net/ieee802154: reject zero-sized raw_sendmsg()
[platform/kernel/linux-rpi.git] / net / ieee802154 / socket.c
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * IEEE802154.4 socket interface
4  *
5  * Copyright 2007, 2008 Siemens AG
6  *
7  * Written by:
8  * Sergey Lapin <slapin@ossfans.org>
9  * Maxim Gorbachyov <maxim.gorbachev@siemens.com>
10  */
11
12 #include <linux/net.h>
13 #include <linux/capability.h>
14 #include <linux/module.h>
15 #include <linux/if_arp.h>
16 #include <linux/if.h>
17 #include <linux/termios.h>      /* For TIOCOUTQ/INQ */
18 #include <linux/list.h>
19 #include <linux/slab.h>
20 #include <linux/socket.h>
21 #include <net/datalink.h>
22 #include <net/psnap.h>
23 #include <net/sock.h>
24 #include <net/tcp_states.h>
25 #include <net/route.h>
26
27 #include <net/af_ieee802154.h>
28 #include <net/ieee802154_netdev.h>
29
30 /* Utility function for families */
31 static struct net_device*
32 ieee802154_get_dev(struct net *net, const struct ieee802154_addr *addr)
33 {
34         struct net_device *dev = NULL;
35         struct net_device *tmp;
36         __le16 pan_id, short_addr;
37         u8 hwaddr[IEEE802154_ADDR_LEN];
38
39         switch (addr->mode) {
40         case IEEE802154_ADDR_LONG:
41                 ieee802154_devaddr_to_raw(hwaddr, addr->extended_addr);
42                 rcu_read_lock();
43                 dev = dev_getbyhwaddr_rcu(net, ARPHRD_IEEE802154, hwaddr);
44                 dev_hold(dev);
45                 rcu_read_unlock();
46                 break;
47         case IEEE802154_ADDR_SHORT:
48                 if (addr->pan_id == cpu_to_le16(IEEE802154_PANID_BROADCAST) ||
49                     addr->short_addr == cpu_to_le16(IEEE802154_ADDR_UNDEF) ||
50                     addr->short_addr == cpu_to_le16(IEEE802154_ADDR_BROADCAST))
51                         break;
52
53                 rtnl_lock();
54
55                 for_each_netdev(net, tmp) {
56                         if (tmp->type != ARPHRD_IEEE802154)
57                                 continue;
58
59                         pan_id = tmp->ieee802154_ptr->pan_id;
60                         short_addr = tmp->ieee802154_ptr->short_addr;
61                         if (pan_id == addr->pan_id &&
62                             short_addr == addr->short_addr) {
63                                 dev = tmp;
64                                 dev_hold(dev);
65                                 break;
66                         }
67                 }
68
69                 rtnl_unlock();
70                 break;
71         default:
72                 pr_warn("Unsupported ieee802154 address type: %d\n",
73                         addr->mode);
74                 break;
75         }
76
77         return dev;
78 }
79
80 static int ieee802154_sock_release(struct socket *sock)
81 {
82         struct sock *sk = sock->sk;
83
84         if (sk) {
85                 sock->sk = NULL;
86                 sk->sk_prot->close(sk, 0);
87         }
88         return 0;
89 }
90
91 static int ieee802154_sock_sendmsg(struct socket *sock, struct msghdr *msg,
92                                    size_t len)
93 {
94         struct sock *sk = sock->sk;
95
96         return sk->sk_prot->sendmsg(sk, msg, len);
97 }
98
99 static int ieee802154_sock_bind(struct socket *sock, struct sockaddr *uaddr,
100                                 int addr_len)
101 {
102         struct sock *sk = sock->sk;
103
104         if (sk->sk_prot->bind)
105                 return sk->sk_prot->bind(sk, uaddr, addr_len);
106
107         return sock_no_bind(sock, uaddr, addr_len);
108 }
109
110 static int ieee802154_sock_connect(struct socket *sock, struct sockaddr *uaddr,
111                                    int addr_len, int flags)
112 {
113         struct sock *sk = sock->sk;
114
115         if (addr_len < sizeof(uaddr->sa_family))
116                 return -EINVAL;
117
118         if (uaddr->sa_family == AF_UNSPEC)
119                 return sk->sk_prot->disconnect(sk, flags);
120
121         return sk->sk_prot->connect(sk, uaddr, addr_len);
122 }
123
124 static int ieee802154_dev_ioctl(struct sock *sk, struct ifreq __user *arg,
125                                 unsigned int cmd)
126 {
127         struct ifreq ifr;
128         int ret = -ENOIOCTLCMD;
129         struct net_device *dev;
130
131         if (get_user_ifreq(&ifr, NULL, arg))
132                 return -EFAULT;
133
134         ifr.ifr_name[IFNAMSIZ-1] = 0;
135
136         dev_load(sock_net(sk), ifr.ifr_name);
137         dev = dev_get_by_name(sock_net(sk), ifr.ifr_name);
138
139         if (!dev)
140                 return -ENODEV;
141
142         if (dev->type == ARPHRD_IEEE802154 && dev->netdev_ops->ndo_do_ioctl)
143                 ret = dev->netdev_ops->ndo_do_ioctl(dev, &ifr, cmd);
144
145         if (!ret && put_user_ifreq(&ifr, arg))
146                 ret = -EFAULT;
147         dev_put(dev);
148
149         return ret;
150 }
151
152 static int ieee802154_sock_ioctl(struct socket *sock, unsigned int cmd,
153                                  unsigned long arg)
154 {
155         struct sock *sk = sock->sk;
156
157         switch (cmd) {
158         case SIOCGIFADDR:
159         case SIOCSIFADDR:
160                 return ieee802154_dev_ioctl(sk, (struct ifreq __user *)arg,
161                                 cmd);
162         default:
163                 if (!sk->sk_prot->ioctl)
164                         return -ENOIOCTLCMD;
165                 return sk->sk_prot->ioctl(sk, cmd, arg);
166         }
167 }
168
169 /* RAW Sockets (802.15.4 created in userspace) */
170 static HLIST_HEAD(raw_head);
171 static DEFINE_RWLOCK(raw_lock);
172
173 static int raw_hash(struct sock *sk)
174 {
175         write_lock_bh(&raw_lock);
176         sk_add_node(sk, &raw_head);
177         sock_prot_inuse_add(sock_net(sk), sk->sk_prot, 1);
178         write_unlock_bh(&raw_lock);
179
180         return 0;
181 }
182
183 static void raw_unhash(struct sock *sk)
184 {
185         write_lock_bh(&raw_lock);
186         if (sk_del_node_init(sk))
187                 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, -1);
188         write_unlock_bh(&raw_lock);
189 }
190
191 static void raw_close(struct sock *sk, long timeout)
192 {
193         sk_common_release(sk);
194 }
195
196 static int raw_bind(struct sock *sk, struct sockaddr *_uaddr, int len)
197 {
198         struct ieee802154_addr addr;
199         struct sockaddr_ieee802154 *uaddr = (struct sockaddr_ieee802154 *)_uaddr;
200         int err = 0;
201         struct net_device *dev = NULL;
202
203         err = ieee802154_sockaddr_check_size(uaddr, len);
204         if (err < 0)
205                 return err;
206
207         uaddr = (struct sockaddr_ieee802154 *)_uaddr;
208         if (uaddr->family != AF_IEEE802154)
209                 return -EINVAL;
210
211         lock_sock(sk);
212
213         ieee802154_addr_from_sa(&addr, &uaddr->addr);
214         dev = ieee802154_get_dev(sock_net(sk), &addr);
215         if (!dev) {
216                 err = -ENODEV;
217                 goto out;
218         }
219
220         sk->sk_bound_dev_if = dev->ifindex;
221         sk_dst_reset(sk);
222
223         dev_put(dev);
224 out:
225         release_sock(sk);
226
227         return err;
228 }
229
230 static int raw_connect(struct sock *sk, struct sockaddr *uaddr,
231                        int addr_len)
232 {
233         return -ENOTSUPP;
234 }
235
236 static int raw_disconnect(struct sock *sk, int flags)
237 {
238         return 0;
239 }
240
241 static int raw_sendmsg(struct sock *sk, struct msghdr *msg, size_t size)
242 {
243         struct net_device *dev;
244         unsigned int mtu;
245         struct sk_buff *skb;
246         int hlen, tlen;
247         int err;
248
249         if (msg->msg_flags & MSG_OOB) {
250                 pr_debug("msg->msg_flags = 0x%x\n", msg->msg_flags);
251                 return -EOPNOTSUPP;
252         }
253
254         if (!size)
255                 return -EINVAL;
256
257         lock_sock(sk);
258         if (!sk->sk_bound_dev_if)
259                 dev = dev_getfirstbyhwtype(sock_net(sk), ARPHRD_IEEE802154);
260         else
261                 dev = dev_get_by_index(sock_net(sk), sk->sk_bound_dev_if);
262         release_sock(sk);
263
264         if (!dev) {
265                 pr_debug("no dev\n");
266                 err = -ENXIO;
267                 goto out;
268         }
269
270         mtu = IEEE802154_MTU;
271         pr_debug("name = %s, mtu = %u\n", dev->name, mtu);
272
273         if (size > mtu) {
274                 pr_debug("size = %zu, mtu = %u\n", size, mtu);
275                 err = -EMSGSIZE;
276                 goto out_dev;
277         }
278
279         hlen = LL_RESERVED_SPACE(dev);
280         tlen = dev->needed_tailroom;
281         skb = sock_alloc_send_skb(sk, hlen + tlen + size,
282                                   msg->msg_flags & MSG_DONTWAIT, &err);
283         if (!skb)
284                 goto out_dev;
285
286         skb_reserve(skb, hlen);
287
288         skb_reset_mac_header(skb);
289         skb_reset_network_header(skb);
290
291         err = memcpy_from_msg(skb_put(skb, size), msg, size);
292         if (err < 0)
293                 goto out_skb;
294
295         skb->dev = dev;
296         skb->protocol = htons(ETH_P_IEEE802154);
297
298         err = dev_queue_xmit(skb);
299         if (err > 0)
300                 err = net_xmit_errno(err);
301
302         dev_put(dev);
303
304         return err ?: size;
305
306 out_skb:
307         kfree_skb(skb);
308 out_dev:
309         dev_put(dev);
310 out:
311         return err;
312 }
313
314 static int raw_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
315                        int noblock, int flags, int *addr_len)
316 {
317         size_t copied = 0;
318         int err = -EOPNOTSUPP;
319         struct sk_buff *skb;
320
321         skb = skb_recv_datagram(sk, flags, noblock, &err);
322         if (!skb)
323                 goto out;
324
325         copied = skb->len;
326         if (len < copied) {
327                 msg->msg_flags |= MSG_TRUNC;
328                 copied = len;
329         }
330
331         err = skb_copy_datagram_msg(skb, 0, msg, copied);
332         if (err)
333                 goto done;
334
335         sock_recv_ts_and_drops(msg, sk, skb);
336
337         if (flags & MSG_TRUNC)
338                 copied = skb->len;
339 done:
340         skb_free_datagram(sk, skb);
341 out:
342         if (err)
343                 return err;
344         return copied;
345 }
346
347 static int raw_rcv_skb(struct sock *sk, struct sk_buff *skb)
348 {
349         skb = skb_share_check(skb, GFP_ATOMIC);
350         if (!skb)
351                 return NET_RX_DROP;
352
353         if (sock_queue_rcv_skb(sk, skb) < 0) {
354                 kfree_skb(skb);
355                 return NET_RX_DROP;
356         }
357
358         return NET_RX_SUCCESS;
359 }
360
361 static void ieee802154_raw_deliver(struct net_device *dev, struct sk_buff *skb)
362 {
363         struct sock *sk;
364
365         read_lock(&raw_lock);
366         sk_for_each(sk, &raw_head) {
367                 bh_lock_sock(sk);
368                 if (!sk->sk_bound_dev_if ||
369                     sk->sk_bound_dev_if == dev->ifindex) {
370                         struct sk_buff *clone;
371
372                         clone = skb_clone(skb, GFP_ATOMIC);
373                         if (clone)
374                                 raw_rcv_skb(sk, clone);
375                 }
376                 bh_unlock_sock(sk);
377         }
378         read_unlock(&raw_lock);
379 }
380
381 static int raw_getsockopt(struct sock *sk, int level, int optname,
382                           char __user *optval, int __user *optlen)
383 {
384         return -EOPNOTSUPP;
385 }
386
387 static int raw_setsockopt(struct sock *sk, int level, int optname,
388                           sockptr_t optval, unsigned int optlen)
389 {
390         return -EOPNOTSUPP;
391 }
392
393 static struct proto ieee802154_raw_prot = {
394         .name           = "IEEE-802.15.4-RAW",
395         .owner          = THIS_MODULE,
396         .obj_size       = sizeof(struct sock),
397         .close          = raw_close,
398         .bind           = raw_bind,
399         .sendmsg        = raw_sendmsg,
400         .recvmsg        = raw_recvmsg,
401         .hash           = raw_hash,
402         .unhash         = raw_unhash,
403         .connect        = raw_connect,
404         .disconnect     = raw_disconnect,
405         .getsockopt     = raw_getsockopt,
406         .setsockopt     = raw_setsockopt,
407 };
408
409 static const struct proto_ops ieee802154_raw_ops = {
410         .family            = PF_IEEE802154,
411         .owner             = THIS_MODULE,
412         .release           = ieee802154_sock_release,
413         .bind              = ieee802154_sock_bind,
414         .connect           = ieee802154_sock_connect,
415         .socketpair        = sock_no_socketpair,
416         .accept            = sock_no_accept,
417         .getname           = sock_no_getname,
418         .poll              = datagram_poll,
419         .ioctl             = ieee802154_sock_ioctl,
420         .gettstamp         = sock_gettstamp,
421         .listen            = sock_no_listen,
422         .shutdown          = sock_no_shutdown,
423         .setsockopt        = sock_common_setsockopt,
424         .getsockopt        = sock_common_getsockopt,
425         .sendmsg           = ieee802154_sock_sendmsg,
426         .recvmsg           = sock_common_recvmsg,
427         .mmap              = sock_no_mmap,
428         .sendpage          = sock_no_sendpage,
429 };
430
431 /* DGRAM Sockets (802.15.4 dataframes) */
432 static HLIST_HEAD(dgram_head);
433 static DEFINE_RWLOCK(dgram_lock);
434
435 struct dgram_sock {
436         struct sock sk;
437
438         struct ieee802154_addr src_addr;
439         struct ieee802154_addr dst_addr;
440
441         unsigned int bound:1;
442         unsigned int connected:1;
443         unsigned int want_ack:1;
444         unsigned int want_lqi:1;
445         unsigned int secen:1;
446         unsigned int secen_override:1;
447         unsigned int seclevel:3;
448         unsigned int seclevel_override:1;
449 };
450
451 static inline struct dgram_sock *dgram_sk(const struct sock *sk)
452 {
453         return container_of(sk, struct dgram_sock, sk);
454 }
455
456 static int dgram_hash(struct sock *sk)
457 {
458         write_lock_bh(&dgram_lock);
459         sk_add_node(sk, &dgram_head);
460         sock_prot_inuse_add(sock_net(sk), sk->sk_prot, 1);
461         write_unlock_bh(&dgram_lock);
462
463         return 0;
464 }
465
466 static void dgram_unhash(struct sock *sk)
467 {
468         write_lock_bh(&dgram_lock);
469         if (sk_del_node_init(sk))
470                 sock_prot_inuse_add(sock_net(sk), sk->sk_prot, -1);
471         write_unlock_bh(&dgram_lock);
472 }
473
474 static int dgram_init(struct sock *sk)
475 {
476         struct dgram_sock *ro = dgram_sk(sk);
477
478         ro->want_ack = 1;
479         ro->want_lqi = 0;
480         return 0;
481 }
482
483 static void dgram_close(struct sock *sk, long timeout)
484 {
485         sk_common_release(sk);
486 }
487
488 static int dgram_bind(struct sock *sk, struct sockaddr *uaddr, int len)
489 {
490         struct sockaddr_ieee802154 *addr = (struct sockaddr_ieee802154 *)uaddr;
491         struct ieee802154_addr haddr;
492         struct dgram_sock *ro = dgram_sk(sk);
493         int err = -EINVAL;
494         struct net_device *dev;
495
496         lock_sock(sk);
497
498         ro->bound = 0;
499
500         err = ieee802154_sockaddr_check_size(addr, len);
501         if (err < 0)
502                 goto out;
503
504         if (addr->family != AF_IEEE802154)
505                 goto out;
506
507         ieee802154_addr_from_sa(&haddr, &addr->addr);
508         dev = ieee802154_get_dev(sock_net(sk), &haddr);
509         if (!dev) {
510                 err = -ENODEV;
511                 goto out;
512         }
513
514         if (dev->type != ARPHRD_IEEE802154) {
515                 err = -ENODEV;
516                 goto out_put;
517         }
518
519         ro->src_addr = haddr;
520
521         ro->bound = 1;
522         err = 0;
523 out_put:
524         dev_put(dev);
525 out:
526         release_sock(sk);
527
528         return err;
529 }
530
531 static int dgram_ioctl(struct sock *sk, int cmd, unsigned long arg)
532 {
533         switch (cmd) {
534         case SIOCOUTQ:
535         {
536                 int amount = sk_wmem_alloc_get(sk);
537
538                 return put_user(amount, (int __user *)arg);
539         }
540
541         case SIOCINQ:
542         {
543                 struct sk_buff *skb;
544                 unsigned long amount;
545
546                 amount = 0;
547                 spin_lock_bh(&sk->sk_receive_queue.lock);
548                 skb = skb_peek(&sk->sk_receive_queue);
549                 if (skb) {
550                         /* We will only return the amount
551                          * of this packet since that is all
552                          * that will be read.
553                          */
554                         amount = skb->len - ieee802154_hdr_length(skb);
555                 }
556                 spin_unlock_bh(&sk->sk_receive_queue.lock);
557                 return put_user(amount, (int __user *)arg);
558         }
559         }
560
561         return -ENOIOCTLCMD;
562 }
563
564 /* FIXME: autobind */
565 static int dgram_connect(struct sock *sk, struct sockaddr *uaddr,
566                          int len)
567 {
568         struct sockaddr_ieee802154 *addr = (struct sockaddr_ieee802154 *)uaddr;
569         struct dgram_sock *ro = dgram_sk(sk);
570         int err = 0;
571
572         err = ieee802154_sockaddr_check_size(addr, len);
573         if (err < 0)
574                 return err;
575
576         if (addr->family != AF_IEEE802154)
577                 return -EINVAL;
578
579         lock_sock(sk);
580
581         if (!ro->bound) {
582                 err = -ENETUNREACH;
583                 goto out;
584         }
585
586         ieee802154_addr_from_sa(&ro->dst_addr, &addr->addr);
587         ro->connected = 1;
588
589 out:
590         release_sock(sk);
591         return err;
592 }
593
594 static int dgram_disconnect(struct sock *sk, int flags)
595 {
596         struct dgram_sock *ro = dgram_sk(sk);
597
598         lock_sock(sk);
599         ro->connected = 0;
600         release_sock(sk);
601
602         return 0;
603 }
604
605 static int dgram_sendmsg(struct sock *sk, struct msghdr *msg, size_t size)
606 {
607         struct net_device *dev;
608         unsigned int mtu;
609         struct sk_buff *skb;
610         struct ieee802154_mac_cb *cb;
611         struct dgram_sock *ro = dgram_sk(sk);
612         struct ieee802154_addr dst_addr;
613         DECLARE_SOCKADDR(struct sockaddr_ieee802154*, daddr, msg->msg_name);
614         int hlen, tlen;
615         int err;
616
617         if (msg->msg_flags & MSG_OOB) {
618                 pr_debug("msg->msg_flags = 0x%x\n", msg->msg_flags);
619                 return -EOPNOTSUPP;
620         }
621
622         if (msg->msg_name) {
623                 if (ro->connected)
624                         return -EISCONN;
625                 if (msg->msg_namelen < IEEE802154_MIN_NAMELEN)
626                         return -EINVAL;
627                 err = ieee802154_sockaddr_check_size(daddr, msg->msg_namelen);
628                 if (err < 0)
629                         return err;
630                 ieee802154_addr_from_sa(&dst_addr, &daddr->addr);
631         } else {
632                 if (!ro->connected)
633                         return -EDESTADDRREQ;
634                 dst_addr = ro->dst_addr;
635         }
636
637         if (!ro->bound)
638                 dev = dev_getfirstbyhwtype(sock_net(sk), ARPHRD_IEEE802154);
639         else
640                 dev = ieee802154_get_dev(sock_net(sk), &ro->src_addr);
641
642         if (!dev) {
643                 pr_debug("no dev\n");
644                 err = -ENXIO;
645                 goto out;
646         }
647         mtu = IEEE802154_MTU;
648         pr_debug("name = %s, mtu = %u\n", dev->name, mtu);
649
650         if (size > mtu) {
651                 pr_debug("size = %zu, mtu = %u\n", size, mtu);
652                 err = -EMSGSIZE;
653                 goto out_dev;
654         }
655
656         hlen = LL_RESERVED_SPACE(dev);
657         tlen = dev->needed_tailroom;
658         skb = sock_alloc_send_skb(sk, hlen + tlen + size,
659                                   msg->msg_flags & MSG_DONTWAIT,
660                                   &err);
661         if (!skb)
662                 goto out_dev;
663
664         skb_reserve(skb, hlen);
665
666         skb_reset_network_header(skb);
667
668         cb = mac_cb_init(skb);
669         cb->type = IEEE802154_FC_TYPE_DATA;
670         cb->ackreq = ro->want_ack;
671         cb->secen = ro->secen;
672         cb->secen_override = ro->secen_override;
673         cb->seclevel = ro->seclevel;
674         cb->seclevel_override = ro->seclevel_override;
675
676         err = wpan_dev_hard_header(skb, dev, &dst_addr,
677                                    ro->bound ? &ro->src_addr : NULL, size);
678         if (err < 0)
679                 goto out_skb;
680
681         err = memcpy_from_msg(skb_put(skb, size), msg, size);
682         if (err < 0)
683                 goto out_skb;
684
685         skb->dev = dev;
686         skb->protocol = htons(ETH_P_IEEE802154);
687
688         err = dev_queue_xmit(skb);
689         if (err > 0)
690                 err = net_xmit_errno(err);
691
692         dev_put(dev);
693
694         return err ?: size;
695
696 out_skb:
697         kfree_skb(skb);
698 out_dev:
699         dev_put(dev);
700 out:
701         return err;
702 }
703
704 static int dgram_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
705                          int noblock, int flags, int *addr_len)
706 {
707         size_t copied = 0;
708         int err = -EOPNOTSUPP;
709         struct sk_buff *skb;
710         struct dgram_sock *ro = dgram_sk(sk);
711         DECLARE_SOCKADDR(struct sockaddr_ieee802154 *, saddr, msg->msg_name);
712
713         skb = skb_recv_datagram(sk, flags, noblock, &err);
714         if (!skb)
715                 goto out;
716
717         copied = skb->len;
718         if (len < copied) {
719                 msg->msg_flags |= MSG_TRUNC;
720                 copied = len;
721         }
722
723         /* FIXME: skip headers if necessary ?! */
724         err = skb_copy_datagram_msg(skb, 0, msg, copied);
725         if (err)
726                 goto done;
727
728         sock_recv_ts_and_drops(msg, sk, skb);
729
730         if (saddr) {
731                 /* Clear the implicit padding in struct sockaddr_ieee802154
732                  * (16 bits between 'family' and 'addr') and in struct
733                  * ieee802154_addr_sa (16 bits at the end of the structure).
734                  */
735                 memset(saddr, 0, sizeof(*saddr));
736
737                 saddr->family = AF_IEEE802154;
738                 ieee802154_addr_to_sa(&saddr->addr, &mac_cb(skb)->source);
739                 *addr_len = sizeof(*saddr);
740         }
741
742         if (ro->want_lqi) {
743                 err = put_cmsg(msg, SOL_IEEE802154, WPAN_WANTLQI,
744                                sizeof(uint8_t), &(mac_cb(skb)->lqi));
745                 if (err)
746                         goto done;
747         }
748
749         if (flags & MSG_TRUNC)
750                 copied = skb->len;
751 done:
752         skb_free_datagram(sk, skb);
753 out:
754         if (err)
755                 return err;
756         return copied;
757 }
758
759 static int dgram_rcv_skb(struct sock *sk, struct sk_buff *skb)
760 {
761         skb = skb_share_check(skb, GFP_ATOMIC);
762         if (!skb)
763                 return NET_RX_DROP;
764
765         if (sock_queue_rcv_skb(sk, skb) < 0) {
766                 kfree_skb(skb);
767                 return NET_RX_DROP;
768         }
769
770         return NET_RX_SUCCESS;
771 }
772
773 static inline bool
774 ieee802154_match_sock(__le64 hw_addr, __le16 pan_id, __le16 short_addr,
775                       struct dgram_sock *ro)
776 {
777         if (!ro->bound)
778                 return true;
779
780         if (ro->src_addr.mode == IEEE802154_ADDR_LONG &&
781             hw_addr == ro->src_addr.extended_addr)
782                 return true;
783
784         if (ro->src_addr.mode == IEEE802154_ADDR_SHORT &&
785             pan_id == ro->src_addr.pan_id &&
786             short_addr == ro->src_addr.short_addr)
787                 return true;
788
789         return false;
790 }
791
792 static int ieee802154_dgram_deliver(struct net_device *dev, struct sk_buff *skb)
793 {
794         struct sock *sk, *prev = NULL;
795         int ret = NET_RX_SUCCESS;
796         __le16 pan_id, short_addr;
797         __le64 hw_addr;
798
799         /* Data frame processing */
800         BUG_ON(dev->type != ARPHRD_IEEE802154);
801
802         pan_id = dev->ieee802154_ptr->pan_id;
803         short_addr = dev->ieee802154_ptr->short_addr;
804         hw_addr = dev->ieee802154_ptr->extended_addr;
805
806         read_lock(&dgram_lock);
807         sk_for_each(sk, &dgram_head) {
808                 if (ieee802154_match_sock(hw_addr, pan_id, short_addr,
809                                           dgram_sk(sk))) {
810                         if (prev) {
811                                 struct sk_buff *clone;
812
813                                 clone = skb_clone(skb, GFP_ATOMIC);
814                                 if (clone)
815                                         dgram_rcv_skb(prev, clone);
816                         }
817
818                         prev = sk;
819                 }
820         }
821
822         if (prev) {
823                 dgram_rcv_skb(prev, skb);
824         } else {
825                 kfree_skb(skb);
826                 ret = NET_RX_DROP;
827         }
828         read_unlock(&dgram_lock);
829
830         return ret;
831 }
832
833 static int dgram_getsockopt(struct sock *sk, int level, int optname,
834                             char __user *optval, int __user *optlen)
835 {
836         struct dgram_sock *ro = dgram_sk(sk);
837
838         int val, len;
839
840         if (level != SOL_IEEE802154)
841                 return -EOPNOTSUPP;
842
843         if (get_user(len, optlen))
844                 return -EFAULT;
845
846         len = min_t(unsigned int, len, sizeof(int));
847
848         switch (optname) {
849         case WPAN_WANTACK:
850                 val = ro->want_ack;
851                 break;
852         case WPAN_WANTLQI:
853                 val = ro->want_lqi;
854                 break;
855         case WPAN_SECURITY:
856                 if (!ro->secen_override)
857                         val = WPAN_SECURITY_DEFAULT;
858                 else if (ro->secen)
859                         val = WPAN_SECURITY_ON;
860                 else
861                         val = WPAN_SECURITY_OFF;
862                 break;
863         case WPAN_SECURITY_LEVEL:
864                 if (!ro->seclevel_override)
865                         val = WPAN_SECURITY_LEVEL_DEFAULT;
866                 else
867                         val = ro->seclevel;
868                 break;
869         default:
870                 return -ENOPROTOOPT;
871         }
872
873         if (put_user(len, optlen))
874                 return -EFAULT;
875         if (copy_to_user(optval, &val, len))
876                 return -EFAULT;
877         return 0;
878 }
879
880 static int dgram_setsockopt(struct sock *sk, int level, int optname,
881                             sockptr_t optval, unsigned int optlen)
882 {
883         struct dgram_sock *ro = dgram_sk(sk);
884         struct net *net = sock_net(sk);
885         int val;
886         int err = 0;
887
888         if (optlen < sizeof(int))
889                 return -EINVAL;
890
891         if (copy_from_sockptr(&val, optval, sizeof(int)))
892                 return -EFAULT;
893
894         lock_sock(sk);
895
896         switch (optname) {
897         case WPAN_WANTACK:
898                 ro->want_ack = !!val;
899                 break;
900         case WPAN_WANTLQI:
901                 ro->want_lqi = !!val;
902                 break;
903         case WPAN_SECURITY:
904                 if (!ns_capable(net->user_ns, CAP_NET_ADMIN) &&
905                     !ns_capable(net->user_ns, CAP_NET_RAW)) {
906                         err = -EPERM;
907                         break;
908                 }
909
910                 switch (val) {
911                 case WPAN_SECURITY_DEFAULT:
912                         ro->secen_override = 0;
913                         break;
914                 case WPAN_SECURITY_ON:
915                         ro->secen_override = 1;
916                         ro->secen = 1;
917                         break;
918                 case WPAN_SECURITY_OFF:
919                         ro->secen_override = 1;
920                         ro->secen = 0;
921                         break;
922                 default:
923                         err = -EINVAL;
924                         break;
925                 }
926                 break;
927         case WPAN_SECURITY_LEVEL:
928                 if (!ns_capable(net->user_ns, CAP_NET_ADMIN) &&
929                     !ns_capable(net->user_ns, CAP_NET_RAW)) {
930                         err = -EPERM;
931                         break;
932                 }
933
934                 if (val < WPAN_SECURITY_LEVEL_DEFAULT ||
935                     val > IEEE802154_SCF_SECLEVEL_ENC_MIC128) {
936                         err = -EINVAL;
937                 } else if (val == WPAN_SECURITY_LEVEL_DEFAULT) {
938                         ro->seclevel_override = 0;
939                 } else {
940                         ro->seclevel_override = 1;
941                         ro->seclevel = val;
942                 }
943                 break;
944         default:
945                 err = -ENOPROTOOPT;
946                 break;
947         }
948
949         release_sock(sk);
950         return err;
951 }
952
953 static struct proto ieee802154_dgram_prot = {
954         .name           = "IEEE-802.15.4-MAC",
955         .owner          = THIS_MODULE,
956         .obj_size       = sizeof(struct dgram_sock),
957         .init           = dgram_init,
958         .close          = dgram_close,
959         .bind           = dgram_bind,
960         .sendmsg        = dgram_sendmsg,
961         .recvmsg        = dgram_recvmsg,
962         .hash           = dgram_hash,
963         .unhash         = dgram_unhash,
964         .connect        = dgram_connect,
965         .disconnect     = dgram_disconnect,
966         .ioctl          = dgram_ioctl,
967         .getsockopt     = dgram_getsockopt,
968         .setsockopt     = dgram_setsockopt,
969 };
970
971 static const struct proto_ops ieee802154_dgram_ops = {
972         .family            = PF_IEEE802154,
973         .owner             = THIS_MODULE,
974         .release           = ieee802154_sock_release,
975         .bind              = ieee802154_sock_bind,
976         .connect           = ieee802154_sock_connect,
977         .socketpair        = sock_no_socketpair,
978         .accept            = sock_no_accept,
979         .getname           = sock_no_getname,
980         .poll              = datagram_poll,
981         .ioctl             = ieee802154_sock_ioctl,
982         .gettstamp         = sock_gettstamp,
983         .listen            = sock_no_listen,
984         .shutdown          = sock_no_shutdown,
985         .setsockopt        = sock_common_setsockopt,
986         .getsockopt        = sock_common_getsockopt,
987         .sendmsg           = ieee802154_sock_sendmsg,
988         .recvmsg           = sock_common_recvmsg,
989         .mmap              = sock_no_mmap,
990         .sendpage          = sock_no_sendpage,
991 };
992
993 static void ieee802154_sock_destruct(struct sock *sk)
994 {
995         skb_queue_purge(&sk->sk_receive_queue);
996 }
997
998 /* Create a socket. Initialise the socket, blank the addresses
999  * set the state.
1000  */
1001 static int ieee802154_create(struct net *net, struct socket *sock,
1002                              int protocol, int kern)
1003 {
1004         struct sock *sk;
1005         int rc;
1006         struct proto *proto;
1007         const struct proto_ops *ops;
1008
1009         if (!net_eq(net, &init_net))
1010                 return -EAFNOSUPPORT;
1011
1012         switch (sock->type) {
1013         case SOCK_RAW:
1014                 rc = -EPERM;
1015                 if (!capable(CAP_NET_RAW))
1016                         goto out;
1017                 proto = &ieee802154_raw_prot;
1018                 ops = &ieee802154_raw_ops;
1019                 break;
1020         case SOCK_DGRAM:
1021                 proto = &ieee802154_dgram_prot;
1022                 ops = &ieee802154_dgram_ops;
1023                 break;
1024         default:
1025                 rc = -ESOCKTNOSUPPORT;
1026                 goto out;
1027         }
1028
1029         rc = -ENOMEM;
1030         sk = sk_alloc(net, PF_IEEE802154, GFP_KERNEL, proto, kern);
1031         if (!sk)
1032                 goto out;
1033         rc = 0;
1034
1035         sock->ops = ops;
1036
1037         sock_init_data(sock, sk);
1038         sk->sk_destruct = ieee802154_sock_destruct;
1039         sk->sk_family = PF_IEEE802154;
1040
1041         /* Checksums on by default */
1042         sock_set_flag(sk, SOCK_ZAPPED);
1043
1044         if (sk->sk_prot->hash) {
1045                 rc = sk->sk_prot->hash(sk);
1046                 if (rc) {
1047                         sk_common_release(sk);
1048                         goto out;
1049                 }
1050         }
1051
1052         if (sk->sk_prot->init) {
1053                 rc = sk->sk_prot->init(sk);
1054                 if (rc)
1055                         sk_common_release(sk);
1056         }
1057 out:
1058         return rc;
1059 }
1060
1061 static const struct net_proto_family ieee802154_family_ops = {
1062         .family         = PF_IEEE802154,
1063         .create         = ieee802154_create,
1064         .owner          = THIS_MODULE,
1065 };
1066
1067 static int ieee802154_rcv(struct sk_buff *skb, struct net_device *dev,
1068                           struct packet_type *pt, struct net_device *orig_dev)
1069 {
1070         if (!netif_running(dev))
1071                 goto drop;
1072         pr_debug("got frame, type %d, dev %p\n", dev->type, dev);
1073 #ifdef DEBUG
1074         print_hex_dump_bytes("ieee802154_rcv ",
1075                              DUMP_PREFIX_NONE, skb->data, skb->len);
1076 #endif
1077
1078         if (!net_eq(dev_net(dev), &init_net))
1079                 goto drop;
1080
1081         ieee802154_raw_deliver(dev, skb);
1082
1083         if (dev->type != ARPHRD_IEEE802154)
1084                 goto drop;
1085
1086         if (skb->pkt_type != PACKET_OTHERHOST)
1087                 return ieee802154_dgram_deliver(dev, skb);
1088
1089 drop:
1090         kfree_skb(skb);
1091         return NET_RX_DROP;
1092 }
1093
1094 static struct packet_type ieee802154_packet_type = {
1095         .type = htons(ETH_P_IEEE802154),
1096         .func = ieee802154_rcv,
1097 };
1098
1099 static int __init af_ieee802154_init(void)
1100 {
1101         int rc;
1102
1103         rc = proto_register(&ieee802154_raw_prot, 1);
1104         if (rc)
1105                 goto out;
1106
1107         rc = proto_register(&ieee802154_dgram_prot, 1);
1108         if (rc)
1109                 goto err_dgram;
1110
1111         /* Tell SOCKET that we are alive */
1112         rc = sock_register(&ieee802154_family_ops);
1113         if (rc)
1114                 goto err_sock;
1115         dev_add_pack(&ieee802154_packet_type);
1116
1117         rc = 0;
1118         goto out;
1119
1120 err_sock:
1121         proto_unregister(&ieee802154_dgram_prot);
1122 err_dgram:
1123         proto_unregister(&ieee802154_raw_prot);
1124 out:
1125         return rc;
1126 }
1127
1128 static void __exit af_ieee802154_remove(void)
1129 {
1130         dev_remove_pack(&ieee802154_packet_type);
1131         sock_unregister(PF_IEEE802154);
1132         proto_unregister(&ieee802154_dgram_prot);
1133         proto_unregister(&ieee802154_raw_prot);
1134 }
1135
1136 module_init(af_ieee802154_init);
1137 module_exit(af_ieee802154_remove);
1138
1139 MODULE_LICENSE("GPL");
1140 MODULE_ALIAS_NETPROTO(PF_IEEE802154);