xref: /openbmc/linux/net/dccp/proto.c (revision 3021ad529950d07e0408d65d0f1df00454c1d223)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  *  net/dccp/proto.c
4  *
5  *  An implementation of the DCCP protocol
6  *  Arnaldo Carvalho de Melo <acme@conectiva.com.br>
7  */
8 
9 #include <linux/dccp.h>
10 #include <linux/module.h>
11 #include <linux/types.h>
12 #include <linux/sched.h>
13 #include <linux/kernel.h>
14 #include <linux/skbuff.h>
15 #include <linux/netdevice.h>
16 #include <linux/in.h>
17 #include <linux/if_arp.h>
18 #include <linux/init.h>
19 #include <linux/random.h>
20 #include <linux/slab.h>
21 #include <net/checksum.h>
22 
23 #include <net/inet_sock.h>
24 #include <net/inet_common.h>
25 #include <net/sock.h>
26 #include <net/xfrm.h>
27 
28 #include <asm/ioctls.h>
29 #include <linux/spinlock.h>
30 #include <linux/timer.h>
31 #include <linux/delay.h>
32 #include <linux/poll.h>
33 
34 #include "ccid.h"
35 #include "dccp.h"
36 #include "feat.h"
37 
38 #define CREATE_TRACE_POINTS
39 #include "trace.h"
40 
41 DEFINE_SNMP_STAT(struct dccp_mib, dccp_statistics) __read_mostly;
42 
43 EXPORT_SYMBOL_GPL(dccp_statistics);
44 
45 struct percpu_counter dccp_orphan_count;
46 EXPORT_SYMBOL_GPL(dccp_orphan_count);
47 
48 struct inet_hashinfo dccp_hashinfo;
49 EXPORT_SYMBOL_GPL(dccp_hashinfo);
50 
51 /* the maximum queue length for tx in packets. 0 is no limit */
52 int sysctl_dccp_tx_qlen __read_mostly = 5;
53 
54 #ifdef CONFIG_IP_DCCP_DEBUG
55 static const char *dccp_state_name(const int state)
56 {
57 	static const char *const dccp_state_names[] = {
58 	[DCCP_OPEN]		= "OPEN",
59 	[DCCP_REQUESTING]	= "REQUESTING",
60 	[DCCP_PARTOPEN]		= "PARTOPEN",
61 	[DCCP_LISTEN]		= "LISTEN",
62 	[DCCP_RESPOND]		= "RESPOND",
63 	[DCCP_CLOSING]		= "CLOSING",
64 	[DCCP_ACTIVE_CLOSEREQ]	= "CLOSEREQ",
65 	[DCCP_PASSIVE_CLOSE]	= "PASSIVE_CLOSE",
66 	[DCCP_PASSIVE_CLOSEREQ]	= "PASSIVE_CLOSEREQ",
67 	[DCCP_TIME_WAIT]	= "TIME_WAIT",
68 	[DCCP_CLOSED]		= "CLOSED",
69 	};
70 
71 	if (state >= DCCP_MAX_STATES)
72 		return "INVALID STATE!";
73 	else
74 		return dccp_state_names[state];
75 }
76 #endif
77 
78 void dccp_set_state(struct sock *sk, const int state)
79 {
80 	const int oldstate = sk->sk_state;
81 
82 	dccp_pr_debug("%s(%p)  %s  -->  %s\n", dccp_role(sk), sk,
83 		      dccp_state_name(oldstate), dccp_state_name(state));
84 	WARN_ON(state == oldstate);
85 
86 	switch (state) {
87 	case DCCP_OPEN:
88 		if (oldstate != DCCP_OPEN)
89 			DCCP_INC_STATS(DCCP_MIB_CURRESTAB);
90 		/* Client retransmits all Confirm options until entering OPEN */
91 		if (oldstate == DCCP_PARTOPEN)
92 			dccp_feat_list_purge(&dccp_sk(sk)->dccps_featneg);
93 		break;
94 
95 	case DCCP_CLOSED:
96 		if (oldstate == DCCP_OPEN || oldstate == DCCP_ACTIVE_CLOSEREQ ||
97 		    oldstate == DCCP_CLOSING)
98 			DCCP_INC_STATS(DCCP_MIB_ESTABRESETS);
99 
100 		sk->sk_prot->unhash(sk);
101 		if (inet_csk(sk)->icsk_bind_hash != NULL &&
102 		    !(sk->sk_userlocks & SOCK_BINDPORT_LOCK))
103 			inet_put_port(sk);
104 		/* fall through */
105 	default:
106 		if (oldstate == DCCP_OPEN)
107 			DCCP_DEC_STATS(DCCP_MIB_CURRESTAB);
108 	}
109 
110 	/* Change state AFTER socket is unhashed to avoid closed
111 	 * socket sitting in hash tables.
112 	 */
113 	inet_sk_set_state(sk, state);
114 }
115 
116 EXPORT_SYMBOL_GPL(dccp_set_state);
117 
118 static void dccp_finish_passive_close(struct sock *sk)
119 {
120 	switch (sk->sk_state) {
121 	case DCCP_PASSIVE_CLOSE:
122 		/* Node (client or server) has received Close packet. */
123 		dccp_send_reset(sk, DCCP_RESET_CODE_CLOSED);
124 		dccp_set_state(sk, DCCP_CLOSED);
125 		break;
126 	case DCCP_PASSIVE_CLOSEREQ:
127 		/*
128 		 * Client received CloseReq. We set the `active' flag so that
129 		 * dccp_send_close() retransmits the Close as per RFC 4340, 8.3.
130 		 */
131 		dccp_send_close(sk, 1);
132 		dccp_set_state(sk, DCCP_CLOSING);
133 	}
134 }
135 
136 void dccp_done(struct sock *sk)
137 {
138 	dccp_set_state(sk, DCCP_CLOSED);
139 	dccp_clear_xmit_timers(sk);
140 
141 	sk->sk_shutdown = SHUTDOWN_MASK;
142 
143 	if (!sock_flag(sk, SOCK_DEAD))
144 		sk->sk_state_change(sk);
145 	else
146 		inet_csk_destroy_sock(sk);
147 }
148 
149 EXPORT_SYMBOL_GPL(dccp_done);
150 
151 const char *dccp_packet_name(const int type)
152 {
153 	static const char *const dccp_packet_names[] = {
154 		[DCCP_PKT_REQUEST]  = "REQUEST",
155 		[DCCP_PKT_RESPONSE] = "RESPONSE",
156 		[DCCP_PKT_DATA]	    = "DATA",
157 		[DCCP_PKT_ACK]	    = "ACK",
158 		[DCCP_PKT_DATAACK]  = "DATAACK",
159 		[DCCP_PKT_CLOSEREQ] = "CLOSEREQ",
160 		[DCCP_PKT_CLOSE]    = "CLOSE",
161 		[DCCP_PKT_RESET]    = "RESET",
162 		[DCCP_PKT_SYNC]	    = "SYNC",
163 		[DCCP_PKT_SYNCACK]  = "SYNCACK",
164 	};
165 
166 	if (type >= DCCP_NR_PKT_TYPES)
167 		return "INVALID";
168 	else
169 		return dccp_packet_names[type];
170 }
171 
172 EXPORT_SYMBOL_GPL(dccp_packet_name);
173 
174 static void dccp_sk_destruct(struct sock *sk)
175 {
176 	struct dccp_sock *dp = dccp_sk(sk);
177 
178 	ccid_hc_tx_delete(dp->dccps_hc_tx_ccid, sk);
179 	dp->dccps_hc_tx_ccid = NULL;
180 	inet_sock_destruct(sk);
181 }
182 
183 int dccp_init_sock(struct sock *sk, const __u8 ctl_sock_initialized)
184 {
185 	struct dccp_sock *dp = dccp_sk(sk);
186 	struct inet_connection_sock *icsk = inet_csk(sk);
187 
188 	icsk->icsk_rto		= DCCP_TIMEOUT_INIT;
189 	icsk->icsk_syn_retries	= sysctl_dccp_request_retries;
190 	sk->sk_state		= DCCP_CLOSED;
191 	sk->sk_write_space	= dccp_write_space;
192 	sk->sk_destruct		= dccp_sk_destruct;
193 	icsk->icsk_sync_mss	= dccp_sync_mss;
194 	dp->dccps_mss_cache	= 536;
195 	dp->dccps_rate_last	= jiffies;
196 	dp->dccps_role		= DCCP_ROLE_UNDEFINED;
197 	dp->dccps_service	= DCCP_SERVICE_CODE_IS_ABSENT;
198 	dp->dccps_tx_qlen	= sysctl_dccp_tx_qlen;
199 
200 	dccp_init_xmit_timers(sk);
201 
202 	INIT_LIST_HEAD(&dp->dccps_featneg);
203 	/* control socket doesn't need feat nego */
204 	if (likely(ctl_sock_initialized))
205 		return dccp_feat_init(sk);
206 	return 0;
207 }
208 
209 EXPORT_SYMBOL_GPL(dccp_init_sock);
210 
211 void dccp_destroy_sock(struct sock *sk)
212 {
213 	struct dccp_sock *dp = dccp_sk(sk);
214 
215 	__skb_queue_purge(&sk->sk_write_queue);
216 	if (sk->sk_send_head != NULL) {
217 		kfree_skb(sk->sk_send_head);
218 		sk->sk_send_head = NULL;
219 	}
220 
221 	/* Clean up a referenced DCCP bind bucket. */
222 	if (inet_csk(sk)->icsk_bind_hash != NULL)
223 		inet_put_port(sk);
224 
225 	kfree(dp->dccps_service_list);
226 	dp->dccps_service_list = NULL;
227 
228 	if (dp->dccps_hc_rx_ackvec != NULL) {
229 		dccp_ackvec_free(dp->dccps_hc_rx_ackvec);
230 		dp->dccps_hc_rx_ackvec = NULL;
231 	}
232 	ccid_hc_rx_delete(dp->dccps_hc_rx_ccid, sk);
233 	dp->dccps_hc_rx_ccid = NULL;
234 
235 	/* clean up feature negotiation state */
236 	dccp_feat_list_purge(&dp->dccps_featneg);
237 }
238 
239 EXPORT_SYMBOL_GPL(dccp_destroy_sock);
240 
241 static inline int dccp_listen_start(struct sock *sk, int backlog)
242 {
243 	struct dccp_sock *dp = dccp_sk(sk);
244 
245 	dp->dccps_role = DCCP_ROLE_LISTEN;
246 	/* do not start to listen if feature negotiation setup fails */
247 	if (dccp_feat_finalise_settings(dp))
248 		return -EPROTO;
249 	return inet_csk_listen_start(sk, backlog);
250 }
251 
252 static inline int dccp_need_reset(int state)
253 {
254 	return state != DCCP_CLOSED && state != DCCP_LISTEN &&
255 	       state != DCCP_REQUESTING;
256 }
257 
258 int dccp_disconnect(struct sock *sk, int flags)
259 {
260 	struct inet_connection_sock *icsk = inet_csk(sk);
261 	struct inet_sock *inet = inet_sk(sk);
262 	struct dccp_sock *dp = dccp_sk(sk);
263 	const int old_state = sk->sk_state;
264 
265 	if (old_state != DCCP_CLOSED)
266 		dccp_set_state(sk, DCCP_CLOSED);
267 
268 	/*
269 	 * This corresponds to the ABORT function of RFC793, sec. 3.8
270 	 * TCP uses a RST segment, DCCP a Reset packet with Code 2, "Aborted".
271 	 */
272 	if (old_state == DCCP_LISTEN) {
273 		inet_csk_listen_stop(sk);
274 	} else if (dccp_need_reset(old_state)) {
275 		dccp_send_reset(sk, DCCP_RESET_CODE_ABORTED);
276 		sk->sk_err = ECONNRESET;
277 	} else if (old_state == DCCP_REQUESTING)
278 		sk->sk_err = ECONNRESET;
279 
280 	dccp_clear_xmit_timers(sk);
281 	ccid_hc_rx_delete(dp->dccps_hc_rx_ccid, sk);
282 	dp->dccps_hc_rx_ccid = NULL;
283 
284 	__skb_queue_purge(&sk->sk_receive_queue);
285 	__skb_queue_purge(&sk->sk_write_queue);
286 	if (sk->sk_send_head != NULL) {
287 		__kfree_skb(sk->sk_send_head);
288 		sk->sk_send_head = NULL;
289 	}
290 
291 	inet->inet_dport = 0;
292 
293 	if (!(sk->sk_userlocks & SOCK_BINDADDR_LOCK))
294 		inet_reset_saddr(sk);
295 
296 	sk->sk_shutdown = 0;
297 	sock_reset_flag(sk, SOCK_DONE);
298 
299 	icsk->icsk_backoff = 0;
300 	inet_csk_delack_init(sk);
301 	__sk_dst_reset(sk);
302 
303 	WARN_ON(inet->inet_num && !icsk->icsk_bind_hash);
304 
305 	sk->sk_error_report(sk);
306 	return 0;
307 }
308 
309 EXPORT_SYMBOL_GPL(dccp_disconnect);
310 
311 /*
312  *	Wait for a DCCP event.
313  *
314  *	Note that we don't need to lock the socket, as the upper poll layers
315  *	take care of normal races (between the test and the event) and we don't
316  *	go look at any of the socket buffers directly.
317  */
318 __poll_t dccp_poll(struct file *file, struct socket *sock,
319 		       poll_table *wait)
320 {
321 	__poll_t mask;
322 	struct sock *sk = sock->sk;
323 
324 	sock_poll_wait(file, sock, wait);
325 	if (sk->sk_state == DCCP_LISTEN)
326 		return inet_csk_listen_poll(sk);
327 
328 	/* Socket is not locked. We are protected from async events
329 	   by poll logic and correct handling of state changes
330 	   made by another threads is impossible in any case.
331 	 */
332 
333 	mask = 0;
334 	if (sk->sk_err)
335 		mask = EPOLLERR;
336 
337 	if (sk->sk_shutdown == SHUTDOWN_MASK || sk->sk_state == DCCP_CLOSED)
338 		mask |= EPOLLHUP;
339 	if (sk->sk_shutdown & RCV_SHUTDOWN)
340 		mask |= EPOLLIN | EPOLLRDNORM | EPOLLRDHUP;
341 
342 	/* Connected? */
343 	if ((1 << sk->sk_state) & ~(DCCPF_REQUESTING | DCCPF_RESPOND)) {
344 		if (atomic_read(&sk->sk_rmem_alloc) > 0)
345 			mask |= EPOLLIN | EPOLLRDNORM;
346 
347 		if (!(sk->sk_shutdown & SEND_SHUTDOWN)) {
348 			if (sk_stream_is_writeable(sk)) {
349 				mask |= EPOLLOUT | EPOLLWRNORM;
350 			} else {  /* send SIGIO later */
351 				sk_set_bit(SOCKWQ_ASYNC_NOSPACE, sk);
352 				set_bit(SOCK_NOSPACE, &sk->sk_socket->flags);
353 
354 				/* Race breaker. If space is freed after
355 				 * wspace test but before the flags are set,
356 				 * IO signal will be lost.
357 				 */
358 				if (sk_stream_is_writeable(sk))
359 					mask |= EPOLLOUT | EPOLLWRNORM;
360 			}
361 		}
362 	}
363 	return mask;
364 }
365 
366 EXPORT_SYMBOL_GPL(dccp_poll);
367 
368 int dccp_ioctl(struct sock *sk, int cmd, unsigned long arg)
369 {
370 	int rc = -ENOTCONN;
371 
372 	lock_sock(sk);
373 
374 	if (sk->sk_state == DCCP_LISTEN)
375 		goto out;
376 
377 	switch (cmd) {
378 	case SIOCINQ: {
379 		struct sk_buff *skb;
380 		unsigned long amount = 0;
381 
382 		skb = skb_peek(&sk->sk_receive_queue);
383 		if (skb != NULL) {
384 			/*
385 			 * We will only return the amount of this packet since
386 			 * that is all that will be read.
387 			 */
388 			amount = skb->len;
389 		}
390 		rc = put_user(amount, (int __user *)arg);
391 	}
392 		break;
393 	default:
394 		rc = -ENOIOCTLCMD;
395 		break;
396 	}
397 out:
398 	release_sock(sk);
399 	return rc;
400 }
401 
402 EXPORT_SYMBOL_GPL(dccp_ioctl);
403 
404 static int dccp_setsockopt_service(struct sock *sk, const __be32 service,
405 				   char __user *optval, unsigned int optlen)
406 {
407 	struct dccp_sock *dp = dccp_sk(sk);
408 	struct dccp_service_list *sl = NULL;
409 
410 	if (service == DCCP_SERVICE_INVALID_VALUE ||
411 	    optlen > DCCP_SERVICE_LIST_MAX_LEN * sizeof(u32))
412 		return -EINVAL;
413 
414 	if (optlen > sizeof(service)) {
415 		sl = kmalloc(optlen, GFP_KERNEL);
416 		if (sl == NULL)
417 			return -ENOMEM;
418 
419 		sl->dccpsl_nr = optlen / sizeof(u32) - 1;
420 		if (copy_from_user(sl->dccpsl_list,
421 				   optval + sizeof(service),
422 				   optlen - sizeof(service)) ||
423 		    dccp_list_has_service(sl, DCCP_SERVICE_INVALID_VALUE)) {
424 			kfree(sl);
425 			return -EFAULT;
426 		}
427 	}
428 
429 	lock_sock(sk);
430 	dp->dccps_service = service;
431 
432 	kfree(dp->dccps_service_list);
433 
434 	dp->dccps_service_list = sl;
435 	release_sock(sk);
436 	return 0;
437 }
438 
439 static int dccp_setsockopt_cscov(struct sock *sk, int cscov, bool rx)
440 {
441 	u8 *list, len;
442 	int i, rc;
443 
444 	if (cscov < 0 || cscov > 15)
445 		return -EINVAL;
446 	/*
447 	 * Populate a list of permissible values, in the range cscov...15. This
448 	 * is necessary since feature negotiation of single values only works if
449 	 * both sides incidentally choose the same value. Since the list starts
450 	 * lowest-value first, negotiation will pick the smallest shared value.
451 	 */
452 	if (cscov == 0)
453 		return 0;
454 	len = 16 - cscov;
455 
456 	list = kmalloc(len, GFP_KERNEL);
457 	if (list == NULL)
458 		return -ENOBUFS;
459 
460 	for (i = 0; i < len; i++)
461 		list[i] = cscov++;
462 
463 	rc = dccp_feat_register_sp(sk, DCCPF_MIN_CSUM_COVER, rx, list, len);
464 
465 	if (rc == 0) {
466 		if (rx)
467 			dccp_sk(sk)->dccps_pcrlen = cscov;
468 		else
469 			dccp_sk(sk)->dccps_pcslen = cscov;
470 	}
471 	kfree(list);
472 	return rc;
473 }
474 
475 static int dccp_setsockopt_ccid(struct sock *sk, int type,
476 				char __user *optval, unsigned int optlen)
477 {
478 	u8 *val;
479 	int rc = 0;
480 
481 	if (optlen < 1 || optlen > DCCP_FEAT_MAX_SP_VALS)
482 		return -EINVAL;
483 
484 	val = memdup_user(optval, optlen);
485 	if (IS_ERR(val))
486 		return PTR_ERR(val);
487 
488 	lock_sock(sk);
489 	if (type == DCCP_SOCKOPT_TX_CCID || type == DCCP_SOCKOPT_CCID)
490 		rc = dccp_feat_register_sp(sk, DCCPF_CCID, 1, val, optlen);
491 
492 	if (!rc && (type == DCCP_SOCKOPT_RX_CCID || type == DCCP_SOCKOPT_CCID))
493 		rc = dccp_feat_register_sp(sk, DCCPF_CCID, 0, val, optlen);
494 	release_sock(sk);
495 
496 	kfree(val);
497 	return rc;
498 }
499 
500 static int do_dccp_setsockopt(struct sock *sk, int level, int optname,
501 		char __user *optval, unsigned int optlen)
502 {
503 	struct dccp_sock *dp = dccp_sk(sk);
504 	int val, err = 0;
505 
506 	switch (optname) {
507 	case DCCP_SOCKOPT_PACKET_SIZE:
508 		DCCP_WARN("sockopt(PACKET_SIZE) is deprecated: fix your app\n");
509 		return 0;
510 	case DCCP_SOCKOPT_CHANGE_L:
511 	case DCCP_SOCKOPT_CHANGE_R:
512 		DCCP_WARN("sockopt(CHANGE_L/R) is deprecated: fix your app\n");
513 		return 0;
514 	case DCCP_SOCKOPT_CCID:
515 	case DCCP_SOCKOPT_RX_CCID:
516 	case DCCP_SOCKOPT_TX_CCID:
517 		return dccp_setsockopt_ccid(sk, optname, optval, optlen);
518 	}
519 
520 	if (optlen < (int)sizeof(int))
521 		return -EINVAL;
522 
523 	if (get_user(val, (int __user *)optval))
524 		return -EFAULT;
525 
526 	if (optname == DCCP_SOCKOPT_SERVICE)
527 		return dccp_setsockopt_service(sk, val, optval, optlen);
528 
529 	lock_sock(sk);
530 	switch (optname) {
531 	case DCCP_SOCKOPT_SERVER_TIMEWAIT:
532 		if (dp->dccps_role != DCCP_ROLE_SERVER)
533 			err = -EOPNOTSUPP;
534 		else
535 			dp->dccps_server_timewait = (val != 0);
536 		break;
537 	case DCCP_SOCKOPT_SEND_CSCOV:
538 		err = dccp_setsockopt_cscov(sk, val, false);
539 		break;
540 	case DCCP_SOCKOPT_RECV_CSCOV:
541 		err = dccp_setsockopt_cscov(sk, val, true);
542 		break;
543 	case DCCP_SOCKOPT_QPOLICY_ID:
544 		if (sk->sk_state != DCCP_CLOSED)
545 			err = -EISCONN;
546 		else if (val < 0 || val >= DCCPQ_POLICY_MAX)
547 			err = -EINVAL;
548 		else
549 			dp->dccps_qpolicy = val;
550 		break;
551 	case DCCP_SOCKOPT_QPOLICY_TXQLEN:
552 		if (val < 0)
553 			err = -EINVAL;
554 		else
555 			dp->dccps_tx_qlen = val;
556 		break;
557 	default:
558 		err = -ENOPROTOOPT;
559 		break;
560 	}
561 	release_sock(sk);
562 
563 	return err;
564 }
565 
566 int dccp_setsockopt(struct sock *sk, int level, int optname,
567 		    char __user *optval, unsigned int optlen)
568 {
569 	if (level != SOL_DCCP)
570 		return inet_csk(sk)->icsk_af_ops->setsockopt(sk, level,
571 							     optname, optval,
572 							     optlen);
573 	return do_dccp_setsockopt(sk, level, optname, optval, optlen);
574 }
575 
576 EXPORT_SYMBOL_GPL(dccp_setsockopt);
577 
578 static int dccp_getsockopt_service(struct sock *sk, int len,
579 				   __be32 __user *optval,
580 				   int __user *optlen)
581 {
582 	const struct dccp_sock *dp = dccp_sk(sk);
583 	const struct dccp_service_list *sl;
584 	int err = -ENOENT, slen = 0, total_len = sizeof(u32);
585 
586 	lock_sock(sk);
587 	if ((sl = dp->dccps_service_list) != NULL) {
588 		slen = sl->dccpsl_nr * sizeof(u32);
589 		total_len += slen;
590 	}
591 
592 	err = -EINVAL;
593 	if (total_len > len)
594 		goto out;
595 
596 	err = 0;
597 	if (put_user(total_len, optlen) ||
598 	    put_user(dp->dccps_service, optval) ||
599 	    (sl != NULL && copy_to_user(optval + 1, sl->dccpsl_list, slen)))
600 		err = -EFAULT;
601 out:
602 	release_sock(sk);
603 	return err;
604 }
605 
606 static int do_dccp_getsockopt(struct sock *sk, int level, int optname,
607 		    char __user *optval, int __user *optlen)
608 {
609 	struct dccp_sock *dp;
610 	int val, len;
611 
612 	if (get_user(len, optlen))
613 		return -EFAULT;
614 
615 	if (len < (int)sizeof(int))
616 		return -EINVAL;
617 
618 	dp = dccp_sk(sk);
619 
620 	switch (optname) {
621 	case DCCP_SOCKOPT_PACKET_SIZE:
622 		DCCP_WARN("sockopt(PACKET_SIZE) is deprecated: fix your app\n");
623 		return 0;
624 	case DCCP_SOCKOPT_SERVICE:
625 		return dccp_getsockopt_service(sk, len,
626 					       (__be32 __user *)optval, optlen);
627 	case DCCP_SOCKOPT_GET_CUR_MPS:
628 		val = dp->dccps_mss_cache;
629 		break;
630 	case DCCP_SOCKOPT_AVAILABLE_CCIDS:
631 		return ccid_getsockopt_builtin_ccids(sk, len, optval, optlen);
632 	case DCCP_SOCKOPT_TX_CCID:
633 		val = ccid_get_current_tx_ccid(dp);
634 		if (val < 0)
635 			return -ENOPROTOOPT;
636 		break;
637 	case DCCP_SOCKOPT_RX_CCID:
638 		val = ccid_get_current_rx_ccid(dp);
639 		if (val < 0)
640 			return -ENOPROTOOPT;
641 		break;
642 	case DCCP_SOCKOPT_SERVER_TIMEWAIT:
643 		val = dp->dccps_server_timewait;
644 		break;
645 	case DCCP_SOCKOPT_SEND_CSCOV:
646 		val = dp->dccps_pcslen;
647 		break;
648 	case DCCP_SOCKOPT_RECV_CSCOV:
649 		val = dp->dccps_pcrlen;
650 		break;
651 	case DCCP_SOCKOPT_QPOLICY_ID:
652 		val = dp->dccps_qpolicy;
653 		break;
654 	case DCCP_SOCKOPT_QPOLICY_TXQLEN:
655 		val = dp->dccps_tx_qlen;
656 		break;
657 	case 128 ... 191:
658 		return ccid_hc_rx_getsockopt(dp->dccps_hc_rx_ccid, sk, optname,
659 					     len, (u32 __user *)optval, optlen);
660 	case 192 ... 255:
661 		return ccid_hc_tx_getsockopt(dp->dccps_hc_tx_ccid, sk, optname,
662 					     len, (u32 __user *)optval, optlen);
663 	default:
664 		return -ENOPROTOOPT;
665 	}
666 
667 	len = sizeof(val);
668 	if (put_user(len, optlen) || copy_to_user(optval, &val, len))
669 		return -EFAULT;
670 
671 	return 0;
672 }
673 
674 int dccp_getsockopt(struct sock *sk, int level, int optname,
675 		    char __user *optval, int __user *optlen)
676 {
677 	if (level != SOL_DCCP)
678 		return inet_csk(sk)->icsk_af_ops->getsockopt(sk, level,
679 							     optname, optval,
680 							     optlen);
681 	return do_dccp_getsockopt(sk, level, optname, optval, optlen);
682 }
683 
684 EXPORT_SYMBOL_GPL(dccp_getsockopt);
685 
686 static int dccp_msghdr_parse(struct msghdr *msg, struct sk_buff *skb)
687 {
688 	struct cmsghdr *cmsg;
689 
690 	/*
691 	 * Assign an (opaque) qpolicy priority value to skb->priority.
692 	 *
693 	 * We are overloading this skb field for use with the qpolicy subystem.
694 	 * The skb->priority is normally used for the SO_PRIORITY option, which
695 	 * is initialised from sk_priority. Since the assignment of sk_priority
696 	 * to skb->priority happens later (on layer 3), we overload this field
697 	 * for use with queueing priorities as long as the skb is on layer 4.
698 	 * The default priority value (if nothing is set) is 0.
699 	 */
700 	skb->priority = 0;
701 
702 	for_each_cmsghdr(cmsg, msg) {
703 		if (!CMSG_OK(msg, cmsg))
704 			return -EINVAL;
705 
706 		if (cmsg->cmsg_level != SOL_DCCP)
707 			continue;
708 
709 		if (cmsg->cmsg_type <= DCCP_SCM_QPOLICY_MAX &&
710 		    !dccp_qpolicy_param_ok(skb->sk, cmsg->cmsg_type))
711 			return -EINVAL;
712 
713 		switch (cmsg->cmsg_type) {
714 		case DCCP_SCM_PRIORITY:
715 			if (cmsg->cmsg_len != CMSG_LEN(sizeof(__u32)))
716 				return -EINVAL;
717 			skb->priority = *(__u32 *)CMSG_DATA(cmsg);
718 			break;
719 		default:
720 			return -EINVAL;
721 		}
722 	}
723 	return 0;
724 }
725 
726 int dccp_sendmsg(struct sock *sk, struct msghdr *msg, size_t len)
727 {
728 	const struct dccp_sock *dp = dccp_sk(sk);
729 	const int flags = msg->msg_flags;
730 	const int noblock = flags & MSG_DONTWAIT;
731 	struct sk_buff *skb;
732 	int rc, size;
733 	long timeo;
734 
735 	trace_dccp_probe(sk, len);
736 
737 	if (len > dp->dccps_mss_cache)
738 		return -EMSGSIZE;
739 
740 	lock_sock(sk);
741 
742 	if (dccp_qpolicy_full(sk)) {
743 		rc = -EAGAIN;
744 		goto out_release;
745 	}
746 
747 	timeo = sock_sndtimeo(sk, noblock);
748 
749 	/*
750 	 * We have to use sk_stream_wait_connect here to set sk_write_pending,
751 	 * so that the trick in dccp_rcv_request_sent_state_process.
752 	 */
753 	/* Wait for a connection to finish. */
754 	if ((1 << sk->sk_state) & ~(DCCPF_OPEN | DCCPF_PARTOPEN))
755 		if ((rc = sk_stream_wait_connect(sk, &timeo)) != 0)
756 			goto out_release;
757 
758 	size = sk->sk_prot->max_header + len;
759 	release_sock(sk);
760 	skb = sock_alloc_send_skb(sk, size, noblock, &rc);
761 	lock_sock(sk);
762 	if (skb == NULL)
763 		goto out_release;
764 
765 	if (sk->sk_state == DCCP_CLOSED) {
766 		rc = -ENOTCONN;
767 		goto out_discard;
768 	}
769 
770 	skb_reserve(skb, sk->sk_prot->max_header);
771 	rc = memcpy_from_msg(skb_put(skb, len), msg, len);
772 	if (rc != 0)
773 		goto out_discard;
774 
775 	rc = dccp_msghdr_parse(msg, skb);
776 	if (rc != 0)
777 		goto out_discard;
778 
779 	dccp_qpolicy_push(sk, skb);
780 	/*
781 	 * The xmit_timer is set if the TX CCID is rate-based and will expire
782 	 * when congestion control permits to release further packets into the
783 	 * network. Window-based CCIDs do not use this timer.
784 	 */
785 	if (!timer_pending(&dp->dccps_xmit_timer))
786 		dccp_write_xmit(sk);
787 out_release:
788 	release_sock(sk);
789 	return rc ? : len;
790 out_discard:
791 	kfree_skb(skb);
792 	goto out_release;
793 }
794 
795 EXPORT_SYMBOL_GPL(dccp_sendmsg);
796 
797 int dccp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int nonblock,
798 		 int flags, int *addr_len)
799 {
800 	const struct dccp_hdr *dh;
801 	long timeo;
802 
803 	lock_sock(sk);
804 
805 	if (sk->sk_state == DCCP_LISTEN) {
806 		len = -ENOTCONN;
807 		goto out;
808 	}
809 
810 	timeo = sock_rcvtimeo(sk, nonblock);
811 
812 	do {
813 		struct sk_buff *skb = skb_peek(&sk->sk_receive_queue);
814 
815 		if (skb == NULL)
816 			goto verify_sock_status;
817 
818 		dh = dccp_hdr(skb);
819 
820 		switch (dh->dccph_type) {
821 		case DCCP_PKT_DATA:
822 		case DCCP_PKT_DATAACK:
823 			goto found_ok_skb;
824 
825 		case DCCP_PKT_CLOSE:
826 		case DCCP_PKT_CLOSEREQ:
827 			if (!(flags & MSG_PEEK))
828 				dccp_finish_passive_close(sk);
829 			/* fall through */
830 		case DCCP_PKT_RESET:
831 			dccp_pr_debug("found fin (%s) ok!\n",
832 				      dccp_packet_name(dh->dccph_type));
833 			len = 0;
834 			goto found_fin_ok;
835 		default:
836 			dccp_pr_debug("packet_type=%s\n",
837 				      dccp_packet_name(dh->dccph_type));
838 			sk_eat_skb(sk, skb);
839 		}
840 verify_sock_status:
841 		if (sock_flag(sk, SOCK_DONE)) {
842 			len = 0;
843 			break;
844 		}
845 
846 		if (sk->sk_err) {
847 			len = sock_error(sk);
848 			break;
849 		}
850 
851 		if (sk->sk_shutdown & RCV_SHUTDOWN) {
852 			len = 0;
853 			break;
854 		}
855 
856 		if (sk->sk_state == DCCP_CLOSED) {
857 			if (!sock_flag(sk, SOCK_DONE)) {
858 				/* This occurs when user tries to read
859 				 * from never connected socket.
860 				 */
861 				len = -ENOTCONN;
862 				break;
863 			}
864 			len = 0;
865 			break;
866 		}
867 
868 		if (!timeo) {
869 			len = -EAGAIN;
870 			break;
871 		}
872 
873 		if (signal_pending(current)) {
874 			len = sock_intr_errno(timeo);
875 			break;
876 		}
877 
878 		sk_wait_data(sk, &timeo, NULL);
879 		continue;
880 	found_ok_skb:
881 		if (len > skb->len)
882 			len = skb->len;
883 		else if (len < skb->len)
884 			msg->msg_flags |= MSG_TRUNC;
885 
886 		if (skb_copy_datagram_msg(skb, 0, msg, len)) {
887 			/* Exception. Bailout! */
888 			len = -EFAULT;
889 			break;
890 		}
891 		if (flags & MSG_TRUNC)
892 			len = skb->len;
893 	found_fin_ok:
894 		if (!(flags & MSG_PEEK))
895 			sk_eat_skb(sk, skb);
896 		break;
897 	} while (1);
898 out:
899 	release_sock(sk);
900 	return len;
901 }
902 
903 EXPORT_SYMBOL_GPL(dccp_recvmsg);
904 
905 int inet_dccp_listen(struct socket *sock, int backlog)
906 {
907 	struct sock *sk = sock->sk;
908 	unsigned char old_state;
909 	int err;
910 
911 	lock_sock(sk);
912 
913 	err = -EINVAL;
914 	if (sock->state != SS_UNCONNECTED || sock->type != SOCK_DCCP)
915 		goto out;
916 
917 	old_state = sk->sk_state;
918 	if (!((1 << old_state) & (DCCPF_CLOSED | DCCPF_LISTEN)))
919 		goto out;
920 
921 	WRITE_ONCE(sk->sk_max_ack_backlog, backlog);
922 	/* Really, if the socket is already in listen state
923 	 * we can only allow the backlog to be adjusted.
924 	 */
925 	if (old_state != DCCP_LISTEN) {
926 		/*
927 		 * FIXME: here it probably should be sk->sk_prot->listen_start
928 		 * see tcp_listen_start
929 		 */
930 		err = dccp_listen_start(sk, backlog);
931 		if (err)
932 			goto out;
933 	}
934 	err = 0;
935 
936 out:
937 	release_sock(sk);
938 	return err;
939 }
940 
941 EXPORT_SYMBOL_GPL(inet_dccp_listen);
942 
943 static void dccp_terminate_connection(struct sock *sk)
944 {
945 	u8 next_state = DCCP_CLOSED;
946 
947 	switch (sk->sk_state) {
948 	case DCCP_PASSIVE_CLOSE:
949 	case DCCP_PASSIVE_CLOSEREQ:
950 		dccp_finish_passive_close(sk);
951 		break;
952 	case DCCP_PARTOPEN:
953 		dccp_pr_debug("Stop PARTOPEN timer (%p)\n", sk);
954 		inet_csk_clear_xmit_timer(sk, ICSK_TIME_DACK);
955 		/* fall through */
956 	case DCCP_OPEN:
957 		dccp_send_close(sk, 1);
958 
959 		if (dccp_sk(sk)->dccps_role == DCCP_ROLE_SERVER &&
960 		    !dccp_sk(sk)->dccps_server_timewait)
961 			next_state = DCCP_ACTIVE_CLOSEREQ;
962 		else
963 			next_state = DCCP_CLOSING;
964 		/* fall through */
965 	default:
966 		dccp_set_state(sk, next_state);
967 	}
968 }
969 
970 void dccp_close(struct sock *sk, long timeout)
971 {
972 	struct dccp_sock *dp = dccp_sk(sk);
973 	struct sk_buff *skb;
974 	u32 data_was_unread = 0;
975 	int state;
976 
977 	lock_sock(sk);
978 
979 	sk->sk_shutdown = SHUTDOWN_MASK;
980 
981 	if (sk->sk_state == DCCP_LISTEN) {
982 		dccp_set_state(sk, DCCP_CLOSED);
983 
984 		/* Special case. */
985 		inet_csk_listen_stop(sk);
986 
987 		goto adjudge_to_death;
988 	}
989 
990 	sk_stop_timer(sk, &dp->dccps_xmit_timer);
991 
992 	/*
993 	 * We need to flush the recv. buffs.  We do this only on the
994 	 * descriptor close, not protocol-sourced closes, because the
995 	  *reader process may not have drained the data yet!
996 	 */
997 	while ((skb = __skb_dequeue(&sk->sk_receive_queue)) != NULL) {
998 		data_was_unread += skb->len;
999 		__kfree_skb(skb);
1000 	}
1001 
1002 	/* If socket has been already reset kill it. */
1003 	if (sk->sk_state == DCCP_CLOSED)
1004 		goto adjudge_to_death;
1005 
1006 	if (data_was_unread) {
1007 		/* Unread data was tossed, send an appropriate Reset Code */
1008 		DCCP_WARN("ABORT with %u bytes unread\n", data_was_unread);
1009 		dccp_send_reset(sk, DCCP_RESET_CODE_ABORTED);
1010 		dccp_set_state(sk, DCCP_CLOSED);
1011 	} else if (sock_flag(sk, SOCK_LINGER) && !sk->sk_lingertime) {
1012 		/* Check zero linger _after_ checking for unread data. */
1013 		sk->sk_prot->disconnect(sk, 0);
1014 	} else if (sk->sk_state != DCCP_CLOSED) {
1015 		/*
1016 		 * Normal connection termination. May need to wait if there are
1017 		 * still packets in the TX queue that are delayed by the CCID.
1018 		 */
1019 		dccp_flush_write_queue(sk, &timeout);
1020 		dccp_terminate_connection(sk);
1021 	}
1022 
1023 	/*
1024 	 * Flush write queue. This may be necessary in several cases:
1025 	 * - we have been closed by the peer but still have application data;
1026 	 * - abortive termination (unread data or zero linger time),
1027 	 * - normal termination but queue could not be flushed within time limit
1028 	 */
1029 	__skb_queue_purge(&sk->sk_write_queue);
1030 
1031 	sk_stream_wait_close(sk, timeout);
1032 
1033 adjudge_to_death:
1034 	state = sk->sk_state;
1035 	sock_hold(sk);
1036 	sock_orphan(sk);
1037 
1038 	/*
1039 	 * It is the last release_sock in its life. It will remove backlog.
1040 	 */
1041 	release_sock(sk);
1042 	/*
1043 	 * Now socket is owned by kernel and we acquire BH lock
1044 	 * to finish close. No need to check for user refs.
1045 	 */
1046 	local_bh_disable();
1047 	bh_lock_sock(sk);
1048 	WARN_ON(sock_owned_by_user(sk));
1049 
1050 	percpu_counter_inc(sk->sk_prot->orphan_count);
1051 
1052 	/* Have we already been destroyed by a softirq or backlog? */
1053 	if (state != DCCP_CLOSED && sk->sk_state == DCCP_CLOSED)
1054 		goto out;
1055 
1056 	if (sk->sk_state == DCCP_CLOSED)
1057 		inet_csk_destroy_sock(sk);
1058 
1059 	/* Otherwise, socket is reprieved until protocol close. */
1060 
1061 out:
1062 	bh_unlock_sock(sk);
1063 	local_bh_enable();
1064 	sock_put(sk);
1065 }
1066 
1067 EXPORT_SYMBOL_GPL(dccp_close);
1068 
1069 void dccp_shutdown(struct sock *sk, int how)
1070 {
1071 	dccp_pr_debug("called shutdown(%x)\n", how);
1072 }
1073 
1074 EXPORT_SYMBOL_GPL(dccp_shutdown);
1075 
1076 static inline int __init dccp_mib_init(void)
1077 {
1078 	dccp_statistics = alloc_percpu(struct dccp_mib);
1079 	if (!dccp_statistics)
1080 		return -ENOMEM;
1081 	return 0;
1082 }
1083 
1084 static inline void dccp_mib_exit(void)
1085 {
1086 	free_percpu(dccp_statistics);
1087 }
1088 
1089 static int thash_entries;
1090 module_param(thash_entries, int, 0444);
1091 MODULE_PARM_DESC(thash_entries, "Number of ehash buckets");
1092 
1093 #ifdef CONFIG_IP_DCCP_DEBUG
1094 bool dccp_debug;
1095 module_param(dccp_debug, bool, 0644);
1096 MODULE_PARM_DESC(dccp_debug, "Enable debug messages");
1097 
1098 EXPORT_SYMBOL_GPL(dccp_debug);
1099 #endif
1100 
1101 static int __init dccp_init(void)
1102 {
1103 	unsigned long goal;
1104 	unsigned long nr_pages = totalram_pages();
1105 	int ehash_order, bhash_order, i;
1106 	int rc;
1107 
1108 	BUILD_BUG_ON(sizeof(struct dccp_skb_cb) >
1109 		     sizeof_field(struct sk_buff, cb));
1110 	rc = percpu_counter_init(&dccp_orphan_count, 0, GFP_KERNEL);
1111 	if (rc)
1112 		goto out_fail;
1113 	inet_hashinfo_init(&dccp_hashinfo);
1114 	rc = inet_hashinfo2_init_mod(&dccp_hashinfo);
1115 	if (rc)
1116 		goto out_free_percpu;
1117 	rc = -ENOBUFS;
1118 	dccp_hashinfo.bind_bucket_cachep =
1119 		kmem_cache_create("dccp_bind_bucket",
1120 				  sizeof(struct inet_bind_bucket), 0,
1121 				  SLAB_HWCACHE_ALIGN, NULL);
1122 	if (!dccp_hashinfo.bind_bucket_cachep)
1123 		goto out_free_hashinfo2;
1124 
1125 	/*
1126 	 * Size and allocate the main established and bind bucket
1127 	 * hash tables.
1128 	 *
1129 	 * The methodology is similar to that of the buffer cache.
1130 	 */
1131 	if (nr_pages >= (128 * 1024))
1132 		goal = nr_pages >> (21 - PAGE_SHIFT);
1133 	else
1134 		goal = nr_pages >> (23 - PAGE_SHIFT);
1135 
1136 	if (thash_entries)
1137 		goal = (thash_entries *
1138 			sizeof(struct inet_ehash_bucket)) >> PAGE_SHIFT;
1139 	for (ehash_order = 0; (1UL << ehash_order) < goal; ehash_order++)
1140 		;
1141 	do {
1142 		unsigned long hash_size = (1UL << ehash_order) * PAGE_SIZE /
1143 					sizeof(struct inet_ehash_bucket);
1144 
1145 		while (hash_size & (hash_size - 1))
1146 			hash_size--;
1147 		dccp_hashinfo.ehash_mask = hash_size - 1;
1148 		dccp_hashinfo.ehash = (struct inet_ehash_bucket *)
1149 			__get_free_pages(GFP_ATOMIC|__GFP_NOWARN, ehash_order);
1150 	} while (!dccp_hashinfo.ehash && --ehash_order > 0);
1151 
1152 	if (!dccp_hashinfo.ehash) {
1153 		DCCP_CRIT("Failed to allocate DCCP established hash table");
1154 		goto out_free_bind_bucket_cachep;
1155 	}
1156 
1157 	for (i = 0; i <= dccp_hashinfo.ehash_mask; i++)
1158 		INIT_HLIST_NULLS_HEAD(&dccp_hashinfo.ehash[i].chain, i);
1159 
1160 	if (inet_ehash_locks_alloc(&dccp_hashinfo))
1161 			goto out_free_dccp_ehash;
1162 
1163 	bhash_order = ehash_order;
1164 
1165 	do {
1166 		dccp_hashinfo.bhash_size = (1UL << bhash_order) * PAGE_SIZE /
1167 					sizeof(struct inet_bind_hashbucket);
1168 		if ((dccp_hashinfo.bhash_size > (64 * 1024)) &&
1169 		    bhash_order > 0)
1170 			continue;
1171 		dccp_hashinfo.bhash = (struct inet_bind_hashbucket *)
1172 			__get_free_pages(GFP_ATOMIC|__GFP_NOWARN, bhash_order);
1173 	} while (!dccp_hashinfo.bhash && --bhash_order >= 0);
1174 
1175 	if (!dccp_hashinfo.bhash) {
1176 		DCCP_CRIT("Failed to allocate DCCP bind hash table");
1177 		goto out_free_dccp_locks;
1178 	}
1179 
1180 	for (i = 0; i < dccp_hashinfo.bhash_size; i++) {
1181 		spin_lock_init(&dccp_hashinfo.bhash[i].lock);
1182 		INIT_HLIST_HEAD(&dccp_hashinfo.bhash[i].chain);
1183 	}
1184 
1185 	rc = dccp_mib_init();
1186 	if (rc)
1187 		goto out_free_dccp_bhash;
1188 
1189 	rc = dccp_ackvec_init();
1190 	if (rc)
1191 		goto out_free_dccp_mib;
1192 
1193 	rc = dccp_sysctl_init();
1194 	if (rc)
1195 		goto out_ackvec_exit;
1196 
1197 	rc = ccid_initialize_builtins();
1198 	if (rc)
1199 		goto out_sysctl_exit;
1200 
1201 	dccp_timestamping_init();
1202 
1203 	return 0;
1204 
1205 out_sysctl_exit:
1206 	dccp_sysctl_exit();
1207 out_ackvec_exit:
1208 	dccp_ackvec_exit();
1209 out_free_dccp_mib:
1210 	dccp_mib_exit();
1211 out_free_dccp_bhash:
1212 	free_pages((unsigned long)dccp_hashinfo.bhash, bhash_order);
1213 out_free_dccp_locks:
1214 	inet_ehash_locks_free(&dccp_hashinfo);
1215 out_free_dccp_ehash:
1216 	free_pages((unsigned long)dccp_hashinfo.ehash, ehash_order);
1217 out_free_bind_bucket_cachep:
1218 	kmem_cache_destroy(dccp_hashinfo.bind_bucket_cachep);
1219 out_free_hashinfo2:
1220 	inet_hashinfo2_free_mod(&dccp_hashinfo);
1221 out_free_percpu:
1222 	percpu_counter_destroy(&dccp_orphan_count);
1223 out_fail:
1224 	dccp_hashinfo.bhash = NULL;
1225 	dccp_hashinfo.ehash = NULL;
1226 	dccp_hashinfo.bind_bucket_cachep = NULL;
1227 	return rc;
1228 }
1229 
1230 static void __exit dccp_fini(void)
1231 {
1232 	ccid_cleanup_builtins();
1233 	dccp_mib_exit();
1234 	free_pages((unsigned long)dccp_hashinfo.bhash,
1235 		   get_order(dccp_hashinfo.bhash_size *
1236 			     sizeof(struct inet_bind_hashbucket)));
1237 	free_pages((unsigned long)dccp_hashinfo.ehash,
1238 		   get_order((dccp_hashinfo.ehash_mask + 1) *
1239 			     sizeof(struct inet_ehash_bucket)));
1240 	inet_ehash_locks_free(&dccp_hashinfo);
1241 	kmem_cache_destroy(dccp_hashinfo.bind_bucket_cachep);
1242 	dccp_ackvec_exit();
1243 	dccp_sysctl_exit();
1244 	inet_hashinfo2_free_mod(&dccp_hashinfo);
1245 	percpu_counter_destroy(&dccp_orphan_count);
1246 }
1247 
1248 module_init(dccp_init);
1249 module_exit(dccp_fini);
1250 
1251 MODULE_LICENSE("GPL");
1252 MODULE_AUTHOR("Arnaldo Carvalho de Melo <acme@conectiva.com.br>");
1253 MODULE_DESCRIPTION("DCCP - Datagram Congestion Controlled Protocol");
1254