1 /* SPDX-License-Identifier: GPL-2.0-or-later */
2 /* SCTP kernel implementation
3  * (C) Copyright IBM Corp. 2001, 2004
4  * Copyright (c) 1999-2000 Cisco, Inc.
5  * Copyright (c) 1999-2001 Motorola, Inc.
6  * Copyright (c) 2001 Intel Corp.
7  *
8  * This file is part of the SCTP kernel implementation
9  *
10  * These are definitions needed by the state machine.
11  *
12  * Please send any bug reports or fixes you make to the
13  * email addresses:
14  *    lksctp developers <linux-sctp@vger.kernel.org>
15  *
16  * Written or modified by:
17  *    La Monte H.P. Yarroll <piggy@acm.org>
18  *    Karl Knutson <karl@athena.chicago.il.us>
19  *    Xingang Guo <xingang.guo@intel.com>
20  *    Jon Grimm <jgrimm@us.ibm.com>
21  *    Dajiang Zhang <dajiang.zhang@nokia.com>
22  *    Sridhar Samudrala <sri@us.ibm.com>
23  *    Daisy Chang <daisyc@us.ibm.com>
24  *    Ardelle Fan <ardelle.fan@intel.com>
25  *    Kevin Gao <kevin.gao@intel.com>
26  */
27 
28 #include <linux/types.h>
29 #include <linux/compiler.h>
30 #include <linux/slab.h>
31 #include <linux/in.h>
32 #include <net/sctp/command.h>
33 #include <net/sctp/sctp.h>
34 
35 #ifndef __sctp_sm_h__
36 #define __sctp_sm_h__
37 
38 /*
39  * Possible values for the disposition are:
40  */
41 enum sctp_disposition {
42 	SCTP_DISPOSITION_DISCARD,	 /* No further processing.  */
43 	SCTP_DISPOSITION_CONSUME,	 /* Process return values normally.  */
44 	SCTP_DISPOSITION_NOMEM,		 /* We ran out of memory--recover.  */
45 	SCTP_DISPOSITION_DELETE_TCB,	 /* Close the association.  */
46 	SCTP_DISPOSITION_ABORT,		 /* Close the association NOW.  */
47 	SCTP_DISPOSITION_VIOLATION,	 /* The peer is misbehaving.  */
48 	SCTP_DISPOSITION_NOT_IMPL,	 /* This entry is not implemented.  */
49 	SCTP_DISPOSITION_ERROR,		 /* This is plain old user error.  */
50 	SCTP_DISPOSITION_BUG,		 /* This is a bug.  */
51 };
52 
53 typedef enum sctp_disposition (sctp_state_fn_t) (
54 					struct net *net,
55 					const struct sctp_endpoint *ep,
56 					const struct sctp_association *asoc,
57 					const union sctp_subtype type,
58 					void *arg,
59 					struct sctp_cmd_seq *commands);
60 typedef void (sctp_timer_event_t) (struct timer_list *);
61 struct sctp_sm_table_entry {
62 	sctp_state_fn_t *fn;
63 	const char *name;
64 };
65 
66 /* A naming convention of "sctp_sf_xxx" applies to all the state functions
67  * currently in use.
68  */
69 
70 /* Prototypes for generic state functions. */
71 sctp_state_fn_t sctp_sf_not_impl;
72 sctp_state_fn_t sctp_sf_bug;
73 
74 /* Prototypes for gener timer state functions. */
75 sctp_state_fn_t sctp_sf_timer_ignore;
76 
77 /* Prototypes for chunk state functions. */
78 sctp_state_fn_t sctp_sf_do_9_1_abort;
79 sctp_state_fn_t sctp_sf_cookie_wait_abort;
80 sctp_state_fn_t sctp_sf_cookie_echoed_abort;
81 sctp_state_fn_t sctp_sf_shutdown_pending_abort;
82 sctp_state_fn_t sctp_sf_shutdown_sent_abort;
83 sctp_state_fn_t sctp_sf_shutdown_ack_sent_abort;
84 sctp_state_fn_t sctp_sf_do_5_1B_init;
85 sctp_state_fn_t sctp_sf_do_5_1C_ack;
86 sctp_state_fn_t sctp_sf_do_5_1D_ce;
87 sctp_state_fn_t sctp_sf_do_5_1E_ca;
88 sctp_state_fn_t sctp_sf_do_4_C;
89 sctp_state_fn_t sctp_sf_eat_data_6_2;
90 sctp_state_fn_t sctp_sf_eat_data_fast_4_4;
91 sctp_state_fn_t sctp_sf_eat_sack_6_2;
92 sctp_state_fn_t sctp_sf_operr_notify;
93 sctp_state_fn_t sctp_sf_t1_init_timer_expire;
94 sctp_state_fn_t sctp_sf_t1_cookie_timer_expire;
95 sctp_state_fn_t sctp_sf_t2_timer_expire;
96 sctp_state_fn_t sctp_sf_t4_timer_expire;
97 sctp_state_fn_t sctp_sf_t5_timer_expire;
98 sctp_state_fn_t sctp_sf_sendbeat_8_3;
99 sctp_state_fn_t sctp_sf_beat_8_3;
100 sctp_state_fn_t sctp_sf_backbeat_8_3;
101 sctp_state_fn_t sctp_sf_do_9_2_final;
102 sctp_state_fn_t sctp_sf_do_9_2_shutdown;
103 sctp_state_fn_t sctp_sf_do_9_2_shut_ctsn;
104 sctp_state_fn_t sctp_sf_do_ecn_cwr;
105 sctp_state_fn_t sctp_sf_do_ecne;
106 sctp_state_fn_t sctp_sf_ootb;
107 sctp_state_fn_t sctp_sf_pdiscard;
108 sctp_state_fn_t sctp_sf_violation;
109 sctp_state_fn_t sctp_sf_discard_chunk;
110 sctp_state_fn_t sctp_sf_do_5_2_1_siminit;
111 sctp_state_fn_t sctp_sf_do_5_2_2_dupinit;
112 sctp_state_fn_t sctp_sf_do_5_2_3_initack;
113 sctp_state_fn_t sctp_sf_do_5_2_4_dupcook;
114 sctp_state_fn_t sctp_sf_unk_chunk;
115 sctp_state_fn_t sctp_sf_do_8_5_1_E_sa;
116 sctp_state_fn_t sctp_sf_cookie_echoed_err;
117 sctp_state_fn_t sctp_sf_do_asconf;
118 sctp_state_fn_t sctp_sf_do_asconf_ack;
119 sctp_state_fn_t sctp_sf_do_reconf;
120 sctp_state_fn_t sctp_sf_do_9_2_reshutack;
121 sctp_state_fn_t sctp_sf_eat_fwd_tsn;
122 sctp_state_fn_t sctp_sf_eat_fwd_tsn_fast;
123 sctp_state_fn_t sctp_sf_eat_auth;
124 
125 /* Prototypes for primitive event state functions.  */
126 sctp_state_fn_t sctp_sf_do_prm_asoc;
127 sctp_state_fn_t sctp_sf_do_prm_send;
128 sctp_state_fn_t sctp_sf_do_9_2_prm_shutdown;
129 sctp_state_fn_t sctp_sf_cookie_wait_prm_shutdown;
130 sctp_state_fn_t sctp_sf_cookie_echoed_prm_shutdown;
131 sctp_state_fn_t sctp_sf_do_9_1_prm_abort;
132 sctp_state_fn_t sctp_sf_cookie_wait_prm_abort;
133 sctp_state_fn_t sctp_sf_cookie_echoed_prm_abort;
134 sctp_state_fn_t sctp_sf_shutdown_pending_prm_abort;
135 sctp_state_fn_t sctp_sf_shutdown_sent_prm_abort;
136 sctp_state_fn_t sctp_sf_shutdown_ack_sent_prm_abort;
137 sctp_state_fn_t sctp_sf_error_closed;
138 sctp_state_fn_t sctp_sf_error_shutdown;
139 sctp_state_fn_t sctp_sf_ignore_primitive;
140 sctp_state_fn_t sctp_sf_do_prm_requestheartbeat;
141 sctp_state_fn_t sctp_sf_do_prm_asconf;
142 sctp_state_fn_t sctp_sf_do_prm_reconf;
143 
144 /* Prototypes for other event state functions.  */
145 sctp_state_fn_t sctp_sf_do_no_pending_tsn;
146 sctp_state_fn_t sctp_sf_do_9_2_start_shutdown;
147 sctp_state_fn_t sctp_sf_do_9_2_shutdown_ack;
148 sctp_state_fn_t sctp_sf_ignore_other;
149 sctp_state_fn_t sctp_sf_cookie_wait_icmp_abort;
150 
151 /* Prototypes for timeout event state functions.  */
152 sctp_state_fn_t sctp_sf_do_6_3_3_rtx;
153 sctp_state_fn_t sctp_sf_send_reconf;
154 sctp_state_fn_t sctp_sf_send_probe;
155 sctp_state_fn_t sctp_sf_do_6_2_sack;
156 sctp_state_fn_t sctp_sf_autoclose_timer_expire;
157 
158 /* Prototypes for utility support functions.  */
159 __u8 sctp_get_chunk_type(struct sctp_chunk *chunk);
160 const struct sctp_sm_table_entry *sctp_sm_lookup_event(
161 					struct net *net,
162 					enum sctp_event_type event_type,
163 					enum sctp_state state,
164 					union sctp_subtype event_subtype);
165 int sctp_chunk_iif(const struct sctp_chunk *);
166 struct sctp_association *sctp_make_temp_asoc(const struct sctp_endpoint *,
167 					     struct sctp_chunk *,
168 					     gfp_t gfp);
169 __u32 sctp_generate_verification_tag(void);
170 void sctp_populate_tie_tags(__u8 *cookie, __u32 curTag, __u32 hisTag);
171 
172 /* Prototypes for chunk-building functions.  */
173 struct sctp_chunk *sctp_make_init(const struct sctp_association *asoc,
174 				  const struct sctp_bind_addr *bp,
175 				  gfp_t gfp, int vparam_len);
176 struct sctp_chunk *sctp_make_init_ack(const struct sctp_association *asoc,
177 				      const struct sctp_chunk *chunk,
178 				      const gfp_t gfp, const int unkparam_len);
179 struct sctp_chunk *sctp_make_cookie_echo(const struct sctp_association *asoc,
180 					 const struct sctp_chunk *chunk);
181 struct sctp_chunk *sctp_make_cookie_ack(const struct sctp_association *asoc,
182 					const struct sctp_chunk *chunk);
183 struct sctp_chunk *sctp_make_cwr(const struct sctp_association *asoc,
184 				 const __u32 lowest_tsn,
185 				 const struct sctp_chunk *chunk);
186 struct sctp_chunk *sctp_make_idata(const struct sctp_association *asoc,
187 				   __u8 flags, int paylen, gfp_t gfp);
188 struct sctp_chunk *sctp_make_ifwdtsn(const struct sctp_association *asoc,
189 				     __u32 new_cum_tsn, size_t nstreams,
190 				     struct sctp_ifwdtsn_skip *skiplist);
191 struct sctp_chunk *sctp_make_datafrag_empty(const struct sctp_association *asoc,
192 					    const struct sctp_sndrcvinfo *sinfo,
193 					    int len, __u8 flags, gfp_t gfp);
194 struct sctp_chunk *sctp_make_ecne(const struct sctp_association *asoc,
195 				  const __u32 lowest_tsn);
196 struct sctp_chunk *sctp_make_sack(struct sctp_association *asoc);
197 struct sctp_chunk *sctp_make_shutdown(const struct sctp_association *asoc,
198 				      const struct sctp_chunk *chunk);
199 struct sctp_chunk *sctp_make_shutdown_ack(const struct sctp_association *asoc,
200 					  const struct sctp_chunk *chunk);
201 struct sctp_chunk *sctp_make_shutdown_complete(
202 					const struct sctp_association *asoc,
203 					const struct sctp_chunk *chunk);
204 int sctp_init_cause(struct sctp_chunk *chunk, __be16 cause, size_t paylen);
205 struct sctp_chunk *sctp_make_abort(const struct sctp_association *asoc,
206 				   const struct sctp_chunk *chunk,
207 				   const size_t hint);
208 struct sctp_chunk *sctp_make_abort_no_data(const struct sctp_association *asoc,
209 					   const struct sctp_chunk *chunk,
210 					   __u32 tsn);
211 struct sctp_chunk *sctp_make_abort_user(const struct sctp_association *asoc,
212 					struct msghdr *msg, size_t msg_len);
213 struct sctp_chunk *sctp_make_abort_violation(
214 					const struct sctp_association *asoc,
215 					const struct sctp_chunk *chunk,
216 					const __u8 *payload,
217 					const size_t paylen);
218 struct sctp_chunk *sctp_make_violation_paramlen(
219 					const struct sctp_association *asoc,
220 					const struct sctp_chunk *chunk,
221 					struct sctp_paramhdr *param);
222 struct sctp_chunk *sctp_make_violation_max_retrans(
223 					const struct sctp_association *asoc,
224 					const struct sctp_chunk *chunk);
225 struct sctp_chunk *sctp_make_new_encap_port(
226 					const struct sctp_association *asoc,
227 					const struct sctp_chunk *chunk);
228 struct sctp_chunk *sctp_make_heartbeat(const struct sctp_association *asoc,
229 				       const struct sctp_transport *transport,
230 				       __u32 probe_size);
231 struct sctp_chunk *sctp_make_heartbeat_ack(const struct sctp_association *asoc,
232 					   const struct sctp_chunk *chunk,
233 					   const void *payload,
234 					   const size_t paylen);
235 struct sctp_chunk *sctp_make_pad(const struct sctp_association *asoc, int len);
236 struct sctp_chunk *sctp_make_op_error(const struct sctp_association *asoc,
237 				      const struct sctp_chunk *chunk,
238 				      __be16 cause_code, const void *payload,
239 				      size_t paylen, size_t reserve_tail);
240 
241 struct sctp_chunk *sctp_make_asconf_update_ip(struct sctp_association *asoc,
242 					      union sctp_addr *laddr,
243 					      struct sockaddr *addrs,
244 					      int addrcnt, __be16 flags);
245 struct sctp_chunk *sctp_make_asconf_set_prim(struct sctp_association *asoc,
246 					     union sctp_addr *addr);
247 bool sctp_verify_asconf(const struct sctp_association *asoc,
248 			struct sctp_chunk *chunk, bool addr_param_needed,
249 			struct sctp_paramhdr **errp);
250 struct sctp_chunk *sctp_process_asconf(struct sctp_association *asoc,
251 				       struct sctp_chunk *asconf);
252 int sctp_process_asconf_ack(struct sctp_association *asoc,
253 			    struct sctp_chunk *asconf_ack);
254 struct sctp_chunk *sctp_make_fwdtsn(const struct sctp_association *asoc,
255 				    __u32 new_cum_tsn, size_t nstreams,
256 				    struct sctp_fwdtsn_skip *skiplist);
257 struct sctp_chunk *sctp_make_auth(const struct sctp_association *asoc,
258 				  __u16 key_id);
259 struct sctp_chunk *sctp_make_strreset_req(const struct sctp_association *asoc,
260 					  __u16 stream_num, __be16 *stream_list,
261 					  bool out, bool in);
262 struct sctp_chunk *sctp_make_strreset_tsnreq(
263 					const struct sctp_association *asoc);
264 struct sctp_chunk *sctp_make_strreset_addstrm(
265 					const struct sctp_association *asoc,
266 					__u16 out, __u16 in);
267 struct sctp_chunk *sctp_make_strreset_resp(const struct sctp_association *asoc,
268 					   __u32 result, __u32 sn);
269 struct sctp_chunk *sctp_make_strreset_tsnresp(struct sctp_association *asoc,
270 					      __u32 result, __u32 sn,
271 					      __u32 sender_tsn,
272 					      __u32 receiver_tsn);
273 bool sctp_verify_reconf(const struct sctp_association *asoc,
274 			struct sctp_chunk *chunk,
275 			struct sctp_paramhdr **errp);
276 void sctp_chunk_assign_tsn(struct sctp_chunk *chunk);
277 void sctp_chunk_assign_ssn(struct sctp_chunk *chunk);
278 
279 /* Prototypes for stream-processing functions.  */
280 struct sctp_chunk *sctp_process_strreset_outreq(
281 				struct sctp_association *asoc,
282 				union sctp_params param,
283 				struct sctp_ulpevent **evp);
284 struct sctp_chunk *sctp_process_strreset_inreq(
285 				struct sctp_association *asoc,
286 				union sctp_params param,
287 				struct sctp_ulpevent **evp);
288 struct sctp_chunk *sctp_process_strreset_tsnreq(
289 				struct sctp_association *asoc,
290 				union sctp_params param,
291 				struct sctp_ulpevent **evp);
292 struct sctp_chunk *sctp_process_strreset_addstrm_out(
293 				struct sctp_association *asoc,
294 				union sctp_params param,
295 				struct sctp_ulpevent **evp);
296 struct sctp_chunk *sctp_process_strreset_addstrm_in(
297 				struct sctp_association *asoc,
298 				union sctp_params param,
299 				struct sctp_ulpevent **evp);
300 struct sctp_chunk *sctp_process_strreset_resp(
301 				struct sctp_association *asoc,
302 				union sctp_params param,
303 				struct sctp_ulpevent **evp);
304 
305 /* Prototypes for statetable processing. */
306 
307 int sctp_do_sm(struct net *net, enum sctp_event_type event_type,
308 	       union sctp_subtype subtype, enum sctp_state state,
309 	       struct sctp_endpoint *ep, struct sctp_association *asoc,
310 	       void *event_arg, gfp_t gfp);
311 
312 /* 2nd level prototypes */
313 void sctp_generate_t3_rtx_event(struct timer_list *t);
314 void sctp_generate_heartbeat_event(struct timer_list *t);
315 void sctp_generate_reconf_event(struct timer_list *t);
316 void sctp_generate_probe_event(struct timer_list *t);
317 void sctp_generate_proto_unreach_event(struct timer_list *t);
318 
319 void sctp_ootb_pkt_free(struct sctp_packet *packet);
320 
321 struct sctp_association *sctp_unpack_cookie(
322 					const struct sctp_endpoint *ep,
323 					const struct sctp_association *asoc,
324 					struct sctp_chunk *chunk,
325 					gfp_t gfp, int *err,
326 					struct sctp_chunk **err_chk_p);
327 
328 /* 3rd level prototypes */
329 __u32 sctp_generate_tag(const struct sctp_endpoint *ep);
330 __u32 sctp_generate_tsn(const struct sctp_endpoint *ep);
331 
332 /* Extern declarations for major data structures.  */
333 extern sctp_timer_event_t *sctp_timer_events[SCTP_NUM_TIMEOUT_TYPES];
334 
335 
336 /* Get the size of a DATA chunk payload. */
sctp_data_size(struct sctp_chunk * chunk)337 static inline __u16 sctp_data_size(struct sctp_chunk *chunk)
338 {
339 	__u16 size;
340 
341 	size = ntohs(chunk->chunk_hdr->length);
342 	size -= sctp_datachk_len(&chunk->asoc->stream);
343 
344 	return size;
345 }
346 
347 /* Compare two TSNs */
348 #define TSN_lt(a,b)	\
349 	(typecheck(__u32, a) && \
350 	 typecheck(__u32, b) && \
351 	 ((__s32)((a) - (b)) < 0))
352 
353 #define TSN_lte(a,b)	\
354 	(typecheck(__u32, a) && \
355 	 typecheck(__u32, b) && \
356 	 ((__s32)((a) - (b)) <= 0))
357 
358 /* Compare two MIDs */
359 #define MID_lt(a, b)	\
360 	(typecheck(__u32, a) && \
361 	 typecheck(__u32, b) && \
362 	 ((__s32)((a) - (b)) < 0))
363 
364 /* Compare two SSNs */
365 #define SSN_lt(a,b)		\
366 	(typecheck(__u16, a) && \
367 	 typecheck(__u16, b) && \
368 	 ((__s16)((a) - (b)) < 0))
369 
370 /* ADDIP 3.1.1 */
371 #define ADDIP_SERIAL_gte(a,b)	\
372 	(typecheck(__u32, a) && \
373 	 typecheck(__u32, b) && \
374 	 ((__s32)((b) - (a)) <= 0))
375 
376 /* Check VTAG of the packet matches the sender's own tag. */
377 static inline int
sctp_vtag_verify(const struct sctp_chunk * chunk,const struct sctp_association * asoc)378 sctp_vtag_verify(const struct sctp_chunk *chunk,
379 		 const struct sctp_association *asoc)
380 {
381 	/* RFC 2960 Sec 8.5 When receiving an SCTP packet, the endpoint
382 	 * MUST ensure that the value in the Verification Tag field of
383 	 * the received SCTP packet matches its own Tag. If the received
384 	 * Verification Tag value does not match the receiver's own
385 	 * tag value, the receiver shall silently discard the packet...
386 	 */
387 	if (ntohl(chunk->sctp_hdr->vtag) != asoc->c.my_vtag)
388 		return 0;
389 
390 	chunk->transport->encap_port = SCTP_INPUT_CB(chunk->skb)->encap_port;
391 	return 1;
392 }
393 
394 /* Check VTAG of the packet matches the sender's own tag and the T bit is
395  * not set, OR its peer's tag and the T bit is set in the Chunk Flags.
396  */
397 static inline int
sctp_vtag_verify_either(const struct sctp_chunk * chunk,const struct sctp_association * asoc)398 sctp_vtag_verify_either(const struct sctp_chunk *chunk,
399 			const struct sctp_association *asoc)
400 {
401         /* RFC 2960 Section 8.5.1, sctpimpguide Section 2.41
402 	 *
403 	 * B) The receiver of a ABORT MUST accept the packet
404 	 *    if the Verification Tag field of the packet matches its own tag
405 	 *    and the T bit is not set
406 	 *    OR
407 	 *    it is set to its peer's tag and the T bit is set in the Chunk
408 	 *    Flags.
409 	 *    Otherwise, the receiver MUST silently discard the packet
410 	 *    and take no further action.
411 	 *
412 	 * C) The receiver of a SHUTDOWN COMPLETE shall accept the packet
413 	 *    if the Verification Tag field of the packet matches its own tag
414 	 *    and the T bit is not set
415 	 *    OR
416 	 *    it is set to its peer's tag and the T bit is set in the Chunk
417 	 *    Flags.
418 	 *    Otherwise, the receiver MUST silently discard the packet
419 	 *    and take no further action.  An endpoint MUST ignore the
420 	 *    SHUTDOWN COMPLETE if it is not in the SHUTDOWN-ACK-SENT state.
421 	 */
422         if ((!sctp_test_T_bit(chunk) &&
423              (ntohl(chunk->sctp_hdr->vtag) == asoc->c.my_vtag)) ||
424 	    (sctp_test_T_bit(chunk) && asoc->c.peer_vtag &&
425 	     (ntohl(chunk->sctp_hdr->vtag) == asoc->c.peer_vtag))) {
426                 return 1;
427 	}
428 
429 	return 0;
430 }
431 
432 #endif /* __sctp_sm_h__ */
433