Back to home page

OSCL-LXR

 
 

    


0001 // SPDX-License-Identifier: GPL-2.0-or-later
0002 /*
0003  *
0004  * Copyright (C) Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
0005  * Copyright (C) Alan Cox GW4PTS (alan@lxorguk.ukuu.org.uk)
0006  * Copyright (C) Terry Dawson VK2KTJ (terry@animats.net)
0007  * Copyright (C) Tomi Manninen OH2BNS (oh2bns@sral.fi)
0008  */
0009 
0010 #include <linux/capability.h>
0011 #include <linux/module.h>
0012 #include <linux/moduleparam.h>
0013 #include <linux/init.h>
0014 #include <linux/errno.h>
0015 #include <linux/types.h>
0016 #include <linux/socket.h>
0017 #include <linux/in.h>
0018 #include <linux/slab.h>
0019 #include <linux/kernel.h>
0020 #include <linux/sched/signal.h>
0021 #include <linux/spinlock.h>
0022 #include <linux/timer.h>
0023 #include <linux/string.h>
0024 #include <linux/sockios.h>
0025 #include <linux/net.h>
0026 #include <linux/stat.h>
0027 #include <net/net_namespace.h>
0028 #include <net/ax25.h>
0029 #include <linux/inet.h>
0030 #include <linux/netdevice.h>
0031 #include <linux/if_arp.h>
0032 #include <linux/skbuff.h>
0033 #include <net/sock.h>
0034 #include <linux/uaccess.h>
0035 #include <linux/fcntl.h>
0036 #include <linux/termios.h>
0037 #include <linux/mm.h>
0038 #include <linux/interrupt.h>
0039 #include <linux/notifier.h>
0040 #include <net/rose.h>
0041 #include <linux/proc_fs.h>
0042 #include <linux/seq_file.h>
0043 #include <net/tcp_states.h>
0044 #include <net/ip.h>
0045 #include <net/arp.h>
0046 
0047 static int rose_ndevs = 10;
0048 
0049 int sysctl_rose_restart_request_timeout = ROSE_DEFAULT_T0;
0050 int sysctl_rose_call_request_timeout    = ROSE_DEFAULT_T1;
0051 int sysctl_rose_reset_request_timeout   = ROSE_DEFAULT_T2;
0052 int sysctl_rose_clear_request_timeout   = ROSE_DEFAULT_T3;
0053 int sysctl_rose_no_activity_timeout     = ROSE_DEFAULT_IDLE;
0054 int sysctl_rose_ack_hold_back_timeout   = ROSE_DEFAULT_HB;
0055 int sysctl_rose_routing_control         = ROSE_DEFAULT_ROUTING;
0056 int sysctl_rose_link_fail_timeout       = ROSE_DEFAULT_FAIL_TIMEOUT;
0057 int sysctl_rose_maximum_vcs             = ROSE_DEFAULT_MAXVC;
0058 int sysctl_rose_window_size             = ROSE_DEFAULT_WINDOW_SIZE;
0059 
0060 static HLIST_HEAD(rose_list);
0061 static DEFINE_SPINLOCK(rose_list_lock);
0062 
0063 static const struct proto_ops rose_proto_ops;
0064 
0065 ax25_address rose_callsign;
0066 
0067 /*
0068  * ROSE network devices are virtual network devices encapsulating ROSE
0069  * frames into AX.25 which will be sent through an AX.25 device, so form a
0070  * special "super class" of normal net devices; split their locks off into a
0071  * separate class since they always nest.
0072  */
0073 static struct lock_class_key rose_netdev_xmit_lock_key;
0074 static struct lock_class_key rose_netdev_addr_lock_key;
0075 
0076 static void rose_set_lockdep_one(struct net_device *dev,
0077                  struct netdev_queue *txq,
0078                  void *_unused)
0079 {
0080     lockdep_set_class(&txq->_xmit_lock, &rose_netdev_xmit_lock_key);
0081 }
0082 
0083 static void rose_set_lockdep_key(struct net_device *dev)
0084 {
0085     lockdep_set_class(&dev->addr_list_lock, &rose_netdev_addr_lock_key);
0086     netdev_for_each_tx_queue(dev, rose_set_lockdep_one, NULL);
0087 }
0088 
0089 /*
0090  *  Convert a ROSE address into text.
0091  */
0092 char *rose2asc(char *buf, const rose_address *addr)
0093 {
0094     if (addr->rose_addr[0] == 0x00 && addr->rose_addr[1] == 0x00 &&
0095         addr->rose_addr[2] == 0x00 && addr->rose_addr[3] == 0x00 &&
0096         addr->rose_addr[4] == 0x00) {
0097         strcpy(buf, "*");
0098     } else {
0099         sprintf(buf, "%02X%02X%02X%02X%02X", addr->rose_addr[0] & 0xFF,
0100                         addr->rose_addr[1] & 0xFF,
0101                         addr->rose_addr[2] & 0xFF,
0102                         addr->rose_addr[3] & 0xFF,
0103                         addr->rose_addr[4] & 0xFF);
0104     }
0105 
0106     return buf;
0107 }
0108 
0109 /*
0110  *  Compare two ROSE addresses, 0 == equal.
0111  */
0112 int rosecmp(const rose_address *addr1, const rose_address *addr2)
0113 {
0114     int i;
0115 
0116     for (i = 0; i < 5; i++)
0117         if (addr1->rose_addr[i] != addr2->rose_addr[i])
0118             return 1;
0119 
0120     return 0;
0121 }
0122 
0123 /*
0124  *  Compare two ROSE addresses for only mask digits, 0 == equal.
0125  */
0126 int rosecmpm(const rose_address *addr1, const rose_address *addr2,
0127          unsigned short mask)
0128 {
0129     unsigned int i, j;
0130 
0131     if (mask > 10)
0132         return 1;
0133 
0134     for (i = 0; i < mask; i++) {
0135         j = i / 2;
0136 
0137         if ((i % 2) != 0) {
0138             if ((addr1->rose_addr[j] & 0x0F) != (addr2->rose_addr[j] & 0x0F))
0139                 return 1;
0140         } else {
0141             if ((addr1->rose_addr[j] & 0xF0) != (addr2->rose_addr[j] & 0xF0))
0142                 return 1;
0143         }
0144     }
0145 
0146     return 0;
0147 }
0148 
0149 /*
0150  *  Socket removal during an interrupt is now safe.
0151  */
0152 static void rose_remove_socket(struct sock *sk)
0153 {
0154     spin_lock_bh(&rose_list_lock);
0155     sk_del_node_init(sk);
0156     spin_unlock_bh(&rose_list_lock);
0157 }
0158 
0159 /*
0160  *  Kill all bound sockets on a broken link layer connection to a
0161  *  particular neighbour.
0162  */
0163 void rose_kill_by_neigh(struct rose_neigh *neigh)
0164 {
0165     struct sock *s;
0166 
0167     spin_lock_bh(&rose_list_lock);
0168     sk_for_each(s, &rose_list) {
0169         struct rose_sock *rose = rose_sk(s);
0170 
0171         if (rose->neighbour == neigh) {
0172             rose_disconnect(s, ENETUNREACH, ROSE_OUT_OF_ORDER, 0);
0173             rose->neighbour->use--;
0174             rose->neighbour = NULL;
0175         }
0176     }
0177     spin_unlock_bh(&rose_list_lock);
0178 }
0179 
0180 /*
0181  *  Kill all bound sockets on a dropped device.
0182  */
0183 static void rose_kill_by_device(struct net_device *dev)
0184 {
0185     struct sock *s;
0186 
0187     spin_lock_bh(&rose_list_lock);
0188     sk_for_each(s, &rose_list) {
0189         struct rose_sock *rose = rose_sk(s);
0190 
0191         if (rose->device == dev) {
0192             rose_disconnect(s, ENETUNREACH, ROSE_OUT_OF_ORDER, 0);
0193             if (rose->neighbour)
0194                 rose->neighbour->use--;
0195             netdev_put(rose->device, &rose->dev_tracker);
0196             rose->device = NULL;
0197         }
0198     }
0199     spin_unlock_bh(&rose_list_lock);
0200 }
0201 
0202 /*
0203  *  Handle device status changes.
0204  */
0205 static int rose_device_event(struct notifier_block *this,
0206                  unsigned long event, void *ptr)
0207 {
0208     struct net_device *dev = netdev_notifier_info_to_dev(ptr);
0209 
0210     if (!net_eq(dev_net(dev), &init_net))
0211         return NOTIFY_DONE;
0212 
0213     if (event != NETDEV_DOWN)
0214         return NOTIFY_DONE;
0215 
0216     switch (dev->type) {
0217     case ARPHRD_ROSE:
0218         rose_kill_by_device(dev);
0219         break;
0220     case ARPHRD_AX25:
0221         rose_link_device_down(dev);
0222         rose_rt_device_down(dev);
0223         break;
0224     }
0225 
0226     return NOTIFY_DONE;
0227 }
0228 
0229 /*
0230  *  Add a socket to the bound sockets list.
0231  */
0232 static void rose_insert_socket(struct sock *sk)
0233 {
0234 
0235     spin_lock_bh(&rose_list_lock);
0236     sk_add_node(sk, &rose_list);
0237     spin_unlock_bh(&rose_list_lock);
0238 }
0239 
0240 /*
0241  *  Find a socket that wants to accept the Call Request we just
0242  *  received.
0243  */
0244 static struct sock *rose_find_listener(rose_address *addr, ax25_address *call)
0245 {
0246     struct sock *s;
0247 
0248     spin_lock_bh(&rose_list_lock);
0249     sk_for_each(s, &rose_list) {
0250         struct rose_sock *rose = rose_sk(s);
0251 
0252         if (!rosecmp(&rose->source_addr, addr) &&
0253             !ax25cmp(&rose->source_call, call) &&
0254             !rose->source_ndigis && s->sk_state == TCP_LISTEN)
0255             goto found;
0256     }
0257 
0258     sk_for_each(s, &rose_list) {
0259         struct rose_sock *rose = rose_sk(s);
0260 
0261         if (!rosecmp(&rose->source_addr, addr) &&
0262             !ax25cmp(&rose->source_call, &null_ax25_address) &&
0263             s->sk_state == TCP_LISTEN)
0264             goto found;
0265     }
0266     s = NULL;
0267 found:
0268     spin_unlock_bh(&rose_list_lock);
0269     return s;
0270 }
0271 
0272 /*
0273  *  Find a connected ROSE socket given my LCI and device.
0274  */
0275 struct sock *rose_find_socket(unsigned int lci, struct rose_neigh *neigh)
0276 {
0277     struct sock *s;
0278 
0279     spin_lock_bh(&rose_list_lock);
0280     sk_for_each(s, &rose_list) {
0281         struct rose_sock *rose = rose_sk(s);
0282 
0283         if (rose->lci == lci && rose->neighbour == neigh)
0284             goto found;
0285     }
0286     s = NULL;
0287 found:
0288     spin_unlock_bh(&rose_list_lock);
0289     return s;
0290 }
0291 
0292 /*
0293  *  Find a unique LCI for a given device.
0294  */
0295 unsigned int rose_new_lci(struct rose_neigh *neigh)
0296 {
0297     int lci;
0298 
0299     if (neigh->dce_mode) {
0300         for (lci = 1; lci <= sysctl_rose_maximum_vcs; lci++)
0301             if (rose_find_socket(lci, neigh) == NULL && rose_route_free_lci(lci, neigh) == NULL)
0302                 return lci;
0303     } else {
0304         for (lci = sysctl_rose_maximum_vcs; lci > 0; lci--)
0305             if (rose_find_socket(lci, neigh) == NULL && rose_route_free_lci(lci, neigh) == NULL)
0306                 return lci;
0307     }
0308 
0309     return 0;
0310 }
0311 
0312 /*
0313  *  Deferred destroy.
0314  */
0315 void rose_destroy_socket(struct sock *);
0316 
0317 /*
0318  *  Handler for deferred kills.
0319  */
0320 static void rose_destroy_timer(struct timer_list *t)
0321 {
0322     struct sock *sk = from_timer(sk, t, sk_timer);
0323 
0324     rose_destroy_socket(sk);
0325 }
0326 
0327 /*
0328  *  This is called from user mode and the timers. Thus it protects itself
0329  *  against interrupt users but doesn't worry about being called during
0330  *  work.  Once it is removed from the queue no interrupt or bottom half
0331  *  will touch it and we are (fairly 8-) ) safe.
0332  */
0333 void rose_destroy_socket(struct sock *sk)
0334 {
0335     struct sk_buff *skb;
0336 
0337     rose_remove_socket(sk);
0338     rose_stop_heartbeat(sk);
0339     rose_stop_idletimer(sk);
0340     rose_stop_timer(sk);
0341 
0342     rose_clear_queues(sk);      /* Flush the queues */
0343 
0344     while ((skb = skb_dequeue(&sk->sk_receive_queue)) != NULL) {
0345         if (skb->sk != sk) {    /* A pending connection */
0346             /* Queue the unaccepted socket for death */
0347             sock_set_flag(skb->sk, SOCK_DEAD);
0348             rose_start_heartbeat(skb->sk);
0349             rose_sk(skb->sk)->state = ROSE_STATE_0;
0350         }
0351 
0352         kfree_skb(skb);
0353     }
0354 
0355     if (sk_has_allocations(sk)) {
0356         /* Defer: outstanding buffers */
0357         timer_setup(&sk->sk_timer, rose_destroy_timer, 0);
0358         sk->sk_timer.expires  = jiffies + 10 * HZ;
0359         add_timer(&sk->sk_timer);
0360     } else
0361         sock_put(sk);
0362 }
0363 
0364 /*
0365  *  Handling for system calls applied via the various interfaces to a
0366  *  ROSE socket object.
0367  */
0368 
0369 static int rose_setsockopt(struct socket *sock, int level, int optname,
0370         sockptr_t optval, unsigned int optlen)
0371 {
0372     struct sock *sk = sock->sk;
0373     struct rose_sock *rose = rose_sk(sk);
0374     int opt;
0375 
0376     if (level != SOL_ROSE)
0377         return -ENOPROTOOPT;
0378 
0379     if (optlen < sizeof(int))
0380         return -EINVAL;
0381 
0382     if (copy_from_sockptr(&opt, optval, sizeof(int)))
0383         return -EFAULT;
0384 
0385     switch (optname) {
0386     case ROSE_DEFER:
0387         rose->defer = opt ? 1 : 0;
0388         return 0;
0389 
0390     case ROSE_T1:
0391         if (opt < 1)
0392             return -EINVAL;
0393         rose->t1 = opt * HZ;
0394         return 0;
0395 
0396     case ROSE_T2:
0397         if (opt < 1)
0398             return -EINVAL;
0399         rose->t2 = opt * HZ;
0400         return 0;
0401 
0402     case ROSE_T3:
0403         if (opt < 1)
0404             return -EINVAL;
0405         rose->t3 = opt * HZ;
0406         return 0;
0407 
0408     case ROSE_HOLDBACK:
0409         if (opt < 1)
0410             return -EINVAL;
0411         rose->hb = opt * HZ;
0412         return 0;
0413 
0414     case ROSE_IDLE:
0415         if (opt < 0)
0416             return -EINVAL;
0417         rose->idle = opt * 60 * HZ;
0418         return 0;
0419 
0420     case ROSE_QBITINCL:
0421         rose->qbitincl = opt ? 1 : 0;
0422         return 0;
0423 
0424     default:
0425         return -ENOPROTOOPT;
0426     }
0427 }
0428 
0429 static int rose_getsockopt(struct socket *sock, int level, int optname,
0430     char __user *optval, int __user *optlen)
0431 {
0432     struct sock *sk = sock->sk;
0433     struct rose_sock *rose = rose_sk(sk);
0434     int val = 0;
0435     int len;
0436 
0437     if (level != SOL_ROSE)
0438         return -ENOPROTOOPT;
0439 
0440     if (get_user(len, optlen))
0441         return -EFAULT;
0442 
0443     if (len < 0)
0444         return -EINVAL;
0445 
0446     switch (optname) {
0447     case ROSE_DEFER:
0448         val = rose->defer;
0449         break;
0450 
0451     case ROSE_T1:
0452         val = rose->t1 / HZ;
0453         break;
0454 
0455     case ROSE_T2:
0456         val = rose->t2 / HZ;
0457         break;
0458 
0459     case ROSE_T3:
0460         val = rose->t3 / HZ;
0461         break;
0462 
0463     case ROSE_HOLDBACK:
0464         val = rose->hb / HZ;
0465         break;
0466 
0467     case ROSE_IDLE:
0468         val = rose->idle / (60 * HZ);
0469         break;
0470 
0471     case ROSE_QBITINCL:
0472         val = rose->qbitincl;
0473         break;
0474 
0475     default:
0476         return -ENOPROTOOPT;
0477     }
0478 
0479     len = min_t(unsigned int, len, sizeof(int));
0480 
0481     if (put_user(len, optlen))
0482         return -EFAULT;
0483 
0484     return copy_to_user(optval, &val, len) ? -EFAULT : 0;
0485 }
0486 
0487 static int rose_listen(struct socket *sock, int backlog)
0488 {
0489     struct sock *sk = sock->sk;
0490 
0491     if (sk->sk_state != TCP_LISTEN) {
0492         struct rose_sock *rose = rose_sk(sk);
0493 
0494         rose->dest_ndigis = 0;
0495         memset(&rose->dest_addr, 0, ROSE_ADDR_LEN);
0496         memset(&rose->dest_call, 0, AX25_ADDR_LEN);
0497         memset(rose->dest_digis, 0, AX25_ADDR_LEN * ROSE_MAX_DIGIS);
0498         sk->sk_max_ack_backlog = backlog;
0499         sk->sk_state           = TCP_LISTEN;
0500         return 0;
0501     }
0502 
0503     return -EOPNOTSUPP;
0504 }
0505 
0506 static struct proto rose_proto = {
0507     .name     = "ROSE",
0508     .owner    = THIS_MODULE,
0509     .obj_size = sizeof(struct rose_sock),
0510 };
0511 
0512 static int rose_create(struct net *net, struct socket *sock, int protocol,
0513                int kern)
0514 {
0515     struct sock *sk;
0516     struct rose_sock *rose;
0517 
0518     if (!net_eq(net, &init_net))
0519         return -EAFNOSUPPORT;
0520 
0521     if (sock->type != SOCK_SEQPACKET || protocol != 0)
0522         return -ESOCKTNOSUPPORT;
0523 
0524     sk = sk_alloc(net, PF_ROSE, GFP_ATOMIC, &rose_proto, kern);
0525     if (sk == NULL)
0526         return -ENOMEM;
0527 
0528     rose = rose_sk(sk);
0529 
0530     sock_init_data(sock, sk);
0531 
0532     skb_queue_head_init(&rose->ack_queue);
0533 #ifdef M_BIT
0534     skb_queue_head_init(&rose->frag_queue);
0535     rose->fraglen    = 0;
0536 #endif
0537 
0538     sock->ops    = &rose_proto_ops;
0539     sk->sk_protocol = protocol;
0540 
0541     timer_setup(&rose->timer, NULL, 0);
0542     timer_setup(&rose->idletimer, NULL, 0);
0543 
0544     rose->t1   = msecs_to_jiffies(sysctl_rose_call_request_timeout);
0545     rose->t2   = msecs_to_jiffies(sysctl_rose_reset_request_timeout);
0546     rose->t3   = msecs_to_jiffies(sysctl_rose_clear_request_timeout);
0547     rose->hb   = msecs_to_jiffies(sysctl_rose_ack_hold_back_timeout);
0548     rose->idle = msecs_to_jiffies(sysctl_rose_no_activity_timeout);
0549 
0550     rose->state = ROSE_STATE_0;
0551 
0552     return 0;
0553 }
0554 
0555 static struct sock *rose_make_new(struct sock *osk)
0556 {
0557     struct sock *sk;
0558     struct rose_sock *rose, *orose;
0559 
0560     if (osk->sk_type != SOCK_SEQPACKET)
0561         return NULL;
0562 
0563     sk = sk_alloc(sock_net(osk), PF_ROSE, GFP_ATOMIC, &rose_proto, 0);
0564     if (sk == NULL)
0565         return NULL;
0566 
0567     rose = rose_sk(sk);
0568 
0569     sock_init_data(NULL, sk);
0570 
0571     skb_queue_head_init(&rose->ack_queue);
0572 #ifdef M_BIT
0573     skb_queue_head_init(&rose->frag_queue);
0574     rose->fraglen  = 0;
0575 #endif
0576 
0577     sk->sk_type     = osk->sk_type;
0578     sk->sk_priority = osk->sk_priority;
0579     sk->sk_protocol = osk->sk_protocol;
0580     sk->sk_rcvbuf   = osk->sk_rcvbuf;
0581     sk->sk_sndbuf   = osk->sk_sndbuf;
0582     sk->sk_state    = TCP_ESTABLISHED;
0583     sock_copy_flags(sk, osk);
0584 
0585     timer_setup(&rose->timer, NULL, 0);
0586     timer_setup(&rose->idletimer, NULL, 0);
0587 
0588     orose       = rose_sk(osk);
0589     rose->t1    = orose->t1;
0590     rose->t2    = orose->t2;
0591     rose->t3    = orose->t3;
0592     rose->hb    = orose->hb;
0593     rose->idle  = orose->idle;
0594     rose->defer = orose->defer;
0595     rose->device    = orose->device;
0596     if (rose->device)
0597         netdev_hold(rose->device, &rose->dev_tracker, GFP_ATOMIC);
0598     rose->qbitincl  = orose->qbitincl;
0599 
0600     return sk;
0601 }
0602 
0603 static int rose_release(struct socket *sock)
0604 {
0605     struct sock *sk = sock->sk;
0606     struct rose_sock *rose;
0607 
0608     if (sk == NULL) return 0;
0609 
0610     sock_hold(sk);
0611     sock_orphan(sk);
0612     lock_sock(sk);
0613     rose = rose_sk(sk);
0614 
0615     switch (rose->state) {
0616     case ROSE_STATE_0:
0617         release_sock(sk);
0618         rose_disconnect(sk, 0, -1, -1);
0619         lock_sock(sk);
0620         rose_destroy_socket(sk);
0621         break;
0622 
0623     case ROSE_STATE_2:
0624         rose->neighbour->use--;
0625         release_sock(sk);
0626         rose_disconnect(sk, 0, -1, -1);
0627         lock_sock(sk);
0628         rose_destroy_socket(sk);
0629         break;
0630 
0631     case ROSE_STATE_1:
0632     case ROSE_STATE_3:
0633     case ROSE_STATE_4:
0634     case ROSE_STATE_5:
0635         rose_clear_queues(sk);
0636         rose_stop_idletimer(sk);
0637         rose_write_internal(sk, ROSE_CLEAR_REQUEST);
0638         rose_start_t3timer(sk);
0639         rose->state  = ROSE_STATE_2;
0640         sk->sk_state    = TCP_CLOSE;
0641         sk->sk_shutdown |= SEND_SHUTDOWN;
0642         sk->sk_state_change(sk);
0643         sock_set_flag(sk, SOCK_DEAD);
0644         sock_set_flag(sk, SOCK_DESTROY);
0645         break;
0646 
0647     default:
0648         break;
0649     }
0650 
0651     netdev_put(rose->device, &rose->dev_tracker);
0652     sock->sk = NULL;
0653     release_sock(sk);
0654     sock_put(sk);
0655 
0656     return 0;
0657 }
0658 
0659 static int rose_bind(struct socket *sock, struct sockaddr *uaddr, int addr_len)
0660 {
0661     struct sock *sk = sock->sk;
0662     struct rose_sock *rose = rose_sk(sk);
0663     struct sockaddr_rose *addr = (struct sockaddr_rose *)uaddr;
0664     struct net_device *dev;
0665     ax25_address *source;
0666     ax25_uid_assoc *user;
0667     int n;
0668 
0669     if (!sock_flag(sk, SOCK_ZAPPED))
0670         return -EINVAL;
0671 
0672     if (addr_len != sizeof(struct sockaddr_rose) && addr_len != sizeof(struct full_sockaddr_rose))
0673         return -EINVAL;
0674 
0675     if (addr->srose_family != AF_ROSE)
0676         return -EINVAL;
0677 
0678     if (addr_len == sizeof(struct sockaddr_rose) && addr->srose_ndigis > 1)
0679         return -EINVAL;
0680 
0681     if ((unsigned int) addr->srose_ndigis > ROSE_MAX_DIGIS)
0682         return -EINVAL;
0683 
0684     if ((dev = rose_dev_get(&addr->srose_addr)) == NULL)
0685         return -EADDRNOTAVAIL;
0686 
0687     source = &addr->srose_call;
0688 
0689     user = ax25_findbyuid(current_euid());
0690     if (user) {
0691         rose->source_call = user->call;
0692         ax25_uid_put(user);
0693     } else {
0694         if (ax25_uid_policy && !capable(CAP_NET_BIND_SERVICE)) {
0695             dev_put(dev);
0696             return -EACCES;
0697         }
0698         rose->source_call   = *source;
0699     }
0700 
0701     rose->source_addr   = addr->srose_addr;
0702     rose->device        = dev;
0703     netdev_tracker_alloc(rose->device, &rose->dev_tracker, GFP_KERNEL);
0704     rose->source_ndigis = addr->srose_ndigis;
0705 
0706     if (addr_len == sizeof(struct full_sockaddr_rose)) {
0707         struct full_sockaddr_rose *full_addr = (struct full_sockaddr_rose *)uaddr;
0708         for (n = 0 ; n < addr->srose_ndigis ; n++)
0709             rose->source_digis[n] = full_addr->srose_digis[n];
0710     } else {
0711         if (rose->source_ndigis == 1) {
0712             rose->source_digis[0] = addr->srose_digi;
0713         }
0714     }
0715 
0716     rose_insert_socket(sk);
0717 
0718     sock_reset_flag(sk, SOCK_ZAPPED);
0719 
0720     return 0;
0721 }
0722 
0723 static int rose_connect(struct socket *sock, struct sockaddr *uaddr, int addr_len, int flags)
0724 {
0725     struct sock *sk = sock->sk;
0726     struct rose_sock *rose = rose_sk(sk);
0727     struct sockaddr_rose *addr = (struct sockaddr_rose *)uaddr;
0728     unsigned char cause, diagnostic;
0729     ax25_uid_assoc *user;
0730     int n, err = 0;
0731 
0732     if (addr_len != sizeof(struct sockaddr_rose) && addr_len != sizeof(struct full_sockaddr_rose))
0733         return -EINVAL;
0734 
0735     if (addr->srose_family != AF_ROSE)
0736         return -EINVAL;
0737 
0738     if (addr_len == sizeof(struct sockaddr_rose) && addr->srose_ndigis > 1)
0739         return -EINVAL;
0740 
0741     if ((unsigned int) addr->srose_ndigis > ROSE_MAX_DIGIS)
0742         return -EINVAL;
0743 
0744     /* Source + Destination digis should not exceed ROSE_MAX_DIGIS */
0745     if ((rose->source_ndigis + addr->srose_ndigis) > ROSE_MAX_DIGIS)
0746         return -EINVAL;
0747 
0748     lock_sock(sk);
0749 
0750     if (sk->sk_state == TCP_ESTABLISHED && sock->state == SS_CONNECTING) {
0751         /* Connect completed during a ERESTARTSYS event */
0752         sock->state = SS_CONNECTED;
0753         goto out_release;
0754     }
0755 
0756     if (sk->sk_state == TCP_CLOSE && sock->state == SS_CONNECTING) {
0757         sock->state = SS_UNCONNECTED;
0758         err = -ECONNREFUSED;
0759         goto out_release;
0760     }
0761 
0762     if (sk->sk_state == TCP_ESTABLISHED) {
0763         /* No reconnect on a seqpacket socket */
0764         err = -EISCONN;
0765         goto out_release;
0766     }
0767 
0768     sk->sk_state   = TCP_CLOSE;
0769     sock->state = SS_UNCONNECTED;
0770 
0771     rose->neighbour = rose_get_neigh(&addr->srose_addr, &cause,
0772                      &diagnostic, 0);
0773     if (!rose->neighbour) {
0774         err = -ENETUNREACH;
0775         goto out_release;
0776     }
0777 
0778     rose->lci = rose_new_lci(rose->neighbour);
0779     if (!rose->lci) {
0780         err = -ENETUNREACH;
0781         goto out_release;
0782     }
0783 
0784     if (sock_flag(sk, SOCK_ZAPPED)) {   /* Must bind first - autobinding in this may or may not work */
0785         struct net_device *dev;
0786 
0787         sock_reset_flag(sk, SOCK_ZAPPED);
0788 
0789         dev = rose_dev_first();
0790         if (!dev) {
0791             err = -ENETUNREACH;
0792             goto out_release;
0793         }
0794 
0795         user = ax25_findbyuid(current_euid());
0796         if (!user) {
0797             err = -EINVAL;
0798             dev_put(dev);
0799             goto out_release;
0800         }
0801 
0802         memcpy(&rose->source_addr, dev->dev_addr, ROSE_ADDR_LEN);
0803         rose->source_call = user->call;
0804         rose->device      = dev;
0805         netdev_tracker_alloc(rose->device, &rose->dev_tracker,
0806                      GFP_KERNEL);
0807         ax25_uid_put(user);
0808 
0809         rose_insert_socket(sk);     /* Finish the bind */
0810     }
0811     rose->dest_addr   = addr->srose_addr;
0812     rose->dest_call   = addr->srose_call;
0813     rose->rand        = ((long)rose & 0xFFFF) + rose->lci;
0814     rose->dest_ndigis = addr->srose_ndigis;
0815 
0816     if (addr_len == sizeof(struct full_sockaddr_rose)) {
0817         struct full_sockaddr_rose *full_addr = (struct full_sockaddr_rose *)uaddr;
0818         for (n = 0 ; n < addr->srose_ndigis ; n++)
0819             rose->dest_digis[n] = full_addr->srose_digis[n];
0820     } else {
0821         if (rose->dest_ndigis == 1) {
0822             rose->dest_digis[0] = addr->srose_digi;
0823         }
0824     }
0825 
0826     /* Move to connecting socket, start sending Connect Requests */
0827     sock->state   = SS_CONNECTING;
0828     sk->sk_state     = TCP_SYN_SENT;
0829 
0830     rose->state = ROSE_STATE_1;
0831 
0832     rose->neighbour->use++;
0833 
0834     rose_write_internal(sk, ROSE_CALL_REQUEST);
0835     rose_start_heartbeat(sk);
0836     rose_start_t1timer(sk);
0837 
0838     /* Now the loop */
0839     if (sk->sk_state != TCP_ESTABLISHED && (flags & O_NONBLOCK)) {
0840         err = -EINPROGRESS;
0841         goto out_release;
0842     }
0843 
0844     /*
0845      * A Connect Ack with Choke or timeout or failed routing will go to
0846      * closed.
0847      */
0848     if (sk->sk_state == TCP_SYN_SENT) {
0849         DEFINE_WAIT(wait);
0850 
0851         for (;;) {
0852             prepare_to_wait(sk_sleep(sk), &wait,
0853                     TASK_INTERRUPTIBLE);
0854             if (sk->sk_state != TCP_SYN_SENT)
0855                 break;
0856             if (!signal_pending(current)) {
0857                 release_sock(sk);
0858                 schedule();
0859                 lock_sock(sk);
0860                 continue;
0861             }
0862             err = -ERESTARTSYS;
0863             break;
0864         }
0865         finish_wait(sk_sleep(sk), &wait);
0866 
0867         if (err)
0868             goto out_release;
0869     }
0870 
0871     if (sk->sk_state != TCP_ESTABLISHED) {
0872         sock->state = SS_UNCONNECTED;
0873         err = sock_error(sk);   /* Always set at this point */
0874         goto out_release;
0875     }
0876 
0877     sock->state = SS_CONNECTED;
0878 
0879 out_release:
0880     release_sock(sk);
0881 
0882     return err;
0883 }
0884 
0885 static int rose_accept(struct socket *sock, struct socket *newsock, int flags,
0886                bool kern)
0887 {
0888     struct sk_buff *skb;
0889     struct sock *newsk;
0890     DEFINE_WAIT(wait);
0891     struct sock *sk;
0892     int err = 0;
0893 
0894     if ((sk = sock->sk) == NULL)
0895         return -EINVAL;
0896 
0897     lock_sock(sk);
0898     if (sk->sk_type != SOCK_SEQPACKET) {
0899         err = -EOPNOTSUPP;
0900         goto out_release;
0901     }
0902 
0903     if (sk->sk_state != TCP_LISTEN) {
0904         err = -EINVAL;
0905         goto out_release;
0906     }
0907 
0908     /*
0909      *  The write queue this time is holding sockets ready to use
0910      *  hooked into the SABM we saved
0911      */
0912     for (;;) {
0913         prepare_to_wait(sk_sleep(sk), &wait, TASK_INTERRUPTIBLE);
0914 
0915         skb = skb_dequeue(&sk->sk_receive_queue);
0916         if (skb)
0917             break;
0918 
0919         if (flags & O_NONBLOCK) {
0920             err = -EWOULDBLOCK;
0921             break;
0922         }
0923         if (!signal_pending(current)) {
0924             release_sock(sk);
0925             schedule();
0926             lock_sock(sk);
0927             continue;
0928         }
0929         err = -ERESTARTSYS;
0930         break;
0931     }
0932     finish_wait(sk_sleep(sk), &wait);
0933     if (err)
0934         goto out_release;
0935 
0936     newsk = skb->sk;
0937     sock_graft(newsk, newsock);
0938 
0939     /* Now attach up the new socket */
0940     skb->sk = NULL;
0941     kfree_skb(skb);
0942     sk_acceptq_removed(sk);
0943 
0944 out_release:
0945     release_sock(sk);
0946 
0947     return err;
0948 }
0949 
0950 static int rose_getname(struct socket *sock, struct sockaddr *uaddr,
0951     int peer)
0952 {
0953     struct full_sockaddr_rose *srose = (struct full_sockaddr_rose *)uaddr;
0954     struct sock *sk = sock->sk;
0955     struct rose_sock *rose = rose_sk(sk);
0956     int n;
0957 
0958     memset(srose, 0, sizeof(*srose));
0959     if (peer != 0) {
0960         if (sk->sk_state != TCP_ESTABLISHED)
0961             return -ENOTCONN;
0962         srose->srose_family = AF_ROSE;
0963         srose->srose_addr   = rose->dest_addr;
0964         srose->srose_call   = rose->dest_call;
0965         srose->srose_ndigis = rose->dest_ndigis;
0966         for (n = 0; n < rose->dest_ndigis; n++)
0967             srose->srose_digis[n] = rose->dest_digis[n];
0968     } else {
0969         srose->srose_family = AF_ROSE;
0970         srose->srose_addr   = rose->source_addr;
0971         srose->srose_call   = rose->source_call;
0972         srose->srose_ndigis = rose->source_ndigis;
0973         for (n = 0; n < rose->source_ndigis; n++)
0974             srose->srose_digis[n] = rose->source_digis[n];
0975     }
0976 
0977     return sizeof(struct full_sockaddr_rose);
0978 }
0979 
0980 int rose_rx_call_request(struct sk_buff *skb, struct net_device *dev, struct rose_neigh *neigh, unsigned int lci)
0981 {
0982     struct sock *sk;
0983     struct sock *make;
0984     struct rose_sock *make_rose;
0985     struct rose_facilities_struct facilities;
0986     int n;
0987 
0988     skb->sk = NULL;     /* Initially we don't know who it's for */
0989 
0990     /*
0991      *  skb->data points to the rose frame start
0992      */
0993     memset(&facilities, 0x00, sizeof(struct rose_facilities_struct));
0994 
0995     if (!rose_parse_facilities(skb->data + ROSE_CALL_REQ_FACILITIES_OFF,
0996                    skb->len - ROSE_CALL_REQ_FACILITIES_OFF,
0997                    &facilities)) {
0998         rose_transmit_clear_request(neigh, lci, ROSE_INVALID_FACILITY, 76);
0999         return 0;
1000     }
1001 
1002     sk = rose_find_listener(&facilities.source_addr, &facilities.source_call);
1003 
1004     /*
1005      * We can't accept the Call Request.
1006      */
1007     if (sk == NULL || sk_acceptq_is_full(sk) ||
1008         (make = rose_make_new(sk)) == NULL) {
1009         rose_transmit_clear_request(neigh, lci, ROSE_NETWORK_CONGESTION, 120);
1010         return 0;
1011     }
1012 
1013     skb->sk     = make;
1014     make->sk_state = TCP_ESTABLISHED;
1015     make_rose = rose_sk(make);
1016 
1017     make_rose->lci           = lci;
1018     make_rose->dest_addr     = facilities.dest_addr;
1019     make_rose->dest_call     = facilities.dest_call;
1020     make_rose->dest_ndigis   = facilities.dest_ndigis;
1021     for (n = 0 ; n < facilities.dest_ndigis ; n++)
1022         make_rose->dest_digis[n] = facilities.dest_digis[n];
1023     make_rose->source_addr   = facilities.source_addr;
1024     make_rose->source_call   = facilities.source_call;
1025     make_rose->source_ndigis = facilities.source_ndigis;
1026     for (n = 0 ; n < facilities.source_ndigis ; n++)
1027         make_rose->source_digis[n] = facilities.source_digis[n];
1028     make_rose->neighbour     = neigh;
1029     make_rose->device        = dev;
1030     /* Caller got a reference for us. */
1031     netdev_tracker_alloc(make_rose->device, &make_rose->dev_tracker,
1032                  GFP_ATOMIC);
1033     make_rose->facilities    = facilities;
1034 
1035     make_rose->neighbour->use++;
1036 
1037     if (rose_sk(sk)->defer) {
1038         make_rose->state = ROSE_STATE_5;
1039     } else {
1040         rose_write_internal(make, ROSE_CALL_ACCEPTED);
1041         make_rose->state = ROSE_STATE_3;
1042         rose_start_idletimer(make);
1043     }
1044 
1045     make_rose->condition = 0x00;
1046     make_rose->vs        = 0;
1047     make_rose->va        = 0;
1048     make_rose->vr        = 0;
1049     make_rose->vl        = 0;
1050     sk_acceptq_added(sk);
1051 
1052     rose_insert_socket(make);
1053 
1054     skb_queue_head(&sk->sk_receive_queue, skb);
1055 
1056     rose_start_heartbeat(make);
1057 
1058     if (!sock_flag(sk, SOCK_DEAD))
1059         sk->sk_data_ready(sk);
1060 
1061     return 1;
1062 }
1063 
1064 static int rose_sendmsg(struct socket *sock, struct msghdr *msg, size_t len)
1065 {
1066     struct sock *sk = sock->sk;
1067     struct rose_sock *rose = rose_sk(sk);
1068     DECLARE_SOCKADDR(struct sockaddr_rose *, usrose, msg->msg_name);
1069     int err;
1070     struct full_sockaddr_rose srose;
1071     struct sk_buff *skb;
1072     unsigned char *asmptr;
1073     int n, size, qbit = 0;
1074 
1075     if (msg->msg_flags & ~(MSG_DONTWAIT|MSG_EOR|MSG_CMSG_COMPAT))
1076         return -EINVAL;
1077 
1078     if (sock_flag(sk, SOCK_ZAPPED))
1079         return -EADDRNOTAVAIL;
1080 
1081     if (sk->sk_shutdown & SEND_SHUTDOWN) {
1082         send_sig(SIGPIPE, current, 0);
1083         return -EPIPE;
1084     }
1085 
1086     if (rose->neighbour == NULL || rose->device == NULL)
1087         return -ENETUNREACH;
1088 
1089     if (usrose != NULL) {
1090         if (msg->msg_namelen != sizeof(struct sockaddr_rose) && msg->msg_namelen != sizeof(struct full_sockaddr_rose))
1091             return -EINVAL;
1092         memset(&srose, 0, sizeof(struct full_sockaddr_rose));
1093         memcpy(&srose, usrose, msg->msg_namelen);
1094         if (rosecmp(&rose->dest_addr, &srose.srose_addr) != 0 ||
1095             ax25cmp(&rose->dest_call, &srose.srose_call) != 0)
1096             return -EISCONN;
1097         if (srose.srose_ndigis != rose->dest_ndigis)
1098             return -EISCONN;
1099         if (srose.srose_ndigis == rose->dest_ndigis) {
1100             for (n = 0 ; n < srose.srose_ndigis ; n++)
1101                 if (ax25cmp(&rose->dest_digis[n],
1102                         &srose.srose_digis[n]))
1103                     return -EISCONN;
1104         }
1105         if (srose.srose_family != AF_ROSE)
1106             return -EINVAL;
1107     } else {
1108         if (sk->sk_state != TCP_ESTABLISHED)
1109             return -ENOTCONN;
1110 
1111         srose.srose_family = AF_ROSE;
1112         srose.srose_addr   = rose->dest_addr;
1113         srose.srose_call   = rose->dest_call;
1114         srose.srose_ndigis = rose->dest_ndigis;
1115         for (n = 0 ; n < rose->dest_ndigis ; n++)
1116             srose.srose_digis[n] = rose->dest_digis[n];
1117     }
1118 
1119     /* Build a packet */
1120     /* Sanity check the packet size */
1121     if (len > 65535)
1122         return -EMSGSIZE;
1123 
1124     size = len + AX25_BPQ_HEADER_LEN + AX25_MAX_HEADER_LEN + ROSE_MIN_LEN;
1125 
1126     if ((skb = sock_alloc_send_skb(sk, size, msg->msg_flags & MSG_DONTWAIT, &err)) == NULL)
1127         return err;
1128 
1129     skb_reserve(skb, AX25_BPQ_HEADER_LEN + AX25_MAX_HEADER_LEN + ROSE_MIN_LEN);
1130 
1131     /*
1132      *  Put the data on the end
1133      */
1134 
1135     skb_reset_transport_header(skb);
1136     skb_put(skb, len);
1137 
1138     err = memcpy_from_msg(skb_transport_header(skb), msg, len);
1139     if (err) {
1140         kfree_skb(skb);
1141         return err;
1142     }
1143 
1144     /*
1145      *  If the Q BIT Include socket option is in force, the first
1146      *  byte of the user data is the logical value of the Q Bit.
1147      */
1148     if (rose->qbitincl) {
1149         qbit = skb->data[0];
1150         skb_pull(skb, 1);
1151     }
1152 
1153     /*
1154      *  Push down the ROSE header
1155      */
1156     asmptr = skb_push(skb, ROSE_MIN_LEN);
1157 
1158     /* Build a ROSE Network header */
1159     asmptr[0] = ((rose->lci >> 8) & 0x0F) | ROSE_GFI;
1160     asmptr[1] = (rose->lci >> 0) & 0xFF;
1161     asmptr[2] = ROSE_DATA;
1162 
1163     if (qbit)
1164         asmptr[0] |= ROSE_Q_BIT;
1165 
1166     if (sk->sk_state != TCP_ESTABLISHED) {
1167         kfree_skb(skb);
1168         return -ENOTCONN;
1169     }
1170 
1171 #ifdef M_BIT
1172 #define ROSE_PACLEN (256-ROSE_MIN_LEN)
1173     if (skb->len - ROSE_MIN_LEN > ROSE_PACLEN) {
1174         unsigned char header[ROSE_MIN_LEN];
1175         struct sk_buff *skbn;
1176         int frontlen;
1177         int lg;
1178 
1179         /* Save a copy of the Header */
1180         skb_copy_from_linear_data(skb, header, ROSE_MIN_LEN);
1181         skb_pull(skb, ROSE_MIN_LEN);
1182 
1183         frontlen = skb_headroom(skb);
1184 
1185         while (skb->len > 0) {
1186             if ((skbn = sock_alloc_send_skb(sk, frontlen + ROSE_PACLEN, 0, &err)) == NULL) {
1187                 kfree_skb(skb);
1188                 return err;
1189             }
1190 
1191             skbn->sk   = sk;
1192             skbn->free = 1;
1193             skbn->arp  = 1;
1194 
1195             skb_reserve(skbn, frontlen);
1196 
1197             lg = (ROSE_PACLEN > skb->len) ? skb->len : ROSE_PACLEN;
1198 
1199             /* Copy the user data */
1200             skb_copy_from_linear_data(skb, skb_put(skbn, lg), lg);
1201             skb_pull(skb, lg);
1202 
1203             /* Duplicate the Header */
1204             skb_push(skbn, ROSE_MIN_LEN);
1205             skb_copy_to_linear_data(skbn, header, ROSE_MIN_LEN);
1206 
1207             if (skb->len > 0)
1208                 skbn->data[2] |= M_BIT;
1209 
1210             skb_queue_tail(&sk->sk_write_queue, skbn); /* Throw it on the queue */
1211         }
1212 
1213         skb->free = 1;
1214         kfree_skb(skb);
1215     } else {
1216         skb_queue_tail(&sk->sk_write_queue, skb);       /* Throw it on the queue */
1217     }
1218 #else
1219     skb_queue_tail(&sk->sk_write_queue, skb);   /* Shove it onto the queue */
1220 #endif
1221 
1222     rose_kick(sk);
1223 
1224     return len;
1225 }
1226 
1227 
1228 static int rose_recvmsg(struct socket *sock, struct msghdr *msg, size_t size,
1229             int flags)
1230 {
1231     struct sock *sk = sock->sk;
1232     struct rose_sock *rose = rose_sk(sk);
1233     size_t copied;
1234     unsigned char *asmptr;
1235     struct sk_buff *skb;
1236     int n, er, qbit;
1237 
1238     /*
1239      * This works for seqpacket too. The receiver has ordered the queue for
1240      * us! We do one quick check first though
1241      */
1242     if (sk->sk_state != TCP_ESTABLISHED)
1243         return -ENOTCONN;
1244 
1245     /* Now we can treat all alike */
1246     skb = skb_recv_datagram(sk, flags, &er);
1247     if (!skb)
1248         return er;
1249 
1250     qbit = (skb->data[0] & ROSE_Q_BIT) == ROSE_Q_BIT;
1251 
1252     skb_pull(skb, ROSE_MIN_LEN);
1253 
1254     if (rose->qbitincl) {
1255         asmptr  = skb_push(skb, 1);
1256         *asmptr = qbit;
1257     }
1258 
1259     skb_reset_transport_header(skb);
1260     copied     = skb->len;
1261 
1262     if (copied > size) {
1263         copied = size;
1264         msg->msg_flags |= MSG_TRUNC;
1265     }
1266 
1267     skb_copy_datagram_msg(skb, 0, msg, copied);
1268 
1269     if (msg->msg_name) {
1270         struct sockaddr_rose *srose;
1271         DECLARE_SOCKADDR(struct full_sockaddr_rose *, full_srose,
1272                  msg->msg_name);
1273 
1274         memset(msg->msg_name, 0, sizeof(struct full_sockaddr_rose));
1275         srose = msg->msg_name;
1276         srose->srose_family = AF_ROSE;
1277         srose->srose_addr   = rose->dest_addr;
1278         srose->srose_call   = rose->dest_call;
1279         srose->srose_ndigis = rose->dest_ndigis;
1280         for (n = 0 ; n < rose->dest_ndigis ; n++)
1281             full_srose->srose_digis[n] = rose->dest_digis[n];
1282         msg->msg_namelen = sizeof(struct full_sockaddr_rose);
1283     }
1284 
1285     skb_free_datagram(sk, skb);
1286 
1287     return copied;
1288 }
1289 
1290 
1291 static int rose_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
1292 {
1293     struct sock *sk = sock->sk;
1294     struct rose_sock *rose = rose_sk(sk);
1295     void __user *argp = (void __user *)arg;
1296 
1297     switch (cmd) {
1298     case TIOCOUTQ: {
1299         long amount;
1300 
1301         amount = sk->sk_sndbuf - sk_wmem_alloc_get(sk);
1302         if (amount < 0)
1303             amount = 0;
1304         return put_user(amount, (unsigned int __user *) argp);
1305     }
1306 
1307     case TIOCINQ: {
1308         struct sk_buff *skb;
1309         long amount = 0L;
1310         /* These two are safe on a single CPU system as only user tasks fiddle here */
1311         if ((skb = skb_peek(&sk->sk_receive_queue)) != NULL)
1312             amount = skb->len;
1313         return put_user(amount, (unsigned int __user *) argp);
1314     }
1315 
1316     case SIOCGIFADDR:
1317     case SIOCSIFADDR:
1318     case SIOCGIFDSTADDR:
1319     case SIOCSIFDSTADDR:
1320     case SIOCGIFBRDADDR:
1321     case SIOCSIFBRDADDR:
1322     case SIOCGIFNETMASK:
1323     case SIOCSIFNETMASK:
1324     case SIOCGIFMETRIC:
1325     case SIOCSIFMETRIC:
1326         return -EINVAL;
1327 
1328     case SIOCADDRT:
1329     case SIOCDELRT:
1330     case SIOCRSCLRRT:
1331         if (!capable(CAP_NET_ADMIN))
1332             return -EPERM;
1333         return rose_rt_ioctl(cmd, argp);
1334 
1335     case SIOCRSGCAUSE: {
1336         struct rose_cause_struct rose_cause;
1337         rose_cause.cause      = rose->cause;
1338         rose_cause.diagnostic = rose->diagnostic;
1339         return copy_to_user(argp, &rose_cause, sizeof(struct rose_cause_struct)) ? -EFAULT : 0;
1340     }
1341 
1342     case SIOCRSSCAUSE: {
1343         struct rose_cause_struct rose_cause;
1344         if (copy_from_user(&rose_cause, argp, sizeof(struct rose_cause_struct)))
1345             return -EFAULT;
1346         rose->cause      = rose_cause.cause;
1347         rose->diagnostic = rose_cause.diagnostic;
1348         return 0;
1349     }
1350 
1351     case SIOCRSSL2CALL:
1352         if (!capable(CAP_NET_ADMIN)) return -EPERM;
1353         if (ax25cmp(&rose_callsign, &null_ax25_address) != 0)
1354             ax25_listen_release(&rose_callsign, NULL);
1355         if (copy_from_user(&rose_callsign, argp, sizeof(ax25_address)))
1356             return -EFAULT;
1357         if (ax25cmp(&rose_callsign, &null_ax25_address) != 0)
1358             return ax25_listen_register(&rose_callsign, NULL);
1359 
1360         return 0;
1361 
1362     case SIOCRSGL2CALL:
1363         return copy_to_user(argp, &rose_callsign, sizeof(ax25_address)) ? -EFAULT : 0;
1364 
1365     case SIOCRSACCEPT:
1366         if (rose->state == ROSE_STATE_5) {
1367             rose_write_internal(sk, ROSE_CALL_ACCEPTED);
1368             rose_start_idletimer(sk);
1369             rose->condition = 0x00;
1370             rose->vs        = 0;
1371             rose->va        = 0;
1372             rose->vr        = 0;
1373             rose->vl        = 0;
1374             rose->state     = ROSE_STATE_3;
1375         }
1376         return 0;
1377 
1378     default:
1379         return -ENOIOCTLCMD;
1380     }
1381 
1382     return 0;
1383 }
1384 
1385 #ifdef CONFIG_PROC_FS
1386 static void *rose_info_start(struct seq_file *seq, loff_t *pos)
1387     __acquires(rose_list_lock)
1388 {
1389     spin_lock_bh(&rose_list_lock);
1390     return seq_hlist_start_head(&rose_list, *pos);
1391 }
1392 
1393 static void *rose_info_next(struct seq_file *seq, void *v, loff_t *pos)
1394 {
1395     return seq_hlist_next(v, &rose_list, pos);
1396 }
1397 
1398 static void rose_info_stop(struct seq_file *seq, void *v)
1399     __releases(rose_list_lock)
1400 {
1401     spin_unlock_bh(&rose_list_lock);
1402 }
1403 
1404 static int rose_info_show(struct seq_file *seq, void *v)
1405 {
1406     char buf[11], rsbuf[11];
1407 
1408     if (v == SEQ_START_TOKEN)
1409         seq_puts(seq,
1410              "dest_addr  dest_call src_addr   src_call  dev   lci neigh st vs vr va   t  t1  t2  t3  hb    idle Snd-Q Rcv-Q inode\n");
1411 
1412     else {
1413         struct sock *s = sk_entry(v);
1414         struct rose_sock *rose = rose_sk(s);
1415         const char *devname, *callsign;
1416         const struct net_device *dev = rose->device;
1417 
1418         if (!dev)
1419             devname = "???";
1420         else
1421             devname = dev->name;
1422 
1423         seq_printf(seq, "%-10s %-9s ",
1424                rose2asc(rsbuf, &rose->dest_addr),
1425                ax2asc(buf, &rose->dest_call));
1426 
1427         if (ax25cmp(&rose->source_call, &null_ax25_address) == 0)
1428             callsign = "??????-?";
1429         else
1430             callsign = ax2asc(buf, &rose->source_call);
1431 
1432         seq_printf(seq,
1433                "%-10s %-9s %-5s %3.3X %05d  %d  %d  %d  %d %3lu %3lu %3lu %3lu %3lu %3lu/%03lu %5d %5d %ld\n",
1434             rose2asc(rsbuf, &rose->source_addr),
1435             callsign,
1436             devname,
1437             rose->lci & 0x0FFF,
1438             (rose->neighbour) ? rose->neighbour->number : 0,
1439             rose->state,
1440             rose->vs,
1441             rose->vr,
1442             rose->va,
1443             ax25_display_timer(&rose->timer) / HZ,
1444             rose->t1 / HZ,
1445             rose->t2 / HZ,
1446             rose->t3 / HZ,
1447             rose->hb / HZ,
1448             ax25_display_timer(&rose->idletimer) / (60 * HZ),
1449             rose->idle / (60 * HZ),
1450             sk_wmem_alloc_get(s),
1451             sk_rmem_alloc_get(s),
1452             s->sk_socket ? SOCK_INODE(s->sk_socket)->i_ino : 0L);
1453     }
1454 
1455     return 0;
1456 }
1457 
1458 static const struct seq_operations rose_info_seqops = {
1459     .start = rose_info_start,
1460     .next = rose_info_next,
1461     .stop = rose_info_stop,
1462     .show = rose_info_show,
1463 };
1464 #endif  /* CONFIG_PROC_FS */
1465 
1466 static const struct net_proto_family rose_family_ops = {
1467     .family     =   PF_ROSE,
1468     .create     =   rose_create,
1469     .owner      =   THIS_MODULE,
1470 };
1471 
1472 static const struct proto_ops rose_proto_ops = {
1473     .family     =   PF_ROSE,
1474     .owner      =   THIS_MODULE,
1475     .release    =   rose_release,
1476     .bind       =   rose_bind,
1477     .connect    =   rose_connect,
1478     .socketpair =   sock_no_socketpair,
1479     .accept     =   rose_accept,
1480     .getname    =   rose_getname,
1481     .poll       =   datagram_poll,
1482     .ioctl      =   rose_ioctl,
1483     .gettstamp  =   sock_gettstamp,
1484     .listen     =   rose_listen,
1485     .shutdown   =   sock_no_shutdown,
1486     .setsockopt =   rose_setsockopt,
1487     .getsockopt =   rose_getsockopt,
1488     .sendmsg    =   rose_sendmsg,
1489     .recvmsg    =   rose_recvmsg,
1490     .mmap       =   sock_no_mmap,
1491     .sendpage   =   sock_no_sendpage,
1492 };
1493 
1494 static struct notifier_block rose_dev_notifier = {
1495     .notifier_call  =   rose_device_event,
1496 };
1497 
1498 static struct net_device **dev_rose;
1499 
1500 static struct ax25_protocol rose_pid = {
1501     .pid    = AX25_P_ROSE,
1502     .func   = rose_route_frame
1503 };
1504 
1505 static struct ax25_linkfail rose_linkfail_notifier = {
1506     .func   = rose_link_failed
1507 };
1508 
1509 static int __init rose_proto_init(void)
1510 {
1511     int i;
1512     int rc;
1513 
1514     if (rose_ndevs > 0x7FFFFFFF/sizeof(struct net_device *)) {
1515         printk(KERN_ERR "ROSE: rose_proto_init - rose_ndevs parameter too large\n");
1516         rc = -EINVAL;
1517         goto out;
1518     }
1519 
1520     rc = proto_register(&rose_proto, 0);
1521     if (rc != 0)
1522         goto out;
1523 
1524     rose_callsign = null_ax25_address;
1525 
1526     dev_rose = kcalloc(rose_ndevs, sizeof(struct net_device *),
1527                GFP_KERNEL);
1528     if (dev_rose == NULL) {
1529         printk(KERN_ERR "ROSE: rose_proto_init - unable to allocate device structure\n");
1530         rc = -ENOMEM;
1531         goto out_proto_unregister;
1532     }
1533 
1534     for (i = 0; i < rose_ndevs; i++) {
1535         struct net_device *dev;
1536         char name[IFNAMSIZ];
1537 
1538         sprintf(name, "rose%d", i);
1539         dev = alloc_netdev(0, name, NET_NAME_UNKNOWN, rose_setup);
1540         if (!dev) {
1541             printk(KERN_ERR "ROSE: rose_proto_init - unable to allocate memory\n");
1542             rc = -ENOMEM;
1543             goto fail;
1544         }
1545         rc = register_netdev(dev);
1546         if (rc) {
1547             printk(KERN_ERR "ROSE: netdevice registration failed\n");
1548             free_netdev(dev);
1549             goto fail;
1550         }
1551         rose_set_lockdep_key(dev);
1552         dev_rose[i] = dev;
1553     }
1554 
1555     sock_register(&rose_family_ops);
1556     register_netdevice_notifier(&rose_dev_notifier);
1557 
1558     ax25_register_pid(&rose_pid);
1559     ax25_linkfail_register(&rose_linkfail_notifier);
1560 
1561 #ifdef CONFIG_SYSCTL
1562     rose_register_sysctl();
1563 #endif
1564     rose_loopback_init();
1565 
1566     rose_add_loopback_neigh();
1567 
1568     proc_create_seq("rose", 0444, init_net.proc_net, &rose_info_seqops);
1569     proc_create_seq("rose_neigh", 0444, init_net.proc_net,
1570             &rose_neigh_seqops);
1571     proc_create_seq("rose_nodes", 0444, init_net.proc_net,
1572             &rose_node_seqops);
1573     proc_create_seq("rose_routes", 0444, init_net.proc_net,
1574             &rose_route_seqops);
1575 out:
1576     return rc;
1577 fail:
1578     while (--i >= 0) {
1579         unregister_netdev(dev_rose[i]);
1580         free_netdev(dev_rose[i]);
1581     }
1582     kfree(dev_rose);
1583 out_proto_unregister:
1584     proto_unregister(&rose_proto);
1585     goto out;
1586 }
1587 module_init(rose_proto_init);
1588 
1589 module_param(rose_ndevs, int, 0);
1590 MODULE_PARM_DESC(rose_ndevs, "number of ROSE devices");
1591 
1592 MODULE_AUTHOR("Jonathan Naylor G4KLX <g4klx@g4klx.demon.co.uk>");
1593 MODULE_DESCRIPTION("The amateur radio ROSE network layer protocol");
1594 MODULE_LICENSE("GPL");
1595 MODULE_ALIAS_NETPROTO(PF_ROSE);
1596 
1597 static void __exit rose_exit(void)
1598 {
1599     int i;
1600 
1601     remove_proc_entry("rose", init_net.proc_net);
1602     remove_proc_entry("rose_neigh", init_net.proc_net);
1603     remove_proc_entry("rose_nodes", init_net.proc_net);
1604     remove_proc_entry("rose_routes", init_net.proc_net);
1605     rose_loopback_clear();
1606 
1607     rose_rt_free();
1608 
1609     ax25_protocol_release(AX25_P_ROSE);
1610     ax25_linkfail_release(&rose_linkfail_notifier);
1611 
1612     if (ax25cmp(&rose_callsign, &null_ax25_address) != 0)
1613         ax25_listen_release(&rose_callsign, NULL);
1614 
1615 #ifdef CONFIG_SYSCTL
1616     rose_unregister_sysctl();
1617 #endif
1618     unregister_netdevice_notifier(&rose_dev_notifier);
1619 
1620     sock_unregister(PF_ROSE);
1621 
1622     for (i = 0; i < rose_ndevs; i++) {
1623         struct net_device *dev = dev_rose[i];
1624 
1625         if (dev) {
1626             unregister_netdev(dev);
1627             free_netdev(dev);
1628         }
1629     }
1630 
1631     kfree(dev_rose);
1632     proto_unregister(&rose_proto);
1633 }
1634 
1635 module_exit(rose_exit);