]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/blame - net/l2tp/l2tp_ppp.c
Merge remote-tracking branches 'asoc/topic/ac97', 'asoc/topic/ac97-mfd', 'asoc/topic...
[mirror_ubuntu-focal-kernel.git] / net / l2tp / l2tp_ppp.c
CommitLineData
fd558d18
JC
1/*****************************************************************************
2 * Linux PPP over L2TP (PPPoX/PPPoL2TP) Sockets
3 *
4 * PPPoX --- Generic PPP encapsulation socket family
5 * PPPoL2TP --- PPP over L2TP (RFC 2661)
6 *
7 * Version: 2.0.0
8 *
9 * Authors: James Chapman (jchapman@katalix.com)
10 *
11 * Based on original work by Martijn van Oosterhout <kleptog@svana.org>
12 *
13 * License:
14 * This program is free software; you can redistribute it and/or
15 * modify it under the terms of the GNU General Public License
16 * as published by the Free Software Foundation; either version
17 * 2 of the License, or (at your option) any later version.
18 *
19 */
20
21/* This driver handles only L2TP data frames; control frames are handled by a
22 * userspace application.
23 *
24 * To send data in an L2TP session, userspace opens a PPPoL2TP socket and
25 * attaches it to a bound UDP socket with local tunnel_id / session_id and
26 * peer tunnel_id / session_id set. Data can then be sent or received using
27 * regular socket sendmsg() / recvmsg() calls. Kernel parameters of the socket
28 * can be read or modified using ioctl() or [gs]etsockopt() calls.
29 *
30 * When a PPPoL2TP socket is connected with local and peer session_id values
31 * zero, the socket is treated as a special tunnel management socket.
32 *
33 * Here's example userspace code to create a socket for sending/receiving data
34 * over an L2TP session:-
35 *
36 * struct sockaddr_pppol2tp sax;
37 * int fd;
38 * int session_fd;
39 *
40 * fd = socket(AF_PPPOX, SOCK_DGRAM, PX_PROTO_OL2TP);
41 *
42 * sax.sa_family = AF_PPPOX;
43 * sax.sa_protocol = PX_PROTO_OL2TP;
44 * sax.pppol2tp.fd = tunnel_fd; // bound UDP socket
45 * sax.pppol2tp.addr.sin_addr.s_addr = addr->sin_addr.s_addr;
46 * sax.pppol2tp.addr.sin_port = addr->sin_port;
47 * sax.pppol2tp.addr.sin_family = AF_INET;
48 * sax.pppol2tp.s_tunnel = tunnel_id;
49 * sax.pppol2tp.s_session = session_id;
50 * sax.pppol2tp.d_tunnel = peer_tunnel_id;
51 * sax.pppol2tp.d_session = peer_session_id;
52 *
53 * session_fd = connect(fd, (struct sockaddr *)&sax, sizeof(sax));
54 *
55 * A pppd plugin that allows PPP traffic to be carried over L2TP using
56 * this driver is available from the OpenL2TP project at
57 * http://openl2tp.sourceforge.net.
58 */
59
a4ca44fa
JP
60#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
61
fd558d18
JC
62#include <linux/module.h>
63#include <linux/string.h>
64#include <linux/list.h>
65#include <linux/uaccess.h>
66
67#include <linux/kernel.h>
68#include <linux/spinlock.h>
69#include <linux/kthread.h>
70#include <linux/sched.h>
71#include <linux/slab.h>
72#include <linux/errno.h>
73#include <linux/jiffies.h>
74
75#include <linux/netdevice.h>
76#include <linux/net.h>
77#include <linux/inetdevice.h>
78#include <linux/skbuff.h>
79#include <linux/init.h>
80#include <linux/ip.h>
81#include <linux/udp.h>
82#include <linux/if_pppox.h>
83#include <linux/if_pppol2tp.h>
84#include <net/sock.h>
85#include <linux/ppp_channel.h>
86#include <linux/ppp_defs.h>
4b32da2b 87#include <linux/ppp-ioctl.h>
fd558d18
JC
88#include <linux/file.h>
89#include <linux/hash.h>
90#include <linux/sort.h>
91#include <linux/proc_fs.h>
309795f4 92#include <linux/l2tp.h>
fd558d18
JC
93#include <linux/nsproxy.h>
94#include <net/net_namespace.h>
95#include <net/netns/generic.h>
96#include <net/dst.h>
97#include <net/ip.h>
98#include <net/udp.h>
99#include <net/xfrm.h>
cf2f5c88 100#include <net/inet_common.h>
fd558d18
JC
101
102#include <asm/byteorder.h>
60063497 103#include <linux/atomic.h>
fd558d18
JC
104
105#include "l2tp_core.h"
106
107#define PPPOL2TP_DRV_VERSION "V2.0"
108
109/* Space for UDP, L2TP and PPP headers */
110#define PPPOL2TP_HEADER_OVERHEAD 40
111
fd558d18
JC
112/* Number of bytes to build transmit L2TP headers.
113 * Unfortunately the size is different depending on whether sequence numbers
114 * are enabled.
115 */
116#define PPPOL2TP_L2TP_HDR_SIZE_SEQ 10
117#define PPPOL2TP_L2TP_HDR_SIZE_NOSEQ 6
118
119/* Private data of each session. This data lives at the end of struct
120 * l2tp_session, referenced via session->priv[].
121 */
122struct pppol2tp_session {
123 int owner; /* pid that opened the socket */
124
125 struct sock *sock; /* Pointer to the session
126 * PPPoX socket */
127 struct sock *tunnel_sock; /* Pointer to the tunnel UDP
128 * socket */
129 int flags; /* accessed by PPPIOCGFLAGS.
130 * Unused. */
131};
132
133static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb);
134
d7100da0 135static const struct ppp_channel_ops pppol2tp_chan_ops = {
136 .start_xmit = pppol2tp_xmit,
137};
138
fd558d18
JC
139static const struct proto_ops pppol2tp_ops;
140
141/* Helpers to obtain tunnel/session contexts from sockets.
142 */
143static inline struct l2tp_session *pppol2tp_sock_to_session(struct sock *sk)
144{
145 struct l2tp_session *session;
146
147 if (sk == NULL)
148 return NULL;
149
150 sock_hold(sk);
151 session = (struct l2tp_session *)(sk->sk_user_data);
152 if (session == NULL) {
153 sock_put(sk);
154 goto out;
155 }
156
157 BUG_ON(session->magic != L2TP_SESSION_MAGIC);
158
159out:
160 return session;
161}
162
163/*****************************************************************************
164 * Receive data handling
165 *****************************************************************************/
166
167static int pppol2tp_recv_payload_hook(struct sk_buff *skb)
168{
169 /* Skip PPP header, if present. In testing, Microsoft L2TP clients
170 * don't send the PPP header (PPP header compression enabled), but
171 * other clients can include the header. So we cope with both cases
172 * here. The PPP header is always FF03 when using L2TP.
173 *
174 * Note that skb->data[] isn't dereferenced from a u16 ptr here since
175 * the field may be unaligned.
176 */
177 if (!pskb_may_pull(skb, 2))
178 return 1;
179
54c151d9 180 if ((skb->data[0] == PPP_ALLSTATIONS) && (skb->data[1] == PPP_UI))
fd558d18
JC
181 skb_pull(skb, 2);
182
183 return 0;
184}
185
186/* Receive message. This is the recvmsg for the PPPoL2TP socket.
187 */
1b784140
YX
188static int pppol2tp_recvmsg(struct socket *sock, struct msghdr *msg,
189 size_t len, int flags)
fd558d18
JC
190{
191 int err;
192 struct sk_buff *skb;
193 struct sock *sk = sock->sk;
194
195 err = -EIO;
196 if (sk->sk_state & PPPOX_BOUND)
197 goto end;
198
fd558d18
JC
199 err = 0;
200 skb = skb_recv_datagram(sk, flags & ~MSG_DONTWAIT,
201 flags & MSG_DONTWAIT, &err);
202 if (!skb)
203 goto end;
204
205 if (len > skb->len)
206 len = skb->len;
207 else if (len < skb->len)
208 msg->msg_flags |= MSG_TRUNC;
209
51f3d02b 210 err = skb_copy_datagram_msg(skb, 0, msg, len);
fd558d18
JC
211 if (likely(err == 0))
212 err = len;
213
214 kfree_skb(skb);
215end:
216 return err;
217}
218
219static void pppol2tp_recv(struct l2tp_session *session, struct sk_buff *skb, int data_len)
220{
221 struct pppol2tp_session *ps = l2tp_session_priv(session);
222 struct sock *sk = NULL;
223
224 /* If the socket is bound, send it in to PPP's input queue. Otherwise
225 * queue it on the session socket.
226 */
227 sk = ps->sock;
228 if (sk == NULL)
229 goto no_sock;
230
231 if (sk->sk_state & PPPOX_BOUND) {
232 struct pppox_sock *po;
98f40b3e 233
fba40c63 234 l2tp_dbg(session, L2TP_MSG_DATA,
a4ca44fa
JP
235 "%s: recv %d byte data frame, passing to ppp\n",
236 session->name, data_len);
fd558d18 237
fd558d18
JC
238 po = pppox_sk(sk);
239 ppp_input(&po->chan, skb);
240 } else {
fba40c63 241 l2tp_dbg(session, L2TP_MSG_DATA,
9e9cb622
GN
242 "%s: recv %d byte data frame, passing to L2TP socket\n",
243 session->name, data_len);
fd558d18 244
9e9cb622
GN
245 if (sock_queue_rcv_skb(sk, skb) < 0) {
246 atomic_long_inc(&session->stats.rx_errors);
247 kfree_skb(skb);
248 }
fd558d18
JC
249 }
250
251 return;
252
253no_sock:
fba40c63 254 l2tp_info(session, L2TP_MSG_DATA, "%s: no socket\n", session->name);
fd558d18
JC
255 kfree_skb(skb);
256}
257
258static void pppol2tp_session_sock_hold(struct l2tp_session *session)
259{
260 struct pppol2tp_session *ps = l2tp_session_priv(session);
261
262 if (ps->sock)
263 sock_hold(ps->sock);
264}
265
266static void pppol2tp_session_sock_put(struct l2tp_session *session)
267{
268 struct pppol2tp_session *ps = l2tp_session_priv(session);
269
270 if (ps->sock)
271 sock_put(ps->sock);
272}
273
274/************************************************************************
275 * Transmit handling
276 ***********************************************************************/
277
fd558d18
JC
278/* This is the sendmsg for the PPPoL2TP pppol2tp_session socket. We come here
279 * when a user application does a sendmsg() on the session socket. L2TP and
280 * PPP headers must be inserted into the user's data.
281 */
1b784140 282static int pppol2tp_sendmsg(struct socket *sock, struct msghdr *m,
fd558d18
JC
283 size_t total_len)
284{
fd558d18
JC
285 struct sock *sk = sock->sk;
286 struct sk_buff *skb;
287 int error;
288 struct l2tp_session *session;
289 struct l2tp_tunnel *tunnel;
290 struct pppol2tp_session *ps;
0d76751f 291 int uhlen;
fd558d18
JC
292
293 error = -ENOTCONN;
294 if (sock_flag(sk, SOCK_DEAD) || !(sk->sk_state & PPPOX_CONNECTED))
295 goto error;
296
297 /* Get session and tunnel contexts */
298 error = -EBADF;
299 session = pppol2tp_sock_to_session(sk);
300 if (session == NULL)
301 goto error;
302
303 ps = l2tp_session_priv(session);
304 tunnel = l2tp_sock_to_tunnel(ps->tunnel_sock);
305 if (tunnel == NULL)
306 goto error_put_sess;
307
0d76751f
JC
308 uhlen = (tunnel->encap == L2TP_ENCAPTYPE_UDP) ? sizeof(struct udphdr) : 0;
309
fd558d18
JC
310 /* Allocate a socket buffer */
311 error = -ENOMEM;
312 skb = sock_wmalloc(sk, NET_SKB_PAD + sizeof(struct iphdr) +
0d76751f 313 uhlen + session->hdr_len +
54c151d9 314 2 + total_len, /* 2 bytes for PPP_ALLSTATIONS & PPP_UI */
fd558d18
JC
315 0, GFP_KERNEL);
316 if (!skb)
317 goto error_put_sess_tun;
318
319 /* Reserve space for headers. */
320 skb_reserve(skb, NET_SKB_PAD);
321 skb_reset_network_header(skb);
322 skb_reserve(skb, sizeof(struct iphdr));
323 skb_reset_transport_header(skb);
0d76751f 324 skb_reserve(skb, uhlen);
fd558d18
JC
325
326 /* Add PPP header */
54c151d9
GF
327 skb->data[0] = PPP_ALLSTATIONS;
328 skb->data[1] = PPP_UI;
fd558d18
JC
329 skb_put(skb, 2);
330
331 /* Copy user data into skb */
6ce8e9ce 332 error = memcpy_from_msg(skb_put(skb, total_len), m, total_len);
fd558d18
JC
333 if (error < 0) {
334 kfree_skb(skb);
335 goto error_put_sess_tun;
336 }
fd558d18 337
455cc32b 338 local_bh_disable();
fd558d18 339 l2tp_xmit_skb(session, skb, session->hdr_len);
455cc32b 340 local_bh_enable();
fd558d18
JC
341
342 sock_put(ps->tunnel_sock);
8b82547e 343 sock_put(sk);
fd558d18 344
a6f79d0f 345 return total_len;
fd558d18
JC
346
347error_put_sess_tun:
348 sock_put(ps->tunnel_sock);
349error_put_sess:
350 sock_put(sk);
351error:
352 return error;
353}
354
355/* Transmit function called by generic PPP driver. Sends PPP frame
356 * over PPPoL2TP socket.
357 *
358 * This is almost the same as pppol2tp_sendmsg(), but rather than
359 * being called with a msghdr from userspace, it is called with a skb
360 * from the kernel.
361 *
362 * The supplied skb from ppp doesn't have enough headroom for the
363 * insertion of L2TP, UDP and IP headers so we need to allocate more
364 * headroom in the skb. This will create a cloned skb. But we must be
365 * careful in the error case because the caller will expect to free
366 * the skb it supplied, not our cloned skb. So we take care to always
367 * leave the original skb unfreed if we return an error.
368 */
369static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb)
370{
fd558d18
JC
371 struct sock *sk = (struct sock *) chan->private;
372 struct sock *sk_tun;
fd558d18
JC
373 struct l2tp_session *session;
374 struct l2tp_tunnel *tunnel;
375 struct pppol2tp_session *ps;
09df57ca 376 int uhlen, headroom;
fd558d18
JC
377
378 if (sock_flag(sk, SOCK_DEAD) || !(sk->sk_state & PPPOX_CONNECTED))
379 goto abort;
380
381 /* Get session and tunnel contexts from the socket */
382 session = pppol2tp_sock_to_session(sk);
383 if (session == NULL)
384 goto abort;
385
386 ps = l2tp_session_priv(session);
387 sk_tun = ps->tunnel_sock;
388 if (sk_tun == NULL)
389 goto abort_put_sess;
390 tunnel = l2tp_sock_to_tunnel(sk_tun);
391 if (tunnel == NULL)
392 goto abort_put_sess;
393
09df57ca
ED
394 uhlen = (tunnel->encap == L2TP_ENCAPTYPE_UDP) ? sizeof(struct udphdr) : 0;
395 headroom = NET_SKB_PAD +
396 sizeof(struct iphdr) + /* IP header */
397 uhlen + /* UDP header (if L2TP_ENCAPTYPE_UDP) */
398 session->hdr_len + /* L2TP header */
54c151d9 399 2; /* 2 bytes for PPP_ALLSTATIONS & PPP_UI */
09df57ca 400 if (skb_cow_head(skb, headroom))
fd558d18
JC
401 goto abort_put_sess_tun;
402
fd558d18 403 /* Setup PPP header */
54c151d9
GF
404 __skb_push(skb, 2);
405 skb->data[0] = PPP_ALLSTATIONS;
406 skb->data[1] = PPP_UI;
fd558d18 407
455cc32b 408 local_bh_disable();
e0d4435f 409 l2tp_xmit_skb(session, skb, session->hdr_len);
455cc32b 410 local_bh_enable();
fd558d18
JC
411
412 sock_put(sk_tun);
413 sock_put(sk);
414 return 1;
415
416abort_put_sess_tun:
417 sock_put(sk_tun);
418abort_put_sess:
419 sock_put(sk);
420abort:
421 /* Free the original skb */
422 kfree_skb(skb);
423 return 1;
424}
425
426/*****************************************************************************
427 * Session (and tunnel control) socket create/destroy.
428 *****************************************************************************/
429
430/* Called by l2tp_core when a session socket is being closed.
431 */
432static void pppol2tp_session_close(struct l2tp_session *session)
433{
434 struct pppol2tp_session *ps = l2tp_session_priv(session);
435 struct sock *sk = ps->sock;
cf2f5c88 436 struct socket *sock = sk->sk_socket;
fd558d18
JC
437
438 BUG_ON(session->magic != L2TP_SESSION_MAGIC);
439
cdd10c96 440 if (sock)
54c151d9 441 inet_shutdown(sock, SEND_SHUTDOWN);
cdd10c96
GN
442
443 /* Don't let the session go away before our socket does */
444 l2tp_session_inc_refcount(session);
fd558d18
JC
445}
446
447/* Really kill the session socket. (Called from sock_put() if
448 * refcnt == 0.)
449 */
450static void pppol2tp_session_destruct(struct sock *sk)
451{
f6e16b29 452 struct l2tp_session *session = sk->sk_user_data;
e91793bb
GN
453
454 skb_queue_purge(&sk->sk_receive_queue);
455 skb_queue_purge(&sk->sk_write_queue);
456
f6e16b29 457 if (session) {
fd558d18
JC
458 sk->sk_user_data = NULL;
459 BUG_ON(session->magic != L2TP_SESSION_MAGIC);
460 l2tp_session_dec_refcount(session);
461 }
fd558d18
JC
462}
463
464/* Called when the PPPoX socket (session) is closed.
465 */
466static int pppol2tp_release(struct socket *sock)
467{
468 struct sock *sk = sock->sk;
469 struct l2tp_session *session;
470 int error;
471
472 if (!sk)
473 return 0;
474
475 error = -EBADF;
476 lock_sock(sk);
477 if (sock_flag(sk, SOCK_DEAD) != 0)
478 goto error;
479
480 pppox_unbind_sock(sk);
481
482 /* Signal the death of the socket. */
483 sk->sk_state = PPPOX_DEAD;
484 sock_orphan(sk);
485 sock->sk = NULL;
486
487 session = pppol2tp_sock_to_session(sk);
488
489 /* Purge any queued data */
fd558d18 490 if (session != NULL) {
f6e16b29 491 __l2tp_session_unhash(session);
cf2f5c88 492 l2tp_session_queue_purge(session);
fd558d18
JC
493 sock_put(sk);
494 }
fd558d18
JC
495 release_sock(sk);
496
497 /* This will delete the session context via
498 * pppol2tp_session_destruct() if the socket's refcnt drops to
499 * zero.
500 */
501 sock_put(sk);
502
503 return 0;
504
505error:
506 release_sock(sk);
507 return error;
508}
509
510static struct proto pppol2tp_sk_proto = {
511 .name = "PPPOL2TP",
512 .owner = THIS_MODULE,
513 .obj_size = sizeof(struct pppox_sock),
514};
515
516static int pppol2tp_backlog_recv(struct sock *sk, struct sk_buff *skb)
517{
518 int rc;
519
520 rc = l2tp_udp_encap_recv(sk, skb);
521 if (rc)
522 kfree_skb(skb);
523
524 return NET_RX_SUCCESS;
525}
526
527/* socket() handler. Initialize a new struct sock.
528 */
11aa9c28 529static int pppol2tp_create(struct net *net, struct socket *sock, int kern)
fd558d18
JC
530{
531 int error = -ENOMEM;
532 struct sock *sk;
533
11aa9c28 534 sk = sk_alloc(net, PF_PPPOX, GFP_KERNEL, &pppol2tp_sk_proto, kern);
fd558d18
JC
535 if (!sk)
536 goto out;
537
538 sock_init_data(sock, sk);
539
540 sock->state = SS_UNCONNECTED;
541 sock->ops = &pppol2tp_ops;
542
543 sk->sk_backlog_rcv = pppol2tp_backlog_recv;
544 sk->sk_protocol = PX_PROTO_OL2TP;
545 sk->sk_family = PF_PPPOX;
546 sk->sk_state = PPPOX_NONE;
547 sk->sk_type = SOCK_STREAM;
548 sk->sk_destruct = pppol2tp_session_destruct;
549
550 error = 0;
551
552out:
553 return error;
554}
555
9dd79945 556#if IS_ENABLED(CONFIG_L2TP_DEBUGFS)
0ad66140
JC
557static void pppol2tp_show(struct seq_file *m, void *arg)
558{
559 struct l2tp_session *session = arg;
560 struct pppol2tp_session *ps = l2tp_session_priv(session);
561
562 if (ps) {
563 struct pppox_sock *po = pppox_sk(ps->sock);
564 if (po)
565 seq_printf(m, " interface %s\n", ppp_dev_name(&po->chan));
566 }
567}
568#endif
569
fd558d18
JC
570/* connect() handler. Attach a PPPoX socket to a tunnel UDP socket
571 */
572static int pppol2tp_connect(struct socket *sock, struct sockaddr *uservaddr,
573 int sockaddr_len, int flags)
574{
575 struct sock *sk = sock->sk;
576 struct sockaddr_pppol2tp *sp = (struct sockaddr_pppol2tp *) uservaddr;
577 struct pppox_sock *po = pppox_sk(sk);
578 struct l2tp_session *session = NULL;
579 struct l2tp_tunnel *tunnel;
580 struct pppol2tp_session *ps;
581 struct dst_entry *dst;
582 struct l2tp_session_cfg cfg = { 0, };
583 int error = 0;
e0d4435f
JC
584 u32 tunnel_id, peer_tunnel_id;
585 u32 session_id, peer_session_id;
dbdbc73b 586 bool drop_refcnt = false;
f9e56baf 587 bool drop_tunnel = false;
e0d4435f
JC
588 int ver = 2;
589 int fd;
fd558d18
JC
590
591 lock_sock(sk);
592
593 error = -EINVAL;
594 if (sp->sa_protocol != PX_PROTO_OL2TP)
595 goto end;
596
597 /* Check for already bound sockets */
598 error = -EBUSY;
599 if (sk->sk_state & PPPOX_CONNECTED)
600 goto end;
601
602 /* We don't supporting rebinding anyway */
603 error = -EALREADY;
604 if (sk->sk_user_data)
605 goto end; /* socket is already attached */
606
b79585f5
JC
607 /* Get params from socket address. Handle L2TPv2 and L2TPv3.
608 * This is nasty because there are different sockaddr_pppol2tp
609 * structs for L2TPv2, L2TPv3, over IPv4 and IPv6. We use
610 * the sockaddr size to determine which structure the caller
611 * is using.
612 */
613 peer_tunnel_id = 0;
e0d4435f
JC
614 if (sockaddr_len == sizeof(struct sockaddr_pppol2tp)) {
615 fd = sp->pppol2tp.fd;
616 tunnel_id = sp->pppol2tp.s_tunnel;
617 peer_tunnel_id = sp->pppol2tp.d_tunnel;
618 session_id = sp->pppol2tp.s_session;
619 peer_session_id = sp->pppol2tp.d_session;
620 } else if (sockaddr_len == sizeof(struct sockaddr_pppol2tpv3)) {
b79585f5
JC
621 struct sockaddr_pppol2tpv3 *sp3 =
622 (struct sockaddr_pppol2tpv3 *) sp;
e0d4435f
JC
623 ver = 3;
624 fd = sp3->pppol2tp.fd;
625 tunnel_id = sp3->pppol2tp.s_tunnel;
626 peer_tunnel_id = sp3->pppol2tp.d_tunnel;
627 session_id = sp3->pppol2tp.s_session;
628 peer_session_id = sp3->pppol2tp.d_session;
b79585f5
JC
629 } else if (sockaddr_len == sizeof(struct sockaddr_pppol2tpin6)) {
630 struct sockaddr_pppol2tpin6 *sp6 =
631 (struct sockaddr_pppol2tpin6 *) sp;
632 fd = sp6->pppol2tp.fd;
633 tunnel_id = sp6->pppol2tp.s_tunnel;
634 peer_tunnel_id = sp6->pppol2tp.d_tunnel;
635 session_id = sp6->pppol2tp.s_session;
636 peer_session_id = sp6->pppol2tp.d_session;
637 } else if (sockaddr_len == sizeof(struct sockaddr_pppol2tpv3in6)) {
638 struct sockaddr_pppol2tpv3in6 *sp6 =
639 (struct sockaddr_pppol2tpv3in6 *) sp;
640 ver = 3;
641 fd = sp6->pppol2tp.fd;
642 tunnel_id = sp6->pppol2tp.s_tunnel;
643 peer_tunnel_id = sp6->pppol2tp.d_tunnel;
644 session_id = sp6->pppol2tp.s_session;
645 peer_session_id = sp6->pppol2tp.d_session;
e0d4435f
JC
646 } else {
647 error = -EINVAL;
648 goto end; /* bad socket address */
649 }
650
651 /* Don't bind if tunnel_id is 0 */
fd558d18 652 error = -EINVAL;
e0d4435f 653 if (tunnel_id == 0)
fd558d18
JC
654 goto end;
655
f9e56baf
GN
656 tunnel = l2tp_tunnel_get(sock_net(sk), tunnel_id);
657 if (tunnel)
658 drop_tunnel = true;
309795f4 659
e0d4435f
JC
660 /* Special case: create tunnel context if session_id and
661 * peer_session_id is 0. Otherwise look up tunnel using supplied
fd558d18
JC
662 * tunnel id.
663 */
e0d4435f 664 if ((session_id == 0) && (peer_session_id == 0)) {
309795f4
JC
665 if (tunnel == NULL) {
666 struct l2tp_tunnel_cfg tcfg = {
667 .encap = L2TP_ENCAPTYPE_UDP,
668 .debug = 0,
669 };
670 error = l2tp_tunnel_create(sock_net(sk), fd, ver, tunnel_id, peer_tunnel_id, &tcfg, &tunnel);
671 if (error < 0)
672 goto end;
673 }
fd558d18 674 } else {
fd558d18
JC
675 /* Error if we can't find the tunnel */
676 error = -ENOENT;
677 if (tunnel == NULL)
678 goto end;
679
680 /* Error if socket is not prepped */
681 if (tunnel->sock == NULL)
682 goto end;
683 }
684
685 if (tunnel->recv_payload_hook == NULL)
686 tunnel->recv_payload_hook = pppol2tp_recv_payload_hook;
687
b79585f5
JC
688 if (tunnel->peer_tunnel_id == 0)
689 tunnel->peer_tunnel_id = peer_tunnel_id;
fd558d18 690
dbdbc73b
GN
691 session = l2tp_session_get(sock_net(sk), tunnel, session_id, false);
692 if (session) {
693 drop_refcnt = true;
694 ps = l2tp_session_priv(session);
695
696 /* Using a pre-existing session is fine as long as it hasn't
697 * been connected yet.
309795f4 698 */
dbdbc73b
GN
699 if (ps->sock) {
700 error = -EEXIST;
701 goto end;
702 }
309795f4 703
dbdbc73b
GN
704 /* consistency checks */
705 if (ps->tunnel_sock != tunnel->sock) {
706 error = -EEXIST;
309795f4
JC
707 goto end;
708 }
709 } else {
dbdbc73b
GN
710 /* Default MTU must allow space for UDP/L2TP/PPP headers */
711 cfg.mtu = 1500 - PPPOL2TP_HEADER_OVERHEAD;
712 cfg.mru = cfg.mtu;
309795f4 713
dbdbc73b
GN
714 session = l2tp_session_create(sizeof(struct pppol2tp_session),
715 tunnel, session_id,
716 peer_session_id, &cfg);
717 if (IS_ERR(session)) {
718 error = PTR_ERR(session);
309795f4 719 goto end;
dbdbc73b 720 }
fd558d18
JC
721 }
722
309795f4 723 /* Associate session with its PPPoL2TP socket */
fd558d18
JC
724 ps = l2tp_session_priv(session);
725 ps->owner = current->pid;
726 ps->sock = sk;
727 ps->tunnel_sock = tunnel->sock;
728
729 session->recv_skb = pppol2tp_recv;
730 session->session_close = pppol2tp_session_close;
9dd79945 731#if IS_ENABLED(CONFIG_L2TP_DEBUGFS)
0ad66140
JC
732 session->show = pppol2tp_show;
733#endif
fd558d18
JC
734
735 /* We need to know each time a skb is dropped from the reorder
736 * queue.
737 */
738 session->ref = pppol2tp_session_sock_hold;
739 session->deref = pppol2tp_session_sock_put;
740
741 /* If PMTU discovery was enabled, use the MTU that was discovered */
f34c4a35 742 dst = sk_dst_get(tunnel->sock);
fd558d18 743 if (dst != NULL) {
eed4d839
GN
744 u32 pmtu = dst_mtu(dst);
745
fd558d18
JC
746 if (pmtu != 0)
747 session->mtu = session->mru = pmtu -
748 PPPOL2TP_HEADER_OVERHEAD;
749 dst_release(dst);
750 }
751
752 /* Special case: if source & dest session_id == 0x0000, this
753 * socket is being created to manage the tunnel. Just set up
754 * the internal context for use by ioctl() and sockopt()
755 * handlers.
756 */
757 if ((session->session_id == 0) &&
758 (session->peer_session_id == 0)) {
759 error = 0;
760 goto out_no_ppp;
761 }
762
763 /* The only header we need to worry about is the L2TP
764 * header. This size is different depending on whether
765 * sequence numbers are enabled for the data channel.
766 */
767 po->chan.hdrlen = PPPOL2TP_L2TP_HDR_SIZE_NOSEQ;
768
769 po->chan.private = sk;
770 po->chan.ops = &pppol2tp_chan_ops;
771 po->chan.mtu = session->mtu;
772
773 error = ppp_register_net_channel(sock_net(sk), &po->chan);
774 if (error)
775 goto end;
776
777out_no_ppp:
778 /* This is how we get the session context from the socket. */
779 sk->sk_user_data = session;
780 sk->sk_state = PPPOX_CONNECTED;
fba40c63 781 l2tp_info(session, L2TP_MSG_CONTROL, "%s: created\n",
a4ca44fa 782 session->name);
fd558d18
JC
783
784end:
dbdbc73b
GN
785 if (drop_refcnt)
786 l2tp_session_dec_refcount(session);
f9e56baf
GN
787 if (drop_tunnel)
788 l2tp_tunnel_dec_refcount(tunnel);
fd558d18
JC
789 release_sock(sk);
790
791 return error;
792}
793
309795f4
JC
794#ifdef CONFIG_L2TP_V3
795
f026bc29
GN
796/* Called when creating sessions via the netlink interface. */
797static int pppol2tp_session_create(struct net *net, struct l2tp_tunnel *tunnel,
798 u32 session_id, u32 peer_session_id,
799 struct l2tp_session_cfg *cfg)
309795f4
JC
800{
801 int error;
309795f4
JC
802 struct l2tp_session *session;
803 struct pppol2tp_session *ps;
804
309795f4 805 /* Error if tunnel socket is not prepped */
f026bc29
GN
806 if (!tunnel->sock) {
807 error = -ENOENT;
309795f4 808 goto out;
f026bc29 809 }
309795f4 810
309795f4
JC
811 /* Default MTU values. */
812 if (cfg->mtu == 0)
813 cfg->mtu = 1500 - PPPOL2TP_HEADER_OVERHEAD;
814 if (cfg->mru == 0)
815 cfg->mru = cfg->mtu;
816
817 /* Allocate and initialize a new session context. */
309795f4
JC
818 session = l2tp_session_create(sizeof(struct pppol2tp_session),
819 tunnel, session_id,
820 peer_session_id, cfg);
dbdbc73b
GN
821 if (IS_ERR(session)) {
822 error = PTR_ERR(session);
309795f4 823 goto out;
dbdbc73b 824 }
309795f4
JC
825
826 ps = l2tp_session_priv(session);
827 ps->tunnel_sock = tunnel->sock;
828
fba40c63 829 l2tp_info(session, L2TP_MSG_CONTROL, "%s: created\n",
a4ca44fa 830 session->name);
309795f4
JC
831
832 error = 0;
833
834out:
835 return error;
836}
837
309795f4
JC
838#endif /* CONFIG_L2TP_V3 */
839
fd558d18
JC
840/* getname() support.
841 */
842static int pppol2tp_getname(struct socket *sock, struct sockaddr *uaddr,
843 int *usockaddr_len, int peer)
844{
e0d4435f 845 int len = 0;
fd558d18
JC
846 int error = 0;
847 struct l2tp_session *session;
848 struct l2tp_tunnel *tunnel;
849 struct sock *sk = sock->sk;
850 struct inet_sock *inet;
851 struct pppol2tp_session *pls;
852
853 error = -ENOTCONN;
854 if (sk == NULL)
855 goto end;
56cff471 856 if (!(sk->sk_state & PPPOX_CONNECTED))
fd558d18
JC
857 goto end;
858
859 error = -EBADF;
860 session = pppol2tp_sock_to_session(sk);
861 if (session == NULL)
862 goto end;
863
864 pls = l2tp_session_priv(session);
865 tunnel = l2tp_sock_to_tunnel(pls->tunnel_sock);
4ac36a4a 866 if (tunnel == NULL)
fd558d18 867 goto end_put_sess;
fd558d18 868
bbdb32cb 869 inet = inet_sk(tunnel->sock);
d2cf3361 870 if ((tunnel->version == 2) && (tunnel->sock->sk_family == AF_INET)) {
e0d4435f
JC
871 struct sockaddr_pppol2tp sp;
872 len = sizeof(sp);
873 memset(&sp, 0, len);
874 sp.sa_family = AF_PPPOX;
875 sp.sa_protocol = PX_PROTO_OL2TP;
876 sp.pppol2tp.fd = tunnel->fd;
877 sp.pppol2tp.pid = pls->owner;
878 sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
879 sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
880 sp.pppol2tp.s_session = session->session_id;
881 sp.pppol2tp.d_session = session->peer_session_id;
882 sp.pppol2tp.addr.sin_family = AF_INET;
883 sp.pppol2tp.addr.sin_port = inet->inet_dport;
884 sp.pppol2tp.addr.sin_addr.s_addr = inet->inet_daddr;
885 memcpy(uaddr, &sp, len);
d2cf3361
BL
886#if IS_ENABLED(CONFIG_IPV6)
887 } else if ((tunnel->version == 2) &&
888 (tunnel->sock->sk_family == AF_INET6)) {
d2cf3361 889 struct sockaddr_pppol2tpin6 sp;
efe4208f 890
d2cf3361
BL
891 len = sizeof(sp);
892 memset(&sp, 0, len);
893 sp.sa_family = AF_PPPOX;
894 sp.sa_protocol = PX_PROTO_OL2TP;
895 sp.pppol2tp.fd = tunnel->fd;
896 sp.pppol2tp.pid = pls->owner;
897 sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
898 sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
899 sp.pppol2tp.s_session = session->session_id;
900 sp.pppol2tp.d_session = session->peer_session_id;
901 sp.pppol2tp.addr.sin6_family = AF_INET6;
902 sp.pppol2tp.addr.sin6_port = inet->inet_dport;
efe4208f
ED
903 memcpy(&sp.pppol2tp.addr.sin6_addr, &tunnel->sock->sk_v6_daddr,
904 sizeof(tunnel->sock->sk_v6_daddr));
d2cf3361
BL
905 memcpy(uaddr, &sp, len);
906 } else if ((tunnel->version == 3) &&
907 (tunnel->sock->sk_family == AF_INET6)) {
d2cf3361 908 struct sockaddr_pppol2tpv3in6 sp;
efe4208f 909
d2cf3361
BL
910 len = sizeof(sp);
911 memset(&sp, 0, len);
912 sp.sa_family = AF_PPPOX;
913 sp.sa_protocol = PX_PROTO_OL2TP;
914 sp.pppol2tp.fd = tunnel->fd;
915 sp.pppol2tp.pid = pls->owner;
916 sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
917 sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
918 sp.pppol2tp.s_session = session->session_id;
919 sp.pppol2tp.d_session = session->peer_session_id;
920 sp.pppol2tp.addr.sin6_family = AF_INET6;
921 sp.pppol2tp.addr.sin6_port = inet->inet_dport;
efe4208f
ED
922 memcpy(&sp.pppol2tp.addr.sin6_addr, &tunnel->sock->sk_v6_daddr,
923 sizeof(tunnel->sock->sk_v6_daddr));
d2cf3361
BL
924 memcpy(uaddr, &sp, len);
925#endif
e0d4435f
JC
926 } else if (tunnel->version == 3) {
927 struct sockaddr_pppol2tpv3 sp;
928 len = sizeof(sp);
929 memset(&sp, 0, len);
930 sp.sa_family = AF_PPPOX;
931 sp.sa_protocol = PX_PROTO_OL2TP;
932 sp.pppol2tp.fd = tunnel->fd;
933 sp.pppol2tp.pid = pls->owner;
934 sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
935 sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
936 sp.pppol2tp.s_session = session->session_id;
937 sp.pppol2tp.d_session = session->peer_session_id;
938 sp.pppol2tp.addr.sin_family = AF_INET;
939 sp.pppol2tp.addr.sin_port = inet->inet_dport;
940 sp.pppol2tp.addr.sin_addr.s_addr = inet->inet_daddr;
941 memcpy(uaddr, &sp, len);
942 }
fd558d18
JC
943
944 *usockaddr_len = len;
4ac36a4a 945 error = 0;
fd558d18
JC
946
947 sock_put(pls->tunnel_sock);
948end_put_sess:
949 sock_put(sk);
fd558d18
JC
950end:
951 return error;
952}
953
954/****************************************************************************
955 * ioctl() handlers.
956 *
957 * The PPPoX socket is created for L2TP sessions: tunnels have their own UDP
958 * sockets. However, in order to control kernel tunnel features, we allow
959 * userspace to create a special "tunnel" PPPoX socket which is used for
960 * control only. Tunnel PPPoX sockets have session_id == 0 and simply allow
961 * the user application to issue L2TP setsockopt(), getsockopt() and ioctl()
962 * calls.
963 ****************************************************************************/
964
965static void pppol2tp_copy_stats(struct pppol2tp_ioc_stats *dest,
966 struct l2tp_stats *stats)
967{
7b7c0719
TP
968 dest->tx_packets = atomic_long_read(&stats->tx_packets);
969 dest->tx_bytes = atomic_long_read(&stats->tx_bytes);
970 dest->tx_errors = atomic_long_read(&stats->tx_errors);
971 dest->rx_packets = atomic_long_read(&stats->rx_packets);
972 dest->rx_bytes = atomic_long_read(&stats->rx_bytes);
973 dest->rx_seq_discards = atomic_long_read(&stats->rx_seq_discards);
974 dest->rx_oos_packets = atomic_long_read(&stats->rx_oos_packets);
975 dest->rx_errors = atomic_long_read(&stats->rx_errors);
fd558d18
JC
976}
977
978/* Session ioctl helper.
979 */
980static int pppol2tp_session_ioctl(struct l2tp_session *session,
981 unsigned int cmd, unsigned long arg)
982{
983 struct ifreq ifr;
984 int err = 0;
985 struct sock *sk;
986 int val = (int) arg;
987 struct pppol2tp_session *ps = l2tp_session_priv(session);
988 struct l2tp_tunnel *tunnel = session->tunnel;
989 struct pppol2tp_ioc_stats stats;
990
fba40c63 991 l2tp_dbg(session, L2TP_MSG_CONTROL,
a4ca44fa
JP
992 "%s: pppol2tp_session_ioctl(cmd=%#x, arg=%#lx)\n",
993 session->name, cmd, arg);
fd558d18
JC
994
995 sk = ps->sock;
5903f594
GN
996 if (!sk)
997 return -EBADR;
998
fd558d18
JC
999 sock_hold(sk);
1000
1001 switch (cmd) {
1002 case SIOCGIFMTU:
1003 err = -ENXIO;
1004 if (!(sk->sk_state & PPPOX_CONNECTED))
1005 break;
1006
1007 err = -EFAULT;
1008 if (copy_from_user(&ifr, (void __user *) arg, sizeof(struct ifreq)))
1009 break;
1010 ifr.ifr_mtu = session->mtu;
1011 if (copy_to_user((void __user *) arg, &ifr, sizeof(struct ifreq)))
1012 break;
1013
fba40c63 1014 l2tp_info(session, L2TP_MSG_CONTROL, "%s: get mtu=%d\n",
a4ca44fa 1015 session->name, session->mtu);
fd558d18
JC
1016 err = 0;
1017 break;
1018
1019 case SIOCSIFMTU:
1020 err = -ENXIO;
1021 if (!(sk->sk_state & PPPOX_CONNECTED))
1022 break;
1023
1024 err = -EFAULT;
1025 if (copy_from_user(&ifr, (void __user *) arg, sizeof(struct ifreq)))
1026 break;
1027
1028 session->mtu = ifr.ifr_mtu;
1029
fba40c63 1030 l2tp_info(session, L2TP_MSG_CONTROL, "%s: set mtu=%d\n",
a4ca44fa 1031 session->name, session->mtu);
fd558d18
JC
1032 err = 0;
1033 break;
1034
1035 case PPPIOCGMRU:
1036 err = -ENXIO;
1037 if (!(sk->sk_state & PPPOX_CONNECTED))
1038 break;
1039
1040 err = -EFAULT;
1041 if (put_user(session->mru, (int __user *) arg))
1042 break;
1043
fba40c63 1044 l2tp_info(session, L2TP_MSG_CONTROL, "%s: get mru=%d\n",
a4ca44fa 1045 session->name, session->mru);
fd558d18
JC
1046 err = 0;
1047 break;
1048
1049 case PPPIOCSMRU:
1050 err = -ENXIO;
1051 if (!(sk->sk_state & PPPOX_CONNECTED))
1052 break;
1053
1054 err = -EFAULT;
1055 if (get_user(val, (int __user *) arg))
1056 break;
1057
1058 session->mru = val;
fba40c63 1059 l2tp_info(session, L2TP_MSG_CONTROL, "%s: set mru=%d\n",
a4ca44fa 1060 session->name, session->mru);
fd558d18
JC
1061 err = 0;
1062 break;
1063
1064 case PPPIOCGFLAGS:
1065 err = -EFAULT;
1066 if (put_user(ps->flags, (int __user *) arg))
1067 break;
1068
fba40c63 1069 l2tp_info(session, L2TP_MSG_CONTROL, "%s: get flags=%d\n",
a4ca44fa 1070 session->name, ps->flags);
fd558d18
JC
1071 err = 0;
1072 break;
1073
1074 case PPPIOCSFLAGS:
1075 err = -EFAULT;
1076 if (get_user(val, (int __user *) arg))
1077 break;
1078 ps->flags = val;
fba40c63 1079 l2tp_info(session, L2TP_MSG_CONTROL, "%s: set flags=%d\n",
a4ca44fa 1080 session->name, ps->flags);
fd558d18
JC
1081 err = 0;
1082 break;
1083
1084 case PPPIOCGL2TPSTATS:
1085 err = -ENXIO;
1086 if (!(sk->sk_state & PPPOX_CONNECTED))
1087 break;
1088
1089 memset(&stats, 0, sizeof(stats));
1090 stats.tunnel_id = tunnel->tunnel_id;
1091 stats.session_id = session->session_id;
1092 pppol2tp_copy_stats(&stats, &session->stats);
1093 if (copy_to_user((void __user *) arg, &stats,
1094 sizeof(stats)))
1095 break;
fba40c63 1096 l2tp_info(session, L2TP_MSG_CONTROL, "%s: get L2TP stats\n",
a4ca44fa 1097 session->name);
fd558d18
JC
1098 err = 0;
1099 break;
1100
1101 default:
1102 err = -ENOSYS;
1103 break;
1104 }
1105
1106 sock_put(sk);
1107
1108 return err;
1109}
1110
1111/* Tunnel ioctl helper.
1112 *
1113 * Note the special handling for PPPIOCGL2TPSTATS below. If the ioctl data
1114 * specifies a session_id, the session ioctl handler is called. This allows an
1115 * application to retrieve session stats via a tunnel socket.
1116 */
1117static int pppol2tp_tunnel_ioctl(struct l2tp_tunnel *tunnel,
1118 unsigned int cmd, unsigned long arg)
1119{
1120 int err = 0;
1121 struct sock *sk;
1122 struct pppol2tp_ioc_stats stats;
1123
fba40c63 1124 l2tp_dbg(tunnel, L2TP_MSG_CONTROL,
a4ca44fa
JP
1125 "%s: pppol2tp_tunnel_ioctl(cmd=%#x, arg=%#lx)\n",
1126 tunnel->name, cmd, arg);
fd558d18
JC
1127
1128 sk = tunnel->sock;
1129 sock_hold(sk);
1130
1131 switch (cmd) {
1132 case PPPIOCGL2TPSTATS:
1133 err = -ENXIO;
1134 if (!(sk->sk_state & PPPOX_CONNECTED))
1135 break;
1136
1137 if (copy_from_user(&stats, (void __user *) arg,
1138 sizeof(stats))) {
1139 err = -EFAULT;
1140 break;
1141 }
1142 if (stats.session_id != 0) {
1143 /* resend to session ioctl handler */
1144 struct l2tp_session *session =
57377d63
GN
1145 l2tp_session_get(sock_net(sk), tunnel,
1146 stats.session_id, true);
1147
1148 if (session) {
1149 err = pppol2tp_session_ioctl(session, cmd,
1150 arg);
1151 if (session->deref)
1152 session->deref(session);
1153 l2tp_session_dec_refcount(session);
1154 } else {
fd558d18 1155 err = -EBADR;
57377d63 1156 }
fd558d18
JC
1157 break;
1158 }
1159#ifdef CONFIG_XFRM
1160 stats.using_ipsec = (sk->sk_policy[0] || sk->sk_policy[1]) ? 1 : 0;
1161#endif
1162 pppol2tp_copy_stats(&stats, &tunnel->stats);
1163 if (copy_to_user((void __user *) arg, &stats, sizeof(stats))) {
1164 err = -EFAULT;
1165 break;
1166 }
fba40c63 1167 l2tp_info(tunnel, L2TP_MSG_CONTROL, "%s: get L2TP stats\n",
a4ca44fa 1168 tunnel->name);
fd558d18
JC
1169 err = 0;
1170 break;
1171
1172 default:
1173 err = -ENOSYS;
1174 break;
1175 }
1176
1177 sock_put(sk);
1178
1179 return err;
1180}
1181
1182/* Main ioctl() handler.
1183 * Dispatch to tunnel or session helpers depending on the socket.
1184 */
1185static int pppol2tp_ioctl(struct socket *sock, unsigned int cmd,
1186 unsigned long arg)
1187{
1188 struct sock *sk = sock->sk;
1189 struct l2tp_session *session;
1190 struct l2tp_tunnel *tunnel;
1191 struct pppol2tp_session *ps;
1192 int err;
1193
1194 if (!sk)
1195 return 0;
1196
1197 err = -EBADF;
1198 if (sock_flag(sk, SOCK_DEAD) != 0)
1199 goto end;
1200
1201 err = -ENOTCONN;
1202 if ((sk->sk_user_data == NULL) ||
1203 (!(sk->sk_state & (PPPOX_CONNECTED | PPPOX_BOUND))))
1204 goto end;
1205
1206 /* Get session context from the socket */
1207 err = -EBADF;
1208 session = pppol2tp_sock_to_session(sk);
1209 if (session == NULL)
1210 goto end;
1211
1212 /* Special case: if session's session_id is zero, treat ioctl as a
1213 * tunnel ioctl
1214 */
1215 ps = l2tp_session_priv(session);
1216 if ((session->session_id == 0) &&
1217 (session->peer_session_id == 0)) {
1218 err = -EBADF;
1219 tunnel = l2tp_sock_to_tunnel(ps->tunnel_sock);
1220 if (tunnel == NULL)
1221 goto end_put_sess;
1222
1223 err = pppol2tp_tunnel_ioctl(tunnel, cmd, arg);
1224 sock_put(ps->tunnel_sock);
1225 goto end_put_sess;
1226 }
1227
1228 err = pppol2tp_session_ioctl(session, cmd, arg);
1229
1230end_put_sess:
1231 sock_put(sk);
1232end:
1233 return err;
1234}
1235
1236/*****************************************************************************
1237 * setsockopt() / getsockopt() support.
1238 *
1239 * The PPPoX socket is created for L2TP sessions: tunnels have their own UDP
1240 * sockets. In order to control kernel tunnel features, we allow userspace to
1241 * create a special "tunnel" PPPoX socket which is used for control only.
1242 * Tunnel PPPoX sockets have session_id == 0 and simply allow the user
1243 * application to issue L2TP setsockopt(), getsockopt() and ioctl() calls.
1244 *****************************************************************************/
1245
1246/* Tunnel setsockopt() helper.
1247 */
1248static int pppol2tp_tunnel_setsockopt(struct sock *sk,
1249 struct l2tp_tunnel *tunnel,
1250 int optname, int val)
1251{
1252 int err = 0;
1253
1254 switch (optname) {
1255 case PPPOL2TP_SO_DEBUG:
1256 tunnel->debug = val;
fba40c63 1257 l2tp_info(tunnel, L2TP_MSG_CONTROL, "%s: set debug=%x\n",
a4ca44fa 1258 tunnel->name, tunnel->debug);
fd558d18
JC
1259 break;
1260
1261 default:
1262 err = -ENOPROTOOPT;
1263 break;
1264 }
1265
1266 return err;
1267}
1268
1269/* Session setsockopt helper.
1270 */
1271static int pppol2tp_session_setsockopt(struct sock *sk,
1272 struct l2tp_session *session,
1273 int optname, int val)
1274{
1275 int err = 0;
1276 struct pppol2tp_session *ps = l2tp_session_priv(session);
1277
1278 switch (optname) {
1279 case PPPOL2TP_SO_RECVSEQ:
1280 if ((val != 0) && (val != 1)) {
1281 err = -EINVAL;
1282 break;
1283 }
3f9b9770 1284 session->recv_seq = !!val;
fba40c63 1285 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa
JP
1286 "%s: set recv_seq=%d\n",
1287 session->name, session->recv_seq);
fd558d18
JC
1288 break;
1289
1290 case PPPOL2TP_SO_SENDSEQ:
1291 if ((val != 0) && (val != 1)) {
1292 err = -EINVAL;
1293 break;
1294 }
3f9b9770 1295 session->send_seq = !!val;
fd558d18
JC
1296 {
1297 struct sock *ssk = ps->sock;
1298 struct pppox_sock *po = pppox_sk(ssk);
1299 po->chan.hdrlen = val ? PPPOL2TP_L2TP_HDR_SIZE_SEQ :
1300 PPPOL2TP_L2TP_HDR_SIZE_NOSEQ;
1301 }
bb5016ea 1302 l2tp_session_set_header_len(session, session->tunnel->version);
fba40c63 1303 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa
JP
1304 "%s: set send_seq=%d\n",
1305 session->name, session->send_seq);
fd558d18
JC
1306 break;
1307
1308 case PPPOL2TP_SO_LNSMODE:
1309 if ((val != 0) && (val != 1)) {
1310 err = -EINVAL;
1311 break;
1312 }
3f9b9770 1313 session->lns_mode = !!val;
fba40c63 1314 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa
JP
1315 "%s: set lns_mode=%d\n",
1316 session->name, session->lns_mode);
fd558d18
JC
1317 break;
1318
1319 case PPPOL2TP_SO_DEBUG:
1320 session->debug = val;
fba40c63 1321 l2tp_info(session, L2TP_MSG_CONTROL, "%s: set debug=%x\n",
a4ca44fa 1322 session->name, session->debug);
fd558d18
JC
1323 break;
1324
1325 case PPPOL2TP_SO_REORDERTO:
1326 session->reorder_timeout = msecs_to_jiffies(val);
fba40c63 1327 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa
JP
1328 "%s: set reorder_timeout=%d\n",
1329 session->name, session->reorder_timeout);
fd558d18
JC
1330 break;
1331
1332 default:
1333 err = -ENOPROTOOPT;
1334 break;
1335 }
1336
1337 return err;
1338}
1339
1340/* Main setsockopt() entry point.
1341 * Does API checks, then calls either the tunnel or session setsockopt
1342 * handler, according to whether the PPPoL2TP socket is a for a regular
1343 * session or the special tunnel type.
1344 */
1345static int pppol2tp_setsockopt(struct socket *sock, int level, int optname,
1346 char __user *optval, unsigned int optlen)
1347{
1348 struct sock *sk = sock->sk;
1349 struct l2tp_session *session;
1350 struct l2tp_tunnel *tunnel;
1351 struct pppol2tp_session *ps;
1352 int val;
1353 int err;
1354
1355 if (level != SOL_PPPOL2TP)
3cf521f7 1356 return -EINVAL;
fd558d18
JC
1357
1358 if (optlen < sizeof(int))
1359 return -EINVAL;
1360
1361 if (get_user(val, (int __user *)optval))
1362 return -EFAULT;
1363
1364 err = -ENOTCONN;
1365 if (sk->sk_user_data == NULL)
1366 goto end;
1367
1368 /* Get session context from the socket */
1369 err = -EBADF;
1370 session = pppol2tp_sock_to_session(sk);
1371 if (session == NULL)
1372 goto end;
1373
1374 /* Special case: if session_id == 0x0000, treat as operation on tunnel
1375 */
1376 ps = l2tp_session_priv(session);
1377 if ((session->session_id == 0) &&
1378 (session->peer_session_id == 0)) {
1379 err = -EBADF;
1380 tunnel = l2tp_sock_to_tunnel(ps->tunnel_sock);
1381 if (tunnel == NULL)
1382 goto end_put_sess;
1383
1384 err = pppol2tp_tunnel_setsockopt(sk, tunnel, optname, val);
1385 sock_put(ps->tunnel_sock);
1386 } else
1387 err = pppol2tp_session_setsockopt(sk, session, optname, val);
1388
fd558d18
JC
1389end_put_sess:
1390 sock_put(sk);
1391end:
1392 return err;
1393}
1394
1395/* Tunnel getsockopt helper. Called with sock locked.
1396 */
1397static int pppol2tp_tunnel_getsockopt(struct sock *sk,
1398 struct l2tp_tunnel *tunnel,
1399 int optname, int *val)
1400{
1401 int err = 0;
1402
1403 switch (optname) {
1404 case PPPOL2TP_SO_DEBUG:
1405 *val = tunnel->debug;
fba40c63 1406 l2tp_info(tunnel, L2TP_MSG_CONTROL, "%s: get debug=%x\n",
a4ca44fa 1407 tunnel->name, tunnel->debug);
fd558d18
JC
1408 break;
1409
1410 default:
1411 err = -ENOPROTOOPT;
1412 break;
1413 }
1414
1415 return err;
1416}
1417
1418/* Session getsockopt helper. Called with sock locked.
1419 */
1420static int pppol2tp_session_getsockopt(struct sock *sk,
1421 struct l2tp_session *session,
1422 int optname, int *val)
1423{
1424 int err = 0;
1425
1426 switch (optname) {
1427 case PPPOL2TP_SO_RECVSEQ:
1428 *val = session->recv_seq;
fba40c63 1429 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa 1430 "%s: get recv_seq=%d\n", session->name, *val);
fd558d18
JC
1431 break;
1432
1433 case PPPOL2TP_SO_SENDSEQ:
1434 *val = session->send_seq;
fba40c63 1435 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa 1436 "%s: get send_seq=%d\n", session->name, *val);
fd558d18
JC
1437 break;
1438
1439 case PPPOL2TP_SO_LNSMODE:
1440 *val = session->lns_mode;
fba40c63 1441 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa 1442 "%s: get lns_mode=%d\n", session->name, *val);
fd558d18
JC
1443 break;
1444
1445 case PPPOL2TP_SO_DEBUG:
1446 *val = session->debug;
fba40c63 1447 l2tp_info(session, L2TP_MSG_CONTROL, "%s: get debug=%d\n",
a4ca44fa 1448 session->name, *val);
fd558d18
JC
1449 break;
1450
1451 case PPPOL2TP_SO_REORDERTO:
1452 *val = (int) jiffies_to_msecs(session->reorder_timeout);
fba40c63 1453 l2tp_info(session, L2TP_MSG_CONTROL,
a4ca44fa 1454 "%s: get reorder_timeout=%d\n", session->name, *val);
fd558d18
JC
1455 break;
1456
1457 default:
1458 err = -ENOPROTOOPT;
1459 }
1460
1461 return err;
1462}
1463
1464/* Main getsockopt() entry point.
1465 * Does API checks, then calls either the tunnel or session getsockopt
1466 * handler, according to whether the PPPoX socket is a for a regular session
1467 * or the special tunnel type.
1468 */
e3192690
JP
1469static int pppol2tp_getsockopt(struct socket *sock, int level, int optname,
1470 char __user *optval, int __user *optlen)
fd558d18
JC
1471{
1472 struct sock *sk = sock->sk;
1473 struct l2tp_session *session;
1474 struct l2tp_tunnel *tunnel;
1475 int val, len;
1476 int err;
1477 struct pppol2tp_session *ps;
1478
1479 if (level != SOL_PPPOL2TP)
3cf521f7 1480 return -EINVAL;
fd558d18 1481
e3192690 1482 if (get_user(len, optlen))
fd558d18
JC
1483 return -EFAULT;
1484
1485 len = min_t(unsigned int, len, sizeof(int));
1486
1487 if (len < 0)
1488 return -EINVAL;
1489
1490 err = -ENOTCONN;
1491 if (sk->sk_user_data == NULL)
1492 goto end;
1493
1494 /* Get the session context */
1495 err = -EBADF;
1496 session = pppol2tp_sock_to_session(sk);
1497 if (session == NULL)
1498 goto end;
1499
1500 /* Special case: if session_id == 0x0000, treat as operation on tunnel */
1501 ps = l2tp_session_priv(session);
1502 if ((session->session_id == 0) &&
1503 (session->peer_session_id == 0)) {
1504 err = -EBADF;
1505 tunnel = l2tp_sock_to_tunnel(ps->tunnel_sock);
1506 if (tunnel == NULL)
1507 goto end_put_sess;
1508
1509 err = pppol2tp_tunnel_getsockopt(sk, tunnel, optname, &val);
1510 sock_put(ps->tunnel_sock);
321a52a3
GN
1511 if (err)
1512 goto end_put_sess;
1513 } else {
fd558d18 1514 err = pppol2tp_session_getsockopt(sk, session, optname, &val);
321a52a3
GN
1515 if (err)
1516 goto end_put_sess;
1517 }
fd558d18
JC
1518
1519 err = -EFAULT;
e3192690 1520 if (put_user(len, optlen))
fd558d18
JC
1521 goto end_put_sess;
1522
1523 if (copy_to_user((void __user *) optval, &val, len))
1524 goto end_put_sess;
1525
1526 err = 0;
1527
1528end_put_sess:
1529 sock_put(sk);
1530end:
1531 return err;
1532}
1533
1534/*****************************************************************************
1535 * /proc filesystem for debug
f7faffa3
JC
1536 * Since the original pppol2tp driver provided /proc/net/pppol2tp for
1537 * L2TPv2, we dump only L2TPv2 tunnels and sessions here.
fd558d18
JC
1538 *****************************************************************************/
1539
1540static unsigned int pppol2tp_net_id;
1541
1542#ifdef CONFIG_PROC_FS
1543
1544struct pppol2tp_seq_data {
1545 struct seq_net_private p;
1546 int tunnel_idx; /* current tunnel */
1547 int session_idx; /* index of session within current tunnel */
1548 struct l2tp_tunnel *tunnel;
1549 struct l2tp_session *session; /* NULL means get next tunnel */
1550};
1551
1552static void pppol2tp_next_tunnel(struct net *net, struct pppol2tp_seq_data *pd)
1553{
f7faffa3
JC
1554 for (;;) {
1555 pd->tunnel = l2tp_tunnel_find_nth(net, pd->tunnel_idx);
1556 pd->tunnel_idx++;
1557
1558 if (pd->tunnel == NULL)
1559 break;
1560
1561 /* Ignore L2TPv3 tunnels */
1562 if (pd->tunnel->version < 3)
1563 break;
1564 }
fd558d18
JC
1565}
1566
1567static void pppol2tp_next_session(struct net *net, struct pppol2tp_seq_data *pd)
1568{
e08293a4 1569 pd->session = l2tp_session_get_nth(pd->tunnel, pd->session_idx, true);
fd558d18 1570 pd->session_idx++;
f7faffa3 1571
fd558d18
JC
1572 if (pd->session == NULL) {
1573 pd->session_idx = 0;
1574 pppol2tp_next_tunnel(net, pd);
1575 }
1576}
1577
1578static void *pppol2tp_seq_start(struct seq_file *m, loff_t *offs)
1579{
1580 struct pppol2tp_seq_data *pd = SEQ_START_TOKEN;
1581 loff_t pos = *offs;
1582 struct net *net;
1583
1584 if (!pos)
1585 goto out;
1586
1587 BUG_ON(m->private == NULL);
1588 pd = m->private;
1589 net = seq_file_net(m);
1590
1591 if (pd->tunnel == NULL)
1592 pppol2tp_next_tunnel(net, pd);
1593 else
1594 pppol2tp_next_session(net, pd);
1595
1596 /* NULL tunnel and session indicates end of list */
1597 if ((pd->tunnel == NULL) && (pd->session == NULL))
1598 pd = NULL;
1599
1600out:
1601 return pd;
1602}
1603
1604static void *pppol2tp_seq_next(struct seq_file *m, void *v, loff_t *pos)
1605{
1606 (*pos)++;
1607 return NULL;
1608}
1609
1610static void pppol2tp_seq_stop(struct seq_file *p, void *v)
1611{
1612 /* nothing to do */
1613}
1614
1615static void pppol2tp_seq_tunnel_show(struct seq_file *m, void *v)
1616{
1617 struct l2tp_tunnel *tunnel = v;
1618
1619 seq_printf(m, "\nTUNNEL '%s', %c %d\n",
1620 tunnel->name,
1621 (tunnel == tunnel->sock->sk_user_data) ? 'Y' : 'N',
fbea9e07 1622 refcount_read(&tunnel->ref_count) - 1);
7b7c0719 1623 seq_printf(m, " %08x %ld/%ld/%ld %ld/%ld/%ld\n",
fd558d18 1624 tunnel->debug,
7b7c0719
TP
1625 atomic_long_read(&tunnel->stats.tx_packets),
1626 atomic_long_read(&tunnel->stats.tx_bytes),
1627 atomic_long_read(&tunnel->stats.tx_errors),
1628 atomic_long_read(&tunnel->stats.rx_packets),
1629 atomic_long_read(&tunnel->stats.rx_bytes),
1630 atomic_long_read(&tunnel->stats.rx_errors));
fd558d18
JC
1631}
1632
1633static void pppol2tp_seq_session_show(struct seq_file *m, void *v)
1634{
1635 struct l2tp_session *session = v;
1636 struct l2tp_tunnel *tunnel = session->tunnel;
1637 struct pppol2tp_session *ps = l2tp_session_priv(session);
9345471b 1638 struct pppox_sock *po = pppox_sk(ps->sock);
fd558d18
JC
1639 u32 ip = 0;
1640 u16 port = 0;
1641
1642 if (tunnel->sock) {
1643 struct inet_sock *inet = inet_sk(tunnel->sock);
1644 ip = ntohl(inet->inet_saddr);
1645 port = ntohs(inet->inet_sport);
1646 }
1647
1648 seq_printf(m, " SESSION '%s' %08X/%d %04X/%04X -> "
1649 "%04X/%04X %d %c\n",
1650 session->name, ip, port,
1651 tunnel->tunnel_id,
1652 session->session_id,
1653 tunnel->peer_tunnel_id,
1654 session->peer_session_id,
1655 ps->sock->sk_state,
1656 (session == ps->sock->sk_user_data) ?
1657 'Y' : 'N');
1658 seq_printf(m, " %d/%d/%c/%c/%s %08x %u\n",
1659 session->mtu, session->mru,
1660 session->recv_seq ? 'R' : '-',
1661 session->send_seq ? 'S' : '-',
1662 session->lns_mode ? "LNS" : "LAC",
1663 session->debug,
1664 jiffies_to_msecs(session->reorder_timeout));
7b7c0719 1665 seq_printf(m, " %hu/%hu %ld/%ld/%ld %ld/%ld/%ld\n",
fd558d18 1666 session->nr, session->ns,
7b7c0719
TP
1667 atomic_long_read(&session->stats.tx_packets),
1668 atomic_long_read(&session->stats.tx_bytes),
1669 atomic_long_read(&session->stats.tx_errors),
1670 atomic_long_read(&session->stats.rx_packets),
1671 atomic_long_read(&session->stats.rx_bytes),
1672 atomic_long_read(&session->stats.rx_errors));
9345471b
JC
1673
1674 if (po)
1675 seq_printf(m, " interface %s\n", ppp_dev_name(&po->chan));
fd558d18
JC
1676}
1677
1678static int pppol2tp_seq_show(struct seq_file *m, void *v)
1679{
1680 struct pppol2tp_seq_data *pd = v;
1681
1682 /* display header on line 1 */
1683 if (v == SEQ_START_TOKEN) {
1684 seq_puts(m, "PPPoL2TP driver info, " PPPOL2TP_DRV_VERSION "\n");
1685 seq_puts(m, "TUNNEL name, user-data-ok session-count\n");
1686 seq_puts(m, " debug tx-pkts/bytes/errs rx-pkts/bytes/errs\n");
1687 seq_puts(m, " SESSION name, addr/port src-tid/sid "
1688 "dest-tid/sid state user-data-ok\n");
1689 seq_puts(m, " mtu/mru/rcvseq/sendseq/lns debug reorderto\n");
1690 seq_puts(m, " nr/ns tx-pkts/bytes/errs rx-pkts/bytes/errs\n");
1691 goto out;
1692 }
1693
1694 /* Show the tunnel or session context.
1695 */
e08293a4 1696 if (!pd->session) {
fd558d18 1697 pppol2tp_seq_tunnel_show(m, pd->tunnel);
e08293a4 1698 } else {
fd558d18 1699 pppol2tp_seq_session_show(m, pd->session);
e08293a4
GN
1700 if (pd->session->deref)
1701 pd->session->deref(pd->session);
1702 l2tp_session_dec_refcount(pd->session);
1703 }
fd558d18
JC
1704
1705out:
1706 return 0;
1707}
1708
1709static const struct seq_operations pppol2tp_seq_ops = {
1710 .start = pppol2tp_seq_start,
1711 .next = pppol2tp_seq_next,
1712 .stop = pppol2tp_seq_stop,
1713 .show = pppol2tp_seq_show,
1714};
1715
1716/* Called when our /proc file is opened. We allocate data for use when
1717 * iterating our tunnel / session contexts and store it in the private
1718 * data of the seq_file.
1719 */
1720static int pppol2tp_proc_open(struct inode *inode, struct file *file)
1721{
1722 return seq_open_net(inode, file, &pppol2tp_seq_ops,
1723 sizeof(struct pppol2tp_seq_data));
1724}
1725
1726static const struct file_operations pppol2tp_proc_fops = {
1727 .owner = THIS_MODULE,
1728 .open = pppol2tp_proc_open,
1729 .read = seq_read,
1730 .llseek = seq_lseek,
1731 .release = seq_release_net,
1732};
1733
1734#endif /* CONFIG_PROC_FS */
1735
1736/*****************************************************************************
1737 * Network namespace
1738 *****************************************************************************/
1739
1740static __net_init int pppol2tp_init_net(struct net *net)
1741{
1742 struct proc_dir_entry *pde;
1743 int err = 0;
1744
d4beaa66
G
1745 pde = proc_create("pppol2tp", S_IRUGO, net->proc_net,
1746 &pppol2tp_proc_fops);
fd558d18
JC
1747 if (!pde) {
1748 err = -ENOMEM;
1749 goto out;
1750 }
1751
1752out:
1753 return err;
1754}
1755
1756static __net_exit void pppol2tp_exit_net(struct net *net)
1757{
ece31ffd 1758 remove_proc_entry("pppol2tp", net->proc_net);
fd558d18
JC
1759}
1760
1761static struct pernet_operations pppol2tp_net_ops = {
1762 .init = pppol2tp_init_net,
1763 .exit = pppol2tp_exit_net,
1764 .id = &pppol2tp_net_id,
1765};
1766
1767/*****************************************************************************
1768 * Init and cleanup
1769 *****************************************************************************/
1770
1771static const struct proto_ops pppol2tp_ops = {
1772 .family = AF_PPPOX,
1773 .owner = THIS_MODULE,
1774 .release = pppol2tp_release,
1775 .bind = sock_no_bind,
1776 .connect = pppol2tp_connect,
1777 .socketpair = sock_no_socketpair,
1778 .accept = sock_no_accept,
1779 .getname = pppol2tp_getname,
1780 .poll = datagram_poll,
1781 .listen = sock_no_listen,
1782 .shutdown = sock_no_shutdown,
1783 .setsockopt = pppol2tp_setsockopt,
1784 .getsockopt = pppol2tp_getsockopt,
1785 .sendmsg = pppol2tp_sendmsg,
1786 .recvmsg = pppol2tp_recvmsg,
1787 .mmap = sock_no_mmap,
1788 .ioctl = pppox_ioctl,
1789};
1790
756e64a0 1791static const struct pppox_proto pppol2tp_proto = {
fd558d18 1792 .create = pppol2tp_create,
e1558a93
WY
1793 .ioctl = pppol2tp_ioctl,
1794 .owner = THIS_MODULE,
fd558d18
JC
1795};
1796
309795f4
JC
1797#ifdef CONFIG_L2TP_V3
1798
1799static const struct l2tp_nl_cmd_ops pppol2tp_nl_cmd_ops = {
1800 .session_create = pppol2tp_session_create,
cf2f5c88 1801 .session_delete = l2tp_session_delete,
309795f4
JC
1802};
1803
1804#endif /* CONFIG_L2TP_V3 */
1805
fd558d18
JC
1806static int __init pppol2tp_init(void)
1807{
1808 int err;
1809
1810 err = register_pernet_device(&pppol2tp_net_ops);
1811 if (err)
1812 goto out;
1813
1814 err = proto_register(&pppol2tp_sk_proto, 0);
1815 if (err)
1816 goto out_unregister_pppol2tp_pernet;
1817
1818 err = register_pppox_proto(PX_PROTO_OL2TP, &pppol2tp_proto);
1819 if (err)
1820 goto out_unregister_pppol2tp_proto;
1821
309795f4
JC
1822#ifdef CONFIG_L2TP_V3
1823 err = l2tp_nl_register_ops(L2TP_PWTYPE_PPP, &pppol2tp_nl_cmd_ops);
1824 if (err)
1825 goto out_unregister_pppox;
1826#endif
1827
a4ca44fa 1828 pr_info("PPPoL2TP kernel driver, %s\n", PPPOL2TP_DRV_VERSION);
fd558d18
JC
1829
1830out:
1831 return err;
309795f4
JC
1832
1833#ifdef CONFIG_L2TP_V3
1834out_unregister_pppox:
1835 unregister_pppox_proto(PX_PROTO_OL2TP);
1836#endif
fd558d18
JC
1837out_unregister_pppol2tp_proto:
1838 proto_unregister(&pppol2tp_sk_proto);
1839out_unregister_pppol2tp_pernet:
1840 unregister_pernet_device(&pppol2tp_net_ops);
1841 goto out;
1842}
1843
1844static void __exit pppol2tp_exit(void)
1845{
309795f4
JC
1846#ifdef CONFIG_L2TP_V3
1847 l2tp_nl_unregister_ops(L2TP_PWTYPE_PPP);
1848#endif
fd558d18
JC
1849 unregister_pppox_proto(PX_PROTO_OL2TP);
1850 proto_unregister(&pppol2tp_sk_proto);
1851 unregister_pernet_device(&pppol2tp_net_ops);
1852}
1853
1854module_init(pppol2tp_init);
1855module_exit(pppol2tp_exit);
1856
1857MODULE_AUTHOR("James Chapman <jchapman@katalix.com>");
1858MODULE_DESCRIPTION("PPP over L2TP over UDP");
1859MODULE_LICENSE("GPL");
1860MODULE_VERSION(PPPOL2TP_DRV_VERSION);
681b4d88 1861MODULE_ALIAS_NET_PF_PROTO(PF_PPPOX, PX_PROTO_OL2TP);
249ee819 1862MODULE_ALIAS_L2TP_PWTYPE(7);