cmd-filter.c 5.4 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28
/*
 * Copyright 2004 Peter M. Jones <pjones@redhat.com>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 *
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public Licens
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-
 *
 */

#include <linux/list.h>
#include <linux/genhd.h>
#include <linux/spinlock.h>
#include <linux/capability.h>
#include <linux/bitops.h>

#include <scsi/scsi.h>
#include <linux/cdrom.h>

29
int blk_verify_command(struct blk_cmd_filter *filter,
30
		       unsigned char *cmd, int has_write_perm)
31 32 33 34 35 36 37 38 39 40 41 42 43 44
{
	/* root can do any command. */
	if (capable(CAP_SYS_RAWIO))
		return 0;

	/* if there's no filter set, assume we're filtering everything out */
	if (!filter)
		return -EPERM;

	/* Anybody who can open the device can do a read-safe command */
	if (test_bit(cmd[0], filter->read_ok))
		return 0;

	/* Write-safe commands require a writable open */
45
	if (test_bit(cmd[0], filter->write_ok) && has_write_perm)
46 47 48 49 50 51
		return 0;

	return -EPERM;
}
EXPORT_SYMBOL(blk_verify_command);

52
#if 0
53
/* and now, the sysfs stuff */
54
static ssize_t rcf_cmds_show(struct blk_cmd_filter *filter, char *page,
55 56 57 58 59 60 61 62 63 64 65 66 67
			     int rw)
{
	char *npage = page;
	unsigned long *okbits;
	int i;

	if (rw == READ)
		okbits = filter->read_ok;
	else
		okbits = filter->write_ok;

	for (i = 0; i < BLK_SCSI_MAX_CMDS; i++) {
		if (test_bit(i, okbits)) {
68
			npage += sprintf(npage, "0x%02x", i);
69 70 71 72 73 74 75 76 77 78 79
			if (i < BLK_SCSI_MAX_CMDS - 1)
				sprintf(npage++, " ");
		}
	}

	if (npage != page)
		npage += sprintf(npage, "\n");

	return npage - page;
}

80
static ssize_t rcf_readcmds_show(struct blk_cmd_filter *filter, char *page)
81 82 83 84
{
	return rcf_cmds_show(filter, page, READ);
}

85
static ssize_t rcf_writecmds_show(struct blk_cmd_filter *filter,
86 87 88 89 90
				 char *page)
{
	return rcf_cmds_show(filter, page, WRITE);
}

91
static ssize_t rcf_cmds_store(struct blk_cmd_filter *filter,
92 93 94
			      const char *page, size_t count, int rw)
{
	unsigned long okbits[BLK_SCSI_CMD_PER_LONG], *target_okbits;
95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117
	int cmd, set;
	char *p, *status;

	if (rw == READ) {
		memcpy(&okbits, filter->read_ok, sizeof(okbits));
		target_okbits = filter->read_ok;
	} else {
		memcpy(&okbits, filter->write_ok, sizeof(okbits));
		target_okbits = filter->write_ok;
	}

	while ((p = strsep((char **)&page, " ")) != NULL) {
		set = 1;

		if (p[0] == '+') {
			p++;
		} else if (p[0] == '-') {
			set = 0;
			p++;
		}

		cmd = simple_strtol(p, &status, 16);

118
		/* either of these cases means invalid input, so do nothing. */
119
		if ((status == p) || cmd >= BLK_SCSI_MAX_CMDS)
120 121
			return -EINVAL;

122 123 124 125
		if (set)
			__set_bit(cmd, okbits);
		else
			__clear_bit(cmd, okbits);
126 127
	}

128
	memcpy(target_okbits, okbits, sizeof(okbits));
129 130 131
	return count;
}

132
static ssize_t rcf_readcmds_store(struct blk_cmd_filter *filter,
133 134 135 136 137
				  const char *page, size_t count)
{
	return rcf_cmds_store(filter, page, count, READ);
}

138
static ssize_t rcf_writecmds_store(struct blk_cmd_filter *filter,
139 140 141 142 143 144 145
				   const char *page, size_t count)
{
	return rcf_cmds_store(filter, page, count, WRITE);
}

struct rcf_sysfs_entry {
	struct attribute attr;
146 147
	ssize_t (*show)(struct blk_cmd_filter *, char *);
	ssize_t (*store)(struct blk_cmd_filter *, const char *, size_t);
148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173
};

static struct rcf_sysfs_entry rcf_readcmds_entry = {
	.attr = { .name = "read_table", .mode = S_IRUGO | S_IWUSR },
	.show = rcf_readcmds_show,
	.store = rcf_readcmds_store,
};

static struct rcf_sysfs_entry rcf_writecmds_entry = {
	.attr = {.name = "write_table", .mode = S_IRUGO | S_IWUSR },
	.show = rcf_writecmds_show,
	.store = rcf_writecmds_store,
};

static struct attribute *default_attrs[] = {
	&rcf_readcmds_entry.attr,
	&rcf_writecmds_entry.attr,
	NULL,
};

#define to_rcf(atr) container_of((atr), struct rcf_sysfs_entry, attr)

static ssize_t
rcf_attr_show(struct kobject *kobj, struct attribute *attr, char *page)
{
	struct rcf_sysfs_entry *entry = to_rcf(attr);
174
	struct blk_cmd_filter *filter;
175

176
	filter = container_of(kobj, struct blk_cmd_filter, kobj);
177 178 179 180 181 182 183 184 185 186 187
	if (entry->show)
		return entry->show(filter, page);

	return 0;
}

static ssize_t
rcf_attr_store(struct kobject *kobj, struct attribute *attr,
			const char *page, size_t length)
{
	struct rcf_sysfs_entry *entry = to_rcf(attr);
188
	struct blk_cmd_filter *filter;
189 190 191 192 193 194 195

	if (!capable(CAP_SYS_RAWIO))
		return -EPERM;

	if (!entry->store)
		return -EINVAL;

196
	filter = container_of(kobj, struct blk_cmd_filter, kobj);
197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212
	return entry->store(filter, page, length);
}

static struct sysfs_ops rcf_sysfs_ops = {
	.show = rcf_attr_show,
	.store = rcf_attr_store,
};

static struct kobj_type rcf_ktype = {
	.sysfs_ops = &rcf_sysfs_ops,
	.default_attrs = default_attrs,
};

int blk_register_filter(struct gendisk *disk)
{
	int ret;
213
	struct blk_cmd_filter *filter = &disk->queue->cmd_filter;
214

215 216
	ret = kobject_init_and_add(&filter->kobj, &rcf_ktype,
				   &disk_to_dev(disk)->kobj,
217
				   "%s", "cmd_filter");
218 219 220 221 222
	if (ret < 0)
		return ret;

	return 0;
}
223
EXPORT_SYMBOL(blk_register_filter);
224 225 226

void blk_unregister_filter(struct gendisk *disk)
{
227
	struct blk_cmd_filter *filter = &disk->queue->cmd_filter;
228 229 230

	kobject_put(&filter->kobj);
}
231
EXPORT_SYMBOL(blk_unregister_filter);
232
#endif