162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci *	LAPB release 002
462306a36Sopenharmony_ci *
562306a36Sopenharmony_ci *	This code REQUIRES 2.1.15 or higher/ NET3.038
662306a36Sopenharmony_ci *
762306a36Sopenharmony_ci *	History
862306a36Sopenharmony_ci *	LAPB 001	Jonathan Naylor	Started Coding
962306a36Sopenharmony_ci */
1062306a36Sopenharmony_ci
1162306a36Sopenharmony_ci#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
1262306a36Sopenharmony_ci
1362306a36Sopenharmony_ci#include <linux/errno.h>
1462306a36Sopenharmony_ci#include <linux/types.h>
1562306a36Sopenharmony_ci#include <linux/socket.h>
1662306a36Sopenharmony_ci#include <linux/in.h>
1762306a36Sopenharmony_ci#include <linux/kernel.h>
1862306a36Sopenharmony_ci#include <linux/timer.h>
1962306a36Sopenharmony_ci#include <linux/string.h>
2062306a36Sopenharmony_ci#include <linux/sockios.h>
2162306a36Sopenharmony_ci#include <linux/net.h>
2262306a36Sopenharmony_ci#include <linux/inet.h>
2362306a36Sopenharmony_ci#include <linux/skbuff.h>
2462306a36Sopenharmony_ci#include <linux/slab.h>
2562306a36Sopenharmony_ci#include <net/sock.h>
2662306a36Sopenharmony_ci#include <linux/uaccess.h>
2762306a36Sopenharmony_ci#include <linux/fcntl.h>
2862306a36Sopenharmony_ci#include <linux/mm.h>
2962306a36Sopenharmony_ci#include <linux/interrupt.h>
3062306a36Sopenharmony_ci#include <net/lapb.h>
3162306a36Sopenharmony_ci
3262306a36Sopenharmony_ci/*
3362306a36Sopenharmony_ci *	This routine purges all the queues of frames.
3462306a36Sopenharmony_ci */
3562306a36Sopenharmony_civoid lapb_clear_queues(struct lapb_cb *lapb)
3662306a36Sopenharmony_ci{
3762306a36Sopenharmony_ci	skb_queue_purge(&lapb->write_queue);
3862306a36Sopenharmony_ci	skb_queue_purge(&lapb->ack_queue);
3962306a36Sopenharmony_ci}
4062306a36Sopenharmony_ci
4162306a36Sopenharmony_ci/*
4262306a36Sopenharmony_ci * This routine purges the input queue of those frames that have been
4362306a36Sopenharmony_ci * acknowledged. This replaces the boxes labelled "V(a) <- N(r)" on the
4462306a36Sopenharmony_ci * SDL diagram.
4562306a36Sopenharmony_ci */
4662306a36Sopenharmony_civoid lapb_frames_acked(struct lapb_cb *lapb, unsigned short nr)
4762306a36Sopenharmony_ci{
4862306a36Sopenharmony_ci	struct sk_buff *skb;
4962306a36Sopenharmony_ci	int modulus;
5062306a36Sopenharmony_ci
5162306a36Sopenharmony_ci	modulus = (lapb->mode & LAPB_EXTENDED) ? LAPB_EMODULUS : LAPB_SMODULUS;
5262306a36Sopenharmony_ci
5362306a36Sopenharmony_ci	/*
5462306a36Sopenharmony_ci	 * Remove all the ack-ed frames from the ack queue.
5562306a36Sopenharmony_ci	 */
5662306a36Sopenharmony_ci	if (lapb->va != nr)
5762306a36Sopenharmony_ci		while (skb_peek(&lapb->ack_queue) && lapb->va != nr) {
5862306a36Sopenharmony_ci			skb = skb_dequeue(&lapb->ack_queue);
5962306a36Sopenharmony_ci			kfree_skb(skb);
6062306a36Sopenharmony_ci			lapb->va = (lapb->va + 1) % modulus;
6162306a36Sopenharmony_ci		}
6262306a36Sopenharmony_ci}
6362306a36Sopenharmony_ci
6462306a36Sopenharmony_civoid lapb_requeue_frames(struct lapb_cb *lapb)
6562306a36Sopenharmony_ci{
6662306a36Sopenharmony_ci	struct sk_buff *skb, *skb_prev = NULL;
6762306a36Sopenharmony_ci
6862306a36Sopenharmony_ci	/*
6962306a36Sopenharmony_ci	 * Requeue all the un-ack-ed frames on the output queue to be picked
7062306a36Sopenharmony_ci	 * up by lapb_kick called from the timer. This arrangement handles the
7162306a36Sopenharmony_ci	 * possibility of an empty output queue.
7262306a36Sopenharmony_ci	 */
7362306a36Sopenharmony_ci	while ((skb = skb_dequeue(&lapb->ack_queue)) != NULL) {
7462306a36Sopenharmony_ci		if (!skb_prev)
7562306a36Sopenharmony_ci			skb_queue_head(&lapb->write_queue, skb);
7662306a36Sopenharmony_ci		else
7762306a36Sopenharmony_ci			skb_append(skb_prev, skb, &lapb->write_queue);
7862306a36Sopenharmony_ci		skb_prev = skb;
7962306a36Sopenharmony_ci	}
8062306a36Sopenharmony_ci}
8162306a36Sopenharmony_ci
8262306a36Sopenharmony_ci/*
8362306a36Sopenharmony_ci *	Validate that the value of nr is between va and vs. Return true or
8462306a36Sopenharmony_ci *	false for testing.
8562306a36Sopenharmony_ci */
8662306a36Sopenharmony_ciint lapb_validate_nr(struct lapb_cb *lapb, unsigned short nr)
8762306a36Sopenharmony_ci{
8862306a36Sopenharmony_ci	unsigned short vc = lapb->va;
8962306a36Sopenharmony_ci	int modulus;
9062306a36Sopenharmony_ci
9162306a36Sopenharmony_ci	modulus = (lapb->mode & LAPB_EXTENDED) ? LAPB_EMODULUS : LAPB_SMODULUS;
9262306a36Sopenharmony_ci
9362306a36Sopenharmony_ci	while (vc != lapb->vs) {
9462306a36Sopenharmony_ci		if (nr == vc)
9562306a36Sopenharmony_ci			return 1;
9662306a36Sopenharmony_ci		vc = (vc + 1) % modulus;
9762306a36Sopenharmony_ci	}
9862306a36Sopenharmony_ci
9962306a36Sopenharmony_ci	return nr == lapb->vs;
10062306a36Sopenharmony_ci}
10162306a36Sopenharmony_ci
10262306a36Sopenharmony_ci/*
10362306a36Sopenharmony_ci *	This routine is the centralised routine for parsing the control
10462306a36Sopenharmony_ci *	information for the different frame formats.
10562306a36Sopenharmony_ci */
10662306a36Sopenharmony_ciint lapb_decode(struct lapb_cb *lapb, struct sk_buff *skb,
10762306a36Sopenharmony_ci		struct lapb_frame *frame)
10862306a36Sopenharmony_ci{
10962306a36Sopenharmony_ci	frame->type = LAPB_ILLEGAL;
11062306a36Sopenharmony_ci
11162306a36Sopenharmony_ci	lapb_dbg(2, "(%p) S%d RX %3ph\n", lapb->dev, lapb->state, skb->data);
11262306a36Sopenharmony_ci
11362306a36Sopenharmony_ci	/* We always need to look at 2 bytes, sometimes we need
11462306a36Sopenharmony_ci	 * to look at 3 and those cases are handled below.
11562306a36Sopenharmony_ci	 */
11662306a36Sopenharmony_ci	if (!pskb_may_pull(skb, 2))
11762306a36Sopenharmony_ci		return -1;
11862306a36Sopenharmony_ci
11962306a36Sopenharmony_ci	if (lapb->mode & LAPB_MLP) {
12062306a36Sopenharmony_ci		if (lapb->mode & LAPB_DCE) {
12162306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_D)
12262306a36Sopenharmony_ci				frame->cr = LAPB_COMMAND;
12362306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_C)
12462306a36Sopenharmony_ci				frame->cr = LAPB_RESPONSE;
12562306a36Sopenharmony_ci		} else {
12662306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_C)
12762306a36Sopenharmony_ci				frame->cr = LAPB_COMMAND;
12862306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_D)
12962306a36Sopenharmony_ci				frame->cr = LAPB_RESPONSE;
13062306a36Sopenharmony_ci		}
13162306a36Sopenharmony_ci	} else {
13262306a36Sopenharmony_ci		if (lapb->mode & LAPB_DCE) {
13362306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_B)
13462306a36Sopenharmony_ci				frame->cr = LAPB_COMMAND;
13562306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_A)
13662306a36Sopenharmony_ci				frame->cr = LAPB_RESPONSE;
13762306a36Sopenharmony_ci		} else {
13862306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_A)
13962306a36Sopenharmony_ci				frame->cr = LAPB_COMMAND;
14062306a36Sopenharmony_ci			if (skb->data[0] == LAPB_ADDR_B)
14162306a36Sopenharmony_ci				frame->cr = LAPB_RESPONSE;
14262306a36Sopenharmony_ci		}
14362306a36Sopenharmony_ci	}
14462306a36Sopenharmony_ci
14562306a36Sopenharmony_ci	skb_pull(skb, 1);
14662306a36Sopenharmony_ci
14762306a36Sopenharmony_ci	if (lapb->mode & LAPB_EXTENDED) {
14862306a36Sopenharmony_ci		if (!(skb->data[0] & LAPB_S)) {
14962306a36Sopenharmony_ci			if (!pskb_may_pull(skb, 2))
15062306a36Sopenharmony_ci				return -1;
15162306a36Sopenharmony_ci			/*
15262306a36Sopenharmony_ci			 * I frame - carries NR/NS/PF
15362306a36Sopenharmony_ci			 */
15462306a36Sopenharmony_ci			frame->type       = LAPB_I;
15562306a36Sopenharmony_ci			frame->ns         = (skb->data[0] >> 1) & 0x7F;
15662306a36Sopenharmony_ci			frame->nr         = (skb->data[1] >> 1) & 0x7F;
15762306a36Sopenharmony_ci			frame->pf         = skb->data[1] & LAPB_EPF;
15862306a36Sopenharmony_ci			frame->control[0] = skb->data[0];
15962306a36Sopenharmony_ci			frame->control[1] = skb->data[1];
16062306a36Sopenharmony_ci			skb_pull(skb, 2);
16162306a36Sopenharmony_ci		} else if ((skb->data[0] & LAPB_U) == 1) {
16262306a36Sopenharmony_ci			if (!pskb_may_pull(skb, 2))
16362306a36Sopenharmony_ci				return -1;
16462306a36Sopenharmony_ci			/*
16562306a36Sopenharmony_ci			 * S frame - take out PF/NR
16662306a36Sopenharmony_ci			 */
16762306a36Sopenharmony_ci			frame->type       = skb->data[0] & 0x0F;
16862306a36Sopenharmony_ci			frame->nr         = (skb->data[1] >> 1) & 0x7F;
16962306a36Sopenharmony_ci			frame->pf         = skb->data[1] & LAPB_EPF;
17062306a36Sopenharmony_ci			frame->control[0] = skb->data[0];
17162306a36Sopenharmony_ci			frame->control[1] = skb->data[1];
17262306a36Sopenharmony_ci			skb_pull(skb, 2);
17362306a36Sopenharmony_ci		} else if ((skb->data[0] & LAPB_U) == 3) {
17462306a36Sopenharmony_ci			/*
17562306a36Sopenharmony_ci			 * U frame - take out PF
17662306a36Sopenharmony_ci			 */
17762306a36Sopenharmony_ci			frame->type       = skb->data[0] & ~LAPB_SPF;
17862306a36Sopenharmony_ci			frame->pf         = skb->data[0] & LAPB_SPF;
17962306a36Sopenharmony_ci			frame->control[0] = skb->data[0];
18062306a36Sopenharmony_ci			frame->control[1] = 0x00;
18162306a36Sopenharmony_ci			skb_pull(skb, 1);
18262306a36Sopenharmony_ci		}
18362306a36Sopenharmony_ci	} else {
18462306a36Sopenharmony_ci		if (!(skb->data[0] & LAPB_S)) {
18562306a36Sopenharmony_ci			/*
18662306a36Sopenharmony_ci			 * I frame - carries NR/NS/PF
18762306a36Sopenharmony_ci			 */
18862306a36Sopenharmony_ci			frame->type = LAPB_I;
18962306a36Sopenharmony_ci			frame->ns   = (skb->data[0] >> 1) & 0x07;
19062306a36Sopenharmony_ci			frame->nr   = (skb->data[0] >> 5) & 0x07;
19162306a36Sopenharmony_ci			frame->pf   = skb->data[0] & LAPB_SPF;
19262306a36Sopenharmony_ci		} else if ((skb->data[0] & LAPB_U) == 1) {
19362306a36Sopenharmony_ci			/*
19462306a36Sopenharmony_ci			 * S frame - take out PF/NR
19562306a36Sopenharmony_ci			 */
19662306a36Sopenharmony_ci			frame->type = skb->data[0] & 0x0F;
19762306a36Sopenharmony_ci			frame->nr   = (skb->data[0] >> 5) & 0x07;
19862306a36Sopenharmony_ci			frame->pf   = skb->data[0] & LAPB_SPF;
19962306a36Sopenharmony_ci		} else if ((skb->data[0] & LAPB_U) == 3) {
20062306a36Sopenharmony_ci			/*
20162306a36Sopenharmony_ci			 * U frame - take out PF
20262306a36Sopenharmony_ci			 */
20362306a36Sopenharmony_ci			frame->type = skb->data[0] & ~LAPB_SPF;
20462306a36Sopenharmony_ci			frame->pf   = skb->data[0] & LAPB_SPF;
20562306a36Sopenharmony_ci		}
20662306a36Sopenharmony_ci
20762306a36Sopenharmony_ci		frame->control[0] = skb->data[0];
20862306a36Sopenharmony_ci
20962306a36Sopenharmony_ci		skb_pull(skb, 1);
21062306a36Sopenharmony_ci	}
21162306a36Sopenharmony_ci
21262306a36Sopenharmony_ci	return 0;
21362306a36Sopenharmony_ci}
21462306a36Sopenharmony_ci
21562306a36Sopenharmony_ci/*
21662306a36Sopenharmony_ci *	This routine is called when the HDLC layer internally  generates a
21762306a36Sopenharmony_ci *	command or  response  for  the remote machine ( eg. RR, UA etc. ).
21862306a36Sopenharmony_ci *	Only supervisory or unnumbered frames are processed, FRMRs are handled
21962306a36Sopenharmony_ci *	by lapb_transmit_frmr below.
22062306a36Sopenharmony_ci */
22162306a36Sopenharmony_civoid lapb_send_control(struct lapb_cb *lapb, int frametype,
22262306a36Sopenharmony_ci		       int poll_bit, int type)
22362306a36Sopenharmony_ci{
22462306a36Sopenharmony_ci	struct sk_buff *skb;
22562306a36Sopenharmony_ci	unsigned char  *dptr;
22662306a36Sopenharmony_ci
22762306a36Sopenharmony_ci	if ((skb = alloc_skb(LAPB_HEADER_LEN + 3, GFP_ATOMIC)) == NULL)
22862306a36Sopenharmony_ci		return;
22962306a36Sopenharmony_ci
23062306a36Sopenharmony_ci	skb_reserve(skb, LAPB_HEADER_LEN + 1);
23162306a36Sopenharmony_ci
23262306a36Sopenharmony_ci	if (lapb->mode & LAPB_EXTENDED) {
23362306a36Sopenharmony_ci		if ((frametype & LAPB_U) == LAPB_U) {
23462306a36Sopenharmony_ci			dptr   = skb_put(skb, 1);
23562306a36Sopenharmony_ci			*dptr  = frametype;
23662306a36Sopenharmony_ci			*dptr |= poll_bit ? LAPB_SPF : 0;
23762306a36Sopenharmony_ci		} else {
23862306a36Sopenharmony_ci			dptr     = skb_put(skb, 2);
23962306a36Sopenharmony_ci			dptr[0]  = frametype;
24062306a36Sopenharmony_ci			dptr[1]  = (lapb->vr << 1);
24162306a36Sopenharmony_ci			dptr[1] |= poll_bit ? LAPB_EPF : 0;
24262306a36Sopenharmony_ci		}
24362306a36Sopenharmony_ci	} else {
24462306a36Sopenharmony_ci		dptr   = skb_put(skb, 1);
24562306a36Sopenharmony_ci		*dptr  = frametype;
24662306a36Sopenharmony_ci		*dptr |= poll_bit ? LAPB_SPF : 0;
24762306a36Sopenharmony_ci		if ((frametype & LAPB_U) == LAPB_S)	/* S frames carry NR */
24862306a36Sopenharmony_ci			*dptr |= (lapb->vr << 5);
24962306a36Sopenharmony_ci	}
25062306a36Sopenharmony_ci
25162306a36Sopenharmony_ci	lapb_transmit_buffer(lapb, skb, type);
25262306a36Sopenharmony_ci}
25362306a36Sopenharmony_ci
25462306a36Sopenharmony_ci/*
25562306a36Sopenharmony_ci *	This routine generates FRMRs based on information previously stored in
25662306a36Sopenharmony_ci *	the LAPB control block.
25762306a36Sopenharmony_ci */
25862306a36Sopenharmony_civoid lapb_transmit_frmr(struct lapb_cb *lapb)
25962306a36Sopenharmony_ci{
26062306a36Sopenharmony_ci	struct sk_buff *skb;
26162306a36Sopenharmony_ci	unsigned char  *dptr;
26262306a36Sopenharmony_ci
26362306a36Sopenharmony_ci	if ((skb = alloc_skb(LAPB_HEADER_LEN + 7, GFP_ATOMIC)) == NULL)
26462306a36Sopenharmony_ci		return;
26562306a36Sopenharmony_ci
26662306a36Sopenharmony_ci	skb_reserve(skb, LAPB_HEADER_LEN + 1);
26762306a36Sopenharmony_ci
26862306a36Sopenharmony_ci	if (lapb->mode & LAPB_EXTENDED) {
26962306a36Sopenharmony_ci		dptr    = skb_put(skb, 6);
27062306a36Sopenharmony_ci		*dptr++ = LAPB_FRMR;
27162306a36Sopenharmony_ci		*dptr++ = lapb->frmr_data.control[0];
27262306a36Sopenharmony_ci		*dptr++ = lapb->frmr_data.control[1];
27362306a36Sopenharmony_ci		*dptr++ = (lapb->vs << 1) & 0xFE;
27462306a36Sopenharmony_ci		*dptr   = (lapb->vr << 1) & 0xFE;
27562306a36Sopenharmony_ci		if (lapb->frmr_data.cr == LAPB_RESPONSE)
27662306a36Sopenharmony_ci			*dptr |= 0x01;
27762306a36Sopenharmony_ci		dptr++;
27862306a36Sopenharmony_ci		*dptr++ = lapb->frmr_type;
27962306a36Sopenharmony_ci
28062306a36Sopenharmony_ci		lapb_dbg(1, "(%p) S%d TX FRMR %5ph\n",
28162306a36Sopenharmony_ci			 lapb->dev, lapb->state,
28262306a36Sopenharmony_ci			 &skb->data[1]);
28362306a36Sopenharmony_ci	} else {
28462306a36Sopenharmony_ci		dptr    = skb_put(skb, 4);
28562306a36Sopenharmony_ci		*dptr++ = LAPB_FRMR;
28662306a36Sopenharmony_ci		*dptr++ = lapb->frmr_data.control[0];
28762306a36Sopenharmony_ci		*dptr   = (lapb->vs << 1) & 0x0E;
28862306a36Sopenharmony_ci		*dptr  |= (lapb->vr << 5) & 0xE0;
28962306a36Sopenharmony_ci		if (lapb->frmr_data.cr == LAPB_RESPONSE)
29062306a36Sopenharmony_ci			*dptr |= 0x10;
29162306a36Sopenharmony_ci		dptr++;
29262306a36Sopenharmony_ci		*dptr++ = lapb->frmr_type;
29362306a36Sopenharmony_ci
29462306a36Sopenharmony_ci		lapb_dbg(1, "(%p) S%d TX FRMR %3ph\n",
29562306a36Sopenharmony_ci			 lapb->dev, lapb->state, &skb->data[1]);
29662306a36Sopenharmony_ci	}
29762306a36Sopenharmony_ci
29862306a36Sopenharmony_ci	lapb_transmit_buffer(lapb, skb, LAPB_RESPONSE);
29962306a36Sopenharmony_ci}
300