1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0-only */
2*4882a593Smuzhiyun /* L2TP internal definitions.
3*4882a593Smuzhiyun *
4*4882a593Smuzhiyun * Copyright (c) 2008,2009 Katalix Systems Ltd
5*4882a593Smuzhiyun */
6*4882a593Smuzhiyun #include <linux/refcount.h>
7*4882a593Smuzhiyun
8*4882a593Smuzhiyun #ifndef _L2TP_CORE_H_
9*4882a593Smuzhiyun #define _L2TP_CORE_H_
10*4882a593Smuzhiyun
11*4882a593Smuzhiyun #include <net/dst.h>
12*4882a593Smuzhiyun #include <net/sock.h>
13*4882a593Smuzhiyun
14*4882a593Smuzhiyun #ifdef CONFIG_XFRM
15*4882a593Smuzhiyun #include <net/xfrm.h>
16*4882a593Smuzhiyun #endif
17*4882a593Smuzhiyun
18*4882a593Smuzhiyun /* Random numbers used for internal consistency checks of tunnel and session structures */
19*4882a593Smuzhiyun #define L2TP_TUNNEL_MAGIC 0x42114DDA
20*4882a593Smuzhiyun #define L2TP_SESSION_MAGIC 0x0C04EB7D
21*4882a593Smuzhiyun
22*4882a593Smuzhiyun /* Per tunnel session hash table size */
23*4882a593Smuzhiyun #define L2TP_HASH_BITS 4
24*4882a593Smuzhiyun #define L2TP_HASH_SIZE BIT(L2TP_HASH_BITS)
25*4882a593Smuzhiyun
26*4882a593Smuzhiyun /* System-wide session hash table size */
27*4882a593Smuzhiyun #define L2TP_HASH_BITS_2 8
28*4882a593Smuzhiyun #define L2TP_HASH_SIZE_2 BIT(L2TP_HASH_BITS_2)
29*4882a593Smuzhiyun
30*4882a593Smuzhiyun struct sk_buff;
31*4882a593Smuzhiyun
32*4882a593Smuzhiyun struct l2tp_stats {
33*4882a593Smuzhiyun atomic_long_t tx_packets;
34*4882a593Smuzhiyun atomic_long_t tx_bytes;
35*4882a593Smuzhiyun atomic_long_t tx_errors;
36*4882a593Smuzhiyun atomic_long_t rx_packets;
37*4882a593Smuzhiyun atomic_long_t rx_bytes;
38*4882a593Smuzhiyun atomic_long_t rx_seq_discards;
39*4882a593Smuzhiyun atomic_long_t rx_oos_packets;
40*4882a593Smuzhiyun atomic_long_t rx_errors;
41*4882a593Smuzhiyun atomic_long_t rx_cookie_discards;
42*4882a593Smuzhiyun atomic_long_t rx_invalid;
43*4882a593Smuzhiyun };
44*4882a593Smuzhiyun
45*4882a593Smuzhiyun struct l2tp_tunnel;
46*4882a593Smuzhiyun
47*4882a593Smuzhiyun /* L2TP session configuration */
48*4882a593Smuzhiyun struct l2tp_session_cfg {
49*4882a593Smuzhiyun enum l2tp_pwtype pw_type;
50*4882a593Smuzhiyun unsigned int recv_seq:1; /* expect receive packets with sequence numbers? */
51*4882a593Smuzhiyun unsigned int send_seq:1; /* send packets with sequence numbers? */
52*4882a593Smuzhiyun unsigned int lns_mode:1; /* behave as LNS?
53*4882a593Smuzhiyun * LAC enables sequence numbers under LNS control.
54*4882a593Smuzhiyun */
55*4882a593Smuzhiyun u16 l2specific_type; /* Layer 2 specific type */
56*4882a593Smuzhiyun u8 cookie[8]; /* optional cookie */
57*4882a593Smuzhiyun int cookie_len; /* 0, 4 or 8 bytes */
58*4882a593Smuzhiyun u8 peer_cookie[8]; /* peer's cookie */
59*4882a593Smuzhiyun int peer_cookie_len; /* 0, 4 or 8 bytes */
60*4882a593Smuzhiyun int reorder_timeout; /* configured reorder timeout (in jiffies) */
61*4882a593Smuzhiyun char *ifname;
62*4882a593Smuzhiyun };
63*4882a593Smuzhiyun
64*4882a593Smuzhiyun /* Represents a session (pseudowire) instance.
65*4882a593Smuzhiyun * Tracks runtime state including cookies, dataplane packet sequencing, and IO statistics.
66*4882a593Smuzhiyun * Is linked into a per-tunnel session hashlist; and in the case of an L2TPv3 session into
67*4882a593Smuzhiyun * an additional per-net ("global") hashlist.
68*4882a593Smuzhiyun */
69*4882a593Smuzhiyun #define L2TP_SESSION_NAME_MAX 32
70*4882a593Smuzhiyun struct l2tp_session {
71*4882a593Smuzhiyun int magic; /* should be L2TP_SESSION_MAGIC */
72*4882a593Smuzhiyun long dead;
73*4882a593Smuzhiyun
74*4882a593Smuzhiyun struct l2tp_tunnel *tunnel; /* back pointer to tunnel context */
75*4882a593Smuzhiyun u32 session_id;
76*4882a593Smuzhiyun u32 peer_session_id;
77*4882a593Smuzhiyun u8 cookie[8];
78*4882a593Smuzhiyun int cookie_len;
79*4882a593Smuzhiyun u8 peer_cookie[8];
80*4882a593Smuzhiyun int peer_cookie_len;
81*4882a593Smuzhiyun u16 l2specific_type;
82*4882a593Smuzhiyun u16 hdr_len;
83*4882a593Smuzhiyun u32 nr; /* session NR state (receive) */
84*4882a593Smuzhiyun u32 ns; /* session NR state (send) */
85*4882a593Smuzhiyun struct sk_buff_head reorder_q; /* receive reorder queue */
86*4882a593Smuzhiyun u32 nr_max; /* max NR. Depends on tunnel */
87*4882a593Smuzhiyun u32 nr_window_size; /* NR window size */
88*4882a593Smuzhiyun u32 nr_oos; /* NR of last OOS packet */
89*4882a593Smuzhiyun int nr_oos_count; /* for OOS recovery */
90*4882a593Smuzhiyun int nr_oos_count_max;
91*4882a593Smuzhiyun struct hlist_node hlist; /* hash list node */
92*4882a593Smuzhiyun refcount_t ref_count;
93*4882a593Smuzhiyun
94*4882a593Smuzhiyun char name[L2TP_SESSION_NAME_MAX]; /* for logging */
95*4882a593Smuzhiyun char ifname[IFNAMSIZ];
96*4882a593Smuzhiyun unsigned int recv_seq:1; /* expect receive packets with sequence numbers? */
97*4882a593Smuzhiyun unsigned int send_seq:1; /* send packets with sequence numbers? */
98*4882a593Smuzhiyun unsigned int lns_mode:1; /* behave as LNS?
99*4882a593Smuzhiyun * LAC enables sequence numbers under LNS control.
100*4882a593Smuzhiyun */
101*4882a593Smuzhiyun int reorder_timeout; /* configured reorder timeout (in jiffies) */
102*4882a593Smuzhiyun int reorder_skip; /* set if skip to next nr */
103*4882a593Smuzhiyun enum l2tp_pwtype pwtype;
104*4882a593Smuzhiyun struct l2tp_stats stats;
105*4882a593Smuzhiyun struct hlist_node global_hlist; /* global hash list node */
106*4882a593Smuzhiyun
107*4882a593Smuzhiyun /* Session receive handler for data packets.
108*4882a593Smuzhiyun * Each pseudowire implementation should implement this callback in order to
109*4882a593Smuzhiyun * handle incoming packets. Packets are passed to the pseudowire handler after
110*4882a593Smuzhiyun * reordering, if data sequence numbers are enabled for the session.
111*4882a593Smuzhiyun */
112*4882a593Smuzhiyun void (*recv_skb)(struct l2tp_session *session, struct sk_buff *skb, int data_len);
113*4882a593Smuzhiyun
114*4882a593Smuzhiyun /* Session close handler.
115*4882a593Smuzhiyun * Each pseudowire implementation may implement this callback in order to carry
116*4882a593Smuzhiyun * out pseudowire-specific shutdown actions.
117*4882a593Smuzhiyun * The callback is called by core after unhashing the session and purging its
118*4882a593Smuzhiyun * reorder queue.
119*4882a593Smuzhiyun */
120*4882a593Smuzhiyun void (*session_close)(struct l2tp_session *session);
121*4882a593Smuzhiyun
122*4882a593Smuzhiyun /* Session show handler.
123*4882a593Smuzhiyun * Pseudowire-specific implementation of debugfs session rendering.
124*4882a593Smuzhiyun * The callback is called by l2tp_debugfs.c after rendering core session
125*4882a593Smuzhiyun * information.
126*4882a593Smuzhiyun */
127*4882a593Smuzhiyun void (*show)(struct seq_file *m, void *priv);
128*4882a593Smuzhiyun
129*4882a593Smuzhiyun u8 priv[]; /* private data */
130*4882a593Smuzhiyun };
131*4882a593Smuzhiyun
132*4882a593Smuzhiyun /* L2TP tunnel configuration */
133*4882a593Smuzhiyun struct l2tp_tunnel_cfg {
134*4882a593Smuzhiyun enum l2tp_encap_type encap;
135*4882a593Smuzhiyun
136*4882a593Smuzhiyun /* Used only for kernel-created sockets */
137*4882a593Smuzhiyun struct in_addr local_ip;
138*4882a593Smuzhiyun struct in_addr peer_ip;
139*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_IPV6)
140*4882a593Smuzhiyun struct in6_addr *local_ip6;
141*4882a593Smuzhiyun struct in6_addr *peer_ip6;
142*4882a593Smuzhiyun #endif
143*4882a593Smuzhiyun u16 local_udp_port;
144*4882a593Smuzhiyun u16 peer_udp_port;
145*4882a593Smuzhiyun unsigned int use_udp_checksums:1,
146*4882a593Smuzhiyun udp6_zero_tx_checksums:1,
147*4882a593Smuzhiyun udp6_zero_rx_checksums:1;
148*4882a593Smuzhiyun };
149*4882a593Smuzhiyun
150*4882a593Smuzhiyun /* Represents a tunnel instance.
151*4882a593Smuzhiyun * Tracks runtime state including IO statistics.
152*4882a593Smuzhiyun * Holds the tunnel socket (either passed from userspace or directly created by the kernel).
153*4882a593Smuzhiyun * Maintains a hashlist of sessions belonging to the tunnel instance.
154*4882a593Smuzhiyun * Is linked into a per-net list of tunnels.
155*4882a593Smuzhiyun */
156*4882a593Smuzhiyun #define L2TP_TUNNEL_NAME_MAX 20
157*4882a593Smuzhiyun struct l2tp_tunnel {
158*4882a593Smuzhiyun int magic; /* Should be L2TP_TUNNEL_MAGIC */
159*4882a593Smuzhiyun
160*4882a593Smuzhiyun unsigned long dead;
161*4882a593Smuzhiyun
162*4882a593Smuzhiyun struct rcu_head rcu;
163*4882a593Smuzhiyun rwlock_t hlist_lock; /* protect session_hlist */
164*4882a593Smuzhiyun bool acpt_newsess; /* indicates whether this tunnel accepts
165*4882a593Smuzhiyun * new sessions. Protected by hlist_lock.
166*4882a593Smuzhiyun */
167*4882a593Smuzhiyun struct hlist_head session_hlist[L2TP_HASH_SIZE];
168*4882a593Smuzhiyun /* hashed list of sessions, hashed by id */
169*4882a593Smuzhiyun u32 tunnel_id;
170*4882a593Smuzhiyun u32 peer_tunnel_id;
171*4882a593Smuzhiyun int version; /* 2=>L2TPv2, 3=>L2TPv3 */
172*4882a593Smuzhiyun
173*4882a593Smuzhiyun char name[L2TP_TUNNEL_NAME_MAX]; /* for logging */
174*4882a593Smuzhiyun enum l2tp_encap_type encap;
175*4882a593Smuzhiyun struct l2tp_stats stats;
176*4882a593Smuzhiyun
177*4882a593Smuzhiyun struct list_head list; /* list node on per-namespace list of tunnels */
178*4882a593Smuzhiyun struct net *l2tp_net; /* the net we belong to */
179*4882a593Smuzhiyun
180*4882a593Smuzhiyun refcount_t ref_count;
181*4882a593Smuzhiyun void (*old_sk_destruct)(struct sock *sk);
182*4882a593Smuzhiyun struct sock *sock; /* parent socket */
183*4882a593Smuzhiyun int fd; /* parent fd, if tunnel socket was created
184*4882a593Smuzhiyun * by userspace
185*4882a593Smuzhiyun */
186*4882a593Smuzhiyun
187*4882a593Smuzhiyun struct work_struct del_work;
188*4882a593Smuzhiyun };
189*4882a593Smuzhiyun
190*4882a593Smuzhiyun /* Pseudowire ops callbacks for use with the l2tp genetlink interface */
191*4882a593Smuzhiyun struct l2tp_nl_cmd_ops {
192*4882a593Smuzhiyun /* The pseudowire session create callback is responsible for creating a session
193*4882a593Smuzhiyun * instance for a specific pseudowire type.
194*4882a593Smuzhiyun * It must call l2tp_session_create and l2tp_session_register to register the
195*4882a593Smuzhiyun * session instance, as well as carry out any pseudowire-specific initialisation.
196*4882a593Smuzhiyun * It must return >= 0 on success, or an appropriate negative errno value on failure.
197*4882a593Smuzhiyun */
198*4882a593Smuzhiyun int (*session_create)(struct net *net, struct l2tp_tunnel *tunnel,
199*4882a593Smuzhiyun u32 session_id, u32 peer_session_id,
200*4882a593Smuzhiyun struct l2tp_session_cfg *cfg);
201*4882a593Smuzhiyun
202*4882a593Smuzhiyun /* The pseudowire session delete callback is responsible for initiating the deletion
203*4882a593Smuzhiyun * of a session instance.
204*4882a593Smuzhiyun * It must call l2tp_session_delete, as well as carry out any pseudowire-specific
205*4882a593Smuzhiyun * teardown actions.
206*4882a593Smuzhiyun */
207*4882a593Smuzhiyun void (*session_delete)(struct l2tp_session *session);
208*4882a593Smuzhiyun };
209*4882a593Smuzhiyun
l2tp_session_priv(struct l2tp_session * session)210*4882a593Smuzhiyun static inline void *l2tp_session_priv(struct l2tp_session *session)
211*4882a593Smuzhiyun {
212*4882a593Smuzhiyun return &session->priv[0];
213*4882a593Smuzhiyun }
214*4882a593Smuzhiyun
215*4882a593Smuzhiyun /* Tunnel and session refcounts */
216*4882a593Smuzhiyun void l2tp_tunnel_inc_refcount(struct l2tp_tunnel *tunnel);
217*4882a593Smuzhiyun void l2tp_tunnel_dec_refcount(struct l2tp_tunnel *tunnel);
218*4882a593Smuzhiyun void l2tp_session_inc_refcount(struct l2tp_session *session);
219*4882a593Smuzhiyun void l2tp_session_dec_refcount(struct l2tp_session *session);
220*4882a593Smuzhiyun
221*4882a593Smuzhiyun /* Tunnel and session lookup.
222*4882a593Smuzhiyun * These functions take a reference on the instances they return, so
223*4882a593Smuzhiyun * the caller must ensure that the reference is dropped appropriately.
224*4882a593Smuzhiyun */
225*4882a593Smuzhiyun struct l2tp_tunnel *l2tp_tunnel_get(const struct net *net, u32 tunnel_id);
226*4882a593Smuzhiyun struct l2tp_tunnel *l2tp_tunnel_get_nth(const struct net *net, int nth);
227*4882a593Smuzhiyun struct l2tp_session *l2tp_tunnel_get_session(struct l2tp_tunnel *tunnel,
228*4882a593Smuzhiyun u32 session_id);
229*4882a593Smuzhiyun
230*4882a593Smuzhiyun struct l2tp_session *l2tp_session_get(const struct net *net, u32 session_id);
231*4882a593Smuzhiyun struct l2tp_session *l2tp_session_get_nth(struct l2tp_tunnel *tunnel, int nth);
232*4882a593Smuzhiyun struct l2tp_session *l2tp_session_get_by_ifname(const struct net *net,
233*4882a593Smuzhiyun const char *ifname);
234*4882a593Smuzhiyun
235*4882a593Smuzhiyun /* Tunnel and session lifetime management.
236*4882a593Smuzhiyun * Creation of a new instance is a two-step process: create, then register.
237*4882a593Smuzhiyun * Destruction is triggered using the *_delete functions, and completes asynchronously.
238*4882a593Smuzhiyun */
239*4882a593Smuzhiyun int l2tp_tunnel_create(int fd, int version, u32 tunnel_id,
240*4882a593Smuzhiyun u32 peer_tunnel_id, struct l2tp_tunnel_cfg *cfg,
241*4882a593Smuzhiyun struct l2tp_tunnel **tunnelp);
242*4882a593Smuzhiyun int l2tp_tunnel_register(struct l2tp_tunnel *tunnel, struct net *net,
243*4882a593Smuzhiyun struct l2tp_tunnel_cfg *cfg);
244*4882a593Smuzhiyun void l2tp_tunnel_delete(struct l2tp_tunnel *tunnel);
245*4882a593Smuzhiyun
246*4882a593Smuzhiyun struct l2tp_session *l2tp_session_create(int priv_size,
247*4882a593Smuzhiyun struct l2tp_tunnel *tunnel,
248*4882a593Smuzhiyun u32 session_id, u32 peer_session_id,
249*4882a593Smuzhiyun struct l2tp_session_cfg *cfg);
250*4882a593Smuzhiyun int l2tp_session_register(struct l2tp_session *session,
251*4882a593Smuzhiyun struct l2tp_tunnel *tunnel);
252*4882a593Smuzhiyun void l2tp_session_delete(struct l2tp_session *session);
253*4882a593Smuzhiyun
254*4882a593Smuzhiyun /* Receive path helpers. If data sequencing is enabled for the session these
255*4882a593Smuzhiyun * functions handle queuing and reordering prior to passing packets to the
256*4882a593Smuzhiyun * pseudowire code to be passed to userspace.
257*4882a593Smuzhiyun */
258*4882a593Smuzhiyun void l2tp_recv_common(struct l2tp_session *session, struct sk_buff *skb,
259*4882a593Smuzhiyun unsigned char *ptr, unsigned char *optr, u16 hdrflags,
260*4882a593Smuzhiyun int length);
261*4882a593Smuzhiyun int l2tp_udp_encap_recv(struct sock *sk, struct sk_buff *skb);
262*4882a593Smuzhiyun
263*4882a593Smuzhiyun /* Transmit path helpers for sending packets over the tunnel socket. */
264*4882a593Smuzhiyun void l2tp_session_set_header_len(struct l2tp_session *session, int version);
265*4882a593Smuzhiyun int l2tp_xmit_skb(struct l2tp_session *session, struct sk_buff *skb);
266*4882a593Smuzhiyun
267*4882a593Smuzhiyun /* Pseudowire management.
268*4882a593Smuzhiyun * Pseudowires should register with l2tp core on module init, and unregister
269*4882a593Smuzhiyun * on module exit.
270*4882a593Smuzhiyun */
271*4882a593Smuzhiyun int l2tp_nl_register_ops(enum l2tp_pwtype pw_type, const struct l2tp_nl_cmd_ops *ops);
272*4882a593Smuzhiyun void l2tp_nl_unregister_ops(enum l2tp_pwtype pw_type);
273*4882a593Smuzhiyun
274*4882a593Smuzhiyun /* IOCTL helper for IP encap modules. */
275*4882a593Smuzhiyun int l2tp_ioctl(struct sock *sk, int cmd, unsigned long arg);
276*4882a593Smuzhiyun
277*4882a593Smuzhiyun /* Extract the tunnel structure from a socket's sk_user_data pointer,
278*4882a593Smuzhiyun * validating the tunnel magic feather.
279*4882a593Smuzhiyun */
280*4882a593Smuzhiyun struct l2tp_tunnel *l2tp_sk_to_tunnel(struct sock *sk);
281*4882a593Smuzhiyun
l2tp_get_l2specific_len(struct l2tp_session * session)282*4882a593Smuzhiyun static inline int l2tp_get_l2specific_len(struct l2tp_session *session)
283*4882a593Smuzhiyun {
284*4882a593Smuzhiyun switch (session->l2specific_type) {
285*4882a593Smuzhiyun case L2TP_L2SPECTYPE_DEFAULT:
286*4882a593Smuzhiyun return 4;
287*4882a593Smuzhiyun case L2TP_L2SPECTYPE_NONE:
288*4882a593Smuzhiyun default:
289*4882a593Smuzhiyun return 0;
290*4882a593Smuzhiyun }
291*4882a593Smuzhiyun }
292*4882a593Smuzhiyun
l2tp_tunnel_dst_mtu(const struct l2tp_tunnel * tunnel)293*4882a593Smuzhiyun static inline u32 l2tp_tunnel_dst_mtu(const struct l2tp_tunnel *tunnel)
294*4882a593Smuzhiyun {
295*4882a593Smuzhiyun struct dst_entry *dst;
296*4882a593Smuzhiyun u32 mtu;
297*4882a593Smuzhiyun
298*4882a593Smuzhiyun dst = sk_dst_get(tunnel->sock);
299*4882a593Smuzhiyun if (!dst)
300*4882a593Smuzhiyun return 0;
301*4882a593Smuzhiyun
302*4882a593Smuzhiyun mtu = dst_mtu(dst);
303*4882a593Smuzhiyun dst_release(dst);
304*4882a593Smuzhiyun
305*4882a593Smuzhiyun return mtu;
306*4882a593Smuzhiyun }
307*4882a593Smuzhiyun
308*4882a593Smuzhiyun #ifdef CONFIG_XFRM
l2tp_tunnel_uses_xfrm(const struct l2tp_tunnel * tunnel)309*4882a593Smuzhiyun static inline bool l2tp_tunnel_uses_xfrm(const struct l2tp_tunnel *tunnel)
310*4882a593Smuzhiyun {
311*4882a593Smuzhiyun struct sock *sk = tunnel->sock;
312*4882a593Smuzhiyun
313*4882a593Smuzhiyun return sk && (rcu_access_pointer(sk->sk_policy[0]) ||
314*4882a593Smuzhiyun rcu_access_pointer(sk->sk_policy[1]));
315*4882a593Smuzhiyun }
316*4882a593Smuzhiyun #else
l2tp_tunnel_uses_xfrm(const struct l2tp_tunnel * tunnel)317*4882a593Smuzhiyun static inline bool l2tp_tunnel_uses_xfrm(const struct l2tp_tunnel *tunnel)
318*4882a593Smuzhiyun {
319*4882a593Smuzhiyun return false;
320*4882a593Smuzhiyun }
321*4882a593Smuzhiyun #endif
322*4882a593Smuzhiyun
l2tp_v3_ensure_opt_in_linear(struct l2tp_session * session,struct sk_buff * skb,unsigned char ** ptr,unsigned char ** optr)323*4882a593Smuzhiyun static inline int l2tp_v3_ensure_opt_in_linear(struct l2tp_session *session, struct sk_buff *skb,
324*4882a593Smuzhiyun unsigned char **ptr, unsigned char **optr)
325*4882a593Smuzhiyun {
326*4882a593Smuzhiyun int opt_len = session->peer_cookie_len + l2tp_get_l2specific_len(session);
327*4882a593Smuzhiyun
328*4882a593Smuzhiyun if (opt_len > 0) {
329*4882a593Smuzhiyun int off = *ptr - *optr;
330*4882a593Smuzhiyun
331*4882a593Smuzhiyun if (!pskb_may_pull(skb, off + opt_len))
332*4882a593Smuzhiyun return -1;
333*4882a593Smuzhiyun
334*4882a593Smuzhiyun if (skb->data != *optr) {
335*4882a593Smuzhiyun *optr = skb->data;
336*4882a593Smuzhiyun *ptr = skb->data + off;
337*4882a593Smuzhiyun }
338*4882a593Smuzhiyun }
339*4882a593Smuzhiyun
340*4882a593Smuzhiyun return 0;
341*4882a593Smuzhiyun }
342*4882a593Smuzhiyun
343*4882a593Smuzhiyun #define MODULE_ALIAS_L2TP_PWTYPE(type) \
344*4882a593Smuzhiyun MODULE_ALIAS("net-l2tp-type-" __stringify(type))
345*4882a593Smuzhiyun
346*4882a593Smuzhiyun #endif /* _L2TP_CORE_H_ */
347