OSDN Git Service

Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/jkirsher/net...
[uclinux-h8/linux.git] / net / batman-adv / routing.c
1 /* Copyright (C) 2007-2013 B.A.T.M.A.N. contributors:
2  *
3  * Marek Lindner, Simon Wunderlich
4  *
5  * This program is free software; you can redistribute it and/or
6  * modify it under the terms of version 2 of the GNU General Public
7  * License as published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but
10  * WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12  * General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program; if not, see <http://www.gnu.org/licenses/>.
16  */
17
18 #include "main.h"
19 #include "routing.h"
20 #include "send.h"
21 #include "soft-interface.h"
22 #include "hard-interface.h"
23 #include "icmp_socket.h"
24 #include "translation-table.h"
25 #include "originator.h"
26 #include "bridge_loop_avoidance.h"
27 #include "distributed-arp-table.h"
28 #include "network-coding.h"
29 #include "fragmentation.h"
30
31 #include <linux/if_vlan.h>
32
33 static int batadv_route_unicast_packet(struct sk_buff *skb,
34                                        struct batadv_hard_iface *recv_if);
35
36 static void _batadv_update_route(struct batadv_priv *bat_priv,
37                                  struct batadv_orig_node *orig_node,
38                                  struct batadv_neigh_node *neigh_node)
39 {
40         struct batadv_neigh_node *curr_router;
41
42         curr_router = batadv_orig_node_get_router(orig_node);
43
44         /* route deleted */
45         if ((curr_router) && (!neigh_node)) {
46                 batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
47                            "Deleting route towards: %pM\n", orig_node->orig);
48                 batadv_tt_global_del_orig(bat_priv, orig_node, -1,
49                                           "Deleted route towards originator");
50
51         /* route added */
52         } else if ((!curr_router) && (neigh_node)) {
53                 batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
54                            "Adding route towards: %pM (via %pM)\n",
55                            orig_node->orig, neigh_node->addr);
56         /* route changed */
57         } else if (neigh_node && curr_router) {
58                 batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
59                            "Changing route towards: %pM (now via %pM - was via %pM)\n",
60                            orig_node->orig, neigh_node->addr,
61                            curr_router->addr);
62         }
63
64         if (curr_router)
65                 batadv_neigh_node_free_ref(curr_router);
66
67         /* increase refcount of new best neighbor */
68         if (neigh_node && !atomic_inc_not_zero(&neigh_node->refcount))
69                 neigh_node = NULL;
70
71         spin_lock_bh(&orig_node->neigh_list_lock);
72         rcu_assign_pointer(orig_node->router, neigh_node);
73         spin_unlock_bh(&orig_node->neigh_list_lock);
74
75         /* decrease refcount of previous best neighbor */
76         if (curr_router)
77                 batadv_neigh_node_free_ref(curr_router);
78 }
79
80 void batadv_update_route(struct batadv_priv *bat_priv,
81                          struct batadv_orig_node *orig_node,
82                          struct batadv_neigh_node *neigh_node)
83 {
84         struct batadv_neigh_node *router = NULL;
85
86         if (!orig_node)
87                 goto out;
88
89         router = batadv_orig_node_get_router(orig_node);
90
91         if (router != neigh_node)
92                 _batadv_update_route(bat_priv, orig_node, neigh_node);
93
94 out:
95         if (router)
96                 batadv_neigh_node_free_ref(router);
97 }
98
99 /* caller must hold the neigh_list_lock */
100 void batadv_bonding_candidate_del(struct batadv_orig_node *orig_node,
101                                   struct batadv_neigh_node *neigh_node)
102 {
103         /* this neighbor is not part of our candidate list */
104         if (list_empty(&neigh_node->bonding_list))
105                 goto out;
106
107         list_del_rcu(&neigh_node->bonding_list);
108         INIT_LIST_HEAD(&neigh_node->bonding_list);
109         batadv_neigh_node_free_ref(neigh_node);
110         atomic_dec(&orig_node->bond_candidates);
111
112 out:
113         return;
114 }
115
116 /**
117  * batadv_bonding_candidate_add - consider a new link for bonding mode towards
118  *  the given originator
119  * @bat_priv: the bat priv with all the soft interface information
120  * @orig_node: the target node
121  * @neigh_node: the neighbor representing the new link to consider for bonding
122  *  mode
123  */
124 void batadv_bonding_candidate_add(struct batadv_priv *bat_priv,
125                                   struct batadv_orig_node *orig_node,
126                                   struct batadv_neigh_node *neigh_node)
127 {
128         struct batadv_algo_ops *bao = bat_priv->bat_algo_ops;
129         struct batadv_neigh_node *tmp_neigh_node, *router = NULL;
130         uint8_t interference_candidate = 0;
131
132         spin_lock_bh(&orig_node->neigh_list_lock);
133
134         /* only consider if it has the same primary address ...  */
135         if (!batadv_compare_eth(orig_node->orig,
136                                 neigh_node->orig_node->primary_addr))
137                 goto candidate_del;
138
139         router = batadv_orig_node_get_router(orig_node);
140         if (!router)
141                 goto candidate_del;
142
143
144         /* ... and is good enough to be considered */
145         if (bao->bat_neigh_is_equiv_or_better(neigh_node, router))
146                 goto candidate_del;
147
148         /* check if we have another candidate with the same mac address or
149          * interface. If we do, we won't select this candidate because of
150          * possible interference.
151          */
152         hlist_for_each_entry_rcu(tmp_neigh_node,
153                                  &orig_node->neigh_list, list) {
154                 if (tmp_neigh_node == neigh_node)
155                         continue;
156
157                 /* we only care if the other candidate is even
158                  * considered as candidate.
159                  */
160                 if (list_empty(&tmp_neigh_node->bonding_list))
161                         continue;
162
163                 if ((neigh_node->if_incoming == tmp_neigh_node->if_incoming) ||
164                     (batadv_compare_eth(neigh_node->addr,
165                                         tmp_neigh_node->addr))) {
166                         interference_candidate = 1;
167                         break;
168                 }
169         }
170
171         /* don't care further if it is an interference candidate */
172         if (interference_candidate)
173                 goto candidate_del;
174
175         /* this neighbor already is part of our candidate list */
176         if (!list_empty(&neigh_node->bonding_list))
177                 goto out;
178
179         if (!atomic_inc_not_zero(&neigh_node->refcount))
180                 goto out;
181
182         list_add_rcu(&neigh_node->bonding_list, &orig_node->bond_list);
183         atomic_inc(&orig_node->bond_candidates);
184         goto out;
185
186 candidate_del:
187         batadv_bonding_candidate_del(orig_node, neigh_node);
188
189 out:
190         spin_unlock_bh(&orig_node->neigh_list_lock);
191
192         if (router)
193                 batadv_neigh_node_free_ref(router);
194 }
195
196 /* copy primary address for bonding */
197 void
198 batadv_bonding_save_primary(const struct batadv_orig_node *orig_node,
199                             struct batadv_orig_node *orig_neigh_node,
200                             const struct batadv_ogm_packet *batman_ogm_packet)
201 {
202         if (!(batman_ogm_packet->flags & BATADV_PRIMARIES_FIRST_HOP))
203                 return;
204
205         memcpy(orig_neigh_node->primary_addr, orig_node->orig, ETH_ALEN);
206 }
207
208 /* checks whether the host restarted and is in the protection time.
209  * returns:
210  *  0 if the packet is to be accepted
211  *  1 if the packet is to be ignored.
212  */
213 int batadv_window_protected(struct batadv_priv *bat_priv, int32_t seq_num_diff,
214                             unsigned long *last_reset)
215 {
216         if (seq_num_diff <= -BATADV_TQ_LOCAL_WINDOW_SIZE ||
217             seq_num_diff >= BATADV_EXPECTED_SEQNO_RANGE) {
218                 if (!batadv_has_timed_out(*last_reset,
219                                           BATADV_RESET_PROTECTION_MS))
220                         return 1;
221
222                 *last_reset = jiffies;
223                 batadv_dbg(BATADV_DBG_BATMAN, bat_priv,
224                            "old packet received, start protection\n");
225         }
226
227         return 0;
228 }
229
230 bool batadv_check_management_packet(struct sk_buff *skb,
231                                     struct batadv_hard_iface *hard_iface,
232                                     int header_len)
233 {
234         struct ethhdr *ethhdr;
235
236         /* drop packet if it has not necessary minimum size */
237         if (unlikely(!pskb_may_pull(skb, header_len)))
238                 return false;
239
240         ethhdr = eth_hdr(skb);
241
242         /* packet with broadcast indication but unicast recipient */
243         if (!is_broadcast_ether_addr(ethhdr->h_dest))
244                 return false;
245
246         /* packet with broadcast sender address */
247         if (is_broadcast_ether_addr(ethhdr->h_source))
248                 return false;
249
250         /* create a copy of the skb, if needed, to modify it. */
251         if (skb_cow(skb, 0) < 0)
252                 return false;
253
254         /* keep skb linear */
255         if (skb_linearize(skb) < 0)
256                 return false;
257
258         return true;
259 }
260
261 /**
262  * batadv_recv_my_icmp_packet - receive an icmp packet locally
263  * @bat_priv: the bat priv with all the soft interface information
264  * @skb: icmp packet to process
265  *
266  * Returns NET_RX_SUCCESS if the packet has been consumed or NET_RX_DROP
267  * otherwise.
268  */
269 static int batadv_recv_my_icmp_packet(struct batadv_priv *bat_priv,
270                                       struct sk_buff *skb)
271 {
272         struct batadv_hard_iface *primary_if = NULL;
273         struct batadv_orig_node *orig_node = NULL;
274         struct batadv_icmp_header *icmph;
275         int res, ret = NET_RX_DROP;
276
277         icmph = (struct batadv_icmp_header *)skb->data;
278
279         switch (icmph->msg_type) {
280         case BATADV_ECHO_REPLY:
281         case BATADV_DESTINATION_UNREACHABLE:
282         case BATADV_TTL_EXCEEDED:
283                 /* receive the packet */
284                 if (skb_linearize(skb) < 0)
285                         break;
286
287                 batadv_socket_receive_packet(icmph, skb->len);
288                 break;
289         case BATADV_ECHO_REQUEST:
290                 /* answer echo request (ping) */
291                 primary_if = batadv_primary_if_get_selected(bat_priv);
292                 if (!primary_if)
293                         goto out;
294
295                 /* get routing information */
296                 orig_node = batadv_orig_hash_find(bat_priv, icmph->orig);
297                 if (!orig_node)
298                         goto out;
299
300                 /* create a copy of the skb, if needed, to modify it. */
301                 if (skb_cow(skb, ETH_HLEN) < 0)
302                         goto out;
303
304                 icmph = (struct batadv_icmp_header *)skb->data;
305
306                 memcpy(icmph->dst, icmph->orig, ETH_ALEN);
307                 memcpy(icmph->orig, primary_if->net_dev->dev_addr, ETH_ALEN);
308                 icmph->msg_type = BATADV_ECHO_REPLY;
309                 icmph->ttl = BATADV_TTL;
310
311                 res = batadv_send_skb_to_orig(skb, orig_node, NULL);
312                 if (res != NET_XMIT_DROP)
313                         ret = NET_RX_SUCCESS;
314
315                 break;
316         default:
317                 /* drop unknown type */
318                 goto out;
319         }
320 out:
321         if (primary_if)
322                 batadv_hardif_free_ref(primary_if);
323         if (orig_node)
324                 batadv_orig_node_free_ref(orig_node);
325         return ret;
326 }
327
328 static int batadv_recv_icmp_ttl_exceeded(struct batadv_priv *bat_priv,
329                                          struct sk_buff *skb)
330 {
331         struct batadv_hard_iface *primary_if = NULL;
332         struct batadv_orig_node *orig_node = NULL;
333         struct batadv_icmp_packet *icmp_packet;
334         int ret = NET_RX_DROP;
335
336         icmp_packet = (struct batadv_icmp_packet *)skb->data;
337
338         /* send TTL exceeded if packet is an echo request (traceroute) */
339         if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) {
340                 pr_debug("Warning - can't forward icmp packet from %pM to %pM: ttl exceeded\n",
341                          icmp_packet->orig, icmp_packet->dst);
342                 goto out;
343         }
344
345         primary_if = batadv_primary_if_get_selected(bat_priv);
346         if (!primary_if)
347                 goto out;
348
349         /* get routing information */
350         orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig);
351         if (!orig_node)
352                 goto out;
353
354         /* create a copy of the skb, if needed, to modify it. */
355         if (skb_cow(skb, ETH_HLEN) < 0)
356                 goto out;
357
358         icmp_packet = (struct batadv_icmp_packet *)skb->data;
359
360         memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN);
361         memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr,
362                ETH_ALEN);
363         icmp_packet->msg_type = BATADV_TTL_EXCEEDED;
364         icmp_packet->ttl = BATADV_TTL;
365
366         if (batadv_send_skb_to_orig(skb, orig_node, NULL) != NET_XMIT_DROP)
367                 ret = NET_RX_SUCCESS;
368
369 out:
370         if (primary_if)
371                 batadv_hardif_free_ref(primary_if);
372         if (orig_node)
373                 batadv_orig_node_free_ref(orig_node);
374         return ret;
375 }
376
377
378 int batadv_recv_icmp_packet(struct sk_buff *skb,
379                             struct batadv_hard_iface *recv_if)
380 {
381         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
382         struct batadv_icmp_header *icmph;
383         struct batadv_icmp_packet_rr *icmp_packet_rr;
384         struct ethhdr *ethhdr;
385         struct batadv_orig_node *orig_node = NULL;
386         int hdr_size = sizeof(struct batadv_icmp_header);
387         int ret = NET_RX_DROP;
388
389         /* drop packet if it has not necessary minimum size */
390         if (unlikely(!pskb_may_pull(skb, hdr_size)))
391                 goto out;
392
393         ethhdr = eth_hdr(skb);
394
395         /* packet with unicast indication but broadcast recipient */
396         if (is_broadcast_ether_addr(ethhdr->h_dest))
397                 goto out;
398
399         /* packet with broadcast sender address */
400         if (is_broadcast_ether_addr(ethhdr->h_source))
401                 goto out;
402
403         /* not for me */
404         if (!batadv_is_my_mac(bat_priv, ethhdr->h_dest))
405                 goto out;
406
407         icmph = (struct batadv_icmp_header *)skb->data;
408
409         /* add record route information if not full */
410         if ((icmph->msg_type == BATADV_ECHO_REPLY ||
411              icmph->msg_type == BATADV_ECHO_REQUEST) &&
412             (skb->len >= sizeof(struct batadv_icmp_packet_rr))) {
413                 if (skb_linearize(skb) < 0)
414                         goto out;
415
416                 /* create a copy of the skb, if needed, to modify it. */
417                 if (skb_cow(skb, ETH_HLEN) < 0)
418                         goto out;
419
420                 icmph = (struct batadv_icmp_header *)skb->data;
421                 icmp_packet_rr = (struct batadv_icmp_packet_rr *)icmph;
422                 if (icmp_packet_rr->rr_cur >= BATADV_RR_LEN)
423                         goto out;
424
425                 memcpy(&(icmp_packet_rr->rr[icmp_packet_rr->rr_cur]),
426                        ethhdr->h_dest, ETH_ALEN);
427                 icmp_packet_rr->rr_cur++;
428         }
429
430         /* packet for me */
431         if (batadv_is_my_mac(bat_priv, icmph->dst))
432                 return batadv_recv_my_icmp_packet(bat_priv, skb);
433
434         /* TTL exceeded */
435         if (icmph->ttl < 2)
436                 return batadv_recv_icmp_ttl_exceeded(bat_priv, skb);
437
438         /* get routing information */
439         orig_node = batadv_orig_hash_find(bat_priv, icmph->dst);
440         if (!orig_node)
441                 goto out;
442
443         /* create a copy of the skb, if needed, to modify it. */
444         if (skb_cow(skb, ETH_HLEN) < 0)
445                 goto out;
446
447         icmph = (struct batadv_icmp_header *)skb->data;
448
449         /* decrement ttl */
450         icmph->ttl--;
451
452         /* route it */
453         if (batadv_send_skb_to_orig(skb, orig_node, recv_if) != NET_XMIT_DROP)
454                 ret = NET_RX_SUCCESS;
455
456 out:
457         if (orig_node)
458                 batadv_orig_node_free_ref(orig_node);
459         return ret;
460 }
461
462 /* In the bonding case, send the packets in a round
463  * robin fashion over the remaining interfaces.
464  *
465  * This method rotates the bonding list and increases the
466  * returned router's refcount.
467  */
468 static struct batadv_neigh_node *
469 batadv_find_bond_router(struct batadv_orig_node *primary_orig,
470                         const struct batadv_hard_iface *recv_if)
471 {
472         struct batadv_neigh_node *tmp_neigh_node;
473         struct batadv_neigh_node *router = NULL, *first_candidate = NULL;
474
475         rcu_read_lock();
476         list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
477                                 bonding_list) {
478                 if (!first_candidate)
479                         first_candidate = tmp_neigh_node;
480
481                 /* recv_if == NULL on the first node. */
482                 if (tmp_neigh_node->if_incoming == recv_if)
483                         continue;
484
485                 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
486                         continue;
487
488                 router = tmp_neigh_node;
489                 break;
490         }
491
492         /* use the first candidate if nothing was found. */
493         if (!router && first_candidate &&
494             atomic_inc_not_zero(&first_candidate->refcount))
495                 router = first_candidate;
496
497         if (!router)
498                 goto out;
499
500         /* selected should point to the next element
501          * after the current router
502          */
503         spin_lock_bh(&primary_orig->neigh_list_lock);
504         /* this is a list_move(), which unfortunately
505          * does not exist as rcu version
506          */
507         list_del_rcu(&primary_orig->bond_list);
508         list_add_rcu(&primary_orig->bond_list,
509                      &router->bonding_list);
510         spin_unlock_bh(&primary_orig->neigh_list_lock);
511
512 out:
513         rcu_read_unlock();
514         return router;
515 }
516
517 /**
518  * batadv_find_ifalter_router - find the best of the remaining candidates which
519  *  are not using this interface
520  * @bat_priv: the bat priv with all the soft interface information
521  * @primary_orig: the destination
522  * @recv_if: the interface that the router returned by this function has to not
523  *  use
524  *
525  * Returns the best candidate towards primary_orig that is not using recv_if.
526  * Increases the returned neighbor's refcount
527  */
528 static struct batadv_neigh_node *
529 batadv_find_ifalter_router(struct batadv_priv *bat_priv,
530                            struct batadv_orig_node *primary_orig,
531                            const struct batadv_hard_iface *recv_if)
532 {
533         struct batadv_neigh_node *router = NULL, *first_candidate = NULL;
534         struct batadv_algo_ops *bao = bat_priv->bat_algo_ops;
535         struct batadv_neigh_node *tmp_neigh_node;
536
537         rcu_read_lock();
538         list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
539                                 bonding_list) {
540                 if (!first_candidate)
541                         first_candidate = tmp_neigh_node;
542
543                 /* recv_if == NULL on the first node. */
544                 if (tmp_neigh_node->if_incoming == recv_if)
545                         continue;
546
547                 if (router && bao->bat_neigh_cmp(tmp_neigh_node, router))
548                         continue;
549
550                 if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
551                         continue;
552
553                 /* decrement refcount of previously selected router */
554                 if (router)
555                         batadv_neigh_node_free_ref(router);
556
557                 /* we found a better router (or at least one valid router) */
558                 router = tmp_neigh_node;
559         }
560
561         /* use the first candidate if nothing was found. */
562         if (!router && first_candidate &&
563             atomic_inc_not_zero(&first_candidate->refcount))
564                 router = first_candidate;
565
566         rcu_read_unlock();
567         return router;
568 }
569
570 /**
571  * batadv_check_unicast_packet - Check for malformed unicast packets
572  * @bat_priv: the bat priv with all the soft interface information
573  * @skb: packet to check
574  * @hdr_size: size of header to pull
575  *
576  * Check for short header and bad addresses in given packet. Returns negative
577  * value when check fails and 0 otherwise. The negative value depends on the
578  * reason: -ENODATA for bad header, -EBADR for broadcast destination or source,
579  * and -EREMOTE for non-local (other host) destination.
580  */
581 static int batadv_check_unicast_packet(struct batadv_priv *bat_priv,
582                                        struct sk_buff *skb, int hdr_size)
583 {
584         struct ethhdr *ethhdr;
585
586         /* drop packet if it has not necessary minimum size */
587         if (unlikely(!pskb_may_pull(skb, hdr_size)))
588                 return -ENODATA;
589
590         ethhdr = eth_hdr(skb);
591
592         /* packet with unicast indication but broadcast recipient */
593         if (is_broadcast_ether_addr(ethhdr->h_dest))
594                 return -EBADR;
595
596         /* packet with broadcast sender address */
597         if (is_broadcast_ether_addr(ethhdr->h_source))
598                 return -EBADR;
599
600         /* not for me */
601         if (!batadv_is_my_mac(bat_priv, ethhdr->h_dest))
602                 return -EREMOTE;
603
604         return 0;
605 }
606
607 /* find a suitable router for this originator, and use
608  * bonding if possible. increases the found neighbors
609  * refcount.
610  */
611 struct batadv_neigh_node *
612 batadv_find_router(struct batadv_priv *bat_priv,
613                    struct batadv_orig_node *orig_node,
614                    const struct batadv_hard_iface *recv_if)
615 {
616         struct batadv_orig_node *primary_orig_node;
617         struct batadv_orig_node *router_orig;
618         struct batadv_neigh_node *router;
619         static uint8_t zero_mac[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
620         int bonding_enabled;
621         uint8_t *primary_addr;
622
623         if (!orig_node)
624                 return NULL;
625
626         router = batadv_orig_node_get_router(orig_node);
627         if (!router)
628                 goto err;
629
630         /* without bonding, the first node should
631          * always choose the default router.
632          */
633         bonding_enabled = atomic_read(&bat_priv->bonding);
634
635         rcu_read_lock();
636         /* select default router to output */
637         router_orig = router->orig_node;
638         if (!router_orig)
639                 goto err_unlock;
640
641         if ((!recv_if) && (!bonding_enabled))
642                 goto return_router;
643
644         primary_addr = router_orig->primary_addr;
645
646         /* if we have something in the primary_addr, we can search
647          * for a potential bonding candidate.
648          */
649         if (batadv_compare_eth(primary_addr, zero_mac))
650                 goto return_router;
651
652         /* find the orig_node which has the primary interface. might
653          * even be the same as our router_orig in many cases
654          */
655         if (batadv_compare_eth(primary_addr, router_orig->orig)) {
656                 primary_orig_node = router_orig;
657         } else {
658                 primary_orig_node = batadv_orig_hash_find(bat_priv,
659                                                           primary_addr);
660                 if (!primary_orig_node)
661                         goto return_router;
662
663                 batadv_orig_node_free_ref(primary_orig_node);
664         }
665
666         /* with less than 2 candidates, we can't do any
667          * bonding and prefer the original router.
668          */
669         if (atomic_read(&primary_orig_node->bond_candidates) < 2)
670                 goto return_router;
671
672         /* all nodes between should choose a candidate which
673          * is is not on the interface where the packet came
674          * in.
675          */
676         batadv_neigh_node_free_ref(router);
677
678         if (bonding_enabled)
679                 router = batadv_find_bond_router(primary_orig_node, recv_if);
680         else
681                 router = batadv_find_ifalter_router(bat_priv, primary_orig_node,
682                                                     recv_if);
683
684 return_router:
685         if (router && router->if_incoming->if_status != BATADV_IF_ACTIVE)
686                 goto err_unlock;
687
688         rcu_read_unlock();
689         return router;
690 err_unlock:
691         rcu_read_unlock();
692 err:
693         if (router)
694                 batadv_neigh_node_free_ref(router);
695         return NULL;
696 }
697
698 static int batadv_route_unicast_packet(struct sk_buff *skb,
699                                        struct batadv_hard_iface *recv_if)
700 {
701         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
702         struct batadv_orig_node *orig_node = NULL;
703         struct batadv_unicast_packet *unicast_packet;
704         struct ethhdr *ethhdr = eth_hdr(skb);
705         int res, hdr_len, ret = NET_RX_DROP;
706
707         unicast_packet = (struct batadv_unicast_packet *)skb->data;
708
709         /* TTL exceeded */
710         if (unicast_packet->ttl < 2) {
711                 pr_debug("Warning - can't forward unicast packet from %pM to %pM: ttl exceeded\n",
712                          ethhdr->h_source, unicast_packet->dest);
713                 goto out;
714         }
715
716         /* get routing information */
717         orig_node = batadv_orig_hash_find(bat_priv, unicast_packet->dest);
718
719         if (!orig_node)
720                 goto out;
721
722         /* create a copy of the skb, if needed, to modify it. */
723         if (skb_cow(skb, ETH_HLEN) < 0)
724                 goto out;
725
726         /* decrement ttl */
727         unicast_packet = (struct batadv_unicast_packet *)skb->data;
728         unicast_packet->ttl--;
729
730         switch (unicast_packet->packet_type) {
731         case BATADV_UNICAST_4ADDR:
732                 hdr_len = sizeof(struct batadv_unicast_4addr_packet);
733                 break;
734         case BATADV_UNICAST:
735                 hdr_len = sizeof(struct batadv_unicast_packet);
736                 break;
737         default:
738                 /* other packet types not supported - yet */
739                 hdr_len = -1;
740                 break;
741         }
742
743         if (hdr_len > 0)
744                 batadv_skb_set_priority(skb, hdr_len);
745
746         res = batadv_send_skb_to_orig(skb, orig_node, recv_if);
747
748         /* translate transmit result into receive result */
749         if (res == NET_XMIT_SUCCESS) {
750                 /* skb was transmitted and consumed */
751                 batadv_inc_counter(bat_priv, BATADV_CNT_FORWARD);
752                 batadv_add_counter(bat_priv, BATADV_CNT_FORWARD_BYTES,
753                                    skb->len + ETH_HLEN);
754
755                 ret = NET_RX_SUCCESS;
756         } else if (res == NET_XMIT_POLICED) {
757                 /* skb was buffered and consumed */
758                 ret = NET_RX_SUCCESS;
759         }
760
761 out:
762         if (orig_node)
763                 batadv_orig_node_free_ref(orig_node);
764         return ret;
765 }
766
767 /**
768  * batadv_reroute_unicast_packet - update the unicast header for re-routing
769  * @bat_priv: the bat priv with all the soft interface information
770  * @unicast_packet: the unicast header to be updated
771  * @dst_addr: the payload destination
772  * @vid: VLAN identifier
773  *
774  * Search the translation table for dst_addr and update the unicast header with
775  * the new corresponding information (originator address where the destination
776  * client currently is and its known TTVN)
777  *
778  * Returns true if the packet header has been updated, false otherwise
779  */
780 static bool
781 batadv_reroute_unicast_packet(struct batadv_priv *bat_priv,
782                               struct batadv_unicast_packet *unicast_packet,
783                               uint8_t *dst_addr, unsigned short vid)
784 {
785         struct batadv_orig_node *orig_node = NULL;
786         struct batadv_hard_iface *primary_if = NULL;
787         bool ret = false;
788         uint8_t *orig_addr, orig_ttvn;
789
790         if (batadv_is_my_client(bat_priv, dst_addr, vid)) {
791                 primary_if = batadv_primary_if_get_selected(bat_priv);
792                 if (!primary_if)
793                         goto out;
794                 orig_addr = primary_if->net_dev->dev_addr;
795                 orig_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn);
796         } else {
797                 orig_node = batadv_transtable_search(bat_priv, NULL, dst_addr,
798                                                      vid);
799                 if (!orig_node)
800                         goto out;
801
802                 if (batadv_compare_eth(orig_node->orig, unicast_packet->dest))
803                         goto out;
804
805                 orig_addr = orig_node->orig;
806                 orig_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn);
807         }
808
809         /* update the packet header */
810         memcpy(unicast_packet->dest, orig_addr, ETH_ALEN);
811         unicast_packet->ttvn = orig_ttvn;
812
813         ret = true;
814 out:
815         if (primary_if)
816                 batadv_hardif_free_ref(primary_if);
817         if (orig_node)
818                 batadv_orig_node_free_ref(orig_node);
819
820         return ret;
821 }
822
823 static int batadv_check_unicast_ttvn(struct batadv_priv *bat_priv,
824                                      struct sk_buff *skb, int hdr_len) {
825         struct batadv_unicast_packet *unicast_packet;
826         struct batadv_hard_iface *primary_if;
827         struct batadv_orig_node *orig_node;
828         uint8_t curr_ttvn, old_ttvn;
829         struct ethhdr *ethhdr;
830         unsigned short vid;
831         int is_old_ttvn;
832
833         /* check if there is enough data before accessing it */
834         if (pskb_may_pull(skb, hdr_len + ETH_HLEN) < 0)
835                 return 0;
836
837         /* create a copy of the skb (in case of for re-routing) to modify it. */
838         if (skb_cow(skb, sizeof(*unicast_packet)) < 0)
839                 return 0;
840
841         unicast_packet = (struct batadv_unicast_packet *)skb->data;
842         vid = batadv_get_vid(skb, hdr_len);
843         ethhdr = (struct ethhdr *)(skb->data + hdr_len);
844
845         /* check if the destination client was served by this node and it is now
846          * roaming. In this case, it means that the node has got a ROAM_ADV
847          * message and that it knows the new destination in the mesh to re-route
848          * the packet to
849          */
850         if (batadv_tt_local_client_is_roaming(bat_priv, ethhdr->h_dest, vid)) {
851                 if (batadv_reroute_unicast_packet(bat_priv, unicast_packet,
852                                                   ethhdr->h_dest, vid))
853                         net_ratelimited_function(batadv_dbg, BATADV_DBG_TT,
854                                                  bat_priv,
855                                                  "Rerouting unicast packet to %pM (dst=%pM): Local Roaming\n",
856                                                  unicast_packet->dest,
857                                                  ethhdr->h_dest);
858                 /* at this point the mesh destination should have been
859                  * substituted with the originator address found in the global
860                  * table. If not, let the packet go untouched anyway because
861                  * there is nothing the node can do
862                  */
863                 return 1;
864         }
865
866         /* retrieve the TTVN known by this node for the packet destination. This
867          * value is used later to check if the node which sent (or re-routed
868          * last time) the packet had an updated information or not
869          */
870         curr_ttvn = (uint8_t)atomic_read(&bat_priv->tt.vn);
871         if (!batadv_is_my_mac(bat_priv, unicast_packet->dest)) {
872                 orig_node = batadv_orig_hash_find(bat_priv,
873                                                   unicast_packet->dest);
874                 /* if it is not possible to find the orig_node representing the
875                  * destination, the packet can immediately be dropped as it will
876                  * not be possible to deliver it
877                  */
878                 if (!orig_node)
879                         return 0;
880
881                 curr_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn);
882                 batadv_orig_node_free_ref(orig_node);
883         }
884
885         /* check if the TTVN contained in the packet is fresher than what the
886          * node knows
887          */
888         is_old_ttvn = batadv_seq_before(unicast_packet->ttvn, curr_ttvn);
889         if (!is_old_ttvn)
890                 return 1;
891
892         old_ttvn = unicast_packet->ttvn;
893         /* the packet was forged based on outdated network information. Its
894          * destination can possibly be updated and forwarded towards the new
895          * target host
896          */
897         if (batadv_reroute_unicast_packet(bat_priv, unicast_packet,
898                                           ethhdr->h_dest, vid)) {
899                 net_ratelimited_function(batadv_dbg, BATADV_DBG_TT, bat_priv,
900                                          "Rerouting unicast packet to %pM (dst=%pM): TTVN mismatch old_ttvn=%u new_ttvn=%u\n",
901                                          unicast_packet->dest, ethhdr->h_dest,
902                                          old_ttvn, curr_ttvn);
903                 return 1;
904         }
905
906         /* the packet has not been re-routed: either the destination is
907          * currently served by this node or there is no destination at all and
908          * it is possible to drop the packet
909          */
910         if (!batadv_is_my_client(bat_priv, ethhdr->h_dest, vid))
911                 return 0;
912
913         /* update the header in order to let the packet be delivered to this
914          * node's soft interface
915          */
916         primary_if = batadv_primary_if_get_selected(bat_priv);
917         if (!primary_if)
918                 return 0;
919
920         memcpy(unicast_packet->dest, primary_if->net_dev->dev_addr, ETH_ALEN);
921
922         batadv_hardif_free_ref(primary_if);
923
924         unicast_packet->ttvn = curr_ttvn;
925
926         return 1;
927 }
928
929 /**
930  * batadv_recv_unhandled_unicast_packet - receive and process packets which
931  *      are in the unicast number space but not yet known to the implementation
932  * @skb: unicast tvlv packet to process
933  * @recv_if: pointer to interface this packet was received on
934  *
935  * Returns NET_RX_SUCCESS if the packet has been consumed or NET_RX_DROP
936  * otherwise.
937  */
938 int batadv_recv_unhandled_unicast_packet(struct sk_buff *skb,
939                                          struct batadv_hard_iface *recv_if)
940 {
941         struct batadv_unicast_packet *unicast_packet;
942         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
943         int check, hdr_size = sizeof(*unicast_packet);
944
945         check = batadv_check_unicast_packet(bat_priv, skb, hdr_size);
946         if (check < 0)
947                 return NET_RX_DROP;
948
949         /* we don't know about this type, drop it. */
950         unicast_packet = (struct batadv_unicast_packet *)skb->data;
951         if (batadv_is_my_mac(bat_priv, unicast_packet->dest))
952                 return NET_RX_DROP;
953
954         return batadv_route_unicast_packet(skb, recv_if);
955 }
956
957 int batadv_recv_unicast_packet(struct sk_buff *skb,
958                                struct batadv_hard_iface *recv_if)
959 {
960         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
961         struct batadv_unicast_packet *unicast_packet;
962         struct batadv_unicast_4addr_packet *unicast_4addr_packet;
963         uint8_t *orig_addr;
964         struct batadv_orig_node *orig_node = NULL;
965         int check, hdr_size = sizeof(*unicast_packet);
966         bool is4addr;
967
968         unicast_packet = (struct batadv_unicast_packet *)skb->data;
969         unicast_4addr_packet = (struct batadv_unicast_4addr_packet *)skb->data;
970
971         is4addr = unicast_packet->packet_type == BATADV_UNICAST_4ADDR;
972         /* the caller function should have already pulled 2 bytes */
973         if (is4addr)
974                 hdr_size = sizeof(*unicast_4addr_packet);
975
976         /* function returns -EREMOTE for promiscuous packets */
977         check = batadv_check_unicast_packet(bat_priv, skb, hdr_size);
978
979         /* Even though the packet is not for us, we might save it to use for
980          * decoding a later received coded packet
981          */
982         if (check == -EREMOTE)
983                 batadv_nc_skb_store_sniffed_unicast(bat_priv, skb);
984
985         if (check < 0)
986                 return NET_RX_DROP;
987         if (!batadv_check_unicast_ttvn(bat_priv, skb, hdr_size))
988                 return NET_RX_DROP;
989
990         /* packet for me */
991         if (batadv_is_my_mac(bat_priv, unicast_packet->dest)) {
992                 if (is4addr) {
993                         batadv_dat_inc_counter(bat_priv,
994                                                unicast_4addr_packet->subtype);
995                         orig_addr = unicast_4addr_packet->src;
996                         orig_node = batadv_orig_hash_find(bat_priv, orig_addr);
997                 }
998
999                 if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb,
1000                                                           hdr_size))
1001                         goto rx_success;
1002                 if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb,
1003                                                         hdr_size))
1004                         goto rx_success;
1005
1006                 batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size,
1007                                     orig_node);
1008
1009 rx_success:
1010                 if (orig_node)
1011                         batadv_orig_node_free_ref(orig_node);
1012
1013                 return NET_RX_SUCCESS;
1014         }
1015
1016         return batadv_route_unicast_packet(skb, recv_if);
1017 }
1018
1019 /**
1020  * batadv_recv_unicast_tvlv - receive and process unicast tvlv packets
1021  * @skb: unicast tvlv packet to process
1022  * @recv_if: pointer to interface this packet was received on
1023  * @dst_addr: the payload destination
1024  *
1025  * Returns NET_RX_SUCCESS if the packet has been consumed or NET_RX_DROP
1026  * otherwise.
1027  */
1028 int batadv_recv_unicast_tvlv(struct sk_buff *skb,
1029                              struct batadv_hard_iface *recv_if)
1030 {
1031         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1032         struct batadv_unicast_tvlv_packet *unicast_tvlv_packet;
1033         unsigned char *tvlv_buff;
1034         uint16_t tvlv_buff_len;
1035         int hdr_size = sizeof(*unicast_tvlv_packet);
1036         int ret = NET_RX_DROP;
1037
1038         if (batadv_check_unicast_packet(bat_priv, skb, hdr_size) < 0)
1039                 return NET_RX_DROP;
1040
1041         /* the header is likely to be modified while forwarding */
1042         if (skb_cow(skb, hdr_size) < 0)
1043                 return NET_RX_DROP;
1044
1045         /* packet needs to be linearized to access the tvlv content */
1046         if (skb_linearize(skb) < 0)
1047                 return NET_RX_DROP;
1048
1049         unicast_tvlv_packet = (struct batadv_unicast_tvlv_packet *)skb->data;
1050
1051         tvlv_buff = (unsigned char *)(skb->data + hdr_size);
1052         tvlv_buff_len = ntohs(unicast_tvlv_packet->tvlv_len);
1053
1054         if (tvlv_buff_len > skb->len - hdr_size)
1055                 return NET_RX_DROP;
1056
1057         ret = batadv_tvlv_containers_process(bat_priv, false, NULL,
1058                                              unicast_tvlv_packet->src,
1059                                              unicast_tvlv_packet->dst,
1060                                              tvlv_buff, tvlv_buff_len);
1061
1062         if (ret != NET_RX_SUCCESS)
1063                 ret = batadv_route_unicast_packet(skb, recv_if);
1064
1065         return ret;
1066 }
1067
1068 /**
1069  * batadv_recv_frag_packet - process received fragment
1070  * @skb: the received fragment
1071  * @recv_if: interface that the skb is received on
1072  *
1073  * This function does one of the three following things: 1) Forward fragment, if
1074  * the assembled packet will exceed our MTU; 2) Buffer fragment, if we till
1075  * lack further fragments; 3) Merge fragments, if we have all needed parts.
1076  *
1077  * Return NET_RX_DROP if the skb is not consumed, NET_RX_SUCCESS otherwise.
1078  */
1079 int batadv_recv_frag_packet(struct sk_buff *skb,
1080                             struct batadv_hard_iface *recv_if)
1081 {
1082         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1083         struct batadv_orig_node *orig_node_src = NULL;
1084         struct batadv_frag_packet *frag_packet;
1085         int ret = NET_RX_DROP;
1086
1087         if (batadv_check_unicast_packet(bat_priv, skb,
1088                                         sizeof(*frag_packet)) < 0)
1089                 goto out;
1090
1091         frag_packet = (struct batadv_frag_packet *)skb->data;
1092         orig_node_src = batadv_orig_hash_find(bat_priv, frag_packet->orig);
1093         if (!orig_node_src)
1094                 goto out;
1095
1096         /* Route the fragment if it is not for us and too big to be merged. */
1097         if (!batadv_is_my_mac(bat_priv, frag_packet->dest) &&
1098             batadv_frag_skb_fwd(skb, recv_if, orig_node_src)) {
1099                 ret = NET_RX_SUCCESS;
1100                 goto out;
1101         }
1102
1103         batadv_inc_counter(bat_priv, BATADV_CNT_FRAG_RX);
1104         batadv_add_counter(bat_priv, BATADV_CNT_FRAG_RX_BYTES, skb->len);
1105
1106         /* Add fragment to buffer and merge if possible. */
1107         if (!batadv_frag_skb_buffer(&skb, orig_node_src))
1108                 goto out;
1109
1110         /* Deliver merged packet to the appropriate handler, if it was
1111          * merged
1112          */
1113         if (skb)
1114                 batadv_batman_skb_recv(skb, recv_if->net_dev,
1115                                        &recv_if->batman_adv_ptype, NULL);
1116
1117         ret = NET_RX_SUCCESS;
1118
1119 out:
1120         if (orig_node_src)
1121                 batadv_orig_node_free_ref(orig_node_src);
1122
1123         return ret;
1124 }
1125
1126 int batadv_recv_bcast_packet(struct sk_buff *skb,
1127                              struct batadv_hard_iface *recv_if)
1128 {
1129         struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1130         struct batadv_orig_node *orig_node = NULL;
1131         struct batadv_bcast_packet *bcast_packet;
1132         struct ethhdr *ethhdr;
1133         int hdr_size = sizeof(*bcast_packet);
1134         int ret = NET_RX_DROP;
1135         int32_t seq_diff;
1136         uint32_t seqno;
1137
1138         /* drop packet if it has not necessary minimum size */
1139         if (unlikely(!pskb_may_pull(skb, hdr_size)))
1140                 goto out;
1141
1142         ethhdr = eth_hdr(skb);
1143
1144         /* packet with broadcast indication but unicast recipient */
1145         if (!is_broadcast_ether_addr(ethhdr->h_dest))
1146                 goto out;
1147
1148         /* packet with broadcast sender address */
1149         if (is_broadcast_ether_addr(ethhdr->h_source))
1150                 goto out;
1151
1152         /* ignore broadcasts sent by myself */
1153         if (batadv_is_my_mac(bat_priv, ethhdr->h_source))
1154                 goto out;
1155
1156         bcast_packet = (struct batadv_bcast_packet *)skb->data;
1157
1158         /* ignore broadcasts originated by myself */
1159         if (batadv_is_my_mac(bat_priv, bcast_packet->orig))
1160                 goto out;
1161
1162         if (bcast_packet->ttl < 2)
1163                 goto out;
1164
1165         orig_node = batadv_orig_hash_find(bat_priv, bcast_packet->orig);
1166
1167         if (!orig_node)
1168                 goto out;
1169
1170         spin_lock_bh(&orig_node->bcast_seqno_lock);
1171
1172         seqno = ntohl(bcast_packet->seqno);
1173         /* check whether the packet is a duplicate */
1174         if (batadv_test_bit(orig_node->bcast_bits, orig_node->last_bcast_seqno,
1175                             seqno))
1176                 goto spin_unlock;
1177
1178         seq_diff = seqno - orig_node->last_bcast_seqno;
1179
1180         /* check whether the packet is old and the host just restarted. */
1181         if (batadv_window_protected(bat_priv, seq_diff,
1182                                     &orig_node->bcast_seqno_reset))
1183                 goto spin_unlock;
1184
1185         /* mark broadcast in flood history, update window position
1186          * if required.
1187          */
1188         if (batadv_bit_get_packet(bat_priv, orig_node->bcast_bits, seq_diff, 1))
1189                 orig_node->last_bcast_seqno = seqno;
1190
1191         spin_unlock_bh(&orig_node->bcast_seqno_lock);
1192
1193         /* check whether this has been sent by another originator before */
1194         if (batadv_bla_check_bcast_duplist(bat_priv, skb))
1195                 goto out;
1196
1197         batadv_skb_set_priority(skb, sizeof(struct batadv_bcast_packet));
1198
1199         /* rebroadcast packet */
1200         batadv_add_bcast_packet_to_list(bat_priv, skb, 1);
1201
1202         /* don't hand the broadcast up if it is from an originator
1203          * from the same backbone.
1204          */
1205         if (batadv_bla_is_backbone_gw(skb, orig_node, hdr_size))
1206                 goto out;
1207
1208         if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb, hdr_size))
1209                 goto rx_success;
1210         if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb, hdr_size))
1211                 goto rx_success;
1212
1213         /* broadcast for me */
1214         batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size,
1215                             orig_node);
1216
1217 rx_success:
1218         ret = NET_RX_SUCCESS;
1219         goto out;
1220
1221 spin_unlock:
1222         spin_unlock_bh(&orig_node->bcast_seqno_lock);
1223 out:
1224         if (orig_node)
1225                 batadv_orig_node_free_ref(orig_node);
1226         return ret;
1227 }