blob: d048ec6dab12a9b7ef329be5ffef9b0b4aaf282e [file] [log] [blame]
rjw1f884582022-01-06 17:20:42 +08001/*
2 * net/tipc/msg.c: TIPC message header routines
3 *
4 * Copyright (c) 2000-2006, 2014-2015, Ericsson AB
5 * Copyright (c) 2005, 2010-2011, Wind River Systems
6 * All rights reserved.
7 *
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions are met:
10 *
11 * 1. Redistributions of source code must retain the above copyright
12 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
16 * 3. Neither the names of the copyright holders nor the names of its
17 * contributors may be used to endorse or promote products derived from
18 * this software without specific prior written permission.
19 *
20 * Alternatively, this software may be distributed under the terms of the
21 * GNU General Public License ("GPL") version 2 as published by the Free
22 * Software Foundation.
23 *
24 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
25 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
27 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
28 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
29 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
30 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
31 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
32 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
33 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
34 * POSSIBILITY OF SUCH DAMAGE.
35 */
36
37#include <net/sock.h>
38#include "core.h"
39#include "msg.h"
40#include "addr.h"
41#include "name_table.h"
42
43#define MAX_FORWARD_SIZE 1024
44#define BUF_HEADROOM (LL_MAX_HEADER + 48)
45#define BUF_TAILROOM 16
46
47static unsigned int align(unsigned int i)
48{
49 return (i + 3) & ~3u;
50}
51
52/**
53 * tipc_buf_acquire - creates a TIPC message buffer
54 * @size: message size (including TIPC header)
55 *
56 * Returns a new buffer with data pointers set to the specified size.
57 *
58 * NOTE: Headroom is reserved to allow prepending of a data link header.
59 * There may also be unrequested tailroom present at the buffer's end.
60 */
61struct sk_buff *tipc_buf_acquire(u32 size, gfp_t gfp)
62{
63 struct sk_buff *skb;
64 unsigned int buf_size = (BUF_HEADROOM + size + 3) & ~3u;
65
66 skb = alloc_skb_fclone(buf_size, gfp);
67 if (skb) {
68 skb_reserve(skb, BUF_HEADROOM);
69 skb_put(skb, size);
70 skb->next = NULL;
71 }
72 return skb;
73}
74
75void tipc_msg_init(u32 own_node, struct tipc_msg *m, u32 user, u32 type,
76 u32 hsize, u32 dnode)
77{
78 memset(m, 0, hsize);
79 msg_set_version(m);
80 msg_set_user(m, user);
81 msg_set_hdr_sz(m, hsize);
82 msg_set_size(m, hsize);
83 msg_set_prevnode(m, own_node);
84 msg_set_type(m, type);
85 if (hsize > SHORT_H_SIZE) {
86 msg_set_orignode(m, own_node);
87 msg_set_destnode(m, dnode);
88 }
89}
90
91struct sk_buff *tipc_msg_create(uint user, uint type,
92 uint hdr_sz, uint data_sz, u32 dnode,
93 u32 onode, u32 dport, u32 oport, int errcode)
94{
95 struct tipc_msg *msg;
96 struct sk_buff *buf;
97
98 buf = tipc_buf_acquire(hdr_sz + data_sz, GFP_ATOMIC);
99 if (unlikely(!buf))
100 return NULL;
101
102 msg = buf_msg(buf);
103 tipc_msg_init(onode, msg, user, type, hdr_sz, dnode);
104 msg_set_size(msg, hdr_sz + data_sz);
105 msg_set_origport(msg, oport);
106 msg_set_destport(msg, dport);
107 msg_set_errcode(msg, errcode);
108 if (hdr_sz > SHORT_H_SIZE) {
109 msg_set_orignode(msg, onode);
110 msg_set_destnode(msg, dnode);
111 }
112 return buf;
113}
114
115/* tipc_buf_append(): Append a buffer to the fragment list of another buffer
116 * @*headbuf: in: NULL for first frag, otherwise value returned from prev call
117 * out: set when successful non-complete reassembly, otherwise NULL
118 * @*buf: in: the buffer to append. Always defined
119 * out: head buf after successful complete reassembly, otherwise NULL
120 * Returns 1 when reassembly complete, otherwise 0
121 */
122int tipc_buf_append(struct sk_buff **headbuf, struct sk_buff **buf)
123{
124 struct sk_buff *head = *headbuf;
125 struct sk_buff *frag = *buf;
126 struct sk_buff *tail = NULL;
127 struct tipc_msg *msg;
128 u32 fragid;
129 int delta;
130 bool headstolen;
131
132 if (!frag)
133 goto err;
134
135 msg = buf_msg(frag);
136 fragid = msg_type(msg);
137 frag->next = NULL;
138 skb_pull(frag, msg_hdr_sz(msg));
139
140 if (fragid == FIRST_FRAGMENT) {
141 if (unlikely(head))
142 goto err;
143 frag = skb_unshare(frag, GFP_ATOMIC);
144 if (unlikely(!frag))
145 goto err;
146 head = *headbuf = frag;
147 *buf = NULL;
148 TIPC_SKB_CB(head)->tail = NULL;
149 if (skb_is_nonlinear(head)) {
150 skb_walk_frags(head, tail) {
151 TIPC_SKB_CB(head)->tail = tail;
152 }
153 } else {
154 skb_frag_list_init(head);
155 }
156 return 0;
157 }
158
159 if (!head)
160 goto err;
161
162 if (skb_try_coalesce(head, frag, &headstolen, &delta)) {
163 kfree_skb_partial(frag, headstolen);
164 } else {
165 tail = TIPC_SKB_CB(head)->tail;
166 if (!skb_has_frag_list(head))
167 skb_shinfo(head)->frag_list = frag;
168 else
169 tail->next = frag;
170 head->truesize += frag->truesize;
171 head->data_len += frag->len;
172 head->len += frag->len;
173 TIPC_SKB_CB(head)->tail = frag;
174 }
175
176 if (fragid == LAST_FRAGMENT) {
177 TIPC_SKB_CB(head)->validated = false;
178 if (unlikely(!tipc_msg_validate(head)))
179 goto err;
180 *buf = head;
181 TIPC_SKB_CB(head)->tail = NULL;
182 *headbuf = NULL;
183 return 1;
184 }
185 *buf = NULL;
186 return 0;
187err:
188 kfree_skb(*buf);
189 kfree_skb(*headbuf);
190 *buf = *headbuf = NULL;
191 return 0;
192}
193
194/* tipc_msg_validate - validate basic format of received message
195 *
196 * This routine ensures a TIPC message has an acceptable header, and at least
197 * as much data as the header indicates it should. The routine also ensures
198 * that the entire message header is stored in the main fragment of the message
199 * buffer, to simplify future access to message header fields.
200 *
201 * Note: Having extra info present in the message header or data areas is OK.
202 * TIPC will ignore the excess, under the assumption that it is optional info
203 * introduced by a later release of the protocol.
204 */
205bool tipc_msg_validate(struct sk_buff *skb)
206{
207 struct tipc_msg *msg;
208 int msz, hsz;
209
210 if (unlikely(TIPC_SKB_CB(skb)->validated))
211 return true;
212 if (unlikely(!pskb_may_pull(skb, MIN_H_SIZE)))
213 return false;
214
215 hsz = msg_hdr_sz(buf_msg(skb));
216 if (unlikely(hsz < MIN_H_SIZE) || (hsz > MAX_H_SIZE))
217 return false;
218 if (unlikely(!pskb_may_pull(skb, hsz)))
219 return false;
220
221 msg = buf_msg(skb);
222 if (unlikely(msg_version(msg) != TIPC_VERSION))
223 return false;
224
225 msz = msg_size(msg);
226 if (unlikely(msz < hsz))
227 return false;
228 if (unlikely((msz - hsz) > TIPC_MAX_USER_MSG_SIZE))
229 return false;
230 if (unlikely(skb->len < msz))
231 return false;
232
233 TIPC_SKB_CB(skb)->validated = true;
234 return true;
235}
236
237/**
238 * tipc_msg_build - create buffer chain containing specified header and data
239 * @mhdr: Message header, to be prepended to data
240 * @m: User message
241 * @dsz: Total length of user data
242 * @pktmax: Max packet size that can be used
243 * @list: Buffer or chain of buffers to be returned to caller
244 *
245 * Returns message data size or errno: -ENOMEM, -EFAULT
246 */
247int tipc_msg_build(struct tipc_msg *mhdr, struct msghdr *m,
248 int offset, int dsz, int pktmax, struct sk_buff_head *list)
249{
250 int mhsz = msg_hdr_sz(mhdr);
251 int msz = mhsz + dsz;
252 int pktno = 1;
253 int pktsz;
254 int pktrem = pktmax;
255 int drem = dsz;
256 struct tipc_msg pkthdr;
257 struct sk_buff *skb;
258 char *pktpos;
259 int rc;
260
261 msg_set_size(mhdr, msz);
262
263 /* No fragmentation needed? */
264 if (likely(msz <= pktmax)) {
265 skb = tipc_buf_acquire(msz, GFP_KERNEL);
266 if (unlikely(!skb))
267 return -ENOMEM;
268 skb_orphan(skb);
269 __skb_queue_tail(list, skb);
270 skb_copy_to_linear_data(skb, mhdr, mhsz);
271 pktpos = skb->data + mhsz;
272 if (copy_from_iter_full(pktpos, dsz, &m->msg_iter))
273 return dsz;
274 rc = -EFAULT;
275 goto error;
276 }
277
278 /* Prepare reusable fragment header */
279 tipc_msg_init(msg_prevnode(mhdr), &pkthdr, MSG_FRAGMENTER,
280 FIRST_FRAGMENT, INT_H_SIZE, msg_destnode(mhdr));
281 msg_set_size(&pkthdr, pktmax);
282 msg_set_fragm_no(&pkthdr, pktno);
283 msg_set_importance(&pkthdr, msg_importance(mhdr));
284
285 /* Prepare first fragment */
286 skb = tipc_buf_acquire(pktmax, GFP_KERNEL);
287 if (!skb)
288 return -ENOMEM;
289 skb_orphan(skb);
290 __skb_queue_tail(list, skb);
291 pktpos = skb->data;
292 skb_copy_to_linear_data(skb, &pkthdr, INT_H_SIZE);
293 pktpos += INT_H_SIZE;
294 pktrem -= INT_H_SIZE;
295 skb_copy_to_linear_data_offset(skb, INT_H_SIZE, mhdr, mhsz);
296 pktpos += mhsz;
297 pktrem -= mhsz;
298
299 do {
300 if (drem < pktrem)
301 pktrem = drem;
302
303 if (!copy_from_iter_full(pktpos, pktrem, &m->msg_iter)) {
304 rc = -EFAULT;
305 goto error;
306 }
307 drem -= pktrem;
308
309 if (!drem)
310 break;
311
312 /* Prepare new fragment: */
313 if (drem < (pktmax - INT_H_SIZE))
314 pktsz = drem + INT_H_SIZE;
315 else
316 pktsz = pktmax;
317 skb = tipc_buf_acquire(pktsz, GFP_KERNEL);
318 if (!skb) {
319 rc = -ENOMEM;
320 goto error;
321 }
322 skb_orphan(skb);
323 __skb_queue_tail(list, skb);
324 msg_set_type(&pkthdr, FRAGMENT);
325 msg_set_size(&pkthdr, pktsz);
326 msg_set_fragm_no(&pkthdr, ++pktno);
327 skb_copy_to_linear_data(skb, &pkthdr, INT_H_SIZE);
328 pktpos = skb->data + INT_H_SIZE;
329 pktrem = pktsz - INT_H_SIZE;
330
331 } while (1);
332 msg_set_type(buf_msg(skb), LAST_FRAGMENT);
333 return dsz;
334error:
335 __skb_queue_purge(list);
336 __skb_queue_head_init(list);
337 return rc;
338}
339
340/**
341 * tipc_msg_bundle(): Append contents of a buffer to tail of an existing one
342 * @skb: the buffer to append to ("bundle")
343 * @msg: message to be appended
344 * @mtu: max allowable size for the bundle buffer
345 * Consumes buffer if successful
346 * Returns true if bundling could be performed, otherwise false
347 */
348bool tipc_msg_bundle(struct sk_buff *skb, struct tipc_msg *msg, u32 mtu)
349{
350 struct tipc_msg *bmsg;
351 unsigned int bsz;
352 unsigned int msz = msg_size(msg);
353 u32 start, pad;
354 u32 max = mtu - INT_H_SIZE;
355
356 if (likely(msg_user(msg) == MSG_FRAGMENTER))
357 return false;
358 if (!skb)
359 return false;
360 bmsg = buf_msg(skb);
361 bsz = msg_size(bmsg);
362 start = align(bsz);
363 pad = start - bsz;
364
365 if (unlikely(msg_user(msg) == TUNNEL_PROTOCOL))
366 return false;
367 if (unlikely(msg_user(msg) == BCAST_PROTOCOL))
368 return false;
369 if (unlikely(msg_user(bmsg) != MSG_BUNDLER))
370 return false;
371 if (unlikely(skb_tailroom(skb) < (pad + msz)))
372 return false;
373 if (unlikely(max < (start + msz)))
374 return false;
375 if ((msg_importance(msg) < TIPC_SYSTEM_IMPORTANCE) &&
376 (msg_importance(bmsg) == TIPC_SYSTEM_IMPORTANCE))
377 return false;
378
379 skb_put(skb, pad + msz);
380 skb_copy_to_linear_data_offset(skb, start, msg, msz);
381 msg_set_size(bmsg, start + msz);
382 msg_set_msgcnt(bmsg, msg_msgcnt(bmsg) + 1);
383 return true;
384}
385
386/**
387 * tipc_msg_extract(): extract bundled inner packet from buffer
388 * @skb: buffer to be extracted from.
389 * @iskb: extracted inner buffer, to be returned
390 * @pos: position in outer message of msg to be extracted.
391 * Returns position of next msg
392 * Consumes outer buffer when last packet extracted
393 * Returns true when when there is an extracted buffer, otherwise false
394 */
395bool tipc_msg_extract(struct sk_buff *skb, struct sk_buff **iskb, int *pos)
396{
397 struct tipc_msg *msg;
398 int imsz, offset;
399
400 *iskb = NULL;
401 if (unlikely(skb_linearize(skb)))
402 goto none;
403
404 msg = buf_msg(skb);
405 offset = msg_hdr_sz(msg) + *pos;
406 if (unlikely(offset > (msg_size(msg) - MIN_H_SIZE)))
407 goto none;
408
409 *iskb = skb_clone(skb, GFP_ATOMIC);
410 if (unlikely(!*iskb))
411 goto none;
412 skb_pull(*iskb, offset);
413 imsz = msg_size(buf_msg(*iskb));
414 skb_trim(*iskb, imsz);
415 if (unlikely(!tipc_msg_validate(*iskb)))
416 goto none;
417 *pos += align(imsz);
418 return true;
419none:
420 kfree_skb(skb);
421 kfree_skb(*iskb);
422 *iskb = NULL;
423 return false;
424}
425
426/**
427 * tipc_msg_make_bundle(): Create bundle buf and append message to its tail
428 * @list: the buffer chain, where head is the buffer to replace/append
429 * @skb: buffer to be created, appended to and returned in case of success
430 * @msg: message to be appended
431 * @mtu: max allowable size for the bundle buffer, inclusive header
432 * @dnode: destination node for message. (Not always present in header)
433 * Returns true if success, otherwise false
434 */
435bool tipc_msg_make_bundle(struct sk_buff **skb, struct tipc_msg *msg,
436 u32 mtu, u32 dnode)
437{
438 struct sk_buff *_skb;
439 struct tipc_msg *bmsg;
440 u32 msz = msg_size(msg);
441 u32 max = mtu - INT_H_SIZE;
442
443 if (msg_user(msg) == MSG_FRAGMENTER)
444 return false;
445 if (msg_user(msg) == TUNNEL_PROTOCOL)
446 return false;
447 if (msg_user(msg) == BCAST_PROTOCOL)
448 return false;
449 if (msz > (max / 2))
450 return false;
451
452 _skb = tipc_buf_acquire(max, GFP_ATOMIC);
453 if (!_skb)
454 return false;
455
456 skb_trim(_skb, INT_H_SIZE);
457 bmsg = buf_msg(_skb);
458 tipc_msg_init(msg_prevnode(msg), bmsg, MSG_BUNDLER, 0,
459 INT_H_SIZE, dnode);
460 msg_set_importance(bmsg, msg_importance(msg));
461 msg_set_seqno(bmsg, msg_seqno(msg));
462 msg_set_ack(bmsg, msg_ack(msg));
463 msg_set_bcast_ack(bmsg, msg_bcast_ack(msg));
464 tipc_msg_bundle(_skb, msg, mtu);
465 *skb = _skb;
466 return true;
467}
468
469/**
470 * tipc_msg_reverse(): swap source and destination addresses and add error code
471 * @own_node: originating node id for reversed message
472 * @skb: buffer containing message to be reversed; may be replaced.
473 * @err: error code to be set in message, if any
474 * Consumes buffer at failure
475 * Returns true if success, otherwise false
476 */
477bool tipc_msg_reverse(u32 own_node, struct sk_buff **skb, int err)
478{
479 struct sk_buff *_skb = *skb;
480 struct tipc_msg *hdr;
481 struct tipc_msg ohdr;
482 int dlen;
483
484 if (skb_linearize(_skb))
485 goto exit;
486 hdr = buf_msg(_skb);
487 dlen = min_t(uint, msg_data_sz(hdr), MAX_FORWARD_SIZE);
488 if (msg_dest_droppable(hdr))
489 goto exit;
490 if (msg_errcode(hdr))
491 goto exit;
492
493 /* Take a copy of original header before altering message */
494 memcpy(&ohdr, hdr, msg_hdr_sz(hdr));
495
496 /* Never return SHORT header; expand by replacing buffer if necessary */
497 if (msg_short(hdr)) {
498 *skb = tipc_buf_acquire(BASIC_H_SIZE + dlen, GFP_ATOMIC);
499 if (!*skb)
500 goto exit;
501 memcpy((*skb)->data + BASIC_H_SIZE, msg_data(hdr), dlen);
502 kfree_skb(_skb);
503 _skb = *skb;
504 hdr = buf_msg(_skb);
505 memcpy(hdr, &ohdr, BASIC_H_SIZE);
506 msg_set_hdr_sz(hdr, BASIC_H_SIZE);
507 }
508
509 if (skb_cloned(_skb) &&
510 pskb_expand_head(_skb, BUF_HEADROOM, BUF_TAILROOM, GFP_ATOMIC))
511 goto exit;
512
513 /* reassign after skb header modifications */
514 hdr = buf_msg(_skb);
515 /* Now reverse the concerned fields */
516 msg_set_errcode(hdr, err);
517 msg_set_non_seq(hdr, 0);
518 msg_set_origport(hdr, msg_destport(&ohdr));
519 msg_set_destport(hdr, msg_origport(&ohdr));
520 msg_set_destnode(hdr, msg_prevnode(&ohdr));
521 msg_set_prevnode(hdr, own_node);
522 msg_set_orignode(hdr, own_node);
523 msg_set_size(hdr, msg_hdr_sz(hdr) + dlen);
524 skb_trim(_skb, msg_size(hdr));
525 skb_orphan(_skb);
526 return true;
527exit:
528 kfree_skb(_skb);
529 *skb = NULL;
530 return false;
531}
532
533/**
534 * tipc_msg_lookup_dest(): try to find new destination for named message
535 * @skb: the buffer containing the message.
536 * @err: error code to be used by caller if lookup fails
537 * Does not consume buffer
538 * Returns true if a destination is found, false otherwise
539 */
540bool tipc_msg_lookup_dest(struct net *net, struct sk_buff *skb, int *err)
541{
542 struct tipc_msg *msg = buf_msg(skb);
543 u32 dport, dnode;
544 u32 onode = tipc_own_addr(net);
545
546 if (!msg_isdata(msg))
547 return false;
548 if (!msg_named(msg))
549 return false;
550 if (msg_errcode(msg))
551 return false;
552 *err = TIPC_ERR_NO_NAME;
553 if (skb_linearize(skb))
554 return false;
555 msg = buf_msg(skb);
556 if (msg_reroute_cnt(msg))
557 return false;
558 dnode = addr_domain(net, msg_lookup_scope(msg));
559 dport = tipc_nametbl_translate(net, msg_nametype(msg),
560 msg_nameinst(msg), &dnode);
561 if (!dport)
562 return false;
563 msg_incr_reroute_cnt(msg);
564 if (dnode != onode)
565 msg_set_prevnode(msg, onode);
566 msg_set_destnode(msg, dnode);
567 msg_set_destport(msg, dport);
568 *err = TIPC_OK;
569
570 if (!skb_cloned(skb))
571 return true;
572
573 /* Unclone buffer in case it was bundled */
574 if (pskb_expand_head(skb, BUF_HEADROOM, BUF_TAILROOM, GFP_ATOMIC))
575 return false;
576
577 return true;
578}
579
580/* tipc_msg_reassemble() - clone a buffer chain of fragments and
581 * reassemble the clones into one message
582 */
583bool tipc_msg_reassemble(struct sk_buff_head *list, struct sk_buff_head *rcvq)
584{
585 struct sk_buff *skb, *_skb;
586 struct sk_buff *frag = NULL;
587 struct sk_buff *head = NULL;
588 int hdr_len;
589
590 /* Copy header if single buffer */
591 if (skb_queue_len(list) == 1) {
592 skb = skb_peek(list);
593 hdr_len = skb_headroom(skb) + msg_hdr_sz(buf_msg(skb));
594 _skb = __pskb_copy(skb, hdr_len, GFP_ATOMIC);
595 if (!_skb)
596 return false;
597 __skb_queue_tail(rcvq, _skb);
598 return true;
599 }
600
601 /* Clone all fragments and reassemble */
602 skb_queue_walk(list, skb) {
603 frag = skb_clone(skb, GFP_ATOMIC);
604 if (!frag)
605 goto error;
606 frag->next = NULL;
607 if (tipc_buf_append(&head, &frag))
608 break;
609 if (!head)
610 goto error;
611 }
612 __skb_queue_tail(rcvq, frag);
613 return true;
614error:
615 pr_warn("Failed do clone local mcast rcv buffer\n");
616 kfree_skb(head);
617 return false;
618}
619
620bool tipc_msg_pskb_copy(u32 dst, struct sk_buff_head *msg,
621 struct sk_buff_head *cpy)
622{
623 struct sk_buff *skb, *_skb;
624
625 skb_queue_walk(msg, skb) {
626 _skb = pskb_copy(skb, GFP_ATOMIC);
627 if (!_skb) {
628 __skb_queue_purge(cpy);
629 return false;
630 }
631 msg_set_destnode(buf_msg(_skb), dst);
632 __skb_queue_tail(cpy, _skb);
633 }
634 return true;
635}
636
637/* tipc_skb_queue_sorted(); sort pkt into list according to sequence number
638 * @list: list to be appended to
639 * @seqno: sequence number of buffer to add
640 * @skb: buffer to add
641 */
642void __tipc_skb_queue_sorted(struct sk_buff_head *list, u16 seqno,
643 struct sk_buff *skb)
644{
645 struct sk_buff *_skb, *tmp;
646
647 if (skb_queue_empty(list) || less(seqno, buf_seqno(skb_peek(list)))) {
648 __skb_queue_head(list, skb);
649 return;
650 }
651
652 if (more(seqno, buf_seqno(skb_peek_tail(list)))) {
653 __skb_queue_tail(list, skb);
654 return;
655 }
656
657 skb_queue_walk_safe(list, _skb, tmp) {
658 if (more(seqno, buf_seqno(_skb)))
659 continue;
660 if (seqno == buf_seqno(_skb))
661 break;
662 __skb_queue_before(list, _skb, skb);
663 return;
664 }
665 kfree_skb(skb);
666}