]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - net/netlink/af_netlink.c
[NETLINK]: Fix race with recvmsg().
[mirror_ubuntu-bionic-kernel.git] / net / netlink / af_netlink.c
CommitLineData
1da177e4
LT
1/*
2 * NETLINK Kernel-user communication protocol.
3 *
4 * Authors: Alan Cox <alan@redhat.com>
5 * Alexey Kuznetsov <kuznet@ms2.inr.ac.ru>
6 *
7 * This program is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU General Public License
9 * as published by the Free Software Foundation; either version
10 * 2 of the License, or (at your option) any later version.
11 *
12 * Tue Jun 26 14:36:48 MEST 2001 Herbert "herp" Rosmanith
13 * added netlink_proto_exit
14 * Tue Jan 22 18:32:44 BRST 2002 Arnaldo C. de Melo <acme@conectiva.com.br>
15 * use nlk_sk, as sk->protinfo is on a diet 8)
16 *
17 */
18
19#include <linux/config.h>
20#include <linux/module.h>
21
22#include <linux/kernel.h>
23#include <linux/init.h>
1da177e4
LT
24#include <linux/signal.h>
25#include <linux/sched.h>
26#include <linux/errno.h>
27#include <linux/string.h>
28#include <linux/stat.h>
29#include <linux/socket.h>
30#include <linux/un.h>
31#include <linux/fcntl.h>
32#include <linux/termios.h>
33#include <linux/sockios.h>
34#include <linux/net.h>
35#include <linux/fs.h>
36#include <linux/slab.h>
37#include <asm/uaccess.h>
38#include <linux/skbuff.h>
39#include <linux/netdevice.h>
40#include <linux/rtnetlink.h>
41#include <linux/proc_fs.h>
42#include <linux/seq_file.h>
43#include <linux/smp_lock.h>
44#include <linux/notifier.h>
45#include <linux/security.h>
46#include <linux/jhash.h>
47#include <linux/jiffies.h>
48#include <linux/random.h>
49#include <linux/bitops.h>
50#include <linux/mm.h>
51#include <linux/types.h>
54e0f520
AM
52#include <linux/audit.h>
53
1da177e4
LT
54#include <net/sock.h>
55#include <net/scm.h>
56
57#define Nprintk(a...)
58
59struct netlink_sock {
60 /* struct sock has to be the first member of netlink_sock */
61 struct sock sk;
62 u32 pid;
63 unsigned int groups;
64 u32 dst_pid;
65 unsigned int dst_groups;
66 unsigned long state;
67 wait_queue_head_t wait;
68 struct netlink_callback *cb;
69 spinlock_t cb_lock;
70 void (*data_ready)(struct sock *sk, int bytes);
71};
72
73static inline struct netlink_sock *nlk_sk(struct sock *sk)
74{
75 return (struct netlink_sock *)sk;
76}
77
78struct nl_pid_hash {
79 struct hlist_head *table;
80 unsigned long rehash_time;
81
82 unsigned int mask;
83 unsigned int shift;
84
85 unsigned int entries;
86 unsigned int max_shift;
87
88 u32 rnd;
89};
90
91struct netlink_table {
92 struct nl_pid_hash hash;
93 struct hlist_head mc_list;
94 unsigned int nl_nonroot;
95};
96
97static struct netlink_table *nl_table;
98
99static DECLARE_WAIT_QUEUE_HEAD(nl_table_wait);
100
101static int netlink_dump(struct sock *sk);
102static void netlink_destroy_callback(struct netlink_callback *cb);
103
104static DEFINE_RWLOCK(nl_table_lock);
105static atomic_t nl_table_users = ATOMIC_INIT(0);
106
107static struct notifier_block *netlink_chain;
108
109static struct hlist_head *nl_pid_hashfn(struct nl_pid_hash *hash, u32 pid)
110{
111 return &hash->table[jhash_1word(pid, hash->rnd) & hash->mask];
112}
113
114static void netlink_sock_destruct(struct sock *sk)
115{
116 skb_queue_purge(&sk->sk_receive_queue);
117
118 if (!sock_flag(sk, SOCK_DEAD)) {
119 printk("Freeing alive netlink socket %p\n", sk);
120 return;
121 }
122 BUG_TRAP(!atomic_read(&sk->sk_rmem_alloc));
123 BUG_TRAP(!atomic_read(&sk->sk_wmem_alloc));
124 BUG_TRAP(!nlk_sk(sk)->cb);
125}
126
127/* This lock without WQ_FLAG_EXCLUSIVE is good on UP and it is _very_ bad on SMP.
128 * Look, when several writers sleep and reader wakes them up, all but one
129 * immediately hit write lock and grab all the cpus. Exclusive sleep solves
130 * this, _but_ remember, it adds useless work on UP machines.
131 */
132
133static void netlink_table_grab(void)
134{
135 write_lock_bh(&nl_table_lock);
136
137 if (atomic_read(&nl_table_users)) {
138 DECLARE_WAITQUEUE(wait, current);
139
140 add_wait_queue_exclusive(&nl_table_wait, &wait);
141 for(;;) {
142 set_current_state(TASK_UNINTERRUPTIBLE);
143 if (atomic_read(&nl_table_users) == 0)
144 break;
145 write_unlock_bh(&nl_table_lock);
146 schedule();
147 write_lock_bh(&nl_table_lock);
148 }
149
150 __set_current_state(TASK_RUNNING);
151 remove_wait_queue(&nl_table_wait, &wait);
152 }
153}
154
155static __inline__ void netlink_table_ungrab(void)
156{
157 write_unlock_bh(&nl_table_lock);
158 wake_up(&nl_table_wait);
159}
160
161static __inline__ void
162netlink_lock_table(void)
163{
164 /* read_lock() synchronizes us to netlink_table_grab */
165
166 read_lock(&nl_table_lock);
167 atomic_inc(&nl_table_users);
168 read_unlock(&nl_table_lock);
169}
170
171static __inline__ void
172netlink_unlock_table(void)
173{
174 if (atomic_dec_and_test(&nl_table_users))
175 wake_up(&nl_table_wait);
176}
177
178static __inline__ struct sock *netlink_lookup(int protocol, u32 pid)
179{
180 struct nl_pid_hash *hash = &nl_table[protocol].hash;
181 struct hlist_head *head;
182 struct sock *sk;
183 struct hlist_node *node;
184
185 read_lock(&nl_table_lock);
186 head = nl_pid_hashfn(hash, pid);
187 sk_for_each(sk, node, head) {
188 if (nlk_sk(sk)->pid == pid) {
189 sock_hold(sk);
190 goto found;
191 }
192 }
193 sk = NULL;
194found:
195 read_unlock(&nl_table_lock);
196 return sk;
197}
198
199static inline struct hlist_head *nl_pid_hash_alloc(size_t size)
200{
201 if (size <= PAGE_SIZE)
202 return kmalloc(size, GFP_ATOMIC);
203 else
204 return (struct hlist_head *)
205 __get_free_pages(GFP_ATOMIC, get_order(size));
206}
207
208static inline void nl_pid_hash_free(struct hlist_head *table, size_t size)
209{
210 if (size <= PAGE_SIZE)
211 kfree(table);
212 else
213 free_pages((unsigned long)table, get_order(size));
214}
215
216static int nl_pid_hash_rehash(struct nl_pid_hash *hash, int grow)
217{
218 unsigned int omask, mask, shift;
219 size_t osize, size;
220 struct hlist_head *otable, *table;
221 int i;
222
223 omask = mask = hash->mask;
224 osize = size = (mask + 1) * sizeof(*table);
225 shift = hash->shift;
226
227 if (grow) {
228 if (++shift > hash->max_shift)
229 return 0;
230 mask = mask * 2 + 1;
231 size *= 2;
232 }
233
234 table = nl_pid_hash_alloc(size);
235 if (!table)
236 return 0;
237
238 memset(table, 0, size);
239 otable = hash->table;
240 hash->table = table;
241 hash->mask = mask;
242 hash->shift = shift;
243 get_random_bytes(&hash->rnd, sizeof(hash->rnd));
244
245 for (i = 0; i <= omask; i++) {
246 struct sock *sk;
247 struct hlist_node *node, *tmp;
248
249 sk_for_each_safe(sk, node, tmp, &otable[i])
250 __sk_add_node(sk, nl_pid_hashfn(hash, nlk_sk(sk)->pid));
251 }
252
253 nl_pid_hash_free(otable, osize);
254 hash->rehash_time = jiffies + 10 * 60 * HZ;
255 return 1;
256}
257
258static inline int nl_pid_hash_dilute(struct nl_pid_hash *hash, int len)
259{
260 int avg = hash->entries >> hash->shift;
261
262 if (unlikely(avg > 1) && nl_pid_hash_rehash(hash, 1))
263 return 1;
264
265 if (unlikely(len > avg) && time_after(jiffies, hash->rehash_time)) {
266 nl_pid_hash_rehash(hash, 0);
267 return 1;
268 }
269
270 return 0;
271}
272
273static struct proto_ops netlink_ops;
274
275static int netlink_insert(struct sock *sk, u32 pid)
276{
277 struct nl_pid_hash *hash = &nl_table[sk->sk_protocol].hash;
278 struct hlist_head *head;
279 int err = -EADDRINUSE;
280 struct sock *osk;
281 struct hlist_node *node;
282 int len;
283
284 netlink_table_grab();
285 head = nl_pid_hashfn(hash, pid);
286 len = 0;
287 sk_for_each(osk, node, head) {
288 if (nlk_sk(osk)->pid == pid)
289 break;
290 len++;
291 }
292 if (node)
293 goto err;
294
295 err = -EBUSY;
296 if (nlk_sk(sk)->pid)
297 goto err;
298
299 err = -ENOMEM;
300 if (BITS_PER_LONG > 32 && unlikely(hash->entries >= UINT_MAX))
301 goto err;
302
303 if (len && nl_pid_hash_dilute(hash, len))
304 head = nl_pid_hashfn(hash, pid);
305 hash->entries++;
306 nlk_sk(sk)->pid = pid;
307 sk_add_node(sk, head);
308 err = 0;
309
310err:
311 netlink_table_ungrab();
312 return err;
313}
314
315static void netlink_remove(struct sock *sk)
316{
317 netlink_table_grab();
318 nl_table[sk->sk_protocol].hash.entries--;
319 sk_del_node_init(sk);
320 if (nlk_sk(sk)->groups)
321 __sk_del_bind_node(sk);
322 netlink_table_ungrab();
323}
324
325static struct proto netlink_proto = {
326 .name = "NETLINK",
327 .owner = THIS_MODULE,
328 .obj_size = sizeof(struct netlink_sock),
329};
330
331static int netlink_create(struct socket *sock, int protocol)
332{
333 struct sock *sk;
334 struct netlink_sock *nlk;
335
336 sock->state = SS_UNCONNECTED;
337
338 if (sock->type != SOCK_RAW && sock->type != SOCK_DGRAM)
339 return -ESOCKTNOSUPPORT;
340
341 if (protocol<0 || protocol >= MAX_LINKS)
342 return -EPROTONOSUPPORT;
343
344 sock->ops = &netlink_ops;
345
346 sk = sk_alloc(PF_NETLINK, GFP_KERNEL, &netlink_proto, 1);
347 if (!sk)
348 return -ENOMEM;
349
350 sock_init_data(sock, sk);
351
352 nlk = nlk_sk(sk);
353
354 spin_lock_init(&nlk->cb_lock);
355 init_waitqueue_head(&nlk->wait);
356 sk->sk_destruct = netlink_sock_destruct;
357
358 sk->sk_protocol = protocol;
359 return 0;
360}
361
362static int netlink_release(struct socket *sock)
363{
364 struct sock *sk = sock->sk;
365 struct netlink_sock *nlk;
366
367 if (!sk)
368 return 0;
369
370 netlink_remove(sk);
371 nlk = nlk_sk(sk);
372
373 spin_lock(&nlk->cb_lock);
374 if (nlk->cb) {
375 nlk->cb->done(nlk->cb);
376 netlink_destroy_callback(nlk->cb);
377 nlk->cb = NULL;
1da177e4
LT
378 }
379 spin_unlock(&nlk->cb_lock);
380
381 /* OK. Socket is unlinked, and, therefore,
382 no new packets will arrive */
383
384 sock_orphan(sk);
385 sock->sk = NULL;
386 wake_up_interruptible_all(&nlk->wait);
387
388 skb_queue_purge(&sk->sk_write_queue);
389
390 if (nlk->pid && !nlk->groups) {
391 struct netlink_notify n = {
392 .protocol = sk->sk_protocol,
393 .pid = nlk->pid,
394 };
395 notifier_call_chain(&netlink_chain, NETLINK_URELEASE, &n);
396 }
397
398 sock_put(sk);
399 return 0;
400}
401
402static int netlink_autobind(struct socket *sock)
403{
404 struct sock *sk = sock->sk;
405 struct nl_pid_hash *hash = &nl_table[sk->sk_protocol].hash;
406 struct hlist_head *head;
407 struct sock *osk;
408 struct hlist_node *node;
409 s32 pid = current->pid;
410 int err;
411 static s32 rover = -4097;
412
413retry:
414 cond_resched();
415 netlink_table_grab();
416 head = nl_pid_hashfn(hash, pid);
417 sk_for_each(osk, node, head) {
418 if (nlk_sk(osk)->pid == pid) {
419 /* Bind collision, search negative pid values. */
420 pid = rover--;
421 if (rover > -4097)
422 rover = -4097;
423 netlink_table_ungrab();
424 goto retry;
425 }
426 }
427 netlink_table_ungrab();
428
429 err = netlink_insert(sk, pid);
430 if (err == -EADDRINUSE)
431 goto retry;
432 return 0;
433}
434
435static inline int netlink_capable(struct socket *sock, unsigned int flag)
436{
437 return (nl_table[sock->sk->sk_protocol].nl_nonroot & flag) ||
438 capable(CAP_NET_ADMIN);
439}
440
441static int netlink_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
442{
443 struct sock *sk = sock->sk;
444 struct netlink_sock *nlk = nlk_sk(sk);
445 struct sockaddr_nl *nladdr = (struct sockaddr_nl *)addr;
446 int err;
447
448 if (nladdr->nl_family != AF_NETLINK)
449 return -EINVAL;
450
451 /* Only superuser is allowed to listen multicasts */
452 if (nladdr->nl_groups && !netlink_capable(sock, NL_NONROOT_RECV))
453 return -EPERM;
454
455 if (nlk->pid) {
456 if (nladdr->nl_pid != nlk->pid)
457 return -EINVAL;
458 } else {
459 err = nladdr->nl_pid ?
460 netlink_insert(sk, nladdr->nl_pid) :
461 netlink_autobind(sock);
462 if (err)
463 return err;
464 }
465
466 if (!nladdr->nl_groups && !nlk->groups)
467 return 0;
468
469 netlink_table_grab();
470 if (nlk->groups && !nladdr->nl_groups)
471 __sk_del_bind_node(sk);
472 else if (!nlk->groups && nladdr->nl_groups)
473 sk_add_bind_node(sk, &nl_table[sk->sk_protocol].mc_list);
474 nlk->groups = nladdr->nl_groups;
475 netlink_table_ungrab();
476
477 return 0;
478}
479
480static int netlink_connect(struct socket *sock, struct sockaddr *addr,
481 int alen, int flags)
482{
483 int err = 0;
484 struct sock *sk = sock->sk;
485 struct netlink_sock *nlk = nlk_sk(sk);
486 struct sockaddr_nl *nladdr=(struct sockaddr_nl*)addr;
487
488 if (addr->sa_family == AF_UNSPEC) {
489 sk->sk_state = NETLINK_UNCONNECTED;
490 nlk->dst_pid = 0;
491 nlk->dst_groups = 0;
492 return 0;
493 }
494 if (addr->sa_family != AF_NETLINK)
495 return -EINVAL;
496
497 /* Only superuser is allowed to send multicasts */
498 if (nladdr->nl_groups && !netlink_capable(sock, NL_NONROOT_SEND))
499 return -EPERM;
500
501 if (!nlk->pid)
502 err = netlink_autobind(sock);
503
504 if (err == 0) {
505 sk->sk_state = NETLINK_CONNECTED;
506 nlk->dst_pid = nladdr->nl_pid;
507 nlk->dst_groups = nladdr->nl_groups;
508 }
509
510 return err;
511}
512
513static int netlink_getname(struct socket *sock, struct sockaddr *addr, int *addr_len, int peer)
514{
515 struct sock *sk = sock->sk;
516 struct netlink_sock *nlk = nlk_sk(sk);
517 struct sockaddr_nl *nladdr=(struct sockaddr_nl *)addr;
518
519 nladdr->nl_family = AF_NETLINK;
520 nladdr->nl_pad = 0;
521 *addr_len = sizeof(*nladdr);
522
523 if (peer) {
524 nladdr->nl_pid = nlk->dst_pid;
525 nladdr->nl_groups = nlk->dst_groups;
526 } else {
527 nladdr->nl_pid = nlk->pid;
528 nladdr->nl_groups = nlk->groups;
529 }
530 return 0;
531}
532
533static void netlink_overrun(struct sock *sk)
534{
535 if (!test_and_set_bit(0, &nlk_sk(sk)->state)) {
536 sk->sk_err = ENOBUFS;
537 sk->sk_error_report(sk);
538 }
539}
540
541static struct sock *netlink_getsockbypid(struct sock *ssk, u32 pid)
542{
543 int protocol = ssk->sk_protocol;
544 struct sock *sock;
545 struct netlink_sock *nlk;
546
547 sock = netlink_lookup(protocol, pid);
548 if (!sock)
549 return ERR_PTR(-ECONNREFUSED);
550
551 /* Don't bother queuing skb if kernel socket has no input function */
552 nlk = nlk_sk(sock);
553 if ((nlk->pid == 0 && !nlk->data_ready) ||
554 (sock->sk_state == NETLINK_CONNECTED &&
555 nlk->dst_pid != nlk_sk(ssk)->pid)) {
556 sock_put(sock);
557 return ERR_PTR(-ECONNREFUSED);
558 }
559 return sock;
560}
561
562struct sock *netlink_getsockbyfilp(struct file *filp)
563{
564 struct inode *inode = filp->f_dentry->d_inode;
565 struct sock *sock;
566
567 if (!S_ISSOCK(inode->i_mode))
568 return ERR_PTR(-ENOTSOCK);
569
570 sock = SOCKET_I(inode)->sk;
571 if (sock->sk_family != AF_NETLINK)
572 return ERR_PTR(-EINVAL);
573
574 sock_hold(sock);
575 return sock;
576}
577
578/*
579 * Attach a skb to a netlink socket.
580 * The caller must hold a reference to the destination socket. On error, the
581 * reference is dropped. The skb is not send to the destination, just all
582 * all error checks are performed and memory in the queue is reserved.
583 * Return values:
584 * < 0: error. skb freed, reference to sock dropped.
585 * 0: continue
586 * 1: repeat lookup - reference dropped while waiting for socket memory.
587 */
588int netlink_attachskb(struct sock *sk, struct sk_buff *skb, int nonblock, long timeo)
589{
590 struct netlink_sock *nlk;
591
592 nlk = nlk_sk(sk);
593
594 if (atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf ||
595 test_bit(0, &nlk->state)) {
596 DECLARE_WAITQUEUE(wait, current);
597 if (!timeo) {
598 if (!nlk->pid)
599 netlink_overrun(sk);
600 sock_put(sk);
601 kfree_skb(skb);
602 return -EAGAIN;
603 }
604
605 __set_current_state(TASK_INTERRUPTIBLE);
606 add_wait_queue(&nlk->wait, &wait);
607
608 if ((atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf ||
609 test_bit(0, &nlk->state)) &&
610 !sock_flag(sk, SOCK_DEAD))
611 timeo = schedule_timeout(timeo);
612
613 __set_current_state(TASK_RUNNING);
614 remove_wait_queue(&nlk->wait, &wait);
615 sock_put(sk);
616
617 if (signal_pending(current)) {
618 kfree_skb(skb);
619 return sock_intr_errno(timeo);
620 }
621 return 1;
622 }
623 skb_set_owner_r(skb, sk);
624 return 0;
625}
626
627int netlink_sendskb(struct sock *sk, struct sk_buff *skb, int protocol)
628{
629 struct netlink_sock *nlk;
630 int len = skb->len;
631
632 nlk = nlk_sk(sk);
633
634 skb_queue_tail(&sk->sk_receive_queue, skb);
635 sk->sk_data_ready(sk, len);
636 sock_put(sk);
637 return len;
638}
639
640void netlink_detachskb(struct sock *sk, struct sk_buff *skb)
641{
642 kfree_skb(skb);
643 sock_put(sk);
644}
645
646static inline struct sk_buff *netlink_trim(struct sk_buff *skb, int allocation)
647{
648 int delta;
649
650 skb_orphan(skb);
651
652 delta = skb->end - skb->tail;
653 if (delta * 2 < skb->truesize)
654 return skb;
655
656 if (skb_shared(skb)) {
657 struct sk_buff *nskb = skb_clone(skb, allocation);
658 if (!nskb)
659 return skb;
660 kfree_skb(skb);
661 skb = nskb;
662 }
663
664 if (!pskb_expand_head(skb, 0, -delta, allocation))
665 skb->truesize -= delta;
666
667 return skb;
668}
669
670int netlink_unicast(struct sock *ssk, struct sk_buff *skb, u32 pid, int nonblock)
671{
672 struct sock *sk;
673 int err;
674 long timeo;
675
676 skb = netlink_trim(skb, gfp_any());
677
678 timeo = sock_sndtimeo(ssk, nonblock);
679retry:
680 sk = netlink_getsockbypid(ssk, pid);
681 if (IS_ERR(sk)) {
682 kfree_skb(skb);
683 return PTR_ERR(sk);
684 }
685 err = netlink_attachskb(sk, skb, nonblock, timeo);
686 if (err == 1)
687 goto retry;
688 if (err)
689 return err;
690
691 return netlink_sendskb(sk, skb, ssk->sk_protocol);
692}
693
694static __inline__ int netlink_broadcast_deliver(struct sock *sk, struct sk_buff *skb)
695{
696 struct netlink_sock *nlk = nlk_sk(sk);
697
698 if (atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf &&
699 !test_bit(0, &nlk->state)) {
db61ecc3 700 skb_orphan(skb);
1da177e4
LT
701 skb_set_owner_r(skb, sk);
702 skb_queue_tail(&sk->sk_receive_queue, skb);
703 sk->sk_data_ready(sk, skb->len);
704 return atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf;
705 }
706 return -1;
707}
708
709struct netlink_broadcast_data {
710 struct sock *exclude_sk;
711 u32 pid;
712 u32 group;
713 int failure;
714 int congested;
715 int delivered;
716 int allocation;
717 struct sk_buff *skb, *skb2;
718};
719
720static inline int do_one_broadcast(struct sock *sk,
721 struct netlink_broadcast_data *p)
722{
723 struct netlink_sock *nlk = nlk_sk(sk);
724 int val;
725
726 if (p->exclude_sk == sk)
727 goto out;
728
729 if (nlk->pid == p->pid || !(nlk->groups & p->group))
730 goto out;
731
732 if (p->failure) {
733 netlink_overrun(sk);
734 goto out;
735 }
736
737 sock_hold(sk);
738 if (p->skb2 == NULL) {
739 if (atomic_read(&p->skb->users) != 1) {
740 p->skb2 = skb_clone(p->skb, p->allocation);
741 } else {
742 p->skb2 = p->skb;
743 atomic_inc(&p->skb->users);
744 }
745 }
746 if (p->skb2 == NULL) {
747 netlink_overrun(sk);
748 /* Clone failed. Notify ALL listeners. */
749 p->failure = 1;
750 } else if ((val = netlink_broadcast_deliver(sk, p->skb2)) < 0) {
751 netlink_overrun(sk);
752 } else {
753 p->congested |= val;
754 p->delivered = 1;
755 p->skb2 = NULL;
756 }
757 sock_put(sk);
758
759out:
760 return 0;
761}
762
763int netlink_broadcast(struct sock *ssk, struct sk_buff *skb, u32 pid,
764 u32 group, int allocation)
765{
766 struct netlink_broadcast_data info;
767 struct hlist_node *node;
768 struct sock *sk;
769
770 skb = netlink_trim(skb, allocation);
771
772 info.exclude_sk = ssk;
773 info.pid = pid;
774 info.group = group;
775 info.failure = 0;
776 info.congested = 0;
777 info.delivered = 0;
778 info.allocation = allocation;
779 info.skb = skb;
780 info.skb2 = NULL;
781
782 /* While we sleep in clone, do not allow to change socket list */
783
784 netlink_lock_table();
785
786 sk_for_each_bound(sk, node, &nl_table[ssk->sk_protocol].mc_list)
787 do_one_broadcast(sk, &info);
788
789 netlink_unlock_table();
790
791 if (info.skb2)
792 kfree_skb(info.skb2);
793 kfree_skb(skb);
794
795 if (info.delivered) {
796 if (info.congested && (allocation & __GFP_WAIT))
797 yield();
798 return 0;
799 }
800 if (info.failure)
801 return -ENOBUFS;
802 return -ESRCH;
803}
804
805struct netlink_set_err_data {
806 struct sock *exclude_sk;
807 u32 pid;
808 u32 group;
809 int code;
810};
811
812static inline int do_one_set_err(struct sock *sk,
813 struct netlink_set_err_data *p)
814{
815 struct netlink_sock *nlk = nlk_sk(sk);
816
817 if (sk == p->exclude_sk)
818 goto out;
819
820 if (nlk->pid == p->pid || !(nlk->groups & p->group))
821 goto out;
822
823 sk->sk_err = p->code;
824 sk->sk_error_report(sk);
825out:
826 return 0;
827}
828
829void netlink_set_err(struct sock *ssk, u32 pid, u32 group, int code)
830{
831 struct netlink_set_err_data info;
832 struct hlist_node *node;
833 struct sock *sk;
834
835 info.exclude_sk = ssk;
836 info.pid = pid;
837 info.group = group;
838 info.code = code;
839
840 read_lock(&nl_table_lock);
841
842 sk_for_each_bound(sk, node, &nl_table[ssk->sk_protocol].mc_list)
843 do_one_set_err(sk, &info);
844
845 read_unlock(&nl_table_lock);
846}
847
848static inline void netlink_rcv_wake(struct sock *sk)
849{
850 struct netlink_sock *nlk = nlk_sk(sk);
851
852 if (!skb_queue_len(&sk->sk_receive_queue))
853 clear_bit(0, &nlk->state);
854 if (!test_bit(0, &nlk->state))
855 wake_up_interruptible(&nlk->wait);
856}
857
858static int netlink_sendmsg(struct kiocb *kiocb, struct socket *sock,
859 struct msghdr *msg, size_t len)
860{
861 struct sock_iocb *siocb = kiocb_to_siocb(kiocb);
862 struct sock *sk = sock->sk;
863 struct netlink_sock *nlk = nlk_sk(sk);
864 struct sockaddr_nl *addr=msg->msg_name;
865 u32 dst_pid;
866 u32 dst_groups;
867 struct sk_buff *skb;
868 int err;
869 struct scm_cookie scm;
870
871 if (msg->msg_flags&MSG_OOB)
872 return -EOPNOTSUPP;
873
874 if (NULL == siocb->scm)
875 siocb->scm = &scm;
876 err = scm_send(sock, msg, siocb->scm);
877 if (err < 0)
878 return err;
879
880 if (msg->msg_namelen) {
881 if (addr->nl_family != AF_NETLINK)
882 return -EINVAL;
883 dst_pid = addr->nl_pid;
884 dst_groups = addr->nl_groups;
885 if (dst_groups && !netlink_capable(sock, NL_NONROOT_SEND))
886 return -EPERM;
887 } else {
888 dst_pid = nlk->dst_pid;
889 dst_groups = nlk->dst_groups;
890 }
891
892 if (!nlk->pid) {
893 err = netlink_autobind(sock);
894 if (err)
895 goto out;
896 }
897
898 err = -EMSGSIZE;
899 if (len > sk->sk_sndbuf - 32)
900 goto out;
901 err = -ENOBUFS;
902 skb = alloc_skb(len, GFP_KERNEL);
903 if (skb==NULL)
904 goto out;
905
906 NETLINK_CB(skb).pid = nlk->pid;
907 NETLINK_CB(skb).groups = nlk->groups;
908 NETLINK_CB(skb).dst_pid = dst_pid;
909 NETLINK_CB(skb).dst_groups = dst_groups;
c94c257c 910 NETLINK_CB(skb).loginuid = audit_get_loginuid(current->audit_context);
1da177e4
LT
911 memcpy(NETLINK_CREDS(skb), &siocb->scm->creds, sizeof(struct ucred));
912
913 /* What can I do? Netlink is asynchronous, so that
914 we will have to save current capabilities to
915 check them, when this message will be delivered
916 to corresponding kernel module. --ANK (980802)
917 */
918
919 err = -EFAULT;
920 if (memcpy_fromiovec(skb_put(skb,len), msg->msg_iov, len)) {
921 kfree_skb(skb);
922 goto out;
923 }
924
925 err = security_netlink_send(sk, skb);
926 if (err) {
927 kfree_skb(skb);
928 goto out;
929 }
930
931 if (dst_groups) {
932 atomic_inc(&skb->users);
933 netlink_broadcast(sk, skb, dst_pid, dst_groups, GFP_KERNEL);
934 }
935 err = netlink_unicast(sk, skb, dst_pid, msg->msg_flags&MSG_DONTWAIT);
936
937out:
938 return err;
939}
940
941static int netlink_recvmsg(struct kiocb *kiocb, struct socket *sock,
942 struct msghdr *msg, size_t len,
943 int flags)
944{
945 struct sock_iocb *siocb = kiocb_to_siocb(kiocb);
946 struct scm_cookie scm;
947 struct sock *sk = sock->sk;
948 struct netlink_sock *nlk = nlk_sk(sk);
949 int noblock = flags&MSG_DONTWAIT;
950 size_t copied;
951 struct sk_buff *skb;
952 int err;
953
954 if (flags&MSG_OOB)
955 return -EOPNOTSUPP;
956
957 copied = 0;
958
959 skb = skb_recv_datagram(sk,flags,noblock,&err);
960 if (skb==NULL)
961 goto out;
962
963 msg->msg_namelen = 0;
964
965 copied = skb->len;
966 if (len < copied) {
967 msg->msg_flags |= MSG_TRUNC;
968 copied = len;
969 }
970
971 skb->h.raw = skb->data;
972 err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, copied);
973
974 if (msg->msg_name) {
975 struct sockaddr_nl *addr = (struct sockaddr_nl*)msg->msg_name;
976 addr->nl_family = AF_NETLINK;
977 addr->nl_pad = 0;
978 addr->nl_pid = NETLINK_CB(skb).pid;
979 addr->nl_groups = NETLINK_CB(skb).dst_groups;
980 msg->msg_namelen = sizeof(*addr);
981 }
982
983 if (NULL == siocb->scm) {
984 memset(&scm, 0, sizeof(scm));
985 siocb->scm = &scm;
986 }
987 siocb->scm->creds = *NETLINK_CREDS(skb);
988 skb_free_datagram(sk, skb);
989
990 if (nlk->cb && atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf / 2)
991 netlink_dump(sk);
992
993 scm_recv(sock, msg, siocb->scm, flags);
994
995out:
996 netlink_rcv_wake(sk);
997 return err ? : copied;
998}
999
1000static void netlink_data_ready(struct sock *sk, int len)
1001{
1002 struct netlink_sock *nlk = nlk_sk(sk);
1003
1004 if (nlk->data_ready)
1005 nlk->data_ready(sk, len);
1006 netlink_rcv_wake(sk);
1007}
1008
1009/*
1010 * We export these functions to other modules. They provide a
1011 * complete set of kernel non-blocking support for message
1012 * queueing.
1013 */
1014
1015struct sock *
1016netlink_kernel_create(int unit, void (*input)(struct sock *sk, int len))
1017{
1018 struct socket *sock;
1019 struct sock *sk;
1020
1021 if (!nl_table)
1022 return NULL;
1023
1024 if (unit<0 || unit>=MAX_LINKS)
1025 return NULL;
1026
1027 if (sock_create_lite(PF_NETLINK, SOCK_DGRAM, unit, &sock))
1028 return NULL;
1029
1030 if (netlink_create(sock, unit) < 0) {
1031 sock_release(sock);
1032 return NULL;
1033 }
1034 sk = sock->sk;
1035 sk->sk_data_ready = netlink_data_ready;
1036 if (input)
1037 nlk_sk(sk)->data_ready = input;
1038
1039 if (netlink_insert(sk, 0)) {
1040 sock_release(sock);
1041 return NULL;
1042 }
1043 return sk;
1044}
1045
1046void netlink_set_nonroot(int protocol, unsigned int flags)
1047{
1048 if ((unsigned int)protocol < MAX_LINKS)
1049 nl_table[protocol].nl_nonroot = flags;
1050}
1051
1052static void netlink_destroy_callback(struct netlink_callback *cb)
1053{
1054 if (cb->skb)
1055 kfree_skb(cb->skb);
1056 kfree(cb);
1057}
1058
1059/*
1060 * It looks a bit ugly.
1061 * It would be better to create kernel thread.
1062 */
1063
1064static int netlink_dump(struct sock *sk)
1065{
1066 struct netlink_sock *nlk = nlk_sk(sk);
1067 struct netlink_callback *cb;
1068 struct sk_buff *skb;
1069 struct nlmsghdr *nlh;
1070 int len;
1071
1072 skb = sock_rmalloc(sk, NLMSG_GOODSIZE, 0, GFP_KERNEL);
1073 if (!skb)
1074 return -ENOBUFS;
1075
1076 spin_lock(&nlk->cb_lock);
1077
1078 cb = nlk->cb;
1079 if (cb == NULL) {
1080 spin_unlock(&nlk->cb_lock);
1081 kfree_skb(skb);
1082 return -EINVAL;
1083 }
1084
1085 len = cb->dump(skb, cb);
1086
1087 if (len > 0) {
1088 spin_unlock(&nlk->cb_lock);
1089 skb_queue_tail(&sk->sk_receive_queue, skb);
1090 sk->sk_data_ready(sk, len);
1091 return 0;
1092 }
1093
1094 nlh = __nlmsg_put(skb, NETLINK_CB(cb->skb).pid, cb->nlh->nlmsg_seq, NLMSG_DONE, sizeof(int));
1095 nlh->nlmsg_flags |= NLM_F_MULTI;
1096 memcpy(NLMSG_DATA(nlh), &len, sizeof(len));
1097 skb_queue_tail(&sk->sk_receive_queue, skb);
1098 sk->sk_data_ready(sk, skb->len);
1099
1100 cb->done(cb);
1101 nlk->cb = NULL;
1102 spin_unlock(&nlk->cb_lock);
1103
1104 netlink_destroy_callback(cb);
1da177e4
LT
1105 return 0;
1106}
1107
1108int netlink_dump_start(struct sock *ssk, struct sk_buff *skb,
1109 struct nlmsghdr *nlh,
1110 int (*dump)(struct sk_buff *skb, struct netlink_callback*),
1111 int (*done)(struct netlink_callback*))
1112{
1113 struct netlink_callback *cb;
1114 struct sock *sk;
1115 struct netlink_sock *nlk;
1116
1117 cb = kmalloc(sizeof(*cb), GFP_KERNEL);
1118 if (cb == NULL)
1119 return -ENOBUFS;
1120
1121 memset(cb, 0, sizeof(*cb));
1122 cb->dump = dump;
1123 cb->done = done;
1124 cb->nlh = nlh;
1125 atomic_inc(&skb->users);
1126 cb->skb = skb;
1127
1128 sk = netlink_lookup(ssk->sk_protocol, NETLINK_CB(skb).pid);
1129 if (sk == NULL) {
1130 netlink_destroy_callback(cb);
1131 return -ECONNREFUSED;
1132 }
1133 nlk = nlk_sk(sk);
1134 /* A dump is in progress... */
1135 spin_lock(&nlk->cb_lock);
1136 if (nlk->cb) {
1137 spin_unlock(&nlk->cb_lock);
1138 netlink_destroy_callback(cb);
1139 sock_put(sk);
1140 return -EBUSY;
1141 }
1142 nlk->cb = cb;
1da177e4
LT
1143 spin_unlock(&nlk->cb_lock);
1144
1145 netlink_dump(sk);
1146 sock_put(sk);
1147 return 0;
1148}
1149
1150void netlink_ack(struct sk_buff *in_skb, struct nlmsghdr *nlh, int err)
1151{
1152 struct sk_buff *skb;
1153 struct nlmsghdr *rep;
1154 struct nlmsgerr *errmsg;
1155 int size;
1156
1157 if (err == 0)
1158 size = NLMSG_SPACE(sizeof(struct nlmsgerr));
1159 else
1160 size = NLMSG_SPACE(4 + NLMSG_ALIGN(nlh->nlmsg_len));
1161
1162 skb = alloc_skb(size, GFP_KERNEL);
1163 if (!skb) {
1164 struct sock *sk;
1165
1166 sk = netlink_lookup(in_skb->sk->sk_protocol,
1167 NETLINK_CB(in_skb).pid);
1168 if (sk) {
1169 sk->sk_err = ENOBUFS;
1170 sk->sk_error_report(sk);
1171 sock_put(sk);
1172 }
1173 return;
1174 }
1175
1176 rep = __nlmsg_put(skb, NETLINK_CB(in_skb).pid, nlh->nlmsg_seq,
1177 NLMSG_ERROR, sizeof(struct nlmsgerr));
1178 errmsg = NLMSG_DATA(rep);
1179 errmsg->error = err;
1180 memcpy(&errmsg->msg, nlh, err ? nlh->nlmsg_len : sizeof(struct nlmsghdr));
1181 netlink_unicast(in_skb->sk, skb, NETLINK_CB(in_skb).pid, MSG_DONTWAIT);
1182}
1183
1184
1185#ifdef CONFIG_PROC_FS
1186struct nl_seq_iter {
1187 int link;
1188 int hash_idx;
1189};
1190
1191static struct sock *netlink_seq_socket_idx(struct seq_file *seq, loff_t pos)
1192{
1193 struct nl_seq_iter *iter = seq->private;
1194 int i, j;
1195 struct sock *s;
1196 struct hlist_node *node;
1197 loff_t off = 0;
1198
1199 for (i=0; i<MAX_LINKS; i++) {
1200 struct nl_pid_hash *hash = &nl_table[i].hash;
1201
1202 for (j = 0; j <= hash->mask; j++) {
1203 sk_for_each(s, node, &hash->table[j]) {
1204 if (off == pos) {
1205 iter->link = i;
1206 iter->hash_idx = j;
1207 return s;
1208 }
1209 ++off;
1210 }
1211 }
1212 }
1213 return NULL;
1214}
1215
1216static void *netlink_seq_start(struct seq_file *seq, loff_t *pos)
1217{
1218 read_lock(&nl_table_lock);
1219 return *pos ? netlink_seq_socket_idx(seq, *pos - 1) : SEQ_START_TOKEN;
1220}
1221
1222static void *netlink_seq_next(struct seq_file *seq, void *v, loff_t *pos)
1223{
1224 struct sock *s;
1225 struct nl_seq_iter *iter;
1226 int i, j;
1227
1228 ++*pos;
1229
1230 if (v == SEQ_START_TOKEN)
1231 return netlink_seq_socket_idx(seq, 0);
1232
1233 s = sk_next(v);
1234 if (s)
1235 return s;
1236
1237 iter = seq->private;
1238 i = iter->link;
1239 j = iter->hash_idx + 1;
1240
1241 do {
1242 struct nl_pid_hash *hash = &nl_table[i].hash;
1243
1244 for (; j <= hash->mask; j++) {
1245 s = sk_head(&hash->table[j]);
1246 if (s) {
1247 iter->link = i;
1248 iter->hash_idx = j;
1249 return s;
1250 }
1251 }
1252
1253 j = 0;
1254 } while (++i < MAX_LINKS);
1255
1256 return NULL;
1257}
1258
1259static void netlink_seq_stop(struct seq_file *seq, void *v)
1260{
1261 read_unlock(&nl_table_lock);
1262}
1263
1264
1265static int netlink_seq_show(struct seq_file *seq, void *v)
1266{
1267 if (v == SEQ_START_TOKEN)
1268 seq_puts(seq,
1269 "sk Eth Pid Groups "
1270 "Rmem Wmem Dump Locks\n");
1271 else {
1272 struct sock *s = v;
1273 struct netlink_sock *nlk = nlk_sk(s);
1274
1275 seq_printf(seq, "%p %-3d %-6d %08x %-8d %-8d %p %d\n",
1276 s,
1277 s->sk_protocol,
1278 nlk->pid,
1279 nlk->groups,
1280 atomic_read(&s->sk_rmem_alloc),
1281 atomic_read(&s->sk_wmem_alloc),
1282 nlk->cb,
1283 atomic_read(&s->sk_refcnt)
1284 );
1285
1286 }
1287 return 0;
1288}
1289
1290static struct seq_operations netlink_seq_ops = {
1291 .start = netlink_seq_start,
1292 .next = netlink_seq_next,
1293 .stop = netlink_seq_stop,
1294 .show = netlink_seq_show,
1295};
1296
1297
1298static int netlink_seq_open(struct inode *inode, struct file *file)
1299{
1300 struct seq_file *seq;
1301 struct nl_seq_iter *iter;
1302 int err;
1303
1304 iter = kmalloc(sizeof(*iter), GFP_KERNEL);
1305 if (!iter)
1306 return -ENOMEM;
1307
1308 err = seq_open(file, &netlink_seq_ops);
1309 if (err) {
1310 kfree(iter);
1311 return err;
1312 }
1313
1314 memset(iter, 0, sizeof(*iter));
1315 seq = file->private_data;
1316 seq->private = iter;
1317 return 0;
1318}
1319
1320static struct file_operations netlink_seq_fops = {
1321 .owner = THIS_MODULE,
1322 .open = netlink_seq_open,
1323 .read = seq_read,
1324 .llseek = seq_lseek,
1325 .release = seq_release_private,
1326};
1327
1328#endif
1329
1330int netlink_register_notifier(struct notifier_block *nb)
1331{
1332 return notifier_chain_register(&netlink_chain, nb);
1333}
1334
1335int netlink_unregister_notifier(struct notifier_block *nb)
1336{
1337 return notifier_chain_unregister(&netlink_chain, nb);
1338}
1339
1340static struct proto_ops netlink_ops = {
1341 .family = PF_NETLINK,
1342 .owner = THIS_MODULE,
1343 .release = netlink_release,
1344 .bind = netlink_bind,
1345 .connect = netlink_connect,
1346 .socketpair = sock_no_socketpair,
1347 .accept = sock_no_accept,
1348 .getname = netlink_getname,
1349 .poll = datagram_poll,
1350 .ioctl = sock_no_ioctl,
1351 .listen = sock_no_listen,
1352 .shutdown = sock_no_shutdown,
1353 .setsockopt = sock_no_setsockopt,
1354 .getsockopt = sock_no_getsockopt,
1355 .sendmsg = netlink_sendmsg,
1356 .recvmsg = netlink_recvmsg,
1357 .mmap = sock_no_mmap,
1358 .sendpage = sock_no_sendpage,
1359};
1360
1361static struct net_proto_family netlink_family_ops = {
1362 .family = PF_NETLINK,
1363 .create = netlink_create,
1364 .owner = THIS_MODULE, /* for consistency 8) */
1365};
1366
1367extern void netlink_skb_parms_too_large(void);
1368
1369static int __init netlink_proto_init(void)
1370{
1371 struct sk_buff *dummy_skb;
1372 int i;
1373 unsigned long max;
1374 unsigned int order;
1375 int err = proto_register(&netlink_proto, 0);
1376
1377 if (err != 0)
1378 goto out;
1379
1380 if (sizeof(struct netlink_skb_parms) > sizeof(dummy_skb->cb))
1381 netlink_skb_parms_too_large();
1382
1383 nl_table = kmalloc(sizeof(*nl_table) * MAX_LINKS, GFP_KERNEL);
1384 if (!nl_table) {
1385enomem:
1386 printk(KERN_CRIT "netlink_init: Cannot allocate nl_table\n");
1387 return -ENOMEM;
1388 }
1389
1390 memset(nl_table, 0, sizeof(*nl_table) * MAX_LINKS);
1391
1392 if (num_physpages >= (128 * 1024))
1393 max = num_physpages >> (21 - PAGE_SHIFT);
1394 else
1395 max = num_physpages >> (23 - PAGE_SHIFT);
1396
1397 order = get_bitmask_order(max) - 1 + PAGE_SHIFT;
1398 max = (1UL << order) / sizeof(struct hlist_head);
1399 order = get_bitmask_order(max > UINT_MAX ? UINT_MAX : max) - 1;
1400
1401 for (i = 0; i < MAX_LINKS; i++) {
1402 struct nl_pid_hash *hash = &nl_table[i].hash;
1403
1404 hash->table = nl_pid_hash_alloc(1 * sizeof(*hash->table));
1405 if (!hash->table) {
1406 while (i-- > 0)
1407 nl_pid_hash_free(nl_table[i].hash.table,
1408 1 * sizeof(*hash->table));
1409 kfree(nl_table);
1410 goto enomem;
1411 }
1412 memset(hash->table, 0, 1 * sizeof(*hash->table));
1413 hash->max_shift = order;
1414 hash->shift = 0;
1415 hash->mask = 0;
1416 hash->rehash_time = jiffies;
1417 }
1418
1419 sock_register(&netlink_family_ops);
1420#ifdef CONFIG_PROC_FS
1421 proc_net_fops_create("netlink", 0, &netlink_seq_fops);
1422#endif
1423 /* The netlink device handler may be needed early. */
1424 rtnetlink_init();
1425out:
1426 return err;
1427}
1428
1429static void __exit netlink_proto_exit(void)
1430{
1431 sock_unregister(PF_NETLINK);
1432 proc_net_remove("netlink");
1433 kfree(nl_table);
1434 nl_table = NULL;
1435 proto_unregister(&netlink_proto);
1436}
1437
1438core_initcall(netlink_proto_init);
1439module_exit(netlink_proto_exit);
1440
1441MODULE_LICENSE("GPL");
1442
1443MODULE_ALIAS_NETPROTO(PF_NETLINK);
1444
1445EXPORT_SYMBOL(netlink_ack);
1446EXPORT_SYMBOL(netlink_broadcast);
1447EXPORT_SYMBOL(netlink_dump_start);
1448EXPORT_SYMBOL(netlink_kernel_create);
1449EXPORT_SYMBOL(netlink_register_notifier);
1450EXPORT_SYMBOL(netlink_set_err);
1451EXPORT_SYMBOL(netlink_set_nonroot);
1452EXPORT_SYMBOL(netlink_unicast);
1453EXPORT_SYMBOL(netlink_unregister_notifier);
1454