162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci *  net/dccp/options.c
462306a36Sopenharmony_ci *
562306a36Sopenharmony_ci *  An implementation of the DCCP protocol
662306a36Sopenharmony_ci *  Copyright (c) 2005 Aristeu Sergio Rozanski Filho <aris@cathedrallabs.org>
762306a36Sopenharmony_ci *  Copyright (c) 2005 Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
862306a36Sopenharmony_ci *  Copyright (c) 2005 Ian McDonald <ian.mcdonald@jandi.co.nz>
962306a36Sopenharmony_ci */
1062306a36Sopenharmony_ci#include <linux/dccp.h>
1162306a36Sopenharmony_ci#include <linux/module.h>
1262306a36Sopenharmony_ci#include <linux/types.h>
1362306a36Sopenharmony_ci#include <asm/unaligned.h>
1462306a36Sopenharmony_ci#include <linux/kernel.h>
1562306a36Sopenharmony_ci#include <linux/skbuff.h>
1662306a36Sopenharmony_ci
1762306a36Sopenharmony_ci#include "ackvec.h"
1862306a36Sopenharmony_ci#include "ccid.h"
1962306a36Sopenharmony_ci#include "dccp.h"
2062306a36Sopenharmony_ci#include "feat.h"
2162306a36Sopenharmony_ci
2262306a36Sopenharmony_ciu64 dccp_decode_value_var(const u8 *bf, const u8 len)
2362306a36Sopenharmony_ci{
2462306a36Sopenharmony_ci	u64 value = 0;
2562306a36Sopenharmony_ci
2662306a36Sopenharmony_ci	if (len >= DCCP_OPTVAL_MAXLEN)
2762306a36Sopenharmony_ci		value += ((u64)*bf++) << 40;
2862306a36Sopenharmony_ci	if (len > 4)
2962306a36Sopenharmony_ci		value += ((u64)*bf++) << 32;
3062306a36Sopenharmony_ci	if (len > 3)
3162306a36Sopenharmony_ci		value += ((u64)*bf++) << 24;
3262306a36Sopenharmony_ci	if (len > 2)
3362306a36Sopenharmony_ci		value += ((u64)*bf++) << 16;
3462306a36Sopenharmony_ci	if (len > 1)
3562306a36Sopenharmony_ci		value += ((u64)*bf++) << 8;
3662306a36Sopenharmony_ci	if (len > 0)
3762306a36Sopenharmony_ci		value += *bf;
3862306a36Sopenharmony_ci
3962306a36Sopenharmony_ci	return value;
4062306a36Sopenharmony_ci}
4162306a36Sopenharmony_ci
4262306a36Sopenharmony_ci/**
4362306a36Sopenharmony_ci * dccp_parse_options  -  Parse DCCP options present in @skb
4462306a36Sopenharmony_ci * @sk: client|server|listening dccp socket (when @dreq != NULL)
4562306a36Sopenharmony_ci * @dreq: request socket to use during connection setup, or NULL
4662306a36Sopenharmony_ci * @skb: frame to parse
4762306a36Sopenharmony_ci */
4862306a36Sopenharmony_ciint dccp_parse_options(struct sock *sk, struct dccp_request_sock *dreq,
4962306a36Sopenharmony_ci		       struct sk_buff *skb)
5062306a36Sopenharmony_ci{
5162306a36Sopenharmony_ci	struct dccp_sock *dp = dccp_sk(sk);
5262306a36Sopenharmony_ci	const struct dccp_hdr *dh = dccp_hdr(skb);
5362306a36Sopenharmony_ci	const u8 pkt_type = DCCP_SKB_CB(skb)->dccpd_type;
5462306a36Sopenharmony_ci	unsigned char *options = (unsigned char *)dh + dccp_hdr_len(skb);
5562306a36Sopenharmony_ci	unsigned char *opt_ptr = options;
5662306a36Sopenharmony_ci	const unsigned char *opt_end = (unsigned char *)dh +
5762306a36Sopenharmony_ci					(dh->dccph_doff * 4);
5862306a36Sopenharmony_ci	struct dccp_options_received *opt_recv = &dp->dccps_options_received;
5962306a36Sopenharmony_ci	unsigned char opt, len;
6062306a36Sopenharmony_ci	unsigned char *value;
6162306a36Sopenharmony_ci	u32 elapsed_time;
6262306a36Sopenharmony_ci	__be32 opt_val;
6362306a36Sopenharmony_ci	int rc;
6462306a36Sopenharmony_ci	int mandatory = 0;
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_ci	memset(opt_recv, 0, sizeof(*opt_recv));
6762306a36Sopenharmony_ci
6862306a36Sopenharmony_ci	opt = len = 0;
6962306a36Sopenharmony_ci	while (opt_ptr != opt_end) {
7062306a36Sopenharmony_ci		opt   = *opt_ptr++;
7162306a36Sopenharmony_ci		len   = 0;
7262306a36Sopenharmony_ci		value = NULL;
7362306a36Sopenharmony_ci
7462306a36Sopenharmony_ci		/* Check if this isn't a single byte option */
7562306a36Sopenharmony_ci		if (opt > DCCPO_MAX_RESERVED) {
7662306a36Sopenharmony_ci			if (opt_ptr == opt_end)
7762306a36Sopenharmony_ci				goto out_nonsensical_length;
7862306a36Sopenharmony_ci
7962306a36Sopenharmony_ci			len = *opt_ptr++;
8062306a36Sopenharmony_ci			if (len < 2)
8162306a36Sopenharmony_ci				goto out_nonsensical_length;
8262306a36Sopenharmony_ci			/*
8362306a36Sopenharmony_ci			 * Remove the type and len fields, leaving
8462306a36Sopenharmony_ci			 * just the value size
8562306a36Sopenharmony_ci			 */
8662306a36Sopenharmony_ci			len	-= 2;
8762306a36Sopenharmony_ci			value	= opt_ptr;
8862306a36Sopenharmony_ci			opt_ptr += len;
8962306a36Sopenharmony_ci
9062306a36Sopenharmony_ci			if (opt_ptr > opt_end)
9162306a36Sopenharmony_ci				goto out_nonsensical_length;
9262306a36Sopenharmony_ci		}
9362306a36Sopenharmony_ci
9462306a36Sopenharmony_ci		/*
9562306a36Sopenharmony_ci		 * CCID-specific options are ignored during connection setup, as
9662306a36Sopenharmony_ci		 * negotiation may still be in progress (see RFC 4340, 10.3).
9762306a36Sopenharmony_ci		 * The same applies to Ack Vectors, as these depend on the CCID.
9862306a36Sopenharmony_ci		 */
9962306a36Sopenharmony_ci		if (dreq != NULL && (opt >= DCCPO_MIN_RX_CCID_SPECIFIC ||
10062306a36Sopenharmony_ci		    opt == DCCPO_ACK_VECTOR_0 || opt == DCCPO_ACK_VECTOR_1))
10162306a36Sopenharmony_ci			goto ignore_option;
10262306a36Sopenharmony_ci
10362306a36Sopenharmony_ci		switch (opt) {
10462306a36Sopenharmony_ci		case DCCPO_PADDING:
10562306a36Sopenharmony_ci			break;
10662306a36Sopenharmony_ci		case DCCPO_MANDATORY:
10762306a36Sopenharmony_ci			if (mandatory)
10862306a36Sopenharmony_ci				goto out_invalid_option;
10962306a36Sopenharmony_ci			if (pkt_type != DCCP_PKT_DATA)
11062306a36Sopenharmony_ci				mandatory = 1;
11162306a36Sopenharmony_ci			break;
11262306a36Sopenharmony_ci		case DCCPO_NDP_COUNT:
11362306a36Sopenharmony_ci			if (len > 6)
11462306a36Sopenharmony_ci				goto out_invalid_option;
11562306a36Sopenharmony_ci
11662306a36Sopenharmony_ci			opt_recv->dccpor_ndp = dccp_decode_value_var(value, len);
11762306a36Sopenharmony_ci			dccp_pr_debug("%s opt: NDP count=%llu\n", dccp_role(sk),
11862306a36Sopenharmony_ci				      (unsigned long long)opt_recv->dccpor_ndp);
11962306a36Sopenharmony_ci			break;
12062306a36Sopenharmony_ci		case DCCPO_CHANGE_L ... DCCPO_CONFIRM_R:
12162306a36Sopenharmony_ci			if (pkt_type == DCCP_PKT_DATA)      /* RFC 4340, 6 */
12262306a36Sopenharmony_ci				break;
12362306a36Sopenharmony_ci			if (len == 0)
12462306a36Sopenharmony_ci				goto out_invalid_option;
12562306a36Sopenharmony_ci			rc = dccp_feat_parse_options(sk, dreq, mandatory, opt,
12662306a36Sopenharmony_ci						    *value, value + 1, len - 1);
12762306a36Sopenharmony_ci			if (rc)
12862306a36Sopenharmony_ci				goto out_featneg_failed;
12962306a36Sopenharmony_ci			break;
13062306a36Sopenharmony_ci		case DCCPO_TIMESTAMP:
13162306a36Sopenharmony_ci			if (len != 4)
13262306a36Sopenharmony_ci				goto out_invalid_option;
13362306a36Sopenharmony_ci			/*
13462306a36Sopenharmony_ci			 * RFC 4340 13.1: "The precise time corresponding to
13562306a36Sopenharmony_ci			 * Timestamp Value zero is not specified". We use
13662306a36Sopenharmony_ci			 * zero to indicate absence of a meaningful timestamp.
13762306a36Sopenharmony_ci			 */
13862306a36Sopenharmony_ci			opt_val = get_unaligned((__be32 *)value);
13962306a36Sopenharmony_ci			if (unlikely(opt_val == 0)) {
14062306a36Sopenharmony_ci				DCCP_WARN("Timestamp with zero value\n");
14162306a36Sopenharmony_ci				break;
14262306a36Sopenharmony_ci			}
14362306a36Sopenharmony_ci
14462306a36Sopenharmony_ci			if (dreq != NULL) {
14562306a36Sopenharmony_ci				dreq->dreq_timestamp_echo = ntohl(opt_val);
14662306a36Sopenharmony_ci				dreq->dreq_timestamp_time = dccp_timestamp();
14762306a36Sopenharmony_ci			} else {
14862306a36Sopenharmony_ci				opt_recv->dccpor_timestamp =
14962306a36Sopenharmony_ci					dp->dccps_timestamp_echo = ntohl(opt_val);
15062306a36Sopenharmony_ci				dp->dccps_timestamp_time = dccp_timestamp();
15162306a36Sopenharmony_ci			}
15262306a36Sopenharmony_ci			dccp_pr_debug("%s rx opt: TIMESTAMP=%u, ackno=%llu\n",
15362306a36Sopenharmony_ci				      dccp_role(sk), ntohl(opt_val),
15462306a36Sopenharmony_ci				      (unsigned long long)
15562306a36Sopenharmony_ci				      DCCP_SKB_CB(skb)->dccpd_ack_seq);
15662306a36Sopenharmony_ci			/* schedule an Ack in case this sender is quiescent */
15762306a36Sopenharmony_ci			inet_csk_schedule_ack(sk);
15862306a36Sopenharmony_ci			break;
15962306a36Sopenharmony_ci		case DCCPO_TIMESTAMP_ECHO:
16062306a36Sopenharmony_ci			if (len != 4 && len != 6 && len != 8)
16162306a36Sopenharmony_ci				goto out_invalid_option;
16262306a36Sopenharmony_ci
16362306a36Sopenharmony_ci			opt_val = get_unaligned((__be32 *)value);
16462306a36Sopenharmony_ci			opt_recv->dccpor_timestamp_echo = ntohl(opt_val);
16562306a36Sopenharmony_ci
16662306a36Sopenharmony_ci			dccp_pr_debug("%s rx opt: TIMESTAMP_ECHO=%u, len=%d, "
16762306a36Sopenharmony_ci				      "ackno=%llu", dccp_role(sk),
16862306a36Sopenharmony_ci				      opt_recv->dccpor_timestamp_echo,
16962306a36Sopenharmony_ci				      len + 2,
17062306a36Sopenharmony_ci				      (unsigned long long)
17162306a36Sopenharmony_ci				      DCCP_SKB_CB(skb)->dccpd_ack_seq);
17262306a36Sopenharmony_ci
17362306a36Sopenharmony_ci			value += 4;
17462306a36Sopenharmony_ci
17562306a36Sopenharmony_ci			if (len == 4) {		/* no elapsed time included */
17662306a36Sopenharmony_ci				dccp_pr_debug_cat("\n");
17762306a36Sopenharmony_ci				break;
17862306a36Sopenharmony_ci			}
17962306a36Sopenharmony_ci
18062306a36Sopenharmony_ci			if (len == 6) {		/* 2-byte elapsed time */
18162306a36Sopenharmony_ci				__be16 opt_val2 = get_unaligned((__be16 *)value);
18262306a36Sopenharmony_ci				elapsed_time = ntohs(opt_val2);
18362306a36Sopenharmony_ci			} else {		/* 4-byte elapsed time */
18462306a36Sopenharmony_ci				opt_val = get_unaligned((__be32 *)value);
18562306a36Sopenharmony_ci				elapsed_time = ntohl(opt_val);
18662306a36Sopenharmony_ci			}
18762306a36Sopenharmony_ci
18862306a36Sopenharmony_ci			dccp_pr_debug_cat(", ELAPSED_TIME=%u\n", elapsed_time);
18962306a36Sopenharmony_ci
19062306a36Sopenharmony_ci			/* Give precedence to the biggest ELAPSED_TIME */
19162306a36Sopenharmony_ci			if (elapsed_time > opt_recv->dccpor_elapsed_time)
19262306a36Sopenharmony_ci				opt_recv->dccpor_elapsed_time = elapsed_time;
19362306a36Sopenharmony_ci			break;
19462306a36Sopenharmony_ci		case DCCPO_ELAPSED_TIME:
19562306a36Sopenharmony_ci			if (dccp_packet_without_ack(skb))   /* RFC 4340, 13.2 */
19662306a36Sopenharmony_ci				break;
19762306a36Sopenharmony_ci
19862306a36Sopenharmony_ci			if (len == 2) {
19962306a36Sopenharmony_ci				__be16 opt_val2 = get_unaligned((__be16 *)value);
20062306a36Sopenharmony_ci				elapsed_time = ntohs(opt_val2);
20162306a36Sopenharmony_ci			} else if (len == 4) {
20262306a36Sopenharmony_ci				opt_val = get_unaligned((__be32 *)value);
20362306a36Sopenharmony_ci				elapsed_time = ntohl(opt_val);
20462306a36Sopenharmony_ci			} else {
20562306a36Sopenharmony_ci				goto out_invalid_option;
20662306a36Sopenharmony_ci			}
20762306a36Sopenharmony_ci
20862306a36Sopenharmony_ci			if (elapsed_time > opt_recv->dccpor_elapsed_time)
20962306a36Sopenharmony_ci				opt_recv->dccpor_elapsed_time = elapsed_time;
21062306a36Sopenharmony_ci
21162306a36Sopenharmony_ci			dccp_pr_debug("%s rx opt: ELAPSED_TIME=%d\n",
21262306a36Sopenharmony_ci				      dccp_role(sk), elapsed_time);
21362306a36Sopenharmony_ci			break;
21462306a36Sopenharmony_ci		case DCCPO_MIN_RX_CCID_SPECIFIC ... DCCPO_MAX_RX_CCID_SPECIFIC:
21562306a36Sopenharmony_ci			if (ccid_hc_rx_parse_options(dp->dccps_hc_rx_ccid, sk,
21662306a36Sopenharmony_ci						     pkt_type, opt, value, len))
21762306a36Sopenharmony_ci				goto out_invalid_option;
21862306a36Sopenharmony_ci			break;
21962306a36Sopenharmony_ci		case DCCPO_ACK_VECTOR_0:
22062306a36Sopenharmony_ci		case DCCPO_ACK_VECTOR_1:
22162306a36Sopenharmony_ci			if (dccp_packet_without_ack(skb))   /* RFC 4340, 11.4 */
22262306a36Sopenharmony_ci				break;
22362306a36Sopenharmony_ci			/*
22462306a36Sopenharmony_ci			 * Ack vectors are processed by the TX CCID if it is
22562306a36Sopenharmony_ci			 * interested. The RX CCID need not parse Ack Vectors,
22662306a36Sopenharmony_ci			 * since it is only interested in clearing old state.
22762306a36Sopenharmony_ci			 */
22862306a36Sopenharmony_ci			fallthrough;
22962306a36Sopenharmony_ci		case DCCPO_MIN_TX_CCID_SPECIFIC ... DCCPO_MAX_TX_CCID_SPECIFIC:
23062306a36Sopenharmony_ci			if (ccid_hc_tx_parse_options(dp->dccps_hc_tx_ccid, sk,
23162306a36Sopenharmony_ci						     pkt_type, opt, value, len))
23262306a36Sopenharmony_ci				goto out_invalid_option;
23362306a36Sopenharmony_ci			break;
23462306a36Sopenharmony_ci		default:
23562306a36Sopenharmony_ci			DCCP_CRIT("DCCP(%p): option %d(len=%d) not "
23662306a36Sopenharmony_ci				  "implemented, ignoring", sk, opt, len);
23762306a36Sopenharmony_ci			break;
23862306a36Sopenharmony_ci		}
23962306a36Sopenharmony_ciignore_option:
24062306a36Sopenharmony_ci		if (opt != DCCPO_MANDATORY)
24162306a36Sopenharmony_ci			mandatory = 0;
24262306a36Sopenharmony_ci	}
24362306a36Sopenharmony_ci
24462306a36Sopenharmony_ci	/* mandatory was the last byte in option list -> reset connection */
24562306a36Sopenharmony_ci	if (mandatory)
24662306a36Sopenharmony_ci		goto out_invalid_option;
24762306a36Sopenharmony_ci
24862306a36Sopenharmony_ciout_nonsensical_length:
24962306a36Sopenharmony_ci	/* RFC 4340, 5.8: ignore option and all remaining option space */
25062306a36Sopenharmony_ci	return 0;
25162306a36Sopenharmony_ci
25262306a36Sopenharmony_ciout_invalid_option:
25362306a36Sopenharmony_ci	DCCP_INC_STATS(DCCP_MIB_INVALIDOPT);
25462306a36Sopenharmony_ci	rc = DCCP_RESET_CODE_OPTION_ERROR;
25562306a36Sopenharmony_ciout_featneg_failed:
25662306a36Sopenharmony_ci	DCCP_WARN("DCCP(%p): Option %d (len=%d) error=%u\n", sk, opt, len, rc);
25762306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_reset_code = rc;
25862306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_reset_data[0] = opt;
25962306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_reset_data[1] = len > 0 ? value[0] : 0;
26062306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_reset_data[2] = len > 1 ? value[1] : 0;
26162306a36Sopenharmony_ci	return -1;
26262306a36Sopenharmony_ci}
26362306a36Sopenharmony_ci
26462306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(dccp_parse_options);
26562306a36Sopenharmony_ci
26662306a36Sopenharmony_civoid dccp_encode_value_var(const u64 value, u8 *to, const u8 len)
26762306a36Sopenharmony_ci{
26862306a36Sopenharmony_ci	if (len >= DCCP_OPTVAL_MAXLEN)
26962306a36Sopenharmony_ci		*to++ = (value & 0xFF0000000000ull) >> 40;
27062306a36Sopenharmony_ci	if (len > 4)
27162306a36Sopenharmony_ci		*to++ = (value & 0xFF00000000ull) >> 32;
27262306a36Sopenharmony_ci	if (len > 3)
27362306a36Sopenharmony_ci		*to++ = (value & 0xFF000000) >> 24;
27462306a36Sopenharmony_ci	if (len > 2)
27562306a36Sopenharmony_ci		*to++ = (value & 0xFF0000) >> 16;
27662306a36Sopenharmony_ci	if (len > 1)
27762306a36Sopenharmony_ci		*to++ = (value & 0xFF00) >> 8;
27862306a36Sopenharmony_ci	if (len > 0)
27962306a36Sopenharmony_ci		*to++ = (value & 0xFF);
28062306a36Sopenharmony_ci}
28162306a36Sopenharmony_ci
28262306a36Sopenharmony_cistatic inline u8 dccp_ndp_len(const u64 ndp)
28362306a36Sopenharmony_ci{
28462306a36Sopenharmony_ci	if (likely(ndp <= 0xFF))
28562306a36Sopenharmony_ci		return 1;
28662306a36Sopenharmony_ci	return likely(ndp <= USHRT_MAX) ? 2 : (ndp <= UINT_MAX ? 4 : 6);
28762306a36Sopenharmony_ci}
28862306a36Sopenharmony_ci
28962306a36Sopenharmony_ciint dccp_insert_option(struct sk_buff *skb, const unsigned char option,
29062306a36Sopenharmony_ci		       const void *value, const unsigned char len)
29162306a36Sopenharmony_ci{
29262306a36Sopenharmony_ci	unsigned char *to;
29362306a36Sopenharmony_ci
29462306a36Sopenharmony_ci	if (DCCP_SKB_CB(skb)->dccpd_opt_len + len + 2 > DCCP_MAX_OPT_LEN)
29562306a36Sopenharmony_ci		return -1;
29662306a36Sopenharmony_ci
29762306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_opt_len += len + 2;
29862306a36Sopenharmony_ci
29962306a36Sopenharmony_ci	to    = skb_push(skb, len + 2);
30062306a36Sopenharmony_ci	*to++ = option;
30162306a36Sopenharmony_ci	*to++ = len + 2;
30262306a36Sopenharmony_ci
30362306a36Sopenharmony_ci	memcpy(to, value, len);
30462306a36Sopenharmony_ci	return 0;
30562306a36Sopenharmony_ci}
30662306a36Sopenharmony_ci
30762306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(dccp_insert_option);
30862306a36Sopenharmony_ci
30962306a36Sopenharmony_cistatic int dccp_insert_option_ndp(struct sock *sk, struct sk_buff *skb)
31062306a36Sopenharmony_ci{
31162306a36Sopenharmony_ci	struct dccp_sock *dp = dccp_sk(sk);
31262306a36Sopenharmony_ci	u64 ndp = dp->dccps_ndp_count;
31362306a36Sopenharmony_ci
31462306a36Sopenharmony_ci	if (dccp_non_data_packet(skb))
31562306a36Sopenharmony_ci		++dp->dccps_ndp_count;
31662306a36Sopenharmony_ci	else
31762306a36Sopenharmony_ci		dp->dccps_ndp_count = 0;
31862306a36Sopenharmony_ci
31962306a36Sopenharmony_ci	if (ndp > 0) {
32062306a36Sopenharmony_ci		unsigned char *ptr;
32162306a36Sopenharmony_ci		const int ndp_len = dccp_ndp_len(ndp);
32262306a36Sopenharmony_ci		const int len = ndp_len + 2;
32362306a36Sopenharmony_ci
32462306a36Sopenharmony_ci		if (DCCP_SKB_CB(skb)->dccpd_opt_len + len > DCCP_MAX_OPT_LEN)
32562306a36Sopenharmony_ci			return -1;
32662306a36Sopenharmony_ci
32762306a36Sopenharmony_ci		DCCP_SKB_CB(skb)->dccpd_opt_len += len;
32862306a36Sopenharmony_ci
32962306a36Sopenharmony_ci		ptr = skb_push(skb, len);
33062306a36Sopenharmony_ci		*ptr++ = DCCPO_NDP_COUNT;
33162306a36Sopenharmony_ci		*ptr++ = len;
33262306a36Sopenharmony_ci		dccp_encode_value_var(ndp, ptr, ndp_len);
33362306a36Sopenharmony_ci	}
33462306a36Sopenharmony_ci
33562306a36Sopenharmony_ci	return 0;
33662306a36Sopenharmony_ci}
33762306a36Sopenharmony_ci
33862306a36Sopenharmony_cistatic inline int dccp_elapsed_time_len(const u32 elapsed_time)
33962306a36Sopenharmony_ci{
34062306a36Sopenharmony_ci	return elapsed_time == 0 ? 0 : elapsed_time <= 0xFFFF ? 2 : 4;
34162306a36Sopenharmony_ci}
34262306a36Sopenharmony_ci
34362306a36Sopenharmony_cistatic int dccp_insert_option_timestamp(struct sk_buff *skb)
34462306a36Sopenharmony_ci{
34562306a36Sopenharmony_ci	__be32 now = htonl(dccp_timestamp());
34662306a36Sopenharmony_ci	/* yes this will overflow but that is the point as we want a
34762306a36Sopenharmony_ci	 * 10 usec 32 bit timer which mean it wraps every 11.9 hours */
34862306a36Sopenharmony_ci
34962306a36Sopenharmony_ci	return dccp_insert_option(skb, DCCPO_TIMESTAMP, &now, sizeof(now));
35062306a36Sopenharmony_ci}
35162306a36Sopenharmony_ci
35262306a36Sopenharmony_cistatic int dccp_insert_option_timestamp_echo(struct dccp_sock *dp,
35362306a36Sopenharmony_ci					     struct dccp_request_sock *dreq,
35462306a36Sopenharmony_ci					     struct sk_buff *skb)
35562306a36Sopenharmony_ci{
35662306a36Sopenharmony_ci	__be32 tstamp_echo;
35762306a36Sopenharmony_ci	unsigned char *to;
35862306a36Sopenharmony_ci	u32 elapsed_time, elapsed_time_len, len;
35962306a36Sopenharmony_ci
36062306a36Sopenharmony_ci	if (dreq != NULL) {
36162306a36Sopenharmony_ci		elapsed_time = dccp_timestamp() - dreq->dreq_timestamp_time;
36262306a36Sopenharmony_ci		tstamp_echo  = htonl(dreq->dreq_timestamp_echo);
36362306a36Sopenharmony_ci		dreq->dreq_timestamp_echo = 0;
36462306a36Sopenharmony_ci	} else {
36562306a36Sopenharmony_ci		elapsed_time = dccp_timestamp() - dp->dccps_timestamp_time;
36662306a36Sopenharmony_ci		tstamp_echo  = htonl(dp->dccps_timestamp_echo);
36762306a36Sopenharmony_ci		dp->dccps_timestamp_echo = 0;
36862306a36Sopenharmony_ci	}
36962306a36Sopenharmony_ci
37062306a36Sopenharmony_ci	elapsed_time_len = dccp_elapsed_time_len(elapsed_time);
37162306a36Sopenharmony_ci	len = 6 + elapsed_time_len;
37262306a36Sopenharmony_ci
37362306a36Sopenharmony_ci	if (DCCP_SKB_CB(skb)->dccpd_opt_len + len > DCCP_MAX_OPT_LEN)
37462306a36Sopenharmony_ci		return -1;
37562306a36Sopenharmony_ci
37662306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_opt_len += len;
37762306a36Sopenharmony_ci
37862306a36Sopenharmony_ci	to    = skb_push(skb, len);
37962306a36Sopenharmony_ci	*to++ = DCCPO_TIMESTAMP_ECHO;
38062306a36Sopenharmony_ci	*to++ = len;
38162306a36Sopenharmony_ci
38262306a36Sopenharmony_ci	memcpy(to, &tstamp_echo, 4);
38362306a36Sopenharmony_ci	to += 4;
38462306a36Sopenharmony_ci
38562306a36Sopenharmony_ci	if (elapsed_time_len == 2) {
38662306a36Sopenharmony_ci		const __be16 var16 = htons((u16)elapsed_time);
38762306a36Sopenharmony_ci		memcpy(to, &var16, 2);
38862306a36Sopenharmony_ci	} else if (elapsed_time_len == 4) {
38962306a36Sopenharmony_ci		const __be32 var32 = htonl(elapsed_time);
39062306a36Sopenharmony_ci		memcpy(to, &var32, 4);
39162306a36Sopenharmony_ci	}
39262306a36Sopenharmony_ci
39362306a36Sopenharmony_ci	return 0;
39462306a36Sopenharmony_ci}
39562306a36Sopenharmony_ci
39662306a36Sopenharmony_cistatic int dccp_insert_option_ackvec(struct sock *sk, struct sk_buff *skb)
39762306a36Sopenharmony_ci{
39862306a36Sopenharmony_ci	struct dccp_sock *dp = dccp_sk(sk);
39962306a36Sopenharmony_ci	struct dccp_ackvec *av = dp->dccps_hc_rx_ackvec;
40062306a36Sopenharmony_ci	struct dccp_skb_cb *dcb = DCCP_SKB_CB(skb);
40162306a36Sopenharmony_ci	const u16 buflen = dccp_ackvec_buflen(av);
40262306a36Sopenharmony_ci	/* Figure out how many options do we need to represent the ackvec */
40362306a36Sopenharmony_ci	const u8 nr_opts = DIV_ROUND_UP(buflen, DCCP_SINGLE_OPT_MAXLEN);
40462306a36Sopenharmony_ci	u16 len = buflen + 2 * nr_opts;
40562306a36Sopenharmony_ci	u8 i, nonce = 0;
40662306a36Sopenharmony_ci	const unsigned char *tail, *from;
40762306a36Sopenharmony_ci	unsigned char *to;
40862306a36Sopenharmony_ci
40962306a36Sopenharmony_ci	if (dcb->dccpd_opt_len + len > DCCP_MAX_OPT_LEN) {
41062306a36Sopenharmony_ci		DCCP_WARN("Lacking space for %u bytes on %s packet\n", len,
41162306a36Sopenharmony_ci			  dccp_packet_name(dcb->dccpd_type));
41262306a36Sopenharmony_ci		return -1;
41362306a36Sopenharmony_ci	}
41462306a36Sopenharmony_ci	/*
41562306a36Sopenharmony_ci	 * Since Ack Vectors are variable-length, we can not always predict
41662306a36Sopenharmony_ci	 * their size. To catch exception cases where the space is running out
41762306a36Sopenharmony_ci	 * on the skb, a separate Sync is scheduled to carry the Ack Vector.
41862306a36Sopenharmony_ci	 */
41962306a36Sopenharmony_ci	if (len > DCCPAV_MIN_OPTLEN &&
42062306a36Sopenharmony_ci	    len + dcb->dccpd_opt_len + skb->len > dp->dccps_mss_cache) {
42162306a36Sopenharmony_ci		DCCP_WARN("No space left for Ack Vector (%u) on skb (%u+%u), "
42262306a36Sopenharmony_ci			  "MPS=%u ==> reduce payload size?\n", len, skb->len,
42362306a36Sopenharmony_ci			  dcb->dccpd_opt_len, dp->dccps_mss_cache);
42462306a36Sopenharmony_ci		dp->dccps_sync_scheduled = 1;
42562306a36Sopenharmony_ci		return 0;
42662306a36Sopenharmony_ci	}
42762306a36Sopenharmony_ci	dcb->dccpd_opt_len += len;
42862306a36Sopenharmony_ci
42962306a36Sopenharmony_ci	to   = skb_push(skb, len);
43062306a36Sopenharmony_ci	len  = buflen;
43162306a36Sopenharmony_ci	from = av->av_buf + av->av_buf_head;
43262306a36Sopenharmony_ci	tail = av->av_buf + DCCPAV_MAX_ACKVEC_LEN;
43362306a36Sopenharmony_ci
43462306a36Sopenharmony_ci	for (i = 0; i < nr_opts; ++i) {
43562306a36Sopenharmony_ci		int copylen = len;
43662306a36Sopenharmony_ci
43762306a36Sopenharmony_ci		if (len > DCCP_SINGLE_OPT_MAXLEN)
43862306a36Sopenharmony_ci			copylen = DCCP_SINGLE_OPT_MAXLEN;
43962306a36Sopenharmony_ci
44062306a36Sopenharmony_ci		/*
44162306a36Sopenharmony_ci		 * RFC 4340, 12.2: Encode the Nonce Echo for this Ack Vector via
44262306a36Sopenharmony_ci		 * its type; ack_nonce is the sum of all individual buf_nonce's.
44362306a36Sopenharmony_ci		 */
44462306a36Sopenharmony_ci		nonce ^= av->av_buf_nonce[i];
44562306a36Sopenharmony_ci
44662306a36Sopenharmony_ci		*to++ = DCCPO_ACK_VECTOR_0 + av->av_buf_nonce[i];
44762306a36Sopenharmony_ci		*to++ = copylen + 2;
44862306a36Sopenharmony_ci
44962306a36Sopenharmony_ci		/* Check if buf_head wraps */
45062306a36Sopenharmony_ci		if (from + copylen > tail) {
45162306a36Sopenharmony_ci			const u16 tailsize = tail - from;
45262306a36Sopenharmony_ci
45362306a36Sopenharmony_ci			memcpy(to, from, tailsize);
45462306a36Sopenharmony_ci			to	+= tailsize;
45562306a36Sopenharmony_ci			len	-= tailsize;
45662306a36Sopenharmony_ci			copylen	-= tailsize;
45762306a36Sopenharmony_ci			from	= av->av_buf;
45862306a36Sopenharmony_ci		}
45962306a36Sopenharmony_ci
46062306a36Sopenharmony_ci		memcpy(to, from, copylen);
46162306a36Sopenharmony_ci		from += copylen;
46262306a36Sopenharmony_ci		to   += copylen;
46362306a36Sopenharmony_ci		len  -= copylen;
46462306a36Sopenharmony_ci	}
46562306a36Sopenharmony_ci	/*
46662306a36Sopenharmony_ci	 * Each sent Ack Vector is recorded in the list, as per A.2 of RFC 4340.
46762306a36Sopenharmony_ci	 */
46862306a36Sopenharmony_ci	if (dccp_ackvec_update_records(av, dcb->dccpd_seq, nonce))
46962306a36Sopenharmony_ci		return -ENOBUFS;
47062306a36Sopenharmony_ci	return 0;
47162306a36Sopenharmony_ci}
47262306a36Sopenharmony_ci
47362306a36Sopenharmony_ci/**
47462306a36Sopenharmony_ci * dccp_insert_option_mandatory  -  Mandatory option (5.8.2)
47562306a36Sopenharmony_ci * @skb: frame into which to insert option
47662306a36Sopenharmony_ci *
47762306a36Sopenharmony_ci * Note that since we are using skb_push, this function needs to be called
47862306a36Sopenharmony_ci * _after_ inserting the option it is supposed to influence (stack order).
47962306a36Sopenharmony_ci */
48062306a36Sopenharmony_ciint dccp_insert_option_mandatory(struct sk_buff *skb)
48162306a36Sopenharmony_ci{
48262306a36Sopenharmony_ci	if (DCCP_SKB_CB(skb)->dccpd_opt_len >= DCCP_MAX_OPT_LEN)
48362306a36Sopenharmony_ci		return -1;
48462306a36Sopenharmony_ci
48562306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_opt_len++;
48662306a36Sopenharmony_ci	*(u8 *)skb_push(skb, 1) = DCCPO_MANDATORY;
48762306a36Sopenharmony_ci	return 0;
48862306a36Sopenharmony_ci}
48962306a36Sopenharmony_ci
49062306a36Sopenharmony_ci/**
49162306a36Sopenharmony_ci * dccp_insert_fn_opt  -  Insert single Feature-Negotiation option into @skb
49262306a36Sopenharmony_ci * @skb: frame to insert feature negotiation option into
49362306a36Sopenharmony_ci * @type: %DCCPO_CHANGE_L, %DCCPO_CHANGE_R, %DCCPO_CONFIRM_L, %DCCPO_CONFIRM_R
49462306a36Sopenharmony_ci * @feat: one out of %dccp_feature_numbers
49562306a36Sopenharmony_ci * @val: NN value or SP array (preferred element first) to copy
49662306a36Sopenharmony_ci * @len: true length of @val in bytes (excluding first element repetition)
49762306a36Sopenharmony_ci * @repeat_first: whether to copy the first element of @val twice
49862306a36Sopenharmony_ci *
49962306a36Sopenharmony_ci * The last argument is used to construct Confirm options, where the preferred
50062306a36Sopenharmony_ci * value and the preference list appear separately (RFC 4340, 6.3.1). Preference
50162306a36Sopenharmony_ci * lists are kept such that the preferred entry is always first, so we only need
50262306a36Sopenharmony_ci * to copy twice, and avoid the overhead of cloning into a bigger array.
50362306a36Sopenharmony_ci */
50462306a36Sopenharmony_ciint dccp_insert_fn_opt(struct sk_buff *skb, u8 type, u8 feat,
50562306a36Sopenharmony_ci		       u8 *val, u8 len, bool repeat_first)
50662306a36Sopenharmony_ci{
50762306a36Sopenharmony_ci	u8 tot_len, *to;
50862306a36Sopenharmony_ci
50962306a36Sopenharmony_ci	/* take the `Feature' field and possible repetition into account */
51062306a36Sopenharmony_ci	if (len > (DCCP_SINGLE_OPT_MAXLEN - 2)) {
51162306a36Sopenharmony_ci		DCCP_WARN("length %u for feature %u too large\n", len, feat);
51262306a36Sopenharmony_ci		return -1;
51362306a36Sopenharmony_ci	}
51462306a36Sopenharmony_ci
51562306a36Sopenharmony_ci	if (unlikely(val == NULL || len == 0))
51662306a36Sopenharmony_ci		len = repeat_first = false;
51762306a36Sopenharmony_ci	tot_len = 3 + repeat_first + len;
51862306a36Sopenharmony_ci
51962306a36Sopenharmony_ci	if (DCCP_SKB_CB(skb)->dccpd_opt_len + tot_len > DCCP_MAX_OPT_LEN) {
52062306a36Sopenharmony_ci		DCCP_WARN("packet too small for feature %d option!\n", feat);
52162306a36Sopenharmony_ci		return -1;
52262306a36Sopenharmony_ci	}
52362306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_opt_len += tot_len;
52462306a36Sopenharmony_ci
52562306a36Sopenharmony_ci	to    = skb_push(skb, tot_len);
52662306a36Sopenharmony_ci	*to++ = type;
52762306a36Sopenharmony_ci	*to++ = tot_len;
52862306a36Sopenharmony_ci	*to++ = feat;
52962306a36Sopenharmony_ci
53062306a36Sopenharmony_ci	if (repeat_first)
53162306a36Sopenharmony_ci		*to++ = *val;
53262306a36Sopenharmony_ci	if (len)
53362306a36Sopenharmony_ci		memcpy(to, val, len);
53462306a36Sopenharmony_ci	return 0;
53562306a36Sopenharmony_ci}
53662306a36Sopenharmony_ci
53762306a36Sopenharmony_ci/* The length of all options needs to be a multiple of 4 (5.8) */
53862306a36Sopenharmony_cistatic void dccp_insert_option_padding(struct sk_buff *skb)
53962306a36Sopenharmony_ci{
54062306a36Sopenharmony_ci	int padding = DCCP_SKB_CB(skb)->dccpd_opt_len % 4;
54162306a36Sopenharmony_ci
54262306a36Sopenharmony_ci	if (padding != 0) {
54362306a36Sopenharmony_ci		padding = 4 - padding;
54462306a36Sopenharmony_ci		memset(skb_push(skb, padding), 0, padding);
54562306a36Sopenharmony_ci		DCCP_SKB_CB(skb)->dccpd_opt_len += padding;
54662306a36Sopenharmony_ci	}
54762306a36Sopenharmony_ci}
54862306a36Sopenharmony_ci
54962306a36Sopenharmony_ciint dccp_insert_options(struct sock *sk, struct sk_buff *skb)
55062306a36Sopenharmony_ci{
55162306a36Sopenharmony_ci	struct dccp_sock *dp = dccp_sk(sk);
55262306a36Sopenharmony_ci
55362306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_opt_len = 0;
55462306a36Sopenharmony_ci
55562306a36Sopenharmony_ci	if (dp->dccps_send_ndp_count && dccp_insert_option_ndp(sk, skb))
55662306a36Sopenharmony_ci		return -1;
55762306a36Sopenharmony_ci
55862306a36Sopenharmony_ci	if (DCCP_SKB_CB(skb)->dccpd_type != DCCP_PKT_DATA) {
55962306a36Sopenharmony_ci
56062306a36Sopenharmony_ci		/* Feature Negotiation */
56162306a36Sopenharmony_ci		if (dccp_feat_insert_opts(dp, NULL, skb))
56262306a36Sopenharmony_ci			return -1;
56362306a36Sopenharmony_ci
56462306a36Sopenharmony_ci		if (DCCP_SKB_CB(skb)->dccpd_type == DCCP_PKT_REQUEST) {
56562306a36Sopenharmony_ci			/*
56662306a36Sopenharmony_ci			 * Obtain RTT sample from Request/Response exchange.
56762306a36Sopenharmony_ci			 * This is currently used for TFRC initialisation.
56862306a36Sopenharmony_ci			 */
56962306a36Sopenharmony_ci			if (dccp_insert_option_timestamp(skb))
57062306a36Sopenharmony_ci				return -1;
57162306a36Sopenharmony_ci
57262306a36Sopenharmony_ci		} else if (dccp_ackvec_pending(sk) &&
57362306a36Sopenharmony_ci			   dccp_insert_option_ackvec(sk, skb)) {
57462306a36Sopenharmony_ci				return -1;
57562306a36Sopenharmony_ci		}
57662306a36Sopenharmony_ci	}
57762306a36Sopenharmony_ci
57862306a36Sopenharmony_ci	if (dp->dccps_hc_rx_insert_options) {
57962306a36Sopenharmony_ci		if (ccid_hc_rx_insert_options(dp->dccps_hc_rx_ccid, sk, skb))
58062306a36Sopenharmony_ci			return -1;
58162306a36Sopenharmony_ci		dp->dccps_hc_rx_insert_options = 0;
58262306a36Sopenharmony_ci	}
58362306a36Sopenharmony_ci
58462306a36Sopenharmony_ci	if (dp->dccps_timestamp_echo != 0 &&
58562306a36Sopenharmony_ci	    dccp_insert_option_timestamp_echo(dp, NULL, skb))
58662306a36Sopenharmony_ci		return -1;
58762306a36Sopenharmony_ci
58862306a36Sopenharmony_ci	dccp_insert_option_padding(skb);
58962306a36Sopenharmony_ci	return 0;
59062306a36Sopenharmony_ci}
59162306a36Sopenharmony_ci
59262306a36Sopenharmony_ciint dccp_insert_options_rsk(struct dccp_request_sock *dreq, struct sk_buff *skb)
59362306a36Sopenharmony_ci{
59462306a36Sopenharmony_ci	DCCP_SKB_CB(skb)->dccpd_opt_len = 0;
59562306a36Sopenharmony_ci
59662306a36Sopenharmony_ci	if (dccp_feat_insert_opts(NULL, dreq, skb))
59762306a36Sopenharmony_ci		return -1;
59862306a36Sopenharmony_ci
59962306a36Sopenharmony_ci	/* Obtain RTT sample from Response/Ack exchange (used by TFRC). */
60062306a36Sopenharmony_ci	if (dccp_insert_option_timestamp(skb))
60162306a36Sopenharmony_ci		return -1;
60262306a36Sopenharmony_ci
60362306a36Sopenharmony_ci	if (dreq->dreq_timestamp_echo != 0 &&
60462306a36Sopenharmony_ci	    dccp_insert_option_timestamp_echo(NULL, dreq, skb))
60562306a36Sopenharmony_ci		return -1;
60662306a36Sopenharmony_ci
60762306a36Sopenharmony_ci	dccp_insert_option_padding(skb);
60862306a36Sopenharmony_ci	return 0;
60962306a36Sopenharmony_ci}
610