1/*
2 *	Spanning tree protocol; BPDU handling
3 *	Linux ethernet bridge
4 *
5 *	Authors:
6 *	Lennert Buytenhek		<buytenh@gnu.org>
7 *
8 *	This program is free software; you can redistribute it and/or
9 *	modify it under the terms of the GNU General Public License
10 *	as published by the Free Software Foundation; either version
11 *	2 of the License, or (at your option) any later version.
12 */
13
14#include <linux/kernel.h>
15#include <linux/netfilter_bridge.h>
16#include <linux/etherdevice.h>
17#include <linux/llc.h>
18#include <linux/slab.h>
19#include <linux/pkt_sched.h>
20#include <net/net_namespace.h>
21#include <net/llc.h>
22#include <net/llc_pdu.h>
23#include <net/stp.h>
24#include <asm/unaligned.h>
25
26#include "br_private.h"
27#include "br_private_stp.h"
28
29#define STP_HZ		256
30
31#define LLC_RESERVE sizeof(struct llc_pdu_un)
32
33static void br_send_bpdu(struct net_bridge_port *p,
34			 const unsigned char *data, int length)
35{
36	struct sk_buff *skb;
37
38	skb = dev_alloc_skb(length+LLC_RESERVE);
39	if (!skb)
40		return;
41
42	skb->dev = p->dev;
43	skb->protocol = htons(ETH_P_802_2);
44	skb->priority = TC_PRIO_CONTROL;
45
46	skb_reserve(skb, LLC_RESERVE);
47	memcpy(__skb_put(skb, length), data, length);
48
49	llc_pdu_header_init(skb, LLC_PDU_TYPE_U, LLC_SAP_BSPAN,
50			    LLC_SAP_BSPAN, LLC_PDU_CMD);
51	llc_pdu_init_as_ui_cmd(skb);
52
53	llc_mac_hdr_init(skb, p->dev->dev_addr, p->br->group_addr);
54
55	skb_reset_mac_header(skb);
56
57	NF_HOOK(NFPROTO_BRIDGE, NF_BR_LOCAL_OUT, NULL, skb,
58		NULL, skb->dev,
59		dev_queue_xmit_sk);
60}
61
62static inline void br_set_ticks(unsigned char *dest, int j)
63{
64	unsigned long ticks = (STP_HZ * j)/ HZ;
65
66	put_unaligned_be16(ticks, dest);
67}
68
69static inline int br_get_ticks(const unsigned char *src)
70{
71	unsigned long ticks = get_unaligned_be16(src);
72
73	return DIV_ROUND_UP(ticks * HZ, STP_HZ);
74}
75
76/* called under bridge lock */
77void br_send_config_bpdu(struct net_bridge_port *p, struct br_config_bpdu *bpdu)
78{
79	unsigned char buf[35];
80
81	if (p->br->stp_enabled != BR_KERNEL_STP)
82		return;
83
84	buf[0] = 0;
85	buf[1] = 0;
86	buf[2] = 0;
87	buf[3] = BPDU_TYPE_CONFIG;
88	buf[4] = (bpdu->topology_change ? 0x01 : 0) |
89		(bpdu->topology_change_ack ? 0x80 : 0);
90	buf[5] = bpdu->root.prio[0];
91	buf[6] = bpdu->root.prio[1];
92	buf[7] = bpdu->root.addr[0];
93	buf[8] = bpdu->root.addr[1];
94	buf[9] = bpdu->root.addr[2];
95	buf[10] = bpdu->root.addr[3];
96	buf[11] = bpdu->root.addr[4];
97	buf[12] = bpdu->root.addr[5];
98	buf[13] = (bpdu->root_path_cost >> 24) & 0xFF;
99	buf[14] = (bpdu->root_path_cost >> 16) & 0xFF;
100	buf[15] = (bpdu->root_path_cost >> 8) & 0xFF;
101	buf[16] = bpdu->root_path_cost & 0xFF;
102	buf[17] = bpdu->bridge_id.prio[0];
103	buf[18] = bpdu->bridge_id.prio[1];
104	buf[19] = bpdu->bridge_id.addr[0];
105	buf[20] = bpdu->bridge_id.addr[1];
106	buf[21] = bpdu->bridge_id.addr[2];
107	buf[22] = bpdu->bridge_id.addr[3];
108	buf[23] = bpdu->bridge_id.addr[4];
109	buf[24] = bpdu->bridge_id.addr[5];
110	buf[25] = (bpdu->port_id >> 8) & 0xFF;
111	buf[26] = bpdu->port_id & 0xFF;
112
113	br_set_ticks(buf+27, bpdu->message_age);
114	br_set_ticks(buf+29, bpdu->max_age);
115	br_set_ticks(buf+31, bpdu->hello_time);
116	br_set_ticks(buf+33, bpdu->forward_delay);
117
118	br_send_bpdu(p, buf, 35);
119}
120
121/* called under bridge lock */
122void br_send_tcn_bpdu(struct net_bridge_port *p)
123{
124	unsigned char buf[4];
125
126	if (p->br->stp_enabled != BR_KERNEL_STP)
127		return;
128
129	buf[0] = 0;
130	buf[1] = 0;
131	buf[2] = 0;
132	buf[3] = BPDU_TYPE_TCN;
133	br_send_bpdu(p, buf, 4);
134}
135
136/*
137 * Called from llc.
138 *
139 * NO locks, but rcu_read_lock
140 */
141void br_stp_rcv(const struct stp_proto *proto, struct sk_buff *skb,
142		struct net_device *dev)
143{
144	const unsigned char *dest = eth_hdr(skb)->h_dest;
145	struct net_bridge_port *p;
146	struct net_bridge *br;
147	const unsigned char *buf;
148
149	if (!pskb_may_pull(skb, 4))
150		goto err;
151
152	/* compare of protocol id and version */
153	buf = skb->data;
154	if (buf[0] != 0 || buf[1] != 0 || buf[2] != 0)
155		goto err;
156
157	p = br_port_get_check_rcu(dev);
158	if (!p)
159		goto err;
160
161	br = p->br;
162	spin_lock(&br->lock);
163
164	if (br->stp_enabled != BR_KERNEL_STP)
165		goto out;
166
167	if (!(br->dev->flags & IFF_UP))
168		goto out;
169
170	if (p->state == BR_STATE_DISABLED)
171		goto out;
172
173	if (!ether_addr_equal(dest, br->group_addr))
174		goto out;
175
176	if (p->flags & BR_BPDU_GUARD) {
177		br_notice(br, "BPDU received on blocked port %u(%s)\n",
178			  (unsigned int) p->port_no, p->dev->name);
179		br_stp_disable_port(p);
180		goto out;
181	}
182
183	buf = skb_pull(skb, 3);
184
185	if (buf[0] == BPDU_TYPE_CONFIG) {
186		struct br_config_bpdu bpdu;
187
188		if (!pskb_may_pull(skb, 32))
189			goto out;
190
191		buf = skb->data;
192		bpdu.topology_change = (buf[1] & 0x01) ? 1 : 0;
193		bpdu.topology_change_ack = (buf[1] & 0x80) ? 1 : 0;
194
195		bpdu.root.prio[0] = buf[2];
196		bpdu.root.prio[1] = buf[3];
197		bpdu.root.addr[0] = buf[4];
198		bpdu.root.addr[1] = buf[5];
199		bpdu.root.addr[2] = buf[6];
200		bpdu.root.addr[3] = buf[7];
201		bpdu.root.addr[4] = buf[8];
202		bpdu.root.addr[5] = buf[9];
203		bpdu.root_path_cost =
204			(buf[10] << 24) |
205			(buf[11] << 16) |
206			(buf[12] << 8) |
207			buf[13];
208		bpdu.bridge_id.prio[0] = buf[14];
209		bpdu.bridge_id.prio[1] = buf[15];
210		bpdu.bridge_id.addr[0] = buf[16];
211		bpdu.bridge_id.addr[1] = buf[17];
212		bpdu.bridge_id.addr[2] = buf[18];
213		bpdu.bridge_id.addr[3] = buf[19];
214		bpdu.bridge_id.addr[4] = buf[20];
215		bpdu.bridge_id.addr[5] = buf[21];
216		bpdu.port_id = (buf[22] << 8) | buf[23];
217
218		bpdu.message_age = br_get_ticks(buf+24);
219		bpdu.max_age = br_get_ticks(buf+26);
220		bpdu.hello_time = br_get_ticks(buf+28);
221		bpdu.forward_delay = br_get_ticks(buf+30);
222
223		if (bpdu.message_age > bpdu.max_age) {
224			if (net_ratelimit())
225				br_notice(p->br,
226					  "port %u config from %pM"
227					  " (message_age %ul > max_age %ul)\n",
228					  p->port_no,
229					  eth_hdr(skb)->h_source,
230					  bpdu.message_age, bpdu.max_age);
231			goto out;
232		}
233
234		br_received_config_bpdu(p, &bpdu);
235	} else if (buf[0] == BPDU_TYPE_TCN) {
236		br_received_tcn_bpdu(p);
237	}
238 out:
239	spin_unlock(&br->lock);
240 err:
241	kfree_skb(skb);
242}
243