blob: cc0405c79dfc0941eabe8b43873c5ff35210cb0b [file] [log] [blame]
Thomas Gleixner47505b82019-05-23 11:14:41 +02001// SPDX-License-Identifier: GPL-2.0-or-later
Vlad Yasevich60c778b2008-01-11 09:57:09 -05002/* SCTP kernel implementation
Linus Torvalds1da177e2005-04-16 15:20:36 -07003 * (C) Copyright IBM Corp. 2003, 2004
4 *
Vlad Yasevich60c778b2008-01-11 09:57:09 -05005 * This file is part of the SCTP kernel implementation
Linus Torvalds1da177e2005-04-16 15:20:36 -07006 *
Michael Opdenacker59c51592007-05-09 08:57:56 +02007 * This file contains the code relating the chunk abstraction.
Linus Torvalds1da177e2005-04-16 15:20:36 -07008 *
Linus Torvalds1da177e2005-04-16 15:20:36 -07009 * Please send any bug reports or fixes you make to the
10 * email address(es):
Daniel Borkmann91705c62013-07-23 14:51:47 +020011 * lksctp developers <linux-sctp@vger.kernel.org>
Linus Torvalds1da177e2005-04-16 15:20:36 -070012 *
Linus Torvalds1da177e2005-04-16 15:20:36 -070013 * Written or modified by:
14 * Jon Grimm <jgrimm@us.ibm.com>
15 * Sridhar Samudrala <sri@us.ibm.com>
Linus Torvalds1da177e2005-04-16 15:20:36 -070016 */
17
Joe Perches145ce502010-08-24 13:21:08 +000018#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
19
Linus Torvalds1da177e2005-04-16 15:20:36 -070020#include <linux/types.h>
21#include <linux/kernel.h>
22#include <linux/net.h>
23#include <linux/inet.h>
24#include <linux/skbuff.h>
Tejun Heo5a0e3ad2010-03-24 17:04:11 +090025#include <linux/slab.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070026#include <net/sock.h>
27#include <net/sctp/sctp.h>
28#include <net/sctp/sm.h>
29
30/* This file is mostly in anticipation of future work, but initially
31 * populate with fragment tracking for an outbound message.
32 */
33
34/* Initialize datamsg from memory. */
35static void sctp_datamsg_init(struct sctp_datamsg *msg)
36{
Reshetova, Elenac0acdfb2017-07-04 15:53:25 +030037 refcount_set(&msg->refcnt, 1);
Linus Torvalds1da177e2005-04-16 15:20:36 -070038 msg->send_failed = 0;
39 msg->send_error = 0;
Vlad Yasevich0e3aef82010-04-30 22:41:10 -040040 msg->can_delay = 1;
Xin Longe5f61292017-11-25 21:18:35 +080041 msg->abandoned = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -070042 msg->expires_at = 0;
43 INIT_LIST_HEAD(&msg->chunks);
44}
45
46/* Allocate and initialize datamsg. */
Daniel Borkmanndda91922013-06-17 11:40:05 +020047static struct sctp_datamsg *sctp_datamsg_new(gfp_t gfp)
Linus Torvalds1da177e2005-04-16 15:20:36 -070048{
49 struct sctp_datamsg *msg;
50 msg = kmalloc(sizeof(struct sctp_datamsg), gfp);
Li Zefane8c38752008-04-10 01:57:24 -070051 if (msg) {
Linus Torvalds1da177e2005-04-16 15:20:36 -070052 sctp_datamsg_init(msg);
Li Zefane8c38752008-04-10 01:57:24 -070053 SCTP_DBG_OBJCNT_INC(datamsg);
54 }
Linus Torvalds1da177e2005-04-16 15:20:36 -070055 return msg;
56}
57
Xin Longb61c6542016-09-14 02:04:20 +080058void sctp_datamsg_free(struct sctp_datamsg *msg)
59{
60 struct sctp_chunk *chunk;
61
62 /* This doesn't have to be a _safe vairant because
63 * sctp_chunk_free() only drops the refs.
64 */
65 list_for_each_entry(chunk, &msg->chunks, frag_list)
66 sctp_chunk_free(chunk);
67
68 sctp_datamsg_put(msg);
69}
70
Linus Torvalds1da177e2005-04-16 15:20:36 -070071/* Final destructruction of datamsg memory. */
72static void sctp_datamsg_destroy(struct sctp_datamsg *msg)
73{
Xin Longa1e3a052018-11-18 16:08:52 +080074 struct sctp_association *asoc = NULL;
Linus Torvalds1da177e2005-04-16 15:20:36 -070075 struct list_head *pos, *temp;
76 struct sctp_chunk *chunk;
Linus Torvalds1da177e2005-04-16 15:20:36 -070077 struct sctp_ulpevent *ev;
Linus Torvalds1da177e2005-04-16 15:20:36 -070078 int error = 0, notify;
79
80 /* If we failed, we may need to notify. */
81 notify = msg->send_failed ? -1 : 0;
82
83 /* Release all references. */
84 list_for_each_safe(pos, temp, &msg->chunks) {
85 list_del_init(pos);
86 chunk = list_entry(pos, struct sctp_chunk, frag_list);
87 /* Check whether we _really_ need to notify. */
88 if (notify < 0) {
89 asoc = chunk->asoc;
90 if (msg->send_error)
91 error = msg->send_error;
92 else
93 error = asoc->outqueue.error;
94
Xin Longa1e3a052018-11-18 16:08:52 +080095 notify = sctp_ulpevent_type_enabled(asoc->subscribe,
Xin Long2cc0eeb2018-11-18 16:08:51 +080096 SCTP_SEND_FAILED);
Linus Torvalds1da177e2005-04-16 15:20:36 -070097 }
98
99 /* Generate a SEND FAILED event only if enabled. */
100 if (notify > 0) {
101 int sent;
102 if (chunk->has_tsn)
103 sent = SCTP_DATA_SENT;
104 else
105 sent = SCTP_DATA_UNSENT;
106
107 ev = sctp_ulpevent_make_send_failed(asoc, chunk, sent,
108 error, GFP_ATOMIC);
109 if (ev)
Xin Long9162e0e2017-12-08 21:04:05 +0800110 asoc->stream.si->enqueue_event(&asoc->ulpq, ev);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700111 }
112
113 sctp_chunk_put(chunk);
114 }
115
116 SCTP_DBG_OBJCNT_DEC(datamsg);
117 kfree(msg);
118}
119
120/* Hold a reference. */
121static void sctp_datamsg_hold(struct sctp_datamsg *msg)
122{
Reshetova, Elenac0acdfb2017-07-04 15:53:25 +0300123 refcount_inc(&msg->refcnt);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700124}
125
126/* Release a reference. */
127void sctp_datamsg_put(struct sctp_datamsg *msg)
128{
Reshetova, Elenac0acdfb2017-07-04 15:53:25 +0300129 if (refcount_dec_and_test(&msg->refcnt))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700130 sctp_datamsg_destroy(msg);
131}
132
Linus Torvalds1da177e2005-04-16 15:20:36 -0700133/* Assign a chunk to this datamsg. */
134static void sctp_datamsg_assign(struct sctp_datamsg *msg, struct sctp_chunk *chunk)
135{
136 sctp_datamsg_hold(msg);
137 chunk->msg = msg;
138}
139
140
141/* A data chunk can have a maximum payload of (2^16 - 20). Break
142 * down any such message into smaller chunks. Opportunistically, fragment
143 * the chunks down to the current MTU constraints. We may get refragmented
144 * later if the PMTU changes, but it is _much better_ to fragment immediately
145 * with a reasonable guess than always doing our fragmentation on the
146 * soft-interrupt.
147 */
148struct sctp_datamsg *sctp_datamsg_from_user(struct sctp_association *asoc,
149 struct sctp_sndrcvinfo *sinfo,
Al Viroe0eb0932014-11-15 01:11:23 -0500150 struct iov_iter *from)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700151{
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200152 size_t len, first_len, max_data, remaining;
153 size_t msg_len = iov_iter_count(from);
Xin Long1b1e0bc2018-03-14 19:05:30 +0800154 struct sctp_shared_key *shkey = NULL;
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200155 struct list_head *pos, *temp;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700156 struct sctp_chunk *chunk;
157 struct sctp_datamsg *msg;
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200158 int err;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700159
160 msg = sctp_datamsg_new(GFP_KERNEL);
161 if (!msg)
Tommi Rantala6e51fe72012-11-22 03:23:16 +0000162 return ERR_PTR(-ENOMEM);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700163
164 /* Note: Calculate this outside of the loop, so that all fragments
165 * have the same expiration.
166 */
Xin Long8ae808e2016-10-08 11:40:16 +0800167 if (asoc->peer.prsctp_capable && sinfo->sinfo_timetolive &&
168 (SCTP_PR_TTL_ENABLED(sinfo->sinfo_flags) ||
169 !SCTP_PR_POLICY(sinfo->sinfo_flags)))
Linus Torvalds1da177e2005-04-16 15:20:36 -0700170 msg->expires_at = jiffies +
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200171 msecs_to_jiffies(sinfo->sinfo_timetolive);
Xin Long06054832016-09-29 02:37:27 +0800172
Vlad Yasevich3e62abf2009-09-04 18:20:56 -0400173 /* This is the biggest possible DATA chunk that can fit into
174 * the packet
175 */
Marcelo Ricardo Leitner2f5e3c92018-04-26 16:58:55 -0300176 max_data = asoc->frag_point;
Jakub Audykowiczafd0a802018-12-04 20:27:41 +0100177 if (unlikely(!max_data)) {
178 max_data = sctp_min_frag_point(sctp_sk(asoc->base.sk),
179 sctp_datachk_len(&asoc->stream));
Matthias Maennichac510502019-02-28 11:36:52 +0000180 pr_warn_ratelimited("%s: asoc:%p frag_point is zero, forcing max_data to default minimum (%zu)",
Jakub Audykowiczafd0a802018-12-04 20:27:41 +0100181 __func__, asoc, max_data);
182 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700183
Vlad Yasevich4cd57c82007-09-16 19:32:45 -0700184 /* If the the peer requested that we authenticate DATA chunks
wangweidong2bccbad2013-10-26 16:06:30 +0800185 * we need to account for bundling of the AUTH chunks along with
Vlad Yasevich4cd57c82007-09-16 19:32:45 -0700186 * DATA.
187 */
188 if (sctp_auth_send_cid(SCTP_CID_DATA, asoc)) {
189 struct sctp_hmac *hmac_desc = sctp_auth_asoc_get_hmac(asoc);
190
191 if (hmac_desc)
Xin Longbb96dec2017-08-03 15:42:22 +0800192 max_data -= SCTP_PAD4(sizeof(struct sctp_auth_chunk) +
Marcelo Ricardo Leitnere2f036a2016-09-21 08:45:55 -0300193 hmac_desc->hmac_len);
Xin Long1b1e0bc2018-03-14 19:05:30 +0800194
Xin Long3ff547c2018-03-14 19:05:31 +0800195 if (sinfo->sinfo_tsn &&
196 sinfo->sinfo_ssn != asoc->active_key_id) {
197 shkey = sctp_auth_get_shkey(asoc, sinfo->sinfo_ssn);
198 if (!shkey) {
199 err = -EINVAL;
200 goto errout;
201 }
202 } else {
203 shkey = asoc->shkey;
204 }
Vlad Yasevich4cd57c82007-09-16 19:32:45 -0700205 }
206
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200207 /* Set first_len and then account for possible bundles on first frag */
208 first_len = max_data;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700209
Vlad Yasevich5d7ff262009-08-07 13:23:28 -0400210 /* Check to see if we have a pending SACK and try to let it be bundled
211 * with this message. Do this if we don't have any data queued already.
212 * To check that, look at out_qlen and retransmit list.
213 * NOTE: we will not reduce to account for SACK, if the message would
214 * not have been fragmented.
215 */
216 if (timer_pending(&asoc->timers[SCTP_EVENT_TIMEOUT_SACK]) &&
217 asoc->outqueue.out_qlen == 0 &&
218 list_empty(&asoc->outqueue.retransmit) &&
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200219 msg_len > max_data)
Xin Longd4d6c612017-07-23 09:34:33 +0800220 first_len -= SCTP_PAD4(sizeof(struct sctp_sack_chunk));
Vlad Yasevich5d7ff262009-08-07 13:23:28 -0400221
Linus Torvalds1da177e2005-04-16 15:20:36 -0700222 /* Encourage Cookie-ECHO bundling. */
Vlad Yasevich5d7ff262009-08-07 13:23:28 -0400223 if (asoc->state < SCTP_STATE_COOKIE_ECHOED)
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200224 first_len -= SCTP_ARBITRARY_COOKIE_ECHO_LEN;
Vlad Yasevich3e62abf2009-09-04 18:20:56 -0400225
226 /* Account for a different sized first fragment */
227 if (msg_len >= first_len) {
Vlad Yasevich0e3aef82010-04-30 22:41:10 -0400228 msg->can_delay = 0;
Marcelo Ricardo Leitnerfedb1bd32018-06-20 12:47:52 -0300229 if (msg_len > first_len)
230 SCTP_INC_STATS(sock_net(asoc->base.sk),
231 SCTP_MIB_FRAGUSRMSGS);
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200232 } else {
233 /* Which may be the only one... */
234 first_len = msg_len;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700235 }
236
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200237 /* Create chunks for all DATA chunks. */
238 for (remaining = msg_len; remaining; remaining -= len) {
239 u8 frag = SCTP_DATA_MIDDLE_FRAG;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700240
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200241 if (remaining == msg_len) {
242 /* First frag, which may also be the last */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700243 frag |= SCTP_DATA_FIRST_FRAG;
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200244 len = first_len;
245 } else {
246 /* Middle frags */
247 len = max_data;
248 }
Linus Torvalds1da177e2005-04-16 15:20:36 -0700249
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200250 if (len >= remaining) {
251 /* Last frag, which may also be the first */
252 len = remaining;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700253 frag |= SCTP_DATA_LAST_FRAG;
254
Wei Yongjunb93d6472009-11-23 15:53:56 -0500255 /* The application requests to set the I-bit of the
256 * last DATA chunk of a user message when providing
257 * the user message to the SCTP implementation.
258 */
259 if ((sinfo->sinfo_flags & SCTP_EOF) ||
260 (sinfo->sinfo_flags & SCTP_SACK_IMMEDIATELY))
261 frag |= SCTP_DATA_SACK_IMM;
262 }
263
Xin Long0c3f6f62017-12-08 21:04:01 +0800264 chunk = asoc->stream.si->make_datafrag(asoc, sinfo, len, frag,
265 GFP_KERNEL);
Tommi Rantala6e51fe72012-11-22 03:23:16 +0000266 if (!chunk) {
267 err = -ENOMEM;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700268 goto errout;
Tommi Rantala6e51fe72012-11-22 03:23:16 +0000269 }
270
Al Viroe0eb0932014-11-15 01:11:23 -0500271 err = sctp_user_addto_chunk(chunk, len, from);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700272 if (err < 0)
Tommi Rantalabe364c82012-11-27 04:01:46 +0000273 goto errout_chunk_free;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700274
Xin Long1b1e0bc2018-03-14 19:05:30 +0800275 chunk->shkey = shkey;
276
Linus Torvalds1da177e2005-04-16 15:20:36 -0700277 /* Put the chunk->skb back into the form expected by send. */
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200278 __skb_pull(chunk->skb, (__u8 *)chunk->chunk_hdr -
279 chunk->skb->data);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700280
281 sctp_datamsg_assign(msg, chunk);
282 list_add_tail(&chunk->frag_list, &msg->chunks);
283 }
284
285 return msg;
286
Tommi Rantalabe364c82012-11-27 04:01:46 +0000287errout_chunk_free:
288 sctp_chunk_free(chunk);
289
Linus Torvalds1da177e2005-04-16 15:20:36 -0700290errout:
291 list_for_each_safe(pos, temp, &msg->chunks) {
292 list_del_init(pos);
293 chunk = list_entry(pos, struct sctp_chunk, frag_list);
294 sctp_chunk_free(chunk);
295 }
Florian Westphal80445cf2008-03-23 22:47:08 -0700296 sctp_datamsg_put(msg);
Marcelo Ricardo Leitnerbfd2e4b2016-12-29 15:53:28 -0200297
Tommi Rantala6e51fe72012-11-22 03:23:16 +0000298 return ERR_PTR(err);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700299}
300
301/* Check whether this message has expired. */
302int sctp_chunk_abandoned(struct sctp_chunk *chunk)
303{
Xin Long8ae808e2016-10-08 11:40:16 +0800304 if (!chunk->asoc->peer.prsctp_capable)
Linus Torvalds1da177e2005-04-16 15:20:36 -0700305 return 0;
306
Xin Longe5f61292017-11-25 21:18:35 +0800307 if (chunk->msg->abandoned)
308 return 1;
309
Xin Long779edd72017-11-25 21:18:36 +0800310 if (!chunk->has_tsn &&
311 !(chunk->chunk_hdr->flags & SCTP_DATA_FIRST_FRAG))
312 return 0;
313
Xin Longa6c2f792016-07-09 19:47:43 +0800314 if (SCTP_PR_TTL_ENABLED(chunk->sinfo.sinfo_flags) &&
Xin Long06054832016-09-29 02:37:27 +0800315 time_after(jiffies, chunk->msg->expires_at)) {
Xin Longd229d482017-04-01 17:07:46 +0800316 struct sctp_stream_out *streamout =
Konstantin Khorenko05364ca2018-08-10 20:11:42 +0300317 SCTP_SO(&chunk->asoc->stream,
318 chunk->sinfo.sinfo_stream);
Xin Longd229d482017-04-01 17:07:46 +0800319
320 if (chunk->sent_count) {
Xin Longa6c2f792016-07-09 19:47:43 +0800321 chunk->asoc->abandoned_sent[SCTP_PR_INDEX(TTL)]++;
Marcelo Ricardo Leitnerf952be72017-10-03 19:20:11 -0300322 streamout->ext->abandoned_sent[SCTP_PR_INDEX(TTL)]++;
Xin Longd229d482017-04-01 17:07:46 +0800323 } else {
Xin Longa6c2f792016-07-09 19:47:43 +0800324 chunk->asoc->abandoned_unsent[SCTP_PR_INDEX(TTL)]++;
Marcelo Ricardo Leitnerf952be72017-10-03 19:20:11 -0300325 streamout->ext->abandoned_unsent[SCTP_PR_INDEX(TTL)]++;
Xin Longd229d482017-04-01 17:07:46 +0800326 }
Xin Longe5f61292017-11-25 21:18:35 +0800327 chunk->msg->abandoned = 1;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700328 return 1;
Xin Long01aadb32016-07-09 19:47:44 +0800329 } else if (SCTP_PR_RTX_ENABLED(chunk->sinfo.sinfo_flags) &&
Xin Long06054832016-09-29 02:37:27 +0800330 chunk->sent_count > chunk->sinfo.sinfo_timetolive) {
Xin Longd229d482017-04-01 17:07:46 +0800331 struct sctp_stream_out *streamout =
Konstantin Khorenko05364ca2018-08-10 20:11:42 +0300332 SCTP_SO(&chunk->asoc->stream,
333 chunk->sinfo.sinfo_stream);
Xin Longd229d482017-04-01 17:07:46 +0800334
Xin Long01aadb32016-07-09 19:47:44 +0800335 chunk->asoc->abandoned_sent[SCTP_PR_INDEX(RTX)]++;
Marcelo Ricardo Leitnerf952be72017-10-03 19:20:11 -0300336 streamout->ext->abandoned_sent[SCTP_PR_INDEX(RTX)]++;
Xin Longe5f61292017-11-25 21:18:35 +0800337 chunk->msg->abandoned = 1;
Xin Long01aadb32016-07-09 19:47:44 +0800338 return 1;
Xin Long8ae808e2016-10-08 11:40:16 +0800339 } else if (!SCTP_PR_POLICY(chunk->sinfo.sinfo_flags) &&
340 chunk->msg->expires_at &&
341 time_after(jiffies, chunk->msg->expires_at)) {
Xin Longe5f61292017-11-25 21:18:35 +0800342 chunk->msg->abandoned = 1;
Xin Long8ae808e2016-10-08 11:40:16 +0800343 return 1;
Xin Longa6c2f792016-07-09 19:47:43 +0800344 }
Xin Long8dbdf1f2016-07-09 19:47:45 +0800345 /* PRIO policy is processed by sendmsg, not here */
Linus Torvalds1da177e2005-04-16 15:20:36 -0700346
347 return 0;
348}
349
350/* This chunk (and consequently entire message) has failed in its sending. */
351void sctp_chunk_fail(struct sctp_chunk *chunk, int error)
352{
353 chunk->msg->send_failed = 1;
354 chunk->msg->send_error = error;
355}