1 /* Copyright (C) 2007-2012 B.A.T.M.A.N. contributors: 2 * 3 * Marek Lindner, Simon Wunderlich 4 * 5 * This program is free software; you can redistribute it and/or 6 * modify it under the terms of version 2 of the GNU General Public 7 * License as published by the Free Software Foundation. 8 * 9 * This program is distributed in the hope that it will be useful, but 10 * WITHOUT ANY WARRANTY; without even the implied warranty of 11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU 12 * General Public License for more details. 13 * 14 * You should have received a copy of the GNU General Public License 15 * along with this program; if not, write to the Free Software 16 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 17 * 02110-1301, USA 18 */ 19 20 #include "main.h" 21 #include "routing.h" 22 #include "send.h" 23 #include "soft-interface.h" 24 #include "hard-interface.h" 25 #include "icmp_socket.h" 26 #include "translation-table.h" 27 #include "originator.h" 28 #include "vis.h" 29 #include "unicast.h" 30 #include "bridge_loop_avoidance.h" 31 #include "distributed-arp-table.h" 32 33 static int batadv_route_unicast_packet(struct sk_buff *skb, 34 struct batadv_hard_iface *recv_if); 35 36 void batadv_slide_own_bcast_window(struct batadv_hard_iface *hard_iface) 37 { 38 struct batadv_priv *bat_priv = netdev_priv(hard_iface->soft_iface); 39 struct batadv_hashtable *hash = bat_priv->orig_hash; 40 struct hlist_node *node; 41 struct hlist_head *head; 42 struct batadv_orig_node *orig_node; 43 unsigned long *word; 44 uint32_t i; 45 size_t word_index; 46 uint8_t *w; 47 48 for (i = 0; i < hash->size; i++) { 49 head = &hash->table[i]; 50 51 rcu_read_lock(); 52 hlist_for_each_entry_rcu(orig_node, node, head, hash_entry) { 53 spin_lock_bh(&orig_node->ogm_cnt_lock); 54 word_index = hard_iface->if_num * BATADV_NUM_WORDS; 55 word = &(orig_node->bcast_own[word_index]); 56 57 batadv_bit_get_packet(bat_priv, word, 1, 0); 58 w = &orig_node->bcast_own_sum[hard_iface->if_num]; 59 *w = bitmap_weight(word, BATADV_TQ_LOCAL_WINDOW_SIZE); 60 spin_unlock_bh(&orig_node->ogm_cnt_lock); 61 } 62 rcu_read_unlock(); 63 } 64 } 65 66 static void _batadv_update_route(struct batadv_priv *bat_priv, 67 struct batadv_orig_node *orig_node, 68 struct batadv_neigh_node *neigh_node) 69 { 70 struct batadv_neigh_node *curr_router; 71 72 curr_router = batadv_orig_node_get_router(orig_node); 73 74 /* route deleted */ 75 if ((curr_router) && (!neigh_node)) { 76 batadv_dbg(BATADV_DBG_ROUTES, bat_priv, 77 "Deleting route towards: %pM\n", orig_node->orig); 78 batadv_tt_global_del_orig(bat_priv, orig_node, 79 "Deleted route towards originator"); 80 81 /* route added */ 82 } else if ((!curr_router) && (neigh_node)) { 83 84 batadv_dbg(BATADV_DBG_ROUTES, bat_priv, 85 "Adding route towards: %pM (via %pM)\n", 86 orig_node->orig, neigh_node->addr); 87 /* route changed */ 88 } else if (neigh_node && curr_router) { 89 batadv_dbg(BATADV_DBG_ROUTES, bat_priv, 90 "Changing route towards: %pM (now via %pM - was via %pM)\n", 91 orig_node->orig, neigh_node->addr, 92 curr_router->addr); 93 } 94 95 if (curr_router) 96 batadv_neigh_node_free_ref(curr_router); 97 98 /* increase refcount of new best neighbor */ 99 if (neigh_node && !atomic_inc_not_zero(&neigh_node->refcount)) 100 neigh_node = NULL; 101 102 spin_lock_bh(&orig_node->neigh_list_lock); 103 rcu_assign_pointer(orig_node->router, neigh_node); 104 spin_unlock_bh(&orig_node->neigh_list_lock); 105 106 /* decrease refcount of previous best neighbor */ 107 if (curr_router) 108 batadv_neigh_node_free_ref(curr_router); 109 } 110 111 void batadv_update_route(struct batadv_priv *bat_priv, 112 struct batadv_orig_node *orig_node, 113 struct batadv_neigh_node *neigh_node) 114 { 115 struct batadv_neigh_node *router = NULL; 116 117 if (!orig_node) 118 goto out; 119 120 router = batadv_orig_node_get_router(orig_node); 121 122 if (router != neigh_node) 123 _batadv_update_route(bat_priv, orig_node, neigh_node); 124 125 out: 126 if (router) 127 batadv_neigh_node_free_ref(router); 128 } 129 130 /* caller must hold the neigh_list_lock */ 131 void batadv_bonding_candidate_del(struct batadv_orig_node *orig_node, 132 struct batadv_neigh_node *neigh_node) 133 { 134 /* this neighbor is not part of our candidate list */ 135 if (list_empty(&neigh_node->bonding_list)) 136 goto out; 137 138 list_del_rcu(&neigh_node->bonding_list); 139 INIT_LIST_HEAD(&neigh_node->bonding_list); 140 batadv_neigh_node_free_ref(neigh_node); 141 atomic_dec(&orig_node->bond_candidates); 142 143 out: 144 return; 145 } 146 147 void batadv_bonding_candidate_add(struct batadv_orig_node *orig_node, 148 struct batadv_neigh_node *neigh_node) 149 { 150 struct hlist_node *node; 151 struct batadv_neigh_node *tmp_neigh_node, *router = NULL; 152 uint8_t interference_candidate = 0; 153 154 spin_lock_bh(&orig_node->neigh_list_lock); 155 156 /* only consider if it has the same primary address ... */ 157 if (!batadv_compare_eth(orig_node->orig, 158 neigh_node->orig_node->primary_addr)) 159 goto candidate_del; 160 161 router = batadv_orig_node_get_router(orig_node); 162 if (!router) 163 goto candidate_del; 164 165 /* ... and is good enough to be considered */ 166 if (neigh_node->tq_avg < router->tq_avg - BATADV_BONDING_TQ_THRESHOLD) 167 goto candidate_del; 168 169 /* check if we have another candidate with the same mac address or 170 * interface. If we do, we won't select this candidate because of 171 * possible interference. 172 */ 173 hlist_for_each_entry_rcu(tmp_neigh_node, node, 174 &orig_node->neigh_list, list) { 175 176 if (tmp_neigh_node == neigh_node) 177 continue; 178 179 /* we only care if the other candidate is even 180 * considered as candidate. 181 */ 182 if (list_empty(&tmp_neigh_node->bonding_list)) 183 continue; 184 185 if ((neigh_node->if_incoming == tmp_neigh_node->if_incoming) || 186 (batadv_compare_eth(neigh_node->addr, 187 tmp_neigh_node->addr))) { 188 interference_candidate = 1; 189 break; 190 } 191 } 192 193 /* don't care further if it is an interference candidate */ 194 if (interference_candidate) 195 goto candidate_del; 196 197 /* this neighbor already is part of our candidate list */ 198 if (!list_empty(&neigh_node->bonding_list)) 199 goto out; 200 201 if (!atomic_inc_not_zero(&neigh_node->refcount)) 202 goto out; 203 204 list_add_rcu(&neigh_node->bonding_list, &orig_node->bond_list); 205 atomic_inc(&orig_node->bond_candidates); 206 goto out; 207 208 candidate_del: 209 batadv_bonding_candidate_del(orig_node, neigh_node); 210 211 out: 212 spin_unlock_bh(&orig_node->neigh_list_lock); 213 214 if (router) 215 batadv_neigh_node_free_ref(router); 216 } 217 218 /* copy primary address for bonding */ 219 void 220 batadv_bonding_save_primary(const struct batadv_orig_node *orig_node, 221 struct batadv_orig_node *orig_neigh_node, 222 const struct batadv_ogm_packet *batman_ogm_packet) 223 { 224 if (!(batman_ogm_packet->flags & BATADV_PRIMARIES_FIRST_HOP)) 225 return; 226 227 memcpy(orig_neigh_node->primary_addr, orig_node->orig, ETH_ALEN); 228 } 229 230 /* checks whether the host restarted and is in the protection time. 231 * returns: 232 * 0 if the packet is to be accepted 233 * 1 if the packet is to be ignored. 234 */ 235 int batadv_window_protected(struct batadv_priv *bat_priv, int32_t seq_num_diff, 236 unsigned long *last_reset) 237 { 238 if (seq_num_diff <= -BATADV_TQ_LOCAL_WINDOW_SIZE || 239 seq_num_diff >= BATADV_EXPECTED_SEQNO_RANGE) { 240 if (!batadv_has_timed_out(*last_reset, 241 BATADV_RESET_PROTECTION_MS)) 242 return 1; 243 244 *last_reset = jiffies; 245 batadv_dbg(BATADV_DBG_BATMAN, bat_priv, 246 "old packet received, start protection\n"); 247 } 248 249 return 0; 250 } 251 252 bool batadv_check_management_packet(struct sk_buff *skb, 253 struct batadv_hard_iface *hard_iface, 254 int header_len) 255 { 256 struct ethhdr *ethhdr; 257 258 /* drop packet if it has not necessary minimum size */ 259 if (unlikely(!pskb_may_pull(skb, header_len))) 260 return false; 261 262 ethhdr = (struct ethhdr *)skb_mac_header(skb); 263 264 /* packet with broadcast indication but unicast recipient */ 265 if (!is_broadcast_ether_addr(ethhdr->h_dest)) 266 return false; 267 268 /* packet with broadcast sender address */ 269 if (is_broadcast_ether_addr(ethhdr->h_source)) 270 return false; 271 272 /* create a copy of the skb, if needed, to modify it. */ 273 if (skb_cow(skb, 0) < 0) 274 return false; 275 276 /* keep skb linear */ 277 if (skb_linearize(skb) < 0) 278 return false; 279 280 return true; 281 } 282 283 static int batadv_recv_my_icmp_packet(struct batadv_priv *bat_priv, 284 struct sk_buff *skb, size_t icmp_len) 285 { 286 struct batadv_hard_iface *primary_if = NULL; 287 struct batadv_orig_node *orig_node = NULL; 288 struct batadv_icmp_packet_rr *icmp_packet; 289 int ret = NET_RX_DROP; 290 291 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 292 293 /* add data to device queue */ 294 if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) { 295 batadv_socket_receive_packet(icmp_packet, icmp_len); 296 goto out; 297 } 298 299 primary_if = batadv_primary_if_get_selected(bat_priv); 300 if (!primary_if) 301 goto out; 302 303 /* answer echo request (ping) */ 304 /* get routing information */ 305 orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig); 306 if (!orig_node) 307 goto out; 308 309 /* create a copy of the skb, if needed, to modify it. */ 310 if (skb_cow(skb, ETH_HLEN) < 0) 311 goto out; 312 313 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 314 315 memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN); 316 memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN); 317 icmp_packet->msg_type = BATADV_ECHO_REPLY; 318 icmp_packet->header.ttl = BATADV_TTL; 319 320 if (batadv_send_skb_to_orig(skb, orig_node, NULL)) 321 ret = NET_RX_SUCCESS; 322 323 out: 324 if (primary_if) 325 batadv_hardif_free_ref(primary_if); 326 if (orig_node) 327 batadv_orig_node_free_ref(orig_node); 328 return ret; 329 } 330 331 static int batadv_recv_icmp_ttl_exceeded(struct batadv_priv *bat_priv, 332 struct sk_buff *skb) 333 { 334 struct batadv_hard_iface *primary_if = NULL; 335 struct batadv_orig_node *orig_node = NULL; 336 struct batadv_icmp_packet *icmp_packet; 337 int ret = NET_RX_DROP; 338 339 icmp_packet = (struct batadv_icmp_packet *)skb->data; 340 341 /* send TTL exceeded if packet is an echo request (traceroute) */ 342 if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) { 343 pr_debug("Warning - can't forward icmp packet from %pM to %pM: ttl exceeded\n", 344 icmp_packet->orig, icmp_packet->dst); 345 goto out; 346 } 347 348 primary_if = batadv_primary_if_get_selected(bat_priv); 349 if (!primary_if) 350 goto out; 351 352 /* get routing information */ 353 orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig); 354 if (!orig_node) 355 goto out; 356 357 /* create a copy of the skb, if needed, to modify it. */ 358 if (skb_cow(skb, ETH_HLEN) < 0) 359 goto out; 360 361 icmp_packet = (struct batadv_icmp_packet *)skb->data; 362 363 memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN); 364 memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN); 365 icmp_packet->msg_type = BATADV_TTL_EXCEEDED; 366 icmp_packet->header.ttl = BATADV_TTL; 367 368 if (batadv_send_skb_to_orig(skb, orig_node, NULL)) 369 ret = NET_RX_SUCCESS; 370 371 out: 372 if (primary_if) 373 batadv_hardif_free_ref(primary_if); 374 if (orig_node) 375 batadv_orig_node_free_ref(orig_node); 376 return ret; 377 } 378 379 380 int batadv_recv_icmp_packet(struct sk_buff *skb, 381 struct batadv_hard_iface *recv_if) 382 { 383 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 384 struct batadv_icmp_packet_rr *icmp_packet; 385 struct ethhdr *ethhdr; 386 struct batadv_orig_node *orig_node = NULL; 387 int hdr_size = sizeof(struct batadv_icmp_packet); 388 int ret = NET_RX_DROP; 389 390 /* we truncate all incoming icmp packets if they don't match our size */ 391 if (skb->len >= sizeof(struct batadv_icmp_packet_rr)) 392 hdr_size = sizeof(struct batadv_icmp_packet_rr); 393 394 /* drop packet if it has not necessary minimum size */ 395 if (unlikely(!pskb_may_pull(skb, hdr_size))) 396 goto out; 397 398 ethhdr = (struct ethhdr *)skb_mac_header(skb); 399 400 /* packet with unicast indication but broadcast recipient */ 401 if (is_broadcast_ether_addr(ethhdr->h_dest)) 402 goto out; 403 404 /* packet with broadcast sender address */ 405 if (is_broadcast_ether_addr(ethhdr->h_source)) 406 goto out; 407 408 /* not for me */ 409 if (!batadv_is_my_mac(ethhdr->h_dest)) 410 goto out; 411 412 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 413 414 /* add record route information if not full */ 415 if ((hdr_size == sizeof(struct batadv_icmp_packet_rr)) && 416 (icmp_packet->rr_cur < BATADV_RR_LEN)) { 417 memcpy(&(icmp_packet->rr[icmp_packet->rr_cur]), 418 ethhdr->h_dest, ETH_ALEN); 419 icmp_packet->rr_cur++; 420 } 421 422 /* packet for me */ 423 if (batadv_is_my_mac(icmp_packet->dst)) 424 return batadv_recv_my_icmp_packet(bat_priv, skb, hdr_size); 425 426 /* TTL exceeded */ 427 if (icmp_packet->header.ttl < 2) 428 return batadv_recv_icmp_ttl_exceeded(bat_priv, skb); 429 430 /* get routing information */ 431 orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->dst); 432 if (!orig_node) 433 goto out; 434 435 /* create a copy of the skb, if needed, to modify it. */ 436 if (skb_cow(skb, ETH_HLEN) < 0) 437 goto out; 438 439 icmp_packet = (struct batadv_icmp_packet_rr *)skb->data; 440 441 /* decrement ttl */ 442 icmp_packet->header.ttl--; 443 444 /* route it */ 445 if (batadv_send_skb_to_orig(skb, orig_node, recv_if)) 446 ret = NET_RX_SUCCESS; 447 448 out: 449 if (orig_node) 450 batadv_orig_node_free_ref(orig_node); 451 return ret; 452 } 453 454 /* In the bonding case, send the packets in a round 455 * robin fashion over the remaining interfaces. 456 * 457 * This method rotates the bonding list and increases the 458 * returned router's refcount. 459 */ 460 static struct batadv_neigh_node * 461 batadv_find_bond_router(struct batadv_orig_node *primary_orig, 462 const struct batadv_hard_iface *recv_if) 463 { 464 struct batadv_neigh_node *tmp_neigh_node; 465 struct batadv_neigh_node *router = NULL, *first_candidate = NULL; 466 467 rcu_read_lock(); 468 list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list, 469 bonding_list) { 470 if (!first_candidate) 471 first_candidate = tmp_neigh_node; 472 473 /* recv_if == NULL on the first node. */ 474 if (tmp_neigh_node->if_incoming == recv_if) 475 continue; 476 477 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount)) 478 continue; 479 480 router = tmp_neigh_node; 481 break; 482 } 483 484 /* use the first candidate if nothing was found. */ 485 if (!router && first_candidate && 486 atomic_inc_not_zero(&first_candidate->refcount)) 487 router = first_candidate; 488 489 if (!router) 490 goto out; 491 492 /* selected should point to the next element 493 * after the current router 494 */ 495 spin_lock_bh(&primary_orig->neigh_list_lock); 496 /* this is a list_move(), which unfortunately 497 * does not exist as rcu version 498 */ 499 list_del_rcu(&primary_orig->bond_list); 500 list_add_rcu(&primary_orig->bond_list, 501 &router->bonding_list); 502 spin_unlock_bh(&primary_orig->neigh_list_lock); 503 504 out: 505 rcu_read_unlock(); 506 return router; 507 } 508 509 /* Interface Alternating: Use the best of the 510 * remaining candidates which are not using 511 * this interface. 512 * 513 * Increases the returned router's refcount 514 */ 515 static struct batadv_neigh_node * 516 batadv_find_ifalter_router(struct batadv_orig_node *primary_orig, 517 const struct batadv_hard_iface *recv_if) 518 { 519 struct batadv_neigh_node *tmp_neigh_node; 520 struct batadv_neigh_node *router = NULL, *first_candidate = NULL; 521 522 rcu_read_lock(); 523 list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list, 524 bonding_list) { 525 if (!first_candidate) 526 first_candidate = tmp_neigh_node; 527 528 /* recv_if == NULL on the first node. */ 529 if (tmp_neigh_node->if_incoming == recv_if) 530 continue; 531 532 if (router && tmp_neigh_node->tq_avg <= router->tq_avg) 533 continue; 534 535 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount)) 536 continue; 537 538 /* decrement refcount of previously selected router */ 539 if (router) 540 batadv_neigh_node_free_ref(router); 541 542 /* we found a better router (or at least one valid router) */ 543 router = tmp_neigh_node; 544 } 545 546 /* use the first candidate if nothing was found. */ 547 if (!router && first_candidate && 548 atomic_inc_not_zero(&first_candidate->refcount)) 549 router = first_candidate; 550 551 rcu_read_unlock(); 552 return router; 553 } 554 555 static int batadv_check_unicast_packet(struct sk_buff *skb, int hdr_size) 556 { 557 struct ethhdr *ethhdr; 558 559 /* drop packet if it has not necessary minimum size */ 560 if (unlikely(!pskb_may_pull(skb, hdr_size))) 561 return -1; 562 563 ethhdr = (struct ethhdr *)skb_mac_header(skb); 564 565 /* packet with unicast indication but broadcast recipient */ 566 if (is_broadcast_ether_addr(ethhdr->h_dest)) 567 return -1; 568 569 /* packet with broadcast sender address */ 570 if (is_broadcast_ether_addr(ethhdr->h_source)) 571 return -1; 572 573 /* not for me */ 574 if (!batadv_is_my_mac(ethhdr->h_dest)) 575 return -1; 576 577 return 0; 578 } 579 580 int batadv_recv_tt_query(struct sk_buff *skb, struct batadv_hard_iface *recv_if) 581 { 582 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 583 struct batadv_tt_query_packet *tt_query; 584 uint16_t tt_size; 585 int hdr_size = sizeof(*tt_query); 586 char tt_flag; 587 size_t packet_size; 588 589 if (batadv_check_unicast_packet(skb, hdr_size) < 0) 590 return NET_RX_DROP; 591 592 /* I could need to modify it */ 593 if (skb_cow(skb, sizeof(struct batadv_tt_query_packet)) < 0) 594 goto out; 595 596 tt_query = (struct batadv_tt_query_packet *)skb->data; 597 598 switch (tt_query->flags & BATADV_TT_QUERY_TYPE_MASK) { 599 case BATADV_TT_REQUEST: 600 batadv_inc_counter(bat_priv, BATADV_CNT_TT_REQUEST_RX); 601 602 /* If we cannot provide an answer the tt_request is 603 * forwarded 604 */ 605 if (!batadv_send_tt_response(bat_priv, tt_query)) { 606 if (tt_query->flags & BATADV_TT_FULL_TABLE) 607 tt_flag = 'F'; 608 else 609 tt_flag = '.'; 610 611 batadv_dbg(BATADV_DBG_TT, bat_priv, 612 "Routing TT_REQUEST to %pM [%c]\n", 613 tt_query->dst, 614 tt_flag); 615 return batadv_route_unicast_packet(skb, recv_if); 616 } 617 break; 618 case BATADV_TT_RESPONSE: 619 batadv_inc_counter(bat_priv, BATADV_CNT_TT_RESPONSE_RX); 620 621 if (batadv_is_my_mac(tt_query->dst)) { 622 /* packet needs to be linearized to access the TT 623 * changes 624 */ 625 if (skb_linearize(skb) < 0) 626 goto out; 627 /* skb_linearize() possibly changed skb->data */ 628 tt_query = (struct batadv_tt_query_packet *)skb->data; 629 630 tt_size = batadv_tt_len(ntohs(tt_query->tt_data)); 631 632 /* Ensure we have all the claimed data */ 633 packet_size = sizeof(struct batadv_tt_query_packet); 634 packet_size += tt_size; 635 if (unlikely(skb_headlen(skb) < packet_size)) 636 goto out; 637 638 batadv_handle_tt_response(bat_priv, tt_query); 639 } else { 640 if (tt_query->flags & BATADV_TT_FULL_TABLE) 641 tt_flag = 'F'; 642 else 643 tt_flag = '.'; 644 batadv_dbg(BATADV_DBG_TT, bat_priv, 645 "Routing TT_RESPONSE to %pM [%c]\n", 646 tt_query->dst, 647 tt_flag); 648 return batadv_route_unicast_packet(skb, recv_if); 649 } 650 break; 651 } 652 653 out: 654 /* returning NET_RX_DROP will make the caller function kfree the skb */ 655 return NET_RX_DROP; 656 } 657 658 int batadv_recv_roam_adv(struct sk_buff *skb, struct batadv_hard_iface *recv_if) 659 { 660 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 661 struct batadv_roam_adv_packet *roam_adv_packet; 662 struct batadv_orig_node *orig_node; 663 664 if (batadv_check_unicast_packet(skb, sizeof(*roam_adv_packet)) < 0) 665 goto out; 666 667 batadv_inc_counter(bat_priv, BATADV_CNT_TT_ROAM_ADV_RX); 668 669 roam_adv_packet = (struct batadv_roam_adv_packet *)skb->data; 670 671 if (!batadv_is_my_mac(roam_adv_packet->dst)) 672 return batadv_route_unicast_packet(skb, recv_if); 673 674 /* check if it is a backbone gateway. we don't accept 675 * roaming advertisement from it, as it has the same 676 * entries as we have. 677 */ 678 if (batadv_bla_is_backbone_gw_orig(bat_priv, roam_adv_packet->src)) 679 goto out; 680 681 orig_node = batadv_orig_hash_find(bat_priv, roam_adv_packet->src); 682 if (!orig_node) 683 goto out; 684 685 batadv_dbg(BATADV_DBG_TT, bat_priv, 686 "Received ROAMING_ADV from %pM (client %pM)\n", 687 roam_adv_packet->src, roam_adv_packet->client); 688 689 batadv_tt_global_add(bat_priv, orig_node, roam_adv_packet->client, 690 BATADV_TT_CLIENT_ROAM, 691 atomic_read(&orig_node->last_ttvn) + 1); 692 693 batadv_orig_node_free_ref(orig_node); 694 out: 695 /* returning NET_RX_DROP will make the caller function kfree the skb */ 696 return NET_RX_DROP; 697 } 698 699 /* find a suitable router for this originator, and use 700 * bonding if possible. increases the found neighbors 701 * refcount. 702 */ 703 struct batadv_neigh_node * 704 batadv_find_router(struct batadv_priv *bat_priv, 705 struct batadv_orig_node *orig_node, 706 const struct batadv_hard_iface *recv_if) 707 { 708 struct batadv_orig_node *primary_orig_node; 709 struct batadv_orig_node *router_orig; 710 struct batadv_neigh_node *router; 711 static uint8_t zero_mac[ETH_ALEN] = {0, 0, 0, 0, 0, 0}; 712 int bonding_enabled; 713 uint8_t *primary_addr; 714 715 if (!orig_node) 716 return NULL; 717 718 router = batadv_orig_node_get_router(orig_node); 719 if (!router) 720 goto err; 721 722 /* without bonding, the first node should 723 * always choose the default router. 724 */ 725 bonding_enabled = atomic_read(&bat_priv->bonding); 726 727 rcu_read_lock(); 728 /* select default router to output */ 729 router_orig = router->orig_node; 730 if (!router_orig) 731 goto err_unlock; 732 733 if ((!recv_if) && (!bonding_enabled)) 734 goto return_router; 735 736 primary_addr = router_orig->primary_addr; 737 738 /* if we have something in the primary_addr, we can search 739 * for a potential bonding candidate. 740 */ 741 if (batadv_compare_eth(primary_addr, zero_mac)) 742 goto return_router; 743 744 /* find the orig_node which has the primary interface. might 745 * even be the same as our router_orig in many cases 746 */ 747 if (batadv_compare_eth(primary_addr, router_orig->orig)) { 748 primary_orig_node = router_orig; 749 } else { 750 primary_orig_node = batadv_orig_hash_find(bat_priv, 751 primary_addr); 752 if (!primary_orig_node) 753 goto return_router; 754 755 batadv_orig_node_free_ref(primary_orig_node); 756 } 757 758 /* with less than 2 candidates, we can't do any 759 * bonding and prefer the original router. 760 */ 761 if (atomic_read(&primary_orig_node->bond_candidates) < 2) 762 goto return_router; 763 764 /* all nodes between should choose a candidate which 765 * is is not on the interface where the packet came 766 * in. 767 */ 768 batadv_neigh_node_free_ref(router); 769 770 if (bonding_enabled) 771 router = batadv_find_bond_router(primary_orig_node, recv_if); 772 else 773 router = batadv_find_ifalter_router(primary_orig_node, recv_if); 774 775 return_router: 776 if (router && router->if_incoming->if_status != BATADV_IF_ACTIVE) 777 goto err_unlock; 778 779 rcu_read_unlock(); 780 return router; 781 err_unlock: 782 rcu_read_unlock(); 783 err: 784 if (router) 785 batadv_neigh_node_free_ref(router); 786 return NULL; 787 } 788 789 static int batadv_route_unicast_packet(struct sk_buff *skb, 790 struct batadv_hard_iface *recv_if) 791 { 792 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 793 struct batadv_orig_node *orig_node = NULL; 794 struct batadv_neigh_node *neigh_node = NULL; 795 struct batadv_unicast_packet *unicast_packet; 796 struct ethhdr *ethhdr = (struct ethhdr *)skb_mac_header(skb); 797 int ret = NET_RX_DROP; 798 struct sk_buff *new_skb; 799 800 unicast_packet = (struct batadv_unicast_packet *)skb->data; 801 802 /* TTL exceeded */ 803 if (unicast_packet->header.ttl < 2) { 804 pr_debug("Warning - can't forward unicast packet from %pM to %pM: ttl exceeded\n", 805 ethhdr->h_source, unicast_packet->dest); 806 goto out; 807 } 808 809 /* get routing information */ 810 orig_node = batadv_orig_hash_find(bat_priv, unicast_packet->dest); 811 812 if (!orig_node) 813 goto out; 814 815 /* find_router() increases neigh_nodes refcount if found. */ 816 neigh_node = batadv_find_router(bat_priv, orig_node, recv_if); 817 818 if (!neigh_node) 819 goto out; 820 821 /* create a copy of the skb, if needed, to modify it. */ 822 if (skb_cow(skb, ETH_HLEN) < 0) 823 goto out; 824 825 unicast_packet = (struct batadv_unicast_packet *)skb->data; 826 827 if (unicast_packet->header.packet_type == BATADV_UNICAST && 828 atomic_read(&bat_priv->fragmentation) && 829 skb->len > neigh_node->if_incoming->net_dev->mtu) { 830 ret = batadv_frag_send_skb(skb, bat_priv, 831 neigh_node->if_incoming, 832 neigh_node->addr); 833 goto out; 834 } 835 836 if (unicast_packet->header.packet_type == BATADV_UNICAST_FRAG && 837 batadv_frag_can_reassemble(skb, 838 neigh_node->if_incoming->net_dev->mtu)) { 839 840 ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb); 841 842 if (ret == NET_RX_DROP) 843 goto out; 844 845 /* packet was buffered for late merge */ 846 if (!new_skb) { 847 ret = NET_RX_SUCCESS; 848 goto out; 849 } 850 851 skb = new_skb; 852 unicast_packet = (struct batadv_unicast_packet *)skb->data; 853 } 854 855 /* decrement ttl */ 856 unicast_packet->header.ttl--; 857 858 /* Update stats counter */ 859 batadv_inc_counter(bat_priv, BATADV_CNT_FORWARD); 860 batadv_add_counter(bat_priv, BATADV_CNT_FORWARD_BYTES, 861 skb->len + ETH_HLEN); 862 863 /* route it */ 864 if (batadv_send_skb_to_orig(skb, orig_node, recv_if)) 865 ret = NET_RX_SUCCESS; 866 867 out: 868 if (neigh_node) 869 batadv_neigh_node_free_ref(neigh_node); 870 if (orig_node) 871 batadv_orig_node_free_ref(orig_node); 872 return ret; 873 } 874 875 /** 876 * batadv_reroute_unicast_packet - update the unicast header for re-routing 877 * @bat_priv: the bat priv with all the soft interface information 878 * @unicast_packet: the unicast header to be updated 879 * @dst_addr: the payload destination 880 * 881 * Search the translation table for dst_addr and update the unicast header with 882 * the new corresponding information (originator address where the destination 883 * client currently is and its known TTVN) 884 * 885 * Returns true if the packet header has been updated, false otherwise 886 */ 887 static bool 888 batadv_reroute_unicast_packet(struct batadv_priv *bat_priv, 889 struct batadv_unicast_packet *unicast_packet, 890 uint8_t *dst_addr) 891 { 892 struct batadv_orig_node *orig_node = NULL; 893 struct batadv_hard_iface *primary_if = NULL; 894 bool ret = false; 895 uint8_t *orig_addr, orig_ttvn; 896 897 if (batadv_is_my_client(bat_priv, dst_addr)) { 898 primary_if = batadv_primary_if_get_selected(bat_priv); 899 if (!primary_if) 900 goto out; 901 orig_addr = primary_if->net_dev->dev_addr; 902 orig_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn); 903 } else { 904 orig_node = batadv_transtable_search(bat_priv, NULL, dst_addr); 905 if (!orig_node) 906 goto out; 907 908 if (batadv_compare_eth(orig_node->orig, unicast_packet->dest)) 909 goto out; 910 911 orig_addr = orig_node->orig; 912 orig_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn); 913 } 914 915 /* update the packet header */ 916 memcpy(unicast_packet->dest, orig_addr, ETH_ALEN); 917 unicast_packet->ttvn = orig_ttvn; 918 919 ret = true; 920 out: 921 if (primary_if) 922 batadv_hardif_free_ref(primary_if); 923 if (orig_node) 924 batadv_orig_node_free_ref(orig_node); 925 926 return ret; 927 } 928 929 static int batadv_check_unicast_ttvn(struct batadv_priv *bat_priv, 930 struct sk_buff *skb) { 931 uint8_t curr_ttvn, old_ttvn; 932 struct batadv_orig_node *orig_node; 933 struct ethhdr *ethhdr; 934 struct batadv_hard_iface *primary_if; 935 struct batadv_unicast_packet *unicast_packet; 936 int is_old_ttvn; 937 938 /* check if there is enough data before accessing it */ 939 if (pskb_may_pull(skb, sizeof(*unicast_packet) + ETH_HLEN) < 0) 940 return 0; 941 942 /* create a copy of the skb (in case of for re-routing) to modify it. */ 943 if (skb_cow(skb, sizeof(*unicast_packet)) < 0) 944 return 0; 945 946 unicast_packet = (struct batadv_unicast_packet *)skb->data; 947 ethhdr = (struct ethhdr *)(skb->data + sizeof(*unicast_packet)); 948 949 /* check if the destination client was served by this node and it is now 950 * roaming. In this case, it means that the node has got a ROAM_ADV 951 * message and that it knows the new destination in the mesh to re-route 952 * the packet to 953 */ 954 if (batadv_tt_local_client_is_roaming(bat_priv, ethhdr->h_dest)) { 955 if (batadv_reroute_unicast_packet(bat_priv, unicast_packet, 956 ethhdr->h_dest)) 957 net_ratelimited_function(batadv_dbg, BATADV_DBG_TT, 958 bat_priv, 959 "Rerouting unicast packet to %pM (dst=%pM): Local Roaming\n", 960 unicast_packet->dest, 961 ethhdr->h_dest); 962 /* at this point the mesh destination should have been 963 * substituted with the originator address found in the global 964 * table. If not, let the packet go untouched anyway because 965 * there is nothing the node can do 966 */ 967 return 1; 968 } 969 970 /* retrieve the TTVN known by this node for the packet destination. This 971 * value is used later to check if the node which sent (or re-routed 972 * last time) the packet had an updated information or not 973 */ 974 curr_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn); 975 if (!batadv_is_my_mac(unicast_packet->dest)) { 976 orig_node = batadv_orig_hash_find(bat_priv, 977 unicast_packet->dest); 978 /* if it is not possible to find the orig_node representing the 979 * destination, the packet can immediately be dropped as it will 980 * not be possible to deliver it 981 */ 982 if (!orig_node) 983 return 0; 984 985 curr_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn); 986 batadv_orig_node_free_ref(orig_node); 987 } 988 989 /* check if the TTVN contained in the packet is fresher than what the 990 * node knows 991 */ 992 is_old_ttvn = batadv_seq_before(unicast_packet->ttvn, curr_ttvn); 993 if (!is_old_ttvn) 994 return 1; 995 996 old_ttvn = unicast_packet->ttvn; 997 /* the packet was forged based on outdated network information. Its 998 * destination can possibly be updated and forwarded towards the new 999 * target host 1000 */ 1001 if (batadv_reroute_unicast_packet(bat_priv, unicast_packet, 1002 ethhdr->h_dest)) { 1003 net_ratelimited_function(batadv_dbg, BATADV_DBG_TT, bat_priv, 1004 "Rerouting unicast packet to %pM (dst=%pM): TTVN mismatch old_ttvn=%u new_ttvn=%u\n", 1005 unicast_packet->dest, ethhdr->h_dest, 1006 old_ttvn, curr_ttvn); 1007 return 1; 1008 } 1009 1010 /* the packet has not been re-routed: either the destination is 1011 * currently served by this node or there is no destination at all and 1012 * it is possible to drop the packet 1013 */ 1014 if (!batadv_is_my_client(bat_priv, ethhdr->h_dest)) 1015 return 0; 1016 1017 /* update the header in order to let the packet be delivered to this 1018 * node's soft interface 1019 */ 1020 primary_if = batadv_primary_if_get_selected(bat_priv); 1021 if (!primary_if) 1022 return 0; 1023 1024 memcpy(unicast_packet->dest, primary_if->net_dev->dev_addr, ETH_ALEN); 1025 1026 batadv_hardif_free_ref(primary_if); 1027 1028 unicast_packet->ttvn = curr_ttvn; 1029 1030 return 1; 1031 } 1032 1033 int batadv_recv_unicast_packet(struct sk_buff *skb, 1034 struct batadv_hard_iface *recv_if) 1035 { 1036 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1037 struct batadv_unicast_packet *unicast_packet; 1038 struct batadv_unicast_4addr_packet *unicast_4addr_packet; 1039 uint8_t *orig_addr; 1040 struct batadv_orig_node *orig_node = NULL; 1041 int hdr_size = sizeof(*unicast_packet); 1042 bool is4addr; 1043 1044 unicast_packet = (struct batadv_unicast_packet *)skb->data; 1045 unicast_4addr_packet = (struct batadv_unicast_4addr_packet *)skb->data; 1046 1047 is4addr = unicast_packet->header.packet_type == BATADV_UNICAST_4ADDR; 1048 /* the caller function should have already pulled 2 bytes */ 1049 if (is4addr) 1050 hdr_size = sizeof(*unicast_4addr_packet); 1051 1052 if (batadv_check_unicast_packet(skb, hdr_size) < 0) 1053 return NET_RX_DROP; 1054 1055 if (!batadv_check_unicast_ttvn(bat_priv, skb)) 1056 return NET_RX_DROP; 1057 1058 /* packet for me */ 1059 if (batadv_is_my_mac(unicast_packet->dest)) { 1060 if (is4addr) { 1061 batadv_dat_inc_counter(bat_priv, 1062 unicast_4addr_packet->subtype); 1063 orig_addr = unicast_4addr_packet->src; 1064 orig_node = batadv_orig_hash_find(bat_priv, orig_addr); 1065 } 1066 1067 if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb, 1068 hdr_size)) 1069 goto rx_success; 1070 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb, 1071 hdr_size)) 1072 goto rx_success; 1073 1074 batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size, 1075 orig_node); 1076 1077 rx_success: 1078 if (orig_node) 1079 batadv_orig_node_free_ref(orig_node); 1080 1081 return NET_RX_SUCCESS; 1082 } 1083 1084 return batadv_route_unicast_packet(skb, recv_if); 1085 } 1086 1087 int batadv_recv_ucast_frag_packet(struct sk_buff *skb, 1088 struct batadv_hard_iface *recv_if) 1089 { 1090 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1091 struct batadv_unicast_frag_packet *unicast_packet; 1092 int hdr_size = sizeof(*unicast_packet); 1093 struct sk_buff *new_skb = NULL; 1094 int ret; 1095 1096 if (batadv_check_unicast_packet(skb, hdr_size) < 0) 1097 return NET_RX_DROP; 1098 1099 if (!batadv_check_unicast_ttvn(bat_priv, skb)) 1100 return NET_RX_DROP; 1101 1102 unicast_packet = (struct batadv_unicast_frag_packet *)skb->data; 1103 1104 /* packet for me */ 1105 if (batadv_is_my_mac(unicast_packet->dest)) { 1106 1107 ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb); 1108 1109 if (ret == NET_RX_DROP) 1110 return NET_RX_DROP; 1111 1112 /* packet was buffered for late merge */ 1113 if (!new_skb) 1114 return NET_RX_SUCCESS; 1115 1116 if (batadv_dat_snoop_incoming_arp_request(bat_priv, new_skb, 1117 hdr_size)) 1118 goto rx_success; 1119 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, new_skb, 1120 hdr_size)) 1121 goto rx_success; 1122 1123 batadv_interface_rx(recv_if->soft_iface, new_skb, recv_if, 1124 sizeof(struct batadv_unicast_packet), NULL); 1125 1126 rx_success: 1127 return NET_RX_SUCCESS; 1128 } 1129 1130 return batadv_route_unicast_packet(skb, recv_if); 1131 } 1132 1133 1134 int batadv_recv_bcast_packet(struct sk_buff *skb, 1135 struct batadv_hard_iface *recv_if) 1136 { 1137 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1138 struct batadv_orig_node *orig_node = NULL; 1139 struct batadv_bcast_packet *bcast_packet; 1140 struct ethhdr *ethhdr; 1141 int hdr_size = sizeof(*bcast_packet); 1142 int ret = NET_RX_DROP; 1143 int32_t seq_diff; 1144 1145 /* drop packet if it has not necessary minimum size */ 1146 if (unlikely(!pskb_may_pull(skb, hdr_size))) 1147 goto out; 1148 1149 ethhdr = (struct ethhdr *)skb_mac_header(skb); 1150 1151 /* packet with broadcast indication but unicast recipient */ 1152 if (!is_broadcast_ether_addr(ethhdr->h_dest)) 1153 goto out; 1154 1155 /* packet with broadcast sender address */ 1156 if (is_broadcast_ether_addr(ethhdr->h_source)) 1157 goto out; 1158 1159 /* ignore broadcasts sent by myself */ 1160 if (batadv_is_my_mac(ethhdr->h_source)) 1161 goto out; 1162 1163 bcast_packet = (struct batadv_bcast_packet *)skb->data; 1164 1165 /* ignore broadcasts originated by myself */ 1166 if (batadv_is_my_mac(bcast_packet->orig)) 1167 goto out; 1168 1169 if (bcast_packet->header.ttl < 2) 1170 goto out; 1171 1172 orig_node = batadv_orig_hash_find(bat_priv, bcast_packet->orig); 1173 1174 if (!orig_node) 1175 goto out; 1176 1177 spin_lock_bh(&orig_node->bcast_seqno_lock); 1178 1179 /* check whether the packet is a duplicate */ 1180 if (batadv_test_bit(orig_node->bcast_bits, orig_node->last_bcast_seqno, 1181 ntohl(bcast_packet->seqno))) 1182 goto spin_unlock; 1183 1184 seq_diff = ntohl(bcast_packet->seqno) - orig_node->last_bcast_seqno; 1185 1186 /* check whether the packet is old and the host just restarted. */ 1187 if (batadv_window_protected(bat_priv, seq_diff, 1188 &orig_node->bcast_seqno_reset)) 1189 goto spin_unlock; 1190 1191 /* mark broadcast in flood history, update window position 1192 * if required. 1193 */ 1194 if (batadv_bit_get_packet(bat_priv, orig_node->bcast_bits, seq_diff, 1)) 1195 orig_node->last_bcast_seqno = ntohl(bcast_packet->seqno); 1196 1197 spin_unlock_bh(&orig_node->bcast_seqno_lock); 1198 1199 /* check whether this has been sent by another originator before */ 1200 if (batadv_bla_check_bcast_duplist(bat_priv, skb)) 1201 goto out; 1202 1203 /* rebroadcast packet */ 1204 batadv_add_bcast_packet_to_list(bat_priv, skb, 1); 1205 1206 /* don't hand the broadcast up if it is from an originator 1207 * from the same backbone. 1208 */ 1209 if (batadv_bla_is_backbone_gw(skb, orig_node, hdr_size)) 1210 goto out; 1211 1212 if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb, hdr_size)) 1213 goto rx_success; 1214 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb, hdr_size)) 1215 goto rx_success; 1216 1217 /* broadcast for me */ 1218 batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size, 1219 orig_node); 1220 1221 rx_success: 1222 ret = NET_RX_SUCCESS; 1223 goto out; 1224 1225 spin_unlock: 1226 spin_unlock_bh(&orig_node->bcast_seqno_lock); 1227 out: 1228 if (orig_node) 1229 batadv_orig_node_free_ref(orig_node); 1230 return ret; 1231 } 1232 1233 int batadv_recv_vis_packet(struct sk_buff *skb, 1234 struct batadv_hard_iface *recv_if) 1235 { 1236 struct batadv_vis_packet *vis_packet; 1237 struct ethhdr *ethhdr; 1238 struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface); 1239 int hdr_size = sizeof(*vis_packet); 1240 1241 /* keep skb linear */ 1242 if (skb_linearize(skb) < 0) 1243 return NET_RX_DROP; 1244 1245 if (unlikely(!pskb_may_pull(skb, hdr_size))) 1246 return NET_RX_DROP; 1247 1248 vis_packet = (struct batadv_vis_packet *)skb->data; 1249 ethhdr = (struct ethhdr *)skb_mac_header(skb); 1250 1251 /* not for me */ 1252 if (!batadv_is_my_mac(ethhdr->h_dest)) 1253 return NET_RX_DROP; 1254 1255 /* ignore own packets */ 1256 if (batadv_is_my_mac(vis_packet->vis_orig)) 1257 return NET_RX_DROP; 1258 1259 if (batadv_is_my_mac(vis_packet->sender_orig)) 1260 return NET_RX_DROP; 1261 1262 switch (vis_packet->vis_type) { 1263 case BATADV_VIS_TYPE_SERVER_SYNC: 1264 batadv_receive_server_sync_packet(bat_priv, vis_packet, 1265 skb_headlen(skb)); 1266 break; 1267 1268 case BATADV_VIS_TYPE_CLIENT_UPDATE: 1269 batadv_receive_client_update_packet(bat_priv, vis_packet, 1270 skb_headlen(skb)); 1271 break; 1272 1273 default: /* ignore unknown packet */ 1274 break; 1275 } 1276 1277 /* We take a copy of the data in the packet, so we should 1278 * always free the skbuf. 1279 */ 1280 return NET_RX_DROP; 1281 } 1282