1/*
2 *  IUCV protocol stack for Linux on zSeries
3 *
4 *  Copyright IBM Corp. 2006, 2009
5 *
6 *  Author(s):	Jennifer Hunt <jenhunt@us.ibm.com>
7 *		Hendrik Brueckner <brueckner@linux.vnet.ibm.com>
8 *  PM functions:
9 *		Ursula Braun <ursula.braun@de.ibm.com>
10 */
11
12#define KMSG_COMPONENT "af_iucv"
13#define pr_fmt(fmt) KMSG_COMPONENT ": " fmt
14
15#include <linux/module.h>
16#include <linux/types.h>
17#include <linux/list.h>
18#include <linux/errno.h>
19#include <linux/kernel.h>
20#include <linux/sched.h>
21#include <linux/slab.h>
22#include <linux/skbuff.h>
23#include <linux/init.h>
24#include <linux/poll.h>
25#include <net/sock.h>
26#include <asm/ebcdic.h>
27#include <asm/cpcmd.h>
28#include <linux/kmod.h>
29
30#include <net/iucv/af_iucv.h>
31
32#define VERSION "1.2"
33
34static char iucv_userid[80];
35
36static const struct proto_ops iucv_sock_ops;
37
38static struct proto iucv_proto = {
39	.name		= "AF_IUCV",
40	.owner		= THIS_MODULE,
41	.obj_size	= sizeof(struct iucv_sock),
42};
43
44static struct iucv_interface *pr_iucv;
45
46/* special AF_IUCV IPRM messages */
47static const u8 iprm_shutdown[8] =
48	{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01};
49
50#define TRGCLS_SIZE	(sizeof(((struct iucv_message *)0)->class))
51
52#define __iucv_sock_wait(sk, condition, timeo, ret)			\
53do {									\
54	DEFINE_WAIT(__wait);						\
55	long __timeo = timeo;						\
56	ret = 0;							\
57	prepare_to_wait(sk_sleep(sk), &__wait, TASK_INTERRUPTIBLE);	\
58	while (!(condition)) {						\
59		if (!__timeo) {						\
60			ret = -EAGAIN;					\
61			break;						\
62		}							\
63		if (signal_pending(current)) {				\
64			ret = sock_intr_errno(__timeo);			\
65			break;						\
66		}							\
67		release_sock(sk);					\
68		__timeo = schedule_timeout(__timeo);			\
69		lock_sock(sk);						\
70		ret = sock_error(sk);					\
71		if (ret)						\
72			break;						\
73	}								\
74	finish_wait(sk_sleep(sk), &__wait);				\
75} while (0)
76
77#define iucv_sock_wait(sk, condition, timeo)				\
78({									\
79	int __ret = 0;							\
80	if (!(condition))						\
81		__iucv_sock_wait(sk, condition, timeo, __ret);		\
82	__ret;								\
83})
84
85static void iucv_sock_kill(struct sock *sk);
86static void iucv_sock_close(struct sock *sk);
87static void iucv_sever_path(struct sock *, int);
88
89static int afiucv_hs_rcv(struct sk_buff *skb, struct net_device *dev,
90	struct packet_type *pt, struct net_device *orig_dev);
91static int afiucv_hs_send(struct iucv_message *imsg, struct sock *sock,
92		   struct sk_buff *skb, u8 flags);
93static void afiucv_hs_callback_txnotify(struct sk_buff *, enum iucv_tx_notify);
94
95/* Call Back functions */
96static void iucv_callback_rx(struct iucv_path *, struct iucv_message *);
97static void iucv_callback_txdone(struct iucv_path *, struct iucv_message *);
98static void iucv_callback_connack(struct iucv_path *, u8 ipuser[16]);
99static int iucv_callback_connreq(struct iucv_path *, u8 ipvmid[8],
100				 u8 ipuser[16]);
101static void iucv_callback_connrej(struct iucv_path *, u8 ipuser[16]);
102static void iucv_callback_shutdown(struct iucv_path *, u8 ipuser[16]);
103
104static struct iucv_sock_list iucv_sk_list = {
105	.lock = __RW_LOCK_UNLOCKED(iucv_sk_list.lock),
106	.autobind_name = ATOMIC_INIT(0)
107};
108
109static struct iucv_handler af_iucv_handler = {
110	.path_pending	  = iucv_callback_connreq,
111	.path_complete	  = iucv_callback_connack,
112	.path_severed	  = iucv_callback_connrej,
113	.message_pending  = iucv_callback_rx,
114	.message_complete = iucv_callback_txdone,
115	.path_quiesced	  = iucv_callback_shutdown,
116};
117
118static inline void high_nmcpy(unsigned char *dst, char *src)
119{
120       memcpy(dst, src, 8);
121}
122
123static inline void low_nmcpy(unsigned char *dst, char *src)
124{
125       memcpy(&dst[8], src, 8);
126}
127
128static int afiucv_pm_prepare(struct device *dev)
129{
130#ifdef CONFIG_PM_DEBUG
131	printk(KERN_WARNING "afiucv_pm_prepare\n");
132#endif
133	return 0;
134}
135
136static void afiucv_pm_complete(struct device *dev)
137{
138#ifdef CONFIG_PM_DEBUG
139	printk(KERN_WARNING "afiucv_pm_complete\n");
140#endif
141}
142
143/**
144 * afiucv_pm_freeze() - Freeze PM callback
145 * @dev:	AFIUCV dummy device
146 *
147 * Sever all established IUCV communication pathes
148 */
149static int afiucv_pm_freeze(struct device *dev)
150{
151	struct iucv_sock *iucv;
152	struct sock *sk;
153	int err = 0;
154
155#ifdef CONFIG_PM_DEBUG
156	printk(KERN_WARNING "afiucv_pm_freeze\n");
157#endif
158	read_lock(&iucv_sk_list.lock);
159	sk_for_each(sk, &iucv_sk_list.head) {
160		iucv = iucv_sk(sk);
161		switch (sk->sk_state) {
162		case IUCV_DISCONN:
163		case IUCV_CLOSING:
164		case IUCV_CONNECTED:
165			iucv_sever_path(sk, 0);
166			break;
167		case IUCV_OPEN:
168		case IUCV_BOUND:
169		case IUCV_LISTEN:
170		case IUCV_CLOSED:
171		default:
172			break;
173		}
174		skb_queue_purge(&iucv->send_skb_q);
175		skb_queue_purge(&iucv->backlog_skb_q);
176	}
177	read_unlock(&iucv_sk_list.lock);
178	return err;
179}
180
181/**
182 * afiucv_pm_restore_thaw() - Thaw and restore PM callback
183 * @dev:	AFIUCV dummy device
184 *
185 * socket clean up after freeze
186 */
187static int afiucv_pm_restore_thaw(struct device *dev)
188{
189	struct sock *sk;
190
191#ifdef CONFIG_PM_DEBUG
192	printk(KERN_WARNING "afiucv_pm_restore_thaw\n");
193#endif
194	read_lock(&iucv_sk_list.lock);
195	sk_for_each(sk, &iucv_sk_list.head) {
196		switch (sk->sk_state) {
197		case IUCV_CONNECTED:
198			sk->sk_err = EPIPE;
199			sk->sk_state = IUCV_DISCONN;
200			sk->sk_state_change(sk);
201			break;
202		case IUCV_DISCONN:
203		case IUCV_CLOSING:
204		case IUCV_LISTEN:
205		case IUCV_BOUND:
206		case IUCV_OPEN:
207		default:
208			break;
209		}
210	}
211	read_unlock(&iucv_sk_list.lock);
212	return 0;
213}
214
215static const struct dev_pm_ops afiucv_pm_ops = {
216	.prepare = afiucv_pm_prepare,
217	.complete = afiucv_pm_complete,
218	.freeze = afiucv_pm_freeze,
219	.thaw = afiucv_pm_restore_thaw,
220	.restore = afiucv_pm_restore_thaw,
221};
222
223static struct device_driver af_iucv_driver = {
224	.owner = THIS_MODULE,
225	.name = "afiucv",
226	.bus  = NULL,
227	.pm   = &afiucv_pm_ops,
228};
229
230/* dummy device used as trigger for PM functions */
231static struct device *af_iucv_dev;
232
233/**
234 * iucv_msg_length() - Returns the length of an iucv message.
235 * @msg:	Pointer to struct iucv_message, MUST NOT be NULL
236 *
237 * The function returns the length of the specified iucv message @msg of data
238 * stored in a buffer and of data stored in the parameter list (PRMDATA).
239 *
240 * For IUCV_IPRMDATA, AF_IUCV uses the following convention to transport socket
241 * data:
242 *	PRMDATA[0..6]	socket data (max 7 bytes);
243 *	PRMDATA[7]	socket data length value (len is 0xff - PRMDATA[7])
244 *
245 * The socket data length is computed by subtracting the socket data length
246 * value from 0xFF.
247 * If the socket data len is greater 7, then PRMDATA can be used for special
248 * notifications (see iucv_sock_shutdown); and further,
249 * if the socket data len is > 7, the function returns 8.
250 *
251 * Use this function to allocate socket buffers to store iucv message data.
252 */
253static inline size_t iucv_msg_length(struct iucv_message *msg)
254{
255	size_t datalen;
256
257	if (msg->flags & IUCV_IPRMDATA) {
258		datalen = 0xff - msg->rmmsg[7];
259		return (datalen < 8) ? datalen : 8;
260	}
261	return msg->length;
262}
263
264/**
265 * iucv_sock_in_state() - check for specific states
266 * @sk:		sock structure
267 * @state:	first iucv sk state
268 * @state:	second iucv sk state
269 *
270 * Returns true if the socket in either in the first or second state.
271 */
272static int iucv_sock_in_state(struct sock *sk, int state, int state2)
273{
274	return (sk->sk_state == state || sk->sk_state == state2);
275}
276
277/**
278 * iucv_below_msglim() - function to check if messages can be sent
279 * @sk:		sock structure
280 *
281 * Returns true if the send queue length is lower than the message limit.
282 * Always returns true if the socket is not connected (no iucv path for
283 * checking the message limit).
284 */
285static inline int iucv_below_msglim(struct sock *sk)
286{
287	struct iucv_sock *iucv = iucv_sk(sk);
288
289	if (sk->sk_state != IUCV_CONNECTED)
290		return 1;
291	if (iucv->transport == AF_IUCV_TRANS_IUCV)
292		return (skb_queue_len(&iucv->send_skb_q) < iucv->path->msglim);
293	else
294		return ((atomic_read(&iucv->msg_sent) < iucv->msglimit_peer) &&
295			(atomic_read(&iucv->pendings) <= 0));
296}
297
298/**
299 * iucv_sock_wake_msglim() - Wake up thread waiting on msg limit
300 */
301static void iucv_sock_wake_msglim(struct sock *sk)
302{
303	struct socket_wq *wq;
304
305	rcu_read_lock();
306	wq = rcu_dereference(sk->sk_wq);
307	if (wq_has_sleeper(wq))
308		wake_up_interruptible_all(&wq->wait);
309	sk_wake_async(sk, SOCK_WAKE_SPACE, POLL_OUT);
310	rcu_read_unlock();
311}
312
313/**
314 * afiucv_hs_send() - send a message through HiperSockets transport
315 */
316static int afiucv_hs_send(struct iucv_message *imsg, struct sock *sock,
317		   struct sk_buff *skb, u8 flags)
318{
319	struct iucv_sock *iucv = iucv_sk(sock);
320	struct af_iucv_trans_hdr *phs_hdr;
321	struct sk_buff *nskb;
322	int err, confirm_recv = 0;
323
324	memset(skb->head, 0, ETH_HLEN);
325	phs_hdr = (struct af_iucv_trans_hdr *)skb_push(skb,
326					sizeof(struct af_iucv_trans_hdr));
327	skb_reset_mac_header(skb);
328	skb_reset_network_header(skb);
329	skb_push(skb, ETH_HLEN);
330	skb_reset_mac_header(skb);
331	memset(phs_hdr, 0, sizeof(struct af_iucv_trans_hdr));
332
333	phs_hdr->magic = ETH_P_AF_IUCV;
334	phs_hdr->version = 1;
335	phs_hdr->flags = flags;
336	if (flags == AF_IUCV_FLAG_SYN)
337		phs_hdr->window = iucv->msglimit;
338	else if ((flags == AF_IUCV_FLAG_WIN) || !flags) {
339		confirm_recv = atomic_read(&iucv->msg_recv);
340		phs_hdr->window = confirm_recv;
341		if (confirm_recv)
342			phs_hdr->flags = phs_hdr->flags | AF_IUCV_FLAG_WIN;
343	}
344	memcpy(phs_hdr->destUserID, iucv->dst_user_id, 8);
345	memcpy(phs_hdr->destAppName, iucv->dst_name, 8);
346	memcpy(phs_hdr->srcUserID, iucv->src_user_id, 8);
347	memcpy(phs_hdr->srcAppName, iucv->src_name, 8);
348	ASCEBC(phs_hdr->destUserID, sizeof(phs_hdr->destUserID));
349	ASCEBC(phs_hdr->destAppName, sizeof(phs_hdr->destAppName));
350	ASCEBC(phs_hdr->srcUserID, sizeof(phs_hdr->srcUserID));
351	ASCEBC(phs_hdr->srcAppName, sizeof(phs_hdr->srcAppName));
352	if (imsg)
353		memcpy(&phs_hdr->iucv_hdr, imsg, sizeof(struct iucv_message));
354
355	skb->dev = iucv->hs_dev;
356	if (!skb->dev)
357		return -ENODEV;
358	if (!(skb->dev->flags & IFF_UP) || !netif_carrier_ok(skb->dev))
359		return -ENETDOWN;
360	if (skb->len > skb->dev->mtu) {
361		if (sock->sk_type == SOCK_SEQPACKET)
362			return -EMSGSIZE;
363		else
364			skb_trim(skb, skb->dev->mtu);
365	}
366	skb->protocol = ETH_P_AF_IUCV;
367	nskb = skb_clone(skb, GFP_ATOMIC);
368	if (!nskb)
369		return -ENOMEM;
370	skb_queue_tail(&iucv->send_skb_q, nskb);
371	err = dev_queue_xmit(skb);
372	if (net_xmit_eval(err)) {
373		skb_unlink(nskb, &iucv->send_skb_q);
374		kfree_skb(nskb);
375	} else {
376		atomic_sub(confirm_recv, &iucv->msg_recv);
377		WARN_ON(atomic_read(&iucv->msg_recv) < 0);
378	}
379	return net_xmit_eval(err);
380}
381
382static struct sock *__iucv_get_sock_by_name(char *nm)
383{
384	struct sock *sk;
385
386	sk_for_each(sk, &iucv_sk_list.head)
387		if (!memcmp(&iucv_sk(sk)->src_name, nm, 8))
388			return sk;
389
390	return NULL;
391}
392
393static void iucv_sock_destruct(struct sock *sk)
394{
395	skb_queue_purge(&sk->sk_receive_queue);
396	skb_queue_purge(&sk->sk_error_queue);
397
398	sk_mem_reclaim(sk);
399
400	if (!sock_flag(sk, SOCK_DEAD)) {
401		pr_err("Attempt to release alive iucv socket %p\n", sk);
402		return;
403	}
404
405	WARN_ON(atomic_read(&sk->sk_rmem_alloc));
406	WARN_ON(atomic_read(&sk->sk_wmem_alloc));
407	WARN_ON(sk->sk_wmem_queued);
408	WARN_ON(sk->sk_forward_alloc);
409}
410
411/* Cleanup Listen */
412static void iucv_sock_cleanup_listen(struct sock *parent)
413{
414	struct sock *sk;
415
416	/* Close non-accepted connections */
417	while ((sk = iucv_accept_dequeue(parent, NULL))) {
418		iucv_sock_close(sk);
419		iucv_sock_kill(sk);
420	}
421
422	parent->sk_state = IUCV_CLOSED;
423}
424
425/* Kill socket (only if zapped and orphaned) */
426static void iucv_sock_kill(struct sock *sk)
427{
428	if (!sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket)
429		return;
430
431	iucv_sock_unlink(&iucv_sk_list, sk);
432	sock_set_flag(sk, SOCK_DEAD);
433	sock_put(sk);
434}
435
436/* Terminate an IUCV path */
437static void iucv_sever_path(struct sock *sk, int with_user_data)
438{
439	unsigned char user_data[16];
440	struct iucv_sock *iucv = iucv_sk(sk);
441	struct iucv_path *path = iucv->path;
442
443	if (iucv->path) {
444		iucv->path = NULL;
445		if (with_user_data) {
446			low_nmcpy(user_data, iucv->src_name);
447			high_nmcpy(user_data, iucv->dst_name);
448			ASCEBC(user_data, sizeof(user_data));
449			pr_iucv->path_sever(path, user_data);
450		} else
451			pr_iucv->path_sever(path, NULL);
452		iucv_path_free(path);
453	}
454}
455
456/* Send FIN through an IUCV socket for HIPER transport */
457static int iucv_send_ctrl(struct sock *sk, u8 flags)
458{
459	int err = 0;
460	int blen;
461	struct sk_buff *skb;
462
463	blen = sizeof(struct af_iucv_trans_hdr) + ETH_HLEN;
464	skb = sock_alloc_send_skb(sk, blen, 1, &err);
465	if (skb) {
466		skb_reserve(skb, blen);
467		err = afiucv_hs_send(NULL, sk, skb, flags);
468	}
469	return err;
470}
471
472/* Close an IUCV socket */
473static void iucv_sock_close(struct sock *sk)
474{
475	struct iucv_sock *iucv = iucv_sk(sk);
476	unsigned long timeo;
477	int err = 0;
478
479	lock_sock(sk);
480
481	switch (sk->sk_state) {
482	case IUCV_LISTEN:
483		iucv_sock_cleanup_listen(sk);
484		break;
485
486	case IUCV_CONNECTED:
487		if (iucv->transport == AF_IUCV_TRANS_HIPER) {
488			err = iucv_send_ctrl(sk, AF_IUCV_FLAG_FIN);
489			sk->sk_state = IUCV_DISCONN;
490			sk->sk_state_change(sk);
491		}
492	case IUCV_DISCONN:   /* fall through */
493		sk->sk_state = IUCV_CLOSING;
494		sk->sk_state_change(sk);
495
496		if (!err && !skb_queue_empty(&iucv->send_skb_q)) {
497			if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime)
498				timeo = sk->sk_lingertime;
499			else
500				timeo = IUCV_DISCONN_TIMEOUT;
501			iucv_sock_wait(sk,
502					iucv_sock_in_state(sk, IUCV_CLOSED, 0),
503					timeo);
504		}
505
506	case IUCV_CLOSING:   /* fall through */
507		sk->sk_state = IUCV_CLOSED;
508		sk->sk_state_change(sk);
509
510		sk->sk_err = ECONNRESET;
511		sk->sk_state_change(sk);
512
513		skb_queue_purge(&iucv->send_skb_q);
514		skb_queue_purge(&iucv->backlog_skb_q);
515
516	default:   /* fall through */
517		iucv_sever_path(sk, 1);
518	}
519
520	if (iucv->hs_dev) {
521		dev_put(iucv->hs_dev);
522		iucv->hs_dev = NULL;
523		sk->sk_bound_dev_if = 0;
524	}
525
526	/* mark socket for deletion by iucv_sock_kill() */
527	sock_set_flag(sk, SOCK_ZAPPED);
528
529	release_sock(sk);
530}
531
532static void iucv_sock_init(struct sock *sk, struct sock *parent)
533{
534	if (parent)
535		sk->sk_type = parent->sk_type;
536}
537
538static struct sock *iucv_sock_alloc(struct socket *sock, int proto, gfp_t prio)
539{
540	struct sock *sk;
541	struct iucv_sock *iucv;
542
543	sk = sk_alloc(&init_net, PF_IUCV, prio, &iucv_proto);
544	if (!sk)
545		return NULL;
546	iucv = iucv_sk(sk);
547
548	sock_init_data(sock, sk);
549	INIT_LIST_HEAD(&iucv->accept_q);
550	spin_lock_init(&iucv->accept_q_lock);
551	skb_queue_head_init(&iucv->send_skb_q);
552	INIT_LIST_HEAD(&iucv->message_q.list);
553	spin_lock_init(&iucv->message_q.lock);
554	skb_queue_head_init(&iucv->backlog_skb_q);
555	iucv->send_tag = 0;
556	atomic_set(&iucv->pendings, 0);
557	iucv->flags = 0;
558	iucv->msglimit = 0;
559	atomic_set(&iucv->msg_sent, 0);
560	atomic_set(&iucv->msg_recv, 0);
561	iucv->path = NULL;
562	iucv->sk_txnotify = afiucv_hs_callback_txnotify;
563	memset(&iucv->src_user_id , 0, 32);
564	if (pr_iucv)
565		iucv->transport = AF_IUCV_TRANS_IUCV;
566	else
567		iucv->transport = AF_IUCV_TRANS_HIPER;
568
569	sk->sk_destruct = iucv_sock_destruct;
570	sk->sk_sndtimeo = IUCV_CONN_TIMEOUT;
571	sk->sk_allocation = GFP_DMA;
572
573	sock_reset_flag(sk, SOCK_ZAPPED);
574
575	sk->sk_protocol = proto;
576	sk->sk_state	= IUCV_OPEN;
577
578	iucv_sock_link(&iucv_sk_list, sk);
579	return sk;
580}
581
582/* Create an IUCV socket */
583static int iucv_sock_create(struct net *net, struct socket *sock, int protocol,
584			    int kern)
585{
586	struct sock *sk;
587
588	if (protocol && protocol != PF_IUCV)
589		return -EPROTONOSUPPORT;
590
591	sock->state = SS_UNCONNECTED;
592
593	switch (sock->type) {
594	case SOCK_STREAM:
595		sock->ops = &iucv_sock_ops;
596		break;
597	case SOCK_SEQPACKET:
598		/* currently, proto ops can handle both sk types */
599		sock->ops = &iucv_sock_ops;
600		break;
601	default:
602		return -ESOCKTNOSUPPORT;
603	}
604
605	sk = iucv_sock_alloc(sock, protocol, GFP_KERNEL);
606	if (!sk)
607		return -ENOMEM;
608
609	iucv_sock_init(sk, NULL);
610
611	return 0;
612}
613
614void iucv_sock_link(struct iucv_sock_list *l, struct sock *sk)
615{
616	write_lock_bh(&l->lock);
617	sk_add_node(sk, &l->head);
618	write_unlock_bh(&l->lock);
619}
620
621void iucv_sock_unlink(struct iucv_sock_list *l, struct sock *sk)
622{
623	write_lock_bh(&l->lock);
624	sk_del_node_init(sk);
625	write_unlock_bh(&l->lock);
626}
627
628void iucv_accept_enqueue(struct sock *parent, struct sock *sk)
629{
630	unsigned long flags;
631	struct iucv_sock *par = iucv_sk(parent);
632
633	sock_hold(sk);
634	spin_lock_irqsave(&par->accept_q_lock, flags);
635	list_add_tail(&iucv_sk(sk)->accept_q, &par->accept_q);
636	spin_unlock_irqrestore(&par->accept_q_lock, flags);
637	iucv_sk(sk)->parent = parent;
638	sk_acceptq_added(parent);
639}
640
641void iucv_accept_unlink(struct sock *sk)
642{
643	unsigned long flags;
644	struct iucv_sock *par = iucv_sk(iucv_sk(sk)->parent);
645
646	spin_lock_irqsave(&par->accept_q_lock, flags);
647	list_del_init(&iucv_sk(sk)->accept_q);
648	spin_unlock_irqrestore(&par->accept_q_lock, flags);
649	sk_acceptq_removed(iucv_sk(sk)->parent);
650	iucv_sk(sk)->parent = NULL;
651	sock_put(sk);
652}
653
654struct sock *iucv_accept_dequeue(struct sock *parent, struct socket *newsock)
655{
656	struct iucv_sock *isk, *n;
657	struct sock *sk;
658
659	list_for_each_entry_safe(isk, n, &iucv_sk(parent)->accept_q, accept_q) {
660		sk = (struct sock *) isk;
661		lock_sock(sk);
662
663		if (sk->sk_state == IUCV_CLOSED) {
664			iucv_accept_unlink(sk);
665			release_sock(sk);
666			continue;
667		}
668
669		if (sk->sk_state == IUCV_CONNECTED ||
670		    sk->sk_state == IUCV_DISCONN ||
671		    !newsock) {
672			iucv_accept_unlink(sk);
673			if (newsock)
674				sock_graft(sk, newsock);
675
676			release_sock(sk);
677			return sk;
678		}
679
680		release_sock(sk);
681	}
682	return NULL;
683}
684
685static void __iucv_auto_name(struct iucv_sock *iucv)
686{
687	char name[12];
688
689	sprintf(name, "%08x", atomic_inc_return(&iucv_sk_list.autobind_name));
690	while (__iucv_get_sock_by_name(name)) {
691		sprintf(name, "%08x",
692			atomic_inc_return(&iucv_sk_list.autobind_name));
693	}
694	memcpy(iucv->src_name, name, 8);
695}
696
697/* Bind an unbound socket */
698static int iucv_sock_bind(struct socket *sock, struct sockaddr *addr,
699			  int addr_len)
700{
701	struct sockaddr_iucv *sa = (struct sockaddr_iucv *) addr;
702	struct sock *sk = sock->sk;
703	struct iucv_sock *iucv;
704	int err = 0;
705	struct net_device *dev;
706	char uid[9];
707
708	/* Verify the input sockaddr */
709	if (!addr || addr->sa_family != AF_IUCV)
710		return -EINVAL;
711
712	if (addr_len < sizeof(struct sockaddr_iucv))
713		return -EINVAL;
714
715	lock_sock(sk);
716	if (sk->sk_state != IUCV_OPEN) {
717		err = -EBADFD;
718		goto done;
719	}
720
721	write_lock_bh(&iucv_sk_list.lock);
722
723	iucv = iucv_sk(sk);
724	if (__iucv_get_sock_by_name(sa->siucv_name)) {
725		err = -EADDRINUSE;
726		goto done_unlock;
727	}
728	if (iucv->path)
729		goto done_unlock;
730
731	/* Bind the socket */
732	if (pr_iucv)
733		if (!memcmp(sa->siucv_user_id, iucv_userid, 8))
734			goto vm_bind; /* VM IUCV transport */
735
736	/* try hiper transport */
737	memcpy(uid, sa->siucv_user_id, sizeof(uid));
738	ASCEBC(uid, 8);
739	rcu_read_lock();
740	for_each_netdev_rcu(&init_net, dev) {
741		if (!memcmp(dev->perm_addr, uid, 8)) {
742			memcpy(iucv->src_user_id, sa->siucv_user_id, 8);
743			/* Check for unitialized siucv_name */
744			if (strncmp(sa->siucv_name, "        ", 8) == 0)
745				__iucv_auto_name(iucv);
746			else
747				memcpy(iucv->src_name, sa->siucv_name, 8);
748			sk->sk_bound_dev_if = dev->ifindex;
749			iucv->hs_dev = dev;
750			dev_hold(dev);
751			sk->sk_state = IUCV_BOUND;
752			iucv->transport = AF_IUCV_TRANS_HIPER;
753			if (!iucv->msglimit)
754				iucv->msglimit = IUCV_HIPER_MSGLIM_DEFAULT;
755			rcu_read_unlock();
756			goto done_unlock;
757		}
758	}
759	rcu_read_unlock();
760vm_bind:
761	if (pr_iucv) {
762		/* use local userid for backward compat */
763		memcpy(iucv->src_name, sa->siucv_name, 8);
764		memcpy(iucv->src_user_id, iucv_userid, 8);
765		sk->sk_state = IUCV_BOUND;
766		iucv->transport = AF_IUCV_TRANS_IUCV;
767		if (!iucv->msglimit)
768			iucv->msglimit = IUCV_QUEUELEN_DEFAULT;
769		goto done_unlock;
770	}
771	/* found no dev to bind */
772	err = -ENODEV;
773done_unlock:
774	/* Release the socket list lock */
775	write_unlock_bh(&iucv_sk_list.lock);
776done:
777	release_sock(sk);
778	return err;
779}
780
781/* Automatically bind an unbound socket */
782static int iucv_sock_autobind(struct sock *sk)
783{
784	struct iucv_sock *iucv = iucv_sk(sk);
785	int err = 0;
786
787	if (unlikely(!pr_iucv))
788		return -EPROTO;
789
790	memcpy(iucv->src_user_id, iucv_userid, 8);
791
792	write_lock_bh(&iucv_sk_list.lock);
793	__iucv_auto_name(iucv);
794	write_unlock_bh(&iucv_sk_list.lock);
795
796	if (!iucv->msglimit)
797		iucv->msglimit = IUCV_QUEUELEN_DEFAULT;
798
799	return err;
800}
801
802static int afiucv_path_connect(struct socket *sock, struct sockaddr *addr)
803{
804	struct sockaddr_iucv *sa = (struct sockaddr_iucv *) addr;
805	struct sock *sk = sock->sk;
806	struct iucv_sock *iucv = iucv_sk(sk);
807	unsigned char user_data[16];
808	int err;
809
810	high_nmcpy(user_data, sa->siucv_name);
811	low_nmcpy(user_data, iucv->src_name);
812	ASCEBC(user_data, sizeof(user_data));
813
814	/* Create path. */
815	iucv->path = iucv_path_alloc(iucv->msglimit,
816				     IUCV_IPRMDATA, GFP_KERNEL);
817	if (!iucv->path) {
818		err = -ENOMEM;
819		goto done;
820	}
821	err = pr_iucv->path_connect(iucv->path, &af_iucv_handler,
822				    sa->siucv_user_id, NULL, user_data,
823				    sk);
824	if (err) {
825		iucv_path_free(iucv->path);
826		iucv->path = NULL;
827		switch (err) {
828		case 0x0b:	/* Target communicator is not logged on */
829			err = -ENETUNREACH;
830			break;
831		case 0x0d:	/* Max connections for this guest exceeded */
832		case 0x0e:	/* Max connections for target guest exceeded */
833			err = -EAGAIN;
834			break;
835		case 0x0f:	/* Missing IUCV authorization */
836			err = -EACCES;
837			break;
838		default:
839			err = -ECONNREFUSED;
840			break;
841		}
842	}
843done:
844	return err;
845}
846
847/* Connect an unconnected socket */
848static int iucv_sock_connect(struct socket *sock, struct sockaddr *addr,
849			     int alen, int flags)
850{
851	struct sockaddr_iucv *sa = (struct sockaddr_iucv *) addr;
852	struct sock *sk = sock->sk;
853	struct iucv_sock *iucv = iucv_sk(sk);
854	int err;
855
856	if (addr->sa_family != AF_IUCV || alen < sizeof(struct sockaddr_iucv))
857		return -EINVAL;
858
859	if (sk->sk_state != IUCV_OPEN && sk->sk_state != IUCV_BOUND)
860		return -EBADFD;
861
862	if (sk->sk_state == IUCV_OPEN &&
863	    iucv->transport == AF_IUCV_TRANS_HIPER)
864		return -EBADFD; /* explicit bind required */
865
866	if (sk->sk_type != SOCK_STREAM && sk->sk_type != SOCK_SEQPACKET)
867		return -EINVAL;
868
869	if (sk->sk_state == IUCV_OPEN) {
870		err = iucv_sock_autobind(sk);
871		if (unlikely(err))
872			return err;
873	}
874
875	lock_sock(sk);
876
877	/* Set the destination information */
878	memcpy(iucv->dst_user_id, sa->siucv_user_id, 8);
879	memcpy(iucv->dst_name, sa->siucv_name, 8);
880
881	if (iucv->transport == AF_IUCV_TRANS_HIPER)
882		err = iucv_send_ctrl(sock->sk, AF_IUCV_FLAG_SYN);
883	else
884		err = afiucv_path_connect(sock, addr);
885	if (err)
886		goto done;
887
888	if (sk->sk_state != IUCV_CONNECTED)
889		err = iucv_sock_wait(sk, iucv_sock_in_state(sk, IUCV_CONNECTED,
890							    IUCV_DISCONN),
891				     sock_sndtimeo(sk, flags & O_NONBLOCK));
892
893	if (sk->sk_state == IUCV_DISCONN || sk->sk_state == IUCV_CLOSED)
894		err = -ECONNREFUSED;
895
896	if (err && iucv->transport == AF_IUCV_TRANS_IUCV)
897		iucv_sever_path(sk, 0);
898
899done:
900	release_sock(sk);
901	return err;
902}
903
904/* Move a socket into listening state. */
905static int iucv_sock_listen(struct socket *sock, int backlog)
906{
907	struct sock *sk = sock->sk;
908	int err;
909
910	lock_sock(sk);
911
912	err = -EINVAL;
913	if (sk->sk_state != IUCV_BOUND)
914		goto done;
915
916	if (sock->type != SOCK_STREAM && sock->type != SOCK_SEQPACKET)
917		goto done;
918
919	sk->sk_max_ack_backlog = backlog;
920	sk->sk_ack_backlog = 0;
921	sk->sk_state = IUCV_LISTEN;
922	err = 0;
923
924done:
925	release_sock(sk);
926	return err;
927}
928
929/* Accept a pending connection */
930static int iucv_sock_accept(struct socket *sock, struct socket *newsock,
931			    int flags)
932{
933	DECLARE_WAITQUEUE(wait, current);
934	struct sock *sk = sock->sk, *nsk;
935	long timeo;
936	int err = 0;
937
938	lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
939
940	if (sk->sk_state != IUCV_LISTEN) {
941		err = -EBADFD;
942		goto done;
943	}
944
945	timeo = sock_rcvtimeo(sk, flags & O_NONBLOCK);
946
947	/* Wait for an incoming connection */
948	add_wait_queue_exclusive(sk_sleep(sk), &wait);
949	while (!(nsk = iucv_accept_dequeue(sk, newsock))) {
950		set_current_state(TASK_INTERRUPTIBLE);
951		if (!timeo) {
952			err = -EAGAIN;
953			break;
954		}
955
956		release_sock(sk);
957		timeo = schedule_timeout(timeo);
958		lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
959
960		if (sk->sk_state != IUCV_LISTEN) {
961			err = -EBADFD;
962			break;
963		}
964
965		if (signal_pending(current)) {
966			err = sock_intr_errno(timeo);
967			break;
968		}
969	}
970
971	set_current_state(TASK_RUNNING);
972	remove_wait_queue(sk_sleep(sk), &wait);
973
974	if (err)
975		goto done;
976
977	newsock->state = SS_CONNECTED;
978
979done:
980	release_sock(sk);
981	return err;
982}
983
984static int iucv_sock_getname(struct socket *sock, struct sockaddr *addr,
985			     int *len, int peer)
986{
987	struct sockaddr_iucv *siucv = (struct sockaddr_iucv *) addr;
988	struct sock *sk = sock->sk;
989	struct iucv_sock *iucv = iucv_sk(sk);
990
991	addr->sa_family = AF_IUCV;
992	*len = sizeof(struct sockaddr_iucv);
993
994	if (peer) {
995		memcpy(siucv->siucv_user_id, iucv->dst_user_id, 8);
996		memcpy(siucv->siucv_name, iucv->dst_name, 8);
997	} else {
998		memcpy(siucv->siucv_user_id, iucv->src_user_id, 8);
999		memcpy(siucv->siucv_name, iucv->src_name, 8);
1000	}
1001	memset(&siucv->siucv_port, 0, sizeof(siucv->siucv_port));
1002	memset(&siucv->siucv_addr, 0, sizeof(siucv->siucv_addr));
1003	memset(&siucv->siucv_nodeid, 0, sizeof(siucv->siucv_nodeid));
1004
1005	return 0;
1006}
1007
1008/**
1009 * iucv_send_iprm() - Send socket data in parameter list of an iucv message.
1010 * @path:	IUCV path
1011 * @msg:	Pointer to a struct iucv_message
1012 * @skb:	The socket data to send, skb->len MUST BE <= 7
1013 *
1014 * Send the socket data in the parameter list in the iucv message
1015 * (IUCV_IPRMDATA). The socket data is stored at index 0 to 6 in the parameter
1016 * list and the socket data len at index 7 (last byte).
1017 * See also iucv_msg_length().
1018 *
1019 * Returns the error code from the iucv_message_send() call.
1020 */
1021static int iucv_send_iprm(struct iucv_path *path, struct iucv_message *msg,
1022			  struct sk_buff *skb)
1023{
1024	u8 prmdata[8];
1025
1026	memcpy(prmdata, (void *) skb->data, skb->len);
1027	prmdata[7] = 0xff - (u8) skb->len;
1028	return pr_iucv->message_send(path, msg, IUCV_IPRMDATA, 0,
1029				 (void *) prmdata, 8);
1030}
1031
1032static int iucv_sock_sendmsg(struct socket *sock, struct msghdr *msg,
1033			     size_t len)
1034{
1035	struct sock *sk = sock->sk;
1036	struct iucv_sock *iucv = iucv_sk(sk);
1037	struct sk_buff *skb;
1038	struct iucv_message txmsg;
1039	struct cmsghdr *cmsg;
1040	int cmsg_done;
1041	long timeo;
1042	char user_id[9];
1043	char appl_id[9];
1044	int err;
1045	int noblock = msg->msg_flags & MSG_DONTWAIT;
1046
1047	err = sock_error(sk);
1048	if (err)
1049		return err;
1050
1051	if (msg->msg_flags & MSG_OOB)
1052		return -EOPNOTSUPP;
1053
1054	/* SOCK_SEQPACKET: we do not support segmented records */
1055	if (sk->sk_type == SOCK_SEQPACKET && !(msg->msg_flags & MSG_EOR))
1056		return -EOPNOTSUPP;
1057
1058	lock_sock(sk);
1059
1060	if (sk->sk_shutdown & SEND_SHUTDOWN) {
1061		err = -EPIPE;
1062		goto out;
1063	}
1064
1065	/* Return if the socket is not in connected state */
1066	if (sk->sk_state != IUCV_CONNECTED) {
1067		err = -ENOTCONN;
1068		goto out;
1069	}
1070
1071	/* initialize defaults */
1072	cmsg_done   = 0;	/* check for duplicate headers */
1073	txmsg.class = 0;
1074
1075	/* iterate over control messages */
1076	for_each_cmsghdr(cmsg, msg) {
1077		if (!CMSG_OK(msg, cmsg)) {
1078			err = -EINVAL;
1079			goto out;
1080		}
1081
1082		if (cmsg->cmsg_level != SOL_IUCV)
1083			continue;
1084
1085		if (cmsg->cmsg_type & cmsg_done) {
1086			err = -EINVAL;
1087			goto out;
1088		}
1089		cmsg_done |= cmsg->cmsg_type;
1090
1091		switch (cmsg->cmsg_type) {
1092		case SCM_IUCV_TRGCLS:
1093			if (cmsg->cmsg_len != CMSG_LEN(TRGCLS_SIZE)) {
1094				err = -EINVAL;
1095				goto out;
1096			}
1097
1098			/* set iucv message target class */
1099			memcpy(&txmsg.class,
1100				(void *) CMSG_DATA(cmsg), TRGCLS_SIZE);
1101
1102			break;
1103
1104		default:
1105			err = -EINVAL;
1106			goto out;
1107		}
1108	}
1109
1110	/* allocate one skb for each iucv message:
1111	 * this is fine for SOCK_SEQPACKET (unless we want to support
1112	 * segmented records using the MSG_EOR flag), but
1113	 * for SOCK_STREAM we might want to improve it in future */
1114	if (iucv->transport == AF_IUCV_TRANS_HIPER)
1115		skb = sock_alloc_send_skb(sk,
1116			len + sizeof(struct af_iucv_trans_hdr) + ETH_HLEN,
1117			noblock, &err);
1118	else
1119		skb = sock_alloc_send_skb(sk, len, noblock, &err);
1120	if (!skb)
1121		goto out;
1122	if (iucv->transport == AF_IUCV_TRANS_HIPER)
1123		skb_reserve(skb, sizeof(struct af_iucv_trans_hdr) + ETH_HLEN);
1124	if (memcpy_from_msg(skb_put(skb, len), msg, len)) {
1125		err = -EFAULT;
1126		goto fail;
1127	}
1128
1129	/* wait if outstanding messages for iucv path has reached */
1130	timeo = sock_sndtimeo(sk, noblock);
1131	err = iucv_sock_wait(sk, iucv_below_msglim(sk), timeo);
1132	if (err)
1133		goto fail;
1134
1135	/* return -ECONNRESET if the socket is no longer connected */
1136	if (sk->sk_state != IUCV_CONNECTED) {
1137		err = -ECONNRESET;
1138		goto fail;
1139	}
1140
1141	/* increment and save iucv message tag for msg_completion cbk */
1142	txmsg.tag = iucv->send_tag++;
1143	IUCV_SKB_CB(skb)->tag = txmsg.tag;
1144
1145	if (iucv->transport == AF_IUCV_TRANS_HIPER) {
1146		atomic_inc(&iucv->msg_sent);
1147		err = afiucv_hs_send(&txmsg, sk, skb, 0);
1148		if (err) {
1149			atomic_dec(&iucv->msg_sent);
1150			goto fail;
1151		}
1152		goto release;
1153	}
1154	skb_queue_tail(&iucv->send_skb_q, skb);
1155
1156	if (((iucv->path->flags & IUCV_IPRMDATA) & iucv->flags)
1157	      && skb->len <= 7) {
1158		err = iucv_send_iprm(iucv->path, &txmsg, skb);
1159
1160		/* on success: there is no message_complete callback
1161		 * for an IPRMDATA msg; remove skb from send queue */
1162		if (err == 0) {
1163			skb_unlink(skb, &iucv->send_skb_q);
1164			kfree_skb(skb);
1165		}
1166
1167		/* this error should never happen since the
1168		 * IUCV_IPRMDATA path flag is set... sever path */
1169		if (err == 0x15) {
1170			pr_iucv->path_sever(iucv->path, NULL);
1171			skb_unlink(skb, &iucv->send_skb_q);
1172			err = -EPIPE;
1173			goto fail;
1174		}
1175	} else
1176		err = pr_iucv->message_send(iucv->path, &txmsg, 0, 0,
1177					(void *) skb->data, skb->len);
1178	if (err) {
1179		if (err == 3) {
1180			user_id[8] = 0;
1181			memcpy(user_id, iucv->dst_user_id, 8);
1182			appl_id[8] = 0;
1183			memcpy(appl_id, iucv->dst_name, 8);
1184			pr_err("Application %s on z/VM guest %s"
1185				" exceeds message limit\n",
1186				appl_id, user_id);
1187			err = -EAGAIN;
1188		} else
1189			err = -EPIPE;
1190		skb_unlink(skb, &iucv->send_skb_q);
1191		goto fail;
1192	}
1193
1194release:
1195	release_sock(sk);
1196	return len;
1197
1198fail:
1199	kfree_skb(skb);
1200out:
1201	release_sock(sk);
1202	return err;
1203}
1204
1205/* iucv_fragment_skb() - Fragment a single IUCV message into multiple skb's
1206 *
1207 * Locking: must be called with message_q.lock held
1208 */
1209static int iucv_fragment_skb(struct sock *sk, struct sk_buff *skb, int len)
1210{
1211	int dataleft, size, copied = 0;
1212	struct sk_buff *nskb;
1213
1214	dataleft = len;
1215	while (dataleft) {
1216		if (dataleft >= sk->sk_rcvbuf / 4)
1217			size = sk->sk_rcvbuf / 4;
1218		else
1219			size = dataleft;
1220
1221		nskb = alloc_skb(size, GFP_ATOMIC | GFP_DMA);
1222		if (!nskb)
1223			return -ENOMEM;
1224
1225		/* copy target class to control buffer of new skb */
1226		IUCV_SKB_CB(nskb)->class = IUCV_SKB_CB(skb)->class;
1227
1228		/* copy data fragment */
1229		memcpy(nskb->data, skb->data + copied, size);
1230		copied += size;
1231		dataleft -= size;
1232
1233		skb_reset_transport_header(nskb);
1234		skb_reset_network_header(nskb);
1235		nskb->len = size;
1236
1237		skb_queue_tail(&iucv_sk(sk)->backlog_skb_q, nskb);
1238	}
1239
1240	return 0;
1241}
1242
1243/* iucv_process_message() - Receive a single outstanding IUCV message
1244 *
1245 * Locking: must be called with message_q.lock held
1246 */
1247static void iucv_process_message(struct sock *sk, struct sk_buff *skb,
1248				 struct iucv_path *path,
1249				 struct iucv_message *msg)
1250{
1251	int rc;
1252	unsigned int len;
1253
1254	len = iucv_msg_length(msg);
1255
1256	/* store msg target class in the second 4 bytes of skb ctrl buffer */
1257	/* Note: the first 4 bytes are reserved for msg tag */
1258	IUCV_SKB_CB(skb)->class = msg->class;
1259
1260	/* check for special IPRM messages (e.g. iucv_sock_shutdown) */
1261	if ((msg->flags & IUCV_IPRMDATA) && len > 7) {
1262		if (memcmp(msg->rmmsg, iprm_shutdown, 8) == 0) {
1263			skb->data = NULL;
1264			skb->len = 0;
1265		}
1266	} else {
1267		rc = pr_iucv->message_receive(path, msg,
1268					      msg->flags & IUCV_IPRMDATA,
1269					      skb->data, len, NULL);
1270		if (rc) {
1271			kfree_skb(skb);
1272			return;
1273		}
1274		/* we need to fragment iucv messages for SOCK_STREAM only;
1275		 * for SOCK_SEQPACKET, it is only relevant if we support
1276		 * record segmentation using MSG_EOR (see also recvmsg()) */
1277		if (sk->sk_type == SOCK_STREAM &&
1278		    skb->truesize >= sk->sk_rcvbuf / 4) {
1279			rc = iucv_fragment_skb(sk, skb, len);
1280			kfree_skb(skb);
1281			skb = NULL;
1282			if (rc) {
1283				pr_iucv->path_sever(path, NULL);
1284				return;
1285			}
1286			skb = skb_dequeue(&iucv_sk(sk)->backlog_skb_q);
1287		} else {
1288			skb_reset_transport_header(skb);
1289			skb_reset_network_header(skb);
1290			skb->len = len;
1291		}
1292	}
1293
1294	IUCV_SKB_CB(skb)->offset = 0;
1295	if (sock_queue_rcv_skb(sk, skb))
1296		skb_queue_head(&iucv_sk(sk)->backlog_skb_q, skb);
1297}
1298
1299/* iucv_process_message_q() - Process outstanding IUCV messages
1300 *
1301 * Locking: must be called with message_q.lock held
1302 */
1303static void iucv_process_message_q(struct sock *sk)
1304{
1305	struct iucv_sock *iucv = iucv_sk(sk);
1306	struct sk_buff *skb;
1307	struct sock_msg_q *p, *n;
1308
1309	list_for_each_entry_safe(p, n, &iucv->message_q.list, list) {
1310		skb = alloc_skb(iucv_msg_length(&p->msg), GFP_ATOMIC | GFP_DMA);
1311		if (!skb)
1312			break;
1313		iucv_process_message(sk, skb, p->path, &p->msg);
1314		list_del(&p->list);
1315		kfree(p);
1316		if (!skb_queue_empty(&iucv->backlog_skb_q))
1317			break;
1318	}
1319}
1320
1321static int iucv_sock_recvmsg(struct socket *sock, struct msghdr *msg,
1322			     size_t len, int flags)
1323{
1324	int noblock = flags & MSG_DONTWAIT;
1325	struct sock *sk = sock->sk;
1326	struct iucv_sock *iucv = iucv_sk(sk);
1327	unsigned int copied, rlen;
1328	struct sk_buff *skb, *rskb, *cskb;
1329	int err = 0;
1330	u32 offset;
1331
1332	if ((sk->sk_state == IUCV_DISCONN) &&
1333	    skb_queue_empty(&iucv->backlog_skb_q) &&
1334	    skb_queue_empty(&sk->sk_receive_queue) &&
1335	    list_empty(&iucv->message_q.list))
1336		return 0;
1337
1338	if (flags & (MSG_OOB))
1339		return -EOPNOTSUPP;
1340
1341	/* receive/dequeue next skb:
1342	 * the function understands MSG_PEEK and, thus, does not dequeue skb */
1343	skb = skb_recv_datagram(sk, flags, noblock, &err);
1344	if (!skb) {
1345		if (sk->sk_shutdown & RCV_SHUTDOWN)
1346			return 0;
1347		return err;
1348	}
1349
1350	offset = IUCV_SKB_CB(skb)->offset;
1351	rlen   = skb->len - offset;		/* real length of skb */
1352	copied = min_t(unsigned int, rlen, len);
1353	if (!rlen)
1354		sk->sk_shutdown = sk->sk_shutdown | RCV_SHUTDOWN;
1355
1356	cskb = skb;
1357	if (skb_copy_datagram_msg(cskb, offset, msg, copied)) {
1358		if (!(flags & MSG_PEEK))
1359			skb_queue_head(&sk->sk_receive_queue, skb);
1360		return -EFAULT;
1361	}
1362
1363	/* SOCK_SEQPACKET: set MSG_TRUNC if recv buf size is too small */
1364	if (sk->sk_type == SOCK_SEQPACKET) {
1365		if (copied < rlen)
1366			msg->msg_flags |= MSG_TRUNC;
1367		/* each iucv message contains a complete record */
1368		msg->msg_flags |= MSG_EOR;
1369	}
1370
1371	/* create control message to store iucv msg target class:
1372	 * get the trgcls from the control buffer of the skb due to
1373	 * fragmentation of original iucv message. */
1374	err = put_cmsg(msg, SOL_IUCV, SCM_IUCV_TRGCLS,
1375		       sizeof(IUCV_SKB_CB(skb)->class),
1376		       (void *)&IUCV_SKB_CB(skb)->class);
1377	if (err) {
1378		if (!(flags & MSG_PEEK))
1379			skb_queue_head(&sk->sk_receive_queue, skb);
1380		return err;
1381	}
1382
1383	/* Mark read part of skb as used */
1384	if (!(flags & MSG_PEEK)) {
1385
1386		/* SOCK_STREAM: re-queue skb if it contains unreceived data */
1387		if (sk->sk_type == SOCK_STREAM) {
1388			if (copied < rlen) {
1389				IUCV_SKB_CB(skb)->offset = offset + copied;
1390				skb_queue_head(&sk->sk_receive_queue, skb);
1391				goto done;
1392			}
1393		}
1394
1395		kfree_skb(skb);
1396		if (iucv->transport == AF_IUCV_TRANS_HIPER) {
1397			atomic_inc(&iucv->msg_recv);
1398			if (atomic_read(&iucv->msg_recv) > iucv->msglimit) {
1399				WARN_ON(1);
1400				iucv_sock_close(sk);
1401				return -EFAULT;
1402			}
1403		}
1404
1405		/* Queue backlog skbs */
1406		spin_lock_bh(&iucv->message_q.lock);
1407		rskb = skb_dequeue(&iucv->backlog_skb_q);
1408		while (rskb) {
1409			IUCV_SKB_CB(rskb)->offset = 0;
1410			if (sock_queue_rcv_skb(sk, rskb)) {
1411				skb_queue_head(&iucv->backlog_skb_q,
1412						rskb);
1413				break;
1414			} else {
1415				rskb = skb_dequeue(&iucv->backlog_skb_q);
1416			}
1417		}
1418		if (skb_queue_empty(&iucv->backlog_skb_q)) {
1419			if (!list_empty(&iucv->message_q.list))
1420				iucv_process_message_q(sk);
1421			if (atomic_read(&iucv->msg_recv) >=
1422							iucv->msglimit / 2) {
1423				err = iucv_send_ctrl(sk, AF_IUCV_FLAG_WIN);
1424				if (err) {
1425					sk->sk_state = IUCV_DISCONN;
1426					sk->sk_state_change(sk);
1427				}
1428			}
1429		}
1430		spin_unlock_bh(&iucv->message_q.lock);
1431	}
1432
1433done:
1434	/* SOCK_SEQPACKET: return real length if MSG_TRUNC is set */
1435	if (sk->sk_type == SOCK_SEQPACKET && (flags & MSG_TRUNC))
1436		copied = rlen;
1437
1438	return copied;
1439}
1440
1441static inline unsigned int iucv_accept_poll(struct sock *parent)
1442{
1443	struct iucv_sock *isk, *n;
1444	struct sock *sk;
1445
1446	list_for_each_entry_safe(isk, n, &iucv_sk(parent)->accept_q, accept_q) {
1447		sk = (struct sock *) isk;
1448
1449		if (sk->sk_state == IUCV_CONNECTED)
1450			return POLLIN | POLLRDNORM;
1451	}
1452
1453	return 0;
1454}
1455
1456unsigned int iucv_sock_poll(struct file *file, struct socket *sock,
1457			    poll_table *wait)
1458{
1459	struct sock *sk = sock->sk;
1460	unsigned int mask = 0;
1461
1462	sock_poll_wait(file, sk_sleep(sk), wait);
1463
1464	if (sk->sk_state == IUCV_LISTEN)
1465		return iucv_accept_poll(sk);
1466
1467	if (sk->sk_err || !skb_queue_empty(&sk->sk_error_queue))
1468		mask |= POLLERR |
1469			(sock_flag(sk, SOCK_SELECT_ERR_QUEUE) ? POLLPRI : 0);
1470
1471	if (sk->sk_shutdown & RCV_SHUTDOWN)
1472		mask |= POLLRDHUP;
1473
1474	if (sk->sk_shutdown == SHUTDOWN_MASK)
1475		mask |= POLLHUP;
1476
1477	if (!skb_queue_empty(&sk->sk_receive_queue) ||
1478	    (sk->sk_shutdown & RCV_SHUTDOWN))
1479		mask |= POLLIN | POLLRDNORM;
1480
1481	if (sk->sk_state == IUCV_CLOSED)
1482		mask |= POLLHUP;
1483
1484	if (sk->sk_state == IUCV_DISCONN)
1485		mask |= POLLIN;
1486
1487	if (sock_writeable(sk) && iucv_below_msglim(sk))
1488		mask |= POLLOUT | POLLWRNORM | POLLWRBAND;
1489	else
1490		set_bit(SOCK_ASYNC_NOSPACE, &sk->sk_socket->flags);
1491
1492	return mask;
1493}
1494
1495static int iucv_sock_shutdown(struct socket *sock, int how)
1496{
1497	struct sock *sk = sock->sk;
1498	struct iucv_sock *iucv = iucv_sk(sk);
1499	struct iucv_message txmsg;
1500	int err = 0;
1501
1502	how++;
1503
1504	if ((how & ~SHUTDOWN_MASK) || !how)
1505		return -EINVAL;
1506
1507	lock_sock(sk);
1508	switch (sk->sk_state) {
1509	case IUCV_LISTEN:
1510	case IUCV_DISCONN:
1511	case IUCV_CLOSING:
1512	case IUCV_CLOSED:
1513		err = -ENOTCONN;
1514		goto fail;
1515	default:
1516		break;
1517	}
1518
1519	if (how == SEND_SHUTDOWN || how == SHUTDOWN_MASK) {
1520		if (iucv->transport == AF_IUCV_TRANS_IUCV) {
1521			txmsg.class = 0;
1522			txmsg.tag = 0;
1523			err = pr_iucv->message_send(iucv->path, &txmsg,
1524				IUCV_IPRMDATA, 0, (void *) iprm_shutdown, 8);
1525			if (err) {
1526				switch (err) {
1527				case 1:
1528					err = -ENOTCONN;
1529					break;
1530				case 2:
1531					err = -ECONNRESET;
1532					break;
1533				default:
1534					err = -ENOTCONN;
1535					break;
1536				}
1537			}
1538		} else
1539			iucv_send_ctrl(sk, AF_IUCV_FLAG_SHT);
1540	}
1541
1542	sk->sk_shutdown |= how;
1543	if (how == RCV_SHUTDOWN || how == SHUTDOWN_MASK) {
1544		if ((iucv->transport == AF_IUCV_TRANS_IUCV) &&
1545		    iucv->path) {
1546			err = pr_iucv->path_quiesce(iucv->path, NULL);
1547			if (err)
1548				err = -ENOTCONN;
1549/*			skb_queue_purge(&sk->sk_receive_queue); */
1550		}
1551		skb_queue_purge(&sk->sk_receive_queue);
1552	}
1553
1554	/* Wake up anyone sleeping in poll */
1555	sk->sk_state_change(sk);
1556
1557fail:
1558	release_sock(sk);
1559	return err;
1560}
1561
1562static int iucv_sock_release(struct socket *sock)
1563{
1564	struct sock *sk = sock->sk;
1565	int err = 0;
1566
1567	if (!sk)
1568		return 0;
1569
1570	iucv_sock_close(sk);
1571
1572	sock_orphan(sk);
1573	iucv_sock_kill(sk);
1574	return err;
1575}
1576
1577/* getsockopt and setsockopt */
1578static int iucv_sock_setsockopt(struct socket *sock, int level, int optname,
1579				char __user *optval, unsigned int optlen)
1580{
1581	struct sock *sk = sock->sk;
1582	struct iucv_sock *iucv = iucv_sk(sk);
1583	int val;
1584	int rc;
1585
1586	if (level != SOL_IUCV)
1587		return -ENOPROTOOPT;
1588
1589	if (optlen < sizeof(int))
1590		return -EINVAL;
1591
1592	if (get_user(val, (int __user *) optval))
1593		return -EFAULT;
1594
1595	rc = 0;
1596
1597	lock_sock(sk);
1598	switch (optname) {
1599	case SO_IPRMDATA_MSG:
1600		if (val)
1601			iucv->flags |= IUCV_IPRMDATA;
1602		else
1603			iucv->flags &= ~IUCV_IPRMDATA;
1604		break;
1605	case SO_MSGLIMIT:
1606		switch (sk->sk_state) {
1607		case IUCV_OPEN:
1608		case IUCV_BOUND:
1609			if (val < 1 || val > (u16)(~0))
1610				rc = -EINVAL;
1611			else
1612				iucv->msglimit = val;
1613			break;
1614		default:
1615			rc = -EINVAL;
1616			break;
1617		}
1618		break;
1619	default:
1620		rc = -ENOPROTOOPT;
1621		break;
1622	}
1623	release_sock(sk);
1624
1625	return rc;
1626}
1627
1628static int iucv_sock_getsockopt(struct socket *sock, int level, int optname,
1629				char __user *optval, int __user *optlen)
1630{
1631	struct sock *sk = sock->sk;
1632	struct iucv_sock *iucv = iucv_sk(sk);
1633	unsigned int val;
1634	int len;
1635
1636	if (level != SOL_IUCV)
1637		return -ENOPROTOOPT;
1638
1639	if (get_user(len, optlen))
1640		return -EFAULT;
1641
1642	if (len < 0)
1643		return -EINVAL;
1644
1645	len = min_t(unsigned int, len, sizeof(int));
1646
1647	switch (optname) {
1648	case SO_IPRMDATA_MSG:
1649		val = (iucv->flags & IUCV_IPRMDATA) ? 1 : 0;
1650		break;
1651	case SO_MSGLIMIT:
1652		lock_sock(sk);
1653		val = (iucv->path != NULL) ? iucv->path->msglim	/* connected */
1654					   : iucv->msglimit;	/* default */
1655		release_sock(sk);
1656		break;
1657	case SO_MSGSIZE:
1658		if (sk->sk_state == IUCV_OPEN)
1659			return -EBADFD;
1660		val = (iucv->hs_dev) ? iucv->hs_dev->mtu -
1661				sizeof(struct af_iucv_trans_hdr) - ETH_HLEN :
1662				0x7fffffff;
1663		break;
1664	default:
1665		return -ENOPROTOOPT;
1666	}
1667
1668	if (put_user(len, optlen))
1669		return -EFAULT;
1670	if (copy_to_user(optval, &val, len))
1671		return -EFAULT;
1672
1673	return 0;
1674}
1675
1676
1677/* Callback wrappers - called from iucv base support */
1678static int iucv_callback_connreq(struct iucv_path *path,
1679				 u8 ipvmid[8], u8 ipuser[16])
1680{
1681	unsigned char user_data[16];
1682	unsigned char nuser_data[16];
1683	unsigned char src_name[8];
1684	struct sock *sk, *nsk;
1685	struct iucv_sock *iucv, *niucv;
1686	int err;
1687
1688	memcpy(src_name, ipuser, 8);
1689	EBCASC(src_name, 8);
1690	/* Find out if this path belongs to af_iucv. */
1691	read_lock(&iucv_sk_list.lock);
1692	iucv = NULL;
1693	sk = NULL;
1694	sk_for_each(sk, &iucv_sk_list.head)
1695		if (sk->sk_state == IUCV_LISTEN &&
1696		    !memcmp(&iucv_sk(sk)->src_name, src_name, 8)) {
1697			/*
1698			 * Found a listening socket with
1699			 * src_name == ipuser[0-7].
1700			 */
1701			iucv = iucv_sk(sk);
1702			break;
1703		}
1704	read_unlock(&iucv_sk_list.lock);
1705	if (!iucv)
1706		/* No socket found, not one of our paths. */
1707		return -EINVAL;
1708
1709	bh_lock_sock(sk);
1710
1711	/* Check if parent socket is listening */
1712	low_nmcpy(user_data, iucv->src_name);
1713	high_nmcpy(user_data, iucv->dst_name);
1714	ASCEBC(user_data, sizeof(user_data));
1715	if (sk->sk_state != IUCV_LISTEN) {
1716		err = pr_iucv->path_sever(path, user_data);
1717		iucv_path_free(path);
1718		goto fail;
1719	}
1720
1721	/* Check for backlog size */
1722	if (sk_acceptq_is_full(sk)) {
1723		err = pr_iucv->path_sever(path, user_data);
1724		iucv_path_free(path);
1725		goto fail;
1726	}
1727
1728	/* Create the new socket */
1729	nsk = iucv_sock_alloc(NULL, sk->sk_type, GFP_ATOMIC);
1730	if (!nsk) {
1731		err = pr_iucv->path_sever(path, user_data);
1732		iucv_path_free(path);
1733		goto fail;
1734	}
1735
1736	niucv = iucv_sk(nsk);
1737	iucv_sock_init(nsk, sk);
1738
1739	/* Set the new iucv_sock */
1740	memcpy(niucv->dst_name, ipuser + 8, 8);
1741	EBCASC(niucv->dst_name, 8);
1742	memcpy(niucv->dst_user_id, ipvmid, 8);
1743	memcpy(niucv->src_name, iucv->src_name, 8);
1744	memcpy(niucv->src_user_id, iucv->src_user_id, 8);
1745	niucv->path = path;
1746
1747	/* Call iucv_accept */
1748	high_nmcpy(nuser_data, ipuser + 8);
1749	memcpy(nuser_data + 8, niucv->src_name, 8);
1750	ASCEBC(nuser_data + 8, 8);
1751
1752	/* set message limit for path based on msglimit of accepting socket */
1753	niucv->msglimit = iucv->msglimit;
1754	path->msglim = iucv->msglimit;
1755	err = pr_iucv->path_accept(path, &af_iucv_handler, nuser_data, nsk);
1756	if (err) {
1757		iucv_sever_path(nsk, 1);
1758		iucv_sock_kill(nsk);
1759		goto fail;
1760	}
1761
1762	iucv_accept_enqueue(sk, nsk);
1763
1764	/* Wake up accept */
1765	nsk->sk_state = IUCV_CONNECTED;
1766	sk->sk_data_ready(sk);
1767	err = 0;
1768fail:
1769	bh_unlock_sock(sk);
1770	return 0;
1771}
1772
1773static void iucv_callback_connack(struct iucv_path *path, u8 ipuser[16])
1774{
1775	struct sock *sk = path->private;
1776
1777	sk->sk_state = IUCV_CONNECTED;
1778	sk->sk_state_change(sk);
1779}
1780
1781static void iucv_callback_rx(struct iucv_path *path, struct iucv_message *msg)
1782{
1783	struct sock *sk = path->private;
1784	struct iucv_sock *iucv = iucv_sk(sk);
1785	struct sk_buff *skb;
1786	struct sock_msg_q *save_msg;
1787	int len;
1788
1789	if (sk->sk_shutdown & RCV_SHUTDOWN) {
1790		pr_iucv->message_reject(path, msg);
1791		return;
1792	}
1793
1794	spin_lock(&iucv->message_q.lock);
1795
1796	if (!list_empty(&iucv->message_q.list) ||
1797	    !skb_queue_empty(&iucv->backlog_skb_q))
1798		goto save_message;
1799
1800	len = atomic_read(&sk->sk_rmem_alloc);
1801	len += SKB_TRUESIZE(iucv_msg_length(msg));
1802	if (len > sk->sk_rcvbuf)
1803		goto save_message;
1804
1805	skb = alloc_skb(iucv_msg_length(msg), GFP_ATOMIC | GFP_DMA);
1806	if (!skb)
1807		goto save_message;
1808
1809	iucv_process_message(sk, skb, path, msg);
1810	goto out_unlock;
1811
1812save_message:
1813	save_msg = kzalloc(sizeof(struct sock_msg_q), GFP_ATOMIC | GFP_DMA);
1814	if (!save_msg)
1815		goto out_unlock;
1816	save_msg->path = path;
1817	save_msg->msg = *msg;
1818
1819	list_add_tail(&save_msg->list, &iucv->message_q.list);
1820
1821out_unlock:
1822	spin_unlock(&iucv->message_q.lock);
1823}
1824
1825static void iucv_callback_txdone(struct iucv_path *path,
1826				 struct iucv_message *msg)
1827{
1828	struct sock *sk = path->private;
1829	struct sk_buff *this = NULL;
1830	struct sk_buff_head *list = &iucv_sk(sk)->send_skb_q;
1831	struct sk_buff *list_skb = list->next;
1832	unsigned long flags;
1833
1834	bh_lock_sock(sk);
1835	if (!skb_queue_empty(list)) {
1836		spin_lock_irqsave(&list->lock, flags);
1837
1838		while (list_skb != (struct sk_buff *)list) {
1839			if (msg->tag == IUCV_SKB_CB(list_skb)->tag) {
1840				this = list_skb;
1841				break;
1842			}
1843			list_skb = list_skb->next;
1844		}
1845		if (this)
1846			__skb_unlink(this, list);
1847
1848		spin_unlock_irqrestore(&list->lock, flags);
1849
1850		if (this) {
1851			kfree_skb(this);
1852			/* wake up any process waiting for sending */
1853			iucv_sock_wake_msglim(sk);
1854		}
1855	}
1856
1857	if (sk->sk_state == IUCV_CLOSING) {
1858		if (skb_queue_empty(&iucv_sk(sk)->send_skb_q)) {
1859			sk->sk_state = IUCV_CLOSED;
1860			sk->sk_state_change(sk);
1861		}
1862	}
1863	bh_unlock_sock(sk);
1864
1865}
1866
1867static void iucv_callback_connrej(struct iucv_path *path, u8 ipuser[16])
1868{
1869	struct sock *sk = path->private;
1870
1871	if (sk->sk_state == IUCV_CLOSED)
1872		return;
1873
1874	bh_lock_sock(sk);
1875	iucv_sever_path(sk, 1);
1876	sk->sk_state = IUCV_DISCONN;
1877
1878	sk->sk_state_change(sk);
1879	bh_unlock_sock(sk);
1880}
1881
1882/* called if the other communication side shuts down its RECV direction;
1883 * in turn, the callback sets SEND_SHUTDOWN to disable sending of data.
1884 */
1885static void iucv_callback_shutdown(struct iucv_path *path, u8 ipuser[16])
1886{
1887	struct sock *sk = path->private;
1888
1889	bh_lock_sock(sk);
1890	if (sk->sk_state != IUCV_CLOSED) {
1891		sk->sk_shutdown |= SEND_SHUTDOWN;
1892		sk->sk_state_change(sk);
1893	}
1894	bh_unlock_sock(sk);
1895}
1896
1897/***************** HiperSockets transport callbacks ********************/
1898static void afiucv_swap_src_dest(struct sk_buff *skb)
1899{
1900	struct af_iucv_trans_hdr *trans_hdr =
1901				(struct af_iucv_trans_hdr *)skb->data;
1902	char tmpID[8];
1903	char tmpName[8];
1904
1905	ASCEBC(trans_hdr->destUserID, sizeof(trans_hdr->destUserID));
1906	ASCEBC(trans_hdr->destAppName, sizeof(trans_hdr->destAppName));
1907	ASCEBC(trans_hdr->srcUserID, sizeof(trans_hdr->srcUserID));
1908	ASCEBC(trans_hdr->srcAppName, sizeof(trans_hdr->srcAppName));
1909	memcpy(tmpID, trans_hdr->srcUserID, 8);
1910	memcpy(tmpName, trans_hdr->srcAppName, 8);
1911	memcpy(trans_hdr->srcUserID, trans_hdr->destUserID, 8);
1912	memcpy(trans_hdr->srcAppName, trans_hdr->destAppName, 8);
1913	memcpy(trans_hdr->destUserID, tmpID, 8);
1914	memcpy(trans_hdr->destAppName, tmpName, 8);
1915	skb_push(skb, ETH_HLEN);
1916	memset(skb->data, 0, ETH_HLEN);
1917}
1918
1919/**
1920 * afiucv_hs_callback_syn - react on received SYN
1921 **/
1922static int afiucv_hs_callback_syn(struct sock *sk, struct sk_buff *skb)
1923{
1924	struct sock *nsk;
1925	struct iucv_sock *iucv, *niucv;
1926	struct af_iucv_trans_hdr *trans_hdr;
1927	int err;
1928
1929	iucv = iucv_sk(sk);
1930	trans_hdr = (struct af_iucv_trans_hdr *)skb->data;
1931	if (!iucv) {
1932		/* no sock - connection refused */
1933		afiucv_swap_src_dest(skb);
1934		trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
1935		err = dev_queue_xmit(skb);
1936		goto out;
1937	}
1938
1939	nsk = iucv_sock_alloc(NULL, sk->sk_type, GFP_ATOMIC);
1940	bh_lock_sock(sk);
1941	if ((sk->sk_state != IUCV_LISTEN) ||
1942	    sk_acceptq_is_full(sk) ||
1943	    !nsk) {
1944		/* error on server socket - connection refused */
1945		afiucv_swap_src_dest(skb);
1946		trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN;
1947		err = dev_queue_xmit(skb);
1948		iucv_sock_kill(nsk);
1949		bh_unlock_sock(sk);
1950		goto out;
1951	}
1952
1953	niucv = iucv_sk(nsk);
1954	iucv_sock_init(nsk, sk);
1955	niucv->transport = AF_IUCV_TRANS_HIPER;
1956	niucv->msglimit = iucv->msglimit;
1957	if (!trans_hdr->window)
1958		niucv->msglimit_peer = IUCV_HIPER_MSGLIM_DEFAULT;
1959	else
1960		niucv->msglimit_peer = trans_hdr->window;
1961	memcpy(niucv->dst_name, trans_hdr->srcAppName, 8);
1962	memcpy(niucv->dst_user_id, trans_hdr->srcUserID, 8);
1963	memcpy(niucv->src_name, iucv->src_name, 8);
1964	memcpy(niucv->src_user_id, iucv->src_user_id, 8);
1965	nsk->sk_bound_dev_if = sk->sk_bound_dev_if;
1966	niucv->hs_dev = iucv->hs_dev;
1967	dev_hold(niucv->hs_dev);
1968	afiucv_swap_src_dest(skb);
1969	trans_hdr->flags = AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_ACK;
1970	trans_hdr->window = niucv->msglimit;
1971	/* if receiver acks the xmit connection is established */
1972	err = dev_queue_xmit(skb);
1973	if (!err) {
1974		iucv_accept_enqueue(sk, nsk);
1975		nsk->sk_state = IUCV_CONNECTED;
1976		sk->sk_data_ready(sk);
1977	} else
1978		iucv_sock_kill(nsk);
1979	bh_unlock_sock(sk);
1980
1981out:
1982	return NET_RX_SUCCESS;
1983}
1984
1985/**
1986 * afiucv_hs_callback_synack() - react on received SYN-ACK
1987 **/
1988static int afiucv_hs_callback_synack(struct sock *sk, struct sk_buff *skb)
1989{
1990	struct iucv_sock *iucv = iucv_sk(sk);
1991	struct af_iucv_trans_hdr *trans_hdr =
1992					(struct af_iucv_trans_hdr *)skb->data;
1993
1994	if (!iucv)
1995		goto out;
1996	if (sk->sk_state != IUCV_BOUND)
1997		goto out;
1998	bh_lock_sock(sk);
1999	iucv->msglimit_peer = trans_hdr->window;
2000	sk->sk_state = IUCV_CONNECTED;
2001	sk->sk_state_change(sk);
2002	bh_unlock_sock(sk);
2003out:
2004	kfree_skb(skb);
2005	return NET_RX_SUCCESS;
2006}
2007
2008/**
2009 * afiucv_hs_callback_synfin() - react on received SYN_FIN
2010 **/
2011static int afiucv_hs_callback_synfin(struct sock *sk, struct sk_buff *skb)
2012{
2013	struct iucv_sock *iucv = iucv_sk(sk);
2014
2015	if (!iucv)
2016		goto out;
2017	if (sk->sk_state != IUCV_BOUND)
2018		goto out;
2019	bh_lock_sock(sk);
2020	sk->sk_state = IUCV_DISCONN;
2021	sk->sk_state_change(sk);
2022	bh_unlock_sock(sk);
2023out:
2024	kfree_skb(skb);
2025	return NET_RX_SUCCESS;
2026}
2027
2028/**
2029 * afiucv_hs_callback_fin() - react on received FIN
2030 **/
2031static int afiucv_hs_callback_fin(struct sock *sk, struct sk_buff *skb)
2032{
2033	struct iucv_sock *iucv = iucv_sk(sk);
2034
2035	/* other end of connection closed */
2036	if (!iucv)
2037		goto out;
2038	bh_lock_sock(sk);
2039	if (sk->sk_state == IUCV_CONNECTED) {
2040		sk->sk_state = IUCV_DISCONN;
2041		sk->sk_state_change(sk);
2042	}
2043	bh_unlock_sock(sk);
2044out:
2045	kfree_skb(skb);
2046	return NET_RX_SUCCESS;
2047}
2048
2049/**
2050 * afiucv_hs_callback_win() - react on received WIN
2051 **/
2052static int afiucv_hs_callback_win(struct sock *sk, struct sk_buff *skb)
2053{
2054	struct iucv_sock *iucv = iucv_sk(sk);
2055	struct af_iucv_trans_hdr *trans_hdr =
2056					(struct af_iucv_trans_hdr *)skb->data;
2057
2058	if (!iucv)
2059		return NET_RX_SUCCESS;
2060
2061	if (sk->sk_state != IUCV_CONNECTED)
2062		return NET_RX_SUCCESS;
2063
2064	atomic_sub(trans_hdr->window, &iucv->msg_sent);
2065	iucv_sock_wake_msglim(sk);
2066	return NET_RX_SUCCESS;
2067}
2068
2069/**
2070 * afiucv_hs_callback_rx() - react on received data
2071 **/
2072static int afiucv_hs_callback_rx(struct sock *sk, struct sk_buff *skb)
2073{
2074	struct iucv_sock *iucv = iucv_sk(sk);
2075
2076	if (!iucv) {
2077		kfree_skb(skb);
2078		return NET_RX_SUCCESS;
2079	}
2080
2081	if (sk->sk_state != IUCV_CONNECTED) {
2082		kfree_skb(skb);
2083		return NET_RX_SUCCESS;
2084	}
2085
2086	if (sk->sk_shutdown & RCV_SHUTDOWN) {
2087		kfree_skb(skb);
2088		return NET_RX_SUCCESS;
2089	}
2090
2091		/* write stuff from iucv_msg to skb cb */
2092	if (skb->len < sizeof(struct af_iucv_trans_hdr)) {
2093		kfree_skb(skb);
2094		return NET_RX_SUCCESS;
2095	}
2096	skb_pull(skb, sizeof(struct af_iucv_trans_hdr));
2097	skb_reset_transport_header(skb);
2098	skb_reset_network_header(skb);
2099	IUCV_SKB_CB(skb)->offset = 0;
2100	spin_lock(&iucv->message_q.lock);
2101	if (skb_queue_empty(&iucv->backlog_skb_q)) {
2102		if (sock_queue_rcv_skb(sk, skb)) {
2103			/* handle rcv queue full */
2104			skb_queue_tail(&iucv->backlog_skb_q, skb);
2105		}
2106	} else
2107		skb_queue_tail(&iucv_sk(sk)->backlog_skb_q, skb);
2108	spin_unlock(&iucv->message_q.lock);
2109	return NET_RX_SUCCESS;
2110}
2111
2112/**
2113 * afiucv_hs_rcv() - base function for arriving data through HiperSockets
2114 *                   transport
2115 *                   called from netif RX softirq
2116 **/
2117static int afiucv_hs_rcv(struct sk_buff *skb, struct net_device *dev,
2118	struct packet_type *pt, struct net_device *orig_dev)
2119{
2120	struct sock *sk;
2121	struct iucv_sock *iucv;
2122	struct af_iucv_trans_hdr *trans_hdr;
2123	char nullstring[8];
2124	int err = 0;
2125
2126	skb_pull(skb, ETH_HLEN);
2127	trans_hdr = (struct af_iucv_trans_hdr *)skb->data;
2128	EBCASC(trans_hdr->destAppName, sizeof(trans_hdr->destAppName));
2129	EBCASC(trans_hdr->destUserID, sizeof(trans_hdr->destUserID));
2130	EBCASC(trans_hdr->srcAppName, sizeof(trans_hdr->srcAppName));
2131	EBCASC(trans_hdr->srcUserID, sizeof(trans_hdr->srcUserID));
2132	memset(nullstring, 0, sizeof(nullstring));
2133	iucv = NULL;
2134	sk = NULL;
2135	read_lock(&iucv_sk_list.lock);
2136	sk_for_each(sk, &iucv_sk_list.head) {
2137		if (trans_hdr->flags == AF_IUCV_FLAG_SYN) {
2138			if ((!memcmp(&iucv_sk(sk)->src_name,
2139				     trans_hdr->destAppName, 8)) &&
2140			    (!memcmp(&iucv_sk(sk)->src_user_id,
2141				     trans_hdr->destUserID, 8)) &&
2142			    (!memcmp(&iucv_sk(sk)->dst_name, nullstring, 8)) &&
2143			    (!memcmp(&iucv_sk(sk)->dst_user_id,
2144				     nullstring, 8))) {
2145				iucv = iucv_sk(sk);
2146				break;
2147			}
2148		} else {
2149			if ((!memcmp(&iucv_sk(sk)->src_name,
2150				     trans_hdr->destAppName, 8)) &&
2151			    (!memcmp(&iucv_sk(sk)->src_user_id,
2152				     trans_hdr->destUserID, 8)) &&
2153			    (!memcmp(&iucv_sk(sk)->dst_name,
2154				     trans_hdr->srcAppName, 8)) &&
2155			    (!memcmp(&iucv_sk(sk)->dst_user_id,
2156				     trans_hdr->srcUserID, 8))) {
2157				iucv = iucv_sk(sk);
2158				break;
2159			}
2160		}
2161	}
2162	read_unlock(&iucv_sk_list.lock);
2163	if (!iucv)
2164		sk = NULL;
2165
2166	/* no sock
2167	how should we send with no sock
2168	1) send without sock no send rc checking?
2169	2) introduce default sock to handle this cases
2170
2171	 SYN -> send SYN|ACK in good case, send SYN|FIN in bad case
2172	 data -> send FIN
2173	 SYN|ACK, SYN|FIN, FIN -> no action? */
2174
2175	switch (trans_hdr->flags) {
2176	case AF_IUCV_FLAG_SYN:
2177		/* connect request */
2178		err = afiucv_hs_callback_syn(sk, skb);
2179		break;
2180	case (AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_ACK):
2181		/* connect request confirmed */
2182		err = afiucv_hs_callback_synack(sk, skb);
2183		break;
2184	case (AF_IUCV_FLAG_SYN | AF_IUCV_FLAG_FIN):
2185		/* connect request refused */
2186		err = afiucv_hs_callback_synfin(sk, skb);
2187		break;
2188	case (AF_IUCV_FLAG_FIN):
2189		/* close request */
2190		err = afiucv_hs_callback_fin(sk, skb);
2191		break;
2192	case (AF_IUCV_FLAG_WIN):
2193		err = afiucv_hs_callback_win(sk, skb);
2194		if (skb->len == sizeof(struct af_iucv_trans_hdr)) {
2195			kfree_skb(skb);
2196			break;
2197		}
2198		/* fall through and receive non-zero length data */
2199	case (AF_IUCV_FLAG_SHT):
2200		/* shutdown request */
2201		/* fall through and receive zero length data */
2202	case 0:
2203		/* plain data frame */
2204		IUCV_SKB_CB(skb)->class = trans_hdr->iucv_hdr.class;
2205		err = afiucv_hs_callback_rx(sk, skb);
2206		break;
2207	default:
2208		;
2209	}
2210
2211	return err;
2212}
2213
2214/**
2215 * afiucv_hs_callback_txnotify() - handle send notifcations from HiperSockets
2216 *                                 transport
2217 **/
2218static void afiucv_hs_callback_txnotify(struct sk_buff *skb,
2219					enum iucv_tx_notify n)
2220{
2221	struct sock *isk = skb->sk;
2222	struct sock *sk = NULL;
2223	struct iucv_sock *iucv = NULL;
2224	struct sk_buff_head *list;
2225	struct sk_buff *list_skb;
2226	struct sk_buff *nskb;
2227	unsigned long flags;
2228
2229	read_lock_irqsave(&iucv_sk_list.lock, flags);
2230	sk_for_each(sk, &iucv_sk_list.head)
2231		if (sk == isk) {
2232			iucv = iucv_sk(sk);
2233			break;
2234		}
2235	read_unlock_irqrestore(&iucv_sk_list.lock, flags);
2236
2237	if (!iucv || sock_flag(sk, SOCK_ZAPPED))
2238		return;
2239
2240	list = &iucv->send_skb_q;
2241	spin_lock_irqsave(&list->lock, flags);
2242	if (skb_queue_empty(list))
2243		goto out_unlock;
2244	list_skb = list->next;
2245	nskb = list_skb->next;
2246	while (list_skb != (struct sk_buff *)list) {
2247		if (skb_shinfo(list_skb) == skb_shinfo(skb)) {
2248			switch (n) {
2249			case TX_NOTIFY_OK:
2250				__skb_unlink(list_skb, list);
2251				kfree_skb(list_skb);
2252				iucv_sock_wake_msglim(sk);
2253				break;
2254			case TX_NOTIFY_PENDING:
2255				atomic_inc(&iucv->pendings);
2256				break;
2257			case TX_NOTIFY_DELAYED_OK:
2258				__skb_unlink(list_skb, list);
2259				atomic_dec(&iucv->pendings);
2260				if (atomic_read(&iucv->pendings) <= 0)
2261					iucv_sock_wake_msglim(sk);
2262				kfree_skb(list_skb);
2263				break;
2264			case TX_NOTIFY_UNREACHABLE:
2265			case TX_NOTIFY_DELAYED_UNREACHABLE:
2266			case TX_NOTIFY_TPQFULL: /* not yet used */
2267			case TX_NOTIFY_GENERALERROR:
2268			case TX_NOTIFY_DELAYED_GENERALERROR:
2269				__skb_unlink(list_skb, list);
2270				kfree_skb(list_skb);
2271				if (sk->sk_state == IUCV_CONNECTED) {
2272					sk->sk_state = IUCV_DISCONN;
2273					sk->sk_state_change(sk);
2274				}
2275				break;
2276			}
2277			break;
2278		}
2279		list_skb = nskb;
2280		nskb = nskb->next;
2281	}
2282out_unlock:
2283	spin_unlock_irqrestore(&list->lock, flags);
2284
2285	if (sk->sk_state == IUCV_CLOSING) {
2286		if (skb_queue_empty(&iucv_sk(sk)->send_skb_q)) {
2287			sk->sk_state = IUCV_CLOSED;
2288			sk->sk_state_change(sk);
2289		}
2290	}
2291
2292}
2293
2294/*
2295 * afiucv_netdev_event: handle netdev notifier chain events
2296 */
2297static int afiucv_netdev_event(struct notifier_block *this,
2298			       unsigned long event, void *ptr)
2299{
2300	struct net_device *event_dev = netdev_notifier_info_to_dev(ptr);
2301	struct sock *sk;
2302	struct iucv_sock *iucv;
2303
2304	switch (event) {
2305	case NETDEV_REBOOT:
2306	case NETDEV_GOING_DOWN:
2307		sk_for_each(sk, &iucv_sk_list.head) {
2308			iucv = iucv_sk(sk);
2309			if ((iucv->hs_dev == event_dev) &&
2310			    (sk->sk_state == IUCV_CONNECTED)) {
2311				if (event == NETDEV_GOING_DOWN)
2312					iucv_send_ctrl(sk, AF_IUCV_FLAG_FIN);
2313				sk->sk_state = IUCV_DISCONN;
2314				sk->sk_state_change(sk);
2315			}
2316		}
2317		break;
2318	case NETDEV_DOWN:
2319	case NETDEV_UNREGISTER:
2320	default:
2321		break;
2322	}
2323	return NOTIFY_DONE;
2324}
2325
2326static struct notifier_block afiucv_netdev_notifier = {
2327	.notifier_call = afiucv_netdev_event,
2328};
2329
2330static const struct proto_ops iucv_sock_ops = {
2331	.family		= PF_IUCV,
2332	.owner		= THIS_MODULE,
2333	.release	= iucv_sock_release,
2334	.bind		= iucv_sock_bind,
2335	.connect	= iucv_sock_connect,
2336	.listen		= iucv_sock_listen,
2337	.accept		= iucv_sock_accept,
2338	.getname	= iucv_sock_getname,
2339	.sendmsg	= iucv_sock_sendmsg,
2340	.recvmsg	= iucv_sock_recvmsg,
2341	.poll		= iucv_sock_poll,
2342	.ioctl		= sock_no_ioctl,
2343	.mmap		= sock_no_mmap,
2344	.socketpair	= sock_no_socketpair,
2345	.shutdown	= iucv_sock_shutdown,
2346	.setsockopt	= iucv_sock_setsockopt,
2347	.getsockopt	= iucv_sock_getsockopt,
2348};
2349
2350static const struct net_proto_family iucv_sock_family_ops = {
2351	.family	= AF_IUCV,
2352	.owner	= THIS_MODULE,
2353	.create	= iucv_sock_create,
2354};
2355
2356static struct packet_type iucv_packet_type = {
2357	.type = cpu_to_be16(ETH_P_AF_IUCV),
2358	.func = afiucv_hs_rcv,
2359};
2360
2361static int afiucv_iucv_init(void)
2362{
2363	int err;
2364
2365	err = pr_iucv->iucv_register(&af_iucv_handler, 0);
2366	if (err)
2367		goto out;
2368	/* establish dummy device */
2369	af_iucv_driver.bus = pr_iucv->bus;
2370	err = driver_register(&af_iucv_driver);
2371	if (err)
2372		goto out_iucv;
2373	af_iucv_dev = kzalloc(sizeof(struct device), GFP_KERNEL);
2374	if (!af_iucv_dev) {
2375		err = -ENOMEM;
2376		goto out_driver;
2377	}
2378	dev_set_name(af_iucv_dev, "af_iucv");
2379	af_iucv_dev->bus = pr_iucv->bus;
2380	af_iucv_dev->parent = pr_iucv->root;
2381	af_iucv_dev->release = (void (*)(struct device *))kfree;
2382	af_iucv_dev->driver = &af_iucv_driver;
2383	err = device_register(af_iucv_dev);
2384	if (err)
2385		goto out_driver;
2386	return 0;
2387
2388out_driver:
2389	driver_unregister(&af_iucv_driver);
2390out_iucv:
2391	pr_iucv->iucv_unregister(&af_iucv_handler, 0);
2392out:
2393	return err;
2394}
2395
2396static int __init afiucv_init(void)
2397{
2398	int err;
2399
2400	if (MACHINE_IS_VM) {
2401		cpcmd("QUERY USERID", iucv_userid, sizeof(iucv_userid), &err);
2402		if (unlikely(err)) {
2403			WARN_ON(err);
2404			err = -EPROTONOSUPPORT;
2405			goto out;
2406		}
2407
2408		pr_iucv = try_then_request_module(symbol_get(iucv_if), "iucv");
2409		if (!pr_iucv) {
2410			printk(KERN_WARNING "iucv_if lookup failed\n");
2411			memset(&iucv_userid, 0, sizeof(iucv_userid));
2412		}
2413	} else {
2414		memset(&iucv_userid, 0, sizeof(iucv_userid));
2415		pr_iucv = NULL;
2416	}
2417
2418	err = proto_register(&iucv_proto, 0);
2419	if (err)
2420		goto out;
2421	err = sock_register(&iucv_sock_family_ops);
2422	if (err)
2423		goto out_proto;
2424
2425	if (pr_iucv) {
2426		err = afiucv_iucv_init();
2427		if (err)
2428			goto out_sock;
2429	} else
2430		register_netdevice_notifier(&afiucv_netdev_notifier);
2431	dev_add_pack(&iucv_packet_type);
2432	return 0;
2433
2434out_sock:
2435	sock_unregister(PF_IUCV);
2436out_proto:
2437	proto_unregister(&iucv_proto);
2438out:
2439	if (pr_iucv)
2440		symbol_put(iucv_if);
2441	return err;
2442}
2443
2444static void __exit afiucv_exit(void)
2445{
2446	if (pr_iucv) {
2447		device_unregister(af_iucv_dev);
2448		driver_unregister(&af_iucv_driver);
2449		pr_iucv->iucv_unregister(&af_iucv_handler, 0);
2450		symbol_put(iucv_if);
2451	} else
2452		unregister_netdevice_notifier(&afiucv_netdev_notifier);
2453	dev_remove_pack(&iucv_packet_type);
2454	sock_unregister(PF_IUCV);
2455	proto_unregister(&iucv_proto);
2456}
2457
2458module_init(afiucv_init);
2459module_exit(afiucv_exit);
2460
2461MODULE_AUTHOR("Jennifer Hunt <jenhunt@us.ibm.com>");
2462MODULE_DESCRIPTION("IUCV Sockets ver " VERSION);
2463MODULE_VERSION(VERSION);
2464MODULE_LICENSE("GPL");
2465MODULE_ALIAS_NETPROTO(PF_IUCV);
2466
2467