br2684.c 22.0 KB
Newer Older
L
Linus Torvalds 已提交
1
/*
2 3 4 5 6 7
 * Ethernet netdevice using ATM AAL5 as underlying carrier
 * (RFC1483 obsoleted by RFC2684) for Linux
 *
 * Authors: Marcell GAL, 2000, XDSL Ltd, Hungary
 *          Eric Kinzie, 2006-2007, US Naval Research Laboratory
 */
L
Linus Torvalds 已提交
8

9 10
#define pr_fmt(fmt) KBUILD_MODNAME ":%s: " fmt, __func__

L
Linus Torvalds 已提交
11 12 13 14 15 16 17 18 19
#include <linux/module.h>
#include <linux/init.h>
#include <linux/kernel.h>
#include <linux/list.h>
#include <linux/netdevice.h>
#include <linux/skbuff.h>
#include <linux/etherdevice.h>
#include <linux/rtnetlink.h>
#include <linux/ip.h>
20
#include <linux/uaccess.h>
21
#include <linux/slab.h>
L
Linus Torvalds 已提交
22 23 24
#include <net/arp.h>
#include <linux/atm.h>
#include <linux/atmdev.h>
25
#include <linux/capability.h>
L
Linus Torvalds 已提交
26 27 28 29 30 31 32 33
#include <linux/seq_file.h>

#include <linux/atmbr2684.h>

#include "common.h"

static void skb_debug(const struct sk_buff *skb)
{
34
#ifdef SKB_DEBUG
L
Linus Torvalds 已提交
35
#define NUM2PRINT 50
36 37
	print_hex_dump(KERN_DEBUG, "br2684: skb: ", DUMP_OFFSET,
		       16, 1, skb->data, min(NUM2PRINT, skb->len), true);
L
Linus Torvalds 已提交
38
#endif
39
}
L
Linus Torvalds 已提交
40

E
Eric Kinzie 已提交
41 42 43 44 45 46 47 48 49 50 51
#define BR2684_ETHERTYPE_LEN	2
#define BR2684_PAD_LEN		2

#define LLC		0xaa, 0xaa, 0x03
#define SNAP_BRIDGED	0x00, 0x80, 0xc2
#define SNAP_ROUTED	0x00, 0x00, 0x00
#define PID_ETHERNET	0x00, 0x07
#define ETHERTYPE_IPV4	0x08, 0x00
#define ETHERTYPE_IPV6	0x86, 0xdd
#define PAD_BRIDGED	0x00, 0x00

52 53 54
static const unsigned char ethertype_ipv4[] = { ETHERTYPE_IPV4 };
static const unsigned char ethertype_ipv6[] = { ETHERTYPE_IPV6 };
static const unsigned char llc_oui_pid_pad[] =
55
			{ LLC, SNAP_BRIDGED, PID_ETHERNET, PAD_BRIDGED };
56 57
static const unsigned char llc_oui_ipv4[] = { LLC, SNAP_ROUTED, ETHERTYPE_IPV4 };
static const unsigned char llc_oui_ipv6[] = { LLC, SNAP_ROUTED, ETHERTYPE_IPV6 };
L
Linus Torvalds 已提交
58 59

enum br2684_encaps {
60
	e_vc = BR2684_ENCAPS_VC,
L
Linus Torvalds 已提交
61 62 63 64
	e_llc = BR2684_ENCAPS_LLC,
};

struct br2684_vcc {
65
	struct atm_vcc *atmvcc;
L
Linus Torvalds 已提交
66
	struct net_device *device;
67
	/* keep old push, pop functions for chaining */
68
	void (*old_push)(struct atm_vcc *vcc, struct sk_buff *skb);
69
	void (*old_pop)(struct atm_vcc *vcc, struct sk_buff *skb);
L
Linus Torvalds 已提交
70 71 72 73 74 75 76 77 78 79 80 81
	enum br2684_encaps encaps;
	struct list_head brvccs;
#ifdef CONFIG_ATM_BR2684_IPFILTER
	struct br2684_filter filter;
#endif /* CONFIG_ATM_BR2684_IPFILTER */
	unsigned copies_needed, copies_failed;
};

struct br2684_dev {
	struct net_device *net_dev;
	struct list_head br2684_devs;
	int number;
82
	struct list_head brvccs;	/* one device <=> one vcc (before xmas) */
L
Linus Torvalds 已提交
83
	int mac_was_set;
E
Eric Kinzie 已提交
84
	enum br2684_payload payload;
L
Linus Torvalds 已提交
85 86 87 88 89 90 91 92 93 94 95 96 97 98 99
};

/*
 * This lock should be held for writing any time the list of devices or
 * their attached vcc's could be altered.  It should be held for reading
 * any time these are being queried.  Note that we sometimes need to
 * do read-locking under interrupt context, so write locking must block
 * the current CPU's interrupts
 */
static DEFINE_RWLOCK(devs_lock);

static LIST_HEAD(br2684_devs);

static inline struct br2684_dev *BRPRIV(const struct net_device *net_dev)
{
100
	return (struct br2684_dev *)netdev_priv(net_dev);
L
Linus Torvalds 已提交
101 102 103 104 105 106 107 108 109
}

static inline struct net_device *list_entry_brdev(const struct list_head *le)
{
	return list_entry(le, struct br2684_dev, br2684_devs)->net_dev;
}

static inline struct br2684_vcc *BR2684_VCC(const struct atm_vcc *atmvcc)
{
110
	return (struct br2684_vcc *)(atmvcc->user_back);
L
Linus Torvalds 已提交
111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141
}

static inline struct br2684_vcc *list_entry_brvcc(const struct list_head *le)
{
	return list_entry(le, struct br2684_vcc, brvccs);
}

/* Caller should hold read_lock(&devs_lock) */
static struct net_device *br2684_find_dev(const struct br2684_if_spec *s)
{
	struct list_head *lh;
	struct net_device *net_dev;
	switch (s->method) {
	case BR2684_FIND_BYNUM:
		list_for_each(lh, &br2684_devs) {
			net_dev = list_entry_brdev(lh);
			if (BRPRIV(net_dev)->number == s->spec.devnum)
				return net_dev;
		}
		break;
	case BR2684_FIND_BYIFNAME:
		list_for_each(lh, &br2684_devs) {
			net_dev = list_entry_brdev(lh);
			if (!strncmp(net_dev->name, s->spec.ifname, IFNAMSIZ))
				return net_dev;
		}
		break;
	}
	return NULL;
}

142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178
static int atm_dev_event(struct notifier_block *this, unsigned long event,
		 void *arg)
{
	struct atm_dev *atm_dev = arg;
	struct list_head *lh;
	struct net_device *net_dev;
	struct br2684_vcc *brvcc;
	struct atm_vcc *atm_vcc;
	unsigned long flags;

	pr_debug("event=%ld dev=%p\n", event, atm_dev);

	read_lock_irqsave(&devs_lock, flags);
	list_for_each(lh, &br2684_devs) {
		net_dev = list_entry_brdev(lh);

		list_for_each_entry(brvcc, &BRPRIV(net_dev)->brvccs, brvccs) {
			atm_vcc = brvcc->atmvcc;
			if (atm_vcc && brvcc->atmvcc->dev == atm_dev) {

				if (atm_vcc->dev->signal == ATM_PHY_SIG_LOST)
					netif_carrier_off(net_dev);
				else
					netif_carrier_on(net_dev);

			}
		}
	}
	read_unlock_irqrestore(&devs_lock, flags);

	return NOTIFY_DONE;
}

static struct notifier_block atm_dev_notifier = {
	.notifier_call = atm_dev_event,
};

179 180 181 182 183 184
/* chained vcc->pop function.  Check if we should wake the netif_queue */
static void br2684_pop(struct atm_vcc *vcc, struct sk_buff *skb)
{
	struct br2684_vcc *brvcc = BR2684_VCC(vcc);
	struct net_device *net_dev = skb->dev;

185
	pr_debug("(vcc %p ; net_dev %p )\n", vcc, net_dev);
186 187 188 189 190 191 192 193 194
	brvcc->old_pop(vcc, skb);

	if (!net_dev)
		return;

	if (atm_may_send(vcc, 0))
		netif_wake_queue(net_dev);

}
L
Linus Torvalds 已提交
195 196 197 198 199
/*
 * Send a packet out a particular vcc.  Not to useful right now, but paves
 * the way for multiple vcc's per itf.  Returns true if we can send,
 * otherwise false
 */
S
Stephen Hemminger 已提交
200
static int br2684_xmit_vcc(struct sk_buff *skb, struct net_device *dev,
201
			   struct br2684_vcc *brvcc)
L
Linus Torvalds 已提交
202
{
S
Stephen Hemminger 已提交
203
	struct br2684_dev *brdev = BRPRIV(dev);
L
Linus Torvalds 已提交
204 205
	struct atm_vcc *atmvcc;
	int minheadroom = (brvcc->encaps == e_llc) ? 10 : 2;
E
Eric Kinzie 已提交
206

L
Linus Torvalds 已提交
207 208 209 210 211 212 213 214 215 216
	if (skb_headroom(skb) < minheadroom) {
		struct sk_buff *skb2 = skb_realloc_headroom(skb, minheadroom);
		brvcc->copies_needed++;
		dev_kfree_skb(skb);
		if (skb2 == NULL) {
			brvcc->copies_failed++;
			return 0;
		}
		skb = skb2;
	}
E
Eric Kinzie 已提交
217 218 219 220

	if (brvcc->encaps == e_llc) {
		if (brdev->payload == p_bridged) {
			skb_push(skb, sizeof(llc_oui_pid_pad));
221 222
			skb_copy_to_linear_data(skb, llc_oui_pid_pad,
						sizeof(llc_oui_pid_pad));
E
Eric Kinzie 已提交
223 224 225 226 227
		} else if (brdev->payload == p_routed) {
			unsigned short prot = ntohs(skb->protocol);

			skb_push(skb, sizeof(llc_oui_ipv4));
			switch (prot) {
228 229 230 231 232 233 234 235 236 237 238
			case ETH_P_IP:
				skb_copy_to_linear_data(skb, llc_oui_ipv4,
							sizeof(llc_oui_ipv4));
				break;
			case ETH_P_IPV6:
				skb_copy_to_linear_data(skb, llc_oui_ipv6,
							sizeof(llc_oui_ipv6));
				break;
			default:
				dev_kfree_skb(skb);
				return 0;
E
Eric Kinzie 已提交
239 240
			}
		}
241 242 243
	} else { /* e_vc */
		if (brdev->payload == p_bridged) {
			skb_push(skb, 2);
E
Eric Kinzie 已提交
244
			memset(skb->data, 0, 2);
245 246 247
		} else { /* p_routed */
			skb_pull(skb, ETH_HLEN);
		}
E
Eric Kinzie 已提交
248
	}
L
Linus Torvalds 已提交
249 250 251
	skb_debug(skb);

	ATM_SKB(skb)->vcc = atmvcc = brvcc->atmvcc;
252
	pr_debug("atm_skb(%p)->vcc(%p)->dev(%p)\n", skb, atmvcc, atmvcc->dev);
L
Linus Torvalds 已提交
253 254
	atomic_add(skb->truesize, &sk_atm(atmvcc)->sk_wmem_alloc);
	ATM_SKB(skb)->atm_options = atmvcc->atm_options;
S
Stephen Hemminger 已提交
255 256
	dev->stats.tx_packets++;
	dev->stats.tx_bytes += skb->len;
L
Linus Torvalds 已提交
257
	atmvcc->send(atmvcc, skb);
258 259 260 261 262 263 264 265

	if (!atm_may_send(atmvcc, 0)) {
		netif_stop_queue(brvcc->device);
		/*check for race with br2684_pop*/
		if (atm_may_send(atmvcc, 0))
			netif_start_queue(brvcc->device);
	}

L
Linus Torvalds 已提交
266 267 268
	return 1;
}

269 270
static inline struct br2684_vcc *pick_outgoing_vcc(const struct sk_buff *skb,
						   const struct br2684_dev *brdev)
L
Linus Torvalds 已提交
271
{
272
	return list_empty(&brdev->brvccs) ? NULL : list_entry_brvcc(brdev->brvccs.next);	/* 1 vcc/dev right now */
L
Linus Torvalds 已提交
273 274
}

275 276
static netdev_tx_t br2684_start_xmit(struct sk_buff *skb,
				     struct net_device *dev)
L
Linus Torvalds 已提交
277 278 279 280
{
	struct br2684_dev *brdev = BRPRIV(dev);
	struct br2684_vcc *brvcc;

281
	pr_debug("skb_dst(skb)=%p\n", skb_dst(skb));
L
Linus Torvalds 已提交
282 283 284
	read_lock(&devs_lock);
	brvcc = pick_outgoing_vcc(skb, brdev);
	if (brvcc == NULL) {
285
		pr_debug("no vcc attached to dev %s\n", dev->name);
S
Stephen Hemminger 已提交
286 287
		dev->stats.tx_errors++;
		dev->stats.tx_carrier_errors++;
L
Linus Torvalds 已提交
288 289 290
		/* netif_stop_queue(dev); */
		dev_kfree_skb(skb);
		read_unlock(&devs_lock);
291
		return NETDEV_TX_OK;
L
Linus Torvalds 已提交
292
	}
S
Stephen Hemminger 已提交
293
	if (!br2684_xmit_vcc(skb, dev, brvcc)) {
L
Linus Torvalds 已提交
294 295 296
		/*
		 * We should probably use netif_*_queue() here, but that
		 * involves added complication.  We need to walk before
297 298 299
		 * we can run.
		 *
		 * Don't free here! this pointer might be no longer valid!
L
Linus Torvalds 已提交
300
		 */
S
Stephen Hemminger 已提交
301 302
		dev->stats.tx_errors++;
		dev->stats.tx_fifo_errors++;
L
Linus Torvalds 已提交
303 304
	}
	read_unlock(&devs_lock);
305
	return NETDEV_TX_OK;
L
Linus Torvalds 已提交
306 307 308 309 310 311 312 313
}

/*
 * We remember when the MAC gets set, so we don't override it later with
 * the ESI of the ATM card of the first VC
 */
static int br2684_mac_addr(struct net_device *dev, void *p)
{
314
	int err = eth_mac_addr(dev, p);
L
Linus Torvalds 已提交
315 316 317 318 319 320 321
	if (!err)
		BRPRIV(dev)->mac_was_set = 1;
	return err;
}

#ifdef CONFIG_ATM_BR2684_IPFILTER
/* this IOCTL is experimental. */
322
static int br2684_setfilt(struct atm_vcc *atmvcc, void __user * arg)
L
Linus Torvalds 已提交
323 324 325 326 327 328 329 330 331
{
	struct br2684_vcc *brvcc;
	struct br2684_filter_set fs;

	if (copy_from_user(&fs, arg, sizeof fs))
		return -EFAULT;
	if (fs.ifspec.method != BR2684_FIND_BYNOTHING) {
		/*
		 * This is really a per-vcc thing, but we can also search
332
		 * by device.
L
Linus Torvalds 已提交
333 334 335 336
		 */
		struct br2684_dev *brdev;
		read_lock(&devs_lock);
		brdev = BRPRIV(br2684_find_dev(&fs.ifspec));
337 338
		if (brdev == NULL || list_empty(&brdev->brvccs) ||
		    brdev->brvccs.next != brdev->brvccs.prev)	/* >1 VCC */
L
Linus Torvalds 已提交
339 340 341 342 343 344 345 346 347 348 349 350 351 352
			brvcc = NULL;
		else
			brvcc = list_entry_brvcc(brdev->brvccs.next);
		read_unlock(&devs_lock);
		if (brvcc == NULL)
			return -ESRCH;
	} else
		brvcc = BR2684_VCC(atmvcc);
	memcpy(&brvcc->filter, &fs.filter, sizeof(brvcc->filter));
	return 0;
}

/* Returns 1 if packet should be dropped */
static inline int
A
Al Viro 已提交
353
packet_fails_filter(__be16 type, struct br2684_vcc *brvcc, struct sk_buff *skb)
L
Linus Torvalds 已提交
354 355
{
	if (brvcc->filter.netmask == 0)
356
		return 0;	/* no filter in place */
357
	if (type == htons(ETH_P_IP) &&
358
	    (((struct iphdr *)(skb->data))->daddr & brvcc->filter.
L
Linus Torvalds 已提交
359 360
	     netmask) == brvcc->filter.prefix)
		return 0;
361
	if (type == htons(ETH_P_ARP))
L
Linus Torvalds 已提交
362
		return 0;
363 364 365
	/*
	 * TODO: we should probably filter ARPs too.. don't want to have
	 * them returning values that don't make sense, or is that ok?
L
Linus Torvalds 已提交
366 367 368 369 370 371 372
	 */
	return 1;		/* drop */
}
#endif /* CONFIG_ATM_BR2684_IPFILTER */

static void br2684_close_vcc(struct br2684_vcc *brvcc)
{
373
	pr_debug("removing VCC %p from dev %p\n", brvcc, brvcc->device);
L
Linus Torvalds 已提交
374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389
	write_lock_irq(&devs_lock);
	list_del(&brvcc->brvccs);
	write_unlock_irq(&devs_lock);
	brvcc->atmvcc->user_back = NULL;	/* what about vcc->recvq ??? */
	brvcc->old_push(brvcc->atmvcc, NULL);	/* pass on the bad news */
	kfree(brvcc);
	module_put(THIS_MODULE);
}

/* when AAL5 PDU comes in: */
static void br2684_push(struct atm_vcc *atmvcc, struct sk_buff *skb)
{
	struct br2684_vcc *brvcc = BR2684_VCC(atmvcc);
	struct net_device *net_dev = brvcc->device;
	struct br2684_dev *brdev = BRPRIV(net_dev);

390
	pr_debug("\n");
L
Linus Torvalds 已提交
391 392 393 394 395

	if (unlikely(skb == NULL)) {
		/* skb==NULL means VCC is being destroyed */
		br2684_close_vcc(brvcc);
		if (list_empty(&brdev->brvccs)) {
396
			write_lock_irq(&devs_lock);
L
Linus Torvalds 已提交
397
			list_del(&brdev->br2684_devs);
398
			write_unlock_irq(&devs_lock);
L
Linus Torvalds 已提交
399
			unregister_netdev(net_dev);
400
			free_netdev(net_dev);
L
Linus Torvalds 已提交
401
		}
402 403 404 405 406 407
		read_lock_irq(&devs_lock);
		if (list_empty(&br2684_devs)) {
			/* last br2684 device */
			unregister_atmdevice_notifier(&atm_dev_notifier);
		}
		read_unlock_irq(&devs_lock);
L
Linus Torvalds 已提交
408 409 410 411 412
		return;
	}

	skb_debug(skb);
	atm_return(atmvcc, skb->truesize);
413
	pr_debug("skb from brdev %p\n", brdev);
L
Linus Torvalds 已提交
414
	if (brvcc->encaps == e_llc) {
E
Eric Kinzie 已提交
415 416 417 418 419

		if (skb->len > 7 && skb->data[7] == 0x01)
			__skb_trim(skb, skb->len - 4);

		/* accept packets that have "ipv[46]" in the snap header */
420 421 422 423 424
		if ((skb->len >= (sizeof(llc_oui_ipv4))) &&
		    (memcmp(skb->data, llc_oui_ipv4,
			    sizeof(llc_oui_ipv4) - BR2684_ETHERTYPE_LEN) == 0)) {
			if (memcmp(skb->data + 6, ethertype_ipv6,
				   sizeof(ethertype_ipv6)) == 0)
425
				skb->protocol = htons(ETH_P_IPV6);
426 427
			else if (memcmp(skb->data + 6, ethertype_ipv4,
					sizeof(ethertype_ipv4)) == 0)
428
				skb->protocol = htons(ETH_P_IP);
429 430
			else
				goto error;
E
Eric Kinzie 已提交
431 432 433
			skb_pull(skb, sizeof(llc_oui_ipv4));
			skb_reset_network_header(skb);
			skb->pkt_type = PACKET_HOST;
434 435 436 437 438
		/*
		 * Let us waste some time for checking the encapsulation.
		 * Note, that only 7 char is checked so frames with a valid FCS
		 * are also accepted (but FCS is not checked of course).
		 */
E
Eric Kinzie 已提交
439
		} else if ((skb->len >= sizeof(llc_oui_pid_pad)) &&
440
			   (memcmp(skb->data, llc_oui_pid_pad, 7) == 0)) {
E
Eric Kinzie 已提交
441 442
			skb_pull(skb, sizeof(llc_oui_pid_pad));
			skb->protocol = eth_type_trans(skb, net_dev);
443 444
		} else
			goto error;
L
Linus Torvalds 已提交
445

446 447 448 449 450 451 452
	} else { /* e_vc */
		if (brdev->payload == p_routed) {
			struct iphdr *iph;

			skb_reset_network_header(skb);
			iph = ip_hdr(skb);
			if (iph->version == 4)
453
				skb->protocol = htons(ETH_P_IP);
454
			else if (iph->version == 6)
455
				skb->protocol = htons(ETH_P_IPV6);
456 457 458 459 460 461 462 463 464
			else
				goto error;
			skb->pkt_type = PACKET_HOST;
		} else { /* p_bridged */
			/* first 2 chars should be 0 */
			if (*((u16 *) (skb->data)) != 0)
				goto error;
			skb_pull(skb, BR2684_PAD_LEN);
			skb->protocol = eth_type_trans(skb, net_dev);
L
Linus Torvalds 已提交
465 466 467 468
		}
	}

#ifdef CONFIG_ATM_BR2684_IPFILTER
469 470
	if (unlikely(packet_fails_filter(skb->protocol, brvcc, skb)))
		goto dropped;
L
Linus Torvalds 已提交
471 472 473
#endif /* CONFIG_ATM_BR2684_IPFILTER */
	skb->dev = net_dev;
	ATM_SKB(skb)->vcc = atmvcc;	/* needed ? */
474
	pr_debug("received packet's protocol: %x\n", ntohs(skb->protocol));
L
Linus Torvalds 已提交
475
	skb_debug(skb);
476 477 478
	/* sigh, interface is down? */
	if (unlikely(!(net_dev->flags & IFF_UP)))
		goto dropped;
S
Stephen Hemminger 已提交
479 480
	net_dev->stats.rx_packets++;
	net_dev->stats.rx_bytes += skb->len;
L
Linus Torvalds 已提交
481 482
	memset(ATM_SKB(skb), 0, sizeof(struct atm_skb_data));
	netif_rx(skb);
483 484 485
	return;

dropped:
S
Stephen Hemminger 已提交
486
	net_dev->stats.rx_dropped++;
487 488
	goto free_skb;
error:
S
Stephen Hemminger 已提交
489
	net_dev->stats.rx_errors++;
490 491
free_skb:
	dev_kfree_skb(skb);
L
Linus Torvalds 已提交
492 493
}

494 495 496 497 498
/*
 * Assign a vcc to a dev
 * Note: we do not have explicit unassign, but look at _push()
 */
static int br2684_regvcc(struct atm_vcc *atmvcc, void __user * arg)
L
Linus Torvalds 已提交
499
{
500
	struct sk_buff_head queue;
L
Linus Torvalds 已提交
501 502
	int err;
	struct br2684_vcc *brvcc;
503
	struct sk_buff *skb, *tmp;
D
David S. Miller 已提交
504
	struct sk_buff_head *rq;
L
Linus Torvalds 已提交
505 506 507
	struct br2684_dev *brdev;
	struct net_device *net_dev;
	struct atm_backend_br2684 be;
D
David S. Miller 已提交
508
	unsigned long flags;
L
Linus Torvalds 已提交
509 510 511

	if (copy_from_user(&be, arg, sizeof be))
		return -EFAULT;
512
	brvcc = kzalloc(sizeof(struct br2684_vcc), GFP_KERNEL);
L
Linus Torvalds 已提交
513 514 515 516 517
	if (!brvcc)
		return -ENOMEM;
	write_lock_irq(&devs_lock);
	net_dev = br2684_find_dev(&be.ifspec);
	if (net_dev == NULL) {
518
		pr_err("tried to attach to non-existant device\n");
L
Linus Torvalds 已提交
519 520 521 522 523 524 525 526 527 528 529 530 531
		err = -ENXIO;
		goto error;
	}
	brdev = BRPRIV(net_dev);
	if (atmvcc->push == NULL) {
		err = -EBADFD;
		goto error;
	}
	if (!list_empty(&brdev->brvccs)) {
		/* Only 1 VCC/dev right now */
		err = -EEXIST;
		goto error;
	}
532 533 534 535 536 537
	if (be.fcs_in != BR2684_FCSIN_NO ||
	    be.fcs_out != BR2684_FCSOUT_NO ||
	    be.fcs_auto || be.has_vpiid || be.send_padding ||
	    (be.encaps != BR2684_ENCAPS_VC &&
	     be.encaps != BR2684_ENCAPS_LLC) ||
	    be.min_size != 0) {
L
Linus Torvalds 已提交
538 539 540
		err = -EINVAL;
		goto error;
	}
541
	pr_debug("vcc=%p, encaps=%d, brvcc=%p\n", atmvcc, be.encaps, brvcc);
L
Linus Torvalds 已提交
542 543 544 545 546 547 548 549 550 551 552 553
	if (list_empty(&brdev->brvccs) && !brdev->mac_was_set) {
		unsigned char *esi = atmvcc->dev->esi;
		if (esi[0] | esi[1] | esi[2] | esi[3] | esi[4] | esi[5])
			memcpy(net_dev->dev_addr, esi, net_dev->addr_len);
		else
			net_dev->dev_addr[2] = 1;
	}
	list_add(&brvcc->brvccs, &brdev->brvccs);
	write_unlock_irq(&devs_lock);
	brvcc->device = net_dev;
	brvcc->atmvcc = atmvcc;
	atmvcc->user_back = brvcc;
554
	brvcc->encaps = (enum br2684_encaps)be.encaps;
L
Linus Torvalds 已提交
555
	brvcc->old_push = atmvcc->push;
556
	brvcc->old_pop = atmvcc->pop;
L
Linus Torvalds 已提交
557 558
	barrier();
	atmvcc->push = br2684_push;
559
	atmvcc->pop = br2684_pop;
D
David S. Miller 已提交
560

561
	__skb_queue_head_init(&queue);
D
David S. Miller 已提交
562 563 564
	rq = &sk_atm(atmvcc)->sk_receive_queue;

	spin_lock_irqsave(&rq->lock, flags);
565
	skb_queue_splice_init(rq, &queue);
D
David S. Miller 已提交
566 567
	spin_unlock_irqrestore(&rq->lock, flags);

568 569
	skb_queue_walk_safe(&queue, skb, tmp) {
		struct net_device *dev = skb->dev;
D
David S. Miller 已提交
570

571 572
		dev->stats.rx_bytes -= skb->len;
		dev->stats.rx_packets--;
D
David S. Miller 已提交
573

574
		br2684_push(atmvcc, skb);
L
Linus Torvalds 已提交
575
	}
576 577 578 579 580 581 582

	/* initialize netdev carrier state */
	if (atmvcc->dev->signal == ATM_PHY_SIG_LOST)
		netif_carrier_off(net_dev);
	else
		netif_carrier_on(net_dev);

L
Linus Torvalds 已提交
583 584
	__module_get(THIS_MODULE);
	return 0;
585 586

error:
L
Linus Torvalds 已提交
587 588 589 590 591
	write_unlock_irq(&devs_lock);
	kfree(brvcc);
	return err;
}

592 593 594 595 596 597 598
static const struct net_device_ops br2684_netdev_ops = {
	.ndo_start_xmit 	= br2684_start_xmit,
	.ndo_set_mac_address	= br2684_mac_addr,
	.ndo_change_mtu		= eth_change_mtu,
	.ndo_validate_addr	= eth_validate_addr,
};

599 600 601 602 603 604
static const struct net_device_ops br2684_netdev_ops_routed = {
	.ndo_start_xmit 	= br2684_start_xmit,
	.ndo_set_mac_address	= br2684_mac_addr,
	.ndo_change_mtu		= eth_change_mtu
};

L
Linus Torvalds 已提交
605 606 607 608 609
static void br2684_setup(struct net_device *netdev)
{
	struct br2684_dev *brdev = BRPRIV(netdev);

	ether_setup(netdev);
610
	brdev->net_dev = netdev;
L
Linus Torvalds 已提交
611

612
	netdev->netdev_ops = &br2684_netdev_ops;
L
Linus Torvalds 已提交
613 614 615 616

	INIT_LIST_HEAD(&brdev->brvccs);
}

E
Eric Kinzie 已提交
617 618 619 620
static void br2684_setup_routed(struct net_device *netdev)
{
	struct br2684_dev *brdev = BRPRIV(netdev);

621
	brdev->net_dev = netdev;
E
Eric Kinzie 已提交
622
	netdev->hard_header_len = 0;
623
	netdev->netdev_ops = &br2684_netdev_ops_routed;
E
Eric Kinzie 已提交
624 625 626 627 628 629 630 631
	netdev->addr_len = 0;
	netdev->mtu = 1500;
	netdev->type = ARPHRD_PPP;
	netdev->flags = IFF_POINTOPOINT | IFF_NOARP | IFF_MULTICAST;
	netdev->tx_queue_len = 100;
	INIT_LIST_HEAD(&brdev->brvccs);
}

632
static int br2684_create(void __user *arg)
L
Linus Torvalds 已提交
633 634 635 636 637
{
	int err;
	struct net_device *netdev;
	struct br2684_dev *brdev;
	struct atm_newif_br2684 ni;
E
Eric Kinzie 已提交
638
	enum br2684_payload payload;
L
Linus Torvalds 已提交
639

640
	pr_debug("\n");
L
Linus Torvalds 已提交
641

642
	if (copy_from_user(&ni, arg, sizeof ni))
L
Linus Torvalds 已提交
643
		return -EFAULT;
E
Eric Kinzie 已提交
644 645 646 647 648

	if (ni.media & BR2684_FLAG_ROUTED)
		payload = p_routed;
	else
		payload = p_bridged;
649
	ni.media &= 0xffff;	/* strip flags */
E
Eric Kinzie 已提交
650

651
	if (ni.media != BR2684_MEDIA_ETHERNET || ni.mtu != 1500)
L
Linus Torvalds 已提交
652 653 654 655
		return -EINVAL;

	netdev = alloc_netdev(sizeof(struct br2684_dev),
			      ni.ifname[0] ? ni.ifname : "nas%d",
E
Eric Kinzie 已提交
656
			      (payload == p_routed) ?
657
			      br2684_setup_routed : br2684_setup);
L
Linus Torvalds 已提交
658 659 660 661 662
	if (!netdev)
		return -ENOMEM;

	brdev = BRPRIV(netdev);

663
	pr_debug("registered netdev %s\n", netdev->name);
L
Linus Torvalds 已提交
664 665 666
	/* open, stop, do_ioctl ? */
	err = register_netdev(netdev);
	if (err < 0) {
667
		pr_err("register_netdev failed\n");
L
Linus Torvalds 已提交
668 669 670 671 672
		free_netdev(netdev);
		return err;
	}

	write_lock_irq(&devs_lock);
673

E
Eric Kinzie 已提交
674
	brdev->payload = payload;
675 676 677 678 679 680 681 682

	if (list_empty(&br2684_devs)) {
		/* 1st br2684 device */
		register_atmdevice_notifier(&atm_dev_notifier);
		brdev->number = 1;
	} else
		brdev->number = BRPRIV(list_entry_brdev(br2684_devs.prev))->number + 1;

L
Linus Torvalds 已提交
683 684 685 686 687 688 689 690 691 692
	list_add_tail(&brdev->br2684_devs, &br2684_devs);
	write_unlock_irq(&devs_lock);
	return 0;
}

/*
 * This handles ioctls actually performed on our vcc - we must return
 * -ENOIOCTLCMD for any unrecognized ioctl
 */
static int br2684_ioctl(struct socket *sock, unsigned int cmd,
693
			unsigned long arg)
L
Linus Torvalds 已提交
694 695 696
{
	struct atm_vcc *atmvcc = ATM_SD(sock);
	void __user *argp = (void __user *)arg;
697
	atm_backend_t b;
L
Linus Torvalds 已提交
698 699

	int err;
700
	switch (cmd) {
L
Linus Torvalds 已提交
701
	case ATM_SETBACKEND:
702
	case ATM_NEWBACKENDIF:
L
Linus Torvalds 已提交
703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720
		err = get_user(b, (atm_backend_t __user *) argp);
		if (err)
			return -EFAULT;
		if (b != ATM_BACKEND_BR2684)
			return -ENOIOCTLCMD;
		if (!capable(CAP_NET_ADMIN))
			return -EPERM;
		if (cmd == ATM_SETBACKEND)
			return br2684_regvcc(atmvcc, argp);
		else
			return br2684_create(argp);
#ifdef CONFIG_ATM_BR2684_IPFILTER
	case BR2684_SETFILT:
		if (atmvcc->push != br2684_push)
			return -ENOIOCTLCMD;
		if (!capable(CAP_NET_ADMIN))
			return -EPERM;
		err = br2684_setfilt(atmvcc, argp);
721

L
Linus Torvalds 已提交
722 723 724 725 726 727 728
		return err;
#endif /* CONFIG_ATM_BR2684_IPFILTER */
	}
	return -ENOIOCTLCMD;
}

static struct atm_ioctl br2684_ioctl_ops = {
729 730
	.owner = THIS_MODULE,
	.ioctl = br2684_ioctl,
L
Linus Torvalds 已提交
731 732 733
};

#ifdef CONFIG_PROC_FS
734
static void *br2684_seq_start(struct seq_file *seq, loff_t * pos)
735
	__acquires(devs_lock)
L
Linus Torvalds 已提交
736 737
{
	read_lock(&devs_lock);
738
	return seq_list_start(&br2684_devs, *pos);
L
Linus Torvalds 已提交
739 740
}

741
static void *br2684_seq_next(struct seq_file *seq, void *v, loff_t * pos)
L
Linus Torvalds 已提交
742
{
743
	return seq_list_next(v, &br2684_devs, pos);
L
Linus Torvalds 已提交
744 745 746
}

static void br2684_seq_stop(struct seq_file *seq, void *v)
747
	__releases(devs_lock)
L
Linus Torvalds 已提交
748 749 750 751 752 753
{
	read_unlock(&devs_lock);
}

static int br2684_seq_show(struct seq_file *seq, void *v)
{
754
	const struct br2684_dev *brdev = list_entry(v, struct br2684_dev,
755
						    br2684_devs);
L
Linus Torvalds 已提交
756 757 758
	const struct net_device *net_dev = brdev->net_dev;
	const struct br2684_vcc *brvcc;

J
Johannes Berg 已提交
759
	seq_printf(seq, "dev %.16s: num=%d, mac=%pM (%s)\n",
760 761
		   net_dev->name,
		   brdev->number,
J
Johannes Berg 已提交
762
		   net_dev->dev_addr,
763
		   brdev->mac_was_set ? "set" : "auto");
L
Linus Torvalds 已提交
764 765

	list_for_each_entry(brvcc, &brdev->brvccs, brvccs) {
E
Eric Kinzie 已提交
766
		seq_printf(seq, "  vcc %d.%d.%d: encaps=%s payload=%s"
767 768 769 770 771 772
			   ", failed copies %u/%u"
			   "\n", brvcc->atmvcc->dev->number,
			   brvcc->atmvcc->vpi, brvcc->atmvcc->vci,
			   (brvcc->encaps == e_llc) ? "LLC" : "VC",
			   (brdev->payload == p_bridged) ? "bridged" : "routed",
			   brvcc->copies_failed, brvcc->copies_needed);
L
Linus Torvalds 已提交
773 774 775
#ifdef CONFIG_ATM_BR2684_IPFILTER
#define b1(var, byte)	((u8 *) &brvcc->filter.var)[byte]
#define bs(var)		b1(var, 0), b1(var, 1), b1(var, 2), b1(var, 3)
776 777 778
		if (brvcc->filter.netmask != 0)
			seq_printf(seq, "    filter=%d.%d.%d.%d/"
				   "%d.%d.%d.%d\n", bs(prefix), bs(netmask));
L
Linus Torvalds 已提交
779 780 781 782 783 784 785
#undef bs
#undef b1
#endif /* CONFIG_ATM_BR2684_IPFILTER */
	}
	return 0;
}

786
static const struct seq_operations br2684_seq_ops = {
L
Linus Torvalds 已提交
787
	.start = br2684_seq_start,
788 789 790
	.next = br2684_seq_next,
	.stop = br2684_seq_stop,
	.show = br2684_seq_show,
L
Linus Torvalds 已提交
791 792 793 794 795 796 797
};

static int br2684_proc_open(struct inode *inode, struct file *file)
{
	return seq_open(file, &br2684_seq_ops);
}

798
static const struct file_operations br2684_proc_ops = {
799 800 801 802
	.owner = THIS_MODULE,
	.open = br2684_proc_open,
	.read = seq_read,
	.llseek = seq_lseek,
L
Linus Torvalds 已提交
803 804 805 806
	.release = seq_release,
};

extern struct proc_dir_entry *atm_proc_root;	/* from proc.c */
807
#endif /* CONFIG_PROC_FS */
L
Linus Torvalds 已提交
808 809 810 811 812

static int __init br2684_init(void)
{
#ifdef CONFIG_PROC_FS
	struct proc_dir_entry *p;
813 814
	p = proc_create("br2684", 0, atm_proc_root, &br2684_proc_ops);
	if (p == NULL)
L
Linus Torvalds 已提交
815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831
		return -ENOMEM;
#endif
	register_atm_ioctl(&br2684_ioctl_ops);
	return 0;
}

static void __exit br2684_exit(void)
{
	struct net_device *net_dev;
	struct br2684_dev *brdev;
	struct br2684_vcc *brvcc;
	deregister_atm_ioctl(&br2684_ioctl_ops);

#ifdef CONFIG_PROC_FS
	remove_proc_entry("br2684", atm_proc_root);
#endif

832 833 834 835 836

	/* if not already empty */
	if (!list_empty(&br2684_devs))
		unregister_atmdevice_notifier(&atm_dev_notifier);

L
Linus Torvalds 已提交
837 838 839 840 841 842 843 844 845 846
	while (!list_empty(&br2684_devs)) {
		net_dev = list_entry_brdev(br2684_devs.next);
		brdev = BRPRIV(net_dev);
		while (!list_empty(&brdev->brvccs)) {
			brvcc = list_entry_brvcc(brdev->brvccs.next);
			br2684_close_vcc(brvcc);
		}

		list_del(&brdev->br2684_devs);
		unregister_netdev(net_dev);
847
		free_netdev(net_dev);
L
Linus Torvalds 已提交
848 849 850 851 852 853 854 855 856
	}
}

module_init(br2684_init);
module_exit(br2684_exit);

MODULE_AUTHOR("Marcell GAL");
MODULE_DESCRIPTION("RFC2684 bridged protocols over ATM/AAL5");
MODULE_LICENSE("GPL");