1 /* Copyright (C) 2011-2017  B.A.T.M.A.N. contributors:
2  *
3  * Simon Wunderlich
4  *
5  * This program is free software; you can redistribute it and/or
6  * modify it under the terms of version 2 of the GNU General Public
7  * License as published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but
10  * WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12  * General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program; if not, see <http://www.gnu.org/licenses/>.
16  */
17 
18 #include "bridge_loop_avoidance.h"
19 #include "main.h"
20 
21 #include <linux/atomic.h>
22 #include <linux/byteorder/generic.h>
23 #include <linux/compiler.h>
24 #include <linux/crc16.h>
25 #include <linux/errno.h>
26 #include <linux/etherdevice.h>
27 #include <linux/fs.h>
28 #include <linux/if_arp.h>
29 #include <linux/if_ether.h>
30 #include <linux/if_vlan.h>
31 #include <linux/jhash.h>
32 #include <linux/jiffies.h>
33 #include <linux/kernel.h>
34 #include <linux/kref.h>
35 #include <linux/list.h>
36 #include <linux/lockdep.h>
37 #include <linux/netdevice.h>
38 #include <linux/netlink.h>
39 #include <linux/rculist.h>
40 #include <linux/rcupdate.h>
41 #include <linux/seq_file.h>
42 #include <linux/skbuff.h>
43 #include <linux/slab.h>
44 #include <linux/spinlock.h>
45 #include <linux/stddef.h>
46 #include <linux/string.h>
47 #include <linux/workqueue.h>
48 #include <net/arp.h>
49 #include <net/genetlink.h>
50 #include <net/netlink.h>
51 #include <net/sock.h>
52 #include <uapi/linux/batman_adv.h>
53 
54 #include "hard-interface.h"
55 #include "hash.h"
56 #include "log.h"
57 #include "netlink.h"
58 #include "originator.h"
59 #include "packet.h"
60 #include "soft-interface.h"
61 #include "sysfs.h"
62 #include "translation-table.h"
63 
64 static const u8 batadv_announce_mac[4] = {0x43, 0x05, 0x43, 0x05};
65 
66 static void batadv_bla_periodic_work(struct work_struct *work);
67 static void
68 batadv_bla_send_announce(struct batadv_priv *bat_priv,
69 			 struct batadv_bla_backbone_gw *backbone_gw);
70 
71 /**
72  * batadv_choose_claim - choose the right bucket for a claim.
73  * @data: data to hash
74  * @size: size of the hash table
75  *
76  * Return: the hash index of the claim
77  */
78 static inline u32 batadv_choose_claim(const void *data, u32 size)
79 {
80 	struct batadv_bla_claim *claim = (struct batadv_bla_claim *)data;
81 	u32 hash = 0;
82 
83 	hash = jhash(&claim->addr, sizeof(claim->addr), hash);
84 	hash = jhash(&claim->vid, sizeof(claim->vid), hash);
85 
86 	return hash % size;
87 }
88 
89 /**
90  * batadv_choose_backbone_gw - choose the right bucket for a backbone gateway.
91  * @data: data to hash
92  * @size: size of the hash table
93  *
94  * Return: the hash index of the backbone gateway
95  */
96 static inline u32 batadv_choose_backbone_gw(const void *data, u32 size)
97 {
98 	const struct batadv_bla_claim *claim = (struct batadv_bla_claim *)data;
99 	u32 hash = 0;
100 
101 	hash = jhash(&claim->addr, sizeof(claim->addr), hash);
102 	hash = jhash(&claim->vid, sizeof(claim->vid), hash);
103 
104 	return hash % size;
105 }
106 
107 /**
108  * batadv_compare_backbone_gw - compare address and vid of two backbone gws
109  * @node: list node of the first entry to compare
110  * @data2: pointer to the second backbone gateway
111  *
112  * Return: true if the backbones have the same data, false otherwise
113  */
114 static bool batadv_compare_backbone_gw(const struct hlist_node *node,
115 				       const void *data2)
116 {
117 	const void *data1 = container_of(node, struct batadv_bla_backbone_gw,
118 					 hash_entry);
119 	const struct batadv_bla_backbone_gw *gw1 = data1;
120 	const struct batadv_bla_backbone_gw *gw2 = data2;
121 
122 	if (!batadv_compare_eth(gw1->orig, gw2->orig))
123 		return false;
124 
125 	if (gw1->vid != gw2->vid)
126 		return false;
127 
128 	return true;
129 }
130 
131 /**
132  * batadv_compare_claim - compare address and vid of two claims
133  * @node: list node of the first entry to compare
134  * @data2: pointer to the second claims
135  *
136  * Return: true if the claim have the same data, 0 otherwise
137  */
138 static bool batadv_compare_claim(const struct hlist_node *node,
139 				 const void *data2)
140 {
141 	const void *data1 = container_of(node, struct batadv_bla_claim,
142 					 hash_entry);
143 	const struct batadv_bla_claim *cl1 = data1;
144 	const struct batadv_bla_claim *cl2 = data2;
145 
146 	if (!batadv_compare_eth(cl1->addr, cl2->addr))
147 		return false;
148 
149 	if (cl1->vid != cl2->vid)
150 		return false;
151 
152 	return true;
153 }
154 
155 /**
156  * batadv_backbone_gw_release - release backbone gw from lists and queue for
157  *  free after rcu grace period
158  * @ref: kref pointer of the backbone gw
159  */
160 static void batadv_backbone_gw_release(struct kref *ref)
161 {
162 	struct batadv_bla_backbone_gw *backbone_gw;
163 
164 	backbone_gw = container_of(ref, struct batadv_bla_backbone_gw,
165 				   refcount);
166 
167 	kfree_rcu(backbone_gw, rcu);
168 }
169 
170 /**
171  * batadv_backbone_gw_put - decrement the backbone gw refcounter and possibly
172  *  release it
173  * @backbone_gw: backbone gateway to be free'd
174  */
175 static void batadv_backbone_gw_put(struct batadv_bla_backbone_gw *backbone_gw)
176 {
177 	kref_put(&backbone_gw->refcount, batadv_backbone_gw_release);
178 }
179 
180 /**
181  * batadv_claim_release - release claim from lists and queue for free after rcu
182  *  grace period
183  * @ref: kref pointer of the claim
184  */
185 static void batadv_claim_release(struct kref *ref)
186 {
187 	struct batadv_bla_claim *claim;
188 	struct batadv_bla_backbone_gw *old_backbone_gw;
189 
190 	claim = container_of(ref, struct batadv_bla_claim, refcount);
191 
192 	spin_lock_bh(&claim->backbone_lock);
193 	old_backbone_gw = claim->backbone_gw;
194 	claim->backbone_gw = NULL;
195 	spin_unlock_bh(&claim->backbone_lock);
196 
197 	spin_lock_bh(&old_backbone_gw->crc_lock);
198 	old_backbone_gw->crc ^= crc16(0, claim->addr, ETH_ALEN);
199 	spin_unlock_bh(&old_backbone_gw->crc_lock);
200 
201 	batadv_backbone_gw_put(old_backbone_gw);
202 
203 	kfree_rcu(claim, rcu);
204 }
205 
206 /**
207  * batadv_claim_put - decrement the claim refcounter and possibly
208  *  release it
209  * @claim: claim to be free'd
210  */
211 static void batadv_claim_put(struct batadv_bla_claim *claim)
212 {
213 	kref_put(&claim->refcount, batadv_claim_release);
214 }
215 
216 /**
217  * batadv_claim_hash_find - looks for a claim in the claim hash
218  * @bat_priv: the bat priv with all the soft interface information
219  * @data: search data (may be local/static data)
220  *
221  * Return: claim if found or NULL otherwise.
222  */
223 static struct batadv_bla_claim *
224 batadv_claim_hash_find(struct batadv_priv *bat_priv,
225 		       struct batadv_bla_claim *data)
226 {
227 	struct batadv_hashtable *hash = bat_priv->bla.claim_hash;
228 	struct hlist_head *head;
229 	struct batadv_bla_claim *claim;
230 	struct batadv_bla_claim *claim_tmp = NULL;
231 	int index;
232 
233 	if (!hash)
234 		return NULL;
235 
236 	index = batadv_choose_claim(data, hash->size);
237 	head = &hash->table[index];
238 
239 	rcu_read_lock();
240 	hlist_for_each_entry_rcu(claim, head, hash_entry) {
241 		if (!batadv_compare_claim(&claim->hash_entry, data))
242 			continue;
243 
244 		if (!kref_get_unless_zero(&claim->refcount))
245 			continue;
246 
247 		claim_tmp = claim;
248 		break;
249 	}
250 	rcu_read_unlock();
251 
252 	return claim_tmp;
253 }
254 
255 /**
256  * batadv_backbone_hash_find - looks for a backbone gateway in the hash
257  * @bat_priv: the bat priv with all the soft interface information
258  * @addr: the address of the originator
259  * @vid: the VLAN ID
260  *
261  * Return: backbone gateway if found or NULL otherwise
262  */
263 static struct batadv_bla_backbone_gw *
264 batadv_backbone_hash_find(struct batadv_priv *bat_priv, u8 *addr,
265 			  unsigned short vid)
266 {
267 	struct batadv_hashtable *hash = bat_priv->bla.backbone_hash;
268 	struct hlist_head *head;
269 	struct batadv_bla_backbone_gw search_entry, *backbone_gw;
270 	struct batadv_bla_backbone_gw *backbone_gw_tmp = NULL;
271 	int index;
272 
273 	if (!hash)
274 		return NULL;
275 
276 	ether_addr_copy(search_entry.orig, addr);
277 	search_entry.vid = vid;
278 
279 	index = batadv_choose_backbone_gw(&search_entry, hash->size);
280 	head = &hash->table[index];
281 
282 	rcu_read_lock();
283 	hlist_for_each_entry_rcu(backbone_gw, head, hash_entry) {
284 		if (!batadv_compare_backbone_gw(&backbone_gw->hash_entry,
285 						&search_entry))
286 			continue;
287 
288 		if (!kref_get_unless_zero(&backbone_gw->refcount))
289 			continue;
290 
291 		backbone_gw_tmp = backbone_gw;
292 		break;
293 	}
294 	rcu_read_unlock();
295 
296 	return backbone_gw_tmp;
297 }
298 
299 /**
300  * batadv_bla_del_backbone_claims - delete all claims for a backbone
301  * @backbone_gw: backbone gateway where the claims should be removed
302  */
303 static void
304 batadv_bla_del_backbone_claims(struct batadv_bla_backbone_gw *backbone_gw)
305 {
306 	struct batadv_hashtable *hash;
307 	struct hlist_node *node_tmp;
308 	struct hlist_head *head;
309 	struct batadv_bla_claim *claim;
310 	int i;
311 	spinlock_t *list_lock;	/* protects write access to the hash lists */
312 
313 	hash = backbone_gw->bat_priv->bla.claim_hash;
314 	if (!hash)
315 		return;
316 
317 	for (i = 0; i < hash->size; i++) {
318 		head = &hash->table[i];
319 		list_lock = &hash->list_locks[i];
320 
321 		spin_lock_bh(list_lock);
322 		hlist_for_each_entry_safe(claim, node_tmp,
323 					  head, hash_entry) {
324 			if (claim->backbone_gw != backbone_gw)
325 				continue;
326 
327 			batadv_claim_put(claim);
328 			hlist_del_rcu(&claim->hash_entry);
329 		}
330 		spin_unlock_bh(list_lock);
331 	}
332 
333 	/* all claims gone, initialize CRC */
334 	spin_lock_bh(&backbone_gw->crc_lock);
335 	backbone_gw->crc = BATADV_BLA_CRC_INIT;
336 	spin_unlock_bh(&backbone_gw->crc_lock);
337 }
338 
339 /**
340  * batadv_bla_send_claim - sends a claim frame according to the provided info
341  * @bat_priv: the bat priv with all the soft interface information
342  * @mac: the mac address to be announced within the claim
343  * @vid: the VLAN ID
344  * @claimtype: the type of the claim (CLAIM, UNCLAIM, ANNOUNCE, ...)
345  */
346 static void batadv_bla_send_claim(struct batadv_priv *bat_priv, u8 *mac,
347 				  unsigned short vid, int claimtype)
348 {
349 	struct sk_buff *skb;
350 	struct ethhdr *ethhdr;
351 	struct batadv_hard_iface *primary_if;
352 	struct net_device *soft_iface;
353 	u8 *hw_src;
354 	struct batadv_bla_claim_dst local_claim_dest;
355 	__be32 zeroip = 0;
356 
357 	primary_if = batadv_primary_if_get_selected(bat_priv);
358 	if (!primary_if)
359 		return;
360 
361 	memcpy(&local_claim_dest, &bat_priv->bla.claim_dest,
362 	       sizeof(local_claim_dest));
363 	local_claim_dest.type = claimtype;
364 
365 	soft_iface = primary_if->soft_iface;
366 
367 	skb = arp_create(ARPOP_REPLY, ETH_P_ARP,
368 			 /* IP DST: 0.0.0.0 */
369 			 zeroip,
370 			 primary_if->soft_iface,
371 			 /* IP SRC: 0.0.0.0 */
372 			 zeroip,
373 			 /* Ethernet DST: Broadcast */
374 			 NULL,
375 			 /* Ethernet SRC/HW SRC:  originator mac */
376 			 primary_if->net_dev->dev_addr,
377 			 /* HW DST: FF:43:05:XX:YY:YY
378 			  * with XX   = claim type
379 			  * and YY:YY = group id
380 			  */
381 			 (u8 *)&local_claim_dest);
382 
383 	if (!skb)
384 		goto out;
385 
386 	ethhdr = (struct ethhdr *)skb->data;
387 	hw_src = (u8 *)ethhdr + ETH_HLEN + sizeof(struct arphdr);
388 
389 	/* now we pretend that the client would have sent this ... */
390 	switch (claimtype) {
391 	case BATADV_CLAIM_TYPE_CLAIM:
392 		/* normal claim frame
393 		 * set Ethernet SRC to the clients mac
394 		 */
395 		ether_addr_copy(ethhdr->h_source, mac);
396 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
397 			   "bla_send_claim(): CLAIM %pM on vid %d\n", mac,
398 			   BATADV_PRINT_VID(vid));
399 		break;
400 	case BATADV_CLAIM_TYPE_UNCLAIM:
401 		/* unclaim frame
402 		 * set HW SRC to the clients mac
403 		 */
404 		ether_addr_copy(hw_src, mac);
405 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
406 			   "bla_send_claim(): UNCLAIM %pM on vid %d\n", mac,
407 			   BATADV_PRINT_VID(vid));
408 		break;
409 	case BATADV_CLAIM_TYPE_ANNOUNCE:
410 		/* announcement frame
411 		 * set HW SRC to the special mac containg the crc
412 		 */
413 		ether_addr_copy(hw_src, mac);
414 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
415 			   "bla_send_claim(): ANNOUNCE of %pM on vid %d\n",
416 			   ethhdr->h_source, BATADV_PRINT_VID(vid));
417 		break;
418 	case BATADV_CLAIM_TYPE_REQUEST:
419 		/* request frame
420 		 * set HW SRC and header destination to the receiving backbone
421 		 * gws mac
422 		 */
423 		ether_addr_copy(hw_src, mac);
424 		ether_addr_copy(ethhdr->h_dest, mac);
425 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
426 			   "bla_send_claim(): REQUEST of %pM to %pM on vid %d\n",
427 			   ethhdr->h_source, ethhdr->h_dest,
428 			   BATADV_PRINT_VID(vid));
429 		break;
430 	case BATADV_CLAIM_TYPE_LOOPDETECT:
431 		ether_addr_copy(ethhdr->h_source, mac);
432 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
433 			   "bla_send_claim(): LOOPDETECT of %pM to %pM on vid %d\n",
434 			   ethhdr->h_source, ethhdr->h_dest,
435 			   BATADV_PRINT_VID(vid));
436 
437 		break;
438 	}
439 
440 	if (vid & BATADV_VLAN_HAS_TAG) {
441 		skb = vlan_insert_tag(skb, htons(ETH_P_8021Q),
442 				      vid & VLAN_VID_MASK);
443 		if (!skb)
444 			goto out;
445 	}
446 
447 	skb_reset_mac_header(skb);
448 	skb->protocol = eth_type_trans(skb, soft_iface);
449 	batadv_inc_counter(bat_priv, BATADV_CNT_RX);
450 	batadv_add_counter(bat_priv, BATADV_CNT_RX_BYTES,
451 			   skb->len + ETH_HLEN);
452 
453 	netif_rx(skb);
454 out:
455 	if (primary_if)
456 		batadv_hardif_put(primary_if);
457 }
458 
459 /**
460  * batadv_bla_loopdetect_report - worker for reporting the loop
461  * @work: work queue item
462  *
463  * Throws an uevent, as the loopdetect check function can't do that itself
464  * since the kernel may sleep while throwing uevents.
465  */
466 static void batadv_bla_loopdetect_report(struct work_struct *work)
467 {
468 	struct batadv_bla_backbone_gw *backbone_gw;
469 	struct batadv_priv *bat_priv;
470 	char vid_str[6] = { '\0' };
471 
472 	backbone_gw = container_of(work, struct batadv_bla_backbone_gw,
473 				   report_work);
474 	bat_priv = backbone_gw->bat_priv;
475 
476 	batadv_info(bat_priv->soft_iface,
477 		    "Possible loop on VLAN %d detected which can't be handled by BLA - please check your network setup!\n",
478 		    BATADV_PRINT_VID(backbone_gw->vid));
479 	snprintf(vid_str, sizeof(vid_str), "%d",
480 		 BATADV_PRINT_VID(backbone_gw->vid));
481 	vid_str[sizeof(vid_str) - 1] = 0;
482 
483 	batadv_throw_uevent(bat_priv, BATADV_UEV_BLA, BATADV_UEV_LOOPDETECT,
484 			    vid_str);
485 
486 	batadv_backbone_gw_put(backbone_gw);
487 }
488 
489 /**
490  * batadv_bla_get_backbone_gw - finds or creates a backbone gateway
491  * @bat_priv: the bat priv with all the soft interface information
492  * @orig: the mac address of the originator
493  * @vid: the VLAN ID
494  * @own_backbone: set if the requested backbone is local
495  *
496  * Return: the (possibly created) backbone gateway or NULL on error
497  */
498 static struct batadv_bla_backbone_gw *
499 batadv_bla_get_backbone_gw(struct batadv_priv *bat_priv, u8 *orig,
500 			   unsigned short vid, bool own_backbone)
501 {
502 	struct batadv_bla_backbone_gw *entry;
503 	struct batadv_orig_node *orig_node;
504 	int hash_added;
505 
506 	entry = batadv_backbone_hash_find(bat_priv, orig, vid);
507 
508 	if (entry)
509 		return entry;
510 
511 	batadv_dbg(BATADV_DBG_BLA, bat_priv,
512 		   "bla_get_backbone_gw(): not found (%pM, %d), creating new entry\n",
513 		   orig, BATADV_PRINT_VID(vid));
514 
515 	entry = kzalloc(sizeof(*entry), GFP_ATOMIC);
516 	if (!entry)
517 		return NULL;
518 
519 	entry->vid = vid;
520 	entry->lasttime = jiffies;
521 	entry->crc = BATADV_BLA_CRC_INIT;
522 	entry->bat_priv = bat_priv;
523 	spin_lock_init(&entry->crc_lock);
524 	atomic_set(&entry->request_sent, 0);
525 	atomic_set(&entry->wait_periods, 0);
526 	ether_addr_copy(entry->orig, orig);
527 	INIT_WORK(&entry->report_work, batadv_bla_loopdetect_report);
528 	kref_init(&entry->refcount);
529 
530 	kref_get(&entry->refcount);
531 	hash_added = batadv_hash_add(bat_priv->bla.backbone_hash,
532 				     batadv_compare_backbone_gw,
533 				     batadv_choose_backbone_gw, entry,
534 				     &entry->hash_entry);
535 
536 	if (unlikely(hash_added != 0)) {
537 		/* hash failed, free the structure */
538 		kfree(entry);
539 		return NULL;
540 	}
541 
542 	/* this is a gateway now, remove any TT entry on this VLAN */
543 	orig_node = batadv_orig_hash_find(bat_priv, orig);
544 	if (orig_node) {
545 		batadv_tt_global_del_orig(bat_priv, orig_node, vid,
546 					  "became a backbone gateway");
547 		batadv_orig_node_put(orig_node);
548 	}
549 
550 	if (own_backbone) {
551 		batadv_bla_send_announce(bat_priv, entry);
552 
553 		/* this will be decreased in the worker thread */
554 		atomic_inc(&entry->request_sent);
555 		atomic_set(&entry->wait_periods, BATADV_BLA_WAIT_PERIODS);
556 		atomic_inc(&bat_priv->bla.num_requests);
557 	}
558 
559 	return entry;
560 }
561 
562 /**
563  * batadv_bla_update_own_backbone_gw - updates the own backbone gw for a VLAN
564  * @bat_priv: the bat priv with all the soft interface information
565  * @primary_if: the selected primary interface
566  * @vid: VLAN identifier
567  *
568  * update or add the own backbone gw to make sure we announce
569  * where we receive other backbone gws
570  */
571 static void
572 batadv_bla_update_own_backbone_gw(struct batadv_priv *bat_priv,
573 				  struct batadv_hard_iface *primary_if,
574 				  unsigned short vid)
575 {
576 	struct batadv_bla_backbone_gw *backbone_gw;
577 
578 	backbone_gw = batadv_bla_get_backbone_gw(bat_priv,
579 						 primary_if->net_dev->dev_addr,
580 						 vid, true);
581 	if (unlikely(!backbone_gw))
582 		return;
583 
584 	backbone_gw->lasttime = jiffies;
585 	batadv_backbone_gw_put(backbone_gw);
586 }
587 
588 /**
589  * batadv_bla_answer_request - answer a bla request by sending own claims
590  * @bat_priv: the bat priv with all the soft interface information
591  * @primary_if: interface where the request came on
592  * @vid: the vid where the request came on
593  *
594  * Repeat all of our own claims, and finally send an ANNOUNCE frame
595  * to allow the requester another check if the CRC is correct now.
596  */
597 static void batadv_bla_answer_request(struct batadv_priv *bat_priv,
598 				      struct batadv_hard_iface *primary_if,
599 				      unsigned short vid)
600 {
601 	struct hlist_head *head;
602 	struct batadv_hashtable *hash;
603 	struct batadv_bla_claim *claim;
604 	struct batadv_bla_backbone_gw *backbone_gw;
605 	int i;
606 
607 	batadv_dbg(BATADV_DBG_BLA, bat_priv,
608 		   "bla_answer_request(): received a claim request, send all of our own claims again\n");
609 
610 	backbone_gw = batadv_backbone_hash_find(bat_priv,
611 						primary_if->net_dev->dev_addr,
612 						vid);
613 	if (!backbone_gw)
614 		return;
615 
616 	hash = bat_priv->bla.claim_hash;
617 	for (i = 0; i < hash->size; i++) {
618 		head = &hash->table[i];
619 
620 		rcu_read_lock();
621 		hlist_for_each_entry_rcu(claim, head, hash_entry) {
622 			/* only own claims are interesting */
623 			if (claim->backbone_gw != backbone_gw)
624 				continue;
625 
626 			batadv_bla_send_claim(bat_priv, claim->addr, claim->vid,
627 					      BATADV_CLAIM_TYPE_CLAIM);
628 		}
629 		rcu_read_unlock();
630 	}
631 
632 	/* finally, send an announcement frame */
633 	batadv_bla_send_announce(bat_priv, backbone_gw);
634 	batadv_backbone_gw_put(backbone_gw);
635 }
636 
637 /**
638  * batadv_bla_send_request - send a request to repeat claims
639  * @backbone_gw: the backbone gateway from whom we are out of sync
640  *
641  * When the crc is wrong, ask the backbone gateway for a full table update.
642  * After the request, it will repeat all of his own claims and finally
643  * send an announcement claim with which we can check again.
644  */
645 static void batadv_bla_send_request(struct batadv_bla_backbone_gw *backbone_gw)
646 {
647 	/* first, remove all old entries */
648 	batadv_bla_del_backbone_claims(backbone_gw);
649 
650 	batadv_dbg(BATADV_DBG_BLA, backbone_gw->bat_priv,
651 		   "Sending REQUEST to %pM\n", backbone_gw->orig);
652 
653 	/* send request */
654 	batadv_bla_send_claim(backbone_gw->bat_priv, backbone_gw->orig,
655 			      backbone_gw->vid, BATADV_CLAIM_TYPE_REQUEST);
656 
657 	/* no local broadcasts should be sent or received, for now. */
658 	if (!atomic_read(&backbone_gw->request_sent)) {
659 		atomic_inc(&backbone_gw->bat_priv->bla.num_requests);
660 		atomic_set(&backbone_gw->request_sent, 1);
661 	}
662 }
663 
664 /**
665  * batadv_bla_send_announce - Send an announcement frame
666  * @bat_priv: the bat priv with all the soft interface information
667  * @backbone_gw: our backbone gateway which should be announced
668  */
669 static void batadv_bla_send_announce(struct batadv_priv *bat_priv,
670 				     struct batadv_bla_backbone_gw *backbone_gw)
671 {
672 	u8 mac[ETH_ALEN];
673 	__be16 crc;
674 
675 	memcpy(mac, batadv_announce_mac, 4);
676 	spin_lock_bh(&backbone_gw->crc_lock);
677 	crc = htons(backbone_gw->crc);
678 	spin_unlock_bh(&backbone_gw->crc_lock);
679 	memcpy(&mac[4], &crc, 2);
680 
681 	batadv_bla_send_claim(bat_priv, mac, backbone_gw->vid,
682 			      BATADV_CLAIM_TYPE_ANNOUNCE);
683 }
684 
685 /**
686  * batadv_bla_add_claim - Adds a claim in the claim hash
687  * @bat_priv: the bat priv with all the soft interface information
688  * @mac: the mac address of the claim
689  * @vid: the VLAN ID of the frame
690  * @backbone_gw: the backbone gateway which claims it
691  */
692 static void batadv_bla_add_claim(struct batadv_priv *bat_priv,
693 				 const u8 *mac, const unsigned short vid,
694 				 struct batadv_bla_backbone_gw *backbone_gw)
695 {
696 	struct batadv_bla_backbone_gw *old_backbone_gw;
697 	struct batadv_bla_claim *claim;
698 	struct batadv_bla_claim search_claim;
699 	bool remove_crc = false;
700 	int hash_added;
701 
702 	ether_addr_copy(search_claim.addr, mac);
703 	search_claim.vid = vid;
704 	claim = batadv_claim_hash_find(bat_priv, &search_claim);
705 
706 	/* create a new claim entry if it does not exist yet. */
707 	if (!claim) {
708 		claim = kzalloc(sizeof(*claim), GFP_ATOMIC);
709 		if (!claim)
710 			return;
711 
712 		ether_addr_copy(claim->addr, mac);
713 		spin_lock_init(&claim->backbone_lock);
714 		claim->vid = vid;
715 		claim->lasttime = jiffies;
716 		kref_get(&backbone_gw->refcount);
717 		claim->backbone_gw = backbone_gw;
718 		kref_init(&claim->refcount);
719 
720 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
721 			   "bla_add_claim(): adding new entry %pM, vid %d to hash ...\n",
722 			   mac, BATADV_PRINT_VID(vid));
723 
724 		kref_get(&claim->refcount);
725 		hash_added = batadv_hash_add(bat_priv->bla.claim_hash,
726 					     batadv_compare_claim,
727 					     batadv_choose_claim, claim,
728 					     &claim->hash_entry);
729 
730 		if (unlikely(hash_added != 0)) {
731 			/* only local changes happened. */
732 			kfree(claim);
733 			return;
734 		}
735 	} else {
736 		claim->lasttime = jiffies;
737 		if (claim->backbone_gw == backbone_gw)
738 			/* no need to register a new backbone */
739 			goto claim_free_ref;
740 
741 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
742 			   "bla_add_claim(): changing ownership for %pM, vid %d\n",
743 			   mac, BATADV_PRINT_VID(vid));
744 
745 		remove_crc = true;
746 	}
747 
748 	/* replace backbone_gw atomically and adjust reference counters */
749 	spin_lock_bh(&claim->backbone_lock);
750 	old_backbone_gw = claim->backbone_gw;
751 	kref_get(&backbone_gw->refcount);
752 	claim->backbone_gw = backbone_gw;
753 	spin_unlock_bh(&claim->backbone_lock);
754 
755 	if (remove_crc) {
756 		/* remove claim address from old backbone_gw */
757 		spin_lock_bh(&old_backbone_gw->crc_lock);
758 		old_backbone_gw->crc ^= crc16(0, claim->addr, ETH_ALEN);
759 		spin_unlock_bh(&old_backbone_gw->crc_lock);
760 	}
761 
762 	batadv_backbone_gw_put(old_backbone_gw);
763 
764 	/* add claim address to new backbone_gw */
765 	spin_lock_bh(&backbone_gw->crc_lock);
766 	backbone_gw->crc ^= crc16(0, claim->addr, ETH_ALEN);
767 	spin_unlock_bh(&backbone_gw->crc_lock);
768 	backbone_gw->lasttime = jiffies;
769 
770 claim_free_ref:
771 	batadv_claim_put(claim);
772 }
773 
774 /**
775  * batadv_bla_claim_get_backbone_gw - Get valid reference for backbone_gw of
776  *  claim
777  * @claim: claim whose backbone_gw should be returned
778  *
779  * Return: valid reference to claim::backbone_gw
780  */
781 static struct batadv_bla_backbone_gw *
782 batadv_bla_claim_get_backbone_gw(struct batadv_bla_claim *claim)
783 {
784 	struct batadv_bla_backbone_gw *backbone_gw;
785 
786 	spin_lock_bh(&claim->backbone_lock);
787 	backbone_gw = claim->backbone_gw;
788 	kref_get(&backbone_gw->refcount);
789 	spin_unlock_bh(&claim->backbone_lock);
790 
791 	return backbone_gw;
792 }
793 
794 /**
795  * batadv_bla_del_claim - delete a claim from the claim hash
796  * @bat_priv: the bat priv with all the soft interface information
797  * @mac: mac address of the claim to be removed
798  * @vid: VLAN id for the claim to be removed
799  */
800 static void batadv_bla_del_claim(struct batadv_priv *bat_priv,
801 				 const u8 *mac, const unsigned short vid)
802 {
803 	struct batadv_bla_claim search_claim, *claim;
804 
805 	ether_addr_copy(search_claim.addr, mac);
806 	search_claim.vid = vid;
807 	claim = batadv_claim_hash_find(bat_priv, &search_claim);
808 	if (!claim)
809 		return;
810 
811 	batadv_dbg(BATADV_DBG_BLA, bat_priv, "bla_del_claim(): %pM, vid %d\n",
812 		   mac, BATADV_PRINT_VID(vid));
813 
814 	batadv_hash_remove(bat_priv->bla.claim_hash, batadv_compare_claim,
815 			   batadv_choose_claim, claim);
816 	batadv_claim_put(claim); /* reference from the hash is gone */
817 
818 	/* don't need the reference from hash_find() anymore */
819 	batadv_claim_put(claim);
820 }
821 
822 /**
823  * batadv_handle_announce - check for ANNOUNCE frame
824  * @bat_priv: the bat priv with all the soft interface information
825  * @an_addr: announcement mac address (ARP Sender HW address)
826  * @backbone_addr: originator address of the sender (Ethernet source MAC)
827  * @vid: the VLAN ID of the frame
828  *
829  * Return: true if handled
830  */
831 static bool batadv_handle_announce(struct batadv_priv *bat_priv, u8 *an_addr,
832 				   u8 *backbone_addr, unsigned short vid)
833 {
834 	struct batadv_bla_backbone_gw *backbone_gw;
835 	u16 backbone_crc, crc;
836 
837 	if (memcmp(an_addr, batadv_announce_mac, 4) != 0)
838 		return false;
839 
840 	backbone_gw = batadv_bla_get_backbone_gw(bat_priv, backbone_addr, vid,
841 						 false);
842 
843 	if (unlikely(!backbone_gw))
844 		return true;
845 
846 	/* handle as ANNOUNCE frame */
847 	backbone_gw->lasttime = jiffies;
848 	crc = ntohs(*((__be16 *)(&an_addr[4])));
849 
850 	batadv_dbg(BATADV_DBG_BLA, bat_priv,
851 		   "handle_announce(): ANNOUNCE vid %d (sent by %pM)... CRC = %#.4x\n",
852 		   BATADV_PRINT_VID(vid), backbone_gw->orig, crc);
853 
854 	spin_lock_bh(&backbone_gw->crc_lock);
855 	backbone_crc = backbone_gw->crc;
856 	spin_unlock_bh(&backbone_gw->crc_lock);
857 
858 	if (backbone_crc != crc) {
859 		batadv_dbg(BATADV_DBG_BLA, backbone_gw->bat_priv,
860 			   "handle_announce(): CRC FAILED for %pM/%d (my = %#.4x, sent = %#.4x)\n",
861 			   backbone_gw->orig,
862 			   BATADV_PRINT_VID(backbone_gw->vid),
863 			   backbone_crc, crc);
864 
865 		batadv_bla_send_request(backbone_gw);
866 	} else {
867 		/* if we have sent a request and the crc was OK,
868 		 * we can allow traffic again.
869 		 */
870 		if (atomic_read(&backbone_gw->request_sent)) {
871 			atomic_dec(&backbone_gw->bat_priv->bla.num_requests);
872 			atomic_set(&backbone_gw->request_sent, 0);
873 		}
874 	}
875 
876 	batadv_backbone_gw_put(backbone_gw);
877 	return true;
878 }
879 
880 /**
881  * batadv_handle_request - check for REQUEST frame
882  * @bat_priv: the bat priv with all the soft interface information
883  * @primary_if: the primary hard interface of this batman soft interface
884  * @backbone_addr: backbone address to be requested (ARP sender HW MAC)
885  * @ethhdr: ethernet header of a packet
886  * @vid: the VLAN ID of the frame
887  *
888  * Return: true if handled
889  */
890 static bool batadv_handle_request(struct batadv_priv *bat_priv,
891 				  struct batadv_hard_iface *primary_if,
892 				  u8 *backbone_addr, struct ethhdr *ethhdr,
893 				  unsigned short vid)
894 {
895 	/* check for REQUEST frame */
896 	if (!batadv_compare_eth(backbone_addr, ethhdr->h_dest))
897 		return false;
898 
899 	/* sanity check, this should not happen on a normal switch,
900 	 * we ignore it in this case.
901 	 */
902 	if (!batadv_compare_eth(ethhdr->h_dest, primary_if->net_dev->dev_addr))
903 		return true;
904 
905 	batadv_dbg(BATADV_DBG_BLA, bat_priv,
906 		   "handle_request(): REQUEST vid %d (sent by %pM)...\n",
907 		   BATADV_PRINT_VID(vid), ethhdr->h_source);
908 
909 	batadv_bla_answer_request(bat_priv, primary_if, vid);
910 	return true;
911 }
912 
913 /**
914  * batadv_handle_unclaim - check for UNCLAIM frame
915  * @bat_priv: the bat priv with all the soft interface information
916  * @primary_if: the primary hard interface of this batman soft interface
917  * @backbone_addr: originator address of the backbone (Ethernet source)
918  * @claim_addr: Client to be unclaimed (ARP sender HW MAC)
919  * @vid: the VLAN ID of the frame
920  *
921  * Return: true if handled
922  */
923 static bool batadv_handle_unclaim(struct batadv_priv *bat_priv,
924 				  struct batadv_hard_iface *primary_if,
925 				  u8 *backbone_addr, u8 *claim_addr,
926 				  unsigned short vid)
927 {
928 	struct batadv_bla_backbone_gw *backbone_gw;
929 
930 	/* unclaim in any case if it is our own */
931 	if (primary_if && batadv_compare_eth(backbone_addr,
932 					     primary_if->net_dev->dev_addr))
933 		batadv_bla_send_claim(bat_priv, claim_addr, vid,
934 				      BATADV_CLAIM_TYPE_UNCLAIM);
935 
936 	backbone_gw = batadv_backbone_hash_find(bat_priv, backbone_addr, vid);
937 
938 	if (!backbone_gw)
939 		return true;
940 
941 	/* this must be an UNCLAIM frame */
942 	batadv_dbg(BATADV_DBG_BLA, bat_priv,
943 		   "handle_unclaim(): UNCLAIM %pM on vid %d (sent by %pM)...\n",
944 		   claim_addr, BATADV_PRINT_VID(vid), backbone_gw->orig);
945 
946 	batadv_bla_del_claim(bat_priv, claim_addr, vid);
947 	batadv_backbone_gw_put(backbone_gw);
948 	return true;
949 }
950 
951 /**
952  * batadv_handle_claim - check for CLAIM frame
953  * @bat_priv: the bat priv with all the soft interface information
954  * @primary_if: the primary hard interface of this batman soft interface
955  * @backbone_addr: originator address of the backbone (Ethernet Source)
956  * @claim_addr: client mac address to be claimed (ARP sender HW MAC)
957  * @vid: the VLAN ID of the frame
958  *
959  * Return: true if handled
960  */
961 static bool batadv_handle_claim(struct batadv_priv *bat_priv,
962 				struct batadv_hard_iface *primary_if,
963 				u8 *backbone_addr, u8 *claim_addr,
964 				unsigned short vid)
965 {
966 	struct batadv_bla_backbone_gw *backbone_gw;
967 
968 	/* register the gateway if not yet available, and add the claim. */
969 
970 	backbone_gw = batadv_bla_get_backbone_gw(bat_priv, backbone_addr, vid,
971 						 false);
972 
973 	if (unlikely(!backbone_gw))
974 		return true;
975 
976 	/* this must be a CLAIM frame */
977 	batadv_bla_add_claim(bat_priv, claim_addr, vid, backbone_gw);
978 	if (batadv_compare_eth(backbone_addr, primary_if->net_dev->dev_addr))
979 		batadv_bla_send_claim(bat_priv, claim_addr, vid,
980 				      BATADV_CLAIM_TYPE_CLAIM);
981 
982 	/* TODO: we could call something like tt_local_del() here. */
983 
984 	batadv_backbone_gw_put(backbone_gw);
985 	return true;
986 }
987 
988 /**
989  * batadv_check_claim_group - check for claim group membership
990  * @bat_priv: the bat priv with all the soft interface information
991  * @primary_if: the primary interface of this batman interface
992  * @hw_src: the Hardware source in the ARP Header
993  * @hw_dst: the Hardware destination in the ARP Header
994  * @ethhdr: pointer to the Ethernet header of the claim frame
995  *
996  * checks if it is a claim packet and if its on the same group.
997  * This function also applies the group ID of the sender
998  * if it is in the same mesh.
999  *
1000  * Return:
1001  *	2  - if it is a claim packet and on the same group
1002  *	1  - if is a claim packet from another group
1003  *	0  - if it is not a claim packet
1004  */
1005 static int batadv_check_claim_group(struct batadv_priv *bat_priv,
1006 				    struct batadv_hard_iface *primary_if,
1007 				    u8 *hw_src, u8 *hw_dst,
1008 				    struct ethhdr *ethhdr)
1009 {
1010 	u8 *backbone_addr;
1011 	struct batadv_orig_node *orig_node;
1012 	struct batadv_bla_claim_dst *bla_dst, *bla_dst_own;
1013 
1014 	bla_dst = (struct batadv_bla_claim_dst *)hw_dst;
1015 	bla_dst_own = &bat_priv->bla.claim_dest;
1016 
1017 	/* if announcement packet, use the source,
1018 	 * otherwise assume it is in the hw_src
1019 	 */
1020 	switch (bla_dst->type) {
1021 	case BATADV_CLAIM_TYPE_CLAIM:
1022 		backbone_addr = hw_src;
1023 		break;
1024 	case BATADV_CLAIM_TYPE_REQUEST:
1025 	case BATADV_CLAIM_TYPE_ANNOUNCE:
1026 	case BATADV_CLAIM_TYPE_UNCLAIM:
1027 		backbone_addr = ethhdr->h_source;
1028 		break;
1029 	default:
1030 		return 0;
1031 	}
1032 
1033 	/* don't accept claim frames from ourselves */
1034 	if (batadv_compare_eth(backbone_addr, primary_if->net_dev->dev_addr))
1035 		return 0;
1036 
1037 	/* if its already the same group, it is fine. */
1038 	if (bla_dst->group == bla_dst_own->group)
1039 		return 2;
1040 
1041 	/* lets see if this originator is in our mesh */
1042 	orig_node = batadv_orig_hash_find(bat_priv, backbone_addr);
1043 
1044 	/* dont accept claims from gateways which are not in
1045 	 * the same mesh or group.
1046 	 */
1047 	if (!orig_node)
1048 		return 1;
1049 
1050 	/* if our mesh friends mac is bigger, use it for ourselves. */
1051 	if (ntohs(bla_dst->group) > ntohs(bla_dst_own->group)) {
1052 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
1053 			   "taking other backbones claim group: %#.4x\n",
1054 			   ntohs(bla_dst->group));
1055 		bla_dst_own->group = bla_dst->group;
1056 	}
1057 
1058 	batadv_orig_node_put(orig_node);
1059 
1060 	return 2;
1061 }
1062 
1063 /**
1064  * batadv_bla_process_claim - Check if this is a claim frame, and process it
1065  * @bat_priv: the bat priv with all the soft interface information
1066  * @primary_if: the primary hard interface of this batman soft interface
1067  * @skb: the frame to be checked
1068  *
1069  * Return: true if it was a claim frame, otherwise return false to
1070  * tell the callee that it can use the frame on its own.
1071  */
1072 static bool batadv_bla_process_claim(struct batadv_priv *bat_priv,
1073 				     struct batadv_hard_iface *primary_if,
1074 				     struct sk_buff *skb)
1075 {
1076 	struct batadv_bla_claim_dst *bla_dst, *bla_dst_own;
1077 	u8 *hw_src, *hw_dst;
1078 	struct vlan_hdr *vhdr, vhdr_buf;
1079 	struct ethhdr *ethhdr;
1080 	struct arphdr *arphdr;
1081 	unsigned short vid;
1082 	int vlan_depth = 0;
1083 	__be16 proto;
1084 	int headlen;
1085 	int ret;
1086 
1087 	vid = batadv_get_vid(skb, 0);
1088 	ethhdr = eth_hdr(skb);
1089 
1090 	proto = ethhdr->h_proto;
1091 	headlen = ETH_HLEN;
1092 	if (vid & BATADV_VLAN_HAS_TAG) {
1093 		/* Traverse the VLAN/Ethertypes.
1094 		 *
1095 		 * At this point it is known that the first protocol is a VLAN
1096 		 * header, so start checking at the encapsulated protocol.
1097 		 *
1098 		 * The depth of the VLAN headers is recorded to drop BLA claim
1099 		 * frames encapsulated into multiple VLAN headers (QinQ).
1100 		 */
1101 		do {
1102 			vhdr = skb_header_pointer(skb, headlen, VLAN_HLEN,
1103 						  &vhdr_buf);
1104 			if (!vhdr)
1105 				return false;
1106 
1107 			proto = vhdr->h_vlan_encapsulated_proto;
1108 			headlen += VLAN_HLEN;
1109 			vlan_depth++;
1110 		} while (proto == htons(ETH_P_8021Q));
1111 	}
1112 
1113 	if (proto != htons(ETH_P_ARP))
1114 		return false; /* not a claim frame */
1115 
1116 	/* this must be a ARP frame. check if it is a claim. */
1117 
1118 	if (unlikely(!pskb_may_pull(skb, headlen + arp_hdr_len(skb->dev))))
1119 		return false;
1120 
1121 	/* pskb_may_pull() may have modified the pointers, get ethhdr again */
1122 	ethhdr = eth_hdr(skb);
1123 	arphdr = (struct arphdr *)((u8 *)ethhdr + headlen);
1124 
1125 	/* Check whether the ARP frame carries a valid
1126 	 * IP information
1127 	 */
1128 	if (arphdr->ar_hrd != htons(ARPHRD_ETHER))
1129 		return false;
1130 	if (arphdr->ar_pro != htons(ETH_P_IP))
1131 		return false;
1132 	if (arphdr->ar_hln != ETH_ALEN)
1133 		return false;
1134 	if (arphdr->ar_pln != 4)
1135 		return false;
1136 
1137 	hw_src = (u8 *)arphdr + sizeof(struct arphdr);
1138 	hw_dst = hw_src + ETH_ALEN + 4;
1139 	bla_dst = (struct batadv_bla_claim_dst *)hw_dst;
1140 	bla_dst_own = &bat_priv->bla.claim_dest;
1141 
1142 	/* check if it is a claim frame in general */
1143 	if (memcmp(bla_dst->magic, bla_dst_own->magic,
1144 		   sizeof(bla_dst->magic)) != 0)
1145 		return false;
1146 
1147 	/* check if there is a claim frame encapsulated deeper in (QinQ) and
1148 	 * drop that, as this is not supported by BLA but should also not be
1149 	 * sent via the mesh.
1150 	 */
1151 	if (vlan_depth > 1)
1152 		return true;
1153 
1154 	/* Let the loopdetect frames on the mesh in any case. */
1155 	if (bla_dst->type == BATADV_CLAIM_TYPE_LOOPDETECT)
1156 		return false;
1157 
1158 	/* check if it is a claim frame. */
1159 	ret = batadv_check_claim_group(bat_priv, primary_if, hw_src, hw_dst,
1160 				       ethhdr);
1161 	if (ret == 1)
1162 		batadv_dbg(BATADV_DBG_BLA, bat_priv,
1163 			   "bla_process_claim(): received a claim frame from another group. From: %pM on vid %d ...(hw_src %pM, hw_dst %pM)\n",
1164 			   ethhdr->h_source, BATADV_PRINT_VID(vid), hw_src,
1165 			   hw_dst);
1166 
1167 	if (ret < 2)
1168 		return !!ret;
1169 
1170 	/* become a backbone gw ourselves on this vlan if not happened yet */
1171 	batadv_bla_update_own_backbone_gw(bat_priv, primary_if, vid);
1172 
1173 	/* check for the different types of claim frames ... */
1174 	switch (bla_dst->type) {
1175 	case BATADV_CLAIM_TYPE_CLAIM:
1176 		if (batadv_handle_claim(bat_priv, primary_if, hw_src,
1177 					ethhdr->h_source, vid))
1178 			return true;
1179 		break;
1180 	case BATADV_CLAIM_TYPE_UNCLAIM:
1181 		if (batadv_handle_unclaim(bat_priv, primary_if,
1182 					  ethhdr->h_source, hw_src, vid))
1183 			return true;
1184 		break;
1185 
1186 	case BATADV_CLAIM_TYPE_ANNOUNCE:
1187 		if (batadv_handle_announce(bat_priv, hw_src, ethhdr->h_source,
1188 					   vid))
1189 			return true;
1190 		break;
1191 	case BATADV_CLAIM_TYPE_REQUEST:
1192 		if (batadv_handle_request(bat_priv, primary_if, hw_src, ethhdr,
1193 					  vid))
1194 			return true;
1195 		break;
1196 	}
1197 
1198 	batadv_dbg(BATADV_DBG_BLA, bat_priv,
1199 		   "bla_process_claim(): ERROR - this looks like a claim frame, but is useless. eth src %pM on vid %d ...(hw_src %pM, hw_dst %pM)\n",
1200 		   ethhdr->h_source, BATADV_PRINT_VID(vid), hw_src, hw_dst);
1201 	return true;
1202 }
1203 
1204 /**
1205  * batadv_bla_purge_backbone_gw - Remove backbone gateways after a timeout or
1206  *  immediately
1207  * @bat_priv: the bat priv with all the soft interface information
1208  * @now: whether the whole hash shall be wiped now
1209  *
1210  * Check when we last heard from other nodes, and remove them in case of
1211  * a time out, or clean all backbone gws if now is set.
1212  */
1213 static void batadv_bla_purge_backbone_gw(struct batadv_priv *bat_priv, int now)
1214 {
1215 	struct batadv_bla_backbone_gw *backbone_gw;
1216 	struct hlist_node *node_tmp;
1217 	struct hlist_head *head;
1218 	struct batadv_hashtable *hash;
1219 	spinlock_t *list_lock;	/* protects write access to the hash lists */
1220 	int i;
1221 
1222 	hash = bat_priv->bla.backbone_hash;
1223 	if (!hash)
1224 		return;
1225 
1226 	for (i = 0; i < hash->size; i++) {
1227 		head = &hash->table[i];
1228 		list_lock = &hash->list_locks[i];
1229 
1230 		spin_lock_bh(list_lock);
1231 		hlist_for_each_entry_safe(backbone_gw, node_tmp,
1232 					  head, hash_entry) {
1233 			if (now)
1234 				goto purge_now;
1235 			if (!batadv_has_timed_out(backbone_gw->lasttime,
1236 						  BATADV_BLA_BACKBONE_TIMEOUT))
1237 				continue;
1238 
1239 			batadv_dbg(BATADV_DBG_BLA, backbone_gw->bat_priv,
1240 				   "bla_purge_backbone_gw(): backbone gw %pM timed out\n",
1241 				   backbone_gw->orig);
1242 
1243 purge_now:
1244 			/* don't wait for the pending request anymore */
1245 			if (atomic_read(&backbone_gw->request_sent))
1246 				atomic_dec(&bat_priv->bla.num_requests);
1247 
1248 			batadv_bla_del_backbone_claims(backbone_gw);
1249 
1250 			hlist_del_rcu(&backbone_gw->hash_entry);
1251 			batadv_backbone_gw_put(backbone_gw);
1252 		}
1253 		spin_unlock_bh(list_lock);
1254 	}
1255 }
1256 
1257 /**
1258  * batadv_bla_purge_claims - Remove claims after a timeout or immediately
1259  * @bat_priv: the bat priv with all the soft interface information
1260  * @primary_if: the selected primary interface, may be NULL if now is set
1261  * @now: whether the whole hash shall be wiped now
1262  *
1263  * Check when we heard last time from our own claims, and remove them in case of
1264  * a time out, or clean all claims if now is set
1265  */
1266 static void batadv_bla_purge_claims(struct batadv_priv *bat_priv,
1267 				    struct batadv_hard_iface *primary_if,
1268 				    int now)
1269 {
1270 	struct batadv_bla_backbone_gw *backbone_gw;
1271 	struct batadv_bla_claim *claim;
1272 	struct hlist_head *head;
1273 	struct batadv_hashtable *hash;
1274 	int i;
1275 
1276 	hash = bat_priv->bla.claim_hash;
1277 	if (!hash)
1278 		return;
1279 
1280 	for (i = 0; i < hash->size; i++) {
1281 		head = &hash->table[i];
1282 
1283 		rcu_read_lock();
1284 		hlist_for_each_entry_rcu(claim, head, hash_entry) {
1285 			backbone_gw = batadv_bla_claim_get_backbone_gw(claim);
1286 			if (now)
1287 				goto purge_now;
1288 
1289 			if (!batadv_compare_eth(backbone_gw->orig,
1290 						primary_if->net_dev->dev_addr))
1291 				goto skip;
1292 
1293 			if (!batadv_has_timed_out(claim->lasttime,
1294 						  BATADV_BLA_CLAIM_TIMEOUT))
1295 				goto skip;
1296 
1297 			batadv_dbg(BATADV_DBG_BLA, bat_priv,
1298 				   "bla_purge_claims(): %pM, vid %d, time out\n",
1299 				   claim->addr, claim->vid);
1300 
1301 purge_now:
1302 			batadv_handle_unclaim(bat_priv, primary_if,
1303 					      backbone_gw->orig,
1304 					      claim->addr, claim->vid);
1305 skip:
1306 			batadv_backbone_gw_put(backbone_gw);
1307 		}
1308 		rcu_read_unlock();
1309 	}
1310 }
1311 
1312 /**
1313  * batadv_bla_update_orig_address - Update the backbone gateways when the own
1314  *  originator address changes
1315  * @bat_priv: the bat priv with all the soft interface information
1316  * @primary_if: the new selected primary_if
1317  * @oldif: the old primary interface, may be NULL
1318  */
1319 void batadv_bla_update_orig_address(struct batadv_priv *bat_priv,
1320 				    struct batadv_hard_iface *primary_if,
1321 				    struct batadv_hard_iface *oldif)
1322 {
1323 	struct batadv_bla_backbone_gw *backbone_gw;
1324 	struct hlist_head *head;
1325 	struct batadv_hashtable *hash;
1326 	__be16 group;
1327 	int i;
1328 
1329 	/* reset bridge loop avoidance group id */
1330 	group = htons(crc16(0, primary_if->net_dev->dev_addr, ETH_ALEN));
1331 	bat_priv->bla.claim_dest.group = group;
1332 
1333 	/* purge everything when bridge loop avoidance is turned off */
1334 	if (!atomic_read(&bat_priv->bridge_loop_avoidance))
1335 		oldif = NULL;
1336 
1337 	if (!oldif) {
1338 		batadv_bla_purge_claims(bat_priv, NULL, 1);
1339 		batadv_bla_purge_backbone_gw(bat_priv, 1);
1340 		return;
1341 	}
1342 
1343 	hash = bat_priv->bla.backbone_hash;
1344 	if (!hash)
1345 		return;
1346 
1347 	for (i = 0; i < hash->size; i++) {
1348 		head = &hash->table[i];
1349 
1350 		rcu_read_lock();
1351 		hlist_for_each_entry_rcu(backbone_gw, head, hash_entry) {
1352 			/* own orig still holds the old value. */
1353 			if (!batadv_compare_eth(backbone_gw->orig,
1354 						oldif->net_dev->dev_addr))
1355 				continue;
1356 
1357 			ether_addr_copy(backbone_gw->orig,
1358 					primary_if->net_dev->dev_addr);
1359 			/* send an announce frame so others will ask for our
1360 			 * claims and update their tables.
1361 			 */
1362 			batadv_bla_send_announce(bat_priv, backbone_gw);
1363 		}
1364 		rcu_read_unlock();
1365 	}
1366 }
1367 
1368 /**
1369  * batadv_bla_send_loopdetect - send a loopdetect frame
1370  * @bat_priv: the bat priv with all the soft interface information
1371  * @backbone_gw: the backbone gateway for which a loop should be detected
1372  *
1373  * To detect loops that the bridge loop avoidance can't handle, send a loop
1374  * detection packet on the backbone. Unlike other BLA frames, this frame will
1375  * be allowed on the mesh by other nodes. If it is received on the mesh, this
1376  * indicates that there is a loop.
1377  */
1378 static void
1379 batadv_bla_send_loopdetect(struct batadv_priv *bat_priv,
1380 			   struct batadv_bla_backbone_gw *backbone_gw)
1381 {
1382 	batadv_dbg(BATADV_DBG_BLA, bat_priv, "Send loopdetect frame for vid %d\n",
1383 		   backbone_gw->vid);
1384 	batadv_bla_send_claim(bat_priv, bat_priv->bla.loopdetect_addr,
1385 			      backbone_gw->vid, BATADV_CLAIM_TYPE_LOOPDETECT);
1386 }
1387 
1388 /**
1389  * batadv_bla_status_update - purge bla interfaces if necessary
1390  * @net_dev: the soft interface net device
1391  */
1392 void batadv_bla_status_update(struct net_device *net_dev)
1393 {
1394 	struct batadv_priv *bat_priv = netdev_priv(net_dev);
1395 	struct batadv_hard_iface *primary_if;
1396 
1397 	primary_if = batadv_primary_if_get_selected(bat_priv);
1398 	if (!primary_if)
1399 		return;
1400 
1401 	/* this function already purges everything when bla is disabled,
1402 	 * so just call that one.
1403 	 */
1404 	batadv_bla_update_orig_address(bat_priv, primary_if, primary_if);
1405 	batadv_hardif_put(primary_if);
1406 }
1407 
1408 /**
1409  * batadv_bla_periodic_work - performs periodic bla work
1410  * @work: kernel work struct
1411  *
1412  * periodic work to do:
1413  *  * purge structures when they are too old
1414  *  * send announcements
1415  */
1416 static void batadv_bla_periodic_work(struct work_struct *work)
1417 {
1418 	struct delayed_work *delayed_work;
1419 	struct batadv_priv *bat_priv;
1420 	struct batadv_priv_bla *priv_bla;
1421 	struct hlist_head *head;
1422 	struct batadv_bla_backbone_gw *backbone_gw;
1423 	struct batadv_hashtable *hash;
1424 	struct batadv_hard_iface *primary_if;
1425 	bool send_loopdetect = false;
1426 	int i;
1427 
1428 	delayed_work = to_delayed_work(work);
1429 	priv_bla = container_of(delayed_work, struct batadv_priv_bla, work);
1430 	bat_priv = container_of(priv_bla, struct batadv_priv, bla);
1431 	primary_if = batadv_primary_if_get_selected(bat_priv);
1432 	if (!primary_if)
1433 		goto out;
1434 
1435 	batadv_bla_purge_claims(bat_priv, primary_if, 0);
1436 	batadv_bla_purge_backbone_gw(bat_priv, 0);
1437 
1438 	if (!atomic_read(&bat_priv->bridge_loop_avoidance))
1439 		goto out;
1440 
1441 	if (atomic_dec_and_test(&bat_priv->bla.loopdetect_next)) {
1442 		/* set a new random mac address for the next bridge loop
1443 		 * detection frames. Set the locally administered bit to avoid
1444 		 * collisions with users mac addresses.
1445 		 */
1446 		random_ether_addr(bat_priv->bla.loopdetect_addr);
1447 		bat_priv->bla.loopdetect_addr[0] = 0xba;
1448 		bat_priv->bla.loopdetect_addr[1] = 0xbe;
1449 		bat_priv->bla.loopdetect_lasttime = jiffies;
1450 		atomic_set(&bat_priv->bla.loopdetect_next,
1451 			   BATADV_BLA_LOOPDETECT_PERIODS);
1452 
1453 		/* mark for sending loop detect on all VLANs */
1454 		send_loopdetect = true;
1455 	}
1456 
1457 	hash = bat_priv->bla.backbone_hash;
1458 	if (!hash)
1459 		goto out;
1460 
1461 	for (i = 0; i < hash->size; i++) {
1462 		head = &hash->table[i];
1463 
1464 		rcu_read_lock();
1465 		hlist_for_each_entry_rcu(backbone_gw, head, hash_entry) {
1466 			if (!batadv_compare_eth(backbone_gw->orig,
1467 						primary_if->net_dev->dev_addr))
1468 				continue;
1469 
1470 			backbone_gw->lasttime = jiffies;
1471 
1472 			batadv_bla_send_announce(bat_priv, backbone_gw);
1473 			if (send_loopdetect)
1474 				batadv_bla_send_loopdetect(bat_priv,
1475 							   backbone_gw);
1476 
1477 			/* request_sent is only set after creation to avoid
1478 			 * problems when we are not yet known as backbone gw
1479 			 * in the backbone.
1480 			 *
1481 			 * We can reset this now after we waited some periods
1482 			 * to give bridge forward delays and bla group forming
1483 			 * some grace time.
1484 			 */
1485 
1486 			if (atomic_read(&backbone_gw->request_sent) == 0)
1487 				continue;
1488 
1489 			if (!atomic_dec_and_test(&backbone_gw->wait_periods))
1490 				continue;
1491 
1492 			atomic_dec(&backbone_gw->bat_priv->bla.num_requests);
1493 			atomic_set(&backbone_gw->request_sent, 0);
1494 		}
1495 		rcu_read_unlock();
1496 	}
1497 out:
1498 	if (primary_if)
1499 		batadv_hardif_put(primary_if);
1500 
1501 	queue_delayed_work(batadv_event_workqueue, &bat_priv->bla.work,
1502 			   msecs_to_jiffies(BATADV_BLA_PERIOD_LENGTH));
1503 }
1504 
1505 /* The hash for claim and backbone hash receive the same key because they
1506  * are getting initialized by hash_new with the same key. Reinitializing
1507  * them with to different keys to allow nested locking without generating
1508  * lockdep warnings
1509  */
1510 static struct lock_class_key batadv_claim_hash_lock_class_key;
1511 static struct lock_class_key batadv_backbone_hash_lock_class_key;
1512 
1513 /**
1514  * batadv_bla_init - initialize all bla structures
1515  * @bat_priv: the bat priv with all the soft interface information
1516  *
1517  * Return: 0 on success, < 0 on error.
1518  */
1519 int batadv_bla_init(struct batadv_priv *bat_priv)
1520 {
1521 	int i;
1522 	u8 claim_dest[ETH_ALEN] = {0xff, 0x43, 0x05, 0x00, 0x00, 0x00};
1523 	struct batadv_hard_iface *primary_if;
1524 	u16 crc;
1525 	unsigned long entrytime;
1526 
1527 	spin_lock_init(&bat_priv->bla.bcast_duplist_lock);
1528 
1529 	batadv_dbg(BATADV_DBG_BLA, bat_priv, "bla hash registering\n");
1530 
1531 	/* setting claim destination address */
1532 	memcpy(&bat_priv->bla.claim_dest.magic, claim_dest, 3);
1533 	bat_priv->bla.claim_dest.type = 0;
1534 	primary_if = batadv_primary_if_get_selected(bat_priv);
1535 	if (primary_if) {
1536 		crc = crc16(0, primary_if->net_dev->dev_addr, ETH_ALEN);
1537 		bat_priv->bla.claim_dest.group = htons(crc);
1538 		batadv_hardif_put(primary_if);
1539 	} else {
1540 		bat_priv->bla.claim_dest.group = 0; /* will be set later */
1541 	}
1542 
1543 	/* initialize the duplicate list */
1544 	entrytime = jiffies - msecs_to_jiffies(BATADV_DUPLIST_TIMEOUT);
1545 	for (i = 0; i < BATADV_DUPLIST_SIZE; i++)
1546 		bat_priv->bla.bcast_duplist[i].entrytime = entrytime;
1547 	bat_priv->bla.bcast_duplist_curr = 0;
1548 
1549 	atomic_set(&bat_priv->bla.loopdetect_next,
1550 		   BATADV_BLA_LOOPDETECT_PERIODS);
1551 
1552 	if (bat_priv->bla.claim_hash)
1553 		return 0;
1554 
1555 	bat_priv->bla.claim_hash = batadv_hash_new(128);
1556 	bat_priv->bla.backbone_hash = batadv_hash_new(32);
1557 
1558 	if (!bat_priv->bla.claim_hash || !bat_priv->bla.backbone_hash)
1559 		return -ENOMEM;
1560 
1561 	batadv_hash_set_lock_class(bat_priv->bla.claim_hash,
1562 				   &batadv_claim_hash_lock_class_key);
1563 	batadv_hash_set_lock_class(bat_priv->bla.backbone_hash,
1564 				   &batadv_backbone_hash_lock_class_key);
1565 
1566 	batadv_dbg(BATADV_DBG_BLA, bat_priv, "bla hashes initialized\n");
1567 
1568 	INIT_DELAYED_WORK(&bat_priv->bla.work, batadv_bla_periodic_work);
1569 
1570 	queue_delayed_work(batadv_event_workqueue, &bat_priv->bla.work,
1571 			   msecs_to_jiffies(BATADV_BLA_PERIOD_LENGTH));
1572 	return 0;
1573 }
1574 
1575 /**
1576  * batadv_bla_check_bcast_duplist - Check if a frame is in the broadcast dup.
1577  * @bat_priv: the bat priv with all the soft interface information
1578  * @skb: contains the bcast_packet to be checked
1579  *
1580  * check if it is on our broadcast list. Another gateway might
1581  * have sent the same packet because it is connected to the same backbone,
1582  * so we have to remove this duplicate.
1583  *
1584  * This is performed by checking the CRC, which will tell us
1585  * with a good chance that it is the same packet. If it is furthermore
1586  * sent by another host, drop it. We allow equal packets from
1587  * the same host however as this might be intended.
1588  *
1589  * Return: true if a packet is in the duplicate list, false otherwise.
1590  */
1591 bool batadv_bla_check_bcast_duplist(struct batadv_priv *bat_priv,
1592 				    struct sk_buff *skb)
1593 {
1594 	int i, curr;
1595 	__be32 crc;
1596 	struct batadv_bcast_packet *bcast_packet;
1597 	struct batadv_bcast_duplist_entry *entry;
1598 	bool ret = false;
1599 
1600 	bcast_packet = (struct batadv_bcast_packet *)skb->data;
1601 
1602 	/* calculate the crc ... */
1603 	crc = batadv_skb_crc32(skb, (u8 *)(bcast_packet + 1));
1604 
1605 	spin_lock_bh(&bat_priv->bla.bcast_duplist_lock);
1606 
1607 	for (i = 0; i < BATADV_DUPLIST_SIZE; i++) {
1608 		curr = (bat_priv->bla.bcast_duplist_curr + i);
1609 		curr %= BATADV_DUPLIST_SIZE;
1610 		entry = &bat_priv->bla.bcast_duplist[curr];
1611 
1612 		/* we can stop searching if the entry is too old ;
1613 		 * later entries will be even older
1614 		 */
1615 		if (batadv_has_timed_out(entry->entrytime,
1616 					 BATADV_DUPLIST_TIMEOUT))
1617 			break;
1618 
1619 		if (entry->crc != crc)
1620 			continue;
1621 
1622 		if (batadv_compare_eth(entry->orig, bcast_packet->orig))
1623 			continue;
1624 
1625 		/* this entry seems to match: same crc, not too old,
1626 		 * and from another gw. therefore return true to forbid it.
1627 		 */
1628 		ret = true;
1629 		goto out;
1630 	}
1631 	/* not found, add a new entry (overwrite the oldest entry)
1632 	 * and allow it, its the first occurrence.
1633 	 */
1634 	curr = (bat_priv->bla.bcast_duplist_curr + BATADV_DUPLIST_SIZE - 1);
1635 	curr %= BATADV_DUPLIST_SIZE;
1636 	entry = &bat_priv->bla.bcast_duplist[curr];
1637 	entry->crc = crc;
1638 	entry->entrytime = jiffies;
1639 	ether_addr_copy(entry->orig, bcast_packet->orig);
1640 	bat_priv->bla.bcast_duplist_curr = curr;
1641 
1642 out:
1643 	spin_unlock_bh(&bat_priv->bla.bcast_duplist_lock);
1644 
1645 	return ret;
1646 }
1647 
1648 /**
1649  * batadv_bla_is_backbone_gw_orig - Check if the originator is a gateway for
1650  *  the VLAN identified by vid.
1651  * @bat_priv: the bat priv with all the soft interface information
1652  * @orig: originator mac address
1653  * @vid: VLAN identifier
1654  *
1655  * Return: true if orig is a backbone for this vid, false otherwise.
1656  */
1657 bool batadv_bla_is_backbone_gw_orig(struct batadv_priv *bat_priv, u8 *orig,
1658 				    unsigned short vid)
1659 {
1660 	struct batadv_hashtable *hash = bat_priv->bla.backbone_hash;
1661 	struct hlist_head *head;
1662 	struct batadv_bla_backbone_gw *backbone_gw;
1663 	int i;
1664 
1665 	if (!atomic_read(&bat_priv->bridge_loop_avoidance))
1666 		return false;
1667 
1668 	if (!hash)
1669 		return false;
1670 
1671 	for (i = 0; i < hash->size; i++) {
1672 		head = &hash->table[i];
1673 
1674 		rcu_read_lock();
1675 		hlist_for_each_entry_rcu(backbone_gw, head, hash_entry) {
1676 			if (batadv_compare_eth(backbone_gw->orig, orig) &&
1677 			    backbone_gw->vid == vid) {
1678 				rcu_read_unlock();
1679 				return true;
1680 			}
1681 		}
1682 		rcu_read_unlock();
1683 	}
1684 
1685 	return false;
1686 }
1687 
1688 /**
1689  * batadv_bla_is_backbone_gw - check if originator is a backbone gw for a VLAN.
1690  * @skb: the frame to be checked
1691  * @orig_node: the orig_node of the frame
1692  * @hdr_size: maximum length of the frame
1693  *
1694  * Return: true if the orig_node is also a gateway on the soft interface,
1695  * otherwise it returns false.
1696  */
1697 bool batadv_bla_is_backbone_gw(struct sk_buff *skb,
1698 			       struct batadv_orig_node *orig_node, int hdr_size)
1699 {
1700 	struct batadv_bla_backbone_gw *backbone_gw;
1701 	unsigned short vid;
1702 
1703 	if (!atomic_read(&orig_node->bat_priv->bridge_loop_avoidance))
1704 		return false;
1705 
1706 	/* first, find out the vid. */
1707 	if (!pskb_may_pull(skb, hdr_size + ETH_HLEN))
1708 		return false;
1709 
1710 	vid = batadv_get_vid(skb, hdr_size);
1711 
1712 	/* see if this originator is a backbone gw for this VLAN */
1713 	backbone_gw = batadv_backbone_hash_find(orig_node->bat_priv,
1714 						orig_node->orig, vid);
1715 	if (!backbone_gw)
1716 		return false;
1717 
1718 	batadv_backbone_gw_put(backbone_gw);
1719 	return true;
1720 }
1721 
1722 /**
1723  * batadv_bla_free - free all bla structures
1724  * @bat_priv: the bat priv with all the soft interface information
1725  *
1726  * for softinterface free or module unload
1727  */
1728 void batadv_bla_free(struct batadv_priv *bat_priv)
1729 {
1730 	struct batadv_hard_iface *primary_if;
1731 
1732 	cancel_delayed_work_sync(&bat_priv->bla.work);
1733 	primary_if = batadv_primary_if_get_selected(bat_priv);
1734 
1735 	if (bat_priv->bla.claim_hash) {
1736 		batadv_bla_purge_claims(bat_priv, primary_if, 1);
1737 		batadv_hash_destroy(bat_priv->bla.claim_hash);
1738 		bat_priv->bla.claim_hash = NULL;
1739 	}
1740 	if (bat_priv->bla.backbone_hash) {
1741 		batadv_bla_purge_backbone_gw(bat_priv, 1);
1742 		batadv_hash_destroy(bat_priv->bla.backbone_hash);
1743 		bat_priv->bla.backbone_hash = NULL;
1744 	}
1745 	if (primary_if)
1746 		batadv_hardif_put(primary_if);
1747 }
1748 
1749 /**
1750  * batadv_bla_loopdetect_check - check and handle a detected loop
1751  * @bat_priv: the bat priv with all the soft interface information
1752  * @skb: the packet to check
1753  * @primary_if: interface where the request came on
1754  * @vid: the VLAN ID of the frame
1755  *
1756  * Checks if this packet is a loop detect frame which has been sent by us,
1757  * throw an uevent and log the event if that is the case.
1758  *
1759  * Return: true if it is a loop detect frame which is to be dropped, false
1760  * otherwise.
1761  */
1762 static bool
1763 batadv_bla_loopdetect_check(struct batadv_priv *bat_priv, struct sk_buff *skb,
1764 			    struct batadv_hard_iface *primary_if,
1765 			    unsigned short vid)
1766 {
1767 	struct batadv_bla_backbone_gw *backbone_gw;
1768 	struct ethhdr *ethhdr;
1769 
1770 	ethhdr = eth_hdr(skb);
1771 
1772 	/* Only check for the MAC address and skip more checks here for
1773 	 * performance reasons - this function is on the hotpath, after all.
1774 	 */
1775 	if (!batadv_compare_eth(ethhdr->h_source,
1776 				bat_priv->bla.loopdetect_addr))
1777 		return false;
1778 
1779 	/* If the packet came too late, don't forward it on the mesh
1780 	 * but don't consider that as loop. It might be a coincidence.
1781 	 */
1782 	if (batadv_has_timed_out(bat_priv->bla.loopdetect_lasttime,
1783 				 BATADV_BLA_LOOPDETECT_TIMEOUT))
1784 		return true;
1785 
1786 	backbone_gw = batadv_bla_get_backbone_gw(bat_priv,
1787 						 primary_if->net_dev->dev_addr,
1788 						 vid, true);
1789 	if (unlikely(!backbone_gw))
1790 		return true;
1791 
1792 	queue_work(batadv_event_workqueue, &backbone_gw->report_work);
1793 	/* backbone_gw is unreferenced in the report work function function */
1794 
1795 	return true;
1796 }
1797 
1798 /**
1799  * batadv_bla_rx - check packets coming from the mesh.
1800  * @bat_priv: the bat priv with all the soft interface information
1801  * @skb: the frame to be checked
1802  * @vid: the VLAN ID of the frame
1803  * @is_bcast: the packet came in a broadcast packet type.
1804  *
1805  * batadv_bla_rx avoidance checks if:
1806  *  * we have to race for a claim
1807  *  * if the frame is allowed on the LAN
1808  *
1809  * in these cases, the skb is further handled by this function
1810  *
1811  * Return: true if handled, otherwise it returns false and the caller shall
1812  * further process the skb.
1813  */
1814 bool batadv_bla_rx(struct batadv_priv *bat_priv, struct sk_buff *skb,
1815 		   unsigned short vid, bool is_bcast)
1816 {
1817 	struct batadv_bla_backbone_gw *backbone_gw;
1818 	struct ethhdr *ethhdr;
1819 	struct batadv_bla_claim search_claim, *claim = NULL;
1820 	struct batadv_hard_iface *primary_if;
1821 	bool own_claim;
1822 	bool ret;
1823 
1824 	ethhdr = eth_hdr(skb);
1825 
1826 	primary_if = batadv_primary_if_get_selected(bat_priv);
1827 	if (!primary_if)
1828 		goto handled;
1829 
1830 	if (!atomic_read(&bat_priv->bridge_loop_avoidance))
1831 		goto allow;
1832 
1833 	if (batadv_bla_loopdetect_check(bat_priv, skb, primary_if, vid))
1834 		goto handled;
1835 
1836 	if (unlikely(atomic_read(&bat_priv->bla.num_requests)))
1837 		/* don't allow broadcasts while requests are in flight */
1838 		if (is_multicast_ether_addr(ethhdr->h_dest) && is_bcast)
1839 			goto handled;
1840 
1841 	ether_addr_copy(search_claim.addr, ethhdr->h_source);
1842 	search_claim.vid = vid;
1843 	claim = batadv_claim_hash_find(bat_priv, &search_claim);
1844 
1845 	if (!claim) {
1846 		/* possible optimization: race for a claim */
1847 		/* No claim exists yet, claim it for us!
1848 		 */
1849 		batadv_handle_claim(bat_priv, primary_if,
1850 				    primary_if->net_dev->dev_addr,
1851 				    ethhdr->h_source, vid);
1852 		goto allow;
1853 	}
1854 
1855 	/* if it is our own claim ... */
1856 	backbone_gw = batadv_bla_claim_get_backbone_gw(claim);
1857 	own_claim = batadv_compare_eth(backbone_gw->orig,
1858 				       primary_if->net_dev->dev_addr);
1859 	batadv_backbone_gw_put(backbone_gw);
1860 
1861 	if (own_claim) {
1862 		/* ... allow it in any case */
1863 		claim->lasttime = jiffies;
1864 		goto allow;
1865 	}
1866 
1867 	/* if it is a broadcast ... */
1868 	if (is_multicast_ether_addr(ethhdr->h_dest) && is_bcast) {
1869 		/* ... drop it. the responsible gateway is in charge.
1870 		 *
1871 		 * We need to check is_bcast because with the gateway
1872 		 * feature, broadcasts (like DHCP requests) may be sent
1873 		 * using a unicast packet type.
1874 		 */
1875 		goto handled;
1876 	} else {
1877 		/* seems the client considers us as its best gateway.
1878 		 * send a claim and update the claim table
1879 		 * immediately.
1880 		 */
1881 		batadv_handle_claim(bat_priv, primary_if,
1882 				    primary_if->net_dev->dev_addr,
1883 				    ethhdr->h_source, vid);
1884 		goto allow;
1885 	}
1886 allow:
1887 	batadv_bla_update_own_backbone_gw(bat_priv, primary_if, vid);
1888 	ret = false;
1889 	goto out;
1890 
1891 handled:
1892 	kfree_skb(skb);
1893 	ret = true;
1894 
1895 out:
1896 	if (primary_if)
1897 		batadv_hardif_put(primary_if);
1898 	if (claim)
1899 		batadv_claim_put(claim);
1900 	return ret;
1901 }
1902 
1903 /**
1904  * batadv_bla_tx - check packets going into the mesh
1905  * @bat_priv: the bat priv with all the soft interface information
1906  * @skb: the frame to be checked
1907  * @vid: the VLAN ID of the frame
1908  *
1909  * batadv_bla_tx checks if:
1910  *  * a claim was received which has to be processed
1911  *  * the frame is allowed on the mesh
1912  *
1913  * in these cases, the skb is further handled by this function.
1914  *
1915  * This call might reallocate skb data.
1916  *
1917  * Return: true if handled, otherwise it returns false and the caller shall
1918  * further process the skb.
1919  */
1920 bool batadv_bla_tx(struct batadv_priv *bat_priv, struct sk_buff *skb,
1921 		   unsigned short vid)
1922 {
1923 	struct ethhdr *ethhdr;
1924 	struct batadv_bla_claim search_claim, *claim = NULL;
1925 	struct batadv_bla_backbone_gw *backbone_gw;
1926 	struct batadv_hard_iface *primary_if;
1927 	bool client_roamed;
1928 	bool ret = false;
1929 
1930 	primary_if = batadv_primary_if_get_selected(bat_priv);
1931 	if (!primary_if)
1932 		goto out;
1933 
1934 	if (!atomic_read(&bat_priv->bridge_loop_avoidance))
1935 		goto allow;
1936 
1937 	if (batadv_bla_process_claim(bat_priv, primary_if, skb))
1938 		goto handled;
1939 
1940 	ethhdr = eth_hdr(skb);
1941 
1942 	if (unlikely(atomic_read(&bat_priv->bla.num_requests)))
1943 		/* don't allow broadcasts while requests are in flight */
1944 		if (is_multicast_ether_addr(ethhdr->h_dest))
1945 			goto handled;
1946 
1947 	ether_addr_copy(search_claim.addr, ethhdr->h_source);
1948 	search_claim.vid = vid;
1949 
1950 	claim = batadv_claim_hash_find(bat_priv, &search_claim);
1951 
1952 	/* if no claim exists, allow it. */
1953 	if (!claim)
1954 		goto allow;
1955 
1956 	/* check if we are responsible. */
1957 	backbone_gw = batadv_bla_claim_get_backbone_gw(claim);
1958 	client_roamed = batadv_compare_eth(backbone_gw->orig,
1959 					   primary_if->net_dev->dev_addr);
1960 	batadv_backbone_gw_put(backbone_gw);
1961 
1962 	if (client_roamed) {
1963 		/* if yes, the client has roamed and we have
1964 		 * to unclaim it.
1965 		 */
1966 		batadv_handle_unclaim(bat_priv, primary_if,
1967 				      primary_if->net_dev->dev_addr,
1968 				      ethhdr->h_source, vid);
1969 		goto allow;
1970 	}
1971 
1972 	/* check if it is a multicast/broadcast frame */
1973 	if (is_multicast_ether_addr(ethhdr->h_dest)) {
1974 		/* drop it. the responsible gateway has forwarded it into
1975 		 * the backbone network.
1976 		 */
1977 		goto handled;
1978 	} else {
1979 		/* we must allow it. at least if we are
1980 		 * responsible for the DESTINATION.
1981 		 */
1982 		goto allow;
1983 	}
1984 allow:
1985 	batadv_bla_update_own_backbone_gw(bat_priv, primary_if, vid);
1986 	ret = false;
1987 	goto out;
1988 handled:
1989 	ret = true;
1990 out:
1991 	if (primary_if)
1992 		batadv_hardif_put(primary_if);
1993 	if (claim)
1994 		batadv_claim_put(claim);
1995 	return ret;
1996 }
1997 
1998 #ifdef CONFIG_BATMAN_ADV_DEBUGFS
1999 /**
2000  * batadv_bla_claim_table_seq_print_text - print the claim table in a seq file
2001  * @seq: seq file to print on
2002  * @offset: not used
2003  *
2004  * Return: always 0
2005  */
2006 int batadv_bla_claim_table_seq_print_text(struct seq_file *seq, void *offset)
2007 {
2008 	struct net_device *net_dev = (struct net_device *)seq->private;
2009 	struct batadv_priv *bat_priv = netdev_priv(net_dev);
2010 	struct batadv_hashtable *hash = bat_priv->bla.claim_hash;
2011 	struct batadv_bla_backbone_gw *backbone_gw;
2012 	struct batadv_bla_claim *claim;
2013 	struct batadv_hard_iface *primary_if;
2014 	struct hlist_head *head;
2015 	u16 backbone_crc;
2016 	u32 i;
2017 	bool is_own;
2018 	u8 *primary_addr;
2019 
2020 	primary_if = batadv_seq_print_text_primary_if_get(seq);
2021 	if (!primary_if)
2022 		goto out;
2023 
2024 	primary_addr = primary_if->net_dev->dev_addr;
2025 	seq_printf(seq,
2026 		   "Claims announced for the mesh %s (orig %pM, group id %#.4x)\n",
2027 		   net_dev->name, primary_addr,
2028 		   ntohs(bat_priv->bla.claim_dest.group));
2029 	seq_puts(seq,
2030 		 "   Client               VID      Originator        [o] (CRC   )\n");
2031 	for (i = 0; i < hash->size; i++) {
2032 		head = &hash->table[i];
2033 
2034 		rcu_read_lock();
2035 		hlist_for_each_entry_rcu(claim, head, hash_entry) {
2036 			backbone_gw = batadv_bla_claim_get_backbone_gw(claim);
2037 
2038 			is_own = batadv_compare_eth(backbone_gw->orig,
2039 						    primary_addr);
2040 
2041 			spin_lock_bh(&backbone_gw->crc_lock);
2042 			backbone_crc = backbone_gw->crc;
2043 			spin_unlock_bh(&backbone_gw->crc_lock);
2044 			seq_printf(seq, " * %pM on %5d by %pM [%c] (%#.4x)\n",
2045 				   claim->addr, BATADV_PRINT_VID(claim->vid),
2046 				   backbone_gw->orig,
2047 				   (is_own ? 'x' : ' '),
2048 				   backbone_crc);
2049 
2050 			batadv_backbone_gw_put(backbone_gw);
2051 		}
2052 		rcu_read_unlock();
2053 	}
2054 out:
2055 	if (primary_if)
2056 		batadv_hardif_put(primary_if);
2057 	return 0;
2058 }
2059 #endif
2060 
2061 /**
2062  * batadv_bla_claim_dump_entry - dump one entry of the claim table
2063  * to a netlink socket
2064  * @msg: buffer for the message
2065  * @portid: netlink port
2066  * @seq: Sequence number of netlink message
2067  * @primary_if: primary interface
2068  * @claim: entry to dump
2069  *
2070  * Return: 0 or error code.
2071  */
2072 static int
2073 batadv_bla_claim_dump_entry(struct sk_buff *msg, u32 portid, u32 seq,
2074 			    struct batadv_hard_iface *primary_if,
2075 			    struct batadv_bla_claim *claim)
2076 {
2077 	u8 *primary_addr = primary_if->net_dev->dev_addr;
2078 	u16 backbone_crc;
2079 	bool is_own;
2080 	void *hdr;
2081 	int ret = -EINVAL;
2082 
2083 	hdr = genlmsg_put(msg, portid, seq, &batadv_netlink_family,
2084 			  NLM_F_MULTI, BATADV_CMD_GET_BLA_CLAIM);
2085 	if (!hdr) {
2086 		ret = -ENOBUFS;
2087 		goto out;
2088 	}
2089 
2090 	is_own = batadv_compare_eth(claim->backbone_gw->orig,
2091 				    primary_addr);
2092 
2093 	spin_lock_bh(&claim->backbone_gw->crc_lock);
2094 	backbone_crc = claim->backbone_gw->crc;
2095 	spin_unlock_bh(&claim->backbone_gw->crc_lock);
2096 
2097 	if (is_own)
2098 		if (nla_put_flag(msg, BATADV_ATTR_BLA_OWN)) {
2099 			genlmsg_cancel(msg, hdr);
2100 			goto out;
2101 		}
2102 
2103 	if (nla_put(msg, BATADV_ATTR_BLA_ADDRESS, ETH_ALEN, claim->addr) ||
2104 	    nla_put_u16(msg, BATADV_ATTR_BLA_VID, claim->vid) ||
2105 	    nla_put(msg, BATADV_ATTR_BLA_BACKBONE, ETH_ALEN,
2106 		    claim->backbone_gw->orig) ||
2107 	    nla_put_u16(msg, BATADV_ATTR_BLA_CRC,
2108 			backbone_crc)) {
2109 		genlmsg_cancel(msg, hdr);
2110 		goto out;
2111 	}
2112 
2113 	genlmsg_end(msg, hdr);
2114 	ret = 0;
2115 
2116 out:
2117 	return ret;
2118 }
2119 
2120 /**
2121  * batadv_bla_claim_dump_bucket - dump one bucket of the claim table
2122  * to a netlink socket
2123  * @msg: buffer for the message
2124  * @portid: netlink port
2125  * @seq: Sequence number of netlink message
2126  * @primary_if: primary interface
2127  * @head: bucket to dump
2128  * @idx_skip: How many entries to skip
2129  *
2130  * Return: always 0.
2131  */
2132 static int
2133 batadv_bla_claim_dump_bucket(struct sk_buff *msg, u32 portid, u32 seq,
2134 			     struct batadv_hard_iface *primary_if,
2135 			     struct hlist_head *head, int *idx_skip)
2136 {
2137 	struct batadv_bla_claim *claim;
2138 	int idx = 0;
2139 
2140 	rcu_read_lock();
2141 	hlist_for_each_entry_rcu(claim, head, hash_entry) {
2142 		if (idx++ < *idx_skip)
2143 			continue;
2144 		if (batadv_bla_claim_dump_entry(msg, portid, seq,
2145 						primary_if, claim)) {
2146 			*idx_skip = idx - 1;
2147 			goto unlock;
2148 		}
2149 	}
2150 
2151 	*idx_skip = idx;
2152 unlock:
2153 	rcu_read_unlock();
2154 	return 0;
2155 }
2156 
2157 /**
2158  * batadv_bla_claim_dump - dump claim table to a netlink socket
2159  * @msg: buffer for the message
2160  * @cb: callback structure containing arguments
2161  *
2162  * Return: message length.
2163  */
2164 int batadv_bla_claim_dump(struct sk_buff *msg, struct netlink_callback *cb)
2165 {
2166 	struct batadv_hard_iface *primary_if = NULL;
2167 	int portid = NETLINK_CB(cb->skb).portid;
2168 	struct net *net = sock_net(cb->skb->sk);
2169 	struct net_device *soft_iface;
2170 	struct batadv_hashtable *hash;
2171 	struct batadv_priv *bat_priv;
2172 	int bucket = cb->args[0];
2173 	struct hlist_head *head;
2174 	int idx = cb->args[1];
2175 	int ifindex;
2176 	int ret = 0;
2177 
2178 	ifindex = batadv_netlink_get_ifindex(cb->nlh,
2179 					     BATADV_ATTR_MESH_IFINDEX);
2180 	if (!ifindex)
2181 		return -EINVAL;
2182 
2183 	soft_iface = dev_get_by_index(net, ifindex);
2184 	if (!soft_iface || !batadv_softif_is_valid(soft_iface)) {
2185 		ret = -ENODEV;
2186 		goto out;
2187 	}
2188 
2189 	bat_priv = netdev_priv(soft_iface);
2190 	hash = bat_priv->bla.claim_hash;
2191 
2192 	primary_if = batadv_primary_if_get_selected(bat_priv);
2193 	if (!primary_if || primary_if->if_status != BATADV_IF_ACTIVE) {
2194 		ret = -ENOENT;
2195 		goto out;
2196 	}
2197 
2198 	while (bucket < hash->size) {
2199 		head = &hash->table[bucket];
2200 
2201 		if (batadv_bla_claim_dump_bucket(msg, portid,
2202 						 cb->nlh->nlmsg_seq,
2203 						 primary_if, head, &idx))
2204 			break;
2205 		bucket++;
2206 	}
2207 
2208 	cb->args[0] = bucket;
2209 	cb->args[1] = idx;
2210 
2211 	ret = msg->len;
2212 
2213 out:
2214 	if (primary_if)
2215 		batadv_hardif_put(primary_if);
2216 
2217 	if (soft_iface)
2218 		dev_put(soft_iface);
2219 
2220 	return ret;
2221 }
2222 
2223 #ifdef CONFIG_BATMAN_ADV_DEBUGFS
2224 /**
2225  * batadv_bla_backbone_table_seq_print_text - print the backbone table in a seq
2226  *  file
2227  * @seq: seq file to print on
2228  * @offset: not used
2229  *
2230  * Return: always 0
2231  */
2232 int batadv_bla_backbone_table_seq_print_text(struct seq_file *seq, void *offset)
2233 {
2234 	struct net_device *net_dev = (struct net_device *)seq->private;
2235 	struct batadv_priv *bat_priv = netdev_priv(net_dev);
2236 	struct batadv_hashtable *hash = bat_priv->bla.backbone_hash;
2237 	struct batadv_bla_backbone_gw *backbone_gw;
2238 	struct batadv_hard_iface *primary_if;
2239 	struct hlist_head *head;
2240 	int secs, msecs;
2241 	u16 backbone_crc;
2242 	u32 i;
2243 	bool is_own;
2244 	u8 *primary_addr;
2245 
2246 	primary_if = batadv_seq_print_text_primary_if_get(seq);
2247 	if (!primary_if)
2248 		goto out;
2249 
2250 	primary_addr = primary_if->net_dev->dev_addr;
2251 	seq_printf(seq,
2252 		   "Backbones announced for the mesh %s (orig %pM, group id %#.4x)\n",
2253 		   net_dev->name, primary_addr,
2254 		   ntohs(bat_priv->bla.claim_dest.group));
2255 	seq_puts(seq, "   Originator           VID   last seen (CRC   )\n");
2256 	for (i = 0; i < hash->size; i++) {
2257 		head = &hash->table[i];
2258 
2259 		rcu_read_lock();
2260 		hlist_for_each_entry_rcu(backbone_gw, head, hash_entry) {
2261 			msecs = jiffies_to_msecs(jiffies -
2262 						 backbone_gw->lasttime);
2263 			secs = msecs / 1000;
2264 			msecs = msecs % 1000;
2265 
2266 			is_own = batadv_compare_eth(backbone_gw->orig,
2267 						    primary_addr);
2268 			if (is_own)
2269 				continue;
2270 
2271 			spin_lock_bh(&backbone_gw->crc_lock);
2272 			backbone_crc = backbone_gw->crc;
2273 			spin_unlock_bh(&backbone_gw->crc_lock);
2274 
2275 			seq_printf(seq, " * %pM on %5d %4i.%03is (%#.4x)\n",
2276 				   backbone_gw->orig,
2277 				   BATADV_PRINT_VID(backbone_gw->vid), secs,
2278 				   msecs, backbone_crc);
2279 		}
2280 		rcu_read_unlock();
2281 	}
2282 out:
2283 	if (primary_if)
2284 		batadv_hardif_put(primary_if);
2285 	return 0;
2286 }
2287 #endif
2288 
2289 /**
2290  * batadv_bla_backbone_dump_entry - dump one entry of the backbone table
2291  * to a netlink socket
2292  * @msg: buffer for the message
2293  * @portid: netlink port
2294  * @seq: Sequence number of netlink message
2295  * @primary_if: primary interface
2296  * @backbone_gw: entry to dump
2297  *
2298  * Return: 0 or error code.
2299  */
2300 static int
2301 batadv_bla_backbone_dump_entry(struct sk_buff *msg, u32 portid, u32 seq,
2302 			       struct batadv_hard_iface *primary_if,
2303 			       struct batadv_bla_backbone_gw *backbone_gw)
2304 {
2305 	u8 *primary_addr = primary_if->net_dev->dev_addr;
2306 	u16 backbone_crc;
2307 	bool is_own;
2308 	int msecs;
2309 	void *hdr;
2310 	int ret = -EINVAL;
2311 
2312 	hdr = genlmsg_put(msg, portid, seq, &batadv_netlink_family,
2313 			  NLM_F_MULTI, BATADV_CMD_GET_BLA_BACKBONE);
2314 	if (!hdr) {
2315 		ret = -ENOBUFS;
2316 		goto out;
2317 	}
2318 
2319 	is_own = batadv_compare_eth(backbone_gw->orig, primary_addr);
2320 
2321 	spin_lock_bh(&backbone_gw->crc_lock);
2322 	backbone_crc = backbone_gw->crc;
2323 	spin_unlock_bh(&backbone_gw->crc_lock);
2324 
2325 	msecs = jiffies_to_msecs(jiffies - backbone_gw->lasttime);
2326 
2327 	if (is_own)
2328 		if (nla_put_flag(msg, BATADV_ATTR_BLA_OWN)) {
2329 			genlmsg_cancel(msg, hdr);
2330 			goto out;
2331 		}
2332 
2333 	if (nla_put(msg, BATADV_ATTR_BLA_BACKBONE, ETH_ALEN,
2334 		    backbone_gw->orig) ||
2335 	    nla_put_u16(msg, BATADV_ATTR_BLA_VID, backbone_gw->vid) ||
2336 	    nla_put_u16(msg, BATADV_ATTR_BLA_CRC,
2337 			backbone_crc) ||
2338 	    nla_put_u32(msg, BATADV_ATTR_LAST_SEEN_MSECS, msecs)) {
2339 		genlmsg_cancel(msg, hdr);
2340 		goto out;
2341 	}
2342 
2343 	genlmsg_end(msg, hdr);
2344 	ret = 0;
2345 
2346 out:
2347 	return ret;
2348 }
2349 
2350 /**
2351  * batadv_bla_backbone_dump_bucket - dump one bucket of the backbone table
2352  * to a netlink socket
2353  * @msg: buffer for the message
2354  * @portid: netlink port
2355  * @seq: Sequence number of netlink message
2356  * @primary_if: primary interface
2357  * @head: bucket to dump
2358  * @idx_skip: How many entries to skip
2359  *
2360  * Return: always 0.
2361  */
2362 static int
2363 batadv_bla_backbone_dump_bucket(struct sk_buff *msg, u32 portid, u32 seq,
2364 				struct batadv_hard_iface *primary_if,
2365 				struct hlist_head *head, int *idx_skip)
2366 {
2367 	struct batadv_bla_backbone_gw *backbone_gw;
2368 	int idx = 0;
2369 
2370 	rcu_read_lock();
2371 	hlist_for_each_entry_rcu(backbone_gw, head, hash_entry) {
2372 		if (idx++ < *idx_skip)
2373 			continue;
2374 		if (batadv_bla_backbone_dump_entry(msg, portid, seq,
2375 						   primary_if, backbone_gw)) {
2376 			*idx_skip = idx - 1;
2377 			goto unlock;
2378 		}
2379 	}
2380 
2381 	*idx_skip = idx;
2382 unlock:
2383 	rcu_read_unlock();
2384 	return 0;
2385 }
2386 
2387 /**
2388  * batadv_bla_backbone_dump - dump backbone table to a netlink socket
2389  * @msg: buffer for the message
2390  * @cb: callback structure containing arguments
2391  *
2392  * Return: message length.
2393  */
2394 int batadv_bla_backbone_dump(struct sk_buff *msg, struct netlink_callback *cb)
2395 {
2396 	struct batadv_hard_iface *primary_if = NULL;
2397 	int portid = NETLINK_CB(cb->skb).portid;
2398 	struct net *net = sock_net(cb->skb->sk);
2399 	struct net_device *soft_iface;
2400 	struct batadv_hashtable *hash;
2401 	struct batadv_priv *bat_priv;
2402 	int bucket = cb->args[0];
2403 	struct hlist_head *head;
2404 	int idx = cb->args[1];
2405 	int ifindex;
2406 	int ret = 0;
2407 
2408 	ifindex = batadv_netlink_get_ifindex(cb->nlh,
2409 					     BATADV_ATTR_MESH_IFINDEX);
2410 	if (!ifindex)
2411 		return -EINVAL;
2412 
2413 	soft_iface = dev_get_by_index(net, ifindex);
2414 	if (!soft_iface || !batadv_softif_is_valid(soft_iface)) {
2415 		ret = -ENODEV;
2416 		goto out;
2417 	}
2418 
2419 	bat_priv = netdev_priv(soft_iface);
2420 	hash = bat_priv->bla.backbone_hash;
2421 
2422 	primary_if = batadv_primary_if_get_selected(bat_priv);
2423 	if (!primary_if || primary_if->if_status != BATADV_IF_ACTIVE) {
2424 		ret = -ENOENT;
2425 		goto out;
2426 	}
2427 
2428 	while (bucket < hash->size) {
2429 		head = &hash->table[bucket];
2430 
2431 		if (batadv_bla_backbone_dump_bucket(msg, portid,
2432 						    cb->nlh->nlmsg_seq,
2433 						    primary_if, head, &idx))
2434 			break;
2435 		bucket++;
2436 	}
2437 
2438 	cb->args[0] = bucket;
2439 	cb->args[1] = idx;
2440 
2441 	ret = msg->len;
2442 
2443 out:
2444 	if (primary_if)
2445 		batadv_hardif_put(primary_if);
2446 
2447 	if (soft_iface)
2448 		dev_put(soft_iface);
2449 
2450 	return ret;
2451 }
2452