userns: don't leak root user
[wrt350n-kernel.git] / net / ax25 / ax25_ip.c
blob930e4918037f51031b6e2839c05b4163d29845b2
1 /*
2 * This program is free software; you can redistribute it and/or modify
3 * it under the terms of the GNU General Public License as published by
4 * the Free Software Foundation; either version 2 of the License, or
5 * (at your option) any later version.
7 * Copyright (C) Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
8 */
9 #include <linux/errno.h>
10 #include <linux/types.h>
11 #include <linux/socket.h>
12 #include <linux/in.h>
13 #include <linux/kernel.h>
14 #include <linux/module.h>
15 #include <linux/timer.h>
16 #include <linux/string.h>
17 #include <linux/sockios.h>
18 #include <linux/net.h>
19 #include <net/ax25.h>
20 #include <linux/inet.h>
21 #include <linux/netdevice.h>
22 #include <linux/if_arp.h>
23 #include <linux/skbuff.h>
24 #include <net/sock.h>
25 #include <asm/uaccess.h>
26 #include <asm/system.h>
27 #include <linux/fcntl.h>
28 #include <linux/termios.h> /* For TIOCINQ/OUTQ */
29 #include <linux/mm.h>
30 #include <linux/interrupt.h>
31 #include <linux/notifier.h>
32 #include <linux/proc_fs.h>
33 #include <linux/stat.h>
34 #include <linux/netfilter.h>
35 #include <linux/sysctl.h>
36 #include <net/ip.h>
37 #include <net/arp.h>
40 * IP over AX.25 encapsulation.
44 * Shove an AX.25 UI header on an IP packet and handle ARP
47 #ifdef CONFIG_INET
49 int ax25_hard_header(struct sk_buff *skb, struct net_device *dev, unsigned short type, void *daddr, void *saddr, unsigned len)
51 unsigned char *buff;
53 /* they sometimes come back to us... */
54 if (type == ETH_P_AX25)
55 return 0;
57 /* header is an AX.25 UI frame from us to them */
58 buff = skb_push(skb, AX25_HEADER_LEN);
59 *buff++ = 0x00; /* KISS DATA */
61 if (daddr != NULL)
62 memcpy(buff, daddr, dev->addr_len); /* Address specified */
64 buff[6] &= ~AX25_CBIT;
65 buff[6] &= ~AX25_EBIT;
66 buff[6] |= AX25_SSSID_SPARE;
67 buff += AX25_ADDR_LEN;
69 if (saddr != NULL)
70 memcpy(buff, saddr, dev->addr_len);
71 else
72 memcpy(buff, dev->dev_addr, dev->addr_len);
74 buff[6] &= ~AX25_CBIT;
75 buff[6] |= AX25_EBIT;
76 buff[6] |= AX25_SSSID_SPARE;
77 buff += AX25_ADDR_LEN;
79 *buff++ = AX25_UI; /* UI */
81 /* Append a suitable AX.25 PID */
82 switch (type) {
83 case ETH_P_IP:
84 *buff++ = AX25_P_IP;
85 break;
86 case ETH_P_ARP:
87 *buff++ = AX25_P_ARP;
88 break;
89 default:
90 printk(KERN_ERR "AX.25: ax25_hard_header - wrong protocol type 0x%2.2x\n", type);
91 *buff++ = 0;
92 break;
95 if (daddr != NULL)
96 return AX25_HEADER_LEN;
98 return -AX25_HEADER_LEN; /* Unfinished header */
101 int ax25_rebuild_header(struct sk_buff *skb)
103 struct sk_buff *ourskb;
104 unsigned char *bp = skb->data;
105 ax25_route *route;
106 struct net_device *dev = NULL;
107 ax25_address *src, *dst;
108 ax25_digi *digipeat = NULL;
109 ax25_dev *ax25_dev;
110 ax25_cb *ax25;
111 char ip_mode = ' ';
113 dst = (ax25_address *)(bp + 1);
114 src = (ax25_address *)(bp + 8);
116 if (arp_find(bp + 1, skb))
117 return 1;
119 route = ax25_get_route(dst, NULL);
120 if (route) {
121 digipeat = route->digipeat;
122 dev = route->dev;
123 ip_mode = route->ip_mode;
126 if (dev == NULL)
127 dev = skb->dev;
129 if ((ax25_dev = ax25_dev_ax25dev(dev)) == NULL) {
130 goto put;
133 if (bp[16] == AX25_P_IP) {
134 if (ip_mode == 'V' || (ip_mode == ' ' && ax25_dev->values[AX25_VALUES_IPDEFMODE])) {
136 * We copy the buffer and release the original thereby
137 * keeping it straight
139 * Note: we report 1 back so the caller will
140 * not feed the frame direct to the physical device
141 * We don't want that to happen. (It won't be upset
142 * as we have pulled the frame from the queue by
143 * freeing it).
145 * NB: TCP modifies buffers that are still
146 * on a device queue, thus we use skb_copy()
147 * instead of using skb_clone() unless this
148 * gets fixed.
151 ax25_address src_c;
152 ax25_address dst_c;
154 if ((ourskb = skb_copy(skb, GFP_ATOMIC)) == NULL) {
155 kfree_skb(skb);
156 goto put;
159 if (skb->sk != NULL)
160 skb_set_owner_w(ourskb, skb->sk);
162 kfree_skb(skb);
163 /* dl9sau: bugfix
164 * after kfree_skb(), dst and src which were pointer
165 * to bp which is part of skb->data would not be valid
166 * anymore hope that after skb_pull(ourskb, ..) our
167 * dsc_c and src_c will not become invalid
169 bp = ourskb->data;
170 dst_c = *(ax25_address *)(bp + 1);
171 src_c = *(ax25_address *)(bp + 8);
173 skb_pull(ourskb, AX25_HEADER_LEN - 1); /* Keep PID */
174 skb_reset_network_header(ourskb);
176 ax25=ax25_send_frame(
177 ourskb,
178 ax25_dev->values[AX25_VALUES_PACLEN],
179 &src_c,
180 &dst_c, digipeat, dev);
181 if (ax25) {
182 ax25_cb_put(ax25);
184 goto put;
188 bp[7] &= ~AX25_CBIT;
189 bp[7] &= ~AX25_EBIT;
190 bp[7] |= AX25_SSSID_SPARE;
192 bp[14] &= ~AX25_CBIT;
193 bp[14] |= AX25_EBIT;
194 bp[14] |= AX25_SSSID_SPARE;
196 skb_pull(skb, AX25_KISS_HEADER_LEN);
198 if (digipeat != NULL) {
199 if ((ourskb = ax25_rt_build_path(skb, src, dst, route->digipeat)) == NULL) {
200 kfree_skb(skb);
201 goto put;
204 skb = ourskb;
207 ax25_queue_xmit(skb, dev);
209 put:
210 if (route)
211 ax25_put_route(route);
213 return 1;
216 #else /* INET */
218 int ax25_hard_header(struct sk_buff *skb, struct net_device *dev, unsigned short type, void *daddr, void *saddr, unsigned len)
220 return -AX25_HEADER_LEN;
223 int ax25_rebuild_header(struct sk_buff *skb)
225 return 1;
228 #endif
230 EXPORT_SYMBOL(ax25_hard_header);
231 EXPORT_SYMBOL(ax25_rebuild_header);