xref: /openbmc/linux/net/tipc/link.c (revision 4bce6fce)
1 /*
2  * net/tipc/link.c: TIPC link code
3  *
4  * Copyright (c) 1996-2007, 2012-2015, Ericsson AB
5  * Copyright (c) 2004-2007, 2010-2013, Wind River Systems
6  * All rights reserved.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted provided that the following conditions are met:
10  *
11  * 1. Redistributions of source code must retain the above copyright
12  *    notice, this list of conditions and the following disclaimer.
13  * 2. Redistributions in binary form must reproduce the above copyright
14  *    notice, this list of conditions and the following disclaimer in the
15  *    documentation and/or other materials provided with the distribution.
16  * 3. Neither the names of the copyright holders nor the names of its
17  *    contributors may be used to endorse or promote products derived from
18  *    this software without specific prior written permission.
19  *
20  * Alternatively, this software may be distributed under the terms of the
21  * GNU General Public License ("GPL") version 2 as published by the Free
22  * Software Foundation.
23  *
24  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
25  * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
27  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
28  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
29  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
30  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
31  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
32  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
33  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
34  * POSSIBILITY OF SUCH DAMAGE.
35  */
36 
37 #include "core.h"
38 #include "subscr.h"
39 #include "link.h"
40 #include "bcast.h"
41 #include "socket.h"
42 #include "name_distr.h"
43 #include "discover.h"
44 #include "netlink.h"
45 
46 #include <linux/pkt_sched.h>
47 
48 /*
49  * Error message prefixes
50  */
51 static const char *link_co_err = "Link changeover error, ";
52 static const char *link_rst_msg = "Resetting link ";
53 static const char *link_unk_evt = "Unknown link event ";
54 
55 static const struct nla_policy tipc_nl_link_policy[TIPC_NLA_LINK_MAX + 1] = {
56 	[TIPC_NLA_LINK_UNSPEC]		= { .type = NLA_UNSPEC },
57 	[TIPC_NLA_LINK_NAME] = {
58 		.type = NLA_STRING,
59 		.len = TIPC_MAX_LINK_NAME
60 	},
61 	[TIPC_NLA_LINK_MTU]		= { .type = NLA_U32 },
62 	[TIPC_NLA_LINK_BROADCAST]	= { .type = NLA_FLAG },
63 	[TIPC_NLA_LINK_UP]		= { .type = NLA_FLAG },
64 	[TIPC_NLA_LINK_ACTIVE]		= { .type = NLA_FLAG },
65 	[TIPC_NLA_LINK_PROP]		= { .type = NLA_NESTED },
66 	[TIPC_NLA_LINK_STATS]		= { .type = NLA_NESTED },
67 	[TIPC_NLA_LINK_RX]		= { .type = NLA_U32 },
68 	[TIPC_NLA_LINK_TX]		= { .type = NLA_U32 }
69 };
70 
71 /* Properties valid for media, bearar and link */
72 static const struct nla_policy tipc_nl_prop_policy[TIPC_NLA_PROP_MAX + 1] = {
73 	[TIPC_NLA_PROP_UNSPEC]		= { .type = NLA_UNSPEC },
74 	[TIPC_NLA_PROP_PRIO]		= { .type = NLA_U32 },
75 	[TIPC_NLA_PROP_TOL]		= { .type = NLA_U32 },
76 	[TIPC_NLA_PROP_WIN]		= { .type = NLA_U32 }
77 };
78 
79 /*
80  * Out-of-range value for link session numbers
81  */
82 #define INVALID_SESSION 0x10000
83 
84 /*
85  * Link state events:
86  */
87 #define  STARTING_EVT    856384768	/* link processing trigger */
88 #define  TRAFFIC_MSG_EVT 560815u	/* rx'd ??? */
89 #define  TIMEOUT_EVT     560817u	/* link timer expired */
90 
91 /*
92  * State value stored in 'failover_pkts'
93  */
94 #define FIRST_FAILOVER 0xffffu
95 
96 static void link_handle_out_of_seq_msg(struct tipc_link *link,
97 				       struct sk_buff *skb);
98 static void tipc_link_proto_rcv(struct tipc_link *link,
99 				struct sk_buff *skb);
100 static void link_set_supervision_props(struct tipc_link *l_ptr, u32 tol);
101 static void link_state_event(struct tipc_link *l_ptr, u32 event);
102 static void link_reset_statistics(struct tipc_link *l_ptr);
103 static void link_print(struct tipc_link *l_ptr, const char *str);
104 static void tipc_link_sync_xmit(struct tipc_link *l);
105 static void tipc_link_sync_rcv(struct tipc_node *n, struct sk_buff *buf);
106 static void tipc_link_input(struct tipc_link *l, struct sk_buff *skb);
107 static bool tipc_data_input(struct tipc_link *l, struct sk_buff *skb);
108 static bool tipc_link_failover_rcv(struct tipc_link *l, struct sk_buff **skb);
109 /*
110  *  Simple link routines
111  */
112 static unsigned int align(unsigned int i)
113 {
114 	return (i + 3) & ~3u;
115 }
116 
117 static void tipc_link_release(struct kref *kref)
118 {
119 	kfree(container_of(kref, struct tipc_link, ref));
120 }
121 
122 static void tipc_link_get(struct tipc_link *l_ptr)
123 {
124 	kref_get(&l_ptr->ref);
125 }
126 
127 static void tipc_link_put(struct tipc_link *l_ptr)
128 {
129 	kref_put(&l_ptr->ref, tipc_link_release);
130 }
131 
132 static struct tipc_link *tipc_parallel_link(struct tipc_link *l)
133 {
134 	if (l->owner->active_links[0] != l)
135 		return l->owner->active_links[0];
136 	return l->owner->active_links[1];
137 }
138 
139 /*
140  *  Simple non-static link routines (i.e. referenced outside this file)
141  */
142 int tipc_link_is_up(struct tipc_link *l_ptr)
143 {
144 	if (!l_ptr)
145 		return 0;
146 	return link_working_working(l_ptr) || link_working_unknown(l_ptr);
147 }
148 
149 int tipc_link_is_active(struct tipc_link *l_ptr)
150 {
151 	return	(l_ptr->owner->active_links[0] == l_ptr) ||
152 		(l_ptr->owner->active_links[1] == l_ptr);
153 }
154 
155 /**
156  * link_timeout - handle expiration of link timer
157  * @l_ptr: pointer to link
158  */
159 static void link_timeout(unsigned long data)
160 {
161 	struct tipc_link *l_ptr = (struct tipc_link *)data;
162 	struct sk_buff *skb;
163 
164 	tipc_node_lock(l_ptr->owner);
165 
166 	/* update counters used in statistical profiling of send traffic */
167 	l_ptr->stats.accu_queue_sz += skb_queue_len(&l_ptr->transmq);
168 	l_ptr->stats.queue_sz_counts++;
169 
170 	skb = skb_peek(&l_ptr->transmq);
171 	if (skb) {
172 		struct tipc_msg *msg = buf_msg(skb);
173 		u32 length = msg_size(msg);
174 
175 		if ((msg_user(msg) == MSG_FRAGMENTER) &&
176 		    (msg_type(msg) == FIRST_FRAGMENT)) {
177 			length = msg_size(msg_get_wrapped(msg));
178 		}
179 		if (length) {
180 			l_ptr->stats.msg_lengths_total += length;
181 			l_ptr->stats.msg_length_counts++;
182 			if (length <= 64)
183 				l_ptr->stats.msg_length_profile[0]++;
184 			else if (length <= 256)
185 				l_ptr->stats.msg_length_profile[1]++;
186 			else if (length <= 1024)
187 				l_ptr->stats.msg_length_profile[2]++;
188 			else if (length <= 4096)
189 				l_ptr->stats.msg_length_profile[3]++;
190 			else if (length <= 16384)
191 				l_ptr->stats.msg_length_profile[4]++;
192 			else if (length <= 32768)
193 				l_ptr->stats.msg_length_profile[5]++;
194 			else
195 				l_ptr->stats.msg_length_profile[6]++;
196 		}
197 	}
198 
199 	/* do all other link processing performed on a periodic basis */
200 	link_state_event(l_ptr, TIMEOUT_EVT);
201 
202 	if (skb_queue_len(&l_ptr->backlogq))
203 		tipc_link_push_packets(l_ptr);
204 
205 	tipc_node_unlock(l_ptr->owner);
206 	tipc_link_put(l_ptr);
207 }
208 
209 static void link_set_timer(struct tipc_link *link, unsigned long time)
210 {
211 	if (!mod_timer(&link->timer, jiffies + time))
212 		tipc_link_get(link);
213 }
214 
215 /**
216  * tipc_link_create - create a new link
217  * @n_ptr: pointer to associated node
218  * @b_ptr: pointer to associated bearer
219  * @media_addr: media address to use when sending messages over link
220  *
221  * Returns pointer to link.
222  */
223 struct tipc_link *tipc_link_create(struct tipc_node *n_ptr,
224 				   struct tipc_bearer *b_ptr,
225 				   const struct tipc_media_addr *media_addr)
226 {
227 	struct tipc_net *tn = net_generic(n_ptr->net, tipc_net_id);
228 	struct tipc_link *l_ptr;
229 	struct tipc_msg *msg;
230 	char *if_name;
231 	char addr_string[16];
232 	u32 peer = n_ptr->addr;
233 
234 	if (n_ptr->link_cnt >= MAX_BEARERS) {
235 		tipc_addr_string_fill(addr_string, n_ptr->addr);
236 		pr_err("Attempt to establish %uth link to %s. Max %u allowed.\n",
237 			n_ptr->link_cnt, addr_string, MAX_BEARERS);
238 		return NULL;
239 	}
240 
241 	if (n_ptr->links[b_ptr->identity]) {
242 		tipc_addr_string_fill(addr_string, n_ptr->addr);
243 		pr_err("Attempt to establish second link on <%s> to %s\n",
244 		       b_ptr->name, addr_string);
245 		return NULL;
246 	}
247 
248 	l_ptr = kzalloc(sizeof(*l_ptr), GFP_ATOMIC);
249 	if (!l_ptr) {
250 		pr_warn("Link creation failed, no memory\n");
251 		return NULL;
252 	}
253 	kref_init(&l_ptr->ref);
254 	l_ptr->addr = peer;
255 	if_name = strchr(b_ptr->name, ':') + 1;
256 	sprintf(l_ptr->name, "%u.%u.%u:%s-%u.%u.%u:unknown",
257 		tipc_zone(tn->own_addr), tipc_cluster(tn->own_addr),
258 		tipc_node(tn->own_addr),
259 		if_name,
260 		tipc_zone(peer), tipc_cluster(peer), tipc_node(peer));
261 		/* note: peer i/f name is updated by reset/activate message */
262 	memcpy(&l_ptr->media_addr, media_addr, sizeof(*media_addr));
263 	l_ptr->owner = n_ptr;
264 	l_ptr->checkpoint = 1;
265 	l_ptr->peer_session = INVALID_SESSION;
266 	l_ptr->bearer_id = b_ptr->identity;
267 	link_set_supervision_props(l_ptr, b_ptr->tolerance);
268 	l_ptr->state = RESET_UNKNOWN;
269 
270 	l_ptr->pmsg = (struct tipc_msg *)&l_ptr->proto_msg;
271 	msg = l_ptr->pmsg;
272 	tipc_msg_init(tn->own_addr, msg, LINK_PROTOCOL, RESET_MSG, INT_H_SIZE,
273 		      l_ptr->addr);
274 	msg_set_size(msg, sizeof(l_ptr->proto_msg));
275 	msg_set_session(msg, (tn->random & 0xffff));
276 	msg_set_bearer_id(msg, b_ptr->identity);
277 	strcpy((char *)msg_data(msg), if_name);
278 	l_ptr->net_plane = b_ptr->net_plane;
279 	l_ptr->advertised_mtu = b_ptr->mtu;
280 	l_ptr->mtu = l_ptr->advertised_mtu;
281 	l_ptr->priority = b_ptr->priority;
282 	tipc_link_set_queue_limits(l_ptr, b_ptr->window);
283 	l_ptr->next_out_no = 1;
284 	__skb_queue_head_init(&l_ptr->transmq);
285 	__skb_queue_head_init(&l_ptr->backlogq);
286 	__skb_queue_head_init(&l_ptr->deferdq);
287 	skb_queue_head_init(&l_ptr->wakeupq);
288 	skb_queue_head_init(&l_ptr->inputq);
289 	skb_queue_head_init(&l_ptr->namedq);
290 	link_reset_statistics(l_ptr);
291 	tipc_node_attach_link(n_ptr, l_ptr);
292 	setup_timer(&l_ptr->timer, link_timeout, (unsigned long)l_ptr);
293 	link_state_event(l_ptr, STARTING_EVT);
294 
295 	return l_ptr;
296 }
297 
298 /**
299  * tipc_link_delete - Delete a link
300  * @l: link to be deleted
301  */
302 void tipc_link_delete(struct tipc_link *l)
303 {
304 	tipc_link_reset(l);
305 	if (del_timer(&l->timer))
306 		tipc_link_put(l);
307 	l->flags |= LINK_STOPPED;
308 	/* Delete link now, or when timer is finished: */
309 	tipc_link_reset_fragments(l);
310 	tipc_node_detach_link(l->owner, l);
311 	tipc_link_put(l);
312 }
313 
314 void tipc_link_delete_list(struct net *net, unsigned int bearer_id,
315 			   bool shutting_down)
316 {
317 	struct tipc_net *tn = net_generic(net, tipc_net_id);
318 	struct tipc_link *link;
319 	struct tipc_node *node;
320 
321 	rcu_read_lock();
322 	list_for_each_entry_rcu(node, &tn->node_list, list) {
323 		tipc_node_lock(node);
324 		link = node->links[bearer_id];
325 		if (link)
326 			tipc_link_delete(link);
327 		tipc_node_unlock(node);
328 	}
329 	rcu_read_unlock();
330 }
331 
332 /**
333  * link_schedule_user - schedule a message sender for wakeup after congestion
334  * @link: congested link
335  * @list: message that was attempted sent
336  * Create pseudo msg to send back to user when congestion abates
337  * Only consumes message if there is an error
338  */
339 static int link_schedule_user(struct tipc_link *link, struct sk_buff_head *list)
340 {
341 	struct tipc_msg *msg = buf_msg(skb_peek(list));
342 	int imp = msg_importance(msg);
343 	u32 oport = msg_origport(msg);
344 	u32 addr = link_own_addr(link);
345 	struct sk_buff *skb;
346 
347 	/* This really cannot happen...  */
348 	if (unlikely(imp > TIPC_CRITICAL_IMPORTANCE)) {
349 		pr_warn("%s<%s>, send queue full", link_rst_msg, link->name);
350 		tipc_link_reset(link);
351 		goto err;
352 	}
353 	/* Non-blocking sender: */
354 	if (TIPC_SKB_CB(skb_peek(list))->wakeup_pending)
355 		return -ELINKCONG;
356 
357 	/* Create and schedule wakeup pseudo message */
358 	skb = tipc_msg_create(SOCK_WAKEUP, 0, INT_H_SIZE, 0,
359 			      addr, addr, oport, 0, 0);
360 	if (!skb)
361 		goto err;
362 	TIPC_SKB_CB(skb)->chain_sz = skb_queue_len(list);
363 	TIPC_SKB_CB(skb)->chain_imp = imp;
364 	skb_queue_tail(&link->wakeupq, skb);
365 	link->stats.link_congs++;
366 	return -ELINKCONG;
367 err:
368 	__skb_queue_purge(list);
369 	return -ENOBUFS;
370 }
371 
372 /**
373  * link_prepare_wakeup - prepare users for wakeup after congestion
374  * @link: congested link
375  * Move a number of waiting users, as permitted by available space in
376  * the send queue, from link wait queue to node wait queue for wakeup
377  */
378 void link_prepare_wakeup(struct tipc_link *l)
379 {
380 	int pnd[TIPC_SYSTEM_IMPORTANCE + 1] = {0,};
381 	int imp, lim;
382 	struct sk_buff *skb, *tmp;
383 
384 	skb_queue_walk_safe(&l->wakeupq, skb, tmp) {
385 		imp = TIPC_SKB_CB(skb)->chain_imp;
386 		lim = l->window + l->backlog[imp].limit;
387 		pnd[imp] += TIPC_SKB_CB(skb)->chain_sz;
388 		if ((pnd[imp] + l->backlog[imp].len) >= lim)
389 			break;
390 		skb_unlink(skb, &l->wakeupq);
391 		skb_queue_tail(&l->inputq, skb);
392 		l->owner->inputq = &l->inputq;
393 		l->owner->action_flags |= TIPC_MSG_EVT;
394 	}
395 }
396 
397 /**
398  * tipc_link_reset_fragments - purge link's inbound message fragments queue
399  * @l_ptr: pointer to link
400  */
401 void tipc_link_reset_fragments(struct tipc_link *l_ptr)
402 {
403 	kfree_skb(l_ptr->reasm_buf);
404 	l_ptr->reasm_buf = NULL;
405 }
406 
407 static void tipc_link_purge_backlog(struct tipc_link *l)
408 {
409 	__skb_queue_purge(&l->backlogq);
410 	l->backlog[TIPC_LOW_IMPORTANCE].len = 0;
411 	l->backlog[TIPC_MEDIUM_IMPORTANCE].len = 0;
412 	l->backlog[TIPC_HIGH_IMPORTANCE].len = 0;
413 	l->backlog[TIPC_CRITICAL_IMPORTANCE].len = 0;
414 	l->backlog[TIPC_SYSTEM_IMPORTANCE].len = 0;
415 }
416 
417 /**
418  * tipc_link_purge_queues - purge all pkt queues associated with link
419  * @l_ptr: pointer to link
420  */
421 void tipc_link_purge_queues(struct tipc_link *l_ptr)
422 {
423 	__skb_queue_purge(&l_ptr->deferdq);
424 	__skb_queue_purge(&l_ptr->transmq);
425 	tipc_link_purge_backlog(l_ptr);
426 	tipc_link_reset_fragments(l_ptr);
427 }
428 
429 void tipc_link_reset(struct tipc_link *l_ptr)
430 {
431 	u32 prev_state = l_ptr->state;
432 	int was_active_link = tipc_link_is_active(l_ptr);
433 	struct tipc_node *owner = l_ptr->owner;
434 	struct tipc_link *pl = tipc_parallel_link(l_ptr);
435 
436 	msg_set_session(l_ptr->pmsg, ((msg_session(l_ptr->pmsg) + 1) & 0xffff));
437 
438 	/* Link is down, accept any session */
439 	l_ptr->peer_session = INVALID_SESSION;
440 
441 	/* Prepare for renewed mtu size negotiation */
442 	l_ptr->mtu = l_ptr->advertised_mtu;
443 
444 	l_ptr->state = RESET_UNKNOWN;
445 
446 	if ((prev_state == RESET_UNKNOWN) || (prev_state == RESET_RESET))
447 		return;
448 
449 	tipc_node_link_down(l_ptr->owner, l_ptr);
450 	tipc_bearer_remove_dest(owner->net, l_ptr->bearer_id, l_ptr->addr);
451 
452 	if (was_active_link && tipc_node_is_up(l_ptr->owner) && (pl != l_ptr)) {
453 		l_ptr->flags |= LINK_FAILINGOVER;
454 		l_ptr->failover_checkpt = l_ptr->next_in_no;
455 		pl->failover_pkts = FIRST_FAILOVER;
456 		pl->failover_checkpt = l_ptr->next_in_no;
457 		pl->failover_skb = l_ptr->reasm_buf;
458 	} else {
459 		kfree_skb(l_ptr->reasm_buf);
460 	}
461 	/* Clean up all queues, except inputq: */
462 	__skb_queue_purge(&l_ptr->transmq);
463 	__skb_queue_purge(&l_ptr->deferdq);
464 	if (!owner->inputq)
465 		owner->inputq = &l_ptr->inputq;
466 	skb_queue_splice_init(&l_ptr->wakeupq, owner->inputq);
467 	if (!skb_queue_empty(owner->inputq))
468 		owner->action_flags |= TIPC_MSG_EVT;
469 	tipc_link_purge_backlog(l_ptr);
470 	l_ptr->reasm_buf = NULL;
471 	l_ptr->rcv_unacked = 0;
472 	l_ptr->checkpoint = 1;
473 	l_ptr->next_out_no = 1;
474 	l_ptr->fsm_msg_cnt = 0;
475 	l_ptr->stale_count = 0;
476 	link_reset_statistics(l_ptr);
477 }
478 
479 void tipc_link_reset_list(struct net *net, unsigned int bearer_id)
480 {
481 	struct tipc_net *tn = net_generic(net, tipc_net_id);
482 	struct tipc_link *l_ptr;
483 	struct tipc_node *n_ptr;
484 
485 	rcu_read_lock();
486 	list_for_each_entry_rcu(n_ptr, &tn->node_list, list) {
487 		tipc_node_lock(n_ptr);
488 		l_ptr = n_ptr->links[bearer_id];
489 		if (l_ptr)
490 			tipc_link_reset(l_ptr);
491 		tipc_node_unlock(n_ptr);
492 	}
493 	rcu_read_unlock();
494 }
495 
496 static void link_activate(struct tipc_link *link)
497 {
498 	struct tipc_node *node = link->owner;
499 
500 	link->next_in_no = 1;
501 	link->stats.recv_info = 1;
502 	tipc_node_link_up(node, link);
503 	tipc_bearer_add_dest(node->net, link->bearer_id, link->addr);
504 }
505 
506 /**
507  * link_state_event - link finite state machine
508  * @l_ptr: pointer to link
509  * @event: state machine event to process
510  */
511 static void link_state_event(struct tipc_link *l_ptr, unsigned int event)
512 {
513 	struct tipc_link *other;
514 	unsigned long cont_intv = l_ptr->cont_intv;
515 
516 	if (l_ptr->flags & LINK_STOPPED)
517 		return;
518 
519 	if (!(l_ptr->flags & LINK_STARTED) && (event != STARTING_EVT))
520 		return;		/* Not yet. */
521 
522 	if (l_ptr->flags & LINK_FAILINGOVER) {
523 		if (event == TIMEOUT_EVT)
524 			link_set_timer(l_ptr, cont_intv);
525 		return;
526 	}
527 
528 	switch (l_ptr->state) {
529 	case WORKING_WORKING:
530 		switch (event) {
531 		case TRAFFIC_MSG_EVT:
532 		case ACTIVATE_MSG:
533 			break;
534 		case TIMEOUT_EVT:
535 			if (l_ptr->next_in_no != l_ptr->checkpoint) {
536 				l_ptr->checkpoint = l_ptr->next_in_no;
537 				if (tipc_bclink_acks_missing(l_ptr->owner)) {
538 					tipc_link_proto_xmit(l_ptr, STATE_MSG,
539 							     0, 0, 0, 0);
540 					l_ptr->fsm_msg_cnt++;
541 				}
542 				link_set_timer(l_ptr, cont_intv);
543 				break;
544 			}
545 			l_ptr->state = WORKING_UNKNOWN;
546 			l_ptr->fsm_msg_cnt = 0;
547 			tipc_link_proto_xmit(l_ptr, STATE_MSG, 1, 0, 0, 0);
548 			l_ptr->fsm_msg_cnt++;
549 			link_set_timer(l_ptr, cont_intv / 4);
550 			break;
551 		case RESET_MSG:
552 			pr_debug("%s<%s>, requested by peer\n",
553 				 link_rst_msg, l_ptr->name);
554 			tipc_link_reset(l_ptr);
555 			l_ptr->state = RESET_RESET;
556 			l_ptr->fsm_msg_cnt = 0;
557 			tipc_link_proto_xmit(l_ptr, ACTIVATE_MSG,
558 					     0, 0, 0, 0);
559 			l_ptr->fsm_msg_cnt++;
560 			link_set_timer(l_ptr, cont_intv);
561 			break;
562 		default:
563 			pr_debug("%s%u in WW state\n", link_unk_evt, event);
564 		}
565 		break;
566 	case WORKING_UNKNOWN:
567 		switch (event) {
568 		case TRAFFIC_MSG_EVT:
569 		case ACTIVATE_MSG:
570 			l_ptr->state = WORKING_WORKING;
571 			l_ptr->fsm_msg_cnt = 0;
572 			link_set_timer(l_ptr, cont_intv);
573 			break;
574 		case RESET_MSG:
575 			pr_debug("%s<%s>, requested by peer while probing\n",
576 				 link_rst_msg, l_ptr->name);
577 			tipc_link_reset(l_ptr);
578 			l_ptr->state = RESET_RESET;
579 			l_ptr->fsm_msg_cnt = 0;
580 			tipc_link_proto_xmit(l_ptr, ACTIVATE_MSG,
581 					     0, 0, 0, 0);
582 			l_ptr->fsm_msg_cnt++;
583 			link_set_timer(l_ptr, cont_intv);
584 			break;
585 		case TIMEOUT_EVT:
586 			if (l_ptr->next_in_no != l_ptr->checkpoint) {
587 				l_ptr->state = WORKING_WORKING;
588 				l_ptr->fsm_msg_cnt = 0;
589 				l_ptr->checkpoint = l_ptr->next_in_no;
590 				if (tipc_bclink_acks_missing(l_ptr->owner)) {
591 					tipc_link_proto_xmit(l_ptr, STATE_MSG,
592 							     0, 0, 0, 0);
593 					l_ptr->fsm_msg_cnt++;
594 				}
595 				link_set_timer(l_ptr, cont_intv);
596 			} else if (l_ptr->fsm_msg_cnt < l_ptr->abort_limit) {
597 				tipc_link_proto_xmit(l_ptr, STATE_MSG,
598 						     1, 0, 0, 0);
599 				l_ptr->fsm_msg_cnt++;
600 				link_set_timer(l_ptr, cont_intv / 4);
601 			} else {	/* Link has failed */
602 				pr_debug("%s<%s>, peer not responding\n",
603 					 link_rst_msg, l_ptr->name);
604 				tipc_link_reset(l_ptr);
605 				l_ptr->state = RESET_UNKNOWN;
606 				l_ptr->fsm_msg_cnt = 0;
607 				tipc_link_proto_xmit(l_ptr, RESET_MSG,
608 						     0, 0, 0, 0);
609 				l_ptr->fsm_msg_cnt++;
610 				link_set_timer(l_ptr, cont_intv);
611 			}
612 			break;
613 		default:
614 			pr_err("%s%u in WU state\n", link_unk_evt, event);
615 		}
616 		break;
617 	case RESET_UNKNOWN:
618 		switch (event) {
619 		case TRAFFIC_MSG_EVT:
620 			break;
621 		case ACTIVATE_MSG:
622 			other = l_ptr->owner->active_links[0];
623 			if (other && link_working_unknown(other))
624 				break;
625 			l_ptr->state = WORKING_WORKING;
626 			l_ptr->fsm_msg_cnt = 0;
627 			link_activate(l_ptr);
628 			tipc_link_proto_xmit(l_ptr, STATE_MSG, 1, 0, 0, 0);
629 			l_ptr->fsm_msg_cnt++;
630 			if (l_ptr->owner->working_links == 1)
631 				tipc_link_sync_xmit(l_ptr);
632 			link_set_timer(l_ptr, cont_intv);
633 			break;
634 		case RESET_MSG:
635 			l_ptr->state = RESET_RESET;
636 			l_ptr->fsm_msg_cnt = 0;
637 			tipc_link_proto_xmit(l_ptr, ACTIVATE_MSG,
638 					     1, 0, 0, 0);
639 			l_ptr->fsm_msg_cnt++;
640 			link_set_timer(l_ptr, cont_intv);
641 			break;
642 		case STARTING_EVT:
643 			l_ptr->flags |= LINK_STARTED;
644 			l_ptr->fsm_msg_cnt++;
645 			link_set_timer(l_ptr, cont_intv);
646 			break;
647 		case TIMEOUT_EVT:
648 			tipc_link_proto_xmit(l_ptr, RESET_MSG, 0, 0, 0, 0);
649 			l_ptr->fsm_msg_cnt++;
650 			link_set_timer(l_ptr, cont_intv);
651 			break;
652 		default:
653 			pr_err("%s%u in RU state\n", link_unk_evt, event);
654 		}
655 		break;
656 	case RESET_RESET:
657 		switch (event) {
658 		case TRAFFIC_MSG_EVT:
659 		case ACTIVATE_MSG:
660 			other = l_ptr->owner->active_links[0];
661 			if (other && link_working_unknown(other))
662 				break;
663 			l_ptr->state = WORKING_WORKING;
664 			l_ptr->fsm_msg_cnt = 0;
665 			link_activate(l_ptr);
666 			tipc_link_proto_xmit(l_ptr, STATE_MSG, 1, 0, 0, 0);
667 			l_ptr->fsm_msg_cnt++;
668 			if (l_ptr->owner->working_links == 1)
669 				tipc_link_sync_xmit(l_ptr);
670 			link_set_timer(l_ptr, cont_intv);
671 			break;
672 		case RESET_MSG:
673 			break;
674 		case TIMEOUT_EVT:
675 			tipc_link_proto_xmit(l_ptr, ACTIVATE_MSG,
676 					     0, 0, 0, 0);
677 			l_ptr->fsm_msg_cnt++;
678 			link_set_timer(l_ptr, cont_intv);
679 			break;
680 		default:
681 			pr_err("%s%u in RR state\n", link_unk_evt, event);
682 		}
683 		break;
684 	default:
685 		pr_err("Unknown link state %u/%u\n", l_ptr->state, event);
686 	}
687 }
688 
689 /**
690  * __tipc_link_xmit(): same as tipc_link_xmit, but destlink is known & locked
691  * @link: link to use
692  * @list: chain of buffers containing message
693  *
694  * Consumes the buffer chain, except when returning -ELINKCONG,
695  * since the caller then may want to make more send attempts.
696  * Returns 0 if success, or errno: -ELINKCONG, -EMSGSIZE or -ENOBUFS
697  * Messages at TIPC_SYSTEM_IMPORTANCE are always accepted
698  */
699 int __tipc_link_xmit(struct net *net, struct tipc_link *link,
700 		     struct sk_buff_head *list)
701 {
702 	struct tipc_msg *msg = buf_msg(skb_peek(list));
703 	unsigned int maxwin = link->window;
704 	unsigned int imp = msg_importance(msg);
705 	uint mtu = link->mtu;
706 	uint ack = mod(link->next_in_no - 1);
707 	uint seqno = link->next_out_no;
708 	uint bc_last_in = link->owner->bclink.last_in;
709 	struct tipc_media_addr *addr = &link->media_addr;
710 	struct sk_buff_head *transmq = &link->transmq;
711 	struct sk_buff_head *backlogq = &link->backlogq;
712 	struct sk_buff *skb, *tmp;
713 
714 	/* Match backlog limit against msg importance: */
715 	if (unlikely(link->backlog[imp].len >= link->backlog[imp].limit))
716 		return link_schedule_user(link, list);
717 
718 	if (unlikely(msg_size(msg) > mtu)) {
719 		__skb_queue_purge(list);
720 		return -EMSGSIZE;
721 	}
722 	/* Prepare each packet for sending, and add to relevant queue: */
723 	skb_queue_walk_safe(list, skb, tmp) {
724 		__skb_unlink(skb, list);
725 		msg = buf_msg(skb);
726 		msg_set_seqno(msg, seqno);
727 		msg_set_ack(msg, ack);
728 		msg_set_bcast_ack(msg, bc_last_in);
729 
730 		if (likely(skb_queue_len(transmq) < maxwin)) {
731 			__skb_queue_tail(transmq, skb);
732 			tipc_bearer_send(net, link->bearer_id, skb, addr);
733 			link->rcv_unacked = 0;
734 			seqno++;
735 			continue;
736 		}
737 		if (tipc_msg_bundle(skb_peek_tail(backlogq), skb, mtu)) {
738 			link->stats.sent_bundled++;
739 			continue;
740 		}
741 		if (tipc_msg_make_bundle(&skb, mtu, link->addr)) {
742 			link->stats.sent_bundled++;
743 			link->stats.sent_bundles++;
744 			imp = msg_importance(buf_msg(skb));
745 		}
746 		__skb_queue_tail(backlogq, skb);
747 		link->backlog[imp].len++;
748 		seqno++;
749 	}
750 	link->next_out_no = seqno;
751 	return 0;
752 }
753 
754 static void skb2list(struct sk_buff *skb, struct sk_buff_head *list)
755 {
756 	skb_queue_head_init(list);
757 	__skb_queue_tail(list, skb);
758 }
759 
760 static int __tipc_link_xmit_skb(struct tipc_link *link, struct sk_buff *skb)
761 {
762 	struct sk_buff_head head;
763 
764 	skb2list(skb, &head);
765 	return __tipc_link_xmit(link->owner->net, link, &head);
766 }
767 
768 /* tipc_link_xmit_skb(): send single buffer to destination
769  * Buffers sent via this functon are generally TIPC_SYSTEM_IMPORTANCE
770  * messages, which will not be rejected
771  * The only exception is datagram messages rerouted after secondary
772  * lookup, which are rare and safe to dispose of anyway.
773  * TODO: Return real return value, and let callers use
774  * tipc_wait_for_sendpkt() where applicable
775  */
776 int tipc_link_xmit_skb(struct net *net, struct sk_buff *skb, u32 dnode,
777 		       u32 selector)
778 {
779 	struct sk_buff_head head;
780 	int rc;
781 
782 	skb2list(skb, &head);
783 	rc = tipc_link_xmit(net, &head, dnode, selector);
784 	if (rc == -ELINKCONG)
785 		kfree_skb(skb);
786 	return 0;
787 }
788 
789 /**
790  * tipc_link_xmit() is the general link level function for message sending
791  * @net: the applicable net namespace
792  * @list: chain of buffers containing message
793  * @dsz: amount of user data to be sent
794  * @dnode: address of destination node
795  * @selector: a number used for deterministic link selection
796  * Consumes the buffer chain, except when returning -ELINKCONG
797  * Returns 0 if success, otherwise errno: -ELINKCONG,-EHOSTUNREACH,-EMSGSIZE
798  */
799 int tipc_link_xmit(struct net *net, struct sk_buff_head *list, u32 dnode,
800 		   u32 selector)
801 {
802 	struct tipc_link *link = NULL;
803 	struct tipc_node *node;
804 	int rc = -EHOSTUNREACH;
805 
806 	node = tipc_node_find(net, dnode);
807 	if (node) {
808 		tipc_node_lock(node);
809 		link = node->active_links[selector & 1];
810 		if (link)
811 			rc = __tipc_link_xmit(net, link, list);
812 		tipc_node_unlock(node);
813 		tipc_node_put(node);
814 	}
815 	if (link)
816 		return rc;
817 
818 	if (likely(in_own_node(net, dnode))) {
819 		tipc_sk_rcv(net, list);
820 		return 0;
821 	}
822 
823 	__skb_queue_purge(list);
824 	return rc;
825 }
826 
827 /*
828  * tipc_link_sync_xmit - synchronize broadcast link endpoints.
829  *
830  * Give a newly added peer node the sequence number where it should
831  * start receiving and acking broadcast packets.
832  *
833  * Called with node locked
834  */
835 static void tipc_link_sync_xmit(struct tipc_link *link)
836 {
837 	struct sk_buff *skb;
838 	struct tipc_msg *msg;
839 
840 	skb = tipc_buf_acquire(INT_H_SIZE);
841 	if (!skb)
842 		return;
843 
844 	msg = buf_msg(skb);
845 	tipc_msg_init(link_own_addr(link), msg, BCAST_PROTOCOL, STATE_MSG,
846 		      INT_H_SIZE, link->addr);
847 	msg_set_last_bcast(msg, link->owner->bclink.acked);
848 	__tipc_link_xmit_skb(link, skb);
849 }
850 
851 /*
852  * tipc_link_sync_rcv - synchronize broadcast link endpoints.
853  * Receive the sequence number where we should start receiving and
854  * acking broadcast packets from a newly added peer node, and open
855  * up for reception of such packets.
856  *
857  * Called with node locked
858  */
859 static void tipc_link_sync_rcv(struct tipc_node *n, struct sk_buff *buf)
860 {
861 	struct tipc_msg *msg = buf_msg(buf);
862 
863 	n->bclink.last_sent = n->bclink.last_in = msg_last_bcast(msg);
864 	n->bclink.recv_permitted = true;
865 	kfree_skb(buf);
866 }
867 
868 /*
869  * tipc_link_push_packets - push unsent packets to bearer
870  *
871  * Push out the unsent messages of a link where congestion
872  * has abated. Node is locked.
873  *
874  * Called with node locked
875  */
876 void tipc_link_push_packets(struct tipc_link *link)
877 {
878 	struct sk_buff *skb;
879 	struct tipc_msg *msg;
880 	unsigned int ack = mod(link->next_in_no - 1);
881 
882 	while (skb_queue_len(&link->transmq) < link->window) {
883 		skb = __skb_dequeue(&link->backlogq);
884 		if (!skb)
885 			break;
886 		msg = buf_msg(skb);
887 		link->backlog[msg_importance(msg)].len--;
888 		msg_set_ack(msg, ack);
889 		msg_set_bcast_ack(msg, link->owner->bclink.last_in);
890 		link->rcv_unacked = 0;
891 		__skb_queue_tail(&link->transmq, skb);
892 		tipc_bearer_send(link->owner->net, link->bearer_id,
893 				 skb, &link->media_addr);
894 	}
895 }
896 
897 void tipc_link_reset_all(struct tipc_node *node)
898 {
899 	char addr_string[16];
900 	u32 i;
901 
902 	tipc_node_lock(node);
903 
904 	pr_warn("Resetting all links to %s\n",
905 		tipc_addr_string_fill(addr_string, node->addr));
906 
907 	for (i = 0; i < MAX_BEARERS; i++) {
908 		if (node->links[i]) {
909 			link_print(node->links[i], "Resetting link\n");
910 			tipc_link_reset(node->links[i]);
911 		}
912 	}
913 
914 	tipc_node_unlock(node);
915 }
916 
917 static void link_retransmit_failure(struct tipc_link *l_ptr,
918 				    struct sk_buff *buf)
919 {
920 	struct tipc_msg *msg = buf_msg(buf);
921 	struct net *net = l_ptr->owner->net;
922 
923 	pr_warn("Retransmission failure on link <%s>\n", l_ptr->name);
924 
925 	if (l_ptr->addr) {
926 		/* Handle failure on standard link */
927 		link_print(l_ptr, "Resetting link\n");
928 		tipc_link_reset(l_ptr);
929 
930 	} else {
931 		/* Handle failure on broadcast link */
932 		struct tipc_node *n_ptr;
933 		char addr_string[16];
934 
935 		pr_info("Msg seq number: %u,  ", msg_seqno(msg));
936 		pr_cont("Outstanding acks: %lu\n",
937 			(unsigned long) TIPC_SKB_CB(buf)->handle);
938 
939 		n_ptr = tipc_bclink_retransmit_to(net);
940 
941 		tipc_addr_string_fill(addr_string, n_ptr->addr);
942 		pr_info("Broadcast link info for %s\n", addr_string);
943 		pr_info("Reception permitted: %d,  Acked: %u\n",
944 			n_ptr->bclink.recv_permitted,
945 			n_ptr->bclink.acked);
946 		pr_info("Last in: %u,  Oos state: %u,  Last sent: %u\n",
947 			n_ptr->bclink.last_in,
948 			n_ptr->bclink.oos_state,
949 			n_ptr->bclink.last_sent);
950 
951 		n_ptr->action_flags |= TIPC_BCAST_RESET;
952 		l_ptr->stale_count = 0;
953 	}
954 }
955 
956 void tipc_link_retransmit(struct tipc_link *l_ptr, struct sk_buff *skb,
957 			  u32 retransmits)
958 {
959 	struct tipc_msg *msg;
960 
961 	if (!skb)
962 		return;
963 
964 	msg = buf_msg(skb);
965 
966 	/* Detect repeated retransmit failures */
967 	if (l_ptr->last_retransmitted == msg_seqno(msg)) {
968 		if (++l_ptr->stale_count > 100) {
969 			link_retransmit_failure(l_ptr, skb);
970 			return;
971 		}
972 	} else {
973 		l_ptr->last_retransmitted = msg_seqno(msg);
974 		l_ptr->stale_count = 1;
975 	}
976 
977 	skb_queue_walk_from(&l_ptr->transmq, skb) {
978 		if (!retransmits)
979 			break;
980 		msg = buf_msg(skb);
981 		msg_set_ack(msg, mod(l_ptr->next_in_no - 1));
982 		msg_set_bcast_ack(msg, l_ptr->owner->bclink.last_in);
983 		tipc_bearer_send(l_ptr->owner->net, l_ptr->bearer_id, skb,
984 				 &l_ptr->media_addr);
985 		retransmits--;
986 		l_ptr->stats.retransmitted++;
987 	}
988 }
989 
990 /* link_synch(): check if all packets arrived before the synch
991  *               point have been consumed
992  * Returns true if the parallel links are synched, otherwise false
993  */
994 static bool link_synch(struct tipc_link *l)
995 {
996 	unsigned int post_synch;
997 	struct tipc_link *pl;
998 
999 	pl  = tipc_parallel_link(l);
1000 	if (pl == l)
1001 		goto synched;
1002 
1003 	/* Was last pre-synch packet added to input queue ? */
1004 	if (less_eq(pl->next_in_no, l->synch_point))
1005 		return false;
1006 
1007 	/* Is it still in the input queue ? */
1008 	post_synch = mod(pl->next_in_no - l->synch_point) - 1;
1009 	if (skb_queue_len(&pl->inputq) > post_synch)
1010 		return false;
1011 synched:
1012 	l->flags &= ~LINK_SYNCHING;
1013 	return true;
1014 }
1015 
1016 static void link_retrieve_defq(struct tipc_link *link,
1017 			       struct sk_buff_head *list)
1018 {
1019 	u32 seq_no;
1020 
1021 	if (skb_queue_empty(&link->deferdq))
1022 		return;
1023 
1024 	seq_no = buf_seqno(skb_peek(&link->deferdq));
1025 	if (seq_no == mod(link->next_in_no))
1026 		skb_queue_splice_tail_init(&link->deferdq, list);
1027 }
1028 
1029 /**
1030  * tipc_rcv - process TIPC packets/messages arriving from off-node
1031  * @net: the applicable net namespace
1032  * @skb: TIPC packet
1033  * @b_ptr: pointer to bearer message arrived on
1034  *
1035  * Invoked with no locks held.  Bearer pointer must point to a valid bearer
1036  * structure (i.e. cannot be NULL), but bearer can be inactive.
1037  */
1038 void tipc_rcv(struct net *net, struct sk_buff *skb, struct tipc_bearer *b_ptr)
1039 {
1040 	struct tipc_net *tn = net_generic(net, tipc_net_id);
1041 	struct sk_buff_head head;
1042 	struct tipc_node *n_ptr;
1043 	struct tipc_link *l_ptr;
1044 	struct sk_buff *skb1, *tmp;
1045 	struct tipc_msg *msg;
1046 	u32 seq_no;
1047 	u32 ackd;
1048 	u32 released;
1049 
1050 	skb2list(skb, &head);
1051 
1052 	while ((skb = __skb_dequeue(&head))) {
1053 		/* Ensure message is well-formed */
1054 		if (unlikely(!tipc_msg_validate(skb)))
1055 			goto discard;
1056 
1057 		/* Handle arrival of a non-unicast link message */
1058 		msg = buf_msg(skb);
1059 		if (unlikely(msg_non_seq(msg))) {
1060 			if (msg_user(msg) ==  LINK_CONFIG)
1061 				tipc_disc_rcv(net, skb, b_ptr);
1062 			else
1063 				tipc_bclink_rcv(net, skb);
1064 			continue;
1065 		}
1066 
1067 		/* Discard unicast link messages destined for another node */
1068 		if (unlikely(!msg_short(msg) &&
1069 			     (msg_destnode(msg) != tn->own_addr)))
1070 			goto discard;
1071 
1072 		/* Locate neighboring node that sent message */
1073 		n_ptr = tipc_node_find(net, msg_prevnode(msg));
1074 		if (unlikely(!n_ptr))
1075 			goto discard;
1076 
1077 		tipc_node_lock(n_ptr);
1078 		/* Locate unicast link endpoint that should handle message */
1079 		l_ptr = n_ptr->links[b_ptr->identity];
1080 		if (unlikely(!l_ptr))
1081 			goto unlock;
1082 
1083 		/* Verify that communication with node is currently allowed */
1084 		if ((n_ptr->action_flags & TIPC_WAIT_PEER_LINKS_DOWN) &&
1085 		    msg_user(msg) == LINK_PROTOCOL &&
1086 		    (msg_type(msg) == RESET_MSG ||
1087 		    msg_type(msg) == ACTIVATE_MSG) &&
1088 		    !msg_redundant_link(msg))
1089 			n_ptr->action_flags &= ~TIPC_WAIT_PEER_LINKS_DOWN;
1090 
1091 		if (tipc_node_blocked(n_ptr))
1092 			goto unlock;
1093 
1094 		/* Validate message sequence number info */
1095 		seq_no = msg_seqno(msg);
1096 		ackd = msg_ack(msg);
1097 
1098 		/* Release acked messages */
1099 		if (unlikely(n_ptr->bclink.acked != msg_bcast_ack(msg)))
1100 			tipc_bclink_acknowledge(n_ptr, msg_bcast_ack(msg));
1101 
1102 		released = 0;
1103 		skb_queue_walk_safe(&l_ptr->transmq, skb1, tmp) {
1104 			if (more(buf_seqno(skb1), ackd))
1105 				break;
1106 			 __skb_unlink(skb1, &l_ptr->transmq);
1107 			 kfree_skb(skb1);
1108 			 released = 1;
1109 		}
1110 
1111 		/* Try sending any messages link endpoint has pending */
1112 		if (unlikely(skb_queue_len(&l_ptr->backlogq)))
1113 			tipc_link_push_packets(l_ptr);
1114 
1115 		if (released && !skb_queue_empty(&l_ptr->wakeupq))
1116 			link_prepare_wakeup(l_ptr);
1117 
1118 		/* Process the incoming packet */
1119 		if (unlikely(!link_working_working(l_ptr))) {
1120 			if (msg_user(msg) == LINK_PROTOCOL) {
1121 				tipc_link_proto_rcv(l_ptr, skb);
1122 				link_retrieve_defq(l_ptr, &head);
1123 				skb = NULL;
1124 				goto unlock;
1125 			}
1126 
1127 			/* Traffic message. Conditionally activate link */
1128 			link_state_event(l_ptr, TRAFFIC_MSG_EVT);
1129 
1130 			if (link_working_working(l_ptr)) {
1131 				/* Re-insert buffer in front of queue */
1132 				__skb_queue_head(&head, skb);
1133 				skb = NULL;
1134 				goto unlock;
1135 			}
1136 			goto unlock;
1137 		}
1138 
1139 		/* Link is now in state WORKING_WORKING */
1140 		if (unlikely(seq_no != mod(l_ptr->next_in_no))) {
1141 			link_handle_out_of_seq_msg(l_ptr, skb);
1142 			link_retrieve_defq(l_ptr, &head);
1143 			skb = NULL;
1144 			goto unlock;
1145 		}
1146 		/* Synchronize with parallel link if applicable */
1147 		if (unlikely((l_ptr->flags & LINK_SYNCHING) && !msg_dup(msg))) {
1148 			link_handle_out_of_seq_msg(l_ptr, skb);
1149 			if (link_synch(l_ptr))
1150 				link_retrieve_defq(l_ptr, &head);
1151 			skb = NULL;
1152 			goto unlock;
1153 		}
1154 		l_ptr->next_in_no++;
1155 		if (unlikely(!skb_queue_empty(&l_ptr->deferdq)))
1156 			link_retrieve_defq(l_ptr, &head);
1157 		if (unlikely(++l_ptr->rcv_unacked >= TIPC_MIN_LINK_WIN)) {
1158 			l_ptr->stats.sent_acks++;
1159 			tipc_link_proto_xmit(l_ptr, STATE_MSG, 0, 0, 0, 0);
1160 		}
1161 		tipc_link_input(l_ptr, skb);
1162 		skb = NULL;
1163 unlock:
1164 		tipc_node_unlock(n_ptr);
1165 		tipc_node_put(n_ptr);
1166 discard:
1167 		if (unlikely(skb))
1168 			kfree_skb(skb);
1169 	}
1170 }
1171 
1172 /* tipc_data_input - deliver data and name distr msgs to upper layer
1173  *
1174  * Consumes buffer if message is of right type
1175  * Node lock must be held
1176  */
1177 static bool tipc_data_input(struct tipc_link *link, struct sk_buff *skb)
1178 {
1179 	struct tipc_node *node = link->owner;
1180 	struct tipc_msg *msg = buf_msg(skb);
1181 	u32 dport = msg_destport(msg);
1182 
1183 	switch (msg_user(msg)) {
1184 	case TIPC_LOW_IMPORTANCE:
1185 	case TIPC_MEDIUM_IMPORTANCE:
1186 	case TIPC_HIGH_IMPORTANCE:
1187 	case TIPC_CRITICAL_IMPORTANCE:
1188 	case CONN_MANAGER:
1189 		if (tipc_skb_queue_tail(&link->inputq, skb, dport)) {
1190 			node->inputq = &link->inputq;
1191 			node->action_flags |= TIPC_MSG_EVT;
1192 		}
1193 		return true;
1194 	case NAME_DISTRIBUTOR:
1195 		node->bclink.recv_permitted = true;
1196 		node->namedq = &link->namedq;
1197 		skb_queue_tail(&link->namedq, skb);
1198 		if (skb_queue_len(&link->namedq) == 1)
1199 			node->action_flags |= TIPC_NAMED_MSG_EVT;
1200 		return true;
1201 	case MSG_BUNDLER:
1202 	case TUNNEL_PROTOCOL:
1203 	case MSG_FRAGMENTER:
1204 	case BCAST_PROTOCOL:
1205 		return false;
1206 	default:
1207 		pr_warn("Dropping received illegal msg type\n");
1208 		kfree_skb(skb);
1209 		return false;
1210 	};
1211 }
1212 
1213 /* tipc_link_input - process packet that has passed link protocol check
1214  *
1215  * Consumes buffer
1216  * Node lock must be held
1217  */
1218 static void tipc_link_input(struct tipc_link *link, struct sk_buff *skb)
1219 {
1220 	struct tipc_node *node = link->owner;
1221 	struct tipc_msg *msg = buf_msg(skb);
1222 	struct sk_buff *iskb;
1223 	int pos = 0;
1224 
1225 	if (likely(tipc_data_input(link, skb)))
1226 		return;
1227 
1228 	switch (msg_user(msg)) {
1229 	case TUNNEL_PROTOCOL:
1230 		if (msg_dup(msg)) {
1231 			link->flags |= LINK_SYNCHING;
1232 			link->synch_point = msg_seqno(msg_get_wrapped(msg));
1233 			kfree_skb(skb);
1234 			break;
1235 		}
1236 		if (!tipc_link_failover_rcv(link, &skb))
1237 			break;
1238 		if (msg_user(buf_msg(skb)) != MSG_BUNDLER) {
1239 			tipc_data_input(link, skb);
1240 			break;
1241 		}
1242 	case MSG_BUNDLER:
1243 		link->stats.recv_bundles++;
1244 		link->stats.recv_bundled += msg_msgcnt(msg);
1245 
1246 		while (tipc_msg_extract(skb, &iskb, &pos))
1247 			tipc_data_input(link, iskb);
1248 		break;
1249 	case MSG_FRAGMENTER:
1250 		link->stats.recv_fragments++;
1251 		if (tipc_buf_append(&link->reasm_buf, &skb)) {
1252 			link->stats.recv_fragmented++;
1253 			tipc_data_input(link, skb);
1254 		} else if (!link->reasm_buf) {
1255 			tipc_link_reset(link);
1256 		}
1257 		break;
1258 	case BCAST_PROTOCOL:
1259 		tipc_link_sync_rcv(node, skb);
1260 		break;
1261 	default:
1262 		break;
1263 	};
1264 }
1265 
1266 /**
1267  * tipc_link_defer_pkt - Add out-of-sequence message to deferred reception queue
1268  *
1269  * Returns increase in queue length (i.e. 0 or 1)
1270  */
1271 u32 tipc_link_defer_pkt(struct sk_buff_head *list, struct sk_buff *skb)
1272 {
1273 	struct sk_buff *skb1;
1274 	u32 seq_no = buf_seqno(skb);
1275 
1276 	/* Empty queue ? */
1277 	if (skb_queue_empty(list)) {
1278 		__skb_queue_tail(list, skb);
1279 		return 1;
1280 	}
1281 
1282 	/* Last ? */
1283 	if (less(buf_seqno(skb_peek_tail(list)), seq_no)) {
1284 		__skb_queue_tail(list, skb);
1285 		return 1;
1286 	}
1287 
1288 	/* Locate insertion point in queue, then insert; discard if duplicate */
1289 	skb_queue_walk(list, skb1) {
1290 		u32 curr_seqno = buf_seqno(skb1);
1291 
1292 		if (seq_no == curr_seqno) {
1293 			kfree_skb(skb);
1294 			return 0;
1295 		}
1296 
1297 		if (less(seq_no, curr_seqno))
1298 			break;
1299 	}
1300 
1301 	__skb_queue_before(list, skb1, skb);
1302 	return 1;
1303 }
1304 
1305 /*
1306  * link_handle_out_of_seq_msg - handle arrival of out-of-sequence packet
1307  */
1308 static void link_handle_out_of_seq_msg(struct tipc_link *l_ptr,
1309 				       struct sk_buff *buf)
1310 {
1311 	u32 seq_no = buf_seqno(buf);
1312 
1313 	if (likely(msg_user(buf_msg(buf)) == LINK_PROTOCOL)) {
1314 		tipc_link_proto_rcv(l_ptr, buf);
1315 		return;
1316 	}
1317 
1318 	/* Record OOS packet arrival (force mismatch on next timeout) */
1319 	l_ptr->checkpoint--;
1320 
1321 	/*
1322 	 * Discard packet if a duplicate; otherwise add it to deferred queue
1323 	 * and notify peer of gap as per protocol specification
1324 	 */
1325 	if (less(seq_no, mod(l_ptr->next_in_no))) {
1326 		l_ptr->stats.duplicates++;
1327 		kfree_skb(buf);
1328 		return;
1329 	}
1330 
1331 	if (tipc_link_defer_pkt(&l_ptr->deferdq, buf)) {
1332 		l_ptr->stats.deferred_recv++;
1333 		if ((skb_queue_len(&l_ptr->deferdq) % TIPC_MIN_LINK_WIN) == 1)
1334 			tipc_link_proto_xmit(l_ptr, STATE_MSG, 0, 0, 0, 0);
1335 	} else {
1336 		l_ptr->stats.duplicates++;
1337 	}
1338 }
1339 
1340 /*
1341  * Send protocol message to the other endpoint.
1342  */
1343 void tipc_link_proto_xmit(struct tipc_link *l_ptr, u32 msg_typ, int probe_msg,
1344 			  u32 gap, u32 tolerance, u32 priority)
1345 {
1346 	struct sk_buff *buf = NULL;
1347 	struct tipc_msg *msg = l_ptr->pmsg;
1348 	u32 msg_size = sizeof(l_ptr->proto_msg);
1349 	int r_flag;
1350 
1351 	/* Don't send protocol message during link failover */
1352 	if (l_ptr->flags & LINK_FAILINGOVER)
1353 		return;
1354 
1355 	/* Abort non-RESET send if communication with node is prohibited */
1356 	if ((tipc_node_blocked(l_ptr->owner)) && (msg_typ != RESET_MSG))
1357 		return;
1358 
1359 	/* Create protocol message with "out-of-sequence" sequence number */
1360 	msg_set_type(msg, msg_typ);
1361 	msg_set_net_plane(msg, l_ptr->net_plane);
1362 	msg_set_bcast_ack(msg, l_ptr->owner->bclink.last_in);
1363 	msg_set_last_bcast(msg, tipc_bclink_get_last_sent(l_ptr->owner->net));
1364 
1365 	if (msg_typ == STATE_MSG) {
1366 		u32 next_sent = mod(l_ptr->next_out_no);
1367 
1368 		if (!tipc_link_is_up(l_ptr))
1369 			return;
1370 		if (skb_queue_len(&l_ptr->backlogq))
1371 			next_sent = buf_seqno(skb_peek(&l_ptr->backlogq));
1372 		msg_set_next_sent(msg, next_sent);
1373 		if (!skb_queue_empty(&l_ptr->deferdq)) {
1374 			u32 rec = buf_seqno(skb_peek(&l_ptr->deferdq));
1375 			gap = mod(rec - mod(l_ptr->next_in_no));
1376 		}
1377 		msg_set_seq_gap(msg, gap);
1378 		if (gap)
1379 			l_ptr->stats.sent_nacks++;
1380 		msg_set_link_tolerance(msg, tolerance);
1381 		msg_set_linkprio(msg, priority);
1382 		msg_set_max_pkt(msg, l_ptr->mtu);
1383 		msg_set_ack(msg, mod(l_ptr->next_in_no - 1));
1384 		msg_set_probe(msg, probe_msg != 0);
1385 		if (probe_msg)
1386 			l_ptr->stats.sent_probes++;
1387 		l_ptr->stats.sent_states++;
1388 	} else {		/* RESET_MSG or ACTIVATE_MSG */
1389 		msg_set_ack(msg, mod(l_ptr->failover_checkpt - 1));
1390 		msg_set_seq_gap(msg, 0);
1391 		msg_set_next_sent(msg, 1);
1392 		msg_set_probe(msg, 0);
1393 		msg_set_link_tolerance(msg, l_ptr->tolerance);
1394 		msg_set_linkprio(msg, l_ptr->priority);
1395 		msg_set_max_pkt(msg, l_ptr->advertised_mtu);
1396 	}
1397 
1398 	r_flag = (l_ptr->owner->working_links > tipc_link_is_up(l_ptr));
1399 	msg_set_redundant_link(msg, r_flag);
1400 	msg_set_linkprio(msg, l_ptr->priority);
1401 	msg_set_size(msg, msg_size);
1402 
1403 	msg_set_seqno(msg, mod(l_ptr->next_out_no + (0xffff/2)));
1404 
1405 	buf = tipc_buf_acquire(msg_size);
1406 	if (!buf)
1407 		return;
1408 
1409 	skb_copy_to_linear_data(buf, msg, sizeof(l_ptr->proto_msg));
1410 	buf->priority = TC_PRIO_CONTROL;
1411 	tipc_bearer_send(l_ptr->owner->net, l_ptr->bearer_id, buf,
1412 			 &l_ptr->media_addr);
1413 	l_ptr->rcv_unacked = 0;
1414 	kfree_skb(buf);
1415 }
1416 
1417 /*
1418  * Receive protocol message :
1419  * Note that network plane id propagates through the network, and may
1420  * change at any time. The node with lowest address rules
1421  */
1422 static void tipc_link_proto_rcv(struct tipc_link *l_ptr,
1423 				struct sk_buff *buf)
1424 {
1425 	u32 rec_gap = 0;
1426 	u32 msg_tol;
1427 	struct tipc_msg *msg = buf_msg(buf);
1428 
1429 	if (l_ptr->flags & LINK_FAILINGOVER)
1430 		goto exit;
1431 
1432 	if (l_ptr->net_plane != msg_net_plane(msg))
1433 		if (link_own_addr(l_ptr) > msg_prevnode(msg))
1434 			l_ptr->net_plane = msg_net_plane(msg);
1435 
1436 	switch (msg_type(msg)) {
1437 
1438 	case RESET_MSG:
1439 		if (!link_working_unknown(l_ptr) &&
1440 		    (l_ptr->peer_session != INVALID_SESSION)) {
1441 			if (less_eq(msg_session(msg), l_ptr->peer_session))
1442 				break; /* duplicate or old reset: ignore */
1443 		}
1444 
1445 		if (!msg_redundant_link(msg) && (link_working_working(l_ptr) ||
1446 				link_working_unknown(l_ptr))) {
1447 			/*
1448 			 * peer has lost contact -- don't allow peer's links
1449 			 * to reactivate before we recognize loss & clean up
1450 			 */
1451 			l_ptr->owner->action_flags |= TIPC_WAIT_OWN_LINKS_DOWN;
1452 		}
1453 
1454 		link_state_event(l_ptr, RESET_MSG);
1455 
1456 		/* fall thru' */
1457 	case ACTIVATE_MSG:
1458 		/* Update link settings according other endpoint's values */
1459 		strcpy((strrchr(l_ptr->name, ':') + 1), (char *)msg_data(msg));
1460 
1461 		msg_tol = msg_link_tolerance(msg);
1462 		if (msg_tol > l_ptr->tolerance)
1463 			link_set_supervision_props(l_ptr, msg_tol);
1464 
1465 		if (msg_linkprio(msg) > l_ptr->priority)
1466 			l_ptr->priority = msg_linkprio(msg);
1467 
1468 		if (l_ptr->mtu > msg_max_pkt(msg))
1469 			l_ptr->mtu = msg_max_pkt(msg);
1470 
1471 		/* Synchronize broadcast link info, if not done previously */
1472 		if (!tipc_node_is_up(l_ptr->owner)) {
1473 			l_ptr->owner->bclink.last_sent =
1474 				l_ptr->owner->bclink.last_in =
1475 				msg_last_bcast(msg);
1476 			l_ptr->owner->bclink.oos_state = 0;
1477 		}
1478 
1479 		l_ptr->peer_session = msg_session(msg);
1480 		l_ptr->peer_bearer_id = msg_bearer_id(msg);
1481 
1482 		if (msg_type(msg) == ACTIVATE_MSG)
1483 			link_state_event(l_ptr, ACTIVATE_MSG);
1484 		break;
1485 	case STATE_MSG:
1486 
1487 		msg_tol = msg_link_tolerance(msg);
1488 		if (msg_tol)
1489 			link_set_supervision_props(l_ptr, msg_tol);
1490 
1491 		if (msg_linkprio(msg) &&
1492 		    (msg_linkprio(msg) != l_ptr->priority)) {
1493 			pr_debug("%s<%s>, priority change %u->%u\n",
1494 				 link_rst_msg, l_ptr->name,
1495 				 l_ptr->priority, msg_linkprio(msg));
1496 			l_ptr->priority = msg_linkprio(msg);
1497 			tipc_link_reset(l_ptr); /* Enforce change to take effect */
1498 			break;
1499 		}
1500 
1501 		/* Record reception; force mismatch at next timeout: */
1502 		l_ptr->checkpoint--;
1503 
1504 		link_state_event(l_ptr, TRAFFIC_MSG_EVT);
1505 		l_ptr->stats.recv_states++;
1506 		if (link_reset_unknown(l_ptr))
1507 			break;
1508 
1509 		if (less_eq(mod(l_ptr->next_in_no), msg_next_sent(msg))) {
1510 			rec_gap = mod(msg_next_sent(msg) -
1511 				      mod(l_ptr->next_in_no));
1512 		}
1513 
1514 		if (msg_probe(msg))
1515 			l_ptr->stats.recv_probes++;
1516 
1517 		/* Protocol message before retransmits, reduce loss risk */
1518 		if (l_ptr->owner->bclink.recv_permitted)
1519 			tipc_bclink_update_link_state(l_ptr->owner,
1520 						      msg_last_bcast(msg));
1521 
1522 		if (rec_gap || (msg_probe(msg))) {
1523 			tipc_link_proto_xmit(l_ptr, STATE_MSG, 0,
1524 					     rec_gap, 0, 0);
1525 		}
1526 		if (msg_seq_gap(msg)) {
1527 			l_ptr->stats.recv_nacks++;
1528 			tipc_link_retransmit(l_ptr, skb_peek(&l_ptr->transmq),
1529 					     msg_seq_gap(msg));
1530 		}
1531 		break;
1532 	}
1533 exit:
1534 	kfree_skb(buf);
1535 }
1536 
1537 
1538 /* tipc_link_tunnel_xmit(): Tunnel one packet via a link belonging to
1539  * a different bearer. Owner node is locked.
1540  */
1541 static void tipc_link_tunnel_xmit(struct tipc_link *l_ptr,
1542 				  struct tipc_msg *tunnel_hdr,
1543 				  struct tipc_msg *msg,
1544 				  u32 selector)
1545 {
1546 	struct tipc_link *tunnel;
1547 	struct sk_buff *skb;
1548 	u32 length = msg_size(msg);
1549 
1550 	tunnel = l_ptr->owner->active_links[selector & 1];
1551 	if (!tipc_link_is_up(tunnel)) {
1552 		pr_warn("%stunnel link no longer available\n", link_co_err);
1553 		return;
1554 	}
1555 	msg_set_size(tunnel_hdr, length + INT_H_SIZE);
1556 	skb = tipc_buf_acquire(length + INT_H_SIZE);
1557 	if (!skb) {
1558 		pr_warn("%sunable to send tunnel msg\n", link_co_err);
1559 		return;
1560 	}
1561 	skb_copy_to_linear_data(skb, tunnel_hdr, INT_H_SIZE);
1562 	skb_copy_to_linear_data_offset(skb, INT_H_SIZE, msg, length);
1563 	__tipc_link_xmit_skb(tunnel, skb);
1564 }
1565 
1566 
1567 /* tipc_link_failover_send_queue(): A link has gone down, but a second
1568  * link is still active. We can do failover. Tunnel the failing link's
1569  * whole send queue via the remaining link. This way, we don't lose
1570  * any packets, and sequence order is preserved for subsequent traffic
1571  * sent over the remaining link. Owner node is locked.
1572  */
1573 void tipc_link_failover_send_queue(struct tipc_link *l_ptr)
1574 {
1575 	int msgcount;
1576 	struct tipc_link *tunnel = l_ptr->owner->active_links[0];
1577 	struct tipc_msg tunnel_hdr;
1578 	struct sk_buff *skb;
1579 	int split_bundles;
1580 
1581 	if (!tunnel)
1582 		return;
1583 
1584 	tipc_msg_init(link_own_addr(l_ptr), &tunnel_hdr, TUNNEL_PROTOCOL,
1585 		      FAILOVER_MSG, INT_H_SIZE, l_ptr->addr);
1586 	skb_queue_splice_tail_init(&l_ptr->backlogq, &l_ptr->transmq);
1587 	tipc_link_purge_backlog(l_ptr);
1588 	msgcount = skb_queue_len(&l_ptr->transmq);
1589 	msg_set_bearer_id(&tunnel_hdr, l_ptr->peer_bearer_id);
1590 	msg_set_msgcnt(&tunnel_hdr, msgcount);
1591 
1592 	if (skb_queue_empty(&l_ptr->transmq)) {
1593 		skb = tipc_buf_acquire(INT_H_SIZE);
1594 		if (skb) {
1595 			skb_copy_to_linear_data(skb, &tunnel_hdr, INT_H_SIZE);
1596 			msg_set_size(&tunnel_hdr, INT_H_SIZE);
1597 			__tipc_link_xmit_skb(tunnel, skb);
1598 		} else {
1599 			pr_warn("%sunable to send changeover msg\n",
1600 				link_co_err);
1601 		}
1602 		return;
1603 	}
1604 
1605 	split_bundles = (l_ptr->owner->active_links[0] !=
1606 			 l_ptr->owner->active_links[1]);
1607 
1608 	skb_queue_walk(&l_ptr->transmq, skb) {
1609 		struct tipc_msg *msg = buf_msg(skb);
1610 
1611 		if ((msg_user(msg) == MSG_BUNDLER) && split_bundles) {
1612 			struct tipc_msg *m = msg_get_wrapped(msg);
1613 			unchar *pos = (unchar *)m;
1614 
1615 			msgcount = msg_msgcnt(msg);
1616 			while (msgcount--) {
1617 				msg_set_seqno(m, msg_seqno(msg));
1618 				tipc_link_tunnel_xmit(l_ptr, &tunnel_hdr, m,
1619 						      msg_link_selector(m));
1620 				pos += align(msg_size(m));
1621 				m = (struct tipc_msg *)pos;
1622 			}
1623 		} else {
1624 			tipc_link_tunnel_xmit(l_ptr, &tunnel_hdr, msg,
1625 					      msg_link_selector(msg));
1626 		}
1627 	}
1628 }
1629 
1630 /* tipc_link_dup_queue_xmit(): A second link has become active. Tunnel a
1631  * duplicate of the first link's send queue via the new link. This way, we
1632  * are guaranteed that currently queued packets from a socket are delivered
1633  * before future traffic from the same socket, even if this is using the
1634  * new link. The last arriving copy of each duplicate packet is dropped at
1635  * the receiving end by the regular protocol check, so packet cardinality
1636  * and sequence order is preserved per sender/receiver socket pair.
1637  * Owner node is locked.
1638  */
1639 void tipc_link_dup_queue_xmit(struct tipc_link *link,
1640 			      struct tipc_link *tnl)
1641 {
1642 	struct sk_buff *skb;
1643 	struct tipc_msg tnl_hdr;
1644 	struct sk_buff_head *queue = &link->transmq;
1645 	int mcnt;
1646 
1647 	tipc_msg_init(link_own_addr(link), &tnl_hdr, TUNNEL_PROTOCOL,
1648 		      SYNCH_MSG, INT_H_SIZE, link->addr);
1649 	mcnt = skb_queue_len(&link->transmq) + skb_queue_len(&link->backlogq);
1650 	msg_set_msgcnt(&tnl_hdr, mcnt);
1651 	msg_set_bearer_id(&tnl_hdr, link->peer_bearer_id);
1652 
1653 tunnel_queue:
1654 	skb_queue_walk(queue, skb) {
1655 		struct sk_buff *outskb;
1656 		struct tipc_msg *msg = buf_msg(skb);
1657 		u32 len = msg_size(msg);
1658 
1659 		msg_set_ack(msg, mod(link->next_in_no - 1));
1660 		msg_set_bcast_ack(msg, link->owner->bclink.last_in);
1661 		msg_set_size(&tnl_hdr, len + INT_H_SIZE);
1662 		outskb = tipc_buf_acquire(len + INT_H_SIZE);
1663 		if (outskb == NULL) {
1664 			pr_warn("%sunable to send duplicate msg\n",
1665 				link_co_err);
1666 			return;
1667 		}
1668 		skb_copy_to_linear_data(outskb, &tnl_hdr, INT_H_SIZE);
1669 		skb_copy_to_linear_data_offset(outskb, INT_H_SIZE,
1670 					       skb->data, len);
1671 		__tipc_link_xmit_skb(tnl, outskb);
1672 		if (!tipc_link_is_up(link))
1673 			return;
1674 	}
1675 	if (queue == &link->backlogq)
1676 		return;
1677 	queue = &link->backlogq;
1678 	goto tunnel_queue;
1679 }
1680 
1681 /*  tipc_link_failover_rcv(): Receive a tunnelled FAILOVER_MSG packet
1682  *  Owner node is locked.
1683  */
1684 static bool tipc_link_failover_rcv(struct tipc_link *link,
1685 				   struct sk_buff **skb)
1686 {
1687 	struct tipc_msg *msg = buf_msg(*skb);
1688 	struct sk_buff *iskb = NULL;
1689 	struct tipc_link *pl = NULL;
1690 	int bearer_id = msg_bearer_id(msg);
1691 	int pos = 0;
1692 
1693 	if (msg_type(msg) != FAILOVER_MSG) {
1694 		pr_warn("%sunknown tunnel pkt received\n", link_co_err);
1695 		goto exit;
1696 	}
1697 	if (bearer_id >= MAX_BEARERS)
1698 		goto exit;
1699 
1700 	if (bearer_id == link->bearer_id)
1701 		goto exit;
1702 
1703 	pl = link->owner->links[bearer_id];
1704 	if (pl && tipc_link_is_up(pl))
1705 		tipc_link_reset(pl);
1706 
1707 	if (link->failover_pkts == FIRST_FAILOVER)
1708 		link->failover_pkts = msg_msgcnt(msg);
1709 
1710 	/* Should we expect an inner packet? */
1711 	if (!link->failover_pkts)
1712 		goto exit;
1713 
1714 	if (!tipc_msg_extract(*skb, &iskb, &pos)) {
1715 		pr_warn("%sno inner failover pkt\n", link_co_err);
1716 		*skb = NULL;
1717 		goto exit;
1718 	}
1719 	link->failover_pkts--;
1720 	*skb = NULL;
1721 
1722 	/* Was this packet already delivered? */
1723 	if (less(buf_seqno(iskb), link->failover_checkpt)) {
1724 		kfree_skb(iskb);
1725 		iskb = NULL;
1726 		goto exit;
1727 	}
1728 	if (msg_user(buf_msg(iskb)) == MSG_FRAGMENTER) {
1729 		link->stats.recv_fragments++;
1730 		tipc_buf_append(&link->failover_skb, &iskb);
1731 	}
1732 exit:
1733 	if (!link->failover_pkts && pl)
1734 		pl->flags &= ~LINK_FAILINGOVER;
1735 	kfree_skb(*skb);
1736 	*skb = iskb;
1737 	return *skb;
1738 }
1739 
1740 static void link_set_supervision_props(struct tipc_link *l_ptr, u32 tol)
1741 {
1742 	unsigned long intv = ((tol / 4) > 500) ? 500 : tol / 4;
1743 
1744 	if ((tol < TIPC_MIN_LINK_TOL) || (tol > TIPC_MAX_LINK_TOL))
1745 		return;
1746 
1747 	l_ptr->tolerance = tol;
1748 	l_ptr->cont_intv = msecs_to_jiffies(intv);
1749 	l_ptr->abort_limit = tol / (jiffies_to_msecs(l_ptr->cont_intv) / 4);
1750 }
1751 
1752 void tipc_link_set_queue_limits(struct tipc_link *l, u32 win)
1753 {
1754 	int max_bulk = TIPC_MAX_PUBLICATIONS / (l->mtu / ITEM_SIZE);
1755 
1756 	l->window = win;
1757 	l->backlog[TIPC_LOW_IMPORTANCE].limit      = win / 2;
1758 	l->backlog[TIPC_MEDIUM_IMPORTANCE].limit   = win;
1759 	l->backlog[TIPC_HIGH_IMPORTANCE].limit     = win / 2 * 3;
1760 	l->backlog[TIPC_CRITICAL_IMPORTANCE].limit = win * 2;
1761 	l->backlog[TIPC_SYSTEM_IMPORTANCE].limit   = max_bulk;
1762 }
1763 
1764 /* tipc_link_find_owner - locate owner node of link by link's name
1765  * @net: the applicable net namespace
1766  * @name: pointer to link name string
1767  * @bearer_id: pointer to index in 'node->links' array where the link was found.
1768  *
1769  * Returns pointer to node owning the link, or 0 if no matching link is found.
1770  */
1771 static struct tipc_node *tipc_link_find_owner(struct net *net,
1772 					      const char *link_name,
1773 					      unsigned int *bearer_id)
1774 {
1775 	struct tipc_net *tn = net_generic(net, tipc_net_id);
1776 	struct tipc_link *l_ptr;
1777 	struct tipc_node *n_ptr;
1778 	struct tipc_node *found_node = NULL;
1779 	int i;
1780 
1781 	*bearer_id = 0;
1782 	rcu_read_lock();
1783 	list_for_each_entry_rcu(n_ptr, &tn->node_list, list) {
1784 		tipc_node_lock(n_ptr);
1785 		for (i = 0; i < MAX_BEARERS; i++) {
1786 			l_ptr = n_ptr->links[i];
1787 			if (l_ptr && !strcmp(l_ptr->name, link_name)) {
1788 				*bearer_id = i;
1789 				found_node = n_ptr;
1790 				break;
1791 			}
1792 		}
1793 		tipc_node_unlock(n_ptr);
1794 		if (found_node)
1795 			break;
1796 	}
1797 	rcu_read_unlock();
1798 
1799 	return found_node;
1800 }
1801 
1802 /**
1803  * link_reset_statistics - reset link statistics
1804  * @l_ptr: pointer to link
1805  */
1806 static void link_reset_statistics(struct tipc_link *l_ptr)
1807 {
1808 	memset(&l_ptr->stats, 0, sizeof(l_ptr->stats));
1809 	l_ptr->stats.sent_info = l_ptr->next_out_no;
1810 	l_ptr->stats.recv_info = l_ptr->next_in_no;
1811 }
1812 
1813 static void link_print(struct tipc_link *l_ptr, const char *str)
1814 {
1815 	struct tipc_net *tn = net_generic(l_ptr->owner->net, tipc_net_id);
1816 	struct tipc_bearer *b_ptr;
1817 
1818 	rcu_read_lock();
1819 	b_ptr = rcu_dereference_rtnl(tn->bearer_list[l_ptr->bearer_id]);
1820 	if (b_ptr)
1821 		pr_info("%s Link %x<%s>:", str, l_ptr->addr, b_ptr->name);
1822 	rcu_read_unlock();
1823 
1824 	if (link_working_unknown(l_ptr))
1825 		pr_cont(":WU\n");
1826 	else if (link_reset_reset(l_ptr))
1827 		pr_cont(":RR\n");
1828 	else if (link_reset_unknown(l_ptr))
1829 		pr_cont(":RU\n");
1830 	else if (link_working_working(l_ptr))
1831 		pr_cont(":WW\n");
1832 	else
1833 		pr_cont("\n");
1834 }
1835 
1836 /* Parse and validate nested (link) properties valid for media, bearer and link
1837  */
1838 int tipc_nl_parse_link_prop(struct nlattr *prop, struct nlattr *props[])
1839 {
1840 	int err;
1841 
1842 	err = nla_parse_nested(props, TIPC_NLA_PROP_MAX, prop,
1843 			       tipc_nl_prop_policy);
1844 	if (err)
1845 		return err;
1846 
1847 	if (props[TIPC_NLA_PROP_PRIO]) {
1848 		u32 prio;
1849 
1850 		prio = nla_get_u32(props[TIPC_NLA_PROP_PRIO]);
1851 		if (prio > TIPC_MAX_LINK_PRI)
1852 			return -EINVAL;
1853 	}
1854 
1855 	if (props[TIPC_NLA_PROP_TOL]) {
1856 		u32 tol;
1857 
1858 		tol = nla_get_u32(props[TIPC_NLA_PROP_TOL]);
1859 		if ((tol < TIPC_MIN_LINK_TOL) || (tol > TIPC_MAX_LINK_TOL))
1860 			return -EINVAL;
1861 	}
1862 
1863 	if (props[TIPC_NLA_PROP_WIN]) {
1864 		u32 win;
1865 
1866 		win = nla_get_u32(props[TIPC_NLA_PROP_WIN]);
1867 		if ((win < TIPC_MIN_LINK_WIN) || (win > TIPC_MAX_LINK_WIN))
1868 			return -EINVAL;
1869 	}
1870 
1871 	return 0;
1872 }
1873 
1874 int tipc_nl_link_set(struct sk_buff *skb, struct genl_info *info)
1875 {
1876 	int err;
1877 	int res = 0;
1878 	int bearer_id;
1879 	char *name;
1880 	struct tipc_link *link;
1881 	struct tipc_node *node;
1882 	struct nlattr *attrs[TIPC_NLA_LINK_MAX + 1];
1883 	struct net *net = sock_net(skb->sk);
1884 
1885 	if (!info->attrs[TIPC_NLA_LINK])
1886 		return -EINVAL;
1887 
1888 	err = nla_parse_nested(attrs, TIPC_NLA_LINK_MAX,
1889 			       info->attrs[TIPC_NLA_LINK],
1890 			       tipc_nl_link_policy);
1891 	if (err)
1892 		return err;
1893 
1894 	if (!attrs[TIPC_NLA_LINK_NAME])
1895 		return -EINVAL;
1896 
1897 	name = nla_data(attrs[TIPC_NLA_LINK_NAME]);
1898 
1899 	node = tipc_link_find_owner(net, name, &bearer_id);
1900 	if (!node)
1901 		return -EINVAL;
1902 
1903 	tipc_node_lock(node);
1904 
1905 	link = node->links[bearer_id];
1906 	if (!link) {
1907 		res = -EINVAL;
1908 		goto out;
1909 	}
1910 
1911 	if (attrs[TIPC_NLA_LINK_PROP]) {
1912 		struct nlattr *props[TIPC_NLA_PROP_MAX + 1];
1913 
1914 		err = tipc_nl_parse_link_prop(attrs[TIPC_NLA_LINK_PROP],
1915 					      props);
1916 		if (err) {
1917 			res = err;
1918 			goto out;
1919 		}
1920 
1921 		if (props[TIPC_NLA_PROP_TOL]) {
1922 			u32 tol;
1923 
1924 			tol = nla_get_u32(props[TIPC_NLA_PROP_TOL]);
1925 			link_set_supervision_props(link, tol);
1926 			tipc_link_proto_xmit(link, STATE_MSG, 0, 0, tol, 0);
1927 		}
1928 		if (props[TIPC_NLA_PROP_PRIO]) {
1929 			u32 prio;
1930 
1931 			prio = nla_get_u32(props[TIPC_NLA_PROP_PRIO]);
1932 			link->priority = prio;
1933 			tipc_link_proto_xmit(link, STATE_MSG, 0, 0, 0, prio);
1934 		}
1935 		if (props[TIPC_NLA_PROP_WIN]) {
1936 			u32 win;
1937 
1938 			win = nla_get_u32(props[TIPC_NLA_PROP_WIN]);
1939 			tipc_link_set_queue_limits(link, win);
1940 		}
1941 	}
1942 
1943 out:
1944 	tipc_node_unlock(node);
1945 
1946 	return res;
1947 }
1948 
1949 static int __tipc_nl_add_stats(struct sk_buff *skb, struct tipc_stats *s)
1950 {
1951 	int i;
1952 	struct nlattr *stats;
1953 
1954 	struct nla_map {
1955 		u32 key;
1956 		u32 val;
1957 	};
1958 
1959 	struct nla_map map[] = {
1960 		{TIPC_NLA_STATS_RX_INFO, s->recv_info},
1961 		{TIPC_NLA_STATS_RX_FRAGMENTS, s->recv_fragments},
1962 		{TIPC_NLA_STATS_RX_FRAGMENTED, s->recv_fragmented},
1963 		{TIPC_NLA_STATS_RX_BUNDLES, s->recv_bundles},
1964 		{TIPC_NLA_STATS_RX_BUNDLED, s->recv_bundled},
1965 		{TIPC_NLA_STATS_TX_INFO, s->sent_info},
1966 		{TIPC_NLA_STATS_TX_FRAGMENTS, s->sent_fragments},
1967 		{TIPC_NLA_STATS_TX_FRAGMENTED, s->sent_fragmented},
1968 		{TIPC_NLA_STATS_TX_BUNDLES, s->sent_bundles},
1969 		{TIPC_NLA_STATS_TX_BUNDLED, s->sent_bundled},
1970 		{TIPC_NLA_STATS_MSG_PROF_TOT, (s->msg_length_counts) ?
1971 			s->msg_length_counts : 1},
1972 		{TIPC_NLA_STATS_MSG_LEN_CNT, s->msg_length_counts},
1973 		{TIPC_NLA_STATS_MSG_LEN_TOT, s->msg_lengths_total},
1974 		{TIPC_NLA_STATS_MSG_LEN_P0, s->msg_length_profile[0]},
1975 		{TIPC_NLA_STATS_MSG_LEN_P1, s->msg_length_profile[1]},
1976 		{TIPC_NLA_STATS_MSG_LEN_P2, s->msg_length_profile[2]},
1977 		{TIPC_NLA_STATS_MSG_LEN_P3, s->msg_length_profile[3]},
1978 		{TIPC_NLA_STATS_MSG_LEN_P4, s->msg_length_profile[4]},
1979 		{TIPC_NLA_STATS_MSG_LEN_P5, s->msg_length_profile[5]},
1980 		{TIPC_NLA_STATS_MSG_LEN_P6, s->msg_length_profile[6]},
1981 		{TIPC_NLA_STATS_RX_STATES, s->recv_states},
1982 		{TIPC_NLA_STATS_RX_PROBES, s->recv_probes},
1983 		{TIPC_NLA_STATS_RX_NACKS, s->recv_nacks},
1984 		{TIPC_NLA_STATS_RX_DEFERRED, s->deferred_recv},
1985 		{TIPC_NLA_STATS_TX_STATES, s->sent_states},
1986 		{TIPC_NLA_STATS_TX_PROBES, s->sent_probes},
1987 		{TIPC_NLA_STATS_TX_NACKS, s->sent_nacks},
1988 		{TIPC_NLA_STATS_TX_ACKS, s->sent_acks},
1989 		{TIPC_NLA_STATS_RETRANSMITTED, s->retransmitted},
1990 		{TIPC_NLA_STATS_DUPLICATES, s->duplicates},
1991 		{TIPC_NLA_STATS_LINK_CONGS, s->link_congs},
1992 		{TIPC_NLA_STATS_MAX_QUEUE, s->max_queue_sz},
1993 		{TIPC_NLA_STATS_AVG_QUEUE, s->queue_sz_counts ?
1994 			(s->accu_queue_sz / s->queue_sz_counts) : 0}
1995 	};
1996 
1997 	stats = nla_nest_start(skb, TIPC_NLA_LINK_STATS);
1998 	if (!stats)
1999 		return -EMSGSIZE;
2000 
2001 	for (i = 0; i <  ARRAY_SIZE(map); i++)
2002 		if (nla_put_u32(skb, map[i].key, map[i].val))
2003 			goto msg_full;
2004 
2005 	nla_nest_end(skb, stats);
2006 
2007 	return 0;
2008 msg_full:
2009 	nla_nest_cancel(skb, stats);
2010 
2011 	return -EMSGSIZE;
2012 }
2013 
2014 /* Caller should hold appropriate locks to protect the link */
2015 static int __tipc_nl_add_link(struct net *net, struct tipc_nl_msg *msg,
2016 			      struct tipc_link *link)
2017 {
2018 	int err;
2019 	void *hdr;
2020 	struct nlattr *attrs;
2021 	struct nlattr *prop;
2022 	struct tipc_net *tn = net_generic(net, tipc_net_id);
2023 
2024 	hdr = genlmsg_put(msg->skb, msg->portid, msg->seq, &tipc_genl_family,
2025 			  NLM_F_MULTI, TIPC_NL_LINK_GET);
2026 	if (!hdr)
2027 		return -EMSGSIZE;
2028 
2029 	attrs = nla_nest_start(msg->skb, TIPC_NLA_LINK);
2030 	if (!attrs)
2031 		goto msg_full;
2032 
2033 	if (nla_put_string(msg->skb, TIPC_NLA_LINK_NAME, link->name))
2034 		goto attr_msg_full;
2035 	if (nla_put_u32(msg->skb, TIPC_NLA_LINK_DEST,
2036 			tipc_cluster_mask(tn->own_addr)))
2037 		goto attr_msg_full;
2038 	if (nla_put_u32(msg->skb, TIPC_NLA_LINK_MTU, link->mtu))
2039 		goto attr_msg_full;
2040 	if (nla_put_u32(msg->skb, TIPC_NLA_LINK_RX, link->next_in_no))
2041 		goto attr_msg_full;
2042 	if (nla_put_u32(msg->skb, TIPC_NLA_LINK_TX, link->next_out_no))
2043 		goto attr_msg_full;
2044 
2045 	if (tipc_link_is_up(link))
2046 		if (nla_put_flag(msg->skb, TIPC_NLA_LINK_UP))
2047 			goto attr_msg_full;
2048 	if (tipc_link_is_active(link))
2049 		if (nla_put_flag(msg->skb, TIPC_NLA_LINK_ACTIVE))
2050 			goto attr_msg_full;
2051 
2052 	prop = nla_nest_start(msg->skb, TIPC_NLA_LINK_PROP);
2053 	if (!prop)
2054 		goto attr_msg_full;
2055 	if (nla_put_u32(msg->skb, TIPC_NLA_PROP_PRIO, link->priority))
2056 		goto prop_msg_full;
2057 	if (nla_put_u32(msg->skb, TIPC_NLA_PROP_TOL, link->tolerance))
2058 		goto prop_msg_full;
2059 	if (nla_put_u32(msg->skb, TIPC_NLA_PROP_WIN,
2060 			link->window))
2061 		goto prop_msg_full;
2062 	if (nla_put_u32(msg->skb, TIPC_NLA_PROP_PRIO, link->priority))
2063 		goto prop_msg_full;
2064 	nla_nest_end(msg->skb, prop);
2065 
2066 	err = __tipc_nl_add_stats(msg->skb, &link->stats);
2067 	if (err)
2068 		goto attr_msg_full;
2069 
2070 	nla_nest_end(msg->skb, attrs);
2071 	genlmsg_end(msg->skb, hdr);
2072 
2073 	return 0;
2074 
2075 prop_msg_full:
2076 	nla_nest_cancel(msg->skb, prop);
2077 attr_msg_full:
2078 	nla_nest_cancel(msg->skb, attrs);
2079 msg_full:
2080 	genlmsg_cancel(msg->skb, hdr);
2081 
2082 	return -EMSGSIZE;
2083 }
2084 
2085 /* Caller should hold node lock  */
2086 static int __tipc_nl_add_node_links(struct net *net, struct tipc_nl_msg *msg,
2087 				    struct tipc_node *node, u32 *prev_link)
2088 {
2089 	u32 i;
2090 	int err;
2091 
2092 	for (i = *prev_link; i < MAX_BEARERS; i++) {
2093 		*prev_link = i;
2094 
2095 		if (!node->links[i])
2096 			continue;
2097 
2098 		err = __tipc_nl_add_link(net, msg, node->links[i]);
2099 		if (err)
2100 			return err;
2101 	}
2102 	*prev_link = 0;
2103 
2104 	return 0;
2105 }
2106 
2107 int tipc_nl_link_dump(struct sk_buff *skb, struct netlink_callback *cb)
2108 {
2109 	struct net *net = sock_net(skb->sk);
2110 	struct tipc_net *tn = net_generic(net, tipc_net_id);
2111 	struct tipc_node *node;
2112 	struct tipc_nl_msg msg;
2113 	u32 prev_node = cb->args[0];
2114 	u32 prev_link = cb->args[1];
2115 	int done = cb->args[2];
2116 	int err;
2117 
2118 	if (done)
2119 		return 0;
2120 
2121 	msg.skb = skb;
2122 	msg.portid = NETLINK_CB(cb->skb).portid;
2123 	msg.seq = cb->nlh->nlmsg_seq;
2124 
2125 	rcu_read_lock();
2126 	if (prev_node) {
2127 		node = tipc_node_find(net, prev_node);
2128 		if (!node) {
2129 			/* We never set seq or call nl_dump_check_consistent()
2130 			 * this means that setting prev_seq here will cause the
2131 			 * consistence check to fail in the netlink callback
2132 			 * handler. Resulting in the last NLMSG_DONE message
2133 			 * having the NLM_F_DUMP_INTR flag set.
2134 			 */
2135 			cb->prev_seq = 1;
2136 			goto out;
2137 		}
2138 		tipc_node_put(node);
2139 
2140 		list_for_each_entry_continue_rcu(node, &tn->node_list,
2141 						 list) {
2142 			tipc_node_lock(node);
2143 			err = __tipc_nl_add_node_links(net, &msg, node,
2144 						       &prev_link);
2145 			tipc_node_unlock(node);
2146 			tipc_node_put(node);
2147 			if (err)
2148 				goto out;
2149 
2150 			prev_node = node->addr;
2151 		}
2152 	} else {
2153 		err = tipc_nl_add_bc_link(net, &msg);
2154 		if (err)
2155 			goto out;
2156 
2157 		list_for_each_entry_rcu(node, &tn->node_list, list) {
2158 			tipc_node_lock(node);
2159 			err = __tipc_nl_add_node_links(net, &msg, node,
2160 						       &prev_link);
2161 			tipc_node_unlock(node);
2162 			if (err)
2163 				goto out;
2164 
2165 			prev_node = node->addr;
2166 		}
2167 	}
2168 	done = 1;
2169 out:
2170 	rcu_read_unlock();
2171 
2172 	cb->args[0] = prev_node;
2173 	cb->args[1] = prev_link;
2174 	cb->args[2] = done;
2175 
2176 	return skb->len;
2177 }
2178 
2179 int tipc_nl_link_get(struct sk_buff *skb, struct genl_info *info)
2180 {
2181 	struct net *net = genl_info_net(info);
2182 	struct sk_buff *ans_skb;
2183 	struct tipc_nl_msg msg;
2184 	struct tipc_link *link;
2185 	struct tipc_node *node;
2186 	char *name;
2187 	int bearer_id;
2188 	int err;
2189 
2190 	if (!info->attrs[TIPC_NLA_LINK_NAME])
2191 		return -EINVAL;
2192 
2193 	name = nla_data(info->attrs[TIPC_NLA_LINK_NAME]);
2194 	node = tipc_link_find_owner(net, name, &bearer_id);
2195 	if (!node)
2196 		return -EINVAL;
2197 
2198 	ans_skb = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2199 	if (!ans_skb)
2200 		return -ENOMEM;
2201 
2202 	msg.skb = ans_skb;
2203 	msg.portid = info->snd_portid;
2204 	msg.seq = info->snd_seq;
2205 
2206 	tipc_node_lock(node);
2207 	link = node->links[bearer_id];
2208 	if (!link) {
2209 		err = -EINVAL;
2210 		goto err_out;
2211 	}
2212 
2213 	err = __tipc_nl_add_link(net, &msg, link);
2214 	if (err)
2215 		goto err_out;
2216 
2217 	tipc_node_unlock(node);
2218 
2219 	return genlmsg_reply(ans_skb, info);
2220 
2221 err_out:
2222 	tipc_node_unlock(node);
2223 	nlmsg_free(ans_skb);
2224 
2225 	return err;
2226 }
2227 
2228 int tipc_nl_link_reset_stats(struct sk_buff *skb, struct genl_info *info)
2229 {
2230 	int err;
2231 	char *link_name;
2232 	unsigned int bearer_id;
2233 	struct tipc_link *link;
2234 	struct tipc_node *node;
2235 	struct nlattr *attrs[TIPC_NLA_LINK_MAX + 1];
2236 	struct net *net = sock_net(skb->sk);
2237 
2238 	if (!info->attrs[TIPC_NLA_LINK])
2239 		return -EINVAL;
2240 
2241 	err = nla_parse_nested(attrs, TIPC_NLA_LINK_MAX,
2242 			       info->attrs[TIPC_NLA_LINK],
2243 			       tipc_nl_link_policy);
2244 	if (err)
2245 		return err;
2246 
2247 	if (!attrs[TIPC_NLA_LINK_NAME])
2248 		return -EINVAL;
2249 
2250 	link_name = nla_data(attrs[TIPC_NLA_LINK_NAME]);
2251 
2252 	if (strcmp(link_name, tipc_bclink_name) == 0) {
2253 		err = tipc_bclink_reset_stats(net);
2254 		if (err)
2255 			return err;
2256 		return 0;
2257 	}
2258 
2259 	node = tipc_link_find_owner(net, link_name, &bearer_id);
2260 	if (!node)
2261 		return -EINVAL;
2262 
2263 	tipc_node_lock(node);
2264 
2265 	link = node->links[bearer_id];
2266 	if (!link) {
2267 		tipc_node_unlock(node);
2268 		return -EINVAL;
2269 	}
2270 
2271 	link_reset_statistics(link);
2272 
2273 	tipc_node_unlock(node);
2274 
2275 	return 0;
2276 }
2277