12874c5fdSThomas Gleixner // SPDX-License-Identifier: GPL-2.0-or-later
21da177e4SLinus Torvalds /*
31da177e4SLinus Torvalds *
41da177e4SLinus Torvalds * Copyright Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
51da177e4SLinus Torvalds */
61da177e4SLinus Torvalds #include <linux/errno.h>
71da177e4SLinus Torvalds #include <linux/types.h>
81da177e4SLinus Torvalds #include <linux/socket.h>
91da177e4SLinus Torvalds #include <linux/in.h>
101da177e4SLinus Torvalds #include <linux/kernel.h>
111da177e4SLinus Torvalds #include <linux/timer.h>
121da177e4SLinus Torvalds #include <linux/string.h>
131da177e4SLinus Torvalds #include <linux/sockios.h>
141da177e4SLinus Torvalds #include <linux/net.h>
155a0e3ad6STejun Heo #include <linux/slab.h>
161da177e4SLinus Torvalds #include <net/ax25.h>
171da177e4SLinus Torvalds #include <linux/inet.h>
181da177e4SLinus Torvalds #include <linux/netdevice.h>
191da177e4SLinus Torvalds #include <linux/skbuff.h>
201da177e4SLinus Torvalds #include <net/sock.h>
21c752f073SArnaldo Carvalho de Melo #include <net/tcp_states.h>
22dc8e5416SFabian Frederick #include <linux/uaccess.h>
231da177e4SLinus Torvalds #include <linux/fcntl.h>
241da177e4SLinus Torvalds #include <linux/mm.h>
251da177e4SLinus Torvalds #include <linux/interrupt.h>
261da177e4SLinus Torvalds #include <net/netrom.h>
271da177e4SLinus Torvalds
281da177e4SLinus Torvalds /*
291da177e4SLinus Torvalds * This routine purges all of the queues of frames.
301da177e4SLinus Torvalds */
nr_clear_queues(struct sock * sk)311da177e4SLinus Torvalds void nr_clear_queues(struct sock *sk)
321da177e4SLinus Torvalds {
331da177e4SLinus Torvalds struct nr_sock *nr = nr_sk(sk);
341da177e4SLinus Torvalds
351da177e4SLinus Torvalds skb_queue_purge(&sk->sk_write_queue);
361da177e4SLinus Torvalds skb_queue_purge(&nr->ack_queue);
371da177e4SLinus Torvalds skb_queue_purge(&nr->reseq_queue);
381da177e4SLinus Torvalds skb_queue_purge(&nr->frag_queue);
391da177e4SLinus Torvalds }
401da177e4SLinus Torvalds
411da177e4SLinus Torvalds /*
421da177e4SLinus Torvalds * This routine purges the input queue of those frames that have been
431da177e4SLinus Torvalds * acknowledged. This replaces the boxes labelled "V(a) <- N(r)" on the
441da177e4SLinus Torvalds * SDL diagram.
451da177e4SLinus Torvalds */
nr_frames_acked(struct sock * sk,unsigned short nr)461da177e4SLinus Torvalds void nr_frames_acked(struct sock *sk, unsigned short nr)
471da177e4SLinus Torvalds {
481da177e4SLinus Torvalds struct nr_sock *nrom = nr_sk(sk);
491da177e4SLinus Torvalds struct sk_buff *skb;
501da177e4SLinus Torvalds
511da177e4SLinus Torvalds /*
521da177e4SLinus Torvalds * Remove all the ack-ed frames from the ack queue.
531da177e4SLinus Torvalds */
541da177e4SLinus Torvalds if (nrom->va != nr) {
551da177e4SLinus Torvalds while (skb_peek(&nrom->ack_queue) != NULL && nrom->va != nr) {
561da177e4SLinus Torvalds skb = skb_dequeue(&nrom->ack_queue);
571da177e4SLinus Torvalds kfree_skb(skb);
581da177e4SLinus Torvalds nrom->va = (nrom->va + 1) % NR_MODULUS;
591da177e4SLinus Torvalds }
601da177e4SLinus Torvalds }
611da177e4SLinus Torvalds }
621da177e4SLinus Torvalds
631da177e4SLinus Torvalds /*
641da177e4SLinus Torvalds * Requeue all the un-ack-ed frames on the output queue to be picked
651da177e4SLinus Torvalds * up by nr_kick called from the timer. This arrangement handles the
661da177e4SLinus Torvalds * possibility of an empty output queue.
671da177e4SLinus Torvalds */
nr_requeue_frames(struct sock * sk)681da177e4SLinus Torvalds void nr_requeue_frames(struct sock *sk)
691da177e4SLinus Torvalds {
701da177e4SLinus Torvalds struct sk_buff *skb, *skb_prev = NULL;
711da177e4SLinus Torvalds
721da177e4SLinus Torvalds while ((skb = skb_dequeue(&nr_sk(sk)->ack_queue)) != NULL) {
731da177e4SLinus Torvalds if (skb_prev == NULL)
741da177e4SLinus Torvalds skb_queue_head(&sk->sk_write_queue, skb);
751da177e4SLinus Torvalds else
768728b834SDavid S. Miller skb_append(skb_prev, skb, &sk->sk_write_queue);
771da177e4SLinus Torvalds skb_prev = skb;
781da177e4SLinus Torvalds }
791da177e4SLinus Torvalds }
801da177e4SLinus Torvalds
811da177e4SLinus Torvalds /*
821da177e4SLinus Torvalds * Validate that the value of nr is between va and vs. Return true or
831da177e4SLinus Torvalds * false for testing.
841da177e4SLinus Torvalds */
nr_validate_nr(struct sock * sk,unsigned short nr)851da177e4SLinus Torvalds int nr_validate_nr(struct sock *sk, unsigned short nr)
861da177e4SLinus Torvalds {
871da177e4SLinus Torvalds struct nr_sock *nrom = nr_sk(sk);
881da177e4SLinus Torvalds unsigned short vc = nrom->va;
891da177e4SLinus Torvalds
901da177e4SLinus Torvalds while (vc != nrom->vs) {
911da177e4SLinus Torvalds if (nr == vc) return 1;
921da177e4SLinus Torvalds vc = (vc + 1) % NR_MODULUS;
931da177e4SLinus Torvalds }
941da177e4SLinus Torvalds
951da177e4SLinus Torvalds return nr == nrom->vs;
961da177e4SLinus Torvalds }
971da177e4SLinus Torvalds
981da177e4SLinus Torvalds /*
991da177e4SLinus Torvalds * Check that ns is within the receive window.
1001da177e4SLinus Torvalds */
nr_in_rx_window(struct sock * sk,unsigned short ns)1011da177e4SLinus Torvalds int nr_in_rx_window(struct sock *sk, unsigned short ns)
1021da177e4SLinus Torvalds {
1031da177e4SLinus Torvalds struct nr_sock *nr = nr_sk(sk);
1041da177e4SLinus Torvalds unsigned short vc = nr->vr;
1051da177e4SLinus Torvalds unsigned short vt = (nr->vl + nr->window) % NR_MODULUS;
1061da177e4SLinus Torvalds
1071da177e4SLinus Torvalds while (vc != vt) {
1081da177e4SLinus Torvalds if (ns == vc) return 1;
1091da177e4SLinus Torvalds vc = (vc + 1) % NR_MODULUS;
1101da177e4SLinus Torvalds }
1111da177e4SLinus Torvalds
1121da177e4SLinus Torvalds return 0;
1131da177e4SLinus Torvalds }
1141da177e4SLinus Torvalds
1151da177e4SLinus Torvalds /*
1161da177e4SLinus Torvalds * This routine is called when the HDLC layer internally generates a
1171da177e4SLinus Torvalds * control frame.
1181da177e4SLinus Torvalds */
nr_write_internal(struct sock * sk,int frametype)1191da177e4SLinus Torvalds void nr_write_internal(struct sock *sk, int frametype)
1201da177e4SLinus Torvalds {
1211da177e4SLinus Torvalds struct nr_sock *nr = nr_sk(sk);
1221da177e4SLinus Torvalds struct sk_buff *skb;
1231da177e4SLinus Torvalds unsigned char *dptr;
1241da177e4SLinus Torvalds int len, timeout;
1251da177e4SLinus Torvalds
12631642e70SEric Dumazet len = NR_TRANSPORT_LEN;
1271da177e4SLinus Torvalds
1281da177e4SLinus Torvalds switch (frametype & 0x0F) {
1291da177e4SLinus Torvalds case NR_CONNREQ:
1301da177e4SLinus Torvalds len += 17;
1311da177e4SLinus Torvalds break;
1321da177e4SLinus Torvalds case NR_CONNACK:
1331da177e4SLinus Torvalds len += (nr->bpqext) ? 2 : 1;
1341da177e4SLinus Torvalds break;
1351da177e4SLinus Torvalds case NR_DISCREQ:
1361da177e4SLinus Torvalds case NR_DISCACK:
1371da177e4SLinus Torvalds case NR_INFOACK:
1381da177e4SLinus Torvalds break;
1391da177e4SLinus Torvalds default:
1401da177e4SLinus Torvalds printk(KERN_ERR "NET/ROM: nr_write_internal - invalid frame type %d\n", frametype);
1411da177e4SLinus Torvalds return;
1421da177e4SLinus Torvalds }
1431da177e4SLinus Torvalds
14431642e70SEric Dumazet skb = alloc_skb(NR_NETWORK_LEN + len, GFP_ATOMIC);
14531642e70SEric Dumazet if (!skb)
1461da177e4SLinus Torvalds return;
1471da177e4SLinus Torvalds
1481da177e4SLinus Torvalds /*
1491da177e4SLinus Torvalds * Space for AX.25 and NET/ROM network header
1501da177e4SLinus Torvalds */
1511da177e4SLinus Torvalds skb_reserve(skb, NR_NETWORK_LEN);
1521da177e4SLinus Torvalds
15331642e70SEric Dumazet dptr = skb_put(skb, len);
1541da177e4SLinus Torvalds
1551da177e4SLinus Torvalds switch (frametype & 0x0F) {
1561da177e4SLinus Torvalds case NR_CONNREQ:
1571da177e4SLinus Torvalds timeout = nr->t1 / HZ;
1581da177e4SLinus Torvalds *dptr++ = nr->my_index;
1591da177e4SLinus Torvalds *dptr++ = nr->my_id;
1601da177e4SLinus Torvalds *dptr++ = 0;
1611da177e4SLinus Torvalds *dptr++ = 0;
1621da177e4SLinus Torvalds *dptr++ = frametype;
1631da177e4SLinus Torvalds *dptr++ = nr->window;
1641da177e4SLinus Torvalds memcpy(dptr, &nr->user_addr, AX25_ADDR_LEN);
1651da177e4SLinus Torvalds dptr[6] &= ~AX25_CBIT;
1661da177e4SLinus Torvalds dptr[6] &= ~AX25_EBIT;
1671da177e4SLinus Torvalds dptr[6] |= AX25_SSSID_SPARE;
1681da177e4SLinus Torvalds dptr += AX25_ADDR_LEN;
1691da177e4SLinus Torvalds memcpy(dptr, &nr->source_addr, AX25_ADDR_LEN);
1701da177e4SLinus Torvalds dptr[6] &= ~AX25_CBIT;
1711da177e4SLinus Torvalds dptr[6] &= ~AX25_EBIT;
1721da177e4SLinus Torvalds dptr[6] |= AX25_SSSID_SPARE;
1731da177e4SLinus Torvalds dptr += AX25_ADDR_LEN;
1741da177e4SLinus Torvalds *dptr++ = timeout % 256;
1751da177e4SLinus Torvalds *dptr++ = timeout / 256;
1761da177e4SLinus Torvalds break;
1771da177e4SLinus Torvalds
1781da177e4SLinus Torvalds case NR_CONNACK:
1791da177e4SLinus Torvalds *dptr++ = nr->your_index;
1801da177e4SLinus Torvalds *dptr++ = nr->your_id;
1811da177e4SLinus Torvalds *dptr++ = nr->my_index;
1821da177e4SLinus Torvalds *dptr++ = nr->my_id;
1831da177e4SLinus Torvalds *dptr++ = frametype;
1841da177e4SLinus Torvalds *dptr++ = nr->window;
185*5731369aSJason Xing if (nr->bpqext)
186*5731369aSJason Xing *dptr++ = READ_ONCE(sysctl_netrom_network_ttl_initialiser);
1871da177e4SLinus Torvalds break;
1881da177e4SLinus Torvalds
1891da177e4SLinus Torvalds case NR_DISCREQ:
1901da177e4SLinus Torvalds case NR_DISCACK:
1911da177e4SLinus Torvalds *dptr++ = nr->your_index;
1921da177e4SLinus Torvalds *dptr++ = nr->your_id;
1931da177e4SLinus Torvalds *dptr++ = 0;
1941da177e4SLinus Torvalds *dptr++ = 0;
1951da177e4SLinus Torvalds *dptr++ = frametype;
1961da177e4SLinus Torvalds break;
1971da177e4SLinus Torvalds
1981da177e4SLinus Torvalds case NR_INFOACK:
1991da177e4SLinus Torvalds *dptr++ = nr->your_index;
2001da177e4SLinus Torvalds *dptr++ = nr->your_id;
2011da177e4SLinus Torvalds *dptr++ = 0;
2021da177e4SLinus Torvalds *dptr++ = nr->vr;
2031da177e4SLinus Torvalds *dptr++ = frametype;
2041da177e4SLinus Torvalds break;
2051da177e4SLinus Torvalds }
2061da177e4SLinus Torvalds
2071da177e4SLinus Torvalds nr_transmit_buffer(sk, skb);
2081da177e4SLinus Torvalds }
2091da177e4SLinus Torvalds
2101da177e4SLinus Torvalds /*
211e21ce8c7SRalf Baechle * This routine is called to send an error reply.
2121da177e4SLinus Torvalds */
__nr_transmit_reply(struct sk_buff * skb,int mine,unsigned char cmdflags)213e21ce8c7SRalf Baechle void __nr_transmit_reply(struct sk_buff *skb, int mine, unsigned char cmdflags)
2141da177e4SLinus Torvalds {
2151da177e4SLinus Torvalds struct sk_buff *skbn;
2161da177e4SLinus Torvalds unsigned char *dptr;
2171da177e4SLinus Torvalds int len;
2181da177e4SLinus Torvalds
2191da177e4SLinus Torvalds len = NR_NETWORK_LEN + NR_TRANSPORT_LEN + 1;
2201da177e4SLinus Torvalds
2211da177e4SLinus Torvalds if ((skbn = alloc_skb(len, GFP_ATOMIC)) == NULL)
2221da177e4SLinus Torvalds return;
2231da177e4SLinus Torvalds
2241da177e4SLinus Torvalds skb_reserve(skbn, 0);
2251da177e4SLinus Torvalds
2261da177e4SLinus Torvalds dptr = skb_put(skbn, NR_NETWORK_LEN + NR_TRANSPORT_LEN);
2271da177e4SLinus Torvalds
228d626f62bSArnaldo Carvalho de Melo skb_copy_from_linear_data_offset(skb, 7, dptr, AX25_ADDR_LEN);
2291da177e4SLinus Torvalds dptr[6] &= ~AX25_CBIT;
2301da177e4SLinus Torvalds dptr[6] &= ~AX25_EBIT;
2311da177e4SLinus Torvalds dptr[6] |= AX25_SSSID_SPARE;
2321da177e4SLinus Torvalds dptr += AX25_ADDR_LEN;
2331da177e4SLinus Torvalds
234d626f62bSArnaldo Carvalho de Melo skb_copy_from_linear_data(skb, dptr, AX25_ADDR_LEN);
2351da177e4SLinus Torvalds dptr[6] &= ~AX25_CBIT;
2361da177e4SLinus Torvalds dptr[6] |= AX25_EBIT;
2371da177e4SLinus Torvalds dptr[6] |= AX25_SSSID_SPARE;
2381da177e4SLinus Torvalds dptr += AX25_ADDR_LEN;
2391da177e4SLinus Torvalds
240*5731369aSJason Xing *dptr++ = READ_ONCE(sysctl_netrom_network_ttl_initialiser);
2411da177e4SLinus Torvalds
2421da177e4SLinus Torvalds if (mine) {
2431da177e4SLinus Torvalds *dptr++ = 0;
2441da177e4SLinus Torvalds *dptr++ = 0;
2451da177e4SLinus Torvalds *dptr++ = skb->data[15];
2461da177e4SLinus Torvalds *dptr++ = skb->data[16];
2471da177e4SLinus Torvalds } else {
2481da177e4SLinus Torvalds *dptr++ = skb->data[15];
2491da177e4SLinus Torvalds *dptr++ = skb->data[16];
2501da177e4SLinus Torvalds *dptr++ = 0;
2511da177e4SLinus Torvalds *dptr++ = 0;
2521da177e4SLinus Torvalds }
2531da177e4SLinus Torvalds
254e21ce8c7SRalf Baechle *dptr++ = cmdflags;
2551da177e4SLinus Torvalds *dptr++ = 0;
2561da177e4SLinus Torvalds
2571da177e4SLinus Torvalds if (!nr_route_frame(skbn, NULL))
2581da177e4SLinus Torvalds kfree_skb(skbn);
2591da177e4SLinus Torvalds }
2601da177e4SLinus Torvalds
nr_disconnect(struct sock * sk,int reason)2611da177e4SLinus Torvalds void nr_disconnect(struct sock *sk, int reason)
2621da177e4SLinus Torvalds {
2631da177e4SLinus Torvalds nr_stop_t1timer(sk);
2641da177e4SLinus Torvalds nr_stop_t2timer(sk);
2651da177e4SLinus Torvalds nr_stop_t4timer(sk);
2661da177e4SLinus Torvalds nr_stop_idletimer(sk);
2671da177e4SLinus Torvalds
2681da177e4SLinus Torvalds nr_clear_queues(sk);
2691da177e4SLinus Torvalds
2701da177e4SLinus Torvalds nr_sk(sk)->state = NR_STATE_0;
2711da177e4SLinus Torvalds
2721da177e4SLinus Torvalds sk->sk_state = TCP_CLOSE;
2731da177e4SLinus Torvalds sk->sk_err = reason;
2741da177e4SLinus Torvalds sk->sk_shutdown |= SEND_SHUTDOWN;
2751da177e4SLinus Torvalds
2761da177e4SLinus Torvalds if (!sock_flag(sk, SOCK_DEAD)) {
2771da177e4SLinus Torvalds sk->sk_state_change(sk);
2781da177e4SLinus Torvalds sock_set_flag(sk, SOCK_DEAD);
2791da177e4SLinus Torvalds }
2801da177e4SLinus Torvalds }
281