routing.c 32.6 KB
Newer Older
1
/* Copyright (C) 2007-2012 B.A.T.M.A.N. contributors:
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
 *
 * Marek Lindner, Simon Wunderlich
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of version 2 of the GNU General Public
 * License as published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
 * General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
 * 02110-1301, USA
 */

#include "main.h"
#include "routing.h"
#include "send.h"
#include "soft-interface.h"
#include "hard-interface.h"
#include "icmp_socket.h"
#include "translation-table.h"
#include "originator.h"
#include "vis.h"
#include "unicast.h"
30
#include "bridge_loop_avoidance.h"
31

32
static int batadv_route_unicast_packet(struct sk_buff *skb,
33
				       struct batadv_hard_iface *recv_if);
34

35
void batadv_slide_own_bcast_window(struct batadv_hard_iface *hard_iface)
36
{
37
	struct batadv_priv *bat_priv = netdev_priv(hard_iface->soft_iface);
38
	struct batadv_hashtable *hash = bat_priv->orig_hash;
39
	struct hlist_node *node;
40
	struct hlist_head *head;
41
	struct batadv_orig_node *orig_node;
42
	unsigned long *word;
43
	uint32_t i;
44
	size_t word_index;
45
	uint8_t *w;
46 47 48 49

	for (i = 0; i < hash->size; i++) {
		head = &hash->table[i];

50
		rcu_read_lock();
51
		hlist_for_each_entry_rcu(orig_node, node, head, hash_entry) {
52
			spin_lock_bh(&orig_node->ogm_cnt_lock);
53
			word_index = hard_iface->if_num * BATADV_NUM_WORDS;
54 55
			word = &(orig_node->bcast_own[word_index]);

56
			batadv_bit_get_packet(bat_priv, word, 1, 0);
57 58
			w = &orig_node->bcast_own_sum[hard_iface->if_num];
			*w = bitmap_weight(word, BATADV_TQ_LOCAL_WINDOW_SIZE);
59
			spin_unlock_bh(&orig_node->ogm_cnt_lock);
60
		}
61
		rcu_read_unlock();
62 63 64
	}
}

65 66 67
static void _batadv_update_route(struct batadv_priv *bat_priv,
				 struct batadv_orig_node *orig_node,
				 struct batadv_neigh_node *neigh_node)
68
{
69
	struct batadv_neigh_node *curr_router;
70

71
	curr_router = batadv_orig_node_get_router(orig_node);
72

73
	/* route deleted */
74
	if ((curr_router) && (!neigh_node)) {
75 76
		batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
			   "Deleting route towards: %pM\n", orig_node->orig);
77 78
		batadv_tt_global_del_orig(bat_priv, orig_node,
					  "Deleted route towards originator");
79

80 81
	/* route added */
	} else if ((!curr_router) && (neigh_node)) {
82

83
		batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
84 85
			   "Adding route towards: %pM (via %pM)\n",
			   orig_node->orig, neigh_node->addr);
86
	/* route changed */
87
	} else if (neigh_node && curr_router) {
88
		batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
89 90 91
			   "Changing route towards: %pM (now via %pM - was via %pM)\n",
			   orig_node->orig, neigh_node->addr,
			   curr_router->addr);
92 93
	}

94
	if (curr_router)
95
		batadv_neigh_node_free_ref(curr_router);
96 97

	/* increase refcount of new best neighbor */
98 99
	if (neigh_node && !atomic_inc_not_zero(&neigh_node->refcount))
		neigh_node = NULL;
100 101 102 103 104 105 106

	spin_lock_bh(&orig_node->neigh_list_lock);
	rcu_assign_pointer(orig_node->router, neigh_node);
	spin_unlock_bh(&orig_node->neigh_list_lock);

	/* decrease refcount of previous best neighbor */
	if (curr_router)
107
		batadv_neigh_node_free_ref(curr_router);
108 109
}

110 111 112
void batadv_update_route(struct batadv_priv *bat_priv,
			 struct batadv_orig_node *orig_node,
			 struct batadv_neigh_node *neigh_node)
113
{
114
	struct batadv_neigh_node *router = NULL;
115 116

	if (!orig_node)
117 118
		goto out;

119
	router = batadv_orig_node_get_router(orig_node);
120

121
	if (router != neigh_node)
122
		_batadv_update_route(bat_priv, orig_node, neigh_node);
123 124 125

out:
	if (router)
126
		batadv_neigh_node_free_ref(router);
127 128
}

129
/* caller must hold the neigh_list_lock */
130 131
void batadv_bonding_candidate_del(struct batadv_orig_node *orig_node,
				  struct batadv_neigh_node *neigh_node)
132 133 134 135 136 137 138
{
	/* this neighbor is not part of our candidate list */
	if (list_empty(&neigh_node->bonding_list))
		goto out;

	list_del_rcu(&neigh_node->bonding_list);
	INIT_LIST_HEAD(&neigh_node->bonding_list);
139
	batadv_neigh_node_free_ref(neigh_node);
140 141 142 143 144 145
	atomic_dec(&orig_node->bond_candidates);

out:
	return;
}

146 147
void batadv_bonding_candidate_add(struct batadv_orig_node *orig_node,
				  struct batadv_neigh_node *neigh_node)
148 149
{
	struct hlist_node *node;
150
	struct batadv_neigh_node *tmp_neigh_node, *router = NULL;
151
	uint8_t interference_candidate = 0;
152 153 154 155

	spin_lock_bh(&orig_node->neigh_list_lock);

	/* only consider if it has the same primary address ...  */
156 157
	if (!batadv_compare_eth(orig_node->orig,
				neigh_node->orig_node->primary_addr))
158 159
		goto candidate_del;

160
	router = batadv_orig_node_get_router(orig_node);
161
	if (!router)
162 163 164
		goto candidate_del;

	/* ... and is good enough to be considered */
165
	if (neigh_node->tq_avg < router->tq_avg - BATADV_BONDING_TQ_THRESHOLD)
166 167
		goto candidate_del;

168
	/* check if we have another candidate with the same mac address or
169 170 171 172 173 174 175 176 177 178
	 * interface. If we do, we won't select this candidate because of
	 * possible interference.
	 */
	hlist_for_each_entry_rcu(tmp_neigh_node, node,
				 &orig_node->neigh_list, list) {

		if (tmp_neigh_node == neigh_node)
			continue;

		/* we only care if the other candidate is even
179 180
		 * considered as candidate.
		 */
181 182 183 184
		if (list_empty(&tmp_neigh_node->bonding_list))
			continue;

		if ((neigh_node->if_incoming == tmp_neigh_node->if_incoming) ||
185 186
		    (batadv_compare_eth(neigh_node->addr,
					tmp_neigh_node->addr))) {
187 188 189 190 191 192 193 194 195 196 197 198 199
			interference_candidate = 1;
			break;
		}
	}

	/* don't care further if it is an interference candidate */
	if (interference_candidate)
		goto candidate_del;

	/* this neighbor already is part of our candidate list */
	if (!list_empty(&neigh_node->bonding_list))
		goto out;

200 201 202
	if (!atomic_inc_not_zero(&neigh_node->refcount))
		goto out;

203 204 205 206 207
	list_add_rcu(&neigh_node->bonding_list, &orig_node->bond_list);
	atomic_inc(&orig_node->bond_candidates);
	goto out;

candidate_del:
208
	batadv_bonding_candidate_del(orig_node, neigh_node);
209 210 211

out:
	spin_unlock_bh(&orig_node->neigh_list_lock);
212 213

	if (router)
214
		batadv_neigh_node_free_ref(router);
215 216 217
}

/* copy primary address for bonding */
218
void
219 220
batadv_bonding_save_primary(const struct batadv_orig_node *orig_node,
			    struct batadv_orig_node *orig_neigh_node,
221
			    const struct batadv_ogm_packet *batman_ogm_packet)
222
{
223
	if (!(batman_ogm_packet->flags & BATADV_PRIMARIES_FIRST_HOP))
224 225 226 227 228
		return;

	memcpy(orig_neigh_node->primary_addr, orig_node->orig, ETH_ALEN);
}

229 230 231 232 233
/* checks whether the host restarted and is in the protection time.
 * returns:
 *  0 if the packet is to be accepted
 *  1 if the packet is to be ignored.
 */
234
int batadv_window_protected(struct batadv_priv *bat_priv, int32_t seq_num_diff,
235
			    unsigned long *last_reset)
236
{
237 238 239 240
	if (seq_num_diff <= -BATADV_TQ_LOCAL_WINDOW_SIZE ||
	    seq_num_diff >= BATADV_EXPECTED_SEQNO_RANGE) {
		if (!batadv_has_timed_out(*last_reset,
					  BATADV_RESET_PROTECTION_MS))
241
			return 1;
242 243

		*last_reset = jiffies;
244
		batadv_dbg(BATADV_DBG_BATMAN, bat_priv,
245
			   "old packet received, start protection\n");
246
	}
247

248 249 250
	return 0;
}

251
bool batadv_check_management_packet(struct sk_buff *skb,
252
				    struct batadv_hard_iface *hard_iface,
253
				    int header_len)
254 255 256 257
{
	struct ethhdr *ethhdr;

	/* drop packet if it has not necessary minimum size */
258 259
	if (unlikely(!pskb_may_pull(skb, header_len)))
		return false;
260 261 262 263 264

	ethhdr = (struct ethhdr *)skb_mac_header(skb);

	/* packet with broadcast indication but unicast recipient */
	if (!is_broadcast_ether_addr(ethhdr->h_dest))
265
		return false;
266 267 268

	/* packet with broadcast sender address */
	if (is_broadcast_ether_addr(ethhdr->h_source))
269
		return false;
270 271 272

	/* create a copy of the skb, if needed, to modify it. */
	if (skb_cow(skb, 0) < 0)
273
		return false;
274 275 276

	/* keep skb linear */
	if (skb_linearize(skb) < 0)
277
		return false;
278

279
	return true;
280 281
}

282
static int batadv_recv_my_icmp_packet(struct batadv_priv *bat_priv,
283
				      struct sk_buff *skb, size_t icmp_len)
284
{
285 286 287
	struct batadv_hard_iface *primary_if = NULL;
	struct batadv_orig_node *orig_node = NULL;
	struct batadv_neigh_node *router = NULL;
288
	struct batadv_icmp_packet_rr *icmp_packet;
289
	int ret = NET_RX_DROP;
290

291
	icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
292 293

	/* add data to device queue */
294
	if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) {
295
		batadv_socket_receive_packet(icmp_packet, icmp_len);
296
		goto out;
297 298
	}

299
	primary_if = batadv_primary_if_get_selected(bat_priv);
300
	if (!primary_if)
301
		goto out;
302 303 304

	/* answer echo request (ping) */
	/* get routing information */
305
	orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig);
306
	if (!orig_node)
307
		goto out;
308

309
	router = batadv_orig_node_get_router(orig_node);
310 311
	if (!router)
		goto out;
312

313
	/* create a copy of the skb, if needed, to modify it. */
314
	if (skb_cow(skb, ETH_HLEN) < 0)
315 316
		goto out;

317
	icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
318 319

	memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN);
320
	memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN);
321
	icmp_packet->msg_type = BATADV_ECHO_REPLY;
322
	icmp_packet->header.ttl = BATADV_TTL;
323

324
	batadv_send_skb_packet(skb, router->if_incoming, router->addr);
325
	ret = NET_RX_SUCCESS;
326

327
out:
328
	if (primary_if)
329
		batadv_hardif_free_ref(primary_if);
330
	if (router)
331
		batadv_neigh_node_free_ref(router);
332
	if (orig_node)
333
		batadv_orig_node_free_ref(orig_node);
334 335 336
	return ret;
}

337
static int batadv_recv_icmp_ttl_exceeded(struct batadv_priv *bat_priv,
338
					 struct sk_buff *skb)
339
{
340 341 342
	struct batadv_hard_iface *primary_if = NULL;
	struct batadv_orig_node *orig_node = NULL;
	struct batadv_neigh_node *router = NULL;
343
	struct batadv_icmp_packet *icmp_packet;
344
	int ret = NET_RX_DROP;
345

346
	icmp_packet = (struct batadv_icmp_packet *)skb->data;
347 348

	/* send TTL exceeded if packet is an echo request (traceroute) */
349
	if (icmp_packet->msg_type != BATADV_ECHO_REQUEST) {
350 351
		pr_debug("Warning - can't forward icmp packet from %pM to %pM: ttl exceeded\n",
			 icmp_packet->orig, icmp_packet->dst);
352
		goto out;
353 354
	}

355
	primary_if = batadv_primary_if_get_selected(bat_priv);
356
	if (!primary_if)
357
		goto out;
358 359

	/* get routing information */
360
	orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->orig);
361
	if (!orig_node)
362
		goto out;
363

364
	router = batadv_orig_node_get_router(orig_node);
365 366
	if (!router)
		goto out;
367

368
	/* create a copy of the skb, if needed, to modify it. */
369
	if (skb_cow(skb, ETH_HLEN) < 0)
370
		goto out;
371

372
	icmp_packet = (struct batadv_icmp_packet *)skb->data;
373

374
	memcpy(icmp_packet->dst, icmp_packet->orig, ETH_ALEN);
375
	memcpy(icmp_packet->orig, primary_if->net_dev->dev_addr, ETH_ALEN);
376
	icmp_packet->msg_type = BATADV_TTL_EXCEEDED;
377
	icmp_packet->header.ttl = BATADV_TTL;
378

379
	batadv_send_skb_packet(skb, router->if_incoming, router->addr);
380
	ret = NET_RX_SUCCESS;
381

382
out:
383
	if (primary_if)
384
		batadv_hardif_free_ref(primary_if);
385
	if (router)
386
		batadv_neigh_node_free_ref(router);
387
	if (orig_node)
388
		batadv_orig_node_free_ref(orig_node);
389 390 391 392
	return ret;
}


393 394
int batadv_recv_icmp_packet(struct sk_buff *skb,
			    struct batadv_hard_iface *recv_if)
395
{
396
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
397
	struct batadv_icmp_packet_rr *icmp_packet;
398
	struct ethhdr *ethhdr;
399 400
	struct batadv_orig_node *orig_node = NULL;
	struct batadv_neigh_node *router = NULL;
401
	int hdr_size = sizeof(struct batadv_icmp_packet);
402
	int ret = NET_RX_DROP;
403

404
	/* we truncate all incoming icmp packets if they don't match our size */
405 406
	if (skb->len >= sizeof(struct batadv_icmp_packet_rr))
		hdr_size = sizeof(struct batadv_icmp_packet_rr);
407 408 409

	/* drop packet if it has not necessary minimum size */
	if (unlikely(!pskb_may_pull(skb, hdr_size)))
410
		goto out;
411 412 413 414 415

	ethhdr = (struct ethhdr *)skb_mac_header(skb);

	/* packet with unicast indication but broadcast recipient */
	if (is_broadcast_ether_addr(ethhdr->h_dest))
416
		goto out;
417 418 419

	/* packet with broadcast sender address */
	if (is_broadcast_ether_addr(ethhdr->h_source))
420
		goto out;
421 422

	/* not for me */
423
	if (!batadv_is_my_mac(ethhdr->h_dest))
424
		goto out;
425

426
	icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
427 428

	/* add record route information if not full */
429
	if ((hdr_size == sizeof(struct batadv_icmp_packet_rr)) &&
430
	    (icmp_packet->rr_cur < BATADV_RR_LEN)) {
431
		memcpy(&(icmp_packet->rr[icmp_packet->rr_cur]),
432
		       ethhdr->h_dest, ETH_ALEN);
433 434 435 436
		icmp_packet->rr_cur++;
	}

	/* packet for me */
437
	if (batadv_is_my_mac(icmp_packet->dst))
438
		return batadv_recv_my_icmp_packet(bat_priv, skb, hdr_size);
439 440

	/* TTL exceeded */
441
	if (icmp_packet->header.ttl < 2)
442
		return batadv_recv_icmp_ttl_exceeded(bat_priv, skb);
443 444

	/* get routing information */
445
	orig_node = batadv_orig_hash_find(bat_priv, icmp_packet->dst);
446
	if (!orig_node)
447
		goto out;
448

449
	router = batadv_orig_node_get_router(orig_node);
450 451
	if (!router)
		goto out;
452

453
	/* create a copy of the skb, if needed, to modify it. */
454
	if (skb_cow(skb, ETH_HLEN) < 0)
455
		goto out;
456

457
	icmp_packet = (struct batadv_icmp_packet_rr *)skb->data;
458

459
	/* decrement ttl */
460
	icmp_packet->header.ttl--;
461 462

	/* route it */
463
	batadv_send_skb_packet(skb, router->if_incoming, router->addr);
464
	ret = NET_RX_SUCCESS;
465

466
out:
467
	if (router)
468
		batadv_neigh_node_free_ref(router);
469
	if (orig_node)
470
		batadv_orig_node_free_ref(orig_node);
471 472 473
	return ret;
}

474 475 476 477
/* In the bonding case, send the packets in a round
 * robin fashion over the remaining interfaces.
 *
 * This method rotates the bonding list and increases the
478 479
 * returned router's refcount.
 */
480 481 482
static struct batadv_neigh_node *
batadv_find_bond_router(struct batadv_orig_node *primary_orig,
			const struct batadv_hard_iface *recv_if)
483
{
484 485
	struct batadv_neigh_node *tmp_neigh_node;
	struct batadv_neigh_node *router = NULL, *first_candidate = NULL;
486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512

	rcu_read_lock();
	list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
				bonding_list) {
		if (!first_candidate)
			first_candidate = tmp_neigh_node;

		/* recv_if == NULL on the first node. */
		if (tmp_neigh_node->if_incoming == recv_if)
			continue;

		if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
			continue;

		router = tmp_neigh_node;
		break;
	}

	/* use the first candidate if nothing was found. */
	if (!router && first_candidate &&
	    atomic_inc_not_zero(&first_candidate->refcount))
		router = first_candidate;

	if (!router)
		goto out;

	/* selected should point to the next element
513 514
	 * after the current router
	 */
515 516
	spin_lock_bh(&primary_orig->neigh_list_lock);
	/* this is a list_move(), which unfortunately
517 518
	 * does not exist as rcu version
	 */
519 520 521 522 523 524 525 526 527 528 529 530 531 532
	list_del_rcu(&primary_orig->bond_list);
	list_add_rcu(&primary_orig->bond_list,
		     &router->bonding_list);
	spin_unlock_bh(&primary_orig->neigh_list_lock);

out:
	rcu_read_unlock();
	return router;
}

/* Interface Alternating: Use the best of the
 * remaining candidates which are not using
 * this interface.
 *
533 534
 * Increases the returned router's refcount
 */
535 536 537
static struct batadv_neigh_node *
batadv_find_ifalter_router(struct batadv_orig_node *primary_orig,
			   const struct batadv_hard_iface *recv_if)
538
{
539 540
	struct batadv_neigh_node *tmp_neigh_node;
	struct batadv_neigh_node *router = NULL, *first_candidate = NULL;
541 542 543 544 545 546 547 548 549 550 551 552 553 554 555

	rcu_read_lock();
	list_for_each_entry_rcu(tmp_neigh_node, &primary_orig->bond_list,
				bonding_list) {
		if (!first_candidate)
			first_candidate = tmp_neigh_node;

		/* recv_if == NULL on the first node. */
		if (tmp_neigh_node->if_incoming == recv_if)
			continue;

		if (!atomic_inc_not_zero(&tmp_neigh_node->refcount))
			continue;

		/* if we don't have a router yet
556 557
		 * or this one is better, choose it.
		 */
558 559 560
		if ((!router) ||
		    (tmp_neigh_node->tq_avg > router->tq_avg)) {
			/* decrement refcount of
561 562
			 * previously selected router
			 */
563
			if (router)
564
				batadv_neigh_node_free_ref(router);
565 566 567 568 569

			router = tmp_neigh_node;
			atomic_inc_not_zero(&router->refcount);
		}

570
		batadv_neigh_node_free_ref(tmp_neigh_node);
571 572 573 574 575 576 577 578 579 580 581
	}

	/* use the first candidate if nothing was found. */
	if (!router && first_candidate &&
	    atomic_inc_not_zero(&first_candidate->refcount))
		router = first_candidate;

	rcu_read_unlock();
	return router;
}

582
int batadv_recv_tt_query(struct sk_buff *skb, struct batadv_hard_iface *recv_if)
583
{
584
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
585
	struct batadv_tt_query_packet *tt_query;
586
	uint16_t tt_size;
587
	struct ethhdr *ethhdr;
588
	char tt_flag;
589
	size_t packet_size;
590 591

	/* drop packet if it has not necessary minimum size */
592 593
	if (unlikely(!pskb_may_pull(skb,
				    sizeof(struct batadv_tt_query_packet))))
594 595 596
		goto out;

	/* I could need to modify it */
597
	if (skb_cow(skb, sizeof(struct batadv_tt_query_packet)) < 0)
598 599 600 601 602 603 604 605 606 607 608 609
		goto out;

	ethhdr = (struct ethhdr *)skb_mac_header(skb);

	/* packet with unicast indication but broadcast recipient */
	if (is_broadcast_ether_addr(ethhdr->h_dest))
		goto out;

	/* packet with broadcast sender address */
	if (is_broadcast_ether_addr(ethhdr->h_source))
		goto out;

610
	tt_query = (struct batadv_tt_query_packet *)skb->data;
611

612
	switch (tt_query->flags & BATADV_TT_QUERY_TYPE_MASK) {
613
	case BATADV_TT_REQUEST:
614
		batadv_inc_counter(bat_priv, BATADV_CNT_TT_REQUEST_RX);
615

616
		/* If we cannot provide an answer the tt_request is
617 618
		 * forwarded
		 */
619
		if (!batadv_send_tt_response(bat_priv, tt_query)) {
620 621 622 623 624
			if (tt_query->flags & BATADV_TT_FULL_TABLE)
				tt_flag = 'F';
			else
				tt_flag = '.';

625
			batadv_dbg(BATADV_DBG_TT, bat_priv,
626 627 628
				   "Routing TT_REQUEST to %pM [%c]\n",
				   tt_query->dst,
				   tt_flag);
629
			return batadv_route_unicast_packet(skb, recv_if);
630 631
		}
		break;
632
	case BATADV_TT_RESPONSE:
633
		batadv_inc_counter(bat_priv, BATADV_CNT_TT_RESPONSE_RX);
634

635
		if (batadv_is_my_mac(tt_query->dst)) {
636
			/* packet needs to be linearized to access the TT
637 638
			 * changes
			 */
639 640
			if (skb_linearize(skb) < 0)
				goto out;
641
			/* skb_linearize() possibly changed skb->data */
642
			tt_query = (struct batadv_tt_query_packet *)skb->data;
643

644
			tt_size = batadv_tt_len(ntohs(tt_query->tt_data));
645 646

			/* Ensure we have all the claimed data */
647 648 649
			packet_size = sizeof(struct batadv_tt_query_packet);
			packet_size += tt_size;
			if (unlikely(skb_headlen(skb) < packet_size))
650 651
				goto out;

652
			batadv_handle_tt_response(bat_priv, tt_query);
653
		} else {
654 655 656 657
			if (tt_query->flags & BATADV_TT_FULL_TABLE)
				tt_flag =  'F';
			else
				tt_flag = '.';
658
			batadv_dbg(BATADV_DBG_TT, bat_priv,
659 660 661
				   "Routing TT_RESPONSE to %pM [%c]\n",
				   tt_query->dst,
				   tt_flag);
662
			return batadv_route_unicast_packet(skb, recv_if);
663 664 665 666 667 668 669 670 671
		}
		break;
	}

out:
	/* returning NET_RX_DROP will make the caller function kfree the skb */
	return NET_RX_DROP;
}

672
int batadv_recv_roam_adv(struct sk_buff *skb, struct batadv_hard_iface *recv_if)
673
{
674
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
675
	struct batadv_roam_adv_packet *roam_adv_packet;
676
	struct batadv_orig_node *orig_node;
677 678 679
	struct ethhdr *ethhdr;

	/* drop packet if it has not necessary minimum size */
680 681
	if (unlikely(!pskb_may_pull(skb,
				    sizeof(struct batadv_roam_adv_packet))))
682 683 684 685 686 687 688 689 690 691 692 693
		goto out;

	ethhdr = (struct ethhdr *)skb_mac_header(skb);

	/* packet with unicast indication but broadcast recipient */
	if (is_broadcast_ether_addr(ethhdr->h_dest))
		goto out;

	/* packet with broadcast sender address */
	if (is_broadcast_ether_addr(ethhdr->h_source))
		goto out;

694
	batadv_inc_counter(bat_priv, BATADV_CNT_TT_ROAM_ADV_RX);
695

696
	roam_adv_packet = (struct batadv_roam_adv_packet *)skb->data;
697

698
	if (!batadv_is_my_mac(roam_adv_packet->dst))
699
		return batadv_route_unicast_packet(skb, recv_if);
700

701 702 703 704
	/* check if it is a backbone gateway. we don't accept
	 * roaming advertisement from it, as it has the same
	 * entries as we have.
	 */
705
	if (batadv_bla_is_backbone_gw_orig(bat_priv, roam_adv_packet->src))
706 707
		goto out;

708
	orig_node = batadv_orig_hash_find(bat_priv, roam_adv_packet->src);
709 710 711
	if (!orig_node)
		goto out;

712
	batadv_dbg(BATADV_DBG_TT, bat_priv,
713 714
		   "Received ROAMING_ADV from %pM (client %pM)\n",
		   roam_adv_packet->src, roam_adv_packet->client);
715

716
	batadv_tt_global_add(bat_priv, orig_node, roam_adv_packet->client,
717
			     BATADV_TT_CLIENT_ROAM,
718
			     atomic_read(&orig_node->last_ttvn) + 1);
719 720 721

	/* Roaming phase starts: I have new information but the ttvn has not
	 * been incremented yet. This flag will make me check all the incoming
722 723
	 * packets for the correct destination.
	 */
724 725
	bat_priv->tt_poss_change = true;

726
	batadv_orig_node_free_ref(orig_node);
727 728 729 730 731
out:
	/* returning NET_RX_DROP will make the caller function kfree the skb */
	return NET_RX_DROP;
}

732
/* find a suitable router for this originator, and use
733
 * bonding if possible. increases the found neighbors
734 735
 * refcount.
 */
736 737 738 739
struct batadv_neigh_node *
batadv_find_router(struct batadv_priv *bat_priv,
		   struct batadv_orig_node *orig_node,
		   const struct batadv_hard_iface *recv_if)
740
{
741 742 743
	struct batadv_orig_node *primary_orig_node;
	struct batadv_orig_node *router_orig;
	struct batadv_neigh_node *router;
744 745
	static uint8_t zero_mac[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
	int bonding_enabled;
746
	uint8_t *primary_addr;
747 748 749 750

	if (!orig_node)
		return NULL;

751
	router = batadv_orig_node_get_router(orig_node);
752
	if (!router)
753
		goto err;
754 755

	/* without bonding, the first node should
756 757
	 * always choose the default router.
	 */
758 759
	bonding_enabled = atomic_read(&bat_priv->bonding);

760 761
	rcu_read_lock();
	/* select default router to output */
762
	router_orig = router->orig_node;
763 764
	if (!router_orig)
		goto err_unlock;
765 766 767

	if ((!recv_if) && (!bonding_enabled))
		goto return_router;
768

769 770
	primary_addr = router_orig->primary_addr;

771
	/* if we have something in the primary_addr, we can search
772 773
	 * for a potential bonding candidate.
	 */
774
	if (batadv_compare_eth(primary_addr, zero_mac))
775
		goto return_router;
776 777

	/* find the orig_node which has the primary interface. might
778 779
	 * even be the same as our router_orig in many cases
	 */
780
	if (batadv_compare_eth(primary_addr, router_orig->orig)) {
781 782
		primary_orig_node = router_orig;
	} else {
783 784
		primary_orig_node = batadv_orig_hash_find(bat_priv,
							  primary_addr);
785
		if (!primary_orig_node)
786
			goto return_router;
787

788
		batadv_orig_node_free_ref(primary_orig_node);
789 790 791
	}

	/* with less than 2 candidates, we can't do any
792 793
	 * bonding and prefer the original router.
	 */
794 795
	if (atomic_read(&primary_orig_node->bond_candidates) < 2)
		goto return_router;
796 797 798

	/* all nodes between should choose a candidate which
	 * is is not on the interface where the packet came
799 800
	 * in.
	 */
801
	batadv_neigh_node_free_ref(router);
802

803
	if (bonding_enabled)
804
		router = batadv_find_bond_router(primary_orig_node, recv_if);
805
	else
806
		router = batadv_find_ifalter_router(primary_orig_node, recv_if);
807

808
return_router:
809
	if (router && router->if_incoming->if_status != BATADV_IF_ACTIVE)
810 811
		goto err_unlock;

812
	rcu_read_unlock();
813
	return router;
814 815 816 817
err_unlock:
	rcu_read_unlock();
err:
	if (router)
818
		batadv_neigh_node_free_ref(router);
819
	return NULL;
820 821
}

822
static int batadv_check_unicast_packet(struct sk_buff *skb, int hdr_size)
823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840
{
	struct ethhdr *ethhdr;

	/* drop packet if it has not necessary minimum size */
	if (unlikely(!pskb_may_pull(skb, hdr_size)))
		return -1;

	ethhdr = (struct ethhdr *)skb_mac_header(skb);

	/* packet with unicast indication but broadcast recipient */
	if (is_broadcast_ether_addr(ethhdr->h_dest))
		return -1;

	/* packet with broadcast sender address */
	if (is_broadcast_ether_addr(ethhdr->h_source))
		return -1;

	/* not for me */
841
	if (!batadv_is_my_mac(ethhdr->h_dest))
842 843 844 845 846
		return -1;

	return 0;
}

847
static int batadv_route_unicast_packet(struct sk_buff *skb,
848
				       struct batadv_hard_iface *recv_if)
849
{
850 851 852
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
	struct batadv_orig_node *orig_node = NULL;
	struct batadv_neigh_node *neigh_node = NULL;
853
	struct batadv_unicast_packet *unicast_packet;
854
	struct ethhdr *ethhdr = (struct ethhdr *)skb_mac_header(skb);
855
	int ret = NET_RX_DROP;
856 857
	struct sk_buff *new_skb;

858
	unicast_packet = (struct batadv_unicast_packet *)skb->data;
859 860

	/* TTL exceeded */
861
	if (unicast_packet->header.ttl < 2) {
862 863
		pr_debug("Warning - can't forward unicast packet from %pM to %pM: ttl exceeded\n",
			 ethhdr->h_source, unicast_packet->dest);
864
		goto out;
865 866 867
	}

	/* get routing information */
868
	orig_node = batadv_orig_hash_find(bat_priv, unicast_packet->dest);
869

870
	if (!orig_node)
871
		goto out;
872

873
	/* find_router() increases neigh_nodes refcount if found. */
874
	neigh_node = batadv_find_router(bat_priv, orig_node, recv_if);
875

876
	if (!neigh_node)
877
		goto out;
878 879

	/* create a copy of the skb, if needed, to modify it. */
880
	if (skb_cow(skb, ETH_HLEN) < 0)
881
		goto out;
882

883
	unicast_packet = (struct batadv_unicast_packet *)skb->data;
884

885
	if (unicast_packet->header.packet_type == BATADV_UNICAST &&
886
	    atomic_read(&bat_priv->fragmentation) &&
887
	    skb->len > neigh_node->if_incoming->net_dev->mtu) {
888 889 890
		ret = batadv_frag_send_skb(skb, bat_priv,
					   neigh_node->if_incoming,
					   neigh_node->addr);
891 892
		goto out;
	}
893

894
	if (unicast_packet->header.packet_type == BATADV_UNICAST_FRAG &&
895 896
	    batadv_frag_can_reassemble(skb,
				       neigh_node->if_incoming->net_dev->mtu)) {
897

898
		ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb);
899 900

		if (ret == NET_RX_DROP)
901
			goto out;
902 903

		/* packet was buffered for late merge */
904 905 906 907
		if (!new_skb) {
			ret = NET_RX_SUCCESS;
			goto out;
		}
908 909

		skb = new_skb;
910
		unicast_packet = (struct batadv_unicast_packet *)skb->data;
911 912 913
	}

	/* decrement ttl */
914
	unicast_packet->header.ttl--;
915

916
	/* Update stats counter */
917 918
	batadv_inc_counter(bat_priv, BATADV_CNT_FORWARD);
	batadv_add_counter(bat_priv, BATADV_CNT_FORWARD_BYTES,
919 920
			   skb->len + ETH_HLEN);

921
	/* route it */
922
	batadv_send_skb_packet(skb, neigh_node->if_incoming, neigh_node->addr);
923
	ret = NET_RX_SUCCESS;
924

925 926
out:
	if (neigh_node)
927
		batadv_neigh_node_free_ref(neigh_node);
928
	if (orig_node)
929
		batadv_orig_node_free_ref(orig_node);
930
	return ret;
931 932
}

933
static int batadv_check_unicast_ttvn(struct batadv_priv *bat_priv,
934
				     struct sk_buff *skb) {
935
	uint8_t curr_ttvn;
936
	struct batadv_orig_node *orig_node;
937
	struct ethhdr *ethhdr;
938
	struct batadv_hard_iface *primary_if;
939
	struct batadv_unicast_packet *unicast_packet;
940
	bool tt_poss_change;
941
	int is_old_ttvn;
942 943

	/* I could need to modify it */
944
	if (skb_cow(skb, sizeof(struct batadv_unicast_packet)) < 0)
945 946
		return 0;

947
	unicast_packet = (struct batadv_unicast_packet *)skb->data;
948

949
	if (batadv_is_my_mac(unicast_packet->dest)) {
950
		tt_poss_change = bat_priv->tt_poss_change;
951
		curr_ttvn = (uint8_t)atomic_read(&bat_priv->ttvn);
952
	} else {
953 954
		orig_node = batadv_orig_hash_find(bat_priv,
						  unicast_packet->dest);
955 956 957 958 959

		if (!orig_node)
			return 0;

		curr_ttvn = (uint8_t)atomic_read(&orig_node->last_ttvn);
960
		tt_poss_change = orig_node->tt_poss_change;
961
		batadv_orig_node_free_ref(orig_node);
962 963 964
	}

	/* Check whether I have to reroute the packet */
965 966
	is_old_ttvn = batadv_seq_before(unicast_packet->ttvn, curr_ttvn);
	if (is_old_ttvn || tt_poss_change) {
967
		/* check if there is enough data before accessing it */
968
		if (pskb_may_pull(skb, sizeof(struct batadv_unicast_packet) +
969
				  ETH_HLEN) < 0)
970 971 972
			return 0;

		ethhdr = (struct ethhdr *)(skb->data +
973
			sizeof(struct batadv_unicast_packet));
974 975 976 977

		/* we don't have an updated route for this client, so we should
		 * not try to reroute the packet!!
		 */
978 979
		if (batadv_tt_global_client_is_roaming(bat_priv,
						       ethhdr->h_dest))
980 981
			return 1;

982 983
		orig_node = batadv_transtable_search(bat_priv, NULL,
						     ethhdr->h_dest);
984 985

		if (!orig_node) {
986
			if (!batadv_is_my_client(bat_priv, ethhdr->h_dest))
987
				return 0;
988
			primary_if = batadv_primary_if_get_selected(bat_priv);
989 990 991 992
			if (!primary_if)
				return 0;
			memcpy(unicast_packet->dest,
			       primary_if->net_dev->dev_addr, ETH_ALEN);
993
			batadv_hardif_free_ref(primary_if);
994 995 996 997 998
		} else {
			memcpy(unicast_packet->dest, orig_node->orig,
			       ETH_ALEN);
			curr_ttvn = (uint8_t)
				atomic_read(&orig_node->last_ttvn);
999
			batadv_orig_node_free_ref(orig_node);
1000 1001
		}

1002
		batadv_dbg(BATADV_DBG_ROUTES, bat_priv,
1003 1004 1005
			   "TTVN mismatch (old_ttvn %u new_ttvn %u)! Rerouting unicast packet (for %pM) to %pM\n",
			   unicast_packet->ttvn, curr_ttvn, ethhdr->h_dest,
			   unicast_packet->dest);
1006 1007 1008 1009 1010 1011

		unicast_packet->ttvn = curr_ttvn;
	}
	return 1;
}

1012 1013
int batadv_recv_unicast_packet(struct sk_buff *skb,
			       struct batadv_hard_iface *recv_if)
1014
{
1015
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1016
	struct batadv_unicast_packet *unicast_packet;
1017
	int hdr_size = sizeof(*unicast_packet);
1018

1019
	if (batadv_check_unicast_packet(skb, hdr_size) < 0)
1020 1021
		return NET_RX_DROP;

1022
	if (!batadv_check_unicast_ttvn(bat_priv, skb))
1023 1024
		return NET_RX_DROP;

1025
	unicast_packet = (struct batadv_unicast_packet *)skb->data;
1026 1027

	/* packet for me */
1028
	if (batadv_is_my_mac(unicast_packet->dest)) {
1029 1030
		batadv_interface_rx(recv_if->soft_iface, skb, recv_if,
				    hdr_size);
1031 1032 1033
		return NET_RX_SUCCESS;
	}

1034
	return batadv_route_unicast_packet(skb, recv_if);
1035 1036
}

1037
int batadv_recv_ucast_frag_packet(struct sk_buff *skb,
1038
				  struct batadv_hard_iface *recv_if)
1039
{
1040
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1041
	struct batadv_unicast_frag_packet *unicast_packet;
1042
	int hdr_size = sizeof(*unicast_packet);
1043 1044 1045
	struct sk_buff *new_skb = NULL;
	int ret;

1046
	if (batadv_check_unicast_packet(skb, hdr_size) < 0)
1047 1048
		return NET_RX_DROP;

1049
	if (!batadv_check_unicast_ttvn(bat_priv, skb))
1050 1051
		return NET_RX_DROP;

1052
	unicast_packet = (struct batadv_unicast_frag_packet *)skb->data;
1053 1054

	/* packet for me */
1055
	if (batadv_is_my_mac(unicast_packet->dest)) {
1056

1057
		ret = batadv_frag_reassemble_skb(skb, bat_priv, &new_skb);
1058 1059 1060 1061 1062 1063 1064 1065

		if (ret == NET_RX_DROP)
			return NET_RX_DROP;

		/* packet was buffered for late merge */
		if (!new_skb)
			return NET_RX_SUCCESS;

1066
		batadv_interface_rx(recv_if->soft_iface, new_skb, recv_if,
1067
				    sizeof(struct batadv_unicast_packet));
1068 1069 1070
		return NET_RX_SUCCESS;
	}

1071
	return batadv_route_unicast_packet(skb, recv_if);
1072 1073 1074
}


1075 1076
int batadv_recv_bcast_packet(struct sk_buff *skb,
			     struct batadv_hard_iface *recv_if)
1077
{
1078 1079
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
	struct batadv_orig_node *orig_node = NULL;
1080
	struct batadv_bcast_packet *bcast_packet;
1081
	struct ethhdr *ethhdr;
1082
	int hdr_size = sizeof(*bcast_packet);
1083
	int ret = NET_RX_DROP;
1084 1085 1086 1087
	int32_t seq_diff;

	/* drop packet if it has not necessary minimum size */
	if (unlikely(!pskb_may_pull(skb, hdr_size)))
1088
		goto out;
1089 1090 1091 1092 1093

	ethhdr = (struct ethhdr *)skb_mac_header(skb);

	/* packet with broadcast indication but unicast recipient */
	if (!is_broadcast_ether_addr(ethhdr->h_dest))
1094
		goto out;
1095 1096 1097

	/* packet with broadcast sender address */
	if (is_broadcast_ether_addr(ethhdr->h_source))
1098
		goto out;
1099 1100

	/* ignore broadcasts sent by myself */
1101
	if (batadv_is_my_mac(ethhdr->h_source))
1102
		goto out;
1103

1104
	bcast_packet = (struct batadv_bcast_packet *)skb->data;
1105 1106

	/* ignore broadcasts originated by myself */
1107
	if (batadv_is_my_mac(bcast_packet->orig))
1108
		goto out;
1109

1110
	if (bcast_packet->header.ttl < 2)
1111
		goto out;
1112

1113
	orig_node = batadv_orig_hash_find(bat_priv, bcast_packet->orig);
1114 1115

	if (!orig_node)
1116
		goto out;
1117

1118
	spin_lock_bh(&orig_node->bcast_seqno_lock);
1119 1120

	/* check whether the packet is a duplicate */
1121 1122
	if (batadv_test_bit(orig_node->bcast_bits, orig_node->last_bcast_seqno,
			    ntohl(bcast_packet->seqno)))
1123
		goto spin_unlock;
1124 1125 1126 1127

	seq_diff = ntohl(bcast_packet->seqno) - orig_node->last_bcast_seqno;

	/* check whether the packet is old and the host just restarted. */
1128 1129
	if (batadv_window_protected(bat_priv, seq_diff,
				    &orig_node->bcast_seqno_reset))
1130
		goto spin_unlock;
1131 1132

	/* mark broadcast in flood history, update window position
1133 1134
	 * if required.
	 */
1135
	if (batadv_bit_get_packet(bat_priv, orig_node->bcast_bits, seq_diff, 1))
1136 1137
		orig_node->last_bcast_seqno = ntohl(bcast_packet->seqno);

1138 1139
	spin_unlock_bh(&orig_node->bcast_seqno_lock);

1140
	/* check whether this has been sent by another originator before */
1141
	if (batadv_bla_check_bcast_duplist(bat_priv, bcast_packet, hdr_size))
1142 1143
		goto out;

1144
	/* rebroadcast packet */
1145
	batadv_add_bcast_packet_to_list(bat_priv, skb, 1);
1146

1147 1148 1149
	/* don't hand the broadcast up if it is from an originator
	 * from the same backbone.
	 */
1150
	if (batadv_bla_is_backbone_gw(skb, orig_node, hdr_size))
1151 1152
		goto out;

1153
	/* broadcast for me */
1154
	batadv_interface_rx(recv_if->soft_iface, skb, recv_if, hdr_size);
1155 1156
	ret = NET_RX_SUCCESS;
	goto out;
1157

1158 1159 1160 1161
spin_unlock:
	spin_unlock_bh(&orig_node->bcast_seqno_lock);
out:
	if (orig_node)
1162
		batadv_orig_node_free_ref(orig_node);
1163
	return ret;
1164 1165
}

1166 1167
int batadv_recv_vis_packet(struct sk_buff *skb,
			   struct batadv_hard_iface *recv_if)
1168
{
1169
	struct batadv_vis_packet *vis_packet;
1170
	struct ethhdr *ethhdr;
1171
	struct batadv_priv *bat_priv = netdev_priv(recv_if->soft_iface);
1172
	int hdr_size = sizeof(*vis_packet);
1173 1174 1175 1176 1177 1178 1179 1180

	/* keep skb linear */
	if (skb_linearize(skb) < 0)
		return NET_RX_DROP;

	if (unlikely(!pskb_may_pull(skb, hdr_size)))
		return NET_RX_DROP;

1181
	vis_packet = (struct batadv_vis_packet *)skb->data;
1182 1183 1184
	ethhdr = (struct ethhdr *)skb_mac_header(skb);

	/* not for me */
1185
	if (!batadv_is_my_mac(ethhdr->h_dest))
1186 1187 1188
		return NET_RX_DROP;

	/* ignore own packets */
1189
	if (batadv_is_my_mac(vis_packet->vis_orig))
1190 1191
		return NET_RX_DROP;

1192
	if (batadv_is_my_mac(vis_packet->sender_orig))
1193 1194 1195
		return NET_RX_DROP;

	switch (vis_packet->vis_type) {
1196
	case BATADV_VIS_TYPE_SERVER_SYNC:
1197 1198
		batadv_receive_server_sync_packet(bat_priv, vis_packet,
						  skb_headlen(skb));
1199 1200
		break;

1201
	case BATADV_VIS_TYPE_CLIENT_UPDATE:
1202 1203
		batadv_receive_client_update_packet(bat_priv, vis_packet,
						    skb_headlen(skb));
1204 1205 1206 1207 1208 1209 1210
		break;

	default:	/* ignore unknown packet */
		break;
	}

	/* We take a copy of the data in the packet, so we should
1211 1212
	 * always free the skbuf.
	 */
1213 1214
	return NET_RX_DROP;
}