1 // SPDX-License-Identifier: GPL-2.0-only 2 /* 3 * Copyright (c) 2008, 2009 open80211s Ltd. 4 * Copyright (C) 2023 Intel Corporation 5 * Author: Luis Carlos Cobo <luisca@cozybit.com> 6 */ 7 8 #include <linux/etherdevice.h> 9 #include <linux/list.h> 10 #include <linux/random.h> 11 #include <linux/slab.h> 12 #include <linux/spinlock.h> 13 #include <linux/string.h> 14 #include <net/mac80211.h> 15 #include "wme.h" 16 #include "ieee80211_i.h" 17 #include "mesh.h" 18 #include <linux/rhashtable.h> 19 20 static void mesh_path_free_rcu(struct mesh_table *tbl, struct mesh_path *mpath); 21 22 static u32 mesh_table_hash(const void *addr, u32 len, u32 seed) 23 { 24 /* Use last four bytes of hw addr as hash index */ 25 return jhash_1word(get_unaligned((u32 *)((u8 *)addr + 2)), seed); 26 } 27 28 static const struct rhashtable_params mesh_rht_params = { 29 .nelem_hint = 2, 30 .automatic_shrinking = true, 31 .key_len = ETH_ALEN, 32 .key_offset = offsetof(struct mesh_path, dst), 33 .head_offset = offsetof(struct mesh_path, rhash), 34 .hashfn = mesh_table_hash, 35 }; 36 37 static const struct rhashtable_params fast_tx_rht_params = { 38 .nelem_hint = 10, 39 .automatic_shrinking = true, 40 .key_len = sizeof_field(struct ieee80211_mesh_fast_tx, key), 41 .key_offset = offsetof(struct ieee80211_mesh_fast_tx, key), 42 .head_offset = offsetof(struct ieee80211_mesh_fast_tx, rhash), 43 .hashfn = mesh_table_hash, 44 }; 45 46 static void __mesh_fast_tx_entry_free(void *ptr, void *tblptr) 47 { 48 struct ieee80211_mesh_fast_tx *entry = ptr; 49 50 kfree_rcu(entry, fast_tx.rcu_head); 51 } 52 53 static void mesh_fast_tx_deinit(struct ieee80211_sub_if_data *sdata) 54 { 55 struct mesh_tx_cache *cache; 56 57 cache = &sdata->u.mesh.tx_cache; 58 rhashtable_free_and_destroy(&cache->rht, 59 __mesh_fast_tx_entry_free, NULL); 60 } 61 62 static void mesh_fast_tx_init(struct ieee80211_sub_if_data *sdata) 63 { 64 struct mesh_tx_cache *cache; 65 66 cache = &sdata->u.mesh.tx_cache; 67 rhashtable_init(&cache->rht, &fast_tx_rht_params); 68 INIT_HLIST_HEAD(&cache->walk_head); 69 spin_lock_init(&cache->walk_lock); 70 } 71 72 static inline bool mpath_expired(struct mesh_path *mpath) 73 { 74 return (mpath->flags & MESH_PATH_ACTIVE) && 75 time_after(jiffies, mpath->exp_time) && 76 !(mpath->flags & MESH_PATH_FIXED); 77 } 78 79 static void mesh_path_rht_free(void *ptr, void *tblptr) 80 { 81 struct mesh_path *mpath = ptr; 82 struct mesh_table *tbl = tblptr; 83 84 mesh_path_free_rcu(tbl, mpath); 85 } 86 87 static void mesh_table_init(struct mesh_table *tbl) 88 { 89 INIT_HLIST_HEAD(&tbl->known_gates); 90 INIT_HLIST_HEAD(&tbl->walk_head); 91 atomic_set(&tbl->entries, 0); 92 spin_lock_init(&tbl->gates_lock); 93 spin_lock_init(&tbl->walk_lock); 94 95 /* rhashtable_init() may fail only in case of wrong 96 * mesh_rht_params 97 */ 98 WARN_ON(rhashtable_init(&tbl->rhead, &mesh_rht_params)); 99 } 100 101 static void mesh_table_free(struct mesh_table *tbl) 102 { 103 rhashtable_free_and_destroy(&tbl->rhead, 104 mesh_path_rht_free, tbl); 105 } 106 107 /** 108 * mesh_path_assign_nexthop - update mesh path next hop 109 * 110 * @mpath: mesh path to update 111 * @sta: next hop to assign 112 * 113 * Locking: mpath->state_lock must be held when calling this function 114 */ 115 void mesh_path_assign_nexthop(struct mesh_path *mpath, struct sta_info *sta) 116 { 117 struct sk_buff *skb; 118 struct ieee80211_hdr *hdr; 119 unsigned long flags; 120 121 rcu_assign_pointer(mpath->next_hop, sta); 122 123 spin_lock_irqsave(&mpath->frame_queue.lock, flags); 124 skb_queue_walk(&mpath->frame_queue, skb) { 125 hdr = (struct ieee80211_hdr *) skb->data; 126 memcpy(hdr->addr1, sta->sta.addr, ETH_ALEN); 127 memcpy(hdr->addr2, mpath->sdata->vif.addr, ETH_ALEN); 128 ieee80211_mps_set_frame_flags(sta->sdata, sta, hdr); 129 } 130 131 spin_unlock_irqrestore(&mpath->frame_queue.lock, flags); 132 } 133 134 static void prepare_for_gate(struct sk_buff *skb, char *dst_addr, 135 struct mesh_path *gate_mpath) 136 { 137 struct ieee80211_hdr *hdr; 138 struct ieee80211s_hdr *mshdr; 139 int mesh_hdrlen, hdrlen; 140 char *next_hop; 141 142 hdr = (struct ieee80211_hdr *) skb->data; 143 hdrlen = ieee80211_hdrlen(hdr->frame_control); 144 mshdr = (struct ieee80211s_hdr *) (skb->data + hdrlen); 145 146 if (!(mshdr->flags & MESH_FLAGS_AE)) { 147 /* size of the fixed part of the mesh header */ 148 mesh_hdrlen = 6; 149 150 /* make room for the two extended addresses */ 151 skb_push(skb, 2 * ETH_ALEN); 152 memmove(skb->data, hdr, hdrlen + mesh_hdrlen); 153 154 hdr = (struct ieee80211_hdr *) skb->data; 155 156 /* we preserve the previous mesh header and only add 157 * the new addresses */ 158 mshdr = (struct ieee80211s_hdr *) (skb->data + hdrlen); 159 mshdr->flags = MESH_FLAGS_AE_A5_A6; 160 memcpy(mshdr->eaddr1, hdr->addr3, ETH_ALEN); 161 memcpy(mshdr->eaddr2, hdr->addr4, ETH_ALEN); 162 } 163 164 /* update next hop */ 165 hdr = (struct ieee80211_hdr *) skb->data; 166 rcu_read_lock(); 167 next_hop = rcu_dereference(gate_mpath->next_hop)->sta.addr; 168 memcpy(hdr->addr1, next_hop, ETH_ALEN); 169 rcu_read_unlock(); 170 memcpy(hdr->addr2, gate_mpath->sdata->vif.addr, ETH_ALEN); 171 memcpy(hdr->addr3, dst_addr, ETH_ALEN); 172 } 173 174 /** 175 * mesh_path_move_to_queue - Move or copy frames from one mpath queue to another 176 * 177 * @gate_mpath: An active mpath the frames will be sent to (i.e. the gate) 178 * @from_mpath: The failed mpath 179 * @copy: When true, copy all the frames to the new mpath queue. When false, 180 * move them. 181 * 182 * This function is used to transfer or copy frames from an unresolved mpath to 183 * a gate mpath. The function also adds the Address Extension field and 184 * updates the next hop. 185 * 186 * If a frame already has an Address Extension field, only the next hop and 187 * destination addresses are updated. 188 * 189 * The gate mpath must be an active mpath with a valid mpath->next_hop. 190 */ 191 static void mesh_path_move_to_queue(struct mesh_path *gate_mpath, 192 struct mesh_path *from_mpath, 193 bool copy) 194 { 195 struct sk_buff *skb, *fskb, *tmp; 196 struct sk_buff_head failq; 197 unsigned long flags; 198 199 if (WARN_ON(gate_mpath == from_mpath)) 200 return; 201 if (WARN_ON(!gate_mpath->next_hop)) 202 return; 203 204 __skb_queue_head_init(&failq); 205 206 spin_lock_irqsave(&from_mpath->frame_queue.lock, flags); 207 skb_queue_splice_init(&from_mpath->frame_queue, &failq); 208 spin_unlock_irqrestore(&from_mpath->frame_queue.lock, flags); 209 210 skb_queue_walk_safe(&failq, fskb, tmp) { 211 if (skb_queue_len(&gate_mpath->frame_queue) >= 212 MESH_FRAME_QUEUE_LEN) { 213 mpath_dbg(gate_mpath->sdata, "mpath queue full!\n"); 214 break; 215 } 216 217 skb = skb_copy(fskb, GFP_ATOMIC); 218 if (WARN_ON(!skb)) 219 break; 220 221 prepare_for_gate(skb, gate_mpath->dst, gate_mpath); 222 skb_queue_tail(&gate_mpath->frame_queue, skb); 223 224 if (copy) 225 continue; 226 227 __skb_unlink(fskb, &failq); 228 kfree_skb(fskb); 229 } 230 231 mpath_dbg(gate_mpath->sdata, "Mpath queue for gate %pM has %d frames\n", 232 gate_mpath->dst, skb_queue_len(&gate_mpath->frame_queue)); 233 234 if (!copy) 235 return; 236 237 spin_lock_irqsave(&from_mpath->frame_queue.lock, flags); 238 skb_queue_splice(&failq, &from_mpath->frame_queue); 239 spin_unlock_irqrestore(&from_mpath->frame_queue.lock, flags); 240 } 241 242 243 static struct mesh_path *mpath_lookup(struct mesh_table *tbl, const u8 *dst, 244 struct ieee80211_sub_if_data *sdata) 245 { 246 struct mesh_path *mpath; 247 248 mpath = rhashtable_lookup(&tbl->rhead, dst, mesh_rht_params); 249 250 if (mpath && mpath_expired(mpath)) { 251 spin_lock_bh(&mpath->state_lock); 252 mpath->flags &= ~MESH_PATH_ACTIVE; 253 spin_unlock_bh(&mpath->state_lock); 254 } 255 return mpath; 256 } 257 258 /** 259 * mesh_path_lookup - look up a path in the mesh path table 260 * @sdata: local subif 261 * @dst: hardware address (ETH_ALEN length) of destination 262 * 263 * Returns: pointer to the mesh path structure, or NULL if not found 264 * 265 * Locking: must be called within a read rcu section. 266 */ 267 struct mesh_path * 268 mesh_path_lookup(struct ieee80211_sub_if_data *sdata, const u8 *dst) 269 { 270 return mpath_lookup(&sdata->u.mesh.mesh_paths, dst, sdata); 271 } 272 273 struct mesh_path * 274 mpp_path_lookup(struct ieee80211_sub_if_data *sdata, const u8 *dst) 275 { 276 return mpath_lookup(&sdata->u.mesh.mpp_paths, dst, sdata); 277 } 278 279 static struct mesh_path * 280 __mesh_path_lookup_by_idx(struct mesh_table *tbl, int idx) 281 { 282 int i = 0; 283 struct mesh_path *mpath; 284 285 hlist_for_each_entry_rcu(mpath, &tbl->walk_head, walk_list) { 286 if (i++ == idx) 287 break; 288 } 289 290 if (!mpath) 291 return NULL; 292 293 if (mpath_expired(mpath)) { 294 spin_lock_bh(&mpath->state_lock); 295 mpath->flags &= ~MESH_PATH_ACTIVE; 296 spin_unlock_bh(&mpath->state_lock); 297 } 298 return mpath; 299 } 300 301 /** 302 * mesh_path_lookup_by_idx - look up a path in the mesh path table by its index 303 * @sdata: local subif, or NULL for all entries 304 * @idx: index 305 * 306 * Returns: pointer to the mesh path structure, or NULL if not found. 307 * 308 * Locking: must be called within a read rcu section. 309 */ 310 struct mesh_path * 311 mesh_path_lookup_by_idx(struct ieee80211_sub_if_data *sdata, int idx) 312 { 313 return __mesh_path_lookup_by_idx(&sdata->u.mesh.mesh_paths, idx); 314 } 315 316 /** 317 * mpp_path_lookup_by_idx - look up a path in the proxy path table by its index 318 * @sdata: local subif, or NULL for all entries 319 * @idx: index 320 * 321 * Returns: pointer to the proxy path structure, or NULL if not found. 322 * 323 * Locking: must be called within a read rcu section. 324 */ 325 struct mesh_path * 326 mpp_path_lookup_by_idx(struct ieee80211_sub_if_data *sdata, int idx) 327 { 328 return __mesh_path_lookup_by_idx(&sdata->u.mesh.mpp_paths, idx); 329 } 330 331 /** 332 * mesh_path_add_gate - add the given mpath to a mesh gate to our path table 333 * @mpath: gate path to add to table 334 * 335 * Returns: 0 on success, -EEXIST 336 */ 337 int mesh_path_add_gate(struct mesh_path *mpath) 338 { 339 struct mesh_table *tbl; 340 int err; 341 342 rcu_read_lock(); 343 tbl = &mpath->sdata->u.mesh.mesh_paths; 344 345 spin_lock_bh(&mpath->state_lock); 346 if (mpath->is_gate) { 347 err = -EEXIST; 348 spin_unlock_bh(&mpath->state_lock); 349 goto err_rcu; 350 } 351 mpath->is_gate = true; 352 mpath->sdata->u.mesh.num_gates++; 353 354 spin_lock(&tbl->gates_lock); 355 hlist_add_head_rcu(&mpath->gate_list, &tbl->known_gates); 356 spin_unlock(&tbl->gates_lock); 357 358 spin_unlock_bh(&mpath->state_lock); 359 360 mpath_dbg(mpath->sdata, 361 "Mesh path: Recorded new gate: %pM. %d known gates\n", 362 mpath->dst, mpath->sdata->u.mesh.num_gates); 363 err = 0; 364 err_rcu: 365 rcu_read_unlock(); 366 return err; 367 } 368 369 /** 370 * mesh_gate_del - remove a mesh gate from the list of known gates 371 * @tbl: table which holds our list of known gates 372 * @mpath: gate mpath 373 */ 374 static void mesh_gate_del(struct mesh_table *tbl, struct mesh_path *mpath) 375 { 376 lockdep_assert_held(&mpath->state_lock); 377 if (!mpath->is_gate) 378 return; 379 380 mpath->is_gate = false; 381 spin_lock_bh(&tbl->gates_lock); 382 hlist_del_rcu(&mpath->gate_list); 383 mpath->sdata->u.mesh.num_gates--; 384 spin_unlock_bh(&tbl->gates_lock); 385 386 mpath_dbg(mpath->sdata, 387 "Mesh path: Deleted gate: %pM. %d known gates\n", 388 mpath->dst, mpath->sdata->u.mesh.num_gates); 389 } 390 391 /** 392 * mesh_gate_num - number of gates known to this interface 393 * @sdata: subif data 394 * 395 * Returns: The number of gates 396 */ 397 int mesh_gate_num(struct ieee80211_sub_if_data *sdata) 398 { 399 return sdata->u.mesh.num_gates; 400 } 401 402 static 403 struct mesh_path *mesh_path_new(struct ieee80211_sub_if_data *sdata, 404 const u8 *dst, gfp_t gfp_flags) 405 { 406 struct mesh_path *new_mpath; 407 408 new_mpath = kzalloc_obj(struct mesh_path, gfp_flags); 409 if (!new_mpath) 410 return NULL; 411 412 memcpy(new_mpath->dst, dst, ETH_ALEN); 413 eth_broadcast_addr(new_mpath->rann_snd_addr); 414 new_mpath->is_root = false; 415 new_mpath->sdata = sdata; 416 new_mpath->flags = 0; 417 skb_queue_head_init(&new_mpath->frame_queue); 418 new_mpath->exp_time = jiffies; 419 spin_lock_init(&new_mpath->state_lock); 420 timer_setup(&new_mpath->timer, mesh_path_timer, 0); 421 422 return new_mpath; 423 } 424 425 static void mesh_fast_tx_entry_free(struct mesh_tx_cache *cache, 426 struct ieee80211_mesh_fast_tx *entry) 427 { 428 hlist_del_rcu(&entry->walk_list); 429 rhashtable_remove_fast(&cache->rht, &entry->rhash, fast_tx_rht_params); 430 kfree_rcu(entry, fast_tx.rcu_head); 431 } 432 433 struct ieee80211_mesh_fast_tx * 434 mesh_fast_tx_get(struct ieee80211_sub_if_data *sdata, 435 struct ieee80211_mesh_fast_tx_key *key) 436 { 437 struct ieee80211_mesh_fast_tx *entry; 438 struct mesh_tx_cache *cache; 439 440 cache = &sdata->u.mesh.tx_cache; 441 entry = rhashtable_lookup(&cache->rht, key, fast_tx_rht_params); 442 if (!entry) 443 return NULL; 444 445 if (!(entry->mpath->flags & MESH_PATH_ACTIVE) || 446 mpath_expired(entry->mpath)) { 447 spin_lock_bh(&cache->walk_lock); 448 entry = rhashtable_lookup(&cache->rht, key, fast_tx_rht_params); 449 if (entry) 450 mesh_fast_tx_entry_free(cache, entry); 451 spin_unlock_bh(&cache->walk_lock); 452 return NULL; 453 } 454 455 mesh_path_refresh(sdata, entry->mpath, NULL); 456 if (entry->mppath) 457 entry->mppath->exp_time = jiffies; 458 entry->timestamp = jiffies; 459 460 return entry; 461 } 462 463 void mesh_fast_tx_cache(struct ieee80211_sub_if_data *sdata, 464 struct sk_buff *skb, struct mesh_path *mpath) 465 { 466 struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data; 467 struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb); 468 struct ieee80211_mesh_fast_tx *entry, *prev; 469 struct ieee80211_mesh_fast_tx build = {}; 470 struct ieee80211s_hdr *meshhdr; 471 struct mesh_tx_cache *cache; 472 struct ieee80211_key *key; 473 struct mesh_path *mppath; 474 struct sta_info *sta; 475 u8 *qc; 476 477 if (sdata->noack_map || 478 !ieee80211_is_data_qos(hdr->frame_control)) 479 return; 480 481 build.fast_tx.hdr_len = ieee80211_hdrlen(hdr->frame_control); 482 meshhdr = (struct ieee80211s_hdr *)(skb->data + build.fast_tx.hdr_len); 483 build.hdrlen = ieee80211_get_mesh_hdrlen(meshhdr); 484 485 cache = &sdata->u.mesh.tx_cache; 486 if (atomic_read(&cache->rht.nelems) >= MESH_FAST_TX_CACHE_MAX_SIZE) 487 return; 488 489 sta = rcu_dereference(mpath->next_hop); 490 if (!sta) 491 return; 492 493 build.key.type = MESH_FAST_TX_TYPE_LOCAL; 494 if ((meshhdr->flags & MESH_FLAGS_AE) == MESH_FLAGS_AE_A5_A6) { 495 /* This is required to keep the mppath alive */ 496 mppath = mpp_path_lookup(sdata, meshhdr->eaddr1); 497 if (!mppath) 498 return; 499 build.mppath = mppath; 500 if (!ether_addr_equal(meshhdr->eaddr2, sdata->vif.addr)) 501 build.key.type = MESH_FAST_TX_TYPE_PROXIED; 502 } else if (ieee80211_has_a4(hdr->frame_control)) { 503 mppath = mpath; 504 } else { 505 return; 506 } 507 508 if (!ether_addr_equal(hdr->addr4, sdata->vif.addr)) 509 build.key.type = MESH_FAST_TX_TYPE_FORWARDED; 510 511 /* rate limit, in case fast xmit can't be enabled */ 512 if (mppath->fast_tx_check == jiffies) 513 return; 514 515 mppath->fast_tx_check = jiffies; 516 517 /* 518 * Same use of the sta lock as in ieee80211_check_fast_xmit, in order 519 * to protect against concurrent sta key updates. 520 */ 521 spin_lock_bh(&sta->lock); 522 key = rcu_access_pointer(sta->ptk[sta->ptk_idx]); 523 if (!key) 524 key = rcu_access_pointer(sdata->default_unicast_key); 525 build.fast_tx.key = key; 526 527 if (key) { 528 bool gen_iv, iv_spc; 529 530 gen_iv = key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_IV; 531 iv_spc = key->conf.flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE; 532 533 if (!(key->flags & KEY_FLAG_UPLOADED_TO_HARDWARE) || 534 (key->flags & KEY_FLAG_TAINTED)) 535 goto unlock_sta; 536 537 switch (key->conf.cipher) { 538 case WLAN_CIPHER_SUITE_CCMP: 539 case WLAN_CIPHER_SUITE_CCMP_256: 540 if (gen_iv) 541 build.fast_tx.pn_offs = build.fast_tx.hdr_len; 542 if (gen_iv || iv_spc) 543 build.fast_tx.hdr_len += IEEE80211_CCMP_HDR_LEN; 544 break; 545 case WLAN_CIPHER_SUITE_GCMP: 546 case WLAN_CIPHER_SUITE_GCMP_256: 547 if (gen_iv) 548 build.fast_tx.pn_offs = build.fast_tx.hdr_len; 549 if (gen_iv || iv_spc) 550 build.fast_tx.hdr_len += IEEE80211_GCMP_HDR_LEN; 551 break; 552 default: 553 goto unlock_sta; 554 } 555 } 556 557 memcpy(build.key.addr, mppath->dst, ETH_ALEN); 558 build.timestamp = jiffies; 559 build.fast_tx.band = info->band; 560 build.fast_tx.da_offs = offsetof(struct ieee80211_hdr, addr3); 561 build.fast_tx.sa_offs = offsetof(struct ieee80211_hdr, addr4); 562 build.mpath = mpath; 563 memcpy(build.hdr, meshhdr, build.hdrlen); 564 memcpy(build.hdr + build.hdrlen, rfc1042_header, sizeof(rfc1042_header)); 565 build.hdrlen += sizeof(rfc1042_header); 566 memcpy(build.fast_tx.hdr, hdr, build.fast_tx.hdr_len); 567 568 hdr = (struct ieee80211_hdr *)build.fast_tx.hdr; 569 if (build.fast_tx.key) 570 hdr->frame_control |= cpu_to_le16(IEEE80211_FCTL_PROTECTED); 571 572 qc = ieee80211_get_qos_ctl(hdr); 573 qc[1] |= IEEE80211_QOS_CTL_MESH_CONTROL_PRESENT >> 8; 574 575 entry = kmemdup(&build, sizeof(build), GFP_ATOMIC); 576 if (!entry) 577 goto unlock_sta; 578 579 spin_lock(&cache->walk_lock); 580 if ((READ_ONCE(mpath->flags) & MESH_PATH_DELETED) || 581 (mppath && (READ_ONCE(mppath->flags) & MESH_PATH_DELETED))) { 582 kfree(entry); 583 goto unlock_cache; 584 } 585 586 prev = rhashtable_lookup_get_insert_fast(&cache->rht, 587 &entry->rhash, 588 fast_tx_rht_params); 589 if (IS_ERR(prev)) { 590 kfree(entry); 591 goto unlock_cache; 592 } 593 594 /* 595 * replace any previous entry in the hash table, in case we're 596 * replacing it with a different type (e.g. mpath -> mpp) 597 */ 598 if (unlikely(prev)) { 599 rhashtable_replace_fast(&cache->rht, &prev->rhash, 600 &entry->rhash, fast_tx_rht_params); 601 hlist_del_rcu(&prev->walk_list); 602 kfree_rcu(prev, fast_tx.rcu_head); 603 } 604 605 hlist_add_head(&entry->walk_list, &cache->walk_head); 606 607 unlock_cache: 608 spin_unlock(&cache->walk_lock); 609 unlock_sta: 610 spin_unlock_bh(&sta->lock); 611 } 612 613 void mesh_fast_tx_gc(struct ieee80211_sub_if_data *sdata) 614 { 615 unsigned long timeout = msecs_to_jiffies(MESH_FAST_TX_CACHE_TIMEOUT); 616 struct mesh_tx_cache *cache = &sdata->u.mesh.tx_cache; 617 struct ieee80211_mesh_fast_tx *entry; 618 struct hlist_node *n; 619 620 if (atomic_read(&cache->rht.nelems) < MESH_FAST_TX_CACHE_THRESHOLD_SIZE) 621 return; 622 623 spin_lock_bh(&cache->walk_lock); 624 hlist_for_each_entry_safe(entry, n, &cache->walk_head, walk_list) 625 if (!time_is_after_jiffies(entry->timestamp + timeout)) 626 mesh_fast_tx_entry_free(cache, entry); 627 spin_unlock_bh(&cache->walk_lock); 628 } 629 630 void mesh_fast_tx_flush_mpath(struct mesh_path *mpath) 631 { 632 struct ieee80211_sub_if_data *sdata = mpath->sdata; 633 struct mesh_tx_cache *cache = &sdata->u.mesh.tx_cache; 634 struct ieee80211_mesh_fast_tx *entry; 635 struct hlist_node *n; 636 637 spin_lock_bh(&cache->walk_lock); 638 hlist_for_each_entry_safe(entry, n, &cache->walk_head, walk_list) 639 if (entry->mpath == mpath) 640 mesh_fast_tx_entry_free(cache, entry); 641 spin_unlock_bh(&cache->walk_lock); 642 } 643 644 void mesh_fast_tx_flush_sta(struct ieee80211_sub_if_data *sdata, 645 struct sta_info *sta) 646 { 647 struct mesh_tx_cache *cache = &sdata->u.mesh.tx_cache; 648 struct ieee80211_mesh_fast_tx *entry; 649 struct hlist_node *n; 650 651 spin_lock_bh(&cache->walk_lock); 652 hlist_for_each_entry_safe(entry, n, &cache->walk_head, walk_list) 653 if (rcu_access_pointer(entry->mpath->next_hop) == sta) 654 mesh_fast_tx_entry_free(cache, entry); 655 spin_unlock_bh(&cache->walk_lock); 656 } 657 658 void mesh_fast_tx_flush_addr(struct ieee80211_sub_if_data *sdata, 659 const u8 *addr) 660 { 661 struct mesh_tx_cache *cache = &sdata->u.mesh.tx_cache; 662 struct ieee80211_mesh_fast_tx_key key = {}; 663 struct ieee80211_mesh_fast_tx *entry; 664 int i; 665 666 ether_addr_copy(key.addr, addr); 667 spin_lock_bh(&cache->walk_lock); 668 for (i = 0; i < NUM_MESH_FAST_TX_TYPE; i++) { 669 key.type = i; 670 entry = rhashtable_lookup_fast(&cache->rht, &key, fast_tx_rht_params); 671 if (entry) 672 mesh_fast_tx_entry_free(cache, entry); 673 } 674 spin_unlock_bh(&cache->walk_lock); 675 } 676 677 /** 678 * mesh_path_add - allocate and add a new path to the mesh path table 679 * @sdata: local subif 680 * @dst: destination address of the path (ETH_ALEN length) 681 * 682 * Returns: 0 on success 683 * 684 * State: the initial state of the new path is set to 0 685 */ 686 struct mesh_path *mesh_path_add(struct ieee80211_sub_if_data *sdata, 687 const u8 *dst) 688 { 689 struct mesh_table *tbl; 690 struct mesh_path *mpath, *new_mpath; 691 692 if (ether_addr_equal(dst, sdata->vif.addr)) 693 /* never add ourselves as neighbours */ 694 return ERR_PTR(-EOPNOTSUPP); 695 696 if (is_multicast_ether_addr(dst)) 697 return ERR_PTR(-EOPNOTSUPP); 698 699 if (atomic_add_unless(&sdata->u.mesh.mpaths, 1, MESH_MAX_MPATHS) == 0) 700 return ERR_PTR(-ENOSPC); 701 702 new_mpath = mesh_path_new(sdata, dst, GFP_ATOMIC); 703 if (!new_mpath) { 704 atomic_dec(&sdata->u.mesh.mpaths); 705 return ERR_PTR(-ENOMEM); 706 } 707 708 tbl = &sdata->u.mesh.mesh_paths; 709 spin_lock_bh(&tbl->walk_lock); 710 mpath = rhashtable_lookup_get_insert_fast(&tbl->rhead, 711 &new_mpath->rhash, 712 mesh_rht_params); 713 if (!mpath) 714 hlist_add_head(&new_mpath->walk_list, &tbl->walk_head); 715 spin_unlock_bh(&tbl->walk_lock); 716 717 if (mpath) { 718 kfree(new_mpath); 719 atomic_dec(&sdata->u.mesh.mpaths); 720 721 if (IS_ERR(mpath)) 722 return mpath; 723 724 new_mpath = mpath; 725 } 726 727 sdata->u.mesh.mesh_paths_generation++; 728 return new_mpath; 729 } 730 731 int mpp_path_add(struct ieee80211_sub_if_data *sdata, 732 const u8 *dst, const u8 *mpp) 733 { 734 struct mesh_table *tbl; 735 struct mesh_path *new_mpath; 736 int ret; 737 738 if (ether_addr_equal(dst, sdata->vif.addr)) 739 /* never add ourselves as neighbours */ 740 return -EOPNOTSUPP; 741 742 if (is_multicast_ether_addr(dst)) 743 return -EOPNOTSUPP; 744 745 if (!atomic_add_unless(&sdata->u.mesh.mpaths, 1, MESH_MAX_MPATHS)) 746 return -ENOSPC; 747 748 new_mpath = mesh_path_new(sdata, dst, GFP_ATOMIC); 749 750 if (!new_mpath) { 751 atomic_dec(&sdata->u.mesh.mpaths); 752 return -ENOMEM; 753 } 754 755 memcpy(new_mpath->mpp, mpp, ETH_ALEN); 756 tbl = &sdata->u.mesh.mpp_paths; 757 758 spin_lock_bh(&tbl->walk_lock); 759 ret = rhashtable_lookup_insert_fast(&tbl->rhead, 760 &new_mpath->rhash, 761 mesh_rht_params); 762 if (!ret) 763 hlist_add_head_rcu(&new_mpath->walk_list, &tbl->walk_head); 764 spin_unlock_bh(&tbl->walk_lock); 765 766 if (ret) { 767 kfree(new_mpath); 768 atomic_dec(&sdata->u.mesh.mpaths); 769 } else { 770 mesh_fast_tx_flush_addr(sdata, dst); 771 } 772 773 sdata->u.mesh.mpp_paths_generation++; 774 return ret; 775 } 776 777 778 /** 779 * mesh_plink_broken - deactivates paths and sends perr when a link breaks 780 * 781 * @sta: broken peer link 782 * 783 * This function must be called from the rate control algorithm if enough 784 * delivery errors suggest that a peer link is no longer usable. 785 */ 786 void mesh_plink_broken(struct sta_info *sta) 787 { 788 struct ieee80211_sub_if_data *sdata = sta->sdata; 789 struct mesh_table *tbl = &sdata->u.mesh.mesh_paths; 790 static const u8 bcast[ETH_ALEN] = {0xff, 0xff, 0xff, 0xff, 0xff, 0xff}; 791 struct mesh_path *mpath; 792 793 rcu_read_lock(); 794 hlist_for_each_entry_rcu(mpath, &tbl->walk_head, walk_list) { 795 if (rcu_access_pointer(mpath->next_hop) == sta && 796 mpath->flags & MESH_PATH_ACTIVE && 797 !(mpath->flags & MESH_PATH_FIXED)) { 798 spin_lock_bh(&mpath->state_lock); 799 mpath->flags &= ~MESH_PATH_ACTIVE; 800 ++mpath->sn; 801 spin_unlock_bh(&mpath->state_lock); 802 mesh_path_error_tx(sdata, 803 sdata->u.mesh.mshcfg.element_ttl, 804 mpath->dst, mpath->sn, 805 WLAN_REASON_MESH_PATH_DEST_UNREACHABLE, bcast); 806 } 807 } 808 rcu_read_unlock(); 809 } 810 811 static void mesh_path_free_rcu(struct mesh_table *tbl, 812 struct mesh_path *mpath) 813 { 814 struct ieee80211_sub_if_data *sdata = mpath->sdata; 815 816 spin_lock_bh(&mpath->state_lock); 817 WRITE_ONCE(mpath->flags, 818 mpath->flags | MESH_PATH_RESOLVING | MESH_PATH_DELETED); 819 mesh_gate_del(tbl, mpath); 820 spin_unlock_bh(&mpath->state_lock); 821 timer_shutdown_sync(&mpath->timer); 822 atomic_dec(&sdata->u.mesh.mpaths); 823 atomic_dec(&tbl->entries); 824 mesh_path_flush_pending(mpath); 825 kfree_rcu(mpath, rcu); 826 } 827 828 static void __mesh_path_del(struct mesh_table *tbl, struct mesh_path *mpath) 829 { 830 hlist_del_rcu(&mpath->walk_list); 831 rhashtable_remove_fast(&tbl->rhead, &mpath->rhash, mesh_rht_params); 832 spin_lock_bh(&mpath->state_lock); 833 WRITE_ONCE(mpath->flags, mpath->flags | MESH_PATH_DELETED); 834 spin_unlock_bh(&mpath->state_lock); 835 if (tbl == &mpath->sdata->u.mesh.mpp_paths) 836 mesh_fast_tx_flush_addr(mpath->sdata, mpath->dst); 837 else 838 mesh_fast_tx_flush_mpath(mpath); 839 mesh_path_free_rcu(tbl, mpath); 840 } 841 842 /** 843 * mesh_path_flush_by_nexthop - Deletes mesh paths if their next hop matches 844 * 845 * @sta: mesh peer to match 846 * 847 * RCU notes: this function is called when a mesh plink transitions from 848 * PLINK_ESTAB to any other state, since PLINK_ESTAB state is the only one that 849 * allows path creation. This will happen before the sta can be freed (because 850 * sta_info_destroy() calls this) so any reader in a rcu read block will be 851 * protected against the plink disappearing. 852 */ 853 void mesh_path_flush_by_nexthop(struct sta_info *sta) 854 { 855 struct ieee80211_sub_if_data *sdata = sta->sdata; 856 struct mesh_table *tbl = &sdata->u.mesh.mesh_paths; 857 struct mesh_path *mpath; 858 struct hlist_node *n; 859 860 spin_lock_bh(&tbl->walk_lock); 861 hlist_for_each_entry_safe(mpath, n, &tbl->walk_head, walk_list) { 862 if (rcu_access_pointer(mpath->next_hop) == sta) 863 __mesh_path_del(tbl, mpath); 864 } 865 spin_unlock_bh(&tbl->walk_lock); 866 } 867 868 static void mpp_flush_by_proxy(struct ieee80211_sub_if_data *sdata, 869 const u8 *proxy) 870 { 871 struct mesh_table *tbl = &sdata->u.mesh.mpp_paths; 872 struct mesh_path *mpath; 873 struct hlist_node *n; 874 875 spin_lock_bh(&tbl->walk_lock); 876 hlist_for_each_entry_safe(mpath, n, &tbl->walk_head, walk_list) { 877 if (ether_addr_equal(mpath->mpp, proxy)) 878 __mesh_path_del(tbl, mpath); 879 } 880 spin_unlock_bh(&tbl->walk_lock); 881 } 882 883 static void table_flush_by_iface(struct mesh_table *tbl) 884 { 885 struct mesh_path *mpath; 886 struct hlist_node *n; 887 888 spin_lock_bh(&tbl->walk_lock); 889 hlist_for_each_entry_safe(mpath, n, &tbl->walk_head, walk_list) { 890 __mesh_path_del(tbl, mpath); 891 } 892 spin_unlock_bh(&tbl->walk_lock); 893 } 894 895 /** 896 * mesh_path_flush_by_iface - Deletes all mesh paths associated with a given iface 897 * 898 * @sdata: interface data to match 899 * 900 * This function deletes both mesh paths as well as mesh portal paths. 901 */ 902 void mesh_path_flush_by_iface(struct ieee80211_sub_if_data *sdata) 903 { 904 table_flush_by_iface(&sdata->u.mesh.mesh_paths); 905 table_flush_by_iface(&sdata->u.mesh.mpp_paths); 906 } 907 908 /** 909 * table_path_del - delete a path from the mesh or mpp table 910 * 911 * @tbl: mesh or mpp path table 912 * @sdata: local subif 913 * @addr: dst address (ETH_ALEN length) 914 * 915 * Returns: 0 if successful 916 */ 917 static int table_path_del(struct mesh_table *tbl, 918 struct ieee80211_sub_if_data *sdata, 919 const u8 *addr) 920 { 921 struct mesh_path *mpath; 922 923 spin_lock_bh(&tbl->walk_lock); 924 mpath = rhashtable_lookup_fast(&tbl->rhead, addr, mesh_rht_params); 925 if (!mpath) { 926 spin_unlock_bh(&tbl->walk_lock); 927 return -ENXIO; 928 } 929 930 __mesh_path_del(tbl, mpath); 931 spin_unlock_bh(&tbl->walk_lock); 932 return 0; 933 } 934 935 936 /** 937 * mesh_path_del - delete a mesh path from the table 938 * 939 * @sdata: local subif 940 * @addr: dst address (ETH_ALEN length) 941 * 942 * Returns: 0 if successful 943 */ 944 int mesh_path_del(struct ieee80211_sub_if_data *sdata, const u8 *addr) 945 { 946 int err; 947 948 /* flush relevant mpp entries first */ 949 mpp_flush_by_proxy(sdata, addr); 950 951 err = table_path_del(&sdata->u.mesh.mesh_paths, sdata, addr); 952 sdata->u.mesh.mesh_paths_generation++; 953 return err; 954 } 955 956 /** 957 * mesh_path_tx_pending - sends pending frames in a mesh path queue 958 * 959 * @mpath: mesh path to activate 960 * 961 * Locking: the state_lock of the mpath structure must NOT be held when calling 962 * this function. 963 */ 964 void mesh_path_tx_pending(struct mesh_path *mpath) 965 { 966 if (mpath->flags & MESH_PATH_ACTIVE) 967 ieee80211_add_pending_skbs(mpath->sdata->local, 968 &mpath->frame_queue); 969 } 970 971 /** 972 * mesh_path_send_to_gates - sends pending frames to all known mesh gates 973 * 974 * @mpath: mesh path whose queue will be emptied 975 * 976 * If there is only one gate, the frames are transferred from the failed mpath 977 * queue to that gate's queue. If there are more than one gates, the frames 978 * are copied from each gate to the next. After frames are copied, the 979 * mpath queues are emptied onto the transmission queue. 980 * 981 * Returns: 0 on success, -EHOSTUNREACH 982 */ 983 int mesh_path_send_to_gates(struct mesh_path *mpath) 984 { 985 struct ieee80211_sub_if_data *sdata = mpath->sdata; 986 struct mesh_table *tbl; 987 struct mesh_path *from_mpath = mpath; 988 struct mesh_path *gate; 989 bool copy = false; 990 991 tbl = &sdata->u.mesh.mesh_paths; 992 993 rcu_read_lock(); 994 hlist_for_each_entry_rcu(gate, &tbl->known_gates, gate_list) { 995 if (gate->flags & MESH_PATH_ACTIVE) { 996 mpath_dbg(sdata, "Forwarding to %pM\n", gate->dst); 997 mesh_path_move_to_queue(gate, from_mpath, copy); 998 from_mpath = gate; 999 copy = true; 1000 } else { 1001 mpath_dbg(sdata, 1002 "Not forwarding to %pM (flags %#x)\n", 1003 gate->dst, gate->flags); 1004 } 1005 } 1006 1007 hlist_for_each_entry_rcu(gate, &tbl->known_gates, gate_list) { 1008 mpath_dbg(sdata, "Sending to %pM\n", gate->dst); 1009 mesh_path_tx_pending(gate); 1010 } 1011 rcu_read_unlock(); 1012 1013 return (from_mpath == mpath) ? -EHOSTUNREACH : 0; 1014 } 1015 1016 /** 1017 * mesh_path_discard_frame - discard a frame whose path could not be resolved 1018 * 1019 * @sdata: network subif the frame was to be sent through 1020 * @skb: frame to discard 1021 * 1022 * Locking: the function must me called within a rcu_read_lock region 1023 */ 1024 void mesh_path_discard_frame(struct ieee80211_sub_if_data *sdata, 1025 struct sk_buff *skb) 1026 { 1027 ieee80211_free_txskb(&sdata->local->hw, skb); 1028 sdata->u.mesh.mshstats.dropped_frames_no_route++; 1029 } 1030 1031 /** 1032 * mesh_path_flush_pending - free the pending queue of a mesh path 1033 * 1034 * @mpath: mesh path whose queue has to be freed 1035 * 1036 * Locking: the function must me called within a rcu_read_lock region 1037 */ 1038 void mesh_path_flush_pending(struct mesh_path *mpath) 1039 { 1040 struct ieee80211_sub_if_data *sdata = mpath->sdata; 1041 struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh; 1042 struct mesh_preq_queue *preq, *tmp; 1043 struct sk_buff *skb; 1044 1045 while ((skb = skb_dequeue(&mpath->frame_queue)) != NULL) 1046 mesh_path_discard_frame(mpath->sdata, skb); 1047 1048 spin_lock_bh(&ifmsh->mesh_preq_queue_lock); 1049 list_for_each_entry_safe(preq, tmp, &ifmsh->preq_queue.list, list) { 1050 if (ether_addr_equal(mpath->dst, preq->dst)) { 1051 list_del(&preq->list); 1052 kfree(preq); 1053 --ifmsh->preq_queue_len; 1054 } 1055 } 1056 spin_unlock_bh(&ifmsh->mesh_preq_queue_lock); 1057 } 1058 1059 /** 1060 * mesh_path_fix_nexthop - force a specific next hop for a mesh path 1061 * 1062 * @mpath: the mesh path to modify 1063 * @next_hop: the next hop to force 1064 * 1065 * Locking: this function must be called holding mpath->state_lock 1066 */ 1067 void mesh_path_fix_nexthop(struct mesh_path *mpath, struct sta_info *next_hop) 1068 { 1069 spin_lock_bh(&mpath->state_lock); 1070 mesh_path_assign_nexthop(mpath, next_hop); 1071 mpath->sn = 0xffff; 1072 mpath->metric = 0; 1073 mpath->hop_count = 0; 1074 mpath->exp_time = 0; 1075 mpath->flags = MESH_PATH_FIXED | MESH_PATH_SN_VALID; 1076 mesh_path_activate(mpath); 1077 mesh_fast_tx_flush_mpath(mpath); 1078 spin_unlock_bh(&mpath->state_lock); 1079 ewma_mesh_fail_avg_init(&next_hop->mesh->fail_avg); 1080 /* init it at a low value - 0 start is tricky */ 1081 ewma_mesh_fail_avg_add(&next_hop->mesh->fail_avg, 1); 1082 mesh_path_tx_pending(mpath); 1083 } 1084 1085 void mesh_pathtbl_init(struct ieee80211_sub_if_data *sdata) 1086 { 1087 mesh_table_init(&sdata->u.mesh.mesh_paths); 1088 mesh_table_init(&sdata->u.mesh.mpp_paths); 1089 mesh_fast_tx_init(sdata); 1090 } 1091 1092 static 1093 void mesh_path_tbl_expire(struct ieee80211_sub_if_data *sdata, 1094 struct mesh_table *tbl) 1095 { 1096 struct mesh_path *mpath; 1097 struct hlist_node *n; 1098 1099 spin_lock_bh(&tbl->walk_lock); 1100 hlist_for_each_entry_safe(mpath, n, &tbl->walk_head, walk_list) { 1101 if ((!(mpath->flags & MESH_PATH_RESOLVING)) && 1102 (!(mpath->flags & MESH_PATH_FIXED)) && 1103 time_after(jiffies, mpath->exp_time + MESH_PATH_EXPIRE)) 1104 __mesh_path_del(tbl, mpath); 1105 } 1106 spin_unlock_bh(&tbl->walk_lock); 1107 } 1108 1109 void mesh_path_expire(struct ieee80211_sub_if_data *sdata) 1110 { 1111 mesh_path_tbl_expire(sdata, &sdata->u.mesh.mesh_paths); 1112 mesh_path_tbl_expire(sdata, &sdata->u.mesh.mpp_paths); 1113 } 1114 1115 void mesh_pathtbl_unregister(struct ieee80211_sub_if_data *sdata) 1116 { 1117 mesh_fast_tx_deinit(sdata); 1118 mesh_table_free(&sdata->u.mesh.mesh_paths); 1119 mesh_table_free(&sdata->u.mesh.mpp_paths); 1120 } 1121