xref: /linux/net/batman-adv/routing.c (revision 91ec2035134982b98fab0609a9fd8480e8217dc1)
1 // SPDX-License-Identifier: GPL-2.0
2 /* Copyright (C) B.A.T.M.A.N. contributors:
3  *
4  * Marek Lindner, Simon Wunderlich
5  */
6 
7 #include "routing.h"
8 #include "main.h"
9 
10 #include <linux/atomic.h>
11 #include <linux/build_bug.h>
12 #include <linux/byteorder/generic.h>
13 #include <linux/compiler.h>
14 #include <linux/errno.h>
15 #include <linux/etherdevice.h>
16 #include <linux/if_ether.h>
17 #include <linux/jiffies.h>
18 #include <linux/kref.h>
19 #include <linux/netdevice.h>
20 #include <linux/printk.h>
21 #include <linux/rculist.h>
22 #include <linux/rcupdate.h>
23 #include <linux/skbuff.h>
24 #include <linux/spinlock.h>
25 #include <linux/stddef.h>
26 #include <uapi/linux/batadv_packet.h>
27 
28 #include "bitarray.h"
29 #include "bridge_loop_avoidance.h"
30 #include "distributed-arp-table.h"
31 #include "fragmentation.h"
32 #include "hard-interface.h"
33 #include "log.h"
34 #include "mesh-interface.h"
35 #include "originator.h"
36 #include "send.h"
37 #include "tp_meter.h"
38 #include "translation-table.h"
39 #include "tvlv.h"
40 
41 static int batadv_route_unicast_packet(struct sk_buff *skb,
42 				       struct batadv_hard_iface *recv_if);
43 
44 /**
45  * _batadv_update_route() - set the router for this originator
46  * @bat_priv: the bat priv with all the mesh interface information
47  * @orig_node: orig node which is to be configured
48  * @recv_if: the receive interface for which this route is set
49  * @neigh_node: neighbor which should be the next router
50  *
51  * This function does not perform any error checks
52  */
_batadv_update_route(struct batadv_priv * bat_priv,struct batadv_orig_node * orig_node,struct batadv_hard_iface * recv_if,struct batadv_neigh_node * neigh_node)53 static void _batadv_update_route(struct batadv_priv *bat_priv,
54 				 struct batadv_orig_node *orig_node,
55 				 struct batadv_hard_iface *recv_if,
56 				 struct batadv_neigh_node *neigh_node)
57 {
58 	struct batadv_orig_ifinfo *orig_ifinfo;
59 	struct batadv_neigh_node *curr_router;
60 
61 	orig_ifinfo = batadv_orig_ifinfo_get(orig_node, recv_if);
62 	if (!orig_ifinfo)
63 		return;
64 
65 	spin_lock_bh(&orig_node->neigh_list_lock);
66 	/* curr_router used earlier may not be the current orig_ifinfo->router
67 	 * anymore because it was dereferenced outside of the neigh_list_lock
68 	 * protected region. After the new best neighbor has replace the current
69 	 * best neighbor the reference counter needs to decrease. Consequently,
70 	 * the code needs to ensure the curr_router variable contains a pointer
71 	 * to the replaced best neighbor.
72 	 */
73 
74 	/* increase refcount of new best neighbor */
75 	if (neigh_node)
76 		kref_get(&neigh_node->refcount);
77 
78 	curr_router = rcu_replace_pointer(orig_ifinfo->router, neigh_node,
79 					  true);
80 	spin_unlock_bh(&orig_node->neigh_list_lock);
81 	batadv_orig_ifinfo_put(orig_ifinfo);
82 
83 	/* route deleted */
84 	if (curr_router && !neigh_node) {
85 		batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
86 			   "Deleting route towards: %pM\n", orig_node->orig);
87 		batadv_tt_global_del_orig(bat_priv, orig_node, -1,
88 					  "Deleted route towards originator");
89 
90 	/* route added */
91 	} else if (!curr_router && neigh_node) {
92 		batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
93 			   "Adding route towards: %pM (via %pM)\n",
94 			   orig_node->orig, neigh_node->addr);
95 	/* route changed */
96 	} else if (neigh_node && curr_router) {
97 		batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
98 			   "Changing route towards: %pM (now via %pM - was via %pM)\n",
99 			   orig_node->orig, neigh_node->addr,
100 			   curr_router->addr);
101 	}
102 
103 	/* decrease refcount of previous best neighbor */
104 	batadv_neigh_node_put(curr_router);
105 }
106 
107 /**
108  * batadv_update_route() - set the router for this originator
109  * @bat_priv: the bat priv with all the mesh interface information
110  * @orig_node: orig node which is to be configured
111  * @recv_if: the receive interface for which this route is set
112  * @neigh_node: neighbor which should be the next router
113  */
batadv_update_route(struct batadv_priv * bat_priv,struct batadv_orig_node * orig_node,struct batadv_hard_iface * recv_if,struct batadv_neigh_node * neigh_node)114 void batadv_update_route(struct batadv_priv *bat_priv,
115 			 struct batadv_orig_node *orig_node,
116 			 struct batadv_hard_iface *recv_if,
117 			 struct batadv_neigh_node *neigh_node)
118 {
119 	struct batadv_neigh_node *router = NULL;
120 
121 	if (!orig_node)
122 		goto out;
123 
124 	router = batadv_orig_router_get(orig_node, recv_if);
125 
126 	if (router != neigh_node)
127 		_batadv_update_route(bat_priv, orig_node, recv_if, neigh_node);
128 
129 out:
130 	batadv_neigh_node_put(router);
131 }
132 
133 /**
134  * batadv_window_protected() - checks whether the host restarted and is in the
135  *  protection time.
136  * @bat_priv: the bat priv with all the mesh interface information
137  * @seq_num_diff: difference between the current/received sequence number and
138  *  the last sequence number
139  * @seq_old_max_diff: maximum age of sequence number not considered as restart
140  * @last_reset: jiffies timestamp of the last reset, will be updated when reset
141  *  is detected
142  * @protection_started: is set to true if the protection window was started,
143  *   doesn't change otherwise.
144  *
145  * Return:
146  *  false if the packet is to be accepted.
147  *  true if the packet is to be ignored.
148  */
batadv_window_protected(struct batadv_priv * bat_priv,s32 seq_num_diff,s32 seq_old_max_diff,unsigned long * last_reset,bool * protection_started)149 bool batadv_window_protected(struct batadv_priv *bat_priv, s32 seq_num_diff,
150 			     s32 seq_old_max_diff, unsigned long *last_reset,
151 			     bool *protection_started)
152 {
153 	if (seq_num_diff <= -seq_old_max_diff ||
154 	    seq_num_diff >= BATADV_EXPECTED_SEQNO_RANGE) {
155 		if (!batadv_has_timed_out(*last_reset,
156 					  BATADV_RESET_PROTECTION_MS))
157 			return true;
158 
159 		*last_reset = jiffies;
160 		if (protection_started)
161 			*protection_started = true;
162 		batadv_dbg(BATADV_DBG_BATMAN, bat_priv,
163 			   "old packet received, start protection\n");
164 	}
165 
166 	return false;
167 }
168 
169 /**
170  * batadv_check_management_packet() - Check preconditions for management packets
171  * @skb: incoming packet buffer
172  * @hard_iface: incoming hard interface
173  * @header_len: minimal header length of packet type
174  *
175  * Warning: This function may reallocate the skb data buffer via
176  * skb_cow()/skb_linearize()/... Any pointer into the skb data (e.g.
177  * obtained from skb->data or eth_hdr()) before this call must be
178  * considered invalid afterwards and has to be reacquired.
179  *
180  * Return: true when management preconditions are met, false otherwise
181  */
batadv_check_management_packet(struct sk_buff * skb,struct batadv_hard_iface * hard_iface,int header_len)182 bool batadv_check_management_packet(struct sk_buff *skb,
183 				    struct batadv_hard_iface *hard_iface,
184 				    int header_len)
185 {
186 	struct ethhdr *ethhdr;
187 
188 	/* drop packet if it has not necessary minimum size */
189 	if (unlikely(!pskb_may_pull(skb, header_len)))
190 		return false;
191 
192 	ethhdr = eth_hdr(skb);
193 
194 	/* packet with broadcast indication but unicast recipient */
195 	if (!is_broadcast_ether_addr(ethhdr->h_dest))
196 		return false;
197 
198 	/* packet with invalid sender address */
199 	if (!is_valid_ether_addr(ethhdr->h_source))
200 		return false;
201 
202 	/* create a copy of the skb, if needed, to modify it. */
203 	if (skb_cow(skb, 0) < 0)
204 		return false;
205 
206 	/* keep skb linear */
207 	if (skb_linearize(skb) < 0)
208 		return false;
209 
210 	return true;
211 }
212 
213 /**
214  * batadv_skb_decrement_ttl() - decrement ttl in a batman-adv header, csum-safe
215  * @skb: the received packet with @skb->data pointing to the batman-adv header
216  *
217  * Supports the following packet types, all of which carry the TTL at offset 2:
218  *
219  * - batadv_ogm_packet
220  * - batadv_ogm2_packet
221  * - batadv_icmp_header
222  * - batadv_icmp_packet
223  * - batadv_icmp_tp_packet
224  * - batadv_icmp_packet_rr
225  * - batadv_unicast_packet
226  * - batadv_frag_packet
227  * - batadv_bcast_packet
228  * - batadv_mcast_packet
229  * - batadv_coded_packet
230  * - batadv_unicast_tvlv_packet
231  *
232  * Return: true if the packet may be forwarded (ttl decremented),
233  *  false if it must be dropped (ttl would expire)
234  */
batadv_skb_decrement_ttl(struct sk_buff * skb)235 static bool batadv_skb_decrement_ttl(struct sk_buff *skb)
236 {
237 	static const size_t ttl_offset = 2;
238 	u8 *ttl_pos;
239 
240 	BUILD_BUG_ON(offsetof(struct batadv_ogm_packet, ttl) != ttl_offset);
241 	BUILD_BUG_ON(offsetof(struct batadv_ogm2_packet, ttl) != ttl_offset);
242 	BUILD_BUG_ON(offsetof(struct batadv_icmp_header, ttl) != ttl_offset);
243 	BUILD_BUG_ON(offsetof(struct batadv_icmp_packet, ttl) != ttl_offset);
244 	BUILD_BUG_ON(offsetof(struct batadv_icmp_tp_packet, ttl) != ttl_offset);
245 	BUILD_BUG_ON(offsetof(struct batadv_icmp_packet_rr, ttl) != ttl_offset);
246 	BUILD_BUG_ON(offsetof(struct batadv_unicast_packet, ttl) != ttl_offset);
247 	BUILD_BUG_ON(offsetof(struct batadv_frag_packet, ttl) != ttl_offset);
248 	BUILD_BUG_ON(offsetof(struct batadv_bcast_packet, ttl) != ttl_offset);
249 	BUILD_BUG_ON(offsetof(struct batadv_mcast_packet, ttl) != ttl_offset);
250 	BUILD_BUG_ON(offsetof(struct batadv_coded_packet, ttl) != ttl_offset);
251 	BUILD_BUG_ON(offsetof(struct batadv_unicast_tvlv_packet, ttl) != ttl_offset);
252 
253 	ttl_pos = skb->data + ttl_offset;
254 
255 	/* would expire on this hop -> drop, leave header + csum untouched */
256 	if (*ttl_pos < 2)
257 		return false;
258 
259 	skb_postpull_rcsum(skb, ttl_pos, 1);
260 	(*ttl_pos)--;
261 	skb_postpush_rcsum(skb, ttl_pos, 1);
262 
263 	return true;
264 }
265 
266 /**
267  * batadv_recv_my_icmp_packet() - receive an icmp packet locally
268  * @bat_priv: the bat priv with all the mesh interface information
269  * @skb: icmp packet to process
270  *
271  * Return: NET_RX_SUCCESS on success or NET_RX_DROP in case of failure
272  */
batadv_recv_my_icmp_packet(struct batadv_priv * bat_priv,struct sk_buff * skb)273 static int batadv_recv_my_icmp_packet(struct batadv_priv *bat_priv,
274 				      struct sk_buff *skb)
275 {
276 	struct batadv_hard_iface *primary_if = NULL;
277 	struct batadv_orig_node *orig_node = NULL;
278 	struct batadv_icmp_header *icmph;
279 	int ret = NET_RX_DROP;
280 	int res;
281 
282 	icmph = (struct batadv_icmp_header *)skb->data;
283 
284 	switch (icmph->msg_type) {
285 	case BATADV_ECHO_REQUEST:
286 		/* answer echo request (ping) */
287 		primary_if = batadv_primary_if_get_selected(bat_priv);
288 		if (!primary_if)
289 			goto out;
290 
291 		/* get routing information */
292 		orig_node = batadv_orig_hash_find(bat_priv, icmph->orig);
293 		if (!orig_node)
294 			goto out;
295 
296 		/* create a copy of the skb, if needed, to modify it. */
297 		if (skb_cow(skb, ETH_HLEN) < 0)
298 			goto out;
299 
300 		icmph = (struct batadv_icmp_header *)skb->data;
301 
302 		ether_addr_copy(icmph->dst, icmph->orig);
303 		ether_addr_copy(icmph->orig, primary_if->net_dev->dev_addr);
304 		icmph->msg_type = BATADV_ECHO_REPLY;
305 		icmph->ttl = BATADV_TTL;
306 
307 		res = batadv_send_skb_to_orig(skb, orig_node, NULL);
308 		if (res == NET_XMIT_SUCCESS)
309 			ret = NET_RX_SUCCESS;
310 
311 		/* skb was consumed */
312 		skb = NULL;
313 		break;
314 	case BATADV_TP:
315 		if (!pskb_may_pull(skb, sizeof(struct batadv_icmp_tp_packet)))
316 			goto out;
317 
318 		batadv_tp_meter_recv(bat_priv, skb);
319 		ret = NET_RX_SUCCESS;
320 		/* skb was consumed */
321 		skb = NULL;
322 		goto out;
323 	default:
324 		/* drop unknown type */
325 		goto out;
326 	}
327 out:
328 	batadv_hardif_put(primary_if);
329 	batadv_orig_node_put(orig_node);
330 
331 	kfree_skb(skb);
332 
333 	return ret;
334 }
335 
336 /**
337  * batadv_recv_icmp_ttl_exceeded() - handle an ICMP packet that hit TTL 0
338  * @bat_priv: the bat priv with all the mesh interface information
339  * @skb: ICMP packet whose TTL has expired
340  *
341  * For traceroute-style ICMP echo requests, send a TTL exceeded reply back to
342  * the source. Other ICMP types are simply dropped.
343  *
344  * Return: NET_RX_SUCCESS if the reply was queued, NET_RX_DROP otherwise
345  */
batadv_recv_icmp_ttl_exceeded(struct batadv_priv * bat_priv,struct sk_buff * skb)346 static int batadv_recv_icmp_ttl_exceeded(struct batadv_priv *bat_priv,
347 					 struct sk_buff *skb)
348 {
349 	struct batadv_hard_iface *primary_if = NULL;
350 	struct batadv_orig_node *orig_node = NULL;
351 	struct batadv_icmp_packet *icmp_packet;
352 	int ret = NET_RX_DROP;
353 	int res;
354 
355 	icmp_packet = (struct batadv_icmp_packet *)skb->data;
356 
357 	/* send TTL exceeded if packet is an echo request (traceroute) */
358 	if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) {
359 		pr_debug("Warning - can't forward icmp packet from %pM to %pM: ttl exceeded\n",
360 			 icmp_packet->orig, icmp_packet->dst);
361 		goto out;
362 	}
363 
364 	primary_if = batadv_primary_if_get_selected(bat_priv);
365 	if (!primary_if)
366 		goto out;
367 
368 	/* get routing information */
369 	orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig);
370 	if (!orig_node)
371 		goto out;
372 
373 	/* create a copy of the skb, if needed, to modify it. */
374 	if (skb_cow(skb, ETH_HLEN) < 0)
375 		goto out;
376 
377 	icmp_packet = (struct batadv_icmp_packet *)skb->data;
378 
379 	ether_addr_copy(icmp_packet->dst, icmp_packet->orig);
380 	ether_addr_copy(icmp_packet->orig, primary_if->net_dev->dev_addr);
381 	icmp_packet->msg_type = BATADV_TTL_EXCEEDED;
382 	icmp_packet->ttl = BATADV_TTL;
383 
384 	res = batadv_send_skb_to_orig(skb, orig_node, NULL);
385 	if (res == NET_XMIT_SUCCESS)
386 		ret = NET_RX_SUCCESS;
387 
388 	/* skb was consumed */
389 	skb = NULL;
390 
391 out:
392 	batadv_hardif_put(primary_if);
393 	batadv_orig_node_put(orig_node);
394 
395 	kfree_skb(skb);
396 
397 	return ret;
398 }
399 
400 /**
401  * batadv_recv_icmp_packet() - Process incoming icmp packet
402  * @skb: incoming packet buffer
403  * @recv_if: incoming hard interface
404  *
405  * Return: NET_RX_SUCCESS on success or NET_RX_DROP in case of failure
406  */
batadv_recv_icmp_packet(struct sk_buff * skb,struct batadv_hard_iface * recv_if)407 int batadv_recv_icmp_packet(struct sk_buff *skb,
408 			    struct batadv_hard_iface *recv_if)
409 {
410 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
411 	int hdr_size = sizeof(struct batadv_icmp_header);
412 	struct batadv_icmp_packet_rr *icmp_packet_rr;
413 	struct batadv_orig_node *orig_node = NULL;
414 	struct batadv_icmp_header *icmph;
415 	struct ethhdr *ethhdr;
416 	int ret = NET_RX_DROP;
417 	int res;
418 
419 	/* drop packet if it has not necessary minimum size */
420 	if (unlikely(!pskb_may_pull(skb, hdr_size)))
421 		goto free_skb;
422 
423 	ethhdr = eth_hdr(skb);
424 
425 	/* packet with unicast indication but non-unicast recipient */
426 	if (!is_valid_ether_addr(ethhdr->h_dest))
427 		goto free_skb;
428 
429 	/* packet with broadcast/multicast sender address */
430 	if (is_multicast_ether_addr(ethhdr->h_source))
431 		goto free_skb;
432 
433 	/* not for me */
434 	if (!batadv_is_my_mac(bat_priv, ethhdr->h_dest))
435 		goto free_skb;
436 
437 	icmph = (struct batadv_icmp_header *)skb->data;
438 
439 	/* add record route information if not full */
440 	if ((icmph->msg_type == BATADV_ECHO_REPLY ||
441 	     icmph->msg_type == BATADV_ECHO_REQUEST) &&
442 	    skb->len >= sizeof(struct batadv_icmp_packet_rr)) {
443 		if (skb_linearize(skb) < 0)
444 			goto free_skb;
445 
446 		/* create a copy of the skb, if needed, to modify it. */
447 		if (skb_cow(skb, ETH_HLEN) < 0)
448 			goto free_skb;
449 
450 		ethhdr = eth_hdr(skb);
451 		icmph = (struct batadv_icmp_header *)skb->data;
452 		icmp_packet_rr = (struct batadv_icmp_packet_rr *)icmph;
453 		if (icmp_packet_rr->rr_cur >= BATADV_RR_LEN)
454 			goto free_skb;
455 
456 		ether_addr_copy(icmp_packet_rr->rr[icmp_packet_rr->rr_cur],
457 				ethhdr->h_dest);
458 		icmp_packet_rr->rr_cur++;
459 	}
460 
461 	/* packet for me */
462 	if (batadv_is_my_mac(bat_priv, icmph->dst))
463 		return batadv_recv_my_icmp_packet(bat_priv, skb);
464 
465 	/* TTL exceeded */
466 	if (icmph->ttl < 2)
467 		return batadv_recv_icmp_ttl_exceeded(bat_priv, skb);
468 
469 	/* get routing information */
470 	orig_node = batadv_orig_hash_find(bat_priv, icmph->dst);
471 	if (!orig_node)
472 		goto free_skb;
473 
474 	/* create a copy of the skb, if needed, to modify it. */
475 	if (skb_cow(skb, ETH_HLEN) < 0)
476 		goto put_orig_node;
477 
478 	icmph = (struct batadv_icmp_header *)skb->data;
479 
480 	/* decrement ttl */
481 	icmph->ttl--;
482 
483 	/* route it */
484 	res = batadv_send_skb_to_orig(skb, orig_node, recv_if);
485 	if (res == NET_XMIT_SUCCESS)
486 		ret = NET_RX_SUCCESS;
487 
488 	/* skb was consumed */
489 	skb = NULL;
490 
491 put_orig_node:
492 	batadv_orig_node_put(orig_node);
493 free_skb:
494 	kfree_skb(skb);
495 
496 	return ret;
497 }
498 
499 /**
500  * batadv_check_unicast_packet() - Check for malformed unicast packets
501  * @bat_priv: the bat priv with all the mesh interface information
502  * @skb: packet to check
503  * @hdr_size: size of header to pull
504  *
505  * Checks for short header and bad addresses in the given packet.
506  *
507  * Return: negative value when check fails and 0 otherwise. The negative value
508  * depends on the reason: -ENODATA for bad header, -EBADR for broadcast
509  * destination or source, and -EREMOTE for non-local (other host) destination.
510  */
batadv_check_unicast_packet(struct batadv_priv * bat_priv,struct sk_buff * skb,int hdr_size)511 static int batadv_check_unicast_packet(struct batadv_priv *bat_priv,
512 				       struct sk_buff *skb, int hdr_size)
513 {
514 	struct ethhdr *ethhdr;
515 
516 	/* drop packet if it has not necessary minimum size */
517 	if (unlikely(!pskb_may_pull(skb, hdr_size)))
518 		return -ENODATA;
519 
520 	ethhdr = eth_hdr(skb);
521 
522 	/* packet with unicast indication but non-unicast recipient */
523 	if (!is_valid_ether_addr(ethhdr->h_dest))
524 		return -EBADR;
525 
526 	/* packet with broadcast/multicast sender address */
527 	if (is_multicast_ether_addr(ethhdr->h_source))
528 		return -EBADR;
529 
530 	/* not for me */
531 	if (!batadv_is_my_mac(bat_priv, ethhdr->h_dest))
532 		return -EREMOTE;
533 
534 	return 0;
535 }
536 
537 /**
538  * batadv_last_bonding_get() - Get last_bonding_candidate of orig_node
539  * @orig_node: originator node whose last bonding candidate should be retrieved
540  *
541  * Return: last bonding candidate of router or NULL if not found
542  *
543  * The object is returned with refcounter increased by 1.
544  */
545 static struct batadv_orig_ifinfo *
batadv_last_bonding_get(struct batadv_orig_node * orig_node)546 batadv_last_bonding_get(struct batadv_orig_node *orig_node)
547 {
548 	struct batadv_orig_ifinfo *last_bonding_candidate;
549 
550 	spin_lock_bh(&orig_node->neigh_list_lock);
551 	last_bonding_candidate = orig_node->last_bonding_candidate;
552 
553 	if (last_bonding_candidate)
554 		kref_get(&last_bonding_candidate->refcount);
555 	spin_unlock_bh(&orig_node->neigh_list_lock);
556 
557 	return last_bonding_candidate;
558 }
559 
560 /**
561  * batadv_last_bonding_replace() - Replace last_bonding_candidate of orig_node
562  * @orig_node: originator node whose bonding candidates should be replaced
563  * @new_candidate: new bonding candidate or NULL
564  */
565 static void
batadv_last_bonding_replace(struct batadv_orig_node * orig_node,struct batadv_orig_ifinfo * new_candidate)566 batadv_last_bonding_replace(struct batadv_orig_node *orig_node,
567 			    struct batadv_orig_ifinfo *new_candidate)
568 {
569 	struct batadv_orig_ifinfo *old_candidate;
570 
571 	spin_lock_bh(&orig_node->neigh_list_lock);
572 	old_candidate = orig_node->last_bonding_candidate;
573 
574 	if (new_candidate)
575 		kref_get(&new_candidate->refcount);
576 	orig_node->last_bonding_candidate = new_candidate;
577 	spin_unlock_bh(&orig_node->neigh_list_lock);
578 
579 	batadv_orig_ifinfo_put(old_candidate);
580 }
581 
582 /**
583  * batadv_find_router() - find a suitable router for this originator
584  * @bat_priv: the bat priv with all the mesh interface information
585  * @orig_node: the destination node
586  * @recv_if: pointer to interface this packet was received on
587  *
588  * Return: the router which should be used for this orig_node on
589  * this interface, or NULL if not available.
590  */
591 struct batadv_neigh_node *
batadv_find_router(struct batadv_priv * bat_priv,struct batadv_orig_node * orig_node,struct batadv_hard_iface * recv_if)592 batadv_find_router(struct batadv_priv *bat_priv,
593 		   struct batadv_orig_node *orig_node,
594 		   struct batadv_hard_iface *recv_if)
595 {
596 	struct batadv_neigh_node *first_candidate_router = NULL;
597 	struct batadv_neigh_node *next_candidate_router = NULL;
598 	struct batadv_neigh_node *last_cand_router = NULL;
599 	struct batadv_orig_ifinfo *first_candidate = NULL;
600 	struct batadv_algo_ops *bao = bat_priv->algo_ops;
601 	struct batadv_orig_ifinfo *next_candidate = NULL;
602 	struct batadv_neigh_node *cand_router = NULL;
603 	struct batadv_orig_ifinfo *last_candidate;
604 	bool last_candidate_found = false;
605 	struct batadv_neigh_node *router;
606 	struct batadv_orig_ifinfo *cand;
607 
608 	if (!orig_node)
609 		return NULL;
610 
611 	router = batadv_orig_router_get(orig_node, recv_if);
612 
613 	if (!router)
614 		return router;
615 
616 	/* only consider bonding for recv_if == BATADV_IF_DEFAULT (first hop)
617 	 * and if activated.
618 	 */
619 	if (!(recv_if == BATADV_IF_DEFAULT && READ_ONCE(bat_priv->bonding)))
620 		return router;
621 
622 	/* bonding: loop through the list of possible routers found
623 	 * for the various outgoing interfaces and find a candidate after
624 	 * the last chosen bonding candidate (next_candidate). If no such
625 	 * router is found, use the first candidate found (the previously
626 	 * chosen bonding candidate might have been the last one in the list).
627 	 * If this can't be found either, return the previously chosen
628 	 * router - obviously there are no other candidates.
629 	 */
630 	rcu_read_lock();
631 	last_candidate = batadv_last_bonding_get(orig_node);
632 	if (last_candidate)
633 		last_cand_router = rcu_dereference(last_candidate->router);
634 
635 	hlist_for_each_entry_rcu(cand, &orig_node->ifinfo_list, list) {
636 		/* acquire some structures and references ... */
637 		if (!kref_get_unless_zero(&cand->refcount))
638 			continue;
639 
640 		cand_router = rcu_dereference(cand->router);
641 		if (!cand_router)
642 			goto next;
643 
644 		if (!kref_get_unless_zero(&cand_router->refcount)) {
645 			cand_router = NULL;
646 			goto next;
647 		}
648 
649 		/* alternative candidate should be good enough to be
650 		 * considered
651 		 */
652 		if (!bao->neigh.is_similar_or_better(cand_router,
653 						     cand->if_outgoing, router,
654 						     recv_if))
655 			goto next;
656 
657 		/* don't use the same router twice */
658 		if (last_cand_router == cand_router)
659 			goto next;
660 
661 		/* mark the first possible candidate */
662 		if (!first_candidate) {
663 			kref_get(&cand_router->refcount);
664 			kref_get(&cand->refcount);
665 			first_candidate = cand;
666 			first_candidate_router = cand_router;
667 		}
668 
669 		/* check if the loop has already passed the previously selected
670 		 * candidate ... this function should select the next candidate
671 		 * AFTER the previously used bonding candidate.
672 		 */
673 		if (!last_candidate || last_candidate_found) {
674 			next_candidate = cand;
675 			next_candidate_router = cand_router;
676 			break;
677 		}
678 
679 		if (last_candidate == cand)
680 			last_candidate_found = true;
681 next:
682 		/* free references */
683 		if (cand_router) {
684 			batadv_neigh_node_put(cand_router);
685 			cand_router = NULL;
686 		}
687 		batadv_orig_ifinfo_put(cand);
688 	}
689 	rcu_read_unlock();
690 
691 	/* After finding candidates, handle the three cases:
692 	 * 1) there is a next candidate, use that
693 	 * 2) there is no next candidate, use the first of the list
694 	 * 3) there is no candidate at all, return the default router
695 	 */
696 	if (next_candidate) {
697 		batadv_neigh_node_put(router);
698 
699 		kref_get(&next_candidate_router->refcount);
700 		router = next_candidate_router;
701 		batadv_last_bonding_replace(orig_node, next_candidate);
702 	} else if (first_candidate) {
703 		batadv_neigh_node_put(router);
704 
705 		kref_get(&first_candidate_router->refcount);
706 		router = first_candidate_router;
707 		batadv_last_bonding_replace(orig_node, first_candidate);
708 	} else {
709 		batadv_last_bonding_replace(orig_node, NULL);
710 	}
711 
712 	/* cleanup of candidates */
713 	if (first_candidate) {
714 		batadv_neigh_node_put(first_candidate_router);
715 		batadv_orig_ifinfo_put(first_candidate);
716 	}
717 
718 	if (next_candidate) {
719 		batadv_neigh_node_put(next_candidate_router);
720 		batadv_orig_ifinfo_put(next_candidate);
721 	}
722 
723 	batadv_orig_ifinfo_put(last_candidate);
724 
725 	return router;
726 }
727 
728 /**
729  * batadv_route_unicast_packet() - forward a unicast packet towards its
730  *  destination originator
731  * @skb: the received unicast packet
732  * @recv_if: interface on which the packet was received
733  *
734  * Decrement the TTL, look up the originator for the destination address and
735  * hand the packet over to batadv_send_skb_to_orig() for transmission. Drop
736  * the packet when the TTL is exhausted or no route exists.
737  *
738  * Return: NET_RX_SUCCESS if the packet was forwarded, NET_RX_DROP otherwise
739  */
batadv_route_unicast_packet(struct sk_buff * skb,struct batadv_hard_iface * recv_if)740 static int batadv_route_unicast_packet(struct sk_buff *skb,
741 				       struct batadv_hard_iface *recv_if)
742 {
743 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
744 	struct batadv_unicast_packet *unicast_packet;
745 	struct batadv_orig_node *orig_node = NULL;
746 	struct ethhdr *ethhdr = eth_hdr(skb);
747 	int ret = NET_RX_DROP;
748 	unsigned int len;
749 	int hdr_len;
750 	int res;
751 
752 	unicast_packet = (struct batadv_unicast_packet *)skb->data;
753 
754 	/* TTL exceeded */
755 	if (unicast_packet->ttl < 2) {
756 		pr_debug("Warning - can't forward unicast packet from %pM to %pM: ttl exceeded\n",
757 			 ethhdr->h_source, unicast_packet->dest);
758 		goto free_skb;
759 	}
760 
761 	/* get routing information */
762 	orig_node = batadv_orig_hash_find(bat_priv, unicast_packet->dest);
763 
764 	if (!orig_node)
765 		goto free_skb;
766 
767 	/* create a copy of the skb, if needed, to modify it. */
768 	if (skb_cow(skb, ETH_HLEN) < 0)
769 		goto put_orig_node;
770 
771 	/* decrement ttl */
772 	unicast_packet = (struct batadv_unicast_packet *)skb->data;
773 	unicast_packet->ttl--;
774 
775 	switch (unicast_packet->packet_type) {
776 	case BATADV_UNICAST_4ADDR:
777 		hdr_len = sizeof(struct batadv_unicast_4addr_packet);
778 		break;
779 	case BATADV_UNICAST:
780 		hdr_len = sizeof(struct batadv_unicast_packet);
781 		break;
782 	default:
783 		/* other packet types not supported - yet */
784 		hdr_len = -1;
785 		break;
786 	}
787 
788 	if (hdr_len > 0)
789 		batadv_skb_set_priority(skb, hdr_len);
790 
791 	len = skb->len;
792 	res = batadv_send_skb_to_orig(skb, orig_node, recv_if);
793 
794 	/* translate transmit result into receive result */
795 	if (res == NET_XMIT_SUCCESS) {
796 		ret = NET_RX_SUCCESS;
797 		/* skb was transmitted and consumed */
798 		batadv_inc_counter(bat_priv, BATADV_CNT_FORWARD);
799 		batadv_add_counter(bat_priv, BATADV_CNT_FORWARD_BYTES,
800 				   len + ETH_HLEN);
801 	}
802 
803 	/* skb was consumed */
804 	skb = NULL;
805 
806 put_orig_node:
807 	batadv_orig_node_put(orig_node);
808 free_skb:
809 	kfree_skb(skb);
810 
811 	return ret;
812 }
813 
814 /**
815  * batadv_reroute_unicast_packet() - update the unicast header for re-routing
816  * @bat_priv: the bat priv with all the mesh interface information
817  * @skb: unicast packet to process
818  * @unicast_packet: the unicast header to be updated
819  * @dst_addr: the payload destination
820  * @vid: VLAN identifier
821  *
822  * Search the translation table for dst_addr and update the unicast header with
823  * the new corresponding information (originator address where the destination
824  * client currently is and its known TTVN)
825  *
826  * Return: true if the packet header has been updated, false otherwise
827  */
828 static bool
batadv_reroute_unicast_packet(struct batadv_priv * bat_priv,struct sk_buff * skb,struct batadv_unicast_packet * unicast_packet,u8 * dst_addr,unsigned short vid)829 batadv_reroute_unicast_packet(struct batadv_priv *bat_priv, struct sk_buff *skb,
830 			      struct batadv_unicast_packet *unicast_packet,
831 			      u8 *dst_addr, unsigned short vid)
832 {
833 	struct batadv_hard_iface *primary_if = NULL;
834 	struct batadv_orig_node *orig_node = NULL;
835 	const u8 *orig_addr;
836 	bool ret = false;
837 	u8 orig_ttvn;
838 
839 	if (batadv_is_my_client(bat_priv, dst_addr, vid)) {
840 		primary_if = batadv_primary_if_get_selected(bat_priv);
841 		if (!primary_if)
842 			goto out;
843 		orig_addr = primary_if->net_dev->dev_addr;
844 		orig_ttvn = (u8)atomic_read(&bat_priv->tt.vn);
845 	} else {
846 		orig_node = batadv_transtable_search(bat_priv, NULL, dst_addr,
847 						     vid);
848 		if (!orig_node)
849 			goto out;
850 
851 		if (batadv_compare_eth(orig_node->orig, unicast_packet->dest))
852 			goto out;
853 
854 		orig_addr = orig_node->orig;
855 		orig_ttvn = READ_ONCE(orig_node->last_ttvn);
856 	}
857 
858 	/* update the packet header */
859 	skb_postpull_rcsum(skb, unicast_packet, sizeof(*unicast_packet));
860 	ether_addr_copy(unicast_packet->dest, orig_addr);
861 	unicast_packet->ttvn = orig_ttvn;
862 	skb_postpush_rcsum(skb, unicast_packet, sizeof(*unicast_packet));
863 
864 	ret = true;
865 out:
866 	batadv_hardif_put(primary_if);
867 	batadv_orig_node_put(orig_node);
868 
869 	return ret;
870 }
871 
872 /**
873  * batadv_check_unicast_ttvn() - check and adjust the TTVN of a unicast packet
874  * @bat_priv: the bat priv with all the mesh interface information
875  * @skb: the unicast packet to check
876  * @hdr_len: length of the unicast header preceding the payload
877  *
878  * Warning: This function may reallocate the skb data buffer via
879  * pskb_may_pull()/batadv_get_vid()/... Any pointer into the skb data (e.g.
880  * obtained from skb->data or eth_hdr()) before this call must be considered
881  * invalid afterwards and has to be reacquired.
882  *
883  * Return: true if the packet may be processed further, false if has to be
884  * dropped by the caller
885  */
batadv_check_unicast_ttvn(struct batadv_priv * bat_priv,struct sk_buff * skb,int hdr_len)886 static bool batadv_check_unicast_ttvn(struct batadv_priv *bat_priv,
887 				      struct sk_buff *skb, int hdr_len)
888 {
889 	struct batadv_unicast_packet *unicast_packet;
890 	struct batadv_hard_iface *primary_if;
891 	struct batadv_orig_node *orig_node;
892 	struct ethhdr *ethhdr;
893 	unsigned short vid;
894 	int is_old_ttvn;
895 	u8 curr_ttvn;
896 	u8 old_ttvn;
897 
898 	/* check if there is enough data before accessing it */
899 	if (!pskb_may_pull(skb, hdr_len + ETH_HLEN))
900 		return false;
901 
902 	/* create a copy of the skb (in case of for re-routing) to modify it. */
903 	if (skb_cow(skb, sizeof(*unicast_packet)) < 0)
904 		return false;
905 
906 	vid = batadv_get_vid(skb, hdr_len);
907 	unicast_packet = (struct batadv_unicast_packet *)skb->data;
908 	ethhdr = (struct ethhdr *)(skb->data + hdr_len);
909 
910 	/* do not reroute multicast frames in a unicast header */
911 	if (is_multicast_ether_addr(ethhdr->h_dest))
912 		return true;
913 
914 	/* check if the destination client was served by this node and it is now
915 	 * roaming. In this case, it means that the node has got a ROAM_ADV
916 	 * message and that it knows the new destination in the mesh to re-route
917 	 * the packet to
918 	 */
919 	if (batadv_tt_local_client_is_roaming(bat_priv, ethhdr->h_dest, vid)) {
920 		if (batadv_reroute_unicast_packet(bat_priv, skb, unicast_packet,
921 						  ethhdr->h_dest, vid))
922 			batadv_dbg_ratelimited(BATADV_DBG_TT,
923 					       bat_priv,
924 					       "Rerouting unicast packet to %pM (dst=%pM): Local Roaming\n",
925 					       unicast_packet->dest,
926 					       ethhdr->h_dest);
927 		/* at this point the mesh destination should have been
928 		 * substituted with the originator address found in the global
929 		 * table. If not, let the packet go untouched anyway because
930 		 * there is nothing the node can do
931 		 */
932 		return true;
933 	}
934 
935 	/* retrieve the TTVN known by this node for the packet destination. This
936 	 * value is used later to check if the node which sent (or re-routed
937 	 * last time) the packet had an updated information or not
938 	 */
939 	curr_ttvn = (u8)atomic_read(&bat_priv->tt.vn);
940 	if (!batadv_is_my_mac(bat_priv, unicast_packet->dest)) {
941 		orig_node = batadv_orig_hash_find(bat_priv,
942 						  unicast_packet->dest);
943 		/* if it is not possible to find the orig_node representing the
944 		 * destination, the packet can immediately be dropped as it will
945 		 * not be possible to deliver it
946 		 */
947 		if (!orig_node)
948 			return false;
949 
950 		curr_ttvn = READ_ONCE(orig_node->last_ttvn);
951 		batadv_orig_node_put(orig_node);
952 	}
953 
954 	/* check if the TTVN contained in the packet is fresher than what the
955 	 * node knows
956 	 */
957 	is_old_ttvn = batadv_seq_before(unicast_packet->ttvn, curr_ttvn);
958 	if (!is_old_ttvn)
959 		return true;
960 
961 	old_ttvn = unicast_packet->ttvn;
962 	/* the packet was forged based on outdated network information. Its
963 	 * destination can possibly be updated and forwarded towards the new
964 	 * target host
965 	 */
966 	if (batadv_reroute_unicast_packet(bat_priv, skb, unicast_packet,
967 					  ethhdr->h_dest, vid)) {
968 		batadv_dbg_ratelimited(BATADV_DBG_TT, bat_priv,
969 				       "Rerouting unicast packet to %pM (dst=%pM): TTVN mismatch old_ttvn=%u new_ttvn=%u\n",
970 				       unicast_packet->dest, ethhdr->h_dest,
971 				       old_ttvn, curr_ttvn);
972 		return true;
973 	}
974 
975 	/* the packet has not been re-routed: either the destination is
976 	 * currently served by this node or there is no destination at all and
977 	 * it is possible to drop the packet
978 	 */
979 	if (!batadv_is_my_client(bat_priv, ethhdr->h_dest, vid))
980 		return false;
981 
982 	/* update the header in order to let the packet be delivered to this
983 	 * node's mesh interface
984 	 */
985 	primary_if = batadv_primary_if_get_selected(bat_priv);
986 	if (!primary_if)
987 		return false;
988 
989 	/* update the packet header */
990 	skb_postpull_rcsum(skb, unicast_packet, sizeof(*unicast_packet));
991 	ether_addr_copy(unicast_packet->dest, primary_if->net_dev->dev_addr);
992 	unicast_packet->ttvn = curr_ttvn;
993 	skb_postpush_rcsum(skb, unicast_packet, sizeof(*unicast_packet));
994 
995 	batadv_hardif_put(primary_if);
996 
997 	return true;
998 }
999 
1000 /**
1001  * batadv_recv_unhandled_unicast_packet() - receive and process packets which
1002  *	are in the unicast number space but not yet known to the implementation
1003  * @skb: unicast tvlv packet to process
1004  * @recv_if: pointer to interface this packet was received on
1005  *
1006  * Return: NET_RX_SUCCESS on success or NET_RX_DROP in case of failure
1007  */
batadv_recv_unhandled_unicast_packet(struct sk_buff * skb,struct batadv_hard_iface * recv_if)1008 int batadv_recv_unhandled_unicast_packet(struct sk_buff *skb,
1009 					 struct batadv_hard_iface *recv_if)
1010 {
1011 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
1012 	struct batadv_unicast_packet *unicast_packet;
1013 	int hdr_size = sizeof(*unicast_packet);
1014 	int check;
1015 
1016 	check = batadv_check_unicast_packet(bat_priv, skb, hdr_size);
1017 	if (check < 0)
1018 		goto free_skb;
1019 
1020 	/* we don't know about this type, drop it. */
1021 	unicast_packet = (struct batadv_unicast_packet *)skb->data;
1022 	if (batadv_is_my_mac(bat_priv, unicast_packet->dest))
1023 		goto free_skb;
1024 
1025 	return batadv_route_unicast_packet(skb, recv_if);
1026 
1027 free_skb:
1028 	kfree_skb(skb);
1029 	return NET_RX_DROP;
1030 }
1031 
1032 /**
1033  * batadv_recv_unicast_packet() - Process incoming unicast packet
1034  * @skb: incoming packet buffer
1035  * @recv_if: incoming hard interface
1036  *
1037  * Return: NET_RX_SUCCESS on success or NET_RX_DROP in case of failure
1038  */
batadv_recv_unicast_packet(struct sk_buff * skb,struct batadv_hard_iface * recv_if)1039 int batadv_recv_unicast_packet(struct sk_buff *skb,
1040 			       struct batadv_hard_iface *recv_if)
1041 {
1042 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
1043 	struct batadv_unicast_4addr_packet *unicast_4addr_packet;
1044 	struct batadv_unicast_packet *unicast_packet;
1045 	struct batadv_orig_node *orig_node_gw = NULL;
1046 	struct batadv_orig_node *orig_node = NULL;
1047 	int hdr_size = sizeof(*unicast_packet);
1048 	enum batadv_subtype subtype;
1049 	int ret = NET_RX_DROP;
1050 	u8 *orig_addr_gw;
1051 	u8 *orig_addr;
1052 	bool is4addr;
1053 	bool is_gw;
1054 	int check;
1055 
1056 	unicast_packet = (struct batadv_unicast_packet *)skb->data;
1057 	is4addr = unicast_packet->packet_type == BATADV_UNICAST_4ADDR;
1058 	/* the caller function should have already pulled 2 bytes */
1059 	if (is4addr)
1060 		hdr_size = sizeof(*unicast_4addr_packet);
1061 
1062 	/* function returns -EREMOTE for promiscuous packets */
1063 	check = batadv_check_unicast_packet(bat_priv, skb, hdr_size);
1064 	if (check < 0)
1065 		goto free_skb;
1066 
1067 	if (!batadv_check_unicast_ttvn(bat_priv, skb, hdr_size))
1068 		goto free_skb;
1069 
1070 	unicast_packet = (struct batadv_unicast_packet *)skb->data;
1071 
1072 	/* packet for me */
1073 	if (batadv_is_my_mac(bat_priv, unicast_packet->dest)) {
1074 		/* If this is a unicast packet from another backgone gw,
1075 		 * drop it.
1076 		 */
1077 		orig_addr_gw = eth_hdr(skb)->h_source;
1078 		orig_node_gw = batadv_orig_hash_find(bat_priv, orig_addr_gw);
1079 		if (orig_node_gw) {
1080 			is_gw = batadv_bla_is_backbone_gw(skb, orig_node_gw,
1081 							  hdr_size);
1082 			batadv_orig_node_put(orig_node_gw);
1083 			if (is_gw) {
1084 				orig_addr_gw = eth_hdr(skb)->h_source;
1085 				batadv_dbg(BATADV_DBG_BLA, bat_priv,
1086 					   "%s(): Dropped unicast pkt received from another backbone gw %pM.\n",
1087 					   __func__, orig_addr_gw);
1088 				goto free_skb;
1089 			}
1090 		}
1091 
1092 		if (is4addr) {
1093 			unicast_4addr_packet =
1094 				(struct batadv_unicast_4addr_packet *)skb->data;
1095 			subtype = unicast_4addr_packet->subtype;
1096 			batadv_dat_inc_counter(bat_priv, subtype);
1097 
1098 			/* Only payload data should be considered for speedy
1099 			 * join. For example, DAT also uses unicast 4addr
1100 			 * types, but those packets should not be considered
1101 			 * for speedy join, since the clients do not actually
1102 			 * reside at the sending originator.
1103 			 */
1104 			if (subtype == BATADV_P_DATA) {
1105 				orig_addr = unicast_4addr_packet->src;
1106 				orig_node = batadv_orig_hash_find(bat_priv,
1107 								  orig_addr);
1108 			}
1109 		}
1110 
1111 		if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb,
1112 							  hdr_size))
1113 			goto rx_success;
1114 		if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb,
1115 							hdr_size))
1116 			goto rx_success;
1117 
1118 		batadv_dat_snoop_incoming_dhcp_ack(bat_priv, skb, hdr_size);
1119 
1120 		batadv_interface_rx(recv_if->mesh_iface, skb, hdr_size,
1121 				    orig_node);
1122 
1123 rx_success:
1124 		batadv_orig_node_put(orig_node);
1125 
1126 		return NET_RX_SUCCESS;
1127 	}
1128 
1129 	ret = batadv_route_unicast_packet(skb, recv_if);
1130 	/* skb was consumed */
1131 	skb = NULL;
1132 
1133 free_skb:
1134 	kfree_skb(skb);
1135 
1136 	return ret;
1137 }
1138 
1139 /**
1140  * batadv_recv_unicast_tvlv() - receive and process unicast tvlv packets
1141  * @skb: unicast tvlv packet to process
1142  * @recv_if: pointer to interface this packet was received on
1143  *
1144  * Return: NET_RX_SUCCESS on success or NET_RX_DROP in case of failure
1145  */
batadv_recv_unicast_tvlv(struct sk_buff * skb,struct batadv_hard_iface * recv_if)1146 int batadv_recv_unicast_tvlv(struct sk_buff *skb,
1147 			     struct batadv_hard_iface *recv_if)
1148 {
1149 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
1150 	struct batadv_unicast_tvlv_packet *unicast_tvlv_packet;
1151 	int hdr_size = sizeof(*unicast_tvlv_packet);
1152 	unsigned char *tvlv_buff;
1153 	int ret = NET_RX_DROP;
1154 	u16 tvlv_buff_len;
1155 
1156 	if (batadv_check_unicast_packet(bat_priv, skb, hdr_size) < 0)
1157 		goto free_skb;
1158 
1159 	/* the header is likely to be modified while forwarding */
1160 	if (skb_cow(skb, hdr_size) < 0)
1161 		goto free_skb;
1162 
1163 	/* packet needs to be linearized to access the tvlv content */
1164 	if (skb_linearize(skb) < 0)
1165 		goto free_skb;
1166 
1167 	unicast_tvlv_packet = (struct batadv_unicast_tvlv_packet *)skb->data;
1168 
1169 	tvlv_buff = (unsigned char *)(skb->data + hdr_size);
1170 	tvlv_buff_len = ntohs(unicast_tvlv_packet->tvlv_len);
1171 
1172 	if (tvlv_buff_len > skb->len - hdr_size)
1173 		goto free_skb;
1174 
1175 	ret = batadv_tvlv_containers_process(bat_priv, BATADV_UNICAST_TVLV,
1176 					     NULL, skb, tvlv_buff,
1177 					     tvlv_buff_len);
1178 
1179 	if (ret != NET_RX_SUCCESS) {
1180 		ret = batadv_route_unicast_packet(skb, recv_if);
1181 		/* skb was consumed */
1182 		skb = NULL;
1183 	}
1184 
1185 free_skb:
1186 	kfree_skb(skb);
1187 
1188 	return ret;
1189 }
1190 
1191 /**
1192  * batadv_recv_frag_packet() - process received fragment
1193  * @skb: the received fragment
1194  * @recv_if: interface that the skb is received on
1195  *
1196  * This function does one of the three following things: 1) Forward fragment, if
1197  * the assembled packet will exceed our MTU; 2) Buffer fragment, if we still
1198  * lack further fragments; 3) Merge fragments, if we have all needed parts.
1199  *
1200  * Return: NET_RX_SUCCESS on success or NET_RX_DROP in case of failure
1201  */
batadv_recv_frag_packet(struct sk_buff * skb,struct batadv_hard_iface * recv_if)1202 int batadv_recv_frag_packet(struct sk_buff *skb,
1203 			    struct batadv_hard_iface *recv_if)
1204 {
1205 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
1206 	struct batadv_orig_node *orig_node_src = NULL;
1207 	struct batadv_frag_packet *frag_packet;
1208 	int ret = NET_RX_DROP;
1209 
1210 	if (batadv_check_unicast_packet(bat_priv, skb,
1211 					sizeof(*frag_packet)) < 0)
1212 		goto free_skb;
1213 
1214 	frag_packet = (struct batadv_frag_packet *)skb->data;
1215 	orig_node_src = batadv_orig_hash_find(bat_priv, frag_packet->orig);
1216 	if (!orig_node_src)
1217 		goto free_skb;
1218 
1219 	skb->priority = frag_packet->priority + 256;
1220 
1221 	/* Route the fragment if it is not for us and too big to be merged. */
1222 	if (!batadv_is_my_mac(bat_priv, frag_packet->dest) &&
1223 	    batadv_frag_skb_fwd(skb, recv_if, orig_node_src, &ret)) {
1224 		/* skb was consumed */
1225 		skb = NULL;
1226 		goto put_orig_node;
1227 	}
1228 
1229 	batadv_inc_counter(bat_priv, BATADV_CNT_FRAG_RX);
1230 	batadv_add_counter(bat_priv, BATADV_CNT_FRAG_RX_BYTES, skb->len);
1231 
1232 	/* Add fragment to buffer and merge if possible. */
1233 	if (!batadv_frag_skb_buffer(&skb, orig_node_src))
1234 		goto put_orig_node;
1235 
1236 	/* Deliver merged packet to the appropriate handler, if it was
1237 	 * merged
1238 	 */
1239 	if (skb) {
1240 		batadv_batman_skb_recv(skb, recv_if->net_dev,
1241 				       &recv_if->batman_adv_ptype, NULL);
1242 		/* skb was consumed */
1243 		skb = NULL;
1244 	}
1245 
1246 	ret = NET_RX_SUCCESS;
1247 
1248 put_orig_node:
1249 	batadv_orig_node_put(orig_node_src);
1250 free_skb:
1251 	kfree_skb(skb);
1252 
1253 	return ret;
1254 }
1255 
1256 /**
1257  * batadv_recv_bcast_packet() - Process incoming broadcast packet
1258  * @skb: incoming packet buffer
1259  * @recv_if: incoming hard interface
1260  *
1261  * Return: NET_RX_SUCCESS on success or NET_RX_DROP in case of failure
1262  */
batadv_recv_bcast_packet(struct sk_buff * skb,struct batadv_hard_iface * recv_if)1263 int batadv_recv_bcast_packet(struct sk_buff *skb,
1264 			     struct batadv_hard_iface *recv_if)
1265 {
1266 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
1267 	struct batadv_orig_node *orig_node = NULL;
1268 	struct batadv_bcast_packet *bcast_packet;
1269 	int hdr_size = sizeof(*bcast_packet);
1270 	struct ethhdr *ethhdr;
1271 	s32 seq_diff;
1272 	u32 seqno;
1273 	int ret;
1274 
1275 	/* drop packet if it has not necessary minimum size */
1276 	if (unlikely(!pskb_may_pull(skb, hdr_size)))
1277 		goto free_skb;
1278 
1279 	ethhdr = eth_hdr(skb);
1280 
1281 	/* packet with broadcast indication but unicast recipient */
1282 	if (!is_broadcast_ether_addr(ethhdr->h_dest))
1283 		goto free_skb;
1284 
1285 	/* packet with broadcast/multicast sender address */
1286 	if (is_multicast_ether_addr(ethhdr->h_source))
1287 		goto free_skb;
1288 
1289 	/* ignore broadcasts sent by myself */
1290 	if (batadv_is_my_mac(bat_priv, ethhdr->h_source))
1291 		goto free_skb;
1292 
1293 	bcast_packet = (struct batadv_bcast_packet *)skb->data;
1294 
1295 	/* ignore broadcasts originated by myself */
1296 	if (batadv_is_my_mac(bat_priv, bcast_packet->orig))
1297 		goto free_skb;
1298 
1299 	/* create a copy of the skb, if needed, to modify it. */
1300 	if (skb_cow(skb, ETH_HLEN) < 0)
1301 		goto free_skb;
1302 
1303 	bcast_packet = (struct batadv_bcast_packet *)skb->data;
1304 
1305 	if (!batadv_skb_decrement_ttl(skb))
1306 		goto free_skb;
1307 
1308 	orig_node = batadv_orig_hash_find(bat_priv, bcast_packet->orig);
1309 
1310 	if (!orig_node)
1311 		goto free_skb;
1312 
1313 	spin_lock_bh(&orig_node->bcast_seqno_lock);
1314 
1315 	seqno = ntohl(bcast_packet->seqno);
1316 	/* check whether the packet is a duplicate */
1317 	if (batadv_test_bit(orig_node->bcast_bits, orig_node->last_bcast_seqno,
1318 			    seqno))
1319 		goto spin_unlock;
1320 
1321 	seq_diff = seqno - orig_node->last_bcast_seqno;
1322 
1323 	/* check whether the packet is old and the host just restarted. */
1324 	if (batadv_window_protected(bat_priv, seq_diff,
1325 				    BATADV_BCAST_MAX_AGE,
1326 				    &orig_node->bcast_seqno_reset, NULL))
1327 		goto spin_unlock;
1328 
1329 	/* mark broadcast in flood history, update window position
1330 	 * if required.
1331 	 */
1332 	if (batadv_bit_get_packet(bat_priv, orig_node->bcast_bits, seq_diff, 1))
1333 		orig_node->last_bcast_seqno = seqno;
1334 
1335 	spin_unlock_bh(&orig_node->bcast_seqno_lock);
1336 
1337 	/* check whether this has been sent by another originator before */
1338 	if (batadv_bla_check_bcast_duplist(bat_priv, skb))
1339 		goto free_skb;
1340 
1341 	batadv_skb_set_priority(skb, sizeof(struct batadv_bcast_packet));
1342 
1343 	/* rebroadcast packet */
1344 	ret = batadv_forw_bcast_packet(bat_priv, skb, 0, false);
1345 	if (ret == NETDEV_TX_BUSY)
1346 		goto free_skb;
1347 
1348 	/* don't hand the broadcast up if it is from an originator
1349 	 * from the same backbone.
1350 	 */
1351 	if (batadv_bla_is_backbone_gw(skb, orig_node, hdr_size))
1352 		goto free_skb;
1353 
1354 	if (batadv_dat_snoop_incoming_arp_request(bat_priv, skb, hdr_size))
1355 		goto rx_success;
1356 	if (batadv_dat_snoop_incoming_arp_reply(bat_priv, skb, hdr_size))
1357 		goto rx_success;
1358 
1359 	batadv_dat_snoop_incoming_dhcp_ack(bat_priv, skb, hdr_size);
1360 
1361 	/* broadcast for me */
1362 	batadv_interface_rx(recv_if->mesh_iface, skb, hdr_size, orig_node);
1363 
1364 rx_success:
1365 	ret = NET_RX_SUCCESS;
1366 	goto out;
1367 
1368 spin_unlock:
1369 	spin_unlock_bh(&orig_node->bcast_seqno_lock);
1370 free_skb:
1371 	kfree_skb(skb);
1372 	ret = NET_RX_DROP;
1373 out:
1374 	batadv_orig_node_put(orig_node);
1375 	return ret;
1376 }
1377 
1378 #ifdef CONFIG_BATMAN_ADV_MCAST
1379 /**
1380  * batadv_recv_mcast_packet() - process received batman-adv multicast packet
1381  * @skb: the received batman-adv multicast packet
1382  * @recv_if: interface that the skb is received on
1383  *
1384  * Parses the given, received batman-adv multicast packet. Depending on the
1385  * contents of its TVLV forwards it and/or decapsulates it to hand it to the
1386  * mesh interface.
1387  *
1388  * Return: NET_RX_SUCCESS if the skb was locally received, NET_RX_DROP otherwise
1389  * or a negative errno code when the multicast tracker TVLV could not be
1390  * processed
1391  */
batadv_recv_mcast_packet(struct sk_buff * skb,struct batadv_hard_iface * recv_if)1392 int batadv_recv_mcast_packet(struct sk_buff *skb,
1393 			     struct batadv_hard_iface *recv_if)
1394 {
1395 	struct batadv_priv *bat_priv = netdev_priv(recv_if->mesh_iface);
1396 	struct batadv_mcast_packet *mcast_packet;
1397 	int hdr_size = sizeof(*mcast_packet);
1398 	unsigned char *tvlv_buff;
1399 	int ret = NET_RX_DROP;
1400 	u16 tvlv_buff_len;
1401 
1402 	if (batadv_check_unicast_packet(bat_priv, skb, hdr_size) < 0)
1403 		goto free_skb;
1404 
1405 	/* create a copy of the skb, if needed, to modify it. */
1406 	if (skb_cow(skb, ETH_HLEN) < 0)
1407 		goto free_skb;
1408 
1409 	/* packet needs to be linearized to access the tvlv content */
1410 	if (skb_linearize(skb) < 0)
1411 		goto free_skb;
1412 
1413 	mcast_packet = (struct batadv_mcast_packet *)skb->data;
1414 	if (!batadv_skb_decrement_ttl(skb))
1415 		goto free_skb;
1416 
1417 	tvlv_buff = (unsigned char *)(skb->data + hdr_size);
1418 	tvlv_buff_len = ntohs(mcast_packet->tvlv_len);
1419 
1420 	if (tvlv_buff_len > skb->len - hdr_size)
1421 		goto free_skb;
1422 
1423 	/* the fields of an multicast payload are accessed assuming (at least)
1424 	 * 2-byte alignment, so a following packet must start at an even offset.
1425 	 */
1426 	if (tvlv_buff_len & 1)
1427 		goto free_skb;
1428 
1429 	ret = batadv_tvlv_containers_process(bat_priv, BATADV_MCAST, NULL, skb,
1430 					     tvlv_buff, tvlv_buff_len);
1431 	if (ret >= 0) {
1432 		batadv_inc_counter(bat_priv, BATADV_CNT_MCAST_RX);
1433 		batadv_add_counter(bat_priv, BATADV_CNT_MCAST_RX_BYTES,
1434 				   skb->len + ETH_HLEN);
1435 	}
1436 
1437 	hdr_size += tvlv_buff_len;
1438 
1439 	if (ret == NET_RX_SUCCESS && (skb->len - hdr_size >= ETH_HLEN)) {
1440 		batadv_inc_counter(bat_priv, BATADV_CNT_MCAST_RX_LOCAL);
1441 		batadv_add_counter(bat_priv, BATADV_CNT_MCAST_RX_LOCAL_BYTES,
1442 				   skb->len - hdr_size);
1443 
1444 		batadv_interface_rx(bat_priv->mesh_iface, skb, hdr_size, NULL);
1445 		/* skb was consumed */
1446 		skb = NULL;
1447 	}
1448 
1449 free_skb:
1450 	kfree_skb(skb);
1451 
1452 	return ret;
1453 }
1454 #endif /* CONFIG_BATMAN_ADV_MCAST */
1455