xref: /openbmc/linux/net/vmw_vsock/virtio_transport_common.c (revision aad29a73199b7fbccfbabea3f1ee627ad1924f52)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * common code for virtio vsock
4  *
5  * Copyright (C) 2013-2015 Red Hat, Inc.
6  * Author: Asias He <asias@redhat.com>
7  *         Stefan Hajnoczi <stefanha@redhat.com>
8  */
9 #include <linux/spinlock.h>
10 #include <linux/module.h>
11 #include <linux/sched/signal.h>
12 #include <linux/ctype.h>
13 #include <linux/list.h>
14 #include <linux/virtio_vsock.h>
15 #include <uapi/linux/vsockmon.h>
16 
17 #include <net/sock.h>
18 #include <net/af_vsock.h>
19 
20 #define CREATE_TRACE_POINTS
21 #include <trace/events/vsock_virtio_transport_common.h>
22 
23 /* How long to wait for graceful shutdown of a connection */
24 #define VSOCK_CLOSE_TIMEOUT (8 * HZ)
25 
26 /* Threshold for detecting small packets to copy */
27 #define GOOD_COPY_LEN  128
28 
29 static void virtio_transport_cancel_close_work(struct vsock_sock *vsk,
30 					       bool cancel_timeout);
31 
32 static const struct virtio_transport *
virtio_transport_get_ops(struct vsock_sock * vsk)33 virtio_transport_get_ops(struct vsock_sock *vsk)
34 {
35 	const struct vsock_transport *t = vsock_core_get_transport(vsk);
36 
37 	if (WARN_ON(!t))
38 		return NULL;
39 
40 	return container_of(t, struct virtio_transport, transport);
41 }
42 
43 /* Returns a new packet on success, otherwise returns NULL.
44  *
45  * If NULL is returned, errp is set to a negative errno.
46  */
47 static struct sk_buff *
virtio_transport_alloc_skb(struct virtio_vsock_pkt_info * info,size_t len,u32 src_cid,u32 src_port,u32 dst_cid,u32 dst_port)48 virtio_transport_alloc_skb(struct virtio_vsock_pkt_info *info,
49 			   size_t len,
50 			   u32 src_cid,
51 			   u32 src_port,
52 			   u32 dst_cid,
53 			   u32 dst_port)
54 {
55 	const size_t skb_len = VIRTIO_VSOCK_SKB_HEADROOM + len;
56 	struct virtio_vsock_hdr *hdr;
57 	struct sk_buff *skb;
58 	void *payload;
59 	int err;
60 
61 	skb = virtio_vsock_alloc_skb(skb_len, GFP_KERNEL);
62 	if (!skb)
63 		return NULL;
64 
65 	hdr = virtio_vsock_hdr(skb);
66 	hdr->type	= cpu_to_le16(info->type);
67 	hdr->op		= cpu_to_le16(info->op);
68 	hdr->src_cid	= cpu_to_le64(src_cid);
69 	hdr->dst_cid	= cpu_to_le64(dst_cid);
70 	hdr->src_port	= cpu_to_le32(src_port);
71 	hdr->dst_port	= cpu_to_le32(dst_port);
72 	hdr->flags	= cpu_to_le32(info->flags);
73 	hdr->len	= cpu_to_le32(len);
74 	hdr->buf_alloc	= cpu_to_le32(0);
75 	hdr->fwd_cnt	= cpu_to_le32(0);
76 
77 	if (info->msg && len > 0) {
78 		payload = skb_put(skb, len);
79 		err = memcpy_from_msg(payload, info->msg, len);
80 		if (err)
81 			goto out;
82 
83 		if (msg_data_left(info->msg) == 0 &&
84 		    info->type == VIRTIO_VSOCK_TYPE_SEQPACKET) {
85 			hdr->flags |= cpu_to_le32(VIRTIO_VSOCK_SEQ_EOM);
86 
87 			if (info->msg->msg_flags & MSG_EOR)
88 				hdr->flags |= cpu_to_le32(VIRTIO_VSOCK_SEQ_EOR);
89 		}
90 	}
91 
92 	if (info->reply)
93 		virtio_vsock_skb_set_reply(skb);
94 
95 	trace_virtio_transport_alloc_pkt(src_cid, src_port,
96 					 dst_cid, dst_port,
97 					 len,
98 					 info->type,
99 					 info->op,
100 					 info->flags);
101 
102 	if (info->vsk && !skb_set_owner_sk_safe(skb, sk_vsock(info->vsk))) {
103 		WARN_ONCE(1, "failed to allocate skb on vsock socket with sk_refcnt == 0\n");
104 		goto out;
105 	}
106 
107 	return skb;
108 
109 out:
110 	kfree_skb(skb);
111 	return NULL;
112 }
113 
114 /* Packet capture */
virtio_transport_build_skb(void * opaque)115 static struct sk_buff *virtio_transport_build_skb(void *opaque)
116 {
117 	struct virtio_vsock_hdr *pkt_hdr;
118 	struct sk_buff *pkt = opaque;
119 	struct af_vsockmon_hdr *hdr;
120 	struct sk_buff *skb;
121 	size_t payload_len;
122 	void *payload_buf;
123 
124 	/* A packet could be split to fit the RX buffer, so we can retrieve
125 	 * the payload length from the header and the buffer pointer taking
126 	 * care of the offset in the original packet.
127 	 */
128 	pkt_hdr = virtio_vsock_hdr(pkt);
129 	payload_len = pkt->len;
130 	payload_buf = pkt->data;
131 
132 	skb = alloc_skb(sizeof(*hdr) + sizeof(*pkt_hdr) + payload_len,
133 			GFP_ATOMIC);
134 	if (!skb)
135 		return NULL;
136 
137 	hdr = skb_put(skb, sizeof(*hdr));
138 
139 	/* pkt->hdr is little-endian so no need to byteswap here */
140 	hdr->src_cid = pkt_hdr->src_cid;
141 	hdr->src_port = pkt_hdr->src_port;
142 	hdr->dst_cid = pkt_hdr->dst_cid;
143 	hdr->dst_port = pkt_hdr->dst_port;
144 
145 	hdr->transport = cpu_to_le16(AF_VSOCK_TRANSPORT_VIRTIO);
146 	hdr->len = cpu_to_le16(sizeof(*pkt_hdr));
147 	memset(hdr->reserved, 0, sizeof(hdr->reserved));
148 
149 	switch (le16_to_cpu(pkt_hdr->op)) {
150 	case VIRTIO_VSOCK_OP_REQUEST:
151 	case VIRTIO_VSOCK_OP_RESPONSE:
152 		hdr->op = cpu_to_le16(AF_VSOCK_OP_CONNECT);
153 		break;
154 	case VIRTIO_VSOCK_OP_RST:
155 	case VIRTIO_VSOCK_OP_SHUTDOWN:
156 		hdr->op = cpu_to_le16(AF_VSOCK_OP_DISCONNECT);
157 		break;
158 	case VIRTIO_VSOCK_OP_RW:
159 		hdr->op = cpu_to_le16(AF_VSOCK_OP_PAYLOAD);
160 		break;
161 	case VIRTIO_VSOCK_OP_CREDIT_UPDATE:
162 	case VIRTIO_VSOCK_OP_CREDIT_REQUEST:
163 		hdr->op = cpu_to_le16(AF_VSOCK_OP_CONTROL);
164 		break;
165 	default:
166 		hdr->op = cpu_to_le16(AF_VSOCK_OP_UNKNOWN);
167 		break;
168 	}
169 
170 	skb_put_data(skb, pkt_hdr, sizeof(*pkt_hdr));
171 
172 	if (payload_len) {
173 		skb_put_data(skb, payload_buf, payload_len);
174 	}
175 
176 	return skb;
177 }
178 
virtio_transport_deliver_tap_pkt(struct sk_buff * skb)179 void virtio_transport_deliver_tap_pkt(struct sk_buff *skb)
180 {
181 	if (virtio_vsock_skb_tap_delivered(skb))
182 		return;
183 
184 	vsock_deliver_tap(virtio_transport_build_skb, skb);
185 	virtio_vsock_skb_set_tap_delivered(skb);
186 }
187 EXPORT_SYMBOL_GPL(virtio_transport_deliver_tap_pkt);
188 
virtio_transport_get_type(struct sock * sk)189 static u16 virtio_transport_get_type(struct sock *sk)
190 {
191 	if (sk->sk_type == SOCK_STREAM)
192 		return VIRTIO_VSOCK_TYPE_STREAM;
193 	else
194 		return VIRTIO_VSOCK_TYPE_SEQPACKET;
195 }
196 
197 /* This function can only be used on connecting/connected sockets,
198  * since a socket assigned to a transport is required.
199  *
200  * Do not use on listener sockets!
201  */
virtio_transport_send_pkt_info(struct vsock_sock * vsk,struct virtio_vsock_pkt_info * info)202 static int virtio_transport_send_pkt_info(struct vsock_sock *vsk,
203 					  struct virtio_vsock_pkt_info *info)
204 {
205 	u32 src_cid, src_port, dst_cid, dst_port;
206 	const struct virtio_transport *t_ops;
207 	struct virtio_vsock_sock *vvs;
208 	u32 pkt_len = info->pkt_len;
209 	u32 rest_len;
210 	int ret;
211 
212 	info->type = virtio_transport_get_type(sk_vsock(vsk));
213 
214 	t_ops = virtio_transport_get_ops(vsk);
215 	if (unlikely(!t_ops))
216 		return -EFAULT;
217 
218 	src_cid = t_ops->transport.get_local_cid();
219 	src_port = vsk->local_addr.svm_port;
220 	if (!info->remote_cid) {
221 		dst_cid	= vsk->remote_addr.svm_cid;
222 		dst_port = vsk->remote_addr.svm_port;
223 	} else {
224 		dst_cid = info->remote_cid;
225 		dst_port = info->remote_port;
226 	}
227 
228 	vvs = vsk->trans;
229 
230 	/* virtio_transport_get_credit might return less than pkt_len credit */
231 	pkt_len = virtio_transport_get_credit(vvs, pkt_len);
232 
233 	/* Do not send zero length OP_RW pkt */
234 	if (pkt_len == 0 && info->op == VIRTIO_VSOCK_OP_RW)
235 		return pkt_len;
236 
237 	rest_len = pkt_len;
238 
239 	do {
240 		struct sk_buff *skb;
241 		size_t skb_len;
242 
243 		skb_len = min_t(u32, VIRTIO_VSOCK_MAX_PKT_BUF_SIZE, rest_len);
244 
245 		skb = virtio_transport_alloc_skb(info, skb_len,
246 						 src_cid, src_port,
247 						 dst_cid, dst_port);
248 		if (!skb) {
249 			ret = -ENOMEM;
250 			break;
251 		}
252 
253 		virtio_transport_inc_tx_pkt(vvs, skb);
254 
255 		ret = t_ops->send_pkt(skb);
256 		if (ret < 0)
257 			break;
258 
259 		/* Both virtio and vhost 'send_pkt()' returns 'skb_len',
260 		 * but for reliability use 'ret' instead of 'skb_len'.
261 		 * Also if partial send happens (e.g. 'ret' != 'skb_len')
262 		 * somehow, we break this loop, but account such returned
263 		 * value in 'virtio_transport_put_credit()'.
264 		 */
265 		rest_len -= ret;
266 
267 		if (WARN_ONCE(ret != skb_len,
268 			      "'send_pkt()' returns %i, but %zu expected\n",
269 			      ret, skb_len))
270 			break;
271 	} while (rest_len);
272 
273 	virtio_transport_put_credit(vvs, rest_len);
274 
275 	/* Return number of bytes, if any data has been sent. */
276 	if (rest_len != pkt_len)
277 		ret = pkt_len - rest_len;
278 
279 	return ret;
280 }
281 
virtio_transport_inc_rx_pkt(struct virtio_vsock_sock * vvs,u32 len)282 static bool virtio_transport_inc_rx_pkt(struct virtio_vsock_sock *vvs,
283 					u32 len)
284 {
285 	if (vvs->rx_bytes + len > vvs->buf_alloc)
286 		return false;
287 
288 	vvs->rx_bytes += len;
289 	return true;
290 }
291 
virtio_transport_dec_rx_pkt(struct virtio_vsock_sock * vvs,u32 len)292 static void virtio_transport_dec_rx_pkt(struct virtio_vsock_sock *vvs,
293 					u32 len)
294 {
295 	vvs->rx_bytes -= len;
296 	vvs->fwd_cnt += len;
297 }
298 
virtio_transport_inc_tx_pkt(struct virtio_vsock_sock * vvs,struct sk_buff * skb)299 void virtio_transport_inc_tx_pkt(struct virtio_vsock_sock *vvs, struct sk_buff *skb)
300 {
301 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
302 
303 	spin_lock_bh(&vvs->rx_lock);
304 	vvs->last_fwd_cnt = vvs->fwd_cnt;
305 	hdr->fwd_cnt = cpu_to_le32(vvs->fwd_cnt);
306 	hdr->buf_alloc = cpu_to_le32(vvs->buf_alloc);
307 	spin_unlock_bh(&vvs->rx_lock);
308 }
309 EXPORT_SYMBOL_GPL(virtio_transport_inc_tx_pkt);
310 
virtio_transport_get_credit(struct virtio_vsock_sock * vvs,u32 credit)311 u32 virtio_transport_get_credit(struct virtio_vsock_sock *vvs, u32 credit)
312 {
313 	u32 ret;
314 
315 	if (!credit)
316 		return 0;
317 
318 	spin_lock_bh(&vvs->tx_lock);
319 	ret = vvs->peer_buf_alloc - (vvs->tx_cnt - vvs->peer_fwd_cnt);
320 	if (ret > credit)
321 		ret = credit;
322 	vvs->tx_cnt += ret;
323 	spin_unlock_bh(&vvs->tx_lock);
324 
325 	return ret;
326 }
327 EXPORT_SYMBOL_GPL(virtio_transport_get_credit);
328 
virtio_transport_put_credit(struct virtio_vsock_sock * vvs,u32 credit)329 void virtio_transport_put_credit(struct virtio_vsock_sock *vvs, u32 credit)
330 {
331 	if (!credit)
332 		return;
333 
334 	spin_lock_bh(&vvs->tx_lock);
335 	vvs->tx_cnt -= credit;
336 	spin_unlock_bh(&vvs->tx_lock);
337 }
338 EXPORT_SYMBOL_GPL(virtio_transport_put_credit);
339 
virtio_transport_send_credit_update(struct vsock_sock * vsk)340 static int virtio_transport_send_credit_update(struct vsock_sock *vsk)
341 {
342 	struct virtio_vsock_pkt_info info = {
343 		.op = VIRTIO_VSOCK_OP_CREDIT_UPDATE,
344 		.vsk = vsk,
345 	};
346 
347 	return virtio_transport_send_pkt_info(vsk, &info);
348 }
349 
350 static ssize_t
virtio_transport_stream_do_peek(struct vsock_sock * vsk,struct msghdr * msg,size_t len)351 virtio_transport_stream_do_peek(struct vsock_sock *vsk,
352 				struct msghdr *msg,
353 				size_t len)
354 {
355 	struct virtio_vsock_sock *vvs = vsk->trans;
356 	struct sk_buff *skb;
357 	size_t total = 0;
358 	int err;
359 
360 	spin_lock_bh(&vvs->rx_lock);
361 
362 	skb_queue_walk(&vvs->rx_queue, skb) {
363 		size_t bytes;
364 
365 		bytes = len - total;
366 		if (bytes > skb->len)
367 			bytes = skb->len;
368 
369 		spin_unlock_bh(&vvs->rx_lock);
370 
371 		/* sk_lock is held by caller so no one else can dequeue.
372 		 * Unlock rx_lock since memcpy_to_msg() may sleep.
373 		 */
374 		err = memcpy_to_msg(msg, skb->data, bytes);
375 		if (err)
376 			goto out;
377 
378 		total += bytes;
379 
380 		spin_lock_bh(&vvs->rx_lock);
381 
382 		if (total == len)
383 			break;
384 	}
385 
386 	spin_unlock_bh(&vvs->rx_lock);
387 
388 	return total;
389 
390 out:
391 	if (total)
392 		err = total;
393 	return err;
394 }
395 
396 static ssize_t
virtio_transport_stream_do_dequeue(struct vsock_sock * vsk,struct msghdr * msg,size_t len)397 virtio_transport_stream_do_dequeue(struct vsock_sock *vsk,
398 				   struct msghdr *msg,
399 				   size_t len)
400 {
401 	struct virtio_vsock_sock *vvs = vsk->trans;
402 	size_t bytes, total = 0;
403 	struct sk_buff *skb;
404 	u32 fwd_cnt_delta;
405 	bool low_rx_bytes;
406 	int err = -EFAULT;
407 	u32 free_space;
408 
409 	spin_lock_bh(&vvs->rx_lock);
410 
411 	if (WARN_ONCE(skb_queue_empty(&vvs->rx_queue) && vvs->rx_bytes,
412 		      "rx_queue is empty, but rx_bytes is non-zero\n")) {
413 		spin_unlock_bh(&vvs->rx_lock);
414 		return err;
415 	}
416 
417 	while (total < len && !skb_queue_empty(&vvs->rx_queue)) {
418 		skb = skb_peek(&vvs->rx_queue);
419 
420 		bytes = len - total;
421 		if (bytes > skb->len)
422 			bytes = skb->len;
423 
424 		/* sk_lock is held by caller so no one else can dequeue.
425 		 * Unlock rx_lock since memcpy_to_msg() may sleep.
426 		 */
427 		spin_unlock_bh(&vvs->rx_lock);
428 
429 		err = memcpy_to_msg(msg, skb->data, bytes);
430 		if (err)
431 			goto out;
432 
433 		spin_lock_bh(&vvs->rx_lock);
434 
435 		total += bytes;
436 		skb_pull(skb, bytes);
437 
438 		if (skb->len == 0) {
439 			u32 pkt_len = le32_to_cpu(virtio_vsock_hdr(skb)->len);
440 
441 			virtio_transport_dec_rx_pkt(vvs, pkt_len);
442 			__skb_unlink(skb, &vvs->rx_queue);
443 			consume_skb(skb);
444 		}
445 	}
446 
447 	fwd_cnt_delta = vvs->fwd_cnt - vvs->last_fwd_cnt;
448 	free_space = vvs->buf_alloc - fwd_cnt_delta;
449 	low_rx_bytes = (vvs->rx_bytes <
450 			sock_rcvlowat(sk_vsock(vsk), 0, INT_MAX));
451 
452 	spin_unlock_bh(&vvs->rx_lock);
453 
454 	/* To reduce the number of credit update messages,
455 	 * don't update credits as long as lots of space is available.
456 	 * Note: the limit chosen here is arbitrary. Setting the limit
457 	 * too high causes extra messages. Too low causes transmitter
458 	 * stalls. As stalls are in theory more expensive than extra
459 	 * messages, we set the limit to a high value. TODO: experiment
460 	 * with different values. Also send credit update message when
461 	 * number of bytes in rx queue is not enough to wake up reader.
462 	 */
463 	if (fwd_cnt_delta &&
464 	    (free_space < VIRTIO_VSOCK_MAX_PKT_BUF_SIZE || low_rx_bytes))
465 		virtio_transport_send_credit_update(vsk);
466 
467 	return total;
468 
469 out:
470 	if (total)
471 		err = total;
472 	return err;
473 }
474 
475 static ssize_t
virtio_transport_seqpacket_do_peek(struct vsock_sock * vsk,struct msghdr * msg)476 virtio_transport_seqpacket_do_peek(struct vsock_sock *vsk,
477 				   struct msghdr *msg)
478 {
479 	struct virtio_vsock_sock *vvs = vsk->trans;
480 	struct sk_buff *skb;
481 	size_t total, len;
482 
483 	spin_lock_bh(&vvs->rx_lock);
484 
485 	if (!vvs->msg_count) {
486 		spin_unlock_bh(&vvs->rx_lock);
487 		return 0;
488 	}
489 
490 	total = 0;
491 	len = msg_data_left(msg);
492 
493 	skb_queue_walk(&vvs->rx_queue, skb) {
494 		struct virtio_vsock_hdr *hdr;
495 
496 		if (total < len) {
497 			size_t bytes;
498 			int err;
499 
500 			bytes = len - total;
501 			if (bytes > skb->len)
502 				bytes = skb->len;
503 
504 			spin_unlock_bh(&vvs->rx_lock);
505 
506 			/* sk_lock is held by caller so no one else can dequeue.
507 			 * Unlock rx_lock since memcpy_to_msg() may sleep.
508 			 */
509 			err = memcpy_to_msg(msg, skb->data, bytes);
510 			if (err)
511 				return err;
512 
513 			spin_lock_bh(&vvs->rx_lock);
514 		}
515 
516 		total += skb->len;
517 		hdr = virtio_vsock_hdr(skb);
518 
519 		if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SEQ_EOM) {
520 			if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SEQ_EOR)
521 				msg->msg_flags |= MSG_EOR;
522 
523 			break;
524 		}
525 	}
526 
527 	spin_unlock_bh(&vvs->rx_lock);
528 
529 	return total;
530 }
531 
virtio_transport_seqpacket_do_dequeue(struct vsock_sock * vsk,struct msghdr * msg,int flags)532 static int virtio_transport_seqpacket_do_dequeue(struct vsock_sock *vsk,
533 						 struct msghdr *msg,
534 						 int flags)
535 {
536 	struct virtio_vsock_sock *vvs = vsk->trans;
537 	int dequeued_len = 0;
538 	size_t user_buf_len = msg_data_left(msg);
539 	bool msg_ready = false;
540 	struct sk_buff *skb;
541 
542 	spin_lock_bh(&vvs->rx_lock);
543 
544 	if (vvs->msg_count == 0) {
545 		spin_unlock_bh(&vvs->rx_lock);
546 		return 0;
547 	}
548 
549 	while (!msg_ready) {
550 		struct virtio_vsock_hdr *hdr;
551 		size_t pkt_len;
552 
553 		skb = __skb_dequeue(&vvs->rx_queue);
554 		if (!skb)
555 			break;
556 		hdr = virtio_vsock_hdr(skb);
557 		pkt_len = (size_t)le32_to_cpu(hdr->len);
558 
559 		if (dequeued_len >= 0) {
560 			size_t bytes_to_copy;
561 
562 			bytes_to_copy = min(user_buf_len, pkt_len);
563 
564 			if (bytes_to_copy) {
565 				int err;
566 
567 				/* sk_lock is held by caller so no one else can dequeue.
568 				 * Unlock rx_lock since memcpy_to_msg() may sleep.
569 				 */
570 				spin_unlock_bh(&vvs->rx_lock);
571 
572 				err = memcpy_to_msg(msg, skb->data, bytes_to_copy);
573 				if (err) {
574 					/* Copy of message failed. Rest of
575 					 * fragments will be freed without copy.
576 					 */
577 					dequeued_len = err;
578 				} else {
579 					user_buf_len -= bytes_to_copy;
580 				}
581 
582 				spin_lock_bh(&vvs->rx_lock);
583 			}
584 
585 			if (dequeued_len >= 0)
586 				dequeued_len += pkt_len;
587 		}
588 
589 		if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SEQ_EOM) {
590 			msg_ready = true;
591 			vvs->msg_count--;
592 
593 			if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SEQ_EOR)
594 				msg->msg_flags |= MSG_EOR;
595 		}
596 
597 		virtio_transport_dec_rx_pkt(vvs, pkt_len);
598 		kfree_skb(skb);
599 	}
600 
601 	spin_unlock_bh(&vvs->rx_lock);
602 
603 	virtio_transport_send_credit_update(vsk);
604 
605 	return dequeued_len;
606 }
607 
608 ssize_t
virtio_transport_stream_dequeue(struct vsock_sock * vsk,struct msghdr * msg,size_t len,int flags)609 virtio_transport_stream_dequeue(struct vsock_sock *vsk,
610 				struct msghdr *msg,
611 				size_t len, int flags)
612 {
613 	if (flags & MSG_PEEK)
614 		return virtio_transport_stream_do_peek(vsk, msg, len);
615 	else
616 		return virtio_transport_stream_do_dequeue(vsk, msg, len);
617 }
618 EXPORT_SYMBOL_GPL(virtio_transport_stream_dequeue);
619 
620 ssize_t
virtio_transport_seqpacket_dequeue(struct vsock_sock * vsk,struct msghdr * msg,int flags)621 virtio_transport_seqpacket_dequeue(struct vsock_sock *vsk,
622 				   struct msghdr *msg,
623 				   int flags)
624 {
625 	if (flags & MSG_PEEK)
626 		return virtio_transport_seqpacket_do_peek(vsk, msg);
627 	else
628 		return virtio_transport_seqpacket_do_dequeue(vsk, msg, flags);
629 }
630 EXPORT_SYMBOL_GPL(virtio_transport_seqpacket_dequeue);
631 
632 int
virtio_transport_seqpacket_enqueue(struct vsock_sock * vsk,struct msghdr * msg,size_t len)633 virtio_transport_seqpacket_enqueue(struct vsock_sock *vsk,
634 				   struct msghdr *msg,
635 				   size_t len)
636 {
637 	struct virtio_vsock_sock *vvs = vsk->trans;
638 
639 	spin_lock_bh(&vvs->tx_lock);
640 
641 	if (len > vvs->peer_buf_alloc) {
642 		spin_unlock_bh(&vvs->tx_lock);
643 		return -EMSGSIZE;
644 	}
645 
646 	spin_unlock_bh(&vvs->tx_lock);
647 
648 	return virtio_transport_stream_enqueue(vsk, msg, len);
649 }
650 EXPORT_SYMBOL_GPL(virtio_transport_seqpacket_enqueue);
651 
652 int
virtio_transport_dgram_dequeue(struct vsock_sock * vsk,struct msghdr * msg,size_t len,int flags)653 virtio_transport_dgram_dequeue(struct vsock_sock *vsk,
654 			       struct msghdr *msg,
655 			       size_t len, int flags)
656 {
657 	return -EOPNOTSUPP;
658 }
659 EXPORT_SYMBOL_GPL(virtio_transport_dgram_dequeue);
660 
virtio_transport_stream_has_data(struct vsock_sock * vsk)661 s64 virtio_transport_stream_has_data(struct vsock_sock *vsk)
662 {
663 	struct virtio_vsock_sock *vvs = vsk->trans;
664 	s64 bytes;
665 
666 	spin_lock_bh(&vvs->rx_lock);
667 	bytes = vvs->rx_bytes;
668 	spin_unlock_bh(&vvs->rx_lock);
669 
670 	return bytes;
671 }
672 EXPORT_SYMBOL_GPL(virtio_transport_stream_has_data);
673 
virtio_transport_seqpacket_has_data(struct vsock_sock * vsk)674 u32 virtio_transport_seqpacket_has_data(struct vsock_sock *vsk)
675 {
676 	struct virtio_vsock_sock *vvs = vsk->trans;
677 	u32 msg_count;
678 
679 	spin_lock_bh(&vvs->rx_lock);
680 	msg_count = vvs->msg_count;
681 	spin_unlock_bh(&vvs->rx_lock);
682 
683 	return msg_count;
684 }
685 EXPORT_SYMBOL_GPL(virtio_transport_seqpacket_has_data);
686 
virtio_transport_has_space(struct vsock_sock * vsk)687 static s64 virtio_transport_has_space(struct vsock_sock *vsk)
688 {
689 	struct virtio_vsock_sock *vvs = vsk->trans;
690 	s64 bytes;
691 
692 	bytes = (s64)vvs->peer_buf_alloc - (vvs->tx_cnt - vvs->peer_fwd_cnt);
693 	if (bytes < 0)
694 		bytes = 0;
695 
696 	return bytes;
697 }
698 
virtio_transport_stream_has_space(struct vsock_sock * vsk)699 s64 virtio_transport_stream_has_space(struct vsock_sock *vsk)
700 {
701 	struct virtio_vsock_sock *vvs = vsk->trans;
702 	s64 bytes;
703 
704 	spin_lock_bh(&vvs->tx_lock);
705 	bytes = virtio_transport_has_space(vsk);
706 	spin_unlock_bh(&vvs->tx_lock);
707 
708 	return bytes;
709 }
710 EXPORT_SYMBOL_GPL(virtio_transport_stream_has_space);
711 
virtio_transport_do_socket_init(struct vsock_sock * vsk,struct vsock_sock * psk)712 int virtio_transport_do_socket_init(struct vsock_sock *vsk,
713 				    struct vsock_sock *psk)
714 {
715 	struct virtio_vsock_sock *vvs;
716 
717 	vvs = kzalloc(sizeof(*vvs), GFP_KERNEL);
718 	if (!vvs)
719 		return -ENOMEM;
720 
721 	vsk->trans = vvs;
722 	vvs->vsk = vsk;
723 	if (psk && psk->trans) {
724 		struct virtio_vsock_sock *ptrans = psk->trans;
725 
726 		vvs->peer_buf_alloc = ptrans->peer_buf_alloc;
727 	}
728 
729 	if (vsk->buffer_size > VIRTIO_VSOCK_MAX_BUF_SIZE)
730 		vsk->buffer_size = VIRTIO_VSOCK_MAX_BUF_SIZE;
731 
732 	vvs->buf_alloc = vsk->buffer_size;
733 
734 	spin_lock_init(&vvs->rx_lock);
735 	spin_lock_init(&vvs->tx_lock);
736 	skb_queue_head_init(&vvs->rx_queue);
737 
738 	return 0;
739 }
740 EXPORT_SYMBOL_GPL(virtio_transport_do_socket_init);
741 
742 /* sk_lock held by the caller */
virtio_transport_notify_buffer_size(struct vsock_sock * vsk,u64 * val)743 void virtio_transport_notify_buffer_size(struct vsock_sock *vsk, u64 *val)
744 {
745 	struct virtio_vsock_sock *vvs = vsk->trans;
746 
747 	if (*val > VIRTIO_VSOCK_MAX_BUF_SIZE)
748 		*val = VIRTIO_VSOCK_MAX_BUF_SIZE;
749 
750 	vvs->buf_alloc = *val;
751 
752 	virtio_transport_send_credit_update(vsk);
753 }
754 EXPORT_SYMBOL_GPL(virtio_transport_notify_buffer_size);
755 
756 int
virtio_transport_notify_poll_in(struct vsock_sock * vsk,size_t target,bool * data_ready_now)757 virtio_transport_notify_poll_in(struct vsock_sock *vsk,
758 				size_t target,
759 				bool *data_ready_now)
760 {
761 	*data_ready_now = vsock_stream_has_data(vsk) >= target;
762 
763 	return 0;
764 }
765 EXPORT_SYMBOL_GPL(virtio_transport_notify_poll_in);
766 
767 int
virtio_transport_notify_poll_out(struct vsock_sock * vsk,size_t target,bool * space_avail_now)768 virtio_transport_notify_poll_out(struct vsock_sock *vsk,
769 				 size_t target,
770 				 bool *space_avail_now)
771 {
772 	s64 free_space;
773 
774 	free_space = vsock_stream_has_space(vsk);
775 	if (free_space > 0)
776 		*space_avail_now = true;
777 	else if (free_space == 0)
778 		*space_avail_now = false;
779 
780 	return 0;
781 }
782 EXPORT_SYMBOL_GPL(virtio_transport_notify_poll_out);
783 
virtio_transport_notify_recv_init(struct vsock_sock * vsk,size_t target,struct vsock_transport_recv_notify_data * data)784 int virtio_transport_notify_recv_init(struct vsock_sock *vsk,
785 	size_t target, struct vsock_transport_recv_notify_data *data)
786 {
787 	return 0;
788 }
789 EXPORT_SYMBOL_GPL(virtio_transport_notify_recv_init);
790 
virtio_transport_notify_recv_pre_block(struct vsock_sock * vsk,size_t target,struct vsock_transport_recv_notify_data * data)791 int virtio_transport_notify_recv_pre_block(struct vsock_sock *vsk,
792 	size_t target, struct vsock_transport_recv_notify_data *data)
793 {
794 	return 0;
795 }
796 EXPORT_SYMBOL_GPL(virtio_transport_notify_recv_pre_block);
797 
virtio_transport_notify_recv_pre_dequeue(struct vsock_sock * vsk,size_t target,struct vsock_transport_recv_notify_data * data)798 int virtio_transport_notify_recv_pre_dequeue(struct vsock_sock *vsk,
799 	size_t target, struct vsock_transport_recv_notify_data *data)
800 {
801 	return 0;
802 }
803 EXPORT_SYMBOL_GPL(virtio_transport_notify_recv_pre_dequeue);
804 
virtio_transport_notify_recv_post_dequeue(struct vsock_sock * vsk,size_t target,ssize_t copied,bool data_read,struct vsock_transport_recv_notify_data * data)805 int virtio_transport_notify_recv_post_dequeue(struct vsock_sock *vsk,
806 	size_t target, ssize_t copied, bool data_read,
807 	struct vsock_transport_recv_notify_data *data)
808 {
809 	return 0;
810 }
811 EXPORT_SYMBOL_GPL(virtio_transport_notify_recv_post_dequeue);
812 
virtio_transport_notify_send_init(struct vsock_sock * vsk,struct vsock_transport_send_notify_data * data)813 int virtio_transport_notify_send_init(struct vsock_sock *vsk,
814 	struct vsock_transport_send_notify_data *data)
815 {
816 	return 0;
817 }
818 EXPORT_SYMBOL_GPL(virtio_transport_notify_send_init);
819 
virtio_transport_notify_send_pre_block(struct vsock_sock * vsk,struct vsock_transport_send_notify_data * data)820 int virtio_transport_notify_send_pre_block(struct vsock_sock *vsk,
821 	struct vsock_transport_send_notify_data *data)
822 {
823 	return 0;
824 }
825 EXPORT_SYMBOL_GPL(virtio_transport_notify_send_pre_block);
826 
virtio_transport_notify_send_pre_enqueue(struct vsock_sock * vsk,struct vsock_transport_send_notify_data * data)827 int virtio_transport_notify_send_pre_enqueue(struct vsock_sock *vsk,
828 	struct vsock_transport_send_notify_data *data)
829 {
830 	return 0;
831 }
832 EXPORT_SYMBOL_GPL(virtio_transport_notify_send_pre_enqueue);
833 
virtio_transport_notify_send_post_enqueue(struct vsock_sock * vsk,ssize_t written,struct vsock_transport_send_notify_data * data)834 int virtio_transport_notify_send_post_enqueue(struct vsock_sock *vsk,
835 	ssize_t written, struct vsock_transport_send_notify_data *data)
836 {
837 	return 0;
838 }
839 EXPORT_SYMBOL_GPL(virtio_transport_notify_send_post_enqueue);
840 
virtio_transport_stream_rcvhiwat(struct vsock_sock * vsk)841 u64 virtio_transport_stream_rcvhiwat(struct vsock_sock *vsk)
842 {
843 	return vsk->buffer_size;
844 }
845 EXPORT_SYMBOL_GPL(virtio_transport_stream_rcvhiwat);
846 
virtio_transport_stream_is_active(struct vsock_sock * vsk)847 bool virtio_transport_stream_is_active(struct vsock_sock *vsk)
848 {
849 	return true;
850 }
851 EXPORT_SYMBOL_GPL(virtio_transport_stream_is_active);
852 
virtio_transport_stream_allow(u32 cid,u32 port)853 bool virtio_transport_stream_allow(u32 cid, u32 port)
854 {
855 	return true;
856 }
857 EXPORT_SYMBOL_GPL(virtio_transport_stream_allow);
858 
virtio_transport_dgram_bind(struct vsock_sock * vsk,struct sockaddr_vm * addr)859 int virtio_transport_dgram_bind(struct vsock_sock *vsk,
860 				struct sockaddr_vm *addr)
861 {
862 	return -EOPNOTSUPP;
863 }
864 EXPORT_SYMBOL_GPL(virtio_transport_dgram_bind);
865 
virtio_transport_dgram_allow(u32 cid,u32 port)866 bool virtio_transport_dgram_allow(u32 cid, u32 port)
867 {
868 	return false;
869 }
870 EXPORT_SYMBOL_GPL(virtio_transport_dgram_allow);
871 
virtio_transport_connect(struct vsock_sock * vsk)872 int virtio_transport_connect(struct vsock_sock *vsk)
873 {
874 	struct virtio_vsock_pkt_info info = {
875 		.op = VIRTIO_VSOCK_OP_REQUEST,
876 		.vsk = vsk,
877 	};
878 
879 	return virtio_transport_send_pkt_info(vsk, &info);
880 }
881 EXPORT_SYMBOL_GPL(virtio_transport_connect);
882 
virtio_transport_shutdown(struct vsock_sock * vsk,int mode)883 int virtio_transport_shutdown(struct vsock_sock *vsk, int mode)
884 {
885 	struct virtio_vsock_pkt_info info = {
886 		.op = VIRTIO_VSOCK_OP_SHUTDOWN,
887 		.flags = (mode & RCV_SHUTDOWN ?
888 			  VIRTIO_VSOCK_SHUTDOWN_RCV : 0) |
889 			 (mode & SEND_SHUTDOWN ?
890 			  VIRTIO_VSOCK_SHUTDOWN_SEND : 0),
891 		.vsk = vsk,
892 	};
893 
894 	return virtio_transport_send_pkt_info(vsk, &info);
895 }
896 EXPORT_SYMBOL_GPL(virtio_transport_shutdown);
897 
898 int
virtio_transport_dgram_enqueue(struct vsock_sock * vsk,struct sockaddr_vm * remote_addr,struct msghdr * msg,size_t dgram_len)899 virtio_transport_dgram_enqueue(struct vsock_sock *vsk,
900 			       struct sockaddr_vm *remote_addr,
901 			       struct msghdr *msg,
902 			       size_t dgram_len)
903 {
904 	return -EOPNOTSUPP;
905 }
906 EXPORT_SYMBOL_GPL(virtio_transport_dgram_enqueue);
907 
908 ssize_t
virtio_transport_stream_enqueue(struct vsock_sock * vsk,struct msghdr * msg,size_t len)909 virtio_transport_stream_enqueue(struct vsock_sock *vsk,
910 				struct msghdr *msg,
911 				size_t len)
912 {
913 	struct virtio_vsock_pkt_info info = {
914 		.op = VIRTIO_VSOCK_OP_RW,
915 		.msg = msg,
916 		.pkt_len = len,
917 		.vsk = vsk,
918 	};
919 
920 	return virtio_transport_send_pkt_info(vsk, &info);
921 }
922 EXPORT_SYMBOL_GPL(virtio_transport_stream_enqueue);
923 
virtio_transport_destruct(struct vsock_sock * vsk)924 void virtio_transport_destruct(struct vsock_sock *vsk)
925 {
926 	struct virtio_vsock_sock *vvs = vsk->trans;
927 
928 	virtio_transport_cancel_close_work(vsk, true);
929 
930 	kfree(vvs);
931 	vsk->trans = NULL;
932 }
933 EXPORT_SYMBOL_GPL(virtio_transport_destruct);
934 
virtio_transport_reset(struct vsock_sock * vsk,struct sk_buff * skb)935 static int virtio_transport_reset(struct vsock_sock *vsk,
936 				  struct sk_buff *skb)
937 {
938 	struct virtio_vsock_pkt_info info = {
939 		.op = VIRTIO_VSOCK_OP_RST,
940 		.reply = !!skb,
941 		.vsk = vsk,
942 	};
943 
944 	/* Send RST only if the original pkt is not a RST pkt */
945 	if (skb && le16_to_cpu(virtio_vsock_hdr(skb)->op) == VIRTIO_VSOCK_OP_RST)
946 		return 0;
947 
948 	return virtio_transport_send_pkt_info(vsk, &info);
949 }
950 
951 /* Normally packets are associated with a socket.  There may be no socket if an
952  * attempt was made to connect to a socket that does not exist.
953  */
virtio_transport_reset_no_sock(const struct virtio_transport * t,struct sk_buff * skb)954 static int virtio_transport_reset_no_sock(const struct virtio_transport *t,
955 					  struct sk_buff *skb)
956 {
957 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
958 	struct virtio_vsock_pkt_info info = {
959 		.op = VIRTIO_VSOCK_OP_RST,
960 		.type = le16_to_cpu(hdr->type),
961 		.reply = true,
962 	};
963 	struct sk_buff *reply;
964 
965 	/* Send RST only if the original pkt is not a RST pkt */
966 	if (le16_to_cpu(hdr->op) == VIRTIO_VSOCK_OP_RST)
967 		return 0;
968 
969 	if (!t)
970 		return -ENOTCONN;
971 
972 	reply = virtio_transport_alloc_skb(&info, 0,
973 					   le64_to_cpu(hdr->dst_cid),
974 					   le32_to_cpu(hdr->dst_port),
975 					   le64_to_cpu(hdr->src_cid),
976 					   le32_to_cpu(hdr->src_port));
977 	if (!reply)
978 		return -ENOMEM;
979 
980 	return t->send_pkt(reply);
981 }
982 
983 /* This function should be called with sk_lock held and SOCK_DONE set */
virtio_transport_remove_sock(struct vsock_sock * vsk)984 static void virtio_transport_remove_sock(struct vsock_sock *vsk)
985 {
986 	struct virtio_vsock_sock *vvs = vsk->trans;
987 
988 	/* We don't need to take rx_lock, as the socket is closing and we are
989 	 * removing it.
990 	 */
991 	__skb_queue_purge(&vvs->rx_queue);
992 	vsock_remove_sock(vsk);
993 }
994 
virtio_transport_wait_close(struct sock * sk,long timeout)995 static void virtio_transport_wait_close(struct sock *sk, long timeout)
996 {
997 	if (timeout) {
998 		DEFINE_WAIT_FUNC(wait, woken_wake_function);
999 
1000 		add_wait_queue(sk_sleep(sk), &wait);
1001 
1002 		do {
1003 			if (sk_wait_event(sk, &timeout,
1004 					  sock_flag(sk, SOCK_DONE), &wait))
1005 				break;
1006 		} while (!signal_pending(current) && timeout);
1007 
1008 		remove_wait_queue(sk_sleep(sk), &wait);
1009 	}
1010 }
1011 
virtio_transport_cancel_close_work(struct vsock_sock * vsk,bool cancel_timeout)1012 static void virtio_transport_cancel_close_work(struct vsock_sock *vsk,
1013 					       bool cancel_timeout)
1014 {
1015 	struct sock *sk = sk_vsock(vsk);
1016 
1017 	if (vsk->close_work_scheduled &&
1018 	    (!cancel_timeout || cancel_delayed_work(&vsk->close_work))) {
1019 		vsk->close_work_scheduled = false;
1020 
1021 		virtio_transport_remove_sock(vsk);
1022 
1023 		/* Release refcnt obtained when we scheduled the timeout */
1024 		sock_put(sk);
1025 	}
1026 }
1027 
virtio_transport_do_close(struct vsock_sock * vsk,bool cancel_timeout)1028 static void virtio_transport_do_close(struct vsock_sock *vsk,
1029 				      bool cancel_timeout)
1030 {
1031 	struct sock *sk = sk_vsock(vsk);
1032 
1033 	sock_set_flag(sk, SOCK_DONE);
1034 	vsk->peer_shutdown = SHUTDOWN_MASK;
1035 	if (vsock_stream_has_data(vsk) <= 0)
1036 		sk->sk_state = TCP_CLOSING;
1037 	sk->sk_state_change(sk);
1038 
1039 	virtio_transport_cancel_close_work(vsk, cancel_timeout);
1040 }
1041 
virtio_transport_close_timeout(struct work_struct * work)1042 static void virtio_transport_close_timeout(struct work_struct *work)
1043 {
1044 	struct vsock_sock *vsk =
1045 		container_of(work, struct vsock_sock, close_work.work);
1046 	struct sock *sk = sk_vsock(vsk);
1047 
1048 	sock_hold(sk);
1049 	lock_sock(sk);
1050 
1051 	if (!sock_flag(sk, SOCK_DONE)) {
1052 		(void)virtio_transport_reset(vsk, NULL);
1053 
1054 		virtio_transport_do_close(vsk, false);
1055 	}
1056 
1057 	vsk->close_work_scheduled = false;
1058 
1059 	release_sock(sk);
1060 	sock_put(sk);
1061 }
1062 
1063 /* User context, vsk->sk is locked */
virtio_transport_close(struct vsock_sock * vsk)1064 static bool virtio_transport_close(struct vsock_sock *vsk)
1065 {
1066 	struct sock *sk = &vsk->sk;
1067 
1068 	if (!(sk->sk_state == TCP_ESTABLISHED ||
1069 	      sk->sk_state == TCP_CLOSING))
1070 		return true;
1071 
1072 	/* Already received SHUTDOWN from peer, reply with RST */
1073 	if ((vsk->peer_shutdown & SHUTDOWN_MASK) == SHUTDOWN_MASK) {
1074 		(void)virtio_transport_reset(vsk, NULL);
1075 		return true;
1076 	}
1077 
1078 	if ((sk->sk_shutdown & SHUTDOWN_MASK) != SHUTDOWN_MASK)
1079 		(void)virtio_transport_shutdown(vsk, SHUTDOWN_MASK);
1080 
1081 	if (sock_flag(sk, SOCK_LINGER) && !(current->flags & PF_EXITING))
1082 		virtio_transport_wait_close(sk, sk->sk_lingertime);
1083 
1084 	if (sock_flag(sk, SOCK_DONE)) {
1085 		return true;
1086 	}
1087 
1088 	sock_hold(sk);
1089 	INIT_DELAYED_WORK(&vsk->close_work,
1090 			  virtio_transport_close_timeout);
1091 	vsk->close_work_scheduled = true;
1092 	schedule_delayed_work(&vsk->close_work, VSOCK_CLOSE_TIMEOUT);
1093 	return false;
1094 }
1095 
virtio_transport_release(struct vsock_sock * vsk)1096 void virtio_transport_release(struct vsock_sock *vsk)
1097 {
1098 	struct sock *sk = &vsk->sk;
1099 	bool remove_sock = true;
1100 
1101 	if (sk->sk_type == SOCK_STREAM || sk->sk_type == SOCK_SEQPACKET)
1102 		remove_sock = virtio_transport_close(vsk);
1103 
1104 	if (remove_sock) {
1105 		sock_set_flag(sk, SOCK_DONE);
1106 		virtio_transport_remove_sock(vsk);
1107 	}
1108 }
1109 EXPORT_SYMBOL_GPL(virtio_transport_release);
1110 
1111 static int
virtio_transport_recv_connecting(struct sock * sk,struct sk_buff * skb)1112 virtio_transport_recv_connecting(struct sock *sk,
1113 				 struct sk_buff *skb)
1114 {
1115 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
1116 	struct vsock_sock *vsk = vsock_sk(sk);
1117 	int skerr;
1118 	int err;
1119 
1120 	switch (le16_to_cpu(hdr->op)) {
1121 	case VIRTIO_VSOCK_OP_RESPONSE:
1122 		sk->sk_state = TCP_ESTABLISHED;
1123 		sk->sk_socket->state = SS_CONNECTED;
1124 		vsock_insert_connected(vsk);
1125 		sk->sk_state_change(sk);
1126 		break;
1127 	case VIRTIO_VSOCK_OP_INVALID:
1128 		break;
1129 	case VIRTIO_VSOCK_OP_RST:
1130 		skerr = ECONNRESET;
1131 		err = 0;
1132 		goto destroy;
1133 	default:
1134 		skerr = EPROTO;
1135 		err = -EINVAL;
1136 		goto destroy;
1137 	}
1138 	return 0;
1139 
1140 destroy:
1141 	virtio_transport_reset(vsk, skb);
1142 	sk->sk_state = TCP_CLOSE;
1143 	sk->sk_err = skerr;
1144 	sk_error_report(sk);
1145 	return err;
1146 }
1147 
1148 static void
virtio_transport_recv_enqueue(struct vsock_sock * vsk,struct sk_buff * skb)1149 virtio_transport_recv_enqueue(struct vsock_sock *vsk,
1150 			      struct sk_buff *skb)
1151 {
1152 	struct virtio_vsock_sock *vvs = vsk->trans;
1153 	bool can_enqueue, free_pkt = false;
1154 	struct virtio_vsock_hdr *hdr;
1155 	u32 len;
1156 
1157 	hdr = virtio_vsock_hdr(skb);
1158 	len = le32_to_cpu(hdr->len);
1159 
1160 	spin_lock_bh(&vvs->rx_lock);
1161 
1162 	can_enqueue = virtio_transport_inc_rx_pkt(vvs, len);
1163 	if (!can_enqueue) {
1164 		free_pkt = true;
1165 		goto out;
1166 	}
1167 
1168 	if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SEQ_EOM)
1169 		vvs->msg_count++;
1170 
1171 	/* Try to copy small packets into the buffer of last packet queued,
1172 	 * to avoid wasting memory queueing the entire buffer with a small
1173 	 * payload.
1174 	 */
1175 	if (len <= GOOD_COPY_LEN && !skb_queue_empty(&vvs->rx_queue)) {
1176 		struct virtio_vsock_hdr *last_hdr;
1177 		struct sk_buff *last_skb;
1178 
1179 		last_skb = skb_peek_tail(&vvs->rx_queue);
1180 		last_hdr = virtio_vsock_hdr(last_skb);
1181 
1182 		/* If there is space in the last packet queued, we copy the
1183 		 * new packet in its buffer. We avoid this if the last packet
1184 		 * queued has VIRTIO_VSOCK_SEQ_EOM set, because this is
1185 		 * delimiter of SEQPACKET message, so 'pkt' is the first packet
1186 		 * of a new message.
1187 		 */
1188 		if (skb->len < skb_tailroom(last_skb) &&
1189 		    !(le32_to_cpu(last_hdr->flags) & VIRTIO_VSOCK_SEQ_EOM)) {
1190 			memcpy(skb_put(last_skb, skb->len), skb->data, skb->len);
1191 			free_pkt = true;
1192 			last_hdr->flags |= hdr->flags;
1193 			le32_add_cpu(&last_hdr->len, len);
1194 			goto out;
1195 		}
1196 	}
1197 
1198 	__skb_queue_tail(&vvs->rx_queue, skb);
1199 
1200 out:
1201 	spin_unlock_bh(&vvs->rx_lock);
1202 	if (free_pkt)
1203 		kfree_skb(skb);
1204 }
1205 
1206 static int
virtio_transport_recv_connected(struct sock * sk,struct sk_buff * skb)1207 virtio_transport_recv_connected(struct sock *sk,
1208 				struct sk_buff *skb)
1209 {
1210 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
1211 	struct vsock_sock *vsk = vsock_sk(sk);
1212 	int err = 0;
1213 
1214 	switch (le16_to_cpu(hdr->op)) {
1215 	case VIRTIO_VSOCK_OP_RW:
1216 		virtio_transport_recv_enqueue(vsk, skb);
1217 		vsock_data_ready(sk);
1218 		return err;
1219 	case VIRTIO_VSOCK_OP_CREDIT_REQUEST:
1220 		virtio_transport_send_credit_update(vsk);
1221 		break;
1222 	case VIRTIO_VSOCK_OP_CREDIT_UPDATE:
1223 		sk->sk_write_space(sk);
1224 		break;
1225 	case VIRTIO_VSOCK_OP_SHUTDOWN:
1226 		if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SHUTDOWN_RCV)
1227 			vsk->peer_shutdown |= RCV_SHUTDOWN;
1228 		if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SHUTDOWN_SEND)
1229 			vsk->peer_shutdown |= SEND_SHUTDOWN;
1230 		if (vsk->peer_shutdown == SHUTDOWN_MASK) {
1231 			if (vsock_stream_has_data(vsk) <= 0 && !sock_flag(sk, SOCK_DONE)) {
1232 				(void)virtio_transport_reset(vsk, NULL);
1233 				virtio_transport_do_close(vsk, true);
1234 			}
1235 			/* Remove this socket anyway because the remote peer sent
1236 			 * the shutdown. This way a new connection will succeed
1237 			 * if the remote peer uses the same source port,
1238 			 * even if the old socket is still unreleased, but now disconnected.
1239 			 */
1240 			vsock_remove_sock(vsk);
1241 		}
1242 		if (le32_to_cpu(virtio_vsock_hdr(skb)->flags))
1243 			sk->sk_state_change(sk);
1244 		break;
1245 	case VIRTIO_VSOCK_OP_RST:
1246 		virtio_transport_do_close(vsk, true);
1247 		break;
1248 	default:
1249 		err = -EINVAL;
1250 		break;
1251 	}
1252 
1253 	kfree_skb(skb);
1254 	return err;
1255 }
1256 
1257 static void
virtio_transport_recv_disconnecting(struct sock * sk,struct sk_buff * skb)1258 virtio_transport_recv_disconnecting(struct sock *sk,
1259 				    struct sk_buff *skb)
1260 {
1261 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
1262 	struct vsock_sock *vsk = vsock_sk(sk);
1263 
1264 	if (le16_to_cpu(hdr->op) == VIRTIO_VSOCK_OP_RST)
1265 		virtio_transport_do_close(vsk, true);
1266 }
1267 
1268 static int
virtio_transport_send_response(struct vsock_sock * vsk,struct sk_buff * skb)1269 virtio_transport_send_response(struct vsock_sock *vsk,
1270 			       struct sk_buff *skb)
1271 {
1272 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
1273 	struct virtio_vsock_pkt_info info = {
1274 		.op = VIRTIO_VSOCK_OP_RESPONSE,
1275 		.remote_cid = le64_to_cpu(hdr->src_cid),
1276 		.remote_port = le32_to_cpu(hdr->src_port),
1277 		.reply = true,
1278 		.vsk = vsk,
1279 	};
1280 
1281 	return virtio_transport_send_pkt_info(vsk, &info);
1282 }
1283 
virtio_transport_space_update(struct sock * sk,struct sk_buff * skb)1284 static bool virtio_transport_space_update(struct sock *sk,
1285 					  struct sk_buff *skb)
1286 {
1287 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
1288 	struct vsock_sock *vsk = vsock_sk(sk);
1289 	struct virtio_vsock_sock *vvs = vsk->trans;
1290 	bool space_available;
1291 
1292 	/* Listener sockets are not associated with any transport, so we are
1293 	 * not able to take the state to see if there is space available in the
1294 	 * remote peer, but since they are only used to receive requests, we
1295 	 * can assume that there is always space available in the other peer.
1296 	 */
1297 	if (!vvs)
1298 		return true;
1299 
1300 	/* buf_alloc and fwd_cnt is always included in the hdr */
1301 	spin_lock_bh(&vvs->tx_lock);
1302 	vvs->peer_buf_alloc = le32_to_cpu(hdr->buf_alloc);
1303 	vvs->peer_fwd_cnt = le32_to_cpu(hdr->fwd_cnt);
1304 	space_available = virtio_transport_has_space(vsk);
1305 	spin_unlock_bh(&vvs->tx_lock);
1306 	return space_available;
1307 }
1308 
1309 /* Handle server socket */
1310 static int
virtio_transport_recv_listen(struct sock * sk,struct sk_buff * skb,struct virtio_transport * t)1311 virtio_transport_recv_listen(struct sock *sk, struct sk_buff *skb,
1312 			     struct virtio_transport *t)
1313 {
1314 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
1315 	struct vsock_sock *vsk = vsock_sk(sk);
1316 	struct vsock_sock *vchild;
1317 	struct sock *child;
1318 	int ret;
1319 
1320 	if (le16_to_cpu(hdr->op) != VIRTIO_VSOCK_OP_REQUEST) {
1321 		virtio_transport_reset_no_sock(t, skb);
1322 		return -EINVAL;
1323 	}
1324 
1325 	if (sk_acceptq_is_full(sk)) {
1326 		virtio_transport_reset_no_sock(t, skb);
1327 		return -ENOMEM;
1328 	}
1329 
1330 	/* __vsock_release() might have already flushed accept_queue.
1331 	 * Subsequent enqueues would lead to a memory leak.
1332 	 */
1333 	if (sk->sk_shutdown == SHUTDOWN_MASK) {
1334 		virtio_transport_reset_no_sock(t, skb);
1335 		return -ESHUTDOWN;
1336 	}
1337 
1338 	child = vsock_create_connected(sk);
1339 	if (!child) {
1340 		virtio_transport_reset_no_sock(t, skb);
1341 		return -ENOMEM;
1342 	}
1343 
1344 	sk_acceptq_added(sk);
1345 
1346 	lock_sock_nested(child, SINGLE_DEPTH_NESTING);
1347 
1348 	child->sk_state = TCP_ESTABLISHED;
1349 
1350 	vchild = vsock_sk(child);
1351 	vsock_addr_init(&vchild->local_addr, le64_to_cpu(hdr->dst_cid),
1352 			le32_to_cpu(hdr->dst_port));
1353 	vsock_addr_init(&vchild->remote_addr, le64_to_cpu(hdr->src_cid),
1354 			le32_to_cpu(hdr->src_port));
1355 
1356 	ret = vsock_assign_transport(vchild, vsk);
1357 	/* Transport assigned (looking at remote_addr) must be the same
1358 	 * where we received the request.
1359 	 */
1360 	if (ret || vchild->transport != &t->transport) {
1361 		release_sock(child);
1362 		virtio_transport_reset_no_sock(t, skb);
1363 		sock_put(child);
1364 		return ret;
1365 	}
1366 
1367 	if (virtio_transport_space_update(child, skb))
1368 		child->sk_write_space(child);
1369 
1370 	vsock_insert_connected(vchild);
1371 	vsock_enqueue_accept(sk, child);
1372 	virtio_transport_send_response(vchild, skb);
1373 
1374 	release_sock(child);
1375 
1376 	sk->sk_data_ready(sk);
1377 	return 0;
1378 }
1379 
virtio_transport_valid_type(u16 type)1380 static bool virtio_transport_valid_type(u16 type)
1381 {
1382 	return (type == VIRTIO_VSOCK_TYPE_STREAM) ||
1383 	       (type == VIRTIO_VSOCK_TYPE_SEQPACKET);
1384 }
1385 
1386 /* We are under the virtio-vsock's vsock->rx_lock or vhost-vsock's vq->mutex
1387  * lock.
1388  */
virtio_transport_recv_pkt(struct virtio_transport * t,struct sk_buff * skb)1389 void virtio_transport_recv_pkt(struct virtio_transport *t,
1390 			       struct sk_buff *skb)
1391 {
1392 	struct virtio_vsock_hdr *hdr = virtio_vsock_hdr(skb);
1393 	struct sockaddr_vm src, dst;
1394 	struct vsock_sock *vsk;
1395 	struct sock *sk;
1396 	bool space_available;
1397 
1398 	vsock_addr_init(&src, le64_to_cpu(hdr->src_cid),
1399 			le32_to_cpu(hdr->src_port));
1400 	vsock_addr_init(&dst, le64_to_cpu(hdr->dst_cid),
1401 			le32_to_cpu(hdr->dst_port));
1402 
1403 	trace_virtio_transport_recv_pkt(src.svm_cid, src.svm_port,
1404 					dst.svm_cid, dst.svm_port,
1405 					le32_to_cpu(hdr->len),
1406 					le16_to_cpu(hdr->type),
1407 					le16_to_cpu(hdr->op),
1408 					le32_to_cpu(hdr->flags),
1409 					le32_to_cpu(hdr->buf_alloc),
1410 					le32_to_cpu(hdr->fwd_cnt));
1411 
1412 	if (!virtio_transport_valid_type(le16_to_cpu(hdr->type))) {
1413 		(void)virtio_transport_reset_no_sock(t, skb);
1414 		goto free_pkt;
1415 	}
1416 
1417 	/* The socket must be in connected or bound table
1418 	 * otherwise send reset back
1419 	 */
1420 	sk = vsock_find_connected_socket(&src, &dst);
1421 	if (!sk) {
1422 		sk = vsock_find_bound_socket(&dst);
1423 		if (!sk) {
1424 			(void)virtio_transport_reset_no_sock(t, skb);
1425 			goto free_pkt;
1426 		}
1427 	}
1428 
1429 	if (virtio_transport_get_type(sk) != le16_to_cpu(hdr->type)) {
1430 		(void)virtio_transport_reset_no_sock(t, skb);
1431 		sock_put(sk);
1432 		goto free_pkt;
1433 	}
1434 
1435 	if (!skb_set_owner_sk_safe(skb, sk)) {
1436 		WARN_ONCE(1, "receiving vsock socket has sk_refcnt == 0\n");
1437 		goto free_pkt;
1438 	}
1439 
1440 	vsk = vsock_sk(sk);
1441 
1442 	lock_sock(sk);
1443 
1444 	/* Check if sk has been closed or assigned to another transport before
1445 	 * lock_sock (note: listener sockets are not assigned to any transport)
1446 	 */
1447 	if (sock_flag(sk, SOCK_DONE) ||
1448 	    (sk->sk_state != TCP_LISTEN && vsk->transport != &t->transport)) {
1449 		(void)virtio_transport_reset_no_sock(t, skb);
1450 		release_sock(sk);
1451 		sock_put(sk);
1452 		goto free_pkt;
1453 	}
1454 
1455 	space_available = virtio_transport_space_update(sk, skb);
1456 
1457 	/* Update CID in case it has changed after a transport reset event */
1458 	if (vsk->local_addr.svm_cid != VMADDR_CID_ANY)
1459 		vsk->local_addr.svm_cid = dst.svm_cid;
1460 
1461 	if (space_available)
1462 		sk->sk_write_space(sk);
1463 
1464 	switch (sk->sk_state) {
1465 	case TCP_LISTEN:
1466 		virtio_transport_recv_listen(sk, skb, t);
1467 		kfree_skb(skb);
1468 		break;
1469 	case TCP_SYN_SENT:
1470 		virtio_transport_recv_connecting(sk, skb);
1471 		kfree_skb(skb);
1472 		break;
1473 	case TCP_ESTABLISHED:
1474 		virtio_transport_recv_connected(sk, skb);
1475 		break;
1476 	case TCP_CLOSING:
1477 		virtio_transport_recv_disconnecting(sk, skb);
1478 		kfree_skb(skb);
1479 		break;
1480 	default:
1481 		(void)virtio_transport_reset_no_sock(t, skb);
1482 		kfree_skb(skb);
1483 		break;
1484 	}
1485 
1486 	release_sock(sk);
1487 
1488 	/* Release refcnt obtained when we fetched this socket out of the
1489 	 * bound or connected list.
1490 	 */
1491 	sock_put(sk);
1492 	return;
1493 
1494 free_pkt:
1495 	kfree_skb(skb);
1496 }
1497 EXPORT_SYMBOL_GPL(virtio_transport_recv_pkt);
1498 
1499 /* Remove skbs found in a queue that have a vsk that matches.
1500  *
1501  * Each skb is freed.
1502  *
1503  * Returns the count of skbs that were reply packets.
1504  */
virtio_transport_purge_skbs(void * vsk,struct sk_buff_head * queue)1505 int virtio_transport_purge_skbs(void *vsk, struct sk_buff_head *queue)
1506 {
1507 	struct sk_buff_head freeme;
1508 	struct sk_buff *skb, *tmp;
1509 	int cnt = 0;
1510 
1511 	skb_queue_head_init(&freeme);
1512 
1513 	spin_lock_bh(&queue->lock);
1514 	skb_queue_walk_safe(queue, skb, tmp) {
1515 		if (vsock_sk(skb->sk) != vsk)
1516 			continue;
1517 
1518 		__skb_unlink(skb, queue);
1519 		__skb_queue_tail(&freeme, skb);
1520 
1521 		if (virtio_vsock_skb_reply(skb))
1522 			cnt++;
1523 	}
1524 	spin_unlock_bh(&queue->lock);
1525 
1526 	__skb_queue_purge(&freeme);
1527 
1528 	return cnt;
1529 }
1530 EXPORT_SYMBOL_GPL(virtio_transport_purge_skbs);
1531 
virtio_transport_read_skb(struct vsock_sock * vsk,skb_read_actor_t recv_actor)1532 int virtio_transport_read_skb(struct vsock_sock *vsk, skb_read_actor_t recv_actor)
1533 {
1534 	struct virtio_vsock_sock *vvs = vsk->trans;
1535 	struct sock *sk = sk_vsock(vsk);
1536 	struct virtio_vsock_hdr *hdr;
1537 	struct sk_buff *skb;
1538 	int off = 0;
1539 	int err;
1540 
1541 	spin_lock_bh(&vvs->rx_lock);
1542 	/* Use __skb_recv_datagram() for race-free handling of the receive. It
1543 	 * works for types other than dgrams.
1544 	 */
1545 	skb = __skb_recv_datagram(sk, &vvs->rx_queue, MSG_DONTWAIT, &off, &err);
1546 	if (!skb) {
1547 		spin_unlock_bh(&vvs->rx_lock);
1548 		return err;
1549 	}
1550 
1551 	hdr = virtio_vsock_hdr(skb);
1552 	if (le32_to_cpu(hdr->flags) & VIRTIO_VSOCK_SEQ_EOM)
1553 		vvs->msg_count--;
1554 
1555 	virtio_transport_dec_rx_pkt(vvs, le32_to_cpu(hdr->len));
1556 	spin_unlock_bh(&vvs->rx_lock);
1557 
1558 	virtio_transport_send_credit_update(vsk);
1559 
1560 	return recv_actor(sk, skb);
1561 }
1562 EXPORT_SYMBOL_GPL(virtio_transport_read_skb);
1563 
virtio_transport_notify_set_rcvlowat(struct vsock_sock * vsk,int val)1564 int virtio_transport_notify_set_rcvlowat(struct vsock_sock *vsk, int val)
1565 {
1566 	struct virtio_vsock_sock *vvs = vsk->trans;
1567 	bool send_update;
1568 
1569 	spin_lock_bh(&vvs->rx_lock);
1570 
1571 	/* If number of available bytes is less than new SO_RCVLOWAT value,
1572 	 * kick sender to send more data, because sender may sleep in its
1573 	 * 'send()' syscall waiting for enough space at our side. Also
1574 	 * don't send credit update when peer already knows actual value -
1575 	 * such transmission will be useless.
1576 	 */
1577 	send_update = (vvs->rx_bytes < val) &&
1578 		      (vvs->fwd_cnt != vvs->last_fwd_cnt);
1579 
1580 	spin_unlock_bh(&vvs->rx_lock);
1581 
1582 	if (send_update) {
1583 		int err;
1584 
1585 		err = virtio_transport_send_credit_update(vsk);
1586 		if (err < 0)
1587 			return err;
1588 	}
1589 
1590 	return 0;
1591 }
1592 EXPORT_SYMBOL_GPL(virtio_transport_notify_set_rcvlowat);
1593 
1594 MODULE_LICENSE("GPL v2");
1595 MODULE_AUTHOR("Asias He");
1596 MODULE_DESCRIPTION("common code for virtio vsock");
1597