gc.c 19.3 KB
Newer Older
T
Tetsuo Handa 已提交
1 2 3 4 5 6 7 8 9 10 11
/*
 * security/tomoyo/gc.c
 *
 * Implementation of the Domain-Based Mandatory Access Control.
 *
 * Copyright (C) 2005-2010  NTT DATA CORPORATION
 *
 */

#include "common.h"
#include <linux/kthread.h>
12
#include <linux/slab.h>
T
Tetsuo Handa 已提交
13

T
Tetsuo Handa 已提交
14 15 16 17 18 19 20 21 22 23 24 25 26 27
/* The list for "struct tomoyo_io_buffer". */
static LIST_HEAD(tomoyo_io_buffer_list);
/* Lock for protecting tomoyo_io_buffer_list. */
static DEFINE_SPINLOCK(tomoyo_io_buffer_list_lock);

/* Size of an element. */
static const u8 tomoyo_element_size[TOMOYO_MAX_POLICY] = {
	[TOMOYO_ID_GROUP] = sizeof(struct tomoyo_group),
	[TOMOYO_ID_PATH_GROUP] = sizeof(struct tomoyo_path_group),
	[TOMOYO_ID_NUMBER_GROUP] = sizeof(struct tomoyo_number_group),
	[TOMOYO_ID_AGGREGATOR] = sizeof(struct tomoyo_aggregator),
	[TOMOYO_ID_TRANSITION_CONTROL] =
	sizeof(struct tomoyo_transition_control),
	[TOMOYO_ID_MANAGER] = sizeof(struct tomoyo_manager),
28
	/* [TOMOYO_ID_CONDITION] = "struct tomoyo_condition"->size, */
T
Tetsuo Handa 已提交
29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121
	/* [TOMOYO_ID_NAME] = "struct tomoyo_name"->size, */
	/* [TOMOYO_ID_ACL] =
	   tomoyo_acl_size["struct tomoyo_acl_info"->type], */
	[TOMOYO_ID_DOMAIN] = sizeof(struct tomoyo_domain_info),
};

/* Size of a domain ACL element. */
static const u8 tomoyo_acl_size[] = {
	[TOMOYO_TYPE_PATH_ACL] = sizeof(struct tomoyo_path_acl),
	[TOMOYO_TYPE_PATH2_ACL] = sizeof(struct tomoyo_path2_acl),
	[TOMOYO_TYPE_PATH_NUMBER_ACL] = sizeof(struct tomoyo_path_number_acl),
	[TOMOYO_TYPE_MKDEV_ACL] = sizeof(struct tomoyo_mkdev_acl),
	[TOMOYO_TYPE_MOUNT_ACL] = sizeof(struct tomoyo_mount_acl),
};

/**
 * tomoyo_struct_used_by_io_buffer - Check whether the list element is used by /sys/kernel/security/tomoyo/ users or not.
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns true if @element is used by /sys/kernel/security/tomoyo/ users,
 * false otherwise.
 */
static bool tomoyo_struct_used_by_io_buffer(const struct list_head *element)
{
	struct tomoyo_io_buffer *head;
	bool in_use = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	list_for_each_entry(head, &tomoyo_io_buffer_list, list) {
		head->users++;
		spin_unlock(&tomoyo_io_buffer_list_lock);
		if (mutex_lock_interruptible(&head->io_sem)) {
			in_use = true;
			goto out;
		}
		if (head->r.domain == element || head->r.group == element ||
		    head->r.acl == element || &head->w.domain->list == element)
			in_use = true;
		mutex_unlock(&head->io_sem);
out:
		spin_lock(&tomoyo_io_buffer_list_lock);
		head->users--;
		if (in_use)
			break;
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	return in_use;
}

/**
 * tomoyo_name_used_by_io_buffer - Check whether the string is used by /sys/kernel/security/tomoyo/ users or not.
 *
 * @string: String to check.
 * @size:   Memory allocated for @string .
 *
 * Returns true if @string is used by /sys/kernel/security/tomoyo/ users,
 * false otherwise.
 */
static bool tomoyo_name_used_by_io_buffer(const char *string,
					  const size_t size)
{
	struct tomoyo_io_buffer *head;
	bool in_use = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	list_for_each_entry(head, &tomoyo_io_buffer_list, list) {
		int i;
		head->users++;
		spin_unlock(&tomoyo_io_buffer_list_lock);
		if (mutex_lock_interruptible(&head->io_sem)) {
			in_use = true;
			goto out;
		}
		for (i = 0; i < TOMOYO_MAX_IO_READ_QUEUE; i++) {
			const char *w = head->r.w[i];
			if (w < string || w > string + size)
				continue;
			in_use = true;
			break;
		}
		mutex_unlock(&head->io_sem);
out:
		spin_lock(&tomoyo_io_buffer_list_lock);
		head->users--;
		if (in_use)
			break;
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	return in_use;
}

/* Structure for garbage collection. */
T
Tetsuo Handa 已提交
122
struct tomoyo_gc {
T
Tetsuo Handa 已提交
123
	struct list_head list;
T
Tetsuo Handa 已提交
124
	enum tomoyo_policy_id type;
T
Tetsuo Handa 已提交
125
	size_t size;
126
	struct list_head *element;
T
Tetsuo Handa 已提交
127
};
T
Tetsuo Handa 已提交
128 129 130 131
/* List of entries to be deleted. */
static LIST_HEAD(tomoyo_gc_list);
/* Length of tomoyo_gc_list. */
static int tomoyo_gc_list_len;
T
Tetsuo Handa 已提交
132

T
Tetsuo Handa 已提交
133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150
/**
 * tomoyo_add_to_gc - Add an entry to to be deleted list.
 *
 * @type:    One of values in "enum tomoyo_policy_id".
 * @element: Pointer to "struct list_head".
 *
 * Returns true on success, false otherwise.
 *
 * Caller holds tomoyo_policy_lock mutex.
 *
 * Adding an entry needs kmalloc(). Thus, if we try to add thousands of
 * entries at once, it will take too long time. Thus, do not add more than 128
 * entries per a scan. But to be able to handle worst case where all entries
 * are in-use, we accept one more entry per a scan.
 *
 * If we use singly linked list using "struct list_head"->prev (which is
 * LIST_POISON2), we can avoid kmalloc().
 */
151
static bool tomoyo_add_to_gc(const int type, struct list_head *element)
T
Tetsuo Handa 已提交
152
{
T
Tetsuo Handa 已提交
153
	struct tomoyo_gc *entry = kzalloc(sizeof(*entry), GFP_ATOMIC);
T
Tetsuo Handa 已提交
154 155 156
	if (!entry)
		return false;
	entry->type = type;
T
Tetsuo Handa 已提交
157 158 159 160 161 162 163 164 165
	if (type == TOMOYO_ID_ACL)
		entry->size = tomoyo_acl_size[
			      container_of(element,
					   typeof(struct tomoyo_acl_info),
					   list)->type];
	else if (type == TOMOYO_ID_NAME)
		entry->size = strlen(container_of(element,
						  typeof(struct tomoyo_name),
						  head.list)->entry.name) + 1;
166 167 168 169
	else if (type == TOMOYO_ID_CONDITION)
		entry->size =
			container_of(element, typeof(struct tomoyo_condition),
				     head.list)->size;
T
Tetsuo Handa 已提交
170 171
	else
		entry->size = tomoyo_element_size[type];
T
Tetsuo Handa 已提交
172
	entry->element = element;
T
Tetsuo Handa 已提交
173
	list_add(&entry->list, &tomoyo_gc_list);
174
	list_del_rcu(element);
T
Tetsuo Handa 已提交
175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196
	return tomoyo_gc_list_len++ < 128;
}

/**
 * tomoyo_element_linked_by_gc - Validate next element of an entry.
 *
 * @element: Pointer to an element.
 * @size:    Size of @element in byte.
 *
 * Returns true if @element is linked by other elements in the garbage
 * collector's queue, false otherwise.
 */
static bool tomoyo_element_linked_by_gc(const u8 *element, const size_t size)
{
	struct tomoyo_gc *p;
	list_for_each_entry(p, &tomoyo_gc_list, list) {
		const u8 *ptr = (const u8 *) p->element->next;
		if (ptr < element || element + size < ptr)
			continue;
		return true;
	}
	return false;
T
Tetsuo Handa 已提交
197 198
}

T
Tetsuo Handa 已提交
199 200 201 202 203 204 205
/**
 * tomoyo_del_transition_control - Delete members in "struct tomoyo_transition_control".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
206
static void tomoyo_del_transition_control(struct list_head *element)
T
Tetsuo Handa 已提交
207
{
208
	struct tomoyo_transition_control *ptr =
209
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
210 211 212 213
	tomoyo_put_name(ptr->domainname);
	tomoyo_put_name(ptr->program);
}

T
Tetsuo Handa 已提交
214 215 216 217 218 219 220
/**
 * tomoyo_del_aggregator - Delete members in "struct tomoyo_aggregator".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
221
static void tomoyo_del_aggregator(struct list_head *element)
222
{
T
Tetsuo Handa 已提交
223
	struct tomoyo_aggregator *ptr =
224
		container_of(element, typeof(*ptr), head.list);
225 226 227 228
	tomoyo_put_name(ptr->original_name);
	tomoyo_put_name(ptr->aggregated_name);
}

T
Tetsuo Handa 已提交
229 230 231 232 233 234 235
/**
 * tomoyo_del_manager - Delete members in "struct tomoyo_manager".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
236
static void tomoyo_del_manager(struct list_head *element)
T
Tetsuo Handa 已提交
237
{
T
Tetsuo Handa 已提交
238
	struct tomoyo_manager *ptr =
239
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
240 241 242
	tomoyo_put_name(ptr->manager);
}

T
Tetsuo Handa 已提交
243 244 245 246 247 248 249
/**
 * tomoyo_del_acl - Delete members in "struct tomoyo_acl_info".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
250
static void tomoyo_del_acl(struct list_head *element)
T
Tetsuo Handa 已提交
251
{
252 253
	struct tomoyo_acl_info *acl =
		container_of(element, typeof(*acl), list);
254
	tomoyo_put_condition(acl->cond);
T
Tetsuo Handa 已提交
255
	switch (acl->type) {
T
Tetsuo Handa 已提交
256
	case TOMOYO_TYPE_PATH_ACL:
T
Tetsuo Handa 已提交
257
		{
T
Tetsuo Handa 已提交
258
			struct tomoyo_path_acl *entry
T
Tetsuo Handa 已提交
259
				= container_of(acl, typeof(*entry), head);
260
			tomoyo_put_name_union(&entry->name);
T
Tetsuo Handa 已提交
261 262
		}
		break;
T
Tetsuo Handa 已提交
263
	case TOMOYO_TYPE_PATH2_ACL:
T
Tetsuo Handa 已提交
264
		{
T
Tetsuo Handa 已提交
265
			struct tomoyo_path2_acl *entry
T
Tetsuo Handa 已提交
266
				= container_of(acl, typeof(*entry), head);
267 268
			tomoyo_put_name_union(&entry->name1);
			tomoyo_put_name_union(&entry->name2);
T
Tetsuo Handa 已提交
269 270
		}
		break;
271 272 273 274 275 276 277 278
	case TOMOYO_TYPE_PATH_NUMBER_ACL:
		{
			struct tomoyo_path_number_acl *entry
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->name);
			tomoyo_put_number_union(&entry->number);
		}
		break;
T
Tetsuo Handa 已提交
279
	case TOMOYO_TYPE_MKDEV_ACL:
280
		{
T
Tetsuo Handa 已提交
281
			struct tomoyo_mkdev_acl *entry
282 283 284 285 286 287 288
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->name);
			tomoyo_put_number_union(&entry->mode);
			tomoyo_put_number_union(&entry->major);
			tomoyo_put_number_union(&entry->minor);
		}
		break;
T
Tetsuo Handa 已提交
289 290 291 292 293 294 295 296 297 298
	case TOMOYO_TYPE_MOUNT_ACL:
		{
			struct tomoyo_mount_acl *entry
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->dev_name);
			tomoyo_put_name_union(&entry->dir_name);
			tomoyo_put_name_union(&entry->fs_type);
			tomoyo_put_number_union(&entry->flags);
		}
		break;
T
Tetsuo Handa 已提交
299 300 301
	}
}

T
Tetsuo Handa 已提交
302 303 304 305 306 307 308
/**
 * tomoyo_del_domain - Delete members in "struct tomoyo_domain_info".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns true if deleted, false otherwise.
 */
309
static bool tomoyo_del_domain(struct list_head *element)
T
Tetsuo Handa 已提交
310
{
311 312
	struct tomoyo_domain_info *domain =
		container_of(element, typeof(*domain), list);
T
Tetsuo Handa 已提交
313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339
	struct tomoyo_acl_info *acl;
	struct tomoyo_acl_info *tmp;
	/*
	 * Since we don't protect whole execve() operation using SRCU,
	 * we need to recheck domain->users at this point.
	 *
	 * (1) Reader starts SRCU section upon execve().
	 * (2) Reader traverses tomoyo_domain_list and finds this domain.
	 * (3) Writer marks this domain as deleted.
	 * (4) Garbage collector removes this domain from tomoyo_domain_list
	 *     because this domain is marked as deleted and used by nobody.
	 * (5) Reader saves reference to this domain into
	 *     "struct linux_binprm"->cred->security .
	 * (6) Reader finishes SRCU section, although execve() operation has
	 *     not finished yet.
	 * (7) Garbage collector waits for SRCU synchronization.
	 * (8) Garbage collector kfree() this domain because this domain is
	 *     used by nobody.
	 * (9) Reader finishes execve() operation and restores this domain from
	 *     "struct linux_binprm"->cred->security.
	 *
	 * By updating domain->users at (5), we can solve this race problem
	 * by rechecking domain->users at (8).
	 */
	if (atomic_read(&domain->users))
		return false;
	list_for_each_entry_safe(acl, tmp, &domain->acl_info_list, list) {
340
		tomoyo_del_acl(&acl->list);
T
Tetsuo Handa 已提交
341 342 343 344 345 346
		tomoyo_memory_free(acl);
	}
	tomoyo_put_name(domain->domainname);
	return true;
}

347 348 349 350 351 352 353 354 355 356 357 358 359
/**
 * tomoyo_del_condition - Delete members in "struct tomoyo_condition".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
void tomoyo_del_condition(struct list_head *element)
{
	struct tomoyo_condition *cond = container_of(element, typeof(*cond),
						     head.list);
	const u16 condc = cond->condc;
	const u16 numbers_count = cond->numbers_count;
360
	const u16 names_count = cond->names_count;
361 362 363 364 365
	unsigned int i;
	const struct tomoyo_condition_element *condp
		= (const struct tomoyo_condition_element *) (cond + 1);
	struct tomoyo_number_union *numbers_p
		= (struct tomoyo_number_union *) (condp + condc);
366 367
	struct tomoyo_name_union *names_p
		= (struct tomoyo_name_union *) (numbers_p + numbers_count);
368 369
	for (i = 0; i < numbers_count; i++)
		tomoyo_put_number_union(numbers_p++);
370 371
	for (i = 0; i < names_count; i++)
		tomoyo_put_name_union(names_p++);
372
}
T
Tetsuo Handa 已提交
373

T
Tetsuo Handa 已提交
374 375 376 377 378 379 380
/**
 * tomoyo_del_name - Delete members in "struct tomoyo_name".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
381
static void tomoyo_del_name(struct list_head *element)
T
Tetsuo Handa 已提交
382
{
T
Tetsuo Handa 已提交
383
	const struct tomoyo_name *ptr =
T
Tetsuo Handa 已提交
384
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
385 386
}

T
Tetsuo Handa 已提交
387 388 389 390 391 392 393
/**
 * tomoyo_del_path_group - Delete members in "struct tomoyo_path_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
394
static void tomoyo_del_path_group(struct list_head *element)
395
{
396
	struct tomoyo_path_group *member =
397
		container_of(element, typeof(*member), head.list);
398 399 400
	tomoyo_put_name(member->member_name);
}

T
Tetsuo Handa 已提交
401 402 403 404 405 406 407
/**
 * tomoyo_del_group - Delete "struct tomoyo_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
408
static void tomoyo_del_group(struct list_head *element)
409
{
410
	struct tomoyo_group *group =
T
Tetsuo Handa 已提交
411
		container_of(element, typeof(*group), head.list);
412 413 414
	tomoyo_put_name(group->group_name);
}

T
Tetsuo Handa 已提交
415 416 417 418 419 420 421
/**
 * tomoyo_del_number_group - Delete members in "struct tomoyo_number_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
422
static void tomoyo_del_number_group(struct list_head *element)
423
{
424 425
	struct tomoyo_number_group *member =
		container_of(element, typeof(*member), head.list);
426 427
}

T
Tetsuo Handa 已提交
428 429 430 431 432 433 434 435 436 437
/**
 * tomoyo_collect_member - Delete elements with "struct tomoyo_acl_head".
 *
 * @id:          One of values in "enum tomoyo_policy_id".
 * @member_list: Pointer to "struct list_head".
 *
 * Returns true if some elements are deleted, false otherwise.
 */
static bool tomoyo_collect_member(const enum tomoyo_policy_id id,
				  struct list_head *member_list)
438 439 440 441 442 443 444 445 446 447 448
{
	struct tomoyo_acl_head *member;
	list_for_each_entry(member, member_list, list) {
		if (!member->is_deleted)
			continue;
		if (!tomoyo_add_to_gc(id, &member->list))
			return false;
	}
        return true;
}

T
Tetsuo Handa 已提交
449 450 451 452 453 454 455 456
/**
 * tomoyo_collect_acl - Delete elements in "struct tomoyo_domain_info".
 *
 * @list: Pointer to "struct list_head".
 *
 * Returns true if some elements are deleted, false otherwise.
 */
static bool tomoyo_collect_acl(struct list_head *list)
457 458
{
	struct tomoyo_acl_info *acl;
T
Tetsuo Handa 已提交
459
	list_for_each_entry(acl, list, list) {
460 461 462 463 464 465 466 467
		if (!acl->is_deleted)
			continue;
		if (!tomoyo_add_to_gc(TOMOYO_ID_ACL, &acl->list))
			return false;
	}
	return true;
}

T
Tetsuo Handa 已提交
468 469 470 471 472
/**
 * tomoyo_collect_entry - Scan lists for deleted elements.
 *
 * Returns nothing.
 */
T
Tetsuo Handa 已提交
473 474
static void tomoyo_collect_entry(void)
{
475
	int i;
476 477 478
	enum tomoyo_policy_id id;
	struct tomoyo_policy_namespace *ns;
	int idx;
479 480
	if (mutex_lock_interruptible(&tomoyo_policy_lock))
		return;
481
	idx = tomoyo_read_lock();
T
Tetsuo Handa 已提交
482 483 484
	{
		struct tomoyo_domain_info *domain;
		list_for_each_entry_rcu(domain, &tomoyo_domain_list, list) {
T
Tetsuo Handa 已提交
485
			if (!tomoyo_collect_acl(&domain->acl_info_list))
486
				goto unlock;
T
Tetsuo Handa 已提交
487 488 489 490 491 492 493
			if (!domain->is_deleted || atomic_read(&domain->users))
				continue;
			/*
			 * Nobody is referring this domain. But somebody may
			 * refer this domain after successful execve().
			 * We recheck domain->users after SRCU synchronization.
			 */
494
			if (!tomoyo_add_to_gc(TOMOYO_ID_DOMAIN, &domain->list))
495
				goto unlock;
T
Tetsuo Handa 已提交
496 497
		}
	}
498 499 500
	list_for_each_entry_rcu(ns, &tomoyo_namespace_list, namespace_list) {
		for (id = 0; id < TOMOYO_MAX_POLICY; id++)
			if (!tomoyo_collect_member(id, &ns->policy_list[id]))
501
				goto unlock;
502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526
		for (i = 0; i < TOMOYO_MAX_ACL_GROUPS; i++)
			if (!tomoyo_collect_acl(&ns->acl_group[i]))
				goto unlock;
		for (i = 0; i < TOMOYO_MAX_GROUP; i++) {
			struct list_head *list = &ns->group_list[i];
			struct tomoyo_group *group;
			switch (i) {
			case 0:
				id = TOMOYO_ID_PATH_GROUP;
				break;
			default:
				id = TOMOYO_ID_NUMBER_GROUP;
				break;
			}
			list_for_each_entry(group, list, head.list) {
				if (!tomoyo_collect_member
				    (id, &group->member_list))
					goto unlock;
				if (!list_empty(&group->member_list) ||
				    atomic_read(&group->head.users))
					continue;
				if (!tomoyo_add_to_gc(TOMOYO_ID_GROUP,
						      &group->head.list))
					goto unlock;
			}
T
Tetsuo Handa 已提交
527 528
		}
	}
529 530 531 532
	id = TOMOYO_ID_CONDITION;
	for (i = 0; i < TOMOYO_MAX_HASH + 1; i++) {
		struct list_head *list = !i ?
			&tomoyo_condition_list : &tomoyo_name_list[i - 1];
533 534 535
		struct tomoyo_shared_acl_head *ptr;
		list_for_each_entry(ptr, list, list) {
			if (atomic_read(&ptr->users))
536
				continue;
537
			if (!tomoyo_add_to_gc(id, &ptr->list))
538
				goto unlock;
539
		}
540
		id = TOMOYO_ID_NAME;
541
	}
542 543
unlock:
	tomoyo_read_unlock(idx);
544
	mutex_unlock(&tomoyo_policy_lock);
T
Tetsuo Handa 已提交
545 546
}

T
Tetsuo Handa 已提交
547 548 549 550 551 552
/**
 * tomoyo_kfree_entry - Delete entries in tomoyo_gc_list.
 *
 * Returns true if some entries were kfree()d, false otherwise.
 */
static bool tomoyo_kfree_entry(void)
T
Tetsuo Handa 已提交
553
{
T
Tetsuo Handa 已提交
554 555
	struct tomoyo_gc *p;
	struct tomoyo_gc *tmp;
T
Tetsuo Handa 已提交
556
	bool result = false;
T
Tetsuo Handa 已提交
557

T
Tetsuo Handa 已提交
558
	list_for_each_entry_safe(p, tmp, &tomoyo_gc_list, list) {
559
		struct list_head *element = p->element;
T
Tetsuo Handa 已提交
560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584

		/*
		 * list_del_rcu() in tomoyo_add_to_gc() guarantees that the
		 * list element became no longer reachable from the list which
		 * the element was originally on (e.g. tomoyo_domain_list).
		 * Also, synchronize_srcu() in tomoyo_gc_thread() guarantees
		 * that the list element became no longer referenced by syscall
		 * users.
		 *
		 * However, there are three users which may still be using the
		 * list element. We need to defer until all of these users
		 * forget the list element.
		 *
		 * Firstly, defer until "struct tomoyo_io_buffer"->r.{domain,
		 * group,acl} and "struct tomoyo_io_buffer"->w.domain forget
		 * the list element.
		 */
		if (tomoyo_struct_used_by_io_buffer(element))
			continue;
		/*
		 * Secondly, defer until all other elements in the
		 * tomoyo_gc_list list forget the list element.
		 */
		if (tomoyo_element_linked_by_gc((const u8 *) element, p->size))
			continue;
T
Tetsuo Handa 已提交
585
		switch (p->type) {
586 587
		case TOMOYO_ID_TRANSITION_CONTROL:
			tomoyo_del_transition_control(element);
T
Tetsuo Handa 已提交
588
			break;
589
		case TOMOYO_ID_AGGREGATOR:
590
			tomoyo_del_aggregator(element);
591
			break;
T
Tetsuo Handa 已提交
592
		case TOMOYO_ID_MANAGER:
593
			tomoyo_del_manager(element);
T
Tetsuo Handa 已提交
594
			break;
595 596 597
		case TOMOYO_ID_CONDITION:
			tomoyo_del_condition(element);
			break;
T
Tetsuo Handa 已提交
598
		case TOMOYO_ID_NAME:
T
Tetsuo Handa 已提交
599 600 601 602 603 604 605 606
			/*
			 * Thirdly, defer until all "struct tomoyo_io_buffer"
			 * ->r.w[] forget the list element.
			 */
			if (tomoyo_name_used_by_io_buffer(
			    container_of(element, typeof(struct tomoyo_name),
					 head.list)->entry.name, p->size))
				continue;
607
			tomoyo_del_name(element);
T
Tetsuo Handa 已提交
608 609
			break;
		case TOMOYO_ID_ACL:
610
			tomoyo_del_acl(element);
T
Tetsuo Handa 已提交
611 612
			break;
		case TOMOYO_ID_DOMAIN:
613
			if (!tomoyo_del_domain(element))
T
Tetsuo Handa 已提交
614 615
				continue;
			break;
616
		case TOMOYO_ID_PATH_GROUP:
617
			tomoyo_del_path_group(element);
618
			break;
619 620
		case TOMOYO_ID_GROUP:
			tomoyo_del_group(element);
621 622
			break;
		case TOMOYO_ID_NUMBER_GROUP:
623
			tomoyo_del_number_group(element);
T
Tetsuo Handa 已提交
624
			break;
T
Tetsuo Handa 已提交
625 626
		case TOMOYO_MAX_POLICY:
			break;
T
Tetsuo Handa 已提交
627
		}
628
		tomoyo_memory_free(element);
T
Tetsuo Handa 已提交
629 630
		list_del(&p->list);
		kfree(p);
T
Tetsuo Handa 已提交
631 632
		tomoyo_gc_list_len--;
		result = true;
T
Tetsuo Handa 已提交
633
	}
T
Tetsuo Handa 已提交
634
	return result;
T
Tetsuo Handa 已提交
635 636
}

T
Tetsuo Handa 已提交
637 638 639 640 641 642 643 644 645 646 647
/**
 * tomoyo_gc_thread - Garbage collector thread function.
 *
 * @unused: Unused.
 *
 * In case OOM-killer choose this thread for termination, we create this thread
 * as a short live thread whenever /sys/kernel/security/tomoyo/ interface was
 * close()d.
 *
 * Returns 0.
 */
T
Tetsuo Handa 已提交
648 649
static int tomoyo_gc_thread(void *unused)
{
T
Tetsuo Handa 已提交
650 651 652 653
	/* Garbage collector thread is exclusive. */
	static DEFINE_MUTEX(tomoyo_gc_mutex);
	if (!mutex_trylock(&tomoyo_gc_mutex))
		goto out;
T
Tetsuo Handa 已提交
654
	daemonize("GC for TOMOYO");
T
Tetsuo Handa 已提交
655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673
	do {
		tomoyo_collect_entry();
		if (list_empty(&tomoyo_gc_list))
			break;
		synchronize_srcu(&tomoyo_ss);
	} while (tomoyo_kfree_entry());
	{
		struct tomoyo_io_buffer *head;
		struct tomoyo_io_buffer *tmp;

		spin_lock(&tomoyo_io_buffer_list_lock);
		list_for_each_entry_safe(head, tmp, &tomoyo_io_buffer_list,
					 list) {
			if (head->users)
				continue;
			list_del(&head->list);
			kfree(head->read_buf);
			kfree(head->write_buf);
			kfree(head);
T
Tetsuo Handa 已提交
674
		}
T
Tetsuo Handa 已提交
675
		spin_unlock(&tomoyo_io_buffer_list_lock);
T
Tetsuo Handa 已提交
676
	}
T
Tetsuo Handa 已提交
677 678 679 680
	mutex_unlock(&tomoyo_gc_mutex);
out:
	/* This acts as do_exit(0). */
	return 0;
T
Tetsuo Handa 已提交
681 682
}

T
Tetsuo Handa 已提交
683 684 685 686 687 688 689 690 691
/**
 * tomoyo_notify_gc - Register/unregister /sys/kernel/security/tomoyo/ users.
 *
 * @head:        Pointer to "struct tomoyo_io_buffer".
 * @is_register: True if register, false if unregister.
 *
 * Returns nothing.
 */
void tomoyo_notify_gc(struct tomoyo_io_buffer *head, const bool is_register)
T
Tetsuo Handa 已提交
692
{
T
Tetsuo Handa 已提交
693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715
	bool is_write = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	if (is_register) {
		head->users = 1;
		list_add(&head->list, &tomoyo_io_buffer_list);
	} else {
		is_write = head->write_buf != NULL;
		if (!--head->users) {
			list_del(&head->list);
			kfree(head->read_buf);
			kfree(head->write_buf);
			kfree(head);
		}
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	if (is_write) {
		struct task_struct *task = kthread_create(tomoyo_gc_thread,
							  NULL,
							  "GC for TOMOYO");
		if (!IS_ERR(task))
			wake_up_process(task);
	}
T
Tetsuo Handa 已提交
716
}