xref: /linux/net/mptcp/pm.c (revision bd34fa0257261b76964df1c98f44b3cb4ee14620)
1 // SPDX-License-Identifier: GPL-2.0
2 /* Multipath TCP
3  *
4  * Copyright (c) 2019, Intel Corporation.
5  */
6 #define pr_fmt(fmt) "MPTCP: " fmt
7 
8 #include <linux/rculist.h>
9 #include <linux/spinlock.h>
10 #include "protocol.h"
11 #include "mib.h"
12 
13 #define ADD_ADDR_RETRANS_MAX	3
14 
15 struct mptcp_pm_add_entry {
16 	struct list_head	list;
17 	struct mptcp_addr_info	addr;
18 	u8			retrans_times;
19 	bool			timer_done;
20 	struct timer_list	add_timer;
21 	struct mptcp_sock	*sock;
22 	struct rcu_head		rcu;
23 };
24 
25 static DEFINE_SPINLOCK(mptcp_pm_list_lock);
26 static LIST_HEAD(mptcp_pm_list);
27 
28 /* path manager helpers */
29 
30 /* if sk is ipv4 or ipv6_only allows only same-family local and remote addresses,
31  * otherwise allow any matching local/remote pair
32  */
33 bool mptcp_pm_addr_families_match(const struct sock *sk,
34 				  const struct mptcp_addr_info *loc,
35 				  const struct mptcp_addr_info *rem)
36 {
37 	bool mptcp_is_v4 = sk->sk_family == AF_INET;
38 
39 #if IS_ENABLED(CONFIG_MPTCP_IPV6)
40 	bool loc_is_v4 = loc->family == AF_INET || ipv6_addr_v4mapped(&loc->addr6);
41 	bool rem_is_v4 = rem->family == AF_INET || ipv6_addr_v4mapped(&rem->addr6);
42 
43 	if (mptcp_is_v4)
44 		return loc_is_v4 && rem_is_v4;
45 
46 	if (ipv6_only_sock(sk))
47 		return !loc_is_v4 && !rem_is_v4;
48 
49 	return loc_is_v4 == rem_is_v4;
50 #else
51 	return mptcp_is_v4 && loc->family == AF_INET && rem->family == AF_INET;
52 #endif
53 }
54 
55 bool mptcp_addresses_equal(const struct mptcp_addr_info *a,
56 			   const struct mptcp_addr_info *b, bool use_port)
57 {
58 	bool addr_equals = false;
59 
60 	if (a->family == b->family) {
61 		if (a->family == AF_INET)
62 			addr_equals = a->addr.s_addr == b->addr.s_addr;
63 #if IS_ENABLED(CONFIG_MPTCP_IPV6)
64 		else
65 			addr_equals = ipv6_addr_equal(&a->addr6, &b->addr6);
66 	} else if (a->family == AF_INET) {
67 		if (ipv6_addr_v4mapped(&b->addr6))
68 			addr_equals = a->addr.s_addr == b->addr6.s6_addr32[3];
69 	} else if (b->family == AF_INET) {
70 		if (ipv6_addr_v4mapped(&a->addr6))
71 			addr_equals = a->addr6.s6_addr32[3] == b->addr.s_addr;
72 #endif
73 	}
74 
75 	if (!addr_equals)
76 		return false;
77 	if (!use_port)
78 		return true;
79 
80 	return a->port == b->port;
81 }
82 
83 void mptcp_local_address(const struct sock_common *skc,
84 			 struct mptcp_addr_info *addr)
85 {
86 	addr->family = skc->skc_family;
87 	addr->port = htons(skc->skc_num);
88 	if (addr->family == AF_INET)
89 		addr->addr.s_addr = skc->skc_rcv_saddr;
90 #if IS_ENABLED(CONFIG_MPTCP_IPV6)
91 	else if (addr->family == AF_INET6)
92 		addr->addr6 = skc->skc_v6_rcv_saddr;
93 #endif
94 }
95 
96 void mptcp_remote_address(const struct sock_common *skc,
97 			  struct mptcp_addr_info *addr)
98 {
99 	addr->family = skc->skc_family;
100 	addr->port = skc->skc_dport;
101 	if (addr->family == AF_INET)
102 		addr->addr.s_addr = skc->skc_daddr;
103 #if IS_ENABLED(CONFIG_MPTCP_IPV6)
104 	else if (addr->family == AF_INET6)
105 		addr->addr6 = skc->skc_v6_daddr;
106 #endif
107 }
108 
109 static bool mptcp_pm_is_init_remote_addr(struct mptcp_sock *msk,
110 					 const struct mptcp_addr_info *remote)
111 {
112 	struct mptcp_addr_info mpc_remote;
113 
114 	mptcp_remote_address((struct sock_common *)msk, &mpc_remote);
115 	return mptcp_addresses_equal(&mpc_remote, remote, remote->port);
116 }
117 
118 bool mptcp_lookup_subflow_by_saddr(const struct list_head *list,
119 				   const struct mptcp_addr_info *saddr)
120 {
121 	struct mptcp_subflow_context *subflow;
122 	struct mptcp_addr_info cur;
123 	struct sock_common *skc;
124 
125 	list_for_each_entry(subflow, list, node) {
126 		skc = (struct sock_common *)mptcp_subflow_tcp_sock(subflow);
127 
128 		mptcp_local_address(skc, &cur);
129 		if (mptcp_addresses_equal(&cur, saddr, saddr->port))
130 			return true;
131 	}
132 
133 	return false;
134 }
135 
136 static struct mptcp_pm_add_entry *
137 mptcp_lookup_anno_list_by_saddr(const struct mptcp_sock *msk,
138 				const struct mptcp_addr_info *addr)
139 {
140 	struct mptcp_pm_add_entry *entry;
141 
142 	lockdep_assert_held(&msk->pm.lock);
143 
144 	list_for_each_entry(entry, &msk->pm.anno_list, list) {
145 		if (mptcp_addresses_equal(&entry->addr, addr, true))
146 			return entry;
147 	}
148 
149 	return NULL;
150 }
151 
152 bool mptcp_remove_anno_list_by_saddr(struct mptcp_sock *msk,
153 				     const struct mptcp_addr_info *addr)
154 {
155 	struct mptcp_pm_add_entry *entry;
156 	bool ret;
157 
158 	entry = mptcp_pm_del_add_timer(msk, addr, false);
159 	ret = entry;
160 	kfree_rcu(entry, rcu);
161 
162 	return ret;
163 }
164 
165 bool mptcp_pm_sport_in_anno_list(struct mptcp_sock *msk, const struct sock *sk)
166 {
167 	struct mptcp_pm_add_entry *entry;
168 	struct mptcp_addr_info saddr;
169 	bool ret = false;
170 
171 	mptcp_local_address((struct sock_common *)sk, &saddr);
172 
173 	spin_lock_bh(&msk->pm.lock);
174 	list_for_each_entry(entry, &msk->pm.anno_list, list) {
175 		if (mptcp_addresses_equal(&entry->addr, &saddr, true)) {
176 			ret = true;
177 			goto out;
178 		}
179 	}
180 
181 out:
182 	spin_unlock_bh(&msk->pm.lock);
183 	return ret;
184 }
185 
186 static void __mptcp_pm_send_ack(struct mptcp_sock *msk,
187 				struct mptcp_subflow_context *subflow,
188 				bool prio, bool backup)
189 {
190 	struct sock *ssk = mptcp_subflow_tcp_sock(subflow);
191 	bool slow;
192 
193 	pr_debug("send ack for %s\n",
194 		 prio ? "mp_prio" :
195 		 (mptcp_pm_should_add_signal(msk) ? "add_addr" : "rm_addr"));
196 
197 	slow = lock_sock_fast(ssk);
198 	if (prio) {
199 		subflow->send_mp_prio = 1;
200 		subflow->request_bkup = backup;
201 	}
202 
203 	__mptcp_subflow_send_ack(ssk);
204 	unlock_sock_fast(ssk, slow);
205 }
206 
207 void mptcp_pm_send_ack(struct mptcp_sock *msk,
208 		       struct mptcp_subflow_context *subflow,
209 		       bool prio, bool backup)
210 {
211 	spin_unlock_bh(&msk->pm.lock);
212 	__mptcp_pm_send_ack(msk, subflow, prio, backup);
213 	spin_lock_bh(&msk->pm.lock);
214 }
215 
216 static bool subflow_in_rm_list(const struct mptcp_subflow_context *subflow,
217 			       const struct mptcp_rm_list *rm_list)
218 {
219 	u8 i, id = subflow_get_local_id(subflow);
220 
221 	for (i = 0; i < rm_list->nr; i++) {
222 		if (rm_list->ids[i] == id)
223 			return true;
224 	}
225 
226 	return false;
227 }
228 
229 static void
230 mptcp_pm_addr_send_ack_avoid_list(struct mptcp_sock *msk,
231 				  const struct mptcp_rm_list *rm_list)
232 {
233 	struct mptcp_subflow_context *subflow, *stale = NULL, *same_id = NULL;
234 
235 	msk_owned_by_me(msk);
236 	lockdep_assert_held(&msk->pm.lock);
237 
238 	if (!mptcp_pm_should_add_signal(msk) &&
239 	    !mptcp_pm_should_rm_signal(msk))
240 		return;
241 
242 	mptcp_for_each_subflow(msk, subflow) {
243 		if (!__mptcp_subflow_active(subflow))
244 			continue;
245 
246 		if (unlikely(subflow->stale)) {
247 			if (!stale)
248 				stale = subflow;
249 		} else if (unlikely(rm_list &&
250 				    subflow_in_rm_list(subflow, rm_list))) {
251 			if (!same_id)
252 				same_id = subflow;
253 		} else {
254 			goto send_ack;
255 		}
256 	}
257 
258 	if (same_id)
259 		subflow = same_id;
260 	else if (stale)
261 		subflow = stale;
262 	else
263 		return;
264 
265 send_ack:
266 	mptcp_pm_send_ack(msk, subflow, false, false);
267 }
268 
269 void mptcp_pm_addr_send_ack(struct mptcp_sock *msk)
270 {
271 	mptcp_pm_addr_send_ack_avoid_list(msk, NULL);
272 }
273 
274 int mptcp_pm_mp_prio_send_ack(struct mptcp_sock *msk,
275 			      struct mptcp_addr_info *addr,
276 			      struct mptcp_addr_info *rem,
277 			      u8 bkup)
278 {
279 	struct mptcp_subflow_context *subflow;
280 
281 	pr_debug("bkup=%d\n", bkup);
282 
283 	mptcp_for_each_subflow(msk, subflow) {
284 		struct sock *ssk = mptcp_subflow_tcp_sock(subflow);
285 		struct mptcp_addr_info local, remote;
286 
287 		if (!__mptcp_subflow_active(subflow))
288 			continue;
289 
290 		mptcp_local_address((struct sock_common *)ssk, &local);
291 		if (!mptcp_addresses_equal(&local, addr, addr->port))
292 			continue;
293 
294 		if (rem && rem->family != AF_UNSPEC) {
295 			mptcp_remote_address((struct sock_common *)ssk, &remote);
296 			if (!mptcp_addresses_equal(&remote, rem, rem->port))
297 				continue;
298 		}
299 
300 		__mptcp_pm_send_ack(msk, subflow, true, bkup);
301 		return 0;
302 	}
303 
304 	return -EINVAL;
305 }
306 
307 static unsigned int mptcp_adjust_add_addr_timeout(struct mptcp_sock *msk)
308 {
309 	const struct net *net = sock_net((struct sock *)msk);
310 	unsigned int rto = mptcp_get_add_addr_timeout(net);
311 	struct mptcp_subflow_context *subflow;
312 	unsigned int max = 0, max_stale = 0;
313 
314 	if (!rto)
315 		return 0;
316 
317 	mptcp_for_each_subflow(msk, subflow) {
318 		struct sock *ssk = mptcp_subflow_tcp_sock(subflow);
319 		struct inet_connection_sock *icsk = inet_csk(ssk);
320 
321 		if (!__mptcp_subflow_active(subflow))
322 			continue;
323 
324 		if (unlikely(subflow->stale)) {
325 			if (icsk->icsk_rto > max_stale)
326 				max_stale = icsk->icsk_rto;
327 		} else if (icsk->icsk_rto > max) {
328 			max = icsk->icsk_rto;
329 		}
330 	}
331 
332 	if (max)
333 		return min(max, rto);
334 
335 	if (max_stale)
336 		return min(max_stale, rto);
337 
338 	return rto;
339 }
340 
341 static void mptcp_pm_add_timer(struct timer_list *timer)
342 {
343 	struct mptcp_pm_add_entry *entry = timer_container_of(entry, timer,
344 							      add_timer);
345 	struct mptcp_sock *msk = entry->sock;
346 	struct sock *sk = (struct sock *)msk;
347 	unsigned int timeout = 0;
348 
349 	pr_debug("msk=%p\n", msk);
350 
351 	bh_lock_sock(sk);
352 	if (unlikely(inet_sk_state_load(sk) == TCP_CLOSE))
353 		goto out;
354 
355 	if (sock_owned_by_user(sk)) {
356 		/* Try again later. */
357 		timeout = HZ / 20;
358 		goto out;
359 	}
360 
361 	timeout = mptcp_adjust_add_addr_timeout(msk);
362 	if (!timeout || mptcp_pm_should_add_signal_addr(msk))
363 		goto out;
364 
365 	spin_lock_bh(&msk->pm.lock);
366 
367 	/* The cancel path (mptcp_pm_del_add_timer()) can race with this
368 	 * callback. Once cancel updates retrans_times to MAX, suppress further
369 	 * retransmissions here. If this callback acquires pm.lock first, one
370 	 * final transmit attempt is still possible.
371 	 */
372 	if (entry->retrans_times < ADD_ADDR_RETRANS_MAX &&
373 	    !mptcp_pm_should_add_signal_addr(msk)) {
374 		pr_debug("retransmit ADD_ADDR id=%d\n", entry->addr.id);
375 		mptcp_pm_announce_addr(msk, &entry->addr, false);
376 		mptcp_pm_add_addr_send_ack(msk);
377 		entry->retrans_times++;
378 	}
379 
380 	if (entry->retrans_times < ADD_ADDR_RETRANS_MAX)
381 		timeout <<= entry->retrans_times;
382 	else
383 		timeout = 0;
384 
385 	spin_unlock_bh(&msk->pm.lock);
386 
387 	if (entry->retrans_times == ADD_ADDR_RETRANS_MAX)
388 		mptcp_pm_subflow_established(msk);
389 
390 out:
391 	if (timeout)
392 		sk_reset_timer(sk, timer, jiffies + timeout);
393 	else
394 		/* if sock_put calls sk_free: avoid waiting for this timer */
395 		entry->timer_done = true;
396 	bh_unlock_sock(sk);
397 	sock_put(sk);
398 }
399 
400 struct mptcp_pm_add_entry *
401 mptcp_pm_del_add_timer(struct mptcp_sock *msk,
402 		       const struct mptcp_addr_info *addr, bool check_id)
403 {
404 	struct mptcp_pm_add_entry *entry;
405 	struct sock *sk = (struct sock *)msk;
406 	bool stop_timer = false;
407 
408 	rcu_read_lock();
409 
410 	spin_lock_bh(&msk->pm.lock);
411 	entry = mptcp_lookup_anno_list_by_saddr(msk, addr);
412 	if (entry && (!check_id || entry->addr.id == addr->id)) {
413 		entry->retrans_times = ADD_ADDR_RETRANS_MAX;
414 		stop_timer = true;
415 	}
416 	if (!check_id && entry)
417 		list_del(&entry->list);
418 	spin_unlock_bh(&msk->pm.lock);
419 
420 	/* Note: entry might have been removed by another thread.
421 	 * We hold rcu_read_lock() to ensure it is not freed under us.
422 	 */
423 	if (stop_timer) {
424 		if (check_id)
425 			sk_stop_timer(sk, &entry->add_timer);
426 		else
427 			sk_stop_timer_sync(sk, &entry->add_timer);
428 	}
429 
430 	rcu_read_unlock();
431 	return entry;
432 }
433 
434 bool mptcp_pm_alloc_anno_list(struct mptcp_sock *msk,
435 			      const struct mptcp_addr_info *addr)
436 {
437 	struct mptcp_pm_add_entry *add_entry = NULL;
438 	struct sock *sk = (struct sock *)msk;
439 	unsigned int timeout;
440 
441 	lockdep_assert_held(&msk->pm.lock);
442 
443 	add_entry = mptcp_lookup_anno_list_by_saddr(msk, addr);
444 
445 	if (add_entry) {
446 		if (WARN_ON_ONCE(mptcp_pm_is_kernel(msk)))
447 			return false;
448 
449 		goto reset_timer;
450 	}
451 
452 	add_entry = kmalloc_obj(*add_entry, GFP_ATOMIC);
453 	if (!add_entry)
454 		return false;
455 
456 	list_add(&add_entry->list, &msk->pm.anno_list);
457 
458 	add_entry->addr = *addr;
459 	add_entry->sock = msk;
460 	add_entry->retrans_times = 0;
461 
462 	timer_setup(&add_entry->add_timer, mptcp_pm_add_timer, 0);
463 reset_timer:
464 	add_entry->timer_done = false;
465 	timeout = mptcp_adjust_add_addr_timeout(msk);
466 	if (timeout)
467 		sk_reset_timer(sk, &add_entry->add_timer, jiffies + timeout);
468 
469 	return true;
470 }
471 
472 static void mptcp_pm_free_anno_list(struct mptcp_sock *msk)
473 {
474 	struct mptcp_pm_add_entry *entry, *tmp;
475 	struct sock *sk = (struct sock *)msk;
476 	LIST_HEAD(free_list);
477 
478 	pr_debug("msk=%p\n", msk);
479 
480 	spin_lock_bh(&msk->pm.lock);
481 	list_splice_init(&msk->pm.anno_list, &free_list);
482 	spin_unlock_bh(&msk->pm.lock);
483 
484 	list_for_each_entry_safe(entry, tmp, &free_list, list) {
485 		if (!entry->timer_done)
486 			sk_stop_timer_sync(sk, &entry->add_timer);
487 		kfree_rcu(entry, rcu);
488 	}
489 }
490 
491 /* path manager command handlers */
492 
493 int mptcp_pm_announce_addr(struct mptcp_sock *msk,
494 			   const struct mptcp_addr_info *addr,
495 			   bool echo)
496 {
497 	u8 add_addr = READ_ONCE(msk->pm.addr_signal);
498 
499 	pr_debug("msk=%p, local_id=%d, echo=%d\n", msk, addr->id, echo);
500 
501 	lockdep_assert_held(&msk->pm.lock);
502 
503 	if (add_addr &
504 	    (echo ? BIT(MPTCP_ADD_ADDR_ECHO) : BIT(MPTCP_ADD_ADDR_SIGNAL))) {
505 		MPTCP_INC_STATS(sock_net((struct sock *)msk),
506 				echo ? MPTCP_MIB_ECHOADDTXDROP : MPTCP_MIB_ADDADDRTXDROP);
507 		return -EINVAL;
508 	}
509 
510 	if (echo) {
511 		msk->pm.remote = *addr;
512 		add_addr |= BIT(MPTCP_ADD_ADDR_ECHO);
513 	} else {
514 		msk->pm.local = *addr;
515 		add_addr |= BIT(MPTCP_ADD_ADDR_SIGNAL);
516 	}
517 	WRITE_ONCE(msk->pm.addr_signal, add_addr);
518 	return 0;
519 }
520 
521 int mptcp_pm_remove_addr(struct mptcp_sock *msk, const struct mptcp_rm_list *rm_list)
522 {
523 	u8 rm_addr = READ_ONCE(msk->pm.addr_signal);
524 
525 	pr_debug("msk=%p, rm_list_nr=%d\n", msk, rm_list->nr);
526 
527 	if (rm_addr) {
528 		MPTCP_ADD_STATS(sock_net((struct sock *)msk),
529 				MPTCP_MIB_RMADDRTXDROP, rm_list->nr);
530 		return -EINVAL;
531 	}
532 
533 	msk->pm.rm_list_tx = *rm_list;
534 	rm_addr |= BIT(MPTCP_RM_ADDR_SIGNAL);
535 	WRITE_ONCE(msk->pm.addr_signal, rm_addr);
536 	mptcp_pm_addr_send_ack_avoid_list(msk, rm_list);
537 	return 0;
538 }
539 
540 /* path manager event handlers */
541 
542 void mptcp_pm_new_connection(struct mptcp_sock *msk, const struct sock *ssk, int server_side)
543 {
544 	struct mptcp_pm_data *pm = &msk->pm;
545 
546 	pr_debug("msk=%p, token=%u side=%d\n", msk, READ_ONCE(msk->token), server_side);
547 
548 	WRITE_ONCE(pm->server_side, server_side);
549 	mptcp_event(MPTCP_EVENT_CREATED, msk, ssk, GFP_ATOMIC);
550 }
551 
552 bool mptcp_pm_allow_new_subflow(struct mptcp_sock *msk)
553 {
554 	struct mptcp_pm_data *pm = &msk->pm;
555 	unsigned int limit_extra_subflows;
556 	int ret = 0;
557 
558 	if (mptcp_pm_is_userspace(msk)) {
559 		if (mptcp_userspace_pm_active(msk)) {
560 			spin_lock_bh(&pm->lock);
561 			pm->extra_subflows++;
562 			spin_unlock_bh(&pm->lock);
563 			return true;
564 		}
565 		return false;
566 	}
567 
568 	limit_extra_subflows = mptcp_pm_get_limit_extra_subflows(msk);
569 
570 	pr_debug("msk=%p subflows=%d max=%d allow=%d\n", msk,
571 		 pm->extra_subflows, limit_extra_subflows,
572 		 READ_ONCE(pm->accept_subflow));
573 
574 	/* try to avoid acquiring the lock below */
575 	if (!READ_ONCE(pm->accept_subflow))
576 		return false;
577 
578 	spin_lock_bh(&pm->lock);
579 	if (READ_ONCE(pm->accept_subflow)) {
580 		ret = pm->extra_subflows < limit_extra_subflows;
581 		if (ret && ++pm->extra_subflows == limit_extra_subflows)
582 			WRITE_ONCE(pm->accept_subflow, false);
583 	}
584 	spin_unlock_bh(&pm->lock);
585 
586 	return ret;
587 }
588 
589 /* return true if the new status bit is currently cleared, that is, this event
590  * can be server, eventually by an already scheduled work
591  */
592 static bool mptcp_pm_schedule_work(struct mptcp_sock *msk,
593 				   enum mptcp_pm_status new_status)
594 {
595 	pr_debug("msk=%p status=%x new=%lx\n", msk, msk->pm.status,
596 		 BIT(new_status));
597 	if (msk->pm.status & BIT(new_status))
598 		return false;
599 
600 	msk->pm.status |= BIT(new_status);
601 	mptcp_schedule_work((struct sock *)msk);
602 	return true;
603 }
604 
605 void mptcp_pm_fully_established(struct mptcp_sock *msk, const struct sock *ssk)
606 {
607 	struct mptcp_pm_data *pm = &msk->pm;
608 	bool announce = false;
609 
610 	pr_debug("msk=%p\n", msk);
611 
612 	spin_lock_bh(&pm->lock);
613 
614 	/* mptcp_pm_fully_established() can be invoked by multiple
615 	 * racing paths - accept() and check_fully_established()
616 	 * be sure to serve this event only once.
617 	 */
618 	if (READ_ONCE(pm->work_pending) &&
619 	    !(pm->status & BIT(MPTCP_PM_ALREADY_ESTABLISHED)))
620 		mptcp_pm_schedule_work(msk, MPTCP_PM_ESTABLISHED);
621 
622 	if ((pm->status & BIT(MPTCP_PM_ALREADY_ESTABLISHED)) == 0)
623 		announce = true;
624 
625 	pm->status |= BIT(MPTCP_PM_ALREADY_ESTABLISHED);
626 	spin_unlock_bh(&pm->lock);
627 
628 	if (announce)
629 		mptcp_event(MPTCP_EVENT_ESTABLISHED, msk, ssk, GFP_ATOMIC);
630 }
631 
632 void mptcp_pm_connection_closed(struct mptcp_sock *msk)
633 {
634 	pr_debug("msk=%p\n", msk);
635 
636 	if (msk->token)
637 		mptcp_event(MPTCP_EVENT_CLOSED, msk, NULL, GFP_KERNEL);
638 }
639 
640 void mptcp_pm_subflow_established(struct mptcp_sock *msk)
641 {
642 	struct mptcp_pm_data *pm = &msk->pm;
643 
644 	pr_debug("msk=%p\n", msk);
645 
646 	if (!READ_ONCE(pm->work_pending))
647 		return;
648 
649 	spin_lock_bh(&pm->lock);
650 
651 	if (READ_ONCE(pm->work_pending))
652 		mptcp_pm_schedule_work(msk, MPTCP_PM_SUBFLOW_ESTABLISHED);
653 
654 	spin_unlock_bh(&pm->lock);
655 }
656 
657 void mptcp_pm_subflow_check_next(struct mptcp_sock *msk,
658 				 const struct mptcp_subflow_context *subflow)
659 {
660 	struct sock *sk = (struct sock *)msk;
661 	struct mptcp_pm_data *pm = &msk->pm;
662 	bool update_subflows;
663 
664 	update_subflows = subflow->request_join || subflow->mp_join;
665 	if (mptcp_pm_is_userspace(msk)) {
666 		if (update_subflows) {
667 			spin_lock_bh(&pm->lock);
668 			pm->extra_subflows--;
669 			spin_unlock_bh(&pm->lock);
670 		}
671 		return;
672 	}
673 
674 	if (!READ_ONCE(pm->work_pending) && !update_subflows)
675 		return;
676 
677 	spin_lock_bh(&pm->lock);
678 	if (update_subflows)
679 		__mptcp_pm_close_subflow(msk);
680 
681 	/* Even if this subflow is not really established, tell the PM to try
682 	 * to pick the next ones, if possible.
683 	 */
684 	if (mptcp_is_fully_established(sk) &&
685 	    mptcp_pm_nl_check_work_pending(msk))
686 		mptcp_pm_schedule_work(msk, MPTCP_PM_SUBFLOW_ESTABLISHED);
687 
688 	spin_unlock_bh(&pm->lock);
689 }
690 
691 void mptcp_pm_add_addr_received(const struct sock *ssk,
692 				const struct mptcp_addr_info *addr)
693 {
694 	struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(ssk);
695 	struct mptcp_sock *msk = mptcp_sk(subflow->conn);
696 	struct mptcp_pm_data *pm = &msk->pm;
697 
698 	pr_debug("msk=%p remote_id=%d accept=%d\n", msk, addr->id,
699 		 READ_ONCE(pm->accept_addr));
700 
701 	mptcp_event_addr_announced(ssk, addr);
702 
703 	spin_lock_bh(&pm->lock);
704 
705 	if (mptcp_pm_is_userspace(msk)) {
706 		if (mptcp_userspace_pm_active(msk)) {
707 			mptcp_pm_announce_addr(msk, addr, true);
708 			mptcp_pm_add_addr_send_ack(msk);
709 		} else {
710 			__MPTCP_INC_STATS(sock_net((struct sock *)msk), MPTCP_MIB_ADDADDRDROP);
711 		}
712 	/* - id0 should not have a different address
713 	 * - special case for C-flag: linked to fill_local_addresses_vec()
714 	 */
715 	} else if ((addr->id == 0 && !mptcp_pm_is_init_remote_addr(msk, addr)) ||
716 		   (addr->id > 0 && !READ_ONCE(pm->accept_addr) &&
717 		    !mptcp_pm_add_addr_c_flag_case(msk))) {
718 		mptcp_pm_announce_addr(msk, addr, true);
719 		mptcp_pm_add_addr_send_ack(msk);
720 	} else if (mptcp_pm_schedule_work(msk, MPTCP_PM_ADD_ADDR_RECEIVED)) {
721 		pm->remote = *addr;
722 	} else {
723 		__MPTCP_INC_STATS(sock_net((struct sock *)msk), MPTCP_MIB_ADDADDRDROP);
724 	}
725 
726 	spin_unlock_bh(&pm->lock);
727 }
728 
729 void mptcp_pm_add_addr_echoed(struct mptcp_sock *msk,
730 			      const struct mptcp_addr_info *addr)
731 {
732 	struct mptcp_pm_data *pm = &msk->pm;
733 
734 	pr_debug("msk=%p\n", msk);
735 
736 	if (!READ_ONCE(pm->work_pending))
737 		return;
738 
739 	spin_lock_bh(&pm->lock);
740 
741 	if (mptcp_lookup_anno_list_by_saddr(msk, addr) && READ_ONCE(pm->work_pending))
742 		mptcp_pm_schedule_work(msk, MPTCP_PM_SUBFLOW_ESTABLISHED);
743 
744 	spin_unlock_bh(&pm->lock);
745 }
746 
747 void mptcp_pm_add_addr_send_ack(struct mptcp_sock *msk)
748 {
749 	if (!mptcp_pm_should_add_signal(msk))
750 		return;
751 
752 	mptcp_pm_schedule_work(msk, MPTCP_PM_ADD_ADDR_SEND_ACK);
753 }
754 
755 static void mptcp_pm_rm_addr_or_subflow(struct mptcp_sock *msk,
756 					const struct mptcp_rm_list *rm_list,
757 					enum linux_mptcp_mib_field rm_type)
758 {
759 	struct mptcp_subflow_context *subflow, *tmp;
760 	struct sock *sk = (struct sock *)msk;
761 	u8 i;
762 
763 	pr_debug("%s rm_list_nr %d\n",
764 		 rm_type == MPTCP_MIB_RMADDR ? "address" : "subflow", rm_list->nr);
765 
766 	msk_owned_by_me(msk);
767 
768 	if (sk->sk_state == TCP_LISTEN)
769 		return;
770 
771 	if (!rm_list->nr)
772 		return;
773 
774 	if (list_empty(&msk->conn_list))
775 		return;
776 
777 	for (i = 0; i < rm_list->nr; i++) {
778 		u8 rm_id = rm_list->ids[i];
779 		bool removed = false;
780 
781 		mptcp_for_each_subflow_safe(msk, subflow, tmp) {
782 			struct sock *ssk = mptcp_subflow_tcp_sock(subflow);
783 			u8 remote_id = READ_ONCE(subflow->remote_id);
784 			int how = RCV_SHUTDOWN | SEND_SHUTDOWN;
785 			u8 id = subflow_get_local_id(subflow);
786 
787 			if ((1 << inet_sk_state_load(ssk)) &
788 			    (TCPF_FIN_WAIT1 | TCPF_FIN_WAIT2 | TCPF_CLOSING | TCPF_CLOSE))
789 				continue;
790 			if (rm_type == MPTCP_MIB_RMADDR && remote_id != rm_id)
791 				continue;
792 			if (rm_type == MPTCP_MIB_RMSUBFLOW && id != rm_id)
793 				continue;
794 
795 			pr_debug(" -> %s rm_list_ids[%d]=%u local_id=%u remote_id=%u mpc_id=%u\n",
796 				 rm_type == MPTCP_MIB_RMADDR ? "address" : "subflow",
797 				 i, rm_id, id, remote_id, msk->mpc_endpoint_id);
798 			spin_unlock_bh(&msk->pm.lock);
799 			mptcp_subflow_shutdown(sk, ssk, how);
800 			removed |= subflow->request_join;
801 
802 			/* the following takes care of updating the subflows counter */
803 			mptcp_close_ssk(sk, ssk, subflow);
804 			spin_lock_bh(&msk->pm.lock);
805 
806 			if (rm_type == MPTCP_MIB_RMSUBFLOW)
807 				__MPTCP_INC_STATS(sock_net(sk), rm_type);
808 		}
809 
810 		if (rm_type == MPTCP_MIB_RMADDR) {
811 			__MPTCP_INC_STATS(sock_net(sk), rm_type);
812 			if (removed && mptcp_pm_is_kernel(msk))
813 				mptcp_pm_nl_rm_addr(msk, rm_id);
814 		}
815 	}
816 }
817 
818 static void mptcp_pm_rm_addr_recv(struct mptcp_sock *msk)
819 {
820 	mptcp_pm_rm_addr_or_subflow(msk, &msk->pm.rm_list_rx, MPTCP_MIB_RMADDR);
821 }
822 
823 void mptcp_pm_rm_subflow(struct mptcp_sock *msk,
824 			 const struct mptcp_rm_list *rm_list)
825 {
826 	mptcp_pm_rm_addr_or_subflow(msk, rm_list, MPTCP_MIB_RMSUBFLOW);
827 }
828 
829 void mptcp_pm_rm_addr_received(struct mptcp_sock *msk,
830 			       const struct mptcp_rm_list *rm_list)
831 {
832 	struct mptcp_pm_data *pm = &msk->pm;
833 	u8 i;
834 
835 	pr_debug("msk=%p remote_ids_nr=%d\n", msk, rm_list->nr);
836 
837 	for (i = 0; i < rm_list->nr; i++)
838 		mptcp_event_addr_removed(msk, rm_list->ids[i]);
839 
840 	spin_lock_bh(&pm->lock);
841 	if (mptcp_pm_schedule_work(msk, MPTCP_PM_RM_ADDR_RECEIVED))
842 		pm->rm_list_rx = *rm_list;
843 	else
844 		__MPTCP_INC_STATS(sock_net((struct sock *)msk), MPTCP_MIB_RMADDRDROP);
845 	spin_unlock_bh(&pm->lock);
846 }
847 
848 void mptcp_pm_mp_prio_received(struct sock *ssk, u8 bkup)
849 {
850 	struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(ssk);
851 	struct sock *sk = subflow->conn;
852 	struct mptcp_sock *msk;
853 
854 	pr_debug("subflow->backup=%d, bkup=%d\n", subflow->backup, bkup);
855 	msk = mptcp_sk(sk);
856 	if (subflow->backup != bkup)
857 		subflow->backup = bkup;
858 
859 	mptcp_event(MPTCP_EVENT_SUB_PRIORITY, msk, ssk, GFP_ATOMIC);
860 }
861 
862 void mptcp_pm_mp_fail_received(struct sock *sk, u64 fail_seq)
863 {
864 	struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(sk);
865 	struct mptcp_sock *msk = mptcp_sk(subflow->conn);
866 
867 	pr_debug("fail_seq=%llu\n", fail_seq);
868 
869 	/* After accepting the fail, we can't create any other subflows */
870 	spin_lock_bh(&msk->fallback_lock);
871 	if (!msk->allow_infinite_fallback) {
872 		spin_unlock_bh(&msk->fallback_lock);
873 		return;
874 	}
875 	msk->allow_subflows = false;
876 	spin_unlock_bh(&msk->fallback_lock);
877 
878 	if (!subflow->fail_tout) {
879 		pr_debug("send MP_FAIL response and infinite map\n");
880 
881 		subflow->send_mp_fail = 1;
882 		subflow->send_infinite_map = 1;
883 		tcp_send_ack(sk);
884 	} else {
885 		pr_debug("MP_FAIL response received\n");
886 		WRITE_ONCE(subflow->fail_tout, 0);
887 	}
888 }
889 
890 bool mptcp_pm_add_addr_signal(struct mptcp_sock *msk, unsigned int opt_size,
891 			      unsigned int remaining,
892 			      struct mptcp_addr_info *addr, bool *echo)
893 {
894 	bool skip_add_addr = false;
895 	int ret = false;
896 	u8 add_addr;
897 	u8 family;
898 	bool port;
899 
900 	spin_lock_bh(&msk->pm.lock);
901 
902 	/* double check after the lock is acquired */
903 	if (!mptcp_pm_should_add_signal(msk))
904 		goto out_unlock;
905 
906 	/* always drop every other options for pure ack ADD_ADDR; this is a
907 	 * plain dup-ack from TCP perspective. The other MPTCP-relevant info,
908 	 * if any, will be carried by the 'original' TCP ack
909 	 */
910 	remaining += opt_size;
911 
912 	*echo = mptcp_pm_should_add_signal_echo(msk);
913 	if (*echo) {
914 		*addr = msk->pm.remote;
915 		add_addr = msk->pm.addr_signal & ~BIT(MPTCP_ADD_ADDR_ECHO);
916 		port = !!msk->pm.remote.port;
917 		family = msk->pm.remote.family;
918 	} else {
919 		*addr = msk->pm.local;
920 		add_addr = msk->pm.addr_signal & ~BIT(MPTCP_ADD_ADDR_SIGNAL);
921 		port = !!msk->pm.local.port;
922 		family = msk->pm.local.family;
923 	}
924 
925 	if (remaining < mptcp_add_addr_len(family, *echo, port)) {
926 		struct net *net = sock_net((struct sock *)msk);
927 
928 		if (*echo) {
929 			MPTCP_INC_STATS(net, MPTCP_MIB_ECHOADDTXDROP);
930 		} else {
931 			skip_add_addr = true;
932 			MPTCP_INC_STATS(net, MPTCP_MIB_ADDADDRTXDROP);
933 		}
934 		goto drop_signal_mark;
935 	}
936 
937 	ret = true;
938 
939 drop_signal_mark:
940 	WRITE_ONCE(msk->pm.addr_signal, add_addr);
941 
942 out_unlock:
943 	spin_unlock_bh(&msk->pm.lock);
944 
945 	/* On pure-ACK option-space exhaustion, stop retrying this ADD_ADDR:
946 	 * clear the signal bit, cancel the matching retransmission timer, and
947 	 * let the PM state machine progress.
948 	 */
949 	if (skip_add_addr) {
950 		mptcp_pm_del_add_timer(msk, addr, true);
951 		mptcp_pm_subflow_established(msk);
952 	}
953 	return ret;
954 }
955 
956 bool mptcp_pm_rm_addr_signal(struct mptcp_sock *msk, unsigned int remaining,
957 			     struct mptcp_rm_list *rm_list)
958 {
959 	int ret = false, len;
960 	u8 rm_addr;
961 
962 	spin_lock_bh(&msk->pm.lock);
963 
964 	/* double check after the lock is acquired */
965 	if (!mptcp_pm_should_rm_signal(msk))
966 		goto out_unlock;
967 
968 	rm_addr = msk->pm.addr_signal & ~BIT(MPTCP_RM_ADDR_SIGNAL);
969 	len = mptcp_rm_addr_len(&msk->pm.rm_list_tx);
970 	if (len < 0) {
971 		WRITE_ONCE(msk->pm.addr_signal, rm_addr);
972 		goto out_unlock;
973 	}
974 	if (remaining < len)
975 		goto out_unlock;
976 
977 	*rm_list = msk->pm.rm_list_tx;
978 	WRITE_ONCE(msk->pm.addr_signal, rm_addr);
979 	ret = true;
980 
981 out_unlock:
982 	spin_unlock_bh(&msk->pm.lock);
983 	return ret;
984 }
985 
986 int mptcp_pm_get_local_id(struct mptcp_sock *msk, struct sock_common *skc)
987 {
988 	struct mptcp_pm_addr_entry skc_local = { 0 };
989 	struct mptcp_addr_info msk_local;
990 
991 	if (WARN_ON_ONCE(!msk))
992 		return -1;
993 
994 	/* The 0 ID mapping is defined by the first subflow, copied into the msk
995 	 * addr
996 	 */
997 	mptcp_local_address((struct sock_common *)msk, &msk_local);
998 	mptcp_local_address((struct sock_common *)skc, &skc_local.addr);
999 	if (mptcp_addresses_equal(&msk_local, &skc_local.addr, false))
1000 		return 0;
1001 
1002 	skc_local.addr.id = 0;
1003 	skc_local.flags = MPTCP_PM_ADDR_FLAG_IMPLICIT;
1004 
1005 	if (mptcp_pm_is_userspace(msk))
1006 		return mptcp_userspace_pm_get_local_id(msk, &skc_local);
1007 	return mptcp_pm_nl_get_local_id(msk, &skc_local);
1008 }
1009 
1010 bool mptcp_pm_is_backup(struct mptcp_sock *msk, struct sock_common *skc)
1011 {
1012 	struct mptcp_addr_info skc_local;
1013 
1014 	mptcp_local_address((struct sock_common *)skc, &skc_local);
1015 
1016 	if (mptcp_pm_is_userspace(msk))
1017 		return mptcp_userspace_pm_is_backup(msk, &skc_local);
1018 
1019 	return mptcp_pm_nl_is_backup(msk, &skc_local);
1020 }
1021 
1022 static void mptcp_pm_subflows_chk_stale(const struct mptcp_sock *msk, struct sock *ssk)
1023 {
1024 	struct mptcp_subflow_context *iter, *subflow = mptcp_subflow_ctx(ssk);
1025 	struct sock *sk = (struct sock *)msk;
1026 	unsigned int active_max_loss_cnt;
1027 	struct net *net = sock_net(sk);
1028 	unsigned int stale_loss_cnt;
1029 	bool slow;
1030 
1031 	stale_loss_cnt = mptcp_stale_loss_cnt(net);
1032 	if (subflow->stale || !stale_loss_cnt || subflow->stale_count <= stale_loss_cnt)
1033 		return;
1034 
1035 	/* look for another available subflow not in loss state */
1036 	active_max_loss_cnt = max_t(int, stale_loss_cnt - 1, 1);
1037 	mptcp_for_each_subflow(msk, iter) {
1038 		if (iter != subflow && mptcp_subflow_active(iter) &&
1039 		    iter->stale_count < active_max_loss_cnt) {
1040 			/* we have some alternatives, try to mark this subflow as idle ...*/
1041 			slow = lock_sock_fast(ssk);
1042 			if (!tcp_rtx_and_write_queues_empty(ssk)) {
1043 				subflow->stale = 1;
1044 				__mptcp_retransmit_pending_data(sk);
1045 				MPTCP_INC_STATS(net, MPTCP_MIB_SUBFLOWSTALE);
1046 			}
1047 			unlock_sock_fast(ssk, slow);
1048 
1049 			/* always try to push the pending data regardless of re-injections:
1050 			 * we can possibly use backup subflows now, and subflow selection
1051 			 * is cheap under the msk socket lock
1052 			 */
1053 			__mptcp_push_pending(sk, 0);
1054 			return;
1055 		}
1056 	}
1057 }
1058 
1059 void mptcp_pm_subflow_chk_stale(const struct mptcp_sock *msk, struct sock *ssk)
1060 {
1061 	struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(ssk);
1062 	u32 rcv_tstamp = READ_ONCE(tcp_sk(ssk)->rcv_tstamp);
1063 
1064 	/* keep track of rtx periods with no progress */
1065 	if (!subflow->stale_count) {
1066 		subflow->stale_rcv_tstamp = rcv_tstamp;
1067 		subflow->stale_count++;
1068 	} else if (subflow->stale_rcv_tstamp == rcv_tstamp) {
1069 		if (subflow->stale_count < U8_MAX)
1070 			subflow->stale_count++;
1071 		mptcp_pm_subflows_chk_stale(msk, ssk);
1072 	} else {
1073 		subflow->stale_count = 0;
1074 		mptcp_subflow_set_active(subflow);
1075 	}
1076 }
1077 
1078 void mptcp_pm_worker(struct mptcp_sock *msk)
1079 {
1080 	struct mptcp_pm_data *pm = &msk->pm;
1081 
1082 	msk_owned_by_me(msk);
1083 
1084 	if (!(pm->status & MPTCP_PM_WORK_MASK))
1085 		return;
1086 
1087 	spin_lock_bh(&msk->pm.lock);
1088 
1089 	pr_debug("msk=%p status=%x\n", msk, pm->status);
1090 	if (pm->status & BIT(MPTCP_PM_ADD_ADDR_SEND_ACK)) {
1091 		pm->status &= ~BIT(MPTCP_PM_ADD_ADDR_SEND_ACK);
1092 		mptcp_pm_addr_send_ack(msk);
1093 	}
1094 	if (pm->status & BIT(MPTCP_PM_RM_ADDR_RECEIVED)) {
1095 		pm->status &= ~BIT(MPTCP_PM_RM_ADDR_RECEIVED);
1096 		mptcp_pm_rm_addr_recv(msk);
1097 	}
1098 	__mptcp_pm_kernel_worker(msk);
1099 
1100 	spin_unlock_bh(&msk->pm.lock);
1101 }
1102 
1103 void mptcp_pm_destroy(struct mptcp_sock *msk)
1104 {
1105 	mptcp_pm_free_anno_list(msk);
1106 
1107 	if (mptcp_pm_is_userspace(msk))
1108 		mptcp_userspace_pm_free_local_addr_list(msk);
1109 }
1110 
1111 void mptcp_pm_data_reset(struct mptcp_sock *msk)
1112 {
1113 	u8 pm_type = mptcp_get_pm_type(sock_net((struct sock *)msk));
1114 	struct mptcp_pm_data *pm = &msk->pm;
1115 
1116 	memset(&pm->reset, 0, sizeof(pm->reset));
1117 	pm->rm_list_tx.nr = 0;
1118 	pm->rm_list_rx.nr = 0;
1119 	WRITE_ONCE(pm->pm_type, pm_type);
1120 
1121 	if (pm_type == MPTCP_PM_TYPE_KERNEL) {
1122 		bool subflows_allowed = !!mptcp_pm_get_limit_extra_subflows(msk);
1123 
1124 		/* pm->work_pending must be only be set to 'true' when
1125 		 * pm->pm_type is set to MPTCP_PM_TYPE_KERNEL
1126 		 */
1127 		WRITE_ONCE(pm->work_pending,
1128 			   (!!mptcp_pm_get_endp_subflow_max(msk) &&
1129 			    subflows_allowed) ||
1130 			   !!mptcp_pm_get_endp_signal_max(msk));
1131 		WRITE_ONCE(pm->accept_addr,
1132 			   !!mptcp_pm_get_limit_add_addr_accepted(msk) &&
1133 			   subflows_allowed);
1134 		WRITE_ONCE(pm->accept_subflow, subflows_allowed);
1135 
1136 		bitmap_fill(pm->id_avail_bitmap, MPTCP_PM_MAX_ADDR_ID + 1);
1137 	}
1138 }
1139 
1140 void mptcp_pm_data_init(struct mptcp_sock *msk)
1141 {
1142 	spin_lock_init(&msk->pm.lock);
1143 	INIT_LIST_HEAD(&msk->pm.anno_list);
1144 	INIT_LIST_HEAD(&msk->pm.userspace_pm_local_addr_list);
1145 	mptcp_pm_data_reset(msk);
1146 }
1147 
1148 void __init mptcp_pm_init(void)
1149 {
1150 	mptcp_pm_kernel_register();
1151 	mptcp_pm_userspace_register();
1152 	mptcp_pm_nl_init();
1153 }
1154 
1155 /* Must be called with rcu read lock held */
1156 struct mptcp_pm_ops *mptcp_pm_find(const char *name)
1157 {
1158 	struct mptcp_pm_ops *pm_ops;
1159 
1160 	list_for_each_entry_rcu(pm_ops, &mptcp_pm_list, list) {
1161 		if (!strcmp(pm_ops->name, name))
1162 			return pm_ops;
1163 	}
1164 
1165 	return NULL;
1166 }
1167 
1168 int mptcp_pm_validate(struct mptcp_pm_ops *pm_ops)
1169 {
1170 	return 0;
1171 }
1172 
1173 int mptcp_pm_register(struct mptcp_pm_ops *pm_ops)
1174 {
1175 	int ret;
1176 
1177 	ret = mptcp_pm_validate(pm_ops);
1178 	if (ret)
1179 		return ret;
1180 
1181 	spin_lock(&mptcp_pm_list_lock);
1182 	if (mptcp_pm_find(pm_ops->name)) {
1183 		spin_unlock(&mptcp_pm_list_lock);
1184 		return -EEXIST;
1185 	}
1186 	list_add_tail_rcu(&pm_ops->list, &mptcp_pm_list);
1187 	spin_unlock(&mptcp_pm_list_lock);
1188 
1189 	pr_debug("%s registered\n", pm_ops->name);
1190 	return 0;
1191 }
1192 
1193 void mptcp_pm_unregister(struct mptcp_pm_ops *pm_ops)
1194 {
1195 	/* skip unregistering the default path manager */
1196 	if (WARN_ON_ONCE(pm_ops == &mptcp_pm_kernel))
1197 		return;
1198 
1199 	spin_lock(&mptcp_pm_list_lock);
1200 	list_del_rcu(&pm_ops->list);
1201 	spin_unlock(&mptcp_pm_list_lock);
1202 }
1203 
1204 /* Build string with list of available path manager values.
1205  * Similar to tcp_get_available_congestion_control()
1206  */
1207 void mptcp_pm_get_available(char *buf, size_t maxlen)
1208 {
1209 	struct mptcp_pm_ops *pm_ops;
1210 	size_t offs = 0;
1211 
1212 	rcu_read_lock();
1213 	list_for_each_entry_rcu(pm_ops, &mptcp_pm_list, list) {
1214 		offs += snprintf(buf + offs, maxlen - offs, "%s%s",
1215 				 offs == 0 ? "" : " ", pm_ops->name);
1216 
1217 		if (WARN_ON_ONCE(offs >= maxlen))
1218 			break;
1219 	}
1220 	rcu_read_unlock();
1221 }
1222