18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
28c2ecf20Sopenharmony_ci/*
38c2ecf20Sopenharmony_ci *
48c2ecf20Sopenharmony_ci * Copyright Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
58c2ecf20Sopenharmony_ci * Copyright Darryl Miles G7LED (dlm@g7led.demon.co.uk)
68c2ecf20Sopenharmony_ci */
78c2ecf20Sopenharmony_ci#include <linux/errno.h>
88c2ecf20Sopenharmony_ci#include <linux/types.h>
98c2ecf20Sopenharmony_ci#include <linux/socket.h>
108c2ecf20Sopenharmony_ci#include <linux/in.h>
118c2ecf20Sopenharmony_ci#include <linux/kernel.h>
128c2ecf20Sopenharmony_ci#include <linux/timer.h>
138c2ecf20Sopenharmony_ci#include <linux/string.h>
148c2ecf20Sopenharmony_ci#include <linux/sockios.h>
158c2ecf20Sopenharmony_ci#include <linux/net.h>
168c2ecf20Sopenharmony_ci#include <linux/slab.h>
178c2ecf20Sopenharmony_ci#include <net/ax25.h>
188c2ecf20Sopenharmony_ci#include <linux/inet.h>
198c2ecf20Sopenharmony_ci#include <linux/netdevice.h>
208c2ecf20Sopenharmony_ci#include <linux/skbuff.h>
218c2ecf20Sopenharmony_ci#include <net/sock.h>
228c2ecf20Sopenharmony_ci#include <net/tcp_states.h>
238c2ecf20Sopenharmony_ci#include <linux/uaccess.h>
248c2ecf20Sopenharmony_ci#include <linux/fcntl.h>
258c2ecf20Sopenharmony_ci#include <linux/mm.h>
268c2ecf20Sopenharmony_ci#include <linux/interrupt.h>
278c2ecf20Sopenharmony_ci#include <net/netrom.h>
288c2ecf20Sopenharmony_ci
298c2ecf20Sopenharmony_cistatic int nr_queue_rx_frame(struct sock *sk, struct sk_buff *skb, int more)
308c2ecf20Sopenharmony_ci{
318c2ecf20Sopenharmony_ci	struct sk_buff *skbo, *skbn = skb;
328c2ecf20Sopenharmony_ci	struct nr_sock *nr = nr_sk(sk);
338c2ecf20Sopenharmony_ci
348c2ecf20Sopenharmony_ci	skb_pull(skb, NR_NETWORK_LEN + NR_TRANSPORT_LEN);
358c2ecf20Sopenharmony_ci
368c2ecf20Sopenharmony_ci	nr_start_idletimer(sk);
378c2ecf20Sopenharmony_ci
388c2ecf20Sopenharmony_ci	if (more) {
398c2ecf20Sopenharmony_ci		nr->fraglen += skb->len;
408c2ecf20Sopenharmony_ci		skb_queue_tail(&nr->frag_queue, skb);
418c2ecf20Sopenharmony_ci		return 0;
428c2ecf20Sopenharmony_ci	}
438c2ecf20Sopenharmony_ci
448c2ecf20Sopenharmony_ci	if (!more && nr->fraglen > 0) {	/* End of fragment */
458c2ecf20Sopenharmony_ci		nr->fraglen += skb->len;
468c2ecf20Sopenharmony_ci		skb_queue_tail(&nr->frag_queue, skb);
478c2ecf20Sopenharmony_ci
488c2ecf20Sopenharmony_ci		if ((skbn = alloc_skb(nr->fraglen, GFP_ATOMIC)) == NULL)
498c2ecf20Sopenharmony_ci			return 1;
508c2ecf20Sopenharmony_ci
518c2ecf20Sopenharmony_ci		skb_reset_transport_header(skbn);
528c2ecf20Sopenharmony_ci
538c2ecf20Sopenharmony_ci		while ((skbo = skb_dequeue(&nr->frag_queue)) != NULL) {
548c2ecf20Sopenharmony_ci			skb_copy_from_linear_data(skbo,
558c2ecf20Sopenharmony_ci						  skb_put(skbn, skbo->len),
568c2ecf20Sopenharmony_ci						  skbo->len);
578c2ecf20Sopenharmony_ci			kfree_skb(skbo);
588c2ecf20Sopenharmony_ci		}
598c2ecf20Sopenharmony_ci
608c2ecf20Sopenharmony_ci		nr->fraglen = 0;
618c2ecf20Sopenharmony_ci	}
628c2ecf20Sopenharmony_ci
638c2ecf20Sopenharmony_ci	return sock_queue_rcv_skb(sk, skbn);
648c2ecf20Sopenharmony_ci}
658c2ecf20Sopenharmony_ci
668c2ecf20Sopenharmony_ci/*
678c2ecf20Sopenharmony_ci * State machine for state 1, Awaiting Connection State.
688c2ecf20Sopenharmony_ci * The handling of the timer(s) is in file nr_timer.c.
698c2ecf20Sopenharmony_ci * Handling of state 0 and connection release is in netrom.c.
708c2ecf20Sopenharmony_ci */
718c2ecf20Sopenharmony_cistatic int nr_state1_machine(struct sock *sk, struct sk_buff *skb,
728c2ecf20Sopenharmony_ci	int frametype)
738c2ecf20Sopenharmony_ci{
748c2ecf20Sopenharmony_ci	switch (frametype) {
758c2ecf20Sopenharmony_ci	case NR_CONNACK: {
768c2ecf20Sopenharmony_ci		struct nr_sock *nr = nr_sk(sk);
778c2ecf20Sopenharmony_ci
788c2ecf20Sopenharmony_ci		nr_stop_t1timer(sk);
798c2ecf20Sopenharmony_ci		nr_start_idletimer(sk);
808c2ecf20Sopenharmony_ci		nr->your_index = skb->data[17];
818c2ecf20Sopenharmony_ci		nr->your_id    = skb->data[18];
828c2ecf20Sopenharmony_ci		nr->vs	       = 0;
838c2ecf20Sopenharmony_ci		nr->va	       = 0;
848c2ecf20Sopenharmony_ci		nr->vr	       = 0;
858c2ecf20Sopenharmony_ci		nr->vl	       = 0;
868c2ecf20Sopenharmony_ci		nr->state      = NR_STATE_3;
878c2ecf20Sopenharmony_ci		nr->n2count    = 0;
888c2ecf20Sopenharmony_ci		nr->window     = skb->data[20];
898c2ecf20Sopenharmony_ci		sk->sk_state   = TCP_ESTABLISHED;
908c2ecf20Sopenharmony_ci		if (!sock_flag(sk, SOCK_DEAD))
918c2ecf20Sopenharmony_ci			sk->sk_state_change(sk);
928c2ecf20Sopenharmony_ci		break;
938c2ecf20Sopenharmony_ci	}
948c2ecf20Sopenharmony_ci
958c2ecf20Sopenharmony_ci	case NR_CONNACK | NR_CHOKE_FLAG:
968c2ecf20Sopenharmony_ci		nr_disconnect(sk, ECONNREFUSED);
978c2ecf20Sopenharmony_ci		break;
988c2ecf20Sopenharmony_ci
998c2ecf20Sopenharmony_ci	case NR_RESET:
1008c2ecf20Sopenharmony_ci		if (sysctl_netrom_reset_circuit)
1018c2ecf20Sopenharmony_ci			nr_disconnect(sk, ECONNRESET);
1028c2ecf20Sopenharmony_ci		break;
1038c2ecf20Sopenharmony_ci
1048c2ecf20Sopenharmony_ci	default:
1058c2ecf20Sopenharmony_ci		break;
1068c2ecf20Sopenharmony_ci	}
1078c2ecf20Sopenharmony_ci	return 0;
1088c2ecf20Sopenharmony_ci}
1098c2ecf20Sopenharmony_ci
1108c2ecf20Sopenharmony_ci/*
1118c2ecf20Sopenharmony_ci * State machine for state 2, Awaiting Release State.
1128c2ecf20Sopenharmony_ci * The handling of the timer(s) is in file nr_timer.c
1138c2ecf20Sopenharmony_ci * Handling of state 0 and connection release is in netrom.c.
1148c2ecf20Sopenharmony_ci */
1158c2ecf20Sopenharmony_cistatic int nr_state2_machine(struct sock *sk, struct sk_buff *skb,
1168c2ecf20Sopenharmony_ci	int frametype)
1178c2ecf20Sopenharmony_ci{
1188c2ecf20Sopenharmony_ci	switch (frametype) {
1198c2ecf20Sopenharmony_ci	case NR_CONNACK | NR_CHOKE_FLAG:
1208c2ecf20Sopenharmony_ci		nr_disconnect(sk, ECONNRESET);
1218c2ecf20Sopenharmony_ci		break;
1228c2ecf20Sopenharmony_ci
1238c2ecf20Sopenharmony_ci	case NR_DISCREQ:
1248c2ecf20Sopenharmony_ci		nr_write_internal(sk, NR_DISCACK);
1258c2ecf20Sopenharmony_ci		fallthrough;
1268c2ecf20Sopenharmony_ci	case NR_DISCACK:
1278c2ecf20Sopenharmony_ci		nr_disconnect(sk, 0);
1288c2ecf20Sopenharmony_ci		break;
1298c2ecf20Sopenharmony_ci
1308c2ecf20Sopenharmony_ci	case NR_RESET:
1318c2ecf20Sopenharmony_ci		if (sysctl_netrom_reset_circuit)
1328c2ecf20Sopenharmony_ci			nr_disconnect(sk, ECONNRESET);
1338c2ecf20Sopenharmony_ci		break;
1348c2ecf20Sopenharmony_ci
1358c2ecf20Sopenharmony_ci	default:
1368c2ecf20Sopenharmony_ci		break;
1378c2ecf20Sopenharmony_ci	}
1388c2ecf20Sopenharmony_ci	return 0;
1398c2ecf20Sopenharmony_ci}
1408c2ecf20Sopenharmony_ci
1418c2ecf20Sopenharmony_ci/*
1428c2ecf20Sopenharmony_ci * State machine for state 3, Connected State.
1438c2ecf20Sopenharmony_ci * The handling of the timer(s) is in file nr_timer.c
1448c2ecf20Sopenharmony_ci * Handling of state 0 and connection release is in netrom.c.
1458c2ecf20Sopenharmony_ci */
1468c2ecf20Sopenharmony_cistatic int nr_state3_machine(struct sock *sk, struct sk_buff *skb, int frametype)
1478c2ecf20Sopenharmony_ci{
1488c2ecf20Sopenharmony_ci	struct nr_sock *nrom = nr_sk(sk);
1498c2ecf20Sopenharmony_ci	struct sk_buff_head temp_queue;
1508c2ecf20Sopenharmony_ci	struct sk_buff *skbn;
1518c2ecf20Sopenharmony_ci	unsigned short save_vr;
1528c2ecf20Sopenharmony_ci	unsigned short nr, ns;
1538c2ecf20Sopenharmony_ci	int queued = 0;
1548c2ecf20Sopenharmony_ci
1558c2ecf20Sopenharmony_ci	nr = skb->data[18];
1568c2ecf20Sopenharmony_ci	ns = skb->data[17];
1578c2ecf20Sopenharmony_ci
1588c2ecf20Sopenharmony_ci	switch (frametype) {
1598c2ecf20Sopenharmony_ci	case NR_CONNREQ:
1608c2ecf20Sopenharmony_ci		nr_write_internal(sk, NR_CONNACK);
1618c2ecf20Sopenharmony_ci		break;
1628c2ecf20Sopenharmony_ci
1638c2ecf20Sopenharmony_ci	case NR_DISCREQ:
1648c2ecf20Sopenharmony_ci		nr_write_internal(sk, NR_DISCACK);
1658c2ecf20Sopenharmony_ci		nr_disconnect(sk, 0);
1668c2ecf20Sopenharmony_ci		break;
1678c2ecf20Sopenharmony_ci
1688c2ecf20Sopenharmony_ci	case NR_CONNACK | NR_CHOKE_FLAG:
1698c2ecf20Sopenharmony_ci	case NR_DISCACK:
1708c2ecf20Sopenharmony_ci		nr_disconnect(sk, ECONNRESET);
1718c2ecf20Sopenharmony_ci		break;
1728c2ecf20Sopenharmony_ci
1738c2ecf20Sopenharmony_ci	case NR_INFOACK:
1748c2ecf20Sopenharmony_ci	case NR_INFOACK | NR_CHOKE_FLAG:
1758c2ecf20Sopenharmony_ci	case NR_INFOACK | NR_NAK_FLAG:
1768c2ecf20Sopenharmony_ci	case NR_INFOACK | NR_NAK_FLAG | NR_CHOKE_FLAG:
1778c2ecf20Sopenharmony_ci		if (frametype & NR_CHOKE_FLAG) {
1788c2ecf20Sopenharmony_ci			nrom->condition |= NR_COND_PEER_RX_BUSY;
1798c2ecf20Sopenharmony_ci			nr_start_t4timer(sk);
1808c2ecf20Sopenharmony_ci		} else {
1818c2ecf20Sopenharmony_ci			nrom->condition &= ~NR_COND_PEER_RX_BUSY;
1828c2ecf20Sopenharmony_ci			nr_stop_t4timer(sk);
1838c2ecf20Sopenharmony_ci		}
1848c2ecf20Sopenharmony_ci		if (!nr_validate_nr(sk, nr)) {
1858c2ecf20Sopenharmony_ci			break;
1868c2ecf20Sopenharmony_ci		}
1878c2ecf20Sopenharmony_ci		if (frametype & NR_NAK_FLAG) {
1888c2ecf20Sopenharmony_ci			nr_frames_acked(sk, nr);
1898c2ecf20Sopenharmony_ci			nr_send_nak_frame(sk);
1908c2ecf20Sopenharmony_ci		} else {
1918c2ecf20Sopenharmony_ci			if (nrom->condition & NR_COND_PEER_RX_BUSY) {
1928c2ecf20Sopenharmony_ci				nr_frames_acked(sk, nr);
1938c2ecf20Sopenharmony_ci			} else {
1948c2ecf20Sopenharmony_ci				nr_check_iframes_acked(sk, nr);
1958c2ecf20Sopenharmony_ci			}
1968c2ecf20Sopenharmony_ci		}
1978c2ecf20Sopenharmony_ci		break;
1988c2ecf20Sopenharmony_ci
1998c2ecf20Sopenharmony_ci	case NR_INFO:
2008c2ecf20Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG:
2018c2ecf20Sopenharmony_ci	case NR_INFO | NR_CHOKE_FLAG:
2028c2ecf20Sopenharmony_ci	case NR_INFO | NR_MORE_FLAG:
2038c2ecf20Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG | NR_CHOKE_FLAG:
2048c2ecf20Sopenharmony_ci	case NR_INFO | NR_CHOKE_FLAG | NR_MORE_FLAG:
2058c2ecf20Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG | NR_MORE_FLAG:
2068c2ecf20Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG | NR_CHOKE_FLAG | NR_MORE_FLAG:
2078c2ecf20Sopenharmony_ci		if (frametype & NR_CHOKE_FLAG) {
2088c2ecf20Sopenharmony_ci			nrom->condition |= NR_COND_PEER_RX_BUSY;
2098c2ecf20Sopenharmony_ci			nr_start_t4timer(sk);
2108c2ecf20Sopenharmony_ci		} else {
2118c2ecf20Sopenharmony_ci			nrom->condition &= ~NR_COND_PEER_RX_BUSY;
2128c2ecf20Sopenharmony_ci			nr_stop_t4timer(sk);
2138c2ecf20Sopenharmony_ci		}
2148c2ecf20Sopenharmony_ci		if (nr_validate_nr(sk, nr)) {
2158c2ecf20Sopenharmony_ci			if (frametype & NR_NAK_FLAG) {
2168c2ecf20Sopenharmony_ci				nr_frames_acked(sk, nr);
2178c2ecf20Sopenharmony_ci				nr_send_nak_frame(sk);
2188c2ecf20Sopenharmony_ci			} else {
2198c2ecf20Sopenharmony_ci				if (nrom->condition & NR_COND_PEER_RX_BUSY) {
2208c2ecf20Sopenharmony_ci					nr_frames_acked(sk, nr);
2218c2ecf20Sopenharmony_ci				} else {
2228c2ecf20Sopenharmony_ci					nr_check_iframes_acked(sk, nr);
2238c2ecf20Sopenharmony_ci				}
2248c2ecf20Sopenharmony_ci			}
2258c2ecf20Sopenharmony_ci		}
2268c2ecf20Sopenharmony_ci		queued = 1;
2278c2ecf20Sopenharmony_ci		skb_queue_head(&nrom->reseq_queue, skb);
2288c2ecf20Sopenharmony_ci		if (nrom->condition & NR_COND_OWN_RX_BUSY)
2298c2ecf20Sopenharmony_ci			break;
2308c2ecf20Sopenharmony_ci		skb_queue_head_init(&temp_queue);
2318c2ecf20Sopenharmony_ci		do {
2328c2ecf20Sopenharmony_ci			save_vr = nrom->vr;
2338c2ecf20Sopenharmony_ci			while ((skbn = skb_dequeue(&nrom->reseq_queue)) != NULL) {
2348c2ecf20Sopenharmony_ci				ns = skbn->data[17];
2358c2ecf20Sopenharmony_ci				if (ns == nrom->vr) {
2368c2ecf20Sopenharmony_ci					if (nr_queue_rx_frame(sk, skbn, frametype & NR_MORE_FLAG) == 0) {
2378c2ecf20Sopenharmony_ci						nrom->vr = (nrom->vr + 1) % NR_MODULUS;
2388c2ecf20Sopenharmony_ci					} else {
2398c2ecf20Sopenharmony_ci						nrom->condition |= NR_COND_OWN_RX_BUSY;
2408c2ecf20Sopenharmony_ci						skb_queue_tail(&temp_queue, skbn);
2418c2ecf20Sopenharmony_ci					}
2428c2ecf20Sopenharmony_ci				} else if (nr_in_rx_window(sk, ns)) {
2438c2ecf20Sopenharmony_ci					skb_queue_tail(&temp_queue, skbn);
2448c2ecf20Sopenharmony_ci				} else {
2458c2ecf20Sopenharmony_ci					kfree_skb(skbn);
2468c2ecf20Sopenharmony_ci				}
2478c2ecf20Sopenharmony_ci			}
2488c2ecf20Sopenharmony_ci			while ((skbn = skb_dequeue(&temp_queue)) != NULL) {
2498c2ecf20Sopenharmony_ci				skb_queue_tail(&nrom->reseq_queue, skbn);
2508c2ecf20Sopenharmony_ci			}
2518c2ecf20Sopenharmony_ci		} while (save_vr != nrom->vr);
2528c2ecf20Sopenharmony_ci		/*
2538c2ecf20Sopenharmony_ci		 * Window is full, ack it immediately.
2548c2ecf20Sopenharmony_ci		 */
2558c2ecf20Sopenharmony_ci		if (((nrom->vl + nrom->window) % NR_MODULUS) == nrom->vr) {
2568c2ecf20Sopenharmony_ci			nr_enquiry_response(sk);
2578c2ecf20Sopenharmony_ci		} else {
2588c2ecf20Sopenharmony_ci			if (!(nrom->condition & NR_COND_ACK_PENDING)) {
2598c2ecf20Sopenharmony_ci				nrom->condition |= NR_COND_ACK_PENDING;
2608c2ecf20Sopenharmony_ci				nr_start_t2timer(sk);
2618c2ecf20Sopenharmony_ci			}
2628c2ecf20Sopenharmony_ci		}
2638c2ecf20Sopenharmony_ci		break;
2648c2ecf20Sopenharmony_ci
2658c2ecf20Sopenharmony_ci	case NR_RESET:
2668c2ecf20Sopenharmony_ci		if (sysctl_netrom_reset_circuit)
2678c2ecf20Sopenharmony_ci			nr_disconnect(sk, ECONNRESET);
2688c2ecf20Sopenharmony_ci		break;
2698c2ecf20Sopenharmony_ci
2708c2ecf20Sopenharmony_ci	default:
2718c2ecf20Sopenharmony_ci		break;
2728c2ecf20Sopenharmony_ci	}
2738c2ecf20Sopenharmony_ci	return queued;
2748c2ecf20Sopenharmony_ci}
2758c2ecf20Sopenharmony_ci
2768c2ecf20Sopenharmony_ci/* Higher level upcall for a LAPB frame - called with sk locked */
2778c2ecf20Sopenharmony_ciint nr_process_rx_frame(struct sock *sk, struct sk_buff *skb)
2788c2ecf20Sopenharmony_ci{
2798c2ecf20Sopenharmony_ci	struct nr_sock *nr = nr_sk(sk);
2808c2ecf20Sopenharmony_ci	int queued = 0, frametype;
2818c2ecf20Sopenharmony_ci
2828c2ecf20Sopenharmony_ci	if (nr->state == NR_STATE_0)
2838c2ecf20Sopenharmony_ci		return 0;
2848c2ecf20Sopenharmony_ci
2858c2ecf20Sopenharmony_ci	frametype = skb->data[19];
2868c2ecf20Sopenharmony_ci
2878c2ecf20Sopenharmony_ci	switch (nr->state) {
2888c2ecf20Sopenharmony_ci	case NR_STATE_1:
2898c2ecf20Sopenharmony_ci		queued = nr_state1_machine(sk, skb, frametype);
2908c2ecf20Sopenharmony_ci		break;
2918c2ecf20Sopenharmony_ci	case NR_STATE_2:
2928c2ecf20Sopenharmony_ci		queued = nr_state2_machine(sk, skb, frametype);
2938c2ecf20Sopenharmony_ci		break;
2948c2ecf20Sopenharmony_ci	case NR_STATE_3:
2958c2ecf20Sopenharmony_ci		queued = nr_state3_machine(sk, skb, frametype);
2968c2ecf20Sopenharmony_ci		break;
2978c2ecf20Sopenharmony_ci	}
2988c2ecf20Sopenharmony_ci
2998c2ecf20Sopenharmony_ci	nr_kick(sk);
3008c2ecf20Sopenharmony_ci
3018c2ecf20Sopenharmony_ci	return queued;
3028c2ecf20Sopenharmony_ci}
303