socket.c 103.0 KB
Newer Older
P
Per Liden 已提交
1
/*
2
 * net/tipc/socket.c: TIPC socket API
3
 *
J
Jon Maloy 已提交
4
 * Copyright (c) 2001-2007, 2012-2017, Ericsson AB
5
 * Copyright (c) 2004-2008, 2010-2013, Wind River Systems
P
Per Liden 已提交
6 7
 * All rights reserved.
 *
P
Per Liden 已提交
8
 * Redistribution and use in source and binary forms, with or without
P
Per Liden 已提交
9 10
 * modification, are permitted provided that the following conditions are met:
 *
P
Per Liden 已提交
11 12 13 14 15 16 17 18
 * 1. Redistributions of source code must retain the above copyright
 *    notice, this list of conditions and the following disclaimer.
 * 2. Redistributions in binary form must reproduce the above copyright
 *    notice, this list of conditions and the following disclaimer in the
 *    documentation and/or other materials provided with the distribution.
 * 3. Neither the names of the copyright holders nor the names of its
 *    contributors may be used to endorse or promote products derived from
 *    this software without specific prior written permission.
P
Per Liden 已提交
19
 *
P
Per Liden 已提交
20 21 22 23 24 25 26 27 28 29 30 31 32 33
 * Alternatively, this software may be distributed under the terms of the
 * GNU General Public License ("GPL") version 2 as published by the Free
 * Software Foundation.
 *
 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
P
Per Liden 已提交
34 35 36
 * POSSIBILITY OF SUCH DAMAGE.
 */

37
#include <linux/rhashtable.h>
38 39
#include <linux/sched/signal.h>

P
Per Liden 已提交
40
#include "core.h"
41
#include "name_table.h"
E
Erik Hugne 已提交
42
#include "node.h"
43
#include "link.h"
44
#include "name_distr.h"
45
#include "socket.h"
46
#include "bcast.h"
47
#include "netlink.h"
J
Jon Maloy 已提交
48
#include "group.h"
T
Tuong Lien 已提交
49
#include "trace.h"
50

51 52
#define NAGLE_START_INIT	4
#define NAGLE_START_MAX		1024
53
#define CONN_TIMEOUT_DEFAULT    8000    /* default connect timeout = 8s */
54
#define CONN_PROBING_INTV	msecs_to_jiffies(3600000)  /* [ms] => 1 h */
55 56 57
#define TIPC_FWD_MSG		1
#define TIPC_MAX_PORT		0xffffffff
#define TIPC_MIN_PORT		1
58
#define TIPC_ACK_RATE		4       /* ACK at 1/4 of of rcv window size */
59

60 61
enum {
	TIPC_LISTEN = TCP_LISTEN,
62
	TIPC_ESTABLISHED = TCP_ESTABLISHED,
63
	TIPC_OPEN = TCP_CLOSE,
64
	TIPC_DISCONNECTING = TCP_CLOSE_WAIT,
65
	TIPC_CONNECTING = TCP_SYN_SENT,
66 67
};

68 69 70 71 72
struct sockaddr_pair {
	struct sockaddr_tipc sock;
	struct sockaddr_tipc member;
};

73 74 75 76 77 78 79
/**
 * struct tipc_sock - TIPC socket structure
 * @sk: socket - interacts with 'port' and with user via the socket API
 * @conn_type: TIPC type used when connection was established
 * @conn_instance: TIPC instance used when connection was established
 * @published: non-zero if port has one or more associated names
 * @max_pkt: maximum packet size "hint" used when building messages sent by port
J
Jon Maloy 已提交
80
 * @maxnagle: maximum size of msg which can be subject to nagle
81
 * @portid: unique port identity in TIPC socket hash table
82
 * @phdr: preformatted message header used when sending messages
83
 * #cong_links: list of congested links
84
 * @publications: list of publications for port
85
 * @blocking_link: address of the congested link we are currently sleeping on
86 87 88
 * @pub_count: total # of publications port has made during its lifetime
 * @conn_timeout: the time we can wait for an unresponded setup request
 * @dupl_rcvcnt: number of bytes counted twice, in both backlog and rcv queue
89
 * @cong_link_cnt: number of congested links
J
Jon Maloy 已提交
90
 * @snt_unacked: # messages sent by socket, and not yet acked by peer
91
 * @rcv_unacked: # messages read by user, but not yet acked back to peer
92
 * @peer: 'connected' peer for dgram/rdm
93
 * @node: hash table node
94
 * @mc_method: cookie for use between socket and broadcast layer
95
 * @rcu: rcu struct for tipc_sock
96 97 98 99 100 101 102
 */
struct tipc_sock {
	struct sock sk;
	u32 conn_type;
	u32 conn_instance;
	int published;
	u32 max_pkt;
J
Jon Maloy 已提交
103
	u32 maxnagle;
104
	u32 portid;
105
	struct tipc_msg phdr;
106
	struct list_head cong_links;
107 108 109
	struct list_head publications;
	u32 pub_count;
	atomic_t dupl_rcvcnt;
110
	u16 conn_timeout;
111
	bool probe_unacked;
112
	u16 cong_link_cnt;
113 114
	u16 snt_unacked;
	u16 snd_win;
115
	u16 peer_caps;
116 117
	u16 rcv_unacked;
	u16 rcv_win;
118
	struct sockaddr_tipc peer;
119
	struct rhash_head node;
120
	struct tipc_mc_method mc_method;
121
	struct rcu_head rcu;
J
Jon Maloy 已提交
122
	struct tipc_group *group;
J
Jon Maloy 已提交
123
	u32 oneway;
124
	u32 nagle_start;
J
Jon Maloy 已提交
125
	u16 snd_backlog;
126 127
	u16 msg_acc;
	u16 pkt_cnt;
J
Jon Maloy 已提交
128 129
	bool expect_ack;
	bool nodelay;
130
	bool group_is_open;
131
};
P
Per Liden 已提交
132

J
Jon Maloy 已提交
133
static int tipc_sk_backlog_rcv(struct sock *sk, struct sk_buff *skb);
134
static void tipc_data_ready(struct sock *sk);
135
static void tipc_write_space(struct sock *sk);
136
static void tipc_sock_destruct(struct sock *sk);
137
static int tipc_release(struct socket *sock);
138 139
static int tipc_accept(struct socket *sock, struct socket *new_sock, int flags,
		       bool kern);
140
static void tipc_sk_timeout(struct timer_list *t);
141
static int tipc_sk_publish(struct tipc_sock *tsk, uint scope,
J
Jon Paul Maloy 已提交
142
			   struct tipc_name_seq const *seq);
143
static int tipc_sk_withdraw(struct tipc_sock *tsk, uint scope,
J
Jon Paul Maloy 已提交
144
			    struct tipc_name_seq const *seq);
J
Jon Maloy 已提交
145
static int tipc_sk_leave(struct tipc_sock *tsk);
146
static struct tipc_sock *tipc_sk_lookup(struct net *net, u32 portid);
147 148
static int tipc_sk_insert(struct tipc_sock *tsk);
static void tipc_sk_remove(struct tipc_sock *tsk);
149
static int __tipc_sendstream(struct socket *sock, struct msghdr *m, size_t dsz);
150
static int __tipc_sendmsg(struct socket *sock, struct msghdr *m, size_t dsz);
151
static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack);
P
Per Liden 已提交
152

153 154 155
static const struct proto_ops packet_ops;
static const struct proto_ops stream_ops;
static const struct proto_ops msg_ops;
P
Per Liden 已提交
156
static struct proto tipc_proto;
157 158
static const struct rhashtable_params tsk_rht_params;

159 160 161 162 163
static u32 tsk_own_node(struct tipc_sock *tsk)
{
	return msg_prevnode(&tsk->phdr);
}

164
static u32 tsk_peer_node(struct tipc_sock *tsk)
165
{
166
	return msg_destnode(&tsk->phdr);
167 168
}

169
static u32 tsk_peer_port(struct tipc_sock *tsk)
170
{
171
	return msg_destport(&tsk->phdr);
172 173
}

174
static  bool tsk_unreliable(struct tipc_sock *tsk)
175
{
176
	return msg_src_droppable(&tsk->phdr) != 0;
177 178
}

179
static void tsk_set_unreliable(struct tipc_sock *tsk, bool unreliable)
180
{
181
	msg_set_src_droppable(&tsk->phdr, unreliable ? 1 : 0);
182 183
}

184
static bool tsk_unreturnable(struct tipc_sock *tsk)
185
{
186
	return msg_dest_droppable(&tsk->phdr) != 0;
187 188
}

189
static void tsk_set_unreturnable(struct tipc_sock *tsk, bool unreturnable)
190
{
191
	msg_set_dest_droppable(&tsk->phdr, unreturnable ? 1 : 0);
192 193
}

194
static int tsk_importance(struct tipc_sock *tsk)
195
{
196
	return msg_importance(&tsk->phdr);
197 198
}

199
static struct tipc_sock *tipc_sk(const struct sock *sk)
200
{
201
	return container_of(sk, struct tipc_sock, sk);
202
}
203

204
int tsk_set_importance(struct sock *sk, int imp)
205
{
206 207 208 209
	if (imp > TIPC_CRITICAL_IMPORTANCE)
		return -EINVAL;
	msg_set_importance(&tipc_sk(sk)->phdr, (u32)imp);
	return 0;
210 211
}

212
static bool tsk_conn_cong(struct tipc_sock *tsk)
213
{
214
	return tsk->snt_unacked > tsk->snd_win;
215 216
}

217 218 219 220 221
static u16 tsk_blocks(int len)
{
	return ((len / FLOWCTL_BLK_SZ) + 1);
}

222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239
/* tsk_blocks(): translate a buffer size in bytes to number of
 * advertisable blocks, taking into account the ratio truesize(len)/len
 * We can trust that this ratio is always < 4 for len >= FLOWCTL_BLK_SZ
 */
static u16 tsk_adv_blocks(int len)
{
	return len / FLOWCTL_BLK_SZ / 4;
}

/* tsk_inc(): increment counter for sent or received data
 * - If block based flow control is not supported by peer we
 *   fall back to message based ditto, incrementing the counter
 */
static u16 tsk_inc(struct tipc_sock *tsk, int msglen)
{
	if (likely(tsk->peer_caps & TIPC_BLOCK_FLOWCTL))
		return ((msglen / FLOWCTL_BLK_SZ) + 1);
	return 1;
240 241
}

J
Jon Maloy 已提交
242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261
/* tsk_set_nagle - enable/disable nagle property by manipulating maxnagle
 */
static void tsk_set_nagle(struct tipc_sock *tsk)
{
	struct sock *sk = &tsk->sk;

	tsk->maxnagle = 0;
	if (sk->sk_type != SOCK_STREAM)
		return;
	if (tsk->nodelay)
		return;
	if (!(tsk->peer_caps & TIPC_NAGLE))
		return;
	/* Limit node local buffer size to avoid receive queue overflow */
	if (tsk->max_pkt == MAX_MSG_SIZE)
		tsk->maxnagle = 1500;
	else
		tsk->maxnagle = tsk->max_pkt;
}

262
/**
263
 * tsk_advance_rx_queue - discard first buffer in socket receive queue
264 265
 *
 * Caller must hold socket lock
P
Per Liden 已提交
266
 */
267
static void tsk_advance_rx_queue(struct sock *sk)
P
Per Liden 已提交
268
{
269
	trace_tipc_sk_advance_rx(sk, NULL, TIPC_DUMP_SK_RCVQ, " ");
270
	kfree_skb(__skb_dequeue(&sk->sk_receive_queue));
P
Per Liden 已提交
271 272
}

273 274 275 276 277 278 279 280 281 282 283
/* tipc_sk_respond() : send response message back to sender
 */
static void tipc_sk_respond(struct sock *sk, struct sk_buff *skb, int err)
{
	u32 selector;
	u32 dnode;
	u32 onode = tipc_own_addr(sock_net(sk));

	if (!tipc_msg_reverse(onode, &skb, err))
		return;

284
	trace_tipc_sk_rej_msg(sk, skb, TIPC_DUMP_NONE, "@sk_respond!");
285 286 287 288 289
	dnode = msg_destnode(buf_msg(skb));
	selector = msg_origport(buf_msg(skb));
	tipc_node_xmit_skb(sock_net(sk), skb, dnode, selector);
}

P
Per Liden 已提交
290
/**
291
 * tsk_rej_rx_queue - reject all buffers in socket receive queue
292 293
 *
 * Caller must hold socket lock
P
Per Liden 已提交
294
 */
295
static void tsk_rej_rx_queue(struct sock *sk, int error)
P
Per Liden 已提交
296
{
297
	struct sk_buff *skb;
298

299
	while ((skb = __skb_dequeue(&sk->sk_receive_queue)))
300
		tipc_sk_respond(sk, skb, error);
P
Per Liden 已提交
301 302
}

303 304
static bool tipc_sk_connected(struct sock *sk)
{
305
	return sk->sk_state == TIPC_ESTABLISHED;
306 307
}

308 309 310 311 312 313 314 315 316 317
/* tipc_sk_type_connectionless - check if the socket is datagram socket
 * @sk: socket
 *
 * Returns true if connection less, false otherwise
 */
static bool tipc_sk_type_connectionless(struct sock *sk)
{
	return sk->sk_type == SOCK_RDM || sk->sk_type == SOCK_DGRAM;
}

318
/* tsk_peer_msg - verify if message was sent by connected port's peer
J
Jon Paul Maloy 已提交
319 320 321 322
 *
 * Handles cases where the node's network address has changed from
 * the default of <0.0.0> to its configured setting.
 */
323
static bool tsk_peer_msg(struct tipc_sock *tsk, struct tipc_msg *msg)
J
Jon Paul Maloy 已提交
324
{
325
	struct sock *sk = &tsk->sk;
326
	u32 self = tipc_own_addr(sock_net(sk));
327
	u32 peer_port = tsk_peer_port(tsk);
328
	u32 orig_node, peer_node;
J
Jon Paul Maloy 已提交
329

330
	if (unlikely(!tipc_sk_connected(sk)))
J
Jon Paul Maloy 已提交
331 332 333 334 335 336
		return false;

	if (unlikely(msg_origport(msg) != peer_port))
		return false;

	orig_node = msg_orignode(msg);
337
	peer_node = tsk_peer_node(tsk);
J
Jon Paul Maloy 已提交
338 339 340 341

	if (likely(orig_node == peer_node))
		return true;

342
	if (!orig_node && peer_node == self)
J
Jon Paul Maloy 已提交
343 344
		return true;

345
	if (!peer_node && orig_node == self)
J
Jon Paul Maloy 已提交
346 347 348 349 350
		return true;

	return false;
}

351 352 353 354 355 356 357 358 359
/* tipc_set_sk_state - set the sk_state of the socket
 * @sk: socket
 *
 * Caller must hold socket lock
 *
 * Returns 0 on success, errno otherwise
 */
static int tipc_set_sk_state(struct sock *sk, int state)
{
360
	int oldsk_state = sk->sk_state;
361 362 363
	int res = -EINVAL;

	switch (state) {
364 365 366
	case TIPC_OPEN:
		res = 0;
		break;
367
	case TIPC_LISTEN:
368
	case TIPC_CONNECTING:
369
		if (oldsk_state == TIPC_OPEN)
370 371
			res = 0;
		break;
372
	case TIPC_ESTABLISHED:
373
		if (oldsk_state == TIPC_CONNECTING ||
374
		    oldsk_state == TIPC_OPEN)
375 376
			res = 0;
		break;
377
	case TIPC_DISCONNECTING:
378
		if (oldsk_state == TIPC_CONNECTING ||
379 380 381
		    oldsk_state == TIPC_ESTABLISHED)
			res = 0;
		break;
382 383 384 385 386 387 388 389
	}

	if (!res)
		sk->sk_state = state;

	return res;
}

390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411
static int tipc_sk_sock_err(struct socket *sock, long *timeout)
{
	struct sock *sk = sock->sk;
	int err = sock_error(sk);
	int typ = sock->type;

	if (err)
		return err;
	if (typ == SOCK_STREAM || typ == SOCK_SEQPACKET) {
		if (sk->sk_state == TIPC_DISCONNECTING)
			return -EPIPE;
		else if (!tipc_sk_connected(sk))
			return -ENOTCONN;
	}
	if (!*timeout)
		return -EAGAIN;
	if (signal_pending(current))
		return sock_intr_errno(*timeout);

	return 0;
}

412 413
#define tipc_wait_for_cond(sock_, timeo_, condition_)			       \
({                                                                             \
414
	DEFINE_WAIT_FUNC(wait_, woken_wake_function);                          \
415 416 417 418
	struct sock *sk_;						       \
	int rc_;							       \
									       \
	while ((rc_ = !(condition_))) {					       \
419 420
		/* coupled with smp_wmb() in tipc_sk_proto_rcv() */            \
		smp_rmb();                                                     \
421 422 423 424
		sk_ = (sock_)->sk;					       \
		rc_ = tipc_sk_sock_err((sock_), timeo_);		       \
		if (rc_)						       \
			break;						       \
425
		add_wait_queue(sk_sleep(sk_), &wait_);                         \
426 427 428 429 430 431 432
		release_sock(sk_);					       \
		*(timeo_) = wait_woken(&wait_, TASK_INTERRUPTIBLE, *(timeo_)); \
		sched_annotate_sleep();				               \
		lock_sock(sk_);						       \
		remove_wait_queue(sk_sleep(sk_), &wait_);		       \
	}								       \
	rc_;								       \
433 434
})

P
Per Liden 已提交
435
/**
436
 * tipc_sk_create - create a TIPC socket
437
 * @net: network namespace (must be default network)
P
Per Liden 已提交
438 439
 * @sock: pre-allocated socket structure
 * @protocol: protocol indicator (must be 0)
440
 * @kern: caused by kernel or by userspace?
441
 *
442 443
 * This routine creates additional data structures used by the TIPC socket,
 * initializes them, and links them together.
P
Per Liden 已提交
444 445 446
 *
 * Returns 0 on success, errno otherwise
 */
447 448
static int tipc_sk_create(struct net *net, struct socket *sock,
			  int protocol, int kern)
P
Per Liden 已提交
449
{
450
	const struct proto_ops *ops;
P
Per Liden 已提交
451
	struct sock *sk;
452
	struct tipc_sock *tsk;
453
	struct tipc_msg *msg;
454 455

	/* Validate arguments */
P
Per Liden 已提交
456 457 458 459 460
	if (unlikely(protocol != 0))
		return -EPROTONOSUPPORT;

	switch (sock->type) {
	case SOCK_STREAM:
461
		ops = &stream_ops;
P
Per Liden 已提交
462 463
		break;
	case SOCK_SEQPACKET:
464
		ops = &packet_ops;
P
Per Liden 已提交
465 466 467
		break;
	case SOCK_DGRAM:
	case SOCK_RDM:
468
		ops = &msg_ops;
P
Per Liden 已提交
469
		break;
470 471
	default:
		return -EPROTOTYPE;
P
Per Liden 已提交
472 473
	}

474
	/* Allocate socket's protocol area */
475
	sk = sk_alloc(net, AF_TIPC, GFP_KERNEL, &tipc_proto, kern);
476
	if (sk == NULL)
P
Per Liden 已提交
477 478
		return -ENOMEM;

479
	tsk = tipc_sk(sk);
480
	tsk->max_pkt = MAX_PKT_DEFAULT;
J
Jon Maloy 已提交
481
	tsk->maxnagle = 0;
482
	tsk->nagle_start = NAGLE_START_INIT;
483
	INIT_LIST_HEAD(&tsk->publications);
484
	INIT_LIST_HEAD(&tsk->cong_links);
485
	msg = &tsk->phdr;
P
Per Liden 已提交
486

487 488 489
	/* Finish initializing socket data structures */
	sock->ops = ops;
	sock_init_data(sock, sk);
490
	tipc_set_sk_state(sk, TIPC_OPEN);
491
	if (tipc_sk_insert(tsk)) {
M
Masanari Iida 已提交
492
		pr_warn("Socket create failed; port number exhausted\n");
493 494
		return -EINVAL;
	}
495 496 497 498

	/* Ensure tsk is visible before we read own_addr. */
	smp_mb();

499 500
	tipc_msg_init(tipc_own_addr(net), msg, TIPC_LOW_IMPORTANCE,
		      TIPC_NAMED_MSG, NAMED_H_SIZE, 0);
501

502
	msg_set_origport(msg, tsk->portid);
503
	timer_setup(&sk->sk_timer, tipc_sk_timeout, 0);
504
	sk->sk_shutdown = 0;
J
Jon Maloy 已提交
505
	sk->sk_backlog_rcv = tipc_sk_backlog_rcv;
506
	sk->sk_rcvbuf = sysctl_tipc_rmem[1];
507 508
	sk->sk_data_ready = tipc_data_ready;
	sk->sk_write_space = tipc_write_space;
509
	sk->sk_destruct = tipc_sock_destruct;
510
	tsk->conn_timeout = CONN_TIMEOUT_DEFAULT;
511
	tsk->group_is_open = true;
512
	atomic_set(&tsk->dupl_rcvcnt, 0);
513

514 515 516 517
	/* Start out with safe limits until we receive an advertised window */
	tsk->snd_win = tsk_adv_blocks(RCVBUF_MIN);
	tsk->rcv_win = tsk->snd_win;

518
	if (tipc_sk_type_connectionless(sk)) {
519
		tsk_set_unreturnable(tsk, true);
520
		if (sock->type == SOCK_DGRAM)
521
			tsk_set_unreliable(tsk, true);
522
	}
J
Jon Maloy 已提交
523
	__skb_queue_head_init(&tsk->mc_method.deferredq);
524
	trace_tipc_sk_create(sk, NULL, TIPC_DUMP_NONE, " ");
P
Per Liden 已提交
525 526 527
	return 0;
}

528 529 530 531 532 533 534
static void tipc_sk_callback(struct rcu_head *head)
{
	struct tipc_sock *tsk = container_of(head, struct tipc_sock, rcu);

	sock_put(&tsk->sk);
}

535 536 537 538 539 540
/* Caller should hold socket lock for the socket. */
static void __tipc_shutdown(struct socket *sock, int error)
{
	struct sock *sk = sock->sk;
	struct tipc_sock *tsk = tipc_sk(sk);
	struct net *net = sock_net(sk);
541
	long timeout = msecs_to_jiffies(CONN_TIMEOUT_DEFAULT);
542 543 544
	u32 dnode = tsk_peer_node(tsk);
	struct sk_buff *skb;

545 546 547 548
	/* Avoid that hi-prio shutdown msgs bypass msgs in link wakeup queue */
	tipc_wait_for_cond(sock, &timeout, (!tsk->cong_link_cnt &&
					    !tsk_conn_cong(tsk)));

549
	/* Push out delayed messages if in Nagle mode */
550
	tipc_sk_push_backlog(tsk, false);
551 552
	/* Remove pending SYN */
	__skb_queue_purge(&sk->sk_write_queue);
553

554 555 556 557 558
	/* Remove partially received buffer if any */
	skb = skb_peek(&sk->sk_receive_queue);
	if (skb && TIPC_SKB_CB(skb)->bytes_read) {
		__skb_unlink(skb, &sk->sk_receive_queue);
		kfree_skb(skb);
559
	}
560

561 562 563
	/* Reject all unreceived messages if connectionless */
	if (tipc_sk_type_connectionless(sk)) {
		tsk_rej_rx_queue(sk, error);
564
		return;
565
	}
566

567 568 569 570 571 572 573 574 575 576 577 578
	switch (sk->sk_state) {
	case TIPC_CONNECTING:
	case TIPC_ESTABLISHED:
		tipc_set_sk_state(sk, TIPC_DISCONNECTING);
		tipc_node_remove_conn(net, dnode, tsk->portid);
		/* Send a FIN+/- to its peer */
		skb = __skb_dequeue(&sk->sk_receive_queue);
		if (skb) {
			__skb_queue_purge(&sk->sk_receive_queue);
			tipc_sk_respond(sk, skb, error);
			break;
		}
579 580 581 582 583 584
		skb = tipc_msg_create(TIPC_CRITICAL_IMPORTANCE,
				      TIPC_CONN_MSG, SHORT_H_SIZE, 0, dnode,
				      tsk_own_node(tsk), tsk_peer_port(tsk),
				      tsk->portid, error);
		if (skb)
			tipc_node_xmit_skb(net, skb, dnode, tsk->portid);
585 586 587 588 589 590 591 592
		break;
	case TIPC_LISTEN:
		/* Reject all SYN messages */
		tsk_rej_rx_queue(sk, error);
		break;
	default:
		__skb_queue_purge(&sk->sk_receive_queue);
		break;
593 594 595
	}
}

P
Per Liden 已提交
596
/**
597
 * tipc_release - destroy a TIPC socket
P
Per Liden 已提交
598 599 600 601 602 603 604
 * @sock: socket to destroy
 *
 * This routine cleans up any messages that are still queued on the socket.
 * For DGRAM and RDM socket types, all queued messages are rejected.
 * For SEQPACKET and STREAM socket types, the first message is rejected
 * and any others are discarded.  (If the first message on a STREAM socket
 * is partially-read, it is discarded and the next one is rejected instead.)
605
 *
P
Per Liden 已提交
606 607 608 609 610 611
 * NOTE: Rejected messages are not necessarily returned to the sender!  They
 * are returned or discarded according to the "destination droppable" setting
 * specified for the message by the sender.
 *
 * Returns 0 on success, errno otherwise
 */
612
static int tipc_release(struct socket *sock)
P
Per Liden 已提交
613 614
{
	struct sock *sk = sock->sk;
615
	struct tipc_sock *tsk;
P
Per Liden 已提交
616

617 618 619 620 621
	/*
	 * Exit if socket isn't fully initialized (occurs when a failed accept()
	 * releases a pre-allocated child socket that was never used)
	 */
	if (sk == NULL)
P
Per Liden 已提交
622
		return 0;
623

624
	tsk = tipc_sk(sk);
625 626
	lock_sock(sk);

627
	trace_tipc_sk_release(sk, NULL, TIPC_DUMP_ALL, " ");
628 629
	__tipc_shutdown(sock, TIPC_ERR_NO_PORT);
	sk->sk_shutdown = SHUTDOWN_MASK;
J
Jon Maloy 已提交
630
	tipc_sk_leave(tsk);
631
	tipc_sk_withdraw(tsk, 0, NULL);
632
	__skb_queue_purge(&tsk->mc_method.deferredq);
633
	sk_stop_timer(sk, &sk->sk_timer);
634
	tipc_sk_remove(tsk);
P
Per Liden 已提交
635

C
Cong Wang 已提交
636
	sock_orphan(sk);
637 638
	/* Reject any messages that accumulated in backlog queue */
	release_sock(sk);
J
Jon Maloy 已提交
639
	tipc_dest_list_purge(&tsk->cong_links);
640
	tsk->cong_link_cnt = 0;
641
	call_rcu(&tsk->rcu, tipc_sk_callback);
642
	sock->sk = NULL;
P
Per Liden 已提交
643

644
	return 0;
P
Per Liden 已提交
645 646 647
}

/**
648
 * tipc_bind - associate or disassocate TIPC name(s) with a socket
P
Per Liden 已提交
649 650 651
 * @sock: socket structure
 * @uaddr: socket address describing name(s) and desired operation
 * @uaddr_len: size of socket address data structure
652
 *
P
Per Liden 已提交
653 654 655
 * Name and name sequence binding is indicated using a positive scope value;
 * a negative scope value unbinds the specified name.  Specifying no name
 * (i.e. a socket address length of 0) unbinds all names from the socket.
656
 *
P
Per Liden 已提交
657
 * Returns 0 on success, errno otherwise
658 659 660
 *
 * NOTE: This routine doesn't need to take the socket lock since it doesn't
 *       access any non-constant socket information.
P
Per Liden 已提交
661
 */
662 663
static int tipc_bind(struct socket *sock, struct sockaddr *uaddr,
		     int uaddr_len)
P
Per Liden 已提交
664
{
665
	struct sock *sk = sock->sk;
P
Per Liden 已提交
666
	struct sockaddr_tipc *addr = (struct sockaddr_tipc *)uaddr;
667
	struct tipc_sock *tsk = tipc_sk(sk);
668
	int res = -EINVAL;
P
Per Liden 已提交
669

670 671
	lock_sock(sk);
	if (unlikely(!uaddr_len)) {
672
		res = tipc_sk_withdraw(tsk, 0, NULL);
673 674
		goto exit;
	}
J
Jon Maloy 已提交
675 676 677 678
	if (tsk->group) {
		res = -EACCES;
		goto exit;
	}
679 680 681 682 683 684 685 686
	if (uaddr_len < sizeof(struct sockaddr_tipc)) {
		res = -EINVAL;
		goto exit;
	}
	if (addr->family != AF_TIPC) {
		res = -EAFNOSUPPORT;
		goto exit;
	}
P
Per Liden 已提交
687 688 689

	if (addr->addrtype == TIPC_ADDR_NAME)
		addr->addr.nameseq.upper = addr->addr.nameseq.lower;
690 691 692 693
	else if (addr->addrtype != TIPC_ADDR_NAMESEQ) {
		res = -EAFNOSUPPORT;
		goto exit;
	}
694

695
	if ((addr->addr.nameseq.type < TIPC_RESERVED_TYPES) &&
696
	    (addr->addr.nameseq.type != TIPC_TOP_SRV) &&
697 698 699 700
	    (addr->addr.nameseq.type != TIPC_CFG_SRV)) {
		res = -EACCES;
		goto exit;
	}
701

J
Jon Maloy 已提交
702
	res = (addr->scope >= 0) ?
703 704
		tipc_sk_publish(tsk, addr->scope, &addr->addr.nameseq) :
		tipc_sk_withdraw(tsk, -addr->scope, &addr->addr.nameseq);
705 706 707
exit:
	release_sock(sk);
	return res;
P
Per Liden 已提交
708 709
}

710
/**
711
 * tipc_getname - get port ID of socket or peer socket
P
Per Liden 已提交
712 713 714
 * @sock: socket structure
 * @uaddr: area for returned socket address
 * @uaddr_len: area for returned length of socket address
715
 * @peer: 0 = own ID, 1 = current peer ID, 2 = current/former peer ID
716
 *
P
Per Liden 已提交
717
 * Returns 0 on success, errno otherwise
718
 *
719 720
 * NOTE: This routine doesn't need to take the socket lock since it only
 *       accesses socket information that is unchanging (or which changes in
721
 *       a completely predictable manner).
P
Per Liden 已提交
722
 */
723
static int tipc_getname(struct socket *sock, struct sockaddr *uaddr,
724
			int peer)
P
Per Liden 已提交
725 726
{
	struct sockaddr_tipc *addr = (struct sockaddr_tipc *)uaddr;
727 728
	struct sock *sk = sock->sk;
	struct tipc_sock *tsk = tipc_sk(sk);
P
Per Liden 已提交
729

730
	memset(addr, 0, sizeof(*addr));
731
	if (peer) {
732
		if ((!tipc_sk_connected(sk)) &&
733
		    ((peer != 2) || (sk->sk_state != TIPC_DISCONNECTING)))
734
			return -ENOTCONN;
735 736
		addr->addr.id.ref = tsk_peer_port(tsk);
		addr->addr.id.node = tsk_peer_node(tsk);
737
	} else {
738
		addr->addr.id.ref = tsk->portid;
739
		addr->addr.id.node = tipc_own_addr(sock_net(sk));
740
	}
P
Per Liden 已提交
741 742 743 744 745 746

	addr->addrtype = TIPC_ADDR_ID;
	addr->family = AF_TIPC;
	addr->scope = 0;
	addr->addr.name.domain = 0;

747
	return sizeof(*addr);
P
Per Liden 已提交
748 749 750
}

/**
751
 * tipc_poll - read and possibly block on pollmask
P
Per Liden 已提交
752 753
 * @file: file structure associated with the socket
 * @sock: socket for which to calculate the poll bits
754
 * @wait: ???
P
Per Liden 已提交
755
 *
756 757 758 759 760 761 762 763
 * Returns pollmask value
 *
 * COMMENTARY:
 * It appears that the usual socket locking mechanisms are not useful here
 * since the pollmask info is potentially out-of-date the moment this routine
 * exits.  TCP and other protocols seem to rely on higher level poll routines
 * to handle any preventable race conditions, so TIPC will do the same ...
 *
764 765 766
 * IMPORTANT: The fact that a read or write operation is indicated does NOT
 * imply that the operation will succeed, merely that it should be performed
 * and will not block.
P
Per Liden 已提交
767
 */
768 769
static __poll_t tipc_poll(struct file *file, struct socket *sock,
			      poll_table *wait)
P
Per Liden 已提交
770
{
771
	struct sock *sk = sock->sk;
772
	struct tipc_sock *tsk = tipc_sk(sk);
A
Al Viro 已提交
773
	__poll_t revents = 0;
774

775
	sock_poll_wait(file, sock, wait);
776
	trace_tipc_sk_poll(sk, NULL, TIPC_DUMP_ALL, " ");
777

778
	if (sk->sk_shutdown & RCV_SHUTDOWN)
779
		revents |= EPOLLRDHUP | EPOLLIN | EPOLLRDNORM;
780
	if (sk->sk_shutdown == SHUTDOWN_MASK)
781
		revents |= EPOLLHUP;
782

783 784
	switch (sk->sk_state) {
	case TIPC_ESTABLISHED:
785
		if (!tsk->cong_link_cnt && !tsk_conn_cong(tsk))
786
			revents |= EPOLLOUT;
787
		/* fall through */
788
	case TIPC_LISTEN:
789
	case TIPC_CONNECTING:
790
		if (!skb_queue_empty_lockless(&sk->sk_receive_queue))
791
			revents |= EPOLLIN | EPOLLRDNORM;
792 793
		break;
	case TIPC_OPEN:
794
		if (tsk->group_is_open && !tsk->cong_link_cnt)
795
			revents |= EPOLLOUT;
796 797
		if (!tipc_sk_type_connectionless(sk))
			break;
798
		if (skb_queue_empty_lockless(&sk->sk_receive_queue))
799
			break;
800
		revents |= EPOLLIN | EPOLLRDNORM;
801 802
		break;
	case TIPC_DISCONNECTING:
803
		revents = EPOLLIN | EPOLLRDNORM | EPOLLHUP;
804
		break;
805
	}
806
	return revents;
P
Per Liden 已提交
807 808
}

809 810 811 812
/**
 * tipc_sendmcast - send multicast message
 * @sock: socket structure
 * @seq: destination address
813
 * @msg: message to send
814 815
 * @dlen: length of data to send
 * @timeout: timeout to wait for wakeup
816 817 818 819 820
 *
 * Called from function tipc_sendmsg(), which has done all sanity checks
 * Returns the number of bytes sent on success, or errno
 */
static int tipc_sendmcast(struct  socket *sock, struct tipc_name_seq *seq,
821
			  struct msghdr *msg, size_t dlen, long timeout)
822 823
{
	struct sock *sk = sock->sk;
824
	struct tipc_sock *tsk = tipc_sk(sk);
825
	struct tipc_msg *hdr = &tsk->phdr;
826
	struct net *net = sock_net(sk);
827
	int mtu = tipc_bcast_get_mtu(net);
828
	struct tipc_mc_method *method = &tsk->mc_method;
829
	struct sk_buff_head pkts;
830
	struct tipc_nlist dsts;
831 832
	int rc;

J
Jon Maloy 已提交
833 834 835
	if (tsk->group)
		return -EACCES;

836
	/* Block or return if any destination link is congested */
837 838 839
	rc = tipc_wait_for_cond(sock, &timeout, !tsk->cong_link_cnt);
	if (unlikely(rc))
		return rc;
840

841 842 843
	/* Lookup destination nodes */
	tipc_nlist_init(&dsts, tipc_own_addr(net));
	tipc_nametbl_lookup_dst_nodes(net, seq->type, seq->lower,
844
				      seq->upper, &dsts);
845 846 847 848
	if (!dsts.local && !dsts.remote)
		return -EHOSTUNREACH;

	/* Build message header */
849
	msg_set_type(hdr, TIPC_MCAST_MSG);
850
	msg_set_hdr_sz(hdr, MCAST_H_SIZE);
851 852 853 854 855 856 857
	msg_set_lookup_scope(hdr, TIPC_CLUSTER_SCOPE);
	msg_set_destport(hdr, 0);
	msg_set_destnode(hdr, 0);
	msg_set_nametype(hdr, seq->type);
	msg_set_namelower(hdr, seq->lower);
	msg_set_nameupper(hdr, seq->upper);

858
	/* Build message as chain of buffers */
859
	__skb_queue_head_init(&pkts);
860
	rc = tipc_msg_build(hdr, msg, 0, dlen, mtu, &pkts);
861

862
	/* Send message if build was successful */
863 864 865
	if (unlikely(rc == dlen)) {
		trace_tipc_sk_sendmcast(sk, skb_peek(&pkts),
					TIPC_DUMP_SK_SNDQ, " ");
866
		rc = tipc_mcast_xmit(net, &pkts, method, &dsts,
867
				     &tsk->cong_link_cnt);
868
	}
869 870

	tipc_nlist_purge(&dsts);
871 872

	return rc ? rc : dlen;
873 874
}

875 876 877 878 879 880 881 882 883 884 885 886 887
/**
 * tipc_send_group_msg - send a message to a member in the group
 * @net: network namespace
 * @m: message to send
 * @mb: group member
 * @dnode: destination node
 * @dport: destination port
 * @dlen: total length of message data
 */
static int tipc_send_group_msg(struct net *net, struct tipc_sock *tsk,
			       struct msghdr *m, struct tipc_member *mb,
			       u32 dnode, u32 dport, int dlen)
{
888
	u16 bc_snd_nxt = tipc_group_bc_snd_nxt(tsk->group);
889
	struct tipc_mc_method *method = &tsk->mc_method;
890 891 892 893 894 895 896 897 898 899
	int blks = tsk_blocks(GROUP_H_SIZE + dlen);
	struct tipc_msg *hdr = &tsk->phdr;
	struct sk_buff_head pkts;
	int mtu, rc;

	/* Complete message header */
	msg_set_type(hdr, TIPC_GRP_UCAST_MSG);
	msg_set_hdr_sz(hdr, GROUP_H_SIZE);
	msg_set_destport(hdr, dport);
	msg_set_destnode(hdr, dnode);
900
	msg_set_grp_bc_seqno(hdr, bc_snd_nxt);
901 902

	/* Build message as chain of buffers */
903
	__skb_queue_head_init(&pkts);
904
	mtu = tipc_node_get_mtu(net, dnode, tsk->portid, false);
905 906 907 908 909 910 911 912 913 914 915
	rc = tipc_msg_build(hdr, m, 0, dlen, mtu, &pkts);
	if (unlikely(rc != dlen))
		return rc;

	/* Send message */
	rc = tipc_node_xmit(net, &pkts, dnode, tsk->portid);
	if (unlikely(rc == -ELINKCONG)) {
		tipc_dest_push(&tsk->cong_links, dnode, 0);
		tsk->cong_link_cnt++;
	}

916
	/* Update send window */
917 918
	tipc_group_update_member(mb, blks);

919 920 921
	/* A broadcast sent within next EXPIRE period must follow same path */
	method->rcast = true;
	method->mandatory = true;
922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954
	return dlen;
}

/**
 * tipc_send_group_unicast - send message to a member in the group
 * @sock: socket structure
 * @m: message to send
 * @dlen: total length of message data
 * @timeout: timeout to wait for wakeup
 *
 * Called from function tipc_sendmsg(), which has done all sanity checks
 * Returns the number of bytes sent on success, or errno
 */
static int tipc_send_group_unicast(struct socket *sock, struct msghdr *m,
				   int dlen, long timeout)
{
	struct sock *sk = sock->sk;
	DECLARE_SOCKADDR(struct sockaddr_tipc *, dest, m->msg_name);
	int blks = tsk_blocks(GROUP_H_SIZE + dlen);
	struct tipc_sock *tsk = tipc_sk(sk);
	struct net *net = sock_net(sk);
	struct tipc_member *mb = NULL;
	u32 node, port;
	int rc;

	node = dest->addr.id.node;
	port = dest->addr.id.ref;
	if (!port && !node)
		return -EHOSTUNREACH;

	/* Block or return if destination link or member is congested */
	rc = tipc_wait_for_cond(sock, &timeout,
				!tipc_dest_find(&tsk->cong_links, node, 0) &&
955 956 957
				tsk->group &&
				!tipc_group_cong(tsk->group, node, port, blks,
						 &mb));
958 959 960 961 962 963 964 965 966 967 968
	if (unlikely(rc))
		return rc;

	if (unlikely(!mb))
		return -EHOSTUNREACH;

	rc = tipc_send_group_msg(net, tsk, m, mb, node, port, dlen);

	return rc ? rc : dlen;
}

969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986
/**
 * tipc_send_group_anycast - send message to any member with given identity
 * @sock: socket structure
 * @m: message to send
 * @dlen: total length of message data
 * @timeout: timeout to wait for wakeup
 *
 * Called from function tipc_sendmsg(), which has done all sanity checks
 * Returns the number of bytes sent on success, or errno
 */
static int tipc_send_group_anycast(struct socket *sock, struct msghdr *m,
				   int dlen, long timeout)
{
	DECLARE_SOCKADDR(struct sockaddr_tipc *, dest, m->msg_name);
	struct sock *sk = sock->sk;
	struct tipc_sock *tsk = tipc_sk(sk);
	struct list_head *cong_links = &tsk->cong_links;
	int blks = tsk_blocks(GROUP_H_SIZE + dlen);
987
	struct tipc_msg *hdr = &tsk->phdr;
988 989 990 991 992
	struct tipc_member *first = NULL;
	struct tipc_member *mbr = NULL;
	struct net *net = sock_net(sk);
	u32 node, port, exclude;
	struct list_head dsts;
993
	u32 type, inst, scope;
994 995 996 997 998 999
	int lookups = 0;
	int dstcnt, rc;
	bool cong;

	INIT_LIST_HEAD(&dsts);

1000
	type = msg_nametype(hdr);
1001
	inst = dest->addr.name.name.instance;
1002
	scope = msg_lookup_scope(hdr);
1003 1004

	while (++lookups < 4) {
1005 1006
		exclude = tipc_group_exclude(tsk->group);

1007 1008 1009 1010
		first = NULL;

		/* Look for a non-congested destination member, if any */
		while (1) {
1011
			if (!tipc_nametbl_lookup(net, type, inst, scope, &dsts,
1012 1013 1014
						 &dstcnt, exclude, false))
				return -EHOSTUNREACH;
			tipc_dest_pop(&dsts, &node, &port);
1015 1016
			cong = tipc_group_cong(tsk->group, node, port, blks,
					       &mbr);
1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034
			if (!cong)
				break;
			if (mbr == first)
				break;
			if (!first)
				first = mbr;
		}

		/* Start over if destination was not in member list */
		if (unlikely(!mbr))
			continue;

		if (likely(!cong && !tipc_dest_find(cong_links, node, 0)))
			break;

		/* Block or return if destination link or member is congested */
		rc = tipc_wait_for_cond(sock, &timeout,
					!tipc_dest_find(cong_links, node, 0) &&
1035 1036
					tsk->group &&
					!tipc_group_cong(tsk->group, node, port,
1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053
							 blks, &mbr));
		if (unlikely(rc))
			return rc;

		/* Send, unless destination disappeared while waiting */
		if (likely(mbr))
			break;
	}

	if (unlikely(lookups >= 4))
		return -EHOSTUNREACH;

	rc = tipc_send_group_msg(net, tsk, m, mbr, node, port, dlen);

	return rc ? rc : dlen;
}

J
Jon Maloy 已提交
1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066
/**
 * tipc_send_group_bcast - send message to all members in communication group
 * @sk: socket structure
 * @m: message to send
 * @dlen: total length of message data
 * @timeout: timeout to wait for wakeup
 *
 * Called from function tipc_sendmsg(), which has done all sanity checks
 * Returns the number of bytes sent on success, or errno
 */
static int tipc_send_group_bcast(struct socket *sock, struct msghdr *m,
				 int dlen, long timeout)
{
1067
	DECLARE_SOCKADDR(struct sockaddr_tipc *, dest, m->msg_name);
J
Jon Maloy 已提交
1068 1069 1070
	struct sock *sk = sock->sk;
	struct net *net = sock_net(sk);
	struct tipc_sock *tsk = tipc_sk(sk);
1071
	struct tipc_nlist *dsts;
J
Jon Maloy 已提交
1072
	struct tipc_mc_method *method = &tsk->mc_method;
1073
	bool ack = method->mandatory && method->rcast;
1074
	int blks = tsk_blocks(MCAST_H_SIZE + dlen);
J
Jon Maloy 已提交
1075 1076 1077 1078 1079
	struct tipc_msg *hdr = &tsk->phdr;
	int mtu = tipc_bcast_get_mtu(net);
	struct sk_buff_head pkts;
	int rc = -EHOSTUNREACH;

1080
	/* Block or return if any destination link or member is congested */
1081 1082 1083
	rc = tipc_wait_for_cond(sock, &timeout,
				!tsk->cong_link_cnt && tsk->group &&
				!tipc_group_bc_cong(tsk->group, blks));
J
Jon Maloy 已提交
1084 1085 1086
	if (unlikely(rc))
		return rc;

1087 1088 1089 1090
	dsts = tipc_group_dests(tsk->group);
	if (!dsts->local && !dsts->remote)
		return -EHOSTUNREACH;

J
Jon Maloy 已提交
1091
	/* Complete message header */
1092 1093 1094 1095 1096 1097 1098
	if (dest) {
		msg_set_type(hdr, TIPC_GRP_MCAST_MSG);
		msg_set_nameinst(hdr, dest->addr.name.name.instance);
	} else {
		msg_set_type(hdr, TIPC_GRP_BCAST_MSG);
		msg_set_nameinst(hdr, 0);
	}
1099
	msg_set_hdr_sz(hdr, GROUP_H_SIZE);
J
Jon Maloy 已提交
1100 1101
	msg_set_destport(hdr, 0);
	msg_set_destnode(hdr, 0);
1102
	msg_set_grp_bc_seqno(hdr, tipc_group_bc_snd_nxt(tsk->group));
J
Jon Maloy 已提交
1103

1104 1105 1106
	/* Avoid getting stuck with repeated forced replicasts */
	msg_set_grp_bc_ack_req(hdr, ack);

J
Jon Maloy 已提交
1107
	/* Build message as chain of buffers */
1108
	__skb_queue_head_init(&pkts);
J
Jon Maloy 已提交
1109 1110 1111 1112 1113
	rc = tipc_msg_build(hdr, m, 0, dlen, mtu, &pkts);
	if (unlikely(rc != dlen))
		return rc;

	/* Send message */
1114
	rc = tipc_mcast_xmit(net, &pkts, method, dsts, &tsk->cong_link_cnt);
J
Jon Maloy 已提交
1115 1116 1117
	if (unlikely(rc))
		return rc;

1118
	/* Update broadcast sequence number and send windows */
1119 1120 1121 1122 1123 1124
	tipc_group_update_bc_members(tsk->group, blks, ack);

	/* Broadcast link is now free to choose method for next broadcast */
	method->mandatory = false;
	method->expires = jiffies;

J
Jon Maloy 已提交
1125 1126 1127
	return dlen;
}

1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144
/**
 * tipc_send_group_mcast - send message to all members with given identity
 * @sock: socket structure
 * @m: message to send
 * @dlen: total length of message data
 * @timeout: timeout to wait for wakeup
 *
 * Called from function tipc_sendmsg(), which has done all sanity checks
 * Returns the number of bytes sent on success, or errno
 */
static int tipc_send_group_mcast(struct socket *sock, struct msghdr *m,
				 int dlen, long timeout)
{
	struct sock *sk = sock->sk;
	DECLARE_SOCKADDR(struct sockaddr_tipc *, dest, m->msg_name);
	struct tipc_sock *tsk = tipc_sk(sk);
	struct tipc_group *grp = tsk->group;
1145
	struct tipc_msg *hdr = &tsk->phdr;
1146
	struct net *net = sock_net(sk);
1147
	u32 type, inst, scope, exclude;
1148
	struct list_head dsts;
1149
	u32 dstcnt;
1150 1151 1152

	INIT_LIST_HEAD(&dsts);

1153 1154 1155
	type = msg_nametype(hdr);
	inst = dest->addr.name.name.instance;
	scope = msg_lookup_scope(hdr);
1156
	exclude = tipc_group_exclude(grp);
1157 1158 1159

	if (!tipc_nametbl_lookup(net, type, inst, scope, &dsts,
				 &dstcnt, exclude, true))
1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170
		return -EHOSTUNREACH;

	if (dstcnt == 1) {
		tipc_dest_pop(&dsts, &dest->addr.id.node, &dest->addr.id.ref);
		return tipc_send_group_unicast(sock, m, dlen, timeout);
	}

	tipc_dest_list_purge(&dsts);
	return tipc_send_group_bcast(sock, m, dlen, timeout);
}

1171 1172 1173 1174 1175 1176
/**
 * tipc_sk_mcast_rcv - Deliver multicast messages to all destination sockets
 * @arrvq: queue with arriving messages, to be cloned after destination lookup
 * @inputq: queue with cloned messages, delivered to socket after dest lookup
 *
 * Multi-threaded: parallel calls with reference to same queues may occur
1177
 */
1178 1179
void tipc_sk_mcast_rcv(struct net *net, struct sk_buff_head *arrvq,
		       struct sk_buff_head *inputq)
1180
{
J
Jon Maloy 已提交
1181
	u32 self = tipc_own_addr(net);
1182
	u32 type, lower, upper, scope;
1183
	struct sk_buff *skb, *_skb;
1184
	u32 portid, onode;
1185
	struct sk_buff_head tmpq;
J
Jon Maloy 已提交
1186
	struct list_head dports;
1187 1188 1189
	struct tipc_msg *hdr;
	int user, mtyp, hlen;
	bool exact;
1190

1191
	__skb_queue_head_init(&tmpq);
1192
	INIT_LIST_HEAD(&dports);
1193

1194 1195
	skb = tipc_skb_peek(arrvq, &inputq->lock);
	for (; skb; skb = tipc_skb_peek(arrvq, &inputq->lock)) {
1196 1197 1198 1199 1200 1201 1202
		hdr = buf_msg(skb);
		user = msg_user(hdr);
		mtyp = msg_type(hdr);
		hlen = skb_headroom(skb) + msg_hdr_sz(hdr);
		onode = msg_orignode(hdr);
		type = msg_nametype(hdr);

1203 1204 1205 1206 1207 1208
		if (mtyp == TIPC_GRP_UCAST_MSG || user == GROUP_PROTOCOL) {
			spin_lock_bh(&inputq->lock);
			if (skb_peek(arrvq) == skb) {
				__skb_dequeue(arrvq);
				__skb_queue_tail(inputq, skb);
			}
J
Jon Maloy 已提交
1209
			kfree_skb(skb);
1210 1211 1212
			spin_unlock_bh(&inputq->lock);
			continue;
		}
1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228

		/* Group messages require exact scope match */
		if (msg_in_group(hdr)) {
			lower = 0;
			upper = ~0;
			scope = msg_lookup_scope(hdr);
			exact = true;
		} else {
			/* TIPC_NODE_SCOPE means "any scope" in this context */
			if (onode == self)
				scope = TIPC_NODE_SCOPE;
			else
				scope = TIPC_CLUSTER_SCOPE;
			exact = false;
			lower = msg_namelower(hdr);
			upper = msg_nameupper(hdr);
J
Jon Maloy 已提交
1229
		}
1230 1231 1232 1233 1234 1235

		/* Create destination port list: */
		tipc_nametbl_mc_lookup(net, type, lower, upper,
				       scope, exact, &dports);

		/* Clone message per destination */
J
Jon Maloy 已提交
1236
		while (tipc_dest_pop(&dports, NULL, &portid)) {
1237
			_skb = __pskb_copy(skb, hlen, GFP_ATOMIC);
1238 1239 1240 1241 1242 1243
			if (_skb) {
				msg_set_destport(buf_msg(_skb), portid);
				__skb_queue_tail(&tmpq, _skb);
				continue;
			}
			pr_warn("Failed to clone mcast rcv buffer\n");
1244
		}
1245 1246 1247 1248 1249 1250 1251 1252 1253
		/* Append to inputq if not already done by other thread */
		spin_lock_bh(&inputq->lock);
		if (skb_peek(arrvq) == skb) {
			skb_queue_splice_tail_init(&tmpq, inputq);
			kfree_skb(__skb_dequeue(arrvq));
		}
		spin_unlock_bh(&inputq->lock);
		__skb_queue_purge(&tmpq);
		kfree_skb(skb);
1254
	}
1255
	tipc_sk_rcv(net, inputq);
1256 1257
}

J
Jon Maloy 已提交
1258 1259 1260
/* tipc_sk_push_backlog(): send accumulated buffers in socket write queue
 *                         when socket is in Nagle mode
 */
1261
static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack)
J
Jon Maloy 已提交
1262 1263
{
	struct sk_buff_head *txq = &tsk->sk.sk_write_queue;
1264
	struct sk_buff *skb = skb_peek_tail(txq);
J
Jon Maloy 已提交
1265 1266 1267 1268
	struct net *net = sock_net(&tsk->sk);
	u32 dnode = tsk_peer_node(tsk);
	int rc;

1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291
	if (nagle_ack) {
		tsk->pkt_cnt += skb_queue_len(txq);
		if (!tsk->pkt_cnt || tsk->msg_acc / tsk->pkt_cnt < 2) {
			tsk->oneway = 0;
			if (tsk->nagle_start < NAGLE_START_MAX)
				tsk->nagle_start *= 2;
			tsk->expect_ack = false;
			pr_debug("tsk %10u: bad nagle %u -> %u, next start %u!\n",
				 tsk->portid, tsk->msg_acc, tsk->pkt_cnt,
				 tsk->nagle_start);
		} else {
			tsk->nagle_start = NAGLE_START_INIT;
			if (skb) {
				msg_set_ack_required(buf_msg(skb));
				tsk->expect_ack = true;
			} else {
				tsk->expect_ack = false;
			}
		}
		tsk->msg_acc = 0;
		tsk->pkt_cnt = 0;
	}

1292 1293 1294 1295 1296
	if (!skb || tsk->cong_link_cnt)
		return;

	/* Do not send SYN again after congestion */
	if (msg_is_syn(buf_msg(skb)))
J
Jon Maloy 已提交
1297 1298
		return;

1299 1300
	if (tsk->msg_acc)
		tsk->pkt_cnt += skb_queue_len(txq);
J
Jon Maloy 已提交
1301 1302 1303 1304 1305 1306 1307
	tsk->snt_unacked += tsk->snd_backlog;
	tsk->snd_backlog = 0;
	rc = tipc_node_xmit(net, txq, dnode, tsk->portid);
	if (rc == -ELINKCONG)
		tsk->cong_link_cnt = 1;
}

1308
/**
J
Jon Maloy 已提交
1309
 * tipc_sk_conn_proto_rcv - receive a connection mng protocol message
1310
 * @tsk: receiving socket
1311
 * @skb: pointer to message buffer.
1312
 */
J
Jon Maloy 已提交
1313
static void tipc_sk_conn_proto_rcv(struct tipc_sock *tsk, struct sk_buff *skb,
1314
				   struct sk_buff_head *inputq,
J
Jon Maloy 已提交
1315
				   struct sk_buff_head *xmitq)
1316
{
1317
	struct tipc_msg *hdr = buf_msg(skb);
J
Jon Maloy 已提交
1318 1319
	u32 onode = tsk_own_node(tsk);
	struct sock *sk = &tsk->sk;
1320
	int mtyp = msg_type(hdr);
J
Jon Maloy 已提交
1321
	bool was_cong;
1322

1323
	/* Ignore if connection cannot be validated: */
1324 1325
	if (!tsk_peer_msg(tsk, hdr)) {
		trace_tipc_sk_drop_msg(sk, skb, TIPC_DUMP_NONE, "@proto_rcv!");
1326
		goto exit;
1327
	}
1328

1329 1330 1331 1332 1333
	if (unlikely(msg_errcode(hdr))) {
		tipc_set_sk_state(sk, TIPC_DISCONNECTING);
		tipc_node_remove_conn(sock_net(sk), tsk_peer_node(tsk),
				      tsk_peer_port(tsk));
		sk->sk_state_change(sk);
1334 1335 1336 1337 1338 1339 1340 1341 1342 1343

		/* State change is ignored if socket already awake,
		 * - convert msg to abort msg and add to inqueue
		 */
		msg_set_user(hdr, TIPC_CRITICAL_IMPORTANCE);
		msg_set_type(hdr, TIPC_CONN_MSG);
		msg_set_size(hdr, BASIC_H_SIZE);
		msg_set_hdr_sz(hdr, BASIC_H_SIZE);
		__skb_queue_tail(inputq, skb);
		return;
1344 1345
	}

1346
	tsk->probe_unacked = false;
1347

1348 1349
	if (mtyp == CONN_PROBE) {
		msg_set_type(hdr, CONN_PROBE_REPLY);
J
Jon Paul Maloy 已提交
1350 1351
		if (tipc_msg_reverse(onode, &skb, TIPC_OK))
			__skb_queue_tail(xmitq, skb);
1352 1353
		return;
	} else if (mtyp == CONN_ACK) {
J
Jon Maloy 已提交
1354
		was_cong = tsk_conn_cong(tsk);
1355
		tipc_sk_push_backlog(tsk, msg_nagle_ack(hdr));
1356 1357 1358
		tsk->snt_unacked -= msg_conn_ack(hdr);
		if (tsk->peer_caps & TIPC_BLOCK_FLOWCTL)
			tsk->snd_win = msg_adv_win(hdr);
J
Jon Maloy 已提交
1359
		if (was_cong && !tsk_conn_cong(tsk))
1360 1361 1362
			sk->sk_write_space(sk);
	} else if (mtyp != CONN_PROBE_REPLY) {
		pr_warn("Received unknown CONN_PROTO msg\n");
1363 1364
	}
exit:
1365
	kfree_skb(skb);
1366 1367
}

P
Per Liden 已提交
1368
/**
1369
 * tipc_sendmsg - send message in connectionless manner
P
Per Liden 已提交
1370 1371
 * @sock: socket structure
 * @m: message to send
1372
 * @dsz: amount of user data to be sent
1373
 *
P
Per Liden 已提交
1374
 * Message must have an destination specified explicitly.
1375
 * Used for SOCK_RDM and SOCK_DGRAM messages,
P
Per Liden 已提交
1376 1377
 * and for 'SYN' messages on SOCK_SEQPACKET and SOCK_STREAM connections.
 * (Note: 'SYN+' is prohibited on SOCK_STREAM.)
1378
 *
P
Per Liden 已提交
1379 1380
 * Returns the number of bytes sent on success, or errno otherwise
 */
1381
static int tipc_sendmsg(struct socket *sock,
1382
			struct msghdr *m, size_t dsz)
1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393
{
	struct sock *sk = sock->sk;
	int ret;

	lock_sock(sk);
	ret = __tipc_sendmsg(sock, m, dsz);
	release_sock(sk);

	return ret;
}

1394
static int __tipc_sendmsg(struct socket *sock, struct msghdr *m, size_t dlen)
P
Per Liden 已提交
1395
{
1396
	struct sock *sk = sock->sk;
1397
	struct net *net = sock_net(sk);
1398 1399 1400 1401 1402
	struct tipc_sock *tsk = tipc_sk(sk);
	DECLARE_SOCKADDR(struct sockaddr_tipc *, dest, m->msg_name);
	long timeout = sock_sndtimeo(sk, m->msg_flags & MSG_DONTWAIT);
	struct list_head *clinks = &tsk->cong_links;
	bool syn = !tipc_sk_type_connectionless(sk);
J
Jon Maloy 已提交
1403
	struct tipc_group *grp = tsk->group;
1404
	struct tipc_msg *hdr = &tsk->phdr;
1405
	struct tipc_name_seq *seq;
1406
	struct sk_buff_head pkts;
1407 1408
	u32 dport = 0, dnode = 0;
	u32 type = 0, inst = 0;
1409
	int mtu, rc;
P
Per Liden 已提交
1410

1411
	if (unlikely(dlen > TIPC_MAX_USER_MSG_SIZE))
1412
		return -EMSGSIZE;
1413

1414 1415 1416 1417 1418 1419 1420 1421 1422 1423
	if (likely(dest)) {
		if (unlikely(m->msg_namelen < sizeof(*dest)))
			return -EINVAL;
		if (unlikely(dest->family != AF_TIPC))
			return -EINVAL;
	}

	if (grp) {
		if (!dest)
			return tipc_send_group_bcast(sock, m, dlen, timeout);
1424 1425
		if (dest->addrtype == TIPC_ADDR_NAME)
			return tipc_send_group_anycast(sock, m, dlen, timeout);
1426 1427
		if (dest->addrtype == TIPC_ADDR_ID)
			return tipc_send_group_unicast(sock, m, dlen, timeout);
1428 1429
		if (dest->addrtype == TIPC_ADDR_MCAST)
			return tipc_send_group_mcast(sock, m, dlen, timeout);
1430 1431
		return -EINVAL;
	}
J
Jon Maloy 已提交
1432

1433
	if (unlikely(!dest)) {
1434
		dest = &tsk->peer;
1435
		if (!syn && dest->family != AF_TIPC)
1436 1437
			return -EDESTADDRREQ;
	}
1438 1439

	if (unlikely(syn)) {
1440
		if (sk->sk_state == TIPC_LISTEN)
1441
			return -EPIPE;
1442
		if (sk->sk_state != TIPC_OPEN)
1443 1444 1445
			return -EISCONN;
		if (tsk->published)
			return -EOPNOTSUPP;
1446
		if (dest->addrtype == TIPC_ADDR_NAME) {
1447 1448
			tsk->conn_type = dest->addr.name.name.type;
			tsk->conn_instance = dest->addr.name.name.instance;
1449
		}
1450
		msg_set_syn(hdr, 1);
P
Per Liden 已提交
1451
	}
1452

1453 1454 1455
	seq = &dest->addr.nameseq;
	if (dest->addrtype == TIPC_ADDR_MCAST)
		return tipc_sendmcast(sock, seq, m, dlen, timeout);
1456

1457 1458 1459
	if (dest->addrtype == TIPC_ADDR_NAME) {
		type = dest->addr.name.name.type;
		inst = dest->addr.name.name.instance;
J
Jon Maloy 已提交
1460
		dnode = dest->addr.name.domain;
1461
		dport = tipc_nametbl_translate(net, type, inst, &dnode);
1462 1463
		if (unlikely(!dport && !dnode))
			return -EHOSTUNREACH;
1464 1465
	} else if (dest->addrtype == TIPC_ADDR_ID) {
		dnode = dest->addr.id.node;
1466 1467
	} else {
		return -EINVAL;
1468 1469
	}

1470
	/* Block or return if destination link is congested */
J
Jon Maloy 已提交
1471 1472
	rc = tipc_wait_for_cond(sock, &timeout,
				!tipc_dest_find(clinks, dnode, 0));
1473 1474 1475
	if (unlikely(rc))
		return rc;

1476 1477 1478 1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489 1490 1491
	if (dest->addrtype == TIPC_ADDR_NAME) {
		msg_set_type(hdr, TIPC_NAMED_MSG);
		msg_set_hdr_sz(hdr, NAMED_H_SIZE);
		msg_set_nametype(hdr, type);
		msg_set_nameinst(hdr, inst);
		msg_set_lookup_scope(hdr, tipc_node2scope(dnode));
		msg_set_destnode(hdr, dnode);
		msg_set_destport(hdr, dport);
	} else { /* TIPC_ADDR_ID */
		msg_set_type(hdr, TIPC_DIRECT_MSG);
		msg_set_lookup_scope(hdr, 0);
		msg_set_destnode(hdr, dnode);
		msg_set_destport(hdr, dest->addr.id.ref);
		msg_set_hdr_sz(hdr, BASIC_H_SIZE);
	}

1492
	__skb_queue_head_init(&pkts);
1493
	mtu = tipc_node_get_mtu(net, dnode, tsk->portid, true);
1494 1495
	rc = tipc_msg_build(hdr, m, 0, dlen, mtu, &pkts);
	if (unlikely(rc != dlen))
1496
		return rc;
1497 1498
	if (unlikely(syn && !tipc_msg_skb_clone(&pkts, &sk->sk_write_queue))) {
		__skb_queue_purge(&pkts);
1499
		return -ENOMEM;
1500
	}
1501

1502
	trace_tipc_sk_sendmsg(sk, skb_peek(&pkts), TIPC_DUMP_SK_SNDQ, " ");
1503 1504
	rc = tipc_node_xmit(net, &pkts, dnode, tsk->portid);
	if (unlikely(rc == -ELINKCONG)) {
J
Jon Maloy 已提交
1505
		tipc_dest_push(clinks, dnode, 0);
1506 1507 1508
		tsk->cong_link_cnt++;
		rc = 0;
	}
1509

1510 1511 1512 1513
	if (unlikely(syn && !rc))
		tipc_set_sk_state(sk, TIPC_CONNECTING);

	return rc ? rc : dlen;
P
Per Liden 已提交
1514 1515
}

1516
/**
1517
 * tipc_sendstream - send stream-oriented data
P
Per Liden 已提交
1518
 * @sock: socket structure
1519 1520
 * @m: data to send
 * @dsz: total length of data to be transmitted
1521
 *
1522
 * Used for SOCK_STREAM data.
1523
 *
1524 1525
 * Returns the number of bytes sent on success (or partial success),
 * or errno if no data sent
P
Per Liden 已提交
1526
 */
1527
static int tipc_sendstream(struct socket *sock, struct msghdr *m, size_t dsz)
1528 1529 1530 1531 1532
{
	struct sock *sk = sock->sk;
	int ret;

	lock_sock(sk);
1533
	ret = __tipc_sendstream(sock, m, dsz);
1534 1535 1536 1537 1538
	release_sock(sk);

	return ret;
}

1539
static int __tipc_sendstream(struct socket *sock, struct msghdr *m, size_t dlen)
P
Per Liden 已提交
1540
{
1541
	struct sock *sk = sock->sk;
1542
	DECLARE_SOCKADDR(struct sockaddr_tipc *, dest, m->msg_name);
1543
	long timeout = sock_sndtimeo(sk, m->msg_flags & MSG_DONTWAIT);
J
Jon Maloy 已提交
1544
	struct sk_buff_head *txq = &sk->sk_write_queue;
1545 1546 1547
	struct tipc_sock *tsk = tipc_sk(sk);
	struct tipc_msg *hdr = &tsk->phdr;
	struct net *net = sock_net(sk);
1548
	struct sk_buff *skb;
1549
	u32 dnode = tsk_peer_node(tsk);
J
Jon Maloy 已提交
1550 1551
	int maxnagle = tsk->maxnagle;
	int maxpkt = tsk->max_pkt;
1552
	int send, sent = 0;
J
Jon Maloy 已提交
1553
	int blocks, rc = 0;
1554

1555 1556
	if (unlikely(dlen > INT_MAX))
		return -EMSGSIZE;
1557

1558 1559 1560
	/* Handle implicit connection setup */
	if (unlikely(dest)) {
		rc = __tipc_sendmsg(sock, m, dlen);
1561 1562
		if (dlen && dlen == rc) {
			tsk->peer_caps = tipc_node_get_capabilities(net, dnode);
1563
			tsk->snt_unacked = tsk_inc(tsk, dlen + msg_hdr_sz(hdr));
1564
		}
1565
		return rc;
1566
	}
1567

1568
	do {
1569 1570
		rc = tipc_wait_for_cond(sock, &timeout,
					(!tsk->cong_link_cnt &&
1571 1572
					 !tsk_conn_cong(tsk) &&
					 tipc_sk_connected(sk)));
1573 1574 1575
		if (unlikely(rc))
			break;
		send = min_t(size_t, dlen - sent, TIPC_MAX_USER_MSG_SIZE);
J
Jon Maloy 已提交
1576
		blocks = tsk->snd_backlog;
1577
		if (tsk->oneway++ >= tsk->nagle_start && send <= maxnagle) {
J
Jon Maloy 已提交
1578 1579 1580 1581
			rc = tipc_msg_append(hdr, m, send, maxnagle, txq);
			if (unlikely(rc < 0))
				break;
			blocks += rc;
1582
			tsk->msg_acc++;
J
Jon Maloy 已提交
1583 1584 1585 1586
			if (blocks <= 64 && tsk->expect_ack) {
				tsk->snd_backlog = blocks;
				sent += send;
				break;
1587 1588 1589 1590 1591 1592 1593 1594
			} else if (blocks > 64) {
				tsk->pkt_cnt += skb_queue_len(txq);
			} else {
				skb = skb_peek_tail(txq);
				msg_set_ack_required(buf_msg(skb));
				tsk->expect_ack = true;
				tsk->msg_acc = 0;
				tsk->pkt_cnt = 0;
J
Jon Maloy 已提交
1595 1596 1597 1598 1599 1600 1601 1602
			}
		} else {
			rc = tipc_msg_build(hdr, m, sent, send, maxpkt, txq);
			if (unlikely(rc != send))
				break;
			blocks += tsk_inc(tsk, send + MIN_H_SIZE);
		}
		trace_tipc_sk_sendstream(sk, skb_peek(txq),
1603
					 TIPC_DUMP_SK_SNDQ, " ");
J
Jon Maloy 已提交
1604
		rc = tipc_node_xmit(net, txq, dnode, tsk->portid);
1605 1606 1607 1608 1609
		if (unlikely(rc == -ELINKCONG)) {
			tsk->cong_link_cnt = 1;
			rc = 0;
		}
		if (likely(!rc)) {
J
Jon Maloy 已提交
1610 1611
			tsk->snt_unacked += blocks;
			tsk->snd_backlog = 0;
1612 1613 1614
			sent += send;
		}
	} while (sent < dlen && !rc);
1615

1616
	return sent ? sent : rc;
P
Per Liden 已提交
1617 1618
}

1619
/**
1620
 * tipc_send_packet - send a connection-oriented message
P
Per Liden 已提交
1621
 * @sock: socket structure
1622 1623
 * @m: message to send
 * @dsz: length of data to be transmitted
1624
 *
1625
 * Used for SOCK_SEQPACKET messages.
1626
 *
1627
 * Returns the number of bytes sent on success, or errno otherwise
P
Per Liden 已提交
1628
 */
1629
static int tipc_send_packet(struct socket *sock, struct msghdr *m, size_t dsz)
P
Per Liden 已提交
1630
{
1631 1632
	if (dsz > TIPC_MAX_USER_MSG_SIZE)
		return -EMSGSIZE;
P
Per Liden 已提交
1633

1634
	return tipc_sendstream(sock, m, dsz);
P
Per Liden 已提交
1635 1636
}

1637
/* tipc_sk_finish_conn - complete the setup of a connection
P
Per Liden 已提交
1638
 */
1639
static void tipc_sk_finish_conn(struct tipc_sock *tsk, u32 peer_port,
1640
				u32 peer_node)
P
Per Liden 已提交
1641
{
1642 1643
	struct sock *sk = &tsk->sk;
	struct net *net = sock_net(sk);
1644
	struct tipc_msg *msg = &tsk->phdr;
P
Per Liden 已提交
1645

1646
	msg_set_syn(msg, 0);
1647 1648 1649 1650 1651
	msg_set_destnode(msg, peer_node);
	msg_set_destport(msg, peer_port);
	msg_set_type(msg, TIPC_CONN_MSG);
	msg_set_lookup_scope(msg, 0);
	msg_set_hdr_sz(msg, SHORT_H_SIZE);
1652

1653
	sk_reset_timer(sk, &sk->sk_timer, jiffies + CONN_PROBING_INTV);
1654
	tipc_set_sk_state(sk, TIPC_ESTABLISHED);
1655
	tipc_node_add_conn(net, peer_node, tsk->portid, peer_port);
1656
	tsk->max_pkt = tipc_node_get_mtu(net, peer_node, tsk->portid, true);
1657
	tsk->peer_caps = tipc_node_get_capabilities(net, peer_node);
J
Jon Maloy 已提交
1658
	tsk_set_nagle(tsk);
1659
	__skb_queue_purge(&sk->sk_write_queue);
1660 1661 1662 1663 1664 1665
	if (tsk->peer_caps & TIPC_BLOCK_FLOWCTL)
		return;

	/* Fall back to message based flow control */
	tsk->rcv_win = FLOWCTL_MSG_WIN;
	tsk->snd_win = FLOWCTL_MSG_WIN;
P
Per Liden 已提交
1666 1667 1668
}

/**
1669
 * tipc_sk_set_orig_addr - capture sender's address for received message
P
Per Liden 已提交
1670
 * @m: descriptor for message info
1671
 * @hdr: received message header
1672
 *
P
Per Liden 已提交
1673 1674
 * Note: Address is not captured if not requested by receiver.
 */
1675
static void tipc_sk_set_orig_addr(struct msghdr *m, struct sk_buff *skb)
P
Per Liden 已提交
1676
{
1677 1678 1679 1680 1681 1682 1683 1684
	DECLARE_SOCKADDR(struct sockaddr_pair *, srcaddr, m->msg_name);
	struct tipc_msg *hdr = buf_msg(skb);

	if (!srcaddr)
		return;

	srcaddr->sock.family = AF_TIPC;
	srcaddr->sock.addrtype = TIPC_ADDR_ID;
1685
	srcaddr->sock.scope = 0;
1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696
	srcaddr->sock.addr.id.ref = msg_origport(hdr);
	srcaddr->sock.addr.id.node = msg_orignode(hdr);
	srcaddr->sock.addr.name.domain = 0;
	m->msg_namelen = sizeof(struct sockaddr_tipc);

	if (!msg_in_group(hdr))
		return;

	/* Group message users may also want to know sending member's id */
	srcaddr->member.family = AF_TIPC;
	srcaddr->member.addrtype = TIPC_ADDR_NAME;
1697
	srcaddr->member.scope = 0;
1698 1699 1700 1701
	srcaddr->member.addr.name.name.type = msg_nametype(hdr);
	srcaddr->member.addr.name.name.instance = TIPC_SKB_CB(skb)->orig_member;
	srcaddr->member.addr.name.domain = 0;
	m->msg_namelen = sizeof(*srcaddr);
P
Per Liden 已提交
1702 1703 1704
}

/**
1705
 * tipc_sk_anc_data_recv - optionally capture ancillary data for received message
P
Per Liden 已提交
1706
 * @m: descriptor for message info
1707
 * @skb: received message buffer
1708
 * @tsk: TIPC port associated with message
1709
 *
P
Per Liden 已提交
1710
 * Note: Ancillary data is not captured if not requested by receiver.
1711
 *
P
Per Liden 已提交
1712 1713
 * Returns 0 if successful, otherwise errno
 */
1714
static int tipc_sk_anc_data_recv(struct msghdr *m, struct sk_buff *skb,
1715
				 struct tipc_sock *tsk)
P
Per Liden 已提交
1716
{
1717
	struct tipc_msg *msg;
P
Per Liden 已提交
1718 1719 1720
	u32 anc_data[3];
	u32 err;
	u32 dest_type;
1721
	int has_name;
P
Per Liden 已提交
1722 1723 1724 1725
	int res;

	if (likely(m->msg_controllen == 0))
		return 0;
1726
	msg = buf_msg(skb);
P
Per Liden 已提交
1727 1728 1729 1730 1731 1732

	/* Optionally capture errored message object(s) */
	err = msg ? msg_errcode(msg) : 0;
	if (unlikely(err)) {
		anc_data[0] = err;
		anc_data[1] = msg_data_sz(msg);
1733 1734
		res = put_cmsg(m, SOL_TIPC, TIPC_ERRINFO, 8, anc_data);
		if (res)
P
Per Liden 已提交
1735
			return res;
1736
		if (anc_data[1]) {
1737 1738 1739
			if (skb_linearize(skb))
				return -ENOMEM;
			msg = buf_msg(skb);
1740 1741 1742 1743 1744
			res = put_cmsg(m, SOL_TIPC, TIPC_RETDATA, anc_data[1],
				       msg_data(msg));
			if (res)
				return res;
		}
P
Per Liden 已提交
1745 1746 1747 1748 1749 1750
	}

	/* Optionally capture message destination object */
	dest_type = msg ? msg_type(msg) : TIPC_DIRECT_MSG;
	switch (dest_type) {
	case TIPC_NAMED_MSG:
1751
		has_name = 1;
P
Per Liden 已提交
1752 1753 1754 1755 1756
		anc_data[0] = msg_nametype(msg);
		anc_data[1] = msg_namelower(msg);
		anc_data[2] = msg_namelower(msg);
		break;
	case TIPC_MCAST_MSG:
1757
		has_name = 1;
P
Per Liden 已提交
1758 1759 1760 1761 1762
		anc_data[0] = msg_nametype(msg);
		anc_data[1] = msg_namelower(msg);
		anc_data[2] = msg_nameupper(msg);
		break;
	case TIPC_CONN_MSG:
1763 1764 1765 1766
		has_name = (tsk->conn_type != 0);
		anc_data[0] = tsk->conn_type;
		anc_data[1] = tsk->conn_instance;
		anc_data[2] = tsk->conn_instance;
P
Per Liden 已提交
1767 1768
		break;
	default:
1769
		has_name = 0;
P
Per Liden 已提交
1770
	}
1771 1772 1773 1774 1775
	if (has_name) {
		res = put_cmsg(m, SOL_TIPC, TIPC_DESTNAME, 12, anc_data);
		if (res)
			return res;
	}
P
Per Liden 已提交
1776 1777 1778 1779

	return 0;
}

1780
static struct sk_buff *tipc_sk_build_ack(struct tipc_sock *tsk)
1781
{
1782
	struct sock *sk = &tsk->sk;
1783
	struct sk_buff *skb = NULL;
1784
	struct tipc_msg *msg;
1785 1786
	u32 peer_port = tsk_peer_port(tsk);
	u32 dnode = tsk_peer_node(tsk);
1787

1788
	if (!tipc_sk_connected(sk))
1789
		return NULL;
1790 1791 1792
	skb = tipc_msg_create(CONN_MANAGER, CONN_ACK, INT_H_SIZE, 0,
			      dnode, tsk_own_node(tsk), peer_port,
			      tsk->portid, TIPC_OK);
1793
	if (!skb)
1794
		return NULL;
1795
	msg = buf_msg(skb);
1796 1797 1798 1799 1800 1801 1802 1803
	msg_set_conn_ack(msg, tsk->rcv_unacked);
	tsk->rcv_unacked = 0;

	/* Adjust to and advertize the correct window limit */
	if (tsk->peer_caps & TIPC_BLOCK_FLOWCTL) {
		tsk->rcv_win = tsk_adv_blocks(tsk->sk.sk_rcvbuf);
		msg_set_adv_win(msg, tsk->rcv_win);
	}
1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816
	return skb;
}

static void tipc_sk_send_ack(struct tipc_sock *tsk)
{
	struct sk_buff *skb;

	skb = tipc_sk_build_ack(tsk);
	if (!skb)
		return;

	tipc_node_xmit_skb(sock_net(&tsk->sk), skb, tsk_peer_node(tsk),
			   msg_link_selector(buf_msg(skb)));
1817 1818
}

1819
static int tipc_wait_for_rcvmsg(struct socket *sock, long *timeop)
Y
Ying Xue 已提交
1820 1821
{
	struct sock *sk = sock->sk;
1822
	DEFINE_WAIT_FUNC(wait, woken_wake_function);
1823
	long timeo = *timeop;
1824 1825 1826 1827
	int err = sock_error(sk);

	if (err)
		return err;
Y
Ying Xue 已提交
1828 1829

	for (;;) {
1830
		if (timeo && skb_queue_empty(&sk->sk_receive_queue)) {
1831
			if (sk->sk_shutdown & RCV_SHUTDOWN) {
Y
Ying Xue 已提交
1832 1833 1834
				err = -ENOTCONN;
				break;
			}
1835
			add_wait_queue(sk_sleep(sk), &wait);
Y
Ying Xue 已提交
1836
			release_sock(sk);
1837 1838
			timeo = wait_woken(&wait, TASK_INTERRUPTIBLE, timeo);
			sched_annotate_sleep();
Y
Ying Xue 已提交
1839
			lock_sock(sk);
1840
			remove_wait_queue(sk_sleep(sk), &wait);
Y
Ying Xue 已提交
1841 1842 1843 1844 1845 1846 1847
		}
		err = 0;
		if (!skb_queue_empty(&sk->sk_receive_queue))
			break;
		err = -EAGAIN;
		if (!timeo)
			break;
1848 1849 1850
		err = sock_intr_errno(timeo);
		if (signal_pending(current))
			break;
1851 1852 1853 1854

		err = sock_error(sk);
		if (err)
			break;
Y
Ying Xue 已提交
1855
	}
1856
	*timeop = timeo;
Y
Ying Xue 已提交
1857 1858 1859
	return err;
}

1860
/**
1861
 * tipc_recvmsg - receive packet-oriented message
P
Per Liden 已提交
1862
 * @m: descriptor for message info
1863
 * @buflen: length of user buffer area
P
Per Liden 已提交
1864
 * @flags: receive flags
1865
 *
P
Per Liden 已提交
1866 1867 1868 1869 1870
 * Used for SOCK_DGRAM, SOCK_RDM, and SOCK_SEQPACKET messages.
 * If the complete message doesn't fit in user area, truncate it.
 *
 * Returns size of returned message data, errno otherwise
 */
1871 1872
static int tipc_recvmsg(struct socket *sock, struct msghdr *m,
			size_t buflen,	int flags)
P
Per Liden 已提交
1873
{
1874
	struct sock *sk = sock->sk;
1875
	bool connected = !tipc_sk_type_connectionless(sk);
1876
	struct tipc_sock *tsk = tipc_sk(sk);
1877
	int rc, err, hlen, dlen, copy;
1878
	struct sk_buff_head xmitq;
1879 1880 1881
	struct tipc_msg *hdr;
	struct sk_buff *skb;
	bool grp_evt;
1882
	long timeout;
P
Per Liden 已提交
1883

1884
	/* Catch invalid receive requests */
1885
	if (unlikely(!buflen))
P
Per Liden 已提交
1886 1887
		return -EINVAL;

1888
	lock_sock(sk);
1889 1890
	if (unlikely(connected && sk->sk_state == TIPC_OPEN)) {
		rc = -ENOTCONN;
P
Per Liden 已提交
1891 1892
		goto exit;
	}
1893
	timeout = sock_rcvtimeo(sk, flags & MSG_DONTWAIT);
P
Per Liden 已提交
1894

1895
	/* Step rcv queue to first msg with data or error; wait if necessary */
1896 1897 1898 1899 1900 1901 1902 1903 1904
	do {
		rc = tipc_wait_for_rcvmsg(sock, &timeout);
		if (unlikely(rc))
			goto exit;
		skb = skb_peek(&sk->sk_receive_queue);
		hdr = buf_msg(skb);
		dlen = msg_data_sz(hdr);
		hlen = msg_hdr_sz(hdr);
		err = msg_errcode(hdr);
1905
		grp_evt = msg_is_grp_evt(hdr);
1906 1907
		if (likely(dlen || err))
			break;
1908
		tsk_advance_rx_queue(sk);
1909
	} while (1);
P
Per Liden 已提交
1910

1911
	/* Collect msg meta data, including error code and rejected data */
1912
	tipc_sk_set_orig_addr(m, skb);
1913
	rc = tipc_sk_anc_data_recv(m, skb, tsk);
1914
	if (unlikely(rc))
P
Per Liden 已提交
1915
		goto exit;
1916
	hdr = buf_msg(skb);
P
Per Liden 已提交
1917

1918 1919 1920 1921
	/* Capture data if non-error msg, otherwise just set return value */
	if (likely(!err)) {
		copy = min_t(int, dlen, buflen);
		if (unlikely(copy != dlen))
P
Per Liden 已提交
1922
			m->msg_flags |= MSG_TRUNC;
1923
		rc = skb_copy_datagram_msg(skb, hlen, m, copy);
P
Per Liden 已提交
1924
	} else {
1925 1926 1927 1928
		copy = 0;
		rc = 0;
		if (err != TIPC_CONN_SHUTDOWN && connected && !m->msg_control)
			rc = -ECONNRESET;
P
Per Liden 已提交
1929
	}
1930 1931
	if (unlikely(rc))
		goto exit;
P
Per Liden 已提交
1932

1933 1934 1935 1936 1937 1938 1939 1940
	/* Mark message as group event if applicable */
	if (unlikely(grp_evt)) {
		if (msg_grp_evt(hdr) == TIPC_WITHDRAWN)
			m->msg_flags |= MSG_EOR;
		m->msg_flags |= MSG_OOB;
		copy = 0;
	}

1941
	/* Caption of data or error code/rejected data was successful */
1942 1943 1944
	if (unlikely(flags & MSG_PEEK))
		goto exit;

1945 1946
	/* Send group flow control advertisement when applicable */
	if (tsk->group && msg_in_group(hdr) && !grp_evt) {
1947
		__skb_queue_head_init(&xmitq);
1948 1949 1950 1951 1952 1953
		tipc_group_update_rcv_win(tsk->group, tsk_blocks(hlen + dlen),
					  msg_orignode(hdr), msg_origport(hdr),
					  &xmitq);
		tipc_node_distr_xmit(sock_net(sk), &xmitq);
	}

1954
	tsk_advance_rx_queue(sk);
1955

1956 1957 1958
	if (likely(!connected))
		goto exit;

1959
	/* Send connection flow control advertisement when applicable */
1960 1961 1962
	tsk->rcv_unacked += tsk_inc(tsk, hlen + dlen);
	if (tsk->rcv_unacked >= tsk->rcv_win / TIPC_ACK_RATE)
		tipc_sk_send_ack(tsk);
P
Per Liden 已提交
1963
exit:
1964
	release_sock(sk);
1965
	return rc ? rc : copy;
P
Per Liden 已提交
1966 1967
}

1968
/**
1969
 * tipc_recvstream - receive stream-oriented data
P
Per Liden 已提交
1970
 * @m: descriptor for message info
1971
 * @buflen: total size of user buffer area
P
Per Liden 已提交
1972
 * @flags: receive flags
1973 1974
 *
 * Used for SOCK_STREAM messages only.  If not enough data is available
P
Per Liden 已提交
1975 1976 1977 1978
 * will optionally wait for more; never truncates data.
 *
 * Returns size of returned message data, errno otherwise
 */
1979 1980
static int tipc_recvstream(struct socket *sock, struct msghdr *m,
			   size_t buflen, int flags)
P
Per Liden 已提交
1981
{
1982
	struct sock *sk = sock->sk;
1983
	struct tipc_sock *tsk = tipc_sk(sk);
1984 1985 1986 1987 1988 1989 1990
	struct sk_buff *skb;
	struct tipc_msg *hdr;
	struct tipc_skb_cb *skb_cb;
	bool peek = flags & MSG_PEEK;
	int offset, required, copy, copied = 0;
	int hlen, dlen, err, rc;
	long timeout;
P
Per Liden 已提交
1991

1992
	/* Catch invalid receive attempts */
1993
	if (unlikely(!buflen))
P
Per Liden 已提交
1994 1995
		return -EINVAL;

1996
	lock_sock(sk);
P
Per Liden 已提交
1997

1998
	if (unlikely(sk->sk_state == TIPC_OPEN)) {
1999
		rc = -ENOTCONN;
Y
Ying Xue 已提交
2000
		goto exit;
P
Per Liden 已提交
2001
	}
2002 2003
	required = sock_rcvlowat(sk, flags & MSG_WAITALL, buflen);
	timeout = sock_rcvtimeo(sk, flags & MSG_DONTWAIT);
P
Per Liden 已提交
2004

2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015
	do {
		/* Look at first msg in receive queue; wait if necessary */
		rc = tipc_wait_for_rcvmsg(sock, &timeout);
		if (unlikely(rc))
			break;
		skb = skb_peek(&sk->sk_receive_queue);
		skb_cb = TIPC_SKB_CB(skb);
		hdr = buf_msg(skb);
		dlen = msg_data_sz(hdr);
		hlen = msg_hdr_sz(hdr);
		err = msg_errcode(hdr);
2016

2017 2018 2019 2020 2021
		/* Discard any empty non-errored (SYN-) message */
		if (unlikely(!dlen && !err)) {
			tsk_advance_rx_queue(sk);
			continue;
		}
2022

2023 2024
		/* Collect msg meta data, incl. error code and rejected data */
		if (!copied) {
2025
			tipc_sk_set_orig_addr(m, skb);
2026
			rc = tipc_sk_anc_data_recv(m, skb, tsk);
2027 2028
			if (rc)
				break;
2029
			hdr = buf_msg(skb);
2030
		}
P
Per Liden 已提交
2031

2032 2033 2034 2035 2036 2037 2038 2039 2040 2041 2042 2043 2044 2045 2046 2047 2048 2049 2050 2051
		/* Copy data if msg ok, otherwise return error/partial data */
		if (likely(!err)) {
			offset = skb_cb->bytes_read;
			copy = min_t(int, dlen - offset, buflen - copied);
			rc = skb_copy_datagram_msg(skb, hlen + offset, m, copy);
			if (unlikely(rc))
				break;
			copied += copy;
			offset += copy;
			if (unlikely(offset < dlen)) {
				if (!peek)
					skb_cb->bytes_read = offset;
				break;
			}
		} else {
			rc = 0;
			if ((err != TIPC_CONN_SHUTDOWN) && !m->msg_control)
				rc = -ECONNRESET;
			if (copied || rc)
				break;
P
Per Liden 已提交
2052 2053
		}

2054 2055
		if (unlikely(peek))
			break;
P
Per Liden 已提交
2056

2057
		tsk_advance_rx_queue(sk);
2058

2059 2060
		/* Send connection flow control advertisement when applicable */
		tsk->rcv_unacked += tsk_inc(tsk, hlen + dlen);
2061
		if (tsk->rcv_unacked >= tsk->rcv_win / TIPC_ACK_RATE)
2062
			tipc_sk_send_ack(tsk);
P
Per Liden 已提交
2063

2064 2065 2066
		/* Exit if all requested data or FIN/error received */
		if (copied == buflen || err)
			break;
P
Per Liden 已提交
2067

2068
	} while (!skb_queue_empty(&sk->sk_receive_queue) || copied < required);
P
Per Liden 已提交
2069
exit:
2070
	release_sock(sk);
2071
	return copied ? copied : rc;
P
Per Liden 已提交
2072 2073
}

2074 2075 2076 2077 2078 2079 2080 2081 2082 2083
/**
 * tipc_write_space - wake up thread if port congestion is released
 * @sk: socket
 */
static void tipc_write_space(struct sock *sk)
{
	struct socket_wq *wq;

	rcu_read_lock();
	wq = rcu_dereference(sk->sk_wq);
H
Herbert Xu 已提交
2084
	if (skwq_has_sleeper(wq))
2085 2086
		wake_up_interruptible_sync_poll(&wq->wait, EPOLLOUT |
						EPOLLWRNORM | EPOLLWRBAND);
2087 2088 2089 2090 2091 2092 2093 2094
	rcu_read_unlock();
}

/**
 * tipc_data_ready - wake up threads to indicate messages have been received
 * @sk: socket
 * @len: the length of messages
 */
2095
static void tipc_data_ready(struct sock *sk)
2096 2097 2098 2099 2100
{
	struct socket_wq *wq;

	rcu_read_lock();
	wq = rcu_dereference(sk->sk_wq);
H
Herbert Xu 已提交
2101
	if (skwq_has_sleeper(wq))
2102 2103
		wake_up_interruptible_sync_poll(&wq->wait, EPOLLIN |
						EPOLLRDNORM | EPOLLRDBAND);
2104 2105 2106
	rcu_read_unlock();
}

2107 2108 2109 2110 2111
static void tipc_sock_destruct(struct sock *sk)
{
	__skb_queue_purge(&sk->sk_receive_queue);
}

J
Jon Maloy 已提交
2112 2113 2114 2115 2116 2117 2118
static void tipc_sk_proto_rcv(struct sock *sk,
			      struct sk_buff_head *inputq,
			      struct sk_buff_head *xmitq)
{
	struct sk_buff *skb = __skb_dequeue(inputq);
	struct tipc_sock *tsk = tipc_sk(sk);
	struct tipc_msg *hdr = buf_msg(skb);
J
Jon Maloy 已提交
2119
	struct tipc_group *grp = tsk->group;
2120
	bool wakeup = false;
J
Jon Maloy 已提交
2121 2122 2123

	switch (msg_user(hdr)) {
	case CONN_MANAGER:
2124
		tipc_sk_conn_proto_rcv(tsk, skb, inputq, xmitq);
J
Jon Maloy 已提交
2125 2126
		return;
	case SOCK_WAKEUP:
J
Jon Maloy 已提交
2127
		tipc_dest_del(&tsk->cong_links, msg_orignode(hdr), 0);
2128 2129
		/* coupled with smp_rmb() in tipc_wait_for_cond() */
		smp_wmb();
J
Jon Maloy 已提交
2130
		tsk->cong_link_cnt--;
2131
		wakeup = true;
2132
		tipc_sk_push_backlog(tsk, false);
J
Jon Maloy 已提交
2133
		break;
J
Jon Maloy 已提交
2134
	case GROUP_PROTOCOL:
2135
		tipc_group_proto_rcv(grp, &wakeup, hdr, inputq, xmitq);
J
Jon Maloy 已提交
2136
		break;
J
Jon Maloy 已提交
2137
	case TOP_SRV:
2138
		tipc_group_member_evt(tsk->group, &wakeup, &sk->sk_rcvbuf,
2139
				      hdr, inputq, xmitq);
J
Jon Maloy 已提交
2140 2141 2142 2143 2144
		break;
	default:
		break;
	}

2145 2146 2147
	if (wakeup)
		sk->sk_write_space(sk);

J
Jon Maloy 已提交
2148 2149 2150
	kfree_skb(skb);
}

2151
/**
2152
 * tipc_sk_filter_connect - check incoming message for a connection-based socket
2153
 * @tsk: TIPC socket
2154
 * @skb: pointer to message buffer.
2155
 * @xmitq: for Nagle ACK if any
2156
 * Returns true if message should be added to receive queue, false otherwise
2157
 */
2158 2159
static bool tipc_sk_filter_connect(struct tipc_sock *tsk, struct sk_buff *skb,
				   struct sk_buff_head *xmitq)
2160
{
2161
	struct sock *sk = &tsk->sk;
2162
	struct net *net = sock_net(sk);
2163
	struct tipc_msg *hdr = buf_msg(skb);
2164 2165 2166 2167 2168 2169
	bool con_msg = msg_connected(hdr);
	u32 pport = tsk_peer_port(tsk);
	u32 pnode = tsk_peer_node(tsk);
	u32 oport = msg_origport(hdr);
	u32 onode = msg_orignode(hdr);
	int err = msg_errcode(hdr);
2170
	unsigned long delay;
2171

2172 2173
	if (unlikely(msg_mcast(hdr)))
		return false;
J
Jon Maloy 已提交
2174
	tsk->oneway = 0;
2175

2176 2177
	switch (sk->sk_state) {
	case TIPC_CONNECTING:
2178 2179 2180 2181 2182 2183 2184 2185 2186 2187
		/* Setup ACK */
		if (likely(con_msg)) {
			if (err)
				break;
			tipc_sk_finish_conn(tsk, oport, onode);
			msg_set_importance(&tsk->phdr, msg_importance(hdr));
			/* ACK+ message with data is added to receive queue */
			if (msg_data_sz(hdr))
				return true;
			/* Empty ACK-, - wake up sleeping connect() and drop */
2188
			sk->sk_state_change(sk);
2189 2190
			msg_set_dest_droppable(hdr, 1);
			return false;
2191
		}
2192 2193 2194
		/* Ignore connectionless message if not from listening socket */
		if (oport != pport || onode != pnode)
			return false;
2195

2196 2197 2198 2199 2200 2201 2202 2203 2204 2205 2206 2207
		/* Rejected SYN */
		if (err != TIPC_ERR_OVERLOAD)
			break;

		/* Prepare for new setup attempt if we have a SYN clone */
		if (skb_queue_empty(&sk->sk_write_queue))
			break;
		get_random_bytes(&delay, 2);
		delay %= (tsk->conn_timeout / 4);
		delay = msecs_to_jiffies(delay + 100);
		sk_reset_timer(sk, &sk->sk_timer, jiffies + delay);
		return false;
2208
	case TIPC_OPEN:
2209
	case TIPC_DISCONNECTING:
2210
		return false;
2211
	case TIPC_LISTEN:
2212
		/* Accept only SYN message */
2213 2214 2215
		if (!msg_is_syn(hdr) &&
		    tipc_node_get_capabilities(net, onode) & TIPC_SYN_BIT)
			return false;
2216
		if (!con_msg && !err)
2217
			return true;
2218
		return false;
2219
	case TIPC_ESTABLISHED:
J
Jon Maloy 已提交
2220
		if (!skb_queue_empty(&sk->sk_write_queue))
2221
			tipc_sk_push_backlog(tsk, false);
2222
		/* Accept only connection-based messages sent by peer */
2223 2224 2225 2226 2227 2228
		if (likely(con_msg && !err && pport == oport &&
			   pnode == onode)) {
			if (msg_ack_required(hdr)) {
				struct sk_buff *skb;

				skb = tipc_sk_build_ack(tsk);
2229 2230
				if (skb) {
					msg_set_nagle_ack(buf_msg(skb));
2231
					__skb_queue_tail(xmitq, skb);
2232
				}
2233
			}
2234
			return true;
2235
		}
2236
		if (!tsk_peer_msg(tsk, hdr))
2237
			return false;
2238 2239 2240 2241 2242
		if (!err)
			return true;
		tipc_set_sk_state(sk, TIPC_DISCONNECTING);
		tipc_node_remove_conn(net, pnode, tsk->portid);
		sk->sk_state_change(sk);
2243
		return true;
2244
	default:
2245
		pr_err("Unknown sk_state %u\n", sk->sk_state);
2246
	}
2247 2248 2249 2250 2251
	/* Abort connection setup attempt */
	tipc_set_sk_state(sk, TIPC_DISCONNECTING);
	sk->sk_err = ECONNREFUSED;
	sk->sk_state_change(sk);
	return true;
2252 2253
}

2254 2255 2256
/**
 * rcvbuf_limit - get proper overload limit of socket receive queue
 * @sk: socket
2257
 * @skb: message
2258
 *
2259 2260
 * For connection oriented messages, irrespective of importance,
 * default queue limit is 2 MB.
2261
 *
2262 2263
 * For connectionless messages, queue limits are based on message
 * importance as follows:
2264
 *
2265 2266 2267 2268
 * TIPC_LOW_IMPORTANCE       (2 MB)
 * TIPC_MEDIUM_IMPORTANCE    (4 MB)
 * TIPC_HIGH_IMPORTANCE      (8 MB)
 * TIPC_CRITICAL_IMPORTANCE  (16 MB)
2269 2270 2271
 *
 * Returns overload limit according to corresponding message importance
 */
2272
static unsigned int rcvbuf_limit(struct sock *sk, struct sk_buff *skb)
2273
{
2274 2275 2276
	struct tipc_sock *tsk = tipc_sk(sk);
	struct tipc_msg *hdr = buf_msg(skb);

2277
	if (unlikely(msg_in_group(hdr)))
2278
		return READ_ONCE(sk->sk_rcvbuf);
2279

2280
	if (unlikely(!msg_connected(hdr)))
2281
		return READ_ONCE(sk->sk_rcvbuf) << msg_importance(hdr);
2282

2283
	if (likely(tsk->peer_caps & TIPC_BLOCK_FLOWCTL))
2284
		return READ_ONCE(sk->sk_rcvbuf);
2285

2286
	return FLOWCTL_MSG_LIM;
2287 2288
}

2289
/**
J
Jon Maloy 已提交
2290
 * tipc_sk_filter_rcv - validate incoming message
2291
 * @sk: socket
2292
 * @skb: pointer to message.
2293
 *
2294 2295 2296
 * Enqueues message on receive queue if acceptable; optionally handles
 * disconnect indication for a connected socket.
 *
2297
 * Called with socket lock already taken
2298
 *
P
Per Liden 已提交
2299
 */
J
Jon Maloy 已提交
2300 2301
static void tipc_sk_filter_rcv(struct sock *sk, struct sk_buff *skb,
			       struct sk_buff_head *xmitq)
P
Per Liden 已提交
2302
{
J
Jon Maloy 已提交
2303
	bool sk_conn = !tipc_sk_type_connectionless(sk);
2304
	struct tipc_sock *tsk = tipc_sk(sk);
J
Jon Maloy 已提交
2305
	struct tipc_group *grp = tsk->group;
2306
	struct tipc_msg *hdr = buf_msg(skb);
J
Jon Maloy 已提交
2307 2308
	struct net *net = sock_net(sk);
	struct sk_buff_head inputq;
2309
	int mtyp = msg_type(hdr);
J
Jon Maloy 已提交
2310
	int limit, err = TIPC_OK;
2311

2312
	trace_tipc_sk_filter_rcv(sk, skb, TIPC_DUMP_ALL, " ");
J
Jon Maloy 已提交
2313 2314 2315
	TIPC_SKB_CB(skb)->bytes_read = 0;
	__skb_queue_head_init(&inputq);
	__skb_queue_tail(&inputq, skb);
2316

J
Jon Maloy 已提交
2317 2318
	if (unlikely(!msg_isdata(hdr)))
		tipc_sk_proto_rcv(sk, &inputq, xmitq);
2319

J
Jon Maloy 已提交
2320 2321 2322
	if (unlikely(grp))
		tipc_group_filter_msg(grp, &inputq, xmitq);

2323
	if (unlikely(!grp) && mtyp == TIPC_MCAST_MSG)
H
Hoang Le 已提交
2324
		tipc_mcast_filter_msg(net, &tsk->mc_method.deferredq, &inputq);
2325

J
Jon Maloy 已提交
2326 2327 2328 2329
	/* Validate and add to receive buffer if there is space */
	while ((skb = __skb_dequeue(&inputq))) {
		hdr = buf_msg(skb);
		limit = rcvbuf_limit(sk, skb);
2330
		if ((sk_conn && !tipc_sk_filter_connect(tsk, skb, xmitq)) ||
J
Jon Maloy 已提交
2331 2332
		    (!sk_conn && msg_connected(hdr)) ||
		    (!grp && msg_in_group(hdr)))
2333
			err = TIPC_ERR_NO_PORT;
2334
		else if (sk_rmem_alloc_get(sk) + skb->truesize >= limit) {
2335 2336
			trace_tipc_sk_dump(sk, skb, TIPC_DUMP_ALL,
					   "err_overload2!");
2337
			atomic_inc(&sk->sk_drops);
J
Jon Maloy 已提交
2338
			err = TIPC_ERR_OVERLOAD;
2339
		}
P
Per Liden 已提交
2340

J
Jon Maloy 已提交
2341
		if (unlikely(err)) {
2342 2343 2344 2345 2346
			if (tipc_msg_reverse(tipc_own_addr(net), &skb, err)) {
				trace_tipc_sk_rej_msg(sk, skb, TIPC_DUMP_NONE,
						      "@filter_rcv!");
				__skb_queue_tail(xmitq, skb);
			}
J
Jon Maloy 已提交
2347 2348 2349 2350 2351
			err = TIPC_OK;
			continue;
		}
		__skb_queue_tail(&sk->sk_receive_queue, skb);
		skb_set_owner_r(skb, sk);
2352 2353
		trace_tipc_sk_overlimit2(sk, skb, TIPC_DUMP_ALL,
					 "rcvq >90% allocated!");
J
Jon Maloy 已提交
2354
		sk->sk_data_ready(sk);
2355
	}
2356
}
P
Per Liden 已提交
2357

2358
/**
J
Jon Maloy 已提交
2359
 * tipc_sk_backlog_rcv - handle incoming message from backlog queue
2360
 * @sk: socket
2361
 * @skb: message
2362
 *
2363
 * Caller must hold socket lock
2364
 */
J
Jon Maloy 已提交
2365
static int tipc_sk_backlog_rcv(struct sock *sk, struct sk_buff *skb)
2366
{
J
Jon Maloy 已提交
2367
	unsigned int before = sk_rmem_alloc_get(sk);
J
Jon Paul Maloy 已提交
2368
	struct sk_buff_head xmitq;
J
Jon Maloy 已提交
2369
	unsigned int added;
2370

J
Jon Paul Maloy 已提交
2371 2372
	__skb_queue_head_init(&xmitq);

J
Jon Maloy 已提交
2373 2374 2375
	tipc_sk_filter_rcv(sk, skb, &xmitq);
	added = sk_rmem_alloc_get(sk) - before;
	atomic_add(added, &tipc_sk(sk)->dupl_rcvcnt);
J
Jon Paul Maloy 已提交
2376

J
Jon Maloy 已提交
2377
	/* Send pending response/rejected messages, if any */
2378
	tipc_node_distr_xmit(sock_net(sk), &xmitq);
2379 2380 2381
	return 0;
}

2382
/**
2383 2384 2385 2386 2387
 * tipc_sk_enqueue - extract all buffers with destination 'dport' from
 *                   inputq and try adding them to socket or backlog queue
 * @inputq: list of incoming buffers with potentially different destinations
 * @sk: socket where the buffers should be enqueued
 * @dport: port number for the socket
2388 2389 2390
 *
 * Caller must hold socket lock
 */
2391
static void tipc_sk_enqueue(struct sk_buff_head *inputq, struct sock *sk,
J
Jon Paul Maloy 已提交
2392
			    u32 dport, struct sk_buff_head *xmitq)
2393
{
J
Jon Paul Maloy 已提交
2394 2395
	unsigned long time_limit = jiffies + 2;
	struct sk_buff *skb;
2396 2397
	unsigned int lim;
	atomic_t *dcnt;
J
Jon Paul Maloy 已提交
2398
	u32 onode;
2399 2400

	while (skb_queue_len(inputq)) {
2401
		if (unlikely(time_after_eq(jiffies, time_limit)))
2402 2403
			return;

2404 2405
		skb = tipc_skb_dequeue(inputq, dport);
		if (unlikely(!skb))
2406 2407 2408
			return;

		/* Add message directly to receive queue if possible */
2409
		if (!sock_owned_by_user(sk)) {
J
Jon Maloy 已提交
2410
			tipc_sk_filter_rcv(sk, skb, xmitq);
2411
			continue;
2412
		}
2413 2414

		/* Try backlog, compensating for double-counted bytes */
2415
		dcnt = &tipc_sk(sk)->dupl_rcvcnt;
2416
		if (!sk->sk_backlog.len)
2417 2418
			atomic_set(dcnt, 0);
		lim = rcvbuf_limit(sk, skb) + atomic_read(dcnt);
2419 2420 2421
		if (likely(!sk_add_backlog(sk, skb, lim))) {
			trace_tipc_sk_overlimit1(sk, skb, TIPC_DUMP_ALL,
						 "bklg & rcvq >90% allocated!");
2422
			continue;
2423
		}
2424

2425
		trace_tipc_sk_dump(sk, skb, TIPC_DUMP_ALL, "err_overload!");
2426
		/* Overload => reject message back to sender */
J
Jon Paul Maloy 已提交
2427
		onode = tipc_own_addr(sock_net(sk));
2428
		atomic_inc(&sk->sk_drops);
2429 2430 2431
		if (tipc_msg_reverse(onode, &skb, TIPC_ERR_OVERLOAD)) {
			trace_tipc_sk_rej_msg(sk, skb, TIPC_DUMP_ALL,
					      "@sk_enqueue!");
J
Jon Paul Maloy 已提交
2432
			__skb_queue_tail(xmitq, skb);
2433
		}
2434
		break;
2435
	}
2436 2437
}

2438
/**
2439 2440 2441 2442
 * tipc_sk_rcv - handle a chain of incoming buffers
 * @inputq: buffer list containing the buffers
 * Consumes all buffers in list until inputq is empty
 * Note: may be called in multiple threads referring to the same queue
2443
 */
2444
void tipc_sk_rcv(struct net *net, struct sk_buff_head *inputq)
2445
{
J
Jon Paul Maloy 已提交
2446
	struct sk_buff_head xmitq;
2447
	u32 dnode, dport = 0;
E
Erik Hugne 已提交
2448
	int err;
2449 2450
	struct tipc_sock *tsk;
	struct sock *sk;
2451
	struct sk_buff *skb;
2452

J
Jon Paul Maloy 已提交
2453
	__skb_queue_head_init(&xmitq);
2454 2455 2456
	while (skb_queue_len(inputq)) {
		dport = tipc_skb_peek_port(inputq, dport);
		tsk = tipc_sk_lookup(net, dport);
2457

2458 2459 2460
		if (likely(tsk)) {
			sk = &tsk->sk;
			if (likely(spin_trylock_bh(&sk->sk_lock.slock))) {
J
Jon Paul Maloy 已提交
2461
				tipc_sk_enqueue(inputq, sk, dport, &xmitq);
2462 2463
				spin_unlock_bh(&sk->sk_lock.slock);
			}
J
Jon Paul Maloy 已提交
2464
			/* Send pending response/rejected messages, if any */
2465
			tipc_node_distr_xmit(sock_net(sk), &xmitq);
2466 2467 2468
			sock_put(sk);
			continue;
		}
2469 2470 2471 2472 2473 2474 2475 2476 2477 2478 2479 2480
		/* No destination socket => dequeue skb if still there */
		skb = tipc_skb_dequeue(inputq, dport);
		if (!skb)
			return;

		/* Try secondary lookup if unresolved named message */
		err = TIPC_ERR_NO_PORT;
		if (tipc_msg_lookup_dest(net, skb, &err))
			goto xmit;

		/* Prepare for message rejection */
		if (!tipc_msg_reverse(tipc_own_addr(net), &skb, err))
2481
			continue;
2482 2483

		trace_tipc_sk_rej_msg(NULL, skb, TIPC_DUMP_NONE, "@sk_rcv!");
2484
xmit:
2485
		dnode = msg_destnode(buf_msg(skb));
2486
		tipc_node_xmit_skb(net, skb, dnode, dport);
2487
	}
P
Per Liden 已提交
2488 2489
}

Y
Ying Xue 已提交
2490 2491
static int tipc_wait_for_connect(struct socket *sock, long *timeo_p)
{
W
WANG Cong 已提交
2492
	DEFINE_WAIT_FUNC(wait, woken_wake_function);
Y
Ying Xue 已提交
2493 2494 2495 2496 2497 2498 2499 2500 2501 2502 2503
	struct sock *sk = sock->sk;
	int done;

	do {
		int err = sock_error(sk);
		if (err)
			return err;
		if (!*timeo_p)
			return -ETIMEDOUT;
		if (signal_pending(current))
			return sock_intr_errno(*timeo_p);
2504 2505
		if (sk->sk_state == TIPC_DISCONNECTING)
			break;
Y
Ying Xue 已提交
2506

W
WANG Cong 已提交
2507
		add_wait_queue(sk_sleep(sk), &wait);
2508 2509
		done = sk_wait_event(sk, timeo_p, tipc_sk_connected(sk),
				     &wait);
W
WANG Cong 已提交
2510
		remove_wait_queue(sk_sleep(sk), &wait);
Y
Ying Xue 已提交
2511 2512 2513 2514
	} while (!done);
	return 0;
}

2515 2516 2517 2518 2519 2520 2521 2522 2523 2524
static bool tipc_sockaddr_is_sane(struct sockaddr_tipc *addr)
{
	if (addr->family != AF_TIPC)
		return false;
	if (addr->addrtype == TIPC_SERVICE_RANGE)
		return (addr->addr.nameseq.lower <= addr->addr.nameseq.upper);
	return (addr->addrtype == TIPC_SERVICE_ADDR ||
		addr->addrtype == TIPC_SOCKET_ADDR);
}

P
Per Liden 已提交
2525
/**
2526
 * tipc_connect - establish a connection to another TIPC port
P
Per Liden 已提交
2527 2528 2529
 * @sock: socket structure
 * @dest: socket address for destination port
 * @destlen: size of socket address data structure
2530
 * @flags: file-related flags associated with socket
P
Per Liden 已提交
2531 2532 2533
 *
 * Returns 0 on success, errno otherwise
 */
2534 2535
static int tipc_connect(struct socket *sock, struct sockaddr *dest,
			int destlen, int flags)
P
Per Liden 已提交
2536
{
2537
	struct sock *sk = sock->sk;
2538
	struct tipc_sock *tsk = tipc_sk(sk);
2539 2540
	struct sockaddr_tipc *dst = (struct sockaddr_tipc *)dest;
	struct msghdr m = {NULL,};
2541
	long timeout = (flags & O_NONBLOCK) ? 0 : tsk->conn_timeout;
2542
	int previous;
2543
	int res = 0;
2544

2545 2546 2547
	if (destlen != sizeof(struct sockaddr_tipc))
		return -EINVAL;

2548 2549
	lock_sock(sk);

J
Jon Maloy 已提交
2550 2551 2552 2553 2554
	if (tsk->group) {
		res = -EINVAL;
		goto exit;
	}

2555 2556 2557
	if (dst->family == AF_UNSPEC) {
		memset(&tsk->peer, 0, sizeof(struct sockaddr_tipc));
		if (!tipc_sk_type_connectionless(sk))
2558
			res = -EINVAL;
2559 2560
		goto exit;
	}
2561
	if (!tipc_sockaddr_is_sane(dst)) {
2562
		res = -EINVAL;
2563
		goto exit;
2564
	}
2565 2566 2567
	/* DGRAM/RDM connect(), just save the destaddr */
	if (tipc_sk_type_connectionless(sk)) {
		memcpy(&tsk->peer, dest, destlen);
2568
		goto exit;
2569 2570 2571
	} else if (dst->addrtype == TIPC_SERVICE_RANGE) {
		res = -EINVAL;
		goto exit;
2572 2573
	}

2574
	previous = sk->sk_state;
2575 2576 2577

	switch (sk->sk_state) {
	case TIPC_OPEN:
2578 2579 2580 2581 2582 2583 2584 2585 2586 2587
		/* Send a 'SYN-' to destination */
		m.msg_name = dest;
		m.msg_namelen = destlen;

		/* If connect is in non-blocking case, set MSG_DONTWAIT to
		 * indicate send_msg() is never blocked.
		 */
		if (!timeout)
			m.msg_flags = MSG_DONTWAIT;

2588
		res = __tipc_sendmsg(sock, &m, 0);
2589 2590 2591
		if ((res < 0) && (res != -EWOULDBLOCK))
			goto exit;

2592
		/* Just entered TIPC_CONNECTING state; the only
2593 2594 2595 2596
		 * difference is that return value in non-blocking
		 * case is EINPROGRESS, rather than EALREADY.
		 */
		res = -EINPROGRESS;
2597
		/* fall through */
2598 2599 2600 2601
	case TIPC_CONNECTING:
		if (!timeout) {
			if (previous == TIPC_CONNECTING)
				res = -EALREADY;
Y
Ying Xue 已提交
2602
			goto exit;
2603
		}
Y
Ying Xue 已提交
2604 2605 2606
		timeout = msecs_to_jiffies(timeout);
		/* Wait until an 'ACK' or 'RST' arrives, or a timeout occurs */
		res = tipc_wait_for_connect(sock, &timeout);
2607 2608
		break;
	case TIPC_ESTABLISHED:
2609
		res = -EISCONN;
2610 2611
		break;
	default:
2612
		res = -EINVAL;
2613
	}
2614

2615 2616
exit:
	release_sock(sk);
2617
	return res;
P
Per Liden 已提交
2618 2619
}

2620
/**
2621
 * tipc_listen - allow socket to listen for incoming connections
P
Per Liden 已提交
2622 2623
 * @sock: socket structure
 * @len: (unused)
2624
 *
P
Per Liden 已提交
2625 2626
 * Returns 0 on success, errno otherwise
 */
2627
static int tipc_listen(struct socket *sock, int len)
P
Per Liden 已提交
2628
{
2629 2630 2631 2632
	struct sock *sk = sock->sk;
	int res;

	lock_sock(sk);
2633
	res = tipc_set_sk_state(sk, TIPC_LISTEN);
2634
	release_sock(sk);
2635

2636
	return res;
P
Per Liden 已提交
2637 2638
}

Y
Ying Xue 已提交
2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650 2651 2652
static int tipc_wait_for_accept(struct socket *sock, long timeo)
{
	struct sock *sk = sock->sk;
	DEFINE_WAIT(wait);
	int err;

	/* True wake-one mechanism for incoming connections: only
	 * one process gets woken up, not the 'whole herd'.
	 * Since we do not 'race & poll' for established sockets
	 * anymore, the common case will execute the loop only once.
	*/
	for (;;) {
		prepare_to_wait_exclusive(sk_sleep(sk), &wait,
					  TASK_INTERRUPTIBLE);
2653
		if (timeo && skb_queue_empty(&sk->sk_receive_queue)) {
Y
Ying Xue 已提交
2654 2655 2656 2657 2658 2659 2660 2661 2662 2663
			release_sock(sk);
			timeo = schedule_timeout(timeo);
			lock_sock(sk);
		}
		err = 0;
		if (!skb_queue_empty(&sk->sk_receive_queue))
			break;
		err = -EAGAIN;
		if (!timeo)
			break;
2664 2665 2666
		err = sock_intr_errno(timeo);
		if (signal_pending(current))
			break;
Y
Ying Xue 已提交
2667 2668 2669 2670 2671
	}
	finish_wait(sk_sleep(sk), &wait);
	return err;
}

2672
/**
2673
 * tipc_accept - wait for connection request
P
Per Liden 已提交
2674 2675 2676
 * @sock: listening socket
 * @newsock: new socket that is to be connected
 * @flags: file-related flags associated with socket
2677
 *
P
Per Liden 已提交
2678 2679
 * Returns 0 on success, errno otherwise
 */
2680 2681
static int tipc_accept(struct socket *sock, struct socket *new_sock, int flags,
		       bool kern)
P
Per Liden 已提交
2682
{
2683
	struct sock *new_sk, *sk = sock->sk;
P
Per Liden 已提交
2684
	struct sk_buff *buf;
2685
	struct tipc_sock *new_tsock;
2686
	struct tipc_msg *msg;
Y
Ying Xue 已提交
2687
	long timeo;
2688
	int res;
P
Per Liden 已提交
2689

2690
	lock_sock(sk);
P
Per Liden 已提交
2691

2692
	if (sk->sk_state != TIPC_LISTEN) {
2693
		res = -EINVAL;
P
Per Liden 已提交
2694 2695
		goto exit;
	}
Y
Ying Xue 已提交
2696 2697 2698 2699
	timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
	res = tipc_wait_for_accept(sock, timeo);
	if (res)
		goto exit;
2700 2701 2702

	buf = skb_peek(&sk->sk_receive_queue);

2703
	res = tipc_sk_create(sock_net(sock->sk), new_sock, 0, kern);
2704 2705
	if (res)
		goto exit;
2706
	security_sk_clone(sock->sk, new_sock->sk);
P
Per Liden 已提交
2707

2708
	new_sk = new_sock->sk;
2709
	new_tsock = tipc_sk(new_sk);
2710
	msg = buf_msg(buf);
P
Per Liden 已提交
2711

2712 2713 2714 2715 2716 2717 2718
	/* we lock on new_sk; but lockdep sees the lock on sk */
	lock_sock_nested(new_sk, SINGLE_DEPTH_NESTING);

	/*
	 * Reject any stray messages received by new socket
	 * before the socket lock was taken (very, very unlikely)
	 */
2719
	tsk_rej_rx_queue(new_sk, TIPC_ERR_NO_PORT);
2720 2721

	/* Connect new socket to it's peer */
2722
	tipc_sk_finish_conn(new_tsock, msg_origport(msg), msg_orignode(msg));
2723

2724
	tsk_set_importance(new_sk, msg_importance(msg));
2725
	if (msg_named(msg)) {
2726 2727
		new_tsock->conn_type = msg_nametype(msg);
		new_tsock->conn_instance = msg_nameinst(msg);
P
Per Liden 已提交
2728
	}
2729 2730 2731 2732 2733 2734 2735 2736

	/*
	 * Respond to 'SYN-' by discarding it & returning 'ACK'-.
	 * Respond to 'SYN+' by queuing it on new socket.
	 */
	if (!msg_data_sz(msg)) {
		struct msghdr m = {NULL,};

2737
		tsk_advance_rx_queue(sk);
2738
		__tipc_sendstream(new_sock, &m, 0);
2739 2740 2741
	} else {
		__skb_dequeue(&sk->sk_receive_queue);
		__skb_queue_head(&new_sk->sk_receive_queue, buf);
2742
		skb_set_owner_r(buf, new_sk);
2743 2744
	}
	release_sock(new_sk);
P
Per Liden 已提交
2745
exit:
2746
	release_sock(sk);
P
Per Liden 已提交
2747 2748 2749 2750
	return res;
}

/**
2751
 * tipc_shutdown - shutdown socket connection
P
Per Liden 已提交
2752
 * @sock: socket structure
2753
 * @how: direction to close (must be SHUT_RDWR)
P
Per Liden 已提交
2754 2755
 *
 * Terminates connection (if necessary), then purges socket's receive queue.
2756
 *
P
Per Liden 已提交
2757 2758
 * Returns 0 on success, errno otherwise
 */
2759
static int tipc_shutdown(struct socket *sock, int how)
P
Per Liden 已提交
2760
{
2761
	struct sock *sk = sock->sk;
P
Per Liden 已提交
2762 2763
	int res;

2764 2765
	if (how != SHUT_RDWR)
		return -EINVAL;
P
Per Liden 已提交
2766

2767
	lock_sock(sk);
P
Per Liden 已提交
2768

2769
	trace_tipc_sk_shutdown(sk, NULL, TIPC_DUMP_ALL, " ");
2770 2771
	__tipc_shutdown(sock, TIPC_CONN_SHUTDOWN);
	sk->sk_shutdown = SEND_SHUTDOWN;
P
Per Liden 已提交
2772

2773
	if (sk->sk_state == TIPC_DISCONNECTING) {
2774
		/* Discard any unreceived messages */
2775
		__skb_queue_purge(&sk->sk_receive_queue);
2776 2777 2778

		/* Wake up anyone sleeping in poll */
		sk->sk_state_change(sk);
P
Per Liden 已提交
2779
		res = 0;
2780
	} else {
P
Per Liden 已提交
2781 2782 2783
		res = -ENOTCONN;
	}

2784
	release_sock(sk);
P
Per Liden 已提交
2785 2786 2787
	return res;
}

2788 2789 2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802 2803 2804 2805 2806 2807 2808 2809 2810 2811 2812 2813
static void tipc_sk_check_probing_state(struct sock *sk,
					struct sk_buff_head *list)
{
	struct tipc_sock *tsk = tipc_sk(sk);
	u32 pnode = tsk_peer_node(tsk);
	u32 pport = tsk_peer_port(tsk);
	u32 self = tsk_own_node(tsk);
	u32 oport = tsk->portid;
	struct sk_buff *skb;

	if (tsk->probe_unacked) {
		tipc_set_sk_state(sk, TIPC_DISCONNECTING);
		sk->sk_err = ECONNABORTED;
		tipc_node_remove_conn(sock_net(sk), pnode, pport);
		sk->sk_state_change(sk);
		return;
	}
	/* Prepare new probe */
	skb = tipc_msg_create(CONN_MANAGER, CONN_PROBE, INT_H_SIZE, 0,
			      pnode, self, pport, oport, TIPC_OK);
	if (skb)
		__skb_queue_tail(list, skb);
	tsk->probe_unacked = true;
	sk_reset_timer(sk, &sk->sk_timer, jiffies + CONN_PROBING_INTV);
}

2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826
static void tipc_sk_retry_connect(struct sock *sk, struct sk_buff_head *list)
{
	struct tipc_sock *tsk = tipc_sk(sk);

	/* Try again later if dest link is congested */
	if (tsk->cong_link_cnt) {
		sk_reset_timer(sk, &sk->sk_timer, msecs_to_jiffies(100));
		return;
	}
	/* Prepare SYN for retransmit */
	tipc_msg_skb_clone(&sk->sk_write_queue, list);
}

2827
static void tipc_sk_timeout(struct timer_list *t)
2828
{
2829 2830
	struct sock *sk = from_timer(sk, t, sk_timer);
	struct tipc_sock *tsk = tipc_sk(sk);
2831 2832
	u32 pnode = tsk_peer_node(tsk);
	struct sk_buff_head list;
2833
	int rc = 0;
2834

2835
	__skb_queue_head_init(&list);
J
Jon Paul Maloy 已提交
2836
	bh_lock_sock(sk);
2837 2838 2839 2840

	/* Try again later if socket is busy */
	if (sock_owned_by_user(sk)) {
		sk_reset_timer(sk, &sk->sk_timer, jiffies + HZ / 20);
2841
		bh_unlock_sock(sk);
2842
		sock_put(sk);
2843
		return;
2844 2845
	}

2846 2847
	if (sk->sk_state == TIPC_ESTABLISHED)
		tipc_sk_check_probing_state(sk, &list);
2848 2849
	else if (sk->sk_state == TIPC_CONNECTING)
		tipc_sk_retry_connect(sk, &list);
2850

2851
	bh_unlock_sock(sk);
2852 2853

	if (!skb_queue_empty(&list))
2854
		rc = tipc_node_xmit(sock_net(sk), &list, pnode, tsk->portid);
2855

2856 2857 2858 2859 2860
	/* SYN messages may cause link congestion */
	if (rc == -ELINKCONG) {
		tipc_dest_push(&tsk->cong_links, pnode, 0);
		tsk->cong_link_cnt = 1;
	}
2861
	sock_put(sk);
2862 2863
}

2864
static int tipc_sk_publish(struct tipc_sock *tsk, uint scope,
J
Jon Paul Maloy 已提交
2865 2866
			   struct tipc_name_seq const *seq)
{
2867 2868
	struct sock *sk = &tsk->sk;
	struct net *net = sock_net(sk);
J
Jon Paul Maloy 已提交
2869 2870 2871
	struct publication *publ;
	u32 key;

J
Jon Maloy 已提交
2872 2873 2874
	if (scope != TIPC_NODE_SCOPE)
		scope = TIPC_CLUSTER_SCOPE;

2875
	if (tipc_sk_connected(sk))
J
Jon Paul Maloy 已提交
2876
		return -EINVAL;
2877 2878
	key = tsk->portid + tsk->pub_count + 1;
	if (key == tsk->portid)
J
Jon Paul Maloy 已提交
2879 2880
		return -EADDRINUSE;

2881
	publ = tipc_nametbl_publish(net, seq->type, seq->lower, seq->upper,
2882
				    scope, tsk->portid, key);
J
Jon Paul Maloy 已提交
2883 2884 2885
	if (unlikely(!publ))
		return -EINVAL;

J
Jon Maloy 已提交
2886
	list_add(&publ->binding_sock, &tsk->publications);
2887 2888
	tsk->pub_count++;
	tsk->published = 1;
J
Jon Paul Maloy 已提交
2889 2890 2891
	return 0;
}

2892
static int tipc_sk_withdraw(struct tipc_sock *tsk, uint scope,
J
Jon Paul Maloy 已提交
2893 2894
			    struct tipc_name_seq const *seq)
{
2895
	struct net *net = sock_net(&tsk->sk);
J
Jon Paul Maloy 已提交
2896 2897 2898 2899
	struct publication *publ;
	struct publication *safe;
	int rc = -EINVAL;

J
Jon Maloy 已提交
2900 2901 2902
	if (scope != TIPC_NODE_SCOPE)
		scope = TIPC_CLUSTER_SCOPE;

J
Jon Maloy 已提交
2903
	list_for_each_entry_safe(publ, safe, &tsk->publications, binding_sock) {
J
Jon Paul Maloy 已提交
2904 2905 2906 2907 2908 2909 2910 2911 2912
		if (seq) {
			if (publ->scope != scope)
				continue;
			if (publ->type != seq->type)
				continue;
			if (publ->lower != seq->lower)
				continue;
			if (publ->upper != seq->upper)
				break;
2913
			tipc_nametbl_withdraw(net, publ->type, publ->lower,
2914
					      publ->upper, publ->key);
J
Jon Paul Maloy 已提交
2915 2916 2917
			rc = 0;
			break;
		}
2918
		tipc_nametbl_withdraw(net, publ->type, publ->lower,
2919
				      publ->upper, publ->key);
J
Jon Paul Maloy 已提交
2920 2921
		rc = 0;
	}
2922 2923
	if (list_empty(&tsk->publications))
		tsk->published = 0;
J
Jon Paul Maloy 已提交
2924 2925 2926
	return rc;
}

2927 2928 2929
/* tipc_sk_reinit: set non-zero address in all existing sockets
 *                 when we go from standalone to network mode.
 */
2930
void tipc_sk_reinit(struct net *net)
2931
{
2932
	struct tipc_net *tn = net_generic(net, tipc_net_id);
2933
	struct rhashtable_iter iter;
2934
	struct tipc_sock *tsk;
2935 2936
	struct tipc_msg *msg;

2937 2938 2939
	rhashtable_walk_enter(&tn->sk_rht, &iter);

	do {
2940
		rhashtable_walk_start(&iter);
2941 2942

		while ((tsk = rhashtable_walk_next(&iter)) && !IS_ERR(tsk)) {
2943 2944 2945
			sock_hold(&tsk->sk);
			rhashtable_walk_stop(&iter);
			lock_sock(&tsk->sk);
2946
			msg = &tsk->phdr;
2947 2948
			msg_set_prevnode(msg, tipc_own_addr(net));
			msg_set_orignode(msg, tipc_own_addr(net));
2949 2950 2951
			release_sock(&tsk->sk);
			rhashtable_walk_start(&iter);
			sock_put(&tsk->sk);
2952
		}
2953

2954 2955
		rhashtable_walk_stop(&iter);
	} while (tsk == ERR_PTR(-EAGAIN));
2956 2957

	rhashtable_walk_exit(&iter);
2958 2959
}

2960
static struct tipc_sock *tipc_sk_lookup(struct net *net, u32 portid)
2961
{
2962
	struct tipc_net *tn = net_generic(net, tipc_net_id);
2963
	struct tipc_sock *tsk;
2964

2965
	rcu_read_lock();
2966
	tsk = rhashtable_lookup(&tn->sk_rht, &portid, tsk_rht_params);
2967 2968 2969
	if (tsk)
		sock_hold(&tsk->sk);
	rcu_read_unlock();
2970

2971
	return tsk;
2972 2973
}

2974
static int tipc_sk_insert(struct tipc_sock *tsk)
2975
{
2976 2977 2978
	struct sock *sk = &tsk->sk;
	struct net *net = sock_net(sk);
	struct tipc_net *tn = net_generic(net, tipc_net_id);
2979 2980
	u32 remaining = (TIPC_MAX_PORT - TIPC_MIN_PORT) + 1;
	u32 portid = prandom_u32() % remaining + TIPC_MIN_PORT;
2981

2982 2983 2984 2985 2986 2987
	while (remaining--) {
		portid++;
		if ((portid < TIPC_MIN_PORT) || (portid > TIPC_MAX_PORT))
			portid = TIPC_MIN_PORT;
		tsk->portid = portid;
		sock_hold(&tsk->sk);
2988 2989
		if (!rhashtable_lookup_insert_fast(&tn->sk_rht, &tsk->node,
						   tsk_rht_params))
2990 2991
			return 0;
		sock_put(&tsk->sk);
2992 2993
	}

2994
	return -1;
2995 2996
}

2997
static void tipc_sk_remove(struct tipc_sock *tsk)
2998
{
2999
	struct sock *sk = &tsk->sk;
3000
	struct tipc_net *tn = net_generic(sock_net(sk), tipc_net_id);
3001

3002
	if (!rhashtable_remove_fast(&tn->sk_rht, &tsk->node, tsk_rht_params)) {
3003
		WARN_ON(refcount_read(&sk->sk_refcnt) == 1);
3004
		__sock_put(sk);
3005 3006 3007
	}
}

3008 3009 3010 3011 3012 3013 3014
static const struct rhashtable_params tsk_rht_params = {
	.nelem_hint = 192,
	.head_offset = offsetof(struct tipc_sock, node),
	.key_offset = offsetof(struct tipc_sock, portid),
	.key_len = sizeof(u32), /* portid */
	.max_size = 1048576,
	.min_size = 256,
3015
	.automatic_shrinking = true,
3016 3017
};

3018
int tipc_sk_rht_init(struct net *net)
3019
{
3020
	struct tipc_net *tn = net_generic(net, tipc_net_id);
3021 3022

	return rhashtable_init(&tn->sk_rht, &tsk_rht_params);
3023 3024
}

3025
void tipc_sk_rht_destroy(struct net *net)
3026
{
3027 3028
	struct tipc_net *tn = net_generic(net, tipc_net_id);

3029 3030
	/* Wait for socket readers to complete */
	synchronize_net();
3031

3032
	rhashtable_destroy(&tn->sk_rht);
3033 3034
}

J
Jon Maloy 已提交
3035 3036 3037 3038 3039 3040 3041 3042 3043 3044
static int tipc_sk_join(struct tipc_sock *tsk, struct tipc_group_req *mreq)
{
	struct net *net = sock_net(&tsk->sk);
	struct tipc_group *grp = tsk->group;
	struct tipc_msg *hdr = &tsk->phdr;
	struct tipc_name_seq seq;
	int rc;

	if (mreq->type < TIPC_RESERVED_TYPES)
		return -EACCES;
3045 3046
	if (mreq->scope > TIPC_NODE_SCOPE)
		return -EINVAL;
J
Jon Maloy 已提交
3047 3048
	if (grp)
		return -EACCES;
3049
	grp = tipc_group_create(net, tsk->portid, mreq, &tsk->group_is_open);
J
Jon Maloy 已提交
3050 3051 3052 3053 3054 3055 3056 3057 3058
	if (!grp)
		return -ENOMEM;
	tsk->group = grp;
	msg_set_lookup_scope(hdr, mreq->scope);
	msg_set_nametype(hdr, mreq->type);
	msg_set_dest_droppable(hdr, true);
	seq.type = mreq->type;
	seq.lower = mreq->instance;
	seq.upper = seq.lower;
3059
	tipc_nametbl_build_group(net, grp, mreq->type, mreq->scope);
J
Jon Maloy 已提交
3060
	rc = tipc_sk_publish(tsk, mreq->scope, &seq);
C
Cong Wang 已提交
3061
	if (rc) {
J
Jon Maloy 已提交
3062
		tipc_group_delete(net, grp);
C
Cong Wang 已提交
3063
		tsk->group = NULL;
3064
		return rc;
C
Cong Wang 已提交
3065
	}
3066
	/* Eliminate any risk that a broadcast overtakes sent JOINs */
3067 3068
	tsk->mc_method.rcast = true;
	tsk->mc_method.mandatory = true;
3069
	tipc_group_join(net, grp, &tsk->sk.sk_rcvbuf);
J
Jon Maloy 已提交
3070 3071 3072 3073 3074 3075 3076 3077 3078 3079 3080 3081 3082 3083 3084 3085 3086 3087 3088
	return rc;
}

static int tipc_sk_leave(struct tipc_sock *tsk)
{
	struct net *net = sock_net(&tsk->sk);
	struct tipc_group *grp = tsk->group;
	struct tipc_name_seq seq;
	int scope;

	if (!grp)
		return -EINVAL;
	tipc_group_self(grp, &seq, &scope);
	tipc_group_delete(net, grp);
	tsk->group = NULL;
	tipc_sk_withdraw(tsk, scope, &seq);
	return 0;
}

P
Per Liden 已提交
3089
/**
3090
 * tipc_setsockopt - set socket option
P
Per Liden 已提交
3091 3092 3093 3094 3095
 * @sock: socket structure
 * @lvl: option level
 * @opt: option identifier
 * @ov: pointer to new option value
 * @ol: length of option value
3096 3097
 *
 * For stream sockets only, accepts and ignores all IPPROTO_TCP options
P
Per Liden 已提交
3098
 * (to ease compatibility).
3099
 *
P
Per Liden 已提交
3100 3101
 * Returns 0 on success, errno otherwise
 */
3102 3103
static int tipc_setsockopt(struct socket *sock, int lvl, int opt,
			   char __user *ov, unsigned int ol)
P
Per Liden 已提交
3104
{
3105
	struct sock *sk = sock->sk;
3106
	struct tipc_sock *tsk = tipc_sk(sk);
J
Jon Maloy 已提交
3107
	struct tipc_group_req mreq;
3108
	u32 value = 0;
3109
	int res = 0;
P
Per Liden 已提交
3110

3111 3112
	if ((lvl == IPPROTO_TCP) && (sock->type == SOCK_STREAM))
		return 0;
P
Per Liden 已提交
3113 3114
	if (lvl != SOL_TIPC)
		return -ENOPROTOOPT;
3115 3116 3117 3118 3119 3120

	switch (opt) {
	case TIPC_IMPORTANCE:
	case TIPC_SRC_DROPPABLE:
	case TIPC_DEST_DROPPABLE:
	case TIPC_CONN_TIMEOUT:
J
Jon Maloy 已提交
3121
	case TIPC_NODELAY:
3122 3123
		if (ol < sizeof(value))
			return -EINVAL;
J
Jon Maloy 已提交
3124 3125 3126 3127 3128 3129 3130 3131
		if (get_user(value, (u32 __user *)ov))
			return -EFAULT;
		break;
	case TIPC_GROUP_JOIN:
		if (ol < sizeof(mreq))
			return -EINVAL;
		if (copy_from_user(&mreq, ov, sizeof(mreq)))
			return -EFAULT;
3132 3133 3134 3135 3136
		break;
	default:
		if (ov || ol)
			return -EINVAL;
	}
P
Per Liden 已提交
3137

3138
	lock_sock(sk);
3139

P
Per Liden 已提交
3140 3141
	switch (opt) {
	case TIPC_IMPORTANCE:
3142
		res = tsk_set_importance(sk, value);
P
Per Liden 已提交
3143 3144 3145
		break;
	case TIPC_SRC_DROPPABLE:
		if (sock->type != SOCK_STREAM)
3146
			tsk_set_unreliable(tsk, value);
3147
		else
P
Per Liden 已提交
3148 3149 3150
			res = -ENOPROTOOPT;
		break;
	case TIPC_DEST_DROPPABLE:
3151
		tsk_set_unreturnable(tsk, value);
P
Per Liden 已提交
3152 3153
		break;
	case TIPC_CONN_TIMEOUT:
3154
		tipc_sk(sk)->conn_timeout = value;
P
Per Liden 已提交
3155
		break;
3156 3157 3158 3159 3160 3161 3162 3163
	case TIPC_MCAST_BROADCAST:
		tsk->mc_method.rcast = false;
		tsk->mc_method.mandatory = true;
		break;
	case TIPC_MCAST_REPLICAST:
		tsk->mc_method.rcast = true;
		tsk->mc_method.mandatory = true;
		break;
J
Jon Maloy 已提交
3164 3165 3166 3167 3168 3169
	case TIPC_GROUP_JOIN:
		res = tipc_sk_join(tsk, &mreq);
		break;
	case TIPC_GROUP_LEAVE:
		res = tipc_sk_leave(tsk);
		break;
J
Jon Maloy 已提交
3170 3171 3172 3173
	case TIPC_NODELAY:
		tsk->nodelay = !!value;
		tsk_set_nagle(tsk);
		break;
P
Per Liden 已提交
3174 3175 3176 3177
	default:
		res = -EINVAL;
	}

3178 3179
	release_sock(sk);

P
Per Liden 已提交
3180 3181 3182 3183
	return res;
}

/**
3184
 * tipc_getsockopt - get socket option
P
Per Liden 已提交
3185 3186 3187 3188 3189
 * @sock: socket structure
 * @lvl: option level
 * @opt: option identifier
 * @ov: receptacle for option value
 * @ol: receptacle for length of option value
3190 3191
 *
 * For stream sockets only, returns 0 length result for all IPPROTO_TCP options
P
Per Liden 已提交
3192
 * (to ease compatibility).
3193
 *
P
Per Liden 已提交
3194 3195
 * Returns 0 on success, errno otherwise
 */
3196 3197
static int tipc_getsockopt(struct socket *sock, int lvl, int opt,
			   char __user *ov, int __user *ol)
P
Per Liden 已提交
3198
{
3199
	struct sock *sk = sock->sk;
3200
	struct tipc_sock *tsk = tipc_sk(sk);
J
Jon Maloy 已提交
3201 3202
	struct tipc_name_seq seq;
	int len, scope;
P
Per Liden 已提交
3203
	u32 value;
3204
	int res;
P
Per Liden 已提交
3205

3206 3207
	if ((lvl == IPPROTO_TCP) && (sock->type == SOCK_STREAM))
		return put_user(0, ol);
P
Per Liden 已提交
3208 3209
	if (lvl != SOL_TIPC)
		return -ENOPROTOOPT;
3210 3211
	res = get_user(len, ol);
	if (res)
3212
		return res;
P
Per Liden 已提交
3213

3214
	lock_sock(sk);
P
Per Liden 已提交
3215 3216 3217

	switch (opt) {
	case TIPC_IMPORTANCE:
3218
		value = tsk_importance(tsk);
P
Per Liden 已提交
3219 3220
		break;
	case TIPC_SRC_DROPPABLE:
3221
		value = tsk_unreliable(tsk);
P
Per Liden 已提交
3222 3223
		break;
	case TIPC_DEST_DROPPABLE:
3224
		value = tsk_unreturnable(tsk);
P
Per Liden 已提交
3225 3226
		break;
	case TIPC_CONN_TIMEOUT:
3227
		value = tsk->conn_timeout;
3228
		/* no need to set "res", since already 0 at this point */
P
Per Liden 已提交
3229
		break;
3230
	case TIPC_NODE_RECVQ_DEPTH:
3231
		value = 0; /* was tipc_queue_size, now obsolete */
3232
		break;
3233
	case TIPC_SOCK_RECVQ_DEPTH:
3234 3235
		value = skb_queue_len(&sk->sk_receive_queue);
		break;
3236 3237 3238
	case TIPC_SOCK_RECVQ_USED:
		value = sk_rmem_alloc_get(sk);
		break;
J
Jon Maloy 已提交
3239 3240 3241 3242 3243 3244
	case TIPC_GROUP_JOIN:
		seq.type = 0;
		if (tsk->group)
			tipc_group_self(tsk->group, &seq, &scope);
		value = seq.type;
		break;
P
Per Liden 已提交
3245 3246 3247 3248
	default:
		res = -EINVAL;
	}

3249 3250
	release_sock(sk);

3251 3252
	if (res)
		return res;	/* "get" failed */
P
Per Liden 已提交
3253

3254 3255 3256 3257 3258 3259 3260
	if (len < sizeof(value))
		return -EINVAL;

	if (copy_to_user(ov, &value, sizeof(value)))
		return -EFAULT;

	return put_user(sizeof(value), ol);
P
Per Liden 已提交
3261 3262
}

3263
static int tipc_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
E
Erik Hugne 已提交
3264
{
3265 3266
	struct net *net = sock_net(sock->sk);
	struct tipc_sioc_nodeid_req nr = {0};
E
Erik Hugne 已提交
3267 3268 3269 3270 3271 3272 3273
	struct tipc_sioc_ln_req lnr;
	void __user *argp = (void __user *)arg;

	switch (cmd) {
	case SIOCGETLINKNAME:
		if (copy_from_user(&lnr, argp, sizeof(lnr)))
			return -EFAULT;
3274
		if (!tipc_node_get_linkname(net,
3275
					    lnr.bearer_id & 0xffff, lnr.peer,
E
Erik Hugne 已提交
3276 3277 3278 3279 3280 3281
					    lnr.linkname, TIPC_MAX_LINK_NAME)) {
			if (copy_to_user(argp, &lnr, sizeof(lnr)))
				return -EFAULT;
			return 0;
		}
		return -EADDRNOTAVAIL;
3282 3283 3284 3285 3286 3287 3288 3289
	case SIOCGETNODEID:
		if (copy_from_user(&nr, argp, sizeof(nr)))
			return -EFAULT;
		if (!tipc_node_get_id(net, nr.peer, nr.node_id))
			return -EADDRNOTAVAIL;
		if (copy_to_user(argp, &nr, sizeof(nr)))
			return -EFAULT;
		return 0;
E
Erik Hugne 已提交
3290 3291 3292 3293 3294
	default:
		return -ENOIOCTLCMD;
	}
}

3295 3296 3297 3298
static int tipc_socketpair(struct socket *sock1, struct socket *sock2)
{
	struct tipc_sock *tsk2 = tipc_sk(sock2->sk);
	struct tipc_sock *tsk1 = tipc_sk(sock1->sk);
E
Erik Hugne 已提交
3299 3300 3301 3302 3303 3304 3305 3306 3307 3308 3309 3310 3311 3312 3313
	u32 onode = tipc_own_addr(sock_net(sock1->sk));

	tsk1->peer.family = AF_TIPC;
	tsk1->peer.addrtype = TIPC_ADDR_ID;
	tsk1->peer.scope = TIPC_NODE_SCOPE;
	tsk1->peer.addr.id.ref = tsk2->portid;
	tsk1->peer.addr.id.node = onode;
	tsk2->peer.family = AF_TIPC;
	tsk2->peer.addrtype = TIPC_ADDR_ID;
	tsk2->peer.scope = TIPC_NODE_SCOPE;
	tsk2->peer.addr.id.ref = tsk1->portid;
	tsk2->peer.addr.id.node = onode;

	tipc_sk_finish_conn(tsk1, tsk2->portid, onode);
	tipc_sk_finish_conn(tsk2, tsk1->portid, onode);
3314 3315 3316
	return 0;
}

3317 3318
/* Protocol switches for the various types of TIPC sockets */

3319
static const struct proto_ops msg_ops = {
3320
	.owner		= THIS_MODULE,
P
Per Liden 已提交
3321
	.family		= AF_TIPC,
3322 3323 3324
	.release	= tipc_release,
	.bind		= tipc_bind,
	.connect	= tipc_connect,
E
Erik Hugne 已提交
3325
	.socketpair	= tipc_socketpair,
3326
	.accept		= sock_no_accept,
3327
	.getname	= tipc_getname,
3328
	.poll		= tipc_poll,
E
Erik Hugne 已提交
3329
	.ioctl		= tipc_ioctl,
3330
	.listen		= sock_no_listen,
3331 3332 3333 3334 3335
	.shutdown	= tipc_shutdown,
	.setsockopt	= tipc_setsockopt,
	.getsockopt	= tipc_getsockopt,
	.sendmsg	= tipc_sendmsg,
	.recvmsg	= tipc_recvmsg,
3336 3337
	.mmap		= sock_no_mmap,
	.sendpage	= sock_no_sendpage
P
Per Liden 已提交
3338 3339
};

3340
static const struct proto_ops packet_ops = {
3341
	.owner		= THIS_MODULE,
P
Per Liden 已提交
3342
	.family		= AF_TIPC,
3343 3344 3345
	.release	= tipc_release,
	.bind		= tipc_bind,
	.connect	= tipc_connect,
3346
	.socketpair	= tipc_socketpair,
3347 3348
	.accept		= tipc_accept,
	.getname	= tipc_getname,
3349
	.poll		= tipc_poll,
E
Erik Hugne 已提交
3350
	.ioctl		= tipc_ioctl,
3351 3352 3353 3354 3355 3356
	.listen		= tipc_listen,
	.shutdown	= tipc_shutdown,
	.setsockopt	= tipc_setsockopt,
	.getsockopt	= tipc_getsockopt,
	.sendmsg	= tipc_send_packet,
	.recvmsg	= tipc_recvmsg,
3357 3358
	.mmap		= sock_no_mmap,
	.sendpage	= sock_no_sendpage
P
Per Liden 已提交
3359 3360
};

3361
static const struct proto_ops stream_ops = {
3362
	.owner		= THIS_MODULE,
P
Per Liden 已提交
3363
	.family		= AF_TIPC,
3364 3365 3366
	.release	= tipc_release,
	.bind		= tipc_bind,
	.connect	= tipc_connect,
3367
	.socketpair	= tipc_socketpair,
3368 3369
	.accept		= tipc_accept,
	.getname	= tipc_getname,
3370
	.poll		= tipc_poll,
E
Erik Hugne 已提交
3371
	.ioctl		= tipc_ioctl,
3372 3373 3374 3375
	.listen		= tipc_listen,
	.shutdown	= tipc_shutdown,
	.setsockopt	= tipc_setsockopt,
	.getsockopt	= tipc_getsockopt,
3376
	.sendmsg	= tipc_sendstream,
3377
	.recvmsg	= tipc_recvstream,
3378 3379
	.mmap		= sock_no_mmap,
	.sendpage	= sock_no_sendpage
P
Per Liden 已提交
3380 3381
};

3382
static const struct net_proto_family tipc_family_ops = {
3383
	.owner		= THIS_MODULE,
P
Per Liden 已提交
3384
	.family		= AF_TIPC,
3385
	.create		= tipc_sk_create
P
Per Liden 已提交
3386 3387 3388 3389 3390
};

static struct proto tipc_proto = {
	.name		= "TIPC",
	.owner		= THIS_MODULE,
3391 3392
	.obj_size	= sizeof(struct tipc_sock),
	.sysctl_rmem	= sysctl_tipc_rmem
P
Per Liden 已提交
3393 3394 3395
};

/**
3396
 * tipc_socket_init - initialize TIPC socket interface
3397
 *
P
Per Liden 已提交
3398 3399
 * Returns 0 on success, errno otherwise
 */
3400
int tipc_socket_init(void)
P
Per Liden 已提交
3401 3402 3403
{
	int res;

3404
	res = proto_register(&tipc_proto, 1);
P
Per Liden 已提交
3405
	if (res) {
3406
		pr_err("Failed to register TIPC protocol type\n");
P
Per Liden 已提交
3407 3408 3409 3410 3411
		goto out;
	}

	res = sock_register(&tipc_family_ops);
	if (res) {
3412
		pr_err("Failed to register TIPC socket type\n");
P
Per Liden 已提交
3413 3414 3415 3416 3417 3418 3419 3420
		proto_unregister(&tipc_proto);
		goto out;
	}
 out:
	return res;
}

/**
3421
 * tipc_socket_stop - stop TIPC socket interface
P
Per Liden 已提交
3422
 */
3423
void tipc_socket_stop(void)
P
Per Liden 已提交
3424 3425 3426 3427
{
	sock_unregister(tipc_family_ops.family);
	proto_unregister(&tipc_proto);
}
3428 3429

/* Caller should hold socket lock for the passed tipc socket. */
3430
static int __tipc_nl_add_sk_con(struct sk_buff *skb, struct tipc_sock *tsk)
3431 3432 3433 3434 3435 3436 3437 3438
{
	u32 peer_node;
	u32 peer_port;
	struct nlattr *nest;

	peer_node = tsk_peer_node(tsk);
	peer_port = tsk_peer_port(tsk);

3439
	nest = nla_nest_start_noflag(skb, TIPC_NLA_SOCK_CON);
3440 3441
	if (!nest)
		return -EMSGSIZE;
3442 3443 3444 3445 3446 3447 3448 3449 3450 3451 3452 3453 3454 3455 3456 3457 3458 3459 3460 3461 3462 3463 3464 3465

	if (nla_put_u32(skb, TIPC_NLA_CON_NODE, peer_node))
		goto msg_full;
	if (nla_put_u32(skb, TIPC_NLA_CON_SOCK, peer_port))
		goto msg_full;

	if (tsk->conn_type != 0) {
		if (nla_put_flag(skb, TIPC_NLA_CON_FLAG))
			goto msg_full;
		if (nla_put_u32(skb, TIPC_NLA_CON_TYPE, tsk->conn_type))
			goto msg_full;
		if (nla_put_u32(skb, TIPC_NLA_CON_INST, tsk->conn_instance))
			goto msg_full;
	}
	nla_nest_end(skb, nest);

	return 0;

msg_full:
	nla_nest_cancel(skb, nest);

	return -EMSGSIZE;
}

3466 3467 3468 3469 3470 3471 3472
static int __tipc_nl_add_sk_info(struct sk_buff *skb, struct tipc_sock
			  *tsk)
{
	struct net *net = sock_net(skb->sk);
	struct sock *sk = &tsk->sk;

	if (nla_put_u32(skb, TIPC_NLA_SOCK_REF, tsk->portid) ||
3473
	    nla_put_u32(skb, TIPC_NLA_SOCK_ADDR, tipc_own_addr(net)))
3474 3475 3476 3477 3478 3479 3480 3481 3482 3483 3484 3485
		return -EMSGSIZE;

	if (tipc_sk_connected(sk)) {
		if (__tipc_nl_add_sk_con(skb, tsk))
			return -EMSGSIZE;
	} else if (!list_empty(&tsk->publications)) {
		if (nla_put_flag(skb, TIPC_NLA_SOCK_HAS_PUBL))
			return -EMSGSIZE;
	}
	return 0;
}

3486
/* Caller should hold socket lock for the passed tipc socket. */
3487 3488
static int __tipc_nl_add_sk(struct sk_buff *skb, struct netlink_callback *cb,
			    struct tipc_sock *tsk)
3489 3490
{
	struct nlattr *attrs;
3491
	void *hdr;
3492 3493

	hdr = genlmsg_put(skb, NETLINK_CB(cb->skb).portid, cb->nlh->nlmsg_seq,
3494
			  &tipc_genl_family, NLM_F_MULTI, TIPC_NL_SOCK_GET);
3495 3496 3497
	if (!hdr)
		goto msg_cancel;

3498
	attrs = nla_nest_start_noflag(skb, TIPC_NLA_SOCK);
3499 3500
	if (!attrs)
		goto genlmsg_cancel;
3501 3502

	if (__tipc_nl_add_sk_info(skb, tsk))
3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517
		goto attr_msg_cancel;

	nla_nest_end(skb, attrs);
	genlmsg_end(skb, hdr);

	return 0;

attr_msg_cancel:
	nla_nest_cancel(skb, attrs);
genlmsg_cancel:
	genlmsg_cancel(skb, hdr);
msg_cancel:
	return -EMSGSIZE;
}

3518 3519 3520 3521
int tipc_nl_sk_walk(struct sk_buff *skb, struct netlink_callback *cb,
		    int (*skb_handler)(struct sk_buff *skb,
				       struct netlink_callback *cb,
				       struct tipc_sock *tsk))
3522
{
3523
	struct rhashtable_iter *iter = (void *)cb->args[4];
3524 3525
	struct tipc_sock *tsk;
	int err;
3526

C
Cong Wang 已提交
3527 3528 3529 3530 3531 3532
	rhashtable_walk_start(iter);
	while ((tsk = rhashtable_walk_next(iter)) != NULL) {
		if (IS_ERR(tsk)) {
			err = PTR_ERR(tsk);
			if (err == -EAGAIN) {
				err = 0;
3533 3534
				continue;
			}
C
Cong Wang 已提交
3535 3536
			break;
		}
3537

C
Cong Wang 已提交
3538 3539 3540 3541 3542 3543 3544 3545
		sock_hold(&tsk->sk);
		rhashtable_walk_stop(iter);
		lock_sock(&tsk->sk);
		err = skb_handler(skb, cb, tsk);
		if (err) {
			release_sock(&tsk->sk);
			sock_put(&tsk->sk);
			goto out;
3546
		}
C
Cong Wang 已提交
3547 3548 3549
		release_sock(&tsk->sk);
		rhashtable_walk_start(iter);
		sock_put(&tsk->sk);
3550
	}
C
Cong Wang 已提交
3551
	rhashtable_walk_stop(iter);
3552
out:
3553 3554
	return skb->len;
}
3555 3556
EXPORT_SYMBOL(tipc_nl_sk_walk);

C
Cong Wang 已提交
3557 3558
int tipc_dump_start(struct netlink_callback *cb)
{
3559 3560 3561 3562 3563 3564 3565 3566
	return __tipc_dump_start(cb, sock_net(cb->skb->sk));
}
EXPORT_SYMBOL(tipc_dump_start);

int __tipc_dump_start(struct netlink_callback *cb, struct net *net)
{
	/* tipc_nl_name_table_dump() uses cb->args[0...3]. */
	struct rhashtable_iter *iter = (void *)cb->args[4];
C
Cong Wang 已提交
3567 3568 3569 3570 3571 3572 3573
	struct tipc_net *tn = tipc_net(net);

	if (!iter) {
		iter = kmalloc(sizeof(*iter), GFP_KERNEL);
		if (!iter)
			return -ENOMEM;

3574
		cb->args[4] = (long)iter;
C
Cong Wang 已提交
3575 3576 3577 3578 3579 3580 3581 3582
	}

	rhashtable_walk_enter(&tn->sk_rht, iter);
	return 0;
}

int tipc_dump_done(struct netlink_callback *cb)
{
3583
	struct rhashtable_iter *hti = (void *)cb->args[4];
C
Cong Wang 已提交
3584 3585 3586 3587 3588 3589 3590

	rhashtable_walk_exit(hti);
	kfree(hti);
	return 0;
}
EXPORT_SYMBOL(tipc_dump_done);

3591 3592
int tipc_sk_fill_sock_diag(struct sk_buff *skb, struct netlink_callback *cb,
			   struct tipc_sock *tsk, u32 sk_filter_state,
3593 3594 3595 3596 3597 3598 3599 3600 3601 3602
			   u64 (*tipc_diag_gen_cookie)(struct sock *sk))
{
	struct sock *sk = &tsk->sk;
	struct nlattr *attrs;
	struct nlattr *stat;

	/*filter response w.r.t sk_state*/
	if (!(sk_filter_state & (1 << sk->sk_state)))
		return 0;

3603
	attrs = nla_nest_start_noflag(skb, TIPC_NLA_SOCK);
3604 3605 3606 3607 3608 3609 3610 3611 3612 3613
	if (!attrs)
		goto msg_cancel;

	if (__tipc_nl_add_sk_info(skb, tsk))
		goto attr_msg_cancel;

	if (nla_put_u32(skb, TIPC_NLA_SOCK_TYPE, (u32)sk->sk_type) ||
	    nla_put_u32(skb, TIPC_NLA_SOCK_TIPC_STATE, (u32)sk->sk_state) ||
	    nla_put_u32(skb, TIPC_NLA_SOCK_INO, sock_i_ino(sk)) ||
	    nla_put_u32(skb, TIPC_NLA_SOCK_UID,
3614
			from_kuid_munged(sk_user_ns(NETLINK_CB(cb->skb).sk),
3615
					 sock_i_uid(sk))) ||
3616 3617 3618 3619 3620
	    nla_put_u64_64bit(skb, TIPC_NLA_SOCK_COOKIE,
			      tipc_diag_gen_cookie(sk),
			      TIPC_NLA_SOCK_PAD))
		goto attr_msg_cancel;

3621
	stat = nla_nest_start_noflag(skb, TIPC_NLA_SOCK_STAT);
3622 3623 3624 3625 3626 3627
	if (!stat)
		goto attr_msg_cancel;

	if (nla_put_u32(skb, TIPC_NLA_SOCK_STAT_RCVQ,
			skb_queue_len(&sk->sk_receive_queue)) ||
	    nla_put_u32(skb, TIPC_NLA_SOCK_STAT_SENDQ,
3628 3629 3630
			skb_queue_len(&sk->sk_write_queue)) ||
	    nla_put_u32(skb, TIPC_NLA_SOCK_STAT_DROP,
			atomic_read(&sk->sk_drops)))
3631 3632 3633 3634 3635 3636 3637 3638 3639 3640 3641
		goto stat_msg_cancel;

	if (tsk->cong_link_cnt &&
	    nla_put_flag(skb, TIPC_NLA_SOCK_STAT_LINK_CONG))
		goto stat_msg_cancel;

	if (tsk_conn_cong(tsk) &&
	    nla_put_flag(skb, TIPC_NLA_SOCK_STAT_CONN_CONG))
		goto stat_msg_cancel;

	nla_nest_end(skb, stat);
3642 3643 3644 3645 3646

	if (tsk->group)
		if (tipc_group_fill_sock_diag(tsk->group, skb))
			goto stat_msg_cancel;

3647 3648 3649 3650 3651 3652 3653 3654 3655 3656 3657 3658
	nla_nest_end(skb, attrs);

	return 0;

stat_msg_cancel:
	nla_nest_cancel(skb, stat);
attr_msg_cancel:
	nla_nest_cancel(skb, attrs);
msg_cancel:
	return -EMSGSIZE;
}
EXPORT_SYMBOL(tipc_sk_fill_sock_diag);
3659

3660 3661
int tipc_nl_sk_dump(struct sk_buff *skb, struct netlink_callback *cb)
{
3662
	return tipc_nl_sk_walk(skb, cb, __tipc_nl_add_sk);
3663 3664
}

3665
/* Caller should hold socket lock for the passed tipc socket. */
3666 3667 3668
static int __tipc_nl_add_sk_publ(struct sk_buff *skb,
				 struct netlink_callback *cb,
				 struct publication *publ)
3669 3670 3671 3672 3673
{
	void *hdr;
	struct nlattr *attrs;

	hdr = genlmsg_put(skb, NETLINK_CB(cb->skb).portid, cb->nlh->nlmsg_seq,
3674
			  &tipc_genl_family, NLM_F_MULTI, TIPC_NL_PUBL_GET);
3675 3676 3677
	if (!hdr)
		goto msg_cancel;

3678
	attrs = nla_nest_start_noflag(skb, TIPC_NLA_PUBL);
3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689 3690 3691 3692 3693 3694 3695 3696 3697 3698 3699 3700 3701 3702 3703 3704
	if (!attrs)
		goto genlmsg_cancel;

	if (nla_put_u32(skb, TIPC_NLA_PUBL_KEY, publ->key))
		goto attr_msg_cancel;
	if (nla_put_u32(skb, TIPC_NLA_PUBL_TYPE, publ->type))
		goto attr_msg_cancel;
	if (nla_put_u32(skb, TIPC_NLA_PUBL_LOWER, publ->lower))
		goto attr_msg_cancel;
	if (nla_put_u32(skb, TIPC_NLA_PUBL_UPPER, publ->upper))
		goto attr_msg_cancel;

	nla_nest_end(skb, attrs);
	genlmsg_end(skb, hdr);

	return 0;

attr_msg_cancel:
	nla_nest_cancel(skb, attrs);
genlmsg_cancel:
	genlmsg_cancel(skb, hdr);
msg_cancel:
	return -EMSGSIZE;
}

/* Caller should hold socket lock for the passed tipc socket. */
3705 3706 3707
static int __tipc_nl_list_sk_publ(struct sk_buff *skb,
				  struct netlink_callback *cb,
				  struct tipc_sock *tsk, u32 *last_publ)
3708 3709 3710 3711 3712
{
	int err;
	struct publication *p;

	if (*last_publ) {
J
Jon Maloy 已提交
3713
		list_for_each_entry(p, &tsk->publications, binding_sock) {
3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726 3727 3728 3729
			if (p->key == *last_publ)
				break;
		}
		if (p->key != *last_publ) {
			/* We never set seq or call nl_dump_check_consistent()
			 * this means that setting prev_seq here will cause the
			 * consistence check to fail in the netlink callback
			 * handler. Resulting in the last NLMSG_DONE message
			 * having the NLM_F_DUMP_INTR flag set.
			 */
			cb->prev_seq = 1;
			*last_publ = 0;
			return -EPIPE;
		}
	} else {
		p = list_first_entry(&tsk->publications, struct publication,
J
Jon Maloy 已提交
3730
				     binding_sock);
3731 3732
	}

J
Jon Maloy 已提交
3733
	list_for_each_entry_from(p, &tsk->publications, binding_sock) {
3734 3735 3736 3737 3738 3739 3740 3741 3742 3743 3744 3745 3746 3747
		err = __tipc_nl_add_sk_publ(skb, cb, p);
		if (err) {
			*last_publ = p->key;
			return err;
		}
	}
	*last_publ = 0;

	return 0;
}

int tipc_nl_publ_dump(struct sk_buff *skb, struct netlink_callback *cb)
{
	int err;
3748
	u32 tsk_portid = cb->args[0];
3749 3750
	u32 last_publ = cb->args[1];
	u32 done = cb->args[2];
3751
	struct net *net = sock_net(skb->sk);
3752 3753
	struct tipc_sock *tsk;

3754
	if (!tsk_portid) {
3755
		struct nlattr **attrs = genl_dumpit_info(cb)->attrs;
3756 3757
		struct nlattr *sock[TIPC_NLA_SOCK_MAX + 1];

3758 3759 3760
		if (!attrs[TIPC_NLA_SOCK])
			return -EINVAL;

3761 3762 3763
		err = nla_parse_nested_deprecated(sock, TIPC_NLA_SOCK_MAX,
						  attrs[TIPC_NLA_SOCK],
						  tipc_nl_sock_policy, NULL);
3764 3765 3766 3767 3768 3769
		if (err)
			return err;

		if (!sock[TIPC_NLA_SOCK_REF])
			return -EINVAL;

3770
		tsk_portid = nla_get_u32(sock[TIPC_NLA_SOCK_REF]);
3771 3772 3773 3774 3775
	}

	if (done)
		return 0;

3776
	tsk = tipc_sk_lookup(net, tsk_portid);
3777 3778 3779 3780 3781 3782 3783 3784
	if (!tsk)
		return -EINVAL;

	lock_sock(&tsk->sk);
	err = __tipc_nl_list_sk_publ(skb, cb, tsk, &last_publ);
	if (!err)
		done = 1;
	release_sock(&tsk->sk);
3785
	sock_put(&tsk->sk);
3786

3787
	cb->args[0] = tsk_portid;
3788 3789 3790 3791 3792
	cb->args[1] = last_publ;
	cb->args[2] = done;

	return skb->len;
}
T
Tuong Lien 已提交
3793

3794 3795 3796 3797 3798 3799 3800 3801 3802 3803 3804 3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818 3819 3820 3821 3822 3823 3824 3825 3826 3827 3828 3829 3830 3831 3832 3833 3834 3835 3836 3837 3838 3839 3840 3841 3842 3843 3844 3845 3846 3847 3848 3849 3850 3851 3852 3853
/**
 * tipc_sk_filtering - check if a socket should be traced
 * @sk: the socket to be examined
 * @sysctl_tipc_sk_filter[]: the socket tuple for filtering,
 *  (portid, sock type, name type, name lower, name upper)
 *
 * Returns true if the socket meets the socket tuple data
 * (value 0 = 'any') or when there is no tuple set (all = 0),
 * otherwise false
 */
bool tipc_sk_filtering(struct sock *sk)
{
	struct tipc_sock *tsk;
	struct publication *p;
	u32 _port, _sktype, _type, _lower, _upper;
	u32 type = 0, lower = 0, upper = 0;

	if (!sk)
		return true;

	tsk = tipc_sk(sk);

	_port = sysctl_tipc_sk_filter[0];
	_sktype = sysctl_tipc_sk_filter[1];
	_type = sysctl_tipc_sk_filter[2];
	_lower = sysctl_tipc_sk_filter[3];
	_upper = sysctl_tipc_sk_filter[4];

	if (!_port && !_sktype && !_type && !_lower && !_upper)
		return true;

	if (_port)
		return (_port == tsk->portid);

	if (_sktype && _sktype != sk->sk_type)
		return false;

	if (tsk->published) {
		p = list_first_entry_or_null(&tsk->publications,
					     struct publication, binding_sock);
		if (p) {
			type = p->type;
			lower = p->lower;
			upper = p->upper;
		}
	}

	if (!tipc_sk_type_connectionless(sk)) {
		type = tsk->conn_type;
		lower = tsk->conn_instance;
		upper = tsk->conn_instance;
	}

	if ((_type && _type != type) || (_lower && _lower != lower) ||
	    (_upper && _upper != upper))
		return false;

	return true;
}

T
Tuong Lien 已提交
3854 3855 3856 3857 3858
u32 tipc_sock_get_portid(struct sock *sk)
{
	return (sk) ? (tipc_sk(sk))->portid : 0;
}

3859 3860 3861 3862 3863 3864 3865 3866 3867 3868 3869 3870 3871 3872 3873 3874 3875 3876 3877 3878 3879 3880 3881 3882 3883 3884 3885 3886 3887 3888 3889 3890 3891 3892 3893
/**
 * tipc_sk_overlimit1 - check if socket rx queue is about to be overloaded,
 *			both the rcv and backlog queues are considered
 * @sk: tipc sk to be checked
 * @skb: tipc msg to be checked
 *
 * Returns true if the socket rx queue allocation is > 90%, otherwise false
 */

bool tipc_sk_overlimit1(struct sock *sk, struct sk_buff *skb)
{
	atomic_t *dcnt = &tipc_sk(sk)->dupl_rcvcnt;
	unsigned int lim = rcvbuf_limit(sk, skb) + atomic_read(dcnt);
	unsigned int qsize = sk->sk_backlog.len + sk_rmem_alloc_get(sk);

	return (qsize > lim * 90 / 100);
}

/**
 * tipc_sk_overlimit2 - check if socket rx queue is about to be overloaded,
 *			only the rcv queue is considered
 * @sk: tipc sk to be checked
 * @skb: tipc msg to be checked
 *
 * Returns true if the socket rx queue allocation is > 90%, otherwise false
 */

bool tipc_sk_overlimit2(struct sock *sk, struct sk_buff *skb)
{
	unsigned int lim = rcvbuf_limit(sk, skb);
	unsigned int qsize = sk_rmem_alloc_get(sk);

	return (qsize > lim * 90 / 100);
}

T
Tuong Lien 已提交
3894 3895 3896 3897 3898 3899 3900 3901 3902 3903 3904 3905 3906 3907 3908 3909 3910 3911 3912 3913 3914 3915 3916 3917 3918 3919 3920 3921 3922 3923 3924 3925 3926 3927 3928 3929 3930 3931 3932 3933 3934 3935 3936 3937 3938 3939 3940 3941 3942 3943 3944 3945 3946 3947 3948 3949 3950 3951 3952
/**
 * tipc_sk_dump - dump TIPC socket
 * @sk: tipc sk to be dumped
 * @dqueues: bitmask to decide if any socket queue to be dumped?
 *           - TIPC_DUMP_NONE: don't dump socket queues
 *           - TIPC_DUMP_SK_SNDQ: dump socket send queue
 *           - TIPC_DUMP_SK_RCVQ: dump socket rcv queue
 *           - TIPC_DUMP_SK_BKLGQ: dump socket backlog queue
 *           - TIPC_DUMP_ALL: dump all the socket queues above
 * @buf: returned buffer of dump data in format
 */
int tipc_sk_dump(struct sock *sk, u16 dqueues, char *buf)
{
	int i = 0;
	size_t sz = (dqueues) ? SK_LMAX : SK_LMIN;
	struct tipc_sock *tsk;
	struct publication *p;
	bool tsk_connected;

	if (!sk) {
		i += scnprintf(buf, sz, "sk data: (null)\n");
		return i;
	}

	tsk = tipc_sk(sk);
	tsk_connected = !tipc_sk_type_connectionless(sk);

	i += scnprintf(buf, sz, "sk data: %u", sk->sk_type);
	i += scnprintf(buf + i, sz - i, " %d", sk->sk_state);
	i += scnprintf(buf + i, sz - i, " %x", tsk_own_node(tsk));
	i += scnprintf(buf + i, sz - i, " %u", tsk->portid);
	i += scnprintf(buf + i, sz - i, " | %u", tsk_connected);
	if (tsk_connected) {
		i += scnprintf(buf + i, sz - i, " %x", tsk_peer_node(tsk));
		i += scnprintf(buf + i, sz - i, " %u", tsk_peer_port(tsk));
		i += scnprintf(buf + i, sz - i, " %u", tsk->conn_type);
		i += scnprintf(buf + i, sz - i, " %u", tsk->conn_instance);
	}
	i += scnprintf(buf + i, sz - i, " | %u", tsk->published);
	if (tsk->published) {
		p = list_first_entry_or_null(&tsk->publications,
					     struct publication, binding_sock);
		i += scnprintf(buf + i, sz - i, " %u", (p) ? p->type : 0);
		i += scnprintf(buf + i, sz - i, " %u", (p) ? p->lower : 0);
		i += scnprintf(buf + i, sz - i, " %u", (p) ? p->upper : 0);
	}
	i += scnprintf(buf + i, sz - i, " | %u", tsk->snd_win);
	i += scnprintf(buf + i, sz - i, " %u", tsk->rcv_win);
	i += scnprintf(buf + i, sz - i, " %u", tsk->max_pkt);
	i += scnprintf(buf + i, sz - i, " %x", tsk->peer_caps);
	i += scnprintf(buf + i, sz - i, " %u", tsk->cong_link_cnt);
	i += scnprintf(buf + i, sz - i, " %u", tsk->snt_unacked);
	i += scnprintf(buf + i, sz - i, " %u", tsk->rcv_unacked);
	i += scnprintf(buf + i, sz - i, " %u", atomic_read(&tsk->dupl_rcvcnt));
	i += scnprintf(buf + i, sz - i, " %u", sk->sk_shutdown);
	i += scnprintf(buf + i, sz - i, " | %d", sk_wmem_alloc_get(sk));
	i += scnprintf(buf + i, sz - i, " %d", sk->sk_sndbuf);
	i += scnprintf(buf + i, sz - i, " | %d", sk_rmem_alloc_get(sk));
	i += scnprintf(buf + i, sz - i, " %d", sk->sk_rcvbuf);
3953
	i += scnprintf(buf + i, sz - i, " | %d\n", READ_ONCE(sk->sk_backlog.len));
T
Tuong Lien 已提交
3954 3955 3956 3957 3958 3959 3960 3961 3962 3963 3964 3965 3966 3967 3968 3969 3970 3971 3972 3973 3974 3975 3976

	if (dqueues & TIPC_DUMP_SK_SNDQ) {
		i += scnprintf(buf + i, sz - i, "sk_write_queue: ");
		i += tipc_list_dump(&sk->sk_write_queue, false, buf + i);
	}

	if (dqueues & TIPC_DUMP_SK_RCVQ) {
		i += scnprintf(buf + i, sz - i, "sk_receive_queue: ");
		i += tipc_list_dump(&sk->sk_receive_queue, false, buf + i);
	}

	if (dqueues & TIPC_DUMP_SK_BKLGQ) {
		i += scnprintf(buf + i, sz - i, "sk_backlog:\n  head ");
		i += tipc_skb_dump(sk->sk_backlog.head, false, buf + i);
		if (sk->sk_backlog.tail != sk->sk_backlog.head) {
			i += scnprintf(buf + i, sz - i, "  tail ");
			i += tipc_skb_dump(sk->sk_backlog.tail, false,
					   buf + i);
		}
	}

	return i;
}