1 /* Copyright (C) 2007-2013 B.A.T.M.A.N. contributors: 2 * 3 * Marek Lindner, Simon Wunderlich 4 * 5 * This program is free software; you can redistribute it and/or 6 * modify it under the terms of version 2 of the GNU General Public 7 * License as published by the Free Software Foundation. 8 * 9 * This program is distributed in the hope that it will be useful, but 10 * WITHOUT ANY WARRANTY; without even the implied warranty of 11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU 12 * General Public License for more details. 13 * 14 * You should have received a copy of the GNU General Public License 15 * along with this program; if not, write to the Free Software 16 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 17 * 02110-1301, USA 18 */ 19 20 #include "main.h" 21 #include "routing.h" 22 #include "send.h" 23 #include "soft-interface.h" 24 #include "hard-interface.h" 25 #include "icmp_socket.h" 26 #include "translation-table.h" 27 #include "originator.h" 28 #include "vis.h" 29 #include "unicast.h" 30 #include "bridge_loop_avoidance.h" 31 #include "distributed-arp-table.h" 32 33 static int batadv_route_unicast_packet(struct sk_buff *skb, 34 struct batadv_hard_iface *recv_if); 35 36 void batadv_slide_own_bcast_window(struct batadv_hard_iface *hard_iface) 37 { 38 struct batadv_priv *bat_priv = netdev_priv(hard_iface->soft_iface); 39 struct batadv_hashtable *hash = bat_priv->orig_hash; 40 struct hlist_head *head; 41 struct batadv_orig_node *orig_node; 42 unsigned long *word; 43 uint32_t i; 44 size_t word_index; 45 uint8_t *w; 46 47 for (i = 0; i < hash->size; i++) { 48 head = &hash->table[i]; 49 50 rcu_read_lock(); 51 hlist_for_each_entry_rcu(orig_node, head, hash_entry) { 52 spin_lock_bh(&orig_node->ogm_cnt_lock); 53 word_index = hard_iface->if_num * BATADV_NUM_WORDS; 54 word = &(orig_node->bcast_own[word_index]); 55 56 batadv_bit_get_packet(bat_priv, word, 1, 0); 57 w = &orig_node->bcast_own_sum[hard_iface->if_num]; 58 *w = bitmap_weight(word, BATADV_TQ_LOCAL_WINDOW_SIZE); 59 spin_unlock_bh(&orig_node->ogm_cnt_lock); 60 } 61 rcu_read_unlock(); 62 } 63 } 64 65 static void _batadv_update_route(struct batadv_priv *bat_priv, 66 struct batadv_orig_node *orig_node, 67 struct batadv_neigh_node *neigh_node) 68 { 69 struct batadv_neigh_node *curr_router; 70 71 curr_router = batadv_orig_node_get_router(orig_node); 72 73 /* route deleted */ 74 if ((curr_router) && (!neigh_node)) { 75 batadv_dbg(BATADV_DBG_ROUTES, bat_priv, 76 "Deleting route towards: %pM\n", orig_node->orig); 77 batadv_tt_global_del_orig(bat_priv, orig_node, 78 "Deleted route towards originator"); 79 80 /* route added */ 81 } else if ((!curr_router) && (neigh_node)) { 82 batadv_dbg(BATADV_DBG_ROUTES, bat_priv, 83 "Adding route towards: %pM (via %pM)\n", 84 orig_node->orig, neigh_node->addr); 85 /* route changed */ 86 } else if (neigh_node && curr_router) { 87 batadv_dbg(BATADV_DBG_ROUTES, bat_priv, 88 "Changing route towards: %pM (now via %pM - was via %pM)\n", 89 orig_node->orig, neigh_node->addr, 90 curr_router->addr); 91 } 92 93 if (curr_router) 94 batadv_neigh_node_free_ref(curr_router); 95 96 /* increase refcount of new best neighbor */ 97 if (neigh_node && !atomic_inc_not_zero(&neigh_node->refcount)) 98 neigh_node = NULL; 99 100 spin_lock_bh(&orig_node->neigh_list_lock); 101 rcu_assign_pointer(orig_node->router, neigh_node); 102 spin_unlock_bh(&orig_node->neigh_list_lock); 103 104 /* decrease refcount of previous best neighbor */ 105 if (curr_router) 106 batadv_neigh_node_free_ref(curr_router); 107 } 108 109 void batadv_update_route(struct batadv_priv *bat_priv, 110 struct batadv_orig_node *orig_node, 111 struct batadv_neigh_node *neigh_node) 112 { 113 struct batadv_neigh_node *router = NULL; 114 115 if (!orig_node) 116 goto out; 117 118 router = batadv_orig_node_get_router(orig_node); 119 120 if (router != neigh_node) 121 _batadv_update_route(bat_priv, orig_node, neigh_node); 122 123 out: 124 if (router) 125 batadv_neigh_node_free_ref(router); 126 } 127 128 /* caller must hold the neigh_list_lock */ 129 void batadv_bonding_candidate_del(struct batadv_orig_node *orig_node, 130 struct batadv_neigh_node *neigh_node) 131 { 132 /* this neighbor is not part of our candidate list */ 133 if (list_empty(&neigh_node->bonding_list)) 134 goto out; 135 136 list_del_rcu(&neigh_node->bonding_list); 137 INIT_LIST_HEAD(&neigh_node->bonding_list); 138 batadv_neigh_node_free_ref(neigh_node); 139 atomic_dec(&orig_node->bond_candidates); 140 141 out: 142 return; 143 } 144 145 void batadv_bonding_candidate_add(struct batadv_orig_node *orig_node, 146 struct batadv_neigh_node *neigh_node) 147 { 148 struct batadv_neigh_node *tmp_neigh_node, *router = NULL; 149 uint8_t interference_candidate = 0; 150 151 spin_lock_bh(&orig_node->neigh_list_lock); 152 153 /* only consider if it has the same primary address ... */ 154 if (!batadv_compare_eth(orig_node->orig, 155 neigh_node->orig_node->primary_addr)) 156 goto candidate_del; 157 158 router = batadv_orig_node_get_router(orig_node); 159 if (!router) 160 goto candidate_del; 161 162 /* ... and is good enough to be considered */ 163 if (neigh_node->tq_avg < router->tq_avg - BATADV_BONDING_TQ_THRESHOLD) 164 goto candidate_del; 165 166 /* check if we have another candidate with the same mac address or 167 * interface. If we do, we won't select this candidate because of 168 * possible interference. 169 */ 170 hlist_for_each_entry_rcu(tmp_neigh_node, 171 &orig_node->neigh_list, list) { 172 if (tmp_neigh_node == neigh_node) 173 continue; 174 175 /* we only care if the other candidate is even 176 * considered as candidate. 177 */ 178 if (list_empty(&tmp_neigh_node->bonding_list)) 179 continue; 180 181 if ((neigh_node->if_incoming == tmp_neigh_node->if_incoming) || 182 (batadv_compare_eth(neigh_node->addr, 183 tmp_neigh_node->addr))) { 184 interference_candidate = 1; 185 break; 186 } 187 } 188 189 /* don't care further if it is an interference candidate */ 190 if (interference_candidate) 191 goto candidate_del; 192 193 /* this neighbor already is part of our candidate list */ 194 if (!list_empty(&neigh_node->bonding_list)) 195 goto out; 196 197 if (!atomic_inc_not_zero(&neigh_node->refcount)) 198 goto out; 199 200 list_add_rcu(&neigh_node->bonding_list, &orig_node->bond_list); 201 atomic_inc(&orig_node->bond_candidates); 202 goto out; 203 204 candidate_del: 205 batadv_bonding_candidate_del(orig_node, neigh_node); 206 207 out: 208 spin_unlock_bh(&orig_node->neigh_list_lock); 209 210 if (router) 211 batadv_neigh_node_free_ref(router); 212 } 213 214 /* copy primary address for bonding */ 215 void 216 batadv_bonding_save_primary(const struct batadv_orig_node *orig_node, 217 struct batadv_orig_node *orig_neigh_node, 218 const struct batadv_ogm_packet *batman_ogm_packet) 219 { 220 if (!(batman_ogm_packet->flags & BATADV_PRIMARIES_FIRST_HOP)) 221 return; 222 223 memcpy(orig_neigh_node->primary_addr, orig_node->orig, ETH_ALEN); 224 } 225 226 /* checks whether the host restarted and is in the protection time. 227 * returns: 228 * 0 if the packet is to be accepted 229 * 1 if the packet is to be ignored. 230 */ 231 int batadv_window_protected(struct batadv_priv *bat_priv, int32_t seq_num_diff, 232 unsigned long *last_reset) 233 { 234 if (seq_num_diff <= -BATADV_TQ_LOCAL_WINDOW_SIZE || 235 seq_num_diff >= BATADV_EXPECTED_SEQNO_RANGE) { 236 if (!batadv_has_timed_out(*last_reset, 237 BATADV_RESET_PROTECTION_MS)) 238 return 1; 239 240 *last_reset = jiffies; 241 batadv_dbg(BATADV_DBG_BATMAN, bat_priv, 242 "old packet received, start protection\n"); 243 } 244 245 return 0; 246 } 247 248 bool batadv_check_management_packet(struct sk_buff *skb, 249 struct batadv_hard_iface *hard_iface, 250 int header_len) 251 { 252 struct ethhdr *ethhdr; 253 254 /* drop packet if it has not necessary minimum size */ 255 if (unlikely(!pskb_may_pull(skb, header_len))) 256 return false; 257 258 ethhdr = (struct ethhdr *)skb_mac_header(skb); 259 260 /* packet with broadcast indication but unicast recipient */ 261 if (!is_broadcast_ether_addr(ethhdr->h_dest)) 262 return false; 263 264 /* packet with broadcast sender address */ 265 if (is_broadcast_ether_addr(ethhdr->h_source)) 266 return false; 267 268 /* create a copy of the skb, if needed, to modify it. */ 269 if (skb_cow(skb, 0) < 0) 270 return false; 271 272 /* keep skb linear */ 273 if (skb_linearize(skb) < 0) 274 return false; 275 276 return true; 277 } 278 279 static int batadv_recv_my_icmp_packet(struct batadv_priv *bat_priv, 280 struct sk_buff *skb, size_t icmp_len) 281 { 282 struct batadv_hard_iface *primary_if = NULL; 283 struct batadv_orig_node *orig_node = NULL; 284 struct batadv_icmp_packet_rr *icmp_packet; 285 int ret = NET_RX_DROP; 286 287 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 288 289 /* add data to device queue */ 290 if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) { 291 batadv_socket_receive_packet(icmp_packet, icmp_len); 292 goto out; 293 } 294 295 primary_if = batadv_primary_if_get_selected(bat_priv); 296 if (!primary_if) 297 goto out; 298 299 /* answer echo request (ping) */ 300 /* get routing information */ 301 orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig); 302 if (!orig_node) 303 goto out; 304 305 /* create a copy of the skb, if needed, to modify it. */ 306 if (skb_cow(skb, ETH_HLEN) < 0) 307 goto out; 308 309 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 310 311 memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN); 312 memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN); 313 icmp_packet->msg_type = BATADV_ECHO_REPLY; 314 icmp_packet->header.ttl = BATADV_TTL; 315 316 if (batadv_send_skb_to_orig(skb, orig_node, NULL)) 317 ret = NET_RX_SUCCESS; 318 319 out: 320 if (primary_if) 321 batadv_hardif_free_ref(primary_if); 322 if (orig_node) 323 batadv_orig_node_free_ref(orig_node); 324 return ret; 325 } 326 327 static int batadv_recv_icmp_ttl_exceeded(struct batadv_priv *bat_priv, 328 struct sk_buff *skb) 329 { 330 struct batadv_hard_iface *primary_if = NULL; 331 struct batadv_orig_node *orig_node = NULL; 332 struct batadv_icmp_packet *icmp_packet; 333 int ret = NET_RX_DROP; 334 335 icmp_packet = (struct batadv_icmp_packet *)skb->data; 336 337 /* send TTL exceeded if packet is an echo request (traceroute) */ 338 if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) { 339 pr_debug("Warning - can't forward icmp packet from %pM to %pM: ttl exceeded\n", 340 icmp_packet->orig, icmp_packet->dst); 341 goto out; 342 } 343 344 primary_if = batadv_primary_if_get_selected(bat_priv); 345 if (!primary_if) 346 goto out; 347 348 /* get routing information */ 349 orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig); 350 if (!orig_node) 351 goto out; 352 353 /* create a copy of the skb, if needed, to modify it. */ 354 if (skb_cow(skb, ETH_HLEN) < 0) 355 goto out; 356 357 icmp_packet = (struct batadv_icmp_packet *)skb->data; 358 359 memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN); 360 memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN); 361 icmp_packet->msg_type = BATADV_TTL_EXCEEDED; 362 icmp_packet->header.ttl = BATADV_TTL; 363 364 if (batadv_send_skb_to_orig(skb, orig_node, NULL)) 365 ret = NET_RX_SUCCESS; 366 367 out: 368 if (primary_if) 369 batadv_hardif_free_ref(primary_if); 370 if (orig_node) 371 batadv_orig_node_free_ref(orig_node); 372 return ret; 373 } 374 375 376 int batadv_recv_icmp_packet(struct sk_buff *skb, 377 struct batadv_hard_iface *recv_if) 378 { 379 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 380 struct batadv_icmp_packet_rr *icmp_packet; 381 struct ethhdr *ethhdr; 382 struct batadv_orig_node *orig_node = NULL; 383 int hdr_size = sizeof(struct batadv_icmp_packet); 384 int ret = NET_RX_DROP; 385 386 /* we truncate all incoming icmp packets if they don't match our size */ 387 if (skb->len >= sizeof(struct batadv_icmp_packet_rr)) 388 hdr_size = sizeof(struct batadv_icmp_packet_rr); 389 390 /* drop packet if it has not necessary minimum size */ 391 if (unlikely(!pskb_may_pull(skb, hdr_size))) 392 goto out; 393 394 ethhdr = (struct ethhdr *)skb_mac_header(skb); 395 396 /* packet with unicast indication but broadcast recipient */ 397 if (is_broadcast_ether_addr(ethhdr->h_dest)) 398 goto out; 399 400 /* packet with broadcast sender address */ 401 if (is_broadcast_ether_addr(ethhdr->h_source)) 402 goto out; 403 404 /* not for me */ 405 if (!batadv_is_my_mac(ethhdr->h_dest)) 406 goto out; 407 408 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 409 410 /* add record route information if not full */ 411 if ((hdr_size == sizeof(struct batadv_icmp_packet_rr)) && 412 (icmp_packet->rr_cur < BATADV_RR_LEN)) { 413 memcpy(&(icmp_packet->rr[icmp_packet->rr_cur]), 414 ethhdr->h_dest, ETH_ALEN); 415 icmp_packet->rr_cur++; 416 } 417 418 /* packet for me */ 419 if (batadv_is_my_mac(icmp_packet->dst)) 420 return batadv_recv_my_icmp_packet(bat_priv, skb, hdr_size); 421 422 /* TTL exceeded */ 423 if (icmp_packet->header.ttl < 2) 424 return batadv_recv_icmp_ttl_exceeded(bat_priv, skb); 425 426 /* get routing information */ 427 orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->dst); 428 if (!orig_node) 429 goto out; 430 431 /* create a copy of the skb, if needed, to modify it. */ 432 if (skb_cow(skb, ETH_HLEN) < 0) 433 goto out; 434 435 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 436 437 /* decrement ttl */ 438 icmp_packet->header.ttl--; 439 440 /* route it */ 441 if (batadv_send_skb_to_orig(skb, orig_node, recv_if)) 442 ret = NET_RX_SUCCESS; 443 444 out: 445 if (orig_node) 446 batadv_orig_node_free_ref(orig_node); 447 return ret; 448 } 449 450 /* In the bonding case, send the packets in a round 451 * robin fashion over the remaining interfaces. 452 * 453 * This method rotates the bonding list and increases the 454 * returned router's refcount. 455 */ 456 static struct batadv_neigh_node * 457 batadv_find_bond_router(struct batadv_orig_node *primary_orig, 458 const struct batadv_hard_iface *recv_if) 459 { 460 struct batadv_neigh_node *tmp_neigh_node; 461 struct batadv_neigh_node *router = NULL, *first_candidate = NULL; 462 463 rcu_read_lock(); 464 list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list, 465 bonding_list) { 466 if (!first_candidate) 467 first_candidate = tmp_neigh_node; 468 469 /* recv_if == NULL on the first node. */ 470 if (tmp_neigh_node->if_incoming == recv_if) 471 continue; 472 473 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount)) 474 continue; 475 476 router = tmp_neigh_node; 477 break; 478 } 479 480 /* use the first candidate if nothing was found. */ 481 if (!router && first_candidate && 482 atomic_inc_not_zero(&first_candidate->refcount)) 483 router = first_candidate; 484 485 if (!router) 486 goto out; 487 488 /* selected should point to the next element 489 * after the current router 490 */ 491 spin_lock_bh(&primary_orig->neigh_list_lock); 492 /* this is a list_move(), which unfortunately 493 * does not exist as rcu version 494 */ 495 list_del_rcu(&primary_orig->bond_list); 496 list_add_rcu(&primary_orig->bond_list, 497 &router->bonding_list); 498 spin_unlock_bh(&primary_orig->neigh_list_lock); 499 500 out: 501 rcu_read_unlock(); 502 return router; 503 } 504 505 /* Interface Alternating: Use the best of the 506 * remaining candidates which are not using 507 * this interface. 508 * 509 * Increases the returned router's refcount 510 */ 511 static struct batadv_neigh_node * 512 batadv_find_ifalter_router(struct batadv_orig_node *primary_orig, 513 const struct batadv_hard_iface *recv_if) 514 { 515 struct batadv_neigh_node *tmp_neigh_node; 516 struct batadv_neigh_node *router = NULL, *first_candidate = NULL; 517 518 rcu_read_lock(); 519 list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list, 520 bonding_list) { 521 if (!first_candidate) 522 first_candidate = tmp_neigh_node; 523 524 /* recv_if == NULL on the first node. */ 525 if (tmp_neigh_node->if_incoming == recv_if) 526 continue; 527 528 if (router && tmp_neigh_node->tq_avg <= router->tq_avg) 529 continue; 530 531 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount)) 532 continue; 533 534 /* decrement refcount of previously selected router */ 535 if (router) 536 batadv_neigh_node_free_ref(router); 537 538 /* we found a better router (or at least one valid router) */ 539 router = tmp_neigh_node; 540 } 541 542 /* use the first candidate if nothing was found. */ 543 if (!router && first_candidate && 544 atomic_inc_not_zero(&first_candidate->refcount)) 545 router = first_candidate; 546 547 rcu_read_unlock(); 548 return router; 549 } 550 551 static int batadv_check_unicast_packet(struct sk_buff *skb, int hdr_size) 552 { 553 struct ethhdr *ethhdr; 554 555 /* drop packet if it has not necessary minimum size */ 556 if (unlikely(!pskb_may_pull(skb, hdr_size))) 557 return -1; 558 559 ethhdr = (struct ethhdr *)skb_mac_header(skb); 560 561 /* packet with unicast indication but broadcast recipient */ 562 if (is_broadcast_ether_addr(ethhdr->h_dest)) 563 return -1; 564 565 /* packet with broadcast sender address */ 566 if (is_broadcast_ether_addr(ethhdr->h_source)) 567 return -1; 568 569 /* not for me */ 570 if (!batadv_is_my_mac(ethhdr->h_dest)) 571 return -1; 572 573 return 0; 574 } 575 576 int batadv_recv_tt_query(struct sk_buff *skb, struct batadv_hard_iface *recv_if) 577 { 578 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 579 struct batadv_tt_query_packet *tt_query; 580 uint16_t tt_size; 581 int hdr_size = sizeof(*tt_query); 582 char tt_flag; 583 size_t packet_size; 584 585 if (batadv_check_unicast_packet(skb, hdr_size) < 0) 586 return NET_RX_DROP; 587 588 /* I could need to modify it */ 589 if (skb_cow(skb, sizeof(struct batadv_tt_query_packet)) < 0) 590 goto out; 591 592 tt_query = (struct batadv_tt_query_packet *)skb->data; 593 594 switch (tt_query->flags & BATADV_TT_QUERY_TYPE_MASK) { 595 case BATADV_TT_REQUEST: 596 batadv_inc_counter(bat_priv, BATADV_CNT_TT_REQUEST_RX); 597 598 /* If we cannot provide an answer the tt_request is 599 * forwarded 600 */ 601 if (!batadv_send_tt_response(bat_priv, tt_query)) { 602 if (tt_query->flags & BATADV_TT_FULL_TABLE) 603 tt_flag = 'F'; 604 else 605 tt_flag = '.'; 606 607 batadv_dbg(BATADV_DBG_TT, bat_priv, 608 "Routing TT_REQUEST to %pM [%c]\n", 609 tt_query->dst, 610 tt_flag); 611 return batadv_route_unicast_packet(skb, recv_if); 612 } 613 break; 614 case BATADV_TT_RESPONSE: 615 batadv_inc_counter(bat_priv, BATADV_CNT_TT_RESPONSE_RX); 616 617 if (batadv_is_my_mac(tt_query->dst)) { 618 /* packet needs to be linearized to access the TT 619 * changes 620 */ 621 if (skb_linearize(skb) < 0) 622 goto out; 623 /* skb_linearize() possibly changed skb->data */ 624 tt_query = (struct batadv_tt_query_packet *)skb->data; 625 626 tt_size = batadv_tt_len(ntohs(tt_query->tt_data)); 627 628 /* Ensure we have all the claimed data */ 629 packet_size = sizeof(struct batadv_tt_query_packet); 630 packet_size += tt_size; 631 if (unlikely(skb_headlen(skb) < packet_size)) 632 goto out; 633 634 batadv_handle_tt_response(bat_priv, tt_query); 635 } else { 636 if (tt_query->flags & BATADV_TT_FULL_TABLE) 637 tt_flag = 'F'; 638 else 639 tt_flag = '.'; 640 batadv_dbg(BATADV_DBG_TT, bat_priv, 641 "Routing TT_RESPONSE to %pM [%c]\n", 642 tt_query->dst, 643 tt_flag); 644 return batadv_route_unicast_packet(skb, recv_if); 645 } 646 break; 647 } 648 649 out: 650 /* returning NET_RX_DROP will make the caller function kfree the skb */ 651 return NET_RX_DROP; 652 } 653 654 int batadv_recv_roam_adv(struct sk_buff *skb, struct batadv_hard_iface *recv_if) 655 { 656 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 657 struct batadv_roam_adv_packet *roam_adv_packet; 658 struct batadv_orig_node *orig_node; 659 660 if (batadv_check_unicast_packet(skb, sizeof(*roam_adv_packet)) < 0) 661 goto out; 662 663 batadv_inc_counter(bat_priv, BATADV_CNT_TT_ROAM_ADV_RX); 664 665 roam_adv_packet = (struct batadv_roam_adv_packet *)skb->data; 666 667 if (!batadv_is_my_mac(roam_adv_packet->dst)) 668 return batadv_route_unicast_packet(skb, recv_if); 669 670 /* check if it is a backbone gateway. we don't accept 671 * roaming advertisement from it, as it has the same 672 * entries as we have. 673 */ 674 if (batadv_bla_is_backbone_gw_orig(bat_priv, roam_adv_packet->src)) 675 goto out; 676 677 orig_node = batadv_orig_hash_find(bat_priv, roam_adv_packet->src); 678 if (!orig_node) 679 goto out; 680 681 batadv_dbg(BATADV_DBG_TT, bat_priv, 682 "Received ROAMING_ADV from %pM (client %pM)\n", 683 roam_adv_packet->src, roam_adv_packet->client); 684 685 batadv_tt_global_add(bat_priv, orig_node, roam_adv_packet->client, 686 BATADV_TT_CLIENT_ROAM, 687 atomic_read(&orig_node->last_ttvn) + 1); 688 689 batadv_orig_node_free_ref(orig_node); 690 out: 691 /* returning NET_RX_DROP will make the caller function kfree the skb */ 692 return NET_RX_DROP; 693 } 694 695 /* find a suitable router for this originator, and use 696 * bonding if possible. increases the found neighbors 697 * refcount. 698 */ 699 struct batadv_neigh_node * 700 batadv_find_router(struct batadv_priv *bat_priv, 701 struct batadv_orig_node *orig_node, 702 const struct batadv_hard_iface *recv_if) 703 { 704 struct batadv_orig_node *primary_orig_node; 705 struct batadv_orig_node *router_orig; 706 struct batadv_neigh_node *router; 707 static uint8_t zero_mac[ETH_ALEN] = {0, 0, 0, 0, 0, 0}; 708 int bonding_enabled; 709 uint8_t *primary_addr; 710 711 if (!orig_node) 712 return NULL; 713 714 router = batadv_orig_node_get_router(orig_node); 715 if (!router) 716 goto err; 717 718 /* without bonding, the first node should 719 * always choose the default router. 720 */ 721 bonding_enabled = atomic_read(&bat_priv->bonding); 722 723 rcu_read_lock(); 724 /* select default router to output */ 725 router_orig = router->orig_node; 726 if (!router_orig) 727 goto err_unlock; 728 729 if ((!recv_if) && (!bonding_enabled)) 730 goto return_router; 731 732 primary_addr = router_orig->primary_addr; 733 734 /* if we have something in the primary_addr, we can search 735 * for a potential bonding candidate. 736 */ 737 if (batadv_compare_eth(primary_addr, zero_mac)) 738 goto return_router; 739 740 /* find the orig_node which has the primary interface. might 741 * even be the same as our router_orig in many cases 742 */ 743 if (batadv_compare_eth(primary_addr, router_orig->orig)) { 744 primary_orig_node = router_orig; 745 } else { 746 primary_orig_node = batadv_orig_hash_find(bat_priv, 747 primary_addr); 748 if (!primary_orig_node) 749 goto return_router; 750 751 batadv_orig_node_free_ref(primary_orig_node); 752 } 753 754 /* with less than 2 candidates, we can't do any 755 * bonding and prefer the original router. 756 */ 757 if (atomic_read(&primary_orig_node->bond_candidates) < 2) 758 goto return_router; 759 760 /* all nodes between should choose a candidate which 761 * is is not on the interface where the packet came 762 * in. 763 */ 764 batadv_neigh_node_free_ref(router); 765 766 if (bonding_enabled) 767 router = batadv_find_bond_router(primary_orig_node, recv_if); 768 else 769 router = batadv_find_ifalter_router(primary_orig_node, recv_if); 770 771 return_router: 772 if (router && router->if_incoming->if_status != BATADV_IF_ACTIVE) 773 goto err_unlock; 774 775 rcu_read_unlock(); 776 return router; 777 err_unlock: 778 rcu_read_unlock(); 779 err: 780 if (router) 781 batadv_neigh_node_free_ref(router); 782 return NULL; 783 } 784 785 static int batadv_route_unicast_packet(struct sk_buff *skb, 786 struct batadv_hard_iface *recv_if) 787 { 788 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 789 struct batadv_orig_node *orig_node = NULL; 790 struct batadv_neigh_node *neigh_node = NULL; 791 struct batadv_unicast_packet *unicast_packet; 792 struct ethhdr *ethhdr = (struct ethhdr *)skb_mac_header(skb); 793 int ret = NET_RX_DROP; 794 struct sk_buff *new_skb; 795 796 unicast_packet = (struct batadv_unicast_packet *)skb->data; 797 798 /* TTL exceeded */ 799 if (unicast_packet->header.ttl < 2) { 800 pr_debug("Warning - can't forward unicast packet from %pM to %pM: ttl exceeded\n", 801 ethhdr->h_source, unicast_packet->dest); 802 goto out; 803 } 804 805 /* get routing information */ 806 orig_node = batadv_orig_hash_find(bat_priv, unicast_packet->dest); 807 808 if (!orig_node) 809 goto out; 810 811 /* find_router() increases neigh_nodes refcount if found. */ 812 neigh_node = batadv_find_router(bat_priv, orig_node, recv_if); 813 814 if (!neigh_node) 815 goto out; 816 817 /* create a copy of the skb, if needed, to modify it. */ 818 if (skb_cow(skb, ETH_HLEN) < 0) 819 goto out; 820 821 unicast_packet = (struct batadv_unicast_packet *)skb->data; 822 823 if (unicast_packet->header.packet_type == BATADV_UNICAST && 824 atomic_read(&bat_priv->fragmentation) && 825 skb->len > neigh_node->if_incoming->net_dev->mtu) { 826 ret = batadv_frag_send_skb(skb, bat_priv, 827 neigh_node->if_incoming, 828 neigh_node->addr); 829 goto out; 830 } 831 832 if (unicast_packet->header.packet_type == BATADV_UNICAST_FRAG && 833 batadv_frag_can_reassemble(skb, 834 neigh_node->if_incoming->net_dev->mtu)) { 835 ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb); 836 837 if (ret == NET_RX_DROP) 838 goto out; 839 840 /* packet was buffered for late merge */ 841 if (!new_skb) { 842 ret = NET_RX_SUCCESS; 843 goto out; 844 } 845 846 skb = new_skb; 847 unicast_packet = (struct batadv_unicast_packet *)skb->data; 848 } 849 850 /* decrement ttl */ 851 unicast_packet->header.ttl--; 852 853 /* Update stats counter */ 854 batadv_inc_counter(bat_priv, BATADV_CNT_FORWARD); 855 batadv_add_counter(bat_priv, BATADV_CNT_FORWARD_BYTES, 856 skb->len + ETH_HLEN); 857 858 /* route it */ 859 if (batadv_send_skb_to_orig(skb, orig_node, recv_if)) 860 ret = NET_RX_SUCCESS; 861 862 out: 863 if (neigh_node) 864 batadv_neigh_node_free_ref(neigh_node); 865 if (orig_node) 866 batadv_orig_node_free_ref(orig_node); 867 return ret; 868 } 869 870 /** 871 * batadv_reroute_unicast_packet - update the unicast header for re-routing 872 * @bat_priv: the bat priv with all the soft interface information 873 * @unicast_packet: the unicast header to be updated 874 * @dst_addr: the payload destination 875 * 876 * Search the translation table for dst_addr and update the unicast header with 877 * the new corresponding information (originator address where the destination 878 * client currently is and its known TTVN) 879 * 880 * Returns true if the packet header has been updated, false otherwise 881 */ 882 static bool 883 batadv_reroute_unicast_packet(struct batadv_priv *bat_priv, 884 struct batadv_unicast_packet *unicast_packet, 885 uint8_t *dst_addr) 886 { 887 struct batadv_orig_node *orig_node = NULL; 888 struct batadv_hard_iface *primary_if = NULL; 889 bool ret = false; 890 uint8_t *orig_addr, orig_ttvn; 891 892 if (batadv_is_my_client(bat_priv, dst_addr)) { 893 primary_if = batadv_primary_if_get_selected(bat_priv); 894 if (!primary_if) 895 goto out; 896 orig_addr = primary_if->net_dev->dev_addr; 897 orig_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn); 898 } else { 899 orig_node = batadv_transtable_search(bat_priv, NULL, dst_addr); 900 if (!orig_node) 901 goto out; 902 903 if (batadv_compare_eth(orig_node->orig, unicast_packet->dest)) 904 goto out; 905 906 orig_addr = orig_node->orig; 907 orig_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn); 908 } 909 910 /* update the packet header */ 911 memcpy(unicast_packet->dest, orig_addr, ETH_ALEN); 912 unicast_packet->ttvn = orig_ttvn; 913 914 ret = true; 915 out: 916 if (primary_if) 917 batadv_hardif_free_ref(primary_if); 918 if (orig_node) 919 batadv_orig_node_free_ref(orig_node); 920 921 return ret; 922 } 923 924 static int batadv_check_unicast_ttvn(struct batadv_priv *bat_priv, 925 struct sk_buff *skb) { 926 uint8_t curr_ttvn, old_ttvn; 927 struct batadv_orig_node *orig_node; 928 struct ethhdr *ethhdr; 929 struct batadv_hard_iface *primary_if; 930 struct batadv_unicast_packet *unicast_packet; 931 int is_old_ttvn; 932 933 /* check if there is enough data before accessing it */ 934 if (pskb_may_pull(skb, sizeof(*unicast_packet) + ETH_HLEN) < 0) 935 return 0; 936 937 /* create a copy of the skb (in case of for re-routing) to modify it. */ 938 if (skb_cow(skb, sizeof(*unicast_packet)) < 0) 939 return 0; 940 941 unicast_packet = (struct batadv_unicast_packet *)skb->data; 942 ethhdr = (struct ethhdr *)(skb->data + sizeof(*unicast_packet)); 943 944 /* check if the destination client was served by this node and it is now 945 * roaming. In this case, it means that the node has got a ROAM_ADV 946 * message and that it knows the new destination in the mesh to re-route 947 * the packet to 948 */ 949 if (batadv_tt_local_client_is_roaming(bat_priv, ethhdr->h_dest)) { 950 if (batadv_reroute_unicast_packet(bat_priv, unicast_packet, 951 ethhdr->h_dest)) 952 net_ratelimited_function(batadv_dbg, BATADV_DBG_TT, 953 bat_priv, 954 "Rerouting unicast packet to %pM (dst=%pM): Local Roaming\n", 955 unicast_packet->dest, 956 ethhdr->h_dest); 957 /* at this point the mesh destination should have been 958 * substituted with the originator address found in the global 959 * table. If not, let the packet go untouched anyway because 960 * there is nothing the node can do 961 */ 962 return 1; 963 } 964 965 /* retrieve the TTVN known by this node for the packet destination. This 966 * value is used later to check if the node which sent (or re-routed 967 * last time) the packet had an updated information or not 968 */ 969 curr_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn); 970 if (!batadv_is_my_mac(unicast_packet->dest)) { 971 orig_node = batadv_orig_hash_find(bat_priv, 972 unicast_packet->dest); 973 /* if it is not possible to find the orig_node representing the 974 * destination, the packet can immediately be dropped as it will 975 * not be possible to deliver it 976 */ 977 if (!orig_node) 978 return 0; 979 980 curr_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn); 981 batadv_orig_node_free_ref(orig_node); 982 } 983 984 /* check if the TTVN contained in the packet is fresher than what the 985 * node knows 986 */ 987 is_old_ttvn = batadv_seq_before(unicast_packet->ttvn, curr_ttvn); 988 if (!is_old_ttvn) 989 return 1; 990 991 old_ttvn = unicast_packet->ttvn; 992 /* the packet was forged based on outdated network information. Its 993 * destination can possibly be updated and forwarded towards the new 994 * target host 995 */ 996 if (batadv_reroute_unicast_packet(bat_priv, unicast_packet, 997 ethhdr->h_dest)) { 998 net_ratelimited_function(batadv_dbg, BATADV_DBG_TT, bat_priv, 999 "Rerouting unicast packet to %pM (dst=%pM): TTVN mismatch old_ttvn=%u new_ttvn=%u\n", 1000 unicast_packet->dest, ethhdr->h_dest, 1001 old_ttvn, curr_ttvn); 1002 return 1; 1003 } 1004 1005 /* the packet has not been re-routed: either the destination is 1006 * currently served by this node or there is no destination at all and 1007 * it is possible to drop the packet 1008 */ 1009 if (!batadv_is_my_client(bat_priv, ethhdr->h_dest)) 1010 return 0; 1011 1012 /* update the header in order to let the packet be delivered to this 1013 * node's soft interface 1014 */ 1015 primary_if = batadv_primary_if_get_selected(bat_priv); 1016 if (!primary_if) 1017 return 0; 1018 1019 memcpy(unicast_packet->dest, primary_if->net_dev->dev_addr, ETH_ALEN); 1020 1021 batadv_hardif_free_ref(primary_if); 1022 1023 unicast_packet->ttvn = curr_ttvn; 1024 1025 return 1; 1026 } 1027 1028 int batadv_recv_unicast_packet(struct sk_buff *skb, 1029 struct batadv_hard_iface *recv_if) 1030 { 1031 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1032 struct batadv_unicast_packet *unicast_packet; 1033 struct batadv_unicast_4addr_packet *unicast_4addr_packet; 1034 uint8_t *orig_addr; 1035 struct batadv_orig_node *orig_node = NULL; 1036 int hdr_size = sizeof(*unicast_packet); 1037 bool is4addr; 1038 1039 unicast_packet = (struct batadv_unicast_packet *)skb->data; 1040 unicast_4addr_packet = (struct batadv_unicast_4addr_packet *)skb->data; 1041 1042 is4addr = unicast_packet->header.packet_type == BATADV_UNICAST_4ADDR; 1043 /* the caller function should have already pulled 2 bytes */ 1044 if (is4addr) 1045 hdr_size = sizeof(*unicast_4addr_packet); 1046 1047 if (batadv_check_unicast_packet(skb, hdr_size) < 0) 1048 return NET_RX_DROP; 1049 1050 if (!batadv_check_unicast_ttvn(bat_priv, skb)) 1051 return NET_RX_DROP; 1052 1053 /* packet for me */ 1054 if (batadv_is_my_mac(unicast_packet->dest)) { 1055 if (is4addr) { 1056 batadv_dat_inc_counter(bat_priv, 1057 unicast_4addr_packet->subtype); 1058 orig_addr = unicast_4addr_packet->src; 1059 orig_node = batadv_orig_hash_find(bat_priv, orig_addr); 1060 } 1061 1062 if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb, 1063 hdr_size)) 1064 goto rx_success; 1065 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb, 1066 hdr_size)) 1067 goto rx_success; 1068 1069 batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size, 1070 orig_node); 1071 1072 rx_success: 1073 if (orig_node) 1074 batadv_orig_node_free_ref(orig_node); 1075 1076 return NET_RX_SUCCESS; 1077 } 1078 1079 return batadv_route_unicast_packet(skb, recv_if); 1080 } 1081 1082 int batadv_recv_ucast_frag_packet(struct sk_buff *skb, 1083 struct batadv_hard_iface *recv_if) 1084 { 1085 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1086 struct batadv_unicast_frag_packet *unicast_packet; 1087 int hdr_size = sizeof(*unicast_packet); 1088 struct sk_buff *new_skb = NULL; 1089 int ret; 1090 1091 if (batadv_check_unicast_packet(skb, hdr_size) < 0) 1092 return NET_RX_DROP; 1093 1094 if (!batadv_check_unicast_ttvn(bat_priv, skb)) 1095 return NET_RX_DROP; 1096 1097 unicast_packet = (struct batadv_unicast_frag_packet *)skb->data; 1098 1099 /* packet for me */ 1100 if (batadv_is_my_mac(unicast_packet->dest)) { 1101 ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb); 1102 1103 if (ret == NET_RX_DROP) 1104 return NET_RX_DROP; 1105 1106 /* packet was buffered for late merge */ 1107 if (!new_skb) 1108 return NET_RX_SUCCESS; 1109 1110 if (batadv_dat_snoop_incoming_arp_request(bat_priv, new_skb, 1111 hdr_size)) 1112 goto rx_success; 1113 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, new_skb, 1114 hdr_size)) 1115 goto rx_success; 1116 1117 batadv_interface_rx(recv_if->soft_iface, new_skb, recv_if, 1118 sizeof(struct batadv_unicast_packet), NULL); 1119 1120 rx_success: 1121 return NET_RX_SUCCESS; 1122 } 1123 1124 return batadv_route_unicast_packet(skb, recv_if); 1125 } 1126 1127 1128 int batadv_recv_bcast_packet(struct sk_buff *skb, 1129 struct batadv_hard_iface *recv_if) 1130 { 1131 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1132 struct batadv_orig_node *orig_node = NULL; 1133 struct batadv_bcast_packet *bcast_packet; 1134 struct ethhdr *ethhdr; 1135 int hdr_size = sizeof(*bcast_packet); 1136 int ret = NET_RX_DROP; 1137 int32_t seq_diff; 1138 1139 /* drop packet if it has not necessary minimum size */ 1140 if (unlikely(!pskb_may_pull(skb, hdr_size))) 1141 goto out; 1142 1143 ethhdr = (struct ethhdr *)skb_mac_header(skb); 1144 1145 /* packet with broadcast indication but unicast recipient */ 1146 if (!is_broadcast_ether_addr(ethhdr->h_dest)) 1147 goto out; 1148 1149 /* packet with broadcast sender address */ 1150 if (is_broadcast_ether_addr(ethhdr->h_source)) 1151 goto out; 1152 1153 /* ignore broadcasts sent by myself */ 1154 if (batadv_is_my_mac(ethhdr->h_source)) 1155 goto out; 1156 1157 bcast_packet = (struct batadv_bcast_packet *)skb->data; 1158 1159 /* ignore broadcasts originated by myself */ 1160 if (batadv_is_my_mac(bcast_packet->orig)) 1161 goto out; 1162 1163 if (bcast_packet->header.ttl < 2) 1164 goto out; 1165 1166 orig_node = batadv_orig_hash_find(bat_priv, bcast_packet->orig); 1167 1168 if (!orig_node) 1169 goto out; 1170 1171 spin_lock_bh(&orig_node->bcast_seqno_lock); 1172 1173 /* check whether the packet is a duplicate */ 1174 if (batadv_test_bit(orig_node->bcast_bits, orig_node->last_bcast_seqno, 1175 ntohl(bcast_packet->seqno))) 1176 goto spin_unlock; 1177 1178 seq_diff = ntohl(bcast_packet->seqno) - orig_node->last_bcast_seqno; 1179 1180 /* check whether the packet is old and the host just restarted. */ 1181 if (batadv_window_protected(bat_priv, seq_diff, 1182 &orig_node->bcast_seqno_reset)) 1183 goto spin_unlock; 1184 1185 /* mark broadcast in flood history, update window position 1186 * if required. 1187 */ 1188 if (batadv_bit_get_packet(bat_priv, orig_node->bcast_bits, seq_diff, 1)) 1189 orig_node->last_bcast_seqno = ntohl(bcast_packet->seqno); 1190 1191 spin_unlock_bh(&orig_node->bcast_seqno_lock); 1192 1193 /* check whether this has been sent by another originator before */ 1194 if (batadv_bla_check_bcast_duplist(bat_priv, skb)) 1195 goto out; 1196 1197 /* rebroadcast packet */ 1198 batadv_add_bcast_packet_to_list(bat_priv, skb, 1); 1199 1200 /* don't hand the broadcast up if it is from an originator 1201 * from the same backbone. 1202 */ 1203 if (batadv_bla_is_backbone_gw(skb, orig_node, hdr_size)) 1204 goto out; 1205 1206 if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb, hdr_size)) 1207 goto rx_success; 1208 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb, hdr_size)) 1209 goto rx_success; 1210 1211 /* broadcast for me */ 1212 batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size, 1213 orig_node); 1214 1215 rx_success: 1216 ret = NET_RX_SUCCESS; 1217 goto out; 1218 1219 spin_unlock: 1220 spin_unlock_bh(&orig_node->bcast_seqno_lock); 1221 out: 1222 if (orig_node) 1223 batadv_orig_node_free_ref(orig_node); 1224 return ret; 1225 } 1226 1227 int batadv_recv_vis_packet(struct sk_buff *skb, 1228 struct batadv_hard_iface *recv_if) 1229 { 1230 struct batadv_vis_packet *vis_packet; 1231 struct ethhdr *ethhdr; 1232 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1233 int hdr_size = sizeof(*vis_packet); 1234 1235 /* keep skb linear */ 1236 if (skb_linearize(skb) < 0) 1237 return NET_RX_DROP; 1238 1239 if (unlikely(!pskb_may_pull(skb, hdr_size))) 1240 return NET_RX_DROP; 1241 1242 vis_packet = (struct batadv_vis_packet *)skb->data; 1243 ethhdr = (struct ethhdr *)skb_mac_header(skb); 1244 1245 /* not for me */ 1246 if (!batadv_is_my_mac(ethhdr->h_dest)) 1247 return NET_RX_DROP; 1248 1249 /* ignore own packets */ 1250 if (batadv_is_my_mac(vis_packet->vis_orig)) 1251 return NET_RX_DROP; 1252 1253 if (batadv_is_my_mac(vis_packet->sender_orig)) 1254 return NET_RX_DROP; 1255 1256 switch (vis_packet->vis_type) { 1257 case BATADV_VIS_TYPE_SERVER_SYNC: 1258 batadv_receive_server_sync_packet(bat_priv, vis_packet, 1259 skb_headlen(skb)); 1260 break; 1261 1262 case BATADV_VIS_TYPE_CLIENT_UPDATE: 1263 batadv_receive_client_update_packet(bat_priv, vis_packet, 1264 skb_headlen(skb)); 1265 break; 1266 1267 default: /* ignore unknown packet */ 1268 break; 1269 } 1270 1271 /* We take a copy of the data in the packet, so we should 1272 * always free the skbuf. 1273 */ 1274 return NET_RX_DROP; 1275 } 1276