Back to home page

OSCL-LXR

 
 

    


0001 // SPDX-License-Identifier: GPL-2.0-only
0002 /*
0003  * Copyright (C) ST-Ericsson AB 2010
0004  * Author:  Sjur Brendeland
0005  */
0006 
0007 #define pr_fmt(fmt) KBUILD_MODNAME ":%s(): " fmt, __func__
0008 
0009 #include <linux/filter.h>
0010 #include <linux/fs.h>
0011 #include <linux/init.h>
0012 #include <linux/module.h>
0013 #include <linux/sched/signal.h>
0014 #include <linux/spinlock.h>
0015 #include <linux/mutex.h>
0016 #include <linux/list.h>
0017 #include <linux/wait.h>
0018 #include <linux/poll.h>
0019 #include <linux/tcp.h>
0020 #include <linux/uaccess.h>
0021 #include <linux/debugfs.h>
0022 #include <linux/caif/caif_socket.h>
0023 #include <linux/pkt_sched.h>
0024 #include <net/sock.h>
0025 #include <net/tcp_states.h>
0026 #include <net/caif/caif_layer.h>
0027 #include <net/caif/caif_dev.h>
0028 #include <net/caif/cfpkt.h>
0029 
0030 MODULE_LICENSE("GPL");
0031 MODULE_ALIAS_NETPROTO(AF_CAIF);
0032 
0033 /*
0034  * CAIF state is re-using the TCP socket states.
0035  * caif_states stored in sk_state reflect the state as reported by
0036  * the CAIF stack, while sk_socket->state is the state of the socket.
0037  */
0038 enum caif_states {
0039     CAIF_CONNECTED      = TCP_ESTABLISHED,
0040     CAIF_CONNECTING = TCP_SYN_SENT,
0041     CAIF_DISCONNECTED   = TCP_CLOSE
0042 };
0043 
0044 #define TX_FLOW_ON_BIT  1
0045 #define RX_FLOW_ON_BIT  2
0046 
0047 struct caifsock {
0048     struct sock sk; /* must be first member */
0049     struct cflayer layer;
0050     unsigned long flow_state;
0051     struct caif_connect_request conn_req;
0052     struct mutex readlock;
0053     struct dentry *debugfs_socket_dir;
0054     int headroom, tailroom, maxframe;
0055 };
0056 
0057 static int rx_flow_is_on(struct caifsock *cf_sk)
0058 {
0059     return test_bit(RX_FLOW_ON_BIT, &cf_sk->flow_state);
0060 }
0061 
0062 static int tx_flow_is_on(struct caifsock *cf_sk)
0063 {
0064     return test_bit(TX_FLOW_ON_BIT, &cf_sk->flow_state);
0065 }
0066 
0067 static void set_rx_flow_off(struct caifsock *cf_sk)
0068 {
0069     clear_bit(RX_FLOW_ON_BIT, &cf_sk->flow_state);
0070 }
0071 
0072 static void set_rx_flow_on(struct caifsock *cf_sk)
0073 {
0074     set_bit(RX_FLOW_ON_BIT, &cf_sk->flow_state);
0075 }
0076 
0077 static void set_tx_flow_off(struct caifsock *cf_sk)
0078 {
0079     clear_bit(TX_FLOW_ON_BIT, &cf_sk->flow_state);
0080 }
0081 
0082 static void set_tx_flow_on(struct caifsock *cf_sk)
0083 {
0084     set_bit(TX_FLOW_ON_BIT, &cf_sk->flow_state);
0085 }
0086 
0087 static void caif_read_lock(struct sock *sk)
0088 {
0089     struct caifsock *cf_sk;
0090     cf_sk = container_of(sk, struct caifsock, sk);
0091     mutex_lock(&cf_sk->readlock);
0092 }
0093 
0094 static void caif_read_unlock(struct sock *sk)
0095 {
0096     struct caifsock *cf_sk;
0097     cf_sk = container_of(sk, struct caifsock, sk);
0098     mutex_unlock(&cf_sk->readlock);
0099 }
0100 
0101 static int sk_rcvbuf_lowwater(struct caifsock *cf_sk)
0102 {
0103     /* A quarter of full buffer is used a low water mark */
0104     return cf_sk->sk.sk_rcvbuf / 4;
0105 }
0106 
0107 static void caif_flow_ctrl(struct sock *sk, int mode)
0108 {
0109     struct caifsock *cf_sk;
0110     cf_sk = container_of(sk, struct caifsock, sk);
0111     if (cf_sk->layer.dn && cf_sk->layer.dn->modemcmd)
0112         cf_sk->layer.dn->modemcmd(cf_sk->layer.dn, mode);
0113 }
0114 
0115 /*
0116  * Copied from sock.c:sock_queue_rcv_skb(), but changed so packets are
0117  * not dropped, but CAIF is sending flow off instead.
0118  */
0119 static void caif_queue_rcv_skb(struct sock *sk, struct sk_buff *skb)
0120 {
0121     int err;
0122     unsigned long flags;
0123     struct sk_buff_head *list = &sk->sk_receive_queue;
0124     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0125     bool queued = false;
0126 
0127     if (atomic_read(&sk->sk_rmem_alloc) + skb->truesize >=
0128         (unsigned int)sk->sk_rcvbuf && rx_flow_is_on(cf_sk)) {
0129         net_dbg_ratelimited("sending flow OFF (queue len = %d %d)\n",
0130                     atomic_read(&cf_sk->sk.sk_rmem_alloc),
0131                     sk_rcvbuf_lowwater(cf_sk));
0132         set_rx_flow_off(cf_sk);
0133         caif_flow_ctrl(sk, CAIF_MODEMCMD_FLOW_OFF_REQ);
0134     }
0135 
0136     err = sk_filter(sk, skb);
0137     if (err)
0138         goto out;
0139 
0140     if (!sk_rmem_schedule(sk, skb, skb->truesize) && rx_flow_is_on(cf_sk)) {
0141         set_rx_flow_off(cf_sk);
0142         net_dbg_ratelimited("sending flow OFF due to rmem_schedule\n");
0143         caif_flow_ctrl(sk, CAIF_MODEMCMD_FLOW_OFF_REQ);
0144     }
0145     skb->dev = NULL;
0146     skb_set_owner_r(skb, sk);
0147     spin_lock_irqsave(&list->lock, flags);
0148     queued = !sock_flag(sk, SOCK_DEAD);
0149     if (queued)
0150         __skb_queue_tail(list, skb);
0151     spin_unlock_irqrestore(&list->lock, flags);
0152 out:
0153     if (queued)
0154         sk->sk_data_ready(sk);
0155     else
0156         kfree_skb(skb);
0157 }
0158 
0159 /* Packet Receive Callback function called from CAIF Stack */
0160 static int caif_sktrecv_cb(struct cflayer *layr, struct cfpkt *pkt)
0161 {
0162     struct caifsock *cf_sk;
0163     struct sk_buff *skb;
0164 
0165     cf_sk = container_of(layr, struct caifsock, layer);
0166     skb = cfpkt_tonative(pkt);
0167 
0168     if (unlikely(cf_sk->sk.sk_state != CAIF_CONNECTED)) {
0169         kfree_skb(skb);
0170         return 0;
0171     }
0172     caif_queue_rcv_skb(&cf_sk->sk, skb);
0173     return 0;
0174 }
0175 
0176 static void cfsk_hold(struct cflayer *layr)
0177 {
0178     struct caifsock *cf_sk = container_of(layr, struct caifsock, layer);
0179     sock_hold(&cf_sk->sk);
0180 }
0181 
0182 static void cfsk_put(struct cflayer *layr)
0183 {
0184     struct caifsock *cf_sk = container_of(layr, struct caifsock, layer);
0185     sock_put(&cf_sk->sk);
0186 }
0187 
0188 /* Packet Control Callback function called from CAIF */
0189 static void caif_ctrl_cb(struct cflayer *layr,
0190              enum caif_ctrlcmd flow,
0191              int phyid)
0192 {
0193     struct caifsock *cf_sk = container_of(layr, struct caifsock, layer);
0194     switch (flow) {
0195     case CAIF_CTRLCMD_FLOW_ON_IND:
0196         /* OK from modem to start sending again */
0197         set_tx_flow_on(cf_sk);
0198         cf_sk->sk.sk_state_change(&cf_sk->sk);
0199         break;
0200 
0201     case CAIF_CTRLCMD_FLOW_OFF_IND:
0202         /* Modem asks us to shut up */
0203         set_tx_flow_off(cf_sk);
0204         cf_sk->sk.sk_state_change(&cf_sk->sk);
0205         break;
0206 
0207     case CAIF_CTRLCMD_INIT_RSP:
0208         /* We're now connected */
0209         caif_client_register_refcnt(&cf_sk->layer,
0210                         cfsk_hold, cfsk_put);
0211         cf_sk->sk.sk_state = CAIF_CONNECTED;
0212         set_tx_flow_on(cf_sk);
0213         cf_sk->sk.sk_shutdown = 0;
0214         cf_sk->sk.sk_state_change(&cf_sk->sk);
0215         break;
0216 
0217     case CAIF_CTRLCMD_DEINIT_RSP:
0218         /* We're now disconnected */
0219         cf_sk->sk.sk_state = CAIF_DISCONNECTED;
0220         cf_sk->sk.sk_state_change(&cf_sk->sk);
0221         break;
0222 
0223     case CAIF_CTRLCMD_INIT_FAIL_RSP:
0224         /* Connect request failed */
0225         cf_sk->sk.sk_err = ECONNREFUSED;
0226         cf_sk->sk.sk_state = CAIF_DISCONNECTED;
0227         cf_sk->sk.sk_shutdown = SHUTDOWN_MASK;
0228         /*
0229          * Socket "standards" seems to require POLLOUT to
0230          * be set at connect failure.
0231          */
0232         set_tx_flow_on(cf_sk);
0233         cf_sk->sk.sk_state_change(&cf_sk->sk);
0234         break;
0235 
0236     case CAIF_CTRLCMD_REMOTE_SHUTDOWN_IND:
0237         /* Modem has closed this connection, or device is down. */
0238         cf_sk->sk.sk_shutdown = SHUTDOWN_MASK;
0239         cf_sk->sk.sk_err = ECONNRESET;
0240         set_rx_flow_on(cf_sk);
0241         sk_error_report(&cf_sk->sk);
0242         break;
0243 
0244     default:
0245         pr_debug("Unexpected flow command %d\n", flow);
0246     }
0247 }
0248 
0249 static void caif_check_flow_release(struct sock *sk)
0250 {
0251     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0252 
0253     if (rx_flow_is_on(cf_sk))
0254         return;
0255 
0256     if (atomic_read(&sk->sk_rmem_alloc) <= sk_rcvbuf_lowwater(cf_sk)) {
0257             set_rx_flow_on(cf_sk);
0258             caif_flow_ctrl(sk, CAIF_MODEMCMD_FLOW_ON_REQ);
0259     }
0260 }
0261 
0262 /*
0263  * Copied from unix_dgram_recvmsg, but removed credit checks,
0264  * changed locking, address handling and added MSG_TRUNC.
0265  */
0266 static int caif_seqpkt_recvmsg(struct socket *sock, struct msghdr *m,
0267                    size_t len, int flags)
0268 
0269 {
0270     struct sock *sk = sock->sk;
0271     struct sk_buff *skb;
0272     int ret;
0273     int copylen;
0274 
0275     ret = -EOPNOTSUPP;
0276     if (flags & MSG_OOB)
0277         goto read_error;
0278 
0279     skb = skb_recv_datagram(sk, flags, &ret);
0280     if (!skb)
0281         goto read_error;
0282     copylen = skb->len;
0283     if (len < copylen) {
0284         m->msg_flags |= MSG_TRUNC;
0285         copylen = len;
0286     }
0287 
0288     ret = skb_copy_datagram_msg(skb, 0, m, copylen);
0289     if (ret)
0290         goto out_free;
0291 
0292     ret = (flags & MSG_TRUNC) ? skb->len : copylen;
0293 out_free:
0294     skb_free_datagram(sk, skb);
0295     caif_check_flow_release(sk);
0296     return ret;
0297 
0298 read_error:
0299     return ret;
0300 }
0301 
0302 
0303 /* Copied from unix_stream_wait_data, identical except for lock call. */
0304 static long caif_stream_data_wait(struct sock *sk, long timeo)
0305 {
0306     DEFINE_WAIT(wait);
0307     lock_sock(sk);
0308 
0309     for (;;) {
0310         prepare_to_wait(sk_sleep(sk), &wait, TASK_INTERRUPTIBLE);
0311 
0312         if (!skb_queue_empty(&sk->sk_receive_queue) ||
0313             sk->sk_err ||
0314             sk->sk_state != CAIF_CONNECTED ||
0315             sock_flag(sk, SOCK_DEAD) ||
0316             (sk->sk_shutdown & RCV_SHUTDOWN) ||
0317             signal_pending(current) ||
0318             !timeo)
0319             break;
0320 
0321         sk_set_bit(SOCKWQ_ASYNC_WAITDATA, sk);
0322         release_sock(sk);
0323         timeo = schedule_timeout(timeo);
0324         lock_sock(sk);
0325 
0326         if (sock_flag(sk, SOCK_DEAD))
0327             break;
0328 
0329         sk_clear_bit(SOCKWQ_ASYNC_WAITDATA, sk);
0330     }
0331 
0332     finish_wait(sk_sleep(sk), &wait);
0333     release_sock(sk);
0334     return timeo;
0335 }
0336 
0337 
0338 /*
0339  * Copied from unix_stream_recvmsg, but removed credit checks,
0340  * changed locking calls, changed address handling.
0341  */
0342 static int caif_stream_recvmsg(struct socket *sock, struct msghdr *msg,
0343                    size_t size, int flags)
0344 {
0345     struct sock *sk = sock->sk;
0346     int copied = 0;
0347     int target;
0348     int err = 0;
0349     long timeo;
0350 
0351     err = -EOPNOTSUPP;
0352     if (flags&MSG_OOB)
0353         goto out;
0354 
0355     /*
0356      * Lock the socket to prevent queue disordering
0357      * while sleeps in memcpy_tomsg
0358      */
0359     err = -EAGAIN;
0360     if (sk->sk_state == CAIF_CONNECTING)
0361         goto out;
0362 
0363     caif_read_lock(sk);
0364     target = sock_rcvlowat(sk, flags&MSG_WAITALL, size);
0365     timeo = sock_rcvtimeo(sk, flags&MSG_DONTWAIT);
0366 
0367     do {
0368         int chunk;
0369         struct sk_buff *skb;
0370 
0371         lock_sock(sk);
0372         if (sock_flag(sk, SOCK_DEAD)) {
0373             err = -ECONNRESET;
0374             goto unlock;
0375         }
0376         skb = skb_dequeue(&sk->sk_receive_queue);
0377         caif_check_flow_release(sk);
0378 
0379         if (skb == NULL) {
0380             if (copied >= target)
0381                 goto unlock;
0382             /*
0383              *  POSIX 1003.1g mandates this order.
0384              */
0385             err = sock_error(sk);
0386             if (err)
0387                 goto unlock;
0388             err = -ECONNRESET;
0389             if (sk->sk_shutdown & RCV_SHUTDOWN)
0390                 goto unlock;
0391 
0392             err = -EPIPE;
0393             if (sk->sk_state != CAIF_CONNECTED)
0394                 goto unlock;
0395             if (sock_flag(sk, SOCK_DEAD))
0396                 goto unlock;
0397 
0398             release_sock(sk);
0399 
0400             err = -EAGAIN;
0401             if (!timeo)
0402                 break;
0403 
0404             caif_read_unlock(sk);
0405 
0406             timeo = caif_stream_data_wait(sk, timeo);
0407 
0408             if (signal_pending(current)) {
0409                 err = sock_intr_errno(timeo);
0410                 goto out;
0411             }
0412             caif_read_lock(sk);
0413             continue;
0414 unlock:
0415             release_sock(sk);
0416             break;
0417         }
0418         release_sock(sk);
0419         chunk = min_t(unsigned int, skb->len, size);
0420         if (memcpy_to_msg(msg, skb->data, chunk)) {
0421             skb_queue_head(&sk->sk_receive_queue, skb);
0422             if (copied == 0)
0423                 copied = -EFAULT;
0424             break;
0425         }
0426         copied += chunk;
0427         size -= chunk;
0428 
0429         /* Mark read part of skb as used */
0430         if (!(flags & MSG_PEEK)) {
0431             skb_pull(skb, chunk);
0432 
0433             /* put the skb back if we didn't use it up. */
0434             if (skb->len) {
0435                 skb_queue_head(&sk->sk_receive_queue, skb);
0436                 break;
0437             }
0438             kfree_skb(skb);
0439 
0440         } else {
0441             /*
0442              * It is questionable, see note in unix_dgram_recvmsg.
0443              */
0444             /* put message back and return */
0445             skb_queue_head(&sk->sk_receive_queue, skb);
0446             break;
0447         }
0448     } while (size);
0449     caif_read_unlock(sk);
0450 
0451 out:
0452     return copied ? : err;
0453 }
0454 
0455 /*
0456  * Copied from sock.c:sock_wait_for_wmem, but change to wait for
0457  * CAIF flow-on and sock_writable.
0458  */
0459 static long caif_wait_for_flow_on(struct caifsock *cf_sk,
0460                   int wait_writeable, long timeo, int *err)
0461 {
0462     struct sock *sk = &cf_sk->sk;
0463     DEFINE_WAIT(wait);
0464     for (;;) {
0465         *err = 0;
0466         if (tx_flow_is_on(cf_sk) &&
0467             (!wait_writeable || sock_writeable(&cf_sk->sk)))
0468             break;
0469         *err = -ETIMEDOUT;
0470         if (!timeo)
0471             break;
0472         *err = -ERESTARTSYS;
0473         if (signal_pending(current))
0474             break;
0475         prepare_to_wait(sk_sleep(sk), &wait, TASK_INTERRUPTIBLE);
0476         *err = -ECONNRESET;
0477         if (sk->sk_shutdown & SHUTDOWN_MASK)
0478             break;
0479         *err = -sk->sk_err;
0480         if (sk->sk_err)
0481             break;
0482         *err = -EPIPE;
0483         if (cf_sk->sk.sk_state != CAIF_CONNECTED)
0484             break;
0485         timeo = schedule_timeout(timeo);
0486     }
0487     finish_wait(sk_sleep(sk), &wait);
0488     return timeo;
0489 }
0490 
0491 /*
0492  * Transmit a SKB. The device may temporarily request re-transmission
0493  * by returning EAGAIN.
0494  */
0495 static int transmit_skb(struct sk_buff *skb, struct caifsock *cf_sk,
0496             int noblock, long timeo)
0497 {
0498     struct cfpkt *pkt;
0499 
0500     pkt = cfpkt_fromnative(CAIF_DIR_OUT, skb);
0501     memset(skb->cb, 0, sizeof(struct caif_payload_info));
0502     cfpkt_set_prio(pkt, cf_sk->sk.sk_priority);
0503 
0504     if (cf_sk->layer.dn == NULL) {
0505         kfree_skb(skb);
0506         return -EINVAL;
0507     }
0508 
0509     return cf_sk->layer.dn->transmit(cf_sk->layer.dn, pkt);
0510 }
0511 
0512 /* Copied from af_unix:unix_dgram_sendmsg, and adapted to CAIF */
0513 static int caif_seqpkt_sendmsg(struct socket *sock, struct msghdr *msg,
0514                    size_t len)
0515 {
0516     struct sock *sk = sock->sk;
0517     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0518     int buffer_size;
0519     int ret = 0;
0520     struct sk_buff *skb = NULL;
0521     int noblock;
0522     long timeo;
0523     caif_assert(cf_sk);
0524     ret = sock_error(sk);
0525     if (ret)
0526         goto err;
0527 
0528     ret = -EOPNOTSUPP;
0529     if (msg->msg_flags&MSG_OOB)
0530         goto err;
0531 
0532     ret = -EOPNOTSUPP;
0533     if (msg->msg_namelen)
0534         goto err;
0535 
0536     ret = -EINVAL;
0537     if (unlikely(msg->msg_iter.nr_segs == 0) ||
0538         unlikely(msg->msg_iter.iov->iov_base == NULL))
0539         goto err;
0540     noblock = msg->msg_flags & MSG_DONTWAIT;
0541 
0542     timeo = sock_sndtimeo(sk, noblock);
0543     timeo = caif_wait_for_flow_on(container_of(sk, struct caifsock, sk),
0544                 1, timeo, &ret);
0545 
0546     if (ret)
0547         goto err;
0548     ret = -EPIPE;
0549     if (cf_sk->sk.sk_state != CAIF_CONNECTED ||
0550         sock_flag(sk, SOCK_DEAD) ||
0551         (sk->sk_shutdown & RCV_SHUTDOWN))
0552         goto err;
0553 
0554     /* Error if trying to write more than maximum frame size. */
0555     ret = -EMSGSIZE;
0556     if (len > cf_sk->maxframe && cf_sk->sk.sk_protocol != CAIFPROTO_RFM)
0557         goto err;
0558 
0559     buffer_size = len + cf_sk->headroom + cf_sk->tailroom;
0560 
0561     ret = -ENOMEM;
0562     skb = sock_alloc_send_skb(sk, buffer_size, noblock, &ret);
0563 
0564     if (!skb || skb_tailroom(skb) < buffer_size)
0565         goto err;
0566 
0567     skb_reserve(skb, cf_sk->headroom);
0568 
0569     ret = memcpy_from_msg(skb_put(skb, len), msg, len);
0570 
0571     if (ret)
0572         goto err;
0573     ret = transmit_skb(skb, cf_sk, noblock, timeo);
0574     if (ret < 0)
0575         /* skb is already freed */
0576         return ret;
0577 
0578     return len;
0579 err:
0580     kfree_skb(skb);
0581     return ret;
0582 }
0583 
0584 /*
0585  * Copied from unix_stream_sendmsg and adapted to CAIF:
0586  * Changed removed permission handling and added waiting for flow on
0587  * and other minor adaptations.
0588  */
0589 static int caif_stream_sendmsg(struct socket *sock, struct msghdr *msg,
0590                    size_t len)
0591 {
0592     struct sock *sk = sock->sk;
0593     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0594     int err, size;
0595     struct sk_buff *skb;
0596     int sent = 0;
0597     long timeo;
0598 
0599     err = -EOPNOTSUPP;
0600     if (unlikely(msg->msg_flags&MSG_OOB))
0601         goto out_err;
0602 
0603     if (unlikely(msg->msg_namelen))
0604         goto out_err;
0605 
0606     timeo = sock_sndtimeo(sk, msg->msg_flags & MSG_DONTWAIT);
0607     timeo = caif_wait_for_flow_on(cf_sk, 1, timeo, &err);
0608 
0609     if (unlikely(sk->sk_shutdown & SEND_SHUTDOWN))
0610         goto pipe_err;
0611 
0612     while (sent < len) {
0613 
0614         size = len-sent;
0615 
0616         if (size > cf_sk->maxframe)
0617             size = cf_sk->maxframe;
0618 
0619         /* If size is more than half of sndbuf, chop up message */
0620         if (size > ((sk->sk_sndbuf >> 1) - 64))
0621             size = (sk->sk_sndbuf >> 1) - 64;
0622 
0623         if (size > SKB_MAX_ALLOC)
0624             size = SKB_MAX_ALLOC;
0625 
0626         skb = sock_alloc_send_skb(sk,
0627                     size + cf_sk->headroom +
0628                     cf_sk->tailroom,
0629                     msg->msg_flags&MSG_DONTWAIT,
0630                     &err);
0631         if (skb == NULL)
0632             goto out_err;
0633 
0634         skb_reserve(skb, cf_sk->headroom);
0635         /*
0636          *  If you pass two values to the sock_alloc_send_skb
0637          *  it tries to grab the large buffer with GFP_NOFS
0638          *  (which can fail easily), and if it fails grab the
0639          *  fallback size buffer which is under a page and will
0640          *  succeed. [Alan]
0641          */
0642         size = min_t(int, size, skb_tailroom(skb));
0643 
0644         err = memcpy_from_msg(skb_put(skb, size), msg, size);
0645         if (err) {
0646             kfree_skb(skb);
0647             goto out_err;
0648         }
0649         err = transmit_skb(skb, cf_sk,
0650                 msg->msg_flags&MSG_DONTWAIT, timeo);
0651         if (err < 0)
0652             /* skb is already freed */
0653             goto pipe_err;
0654 
0655         sent += size;
0656     }
0657 
0658     return sent;
0659 
0660 pipe_err:
0661     if (sent == 0 && !(msg->msg_flags&MSG_NOSIGNAL))
0662         send_sig(SIGPIPE, current, 0);
0663     err = -EPIPE;
0664 out_err:
0665     return sent ? : err;
0666 }
0667 
0668 static int setsockopt(struct socket *sock, int lvl, int opt, sockptr_t ov,
0669         unsigned int ol)
0670 {
0671     struct sock *sk = sock->sk;
0672     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0673     int linksel;
0674 
0675     if (cf_sk->sk.sk_socket->state != SS_UNCONNECTED)
0676         return -ENOPROTOOPT;
0677 
0678     switch (opt) {
0679     case CAIFSO_LINK_SELECT:
0680         if (ol < sizeof(int))
0681             return -EINVAL;
0682         if (lvl != SOL_CAIF)
0683             goto bad_sol;
0684         if (copy_from_sockptr(&linksel, ov, sizeof(int)))
0685             return -EINVAL;
0686         lock_sock(&(cf_sk->sk));
0687         cf_sk->conn_req.link_selector = linksel;
0688         release_sock(&cf_sk->sk);
0689         return 0;
0690 
0691     case CAIFSO_REQ_PARAM:
0692         if (lvl != SOL_CAIF)
0693             goto bad_sol;
0694         if (cf_sk->sk.sk_protocol != CAIFPROTO_UTIL)
0695             return -ENOPROTOOPT;
0696         lock_sock(&(cf_sk->sk));
0697         if (ol > sizeof(cf_sk->conn_req.param.data) ||
0698             copy_from_sockptr(&cf_sk->conn_req.param.data, ov, ol)) {
0699             release_sock(&cf_sk->sk);
0700             return -EINVAL;
0701         }
0702         cf_sk->conn_req.param.size = ol;
0703         release_sock(&cf_sk->sk);
0704         return 0;
0705 
0706     default:
0707         return -ENOPROTOOPT;
0708     }
0709 
0710     return 0;
0711 bad_sol:
0712     return -ENOPROTOOPT;
0713 
0714 }
0715 
0716 /*
0717  * caif_connect() - Connect a CAIF Socket
0718  * Copied and modified af_irda.c:irda_connect().
0719  *
0720  * Note : by consulting "errno", the user space caller may learn the cause
0721  * of the failure. Most of them are visible in the function, others may come
0722  * from subroutines called and are listed here :
0723  *  o -EAFNOSUPPORT: bad socket family or type.
0724  *  o -ESOCKTNOSUPPORT: bad socket type or protocol
0725  *  o -EINVAL: bad socket address, or CAIF link type
0726  *  o -ECONNREFUSED: remote end refused the connection.
0727  *  o -EINPROGRESS: connect request sent but timed out (or non-blocking)
0728  *  o -EISCONN: already connected.
0729  *  o -ETIMEDOUT: Connection timed out (send timeout)
0730  *  o -ENODEV: No link layer to send request
0731  *  o -ECONNRESET: Received Shutdown indication or lost link layer
0732  *  o -ENOMEM: Out of memory
0733  *
0734  *  State Strategy:
0735  *  o sk_state: holds the CAIF_* protocol state, it's updated by
0736  *  caif_ctrl_cb.
0737  *  o sock->state: holds the SS_* socket state and is updated by connect and
0738  *  disconnect.
0739  */
0740 static int caif_connect(struct socket *sock, struct sockaddr *uaddr,
0741             int addr_len, int flags)
0742 {
0743     struct sock *sk = sock->sk;
0744     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0745     long timeo;
0746     int err;
0747     int ifindex, headroom, tailroom;
0748     unsigned int mtu;
0749     struct net_device *dev;
0750 
0751     lock_sock(sk);
0752 
0753     err = -EINVAL;
0754     if (addr_len < offsetofend(struct sockaddr, sa_family))
0755         goto out;
0756 
0757     err = -EAFNOSUPPORT;
0758     if (uaddr->sa_family != AF_CAIF)
0759         goto out;
0760 
0761     switch (sock->state) {
0762     case SS_UNCONNECTED:
0763         /* Normal case, a fresh connect */
0764         caif_assert(sk->sk_state == CAIF_DISCONNECTED);
0765         break;
0766     case SS_CONNECTING:
0767         switch (sk->sk_state) {
0768         case CAIF_CONNECTED:
0769             sock->state = SS_CONNECTED;
0770             err = -EISCONN;
0771             goto out;
0772         case CAIF_DISCONNECTED:
0773             /* Reconnect allowed */
0774             break;
0775         case CAIF_CONNECTING:
0776             err = -EALREADY;
0777             if (flags & O_NONBLOCK)
0778                 goto out;
0779             goto wait_connect;
0780         }
0781         break;
0782     case SS_CONNECTED:
0783         caif_assert(sk->sk_state == CAIF_CONNECTED ||
0784                 sk->sk_state == CAIF_DISCONNECTED);
0785         if (sk->sk_shutdown & SHUTDOWN_MASK) {
0786             /* Allow re-connect after SHUTDOWN_IND */
0787             caif_disconnect_client(sock_net(sk), &cf_sk->layer);
0788             caif_free_client(&cf_sk->layer);
0789             break;
0790         }
0791         /* No reconnect on a seqpacket socket */
0792         err = -EISCONN;
0793         goto out;
0794     case SS_DISCONNECTING:
0795     case SS_FREE:
0796         caif_assert(1); /*Should never happen */
0797         break;
0798     }
0799     sk->sk_state = CAIF_DISCONNECTED;
0800     sock->state = SS_UNCONNECTED;
0801     sk_stream_kill_queues(&cf_sk->sk);
0802 
0803     err = -EINVAL;
0804     if (addr_len != sizeof(struct sockaddr_caif))
0805         goto out;
0806 
0807     memcpy(&cf_sk->conn_req.sockaddr, uaddr,
0808         sizeof(struct sockaddr_caif));
0809 
0810     /* Move to connecting socket, start sending Connect Requests */
0811     sock->state = SS_CONNECTING;
0812     sk->sk_state = CAIF_CONNECTING;
0813 
0814     /* Check priority value comming from socket */
0815     /* if priority value is out of range it will be ajusted */
0816     if (cf_sk->sk.sk_priority > CAIF_PRIO_MAX)
0817         cf_sk->conn_req.priority = CAIF_PRIO_MAX;
0818     else if (cf_sk->sk.sk_priority < CAIF_PRIO_MIN)
0819         cf_sk->conn_req.priority = CAIF_PRIO_MIN;
0820     else
0821         cf_sk->conn_req.priority = cf_sk->sk.sk_priority;
0822 
0823     /*ifindex = id of the interface.*/
0824     cf_sk->conn_req.ifindex = cf_sk->sk.sk_bound_dev_if;
0825 
0826     cf_sk->layer.receive = caif_sktrecv_cb;
0827 
0828     err = caif_connect_client(sock_net(sk), &cf_sk->conn_req,
0829                 &cf_sk->layer, &ifindex, &headroom, &tailroom);
0830 
0831     if (err < 0) {
0832         cf_sk->sk.sk_socket->state = SS_UNCONNECTED;
0833         cf_sk->sk.sk_state = CAIF_DISCONNECTED;
0834         goto out;
0835     }
0836 
0837     err = -ENODEV;
0838     rcu_read_lock();
0839     dev = dev_get_by_index_rcu(sock_net(sk), ifindex);
0840     if (!dev) {
0841         rcu_read_unlock();
0842         goto out;
0843     }
0844     cf_sk->headroom = LL_RESERVED_SPACE_EXTRA(dev, headroom);
0845     mtu = dev->mtu;
0846     rcu_read_unlock();
0847 
0848     cf_sk->tailroom = tailroom;
0849     cf_sk->maxframe = mtu - (headroom + tailroom);
0850     if (cf_sk->maxframe < 1) {
0851         pr_warn("CAIF Interface MTU too small (%d)\n", dev->mtu);
0852         err = -ENODEV;
0853         goto out;
0854     }
0855 
0856     err = -EINPROGRESS;
0857 wait_connect:
0858 
0859     if (sk->sk_state != CAIF_CONNECTED && (flags & O_NONBLOCK))
0860         goto out;
0861 
0862     timeo = sock_sndtimeo(sk, flags & O_NONBLOCK);
0863 
0864     release_sock(sk);
0865     err = -ERESTARTSYS;
0866     timeo = wait_event_interruptible_timeout(*sk_sleep(sk),
0867             sk->sk_state != CAIF_CONNECTING,
0868             timeo);
0869     lock_sock(sk);
0870     if (timeo < 0)
0871         goto out; /* -ERESTARTSYS */
0872 
0873     err = -ETIMEDOUT;
0874     if (timeo == 0 && sk->sk_state != CAIF_CONNECTED)
0875         goto out;
0876     if (sk->sk_state != CAIF_CONNECTED) {
0877         sock->state = SS_UNCONNECTED;
0878         err = sock_error(sk);
0879         if (!err)
0880             err = -ECONNREFUSED;
0881         goto out;
0882     }
0883     sock->state = SS_CONNECTED;
0884     err = 0;
0885 out:
0886     release_sock(sk);
0887     return err;
0888 }
0889 
0890 /*
0891  * caif_release() - Disconnect a CAIF Socket
0892  * Copied and modified af_irda.c:irda_release().
0893  */
0894 static int caif_release(struct socket *sock)
0895 {
0896     struct sock *sk = sock->sk;
0897     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0898 
0899     if (!sk)
0900         return 0;
0901 
0902     set_tx_flow_off(cf_sk);
0903 
0904     /*
0905      * Ensure that packets are not queued after this point in time.
0906      * caif_queue_rcv_skb checks SOCK_DEAD holding the queue lock,
0907      * this ensures no packets when sock is dead.
0908      */
0909     spin_lock_bh(&sk->sk_receive_queue.lock);
0910     sock_set_flag(sk, SOCK_DEAD);
0911     spin_unlock_bh(&sk->sk_receive_queue.lock);
0912     sock->sk = NULL;
0913 
0914     WARN_ON(IS_ERR(cf_sk->debugfs_socket_dir));
0915     debugfs_remove_recursive(cf_sk->debugfs_socket_dir);
0916 
0917     lock_sock(&(cf_sk->sk));
0918     sk->sk_state = CAIF_DISCONNECTED;
0919     sk->sk_shutdown = SHUTDOWN_MASK;
0920 
0921     caif_disconnect_client(sock_net(sk), &cf_sk->layer);
0922     cf_sk->sk.sk_socket->state = SS_DISCONNECTING;
0923     wake_up_interruptible_poll(sk_sleep(sk), EPOLLERR|EPOLLHUP);
0924 
0925     sock_orphan(sk);
0926     sk_stream_kill_queues(&cf_sk->sk);
0927     release_sock(sk);
0928     sock_put(sk);
0929     return 0;
0930 }
0931 
0932 /* Copied from af_unix.c:unix_poll(), added CAIF tx_flow handling */
0933 static __poll_t caif_poll(struct file *file,
0934                   struct socket *sock, poll_table *wait)
0935 {
0936     struct sock *sk = sock->sk;
0937     __poll_t mask;
0938     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
0939 
0940     sock_poll_wait(file, sock, wait);
0941     mask = 0;
0942 
0943     /* exceptional events? */
0944     if (sk->sk_err)
0945         mask |= EPOLLERR;
0946     if (sk->sk_shutdown == SHUTDOWN_MASK)
0947         mask |= EPOLLHUP;
0948     if (sk->sk_shutdown & RCV_SHUTDOWN)
0949         mask |= EPOLLRDHUP;
0950 
0951     /* readable? */
0952     if (!skb_queue_empty_lockless(&sk->sk_receive_queue) ||
0953         (sk->sk_shutdown & RCV_SHUTDOWN))
0954         mask |= EPOLLIN | EPOLLRDNORM;
0955 
0956     /*
0957      * we set writable also when the other side has shut down the
0958      * connection. This prevents stuck sockets.
0959      */
0960     if (sock_writeable(sk) && tx_flow_is_on(cf_sk))
0961         mask |= EPOLLOUT | EPOLLWRNORM | EPOLLWRBAND;
0962 
0963     return mask;
0964 }
0965 
0966 static const struct proto_ops caif_seqpacket_ops = {
0967     .family = PF_CAIF,
0968     .owner = THIS_MODULE,
0969     .release = caif_release,
0970     .bind = sock_no_bind,
0971     .connect = caif_connect,
0972     .socketpair = sock_no_socketpair,
0973     .accept = sock_no_accept,
0974     .getname = sock_no_getname,
0975     .poll = caif_poll,
0976     .ioctl = sock_no_ioctl,
0977     .listen = sock_no_listen,
0978     .shutdown = sock_no_shutdown,
0979     .setsockopt = setsockopt,
0980     .sendmsg = caif_seqpkt_sendmsg,
0981     .recvmsg = caif_seqpkt_recvmsg,
0982     .mmap = sock_no_mmap,
0983     .sendpage = sock_no_sendpage,
0984 };
0985 
0986 static const struct proto_ops caif_stream_ops = {
0987     .family = PF_CAIF,
0988     .owner = THIS_MODULE,
0989     .release = caif_release,
0990     .bind = sock_no_bind,
0991     .connect = caif_connect,
0992     .socketpair = sock_no_socketpair,
0993     .accept = sock_no_accept,
0994     .getname = sock_no_getname,
0995     .poll = caif_poll,
0996     .ioctl = sock_no_ioctl,
0997     .listen = sock_no_listen,
0998     .shutdown = sock_no_shutdown,
0999     .setsockopt = setsockopt,
1000     .sendmsg = caif_stream_sendmsg,
1001     .recvmsg = caif_stream_recvmsg,
1002     .mmap = sock_no_mmap,
1003     .sendpage = sock_no_sendpage,
1004 };
1005 
1006 /* This function is called when a socket is finally destroyed. */
1007 static void caif_sock_destructor(struct sock *sk)
1008 {
1009     struct caifsock *cf_sk = container_of(sk, struct caifsock, sk);
1010     caif_assert(!refcount_read(&sk->sk_wmem_alloc));
1011     caif_assert(sk_unhashed(sk));
1012     caif_assert(!sk->sk_socket);
1013     if (!sock_flag(sk, SOCK_DEAD)) {
1014         pr_debug("Attempt to release alive CAIF socket: %p\n", sk);
1015         return;
1016     }
1017     sk_stream_kill_queues(&cf_sk->sk);
1018     caif_free_client(&cf_sk->layer);
1019 }
1020 
1021 static int caif_create(struct net *net, struct socket *sock, int protocol,
1022                int kern)
1023 {
1024     struct sock *sk = NULL;
1025     struct caifsock *cf_sk = NULL;
1026     static struct proto prot = {.name = "PF_CAIF",
1027         .owner = THIS_MODULE,
1028         .obj_size = sizeof(struct caifsock),
1029         .useroffset = offsetof(struct caifsock, conn_req.param),
1030         .usersize = sizeof_field(struct caifsock, conn_req.param)
1031     };
1032 
1033     if (!capable(CAP_SYS_ADMIN) && !capable(CAP_NET_ADMIN))
1034         return -EPERM;
1035     /*
1036      * The sock->type specifies the socket type to use.
1037      * The CAIF socket is a packet stream in the sense
1038      * that it is packet based. CAIF trusts the reliability
1039      * of the link, no resending is implemented.
1040      */
1041     if (sock->type == SOCK_SEQPACKET)
1042         sock->ops = &caif_seqpacket_ops;
1043     else if (sock->type == SOCK_STREAM)
1044         sock->ops = &caif_stream_ops;
1045     else
1046         return -ESOCKTNOSUPPORT;
1047 
1048     if (protocol < 0 || protocol >= CAIFPROTO_MAX)
1049         return -EPROTONOSUPPORT;
1050     /*
1051      * Set the socket state to unconnected.  The socket state
1052      * is really not used at all in the net/core or socket.c but the
1053      * initialization makes sure that sock->state is not uninitialized.
1054      */
1055     sk = sk_alloc(net, PF_CAIF, GFP_KERNEL, &prot, kern);
1056     if (!sk)
1057         return -ENOMEM;
1058 
1059     cf_sk = container_of(sk, struct caifsock, sk);
1060 
1061     /* Store the protocol */
1062     sk->sk_protocol = (unsigned char) protocol;
1063 
1064     /* Initialize default priority for well-known cases */
1065     switch (protocol) {
1066     case CAIFPROTO_AT:
1067         sk->sk_priority = TC_PRIO_CONTROL;
1068         break;
1069     case CAIFPROTO_RFM:
1070         sk->sk_priority = TC_PRIO_INTERACTIVE_BULK;
1071         break;
1072     default:
1073         sk->sk_priority = TC_PRIO_BESTEFFORT;
1074     }
1075 
1076     /*
1077      * Lock in order to try to stop someone from opening the socket
1078      * too early.
1079      */
1080     lock_sock(&(cf_sk->sk));
1081 
1082     /* Initialize the nozero default sock structure data. */
1083     sock_init_data(sock, sk);
1084     sk->sk_destruct = caif_sock_destructor;
1085 
1086     mutex_init(&cf_sk->readlock); /* single task reading lock */
1087     cf_sk->layer.ctrlcmd = caif_ctrl_cb;
1088     cf_sk->sk.sk_socket->state = SS_UNCONNECTED;
1089     cf_sk->sk.sk_state = CAIF_DISCONNECTED;
1090 
1091     set_tx_flow_off(cf_sk);
1092     set_rx_flow_on(cf_sk);
1093 
1094     /* Set default options on configuration */
1095     cf_sk->conn_req.link_selector = CAIF_LINK_LOW_LATENCY;
1096     cf_sk->conn_req.protocol = protocol;
1097     release_sock(&cf_sk->sk);
1098     return 0;
1099 }
1100 
1101 
1102 static const struct net_proto_family caif_family_ops = {
1103     .family = PF_CAIF,
1104     .create = caif_create,
1105     .owner = THIS_MODULE,
1106 };
1107 
1108 static int __init caif_sktinit_module(void)
1109 {
1110     return sock_register(&caif_family_ops);
1111 }
1112 
1113 static void __exit caif_sktexit_module(void)
1114 {
1115     sock_unregister(PF_CAIF);
1116 }
1117 module_init(caif_sktinit_module);
1118 module_exit(caif_sktexit_module);