batman-adv: Correct rcu refcounting for neigh_node
[firefly-linux-kernel-4.4.55.git] / net / batman-adv / icmp_socket.c
1 /*
2  * Copyright (C) 2007-2011 B.A.T.M.A.N. contributors:
3  *
4  * Marek Lindner
5  *
6  * This program is free software; you can redistribute it and/or
7  * modify it under the terms of version 2 of the GNU General Public
8  * License as published by the Free Software Foundation.
9  *
10  * This program is distributed in the hope that it will be useful, but
11  * WITHOUT ANY WARRANTY; without even the implied warranty of
12  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13  * General Public License for more details.
14  *
15  * You should have received a copy of the GNU General Public License
16  * along with this program; if not, write to the Free Software
17  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
18  * 02110-1301, USA
19  *
20  */
21
22 #include "main.h"
23 #include <linux/debugfs.h>
24 #include <linux/slab.h>
25 #include "icmp_socket.h"
26 #include "send.h"
27 #include "hash.h"
28 #include "originator.h"
29 #include "hard-interface.h"
30
31 static struct socket_client *socket_client_hash[256];
32
33 static void bat_socket_add_packet(struct socket_client *socket_client,
34                                   struct icmp_packet_rr *icmp_packet,
35                                   size_t icmp_len);
36
37 void bat_socket_init(void)
38 {
39         memset(socket_client_hash, 0, sizeof(socket_client_hash));
40 }
41
42 static int bat_socket_open(struct inode *inode, struct file *file)
43 {
44         unsigned int i;
45         struct socket_client *socket_client;
46
47         nonseekable_open(inode, file);
48
49         socket_client = kmalloc(sizeof(struct socket_client), GFP_KERNEL);
50
51         if (!socket_client)
52                 return -ENOMEM;
53
54         for (i = 0; i < ARRAY_SIZE(socket_client_hash); i++) {
55                 if (!socket_client_hash[i]) {
56                         socket_client_hash[i] = socket_client;
57                         break;
58                 }
59         }
60
61         if (i == ARRAY_SIZE(socket_client_hash)) {
62                 pr_err("Error - can't add another packet client: "
63                        "maximum number of clients reached\n");
64                 kfree(socket_client);
65                 return -EXFULL;
66         }
67
68         INIT_LIST_HEAD(&socket_client->queue_list);
69         socket_client->queue_len = 0;
70         socket_client->index = i;
71         socket_client->bat_priv = inode->i_private;
72         spin_lock_init(&socket_client->lock);
73         init_waitqueue_head(&socket_client->queue_wait);
74
75         file->private_data = socket_client;
76
77         inc_module_count();
78         return 0;
79 }
80
81 static int bat_socket_release(struct inode *inode, struct file *file)
82 {
83         struct socket_client *socket_client = file->private_data;
84         struct socket_packet *socket_packet;
85         struct list_head *list_pos, *list_pos_tmp;
86
87         spin_lock_bh(&socket_client->lock);
88
89         /* for all packets in the queue ... */
90         list_for_each_safe(list_pos, list_pos_tmp, &socket_client->queue_list) {
91                 socket_packet = list_entry(list_pos,
92                                            struct socket_packet, list);
93
94                 list_del(list_pos);
95                 kfree(socket_packet);
96         }
97
98         socket_client_hash[socket_client->index] = NULL;
99         spin_unlock_bh(&socket_client->lock);
100
101         kfree(socket_client);
102         dec_module_count();
103
104         return 0;
105 }
106
107 static ssize_t bat_socket_read(struct file *file, char __user *buf,
108                                size_t count, loff_t *ppos)
109 {
110         struct socket_client *socket_client = file->private_data;
111         struct socket_packet *socket_packet;
112         size_t packet_len;
113         int error;
114
115         if ((file->f_flags & O_NONBLOCK) && (socket_client->queue_len == 0))
116                 return -EAGAIN;
117
118         if ((!buf) || (count < sizeof(struct icmp_packet)))
119                 return -EINVAL;
120
121         if (!access_ok(VERIFY_WRITE, buf, count))
122                 return -EFAULT;
123
124         error = wait_event_interruptible(socket_client->queue_wait,
125                                          socket_client->queue_len);
126
127         if (error)
128                 return error;
129
130         spin_lock_bh(&socket_client->lock);
131
132         socket_packet = list_first_entry(&socket_client->queue_list,
133                                          struct socket_packet, list);
134         list_del(&socket_packet->list);
135         socket_client->queue_len--;
136
137         spin_unlock_bh(&socket_client->lock);
138
139         error = __copy_to_user(buf, &socket_packet->icmp_packet,
140                                socket_packet->icmp_len);
141
142         packet_len = socket_packet->icmp_len;
143         kfree(socket_packet);
144
145         if (error)
146                 return -EFAULT;
147
148         return packet_len;
149 }
150
151 static ssize_t bat_socket_write(struct file *file, const char __user *buff,
152                                 size_t len, loff_t *off)
153 {
154         struct socket_client *socket_client = file->private_data;
155         struct bat_priv *bat_priv = socket_client->bat_priv;
156         struct sk_buff *skb;
157         struct icmp_packet_rr *icmp_packet;
158
159         struct orig_node *orig_node = NULL;
160         struct neigh_node *neigh_node = NULL;
161         struct batman_if *batman_if;
162         size_t packet_len = sizeof(struct icmp_packet);
163         uint8_t dstaddr[ETH_ALEN];
164
165         if (len < sizeof(struct icmp_packet)) {
166                 bat_dbg(DBG_BATMAN, bat_priv,
167                         "Error - can't send packet from char device: "
168                         "invalid packet size\n");
169                 return -EINVAL;
170         }
171
172         if (!bat_priv->primary_if)
173                 return -EFAULT;
174
175         if (len >= sizeof(struct icmp_packet_rr))
176                 packet_len = sizeof(struct icmp_packet_rr);
177
178         skb = dev_alloc_skb(packet_len + sizeof(struct ethhdr));
179         if (!skb)
180                 return -ENOMEM;
181
182         skb_reserve(skb, sizeof(struct ethhdr));
183         icmp_packet = (struct icmp_packet_rr *)skb_put(skb, packet_len);
184
185         if (!access_ok(VERIFY_READ, buff, packet_len)) {
186                 len = -EFAULT;
187                 goto free_skb;
188         }
189
190         if (__copy_from_user(icmp_packet, buff, packet_len)) {
191                 len = -EFAULT;
192                 goto free_skb;
193         }
194
195         if (icmp_packet->packet_type != BAT_ICMP) {
196                 bat_dbg(DBG_BATMAN, bat_priv,
197                         "Error - can't send packet from char device: "
198                         "got bogus packet type (expected: BAT_ICMP)\n");
199                 len = -EINVAL;
200                 goto free_skb;
201         }
202
203         if (icmp_packet->msg_type != ECHO_REQUEST) {
204                 bat_dbg(DBG_BATMAN, bat_priv,
205                         "Error - can't send packet from char device: "
206                         "got bogus message type (expected: ECHO_REQUEST)\n");
207                 len = -EINVAL;
208                 goto free_skb;
209         }
210
211         icmp_packet->uid = socket_client->index;
212
213         if (icmp_packet->version != COMPAT_VERSION) {
214                 icmp_packet->msg_type = PARAMETER_PROBLEM;
215                 icmp_packet->ttl = COMPAT_VERSION;
216                 bat_socket_add_packet(socket_client, icmp_packet, packet_len);
217                 goto free_skb;
218         }
219
220         if (atomic_read(&bat_priv->mesh_state) != MESH_ACTIVE)
221                 goto dst_unreach;
222
223         spin_lock_bh(&bat_priv->orig_hash_lock);
224         rcu_read_lock();
225         orig_node = ((struct orig_node *)hash_find(bat_priv->orig_hash,
226                                                    compare_orig, choose_orig,
227                                                    icmp_packet->dst));
228
229         if (!orig_node)
230                 goto unlock;
231
232         kref_get(&orig_node->refcount);
233         neigh_node = orig_node->router;
234
235         if (!neigh_node)
236                 goto unlock;
237
238         if (!atomic_inc_not_zero(&neigh_node->refcount)) {
239                 neigh_node = NULL;
240                 goto unlock;
241         }
242
243         rcu_read_unlock();
244
245         batman_if = orig_node->router->if_incoming;
246         memcpy(dstaddr, orig_node->router->addr, ETH_ALEN);
247         spin_unlock_bh(&bat_priv->orig_hash_lock);
248
249         if (!batman_if)
250                 goto dst_unreach;
251
252         if (batman_if->if_status != IF_ACTIVE)
253                 goto dst_unreach;
254
255         memcpy(icmp_packet->orig,
256                bat_priv->primary_if->net_dev->dev_addr, ETH_ALEN);
257
258         if (packet_len == sizeof(struct icmp_packet_rr))
259                 memcpy(icmp_packet->rr,
260                        batman_if->net_dev->dev_addr, ETH_ALEN);
261
262         send_skb_packet(skb, batman_if, dstaddr);
263         goto out;
264
265 unlock:
266         rcu_read_unlock();
267         spin_unlock_bh(&bat_priv->orig_hash_lock);
268 dst_unreach:
269         icmp_packet->msg_type = DESTINATION_UNREACHABLE;
270         bat_socket_add_packet(socket_client, icmp_packet, packet_len);
271 free_skb:
272         kfree_skb(skb);
273 out:
274         if (neigh_node)
275                 neigh_node_free_ref(neigh_node);
276         if (orig_node)
277                 kref_put(&orig_node->refcount, orig_node_free_ref);
278         return len;
279 }
280
281 static unsigned int bat_socket_poll(struct file *file, poll_table *wait)
282 {
283         struct socket_client *socket_client = file->private_data;
284
285         poll_wait(file, &socket_client->queue_wait, wait);
286
287         if (socket_client->queue_len > 0)
288                 return POLLIN | POLLRDNORM;
289
290         return 0;
291 }
292
293 static const struct file_operations fops = {
294         .owner = THIS_MODULE,
295         .open = bat_socket_open,
296         .release = bat_socket_release,
297         .read = bat_socket_read,
298         .write = bat_socket_write,
299         .poll = bat_socket_poll,
300         .llseek = no_llseek,
301 };
302
303 int bat_socket_setup(struct bat_priv *bat_priv)
304 {
305         struct dentry *d;
306
307         if (!bat_priv->debug_dir)
308                 goto err;
309
310         d = debugfs_create_file(ICMP_SOCKET, S_IFREG | S_IWUSR | S_IRUSR,
311                                 bat_priv->debug_dir, bat_priv, &fops);
312         if (d)
313                 goto err;
314
315         return 0;
316
317 err:
318         return 1;
319 }
320
321 static void bat_socket_add_packet(struct socket_client *socket_client,
322                                   struct icmp_packet_rr *icmp_packet,
323                                   size_t icmp_len)
324 {
325         struct socket_packet *socket_packet;
326
327         socket_packet = kmalloc(sizeof(struct socket_packet), GFP_ATOMIC);
328
329         if (!socket_packet)
330                 return;
331
332         INIT_LIST_HEAD(&socket_packet->list);
333         memcpy(&socket_packet->icmp_packet, icmp_packet, icmp_len);
334         socket_packet->icmp_len = icmp_len;
335
336         spin_lock_bh(&socket_client->lock);
337
338         /* while waiting for the lock the socket_client could have been
339          * deleted */
340         if (!socket_client_hash[icmp_packet->uid]) {
341                 spin_unlock_bh(&socket_client->lock);
342                 kfree(socket_packet);
343                 return;
344         }
345
346         list_add_tail(&socket_packet->list, &socket_client->queue_list);
347         socket_client->queue_len++;
348
349         if (socket_client->queue_len > 100) {
350                 socket_packet = list_first_entry(&socket_client->queue_list,
351                                                  struct socket_packet, list);
352
353                 list_del(&socket_packet->list);
354                 kfree(socket_packet);
355                 socket_client->queue_len--;
356         }
357
358         spin_unlock_bh(&socket_client->lock);
359
360         wake_up(&socket_client->queue_wait);
361 }
362
363 void bat_socket_receive_packet(struct icmp_packet_rr *icmp_packet,
364                                size_t icmp_len)
365 {
366         struct socket_client *hash = socket_client_hash[icmp_packet->uid];
367
368         if (hash)
369                 bat_socket_add_packet(hash, icmp_packet, icmp_len);
370 }