net: mctp: hold key reference when looking up a general key
[platform/kernel/linux-starfive.git] / net / mctp / route.c
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * Management Component Transport Protocol (MCTP) - routing
4  * implementation.
5  *
6  * This is currently based on a simple routing table, with no dst cache. The
7  * number of routes should stay fairly small, so the lookup cost is small.
8  *
9  * Copyright (c) 2021 Code Construct
10  * Copyright (c) 2021 Google
11  */
12
13 #include <linux/idr.h>
14 #include <linux/kconfig.h>
15 #include <linux/mctp.h>
16 #include <linux/netdevice.h>
17 #include <linux/rtnetlink.h>
18 #include <linux/skbuff.h>
19
20 #include <uapi/linux/if_arp.h>
21
22 #include <net/mctp.h>
23 #include <net/mctpdevice.h>
24 #include <net/netlink.h>
25 #include <net/sock.h>
26
27 #include <trace/events/mctp.h>
28
29 static const unsigned int mctp_message_maxlen = 64 * 1024;
30 static const unsigned long mctp_key_lifetime = 6 * CONFIG_HZ;
31
32 static void mctp_flow_prepare_output(struct sk_buff *skb, struct mctp_dev *dev);
33
34 /* route output callbacks */
35 static int mctp_route_discard(struct mctp_route *route, struct sk_buff *skb)
36 {
37         kfree_skb(skb);
38         return 0;
39 }
40
41 static struct mctp_sock *mctp_lookup_bind(struct net *net, struct sk_buff *skb)
42 {
43         struct mctp_skb_cb *cb = mctp_cb(skb);
44         struct mctp_hdr *mh;
45         struct sock *sk;
46         u8 type;
47
48         WARN_ON(!rcu_read_lock_held());
49
50         /* TODO: look up in skb->cb? */
51         mh = mctp_hdr(skb);
52
53         if (!skb_headlen(skb))
54                 return NULL;
55
56         type = (*(u8 *)skb->data) & 0x7f;
57
58         sk_for_each_rcu(sk, &net->mctp.binds) {
59                 struct mctp_sock *msk = container_of(sk, struct mctp_sock, sk);
60
61                 if (msk->bind_net != MCTP_NET_ANY && msk->bind_net != cb->net)
62                         continue;
63
64                 if (msk->bind_type != type)
65                         continue;
66
67                 if (!mctp_address_matches(msk->bind_addr, mh->dest))
68                         continue;
69
70                 return msk;
71         }
72
73         return NULL;
74 }
75
76 static bool mctp_key_match(struct mctp_sk_key *key, mctp_eid_t local,
77                            mctp_eid_t peer, u8 tag)
78 {
79         if (!mctp_address_matches(key->local_addr, local))
80                 return false;
81
82         if (key->peer_addr != peer)
83                 return false;
84
85         if (key->tag != tag)
86                 return false;
87
88         return true;
89 }
90
91 /* returns a key (with key->lock held, and refcounted), or NULL if no such
92  * key exists.
93  */
94 static struct mctp_sk_key *mctp_lookup_key(struct net *net, struct sk_buff *skb,
95                                            mctp_eid_t peer,
96                                            unsigned long *irqflags)
97         __acquires(&key->lock)
98 {
99         struct mctp_sk_key *key, *ret;
100         unsigned long flags;
101         struct mctp_hdr *mh;
102         u8 tag;
103
104         mh = mctp_hdr(skb);
105         tag = mh->flags_seq_tag & (MCTP_HDR_TAG_MASK | MCTP_HDR_FLAG_TO);
106
107         ret = NULL;
108         spin_lock_irqsave(&net->mctp.keys_lock, flags);
109
110         hlist_for_each_entry(key, &net->mctp.keys, hlist) {
111                 if (!mctp_key_match(key, mh->dest, peer, tag))
112                         continue;
113
114                 spin_lock(&key->lock);
115                 if (key->valid) {
116                         refcount_inc(&key->refs);
117                         ret = key;
118                         break;
119                 }
120                 spin_unlock(&key->lock);
121         }
122
123         if (ret) {
124                 spin_unlock(&net->mctp.keys_lock);
125                 *irqflags = flags;
126         } else {
127                 spin_unlock_irqrestore(&net->mctp.keys_lock, flags);
128         }
129
130         return ret;
131 }
132
133 static struct mctp_sk_key *mctp_key_alloc(struct mctp_sock *msk,
134                                           mctp_eid_t local, mctp_eid_t peer,
135                                           u8 tag, gfp_t gfp)
136 {
137         struct mctp_sk_key *key;
138
139         key = kzalloc(sizeof(*key), gfp);
140         if (!key)
141                 return NULL;
142
143         key->peer_addr = peer;
144         key->local_addr = local;
145         key->tag = tag;
146         key->sk = &msk->sk;
147         key->valid = true;
148         spin_lock_init(&key->lock);
149         refcount_set(&key->refs, 1);
150         sock_hold(key->sk);
151
152         return key;
153 }
154
155 void mctp_key_unref(struct mctp_sk_key *key)
156 {
157         unsigned long flags;
158
159         if (!refcount_dec_and_test(&key->refs))
160                 return;
161
162         /* even though no refs exist here, the lock allows us to stay
163          * consistent with the locking requirement of mctp_dev_release_key
164          */
165         spin_lock_irqsave(&key->lock, flags);
166         mctp_dev_release_key(key->dev, key);
167         spin_unlock_irqrestore(&key->lock, flags);
168
169         sock_put(key->sk);
170         kfree(key);
171 }
172
173 static int mctp_key_add(struct mctp_sk_key *key, struct mctp_sock *msk)
174 {
175         struct net *net = sock_net(&msk->sk);
176         struct mctp_sk_key *tmp;
177         unsigned long flags;
178         int rc = 0;
179
180         spin_lock_irqsave(&net->mctp.keys_lock, flags);
181
182         hlist_for_each_entry(tmp, &net->mctp.keys, hlist) {
183                 if (mctp_key_match(tmp, key->local_addr, key->peer_addr,
184                                    key->tag)) {
185                         spin_lock(&tmp->lock);
186                         if (tmp->valid)
187                                 rc = -EEXIST;
188                         spin_unlock(&tmp->lock);
189                         if (rc)
190                                 break;
191                 }
192         }
193
194         if (!rc) {
195                 refcount_inc(&key->refs);
196                 key->expiry = jiffies + mctp_key_lifetime;
197                 timer_reduce(&msk->key_expiry, key->expiry);
198
199                 hlist_add_head(&key->hlist, &net->mctp.keys);
200                 hlist_add_head(&key->sklist, &msk->keys);
201         }
202
203         spin_unlock_irqrestore(&net->mctp.keys_lock, flags);
204
205         return rc;
206 }
207
208 /* Helper for mctp_route_input().
209  * We're done with the key; unlock and unref the key.
210  * For the usual case of automatic expiry we remove the key from lists.
211  * In the case that manual allocation is set on a key we release the lock
212  * and local ref, reset reassembly, but don't remove from lists.
213  */
214 static void __mctp_key_done_in(struct mctp_sk_key *key, struct net *net,
215                                unsigned long flags, unsigned long reason)
216 __releases(&key->lock)
217 {
218         struct sk_buff *skb;
219
220         trace_mctp_key_release(key, reason);
221         skb = key->reasm_head;
222         key->reasm_head = NULL;
223
224         if (!key->manual_alloc) {
225                 key->reasm_dead = true;
226                 key->valid = false;
227                 mctp_dev_release_key(key->dev, key);
228         }
229         spin_unlock_irqrestore(&key->lock, flags);
230
231         if (!key->manual_alloc) {
232                 spin_lock_irqsave(&net->mctp.keys_lock, flags);
233                 if (!hlist_unhashed(&key->hlist)) {
234                         hlist_del_init(&key->hlist);
235                         hlist_del_init(&key->sklist);
236                         mctp_key_unref(key);
237                 }
238                 spin_unlock_irqrestore(&net->mctp.keys_lock, flags);
239         }
240
241         /* and one for the local reference */
242         mctp_key_unref(key);
243
244         kfree_skb(skb);
245 }
246
247 #ifdef CONFIG_MCTP_FLOWS
248 static void mctp_skb_set_flow(struct sk_buff *skb, struct mctp_sk_key *key)
249 {
250         struct mctp_flow *flow;
251
252         flow = skb_ext_add(skb, SKB_EXT_MCTP);
253         if (!flow)
254                 return;
255
256         refcount_inc(&key->refs);
257         flow->key = key;
258 }
259
260 static void mctp_flow_prepare_output(struct sk_buff *skb, struct mctp_dev *dev)
261 {
262         struct mctp_sk_key *key;
263         struct mctp_flow *flow;
264
265         flow = skb_ext_find(skb, SKB_EXT_MCTP);
266         if (!flow)
267                 return;
268
269         key = flow->key;
270
271         if (WARN_ON(key->dev && key->dev != dev))
272                 return;
273
274         mctp_dev_set_key(dev, key);
275 }
276 #else
277 static void mctp_skb_set_flow(struct sk_buff *skb, struct mctp_sk_key *key) {}
278 static void mctp_flow_prepare_output(struct sk_buff *skb, struct mctp_dev *dev) {}
279 #endif
280
281 static int mctp_frag_queue(struct mctp_sk_key *key, struct sk_buff *skb)
282 {
283         struct mctp_hdr *hdr = mctp_hdr(skb);
284         u8 exp_seq, this_seq;
285
286         this_seq = (hdr->flags_seq_tag >> MCTP_HDR_SEQ_SHIFT)
287                 & MCTP_HDR_SEQ_MASK;
288
289         if (!key->reasm_head) {
290                 key->reasm_head = skb;
291                 key->reasm_tailp = &(skb_shinfo(skb)->frag_list);
292                 key->last_seq = this_seq;
293                 return 0;
294         }
295
296         exp_seq = (key->last_seq + 1) & MCTP_HDR_SEQ_MASK;
297
298         if (this_seq != exp_seq)
299                 return -EINVAL;
300
301         if (key->reasm_head->len + skb->len > mctp_message_maxlen)
302                 return -EINVAL;
303
304         skb->next = NULL;
305         skb->sk = NULL;
306         *key->reasm_tailp = skb;
307         key->reasm_tailp = &skb->next;
308
309         key->last_seq = this_seq;
310
311         key->reasm_head->data_len += skb->len;
312         key->reasm_head->len += skb->len;
313         key->reasm_head->truesize += skb->truesize;
314
315         return 0;
316 }
317
318 static int mctp_route_input(struct mctp_route *route, struct sk_buff *skb)
319 {
320         struct mctp_sk_key *key, *any_key = NULL;
321         struct net *net = dev_net(skb->dev);
322         struct mctp_sock *msk;
323         struct mctp_hdr *mh;
324         unsigned long f;
325         u8 tag, flags;
326         int rc;
327
328         msk = NULL;
329         rc = -EINVAL;
330
331         /* we may be receiving a locally-routed packet; drop source sk
332          * accounting
333          */
334         skb_orphan(skb);
335
336         /* ensure we have enough data for a header and a type */
337         if (skb->len < sizeof(struct mctp_hdr) + 1)
338                 goto out;
339
340         /* grab header, advance data ptr */
341         mh = mctp_hdr(skb);
342         skb_pull(skb, sizeof(struct mctp_hdr));
343
344         if (mh->ver != 1)
345                 goto out;
346
347         flags = mh->flags_seq_tag & (MCTP_HDR_FLAG_SOM | MCTP_HDR_FLAG_EOM);
348         tag = mh->flags_seq_tag & (MCTP_HDR_TAG_MASK | MCTP_HDR_FLAG_TO);
349
350         rcu_read_lock();
351
352         /* lookup socket / reasm context, exactly matching (src,dest,tag).
353          * we hold a ref on the key, and key->lock held.
354          */
355         key = mctp_lookup_key(net, skb, mh->src, &f);
356
357         if (flags & MCTP_HDR_FLAG_SOM) {
358                 if (key) {
359                         msk = container_of(key->sk, struct mctp_sock, sk);
360                 } else {
361                         /* first response to a broadcast? do a more general
362                          * key lookup to find the socket, but don't use this
363                          * key for reassembly - we'll create a more specific
364                          * one for future packets if required (ie, !EOM).
365                          */
366                         any_key = mctp_lookup_key(net, skb, MCTP_ADDR_ANY, &f);
367                         if (any_key) {
368                                 msk = container_of(any_key->sk,
369                                                    struct mctp_sock, sk);
370                                 spin_unlock_irqrestore(&any_key->lock, f);
371                         }
372                 }
373
374                 if (!key && !msk && (tag & MCTP_HDR_FLAG_TO))
375                         msk = mctp_lookup_bind(net, skb);
376
377                 if (!msk) {
378                         rc = -ENOENT;
379                         goto out_unlock;
380                 }
381
382                 /* single-packet message? deliver to socket, clean up any
383                  * pending key.
384                  */
385                 if (flags & MCTP_HDR_FLAG_EOM) {
386                         sock_queue_rcv_skb(&msk->sk, skb);
387                         if (key) {
388                                 /* we've hit a pending reassembly; not much we
389                                  * can do but drop it
390                                  */
391                                 __mctp_key_done_in(key, net, f,
392                                                    MCTP_TRACE_KEY_REPLIED);
393                                 key = NULL;
394                         }
395                         rc = 0;
396                         goto out_unlock;
397                 }
398
399                 /* broadcast response or a bind() - create a key for further
400                  * packets for this message
401                  */
402                 if (!key) {
403                         key = mctp_key_alloc(msk, mh->dest, mh->src,
404                                              tag, GFP_ATOMIC);
405                         if (!key) {
406                                 rc = -ENOMEM;
407                                 goto out_unlock;
408                         }
409
410                         /* we can queue without the key lock here, as the
411                          * key isn't observable yet
412                          */
413                         mctp_frag_queue(key, skb);
414
415                         /* if the key_add fails, we've raced with another
416                          * SOM packet with the same src, dest and tag. There's
417                          * no way to distinguish future packets, so all we
418                          * can do is drop; we'll free the skb on exit from
419                          * this function.
420                          */
421                         rc = mctp_key_add(key, msk);
422                         if (!rc)
423                                 trace_mctp_key_acquire(key);
424
425                         /* we don't need to release key->lock on exit, so
426                          * clean up here and suppress the unlock via
427                          * setting to NULL
428                          */
429                         mctp_key_unref(key);
430                         key = NULL;
431
432                 } else {
433                         if (key->reasm_head || key->reasm_dead) {
434                                 /* duplicate start? drop everything */
435                                 __mctp_key_done_in(key, net, f,
436                                                    MCTP_TRACE_KEY_INVALIDATED);
437                                 rc = -EEXIST;
438                                 key = NULL;
439                         } else {
440                                 rc = mctp_frag_queue(key, skb);
441                         }
442                 }
443
444         } else if (key) {
445                 /* this packet continues a previous message; reassemble
446                  * using the message-specific key
447                  */
448
449                 /* we need to be continuing an existing reassembly... */
450                 if (!key->reasm_head)
451                         rc = -EINVAL;
452                 else
453                         rc = mctp_frag_queue(key, skb);
454
455                 /* end of message? deliver to socket, and we're done with
456                  * the reassembly/response key
457                  */
458                 if (!rc && flags & MCTP_HDR_FLAG_EOM) {
459                         sock_queue_rcv_skb(key->sk, key->reasm_head);
460                         key->reasm_head = NULL;
461                         __mctp_key_done_in(key, net, f, MCTP_TRACE_KEY_REPLIED);
462                         key = NULL;
463                 }
464
465         } else {
466                 /* not a start, no matching key */
467                 rc = -ENOENT;
468         }
469
470 out_unlock:
471         rcu_read_unlock();
472         if (key) {
473                 spin_unlock_irqrestore(&key->lock, f);
474                 mctp_key_unref(key);
475         }
476         if (any_key)
477                 mctp_key_unref(any_key);
478 out:
479         if (rc)
480                 kfree_skb(skb);
481         return rc;
482 }
483
484 static unsigned int mctp_route_mtu(struct mctp_route *rt)
485 {
486         return rt->mtu ?: READ_ONCE(rt->dev->dev->mtu);
487 }
488
489 static int mctp_route_output(struct mctp_route *route, struct sk_buff *skb)
490 {
491         struct mctp_skb_cb *cb = mctp_cb(skb);
492         struct mctp_hdr *hdr = mctp_hdr(skb);
493         char daddr_buf[MAX_ADDR_LEN];
494         char *daddr = NULL;
495         unsigned int mtu;
496         int rc;
497
498         skb->protocol = htons(ETH_P_MCTP);
499
500         mtu = READ_ONCE(skb->dev->mtu);
501         if (skb->len > mtu) {
502                 kfree_skb(skb);
503                 return -EMSGSIZE;
504         }
505
506         if (cb->ifindex) {
507                 /* direct route; use the hwaddr we stashed in sendmsg */
508                 if (cb->halen != skb->dev->addr_len) {
509                         /* sanity check, sendmsg should have already caught this */
510                         kfree_skb(skb);
511                         return -EMSGSIZE;
512                 }
513                 daddr = cb->haddr;
514         } else {
515                 /* If lookup fails let the device handle daddr==NULL */
516                 if (mctp_neigh_lookup(route->dev, hdr->dest, daddr_buf) == 0)
517                         daddr = daddr_buf;
518         }
519
520         rc = dev_hard_header(skb, skb->dev, ntohs(skb->protocol),
521                              daddr, skb->dev->dev_addr, skb->len);
522         if (rc < 0) {
523                 kfree_skb(skb);
524                 return -EHOSTUNREACH;
525         }
526
527         mctp_flow_prepare_output(skb, route->dev);
528
529         rc = dev_queue_xmit(skb);
530         if (rc)
531                 rc = net_xmit_errno(rc);
532
533         return rc;
534 }
535
536 /* route alloc/release */
537 static void mctp_route_release(struct mctp_route *rt)
538 {
539         if (refcount_dec_and_test(&rt->refs)) {
540                 mctp_dev_put(rt->dev);
541                 kfree_rcu(rt, rcu);
542         }
543 }
544
545 /* returns a route with the refcount at 1 */
546 static struct mctp_route *mctp_route_alloc(void)
547 {
548         struct mctp_route *rt;
549
550         rt = kzalloc(sizeof(*rt), GFP_KERNEL);
551         if (!rt)
552                 return NULL;
553
554         INIT_LIST_HEAD(&rt->list);
555         refcount_set(&rt->refs, 1);
556         rt->output = mctp_route_discard;
557
558         return rt;
559 }
560
561 unsigned int mctp_default_net(struct net *net)
562 {
563         return READ_ONCE(net->mctp.default_net);
564 }
565
566 int mctp_default_net_set(struct net *net, unsigned int index)
567 {
568         if (index == 0)
569                 return -EINVAL;
570         WRITE_ONCE(net->mctp.default_net, index);
571         return 0;
572 }
573
574 /* tag management */
575 static void mctp_reserve_tag(struct net *net, struct mctp_sk_key *key,
576                              struct mctp_sock *msk)
577 {
578         struct netns_mctp *mns = &net->mctp;
579
580         lockdep_assert_held(&mns->keys_lock);
581
582         key->expiry = jiffies + mctp_key_lifetime;
583         timer_reduce(&msk->key_expiry, key->expiry);
584
585         /* we hold the net->key_lock here, allowing updates to both
586          * then net and sk
587          */
588         hlist_add_head_rcu(&key->hlist, &mns->keys);
589         hlist_add_head_rcu(&key->sklist, &msk->keys);
590         refcount_inc(&key->refs);
591 }
592
593 /* Allocate a locally-owned tag value for (saddr, daddr), and reserve
594  * it for the socket msk
595  */
596 struct mctp_sk_key *mctp_alloc_local_tag(struct mctp_sock *msk,
597                                          mctp_eid_t daddr, mctp_eid_t saddr,
598                                          bool manual, u8 *tagp)
599 {
600         struct net *net = sock_net(&msk->sk);
601         struct netns_mctp *mns = &net->mctp;
602         struct mctp_sk_key *key, *tmp;
603         unsigned long flags;
604         u8 tagbits;
605
606         /* for NULL destination EIDs, we may get a response from any peer */
607         if (daddr == MCTP_ADDR_NULL)
608                 daddr = MCTP_ADDR_ANY;
609
610         /* be optimistic, alloc now */
611         key = mctp_key_alloc(msk, saddr, daddr, 0, GFP_KERNEL);
612         if (!key)
613                 return ERR_PTR(-ENOMEM);
614
615         /* 8 possible tag values */
616         tagbits = 0xff;
617
618         spin_lock_irqsave(&mns->keys_lock, flags);
619
620         /* Walk through the existing keys, looking for potential conflicting
621          * tags. If we find a conflict, clear that bit from tagbits
622          */
623         hlist_for_each_entry(tmp, &mns->keys, hlist) {
624                 /* We can check the lookup fields (*_addr, tag) without the
625                  * lock held, they don't change over the lifetime of the key.
626                  */
627
628                 /* if we don't own the tag, it can't conflict */
629                 if (tmp->tag & MCTP_HDR_FLAG_TO)
630                         continue;
631
632                 if (!(mctp_address_matches(tmp->peer_addr, daddr) &&
633                       mctp_address_matches(tmp->local_addr, saddr)))
634                         continue;
635
636                 spin_lock(&tmp->lock);
637                 /* key must still be valid. If we find a match, clear the
638                  * potential tag value
639                  */
640                 if (tmp->valid)
641                         tagbits &= ~(1 << tmp->tag);
642                 spin_unlock(&tmp->lock);
643
644                 if (!tagbits)
645                         break;
646         }
647
648         if (tagbits) {
649                 key->tag = __ffs(tagbits);
650                 mctp_reserve_tag(net, key, msk);
651                 trace_mctp_key_acquire(key);
652
653                 key->manual_alloc = manual;
654                 *tagp = key->tag;
655         }
656
657         spin_unlock_irqrestore(&mns->keys_lock, flags);
658
659         if (!tagbits) {
660                 kfree(key);
661                 return ERR_PTR(-EBUSY);
662         }
663
664         return key;
665 }
666
667 static struct mctp_sk_key *mctp_lookup_prealloc_tag(struct mctp_sock *msk,
668                                                     mctp_eid_t daddr,
669                                                     u8 req_tag, u8 *tagp)
670 {
671         struct net *net = sock_net(&msk->sk);
672         struct netns_mctp *mns = &net->mctp;
673         struct mctp_sk_key *key, *tmp;
674         unsigned long flags;
675
676         req_tag &= ~(MCTP_TAG_PREALLOC | MCTP_TAG_OWNER);
677         key = NULL;
678
679         spin_lock_irqsave(&mns->keys_lock, flags);
680
681         hlist_for_each_entry(tmp, &mns->keys, hlist) {
682                 if (tmp->tag != req_tag)
683                         continue;
684
685                 if (!mctp_address_matches(tmp->peer_addr, daddr))
686                         continue;
687
688                 if (!tmp->manual_alloc)
689                         continue;
690
691                 spin_lock(&tmp->lock);
692                 if (tmp->valid) {
693                         key = tmp;
694                         refcount_inc(&key->refs);
695                         spin_unlock(&tmp->lock);
696                         break;
697                 }
698                 spin_unlock(&tmp->lock);
699         }
700         spin_unlock_irqrestore(&mns->keys_lock, flags);
701
702         if (!key)
703                 return ERR_PTR(-ENOENT);
704
705         if (tagp)
706                 *tagp = key->tag;
707
708         return key;
709 }
710
711 /* routing lookups */
712 static bool mctp_rt_match_eid(struct mctp_route *rt,
713                               unsigned int net, mctp_eid_t eid)
714 {
715         return READ_ONCE(rt->dev->net) == net &&
716                 rt->min <= eid && rt->max >= eid;
717 }
718
719 /* compares match, used for duplicate prevention */
720 static bool mctp_rt_compare_exact(struct mctp_route *rt1,
721                                   struct mctp_route *rt2)
722 {
723         ASSERT_RTNL();
724         return rt1->dev->net == rt2->dev->net &&
725                 rt1->min == rt2->min &&
726                 rt1->max == rt2->max;
727 }
728
729 struct mctp_route *mctp_route_lookup(struct net *net, unsigned int dnet,
730                                      mctp_eid_t daddr)
731 {
732         struct mctp_route *tmp, *rt = NULL;
733
734         list_for_each_entry_rcu(tmp, &net->mctp.routes, list) {
735                 /* TODO: add metrics */
736                 if (mctp_rt_match_eid(tmp, dnet, daddr)) {
737                         if (refcount_inc_not_zero(&tmp->refs)) {
738                                 rt = tmp;
739                                 break;
740                         }
741                 }
742         }
743
744         return rt;
745 }
746
747 static struct mctp_route *mctp_route_lookup_null(struct net *net,
748                                                  struct net_device *dev)
749 {
750         struct mctp_route *rt;
751
752         list_for_each_entry_rcu(rt, &net->mctp.routes, list) {
753                 if (rt->dev->dev == dev && rt->type == RTN_LOCAL &&
754                     refcount_inc_not_zero(&rt->refs))
755                         return rt;
756         }
757
758         return NULL;
759 }
760
761 static int mctp_do_fragment_route(struct mctp_route *rt, struct sk_buff *skb,
762                                   unsigned int mtu, u8 tag)
763 {
764         const unsigned int hlen = sizeof(struct mctp_hdr);
765         struct mctp_hdr *hdr, *hdr2;
766         unsigned int pos, size, headroom;
767         struct sk_buff *skb2;
768         int rc;
769         u8 seq;
770
771         hdr = mctp_hdr(skb);
772         seq = 0;
773         rc = 0;
774
775         if (mtu < hlen + 1) {
776                 kfree_skb(skb);
777                 return -EMSGSIZE;
778         }
779
780         /* keep same headroom as the original skb */
781         headroom = skb_headroom(skb);
782
783         /* we've got the header */
784         skb_pull(skb, hlen);
785
786         for (pos = 0; pos < skb->len;) {
787                 /* size of message payload */
788                 size = min(mtu - hlen, skb->len - pos);
789
790                 skb2 = alloc_skb(headroom + hlen + size, GFP_KERNEL);
791                 if (!skb2) {
792                         rc = -ENOMEM;
793                         break;
794                 }
795
796                 /* generic skb copy */
797                 skb2->protocol = skb->protocol;
798                 skb2->priority = skb->priority;
799                 skb2->dev = skb->dev;
800                 memcpy(skb2->cb, skb->cb, sizeof(skb2->cb));
801
802                 if (skb->sk)
803                         skb_set_owner_w(skb2, skb->sk);
804
805                 /* establish packet */
806                 skb_reserve(skb2, headroom);
807                 skb_reset_network_header(skb2);
808                 skb_put(skb2, hlen + size);
809                 skb2->transport_header = skb2->network_header + hlen;
810
811                 /* copy header fields, calculate SOM/EOM flags & seq */
812                 hdr2 = mctp_hdr(skb2);
813                 hdr2->ver = hdr->ver;
814                 hdr2->dest = hdr->dest;
815                 hdr2->src = hdr->src;
816                 hdr2->flags_seq_tag = tag &
817                         (MCTP_HDR_TAG_MASK | MCTP_HDR_FLAG_TO);
818
819                 if (pos == 0)
820                         hdr2->flags_seq_tag |= MCTP_HDR_FLAG_SOM;
821
822                 if (pos + size == skb->len)
823                         hdr2->flags_seq_tag |= MCTP_HDR_FLAG_EOM;
824
825                 hdr2->flags_seq_tag |= seq << MCTP_HDR_SEQ_SHIFT;
826
827                 /* copy message payload */
828                 skb_copy_bits(skb, pos, skb_transport_header(skb2), size);
829
830                 /* do route */
831                 rc = rt->output(rt, skb2);
832                 if (rc)
833                         break;
834
835                 seq = (seq + 1) & MCTP_HDR_SEQ_MASK;
836                 pos += size;
837         }
838
839         consume_skb(skb);
840         return rc;
841 }
842
843 int mctp_local_output(struct sock *sk, struct mctp_route *rt,
844                       struct sk_buff *skb, mctp_eid_t daddr, u8 req_tag)
845 {
846         struct mctp_sock *msk = container_of(sk, struct mctp_sock, sk);
847         struct mctp_skb_cb *cb = mctp_cb(skb);
848         struct mctp_route tmp_rt = {0};
849         struct mctp_sk_key *key;
850         struct mctp_hdr *hdr;
851         unsigned long flags;
852         unsigned int mtu;
853         mctp_eid_t saddr;
854         bool ext_rt;
855         int rc;
856         u8 tag;
857
858         rc = -ENODEV;
859
860         if (rt) {
861                 ext_rt = false;
862                 if (WARN_ON(!rt->dev))
863                         goto out_release;
864
865         } else if (cb->ifindex) {
866                 struct net_device *dev;
867
868                 ext_rt = true;
869                 rt = &tmp_rt;
870
871                 rcu_read_lock();
872                 dev = dev_get_by_index_rcu(sock_net(sk), cb->ifindex);
873                 if (!dev) {
874                         rcu_read_unlock();
875                         return rc;
876                 }
877                 rt->dev = __mctp_dev_get(dev);
878                 rcu_read_unlock();
879
880                 if (!rt->dev)
881                         goto out_release;
882
883                 /* establish temporary route - we set up enough to keep
884                  * mctp_route_output happy
885                  */
886                 rt->output = mctp_route_output;
887                 rt->mtu = 0;
888
889         } else {
890                 return -EINVAL;
891         }
892
893         spin_lock_irqsave(&rt->dev->addrs_lock, flags);
894         if (rt->dev->num_addrs == 0) {
895                 rc = -EHOSTUNREACH;
896         } else {
897                 /* use the outbound interface's first address as our source */
898                 saddr = rt->dev->addrs[0];
899                 rc = 0;
900         }
901         spin_unlock_irqrestore(&rt->dev->addrs_lock, flags);
902
903         if (rc)
904                 goto out_release;
905
906         if (req_tag & MCTP_TAG_OWNER) {
907                 if (req_tag & MCTP_TAG_PREALLOC)
908                         key = mctp_lookup_prealloc_tag(msk, daddr,
909                                                        req_tag, &tag);
910                 else
911                         key = mctp_alloc_local_tag(msk, daddr, saddr,
912                                                    false, &tag);
913
914                 if (IS_ERR(key)) {
915                         rc = PTR_ERR(key);
916                         goto out_release;
917                 }
918                 mctp_skb_set_flow(skb, key);
919                 /* done with the key in this scope */
920                 mctp_key_unref(key);
921                 tag |= MCTP_HDR_FLAG_TO;
922         } else {
923                 key = NULL;
924                 tag = req_tag & MCTP_TAG_MASK;
925         }
926
927         skb->protocol = htons(ETH_P_MCTP);
928         skb->priority = 0;
929         skb_reset_transport_header(skb);
930         skb_push(skb, sizeof(struct mctp_hdr));
931         skb_reset_network_header(skb);
932         skb->dev = rt->dev->dev;
933
934         /* cb->net will have been set on initial ingress */
935         cb->src = saddr;
936
937         /* set up common header fields */
938         hdr = mctp_hdr(skb);
939         hdr->ver = 1;
940         hdr->dest = daddr;
941         hdr->src = saddr;
942
943         mtu = mctp_route_mtu(rt);
944
945         if (skb->len + sizeof(struct mctp_hdr) <= mtu) {
946                 hdr->flags_seq_tag = MCTP_HDR_FLAG_SOM |
947                         MCTP_HDR_FLAG_EOM | tag;
948                 rc = rt->output(rt, skb);
949         } else {
950                 rc = mctp_do_fragment_route(rt, skb, mtu, tag);
951         }
952
953 out_release:
954         if (!ext_rt)
955                 mctp_route_release(rt);
956
957         mctp_dev_put(tmp_rt.dev);
958
959         return rc;
960 }
961
962 /* route management */
963 static int mctp_route_add(struct mctp_dev *mdev, mctp_eid_t daddr_start,
964                           unsigned int daddr_extent, unsigned int mtu,
965                           unsigned char type)
966 {
967         int (*rtfn)(struct mctp_route *rt, struct sk_buff *skb);
968         struct net *net = dev_net(mdev->dev);
969         struct mctp_route *rt, *ert;
970
971         if (!mctp_address_unicast(daddr_start))
972                 return -EINVAL;
973
974         if (daddr_extent > 0xff || daddr_start + daddr_extent >= 255)
975                 return -EINVAL;
976
977         switch (type) {
978         case RTN_LOCAL:
979                 rtfn = mctp_route_input;
980                 break;
981         case RTN_UNICAST:
982                 rtfn = mctp_route_output;
983                 break;
984         default:
985                 return -EINVAL;
986         }
987
988         rt = mctp_route_alloc();
989         if (!rt)
990                 return -ENOMEM;
991
992         rt->min = daddr_start;
993         rt->max = daddr_start + daddr_extent;
994         rt->mtu = mtu;
995         rt->dev = mdev;
996         mctp_dev_hold(rt->dev);
997         rt->type = type;
998         rt->output = rtfn;
999
1000         ASSERT_RTNL();
1001         /* Prevent duplicate identical routes. */
1002         list_for_each_entry(ert, &net->mctp.routes, list) {
1003                 if (mctp_rt_compare_exact(rt, ert)) {
1004                         mctp_route_release(rt);
1005                         return -EEXIST;
1006                 }
1007         }
1008
1009         list_add_rcu(&rt->list, &net->mctp.routes);
1010
1011         return 0;
1012 }
1013
1014 static int mctp_route_remove(struct mctp_dev *mdev, mctp_eid_t daddr_start,
1015                              unsigned int daddr_extent, unsigned char type)
1016 {
1017         struct net *net = dev_net(mdev->dev);
1018         struct mctp_route *rt, *tmp;
1019         mctp_eid_t daddr_end;
1020         bool dropped;
1021
1022         if (daddr_extent > 0xff || daddr_start + daddr_extent >= 255)
1023                 return -EINVAL;
1024
1025         daddr_end = daddr_start + daddr_extent;
1026         dropped = false;
1027
1028         ASSERT_RTNL();
1029
1030         list_for_each_entry_safe(rt, tmp, &net->mctp.routes, list) {
1031                 if (rt->dev == mdev &&
1032                     rt->min == daddr_start && rt->max == daddr_end &&
1033                     rt->type == type) {
1034                         list_del_rcu(&rt->list);
1035                         /* TODO: immediate RTM_DELROUTE */
1036                         mctp_route_release(rt);
1037                         dropped = true;
1038                 }
1039         }
1040
1041         return dropped ? 0 : -ENOENT;
1042 }
1043
1044 int mctp_route_add_local(struct mctp_dev *mdev, mctp_eid_t addr)
1045 {
1046         return mctp_route_add(mdev, addr, 0, 0, RTN_LOCAL);
1047 }
1048
1049 int mctp_route_remove_local(struct mctp_dev *mdev, mctp_eid_t addr)
1050 {
1051         return mctp_route_remove(mdev, addr, 0, RTN_LOCAL);
1052 }
1053
1054 /* removes all entries for a given device */
1055 void mctp_route_remove_dev(struct mctp_dev *mdev)
1056 {
1057         struct net *net = dev_net(mdev->dev);
1058         struct mctp_route *rt, *tmp;
1059
1060         ASSERT_RTNL();
1061         list_for_each_entry_safe(rt, tmp, &net->mctp.routes, list) {
1062                 if (rt->dev == mdev) {
1063                         list_del_rcu(&rt->list);
1064                         /* TODO: immediate RTM_DELROUTE */
1065                         mctp_route_release(rt);
1066                 }
1067         }
1068 }
1069
1070 /* Incoming packet-handling */
1071
1072 static int mctp_pkttype_receive(struct sk_buff *skb, struct net_device *dev,
1073                                 struct packet_type *pt,
1074                                 struct net_device *orig_dev)
1075 {
1076         struct net *net = dev_net(dev);
1077         struct mctp_dev *mdev;
1078         struct mctp_skb_cb *cb;
1079         struct mctp_route *rt;
1080         struct mctp_hdr *mh;
1081
1082         rcu_read_lock();
1083         mdev = __mctp_dev_get(dev);
1084         rcu_read_unlock();
1085         if (!mdev) {
1086                 /* basic non-data sanity checks */
1087                 goto err_drop;
1088         }
1089
1090         if (!pskb_may_pull(skb, sizeof(struct mctp_hdr)))
1091                 goto err_drop;
1092
1093         skb_reset_transport_header(skb);
1094         skb_reset_network_header(skb);
1095
1096         /* We have enough for a header; decode and route */
1097         mh = mctp_hdr(skb);
1098         if (mh->ver < MCTP_VER_MIN || mh->ver > MCTP_VER_MAX)
1099                 goto err_drop;
1100
1101         /* source must be valid unicast or null; drop reserved ranges and
1102          * broadcast
1103          */
1104         if (!(mctp_address_unicast(mh->src) || mctp_address_null(mh->src)))
1105                 goto err_drop;
1106
1107         /* dest address: as above, but allow broadcast */
1108         if (!(mctp_address_unicast(mh->dest) || mctp_address_null(mh->dest) ||
1109               mctp_address_broadcast(mh->dest)))
1110                 goto err_drop;
1111
1112         /* MCTP drivers must populate halen/haddr */
1113         if (dev->type == ARPHRD_MCTP) {
1114                 cb = mctp_cb(skb);
1115         } else {
1116                 cb = __mctp_cb(skb);
1117                 cb->halen = 0;
1118         }
1119         cb->net = READ_ONCE(mdev->net);
1120         cb->ifindex = dev->ifindex;
1121
1122         rt = mctp_route_lookup(net, cb->net, mh->dest);
1123
1124         /* NULL EID, but addressed to our physical address */
1125         if (!rt && mh->dest == MCTP_ADDR_NULL && skb->pkt_type == PACKET_HOST)
1126                 rt = mctp_route_lookup_null(net, dev);
1127
1128         if (!rt)
1129                 goto err_drop;
1130
1131         rt->output(rt, skb);
1132         mctp_route_release(rt);
1133         mctp_dev_put(mdev);
1134
1135         return NET_RX_SUCCESS;
1136
1137 err_drop:
1138         kfree_skb(skb);
1139         mctp_dev_put(mdev);
1140         return NET_RX_DROP;
1141 }
1142
1143 static struct packet_type mctp_packet_type = {
1144         .type = cpu_to_be16(ETH_P_MCTP),
1145         .func = mctp_pkttype_receive,
1146 };
1147
1148 /* netlink interface */
1149
1150 static const struct nla_policy rta_mctp_policy[RTA_MAX + 1] = {
1151         [RTA_DST]               = { .type = NLA_U8 },
1152         [RTA_METRICS]           = { .type = NLA_NESTED },
1153         [RTA_OIF]               = { .type = NLA_U32 },
1154 };
1155
1156 /* Common part for RTM_NEWROUTE and RTM_DELROUTE parsing.
1157  * tb must hold RTA_MAX+1 elements.
1158  */
1159 static int mctp_route_nlparse(struct sk_buff *skb, struct nlmsghdr *nlh,
1160                               struct netlink_ext_ack *extack,
1161                               struct nlattr **tb, struct rtmsg **rtm,
1162                               struct mctp_dev **mdev, mctp_eid_t *daddr_start)
1163 {
1164         struct net *net = sock_net(skb->sk);
1165         struct net_device *dev;
1166         unsigned int ifindex;
1167         int rc;
1168
1169         rc = nlmsg_parse(nlh, sizeof(struct rtmsg), tb, RTA_MAX,
1170                          rta_mctp_policy, extack);
1171         if (rc < 0) {
1172                 NL_SET_ERR_MSG(extack, "incorrect format");
1173                 return rc;
1174         }
1175
1176         if (!tb[RTA_DST]) {
1177                 NL_SET_ERR_MSG(extack, "dst EID missing");
1178                 return -EINVAL;
1179         }
1180         *daddr_start = nla_get_u8(tb[RTA_DST]);
1181
1182         if (!tb[RTA_OIF]) {
1183                 NL_SET_ERR_MSG(extack, "ifindex missing");
1184                 return -EINVAL;
1185         }
1186         ifindex = nla_get_u32(tb[RTA_OIF]);
1187
1188         *rtm = nlmsg_data(nlh);
1189         if ((*rtm)->rtm_family != AF_MCTP) {
1190                 NL_SET_ERR_MSG(extack, "route family must be AF_MCTP");
1191                 return -EINVAL;
1192         }
1193
1194         dev = __dev_get_by_index(net, ifindex);
1195         if (!dev) {
1196                 NL_SET_ERR_MSG(extack, "bad ifindex");
1197                 return -ENODEV;
1198         }
1199         *mdev = mctp_dev_get_rtnl(dev);
1200         if (!*mdev)
1201                 return -ENODEV;
1202
1203         if (dev->flags & IFF_LOOPBACK) {
1204                 NL_SET_ERR_MSG(extack, "no routes to loopback");
1205                 return -EINVAL;
1206         }
1207
1208         return 0;
1209 }
1210
1211 static const struct nla_policy rta_metrics_policy[RTAX_MAX + 1] = {
1212         [RTAX_MTU]              = { .type = NLA_U32 },
1213 };
1214
1215 static int mctp_newroute(struct sk_buff *skb, struct nlmsghdr *nlh,
1216                          struct netlink_ext_ack *extack)
1217 {
1218         struct nlattr *tb[RTA_MAX + 1];
1219         struct nlattr *tbx[RTAX_MAX + 1];
1220         mctp_eid_t daddr_start;
1221         struct mctp_dev *mdev;
1222         struct rtmsg *rtm;
1223         unsigned int mtu;
1224         int rc;
1225
1226         rc = mctp_route_nlparse(skb, nlh, extack, tb,
1227                                 &rtm, &mdev, &daddr_start);
1228         if (rc < 0)
1229                 return rc;
1230
1231         if (rtm->rtm_type != RTN_UNICAST) {
1232                 NL_SET_ERR_MSG(extack, "rtm_type must be RTN_UNICAST");
1233                 return -EINVAL;
1234         }
1235
1236         mtu = 0;
1237         if (tb[RTA_METRICS]) {
1238                 rc = nla_parse_nested(tbx, RTAX_MAX, tb[RTA_METRICS],
1239                                       rta_metrics_policy, NULL);
1240                 if (rc < 0)
1241                         return rc;
1242                 if (tbx[RTAX_MTU])
1243                         mtu = nla_get_u32(tbx[RTAX_MTU]);
1244         }
1245
1246         if (rtm->rtm_type != RTN_UNICAST)
1247                 return -EINVAL;
1248
1249         rc = mctp_route_add(mdev, daddr_start, rtm->rtm_dst_len, mtu,
1250                             rtm->rtm_type);
1251         return rc;
1252 }
1253
1254 static int mctp_delroute(struct sk_buff *skb, struct nlmsghdr *nlh,
1255                          struct netlink_ext_ack *extack)
1256 {
1257         struct nlattr *tb[RTA_MAX + 1];
1258         mctp_eid_t daddr_start;
1259         struct mctp_dev *mdev;
1260         struct rtmsg *rtm;
1261         int rc;
1262
1263         rc = mctp_route_nlparse(skb, nlh, extack, tb,
1264                                 &rtm, &mdev, &daddr_start);
1265         if (rc < 0)
1266                 return rc;
1267
1268         /* we only have unicast routes */
1269         if (rtm->rtm_type != RTN_UNICAST)
1270                 return -EINVAL;
1271
1272         rc = mctp_route_remove(mdev, daddr_start, rtm->rtm_dst_len, RTN_UNICAST);
1273         return rc;
1274 }
1275
1276 static int mctp_fill_rtinfo(struct sk_buff *skb, struct mctp_route *rt,
1277                             u32 portid, u32 seq, int event, unsigned int flags)
1278 {
1279         struct nlmsghdr *nlh;
1280         struct rtmsg *hdr;
1281         void *metrics;
1282
1283         nlh = nlmsg_put(skb, portid, seq, event, sizeof(*hdr), flags);
1284         if (!nlh)
1285                 return -EMSGSIZE;
1286
1287         hdr = nlmsg_data(nlh);
1288         hdr->rtm_family = AF_MCTP;
1289
1290         /* we use the _len fields as a number of EIDs, rather than
1291          * a number of bits in the address
1292          */
1293         hdr->rtm_dst_len = rt->max - rt->min;
1294         hdr->rtm_src_len = 0;
1295         hdr->rtm_tos = 0;
1296         hdr->rtm_table = RT_TABLE_DEFAULT;
1297         hdr->rtm_protocol = RTPROT_STATIC; /* everything is user-defined */
1298         hdr->rtm_scope = RT_SCOPE_LINK; /* TODO: scope in mctp_route? */
1299         hdr->rtm_type = rt->type;
1300
1301         if (nla_put_u8(skb, RTA_DST, rt->min))
1302                 goto cancel;
1303
1304         metrics = nla_nest_start_noflag(skb, RTA_METRICS);
1305         if (!metrics)
1306                 goto cancel;
1307
1308         if (rt->mtu) {
1309                 if (nla_put_u32(skb, RTAX_MTU, rt->mtu))
1310                         goto cancel;
1311         }
1312
1313         nla_nest_end(skb, metrics);
1314
1315         if (rt->dev) {
1316                 if (nla_put_u32(skb, RTA_OIF, rt->dev->dev->ifindex))
1317                         goto cancel;
1318         }
1319
1320         /* TODO: conditional neighbour physaddr? */
1321
1322         nlmsg_end(skb, nlh);
1323
1324         return 0;
1325
1326 cancel:
1327         nlmsg_cancel(skb, nlh);
1328         return -EMSGSIZE;
1329 }
1330
1331 static int mctp_dump_rtinfo(struct sk_buff *skb, struct netlink_callback *cb)
1332 {
1333         struct net *net = sock_net(skb->sk);
1334         struct mctp_route *rt;
1335         int s_idx, idx;
1336
1337         /* TODO: allow filtering on route data, possibly under
1338          * cb->strict_check
1339          */
1340
1341         /* TODO: change to struct overlay */
1342         s_idx = cb->args[0];
1343         idx = 0;
1344
1345         rcu_read_lock();
1346         list_for_each_entry_rcu(rt, &net->mctp.routes, list) {
1347                 if (idx++ < s_idx)
1348                         continue;
1349                 if (mctp_fill_rtinfo(skb, rt,
1350                                      NETLINK_CB(cb->skb).portid,
1351                                      cb->nlh->nlmsg_seq,
1352                                      RTM_NEWROUTE, NLM_F_MULTI) < 0)
1353                         break;
1354         }
1355
1356         rcu_read_unlock();
1357         cb->args[0] = idx;
1358
1359         return skb->len;
1360 }
1361
1362 /* net namespace implementation */
1363 static int __net_init mctp_routes_net_init(struct net *net)
1364 {
1365         struct netns_mctp *ns = &net->mctp;
1366
1367         INIT_LIST_HEAD(&ns->routes);
1368         INIT_HLIST_HEAD(&ns->binds);
1369         mutex_init(&ns->bind_lock);
1370         INIT_HLIST_HEAD(&ns->keys);
1371         spin_lock_init(&ns->keys_lock);
1372         WARN_ON(mctp_default_net_set(net, MCTP_INITIAL_DEFAULT_NET));
1373         return 0;
1374 }
1375
1376 static void __net_exit mctp_routes_net_exit(struct net *net)
1377 {
1378         struct mctp_route *rt;
1379
1380         rcu_read_lock();
1381         list_for_each_entry_rcu(rt, &net->mctp.routes, list)
1382                 mctp_route_release(rt);
1383         rcu_read_unlock();
1384 }
1385
1386 static struct pernet_operations mctp_net_ops = {
1387         .init = mctp_routes_net_init,
1388         .exit = mctp_routes_net_exit,
1389 };
1390
1391 int __init mctp_routes_init(void)
1392 {
1393         dev_add_pack(&mctp_packet_type);
1394
1395         rtnl_register_module(THIS_MODULE, PF_MCTP, RTM_GETROUTE,
1396                              NULL, mctp_dump_rtinfo, 0);
1397         rtnl_register_module(THIS_MODULE, PF_MCTP, RTM_NEWROUTE,
1398                              mctp_newroute, NULL, 0);
1399         rtnl_register_module(THIS_MODULE, PF_MCTP, RTM_DELROUTE,
1400                              mctp_delroute, NULL, 0);
1401
1402         return register_pernet_subsys(&mctp_net_ops);
1403 }
1404
1405 void mctp_routes_exit(void)
1406 {
1407         unregister_pernet_subsys(&mctp_net_ops);
1408         rtnl_unregister(PF_MCTP, RTM_DELROUTE);
1409         rtnl_unregister(PF_MCTP, RTM_NEWROUTE);
1410         rtnl_unregister(PF_MCTP, RTM_GETROUTE);
1411         dev_remove_pack(&mctp_packet_type);
1412 }
1413
1414 #if IS_ENABLED(CONFIG_MCTP_TEST)
1415 #include "test/route-test.c"
1416 #endif