2 * Copyright (c) 2008, 2009 open80211s Ltd.
3 * Author: Luis Carlos Cobo <luisca@cozybit.com>
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License version 2 as
7 * published by the Free Software Foundation.
10 #include <linux/kernel.h>
11 #include <linux/random.h>
12 #include "ieee80211_i.h"
16 #ifdef CONFIG_MAC80211_VERBOSE_MPL_DEBUG
17 #define mpl_dbg(fmt, args...) printk(KERN_DEBUG fmt, ##args)
19 #define mpl_dbg(fmt, args...) do { (void)(0); } while (0)
22 #define PLINK_GET_LLID(p) (p + 4)
23 #define PLINK_GET_PLID(p) (p + 6)
25 #define mod_plink_timer(s, t) (mod_timer(&s->plink_timer, \
26 jiffies + HZ * t / 1000))
28 /* Peer link cancel reasons, all subject to ANA approval */
29 #define MESH_LINK_CANCELLED 2
30 #define MESH_MAX_NEIGHBORS 3
31 #define MESH_CAPABILITY_POLICY_VIOLATION 4
32 #define MESH_CLOSE_RCVD 5
33 #define MESH_MAX_RETRIES 6
34 #define MESH_CONFIRM_TIMEOUT 7
35 #define MESH_SECURITY_ROLE_NEGOTIATION_DIFFERS 8
36 #define MESH_SECURITY_AUTHENTICATION_IMPOSSIBLE 9
37 #define MESH_SECURITY_FAILED_VERIFICATION 10
39 #define dot11MeshMaxRetries(s) (s->u.mesh.mshcfg.dot11MeshMaxRetries)
40 #define dot11MeshRetryTimeout(s) (s->u.mesh.mshcfg.dot11MeshRetryTimeout)
41 #define dot11MeshConfirmTimeout(s) (s->u.mesh.mshcfg.dot11MeshConfirmTimeout)
42 #define dot11MeshHoldingTimeout(s) (s->u.mesh.mshcfg.dot11MeshHoldingTimeout)
43 #define dot11MeshMaxPeerLinks(s) (s->u.mesh.mshcfg.dot11MeshMaxPeerLinks)
45 enum plink_frame_type
{
64 void mesh_plink_inc_estab_count(struct ieee80211_sub_if_data
*sdata
)
66 atomic_inc(&sdata
->u
.mesh
.mshstats
.estab_plinks
);
67 mesh_accept_plinks_update(sdata
);
71 void mesh_plink_dec_estab_count(struct ieee80211_sub_if_data
*sdata
)
73 atomic_dec(&sdata
->u
.mesh
.mshstats
.estab_plinks
);
74 mesh_accept_plinks_update(sdata
);
78 * mesh_plink_fsm_restart - restart a mesh peer link finite state machine
80 * @sta: mesh peer link to restart
82 * Locking: this function must be called holding sta->lock
84 static inline void mesh_plink_fsm_restart(struct sta_info
*sta
)
86 sta
->plink_state
= PLINK_LISTEN
;
87 sta
->llid
= sta
->plid
= sta
->reason
= 0;
88 sta
->plink_retries
= 0;
92 * NOTE: This is just an alias for sta_info_alloc(), see notes
93 * on it in the lifecycle management section!
95 static struct sta_info
*mesh_plink_alloc(struct ieee80211_sub_if_data
*sdata
,
96 u8
*hw_addr
, u32 rates
)
98 struct ieee80211_local
*local
= sdata
->local
;
101 if (local
->num_sta
>= MESH_MAX_PLINKS
)
104 sta
= sta_info_alloc(sdata
, hw_addr
, GFP_KERNEL
);
108 sta
->flags
= WLAN_STA_AUTHORIZED
;
109 sta
->sta
.supp_rates
[local
->hw
.conf
.channel
->band
] = rates
;
110 rate_control_rate_init(sta
);
116 * __mesh_plink_deactivate - deactivate mesh peer link
118 * @sta: mesh peer link to deactivate
120 * All mesh paths with this peer as next hop will be flushed
122 * Locking: the caller must hold sta->lock
124 static bool __mesh_plink_deactivate(struct sta_info
*sta
)
126 struct ieee80211_sub_if_data
*sdata
= sta
->sdata
;
127 bool deactivated
= false;
129 if (sta
->plink_state
== PLINK_ESTAB
) {
130 mesh_plink_dec_estab_count(sdata
);
133 sta
->plink_state
= PLINK_BLOCKED
;
134 mesh_path_flush_by_nexthop(sta
);
140 * mesh_plink_deactivate - deactivate mesh peer link
142 * @sta: mesh peer link to deactivate
144 * All mesh paths with this peer as next hop will be flushed
146 void mesh_plink_deactivate(struct sta_info
*sta
)
148 struct ieee80211_sub_if_data
*sdata
= sta
->sdata
;
151 spin_lock_bh(&sta
->lock
);
152 deactivated
= __mesh_plink_deactivate(sta
);
153 spin_unlock_bh(&sta
->lock
);
156 ieee80211_bss_info_change_notify(sdata
, BSS_CHANGED_BEACON
);
159 static int mesh_plink_frame_tx(struct ieee80211_sub_if_data
*sdata
,
160 enum plink_frame_type action
, u8
*da
, __le16 llid
, __le16 plid
,
162 struct ieee80211_local
*local
= sdata
->local
;
163 struct sk_buff
*skb
= dev_alloc_skb(local
->hw
.extra_tx_headroom
+ 400 +
164 sdata
->u
.mesh
.vendor_ie_len
);
165 struct ieee80211_mgmt
*mgmt
;
166 bool include_plid
= false;
167 static const u8 meshpeeringproto
[] = { 0x00, 0x0F, 0xAC, 0x2A };
173 skb_reserve(skb
, local
->hw
.extra_tx_headroom
);
174 /* 25 is the size of the common mgmt part (24) plus the size of the
175 * common action part (1)
177 mgmt
= (struct ieee80211_mgmt
*)
178 skb_put(skb
, 25 + sizeof(mgmt
->u
.action
.u
.plink_action
));
179 memset(mgmt
, 0, 25 + sizeof(mgmt
->u
.action
.u
.plink_action
));
180 mgmt
->frame_control
= cpu_to_le16(IEEE80211_FTYPE_MGMT
|
181 IEEE80211_STYPE_ACTION
);
182 memcpy(mgmt
->da
, da
, ETH_ALEN
);
183 memcpy(mgmt
->sa
, sdata
->vif
.addr
, ETH_ALEN
);
184 /* BSSID is left zeroed, wildcard value */
185 mgmt
->u
.action
.category
= WLAN_CATEGORY_MESH_PLINK
;
186 mgmt
->u
.action
.u
.plink_action
.action_code
= action
;
188 if (action
== PLINK_CLOSE
)
189 mgmt
->u
.action
.u
.plink_action
.aux
= reason
;
191 mgmt
->u
.action
.u
.plink_action
.aux
= cpu_to_le16(0x0);
192 if (action
== PLINK_CONFIRM
) {
193 pos
= skb_put(skb
, 4);
194 /* two-byte status code followed by two-byte AID */
196 memcpy(pos
+ 2, &plid
, 2);
198 mesh_mgmt_ies_add(skb
, sdata
);
201 /* Add Peer Link Management element */
221 pos
= skb_put(skb
, 2 + ie_len
);
222 *pos
++ = WLAN_EID_PEER_LINK
;
224 memcpy(pos
, meshpeeringproto
, sizeof(meshpeeringproto
));
226 memcpy(pos
, &llid
, 2);
229 memcpy(pos
, &plid
, 2);
231 if (action
== PLINK_CLOSE
) {
233 memcpy(pos
, &reason
, 2);
236 ieee80211_tx_skb(sdata
, skb
);
240 void mesh_neighbour_update(u8
*hw_addr
, u32 rates
, struct ieee80211_sub_if_data
*sdata
,
241 bool peer_accepting_plinks
)
243 struct ieee80211_local
*local
= sdata
->local
;
244 struct sta_info
*sta
;
248 sta
= sta_info_get(sdata
, hw_addr
);
252 sta
= mesh_plink_alloc(sdata
, hw_addr
, rates
);
255 if (sta_info_insert_rcu(sta
)) {
261 sta
->last_rx
= jiffies
;
262 sta
->sta
.supp_rates
[local
->hw
.conf
.channel
->band
] = rates
;
263 if (peer_accepting_plinks
&& sta
->plink_state
== PLINK_LISTEN
&&
264 sdata
->u
.mesh
.accepting_plinks
&&
265 sdata
->u
.mesh
.mshcfg
.auto_open_plinks
)
266 mesh_plink_open(sta
);
271 static void mesh_plink_timer(unsigned long data
)
273 struct sta_info
*sta
;
274 __le16 llid
, plid
, reason
;
275 struct ieee80211_sub_if_data
*sdata
;
278 * This STA is valid because sta_info_destroy() will
279 * del_timer_sync() this timer after having made sure
280 * it cannot be readded (by deleting the plink.)
282 sta
= (struct sta_info
*) data
;
284 if (sta
->sdata
->local
->quiescing
) {
285 sta
->plink_timer_was_running
= true;
289 spin_lock_bh(&sta
->lock
);
290 if (sta
->ignore_plink_timer
) {
291 sta
->ignore_plink_timer
= false;
292 spin_unlock_bh(&sta
->lock
);
295 mpl_dbg("Mesh plink timer for %pM fired on state %d\n",
296 sta
->sta
.addr
, sta
->plink_state
);
302 switch (sta
->plink_state
) {
306 if (sta
->plink_retries
< dot11MeshMaxRetries(sdata
)) {
308 mpl_dbg("Mesh plink for %pM (retry, timeout): %d %d\n",
309 sta
->sta
.addr
, sta
->plink_retries
,
311 get_random_bytes(&rand
, sizeof(u32
));
312 sta
->plink_timeout
= sta
->plink_timeout
+
313 rand
% sta
->plink_timeout
;
314 ++sta
->plink_retries
;
315 mod_plink_timer(sta
, sta
->plink_timeout
);
316 spin_unlock_bh(&sta
->lock
);
317 mesh_plink_frame_tx(sdata
, PLINK_OPEN
, sta
->sta
.addr
, llid
,
321 reason
= cpu_to_le16(MESH_MAX_RETRIES
);
322 /* fall through on else */
326 reason
= cpu_to_le16(MESH_CONFIRM_TIMEOUT
);
327 sta
->plink_state
= PLINK_HOLDING
;
328 mod_plink_timer(sta
, dot11MeshHoldingTimeout(sdata
));
329 spin_unlock_bh(&sta
->lock
);
330 mesh_plink_frame_tx(sdata
, PLINK_CLOSE
, sta
->sta
.addr
, llid
, plid
,
335 del_timer(&sta
->plink_timer
);
336 mesh_plink_fsm_restart(sta
);
337 spin_unlock_bh(&sta
->lock
);
340 spin_unlock_bh(&sta
->lock
);
346 void mesh_plink_quiesce(struct sta_info
*sta
)
348 if (del_timer_sync(&sta
->plink_timer
))
349 sta
->plink_timer_was_running
= true;
352 void mesh_plink_restart(struct sta_info
*sta
)
354 if (sta
->plink_timer_was_running
) {
355 add_timer(&sta
->plink_timer
);
356 sta
->plink_timer_was_running
= false;
361 static inline void mesh_plink_timer_set(struct sta_info
*sta
, int timeout
)
363 sta
->plink_timer
.expires
= jiffies
+ (HZ
* timeout
/ 1000);
364 sta
->plink_timer
.data
= (unsigned long) sta
;
365 sta
->plink_timer
.function
= mesh_plink_timer
;
366 sta
->plink_timeout
= timeout
;
367 add_timer(&sta
->plink_timer
);
370 int mesh_plink_open(struct sta_info
*sta
)
373 struct ieee80211_sub_if_data
*sdata
= sta
->sdata
;
375 spin_lock_bh(&sta
->lock
);
376 get_random_bytes(&llid
, 2);
378 if (sta
->plink_state
!= PLINK_LISTEN
) {
379 spin_unlock_bh(&sta
->lock
);
382 sta
->plink_state
= PLINK_OPN_SNT
;
383 mesh_plink_timer_set(sta
, dot11MeshRetryTimeout(sdata
));
384 spin_unlock_bh(&sta
->lock
);
385 mpl_dbg("Mesh plink: starting establishment with %pM\n",
388 return mesh_plink_frame_tx(sdata
, PLINK_OPEN
,
389 sta
->sta
.addr
, llid
, 0, 0);
392 void mesh_plink_block(struct sta_info
*sta
)
394 struct ieee80211_sub_if_data
*sdata
= sta
->sdata
;
397 spin_lock_bh(&sta
->lock
);
398 deactivated
= __mesh_plink_deactivate(sta
);
399 sta
->plink_state
= PLINK_BLOCKED
;
400 spin_unlock_bh(&sta
->lock
);
403 ieee80211_bss_info_change_notify(sdata
, BSS_CHANGED_BEACON
);
407 void mesh_rx_plink_frame(struct ieee80211_sub_if_data
*sdata
, struct ieee80211_mgmt
*mgmt
,
408 size_t len
, struct ieee80211_rx_status
*rx_status
)
410 struct ieee80211_local
*local
= sdata
->local
;
411 struct ieee802_11_elems elems
;
412 struct sta_info
*sta
;
413 enum plink_event event
;
414 enum plink_frame_type ftype
;
416 bool deactivated
, matches_local
= true;
419 __le16 plid
, llid
, reason
;
420 #ifdef CONFIG_MAC80211_VERBOSE_MPL_DEBUG
421 static const char *mplstates
[] = {
422 [PLINK_LISTEN
] = "LISTEN",
423 [PLINK_OPN_SNT
] = "OPN-SNT",
424 [PLINK_OPN_RCVD
] = "OPN-RCVD",
425 [PLINK_CNF_RCVD
] = "CNF_RCVD",
426 [PLINK_ESTAB
] = "ESTAB",
427 [PLINK_HOLDING
] = "HOLDING",
428 [PLINK_BLOCKED
] = "BLOCKED"
432 /* need action_code, aux */
433 if (len
< IEEE80211_MIN_ACTION_SIZE
+ 3)
436 if (is_multicast_ether_addr(mgmt
->da
)) {
437 mpl_dbg("Mesh plink: ignore frame from multicast address");
441 baseaddr
= mgmt
->u
.action
.u
.plink_action
.variable
;
442 baselen
= (u8
*) mgmt
->u
.action
.u
.plink_action
.variable
- (u8
*) mgmt
;
443 if (mgmt
->u
.action
.u
.plink_action
.action_code
== PLINK_CONFIRM
) {
447 ieee802_11_parse_elems(baseaddr
, len
- baselen
, &elems
);
448 if (!elems
.peer_link
) {
449 mpl_dbg("Mesh plink: missing necessary peer link ie\n");
453 ftype
= mgmt
->u
.action
.u
.plink_action
.action_code
;
454 ie_len
= elems
.peer_link_len
;
455 if ((ftype
== PLINK_OPEN
&& ie_len
!= 6) ||
456 (ftype
== PLINK_CONFIRM
&& ie_len
!= 8) ||
457 (ftype
== PLINK_CLOSE
&& ie_len
!= 8 && ie_len
!= 10)) {
458 mpl_dbg("Mesh plink: incorrect plink ie length %d %d\n",
463 if (ftype
!= PLINK_CLOSE
&& (!elems
.mesh_id
|| !elems
.mesh_config
)) {
464 mpl_dbg("Mesh plink: missing necessary ie\n");
467 /* Note the lines below are correct, the llid in the frame is the plid
468 * from the point of view of this host.
470 memcpy(&plid
, PLINK_GET_LLID(elems
.peer_link
), 2);
471 if (ftype
== PLINK_CONFIRM
|| (ftype
== PLINK_CLOSE
&& ie_len
== 10))
472 memcpy(&llid
, PLINK_GET_PLID(elems
.peer_link
), 2);
476 sta
= sta_info_get(sdata
, mgmt
->sa
);
477 if (!sta
&& ftype
!= PLINK_OPEN
) {
478 mpl_dbg("Mesh plink: cls or cnf from unknown peer\n");
483 if (sta
&& sta
->plink_state
== PLINK_BLOCKED
) {
488 /* Now we will figure out the appropriate event... */
489 event
= PLINK_UNDEFINED
;
490 if (ftype
!= PLINK_CLOSE
&& (!mesh_matches_local(&elems
, sdata
))) {
491 matches_local
= false;
505 if (!sta
&& !matches_local
) {
507 reason
= cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION
);
509 mesh_plink_frame_tx(sdata
, PLINK_CLOSE
, mgmt
->sa
, llid
,
513 /* ftype == PLINK_OPEN */
518 if (!mesh_plink_free_count(sdata
)) {
519 mpl_dbg("Mesh plink error: no more free plinks\n");
523 rates
= ieee80211_sta_get_rates(local
, &elems
, rx_status
->band
);
524 sta
= mesh_plink_alloc(sdata
, mgmt
->sa
, rates
);
526 mpl_dbg("Mesh plink error: plink table full\n");
529 if (sta_info_insert_rcu(sta
)) {
534 spin_lock_bh(&sta
->lock
);
535 } else if (matches_local
) {
536 spin_lock_bh(&sta
->lock
);
539 if (!mesh_plink_free_count(sdata
) ||
540 (sta
->plid
&& sta
->plid
!= plid
))
546 if (!mesh_plink_free_count(sdata
) ||
547 (sta
->llid
!= llid
|| sta
->plid
!= plid
))
553 if (sta
->plink_state
== PLINK_ESTAB
)
554 /* Do not check for llid or plid. This does not
555 * follow the standard but since multiple plinks
556 * per sta are not supported, it is necessary in
557 * order to avoid a livelock when MP A sees an
558 * establish peer link to MP B but MP B does not
559 * see it. This can be caused by a timeout in
560 * B's peer link establishment or B beign
564 else if (sta
->plid
!= plid
)
566 else if (ie_len
== 7 && sta
->llid
!= llid
)
572 mpl_dbg("Mesh plink: unknown frame subtype\n");
573 spin_unlock_bh(&sta
->lock
);
578 spin_lock_bh(&sta
->lock
);
581 mpl_dbg("Mesh plink (peer, state, llid, plid, event): %pM %s %d %d %d\n",
582 mgmt
->sa
, mplstates
[sta
->plink_state
],
583 le16_to_cpu(sta
->llid
), le16_to_cpu(sta
->plid
),
586 switch (sta
->plink_state
) {
587 /* spin_unlock as soon as state is updated at each case */
591 mesh_plink_fsm_restart(sta
);
592 spin_unlock_bh(&sta
->lock
);
595 sta
->plink_state
= PLINK_OPN_RCVD
;
597 get_random_bytes(&llid
, 2);
599 mesh_plink_timer_set(sta
, dot11MeshRetryTimeout(sdata
));
600 spin_unlock_bh(&sta
->lock
);
601 mesh_plink_frame_tx(sdata
, PLINK_OPEN
, sta
->sta
.addr
, llid
,
603 mesh_plink_frame_tx(sdata
, PLINK_CONFIRM
, sta
->sta
.addr
,
607 spin_unlock_bh(&sta
->lock
);
616 reason
= cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION
);
619 reason
= cpu_to_le16(MESH_CLOSE_RCVD
);
620 sta
->reason
= reason
;
621 sta
->plink_state
= PLINK_HOLDING
;
622 if (!mod_plink_timer(sta
,
623 dot11MeshHoldingTimeout(sdata
)))
624 sta
->ignore_plink_timer
= true;
627 spin_unlock_bh(&sta
->lock
);
628 mesh_plink_frame_tx(sdata
, PLINK_CLOSE
, sta
->sta
.addr
, llid
,
632 /* retry timer is left untouched */
633 sta
->plink_state
= PLINK_OPN_RCVD
;
636 spin_unlock_bh(&sta
->lock
);
637 mesh_plink_frame_tx(sdata
, PLINK_CONFIRM
, sta
->sta
.addr
, llid
,
641 sta
->plink_state
= PLINK_CNF_RCVD
;
642 if (!mod_plink_timer(sta
,
643 dot11MeshConfirmTimeout(sdata
)))
644 sta
->ignore_plink_timer
= true;
646 spin_unlock_bh(&sta
->lock
);
649 spin_unlock_bh(&sta
->lock
);
658 reason
= cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION
);
661 reason
= cpu_to_le16(MESH_CLOSE_RCVD
);
662 sta
->reason
= reason
;
663 sta
->plink_state
= PLINK_HOLDING
;
664 if (!mod_plink_timer(sta
,
665 dot11MeshHoldingTimeout(sdata
)))
666 sta
->ignore_plink_timer
= true;
669 spin_unlock_bh(&sta
->lock
);
670 mesh_plink_frame_tx(sdata
, PLINK_CLOSE
, sta
->sta
.addr
, llid
,
675 spin_unlock_bh(&sta
->lock
);
676 mesh_plink_frame_tx(sdata
, PLINK_CONFIRM
, sta
->sta
.addr
, llid
,
680 del_timer(&sta
->plink_timer
);
681 sta
->plink_state
= PLINK_ESTAB
;
682 spin_unlock_bh(&sta
->lock
);
683 mesh_plink_inc_estab_count(sdata
);
684 ieee80211_bss_info_change_notify(sdata
, BSS_CHANGED_BEACON
);
685 mpl_dbg("Mesh plink with %pM ESTABLISHED\n",
689 spin_unlock_bh(&sta
->lock
);
698 reason
= cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION
);
701 reason
= cpu_to_le16(MESH_CLOSE_RCVD
);
702 sta
->reason
= reason
;
703 sta
->plink_state
= PLINK_HOLDING
;
704 if (!mod_plink_timer(sta
,
705 dot11MeshHoldingTimeout(sdata
)))
706 sta
->ignore_plink_timer
= true;
709 spin_unlock_bh(&sta
->lock
);
710 mesh_plink_frame_tx(sdata
, PLINK_CLOSE
, sta
->sta
.addr
, llid
,
714 del_timer(&sta
->plink_timer
);
715 sta
->plink_state
= PLINK_ESTAB
;
716 spin_unlock_bh(&sta
->lock
);
717 mesh_plink_inc_estab_count(sdata
);
718 ieee80211_bss_info_change_notify(sdata
, BSS_CHANGED_BEACON
);
719 mpl_dbg("Mesh plink with %pM ESTABLISHED\n",
721 mesh_plink_frame_tx(sdata
, PLINK_CONFIRM
, sta
->sta
.addr
, llid
,
725 spin_unlock_bh(&sta
->lock
);
733 reason
= cpu_to_le16(MESH_CLOSE_RCVD
);
734 sta
->reason
= reason
;
735 deactivated
= __mesh_plink_deactivate(sta
);
736 sta
->plink_state
= PLINK_HOLDING
;
738 mod_plink_timer(sta
, dot11MeshHoldingTimeout(sdata
));
739 spin_unlock_bh(&sta
->lock
);
741 ieee80211_bss_info_change_notify(sdata
, BSS_CHANGED_BEACON
);
742 mesh_plink_frame_tx(sdata
, PLINK_CLOSE
, sta
->sta
.addr
, llid
,
747 spin_unlock_bh(&sta
->lock
);
748 mesh_plink_frame_tx(sdata
, PLINK_CONFIRM
, sta
->sta
.addr
, llid
,
752 spin_unlock_bh(&sta
->lock
);
759 if (del_timer(&sta
->plink_timer
))
760 sta
->ignore_plink_timer
= 1;
761 mesh_plink_fsm_restart(sta
);
762 spin_unlock_bh(&sta
->lock
);
769 reason
= sta
->reason
;
770 spin_unlock_bh(&sta
->lock
);
771 mesh_plink_frame_tx(sdata
, PLINK_CLOSE
, sta
->sta
.addr
,
775 spin_unlock_bh(&sta
->lock
);
779 /* should not get here, PLINK_BLOCKED is dealt with at the
780 * beginning of the function
782 spin_unlock_bh(&sta
->lock
);