PageRenderTime 52ms CodeModel.GetById 14ms RepoModel.GetById 1ms app.codeStats 0ms

/drivers/net/ppp/pppopns.c

https://gitlab.com/HRTKernel/Hacker_Kernel_SM-N910F
C | 525 lines | 399 code | 74 blank | 52 comment | 60 complexity | 102797f4b60dbe1173eeb631ff6e2c2f MD5 | raw file
Possible License(s): GPL-2.0
  1. /* drivers/net/pppopns.c
  2. *
  3. * Driver for PPP on PPTP Network Server / PPPoPNS Socket (RFC 2637)
  4. *
  5. * Copyright (C) 2009 Google, Inc.
  6. *
  7. * This software is licensed under the terms of the GNU General Public
  8. * License version 2, as published by the Free Software Foundation, and
  9. * may be copied, distributed, and modified under those terms.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  14. * GNU General Public License for more details.
  15. */
  16. /* This driver handles PPTP data packets between a RAW socket and a PPP channel.
  17. * The socket is created in the kernel space and connected to the same address
  18. * of the control socket. Outgoing packets are always sent with sequences but
  19. * without acknowledgements. Incoming packets with sequences are reordered
  20. * within a sliding window of one second. Currently reordering only happens when
  21. * a packet is received. It is done for simplicity since no additional locks or
  22. * threads are required. This driver should work on both IPv4 and IPv6. */
  23. #include <linux/module.h>
  24. #include <linux/jiffies.h>
  25. #include <linux/workqueue.h>
  26. #include <linux/skbuff.h>
  27. #include <linux/file.h>
  28. #include <linux/netdevice.h>
  29. #include <linux/net.h>
  30. #include <linux/ppp_defs.h>
  31. #include <linux/if.h>
  32. #include <linux/if_ppp.h>
  33. #include <linux/if_pppox.h>
  34. #include <linux/ppp_channel.h>
  35. #include <asm/uaccess.h>
  36. #define GRE_HEADER_SIZE 8
  37. #define PPTP_GRE_BITS htons(0x2001)
  38. #define PPTP_GRE_BITS_MASK htons(0xEF7F)
  39. #define PPTP_GRE_SEQ_BIT htons(0x1000)
  40. #define PPTP_GRE_ACK_BIT htons(0x0080)
  41. #define PPTP_GRE_TYPE htons(0x880B)
  42. #define PPP_ADDR 0xFF
  43. #define PPP_CTRL 0x03
  44. struct header {
  45. __u16 bits;
  46. __u16 type;
  47. __u16 length;
  48. __u16 call;
  49. __u32 sequence;
  50. } __attribute__((packed));
  51. struct meta {
  52. __u32 sequence;
  53. __u32 timestamp;
  54. };
  55. static inline struct meta *skb_meta(struct sk_buff *skb)
  56. {
  57. return (struct meta *)skb->cb;
  58. }
  59. static void recv_queue_timer_callback(unsigned long data);
  60. static void traverse_receive_queue(struct sock *sk)
  61. {
  62. struct pppox_sock *po = pppox_sk(sk);
  63. struct pppopns_opt *opt = &pppox_sk(sk)->proto.pns;
  64. struct sk_buff *skb;
  65. struct sk_buff *skb1;
  66. struct meta *meta;
  67. __u32 now = jiffies;
  68. /* Remove packets from receive queue as long as
  69. * 1. the receive buffer is full,
  70. * 2. they are queued longer than one second, or
  71. * 3. there are no missing packets before them. */
  72. skb_queue_walk_safe(&sk->sk_receive_queue, skb, skb1) {
  73. meta = skb_meta(skb);
  74. if (atomic_read(&sk->sk_rmem_alloc) < sk->sk_rcvbuf &&
  75. now - meta->timestamp < (HZ - 5) &&
  76. meta->sequence != opt->recv_sequence)
  77. break;
  78. skb_unlink(skb, &sk->sk_receive_queue);
  79. opt->recv_sequence = meta->sequence + 1;
  80. skb_orphan(skb);
  81. ppp_input(&po->chan, skb);
  82. }
  83. if (skb_queue_len(&sk->sk_receive_queue) > 0) {
  84. /* Start the timer. The timer will
  85. expire after one second. When the
  86. timer expires, the receive_queue is
  87. checked and all packets older than
  88. one second are removed from the queue and
  89. passed forward. */
  90. if (timer_pending(&po->recv_queue_timer)) {
  91. /* Something is wrong. Recv timer is already active. However, Ignoring...*/
  92. } else {
  93. init_timer(&po->recv_queue_timer);
  94. po->recv_queue_timer.data = (unsigned long)sk;
  95. po->recv_queue_timer.function = recv_queue_timer_callback;
  96. po->recv_queue_timer.expires = now + HZ;
  97. add_timer(&po->recv_queue_timer);
  98. }
  99. }
  100. }
  101. static void recv_queue_timer_callback(unsigned long data)
  102. {
  103. struct sock *sk = (struct sock *)data;
  104. spin_lock(&pppox_sk(sk)->recv_queue_lock);
  105. traverse_receive_queue(sk);
  106. spin_unlock(&pppox_sk(sk)->recv_queue_lock);
  107. }
  108. /******************************************************************************/
  109. static int pppopns_recv_core(struct sock *sk_raw, struct sk_buff *skb)
  110. {
  111. struct sock *sk = (struct sock *)sk_raw->sk_user_data;
  112. struct pppopns_opt *opt = &pppox_sk(sk)->proto.pns;
  113. struct meta *meta = skb_meta(skb);
  114. __u32 now = jiffies;
  115. struct header *hdr;
  116. /* Skip transport header */
  117. skb_pull(skb, skb_transport_header(skb) - skb->data);
  118. /* Drop the packet if GRE header is missing. */
  119. if (skb->len < GRE_HEADER_SIZE)
  120. goto drop;
  121. hdr = (struct header *)skb->data;
  122. /* Check the header. */
  123. if (hdr->type != PPTP_GRE_TYPE || hdr->call != opt->local ||
  124. (hdr->bits & PPTP_GRE_BITS_MASK) != PPTP_GRE_BITS)
  125. goto drop;
  126. /* Skip all fields including optional ones. */
  127. if (!skb_pull(skb, GRE_HEADER_SIZE +
  128. (hdr->bits & PPTP_GRE_SEQ_BIT ? 4 : 0) +
  129. (hdr->bits & PPTP_GRE_ACK_BIT ? 4 : 0)))
  130. goto drop;
  131. /* Check the length. */
  132. if (skb->len != ntohs(hdr->length))
  133. goto drop;
  134. /* Check the sequence if it is present. */
  135. if (hdr->bits & PPTP_GRE_SEQ_BIT) {
  136. meta->sequence = ntohl(hdr->sequence);
  137. if ((__s32)(meta->sequence - opt->recv_sequence) < 0)
  138. goto drop;
  139. }
  140. /* Skip PPP address and control if they are present. */
  141. if (skb->len >= 2 && skb->data[0] == PPP_ADDR &&
  142. skb->data[1] == PPP_CTRL)
  143. skb_pull(skb, 2);
  144. /* Fix PPP protocol if it is compressed. */
  145. if (skb->len >= 1 && skb->data[0] & 1)
  146. skb_push(skb, 1)[0] = 0;
  147. /* Drop the packet if PPP protocol is missing. */
  148. if (skb->len < 2)
  149. goto drop;
  150. /* Perform reordering if sequencing is enabled. */
  151. if (hdr->bits & PPTP_GRE_SEQ_BIT) {
  152. struct sk_buff *skb1;
  153. spin_lock(&pppox_sk(sk)->recv_queue_lock);
  154. /* Insert the packet into receive queue in order. */
  155. skb_set_owner_r(skb, sk);
  156. skb_queue_walk(&sk->sk_receive_queue, skb1) {
  157. struct meta *meta1 = skb_meta(skb1);
  158. __s32 order = meta->sequence - meta1->sequence;
  159. if (order == 0) {
  160. spin_unlock(&pppox_sk(sk)->recv_queue_lock);
  161. goto drop;
  162. }
  163. if (order < 0) {
  164. meta->timestamp = meta1->timestamp;
  165. skb_insert(skb1, skb, &sk->sk_receive_queue);
  166. skb = NULL;
  167. break;
  168. }
  169. }
  170. if (skb) {
  171. meta->timestamp = now;
  172. skb_queue_tail(&sk->sk_receive_queue, skb);
  173. }
  174. if (timer_pending(&pppox_sk(sk)->recv_queue_timer)) {
  175. del_timer_sync(&pppox_sk(sk)->recv_queue_timer);
  176. }
  177. traverse_receive_queue(sk);
  178. spin_unlock(&pppox_sk(sk)->recv_queue_lock);
  179. return NET_RX_SUCCESS;
  180. }
  181. /* Flush receive queue if sequencing is disabled. */
  182. skb_queue_purge(&sk->sk_receive_queue);
  183. skb_orphan(skb);
  184. ppp_input(&pppox_sk(sk)->chan, skb);
  185. return NET_RX_SUCCESS;
  186. drop:
  187. kfree_skb(skb);
  188. return NET_RX_DROP;
  189. }
  190. static void pppopns_recv(struct sock *sk_raw)
  191. {
  192. struct sk_buff *skb;
  193. while ((skb = skb_dequeue(&sk_raw->sk_receive_queue))) {
  194. sock_hold(sk_raw);
  195. sk_receive_skb(sk_raw, skb, 0);
  196. }
  197. }
  198. static struct sk_buff_head delivery_queue;
  199. static void pppopns_xmit_core(struct work_struct *delivery_work)
  200. {
  201. mm_segment_t old_fs = get_fs();
  202. struct sk_buff *skb;
  203. set_fs(KERNEL_DS);
  204. while ((skb = skb_dequeue(&delivery_queue))) {
  205. struct sock *sk_raw = skb->sk;
  206. struct kvec iov = {.iov_base = skb->data, .iov_len = skb->len};
  207. struct msghdr msg = {
  208. .msg_iov = (struct iovec *)&iov,
  209. .msg_iovlen = 1,
  210. .msg_flags = MSG_NOSIGNAL | MSG_DONTWAIT,
  211. };
  212. sk_raw->sk_prot->sendmsg(NULL, sk_raw, &msg, skb->len);
  213. kfree_skb(skb);
  214. }
  215. set_fs(old_fs);
  216. }
  217. static DECLARE_WORK(delivery_work, pppopns_xmit_core);
  218. static int pppopns_xmit(struct ppp_channel *chan, struct sk_buff *skb)
  219. {
  220. struct sock *sk_raw = (struct sock *)chan->private;
  221. struct pppopns_opt *opt = &pppox_sk(sk_raw->sk_user_data)->proto.pns;
  222. struct header *hdr;
  223. __u16 length;
  224. /* Install PPP address and control. */
  225. skb_push(skb, 2);
  226. skb->data[0] = PPP_ADDR;
  227. skb->data[1] = PPP_CTRL;
  228. length = skb->len;
  229. /* Install PPTP GRE header. */
  230. hdr = (struct header *)skb_push(skb, 12);
  231. hdr->bits = PPTP_GRE_BITS | PPTP_GRE_SEQ_BIT;
  232. hdr->type = PPTP_GRE_TYPE;
  233. hdr->length = htons(length);
  234. hdr->call = opt->remote;
  235. hdr->sequence = htonl(opt->xmit_sequence);
  236. opt->xmit_sequence++;
  237. /* Now send the packet via the delivery queue. */
  238. skb_set_owner_w(skb, sk_raw);
  239. skb_queue_tail(&delivery_queue, skb);
  240. schedule_work(&delivery_work);
  241. return 1;
  242. }
  243. /******************************************************************************/
  244. static struct ppp_channel_ops pppopns_channel_ops = {
  245. .start_xmit = pppopns_xmit,
  246. };
  247. static int pppopns_connect(struct socket *sock, struct sockaddr *useraddr,
  248. int addrlen, int flags)
  249. {
  250. struct sock *sk = sock->sk;
  251. struct pppox_sock *po = pppox_sk(sk);
  252. struct sockaddr_pppopns *addr = (struct sockaddr_pppopns *)useraddr;
  253. struct sockaddr_storage ss;
  254. struct socket *sock_tcp = NULL;
  255. struct socket *sock_raw = NULL;
  256. struct sock *sk_tcp;
  257. struct sock *sk_raw;
  258. int error;
  259. if (addrlen != sizeof(struct sockaddr_pppopns))
  260. return -EINVAL;
  261. lock_sock(sk);
  262. error = -EALREADY;
  263. if (sk->sk_state != PPPOX_NONE)
  264. goto out;
  265. sock_tcp = sockfd_lookup(addr->tcp_socket, &error);
  266. if (!sock_tcp)
  267. goto out;
  268. sk_tcp = sock_tcp->sk;
  269. error = -EPROTONOSUPPORT;
  270. if (sk_tcp->sk_protocol != IPPROTO_TCP)
  271. goto out;
  272. addrlen = sizeof(struct sockaddr_storage);
  273. error = kernel_getpeername(sock_tcp, (struct sockaddr *)&ss, &addrlen);
  274. if (error)
  275. goto out;
  276. if (!sk_tcp->sk_bound_dev_if) {
  277. struct dst_entry *dst = sk_dst_get(sk_tcp);
  278. error = -ENODEV;
  279. if (!dst)
  280. goto out;
  281. sk_tcp->sk_bound_dev_if = dst->dev->ifindex;
  282. dst_release(dst);
  283. }
  284. error = sock_create(ss.ss_family, SOCK_RAW, IPPROTO_GRE, &sock_raw);
  285. if (error)
  286. goto out;
  287. sk_raw = sock_raw->sk;
  288. sk_raw->sk_bound_dev_if = sk_tcp->sk_bound_dev_if;
  289. error = kernel_connect(sock_raw, (struct sockaddr *)&ss, addrlen, 0);
  290. if (error)
  291. goto out;
  292. po->chan.hdrlen = 14;
  293. po->chan.private = sk_raw;
  294. po->chan.ops = &pppopns_channel_ops;
  295. po->chan.mtu = PPP_MRU - 80;
  296. po->proto.pns.local = addr->local;
  297. po->proto.pns.remote = addr->remote;
  298. po->proto.pns.data_ready = sk_raw->sk_data_ready;
  299. po->proto.pns.backlog_rcv = sk_raw->sk_backlog_rcv;
  300. error = ppp_register_channel(&po->chan);
  301. if (error)
  302. goto out;
  303. sk->sk_state = PPPOX_CONNECTED;
  304. lock_sock(sk_raw);
  305. sk_raw->sk_data_ready = pppopns_recv;
  306. sk_raw->sk_backlog_rcv = pppopns_recv_core;
  307. sk_raw->sk_user_data = sk;
  308. release_sock(sk_raw);
  309. out:
  310. if (sock_tcp)
  311. sockfd_put(sock_tcp);
  312. if (error && sock_raw)
  313. sock_release(sock_raw);
  314. release_sock(sk);
  315. return error;
  316. }
  317. static int pppopns_release(struct socket *sock)
  318. {
  319. struct sock *sk = sock->sk;
  320. struct pppox_sock *po = pppox_sk(sk);
  321. if (!sk)
  322. return 0;
  323. lock_sock(sk);
  324. if (sock_flag(sk, SOCK_DEAD)) {
  325. release_sock(sk);
  326. return -EBADF;
  327. }
  328. if (po) {
  329. spin_lock(&po->recv_queue_lock);
  330. if (po && timer_pending( &po->recv_queue_timer )) {
  331. del_timer_sync( &po->recv_queue_timer );
  332. }
  333. spin_unlock(&po->recv_queue_lock);
  334. }
  335. if (sk->sk_state != PPPOX_NONE) {
  336. struct sock *sk_raw = (struct sock *)pppox_sk(sk)->chan.private;
  337. lock_sock(sk_raw);
  338. skb_queue_purge(&sk->sk_receive_queue);
  339. pppox_unbind_sock(sk);
  340. sk_raw->sk_data_ready = pppox_sk(sk)->proto.pns.data_ready;
  341. sk_raw->sk_backlog_rcv = pppox_sk(sk)->proto.pns.backlog_rcv;
  342. sk_raw->sk_user_data = NULL;
  343. release_sock(sk_raw);
  344. sock_release(sk_raw->sk_socket);
  345. }
  346. sock_orphan(sk);
  347. sock->sk = NULL;
  348. release_sock(sk);
  349. sock_put(sk);
  350. return 0;
  351. }
  352. /******************************************************************************/
  353. static struct proto pppopns_proto = {
  354. .name = "PPPOPNS",
  355. .owner = THIS_MODULE,
  356. .obj_size = sizeof(struct pppox_sock),
  357. };
  358. static struct proto_ops pppopns_proto_ops = {
  359. .family = PF_PPPOX,
  360. .owner = THIS_MODULE,
  361. .release = pppopns_release,
  362. .bind = sock_no_bind,
  363. .connect = pppopns_connect,
  364. .socketpair = sock_no_socketpair,
  365. .accept = sock_no_accept,
  366. .getname = sock_no_getname,
  367. .poll = sock_no_poll,
  368. .ioctl = pppox_ioctl,
  369. .listen = sock_no_listen,
  370. .shutdown = sock_no_shutdown,
  371. .setsockopt = sock_no_setsockopt,
  372. .getsockopt = sock_no_getsockopt,
  373. .sendmsg = sock_no_sendmsg,
  374. .recvmsg = sock_no_recvmsg,
  375. .mmap = sock_no_mmap,
  376. };
  377. static int pppopns_create(struct net *net, struct socket *sock)
  378. {
  379. struct sock *sk;
  380. struct pppox_sock *po;
  381. struct pppopns_opt *opt;
  382. sk = sk_alloc(net, PF_PPPOX, GFP_KERNEL, &pppopns_proto);
  383. if (!sk)
  384. return -ENOMEM;
  385. sock_init_data(sock, sk);
  386. sock->state = SS_UNCONNECTED;
  387. sock->ops = &pppopns_proto_ops;
  388. sk->sk_protocol = PX_PROTO_OPNS;
  389. sk->sk_state = PPPOX_NONE;
  390. po = pppox_sk(sk);
  391. opt = &po->proto.pns;
  392. opt->ppp_flags = SC_GRE_SEQ_CHK;
  393. init_timer(&po->recv_queue_timer);
  394. spin_lock_init(&po->recv_queue_lock);
  395. return 0;
  396. }
  397. static int pppopns_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
  398. {
  399. struct sock *sk = sock->sk;
  400. struct pppox_sock *po = pppox_sk(sk);
  401. struct pppopns_opt *opt = &po->proto.pns;
  402. void __user *argp = (void __user *)arg;
  403. int __user *p = argp;
  404. int err = -ENOTTY, val;
  405. switch (cmd) {
  406. case PPPIOCGFLAGS:
  407. printk("Getting pppopns socket flags.\n");
  408. val = opt->ppp_flags;
  409. if (put_user(val, p))
  410. break;
  411. err = 0;
  412. break;
  413. case PPPIOCSFLAGS:
  414. printk("Setting pppopns socket flags.\n");
  415. if (get_user(val, p))
  416. break;
  417. opt->ppp_flags = val;
  418. err = 0;
  419. break;
  420. }
  421. return err;
  422. }
  423. /******************************************************************************/
  424. static struct pppox_proto pppopns_pppox_proto = {
  425. .create = pppopns_create,
  426. .ioctl = pppopns_ioctl,
  427. .owner = THIS_MODULE,
  428. };
  429. static int __init pppopns_init(void)
  430. {
  431. int error;
  432. error = proto_register(&pppopns_proto, 0);
  433. if (error)
  434. return error;
  435. error = register_pppox_proto(PX_PROTO_OPNS, &pppopns_pppox_proto);
  436. if (error)
  437. proto_unregister(&pppopns_proto);
  438. else
  439. skb_queue_head_init(&delivery_queue);
  440. return error;
  441. }
  442. static void __exit pppopns_exit(void)
  443. {
  444. unregister_pppox_proto(PX_PROTO_OPNS);
  445. proto_unregister(&pppopns_proto);
  446. }
  447. module_init(pppopns_init);
  448. module_exit(pppopns_exit);
  449. MODULE_DESCRIPTION("PPP on PPTP Network Server (PPPoPNS)");
  450. MODULE_AUTHOR("Chia-chi Yeh <chiachi@android.com>");
  451. MODULE_LICENSE("GPL");