1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3 * Spanning tree protocol; BPDU handling
4 * Linux ethernet bridge
5 *
6 * Authors:
7 * Lennert Buytenhek <buytenh@gnu.org>
8 */
9
10 #include <linux/kernel.h>
11 #include <linux/netfilter_bridge.h>
12 #include <linux/etherdevice.h>
13 #include <linux/llc.h>
14 #include <linux/slab.h>
15 #include <linux/pkt_sched.h>
16 #include <net/net_namespace.h>
17 #include <net/llc.h>
18 #include <net/llc_pdu.h>
19 #include <net/stp.h>
20 #include <linux/unaligned.h>
21
22 #include "br_private.h"
23 #include "br_private_stp.h"
24
25 #define STP_HZ 256
26
27 #define LLC_RESERVE sizeof(struct llc_pdu_un)
28
br_send_bpdu_finish(struct net * net,struct sock * sk,struct sk_buff * skb)29 static int br_send_bpdu_finish(struct net *net, struct sock *sk,
30 struct sk_buff *skb)
31 {
32 return dev_queue_xmit(skb);
33 }
34
br_send_bpdu(struct net_bridge_port * p,const unsigned char * data,int length)35 static void br_send_bpdu(struct net_bridge_port *p,
36 const unsigned char *data, int length)
37 {
38 struct sk_buff *skb;
39
40 skb = dev_alloc_skb(length+LLC_RESERVE);
41 if (!skb)
42 return;
43
44 skb->dev = p->dev;
45 skb->protocol = htons(ETH_P_802_2);
46 skb->priority = TC_PRIO_CONTROL;
47
48 skb_reserve(skb, LLC_RESERVE);
49 __skb_put_data(skb, data, length);
50
51 llc_pdu_header_init(skb, LLC_PDU_TYPE_U, LLC_SAP_BSPAN,
52 LLC_SAP_BSPAN, LLC_PDU_CMD);
53 llc_pdu_init_as_ui_cmd(skb);
54
55 if (llc_mac_hdr_init(skb, p->dev->dev_addr, p->br->group_addr)) {
56 kfree_skb(skb);
57 return;
58 }
59
60 skb_reset_mac_header(skb);
61
62 NF_HOOK(NFPROTO_BRIDGE, NF_BR_LOCAL_OUT,
63 dev_net(p->dev), NULL, skb, NULL, skb->dev,
64 br_send_bpdu_finish);
65 }
66
br_set_ticks(unsigned char * dest,int j)67 static inline void br_set_ticks(unsigned char *dest, int j)
68 {
69 unsigned long ticks = (STP_HZ * j)/ HZ;
70
71 put_unaligned_be16(ticks, dest);
72 }
73
br_get_ticks(const unsigned char * src)74 static inline int br_get_ticks(const unsigned char *src)
75 {
76 unsigned long ticks = get_unaligned_be16(src);
77
78 return DIV_ROUND_UP(ticks * HZ, STP_HZ);
79 }
80
81 /* called under bridge lock */
br_send_config_bpdu(struct net_bridge_port * p,struct br_config_bpdu * bpdu)82 void br_send_config_bpdu(struct net_bridge_port *p, struct br_config_bpdu *bpdu)
83 {
84 unsigned char buf[35];
85
86 if (p->br->stp_enabled != BR_KERNEL_STP)
87 return;
88
89 buf[0] = 0;
90 buf[1] = 0;
91 buf[2] = 0;
92 buf[3] = BPDU_TYPE_CONFIG;
93 buf[4] = (bpdu->topology_change ? 0x01 : 0) |
94 (bpdu->topology_change_ack ? 0x80 : 0);
95 buf[5] = bpdu->root.prio[0];
96 buf[6] = bpdu->root.prio[1];
97 buf[7] = bpdu->root.addr[0];
98 buf[8] = bpdu->root.addr[1];
99 buf[9] = bpdu->root.addr[2];
100 buf[10] = bpdu->root.addr[3];
101 buf[11] = bpdu->root.addr[4];
102 buf[12] = bpdu->root.addr[5];
103 buf[13] = (bpdu->root_path_cost >> 24) & 0xFF;
104 buf[14] = (bpdu->root_path_cost >> 16) & 0xFF;
105 buf[15] = (bpdu->root_path_cost >> 8) & 0xFF;
106 buf[16] = bpdu->root_path_cost & 0xFF;
107 buf[17] = bpdu->bridge_id.prio[0];
108 buf[18] = bpdu->bridge_id.prio[1];
109 buf[19] = bpdu->bridge_id.addr[0];
110 buf[20] = bpdu->bridge_id.addr[1];
111 buf[21] = bpdu->bridge_id.addr[2];
112 buf[22] = bpdu->bridge_id.addr[3];
113 buf[23] = bpdu->bridge_id.addr[4];
114 buf[24] = bpdu->bridge_id.addr[5];
115 buf[25] = (bpdu->port_id >> 8) & 0xFF;
116 buf[26] = bpdu->port_id & 0xFF;
117
118 br_set_ticks(buf+27, bpdu->message_age);
119 br_set_ticks(buf+29, bpdu->max_age);
120 br_set_ticks(buf+31, bpdu->hello_time);
121 br_set_ticks(buf+33, bpdu->forward_delay);
122
123 br_send_bpdu(p, buf, 35);
124
125 p->stp_xstats.tx_bpdu++;
126 }
127
128 /* called under bridge lock */
br_send_tcn_bpdu(struct net_bridge_port * p)129 void br_send_tcn_bpdu(struct net_bridge_port *p)
130 {
131 unsigned char buf[4];
132
133 if (p->br->stp_enabled != BR_KERNEL_STP)
134 return;
135
136 buf[0] = 0;
137 buf[1] = 0;
138 buf[2] = 0;
139 buf[3] = BPDU_TYPE_TCN;
140 br_send_bpdu(p, buf, 4);
141
142 p->stp_xstats.tx_tcn++;
143 }
144
145 /*
146 * Called from llc.
147 *
148 * NO locks, but rcu_read_lock
149 */
br_stp_rcv(const struct stp_proto * proto,struct sk_buff * skb,struct net_device * dev)150 void br_stp_rcv(const struct stp_proto *proto, struct sk_buff *skb,
151 struct net_device *dev)
152 {
153 struct net_bridge_port *p;
154 struct net_bridge *br;
155 const unsigned char *buf;
156
157 if (!pskb_may_pull(skb, 4))
158 goto err;
159
160 /* compare of protocol id and version */
161 buf = skb->data;
162 if (buf[0] != 0 || buf[1] != 0 || buf[2] != 0)
163 goto err;
164
165 p = br_port_get_check_rcu(dev);
166 if (!p)
167 goto err;
168
169 br = p->br;
170 spin_lock(&br->lock);
171
172 if (br->stp_enabled != BR_KERNEL_STP)
173 goto out;
174
175 if (!(br->dev->flags & IFF_UP))
176 goto out;
177
178 if (p->state == BR_STATE_DISABLED)
179 goto out;
180
181 if (!ether_addr_equal(eth_hdr(skb)->h_dest, br->group_addr))
182 goto out;
183
184 if (test_bit(BR_BPDU_GUARD_BIT, &p->flags)) {
185 br_notice(br, "BPDU received on blocked port %u(%s)\n",
186 (unsigned int) p->port_no, p->dev->name);
187 br_stp_disable_port(p);
188 goto out;
189 }
190
191 buf = skb_pull(skb, 3);
192
193 if (buf[0] == BPDU_TYPE_CONFIG) {
194 struct br_config_bpdu bpdu;
195
196 if (!pskb_may_pull(skb, 32))
197 goto out;
198
199 buf = skb->data;
200 bpdu.topology_change = (buf[1] & 0x01) ? 1 : 0;
201 bpdu.topology_change_ack = (buf[1] & 0x80) ? 1 : 0;
202
203 bpdu.root.prio[0] = buf[2];
204 bpdu.root.prio[1] = buf[3];
205 bpdu.root.addr[0] = buf[4];
206 bpdu.root.addr[1] = buf[5];
207 bpdu.root.addr[2] = buf[6];
208 bpdu.root.addr[3] = buf[7];
209 bpdu.root.addr[4] = buf[8];
210 bpdu.root.addr[5] = buf[9];
211 bpdu.root_path_cost =
212 (buf[10] << 24) |
213 (buf[11] << 16) |
214 (buf[12] << 8) |
215 buf[13];
216 bpdu.bridge_id.prio[0] = buf[14];
217 bpdu.bridge_id.prio[1] = buf[15];
218 bpdu.bridge_id.addr[0] = buf[16];
219 bpdu.bridge_id.addr[1] = buf[17];
220 bpdu.bridge_id.addr[2] = buf[18];
221 bpdu.bridge_id.addr[3] = buf[19];
222 bpdu.bridge_id.addr[4] = buf[20];
223 bpdu.bridge_id.addr[5] = buf[21];
224 bpdu.port_id = (buf[22] << 8) | buf[23];
225
226 bpdu.message_age = br_get_ticks(buf+24);
227 bpdu.max_age = br_get_ticks(buf+26);
228 bpdu.hello_time = br_get_ticks(buf+28);
229 bpdu.forward_delay = br_get_ticks(buf+30);
230
231 if (bpdu.message_age > bpdu.max_age) {
232 if (net_ratelimit())
233 br_notice(p->br,
234 "port %u config from %pM"
235 " (message_age %ul > max_age %ul)\n",
236 p->port_no,
237 eth_hdr(skb)->h_source,
238 bpdu.message_age, bpdu.max_age);
239 goto out;
240 }
241
242 br_received_config_bpdu(p, &bpdu);
243 } else if (buf[0] == BPDU_TYPE_TCN) {
244 br_received_tcn_bpdu(p);
245 }
246 out:
247 spin_unlock(&br->lock);
248 err:
249 kfree_skb(skb);
250 }
251