11da177e4SLinus Torvalds /* 21da177e4SLinus Torvalds * INET An implementation of the TCP/IP protocol suite for the LINUX 31da177e4SLinus Torvalds * operating system. INET is implemented using the BSD Socket 41da177e4SLinus Torvalds * interface as the means of communication with the user level. 51da177e4SLinus Torvalds * 61da177e4SLinus Torvalds * Implementation of the Transmission Control Protocol(TCP). 71da177e4SLinus Torvalds * 802c30a84SJesper Juhl * Authors: Ross Biro 91da177e4SLinus Torvalds * Fred N. van Kempen, <waltje@uWalt.NL.Mugnet.ORG> 101da177e4SLinus Torvalds * Mark Evans, <evansmp@uhura.aston.ac.uk> 111da177e4SLinus Torvalds * Corey Minyard <wf-rch!minyard@relay.EU.net> 121da177e4SLinus Torvalds * Florian La Roche, <flla@stud.uni-sb.de> 131da177e4SLinus Torvalds * Charles Hedrick, <hedrick@klinzhai.rutgers.edu> 141da177e4SLinus Torvalds * Linus Torvalds, <torvalds@cs.helsinki.fi> 151da177e4SLinus Torvalds * Alan Cox, <gw4pts@gw4pts.ampr.org> 161da177e4SLinus Torvalds * Matthew Dillon, <dillon@apollo.west.oic.com> 171da177e4SLinus Torvalds * Arnt Gulbrandsen, <agulbra@nvg.unit.no> 181da177e4SLinus Torvalds * Jorge Cwik, <jorge@laser.satlink.net> 191da177e4SLinus Torvalds * 201da177e4SLinus Torvalds * Fixes: 211da177e4SLinus Torvalds * Alan Cox : Numerous verify_area() calls 221da177e4SLinus Torvalds * Alan Cox : Set the ACK bit on a reset 231da177e4SLinus Torvalds * Alan Cox : Stopped it crashing if it closed while 241da177e4SLinus Torvalds * sk->inuse=1 and was trying to connect 251da177e4SLinus Torvalds * (tcp_err()). 261da177e4SLinus Torvalds * Alan Cox : All icmp error handling was broken 271da177e4SLinus Torvalds * pointers passed where wrong and the 281da177e4SLinus Torvalds * socket was looked up backwards. Nobody 291da177e4SLinus Torvalds * tested any icmp error code obviously. 301da177e4SLinus Torvalds * Alan Cox : tcp_err() now handled properly. It 311da177e4SLinus Torvalds * wakes people on errors. poll 321da177e4SLinus Torvalds * behaves and the icmp error race 331da177e4SLinus Torvalds * has gone by moving it into sock.c 341da177e4SLinus Torvalds * Alan Cox : tcp_send_reset() fixed to work for 351da177e4SLinus Torvalds * everything not just packets for 361da177e4SLinus Torvalds * unknown sockets. 371da177e4SLinus Torvalds * Alan Cox : tcp option processing. 381da177e4SLinus Torvalds * Alan Cox : Reset tweaked (still not 100%) [Had 391da177e4SLinus Torvalds * syn rule wrong] 401da177e4SLinus Torvalds * Herp Rosmanith : More reset fixes 411da177e4SLinus Torvalds * Alan Cox : No longer acks invalid rst frames. 421da177e4SLinus Torvalds * Acking any kind of RST is right out. 431da177e4SLinus Torvalds * Alan Cox : Sets an ignore me flag on an rst 441da177e4SLinus Torvalds * receive otherwise odd bits of prattle 451da177e4SLinus Torvalds * escape still 461da177e4SLinus Torvalds * Alan Cox : Fixed another acking RST frame bug. 471da177e4SLinus Torvalds * Should stop LAN workplace lockups. 481da177e4SLinus Torvalds * Alan Cox : Some tidyups using the new skb list 491da177e4SLinus Torvalds * facilities 501da177e4SLinus Torvalds * Alan Cox : sk->keepopen now seems to work 511da177e4SLinus Torvalds * Alan Cox : Pulls options out correctly on accepts 521da177e4SLinus Torvalds * Alan Cox : Fixed assorted sk->rqueue->next errors 531da177e4SLinus Torvalds * Alan Cox : PSH doesn't end a TCP read. Switched a 541da177e4SLinus Torvalds * bit to skb ops. 551da177e4SLinus Torvalds * Alan Cox : Tidied tcp_data to avoid a potential 561da177e4SLinus Torvalds * nasty. 571da177e4SLinus Torvalds * Alan Cox : Added some better commenting, as the 581da177e4SLinus Torvalds * tcp is hard to follow 591da177e4SLinus Torvalds * Alan Cox : Removed incorrect check for 20 * psh 601da177e4SLinus Torvalds * Michael O'Reilly : ack < copied bug fix. 611da177e4SLinus Torvalds * Johannes Stille : Misc tcp fixes (not all in yet). 621da177e4SLinus Torvalds * Alan Cox : FIN with no memory -> CRASH 631da177e4SLinus Torvalds * Alan Cox : Added socket option proto entries. 641da177e4SLinus Torvalds * Also added awareness of them to accept. 651da177e4SLinus Torvalds * Alan Cox : Added TCP options (SOL_TCP) 661da177e4SLinus Torvalds * Alan Cox : Switched wakeup calls to callbacks, 671da177e4SLinus Torvalds * so the kernel can layer network 681da177e4SLinus Torvalds * sockets. 691da177e4SLinus Torvalds * Alan Cox : Use ip_tos/ip_ttl settings. 701da177e4SLinus Torvalds * Alan Cox : Handle FIN (more) properly (we hope). 711da177e4SLinus Torvalds * Alan Cox : RST frames sent on unsynchronised 721da177e4SLinus Torvalds * state ack error. 731da177e4SLinus Torvalds * Alan Cox : Put in missing check for SYN bit. 741da177e4SLinus Torvalds * Alan Cox : Added tcp_select_window() aka NET2E 751da177e4SLinus Torvalds * window non shrink trick. 761da177e4SLinus Torvalds * Alan Cox : Added a couple of small NET2E timer 771da177e4SLinus Torvalds * fixes 781da177e4SLinus Torvalds * Charles Hedrick : TCP fixes 791da177e4SLinus Torvalds * Toomas Tamm : TCP window fixes 801da177e4SLinus Torvalds * Alan Cox : Small URG fix to rlogin ^C ack fight 811da177e4SLinus Torvalds * Charles Hedrick : Rewrote most of it to actually work 821da177e4SLinus Torvalds * Linus : Rewrote tcp_read() and URG handling 831da177e4SLinus Torvalds * completely 841da177e4SLinus Torvalds * Gerhard Koerting: Fixed some missing timer handling 851da177e4SLinus Torvalds * Matthew Dillon : Reworked TCP machine states as per RFC 861da177e4SLinus Torvalds * Gerhard Koerting: PC/TCP workarounds 871da177e4SLinus Torvalds * Adam Caldwell : Assorted timer/timing errors 881da177e4SLinus Torvalds * Matthew Dillon : Fixed another RST bug 891da177e4SLinus Torvalds * Alan Cox : Move to kernel side addressing changes. 901da177e4SLinus Torvalds * Alan Cox : Beginning work on TCP fastpathing 911da177e4SLinus Torvalds * (not yet usable) 921da177e4SLinus Torvalds * Arnt Gulbrandsen: Turbocharged tcp_check() routine. 931da177e4SLinus Torvalds * Alan Cox : TCP fast path debugging 941da177e4SLinus Torvalds * Alan Cox : Window clamping 951da177e4SLinus Torvalds * Michael Riepe : Bug in tcp_check() 961da177e4SLinus Torvalds * Matt Dillon : More TCP improvements and RST bug fixes 971da177e4SLinus Torvalds * Matt Dillon : Yet more small nasties remove from the 981da177e4SLinus Torvalds * TCP code (Be very nice to this man if 991da177e4SLinus Torvalds * tcp finally works 100%) 8) 1001da177e4SLinus Torvalds * Alan Cox : BSD accept semantics. 1011da177e4SLinus Torvalds * Alan Cox : Reset on closedown bug. 1021da177e4SLinus Torvalds * Peter De Schrijver : ENOTCONN check missing in tcp_sendto(). 1031da177e4SLinus Torvalds * Michael Pall : Handle poll() after URG properly in 1041da177e4SLinus Torvalds * all cases. 1051da177e4SLinus Torvalds * Michael Pall : Undo the last fix in tcp_read_urg() 1061da177e4SLinus Torvalds * (multi URG PUSH broke rlogin). 1071da177e4SLinus Torvalds * Michael Pall : Fix the multi URG PUSH problem in 1081da177e4SLinus Torvalds * tcp_readable(), poll() after URG 1091da177e4SLinus Torvalds * works now. 1101da177e4SLinus Torvalds * Michael Pall : recv(...,MSG_OOB) never blocks in the 1111da177e4SLinus Torvalds * BSD api. 1121da177e4SLinus Torvalds * Alan Cox : Changed the semantics of sk->socket to 1131da177e4SLinus Torvalds * fix a race and a signal problem with 1141da177e4SLinus Torvalds * accept() and async I/O. 1151da177e4SLinus Torvalds * Alan Cox : Relaxed the rules on tcp_sendto(). 1161da177e4SLinus Torvalds * Yury Shevchuk : Really fixed accept() blocking problem. 1171da177e4SLinus Torvalds * Craig I. Hagan : Allow for BSD compatible TIME_WAIT for 1181da177e4SLinus Torvalds * clients/servers which listen in on 1191da177e4SLinus Torvalds * fixed ports. 1201da177e4SLinus Torvalds * Alan Cox : Cleaned the above up and shrank it to 1211da177e4SLinus Torvalds * a sensible code size. 1221da177e4SLinus Torvalds * Alan Cox : Self connect lockup fix. 1231da177e4SLinus Torvalds * Alan Cox : No connect to multicast. 1241da177e4SLinus Torvalds * Ross Biro : Close unaccepted children on master 1251da177e4SLinus Torvalds * socket close. 1261da177e4SLinus Torvalds * Alan Cox : Reset tracing code. 1271da177e4SLinus Torvalds * Alan Cox : Spurious resets on shutdown. 1281da177e4SLinus Torvalds * Alan Cox : Giant 15 minute/60 second timer error 1291da177e4SLinus Torvalds * Alan Cox : Small whoops in polling before an 1301da177e4SLinus Torvalds * accept. 1311da177e4SLinus Torvalds * Alan Cox : Kept the state trace facility since 1321da177e4SLinus Torvalds * it's handy for debugging. 1331da177e4SLinus Torvalds * Alan Cox : More reset handler fixes. 1341da177e4SLinus Torvalds * Alan Cox : Started rewriting the code based on 1351da177e4SLinus Torvalds * the RFC's for other useful protocol 1361da177e4SLinus Torvalds * references see: Comer, KA9Q NOS, and 1371da177e4SLinus Torvalds * for a reference on the difference 1381da177e4SLinus Torvalds * between specifications and how BSD 1391da177e4SLinus Torvalds * works see the 4.4lite source. 1401da177e4SLinus Torvalds * A.N.Kuznetsov : Don't time wait on completion of tidy 1411da177e4SLinus Torvalds * close. 1421da177e4SLinus Torvalds * Linus Torvalds : Fin/Shutdown & copied_seq changes. 1431da177e4SLinus Torvalds * Linus Torvalds : Fixed BSD port reuse to work first syn 1441da177e4SLinus Torvalds * Alan Cox : Reimplemented timers as per the RFC 1451da177e4SLinus Torvalds * and using multiple timers for sanity. 1461da177e4SLinus Torvalds * Alan Cox : Small bug fixes, and a lot of new 1471da177e4SLinus Torvalds * comments. 1481da177e4SLinus Torvalds * Alan Cox : Fixed dual reader crash by locking 1491da177e4SLinus Torvalds * the buffers (much like datagram.c) 1501da177e4SLinus Torvalds * Alan Cox : Fixed stuck sockets in probe. A probe 1511da177e4SLinus Torvalds * now gets fed up of retrying without 1521da177e4SLinus Torvalds * (even a no space) answer. 1531da177e4SLinus Torvalds * Alan Cox : Extracted closing code better 1541da177e4SLinus Torvalds * Alan Cox : Fixed the closing state machine to 1551da177e4SLinus Torvalds * resemble the RFC. 1561da177e4SLinus Torvalds * Alan Cox : More 'per spec' fixes. 1571da177e4SLinus Torvalds * Jorge Cwik : Even faster checksumming. 1581da177e4SLinus Torvalds * Alan Cox : tcp_data() doesn't ack illegal PSH 1591da177e4SLinus Torvalds * only frames. At least one pc tcp stack 1601da177e4SLinus Torvalds * generates them. 1611da177e4SLinus Torvalds * Alan Cox : Cache last socket. 1621da177e4SLinus Torvalds * Alan Cox : Per route irtt. 1631da177e4SLinus Torvalds * Matt Day : poll()->select() match BSD precisely on error 1641da177e4SLinus Torvalds * Alan Cox : New buffers 1651da177e4SLinus Torvalds * Marc Tamsky : Various sk->prot->retransmits and 1661da177e4SLinus Torvalds * sk->retransmits misupdating fixed. 1671da177e4SLinus Torvalds * Fixed tcp_write_timeout: stuck close, 1681da177e4SLinus Torvalds * and TCP syn retries gets used now. 1691da177e4SLinus Torvalds * Mark Yarvis : In tcp_read_wakeup(), don't send an 1701da177e4SLinus Torvalds * ack if state is TCP_CLOSED. 1711da177e4SLinus Torvalds * Alan Cox : Look up device on a retransmit - routes may 1721da177e4SLinus Torvalds * change. Doesn't yet cope with MSS shrink right 1731da177e4SLinus Torvalds * but it's a start! 1741da177e4SLinus Torvalds * Marc Tamsky : Closing in closing fixes. 1751da177e4SLinus Torvalds * Mike Shaver : RFC1122 verifications. 1761da177e4SLinus Torvalds * Alan Cox : rcv_saddr errors. 1771da177e4SLinus Torvalds * Alan Cox : Block double connect(). 1781da177e4SLinus Torvalds * Alan Cox : Small hooks for enSKIP. 1791da177e4SLinus Torvalds * Alexey Kuznetsov: Path MTU discovery. 1801da177e4SLinus Torvalds * Alan Cox : Support soft errors. 1811da177e4SLinus Torvalds * Alan Cox : Fix MTU discovery pathological case 1821da177e4SLinus Torvalds * when the remote claims no mtu! 1831da177e4SLinus Torvalds * Marc Tamsky : TCP_CLOSE fix. 1841da177e4SLinus Torvalds * Colin (G3TNE) : Send a reset on syn ack replies in 1851da177e4SLinus Torvalds * window but wrong (fixes NT lpd problems) 1861da177e4SLinus Torvalds * Pedro Roque : Better TCP window handling, delayed ack. 1871da177e4SLinus Torvalds * Joerg Reuter : No modification of locked buffers in 1881da177e4SLinus Torvalds * tcp_do_retransmit() 1891da177e4SLinus Torvalds * Eric Schenk : Changed receiver side silly window 1901da177e4SLinus Torvalds * avoidance algorithm to BSD style 1911da177e4SLinus Torvalds * algorithm. This doubles throughput 1921da177e4SLinus Torvalds * against machines running Solaris, 1931da177e4SLinus Torvalds * and seems to result in general 1941da177e4SLinus Torvalds * improvement. 1951da177e4SLinus Torvalds * Stefan Magdalinski : adjusted tcp_readable() to fix FIONREAD 1961da177e4SLinus Torvalds * Willy Konynenberg : Transparent proxying support. 1971da177e4SLinus Torvalds * Mike McLagan : Routing by source 1981da177e4SLinus Torvalds * Keith Owens : Do proper merging with partial SKB's in 1991da177e4SLinus Torvalds * tcp_do_sendmsg to avoid burstiness. 2001da177e4SLinus Torvalds * Eric Schenk : Fix fast close down bug with 2011da177e4SLinus Torvalds * shutdown() followed by close(). 2021da177e4SLinus Torvalds * Andi Kleen : Make poll agree with SIGIO 2031da177e4SLinus Torvalds * Salvatore Sanfilippo : Support SO_LINGER with linger == 1 and 2041da177e4SLinus Torvalds * lingertime == 0 (RFC 793 ABORT Call) 2051da177e4SLinus Torvalds * Hirokazu Takahashi : Use copy_from_user() instead of 2061da177e4SLinus Torvalds * csum_and_copy_from_user() if possible. 2071da177e4SLinus Torvalds * 2081da177e4SLinus Torvalds * This program is free software; you can redistribute it and/or 2091da177e4SLinus Torvalds * modify it under the terms of the GNU General Public License 2101da177e4SLinus Torvalds * as published by the Free Software Foundation; either version 2111da177e4SLinus Torvalds * 2 of the License, or(at your option) any later version. 2121da177e4SLinus Torvalds * 2131da177e4SLinus Torvalds * Description of States: 2141da177e4SLinus Torvalds * 2151da177e4SLinus Torvalds * TCP_SYN_SENT sent a connection request, waiting for ack 2161da177e4SLinus Torvalds * 2171da177e4SLinus Torvalds * TCP_SYN_RECV received a connection request, sent ack, 2181da177e4SLinus Torvalds * waiting for final ack in three-way handshake. 2191da177e4SLinus Torvalds * 2201da177e4SLinus Torvalds * TCP_ESTABLISHED connection established 2211da177e4SLinus Torvalds * 2221da177e4SLinus Torvalds * TCP_FIN_WAIT1 our side has shutdown, waiting to complete 2231da177e4SLinus Torvalds * transmission of remaining buffered data 2241da177e4SLinus Torvalds * 2251da177e4SLinus Torvalds * TCP_FIN_WAIT2 all buffered data sent, waiting for remote 2261da177e4SLinus Torvalds * to shutdown 2271da177e4SLinus Torvalds * 2281da177e4SLinus Torvalds * TCP_CLOSING both sides have shutdown but we still have 2291da177e4SLinus Torvalds * data we have to finish sending 2301da177e4SLinus Torvalds * 2311da177e4SLinus Torvalds * TCP_TIME_WAIT timeout to catch resent junk before entering 2321da177e4SLinus Torvalds * closed, can only be entered from FIN_WAIT2 2331da177e4SLinus Torvalds * or CLOSING. Required because the other end 2341da177e4SLinus Torvalds * may not have gotten our last ACK causing it 2351da177e4SLinus Torvalds * to retransmit the data packet (which we ignore) 2361da177e4SLinus Torvalds * 2371da177e4SLinus Torvalds * TCP_CLOSE_WAIT remote side has shutdown and is waiting for 2381da177e4SLinus Torvalds * us to finish writing our data and to shutdown 2391da177e4SLinus Torvalds * (we have to close() to move on to LAST_ACK) 2401da177e4SLinus Torvalds * 2411da177e4SLinus Torvalds * TCP_LAST_ACK out side has shutdown after remote has 2421da177e4SLinus Torvalds * shutdown. There may still be data in our 2431da177e4SLinus Torvalds * buffer that we have to finish sending 2441da177e4SLinus Torvalds * 2451da177e4SLinus Torvalds * TCP_CLOSE socket is finished 2461da177e4SLinus Torvalds */ 2471da177e4SLinus Torvalds 248afd46503SJoe Perches #define pr_fmt(fmt) "TCP: " fmt 249afd46503SJoe Perches 250172589ccSIlpo Järvinen #include <linux/kernel.h> 2511da177e4SLinus Torvalds #include <linux/module.h> 2521da177e4SLinus Torvalds #include <linux/types.h> 2531da177e4SLinus Torvalds #include <linux/fcntl.h> 2541da177e4SLinus Torvalds #include <linux/poll.h> 2551da177e4SLinus Torvalds #include <linux/init.h> 2561da177e4SLinus Torvalds #include <linux/fs.h> 2579c55e01cSJens Axboe #include <linux/skbuff.h> 25881b23b4aSAndrew Morton #include <linux/scatterlist.h> 2599c55e01cSJens Axboe #include <linux/splice.h> 2609c55e01cSJens Axboe #include <linux/net.h> 2619c55e01cSJens Axboe #include <linux/socket.h> 2621da177e4SLinus Torvalds #include <linux/random.h> 2631da177e4SLinus Torvalds #include <linux/bootmem.h> 26457413ebcSMiquel van Smoorenburg #include <linux/highmem.h> 26557413ebcSMiquel van Smoorenburg #include <linux/swap.h> 266b8059eadSDavid S. Miller #include <linux/cache.h> 267f4c50d99SHerbert Xu #include <linux/err.h> 268cfb6eeb4SYOSHIFUJI Hideaki #include <linux/crypto.h> 269da5c78c8SWilliam Allen Simpson #include <linux/time.h> 2705a0e3ad6STejun Heo #include <linux/slab.h> 2711da177e4SLinus Torvalds 2721da177e4SLinus Torvalds #include <net/icmp.h> 2731da177e4SLinus Torvalds #include <net/tcp.h> 2741da177e4SLinus Torvalds #include <net/xfrm.h> 2751da177e4SLinus Torvalds #include <net/ip.h> 2761a2449a8SChris Leech #include <net/netdma.h> 2779c55e01cSJens Axboe #include <net/sock.h> 2781da177e4SLinus Torvalds 2791da177e4SLinus Torvalds #include <asm/uaccess.h> 2801da177e4SLinus Torvalds #include <asm/ioctls.h> 2811da177e4SLinus Torvalds 282ab32ea5dSBrian Haley int sysctl_tcp_fin_timeout __read_mostly = TCP_FIN_TIMEOUT; 2831da177e4SLinus Torvalds 284dd24c001SEric Dumazet struct percpu_counter tcp_orphan_count; 2850a5578cfSArnaldo Carvalho de Melo EXPORT_SYMBOL_GPL(tcp_orphan_count); 2860a5578cfSArnaldo Carvalho de Melo 287b8059eadSDavid S. Miller int sysctl_tcp_wmem[3] __read_mostly; 288b8059eadSDavid S. Miller int sysctl_tcp_rmem[3] __read_mostly; 2891da177e4SLinus Torvalds 2901da177e4SLinus Torvalds EXPORT_SYMBOL(sysctl_tcp_rmem); 2911da177e4SLinus Torvalds EXPORT_SYMBOL(sysctl_tcp_wmem); 2921da177e4SLinus Torvalds 2938d987e5cSEric Dumazet atomic_long_t tcp_memory_allocated; /* Current allocated memory. */ 2941da177e4SLinus Torvalds EXPORT_SYMBOL(tcp_memory_allocated); 2951748376bSEric Dumazet 2961748376bSEric Dumazet /* 2971748376bSEric Dumazet * Current number of TCP sockets. 2981748376bSEric Dumazet */ 2991748376bSEric Dumazet struct percpu_counter tcp_sockets_allocated; 3001da177e4SLinus Torvalds EXPORT_SYMBOL(tcp_sockets_allocated); 3011da177e4SLinus Torvalds 3021da177e4SLinus Torvalds /* 3039c55e01cSJens Axboe * TCP splice context 3049c55e01cSJens Axboe */ 3059c55e01cSJens Axboe struct tcp_splice_state { 3069c55e01cSJens Axboe struct pipe_inode_info *pipe; 3079c55e01cSJens Axboe size_t len; 3089c55e01cSJens Axboe unsigned int flags; 3099c55e01cSJens Axboe }; 3109c55e01cSJens Axboe 3119c55e01cSJens Axboe /* 3121da177e4SLinus Torvalds * Pressure flag: try to collapse. 3131da177e4SLinus Torvalds * Technical note: it is used by multiple contexts non atomically. 3143ab224beSHideo Aoki * All the __sk_mem_schedule() is of this nature: accounting 3151da177e4SLinus Torvalds * is strict, actions are advisory and have some latency. 3161da177e4SLinus Torvalds */ 3174103f8cdSEric Dumazet int tcp_memory_pressure __read_mostly; 3181da177e4SLinus Torvalds EXPORT_SYMBOL(tcp_memory_pressure); 3191da177e4SLinus Torvalds 3205c52ba17SPavel Emelyanov void tcp_enter_memory_pressure(struct sock *sk) 3211da177e4SLinus Torvalds { 3221da177e4SLinus Torvalds if (!tcp_memory_pressure) { 3234e673444SPavel Emelyanov NET_INC_STATS(sock_net(sk), LINUX_MIB_TCPMEMORYPRESSURES); 3241da177e4SLinus Torvalds tcp_memory_pressure = 1; 3251da177e4SLinus Torvalds } 3261da177e4SLinus Torvalds } 3271da177e4SLinus Torvalds EXPORT_SYMBOL(tcp_enter_memory_pressure); 3281da177e4SLinus Torvalds 329b103cf34SJulian Anastasov /* Convert seconds to retransmits based on initial and max timeout */ 330b103cf34SJulian Anastasov static u8 secs_to_retrans(int seconds, int timeout, int rto_max) 331b103cf34SJulian Anastasov { 332b103cf34SJulian Anastasov u8 res = 0; 333b103cf34SJulian Anastasov 334b103cf34SJulian Anastasov if (seconds > 0) { 335b103cf34SJulian Anastasov int period = timeout; 336b103cf34SJulian Anastasov 337b103cf34SJulian Anastasov res = 1; 338b103cf34SJulian Anastasov while (seconds > period && res < 255) { 339b103cf34SJulian Anastasov res++; 340b103cf34SJulian Anastasov timeout <<= 1; 341b103cf34SJulian Anastasov if (timeout > rto_max) 342b103cf34SJulian Anastasov timeout = rto_max; 343b103cf34SJulian Anastasov period += timeout; 344b103cf34SJulian Anastasov } 345b103cf34SJulian Anastasov } 346b103cf34SJulian Anastasov return res; 347b103cf34SJulian Anastasov } 348b103cf34SJulian Anastasov 349b103cf34SJulian Anastasov /* Convert retransmits to seconds based on initial and max timeout */ 350b103cf34SJulian Anastasov static int retrans_to_secs(u8 retrans, int timeout, int rto_max) 351b103cf34SJulian Anastasov { 352b103cf34SJulian Anastasov int period = 0; 353b103cf34SJulian Anastasov 354b103cf34SJulian Anastasov if (retrans > 0) { 355b103cf34SJulian Anastasov period = timeout; 356b103cf34SJulian Anastasov while (--retrans) { 357b103cf34SJulian Anastasov timeout <<= 1; 358b103cf34SJulian Anastasov if (timeout > rto_max) 359b103cf34SJulian Anastasov timeout = rto_max; 360b103cf34SJulian Anastasov period += timeout; 361b103cf34SJulian Anastasov } 362b103cf34SJulian Anastasov } 363b103cf34SJulian Anastasov return period; 364b103cf34SJulian Anastasov } 365b103cf34SJulian Anastasov 3661da177e4SLinus Torvalds /* 3671da177e4SLinus Torvalds * Wait for a TCP event. 3681da177e4SLinus Torvalds * 3691da177e4SLinus Torvalds * Note that we don't need to lock the socket, as the upper poll layers 3701da177e4SLinus Torvalds * take care of normal races (between the test and the event) and we don't 3711da177e4SLinus Torvalds * go look at any of the socket buffers directly. 3721da177e4SLinus Torvalds */ 3731da177e4SLinus Torvalds unsigned int tcp_poll(struct file *file, struct socket *sock, poll_table *wait) 3741da177e4SLinus Torvalds { 3751da177e4SLinus Torvalds unsigned int mask; 3761da177e4SLinus Torvalds struct sock *sk = sock->sk; 377cf533ea5SEric Dumazet const struct tcp_sock *tp = tcp_sk(sk); 3781da177e4SLinus Torvalds 379aa395145SEric Dumazet sock_poll_wait(file, sk_sleep(sk), wait); 3801da177e4SLinus Torvalds if (sk->sk_state == TCP_LISTEN) 381dc40c7bcSArnaldo Carvalho de Melo return inet_csk_listen_poll(sk); 3821da177e4SLinus Torvalds 3831da177e4SLinus Torvalds /* Socket is not locked. We are protected from async events 38470efce27SWill Newton * by poll logic and correct handling of state changes 38570efce27SWill Newton * made by other threads is impossible in any case. 3861da177e4SLinus Torvalds */ 3871da177e4SLinus Torvalds 3881da177e4SLinus Torvalds mask = 0; 3891da177e4SLinus Torvalds 3901da177e4SLinus Torvalds /* 3911da177e4SLinus Torvalds * POLLHUP is certainly not done right. But poll() doesn't 3921da177e4SLinus Torvalds * have a notion of HUP in just one direction, and for a 3931da177e4SLinus Torvalds * socket the read side is more interesting. 3941da177e4SLinus Torvalds * 3951da177e4SLinus Torvalds * Some poll() documentation says that POLLHUP is incompatible 3961da177e4SLinus Torvalds * with the POLLOUT/POLLWR flags, so somebody should check this 3971da177e4SLinus Torvalds * all. But careful, it tends to be safer to return too many 3981da177e4SLinus Torvalds * bits than too few, and you can easily break real applications 3991da177e4SLinus Torvalds * if you don't tell them that something has hung up! 4001da177e4SLinus Torvalds * 4011da177e4SLinus Torvalds * Check-me. 4021da177e4SLinus Torvalds * 4031da177e4SLinus Torvalds * Check number 1. POLLHUP is _UNMASKABLE_ event (see UNIX98 and 4041da177e4SLinus Torvalds * our fs/select.c). It means that after we received EOF, 4051da177e4SLinus Torvalds * poll always returns immediately, making impossible poll() on write() 4061da177e4SLinus Torvalds * in state CLOSE_WAIT. One solution is evident --- to set POLLHUP 4071da177e4SLinus Torvalds * if and only if shutdown has been made in both directions. 4081da177e4SLinus Torvalds * Actually, it is interesting to look how Solaris and DUX 40970efce27SWill Newton * solve this dilemma. I would prefer, if POLLHUP were maskable, 4101da177e4SLinus Torvalds * then we could set it on SND_SHUTDOWN. BTW examples given 4111da177e4SLinus Torvalds * in Stevens' books assume exactly this behaviour, it explains 41270efce27SWill Newton * why POLLHUP is incompatible with POLLOUT. --ANK 4131da177e4SLinus Torvalds * 4141da177e4SLinus Torvalds * NOTE. Check for TCP_CLOSE is added. The goal is to prevent 4151da177e4SLinus Torvalds * blocking on fresh not-connected or disconnected socket. --ANK 4161da177e4SLinus Torvalds */ 4171da177e4SLinus Torvalds if (sk->sk_shutdown == SHUTDOWN_MASK || sk->sk_state == TCP_CLOSE) 4181da177e4SLinus Torvalds mask |= POLLHUP; 4191da177e4SLinus Torvalds if (sk->sk_shutdown & RCV_SHUTDOWN) 420f348d70aSDavide Libenzi mask |= POLLIN | POLLRDNORM | POLLRDHUP; 4211da177e4SLinus Torvalds 4221da177e4SLinus Torvalds /* Connected? */ 4231da177e4SLinus Torvalds if ((1 << sk->sk_state) & ~(TCPF_SYN_SENT | TCPF_SYN_RECV)) { 424c7004482SDavid S. Miller int target = sock_rcvlowat(sk, 0, INT_MAX); 425c7004482SDavid S. Miller 426c7004482SDavid S. Miller if (tp->urg_seq == tp->copied_seq && 427c7004482SDavid S. Miller !sock_flag(sk, SOCK_URGINLINE) && 428c7004482SDavid S. Miller tp->urg_data) 429b634f875SAlexandra Kossovsky target++; 430c7004482SDavid S. Miller 4311da177e4SLinus Torvalds /* Potential race condition. If read of tp below will 4321da177e4SLinus Torvalds * escape above sk->sk_state, we can be illegally awaken 4331da177e4SLinus Torvalds * in SYN_* states. */ 434c7004482SDavid S. Miller if (tp->rcv_nxt - tp->copied_seq >= target) 4351da177e4SLinus Torvalds mask |= POLLIN | POLLRDNORM; 4361da177e4SLinus Torvalds 4371da177e4SLinus Torvalds if (!(sk->sk_shutdown & SEND_SHUTDOWN)) { 4381da177e4SLinus Torvalds if (sk_stream_wspace(sk) >= sk_stream_min_wspace(sk)) { 4391da177e4SLinus Torvalds mask |= POLLOUT | POLLWRNORM; 4401da177e4SLinus Torvalds } else { /* send SIGIO later */ 4411da177e4SLinus Torvalds set_bit(SOCK_ASYNC_NOSPACE, 4421da177e4SLinus Torvalds &sk->sk_socket->flags); 4431da177e4SLinus Torvalds set_bit(SOCK_NOSPACE, &sk->sk_socket->flags); 4441da177e4SLinus Torvalds 4451da177e4SLinus Torvalds /* Race breaker. If space is freed after 4461da177e4SLinus Torvalds * wspace test but before the flags are set, 4471da177e4SLinus Torvalds * IO signal will be lost. 4481da177e4SLinus Torvalds */ 4491da177e4SLinus Torvalds if (sk_stream_wspace(sk) >= sk_stream_min_wspace(sk)) 4501da177e4SLinus Torvalds mask |= POLLOUT | POLLWRNORM; 4511da177e4SLinus Torvalds } 452d84ba638SKOSAKI Motohiro } else 453d84ba638SKOSAKI Motohiro mask |= POLLOUT | POLLWRNORM; 4541da177e4SLinus Torvalds 4551da177e4SLinus Torvalds if (tp->urg_data & TCP_URG_VALID) 4561da177e4SLinus Torvalds mask |= POLLPRI; 4571da177e4SLinus Torvalds } 458a4d25803STom Marshall /* This barrier is coupled with smp_wmb() in tcp_reset() */ 459a4d25803STom Marshall smp_rmb(); 460a4d25803STom Marshall if (sk->sk_err) 461a4d25803STom Marshall mask |= POLLERR; 462a4d25803STom Marshall 4631da177e4SLinus Torvalds return mask; 4641da177e4SLinus Torvalds } 4654bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_poll); 4661da177e4SLinus Torvalds 4671da177e4SLinus Torvalds int tcp_ioctl(struct sock *sk, int cmd, unsigned long arg) 4681da177e4SLinus Torvalds { 4691da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 4701da177e4SLinus Torvalds int answ; 4711da177e4SLinus Torvalds 4721da177e4SLinus Torvalds switch (cmd) { 4731da177e4SLinus Torvalds case SIOCINQ: 4741da177e4SLinus Torvalds if (sk->sk_state == TCP_LISTEN) 4751da177e4SLinus Torvalds return -EINVAL; 4761da177e4SLinus Torvalds 4771da177e4SLinus Torvalds lock_sock(sk); 4781da177e4SLinus Torvalds if ((1 << sk->sk_state) & (TCPF_SYN_SENT | TCPF_SYN_RECV)) 4791da177e4SLinus Torvalds answ = 0; 4801da177e4SLinus Torvalds else if (sock_flag(sk, SOCK_URGINLINE) || 4811da177e4SLinus Torvalds !tp->urg_data || 4821da177e4SLinus Torvalds before(tp->urg_seq, tp->copied_seq) || 4831da177e4SLinus Torvalds !before(tp->urg_seq, tp->rcv_nxt)) { 48491521944SDavid S. Miller struct sk_buff *skb; 48591521944SDavid S. Miller 4861da177e4SLinus Torvalds answ = tp->rcv_nxt - tp->copied_seq; 4871da177e4SLinus Torvalds 4881da177e4SLinus Torvalds /* Subtract 1, if FIN is in queue. */ 48991521944SDavid S. Miller skb = skb_peek_tail(&sk->sk_receive_queue); 49091521944SDavid S. Miller if (answ && skb) 49191521944SDavid S. Miller answ -= tcp_hdr(skb)->fin; 4921da177e4SLinus Torvalds } else 4931da177e4SLinus Torvalds answ = tp->urg_seq - tp->copied_seq; 4941da177e4SLinus Torvalds release_sock(sk); 4951da177e4SLinus Torvalds break; 4961da177e4SLinus Torvalds case SIOCATMARK: 4971da177e4SLinus Torvalds answ = tp->urg_data && tp->urg_seq == tp->copied_seq; 4981da177e4SLinus Torvalds break; 4991da177e4SLinus Torvalds case SIOCOUTQ: 5001da177e4SLinus Torvalds if (sk->sk_state == TCP_LISTEN) 5011da177e4SLinus Torvalds return -EINVAL; 5021da177e4SLinus Torvalds 5031da177e4SLinus Torvalds if ((1 << sk->sk_state) & (TCPF_SYN_SENT | TCPF_SYN_RECV)) 5041da177e4SLinus Torvalds answ = 0; 5051da177e4SLinus Torvalds else 5061da177e4SLinus Torvalds answ = tp->write_seq - tp->snd_una; 5071da177e4SLinus Torvalds break; 5082f4e1b39SMario Schuknecht case SIOCOUTQNSD: 5092f4e1b39SMario Schuknecht if (sk->sk_state == TCP_LISTEN) 5102f4e1b39SMario Schuknecht return -EINVAL; 5112f4e1b39SMario Schuknecht 5122f4e1b39SMario Schuknecht if ((1 << sk->sk_state) & (TCPF_SYN_SENT | TCPF_SYN_RECV)) 5132f4e1b39SMario Schuknecht answ = 0; 5142f4e1b39SMario Schuknecht else 5152f4e1b39SMario Schuknecht answ = tp->write_seq - tp->snd_nxt; 5162f4e1b39SMario Schuknecht break; 5171da177e4SLinus Torvalds default: 5181da177e4SLinus Torvalds return -ENOIOCTLCMD; 5193ff50b79SStephen Hemminger } 5201da177e4SLinus Torvalds 5211da177e4SLinus Torvalds return put_user(answ, (int __user *)arg); 5221da177e4SLinus Torvalds } 5234bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_ioctl); 5241da177e4SLinus Torvalds 5251da177e4SLinus Torvalds static inline void tcp_mark_push(struct tcp_sock *tp, struct sk_buff *skb) 5261da177e4SLinus Torvalds { 5274de075e0SEric Dumazet TCP_SKB_CB(skb)->tcp_flags |= TCPHDR_PSH; 5281da177e4SLinus Torvalds tp->pushed_seq = tp->write_seq; 5291da177e4SLinus Torvalds } 5301da177e4SLinus Torvalds 531cf533ea5SEric Dumazet static inline int forced_push(const struct tcp_sock *tp) 5321da177e4SLinus Torvalds { 5331da177e4SLinus Torvalds return after(tp->write_seq, tp->pushed_seq + (tp->max_window >> 1)); 5341da177e4SLinus Torvalds } 5351da177e4SLinus Torvalds 5369e412ba7SIlpo Järvinen static inline void skb_entail(struct sock *sk, struct sk_buff *skb) 5371da177e4SLinus Torvalds { 5389e412ba7SIlpo Järvinen struct tcp_sock *tp = tcp_sk(sk); 539352d4800SArnaldo Carvalho de Melo struct tcp_skb_cb *tcb = TCP_SKB_CB(skb); 540352d4800SArnaldo Carvalho de Melo 5411da177e4SLinus Torvalds skb->csum = 0; 542352d4800SArnaldo Carvalho de Melo tcb->seq = tcb->end_seq = tp->write_seq; 5434de075e0SEric Dumazet tcb->tcp_flags = TCPHDR_ACK; 544352d4800SArnaldo Carvalho de Melo tcb->sacked = 0; 5451da177e4SLinus Torvalds skb_header_release(skb); 546fe067e8aSDavid S. Miller tcp_add_write_queue_tail(sk, skb); 5473ab224beSHideo Aoki sk->sk_wmem_queued += skb->truesize; 5483ab224beSHideo Aoki sk_mem_charge(sk, skb->truesize); 54989ebd197SDavid S. Miller if (tp->nonagle & TCP_NAGLE_PUSH) 5501da177e4SLinus Torvalds tp->nonagle &= ~TCP_NAGLE_PUSH; 5511da177e4SLinus Torvalds } 5521da177e4SLinus Torvalds 553afeca340SKrishna Kumar static inline void tcp_mark_urg(struct tcp_sock *tp, int flags) 5541da177e4SLinus Torvalds { 55533f5f57eSIlpo Järvinen if (flags & MSG_OOB) 5561da177e4SLinus Torvalds tp->snd_up = tp->write_seq; 5571da177e4SLinus Torvalds } 5581da177e4SLinus Torvalds 5599e412ba7SIlpo Järvinen static inline void tcp_push(struct sock *sk, int flags, int mss_now, 5609e412ba7SIlpo Järvinen int nonagle) 5611da177e4SLinus Torvalds { 562afeca340SKrishna Kumar if (tcp_send_head(sk)) { 5639e412ba7SIlpo Järvinen struct tcp_sock *tp = tcp_sk(sk); 5649e412ba7SIlpo Järvinen 5651da177e4SLinus Torvalds if (!(flags & MSG_MORE) || forced_push(tp)) 566afeca340SKrishna Kumar tcp_mark_push(tp, tcp_write_queue_tail(sk)); 567afeca340SKrishna Kumar 568afeca340SKrishna Kumar tcp_mark_urg(tp, flags); 5699e412ba7SIlpo Järvinen __tcp_push_pending_frames(sk, mss_now, 5701da177e4SLinus Torvalds (flags & MSG_MORE) ? TCP_NAGLE_CORK : nonagle); 5711da177e4SLinus Torvalds } 5721da177e4SLinus Torvalds } 5731da177e4SLinus Torvalds 5746ff7751dSAdrian Bunk static int tcp_splice_data_recv(read_descriptor_t *rd_desc, struct sk_buff *skb, 5759c55e01cSJens Axboe unsigned int offset, size_t len) 5769c55e01cSJens Axboe { 5779c55e01cSJens Axboe struct tcp_splice_state *tss = rd_desc->arg.data; 57833966dd0SWilly Tarreau int ret; 5799c55e01cSJens Axboe 5809fa5fdf2SDimitris Michailidis ret = skb_splice_bits(skb, offset, tss->pipe, min(rd_desc->count, len), 5819fa5fdf2SDimitris Michailidis tss->flags); 58233966dd0SWilly Tarreau if (ret > 0) 58333966dd0SWilly Tarreau rd_desc->count -= ret; 58433966dd0SWilly Tarreau return ret; 5859c55e01cSJens Axboe } 5869c55e01cSJens Axboe 5879c55e01cSJens Axboe static int __tcp_splice_read(struct sock *sk, struct tcp_splice_state *tss) 5889c55e01cSJens Axboe { 5899c55e01cSJens Axboe /* Store TCP splice context information in read_descriptor_t. */ 5909c55e01cSJens Axboe read_descriptor_t rd_desc = { 5919c55e01cSJens Axboe .arg.data = tss, 59233966dd0SWilly Tarreau .count = tss->len, 5939c55e01cSJens Axboe }; 5949c55e01cSJens Axboe 5959c55e01cSJens Axboe return tcp_read_sock(sk, &rd_desc, tcp_splice_data_recv); 5969c55e01cSJens Axboe } 5979c55e01cSJens Axboe 5989c55e01cSJens Axboe /** 5999c55e01cSJens Axboe * tcp_splice_read - splice data from TCP socket to a pipe 6009c55e01cSJens Axboe * @sock: socket to splice from 6019c55e01cSJens Axboe * @ppos: position (not valid) 6029c55e01cSJens Axboe * @pipe: pipe to splice to 6039c55e01cSJens Axboe * @len: number of bytes to splice 6049c55e01cSJens Axboe * @flags: splice modifier flags 6059c55e01cSJens Axboe * 6069c55e01cSJens Axboe * Description: 6079c55e01cSJens Axboe * Will read pages from given socket and fill them into a pipe. 6089c55e01cSJens Axboe * 6099c55e01cSJens Axboe **/ 6109c55e01cSJens Axboe ssize_t tcp_splice_read(struct socket *sock, loff_t *ppos, 6119c55e01cSJens Axboe struct pipe_inode_info *pipe, size_t len, 6129c55e01cSJens Axboe unsigned int flags) 6139c55e01cSJens Axboe { 6149c55e01cSJens Axboe struct sock *sk = sock->sk; 6159c55e01cSJens Axboe struct tcp_splice_state tss = { 6169c55e01cSJens Axboe .pipe = pipe, 6179c55e01cSJens Axboe .len = len, 6189c55e01cSJens Axboe .flags = flags, 6199c55e01cSJens Axboe }; 6209c55e01cSJens Axboe long timeo; 6219c55e01cSJens Axboe ssize_t spliced; 6229c55e01cSJens Axboe int ret; 6239c55e01cSJens Axboe 6243a047bf8SChangli Gao sock_rps_record_flow(sk); 6259c55e01cSJens Axboe /* 6269c55e01cSJens Axboe * We can't seek on a socket input 6279c55e01cSJens Axboe */ 6289c55e01cSJens Axboe if (unlikely(*ppos)) 6299c55e01cSJens Axboe return -ESPIPE; 6309c55e01cSJens Axboe 6319c55e01cSJens Axboe ret = spliced = 0; 6329c55e01cSJens Axboe 6339c55e01cSJens Axboe lock_sock(sk); 6349c55e01cSJens Axboe 63542324c62SEric Dumazet timeo = sock_rcvtimeo(sk, sock->file->f_flags & O_NONBLOCK); 6369c55e01cSJens Axboe while (tss.len) { 6379c55e01cSJens Axboe ret = __tcp_splice_read(sk, &tss); 6389c55e01cSJens Axboe if (ret < 0) 6399c55e01cSJens Axboe break; 6409c55e01cSJens Axboe else if (!ret) { 6419c55e01cSJens Axboe if (spliced) 6429c55e01cSJens Axboe break; 6439c55e01cSJens Axboe if (sock_flag(sk, SOCK_DONE)) 6449c55e01cSJens Axboe break; 6459c55e01cSJens Axboe if (sk->sk_err) { 6469c55e01cSJens Axboe ret = sock_error(sk); 6479c55e01cSJens Axboe break; 6489c55e01cSJens Axboe } 6499c55e01cSJens Axboe if (sk->sk_shutdown & RCV_SHUTDOWN) 6509c55e01cSJens Axboe break; 6519c55e01cSJens Axboe if (sk->sk_state == TCP_CLOSE) { 6529c55e01cSJens Axboe /* 6539c55e01cSJens Axboe * This occurs when user tries to read 6549c55e01cSJens Axboe * from never connected socket. 6559c55e01cSJens Axboe */ 6569c55e01cSJens Axboe if (!sock_flag(sk, SOCK_DONE)) 6579c55e01cSJens Axboe ret = -ENOTCONN; 6589c55e01cSJens Axboe break; 6599c55e01cSJens Axboe } 6609c55e01cSJens Axboe if (!timeo) { 6619c55e01cSJens Axboe ret = -EAGAIN; 6629c55e01cSJens Axboe break; 6639c55e01cSJens Axboe } 6649c55e01cSJens Axboe sk_wait_data(sk, &timeo); 6659c55e01cSJens Axboe if (signal_pending(current)) { 6669c55e01cSJens Axboe ret = sock_intr_errno(timeo); 6679c55e01cSJens Axboe break; 6689c55e01cSJens Axboe } 6699c55e01cSJens Axboe continue; 6709c55e01cSJens Axboe } 6719c55e01cSJens Axboe tss.len -= ret; 6729c55e01cSJens Axboe spliced += ret; 6739c55e01cSJens Axboe 67433966dd0SWilly Tarreau if (!timeo) 67533966dd0SWilly Tarreau break; 6769c55e01cSJens Axboe release_sock(sk); 6779c55e01cSJens Axboe lock_sock(sk); 6789c55e01cSJens Axboe 6799c55e01cSJens Axboe if (sk->sk_err || sk->sk_state == TCP_CLOSE || 68033966dd0SWilly Tarreau (sk->sk_shutdown & RCV_SHUTDOWN) || 6819c55e01cSJens Axboe signal_pending(current)) 6829c55e01cSJens Axboe break; 6839c55e01cSJens Axboe } 6849c55e01cSJens Axboe 6859c55e01cSJens Axboe release_sock(sk); 6869c55e01cSJens Axboe 6879c55e01cSJens Axboe if (spliced) 6889c55e01cSJens Axboe return spliced; 6899c55e01cSJens Axboe 6909c55e01cSJens Axboe return ret; 6919c55e01cSJens Axboe } 6924bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_splice_read); 6939c55e01cSJens Axboe 694df97c708SPavel Emelyanov struct sk_buff *sk_stream_alloc_skb(struct sock *sk, int size, gfp_t gfp) 695f561d0f2SPavel Emelyanov { 696f561d0f2SPavel Emelyanov struct sk_buff *skb; 697f561d0f2SPavel Emelyanov 698f561d0f2SPavel Emelyanov /* The TCP header must be at least 32-bit aligned. */ 699f561d0f2SPavel Emelyanov size = ALIGN(size, 4); 700f561d0f2SPavel Emelyanov 701f561d0f2SPavel Emelyanov skb = alloc_skb_fclone(size + sk->sk_prot->max_header, gfp); 702f561d0f2SPavel Emelyanov if (skb) { 7033ab224beSHideo Aoki if (sk_wmem_schedule(sk, skb->truesize)) { 704a21d4572SEric Dumazet skb_reserve(skb, sk->sk_prot->max_header); 705f561d0f2SPavel Emelyanov /* 706f561d0f2SPavel Emelyanov * Make sure that we have exactly size bytes 707f561d0f2SPavel Emelyanov * available to the caller, no more, no less. 708f561d0f2SPavel Emelyanov */ 709a21d4572SEric Dumazet skb->avail_size = size; 710f561d0f2SPavel Emelyanov return skb; 711f561d0f2SPavel Emelyanov } 712f561d0f2SPavel Emelyanov __kfree_skb(skb); 713f561d0f2SPavel Emelyanov } else { 7145c52ba17SPavel Emelyanov sk->sk_prot->enter_memory_pressure(sk); 715f561d0f2SPavel Emelyanov sk_stream_moderate_sndbuf(sk); 716f561d0f2SPavel Emelyanov } 717f561d0f2SPavel Emelyanov return NULL; 718f561d0f2SPavel Emelyanov } 719f561d0f2SPavel Emelyanov 7200c54b85fSIlpo Järvinen static unsigned int tcp_xmit_size_goal(struct sock *sk, u32 mss_now, 7210c54b85fSIlpo Järvinen int large_allowed) 7220c54b85fSIlpo Järvinen { 7230c54b85fSIlpo Järvinen struct tcp_sock *tp = tcp_sk(sk); 7242a3a041cSIlpo Järvinen u32 xmit_size_goal, old_size_goal; 7250c54b85fSIlpo Järvinen 7260c54b85fSIlpo Järvinen xmit_size_goal = mss_now; 7270c54b85fSIlpo Järvinen 7280c54b85fSIlpo Järvinen if (large_allowed && sk_can_gso(sk)) { 7290c54b85fSIlpo Järvinen xmit_size_goal = ((sk->sk_gso_max_size - 1) - 7300c54b85fSIlpo Järvinen inet_csk(sk)->icsk_af_ops->net_header_len - 7310c54b85fSIlpo Järvinen inet_csk(sk)->icsk_ext_hdr_len - 7320c54b85fSIlpo Järvinen tp->tcp_header_len); 7330c54b85fSIlpo Järvinen 7340c54b85fSIlpo Järvinen xmit_size_goal = tcp_bound_to_half_wnd(tp, xmit_size_goal); 7352a3a041cSIlpo Järvinen 7362a3a041cSIlpo Järvinen /* We try hard to avoid divides here */ 7372a3a041cSIlpo Järvinen old_size_goal = tp->xmit_size_goal_segs * mss_now; 7382a3a041cSIlpo Järvinen 7392a3a041cSIlpo Järvinen if (likely(old_size_goal <= xmit_size_goal && 7402a3a041cSIlpo Järvinen old_size_goal + mss_now > xmit_size_goal)) { 7412a3a041cSIlpo Järvinen xmit_size_goal = old_size_goal; 7422a3a041cSIlpo Järvinen } else { 7432a3a041cSIlpo Järvinen tp->xmit_size_goal_segs = xmit_size_goal / mss_now; 7442a3a041cSIlpo Järvinen xmit_size_goal = tp->xmit_size_goal_segs * mss_now; 7452a3a041cSIlpo Järvinen } 7460c54b85fSIlpo Järvinen } 7470c54b85fSIlpo Järvinen 748afece1c6SIlpo Järvinen return max(xmit_size_goal, mss_now); 7490c54b85fSIlpo Järvinen } 7500c54b85fSIlpo Järvinen 7510c54b85fSIlpo Järvinen static int tcp_send_mss(struct sock *sk, int *size_goal, int flags) 7520c54b85fSIlpo Järvinen { 7530c54b85fSIlpo Järvinen int mss_now; 7540c54b85fSIlpo Järvinen 7550c54b85fSIlpo Järvinen mss_now = tcp_current_mss(sk); 7560c54b85fSIlpo Järvinen *size_goal = tcp_xmit_size_goal(sk, mss_now, !(flags & MSG_OOB)); 7570c54b85fSIlpo Järvinen 7580c54b85fSIlpo Järvinen return mss_now; 7590c54b85fSIlpo Järvinen } 7600c54b85fSIlpo Järvinen 7611da177e4SLinus Torvalds static ssize_t do_tcp_sendpages(struct sock *sk, struct page **pages, int poffset, 7621da177e4SLinus Torvalds size_t psize, int flags) 7631da177e4SLinus Torvalds { 7641da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 765c1b4a7e6SDavid S. Miller int mss_now, size_goal; 7661da177e4SLinus Torvalds int err; 7671da177e4SLinus Torvalds ssize_t copied; 7681da177e4SLinus Torvalds long timeo = sock_sndtimeo(sk, flags & MSG_DONTWAIT); 7691da177e4SLinus Torvalds 7701da177e4SLinus Torvalds /* Wait for a connection to finish. */ 7711da177e4SLinus Torvalds if ((1 << sk->sk_state) & ~(TCPF_ESTABLISHED | TCPF_CLOSE_WAIT)) 7721da177e4SLinus Torvalds if ((err = sk_stream_wait_connect(sk, &timeo)) != 0) 7731da177e4SLinus Torvalds goto out_err; 7741da177e4SLinus Torvalds 7751da177e4SLinus Torvalds clear_bit(SOCK_ASYNC_NOSPACE, &sk->sk_socket->flags); 7761da177e4SLinus Torvalds 7770c54b85fSIlpo Järvinen mss_now = tcp_send_mss(sk, &size_goal, flags); 7781da177e4SLinus Torvalds copied = 0; 7791da177e4SLinus Torvalds 7801da177e4SLinus Torvalds err = -EPIPE; 7811da177e4SLinus Torvalds if (sk->sk_err || (sk->sk_shutdown & SEND_SHUTDOWN)) 7820d6a775eSIlpo Järvinen goto out_err; 7831da177e4SLinus Torvalds 7841da177e4SLinus Torvalds while (psize > 0) { 785fe067e8aSDavid S. Miller struct sk_buff *skb = tcp_write_queue_tail(sk); 7861da177e4SLinus Torvalds struct page *page = pages[poffset / PAGE_SIZE]; 7871da177e4SLinus Torvalds int copy, i, can_coalesce; 7881da177e4SLinus Torvalds int offset = poffset % PAGE_SIZE; 7891da177e4SLinus Torvalds int size = min_t(size_t, psize, PAGE_SIZE - offset); 7901da177e4SLinus Torvalds 791fe067e8aSDavid S. Miller if (!tcp_send_head(sk) || (copy = size_goal - skb->len) <= 0) { 7921da177e4SLinus Torvalds new_segment: 7931da177e4SLinus Torvalds if (!sk_stream_memory_free(sk)) 7941da177e4SLinus Torvalds goto wait_for_sndbuf; 7951da177e4SLinus Torvalds 796df97c708SPavel Emelyanov skb = sk_stream_alloc_skb(sk, 0, sk->sk_allocation); 7971da177e4SLinus Torvalds if (!skb) 7981da177e4SLinus Torvalds goto wait_for_memory; 7991da177e4SLinus Torvalds 8009e412ba7SIlpo Järvinen skb_entail(sk, skb); 801c1b4a7e6SDavid S. Miller copy = size_goal; 8021da177e4SLinus Torvalds } 8031da177e4SLinus Torvalds 8041da177e4SLinus Torvalds if (copy > size) 8051da177e4SLinus Torvalds copy = size; 8061da177e4SLinus Torvalds 8071da177e4SLinus Torvalds i = skb_shinfo(skb)->nr_frags; 8081da177e4SLinus Torvalds can_coalesce = skb_can_coalesce(skb, i, page, offset); 8091da177e4SLinus Torvalds if (!can_coalesce && i >= MAX_SKB_FRAGS) { 8101da177e4SLinus Torvalds tcp_mark_push(tp, skb); 8111da177e4SLinus Torvalds goto new_segment; 8121da177e4SLinus Torvalds } 8133ab224beSHideo Aoki if (!sk_wmem_schedule(sk, copy)) 8141da177e4SLinus Torvalds goto wait_for_memory; 8151da177e4SLinus Torvalds 8161da177e4SLinus Torvalds if (can_coalesce) { 8179e903e08SEric Dumazet skb_frag_size_add(&skb_shinfo(skb)->frags[i - 1], copy); 8181da177e4SLinus Torvalds } else { 8191da177e4SLinus Torvalds get_page(page); 8201da177e4SLinus Torvalds skb_fill_page_desc(skb, i, page, offset, copy); 8211da177e4SLinus Torvalds } 8221da177e4SLinus Torvalds 8231da177e4SLinus Torvalds skb->len += copy; 8241da177e4SLinus Torvalds skb->data_len += copy; 8251da177e4SLinus Torvalds skb->truesize += copy; 8261da177e4SLinus Torvalds sk->sk_wmem_queued += copy; 8273ab224beSHideo Aoki sk_mem_charge(sk, copy); 82884fa7933SPatrick McHardy skb->ip_summed = CHECKSUM_PARTIAL; 8291da177e4SLinus Torvalds tp->write_seq += copy; 8301da177e4SLinus Torvalds TCP_SKB_CB(skb)->end_seq += copy; 8317967168cSHerbert Xu skb_shinfo(skb)->gso_segs = 0; 8321da177e4SLinus Torvalds 8331da177e4SLinus Torvalds if (!copied) 8344de075e0SEric Dumazet TCP_SKB_CB(skb)->tcp_flags &= ~TCPHDR_PSH; 8351da177e4SLinus Torvalds 8361da177e4SLinus Torvalds copied += copy; 8371da177e4SLinus Torvalds poffset += copy; 8381da177e4SLinus Torvalds if (!(psize -= copy)) 8391da177e4SLinus Torvalds goto out; 8401da177e4SLinus Torvalds 84169d15067SHerbert Xu if (skb->len < size_goal || (flags & MSG_OOB)) 8421da177e4SLinus Torvalds continue; 8431da177e4SLinus Torvalds 8441da177e4SLinus Torvalds if (forced_push(tp)) { 8451da177e4SLinus Torvalds tcp_mark_push(tp, skb); 8469e412ba7SIlpo Järvinen __tcp_push_pending_frames(sk, mss_now, TCP_NAGLE_PUSH); 847fe067e8aSDavid S. Miller } else if (skb == tcp_send_head(sk)) 8481da177e4SLinus Torvalds tcp_push_one(sk, mss_now); 8491da177e4SLinus Torvalds continue; 8501da177e4SLinus Torvalds 8511da177e4SLinus Torvalds wait_for_sndbuf: 8521da177e4SLinus Torvalds set_bit(SOCK_NOSPACE, &sk->sk_socket->flags); 8531da177e4SLinus Torvalds wait_for_memory: 8541da177e4SLinus Torvalds if (copied) 8559e412ba7SIlpo Järvinen tcp_push(sk, flags & ~MSG_MORE, mss_now, TCP_NAGLE_PUSH); 8561da177e4SLinus Torvalds 8571da177e4SLinus Torvalds if ((err = sk_stream_wait_memory(sk, &timeo)) != 0) 8581da177e4SLinus Torvalds goto do_error; 8591da177e4SLinus Torvalds 8600c54b85fSIlpo Järvinen mss_now = tcp_send_mss(sk, &size_goal, flags); 8611da177e4SLinus Torvalds } 8621da177e4SLinus Torvalds 8631da177e4SLinus Torvalds out: 86435f9c09fSEric Dumazet if (copied && !(flags & MSG_SENDPAGE_NOTLAST)) 8659e412ba7SIlpo Järvinen tcp_push(sk, flags, mss_now, tp->nonagle); 8661da177e4SLinus Torvalds return copied; 8671da177e4SLinus Torvalds 8681da177e4SLinus Torvalds do_error: 8691da177e4SLinus Torvalds if (copied) 8701da177e4SLinus Torvalds goto out; 8711da177e4SLinus Torvalds out_err: 8721da177e4SLinus Torvalds return sk_stream_error(sk, flags, err); 8731da177e4SLinus Torvalds } 8741da177e4SLinus Torvalds 8757ba42910SChangli Gao int tcp_sendpage(struct sock *sk, struct page *page, int offset, 8761da177e4SLinus Torvalds size_t size, int flags) 8771da177e4SLinus Torvalds { 8781da177e4SLinus Torvalds ssize_t res; 8791da177e4SLinus Torvalds 8801da177e4SLinus Torvalds if (!(sk->sk_route_caps & NETIF_F_SG) || 8818648b305SHerbert Xu !(sk->sk_route_caps & NETIF_F_ALL_CSUM)) 8827ba42910SChangli Gao return sock_no_sendpage(sk->sk_socket, page, offset, size, 8837ba42910SChangli Gao flags); 8841da177e4SLinus Torvalds 8851da177e4SLinus Torvalds lock_sock(sk); 8861da177e4SLinus Torvalds res = do_tcp_sendpages(sk, &page, offset, size, flags); 8871da177e4SLinus Torvalds release_sock(sk); 8881da177e4SLinus Torvalds return res; 8891da177e4SLinus Torvalds } 8904bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_sendpage); 8911da177e4SLinus Torvalds 892690e99c4SEric Dumazet static inline int select_size(const struct sock *sk, bool sg) 8931da177e4SLinus Torvalds { 894cf533ea5SEric Dumazet const struct tcp_sock *tp = tcp_sk(sk); 895c1b4a7e6SDavid S. Miller int tmp = tp->mss_cache; 8961da177e4SLinus Torvalds 897def87cf4SKrishna Kumar if (sg) { 898f07d960dSEric Dumazet if (sk_can_gso(sk)) { 899f07d960dSEric Dumazet /* Small frames wont use a full page: 900f07d960dSEric Dumazet * Payload will immediately follow tcp header. 901f07d960dSEric Dumazet */ 902f07d960dSEric Dumazet tmp = SKB_WITH_OVERHEAD(2048 - MAX_TCP_HEADER); 903f07d960dSEric Dumazet } else { 904b4e26f5eSDavid S. Miller int pgbreak = SKB_MAX_HEAD(MAX_TCP_HEADER); 905b4e26f5eSDavid S. Miller 906b4e26f5eSDavid S. Miller if (tmp >= pgbreak && 907b4e26f5eSDavid S. Miller tmp <= pgbreak + (MAX_SKB_FRAGS - 1) * PAGE_SIZE) 908b4e26f5eSDavid S. Miller tmp = pgbreak; 909b4e26f5eSDavid S. Miller } 910b4e26f5eSDavid S. Miller } 9111da177e4SLinus Torvalds 9121da177e4SLinus Torvalds return tmp; 9131da177e4SLinus Torvalds } 9141da177e4SLinus Torvalds 915c0e88ff0SPavel Emelyanov static int tcp_send_rcvq(struct sock *sk, struct msghdr *msg, size_t size) 916c0e88ff0SPavel Emelyanov { 917c0e88ff0SPavel Emelyanov struct sk_buff *skb; 918c0e88ff0SPavel Emelyanov struct tcp_skb_cb *cb; 919c0e88ff0SPavel Emelyanov struct tcphdr *th; 920c0e88ff0SPavel Emelyanov 921c0e88ff0SPavel Emelyanov skb = alloc_skb(size + sizeof(*th), sk->sk_allocation); 922c0e88ff0SPavel Emelyanov if (!skb) 923c0e88ff0SPavel Emelyanov goto err; 924c0e88ff0SPavel Emelyanov 925c0e88ff0SPavel Emelyanov th = (struct tcphdr *)skb_put(skb, sizeof(*th)); 926c0e88ff0SPavel Emelyanov skb_reset_transport_header(skb); 927c0e88ff0SPavel Emelyanov memset(th, 0, sizeof(*th)); 928c0e88ff0SPavel Emelyanov 929c0e88ff0SPavel Emelyanov if (memcpy_fromiovec(skb_put(skb, size), msg->msg_iov, size)) 930c0e88ff0SPavel Emelyanov goto err_free; 931c0e88ff0SPavel Emelyanov 932c0e88ff0SPavel Emelyanov cb = TCP_SKB_CB(skb); 933c0e88ff0SPavel Emelyanov 934c0e88ff0SPavel Emelyanov TCP_SKB_CB(skb)->seq = tcp_sk(sk)->rcv_nxt; 935c0e88ff0SPavel Emelyanov TCP_SKB_CB(skb)->end_seq = TCP_SKB_CB(skb)->seq + size; 936c0e88ff0SPavel Emelyanov TCP_SKB_CB(skb)->ack_seq = tcp_sk(sk)->snd_una - 1; 937c0e88ff0SPavel Emelyanov 938c0e88ff0SPavel Emelyanov tcp_queue_rcv(sk, skb, sizeof(*th)); 939c0e88ff0SPavel Emelyanov 940c0e88ff0SPavel Emelyanov return size; 941c0e88ff0SPavel Emelyanov 942c0e88ff0SPavel Emelyanov err_free: 943c0e88ff0SPavel Emelyanov kfree_skb(skb); 944c0e88ff0SPavel Emelyanov err: 945c0e88ff0SPavel Emelyanov return -ENOMEM; 946c0e88ff0SPavel Emelyanov } 947c0e88ff0SPavel Emelyanov 9487ba42910SChangli Gao int tcp_sendmsg(struct kiocb *iocb, struct sock *sk, struct msghdr *msg, 9491da177e4SLinus Torvalds size_t size) 9501da177e4SLinus Torvalds { 9511da177e4SLinus Torvalds struct iovec *iov; 9521da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 9531da177e4SLinus Torvalds struct sk_buff *skb; 954690e99c4SEric Dumazet int iovlen, flags, err, copied; 955370816aeSPavel Emelyanov int mss_now = 0, size_goal; 956690e99c4SEric Dumazet bool sg; 9571da177e4SLinus Torvalds long timeo; 9581da177e4SLinus Torvalds 9591da177e4SLinus Torvalds lock_sock(sk); 9601da177e4SLinus Torvalds 9611da177e4SLinus Torvalds flags = msg->msg_flags; 9621da177e4SLinus Torvalds timeo = sock_sndtimeo(sk, flags & MSG_DONTWAIT); 9631da177e4SLinus Torvalds 9641da177e4SLinus Torvalds /* Wait for a connection to finish. */ 9651da177e4SLinus Torvalds if ((1 << sk->sk_state) & ~(TCPF_ESTABLISHED | TCPF_CLOSE_WAIT)) 9661da177e4SLinus Torvalds if ((err = sk_stream_wait_connect(sk, &timeo)) != 0) 9671da177e4SLinus Torvalds goto out_err; 9681da177e4SLinus Torvalds 969c0e88ff0SPavel Emelyanov if (unlikely(tp->repair)) { 970c0e88ff0SPavel Emelyanov if (tp->repair_queue == TCP_RECV_QUEUE) { 971c0e88ff0SPavel Emelyanov copied = tcp_send_rcvq(sk, msg, size); 972c0e88ff0SPavel Emelyanov goto out; 973c0e88ff0SPavel Emelyanov } 974c0e88ff0SPavel Emelyanov 975c0e88ff0SPavel Emelyanov err = -EINVAL; 976c0e88ff0SPavel Emelyanov if (tp->repair_queue == TCP_NO_QUEUE) 977c0e88ff0SPavel Emelyanov goto out_err; 978c0e88ff0SPavel Emelyanov 979c0e88ff0SPavel Emelyanov /* 'common' sending to sendq */ 980c0e88ff0SPavel Emelyanov } 981c0e88ff0SPavel Emelyanov 9821da177e4SLinus Torvalds /* This should be in poll */ 9831da177e4SLinus Torvalds clear_bit(SOCK_ASYNC_NOSPACE, &sk->sk_socket->flags); 9841da177e4SLinus Torvalds 9850c54b85fSIlpo Järvinen mss_now = tcp_send_mss(sk, &size_goal, flags); 9861da177e4SLinus Torvalds 9871da177e4SLinus Torvalds /* Ok commence sending. */ 9881da177e4SLinus Torvalds iovlen = msg->msg_iovlen; 9891da177e4SLinus Torvalds iov = msg->msg_iov; 9901da177e4SLinus Torvalds copied = 0; 9911da177e4SLinus Torvalds 9921da177e4SLinus Torvalds err = -EPIPE; 9931da177e4SLinus Torvalds if (sk->sk_err || (sk->sk_shutdown & SEND_SHUTDOWN)) 9940d6a775eSIlpo Järvinen goto out_err; 9951da177e4SLinus Torvalds 996690e99c4SEric Dumazet sg = !!(sk->sk_route_caps & NETIF_F_SG); 997def87cf4SKrishna Kumar 9981da177e4SLinus Torvalds while (--iovlen >= 0) { 99901db403cSDavid S. Miller size_t seglen = iov->iov_len; 10001da177e4SLinus Torvalds unsigned char __user *from = iov->iov_base; 10011da177e4SLinus Torvalds 10021da177e4SLinus Torvalds iov++; 10031da177e4SLinus Torvalds 10041da177e4SLinus Torvalds while (seglen > 0) { 10056828b92bSHerbert Xu int copy = 0; 10066828b92bSHerbert Xu int max = size_goal; 10071da177e4SLinus Torvalds 1008fe067e8aSDavid S. Miller skb = tcp_write_queue_tail(sk); 10096828b92bSHerbert Xu if (tcp_send_head(sk)) { 10106828b92bSHerbert Xu if (skb->ip_summed == CHECKSUM_NONE) 10116828b92bSHerbert Xu max = mss_now; 10126828b92bSHerbert Xu copy = max - skb->len; 10136828b92bSHerbert Xu } 10141da177e4SLinus Torvalds 10156828b92bSHerbert Xu if (copy <= 0) { 10161da177e4SLinus Torvalds new_segment: 10171da177e4SLinus Torvalds /* Allocate new segment. If the interface is SG, 10181da177e4SLinus Torvalds * allocate skb fitting to single page. 10191da177e4SLinus Torvalds */ 10201da177e4SLinus Torvalds if (!sk_stream_memory_free(sk)) 10211da177e4SLinus Torvalds goto wait_for_sndbuf; 10221da177e4SLinus Torvalds 1023def87cf4SKrishna Kumar skb = sk_stream_alloc_skb(sk, 1024def87cf4SKrishna Kumar select_size(sk, sg), 1025df97c708SPavel Emelyanov sk->sk_allocation); 10261da177e4SLinus Torvalds if (!skb) 10271da177e4SLinus Torvalds goto wait_for_memory; 10281da177e4SLinus Torvalds 10291da177e4SLinus Torvalds /* 10301da177e4SLinus Torvalds * Check whether we can use HW checksum. 10311da177e4SLinus Torvalds */ 10328648b305SHerbert Xu if (sk->sk_route_caps & NETIF_F_ALL_CSUM) 103384fa7933SPatrick McHardy skb->ip_summed = CHECKSUM_PARTIAL; 10341da177e4SLinus Torvalds 10359e412ba7SIlpo Järvinen skb_entail(sk, skb); 1036c1b4a7e6SDavid S. Miller copy = size_goal; 10376828b92bSHerbert Xu max = size_goal; 10381da177e4SLinus Torvalds } 10391da177e4SLinus Torvalds 10401da177e4SLinus Torvalds /* Try to append data to the end of skb. */ 10411da177e4SLinus Torvalds if (copy > seglen) 10421da177e4SLinus Torvalds copy = seglen; 10431da177e4SLinus Torvalds 10441da177e4SLinus Torvalds /* Where to copy to? */ 1045a21d4572SEric Dumazet if (skb_availroom(skb) > 0) { 10461da177e4SLinus Torvalds /* We have some space in skb head. Superb! */ 1047a21d4572SEric Dumazet copy = min_t(int, copy, skb_availroom(skb)); 1048c6e1a0d1STom Herbert err = skb_add_data_nocache(sk, skb, from, copy); 1049c6e1a0d1STom Herbert if (err) 10501da177e4SLinus Torvalds goto do_fault; 10511da177e4SLinus Torvalds } else { 10521da177e4SLinus Torvalds int merge = 0; 10531da177e4SLinus Torvalds int i = skb_shinfo(skb)->nr_frags; 10540a5912dbSEric Dumazet struct page *page = sk->sk_sndmsg_page; 1055761965eaSEric Dumazet int off; 1056761965eaSEric Dumazet 1057761965eaSEric Dumazet if (page && page_count(page) == 1) 10580a5912dbSEric Dumazet sk->sk_sndmsg_off = 0; 1059761965eaSEric Dumazet 10600a5912dbSEric Dumazet off = sk->sk_sndmsg_off; 10611da177e4SLinus Torvalds 10621da177e4SLinus Torvalds if (skb_can_coalesce(skb, i, page, off) && 10631da177e4SLinus Torvalds off != PAGE_SIZE) { 10641da177e4SLinus Torvalds /* We can extend the last page 10651da177e4SLinus Torvalds * fragment. */ 10661da177e4SLinus Torvalds merge = 1; 1067def87cf4SKrishna Kumar } else if (i == MAX_SKB_FRAGS || !sg) { 10681da177e4SLinus Torvalds /* Need to add new fragment and cannot 10691da177e4SLinus Torvalds * do this because interface is non-SG, 10701da177e4SLinus Torvalds * or because all the page slots are 10711da177e4SLinus Torvalds * busy. */ 10721da177e4SLinus Torvalds tcp_mark_push(tp, skb); 10731da177e4SLinus Torvalds goto new_segment; 10741da177e4SLinus Torvalds } else if (page) { 10751da177e4SLinus Torvalds if (off == PAGE_SIZE) { 10761da177e4SLinus Torvalds put_page(page); 10770a5912dbSEric Dumazet sk->sk_sndmsg_page = page = NULL; 1078fb5f5e6eSHerbert Xu off = 0; 10791da177e4SLinus Torvalds } 1080ef015786SHerbert Xu } else 1081fb5f5e6eSHerbert Xu off = 0; 1082ef015786SHerbert Xu 1083ef015786SHerbert Xu if (copy > PAGE_SIZE - off) 1084ef015786SHerbert Xu copy = PAGE_SIZE - off; 1085ef015786SHerbert Xu 10863ab224beSHideo Aoki if (!sk_wmem_schedule(sk, copy)) 1087ef015786SHerbert Xu goto wait_for_memory; 10881da177e4SLinus Torvalds 10891da177e4SLinus Torvalds if (!page) { 10901da177e4SLinus Torvalds /* Allocate new cache page. */ 10911da177e4SLinus Torvalds if (!(page = sk_stream_alloc_page(sk))) 10921da177e4SLinus Torvalds goto wait_for_memory; 10931da177e4SLinus Torvalds } 10941da177e4SLinus Torvalds 10951da177e4SLinus Torvalds /* Time to copy data. We are close to 10961da177e4SLinus Torvalds * the end! */ 1097c6e1a0d1STom Herbert err = skb_copy_to_page_nocache(sk, from, skb, 1098c6e1a0d1STom Herbert page, off, copy); 10991da177e4SLinus Torvalds if (err) { 11001da177e4SLinus Torvalds /* If this page was new, give it to the 11011da177e4SLinus Torvalds * socket so it does not get leaked. 11021da177e4SLinus Torvalds */ 11030a5912dbSEric Dumazet if (!sk->sk_sndmsg_page) { 11040a5912dbSEric Dumazet sk->sk_sndmsg_page = page; 11050a5912dbSEric Dumazet sk->sk_sndmsg_off = 0; 11061da177e4SLinus Torvalds } 11071da177e4SLinus Torvalds goto do_error; 11081da177e4SLinus Torvalds } 11091da177e4SLinus Torvalds 11101da177e4SLinus Torvalds /* Update the skb. */ 11111da177e4SLinus Torvalds if (merge) { 11129e903e08SEric Dumazet skb_frag_size_add(&skb_shinfo(skb)->frags[i - 1], copy); 11131da177e4SLinus Torvalds } else { 11141da177e4SLinus Torvalds skb_fill_page_desc(skb, i, page, off, copy); 11150a5912dbSEric Dumazet if (sk->sk_sndmsg_page) { 11161da177e4SLinus Torvalds get_page(page); 11171da177e4SLinus Torvalds } else if (off + copy < PAGE_SIZE) { 11181da177e4SLinus Torvalds get_page(page); 11190a5912dbSEric Dumazet sk->sk_sndmsg_page = page; 11201da177e4SLinus Torvalds } 11211da177e4SLinus Torvalds } 11221da177e4SLinus Torvalds 11230a5912dbSEric Dumazet sk->sk_sndmsg_off = off + copy; 11241da177e4SLinus Torvalds } 11251da177e4SLinus Torvalds 11261da177e4SLinus Torvalds if (!copied) 11274de075e0SEric Dumazet TCP_SKB_CB(skb)->tcp_flags &= ~TCPHDR_PSH; 11281da177e4SLinus Torvalds 11291da177e4SLinus Torvalds tp->write_seq += copy; 11301da177e4SLinus Torvalds TCP_SKB_CB(skb)->end_seq += copy; 11317967168cSHerbert Xu skb_shinfo(skb)->gso_segs = 0; 11321da177e4SLinus Torvalds 11331da177e4SLinus Torvalds from += copy; 11341da177e4SLinus Torvalds copied += copy; 11351da177e4SLinus Torvalds if ((seglen -= copy) == 0 && iovlen == 0) 11361da177e4SLinus Torvalds goto out; 11371da177e4SLinus Torvalds 1138c0e88ff0SPavel Emelyanov if (skb->len < max || (flags & MSG_OOB) || unlikely(tp->repair)) 11391da177e4SLinus Torvalds continue; 11401da177e4SLinus Torvalds 11411da177e4SLinus Torvalds if (forced_push(tp)) { 11421da177e4SLinus Torvalds tcp_mark_push(tp, skb); 11439e412ba7SIlpo Järvinen __tcp_push_pending_frames(sk, mss_now, TCP_NAGLE_PUSH); 1144fe067e8aSDavid S. Miller } else if (skb == tcp_send_head(sk)) 11451da177e4SLinus Torvalds tcp_push_one(sk, mss_now); 11461da177e4SLinus Torvalds continue; 11471da177e4SLinus Torvalds 11481da177e4SLinus Torvalds wait_for_sndbuf: 11491da177e4SLinus Torvalds set_bit(SOCK_NOSPACE, &sk->sk_socket->flags); 11501da177e4SLinus Torvalds wait_for_memory: 1151c0e88ff0SPavel Emelyanov if (copied && likely(!tp->repair)) 11529e412ba7SIlpo Järvinen tcp_push(sk, flags & ~MSG_MORE, mss_now, TCP_NAGLE_PUSH); 11531da177e4SLinus Torvalds 11541da177e4SLinus Torvalds if ((err = sk_stream_wait_memory(sk, &timeo)) != 0) 11551da177e4SLinus Torvalds goto do_error; 11561da177e4SLinus Torvalds 11570c54b85fSIlpo Järvinen mss_now = tcp_send_mss(sk, &size_goal, flags); 11581da177e4SLinus Torvalds } 11591da177e4SLinus Torvalds } 11601da177e4SLinus Torvalds 11611da177e4SLinus Torvalds out: 1162c0e88ff0SPavel Emelyanov if (copied && likely(!tp->repair)) 11639e412ba7SIlpo Järvinen tcp_push(sk, flags, mss_now, tp->nonagle); 11641da177e4SLinus Torvalds release_sock(sk); 11651da177e4SLinus Torvalds return copied; 11661da177e4SLinus Torvalds 11671da177e4SLinus Torvalds do_fault: 11681da177e4SLinus Torvalds if (!skb->len) { 1169fe067e8aSDavid S. Miller tcp_unlink_write_queue(skb, sk); 1170fe067e8aSDavid S. Miller /* It is the one place in all of TCP, except connection 1171fe067e8aSDavid S. Miller * reset, where we can be unlinking the send_head. 1172fe067e8aSDavid S. Miller */ 1173fe067e8aSDavid S. Miller tcp_check_send_head(sk, skb); 11743ab224beSHideo Aoki sk_wmem_free_skb(sk, skb); 11751da177e4SLinus Torvalds } 11761da177e4SLinus Torvalds 11771da177e4SLinus Torvalds do_error: 11781da177e4SLinus Torvalds if (copied) 11791da177e4SLinus Torvalds goto out; 11801da177e4SLinus Torvalds out_err: 11811da177e4SLinus Torvalds err = sk_stream_error(sk, flags, err); 11821da177e4SLinus Torvalds release_sock(sk); 11831da177e4SLinus Torvalds return err; 11841da177e4SLinus Torvalds } 11854bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_sendmsg); 11861da177e4SLinus Torvalds 11871da177e4SLinus Torvalds /* 11881da177e4SLinus Torvalds * Handle reading urgent data. BSD has very simple semantics for 11891da177e4SLinus Torvalds * this, no blocking and very strange errors 8) 11901da177e4SLinus Torvalds */ 11911da177e4SLinus Torvalds 1192377f0a08SRami Rosen static int tcp_recv_urg(struct sock *sk, struct msghdr *msg, int len, int flags) 11931da177e4SLinus Torvalds { 11941da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 11951da177e4SLinus Torvalds 11961da177e4SLinus Torvalds /* No URG data to read. */ 11971da177e4SLinus Torvalds if (sock_flag(sk, SOCK_URGINLINE) || !tp->urg_data || 11981da177e4SLinus Torvalds tp->urg_data == TCP_URG_READ) 11991da177e4SLinus Torvalds return -EINVAL; /* Yes this is right ! */ 12001da177e4SLinus Torvalds 12011da177e4SLinus Torvalds if (sk->sk_state == TCP_CLOSE && !sock_flag(sk, SOCK_DONE)) 12021da177e4SLinus Torvalds return -ENOTCONN; 12031da177e4SLinus Torvalds 12041da177e4SLinus Torvalds if (tp->urg_data & TCP_URG_VALID) { 12051da177e4SLinus Torvalds int err = 0; 12061da177e4SLinus Torvalds char c = tp->urg_data; 12071da177e4SLinus Torvalds 12081da177e4SLinus Torvalds if (!(flags & MSG_PEEK)) 12091da177e4SLinus Torvalds tp->urg_data = TCP_URG_READ; 12101da177e4SLinus Torvalds 12111da177e4SLinus Torvalds /* Read urgent data. */ 12121da177e4SLinus Torvalds msg->msg_flags |= MSG_OOB; 12131da177e4SLinus Torvalds 12141da177e4SLinus Torvalds if (len > 0) { 12151da177e4SLinus Torvalds if (!(flags & MSG_TRUNC)) 12161da177e4SLinus Torvalds err = memcpy_toiovec(msg->msg_iov, &c, 1); 12171da177e4SLinus Torvalds len = 1; 12181da177e4SLinus Torvalds } else 12191da177e4SLinus Torvalds msg->msg_flags |= MSG_TRUNC; 12201da177e4SLinus Torvalds 12211da177e4SLinus Torvalds return err ? -EFAULT : len; 12221da177e4SLinus Torvalds } 12231da177e4SLinus Torvalds 12241da177e4SLinus Torvalds if (sk->sk_state == TCP_CLOSE || (sk->sk_shutdown & RCV_SHUTDOWN)) 12251da177e4SLinus Torvalds return 0; 12261da177e4SLinus Torvalds 12271da177e4SLinus Torvalds /* Fixed the recv(..., MSG_OOB) behaviour. BSD docs and 12281da177e4SLinus Torvalds * the available implementations agree in this case: 12291da177e4SLinus Torvalds * this call should never block, independent of the 12301da177e4SLinus Torvalds * blocking state of the socket. 12311da177e4SLinus Torvalds * Mike <pall@rz.uni-karlsruhe.de> 12321da177e4SLinus Torvalds */ 12331da177e4SLinus Torvalds return -EAGAIN; 12341da177e4SLinus Torvalds } 12351da177e4SLinus Torvalds 1236c0e88ff0SPavel Emelyanov static int tcp_peek_sndq(struct sock *sk, struct msghdr *msg, int len) 1237c0e88ff0SPavel Emelyanov { 1238c0e88ff0SPavel Emelyanov struct sk_buff *skb; 1239c0e88ff0SPavel Emelyanov int copied = 0, err = 0; 1240c0e88ff0SPavel Emelyanov 1241c0e88ff0SPavel Emelyanov /* XXX -- need to support SO_PEEK_OFF */ 1242c0e88ff0SPavel Emelyanov 1243c0e88ff0SPavel Emelyanov skb_queue_walk(&sk->sk_write_queue, skb) { 1244c0e88ff0SPavel Emelyanov err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, skb->len); 1245c0e88ff0SPavel Emelyanov if (err) 1246c0e88ff0SPavel Emelyanov break; 1247c0e88ff0SPavel Emelyanov 1248c0e88ff0SPavel Emelyanov copied += skb->len; 1249c0e88ff0SPavel Emelyanov } 1250c0e88ff0SPavel Emelyanov 1251c0e88ff0SPavel Emelyanov return err ?: copied; 1252c0e88ff0SPavel Emelyanov } 1253c0e88ff0SPavel Emelyanov 12541da177e4SLinus Torvalds /* Clean up the receive buffer for full frames taken by the user, 12551da177e4SLinus Torvalds * then send an ACK if necessary. COPIED is the number of bytes 12561da177e4SLinus Torvalds * tcp_recvmsg has given to the user so far, it speeds up the 12571da177e4SLinus Torvalds * calculation of whether or not we must ACK for the sake of 12581da177e4SLinus Torvalds * a window update. 12591da177e4SLinus Torvalds */ 12600e4b4992SChris Leech void tcp_cleanup_rbuf(struct sock *sk, int copied) 12611da177e4SLinus Torvalds { 12621da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 12631da177e4SLinus Torvalds int time_to_ack = 0; 12641da177e4SLinus Torvalds 12651da177e4SLinus Torvalds struct sk_buff *skb = skb_peek(&sk->sk_receive_queue); 12661da177e4SLinus Torvalds 1267d792c100SIlpo Järvinen WARN(skb && !before(tp->copied_seq, TCP_SKB_CB(skb)->end_seq), 12682af6fd8bSJoe Perches "cleanup rbuf bug: copied %X seq %X rcvnxt %X\n", 1269d792c100SIlpo Järvinen tp->copied_seq, TCP_SKB_CB(skb)->end_seq, tp->rcv_nxt); 12701da177e4SLinus Torvalds 1271463c84b9SArnaldo Carvalho de Melo if (inet_csk_ack_scheduled(sk)) { 1272463c84b9SArnaldo Carvalho de Melo const struct inet_connection_sock *icsk = inet_csk(sk); 12731da177e4SLinus Torvalds /* Delayed ACKs frequently hit locked sockets during bulk 12741da177e4SLinus Torvalds * receive. */ 1275463c84b9SArnaldo Carvalho de Melo if (icsk->icsk_ack.blocked || 12761da177e4SLinus Torvalds /* Once-per-two-segments ACK was not sent by tcp_input.c */ 1277463c84b9SArnaldo Carvalho de Melo tp->rcv_nxt - tp->rcv_wup > icsk->icsk_ack.rcv_mss || 12781da177e4SLinus Torvalds /* 12791da177e4SLinus Torvalds * If this read emptied read buffer, we send ACK, if 12801da177e4SLinus Torvalds * connection is not bidirectional, user drained 12811da177e4SLinus Torvalds * receive buffer and there was a small segment 12821da177e4SLinus Torvalds * in queue. 12831da177e4SLinus Torvalds */ 12841ef9696cSAlexey Kuznetsov (copied > 0 && 12851ef9696cSAlexey Kuznetsov ((icsk->icsk_ack.pending & ICSK_ACK_PUSHED2) || 12861ef9696cSAlexey Kuznetsov ((icsk->icsk_ack.pending & ICSK_ACK_PUSHED) && 12871ef9696cSAlexey Kuznetsov !icsk->icsk_ack.pingpong)) && 12881ef9696cSAlexey Kuznetsov !atomic_read(&sk->sk_rmem_alloc))) 12891da177e4SLinus Torvalds time_to_ack = 1; 12901da177e4SLinus Torvalds } 12911da177e4SLinus Torvalds 12921da177e4SLinus Torvalds /* We send an ACK if we can now advertise a non-zero window 12931da177e4SLinus Torvalds * which has been raised "significantly". 12941da177e4SLinus Torvalds * 12951da177e4SLinus Torvalds * Even if window raised up to infinity, do not send window open ACK 12961da177e4SLinus Torvalds * in states, where we will not receive more. It is useless. 12971da177e4SLinus Torvalds */ 12981da177e4SLinus Torvalds if (copied > 0 && !time_to_ack && !(sk->sk_shutdown & RCV_SHUTDOWN)) { 12991da177e4SLinus Torvalds __u32 rcv_window_now = tcp_receive_window(tp); 13001da177e4SLinus Torvalds 13011da177e4SLinus Torvalds /* Optimize, __tcp_select_window() is not cheap. */ 13021da177e4SLinus Torvalds if (2*rcv_window_now <= tp->window_clamp) { 13031da177e4SLinus Torvalds __u32 new_window = __tcp_select_window(sk); 13041da177e4SLinus Torvalds 13051da177e4SLinus Torvalds /* Send ACK now, if this read freed lots of space 13061da177e4SLinus Torvalds * in our buffer. Certainly, new_window is new window. 13071da177e4SLinus Torvalds * We can advertise it now, if it is not less than current one. 13081da177e4SLinus Torvalds * "Lots" means "at least twice" here. 13091da177e4SLinus Torvalds */ 13101da177e4SLinus Torvalds if (new_window && new_window >= 2 * rcv_window_now) 13111da177e4SLinus Torvalds time_to_ack = 1; 13121da177e4SLinus Torvalds } 13131da177e4SLinus Torvalds } 13141da177e4SLinus Torvalds if (time_to_ack) 13151da177e4SLinus Torvalds tcp_send_ack(sk); 13161da177e4SLinus Torvalds } 13171da177e4SLinus Torvalds 13181da177e4SLinus Torvalds static void tcp_prequeue_process(struct sock *sk) 13191da177e4SLinus Torvalds { 13201da177e4SLinus Torvalds struct sk_buff *skb; 13211da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 13221da177e4SLinus Torvalds 13236f67c817SPavel Emelyanov NET_INC_STATS_USER(sock_net(sk), LINUX_MIB_TCPPREQUEUED); 13241da177e4SLinus Torvalds 13251da177e4SLinus Torvalds /* RX process wants to run with disabled BHs, though it is not 13261da177e4SLinus Torvalds * necessary */ 13271da177e4SLinus Torvalds local_bh_disable(); 13281da177e4SLinus Torvalds while ((skb = __skb_dequeue(&tp->ucopy.prequeue)) != NULL) 1329c57943a1SPeter Zijlstra sk_backlog_rcv(sk, skb); 13301da177e4SLinus Torvalds local_bh_enable(); 13311da177e4SLinus Torvalds 13321da177e4SLinus Torvalds /* Clear memory counter. */ 13331da177e4SLinus Torvalds tp->ucopy.memory = 0; 13341da177e4SLinus Torvalds } 13351da177e4SLinus Torvalds 133673852e81SSteven J. Magnani #ifdef CONFIG_NET_DMA 133773852e81SSteven J. Magnani static void tcp_service_net_dma(struct sock *sk, bool wait) 133873852e81SSteven J. Magnani { 133973852e81SSteven J. Magnani dma_cookie_t done, used; 134073852e81SSteven J. Magnani dma_cookie_t last_issued; 134173852e81SSteven J. Magnani struct tcp_sock *tp = tcp_sk(sk); 134273852e81SSteven J. Magnani 134373852e81SSteven J. Magnani if (!tp->ucopy.dma_chan) 134473852e81SSteven J. Magnani return; 134573852e81SSteven J. Magnani 134673852e81SSteven J. Magnani last_issued = tp->ucopy.dma_cookie; 134773852e81SSteven J. Magnani dma_async_memcpy_issue_pending(tp->ucopy.dma_chan); 134873852e81SSteven J. Magnani 134973852e81SSteven J. Magnani do { 135073852e81SSteven J. Magnani if (dma_async_memcpy_complete(tp->ucopy.dma_chan, 135173852e81SSteven J. Magnani last_issued, &done, 135273852e81SSteven J. Magnani &used) == DMA_SUCCESS) { 135373852e81SSteven J. Magnani /* Safe to free early-copied skbs now */ 135473852e81SSteven J. Magnani __skb_queue_purge(&sk->sk_async_wait_queue); 135573852e81SSteven J. Magnani break; 135673852e81SSteven J. Magnani } else { 135773852e81SSteven J. Magnani struct sk_buff *skb; 135873852e81SSteven J. Magnani while ((skb = skb_peek(&sk->sk_async_wait_queue)) && 135973852e81SSteven J. Magnani (dma_async_is_complete(skb->dma_cookie, done, 136073852e81SSteven J. Magnani used) == DMA_SUCCESS)) { 136173852e81SSteven J. Magnani __skb_dequeue(&sk->sk_async_wait_queue); 136273852e81SSteven J. Magnani kfree_skb(skb); 136373852e81SSteven J. Magnani } 136473852e81SSteven J. Magnani } 136573852e81SSteven J. Magnani } while (wait); 136673852e81SSteven J. Magnani } 136773852e81SSteven J. Magnani #endif 136873852e81SSteven J. Magnani 13691da177e4SLinus Torvalds static inline struct sk_buff *tcp_recv_skb(struct sock *sk, u32 seq, u32 *off) 13701da177e4SLinus Torvalds { 13711da177e4SLinus Torvalds struct sk_buff *skb; 13721da177e4SLinus Torvalds u32 offset; 13731da177e4SLinus Torvalds 13741da177e4SLinus Torvalds skb_queue_walk(&sk->sk_receive_queue, skb) { 13751da177e4SLinus Torvalds offset = seq - TCP_SKB_CB(skb)->seq; 1376aa8223c7SArnaldo Carvalho de Melo if (tcp_hdr(skb)->syn) 13771da177e4SLinus Torvalds offset--; 1378aa8223c7SArnaldo Carvalho de Melo if (offset < skb->len || tcp_hdr(skb)->fin) { 13791da177e4SLinus Torvalds *off = offset; 13801da177e4SLinus Torvalds return skb; 13811da177e4SLinus Torvalds } 13821da177e4SLinus Torvalds } 13831da177e4SLinus Torvalds return NULL; 13841da177e4SLinus Torvalds } 13851da177e4SLinus Torvalds 13861da177e4SLinus Torvalds /* 13871da177e4SLinus Torvalds * This routine provides an alternative to tcp_recvmsg() for routines 13881da177e4SLinus Torvalds * that would like to handle copying from skbuffs directly in 'sendfile' 13891da177e4SLinus Torvalds * fashion. 13901da177e4SLinus Torvalds * Note: 13911da177e4SLinus Torvalds * - It is assumed that the socket was locked by the caller. 13921da177e4SLinus Torvalds * - The routine does not block. 13931da177e4SLinus Torvalds * - At present, there is no support for reading OOB data 13941da177e4SLinus Torvalds * or for 'peeking' the socket using this routine 13951da177e4SLinus Torvalds * (although both would be easy to implement). 13961da177e4SLinus Torvalds */ 13971da177e4SLinus Torvalds int tcp_read_sock(struct sock *sk, read_descriptor_t *desc, 13981da177e4SLinus Torvalds sk_read_actor_t recv_actor) 13991da177e4SLinus Torvalds { 14001da177e4SLinus Torvalds struct sk_buff *skb; 14011da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 14021da177e4SLinus Torvalds u32 seq = tp->copied_seq; 14031da177e4SLinus Torvalds u32 offset; 14041da177e4SLinus Torvalds int copied = 0; 14051da177e4SLinus Torvalds 14061da177e4SLinus Torvalds if (sk->sk_state == TCP_LISTEN) 14071da177e4SLinus Torvalds return -ENOTCONN; 14081da177e4SLinus Torvalds while ((skb = tcp_recv_skb(sk, seq, &offset)) != NULL) { 14091da177e4SLinus Torvalds if (offset < skb->len) { 1410374e7b59SOctavian Purdila int used; 1411374e7b59SOctavian Purdila size_t len; 14121da177e4SLinus Torvalds 14131da177e4SLinus Torvalds len = skb->len - offset; 14141da177e4SLinus Torvalds /* Stop reading if we hit a patch of urgent data */ 14151da177e4SLinus Torvalds if (tp->urg_data) { 14161da177e4SLinus Torvalds u32 urg_offset = tp->urg_seq - seq; 14171da177e4SLinus Torvalds if (urg_offset < len) 14181da177e4SLinus Torvalds len = urg_offset; 14191da177e4SLinus Torvalds if (!len) 14201da177e4SLinus Torvalds break; 14211da177e4SLinus Torvalds } 14221da177e4SLinus Torvalds used = recv_actor(desc, skb, offset, len); 1423ddb61a57SJens Axboe if (used < 0) { 1424ddb61a57SJens Axboe if (!copied) 1425ddb61a57SJens Axboe copied = used; 1426ddb61a57SJens Axboe break; 1427ddb61a57SJens Axboe } else if (used <= len) { 14281da177e4SLinus Torvalds seq += used; 14291da177e4SLinus Torvalds copied += used; 14301da177e4SLinus Torvalds offset += used; 14311da177e4SLinus Torvalds } 1432293ad604SOctavian Purdila /* 1433293ad604SOctavian Purdila * If recv_actor drops the lock (e.g. TCP splice 1434293ad604SOctavian Purdila * receive) the skb pointer might be invalid when 1435293ad604SOctavian Purdila * getting here: tcp_collapse might have deleted it 1436293ad604SOctavian Purdila * while aggregating skbs from the socket queue. 1437293ad604SOctavian Purdila */ 1438293ad604SOctavian Purdila skb = tcp_recv_skb(sk, seq-1, &offset); 1439293ad604SOctavian Purdila if (!skb || (offset+1 != skb->len)) 14401da177e4SLinus Torvalds break; 14411da177e4SLinus Torvalds } 1442aa8223c7SArnaldo Carvalho de Melo if (tcp_hdr(skb)->fin) { 1443624d1164SChris Leech sk_eat_skb(sk, skb, 0); 14441da177e4SLinus Torvalds ++seq; 14451da177e4SLinus Torvalds break; 14461da177e4SLinus Torvalds } 1447624d1164SChris Leech sk_eat_skb(sk, skb, 0); 14481da177e4SLinus Torvalds if (!desc->count) 14491da177e4SLinus Torvalds break; 1450baff42abSSteven J. Magnani tp->copied_seq = seq; 14511da177e4SLinus Torvalds } 14521da177e4SLinus Torvalds tp->copied_seq = seq; 14531da177e4SLinus Torvalds 14541da177e4SLinus Torvalds tcp_rcv_space_adjust(sk); 14551da177e4SLinus Torvalds 14561da177e4SLinus Torvalds /* Clean up data we have read: This will do ACK frames. */ 1457ddb61a57SJens Axboe if (copied > 0) 14580e4b4992SChris Leech tcp_cleanup_rbuf(sk, copied); 14591da177e4SLinus Torvalds return copied; 14601da177e4SLinus Torvalds } 14614bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_read_sock); 14621da177e4SLinus Torvalds 14631da177e4SLinus Torvalds /* 14641da177e4SLinus Torvalds * This routine copies from a sock struct into the user buffer. 14651da177e4SLinus Torvalds * 14661da177e4SLinus Torvalds * Technical note: in 2.3 we work on _locked_ socket, so that 14671da177e4SLinus Torvalds * tricks with *seq access order and skb->users are not required. 14681da177e4SLinus Torvalds * Probably, code can be easily improved even more. 14691da177e4SLinus Torvalds */ 14701da177e4SLinus Torvalds 14711da177e4SLinus Torvalds int tcp_recvmsg(struct kiocb *iocb, struct sock *sk, struct msghdr *msg, 14721da177e4SLinus Torvalds size_t len, int nonblock, int flags, int *addr_len) 14731da177e4SLinus Torvalds { 14741da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 14751da177e4SLinus Torvalds int copied = 0; 14761da177e4SLinus Torvalds u32 peek_seq; 14771da177e4SLinus Torvalds u32 *seq; 14781da177e4SLinus Torvalds unsigned long used; 14791da177e4SLinus Torvalds int err; 14801da177e4SLinus Torvalds int target; /* Read at least this many bytes */ 14811da177e4SLinus Torvalds long timeo; 14821da177e4SLinus Torvalds struct task_struct *user_recv = NULL; 14831a2449a8SChris Leech int copied_early = 0; 14842b1244a4SChris Leech struct sk_buff *skb; 148577527313SIlpo Järvinen u32 urg_hole = 0; 14861da177e4SLinus Torvalds 14871da177e4SLinus Torvalds lock_sock(sk); 14881da177e4SLinus Torvalds 14891da177e4SLinus Torvalds err = -ENOTCONN; 14901da177e4SLinus Torvalds if (sk->sk_state == TCP_LISTEN) 14911da177e4SLinus Torvalds goto out; 14921da177e4SLinus Torvalds 14931da177e4SLinus Torvalds timeo = sock_rcvtimeo(sk, nonblock); 14941da177e4SLinus Torvalds 14951da177e4SLinus Torvalds /* Urgent data needs to be handled specially. */ 14961da177e4SLinus Torvalds if (flags & MSG_OOB) 14971da177e4SLinus Torvalds goto recv_urg; 14981da177e4SLinus Torvalds 1499c0e88ff0SPavel Emelyanov if (unlikely(tp->repair)) { 1500c0e88ff0SPavel Emelyanov err = -EPERM; 1501c0e88ff0SPavel Emelyanov if (!(flags & MSG_PEEK)) 1502c0e88ff0SPavel Emelyanov goto out; 1503c0e88ff0SPavel Emelyanov 1504c0e88ff0SPavel Emelyanov if (tp->repair_queue == TCP_SEND_QUEUE) 1505c0e88ff0SPavel Emelyanov goto recv_sndq; 1506c0e88ff0SPavel Emelyanov 1507c0e88ff0SPavel Emelyanov err = -EINVAL; 1508c0e88ff0SPavel Emelyanov if (tp->repair_queue == TCP_NO_QUEUE) 1509c0e88ff0SPavel Emelyanov goto out; 1510c0e88ff0SPavel Emelyanov 1511c0e88ff0SPavel Emelyanov /* 'common' recv queue MSG_PEEK-ing */ 1512c0e88ff0SPavel Emelyanov } 1513c0e88ff0SPavel Emelyanov 15141da177e4SLinus Torvalds seq = &tp->copied_seq; 15151da177e4SLinus Torvalds if (flags & MSG_PEEK) { 15161da177e4SLinus Torvalds peek_seq = tp->copied_seq; 15171da177e4SLinus Torvalds seq = &peek_seq; 15181da177e4SLinus Torvalds } 15191da177e4SLinus Torvalds 15201da177e4SLinus Torvalds target = sock_rcvlowat(sk, flags & MSG_WAITALL, len); 15211da177e4SLinus Torvalds 15221a2449a8SChris Leech #ifdef CONFIG_NET_DMA 15231a2449a8SChris Leech tp->ucopy.dma_chan = NULL; 15241a2449a8SChris Leech preempt_disable(); 15252b1244a4SChris Leech skb = skb_peek_tail(&sk->sk_receive_queue); 1526e00c5d8bSAndrew Morton { 1527e00c5d8bSAndrew Morton int available = 0; 1528e00c5d8bSAndrew Morton 15292b1244a4SChris Leech if (skb) 15302b1244a4SChris Leech available = TCP_SKB_CB(skb)->seq + skb->len - (*seq); 15312b1244a4SChris Leech if ((available < target) && 15322b1244a4SChris Leech (len > sysctl_tcp_dma_copybreak) && !(flags & MSG_PEEK) && 1533e00c5d8bSAndrew Morton !sysctl_tcp_low_latency && 1534a2bd1140SDave Jiang net_dma_find_channel()) { 15351a2449a8SChris Leech preempt_enable_no_resched(); 1536e00c5d8bSAndrew Morton tp->ucopy.pinned_list = 1537e00c5d8bSAndrew Morton dma_pin_iovec_pages(msg->msg_iov, len); 1538e00c5d8bSAndrew Morton } else { 15391a2449a8SChris Leech preempt_enable_no_resched(); 1540e00c5d8bSAndrew Morton } 1541e00c5d8bSAndrew Morton } 15421a2449a8SChris Leech #endif 15431a2449a8SChris Leech 15441da177e4SLinus Torvalds do { 15451da177e4SLinus Torvalds u32 offset; 15461da177e4SLinus Torvalds 15471da177e4SLinus Torvalds /* Are we at urgent data? Stop if we have read anything or have SIGURG pending. */ 15481da177e4SLinus Torvalds if (tp->urg_data && tp->urg_seq == *seq) { 15491da177e4SLinus Torvalds if (copied) 15501da177e4SLinus Torvalds break; 15511da177e4SLinus Torvalds if (signal_pending(current)) { 15521da177e4SLinus Torvalds copied = timeo ? sock_intr_errno(timeo) : -EAGAIN; 15531da177e4SLinus Torvalds break; 15541da177e4SLinus Torvalds } 15551da177e4SLinus Torvalds } 15561da177e4SLinus Torvalds 15571da177e4SLinus Torvalds /* Next get a buffer. */ 15581da177e4SLinus Torvalds 155991521944SDavid S. Miller skb_queue_walk(&sk->sk_receive_queue, skb) { 15601da177e4SLinus Torvalds /* Now that we have two receive queues this 15611da177e4SLinus Torvalds * shouldn't happen. 15621da177e4SLinus Torvalds */ 1563d792c100SIlpo Järvinen if (WARN(before(*seq, TCP_SKB_CB(skb)->seq), 15642af6fd8bSJoe Perches "recvmsg bug: copied %X seq %X rcvnxt %X fl %X\n", 15652af6fd8bSJoe Perches *seq, TCP_SKB_CB(skb)->seq, tp->rcv_nxt, 1566d792c100SIlpo Järvinen flags)) 15671da177e4SLinus Torvalds break; 1568d792c100SIlpo Järvinen 15691da177e4SLinus Torvalds offset = *seq - TCP_SKB_CB(skb)->seq; 1570aa8223c7SArnaldo Carvalho de Melo if (tcp_hdr(skb)->syn) 15711da177e4SLinus Torvalds offset--; 15721da177e4SLinus Torvalds if (offset < skb->len) 15731da177e4SLinus Torvalds goto found_ok_skb; 1574aa8223c7SArnaldo Carvalho de Melo if (tcp_hdr(skb)->fin) 15751da177e4SLinus Torvalds goto found_fin_ok; 15762af6fd8bSJoe Perches WARN(!(flags & MSG_PEEK), 15772af6fd8bSJoe Perches "recvmsg bug 2: copied %X seq %X rcvnxt %X fl %X\n", 15782af6fd8bSJoe Perches *seq, TCP_SKB_CB(skb)->seq, tp->rcv_nxt, flags); 157991521944SDavid S. Miller } 15801da177e4SLinus Torvalds 15811da177e4SLinus Torvalds /* Well, if we have backlog, try to process it now yet. */ 15821da177e4SLinus Torvalds 15831da177e4SLinus Torvalds if (copied >= target && !sk->sk_backlog.tail) 15841da177e4SLinus Torvalds break; 15851da177e4SLinus Torvalds 15861da177e4SLinus Torvalds if (copied) { 15871da177e4SLinus Torvalds if (sk->sk_err || 15881da177e4SLinus Torvalds sk->sk_state == TCP_CLOSE || 15891da177e4SLinus Torvalds (sk->sk_shutdown & RCV_SHUTDOWN) || 15901da177e4SLinus Torvalds !timeo || 1591518a09efSDavid S. Miller signal_pending(current)) 15921da177e4SLinus Torvalds break; 15931da177e4SLinus Torvalds } else { 15941da177e4SLinus Torvalds if (sock_flag(sk, SOCK_DONE)) 15951da177e4SLinus Torvalds break; 15961da177e4SLinus Torvalds 15971da177e4SLinus Torvalds if (sk->sk_err) { 15981da177e4SLinus Torvalds copied = sock_error(sk); 15991da177e4SLinus Torvalds break; 16001da177e4SLinus Torvalds } 16011da177e4SLinus Torvalds 16021da177e4SLinus Torvalds if (sk->sk_shutdown & RCV_SHUTDOWN) 16031da177e4SLinus Torvalds break; 16041da177e4SLinus Torvalds 16051da177e4SLinus Torvalds if (sk->sk_state == TCP_CLOSE) { 16061da177e4SLinus Torvalds if (!sock_flag(sk, SOCK_DONE)) { 16071da177e4SLinus Torvalds /* This occurs when user tries to read 16081da177e4SLinus Torvalds * from never connected socket. 16091da177e4SLinus Torvalds */ 16101da177e4SLinus Torvalds copied = -ENOTCONN; 16111da177e4SLinus Torvalds break; 16121da177e4SLinus Torvalds } 16131da177e4SLinus Torvalds break; 16141da177e4SLinus Torvalds } 16151da177e4SLinus Torvalds 16161da177e4SLinus Torvalds if (!timeo) { 16171da177e4SLinus Torvalds copied = -EAGAIN; 16181da177e4SLinus Torvalds break; 16191da177e4SLinus Torvalds } 16201da177e4SLinus Torvalds 16211da177e4SLinus Torvalds if (signal_pending(current)) { 16221da177e4SLinus Torvalds copied = sock_intr_errno(timeo); 16231da177e4SLinus Torvalds break; 16241da177e4SLinus Torvalds } 16251da177e4SLinus Torvalds } 16261da177e4SLinus Torvalds 16270e4b4992SChris Leech tcp_cleanup_rbuf(sk, copied); 16281da177e4SLinus Torvalds 16297df55125SDavid S. Miller if (!sysctl_tcp_low_latency && tp->ucopy.task == user_recv) { 16301da177e4SLinus Torvalds /* Install new reader */ 16311da177e4SLinus Torvalds if (!user_recv && !(flags & (MSG_TRUNC | MSG_PEEK))) { 16321da177e4SLinus Torvalds user_recv = current; 16331da177e4SLinus Torvalds tp->ucopy.task = user_recv; 16341da177e4SLinus Torvalds tp->ucopy.iov = msg->msg_iov; 16351da177e4SLinus Torvalds } 16361da177e4SLinus Torvalds 16371da177e4SLinus Torvalds tp->ucopy.len = len; 16381da177e4SLinus Torvalds 1639547b792cSIlpo Järvinen WARN_ON(tp->copied_seq != tp->rcv_nxt && 1640547b792cSIlpo Järvinen !(flags & (MSG_PEEK | MSG_TRUNC))); 16411da177e4SLinus Torvalds 16421da177e4SLinus Torvalds /* Ugly... If prequeue is not empty, we have to 16431da177e4SLinus Torvalds * process it before releasing socket, otherwise 16441da177e4SLinus Torvalds * order will be broken at second iteration. 16451da177e4SLinus Torvalds * More elegant solution is required!!! 16461da177e4SLinus Torvalds * 16471da177e4SLinus Torvalds * Look: we have the following (pseudo)queues: 16481da177e4SLinus Torvalds * 16491da177e4SLinus Torvalds * 1. packets in flight 16501da177e4SLinus Torvalds * 2. backlog 16511da177e4SLinus Torvalds * 3. prequeue 16521da177e4SLinus Torvalds * 4. receive_queue 16531da177e4SLinus Torvalds * 16541da177e4SLinus Torvalds * Each queue can be processed only if the next ones 16551da177e4SLinus Torvalds * are empty. At this point we have empty receive_queue. 16561da177e4SLinus Torvalds * But prequeue _can_ be not empty after 2nd iteration, 16571da177e4SLinus Torvalds * when we jumped to start of loop because backlog 16581da177e4SLinus Torvalds * processing added something to receive_queue. 16591da177e4SLinus Torvalds * We cannot release_sock(), because backlog contains 16601da177e4SLinus Torvalds * packets arrived _after_ prequeued ones. 16611da177e4SLinus Torvalds * 16621da177e4SLinus Torvalds * Shortly, algorithm is clear --- to process all 16631da177e4SLinus Torvalds * the queues in order. We could make it more directly, 16641da177e4SLinus Torvalds * requeueing packets from backlog to prequeue, if 16651da177e4SLinus Torvalds * is not empty. It is more elegant, but eats cycles, 16661da177e4SLinus Torvalds * unfortunately. 16671da177e4SLinus Torvalds */ 1668b03efcfbSDavid S. Miller if (!skb_queue_empty(&tp->ucopy.prequeue)) 16691da177e4SLinus Torvalds goto do_prequeue; 16701da177e4SLinus Torvalds 16711da177e4SLinus Torvalds /* __ Set realtime policy in scheduler __ */ 16721da177e4SLinus Torvalds } 16731da177e4SLinus Torvalds 167473852e81SSteven J. Magnani #ifdef CONFIG_NET_DMA 167573852e81SSteven J. Magnani if (tp->ucopy.dma_chan) 167673852e81SSteven J. Magnani dma_async_memcpy_issue_pending(tp->ucopy.dma_chan); 167773852e81SSteven J. Magnani #endif 16781da177e4SLinus Torvalds if (copied >= target) { 16791da177e4SLinus Torvalds /* Do not sleep, just process backlog. */ 16801da177e4SLinus Torvalds release_sock(sk); 16811da177e4SLinus Torvalds lock_sock(sk); 16821da177e4SLinus Torvalds } else 16831da177e4SLinus Torvalds sk_wait_data(sk, &timeo); 16841da177e4SLinus Torvalds 16851a2449a8SChris Leech #ifdef CONFIG_NET_DMA 168673852e81SSteven J. Magnani tcp_service_net_dma(sk, false); /* Don't block */ 16871a2449a8SChris Leech tp->ucopy.wakeup = 0; 16881a2449a8SChris Leech #endif 16891a2449a8SChris Leech 16901da177e4SLinus Torvalds if (user_recv) { 16911da177e4SLinus Torvalds int chunk; 16921da177e4SLinus Torvalds 16931da177e4SLinus Torvalds /* __ Restore normal policy in scheduler __ */ 16941da177e4SLinus Torvalds 16951da177e4SLinus Torvalds if ((chunk = len - tp->ucopy.len) != 0) { 1696ed88098eSPavel Emelyanov NET_ADD_STATS_USER(sock_net(sk), LINUX_MIB_TCPDIRECTCOPYFROMBACKLOG, chunk); 16971da177e4SLinus Torvalds len -= chunk; 16981da177e4SLinus Torvalds copied += chunk; 16991da177e4SLinus Torvalds } 17001da177e4SLinus Torvalds 17011da177e4SLinus Torvalds if (tp->rcv_nxt == tp->copied_seq && 1702b03efcfbSDavid S. Miller !skb_queue_empty(&tp->ucopy.prequeue)) { 17031da177e4SLinus Torvalds do_prequeue: 17041da177e4SLinus Torvalds tcp_prequeue_process(sk); 17051da177e4SLinus Torvalds 17061da177e4SLinus Torvalds if ((chunk = len - tp->ucopy.len) != 0) { 1707ed88098eSPavel Emelyanov NET_ADD_STATS_USER(sock_net(sk), LINUX_MIB_TCPDIRECTCOPYFROMPREQUEUE, chunk); 17081da177e4SLinus Torvalds len -= chunk; 17091da177e4SLinus Torvalds copied += chunk; 17101da177e4SLinus Torvalds } 17111da177e4SLinus Torvalds } 17121da177e4SLinus Torvalds } 171377527313SIlpo Järvinen if ((flags & MSG_PEEK) && 171477527313SIlpo Järvinen (peek_seq - copied - urg_hole != tp->copied_seq)) { 17151da177e4SLinus Torvalds if (net_ratelimit()) 17161da177e4SLinus Torvalds printk(KERN_DEBUG "TCP(%s:%d): Application bug, race in MSG_PEEK.\n", 1717ba25f9dcSPavel Emelyanov current->comm, task_pid_nr(current)); 17181da177e4SLinus Torvalds peek_seq = tp->copied_seq; 17191da177e4SLinus Torvalds } 17201da177e4SLinus Torvalds continue; 17211da177e4SLinus Torvalds 17221da177e4SLinus Torvalds found_ok_skb: 17231da177e4SLinus Torvalds /* Ok so how much can we use? */ 17241da177e4SLinus Torvalds used = skb->len - offset; 17251da177e4SLinus Torvalds if (len < used) 17261da177e4SLinus Torvalds used = len; 17271da177e4SLinus Torvalds 17281da177e4SLinus Torvalds /* Do we have urgent data here? */ 17291da177e4SLinus Torvalds if (tp->urg_data) { 17301da177e4SLinus Torvalds u32 urg_offset = tp->urg_seq - *seq; 17311da177e4SLinus Torvalds if (urg_offset < used) { 17321da177e4SLinus Torvalds if (!urg_offset) { 17331da177e4SLinus Torvalds if (!sock_flag(sk, SOCK_URGINLINE)) { 17341da177e4SLinus Torvalds ++*seq; 173577527313SIlpo Järvinen urg_hole++; 17361da177e4SLinus Torvalds offset++; 17371da177e4SLinus Torvalds used--; 17381da177e4SLinus Torvalds if (!used) 17391da177e4SLinus Torvalds goto skip_copy; 17401da177e4SLinus Torvalds } 17411da177e4SLinus Torvalds } else 17421da177e4SLinus Torvalds used = urg_offset; 17431da177e4SLinus Torvalds } 17441da177e4SLinus Torvalds } 17451da177e4SLinus Torvalds 17461da177e4SLinus Torvalds if (!(flags & MSG_TRUNC)) { 17471a2449a8SChris Leech #ifdef CONFIG_NET_DMA 17481a2449a8SChris Leech if (!tp->ucopy.dma_chan && tp->ucopy.pinned_list) 1749a2bd1140SDave Jiang tp->ucopy.dma_chan = net_dma_find_channel(); 17501a2449a8SChris Leech 17511a2449a8SChris Leech if (tp->ucopy.dma_chan) { 17521a2449a8SChris Leech tp->ucopy.dma_cookie = dma_skb_copy_datagram_iovec( 17531a2449a8SChris Leech tp->ucopy.dma_chan, skb, offset, 17541a2449a8SChris Leech msg->msg_iov, used, 17551a2449a8SChris Leech tp->ucopy.pinned_list); 17561a2449a8SChris Leech 17571a2449a8SChris Leech if (tp->ucopy.dma_cookie < 0) { 17581a2449a8SChris Leech 1759afd46503SJoe Perches pr_alert("%s: dma_cookie < 0\n", 1760afd46503SJoe Perches __func__); 17611a2449a8SChris Leech 17621a2449a8SChris Leech /* Exception. Bailout! */ 17631a2449a8SChris Leech if (!copied) 17641a2449a8SChris Leech copied = -EFAULT; 17651a2449a8SChris Leech break; 17661a2449a8SChris Leech } 176773852e81SSteven J. Magnani 176873852e81SSteven J. Magnani dma_async_memcpy_issue_pending(tp->ucopy.dma_chan); 176973852e81SSteven J. Magnani 17701a2449a8SChris Leech if ((offset + used) == skb->len) 17711a2449a8SChris Leech copied_early = 1; 17721a2449a8SChris Leech 17731a2449a8SChris Leech } else 17741a2449a8SChris Leech #endif 17751a2449a8SChris Leech { 17761da177e4SLinus Torvalds err = skb_copy_datagram_iovec(skb, offset, 17771da177e4SLinus Torvalds msg->msg_iov, used); 17781da177e4SLinus Torvalds if (err) { 17791da177e4SLinus Torvalds /* Exception. Bailout! */ 17801da177e4SLinus Torvalds if (!copied) 17811da177e4SLinus Torvalds copied = -EFAULT; 17821da177e4SLinus Torvalds break; 17831da177e4SLinus Torvalds } 17841da177e4SLinus Torvalds } 17851a2449a8SChris Leech } 17861da177e4SLinus Torvalds 17871da177e4SLinus Torvalds *seq += used; 17881da177e4SLinus Torvalds copied += used; 17891da177e4SLinus Torvalds len -= used; 17901da177e4SLinus Torvalds 17911da177e4SLinus Torvalds tcp_rcv_space_adjust(sk); 17921da177e4SLinus Torvalds 17931da177e4SLinus Torvalds skip_copy: 17941da177e4SLinus Torvalds if (tp->urg_data && after(tp->copied_seq, tp->urg_seq)) { 17951da177e4SLinus Torvalds tp->urg_data = 0; 17969e412ba7SIlpo Järvinen tcp_fast_path_check(sk); 17971da177e4SLinus Torvalds } 17981da177e4SLinus Torvalds if (used + offset < skb->len) 17991da177e4SLinus Torvalds continue; 18001da177e4SLinus Torvalds 1801aa8223c7SArnaldo Carvalho de Melo if (tcp_hdr(skb)->fin) 18021da177e4SLinus Torvalds goto found_fin_ok; 18031a2449a8SChris Leech if (!(flags & MSG_PEEK)) { 18041a2449a8SChris Leech sk_eat_skb(sk, skb, copied_early); 18051a2449a8SChris Leech copied_early = 0; 18061a2449a8SChris Leech } 18071da177e4SLinus Torvalds continue; 18081da177e4SLinus Torvalds 18091da177e4SLinus Torvalds found_fin_ok: 18101da177e4SLinus Torvalds /* Process the FIN. */ 18111da177e4SLinus Torvalds ++*seq; 18121a2449a8SChris Leech if (!(flags & MSG_PEEK)) { 18131a2449a8SChris Leech sk_eat_skb(sk, skb, copied_early); 18141a2449a8SChris Leech copied_early = 0; 18151a2449a8SChris Leech } 18161da177e4SLinus Torvalds break; 18171da177e4SLinus Torvalds } while (len > 0); 18181da177e4SLinus Torvalds 18191da177e4SLinus Torvalds if (user_recv) { 1820b03efcfbSDavid S. Miller if (!skb_queue_empty(&tp->ucopy.prequeue)) { 18211da177e4SLinus Torvalds int chunk; 18221da177e4SLinus Torvalds 18231da177e4SLinus Torvalds tp->ucopy.len = copied > 0 ? len : 0; 18241da177e4SLinus Torvalds 18251da177e4SLinus Torvalds tcp_prequeue_process(sk); 18261da177e4SLinus Torvalds 18271da177e4SLinus Torvalds if (copied > 0 && (chunk = len - tp->ucopy.len) != 0) { 1828ed88098eSPavel Emelyanov NET_ADD_STATS_USER(sock_net(sk), LINUX_MIB_TCPDIRECTCOPYFROMPREQUEUE, chunk); 18291da177e4SLinus Torvalds len -= chunk; 18301da177e4SLinus Torvalds copied += chunk; 18311da177e4SLinus Torvalds } 18321da177e4SLinus Torvalds } 18331da177e4SLinus Torvalds 18341da177e4SLinus Torvalds tp->ucopy.task = NULL; 18351da177e4SLinus Torvalds tp->ucopy.len = 0; 18361da177e4SLinus Torvalds } 18371da177e4SLinus Torvalds 18381a2449a8SChris Leech #ifdef CONFIG_NET_DMA 183973852e81SSteven J. Magnani tcp_service_net_dma(sk, true); /* Wait for queue to drain */ 18401a2449a8SChris Leech tp->ucopy.dma_chan = NULL; 184173852e81SSteven J. Magnani 18421a2449a8SChris Leech if (tp->ucopy.pinned_list) { 18431a2449a8SChris Leech dma_unpin_iovec_pages(tp->ucopy.pinned_list); 18441a2449a8SChris Leech tp->ucopy.pinned_list = NULL; 18451a2449a8SChris Leech } 18461a2449a8SChris Leech #endif 18471a2449a8SChris Leech 18481da177e4SLinus Torvalds /* According to UNIX98, msg_name/msg_namelen are ignored 18491da177e4SLinus Torvalds * on connected socket. I was just happy when found this 8) --ANK 18501da177e4SLinus Torvalds */ 18511da177e4SLinus Torvalds 18521da177e4SLinus Torvalds /* Clean up data we have read: This will do ACK frames. */ 18530e4b4992SChris Leech tcp_cleanup_rbuf(sk, copied); 18541da177e4SLinus Torvalds 18551da177e4SLinus Torvalds release_sock(sk); 18561da177e4SLinus Torvalds return copied; 18571da177e4SLinus Torvalds 18581da177e4SLinus Torvalds out: 18591da177e4SLinus Torvalds release_sock(sk); 18601da177e4SLinus Torvalds return err; 18611da177e4SLinus Torvalds 18621da177e4SLinus Torvalds recv_urg: 1863377f0a08SRami Rosen err = tcp_recv_urg(sk, msg, len, flags); 18641da177e4SLinus Torvalds goto out; 1865c0e88ff0SPavel Emelyanov 1866c0e88ff0SPavel Emelyanov recv_sndq: 1867c0e88ff0SPavel Emelyanov err = tcp_peek_sndq(sk, msg, len); 1868c0e88ff0SPavel Emelyanov goto out; 18691da177e4SLinus Torvalds } 18704bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_recvmsg); 18711da177e4SLinus Torvalds 1872490d5046SIlpo Järvinen void tcp_set_state(struct sock *sk, int state) 1873490d5046SIlpo Järvinen { 1874490d5046SIlpo Järvinen int oldstate = sk->sk_state; 1875490d5046SIlpo Järvinen 1876490d5046SIlpo Järvinen switch (state) { 1877490d5046SIlpo Järvinen case TCP_ESTABLISHED: 1878490d5046SIlpo Järvinen if (oldstate != TCP_ESTABLISHED) 187981cc8a75SPavel Emelyanov TCP_INC_STATS(sock_net(sk), TCP_MIB_CURRESTAB); 1880490d5046SIlpo Järvinen break; 1881490d5046SIlpo Järvinen 1882490d5046SIlpo Järvinen case TCP_CLOSE: 1883490d5046SIlpo Järvinen if (oldstate == TCP_CLOSE_WAIT || oldstate == TCP_ESTABLISHED) 188481cc8a75SPavel Emelyanov TCP_INC_STATS(sock_net(sk), TCP_MIB_ESTABRESETS); 1885490d5046SIlpo Järvinen 1886490d5046SIlpo Järvinen sk->sk_prot->unhash(sk); 1887490d5046SIlpo Järvinen if (inet_csk(sk)->icsk_bind_hash && 1888490d5046SIlpo Järvinen !(sk->sk_userlocks & SOCK_BINDPORT_LOCK)) 1889ab1e0a13SArnaldo Carvalho de Melo inet_put_port(sk); 1890490d5046SIlpo Järvinen /* fall through */ 1891490d5046SIlpo Järvinen default: 1892490d5046SIlpo Järvinen if (oldstate == TCP_ESTABLISHED) 189374688e48SPavel Emelyanov TCP_DEC_STATS(sock_net(sk), TCP_MIB_CURRESTAB); 1894490d5046SIlpo Järvinen } 1895490d5046SIlpo Järvinen 1896490d5046SIlpo Järvinen /* Change state AFTER socket is unhashed to avoid closed 1897490d5046SIlpo Järvinen * socket sitting in hash tables. 1898490d5046SIlpo Järvinen */ 1899490d5046SIlpo Järvinen sk->sk_state = state; 1900490d5046SIlpo Järvinen 1901490d5046SIlpo Järvinen #ifdef STATE_TRACE 1902490d5046SIlpo Järvinen SOCK_DEBUG(sk, "TCP sk=%p, State %s -> %s\n", sk, statename[oldstate], statename[state]); 1903490d5046SIlpo Järvinen #endif 1904490d5046SIlpo Järvinen } 1905490d5046SIlpo Järvinen EXPORT_SYMBOL_GPL(tcp_set_state); 1906490d5046SIlpo Järvinen 19071da177e4SLinus Torvalds /* 19081da177e4SLinus Torvalds * State processing on a close. This implements the state shift for 19091da177e4SLinus Torvalds * sending our FIN frame. Note that we only send a FIN for some 19101da177e4SLinus Torvalds * states. A shutdown() may have already sent the FIN, or we may be 19111da177e4SLinus Torvalds * closed. 19121da177e4SLinus Torvalds */ 19131da177e4SLinus Torvalds 19149b5b5cffSArjan van de Ven static const unsigned char new_state[16] = { 19151da177e4SLinus Torvalds /* current state: new state: action: */ 19161da177e4SLinus Torvalds /* (Invalid) */ TCP_CLOSE, 19171da177e4SLinus Torvalds /* TCP_ESTABLISHED */ TCP_FIN_WAIT1 | TCP_ACTION_FIN, 19181da177e4SLinus Torvalds /* TCP_SYN_SENT */ TCP_CLOSE, 19191da177e4SLinus Torvalds /* TCP_SYN_RECV */ TCP_FIN_WAIT1 | TCP_ACTION_FIN, 19201da177e4SLinus Torvalds /* TCP_FIN_WAIT1 */ TCP_FIN_WAIT1, 19211da177e4SLinus Torvalds /* TCP_FIN_WAIT2 */ TCP_FIN_WAIT2, 19221da177e4SLinus Torvalds /* TCP_TIME_WAIT */ TCP_CLOSE, 19231da177e4SLinus Torvalds /* TCP_CLOSE */ TCP_CLOSE, 19241da177e4SLinus Torvalds /* TCP_CLOSE_WAIT */ TCP_LAST_ACK | TCP_ACTION_FIN, 19251da177e4SLinus Torvalds /* TCP_LAST_ACK */ TCP_LAST_ACK, 19261da177e4SLinus Torvalds /* TCP_LISTEN */ TCP_CLOSE, 19271da177e4SLinus Torvalds /* TCP_CLOSING */ TCP_CLOSING, 19281da177e4SLinus Torvalds }; 19291da177e4SLinus Torvalds 19301da177e4SLinus Torvalds static int tcp_close_state(struct sock *sk) 19311da177e4SLinus Torvalds { 19321da177e4SLinus Torvalds int next = (int)new_state[sk->sk_state]; 19331da177e4SLinus Torvalds int ns = next & TCP_STATE_MASK; 19341da177e4SLinus Torvalds 19351da177e4SLinus Torvalds tcp_set_state(sk, ns); 19361da177e4SLinus Torvalds 19371da177e4SLinus Torvalds return next & TCP_ACTION_FIN; 19381da177e4SLinus Torvalds } 19391da177e4SLinus Torvalds 19401da177e4SLinus Torvalds /* 19411da177e4SLinus Torvalds * Shutdown the sending side of a connection. Much like close except 19421f29b058SSatoru SATOH * that we don't receive shut down or sock_set_flag(sk, SOCK_DEAD). 19431da177e4SLinus Torvalds */ 19441da177e4SLinus Torvalds 19451da177e4SLinus Torvalds void tcp_shutdown(struct sock *sk, int how) 19461da177e4SLinus Torvalds { 19471da177e4SLinus Torvalds /* We need to grab some memory, and put together a FIN, 19481da177e4SLinus Torvalds * and then put it into the queue to be sent. 19491da177e4SLinus Torvalds * Tim MacKenzie(tym@dibbler.cs.monash.edu.au) 4 Dec '92. 19501da177e4SLinus Torvalds */ 19511da177e4SLinus Torvalds if (!(how & SEND_SHUTDOWN)) 19521da177e4SLinus Torvalds return; 19531da177e4SLinus Torvalds 19541da177e4SLinus Torvalds /* If we've already sent a FIN, or it's a closed state, skip this. */ 19551da177e4SLinus Torvalds if ((1 << sk->sk_state) & 19561da177e4SLinus Torvalds (TCPF_ESTABLISHED | TCPF_SYN_SENT | 19571da177e4SLinus Torvalds TCPF_SYN_RECV | TCPF_CLOSE_WAIT)) { 19581da177e4SLinus Torvalds /* Clear out any half completed packets. FIN if needed. */ 19591da177e4SLinus Torvalds if (tcp_close_state(sk)) 19601da177e4SLinus Torvalds tcp_send_fin(sk); 19611da177e4SLinus Torvalds } 19621da177e4SLinus Torvalds } 19634bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_shutdown); 19641da177e4SLinus Torvalds 1965efcdbf24SArun Sharma bool tcp_check_oom(struct sock *sk, int shift) 1966efcdbf24SArun Sharma { 1967efcdbf24SArun Sharma bool too_many_orphans, out_of_socket_memory; 1968efcdbf24SArun Sharma 1969efcdbf24SArun Sharma too_many_orphans = tcp_too_many_orphans(sk, shift); 1970efcdbf24SArun Sharma out_of_socket_memory = tcp_out_of_memory(sk); 1971efcdbf24SArun Sharma 1972efcdbf24SArun Sharma if (too_many_orphans && net_ratelimit()) 1973afd46503SJoe Perches pr_info("too many orphaned sockets\n"); 1974efcdbf24SArun Sharma if (out_of_socket_memory && net_ratelimit()) 1975afd46503SJoe Perches pr_info("out of memory -- consider tuning tcp_mem\n"); 1976efcdbf24SArun Sharma return too_many_orphans || out_of_socket_memory; 1977efcdbf24SArun Sharma } 1978efcdbf24SArun Sharma 19791da177e4SLinus Torvalds void tcp_close(struct sock *sk, long timeout) 19801da177e4SLinus Torvalds { 19811da177e4SLinus Torvalds struct sk_buff *skb; 19821da177e4SLinus Torvalds int data_was_unread = 0; 198375c2d907SHerbert Xu int state; 19841da177e4SLinus Torvalds 19851da177e4SLinus Torvalds lock_sock(sk); 19861da177e4SLinus Torvalds sk->sk_shutdown = SHUTDOWN_MASK; 19871da177e4SLinus Torvalds 19881da177e4SLinus Torvalds if (sk->sk_state == TCP_LISTEN) { 19891da177e4SLinus Torvalds tcp_set_state(sk, TCP_CLOSE); 19901da177e4SLinus Torvalds 19911da177e4SLinus Torvalds /* Special case. */ 19920a5578cfSArnaldo Carvalho de Melo inet_csk_listen_stop(sk); 19931da177e4SLinus Torvalds 19941da177e4SLinus Torvalds goto adjudge_to_death; 19951da177e4SLinus Torvalds } 19961da177e4SLinus Torvalds 19971da177e4SLinus Torvalds /* We need to flush the recv. buffs. We do this only on the 19981da177e4SLinus Torvalds * descriptor close, not protocol-sourced closes, because the 19991da177e4SLinus Torvalds * reader process may not have drained the data yet! 20001da177e4SLinus Torvalds */ 20011da177e4SLinus Torvalds while ((skb = __skb_dequeue(&sk->sk_receive_queue)) != NULL) { 20021da177e4SLinus Torvalds u32 len = TCP_SKB_CB(skb)->end_seq - TCP_SKB_CB(skb)->seq - 2003aa8223c7SArnaldo Carvalho de Melo tcp_hdr(skb)->fin; 20041da177e4SLinus Torvalds data_was_unread += len; 20051da177e4SLinus Torvalds __kfree_skb(skb); 20061da177e4SLinus Torvalds } 20071da177e4SLinus Torvalds 20083ab224beSHideo Aoki sk_mem_reclaim(sk); 20091da177e4SLinus Torvalds 2010565b7b2dSKonstantin Khorenko /* If socket has been already reset (e.g. in tcp_reset()) - kill it. */ 2011565b7b2dSKonstantin Khorenko if (sk->sk_state == TCP_CLOSE) 2012565b7b2dSKonstantin Khorenko goto adjudge_to_death; 2013565b7b2dSKonstantin Khorenko 201465bb723cSGerrit Renker /* As outlined in RFC 2525, section 2.17, we send a RST here because 201565bb723cSGerrit Renker * data was lost. To witness the awful effects of the old behavior of 201665bb723cSGerrit Renker * always doing a FIN, run an older 2.1.x kernel or 2.0.x, start a bulk 201765bb723cSGerrit Renker * GET in an FTP client, suspend the process, wait for the client to 201865bb723cSGerrit Renker * advertise a zero window, then kill -9 the FTP client, wheee... 201965bb723cSGerrit Renker * Note: timeout is always zero in such a case. 20201da177e4SLinus Torvalds */ 2021ee995283SPavel Emelyanov if (unlikely(tcp_sk(sk)->repair)) { 2022ee995283SPavel Emelyanov sk->sk_prot->disconnect(sk, 0); 2023ee995283SPavel Emelyanov } else if (data_was_unread) { 20241da177e4SLinus Torvalds /* Unread data was tossed, zap the connection. */ 20256f67c817SPavel Emelyanov NET_INC_STATS_USER(sock_net(sk), LINUX_MIB_TCPABORTONCLOSE); 20261da177e4SLinus Torvalds tcp_set_state(sk, TCP_CLOSE); 2027aa133076SWu Fengguang tcp_send_active_reset(sk, sk->sk_allocation); 20281da177e4SLinus Torvalds } else if (sock_flag(sk, SOCK_LINGER) && !sk->sk_lingertime) { 20291da177e4SLinus Torvalds /* Check zero linger _after_ checking for unread data. */ 20301da177e4SLinus Torvalds sk->sk_prot->disconnect(sk, 0); 20316f67c817SPavel Emelyanov NET_INC_STATS_USER(sock_net(sk), LINUX_MIB_TCPABORTONDATA); 20321da177e4SLinus Torvalds } else if (tcp_close_state(sk)) { 20331da177e4SLinus Torvalds /* We FIN if the application ate all the data before 20341da177e4SLinus Torvalds * zapping the connection. 20351da177e4SLinus Torvalds */ 20361da177e4SLinus Torvalds 20371da177e4SLinus Torvalds /* RED-PEN. Formally speaking, we have broken TCP state 20381da177e4SLinus Torvalds * machine. State transitions: 20391da177e4SLinus Torvalds * 20401da177e4SLinus Torvalds * TCP_ESTABLISHED -> TCP_FIN_WAIT1 20411da177e4SLinus Torvalds * TCP_SYN_RECV -> TCP_FIN_WAIT1 (forget it, it's impossible) 20421da177e4SLinus Torvalds * TCP_CLOSE_WAIT -> TCP_LAST_ACK 20431da177e4SLinus Torvalds * 20441da177e4SLinus Torvalds * are legal only when FIN has been sent (i.e. in window), 20451da177e4SLinus Torvalds * rather than queued out of window. Purists blame. 20461da177e4SLinus Torvalds * 20471da177e4SLinus Torvalds * F.e. "RFC state" is ESTABLISHED, 20481da177e4SLinus Torvalds * if Linux state is FIN-WAIT-1, but FIN is still not sent. 20491da177e4SLinus Torvalds * 20501da177e4SLinus Torvalds * The visible declinations are that sometimes 20511da177e4SLinus Torvalds * we enter time-wait state, when it is not required really 20521da177e4SLinus Torvalds * (harmless), do not send active resets, when they are 20531da177e4SLinus Torvalds * required by specs (TCP_ESTABLISHED, TCP_CLOSE_WAIT, when 20541da177e4SLinus Torvalds * they look as CLOSING or LAST_ACK for Linux) 20551da177e4SLinus Torvalds * Probably, I missed some more holelets. 20561da177e4SLinus Torvalds * --ANK 20571da177e4SLinus Torvalds */ 20581da177e4SLinus Torvalds tcp_send_fin(sk); 20591da177e4SLinus Torvalds } 20601da177e4SLinus Torvalds 20611da177e4SLinus Torvalds sk_stream_wait_close(sk, timeout); 20621da177e4SLinus Torvalds 20631da177e4SLinus Torvalds adjudge_to_death: 206475c2d907SHerbert Xu state = sk->sk_state; 206575c2d907SHerbert Xu sock_hold(sk); 206675c2d907SHerbert Xu sock_orphan(sk); 206775c2d907SHerbert Xu 20681da177e4SLinus Torvalds /* It is the last release_sock in its life. It will remove backlog. */ 20691da177e4SLinus Torvalds release_sock(sk); 20701da177e4SLinus Torvalds 20711da177e4SLinus Torvalds 20721da177e4SLinus Torvalds /* Now socket is owned by kernel and we acquire BH lock 20731da177e4SLinus Torvalds to finish close. No need to check for user refs. 20741da177e4SLinus Torvalds */ 20751da177e4SLinus Torvalds local_bh_disable(); 20761da177e4SLinus Torvalds bh_lock_sock(sk); 2077547b792cSIlpo Järvinen WARN_ON(sock_owned_by_user(sk)); 20781da177e4SLinus Torvalds 2079eb4dea58SHerbert Xu percpu_counter_inc(sk->sk_prot->orphan_count); 2080eb4dea58SHerbert Xu 208175c2d907SHerbert Xu /* Have we already been destroyed by a softirq or backlog? */ 208275c2d907SHerbert Xu if (state != TCP_CLOSE && sk->sk_state == TCP_CLOSE) 208375c2d907SHerbert Xu goto out; 20841da177e4SLinus Torvalds 20851da177e4SLinus Torvalds /* This is a (useful) BSD violating of the RFC. There is a 20861da177e4SLinus Torvalds * problem with TCP as specified in that the other end could 20871da177e4SLinus Torvalds * keep a socket open forever with no application left this end. 20881da177e4SLinus Torvalds * We use a 3 minute timeout (about the same as BSD) then kill 20891da177e4SLinus Torvalds * our end. If they send after that then tough - BUT: long enough 20901da177e4SLinus Torvalds * that we won't make the old 4*rto = almost no time - whoops 20911da177e4SLinus Torvalds * reset mistake. 20921da177e4SLinus Torvalds * 20931da177e4SLinus Torvalds * Nope, it was not mistake. It is really desired behaviour 20941da177e4SLinus Torvalds * f.e. on http servers, when such sockets are useless, but 20951da177e4SLinus Torvalds * consume significant resources. Let's do it with special 20961da177e4SLinus Torvalds * linger2 option. --ANK 20971da177e4SLinus Torvalds */ 20981da177e4SLinus Torvalds 20991da177e4SLinus Torvalds if (sk->sk_state == TCP_FIN_WAIT2) { 21001da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 21011da177e4SLinus Torvalds if (tp->linger2 < 0) { 21021da177e4SLinus Torvalds tcp_set_state(sk, TCP_CLOSE); 21031da177e4SLinus Torvalds tcp_send_active_reset(sk, GFP_ATOMIC); 2104de0744afSPavel Emelyanov NET_INC_STATS_BH(sock_net(sk), 2105de0744afSPavel Emelyanov LINUX_MIB_TCPABORTONLINGER); 21061da177e4SLinus Torvalds } else { 2107463c84b9SArnaldo Carvalho de Melo const int tmo = tcp_fin_time(sk); 21081da177e4SLinus Torvalds 21091da177e4SLinus Torvalds if (tmo > TCP_TIMEWAIT_LEN) { 211052499afeSDavid S. Miller inet_csk_reset_keepalive_timer(sk, 211152499afeSDavid S. Miller tmo - TCP_TIMEWAIT_LEN); 21121da177e4SLinus Torvalds } else { 21131da177e4SLinus Torvalds tcp_time_wait(sk, TCP_FIN_WAIT2, tmo); 21141da177e4SLinus Torvalds goto out; 21151da177e4SLinus Torvalds } 21161da177e4SLinus Torvalds } 21171da177e4SLinus Torvalds } 21181da177e4SLinus Torvalds if (sk->sk_state != TCP_CLOSE) { 21193ab224beSHideo Aoki sk_mem_reclaim(sk); 2120efcdbf24SArun Sharma if (tcp_check_oom(sk, 0)) { 21211da177e4SLinus Torvalds tcp_set_state(sk, TCP_CLOSE); 21221da177e4SLinus Torvalds tcp_send_active_reset(sk, GFP_ATOMIC); 2123de0744afSPavel Emelyanov NET_INC_STATS_BH(sock_net(sk), 2124de0744afSPavel Emelyanov LINUX_MIB_TCPABORTONMEMORY); 21251da177e4SLinus Torvalds } 21261da177e4SLinus Torvalds } 21271da177e4SLinus Torvalds 21281da177e4SLinus Torvalds if (sk->sk_state == TCP_CLOSE) 21290a5578cfSArnaldo Carvalho de Melo inet_csk_destroy_sock(sk); 21301da177e4SLinus Torvalds /* Otherwise, socket is reprieved until protocol close. */ 21311da177e4SLinus Torvalds 21321da177e4SLinus Torvalds out: 21331da177e4SLinus Torvalds bh_unlock_sock(sk); 21341da177e4SLinus Torvalds local_bh_enable(); 21351da177e4SLinus Torvalds sock_put(sk); 21361da177e4SLinus Torvalds } 21374bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_close); 21381da177e4SLinus Torvalds 21391da177e4SLinus Torvalds /* These states need RST on ABORT according to RFC793 */ 21401da177e4SLinus Torvalds 21411da177e4SLinus Torvalds static inline int tcp_need_reset(int state) 21421da177e4SLinus Torvalds { 21431da177e4SLinus Torvalds return (1 << state) & 21441da177e4SLinus Torvalds (TCPF_ESTABLISHED | TCPF_CLOSE_WAIT | TCPF_FIN_WAIT1 | 21451da177e4SLinus Torvalds TCPF_FIN_WAIT2 | TCPF_SYN_RECV); 21461da177e4SLinus Torvalds } 21471da177e4SLinus Torvalds 21481da177e4SLinus Torvalds int tcp_disconnect(struct sock *sk, int flags) 21491da177e4SLinus Torvalds { 21501da177e4SLinus Torvalds struct inet_sock *inet = inet_sk(sk); 2151463c84b9SArnaldo Carvalho de Melo struct inet_connection_sock *icsk = inet_csk(sk); 21521da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 21531da177e4SLinus Torvalds int err = 0; 21541da177e4SLinus Torvalds int old_state = sk->sk_state; 21551da177e4SLinus Torvalds 21561da177e4SLinus Torvalds if (old_state != TCP_CLOSE) 21571da177e4SLinus Torvalds tcp_set_state(sk, TCP_CLOSE); 21581da177e4SLinus Torvalds 21591da177e4SLinus Torvalds /* ABORT function of RFC793 */ 21601da177e4SLinus Torvalds if (old_state == TCP_LISTEN) { 21610a5578cfSArnaldo Carvalho de Melo inet_csk_listen_stop(sk); 2162ee995283SPavel Emelyanov } else if (unlikely(tp->repair)) { 2163ee995283SPavel Emelyanov sk->sk_err = ECONNABORTED; 21641da177e4SLinus Torvalds } else if (tcp_need_reset(old_state) || 21651da177e4SLinus Torvalds (tp->snd_nxt != tp->write_seq && 21661da177e4SLinus Torvalds (1 << old_state) & (TCPF_CLOSING | TCPF_LAST_ACK))) { 2167caa20d9aSStephen Hemminger /* The last check adjusts for discrepancy of Linux wrt. RFC 21681da177e4SLinus Torvalds * states 21691da177e4SLinus Torvalds */ 21701da177e4SLinus Torvalds tcp_send_active_reset(sk, gfp_any()); 21711da177e4SLinus Torvalds sk->sk_err = ECONNRESET; 21721da177e4SLinus Torvalds } else if (old_state == TCP_SYN_SENT) 21731da177e4SLinus Torvalds sk->sk_err = ECONNRESET; 21741da177e4SLinus Torvalds 21751da177e4SLinus Torvalds tcp_clear_xmit_timers(sk); 21761da177e4SLinus Torvalds __skb_queue_purge(&sk->sk_receive_queue); 2177fe067e8aSDavid S. Miller tcp_write_queue_purge(sk); 21781da177e4SLinus Torvalds __skb_queue_purge(&tp->out_of_order_queue); 21791a2449a8SChris Leech #ifdef CONFIG_NET_DMA 21801a2449a8SChris Leech __skb_queue_purge(&sk->sk_async_wait_queue); 21811a2449a8SChris Leech #endif 21821da177e4SLinus Torvalds 2183c720c7e8SEric Dumazet inet->inet_dport = 0; 21841da177e4SLinus Torvalds 21851da177e4SLinus Torvalds if (!(sk->sk_userlocks & SOCK_BINDADDR_LOCK)) 21861da177e4SLinus Torvalds inet_reset_saddr(sk); 21871da177e4SLinus Torvalds 21881da177e4SLinus Torvalds sk->sk_shutdown = 0; 21891da177e4SLinus Torvalds sock_reset_flag(sk, SOCK_DONE); 21901da177e4SLinus Torvalds tp->srtt = 0; 21911da177e4SLinus Torvalds if ((tp->write_seq += tp->max_window + 2) == 0) 21921da177e4SLinus Torvalds tp->write_seq = 1; 2193463c84b9SArnaldo Carvalho de Melo icsk->icsk_backoff = 0; 21941da177e4SLinus Torvalds tp->snd_cwnd = 2; 21956687e988SArnaldo Carvalho de Melo icsk->icsk_probes_out = 0; 21961da177e4SLinus Torvalds tp->packets_out = 0; 21970b6a05c1SIlpo Järvinen tp->snd_ssthresh = TCP_INFINITE_SSTHRESH; 21981da177e4SLinus Torvalds tp->snd_cwnd_cnt = 0; 21999772efb9SStephen Hemminger tp->bytes_acked = 0; 22001fdf475aSEric Dumazet tp->window_clamp = 0; 22016687e988SArnaldo Carvalho de Melo tcp_set_ca_state(sk, TCP_CA_Open); 22021da177e4SLinus Torvalds tcp_clear_retrans(tp); 2203463c84b9SArnaldo Carvalho de Melo inet_csk_delack_init(sk); 2204fe067e8aSDavid S. Miller tcp_init_send_head(sk); 2205b40b4f79SSrinivas Aji memset(&tp->rx_opt, 0, sizeof(tp->rx_opt)); 22061da177e4SLinus Torvalds __sk_dst_reset(sk); 22071da177e4SLinus Torvalds 2208c720c7e8SEric Dumazet WARN_ON(inet->inet_num && !icsk->icsk_bind_hash); 22091da177e4SLinus Torvalds 22101da177e4SLinus Torvalds sk->sk_error_report(sk); 22111da177e4SLinus Torvalds return err; 22121da177e4SLinus Torvalds } 22134bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_disconnect); 22141da177e4SLinus Torvalds 2215ee995283SPavel Emelyanov static inline int tcp_can_repair_sock(struct sock *sk) 2216ee995283SPavel Emelyanov { 2217ee995283SPavel Emelyanov return capable(CAP_NET_ADMIN) && 2218ee995283SPavel Emelyanov ((1 << sk->sk_state) & (TCPF_CLOSE | TCPF_ESTABLISHED)); 2219ee995283SPavel Emelyanov } 2220ee995283SPavel Emelyanov 22211da177e4SLinus Torvalds /* 22221da177e4SLinus Torvalds * Socket option code for TCP. 22231da177e4SLinus Torvalds */ 22243fdadf7dSDmitry Mishin static int do_tcp_setsockopt(struct sock *sk, int level, 2225b7058842SDavid S. Miller int optname, char __user *optval, unsigned int optlen) 22261da177e4SLinus Torvalds { 22271da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 2228463c84b9SArnaldo Carvalho de Melo struct inet_connection_sock *icsk = inet_csk(sk); 22291da177e4SLinus Torvalds int val; 22301da177e4SLinus Torvalds int err = 0; 22311da177e4SLinus Torvalds 2232e56fb50fSWilliam Allen Simpson /* These are data/string values, all the others are ints */ 2233e56fb50fSWilliam Allen Simpson switch (optname) { 2234e56fb50fSWilliam Allen Simpson case TCP_CONGESTION: { 22355f8ef48dSStephen Hemminger char name[TCP_CA_NAME_MAX]; 22365f8ef48dSStephen Hemminger 22375f8ef48dSStephen Hemminger if (optlen < 1) 22385f8ef48dSStephen Hemminger return -EINVAL; 22395f8ef48dSStephen Hemminger 22405f8ef48dSStephen Hemminger val = strncpy_from_user(name, optval, 22414fdb78d3SAndrew Morton min_t(long, TCP_CA_NAME_MAX-1, optlen)); 22425f8ef48dSStephen Hemminger if (val < 0) 22435f8ef48dSStephen Hemminger return -EFAULT; 22445f8ef48dSStephen Hemminger name[val] = 0; 22455f8ef48dSStephen Hemminger 22465f8ef48dSStephen Hemminger lock_sock(sk); 22476687e988SArnaldo Carvalho de Melo err = tcp_set_congestion_control(sk, name); 22485f8ef48dSStephen Hemminger release_sock(sk); 22495f8ef48dSStephen Hemminger return err; 22505f8ef48dSStephen Hemminger } 2251e56fb50fSWilliam Allen Simpson case TCP_COOKIE_TRANSACTIONS: { 2252e56fb50fSWilliam Allen Simpson struct tcp_cookie_transactions ctd; 2253e56fb50fSWilliam Allen Simpson struct tcp_cookie_values *cvp = NULL; 2254e56fb50fSWilliam Allen Simpson 2255e56fb50fSWilliam Allen Simpson if (sizeof(ctd) > optlen) 2256e56fb50fSWilliam Allen Simpson return -EINVAL; 2257e56fb50fSWilliam Allen Simpson if (copy_from_user(&ctd, optval, sizeof(ctd))) 2258e56fb50fSWilliam Allen Simpson return -EFAULT; 2259e56fb50fSWilliam Allen Simpson 2260e56fb50fSWilliam Allen Simpson if (ctd.tcpct_used > sizeof(ctd.tcpct_value) || 2261e56fb50fSWilliam Allen Simpson ctd.tcpct_s_data_desired > TCP_MSS_DESIRED) 2262e56fb50fSWilliam Allen Simpson return -EINVAL; 2263e56fb50fSWilliam Allen Simpson 2264e56fb50fSWilliam Allen Simpson if (ctd.tcpct_cookie_desired == 0) { 2265e56fb50fSWilliam Allen Simpson /* default to global value */ 2266e56fb50fSWilliam Allen Simpson } else if ((0x1 & ctd.tcpct_cookie_desired) || 2267e56fb50fSWilliam Allen Simpson ctd.tcpct_cookie_desired > TCP_COOKIE_MAX || 2268e56fb50fSWilliam Allen Simpson ctd.tcpct_cookie_desired < TCP_COOKIE_MIN) { 2269e56fb50fSWilliam Allen Simpson return -EINVAL; 2270e56fb50fSWilliam Allen Simpson } 2271e56fb50fSWilliam Allen Simpson 2272e56fb50fSWilliam Allen Simpson if (TCP_COOKIE_OUT_NEVER & ctd.tcpct_flags) { 2273e56fb50fSWilliam Allen Simpson /* Supercedes all other values */ 2274e56fb50fSWilliam Allen Simpson lock_sock(sk); 2275e56fb50fSWilliam Allen Simpson if (tp->cookie_values != NULL) { 2276e56fb50fSWilliam Allen Simpson kref_put(&tp->cookie_values->kref, 2277e56fb50fSWilliam Allen Simpson tcp_cookie_values_release); 2278e56fb50fSWilliam Allen Simpson tp->cookie_values = NULL; 2279e56fb50fSWilliam Allen Simpson } 2280e56fb50fSWilliam Allen Simpson tp->rx_opt.cookie_in_always = 0; /* false */ 2281e56fb50fSWilliam Allen Simpson tp->rx_opt.cookie_out_never = 1; /* true */ 2282e56fb50fSWilliam Allen Simpson release_sock(sk); 2283e56fb50fSWilliam Allen Simpson return err; 2284e56fb50fSWilliam Allen Simpson } 2285e56fb50fSWilliam Allen Simpson 2286e56fb50fSWilliam Allen Simpson /* Allocate ancillary memory before locking. 2287e56fb50fSWilliam Allen Simpson */ 2288e56fb50fSWilliam Allen Simpson if (ctd.tcpct_used > 0 || 2289e56fb50fSWilliam Allen Simpson (tp->cookie_values == NULL && 2290e56fb50fSWilliam Allen Simpson (sysctl_tcp_cookie_size > 0 || 2291e56fb50fSWilliam Allen Simpson ctd.tcpct_cookie_desired > 0 || 2292e56fb50fSWilliam Allen Simpson ctd.tcpct_s_data_desired > 0))) { 2293e56fb50fSWilliam Allen Simpson cvp = kzalloc(sizeof(*cvp) + ctd.tcpct_used, 2294e56fb50fSWilliam Allen Simpson GFP_KERNEL); 2295e56fb50fSWilliam Allen Simpson if (cvp == NULL) 2296e56fb50fSWilliam Allen Simpson return -ENOMEM; 2297a3bdb549SDmitry Popov 2298a3bdb549SDmitry Popov kref_init(&cvp->kref); 2299e56fb50fSWilliam Allen Simpson } 2300e56fb50fSWilliam Allen Simpson lock_sock(sk); 2301e56fb50fSWilliam Allen Simpson tp->rx_opt.cookie_in_always = 2302e56fb50fSWilliam Allen Simpson (TCP_COOKIE_IN_ALWAYS & ctd.tcpct_flags); 2303e56fb50fSWilliam Allen Simpson tp->rx_opt.cookie_out_never = 0; /* false */ 2304e56fb50fSWilliam Allen Simpson 2305e56fb50fSWilliam Allen Simpson if (tp->cookie_values != NULL) { 2306e56fb50fSWilliam Allen Simpson if (cvp != NULL) { 2307e56fb50fSWilliam Allen Simpson /* Changed values are recorded by a changed 2308e56fb50fSWilliam Allen Simpson * pointer, ensuring the cookie will differ, 2309e56fb50fSWilliam Allen Simpson * without separately hashing each value later. 2310e56fb50fSWilliam Allen Simpson */ 2311e56fb50fSWilliam Allen Simpson kref_put(&tp->cookie_values->kref, 2312e56fb50fSWilliam Allen Simpson tcp_cookie_values_release); 2313e56fb50fSWilliam Allen Simpson } else { 2314e56fb50fSWilliam Allen Simpson cvp = tp->cookie_values; 2315e56fb50fSWilliam Allen Simpson } 2316e56fb50fSWilliam Allen Simpson } 2317a3bdb549SDmitry Popov 2318e56fb50fSWilliam Allen Simpson if (cvp != NULL) { 2319e56fb50fSWilliam Allen Simpson cvp->cookie_desired = ctd.tcpct_cookie_desired; 2320e56fb50fSWilliam Allen Simpson 2321e56fb50fSWilliam Allen Simpson if (ctd.tcpct_used > 0) { 2322e56fb50fSWilliam Allen Simpson memcpy(cvp->s_data_payload, ctd.tcpct_value, 2323e56fb50fSWilliam Allen Simpson ctd.tcpct_used); 2324e56fb50fSWilliam Allen Simpson cvp->s_data_desired = ctd.tcpct_used; 2325e56fb50fSWilliam Allen Simpson cvp->s_data_constant = 1; /* true */ 2326e56fb50fSWilliam Allen Simpson } else { 2327e56fb50fSWilliam Allen Simpson /* No constant payload data. */ 2328e56fb50fSWilliam Allen Simpson cvp->s_data_desired = ctd.tcpct_s_data_desired; 2329e56fb50fSWilliam Allen Simpson cvp->s_data_constant = 0; /* false */ 2330e56fb50fSWilliam Allen Simpson } 2331a3bdb549SDmitry Popov 2332a3bdb549SDmitry Popov tp->cookie_values = cvp; 2333e56fb50fSWilliam Allen Simpson } 2334e56fb50fSWilliam Allen Simpson release_sock(sk); 2335e56fb50fSWilliam Allen Simpson return err; 2336e56fb50fSWilliam Allen Simpson } 2337e56fb50fSWilliam Allen Simpson default: 2338e56fb50fSWilliam Allen Simpson /* fallthru */ 2339e56fb50fSWilliam Allen Simpson break; 2340ccbd6a5aSJoe Perches } 23415f8ef48dSStephen Hemminger 23421da177e4SLinus Torvalds if (optlen < sizeof(int)) 23431da177e4SLinus Torvalds return -EINVAL; 23441da177e4SLinus Torvalds 23451da177e4SLinus Torvalds if (get_user(val, (int __user *)optval)) 23461da177e4SLinus Torvalds return -EFAULT; 23471da177e4SLinus Torvalds 23481da177e4SLinus Torvalds lock_sock(sk); 23491da177e4SLinus Torvalds 23501da177e4SLinus Torvalds switch (optname) { 23511da177e4SLinus Torvalds case TCP_MAXSEG: 23521da177e4SLinus Torvalds /* Values greater than interface MTU won't take effect. However 23531da177e4SLinus Torvalds * at the point when this call is done we typically don't yet 23541da177e4SLinus Torvalds * know which interface is going to be used */ 2355c39508d6SDavid S. Miller if (val < TCP_MIN_MSS || val > MAX_TCP_WINDOW) { 23561da177e4SLinus Torvalds err = -EINVAL; 23571da177e4SLinus Torvalds break; 23581da177e4SLinus Torvalds } 23591da177e4SLinus Torvalds tp->rx_opt.user_mss = val; 23601da177e4SLinus Torvalds break; 23611da177e4SLinus Torvalds 23621da177e4SLinus Torvalds case TCP_NODELAY: 23631da177e4SLinus Torvalds if (val) { 23641da177e4SLinus Torvalds /* TCP_NODELAY is weaker than TCP_CORK, so that 23651da177e4SLinus Torvalds * this option on corked socket is remembered, but 23661da177e4SLinus Torvalds * it is not activated until cork is cleared. 23671da177e4SLinus Torvalds * 23681da177e4SLinus Torvalds * However, when TCP_NODELAY is set we make 23691da177e4SLinus Torvalds * an explicit push, which overrides even TCP_CORK 23701da177e4SLinus Torvalds * for currently queued segments. 23711da177e4SLinus Torvalds */ 23721da177e4SLinus Torvalds tp->nonagle |= TCP_NAGLE_OFF|TCP_NAGLE_PUSH; 23739e412ba7SIlpo Järvinen tcp_push_pending_frames(sk); 23741da177e4SLinus Torvalds } else { 23751da177e4SLinus Torvalds tp->nonagle &= ~TCP_NAGLE_OFF; 23761da177e4SLinus Torvalds } 23771da177e4SLinus Torvalds break; 23781da177e4SLinus Torvalds 237936e31b0aSAndreas Petlund case TCP_THIN_LINEAR_TIMEOUTS: 238036e31b0aSAndreas Petlund if (val < 0 || val > 1) 238136e31b0aSAndreas Petlund err = -EINVAL; 238236e31b0aSAndreas Petlund else 238336e31b0aSAndreas Petlund tp->thin_lto = val; 238436e31b0aSAndreas Petlund break; 238536e31b0aSAndreas Petlund 23867e380175SAndreas Petlund case TCP_THIN_DUPACK: 23877e380175SAndreas Petlund if (val < 0 || val > 1) 23887e380175SAndreas Petlund err = -EINVAL; 23897e380175SAndreas Petlund else 23907e380175SAndreas Petlund tp->thin_dupack = val; 23917e380175SAndreas Petlund break; 23927e380175SAndreas Petlund 2393ee995283SPavel Emelyanov case TCP_REPAIR: 2394ee995283SPavel Emelyanov if (!tcp_can_repair_sock(sk)) 2395ee995283SPavel Emelyanov err = -EPERM; 2396ee995283SPavel Emelyanov else if (val == 1) { 2397ee995283SPavel Emelyanov tp->repair = 1; 2398ee995283SPavel Emelyanov sk->sk_reuse = SK_FORCE_REUSE; 2399ee995283SPavel Emelyanov tp->repair_queue = TCP_NO_QUEUE; 2400ee995283SPavel Emelyanov } else if (val == 0) { 2401ee995283SPavel Emelyanov tp->repair = 0; 2402ee995283SPavel Emelyanov sk->sk_reuse = SK_NO_REUSE; 2403ee995283SPavel Emelyanov tcp_send_window_probe(sk); 2404ee995283SPavel Emelyanov } else 2405ee995283SPavel Emelyanov err = -EINVAL; 2406ee995283SPavel Emelyanov 2407ee995283SPavel Emelyanov break; 2408ee995283SPavel Emelyanov 2409ee995283SPavel Emelyanov case TCP_REPAIR_QUEUE: 2410ee995283SPavel Emelyanov if (!tp->repair) 2411ee995283SPavel Emelyanov err = -EPERM; 2412ee995283SPavel Emelyanov else if (val < TCP_QUEUES_NR) 2413ee995283SPavel Emelyanov tp->repair_queue = val; 2414ee995283SPavel Emelyanov else 2415ee995283SPavel Emelyanov err = -EINVAL; 2416ee995283SPavel Emelyanov break; 2417ee995283SPavel Emelyanov 2418ee995283SPavel Emelyanov case TCP_QUEUE_SEQ: 2419ee995283SPavel Emelyanov if (sk->sk_state != TCP_CLOSE) 2420ee995283SPavel Emelyanov err = -EPERM; 2421ee995283SPavel Emelyanov else if (tp->repair_queue == TCP_SEND_QUEUE) 2422ee995283SPavel Emelyanov tp->write_seq = val; 2423ee995283SPavel Emelyanov else if (tp->repair_queue == TCP_RECV_QUEUE) 2424ee995283SPavel Emelyanov tp->rcv_nxt = val; 2425ee995283SPavel Emelyanov else 2426ee995283SPavel Emelyanov err = -EINVAL; 2427ee995283SPavel Emelyanov break; 2428ee995283SPavel Emelyanov 24291da177e4SLinus Torvalds case TCP_CORK: 24301da177e4SLinus Torvalds /* When set indicates to always queue non-full frames. 24311da177e4SLinus Torvalds * Later the user clears this option and we transmit 24321da177e4SLinus Torvalds * any pending partial frames in the queue. This is 24331da177e4SLinus Torvalds * meant to be used alongside sendfile() to get properly 24341da177e4SLinus Torvalds * filled frames when the user (for example) must write 24351da177e4SLinus Torvalds * out headers with a write() call first and then use 24361da177e4SLinus Torvalds * sendfile to send out the data parts. 24371da177e4SLinus Torvalds * 24381da177e4SLinus Torvalds * TCP_CORK can be set together with TCP_NODELAY and it is 24391da177e4SLinus Torvalds * stronger than TCP_NODELAY. 24401da177e4SLinus Torvalds */ 24411da177e4SLinus Torvalds if (val) { 24421da177e4SLinus Torvalds tp->nonagle |= TCP_NAGLE_CORK; 24431da177e4SLinus Torvalds } else { 24441da177e4SLinus Torvalds tp->nonagle &= ~TCP_NAGLE_CORK; 24451da177e4SLinus Torvalds if (tp->nonagle&TCP_NAGLE_OFF) 24461da177e4SLinus Torvalds tp->nonagle |= TCP_NAGLE_PUSH; 24479e412ba7SIlpo Järvinen tcp_push_pending_frames(sk); 24481da177e4SLinus Torvalds } 24491da177e4SLinus Torvalds break; 24501da177e4SLinus Torvalds 24511da177e4SLinus Torvalds case TCP_KEEPIDLE: 24521da177e4SLinus Torvalds if (val < 1 || val > MAX_TCP_KEEPIDLE) 24531da177e4SLinus Torvalds err = -EINVAL; 24541da177e4SLinus Torvalds else { 24551da177e4SLinus Torvalds tp->keepalive_time = val * HZ; 24561da177e4SLinus Torvalds if (sock_flag(sk, SOCK_KEEPOPEN) && 24571da177e4SLinus Torvalds !((1 << sk->sk_state) & 24581da177e4SLinus Torvalds (TCPF_CLOSE | TCPF_LISTEN))) { 24596c37e5deSFlavio Leitner u32 elapsed = keepalive_time_elapsed(tp); 24601da177e4SLinus Torvalds if (tp->keepalive_time > elapsed) 24611da177e4SLinus Torvalds elapsed = tp->keepalive_time - elapsed; 24621da177e4SLinus Torvalds else 24631da177e4SLinus Torvalds elapsed = 0; 2464463c84b9SArnaldo Carvalho de Melo inet_csk_reset_keepalive_timer(sk, elapsed); 24651da177e4SLinus Torvalds } 24661da177e4SLinus Torvalds } 24671da177e4SLinus Torvalds break; 24681da177e4SLinus Torvalds case TCP_KEEPINTVL: 24691da177e4SLinus Torvalds if (val < 1 || val > MAX_TCP_KEEPINTVL) 24701da177e4SLinus Torvalds err = -EINVAL; 24711da177e4SLinus Torvalds else 24721da177e4SLinus Torvalds tp->keepalive_intvl = val * HZ; 24731da177e4SLinus Torvalds break; 24741da177e4SLinus Torvalds case TCP_KEEPCNT: 24751da177e4SLinus Torvalds if (val < 1 || val > MAX_TCP_KEEPCNT) 24761da177e4SLinus Torvalds err = -EINVAL; 24771da177e4SLinus Torvalds else 24781da177e4SLinus Torvalds tp->keepalive_probes = val; 24791da177e4SLinus Torvalds break; 24801da177e4SLinus Torvalds case TCP_SYNCNT: 24811da177e4SLinus Torvalds if (val < 1 || val > MAX_TCP_SYNCNT) 24821da177e4SLinus Torvalds err = -EINVAL; 24831da177e4SLinus Torvalds else 2484463c84b9SArnaldo Carvalho de Melo icsk->icsk_syn_retries = val; 24851da177e4SLinus Torvalds break; 24861da177e4SLinus Torvalds 24871da177e4SLinus Torvalds case TCP_LINGER2: 24881da177e4SLinus Torvalds if (val < 0) 24891da177e4SLinus Torvalds tp->linger2 = -1; 24901da177e4SLinus Torvalds else if (val > sysctl_tcp_fin_timeout / HZ) 24911da177e4SLinus Torvalds tp->linger2 = 0; 24921da177e4SLinus Torvalds else 24931da177e4SLinus Torvalds tp->linger2 = val * HZ; 24941da177e4SLinus Torvalds break; 24951da177e4SLinus Torvalds 24961da177e4SLinus Torvalds case TCP_DEFER_ACCEPT: 2497b103cf34SJulian Anastasov /* Translate value in seconds to number of retransmits */ 2498b103cf34SJulian Anastasov icsk->icsk_accept_queue.rskq_defer_accept = 2499b103cf34SJulian Anastasov secs_to_retrans(val, TCP_TIMEOUT_INIT / HZ, 2500b103cf34SJulian Anastasov TCP_RTO_MAX / HZ); 25011da177e4SLinus Torvalds break; 25021da177e4SLinus Torvalds 25031da177e4SLinus Torvalds case TCP_WINDOW_CLAMP: 25041da177e4SLinus Torvalds if (!val) { 25051da177e4SLinus Torvalds if (sk->sk_state != TCP_CLOSE) { 25061da177e4SLinus Torvalds err = -EINVAL; 25071da177e4SLinus Torvalds break; 25081da177e4SLinus Torvalds } 25091da177e4SLinus Torvalds tp->window_clamp = 0; 25101da177e4SLinus Torvalds } else 25111da177e4SLinus Torvalds tp->window_clamp = val < SOCK_MIN_RCVBUF / 2 ? 25121da177e4SLinus Torvalds SOCK_MIN_RCVBUF / 2 : val; 25131da177e4SLinus Torvalds break; 25141da177e4SLinus Torvalds 25151da177e4SLinus Torvalds case TCP_QUICKACK: 25161da177e4SLinus Torvalds if (!val) { 2517463c84b9SArnaldo Carvalho de Melo icsk->icsk_ack.pingpong = 1; 25181da177e4SLinus Torvalds } else { 2519463c84b9SArnaldo Carvalho de Melo icsk->icsk_ack.pingpong = 0; 25201da177e4SLinus Torvalds if ((1 << sk->sk_state) & 25211da177e4SLinus Torvalds (TCPF_ESTABLISHED | TCPF_CLOSE_WAIT) && 2522463c84b9SArnaldo Carvalho de Melo inet_csk_ack_scheduled(sk)) { 2523463c84b9SArnaldo Carvalho de Melo icsk->icsk_ack.pending |= ICSK_ACK_PUSHED; 25240e4b4992SChris Leech tcp_cleanup_rbuf(sk, 1); 25251da177e4SLinus Torvalds if (!(val & 1)) 2526463c84b9SArnaldo Carvalho de Melo icsk->icsk_ack.pingpong = 1; 25271da177e4SLinus Torvalds } 25281da177e4SLinus Torvalds } 25291da177e4SLinus Torvalds break; 25301da177e4SLinus Torvalds 2531cfb6eeb4SYOSHIFUJI Hideaki #ifdef CONFIG_TCP_MD5SIG 2532cfb6eeb4SYOSHIFUJI Hideaki case TCP_MD5SIG: 2533cfb6eeb4SYOSHIFUJI Hideaki /* Read the IP->Key mappings from userspace */ 2534cfb6eeb4SYOSHIFUJI Hideaki err = tp->af_specific->md5_parse(sk, optval, optlen); 2535cfb6eeb4SYOSHIFUJI Hideaki break; 2536cfb6eeb4SYOSHIFUJI Hideaki #endif 2537dca43c75SJerry Chu case TCP_USER_TIMEOUT: 2538dca43c75SJerry Chu /* Cap the max timeout in ms TCP will retry/retrans 2539dca43c75SJerry Chu * before giving up and aborting (ETIMEDOUT) a connection. 2540dca43c75SJerry Chu */ 2541dca43c75SJerry Chu icsk->icsk_user_timeout = msecs_to_jiffies(val); 2542dca43c75SJerry Chu break; 25431da177e4SLinus Torvalds default: 25441da177e4SLinus Torvalds err = -ENOPROTOOPT; 25451da177e4SLinus Torvalds break; 25463ff50b79SStephen Hemminger } 25473ff50b79SStephen Hemminger 25481da177e4SLinus Torvalds release_sock(sk); 25491da177e4SLinus Torvalds return err; 25501da177e4SLinus Torvalds } 25511da177e4SLinus Torvalds 25523fdadf7dSDmitry Mishin int tcp_setsockopt(struct sock *sk, int level, int optname, char __user *optval, 2553b7058842SDavid S. Miller unsigned int optlen) 25543fdadf7dSDmitry Mishin { 2555cf533ea5SEric Dumazet const struct inet_connection_sock *icsk = inet_csk(sk); 25563fdadf7dSDmitry Mishin 25573fdadf7dSDmitry Mishin if (level != SOL_TCP) 25583fdadf7dSDmitry Mishin return icsk->icsk_af_ops->setsockopt(sk, level, optname, 25593fdadf7dSDmitry Mishin optval, optlen); 25603fdadf7dSDmitry Mishin return do_tcp_setsockopt(sk, level, optname, optval, optlen); 25613fdadf7dSDmitry Mishin } 25624bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_setsockopt); 25633fdadf7dSDmitry Mishin 25643fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT 2565543d9cfeSArnaldo Carvalho de Melo int compat_tcp_setsockopt(struct sock *sk, int level, int optname, 2566b7058842SDavid S. Miller char __user *optval, unsigned int optlen) 25673fdadf7dSDmitry Mishin { 2568dec73ff0SArnaldo Carvalho de Melo if (level != SOL_TCP) 2569dec73ff0SArnaldo Carvalho de Melo return inet_csk_compat_setsockopt(sk, level, optname, 2570dec73ff0SArnaldo Carvalho de Melo optval, optlen); 25713fdadf7dSDmitry Mishin return do_tcp_setsockopt(sk, level, optname, optval, optlen); 25723fdadf7dSDmitry Mishin } 2573543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_tcp_setsockopt); 25743fdadf7dSDmitry Mishin #endif 25753fdadf7dSDmitry Mishin 25761da177e4SLinus Torvalds /* Return information about state of tcp endpoint in API format. */ 2577cf533ea5SEric Dumazet void tcp_get_info(const struct sock *sk, struct tcp_info *info) 25781da177e4SLinus Torvalds { 2579cf533ea5SEric Dumazet const struct tcp_sock *tp = tcp_sk(sk); 2580463c84b9SArnaldo Carvalho de Melo const struct inet_connection_sock *icsk = inet_csk(sk); 25811da177e4SLinus Torvalds u32 now = tcp_time_stamp; 25821da177e4SLinus Torvalds 25831da177e4SLinus Torvalds memset(info, 0, sizeof(*info)); 25841da177e4SLinus Torvalds 25851da177e4SLinus Torvalds info->tcpi_state = sk->sk_state; 25866687e988SArnaldo Carvalho de Melo info->tcpi_ca_state = icsk->icsk_ca_state; 2587463c84b9SArnaldo Carvalho de Melo info->tcpi_retransmits = icsk->icsk_retransmits; 25886687e988SArnaldo Carvalho de Melo info->tcpi_probes = icsk->icsk_probes_out; 2589463c84b9SArnaldo Carvalho de Melo info->tcpi_backoff = icsk->icsk_backoff; 25901da177e4SLinus Torvalds 25911da177e4SLinus Torvalds if (tp->rx_opt.tstamp_ok) 25921da177e4SLinus Torvalds info->tcpi_options |= TCPI_OPT_TIMESTAMPS; 2593e60402d0SIlpo Järvinen if (tcp_is_sack(tp)) 25941da177e4SLinus Torvalds info->tcpi_options |= TCPI_OPT_SACK; 25951da177e4SLinus Torvalds if (tp->rx_opt.wscale_ok) { 25961da177e4SLinus Torvalds info->tcpi_options |= TCPI_OPT_WSCALE; 25971da177e4SLinus Torvalds info->tcpi_snd_wscale = tp->rx_opt.snd_wscale; 25981da177e4SLinus Torvalds info->tcpi_rcv_wscale = tp->rx_opt.rcv_wscale; 25991da177e4SLinus Torvalds } 26001da177e4SLinus Torvalds 26011da177e4SLinus Torvalds if (tp->ecn_flags & TCP_ECN_OK) 26021da177e4SLinus Torvalds info->tcpi_options |= TCPI_OPT_ECN; 2603b5c5693bSEric Dumazet if (tp->ecn_flags & TCP_ECN_SEEN) 2604b5c5693bSEric Dumazet info->tcpi_options |= TCPI_OPT_ECN_SEEN; 26051da177e4SLinus Torvalds 2606463c84b9SArnaldo Carvalho de Melo info->tcpi_rto = jiffies_to_usecs(icsk->icsk_rto); 2607463c84b9SArnaldo Carvalho de Melo info->tcpi_ato = jiffies_to_usecs(icsk->icsk_ack.ato); 2608c1b4a7e6SDavid S. Miller info->tcpi_snd_mss = tp->mss_cache; 2609463c84b9SArnaldo Carvalho de Melo info->tcpi_rcv_mss = icsk->icsk_ack.rcv_mss; 26101da177e4SLinus Torvalds 26115ee3afbaSRick Jones if (sk->sk_state == TCP_LISTEN) { 26125ee3afbaSRick Jones info->tcpi_unacked = sk->sk_ack_backlog; 26135ee3afbaSRick Jones info->tcpi_sacked = sk->sk_max_ack_backlog; 26145ee3afbaSRick Jones } else { 26151da177e4SLinus Torvalds info->tcpi_unacked = tp->packets_out; 26161da177e4SLinus Torvalds info->tcpi_sacked = tp->sacked_out; 26175ee3afbaSRick Jones } 26181da177e4SLinus Torvalds info->tcpi_lost = tp->lost_out; 26191da177e4SLinus Torvalds info->tcpi_retrans = tp->retrans_out; 26201da177e4SLinus Torvalds info->tcpi_fackets = tp->fackets_out; 26211da177e4SLinus Torvalds 26221da177e4SLinus Torvalds info->tcpi_last_data_sent = jiffies_to_msecs(now - tp->lsndtime); 2623463c84b9SArnaldo Carvalho de Melo info->tcpi_last_data_recv = jiffies_to_msecs(now - icsk->icsk_ack.lrcvtime); 26241da177e4SLinus Torvalds info->tcpi_last_ack_recv = jiffies_to_msecs(now - tp->rcv_tstamp); 26251da177e4SLinus Torvalds 2626d83d8461SArnaldo Carvalho de Melo info->tcpi_pmtu = icsk->icsk_pmtu_cookie; 26271da177e4SLinus Torvalds info->tcpi_rcv_ssthresh = tp->rcv_ssthresh; 26281da177e4SLinus Torvalds info->tcpi_rtt = jiffies_to_usecs(tp->srtt)>>3; 26291da177e4SLinus Torvalds info->tcpi_rttvar = jiffies_to_usecs(tp->mdev)>>2; 26301da177e4SLinus Torvalds info->tcpi_snd_ssthresh = tp->snd_ssthresh; 26311da177e4SLinus Torvalds info->tcpi_snd_cwnd = tp->snd_cwnd; 26321da177e4SLinus Torvalds info->tcpi_advmss = tp->advmss; 26331da177e4SLinus Torvalds info->tcpi_reordering = tp->reordering; 26341da177e4SLinus Torvalds 26351da177e4SLinus Torvalds info->tcpi_rcv_rtt = jiffies_to_usecs(tp->rcv_rtt_est.rtt)>>3; 26361da177e4SLinus Torvalds info->tcpi_rcv_space = tp->rcvq_space.space; 26371da177e4SLinus Torvalds 26381da177e4SLinus Torvalds info->tcpi_total_retrans = tp->total_retrans; 26391da177e4SLinus Torvalds } 26401da177e4SLinus Torvalds EXPORT_SYMBOL_GPL(tcp_get_info); 26411da177e4SLinus Torvalds 26423fdadf7dSDmitry Mishin static int do_tcp_getsockopt(struct sock *sk, int level, 26433fdadf7dSDmitry Mishin int optname, char __user *optval, int __user *optlen) 26441da177e4SLinus Torvalds { 2645295f7324SArnaldo Carvalho de Melo struct inet_connection_sock *icsk = inet_csk(sk); 26461da177e4SLinus Torvalds struct tcp_sock *tp = tcp_sk(sk); 26471da177e4SLinus Torvalds int val, len; 26481da177e4SLinus Torvalds 26491da177e4SLinus Torvalds if (get_user(len, optlen)) 26501da177e4SLinus Torvalds return -EFAULT; 26511da177e4SLinus Torvalds 26521da177e4SLinus Torvalds len = min_t(unsigned int, len, sizeof(int)); 26531da177e4SLinus Torvalds 26541da177e4SLinus Torvalds if (len < 0) 26551da177e4SLinus Torvalds return -EINVAL; 26561da177e4SLinus Torvalds 26571da177e4SLinus Torvalds switch (optname) { 26581da177e4SLinus Torvalds case TCP_MAXSEG: 2659c1b4a7e6SDavid S. Miller val = tp->mss_cache; 26601da177e4SLinus Torvalds if (!val && ((1 << sk->sk_state) & (TCPF_CLOSE | TCPF_LISTEN))) 26611da177e4SLinus Torvalds val = tp->rx_opt.user_mss; 2662*5e6a3ce6SPavel Emelyanov if (tp->repair) 2663*5e6a3ce6SPavel Emelyanov val = tp->rx_opt.mss_clamp; 26641da177e4SLinus Torvalds break; 26651da177e4SLinus Torvalds case TCP_NODELAY: 26661da177e4SLinus Torvalds val = !!(tp->nonagle&TCP_NAGLE_OFF); 26671da177e4SLinus Torvalds break; 26681da177e4SLinus Torvalds case TCP_CORK: 26691da177e4SLinus Torvalds val = !!(tp->nonagle&TCP_NAGLE_CORK); 26701da177e4SLinus Torvalds break; 26711da177e4SLinus Torvalds case TCP_KEEPIDLE: 2672df19a626SEric Dumazet val = keepalive_time_when(tp) / HZ; 26731da177e4SLinus Torvalds break; 26741da177e4SLinus Torvalds case TCP_KEEPINTVL: 2675df19a626SEric Dumazet val = keepalive_intvl_when(tp) / HZ; 26761da177e4SLinus Torvalds break; 26771da177e4SLinus Torvalds case TCP_KEEPCNT: 2678df19a626SEric Dumazet val = keepalive_probes(tp); 26791da177e4SLinus Torvalds break; 26801da177e4SLinus Torvalds case TCP_SYNCNT: 2681295f7324SArnaldo Carvalho de Melo val = icsk->icsk_syn_retries ? : sysctl_tcp_syn_retries; 26821da177e4SLinus Torvalds break; 26831da177e4SLinus Torvalds case TCP_LINGER2: 26841da177e4SLinus Torvalds val = tp->linger2; 26851da177e4SLinus Torvalds if (val >= 0) 26861da177e4SLinus Torvalds val = (val ? : sysctl_tcp_fin_timeout) / HZ; 26871da177e4SLinus Torvalds break; 26881da177e4SLinus Torvalds case TCP_DEFER_ACCEPT: 2689b103cf34SJulian Anastasov val = retrans_to_secs(icsk->icsk_accept_queue.rskq_defer_accept, 2690b103cf34SJulian Anastasov TCP_TIMEOUT_INIT / HZ, TCP_RTO_MAX / HZ); 26911da177e4SLinus Torvalds break; 26921da177e4SLinus Torvalds case TCP_WINDOW_CLAMP: 26931da177e4SLinus Torvalds val = tp->window_clamp; 26941da177e4SLinus Torvalds break; 26951da177e4SLinus Torvalds case TCP_INFO: { 26961da177e4SLinus Torvalds struct tcp_info info; 26971da177e4SLinus Torvalds 26981da177e4SLinus Torvalds if (get_user(len, optlen)) 26991da177e4SLinus Torvalds return -EFAULT; 27001da177e4SLinus Torvalds 27011da177e4SLinus Torvalds tcp_get_info(sk, &info); 27021da177e4SLinus Torvalds 27031da177e4SLinus Torvalds len = min_t(unsigned int, len, sizeof(info)); 27041da177e4SLinus Torvalds if (put_user(len, optlen)) 27051da177e4SLinus Torvalds return -EFAULT; 27061da177e4SLinus Torvalds if (copy_to_user(optval, &info, len)) 27071da177e4SLinus Torvalds return -EFAULT; 27081da177e4SLinus Torvalds return 0; 27091da177e4SLinus Torvalds } 27101da177e4SLinus Torvalds case TCP_QUICKACK: 2711295f7324SArnaldo Carvalho de Melo val = !icsk->icsk_ack.pingpong; 27121da177e4SLinus Torvalds break; 27135f8ef48dSStephen Hemminger 27145f8ef48dSStephen Hemminger case TCP_CONGESTION: 27155f8ef48dSStephen Hemminger if (get_user(len, optlen)) 27165f8ef48dSStephen Hemminger return -EFAULT; 27175f8ef48dSStephen Hemminger len = min_t(unsigned int, len, TCP_CA_NAME_MAX); 27185f8ef48dSStephen Hemminger if (put_user(len, optlen)) 27195f8ef48dSStephen Hemminger return -EFAULT; 27206687e988SArnaldo Carvalho de Melo if (copy_to_user(optval, icsk->icsk_ca_ops->name, len)) 27215f8ef48dSStephen Hemminger return -EFAULT; 27225f8ef48dSStephen Hemminger return 0; 2723e56fb50fSWilliam Allen Simpson 2724e56fb50fSWilliam Allen Simpson case TCP_COOKIE_TRANSACTIONS: { 2725e56fb50fSWilliam Allen Simpson struct tcp_cookie_transactions ctd; 2726e56fb50fSWilliam Allen Simpson struct tcp_cookie_values *cvp = tp->cookie_values; 2727e56fb50fSWilliam Allen Simpson 2728e56fb50fSWilliam Allen Simpson if (get_user(len, optlen)) 2729e56fb50fSWilliam Allen Simpson return -EFAULT; 2730e56fb50fSWilliam Allen Simpson if (len < sizeof(ctd)) 2731e56fb50fSWilliam Allen Simpson return -EINVAL; 2732e56fb50fSWilliam Allen Simpson 2733e56fb50fSWilliam Allen Simpson memset(&ctd, 0, sizeof(ctd)); 2734e56fb50fSWilliam Allen Simpson ctd.tcpct_flags = (tp->rx_opt.cookie_in_always ? 2735e56fb50fSWilliam Allen Simpson TCP_COOKIE_IN_ALWAYS : 0) 2736e56fb50fSWilliam Allen Simpson | (tp->rx_opt.cookie_out_never ? 2737e56fb50fSWilliam Allen Simpson TCP_COOKIE_OUT_NEVER : 0); 2738e56fb50fSWilliam Allen Simpson 2739e56fb50fSWilliam Allen Simpson if (cvp != NULL) { 2740e56fb50fSWilliam Allen Simpson ctd.tcpct_flags |= (cvp->s_data_in ? 2741e56fb50fSWilliam Allen Simpson TCP_S_DATA_IN : 0) 2742e56fb50fSWilliam Allen Simpson | (cvp->s_data_out ? 2743e56fb50fSWilliam Allen Simpson TCP_S_DATA_OUT : 0); 2744e56fb50fSWilliam Allen Simpson 2745e56fb50fSWilliam Allen Simpson ctd.tcpct_cookie_desired = cvp->cookie_desired; 2746e56fb50fSWilliam Allen Simpson ctd.tcpct_s_data_desired = cvp->s_data_desired; 2747e56fb50fSWilliam Allen Simpson 2748e56fb50fSWilliam Allen Simpson memcpy(&ctd.tcpct_value[0], &cvp->cookie_pair[0], 2749e56fb50fSWilliam Allen Simpson cvp->cookie_pair_size); 2750e56fb50fSWilliam Allen Simpson ctd.tcpct_used = cvp->cookie_pair_size; 2751e56fb50fSWilliam Allen Simpson } 2752e56fb50fSWilliam Allen Simpson 2753e56fb50fSWilliam Allen Simpson if (put_user(sizeof(ctd), optlen)) 2754e56fb50fSWilliam Allen Simpson return -EFAULT; 2755e56fb50fSWilliam Allen Simpson if (copy_to_user(optval, &ctd, sizeof(ctd))) 2756e56fb50fSWilliam Allen Simpson return -EFAULT; 2757e56fb50fSWilliam Allen Simpson return 0; 2758e56fb50fSWilliam Allen Simpson } 27593c0fef0bSJosh Hunt case TCP_THIN_LINEAR_TIMEOUTS: 27603c0fef0bSJosh Hunt val = tp->thin_lto; 27613c0fef0bSJosh Hunt break; 27623c0fef0bSJosh Hunt case TCP_THIN_DUPACK: 27633c0fef0bSJosh Hunt val = tp->thin_dupack; 27643c0fef0bSJosh Hunt break; 2765dca43c75SJerry Chu 2766ee995283SPavel Emelyanov case TCP_REPAIR: 2767ee995283SPavel Emelyanov val = tp->repair; 2768ee995283SPavel Emelyanov break; 2769ee995283SPavel Emelyanov 2770ee995283SPavel Emelyanov case TCP_REPAIR_QUEUE: 2771ee995283SPavel Emelyanov if (tp->repair) 2772ee995283SPavel Emelyanov val = tp->repair_queue; 2773ee995283SPavel Emelyanov else 2774ee995283SPavel Emelyanov return -EINVAL; 2775ee995283SPavel Emelyanov break; 2776ee995283SPavel Emelyanov 2777ee995283SPavel Emelyanov case TCP_QUEUE_SEQ: 2778ee995283SPavel Emelyanov if (tp->repair_queue == TCP_SEND_QUEUE) 2779ee995283SPavel Emelyanov val = tp->write_seq; 2780ee995283SPavel Emelyanov else if (tp->repair_queue == TCP_RECV_QUEUE) 2781ee995283SPavel Emelyanov val = tp->rcv_nxt; 2782ee995283SPavel Emelyanov else 2783ee995283SPavel Emelyanov return -EINVAL; 2784ee995283SPavel Emelyanov break; 2785ee995283SPavel Emelyanov 2786dca43c75SJerry Chu case TCP_USER_TIMEOUT: 2787dca43c75SJerry Chu val = jiffies_to_msecs(icsk->icsk_user_timeout); 2788dca43c75SJerry Chu break; 27891da177e4SLinus Torvalds default: 27901da177e4SLinus Torvalds return -ENOPROTOOPT; 27913ff50b79SStephen Hemminger } 27921da177e4SLinus Torvalds 27931da177e4SLinus Torvalds if (put_user(len, optlen)) 27941da177e4SLinus Torvalds return -EFAULT; 27951da177e4SLinus Torvalds if (copy_to_user(optval, &val, len)) 27961da177e4SLinus Torvalds return -EFAULT; 27971da177e4SLinus Torvalds return 0; 27981da177e4SLinus Torvalds } 27991da177e4SLinus Torvalds 28003fdadf7dSDmitry Mishin int tcp_getsockopt(struct sock *sk, int level, int optname, char __user *optval, 28013fdadf7dSDmitry Mishin int __user *optlen) 28023fdadf7dSDmitry Mishin { 28033fdadf7dSDmitry Mishin struct inet_connection_sock *icsk = inet_csk(sk); 28043fdadf7dSDmitry Mishin 28053fdadf7dSDmitry Mishin if (level != SOL_TCP) 28063fdadf7dSDmitry Mishin return icsk->icsk_af_ops->getsockopt(sk, level, optname, 28073fdadf7dSDmitry Mishin optval, optlen); 28083fdadf7dSDmitry Mishin return do_tcp_getsockopt(sk, level, optname, optval, optlen); 28093fdadf7dSDmitry Mishin } 28104bc2f18bSEric Dumazet EXPORT_SYMBOL(tcp_getsockopt); 28113fdadf7dSDmitry Mishin 28123fdadf7dSDmitry Mishin #ifdef CONFIG_COMPAT 2813543d9cfeSArnaldo Carvalho de Melo int compat_tcp_getsockopt(struct sock *sk, int level, int optname, 2814543d9cfeSArnaldo Carvalho de Melo char __user *optval, int __user *optlen) 28153fdadf7dSDmitry Mishin { 2816dec73ff0SArnaldo Carvalho de Melo if (level != SOL_TCP) 2817dec73ff0SArnaldo Carvalho de Melo return inet_csk_compat_getsockopt(sk, level, optname, 2818dec73ff0SArnaldo Carvalho de Melo optval, optlen); 28193fdadf7dSDmitry Mishin return do_tcp_getsockopt(sk, level, optname, optval, optlen); 28203fdadf7dSDmitry Mishin } 2821543d9cfeSArnaldo Carvalho de Melo EXPORT_SYMBOL(compat_tcp_getsockopt); 28223fdadf7dSDmitry Mishin #endif 28231da177e4SLinus Torvalds 2824c8f44affSMichał Mirosław struct sk_buff *tcp_tso_segment(struct sk_buff *skb, 2825c8f44affSMichał Mirosław netdev_features_t features) 2826f4c50d99SHerbert Xu { 2827f4c50d99SHerbert Xu struct sk_buff *segs = ERR_PTR(-EINVAL); 2828f4c50d99SHerbert Xu struct tcphdr *th; 282995c96174SEric Dumazet unsigned int thlen; 2830f4c50d99SHerbert Xu unsigned int seq; 2831d3bc23e7SAl Viro __be32 delta; 2832f4c50d99SHerbert Xu unsigned int oldlen; 28334e704ee3SHerbert Xu unsigned int mss; 2834f4c50d99SHerbert Xu 2835f4c50d99SHerbert Xu if (!pskb_may_pull(skb, sizeof(*th))) 2836f4c50d99SHerbert Xu goto out; 2837f4c50d99SHerbert Xu 2838aa8223c7SArnaldo Carvalho de Melo th = tcp_hdr(skb); 2839f4c50d99SHerbert Xu thlen = th->doff * 4; 2840f4c50d99SHerbert Xu if (thlen < sizeof(*th)) 2841f4c50d99SHerbert Xu goto out; 2842f4c50d99SHerbert Xu 2843f4c50d99SHerbert Xu if (!pskb_may_pull(skb, thlen)) 2844f4c50d99SHerbert Xu goto out; 2845f4c50d99SHerbert Xu 28460718bcc0SHerbert Xu oldlen = (u16)~skb->len; 2847f4c50d99SHerbert Xu __skb_pull(skb, thlen); 2848f4c50d99SHerbert Xu 28494e704ee3SHerbert Xu mss = skb_shinfo(skb)->gso_size; 28504e704ee3SHerbert Xu if (unlikely(skb->len <= mss)) 28514e704ee3SHerbert Xu goto out; 28524e704ee3SHerbert Xu 28533820c3f3SHerbert Xu if (skb_gso_ok(skb, features | NETIF_F_GSO_ROBUST)) { 28543820c3f3SHerbert Xu /* Packet is from an untrusted source, reset gso_segs. */ 2855bbcf467dSHerbert Xu int type = skb_shinfo(skb)->gso_type; 28563820c3f3SHerbert Xu 2857bbcf467dSHerbert Xu if (unlikely(type & 2858bbcf467dSHerbert Xu ~(SKB_GSO_TCPV4 | 2859bbcf467dSHerbert Xu SKB_GSO_DODGY | 2860bbcf467dSHerbert Xu SKB_GSO_TCP_ECN | 2861bbcf467dSHerbert Xu SKB_GSO_TCPV6 | 2862bbcf467dSHerbert Xu 0) || 2863bbcf467dSHerbert Xu !(type & (SKB_GSO_TCPV4 | SKB_GSO_TCPV6)))) 2864bbcf467dSHerbert Xu goto out; 2865bbcf467dSHerbert Xu 2866172589ccSIlpo Järvinen skb_shinfo(skb)->gso_segs = DIV_ROUND_UP(skb->len, mss); 28673820c3f3SHerbert Xu 28683820c3f3SHerbert Xu segs = NULL; 28693820c3f3SHerbert Xu goto out; 28703820c3f3SHerbert Xu } 28713820c3f3SHerbert Xu 2872576a30ebSHerbert Xu segs = skb_segment(skb, features); 2873f4c50d99SHerbert Xu if (IS_ERR(segs)) 2874f4c50d99SHerbert Xu goto out; 2875f4c50d99SHerbert Xu 28764e704ee3SHerbert Xu delta = htonl(oldlen + (thlen + mss)); 2877f4c50d99SHerbert Xu 2878f4c50d99SHerbert Xu skb = segs; 2879aa8223c7SArnaldo Carvalho de Melo th = tcp_hdr(skb); 2880f4c50d99SHerbert Xu seq = ntohl(th->seq); 2881f4c50d99SHerbert Xu 2882f4c50d99SHerbert Xu do { 2883f4c50d99SHerbert Xu th->fin = th->psh = 0; 2884f4c50d99SHerbert Xu 2885d3bc23e7SAl Viro th->check = ~csum_fold((__force __wsum)((__force u32)th->check + 2886d3bc23e7SAl Viro (__force u32)delta)); 288784fa7933SPatrick McHardy if (skb->ip_summed != CHECKSUM_PARTIAL) 28889c70220bSArnaldo Carvalho de Melo th->check = 28899c70220bSArnaldo Carvalho de Melo csum_fold(csum_partial(skb_transport_header(skb), 28909c70220bSArnaldo Carvalho de Melo thlen, skb->csum)); 2891f4c50d99SHerbert Xu 28924e704ee3SHerbert Xu seq += mss; 2893f4c50d99SHerbert Xu skb = skb->next; 2894aa8223c7SArnaldo Carvalho de Melo th = tcp_hdr(skb); 2895f4c50d99SHerbert Xu 2896f4c50d99SHerbert Xu th->seq = htonl(seq); 2897f4c50d99SHerbert Xu th->cwr = 0; 2898f4c50d99SHerbert Xu } while (skb->next); 2899f4c50d99SHerbert Xu 290027a884dcSArnaldo Carvalho de Melo delta = htonl(oldlen + (skb->tail - skb->transport_header) + 29019c70220bSArnaldo Carvalho de Melo skb->data_len); 2902d3bc23e7SAl Viro th->check = ~csum_fold((__force __wsum)((__force u32)th->check + 2903d3bc23e7SAl Viro (__force u32)delta)); 290484fa7933SPatrick McHardy if (skb->ip_summed != CHECKSUM_PARTIAL) 29059c70220bSArnaldo Carvalho de Melo th->check = csum_fold(csum_partial(skb_transport_header(skb), 29069c70220bSArnaldo Carvalho de Melo thlen, skb->csum)); 2907f4c50d99SHerbert Xu 2908f4c50d99SHerbert Xu out: 2909f4c50d99SHerbert Xu return segs; 2910f4c50d99SHerbert Xu } 2911adcfc7d0SHerbert Xu EXPORT_SYMBOL(tcp_tso_segment); 2912f4c50d99SHerbert Xu 2913bf296b12SHerbert Xu struct sk_buff **tcp_gro_receive(struct sk_buff **head, struct sk_buff *skb) 2914bf296b12SHerbert Xu { 2915bf296b12SHerbert Xu struct sk_buff **pp = NULL; 2916bf296b12SHerbert Xu struct sk_buff *p; 2917bf296b12SHerbert Xu struct tcphdr *th; 2918bf296b12SHerbert Xu struct tcphdr *th2; 2919a0a69a01SHerbert Xu unsigned int len; 2920bf296b12SHerbert Xu unsigned int thlen; 29210eae88f3SEric Dumazet __be32 flags; 2922bf296b12SHerbert Xu unsigned int mss = 1; 2923a5b1cf28SHerbert Xu unsigned int hlen; 2924a5b1cf28SHerbert Xu unsigned int off; 2925bf296b12SHerbert Xu int flush = 1; 2926aa6320d3SHerbert Xu int i; 2927bf296b12SHerbert Xu 2928a5b1cf28SHerbert Xu off = skb_gro_offset(skb); 2929a5b1cf28SHerbert Xu hlen = off + sizeof(*th); 2930a5b1cf28SHerbert Xu th = skb_gro_header_fast(skb, off); 2931a5b1cf28SHerbert Xu if (skb_gro_header_hard(skb, hlen)) { 2932a5b1cf28SHerbert Xu th = skb_gro_header_slow(skb, hlen, off); 293386911732SHerbert Xu if (unlikely(!th)) 2934bf296b12SHerbert Xu goto out; 2935a5b1cf28SHerbert Xu } 2936bf296b12SHerbert Xu 2937bf296b12SHerbert Xu thlen = th->doff * 4; 2938bf296b12SHerbert Xu if (thlen < sizeof(*th)) 2939bf296b12SHerbert Xu goto out; 2940bf296b12SHerbert Xu 2941a5b1cf28SHerbert Xu hlen = off + thlen; 2942a5b1cf28SHerbert Xu if (skb_gro_header_hard(skb, hlen)) { 2943a5b1cf28SHerbert Xu th = skb_gro_header_slow(skb, hlen, off); 294486911732SHerbert Xu if (unlikely(!th)) 2945bf296b12SHerbert Xu goto out; 2946a5b1cf28SHerbert Xu } 2947bf296b12SHerbert Xu 294886911732SHerbert Xu skb_gro_pull(skb, thlen); 2949bf296b12SHerbert Xu 2950a0a69a01SHerbert Xu len = skb_gro_len(skb); 2951bf296b12SHerbert Xu flags = tcp_flag_word(th); 2952bf296b12SHerbert Xu 2953bf296b12SHerbert Xu for (; (p = *head); head = &p->next) { 2954bf296b12SHerbert Xu if (!NAPI_GRO_CB(p)->same_flow) 2955bf296b12SHerbert Xu continue; 2956bf296b12SHerbert Xu 2957bf296b12SHerbert Xu th2 = tcp_hdr(p); 2958bf296b12SHerbert Xu 2959745898eaSHerbert Xu if (*(u32 *)&th->source ^ *(u32 *)&th2->source) { 2960bf296b12SHerbert Xu NAPI_GRO_CB(p)->same_flow = 0; 2961bf296b12SHerbert Xu continue; 2962bf296b12SHerbert Xu } 2963bf296b12SHerbert Xu 2964bf296b12SHerbert Xu goto found; 2965bf296b12SHerbert Xu } 2966bf296b12SHerbert Xu 2967bf296b12SHerbert Xu goto out_check_final; 2968bf296b12SHerbert Xu 2969bf296b12SHerbert Xu found: 2970bf296b12SHerbert Xu flush = NAPI_GRO_CB(p)->flush; 29710eae88f3SEric Dumazet flush |= (__force int)(flags & TCP_FLAG_CWR); 29720eae88f3SEric Dumazet flush |= (__force int)((flags ^ tcp_flag_word(th2)) & 29730eae88f3SEric Dumazet ~(TCP_FLAG_CWR | TCP_FLAG_FIN | TCP_FLAG_PSH)); 29740eae88f3SEric Dumazet flush |= (__force int)(th->ack_seq ^ th2->ack_seq); 2975a2a804cdSHerbert Xu for (i = sizeof(*th); i < thlen; i += 4) 2976aa6320d3SHerbert Xu flush |= *(u32 *)((u8 *)th + i) ^ 2977aa6320d3SHerbert Xu *(u32 *)((u8 *)th2 + i); 2978bf296b12SHerbert Xu 2979b530256dSHerbert Xu mss = skb_shinfo(p)->gso_size; 2980bf296b12SHerbert Xu 298130a3ae30SHerbert Xu flush |= (len - 1) >= mss; 2982aa6320d3SHerbert Xu flush |= (ntohl(th2->seq) + skb_gro_len(p)) ^ ntohl(th->seq); 2983bf296b12SHerbert Xu 2984bf296b12SHerbert Xu if (flush || skb_gro_receive(head, skb)) { 2985bf296b12SHerbert Xu mss = 1; 2986bf296b12SHerbert Xu goto out_check_final; 2987bf296b12SHerbert Xu } 2988bf296b12SHerbert Xu 2989bf296b12SHerbert Xu p = *head; 2990bf296b12SHerbert Xu th2 = tcp_hdr(p); 2991bf296b12SHerbert Xu tcp_flag_word(th2) |= flags & (TCP_FLAG_FIN | TCP_FLAG_PSH); 2992bf296b12SHerbert Xu 2993bf296b12SHerbert Xu out_check_final: 2994a0a69a01SHerbert Xu flush = len < mss; 29950eae88f3SEric Dumazet flush |= (__force int)(flags & (TCP_FLAG_URG | TCP_FLAG_PSH | 29960eae88f3SEric Dumazet TCP_FLAG_RST | TCP_FLAG_SYN | 29970eae88f3SEric Dumazet TCP_FLAG_FIN)); 2998bf296b12SHerbert Xu 2999bf296b12SHerbert Xu if (p && (!NAPI_GRO_CB(skb)->same_flow || flush)) 3000bf296b12SHerbert Xu pp = head; 3001bf296b12SHerbert Xu 3002bf296b12SHerbert Xu out: 3003bf296b12SHerbert Xu NAPI_GRO_CB(skb)->flush |= flush; 3004bf296b12SHerbert Xu 3005bf296b12SHerbert Xu return pp; 3006bf296b12SHerbert Xu } 3007684f2176SHerbert Xu EXPORT_SYMBOL(tcp_gro_receive); 3008bf296b12SHerbert Xu 3009bf296b12SHerbert Xu int tcp_gro_complete(struct sk_buff *skb) 3010bf296b12SHerbert Xu { 3011bf296b12SHerbert Xu struct tcphdr *th = tcp_hdr(skb); 3012bf296b12SHerbert Xu 3013bf296b12SHerbert Xu skb->csum_start = skb_transport_header(skb) - skb->head; 3014bf296b12SHerbert Xu skb->csum_offset = offsetof(struct tcphdr, check); 3015bf296b12SHerbert Xu skb->ip_summed = CHECKSUM_PARTIAL; 3016bf296b12SHerbert Xu 3017bf296b12SHerbert Xu skb_shinfo(skb)->gso_segs = NAPI_GRO_CB(skb)->count; 3018bf296b12SHerbert Xu 3019bf296b12SHerbert Xu if (th->cwr) 3020bf296b12SHerbert Xu skb_shinfo(skb)->gso_type |= SKB_GSO_TCP_ECN; 3021bf296b12SHerbert Xu 3022bf296b12SHerbert Xu return 0; 3023bf296b12SHerbert Xu } 3024684f2176SHerbert Xu EXPORT_SYMBOL(tcp_gro_complete); 3025bf296b12SHerbert Xu 3026cfb6eeb4SYOSHIFUJI Hideaki #ifdef CONFIG_TCP_MD5SIG 3027cfb6eeb4SYOSHIFUJI Hideaki static unsigned long tcp_md5sig_users; 3028765cf997SEric Dumazet static struct tcp_md5sig_pool __percpu *tcp_md5sig_pool; 3029cfb6eeb4SYOSHIFUJI Hideaki static DEFINE_SPINLOCK(tcp_md5sig_pool_lock); 3030cfb6eeb4SYOSHIFUJI Hideaki 3031765cf997SEric Dumazet static void __tcp_free_md5sig_pool(struct tcp_md5sig_pool __percpu *pool) 3032cfb6eeb4SYOSHIFUJI Hideaki { 3033cfb6eeb4SYOSHIFUJI Hideaki int cpu; 3034765cf997SEric Dumazet 3035cfb6eeb4SYOSHIFUJI Hideaki for_each_possible_cpu(cpu) { 3036765cf997SEric Dumazet struct tcp_md5sig_pool *p = per_cpu_ptr(pool, cpu); 3037765cf997SEric Dumazet 3038cfb6eeb4SYOSHIFUJI Hideaki if (p->md5_desc.tfm) 3039cfb6eeb4SYOSHIFUJI Hideaki crypto_free_hash(p->md5_desc.tfm); 3040cfb6eeb4SYOSHIFUJI Hideaki } 3041cfb6eeb4SYOSHIFUJI Hideaki free_percpu(pool); 3042cfb6eeb4SYOSHIFUJI Hideaki } 3043cfb6eeb4SYOSHIFUJI Hideaki 3044cfb6eeb4SYOSHIFUJI Hideaki void tcp_free_md5sig_pool(void) 3045cfb6eeb4SYOSHIFUJI Hideaki { 3046765cf997SEric Dumazet struct tcp_md5sig_pool __percpu *pool = NULL; 3047cfb6eeb4SYOSHIFUJI Hideaki 30482c4f6219SDavid S. Miller spin_lock_bh(&tcp_md5sig_pool_lock); 3049cfb6eeb4SYOSHIFUJI Hideaki if (--tcp_md5sig_users == 0) { 3050cfb6eeb4SYOSHIFUJI Hideaki pool = tcp_md5sig_pool; 3051cfb6eeb4SYOSHIFUJI Hideaki tcp_md5sig_pool = NULL; 3052cfb6eeb4SYOSHIFUJI Hideaki } 30532c4f6219SDavid S. Miller spin_unlock_bh(&tcp_md5sig_pool_lock); 3054cfb6eeb4SYOSHIFUJI Hideaki if (pool) 3055cfb6eeb4SYOSHIFUJI Hideaki __tcp_free_md5sig_pool(pool); 3056cfb6eeb4SYOSHIFUJI Hideaki } 3057cfb6eeb4SYOSHIFUJI Hideaki EXPORT_SYMBOL(tcp_free_md5sig_pool); 3058cfb6eeb4SYOSHIFUJI Hideaki 3059765cf997SEric Dumazet static struct tcp_md5sig_pool __percpu * 30607d720c3eSTejun Heo __tcp_alloc_md5sig_pool(struct sock *sk) 3061cfb6eeb4SYOSHIFUJI Hideaki { 3062cfb6eeb4SYOSHIFUJI Hideaki int cpu; 3063765cf997SEric Dumazet struct tcp_md5sig_pool __percpu *pool; 3064cfb6eeb4SYOSHIFUJI Hideaki 3065765cf997SEric Dumazet pool = alloc_percpu(struct tcp_md5sig_pool); 3066cfb6eeb4SYOSHIFUJI Hideaki if (!pool) 3067cfb6eeb4SYOSHIFUJI Hideaki return NULL; 3068cfb6eeb4SYOSHIFUJI Hideaki 3069cfb6eeb4SYOSHIFUJI Hideaki for_each_possible_cpu(cpu) { 3070cfb6eeb4SYOSHIFUJI Hideaki struct crypto_hash *hash; 3071cfb6eeb4SYOSHIFUJI Hideaki 3072cfb6eeb4SYOSHIFUJI Hideaki hash = crypto_alloc_hash("md5", 0, CRYPTO_ALG_ASYNC); 3073cfb6eeb4SYOSHIFUJI Hideaki if (!hash || IS_ERR(hash)) 3074cfb6eeb4SYOSHIFUJI Hideaki goto out_free; 3075cfb6eeb4SYOSHIFUJI Hideaki 3076765cf997SEric Dumazet per_cpu_ptr(pool, cpu)->md5_desc.tfm = hash; 3077cfb6eeb4SYOSHIFUJI Hideaki } 3078cfb6eeb4SYOSHIFUJI Hideaki return pool; 3079cfb6eeb4SYOSHIFUJI Hideaki out_free: 3080cfb6eeb4SYOSHIFUJI Hideaki __tcp_free_md5sig_pool(pool); 3081cfb6eeb4SYOSHIFUJI Hideaki return NULL; 3082cfb6eeb4SYOSHIFUJI Hideaki } 3083cfb6eeb4SYOSHIFUJI Hideaki 3084765cf997SEric Dumazet struct tcp_md5sig_pool __percpu *tcp_alloc_md5sig_pool(struct sock *sk) 3085cfb6eeb4SYOSHIFUJI Hideaki { 3086765cf997SEric Dumazet struct tcp_md5sig_pool __percpu *pool; 3087cfb6eeb4SYOSHIFUJI Hideaki int alloc = 0; 3088cfb6eeb4SYOSHIFUJI Hideaki 3089cfb6eeb4SYOSHIFUJI Hideaki retry: 30902c4f6219SDavid S. Miller spin_lock_bh(&tcp_md5sig_pool_lock); 3091cfb6eeb4SYOSHIFUJI Hideaki pool = tcp_md5sig_pool; 3092cfb6eeb4SYOSHIFUJI Hideaki if (tcp_md5sig_users++ == 0) { 3093cfb6eeb4SYOSHIFUJI Hideaki alloc = 1; 30942c4f6219SDavid S. Miller spin_unlock_bh(&tcp_md5sig_pool_lock); 3095cfb6eeb4SYOSHIFUJI Hideaki } else if (!pool) { 3096cfb6eeb4SYOSHIFUJI Hideaki tcp_md5sig_users--; 30972c4f6219SDavid S. Miller spin_unlock_bh(&tcp_md5sig_pool_lock); 3098cfb6eeb4SYOSHIFUJI Hideaki cpu_relax(); 3099cfb6eeb4SYOSHIFUJI Hideaki goto retry; 3100cfb6eeb4SYOSHIFUJI Hideaki } else 31012c4f6219SDavid S. Miller spin_unlock_bh(&tcp_md5sig_pool_lock); 3102cfb6eeb4SYOSHIFUJI Hideaki 3103cfb6eeb4SYOSHIFUJI Hideaki if (alloc) { 3104cfb6eeb4SYOSHIFUJI Hideaki /* we cannot hold spinlock here because this may sleep. */ 3105765cf997SEric Dumazet struct tcp_md5sig_pool __percpu *p; 31067d720c3eSTejun Heo 31077d720c3eSTejun Heo p = __tcp_alloc_md5sig_pool(sk); 31082c4f6219SDavid S. Miller spin_lock_bh(&tcp_md5sig_pool_lock); 3109cfb6eeb4SYOSHIFUJI Hideaki if (!p) { 3110cfb6eeb4SYOSHIFUJI Hideaki tcp_md5sig_users--; 31112c4f6219SDavid S. Miller spin_unlock_bh(&tcp_md5sig_pool_lock); 3112cfb6eeb4SYOSHIFUJI Hideaki return NULL; 3113cfb6eeb4SYOSHIFUJI Hideaki } 3114cfb6eeb4SYOSHIFUJI Hideaki pool = tcp_md5sig_pool; 3115cfb6eeb4SYOSHIFUJI Hideaki if (pool) { 3116cfb6eeb4SYOSHIFUJI Hideaki /* oops, it has already been assigned. */ 31172c4f6219SDavid S. Miller spin_unlock_bh(&tcp_md5sig_pool_lock); 3118cfb6eeb4SYOSHIFUJI Hideaki __tcp_free_md5sig_pool(p); 3119cfb6eeb4SYOSHIFUJI Hideaki } else { 3120cfb6eeb4SYOSHIFUJI Hideaki tcp_md5sig_pool = pool = p; 31212c4f6219SDavid S. Miller spin_unlock_bh(&tcp_md5sig_pool_lock); 3122cfb6eeb4SYOSHIFUJI Hideaki } 3123cfb6eeb4SYOSHIFUJI Hideaki } 3124cfb6eeb4SYOSHIFUJI Hideaki return pool; 3125cfb6eeb4SYOSHIFUJI Hideaki } 3126cfb6eeb4SYOSHIFUJI Hideaki EXPORT_SYMBOL(tcp_alloc_md5sig_pool); 3127cfb6eeb4SYOSHIFUJI Hideaki 312835790c04SEric Dumazet 312935790c04SEric Dumazet /** 313035790c04SEric Dumazet * tcp_get_md5sig_pool - get md5sig_pool for this user 313135790c04SEric Dumazet * 313235790c04SEric Dumazet * We use percpu structure, so if we succeed, we exit with preemption 313335790c04SEric Dumazet * and BH disabled, to make sure another thread or softirq handling 313435790c04SEric Dumazet * wont try to get same context. 313535790c04SEric Dumazet */ 313635790c04SEric Dumazet struct tcp_md5sig_pool *tcp_get_md5sig_pool(void) 3137cfb6eeb4SYOSHIFUJI Hideaki { 3138765cf997SEric Dumazet struct tcp_md5sig_pool __percpu *p; 313935790c04SEric Dumazet 314035790c04SEric Dumazet local_bh_disable(); 314135790c04SEric Dumazet 314235790c04SEric Dumazet spin_lock(&tcp_md5sig_pool_lock); 3143cfb6eeb4SYOSHIFUJI Hideaki p = tcp_md5sig_pool; 3144cfb6eeb4SYOSHIFUJI Hideaki if (p) 3145cfb6eeb4SYOSHIFUJI Hideaki tcp_md5sig_users++; 314635790c04SEric Dumazet spin_unlock(&tcp_md5sig_pool_lock); 314735790c04SEric Dumazet 314835790c04SEric Dumazet if (p) 3149765cf997SEric Dumazet return this_cpu_ptr(p); 315035790c04SEric Dumazet 315135790c04SEric Dumazet local_bh_enable(); 315235790c04SEric Dumazet return NULL; 3153cfb6eeb4SYOSHIFUJI Hideaki } 315435790c04SEric Dumazet EXPORT_SYMBOL(tcp_get_md5sig_pool); 3155cfb6eeb4SYOSHIFUJI Hideaki 315635790c04SEric Dumazet void tcp_put_md5sig_pool(void) 31576931ba7cSDavid S. Miller { 315835790c04SEric Dumazet local_bh_enable(); 31596931ba7cSDavid S. Miller tcp_free_md5sig_pool(); 3160cfb6eeb4SYOSHIFUJI Hideaki } 316135790c04SEric Dumazet EXPORT_SYMBOL(tcp_put_md5sig_pool); 316249a72dfbSAdam Langley 316349a72dfbSAdam Langley int tcp_md5_hash_header(struct tcp_md5sig_pool *hp, 3164ca35a0efSEric Dumazet const struct tcphdr *th) 316549a72dfbSAdam Langley { 316649a72dfbSAdam Langley struct scatterlist sg; 3167ca35a0efSEric Dumazet struct tcphdr hdr; 316849a72dfbSAdam Langley int err; 316949a72dfbSAdam Langley 3170ca35a0efSEric Dumazet /* We are not allowed to change tcphdr, make a local copy */ 3171ca35a0efSEric Dumazet memcpy(&hdr, th, sizeof(hdr)); 3172ca35a0efSEric Dumazet hdr.check = 0; 3173ca35a0efSEric Dumazet 317449a72dfbSAdam Langley /* options aren't included in the hash */ 3175ca35a0efSEric Dumazet sg_init_one(&sg, &hdr, sizeof(hdr)); 3176ca35a0efSEric Dumazet err = crypto_hash_update(&hp->md5_desc, &sg, sizeof(hdr)); 317749a72dfbSAdam Langley return err; 317849a72dfbSAdam Langley } 317949a72dfbSAdam Langley EXPORT_SYMBOL(tcp_md5_hash_header); 318049a72dfbSAdam Langley 318149a72dfbSAdam Langley int tcp_md5_hash_skb_data(struct tcp_md5sig_pool *hp, 3182cf533ea5SEric Dumazet const struct sk_buff *skb, unsigned int header_len) 318349a72dfbSAdam Langley { 318449a72dfbSAdam Langley struct scatterlist sg; 318549a72dfbSAdam Langley const struct tcphdr *tp = tcp_hdr(skb); 318649a72dfbSAdam Langley struct hash_desc *desc = &hp->md5_desc; 318795c96174SEric Dumazet unsigned int i; 318895c96174SEric Dumazet const unsigned int head_data_len = skb_headlen(skb) > header_len ? 318949a72dfbSAdam Langley skb_headlen(skb) - header_len : 0; 319049a72dfbSAdam Langley const struct skb_shared_info *shi = skb_shinfo(skb); 3191d7fd1b57SEric Dumazet struct sk_buff *frag_iter; 319249a72dfbSAdam Langley 319349a72dfbSAdam Langley sg_init_table(&sg, 1); 319449a72dfbSAdam Langley 319549a72dfbSAdam Langley sg_set_buf(&sg, ((u8 *) tp) + header_len, head_data_len); 319649a72dfbSAdam Langley if (crypto_hash_update(desc, &sg, head_data_len)) 319749a72dfbSAdam Langley return 1; 319849a72dfbSAdam Langley 319949a72dfbSAdam Langley for (i = 0; i < shi->nr_frags; ++i) { 320049a72dfbSAdam Langley const struct skb_frag_struct *f = &shi->frags[i]; 3201aff65da0SIan Campbell struct page *page = skb_frag_page(f); 32029e903e08SEric Dumazet sg_set_page(&sg, page, skb_frag_size(f), f->page_offset); 32039e903e08SEric Dumazet if (crypto_hash_update(desc, &sg, skb_frag_size(f))) 320449a72dfbSAdam Langley return 1; 320549a72dfbSAdam Langley } 320649a72dfbSAdam Langley 3207d7fd1b57SEric Dumazet skb_walk_frags(skb, frag_iter) 3208d7fd1b57SEric Dumazet if (tcp_md5_hash_skb_data(hp, frag_iter, 0)) 3209d7fd1b57SEric Dumazet return 1; 3210d7fd1b57SEric Dumazet 321149a72dfbSAdam Langley return 0; 321249a72dfbSAdam Langley } 321349a72dfbSAdam Langley EXPORT_SYMBOL(tcp_md5_hash_skb_data); 321449a72dfbSAdam Langley 3215cf533ea5SEric Dumazet int tcp_md5_hash_key(struct tcp_md5sig_pool *hp, const struct tcp_md5sig_key *key) 321649a72dfbSAdam Langley { 321749a72dfbSAdam Langley struct scatterlist sg; 321849a72dfbSAdam Langley 321949a72dfbSAdam Langley sg_init_one(&sg, key->key, key->keylen); 322049a72dfbSAdam Langley return crypto_hash_update(&hp->md5_desc, &sg, key->keylen); 322149a72dfbSAdam Langley } 322249a72dfbSAdam Langley EXPORT_SYMBOL(tcp_md5_hash_key); 322349a72dfbSAdam Langley 3224cfb6eeb4SYOSHIFUJI Hideaki #endif 3225cfb6eeb4SYOSHIFUJI Hideaki 3226da5c78c8SWilliam Allen Simpson /** 3227da5c78c8SWilliam Allen Simpson * Each Responder maintains up to two secret values concurrently for 3228da5c78c8SWilliam Allen Simpson * efficient secret rollover. Each secret value has 4 states: 3229da5c78c8SWilliam Allen Simpson * 3230da5c78c8SWilliam Allen Simpson * Generating. (tcp_secret_generating != tcp_secret_primary) 3231da5c78c8SWilliam Allen Simpson * Generates new Responder-Cookies, but not yet used for primary 3232da5c78c8SWilliam Allen Simpson * verification. This is a short-term state, typically lasting only 3233da5c78c8SWilliam Allen Simpson * one round trip time (RTT). 3234da5c78c8SWilliam Allen Simpson * 3235da5c78c8SWilliam Allen Simpson * Primary. (tcp_secret_generating == tcp_secret_primary) 3236da5c78c8SWilliam Allen Simpson * Used both for generation and primary verification. 3237da5c78c8SWilliam Allen Simpson * 3238da5c78c8SWilliam Allen Simpson * Retiring. (tcp_secret_retiring != tcp_secret_secondary) 3239da5c78c8SWilliam Allen Simpson * Used for verification, until the first failure that can be 3240da5c78c8SWilliam Allen Simpson * verified by the newer Generating secret. At that time, this 3241da5c78c8SWilliam Allen Simpson * cookie's state is changed to Secondary, and the Generating 3242da5c78c8SWilliam Allen Simpson * cookie's state is changed to Primary. This is a short-term state, 3243da5c78c8SWilliam Allen Simpson * typically lasting only one round trip time (RTT). 3244da5c78c8SWilliam Allen Simpson * 3245da5c78c8SWilliam Allen Simpson * Secondary. (tcp_secret_retiring == tcp_secret_secondary) 3246da5c78c8SWilliam Allen Simpson * Used for secondary verification, after primary verification 3247da5c78c8SWilliam Allen Simpson * failures. This state lasts no more than twice the Maximum Segment 3248da5c78c8SWilliam Allen Simpson * Lifetime (2MSL). Then, the secret is discarded. 3249da5c78c8SWilliam Allen Simpson */ 3250da5c78c8SWilliam Allen Simpson struct tcp_cookie_secret { 3251da5c78c8SWilliam Allen Simpson /* The secret is divided into two parts. The digest part is the 3252da5c78c8SWilliam Allen Simpson * equivalent of previously hashing a secret and saving the state, 3253da5c78c8SWilliam Allen Simpson * and serves as an initialization vector (IV). The message part 3254da5c78c8SWilliam Allen Simpson * serves as the trailing secret. 3255da5c78c8SWilliam Allen Simpson */ 3256da5c78c8SWilliam Allen Simpson u32 secrets[COOKIE_WORKSPACE_WORDS]; 3257da5c78c8SWilliam Allen Simpson unsigned long expires; 3258da5c78c8SWilliam Allen Simpson }; 3259da5c78c8SWilliam Allen Simpson 3260da5c78c8SWilliam Allen Simpson #define TCP_SECRET_1MSL (HZ * TCP_PAWS_MSL) 3261da5c78c8SWilliam Allen Simpson #define TCP_SECRET_2MSL (HZ * TCP_PAWS_MSL * 2) 3262da5c78c8SWilliam Allen Simpson #define TCP_SECRET_LIFE (HZ * 600) 3263da5c78c8SWilliam Allen Simpson 3264da5c78c8SWilliam Allen Simpson static struct tcp_cookie_secret tcp_secret_one; 3265da5c78c8SWilliam Allen Simpson static struct tcp_cookie_secret tcp_secret_two; 3266da5c78c8SWilliam Allen Simpson 3267da5c78c8SWilliam Allen Simpson /* Essentially a circular list, without dynamic allocation. */ 3268da5c78c8SWilliam Allen Simpson static struct tcp_cookie_secret *tcp_secret_generating; 3269da5c78c8SWilliam Allen Simpson static struct tcp_cookie_secret *tcp_secret_primary; 3270da5c78c8SWilliam Allen Simpson static struct tcp_cookie_secret *tcp_secret_retiring; 3271da5c78c8SWilliam Allen Simpson static struct tcp_cookie_secret *tcp_secret_secondary; 3272da5c78c8SWilliam Allen Simpson 3273da5c78c8SWilliam Allen Simpson static DEFINE_SPINLOCK(tcp_secret_locker); 3274da5c78c8SWilliam Allen Simpson 3275da5c78c8SWilliam Allen Simpson /* Select a pseudo-random word in the cookie workspace. 3276da5c78c8SWilliam Allen Simpson */ 3277da5c78c8SWilliam Allen Simpson static inline u32 tcp_cookie_work(const u32 *ws, const int n) 3278da5c78c8SWilliam Allen Simpson { 3279da5c78c8SWilliam Allen Simpson return ws[COOKIE_DIGEST_WORDS + ((COOKIE_MESSAGE_WORDS-1) & ws[n])]; 3280da5c78c8SWilliam Allen Simpson } 3281da5c78c8SWilliam Allen Simpson 3282da5c78c8SWilliam Allen Simpson /* Fill bakery[COOKIE_WORKSPACE_WORDS] with generator, updating as needed. 3283da5c78c8SWilliam Allen Simpson * Called in softirq context. 3284da5c78c8SWilliam Allen Simpson * Returns: 0 for success. 3285da5c78c8SWilliam Allen Simpson */ 3286da5c78c8SWilliam Allen Simpson int tcp_cookie_generator(u32 *bakery) 3287da5c78c8SWilliam Allen Simpson { 3288da5c78c8SWilliam Allen Simpson unsigned long jiffy = jiffies; 3289da5c78c8SWilliam Allen Simpson 3290da5c78c8SWilliam Allen Simpson if (unlikely(time_after_eq(jiffy, tcp_secret_generating->expires))) { 3291da5c78c8SWilliam Allen Simpson spin_lock_bh(&tcp_secret_locker); 3292da5c78c8SWilliam Allen Simpson if (!time_after_eq(jiffy, tcp_secret_generating->expires)) { 3293da5c78c8SWilliam Allen Simpson /* refreshed by another */ 3294da5c78c8SWilliam Allen Simpson memcpy(bakery, 3295da5c78c8SWilliam Allen Simpson &tcp_secret_generating->secrets[0], 3296da5c78c8SWilliam Allen Simpson COOKIE_WORKSPACE_WORDS); 3297da5c78c8SWilliam Allen Simpson } else { 3298da5c78c8SWilliam Allen Simpson /* still needs refreshing */ 3299da5c78c8SWilliam Allen Simpson get_random_bytes(bakery, COOKIE_WORKSPACE_WORDS); 3300da5c78c8SWilliam Allen Simpson 3301da5c78c8SWilliam Allen Simpson /* The first time, paranoia assumes that the 3302da5c78c8SWilliam Allen Simpson * randomization function isn't as strong. But, 3303da5c78c8SWilliam Allen Simpson * this secret initialization is delayed until 3304da5c78c8SWilliam Allen Simpson * the last possible moment (packet arrival). 3305da5c78c8SWilliam Allen Simpson * Although that time is observable, it is 3306da5c78c8SWilliam Allen Simpson * unpredictably variable. Mash in the most 3307da5c78c8SWilliam Allen Simpson * volatile clock bits available, and expire the 3308da5c78c8SWilliam Allen Simpson * secret extra quickly. 3309da5c78c8SWilliam Allen Simpson */ 3310da5c78c8SWilliam Allen Simpson if (unlikely(tcp_secret_primary->expires == 3311da5c78c8SWilliam Allen Simpson tcp_secret_secondary->expires)) { 3312da5c78c8SWilliam Allen Simpson struct timespec tv; 3313da5c78c8SWilliam Allen Simpson 3314da5c78c8SWilliam Allen Simpson getnstimeofday(&tv); 3315da5c78c8SWilliam Allen Simpson bakery[COOKIE_DIGEST_WORDS+0] ^= 3316da5c78c8SWilliam Allen Simpson (u32)tv.tv_nsec; 3317da5c78c8SWilliam Allen Simpson 3318da5c78c8SWilliam Allen Simpson tcp_secret_secondary->expires = jiffy 3319da5c78c8SWilliam Allen Simpson + TCP_SECRET_1MSL 3320da5c78c8SWilliam Allen Simpson + (0x0f & tcp_cookie_work(bakery, 0)); 3321da5c78c8SWilliam Allen Simpson } else { 3322da5c78c8SWilliam Allen Simpson tcp_secret_secondary->expires = jiffy 3323da5c78c8SWilliam Allen Simpson + TCP_SECRET_LIFE 3324da5c78c8SWilliam Allen Simpson + (0xff & tcp_cookie_work(bakery, 1)); 3325da5c78c8SWilliam Allen Simpson tcp_secret_primary->expires = jiffy 3326da5c78c8SWilliam Allen Simpson + TCP_SECRET_2MSL 3327da5c78c8SWilliam Allen Simpson + (0x1f & tcp_cookie_work(bakery, 2)); 3328da5c78c8SWilliam Allen Simpson } 3329da5c78c8SWilliam Allen Simpson memcpy(&tcp_secret_secondary->secrets[0], 3330da5c78c8SWilliam Allen Simpson bakery, COOKIE_WORKSPACE_WORDS); 3331da5c78c8SWilliam Allen Simpson 3332da5c78c8SWilliam Allen Simpson rcu_assign_pointer(tcp_secret_generating, 3333da5c78c8SWilliam Allen Simpson tcp_secret_secondary); 3334da5c78c8SWilliam Allen Simpson rcu_assign_pointer(tcp_secret_retiring, 3335da5c78c8SWilliam Allen Simpson tcp_secret_primary); 3336da5c78c8SWilliam Allen Simpson /* 3337da5c78c8SWilliam Allen Simpson * Neither call_rcu() nor synchronize_rcu() needed. 3338da5c78c8SWilliam Allen Simpson * Retiring data is not freed. It is replaced after 3339da5c78c8SWilliam Allen Simpson * further (locked) pointer updates, and a quiet time 3340da5c78c8SWilliam Allen Simpson * (minimum 1MSL, maximum LIFE - 2MSL). 3341da5c78c8SWilliam Allen Simpson */ 3342da5c78c8SWilliam Allen Simpson } 3343da5c78c8SWilliam Allen Simpson spin_unlock_bh(&tcp_secret_locker); 3344da5c78c8SWilliam Allen Simpson } else { 3345da5c78c8SWilliam Allen Simpson rcu_read_lock_bh(); 3346da5c78c8SWilliam Allen Simpson memcpy(bakery, 3347da5c78c8SWilliam Allen Simpson &rcu_dereference(tcp_secret_generating)->secrets[0], 3348da5c78c8SWilliam Allen Simpson COOKIE_WORKSPACE_WORDS); 3349da5c78c8SWilliam Allen Simpson rcu_read_unlock_bh(); 3350da5c78c8SWilliam Allen Simpson } 3351da5c78c8SWilliam Allen Simpson return 0; 3352da5c78c8SWilliam Allen Simpson } 3353da5c78c8SWilliam Allen Simpson EXPORT_SYMBOL(tcp_cookie_generator); 3354da5c78c8SWilliam Allen Simpson 33554ac02babSAndi Kleen void tcp_done(struct sock *sk) 33564ac02babSAndi Kleen { 33574ac02babSAndi Kleen if (sk->sk_state == TCP_SYN_SENT || sk->sk_state == TCP_SYN_RECV) 335863231bddSPavel Emelyanov TCP_INC_STATS_BH(sock_net(sk), TCP_MIB_ATTEMPTFAILS); 33594ac02babSAndi Kleen 33604ac02babSAndi Kleen tcp_set_state(sk, TCP_CLOSE); 33614ac02babSAndi Kleen tcp_clear_xmit_timers(sk); 33624ac02babSAndi Kleen 33634ac02babSAndi Kleen sk->sk_shutdown = SHUTDOWN_MASK; 33644ac02babSAndi Kleen 33654ac02babSAndi Kleen if (!sock_flag(sk, SOCK_DEAD)) 33664ac02babSAndi Kleen sk->sk_state_change(sk); 33674ac02babSAndi Kleen else 33684ac02babSAndi Kleen inet_csk_destroy_sock(sk); 33694ac02babSAndi Kleen } 33704ac02babSAndi Kleen EXPORT_SYMBOL_GPL(tcp_done); 33714ac02babSAndi Kleen 33725f8ef48dSStephen Hemminger extern struct tcp_congestion_ops tcp_reno; 33731da177e4SLinus Torvalds 33741da177e4SLinus Torvalds static __initdata unsigned long thash_entries; 33751da177e4SLinus Torvalds static int __init set_thash_entries(char *str) 33761da177e4SLinus Torvalds { 33771da177e4SLinus Torvalds if (!str) 33781da177e4SLinus Torvalds return 0; 33791da177e4SLinus Torvalds thash_entries = simple_strtoul(str, &str, 0); 33801da177e4SLinus Torvalds return 1; 33811da177e4SLinus Torvalds } 33821da177e4SLinus Torvalds __setup("thash_entries=", set_thash_entries); 33831da177e4SLinus Torvalds 33844acb4190SGlauber Costa void tcp_init_mem(struct net *net) 33854acb4190SGlauber Costa { 33864acb4190SGlauber Costa unsigned long limit = nr_free_buffer_pages() / 8; 33874acb4190SGlauber Costa limit = max(limit, 128UL); 33884acb4190SGlauber Costa net->ipv4.sysctl_tcp_mem[0] = limit / 4 * 3; 33894acb4190SGlauber Costa net->ipv4.sysctl_tcp_mem[1] = limit; 33904acb4190SGlauber Costa net->ipv4.sysctl_tcp_mem[2] = net->ipv4.sysctl_tcp_mem[0] * 2; 33914acb4190SGlauber Costa } 33924acb4190SGlauber Costa 33931da177e4SLinus Torvalds void __init tcp_init(void) 33941da177e4SLinus Torvalds { 33951da177e4SLinus Torvalds struct sk_buff *skb = NULL; 3396f03d78dbSEric Dumazet unsigned long limit; 3397074b8517SDimitri Sivanich int max_share, cnt; 3398074b8517SDimitri Sivanich unsigned int i; 3399da5c78c8SWilliam Allen Simpson unsigned long jiffy = jiffies; 34001da177e4SLinus Torvalds 34011f9e636eSPavel Emelyanov BUILD_BUG_ON(sizeof(struct tcp_skb_cb) > sizeof(skb->cb)); 34021da177e4SLinus Torvalds 34031748376bSEric Dumazet percpu_counter_init(&tcp_sockets_allocated, 0); 3404dd24c001SEric Dumazet percpu_counter_init(&tcp_orphan_count, 0); 34056e04e021SArnaldo Carvalho de Melo tcp_hashinfo.bind_bucket_cachep = 34066e04e021SArnaldo Carvalho de Melo kmem_cache_create("tcp_bind_bucket", 34076e04e021SArnaldo Carvalho de Melo sizeof(struct inet_bind_bucket), 0, 340820c2df83SPaul Mundt SLAB_HWCACHE_ALIGN|SLAB_PANIC, NULL); 34091da177e4SLinus Torvalds 34101da177e4SLinus Torvalds /* Size and allocate the main established and bind bucket 34111da177e4SLinus Torvalds * hash tables. 34121da177e4SLinus Torvalds * 34131da177e4SLinus Torvalds * The methodology is similar to that of the buffer cache. 34141da177e4SLinus Torvalds */ 34156e04e021SArnaldo Carvalho de Melo tcp_hashinfo.ehash = 34161da177e4SLinus Torvalds alloc_large_system_hash("TCP established", 34170f7ff927SArnaldo Carvalho de Melo sizeof(struct inet_ehash_bucket), 34181da177e4SLinus Torvalds thash_entries, 34194481374cSJan Beulich (totalram_pages >= 128 * 1024) ? 342018955cfcSMike Stroyan 13 : 15, 34219e950efaSJohn Heffner 0, 34221da177e4SLinus Torvalds NULL, 3423f373b53bSEric Dumazet &tcp_hashinfo.ehash_mask, 34240ccfe618SJean Delvare thash_entries ? 0 : 512 * 1024); 3425f373b53bSEric Dumazet for (i = 0; i <= tcp_hashinfo.ehash_mask; i++) { 34263ab5aee7SEric Dumazet INIT_HLIST_NULLS_HEAD(&tcp_hashinfo.ehash[i].chain, i); 34273ab5aee7SEric Dumazet INIT_HLIST_NULLS_HEAD(&tcp_hashinfo.ehash[i].twchain, i); 34281da177e4SLinus Torvalds } 3429230140cfSEric Dumazet if (inet_ehash_locks_alloc(&tcp_hashinfo)) 3430230140cfSEric Dumazet panic("TCP: failed to alloc ehash_locks"); 34316e04e021SArnaldo Carvalho de Melo tcp_hashinfo.bhash = 34321da177e4SLinus Torvalds alloc_large_system_hash("TCP bind", 34330f7ff927SArnaldo Carvalho de Melo sizeof(struct inet_bind_hashbucket), 3434f373b53bSEric Dumazet tcp_hashinfo.ehash_mask + 1, 34354481374cSJan Beulich (totalram_pages >= 128 * 1024) ? 343618955cfcSMike Stroyan 13 : 15, 34379e950efaSJohn Heffner 0, 34386e04e021SArnaldo Carvalho de Melo &tcp_hashinfo.bhash_size, 34391da177e4SLinus Torvalds NULL, 34401da177e4SLinus Torvalds 64 * 1024); 3441074b8517SDimitri Sivanich tcp_hashinfo.bhash_size = 1U << tcp_hashinfo.bhash_size; 34426e04e021SArnaldo Carvalho de Melo for (i = 0; i < tcp_hashinfo.bhash_size; i++) { 34436e04e021SArnaldo Carvalho de Melo spin_lock_init(&tcp_hashinfo.bhash[i].lock); 34446e04e021SArnaldo Carvalho de Melo INIT_HLIST_HEAD(&tcp_hashinfo.bhash[i].chain); 34451da177e4SLinus Torvalds } 34461da177e4SLinus Torvalds 3447c5ed63d6SEric Dumazet 3448c5ed63d6SEric Dumazet cnt = tcp_hashinfo.ehash_mask + 1; 3449c5ed63d6SEric Dumazet 3450c5ed63d6SEric Dumazet tcp_death_row.sysctl_max_tw_buckets = cnt / 2; 3451c5ed63d6SEric Dumazet sysctl_tcp_max_orphans = cnt / 2; 3452c5ed63d6SEric Dumazet sysctl_max_syn_backlog = max(128, cnt / 256); 34531da177e4SLinus Torvalds 34544acb4190SGlauber Costa tcp_init_mem(&init_net); 3455c43b874dSJason Wang /* Set per-socket limits to no more than 1/128 the pressure threshold */ 34565fb84b14SEric Dumazet limit = nr_free_buffer_pages() << (PAGE_SHIFT - 7); 34577b4f4b5eSJohn Heffner max_share = min(4UL*1024*1024, limit); 34587b4f4b5eSJohn Heffner 34593ab224beSHideo Aoki sysctl_tcp_wmem[0] = SK_MEM_QUANTUM; 34607b4f4b5eSJohn Heffner sysctl_tcp_wmem[1] = 16*1024; 34617b4f4b5eSJohn Heffner sysctl_tcp_wmem[2] = max(64*1024, max_share); 34627b4f4b5eSJohn Heffner 34633ab224beSHideo Aoki sysctl_tcp_rmem[0] = SK_MEM_QUANTUM; 34647b4f4b5eSJohn Heffner sysctl_tcp_rmem[1] = 87380; 34657b4f4b5eSJohn Heffner sysctl_tcp_rmem[2] = max(87380, max_share); 34661da177e4SLinus Torvalds 3467afd46503SJoe Perches pr_info("Hash tables configured (established %u bind %u)\n", 3468f373b53bSEric Dumazet tcp_hashinfo.ehash_mask + 1, tcp_hashinfo.bhash_size); 3469317a76f9SStephen Hemminger 3470317a76f9SStephen Hemminger tcp_register_congestion_control(&tcp_reno); 3471da5c78c8SWilliam Allen Simpson 3472da5c78c8SWilliam Allen Simpson memset(&tcp_secret_one.secrets[0], 0, sizeof(tcp_secret_one.secrets)); 3473da5c78c8SWilliam Allen Simpson memset(&tcp_secret_two.secrets[0], 0, sizeof(tcp_secret_two.secrets)); 3474da5c78c8SWilliam Allen Simpson tcp_secret_one.expires = jiffy; /* past due */ 3475da5c78c8SWilliam Allen Simpson tcp_secret_two.expires = jiffy; /* past due */ 3476da5c78c8SWilliam Allen Simpson tcp_secret_generating = &tcp_secret_one; 3477da5c78c8SWilliam Allen Simpson tcp_secret_primary = &tcp_secret_one; 3478da5c78c8SWilliam Allen Simpson tcp_secret_retiring = &tcp_secret_two; 3479da5c78c8SWilliam Allen Simpson tcp_secret_secondary = &tcp_secret_two; 34801da177e4SLinus Torvalds } 3481