xref: /OK3568_Linux_fs/kernel/net/can/j1939/address-claim.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0
2*4882a593Smuzhiyun // Copyright (c) 2010-2011 EIA Electronics,
3*4882a593Smuzhiyun //                         Kurt Van Dijck <kurt.van.dijck@eia.be>
4*4882a593Smuzhiyun // Copyright (c) 2010-2011 EIA Electronics,
5*4882a593Smuzhiyun //                         Pieter Beyens <pieter.beyens@eia.be>
6*4882a593Smuzhiyun // Copyright (c) 2017-2019 Pengutronix,
7*4882a593Smuzhiyun //                         Marc Kleine-Budde <kernel@pengutronix.de>
8*4882a593Smuzhiyun // Copyright (c) 2017-2019 Pengutronix,
9*4882a593Smuzhiyun //                         Oleksij Rempel <kernel@pengutronix.de>
10*4882a593Smuzhiyun 
11*4882a593Smuzhiyun /* J1939 Address Claiming.
12*4882a593Smuzhiyun  * Address Claiming in the kernel
13*4882a593Smuzhiyun  * - keeps track of the AC states of ECU's,
14*4882a593Smuzhiyun  * - resolves NAME<=>SA taking into account the AC states of ECU's.
15*4882a593Smuzhiyun  *
16*4882a593Smuzhiyun  * All Address Claim msgs (including host-originated msg) are processed
17*4882a593Smuzhiyun  * at the receive path (a sent msg is always received again via CAN echo).
18*4882a593Smuzhiyun  * As such, the processing of AC msgs is done in the order on which msgs
19*4882a593Smuzhiyun  * are sent on the bus.
20*4882a593Smuzhiyun  *
21*4882a593Smuzhiyun  * This module doesn't send msgs itself (e.g. replies on Address Claims),
22*4882a593Smuzhiyun  * this is the responsibility of a user space application or daemon.
23*4882a593Smuzhiyun  */
24*4882a593Smuzhiyun 
25*4882a593Smuzhiyun #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
26*4882a593Smuzhiyun 
27*4882a593Smuzhiyun #include <linux/netdevice.h>
28*4882a593Smuzhiyun #include <linux/skbuff.h>
29*4882a593Smuzhiyun 
30*4882a593Smuzhiyun #include "j1939-priv.h"
31*4882a593Smuzhiyun 
j1939_skb_to_name(const struct sk_buff * skb)32*4882a593Smuzhiyun static inline name_t j1939_skb_to_name(const struct sk_buff *skb)
33*4882a593Smuzhiyun {
34*4882a593Smuzhiyun 	return le64_to_cpup((__le64 *)skb->data);
35*4882a593Smuzhiyun }
36*4882a593Smuzhiyun 
j1939_ac_msg_is_request(struct sk_buff * skb)37*4882a593Smuzhiyun static inline bool j1939_ac_msg_is_request(struct sk_buff *skb)
38*4882a593Smuzhiyun {
39*4882a593Smuzhiyun 	struct j1939_sk_buff_cb *skcb = j1939_skb_to_cb(skb);
40*4882a593Smuzhiyun 	int req_pgn;
41*4882a593Smuzhiyun 
42*4882a593Smuzhiyun 	if (skb->len < 3 || skcb->addr.pgn != J1939_PGN_REQUEST)
43*4882a593Smuzhiyun 		return false;
44*4882a593Smuzhiyun 
45*4882a593Smuzhiyun 	req_pgn = skb->data[0] | (skb->data[1] << 8) | (skb->data[2] << 16);
46*4882a593Smuzhiyun 
47*4882a593Smuzhiyun 	return req_pgn == J1939_PGN_ADDRESS_CLAIMED;
48*4882a593Smuzhiyun }
49*4882a593Smuzhiyun 
j1939_ac_verify_outgoing(struct j1939_priv * priv,struct sk_buff * skb)50*4882a593Smuzhiyun static int j1939_ac_verify_outgoing(struct j1939_priv *priv,
51*4882a593Smuzhiyun 				    struct sk_buff *skb)
52*4882a593Smuzhiyun {
53*4882a593Smuzhiyun 	struct j1939_sk_buff_cb *skcb = j1939_skb_to_cb(skb);
54*4882a593Smuzhiyun 
55*4882a593Smuzhiyun 	if (skb->len != 8) {
56*4882a593Smuzhiyun 		netdev_notice(priv->ndev, "tx address claim with dlc %i\n",
57*4882a593Smuzhiyun 			      skb->len);
58*4882a593Smuzhiyun 		return -EPROTO;
59*4882a593Smuzhiyun 	}
60*4882a593Smuzhiyun 
61*4882a593Smuzhiyun 	if (skcb->addr.src_name != j1939_skb_to_name(skb)) {
62*4882a593Smuzhiyun 		netdev_notice(priv->ndev, "tx address claim with different name\n");
63*4882a593Smuzhiyun 		return -EPROTO;
64*4882a593Smuzhiyun 	}
65*4882a593Smuzhiyun 
66*4882a593Smuzhiyun 	if (skcb->addr.sa == J1939_NO_ADDR) {
67*4882a593Smuzhiyun 		netdev_notice(priv->ndev, "tx address claim with broadcast sa\n");
68*4882a593Smuzhiyun 		return -EPROTO;
69*4882a593Smuzhiyun 	}
70*4882a593Smuzhiyun 
71*4882a593Smuzhiyun 	/* ac must always be a broadcast */
72*4882a593Smuzhiyun 	if (skcb->addr.dst_name || skcb->addr.da != J1939_NO_ADDR) {
73*4882a593Smuzhiyun 		netdev_notice(priv->ndev, "tx address claim with dest, not broadcast\n");
74*4882a593Smuzhiyun 		return -EPROTO;
75*4882a593Smuzhiyun 	}
76*4882a593Smuzhiyun 	return 0;
77*4882a593Smuzhiyun }
78*4882a593Smuzhiyun 
j1939_ac_fixup(struct j1939_priv * priv,struct sk_buff * skb)79*4882a593Smuzhiyun int j1939_ac_fixup(struct j1939_priv *priv, struct sk_buff *skb)
80*4882a593Smuzhiyun {
81*4882a593Smuzhiyun 	struct j1939_sk_buff_cb *skcb = j1939_skb_to_cb(skb);
82*4882a593Smuzhiyun 	int ret;
83*4882a593Smuzhiyun 	u8 addr;
84*4882a593Smuzhiyun 
85*4882a593Smuzhiyun 	/* network mgmt: address claiming msgs */
86*4882a593Smuzhiyun 	if (skcb->addr.pgn == J1939_PGN_ADDRESS_CLAIMED) {
87*4882a593Smuzhiyun 		struct j1939_ecu *ecu;
88*4882a593Smuzhiyun 
89*4882a593Smuzhiyun 		ret = j1939_ac_verify_outgoing(priv, skb);
90*4882a593Smuzhiyun 		/* return both when failure & when successful */
91*4882a593Smuzhiyun 		if (ret < 0)
92*4882a593Smuzhiyun 			return ret;
93*4882a593Smuzhiyun 		ecu = j1939_ecu_get_by_name(priv, skcb->addr.src_name);
94*4882a593Smuzhiyun 		if (!ecu)
95*4882a593Smuzhiyun 			return -ENODEV;
96*4882a593Smuzhiyun 
97*4882a593Smuzhiyun 		if (ecu->addr != skcb->addr.sa)
98*4882a593Smuzhiyun 			/* hold further traffic for ecu, remove from parent */
99*4882a593Smuzhiyun 			j1939_ecu_unmap(ecu);
100*4882a593Smuzhiyun 		j1939_ecu_put(ecu);
101*4882a593Smuzhiyun 	} else if (skcb->addr.src_name) {
102*4882a593Smuzhiyun 		/* assign source address */
103*4882a593Smuzhiyun 		addr = j1939_name_to_addr(priv, skcb->addr.src_name);
104*4882a593Smuzhiyun 		if (!j1939_address_is_unicast(addr) &&
105*4882a593Smuzhiyun 		    !j1939_ac_msg_is_request(skb)) {
106*4882a593Smuzhiyun 			netdev_notice(priv->ndev, "tx drop: invalid sa for name 0x%016llx\n",
107*4882a593Smuzhiyun 				      skcb->addr.src_name);
108*4882a593Smuzhiyun 			return -EADDRNOTAVAIL;
109*4882a593Smuzhiyun 		}
110*4882a593Smuzhiyun 		skcb->addr.sa = addr;
111*4882a593Smuzhiyun 	}
112*4882a593Smuzhiyun 
113*4882a593Smuzhiyun 	/* assign destination address */
114*4882a593Smuzhiyun 	if (skcb->addr.dst_name) {
115*4882a593Smuzhiyun 		addr = j1939_name_to_addr(priv, skcb->addr.dst_name);
116*4882a593Smuzhiyun 		if (!j1939_address_is_unicast(addr)) {
117*4882a593Smuzhiyun 			netdev_notice(priv->ndev, "tx drop: invalid da for name 0x%016llx\n",
118*4882a593Smuzhiyun 				      skcb->addr.dst_name);
119*4882a593Smuzhiyun 			return -EADDRNOTAVAIL;
120*4882a593Smuzhiyun 		}
121*4882a593Smuzhiyun 		skcb->addr.da = addr;
122*4882a593Smuzhiyun 	}
123*4882a593Smuzhiyun 	return 0;
124*4882a593Smuzhiyun }
125*4882a593Smuzhiyun 
j1939_ac_process(struct j1939_priv * priv,struct sk_buff * skb)126*4882a593Smuzhiyun static void j1939_ac_process(struct j1939_priv *priv, struct sk_buff *skb)
127*4882a593Smuzhiyun {
128*4882a593Smuzhiyun 	struct j1939_sk_buff_cb *skcb = j1939_skb_to_cb(skb);
129*4882a593Smuzhiyun 	struct j1939_ecu *ecu, *prev;
130*4882a593Smuzhiyun 	name_t name;
131*4882a593Smuzhiyun 
132*4882a593Smuzhiyun 	if (skb->len != 8) {
133*4882a593Smuzhiyun 		netdev_notice(priv->ndev, "rx address claim with wrong dlc %i\n",
134*4882a593Smuzhiyun 			      skb->len);
135*4882a593Smuzhiyun 		return;
136*4882a593Smuzhiyun 	}
137*4882a593Smuzhiyun 
138*4882a593Smuzhiyun 	name = j1939_skb_to_name(skb);
139*4882a593Smuzhiyun 	skcb->addr.src_name = name;
140*4882a593Smuzhiyun 	if (!name) {
141*4882a593Smuzhiyun 		netdev_notice(priv->ndev, "rx address claim without name\n");
142*4882a593Smuzhiyun 		return;
143*4882a593Smuzhiyun 	}
144*4882a593Smuzhiyun 
145*4882a593Smuzhiyun 	if (!j1939_address_is_valid(skcb->addr.sa)) {
146*4882a593Smuzhiyun 		netdev_notice(priv->ndev, "rx address claim with broadcast sa\n");
147*4882a593Smuzhiyun 		return;
148*4882a593Smuzhiyun 	}
149*4882a593Smuzhiyun 
150*4882a593Smuzhiyun 	write_lock_bh(&priv->lock);
151*4882a593Smuzhiyun 
152*4882a593Smuzhiyun 	/* Few words on the ECU ref counting:
153*4882a593Smuzhiyun 	 *
154*4882a593Smuzhiyun 	 * First we get an ECU handle, either with
155*4882a593Smuzhiyun 	 * j1939_ecu_get_by_name_locked() (increments the ref counter)
156*4882a593Smuzhiyun 	 * or j1939_ecu_create_locked() (initializes an ECU object
157*4882a593Smuzhiyun 	 * with a ref counter of 1).
158*4882a593Smuzhiyun 	 *
159*4882a593Smuzhiyun 	 * j1939_ecu_unmap_locked() will decrement the ref counter,
160*4882a593Smuzhiyun 	 * but only if the ECU was mapped before. So "ecu" still
161*4882a593Smuzhiyun 	 * belongs to us.
162*4882a593Smuzhiyun 	 *
163*4882a593Smuzhiyun 	 * j1939_ecu_timer_start() will increment the ref counter
164*4882a593Smuzhiyun 	 * before it starts the timer, so we can put the ecu when
165*4882a593Smuzhiyun 	 * leaving this function.
166*4882a593Smuzhiyun 	 */
167*4882a593Smuzhiyun 	ecu = j1939_ecu_get_by_name_locked(priv, name);
168*4882a593Smuzhiyun 	if (!ecu && j1939_address_is_unicast(skcb->addr.sa))
169*4882a593Smuzhiyun 		ecu = j1939_ecu_create_locked(priv, name);
170*4882a593Smuzhiyun 
171*4882a593Smuzhiyun 	if (IS_ERR_OR_NULL(ecu))
172*4882a593Smuzhiyun 		goto out_unlock_bh;
173*4882a593Smuzhiyun 
174*4882a593Smuzhiyun 	/* cancel pending (previous) address claim */
175*4882a593Smuzhiyun 	j1939_ecu_timer_cancel(ecu);
176*4882a593Smuzhiyun 
177*4882a593Smuzhiyun 	if (j1939_address_is_idle(skcb->addr.sa)) {
178*4882a593Smuzhiyun 		j1939_ecu_unmap_locked(ecu);
179*4882a593Smuzhiyun 		goto out_ecu_put;
180*4882a593Smuzhiyun 	}
181*4882a593Smuzhiyun 
182*4882a593Smuzhiyun 	/* save new addr */
183*4882a593Smuzhiyun 	if (ecu->addr != skcb->addr.sa)
184*4882a593Smuzhiyun 		j1939_ecu_unmap_locked(ecu);
185*4882a593Smuzhiyun 	ecu->addr = skcb->addr.sa;
186*4882a593Smuzhiyun 
187*4882a593Smuzhiyun 	prev = j1939_ecu_get_by_addr_locked(priv, skcb->addr.sa);
188*4882a593Smuzhiyun 	if (prev) {
189*4882a593Smuzhiyun 		if (ecu->name > prev->name) {
190*4882a593Smuzhiyun 			j1939_ecu_unmap_locked(ecu);
191*4882a593Smuzhiyun 			j1939_ecu_put(prev);
192*4882a593Smuzhiyun 			goto out_ecu_put;
193*4882a593Smuzhiyun 		} else {
194*4882a593Smuzhiyun 			/* kick prev if less or equal */
195*4882a593Smuzhiyun 			j1939_ecu_unmap_locked(prev);
196*4882a593Smuzhiyun 			j1939_ecu_put(prev);
197*4882a593Smuzhiyun 		}
198*4882a593Smuzhiyun 	}
199*4882a593Smuzhiyun 
200*4882a593Smuzhiyun 	j1939_ecu_timer_start(ecu);
201*4882a593Smuzhiyun  out_ecu_put:
202*4882a593Smuzhiyun 	j1939_ecu_put(ecu);
203*4882a593Smuzhiyun  out_unlock_bh:
204*4882a593Smuzhiyun 	write_unlock_bh(&priv->lock);
205*4882a593Smuzhiyun }
206*4882a593Smuzhiyun 
j1939_ac_recv(struct j1939_priv * priv,struct sk_buff * skb)207*4882a593Smuzhiyun void j1939_ac_recv(struct j1939_priv *priv, struct sk_buff *skb)
208*4882a593Smuzhiyun {
209*4882a593Smuzhiyun 	struct j1939_sk_buff_cb *skcb = j1939_skb_to_cb(skb);
210*4882a593Smuzhiyun 	struct j1939_ecu *ecu;
211*4882a593Smuzhiyun 
212*4882a593Smuzhiyun 	/* network mgmt */
213*4882a593Smuzhiyun 	if (skcb->addr.pgn == J1939_PGN_ADDRESS_CLAIMED) {
214*4882a593Smuzhiyun 		j1939_ac_process(priv, skb);
215*4882a593Smuzhiyun 	} else if (j1939_address_is_unicast(skcb->addr.sa)) {
216*4882a593Smuzhiyun 		/* assign source name */
217*4882a593Smuzhiyun 		ecu = j1939_ecu_get_by_addr(priv, skcb->addr.sa);
218*4882a593Smuzhiyun 		if (ecu) {
219*4882a593Smuzhiyun 			skcb->addr.src_name = ecu->name;
220*4882a593Smuzhiyun 			j1939_ecu_put(ecu);
221*4882a593Smuzhiyun 		}
222*4882a593Smuzhiyun 	}
223*4882a593Smuzhiyun 
224*4882a593Smuzhiyun 	/* assign destination name */
225*4882a593Smuzhiyun 	ecu = j1939_ecu_get_by_addr(priv, skcb->addr.da);
226*4882a593Smuzhiyun 	if (ecu) {
227*4882a593Smuzhiyun 		skcb->addr.dst_name = ecu->name;
228*4882a593Smuzhiyun 		j1939_ecu_put(ecu);
229*4882a593Smuzhiyun 	}
230*4882a593Smuzhiyun }
231