xref: /linux/net/batman-adv/routing.c (revision 9455e34cb2ded22e01abb6daa65ba1caeed8d7fe)
1 /*
2  * Copyright (C) 2007-2012 B.A.T.M.A.N. contributors:
3  *
4  * Marek Lindner, Simon Wunderlich
5  *
6  * This program is free software; you can redistribute it and/or
7  * modify it under the terms of version 2 of the GNU General Public
8  * License as published by the Free Software Foundation.
9  *
10  * This program is distributed in the hope that it will be useful, but
11  * WITHOUT ANY WARRANTY; without even the implied warranty of
12  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13  * General Public License for more details.
14  *
15  * You should have received a copy of the GNU General Public License
16  * along with this program; if not, write to the Free Software
17  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
18  * 02110-1301, USA
19  *
20  */
21 
22 #include "main.h"
23 #include "routing.h"
24 #include "send.h"
25 #include "soft-interface.h"
26 #include "hard-interface.h"
27 #include "icmp_socket.h"
28 #include "translation-table.h"
29 #include "originator.h"
30 #include "vis.h"
31 #include "unicast.h"
32 #include "bridge_loop_avoidance.h"
33 
34 static int route_unicast_packet(struct sk_buff *skb,
35 				struct hard_iface *recv_if);
36 
37 void batadv_slide_own_bcast_window(struct hard_iface *hard_iface)
38 {
39 	struct bat_priv *bat_priv = netdev_priv(hard_iface->soft_iface);
40 	struct hashtable_t *hash = bat_priv->orig_hash;
41 	struct hlist_node *node;
42 	struct hlist_head *head;
43 	struct orig_node *orig_node;
44 	unsigned long *word;
45 	uint32_t i;
46 	size_t word_index;
47 
48 	for (i = 0; i < hash->size; i++) {
49 		head = &hash->table[i];
50 
51 		rcu_read_lock();
52 		hlist_for_each_entry_rcu(orig_node, node, head, hash_entry) {
53 			spin_lock_bh(&orig_node->ogm_cnt_lock);
54 			word_index = hard_iface->if_num * NUM_WORDS;
55 			word = &(orig_node->bcast_own[word_index]);
56 
57 			batadv_bit_get_packet(bat_priv, word, 1, 0);
58 			orig_node->bcast_own_sum[hard_iface->if_num] =
59 				bitmap_weight(word, TQ_LOCAL_WINDOW_SIZE);
60 			spin_unlock_bh(&orig_node->ogm_cnt_lock);
61 		}
62 		rcu_read_unlock();
63 	}
64 }
65 
66 static void _update_route(struct bat_priv *bat_priv,
67 			  struct orig_node *orig_node,
68 			  struct neigh_node *neigh_node)
69 {
70 	struct neigh_node *curr_router;
71 
72 	curr_router = batadv_orig_node_get_router(orig_node);
73 
74 	/* route deleted */
75 	if ((curr_router) && (!neigh_node)) {
76 		bat_dbg(DBG_ROUTES, bat_priv, "Deleting route towards: %pM\n",
77 			orig_node->orig);
78 		tt_global_del_orig(bat_priv, orig_node,
79 				   "Deleted route towards originator");
80 
81 	/* route added */
82 	} else if ((!curr_router) && (neigh_node)) {
83 
84 		bat_dbg(DBG_ROUTES, bat_priv,
85 			"Adding route towards: %pM (via %pM)\n",
86 			orig_node->orig, neigh_node->addr);
87 	/* route changed */
88 	} else if (neigh_node && curr_router) {
89 		bat_dbg(DBG_ROUTES, bat_priv,
90 			"Changing route towards: %pM (now via %pM - was via %pM)\n",
91 			orig_node->orig, neigh_node->addr,
92 			curr_router->addr);
93 	}
94 
95 	if (curr_router)
96 		batadv_neigh_node_free_ref(curr_router);
97 
98 	/* increase refcount of new best neighbor */
99 	if (neigh_node && !atomic_inc_not_zero(&neigh_node->refcount))
100 		neigh_node = NULL;
101 
102 	spin_lock_bh(&orig_node->neigh_list_lock);
103 	rcu_assign_pointer(orig_node->router, neigh_node);
104 	spin_unlock_bh(&orig_node->neigh_list_lock);
105 
106 	/* decrease refcount of previous best neighbor */
107 	if (curr_router)
108 		batadv_neigh_node_free_ref(curr_router);
109 }
110 
111 void batadv_update_route(struct bat_priv *bat_priv, struct orig_node *orig_node,
112 			 struct neigh_node *neigh_node)
113 {
114 	struct neigh_node *router = NULL;
115 
116 	if (!orig_node)
117 		goto out;
118 
119 	router = batadv_orig_node_get_router(orig_node);
120 
121 	if (router != neigh_node)
122 		_update_route(bat_priv, orig_node, neigh_node);
123 
124 out:
125 	if (router)
126 		batadv_neigh_node_free_ref(router);
127 }
128 
129 /* caller must hold the neigh_list_lock */
130 void batadv_bonding_candidate_del(struct orig_node *orig_node,
131 				  struct neigh_node *neigh_node)
132 {
133 	/* this neighbor is not part of our candidate list */
134 	if (list_empty(&neigh_node->bonding_list))
135 		goto out;
136 
137 	list_del_rcu(&neigh_node->bonding_list);
138 	INIT_LIST_HEAD(&neigh_node->bonding_list);
139 	batadv_neigh_node_free_ref(neigh_node);
140 	atomic_dec(&orig_node->bond_candidates);
141 
142 out:
143 	return;
144 }
145 
146 void batadv_bonding_candidate_add(struct orig_node *orig_node,
147 				  struct neigh_node *neigh_node)
148 {
149 	struct hlist_node *node;
150 	struct neigh_node *tmp_neigh_node, *router = NULL;
151 	uint8_t interference_candidate = 0;
152 
153 	spin_lock_bh(&orig_node->neigh_list_lock);
154 
155 	/* only consider if it has the same primary address ...  */
156 	if (!compare_eth(orig_node->orig,
157 			 neigh_node->orig_node->primary_addr))
158 		goto candidate_del;
159 
160 	router = batadv_orig_node_get_router(orig_node);
161 	if (!router)
162 		goto candidate_del;
163 
164 	/* ... and is good enough to be considered */
165 	if (neigh_node->tq_avg < router->tq_avg - BONDING_TQ_THRESHOLD)
166 		goto candidate_del;
167 
168 	/**
169 	 * check if we have another candidate with the same mac address or
170 	 * interface. If we do, we won't select this candidate because of
171 	 * possible interference.
172 	 */
173 	hlist_for_each_entry_rcu(tmp_neigh_node, node,
174 				 &orig_node->neigh_list, list) {
175 
176 		if (tmp_neigh_node == neigh_node)
177 			continue;
178 
179 		/* we only care if the other candidate is even
180 		* considered as candidate. */
181 		if (list_empty(&tmp_neigh_node->bonding_list))
182 			continue;
183 
184 		if ((neigh_node->if_incoming == tmp_neigh_node->if_incoming) ||
185 		    (compare_eth(neigh_node->addr, tmp_neigh_node->addr))) {
186 			interference_candidate = 1;
187 			break;
188 		}
189 	}
190 
191 	/* don't care further if it is an interference candidate */
192 	if (interference_candidate)
193 		goto candidate_del;
194 
195 	/* this neighbor already is part of our candidate list */
196 	if (!list_empty(&neigh_node->bonding_list))
197 		goto out;
198 
199 	if (!atomic_inc_not_zero(&neigh_node->refcount))
200 		goto out;
201 
202 	list_add_rcu(&neigh_node->bonding_list, &orig_node->bond_list);
203 	atomic_inc(&orig_node->bond_candidates);
204 	goto out;
205 
206 candidate_del:
207 	batadv_bonding_candidate_del(orig_node, neigh_node);
208 
209 out:
210 	spin_unlock_bh(&orig_node->neigh_list_lock);
211 
212 	if (router)
213 		batadv_neigh_node_free_ref(router);
214 }
215 
216 /* copy primary address for bonding */
217 void
218 batadv_bonding_save_primary(const struct orig_node *orig_node,
219 			    struct orig_node *orig_neigh_node,
220 			    const struct batman_ogm_packet *batman_ogm_packet)
221 {
222 	if (!(batman_ogm_packet->flags & PRIMARIES_FIRST_HOP))
223 		return;
224 
225 	memcpy(orig_neigh_node->primary_addr, orig_node->orig, ETH_ALEN);
226 }
227 
228 /* checks whether the host restarted and is in the protection time.
229  * returns:
230  *  0 if the packet is to be accepted
231  *  1 if the packet is to be ignored.
232  */
233 int batadv_window_protected(struct bat_priv *bat_priv, int32_t seq_num_diff,
234 			    unsigned long *last_reset)
235 {
236 	if ((seq_num_diff <= -TQ_LOCAL_WINDOW_SIZE) ||
237 	    (seq_num_diff >= EXPECTED_SEQNO_RANGE)) {
238 		if (!has_timed_out(*last_reset, RESET_PROTECTION_MS))
239 			return 1;
240 
241 		*last_reset = jiffies;
242 		bat_dbg(DBG_BATMAN, bat_priv,
243 			"old packet received, start protection\n");
244 	}
245 
246 	return 0;
247 }
248 
249 bool batadv_check_management_packet(struct sk_buff *skb,
250 				    struct hard_iface *hard_iface,
251 				    int header_len)
252 {
253 	struct ethhdr *ethhdr;
254 
255 	/* drop packet if it has not necessary minimum size */
256 	if (unlikely(!pskb_may_pull(skb, header_len)))
257 		return false;
258 
259 	ethhdr = (struct ethhdr *)skb_mac_header(skb);
260 
261 	/* packet with broadcast indication but unicast recipient */
262 	if (!is_broadcast_ether_addr(ethhdr->h_dest))
263 		return false;
264 
265 	/* packet with broadcast sender address */
266 	if (is_broadcast_ether_addr(ethhdr->h_source))
267 		return false;
268 
269 	/* create a copy of the skb, if needed, to modify it. */
270 	if (skb_cow(skb, 0) < 0)
271 		return false;
272 
273 	/* keep skb linear */
274 	if (skb_linearize(skb) < 0)
275 		return false;
276 
277 	return true;
278 }
279 
280 static int recv_my_icmp_packet(struct bat_priv *bat_priv,
281 			       struct sk_buff *skb, size_t icmp_len)
282 {
283 	struct hard_iface *primary_if = NULL;
284 	struct orig_node *orig_node = NULL;
285 	struct neigh_node *router = NULL;
286 	struct icmp_packet_rr *icmp_packet;
287 	int ret = NET_RX_DROP;
288 
289 	icmp_packet = (struct icmp_packet_rr *)skb->data;
290 
291 	/* add data to device queue */
292 	if (icmp_packet->msg_type != ECHO_REQUEST) {
293 		batadv_socket_receive_packet(icmp_packet, icmp_len);
294 		goto out;
295 	}
296 
297 	primary_if = primary_if_get_selected(bat_priv);
298 	if (!primary_if)
299 		goto out;
300 
301 	/* answer echo request (ping) */
302 	/* get routing information */
303 	orig_node = orig_hash_find(bat_priv, icmp_packet->orig);
304 	if (!orig_node)
305 		goto out;
306 
307 	router = batadv_orig_node_get_router(orig_node);
308 	if (!router)
309 		goto out;
310 
311 	/* create a copy of the skb, if needed, to modify it. */
312 	if (skb_cow(skb, ETH_HLEN) < 0)
313 		goto out;
314 
315 	icmp_packet = (struct icmp_packet_rr *)skb->data;
316 
317 	memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN);
318 	memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN);
319 	icmp_packet->msg_type = ECHO_REPLY;
320 	icmp_packet->header.ttl = TTL;
321 
322 	batadv_send_skb_packet(skb, router->if_incoming, router->addr);
323 	ret = NET_RX_SUCCESS;
324 
325 out:
326 	if (primary_if)
327 		hardif_free_ref(primary_if);
328 	if (router)
329 		batadv_neigh_node_free_ref(router);
330 	if (orig_node)
331 		batadv_orig_node_free_ref(orig_node);
332 	return ret;
333 }
334 
335 static int recv_icmp_ttl_exceeded(struct bat_priv *bat_priv,
336 				  struct sk_buff *skb)
337 {
338 	struct hard_iface *primary_if = NULL;
339 	struct orig_node *orig_node = NULL;
340 	struct neigh_node *router = NULL;
341 	struct icmp_packet *icmp_packet;
342 	int ret = NET_RX_DROP;
343 
344 	icmp_packet = (struct icmp_packet *)skb->data;
345 
346 	/* send TTL exceeded if packet is an echo request (traceroute) */
347 	if (icmp_packet->msg_type != ECHO_REQUEST) {
348 		pr_debug("Warning - can't forward icmp packet from %pM to %pM: ttl exceeded\n",
349 			 icmp_packet->orig, icmp_packet->dst);
350 		goto out;
351 	}
352 
353 	primary_if = primary_if_get_selected(bat_priv);
354 	if (!primary_if)
355 		goto out;
356 
357 	/* get routing information */
358 	orig_node = orig_hash_find(bat_priv, icmp_packet->orig);
359 	if (!orig_node)
360 		goto out;
361 
362 	router = batadv_orig_node_get_router(orig_node);
363 	if (!router)
364 		goto out;
365 
366 	/* create a copy of the skb, if needed, to modify it. */
367 	if (skb_cow(skb, ETH_HLEN) < 0)
368 		goto out;
369 
370 	icmp_packet = (struct icmp_packet *)skb->data;
371 
372 	memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN);
373 	memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN);
374 	icmp_packet->msg_type = TTL_EXCEEDED;
375 	icmp_packet->header.ttl = TTL;
376 
377 	batadv_send_skb_packet(skb, router->if_incoming, router->addr);
378 	ret = NET_RX_SUCCESS;
379 
380 out:
381 	if (primary_if)
382 		hardif_free_ref(primary_if);
383 	if (router)
384 		batadv_neigh_node_free_ref(router);
385 	if (orig_node)
386 		batadv_orig_node_free_ref(orig_node);
387 	return ret;
388 }
389 
390 
391 int batadv_recv_icmp_packet(struct sk_buff *skb, struct hard_iface *recv_if)
392 {
393 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
394 	struct icmp_packet_rr *icmp_packet;
395 	struct ethhdr *ethhdr;
396 	struct orig_node *orig_node = NULL;
397 	struct neigh_node *router = NULL;
398 	int hdr_size = sizeof(struct icmp_packet);
399 	int ret = NET_RX_DROP;
400 
401 	/**
402 	 * we truncate all incoming icmp packets if they don't match our size
403 	 */
404 	if (skb->len >= sizeof(struct icmp_packet_rr))
405 		hdr_size = sizeof(struct icmp_packet_rr);
406 
407 	/* drop packet if it has not necessary minimum size */
408 	if (unlikely(!pskb_may_pull(skb, hdr_size)))
409 		goto out;
410 
411 	ethhdr = (struct ethhdr *)skb_mac_header(skb);
412 
413 	/* packet with unicast indication but broadcast recipient */
414 	if (is_broadcast_ether_addr(ethhdr->h_dest))
415 		goto out;
416 
417 	/* packet with broadcast sender address */
418 	if (is_broadcast_ether_addr(ethhdr->h_source))
419 		goto out;
420 
421 	/* not for me */
422 	if (!is_my_mac(ethhdr->h_dest))
423 		goto out;
424 
425 	icmp_packet = (struct icmp_packet_rr *)skb->data;
426 
427 	/* add record route information if not full */
428 	if ((hdr_size == sizeof(struct icmp_packet_rr)) &&
429 	    (icmp_packet->rr_cur < BAT_RR_LEN)) {
430 		memcpy(&(icmp_packet->rr[icmp_packet->rr_cur]),
431 		       ethhdr->h_dest, ETH_ALEN);
432 		icmp_packet->rr_cur++;
433 	}
434 
435 	/* packet for me */
436 	if (is_my_mac(icmp_packet->dst))
437 		return recv_my_icmp_packet(bat_priv, skb, hdr_size);
438 
439 	/* TTL exceeded */
440 	if (icmp_packet->header.ttl < 2)
441 		return recv_icmp_ttl_exceeded(bat_priv, skb);
442 
443 	/* get routing information */
444 	orig_node = orig_hash_find(bat_priv, icmp_packet->dst);
445 	if (!orig_node)
446 		goto out;
447 
448 	router = batadv_orig_node_get_router(orig_node);
449 	if (!router)
450 		goto out;
451 
452 	/* create a copy of the skb, if needed, to modify it. */
453 	if (skb_cow(skb, ETH_HLEN) < 0)
454 		goto out;
455 
456 	icmp_packet = (struct icmp_packet_rr *)skb->data;
457 
458 	/* decrement ttl */
459 	icmp_packet->header.ttl--;
460 
461 	/* route it */
462 	batadv_send_skb_packet(skb, router->if_incoming, router->addr);
463 	ret = NET_RX_SUCCESS;
464 
465 out:
466 	if (router)
467 		batadv_neigh_node_free_ref(router);
468 	if (orig_node)
469 		batadv_orig_node_free_ref(orig_node);
470 	return ret;
471 }
472 
473 /* In the bonding case, send the packets in a round
474  * robin fashion over the remaining interfaces.
475  *
476  * This method rotates the bonding list and increases the
477  * returned router's refcount. */
478 static struct neigh_node *find_bond_router(struct orig_node *primary_orig,
479 					   const struct hard_iface *recv_if)
480 {
481 	struct neigh_node *tmp_neigh_node;
482 	struct neigh_node *router = NULL, *first_candidate = NULL;
483 
484 	rcu_read_lock();
485 	list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
486 				bonding_list) {
487 		if (!first_candidate)
488 			first_candidate = tmp_neigh_node;
489 
490 		/* recv_if == NULL on the first node. */
491 		if (tmp_neigh_node->if_incoming == recv_if)
492 			continue;
493 
494 		if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
495 			continue;
496 
497 		router = tmp_neigh_node;
498 		break;
499 	}
500 
501 	/* use the first candidate if nothing was found. */
502 	if (!router && first_candidate &&
503 	    atomic_inc_not_zero(&first_candidate->refcount))
504 		router = first_candidate;
505 
506 	if (!router)
507 		goto out;
508 
509 	/* selected should point to the next element
510 	 * after the current router */
511 	spin_lock_bh(&primary_orig->neigh_list_lock);
512 	/* this is a list_move(), which unfortunately
513 	 * does not exist as rcu version */
514 	list_del_rcu(&primary_orig->bond_list);
515 	list_add_rcu(&primary_orig->bond_list,
516 		     &router->bonding_list);
517 	spin_unlock_bh(&primary_orig->neigh_list_lock);
518 
519 out:
520 	rcu_read_unlock();
521 	return router;
522 }
523 
524 /* Interface Alternating: Use the best of the
525  * remaining candidates which are not using
526  * this interface.
527  *
528  * Increases the returned router's refcount */
529 static struct neigh_node *find_ifalter_router(struct orig_node *primary_orig,
530 					      const struct hard_iface *recv_if)
531 {
532 	struct neigh_node *tmp_neigh_node;
533 	struct neigh_node *router = NULL, *first_candidate = NULL;
534 
535 	rcu_read_lock();
536 	list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
537 				bonding_list) {
538 		if (!first_candidate)
539 			first_candidate = tmp_neigh_node;
540 
541 		/* recv_if == NULL on the first node. */
542 		if (tmp_neigh_node->if_incoming == recv_if)
543 			continue;
544 
545 		if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
546 			continue;
547 
548 		/* if we don't have a router yet
549 		 * or this one is better, choose it. */
550 		if ((!router) ||
551 		    (tmp_neigh_node->tq_avg > router->tq_avg)) {
552 			/* decrement refcount of
553 			 * previously selected router */
554 			if (router)
555 				batadv_neigh_node_free_ref(router);
556 
557 			router = tmp_neigh_node;
558 			atomic_inc_not_zero(&router->refcount);
559 		}
560 
561 		batadv_neigh_node_free_ref(tmp_neigh_node);
562 	}
563 
564 	/* use the first candidate if nothing was found. */
565 	if (!router && first_candidate &&
566 	    atomic_inc_not_zero(&first_candidate->refcount))
567 		router = first_candidate;
568 
569 	rcu_read_unlock();
570 	return router;
571 }
572 
573 int batadv_recv_tt_query(struct sk_buff *skb, struct hard_iface *recv_if)
574 {
575 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
576 	struct tt_query_packet *tt_query;
577 	uint16_t tt_size;
578 	struct ethhdr *ethhdr;
579 
580 	/* drop packet if it has not necessary minimum size */
581 	if (unlikely(!pskb_may_pull(skb, sizeof(struct tt_query_packet))))
582 		goto out;
583 
584 	/* I could need to modify it */
585 	if (skb_cow(skb, sizeof(struct tt_query_packet)) < 0)
586 		goto out;
587 
588 	ethhdr = (struct ethhdr *)skb_mac_header(skb);
589 
590 	/* packet with unicast indication but broadcast recipient */
591 	if (is_broadcast_ether_addr(ethhdr->h_dest))
592 		goto out;
593 
594 	/* packet with broadcast sender address */
595 	if (is_broadcast_ether_addr(ethhdr->h_source))
596 		goto out;
597 
598 	tt_query = (struct tt_query_packet *)skb->data;
599 
600 	switch (tt_query->flags & TT_QUERY_TYPE_MASK) {
601 	case TT_REQUEST:
602 		batadv_inc_counter(bat_priv, BAT_CNT_TT_REQUEST_RX);
603 
604 		/* If we cannot provide an answer the tt_request is
605 		 * forwarded */
606 		if (!send_tt_response(bat_priv, tt_query)) {
607 			bat_dbg(DBG_TT, bat_priv,
608 				"Routing TT_REQUEST to %pM [%c]\n",
609 				tt_query->dst,
610 				(tt_query->flags & TT_FULL_TABLE ? 'F' : '.'));
611 			return route_unicast_packet(skb, recv_if);
612 		}
613 		break;
614 	case TT_RESPONSE:
615 		batadv_inc_counter(bat_priv, BAT_CNT_TT_RESPONSE_RX);
616 
617 		if (is_my_mac(tt_query->dst)) {
618 			/* packet needs to be linearized to access the TT
619 			 * changes */
620 			if (skb_linearize(skb) < 0)
621 				goto out;
622 			/* skb_linearize() possibly changed skb->data */
623 			tt_query = (struct tt_query_packet *)skb->data;
624 
625 			tt_size = tt_len(ntohs(tt_query->tt_data));
626 
627 			/* Ensure we have all the claimed data */
628 			if (unlikely(skb_headlen(skb) <
629 				     sizeof(struct tt_query_packet) + tt_size))
630 				goto out;
631 
632 			handle_tt_response(bat_priv, tt_query);
633 		} else {
634 			bat_dbg(DBG_TT, bat_priv,
635 				"Routing TT_RESPONSE to %pM [%c]\n",
636 				tt_query->dst,
637 				(tt_query->flags & TT_FULL_TABLE ? 'F' : '.'));
638 			return route_unicast_packet(skb, recv_if);
639 		}
640 		break;
641 	}
642 
643 out:
644 	/* returning NET_RX_DROP will make the caller function kfree the skb */
645 	return NET_RX_DROP;
646 }
647 
648 int batadv_recv_roam_adv(struct sk_buff *skb, struct hard_iface *recv_if)
649 {
650 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
651 	struct roam_adv_packet *roam_adv_packet;
652 	struct orig_node *orig_node;
653 	struct ethhdr *ethhdr;
654 
655 	/* drop packet if it has not necessary minimum size */
656 	if (unlikely(!pskb_may_pull(skb, sizeof(struct roam_adv_packet))))
657 		goto out;
658 
659 	ethhdr = (struct ethhdr *)skb_mac_header(skb);
660 
661 	/* packet with unicast indication but broadcast recipient */
662 	if (is_broadcast_ether_addr(ethhdr->h_dest))
663 		goto out;
664 
665 	/* packet with broadcast sender address */
666 	if (is_broadcast_ether_addr(ethhdr->h_source))
667 		goto out;
668 
669 	batadv_inc_counter(bat_priv, BAT_CNT_TT_ROAM_ADV_RX);
670 
671 	roam_adv_packet = (struct roam_adv_packet *)skb->data;
672 
673 	if (!is_my_mac(roam_adv_packet->dst))
674 		return route_unicast_packet(skb, recv_if);
675 
676 	/* check if it is a backbone gateway. we don't accept
677 	 * roaming advertisement from it, as it has the same
678 	 * entries as we have.
679 	 */
680 	if (batadv_bla_is_backbone_gw_orig(bat_priv, roam_adv_packet->src))
681 		goto out;
682 
683 	orig_node = orig_hash_find(bat_priv, roam_adv_packet->src);
684 	if (!orig_node)
685 		goto out;
686 
687 	bat_dbg(DBG_TT, bat_priv,
688 		"Received ROAMING_ADV from %pM (client %pM)\n",
689 		roam_adv_packet->src, roam_adv_packet->client);
690 
691 	tt_global_add(bat_priv, orig_node, roam_adv_packet->client,
692 		      atomic_read(&orig_node->last_ttvn) + 1, true, false);
693 
694 	/* Roaming phase starts: I have new information but the ttvn has not
695 	 * been incremented yet. This flag will make me check all the incoming
696 	 * packets for the correct destination. */
697 	bat_priv->tt_poss_change = true;
698 
699 	batadv_orig_node_free_ref(orig_node);
700 out:
701 	/* returning NET_RX_DROP will make the caller function kfree the skb */
702 	return NET_RX_DROP;
703 }
704 
705 /* find a suitable router for this originator, and use
706  * bonding if possible. increases the found neighbors
707  * refcount.*/
708 struct neigh_node *batadv_find_router(struct bat_priv *bat_priv,
709 				      struct orig_node *orig_node,
710 				      const struct hard_iface *recv_if)
711 {
712 	struct orig_node *primary_orig_node;
713 	struct orig_node *router_orig;
714 	struct neigh_node *router;
715 	static uint8_t zero_mac[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
716 	int bonding_enabled;
717 
718 	if (!orig_node)
719 		return NULL;
720 
721 	router = batadv_orig_node_get_router(orig_node);
722 	if (!router)
723 		goto err;
724 
725 	/* without bonding, the first node should
726 	 * always choose the default router. */
727 	bonding_enabled = atomic_read(&bat_priv->bonding);
728 
729 	rcu_read_lock();
730 	/* select default router to output */
731 	router_orig = router->orig_node;
732 	if (!router_orig)
733 		goto err_unlock;
734 
735 	if ((!recv_if) && (!bonding_enabled))
736 		goto return_router;
737 
738 	/* if we have something in the primary_addr, we can search
739 	 * for a potential bonding candidate. */
740 	if (compare_eth(router_orig->primary_addr, zero_mac))
741 		goto return_router;
742 
743 	/* find the orig_node which has the primary interface. might
744 	 * even be the same as our router_orig in many cases */
745 
746 	if (compare_eth(router_orig->primary_addr, router_orig->orig)) {
747 		primary_orig_node = router_orig;
748 	} else {
749 		primary_orig_node = orig_hash_find(bat_priv,
750 						   router_orig->primary_addr);
751 		if (!primary_orig_node)
752 			goto return_router;
753 
754 		batadv_orig_node_free_ref(primary_orig_node);
755 	}
756 
757 	/* with less than 2 candidates, we can't do any
758 	 * bonding and prefer the original router. */
759 	if (atomic_read(&primary_orig_node->bond_candidates) < 2)
760 		goto return_router;
761 
762 	/* all nodes between should choose a candidate which
763 	 * is is not on the interface where the packet came
764 	 * in. */
765 
766 	batadv_neigh_node_free_ref(router);
767 
768 	if (bonding_enabled)
769 		router = find_bond_router(primary_orig_node, recv_if);
770 	else
771 		router = find_ifalter_router(primary_orig_node, recv_if);
772 
773 return_router:
774 	if (router && router->if_incoming->if_status != IF_ACTIVE)
775 		goto err_unlock;
776 
777 	rcu_read_unlock();
778 	return router;
779 err_unlock:
780 	rcu_read_unlock();
781 err:
782 	if (router)
783 		batadv_neigh_node_free_ref(router);
784 	return NULL;
785 }
786 
787 static int check_unicast_packet(struct sk_buff *skb, int hdr_size)
788 {
789 	struct ethhdr *ethhdr;
790 
791 	/* drop packet if it has not necessary minimum size */
792 	if (unlikely(!pskb_may_pull(skb, hdr_size)))
793 		return -1;
794 
795 	ethhdr = (struct ethhdr *)skb_mac_header(skb);
796 
797 	/* packet with unicast indication but broadcast recipient */
798 	if (is_broadcast_ether_addr(ethhdr->h_dest))
799 		return -1;
800 
801 	/* packet with broadcast sender address */
802 	if (is_broadcast_ether_addr(ethhdr->h_source))
803 		return -1;
804 
805 	/* not for me */
806 	if (!is_my_mac(ethhdr->h_dest))
807 		return -1;
808 
809 	return 0;
810 }
811 
812 static int route_unicast_packet(struct sk_buff *skb, struct hard_iface *recv_if)
813 {
814 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
815 	struct orig_node *orig_node = NULL;
816 	struct neigh_node *neigh_node = NULL;
817 	struct unicast_packet *unicast_packet;
818 	struct ethhdr *ethhdr = (struct ethhdr *)skb_mac_header(skb);
819 	int ret = NET_RX_DROP;
820 	struct sk_buff *new_skb;
821 
822 	unicast_packet = (struct unicast_packet *)skb->data;
823 
824 	/* TTL exceeded */
825 	if (unicast_packet->header.ttl < 2) {
826 		pr_debug("Warning - can't forward unicast packet from %pM to %pM: ttl exceeded\n",
827 			 ethhdr->h_source, unicast_packet->dest);
828 		goto out;
829 	}
830 
831 	/* get routing information */
832 	orig_node = orig_hash_find(bat_priv, unicast_packet->dest);
833 
834 	if (!orig_node)
835 		goto out;
836 
837 	/* find_router() increases neigh_nodes refcount if found. */
838 	neigh_node = batadv_find_router(bat_priv, orig_node, recv_if);
839 
840 	if (!neigh_node)
841 		goto out;
842 
843 	/* create a copy of the skb, if needed, to modify it. */
844 	if (skb_cow(skb, ETH_HLEN) < 0)
845 		goto out;
846 
847 	unicast_packet = (struct unicast_packet *)skb->data;
848 
849 	if (unicast_packet->header.packet_type == BAT_UNICAST &&
850 	    atomic_read(&bat_priv->fragmentation) &&
851 	    skb->len > neigh_node->if_incoming->net_dev->mtu) {
852 		ret = frag_send_skb(skb, bat_priv,
853 				    neigh_node->if_incoming, neigh_node->addr);
854 		goto out;
855 	}
856 
857 	if (unicast_packet->header.packet_type == BAT_UNICAST_FRAG &&
858 	    frag_can_reassemble(skb, neigh_node->if_incoming->net_dev->mtu)) {
859 
860 		ret = frag_reassemble_skb(skb, bat_priv, &new_skb);
861 
862 		if (ret == NET_RX_DROP)
863 			goto out;
864 
865 		/* packet was buffered for late merge */
866 		if (!new_skb) {
867 			ret = NET_RX_SUCCESS;
868 			goto out;
869 		}
870 
871 		skb = new_skb;
872 		unicast_packet = (struct unicast_packet *)skb->data;
873 	}
874 
875 	/* decrement ttl */
876 	unicast_packet->header.ttl--;
877 
878 	/* Update stats counter */
879 	batadv_inc_counter(bat_priv, BAT_CNT_FORWARD);
880 	batadv_add_counter(bat_priv, BAT_CNT_FORWARD_BYTES,
881 			   skb->len + ETH_HLEN);
882 
883 	/* route it */
884 	batadv_send_skb_packet(skb, neigh_node->if_incoming, neigh_node->addr);
885 	ret = NET_RX_SUCCESS;
886 
887 out:
888 	if (neigh_node)
889 		batadv_neigh_node_free_ref(neigh_node);
890 	if (orig_node)
891 		batadv_orig_node_free_ref(orig_node);
892 	return ret;
893 }
894 
895 static int check_unicast_ttvn(struct bat_priv *bat_priv,
896 			       struct sk_buff *skb) {
897 	uint8_t curr_ttvn;
898 	struct orig_node *orig_node;
899 	struct ethhdr *ethhdr;
900 	struct hard_iface *primary_if;
901 	struct unicast_packet *unicast_packet;
902 	bool tt_poss_change;
903 
904 	/* I could need to modify it */
905 	if (skb_cow(skb, sizeof(struct unicast_packet)) < 0)
906 		return 0;
907 
908 	unicast_packet = (struct unicast_packet *)skb->data;
909 
910 	if (is_my_mac(unicast_packet->dest)) {
911 		tt_poss_change = bat_priv->tt_poss_change;
912 		curr_ttvn = (uint8_t)atomic_read(&bat_priv->ttvn);
913 	} else {
914 		orig_node = orig_hash_find(bat_priv, unicast_packet->dest);
915 
916 		if (!orig_node)
917 			return 0;
918 
919 		curr_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn);
920 		tt_poss_change = orig_node->tt_poss_change;
921 		batadv_orig_node_free_ref(orig_node);
922 	}
923 
924 	/* Check whether I have to reroute the packet */
925 	if (seq_before(unicast_packet->ttvn, curr_ttvn) || tt_poss_change) {
926 		/* check if there is enough data before accessing it */
927 		if (pskb_may_pull(skb, sizeof(struct unicast_packet) +
928 				  ETH_HLEN) < 0)
929 			return 0;
930 
931 		ethhdr = (struct ethhdr *)(skb->data +
932 			sizeof(struct unicast_packet));
933 
934 		/* we don't have an updated route for this client, so we should
935 		 * not try to reroute the packet!!
936 		 */
937 		if (tt_global_client_is_roaming(bat_priv, ethhdr->h_dest))
938 			return 1;
939 
940 		orig_node = transtable_search(bat_priv, NULL, ethhdr->h_dest);
941 
942 		if (!orig_node) {
943 			if (!is_my_client(bat_priv, ethhdr->h_dest))
944 				return 0;
945 			primary_if = primary_if_get_selected(bat_priv);
946 			if (!primary_if)
947 				return 0;
948 			memcpy(unicast_packet->dest,
949 			       primary_if->net_dev->dev_addr, ETH_ALEN);
950 			hardif_free_ref(primary_if);
951 		} else {
952 			memcpy(unicast_packet->dest, orig_node->orig,
953 			       ETH_ALEN);
954 			curr_ttvn = (uint8_t)
955 				atomic_read(&orig_node->last_ttvn);
956 			batadv_orig_node_free_ref(orig_node);
957 		}
958 
959 		bat_dbg(DBG_ROUTES, bat_priv,
960 			"TTVN mismatch (old_ttvn %u new_ttvn %u)! Rerouting unicast packet (for %pM) to %pM\n",
961 			unicast_packet->ttvn, curr_ttvn, ethhdr->h_dest,
962 			unicast_packet->dest);
963 
964 		unicast_packet->ttvn = curr_ttvn;
965 	}
966 	return 1;
967 }
968 
969 int batadv_recv_unicast_packet(struct sk_buff *skb, struct hard_iface *recv_if)
970 {
971 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
972 	struct unicast_packet *unicast_packet;
973 	int hdr_size = sizeof(*unicast_packet);
974 
975 	if (check_unicast_packet(skb, hdr_size) < 0)
976 		return NET_RX_DROP;
977 
978 	if (!check_unicast_ttvn(bat_priv, skb))
979 		return NET_RX_DROP;
980 
981 	unicast_packet = (struct unicast_packet *)skb->data;
982 
983 	/* packet for me */
984 	if (is_my_mac(unicast_packet->dest)) {
985 		interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size);
986 		return NET_RX_SUCCESS;
987 	}
988 
989 	return route_unicast_packet(skb, recv_if);
990 }
991 
992 int batadv_recv_ucast_frag_packet(struct sk_buff *skb,
993 				  struct hard_iface *recv_if)
994 {
995 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
996 	struct unicast_frag_packet *unicast_packet;
997 	int hdr_size = sizeof(*unicast_packet);
998 	struct sk_buff *new_skb = NULL;
999 	int ret;
1000 
1001 	if (check_unicast_packet(skb, hdr_size) < 0)
1002 		return NET_RX_DROP;
1003 
1004 	if (!check_unicast_ttvn(bat_priv, skb))
1005 		return NET_RX_DROP;
1006 
1007 	unicast_packet = (struct unicast_frag_packet *)skb->data;
1008 
1009 	/* packet for me */
1010 	if (is_my_mac(unicast_packet->dest)) {
1011 
1012 		ret = frag_reassemble_skb(skb, bat_priv, &new_skb);
1013 
1014 		if (ret == NET_RX_DROP)
1015 			return NET_RX_DROP;
1016 
1017 		/* packet was buffered for late merge */
1018 		if (!new_skb)
1019 			return NET_RX_SUCCESS;
1020 
1021 		interface_rx(recv_if->soft_iface, new_skb, recv_if,
1022 			     sizeof(struct unicast_packet));
1023 		return NET_RX_SUCCESS;
1024 	}
1025 
1026 	return route_unicast_packet(skb, recv_if);
1027 }
1028 
1029 
1030 int batadv_recv_bcast_packet(struct sk_buff *skb, struct hard_iface *recv_if)
1031 {
1032 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1033 	struct orig_node *orig_node = NULL;
1034 	struct bcast_packet *bcast_packet;
1035 	struct ethhdr *ethhdr;
1036 	int hdr_size = sizeof(*bcast_packet);
1037 	int ret = NET_RX_DROP;
1038 	int32_t seq_diff;
1039 
1040 	/* drop packet if it has not necessary minimum size */
1041 	if (unlikely(!pskb_may_pull(skb, hdr_size)))
1042 		goto out;
1043 
1044 	ethhdr = (struct ethhdr *)skb_mac_header(skb);
1045 
1046 	/* packet with broadcast indication but unicast recipient */
1047 	if (!is_broadcast_ether_addr(ethhdr->h_dest))
1048 		goto out;
1049 
1050 	/* packet with broadcast sender address */
1051 	if (is_broadcast_ether_addr(ethhdr->h_source))
1052 		goto out;
1053 
1054 	/* ignore broadcasts sent by myself */
1055 	if (is_my_mac(ethhdr->h_source))
1056 		goto out;
1057 
1058 	bcast_packet = (struct bcast_packet *)skb->data;
1059 
1060 	/* ignore broadcasts originated by myself */
1061 	if (is_my_mac(bcast_packet->orig))
1062 		goto out;
1063 
1064 	if (bcast_packet->header.ttl < 2)
1065 		goto out;
1066 
1067 	orig_node = orig_hash_find(bat_priv, bcast_packet->orig);
1068 
1069 	if (!orig_node)
1070 		goto out;
1071 
1072 	spin_lock_bh(&orig_node->bcast_seqno_lock);
1073 
1074 	/* check whether the packet is a duplicate */
1075 	if (bat_test_bit(orig_node->bcast_bits, orig_node->last_bcast_seqno,
1076 			 ntohl(bcast_packet->seqno)))
1077 		goto spin_unlock;
1078 
1079 	seq_diff = ntohl(bcast_packet->seqno) - orig_node->last_bcast_seqno;
1080 
1081 	/* check whether the packet is old and the host just restarted. */
1082 	if (batadv_window_protected(bat_priv, seq_diff,
1083 				    &orig_node->bcast_seqno_reset))
1084 		goto spin_unlock;
1085 
1086 	/* mark broadcast in flood history, update window position
1087 	 * if required. */
1088 	if (batadv_bit_get_packet(bat_priv, orig_node->bcast_bits, seq_diff, 1))
1089 		orig_node->last_bcast_seqno = ntohl(bcast_packet->seqno);
1090 
1091 	spin_unlock_bh(&orig_node->bcast_seqno_lock);
1092 
1093 	/* check whether this has been sent by another originator before */
1094 	if (batadv_bla_check_bcast_duplist(bat_priv, bcast_packet, hdr_size))
1095 		goto out;
1096 
1097 	/* rebroadcast packet */
1098 	batadv_add_bcast_packet_to_list(bat_priv, skb, 1);
1099 
1100 	/* don't hand the broadcast up if it is from an originator
1101 	 * from the same backbone.
1102 	 */
1103 	if (batadv_bla_is_backbone_gw(skb, orig_node, hdr_size))
1104 		goto out;
1105 
1106 	/* broadcast for me */
1107 	interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size);
1108 	ret = NET_RX_SUCCESS;
1109 	goto out;
1110 
1111 spin_unlock:
1112 	spin_unlock_bh(&orig_node->bcast_seqno_lock);
1113 out:
1114 	if (orig_node)
1115 		batadv_orig_node_free_ref(orig_node);
1116 	return ret;
1117 }
1118 
1119 int batadv_recv_vis_packet(struct sk_buff *skb, struct hard_iface *recv_if)
1120 {
1121 	struct vis_packet *vis_packet;
1122 	struct ethhdr *ethhdr;
1123 	struct bat_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1124 	int hdr_size = sizeof(*vis_packet);
1125 
1126 	/* keep skb linear */
1127 	if (skb_linearize(skb) < 0)
1128 		return NET_RX_DROP;
1129 
1130 	if (unlikely(!pskb_may_pull(skb, hdr_size)))
1131 		return NET_RX_DROP;
1132 
1133 	vis_packet = (struct vis_packet *)skb->data;
1134 	ethhdr = (struct ethhdr *)skb_mac_header(skb);
1135 
1136 	/* not for me */
1137 	if (!is_my_mac(ethhdr->h_dest))
1138 		return NET_RX_DROP;
1139 
1140 	/* ignore own packets */
1141 	if (is_my_mac(vis_packet->vis_orig))
1142 		return NET_RX_DROP;
1143 
1144 	if (is_my_mac(vis_packet->sender_orig))
1145 		return NET_RX_DROP;
1146 
1147 	switch (vis_packet->vis_type) {
1148 	case VIS_TYPE_SERVER_SYNC:
1149 		receive_server_sync_packet(bat_priv, vis_packet,
1150 					   skb_headlen(skb));
1151 		break;
1152 
1153 	case VIS_TYPE_CLIENT_UPDATE:
1154 		receive_client_update_packet(bat_priv, vis_packet,
1155 					     skb_headlen(skb));
1156 		break;
1157 
1158 	default:	/* ignore unknown packet */
1159 		break;
1160 	}
1161 
1162 	/* We take a copy of the data in the packet, so we should
1163 	   always free the skbuf. */
1164 	return NET_RX_DROP;
1165 }
1166