af_x25.c 41 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866
  1. /*
  2. * X.25 Packet Layer release 002
  3. *
  4. * This is ALPHA test software. This code may break your machine,
  5. * randomly fail to work with new releases, misbehave and/or generally
  6. * screw up. It might even work.
  7. *
  8. * This code REQUIRES 2.1.15 or higher
  9. *
  10. * This module:
  11. * This module is free software; you can redistribute it and/or
  12. * modify it under the terms of the GNU General Public License
  13. * as published by the Free Software Foundation; either version
  14. * 2 of the License, or (at your option) any later version.
  15. *
  16. * History
  17. * X.25 001 Jonathan Naylor Started coding.
  18. * X.25 002 Jonathan Naylor Centralised disconnect handling.
  19. * New timer architecture.
  20. * 2000-03-11 Henner Eisen MSG_EOR handling more POSIX compliant.
  21. * 2000-03-22 Daniela Squassoni Allowed disabling/enabling of
  22. * facilities negotiation and increased
  23. * the throughput upper limit.
  24. * 2000-08-27 Arnaldo C. Melo s/suser/capable/ + micro cleanups
  25. * 2000-09-04 Henner Eisen Set sock->state in x25_accept().
  26. * Fixed x25_output() related skb leakage.
  27. * 2000-10-02 Henner Eisen Made x25_kick() single threaded per socket.
  28. * 2000-10-27 Henner Eisen MSG_DONTWAIT for fragment allocation.
  29. * 2000-11-14 Henner Eisen Closing datalink from NETDEV_GOING_DOWN
  30. * 2002-10-06 Arnaldo C. Melo Get rid of cli/sti, move proc stuff to
  31. * x25_proc.c, using seq_file
  32. * 2005-04-02 Shaun Pereira Selective sub address matching
  33. * with call user data
  34. * 2005-04-15 Shaun Pereira Fast select with no restriction on
  35. * response
  36. */
  37. #include <linux/module.h>
  38. #include <linux/capability.h>
  39. #include <linux/errno.h>
  40. #include <linux/kernel.h>
  41. #include <linux/sched.h>
  42. #include <linux/timer.h>
  43. #include <linux/string.h>
  44. #include <linux/net.h>
  45. #include <linux/netdevice.h>
  46. #include <linux/if_arp.h>
  47. #include <linux/skbuff.h>
  48. #include <linux/slab.h>
  49. #include <net/sock.h>
  50. #include <net/tcp_states.h>
  51. #include <asm/uaccess.h>
  52. #include <linux/fcntl.h>
  53. #include <linux/termios.h> /* For TIOCINQ/OUTQ */
  54. #include <linux/notifier.h>
  55. #include <linux/init.h>
  56. #include <linux/compat.h>
  57. #include <linux/ctype.h>
  58. #include <net/x25.h>
  59. #include <net/compat.h>
  60. #ifdef KW_TAINT_ANALYSIS
  61. extern void * get_tainted_stuff();
  62. #endif
  63. int sysctl_x25_restart_request_timeout = X25_DEFAULT_T20;
  64. int sysctl_x25_call_request_timeout = X25_DEFAULT_T21;
  65. int sysctl_x25_reset_request_timeout = X25_DEFAULT_T22;
  66. int sysctl_x25_clear_request_timeout = X25_DEFAULT_T23;
  67. int sysctl_x25_ack_holdback_timeout = X25_DEFAULT_T2;
  68. int sysctl_x25_forward = 0;
  69. HLIST_HEAD(x25_list);
  70. DEFINE_RWLOCK(x25_list_lock);
  71. static const struct proto_ops x25_proto_ops;
  72. static struct x25_address null_x25_address = {" "};
  73. #ifdef CONFIG_COMPAT
  74. struct compat_x25_subscrip_struct {
  75. char device[200-sizeof(compat_ulong_t)];
  76. compat_ulong_t global_facil_mask;
  77. compat_uint_t extended;
  78. };
  79. #endif
  80. int x25_parse_address_block(struct sk_buff *skb,
  81. struct x25_address *called_addr,
  82. struct x25_address *calling_addr)
  83. {
  84. unsigned char len;
  85. int needed;
  86. int rc;
  87. if (!pskb_may_pull(skb, 1)) {
  88. /* packet has no address block */
  89. rc = 0;
  90. goto empty;
  91. }
  92. len = *skb->data;
  93. needed = 1 + (len >> 4) + (len & 0x0f);
  94. if (!pskb_may_pull(skb, needed)) {
  95. /* packet is too short to hold the addresses it claims
  96. to hold */
  97. rc = -1;
  98. goto empty;
  99. }
  100. return x25_addr_ntoa(skb->data, called_addr, calling_addr);
  101. empty:
  102. *called_addr->x25_addr = 0;
  103. *calling_addr->x25_addr = 0;
  104. return rc;
  105. }
  106. int x25_addr_ntoa(unsigned char *p, struct x25_address *called_addr,
  107. struct x25_address *calling_addr)
  108. {
  109. unsigned int called_len, calling_len;
  110. char *called, *calling;
  111. unsigned int i;
  112. called_len = (*p >> 0) & 0x0F;
  113. calling_len = (*p >> 4) & 0x0F;
  114. called = called_addr->x25_addr;
  115. calling = calling_addr->x25_addr;
  116. p++;
  117. for (i = 0; i < (called_len + calling_len); i++) {
  118. if (i < called_len) {
  119. if (i % 2 != 0) {
  120. *called++ = ((*p >> 0) & 0x0F) + '0';
  121. p++;
  122. } else {
  123. *called++ = ((*p >> 4) & 0x0F) + '0';
  124. }
  125. } else {
  126. if (i % 2 != 0) {
  127. *calling++ = ((*p >> 0) & 0x0F) + '0';
  128. p++;
  129. } else {
  130. *calling++ = ((*p >> 4) & 0x0F) + '0';
  131. }
  132. }
  133. }
  134. *called = *calling = '\0';
  135. return 1 + (called_len + calling_len + 1) / 2;
  136. }
  137. int x25_addr_aton(unsigned char *p, struct x25_address *called_addr,
  138. struct x25_address *calling_addr)
  139. {
  140. unsigned int called_len, calling_len;
  141. char *called, *calling;
  142. int i;
  143. called = called_addr->x25_addr;
  144. calling = calling_addr->x25_addr;
  145. called_len = strlen(called);
  146. calling_len = strlen(calling);
  147. *p++ = (calling_len << 4) | (called_len << 0);
  148. for (i = 0; i < (called_len + calling_len); i++) {
  149. if (i < called_len) {
  150. if (i % 2 != 0) {
  151. *p |= (*called++ - '0') << 0;
  152. p++;
  153. } else {
  154. *p = 0x00;
  155. *p |= (*called++ - '0') << 4;
  156. }
  157. } else {
  158. if (i % 2 != 0) {
  159. *p |= (*calling++ - '0') << 0;
  160. p++;
  161. } else {
  162. *p = 0x00;
  163. *p |= (*calling++ - '0') << 4;
  164. }
  165. }
  166. }
  167. return 1 + (called_len + calling_len + 1) / 2;
  168. }
  169. /*
  170. * Socket removal during an interrupt is now safe.
  171. */
  172. static void x25_remove_socket(struct sock *sk)
  173. {
  174. write_lock_bh(&x25_list_lock);
  175. sk_del_node_init(sk);
  176. write_unlock_bh(&x25_list_lock);
  177. }
  178. /*
  179. * Kill all bound sockets on a dropped device.
  180. */
  181. static void x25_kill_by_device(struct net_device *dev)
  182. {
  183. struct sock *s;
  184. struct hlist_node *node;
  185. write_lock_bh(&x25_list_lock);
  186. sk_for_each(s, node, &x25_list)
  187. if (x25_sk(s)->neighbour && x25_sk(s)->neighbour->dev == dev)
  188. x25_disconnect(s, ENETUNREACH, 0, 0);
  189. write_unlock_bh(&x25_list_lock);
  190. }
  191. /*
  192. * Handle device status changes.
  193. */
  194. static int x25_device_event(struct notifier_block *this, unsigned long event,
  195. void *ptr)
  196. {
  197. struct net_device *dev = ptr;
  198. struct x25_neigh *nb;
  199. if (!net_eq(dev_net(dev), &init_net))
  200. return NOTIFY_DONE;
  201. if (dev->type == ARPHRD_X25
  202. #if IS_ENABLED(CONFIG_LLC)
  203. || dev->type == ARPHRD_ETHER
  204. #endif
  205. ) {
  206. switch (event) {
  207. case NETDEV_UP:
  208. x25_link_device_up(dev);
  209. break;
  210. case NETDEV_GOING_DOWN:
  211. nb = x25_get_neigh(dev);
  212. if (nb) {
  213. x25_terminate_link(nb);
  214. x25_neigh_put(nb);
  215. }
  216. break;
  217. case NETDEV_DOWN:
  218. x25_kill_by_device(dev);
  219. x25_route_device_down(dev);
  220. x25_link_device_down(dev);
  221. break;
  222. }
  223. }
  224. return NOTIFY_DONE;
  225. }
  226. /*
  227. * Add a socket to the bound sockets list.
  228. */
  229. static void x25_insert_socket(struct sock *sk)
  230. {
  231. write_lock_bh(&x25_list_lock);
  232. sk_add_node(sk, &x25_list);
  233. write_unlock_bh(&x25_list_lock);
  234. }
  235. /*
  236. * Find a socket that wants to accept the Call Request we just
  237. * received. Check the full list for an address/cud match.
  238. * If no cuds match return the next_best thing, an address match.
  239. * Note: if a listening socket has cud set it must only get calls
  240. * with matching cud.
  241. */
  242. static struct sock *x25_find_listener(struct x25_address *addr,
  243. struct sk_buff *skb)
  244. {
  245. struct sock *s;
  246. struct sock *next_best;
  247. struct hlist_node *node;
  248. read_lock_bh(&x25_list_lock);
  249. next_best = NULL;
  250. sk_for_each(s, node, &x25_list)
  251. if ((!strcmp(addr->x25_addr,
  252. x25_sk(s)->source_addr.x25_addr) ||
  253. !strcmp(addr->x25_addr,
  254. null_x25_address.x25_addr)) &&
  255. s->sk_state == TCP_LISTEN) {
  256. /*
  257. * Found a listening socket, now check the incoming
  258. * call user data vs this sockets call user data
  259. */
  260. if (x25_sk(s)->cudmatchlength > 0 &&
  261. skb->len >= x25_sk(s)->cudmatchlength) {
  262. if((memcmp(x25_sk(s)->calluserdata.cuddata,
  263. skb->data,
  264. x25_sk(s)->cudmatchlength)) == 0) {
  265. sock_hold(s);
  266. goto found;
  267. }
  268. } else
  269. next_best = s;
  270. }
  271. if (next_best) {
  272. s = next_best;
  273. sock_hold(s);
  274. goto found;
  275. }
  276. s = NULL;
  277. found:
  278. read_unlock_bh(&x25_list_lock);
  279. return s;
  280. }
  281. /*
  282. * Find a connected X.25 socket given my LCI and neighbour.
  283. */
  284. static struct sock *__x25_find_socket(unsigned int lci, struct x25_neigh *nb)
  285. {
  286. struct sock *s;
  287. struct hlist_node *node;
  288. sk_for_each(s, node, &x25_list)
  289. if (x25_sk(s)->lci == lci && x25_sk(s)->neighbour == nb) {
  290. sock_hold(s);
  291. goto found;
  292. }
  293. s = NULL;
  294. found:
  295. return s;
  296. }
  297. struct sock *x25_find_socket(unsigned int lci, struct x25_neigh *nb)
  298. {
  299. struct sock *s;
  300. read_lock_bh(&x25_list_lock);
  301. s = __x25_find_socket(lci, nb);
  302. read_unlock_bh(&x25_list_lock);
  303. return s;
  304. }
  305. /*
  306. * Find a unique LCI for a given device.
  307. */
  308. static unsigned int x25_new_lci(struct x25_neigh *nb)
  309. {
  310. unsigned int lci = 1;
  311. struct sock *sk;
  312. read_lock_bh(&x25_list_lock);
  313. while ((sk = __x25_find_socket(lci, nb)) != NULL) {
  314. sock_put(sk);
  315. if (++lci == 4096) {
  316. lci = 0;
  317. break;
  318. }
  319. }
  320. read_unlock_bh(&x25_list_lock);
  321. return lci;
  322. }
  323. /*
  324. * Deferred destroy.
  325. */
  326. static void __x25_destroy_socket(struct sock *);
  327. /*
  328. * handler for deferred kills.
  329. */
  330. static void x25_destroy_timer(unsigned long data)
  331. {
  332. x25_destroy_socket_from_timer((struct sock *)data);
  333. }
  334. /*
  335. * This is called from user mode and the timers. Thus it protects itself
  336. * against interrupt users but doesn't worry about being called during
  337. * work. Once it is removed from the queue no interrupt or bottom half
  338. * will touch it and we are (fairly 8-) ) safe.
  339. * Not static as it's used by the timer
  340. */
  341. static void __x25_destroy_socket(struct sock *sk)
  342. {
  343. struct sk_buff *skb;
  344. x25_stop_heartbeat(sk);
  345. x25_stop_timer(sk);
  346. x25_remove_socket(sk);
  347. x25_clear_queues(sk); /* Flush the queues */
  348. while ((skb = skb_dequeue(&sk->sk_receive_queue)) != NULL) {
  349. if (skb->sk != sk) { /* A pending connection */
  350. /*
  351. * Queue the unaccepted socket for death
  352. */
  353. skb->sk->sk_state = TCP_LISTEN;
  354. sock_set_flag(skb->sk, SOCK_DEAD);
  355. x25_start_heartbeat(skb->sk);
  356. x25_sk(skb->sk)->state = X25_STATE_0;
  357. }
  358. kfree_skb(skb);
  359. }
  360. if (sk_has_allocations(sk)) {
  361. /* Defer: outstanding buffers */
  362. sk->sk_timer.expires = jiffies + 10 * HZ;
  363. sk->sk_timer.function = x25_destroy_timer;
  364. sk->sk_timer.data = (unsigned long)sk;
  365. add_timer(&sk->sk_timer);
  366. } else {
  367. /* drop last reference so sock_put will free */
  368. __sock_put(sk);
  369. }
  370. }
  371. void x25_destroy_socket_from_timer(struct sock *sk)
  372. {
  373. sock_hold(sk);
  374. bh_lock_sock(sk);
  375. __x25_destroy_socket(sk);
  376. bh_unlock_sock(sk);
  377. sock_put(sk);
  378. }
  379. /*
  380. * Handling for system calls applied via the various interfaces to a
  381. * X.25 socket object.
  382. */
  383. static int x25_setsockopt(struct socket *sock, int level, int optname,
  384. char __user *optval, unsigned int optlen)
  385. {
  386. int opt;
  387. struct sock *sk = sock->sk;
  388. int rc = -ENOPROTOOPT;
  389. if (level != SOL_X25 || optname != X25_QBITINCL)
  390. goto out;
  391. rc = -EINVAL;
  392. if (optlen < sizeof(int))
  393. goto out;
  394. rc = -EFAULT;
  395. if (get_user(opt, (int __user *)optval))
  396. goto out;
  397. if (opt)
  398. set_bit(X25_Q_BIT_FLAG, &x25_sk(sk)->flags);
  399. else
  400. clear_bit(X25_Q_BIT_FLAG, &x25_sk(sk)->flags);
  401. rc = 0;
  402. out:
  403. return rc;
  404. }
  405. static int x25_getsockopt(struct socket *sock, int level, int optname,
  406. char __user *optval, int __user *optlen)
  407. {
  408. struct sock *sk = sock->sk;
  409. int val, len, rc = -ENOPROTOOPT;
  410. if (level != SOL_X25 || optname != X25_QBITINCL)
  411. goto out;
  412. rc = -EFAULT;
  413. if (get_user(len, optlen))
  414. goto out;
  415. len = min_t(unsigned int, len, sizeof(int));
  416. rc = -EINVAL;
  417. if (len < 0)
  418. goto out;
  419. rc = -EFAULT;
  420. if (put_user(len, optlen))
  421. goto out;
  422. val = test_bit(X25_Q_BIT_FLAG, &x25_sk(sk)->flags);
  423. rc = copy_to_user(optval, &val, len) ? -EFAULT : 0;
  424. out:
  425. return rc;
  426. }
  427. static int x25_listen(struct socket *sock, int backlog)
  428. {
  429. struct sock *sk = sock->sk;
  430. int rc = -EOPNOTSUPP;
  431. lock_sock(sk);
  432. if (sk->sk_state != TCP_LISTEN) {
  433. memset(&x25_sk(sk)->dest_addr, 0, X25_ADDR_LEN);
  434. sk->sk_max_ack_backlog = backlog;
  435. sk->sk_state = TCP_LISTEN;
  436. rc = 0;
  437. }
  438. release_sock(sk);
  439. return rc;
  440. }
  441. static struct proto x25_proto = {
  442. .name = "X25",
  443. .owner = THIS_MODULE,
  444. .obj_size = sizeof(struct x25_sock),
  445. };
  446. static struct sock *x25_alloc_socket(struct net *net)
  447. {
  448. struct x25_sock *x25;
  449. struct sock *sk = sk_alloc(net, AF_X25, GFP_ATOMIC, &x25_proto);
  450. if (!sk)
  451. goto out;
  452. sock_init_data(NULL, sk);
  453. x25 = x25_sk(sk);
  454. skb_queue_head_init(&x25->ack_queue);
  455. skb_queue_head_init(&x25->fragment_queue);
  456. skb_queue_head_init(&x25->interrupt_in_queue);
  457. skb_queue_head_init(&x25->interrupt_out_queue);
  458. out:
  459. return sk;
  460. }
  461. static int x25_create(struct net *net, struct socket *sock, int protocol,
  462. int kern)
  463. {
  464. struct sock *sk;
  465. struct x25_sock *x25;
  466. int rc = -EAFNOSUPPORT;
  467. if (!net_eq(net, &init_net))
  468. goto out;
  469. rc = -ESOCKTNOSUPPORT;
  470. if (sock->type != SOCK_SEQPACKET)
  471. goto out;
  472. rc = -EINVAL;
  473. if (protocol)
  474. goto out;
  475. rc = -ENOBUFS;
  476. if ((sk = x25_alloc_socket(net)) == NULL)
  477. goto out;
  478. x25 = x25_sk(sk);
  479. sock_init_data(sock, sk);
  480. x25_init_timers(sk);
  481. sock->ops = &x25_proto_ops;
  482. sk->sk_protocol = protocol;
  483. sk->sk_backlog_rcv = x25_backlog_rcv;
  484. x25->t21 = sysctl_x25_call_request_timeout;
  485. x25->t22 = sysctl_x25_reset_request_timeout;
  486. x25->t23 = sysctl_x25_clear_request_timeout;
  487. x25->t2 = sysctl_x25_ack_holdback_timeout;
  488. x25->state = X25_STATE_0;
  489. x25->cudmatchlength = 0;
  490. set_bit(X25_ACCPT_APPRV_FLAG, &x25->flags); /* normally no cud */
  491. /* on call accept */
  492. x25->facilities.winsize_in = X25_DEFAULT_WINDOW_SIZE;
  493. x25->facilities.winsize_out = X25_DEFAULT_WINDOW_SIZE;
  494. x25->facilities.pacsize_in = X25_DEFAULT_PACKET_SIZE;
  495. x25->facilities.pacsize_out = X25_DEFAULT_PACKET_SIZE;
  496. x25->facilities.throughput = 0; /* by default don't negotiate
  497. throughput */
  498. x25->facilities.reverse = X25_DEFAULT_REVERSE;
  499. x25->dte_facilities.calling_len = 0;
  500. x25->dte_facilities.called_len = 0;
  501. memset(x25->dte_facilities.called_ae, '\0',
  502. sizeof(x25->dte_facilities.called_ae));
  503. memset(x25->dte_facilities.calling_ae, '\0',
  504. sizeof(x25->dte_facilities.calling_ae));
  505. rc = 0;
  506. out:
  507. return rc;
  508. }
  509. static struct sock *x25_make_new(struct sock *osk)
  510. {
  511. struct sock *sk = NULL;
  512. struct x25_sock *x25, *ox25;
  513. if (osk->sk_type != SOCK_SEQPACKET)
  514. goto out;
  515. if ((sk = x25_alloc_socket(sock_net(osk))) == NULL)
  516. goto out;
  517. x25 = x25_sk(sk);
  518. sk->sk_type = osk->sk_type;
  519. sk->sk_priority = osk->sk_priority;
  520. sk->sk_protocol = osk->sk_protocol;
  521. sk->sk_rcvbuf = osk->sk_rcvbuf;
  522. sk->sk_sndbuf = osk->sk_sndbuf;
  523. sk->sk_state = TCP_ESTABLISHED;
  524. sk->sk_backlog_rcv = osk->sk_backlog_rcv;
  525. sock_copy_flags(sk, osk);
  526. ox25 = x25_sk(osk);
  527. x25->t21 = ox25->t21;
  528. x25->t22 = ox25->t22;
  529. x25->t23 = ox25->t23;
  530. x25->t2 = ox25->t2;
  531. x25->flags = ox25->flags;
  532. x25->facilities = ox25->facilities;
  533. x25->dte_facilities = ox25->dte_facilities;
  534. x25->cudmatchlength = ox25->cudmatchlength;
  535. clear_bit(X25_INTERRUPT_FLAG, &x25->flags);
  536. x25_init_timers(sk);
  537. out:
  538. return sk;
  539. }
  540. static int x25_release(struct socket *sock)
  541. {
  542. struct sock *sk = sock->sk;
  543. struct x25_sock *x25;
  544. if (!sk)
  545. return 0;
  546. x25 = x25_sk(sk);
  547. sock_hold(sk);
  548. lock_sock(sk);
  549. switch (x25->state) {
  550. case X25_STATE_0:
  551. case X25_STATE_2:
  552. x25_disconnect(sk, 0, 0, 0);
  553. __x25_destroy_socket(sk);
  554. goto out;
  555. case X25_STATE_1:
  556. case X25_STATE_3:
  557. case X25_STATE_4:
  558. x25_clear_queues(sk);
  559. x25_write_internal(sk, X25_CLEAR_REQUEST);
  560. x25_start_t23timer(sk);
  561. x25->state = X25_STATE_2;
  562. sk->sk_state = TCP_CLOSE;
  563. sk->sk_shutdown |= SEND_SHUTDOWN;
  564. sk->sk_state_change(sk);
  565. sock_set_flag(sk, SOCK_DEAD);
  566. sock_set_flag(sk, SOCK_DESTROY);
  567. break;
  568. }
  569. sock_orphan(sk);
  570. out:
  571. release_sock(sk);
  572. sock_put(sk);
  573. return 0;
  574. }
  575. static int x25_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
  576. {
  577. struct sock *sk = sock->sk;
  578. struct sockaddr_x25 *addr = (struct sockaddr_x25 *)uaddr;
  579. int len, i, rc = 0;
  580. if (!sock_flag(sk, SOCK_ZAPPED) ||
  581. addr_len != sizeof(struct sockaddr_x25) ||
  582. addr->sx25_family != AF_X25) {
  583. rc = -EINVAL;
  584. goto out;
  585. }
  586. len = strlen(addr->sx25_addr.x25_addr);
  587. for (i = 0; i < len; i++) {
  588. if (!isdigit(addr->sx25_addr.x25_addr[i])) {
  589. rc = -EINVAL;
  590. goto out;
  591. }
  592. }
  593. lock_sock(sk);
  594. x25_sk(sk)->source_addr = addr->sx25_addr;
  595. x25_insert_socket(sk);
  596. sock_reset_flag(sk, SOCK_ZAPPED);
  597. release_sock(sk);
  598. SOCK_DEBUG(sk, "x25_bind: socket is bound\n");
  599. out:
  600. return rc;
  601. }
  602. static int x25_wait_for_connection_establishment(struct sock *sk)
  603. {
  604. DECLARE_WAITQUEUE(wait, current);
  605. int rc;
  606. add_wait_queue_exclusive(sk_sleep(sk), &wait);
  607. for (;;) {
  608. __set_current_state(TASK_INTERRUPTIBLE);
  609. rc = -ERESTARTSYS;
  610. if (signal_pending(current))
  611. break;
  612. rc = sock_error(sk);
  613. if (rc) {
  614. sk->sk_socket->state = SS_UNCONNECTED;
  615. break;
  616. }
  617. rc = 0;
  618. if (sk->sk_state != TCP_ESTABLISHED) {
  619. release_sock(sk);
  620. schedule();
  621. lock_sock(sk);
  622. } else
  623. break;
  624. }
  625. __set_current_state(TASK_RUNNING);
  626. remove_wait_queue(sk_sleep(sk), &wait);
  627. return rc;
  628. }
  629. static int x25_connect(struct socket *sock, struct sockaddr *uaddr,
  630. int addr_len, int flags)
  631. {
  632. struct sock *sk = sock->sk;
  633. struct x25_sock *x25 = x25_sk(sk);
  634. struct sockaddr_x25 *addr = (struct sockaddr_x25 *)uaddr;
  635. struct x25_route *rt;
  636. int rc = 0;
  637. lock_sock(sk);
  638. if (sk->sk_state == TCP_ESTABLISHED && sock->state == SS_CONNECTING) {
  639. sock->state = SS_CONNECTED;
  640. goto out; /* Connect completed during a ERESTARTSYS event */
  641. }
  642. rc = -ECONNREFUSED;
  643. if (sk->sk_state == TCP_CLOSE && sock->state == SS_CONNECTING) {
  644. sock->state = SS_UNCONNECTED;
  645. goto out;
  646. }
  647. rc = -EISCONN; /* No reconnect on a seqpacket socket */
  648. if (sk->sk_state == TCP_ESTABLISHED)
  649. goto out;
  650. sk->sk_state = TCP_CLOSE;
  651. sock->state = SS_UNCONNECTED;
  652. rc = -EINVAL;
  653. if (addr_len != sizeof(struct sockaddr_x25) ||
  654. addr->sx25_family != AF_X25)
  655. goto out;
  656. rc = -ENETUNREACH;
  657. rt = x25_get_route(&addr->sx25_addr);
  658. if (!rt)
  659. goto out;
  660. x25->neighbour = x25_get_neigh(rt->dev);
  661. if (!x25->neighbour)
  662. goto out_put_route;
  663. x25_limit_facilities(&x25->facilities, x25->neighbour);
  664. x25->lci = x25_new_lci(x25->neighbour);
  665. if (!x25->lci)
  666. goto out_put_neigh;
  667. rc = -EINVAL;
  668. if (sock_flag(sk, SOCK_ZAPPED)) /* Must bind first - autobinding does not work */
  669. goto out_put_neigh;
  670. if (!strcmp(x25->source_addr.x25_addr, null_x25_address.x25_addr))
  671. memset(&x25->source_addr, '\0', X25_ADDR_LEN);
  672. x25->dest_addr = addr->sx25_addr;
  673. /* Move to connecting socket, start sending Connect Requests */
  674. sock->state = SS_CONNECTING;
  675. sk->sk_state = TCP_SYN_SENT;
  676. x25->state = X25_STATE_1;
  677. x25_write_internal(sk, X25_CALL_REQUEST);
  678. x25_start_heartbeat(sk);
  679. x25_start_t21timer(sk);
  680. /* Now the loop */
  681. rc = -EINPROGRESS;
  682. if (sk->sk_state != TCP_ESTABLISHED && (flags & O_NONBLOCK))
  683. goto out_put_neigh;
  684. rc = x25_wait_for_connection_establishment(sk);
  685. if (rc)
  686. goto out_put_neigh;
  687. sock->state = SS_CONNECTED;
  688. rc = 0;
  689. out_put_neigh:
  690. if (rc)
  691. x25_neigh_put(x25->neighbour);
  692. out_put_route:
  693. x25_route_put(rt);
  694. out:
  695. release_sock(sk);
  696. return rc;
  697. }
  698. static int x25_wait_for_data(struct sock *sk, long timeout)
  699. {
  700. DECLARE_WAITQUEUE(wait, current);
  701. int rc = 0;
  702. add_wait_queue_exclusive(sk_sleep(sk), &wait);
  703. for (;;) {
  704. __set_current_state(TASK_INTERRUPTIBLE);
  705. if (sk->sk_shutdown & RCV_SHUTDOWN)
  706. break;
  707. rc = -ERESTARTSYS;
  708. if (signal_pending(current))
  709. break;
  710. rc = -EAGAIN;
  711. if (!timeout)
  712. break;
  713. rc = 0;
  714. if (skb_queue_empty(&sk->sk_receive_queue)) {
  715. release_sock(sk);
  716. timeout = schedule_timeout(timeout);
  717. lock_sock(sk);
  718. } else
  719. break;
  720. }
  721. __set_current_state(TASK_RUNNING);
  722. remove_wait_queue(sk_sleep(sk), &wait);
  723. return rc;
  724. }
  725. static int x25_accept(struct socket *sock, struct socket *newsock, int flags)
  726. {
  727. struct sock *sk = sock->sk;
  728. struct sock *newsk;
  729. struct sk_buff *skb;
  730. int rc = -EINVAL;
  731. if (!sk)
  732. goto out;
  733. rc = -EOPNOTSUPP;
  734. if (sk->sk_type != SOCK_SEQPACKET)
  735. goto out;
  736. lock_sock(sk);
  737. rc = -EINVAL;
  738. if (sk->sk_state != TCP_LISTEN)
  739. goto out2;
  740. rc = x25_wait_for_data(sk, sk->sk_rcvtimeo);
  741. if (rc)
  742. goto out2;
  743. skb = skb_dequeue(&sk->sk_receive_queue);
  744. rc = -EINVAL;
  745. if (!skb->sk)
  746. goto out2;
  747. newsk = skb->sk;
  748. sock_graft(newsk, newsock);
  749. /* Now attach up the new socket */
  750. skb->sk = NULL;
  751. kfree_skb(skb);
  752. sk->sk_ack_backlog--;
  753. newsock->state = SS_CONNECTED;
  754. rc = 0;
  755. out2:
  756. release_sock(sk);
  757. out:
  758. return rc;
  759. }
  760. static int x25_getname(struct socket *sock, struct sockaddr *uaddr,
  761. int *uaddr_len, int peer)
  762. {
  763. struct sockaddr_x25 *sx25 = (struct sockaddr_x25 *)uaddr;
  764. struct sock *sk = sock->sk;
  765. struct x25_sock *x25 = x25_sk(sk);
  766. int rc = 0;
  767. if (peer) {
  768. if (sk->sk_state != TCP_ESTABLISHED) {
  769. rc = -ENOTCONN;
  770. goto out;
  771. }
  772. sx25->sx25_addr = x25->dest_addr;
  773. } else
  774. sx25->sx25_addr = x25->source_addr;
  775. sx25->sx25_family = AF_X25;
  776. *uaddr_len = sizeof(*sx25);
  777. out:
  778. return rc;
  779. }
  780. int x25_rx_call_request(struct sk_buff *skb, struct x25_neigh *nb,
  781. unsigned int lci)
  782. {
  783. struct sock *sk;
  784. struct sock *make;
  785. struct x25_sock *makex25;
  786. struct x25_address source_addr, dest_addr;
  787. struct x25_facilities facilities;
  788. struct x25_dte_facilities dte_facilities;
  789. int len, addr_len, rc;
  790. /*
  791. * Remove the LCI and frame type.
  792. */
  793. skb_pull(skb, X25_STD_MIN_LEN);
  794. /*
  795. * Extract the X.25 addresses and convert them to ASCII strings,
  796. * and remove them.
  797. *
  798. * Address block is mandatory in call request packets
  799. */
  800. addr_len = x25_parse_address_block(skb, &source_addr, &dest_addr);
  801. if (addr_len <= 0)
  802. goto out_clear_request;
  803. skb_pull(skb, addr_len);
  804. /*
  805. * Get the length of the facilities, skip past them for the moment
  806. * get the call user data because this is needed to determine
  807. * the correct listener
  808. *
  809. * Facilities length is mandatory in call request packets
  810. */
  811. if (!pskb_may_pull(skb, 1))
  812. goto out_clear_request;
  813. len = skb->data[0] + 1;
  814. if (!pskb_may_pull(skb, len))
  815. goto out_clear_request;
  816. skb_pull(skb,len);
  817. /*
  818. * Ensure that the amount of call user data is valid.
  819. */
  820. if (skb->len > X25_MAX_CUD_LEN)
  821. goto out_clear_request;
  822. /*
  823. * Get all the call user data so it can be used in
  824. * x25_find_listener and skb_copy_from_linear_data up ahead.
  825. */
  826. if (!pskb_may_pull(skb, skb->len))
  827. goto out_clear_request;
  828. /*
  829. * Find a listener for the particular address/cud pair.
  830. */
  831. sk = x25_find_listener(&source_addr,skb);
  832. skb_push(skb,len);
  833. if (sk != NULL && sk_acceptq_is_full(sk)) {
  834. goto out_sock_put;
  835. }
  836. /*
  837. * We dont have any listeners for this incoming call.
  838. * Try forwarding it.
  839. */
  840. if (sk == NULL) {
  841. skb_push(skb, addr_len + X25_STD_MIN_LEN);
  842. if (sysctl_x25_forward &&
  843. x25_forward_call(&dest_addr, nb, skb, lci) > 0)
  844. {
  845. /* Call was forwarded, dont process it any more */
  846. kfree_skb(skb);
  847. rc = 1;
  848. goto out;
  849. } else {
  850. /* No listeners, can't forward, clear the call */
  851. goto out_clear_request;
  852. }
  853. }
  854. /*
  855. * Try to reach a compromise on the requested facilities.
  856. */
  857. len = x25_negotiate_facilities(skb, sk, &facilities, &dte_facilities);
  858. if (len == -1)
  859. goto out_sock_put;
  860. /*
  861. * current neighbour/link might impose additional limits
  862. * on certain facilties
  863. */
  864. x25_limit_facilities(&facilities, nb);
  865. /*
  866. * Try to create a new socket.
  867. */
  868. make = x25_make_new(sk);
  869. if (!make)
  870. goto out_sock_put;
  871. /*
  872. * Remove the facilities
  873. */
  874. skb_pull(skb, len);
  875. skb->sk = make;
  876. make->sk_state = TCP_ESTABLISHED;
  877. makex25 = x25_sk(make);
  878. makex25->lci = lci;
  879. makex25->dest_addr = dest_addr;
  880. makex25->source_addr = source_addr;
  881. makex25->neighbour = nb;
  882. makex25->facilities = facilities;
  883. makex25->dte_facilities= dte_facilities;
  884. makex25->vc_facil_mask = x25_sk(sk)->vc_facil_mask;
  885. /* ensure no reverse facil on accept */
  886. makex25->vc_facil_mask &= ~X25_MASK_REVERSE;
  887. /* ensure no calling address extension on accept */
  888. makex25->vc_facil_mask &= ~X25_MASK_CALLING_AE;
  889. makex25->cudmatchlength = x25_sk(sk)->cudmatchlength;
  890. /* Normally all calls are accepted immediately */
  891. if (test_bit(X25_ACCPT_APPRV_FLAG, &makex25->flags)) {
  892. x25_write_internal(make, X25_CALL_ACCEPTED);
  893. makex25->state = X25_STATE_3;
  894. }
  895. /*
  896. * Incoming Call User Data.
  897. */
  898. skb_copy_from_linear_data(skb, makex25->calluserdata.cuddata, skb->len);
  899. makex25->calluserdata.cudlength = skb->len;
  900. sk->sk_ack_backlog++;
  901. x25_insert_socket(make);
  902. skb_queue_head(&sk->sk_receive_queue, skb);
  903. x25_start_heartbeat(make);
  904. if (!sock_flag(sk, SOCK_DEAD))
  905. sk->sk_data_ready(sk, skb->len);
  906. rc = 1;
  907. sock_put(sk);
  908. out:
  909. return rc;
  910. out_sock_put:
  911. sock_put(sk);
  912. out_clear_request:
  913. rc = 0;
  914. x25_transmit_clear_request(nb, lci, 0x01);
  915. goto out;
  916. }
  917. static int x25_sendmsg(struct kiocb *iocb, struct socket *sock,
  918. struct msghdr *msg, size_t len)
  919. {
  920. struct sock *sk = sock->sk;
  921. struct x25_sock *x25 = x25_sk(sk);
  922. struct sockaddr_x25 *usx25 = (struct sockaddr_x25 *)msg->msg_name;
  923. struct sockaddr_x25 sx25;
  924. struct sk_buff *skb;
  925. unsigned char *asmptr;
  926. int noblock = msg->msg_flags & MSG_DONTWAIT;
  927. size_t size;
  928. int qbit = 0, rc = -EINVAL;
  929. lock_sock(sk);
  930. if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_OOB|MSG_EOR|MSG_CMSG_COMPAT))
  931. goto out;
  932. /* we currently don't support segmented records at the user interface */
  933. if (!(msg->msg_flags & (MSG_EOR|MSG_OOB)))
  934. goto out;
  935. rc = -EADDRNOTAVAIL;
  936. if (sock_flag(sk, SOCK_ZAPPED))
  937. goto out;
  938. rc = -EPIPE;
  939. if (sk->sk_shutdown & SEND_SHUTDOWN) {
  940. send_sig(SIGPIPE, current, 0);
  941. goto out;
  942. }
  943. rc = -ENETUNREACH;
  944. if (!x25->neighbour)
  945. goto out;
  946. if (usx25) {
  947. rc = -EINVAL;
  948. if (msg->msg_namelen < sizeof(sx25))
  949. goto out;
  950. memcpy(&sx25, usx25, sizeof(sx25));
  951. rc = -EISCONN;
  952. if (strcmp(x25->dest_addr.x25_addr, sx25.sx25_addr.x25_addr))
  953. goto out;
  954. rc = -EINVAL;
  955. if (sx25.sx25_family != AF_X25)
  956. goto out;
  957. } else {
  958. /*
  959. * FIXME 1003.1g - if the socket is like this because
  960. * it has become closed (not started closed) we ought
  961. * to SIGPIPE, EPIPE;
  962. */
  963. rc = -ENOTCONN;
  964. if (sk->sk_state != TCP_ESTABLISHED)
  965. goto out;
  966. sx25.sx25_family = AF_X25;
  967. sx25.sx25_addr = x25->dest_addr;
  968. }
  969. /* Sanity check the packet size */
  970. if (len > 65535) {
  971. rc = -EMSGSIZE;
  972. goto out;
  973. }
  974. SOCK_DEBUG(sk, "x25_sendmsg: sendto: Addresses built.\n");
  975. /* Build a packet */
  976. SOCK_DEBUG(sk, "x25_sendmsg: sendto: building packet.\n");
  977. if ((msg->msg_flags & MSG_OOB) && len > 32)
  978. len = 32;
  979. size = len + X25_MAX_L2_LEN + X25_EXT_MIN_LEN;
  980. release_sock(sk);
  981. skb = sock_alloc_send_skb(sk, size, noblock, &rc);
  982. lock_sock(sk);
  983. if (!skb)
  984. goto out;
  985. X25_SKB_CB(skb)->flags = msg->msg_flags;
  986. skb_reserve(skb, X25_MAX_L2_LEN + X25_EXT_MIN_LEN);
  987. /*
  988. * Put the data on the end
  989. */
  990. SOCK_DEBUG(sk, "x25_sendmsg: Copying user data\n");
  991. skb_reset_transport_header(skb);
  992. skb_put(skb, len);
  993. rc = memcpy_fromiovec(skb_transport_header(skb), msg->msg_iov, len);
  994. if (rc)
  995. goto out_kfree_skb;
  996. /*
  997. * If the Q BIT Include socket option is in force, the first
  998. * byte of the user data is the logical value of the Q Bit.
  999. */
  1000. if (test_bit(X25_Q_BIT_FLAG, &x25->flags)) {
  1001. if (!pskb_may_pull(skb, 1))
  1002. goto out_kfree_skb;
  1003. qbit = skb->data[0];
  1004. skb_pull(skb, 1);
  1005. }
  1006. /*
  1007. * Push down the X.25 header
  1008. */
  1009. SOCK_DEBUG(sk, "x25_sendmsg: Building X.25 Header.\n");
  1010. if (msg->msg_flags & MSG_OOB) {
  1011. if (x25->neighbour->extended) {
  1012. asmptr = skb_push(skb, X25_STD_MIN_LEN);
  1013. *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_EXTSEQ;
  1014. *asmptr++ = (x25->lci >> 0) & 0xFF;
  1015. *asmptr++ = X25_INTERRUPT;
  1016. } else {
  1017. asmptr = skb_push(skb, X25_STD_MIN_LEN);
  1018. *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_STDSEQ;
  1019. *asmptr++ = (x25->lci >> 0) & 0xFF;
  1020. *asmptr++ = X25_INTERRUPT;
  1021. }
  1022. } else {
  1023. if (x25->neighbour->extended) {
  1024. /* Build an Extended X.25 header */
  1025. asmptr = skb_push(skb, X25_EXT_MIN_LEN);
  1026. *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_EXTSEQ;
  1027. *asmptr++ = (x25->lci >> 0) & 0xFF;
  1028. *asmptr++ = X25_DATA;
  1029. *asmptr++ = X25_DATA;
  1030. } else {
  1031. /* Build an Standard X.25 header */
  1032. asmptr = skb_push(skb, X25_STD_MIN_LEN);
  1033. *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_STDSEQ;
  1034. *asmptr++ = (x25->lci >> 0) & 0xFF;
  1035. *asmptr++ = X25_DATA;
  1036. }
  1037. if (qbit)
  1038. skb->data[0] |= X25_Q_BIT;
  1039. }
  1040. SOCK_DEBUG(sk, "x25_sendmsg: Built header.\n");
  1041. SOCK_DEBUG(sk, "x25_sendmsg: Transmitting buffer\n");
  1042. rc = -ENOTCONN;
  1043. if (sk->sk_state != TCP_ESTABLISHED)
  1044. goto out_kfree_skb;
  1045. if (msg->msg_flags & MSG_OOB)
  1046. skb_queue_tail(&x25->interrupt_out_queue, skb);
  1047. else {
  1048. rc = x25_output(sk, skb);
  1049. len = rc;
  1050. if (rc < 0)
  1051. kfree_skb(skb);
  1052. else if (test_bit(X25_Q_BIT_FLAG, &x25->flags))
  1053. len++;
  1054. }
  1055. x25_kick(sk);
  1056. rc = len;
  1057. out:
  1058. release_sock(sk);
  1059. return rc;
  1060. out_kfree_skb:
  1061. kfree_skb(skb);
  1062. goto out;
  1063. }
  1064. static int x25_recvmsg(struct kiocb *iocb, struct socket *sock,
  1065. struct msghdr *msg, size_t size,
  1066. int flags)
  1067. {
  1068. struct sock *sk = sock->sk;
  1069. struct x25_sock *x25 = x25_sk(sk);
  1070. struct sockaddr_x25 *sx25 = (struct sockaddr_x25 *)msg->msg_name;
  1071. size_t copied;
  1072. int qbit, header_len;
  1073. struct sk_buff *skb;
  1074. unsigned char *asmptr;
  1075. int rc = -ENOTCONN;
  1076. lock_sock(sk);
  1077. if (x25->neighbour == NULL)
  1078. goto out;
  1079. header_len = x25->neighbour->extended ?
  1080. X25_EXT_MIN_LEN : X25_STD_MIN_LEN;
  1081. /*
  1082. * This works for seqpacket too. The receiver has ordered the queue for
  1083. * us! We do one quick check first though
  1084. */
  1085. if (sk->sk_state != TCP_ESTABLISHED)
  1086. goto out;
  1087. if (flags & MSG_OOB) {
  1088. rc = -EINVAL;
  1089. if (sock_flag(sk, SOCK_URGINLINE) ||
  1090. !skb_peek(&x25->interrupt_in_queue))
  1091. goto out;
  1092. skb = skb_dequeue(&x25->interrupt_in_queue);
  1093. if (!pskb_may_pull(skb, X25_STD_MIN_LEN))
  1094. goto out_free_dgram;
  1095. skb_pull(skb, X25_STD_MIN_LEN);
  1096. /*
  1097. * No Q bit information on Interrupt data.
  1098. */
  1099. if (test_bit(X25_Q_BIT_FLAG, &x25->flags)) {
  1100. asmptr = skb_push(skb, 1);
  1101. *asmptr = 0x00;
  1102. }
  1103. msg->msg_flags |= MSG_OOB;
  1104. } else {
  1105. /* Now we can treat all alike */
  1106. release_sock(sk);
  1107. skb = skb_recv_datagram(sk, flags & ~MSG_DONTWAIT,
  1108. flags & MSG_DONTWAIT, &rc);
  1109. lock_sock(sk);
  1110. if (!skb)
  1111. goto out;
  1112. if (!pskb_may_pull(skb, header_len))
  1113. goto out_free_dgram;
  1114. qbit = (skb->data[0] & X25_Q_BIT) == X25_Q_BIT;
  1115. skb_pull(skb, header_len);
  1116. if (test_bit(X25_Q_BIT_FLAG, &x25->flags)) {
  1117. asmptr = skb_push(skb, 1);
  1118. *asmptr = qbit;
  1119. }
  1120. }
  1121. skb_reset_transport_header(skb);
  1122. copied = skb->len;
  1123. if (copied > size) {
  1124. copied = size;
  1125. msg->msg_flags |= MSG_TRUNC;
  1126. }
  1127. /* Currently, each datagram always contains a complete record */
  1128. msg->msg_flags |= MSG_EOR;
  1129. rc = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
  1130. if (rc)
  1131. goto out_free_dgram;
  1132. if (sx25) {
  1133. sx25->sx25_family = AF_X25;
  1134. sx25->sx25_addr = x25->dest_addr;
  1135. msg->msg_namelen = sizeof(*sx25);
  1136. }
  1137. x25_check_rbuf(sk);
  1138. rc = copied;
  1139. out_free_dgram:
  1140. skb_free_datagram(sk, skb);
  1141. out:
  1142. release_sock(sk);
  1143. return rc;
  1144. }
  1145. static int x25_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
  1146. {
  1147. struct sock *sk = sock->sk;
  1148. struct x25_sock *x25 = x25_sk(sk);
  1149. void __user *argp = (void __user *)arg;
  1150. int rc;
  1151. switch (cmd) {
  1152. case TIOCOUTQ: {
  1153. int amount;
  1154. amount = sk->sk_sndbuf - sk_wmem_alloc_get(sk);
  1155. if (amount < 0)
  1156. amount = 0;
  1157. rc = put_user(amount, (unsigned int __user *)argp);
  1158. break;
  1159. }
  1160. case TIOCINQ: {
  1161. struct sk_buff *skb;
  1162. int amount = 0;
  1163. /*
  1164. * These two are safe on a single CPU system as
  1165. * only user tasks fiddle here
  1166. */
  1167. lock_sock(sk);
  1168. if ((skb = skb_peek(&sk->sk_receive_queue)) != NULL)
  1169. amount = skb->len;
  1170. release_sock(sk);
  1171. rc = put_user(amount, (unsigned int __user *)argp);
  1172. break;
  1173. }
  1174. case SIOCGSTAMP:
  1175. rc = -EINVAL;
  1176. if (sk)
  1177. rc = sock_get_timestamp(sk,
  1178. (struct timeval __user *)argp);
  1179. break;
  1180. case SIOCGSTAMPNS:
  1181. rc = -EINVAL;
  1182. if (sk)
  1183. rc = sock_get_timestampns(sk,
  1184. (struct timespec __user *)argp);
  1185. break;
  1186. case SIOCGIFADDR:
  1187. case SIOCSIFADDR:
  1188. case SIOCGIFDSTADDR:
  1189. case SIOCSIFDSTADDR:
  1190. case SIOCGIFBRDADDR:
  1191. case SIOCSIFBRDADDR:
  1192. case SIOCGIFNETMASK:
  1193. case SIOCSIFNETMASK:
  1194. case SIOCGIFMETRIC:
  1195. case SIOCSIFMETRIC:
  1196. rc = -EINVAL;
  1197. break;
  1198. case SIOCADDRT:
  1199. case SIOCDELRT:
  1200. rc = -EPERM;
  1201. if (!capable(CAP_NET_ADMIN))
  1202. break;
  1203. rc = x25_route_ioctl(cmd, argp);
  1204. break;
  1205. case SIOCX25GSUBSCRIP:
  1206. rc = x25_subscr_ioctl(cmd, argp);
  1207. break;
  1208. case SIOCX25SSUBSCRIP:
  1209. rc = -EPERM;
  1210. if (!capable(CAP_NET_ADMIN))
  1211. break;
  1212. rc = x25_subscr_ioctl(cmd, argp);
  1213. break;
  1214. case SIOCX25GFACILITIES: {
  1215. lock_sock(sk);
  1216. rc = copy_to_user(argp, &x25->facilities,
  1217. sizeof(x25->facilities))
  1218. ? -EFAULT : 0;
  1219. release_sock(sk);
  1220. break;
  1221. }
  1222. case SIOCX25SFACILITIES: {
  1223. struct x25_facilities facilities;
  1224. rc = -EFAULT;
  1225. if (copy_from_user(&facilities, argp, sizeof(facilities)))
  1226. break;
  1227. rc = -EINVAL;
  1228. lock_sock(sk);
  1229. if (sk->sk_state != TCP_LISTEN &&
  1230. sk->sk_state != TCP_CLOSE)
  1231. goto out_fac_release;
  1232. if (facilities.pacsize_in < X25_PS16 ||
  1233. facilities.pacsize_in > X25_PS4096)
  1234. goto out_fac_release;
  1235. if (facilities.pacsize_out < X25_PS16 ||
  1236. facilities.pacsize_out > X25_PS4096)
  1237. goto out_fac_release;
  1238. if (facilities.winsize_in < 1 ||
  1239. facilities.winsize_in > 127)
  1240. goto out_fac_release;
  1241. if (facilities.throughput) {
  1242. int out = facilities.throughput & 0xf0;
  1243. int in = facilities.throughput & 0x0f;
  1244. if (!out)
  1245. facilities.throughput |=
  1246. X25_DEFAULT_THROUGHPUT << 4;
  1247. else if (out < 0x30 || out > 0xD0)
  1248. goto out_fac_release;
  1249. if (!in)
  1250. facilities.throughput |=
  1251. X25_DEFAULT_THROUGHPUT;
  1252. else if (in < 0x03 || in > 0x0D)
  1253. goto out_fac_release;
  1254. }
  1255. if (facilities.reverse &&
  1256. (facilities.reverse & 0x81) != 0x81)
  1257. goto out_fac_release;
  1258. x25->facilities = facilities;
  1259. rc = 0;
  1260. out_fac_release:
  1261. release_sock(sk);
  1262. break;
  1263. }
  1264. case SIOCX25GDTEFACILITIES: {
  1265. lock_sock(sk);
  1266. rc = copy_to_user(argp, &x25->dte_facilities,
  1267. sizeof(x25->dte_facilities));
  1268. release_sock(sk);
  1269. if (rc)
  1270. rc = -EFAULT;
  1271. break;
  1272. }
  1273. case SIOCX25SDTEFACILITIES: {
  1274. struct x25_dte_facilities dtefacs;
  1275. rc = -EFAULT;
  1276. if (copy_from_user(&dtefacs, argp, sizeof(dtefacs)))
  1277. break;
  1278. rc = -EINVAL;
  1279. lock_sock(sk);
  1280. if (sk->sk_state != TCP_LISTEN &&
  1281. sk->sk_state != TCP_CLOSE)
  1282. goto out_dtefac_release;
  1283. if (dtefacs.calling_len > X25_MAX_AE_LEN)
  1284. goto out_dtefac_release;
  1285. if (dtefacs.calling_ae == NULL)
  1286. goto out_dtefac_release;
  1287. if (dtefacs.called_len > X25_MAX_AE_LEN)
  1288. goto out_dtefac_release;
  1289. if (dtefacs.called_ae == NULL)
  1290. goto out_dtefac_release;
  1291. x25->dte_facilities = dtefacs;
  1292. rc = 0;
  1293. out_dtefac_release:
  1294. release_sock(sk);
  1295. break;
  1296. }
  1297. case SIOCX25GCALLUSERDATA: {
  1298. lock_sock(sk);
  1299. rc = copy_to_user(argp, &x25->calluserdata,
  1300. sizeof(x25->calluserdata))
  1301. ? -EFAULT : 0;
  1302. release_sock(sk);
  1303. break;
  1304. }
  1305. case SIOCX25SCALLUSERDATA: {
  1306. struct x25_calluserdata calluserdata;
  1307. rc = -EFAULT;
  1308. if (copy_from_user(&calluserdata, argp, sizeof(calluserdata)))
  1309. break;
  1310. rc = -EINVAL;
  1311. if (calluserdata.cudlength > X25_MAX_CUD_LEN)
  1312. break;
  1313. lock_sock(sk);
  1314. x25->calluserdata = calluserdata;
  1315. release_sock(sk);
  1316. rc = 0;
  1317. break;
  1318. }
  1319. case SIOCX25GCAUSEDIAG: {
  1320. lock_sock(sk);
  1321. rc = copy_to_user(argp, &x25->causediag, sizeof(x25->causediag))
  1322. ? -EFAULT : 0;
  1323. release_sock(sk);
  1324. break;
  1325. }
  1326. case SIOCX25SCAUSEDIAG: {
  1327. struct x25_causediag causediag;
  1328. rc = -EFAULT;
  1329. if (copy_from_user(&causediag, argp, sizeof(causediag)))
  1330. break;
  1331. lock_sock(sk);
  1332. x25->causediag = causediag;
  1333. release_sock(sk);
  1334. rc = 0;
  1335. break;
  1336. }
  1337. case SIOCX25SCUDMATCHLEN: {
  1338. struct x25_subaddr sub_addr;
  1339. rc = -EINVAL;
  1340. lock_sock(sk);
  1341. if(sk->sk_state != TCP_CLOSE)
  1342. goto out_cud_release;
  1343. rc = -EFAULT;
  1344. if (copy_from_user(&sub_addr, argp,
  1345. sizeof(sub_addr)))
  1346. goto out_cud_release;
  1347. rc = -EINVAL;
  1348. if (sub_addr.cudmatchlength > X25_MAX_CUD_LEN)
  1349. goto out_cud_release;
  1350. x25->cudmatchlength = sub_addr.cudmatchlength;
  1351. rc = 0;
  1352. out_cud_release:
  1353. release_sock(sk);
  1354. break;
  1355. }
  1356. case SIOCX25CALLACCPTAPPRV: {
  1357. rc = -EINVAL;
  1358. lock_sock(sk);
  1359. if (sk->sk_state == TCP_CLOSE) {
  1360. clear_bit(X25_ACCPT_APPRV_FLAG, &x25->flags);
  1361. rc = 0;
  1362. }
  1363. release_sock(sk);
  1364. break;
  1365. }
  1366. case SIOCX25SENDCALLACCPT: {
  1367. rc = -EINVAL;
  1368. lock_sock(sk);
  1369. if (sk->sk_state != TCP_ESTABLISHED)
  1370. goto out_sendcallaccpt_release;
  1371. /* must call accptapprv above */
  1372. if (test_bit(X25_ACCPT_APPRV_FLAG, &x25->flags))
  1373. goto out_sendcallaccpt_release;
  1374. x25_write_internal(sk, X25_CALL_ACCEPTED);
  1375. x25->state = X25_STATE_3;
  1376. rc = 0;
  1377. out_sendcallaccpt_release:
  1378. release_sock(sk);
  1379. break;
  1380. }
  1381. default:
  1382. rc = -ENOIOCTLCMD;
  1383. break;
  1384. }
  1385. return rc;
  1386. }
  1387. static const struct net_proto_family x25_family_ops = {
  1388. .family = AF_X25,
  1389. .create = x25_create,
  1390. .owner = THIS_MODULE,
  1391. };
  1392. #ifdef CONFIG_COMPAT
  1393. static int compat_x25_subscr_ioctl(unsigned int cmd,
  1394. struct compat_x25_subscrip_struct __user *x25_subscr32_actual)
  1395. {
  1396. struct compat_x25_subscrip_struct x25_subscr;
  1397. struct x25_neigh *nb;
  1398. struct net_device *dev;
  1399. int rc = -EINVAL;
  1400. rc = -EFAULT;
  1401. #ifdef KW_TAINT_ANALYSIS
  1402. struct compat_x25_subscrip_struct __user *x25_subscr32 = (struct compat_x25_subscrip_struct __user *)get_tainted_stuff();
  1403. #else
  1404. struct compat_x25_subscrip_struct __user *x25_subscr32 = x25_subscr32_actual;
  1405. #endif
  1406. if (copy_from_user(&x25_subscr, x25_subscr32, sizeof(*x25_subscr32)))
  1407. goto out;
  1408. rc = -EINVAL;
  1409. dev = x25_dev_get(x25_subscr.device);
  1410. if (dev == NULL)
  1411. goto out;
  1412. nb = x25_get_neigh(dev);
  1413. if (nb == NULL)
  1414. goto out_dev_put;
  1415. dev_put(dev);
  1416. if (cmd == SIOCX25GSUBSCRIP) {
  1417. read_lock_bh(&x25_neigh_list_lock);
  1418. x25_subscr.extended = nb->extended;
  1419. x25_subscr.global_facil_mask = nb->global_facil_mask;
  1420. read_unlock_bh(&x25_neigh_list_lock);
  1421. rc = copy_to_user(x25_subscr32, &x25_subscr,
  1422. sizeof(*x25_subscr32)) ? -EFAULT : 0;
  1423. } else {
  1424. rc = -EINVAL;
  1425. if (x25_subscr.extended == 0 || x25_subscr.extended == 1) {
  1426. rc = 0;
  1427. write_lock_bh(&x25_neigh_list_lock);
  1428. nb->extended = x25_subscr.extended;
  1429. nb->global_facil_mask = x25_subscr.global_facil_mask;
  1430. write_unlock_bh(&x25_neigh_list_lock);
  1431. }
  1432. }
  1433. x25_neigh_put(nb);
  1434. out:
  1435. return rc;
  1436. out_dev_put:
  1437. dev_put(dev);
  1438. goto out;
  1439. }
  1440. static int compat_x25_ioctl(struct socket *sock, unsigned int cmd,
  1441. unsigned long arg)
  1442. {
  1443. #ifdef KW_TAINT_ANALYSIS
  1444. void __user *argp = (void __user *)get_tainted_stuff();
  1445. #else
  1446. void __user *argp = compat_ptr(arg);
  1447. #endif
  1448. struct sock *sk = sock->sk;
  1449. int rc = -ENOIOCTLCMD;
  1450. switch(cmd) {
  1451. case TIOCOUTQ:
  1452. case TIOCINQ:
  1453. rc = x25_ioctl(sock, cmd, (unsigned long)argp);
  1454. break;
  1455. case SIOCGSTAMP:
  1456. rc = -EINVAL;
  1457. if (sk)
  1458. rc = compat_sock_get_timestamp(sk,
  1459. (struct timeval __user*)argp);
  1460. break;
  1461. case SIOCGSTAMPNS:
  1462. rc = -EINVAL;
  1463. if (sk)
  1464. rc = compat_sock_get_timestampns(sk,
  1465. (struct timespec __user*)argp);
  1466. break;
  1467. case SIOCGIFADDR:
  1468. case SIOCSIFADDR:
  1469. case SIOCGIFDSTADDR:
  1470. case SIOCSIFDSTADDR:
  1471. case SIOCGIFBRDADDR:
  1472. case SIOCSIFBRDADDR:
  1473. case SIOCGIFNETMASK:
  1474. case SIOCSIFNETMASK:
  1475. case SIOCGIFMETRIC:
  1476. case SIOCSIFMETRIC:
  1477. rc = -EINVAL;
  1478. break;
  1479. case SIOCADDRT:
  1480. case SIOCDELRT:
  1481. rc = -EPERM;
  1482. if (!capable(CAP_NET_ADMIN))
  1483. break;
  1484. rc = x25_route_ioctl(cmd, argp);
  1485. break;
  1486. case SIOCX25GSUBSCRIP:
  1487. rc = compat_x25_subscr_ioctl(cmd, argp);
  1488. break;
  1489. case SIOCX25SSUBSCRIP:
  1490. rc = -EPERM;
  1491. if (!capable(CAP_NET_ADMIN))
  1492. break;
  1493. rc = compat_x25_subscr_ioctl(cmd, argp);
  1494. break;
  1495. case SIOCX25GFACILITIES:
  1496. case SIOCX25SFACILITIES:
  1497. case SIOCX25GDTEFACILITIES:
  1498. case SIOCX25SDTEFACILITIES:
  1499. case SIOCX25GCALLUSERDATA:
  1500. case SIOCX25SCALLUSERDATA:
  1501. case SIOCX25GCAUSEDIAG:
  1502. case SIOCX25SCAUSEDIAG:
  1503. case SIOCX25SCUDMATCHLEN:
  1504. case SIOCX25CALLACCPTAPPRV:
  1505. case SIOCX25SENDCALLACCPT:
  1506. rc = x25_ioctl(sock, cmd, (unsigned long)argp);
  1507. break;
  1508. default:
  1509. rc = -ENOIOCTLCMD;
  1510. break;
  1511. }
  1512. return rc;
  1513. }
  1514. #endif
  1515. static const struct proto_ops x25_proto_ops = {
  1516. .family = AF_X25,
  1517. .owner = THIS_MODULE,
  1518. .release = x25_release,
  1519. .bind = x25_bind,
  1520. .connect = x25_connect,
  1521. .socketpair = sock_no_socketpair,
  1522. .accept = x25_accept,
  1523. .getname = x25_getname,
  1524. .poll = datagram_poll,
  1525. .ioctl = x25_ioctl,
  1526. #ifdef CONFIG_COMPAT
  1527. .compat_ioctl = compat_x25_ioctl,
  1528. #endif
  1529. .listen = x25_listen,
  1530. .shutdown = sock_no_shutdown,
  1531. .setsockopt = x25_setsockopt,
  1532. .getsockopt = x25_getsockopt,
  1533. .sendmsg = x25_sendmsg,
  1534. .recvmsg = x25_recvmsg,
  1535. .mmap = sock_no_mmap,
  1536. .sendpage = sock_no_sendpage,
  1537. };
  1538. static struct packet_type x25_packet_type __read_mostly = {
  1539. .type = cpu_to_be16(ETH_P_X25),
  1540. .func = x25_lapb_receive_frame,
  1541. };
  1542. static struct notifier_block x25_dev_notifier = {
  1543. .notifier_call = x25_device_event,
  1544. };
  1545. void x25_kill_by_neigh(struct x25_neigh *nb)
  1546. {
  1547. struct sock *s;
  1548. struct hlist_node *node;
  1549. write_lock_bh(&x25_list_lock);
  1550. sk_for_each(s, node, &x25_list)
  1551. if (x25_sk(s)->neighbour == nb)
  1552. x25_disconnect(s, ENETUNREACH, 0, 0);
  1553. write_unlock_bh(&x25_list_lock);
  1554. /* Remove any related forwards */
  1555. x25_clear_forward_by_dev(nb->dev);
  1556. }
  1557. static int __init x25_init(void)
  1558. {
  1559. int rc = proto_register(&x25_proto, 0);
  1560. if (rc != 0)
  1561. goto out;
  1562. rc = sock_register(&x25_family_ops);
  1563. if (rc != 0)
  1564. goto out_proto;
  1565. dev_add_pack(&x25_packet_type);
  1566. rc = register_netdevice_notifier(&x25_dev_notifier);
  1567. if (rc != 0)
  1568. goto out_sock;
  1569. printk(KERN_INFO "X.25 for Linux Version 0.2\n");
  1570. x25_register_sysctl();
  1571. rc = x25_proc_init();
  1572. if (rc != 0)
  1573. goto out_dev;
  1574. out:
  1575. return rc;
  1576. out_dev:
  1577. unregister_netdevice_notifier(&x25_dev_notifier);
  1578. out_sock:
  1579. sock_unregister(AF_X25);
  1580. out_proto:
  1581. proto_unregister(&x25_proto);
  1582. goto out;
  1583. }
  1584. module_init(x25_init);
  1585. static void __exit x25_exit(void)
  1586. {
  1587. x25_proc_exit();
  1588. x25_link_free();
  1589. x25_route_free();
  1590. x25_unregister_sysctl();
  1591. unregister_netdevice_notifier(&x25_dev_notifier);
  1592. dev_remove_pack(&x25_packet_type);
  1593. sock_unregister(AF_X25);
  1594. proto_unregister(&x25_proto);
  1595. }
  1596. module_exit(x25_exit);
  1597. MODULE_AUTHOR("Jonathan Naylor <g4klx@g4klx.demon.co.uk>");
  1598. MODULE_DESCRIPTION("The X.25 Packet Layer network layer protocol");
  1599. MODULE_LICENSE("GPL");
  1600. MODULE_ALIAS_NETPROTO(PF_X25);