1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun *
4*4882a593Smuzhiyun * Copyright Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
5*4882a593Smuzhiyun * Copyright Darryl Miles G7LED (dlm@g7led.demon.co.uk)
6*4882a593Smuzhiyun */
7*4882a593Smuzhiyun #include <linux/errno.h>
8*4882a593Smuzhiyun #include <linux/types.h>
9*4882a593Smuzhiyun #include <linux/socket.h>
10*4882a593Smuzhiyun #include <linux/in.h>
11*4882a593Smuzhiyun #include <linux/kernel.h>
12*4882a593Smuzhiyun #include <linux/timer.h>
13*4882a593Smuzhiyun #include <linux/string.h>
14*4882a593Smuzhiyun #include <linux/sockios.h>
15*4882a593Smuzhiyun #include <linux/net.h>
16*4882a593Smuzhiyun #include <linux/slab.h>
17*4882a593Smuzhiyun #include <net/ax25.h>
18*4882a593Smuzhiyun #include <linux/inet.h>
19*4882a593Smuzhiyun #include <linux/netdevice.h>
20*4882a593Smuzhiyun #include <linux/skbuff.h>
21*4882a593Smuzhiyun #include <net/sock.h>
22*4882a593Smuzhiyun #include <net/tcp_states.h>
23*4882a593Smuzhiyun #include <linux/uaccess.h>
24*4882a593Smuzhiyun #include <linux/fcntl.h>
25*4882a593Smuzhiyun #include <linux/mm.h>
26*4882a593Smuzhiyun #include <linux/interrupt.h>
27*4882a593Smuzhiyun #include <net/netrom.h>
28*4882a593Smuzhiyun
nr_queue_rx_frame(struct sock * sk,struct sk_buff * skb,int more)29*4882a593Smuzhiyun static int nr_queue_rx_frame(struct sock *sk, struct sk_buff *skb, int more)
30*4882a593Smuzhiyun {
31*4882a593Smuzhiyun struct sk_buff *skbo, *skbn = skb;
32*4882a593Smuzhiyun struct nr_sock *nr = nr_sk(sk);
33*4882a593Smuzhiyun
34*4882a593Smuzhiyun skb_pull(skb, NR_NETWORK_LEN + NR_TRANSPORT_LEN);
35*4882a593Smuzhiyun
36*4882a593Smuzhiyun nr_start_idletimer(sk);
37*4882a593Smuzhiyun
38*4882a593Smuzhiyun if (more) {
39*4882a593Smuzhiyun nr->fraglen += skb->len;
40*4882a593Smuzhiyun skb_queue_tail(&nr->frag_queue, skb);
41*4882a593Smuzhiyun return 0;
42*4882a593Smuzhiyun }
43*4882a593Smuzhiyun
44*4882a593Smuzhiyun if (!more && nr->fraglen > 0) { /* End of fragment */
45*4882a593Smuzhiyun nr->fraglen += skb->len;
46*4882a593Smuzhiyun skb_queue_tail(&nr->frag_queue, skb);
47*4882a593Smuzhiyun
48*4882a593Smuzhiyun if ((skbn = alloc_skb(nr->fraglen, GFP_ATOMIC)) == NULL)
49*4882a593Smuzhiyun return 1;
50*4882a593Smuzhiyun
51*4882a593Smuzhiyun skb_reset_transport_header(skbn);
52*4882a593Smuzhiyun
53*4882a593Smuzhiyun while ((skbo = skb_dequeue(&nr->frag_queue)) != NULL) {
54*4882a593Smuzhiyun skb_copy_from_linear_data(skbo,
55*4882a593Smuzhiyun skb_put(skbn, skbo->len),
56*4882a593Smuzhiyun skbo->len);
57*4882a593Smuzhiyun kfree_skb(skbo);
58*4882a593Smuzhiyun }
59*4882a593Smuzhiyun
60*4882a593Smuzhiyun nr->fraglen = 0;
61*4882a593Smuzhiyun }
62*4882a593Smuzhiyun
63*4882a593Smuzhiyun return sock_queue_rcv_skb(sk, skbn);
64*4882a593Smuzhiyun }
65*4882a593Smuzhiyun
66*4882a593Smuzhiyun /*
67*4882a593Smuzhiyun * State machine for state 1, Awaiting Connection State.
68*4882a593Smuzhiyun * The handling of the timer(s) is in file nr_timer.c.
69*4882a593Smuzhiyun * Handling of state 0 and connection release is in netrom.c.
70*4882a593Smuzhiyun */
nr_state1_machine(struct sock * sk,struct sk_buff * skb,int frametype)71*4882a593Smuzhiyun static int nr_state1_machine(struct sock *sk, struct sk_buff *skb,
72*4882a593Smuzhiyun int frametype)
73*4882a593Smuzhiyun {
74*4882a593Smuzhiyun switch (frametype) {
75*4882a593Smuzhiyun case NR_CONNACK: {
76*4882a593Smuzhiyun struct nr_sock *nr = nr_sk(sk);
77*4882a593Smuzhiyun
78*4882a593Smuzhiyun nr_stop_t1timer(sk);
79*4882a593Smuzhiyun nr_start_idletimer(sk);
80*4882a593Smuzhiyun nr->your_index = skb->data[17];
81*4882a593Smuzhiyun nr->your_id = skb->data[18];
82*4882a593Smuzhiyun nr->vs = 0;
83*4882a593Smuzhiyun nr->va = 0;
84*4882a593Smuzhiyun nr->vr = 0;
85*4882a593Smuzhiyun nr->vl = 0;
86*4882a593Smuzhiyun nr->state = NR_STATE_3;
87*4882a593Smuzhiyun nr->n2count = 0;
88*4882a593Smuzhiyun nr->window = skb->data[20];
89*4882a593Smuzhiyun sk->sk_state = TCP_ESTABLISHED;
90*4882a593Smuzhiyun if (!sock_flag(sk, SOCK_DEAD))
91*4882a593Smuzhiyun sk->sk_state_change(sk);
92*4882a593Smuzhiyun break;
93*4882a593Smuzhiyun }
94*4882a593Smuzhiyun
95*4882a593Smuzhiyun case NR_CONNACK | NR_CHOKE_FLAG:
96*4882a593Smuzhiyun nr_disconnect(sk, ECONNREFUSED);
97*4882a593Smuzhiyun break;
98*4882a593Smuzhiyun
99*4882a593Smuzhiyun case NR_RESET:
100*4882a593Smuzhiyun if (sysctl_netrom_reset_circuit)
101*4882a593Smuzhiyun nr_disconnect(sk, ECONNRESET);
102*4882a593Smuzhiyun break;
103*4882a593Smuzhiyun
104*4882a593Smuzhiyun default:
105*4882a593Smuzhiyun break;
106*4882a593Smuzhiyun }
107*4882a593Smuzhiyun return 0;
108*4882a593Smuzhiyun }
109*4882a593Smuzhiyun
110*4882a593Smuzhiyun /*
111*4882a593Smuzhiyun * State machine for state 2, Awaiting Release State.
112*4882a593Smuzhiyun * The handling of the timer(s) is in file nr_timer.c
113*4882a593Smuzhiyun * Handling of state 0 and connection release is in netrom.c.
114*4882a593Smuzhiyun */
nr_state2_machine(struct sock * sk,struct sk_buff * skb,int frametype)115*4882a593Smuzhiyun static int nr_state2_machine(struct sock *sk, struct sk_buff *skb,
116*4882a593Smuzhiyun int frametype)
117*4882a593Smuzhiyun {
118*4882a593Smuzhiyun switch (frametype) {
119*4882a593Smuzhiyun case NR_CONNACK | NR_CHOKE_FLAG:
120*4882a593Smuzhiyun nr_disconnect(sk, ECONNRESET);
121*4882a593Smuzhiyun break;
122*4882a593Smuzhiyun
123*4882a593Smuzhiyun case NR_DISCREQ:
124*4882a593Smuzhiyun nr_write_internal(sk, NR_DISCACK);
125*4882a593Smuzhiyun fallthrough;
126*4882a593Smuzhiyun case NR_DISCACK:
127*4882a593Smuzhiyun nr_disconnect(sk, 0);
128*4882a593Smuzhiyun break;
129*4882a593Smuzhiyun
130*4882a593Smuzhiyun case NR_RESET:
131*4882a593Smuzhiyun if (sysctl_netrom_reset_circuit)
132*4882a593Smuzhiyun nr_disconnect(sk, ECONNRESET);
133*4882a593Smuzhiyun break;
134*4882a593Smuzhiyun
135*4882a593Smuzhiyun default:
136*4882a593Smuzhiyun break;
137*4882a593Smuzhiyun }
138*4882a593Smuzhiyun return 0;
139*4882a593Smuzhiyun }
140*4882a593Smuzhiyun
141*4882a593Smuzhiyun /*
142*4882a593Smuzhiyun * State machine for state 3, Connected State.
143*4882a593Smuzhiyun * The handling of the timer(s) is in file nr_timer.c
144*4882a593Smuzhiyun * Handling of state 0 and connection release is in netrom.c.
145*4882a593Smuzhiyun */
nr_state3_machine(struct sock * sk,struct sk_buff * skb,int frametype)146*4882a593Smuzhiyun static int nr_state3_machine(struct sock *sk, struct sk_buff *skb, int frametype)
147*4882a593Smuzhiyun {
148*4882a593Smuzhiyun struct nr_sock *nrom = nr_sk(sk);
149*4882a593Smuzhiyun struct sk_buff_head temp_queue;
150*4882a593Smuzhiyun struct sk_buff *skbn;
151*4882a593Smuzhiyun unsigned short save_vr;
152*4882a593Smuzhiyun unsigned short nr, ns;
153*4882a593Smuzhiyun int queued = 0;
154*4882a593Smuzhiyun
155*4882a593Smuzhiyun nr = skb->data[18];
156*4882a593Smuzhiyun ns = skb->data[17];
157*4882a593Smuzhiyun
158*4882a593Smuzhiyun switch (frametype) {
159*4882a593Smuzhiyun case NR_CONNREQ:
160*4882a593Smuzhiyun nr_write_internal(sk, NR_CONNACK);
161*4882a593Smuzhiyun break;
162*4882a593Smuzhiyun
163*4882a593Smuzhiyun case NR_DISCREQ:
164*4882a593Smuzhiyun nr_write_internal(sk, NR_DISCACK);
165*4882a593Smuzhiyun nr_disconnect(sk, 0);
166*4882a593Smuzhiyun break;
167*4882a593Smuzhiyun
168*4882a593Smuzhiyun case NR_CONNACK | NR_CHOKE_FLAG:
169*4882a593Smuzhiyun case NR_DISCACK:
170*4882a593Smuzhiyun nr_disconnect(sk, ECONNRESET);
171*4882a593Smuzhiyun break;
172*4882a593Smuzhiyun
173*4882a593Smuzhiyun case NR_INFOACK:
174*4882a593Smuzhiyun case NR_INFOACK | NR_CHOKE_FLAG:
175*4882a593Smuzhiyun case NR_INFOACK | NR_NAK_FLAG:
176*4882a593Smuzhiyun case NR_INFOACK | NR_NAK_FLAG | NR_CHOKE_FLAG:
177*4882a593Smuzhiyun if (frametype & NR_CHOKE_FLAG) {
178*4882a593Smuzhiyun nrom->condition |= NR_COND_PEER_RX_BUSY;
179*4882a593Smuzhiyun nr_start_t4timer(sk);
180*4882a593Smuzhiyun } else {
181*4882a593Smuzhiyun nrom->condition &= ~NR_COND_PEER_RX_BUSY;
182*4882a593Smuzhiyun nr_stop_t4timer(sk);
183*4882a593Smuzhiyun }
184*4882a593Smuzhiyun if (!nr_validate_nr(sk, nr)) {
185*4882a593Smuzhiyun break;
186*4882a593Smuzhiyun }
187*4882a593Smuzhiyun if (frametype & NR_NAK_FLAG) {
188*4882a593Smuzhiyun nr_frames_acked(sk, nr);
189*4882a593Smuzhiyun nr_send_nak_frame(sk);
190*4882a593Smuzhiyun } else {
191*4882a593Smuzhiyun if (nrom->condition & NR_COND_PEER_RX_BUSY) {
192*4882a593Smuzhiyun nr_frames_acked(sk, nr);
193*4882a593Smuzhiyun } else {
194*4882a593Smuzhiyun nr_check_iframes_acked(sk, nr);
195*4882a593Smuzhiyun }
196*4882a593Smuzhiyun }
197*4882a593Smuzhiyun break;
198*4882a593Smuzhiyun
199*4882a593Smuzhiyun case NR_INFO:
200*4882a593Smuzhiyun case NR_INFO | NR_NAK_FLAG:
201*4882a593Smuzhiyun case NR_INFO | NR_CHOKE_FLAG:
202*4882a593Smuzhiyun case NR_INFO | NR_MORE_FLAG:
203*4882a593Smuzhiyun case NR_INFO | NR_NAK_FLAG | NR_CHOKE_FLAG:
204*4882a593Smuzhiyun case NR_INFO | NR_CHOKE_FLAG | NR_MORE_FLAG:
205*4882a593Smuzhiyun case NR_INFO | NR_NAK_FLAG | NR_MORE_FLAG:
206*4882a593Smuzhiyun case NR_INFO | NR_NAK_FLAG | NR_CHOKE_FLAG | NR_MORE_FLAG:
207*4882a593Smuzhiyun if (frametype & NR_CHOKE_FLAG) {
208*4882a593Smuzhiyun nrom->condition |= NR_COND_PEER_RX_BUSY;
209*4882a593Smuzhiyun nr_start_t4timer(sk);
210*4882a593Smuzhiyun } else {
211*4882a593Smuzhiyun nrom->condition &= ~NR_COND_PEER_RX_BUSY;
212*4882a593Smuzhiyun nr_stop_t4timer(sk);
213*4882a593Smuzhiyun }
214*4882a593Smuzhiyun if (nr_validate_nr(sk, nr)) {
215*4882a593Smuzhiyun if (frametype & NR_NAK_FLAG) {
216*4882a593Smuzhiyun nr_frames_acked(sk, nr);
217*4882a593Smuzhiyun nr_send_nak_frame(sk);
218*4882a593Smuzhiyun } else {
219*4882a593Smuzhiyun if (nrom->condition & NR_COND_PEER_RX_BUSY) {
220*4882a593Smuzhiyun nr_frames_acked(sk, nr);
221*4882a593Smuzhiyun } else {
222*4882a593Smuzhiyun nr_check_iframes_acked(sk, nr);
223*4882a593Smuzhiyun }
224*4882a593Smuzhiyun }
225*4882a593Smuzhiyun }
226*4882a593Smuzhiyun queued = 1;
227*4882a593Smuzhiyun skb_queue_head(&nrom->reseq_queue, skb);
228*4882a593Smuzhiyun if (nrom->condition & NR_COND_OWN_RX_BUSY)
229*4882a593Smuzhiyun break;
230*4882a593Smuzhiyun skb_queue_head_init(&temp_queue);
231*4882a593Smuzhiyun do {
232*4882a593Smuzhiyun save_vr = nrom->vr;
233*4882a593Smuzhiyun while ((skbn = skb_dequeue(&nrom->reseq_queue)) != NULL) {
234*4882a593Smuzhiyun ns = skbn->data[17];
235*4882a593Smuzhiyun if (ns == nrom->vr) {
236*4882a593Smuzhiyun if (nr_queue_rx_frame(sk, skbn, frametype & NR_MORE_FLAG) == 0) {
237*4882a593Smuzhiyun nrom->vr = (nrom->vr + 1) % NR_MODULUS;
238*4882a593Smuzhiyun } else {
239*4882a593Smuzhiyun nrom->condition |= NR_COND_OWN_RX_BUSY;
240*4882a593Smuzhiyun skb_queue_tail(&temp_queue, skbn);
241*4882a593Smuzhiyun }
242*4882a593Smuzhiyun } else if (nr_in_rx_window(sk, ns)) {
243*4882a593Smuzhiyun skb_queue_tail(&temp_queue, skbn);
244*4882a593Smuzhiyun } else {
245*4882a593Smuzhiyun kfree_skb(skbn);
246*4882a593Smuzhiyun }
247*4882a593Smuzhiyun }
248*4882a593Smuzhiyun while ((skbn = skb_dequeue(&temp_queue)) != NULL) {
249*4882a593Smuzhiyun skb_queue_tail(&nrom->reseq_queue, skbn);
250*4882a593Smuzhiyun }
251*4882a593Smuzhiyun } while (save_vr != nrom->vr);
252*4882a593Smuzhiyun /*
253*4882a593Smuzhiyun * Window is full, ack it immediately.
254*4882a593Smuzhiyun */
255*4882a593Smuzhiyun if (((nrom->vl + nrom->window) % NR_MODULUS) == nrom->vr) {
256*4882a593Smuzhiyun nr_enquiry_response(sk);
257*4882a593Smuzhiyun } else {
258*4882a593Smuzhiyun if (!(nrom->condition & NR_COND_ACK_PENDING)) {
259*4882a593Smuzhiyun nrom->condition |= NR_COND_ACK_PENDING;
260*4882a593Smuzhiyun nr_start_t2timer(sk);
261*4882a593Smuzhiyun }
262*4882a593Smuzhiyun }
263*4882a593Smuzhiyun break;
264*4882a593Smuzhiyun
265*4882a593Smuzhiyun case NR_RESET:
266*4882a593Smuzhiyun if (sysctl_netrom_reset_circuit)
267*4882a593Smuzhiyun nr_disconnect(sk, ECONNRESET);
268*4882a593Smuzhiyun break;
269*4882a593Smuzhiyun
270*4882a593Smuzhiyun default:
271*4882a593Smuzhiyun break;
272*4882a593Smuzhiyun }
273*4882a593Smuzhiyun return queued;
274*4882a593Smuzhiyun }
275*4882a593Smuzhiyun
276*4882a593Smuzhiyun /* Higher level upcall for a LAPB frame - called with sk locked */
nr_process_rx_frame(struct sock * sk,struct sk_buff * skb)277*4882a593Smuzhiyun int nr_process_rx_frame(struct sock *sk, struct sk_buff *skb)
278*4882a593Smuzhiyun {
279*4882a593Smuzhiyun struct nr_sock *nr = nr_sk(sk);
280*4882a593Smuzhiyun int queued = 0, frametype;
281*4882a593Smuzhiyun
282*4882a593Smuzhiyun if (nr->state == NR_STATE_0)
283*4882a593Smuzhiyun return 0;
284*4882a593Smuzhiyun
285*4882a593Smuzhiyun frametype = skb->data[19];
286*4882a593Smuzhiyun
287*4882a593Smuzhiyun switch (nr->state) {
288*4882a593Smuzhiyun case NR_STATE_1:
289*4882a593Smuzhiyun queued = nr_state1_machine(sk, skb, frametype);
290*4882a593Smuzhiyun break;
291*4882a593Smuzhiyun case NR_STATE_2:
292*4882a593Smuzhiyun queued = nr_state2_machine(sk, skb, frametype);
293*4882a593Smuzhiyun break;
294*4882a593Smuzhiyun case NR_STATE_3:
295*4882a593Smuzhiyun queued = nr_state3_machine(sk, skb, frametype);
296*4882a593Smuzhiyun break;
297*4882a593Smuzhiyun }
298*4882a593Smuzhiyun
299*4882a593Smuzhiyun nr_kick(sk);
300*4882a593Smuzhiyun
301*4882a593Smuzhiyun return queued;
302*4882a593Smuzhiyun }
303