock(sk);
  684. gprs_detach(sk);
  685. err = 0;
  686. }
  687. goto out_norel;
  688. default:
  689. err = -ENOPROTOOPT;
  690. }
  691. release_sock(sk);
  692. out_norel:
  693. return err;
  694. }
  695. static int pep_getsockopt(struct sock *sk, int level, int optname,
  696. char __user *optval, int __user *optlen)
  697. {
  698. struct pep_sock *pn = pep_sk(sk);
  699. int len, val;
  700. if (level != SOL_PNPIPE)
  701. return -ENOPROTOOPT;
  702. if (get_user(len, optlen))
  703. return -EFAULT;
  704. switch (optname) {
  705. case PNPIPE_ENCAP:
  706. val = pn->ifindex ? PNPIPE_ENCAP_IP : PNPIPE_ENCAP_NONE;
  707. break;
  708. case PNPIPE_IFINDEX:
  709. val = pn->ifindex;
  710. break;
  711. default:
  712. return -ENOPROTOOPT;
  713. }
  714. len = min_t(unsigned int, sizeof(int), len);
  715. if (put_user(len, optlen))
  716. return -EFAULT;
  717. if (put_user(val, (int __user *) optval))
  718. return -EFAULT;
  719. return 0;
  720. }
  721. static int pipe_skb_send(struct sock *sk, struct sk_buff *skb)
  722. {
  723. struct pep_sock *pn = pep_sk(sk);
  724. struct pnpipehdr *ph;
  725. if (pn_flow_safe(pn->tx_fc) &&
  726. !atomic_add_unless(&pn->tx_credits, -1, 0)) {
  727. kfree_skb(skb);
  728. return -ENOBUFS;
  729. }
  730. skb_push(skb, 3 + pn->aligned);
  731. skb_reset_transport_header(skb);
  732. ph = pnp_hdr(skb);
  733. ph->utid = 0;
  734. if (pn->aligned) {
  735. ph->message_id = PNS_PIPE_ALIGNED_DATA;
  736. ph->data[0] = 0; /* padding */
  737. } else
  738. ph->message_id = PNS_PIPE_DATA;
  739. ph->pipe_handle = pn->pipe_handle;
  740. return pn_skb_send(sk, skb, &pipe_srv);
  741. }
  742. static int pep_sendmsg(struct kiocb *iocb, struct sock *sk,
  743. struct msghdr *msg, size_t len)
  744. {
  745. struct pep_sock *pn = pep_sk(sk);
  746. struct sk_buff *skb;
  747. long timeo;
  748. int flags = msg->msg_flags;
  749. int err, done;
  750. if ((msg->msg_flags & ~(MSG_DONTWAIT|MSG_EOR|MSG_NOSIGNAL|
  751. MSG_CMSG_COMPAT)) ||
  752. !(msg->msg_flags & MSG_EOR))
  753. return -EOPNOTSUPP;
  754. skb = sock_alloc_send_skb(sk, MAX_PNPIPE_HEADER + len,
  755. flags & MSG_DONTWAIT, &err);
  756. if (!skb)
  757. return -ENOBUFS;
  758. skb_reserve(skb, MAX_PHONET_HEADER + 3);
  759. err = memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len);
  760. if (err < 0)
  761. goto outfree;
  762. lock_sock(sk);
  763. timeo = sock_sndtimeo(sk, flags & MSG_DONTWAIT);
  764. if ((1 << sk->sk_state) & (TCPF_LISTEN|TCPF_CLOSE)) {
  765. err = -ENOTCONN;
  766. goto out;
  767. }
  768. if (sk->sk_state != TCP_ESTABLISHED) {
  769. /* Wait until the pipe gets to enabled state */
  770. disabled:
  771. err = sk_stream_wait_connect(sk, &timeo);
  772. if (err)
  773. goto out;
  774. if (sk->sk_state == TCP_CLOSE_WAIT) {
  775. err = -ECONNRESET;
  776. goto out;
  777. }
  778. }
  779. BUG_ON(sk->sk_state != TCP_ESTABLISHED);
  780. /* Wait until flow control allows TX */
  781. done = atomic_read(&pn->tx_credits);
  782. while (!done) {
  783. DEFINE_WAIT(wait);
  784. if (!timeo) {
  785. err = -EAGAIN;
  786. goto out;
  787. }
  788. if (signal_pending(current)) {
  789. err = sock_intr_errno(timeo);
  790. goto out;
  791. }
  792. prepare_to_wait(sk_sleep(sk), &wait,
  793. TASK_INTERRUPTIBLE);
  794. done = sk_wait_event(sk, &timeo, atomic_read(&pn->tx_credits));
  795. finish_wait(sk_sleep(sk), &wait);
  796. if (sk->sk_state != TCP_ESTABLISHED)
  797. goto disabled;
  798. }
  799. err = pipe_skb_send(sk, skb);
  800. if (err >= 0)
  801. err = len; /* success! */
  802. skb = NULL;
  803. out:
  804. release_sock(sk);
  805. outfree:
  806. kfree_skb(skb);
  807. return err;
  808. }
  809. int pep_writeable(struct sock *sk)
  810. {
  811. struct pep_sock *pn = pep_sk(sk);
  812. return atomic_read(&pn->tx_credits);
  813. }
  814. int pep_write(struct sock *sk, struct sk_buff *skb)
  815. {
  816. struct sk_buff *rskb, *fs;
  817. int flen = 0;
  818. if (pep_sk(sk)->aligned)
  819. return pipe_skb_send(sk, skb);
  820. rskb = alloc_skb(MAX_PNPIPE_HEADER, GFP_ATOMIC);
  821. if (!rskb) {
  822. kfree_skb(skb);
  823. return -ENOMEM;
  824. }
  825. skb_shinfo(rskb)->frag_list = skb;
  826. rskb->len += skb->len;
  827. rskb->data_len += rskb->len;
  828. rskb->truesize += rskb->len;
  829. /* Avoid nested fragments */
  830. skb_walk_frags(skb, fs)
  831. flen += fs->len;
  832. skb->next = skb_shinfo(skb)->frag_list;
  833. skb_frag_list_init(skb);
  834. skb->len -= flen;
  835. skb->data_len -= flen;
  836. skb->truesize -= flen;
  837. skb_reserve(rskb, MAX_PHONET_HEADER + 3);
  838. return pipe_skb_send(sk, rskb);
  839. }
  840. struct sk_buff *pep_read(struct sock *sk)
  841. {
  842. struct sk_buff *skb = skb_dequeue(&sk->sk_receive_queue);
  843. if (sk->sk_state == TCP_ESTABLISHED)
  844. pipe_grant_credits(sk);
  845. return skb;
  846. }
  847. static int pep_recvmsg(struct kiocb *iocb, struct sock *sk,
  848. struct msghdr *msg, size_t len, int noblock,
  849. int flags, int *addr_len)
  850. {
  851. struct sk_buff *skb;
  852. int err;
  853. if (flags & ~(MSG_OOB|MSG_PEEK|MSG_TRUNC|MSG_DONTWAIT|MSG_WAITALL|
  854. MSG_NOSIGNAL|MSG_CMSG_COMPAT))
  855. return -EOPNOTSUPP;
  856. if (unlikely(1 << sk->sk_state & (TCPF_LISTEN | TCPF_CLOSE)))
  857. return -ENOTCONN;
  858. if ((flags & MSG_OOB) || sock_flag(sk, SOCK_URGINLINE)) {
  859. /* Dequeue and acknowledge control request */
  860. struct pep_sock *pn = pep_sk(sk);
  861. if (flags & MSG_PEEK)
  862. return -EOPNOTSUPP;
  863. skb = skb_dequeue(&pn->ctrlreq_queue);
  864. if (skb) {
  865. pep_ctrlreq_error(sk, skb, PN_PIPE_NO_ERROR,
  866. GFP_KERNEL);
  867. msg->msg_flags |= MSG_OOB;
  868. goto copy;
  869. }
  870. if (flags & MSG_OOB)
  871. return -EINVAL;
  872. }
  873. skb = skb_recv_datagram(sk, flags, noblock, &err);
  874. lock_sock(sk);
  875. if (skb == NULL) {
  876. if (err == -ENOTCONN && sk->sk_state == TCP_CLOSE_WAIT)
  877. err = -ECONNRESET;
  878. release_sock(sk);
  879. return err;
  880. }
  881. if (sk->sk_state == TCP_ESTABLISHED)
  882. pipe_grant_credits(sk);
  883. release_sock(sk);
  884. copy:
  885. msg->msg_flags |= MSG_EOR;
  886. if (skb->len > len)
  887. msg->msg_flags |= MSG_TRUNC;
  888. else
  889. len = skb->len;
  890. err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, len);
  891. if (!err)
  892. err = (flags & MSG_TRUNC) ? skb->len : len;
  893. skb_free_datagram(sk, skb);
  894. return err;
  895. }
  896. static void pep_sock_unhash(struct sock *sk)
  897. {
  898. struct pep_sock *pn = pep_sk(sk);
  899. struct sock *skparent = NULL;
  900. lock_sock(sk);
  901. if ((1 << sk->sk_state) & ~(TCPF_CLOSE|TCPF_LISTEN)) {
  902. skparent = pn->listener;
  903. sk_del_node_init(sk);
  904. release_sock(sk);
  905. sk = skparent;
  906. pn = pep_sk(skparent);
  907. lock_sock(sk);
  908. }
  909. /* Unhash a listening sock only when it is closed
  910. * and all of its active connected pipes are closed. */
  911. if (hlist_empty(&pn->hlist))
  912. pn_sock_unhash(&pn->pn_sk.sk);
  913. release_sock(sk);
  914. if (skparent)
  915. sock_put(skparent);
  916. }
  917. static struct proto pep_proto = {
  918. .close = pep_sock_close,
  919. .accept = pep_sock_accept,
  920. .ioctl = pep_ioctl,
  921. .init = pep_init,
  922. .setsockopt = pep_setsockopt,
  923. .getsockopt = pep_getsockopt,
  924. .sendmsg = pep_sendmsg,
  925. .recvmsg = pep_recvmsg,
  926. .backlog_rcv = pep_do_rcv,
  927. .hash = pn_sock_hash,
  928. .unhash = pep_sock_unhash,
  929. .get_port = pn_sock_get_port,
  930. .obj_size = sizeof(struct pep_sock),
  931. .owner = THIS_MODULE,
  932. .name = "PNPIPE",
  933. };
  934. static struct phonet_protocol pep_pn_proto = {
  935. .ops = &phonet_stream_ops,
  936. .prot = &pep_proto,
  937. .sock_type = SOCK_SEQPACKET,
  938. };
  939. static int __init pep_register(void)
  940. {
  941. return phonet_proto_register(PN_PROTO_PIPE, &pep_pn_proto);
  942. }
  943. static void __exit pep_unregister(void)
  944. {
  945. phonet_proto_unregister(PN_PROTO_PIPE, &pep_pn_proto);
  946. }
  947. module_init(pep_register);
  948. module_exit(pep_unregister);
  949. MODULE_AUTHOR("Remi Denis-Courmont, Nokia");
  950. MODULE_DESCRIPTION("Phonet pipe protocol");
  951. MODULE_LICENSE("GPL");
  952. MODULE_ALIAS_NET_PF_PROTO(PF_PHONET, PN_PROTO_PIPE);