]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/batman-adv/icmp_socket.c
batman-adv: protect bonding with rcu locks
[mirror_ubuntu-bionic-kernel.git] / net / batman-adv / icmp_socket.c
CommitLineData
c6c8fea2 1/*
64afe353 2 * Copyright (C) 2007-2011 B.A.T.M.A.N. contributors:
c6c8fea2
SE
3 *
4 * Marek Lindner
5 *
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of version 2 of the GNU General Public
8 * License as published by the Free Software Foundation.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 * General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License
16 * along with this program; if not, write to the Free Software
17 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
18 * 02110-1301, USA
19 *
20 */
21
22#include "main.h"
23#include <linux/debugfs.h>
24#include <linux/slab.h>
25#include "icmp_socket.h"
26#include "send.h"
c6c8fea2
SE
27#include "hash.h"
28#include "originator.h"
29#include "hard-interface.h"
30
31static struct socket_client *socket_client_hash[256];
32
33static void bat_socket_add_packet(struct socket_client *socket_client,
34 struct icmp_packet_rr *icmp_packet,
35 size_t icmp_len);
36
37void bat_socket_init(void)
38{
39 memset(socket_client_hash, 0, sizeof(socket_client_hash));
40}
41
42static int bat_socket_open(struct inode *inode, struct file *file)
43{
44 unsigned int i;
45 struct socket_client *socket_client;
46
47 nonseekable_open(inode, file);
48
49 socket_client = kmalloc(sizeof(struct socket_client), GFP_KERNEL);
50
51 if (!socket_client)
52 return -ENOMEM;
53
54 for (i = 0; i < ARRAY_SIZE(socket_client_hash); i++) {
55 if (!socket_client_hash[i]) {
56 socket_client_hash[i] = socket_client;
57 break;
58 }
59 }
60
61 if (i == ARRAY_SIZE(socket_client_hash)) {
62 pr_err("Error - can't add another packet client: "
63 "maximum number of clients reached\n");
64 kfree(socket_client);
65 return -EXFULL;
66 }
67
68 INIT_LIST_HEAD(&socket_client->queue_list);
69 socket_client->queue_len = 0;
70 socket_client->index = i;
71 socket_client->bat_priv = inode->i_private;
72 spin_lock_init(&socket_client->lock);
73 init_waitqueue_head(&socket_client->queue_wait);
74
75 file->private_data = socket_client;
76
77 inc_module_count();
78 return 0;
79}
80
81static int bat_socket_release(struct inode *inode, struct file *file)
82{
83 struct socket_client *socket_client = file->private_data;
84 struct socket_packet *socket_packet;
85 struct list_head *list_pos, *list_pos_tmp;
86
87 spin_lock_bh(&socket_client->lock);
88
89 /* for all packets in the queue ... */
90 list_for_each_safe(list_pos, list_pos_tmp, &socket_client->queue_list) {
91 socket_packet = list_entry(list_pos,
92 struct socket_packet, list);
93
94 list_del(list_pos);
95 kfree(socket_packet);
96 }
97
98 socket_client_hash[socket_client->index] = NULL;
99 spin_unlock_bh(&socket_client->lock);
100
101 kfree(socket_client);
102 dec_module_count();
103
104 return 0;
105}
106
107static ssize_t bat_socket_read(struct file *file, char __user *buf,
108 size_t count, loff_t *ppos)
109{
110 struct socket_client *socket_client = file->private_data;
111 struct socket_packet *socket_packet;
112 size_t packet_len;
113 int error;
114
115 if ((file->f_flags & O_NONBLOCK) && (socket_client->queue_len == 0))
116 return -EAGAIN;
117
118 if ((!buf) || (count < sizeof(struct icmp_packet)))
119 return -EINVAL;
120
121 if (!access_ok(VERIFY_WRITE, buf, count))
122 return -EFAULT;
123
124 error = wait_event_interruptible(socket_client->queue_wait,
125 socket_client->queue_len);
126
127 if (error)
128 return error;
129
130 spin_lock_bh(&socket_client->lock);
131
132 socket_packet = list_first_entry(&socket_client->queue_list,
133 struct socket_packet, list);
134 list_del(&socket_packet->list);
135 socket_client->queue_len--;
136
137 spin_unlock_bh(&socket_client->lock);
138
139 error = __copy_to_user(buf, &socket_packet->icmp_packet,
140 socket_packet->icmp_len);
141
142 packet_len = socket_packet->icmp_len;
143 kfree(socket_packet);
144
145 if (error)
146 return -EFAULT;
147
148 return packet_len;
149}
150
151static ssize_t bat_socket_write(struct file *file, const char __user *buff,
152 size_t len, loff_t *off)
153{
154 struct socket_client *socket_client = file->private_data;
155 struct bat_priv *bat_priv = socket_client->bat_priv;
156 struct sk_buff *skb;
157 struct icmp_packet_rr *icmp_packet;
158
159 struct orig_node *orig_node;
160 struct batman_if *batman_if;
161 size_t packet_len = sizeof(struct icmp_packet);
162 uint8_t dstaddr[ETH_ALEN];
163
164 if (len < sizeof(struct icmp_packet)) {
165 bat_dbg(DBG_BATMAN, bat_priv,
166 "Error - can't send packet from char device: "
167 "invalid packet size\n");
168 return -EINVAL;
169 }
170
171 if (!bat_priv->primary_if)
172 return -EFAULT;
173
174 if (len >= sizeof(struct icmp_packet_rr))
175 packet_len = sizeof(struct icmp_packet_rr);
176
177 skb = dev_alloc_skb(packet_len + sizeof(struct ethhdr));
178 if (!skb)
179 return -ENOMEM;
180
181 skb_reserve(skb, sizeof(struct ethhdr));
182 icmp_packet = (struct icmp_packet_rr *)skb_put(skb, packet_len);
183
184 if (!access_ok(VERIFY_READ, buff, packet_len)) {
185 len = -EFAULT;
186 goto free_skb;
187 }
188
189 if (__copy_from_user(icmp_packet, buff, packet_len)) {
190 len = -EFAULT;
191 goto free_skb;
192 }
193
194 if (icmp_packet->packet_type != BAT_ICMP) {
195 bat_dbg(DBG_BATMAN, bat_priv,
196 "Error - can't send packet from char device: "
197 "got bogus packet type (expected: BAT_ICMP)\n");
198 len = -EINVAL;
199 goto free_skb;
200 }
201
202 if (icmp_packet->msg_type != ECHO_REQUEST) {
203 bat_dbg(DBG_BATMAN, bat_priv,
204 "Error - can't send packet from char device: "
205 "got bogus message type (expected: ECHO_REQUEST)\n");
206 len = -EINVAL;
207 goto free_skb;
208 }
209
210 icmp_packet->uid = socket_client->index;
211
212 if (icmp_packet->version != COMPAT_VERSION) {
213 icmp_packet->msg_type = PARAMETER_PROBLEM;
214 icmp_packet->ttl = COMPAT_VERSION;
215 bat_socket_add_packet(socket_client, icmp_packet, packet_len);
216 goto free_skb;
217 }
218
219 if (atomic_read(&bat_priv->mesh_state) != MESH_ACTIVE)
220 goto dst_unreach;
221
222 spin_lock_bh(&bat_priv->orig_hash_lock);
fb778ea1 223 rcu_read_lock();
c6c8fea2
SE
224 orig_node = ((struct orig_node *)hash_find(bat_priv->orig_hash,
225 compare_orig, choose_orig,
226 icmp_packet->dst));
fb778ea1 227 rcu_read_unlock();
c6c8fea2
SE
228
229 if (!orig_node)
230 goto unlock;
231
232 if (!orig_node->router)
233 goto unlock;
234
235 batman_if = orig_node->router->if_incoming;
236 memcpy(dstaddr, orig_node->router->addr, ETH_ALEN);
237
238 spin_unlock_bh(&bat_priv->orig_hash_lock);
239
240 if (!batman_if)
241 goto dst_unreach;
242
243 if (batman_if->if_status != IF_ACTIVE)
244 goto dst_unreach;
245
246 memcpy(icmp_packet->orig,
247 bat_priv->primary_if->net_dev->dev_addr, ETH_ALEN);
248
249 if (packet_len == sizeof(struct icmp_packet_rr))
250 memcpy(icmp_packet->rr, batman_if->net_dev->dev_addr, ETH_ALEN);
251
252
253 send_skb_packet(skb, batman_if, dstaddr);
254
255 goto out;
256
257unlock:
258 spin_unlock_bh(&bat_priv->orig_hash_lock);
259dst_unreach:
260 icmp_packet->msg_type = DESTINATION_UNREACHABLE;
261 bat_socket_add_packet(socket_client, icmp_packet, packet_len);
262free_skb:
263 kfree_skb(skb);
264out:
265 return len;
266}
267
268static unsigned int bat_socket_poll(struct file *file, poll_table *wait)
269{
270 struct socket_client *socket_client = file->private_data;
271
272 poll_wait(file, &socket_client->queue_wait, wait);
273
274 if (socket_client->queue_len > 0)
275 return POLLIN | POLLRDNORM;
276
277 return 0;
278}
279
280static const struct file_operations fops = {
281 .owner = THIS_MODULE,
282 .open = bat_socket_open,
283 .release = bat_socket_release,
284 .read = bat_socket_read,
285 .write = bat_socket_write,
286 .poll = bat_socket_poll,
287 .llseek = no_llseek,
288};
289
290int bat_socket_setup(struct bat_priv *bat_priv)
291{
292 struct dentry *d;
293
294 if (!bat_priv->debug_dir)
295 goto err;
296
297 d = debugfs_create_file(ICMP_SOCKET, S_IFREG | S_IWUSR | S_IRUSR,
298 bat_priv->debug_dir, bat_priv, &fops);
299 if (d)
300 goto err;
301
302 return 0;
303
304err:
305 return 1;
306}
307
308static void bat_socket_add_packet(struct socket_client *socket_client,
309 struct icmp_packet_rr *icmp_packet,
310 size_t icmp_len)
311{
312 struct socket_packet *socket_packet;
313
314 socket_packet = kmalloc(sizeof(struct socket_packet), GFP_ATOMIC);
315
316 if (!socket_packet)
317 return;
318
319 INIT_LIST_HEAD(&socket_packet->list);
320 memcpy(&socket_packet->icmp_packet, icmp_packet, icmp_len);
321 socket_packet->icmp_len = icmp_len;
322
323 spin_lock_bh(&socket_client->lock);
324
325 /* while waiting for the lock the socket_client could have been
326 * deleted */
327 if (!socket_client_hash[icmp_packet->uid]) {
328 spin_unlock_bh(&socket_client->lock);
329 kfree(socket_packet);
330 return;
331 }
332
333 list_add_tail(&socket_packet->list, &socket_client->queue_list);
334 socket_client->queue_len++;
335
336 if (socket_client->queue_len > 100) {
337 socket_packet = list_first_entry(&socket_client->queue_list,
338 struct socket_packet, list);
339
340 list_del(&socket_packet->list);
341 kfree(socket_packet);
342 socket_client->queue_len--;
343 }
344
345 spin_unlock_bh(&socket_client->lock);
346
347 wake_up(&socket_client->queue_wait);
348}
349
350void bat_socket_receive_packet(struct icmp_packet_rr *icmp_packet,
351 size_t icmp_len)
352{
353 struct socket_client *hash = socket_client_hash[icmp_packet->uid];
354
355 if (hash)
356 bat_socket_add_packet(hash, icmp_packet, icmp_len);
357}