xref: /OK3568_Linux_fs/kernel/net/phonet/pep.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-only
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * File: pep.c
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * Phonet pipe protocol end point socket
6*4882a593Smuzhiyun  *
7*4882a593Smuzhiyun  * Copyright (C) 2008 Nokia Corporation.
8*4882a593Smuzhiyun  *
9*4882a593Smuzhiyun  * Author: Rémi Denis-Courmont
10*4882a593Smuzhiyun  */
11*4882a593Smuzhiyun 
12*4882a593Smuzhiyun #include <linux/kernel.h>
13*4882a593Smuzhiyun #include <linux/sched/signal.h>
14*4882a593Smuzhiyun #include <linux/slab.h>
15*4882a593Smuzhiyun #include <linux/socket.h>
16*4882a593Smuzhiyun #include <net/sock.h>
17*4882a593Smuzhiyun #include <net/tcp_states.h>
18*4882a593Smuzhiyun #include <asm/ioctls.h>
19*4882a593Smuzhiyun 
20*4882a593Smuzhiyun #include <linux/phonet.h>
21*4882a593Smuzhiyun #include <linux/module.h>
22*4882a593Smuzhiyun #include <net/phonet/phonet.h>
23*4882a593Smuzhiyun #include <net/phonet/pep.h>
24*4882a593Smuzhiyun #include <net/phonet/gprs.h>
25*4882a593Smuzhiyun 
26*4882a593Smuzhiyun /* sk_state values:
27*4882a593Smuzhiyun  * TCP_CLOSE		sock not in use yet
28*4882a593Smuzhiyun  * TCP_CLOSE_WAIT	disconnected pipe
29*4882a593Smuzhiyun  * TCP_LISTEN		listening pipe endpoint
30*4882a593Smuzhiyun  * TCP_SYN_RECV		connected pipe in disabled state
31*4882a593Smuzhiyun  * TCP_ESTABLISHED	connected pipe in enabled state
32*4882a593Smuzhiyun  *
33*4882a593Smuzhiyun  * pep_sock locking:
34*4882a593Smuzhiyun  *  - sk_state, hlist: sock lock needed
35*4882a593Smuzhiyun  *  - listener: read only
36*4882a593Smuzhiyun  *  - pipe_handle: read only
37*4882a593Smuzhiyun  */
38*4882a593Smuzhiyun 
39*4882a593Smuzhiyun #define CREDITS_MAX	10
40*4882a593Smuzhiyun #define CREDITS_THR	7
41*4882a593Smuzhiyun 
42*4882a593Smuzhiyun #define pep_sb_size(s) (((s) + 5) & ~3) /* 2-bytes head, 32-bits aligned */
43*4882a593Smuzhiyun 
44*4882a593Smuzhiyun /* Get the next TLV sub-block. */
pep_get_sb(struct sk_buff * skb,u8 * ptype,u8 * plen,void * buf)45*4882a593Smuzhiyun static unsigned char *pep_get_sb(struct sk_buff *skb, u8 *ptype, u8 *plen,
46*4882a593Smuzhiyun 					void *buf)
47*4882a593Smuzhiyun {
48*4882a593Smuzhiyun 	void *data = NULL;
49*4882a593Smuzhiyun 	struct {
50*4882a593Smuzhiyun 		u8 sb_type;
51*4882a593Smuzhiyun 		u8 sb_len;
52*4882a593Smuzhiyun 	} *ph, h;
53*4882a593Smuzhiyun 	int buflen = *plen;
54*4882a593Smuzhiyun 
55*4882a593Smuzhiyun 	ph = skb_header_pointer(skb, 0, 2, &h);
56*4882a593Smuzhiyun 	if (ph == NULL || ph->sb_len < 2 || !pskb_may_pull(skb, ph->sb_len))
57*4882a593Smuzhiyun 		return NULL;
58*4882a593Smuzhiyun 	ph->sb_len -= 2;
59*4882a593Smuzhiyun 	*ptype = ph->sb_type;
60*4882a593Smuzhiyun 	*plen = ph->sb_len;
61*4882a593Smuzhiyun 
62*4882a593Smuzhiyun 	if (buflen > ph->sb_len)
63*4882a593Smuzhiyun 		buflen = ph->sb_len;
64*4882a593Smuzhiyun 	data = skb_header_pointer(skb, 2, buflen, buf);
65*4882a593Smuzhiyun 	__skb_pull(skb, 2 + ph->sb_len);
66*4882a593Smuzhiyun 	return data;
67*4882a593Smuzhiyun }
68*4882a593Smuzhiyun 
pep_alloc_skb(struct sock * sk,const void * payload,int len,gfp_t priority)69*4882a593Smuzhiyun static struct sk_buff *pep_alloc_skb(struct sock *sk, const void *payload,
70*4882a593Smuzhiyun 					int len, gfp_t priority)
71*4882a593Smuzhiyun {
72*4882a593Smuzhiyun 	struct sk_buff *skb = alloc_skb(MAX_PNPIPE_HEADER + len, priority);
73*4882a593Smuzhiyun 	if (!skb)
74*4882a593Smuzhiyun 		return NULL;
75*4882a593Smuzhiyun 	skb_set_owner_w(skb, sk);
76*4882a593Smuzhiyun 
77*4882a593Smuzhiyun 	skb_reserve(skb, MAX_PNPIPE_HEADER);
78*4882a593Smuzhiyun 	__skb_put(skb, len);
79*4882a593Smuzhiyun 	skb_copy_to_linear_data(skb, payload, len);
80*4882a593Smuzhiyun 	__skb_push(skb, sizeof(struct pnpipehdr));
81*4882a593Smuzhiyun 	skb_reset_transport_header(skb);
82*4882a593Smuzhiyun 	return skb;
83*4882a593Smuzhiyun }
84*4882a593Smuzhiyun 
pep_reply(struct sock * sk,struct sk_buff * oskb,u8 code,const void * data,int len,gfp_t priority)85*4882a593Smuzhiyun static int pep_reply(struct sock *sk, struct sk_buff *oskb, u8 code,
86*4882a593Smuzhiyun 			const void *data, int len, gfp_t priority)
87*4882a593Smuzhiyun {
88*4882a593Smuzhiyun 	const struct pnpipehdr *oph = pnp_hdr(oskb);
89*4882a593Smuzhiyun 	struct pnpipehdr *ph;
90*4882a593Smuzhiyun 	struct sk_buff *skb;
91*4882a593Smuzhiyun 	struct sockaddr_pn peer;
92*4882a593Smuzhiyun 
93*4882a593Smuzhiyun 	skb = pep_alloc_skb(sk, data, len, priority);
94*4882a593Smuzhiyun 	if (!skb)
95*4882a593Smuzhiyun 		return -ENOMEM;
96*4882a593Smuzhiyun 
97*4882a593Smuzhiyun 	ph = pnp_hdr(skb);
98*4882a593Smuzhiyun 	ph->utid = oph->utid;
99*4882a593Smuzhiyun 	ph->message_id = oph->message_id + 1; /* REQ -> RESP */
100*4882a593Smuzhiyun 	ph->pipe_handle = oph->pipe_handle;
101*4882a593Smuzhiyun 	ph->error_code = code;
102*4882a593Smuzhiyun 
103*4882a593Smuzhiyun 	pn_skb_get_src_sockaddr(oskb, &peer);
104*4882a593Smuzhiyun 	return pn_skb_send(sk, skb, &peer);
105*4882a593Smuzhiyun }
106*4882a593Smuzhiyun 
pep_indicate(struct sock * sk,u8 id,u8 code,const void * data,int len,gfp_t priority)107*4882a593Smuzhiyun static int pep_indicate(struct sock *sk, u8 id, u8 code,
108*4882a593Smuzhiyun 			const void *data, int len, gfp_t priority)
109*4882a593Smuzhiyun {
110*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
111*4882a593Smuzhiyun 	struct pnpipehdr *ph;
112*4882a593Smuzhiyun 	struct sk_buff *skb;
113*4882a593Smuzhiyun 
114*4882a593Smuzhiyun 	skb = pep_alloc_skb(sk, data, len, priority);
115*4882a593Smuzhiyun 	if (!skb)
116*4882a593Smuzhiyun 		return -ENOMEM;
117*4882a593Smuzhiyun 
118*4882a593Smuzhiyun 	ph = pnp_hdr(skb);
119*4882a593Smuzhiyun 	ph->utid = 0;
120*4882a593Smuzhiyun 	ph->message_id = id;
121*4882a593Smuzhiyun 	ph->pipe_handle = pn->pipe_handle;
122*4882a593Smuzhiyun 	ph->error_code = code;
123*4882a593Smuzhiyun 	return pn_skb_send(sk, skb, NULL);
124*4882a593Smuzhiyun }
125*4882a593Smuzhiyun 
126*4882a593Smuzhiyun #define PAD 0x00
127*4882a593Smuzhiyun 
pipe_handler_request(struct sock * sk,u8 id,u8 code,const void * data,int len)128*4882a593Smuzhiyun static int pipe_handler_request(struct sock *sk, u8 id, u8 code,
129*4882a593Smuzhiyun 				const void *data, int len)
130*4882a593Smuzhiyun {
131*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
132*4882a593Smuzhiyun 	struct pnpipehdr *ph;
133*4882a593Smuzhiyun 	struct sk_buff *skb;
134*4882a593Smuzhiyun 
135*4882a593Smuzhiyun 	skb = pep_alloc_skb(sk, data, len, GFP_KERNEL);
136*4882a593Smuzhiyun 	if (!skb)
137*4882a593Smuzhiyun 		return -ENOMEM;
138*4882a593Smuzhiyun 
139*4882a593Smuzhiyun 	ph = pnp_hdr(skb);
140*4882a593Smuzhiyun 	ph->utid = id; /* whatever */
141*4882a593Smuzhiyun 	ph->message_id = id;
142*4882a593Smuzhiyun 	ph->pipe_handle = pn->pipe_handle;
143*4882a593Smuzhiyun 	ph->error_code = code;
144*4882a593Smuzhiyun 	return pn_skb_send(sk, skb, NULL);
145*4882a593Smuzhiyun }
146*4882a593Smuzhiyun 
pipe_handler_send_created_ind(struct sock * sk)147*4882a593Smuzhiyun static int pipe_handler_send_created_ind(struct sock *sk)
148*4882a593Smuzhiyun {
149*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
150*4882a593Smuzhiyun 	u8 data[4] = {
151*4882a593Smuzhiyun 		PN_PIPE_SB_NEGOTIATED_FC, pep_sb_size(2),
152*4882a593Smuzhiyun 		pn->tx_fc, pn->rx_fc,
153*4882a593Smuzhiyun 	};
154*4882a593Smuzhiyun 
155*4882a593Smuzhiyun 	return pep_indicate(sk, PNS_PIPE_CREATED_IND, 1 /* sub-blocks */,
156*4882a593Smuzhiyun 				data, 4, GFP_ATOMIC);
157*4882a593Smuzhiyun }
158*4882a593Smuzhiyun 
pep_accept_conn(struct sock * sk,struct sk_buff * skb)159*4882a593Smuzhiyun static int pep_accept_conn(struct sock *sk, struct sk_buff *skb)
160*4882a593Smuzhiyun {
161*4882a593Smuzhiyun 	static const u8 data[20] = {
162*4882a593Smuzhiyun 		PAD, PAD, PAD, 2 /* sub-blocks */,
163*4882a593Smuzhiyun 		PN_PIPE_SB_REQUIRED_FC_TX, pep_sb_size(5), 3, PAD,
164*4882a593Smuzhiyun 			PN_MULTI_CREDIT_FLOW_CONTROL,
165*4882a593Smuzhiyun 			PN_ONE_CREDIT_FLOW_CONTROL,
166*4882a593Smuzhiyun 			PN_LEGACY_FLOW_CONTROL,
167*4882a593Smuzhiyun 			PAD,
168*4882a593Smuzhiyun 		PN_PIPE_SB_PREFERRED_FC_RX, pep_sb_size(5), 3, PAD,
169*4882a593Smuzhiyun 			PN_MULTI_CREDIT_FLOW_CONTROL,
170*4882a593Smuzhiyun 			PN_ONE_CREDIT_FLOW_CONTROL,
171*4882a593Smuzhiyun 			PN_LEGACY_FLOW_CONTROL,
172*4882a593Smuzhiyun 			PAD,
173*4882a593Smuzhiyun 	};
174*4882a593Smuzhiyun 
175*4882a593Smuzhiyun 	might_sleep();
176*4882a593Smuzhiyun 	return pep_reply(sk, skb, PN_PIPE_NO_ERROR, data, sizeof(data),
177*4882a593Smuzhiyun 				GFP_KERNEL);
178*4882a593Smuzhiyun }
179*4882a593Smuzhiyun 
pep_reject_conn(struct sock * sk,struct sk_buff * skb,u8 code,gfp_t priority)180*4882a593Smuzhiyun static int pep_reject_conn(struct sock *sk, struct sk_buff *skb, u8 code,
181*4882a593Smuzhiyun 				gfp_t priority)
182*4882a593Smuzhiyun {
183*4882a593Smuzhiyun 	static const u8 data[4] = { PAD, PAD, PAD, 0 /* sub-blocks */ };
184*4882a593Smuzhiyun 	WARN_ON(code == PN_PIPE_NO_ERROR);
185*4882a593Smuzhiyun 	return pep_reply(sk, skb, code, data, sizeof(data), priority);
186*4882a593Smuzhiyun }
187*4882a593Smuzhiyun 
188*4882a593Smuzhiyun /* Control requests are not sent by the pipe service and have a specific
189*4882a593Smuzhiyun  * message format. */
pep_ctrlreq_error(struct sock * sk,struct sk_buff * oskb,u8 code,gfp_t priority)190*4882a593Smuzhiyun static int pep_ctrlreq_error(struct sock *sk, struct sk_buff *oskb, u8 code,
191*4882a593Smuzhiyun 				gfp_t priority)
192*4882a593Smuzhiyun {
193*4882a593Smuzhiyun 	const struct pnpipehdr *oph = pnp_hdr(oskb);
194*4882a593Smuzhiyun 	struct sk_buff *skb;
195*4882a593Smuzhiyun 	struct pnpipehdr *ph;
196*4882a593Smuzhiyun 	struct sockaddr_pn dst;
197*4882a593Smuzhiyun 	u8 data[4] = {
198*4882a593Smuzhiyun 		oph->pep_type, /* PEP type */
199*4882a593Smuzhiyun 		code, /* error code, at an unusual offset */
200*4882a593Smuzhiyun 		PAD, PAD,
201*4882a593Smuzhiyun 	};
202*4882a593Smuzhiyun 
203*4882a593Smuzhiyun 	skb = pep_alloc_skb(sk, data, 4, priority);
204*4882a593Smuzhiyun 	if (!skb)
205*4882a593Smuzhiyun 		return -ENOMEM;
206*4882a593Smuzhiyun 
207*4882a593Smuzhiyun 	ph = pnp_hdr(skb);
208*4882a593Smuzhiyun 	ph->utid = oph->utid;
209*4882a593Smuzhiyun 	ph->message_id = PNS_PEP_CTRL_RESP;
210*4882a593Smuzhiyun 	ph->pipe_handle = oph->pipe_handle;
211*4882a593Smuzhiyun 	ph->data0 = oph->data[0]; /* CTRL id */
212*4882a593Smuzhiyun 
213*4882a593Smuzhiyun 	pn_skb_get_src_sockaddr(oskb, &dst);
214*4882a593Smuzhiyun 	return pn_skb_send(sk, skb, &dst);
215*4882a593Smuzhiyun }
216*4882a593Smuzhiyun 
pipe_snd_status(struct sock * sk,u8 type,u8 status,gfp_t priority)217*4882a593Smuzhiyun static int pipe_snd_status(struct sock *sk, u8 type, u8 status, gfp_t priority)
218*4882a593Smuzhiyun {
219*4882a593Smuzhiyun 	u8 data[4] = { type, PAD, PAD, status };
220*4882a593Smuzhiyun 
221*4882a593Smuzhiyun 	return pep_indicate(sk, PNS_PEP_STATUS_IND, PN_PEP_TYPE_COMMON,
222*4882a593Smuzhiyun 				data, 4, priority);
223*4882a593Smuzhiyun }
224*4882a593Smuzhiyun 
225*4882a593Smuzhiyun /* Send our RX flow control information to the sender.
226*4882a593Smuzhiyun  * Socket must be locked. */
pipe_grant_credits(struct sock * sk,gfp_t priority)227*4882a593Smuzhiyun static void pipe_grant_credits(struct sock *sk, gfp_t priority)
228*4882a593Smuzhiyun {
229*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
230*4882a593Smuzhiyun 
231*4882a593Smuzhiyun 	BUG_ON(sk->sk_state != TCP_ESTABLISHED);
232*4882a593Smuzhiyun 
233*4882a593Smuzhiyun 	switch (pn->rx_fc) {
234*4882a593Smuzhiyun 	case PN_LEGACY_FLOW_CONTROL: /* TODO */
235*4882a593Smuzhiyun 		break;
236*4882a593Smuzhiyun 	case PN_ONE_CREDIT_FLOW_CONTROL:
237*4882a593Smuzhiyun 		if (pipe_snd_status(sk, PN_PEP_IND_FLOW_CONTROL,
238*4882a593Smuzhiyun 					PEP_IND_READY, priority) == 0)
239*4882a593Smuzhiyun 			pn->rx_credits = 1;
240*4882a593Smuzhiyun 		break;
241*4882a593Smuzhiyun 	case PN_MULTI_CREDIT_FLOW_CONTROL:
242*4882a593Smuzhiyun 		if ((pn->rx_credits + CREDITS_THR) > CREDITS_MAX)
243*4882a593Smuzhiyun 			break;
244*4882a593Smuzhiyun 		if (pipe_snd_status(sk, PN_PEP_IND_ID_MCFC_GRANT_CREDITS,
245*4882a593Smuzhiyun 					CREDITS_MAX - pn->rx_credits,
246*4882a593Smuzhiyun 					priority) == 0)
247*4882a593Smuzhiyun 			pn->rx_credits = CREDITS_MAX;
248*4882a593Smuzhiyun 		break;
249*4882a593Smuzhiyun 	}
250*4882a593Smuzhiyun }
251*4882a593Smuzhiyun 
pipe_rcv_status(struct sock * sk,struct sk_buff * skb)252*4882a593Smuzhiyun static int pipe_rcv_status(struct sock *sk, struct sk_buff *skb)
253*4882a593Smuzhiyun {
254*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
255*4882a593Smuzhiyun 	struct pnpipehdr *hdr;
256*4882a593Smuzhiyun 	int wake = 0;
257*4882a593Smuzhiyun 
258*4882a593Smuzhiyun 	if (!pskb_may_pull(skb, sizeof(*hdr) + 4))
259*4882a593Smuzhiyun 		return -EINVAL;
260*4882a593Smuzhiyun 
261*4882a593Smuzhiyun 	hdr = pnp_hdr(skb);
262*4882a593Smuzhiyun 	if (hdr->pep_type != PN_PEP_TYPE_COMMON) {
263*4882a593Smuzhiyun 		net_dbg_ratelimited("Phonet unknown PEP type: %u\n",
264*4882a593Smuzhiyun 				    (unsigned int)hdr->pep_type);
265*4882a593Smuzhiyun 		return -EOPNOTSUPP;
266*4882a593Smuzhiyun 	}
267*4882a593Smuzhiyun 
268*4882a593Smuzhiyun 	switch (hdr->data[0]) {
269*4882a593Smuzhiyun 	case PN_PEP_IND_FLOW_CONTROL:
270*4882a593Smuzhiyun 		switch (pn->tx_fc) {
271*4882a593Smuzhiyun 		case PN_LEGACY_FLOW_CONTROL:
272*4882a593Smuzhiyun 			switch (hdr->data[3]) {
273*4882a593Smuzhiyun 			case PEP_IND_BUSY:
274*4882a593Smuzhiyun 				atomic_set(&pn->tx_credits, 0);
275*4882a593Smuzhiyun 				break;
276*4882a593Smuzhiyun 			case PEP_IND_READY:
277*4882a593Smuzhiyun 				atomic_set(&pn->tx_credits, wake = 1);
278*4882a593Smuzhiyun 				break;
279*4882a593Smuzhiyun 			}
280*4882a593Smuzhiyun 			break;
281*4882a593Smuzhiyun 		case PN_ONE_CREDIT_FLOW_CONTROL:
282*4882a593Smuzhiyun 			if (hdr->data[3] == PEP_IND_READY)
283*4882a593Smuzhiyun 				atomic_set(&pn->tx_credits, wake = 1);
284*4882a593Smuzhiyun 			break;
285*4882a593Smuzhiyun 		}
286*4882a593Smuzhiyun 		break;
287*4882a593Smuzhiyun 
288*4882a593Smuzhiyun 	case PN_PEP_IND_ID_MCFC_GRANT_CREDITS:
289*4882a593Smuzhiyun 		if (pn->tx_fc != PN_MULTI_CREDIT_FLOW_CONTROL)
290*4882a593Smuzhiyun 			break;
291*4882a593Smuzhiyun 		atomic_add(wake = hdr->data[3], &pn->tx_credits);
292*4882a593Smuzhiyun 		break;
293*4882a593Smuzhiyun 
294*4882a593Smuzhiyun 	default:
295*4882a593Smuzhiyun 		net_dbg_ratelimited("Phonet unknown PEP indication: %u\n",
296*4882a593Smuzhiyun 				    (unsigned int)hdr->data[0]);
297*4882a593Smuzhiyun 		return -EOPNOTSUPP;
298*4882a593Smuzhiyun 	}
299*4882a593Smuzhiyun 	if (wake)
300*4882a593Smuzhiyun 		sk->sk_write_space(sk);
301*4882a593Smuzhiyun 	return 0;
302*4882a593Smuzhiyun }
303*4882a593Smuzhiyun 
pipe_rcv_created(struct sock * sk,struct sk_buff * skb)304*4882a593Smuzhiyun static int pipe_rcv_created(struct sock *sk, struct sk_buff *skb)
305*4882a593Smuzhiyun {
306*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
307*4882a593Smuzhiyun 	struct pnpipehdr *hdr = pnp_hdr(skb);
308*4882a593Smuzhiyun 	u8 n_sb = hdr->data0;
309*4882a593Smuzhiyun 
310*4882a593Smuzhiyun 	pn->rx_fc = pn->tx_fc = PN_LEGACY_FLOW_CONTROL;
311*4882a593Smuzhiyun 	__skb_pull(skb, sizeof(*hdr));
312*4882a593Smuzhiyun 	while (n_sb > 0) {
313*4882a593Smuzhiyun 		u8 type, buf[2], len = sizeof(buf);
314*4882a593Smuzhiyun 		u8 *data = pep_get_sb(skb, &type, &len, buf);
315*4882a593Smuzhiyun 
316*4882a593Smuzhiyun 		if (data == NULL)
317*4882a593Smuzhiyun 			return -EINVAL;
318*4882a593Smuzhiyun 		switch (type) {
319*4882a593Smuzhiyun 		case PN_PIPE_SB_NEGOTIATED_FC:
320*4882a593Smuzhiyun 			if (len < 2 || (data[0] | data[1]) > 3)
321*4882a593Smuzhiyun 				break;
322*4882a593Smuzhiyun 			pn->tx_fc = data[0] & 3;
323*4882a593Smuzhiyun 			pn->rx_fc = data[1] & 3;
324*4882a593Smuzhiyun 			break;
325*4882a593Smuzhiyun 		}
326*4882a593Smuzhiyun 		n_sb--;
327*4882a593Smuzhiyun 	}
328*4882a593Smuzhiyun 	return 0;
329*4882a593Smuzhiyun }
330*4882a593Smuzhiyun 
331*4882a593Smuzhiyun /* Queue an skb to a connected sock.
332*4882a593Smuzhiyun  * Socket lock must be held. */
pipe_do_rcv(struct sock * sk,struct sk_buff * skb)333*4882a593Smuzhiyun static int pipe_do_rcv(struct sock *sk, struct sk_buff *skb)
334*4882a593Smuzhiyun {
335*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
336*4882a593Smuzhiyun 	struct pnpipehdr *hdr = pnp_hdr(skb);
337*4882a593Smuzhiyun 	struct sk_buff_head *queue;
338*4882a593Smuzhiyun 	int err = 0;
339*4882a593Smuzhiyun 
340*4882a593Smuzhiyun 	BUG_ON(sk->sk_state == TCP_CLOSE_WAIT);
341*4882a593Smuzhiyun 
342*4882a593Smuzhiyun 	switch (hdr->message_id) {
343*4882a593Smuzhiyun 	case PNS_PEP_CONNECT_REQ:
344*4882a593Smuzhiyun 		pep_reject_conn(sk, skb, PN_PIPE_ERR_PEP_IN_USE, GFP_ATOMIC);
345*4882a593Smuzhiyun 		break;
346*4882a593Smuzhiyun 
347*4882a593Smuzhiyun 	case PNS_PEP_DISCONNECT_REQ:
348*4882a593Smuzhiyun 		pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
349*4882a593Smuzhiyun 		sk->sk_state = TCP_CLOSE_WAIT;
350*4882a593Smuzhiyun 		if (!sock_flag(sk, SOCK_DEAD))
351*4882a593Smuzhiyun 			sk->sk_state_change(sk);
352*4882a593Smuzhiyun 		break;
353*4882a593Smuzhiyun 
354*4882a593Smuzhiyun 	case PNS_PEP_ENABLE_REQ:
355*4882a593Smuzhiyun 		/* Wait for PNS_PIPE_(ENABLED|REDIRECTED)_IND */
356*4882a593Smuzhiyun 		pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
357*4882a593Smuzhiyun 		break;
358*4882a593Smuzhiyun 
359*4882a593Smuzhiyun 	case PNS_PEP_RESET_REQ:
360*4882a593Smuzhiyun 		switch (hdr->state_after_reset) {
361*4882a593Smuzhiyun 		case PN_PIPE_DISABLE:
362*4882a593Smuzhiyun 			pn->init_enable = 0;
363*4882a593Smuzhiyun 			break;
364*4882a593Smuzhiyun 		case PN_PIPE_ENABLE:
365*4882a593Smuzhiyun 			pn->init_enable = 1;
366*4882a593Smuzhiyun 			break;
367*4882a593Smuzhiyun 		default: /* not allowed to send an error here!? */
368*4882a593Smuzhiyun 			err = -EINVAL;
369*4882a593Smuzhiyun 			goto out;
370*4882a593Smuzhiyun 		}
371*4882a593Smuzhiyun 		fallthrough;
372*4882a593Smuzhiyun 	case PNS_PEP_DISABLE_REQ:
373*4882a593Smuzhiyun 		atomic_set(&pn->tx_credits, 0);
374*4882a593Smuzhiyun 		pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
375*4882a593Smuzhiyun 		break;
376*4882a593Smuzhiyun 
377*4882a593Smuzhiyun 	case PNS_PEP_CTRL_REQ:
378*4882a593Smuzhiyun 		if (skb_queue_len(&pn->ctrlreq_queue) >= PNPIPE_CTRLREQ_MAX) {
379*4882a593Smuzhiyun 			atomic_inc(&sk->sk_drops);
380*4882a593Smuzhiyun 			break;
381*4882a593Smuzhiyun 		}
382*4882a593Smuzhiyun 		__skb_pull(skb, 4);
383*4882a593Smuzhiyun 		queue = &pn->ctrlreq_queue;
384*4882a593Smuzhiyun 		goto queue;
385*4882a593Smuzhiyun 
386*4882a593Smuzhiyun 	case PNS_PIPE_ALIGNED_DATA:
387*4882a593Smuzhiyun 		__skb_pull(skb, 1);
388*4882a593Smuzhiyun 		fallthrough;
389*4882a593Smuzhiyun 	case PNS_PIPE_DATA:
390*4882a593Smuzhiyun 		__skb_pull(skb, 3); /* Pipe data header */
391*4882a593Smuzhiyun 		if (!pn_flow_safe(pn->rx_fc)) {
392*4882a593Smuzhiyun 			err = sock_queue_rcv_skb(sk, skb);
393*4882a593Smuzhiyun 			if (!err)
394*4882a593Smuzhiyun 				return NET_RX_SUCCESS;
395*4882a593Smuzhiyun 			err = -ENOBUFS;
396*4882a593Smuzhiyun 			break;
397*4882a593Smuzhiyun 		}
398*4882a593Smuzhiyun 
399*4882a593Smuzhiyun 		if (pn->rx_credits == 0) {
400*4882a593Smuzhiyun 			atomic_inc(&sk->sk_drops);
401*4882a593Smuzhiyun 			err = -ENOBUFS;
402*4882a593Smuzhiyun 			break;
403*4882a593Smuzhiyun 		}
404*4882a593Smuzhiyun 		pn->rx_credits--;
405*4882a593Smuzhiyun 		queue = &sk->sk_receive_queue;
406*4882a593Smuzhiyun 		goto queue;
407*4882a593Smuzhiyun 
408*4882a593Smuzhiyun 	case PNS_PEP_STATUS_IND:
409*4882a593Smuzhiyun 		pipe_rcv_status(sk, skb);
410*4882a593Smuzhiyun 		break;
411*4882a593Smuzhiyun 
412*4882a593Smuzhiyun 	case PNS_PIPE_REDIRECTED_IND:
413*4882a593Smuzhiyun 		err = pipe_rcv_created(sk, skb);
414*4882a593Smuzhiyun 		break;
415*4882a593Smuzhiyun 
416*4882a593Smuzhiyun 	case PNS_PIPE_CREATED_IND:
417*4882a593Smuzhiyun 		err = pipe_rcv_created(sk, skb);
418*4882a593Smuzhiyun 		if (err)
419*4882a593Smuzhiyun 			break;
420*4882a593Smuzhiyun 		fallthrough;
421*4882a593Smuzhiyun 	case PNS_PIPE_RESET_IND:
422*4882a593Smuzhiyun 		if (!pn->init_enable)
423*4882a593Smuzhiyun 			break;
424*4882a593Smuzhiyun 		fallthrough;
425*4882a593Smuzhiyun 	case PNS_PIPE_ENABLED_IND:
426*4882a593Smuzhiyun 		if (!pn_flow_safe(pn->tx_fc)) {
427*4882a593Smuzhiyun 			atomic_set(&pn->tx_credits, 1);
428*4882a593Smuzhiyun 			sk->sk_write_space(sk);
429*4882a593Smuzhiyun 		}
430*4882a593Smuzhiyun 		if (sk->sk_state == TCP_ESTABLISHED)
431*4882a593Smuzhiyun 			break; /* Nothing to do */
432*4882a593Smuzhiyun 		sk->sk_state = TCP_ESTABLISHED;
433*4882a593Smuzhiyun 		pipe_grant_credits(sk, GFP_ATOMIC);
434*4882a593Smuzhiyun 		break;
435*4882a593Smuzhiyun 
436*4882a593Smuzhiyun 	case PNS_PIPE_DISABLED_IND:
437*4882a593Smuzhiyun 		sk->sk_state = TCP_SYN_RECV;
438*4882a593Smuzhiyun 		pn->rx_credits = 0;
439*4882a593Smuzhiyun 		break;
440*4882a593Smuzhiyun 
441*4882a593Smuzhiyun 	default:
442*4882a593Smuzhiyun 		net_dbg_ratelimited("Phonet unknown PEP message: %u\n",
443*4882a593Smuzhiyun 				    hdr->message_id);
444*4882a593Smuzhiyun 		err = -EINVAL;
445*4882a593Smuzhiyun 	}
446*4882a593Smuzhiyun out:
447*4882a593Smuzhiyun 	kfree_skb(skb);
448*4882a593Smuzhiyun 	return (err == -ENOBUFS) ? NET_RX_DROP : NET_RX_SUCCESS;
449*4882a593Smuzhiyun 
450*4882a593Smuzhiyun queue:
451*4882a593Smuzhiyun 	skb->dev = NULL;
452*4882a593Smuzhiyun 	skb_set_owner_r(skb, sk);
453*4882a593Smuzhiyun 	skb_queue_tail(queue, skb);
454*4882a593Smuzhiyun 	if (!sock_flag(sk, SOCK_DEAD))
455*4882a593Smuzhiyun 		sk->sk_data_ready(sk);
456*4882a593Smuzhiyun 	return NET_RX_SUCCESS;
457*4882a593Smuzhiyun }
458*4882a593Smuzhiyun 
459*4882a593Smuzhiyun /* Destroy connected sock. */
pipe_destruct(struct sock * sk)460*4882a593Smuzhiyun static void pipe_destruct(struct sock *sk)
461*4882a593Smuzhiyun {
462*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
463*4882a593Smuzhiyun 
464*4882a593Smuzhiyun 	skb_queue_purge(&sk->sk_receive_queue);
465*4882a593Smuzhiyun 	skb_queue_purge(&pn->ctrlreq_queue);
466*4882a593Smuzhiyun }
467*4882a593Smuzhiyun 
pipe_negotiate_fc(const u8 * fcs,unsigned int n)468*4882a593Smuzhiyun static u8 pipe_negotiate_fc(const u8 *fcs, unsigned int n)
469*4882a593Smuzhiyun {
470*4882a593Smuzhiyun 	unsigned int i;
471*4882a593Smuzhiyun 	u8 final_fc = PN_NO_FLOW_CONTROL;
472*4882a593Smuzhiyun 
473*4882a593Smuzhiyun 	for (i = 0; i < n; i++) {
474*4882a593Smuzhiyun 		u8 fc = fcs[i];
475*4882a593Smuzhiyun 
476*4882a593Smuzhiyun 		if (fc > final_fc && fc < PN_MAX_FLOW_CONTROL)
477*4882a593Smuzhiyun 			final_fc = fc;
478*4882a593Smuzhiyun 	}
479*4882a593Smuzhiyun 	return final_fc;
480*4882a593Smuzhiyun }
481*4882a593Smuzhiyun 
pep_connresp_rcv(struct sock * sk,struct sk_buff * skb)482*4882a593Smuzhiyun static int pep_connresp_rcv(struct sock *sk, struct sk_buff *skb)
483*4882a593Smuzhiyun {
484*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
485*4882a593Smuzhiyun 	struct pnpipehdr *hdr;
486*4882a593Smuzhiyun 	u8 n_sb;
487*4882a593Smuzhiyun 
488*4882a593Smuzhiyun 	if (!pskb_pull(skb, sizeof(*hdr) + 4))
489*4882a593Smuzhiyun 		return -EINVAL;
490*4882a593Smuzhiyun 
491*4882a593Smuzhiyun 	hdr = pnp_hdr(skb);
492*4882a593Smuzhiyun 	if (hdr->error_code != PN_PIPE_NO_ERROR)
493*4882a593Smuzhiyun 		return -ECONNREFUSED;
494*4882a593Smuzhiyun 
495*4882a593Smuzhiyun 	/* Parse sub-blocks */
496*4882a593Smuzhiyun 	n_sb = hdr->data[3];
497*4882a593Smuzhiyun 	while (n_sb > 0) {
498*4882a593Smuzhiyun 		u8 type, buf[6], len = sizeof(buf);
499*4882a593Smuzhiyun 		const u8 *data = pep_get_sb(skb, &type, &len, buf);
500*4882a593Smuzhiyun 
501*4882a593Smuzhiyun 		if (data == NULL)
502*4882a593Smuzhiyun 			return -EINVAL;
503*4882a593Smuzhiyun 
504*4882a593Smuzhiyun 		switch (type) {
505*4882a593Smuzhiyun 		case PN_PIPE_SB_REQUIRED_FC_TX:
506*4882a593Smuzhiyun 			if (len < 2 || len < data[0])
507*4882a593Smuzhiyun 				break;
508*4882a593Smuzhiyun 			pn->tx_fc = pipe_negotiate_fc(data + 2, len - 2);
509*4882a593Smuzhiyun 			break;
510*4882a593Smuzhiyun 
511*4882a593Smuzhiyun 		case PN_PIPE_SB_PREFERRED_FC_RX:
512*4882a593Smuzhiyun 			if (len < 2 || len < data[0])
513*4882a593Smuzhiyun 				break;
514*4882a593Smuzhiyun 			pn->rx_fc = pipe_negotiate_fc(data + 2, len - 2);
515*4882a593Smuzhiyun 			break;
516*4882a593Smuzhiyun 
517*4882a593Smuzhiyun 		}
518*4882a593Smuzhiyun 		n_sb--;
519*4882a593Smuzhiyun 	}
520*4882a593Smuzhiyun 
521*4882a593Smuzhiyun 	return pipe_handler_send_created_ind(sk);
522*4882a593Smuzhiyun }
523*4882a593Smuzhiyun 
pep_enableresp_rcv(struct sock * sk,struct sk_buff * skb)524*4882a593Smuzhiyun static int pep_enableresp_rcv(struct sock *sk, struct sk_buff *skb)
525*4882a593Smuzhiyun {
526*4882a593Smuzhiyun 	struct pnpipehdr *hdr = pnp_hdr(skb);
527*4882a593Smuzhiyun 
528*4882a593Smuzhiyun 	if (hdr->error_code != PN_PIPE_NO_ERROR)
529*4882a593Smuzhiyun 		return -ECONNREFUSED;
530*4882a593Smuzhiyun 
531*4882a593Smuzhiyun 	return pep_indicate(sk, PNS_PIPE_ENABLED_IND, 0 /* sub-blocks */,
532*4882a593Smuzhiyun 		NULL, 0, GFP_ATOMIC);
533*4882a593Smuzhiyun 
534*4882a593Smuzhiyun }
535*4882a593Smuzhiyun 
pipe_start_flow_control(struct sock * sk)536*4882a593Smuzhiyun static void pipe_start_flow_control(struct sock *sk)
537*4882a593Smuzhiyun {
538*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
539*4882a593Smuzhiyun 
540*4882a593Smuzhiyun 	if (!pn_flow_safe(pn->tx_fc)) {
541*4882a593Smuzhiyun 		atomic_set(&pn->tx_credits, 1);
542*4882a593Smuzhiyun 		sk->sk_write_space(sk);
543*4882a593Smuzhiyun 	}
544*4882a593Smuzhiyun 	pipe_grant_credits(sk, GFP_ATOMIC);
545*4882a593Smuzhiyun }
546*4882a593Smuzhiyun 
547*4882a593Smuzhiyun /* Queue an skb to an actively connected sock.
548*4882a593Smuzhiyun  * Socket lock must be held. */
pipe_handler_do_rcv(struct sock * sk,struct sk_buff * skb)549*4882a593Smuzhiyun static int pipe_handler_do_rcv(struct sock *sk, struct sk_buff *skb)
550*4882a593Smuzhiyun {
551*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
552*4882a593Smuzhiyun 	struct pnpipehdr *hdr = pnp_hdr(skb);
553*4882a593Smuzhiyun 	int err = NET_RX_SUCCESS;
554*4882a593Smuzhiyun 
555*4882a593Smuzhiyun 	switch (hdr->message_id) {
556*4882a593Smuzhiyun 	case PNS_PIPE_ALIGNED_DATA:
557*4882a593Smuzhiyun 		__skb_pull(skb, 1);
558*4882a593Smuzhiyun 		fallthrough;
559*4882a593Smuzhiyun 	case PNS_PIPE_DATA:
560*4882a593Smuzhiyun 		__skb_pull(skb, 3); /* Pipe data header */
561*4882a593Smuzhiyun 		if (!pn_flow_safe(pn->rx_fc)) {
562*4882a593Smuzhiyun 			err = sock_queue_rcv_skb(sk, skb);
563*4882a593Smuzhiyun 			if (!err)
564*4882a593Smuzhiyun 				return NET_RX_SUCCESS;
565*4882a593Smuzhiyun 			err = NET_RX_DROP;
566*4882a593Smuzhiyun 			break;
567*4882a593Smuzhiyun 		}
568*4882a593Smuzhiyun 
569*4882a593Smuzhiyun 		if (pn->rx_credits == 0) {
570*4882a593Smuzhiyun 			atomic_inc(&sk->sk_drops);
571*4882a593Smuzhiyun 			err = NET_RX_DROP;
572*4882a593Smuzhiyun 			break;
573*4882a593Smuzhiyun 		}
574*4882a593Smuzhiyun 		pn->rx_credits--;
575*4882a593Smuzhiyun 		skb->dev = NULL;
576*4882a593Smuzhiyun 		skb_set_owner_r(skb, sk);
577*4882a593Smuzhiyun 		skb_queue_tail(&sk->sk_receive_queue, skb);
578*4882a593Smuzhiyun 		if (!sock_flag(sk, SOCK_DEAD))
579*4882a593Smuzhiyun 			sk->sk_data_ready(sk);
580*4882a593Smuzhiyun 		return NET_RX_SUCCESS;
581*4882a593Smuzhiyun 
582*4882a593Smuzhiyun 	case PNS_PEP_CONNECT_RESP:
583*4882a593Smuzhiyun 		if (sk->sk_state != TCP_SYN_SENT)
584*4882a593Smuzhiyun 			break;
585*4882a593Smuzhiyun 		if (!sock_flag(sk, SOCK_DEAD))
586*4882a593Smuzhiyun 			sk->sk_state_change(sk);
587*4882a593Smuzhiyun 		if (pep_connresp_rcv(sk, skb)) {
588*4882a593Smuzhiyun 			sk->sk_state = TCP_CLOSE_WAIT;
589*4882a593Smuzhiyun 			break;
590*4882a593Smuzhiyun 		}
591*4882a593Smuzhiyun 		if (pn->init_enable == PN_PIPE_DISABLE)
592*4882a593Smuzhiyun 			sk->sk_state = TCP_SYN_RECV;
593*4882a593Smuzhiyun 		else {
594*4882a593Smuzhiyun 			sk->sk_state = TCP_ESTABLISHED;
595*4882a593Smuzhiyun 			pipe_start_flow_control(sk);
596*4882a593Smuzhiyun 		}
597*4882a593Smuzhiyun 		break;
598*4882a593Smuzhiyun 
599*4882a593Smuzhiyun 	case PNS_PEP_ENABLE_RESP:
600*4882a593Smuzhiyun 		if (sk->sk_state != TCP_SYN_SENT)
601*4882a593Smuzhiyun 			break;
602*4882a593Smuzhiyun 
603*4882a593Smuzhiyun 		if (pep_enableresp_rcv(sk, skb)) {
604*4882a593Smuzhiyun 			sk->sk_state = TCP_CLOSE_WAIT;
605*4882a593Smuzhiyun 			break;
606*4882a593Smuzhiyun 		}
607*4882a593Smuzhiyun 
608*4882a593Smuzhiyun 		sk->sk_state = TCP_ESTABLISHED;
609*4882a593Smuzhiyun 		pipe_start_flow_control(sk);
610*4882a593Smuzhiyun 		break;
611*4882a593Smuzhiyun 
612*4882a593Smuzhiyun 	case PNS_PEP_DISCONNECT_RESP:
613*4882a593Smuzhiyun 		/* sock should already be dead, nothing to do */
614*4882a593Smuzhiyun 		break;
615*4882a593Smuzhiyun 
616*4882a593Smuzhiyun 	case PNS_PEP_STATUS_IND:
617*4882a593Smuzhiyun 		pipe_rcv_status(sk, skb);
618*4882a593Smuzhiyun 		break;
619*4882a593Smuzhiyun 	}
620*4882a593Smuzhiyun 	kfree_skb(skb);
621*4882a593Smuzhiyun 	return err;
622*4882a593Smuzhiyun }
623*4882a593Smuzhiyun 
624*4882a593Smuzhiyun /* Listening sock must be locked */
pep_find_pipe(const struct hlist_head * hlist,const struct sockaddr_pn * dst,u8 pipe_handle)625*4882a593Smuzhiyun static struct sock *pep_find_pipe(const struct hlist_head *hlist,
626*4882a593Smuzhiyun 					const struct sockaddr_pn *dst,
627*4882a593Smuzhiyun 					u8 pipe_handle)
628*4882a593Smuzhiyun {
629*4882a593Smuzhiyun 	struct sock *sknode;
630*4882a593Smuzhiyun 	u16 dobj = pn_sockaddr_get_object(dst);
631*4882a593Smuzhiyun 
632*4882a593Smuzhiyun 	sk_for_each(sknode, hlist) {
633*4882a593Smuzhiyun 		struct pep_sock *pnnode = pep_sk(sknode);
634*4882a593Smuzhiyun 
635*4882a593Smuzhiyun 		/* Ports match, but addresses might not: */
636*4882a593Smuzhiyun 		if (pnnode->pn_sk.sobject != dobj)
637*4882a593Smuzhiyun 			continue;
638*4882a593Smuzhiyun 		if (pnnode->pipe_handle != pipe_handle)
639*4882a593Smuzhiyun 			continue;
640*4882a593Smuzhiyun 		if (sknode->sk_state == TCP_CLOSE_WAIT)
641*4882a593Smuzhiyun 			continue;
642*4882a593Smuzhiyun 
643*4882a593Smuzhiyun 		sock_hold(sknode);
644*4882a593Smuzhiyun 		return sknode;
645*4882a593Smuzhiyun 	}
646*4882a593Smuzhiyun 	return NULL;
647*4882a593Smuzhiyun }
648*4882a593Smuzhiyun 
649*4882a593Smuzhiyun /*
650*4882a593Smuzhiyun  * Deliver an skb to a listening sock.
651*4882a593Smuzhiyun  * Socket lock must be held.
652*4882a593Smuzhiyun  * We then queue the skb to the right connected sock (if any).
653*4882a593Smuzhiyun  */
pep_do_rcv(struct sock * sk,struct sk_buff * skb)654*4882a593Smuzhiyun static int pep_do_rcv(struct sock *sk, struct sk_buff *skb)
655*4882a593Smuzhiyun {
656*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
657*4882a593Smuzhiyun 	struct sock *sknode;
658*4882a593Smuzhiyun 	struct pnpipehdr *hdr;
659*4882a593Smuzhiyun 	struct sockaddr_pn dst;
660*4882a593Smuzhiyun 	u8 pipe_handle;
661*4882a593Smuzhiyun 
662*4882a593Smuzhiyun 	if (!pskb_may_pull(skb, sizeof(*hdr)))
663*4882a593Smuzhiyun 		goto drop;
664*4882a593Smuzhiyun 
665*4882a593Smuzhiyun 	hdr = pnp_hdr(skb);
666*4882a593Smuzhiyun 	pipe_handle = hdr->pipe_handle;
667*4882a593Smuzhiyun 	if (pipe_handle == PN_PIPE_INVALID_HANDLE)
668*4882a593Smuzhiyun 		goto drop;
669*4882a593Smuzhiyun 
670*4882a593Smuzhiyun 	pn_skb_get_dst_sockaddr(skb, &dst);
671*4882a593Smuzhiyun 
672*4882a593Smuzhiyun 	/* Look for an existing pipe handle */
673*4882a593Smuzhiyun 	sknode = pep_find_pipe(&pn->hlist, &dst, pipe_handle);
674*4882a593Smuzhiyun 	if (sknode)
675*4882a593Smuzhiyun 		return sk_receive_skb(sknode, skb, 1);
676*4882a593Smuzhiyun 
677*4882a593Smuzhiyun 	switch (hdr->message_id) {
678*4882a593Smuzhiyun 	case PNS_PEP_CONNECT_REQ:
679*4882a593Smuzhiyun 		if (sk->sk_state != TCP_LISTEN || sk_acceptq_is_full(sk)) {
680*4882a593Smuzhiyun 			pep_reject_conn(sk, skb, PN_PIPE_ERR_PEP_IN_USE,
681*4882a593Smuzhiyun 					GFP_ATOMIC);
682*4882a593Smuzhiyun 			break;
683*4882a593Smuzhiyun 		}
684*4882a593Smuzhiyun 		skb_queue_head(&sk->sk_receive_queue, skb);
685*4882a593Smuzhiyun 		sk_acceptq_added(sk);
686*4882a593Smuzhiyun 		if (!sock_flag(sk, SOCK_DEAD))
687*4882a593Smuzhiyun 			sk->sk_data_ready(sk);
688*4882a593Smuzhiyun 		return NET_RX_SUCCESS;
689*4882a593Smuzhiyun 
690*4882a593Smuzhiyun 	case PNS_PEP_DISCONNECT_REQ:
691*4882a593Smuzhiyun 		pep_reply(sk, skb, PN_PIPE_NO_ERROR, NULL, 0, GFP_ATOMIC);
692*4882a593Smuzhiyun 		break;
693*4882a593Smuzhiyun 
694*4882a593Smuzhiyun 	case PNS_PEP_CTRL_REQ:
695*4882a593Smuzhiyun 		pep_ctrlreq_error(sk, skb, PN_PIPE_INVALID_HANDLE, GFP_ATOMIC);
696*4882a593Smuzhiyun 		break;
697*4882a593Smuzhiyun 
698*4882a593Smuzhiyun 	case PNS_PEP_RESET_REQ:
699*4882a593Smuzhiyun 	case PNS_PEP_ENABLE_REQ:
700*4882a593Smuzhiyun 	case PNS_PEP_DISABLE_REQ:
701*4882a593Smuzhiyun 		/* invalid handle is not even allowed here! */
702*4882a593Smuzhiyun 		break;
703*4882a593Smuzhiyun 
704*4882a593Smuzhiyun 	default:
705*4882a593Smuzhiyun 		if ((1 << sk->sk_state)
706*4882a593Smuzhiyun 				& ~(TCPF_CLOSE|TCPF_LISTEN|TCPF_CLOSE_WAIT))
707*4882a593Smuzhiyun 			/* actively connected socket */
708*4882a593Smuzhiyun 			return pipe_handler_do_rcv(sk, skb);
709*4882a593Smuzhiyun 	}
710*4882a593Smuzhiyun drop:
711*4882a593Smuzhiyun 	kfree_skb(skb);
712*4882a593Smuzhiyun 	return NET_RX_SUCCESS;
713*4882a593Smuzhiyun }
714*4882a593Smuzhiyun 
pipe_do_remove(struct sock * sk)715*4882a593Smuzhiyun static int pipe_do_remove(struct sock *sk)
716*4882a593Smuzhiyun {
717*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
718*4882a593Smuzhiyun 	struct pnpipehdr *ph;
719*4882a593Smuzhiyun 	struct sk_buff *skb;
720*4882a593Smuzhiyun 
721*4882a593Smuzhiyun 	skb = pep_alloc_skb(sk, NULL, 0, GFP_KERNEL);
722*4882a593Smuzhiyun 	if (!skb)
723*4882a593Smuzhiyun 		return -ENOMEM;
724*4882a593Smuzhiyun 
725*4882a593Smuzhiyun 	ph = pnp_hdr(skb);
726*4882a593Smuzhiyun 	ph->utid = 0;
727*4882a593Smuzhiyun 	ph->message_id = PNS_PIPE_REMOVE_REQ;
728*4882a593Smuzhiyun 	ph->pipe_handle = pn->pipe_handle;
729*4882a593Smuzhiyun 	ph->data0 = PAD;
730*4882a593Smuzhiyun 	return pn_skb_send(sk, skb, NULL);
731*4882a593Smuzhiyun }
732*4882a593Smuzhiyun 
733*4882a593Smuzhiyun /* associated socket ceases to exist */
pep_sock_close(struct sock * sk,long timeout)734*4882a593Smuzhiyun static void pep_sock_close(struct sock *sk, long timeout)
735*4882a593Smuzhiyun {
736*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
737*4882a593Smuzhiyun 	int ifindex = 0;
738*4882a593Smuzhiyun 
739*4882a593Smuzhiyun 	sock_hold(sk); /* keep a reference after sk_common_release() */
740*4882a593Smuzhiyun 	sk_common_release(sk);
741*4882a593Smuzhiyun 
742*4882a593Smuzhiyun 	lock_sock(sk);
743*4882a593Smuzhiyun 	if ((1 << sk->sk_state) & (TCPF_SYN_RECV|TCPF_ESTABLISHED)) {
744*4882a593Smuzhiyun 		if (sk->sk_backlog_rcv == pipe_do_rcv)
745*4882a593Smuzhiyun 			/* Forcefully remove dangling Phonet pipe */
746*4882a593Smuzhiyun 			pipe_do_remove(sk);
747*4882a593Smuzhiyun 		else
748*4882a593Smuzhiyun 			pipe_handler_request(sk, PNS_PEP_DISCONNECT_REQ, PAD,
749*4882a593Smuzhiyun 						NULL, 0);
750*4882a593Smuzhiyun 	}
751*4882a593Smuzhiyun 	sk->sk_state = TCP_CLOSE;
752*4882a593Smuzhiyun 
753*4882a593Smuzhiyun 	ifindex = pn->ifindex;
754*4882a593Smuzhiyun 	pn->ifindex = 0;
755*4882a593Smuzhiyun 	release_sock(sk);
756*4882a593Smuzhiyun 
757*4882a593Smuzhiyun 	if (ifindex)
758*4882a593Smuzhiyun 		gprs_detach(sk);
759*4882a593Smuzhiyun 	sock_put(sk);
760*4882a593Smuzhiyun }
761*4882a593Smuzhiyun 
pep_sock_accept(struct sock * sk,int flags,int * errp,bool kern)762*4882a593Smuzhiyun static struct sock *pep_sock_accept(struct sock *sk, int flags, int *errp,
763*4882a593Smuzhiyun 				    bool kern)
764*4882a593Smuzhiyun {
765*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk), *newpn;
766*4882a593Smuzhiyun 	struct sock *newsk = NULL;
767*4882a593Smuzhiyun 	struct sk_buff *skb;
768*4882a593Smuzhiyun 	struct pnpipehdr *hdr;
769*4882a593Smuzhiyun 	struct sockaddr_pn dst, src;
770*4882a593Smuzhiyun 	int err;
771*4882a593Smuzhiyun 	u16 peer_type;
772*4882a593Smuzhiyun 	u8 pipe_handle, enabled, n_sb;
773*4882a593Smuzhiyun 	u8 aligned = 0;
774*4882a593Smuzhiyun 
775*4882a593Smuzhiyun 	skb = skb_recv_datagram(sk, 0, flags & O_NONBLOCK, errp);
776*4882a593Smuzhiyun 	if (!skb)
777*4882a593Smuzhiyun 		return NULL;
778*4882a593Smuzhiyun 
779*4882a593Smuzhiyun 	lock_sock(sk);
780*4882a593Smuzhiyun 	if (sk->sk_state != TCP_LISTEN) {
781*4882a593Smuzhiyun 		err = -EINVAL;
782*4882a593Smuzhiyun 		goto drop;
783*4882a593Smuzhiyun 	}
784*4882a593Smuzhiyun 	sk_acceptq_removed(sk);
785*4882a593Smuzhiyun 
786*4882a593Smuzhiyun 	err = -EPROTO;
787*4882a593Smuzhiyun 	if (!pskb_may_pull(skb, sizeof(*hdr) + 4))
788*4882a593Smuzhiyun 		goto drop;
789*4882a593Smuzhiyun 
790*4882a593Smuzhiyun 	hdr = pnp_hdr(skb);
791*4882a593Smuzhiyun 	pipe_handle = hdr->pipe_handle;
792*4882a593Smuzhiyun 	switch (hdr->state_after_connect) {
793*4882a593Smuzhiyun 	case PN_PIPE_DISABLE:
794*4882a593Smuzhiyun 		enabled = 0;
795*4882a593Smuzhiyun 		break;
796*4882a593Smuzhiyun 	case PN_PIPE_ENABLE:
797*4882a593Smuzhiyun 		enabled = 1;
798*4882a593Smuzhiyun 		break;
799*4882a593Smuzhiyun 	default:
800*4882a593Smuzhiyun 		pep_reject_conn(sk, skb, PN_PIPE_ERR_INVALID_PARAM,
801*4882a593Smuzhiyun 				GFP_KERNEL);
802*4882a593Smuzhiyun 		goto drop;
803*4882a593Smuzhiyun 	}
804*4882a593Smuzhiyun 	peer_type = hdr->other_pep_type << 8;
805*4882a593Smuzhiyun 
806*4882a593Smuzhiyun 	/* Parse sub-blocks (options) */
807*4882a593Smuzhiyun 	n_sb = hdr->data[3];
808*4882a593Smuzhiyun 	while (n_sb > 0) {
809*4882a593Smuzhiyun 		u8 type, buf[1], len = sizeof(buf);
810*4882a593Smuzhiyun 		const u8 *data = pep_get_sb(skb, &type, &len, buf);
811*4882a593Smuzhiyun 
812*4882a593Smuzhiyun 		if (data == NULL)
813*4882a593Smuzhiyun 			goto drop;
814*4882a593Smuzhiyun 		switch (type) {
815*4882a593Smuzhiyun 		case PN_PIPE_SB_CONNECT_REQ_PEP_SUB_TYPE:
816*4882a593Smuzhiyun 			if (len < 1)
817*4882a593Smuzhiyun 				goto drop;
818*4882a593Smuzhiyun 			peer_type = (peer_type & 0xff00) | data[0];
819*4882a593Smuzhiyun 			break;
820*4882a593Smuzhiyun 		case PN_PIPE_SB_ALIGNED_DATA:
821*4882a593Smuzhiyun 			aligned = data[0] != 0;
822*4882a593Smuzhiyun 			break;
823*4882a593Smuzhiyun 		}
824*4882a593Smuzhiyun 		n_sb--;
825*4882a593Smuzhiyun 	}
826*4882a593Smuzhiyun 
827*4882a593Smuzhiyun 	/* Check for duplicate pipe handle */
828*4882a593Smuzhiyun 	newsk = pep_find_pipe(&pn->hlist, &dst, pipe_handle);
829*4882a593Smuzhiyun 	if (unlikely(newsk)) {
830*4882a593Smuzhiyun 		__sock_put(newsk);
831*4882a593Smuzhiyun 		newsk = NULL;
832*4882a593Smuzhiyun 		pep_reject_conn(sk, skb, PN_PIPE_ERR_PEP_IN_USE, GFP_KERNEL);
833*4882a593Smuzhiyun 		goto drop;
834*4882a593Smuzhiyun 	}
835*4882a593Smuzhiyun 
836*4882a593Smuzhiyun 	/* Create a new to-be-accepted sock */
837*4882a593Smuzhiyun 	newsk = sk_alloc(sock_net(sk), PF_PHONET, GFP_KERNEL, sk->sk_prot,
838*4882a593Smuzhiyun 			 kern);
839*4882a593Smuzhiyun 	if (!newsk) {
840*4882a593Smuzhiyun 		pep_reject_conn(sk, skb, PN_PIPE_ERR_OVERLOAD, GFP_KERNEL);
841*4882a593Smuzhiyun 		err = -ENOBUFS;
842*4882a593Smuzhiyun 		goto drop;
843*4882a593Smuzhiyun 	}
844*4882a593Smuzhiyun 
845*4882a593Smuzhiyun 	sock_init_data(NULL, newsk);
846*4882a593Smuzhiyun 	newsk->sk_state = TCP_SYN_RECV;
847*4882a593Smuzhiyun 	newsk->sk_backlog_rcv = pipe_do_rcv;
848*4882a593Smuzhiyun 	newsk->sk_protocol = sk->sk_protocol;
849*4882a593Smuzhiyun 	newsk->sk_destruct = pipe_destruct;
850*4882a593Smuzhiyun 
851*4882a593Smuzhiyun 	newpn = pep_sk(newsk);
852*4882a593Smuzhiyun 	pn_skb_get_dst_sockaddr(skb, &dst);
853*4882a593Smuzhiyun 	pn_skb_get_src_sockaddr(skb, &src);
854*4882a593Smuzhiyun 	newpn->pn_sk.sobject = pn_sockaddr_get_object(&dst);
855*4882a593Smuzhiyun 	newpn->pn_sk.dobject = pn_sockaddr_get_object(&src);
856*4882a593Smuzhiyun 	newpn->pn_sk.resource = pn_sockaddr_get_resource(&dst);
857*4882a593Smuzhiyun 	sock_hold(sk);
858*4882a593Smuzhiyun 	newpn->listener = sk;
859*4882a593Smuzhiyun 	skb_queue_head_init(&newpn->ctrlreq_queue);
860*4882a593Smuzhiyun 	newpn->pipe_handle = pipe_handle;
861*4882a593Smuzhiyun 	atomic_set(&newpn->tx_credits, 0);
862*4882a593Smuzhiyun 	newpn->ifindex = 0;
863*4882a593Smuzhiyun 	newpn->peer_type = peer_type;
864*4882a593Smuzhiyun 	newpn->rx_credits = 0;
865*4882a593Smuzhiyun 	newpn->rx_fc = newpn->tx_fc = PN_LEGACY_FLOW_CONTROL;
866*4882a593Smuzhiyun 	newpn->init_enable = enabled;
867*4882a593Smuzhiyun 	newpn->aligned = aligned;
868*4882a593Smuzhiyun 
869*4882a593Smuzhiyun 	err = pep_accept_conn(newsk, skb);
870*4882a593Smuzhiyun 	if (err) {
871*4882a593Smuzhiyun 		__sock_put(sk);
872*4882a593Smuzhiyun 		sock_put(newsk);
873*4882a593Smuzhiyun 		newsk = NULL;
874*4882a593Smuzhiyun 		goto drop;
875*4882a593Smuzhiyun 	}
876*4882a593Smuzhiyun 	sk_add_node(newsk, &pn->hlist);
877*4882a593Smuzhiyun drop:
878*4882a593Smuzhiyun 	release_sock(sk);
879*4882a593Smuzhiyun 	kfree_skb(skb);
880*4882a593Smuzhiyun 	*errp = err;
881*4882a593Smuzhiyun 	return newsk;
882*4882a593Smuzhiyun }
883*4882a593Smuzhiyun 
pep_sock_connect(struct sock * sk,struct sockaddr * addr,int len)884*4882a593Smuzhiyun static int pep_sock_connect(struct sock *sk, struct sockaddr *addr, int len)
885*4882a593Smuzhiyun {
886*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
887*4882a593Smuzhiyun 	int err;
888*4882a593Smuzhiyun 	u8 data[4] = { 0 /* sub-blocks */, PAD, PAD, PAD };
889*4882a593Smuzhiyun 
890*4882a593Smuzhiyun 	if (pn->pipe_handle == PN_PIPE_INVALID_HANDLE)
891*4882a593Smuzhiyun 		pn->pipe_handle = 1; /* anything but INVALID_HANDLE */
892*4882a593Smuzhiyun 
893*4882a593Smuzhiyun 	err = pipe_handler_request(sk, PNS_PEP_CONNECT_REQ,
894*4882a593Smuzhiyun 				pn->init_enable, data, 4);
895*4882a593Smuzhiyun 	if (err) {
896*4882a593Smuzhiyun 		pn->pipe_handle = PN_PIPE_INVALID_HANDLE;
897*4882a593Smuzhiyun 		return err;
898*4882a593Smuzhiyun 	}
899*4882a593Smuzhiyun 
900*4882a593Smuzhiyun 	sk->sk_state = TCP_SYN_SENT;
901*4882a593Smuzhiyun 
902*4882a593Smuzhiyun 	return 0;
903*4882a593Smuzhiyun }
904*4882a593Smuzhiyun 
pep_sock_enable(struct sock * sk,struct sockaddr * addr,int len)905*4882a593Smuzhiyun static int pep_sock_enable(struct sock *sk, struct sockaddr *addr, int len)
906*4882a593Smuzhiyun {
907*4882a593Smuzhiyun 	int err;
908*4882a593Smuzhiyun 
909*4882a593Smuzhiyun 	err = pipe_handler_request(sk, PNS_PEP_ENABLE_REQ, PAD,
910*4882a593Smuzhiyun 				NULL, 0);
911*4882a593Smuzhiyun 	if (err)
912*4882a593Smuzhiyun 		return err;
913*4882a593Smuzhiyun 
914*4882a593Smuzhiyun 	sk->sk_state = TCP_SYN_SENT;
915*4882a593Smuzhiyun 
916*4882a593Smuzhiyun 	return 0;
917*4882a593Smuzhiyun }
918*4882a593Smuzhiyun 
pep_ioctl(struct sock * sk,int cmd,unsigned long arg)919*4882a593Smuzhiyun static int pep_ioctl(struct sock *sk, int cmd, unsigned long arg)
920*4882a593Smuzhiyun {
921*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
922*4882a593Smuzhiyun 	int answ;
923*4882a593Smuzhiyun 	int ret = -ENOIOCTLCMD;
924*4882a593Smuzhiyun 
925*4882a593Smuzhiyun 	switch (cmd) {
926*4882a593Smuzhiyun 	case SIOCINQ:
927*4882a593Smuzhiyun 		if (sk->sk_state == TCP_LISTEN) {
928*4882a593Smuzhiyun 			ret = -EINVAL;
929*4882a593Smuzhiyun 			break;
930*4882a593Smuzhiyun 		}
931*4882a593Smuzhiyun 
932*4882a593Smuzhiyun 		lock_sock(sk);
933*4882a593Smuzhiyun 		if (sock_flag(sk, SOCK_URGINLINE) &&
934*4882a593Smuzhiyun 		    !skb_queue_empty(&pn->ctrlreq_queue))
935*4882a593Smuzhiyun 			answ = skb_peek(&pn->ctrlreq_queue)->len;
936*4882a593Smuzhiyun 		else if (!skb_queue_empty(&sk->sk_receive_queue))
937*4882a593Smuzhiyun 			answ = skb_peek(&sk->sk_receive_queue)->len;
938*4882a593Smuzhiyun 		else
939*4882a593Smuzhiyun 			answ = 0;
940*4882a593Smuzhiyun 		release_sock(sk);
941*4882a593Smuzhiyun 		ret = put_user(answ, (int __user *)arg);
942*4882a593Smuzhiyun 		break;
943*4882a593Smuzhiyun 
944*4882a593Smuzhiyun 	case SIOCPNENABLEPIPE:
945*4882a593Smuzhiyun 		lock_sock(sk);
946*4882a593Smuzhiyun 		if (sk->sk_state == TCP_SYN_SENT)
947*4882a593Smuzhiyun 			ret =  -EBUSY;
948*4882a593Smuzhiyun 		else if (sk->sk_state == TCP_ESTABLISHED)
949*4882a593Smuzhiyun 			ret = -EISCONN;
950*4882a593Smuzhiyun 		else if (!pn->pn_sk.sobject)
951*4882a593Smuzhiyun 			ret = -EADDRNOTAVAIL;
952*4882a593Smuzhiyun 		else
953*4882a593Smuzhiyun 			ret = pep_sock_enable(sk, NULL, 0);
954*4882a593Smuzhiyun 		release_sock(sk);
955*4882a593Smuzhiyun 		break;
956*4882a593Smuzhiyun 	}
957*4882a593Smuzhiyun 
958*4882a593Smuzhiyun 	return ret;
959*4882a593Smuzhiyun }
960*4882a593Smuzhiyun 
pep_init(struct sock * sk)961*4882a593Smuzhiyun static int pep_init(struct sock *sk)
962*4882a593Smuzhiyun {
963*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
964*4882a593Smuzhiyun 
965*4882a593Smuzhiyun 	sk->sk_destruct = pipe_destruct;
966*4882a593Smuzhiyun 	INIT_HLIST_HEAD(&pn->hlist);
967*4882a593Smuzhiyun 	pn->listener = NULL;
968*4882a593Smuzhiyun 	skb_queue_head_init(&pn->ctrlreq_queue);
969*4882a593Smuzhiyun 	atomic_set(&pn->tx_credits, 0);
970*4882a593Smuzhiyun 	pn->ifindex = 0;
971*4882a593Smuzhiyun 	pn->peer_type = 0;
972*4882a593Smuzhiyun 	pn->pipe_handle = PN_PIPE_INVALID_HANDLE;
973*4882a593Smuzhiyun 	pn->rx_credits = 0;
974*4882a593Smuzhiyun 	pn->rx_fc = pn->tx_fc = PN_LEGACY_FLOW_CONTROL;
975*4882a593Smuzhiyun 	pn->init_enable = 1;
976*4882a593Smuzhiyun 	pn->aligned = 0;
977*4882a593Smuzhiyun 	return 0;
978*4882a593Smuzhiyun }
979*4882a593Smuzhiyun 
pep_setsockopt(struct sock * sk,int level,int optname,sockptr_t optval,unsigned int optlen)980*4882a593Smuzhiyun static int pep_setsockopt(struct sock *sk, int level, int optname,
981*4882a593Smuzhiyun 			  sockptr_t optval, unsigned int optlen)
982*4882a593Smuzhiyun {
983*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
984*4882a593Smuzhiyun 	int val = 0, err = 0;
985*4882a593Smuzhiyun 
986*4882a593Smuzhiyun 	if (level != SOL_PNPIPE)
987*4882a593Smuzhiyun 		return -ENOPROTOOPT;
988*4882a593Smuzhiyun 	if (optlen >= sizeof(int)) {
989*4882a593Smuzhiyun 		if (copy_from_sockptr(&val, optval, sizeof(int)))
990*4882a593Smuzhiyun 			return -EFAULT;
991*4882a593Smuzhiyun 	}
992*4882a593Smuzhiyun 
993*4882a593Smuzhiyun 	lock_sock(sk);
994*4882a593Smuzhiyun 	switch (optname) {
995*4882a593Smuzhiyun 	case PNPIPE_ENCAP:
996*4882a593Smuzhiyun 		if (val && val != PNPIPE_ENCAP_IP) {
997*4882a593Smuzhiyun 			err = -EINVAL;
998*4882a593Smuzhiyun 			break;
999*4882a593Smuzhiyun 		}
1000*4882a593Smuzhiyun 		if (!pn->ifindex == !val)
1001*4882a593Smuzhiyun 			break; /* Nothing to do! */
1002*4882a593Smuzhiyun 		if (!capable(CAP_NET_ADMIN)) {
1003*4882a593Smuzhiyun 			err = -EPERM;
1004*4882a593Smuzhiyun 			break;
1005*4882a593Smuzhiyun 		}
1006*4882a593Smuzhiyun 		if (val) {
1007*4882a593Smuzhiyun 			release_sock(sk);
1008*4882a593Smuzhiyun 			err = gprs_attach(sk);
1009*4882a593Smuzhiyun 			if (err > 0) {
1010*4882a593Smuzhiyun 				pn->ifindex = err;
1011*4882a593Smuzhiyun 				err = 0;
1012*4882a593Smuzhiyun 			}
1013*4882a593Smuzhiyun 		} else {
1014*4882a593Smuzhiyun 			pn->ifindex = 0;
1015*4882a593Smuzhiyun 			release_sock(sk);
1016*4882a593Smuzhiyun 			gprs_detach(sk);
1017*4882a593Smuzhiyun 			err = 0;
1018*4882a593Smuzhiyun 		}
1019*4882a593Smuzhiyun 		goto out_norel;
1020*4882a593Smuzhiyun 
1021*4882a593Smuzhiyun 	case PNPIPE_HANDLE:
1022*4882a593Smuzhiyun 		if ((sk->sk_state == TCP_CLOSE) &&
1023*4882a593Smuzhiyun 			(val >= 0) && (val < PN_PIPE_INVALID_HANDLE))
1024*4882a593Smuzhiyun 			pn->pipe_handle = val;
1025*4882a593Smuzhiyun 		else
1026*4882a593Smuzhiyun 			err = -EINVAL;
1027*4882a593Smuzhiyun 		break;
1028*4882a593Smuzhiyun 
1029*4882a593Smuzhiyun 	case PNPIPE_INITSTATE:
1030*4882a593Smuzhiyun 		pn->init_enable = !!val;
1031*4882a593Smuzhiyun 		break;
1032*4882a593Smuzhiyun 
1033*4882a593Smuzhiyun 	default:
1034*4882a593Smuzhiyun 		err = -ENOPROTOOPT;
1035*4882a593Smuzhiyun 	}
1036*4882a593Smuzhiyun 	release_sock(sk);
1037*4882a593Smuzhiyun 
1038*4882a593Smuzhiyun out_norel:
1039*4882a593Smuzhiyun 	return err;
1040*4882a593Smuzhiyun }
1041*4882a593Smuzhiyun 
pep_getsockopt(struct sock * sk,int level,int optname,char __user * optval,int __user * optlen)1042*4882a593Smuzhiyun static int pep_getsockopt(struct sock *sk, int level, int optname,
1043*4882a593Smuzhiyun 				char __user *optval, int __user *optlen)
1044*4882a593Smuzhiyun {
1045*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
1046*4882a593Smuzhiyun 	int len, val;
1047*4882a593Smuzhiyun 
1048*4882a593Smuzhiyun 	if (level != SOL_PNPIPE)
1049*4882a593Smuzhiyun 		return -ENOPROTOOPT;
1050*4882a593Smuzhiyun 	if (get_user(len, optlen))
1051*4882a593Smuzhiyun 		return -EFAULT;
1052*4882a593Smuzhiyun 
1053*4882a593Smuzhiyun 	switch (optname) {
1054*4882a593Smuzhiyun 	case PNPIPE_ENCAP:
1055*4882a593Smuzhiyun 		val = pn->ifindex ? PNPIPE_ENCAP_IP : PNPIPE_ENCAP_NONE;
1056*4882a593Smuzhiyun 		break;
1057*4882a593Smuzhiyun 
1058*4882a593Smuzhiyun 	case PNPIPE_IFINDEX:
1059*4882a593Smuzhiyun 		val = pn->ifindex;
1060*4882a593Smuzhiyun 		break;
1061*4882a593Smuzhiyun 
1062*4882a593Smuzhiyun 	case PNPIPE_HANDLE:
1063*4882a593Smuzhiyun 		val = pn->pipe_handle;
1064*4882a593Smuzhiyun 		if (val == PN_PIPE_INVALID_HANDLE)
1065*4882a593Smuzhiyun 			return -EINVAL;
1066*4882a593Smuzhiyun 		break;
1067*4882a593Smuzhiyun 
1068*4882a593Smuzhiyun 	case PNPIPE_INITSTATE:
1069*4882a593Smuzhiyun 		val = pn->init_enable;
1070*4882a593Smuzhiyun 		break;
1071*4882a593Smuzhiyun 
1072*4882a593Smuzhiyun 	default:
1073*4882a593Smuzhiyun 		return -ENOPROTOOPT;
1074*4882a593Smuzhiyun 	}
1075*4882a593Smuzhiyun 
1076*4882a593Smuzhiyun 	len = min_t(unsigned int, sizeof(int), len);
1077*4882a593Smuzhiyun 	if (put_user(len, optlen))
1078*4882a593Smuzhiyun 		return -EFAULT;
1079*4882a593Smuzhiyun 	if (put_user(val, (int __user *) optval))
1080*4882a593Smuzhiyun 		return -EFAULT;
1081*4882a593Smuzhiyun 	return 0;
1082*4882a593Smuzhiyun }
1083*4882a593Smuzhiyun 
pipe_skb_send(struct sock * sk,struct sk_buff * skb)1084*4882a593Smuzhiyun static int pipe_skb_send(struct sock *sk, struct sk_buff *skb)
1085*4882a593Smuzhiyun {
1086*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
1087*4882a593Smuzhiyun 	struct pnpipehdr *ph;
1088*4882a593Smuzhiyun 	int err;
1089*4882a593Smuzhiyun 
1090*4882a593Smuzhiyun 	if (pn_flow_safe(pn->tx_fc) &&
1091*4882a593Smuzhiyun 	    !atomic_add_unless(&pn->tx_credits, -1, 0)) {
1092*4882a593Smuzhiyun 		kfree_skb(skb);
1093*4882a593Smuzhiyun 		return -ENOBUFS;
1094*4882a593Smuzhiyun 	}
1095*4882a593Smuzhiyun 
1096*4882a593Smuzhiyun 	skb_push(skb, 3 + pn->aligned);
1097*4882a593Smuzhiyun 	skb_reset_transport_header(skb);
1098*4882a593Smuzhiyun 	ph = pnp_hdr(skb);
1099*4882a593Smuzhiyun 	ph->utid = 0;
1100*4882a593Smuzhiyun 	if (pn->aligned) {
1101*4882a593Smuzhiyun 		ph->message_id = PNS_PIPE_ALIGNED_DATA;
1102*4882a593Smuzhiyun 		ph->data0 = 0; /* padding */
1103*4882a593Smuzhiyun 	} else
1104*4882a593Smuzhiyun 		ph->message_id = PNS_PIPE_DATA;
1105*4882a593Smuzhiyun 	ph->pipe_handle = pn->pipe_handle;
1106*4882a593Smuzhiyun 	err = pn_skb_send(sk, skb, NULL);
1107*4882a593Smuzhiyun 
1108*4882a593Smuzhiyun 	if (err && pn_flow_safe(pn->tx_fc))
1109*4882a593Smuzhiyun 		atomic_inc(&pn->tx_credits);
1110*4882a593Smuzhiyun 	return err;
1111*4882a593Smuzhiyun 
1112*4882a593Smuzhiyun }
1113*4882a593Smuzhiyun 
pep_sendmsg(struct sock * sk,struct msghdr * msg,size_t len)1114*4882a593Smuzhiyun static int pep_sendmsg(struct sock *sk, struct msghdr *msg, size_t len)
1115*4882a593Smuzhiyun {
1116*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
1117*4882a593Smuzhiyun 	struct sk_buff *skb;
1118*4882a593Smuzhiyun 	long timeo;
1119*4882a593Smuzhiyun 	int flags = msg->msg_flags;
1120*4882a593Smuzhiyun 	int err, done;
1121*4882a593Smuzhiyun 
1122*4882a593Smuzhiyun 	if (len > USHRT_MAX)
1123*4882a593Smuzhiyun 		return -EMSGSIZE;
1124*4882a593Smuzhiyun 
1125*4882a593Smuzhiyun 	if ((msg->msg_flags & ~(MSG_DONTWAIT|MSG_EOR|MSG_NOSIGNAL|
1126*4882a593Smuzhiyun 				MSG_CMSG_COMPAT)) ||
1127*4882a593Smuzhiyun 			!(msg->msg_flags & MSG_EOR))
1128*4882a593Smuzhiyun 		return -EOPNOTSUPP;
1129*4882a593Smuzhiyun 
1130*4882a593Smuzhiyun 	skb = sock_alloc_send_skb(sk, MAX_PNPIPE_HEADER + len,
1131*4882a593Smuzhiyun 					flags & MSG_DONTWAIT, &err);
1132*4882a593Smuzhiyun 	if (!skb)
1133*4882a593Smuzhiyun 		return err;
1134*4882a593Smuzhiyun 
1135*4882a593Smuzhiyun 	skb_reserve(skb, MAX_PHONET_HEADER + 3 + pn->aligned);
1136*4882a593Smuzhiyun 	err = memcpy_from_msg(skb_put(skb, len), msg, len);
1137*4882a593Smuzhiyun 	if (err < 0)
1138*4882a593Smuzhiyun 		goto outfree;
1139*4882a593Smuzhiyun 
1140*4882a593Smuzhiyun 	lock_sock(sk);
1141*4882a593Smuzhiyun 	timeo = sock_sndtimeo(sk, flags & MSG_DONTWAIT);
1142*4882a593Smuzhiyun 	if ((1 << sk->sk_state) & (TCPF_LISTEN|TCPF_CLOSE)) {
1143*4882a593Smuzhiyun 		err = -ENOTCONN;
1144*4882a593Smuzhiyun 		goto out;
1145*4882a593Smuzhiyun 	}
1146*4882a593Smuzhiyun 	if (sk->sk_state != TCP_ESTABLISHED) {
1147*4882a593Smuzhiyun 		/* Wait until the pipe gets to enabled state */
1148*4882a593Smuzhiyun disabled:
1149*4882a593Smuzhiyun 		err = sk_stream_wait_connect(sk, &timeo);
1150*4882a593Smuzhiyun 		if (err)
1151*4882a593Smuzhiyun 			goto out;
1152*4882a593Smuzhiyun 
1153*4882a593Smuzhiyun 		if (sk->sk_state == TCP_CLOSE_WAIT) {
1154*4882a593Smuzhiyun 			err = -ECONNRESET;
1155*4882a593Smuzhiyun 			goto out;
1156*4882a593Smuzhiyun 		}
1157*4882a593Smuzhiyun 	}
1158*4882a593Smuzhiyun 	BUG_ON(sk->sk_state != TCP_ESTABLISHED);
1159*4882a593Smuzhiyun 
1160*4882a593Smuzhiyun 	/* Wait until flow control allows TX */
1161*4882a593Smuzhiyun 	done = atomic_read(&pn->tx_credits);
1162*4882a593Smuzhiyun 	while (!done) {
1163*4882a593Smuzhiyun 		DEFINE_WAIT_FUNC(wait, woken_wake_function);
1164*4882a593Smuzhiyun 
1165*4882a593Smuzhiyun 		if (!timeo) {
1166*4882a593Smuzhiyun 			err = -EAGAIN;
1167*4882a593Smuzhiyun 			goto out;
1168*4882a593Smuzhiyun 		}
1169*4882a593Smuzhiyun 		if (signal_pending(current)) {
1170*4882a593Smuzhiyun 			err = sock_intr_errno(timeo);
1171*4882a593Smuzhiyun 			goto out;
1172*4882a593Smuzhiyun 		}
1173*4882a593Smuzhiyun 
1174*4882a593Smuzhiyun 		add_wait_queue(sk_sleep(sk), &wait);
1175*4882a593Smuzhiyun 		done = sk_wait_event(sk, &timeo, atomic_read(&pn->tx_credits), &wait);
1176*4882a593Smuzhiyun 		remove_wait_queue(sk_sleep(sk), &wait);
1177*4882a593Smuzhiyun 
1178*4882a593Smuzhiyun 		if (sk->sk_state != TCP_ESTABLISHED)
1179*4882a593Smuzhiyun 			goto disabled;
1180*4882a593Smuzhiyun 	}
1181*4882a593Smuzhiyun 
1182*4882a593Smuzhiyun 	err = pipe_skb_send(sk, skb);
1183*4882a593Smuzhiyun 	if (err >= 0)
1184*4882a593Smuzhiyun 		err = len; /* success! */
1185*4882a593Smuzhiyun 	skb = NULL;
1186*4882a593Smuzhiyun out:
1187*4882a593Smuzhiyun 	release_sock(sk);
1188*4882a593Smuzhiyun outfree:
1189*4882a593Smuzhiyun 	kfree_skb(skb);
1190*4882a593Smuzhiyun 	return err;
1191*4882a593Smuzhiyun }
1192*4882a593Smuzhiyun 
pep_writeable(struct sock * sk)1193*4882a593Smuzhiyun int pep_writeable(struct sock *sk)
1194*4882a593Smuzhiyun {
1195*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
1196*4882a593Smuzhiyun 
1197*4882a593Smuzhiyun 	return atomic_read(&pn->tx_credits);
1198*4882a593Smuzhiyun }
1199*4882a593Smuzhiyun 
pep_write(struct sock * sk,struct sk_buff * skb)1200*4882a593Smuzhiyun int pep_write(struct sock *sk, struct sk_buff *skb)
1201*4882a593Smuzhiyun {
1202*4882a593Smuzhiyun 	struct sk_buff *rskb, *fs;
1203*4882a593Smuzhiyun 	int flen = 0;
1204*4882a593Smuzhiyun 
1205*4882a593Smuzhiyun 	if (pep_sk(sk)->aligned)
1206*4882a593Smuzhiyun 		return pipe_skb_send(sk, skb);
1207*4882a593Smuzhiyun 
1208*4882a593Smuzhiyun 	rskb = alloc_skb(MAX_PNPIPE_HEADER, GFP_ATOMIC);
1209*4882a593Smuzhiyun 	if (!rskb) {
1210*4882a593Smuzhiyun 		kfree_skb(skb);
1211*4882a593Smuzhiyun 		return -ENOMEM;
1212*4882a593Smuzhiyun 	}
1213*4882a593Smuzhiyun 	skb_shinfo(rskb)->frag_list = skb;
1214*4882a593Smuzhiyun 	rskb->len += skb->len;
1215*4882a593Smuzhiyun 	rskb->data_len += rskb->len;
1216*4882a593Smuzhiyun 	rskb->truesize += rskb->len;
1217*4882a593Smuzhiyun 
1218*4882a593Smuzhiyun 	/* Avoid nested fragments */
1219*4882a593Smuzhiyun 	skb_walk_frags(skb, fs)
1220*4882a593Smuzhiyun 		flen += fs->len;
1221*4882a593Smuzhiyun 	skb->next = skb_shinfo(skb)->frag_list;
1222*4882a593Smuzhiyun 	skb_frag_list_init(skb);
1223*4882a593Smuzhiyun 	skb->len -= flen;
1224*4882a593Smuzhiyun 	skb->data_len -= flen;
1225*4882a593Smuzhiyun 	skb->truesize -= flen;
1226*4882a593Smuzhiyun 
1227*4882a593Smuzhiyun 	skb_reserve(rskb, MAX_PHONET_HEADER + 3);
1228*4882a593Smuzhiyun 	return pipe_skb_send(sk, rskb);
1229*4882a593Smuzhiyun }
1230*4882a593Smuzhiyun 
pep_read(struct sock * sk)1231*4882a593Smuzhiyun struct sk_buff *pep_read(struct sock *sk)
1232*4882a593Smuzhiyun {
1233*4882a593Smuzhiyun 	struct sk_buff *skb = skb_dequeue(&sk->sk_receive_queue);
1234*4882a593Smuzhiyun 
1235*4882a593Smuzhiyun 	if (sk->sk_state == TCP_ESTABLISHED)
1236*4882a593Smuzhiyun 		pipe_grant_credits(sk, GFP_ATOMIC);
1237*4882a593Smuzhiyun 	return skb;
1238*4882a593Smuzhiyun }
1239*4882a593Smuzhiyun 
pep_recvmsg(struct sock * sk,struct msghdr * msg,size_t len,int noblock,int flags,int * addr_len)1240*4882a593Smuzhiyun static int pep_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
1241*4882a593Smuzhiyun 		       int noblock, int flags, int *addr_len)
1242*4882a593Smuzhiyun {
1243*4882a593Smuzhiyun 	struct sk_buff *skb;
1244*4882a593Smuzhiyun 	int err;
1245*4882a593Smuzhiyun 
1246*4882a593Smuzhiyun 	if (flags & ~(MSG_OOB|MSG_PEEK|MSG_TRUNC|MSG_DONTWAIT|MSG_WAITALL|
1247*4882a593Smuzhiyun 			MSG_NOSIGNAL|MSG_CMSG_COMPAT))
1248*4882a593Smuzhiyun 		return -EOPNOTSUPP;
1249*4882a593Smuzhiyun 
1250*4882a593Smuzhiyun 	if (unlikely(1 << sk->sk_state & (TCPF_LISTEN | TCPF_CLOSE)))
1251*4882a593Smuzhiyun 		return -ENOTCONN;
1252*4882a593Smuzhiyun 
1253*4882a593Smuzhiyun 	if ((flags & MSG_OOB) || sock_flag(sk, SOCK_URGINLINE)) {
1254*4882a593Smuzhiyun 		/* Dequeue and acknowledge control request */
1255*4882a593Smuzhiyun 		struct pep_sock *pn = pep_sk(sk);
1256*4882a593Smuzhiyun 
1257*4882a593Smuzhiyun 		if (flags & MSG_PEEK)
1258*4882a593Smuzhiyun 			return -EOPNOTSUPP;
1259*4882a593Smuzhiyun 		skb = skb_dequeue(&pn->ctrlreq_queue);
1260*4882a593Smuzhiyun 		if (skb) {
1261*4882a593Smuzhiyun 			pep_ctrlreq_error(sk, skb, PN_PIPE_NO_ERROR,
1262*4882a593Smuzhiyun 						GFP_KERNEL);
1263*4882a593Smuzhiyun 			msg->msg_flags |= MSG_OOB;
1264*4882a593Smuzhiyun 			goto copy;
1265*4882a593Smuzhiyun 		}
1266*4882a593Smuzhiyun 		if (flags & MSG_OOB)
1267*4882a593Smuzhiyun 			return -EINVAL;
1268*4882a593Smuzhiyun 	}
1269*4882a593Smuzhiyun 
1270*4882a593Smuzhiyun 	skb = skb_recv_datagram(sk, flags, noblock, &err);
1271*4882a593Smuzhiyun 	lock_sock(sk);
1272*4882a593Smuzhiyun 	if (skb == NULL) {
1273*4882a593Smuzhiyun 		if (err == -ENOTCONN && sk->sk_state == TCP_CLOSE_WAIT)
1274*4882a593Smuzhiyun 			err = -ECONNRESET;
1275*4882a593Smuzhiyun 		release_sock(sk);
1276*4882a593Smuzhiyun 		return err;
1277*4882a593Smuzhiyun 	}
1278*4882a593Smuzhiyun 
1279*4882a593Smuzhiyun 	if (sk->sk_state == TCP_ESTABLISHED)
1280*4882a593Smuzhiyun 		pipe_grant_credits(sk, GFP_KERNEL);
1281*4882a593Smuzhiyun 	release_sock(sk);
1282*4882a593Smuzhiyun copy:
1283*4882a593Smuzhiyun 	msg->msg_flags |= MSG_EOR;
1284*4882a593Smuzhiyun 	if (skb->len > len)
1285*4882a593Smuzhiyun 		msg->msg_flags |= MSG_TRUNC;
1286*4882a593Smuzhiyun 	else
1287*4882a593Smuzhiyun 		len = skb->len;
1288*4882a593Smuzhiyun 
1289*4882a593Smuzhiyun 	err = skb_copy_datagram_msg(skb, 0, msg, len);
1290*4882a593Smuzhiyun 	if (!err)
1291*4882a593Smuzhiyun 		err = (flags & MSG_TRUNC) ? skb->len : len;
1292*4882a593Smuzhiyun 
1293*4882a593Smuzhiyun 	skb_free_datagram(sk, skb);
1294*4882a593Smuzhiyun 	return err;
1295*4882a593Smuzhiyun }
1296*4882a593Smuzhiyun 
pep_sock_unhash(struct sock * sk)1297*4882a593Smuzhiyun static void pep_sock_unhash(struct sock *sk)
1298*4882a593Smuzhiyun {
1299*4882a593Smuzhiyun 	struct pep_sock *pn = pep_sk(sk);
1300*4882a593Smuzhiyun 	struct sock *skparent = NULL;
1301*4882a593Smuzhiyun 
1302*4882a593Smuzhiyun 	lock_sock(sk);
1303*4882a593Smuzhiyun 
1304*4882a593Smuzhiyun 	if (pn->listener != NULL) {
1305*4882a593Smuzhiyun 		skparent = pn->listener;
1306*4882a593Smuzhiyun 		pn->listener = NULL;
1307*4882a593Smuzhiyun 		release_sock(sk);
1308*4882a593Smuzhiyun 
1309*4882a593Smuzhiyun 		pn = pep_sk(skparent);
1310*4882a593Smuzhiyun 		lock_sock(skparent);
1311*4882a593Smuzhiyun 		sk_del_node_init(sk);
1312*4882a593Smuzhiyun 		sk = skparent;
1313*4882a593Smuzhiyun 	}
1314*4882a593Smuzhiyun 
1315*4882a593Smuzhiyun 	/* Unhash a listening sock only when it is closed
1316*4882a593Smuzhiyun 	 * and all of its active connected pipes are closed. */
1317*4882a593Smuzhiyun 	if (hlist_empty(&pn->hlist))
1318*4882a593Smuzhiyun 		pn_sock_unhash(&pn->pn_sk.sk);
1319*4882a593Smuzhiyun 	release_sock(sk);
1320*4882a593Smuzhiyun 
1321*4882a593Smuzhiyun 	if (skparent)
1322*4882a593Smuzhiyun 		sock_put(skparent);
1323*4882a593Smuzhiyun }
1324*4882a593Smuzhiyun 
1325*4882a593Smuzhiyun static struct proto pep_proto = {
1326*4882a593Smuzhiyun 	.close		= pep_sock_close,
1327*4882a593Smuzhiyun 	.accept		= pep_sock_accept,
1328*4882a593Smuzhiyun 	.connect	= pep_sock_connect,
1329*4882a593Smuzhiyun 	.ioctl		= pep_ioctl,
1330*4882a593Smuzhiyun 	.init		= pep_init,
1331*4882a593Smuzhiyun 	.setsockopt	= pep_setsockopt,
1332*4882a593Smuzhiyun 	.getsockopt	= pep_getsockopt,
1333*4882a593Smuzhiyun 	.sendmsg	= pep_sendmsg,
1334*4882a593Smuzhiyun 	.recvmsg	= pep_recvmsg,
1335*4882a593Smuzhiyun 	.backlog_rcv	= pep_do_rcv,
1336*4882a593Smuzhiyun 	.hash		= pn_sock_hash,
1337*4882a593Smuzhiyun 	.unhash		= pep_sock_unhash,
1338*4882a593Smuzhiyun 	.get_port	= pn_sock_get_port,
1339*4882a593Smuzhiyun 	.obj_size	= sizeof(struct pep_sock),
1340*4882a593Smuzhiyun 	.owner		= THIS_MODULE,
1341*4882a593Smuzhiyun 	.name		= "PNPIPE",
1342*4882a593Smuzhiyun };
1343*4882a593Smuzhiyun 
1344*4882a593Smuzhiyun static const struct phonet_protocol pep_pn_proto = {
1345*4882a593Smuzhiyun 	.ops		= &phonet_stream_ops,
1346*4882a593Smuzhiyun 	.prot		= &pep_proto,
1347*4882a593Smuzhiyun 	.sock_type	= SOCK_SEQPACKET,
1348*4882a593Smuzhiyun };
1349*4882a593Smuzhiyun 
pep_register(void)1350*4882a593Smuzhiyun static int __init pep_register(void)
1351*4882a593Smuzhiyun {
1352*4882a593Smuzhiyun 	return phonet_proto_register(PN_PROTO_PIPE, &pep_pn_proto);
1353*4882a593Smuzhiyun }
1354*4882a593Smuzhiyun 
pep_unregister(void)1355*4882a593Smuzhiyun static void __exit pep_unregister(void)
1356*4882a593Smuzhiyun {
1357*4882a593Smuzhiyun 	phonet_proto_unregister(PN_PROTO_PIPE, &pep_pn_proto);
1358*4882a593Smuzhiyun }
1359*4882a593Smuzhiyun 
1360*4882a593Smuzhiyun module_init(pep_register);
1361*4882a593Smuzhiyun module_exit(pep_unregister);
1362*4882a593Smuzhiyun MODULE_AUTHOR("Remi Denis-Courmont, Nokia");
1363*4882a593Smuzhiyun MODULE_DESCRIPTION("Phonet pipe protocol");
1364*4882a593Smuzhiyun MODULE_LICENSE("GPL");
1365*4882a593Smuzhiyun MODULE_ALIAS_NET_PF_PROTO(PF_PHONET, PN_PROTO_PIPE);
1366