1 // SPDX-License-Identifier: GPL-2.0-only
2 /******************************************************************************
4 Copyright(c) 2003 - 2005 Intel Corporation. All rights reserved.
8 Intel Linux Wireless <ilw@linux.intel.com>
9 Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
11 ******************************************************************************/
12 #include <linux/compiler.h>
13 #include <linux/errno.h>
14 #include <linux/if_arp.h>
15 #include <linux/in6.h>
18 #include <linux/kernel.h>
19 #include <linux/module.h>
20 #include <linux/netdevice.h>
21 #include <linux/proc_fs.h>
22 #include <linux/skbuff.h>
23 #include <linux/slab.h>
24 #include <linux/tcp.h>
25 #include <linux/types.h>
26 #include <linux/wireless.h>
27 #include <linux/etherdevice.h>
28 #include <linux/uaccess.h>
36 ,-------------------------------------------------------------------.
37 Bytes | 2 | 2 | 6 | 6 | 6 | 2 | 0..2312 | 4 |
38 |------|------|---------|---------|---------|------|---------|------|
39 Desc. | ctrl | dura | DA/RA | TA | SA | Sequ | Frame | fcs |
40 | | tion | (BSSID) | | | ence | data | |
41 `--------------------------------------------------| |------'
42 Total: 28 non-data bytes `----.----'
44 .- 'Frame data' expands, if WEP enabled, to <----------'
47 ,-----------------------.
48 Bytes | 4 | 0-2296 | 4 |
49 |-----|-----------|-----|
50 Desc. | IV | Encrypted | ICV |
55 .- 'Encrypted Packet' expands to
58 ,---------------------------------------------------.
59 Bytes | 1 | 1 | 1 | 3 | 2 | 0-2304 |
60 |------|------|---------|----------|------|---------|
61 Desc. | SNAP | SNAP | Control |Eth Tunnel| Type | IP |
62 | DSAP | SSAP | | | | Packet |
63 | 0xAA | 0xAA |0x03 (UI)|0x00-00-F8| | |
64 `----------------------------------------------------
65 Total: 8 non-data bytes
67 802.3 Ethernet Data Frame
69 ,-----------------------------------------.
70 Bytes | 6 | 6 | 2 | Variable | 4 |
71 |-------|-------|------|-----------|------|
72 Desc. | Dest. | Source| Type | IP Packet | fcs |
74 `-----------------------------------------'
75 Total: 18 non-data bytes
77 In the event that fragmentation is required, the incoming payload is split into
78 N parts of size ieee->fts. The first fragment contains the SNAP header and the
79 remaining packets are just data.
81 If encryption is enabled, each fragment payload size is reduced by enough space
82 to add the prefix and postfix (IV and ICV totalling 8 bytes in the case of WEP)
83 So if you have 1500 bytes of payload with ieee->fts set to 500 without
84 encryption it will take 3 frames. With WEP it will take 4 frames as the
85 payload of each frame is reduced to 492 bytes.
91 * | ETHERNET HEADER ,-<-- PAYLOAD
92 * | | 14 bytes from skb->data
93 * | 2 bytes for Type --> ,T. | (sizeof ethhdr)
95 * |,-Dest.--. ,--Src.---. | | |
96 * | 6 bytes| | 6 bytes | | | |
99 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5
102 * | | | | `T' <---- 2 bytes for Type
104 * | | '---SNAP--' <-------- 6 bytes for SNAP
106 * `-IV--' <-------------------- 4 bytes for IV (WEP)
112 static u8 P802_1H_OUI
[P80211_OUI_LEN
] = { 0x00, 0x00, 0xf8 };
113 static u8 RFC1042_OUI
[P80211_OUI_LEN
] = { 0x00, 0x00, 0x00 };
115 static int libipw_copy_snap(u8
* data
, __be16 h_proto
)
117 struct libipw_snap_hdr
*snap
;
120 snap
= (struct libipw_snap_hdr
*)data
;
125 if (h_proto
== htons(ETH_P_AARP
) || h_proto
== htons(ETH_P_IPX
))
129 snap
->oui
[0] = oui
[0];
130 snap
->oui
[1] = oui
[1];
131 snap
->oui
[2] = oui
[2];
133 memcpy(data
+ SNAP_SIZE
, &h_proto
, sizeof(u16
));
135 return SNAP_SIZE
+ sizeof(u16
);
138 static int libipw_encrypt_fragment(struct libipw_device
*ieee
,
139 struct sk_buff
*frag
, int hdr_len
)
141 struct lib80211_crypt_data
*crypt
=
142 ieee
->crypt_info
.crypt
[ieee
->crypt_info
.tx_keyidx
];
148 /* To encrypt, frame format is:
149 * IV (4 bytes), clear payload (including SNAP), ICV (4 bytes) */
150 atomic_inc(&crypt
->refcnt
);
152 if (crypt
->ops
&& crypt
->ops
->encrypt_mpdu
)
153 res
= crypt
->ops
->encrypt_mpdu(frag
, hdr_len
, crypt
->priv
);
155 atomic_dec(&crypt
->refcnt
);
157 printk(KERN_INFO
"%s: Encryption failed: len=%d.\n",
158 ieee
->dev
->name
, frag
->len
);
159 ieee
->ieee_stats
.tx_discards
++;
166 void libipw_txb_free(struct libipw_txb
*txb
)
171 for (i
= 0; i
< txb
->nr_frags
; i
++)
172 if (txb
->fragments
[i
])
173 dev_kfree_skb_any(txb
->fragments
[i
]);
177 static struct libipw_txb
*libipw_alloc_txb(int nr_frags
, int txb_size
,
178 int headroom
, gfp_t gfp_mask
)
180 struct libipw_txb
*txb
;
182 txb
= kmalloc(sizeof(struct libipw_txb
) + (sizeof(u8
*) * nr_frags
),
187 memset(txb
, 0, sizeof(struct libipw_txb
));
188 txb
->nr_frags
= nr_frags
;
189 txb
->frag_size
= txb_size
;
191 for (i
= 0; i
< nr_frags
; i
++) {
192 txb
->fragments
[i
] = __dev_alloc_skb(txb_size
+ headroom
,
194 if (unlikely(!txb
->fragments
[i
])) {
198 skb_reserve(txb
->fragments
[i
], headroom
);
200 if (unlikely(i
!= nr_frags
)) {
202 dev_kfree_skb_any(txb
->fragments
[i
--]);
209 static int libipw_classify(struct sk_buff
*skb
)
214 eth
= (struct ethhdr
*)skb
->data
;
215 if (eth
->h_proto
!= htons(ETH_P_IP
))
219 switch (ip
->tos
& 0xfc) {
239 /* Incoming skb is converted to a txb which consists of
240 * a block of 802.11 fragment packets (stored as skbs) */
241 netdev_tx_t
libipw_xmit(struct sk_buff
*skb
, struct net_device
*dev
)
243 struct libipw_device
*ieee
= netdev_priv(dev
);
244 struct libipw_txb
*txb
= NULL
;
245 struct libipw_hdr_3addrqos
*frag_hdr
;
246 int i
, bytes_per_frag
, nr_frags
, bytes_last_frag
, frag_size
,
249 int encrypt
, host_encrypt
, host_encrypt_msdu
;
251 int bytes
, fc
, hdr_len
;
252 struct sk_buff
*skb_frag
;
253 struct libipw_hdr_3addrqos header
= {/* Ensure zero initialized */
258 u8 dest
[ETH_ALEN
], src
[ETH_ALEN
];
259 struct lib80211_crypt_data
*crypt
;
260 int priority
= skb
->priority
;
263 if (ieee
->is_queue_full
&& (*ieee
->is_queue_full
) (dev
, priority
))
264 return NETDEV_TX_BUSY
;
266 spin_lock_irqsave(&ieee
->lock
, flags
);
268 /* If there is no driver handler to take the TXB, dont' bother
270 if (!ieee
->hard_start_xmit
) {
271 printk(KERN_WARNING
"%s: No xmit handler.\n", ieee
->dev
->name
);
275 if (unlikely(skb
->len
< SNAP_SIZE
+ sizeof(u16
))) {
276 printk(KERN_WARNING
"%s: skb too small (%d).\n",
277 ieee
->dev
->name
, skb
->len
);
281 ether_type
= ((struct ethhdr
*)skb
->data
)->h_proto
;
283 crypt
= ieee
->crypt_info
.crypt
[ieee
->crypt_info
.tx_keyidx
];
285 encrypt
= !(ether_type
== htons(ETH_P_PAE
) && ieee
->ieee802_1x
) &&
288 host_encrypt
= ieee
->host_encrypt
&& encrypt
&& crypt
;
289 host_encrypt_msdu
= ieee
->host_encrypt_msdu
&& encrypt
&& crypt
;
291 if (!encrypt
&& ieee
->ieee802_1x
&&
292 ieee
->drop_unencrypted
&& ether_type
!= htons(ETH_P_PAE
)) {
293 dev
->stats
.tx_dropped
++;
297 /* Save source and destination addresses */
298 skb_copy_from_linear_data(skb
, dest
, ETH_ALEN
);
299 skb_copy_from_linear_data_offset(skb
, ETH_ALEN
, src
, ETH_ALEN
);
302 fc
= IEEE80211_FTYPE_DATA
| IEEE80211_STYPE_DATA
|
303 IEEE80211_FCTL_PROTECTED
;
305 fc
= IEEE80211_FTYPE_DATA
| IEEE80211_STYPE_DATA
;
307 if (ieee
->iw_mode
== IW_MODE_INFRA
) {
308 fc
|= IEEE80211_FCTL_TODS
;
309 /* To DS: Addr1 = BSSID, Addr2 = SA, Addr3 = DA */
310 memcpy(header
.addr1
, ieee
->bssid
, ETH_ALEN
);
311 memcpy(header
.addr2
, src
, ETH_ALEN
);
312 memcpy(header
.addr3
, dest
, ETH_ALEN
);
313 } else if (ieee
->iw_mode
== IW_MODE_ADHOC
) {
314 /* not From/To DS: Addr1 = DA, Addr2 = SA, Addr3 = BSSID */
315 memcpy(header
.addr1
, dest
, ETH_ALEN
);
316 memcpy(header
.addr2
, src
, ETH_ALEN
);
317 memcpy(header
.addr3
, ieee
->bssid
, ETH_ALEN
);
319 hdr_len
= LIBIPW_3ADDR_LEN
;
321 if (ieee
->is_qos_active
&& ieee
->is_qos_active(dev
, skb
)) {
322 fc
|= IEEE80211_STYPE_QOS_DATA
;
325 skb
->priority
= libipw_classify(skb
);
326 header
.qos_ctl
|= cpu_to_le16(skb
->priority
& LIBIPW_QCTL_TID
);
328 header
.frame_ctl
= cpu_to_le16(fc
);
330 /* Advance the SKB to the start of the payload */
331 skb_pull(skb
, sizeof(struct ethhdr
));
333 /* Determine total amount of storage required for TXB packets */
334 bytes
= skb
->len
+ SNAP_SIZE
+ sizeof(u16
);
336 /* Encrypt msdu first on the whole data packet. */
337 if ((host_encrypt
|| host_encrypt_msdu
) &&
338 crypt
&& crypt
->ops
&& crypt
->ops
->encrypt_msdu
) {
340 int len
= bytes
+ hdr_len
+ crypt
->ops
->extra_msdu_prefix_len
+
341 crypt
->ops
->extra_msdu_postfix_len
;
342 struct sk_buff
*skb_new
= dev_alloc_skb(len
);
344 if (unlikely(!skb_new
))
347 skb_reserve(skb_new
, crypt
->ops
->extra_msdu_prefix_len
);
348 skb_put_data(skb_new
, &header
, hdr_len
);
350 libipw_copy_snap(skb_put(skb_new
, SNAP_SIZE
+ sizeof(u16
)),
352 skb_copy_from_linear_data(skb
, skb_put(skb_new
, skb
->len
), skb
->len
);
353 res
= crypt
->ops
->encrypt_msdu(skb_new
, hdr_len
, crypt
->priv
);
355 LIBIPW_ERROR("msdu encryption failed\n");
356 dev_kfree_skb_any(skb_new
);
359 dev_kfree_skb_any(skb
);
361 bytes
+= crypt
->ops
->extra_msdu_prefix_len
+
362 crypt
->ops
->extra_msdu_postfix_len
;
363 skb_pull(skb
, hdr_len
);
366 if (host_encrypt
|| ieee
->host_open_frag
) {
367 /* Determine fragmentation size based on destination (multicast
368 * and broadcast are not fragmented) */
369 if (is_multicast_ether_addr(dest
) ||
370 is_broadcast_ether_addr(dest
))
371 frag_size
= MAX_FRAG_THRESHOLD
;
373 frag_size
= ieee
->fts
;
375 /* Determine amount of payload per fragment. Regardless of if
376 * this stack is providing the full 802.11 header, one will
377 * eventually be affixed to this fragment -- so we must account
378 * for it when determining the amount of payload space. */
379 bytes_per_frag
= frag_size
- hdr_len
;
381 (CFG_LIBIPW_COMPUTE_FCS
| CFG_LIBIPW_RESERVE_FCS
))
382 bytes_per_frag
-= LIBIPW_FCS_LEN
;
384 /* Each fragment may need to have room for encryption
387 bytes_per_frag
-= crypt
->ops
->extra_mpdu_prefix_len
+
388 crypt
->ops
->extra_mpdu_postfix_len
;
390 /* Number of fragments is the total
391 * bytes_per_frag / payload_per_fragment */
392 nr_frags
= bytes
/ bytes_per_frag
;
393 bytes_last_frag
= bytes
% bytes_per_frag
;
397 bytes_last_frag
= bytes_per_frag
;
400 bytes_per_frag
= bytes_last_frag
= bytes
;
401 frag_size
= bytes
+ hdr_len
;
404 rts_required
= (frag_size
> ieee
->rts
405 && ieee
->config
& CFG_LIBIPW_RTS
);
409 /* When we allocate the TXB we allocate enough space for the reserve
410 * and full fragment bytes (bytes_per_frag doesn't include prefix,
411 * postfix, header, FCS, etc.) */
412 txb
= libipw_alloc_txb(nr_frags
, frag_size
,
413 ieee
->tx_headroom
, GFP_ATOMIC
);
414 if (unlikely(!txb
)) {
415 printk(KERN_WARNING
"%s: Could not allocate TXB\n",
419 txb
->encrypted
= encrypt
;
421 txb
->payload_size
= frag_size
* (nr_frags
- 1) +
424 txb
->payload_size
= bytes
;
427 skb_frag
= txb
->fragments
[0];
428 frag_hdr
= skb_put(skb_frag
, hdr_len
);
431 * Set header frame_ctl to the RTS.
434 cpu_to_le16(IEEE80211_FTYPE_CTL
| IEEE80211_STYPE_RTS
);
435 memcpy(frag_hdr
, &header
, hdr_len
);
438 * Restore header frame_ctl to the original data setting.
440 header
.frame_ctl
= cpu_to_le16(fc
);
443 (CFG_LIBIPW_COMPUTE_FCS
| CFG_LIBIPW_RESERVE_FCS
))
444 skb_put(skb_frag
, 4);
446 txb
->rts_included
= 1;
451 for (; i
< nr_frags
; i
++) {
452 skb_frag
= txb
->fragments
[i
];
455 skb_reserve(skb_frag
,
456 crypt
->ops
->extra_mpdu_prefix_len
);
458 frag_hdr
= skb_put_data(skb_frag
, &header
, hdr_len
);
460 /* If this is not the last fragment, then add the MOREFRAGS
461 * bit to the frame control */
462 if (i
!= nr_frags
- 1) {
463 frag_hdr
->frame_ctl
=
464 cpu_to_le16(fc
| IEEE80211_FCTL_MOREFRAGS
);
465 bytes
= bytes_per_frag
;
467 /* The last fragment takes the remaining length */
468 bytes
= bytes_last_frag
;
471 if (i
== 0 && !snapped
) {
472 libipw_copy_snap(skb_put
473 (skb_frag
, SNAP_SIZE
+ sizeof(u16
)),
475 bytes
-= SNAP_SIZE
+ sizeof(u16
);
478 skb_copy_from_linear_data(skb
, skb_put(skb_frag
, bytes
), bytes
);
480 /* Advance the SKB... */
481 skb_pull(skb
, bytes
);
483 /* Encryption routine will move the header forward in order
484 * to insert the IV between the header and the payload */
486 libipw_encrypt_fragment(ieee
, skb_frag
, hdr_len
);
489 (CFG_LIBIPW_COMPUTE_FCS
| CFG_LIBIPW_RESERVE_FCS
))
490 skb_put(skb_frag
, 4);
494 spin_unlock_irqrestore(&ieee
->lock
, flags
);
496 dev_kfree_skb_any(skb
);
499 netdev_tx_t ret
= (*ieee
->hard_start_xmit
)(txb
, dev
, priority
);
500 if (ret
== NETDEV_TX_OK
) {
501 dev
->stats
.tx_packets
++;
502 dev
->stats
.tx_bytes
+= txb
->payload_size
;
506 libipw_txb_free(txb
);
512 spin_unlock_irqrestore(&ieee
->lock
, flags
);
513 netif_stop_queue(dev
);
514 dev
->stats
.tx_errors
++;
515 return NETDEV_TX_BUSY
;
517 EXPORT_SYMBOL(libipw_xmit
);
519 EXPORT_SYMBOL(libipw_txb_free
);