1*2874c5fdSThomas Gleixner // SPDX-License-Identifier: GPL-2.0-or-later
21da177e4SLinus Torvalds /*
31da177e4SLinus Torvalds *
41da177e4SLinus Torvalds * Copyright (C) Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
51da177e4SLinus Torvalds * Copyright (C) Joerg Reuter DL1BKE (jreuter@yaina.de)
61da177e4SLinus Torvalds */
71da177e4SLinus Torvalds #include <linux/errno.h>
81da177e4SLinus Torvalds #include <linux/types.h>
91da177e4SLinus Torvalds #include <linux/socket.h>
101da177e4SLinus Torvalds #include <linux/in.h>
111da177e4SLinus Torvalds #include <linux/kernel.h>
121da177e4SLinus Torvalds #include <linux/timer.h>
131da177e4SLinus Torvalds #include <linux/string.h>
141da177e4SLinus Torvalds #include <linux/sockios.h>
151da177e4SLinus Torvalds #include <linux/net.h>
161da177e4SLinus Torvalds #include <net/ax25.h>
171da177e4SLinus Torvalds #include <linux/inet.h>
181da177e4SLinus Torvalds #include <linux/netdevice.h>
191da177e4SLinus Torvalds #include <linux/skbuff.h>
201da177e4SLinus Torvalds #include <net/sock.h>
21c752f073SArnaldo Carvalho de Melo #include <net/tcp_states.h>
227c0f6ba6SLinus Torvalds #include <linux/uaccess.h>
231da177e4SLinus Torvalds #include <linux/fcntl.h>
241da177e4SLinus Torvalds #include <linux/mm.h>
251da177e4SLinus Torvalds #include <linux/interrupt.h>
261da177e4SLinus Torvalds
271da177e4SLinus Torvalds /*
281da177e4SLinus Torvalds * State machine for state 1, Awaiting Connection State.
291da177e4SLinus Torvalds * The handling of the timer(s) is in file ax25_ds_timer.c.
301da177e4SLinus Torvalds * Handling of state 0 and connection release is in ax25.c.
311da177e4SLinus Torvalds */
ax25_ds_state1_machine(ax25_cb * ax25,struct sk_buff * skb,int frametype,int pf,int type)321da177e4SLinus Torvalds static int ax25_ds_state1_machine(ax25_cb *ax25, struct sk_buff *skb, int frametype, int pf, int type)
331da177e4SLinus Torvalds {
341da177e4SLinus Torvalds switch (frametype) {
351da177e4SLinus Torvalds case AX25_SABM:
361da177e4SLinus Torvalds ax25->modulus = AX25_MODULUS;
371da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_WINDOW];
381da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE);
391da177e4SLinus Torvalds break;
401da177e4SLinus Torvalds
411da177e4SLinus Torvalds case AX25_SABME:
421da177e4SLinus Torvalds ax25->modulus = AX25_EMODULUS;
431da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_EWINDOW];
441da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE);
451da177e4SLinus Torvalds break;
461da177e4SLinus Torvalds
471da177e4SLinus Torvalds case AX25_DISC:
481da177e4SLinus Torvalds ax25_send_control(ax25, AX25_DM, pf, AX25_RESPONSE);
491da177e4SLinus Torvalds break;
501da177e4SLinus Torvalds
511da177e4SLinus Torvalds case AX25_UA:
521da177e4SLinus Torvalds ax25_calculate_rtt(ax25);
531da177e4SLinus Torvalds ax25_stop_t1timer(ax25);
541da177e4SLinus Torvalds ax25_start_t3timer(ax25);
551da177e4SLinus Torvalds ax25_start_idletimer(ax25);
561da177e4SLinus Torvalds ax25->vs = 0;
571da177e4SLinus Torvalds ax25->va = 0;
581da177e4SLinus Torvalds ax25->vr = 0;
591da177e4SLinus Torvalds ax25->state = AX25_STATE_3;
601da177e4SLinus Torvalds ax25->n2count = 0;
611da177e4SLinus Torvalds if (ax25->sk != NULL) {
621da177e4SLinus Torvalds bh_lock_sock(ax25->sk);
631da177e4SLinus Torvalds ax25->sk->sk_state = TCP_ESTABLISHED;
641da177e4SLinus Torvalds /*
651da177e4SLinus Torvalds * For WAIT_SABM connections we will produce an accept
661da177e4SLinus Torvalds * ready socket here
671da177e4SLinus Torvalds */
681da177e4SLinus Torvalds if (!sock_flag(ax25->sk, SOCK_DEAD))
691da177e4SLinus Torvalds ax25->sk->sk_state_change(ax25->sk);
701da177e4SLinus Torvalds bh_unlock_sock(ax25->sk);
711da177e4SLinus Torvalds }
721da177e4SLinus Torvalds ax25_dama_on(ax25);
731da177e4SLinus Torvalds
7496de0e25SJan Engelhardt /* according to DK4EG's spec we are required to
751da177e4SLinus Torvalds * send a RR RESPONSE FINAL NR=0.
761da177e4SLinus Torvalds */
771da177e4SLinus Torvalds
781da177e4SLinus Torvalds ax25_std_enquiry_response(ax25);
791da177e4SLinus Torvalds break;
801da177e4SLinus Torvalds
811da177e4SLinus Torvalds case AX25_DM:
821da177e4SLinus Torvalds if (pf)
831da177e4SLinus Torvalds ax25_disconnect(ax25, ECONNREFUSED);
841da177e4SLinus Torvalds break;
851da177e4SLinus Torvalds
861da177e4SLinus Torvalds default:
871da177e4SLinus Torvalds if (pf)
881da177e4SLinus Torvalds ax25_send_control(ax25, AX25_SABM, AX25_POLLON, AX25_COMMAND);
891da177e4SLinus Torvalds break;
901da177e4SLinus Torvalds }
911da177e4SLinus Torvalds
921da177e4SLinus Torvalds return 0;
931da177e4SLinus Torvalds }
941da177e4SLinus Torvalds
951da177e4SLinus Torvalds /*
961da177e4SLinus Torvalds * State machine for state 2, Awaiting Release State.
971da177e4SLinus Torvalds * The handling of the timer(s) is in file ax25_ds_timer.c
981da177e4SLinus Torvalds * Handling of state 0 and connection release is in ax25.c.
991da177e4SLinus Torvalds */
ax25_ds_state2_machine(ax25_cb * ax25,struct sk_buff * skb,int frametype,int pf,int type)1001da177e4SLinus Torvalds static int ax25_ds_state2_machine(ax25_cb *ax25, struct sk_buff *skb, int frametype, int pf, int type)
1011da177e4SLinus Torvalds {
1021da177e4SLinus Torvalds switch (frametype) {
1031da177e4SLinus Torvalds case AX25_SABM:
1041da177e4SLinus Torvalds case AX25_SABME:
1051da177e4SLinus Torvalds ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND);
1061da177e4SLinus Torvalds ax25_dama_off(ax25);
1071da177e4SLinus Torvalds break;
1081da177e4SLinus Torvalds
1091da177e4SLinus Torvalds case AX25_DISC:
1101da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE);
1111da177e4SLinus Torvalds ax25_dama_off(ax25);
1121da177e4SLinus Torvalds ax25_disconnect(ax25, 0);
1131da177e4SLinus Torvalds break;
1141da177e4SLinus Torvalds
1151da177e4SLinus Torvalds case AX25_DM:
1161da177e4SLinus Torvalds case AX25_UA:
1171da177e4SLinus Torvalds if (pf) {
1181da177e4SLinus Torvalds ax25_dama_off(ax25);
1191da177e4SLinus Torvalds ax25_disconnect(ax25, 0);
1201da177e4SLinus Torvalds }
1211da177e4SLinus Torvalds break;
1221da177e4SLinus Torvalds
1231da177e4SLinus Torvalds case AX25_I:
1241da177e4SLinus Torvalds case AX25_REJ:
1251da177e4SLinus Torvalds case AX25_RNR:
1261da177e4SLinus Torvalds case AX25_RR:
1271da177e4SLinus Torvalds if (pf) {
1281da177e4SLinus Torvalds ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND);
1291da177e4SLinus Torvalds ax25_dama_off(ax25);
1301da177e4SLinus Torvalds }
1311da177e4SLinus Torvalds break;
1321da177e4SLinus Torvalds
1331da177e4SLinus Torvalds default:
1341da177e4SLinus Torvalds break;
1351da177e4SLinus Torvalds }
1361da177e4SLinus Torvalds
1371da177e4SLinus Torvalds return 0;
1381da177e4SLinus Torvalds }
1391da177e4SLinus Torvalds
1401da177e4SLinus Torvalds /*
1411da177e4SLinus Torvalds * State machine for state 3, Connected State.
1421da177e4SLinus Torvalds * The handling of the timer(s) is in file ax25_timer.c
1431da177e4SLinus Torvalds * Handling of state 0 and connection release is in ax25.c.
1441da177e4SLinus Torvalds */
ax25_ds_state3_machine(ax25_cb * ax25,struct sk_buff * skb,int frametype,int ns,int nr,int pf,int type)1451da177e4SLinus Torvalds static int ax25_ds_state3_machine(ax25_cb *ax25, struct sk_buff *skb, int frametype, int ns, int nr, int pf, int type)
1461da177e4SLinus Torvalds {
1471da177e4SLinus Torvalds int queued = 0;
1481da177e4SLinus Torvalds
1491da177e4SLinus Torvalds switch (frametype) {
1501da177e4SLinus Torvalds case AX25_SABM:
1511da177e4SLinus Torvalds case AX25_SABME:
1521da177e4SLinus Torvalds if (frametype == AX25_SABM) {
1531da177e4SLinus Torvalds ax25->modulus = AX25_MODULUS;
1541da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_WINDOW];
1551da177e4SLinus Torvalds } else {
1561da177e4SLinus Torvalds ax25->modulus = AX25_EMODULUS;
1571da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_EWINDOW];
1581da177e4SLinus Torvalds }
1591da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE);
1601da177e4SLinus Torvalds ax25_stop_t1timer(ax25);
1611da177e4SLinus Torvalds ax25_start_t3timer(ax25);
1621da177e4SLinus Torvalds ax25_start_idletimer(ax25);
1631da177e4SLinus Torvalds ax25->condition = 0x00;
1641da177e4SLinus Torvalds ax25->vs = 0;
1651da177e4SLinus Torvalds ax25->va = 0;
1661da177e4SLinus Torvalds ax25->vr = 0;
1671da177e4SLinus Torvalds ax25_requeue_frames(ax25);
1681da177e4SLinus Torvalds ax25_dama_on(ax25);
1691da177e4SLinus Torvalds break;
1701da177e4SLinus Torvalds
1711da177e4SLinus Torvalds case AX25_DISC:
1721da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE);
1731da177e4SLinus Torvalds ax25_dama_off(ax25);
1741da177e4SLinus Torvalds ax25_disconnect(ax25, 0);
1751da177e4SLinus Torvalds break;
1761da177e4SLinus Torvalds
1771da177e4SLinus Torvalds case AX25_DM:
1781da177e4SLinus Torvalds ax25_dama_off(ax25);
1791da177e4SLinus Torvalds ax25_disconnect(ax25, ECONNRESET);
1801da177e4SLinus Torvalds break;
1811da177e4SLinus Torvalds
1821da177e4SLinus Torvalds case AX25_RR:
1831da177e4SLinus Torvalds case AX25_RNR:
1841da177e4SLinus Torvalds if (frametype == AX25_RR)
1851da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_PEER_RX_BUSY;
1861da177e4SLinus Torvalds else
1871da177e4SLinus Torvalds ax25->condition |= AX25_COND_PEER_RX_BUSY;
1881da177e4SLinus Torvalds
1891da177e4SLinus Torvalds if (ax25_validate_nr(ax25, nr)) {
1901da177e4SLinus Torvalds if (ax25_check_iframes_acked(ax25, nr))
1911da177e4SLinus Torvalds ax25->n2count=0;
1921da177e4SLinus Torvalds if (type == AX25_COMMAND && pf)
1931da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25);
1941da177e4SLinus Torvalds } else {
1951da177e4SLinus Torvalds ax25_ds_nr_error_recovery(ax25);
1961da177e4SLinus Torvalds ax25->state = AX25_STATE_1;
1971da177e4SLinus Torvalds }
1981da177e4SLinus Torvalds break;
1991da177e4SLinus Torvalds
2001da177e4SLinus Torvalds case AX25_REJ:
2011da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_PEER_RX_BUSY;
2021da177e4SLinus Torvalds
2031da177e4SLinus Torvalds if (ax25_validate_nr(ax25, nr)) {
2041da177e4SLinus Torvalds if (ax25->va != nr)
2051da177e4SLinus Torvalds ax25->n2count=0;
2061da177e4SLinus Torvalds
2071da177e4SLinus Torvalds ax25_frames_acked(ax25, nr);
2081da177e4SLinus Torvalds ax25_calculate_rtt(ax25);
2091da177e4SLinus Torvalds ax25_stop_t1timer(ax25);
2101da177e4SLinus Torvalds ax25_start_t3timer(ax25);
2111da177e4SLinus Torvalds ax25_requeue_frames(ax25);
2121da177e4SLinus Torvalds
2131da177e4SLinus Torvalds if (type == AX25_COMMAND && pf)
2141da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25);
2151da177e4SLinus Torvalds } else {
2161da177e4SLinus Torvalds ax25_ds_nr_error_recovery(ax25);
2171da177e4SLinus Torvalds ax25->state = AX25_STATE_1;
2181da177e4SLinus Torvalds }
2191da177e4SLinus Torvalds break;
2201da177e4SLinus Torvalds
2211da177e4SLinus Torvalds case AX25_I:
2221da177e4SLinus Torvalds if (!ax25_validate_nr(ax25, nr)) {
2231da177e4SLinus Torvalds ax25_ds_nr_error_recovery(ax25);
2241da177e4SLinus Torvalds ax25->state = AX25_STATE_1;
2251da177e4SLinus Torvalds break;
2261da177e4SLinus Torvalds }
2271da177e4SLinus Torvalds if (ax25->condition & AX25_COND_PEER_RX_BUSY) {
2281da177e4SLinus Torvalds ax25_frames_acked(ax25, nr);
2291da177e4SLinus Torvalds ax25->n2count = 0;
2301da177e4SLinus Torvalds } else {
2311da177e4SLinus Torvalds if (ax25_check_iframes_acked(ax25, nr))
2321da177e4SLinus Torvalds ax25->n2count = 0;
2331da177e4SLinus Torvalds }
2341da177e4SLinus Torvalds if (ax25->condition & AX25_COND_OWN_RX_BUSY) {
2351da177e4SLinus Torvalds if (pf) ax25_ds_enquiry_response(ax25);
2361da177e4SLinus Torvalds break;
2371da177e4SLinus Torvalds }
2381da177e4SLinus Torvalds if (ns == ax25->vr) {
2391da177e4SLinus Torvalds ax25->vr = (ax25->vr + 1) % ax25->modulus;
2401da177e4SLinus Torvalds queued = ax25_rx_iframe(ax25, skb);
2411da177e4SLinus Torvalds if (ax25->condition & AX25_COND_OWN_RX_BUSY)
2421da177e4SLinus Torvalds ax25->vr = ns; /* ax25->vr - 1 */
2431da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_REJECT;
2441da177e4SLinus Torvalds if (pf) {
2451da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25);
2461da177e4SLinus Torvalds } else {
2471da177e4SLinus Torvalds if (!(ax25->condition & AX25_COND_ACK_PENDING)) {
2481da177e4SLinus Torvalds ax25->condition |= AX25_COND_ACK_PENDING;
2491da177e4SLinus Torvalds ax25_start_t2timer(ax25);
2501da177e4SLinus Torvalds }
2511da177e4SLinus Torvalds }
2521da177e4SLinus Torvalds } else {
2531da177e4SLinus Torvalds if (ax25->condition & AX25_COND_REJECT) {
2541da177e4SLinus Torvalds if (pf) ax25_ds_enquiry_response(ax25);
2551da177e4SLinus Torvalds } else {
2561da177e4SLinus Torvalds ax25->condition |= AX25_COND_REJECT;
2571da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25);
2581da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_ACK_PENDING;
2591da177e4SLinus Torvalds }
2601da177e4SLinus Torvalds }
2611da177e4SLinus Torvalds break;
2621da177e4SLinus Torvalds
2631da177e4SLinus Torvalds case AX25_FRMR:
2641da177e4SLinus Torvalds case AX25_ILLEGAL:
2651da177e4SLinus Torvalds ax25_ds_establish_data_link(ax25);
2661da177e4SLinus Torvalds ax25->state = AX25_STATE_1;
2671da177e4SLinus Torvalds break;
2681da177e4SLinus Torvalds
2691da177e4SLinus Torvalds default:
2701da177e4SLinus Torvalds break;
2711da177e4SLinus Torvalds }
2721da177e4SLinus Torvalds
2731da177e4SLinus Torvalds return queued;
2741da177e4SLinus Torvalds }
2751da177e4SLinus Torvalds
2761da177e4SLinus Torvalds /*
2771da177e4SLinus Torvalds * Higher level upcall for a LAPB frame
2781da177e4SLinus Torvalds */
ax25_ds_frame_in(ax25_cb * ax25,struct sk_buff * skb,int type)2791da177e4SLinus Torvalds int ax25_ds_frame_in(ax25_cb *ax25, struct sk_buff *skb, int type)
2801da177e4SLinus Torvalds {
2811da177e4SLinus Torvalds int queued = 0, frametype, ns, nr, pf;
2821da177e4SLinus Torvalds
2831da177e4SLinus Torvalds frametype = ax25_decode(ax25, skb, &ns, &nr, &pf);
2841da177e4SLinus Torvalds
2851da177e4SLinus Torvalds switch (ax25->state) {
2861da177e4SLinus Torvalds case AX25_STATE_1:
2871da177e4SLinus Torvalds queued = ax25_ds_state1_machine(ax25, skb, frametype, pf, type);
2881da177e4SLinus Torvalds break;
2891da177e4SLinus Torvalds case AX25_STATE_2:
2901da177e4SLinus Torvalds queued = ax25_ds_state2_machine(ax25, skb, frametype, pf, type);
2911da177e4SLinus Torvalds break;
2921da177e4SLinus Torvalds case AX25_STATE_3:
2931da177e4SLinus Torvalds queued = ax25_ds_state3_machine(ax25, skb, frametype, ns, nr, pf, type);
2941da177e4SLinus Torvalds break;
2951da177e4SLinus Torvalds }
2961da177e4SLinus Torvalds
2971da177e4SLinus Torvalds return queued;
2981da177e4SLinus Torvalds }
299