1*2874c5fdSThomas Gleixner // SPDX-License-Identifier: GPL-2.0-or-later 21da177e4SLinus Torvalds /* 31da177e4SLinus Torvalds * 41da177e4SLinus Torvalds * Copyright (C) Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk) 51da177e4SLinus Torvalds * Copyright (C) Joerg Reuter DL1BKE (jreuter@yaina.de) 61da177e4SLinus Torvalds */ 71da177e4SLinus Torvalds #include <linux/errno.h> 81da177e4SLinus Torvalds #include <linux/types.h> 91da177e4SLinus Torvalds #include <linux/socket.h> 101da177e4SLinus Torvalds #include <linux/in.h> 111da177e4SLinus Torvalds #include <linux/kernel.h> 121da177e4SLinus Torvalds #include <linux/timer.h> 131da177e4SLinus Torvalds #include <linux/string.h> 141da177e4SLinus Torvalds #include <linux/sockios.h> 151da177e4SLinus Torvalds #include <linux/net.h> 161da177e4SLinus Torvalds #include <net/ax25.h> 171da177e4SLinus Torvalds #include <linux/inet.h> 181da177e4SLinus Torvalds #include <linux/netdevice.h> 191da177e4SLinus Torvalds #include <linux/skbuff.h> 201da177e4SLinus Torvalds #include <net/sock.h> 21c752f073SArnaldo Carvalho de Melo #include <net/tcp_states.h> 227c0f6ba6SLinus Torvalds #include <linux/uaccess.h> 231da177e4SLinus Torvalds #include <linux/fcntl.h> 241da177e4SLinus Torvalds #include <linux/mm.h> 251da177e4SLinus Torvalds #include <linux/interrupt.h> 261da177e4SLinus Torvalds 271da177e4SLinus Torvalds /* 281da177e4SLinus Torvalds * State machine for state 1, Awaiting Connection State. 291da177e4SLinus Torvalds * The handling of the timer(s) is in file ax25_ds_timer.c. 301da177e4SLinus Torvalds * Handling of state 0 and connection release is in ax25.c. 311da177e4SLinus Torvalds */ 321da177e4SLinus Torvalds static int ax25_ds_state1_machine(ax25_cb *ax25, struct sk_buff *skb, int frametype, int pf, int type) 331da177e4SLinus Torvalds { 341da177e4SLinus Torvalds switch (frametype) { 351da177e4SLinus Torvalds case AX25_SABM: 361da177e4SLinus Torvalds ax25->modulus = AX25_MODULUS; 371da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_WINDOW]; 381da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE); 391da177e4SLinus Torvalds break; 401da177e4SLinus Torvalds 411da177e4SLinus Torvalds case AX25_SABME: 421da177e4SLinus Torvalds ax25->modulus = AX25_EMODULUS; 431da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_EWINDOW]; 441da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE); 451da177e4SLinus Torvalds break; 461da177e4SLinus Torvalds 471da177e4SLinus Torvalds case AX25_DISC: 481da177e4SLinus Torvalds ax25_send_control(ax25, AX25_DM, pf, AX25_RESPONSE); 491da177e4SLinus Torvalds break; 501da177e4SLinus Torvalds 511da177e4SLinus Torvalds case AX25_UA: 521da177e4SLinus Torvalds ax25_calculate_rtt(ax25); 531da177e4SLinus Torvalds ax25_stop_t1timer(ax25); 541da177e4SLinus Torvalds ax25_start_t3timer(ax25); 551da177e4SLinus Torvalds ax25_start_idletimer(ax25); 561da177e4SLinus Torvalds ax25->vs = 0; 571da177e4SLinus Torvalds ax25->va = 0; 581da177e4SLinus Torvalds ax25->vr = 0; 591da177e4SLinus Torvalds ax25->state = AX25_STATE_3; 601da177e4SLinus Torvalds ax25->n2count = 0; 611da177e4SLinus Torvalds if (ax25->sk != NULL) { 621da177e4SLinus Torvalds bh_lock_sock(ax25->sk); 631da177e4SLinus Torvalds ax25->sk->sk_state = TCP_ESTABLISHED; 641da177e4SLinus Torvalds /* 651da177e4SLinus Torvalds * For WAIT_SABM connections we will produce an accept 661da177e4SLinus Torvalds * ready socket here 671da177e4SLinus Torvalds */ 681da177e4SLinus Torvalds if (!sock_flag(ax25->sk, SOCK_DEAD)) 691da177e4SLinus Torvalds ax25->sk->sk_state_change(ax25->sk); 701da177e4SLinus Torvalds bh_unlock_sock(ax25->sk); 711da177e4SLinus Torvalds } 721da177e4SLinus Torvalds ax25_dama_on(ax25); 731da177e4SLinus Torvalds 7496de0e25SJan Engelhardt /* according to DK4EG's spec we are required to 751da177e4SLinus Torvalds * send a RR RESPONSE FINAL NR=0. 761da177e4SLinus Torvalds */ 771da177e4SLinus Torvalds 781da177e4SLinus Torvalds ax25_std_enquiry_response(ax25); 791da177e4SLinus Torvalds break; 801da177e4SLinus Torvalds 811da177e4SLinus Torvalds case AX25_DM: 821da177e4SLinus Torvalds if (pf) 831da177e4SLinus Torvalds ax25_disconnect(ax25, ECONNREFUSED); 841da177e4SLinus Torvalds break; 851da177e4SLinus Torvalds 861da177e4SLinus Torvalds default: 871da177e4SLinus Torvalds if (pf) 881da177e4SLinus Torvalds ax25_send_control(ax25, AX25_SABM, AX25_POLLON, AX25_COMMAND); 891da177e4SLinus Torvalds break; 901da177e4SLinus Torvalds } 911da177e4SLinus Torvalds 921da177e4SLinus Torvalds return 0; 931da177e4SLinus Torvalds } 941da177e4SLinus Torvalds 951da177e4SLinus Torvalds /* 961da177e4SLinus Torvalds * State machine for state 2, Awaiting Release State. 971da177e4SLinus Torvalds * The handling of the timer(s) is in file ax25_ds_timer.c 981da177e4SLinus Torvalds * Handling of state 0 and connection release is in ax25.c. 991da177e4SLinus Torvalds */ 1001da177e4SLinus Torvalds static int ax25_ds_state2_machine(ax25_cb *ax25, struct sk_buff *skb, int frametype, int pf, int type) 1011da177e4SLinus Torvalds { 1021da177e4SLinus Torvalds switch (frametype) { 1031da177e4SLinus Torvalds case AX25_SABM: 1041da177e4SLinus Torvalds case AX25_SABME: 1051da177e4SLinus Torvalds ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND); 1061da177e4SLinus Torvalds ax25_dama_off(ax25); 1071da177e4SLinus Torvalds break; 1081da177e4SLinus Torvalds 1091da177e4SLinus Torvalds case AX25_DISC: 1101da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE); 1111da177e4SLinus Torvalds ax25_dama_off(ax25); 1121da177e4SLinus Torvalds ax25_disconnect(ax25, 0); 1131da177e4SLinus Torvalds break; 1141da177e4SLinus Torvalds 1151da177e4SLinus Torvalds case AX25_DM: 1161da177e4SLinus Torvalds case AX25_UA: 1171da177e4SLinus Torvalds if (pf) { 1181da177e4SLinus Torvalds ax25_dama_off(ax25); 1191da177e4SLinus Torvalds ax25_disconnect(ax25, 0); 1201da177e4SLinus Torvalds } 1211da177e4SLinus Torvalds break; 1221da177e4SLinus Torvalds 1231da177e4SLinus Torvalds case AX25_I: 1241da177e4SLinus Torvalds case AX25_REJ: 1251da177e4SLinus Torvalds case AX25_RNR: 1261da177e4SLinus Torvalds case AX25_RR: 1271da177e4SLinus Torvalds if (pf) { 1281da177e4SLinus Torvalds ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND); 1291da177e4SLinus Torvalds ax25_dama_off(ax25); 1301da177e4SLinus Torvalds } 1311da177e4SLinus Torvalds break; 1321da177e4SLinus Torvalds 1331da177e4SLinus Torvalds default: 1341da177e4SLinus Torvalds break; 1351da177e4SLinus Torvalds } 1361da177e4SLinus Torvalds 1371da177e4SLinus Torvalds return 0; 1381da177e4SLinus Torvalds } 1391da177e4SLinus Torvalds 1401da177e4SLinus Torvalds /* 1411da177e4SLinus Torvalds * State machine for state 3, Connected State. 1421da177e4SLinus Torvalds * The handling of the timer(s) is in file ax25_timer.c 1431da177e4SLinus Torvalds * Handling of state 0 and connection release is in ax25.c. 1441da177e4SLinus Torvalds */ 1451da177e4SLinus Torvalds static int ax25_ds_state3_machine(ax25_cb *ax25, struct sk_buff *skb, int frametype, int ns, int nr, int pf, int type) 1461da177e4SLinus Torvalds { 1471da177e4SLinus Torvalds int queued = 0; 1481da177e4SLinus Torvalds 1491da177e4SLinus Torvalds switch (frametype) { 1501da177e4SLinus Torvalds case AX25_SABM: 1511da177e4SLinus Torvalds case AX25_SABME: 1521da177e4SLinus Torvalds if (frametype == AX25_SABM) { 1531da177e4SLinus Torvalds ax25->modulus = AX25_MODULUS; 1541da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_WINDOW]; 1551da177e4SLinus Torvalds } else { 1561da177e4SLinus Torvalds ax25->modulus = AX25_EMODULUS; 1571da177e4SLinus Torvalds ax25->window = ax25->ax25_dev->values[AX25_VALUES_EWINDOW]; 1581da177e4SLinus Torvalds } 1591da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE); 1601da177e4SLinus Torvalds ax25_stop_t1timer(ax25); 1611da177e4SLinus Torvalds ax25_start_t3timer(ax25); 1621da177e4SLinus Torvalds ax25_start_idletimer(ax25); 1631da177e4SLinus Torvalds ax25->condition = 0x00; 1641da177e4SLinus Torvalds ax25->vs = 0; 1651da177e4SLinus Torvalds ax25->va = 0; 1661da177e4SLinus Torvalds ax25->vr = 0; 1671da177e4SLinus Torvalds ax25_requeue_frames(ax25); 1681da177e4SLinus Torvalds ax25_dama_on(ax25); 1691da177e4SLinus Torvalds break; 1701da177e4SLinus Torvalds 1711da177e4SLinus Torvalds case AX25_DISC: 1721da177e4SLinus Torvalds ax25_send_control(ax25, AX25_UA, pf, AX25_RESPONSE); 1731da177e4SLinus Torvalds ax25_dama_off(ax25); 1741da177e4SLinus Torvalds ax25_disconnect(ax25, 0); 1751da177e4SLinus Torvalds break; 1761da177e4SLinus Torvalds 1771da177e4SLinus Torvalds case AX25_DM: 1781da177e4SLinus Torvalds ax25_dama_off(ax25); 1791da177e4SLinus Torvalds ax25_disconnect(ax25, ECONNRESET); 1801da177e4SLinus Torvalds break; 1811da177e4SLinus Torvalds 1821da177e4SLinus Torvalds case AX25_RR: 1831da177e4SLinus Torvalds case AX25_RNR: 1841da177e4SLinus Torvalds if (frametype == AX25_RR) 1851da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_PEER_RX_BUSY; 1861da177e4SLinus Torvalds else 1871da177e4SLinus Torvalds ax25->condition |= AX25_COND_PEER_RX_BUSY; 1881da177e4SLinus Torvalds 1891da177e4SLinus Torvalds if (ax25_validate_nr(ax25, nr)) { 1901da177e4SLinus Torvalds if (ax25_check_iframes_acked(ax25, nr)) 1911da177e4SLinus Torvalds ax25->n2count=0; 1921da177e4SLinus Torvalds if (type == AX25_COMMAND && pf) 1931da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25); 1941da177e4SLinus Torvalds } else { 1951da177e4SLinus Torvalds ax25_ds_nr_error_recovery(ax25); 1961da177e4SLinus Torvalds ax25->state = AX25_STATE_1; 1971da177e4SLinus Torvalds } 1981da177e4SLinus Torvalds break; 1991da177e4SLinus Torvalds 2001da177e4SLinus Torvalds case AX25_REJ: 2011da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_PEER_RX_BUSY; 2021da177e4SLinus Torvalds 2031da177e4SLinus Torvalds if (ax25_validate_nr(ax25, nr)) { 2041da177e4SLinus Torvalds if (ax25->va != nr) 2051da177e4SLinus Torvalds ax25->n2count=0; 2061da177e4SLinus Torvalds 2071da177e4SLinus Torvalds ax25_frames_acked(ax25, nr); 2081da177e4SLinus Torvalds ax25_calculate_rtt(ax25); 2091da177e4SLinus Torvalds ax25_stop_t1timer(ax25); 2101da177e4SLinus Torvalds ax25_start_t3timer(ax25); 2111da177e4SLinus Torvalds ax25_requeue_frames(ax25); 2121da177e4SLinus Torvalds 2131da177e4SLinus Torvalds if (type == AX25_COMMAND && pf) 2141da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25); 2151da177e4SLinus Torvalds } else { 2161da177e4SLinus Torvalds ax25_ds_nr_error_recovery(ax25); 2171da177e4SLinus Torvalds ax25->state = AX25_STATE_1; 2181da177e4SLinus Torvalds } 2191da177e4SLinus Torvalds break; 2201da177e4SLinus Torvalds 2211da177e4SLinus Torvalds case AX25_I: 2221da177e4SLinus Torvalds if (!ax25_validate_nr(ax25, nr)) { 2231da177e4SLinus Torvalds ax25_ds_nr_error_recovery(ax25); 2241da177e4SLinus Torvalds ax25->state = AX25_STATE_1; 2251da177e4SLinus Torvalds break; 2261da177e4SLinus Torvalds } 2271da177e4SLinus Torvalds if (ax25->condition & AX25_COND_PEER_RX_BUSY) { 2281da177e4SLinus Torvalds ax25_frames_acked(ax25, nr); 2291da177e4SLinus Torvalds ax25->n2count = 0; 2301da177e4SLinus Torvalds } else { 2311da177e4SLinus Torvalds if (ax25_check_iframes_acked(ax25, nr)) 2321da177e4SLinus Torvalds ax25->n2count = 0; 2331da177e4SLinus Torvalds } 2341da177e4SLinus Torvalds if (ax25->condition & AX25_COND_OWN_RX_BUSY) { 2351da177e4SLinus Torvalds if (pf) ax25_ds_enquiry_response(ax25); 2361da177e4SLinus Torvalds break; 2371da177e4SLinus Torvalds } 2381da177e4SLinus Torvalds if (ns == ax25->vr) { 2391da177e4SLinus Torvalds ax25->vr = (ax25->vr + 1) % ax25->modulus; 2401da177e4SLinus Torvalds queued = ax25_rx_iframe(ax25, skb); 2411da177e4SLinus Torvalds if (ax25->condition & AX25_COND_OWN_RX_BUSY) 2421da177e4SLinus Torvalds ax25->vr = ns; /* ax25->vr - 1 */ 2431da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_REJECT; 2441da177e4SLinus Torvalds if (pf) { 2451da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25); 2461da177e4SLinus Torvalds } else { 2471da177e4SLinus Torvalds if (!(ax25->condition & AX25_COND_ACK_PENDING)) { 2481da177e4SLinus Torvalds ax25->condition |= AX25_COND_ACK_PENDING; 2491da177e4SLinus Torvalds ax25_start_t2timer(ax25); 2501da177e4SLinus Torvalds } 2511da177e4SLinus Torvalds } 2521da177e4SLinus Torvalds } else { 2531da177e4SLinus Torvalds if (ax25->condition & AX25_COND_REJECT) { 2541da177e4SLinus Torvalds if (pf) ax25_ds_enquiry_response(ax25); 2551da177e4SLinus Torvalds } else { 2561da177e4SLinus Torvalds ax25->condition |= AX25_COND_REJECT; 2571da177e4SLinus Torvalds ax25_ds_enquiry_response(ax25); 2581da177e4SLinus Torvalds ax25->condition &= ~AX25_COND_ACK_PENDING; 2591da177e4SLinus Torvalds } 2601da177e4SLinus Torvalds } 2611da177e4SLinus Torvalds break; 2621da177e4SLinus Torvalds 2631da177e4SLinus Torvalds case AX25_FRMR: 2641da177e4SLinus Torvalds case AX25_ILLEGAL: 2651da177e4SLinus Torvalds ax25_ds_establish_data_link(ax25); 2661da177e4SLinus Torvalds ax25->state = AX25_STATE_1; 2671da177e4SLinus Torvalds break; 2681da177e4SLinus Torvalds 2691da177e4SLinus Torvalds default: 2701da177e4SLinus Torvalds break; 2711da177e4SLinus Torvalds } 2721da177e4SLinus Torvalds 2731da177e4SLinus Torvalds return queued; 2741da177e4SLinus Torvalds } 2751da177e4SLinus Torvalds 2761da177e4SLinus Torvalds /* 2771da177e4SLinus Torvalds * Higher level upcall for a LAPB frame 2781da177e4SLinus Torvalds */ 2791da177e4SLinus Torvalds int ax25_ds_frame_in(ax25_cb *ax25, struct sk_buff *skb, int type) 2801da177e4SLinus Torvalds { 2811da177e4SLinus Torvalds int queued = 0, frametype, ns, nr, pf; 2821da177e4SLinus Torvalds 2831da177e4SLinus Torvalds frametype = ax25_decode(ax25, skb, &ns, &nr, &pf); 2841da177e4SLinus Torvalds 2851da177e4SLinus Torvalds switch (ax25->state) { 2861da177e4SLinus Torvalds case AX25_STATE_1: 2871da177e4SLinus Torvalds queued = ax25_ds_state1_machine(ax25, skb, frametype, pf, type); 2881da177e4SLinus Torvalds break; 2891da177e4SLinus Torvalds case AX25_STATE_2: 2901da177e4SLinus Torvalds queued = ax25_ds_state2_machine(ax25, skb, frametype, pf, type); 2911da177e4SLinus Torvalds break; 2921da177e4SLinus Torvalds case AX25_STATE_3: 2931da177e4SLinus Torvalds queued = ax25_ds_state3_machine(ax25, skb, frametype, ns, nr, pf, type); 2941da177e4SLinus Torvalds break; 2951da177e4SLinus Torvalds } 2961da177e4SLinus Torvalds 2971da177e4SLinus Torvalds return queued; 2981da177e4SLinus Torvalds } 299