162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci *
462306a36Sopenharmony_ci * Copyright Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
562306a36Sopenharmony_ci * Copyright Darryl Miles G7LED (dlm@g7led.demon.co.uk)
662306a36Sopenharmony_ci */
762306a36Sopenharmony_ci#include <linux/errno.h>
862306a36Sopenharmony_ci#include <linux/types.h>
962306a36Sopenharmony_ci#include <linux/socket.h>
1062306a36Sopenharmony_ci#include <linux/in.h>
1162306a36Sopenharmony_ci#include <linux/kernel.h>
1262306a36Sopenharmony_ci#include <linux/timer.h>
1362306a36Sopenharmony_ci#include <linux/string.h>
1462306a36Sopenharmony_ci#include <linux/sockios.h>
1562306a36Sopenharmony_ci#include <linux/net.h>
1662306a36Sopenharmony_ci#include <linux/slab.h>
1762306a36Sopenharmony_ci#include <net/ax25.h>
1862306a36Sopenharmony_ci#include <linux/inet.h>
1962306a36Sopenharmony_ci#include <linux/netdevice.h>
2062306a36Sopenharmony_ci#include <linux/skbuff.h>
2162306a36Sopenharmony_ci#include <net/sock.h>
2262306a36Sopenharmony_ci#include <net/tcp_states.h>
2362306a36Sopenharmony_ci#include <linux/uaccess.h>
2462306a36Sopenharmony_ci#include <linux/fcntl.h>
2562306a36Sopenharmony_ci#include <linux/mm.h>
2662306a36Sopenharmony_ci#include <linux/interrupt.h>
2762306a36Sopenharmony_ci#include <net/netrom.h>
2862306a36Sopenharmony_ci
2962306a36Sopenharmony_cistatic int nr_queue_rx_frame(struct sock *sk, struct sk_buff *skb, int more)
3062306a36Sopenharmony_ci{
3162306a36Sopenharmony_ci	struct sk_buff *skbo, *skbn = skb;
3262306a36Sopenharmony_ci	struct nr_sock *nr = nr_sk(sk);
3362306a36Sopenharmony_ci
3462306a36Sopenharmony_ci	skb_pull(skb, NR_NETWORK_LEN + NR_TRANSPORT_LEN);
3562306a36Sopenharmony_ci
3662306a36Sopenharmony_ci	nr_start_idletimer(sk);
3762306a36Sopenharmony_ci
3862306a36Sopenharmony_ci	if (more) {
3962306a36Sopenharmony_ci		nr->fraglen += skb->len;
4062306a36Sopenharmony_ci		skb_queue_tail(&nr->frag_queue, skb);
4162306a36Sopenharmony_ci		return 0;
4262306a36Sopenharmony_ci	}
4362306a36Sopenharmony_ci
4462306a36Sopenharmony_ci	if (!more && nr->fraglen > 0) {	/* End of fragment */
4562306a36Sopenharmony_ci		nr->fraglen += skb->len;
4662306a36Sopenharmony_ci		skb_queue_tail(&nr->frag_queue, skb);
4762306a36Sopenharmony_ci
4862306a36Sopenharmony_ci		if ((skbn = alloc_skb(nr->fraglen, GFP_ATOMIC)) == NULL)
4962306a36Sopenharmony_ci			return 1;
5062306a36Sopenharmony_ci
5162306a36Sopenharmony_ci		skb_reset_transport_header(skbn);
5262306a36Sopenharmony_ci
5362306a36Sopenharmony_ci		while ((skbo = skb_dequeue(&nr->frag_queue)) != NULL) {
5462306a36Sopenharmony_ci			skb_copy_from_linear_data(skbo,
5562306a36Sopenharmony_ci						  skb_put(skbn, skbo->len),
5662306a36Sopenharmony_ci						  skbo->len);
5762306a36Sopenharmony_ci			kfree_skb(skbo);
5862306a36Sopenharmony_ci		}
5962306a36Sopenharmony_ci
6062306a36Sopenharmony_ci		nr->fraglen = 0;
6162306a36Sopenharmony_ci	}
6262306a36Sopenharmony_ci
6362306a36Sopenharmony_ci	return sock_queue_rcv_skb(sk, skbn);
6462306a36Sopenharmony_ci}
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_ci/*
6762306a36Sopenharmony_ci * State machine for state 1, Awaiting Connection State.
6862306a36Sopenharmony_ci * The handling of the timer(s) is in file nr_timer.c.
6962306a36Sopenharmony_ci * Handling of state 0 and connection release is in netrom.c.
7062306a36Sopenharmony_ci */
7162306a36Sopenharmony_cistatic int nr_state1_machine(struct sock *sk, struct sk_buff *skb,
7262306a36Sopenharmony_ci	int frametype)
7362306a36Sopenharmony_ci{
7462306a36Sopenharmony_ci	switch (frametype) {
7562306a36Sopenharmony_ci	case NR_CONNACK: {
7662306a36Sopenharmony_ci		struct nr_sock *nr = nr_sk(sk);
7762306a36Sopenharmony_ci
7862306a36Sopenharmony_ci		nr_stop_t1timer(sk);
7962306a36Sopenharmony_ci		nr_start_idletimer(sk);
8062306a36Sopenharmony_ci		nr->your_index = skb->data[17];
8162306a36Sopenharmony_ci		nr->your_id    = skb->data[18];
8262306a36Sopenharmony_ci		nr->vs	       = 0;
8362306a36Sopenharmony_ci		nr->va	       = 0;
8462306a36Sopenharmony_ci		nr->vr	       = 0;
8562306a36Sopenharmony_ci		nr->vl	       = 0;
8662306a36Sopenharmony_ci		nr->state      = NR_STATE_3;
8762306a36Sopenharmony_ci		nr->n2count    = 0;
8862306a36Sopenharmony_ci		nr->window     = skb->data[20];
8962306a36Sopenharmony_ci		sk->sk_state   = TCP_ESTABLISHED;
9062306a36Sopenharmony_ci		if (!sock_flag(sk, SOCK_DEAD))
9162306a36Sopenharmony_ci			sk->sk_state_change(sk);
9262306a36Sopenharmony_ci		break;
9362306a36Sopenharmony_ci	}
9462306a36Sopenharmony_ci
9562306a36Sopenharmony_ci	case NR_CONNACK | NR_CHOKE_FLAG:
9662306a36Sopenharmony_ci		nr_disconnect(sk, ECONNREFUSED);
9762306a36Sopenharmony_ci		break;
9862306a36Sopenharmony_ci
9962306a36Sopenharmony_ci	case NR_RESET:
10062306a36Sopenharmony_ci		if (READ_ONCE(sysctl_netrom_reset_circuit))
10162306a36Sopenharmony_ci			nr_disconnect(sk, ECONNRESET);
10262306a36Sopenharmony_ci		break;
10362306a36Sopenharmony_ci
10462306a36Sopenharmony_ci	default:
10562306a36Sopenharmony_ci		break;
10662306a36Sopenharmony_ci	}
10762306a36Sopenharmony_ci	return 0;
10862306a36Sopenharmony_ci}
10962306a36Sopenharmony_ci
11062306a36Sopenharmony_ci/*
11162306a36Sopenharmony_ci * State machine for state 2, Awaiting Release State.
11262306a36Sopenharmony_ci * The handling of the timer(s) is in file nr_timer.c
11362306a36Sopenharmony_ci * Handling of state 0 and connection release is in netrom.c.
11462306a36Sopenharmony_ci */
11562306a36Sopenharmony_cistatic int nr_state2_machine(struct sock *sk, struct sk_buff *skb,
11662306a36Sopenharmony_ci	int frametype)
11762306a36Sopenharmony_ci{
11862306a36Sopenharmony_ci	switch (frametype) {
11962306a36Sopenharmony_ci	case NR_CONNACK | NR_CHOKE_FLAG:
12062306a36Sopenharmony_ci		nr_disconnect(sk, ECONNRESET);
12162306a36Sopenharmony_ci		break;
12262306a36Sopenharmony_ci
12362306a36Sopenharmony_ci	case NR_DISCREQ:
12462306a36Sopenharmony_ci		nr_write_internal(sk, NR_DISCACK);
12562306a36Sopenharmony_ci		fallthrough;
12662306a36Sopenharmony_ci	case NR_DISCACK:
12762306a36Sopenharmony_ci		nr_disconnect(sk, 0);
12862306a36Sopenharmony_ci		break;
12962306a36Sopenharmony_ci
13062306a36Sopenharmony_ci	case NR_RESET:
13162306a36Sopenharmony_ci		if (READ_ONCE(sysctl_netrom_reset_circuit))
13262306a36Sopenharmony_ci			nr_disconnect(sk, ECONNRESET);
13362306a36Sopenharmony_ci		break;
13462306a36Sopenharmony_ci
13562306a36Sopenharmony_ci	default:
13662306a36Sopenharmony_ci		break;
13762306a36Sopenharmony_ci	}
13862306a36Sopenharmony_ci	return 0;
13962306a36Sopenharmony_ci}
14062306a36Sopenharmony_ci
14162306a36Sopenharmony_ci/*
14262306a36Sopenharmony_ci * State machine for state 3, Connected State.
14362306a36Sopenharmony_ci * The handling of the timer(s) is in file nr_timer.c
14462306a36Sopenharmony_ci * Handling of state 0 and connection release is in netrom.c.
14562306a36Sopenharmony_ci */
14662306a36Sopenharmony_cistatic int nr_state3_machine(struct sock *sk, struct sk_buff *skb, int frametype)
14762306a36Sopenharmony_ci{
14862306a36Sopenharmony_ci	struct nr_sock *nrom = nr_sk(sk);
14962306a36Sopenharmony_ci	struct sk_buff_head temp_queue;
15062306a36Sopenharmony_ci	struct sk_buff *skbn;
15162306a36Sopenharmony_ci	unsigned short save_vr;
15262306a36Sopenharmony_ci	unsigned short nr, ns;
15362306a36Sopenharmony_ci	int queued = 0;
15462306a36Sopenharmony_ci
15562306a36Sopenharmony_ci	nr = skb->data[18];
15662306a36Sopenharmony_ci
15762306a36Sopenharmony_ci	switch (frametype) {
15862306a36Sopenharmony_ci	case NR_CONNREQ:
15962306a36Sopenharmony_ci		nr_write_internal(sk, NR_CONNACK);
16062306a36Sopenharmony_ci		break;
16162306a36Sopenharmony_ci
16262306a36Sopenharmony_ci	case NR_DISCREQ:
16362306a36Sopenharmony_ci		nr_write_internal(sk, NR_DISCACK);
16462306a36Sopenharmony_ci		nr_disconnect(sk, 0);
16562306a36Sopenharmony_ci		break;
16662306a36Sopenharmony_ci
16762306a36Sopenharmony_ci	case NR_CONNACK | NR_CHOKE_FLAG:
16862306a36Sopenharmony_ci	case NR_DISCACK:
16962306a36Sopenharmony_ci		nr_disconnect(sk, ECONNRESET);
17062306a36Sopenharmony_ci		break;
17162306a36Sopenharmony_ci
17262306a36Sopenharmony_ci	case NR_INFOACK:
17362306a36Sopenharmony_ci	case NR_INFOACK | NR_CHOKE_FLAG:
17462306a36Sopenharmony_ci	case NR_INFOACK | NR_NAK_FLAG:
17562306a36Sopenharmony_ci	case NR_INFOACK | NR_NAK_FLAG | NR_CHOKE_FLAG:
17662306a36Sopenharmony_ci		if (frametype & NR_CHOKE_FLAG) {
17762306a36Sopenharmony_ci			nrom->condition |= NR_COND_PEER_RX_BUSY;
17862306a36Sopenharmony_ci			nr_start_t4timer(sk);
17962306a36Sopenharmony_ci		} else {
18062306a36Sopenharmony_ci			nrom->condition &= ~NR_COND_PEER_RX_BUSY;
18162306a36Sopenharmony_ci			nr_stop_t4timer(sk);
18262306a36Sopenharmony_ci		}
18362306a36Sopenharmony_ci		if (!nr_validate_nr(sk, nr)) {
18462306a36Sopenharmony_ci			break;
18562306a36Sopenharmony_ci		}
18662306a36Sopenharmony_ci		if (frametype & NR_NAK_FLAG) {
18762306a36Sopenharmony_ci			nr_frames_acked(sk, nr);
18862306a36Sopenharmony_ci			nr_send_nak_frame(sk);
18962306a36Sopenharmony_ci		} else {
19062306a36Sopenharmony_ci			if (nrom->condition & NR_COND_PEER_RX_BUSY) {
19162306a36Sopenharmony_ci				nr_frames_acked(sk, nr);
19262306a36Sopenharmony_ci			} else {
19362306a36Sopenharmony_ci				nr_check_iframes_acked(sk, nr);
19462306a36Sopenharmony_ci			}
19562306a36Sopenharmony_ci		}
19662306a36Sopenharmony_ci		break;
19762306a36Sopenharmony_ci
19862306a36Sopenharmony_ci	case NR_INFO:
19962306a36Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG:
20062306a36Sopenharmony_ci	case NR_INFO | NR_CHOKE_FLAG:
20162306a36Sopenharmony_ci	case NR_INFO | NR_MORE_FLAG:
20262306a36Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG | NR_CHOKE_FLAG:
20362306a36Sopenharmony_ci	case NR_INFO | NR_CHOKE_FLAG | NR_MORE_FLAG:
20462306a36Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG | NR_MORE_FLAG:
20562306a36Sopenharmony_ci	case NR_INFO | NR_NAK_FLAG | NR_CHOKE_FLAG | NR_MORE_FLAG:
20662306a36Sopenharmony_ci		if (frametype & NR_CHOKE_FLAG) {
20762306a36Sopenharmony_ci			nrom->condition |= NR_COND_PEER_RX_BUSY;
20862306a36Sopenharmony_ci			nr_start_t4timer(sk);
20962306a36Sopenharmony_ci		} else {
21062306a36Sopenharmony_ci			nrom->condition &= ~NR_COND_PEER_RX_BUSY;
21162306a36Sopenharmony_ci			nr_stop_t4timer(sk);
21262306a36Sopenharmony_ci		}
21362306a36Sopenharmony_ci		if (nr_validate_nr(sk, nr)) {
21462306a36Sopenharmony_ci			if (frametype & NR_NAK_FLAG) {
21562306a36Sopenharmony_ci				nr_frames_acked(sk, nr);
21662306a36Sopenharmony_ci				nr_send_nak_frame(sk);
21762306a36Sopenharmony_ci			} else {
21862306a36Sopenharmony_ci				if (nrom->condition & NR_COND_PEER_RX_BUSY) {
21962306a36Sopenharmony_ci					nr_frames_acked(sk, nr);
22062306a36Sopenharmony_ci				} else {
22162306a36Sopenharmony_ci					nr_check_iframes_acked(sk, nr);
22262306a36Sopenharmony_ci				}
22362306a36Sopenharmony_ci			}
22462306a36Sopenharmony_ci		}
22562306a36Sopenharmony_ci		queued = 1;
22662306a36Sopenharmony_ci		skb_queue_head(&nrom->reseq_queue, skb);
22762306a36Sopenharmony_ci		if (nrom->condition & NR_COND_OWN_RX_BUSY)
22862306a36Sopenharmony_ci			break;
22962306a36Sopenharmony_ci		skb_queue_head_init(&temp_queue);
23062306a36Sopenharmony_ci		do {
23162306a36Sopenharmony_ci			save_vr = nrom->vr;
23262306a36Sopenharmony_ci			while ((skbn = skb_dequeue(&nrom->reseq_queue)) != NULL) {
23362306a36Sopenharmony_ci				ns = skbn->data[17];
23462306a36Sopenharmony_ci				if (ns == nrom->vr) {
23562306a36Sopenharmony_ci					if (nr_queue_rx_frame(sk, skbn, frametype & NR_MORE_FLAG) == 0) {
23662306a36Sopenharmony_ci						nrom->vr = (nrom->vr + 1) % NR_MODULUS;
23762306a36Sopenharmony_ci					} else {
23862306a36Sopenharmony_ci						nrom->condition |= NR_COND_OWN_RX_BUSY;
23962306a36Sopenharmony_ci						skb_queue_tail(&temp_queue, skbn);
24062306a36Sopenharmony_ci					}
24162306a36Sopenharmony_ci				} else if (nr_in_rx_window(sk, ns)) {
24262306a36Sopenharmony_ci					skb_queue_tail(&temp_queue, skbn);
24362306a36Sopenharmony_ci				} else {
24462306a36Sopenharmony_ci					kfree_skb(skbn);
24562306a36Sopenharmony_ci				}
24662306a36Sopenharmony_ci			}
24762306a36Sopenharmony_ci			while ((skbn = skb_dequeue(&temp_queue)) != NULL) {
24862306a36Sopenharmony_ci				skb_queue_tail(&nrom->reseq_queue, skbn);
24962306a36Sopenharmony_ci			}
25062306a36Sopenharmony_ci		} while (save_vr != nrom->vr);
25162306a36Sopenharmony_ci		/*
25262306a36Sopenharmony_ci		 * Window is full, ack it immediately.
25362306a36Sopenharmony_ci		 */
25462306a36Sopenharmony_ci		if (((nrom->vl + nrom->window) % NR_MODULUS) == nrom->vr) {
25562306a36Sopenharmony_ci			nr_enquiry_response(sk);
25662306a36Sopenharmony_ci		} else {
25762306a36Sopenharmony_ci			if (!(nrom->condition & NR_COND_ACK_PENDING)) {
25862306a36Sopenharmony_ci				nrom->condition |= NR_COND_ACK_PENDING;
25962306a36Sopenharmony_ci				nr_start_t2timer(sk);
26062306a36Sopenharmony_ci			}
26162306a36Sopenharmony_ci		}
26262306a36Sopenharmony_ci		break;
26362306a36Sopenharmony_ci
26462306a36Sopenharmony_ci	case NR_RESET:
26562306a36Sopenharmony_ci		if (READ_ONCE(sysctl_netrom_reset_circuit))
26662306a36Sopenharmony_ci			nr_disconnect(sk, ECONNRESET);
26762306a36Sopenharmony_ci		break;
26862306a36Sopenharmony_ci
26962306a36Sopenharmony_ci	default:
27062306a36Sopenharmony_ci		break;
27162306a36Sopenharmony_ci	}
27262306a36Sopenharmony_ci	return queued;
27362306a36Sopenharmony_ci}
27462306a36Sopenharmony_ci
27562306a36Sopenharmony_ci/* Higher level upcall for a LAPB frame - called with sk locked */
27662306a36Sopenharmony_ciint nr_process_rx_frame(struct sock *sk, struct sk_buff *skb)
27762306a36Sopenharmony_ci{
27862306a36Sopenharmony_ci	struct nr_sock *nr = nr_sk(sk);
27962306a36Sopenharmony_ci	int queued = 0, frametype;
28062306a36Sopenharmony_ci
28162306a36Sopenharmony_ci	if (nr->state == NR_STATE_0)
28262306a36Sopenharmony_ci		return 0;
28362306a36Sopenharmony_ci
28462306a36Sopenharmony_ci	frametype = skb->data[19];
28562306a36Sopenharmony_ci
28662306a36Sopenharmony_ci	switch (nr->state) {
28762306a36Sopenharmony_ci	case NR_STATE_1:
28862306a36Sopenharmony_ci		queued = nr_state1_machine(sk, skb, frametype);
28962306a36Sopenharmony_ci		break;
29062306a36Sopenharmony_ci	case NR_STATE_2:
29162306a36Sopenharmony_ci		queued = nr_state2_machine(sk, skb, frametype);
29262306a36Sopenharmony_ci		break;
29362306a36Sopenharmony_ci	case NR_STATE_3:
29462306a36Sopenharmony_ci		queued = nr_state3_machine(sk, skb, frametype);
29562306a36Sopenharmony_ci		break;
29662306a36Sopenharmony_ci	}
29762306a36Sopenharmony_ci
29862306a36Sopenharmony_ci	nr_kick(sk);
29962306a36Sopenharmony_ci
30062306a36Sopenharmony_ci	return queued;
30162306a36Sopenharmony_ci}
302