net: correct off-by-one write allocations reports
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / x25 / af_x25.c
CommitLineData
1da177e4
LT
1/*
2 * X.25 Packet Layer release 002
3 *
4 * This is ALPHA test software. This code may break your machine,
5 * randomly fail to work with new releases, misbehave and/or generally
f8e1d201 6 * screw up. It might even work.
1da177e4
LT
7 *
8 * This code REQUIRES 2.1.15 or higher
9 *
10 * This module:
11 * This module is free software; you can redistribute it and/or
12 * modify it under the terms of the GNU General Public License
13 * as published by the Free Software Foundation; either version
14 * 2 of the License, or (at your option) any later version.
15 *
16 * History
17 * X.25 001 Jonathan Naylor Started coding.
18 * X.25 002 Jonathan Naylor Centralised disconnect handling.
19 * New timer architecture.
20 * 2000-03-11 Henner Eisen MSG_EOR handling more POSIX compliant.
f8e1d201
YH
21 * 2000-03-22 Daniela Squassoni Allowed disabling/enabling of
22 * facilities negotiation and increased
1da177e4
LT
23 * the throughput upper limit.
24 * 2000-08-27 Arnaldo C. Melo s/suser/capable/ + micro cleanups
f8e1d201 25 * 2000-09-04 Henner Eisen Set sock->state in x25_accept().
1da177e4
LT
26 * Fixed x25_output() related skb leakage.
27 * 2000-10-02 Henner Eisen Made x25_kick() single threaded per socket.
28 * 2000-10-27 Henner Eisen MSG_DONTWAIT for fragment allocation.
29 * 2000-11-14 Henner Eisen Closing datalink from NETDEV_GOING_DOWN
30 * 2002-10-06 Arnaldo C. Melo Get rid of cli/sti, move proc stuff to
31 * x25_proc.c, using seq_file
cb65d506
SP
32 * 2005-04-02 Shaun Pereira Selective sub address matching
33 * with call user data
ebc3f64b
SP
34 * 2005-04-15 Shaun Pereira Fast select with no restriction on
35 * response
1da177e4
LT
36 */
37
1da177e4 38#include <linux/module.h>
4fc268d2 39#include <linux/capability.h>
1da177e4
LT
40#include <linux/errno.h>
41#include <linux/kernel.h>
42#include <linux/sched.h>
43#include <linux/timer.h>
44#include <linux/string.h>
45#include <linux/net.h>
46#include <linux/netdevice.h>
47#include <linux/if_arp.h>
48#include <linux/skbuff.h>
49#include <net/sock.h>
c752f073 50#include <net/tcp_states.h>
1da177e4
LT
51#include <asm/uaccess.h>
52#include <linux/fcntl.h>
53#include <linux/termios.h> /* For TIOCINQ/OUTQ */
54#include <linux/notifier.h>
55#include <linux/init.h>
1b06e6ba
SP
56#include <linux/compat.h>
57
1da177e4 58#include <net/x25.h>
1b06e6ba 59#include <net/compat.h>
1da177e4
LT
60
61int sysctl_x25_restart_request_timeout = X25_DEFAULT_T20;
62int sysctl_x25_call_request_timeout = X25_DEFAULT_T21;
63int sysctl_x25_reset_request_timeout = X25_DEFAULT_T22;
64int sysctl_x25_clear_request_timeout = X25_DEFAULT_T23;
65int sysctl_x25_ack_holdback_timeout = X25_DEFAULT_T2;
39e21c0d 66int sysctl_x25_forward = 0;
1da177e4
LT
67
68HLIST_HEAD(x25_list);
69DEFINE_RWLOCK(x25_list_lock);
70
90ddc4f0 71static const struct proto_ops x25_proto_ops;
1da177e4
LT
72
73static struct x25_address null_x25_address = {" "};
74
1b06e6ba
SP
75#ifdef CONFIG_COMPAT
76struct compat_x25_subscrip_struct {
77 char device[200-sizeof(compat_ulong_t)];
78 compat_ulong_t global_facil_mask;
79 compat_uint_t extended;
80};
81#endif
82
1da177e4
LT
83int x25_addr_ntoa(unsigned char *p, struct x25_address *called_addr,
84 struct x25_address *calling_addr)
85{
6bf1574e 86 unsigned int called_len, calling_len;
1da177e4 87 char *called, *calling;
6bf1574e 88 unsigned int i;
1da177e4
LT
89
90 called_len = (*p >> 0) & 0x0F;
91 calling_len = (*p >> 4) & 0x0F;
92
93 called = called_addr->x25_addr;
94 calling = calling_addr->x25_addr;
95 p++;
96
97 for (i = 0; i < (called_len + calling_len); i++) {
98 if (i < called_len) {
99 if (i % 2 != 0) {
100 *called++ = ((*p >> 0) & 0x0F) + '0';
101 p++;
102 } else {
103 *called++ = ((*p >> 4) & 0x0F) + '0';
104 }
105 } else {
106 if (i % 2 != 0) {
107 *calling++ = ((*p >> 0) & 0x0F) + '0';
108 p++;
109 } else {
110 *calling++ = ((*p >> 4) & 0x0F) + '0';
111 }
112 }
113 }
114
115 *called = *calling = '\0';
116
117 return 1 + (called_len + calling_len + 1) / 2;
118}
119
120int x25_addr_aton(unsigned char *p, struct x25_address *called_addr,
121 struct x25_address *calling_addr)
122{
123 unsigned int called_len, calling_len;
124 char *called, *calling;
125 int i;
126
127 called = called_addr->x25_addr;
128 calling = calling_addr->x25_addr;
129
130 called_len = strlen(called);
131 calling_len = strlen(calling);
132
133 *p++ = (calling_len << 4) | (called_len << 0);
134
135 for (i = 0; i < (called_len + calling_len); i++) {
136 if (i < called_len) {
137 if (i % 2 != 0) {
138 *p |= (*called++ - '0') << 0;
139 p++;
140 } else {
141 *p = 0x00;
142 *p |= (*called++ - '0') << 4;
143 }
144 } else {
145 if (i % 2 != 0) {
146 *p |= (*calling++ - '0') << 0;
147 p++;
148 } else {
149 *p = 0x00;
150 *p |= (*calling++ - '0') << 4;
151 }
152 }
153 }
154
155 return 1 + (called_len + calling_len + 1) / 2;
156}
157
158/*
159 * Socket removal during an interrupt is now safe.
160 */
161static void x25_remove_socket(struct sock *sk)
162{
163 write_lock_bh(&x25_list_lock);
164 sk_del_node_init(sk);
165 write_unlock_bh(&x25_list_lock);
166}
167
168/*
169 * Kill all bound sockets on a dropped device.
170 */
171static void x25_kill_by_device(struct net_device *dev)
172{
173 struct sock *s;
174 struct hlist_node *node;
175
176 write_lock_bh(&x25_list_lock);
177
178 sk_for_each(s, node, &x25_list)
179 if (x25_sk(s)->neighbour && x25_sk(s)->neighbour->dev == dev)
180 x25_disconnect(s, ENETUNREACH, 0, 0);
181
182 write_unlock_bh(&x25_list_lock);
183}
184
185/*
186 * Handle device status changes.
187 */
188static int x25_device_event(struct notifier_block *this, unsigned long event,
189 void *ptr)
190{
191 struct net_device *dev = ptr;
192 struct x25_neigh *nb;
193
721499e8 194 if (!net_eq(dev_net(dev), &init_net))
e9dc8653
EB
195 return NOTIFY_DONE;
196
1da177e4
LT
197 if (dev->type == ARPHRD_X25
198#if defined(CONFIG_LLC) || defined(CONFIG_LLC_MODULE)
199 || dev->type == ARPHRD_ETHER
200#endif
201 ) {
202 switch (event) {
203 case NETDEV_UP:
204 x25_link_device_up(dev);
205 break;
206 case NETDEV_GOING_DOWN:
207 nb = x25_get_neigh(dev);
208 if (nb) {
209 x25_terminate_link(nb);
210 x25_neigh_put(nb);
211 }
212 break;
213 case NETDEV_DOWN:
214 x25_kill_by_device(dev);
215 x25_route_device_down(dev);
216 x25_link_device_down(dev);
217 break;
218 }
219 }
220
221 return NOTIFY_DONE;
222}
223
224/*
225 * Add a socket to the bound sockets list.
226 */
227static void x25_insert_socket(struct sock *sk)
228{
229 write_lock_bh(&x25_list_lock);
230 sk_add_node(sk, &x25_list);
231 write_unlock_bh(&x25_list_lock);
232}
233
234/*
235 * Find a socket that wants to accept the Call Request we just
236 * received. Check the full list for an address/cud match.
237 * If no cuds match return the next_best thing, an address match.
238 * Note: if a listening socket has cud set it must only get calls
239 * with matching cud.
240 */
cb65d506
SP
241static struct sock *x25_find_listener(struct x25_address *addr,
242 struct sk_buff *skb)
1da177e4
LT
243{
244 struct sock *s;
245 struct sock *next_best;
246 struct hlist_node *node;
247
248 read_lock_bh(&x25_list_lock);
249 next_best = NULL;
250
251 sk_for_each(s, node, &x25_list)
252 if ((!strcmp(addr->x25_addr,
cb65d506
SP
253 x25_sk(s)->source_addr.x25_addr) ||
254 !strcmp(addr->x25_addr,
255 null_x25_address.x25_addr)) &&
256 s->sk_state == TCP_LISTEN) {
1da177e4
LT
257 /*
258 * Found a listening socket, now check the incoming
259 * call user data vs this sockets call user data
260 */
cb65d506 261 if(skb->len > 0 && x25_sk(s)->cudmatchlength > 0) {
f8e1d201
YH
262 if((memcmp(x25_sk(s)->calluserdata.cuddata,
263 skb->data,
cb65d506
SP
264 x25_sk(s)->cudmatchlength)) == 0) {
265 sock_hold(s);
266 goto found;
267 }
268 } else
1da177e4 269 next_best = s;
1da177e4
LT
270 }
271 if (next_best) {
272 s = next_best;
273 sock_hold(s);
274 goto found;
275 }
276 s = NULL;
277found:
278 read_unlock_bh(&x25_list_lock);
279 return s;
280}
281
282/*
283 * Find a connected X.25 socket given my LCI and neighbour.
284 */
285static struct sock *__x25_find_socket(unsigned int lci, struct x25_neigh *nb)
286{
287 struct sock *s;
288 struct hlist_node *node;
289
290 sk_for_each(s, node, &x25_list)
291 if (x25_sk(s)->lci == lci && x25_sk(s)->neighbour == nb) {
292 sock_hold(s);
293 goto found;
294 }
295 s = NULL;
296found:
297 return s;
298}
299
300struct sock *x25_find_socket(unsigned int lci, struct x25_neigh *nb)
301{
302 struct sock *s;
303
304 read_lock_bh(&x25_list_lock);
305 s = __x25_find_socket(lci, nb);
306 read_unlock_bh(&x25_list_lock);
307 return s;
308}
309
310/*
311 * Find a unique LCI for a given device.
312 */
313static unsigned int x25_new_lci(struct x25_neigh *nb)
314{
315 unsigned int lci = 1;
316 struct sock *sk;
317
318 read_lock_bh(&x25_list_lock);
319
320 while ((sk = __x25_find_socket(lci, nb)) != NULL) {
321 sock_put(sk);
322 if (++lci == 4096) {
323 lci = 0;
324 break;
325 }
326 }
327
328 read_unlock_bh(&x25_list_lock);
329 return lci;
330}
331
332/*
333 * Deferred destroy.
334 */
14ebaf81 335static void __x25_destroy_socket(struct sock *);
1da177e4
LT
336
337/*
338 * handler for deferred kills.
339 */
340static void x25_destroy_timer(unsigned long data)
341{
14ebaf81 342 x25_destroy_socket_from_timer((struct sock *)data);
1da177e4
LT
343}
344
345/*
346 * This is called from user mode and the timers. Thus it protects itself
347 * against interrupt users but doesn't worry about being called during
348 * work. Once it is removed from the queue no interrupt or bottom half
349 * will touch it and we are (fairly 8-) ) safe.
350 * Not static as it's used by the timer
351 */
14ebaf81 352static void __x25_destroy_socket(struct sock *sk)
1da177e4
LT
353{
354 struct sk_buff *skb;
355
1da177e4
LT
356 x25_stop_heartbeat(sk);
357 x25_stop_timer(sk);
358
359 x25_remove_socket(sk);
360 x25_clear_queues(sk); /* Flush the queues */
361
362 while ((skb = skb_dequeue(&sk->sk_receive_queue)) != NULL) {
363 if (skb->sk != sk) { /* A pending connection */
364 /*
365 * Queue the unaccepted socket for death
366 */
367 sock_set_flag(skb->sk, SOCK_DEAD);
368 x25_start_heartbeat(skb->sk);
369 x25_sk(skb->sk)->state = X25_STATE_0;
370 }
371
372 kfree_skb(skb);
373 }
374
c564039f 375 if (sk_has_allocations(sk)) {
1da177e4
LT
376 /* Defer: outstanding buffers */
377 sk->sk_timer.expires = jiffies + 10 * HZ;
378 sk->sk_timer.function = x25_destroy_timer;
379 sk->sk_timer.data = (unsigned long)sk;
380 add_timer(&sk->sk_timer);
381 } else {
382 /* drop last reference so sock_put will free */
383 __sock_put(sk);
384 }
14ebaf81 385}
1da177e4 386
14ebaf81
DM
387void x25_destroy_socket_from_timer(struct sock *sk)
388{
389 sock_hold(sk);
390 bh_lock_sock(sk);
391 __x25_destroy_socket(sk);
392 bh_unlock_sock(sk);
393 sock_put(sk);
394}
395
396static void x25_destroy_socket(struct sock *sk)
397{
398 sock_hold(sk);
399 lock_sock(sk);
400 __x25_destroy_socket(sk);
1da177e4
LT
401 release_sock(sk);
402 sock_put(sk);
403}
404
405/*
406 * Handling for system calls applied via the various interfaces to a
407 * X.25 socket object.
408 */
409
410static int x25_setsockopt(struct socket *sock, int level, int optname,
411 char __user *optval, int optlen)
412{
413 int opt;
414 struct sock *sk = sock->sk;
415 int rc = -ENOPROTOOPT;
416
417 if (level != SOL_X25 || optname != X25_QBITINCL)
418 goto out;
419
420 rc = -EINVAL;
421 if (optlen < sizeof(int))
422 goto out;
423
424 rc = -EFAULT;
425 if (get_user(opt, (int __user *)optval))
426 goto out;
427
428 x25_sk(sk)->qbitincl = !!opt;
429 rc = 0;
430out:
431 return rc;
432}
433
434static int x25_getsockopt(struct socket *sock, int level, int optname,
435 char __user *optval, int __user *optlen)
436{
437 struct sock *sk = sock->sk;
438 int val, len, rc = -ENOPROTOOPT;
f8e1d201 439
1da177e4
LT
440 if (level != SOL_X25 || optname != X25_QBITINCL)
441 goto out;
442
443 rc = -EFAULT;
444 if (get_user(len, optlen))
445 goto out;
446
447 len = min_t(unsigned int, len, sizeof(int));
448
449 rc = -EINVAL;
450 if (len < 0)
451 goto out;
f8e1d201 452
1da177e4
LT
453 rc = -EFAULT;
454 if (put_user(len, optlen))
455 goto out;
456
457 val = x25_sk(sk)->qbitincl;
458 rc = copy_to_user(optval, &val, len) ? -EFAULT : 0;
459out:
460 return rc;
461}
462
463static int x25_listen(struct socket *sock, int backlog)
464{
465 struct sock *sk = sock->sk;
466 int rc = -EOPNOTSUPP;
467
468 if (sk->sk_state != TCP_LISTEN) {
469 memset(&x25_sk(sk)->dest_addr, 0, X25_ADDR_LEN);
470 sk->sk_max_ack_backlog = backlog;
471 sk->sk_state = TCP_LISTEN;
472 rc = 0;
473 }
474
475 return rc;
476}
477
478static struct proto x25_proto = {
479 .name = "X25",
480 .owner = THIS_MODULE,
481 .obj_size = sizeof(struct x25_sock),
482};
483
1b8d7ae4 484static struct sock *x25_alloc_socket(struct net *net)
1da177e4
LT
485{
486 struct x25_sock *x25;
6257ff21 487 struct sock *sk = sk_alloc(net, AF_X25, GFP_ATOMIC, &x25_proto);
1da177e4
LT
488
489 if (!sk)
490 goto out;
491
492 sock_init_data(NULL, sk);
493
494 x25 = x25_sk(sk);
495 skb_queue_head_init(&x25->ack_queue);
496 skb_queue_head_init(&x25->fragment_queue);
497 skb_queue_head_init(&x25->interrupt_in_queue);
498 skb_queue_head_init(&x25->interrupt_out_queue);
499out:
500 return sk;
501}
502
1b8d7ae4 503static int x25_create(struct net *net, struct socket *sock, int protocol)
1da177e4
LT
504{
505 struct sock *sk;
506 struct x25_sock *x25;
507 int rc = -ESOCKTNOSUPPORT;
508
1b8d7ae4
EB
509 if (net != &init_net)
510 return -EAFNOSUPPORT;
511
1da177e4
LT
512 if (sock->type != SOCK_SEQPACKET || protocol)
513 goto out;
514
515 rc = -ENOMEM;
1b8d7ae4 516 if ((sk = x25_alloc_socket(net)) == NULL)
1da177e4
LT
517 goto out;
518
519 x25 = x25_sk(sk);
520
521 sock_init_data(sock, sk);
522
523 x25_init_timers(sk);
524
525 sock->ops = &x25_proto_ops;
526 sk->sk_protocol = protocol;
527 sk->sk_backlog_rcv = x25_backlog_rcv;
528
529 x25->t21 = sysctl_x25_call_request_timeout;
530 x25->t22 = sysctl_x25_reset_request_timeout;
531 x25->t23 = sysctl_x25_clear_request_timeout;
532 x25->t2 = sysctl_x25_ack_holdback_timeout;
533 x25->state = X25_STATE_0;
cb65d506 534 x25->cudmatchlength = 0;
ebc3f64b
SP
535 x25->accptapprv = X25_DENY_ACCPT_APPRV; /* normally no cud */
536 /* on call accept */
1da177e4
LT
537
538 x25->facilities.winsize_in = X25_DEFAULT_WINDOW_SIZE;
539 x25->facilities.winsize_out = X25_DEFAULT_WINDOW_SIZE;
540 x25->facilities.pacsize_in = X25_DEFAULT_PACKET_SIZE;
541 x25->facilities.pacsize_out = X25_DEFAULT_PACKET_SIZE;
542 x25->facilities.throughput = X25_DEFAULT_THROUGHPUT;
543 x25->facilities.reverse = X25_DEFAULT_REVERSE;
f8e1d201
YH
544 x25->dte_facilities.calling_len = 0;
545 x25->dte_facilities.called_len = 0;
546 memset(x25->dte_facilities.called_ae, '\0',
547 sizeof(x25->dte_facilities.called_ae));
548 memset(x25->dte_facilities.calling_ae, '\0',
549 sizeof(x25->dte_facilities.calling_ae));
a64b7b93 550
1da177e4
LT
551 rc = 0;
552out:
553 return rc;
554}
555
556static struct sock *x25_make_new(struct sock *osk)
557{
558 struct sock *sk = NULL;
559 struct x25_sock *x25, *ox25;
560
561 if (osk->sk_type != SOCK_SEQPACKET)
562 goto out;
563
3b1e0a65 564 if ((sk = x25_alloc_socket(sock_net(osk))) == NULL)
1da177e4
LT
565 goto out;
566
567 x25 = x25_sk(sk);
568
569 sk->sk_type = osk->sk_type;
1da177e4
LT
570 sk->sk_priority = osk->sk_priority;
571 sk->sk_protocol = osk->sk_protocol;
572 sk->sk_rcvbuf = osk->sk_rcvbuf;
573 sk->sk_sndbuf = osk->sk_sndbuf;
574 sk->sk_state = TCP_ESTABLISHED;
1da177e4 575 sk->sk_backlog_rcv = osk->sk_backlog_rcv;
a20a8554 576 sock_copy_flags(sk, osk);
1da177e4
LT
577
578 ox25 = x25_sk(osk);
579 x25->t21 = ox25->t21;
580 x25->t22 = ox25->t22;
581 x25->t23 = ox25->t23;
582 x25->t2 = ox25->t2;
583 x25->facilities = ox25->facilities;
584 x25->qbitincl = ox25->qbitincl;
a64b7b93 585 x25->dte_facilities = ox25->dte_facilities;
cb65d506 586 x25->cudmatchlength = ox25->cudmatchlength;
ebc3f64b 587 x25->accptapprv = ox25->accptapprv;
1da177e4
LT
588
589 x25_init_timers(sk);
590out:
591 return sk;
592}
593
594static int x25_release(struct socket *sock)
595{
596 struct sock *sk = sock->sk;
597 struct x25_sock *x25;
598
599 if (!sk)
600 goto out;
601
602 x25 = x25_sk(sk);
603
604 switch (x25->state) {
605
606 case X25_STATE_0:
607 case X25_STATE_2:
608 x25_disconnect(sk, 0, 0, 0);
609 x25_destroy_socket(sk);
610 goto out;
611
612 case X25_STATE_1:
613 case X25_STATE_3:
614 case X25_STATE_4:
615 x25_clear_queues(sk);
616 x25_write_internal(sk, X25_CLEAR_REQUEST);
617 x25_start_t23timer(sk);
618 x25->state = X25_STATE_2;
619 sk->sk_state = TCP_CLOSE;
620 sk->sk_shutdown |= SEND_SHUTDOWN;
621 sk->sk_state_change(sk);
622 sock_set_flag(sk, SOCK_DEAD);
623 sock_set_flag(sk, SOCK_DESTROY);
624 break;
625 }
626
c751e4f8 627 sock_orphan(sk);
1da177e4
LT
628out:
629 return 0;
630}
631
632static int x25_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
633{
634 struct sock *sk = sock->sk;
635 struct sockaddr_x25 *addr = (struct sockaddr_x25 *)uaddr;
636
637 if (!sock_flag(sk, SOCK_ZAPPED) ||
638 addr_len != sizeof(struct sockaddr_x25) ||
639 addr->sx25_family != AF_X25)
640 return -EINVAL;
641
642 x25_sk(sk)->source_addr = addr->sx25_addr;
643 x25_insert_socket(sk);
644 sock_reset_flag(sk, SOCK_ZAPPED);
645 SOCK_DEBUG(sk, "x25_bind: socket is bound\n");
646
647 return 0;
648}
649
650static int x25_wait_for_connection_establishment(struct sock *sk)
651{
652 DECLARE_WAITQUEUE(wait, current);
f8e1d201 653 int rc;
1da177e4
LT
654
655 add_wait_queue_exclusive(sk->sk_sleep, &wait);
656 for (;;) {
657 __set_current_state(TASK_INTERRUPTIBLE);
658 rc = -ERESTARTSYS;
659 if (signal_pending(current))
660 break;
661 rc = sock_error(sk);
662 if (rc) {
663 sk->sk_socket->state = SS_UNCONNECTED;
664 break;
665 }
666 rc = 0;
667 if (sk->sk_state != TCP_ESTABLISHED) {
668 release_sock(sk);
669 schedule();
670 lock_sock(sk);
671 } else
672 break;
673 }
674 __set_current_state(TASK_RUNNING);
675 remove_wait_queue(sk->sk_sleep, &wait);
676 return rc;
677}
678
679static int x25_connect(struct socket *sock, struct sockaddr *uaddr,
680 int addr_len, int flags)
681{
682 struct sock *sk = sock->sk;
683 struct x25_sock *x25 = x25_sk(sk);
684 struct sockaddr_x25 *addr = (struct sockaddr_x25 *)uaddr;
685 struct x25_route *rt;
686 int rc = 0;
687
688 lock_sock(sk);
689 if (sk->sk_state == TCP_ESTABLISHED && sock->state == SS_CONNECTING) {
690 sock->state = SS_CONNECTED;
691 goto out; /* Connect completed during a ERESTARTSYS event */
692 }
693
694 rc = -ECONNREFUSED;
695 if (sk->sk_state == TCP_CLOSE && sock->state == SS_CONNECTING) {
696 sock->state = SS_UNCONNECTED;
697 goto out;
698 }
699
700 rc = -EISCONN; /* No reconnect on a seqpacket socket */
701 if (sk->sk_state == TCP_ESTABLISHED)
702 goto out;
703
f8e1d201 704 sk->sk_state = TCP_CLOSE;
1da177e4
LT
705 sock->state = SS_UNCONNECTED;
706
707 rc = -EINVAL;
708 if (addr_len != sizeof(struct sockaddr_x25) ||
709 addr->sx25_family != AF_X25)
710 goto out;
711
712 rc = -ENETUNREACH;
713 rt = x25_get_route(&addr->sx25_addr);
714 if (!rt)
715 goto out;
716
717 x25->neighbour = x25_get_neigh(rt->dev);
718 if (!x25->neighbour)
719 goto out_put_route;
720
721 x25_limit_facilities(&x25->facilities, x25->neighbour);
722
723 x25->lci = x25_new_lci(x25->neighbour);
724 if (!x25->lci)
725 goto out_put_neigh;
726
727 rc = -EINVAL;
728 if (sock_flag(sk, SOCK_ZAPPED)) /* Must bind first - autobinding does not work */
729 goto out_put_neigh;
730
731 if (!strcmp(x25->source_addr.x25_addr, null_x25_address.x25_addr))
732 memset(&x25->source_addr, '\0', X25_ADDR_LEN);
733
734 x25->dest_addr = addr->sx25_addr;
735
736 /* Move to connecting socket, start sending Connect Requests */
737 sock->state = SS_CONNECTING;
738 sk->sk_state = TCP_SYN_SENT;
739
740 x25->state = X25_STATE_1;
741
742 x25_write_internal(sk, X25_CALL_REQUEST);
743
744 x25_start_heartbeat(sk);
745 x25_start_t21timer(sk);
746
747 /* Now the loop */
748 rc = -EINPROGRESS;
749 if (sk->sk_state != TCP_ESTABLISHED && (flags & O_NONBLOCK))
750 goto out_put_neigh;
751
752 rc = x25_wait_for_connection_establishment(sk);
753 if (rc)
754 goto out_put_neigh;
755
756 sock->state = SS_CONNECTED;
757 rc = 0;
758out_put_neigh:
759 if (rc)
760 x25_neigh_put(x25->neighbour);
761out_put_route:
762 x25_route_put(rt);
763out:
764 release_sock(sk);
765 return rc;
766}
767
bac37ec8 768static int x25_wait_for_data(struct sock *sk, long timeout)
1da177e4
LT
769{
770 DECLARE_WAITQUEUE(wait, current);
771 int rc = 0;
772
773 add_wait_queue_exclusive(sk->sk_sleep, &wait);
774 for (;;) {
775 __set_current_state(TASK_INTERRUPTIBLE);
776 if (sk->sk_shutdown & RCV_SHUTDOWN)
777 break;
778 rc = -ERESTARTSYS;
779 if (signal_pending(current))
780 break;
781 rc = -EAGAIN;
782 if (!timeout)
783 break;
784 rc = 0;
785 if (skb_queue_empty(&sk->sk_receive_queue)) {
786 release_sock(sk);
787 timeout = schedule_timeout(timeout);
788 lock_sock(sk);
789 } else
790 break;
791 }
792 __set_current_state(TASK_RUNNING);
793 remove_wait_queue(sk->sk_sleep, &wait);
794 return rc;
795}
f8e1d201 796
1da177e4
LT
797static int x25_accept(struct socket *sock, struct socket *newsock, int flags)
798{
799 struct sock *sk = sock->sk;
800 struct sock *newsk;
801 struct sk_buff *skb;
802 int rc = -EINVAL;
803
804 if (!sk || sk->sk_state != TCP_LISTEN)
805 goto out;
806
807 rc = -EOPNOTSUPP;
808 if (sk->sk_type != SOCK_SEQPACKET)
809 goto out;
810
811 lock_sock(sk);
812 rc = x25_wait_for_data(sk, sk->sk_rcvtimeo);
813 if (rc)
814 goto out2;
815 skb = skb_dequeue(&sk->sk_receive_queue);
816 rc = -EINVAL;
817 if (!skb->sk)
818 goto out2;
819 newsk = skb->sk;
b61d38e0 820 sock_graft(newsk, newsock);
1da177e4
LT
821
822 /* Now attach up the new socket */
823 skb->sk = NULL;
824 kfree_skb(skb);
825 sk->sk_ack_backlog--;
1da177e4
LT
826 newsock->state = SS_CONNECTED;
827 rc = 0;
828out2:
829 release_sock(sk);
830out:
831 return rc;
832}
833
834static int x25_getname(struct socket *sock, struct sockaddr *uaddr,
835 int *uaddr_len, int peer)
836{
837 struct sockaddr_x25 *sx25 = (struct sockaddr_x25 *)uaddr;
838 struct sock *sk = sock->sk;
839 struct x25_sock *x25 = x25_sk(sk);
840
841 if (peer) {
842 if (sk->sk_state != TCP_ESTABLISHED)
843 return -ENOTCONN;
844 sx25->sx25_addr = x25->dest_addr;
845 } else
846 sx25->sx25_addr = x25->source_addr;
847
848 sx25->sx25_family = AF_X25;
849 *uaddr_len = sizeof(*sx25);
850
851 return 0;
852}
f8e1d201 853
1da177e4
LT
854int x25_rx_call_request(struct sk_buff *skb, struct x25_neigh *nb,
855 unsigned int lci)
856{
857 struct sock *sk;
858 struct sock *make;
859 struct x25_sock *makex25;
860 struct x25_address source_addr, dest_addr;
861 struct x25_facilities facilities;
a64b7b93 862 struct x25_dte_facilities dte_facilities;
95a9dc43 863 int len, addr_len, rc;
1da177e4
LT
864
865 /*
866 * Remove the LCI and frame type.
867 */
868 skb_pull(skb, X25_STD_MIN_LEN);
869
870 /*
871 * Extract the X.25 addresses and convert them to ASCII strings,
872 * and remove them.
873 */
95a9dc43
AH
874 addr_len = x25_addr_ntoa(skb->data, &source_addr, &dest_addr);
875 skb_pull(skb, addr_len);
1da177e4
LT
876
877 /*
878 * Get the length of the facilities, skip past them for the moment
879 * get the call user data because this is needed to determine
880 * the correct listener
881 */
882 len = skb->data[0] + 1;
883 skb_pull(skb,len);
884
1da177e4
LT
885 /*
886 * Find a listener for the particular address/cud pair.
887 */
cb65d506
SP
888 sk = x25_find_listener(&source_addr,skb);
889 skb_push(skb,len);
1da177e4 890
95a9dc43
AH
891 if (sk != NULL && sk_acceptq_is_full(sk)) {
892 goto out_sock_put;
893 }
894
1da177e4 895 /*
95a9dc43
AH
896 * We dont have any listeners for this incoming call.
897 * Try forwarding it.
1da177e4 898 */
95a9dc43
AH
899 if (sk == NULL) {
900 skb_push(skb, addr_len + X25_STD_MIN_LEN);
39e21c0d
AH
901 if (sysctl_x25_forward &&
902 x25_forward_call(&dest_addr, nb, skb, lci) > 0)
95a9dc43
AH
903 {
904 /* Call was forwarded, dont process it any more */
905 kfree_skb(skb);
906 rc = 1;
907 goto out;
908 } else {
909 /* No listeners, can't forward, clear the call */
910 goto out_clear_request;
911 }
912 }
1da177e4
LT
913
914 /*
915 * Try to reach a compromise on the requested facilities.
916 */
a64b7b93
SP
917 len = x25_negotiate_facilities(skb, sk, &facilities, &dte_facilities);
918 if (len == -1)
1da177e4
LT
919 goto out_sock_put;
920
921 /*
922 * current neighbour/link might impose additional limits
923 * on certain facilties
924 */
925
926 x25_limit_facilities(&facilities, nb);
927
928 /*
929 * Try to create a new socket.
930 */
931 make = x25_make_new(sk);
932 if (!make)
933 goto out_sock_put;
934
935 /*
936 * Remove the facilities
937 */
938 skb_pull(skb, len);
939
940 skb->sk = make;
941 make->sk_state = TCP_ESTABLISHED;
942
943 makex25 = x25_sk(make);
944 makex25->lci = lci;
945 makex25->dest_addr = dest_addr;
946 makex25->source_addr = source_addr;
947 makex25->neighbour = nb;
948 makex25->facilities = facilities;
a64b7b93 949 makex25->dte_facilities= dte_facilities;
1da177e4 950 makex25->vc_facil_mask = x25_sk(sk)->vc_facil_mask;
cb65d506
SP
951 /* ensure no reverse facil on accept */
952 makex25->vc_facil_mask &= ~X25_MASK_REVERSE;
a64b7b93
SP
953 /* ensure no calling address extension on accept */
954 makex25->vc_facil_mask &= ~X25_MASK_CALLING_AE;
cb65d506 955 makex25->cudmatchlength = x25_sk(sk)->cudmatchlength;
1da177e4 956
ebc3f64b
SP
957 /* Normally all calls are accepted immediatly */
958 if(makex25->accptapprv & X25_DENY_ACCPT_APPRV) {
959 x25_write_internal(make, X25_CALL_ACCEPTED);
960 makex25->state = X25_STATE_3;
961 }
1da177e4 962
cb65d506
SP
963 /*
964 * Incoming Call User Data.
965 */
8db09f26
RK
966 skb_copy_from_linear_data(skb, makex25->calluserdata.cuddata, skb->len);
967 makex25->calluserdata.cudlength = skb->len;
cb65d506 968
1da177e4
LT
969 sk->sk_ack_backlog++;
970
971 x25_insert_socket(make);
972
973 skb_queue_head(&sk->sk_receive_queue, skb);
974
975 x25_start_heartbeat(make);
976
977 if (!sock_flag(sk, SOCK_DEAD))
978 sk->sk_data_ready(sk, skb->len);
979 rc = 1;
980 sock_put(sk);
981out:
982 return rc;
983out_sock_put:
984 sock_put(sk);
985out_clear_request:
986 rc = 0;
987 x25_transmit_clear_request(nb, lci, 0x01);
988 goto out;
989}
990
991static int x25_sendmsg(struct kiocb *iocb, struct socket *sock,
992 struct msghdr *msg, size_t len)
993{
994 struct sock *sk = sock->sk;
995 struct x25_sock *x25 = x25_sk(sk);
996 struct sockaddr_x25 *usx25 = (struct sockaddr_x25 *)msg->msg_name;
997 struct sockaddr_x25 sx25;
998 struct sk_buff *skb;
999 unsigned char *asmptr;
1000 int noblock = msg->msg_flags & MSG_DONTWAIT;
1001 size_t size;
1002 int qbit = 0, rc = -EINVAL;
1003
1004 if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_OOB|MSG_EOR|MSG_CMSG_COMPAT))
1005 goto out;
1006
1007 /* we currently don't support segmented records at the user interface */
1008 if (!(msg->msg_flags & (MSG_EOR|MSG_OOB)))
1009 goto out;
1010
1011 rc = -EADDRNOTAVAIL;
1012 if (sock_flag(sk, SOCK_ZAPPED))
1013 goto out;
1014
1015 rc = -EPIPE;
1016 if (sk->sk_shutdown & SEND_SHUTDOWN) {
1017 send_sig(SIGPIPE, current, 0);
1018 goto out;
1019 }
1020
1021 rc = -ENETUNREACH;
1022 if (!x25->neighbour)
1023 goto out;
1024
1025 if (usx25) {
1026 rc = -EINVAL;
1027 if (msg->msg_namelen < sizeof(sx25))
1028 goto out;
1029 memcpy(&sx25, usx25, sizeof(sx25));
1030 rc = -EISCONN;
1031 if (strcmp(x25->dest_addr.x25_addr, sx25.sx25_addr.x25_addr))
1032 goto out;
1033 rc = -EINVAL;
1034 if (sx25.sx25_family != AF_X25)
1035 goto out;
1036 } else {
1037 /*
1038 * FIXME 1003.1g - if the socket is like this because
1039 * it has become closed (not started closed) we ought
1040 * to SIGPIPE, EPIPE;
1041 */
1042 rc = -ENOTCONN;
1043 if (sk->sk_state != TCP_ESTABLISHED)
1044 goto out;
1045
1046 sx25.sx25_family = AF_X25;
1047 sx25.sx25_addr = x25->dest_addr;
1048 }
1049
83e0bbcb
AC
1050 /* Sanity check the packet size */
1051 if (len > 65535) {
1052 rc = -EMSGSIZE;
1053 goto out;
1054 }
1055
1da177e4
LT
1056 SOCK_DEBUG(sk, "x25_sendmsg: sendto: Addresses built.\n");
1057
1058 /* Build a packet */
1059 SOCK_DEBUG(sk, "x25_sendmsg: sendto: building packet.\n");
1060
1061 if ((msg->msg_flags & MSG_OOB) && len > 32)
1062 len = 32;
1063
1064 size = len + X25_MAX_L2_LEN + X25_EXT_MIN_LEN;
1065
1066 skb = sock_alloc_send_skb(sk, size, noblock, &rc);
1067 if (!skb)
1068 goto out;
1069 X25_SKB_CB(skb)->flags = msg->msg_flags;
1070
1071 skb_reserve(skb, X25_MAX_L2_LEN + X25_EXT_MIN_LEN);
1072
1073 /*
1074 * Put the data on the end
1075 */
1076 SOCK_DEBUG(sk, "x25_sendmsg: Copying user data\n");
1077
eeeb0374
ACM
1078 skb_reset_transport_header(skb);
1079 skb_put(skb, len);
1da177e4 1080
eeeb0374 1081 rc = memcpy_fromiovec(skb_transport_header(skb), msg->msg_iov, len);
1da177e4
LT
1082 if (rc)
1083 goto out_kfree_skb;
1084
1085 /*
1086 * If the Q BIT Include socket option is in force, the first
1087 * byte of the user data is the logical value of the Q Bit.
1088 */
1089 if (x25->qbitincl) {
1090 qbit = skb->data[0];
1091 skb_pull(skb, 1);
1092 }
1093
1094 /*
1095 * Push down the X.25 header
1096 */
1097 SOCK_DEBUG(sk, "x25_sendmsg: Building X.25 Header.\n");
1098
1099 if (msg->msg_flags & MSG_OOB) {
1100 if (x25->neighbour->extended) {
1101 asmptr = skb_push(skb, X25_STD_MIN_LEN);
1102 *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_EXTSEQ;
1103 *asmptr++ = (x25->lci >> 0) & 0xFF;
1104 *asmptr++ = X25_INTERRUPT;
1105 } else {
1106 asmptr = skb_push(skb, X25_STD_MIN_LEN);
1107 *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_STDSEQ;
1108 *asmptr++ = (x25->lci >> 0) & 0xFF;
1109 *asmptr++ = X25_INTERRUPT;
1110 }
1111 } else {
1112 if (x25->neighbour->extended) {
1113 /* Build an Extended X.25 header */
1114 asmptr = skb_push(skb, X25_EXT_MIN_LEN);
1115 *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_EXTSEQ;
1116 *asmptr++ = (x25->lci >> 0) & 0xFF;
1117 *asmptr++ = X25_DATA;
1118 *asmptr++ = X25_DATA;
1119 } else {
1120 /* Build an Standard X.25 header */
1121 asmptr = skb_push(skb, X25_STD_MIN_LEN);
1122 *asmptr++ = ((x25->lci >> 8) & 0x0F) | X25_GFI_STDSEQ;
1123 *asmptr++ = (x25->lci >> 0) & 0xFF;
1124 *asmptr++ = X25_DATA;
1125 }
1126
1127 if (qbit)
1128 skb->data[0] |= X25_Q_BIT;
1129 }
1130
1131 SOCK_DEBUG(sk, "x25_sendmsg: Built header.\n");
1132 SOCK_DEBUG(sk, "x25_sendmsg: Transmitting buffer\n");
1133
1134 rc = -ENOTCONN;
1135 if (sk->sk_state != TCP_ESTABLISHED)
1136 goto out_kfree_skb;
1137
1138 if (msg->msg_flags & MSG_OOB)
1139 skb_queue_tail(&x25->interrupt_out_queue, skb);
1140 else {
8db09f26
RK
1141 rc = x25_output(sk, skb);
1142 len = rc;
1143 if (rc < 0)
1da177e4
LT
1144 kfree_skb(skb);
1145 else if (x25->qbitincl)
1146 len++;
1147 }
1148
1149 /*
1150 * lock_sock() is currently only used to serialize this x25_kick()
1151 * against input-driven x25_kick() calls. It currently only blocks
1152 * incoming packets for this socket and does not protect against
1153 * any other socket state changes and is not called from anywhere
1154 * else. As x25_kick() cannot block and as long as all socket
1155 * operations are BKL-wrapped, we don't need take to care about
1156 * purging the backlog queue in x25_release().
1157 *
1158 * Using lock_sock() to protect all socket operations entirely
1159 * (and making the whole x25 stack SMP aware) unfortunately would
1160 * require major changes to {send,recv}msg and skb allocation methods.
1161 * -> 2.5 ;)
1162 */
1163 lock_sock(sk);
1164 x25_kick(sk);
1165 release_sock(sk);
1166 rc = len;
1167out:
1168 return rc;
1169out_kfree_skb:
1170 kfree_skb(skb);
1171 goto out;
1172}
1173
1174
1175static int x25_recvmsg(struct kiocb *iocb, struct socket *sock,
1176 struct msghdr *msg, size_t size,
1177 int flags)
1178{
1179 struct sock *sk = sock->sk;
1180 struct x25_sock *x25 = x25_sk(sk);
1181 struct sockaddr_x25 *sx25 = (struct sockaddr_x25 *)msg->msg_name;
1182 size_t copied;
1183 int qbit;
1184 struct sk_buff *skb;
1185 unsigned char *asmptr;
1186 int rc = -ENOTCONN;
1187
1188 /*
1189 * This works for seqpacket too. The receiver has ordered the queue for
1190 * us! We do one quick check first though
1191 */
1192 if (sk->sk_state != TCP_ESTABLISHED)
1193 goto out;
1194
1195 if (flags & MSG_OOB) {
1196 rc = -EINVAL;
1197 if (sock_flag(sk, SOCK_URGINLINE) ||
1198 !skb_peek(&x25->interrupt_in_queue))
1199 goto out;
1200
1201 skb = skb_dequeue(&x25->interrupt_in_queue);
1202
1203 skb_pull(skb, X25_STD_MIN_LEN);
1204
1205 /*
1206 * No Q bit information on Interrupt data.
1207 */
1208 if (x25->qbitincl) {
1209 asmptr = skb_push(skb, 1);
1210 *asmptr = 0x00;
1211 }
1212
1213 msg->msg_flags |= MSG_OOB;
1214 } else {
1215 /* Now we can treat all alike */
1216 skb = skb_recv_datagram(sk, flags & ~MSG_DONTWAIT,
1217 flags & MSG_DONTWAIT, &rc);
1218 if (!skb)
1219 goto out;
1220
1221 qbit = (skb->data[0] & X25_Q_BIT) == X25_Q_BIT;
1222
1223 skb_pull(skb, x25->neighbour->extended ?
1224 X25_EXT_MIN_LEN : X25_STD_MIN_LEN);
1225
1226 if (x25->qbitincl) {
1227 asmptr = skb_push(skb, 1);
1228 *asmptr = qbit;
1229 }
1230 }
1231
badff6d0 1232 skb_reset_transport_header(skb);
1da177e4
LT
1233 copied = skb->len;
1234
1235 if (copied > size) {
1236 copied = size;
1237 msg->msg_flags |= MSG_TRUNC;
1238 }
1239
f8e1d201 1240 /* Currently, each datagram always contains a complete record */
1da177e4
LT
1241 msg->msg_flags |= MSG_EOR;
1242
1243 rc = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
1244 if (rc)
1245 goto out_free_dgram;
1246
1247 if (sx25) {
1248 sx25->sx25_family = AF_X25;
1249 sx25->sx25_addr = x25->dest_addr;
1250 }
1251
1252 msg->msg_namelen = sizeof(struct sockaddr_x25);
1253
1254 lock_sock(sk);
1255 x25_check_rbuf(sk);
1256 release_sock(sk);
1257 rc = copied;
1258out_free_dgram:
1259 skb_free_datagram(sk, skb);
1260out:
1261 return rc;
1262}
1263
1264
1265static int x25_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
1266{
1267 struct sock *sk = sock->sk;
1268 struct x25_sock *x25 = x25_sk(sk);
1269 void __user *argp = (void __user *)arg;
1270 int rc;
1271
1272 switch (cmd) {
1273 case TIOCOUTQ: {
31e6d363
ED
1274 int amount = sk->sk_sndbuf - sk_wmem_alloc_get(sk);
1275
1da177e4
LT
1276 if (amount < 0)
1277 amount = 0;
1278 rc = put_user(amount, (unsigned int __user *)argp);
1279 break;
1280 }
1281
1282 case TIOCINQ: {
1283 struct sk_buff *skb;
1284 int amount = 0;
1285 /*
1286 * These two are safe on a single CPU system as
1287 * only user tasks fiddle here
1288 */
1289 if ((skb = skb_peek(&sk->sk_receive_queue)) != NULL)
1290 amount = skb->len;
1291 rc = put_user(amount, (unsigned int __user *)argp);
1292 break;
1293 }
1294
1295 case SIOCGSTAMP:
1296 rc = -EINVAL;
1297 if (sk)
f8e1d201
YH
1298 rc = sock_get_timestamp(sk,
1299 (struct timeval __user *)argp);
1da177e4 1300 break;
ae40eb1e
ED
1301 case SIOCGSTAMPNS:
1302 rc = -EINVAL;
1303 if (sk)
1304 rc = sock_get_timestampns(sk,
1305 (struct timespec __user *)argp);
1306 break;
1da177e4
LT
1307 case SIOCGIFADDR:
1308 case SIOCSIFADDR:
1309 case SIOCGIFDSTADDR:
1310 case SIOCSIFDSTADDR:
1311 case SIOCGIFBRDADDR:
1312 case SIOCSIFBRDADDR:
1313 case SIOCGIFNETMASK:
1314 case SIOCSIFNETMASK:
1315 case SIOCGIFMETRIC:
1316 case SIOCSIFMETRIC:
1317 rc = -EINVAL;
1318 break;
1319 case SIOCADDRT:
1320 case SIOCDELRT:
1321 rc = -EPERM;
1322 if (!capable(CAP_NET_ADMIN))
1323 break;
1324 rc = x25_route_ioctl(cmd, argp);
1325 break;
1326 case SIOCX25GSUBSCRIP:
1327 rc = x25_subscr_ioctl(cmd, argp);
1328 break;
1329 case SIOCX25SSUBSCRIP:
1330 rc = -EPERM;
1331 if (!capable(CAP_NET_ADMIN))
1332 break;
1333 rc = x25_subscr_ioctl(cmd, argp);
1334 break;
1335 case SIOCX25GFACILITIES: {
1336 struct x25_facilities fac = x25->facilities;
1337 rc = copy_to_user(argp, &fac,
1338 sizeof(fac)) ? -EFAULT : 0;
1339 break;
1340 }
1341
1342 case SIOCX25SFACILITIES: {
1343 struct x25_facilities facilities;
1344 rc = -EFAULT;
1345 if (copy_from_user(&facilities, argp,
1346 sizeof(facilities)))
1347 break;
1348 rc = -EINVAL;
1349 if (sk->sk_state != TCP_LISTEN &&
1350 sk->sk_state != TCP_CLOSE)
1351 break;
1352 if (facilities.pacsize_in < X25_PS16 ||
1353 facilities.pacsize_in > X25_PS4096)
1354 break;
1355 if (facilities.pacsize_out < X25_PS16 ||
1356 facilities.pacsize_out > X25_PS4096)
1357 break;
1358 if (facilities.winsize_in < 1 ||
1359 facilities.winsize_in > 127)
1360 break;
1361 if (facilities.throughput < 0x03 ||
1362 facilities.throughput > 0xDD)
1363 break;
ebc3f64b
SP
1364 if (facilities.reverse &&
1365 (facilities.reverse | 0x81)!= 0x81)
1da177e4
LT
1366 break;
1367 x25->facilities = facilities;
1368 rc = 0;
1369 break;
1370 }
1371
a64b7b93 1372 case SIOCX25GDTEFACILITIES: {
f8e1d201 1373 rc = copy_to_user(argp, &x25->dte_facilities,
a64b7b93
SP
1374 sizeof(x25->dte_facilities));
1375 if (rc)
1376 rc = -EFAULT;
f8e1d201
YH
1377 break;
1378 }
a64b7b93 1379
f8e1d201
YH
1380 case SIOCX25SDTEFACILITIES: {
1381 struct x25_dte_facilities dtefacs;
1382 rc = -EFAULT;
1383 if (copy_from_user(&dtefacs, argp, sizeof(dtefacs)))
a64b7b93
SP
1384 break;
1385 rc = -EINVAL;
1386 if (sk->sk_state != TCP_LISTEN &&
1387 sk->sk_state != TCP_CLOSE)
1388 break;
1389 if (dtefacs.calling_len > X25_MAX_AE_LEN)
1390 break;
1391 if (dtefacs.calling_ae == NULL)
1392 break;
1393 if (dtefacs.called_len > X25_MAX_AE_LEN)
1394 break;
1395 if (dtefacs.called_ae == NULL)
1396 break;
1397 x25->dte_facilities = dtefacs;
1398 rc = 0;
1399 break;
1400 }
1401
1da177e4
LT
1402 case SIOCX25GCALLUSERDATA: {
1403 struct x25_calluserdata cud = x25->calluserdata;
1404 rc = copy_to_user(argp, &cud,
1405 sizeof(cud)) ? -EFAULT : 0;
1406 break;
1407 }
1408
1409 case SIOCX25SCALLUSERDATA: {
1410 struct x25_calluserdata calluserdata;
1411
1412 rc = -EFAULT;
1413 if (copy_from_user(&calluserdata, argp,
1414 sizeof(calluserdata)))
1415 break;
1416 rc = -EINVAL;
1417 if (calluserdata.cudlength > X25_MAX_CUD_LEN)
1418 break;
1419 x25->calluserdata = calluserdata;
1420 rc = 0;
1421 break;
1422 }
1423
1424 case SIOCX25GCAUSEDIAG: {
1425 struct x25_causediag causediag;
1426 causediag = x25->causediag;
1427 rc = copy_to_user(argp, &causediag,
1428 sizeof(causediag)) ? -EFAULT : 0;
1429 break;
1430 }
1431
cb65d506
SP
1432 case SIOCX25SCUDMATCHLEN: {
1433 struct x25_subaddr sub_addr;
1434 rc = -EINVAL;
1435 if(sk->sk_state != TCP_CLOSE)
1436 break;
1437 rc = -EFAULT;
1438 if (copy_from_user(&sub_addr, argp,
1439 sizeof(sub_addr)))
1440 break;
f8e1d201 1441 rc = -EINVAL;
cb65d506
SP
1442 if(sub_addr.cudmatchlength > X25_MAX_CUD_LEN)
1443 break;
1444 x25->cudmatchlength = sub_addr.cudmatchlength;
1445 rc = 0;
1446 break;
1447 }
1448
ebc3f64b
SP
1449 case SIOCX25CALLACCPTAPPRV: {
1450 rc = -EINVAL;
1451 if (sk->sk_state != TCP_CLOSE)
1452 break;
1453 x25->accptapprv = X25_ALLOW_ACCPT_APPRV;
1454 rc = 0;
1455 break;
1456 }
1457
1458 case SIOCX25SENDCALLACCPT: {
1459 rc = -EINVAL;
1460 if (sk->sk_state != TCP_ESTABLISHED)
1461 break;
1462 if (x25->accptapprv) /* must call accptapprv above */
1463 break;
1464 x25_write_internal(sk, X25_CALL_ACCEPTED);
1465 x25->state = X25_STATE_3;
1466 rc = 0;
1467 break;
1468 }
1469
f8e1d201 1470 default:
b5e5fa5e 1471 rc = -ENOIOCTLCMD;
1da177e4
LT
1472 break;
1473 }
1474
1475 return rc;
1476}
1477
1478static struct net_proto_family x25_family_ops = {
1479 .family = AF_X25,
1480 .create = x25_create,
1481 .owner = THIS_MODULE,
1482};
1483
1b06e6ba
SP
1484#ifdef CONFIG_COMPAT
1485static int compat_x25_subscr_ioctl(unsigned int cmd,
1486 struct compat_x25_subscrip_struct __user *x25_subscr32)
1487{
1488 struct compat_x25_subscrip_struct x25_subscr;
1489 struct x25_neigh *nb;
1490 struct net_device *dev;
1491 int rc = -EINVAL;
1492
1493 rc = -EFAULT;
1494 if (copy_from_user(&x25_subscr, x25_subscr32, sizeof(*x25_subscr32)))
1495 goto out;
1496
1497 rc = -EINVAL;
1498 dev = x25_dev_get(x25_subscr.device);
1499 if (dev == NULL)
1500 goto out;
1501
1502 nb = x25_get_neigh(dev);
1503 if (nb == NULL)
1504 goto out_dev_put;
1505
1506 dev_put(dev);
1507
1508 if (cmd == SIOCX25GSUBSCRIP) {
1509 x25_subscr.extended = nb->extended;
1510 x25_subscr.global_facil_mask = nb->global_facil_mask;
1511 rc = copy_to_user(x25_subscr32, &x25_subscr,
1512 sizeof(*x25_subscr32)) ? -EFAULT : 0;
1513 } else {
1514 rc = -EINVAL;
1515 if (x25_subscr.extended == 0 || x25_subscr.extended == 1) {
1516 rc = 0;
1517 nb->extended = x25_subscr.extended;
1518 nb->global_facil_mask = x25_subscr.global_facil_mask;
1519 }
1520 }
1521 x25_neigh_put(nb);
1522out:
1523 return rc;
1524out_dev_put:
1525 dev_put(dev);
1526 goto out;
1527}
1528
1529static int compat_x25_ioctl(struct socket *sock, unsigned int cmd,
1530 unsigned long arg)
1531{
1532 void __user *argp = compat_ptr(arg);
1533 struct sock *sk = sock->sk;
1534
1535 int rc = -ENOIOCTLCMD;
1536
1537 switch(cmd) {
1538 case TIOCOUTQ:
1539 case TIOCINQ:
1540 rc = x25_ioctl(sock, cmd, (unsigned long)argp);
1541 break;
1542 case SIOCGSTAMP:
1543 rc = -EINVAL;
1544 if (sk)
1545 rc = compat_sock_get_timestamp(sk,
1546 (struct timeval __user*)argp);
1547 break;
ae40eb1e
ED
1548 case SIOCGSTAMPNS:
1549 rc = -EINVAL;
1550 if (sk)
1551 rc = compat_sock_get_timestampns(sk,
1552 (struct timespec __user*)argp);
1553 break;
1b06e6ba
SP
1554 case SIOCGIFADDR:
1555 case SIOCSIFADDR:
1556 case SIOCGIFDSTADDR:
1557 case SIOCSIFDSTADDR:
1558 case SIOCGIFBRDADDR:
1559 case SIOCSIFBRDADDR:
1560 case SIOCGIFNETMASK:
1561 case SIOCSIFNETMASK:
1562 case SIOCGIFMETRIC:
1563 case SIOCSIFMETRIC:
1564 rc = -EINVAL;
1565 break;
1566 case SIOCADDRT:
1567 case SIOCDELRT:
1568 rc = -EPERM;
1569 if (!capable(CAP_NET_ADMIN))
1570 break;
1571 rc = x25_route_ioctl(cmd, argp);
1572 break;
1573 case SIOCX25GSUBSCRIP:
1574 rc = compat_x25_subscr_ioctl(cmd, argp);
1575 break;
1576 case SIOCX25SSUBSCRIP:
1577 rc = -EPERM;
1578 if (!capable(CAP_NET_ADMIN))
1579 break;
1580 rc = compat_x25_subscr_ioctl(cmd, argp);
1581 break;
1582 case SIOCX25GFACILITIES:
1583 case SIOCX25SFACILITIES:
9a6b9f2e
SP
1584 case SIOCX25GDTEFACILITIES:
1585 case SIOCX25SDTEFACILITIES:
1b06e6ba
SP
1586 case SIOCX25GCALLUSERDATA:
1587 case SIOCX25SCALLUSERDATA:
1588 case SIOCX25GCAUSEDIAG:
1589 case SIOCX25SCUDMATCHLEN:
1590 case SIOCX25CALLACCPTAPPRV:
1591 case SIOCX25SENDCALLACCPT:
1592 rc = x25_ioctl(sock, cmd, (unsigned long)argp);
1593 break;
1594 default:
1595 rc = -ENOIOCTLCMD;
1596 break;
1597 }
1598 return rc;
1599}
1600#endif
1601
90ddc4f0 1602static const struct proto_ops SOCKOPS_WRAPPED(x25_proto_ops) = {
1da177e4
LT
1603 .family = AF_X25,
1604 .owner = THIS_MODULE,
1605 .release = x25_release,
1606 .bind = x25_bind,
1607 .connect = x25_connect,
1608 .socketpair = sock_no_socketpair,
1609 .accept = x25_accept,
1610 .getname = x25_getname,
1611 .poll = datagram_poll,
1612 .ioctl = x25_ioctl,
1b06e6ba
SP
1613#ifdef CONFIG_COMPAT
1614 .compat_ioctl = compat_x25_ioctl,
1615#endif
1da177e4
LT
1616 .listen = x25_listen,
1617 .shutdown = sock_no_shutdown,
1618 .setsockopt = x25_setsockopt,
1619 .getsockopt = x25_getsockopt,
1620 .sendmsg = x25_sendmsg,
1621 .recvmsg = x25_recvmsg,
1622 .mmap = sock_no_mmap,
1623 .sendpage = sock_no_sendpage,
1624};
1625
1da177e4
LT
1626SOCKOPS_WRAP(x25_proto, AF_X25);
1627
7546dd97 1628static struct packet_type x25_packet_type __read_mostly = {
09640e63 1629 .type = cpu_to_be16(ETH_P_X25),
1da177e4
LT
1630 .func = x25_lapb_receive_frame,
1631};
1632
1633static struct notifier_block x25_dev_notifier = {
1634 .notifier_call = x25_device_event,
1635};
1636
1637void x25_kill_by_neigh(struct x25_neigh *nb)
1638{
1639 struct sock *s;
1640 struct hlist_node *node;
1641
1642 write_lock_bh(&x25_list_lock);
1643
1644 sk_for_each(s, node, &x25_list)
1645 if (x25_sk(s)->neighbour == nb)
1646 x25_disconnect(s, ENETUNREACH, 0, 0);
1647
1648 write_unlock_bh(&x25_list_lock);
95a9dc43
AH
1649
1650 /* Remove any related forwards */
1651 x25_clear_forward_by_dev(nb->dev);
1da177e4
LT
1652}
1653
1654static int __init x25_init(void)
1655{
1656 int rc = proto_register(&x25_proto, 0);
1657
1658 if (rc != 0)
1659 goto out;
1660
1661 sock_register(&x25_family_ops);
1662
1663 dev_add_pack(&x25_packet_type);
1664
1665 register_netdevice_notifier(&x25_dev_notifier);
1666
a44562e4 1667 printk(KERN_INFO "X.25 for Linux Version 0.2\n");
1da177e4
LT
1668
1669#ifdef CONFIG_SYSCTL
1670 x25_register_sysctl();
1671#endif
1672 x25_proc_init();
1673out:
1674 return rc;
1675}
1676module_init(x25_init);
1677
1678static void __exit x25_exit(void)
1679{
1680 x25_proc_exit();
1681 x25_link_free();
1682 x25_route_free();
1683
1684#ifdef CONFIG_SYSCTL
1685 x25_unregister_sysctl();
1686#endif
1687
1688 unregister_netdevice_notifier(&x25_dev_notifier);
1689
1690 dev_remove_pack(&x25_packet_type);
1691
1692 sock_unregister(AF_X25);
1693 proto_unregister(&x25_proto);
1694}
1695module_exit(x25_exit);
1696
1697MODULE_AUTHOR("Jonathan Naylor <g4klx@g4klx.demon.co.uk>");
1698MODULE_DESCRIPTION("The X.25 Packet Layer network layer protocol");
1699MODULE_LICENSE("GPL");
1700MODULE_ALIAS_NETPROTO(PF_X25);