]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/sched/sch_atm.c
net_sched: fix a NULL pointer deref in ipt action
[mirror_ubuntu-bionic-kernel.git] / net / sched / sch_atm.c
CommitLineData
1da177e4
LT
1/* net/sched/sch_atm.c - ATM VC selection "queueing discipline" */
2
3/* Written 1998-2000 by Werner Almesberger, EPFL ICA */
4
1da177e4 5#include <linux/module.h>
5a0e3ad6 6#include <linux/slab.h>
1da177e4 7#include <linux/init.h>
a6b7a407 8#include <linux/interrupt.h>
1da177e4
LT
9#include <linux/string.h>
10#include <linux/errno.h>
11#include <linux/skbuff.h>
1da177e4
LT
12#include <linux/atmdev.h>
13#include <linux/atmclip.h>
1da177e4 14#include <linux/rtnetlink.h>
b0188d4d 15#include <linux/file.h> /* for fput */
dc5fc579 16#include <net/netlink.h>
1da177e4 17#include <net/pkt_sched.h>
cf1facda 18#include <net/pkt_cls.h>
1da177e4 19
1da177e4
LT
20/*
21 * The ATM queuing discipline provides a framework for invoking classifiers
22 * (aka "filters"), which in turn select classes of this queuing discipline.
23 * Each class maps the flow(s) it is handling to a given VC. Multiple classes
24 * may share the same VC.
25 *
26 * When creating a class, VCs are specified by passing the number of the open
27 * socket descriptor by which the calling process references the VC. The kernel
28 * keeps the VC open at least until all classes using it are removed.
29 *
30 * In this file, most functions are named atm_tc_* to avoid confusion with all
31 * the atm_* in net/atm. This naming convention differs from what's used in the
32 * rest of net/sched.
33 *
34 * Known bugs:
35 * - sometimes messes up the IP stack
36 * - any manipulations besides the few operations described in the README, are
37 * untested and likely to crash the system
38 * - should lock the flow while there is data in the queue (?)
39 */
40
1da177e4
LT
41#define VCC2FLOW(vcc) ((struct atm_flow_data *) ((vcc)->user_back))
42
1da177e4 43struct atm_flow_data {
f7ebdff7 44 struct Qdisc_class_common common;
b0188d4d 45 struct Qdisc *q; /* FIFO, TBF, etc. */
25d8c0d5 46 struct tcf_proto __rcu *filter_list;
6529eaba 47 struct tcf_block *block;
b0188d4d
PM
48 struct atm_vcc *vcc; /* VCC; NULL if VCC is closed */
49 void (*old_pop)(struct atm_vcc *vcc,
786a9036 50 struct sk_buff *skb); /* chaining */
1da177e4
LT
51 struct atm_qdisc_data *parent; /* parent qdisc */
52 struct socket *sock; /* for closing */
1da177e4 53 int ref; /* reference count */
c1a8f1f1 54 struct gnet_stats_basic_packed bstats;
1da177e4 55 struct gnet_stats_queue qstats;
6accec76 56 struct list_head list;
1da177e4
LT
57 struct atm_flow_data *excess; /* flow for excess traffic;
58 NULL to set CLP instead */
59 int hdr_len;
60 unsigned char hdr[0]; /* header data; MUST BE LAST */
61};
62
63struct atm_qdisc_data {
64 struct atm_flow_data link; /* unclassified skbs go here */
6accec76 65 struct list_head flows; /* NB: "link" is also on this
1da177e4 66 list */
f30ab418 67 struct tasklet_struct task; /* dequeue tasklet */
1da177e4
LT
68};
69
1da177e4
LT
70/* ------------------------- Class/flow operations ------------------------- */
71
b0188d4d 72static inline struct atm_flow_data *lookup_flow(struct Qdisc *sch, u32 classid)
1da177e4 73{
786a9036 74 struct atm_qdisc_data *p = qdisc_priv(sch);
1da177e4
LT
75 struct atm_flow_data *flow;
76
6accec76 77 list_for_each_entry(flow, &p->flows, list) {
f7ebdff7 78 if (flow->common.classid == classid)
6accec76
DM
79 return flow;
80 }
81 return NULL;
1da177e4
LT
82}
83
b0188d4d
PM
84static int atm_tc_graft(struct Qdisc *sch, unsigned long arg,
85 struct Qdisc *new, struct Qdisc **old)
1da177e4 86{
786a9036 87 struct atm_qdisc_data *p = qdisc_priv(sch);
b0188d4d
PM
88 struct atm_flow_data *flow = (struct atm_flow_data *)arg;
89
786a9036 90 pr_debug("atm_tc_graft(sch %p,[qdisc %p],flow %p,new %p,old %p)\n",
b0188d4d 91 sch, p, flow, new, old);
6accec76 92 if (list_empty(&flow->list))
b0188d4d
PM
93 return -EINVAL;
94 if (!new)
95 new = &noop_qdisc;
b94c8afc
PM
96 *old = flow->q;
97 flow->q = new;
b0188d4d
PM
98 if (*old)
99 qdisc_reset(*old);
10297b99 100 return 0;
1da177e4
LT
101}
102
b0188d4d 103static struct Qdisc *atm_tc_leaf(struct Qdisc *sch, unsigned long cl)
1da177e4 104{
b0188d4d 105 struct atm_flow_data *flow = (struct atm_flow_data *)cl;
1da177e4 106
786a9036 107 pr_debug("atm_tc_leaf(sch %p,flow %p)\n", sch, flow);
1da177e4
LT
108 return flow ? flow->q : NULL;
109}
110
143976ce 111static unsigned long atm_tc_find(struct Qdisc *sch, u32 classid)
1da177e4 112{
786a9036 113 struct atm_qdisc_data *p __maybe_unused = qdisc_priv(sch);
1da177e4
LT
114 struct atm_flow_data *flow;
115
143976ce 116 pr_debug("%s(sch %p,[qdisc %p],classid %x)\n", __func__, sch, p, classid);
b0188d4d 117 flow = lookup_flow(sch, classid);
143976ce 118 pr_debug("%s: flow %p\n", __func__, flow);
b0188d4d 119 return (unsigned long)flow;
1da177e4
LT
120}
121
1da177e4 122static unsigned long atm_tc_bind_filter(struct Qdisc *sch,
b0188d4d 123 unsigned long parent, u32 classid)
1da177e4 124{
143976ce
WC
125 struct atm_qdisc_data *p __maybe_unused = qdisc_priv(sch);
126 struct atm_flow_data *flow;
127
128 pr_debug("%s(sch %p,[qdisc %p],classid %x)\n", __func__, sch, p, classid);
129 flow = lookup_flow(sch, classid);
130 if (flow)
131 flow->ref++;
132 pr_debug("%s: flow %p\n", __func__, flow);
133 return (unsigned long)flow;
1da177e4
LT
134}
135
1da177e4
LT
136/*
137 * atm_tc_put handles all destructions, including the ones that are explicitly
138 * requested (atm_tc_destroy, etc.). The assumption here is that we never drop
139 * anything that still seems to be in use.
140 */
1da177e4
LT
141static void atm_tc_put(struct Qdisc *sch, unsigned long cl)
142{
786a9036 143 struct atm_qdisc_data *p = qdisc_priv(sch);
b0188d4d 144 struct atm_flow_data *flow = (struct atm_flow_data *)cl;
1da177e4 145
786a9036 146 pr_debug("atm_tc_put(sch %p,[qdisc %p],flow %p)\n", sch, p, flow);
b0188d4d
PM
147 if (--flow->ref)
148 return;
786a9036 149 pr_debug("atm_tc_put: destroying\n");
6accec76 150 list_del_init(&flow->list);
786a9036 151 pr_debug("atm_tc_put: qdisc %p\n", flow->q);
1da177e4 152 qdisc_destroy(flow->q);
6529eaba 153 tcf_block_put(flow->block);
1da177e4 154 if (flow->sock) {
516e0cc5 155 pr_debug("atm_tc_put: f_count %ld\n",
b0188d4d 156 file_count(flow->sock->file));
1da177e4
LT
157 flow->vcc->pop = flow->old_pop;
158 sockfd_put(flow->sock);
159 }
b0188d4d
PM
160 if (flow->excess)
161 atm_tc_put(sch, (unsigned long)flow->excess);
162 if (flow != &p->link)
163 kfree(flow);
1da177e4
LT
164 /*
165 * If flow == &p->link, the qdisc no longer works at this point and
166 * needs to be removed. (By the caller of atm_tc_put.)
167 */
168}
169
b0188d4d 170static void sch_atm_pop(struct atm_vcc *vcc, struct sk_buff *skb)
1da177e4
LT
171{
172 struct atm_qdisc_data *p = VCC2FLOW(vcc)->parent;
173
786a9036 174 pr_debug("sch_atm_pop(vcc %p,skb %p,[qdisc %p])\n", vcc, skb, p);
b0188d4d 175 VCC2FLOW(vcc)->old_pop(vcc, skb);
1da177e4
LT
176 tasklet_schedule(&p->task);
177}
178
179static const u8 llc_oui_ip[] = {
b0188d4d
PM
180 0xaa, /* DSAP: non-ISO */
181 0xaa, /* SSAP: non-ISO */
182 0x03, /* Ctrl: Unnumbered Information Command PDU */
183 0x00, /* OUI: EtherType */
1da177e4 184 0x00, 0x00,
b0188d4d
PM
185 0x08, 0x00
186}; /* Ethertype IP (0800) */
1da177e4 187
27a3421e
PM
188static const struct nla_policy atm_policy[TCA_ATM_MAX + 1] = {
189 [TCA_ATM_FD] = { .type = NLA_U32 },
190 [TCA_ATM_EXCESS] = { .type = NLA_U32 },
191};
192
1da177e4 193static int atm_tc_change(struct Qdisc *sch, u32 classid, u32 parent,
1e90474c 194 struct nlattr **tca, unsigned long *arg)
1da177e4 195{
786a9036 196 struct atm_qdisc_data *p = qdisc_priv(sch);
b0188d4d 197 struct atm_flow_data *flow = (struct atm_flow_data *)*arg;
1da177e4 198 struct atm_flow_data *excess = NULL;
1e90474c
PM
199 struct nlattr *opt = tca[TCA_OPTIONS];
200 struct nlattr *tb[TCA_ATM_MAX + 1];
1da177e4 201 struct socket *sock;
b0188d4d 202 int fd, error, hdr_len;
1da177e4
LT
203 void *hdr;
204
786a9036 205 pr_debug("atm_tc_change(sch %p,[qdisc %p],classid %x,parent %x,"
b0188d4d 206 "flow %p,opt %p)\n", sch, p, classid, parent, flow, opt);
1da177e4
LT
207 /*
208 * The concept of parents doesn't apply for this qdisc.
209 */
210 if (parent && parent != TC_H_ROOT && parent != sch->handle)
211 return -EINVAL;
212 /*
213 * ATM classes cannot be changed. In order to change properties of the
214 * ATM connection, that socket needs to be modified directly (via the
215 * native ATM API. In order to send a flow to a different VC, the old
216 * class needs to be removed and a new one added. (This may be changed
217 * later.)
218 */
b0188d4d
PM
219 if (flow)
220 return -EBUSY;
cee63723 221 if (opt == NULL)
1da177e4 222 return -EINVAL;
27a3421e 223
fceb6435 224 error = nla_parse_nested(tb, TCA_ATM_MAX, opt, atm_policy, NULL);
cee63723
PM
225 if (error < 0)
226 return error;
227
27a3421e 228 if (!tb[TCA_ATM_FD])
1da177e4 229 return -EINVAL;
1587bac4 230 fd = nla_get_u32(tb[TCA_ATM_FD]);
786a9036 231 pr_debug("atm_tc_change: fd %d\n", fd);
1e90474c
PM
232 if (tb[TCA_ATM_HDR]) {
233 hdr_len = nla_len(tb[TCA_ATM_HDR]);
234 hdr = nla_data(tb[TCA_ATM_HDR]);
b0188d4d 235 } else {
1da177e4 236 hdr_len = RFC1483LLC_LEN;
b0188d4d 237 hdr = NULL; /* default LLC/SNAP for IP */
1da177e4 238 }
1e90474c 239 if (!tb[TCA_ATM_EXCESS])
b0188d4d 240 excess = NULL;
1da177e4 241 else {
b0188d4d 242 excess = (struct atm_flow_data *)
143976ce 243 atm_tc_find(sch, nla_get_u32(tb[TCA_ATM_EXCESS]));
b0188d4d
PM
244 if (!excess)
245 return -ENOENT;
1da177e4 246 }
f5e5cb75 247 pr_debug("atm_tc_change: type %d, payload %d, hdr_len %d\n",
1e90474c 248 opt->nla_type, nla_len(opt), hdr_len);
786a9036
SH
249 sock = sockfd_lookup(fd, &error);
250 if (!sock)
b0188d4d 251 return error; /* f_count++ */
516e0cc5 252 pr_debug("atm_tc_change: f_count %ld\n", file_count(sock->file));
10297b99 253 if (sock->ops->family != PF_ATMSVC && sock->ops->family != PF_ATMPVC) {
1da177e4 254 error = -EPROTOTYPE;
10297b99 255 goto err_out;
1da177e4
LT
256 }
257 /* @@@ should check if the socket is really operational or we'll crash
258 on vcc->send */
259 if (classid) {
260 if (TC_H_MAJ(classid ^ sch->handle)) {
786a9036 261 pr_debug("atm_tc_change: classid mismatch\n");
1da177e4
LT
262 error = -EINVAL;
263 goto err_out;
264 }
b0188d4d 265 } else {
1da177e4
LT
266 int i;
267 unsigned long cl;
268
269 for (i = 1; i < 0x8000; i++) {
b0188d4d 270 classid = TC_H_MAKE(sch->handle, 0x8000 | i);
143976ce 271 cl = atm_tc_find(sch, classid);
786a9036 272 if (!cl)
b0188d4d 273 break;
1da177e4
LT
274 }
275 }
786a9036 276 pr_debug("atm_tc_change: new id %x\n", classid);
782f7956 277 flow = kzalloc(sizeof(struct atm_flow_data) + hdr_len, GFP_KERNEL);
786a9036 278 pr_debug("atm_tc_change: flow %p\n", flow);
1da177e4
LT
279 if (!flow) {
280 error = -ENOBUFS;
281 goto err_out;
282 }
6529eaba 283
69d78ef2 284 error = tcf_block_get(&flow->block, &flow->filter_list, sch);
6529eaba
JP
285 if (error) {
286 kfree(flow);
287 goto err_out;
288 }
289
3511c913 290 flow->q = qdisc_create_dflt(sch->dev_queue, &pfifo_qdisc_ops, classid);
786a9036 291 if (!flow->q)
1da177e4 292 flow->q = &noop_qdisc;
786a9036 293 pr_debug("atm_tc_change: qdisc %p\n", flow->q);
1da177e4 294 flow->sock = sock;
b0188d4d 295 flow->vcc = ATM_SD(sock); /* speedup */
1da177e4 296 flow->vcc->user_back = flow;
786a9036 297 pr_debug("atm_tc_change: vcc %p\n", flow->vcc);
1da177e4
LT
298 flow->old_pop = flow->vcc->pop;
299 flow->parent = p;
300 flow->vcc->pop = sch_atm_pop;
f7ebdff7 301 flow->common.classid = classid;
1da177e4
LT
302 flow->ref = 1;
303 flow->excess = excess;
6accec76 304 list_add(&flow->list, &p->link.list);
1da177e4
LT
305 flow->hdr_len = hdr_len;
306 if (hdr)
b0188d4d 307 memcpy(flow->hdr, hdr, hdr_len);
1da177e4 308 else
b0188d4d
PM
309 memcpy(flow->hdr, llc_oui_ip, sizeof(llc_oui_ip));
310 *arg = (unsigned long)flow;
1da177e4
LT
311 return 0;
312err_out:
1da177e4
LT
313 sockfd_put(sock);
314 return error;
315}
316
b0188d4d 317static int atm_tc_delete(struct Qdisc *sch, unsigned long arg)
1da177e4 318{
786a9036 319 struct atm_qdisc_data *p = qdisc_priv(sch);
b0188d4d 320 struct atm_flow_data *flow = (struct atm_flow_data *)arg;
1da177e4 321
786a9036 322 pr_debug("atm_tc_delete(sch %p,[qdisc %p],flow %p)\n", sch, p, flow);
6accec76 323 if (list_empty(&flow->list))
b0188d4d 324 return -EINVAL;
25d8c0d5 325 if (rcu_access_pointer(flow->filter_list) || flow == &p->link)
b0188d4d 326 return -EBUSY;
1da177e4
LT
327 /*
328 * Reference count must be 2: one for "keepalive" (set at class
329 * creation), and one for the reference held when calling delete.
330 */
331 if (flow->ref < 2) {
cc7ec456 332 pr_err("atm_tc_delete: flow->ref == %d\n", flow->ref);
1da177e4
LT
333 return -EINVAL;
334 }
b0188d4d
PM
335 if (flow->ref > 2)
336 return -EBUSY; /* catch references via excess, etc. */
337 atm_tc_put(sch, arg);
1da177e4
LT
338 return 0;
339}
340
b0188d4d 341static void atm_tc_walk(struct Qdisc *sch, struct qdisc_walker *walker)
1da177e4 342{
786a9036 343 struct atm_qdisc_data *p = qdisc_priv(sch);
1da177e4
LT
344 struct atm_flow_data *flow;
345
786a9036 346 pr_debug("atm_tc_walk(sch %p,[qdisc %p],walker %p)\n", sch, p, walker);
b0188d4d
PM
347 if (walker->stop)
348 return;
6accec76
DM
349 list_for_each_entry(flow, &p->flows, list) {
350 if (walker->count >= walker->skip &&
351 walker->fn(sch, (unsigned long)flow, walker) < 0) {
352 walker->stop = 1;
353 break;
354 }
1da177e4
LT
355 walker->count++;
356 }
357}
358
6529eaba 359static struct tcf_block *atm_tc_tcf_block(struct Qdisc *sch, unsigned long cl)
1da177e4 360{
786a9036 361 struct atm_qdisc_data *p = qdisc_priv(sch);
b0188d4d 362 struct atm_flow_data *flow = (struct atm_flow_data *)cl;
1da177e4 363
786a9036 364 pr_debug("atm_tc_find_tcf(sch %p,[qdisc %p],flow %p)\n", sch, p, flow);
6529eaba 365 return flow ? flow->block : p->link.block;
1da177e4
LT
366}
367
1da177e4
LT
368/* --------------------------- Qdisc operations ---------------------------- */
369
520ac30f
ED
370static int atm_tc_enqueue(struct sk_buff *skb, struct Qdisc *sch,
371 struct sk_buff **to_free)
1da177e4 372{
786a9036 373 struct atm_qdisc_data *p = qdisc_priv(sch);
6accec76 374 struct atm_flow_data *flow;
1da177e4
LT
375 struct tcf_result res;
376 int result;
99860208 377 int ret = NET_XMIT_SUCCESS | __NET_XMIT_BYPASS;
1da177e4 378
786a9036 379 pr_debug("atm_tc_enqueue(skb %p,sch %p,[qdisc %p])\n", skb, sch, p);
95df1b16 380 result = TC_ACT_OK; /* be nice to gcc */
6accec76 381 flow = NULL;
1da177e4 382 if (TC_H_MAJ(skb->priority) != sch->handle ||
143976ce 383 !(flow = (struct atm_flow_data *)atm_tc_find(sch, skb->priority))) {
25d8c0d5
JF
384 struct tcf_proto *fl;
385
6accec76 386 list_for_each_entry(flow, &p->flows, list) {
25d8c0d5
JF
387 fl = rcu_dereference_bh(flow->filter_list);
388 if (fl) {
87d83093 389 result = tcf_classify(skb, fl, &res, true);
b0188d4d
PM
390 if (result < 0)
391 continue;
392 flow = (struct atm_flow_data *)res.class;
393 if (!flow)
394 flow = lookup_flow(sch, res.classid);
6accec76 395 goto done;
1da177e4 396 }
6accec76
DM
397 }
398 flow = NULL;
cc7ec456
ED
399done:
400 ;
6accec76 401 }
cc7ec456 402 if (!flow) {
b0188d4d 403 flow = &p->link;
cc7ec456 404 } else {
1da177e4
LT
405 if (flow->vcc)
406 ATM_SKB(skb)->atm_options = flow->vcc->atm_options;
b0188d4d 407 /*@@@ looks good ... but it's not supposed to work :-) */
92100804
PM
408#ifdef CONFIG_NET_CLS_ACT
409 switch (result) {
410 case TC_ACT_QUEUED:
411 case TC_ACT_STOLEN:
e25ea21f 412 case TC_ACT_TRAP:
520ac30f 413 __qdisc_drop(skb, to_free);
378a2f09 414 return NET_XMIT_SUCCESS | __NET_XMIT_STOLEN;
92100804 415 case TC_ACT_SHOT:
520ac30f 416 __qdisc_drop(skb, to_free);
92100804 417 goto drop;
95df1b16 418 case TC_ACT_RECLASSIFY:
73ca4918
PM
419 if (flow->excess)
420 flow = flow->excess;
421 else
422 ATM_SKB(skb)->atm_options |= ATM_ATMOPT_CLP;
423 break;
92100804 424 }
1da177e4
LT
425#endif
426 }
c3bc7cff 427
520ac30f 428 ret = qdisc_enqueue(skb, flow->q, to_free);
9871e50e 429 if (ret != NET_XMIT_SUCCESS) {
92100804 430drop: __maybe_unused
378a2f09 431 if (net_xmit_drop_count(ret)) {
25331d6c 432 qdisc_qstats_drop(sch);
378a2f09
JP
433 if (flow)
434 flow->qstats.drops++;
435 }
1da177e4
LT
436 return ret;
437 }
1da177e4
LT
438 /*
439 * Okay, this may seem weird. We pretend we've dropped the packet if
440 * it goes via ATM. The reason for this is that the outer qdisc
441 * expects to be able to q->dequeue the packet later on if we return
442 * success at this place. Also, sch->q.qdisc needs to reflect whether
443 * there is a packet egligible for dequeuing or not. Note that the
444 * statistics of the outer qdisc are necessarily wrong because of all
445 * this. There's currently no correct solution for this.
446 */
447 if (flow == &p->link) {
448 sch->q.qlen++;
9871e50e 449 return NET_XMIT_SUCCESS;
1da177e4
LT
450 }
451 tasklet_schedule(&p->task);
c27f339a 452 return NET_XMIT_SUCCESS | __NET_XMIT_BYPASS;
1da177e4
LT
453}
454
1da177e4
LT
455/*
456 * Dequeue packets and send them over ATM. Note that we quite deliberately
457 * avoid checking net_device's flow control here, simply because sch_atm
458 * uses its own channels, which have nothing to do with any CLIP/LANE/or
459 * non-ATM interfaces.
460 */
461
1da177e4
LT
462static void sch_atm_dequeue(unsigned long data)
463{
b0188d4d 464 struct Qdisc *sch = (struct Qdisc *)data;
786a9036 465 struct atm_qdisc_data *p = qdisc_priv(sch);
1da177e4
LT
466 struct atm_flow_data *flow;
467 struct sk_buff *skb;
468
786a9036 469 pr_debug("sch_atm_dequeue(sch %p,[qdisc %p])\n", sch, p);
6accec76
DM
470 list_for_each_entry(flow, &p->flows, list) {
471 if (flow == &p->link)
472 continue;
1da177e4
LT
473 /*
474 * If traffic is properly shaped, this won't generate nasty
475 * little bursts. Otherwise, it may ... (but that's okay)
476 */
03c05f0d
JP
477 while ((skb = flow->q->ops->peek(flow->q))) {
478 if (!atm_may_send(flow->vcc, skb->truesize))
1da177e4 479 break;
03c05f0d 480
77be155c 481 skb = qdisc_dequeue_peeked(flow->q);
03c05f0d
JP
482 if (unlikely(!skb))
483 break;
484
2dd875ff
ED
485 qdisc_bstats_update(sch, skb);
486 bstats_update(&flow->bstats, skb);
786a9036 487 pr_debug("atm_tc_dequeue: sending on class %p\n", flow);
1da177e4 488 /* remove any LL header somebody else has attached */
eddc9ec5 489 skb_pull(skb, skb_network_offset(skb));
1da177e4
LT
490 if (skb_headroom(skb) < flow->hdr_len) {
491 struct sk_buff *new;
492
b0188d4d 493 new = skb_realloc_headroom(skb, flow->hdr_len);
1da177e4 494 dev_kfree_skb(skb);
b0188d4d
PM
495 if (!new)
496 continue;
1da177e4
LT
497 skb = new;
498 }
786a9036 499 pr_debug("sch_atm_dequeue: ip %p, data %p\n",
eddc9ec5 500 skb_network_header(skb), skb->data);
1da177e4 501 ATM_SKB(skb)->vcc = flow->vcc;
b0188d4d
PM
502 memcpy(skb_push(skb, flow->hdr_len), flow->hdr,
503 flow->hdr_len);
14afee4b 504 refcount_add(skb->truesize,
1da177e4
LT
505 &sk_atm(flow->vcc)->sk_wmem_alloc);
506 /* atm.atm_options are already set by atm_tc_enqueue */
b0188d4d 507 flow->vcc->send(flow->vcc, skb);
1da177e4 508 }
6accec76 509 }
1da177e4
LT
510}
511
1da177e4
LT
512static struct sk_buff *atm_tc_dequeue(struct Qdisc *sch)
513{
786a9036 514 struct atm_qdisc_data *p = qdisc_priv(sch);
1da177e4
LT
515 struct sk_buff *skb;
516
786a9036 517 pr_debug("atm_tc_dequeue(sch %p,[qdisc %p])\n", sch, p);
1da177e4 518 tasklet_schedule(&p->task);
77be155c 519 skb = qdisc_dequeue_peeked(p->link.q);
b0188d4d
PM
520 if (skb)
521 sch->q.qlen--;
1da177e4
LT
522 return skb;
523}
524
8e3af978
JP
525static struct sk_buff *atm_tc_peek(struct Qdisc *sch)
526{
527 struct atm_qdisc_data *p = qdisc_priv(sch);
528
529 pr_debug("atm_tc_peek(sch %p,[qdisc %p])\n", sch, p);
530
531 return p->link.q->ops->peek(p->link.q);
532}
533
1e90474c 534static int atm_tc_init(struct Qdisc *sch, struct nlattr *opt)
1da177e4 535{
786a9036 536 struct atm_qdisc_data *p = qdisc_priv(sch);
6529eaba 537 int err;
1da177e4 538
786a9036 539 pr_debug("atm_tc_init(sch %p,[qdisc %p],opt %p)\n", sch, p, opt);
6accec76
DM
540 INIT_LIST_HEAD(&p->flows);
541 INIT_LIST_HEAD(&p->link.list);
542 list_add(&p->link.list, &p->flows);
3511c913 543 p->link.q = qdisc_create_dflt(sch->dev_queue,
bb949fbd 544 &pfifo_qdisc_ops, sch->handle);
786a9036 545 if (!p->link.q)
1da177e4 546 p->link.q = &noop_qdisc;
786a9036 547 pr_debug("atm_tc_init: link (%p) qdisc %p\n", &p->link, p->link.q);
6529eaba 548
69d78ef2 549 err = tcf_block_get(&p->link.block, &p->link.filter_list, sch);
6529eaba
JP
550 if (err)
551 return err;
552
1da177e4
LT
553 p->link.vcc = NULL;
554 p->link.sock = NULL;
f7ebdff7 555 p->link.common.classid = sch->handle;
1da177e4 556 p->link.ref = 1;
b0188d4d 557 tasklet_init(&p->task, sch_atm_dequeue, (unsigned long)sch);
1da177e4
LT
558 return 0;
559}
560
1da177e4
LT
561static void atm_tc_reset(struct Qdisc *sch)
562{
786a9036 563 struct atm_qdisc_data *p = qdisc_priv(sch);
1da177e4
LT
564 struct atm_flow_data *flow;
565
786a9036 566 pr_debug("atm_tc_reset(sch %p,[qdisc %p])\n", sch, p);
6accec76 567 list_for_each_entry(flow, &p->flows, list)
b0188d4d 568 qdisc_reset(flow->q);
1da177e4
LT
569 sch->q.qlen = 0;
570}
571
1da177e4
LT
572static void atm_tc_destroy(struct Qdisc *sch)
573{
786a9036 574 struct atm_qdisc_data *p = qdisc_priv(sch);
6accec76 575 struct atm_flow_data *flow, *tmp;
1da177e4 576
786a9036 577 pr_debug("atm_tc_destroy(sch %p,[qdisc %p])\n", sch, p);
89890422 578 list_for_each_entry(flow, &p->flows, list) {
6529eaba 579 tcf_block_put(flow->block);
89890422
KK
580 flow->block = NULL;
581 }
a4aebb83 582
6accec76 583 list_for_each_entry_safe(flow, tmp, &p->flows, list) {
1da177e4 584 if (flow->ref > 1)
cc7ec456 585 pr_err("atm_destroy: %p->ref = %d\n", flow, flow->ref);
b0188d4d 586 atm_tc_put(sch, (unsigned long)flow);
1da177e4
LT
587 }
588 tasklet_kill(&p->task);
589}
590
1da177e4 591static int atm_tc_dump_class(struct Qdisc *sch, unsigned long cl,
b0188d4d 592 struct sk_buff *skb, struct tcmsg *tcm)
1da177e4 593{
786a9036 594 struct atm_qdisc_data *p = qdisc_priv(sch);
b0188d4d 595 struct atm_flow_data *flow = (struct atm_flow_data *)cl;
4b3550ef 596 struct nlattr *nest;
1da177e4 597
786a9036 598 pr_debug("atm_tc_dump_class(sch %p,[qdisc %p],flow %p,skb %p,tcm %p)\n",
b0188d4d 599 sch, p, flow, skb, tcm);
6accec76 600 if (list_empty(&flow->list))
b0188d4d 601 return -EINVAL;
f7ebdff7 602 tcm->tcm_handle = flow->common.classid;
cdc7f8e3 603 tcm->tcm_info = flow->q->handle;
4b3550ef
PM
604
605 nest = nla_nest_start(skb, TCA_OPTIONS);
606 if (nest == NULL)
607 goto nla_put_failure;
608
1b34ec43
DM
609 if (nla_put(skb, TCA_ATM_HDR, flow->hdr_len, flow->hdr))
610 goto nla_put_failure;
1da177e4
LT
611 if (flow->vcc) {
612 struct sockaddr_atmpvc pvc;
613 int state;
614
8cb3b9c3 615 memset(&pvc, 0, sizeof(pvc));
1da177e4
LT
616 pvc.sap_family = AF_ATMPVC;
617 pvc.sap_addr.itf = flow->vcc->dev ? flow->vcc->dev->number : -1;
618 pvc.sap_addr.vpi = flow->vcc->vpi;
619 pvc.sap_addr.vci = flow->vcc->vci;
1b34ec43
DM
620 if (nla_put(skb, TCA_ATM_ADDR, sizeof(pvc), &pvc))
621 goto nla_put_failure;
1da177e4 622 state = ATM_VF2VS(flow->vcc->flags);
1b34ec43
DM
623 if (nla_put_u32(skb, TCA_ATM_STATE, state))
624 goto nla_put_failure;
625 }
626 if (flow->excess) {
f7ebdff7 627 if (nla_put_u32(skb, TCA_ATM_EXCESS, flow->common.classid))
1b34ec43
DM
628 goto nla_put_failure;
629 } else {
630 if (nla_put_u32(skb, TCA_ATM_EXCESS, 0))
631 goto nla_put_failure;
1da177e4 632 }
d59b7d80 633 return nla_nest_end(skb, nest);
1da177e4 634
1e90474c 635nla_put_failure:
4b3550ef 636 nla_nest_cancel(skb, nest);
1da177e4
LT
637 return -1;
638}
639static int
640atm_tc_dump_class_stats(struct Qdisc *sch, unsigned long arg,
b0188d4d 641 struct gnet_dump *d)
1da177e4 642{
b0188d4d 643 struct atm_flow_data *flow = (struct atm_flow_data *)arg;
1da177e4 644
edb09eb1
ED
645 if (gnet_stats_copy_basic(qdisc_root_sleeping_running(sch),
646 d, NULL, &flow->bstats) < 0 ||
b0ab6f92 647 gnet_stats_copy_queue(d, NULL, &flow->qstats, flow->q->q.qlen) < 0)
1da177e4
LT
648 return -1;
649
650 return 0;
651}
652
653static int atm_tc_dump(struct Qdisc *sch, struct sk_buff *skb)
654{
655 return 0;
656}
657
20fea08b 658static const struct Qdisc_class_ops atm_class_ops = {
b0188d4d
PM
659 .graft = atm_tc_graft,
660 .leaf = atm_tc_leaf,
143976ce 661 .find = atm_tc_find,
b0188d4d
PM
662 .change = atm_tc_change,
663 .delete = atm_tc_delete,
664 .walk = atm_tc_walk,
6529eaba 665 .tcf_block = atm_tc_tcf_block,
b0188d4d
PM
666 .bind_tcf = atm_tc_bind_filter,
667 .unbind_tcf = atm_tc_put,
668 .dump = atm_tc_dump_class,
669 .dump_stats = atm_tc_dump_class_stats,
1da177e4
LT
670};
671
20fea08b 672static struct Qdisc_ops atm_qdisc_ops __read_mostly = {
b0188d4d
PM
673 .cl_ops = &atm_class_ops,
674 .id = "atm",
675 .priv_size = sizeof(struct atm_qdisc_data),
676 .enqueue = atm_tc_enqueue,
677 .dequeue = atm_tc_dequeue,
8e3af978 678 .peek = atm_tc_peek,
b0188d4d
PM
679 .init = atm_tc_init,
680 .reset = atm_tc_reset,
681 .destroy = atm_tc_destroy,
682 .dump = atm_tc_dump,
683 .owner = THIS_MODULE,
1da177e4
LT
684};
685
1da177e4
LT
686static int __init atm_init(void)
687{
688 return register_qdisc(&atm_qdisc_ops);
689}
690
10297b99 691static void __exit atm_exit(void)
1da177e4
LT
692{
693 unregister_qdisc(&atm_qdisc_ops);
694}
695
696module_init(atm_init)
697module_exit(atm_exit)
698MODULE_LICENSE("GPL");