l2tp_ppp.c 44 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765
  1. /*****************************************************************************
  2. * Linux PPP over L2TP (PPPoX/PPPoL2TP) Sockets
  3. *
  4. * PPPoX --- Generic PPP encapsulation socket family
  5. * PPPoL2TP --- PPP over L2TP (RFC 2661)
  6. *
  7. * Version: 2.0.0
  8. *
  9. * Authors: James Chapman (jchapman@katalix.com)
  10. *
  11. * Based on original work by Martijn van Oosterhout <kleptog@svana.org>
  12. *
  13. * License:
  14. * This program is free software; you can redistribute it and/or
  15. * modify it under the terms of the GNU General Public License
  16. * as published by the Free Software Foundation; either version
  17. * 2 of the License, or (at your option) any later version.
  18. *
  19. */
  20. /* This driver handles only L2TP data frames; control frames are handled by a
  21. * userspace application.
  22. *
  23. * To send data in an L2TP session, userspace opens a PPPoL2TP socket and
  24. * attaches it to a bound UDP socket with local tunnel_id / session_id and
  25. * peer tunnel_id / session_id set. Data can then be sent or received using
  26. * regular socket sendmsg() / recvmsg() calls. Kernel parameters of the socket
  27. * can be read or modified using ioctl() or [gs]etsockopt() calls.
  28. *
  29. * When a PPPoL2TP socket is connected with local and peer session_id values
  30. * zero, the socket is treated as a special tunnel management socket.
  31. *
  32. * Here's example userspace code to create a socket for sending/receiving data
  33. * over an L2TP session:-
  34. *
  35. * struct sockaddr_pppol2tp sax;
  36. * int fd;
  37. * int session_fd;
  38. *
  39. * fd = socket(AF_PPPOX, SOCK_DGRAM, PX_PROTO_OL2TP);
  40. *
  41. * sax.sa_family = AF_PPPOX;
  42. * sax.sa_protocol = PX_PROTO_OL2TP;
  43. * sax.pppol2tp.fd = tunnel_fd; // bound UDP socket
  44. * sax.pppol2tp.addr.sin_addr.s_addr = addr->sin_addr.s_addr;
  45. * sax.pppol2tp.addr.sin_port = addr->sin_port;
  46. * sax.pppol2tp.addr.sin_family = AF_INET;
  47. * sax.pppol2tp.s_tunnel = tunnel_id;
  48. * sax.pppol2tp.s_session = session_id;
  49. * sax.pppol2tp.d_tunnel = peer_tunnel_id;
  50. * sax.pppol2tp.d_session = peer_session_id;
  51. *
  52. * session_fd = connect(fd, (struct sockaddr *)&sax, sizeof(sax));
  53. *
  54. * A pppd plugin that allows PPP traffic to be carried over L2TP using
  55. * this driver is available from the OpenL2TP project at
  56. * http://openl2tp.sourceforge.net.
  57. */
  58. #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
  59. #include <linux/module.h>
  60. #include <linux/string.h>
  61. #include <linux/list.h>
  62. #include <linux/uaccess.h>
  63. #include <linux/kernel.h>
  64. #include <linux/spinlock.h>
  65. #include <linux/kthread.h>
  66. #include <linux/sched.h>
  67. #include <linux/slab.h>
  68. #include <linux/errno.h>
  69. #include <linux/jiffies.h>
  70. #include <linux/netdevice.h>
  71. #include <linux/net.h>
  72. #include <linux/inetdevice.h>
  73. #include <linux/skbuff.h>
  74. #include <linux/init.h>
  75. #include <linux/ip.h>
  76. #include <linux/udp.h>
  77. #include <linux/if_pppox.h>
  78. #include <linux/if_pppol2tp.h>
  79. #include <net/sock.h>
  80. #include <linux/ppp_channel.h>
  81. #include <linux/ppp_defs.h>
  82. #include <linux/ppp-ioctl.h>
  83. #include <linux/file.h>
  84. #include <linux/hash.h>
  85. #include <linux/sort.h>
  86. #include <linux/proc_fs.h>
  87. #include <linux/l2tp.h>
  88. #include <linux/nsproxy.h>
  89. #include <net/net_namespace.h>
  90. #include <net/netns/generic.h>
  91. #include <net/ip.h>
  92. #include <net/udp.h>
  93. #include <net/inet_common.h>
  94. #include <asm/byteorder.h>
  95. #include <linux/atomic.h>
  96. #include "l2tp_core.h"
  97. #define PPPOL2TP_DRV_VERSION "V2.0"
  98. /* Space for UDP, L2TP and PPP headers */
  99. #define PPPOL2TP_HEADER_OVERHEAD 40
  100. /* Number of bytes to build transmit L2TP headers.
  101. * Unfortunately the size is different depending on whether sequence numbers
  102. * are enabled.
  103. */
  104. #define PPPOL2TP_L2TP_HDR_SIZE_SEQ 10
  105. #define PPPOL2TP_L2TP_HDR_SIZE_NOSEQ 6
  106. /* Private data of each session. This data lives at the end of struct
  107. * l2tp_session, referenced via session->priv[].
  108. */
  109. struct pppol2tp_session {
  110. int owner; /* pid that opened the socket */
  111. struct mutex sk_lock; /* Protects .sk */
  112. struct sock __rcu *sk; /* Pointer to the session
  113. * PPPoX socket */
  114. struct sock *__sk; /* Copy of .sk, for cleanup */
  115. struct rcu_head rcu; /* For asynchronous release */
  116. };
  117. static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb);
  118. static const struct ppp_channel_ops pppol2tp_chan_ops = {
  119. .start_xmit = pppol2tp_xmit,
  120. };
  121. static const struct proto_ops pppol2tp_ops;
  122. /* Retrieves the pppol2tp socket associated to a session.
  123. * A reference is held on the returned socket, so this function must be paired
  124. * with sock_put().
  125. */
  126. static struct sock *pppol2tp_session_get_sock(struct l2tp_session *session)
  127. {
  128. struct pppol2tp_session *ps = l2tp_session_priv(session);
  129. struct sock *sk;
  130. rcu_read_lock();
  131. sk = rcu_dereference(ps->sk);
  132. if (sk)
  133. sock_hold(sk);
  134. rcu_read_unlock();
  135. return sk;
  136. }
  137. /* Helpers to obtain tunnel/session contexts from sockets.
  138. */
  139. static inline struct l2tp_session *pppol2tp_sock_to_session(struct sock *sk)
  140. {
  141. struct l2tp_session *session;
  142. if (sk == NULL)
  143. return NULL;
  144. sock_hold(sk);
  145. session = (struct l2tp_session *)(sk->sk_user_data);
  146. if (session == NULL) {
  147. sock_put(sk);
  148. goto out;
  149. }
  150. BUG_ON(session->magic != L2TP_SESSION_MAGIC);
  151. out:
  152. return session;
  153. }
  154. /*****************************************************************************
  155. * Receive data handling
  156. *****************************************************************************/
  157. /* Receive message. This is the recvmsg for the PPPoL2TP socket.
  158. */
  159. static int pppol2tp_recvmsg(struct socket *sock, struct msghdr *msg,
  160. size_t len, int flags)
  161. {
  162. int err;
  163. struct sk_buff *skb;
  164. struct sock *sk = sock->sk;
  165. err = -EIO;
  166. if (sk->sk_state & PPPOX_BOUND)
  167. goto end;
  168. err = 0;
  169. skb = skb_recv_datagram(sk, flags & ~MSG_DONTWAIT,
  170. flags & MSG_DONTWAIT, &err);
  171. if (!skb)
  172. goto end;
  173. if (len > skb->len)
  174. len = skb->len;
  175. else if (len < skb->len)
  176. msg->msg_flags |= MSG_TRUNC;
  177. err = skb_copy_datagram_msg(skb, 0, msg, len);
  178. if (likely(err == 0))
  179. err = len;
  180. kfree_skb(skb);
  181. end:
  182. return err;
  183. }
  184. static void pppol2tp_recv(struct l2tp_session *session, struct sk_buff *skb, int data_len)
  185. {
  186. struct pppol2tp_session *ps = l2tp_session_priv(session);
  187. struct sock *sk = NULL;
  188. /* If the socket is bound, send it in to PPP's input queue. Otherwise
  189. * queue it on the session socket.
  190. */
  191. rcu_read_lock();
  192. sk = rcu_dereference(ps->sk);
  193. if (sk == NULL)
  194. goto no_sock;
  195. /* If the first two bytes are 0xFF03, consider that it is the PPP's
  196. * Address and Control fields and skip them. The L2TP module has always
  197. * worked this way, although, in theory, the use of these fields should
  198. * be negociated and handled at the PPP layer. These fields are
  199. * constant: 0xFF is the All-Stations Address and 0x03 the Unnumbered
  200. * Information command with Poll/Final bit set to zero (RFC 1662).
  201. */
  202. if (pskb_may_pull(skb, 2) && skb->data[0] == PPP_ALLSTATIONS &&
  203. skb->data[1] == PPP_UI)
  204. skb_pull(skb, 2);
  205. if (sk->sk_state & PPPOX_BOUND) {
  206. struct pppox_sock *po;
  207. l2tp_dbg(session, L2TP_MSG_DATA,
  208. "%s: recv %d byte data frame, passing to ppp\n",
  209. session->name, data_len);
  210. po = pppox_sk(sk);
  211. ppp_input(&po->chan, skb);
  212. } else {
  213. l2tp_dbg(session, L2TP_MSG_DATA,
  214. "%s: recv %d byte data frame, passing to L2TP socket\n",
  215. session->name, data_len);
  216. if (sock_queue_rcv_skb(sk, skb) < 0) {
  217. atomic_long_inc(&session->stats.rx_errors);
  218. kfree_skb(skb);
  219. }
  220. }
  221. rcu_read_unlock();
  222. return;
  223. no_sock:
  224. rcu_read_unlock();
  225. l2tp_info(session, L2TP_MSG_DATA, "%s: no socket\n", session->name);
  226. kfree_skb(skb);
  227. }
  228. /************************************************************************
  229. * Transmit handling
  230. ***********************************************************************/
  231. /* This is the sendmsg for the PPPoL2TP pppol2tp_session socket. We come here
  232. * when a user application does a sendmsg() on the session socket. L2TP and
  233. * PPP headers must be inserted into the user's data.
  234. */
  235. static int pppol2tp_sendmsg(struct socket *sock, struct msghdr *m,
  236. size_t total_len)
  237. {
  238. struct sock *sk = sock->sk;
  239. struct sk_buff *skb;
  240. int error;
  241. struct l2tp_session *session;
  242. struct l2tp_tunnel *tunnel;
  243. int uhlen;
  244. error = -ENOTCONN;
  245. if (sock_flag(sk, SOCK_DEAD) || !(sk->sk_state & PPPOX_CONNECTED))
  246. goto error;
  247. /* Get session and tunnel contexts */
  248. error = -EBADF;
  249. session = pppol2tp_sock_to_session(sk);
  250. if (session == NULL)
  251. goto error;
  252. tunnel = session->tunnel;
  253. uhlen = (tunnel->encap == L2TP_ENCAPTYPE_UDP) ? sizeof(struct udphdr) : 0;
  254. /* Allocate a socket buffer */
  255. error = -ENOMEM;
  256. skb = sock_wmalloc(sk, NET_SKB_PAD + sizeof(struct iphdr) +
  257. uhlen + session->hdr_len +
  258. 2 + total_len, /* 2 bytes for PPP_ALLSTATIONS & PPP_UI */
  259. 0, GFP_KERNEL);
  260. if (!skb)
  261. goto error_put_sess;
  262. /* Reserve space for headers. */
  263. skb_reserve(skb, NET_SKB_PAD);
  264. skb_reset_network_header(skb);
  265. skb_reserve(skb, sizeof(struct iphdr));
  266. skb_reset_transport_header(skb);
  267. skb_reserve(skb, uhlen);
  268. /* Add PPP header */
  269. skb->data[0] = PPP_ALLSTATIONS;
  270. skb->data[1] = PPP_UI;
  271. skb_put(skb, 2);
  272. /* Copy user data into skb */
  273. error = memcpy_from_msg(skb_put(skb, total_len), m, total_len);
  274. if (error < 0) {
  275. kfree_skb(skb);
  276. goto error_put_sess;
  277. }
  278. local_bh_disable();
  279. l2tp_xmit_skb(session, skb, session->hdr_len);
  280. local_bh_enable();
  281. sock_put(sk);
  282. return total_len;
  283. error_put_sess:
  284. sock_put(sk);
  285. error:
  286. return error;
  287. }
  288. /* Transmit function called by generic PPP driver. Sends PPP frame
  289. * over PPPoL2TP socket.
  290. *
  291. * This is almost the same as pppol2tp_sendmsg(), but rather than
  292. * being called with a msghdr from userspace, it is called with a skb
  293. * from the kernel.
  294. *
  295. * The supplied skb from ppp doesn't have enough headroom for the
  296. * insertion of L2TP, UDP and IP headers so we need to allocate more
  297. * headroom in the skb. This will create a cloned skb. But we must be
  298. * careful in the error case because the caller will expect to free
  299. * the skb it supplied, not our cloned skb. So we take care to always
  300. * leave the original skb unfreed if we return an error.
  301. */
  302. static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb)
  303. {
  304. struct sock *sk = (struct sock *) chan->private;
  305. struct l2tp_session *session;
  306. struct l2tp_tunnel *tunnel;
  307. int uhlen, headroom;
  308. if (sock_flag(sk, SOCK_DEAD) || !(sk->sk_state & PPPOX_CONNECTED))
  309. goto abort;
  310. /* Get session and tunnel contexts from the socket */
  311. session = pppol2tp_sock_to_session(sk);
  312. if (session == NULL)
  313. goto abort;
  314. tunnel = session->tunnel;
  315. uhlen = (tunnel->encap == L2TP_ENCAPTYPE_UDP) ? sizeof(struct udphdr) : 0;
  316. headroom = NET_SKB_PAD +
  317. sizeof(struct iphdr) + /* IP header */
  318. uhlen + /* UDP header (if L2TP_ENCAPTYPE_UDP) */
  319. session->hdr_len + /* L2TP header */
  320. 2; /* 2 bytes for PPP_ALLSTATIONS & PPP_UI */
  321. if (skb_cow_head(skb, headroom))
  322. goto abort_put_sess;
  323. /* Setup PPP header */
  324. __skb_push(skb, 2);
  325. skb->data[0] = PPP_ALLSTATIONS;
  326. skb->data[1] = PPP_UI;
  327. local_bh_disable();
  328. l2tp_xmit_skb(session, skb, session->hdr_len);
  329. local_bh_enable();
  330. sock_put(sk);
  331. return 1;
  332. abort_put_sess:
  333. sock_put(sk);
  334. abort:
  335. /* Free the original skb */
  336. kfree_skb(skb);
  337. return 1;
  338. }
  339. /*****************************************************************************
  340. * Session (and tunnel control) socket create/destroy.
  341. *****************************************************************************/
  342. static void pppol2tp_put_sk(struct rcu_head *head)
  343. {
  344. struct pppol2tp_session *ps;
  345. ps = container_of(head, typeof(*ps), rcu);
  346. sock_put(ps->__sk);
  347. }
  348. /* Really kill the session socket. (Called from sock_put() if
  349. * refcnt == 0.)
  350. */
  351. static void pppol2tp_session_destruct(struct sock *sk)
  352. {
  353. struct l2tp_session *session = sk->sk_user_data;
  354. skb_queue_purge(&sk->sk_receive_queue);
  355. skb_queue_purge(&sk->sk_write_queue);
  356. if (session) {
  357. sk->sk_user_data = NULL;
  358. BUG_ON(session->magic != L2TP_SESSION_MAGIC);
  359. l2tp_session_dec_refcount(session);
  360. }
  361. }
  362. /* Called when the PPPoX socket (session) is closed.
  363. */
  364. static int pppol2tp_release(struct socket *sock)
  365. {
  366. struct sock *sk = sock->sk;
  367. struct l2tp_session *session;
  368. int error;
  369. if (!sk)
  370. return 0;
  371. error = -EBADF;
  372. lock_sock(sk);
  373. if (sock_flag(sk, SOCK_DEAD) != 0)
  374. goto error;
  375. pppox_unbind_sock(sk);
  376. /* Signal the death of the socket. */
  377. sk->sk_state = PPPOX_DEAD;
  378. sock_orphan(sk);
  379. sock->sk = NULL;
  380. session = pppol2tp_sock_to_session(sk);
  381. if (session) {
  382. struct pppol2tp_session *ps;
  383. l2tp_session_delete(session);
  384. ps = l2tp_session_priv(session);
  385. mutex_lock(&ps->sk_lock);
  386. ps->__sk = rcu_dereference_protected(ps->sk,
  387. lockdep_is_held(&ps->sk_lock));
  388. RCU_INIT_POINTER(ps->sk, NULL);
  389. mutex_unlock(&ps->sk_lock);
  390. call_rcu(&ps->rcu, pppol2tp_put_sk);
  391. /* Rely on the sock_put() call at the end of the function for
  392. * dropping the reference held by pppol2tp_sock_to_session().
  393. * The last reference will be dropped by pppol2tp_put_sk().
  394. */
  395. }
  396. release_sock(sk);
  397. /* This will delete the session context via
  398. * pppol2tp_session_destruct() if the socket's refcnt drops to
  399. * zero.
  400. */
  401. sock_put(sk);
  402. return 0;
  403. error:
  404. release_sock(sk);
  405. return error;
  406. }
  407. static struct proto pppol2tp_sk_proto = {
  408. .name = "PPPOL2TP",
  409. .owner = THIS_MODULE,
  410. .obj_size = sizeof(struct pppox_sock),
  411. };
  412. static int pppol2tp_backlog_recv(struct sock *sk, struct sk_buff *skb)
  413. {
  414. int rc;
  415. rc = l2tp_udp_encap_recv(sk, skb);
  416. if (rc)
  417. kfree_skb(skb);
  418. return NET_RX_SUCCESS;
  419. }
  420. /* socket() handler. Initialize a new struct sock.
  421. */
  422. static int pppol2tp_create(struct net *net, struct socket *sock, int kern)
  423. {
  424. int error = -ENOMEM;
  425. struct sock *sk;
  426. sk = sk_alloc(net, PF_PPPOX, GFP_KERNEL, &pppol2tp_sk_proto, kern);
  427. if (!sk)
  428. goto out;
  429. sock_init_data(sock, sk);
  430. sock->state = SS_UNCONNECTED;
  431. sock->ops = &pppol2tp_ops;
  432. sk->sk_backlog_rcv = pppol2tp_backlog_recv;
  433. sk->sk_protocol = PX_PROTO_OL2TP;
  434. sk->sk_family = PF_PPPOX;
  435. sk->sk_state = PPPOX_NONE;
  436. sk->sk_type = SOCK_STREAM;
  437. sk->sk_destruct = pppol2tp_session_destruct;
  438. error = 0;
  439. out:
  440. return error;
  441. }
  442. static void pppol2tp_show(struct seq_file *m, void *arg)
  443. {
  444. struct l2tp_session *session = arg;
  445. struct sock *sk;
  446. sk = pppol2tp_session_get_sock(session);
  447. if (sk) {
  448. struct pppox_sock *po = pppox_sk(sk);
  449. seq_printf(m, " interface %s\n", ppp_dev_name(&po->chan));
  450. sock_put(sk);
  451. }
  452. }
  453. static void pppol2tp_session_init(struct l2tp_session *session)
  454. {
  455. struct pppol2tp_session *ps;
  456. session->recv_skb = pppol2tp_recv;
  457. if (IS_ENABLED(CONFIG_L2TP_DEBUGFS))
  458. session->show = pppol2tp_show;
  459. ps = l2tp_session_priv(session);
  460. mutex_init(&ps->sk_lock);
  461. ps->owner = current->pid;
  462. }
  463. struct l2tp_connect_info {
  464. u8 version;
  465. int fd;
  466. u32 tunnel_id;
  467. u32 peer_tunnel_id;
  468. u32 session_id;
  469. u32 peer_session_id;
  470. };
  471. static int pppol2tp_sockaddr_get_info(const void *sa, int sa_len,
  472. struct l2tp_connect_info *info)
  473. {
  474. switch (sa_len) {
  475. case sizeof(struct sockaddr_pppol2tp):
  476. {
  477. const struct sockaddr_pppol2tp *sa_v2in4 = sa;
  478. if (sa_v2in4->sa_protocol != PX_PROTO_OL2TP)
  479. return -EINVAL;
  480. info->version = 2;
  481. info->fd = sa_v2in4->pppol2tp.fd;
  482. info->tunnel_id = sa_v2in4->pppol2tp.s_tunnel;
  483. info->peer_tunnel_id = sa_v2in4->pppol2tp.d_tunnel;
  484. info->session_id = sa_v2in4->pppol2tp.s_session;
  485. info->peer_session_id = sa_v2in4->pppol2tp.d_session;
  486. break;
  487. }
  488. case sizeof(struct sockaddr_pppol2tpv3):
  489. {
  490. const struct sockaddr_pppol2tpv3 *sa_v3in4 = sa;
  491. if (sa_v3in4->sa_protocol != PX_PROTO_OL2TP)
  492. return -EINVAL;
  493. info->version = 3;
  494. info->fd = sa_v3in4->pppol2tp.fd;
  495. info->tunnel_id = sa_v3in4->pppol2tp.s_tunnel;
  496. info->peer_tunnel_id = sa_v3in4->pppol2tp.d_tunnel;
  497. info->session_id = sa_v3in4->pppol2tp.s_session;
  498. info->peer_session_id = sa_v3in4->pppol2tp.d_session;
  499. break;
  500. }
  501. case sizeof(struct sockaddr_pppol2tpin6):
  502. {
  503. const struct sockaddr_pppol2tpin6 *sa_v2in6 = sa;
  504. if (sa_v2in6->sa_protocol != PX_PROTO_OL2TP)
  505. return -EINVAL;
  506. info->version = 2;
  507. info->fd = sa_v2in6->pppol2tp.fd;
  508. info->tunnel_id = sa_v2in6->pppol2tp.s_tunnel;
  509. info->peer_tunnel_id = sa_v2in6->pppol2tp.d_tunnel;
  510. info->session_id = sa_v2in6->pppol2tp.s_session;
  511. info->peer_session_id = sa_v2in6->pppol2tp.d_session;
  512. break;
  513. }
  514. case sizeof(struct sockaddr_pppol2tpv3in6):
  515. {
  516. const struct sockaddr_pppol2tpv3in6 *sa_v3in6 = sa;
  517. if (sa_v3in6->sa_protocol != PX_PROTO_OL2TP)
  518. return -EINVAL;
  519. info->version = 3;
  520. info->fd = sa_v3in6->pppol2tp.fd;
  521. info->tunnel_id = sa_v3in6->pppol2tp.s_tunnel;
  522. info->peer_tunnel_id = sa_v3in6->pppol2tp.d_tunnel;
  523. info->session_id = sa_v3in6->pppol2tp.s_session;
  524. info->peer_session_id = sa_v3in6->pppol2tp.d_session;
  525. break;
  526. }
  527. default:
  528. return -EINVAL;
  529. }
  530. return 0;
  531. }
  532. /* Rough estimation of the maximum payload size a tunnel can transmit without
  533. * fragmenting at the lower IP layer. Assumes L2TPv2 with sequence
  534. * numbers and no IP option. Not quite accurate, but the result is mostly
  535. * unused anyway.
  536. */
  537. static int pppol2tp_tunnel_mtu(const struct l2tp_tunnel *tunnel)
  538. {
  539. int mtu;
  540. mtu = l2tp_tunnel_dst_mtu(tunnel);
  541. if (mtu <= PPPOL2TP_HEADER_OVERHEAD)
  542. return 1500 - PPPOL2TP_HEADER_OVERHEAD;
  543. return mtu - PPPOL2TP_HEADER_OVERHEAD;
  544. }
  545. /* connect() handler. Attach a PPPoX socket to a tunnel UDP socket
  546. */
  547. static int pppol2tp_connect(struct socket *sock, struct sockaddr *uservaddr,
  548. int sockaddr_len, int flags)
  549. {
  550. struct sock *sk = sock->sk;
  551. struct pppox_sock *po = pppox_sk(sk);
  552. struct l2tp_session *session = NULL;
  553. struct l2tp_connect_info info;
  554. struct l2tp_tunnel *tunnel;
  555. struct pppol2tp_session *ps;
  556. struct l2tp_session_cfg cfg = { 0, };
  557. bool drop_refcnt = false;
  558. bool drop_tunnel = false;
  559. bool new_session = false;
  560. bool new_tunnel = false;
  561. int error;
  562. error = pppol2tp_sockaddr_get_info(uservaddr, sockaddr_len, &info);
  563. if (error < 0)
  564. return error;
  565. lock_sock(sk);
  566. /* Check for already bound sockets */
  567. error = -EBUSY;
  568. if (sk->sk_state & PPPOX_CONNECTED)
  569. goto end;
  570. /* We don't supporting rebinding anyway */
  571. error = -EALREADY;
  572. if (sk->sk_user_data)
  573. goto end; /* socket is already attached */
  574. /* Don't bind if tunnel_id is 0 */
  575. error = -EINVAL;
  576. if (!info.tunnel_id)
  577. goto end;
  578. tunnel = l2tp_tunnel_get(sock_net(sk), info.tunnel_id);
  579. if (tunnel)
  580. drop_tunnel = true;
  581. /* Special case: create tunnel context if session_id and
  582. * peer_session_id is 0. Otherwise look up tunnel using supplied
  583. * tunnel id.
  584. */
  585. if (!info.session_id && !info.peer_session_id) {
  586. if (tunnel == NULL) {
  587. struct l2tp_tunnel_cfg tcfg = {
  588. .encap = L2TP_ENCAPTYPE_UDP,
  589. .debug = 0,
  590. };
  591. /* Prevent l2tp_tunnel_register() from trying to set up
  592. * a kernel socket.
  593. */
  594. if (info.fd < 0) {
  595. error = -EBADF;
  596. goto end;
  597. }
  598. error = l2tp_tunnel_create(sock_net(sk), info.fd,
  599. info.version,
  600. info.tunnel_id,
  601. info.peer_tunnel_id, &tcfg,
  602. &tunnel);
  603. if (error < 0)
  604. goto end;
  605. l2tp_tunnel_inc_refcount(tunnel);
  606. error = l2tp_tunnel_register(tunnel, sock_net(sk),
  607. &tcfg);
  608. if (error < 0) {
  609. kfree(tunnel);
  610. goto end;
  611. }
  612. drop_tunnel = true;
  613. new_tunnel = true;
  614. }
  615. } else {
  616. /* Error if we can't find the tunnel */
  617. error = -ENOENT;
  618. if (tunnel == NULL)
  619. goto end;
  620. /* Error if socket is not prepped */
  621. if (tunnel->sock == NULL)
  622. goto end;
  623. }
  624. if (tunnel->peer_tunnel_id == 0)
  625. tunnel->peer_tunnel_id = info.peer_tunnel_id;
  626. session = l2tp_tunnel_get_session(tunnel, info.session_id);
  627. if (session) {
  628. drop_refcnt = true;
  629. if (session->pwtype != L2TP_PWTYPE_PPP) {
  630. error = -EPROTOTYPE;
  631. goto end;
  632. }
  633. ps = l2tp_session_priv(session);
  634. /* Using a pre-existing session is fine as long as it hasn't
  635. * been connected yet.
  636. */
  637. mutex_lock(&ps->sk_lock);
  638. if (rcu_dereference_protected(ps->sk,
  639. lockdep_is_held(&ps->sk_lock)) ||
  640. ps->__sk) {
  641. mutex_unlock(&ps->sk_lock);
  642. error = -EEXIST;
  643. goto end;
  644. }
  645. } else {
  646. cfg.pw_type = L2TP_PWTYPE_PPP;
  647. session = l2tp_session_create(sizeof(struct pppol2tp_session),
  648. tunnel, info.session_id,
  649. info.peer_session_id, &cfg);
  650. if (IS_ERR(session)) {
  651. error = PTR_ERR(session);
  652. goto end;
  653. }
  654. pppol2tp_session_init(session);
  655. ps = l2tp_session_priv(session);
  656. l2tp_session_inc_refcount(session);
  657. mutex_lock(&ps->sk_lock);
  658. error = l2tp_session_register(session, tunnel);
  659. if (error < 0) {
  660. mutex_unlock(&ps->sk_lock);
  661. kfree(session);
  662. goto end;
  663. }
  664. drop_refcnt = true;
  665. new_session = true;
  666. }
  667. /* Special case: if source & dest session_id == 0x0000, this
  668. * socket is being created to manage the tunnel. Just set up
  669. * the internal context for use by ioctl() and sockopt()
  670. * handlers.
  671. */
  672. if ((session->session_id == 0) &&
  673. (session->peer_session_id == 0)) {
  674. error = 0;
  675. goto out_no_ppp;
  676. }
  677. /* The only header we need to worry about is the L2TP
  678. * header. This size is different depending on whether
  679. * sequence numbers are enabled for the data channel.
  680. */
  681. po->chan.hdrlen = PPPOL2TP_L2TP_HDR_SIZE_NOSEQ;
  682. po->chan.private = sk;
  683. po->chan.ops = &pppol2tp_chan_ops;
  684. po->chan.mtu = pppol2tp_tunnel_mtu(tunnel);
  685. error = ppp_register_net_channel(sock_net(sk), &po->chan);
  686. if (error) {
  687. mutex_unlock(&ps->sk_lock);
  688. goto end;
  689. }
  690. out_no_ppp:
  691. /* This is how we get the session context from the socket. */
  692. sk->sk_user_data = session;
  693. rcu_assign_pointer(ps->sk, sk);
  694. mutex_unlock(&ps->sk_lock);
  695. /* Keep the reference we've grabbed on the session: sk doesn't expect
  696. * the session to disappear. pppol2tp_session_destruct() is responsible
  697. * for dropping it.
  698. */
  699. drop_refcnt = false;
  700. sk->sk_state = PPPOX_CONNECTED;
  701. l2tp_info(session, L2TP_MSG_CONTROL, "%s: created\n",
  702. session->name);
  703. end:
  704. if (error) {
  705. if (new_session)
  706. l2tp_session_delete(session);
  707. if (new_tunnel)
  708. l2tp_tunnel_delete(tunnel);
  709. }
  710. if (drop_refcnt)
  711. l2tp_session_dec_refcount(session);
  712. if (drop_tunnel)
  713. l2tp_tunnel_dec_refcount(tunnel);
  714. release_sock(sk);
  715. return error;
  716. }
  717. #ifdef CONFIG_L2TP_V3
  718. /* Called when creating sessions via the netlink interface. */
  719. static int pppol2tp_session_create(struct net *net, struct l2tp_tunnel *tunnel,
  720. u32 session_id, u32 peer_session_id,
  721. struct l2tp_session_cfg *cfg)
  722. {
  723. int error;
  724. struct l2tp_session *session;
  725. /* Error if tunnel socket is not prepped */
  726. if (!tunnel->sock) {
  727. error = -ENOENT;
  728. goto err;
  729. }
  730. /* Allocate and initialize a new session context. */
  731. session = l2tp_session_create(sizeof(struct pppol2tp_session),
  732. tunnel, session_id,
  733. peer_session_id, cfg);
  734. if (IS_ERR(session)) {
  735. error = PTR_ERR(session);
  736. goto err;
  737. }
  738. pppol2tp_session_init(session);
  739. error = l2tp_session_register(session, tunnel);
  740. if (error < 0)
  741. goto err_sess;
  742. return 0;
  743. err_sess:
  744. kfree(session);
  745. err:
  746. return error;
  747. }
  748. #endif /* CONFIG_L2TP_V3 */
  749. /* getname() support.
  750. */
  751. static int pppol2tp_getname(struct socket *sock, struct sockaddr *uaddr,
  752. int peer)
  753. {
  754. int len = 0;
  755. int error = 0;
  756. struct l2tp_session *session;
  757. struct l2tp_tunnel *tunnel;
  758. struct sock *sk = sock->sk;
  759. struct inet_sock *inet;
  760. struct pppol2tp_session *pls;
  761. error = -ENOTCONN;
  762. if (sk == NULL)
  763. goto end;
  764. if (!(sk->sk_state & PPPOX_CONNECTED))
  765. goto end;
  766. error = -EBADF;
  767. session = pppol2tp_sock_to_session(sk);
  768. if (session == NULL)
  769. goto end;
  770. pls = l2tp_session_priv(session);
  771. tunnel = session->tunnel;
  772. inet = inet_sk(tunnel->sock);
  773. if ((tunnel->version == 2) && (tunnel->sock->sk_family == AF_INET)) {
  774. struct sockaddr_pppol2tp sp;
  775. len = sizeof(sp);
  776. memset(&sp, 0, len);
  777. sp.sa_family = AF_PPPOX;
  778. sp.sa_protocol = PX_PROTO_OL2TP;
  779. sp.pppol2tp.fd = tunnel->fd;
  780. sp.pppol2tp.pid = pls->owner;
  781. sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
  782. sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
  783. sp.pppol2tp.s_session = session->session_id;
  784. sp.pppol2tp.d_session = session->peer_session_id;
  785. sp.pppol2tp.addr.sin_family = AF_INET;
  786. sp.pppol2tp.addr.sin_port = inet->inet_dport;
  787. sp.pppol2tp.addr.sin_addr.s_addr = inet->inet_daddr;
  788. memcpy(uaddr, &sp, len);
  789. #if IS_ENABLED(CONFIG_IPV6)
  790. } else if ((tunnel->version == 2) &&
  791. (tunnel->sock->sk_family == AF_INET6)) {
  792. struct sockaddr_pppol2tpin6 sp;
  793. len = sizeof(sp);
  794. memset(&sp, 0, len);
  795. sp.sa_family = AF_PPPOX;
  796. sp.sa_protocol = PX_PROTO_OL2TP;
  797. sp.pppol2tp.fd = tunnel->fd;
  798. sp.pppol2tp.pid = pls->owner;
  799. sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
  800. sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
  801. sp.pppol2tp.s_session = session->session_id;
  802. sp.pppol2tp.d_session = session->peer_session_id;
  803. sp.pppol2tp.addr.sin6_family = AF_INET6;
  804. sp.pppol2tp.addr.sin6_port = inet->inet_dport;
  805. memcpy(&sp.pppol2tp.addr.sin6_addr, &tunnel->sock->sk_v6_daddr,
  806. sizeof(tunnel->sock->sk_v6_daddr));
  807. memcpy(uaddr, &sp, len);
  808. } else if ((tunnel->version == 3) &&
  809. (tunnel->sock->sk_family == AF_INET6)) {
  810. struct sockaddr_pppol2tpv3in6 sp;
  811. len = sizeof(sp);
  812. memset(&sp, 0, len);
  813. sp.sa_family = AF_PPPOX;
  814. sp.sa_protocol = PX_PROTO_OL2TP;
  815. sp.pppol2tp.fd = tunnel->fd;
  816. sp.pppol2tp.pid = pls->owner;
  817. sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
  818. sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
  819. sp.pppol2tp.s_session = session->session_id;
  820. sp.pppol2tp.d_session = session->peer_session_id;
  821. sp.pppol2tp.addr.sin6_family = AF_INET6;
  822. sp.pppol2tp.addr.sin6_port = inet->inet_dport;
  823. memcpy(&sp.pppol2tp.addr.sin6_addr, &tunnel->sock->sk_v6_daddr,
  824. sizeof(tunnel->sock->sk_v6_daddr));
  825. memcpy(uaddr, &sp, len);
  826. #endif
  827. } else if (tunnel->version == 3) {
  828. struct sockaddr_pppol2tpv3 sp;
  829. len = sizeof(sp);
  830. memset(&sp, 0, len);
  831. sp.sa_family = AF_PPPOX;
  832. sp.sa_protocol = PX_PROTO_OL2TP;
  833. sp.pppol2tp.fd = tunnel->fd;
  834. sp.pppol2tp.pid = pls->owner;
  835. sp.pppol2tp.s_tunnel = tunnel->tunnel_id;
  836. sp.pppol2tp.d_tunnel = tunnel->peer_tunnel_id;
  837. sp.pppol2tp.s_session = session->session_id;
  838. sp.pppol2tp.d_session = session->peer_session_id;
  839. sp.pppol2tp.addr.sin_family = AF_INET;
  840. sp.pppol2tp.addr.sin_port = inet->inet_dport;
  841. sp.pppol2tp.addr.sin_addr.s_addr = inet->inet_daddr;
  842. memcpy(uaddr, &sp, len);
  843. }
  844. error = len;
  845. sock_put(sk);
  846. end:
  847. return error;
  848. }
  849. /****************************************************************************
  850. * ioctl() handlers.
  851. *
  852. * The PPPoX socket is created for L2TP sessions: tunnels have their own UDP
  853. * sockets. However, in order to control kernel tunnel features, we allow
  854. * userspace to create a special "tunnel" PPPoX socket which is used for
  855. * control only. Tunnel PPPoX sockets have session_id == 0 and simply allow
  856. * the user application to issue L2TP setsockopt(), getsockopt() and ioctl()
  857. * calls.
  858. ****************************************************************************/
  859. static void pppol2tp_copy_stats(struct pppol2tp_ioc_stats *dest,
  860. const struct l2tp_stats *stats)
  861. {
  862. memset(dest, 0, sizeof(*dest));
  863. dest->tx_packets = atomic_long_read(&stats->tx_packets);
  864. dest->tx_bytes = atomic_long_read(&stats->tx_bytes);
  865. dest->tx_errors = atomic_long_read(&stats->tx_errors);
  866. dest->rx_packets = atomic_long_read(&stats->rx_packets);
  867. dest->rx_bytes = atomic_long_read(&stats->rx_bytes);
  868. dest->rx_seq_discards = atomic_long_read(&stats->rx_seq_discards);
  869. dest->rx_oos_packets = atomic_long_read(&stats->rx_oos_packets);
  870. dest->rx_errors = atomic_long_read(&stats->rx_errors);
  871. }
  872. static int pppol2tp_tunnel_copy_stats(struct pppol2tp_ioc_stats *stats,
  873. struct l2tp_tunnel *tunnel)
  874. {
  875. struct l2tp_session *session;
  876. if (!stats->session_id) {
  877. pppol2tp_copy_stats(stats, &tunnel->stats);
  878. return 0;
  879. }
  880. /* If session_id is set, search the corresponding session in the
  881. * context of this tunnel and record the session's statistics.
  882. */
  883. session = l2tp_tunnel_get_session(tunnel, stats->session_id);
  884. if (!session)
  885. return -EBADR;
  886. if (session->pwtype != L2TP_PWTYPE_PPP) {
  887. l2tp_session_dec_refcount(session);
  888. return -EBADR;
  889. }
  890. pppol2tp_copy_stats(stats, &session->stats);
  891. l2tp_session_dec_refcount(session);
  892. return 0;
  893. }
  894. static int pppol2tp_ioctl(struct socket *sock, unsigned int cmd,
  895. unsigned long arg)
  896. {
  897. struct pppol2tp_ioc_stats stats;
  898. struct l2tp_session *session;
  899. int val;
  900. switch (cmd) {
  901. case PPPIOCGMRU:
  902. case PPPIOCGFLAGS:
  903. session = sock->sk->sk_user_data;
  904. if (!session)
  905. return -ENOTCONN;
  906. /* Not defined for tunnels */
  907. if (!session->session_id && !session->peer_session_id)
  908. return -ENOSYS;
  909. if (put_user(0, (int __user *)arg))
  910. return -EFAULT;
  911. break;
  912. case PPPIOCSMRU:
  913. case PPPIOCSFLAGS:
  914. session = sock->sk->sk_user_data;
  915. if (!session)
  916. return -ENOTCONN;
  917. /* Not defined for tunnels */
  918. if (!session->session_id && !session->peer_session_id)
  919. return -ENOSYS;
  920. if (get_user(val, (int __user *)arg))
  921. return -EFAULT;
  922. break;
  923. case PPPIOCGL2TPSTATS:
  924. session = sock->sk->sk_user_data;
  925. if (!session)
  926. return -ENOTCONN;
  927. /* Session 0 represents the parent tunnel */
  928. if (!session->session_id && !session->peer_session_id) {
  929. u32 session_id;
  930. int err;
  931. if (copy_from_user(&stats, (void __user *)arg,
  932. sizeof(stats)))
  933. return -EFAULT;
  934. session_id = stats.session_id;
  935. err = pppol2tp_tunnel_copy_stats(&stats,
  936. session->tunnel);
  937. if (err < 0)
  938. return err;
  939. stats.session_id = session_id;
  940. } else {
  941. pppol2tp_copy_stats(&stats, &session->stats);
  942. stats.session_id = session->session_id;
  943. }
  944. stats.tunnel_id = session->tunnel->tunnel_id;
  945. stats.using_ipsec = l2tp_tunnel_uses_xfrm(session->tunnel);
  946. if (copy_to_user((void __user *)arg, &stats, sizeof(stats)))
  947. return -EFAULT;
  948. break;
  949. default:
  950. return -ENOIOCTLCMD;
  951. }
  952. return 0;
  953. }
  954. /*****************************************************************************
  955. * setsockopt() / getsockopt() support.
  956. *
  957. * The PPPoX socket is created for L2TP sessions: tunnels have their own UDP
  958. * sockets. In order to control kernel tunnel features, we allow userspace to
  959. * create a special "tunnel" PPPoX socket which is used for control only.
  960. * Tunnel PPPoX sockets have session_id == 0 and simply allow the user
  961. * application to issue L2TP setsockopt(), getsockopt() and ioctl() calls.
  962. *****************************************************************************/
  963. /* Tunnel setsockopt() helper.
  964. */
  965. static int pppol2tp_tunnel_setsockopt(struct sock *sk,
  966. struct l2tp_tunnel *tunnel,
  967. int optname, int val)
  968. {
  969. int err = 0;
  970. switch (optname) {
  971. case PPPOL2TP_SO_DEBUG:
  972. tunnel->debug = val;
  973. l2tp_info(tunnel, L2TP_MSG_CONTROL, "%s: set debug=%x\n",
  974. tunnel->name, tunnel->debug);
  975. break;
  976. default:
  977. err = -ENOPROTOOPT;
  978. break;
  979. }
  980. return err;
  981. }
  982. /* Session setsockopt helper.
  983. */
  984. static int pppol2tp_session_setsockopt(struct sock *sk,
  985. struct l2tp_session *session,
  986. int optname, int val)
  987. {
  988. int err = 0;
  989. switch (optname) {
  990. case PPPOL2TP_SO_RECVSEQ:
  991. if ((val != 0) && (val != 1)) {
  992. err = -EINVAL;
  993. break;
  994. }
  995. session->recv_seq = !!val;
  996. l2tp_info(session, L2TP_MSG_CONTROL,
  997. "%s: set recv_seq=%d\n",
  998. session->name, session->recv_seq);
  999. break;
  1000. case PPPOL2TP_SO_SENDSEQ:
  1001. if ((val != 0) && (val != 1)) {
  1002. err = -EINVAL;
  1003. break;
  1004. }
  1005. session->send_seq = !!val;
  1006. {
  1007. struct pppox_sock *po = pppox_sk(sk);
  1008. po->chan.hdrlen = val ? PPPOL2TP_L2TP_HDR_SIZE_SEQ :
  1009. PPPOL2TP_L2TP_HDR_SIZE_NOSEQ;
  1010. }
  1011. l2tp_session_set_header_len(session, session->tunnel->version);
  1012. l2tp_info(session, L2TP_MSG_CONTROL,
  1013. "%s: set send_seq=%d\n",
  1014. session->name, session->send_seq);
  1015. break;
  1016. case PPPOL2TP_SO_LNSMODE:
  1017. if ((val != 0) && (val != 1)) {
  1018. err = -EINVAL;
  1019. break;
  1020. }
  1021. session->lns_mode = !!val;
  1022. l2tp_info(session, L2TP_MSG_CONTROL,
  1023. "%s: set lns_mode=%d\n",
  1024. session->name, session->lns_mode);
  1025. break;
  1026. case PPPOL2TP_SO_DEBUG:
  1027. session->debug = val;
  1028. l2tp_info(session, L2TP_MSG_CONTROL, "%s: set debug=%x\n",
  1029. session->name, session->debug);
  1030. break;
  1031. case PPPOL2TP_SO_REORDERTO:
  1032. session->reorder_timeout = msecs_to_jiffies(val);
  1033. l2tp_info(session, L2TP_MSG_CONTROL,
  1034. "%s: set reorder_timeout=%d\n",
  1035. session->name, session->reorder_timeout);
  1036. break;
  1037. default:
  1038. err = -ENOPROTOOPT;
  1039. break;
  1040. }
  1041. return err;
  1042. }
  1043. /* Main setsockopt() entry point.
  1044. * Does API checks, then calls either the tunnel or session setsockopt
  1045. * handler, according to whether the PPPoL2TP socket is a for a regular
  1046. * session or the special tunnel type.
  1047. */
  1048. static int pppol2tp_setsockopt(struct socket *sock, int level, int optname,
  1049. char __user *optval, unsigned int optlen)
  1050. {
  1051. struct sock *sk = sock->sk;
  1052. struct l2tp_session *session;
  1053. struct l2tp_tunnel *tunnel;
  1054. int val;
  1055. int err;
  1056. if (level != SOL_PPPOL2TP)
  1057. return -EINVAL;
  1058. if (optlen < sizeof(int))
  1059. return -EINVAL;
  1060. if (get_user(val, (int __user *)optval))
  1061. return -EFAULT;
  1062. err = -ENOTCONN;
  1063. if (sk->sk_user_data == NULL)
  1064. goto end;
  1065. /* Get session context from the socket */
  1066. err = -EBADF;
  1067. session = pppol2tp_sock_to_session(sk);
  1068. if (session == NULL)
  1069. goto end;
  1070. /* Special case: if session_id == 0x0000, treat as operation on tunnel
  1071. */
  1072. if ((session->session_id == 0) &&
  1073. (session->peer_session_id == 0)) {
  1074. tunnel = session->tunnel;
  1075. err = pppol2tp_tunnel_setsockopt(sk, tunnel, optname, val);
  1076. } else {
  1077. err = pppol2tp_session_setsockopt(sk, session, optname, val);
  1078. }
  1079. sock_put(sk);
  1080. end:
  1081. return err;
  1082. }
  1083. /* Tunnel getsockopt helper. Called with sock locked.
  1084. */
  1085. static int pppol2tp_tunnel_getsockopt(struct sock *sk,
  1086. struct l2tp_tunnel *tunnel,
  1087. int optname, int *val)
  1088. {
  1089. int err = 0;
  1090. switch (optname) {
  1091. case PPPOL2TP_SO_DEBUG:
  1092. *val = tunnel->debug;
  1093. l2tp_info(tunnel, L2TP_MSG_CONTROL, "%s: get debug=%x\n",
  1094. tunnel->name, tunnel->debug);
  1095. break;
  1096. default:
  1097. err = -ENOPROTOOPT;
  1098. break;
  1099. }
  1100. return err;
  1101. }
  1102. /* Session getsockopt helper. Called with sock locked.
  1103. */
  1104. static int pppol2tp_session_getsockopt(struct sock *sk,
  1105. struct l2tp_session *session,
  1106. int optname, int *val)
  1107. {
  1108. int err = 0;
  1109. switch (optname) {
  1110. case PPPOL2TP_SO_RECVSEQ:
  1111. *val = session->recv_seq;
  1112. l2tp_info(session, L2TP_MSG_CONTROL,
  1113. "%s: get recv_seq=%d\n", session->name, *val);
  1114. break;
  1115. case PPPOL2TP_SO_SENDSEQ:
  1116. *val = session->send_seq;
  1117. l2tp_info(session, L2TP_MSG_CONTROL,
  1118. "%s: get send_seq=%d\n", session->name, *val);
  1119. break;
  1120. case PPPOL2TP_SO_LNSMODE:
  1121. *val = session->lns_mode;
  1122. l2tp_info(session, L2TP_MSG_CONTROL,
  1123. "%s: get lns_mode=%d\n", session->name, *val);
  1124. break;
  1125. case PPPOL2TP_SO_DEBUG:
  1126. *val = session->debug;
  1127. l2tp_info(session, L2TP_MSG_CONTROL, "%s: get debug=%d\n",
  1128. session->name, *val);
  1129. break;
  1130. case PPPOL2TP_SO_REORDERTO:
  1131. *val = (int) jiffies_to_msecs(session->reorder_timeout);
  1132. l2tp_info(session, L2TP_MSG_CONTROL,
  1133. "%s: get reorder_timeout=%d\n", session->name, *val);
  1134. break;
  1135. default:
  1136. err = -ENOPROTOOPT;
  1137. }
  1138. return err;
  1139. }
  1140. /* Main getsockopt() entry point.
  1141. * Does API checks, then calls either the tunnel or session getsockopt
  1142. * handler, according to whether the PPPoX socket is a for a regular session
  1143. * or the special tunnel type.
  1144. */
  1145. static int pppol2tp_getsockopt(struct socket *sock, int level, int optname,
  1146. char __user *optval, int __user *optlen)
  1147. {
  1148. struct sock *sk = sock->sk;
  1149. struct l2tp_session *session;
  1150. struct l2tp_tunnel *tunnel;
  1151. int val, len;
  1152. int err;
  1153. if (level != SOL_PPPOL2TP)
  1154. return -EINVAL;
  1155. if (get_user(len, optlen))
  1156. return -EFAULT;
  1157. len = min_t(unsigned int, len, sizeof(int));
  1158. if (len < 0)
  1159. return -EINVAL;
  1160. err = -ENOTCONN;
  1161. if (sk->sk_user_data == NULL)
  1162. goto end;
  1163. /* Get the session context */
  1164. err = -EBADF;
  1165. session = pppol2tp_sock_to_session(sk);
  1166. if (session == NULL)
  1167. goto end;
  1168. /* Special case: if session_id == 0x0000, treat as operation on tunnel */
  1169. if ((session->session_id == 0) &&
  1170. (session->peer_session_id == 0)) {
  1171. tunnel = session->tunnel;
  1172. err = pppol2tp_tunnel_getsockopt(sk, tunnel, optname, &val);
  1173. if (err)
  1174. goto end_put_sess;
  1175. } else {
  1176. err = pppol2tp_session_getsockopt(sk, session, optname, &val);
  1177. if (err)
  1178. goto end_put_sess;
  1179. }
  1180. err = -EFAULT;
  1181. if (put_user(len, optlen))
  1182. goto end_put_sess;
  1183. if (copy_to_user((void __user *) optval, &val, len))
  1184. goto end_put_sess;
  1185. err = 0;
  1186. end_put_sess:
  1187. sock_put(sk);
  1188. end:
  1189. return err;
  1190. }
  1191. /*****************************************************************************
  1192. * /proc filesystem for debug
  1193. * Since the original pppol2tp driver provided /proc/net/pppol2tp for
  1194. * L2TPv2, we dump only L2TPv2 tunnels and sessions here.
  1195. *****************************************************************************/
  1196. static unsigned int pppol2tp_net_id;
  1197. #ifdef CONFIG_PROC_FS
  1198. struct pppol2tp_seq_data {
  1199. struct seq_net_private p;
  1200. int tunnel_idx; /* current tunnel */
  1201. int session_idx; /* index of session within current tunnel */
  1202. struct l2tp_tunnel *tunnel;
  1203. struct l2tp_session *session; /* NULL means get next tunnel */
  1204. };
  1205. static void pppol2tp_next_tunnel(struct net *net, struct pppol2tp_seq_data *pd)
  1206. {
  1207. /* Drop reference taken during previous invocation */
  1208. if (pd->tunnel)
  1209. l2tp_tunnel_dec_refcount(pd->tunnel);
  1210. for (;;) {
  1211. pd->tunnel = l2tp_tunnel_get_nth(net, pd->tunnel_idx);
  1212. pd->tunnel_idx++;
  1213. /* Only accept L2TPv2 tunnels */
  1214. if (!pd->tunnel || pd->tunnel->version == 2)
  1215. return;
  1216. l2tp_tunnel_dec_refcount(pd->tunnel);
  1217. }
  1218. }
  1219. static void pppol2tp_next_session(struct net *net, struct pppol2tp_seq_data *pd)
  1220. {
  1221. /* Drop reference taken during previous invocation */
  1222. if (pd->session)
  1223. l2tp_session_dec_refcount(pd->session);
  1224. pd->session = l2tp_session_get_nth(pd->tunnel, pd->session_idx);
  1225. pd->session_idx++;
  1226. if (pd->session == NULL) {
  1227. pd->session_idx = 0;
  1228. pppol2tp_next_tunnel(net, pd);
  1229. }
  1230. }
  1231. static void *pppol2tp_seq_start(struct seq_file *m, loff_t *offs)
  1232. {
  1233. struct pppol2tp_seq_data *pd = SEQ_START_TOKEN;
  1234. loff_t pos = *offs;
  1235. struct net *net;
  1236. if (!pos)
  1237. goto out;
  1238. BUG_ON(m->private == NULL);
  1239. pd = m->private;
  1240. net = seq_file_net(m);
  1241. if (pd->tunnel == NULL)
  1242. pppol2tp_next_tunnel(net, pd);
  1243. else
  1244. pppol2tp_next_session(net, pd);
  1245. /* NULL tunnel and session indicates end of list */
  1246. if ((pd->tunnel == NULL) && (pd->session == NULL))
  1247. pd = NULL;
  1248. out:
  1249. return pd;
  1250. }
  1251. static void *pppol2tp_seq_next(struct seq_file *m, void *v, loff_t *pos)
  1252. {
  1253. (*pos)++;
  1254. return NULL;
  1255. }
  1256. static void pppol2tp_seq_stop(struct seq_file *p, void *v)
  1257. {
  1258. struct pppol2tp_seq_data *pd = v;
  1259. if (!pd || pd == SEQ_START_TOKEN)
  1260. return;
  1261. /* Drop reference taken by last invocation of pppol2tp_next_session()
  1262. * or pppol2tp_next_tunnel().
  1263. */
  1264. if (pd->session) {
  1265. l2tp_session_dec_refcount(pd->session);
  1266. pd->session = NULL;
  1267. }
  1268. if (pd->tunnel) {
  1269. l2tp_tunnel_dec_refcount(pd->tunnel);
  1270. pd->tunnel = NULL;
  1271. }
  1272. }
  1273. static void pppol2tp_seq_tunnel_show(struct seq_file *m, void *v)
  1274. {
  1275. struct l2tp_tunnel *tunnel = v;
  1276. seq_printf(m, "\nTUNNEL '%s', %c %d\n",
  1277. tunnel->name,
  1278. (tunnel == tunnel->sock->sk_user_data) ? 'Y' : 'N',
  1279. refcount_read(&tunnel->ref_count) - 1);
  1280. seq_printf(m, " %08x %ld/%ld/%ld %ld/%ld/%ld\n",
  1281. tunnel->debug,
  1282. atomic_long_read(&tunnel->stats.tx_packets),
  1283. atomic_long_read(&tunnel->stats.tx_bytes),
  1284. atomic_long_read(&tunnel->stats.tx_errors),
  1285. atomic_long_read(&tunnel->stats.rx_packets),
  1286. atomic_long_read(&tunnel->stats.rx_bytes),
  1287. atomic_long_read(&tunnel->stats.rx_errors));
  1288. }
  1289. static void pppol2tp_seq_session_show(struct seq_file *m, void *v)
  1290. {
  1291. struct l2tp_session *session = v;
  1292. struct l2tp_tunnel *tunnel = session->tunnel;
  1293. unsigned char state;
  1294. char user_data_ok;
  1295. struct sock *sk;
  1296. u32 ip = 0;
  1297. u16 port = 0;
  1298. if (tunnel->sock) {
  1299. struct inet_sock *inet = inet_sk(tunnel->sock);
  1300. ip = ntohl(inet->inet_saddr);
  1301. port = ntohs(inet->inet_sport);
  1302. }
  1303. sk = pppol2tp_session_get_sock(session);
  1304. if (sk) {
  1305. state = sk->sk_state;
  1306. user_data_ok = (session == sk->sk_user_data) ? 'Y' : 'N';
  1307. } else {
  1308. state = 0;
  1309. user_data_ok = 'N';
  1310. }
  1311. seq_printf(m, " SESSION '%s' %08X/%d %04X/%04X -> "
  1312. "%04X/%04X %d %c\n",
  1313. session->name, ip, port,
  1314. tunnel->tunnel_id,
  1315. session->session_id,
  1316. tunnel->peer_tunnel_id,
  1317. session->peer_session_id,
  1318. state, user_data_ok);
  1319. seq_printf(m, " 0/0/%c/%c/%s %08x %u\n",
  1320. session->recv_seq ? 'R' : '-',
  1321. session->send_seq ? 'S' : '-',
  1322. session->lns_mode ? "LNS" : "LAC",
  1323. session->debug,
  1324. jiffies_to_msecs(session->reorder_timeout));
  1325. seq_printf(m, " %hu/%hu %ld/%ld/%ld %ld/%ld/%ld\n",
  1326. session->nr, session->ns,
  1327. atomic_long_read(&session->stats.tx_packets),
  1328. atomic_long_read(&session->stats.tx_bytes),
  1329. atomic_long_read(&session->stats.tx_errors),
  1330. atomic_long_read(&session->stats.rx_packets),
  1331. atomic_long_read(&session->stats.rx_bytes),
  1332. atomic_long_read(&session->stats.rx_errors));
  1333. if (sk) {
  1334. struct pppox_sock *po = pppox_sk(sk);
  1335. seq_printf(m, " interface %s\n", ppp_dev_name(&po->chan));
  1336. sock_put(sk);
  1337. }
  1338. }
  1339. static int pppol2tp_seq_show(struct seq_file *m, void *v)
  1340. {
  1341. struct pppol2tp_seq_data *pd = v;
  1342. /* display header on line 1 */
  1343. if (v == SEQ_START_TOKEN) {
  1344. seq_puts(m, "PPPoL2TP driver info, " PPPOL2TP_DRV_VERSION "\n");
  1345. seq_puts(m, "TUNNEL name, user-data-ok session-count\n");
  1346. seq_puts(m, " debug tx-pkts/bytes/errs rx-pkts/bytes/errs\n");
  1347. seq_puts(m, " SESSION name, addr/port src-tid/sid "
  1348. "dest-tid/sid state user-data-ok\n");
  1349. seq_puts(m, " mtu/mru/rcvseq/sendseq/lns debug reorderto\n");
  1350. seq_puts(m, " nr/ns tx-pkts/bytes/errs rx-pkts/bytes/errs\n");
  1351. goto out;
  1352. }
  1353. if (!pd->session)
  1354. pppol2tp_seq_tunnel_show(m, pd->tunnel);
  1355. else
  1356. pppol2tp_seq_session_show(m, pd->session);
  1357. out:
  1358. return 0;
  1359. }
  1360. static const struct seq_operations pppol2tp_seq_ops = {
  1361. .start = pppol2tp_seq_start,
  1362. .next = pppol2tp_seq_next,
  1363. .stop = pppol2tp_seq_stop,
  1364. .show = pppol2tp_seq_show,
  1365. };
  1366. #endif /* CONFIG_PROC_FS */
  1367. /*****************************************************************************
  1368. * Network namespace
  1369. *****************************************************************************/
  1370. static __net_init int pppol2tp_init_net(struct net *net)
  1371. {
  1372. struct proc_dir_entry *pde;
  1373. int err = 0;
  1374. pde = proc_create_net("pppol2tp", 0444, net->proc_net,
  1375. &pppol2tp_seq_ops, sizeof(struct pppol2tp_seq_data));
  1376. if (!pde) {
  1377. err = -ENOMEM;
  1378. goto out;
  1379. }
  1380. out:
  1381. return err;
  1382. }
  1383. static __net_exit void pppol2tp_exit_net(struct net *net)
  1384. {
  1385. remove_proc_entry("pppol2tp", net->proc_net);
  1386. }
  1387. static struct pernet_operations pppol2tp_net_ops = {
  1388. .init = pppol2tp_init_net,
  1389. .exit = pppol2tp_exit_net,
  1390. .id = &pppol2tp_net_id,
  1391. };
  1392. /*****************************************************************************
  1393. * Init and cleanup
  1394. *****************************************************************************/
  1395. static const struct proto_ops pppol2tp_ops = {
  1396. .family = AF_PPPOX,
  1397. .owner = THIS_MODULE,
  1398. .release = pppol2tp_release,
  1399. .bind = sock_no_bind,
  1400. .connect = pppol2tp_connect,
  1401. .socketpair = sock_no_socketpair,
  1402. .accept = sock_no_accept,
  1403. .getname = pppol2tp_getname,
  1404. .poll = datagram_poll,
  1405. .listen = sock_no_listen,
  1406. .shutdown = sock_no_shutdown,
  1407. .setsockopt = pppol2tp_setsockopt,
  1408. .getsockopt = pppol2tp_getsockopt,
  1409. .sendmsg = pppol2tp_sendmsg,
  1410. .recvmsg = pppol2tp_recvmsg,
  1411. .mmap = sock_no_mmap,
  1412. .ioctl = pppox_ioctl,
  1413. #ifdef CONFIG_COMPAT
  1414. .compat_ioctl = pppox_compat_ioctl,
  1415. #endif
  1416. };
  1417. static const struct pppox_proto pppol2tp_proto = {
  1418. .create = pppol2tp_create,
  1419. .ioctl = pppol2tp_ioctl,
  1420. .owner = THIS_MODULE,
  1421. };
  1422. #ifdef CONFIG_L2TP_V3
  1423. static const struct l2tp_nl_cmd_ops pppol2tp_nl_cmd_ops = {
  1424. .session_create = pppol2tp_session_create,
  1425. .session_delete = l2tp_session_delete,
  1426. };
  1427. #endif /* CONFIG_L2TP_V3 */
  1428. static int __init pppol2tp_init(void)
  1429. {
  1430. int err;
  1431. err = register_pernet_device(&pppol2tp_net_ops);
  1432. if (err)
  1433. goto out;
  1434. err = proto_register(&pppol2tp_sk_proto, 0);
  1435. if (err)
  1436. goto out_unregister_pppol2tp_pernet;
  1437. err = register_pppox_proto(PX_PROTO_OL2TP, &pppol2tp_proto);
  1438. if (err)
  1439. goto out_unregister_pppol2tp_proto;
  1440. #ifdef CONFIG_L2TP_V3
  1441. err = l2tp_nl_register_ops(L2TP_PWTYPE_PPP, &pppol2tp_nl_cmd_ops);
  1442. if (err)
  1443. goto out_unregister_pppox;
  1444. #endif
  1445. pr_info("PPPoL2TP kernel driver, %s\n", PPPOL2TP_DRV_VERSION);
  1446. out:
  1447. return err;
  1448. #ifdef CONFIG_L2TP_V3
  1449. out_unregister_pppox:
  1450. unregister_pppox_proto(PX_PROTO_OL2TP);
  1451. #endif
  1452. out_unregister_pppol2tp_proto:
  1453. proto_unregister(&pppol2tp_sk_proto);
  1454. out_unregister_pppol2tp_pernet:
  1455. unregister_pernet_device(&pppol2tp_net_ops);
  1456. goto out;
  1457. }
  1458. static void __exit pppol2tp_exit(void)
  1459. {
  1460. #ifdef CONFIG_L2TP_V3
  1461. l2tp_nl_unregister_ops(L2TP_PWTYPE_PPP);
  1462. #endif
  1463. unregister_pppox_proto(PX_PROTO_OL2TP);
  1464. proto_unregister(&pppol2tp_sk_proto);
  1465. unregister_pernet_device(&pppol2tp_net_ops);
  1466. }
  1467. module_init(pppol2tp_init);
  1468. module_exit(pppol2tp_exit);
  1469. MODULE_AUTHOR("James Chapman <jchapman@katalix.com>");
  1470. MODULE_DESCRIPTION("PPP over L2TP over UDP");
  1471. MODULE_LICENSE("GPL");
  1472. MODULE_VERSION(PPPOL2TP_DRV_VERSION);
  1473. MODULE_ALIAS_NET_PF_PROTO(PF_PPPOX, PX_PROTO_OL2TP);
  1474. MODULE_ALIAS_L2TP_PWTYPE(7);