]> bbs.cooldavid.org Git - net-next-2.6.git/blame - net/bridge/br_stp_bpdu.c
bridge: fix RCU races with bridge port
[net-next-2.6.git] / net / bridge / br_stp_bpdu.c
CommitLineData
1da177e4
LT
1/*
2 * Spanning tree protocol; BPDU handling
3 * Linux ethernet bridge
4 *
5 * Authors:
6 * Lennert Buytenhek <buytenh@gnu.org>
7 *
1da177e4
LT
8 * This program is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU General Public License
10 * as published by the Free Software Foundation; either version
11 * 2 of the License, or (at your option) any later version.
12 */
13
14#include <linux/kernel.h>
15#include <linux/netfilter_bridge.h>
cf0f02d0
SH
16#include <linux/etherdevice.h>
17#include <linux/llc.h>
5a0e3ad6 18#include <linux/slab.h>
e730c155 19#include <net/net_namespace.h>
12ac84c4 20#include <net/llc.h>
cf0f02d0 21#include <net/llc_pdu.h>
7c85fbf0 22#include <net/stp.h>
4dc6d9cc 23#include <asm/unaligned.h>
1da177e4
LT
24
25#include "br_private.h"
26#include "br_private_stp.h"
27
18fdb2b2 28#define STP_HZ 256
1da177e4 29
12ac84c4
SH
30#define LLC_RESERVE sizeof(struct llc_pdu_un)
31
32static void br_send_bpdu(struct net_bridge_port *p,
9d6f229f 33 const unsigned char *data, int length)
1da177e4 34{
1da177e4 35 struct sk_buff *skb;
1da177e4 36
12ac84c4
SH
37 skb = dev_alloc_skb(length+LLC_RESERVE);
38 if (!skb)
1da177e4 39 return;
1da177e4 40
12ac84c4 41 skb->dev = p->dev;
1da177e4 42 skb->protocol = htons(ETH_P_802_2);
12ac84c4
SH
43
44 skb_reserve(skb, LLC_RESERVE);
45 memcpy(__skb_put(skb, length), data, length);
46
47 llc_pdu_header_init(skb, LLC_PDU_TYPE_U, LLC_SAP_BSPAN,
48 LLC_SAP_BSPAN, LLC_PDU_CMD);
49 llc_pdu_init_as_ui_cmd(skb);
50
51 llc_mac_hdr_init(skb, p->dev->dev_addr, p->br->group_addr);
1da177e4 52
713aefa3 53 NF_HOOK(NFPROTO_BRIDGE, NF_BR_LOCAL_OUT, skb, NULL, skb->dev,
1da177e4
LT
54 dev_queue_xmit);
55}
56
18fdb2b2 57static inline void br_set_ticks(unsigned char *dest, int j)
1da177e4 58{
18fdb2b2 59 unsigned long ticks = (STP_HZ * j)/ HZ;
1da177e4 60
d3e2ce3b 61 put_unaligned_be16(ticks, dest);
1da177e4
LT
62}
63
18fdb2b2 64static inline int br_get_ticks(const unsigned char *src)
1da177e4 65{
d3e2ce3b 66 unsigned long ticks = get_unaligned_be16(src);
18fdb2b2 67
172589cc 68 return DIV_ROUND_UP(ticks * HZ, STP_HZ);
1da177e4
LT
69}
70
71/* called under bridge lock */
72void br_send_config_bpdu(struct net_bridge_port *p, struct br_config_bpdu *bpdu)
73{
12ac84c4
SH
74 unsigned char buf[35];
75
9cde0708
SH
76 if (p->br->stp_enabled != BR_KERNEL_STP)
77 return;
78
12ac84c4
SH
79 buf[0] = 0;
80 buf[1] = 0;
81 buf[2] = 0;
82 buf[3] = BPDU_TYPE_CONFIG;
83 buf[4] = (bpdu->topology_change ? 0x01 : 0) |
1da177e4 84 (bpdu->topology_change_ack ? 0x80 : 0);
12ac84c4
SH
85 buf[5] = bpdu->root.prio[0];
86 buf[6] = bpdu->root.prio[1];
87 buf[7] = bpdu->root.addr[0];
88 buf[8] = bpdu->root.addr[1];
89 buf[9] = bpdu->root.addr[2];
90 buf[10] = bpdu->root.addr[3];
91 buf[11] = bpdu->root.addr[4];
92 buf[12] = bpdu->root.addr[5];
93 buf[13] = (bpdu->root_path_cost >> 24) & 0xFF;
94 buf[14] = (bpdu->root_path_cost >> 16) & 0xFF;
95 buf[15] = (bpdu->root_path_cost >> 8) & 0xFF;
96 buf[16] = bpdu->root_path_cost & 0xFF;
97 buf[17] = bpdu->bridge_id.prio[0];
98 buf[18] = bpdu->bridge_id.prio[1];
99 buf[19] = bpdu->bridge_id.addr[0];
100 buf[20] = bpdu->bridge_id.addr[1];
101 buf[21] = bpdu->bridge_id.addr[2];
102 buf[22] = bpdu->bridge_id.addr[3];
103 buf[23] = bpdu->bridge_id.addr[4];
104 buf[24] = bpdu->bridge_id.addr[5];
105 buf[25] = (bpdu->port_id >> 8) & 0xFF;
106 buf[26] = bpdu->port_id & 0xFF;
107
108 br_set_ticks(buf+27, bpdu->message_age);
109 br_set_ticks(buf+29, bpdu->max_age);
110 br_set_ticks(buf+31, bpdu->hello_time);
111 br_set_ticks(buf+33, bpdu->forward_delay);
112
113 br_send_bpdu(p, buf, 35);
1da177e4
LT
114}
115
116/* called under bridge lock */
117void br_send_tcn_bpdu(struct net_bridge_port *p)
118{
12ac84c4
SH
119 unsigned char buf[4];
120
9cde0708
SH
121 if (p->br->stp_enabled != BR_KERNEL_STP)
122 return;
123
12ac84c4
SH
124 buf[0] = 0;
125 buf[1] = 0;
126 buf[2] = 0;
127 buf[3] = BPDU_TYPE_TCN;
485c2967 128 br_send_bpdu(p, buf, 4);
1da177e4
LT
129}
130
cf0f02d0
SH
131/*
132 * Called from llc.
133 *
eeaf61d8 134 * NO locks, but rcu_read_lock
cf0f02d0 135 */
7c85fbf0
PM
136void br_stp_rcv(const struct stp_proto *proto, struct sk_buff *skb,
137 struct net_device *dev)
1da177e4 138{
cf0f02d0 139 const unsigned char *dest = eth_hdr(skb)->h_dest;
f350a0a8 140 struct net_bridge_port *p;
b3f1be4b 141 struct net_bridge *br;
cf0f02d0 142 const unsigned char *buf;
1da177e4 143
cf0f02d0
SH
144 if (!pskb_may_pull(skb, 4))
145 goto err;
146
147 /* compare of protocol id and version */
148 buf = skb->data;
149 if (buf[0] != 0 || buf[1] != 0 || buf[2] != 0)
150 goto err;
b3f1be4b 151
b5ed54e9 152 p = br_port_get_rcu(dev);
153 if (!p)
154 goto err;
155
cf0f02d0
SH
156 br = p->br;
157 spin_lock(&br->lock);
b3f1be4b 158
9cde0708
SH
159 if (br->stp_enabled != BR_KERNEL_STP)
160 goto out;
161
162 if (!(br->dev->flags & IFF_UP))
163 goto out;
164
165 if (p->state == BR_STATE_DISABLED)
b3f1be4b 166 goto out;
85967bb4 167
fda93d92 168 if (compare_ether_addr(dest, br->group_addr) != 0)
b3f1be4b 169 goto out;
1da177e4 170
cf0f02d0 171 buf = skb_pull(skb, 3);
1da177e4 172
1da177e4
LT
173 if (buf[0] == BPDU_TYPE_CONFIG) {
174 struct br_config_bpdu bpdu;
175
176 if (!pskb_may_pull(skb, 32))
cf0f02d0 177 goto out;
1da177e4
LT
178
179 buf = skb->data;
180 bpdu.topology_change = (buf[1] & 0x01) ? 1 : 0;
181 bpdu.topology_change_ack = (buf[1] & 0x80) ? 1 : 0;
182
183 bpdu.root.prio[0] = buf[2];
184 bpdu.root.prio[1] = buf[3];
185 bpdu.root.addr[0] = buf[4];
186 bpdu.root.addr[1] = buf[5];
187 bpdu.root.addr[2] = buf[6];
188 bpdu.root.addr[3] = buf[7];
189 bpdu.root.addr[4] = buf[8];
190 bpdu.root.addr[5] = buf[9];
191 bpdu.root_path_cost =
192 (buf[10] << 24) |
193 (buf[11] << 16) |
194 (buf[12] << 8) |
195 buf[13];
196 bpdu.bridge_id.prio[0] = buf[14];
197 bpdu.bridge_id.prio[1] = buf[15];
198 bpdu.bridge_id.addr[0] = buf[16];
199 bpdu.bridge_id.addr[1] = buf[17];
200 bpdu.bridge_id.addr[2] = buf[18];
201 bpdu.bridge_id.addr[3] = buf[19];
202 bpdu.bridge_id.addr[4] = buf[20];
203 bpdu.bridge_id.addr[5] = buf[21];
204 bpdu.port_id = (buf[22] << 8) | buf[23];
205
206 bpdu.message_age = br_get_ticks(buf+24);
207 bpdu.max_age = br_get_ticks(buf+26);
208 bpdu.hello_time = br_get_ticks(buf+28);
209 bpdu.forward_delay = br_get_ticks(buf+30);
210
211 br_received_config_bpdu(p, &bpdu);
212 }
213
214 else if (buf[0] == BPDU_TYPE_TCN) {
215 br_received_tcn_bpdu(p);
216 }
217 out:
b3f1be4b 218 spin_unlock(&br->lock);
1da177e4
LT
219 err:
220 kfree_skb(skb);
1da177e4 221}