Merge tag 'usb-3.9-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb
[firefly-linux-kernel-4.4.55.git] / net / batman-adv / routing.c
1 /* Copyright (C) 2007-2013 B.A.T.M.A.N. contributors:
2  *
3  * Marek Lindner, Simon Wunderlich
4  *
5  * This program is free software; you can redistribute it and/or
6  * modify it under the terms of version 2 of the GNU General Public
7  * License as published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but
10  * WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12  * General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program; if not, write to the Free Software
16  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
17  * 02110-1301, USA
18  */
19
20 #include "main.h"
21 #include "routing.h"
22 #include "send.h"
23 #include "soft-interface.h"
24 #include "hard-interface.h"
25 #include "icmp_socket.h"
26 #include "translation-table.h"
27 #include "originator.h"
28 #include "vis.h"
29 #include "unicast.h"
30 #include "bridge_loop_avoidance.h"
31 #include "distributed-arp-table.h"
32
33 static int batadv_route_unicast_packet(struct sk_buff *skb,
34                                        struct batadv_hard_iface *recv_if);
35
36 void batadv_slide_own_bcast_window(struct batadv_hard_iface *hard_iface)
37 {
38         struct batadv_priv *bat_priv = netdev_priv(hard_iface->soft_iface);
39         struct batadv_hashtable *hash = bat_priv->orig_hash;
40         struct hlist_head *head;
41         struct batadv_orig_node *orig_node;
42         unsigned long *word;
43         uint32_t i;
44         size_t word_index;
45         uint8_t *w;
46
47         for (i = 0; i < hash->size; i++) {
48                 head = &hash->table[i];
49
50                 rcu_read_lock();
51                 hlist_for_each_entry_rcu(orig_node, head, hash_entry) {
52                         spin_lock_bh(&orig_node->ogm_cnt_lock);
53                         word_index = hard_iface->if_num * BATADV_NUM_WORDS;
54                         word = &(orig_node->bcast_own[word_index]);
55
56                         batadv_bit_get_packet(bat_priv, word, 1, 0);
57                         w = &orig_node->bcast_own_sum[hard_iface->if_num];
58                         *w = bitmap_weight(word, BATADV_TQ_LOCAL_WINDOW_SIZE);
59                         spin_unlock_bh(&orig_node->ogm_cnt_lock);
60                 }
61                 rcu_read_unlock();
62         }
63 }
64
65 static void _batadv_update_route(struct batadv_priv *bat_priv,
66                                  struct batadv_orig_node *orig_node,
67                                  struct batadv_neigh_node *neigh_node)
68 {
69         struct batadv_neigh_node *curr_router;
70
71         curr_router = batadv_orig_node_get_router(orig_node);
72
73         /* route deleted */
74         if ((curr_router) && (!neigh_node)) {
75                 batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
76                            "Deleting route towards: %pM\n", orig_node->orig);
77                 batadv_tt_global_del_orig(bat_priv, orig_node,
78                                           "Deleted route towards originator");
79
80         /* route added */
81         } else if ((!curr_router) && (neigh_node)) {
82                 batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
83                            "Adding route towards: %pM (via %pM)\n",
84                            orig_node->orig, neigh_node->addr);
85         /* route changed */
86         } else if (neigh_node && curr_router) {
87                 batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
88                            "Changing route towards: %pM (now via %pM - was via %pM)\n",
89                            orig_node->orig, neigh_node->addr,
90                            curr_router->addr);
91         }
92
93         if (curr_router)
94                 batadv_neigh_node_free_ref(curr_router);
95
96         /* increase refcount of new best neighbor */
97         if (neigh_node && !atomic_inc_not_zero(&neigh_node->refcount))
98                 neigh_node = NULL;
99
100         spin_lock_bh(&orig_node->neigh_list_lock);
101         rcu_assign_pointer(orig_node->router, neigh_node);
102         spin_unlock_bh(&orig_node->neigh_list_lock);
103
104         /* decrease refcount of previous best neighbor */
105         if (curr_router)
106                 batadv_neigh_node_free_ref(curr_router);
107 }
108
109 void batadv_update_route(struct batadv_priv *bat_priv,
110                          struct batadv_orig_node *orig_node,
111                          struct batadv_neigh_node *neigh_node)
112 {
113         struct batadv_neigh_node *router = NULL;
114
115         if (!orig_node)
116                 goto out;
117
118         router = batadv_orig_node_get_router(orig_node);
119
120         if (router != neigh_node)
121                 _batadv_update_route(bat_priv, orig_node, neigh_node);
122
123 out:
124         if (router)
125                 batadv_neigh_node_free_ref(router);
126 }
127
128 /* caller must hold the neigh_list_lock */
129 void batadv_bonding_candidate_del(struct batadv_orig_node *orig_node,
130                                   struct batadv_neigh_node *neigh_node)
131 {
132         /* this neighbor is not part of our candidate list */
133         if (list_empty(&neigh_node->bonding_list))
134                 goto out;
135
136         list_del_rcu(&neigh_node->bonding_list);
137         INIT_LIST_HEAD(&neigh_node->bonding_list);
138         batadv_neigh_node_free_ref(neigh_node);
139         atomic_dec(&orig_node->bond_candidates);
140
141 out:
142         return;
143 }
144
145 void batadv_bonding_candidate_add(struct batadv_orig_node *orig_node,
146                                   struct batadv_neigh_node *neigh_node)
147 {
148         struct batadv_neigh_node *tmp_neigh_node, *router = NULL;
149         uint8_t interference_candidate = 0;
150
151         spin_lock_bh(&orig_node->neigh_list_lock);
152
153         /* only consider if it has the same primary address ...  */
154         if (!batadv_compare_eth(orig_node->orig,
155                                 neigh_node->orig_node->primary_addr))
156                 goto candidate_del;
157
158         router = batadv_orig_node_get_router(orig_node);
159         if (!router)
160                 goto candidate_del;
161
162         /* ... and is good enough to be considered */
163         if (neigh_node->tq_avg < router->tq_avg - BATADV_BONDING_TQ_THRESHOLD)
164                 goto candidate_del;
165
166         /* check if we have another candidate with the same mac address or
167          * interface. If we do, we won't select this candidate because of
168          * possible interference.
169          */
170         hlist_for_each_entry_rcu(tmp_neigh_node,
171                                  &orig_node->neigh_list, list) {
172                 if (tmp_neigh_node == neigh_node)
173                         continue;
174
175                 /* we only care if the other candidate is even
176                  * considered as candidate.
177                  */
178                 if (list_empty(&tmp_neigh_node->bonding_list))
179                         continue;
180
181                 if ((neigh_node->if_incoming == tmp_neigh_node->if_incoming) ||
182                     (batadv_compare_eth(neigh_node->addr,
183                                         tmp_neigh_node->addr))) {
184                         interference_candidate = 1;
185                         break;
186                 }
187         }
188
189         /* don't care further if it is an interference candidate */
190         if (interference_candidate)
191                 goto candidate_del;
192
193         /* this neighbor already is part of our candidate list */
194         if (!list_empty(&neigh_node->bonding_list))
195                 goto out;
196
197         if (!atomic_inc_not_zero(&neigh_node->refcount))
198                 goto out;
199
200         list_add_rcu(&neigh_node->bonding_list, &orig_node->bond_list);
201         atomic_inc(&orig_node->bond_candidates);
202         goto out;
203
204 candidate_del:
205         batadv_bonding_candidate_del(orig_node, neigh_node);
206
207 out:
208         spin_unlock_bh(&orig_node->neigh_list_lock);
209
210         if (router)
211                 batadv_neigh_node_free_ref(router);
212 }
213
214 /* copy primary address for bonding */
215 void
216 batadv_bonding_save_primary(const struct batadv_orig_node *orig_node,
217                             struct batadv_orig_node *orig_neigh_node,
218                             const struct batadv_ogm_packet *batman_ogm_packet)
219 {
220         if (!(batman_ogm_packet->flags & BATADV_PRIMARIES_FIRST_HOP))
221                 return;
222
223         memcpy(orig_neigh_node->primary_addr, orig_node->orig, ETH_ALEN);
224 }
225
226 /* checks whether the host restarted and is in the protection time.
227  * returns:
228  *  0 if the packet is to be accepted
229  *  1 if the packet is to be ignored.
230  */
231 int batadv_window_protected(struct batadv_priv *bat_priv, int32_t seq_num_diff,
232                             unsigned long *last_reset)
233 {
234         if (seq_num_diff <= -BATADV_TQ_LOCAL_WINDOW_SIZE ||
235             seq_num_diff >= BATADV_EXPECTED_SEQNO_RANGE) {
236                 if (!batadv_has_timed_out(*last_reset,
237                                           BATADV_RESET_PROTECTION_MS))
238                         return 1;
239
240                 *last_reset = jiffies;
241                 batadv_dbg(BATADV_DBG_BATMAN, bat_priv,
242                            "old packet received, start protection\n");
243         }
244
245         return 0;
246 }
247
248 bool batadv_check_management_packet(struct sk_buff *skb,
249                                     struct batadv_hard_iface *hard_iface,
250                                     int header_len)
251 {
252         struct ethhdr *ethhdr;
253
254         /* drop packet if it has not necessary minimum size */
255         if (unlikely(!pskb_may_pull(skb, header_len)))
256                 return false;
257
258         ethhdr = (struct ethhdr *)skb_mac_header(skb);
259
260         /* packet with broadcast indication but unicast recipient */
261         if (!is_broadcast_ether_addr(ethhdr->h_dest))
262                 return false;
263
264         /* packet with broadcast sender address */
265         if (is_broadcast_ether_addr(ethhdr->h_source))
266                 return false;
267
268         /* create a copy of the skb, if needed, to modify it. */
269         if (skb_cow(skb, 0) < 0)
270                 return false;
271
272         /* keep skb linear */
273         if (skb_linearize(skb) < 0)
274                 return false;
275
276         return true;
277 }
278
279 static int batadv_recv_my_icmp_packet(struct batadv_priv *bat_priv,
280                                       struct sk_buff *skb, size_t icmp_len)
281 {
282         struct batadv_hard_iface *primary_if = NULL;
283         struct batadv_orig_node *orig_node = NULL;
284         struct batadv_icmp_packet_rr *icmp_packet;
285         int ret = NET_RX_DROP;
286
287         icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
288
289         /* add data to device queue */
290         if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) {
291                 batadv_socket_receive_packet(icmp_packet, icmp_len);
292                 goto out;
293         }
294
295         primary_if = batadv_primary_if_get_selected(bat_priv);
296         if (!primary_if)
297                 goto out;
298
299         /* answer echo request (ping) */
300         /* get routing information */
301         orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig);
302         if (!orig_node)
303                 goto out;
304
305         /* create a copy of the skb, if needed, to modify it. */
306         if (skb_cow(skb, ETH_HLEN) < 0)
307                 goto out;
308
309         icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
310
311         memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN);
312         memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN);
313         icmp_packet->msg_type = BATADV_ECHO_REPLY;
314         icmp_packet->header.ttl = BATADV_TTL;
315
316         if (batadv_send_skb_to_orig(skb, orig_node, NULL))
317                 ret = NET_RX_SUCCESS;
318
319 out:
320         if (primary_if)
321                 batadv_hardif_free_ref(primary_if);
322         if (orig_node)
323                 batadv_orig_node_free_ref(orig_node);
324         return ret;
325 }
326
327 static int batadv_recv_icmp_ttl_exceeded(struct batadv_priv *bat_priv,
328                                          struct sk_buff *skb)
329 {
330         struct batadv_hard_iface *primary_if = NULL;
331         struct batadv_orig_node *orig_node = NULL;
332         struct batadv_icmp_packet *icmp_packet;
333         int ret = NET_RX_DROP;
334
335         icmp_packet = (struct batadv_icmp_packet *)skb->data;
336
337         /* send TTL exceeded if packet is an echo request (traceroute) */
338         if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) {
339                 pr_debug("Warning - can't forward icmp packet from %pM to %pM: ttl exceeded\n",
340                          icmp_packet->orig, icmp_packet->dst);
341                 goto out;
342         }
343
344         primary_if = batadv_primary_if_get_selected(bat_priv);
345         if (!primary_if)
346                 goto out;
347
348         /* get routing information */
349         orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig);
350         if (!orig_node)
351                 goto out;
352
353         /* create a copy of the skb, if needed, to modify it. */
354         if (skb_cow(skb, ETH_HLEN) < 0)
355                 goto out;
356
357         icmp_packet = (struct batadv_icmp_packet *)skb->data;
358
359         memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN);
360         memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN);
361         icmp_packet->msg_type = BATADV_TTL_EXCEEDED;
362         icmp_packet->header.ttl = BATADV_TTL;
363
364         if (batadv_send_skb_to_orig(skb, orig_node, NULL))
365                 ret = NET_RX_SUCCESS;
366
367 out:
368         if (primary_if)
369                 batadv_hardif_free_ref(primary_if);
370         if (orig_node)
371                 batadv_orig_node_free_ref(orig_node);
372         return ret;
373 }
374
375
376 int batadv_recv_icmp_packet(struct sk_buff *skb,
377                             struct batadv_hard_iface *recv_if)
378 {
379         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
380         struct batadv_icmp_packet_rr *icmp_packet;
381         struct ethhdr *ethhdr;
382         struct batadv_orig_node *orig_node = NULL;
383         int hdr_size = sizeof(struct batadv_icmp_packet);
384         int ret = NET_RX_DROP;
385
386         /* we truncate all incoming icmp packets if they don't match our size */
387         if (skb->len >= sizeof(struct batadv_icmp_packet_rr))
388                 hdr_size = sizeof(struct batadv_icmp_packet_rr);
389
390         /* drop packet if it has not necessary minimum size */
391         if (unlikely(!pskb_may_pull(skb, hdr_size)))
392                 goto out;
393
394         ethhdr = (struct ethhdr *)skb_mac_header(skb);
395
396         /* packet with unicast indication but broadcast recipient */
397         if (is_broadcast_ether_addr(ethhdr->h_dest))
398                 goto out;
399
400         /* packet with broadcast sender address */
401         if (is_broadcast_ether_addr(ethhdr->h_source))
402                 goto out;
403
404         /* not for me */
405         if (!batadv_is_my_mac(ethhdr->h_dest))
406                 goto out;
407
408         icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
409
410         /* add record route information if not full */
411         if ((hdr_size == sizeof(struct batadv_icmp_packet_rr)) &&
412             (icmp_packet->rr_cur < BATADV_RR_LEN)) {
413                 memcpy(&(icmp_packet->rr[icmp_packet->rr_cur]),
414                        ethhdr->h_dest, ETH_ALEN);
415                 icmp_packet->rr_cur++;
416         }
417
418         /* packet for me */
419         if (batadv_is_my_mac(icmp_packet->dst))
420                 return batadv_recv_my_icmp_packet(bat_priv, skb, hdr_size);
421
422         /* TTL exceeded */
423         if (icmp_packet->header.ttl < 2)
424                 return batadv_recv_icmp_ttl_exceeded(bat_priv, skb);
425
426         /* get routing information */
427         orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->dst);
428         if (!orig_node)
429                 goto out;
430
431         /* create a copy of the skb, if needed, to modify it. */
432         if (skb_cow(skb, ETH_HLEN) < 0)
433                 goto out;
434
435         icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
436
437         /* decrement ttl */
438         icmp_packet->header.ttl--;
439
440         /* route it */
441         if (batadv_send_skb_to_orig(skb, orig_node, recv_if))
442                 ret = NET_RX_SUCCESS;
443
444 out:
445         if (orig_node)
446                 batadv_orig_node_free_ref(orig_node);
447         return ret;
448 }
449
450 /* In the bonding case, send the packets in a round
451  * robin fashion over the remaining interfaces.
452  *
453  * This method rotates the bonding list and increases the
454  * returned router's refcount.
455  */
456 static struct batadv_neigh_node *
457 batadv_find_bond_router(struct batadv_orig_node *primary_orig,
458                         const struct batadv_hard_iface *recv_if)
459 {
460         struct batadv_neigh_node *tmp_neigh_node;
461         struct batadv_neigh_node *router = NULL, *first_candidate = NULL;
462
463         rcu_read_lock();
464         list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
465                                 bonding_list) {
466                 if (!first_candidate)
467                         first_candidate = tmp_neigh_node;
468
469                 /* recv_if == NULL on the first node. */
470                 if (tmp_neigh_node->if_incoming == recv_if)
471                         continue;
472
473                 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
474                         continue;
475
476                 router = tmp_neigh_node;
477                 break;
478         }
479
480         /* use the first candidate if nothing was found. */
481         if (!router && first_candidate &&
482             atomic_inc_not_zero(&first_candidate->refcount))
483                 router = first_candidate;
484
485         if (!router)
486                 goto out;
487
488         /* selected should point to the next element
489          * after the current router
490          */
491         spin_lock_bh(&primary_orig->neigh_list_lock);
492         /* this is a list_move(), which unfortunately
493          * does not exist as rcu version
494          */
495         list_del_rcu(&primary_orig->bond_list);
496         list_add_rcu(&primary_orig->bond_list,
497                      &router->bonding_list);
498         spin_unlock_bh(&primary_orig->neigh_list_lock);
499
500 out:
501         rcu_read_unlock();
502         return router;
503 }
504
505 /* Interface Alternating: Use the best of the
506  * remaining candidates which are not using
507  * this interface.
508  *
509  * Increases the returned router's refcount
510  */
511 static struct batadv_neigh_node *
512 batadv_find_ifalter_router(struct batadv_orig_node *primary_orig,
513                            const struct batadv_hard_iface *recv_if)
514 {
515         struct batadv_neigh_node *tmp_neigh_node;
516         struct batadv_neigh_node *router = NULL, *first_candidate = NULL;
517
518         rcu_read_lock();
519         list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
520                                 bonding_list) {
521                 if (!first_candidate)
522                         first_candidate = tmp_neigh_node;
523
524                 /* recv_if == NULL on the first node. */
525                 if (tmp_neigh_node->if_incoming == recv_if)
526                         continue;
527
528                 if (router && tmp_neigh_node->tq_avg <= router->tq_avg)
529                         continue;
530
531                 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
532                         continue;
533
534                 /* decrement refcount of previously selected router */
535                 if (router)
536                         batadv_neigh_node_free_ref(router);
537
538                 /* we found a better router (or at least one valid router) */
539                 router = tmp_neigh_node;
540         }
541
542         /* use the first candidate if nothing was found. */
543         if (!router && first_candidate &&
544             atomic_inc_not_zero(&first_candidate->refcount))
545                 router = first_candidate;
546
547         rcu_read_unlock();
548         return router;
549 }
550
551 static int batadv_check_unicast_packet(struct sk_buff *skb, int hdr_size)
552 {
553         struct ethhdr *ethhdr;
554
555         /* drop packet if it has not necessary minimum size */
556         if (unlikely(!pskb_may_pull(skb, hdr_size)))
557                 return -1;
558
559         ethhdr = (struct ethhdr *)skb_mac_header(skb);
560
561         /* packet with unicast indication but broadcast recipient */
562         if (is_broadcast_ether_addr(ethhdr->h_dest))
563                 return -1;
564
565         /* packet with broadcast sender address */
566         if (is_broadcast_ether_addr(ethhdr->h_source))
567                 return -1;
568
569         /* not for me */
570         if (!batadv_is_my_mac(ethhdr->h_dest))
571                 return -1;
572
573         return 0;
574 }
575
576 int batadv_recv_tt_query(struct sk_buff *skb, struct batadv_hard_iface *recv_if)
577 {
578         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
579         struct batadv_tt_query_packet *tt_query;
580         uint16_t tt_size;
581         int hdr_size = sizeof(*tt_query);
582         char tt_flag;
583         size_t packet_size;
584
585         if (batadv_check_unicast_packet(skb, hdr_size) < 0)
586                 return NET_RX_DROP;
587
588         /* I could need to modify it */
589         if (skb_cow(skb, sizeof(struct batadv_tt_query_packet)) < 0)
590                 goto out;
591
592         tt_query = (struct batadv_tt_query_packet *)skb->data;
593
594         switch (tt_query->flags & BATADV_TT_QUERY_TYPE_MASK) {
595         case BATADV_TT_REQUEST:
596                 batadv_inc_counter(bat_priv, BATADV_CNT_TT_REQUEST_RX);
597
598                 /* If we cannot provide an answer the tt_request is
599                  * forwarded
600                  */
601                 if (!batadv_send_tt_response(bat_priv, tt_query)) {
602                         if (tt_query->flags & BATADV_TT_FULL_TABLE)
603                                 tt_flag = 'F';
604                         else
605                                 tt_flag = '.';
606
607                         batadv_dbg(BATADV_DBG_TT, bat_priv,
608                                    "Routing TT_REQUEST to %pM [%c]\n",
609                                    tt_query->dst,
610                                    tt_flag);
611                         return batadv_route_unicast_packet(skb, recv_if);
612                 }
613                 break;
614         case BATADV_TT_RESPONSE:
615                 batadv_inc_counter(bat_priv, BATADV_CNT_TT_RESPONSE_RX);
616
617                 if (batadv_is_my_mac(tt_query->dst)) {
618                         /* packet needs to be linearized to access the TT
619                          * changes
620                          */
621                         if (skb_linearize(skb) < 0)
622                                 goto out;
623                         /* skb_linearize() possibly changed skb->data */
624                         tt_query = (struct batadv_tt_query_packet *)skb->data;
625
626                         tt_size = batadv_tt_len(ntohs(tt_query->tt_data));
627
628                         /* Ensure we have all the claimed data */
629                         packet_size = sizeof(struct batadv_tt_query_packet);
630                         packet_size += tt_size;
631                         if (unlikely(skb_headlen(skb) < packet_size))
632                                 goto out;
633
634                         batadv_handle_tt_response(bat_priv, tt_query);
635                 } else {
636                         if (tt_query->flags & BATADV_TT_FULL_TABLE)
637                                 tt_flag =  'F';
638                         else
639                                 tt_flag = '.';
640                         batadv_dbg(BATADV_DBG_TT, bat_priv,
641                                    "Routing TT_RESPONSE to %pM [%c]\n",
642                                    tt_query->dst,
643                                    tt_flag);
644                         return batadv_route_unicast_packet(skb, recv_if);
645                 }
646                 break;
647         }
648
649 out:
650         /* returning NET_RX_DROP will make the caller function kfree the skb */
651         return NET_RX_DROP;
652 }
653
654 int batadv_recv_roam_adv(struct sk_buff *skb, struct batadv_hard_iface *recv_if)
655 {
656         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
657         struct batadv_roam_adv_packet *roam_adv_packet;
658         struct batadv_orig_node *orig_node;
659
660         if (batadv_check_unicast_packet(skb, sizeof(*roam_adv_packet)) < 0)
661                 goto out;
662
663         batadv_inc_counter(bat_priv, BATADV_CNT_TT_ROAM_ADV_RX);
664
665         roam_adv_packet = (struct batadv_roam_adv_packet *)skb->data;
666
667         if (!batadv_is_my_mac(roam_adv_packet->dst))
668                 return batadv_route_unicast_packet(skb, recv_if);
669
670         /* check if it is a backbone gateway. we don't accept
671          * roaming advertisement from it, as it has the same
672          * entries as we have.
673          */
674         if (batadv_bla_is_backbone_gw_orig(bat_priv, roam_adv_packet->src))
675                 goto out;
676
677         orig_node = batadv_orig_hash_find(bat_priv, roam_adv_packet->src);
678         if (!orig_node)
679                 goto out;
680
681         batadv_dbg(BATADV_DBG_TT, bat_priv,
682                    "Received ROAMING_ADV from %pM (client %pM)\n",
683                    roam_adv_packet->src, roam_adv_packet->client);
684
685         batadv_tt_global_add(bat_priv, orig_node, roam_adv_packet->client,
686                              BATADV_TT_CLIENT_ROAM,
687                              atomic_read(&orig_node->last_ttvn) + 1);
688
689         batadv_orig_node_free_ref(orig_node);
690 out:
691         /* returning NET_RX_DROP will make the caller function kfree the skb */
692         return NET_RX_DROP;
693 }
694
695 /* find a suitable router for this originator, and use
696  * bonding if possible. increases the found neighbors
697  * refcount.
698  */
699 struct batadv_neigh_node *
700 batadv_find_router(struct batadv_priv *bat_priv,
701                    struct batadv_orig_node *orig_node,
702                    const struct batadv_hard_iface *recv_if)
703 {
704         struct batadv_orig_node *primary_orig_node;
705         struct batadv_orig_node *router_orig;
706         struct batadv_neigh_node *router;
707         static uint8_t zero_mac[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
708         int bonding_enabled;
709         uint8_t *primary_addr;
710
711         if (!orig_node)
712                 return NULL;
713
714         router = batadv_orig_node_get_router(orig_node);
715         if (!router)
716                 goto err;
717
718         /* without bonding, the first node should
719          * always choose the default router.
720          */
721         bonding_enabled = atomic_read(&bat_priv->bonding);
722
723         rcu_read_lock();
724         /* select default router to output */
725         router_orig = router->orig_node;
726         if (!router_orig)
727                 goto err_unlock;
728
729         if ((!recv_if) && (!bonding_enabled))
730                 goto return_router;
731
732         primary_addr = router_orig->primary_addr;
733
734         /* if we have something in the primary_addr, we can search
735          * for a potential bonding candidate.
736          */
737         if (batadv_compare_eth(primary_addr, zero_mac))
738                 goto return_router;
739
740         /* find the orig_node which has the primary interface. might
741          * even be the same as our router_orig in many cases
742          */
743         if (batadv_compare_eth(primary_addr, router_orig->orig)) {
744                 primary_orig_node = router_orig;
745         } else {
746                 primary_orig_node = batadv_orig_hash_find(bat_priv,
747                                                           primary_addr);
748                 if (!primary_orig_node)
749                         goto return_router;
750
751                 batadv_orig_node_free_ref(primary_orig_node);
752         }
753
754         /* with less than 2 candidates, we can't do any
755          * bonding and prefer the original router.
756          */
757         if (atomic_read(&primary_orig_node->bond_candidates) < 2)
758                 goto return_router;
759
760         /* all nodes between should choose a candidate which
761          * is is not on the interface where the packet came
762          * in.
763          */
764         batadv_neigh_node_free_ref(router);
765
766         if (bonding_enabled)
767                 router = batadv_find_bond_router(primary_orig_node, recv_if);
768         else
769                 router = batadv_find_ifalter_router(primary_orig_node, recv_if);
770
771 return_router:
772         if (router && router->if_incoming->if_status != BATADV_IF_ACTIVE)
773                 goto err_unlock;
774
775         rcu_read_unlock();
776         return router;
777 err_unlock:
778         rcu_read_unlock();
779 err:
780         if (router)
781                 batadv_neigh_node_free_ref(router);
782         return NULL;
783 }
784
785 static int batadv_route_unicast_packet(struct sk_buff *skb,
786                                        struct batadv_hard_iface *recv_if)
787 {
788         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
789         struct batadv_orig_node *orig_node = NULL;
790         struct batadv_neigh_node *neigh_node = NULL;
791         struct batadv_unicast_packet *unicast_packet;
792         struct ethhdr *ethhdr = (struct ethhdr *)skb_mac_header(skb);
793         int ret = NET_RX_DROP;
794         struct sk_buff *new_skb;
795
796         unicast_packet = (struct batadv_unicast_packet *)skb->data;
797
798         /* TTL exceeded */
799         if (unicast_packet->header.ttl < 2) {
800                 pr_debug("Warning - can't forward unicast packet from %pM to %pM: ttl exceeded\n",
801                          ethhdr->h_source, unicast_packet->dest);
802                 goto out;
803         }
804
805         /* get routing information */
806         orig_node = batadv_orig_hash_find(bat_priv, unicast_packet->dest);
807
808         if (!orig_node)
809                 goto out;
810
811         /* find_router() increases neigh_nodes refcount if found. */
812         neigh_node = batadv_find_router(bat_priv, orig_node, recv_if);
813
814         if (!neigh_node)
815                 goto out;
816
817         /* create a copy of the skb, if needed, to modify it. */
818         if (skb_cow(skb, ETH_HLEN) < 0)
819                 goto out;
820
821         unicast_packet = (struct batadv_unicast_packet *)skb->data;
822
823         if (unicast_packet->header.packet_type == BATADV_UNICAST &&
824             atomic_read(&bat_priv->fragmentation) &&
825             skb->len > neigh_node->if_incoming->net_dev->mtu) {
826                 ret = batadv_frag_send_skb(skb, bat_priv,
827                                            neigh_node->if_incoming,
828                                            neigh_node->addr);
829                 goto out;
830         }
831
832         if (unicast_packet->header.packet_type == BATADV_UNICAST_FRAG &&
833             batadv_frag_can_reassemble(skb,
834                                        neigh_node->if_incoming->net_dev->mtu)) {
835                 ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb);
836
837                 if (ret == NET_RX_DROP)
838                         goto out;
839
840                 /* packet was buffered for late merge */
841                 if (!new_skb) {
842                         ret = NET_RX_SUCCESS;
843                         goto out;
844                 }
845
846                 skb = new_skb;
847                 unicast_packet = (struct batadv_unicast_packet *)skb->data;
848         }
849
850         /* decrement ttl */
851         unicast_packet->header.ttl--;
852
853         /* Update stats counter */
854         batadv_inc_counter(bat_priv, BATADV_CNT_FORWARD);
855         batadv_add_counter(bat_priv, BATADV_CNT_FORWARD_BYTES,
856                            skb->len + ETH_HLEN);
857
858         /* route it */
859         if (batadv_send_skb_to_orig(skb, orig_node, recv_if))
860                 ret = NET_RX_SUCCESS;
861
862 out:
863         if (neigh_node)
864                 batadv_neigh_node_free_ref(neigh_node);
865         if (orig_node)
866                 batadv_orig_node_free_ref(orig_node);
867         return ret;
868 }
869
870 /**
871  * batadv_reroute_unicast_packet - update the unicast header for re-routing
872  * @bat_priv: the bat priv with all the soft interface information
873  * @unicast_packet: the unicast header to be updated
874  * @dst_addr: the payload destination
875  *
876  * Search the translation table for dst_addr and update the unicast header with
877  * the new corresponding information (originator address where the destination
878  * client currently is and its known TTVN)
879  *
880  * Returns true if the packet header has been updated, false otherwise
881  */
882 static bool
883 batadv_reroute_unicast_packet(struct batadv_priv *bat_priv,
884                               struct batadv_unicast_packet *unicast_packet,
885                               uint8_t *dst_addr)
886 {
887         struct batadv_orig_node *orig_node = NULL;
888         struct batadv_hard_iface *primary_if = NULL;
889         bool ret = false;
890         uint8_t *orig_addr, orig_ttvn;
891
892         if (batadv_is_my_client(bat_priv, dst_addr)) {
893                 primary_if = batadv_primary_if_get_selected(bat_priv);
894                 if (!primary_if)
895                         goto out;
896                 orig_addr = primary_if->net_dev->dev_addr;
897                 orig_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn);
898         } else {
899                 orig_node = batadv_transtable_search(bat_priv, NULL, dst_addr);
900                 if (!orig_node)
901                         goto out;
902
903                 if (batadv_compare_eth(orig_node->orig, unicast_packet->dest))
904                         goto out;
905
906                 orig_addr = orig_node->orig;
907                 orig_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn);
908         }
909
910         /* update the packet header */
911         memcpy(unicast_packet->dest, orig_addr, ETH_ALEN);
912         unicast_packet->ttvn = orig_ttvn;
913
914         ret = true;
915 out:
916         if (primary_if)
917                 batadv_hardif_free_ref(primary_if);
918         if (orig_node)
919                 batadv_orig_node_free_ref(orig_node);
920
921         return ret;
922 }
923
924 static int batadv_check_unicast_ttvn(struct batadv_priv *bat_priv,
925                                      struct sk_buff *skb) {
926         uint8_t curr_ttvn, old_ttvn;
927         struct batadv_orig_node *orig_node;
928         struct ethhdr *ethhdr;
929         struct batadv_hard_iface *primary_if;
930         struct batadv_unicast_packet *unicast_packet;
931         int is_old_ttvn;
932
933         /* check if there is enough data before accessing it */
934         if (pskb_may_pull(skb, sizeof(*unicast_packet) + ETH_HLEN) < 0)
935                 return 0;
936
937         /* create a copy of the skb (in case of for re-routing) to modify it. */
938         if (skb_cow(skb, sizeof(*unicast_packet)) < 0)
939                 return 0;
940
941         unicast_packet = (struct batadv_unicast_packet *)skb->data;
942         ethhdr = (struct ethhdr *)(skb->data + sizeof(*unicast_packet));
943
944         /* check if the destination client was served by this node and it is now
945          * roaming. In this case, it means that the node has got a ROAM_ADV
946          * message and that it knows the new destination in the mesh to re-route
947          * the packet to
948          */
949         if (batadv_tt_local_client_is_roaming(bat_priv, ethhdr->h_dest)) {
950                 if (batadv_reroute_unicast_packet(bat_priv, unicast_packet,
951                                                   ethhdr->h_dest))
952                         net_ratelimited_function(batadv_dbg, BATADV_DBG_TT,
953                                                  bat_priv,
954                                                  "Rerouting unicast packet to %pM (dst=%pM): Local Roaming\n",
955                                                  unicast_packet->dest,
956                                                  ethhdr->h_dest);
957                 /* at this point the mesh destination should have been
958                  * substituted with the originator address found in the global
959                  * table. If not, let the packet go untouched anyway because
960                  * there is nothing the node can do
961                  */
962                 return 1;
963         }
964
965         /* retrieve the TTVN known by this node for the packet destination. This
966          * value is used later to check if the node which sent (or re-routed
967          * last time) the packet had an updated information or not
968          */
969         curr_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn);
970         if (!batadv_is_my_mac(unicast_packet->dest)) {
971                 orig_node = batadv_orig_hash_find(bat_priv,
972                                                   unicast_packet->dest);
973                 /* if it is not possible to find the orig_node representing the
974                  * destination, the packet can immediately be dropped as it will
975                  * not be possible to deliver it
976                  */
977                 if (!orig_node)
978                         return 0;
979
980                 curr_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn);
981                 batadv_orig_node_free_ref(orig_node);
982         }
983
984         /* check if the TTVN contained in the packet is fresher than what the
985          * node knows
986          */
987         is_old_ttvn = batadv_seq_before(unicast_packet->ttvn, curr_ttvn);
988         if (!is_old_ttvn)
989                 return 1;
990
991         old_ttvn = unicast_packet->ttvn;
992         /* the packet was forged based on outdated network information. Its
993          * destination can possibly be updated and forwarded towards the new
994          * target host
995          */
996         if (batadv_reroute_unicast_packet(bat_priv, unicast_packet,
997                                           ethhdr->h_dest)) {
998                 net_ratelimited_function(batadv_dbg, BATADV_DBG_TT, bat_priv,
999                                          "Rerouting unicast packet to %pM (dst=%pM): TTVN mismatch old_ttvn=%u new_ttvn=%u\n",
1000                                          unicast_packet->dest, ethhdr->h_dest,
1001                                          old_ttvn, curr_ttvn);
1002                 return 1;
1003         }
1004
1005         /* the packet has not been re-routed: either the destination is
1006          * currently served by this node or there is no destination at all and
1007          * it is possible to drop the packet
1008          */
1009         if (!batadv_is_my_client(bat_priv, ethhdr->h_dest))
1010                 return 0;
1011
1012         /* update the header in order to let the packet be delivered to this
1013          * node's soft interface
1014          */
1015         primary_if = batadv_primary_if_get_selected(bat_priv);
1016         if (!primary_if)
1017                 return 0;
1018
1019         memcpy(unicast_packet->dest, primary_if->net_dev->dev_addr, ETH_ALEN);
1020
1021         batadv_hardif_free_ref(primary_if);
1022
1023         unicast_packet->ttvn = curr_ttvn;
1024
1025         return 1;
1026 }
1027
1028 int batadv_recv_unicast_packet(struct sk_buff *skb,
1029                                struct batadv_hard_iface *recv_if)
1030 {
1031         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1032         struct batadv_unicast_packet *unicast_packet;
1033         struct batadv_unicast_4addr_packet *unicast_4addr_packet;
1034         uint8_t *orig_addr;
1035         struct batadv_orig_node *orig_node = NULL;
1036         int hdr_size = sizeof(*unicast_packet);
1037         bool is4addr;
1038
1039         unicast_packet = (struct batadv_unicast_packet *)skb->data;
1040         unicast_4addr_packet = (struct batadv_unicast_4addr_packet *)skb->data;
1041
1042         is4addr = unicast_packet->header.packet_type == BATADV_UNICAST_4ADDR;
1043         /* the caller function should have already pulled 2 bytes */
1044         if (is4addr)
1045                 hdr_size = sizeof(*unicast_4addr_packet);
1046
1047         if (batadv_check_unicast_packet(skb, hdr_size) < 0)
1048                 return NET_RX_DROP;
1049
1050         if (!batadv_check_unicast_ttvn(bat_priv, skb))
1051                 return NET_RX_DROP;
1052
1053         /* packet for me */
1054         if (batadv_is_my_mac(unicast_packet->dest)) {
1055                 if (is4addr) {
1056                         batadv_dat_inc_counter(bat_priv,
1057                                                unicast_4addr_packet->subtype);
1058                         orig_addr = unicast_4addr_packet->src;
1059                         orig_node = batadv_orig_hash_find(bat_priv, orig_addr);
1060                 }
1061
1062                 if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb,
1063                                                           hdr_size))
1064                         goto rx_success;
1065                 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb,
1066                                                         hdr_size))
1067                         goto rx_success;
1068
1069                 batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size,
1070                                     orig_node);
1071
1072 rx_success:
1073                 if (orig_node)
1074                         batadv_orig_node_free_ref(orig_node);
1075
1076                 return NET_RX_SUCCESS;
1077         }
1078
1079         return batadv_route_unicast_packet(skb, recv_if);
1080 }
1081
1082 int batadv_recv_ucast_frag_packet(struct sk_buff *skb,
1083                                   struct batadv_hard_iface *recv_if)
1084 {
1085         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1086         struct batadv_unicast_frag_packet *unicast_packet;
1087         int hdr_size = sizeof(*unicast_packet);
1088         struct sk_buff *new_skb = NULL;
1089         int ret;
1090
1091         if (batadv_check_unicast_packet(skb, hdr_size) < 0)
1092                 return NET_RX_DROP;
1093
1094         if (!batadv_check_unicast_ttvn(bat_priv, skb))
1095                 return NET_RX_DROP;
1096
1097         unicast_packet = (struct batadv_unicast_frag_packet *)skb->data;
1098
1099         /* packet for me */
1100         if (batadv_is_my_mac(unicast_packet->dest)) {
1101                 ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb);
1102
1103                 if (ret == NET_RX_DROP)
1104                         return NET_RX_DROP;
1105
1106                 /* packet was buffered for late merge */
1107                 if (!new_skb)
1108                         return NET_RX_SUCCESS;
1109
1110                 if (batadv_dat_snoop_incoming_arp_request(bat_priv, new_skb,
1111                                                           hdr_size))
1112                         goto rx_success;
1113                 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, new_skb,
1114                                                         hdr_size))
1115                         goto rx_success;
1116
1117                 batadv_interface_rx(recv_if->soft_iface, new_skb, recv_if,
1118                                     sizeof(struct batadv_unicast_packet), NULL);
1119
1120 rx_success:
1121                 return NET_RX_SUCCESS;
1122         }
1123
1124         return batadv_route_unicast_packet(skb, recv_if);
1125 }
1126
1127
1128 int batadv_recv_bcast_packet(struct sk_buff *skb,
1129                              struct batadv_hard_iface *recv_if)
1130 {
1131         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1132         struct batadv_orig_node *orig_node = NULL;
1133         struct batadv_bcast_packet *bcast_packet;
1134         struct ethhdr *ethhdr;
1135         int hdr_size = sizeof(*bcast_packet);
1136         int ret = NET_RX_DROP;
1137         int32_t seq_diff;
1138
1139         /* drop packet if it has not necessary minimum size */
1140         if (unlikely(!pskb_may_pull(skb, hdr_size)))
1141                 goto out;
1142
1143         ethhdr = (struct ethhdr *)skb_mac_header(skb);
1144
1145         /* packet with broadcast indication but unicast recipient */
1146         if (!is_broadcast_ether_addr(ethhdr->h_dest))
1147                 goto out;
1148
1149         /* packet with broadcast sender address */
1150         if (is_broadcast_ether_addr(ethhdr->h_source))
1151                 goto out;
1152
1153         /* ignore broadcasts sent by myself */
1154         if (batadv_is_my_mac(ethhdr->h_source))
1155                 goto out;
1156
1157         bcast_packet = (struct batadv_bcast_packet *)skb->data;
1158
1159         /* ignore broadcasts originated by myself */
1160         if (batadv_is_my_mac(bcast_packet->orig))
1161                 goto out;
1162
1163         if (bcast_packet->header.ttl < 2)
1164                 goto out;
1165
1166         orig_node = batadv_orig_hash_find(bat_priv, bcast_packet->orig);
1167
1168         if (!orig_node)
1169                 goto out;
1170
1171         spin_lock_bh(&orig_node->bcast_seqno_lock);
1172
1173         /* check whether the packet is a duplicate */
1174         if (batadv_test_bit(orig_node->bcast_bits, orig_node->last_bcast_seqno,
1175                             ntohl(bcast_packet->seqno)))
1176                 goto spin_unlock;
1177
1178         seq_diff = ntohl(bcast_packet->seqno) - orig_node->last_bcast_seqno;
1179
1180         /* check whether the packet is old and the host just restarted. */
1181         if (batadv_window_protected(bat_priv, seq_diff,
1182                                     &orig_node->bcast_seqno_reset))
1183                 goto spin_unlock;
1184
1185         /* mark broadcast in flood history, update window position
1186          * if required.
1187          */
1188         if (batadv_bit_get_packet(bat_priv, orig_node->bcast_bits, seq_diff, 1))
1189                 orig_node->last_bcast_seqno = ntohl(bcast_packet->seqno);
1190
1191         spin_unlock_bh(&orig_node->bcast_seqno_lock);
1192
1193         /* check whether this has been sent by another originator before */
1194         if (batadv_bla_check_bcast_duplist(bat_priv, skb))
1195                 goto out;
1196
1197         /* rebroadcast packet */
1198         batadv_add_bcast_packet_to_list(bat_priv, skb, 1);
1199
1200         /* don't hand the broadcast up if it is from an originator
1201          * from the same backbone.
1202          */
1203         if (batadv_bla_is_backbone_gw(skb, orig_node, hdr_size))
1204                 goto out;
1205
1206         if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb, hdr_size))
1207                 goto rx_success;
1208         if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb, hdr_size))
1209                 goto rx_success;
1210
1211         /* broadcast for me */
1212         batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size,
1213                             orig_node);
1214
1215 rx_success:
1216         ret = NET_RX_SUCCESS;
1217         goto out;
1218
1219 spin_unlock:
1220         spin_unlock_bh(&orig_node->bcast_seqno_lock);
1221 out:
1222         if (orig_node)
1223                 batadv_orig_node_free_ref(orig_node);
1224         return ret;
1225 }
1226
1227 int batadv_recv_vis_packet(struct sk_buff *skb,
1228                            struct batadv_hard_iface *recv_if)
1229 {
1230         struct batadv_vis_packet *vis_packet;
1231         struct ethhdr *ethhdr;
1232         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1233         int hdr_size = sizeof(*vis_packet);
1234
1235         /* keep skb linear */
1236         if (skb_linearize(skb) < 0)
1237                 return NET_RX_DROP;
1238
1239         if (unlikely(!pskb_may_pull(skb, hdr_size)))
1240                 return NET_RX_DROP;
1241
1242         vis_packet = (struct batadv_vis_packet *)skb->data;
1243         ethhdr = (struct ethhdr *)skb_mac_header(skb);
1244
1245         /* not for me */
1246         if (!batadv_is_my_mac(ethhdr->h_dest))
1247                 return NET_RX_DROP;
1248
1249         /* ignore own packets */
1250         if (batadv_is_my_mac(vis_packet->vis_orig))
1251                 return NET_RX_DROP;
1252
1253         if (batadv_is_my_mac(vis_packet->sender_orig))
1254                 return NET_RX_DROP;
1255
1256         switch (vis_packet->vis_type) {
1257         case BATADV_VIS_TYPE_SERVER_SYNC:
1258                 batadv_receive_server_sync_packet(bat_priv, vis_packet,
1259                                                   skb_headlen(skb));
1260                 break;
1261
1262         case BATADV_VIS_TYPE_CLIENT_UPDATE:
1263                 batadv_receive_client_update_packet(bat_priv, vis_packet,
1264                                                     skb_headlen(skb));
1265                 break;
1266
1267         default:        /* ignore unknown packet */
1268                 break;
1269         }
1270
1271         /* We take a copy of the data in the packet, so we should
1272          * always free the skbuf.
1273          */
1274         return NET_RX_DROP;
1275 }