1/*
2 *  IUCV protocol stack for Linux on zSeries
3 *
4 *  Copyright IBM Corp. 2006, 2009
5 *
6 *  Author(s):	Jennifer Hunt <jenhunt@us.ibm.com>
7 *		Hendrik Brueckner <brueckner@linux.vnet.ibm.com>
8 *  PM functions:
9 *		Ursula Braun <ursula.braun@de.ibm.com>
10 */
11
12#define KMSG_COMPONENT "af_iucv"
13#define pr_fmt(fmt) KMSG_COMPONENT ": " fmt
14
15#include <linux/module.h>
16#include <linux/types.h>
17#include <linux/list.h>
18#include <linux/errno.h>
19#include <linux/kernel.h>
20#include <linux/sched.h>
21#include <linux/slab.h>
22#include <linux/skbuff.h>
23#include <linux/init.h>
24#include <linux/poll.h>
25#include <net/sock.h>
26#include <asm/ebcdic.h>
27#include <asm/cpcmd.h>
28#include <linux/kmod.h>
29
30#include <net/iucv/af_iucv.h>
31
32#define VERSION "1.2"
33
34static char iucv_userid[80];
35
36static const struct proto_ops iucv_sock_ops;
37
38static struct proto iucv_proto = {
39	.name		= "AF_IUCV",
40	.owner		= THIS_MODULE,
41	.obj_size	= sizeof(struct iucv_sock),
42};
43
44static struct iucv_interface *pr_iucv;
45
46/* special AF_IUCV IPRM messages */
47static const u8 iprm_shutdown[8] =
48	{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01};
49
50#define TRGCLS_SIZE	(sizeof(((struct iucv_message *)0)->class))
51
52#define __iucv_sock_wait(sk, condition, timeo, ret)			\
53do {									\
54	DEFINE_WAIT(__wait);						\
55	long __timeo = timeo;						\
56	ret = 0;							\
57	prepare_to_wait(sk_sleep(sk), &__wait, TASK_INTERRUPTIBLE);	\
58	while (!(condition)) {						\
59		if (!__timeo) {						\
60			ret = -EAGAIN;					\
61			break;						\
62		}							\
63		if (signal_pending(current)) {				\
64			ret = sock_intr_errno(__timeo);			\
65			break;						\
66		}							\
67		release_sock(sk);					\
68		__timeo = schedule_timeout(__timeo);			\
69		lock_sock(sk);						\
70		ret = sock_error(sk);					\
71		if (ret)						\
72			break;						\
73	}								\
74	finish_wait(sk_sleep(sk), &__wait);				\
75} while (0)
76
77#define iucv_sock_wait(sk, condition, timeo)				\
78({									\
79	int __ret = 0;							\
80	if (!(condition))						\
81		__iucv_sock_wait(sk, condition, timeo, __ret);		\
82	__ret;								\
83})
84
85static void iucv_sock_kill(struct sock *sk);
86static void iucv_sock_close(struct sock *sk);
87static void iucv_sever_path(struct sock *, int);
88
89static int afiucv_hs_rcv(struct sk_buff *skb, struct net_device *dev,
90	struct packet_type *pt, struct net_device *orig_dev);
91static int afiucv_hs_send(struct iucv_message *imsg, struct sock *sock,
92		   struct sk_buff *skb, u8 flags);
93static void afiucv_hs_callback_txnotify(struct sk_buff *, enum iucv_tx_notify);
94
95/* Call Back functions */
96static void iucv_callback_rx(struct iucv_path *, struct iucv_message *);
97static void iucv_callback_txdone(struct iucv_path *, struct iucv_message *);
98static void iucv_callback_connack(struct iucv_path *, u8 ipuser[16]);
99static int iucv_callback_connreq(struct iucv_path *, u8 ipvmid[8],
100				 u8 ipuser[16]);
101static void iucv_callback_connrej(struct iucv_path *, u8 ipuser[16]);
102static void iucv_callback_shutdown(struct iucv_path *, u8 ipuser[16]);
103
104static struct iucv_sock_list iucv_sk_list = {
105	.lock = __RW_LOCK_UNLOCKED(iucv_sk_list.lock),
106	.autobind_name = ATOMIC_INIT(0)
107};
108
109static struct iucv_handler af_iucv_handler = {
110	.path_pending	  = iucv_callback_connreq,
111	.path_complete	  = iucv_callback_connack,
112	.path_severed	  = iucv_callback_connrej,
113	.message_pending  = iucv_callback_rx,
114	.message_complete = iucv_callback_txdone,
115	.path_quiesced	  = iucv_callback_shutdown,
116};
117
118static inline void high_nmcpy(unsigned char *dst, char *src)
119{
120       memcpy(dst, src, 8);
121}
122
123static inline void low_nmcpy(unsigned char *dst, char *src)
124{
125       memcpy(&dst[8], src, 8);
126}
127
128static int afiucv_pm_prepare(struct device *dev)
129{
130#ifdef CONFIG_PM_DEBUG
131	printk(KERN_WARNING "afiucv_pm_prepare\n");
132#endif
133	return 0;
134}
135
136static void afiucv_pm_complete(struct device *dev)
137{
138#ifdef CONFIG_PM_DEBUG
139	printk(KERN_WARNING "afiucv_pm_complete\n");
140#endif
141}
142
143/**
144 * afiucv_pm_freeze() - Freeze PM callback
145 * @dev:	AFIUCV dummy device
146 *
147 * Sever all established IUCV communication pathes
148 */
149static int afiucv_pm_freeze(struct device *dev)
150{
151	struct iucv_sock *iucv;
152	struct sock *sk;
153	int err = 0;
154
155#ifdef CONFIG_PM_DEBUG
156	printk(KERN_WARNING "afiucv_pm_freeze\n");
157#endif
158	read_lock(&iucv_sk_list.lock);
159	sk_for_each(sk, &iucv_sk_list.head) {
160		iucv = iucv_sk(sk);
161		switch (sk->sk_state) {
162		case IUCV_DISCONN:
163		case IUCV_CLOSING:
164		case IUCV_CONNECTED:
165			iucv_sever_path(sk, 0);
166			break;
167		case IUCV_OPEN:
168		case IUCV_BOUND:
169		case IUCV_LISTEN:
170		case IUCV_CLOSED:
171		default:
172			break;
173		}
174		skb_queue_purge(&iucv->send_skb_q);
175		skb_queue_purge(&iucv->backlog_skb_q);
176	}
177	read_unlock(&iucv_sk_list.lock);
178	return err;
179}
180
181/**
182 * afiucv_pm_restore_thaw() - Thaw and restore PM callback
183 * @dev:	AFIUCV dummy device
184 *
185 * socket clean up after freeze
186 */
187static int afiucv_pm_restore_thaw(struct device *dev)
188{
189	struct sock *sk;
190
191#ifdef CONFIG_PM_DEBUG
192	printk(KERN_WARNING "afiucv_pm_restore_thaw\n");
193#endif
194	read_lock(&iucv_sk_list.lock);
195	sk_for_each(sk, &iucv_sk_list.head) {
196		switch (sk->sk_state) {
197		case IUCV_CONNECTED:
198			sk->sk_err = EPIPE;
199			sk->sk_state = IUCV_DISCONN;
200			sk->sk_state_change(sk);
201			break;
202		case IUCV_DISCONN:
203		case IUCV_CLOSING:
204		case IUCV_LISTEN:
205		case IUCV_BOUND:
206		case IUCV_OPEN:
207		default:
208			break;
209		}
210	}
211	read_unlock(&iucv_sk_list.lock);
212	return 0;
213}
214
215static const struct dev_pm_ops afiucv_pm_ops = {
216	.prepare = afiucv_pm_prepare,
217	.complete = afiucv_pm_complete,
218	.freeze = afiucv_pm_freeze,
219	.thaw = afiucv_pm_restore_thaw,
220	.restore = afiucv_pm_restore_thaw,
221};
222
223static struct device_driver af_iucv_driver = {
224	.owner = THIS_MODULE,
225	.name = "afiucv",
226	.bus  = NULL,
227	.pm   = &afiucv_pm_ops,
228};
229
230/* dummy device used as trigger for PM functions */
231static struct device *af_iucv_dev;
232
233/**
234 * iucv_msg_length() - Returns the length of an iucv message.
235 * @msg:	Pointer to struct iucv_message, MUST NOT be NULL
236 *
237 * The function returns the length of the specified iucv message @msg of data
238 * stored in a buffer and of data stored in the parameter list (PRMDATA).
239 *
240 * For IUCV_IPRMDATA, AF_IUCV uses the following convention to transport socket
241 * data:
242 *	PRMDATA[0..6]	socket data (max 7 bytes);
243 *	PRMDATA[7]	socket data length value (len is 0xff - PRMDATA[7])
244 *
245 * The socket data length is computed by subtracting the socket data length
246 * value from 0xFF.
247 * If the socket data len is greater 7, then PRMDATA can be used for special
248 * notifications (see iucv_sock_shutdown); and further,
249 * if the socket data len is > 7, the function returns 8.
250 *
251 * Use this function to allocate socket buffers to store iucv message data.
252 */
253static inline size_t iucv_msg_length(struct iucv_message *msg)
254{
255	size_t datalen;
256
257	if (msg->flags & IUCV_IPRMDATA) {
258		datalen = 0xff - msg->rmmsg[7];
259		return (datalen < 8) ? datalen : 8;
260	}
261	return msg->length;
262}
263
264/**
265 * iucv_sock_in_state() - check for specific states
266 * @sk:		sock structure
267 * @state:	first iucv sk state
268 * @state:	second iucv sk state
269 *
270 * Returns true if the socket in either in the first or second state.
271 */
272static int iucv_sock_in_state(struct sock *sk, int state, int state2)
273{
274	return (sk->sk_state == state || sk->sk_state == state2);
275}
276
277/**
278 * iucv_below_msglim() - function to check if messages can be sent
279 * @sk:		sock structure
280 *
281 * Returns true if the send queue length is lower than the message limit.
282 * Always returns true if the socket is not connected (no iucv path for
283 * checking the message limit).
284 */
285static inline int iucv_below_msglim(struct sock *sk)
286{
287	struct iucv_sock *iucv = iucv_sk(sk);
288
289	if (sk->sk_state != IUCV_CONNECTED)
290		return 1;
291	if (iucv->transport == AF_IUCV_TRANS_IUCV)
292		return (skb_queue_len(&iucv->send_skb_q) < iucv->path->msglim);
293	else
294		return ((atomic_read(&iucv->msg_sent) < iucv->msglimit_peer) &&
295			(atomic_read(&iucv->pendings) <= 0));
296}
297
298/**
299 * iucv_sock_wake_msglim() - Wake up thread waiting on msg limit
300 */
301static void iucv_sock_wake_msglim(struct sock *sk)
302{
303	struct socket_wq *wq;
304
305	rcu_read_lock();
306	wq = rcu_dereference(sk->sk_wq);
307	if (wq_has_sleeper(wq))
308		wake_up_interruptible_all(&wq->wait);
309	sk_wake_async(sk, SOCK_WAKE_SPACE, POLL_OUT);
310	rcu_read_unlock();
311}
312
313/**
314 * afiucv_hs_send() - send a message through HiperSockets transport
315 */
316static int afiucv_hs_send(struct iucv_message *imsg, struct sock *sock,
317		   struct sk_buff *skb, u8 flags)
318{
319	struct iucv_sock *iucv = iucv_sk(sock);
320	struct af_iucv_trans_hdr *phs_hdr;
321	struct sk_buff *nskb;
322	int err, confirm_recv = 0;
323
324	memset(skb->head, 0, ETH_HLEN);
325	phs_hdr = (struct af_iucv_trans_hdr *)skb_push(skb,
326					sizeof(struct af_iucv_trans_hdr));
327	skb_reset_mac_header(skb);
328	skb_reset_network_header(skb);
329	skb_push(skb, ETH_HLEN);
330	skb_reset_mac_header(skb);
331	memset(phs_hdr, 0, sizeof(struct af_iucv_trans_hdr));
332
333	phs_hdr->magic = ETH_P_AF_IUCV;
334	phs_hdr->version = 1;
335	phs_hdr->flags = flags;
336	if (flags == AF_IUCV_FLAG_SYN)
337		phs_hdr->window = iucv->msglimit;
338	else if ((flags == AF_IUCV_FLAG_WIN) || !flags) {
339		confirm_recv = atomic_read(&iucv->msg_recv);
340		phs_hdr->window = confirm_recv;
341		if (confirm_recv)
342			phs_hdr->flags = phs_hdr->flags | AF_IUCV_FLAG_WIN;
343	}
344	memcpy(phs_hdr->destUserID, iucv->dst_user_id, 8);
345	memcpy(phs_hdr->destAppName, iucv->dst_name, 8);
346	memcpy(phs_hdr->srcUserID, iucv->src_user_id, 8);
347	memcpy(phs_hdr->srcAppName, iucv->src_name, 8);
348	ASCEBC(phs_hdr->destUserID, sizeof(phs_hdr->destUserID));
349	ASCEBC(phs_hdr->destAppName, sizeof(phs_hdr->destAppName));
350	ASCEBC(phs_hdr->srcUserID, sizeof(phs_hdr->srcUserID));
351	ASCEBC(phs_hdr->srcAppName, sizeof(phs_hdr->srcAppName));
352	if (imsg)
353		memcpy(&phs_hdr->iucv_hdr, imsg, sizeof(struct iucv_message));
354
355	skb->dev = iucv->hs_dev;
356	if (!skb->dev)
357		return -ENODEV;
358	if (!(skb->dev->flags & IFF_UP) || !netif_carrier_ok(skb->dev))
359		return -ENETDOWN;
360	if (skb->len > skb->dev->mtu) {
361		if (sock->sk_type == SOCK_SEQPACKET)
362			return -EMSGSIZE;
363		else
364			skb_trim(skb, skb->dev->mtu);
365	}
366	skb->protocol = ETH_P_AF_IUCV;
367	nskb = skb_clone(skb, GFP_ATOMIC);
368	if (!nskb)
369		return -ENOMEM;
370	skb_queue_tail(&iucv->send_skb_q, nskb);
371	err = dev_queue_xmit(skb);
372	if (net_xmit_eval(err)) {
373		skb_unlink(nskb, &iucv->send_skb_q);
374		kfree_skb(nskb);
375	} else {
376		atomic_sub(confirm_recv, &iucv->msg_recv);
377		WARN_ON(atomic_read(&iucv->msg_recv) < 0);
378	}
379	return net_xmit_eval(err);
380}
381
382static struct sock *__iucv_get_sock_by_name(char *nm)
383{
384	struct sock *sk;
385
386	sk_for_each(sk, &iucv_sk_list.head)
387		if (!memcmp(&iucv_sk(sk)->src_name, nm, 8))
388			return sk;
389
390	return NULL;
391}
392
393static void iucv_sock_destruct(struct sock *sk)
394{
395	skb_queue_purge(&sk->sk_receive_queue);
396	skb_queue_purge(&sk->sk_error_queue);
397
398	sk_mem_reclaim(sk);
399
400	if (!sock_flag(sk, SOCK_DEAD)) {
401		pr_err("Attempt to release alive iucv socket %p\n", sk);
402		return;
403	}
404
405	WARN_ON(atomic_read(&sk->sk_rmem_alloc));
406	WARN_ON(atomic_read(&sk->sk_wmem_alloc));
407	WARN_ON(sk->sk_wmem_queued);
408	WARN_ON(sk->sk_forward_alloc);
409}
410
411/* Cleanup Listen */
412static void iucv_sock_cleanup_listen(struct sock *parent)
413{
414	struct sock *sk;
415
416	/* Close non-accepted connections */
417	while ((sk = iucv_accept_dequeue(parent, NULL))) {
418		iucv_sock_close(sk);
419		iucv_sock_kill(sk);
420	}
421
422	parent->sk_state = IUCV_CLOSED;
423}
424
425/* Kill socket (only if zapped and orphaned) */
426static void iucv_sock_kill(struct sock *sk)
427{
428	if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
429		return;
430
431	iucv_sock_unlink(&iucv_sk_list, sk);
432	sock_set_flag(sk, SOCK_DEAD);
433	sock_put(sk);
434}
435
436/* Terminate an IUCV path */
437static void iucv_sever_path(struct sock *sk, int with_user_data)
438{
439	unsigned char user_data[16];
440	struct iucv_sock *iucv = iucv_sk(sk);
441	struct iucv_path *path = iucv->path;
442
443	if (iucv->path) {
444		iucv->path = NULL;
445		if (with_user_data) {
446			low_nmcpy(user_data, iucv->src_name);
447			high_nmcpy(user_data, iucv->dst_name);
448			ASCEBC(user_data, sizeof(user_data));
449			pr_iucv->path_sever(path, user_data);
450		} else
451			pr_iucv->path_sever(path, NULL);
452		iucv_path_free(path);
453	}
454}
455
456/* Send FIN through an IUCV socket for HIPER transport */
457static int iucv_send_ctrl(struct sock *sk, u8 flags)
458{
459	int err = 0;
460	int blen;
461	struct sk_buff *skb;
462
463	blen = sizeof(struct af_iucv_trans_hdr) + ETH_HLEN;
464	skb = sock_alloc_send_skb(sk, blen, 1, &err);
465	if (skb) {
466		skb_reserve(skb, blen);
467		err = afiucv_hs_send(NULL, sk, skb, flags);
468	}
469	return err;
470}
471
472/* Close an IUCV socket */
473static void iucv_sock_close(struct sock *sk)
474{
475	struct iucv_sock *iucv = iucv_sk(sk);
476	unsigned long timeo;
477	int err = 0;
478
479	lock_sock(sk);
480
481	switch (sk->sk_state) {
482	case IUCV_LISTEN:
483		iucv_sock_cleanup_listen(sk);
484		break;
485
486	case IUCV_CONNECTED:
487		if (iucv->transport == AF_IUCV_TRANS_HIPER) {
488			err = iucv_send_ctrl(sk, AF_IUCV_FLAG_FIN);
489			sk->sk_state = IUCV_DISCONN;
490			sk->sk_state_change(sk);
491		}
492	case IUCV_DISCONN:   /* fall through */
493		sk->sk_state = IUCV_CLOSING;
494		sk->sk_state_change(sk);
495
496		if (!err && !skb_queue_empty(&iucv->send_skb_q)) {
497			if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
498				timeo = sk->sk_lingertime;
499			else
500				timeo = IUCV_DISCONN_TIMEOUT;
501			iucv_sock_wait(sk,
502					iucv_sock_in_state(sk, IUCV_CLOSED, 0),
503					timeo);
504		}
505
506	case IUCV_CLOSING:   /* fall through */
507		sk->sk_state = IUCV_CLOSED;
508		sk->sk_state_change(sk);
509
510		sk->sk_err = ECONNRESET;
511		sk->sk_state_change(sk);
512
513		skb_queue_purge(&iucv->send_skb_q);
514		skb_queue_purge(&iucv->backlog_skb_q);
515
516	default:   /* fall through */
517		iucv_sever_path(sk, 1);
518	}
519
520	if (iucv->hs_dev) {
521		dev_put(iucv->hs_dev);
522		iucv->hs_dev = NULL;
523		sk->sk_bound_dev_if = 0;
524	}
525
526	/* mark socket for deletion by iucv_sock_kill() */
527	sock_set_flag(sk, SOCK_ZAPPED);
528
529	release_sock(sk);
530}
531
532static void iucv_sock_init(struct sock *sk, struct sock *parent)
533{
534	if (parent)
535		sk->sk_type = parent->sk_type;
536}
537
538static struct sock *iucv_sock_alloc(struct socket *sock, int proto, gfp_t prio)
539{
540	struct sock *sk;
541	struct iucv_sock *iucv;
542
543	sk = sk_alloc(&init_net, PF_IUCV, prio, &iucv_proto);
544	if (!sk)
545		return NULL;
546	iucv = iucv_sk(sk);
547
548	sock_init_data(sock, sk);
549	INIT_LIST_HEAD(&iucv->accept_q);
550	spin_lock_init(&iucv->accept_q_lock);
551	skb_queue_head_init(&iucv->send_skb_q);
552	INIT_LIST_HEAD(&iucv->message_q.list);
553	spin_lock_init(&iucv->message_q.lock);
554	skb_queue_head_init(&iucv->backlog_skb_q);
555	iucv->send_tag = 0;
556	atomic_set(&iucv->pendings, 0);
557	iucv->flags = 0;
558	iucv->msglimit = 0;
559	atomic_set(&iucv->msg_sent, 0);
560	atomic_set(&iucv->msg_recv, 0);
561	iucv->path = NULL;
562	iucv->sk_txnotify = afiucv_hs_callback_txnotify;
563	memset(&iucv->src_user_id , 0, 32);
564	if (pr_iucv)
565		iucv->transport = AF_IUCV_TRANS_IUCV;
566	else
567		iucv->transport = AF_IUCV_TRANS_HIPER;
568
569	sk->sk_destruct = iucv_sock_destruct;
570	sk->sk_sndtimeo = IUCV_CONN_TIMEOUT;
571	sk->sk_allocation = GFP_DMA;
572
573	sock_reset_flag(sk, SOCK_ZAPPED);
574
575	sk->sk_protocol = proto;
576	sk->sk_state	= IUCV_OPEN;
577
578	iucv_sock_link(&iucv_sk_list, sk);
579	return sk;
580}
581
582/* Create an IUCV socket */
583static int iucv_sock_create(struct net *net, struct socket *sock, int protocol,
584			    int kern)
585{
586	struct sock *sk;
587
588	if (protocol && protocol != PF_IUCV)
589		return -EPROTONOSUPPORT;
590
591	sock->state = SS_UNCONNECTED;
592
593	switch (sock->type) {
594	case SOCK_STREAM:
595		sock->ops = &iucv_sock_ops;
596		break;
597	case SOCK_SEQPACKET:
598		/* currently, proto ops can handle both sk types */
599		sock->ops = &iucv_sock_ops;
600		break;
601	default:
602		return -ESOCKTNOSUPPORT;
603	}
604
605	sk = iucv_sock_alloc(sock, protocol, GFP_KERNEL);
606	if (!sk)
607		return -ENOMEM;
608
609	iucv_sock_init(sk, NULL);
610
611	return 0;
612}
613
614void iucv_sock_link(struct iucv_sock_list *l, struct sock *sk)
615{
616	write_lock_bh(&l->lock);
617	sk_add_node(sk, &l->head);
618	write_unlock_bh(&l->lock);
619}
620
621void iucv_sock_unlink(struct iucv_sock_list *l, struct sock *sk)
622{
623	write_lock_bh(&l->lock);
624	sk_del_node_init(sk);
625	write_unlock_bh(&l->lock);
626}
627
628void iucv_accept_enqueue(struct sock *parent, struct sock *sk)
629{
630	unsigned long flags;
631	struct iucv_sock *par = iucv_sk(parent);
632
633	sock_hold(sk);
634	spin_lock_irqsave(&par->accept_q_lock, flags);
635	list_add_tail(&iucv_sk(sk)->accept_q, &par->accept_q);
636	spin_unlock_irqrestore(&par->accept_q_lock, flags);
637	iucv_sk(sk)->parent = parent;
638	sk_acceptq_added(parent);
639}
640
641void iucv_accept_unlink(struct sock *sk)
642{
643	unsigned long flags;
644	struct iucv_sock *par = iucv_sk(iucv_sk(sk)->parent);
645
646	spin_lock_irqsave(&par->accept_q_lock, flags);
647	list_del_init(&iucv_sk(sk)->accept_q);
648	spin_unlock_irqrestore(&par->accept_q_lock, flags);
649	sk_acceptq_removed(iucv_sk(sk)->parent);
650	iucv_sk(sk)->parent = NULL;
651	sock_put(sk);
652}
653
654struct sock *iucv_accept_dequeue(struct sock *parent, struct socket *newsock)
655{
656	struct iucv_sock *isk, *n;
657	struct sock *sk;
658
659	list_for_each_entry_safe(isk, n, &iucv_sk(parent)->accept_q, accept_q) {
660		sk = (struct sock *) isk;
661		lock_sock(sk);
662
663		if (sk->sk_state == IUCV_CLOSED) {
664			iucv_accept_unlink(sk);
665			release_sock(sk);
666			continue;
667		}
668
669		if (sk->sk_state == IUCV_CONNECTED ||
670		    sk->sk_state == IUCV_DISCONN ||
671		    !newsock) {
672			iucv_accept_unlink(sk);
673			if (newsock)
674				sock_graft(sk, newsock);
675
676			release_sock(sk);
677			return sk;
678		}
679
680		release_sock(sk);
681	}
682	return NULL;
683}
684
685static void __iucv_auto_name(struct iucv_sock *iucv)
686{
687	char name[12];
688
689	sprintf(name, "%08x", atomic_inc_return(&iucv_sk_list.autobind_name));
690	while (__iucv_get_sock_by_name(name)) {
691		sprintf(name, "%08x",
692			atomic_inc_return(&iucv_sk_list.autobind_name));
693	}
694	memcpy(iucv->src_name, name, 8);
695}
696
697/* Bind an unbound socket */
698static int iucv_sock_bind(struct socket *sock, struct sockaddr *addr,
699			  int addr_len)
700{
701	struct sockaddr_iucv *sa = (struct sockaddr_iucv *) addr;
702	struct sock *sk = sock->sk;
703	struct iucv_sock *iucv;
704	int err = 0;
705	struct net_device *dev;
706	char uid[9];
707
708	/* Verify the input sockaddr */
709	if (!addr || addr->sa_family != AF_IUCV)
710		return -EINVAL;
711
712	lock_sock(sk);
713	if (sk->sk_state != IUCV_OPEN) {
714		err = -EBADFD;
715		goto done;
716	}
717
718	write_lock_bh(&iucv_sk_list.lock);
719
720	iucv = iucv_sk(sk);
721	if (__iucv_get_sock_by_name(sa->siucv_name)) {
722		err = -EADDRINUSE;
723		goto done_unlock;
724	}
725	if (iucv->path)
726		goto done_unlock;
727
728	/* Bind the socket */
729	if (pr_iucv)
730		if (!memcmp(sa->siucv_user_id, iucv_userid, 8))
731			goto vm_bind; /* VM IUCV transport */
732
733	/* try hiper transport */
734	memcpy(uid, sa->siucv_user_id, sizeof(uid));
735	ASCEBC(uid, 8);
736	rcu_read_lock();
737	for_each_netdev_rcu(&init_net, dev) {
738		if (!memcmp(dev->perm_addr, uid, 8)) {
739			memcpy(iucv->src_user_id, sa->siucv_user_id, 8);
740			/* Check for unitialized siucv_name */
741			if (strncmp(sa->siucv_name, "        ", 8) == 0)
742				__iucv_auto_name(iucv);
743			else
744				memcpy(iucv->src_name, sa->siucv_name, 8);
745			sk->sk_bound_dev_if = dev->ifindex;
746			iucv->hs_dev = dev;
747			dev_hold(dev);
748			sk->sk_state = IUCV_BOUND;
749			iucv->transport = AF_IUCV_TRANS_HIPER;
750			if (!iucv->msglimit)
751				iucv->msglimit = IUCV_HIPER_MSGLIM_DEFAULT;
752			rcu_read_unlock();
753			goto done_unlock;
754		}
755	}
756	rcu_read_unlock();
757vm_bind:
758	if (pr_iucv) {
759		/* use local userid for backward compat */
760		memcpy(iucv->src_name, sa->siucv_name, 8);
761		memcpy(iucv->src_user_id, iucv_userid, 8);
762		sk->sk_state = IUCV_BOUND;
763		iucv->transport = AF_IUCV_TRANS_IUCV;
764		if (!iucv->msglimit)
765			iucv->msglimit = IUCV_QUEUELEN_DEFAULT;
766		goto done_unlock;
767	}
768	/* found no dev to bind */
769	err = -ENODEV;
770done_unlock:
771	/* Release the socket list lock */
772	write_unlock_bh(&iucv_sk_list.lock);
773done:
774	release_sock(sk);
775	return err;
776}
777
778/* Automatically bind an unbound socket */
779static int iucv_sock_autobind(struct sock *sk)
780{
781	struct iucv_sock *iucv = iucv_sk(sk);
782	int err = 0;
783
784	if (unlikely(!pr_iucv))
785		return -EPROTO;
786
787	memcpy(iucv->src_user_id, iucv_userid, 8);
788
789	write_lock_bh(&iucv_sk_list.lock);
790	__iucv_auto_name(iucv);
791	write_unlock_bh(&iucv_sk_list.lock);
792
793	if (!iucv->msglimit)
794		iucv->msglimit = IUCV_QUEUELEN_DEFAULT;
795
796	return err;
797}
798
799static int afiucv_path_connect(struct socket *sock, struct sockaddr *addr)
800{
801	struct sockaddr_iucv *sa = (struct sockaddr_iucv *) addr;
802	struct sock *sk = sock->sk;
803	struct iucv_sock *iucv = iucv_sk(sk);
804	unsigned char user_data[16];
805	int err;
806
807	high_nmcpy(user_data, sa->siucv_name);
808	low_nmcpy(user_data, iucv->src_name);
809	ASCEBC(user_data, sizeof(user_data));
810
811	/* Create path. */
812	iucv->path = iucv_path_alloc(iucv->msglimit,
813				     IUCV_IPRMDATA, GFP_KERNEL);
814	if (!iucv->path) {
815		err = -ENOMEM;
816		goto done;
817	}
818	err = pr_iucv->path_connect(iucv->path, &af_iucv_handler,
819				    sa->siucv_user_id, NULL, user_data,
820				    sk);
821	if (err) {
822		iucv_path_free(iucv->path);
823		iucv->path = NULL;
824		switch (err) {
825		case 0x0b:	/* Target communicator is not logged on */
826			err = -ENETUNREACH;
827			break;
828		case 0x0d:	/* Max connections for this guest exceeded */
829		case 0x0e:	/* Max connections for target guest exceeded */
830			err = -EAGAIN;
831			break;
832		case 0x0f:	/* Missing IUCV authorization */
833			err = -EACCES;
834			break;
835		default:
836			err = -ECONNREFUSED;
837			break;
838		}
839	}
840done:
841	return err;
842}
843
844/* Connect an unconnected socket */
845static int iucv_sock_connect(struct socket *sock, struct sockaddr *addr,
846			     int alen, int flags)
847{
848	struct sockaddr_iucv *sa = (struct sockaddr_iucv *) addr;
849	struct sock *sk = sock->sk;
850	struct iucv_sock *iucv = iucv_sk(sk);
851	int err;
852
853	if (addr->sa_family != AF_IUCV || alen < sizeof(struct sockaddr_iucv))
854		return -EINVAL;
855
856	if (sk->sk_state != IUCV_OPEN && sk->sk_state != IUCV_BOUND)
857		return -EBADFD;
858
859	if (sk->sk_state == IUCV_OPEN &&
860	    iucv->transport == AF_IUCV_TRANS_HIPER)
861		return -EBADFD; /* explicit bind required */
862
863	if (sk->sk_type != SOCK_STREAM && sk->sk_type != SOCK_SEQPACKET)
864		return -EINVAL;
865
866	if (sk->sk_state == IUCV_OPEN) {
867		err = iucv_sock_autobind(sk);
868		if (unlikely(err))
869			return err;
870	}
871
872	lock_sock(sk);
873
874	/* Set the destination information */
875	memcpy(iucv->dst_user_id, sa->siucv_user_id, 8);
876	memcpy(iucv->dst_name, sa->siucv_name, 8);
877
878	if (iucv->transport == AF_IUCV_TRANS_HIPER)
879		err = iucv_send_ctrl(sock->sk, AF_IUCV_FLAG_SYN);
880	else
881		err = afiucv_path_connect(sock, addr);
882	if (err)
883		goto done;
884
885	if (sk->sk_state != IUCV_CONNECTED)
886		err = iucv_sock_wait(sk, iucv_sock_in_state(sk, IUCV_CONNECTED,
887							    IUCV_DISCONN),
888				     sock_sndtimeo(sk, flags & O_NONBLOCK));
889
890	if (sk->sk_state == IUCV_DISCONN || sk->sk_state == IUCV_CLOSED)
891		err = -ECONNREFUSED;
892
893	if (err && iucv->transport == AF_IUCV_TRANS_IUCV)
894		iucv_sever_path(sk, 0);
895
896done:
897	release_sock(sk);
898	return err;
899}
900
901/* Move a socket into listening state. */
902static int iucv_sock_listen(struct socket *sock, int backlog)
903{
904	struct sock *sk = sock->sk;
905	int err;
906
907	lock_sock(sk);
908
909	err = -EINVAL;
910	if (sk->sk_state != IUCV_BOUND)
911		goto done;
912
913	if (sock->type != SOCK_STREAM && sock->type != SOCK_SEQPACKET)
914		goto done;
915
916	sk->sk_max_ack_backlog = backlog;
917	sk->sk_ack_backlog = 0;
918	sk->sk_state = IUCV_LISTEN;
919	err = 0;
920
921done:
922	release_sock(sk);
923	return err;
924}
925
926/* Accept a pending connection */
927static int iucv_sock_accept(struct socket *sock, struct socket *newsock,
928			    int flags)
929{
930	DECLARE_WAITQUEUE(wait, current);
931	struct sock *sk = sock->sk, *nsk;
932	long timeo;
933	int err = 0;
934
935	lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
936
937	if (sk->sk_state != IUCV_LISTEN) {
938		err = -EBADFD;
939		goto done;
940	}
941
942	timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
943
944	/* Wait for an incoming connection */
945	add_wait_queue_exclusive(sk_sleep(sk), &wait);
946	while (!(nsk = iucv_accept_dequeue(sk, newsock))) {
947		set_current_state(TASK_INTERRUPTIBLE);
948		if (!timeo) {
949			err = -EAGAIN;
950			break;
951		}
952
953		release_sock(sk);
954		timeo = schedule_timeout(timeo);
955		lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
956
957		if (sk->sk_state != IUCV_LISTEN) {
958			err = -EBADFD;
959			break;
960		}
961
962		if (signal_pending(current)) {
963			err = sock_intr_errno(timeo);
964			break;
965		}
966	}
967
968	set_current_state(TASK_RUNNING);
969	remove_wait_queue(sk_sleep(sk), &wait);
970
971	if (err)
972		goto done;
973
974	newsock->state = SS_CONNECTED;
975
976done:
977	release_sock(sk);
978	return err;
979}
980
981static int iucv_sock_getname(struct socket *sock, struct sockaddr *addr,
982			     int *len, int peer)
983{
984	struct sockaddr_iucv *siucv = (struct sockaddr_iucv *) addr;
985	struct sock *sk = sock->sk;
986	struct iucv_sock *iucv = iucv_sk(sk);
987
988	addr->sa_family = AF_IUCV;
989	*len = sizeof(struct sockaddr_iucv);
990
991	if (peer) {
992		memcpy(siucv->siucv_user_id, iucv->dst_user_id, 8);
993		memcpy(siucv->siucv_name, iucv->dst_name, 8);
994	} else {
995		memcpy(siucv->siucv_user_id, iucv->src_user_id, 8);
996		memcpy(siucv->siucv_name, iucv->src_name, 8);
997	}
998	memset(&siucv->siucv_port, 0, sizeof(siucv->siucv_port));
999	memset(&siucv->siucv_addr, 0, sizeof(siucv->siucv_addr));
1000	memset(&siucv->siucv_nodeid, 0, sizeof(siucv->siucv_nodeid));
1001
1002	return 0;
1003}
1004
1005/**
1006 * iucv_send_iprm() - Send socket data in parameter list of an iucv message.
1007 * @path:	IUCV path
1008 * @msg:	Pointer to a struct iucv_message
1009 * @skb:	The socket data to send, skb->len MUST BE <= 7
1010 *
1011 * Send the socket data in the parameter list in the iucv message
1012 * (IUCV_IPRMDATA). The socket data is stored at index 0 to 6 in the parameter
1013 * list and the socket data len at index 7 (last byte).
1014 * See also iucv_msg_length().
1015 *
1016 * Returns the error code from the iucv_message_send() call.
1017 */
1018static int iucv_send_iprm(struct iucv_path *path, struct iucv_message *msg,
1019			  struct sk_buff *skb)
1020{
1021	u8 prmdata[8];
1022
1023	memcpy(prmdata, (void *) skb->data, skb->len);
1024	prmdata[7] = 0xff - (u8) skb->len;
1025	return pr_iucv->message_send(path, msg, IUCV_IPRMDATA, 0,
1026				 (void *) prmdata, 8);
1027}
1028
1029static int iucv_sock_sendmsg(struct kiocb *iocb, struct socket *sock,
1030			     struct msghdr *msg, size_t len)
1031{
1032	struct sock *sk = sock->sk;
1033	struct iucv_sock *iucv = iucv_sk(sk);
1034	struct sk_buff *skb;
1035	struct iucv_message txmsg;
1036	struct cmsghdr *cmsg;
1037	int cmsg_done;
1038	long timeo;
1039	char user_id[9];
1040	char appl_id[9];
1041	int err;
1042	int noblock = msg->msg_flags & MSG_DONTWAIT;
1043
1044	err = sock_error(sk);
1045	if (err)
1046		return err;
1047
1048	if (msg->msg_flags & MSG_OOB)
1049		return -EOPNOTSUPP;
1050
1051	/* SOCK_SEQPACKET: we do not support segmented records */
1052	if (sk->sk_type == SOCK_SEQPACKET && !(msg->msg_flags & MSG_EOR))
1053		return -EOPNOTSUPP;
1054
1055	lock_sock(sk);
1056
1057	if (sk->sk_shutdown & SEND_SHUTDOWN) {
1058		err = -EPIPE;
1059		goto out;
1060	}
1061
1062	/* Return if the socket is not in connected state */
1063	if (sk->sk_state != IUCV_CONNECTED) {
1064		err = -ENOTCONN;
1065		goto out;
1066	}
1067
1068	/* initialize defaults */
1069	cmsg_done   = 0;	/* check for duplicate headers */
1070	txmsg.class = 0;
1071
1072	/* iterate over control messages */
1073	for (cmsg = CMSG_FIRSTHDR(msg); cmsg;
1074		cmsg = CMSG_NXTHDR(msg, cmsg)) {
1075
1076		if (!CMSG_OK(msg, cmsg)) {
1077			err = -EINVAL;
1078			goto out;
1079		}
1080
1081		if (cmsg->cmsg_level != SOL_IUCV)
1082			continue;
1083
1084		if (cmsg->cmsg_type & cmsg_done) {
1085			err = -EINVAL;
1086			goto out;
1087		}
1088		cmsg_done |= cmsg->cmsg_type;
1089
1090		switch (cmsg->cmsg_type) {
1091		case SCM_IUCV_TRGCLS:
1092			if (cmsg->cmsg_len != CMSG_LEN(TRGCLS_SIZE)) {
1093				err = -EINVAL;
1094				goto out;
1095			}
1096
1097			/* set iucv message target class */
1098			memcpy(&txmsg.class,
1099				(void *) CMSG_DATA(cmsg), TRGCLS_SIZE);
1100
1101			break;
1102
1103		default:
1104			err = -EINVAL;
1105			goto out;
1106		}
1107	}
1108
1109	/* allocate one skb for each iucv message:
1110	 * this is fine for SOCK_SEQPACKET (unless we want to support
1111	 * segmented records using the MSG_EOR flag), but
1112	 * for SOCK_STREAM we might want to improve it in future */
1113	if (iucv->transport == AF_IUCV_TRANS_HIPER)
1114		skb = sock_alloc_send_skb(sk,
1115			len + sizeof(struct af_iucv_trans_hdr) + ETH_HLEN,
1116			noblock, &err);
1117	else
1118		skb = sock_alloc_send_skb(sk, len, noblock, &err);
1119	if (!skb) {
1120		err = -ENOMEM;
1121		goto out;
1122	}
1123	if (iucv->transport == AF_IUCV_TRANS_HIPER)
1124		skb_reserve(skb, sizeof(struct af_iucv_trans_hdr) + ETH_HLEN);
1125	if (memcpy_fromiovec(skb_put(skb, len), msg->msg_iov, len)) {
1126		err = -EFAULT;
1127		goto fail;
1128	}
1129
1130	/* wait if outstanding messages for iucv path has reached */
1131	timeo = sock_sndtimeo(sk, noblock);
1132	err = iucv_sock_wait(sk, iucv_below_msglim(sk), timeo);
1133	if (err)
1134		goto fail;
1135
1136	/* return -ECONNRESET if the socket is no longer connected */
1137	if (sk->sk_state != IUCV_CONNECTED) {
1138		err = -ECONNRESET;
1139		goto fail;
1140	}
1141
1142	/* increment and save iucv message tag for msg_completion cbk */
1143	txmsg.tag = iucv->send_tag++;
1144	IUCV_SKB_CB(skb)->tag = txmsg.tag;
1145
1146	if (iucv->transport == AF_IUCV_TRANS_HIPER) {
1147		atomic_inc(&iucv->msg_sent);
1148		err = afiucv_hs_send(&txmsg, sk, skb, 0);
1149		if (err) {
1150			atomic_dec(&iucv->msg_sent);
1151			goto fail;
1152		}
1153		goto release;
1154	}
1155	skb_queue_tail(&iucv->send_skb_q, skb);
1156
1157	if (((iucv->path->flags & IUCV_IPRMDATA) & iucv->flags)
1158	      && skb->len <= 7) {
1159		err = iucv_send_iprm(iucv->path, &txmsg, skb);
1160
1161		/* on success: there is no message_complete callback
1162		 * for an IPRMDATA msg; remove skb from send queue */
1163		if (err == 0) {
1164			skb_unlink(skb, &iucv->send_skb_q);
1165			kfree_skb(skb);
1166		}
1167
1168		/* this error should never happen since the
1169		 * IUCV_IPRMDATA path flag is set... sever path */
1170		if (err == 0x15) {
1171			pr_iucv->path_sever(iucv->path, NULL);
1172			skb_unlink(skb, &iucv->send_skb_q);
1173			err = -EPIPE;
1174			goto fail;
1175		}
1176	} else
1177		err = pr_iucv->message_send(iucv->path, &txmsg, 0, 0,
1178					(void *) skb->data, skb->len);
1179	if (err) {
1180		if (err == 3) {
1181			user_id[8] = 0;
1182			memcpy(user_id, iucv->dst_user_id, 8);
1183			appl_id[8] = 0;
1184			memcpy(appl_id, iucv->dst_name, 8);
1185			pr_err("Application %s on z/VM guest %s"
1186				" exceeds message limit\n",
1187				appl_id, user_id);
1188			err = -EAGAIN;
1189		} else
1190			err = -EPIPE;
1191		skb_unlink(skb, &iucv->send_skb_q);
1192		goto fail;
1193	}
1194
1195release:
1196	release_sock(sk);
1197	return len;
1198
1199fail:
1200	kfree_skb(skb);
1201out:
1202	release_sock(sk);
1203	return err;
1204}
1205
1206/* iucv_fragment_skb() - Fragment a single IUCV message into multiple skb's
1207 *
1208 * Locking: must be called with message_q.lock held
1209 */
1210static int iucv_fragment_skb(struct sock *sk, struct sk_buff *skb, int len)
1211{
1212	int dataleft, size, copied = 0;
1213	struct sk_buff *nskb;
1214
1215	dataleft = len;
1216	while (dataleft) {
1217		if (dataleft >= sk->sk_rcvbuf / 4)
1218			size = sk->sk_rcvbuf / 4;
1219		else
1220			size = dataleft;
1221
1222		nskb = alloc_skb(size, GFP_ATOMIC | GFP_DMA);
1223		if (!nskb)
1224			return -ENOMEM;
1225
1226		/* copy target class to control buffer of new skb */
1227		IUCV_SKB_CB(nskb)->class = IUCV_SKB_CB(skb)->class;
1228
1229		/* copy data fragment */
1230		memcpy(nskb->data, skb->data + copied, size);
1231		copied += size;
1232		dataleft -= size;
1233
1234		skb_reset_transport_header(nskb);
1235		skb_reset_network_header(nskb);
1236		nskb->len = size;
1237
1238		skb_queue_tail(&iucv_sk(sk)->backlog_skb_q, nskb);
1239	}
1240
1241	return 0;
1242}
1243
1244/* iucv_process_message() - Receive a single outstanding IUCV message
1245 *
1246 * Locking: must be called with message_q.lock held
1247 */
1248static void iucv_process_message(struct sock *sk, struct sk_buff *skb,
1249				 struct iucv_path *path,
1250				 struct iucv_message *msg)
1251{
1252	int rc;
1253	unsigned int len;
1254
1255	len = iucv_msg_length(msg);
1256
1257	/* store msg target class in the second 4 bytes of skb ctrl buffer */
1258	/* Note: the first 4 bytes are reserved for msg tag */
1259	IUCV_SKB_CB(skb)->class = msg->class;
1260
1261	/* check for special IPRM messages (e.g. iucv_sock_shutdown) */
1262	if ((msg->flags & IUCV_IPRMDATA) && len > 7) {
1263		if (memcmp(msg->rmmsg, iprm_shutdown, 8) == 0) {
1264			skb->data = NULL;
1265			skb->len = 0;
1266		}
1267	} else {
1268		rc = pr_iucv->message_receive(path, msg,
1269					      msg->flags & IUCV_IPRMDATA,
1270					      skb->data, len, NULL);
1271		if (rc) {
1272			kfree_skb(skb);
1273			return;
1274		}
1275		/* we need to fragment iucv messages for SOCK_STREAM only;
1276		 * for SOCK_SEQPACKET, it is only relevant if we support
1277		 * record segmentation using MSG_EOR (see also recvmsg()) */
1278		if (sk->sk_type == SOCK_STREAM &&
1279		    skb->truesize >= sk->sk_rcvbuf / 4) {
1280			rc = iucv_fragment_skb(sk, skb, len);
1281			kfree_skb(skb);
1282			skb = NULL;
1283			if (rc) {
1284				pr_iucv->path_sever(path, NULL);
1285				return;
1286			}
1287			skb = skb_dequeue(&iucv_sk(sk)->backlog_skb_q);
1288		} else {
1289			skb_reset_transport_header(skb);
1290			skb_reset_network_header(skb);
1291			skb->len = len;
1292		}
1293	}
1294
1295	IUCV_SKB_CB(skb)->offset = 0;
1296	if (sock_queue_rcv_skb(sk, skb))
1297		skb_queue_head(&iucv_sk(sk)->backlog_skb_q, skb);
1298}
1299
1300/* iucv_process_message_q() - Process outstanding IUCV messages
1301 *
1302 * Locking: must be called with message_q.lock held
1303 */
1304static void iucv_process_message_q(struct sock *sk)
1305{
1306	struct iucv_sock *iucv = iucv_sk(sk);
1307	struct sk_buff *skb;
1308	struct sock_msg_q *p, *n;
1309
1310	list_for_each_entry_safe(p, n, &iucv->message_q.list, list) {
1311		skb = alloc_skb(iucv_msg_length(&p->msg), GFP_ATOMIC | GFP_DMA);
1312		if (!skb)
1313			break;
1314		iucv_process_message(sk, skb, p->path, &p->msg);
1315		list_del(&p->list);
1316		kfree(p);
1317		if (!skb_queue_empty(&iucv->backlog_skb_q))
1318			break;
1319	}
1320}
1321
1322static int iucv_sock_recvmsg(struct kiocb *iocb, struct socket *sock,
1323			     struct msghdr *msg, size_t len, int flags)
1324{
1325	int noblock = flags & MSG_DONTWAIT;
1326	struct sock *sk = sock->sk;
1327	struct iucv_sock *iucv = iucv_sk(sk);
1328	unsigned int copied, rlen;
1329	struct sk_buff *skb, *rskb, *cskb;
1330	int err = 0;
1331	u32 offset;
1332
1333	if ((sk->sk_state == IUCV_DISCONN) &&
1334	    skb_queue_empty(&iucv->backlog_skb_q) &&
1335	    skb_queue_empty(&sk->sk_receive_queue) &&
1336	    list_empty(&iucv->message_q.list))
1337		return 0;
1338
1339	if (flags & (MSG_OOB))
1340		return -EOPNOTSUPP;
1341
1342	/* receive/dequeue next skb:
1343	 * the function understands MSG_PEEK and, thus, does not dequeue skb */
1344	skb = skb_recv_datagram(sk, flags, noblock, &err);
1345	if (!skb) {
1346		if (sk->sk_shutdown & RCV_SHUTDOWN)
1347			return 0;
1348		return err;
1349	}
1350
1351	offset = IUCV_SKB_CB(skb)->offset;
1352	rlen   = skb->len - offset;		/* real length of skb */
1353	copied = min_t(unsigned int, rlen, len);
1354	if (!rlen)
1355		sk->sk_shutdown = sk->sk_shutdown | RCV_SHUTDOWN;
1356
1357	cskb = skb;
1358	if (skb_copy_datagram_iovec(cskb, offset, msg->msg_iov, copied)) {
1359		if (!(flags & MSG_PEEK))
1360			skb_queue_head(&sk->sk_receive_queue, skb);
1361		return -EFAULT;
1362	}
1363
1364	/* SOCK_SEQPACKET: set MSG_TRUNC if recv buf size is too small */
1365	if (sk->sk_type == SOCK_SEQPACKET) {
1366		if (copied < rlen)
1367			msg->msg_flags |= MSG_TRUNC;
1368		/* each iucv message contains a complete record */
1369		msg->msg_flags |= MSG_EOR;
1370	}
1371
1372	/* create control message to store iucv msg target class:
1373	 * get the trgcls from the control buffer of the skb due to
1374	 * fragmentation of original iucv message. */
1375	err = put_cmsg(msg, SOL_IUCV, SCM_IUCV_TRGCLS,
1376		       sizeof(IUCV_SKB_CB(skb)->class),
1377		       (void *)&IUCV_SKB_CB(skb)->class);
1378	if (err) {
1379		if (!(flags & MSG_PEEK))
1380			skb_queue_head(&sk->sk_receive_queue, skb);
1381		return err;
1382	}
1383
1384	/* Mark read part of skb as used */
1385	if (!(flags & MSG_PEEK)) {
1386
1387		/* SOCK_STREAM: re-queue skb if it contains unreceived data */
1388		if (sk->sk_type == SOCK_STREAM) {
1389			if (copied < rlen) {
1390				IUCV_SKB_CB(skb)->offset = offset + copied;
1391				skb_queue_head(&sk->sk_receive_queue, skb);
1392				goto done;
1393			}
1394		}
1395
1396		kfree_skb(skb);
1397		if (iucv->transport == AF_IUCV_TRANS_HIPER) {
1398			atomic_inc(&iucv->msg_recv);
1399			if (atomic_read(&iucv->msg_recv) > iucv->msglimit) {
1400				WARN_ON(1);
1401				iucv_sock_close(sk);
1402				return -EFAULT;
1403			}
1404		}
1405
1406		/* Queue backlog skbs */
1407		spin_lock_bh(&iucv->message_q.lock);
1408		rskb = skb_dequeue(&iucv->backlog_skb_q);
1409		while (rskb) {
1410			IUCV_SKB_CB(rskb)->offset = 0;
1411			if (sock_queue_rcv_skb(sk, rskb)) {
1412				skb_queue_head(&iucv->backlog_skb_q,
1413						rskb);
1414				break;
1415			} else {
1416				rskb = skb_dequeue(&iucv->backlog_skb_q);
1417			}
1418		}
1419		if (skb_queue_empty(&iucv->backlog_skb_q)) {
1420			if (!list_empty(&iucv->message_q.list))
1421				iucv_process_message_q(sk);
1422			if (atomic_read(&iucv->msg_recv) >=
1423							iucv->msglimit / 2) {
1424				err = iucv_send_ctrl(sk, AF_IUCV_FLAG_WIN);
1425				if (err) {
1426					sk->sk_state = IUCV_DISCONN;
1427					sk->sk_state_change(sk);
1428				}
1429			}
1430		}
1431		spin_unlock_bh(&iucv->message_q.lock);
1432	}
1433
1434done:
1435	/* SOCK_SEQPACKET: return real length if MSG_TRUNC is set */
1436	if (sk->sk_type == SOCK_SEQPACKET && (flags & MSG_TRUNC))
1437		copied = rlen;
1438
1439	return copied;
1440}
1441
1442static inline unsigned int iucv_accept_poll(struct sock *parent)
1443{
1444	struct iucv_sock *isk, *n;
1445	struct sock *sk;
1446
1447	list_for_each_entry_safe(isk, n, &iucv_sk(parent)->accept_q, accept_q) {
1448		sk = (struct sock *) isk;
1449
1450		if (sk->sk_state == IUCV_CONNECTED)
1451			return POLLIN | POLLRDNORM;
1452	}
1453
1454	return 0;
1455}
1456
1457unsigned int iucv_sock_poll(struct file *file, struct socket *sock,
1458			    poll_table *wait)
1459{
1460	struct sock *sk = sock->sk;
1461	unsigned int mask = 0;
1462
1463	sock_poll_wait(file, sk_sleep(sk), wait);
1464
1465	if (sk->sk_state == IUCV_LISTEN)
1466		return iucv_accept_poll(sk);
1467
1468	if (sk->sk_err || !skb_queue_empty(&sk->sk_error_queue))
1469		mask |= POLLERR |
1470			(sock_flag(sk, SOCK_SELECT_ERR_QUEUE) ? POLLPRI : 0);
1471
1472	if (sk->sk_shutdown & RCV_SHUTDOWN)
1473		mask |= POLLRDHUP;
1474
1475	if (sk->sk_shutdown == SHUTDOWN_MASK)
1476		mask |= POLLHUP;
1477
1478	if (!skb_queue_empty(&sk->sk_receive_queue) ||
1479	    (sk->sk_shutdown & RCV_SHUTDOWN))
1480		mask |= POLLIN | POLLRDNORM;
1481
1482	if (sk->sk_state == IUCV_CLOSED)
1483		mask |= POLLHUP;
1484
1485	if (sk->sk_state == IUCV_DISCONN)
1486		mask |= POLLIN;
1487
1488	if (sock_writeable(sk) && iucv_below_msglim(sk))
1489		mask |= POLLOUT | POLLWRNORM | POLLWRBAND;
1490	else
1491		set_bit(SOCK_ASYNC_NOSPACE, &sk->sk_socket->flags);
1492
1493	return mask;
1494}
1495
1496static int iucv_sock_shutdown(struct socket *sock, int how)
1497{
1498	struct sock *sk = sock->sk;
1499	struct iucv_sock *iucv = iucv_sk(sk);
1500	struct iucv_message txmsg;
1501	int err = 0;
1502
1503	how++;
1504
1505	if ((how & ~SHUTDOWN_MASK) || !how)
1506		return -EINVAL;
1507
1508	lock_sock(sk);
1509	switch (sk->sk_state) {
1510	case IUCV_LISTEN:
1511	case IUCV_DISCONN:
1512	case IUCV_CLOSING:
1513	case IUCV_CLOSED:
1514		err = -ENOTCONN;
1515		goto fail;
1516	default:
1517		break;
1518	}
1519
1520	if (how == SEND_SHUTDOWN || how == SHUTDOWN_MASK) {
1521		if (iucv->transport == AF_IUCV_TRANS_IUCV) {
1522			txmsg.class = 0;
1523			txmsg.tag = 0;
1524			err = pr_iucv->message_send(iucv->path, &txmsg,
1525				IUCV_IPRMDATA, 0, (void *) iprm_shutdown, 8);
1526			if (err) {
1527				switch (err) {
1528				case 1:
1529					err = -ENOTCONN;
1530					break;
1531				case 2:
1532					err = -ECONNRESET;
1533					break;
1534				default:
1535					err = -ENOTCONN;
1536					break;
1537				}
1538			}
1539		} else
1540			iucv_send_ctrl(sk, AF_IUCV_FLAG_SHT);
1541	}
1542
1543	sk->sk_shutdown |= how;
1544	if (how == RCV_SHUTDOWN || how == SHUTDOWN_MASK) {
1545		if ((iucv->transport == AF_IUCV_TRANS_IUCV) &&
1546		    iucv->path) {
1547			err = pr_iucv->path_quiesce(iucv->path, NULL);
1548			if (err)
1549				err = -ENOTCONN;
1550/*			skb_queue_purge(&sk->sk_receive_queue); */
1551		}
1552		skb_queue_purge(&sk->sk_receive_queue);
1553	}
1554
1555	/* Wake up anyone sleeping in poll */
1556	sk->sk_state_change(sk);
1557
1558fail:
1559	release_sock(sk);
1560	return err;
1561}
1562
1563static int iucv_sock_release(struct socket *sock)
1564{
1565	struct sock *sk = sock->sk;
1566	int err = 0;
1567
1568	if (!sk)
1569		return 0;
1570
1571	iucv_sock_close(sk);
1572
1573	sock_orphan(sk);
1574	iucv_sock_kill(sk);
1575	return err;
1576}
1577
1578/* getsockopt and setsockopt */
1579static int iucv_sock_setsockopt(struct socket *sock, int level, int optname,
1580				char __user *optval, unsigned int optlen)
1581{
1582	struct sock *sk = sock->sk;
1583	struct iucv_sock *iucv = iucv_sk(sk);
1584	int val;
1585	int rc;
1586
1587	if (level != SOL_IUCV)
1588		return -ENOPROTOOPT;
1589
1590	if (optlen < sizeof(int))
1591		return -EINVAL;
1592
1593	if (get_user(val, (int __user *) optval))
1594		return -EFAULT;
1595
1596	rc = 0;
1597
1598	lock_sock(sk);
1599	switch (optname) {
1600	case SO_IPRMDATA_MSG:
1601		if (val)
1602			iucv->flags |= IUCV_IPRMDATA;
1603		else
1604			iucv->flags &= ~IUCV_IPRMDATA;
1605		break;
1606	case SO_MSGLIMIT:
1607		switch (sk->sk_state) {
1608		case IUCV_OPEN:
1609		case IUCV_BOUND:
1610			if (val < 1 || val > (u16)(~0))
1611				rc = -EINVAL;
1612			else
1613				iucv->msglimit = val;
1614			break;
1615		default:
1616			rc = -EINVAL;
1617			break;
1618		}
1619		break;
1620	default:
1621		rc = -ENOPROTOOPT;
1622		break;
1623	}
1624	release_sock(sk);
1625
1626	return rc;
1627}
1628
1629static int iucv_sock_getsockopt(struct socket *sock, int level, int optname,
1630				char __user *optval, int __user *optlen)
1631{
1632	struct sock *sk = sock->sk;
1633	struct iucv_sock *iucv = iucv_sk(sk);
1634	unsigned int val;
1635	int len;
1636
1637	if (level != SOL_IUCV)
1638		return -ENOPROTOOPT;
1639
1640	if (get_user(len, optlen))
1641		return -EFAULT;
1642
1643	if (len < 0)
1644		return -EINVAL;
1645
1646	len = min_t(unsigned int, len, sizeof(int));
1647
1648	switch (optname) {
1649	case SO_IPRMDATA_MSG:
1650		val = (iucv->flags & IUCV_IPRMDATA) ? 1 : 0;
1651		break;
1652	case SO_MSGLIMIT:
1653		lock_sock(sk);
1654		val = (iucv->path != NULL) ? iucv->path->msglim	/* connected */
1655					   : iucv->msglimit;	/* default */
1656		release_sock(sk);
1657		break;
1658	case SO_MSGSIZE:
1659		if (sk->sk_state == IUCV_OPEN)
1660			return -EBADFD;
1661		val = (iucv->hs_dev) ? iucv->hs_dev->mtu -
1662				sizeof(struct af_iucv_trans_hdr) - ETH_HLEN :
1663				0x7fffffff;
1664		break;
1665	default:
1666		return -ENOPROTOOPT;
1667	}
1668
1669	if (put_user(len, optlen))
1670		return -EFAULT;
1671	if (copy_to_user(optval, &val, len))
1672		return -EFAULT;
1673
1674	return 0;
1675}
1676
1677
1678/* Callback wrappers - called from iucv base support */
1679static int iucv_callback_connreq(struct iucv_path *path,
1680				 u8 ipvmid[8], u8 ipuser[16])
1681{
1682	unsigned char user_data[16];
1683	unsigned char nuser_data[16];
1684	unsigned char src_name[8];
1685	struct sock *sk, *nsk;
1686	struct iucv_sock *iucv, *niucv;
1687	int err;
1688
1689	memcpy(src_name, ipuser, 8);
1690	EBCASC(src_name, 8);
1691	/* Find out if this path belongs to af_iucv. */
1692	read_lock(&iucv_sk_list.lock);
1693	iucv = NULL;
1694	sk = NULL;
1695	sk_for_each(sk, &iucv_sk_list.head)
1696		if (sk->sk_state == IUCV_LISTEN &&
1697		    !memcmp(&iucv_sk(sk)->src_name, src_name, 8)) {
1698			/*
1699			 * Found a listening socket with
1700			 * src_name == ipuser[0-7].
1701			 */
1702			iucv = iucv_sk(sk);
1703			break;
1704		}
1705	read_unlock(&iucv_sk_list.lock);
1706	if (!iucv)
1707		/* No socket found, not one of our paths. */
1708		return -EINVAL;
1709
1710	bh_lock_sock(sk);
1711
1712	/* Check if parent socket is listening */
1713	low_nmcpy(user_data, iucv->src_name);
1714	high_nmcpy(user_data, iucv->dst_name);
1715	ASCEBC(user_data, sizeof(user_data));
1716	if (sk->sk_state != IUCV_LISTEN) {
1717		err = pr_iucv->path_sever(path, user_data);
1718		iucv_path_free(path);
1719		goto fail;
1720	}
1721
1722	/* Check for backlog size */
1723	if (sk_acceptq_is_full(sk)) {
1724		err = pr_iucv->path_sever(path, user_data);
1725		iucv_path_free(path);
1726		goto fail;
1727	}
1728
1729	/* Create the new socket */
1730	nsk = iucv_sock_alloc(NULL, sk->sk_type, GFP_ATOMIC);
1731	if (!nsk) {
1732		err = pr_iucv->path_sever(path, user_data);
1733		iucv_path_free(path);
1734		goto fail;
1735	}
1736
1737	niucv = iucv_sk(nsk);
1738	iucv_sock_init(nsk, sk);
1739
1740	/* Set the new iucv_sock */
1741	memcpy(niucv->dst_name, ipuser + 8, 8);
1742	EBCASC(niucv->dst_name, 8);
1743	memcpy(niucv->dst_user_id, ipvmid, 8);
1744	memcpy(niucv->src_name, iucv->src_name, 8);
1745	memcpy(niucv->src_user_id, iucv->src_user_id, 8);
1746	niucv->path = path;
1747
1748	/* Call iucv_accept */
1749	high_nmcpy(nuser_data, ipuser + 8);
1750	memcpy(nuser_data + 8, niucv->src_name, 8);
1751	ASCEBC(nuser_data + 8, 8);
1752
1753	/* set message limit for path based on msglimit of accepting socket */
1754	niucv->msglimit = iucv->msglimit;
1755	path->msglim = iucv->msglimit;
1756	err = pr_iucv->path_accept(path, &af_iucv_handler, nuser_data, nsk);
1757	if (err) {
1758		iucv_sever_path(nsk, 1);
1759		iucv_sock_kill(nsk);
1760		goto fail;
1761	}
1762
1763	iucv_accept_enqueue(sk, nsk);
1764
1765	/* Wake up accept */
1766	nsk->sk_state = IUCV_CONNECTED;
1767	sk->sk_data_ready(sk);
1768	err = 0;
1769fail:
1770	bh_unlock_sock(sk);
1771	return 0;
1772}
1773
1774static void iucv_callback_connack(struct iucv_path *path, u8 ipuser[16])
1775{
1776	struct sock *sk = path->private;
1777
1778	sk->sk_state = IUCV_CONNECTED;
1779	sk->sk_state_change(sk);
1780}
1781
1782static void iucv_callback_rx(struct iucv_path *path, struct iucv_message *msg)
1783{
1784	struct sock *sk = path->private;
1785	struct iucv_sock *iucv = iucv_sk(sk);
1786	struct sk_buff *skb;
1787	struct sock_msg_q *save_msg;
1788	int len;
1789
1790	if (sk->sk_shutdown & RCV_SHUTDOWN) {
1791		pr_iucv->message_reject(path, msg);
1792		return;
1793	}
1794
1795	spin_lock(&iucv->message_q.lock);
1796
1797	if (!list_empty(&iucv->message_q.list) ||
1798	    !skb_queue_empty(&iucv->backlog_skb_q))
1799		goto save_message;
1800
1801	len = atomic_read(&sk->sk_rmem_alloc);
1802	len += SKB_TRUESIZE(iucv_msg_length(msg));
1803	if (len > sk->sk_rcvbuf)
1804		goto save_message;
1805
1806	skb = alloc_skb(iucv_msg_length(msg), GFP_ATOMIC | GFP_DMA);
1807	if (!skb)
1808		goto save_message;
1809
1810	iucv_process_message(sk, skb, path, msg);
1811	goto out_unlock;
1812
1813save_message:
1814	save_msg = kzalloc(sizeof(struct sock_msg_q), GFP_ATOMIC | GFP_DMA);
1815	if (!save_msg)
1816		goto out_unlock;
1817	save_msg->path = path;
1818	save_msg->msg = *msg;
1819
1820	list_add_tail(&save_msg->list, &iucv->message_q.list);
1821
1822out_unlock:
1823	spin_unlock(&iucv->message_q.lock);
1824}
1825
1826static void iucv_callback_txdone(struct iucv_path *path,
1827				 struct iucv_message *msg)
1828{
1829	struct sock *sk = path->private;
1830	struct sk_buff *this = NULL;
1831	struct sk_buff_head *list = &iucv_sk(sk)->send_skb_q;
1832	struct sk_buff *list_skb = list->next;
1833	unsigned long flags;
1834
1835	bh_lock_sock(sk);
1836	if (!skb_queue_empty(list)) {
1837		spin_lock_irqsave(&list->lock, flags);
1838
1839		while (list_skb != (struct sk_buff *)list) {
1840			if (msg->tag == IUCV_SKB_CB(list_skb)->tag) {
1841				this = list_skb;
1842				break;
1843			}
1844			list_skb = list_skb->next;
1845		}
1846		if (this)
1847			__skb_unlink(this, list);
1848
1849		spin_unlock_irqrestore(&list->lock, flags);
1850
1851		if (this) {
1852			kfree_skb(this);
1853			/* wake up any process waiting for sending */
1854			iucv_sock_wake_msglim(sk);
1855		}
1856	}
1857
1858	if (sk->sk_state == IUCV_CLOSING) {
1859		if (skb_queue_empty(&iucv_sk(sk)->send_skb_q)) {
1860			sk->sk_state = IUCV_CLOSED;
1861			sk->sk_state_change(sk);
1862		}
1863	}
1864	bh_unlock_sock(sk);
1865
1866}
1867
1868static void iucv_callback_connrej(struct iucv_path *path, u8 ipuser[16])
1869{
1870	struct sock *sk = path->private;
1871
1872	if (sk->sk_state == IUCV_CLOSED)
1873		return;
1874
1875	bh_lock_sock(sk);
1876	iucv_sever_path(sk, 1);
1877	sk->sk_state = IUCV_DISCONN;
1878
1879	sk->sk_state_change(sk);
1880	bh_unlock_sock(sk);
1881}
1882
1883/* called if the other communication side shuts down its RECV direction;
1884 * in turn, the callback sets SEND_SHUTDOWN to disable sending of data.
1885 */
1886static void iucv_callback_shutdown(struct iucv_path *path, u8 ipuser[16])
1887{
1888	struct sock *sk = path->private;
1889
1890	bh_lock_sock(sk);
1891	if (sk->sk_state != IUCV_CLOSED) {
1892		sk->sk_shutdown |= SEND_SHUTDOWN;
1893		sk->sk_state_change(sk);
1894	}
1895	bh_unlock_sock(sk);
1896}
1897
1898/***************** HiperSockets transport callbacks ********************/
1899static void afiucv_swap_src_dest(struct sk_buff *skb)
1900{
1901	struct af_iucv_trans_hdr *trans_hdr =
1902				(struct af_iucv_trans_hdr *)skb->data;
1903	char tmpID[8];
1904	char tmpName[8];
1905
1906	ASCEBC(trans_hdr->destUserID, sizeof(trans_hdr->destUserID));
1907	ASCEBC(trans_hdr->destAppName, sizeof(trans_hdr->destAppName));
1908	ASCEBC(trans_hdr->srcUserID, sizeof(trans_hdr->srcUserID));
1909	ASCEBC(trans_hdr->srcAppName, sizeof(trans_hdr->srcAppName));
1910	memcpy(tmpID, trans_hdr->srcUserID, 8);
1911	memcpy(tmpName, trans_hdr->srcAppName, 8);
1912	memcpy(trans_hdr->srcUserID, trans_hdr->destUserID, 8);
1913	memcpy(trans_hdr->srcAppName, trans_hdr->destAppName, 8);
1914	memcpy(trans_hdr->destUserID, tmpID, 8);
1915	memcpy(trans_hdr->destAppName, tmpName, 8);
1916	skb_push(skb, ETH_HLEN);
1917	memset(skb->data, 0, ETH_HLEN);
1918}
1919
1920/**
1921 * afiucv_hs_callback_syn - react on received SYN
1922 **/
1923static int afiucv_hs_callback_syn(struct sock *sk, struct sk_buff *skb)
1924{
1925	struct sock *nsk;
1926	struct iucv_sock *iucv, *niucv;
1927	struct af_iucv_trans_hdr *trans_hdr;
1928	int err;
1929
1930	iucv = iucv_sk(sk);
1931	trans_hdr = (struct af_iucv_trans_hdr *)skb->data;
1932	if (!iucv) {
1933		/* no sock - connection refused */
1934		afiucv_swap_src_dest(skb);
1935		trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
1936		err = dev_queue_xmit(skb);
1937		goto out;
1938	}
1939
1940	nsk = iucv_sock_alloc(NULL, sk->sk_type, GFP_ATOMIC);
1941	bh_lock_sock(sk);
1942	if ((sk->sk_state != IUCV_LISTEN) ||
1943	    sk_acceptq_is_full(sk) ||
1944	    !nsk) {
1945		/* error on server socket - connection refused */
1946		afiucv_swap_src_dest(skb);
1947		trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
1948		err = dev_queue_xmit(skb);
1949		iucv_sock_kill(nsk);
1950		bh_unlock_sock(sk);
1951		goto out;
1952	}
1953
1954	niucv = iucv_sk(nsk);
1955	iucv_sock_init(nsk, sk);
1956	niucv->transport = AF_IUCV_TRANS_HIPER;
1957	niucv->msglimit = iucv->msglimit;
1958	if (!trans_hdr->window)
1959		niucv->msglimit_peer = IUCV_HIPER_MSGLIM_DEFAULT;
1960	else
1961		niucv->msglimit_peer = trans_hdr->window;
1962	memcpy(niucv->dst_name, trans_hdr->srcAppName, 8);
1963	memcpy(niucv->dst_user_id, trans_hdr->srcUserID, 8);
1964	memcpy(niucv->src_name, iucv->src_name, 8);
1965	memcpy(niucv->src_user_id, iucv->src_user_id, 8);
1966	nsk->sk_bound_dev_if = sk->sk_bound_dev_if;
1967	niucv->hs_dev = iucv->hs_dev;
1968	dev_hold(niucv->hs_dev);
1969	afiucv_swap_src_dest(skb);
1970	trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_ACK;
1971	trans_hdr->window = niucv->msglimit;
1972	/* if receiver acks the xmit connection is established */
1973	err = dev_queue_xmit(skb);
1974	if (!err) {
1975		iucv_accept_enqueue(sk, nsk);
1976		nsk->sk_state = IUCV_CONNECTED;
1977		sk->sk_data_ready(sk);
1978	} else
1979		iucv_sock_kill(nsk);
1980	bh_unlock_sock(sk);
1981
1982out:
1983	return NET_RX_SUCCESS;
1984}
1985
1986/**
1987 * afiucv_hs_callback_synack() - react on received SYN-ACK
1988 **/
1989static int afiucv_hs_callback_synack(struct sock *sk, struct sk_buff *skb)
1990{
1991	struct iucv_sock *iucv = iucv_sk(sk);
1992	struct af_iucv_trans_hdr *trans_hdr =
1993					(struct af_iucv_trans_hdr *)skb->data;
1994
1995	if (!iucv)
1996		goto out;
1997	if (sk->sk_state != IUCV_BOUND)
1998		goto out;
1999	bh_lock_sock(sk);
2000	iucv->msglimit_peer = trans_hdr->window;
2001	sk->sk_state = IUCV_CONNECTED;
2002	sk->sk_state_change(sk);
2003	bh_unlock_sock(sk);
2004out:
2005	kfree_skb(skb);
2006	return NET_RX_SUCCESS;
2007}
2008
2009/**
2010 * afiucv_hs_callback_synfin() - react on received SYN_FIN
2011 **/
2012static int afiucv_hs_callback_synfin(struct sock *sk, struct sk_buff *skb)
2013{
2014	struct iucv_sock *iucv = iucv_sk(sk);
2015
2016	if (!iucv)
2017		goto out;
2018	if (sk->sk_state != IUCV_BOUND)
2019		goto out;
2020	bh_lock_sock(sk);
2021	sk->sk_state = IUCV_DISCONN;
2022	sk->sk_state_change(sk);
2023	bh_unlock_sock(sk);
2024out:
2025	kfree_skb(skb);
2026	return NET_RX_SUCCESS;
2027}
2028
2029/**
2030 * afiucv_hs_callback_fin() - react on received FIN
2031 **/
2032static int afiucv_hs_callback_fin(struct sock *sk, struct sk_buff *skb)
2033{
2034	struct iucv_sock *iucv = iucv_sk(sk);
2035
2036	/* other end of connection closed */
2037	if (!iucv)
2038		goto out;
2039	bh_lock_sock(sk);
2040	if (sk->sk_state == IUCV_CONNECTED) {
2041		sk->sk_state = IUCV_DISCONN;
2042		sk->sk_state_change(sk);
2043	}
2044	bh_unlock_sock(sk);
2045out:
2046	kfree_skb(skb);
2047	return NET_RX_SUCCESS;
2048}
2049
2050/**
2051 * afiucv_hs_callback_win() - react on received WIN
2052 **/
2053static int afiucv_hs_callback_win(struct sock *sk, struct sk_buff *skb)
2054{
2055	struct iucv_sock *iucv = iucv_sk(sk);
2056	struct af_iucv_trans_hdr *trans_hdr =
2057					(struct af_iucv_trans_hdr *)skb->data;
2058
2059	if (!iucv)
2060		return NET_RX_SUCCESS;
2061
2062	if (sk->sk_state != IUCV_CONNECTED)
2063		return NET_RX_SUCCESS;
2064
2065	atomic_sub(trans_hdr->window, &iucv->msg_sent);
2066	iucv_sock_wake_msglim(sk);
2067	return NET_RX_SUCCESS;
2068}
2069
2070/**
2071 * afiucv_hs_callback_rx() - react on received data
2072 **/
2073static int afiucv_hs_callback_rx(struct sock *sk, struct sk_buff *skb)
2074{
2075	struct iucv_sock *iucv = iucv_sk(sk);
2076
2077	if (!iucv) {
2078		kfree_skb(skb);
2079		return NET_RX_SUCCESS;
2080	}
2081
2082	if (sk->sk_state != IUCV_CONNECTED) {
2083		kfree_skb(skb);
2084		return NET_RX_SUCCESS;
2085	}
2086
2087	if (sk->sk_shutdown & RCV_SHUTDOWN) {
2088		kfree_skb(skb);
2089		return NET_RX_SUCCESS;
2090	}
2091
2092		/* write stuff from iucv_msg to skb cb */
2093	if (skb->len < sizeof(struct af_iucv_trans_hdr)) {
2094		kfree_skb(skb);
2095		return NET_RX_SUCCESS;
2096	}
2097	skb_pull(skb, sizeof(struct af_iucv_trans_hdr));
2098	skb_reset_transport_header(skb);
2099	skb_reset_network_header(skb);
2100	IUCV_SKB_CB(skb)->offset = 0;
2101	spin_lock(&iucv->message_q.lock);
2102	if (skb_queue_empty(&iucv->backlog_skb_q)) {
2103		if (sock_queue_rcv_skb(sk, skb)) {
2104			/* handle rcv queue full */
2105			skb_queue_tail(&iucv->backlog_skb_q, skb);
2106		}
2107	} else
2108		skb_queue_tail(&iucv_sk(sk)->backlog_skb_q, skb);
2109	spin_unlock(&iucv->message_q.lock);
2110	return NET_RX_SUCCESS;
2111}
2112
2113/**
2114 * afiucv_hs_rcv() - base function for arriving data through HiperSockets
2115 *                   transport
2116 *                   called from netif RX softirq
2117 **/
2118static int afiucv_hs_rcv(struct sk_buff *skb, struct net_device *dev,
2119	struct packet_type *pt, struct net_device *orig_dev)
2120{
2121	struct sock *sk;
2122	struct iucv_sock *iucv;
2123	struct af_iucv_trans_hdr *trans_hdr;
2124	char nullstring[8];
2125	int err = 0;
2126
2127	skb_pull(skb, ETH_HLEN);
2128	trans_hdr = (struct af_iucv_trans_hdr *)skb->data;
2129	EBCASC(trans_hdr->destAppName, sizeof(trans_hdr->destAppName));
2130	EBCASC(trans_hdr->destUserID, sizeof(trans_hdr->destUserID));
2131	EBCASC(trans_hdr->srcAppName, sizeof(trans_hdr->srcAppName));
2132	EBCASC(trans_hdr->srcUserID, sizeof(trans_hdr->srcUserID));
2133	memset(nullstring, 0, sizeof(nullstring));
2134	iucv = NULL;
2135	sk = NULL;
2136	read_lock(&iucv_sk_list.lock);
2137	sk_for_each(sk, &iucv_sk_list.head) {
2138		if (trans_hdr->flags == AF_IUCV_FLAG_SYN) {
2139			if ((!memcmp(&iucv_sk(sk)->src_name,
2140				     trans_hdr->destAppName, 8)) &&
2141			    (!memcmp(&iucv_sk(sk)->src_user_id,
2142				     trans_hdr->destUserID, 8)) &&
2143			    (!memcmp(&iucv_sk(sk)->dst_name, nullstring, 8)) &&
2144			    (!memcmp(&iucv_sk(sk)->dst_user_id,
2145				     nullstring, 8))) {
2146				iucv = iucv_sk(sk);
2147				break;
2148			}
2149		} else {
2150			if ((!memcmp(&iucv_sk(sk)->src_name,
2151				     trans_hdr->destAppName, 8)) &&
2152			    (!memcmp(&iucv_sk(sk)->src_user_id,
2153				     trans_hdr->destUserID, 8)) &&
2154			    (!memcmp(&iucv_sk(sk)->dst_name,
2155				     trans_hdr->srcAppName, 8)) &&
2156			    (!memcmp(&iucv_sk(sk)->dst_user_id,
2157				     trans_hdr->srcUserID, 8))) {
2158				iucv = iucv_sk(sk);
2159				break;
2160			}
2161		}
2162	}
2163	read_unlock(&iucv_sk_list.lock);
2164	if (!iucv)
2165		sk = NULL;
2166
2167	/* no sock
2168	how should we send with no sock
2169	1) send without sock no send rc checking?
2170	2) introduce default sock to handle this cases
2171
2172	 SYN -> send SYN|ACK in good case, send SYN|FIN in bad case
2173	 data -> send FIN
2174	 SYN|ACK, SYN|FIN, FIN -> no action? */
2175
2176	switch (trans_hdr->flags) {
2177	case AF_IUCV_FLAG_SYN:
2178		/* connect request */
2179		err = afiucv_hs_callback_syn(sk, skb);
2180		break;
2181	case (AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_ACK):
2182		/* connect request confirmed */
2183		err = afiucv_hs_callback_synack(sk, skb);
2184		break;
2185	case (AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN):
2186		/* connect request refused */
2187		err = afiucv_hs_callback_synfin(sk, skb);
2188		break;
2189	case (AF_IUCV_FLAG_FIN):
2190		/* close request */
2191		err = afiucv_hs_callback_fin(sk, skb);
2192		break;
2193	case (AF_IUCV_FLAG_WIN):
2194		err = afiucv_hs_callback_win(sk, skb);
2195		if (skb->len == sizeof(struct af_iucv_trans_hdr)) {
2196			kfree_skb(skb);
2197			break;
2198		}
2199		/* fall through and receive non-zero length data */
2200	case (AF_IUCV_FLAG_SHT):
2201		/* shutdown request */
2202		/* fall through and receive zero length data */
2203	case 0:
2204		/* plain data frame */
2205		IUCV_SKB_CB(skb)->class = trans_hdr->iucv_hdr.class;
2206		err = afiucv_hs_callback_rx(sk, skb);
2207		break;
2208	default:
2209		;
2210	}
2211
2212	return err;
2213}
2214
2215/**
2216 * afiucv_hs_callback_txnotify() - handle send notifcations from HiperSockets
2217 *                                 transport
2218 **/
2219static void afiucv_hs_callback_txnotify(struct sk_buff *skb,
2220					enum iucv_tx_notify n)
2221{
2222	struct sock *isk = skb->sk;
2223	struct sock *sk = NULL;
2224	struct iucv_sock *iucv = NULL;
2225	struct sk_buff_head *list;
2226	struct sk_buff *list_skb;
2227	struct sk_buff *nskb;
2228	unsigned long flags;
2229
2230	read_lock_irqsave(&iucv_sk_list.lock, flags);
2231	sk_for_each(sk, &iucv_sk_list.head)
2232		if (sk == isk) {
2233			iucv = iucv_sk(sk);
2234			break;
2235		}
2236	read_unlock_irqrestore(&iucv_sk_list.lock, flags);
2237
2238	if (!iucv || sock_flag(sk, SOCK_ZAPPED))
2239		return;
2240
2241	list = &iucv->send_skb_q;
2242	spin_lock_irqsave(&list->lock, flags);
2243	if (skb_queue_empty(list))
2244		goto out_unlock;
2245	list_skb = list->next;
2246	nskb = list_skb->next;
2247	while (list_skb != (struct sk_buff *)list) {
2248		if (skb_shinfo(list_skb) == skb_shinfo(skb)) {
2249			switch (n) {
2250			case TX_NOTIFY_OK:
2251				__skb_unlink(list_skb, list);
2252				kfree_skb(list_skb);
2253				iucv_sock_wake_msglim(sk);
2254				break;
2255			case TX_NOTIFY_PENDING:
2256				atomic_inc(&iucv->pendings);
2257				break;
2258			case TX_NOTIFY_DELAYED_OK:
2259				__skb_unlink(list_skb, list);
2260				atomic_dec(&iucv->pendings);
2261				if (atomic_read(&iucv->pendings) <= 0)
2262					iucv_sock_wake_msglim(sk);
2263				kfree_skb(list_skb);
2264				break;
2265			case TX_NOTIFY_UNREACHABLE:
2266			case TX_NOTIFY_DELAYED_UNREACHABLE:
2267			case TX_NOTIFY_TPQFULL: /* not yet used */
2268			case TX_NOTIFY_GENERALERROR:
2269			case TX_NOTIFY_DELAYED_GENERALERROR:
2270				__skb_unlink(list_skb, list);
2271				kfree_skb(list_skb);
2272				if (sk->sk_state == IUCV_CONNECTED) {
2273					sk->sk_state = IUCV_DISCONN;
2274					sk->sk_state_change(sk);
2275				}
2276				break;
2277			}
2278			break;
2279		}
2280		list_skb = nskb;
2281		nskb = nskb->next;
2282	}
2283out_unlock:
2284	spin_unlock_irqrestore(&list->lock, flags);
2285
2286	if (sk->sk_state == IUCV_CLOSING) {
2287		if (skb_queue_empty(&iucv_sk(sk)->send_skb_q)) {
2288			sk->sk_state = IUCV_CLOSED;
2289			sk->sk_state_change(sk);
2290		}
2291	}
2292
2293}
2294
2295/*
2296 * afiucv_netdev_event: handle netdev notifier chain events
2297 */
2298static int afiucv_netdev_event(struct notifier_block *this,
2299			       unsigned long event, void *ptr)
2300{
2301	struct net_device *event_dev = netdev_notifier_info_to_dev(ptr);
2302	struct sock *sk;
2303	struct iucv_sock *iucv;
2304
2305	switch (event) {
2306	case NETDEV_REBOOT:
2307	case NETDEV_GOING_DOWN:
2308		sk_for_each(sk, &iucv_sk_list.head) {
2309			iucv = iucv_sk(sk);
2310			if ((iucv->hs_dev == event_dev) &&
2311			    (sk->sk_state == IUCV_CONNECTED)) {
2312				if (event == NETDEV_GOING_DOWN)
2313					iucv_send_ctrl(sk, AF_IUCV_FLAG_FIN);
2314				sk->sk_state = IUCV_DISCONN;
2315				sk->sk_state_change(sk);
2316			}
2317		}
2318		break;
2319	case NETDEV_DOWN:
2320	case NETDEV_UNREGISTER:
2321	default:
2322		break;
2323	}
2324	return NOTIFY_DONE;
2325}
2326
2327static struct notifier_block afiucv_netdev_notifier = {
2328	.notifier_call = afiucv_netdev_event,
2329};
2330
2331static const struct proto_ops iucv_sock_ops = {
2332	.family		= PF_IUCV,
2333	.owner		= THIS_MODULE,
2334	.release	= iucv_sock_release,
2335	.bind		= iucv_sock_bind,
2336	.connect	= iucv_sock_connect,
2337	.listen		= iucv_sock_listen,
2338	.accept		= iucv_sock_accept,
2339	.getname	= iucv_sock_getname,
2340	.sendmsg	= iucv_sock_sendmsg,
2341	.recvmsg	= iucv_sock_recvmsg,
2342	.poll		= iucv_sock_poll,
2343	.ioctl		= sock_no_ioctl,
2344	.mmap		= sock_no_mmap,
2345	.socketpair	= sock_no_socketpair,
2346	.shutdown	= iucv_sock_shutdown,
2347	.setsockopt	= iucv_sock_setsockopt,
2348	.getsockopt	= iucv_sock_getsockopt,
2349};
2350
2351static const struct net_proto_family iucv_sock_family_ops = {
2352	.family	= AF_IUCV,
2353	.owner	= THIS_MODULE,
2354	.create	= iucv_sock_create,
2355};
2356
2357static struct packet_type iucv_packet_type = {
2358	.type = cpu_to_be16(ETH_P_AF_IUCV),
2359	.func = afiucv_hs_rcv,
2360};
2361
2362static int afiucv_iucv_init(void)
2363{
2364	int err;
2365
2366	err = pr_iucv->iucv_register(&af_iucv_handler, 0);
2367	if (err)
2368		goto out;
2369	/* establish dummy device */
2370	af_iucv_driver.bus = pr_iucv->bus;
2371	err = driver_register(&af_iucv_driver);
2372	if (err)
2373		goto out_iucv;
2374	af_iucv_dev = kzalloc(sizeof(struct device), GFP_KERNEL);
2375	if (!af_iucv_dev) {
2376		err = -ENOMEM;
2377		goto out_driver;
2378	}
2379	dev_set_name(af_iucv_dev, "af_iucv");
2380	af_iucv_dev->bus = pr_iucv->bus;
2381	af_iucv_dev->parent = pr_iucv->root;
2382	af_iucv_dev->release = (void (*)(struct device *))kfree;
2383	af_iucv_dev->driver = &af_iucv_driver;
2384	err = device_register(af_iucv_dev);
2385	if (err)
2386		goto out_driver;
2387	return 0;
2388
2389out_driver:
2390	driver_unregister(&af_iucv_driver);
2391out_iucv:
2392	pr_iucv->iucv_unregister(&af_iucv_handler, 0);
2393out:
2394	return err;
2395}
2396
2397static int __init afiucv_init(void)
2398{
2399	int err;
2400
2401	if (MACHINE_IS_VM) {
2402		cpcmd("QUERY USERID", iucv_userid, sizeof(iucv_userid), &err);
2403		if (unlikely(err)) {
2404			WARN_ON(err);
2405			err = -EPROTONOSUPPORT;
2406			goto out;
2407		}
2408
2409		pr_iucv = try_then_request_module(symbol_get(iucv_if), "iucv");
2410		if (!pr_iucv) {
2411			printk(KERN_WARNING "iucv_if lookup failed\n");
2412			memset(&iucv_userid, 0, sizeof(iucv_userid));
2413		}
2414	} else {
2415		memset(&iucv_userid, 0, sizeof(iucv_userid));
2416		pr_iucv = NULL;
2417	}
2418
2419	err = proto_register(&iucv_proto, 0);
2420	if (err)
2421		goto out;
2422	err = sock_register(&iucv_sock_family_ops);
2423	if (err)
2424		goto out_proto;
2425
2426	if (pr_iucv) {
2427		err = afiucv_iucv_init();
2428		if (err)
2429			goto out_sock;
2430	} else
2431		register_netdevice_notifier(&afiucv_netdev_notifier);
2432	dev_add_pack(&iucv_packet_type);
2433	return 0;
2434
2435out_sock:
2436	sock_unregister(PF_IUCV);
2437out_proto:
2438	proto_unregister(&iucv_proto);
2439out:
2440	if (pr_iucv)
2441		symbol_put(iucv_if);
2442	return err;
2443}
2444
2445static void __exit afiucv_exit(void)
2446{
2447	if (pr_iucv) {
2448		device_unregister(af_iucv_dev);
2449		driver_unregister(&af_iucv_driver);
2450		pr_iucv->iucv_unregister(&af_iucv_handler, 0);
2451		symbol_put(iucv_if);
2452	} else
2453		unregister_netdevice_notifier(&afiucv_netdev_notifier);
2454	dev_remove_pack(&iucv_packet_type);
2455	sock_unregister(PF_IUCV);
2456	proto_unregister(&iucv_proto);
2457}
2458
2459module_init(afiucv_init);
2460module_exit(afiucv_exit);
2461
2462MODULE_AUTHOR("Jennifer Hunt <jenhunt@us.ibm.com>");
2463MODULE_DESCRIPTION("IUCV Sockets ver " VERSION);
2464MODULE_VERSION(VERSION);
2465MODULE_LICENSE("GPL");
2466MODULE_ALIAS_NETPROTO(PF_IUCV);
2467
2468