af_netlink.c 61.7 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3
/*
 * NETLINK      Kernel-user communication protocol.
 *
4
 * 		Authors:	Alan Cox <alan@lxorguk.ukuu.org.uk>
L
Linus Torvalds 已提交
5
 * 				Alexey Kuznetsov <kuznet@ms2.inr.ac.ru>
6
 * 				Patrick McHardy <kaber@trash.net>
L
Linus Torvalds 已提交
7 8 9 10 11
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
12
 *
L
Linus Torvalds 已提交
13 14 15 16
 * Tue Jun 26 14:36:48 MEST 2001 Herbert "herp" Rosmanith
 *                               added netlink_proto_exit
 * Tue Jan 22 18:32:44 BRST 2002 Arnaldo C. de Melo <acme@conectiva.com.br>
 * 				 use nlk_sk, as sk->protinfo is on a diet 8)
17 18 19 20 21 22
 * Fri Jul 22 19:51:12 MEST 2005 Harald Welte <laforge@gnumonks.org>
 * 				 - inc module use count of module that owns
 * 				   the kernel socket in case userspace opens
 * 				   socket of same protocol
 * 				 - remove all module support, since netlink is
 * 				   mandatory if CONFIG_NET=y these days
L
Linus Torvalds 已提交
23 24 25 26
 */

#include <linux/module.h>

27
#include <linux/capability.h>
L
Linus Torvalds 已提交
28 29 30 31 32 33 34 35 36 37 38 39 40 41 42
#include <linux/kernel.h>
#include <linux/init.h>
#include <linux/signal.h>
#include <linux/sched.h>
#include <linux/errno.h>
#include <linux/string.h>
#include <linux/stat.h>
#include <linux/socket.h>
#include <linux/un.h>
#include <linux/fcntl.h>
#include <linux/termios.h>
#include <linux/sockios.h>
#include <linux/net.h>
#include <linux/fs.h>
#include <linux/slab.h>
43
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
44 45 46 47 48 49 50 51 52 53 54 55 56
#include <linux/skbuff.h>
#include <linux/netdevice.h>
#include <linux/rtnetlink.h>
#include <linux/proc_fs.h>
#include <linux/seq_file.h>
#include <linux/notifier.h>
#include <linux/security.h>
#include <linux/jhash.h>
#include <linux/jiffies.h>
#include <linux/random.h>
#include <linux/bitops.h>
#include <linux/mm.h>
#include <linux/types.h>
A
Andrew Morton 已提交
57
#include <linux/audit.h>
58
#include <linux/mutex.h>
59
#include <linux/vmalloc.h>
60
#include <linux/if_arp.h>
61
#include <linux/rhashtable.h>
62
#include <asm/cacheflush.h>
63
#include <linux/hash.h>
64
#include <linux/genetlink.h>
A
Andrew Morton 已提交
65

66
#include <net/net_namespace.h>
L
Linus Torvalds 已提交
67 68
#include <net/sock.h>
#include <net/scm.h>
69
#include <net/netlink.h>
L
Linus Torvalds 已提交
70

71
#include "af_netlink.h"
L
Linus Torvalds 已提交
72

73 74 75
struct listeners {
	struct rcu_head		rcu;
	unsigned long		masks[0];
76 77
};

78
/* state bits */
79
#define NETLINK_S_CONGESTED		0x0
80

81
static inline int netlink_is_kernel(struct sock *sk)
82
{
83
	return nlk_sk(sk)->flags & NETLINK_F_KERNEL_SOCKET;
84 85
}

86
struct netlink_table *nl_table __read_mostly;
87
EXPORT_SYMBOL_GPL(nl_table);
L
Linus Torvalds 已提交
88 89 90

static DECLARE_WAIT_QUEUE_HEAD(nl_table_wait);

91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128
static struct lock_class_key nlk_cb_mutex_keys[MAX_LINKS];

static const char *const nlk_cb_mutex_key_strings[MAX_LINKS + 1] = {
	"nlk_cb_mutex-ROUTE",
	"nlk_cb_mutex-1",
	"nlk_cb_mutex-USERSOCK",
	"nlk_cb_mutex-FIREWALL",
	"nlk_cb_mutex-SOCK_DIAG",
	"nlk_cb_mutex-NFLOG",
	"nlk_cb_mutex-XFRM",
	"nlk_cb_mutex-SELINUX",
	"nlk_cb_mutex-ISCSI",
	"nlk_cb_mutex-AUDIT",
	"nlk_cb_mutex-FIB_LOOKUP",
	"nlk_cb_mutex-CONNECTOR",
	"nlk_cb_mutex-NETFILTER",
	"nlk_cb_mutex-IP6_FW",
	"nlk_cb_mutex-DNRTMSG",
	"nlk_cb_mutex-KOBJECT_UEVENT",
	"nlk_cb_mutex-GENERIC",
	"nlk_cb_mutex-17",
	"nlk_cb_mutex-SCSITRANSPORT",
	"nlk_cb_mutex-ECRYPTFS",
	"nlk_cb_mutex-RDMA",
	"nlk_cb_mutex-CRYPTO",
	"nlk_cb_mutex-SMC",
	"nlk_cb_mutex-23",
	"nlk_cb_mutex-24",
	"nlk_cb_mutex-25",
	"nlk_cb_mutex-26",
	"nlk_cb_mutex-27",
	"nlk_cb_mutex-28",
	"nlk_cb_mutex-29",
	"nlk_cb_mutex-30",
	"nlk_cb_mutex-31",
	"nlk_cb_mutex-MAX_LINKS"
};

L
Linus Torvalds 已提交
129
static int netlink_dump(struct sock *sk);
130
static void netlink_skb_destructor(struct sk_buff *skb);
L
Linus Torvalds 已提交
131

132
/* nl_table locking explained:
133
 * Lookup and traversal are protected with an RCU read-side lock. Insertion
Y
Ying Xue 已提交
134
 * and removal are protected with per bucket lock while using RCU list
135 136 137 138
 * modification primitives and may run in parallel to RCU protected lookups.
 * Destruction of the Netlink socket may only occur *after* nl_table_lock has
 * been acquired * either during or after the socket has been removed from
 * the list and after an RCU grace period.
139
 */
140 141
DEFINE_RWLOCK(nl_table_lock);
EXPORT_SYMBOL_GPL(nl_table_lock);
L
Linus Torvalds 已提交
142 143
static atomic_t nl_table_users = ATOMIC_INIT(0);

144 145
#define nl_deref_protected(X) rcu_dereference_protected(X, lockdep_is_held(&nl_table_lock));

W
WANG Cong 已提交
146
static BLOCKING_NOTIFIER_HEAD(netlink_chain);
L
Linus Torvalds 已提交
147

148 149 150
static DEFINE_SPINLOCK(netlink_tap_lock);
static struct list_head netlink_tap_all __read_mostly;

151 152
static const struct rhashtable_params netlink_rhashtable_params;

153
static inline u32 netlink_group_mask(u32 group)
154 155 156 157
{
	return group ? 1 << (group - 1) : 0;
}

158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175
static struct sk_buff *netlink_to_full_skb(const struct sk_buff *skb,
					   gfp_t gfp_mask)
{
	unsigned int len = skb_end_offset(skb);
	struct sk_buff *new;

	new = alloc_skb(len, gfp_mask);
	if (new == NULL)
		return NULL;

	NETLINK_CB(new).portid = NETLINK_CB(skb).portid;
	NETLINK_CB(new).dst_group = NETLINK_CB(skb).dst_group;
	NETLINK_CB(new).creds = NETLINK_CB(skb).creds;

	memcpy(skb_put(new, len), skb->data, len);
	return new;
}

176 177 178 179 180 181 182 183 184
int netlink_add_tap(struct netlink_tap *nt)
{
	if (unlikely(nt->dev->type != ARPHRD_NETLINK))
		return -EINVAL;

	spin_lock(&netlink_tap_lock);
	list_add_rcu(&nt->list, &netlink_tap_all);
	spin_unlock(&netlink_tap_lock);

185
	__module_get(nt->module);
186 187 188 189 190

	return 0;
}
EXPORT_SYMBOL_GPL(netlink_add_tap);

191
static int __netlink_remove_tap(struct netlink_tap *nt)
192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209
{
	bool found = false;
	struct netlink_tap *tmp;

	spin_lock(&netlink_tap_lock);

	list_for_each_entry(tmp, &netlink_tap_all, list) {
		if (nt == tmp) {
			list_del_rcu(&nt->list);
			found = true;
			goto out;
		}
	}

	pr_warn("__netlink_remove_tap: %p not found\n", nt);
out:
	spin_unlock(&netlink_tap_lock);

210
	if (found)
211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226
		module_put(nt->module);

	return found ? 0 : -ENODEV;
}

int netlink_remove_tap(struct netlink_tap *nt)
{
	int ret;

	ret = __netlink_remove_tap(nt);
	synchronize_net();

	return ret;
}
EXPORT_SYMBOL_GPL(netlink_remove_tap);

227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242
static bool netlink_filter_tap(const struct sk_buff *skb)
{
	struct sock *sk = skb->sk;

	/* We take the more conservative approach and
	 * whitelist socket protocols that may pass.
	 */
	switch (sk->sk_protocol) {
	case NETLINK_ROUTE:
	case NETLINK_USERSOCK:
	case NETLINK_SOCK_DIAG:
	case NETLINK_NFLOG:
	case NETLINK_XFRM:
	case NETLINK_FIB_LOOKUP:
	case NETLINK_NETFILTER:
	case NETLINK_GENERIC:
V
Varka Bhadram 已提交
243
		return true;
244 245
	}

V
Varka Bhadram 已提交
246
	return false;
247 248
}

249 250 251 252
static int __netlink_deliver_tap_skb(struct sk_buff *skb,
				     struct net_device *dev)
{
	struct sk_buff *nskb;
253
	struct sock *sk = skb->sk;
254 255 256
	int ret = -ENOMEM;

	dev_hold(dev);
257

258
	if (is_vmalloc_addr(skb->head))
259 260 261
		nskb = netlink_to_full_skb(skb, GFP_ATOMIC);
	else
		nskb = skb_clone(skb, GFP_ATOMIC);
262 263
	if (nskb) {
		nskb->dev = dev;
264
		nskb->protocol = htons((u16) sk->sk_protocol);
265 266
		nskb->pkt_type = netlink_is_kernel(sk) ?
				 PACKET_KERNEL : PACKET_USER;
267
		skb_reset_network_header(nskb);
268 269 270 271 272 273 274 275 276 277 278 279 280 281
		ret = dev_queue_xmit(nskb);
		if (unlikely(ret > 0))
			ret = net_xmit_errno(ret);
	}

	dev_put(dev);
	return ret;
}

static void __netlink_deliver_tap(struct sk_buff *skb)
{
	int ret;
	struct netlink_tap *tmp;

282 283 284
	if (!netlink_filter_tap(skb))
		return;

285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301
	list_for_each_entry_rcu(tmp, &netlink_tap_all, list) {
		ret = __netlink_deliver_tap_skb(skb, tmp->dev);
		if (unlikely(ret))
			break;
	}
}

static void netlink_deliver_tap(struct sk_buff *skb)
{
	rcu_read_lock();

	if (unlikely(!list_empty(&netlink_tap_all)))
		__netlink_deliver_tap(skb);

	rcu_read_unlock();
}

302 303 304 305 306 307 308
static void netlink_deliver_tap_kernel(struct sock *dst, struct sock *src,
				       struct sk_buff *skb)
{
	if (!(netlink_is_kernel(dst) && netlink_is_kernel(src)))
		netlink_deliver_tap(skb);
}

309 310 311 312
static void netlink_overrun(struct sock *sk)
{
	struct netlink_sock *nlk = nlk_sk(sk);

313 314 315
	if (!(nlk->flags & NETLINK_F_RECV_NO_ENOBUFS)) {
		if (!test_and_set_bit(NETLINK_S_CONGESTED,
				      &nlk_sk(sk)->state)) {
316 317 318 319 320 321 322 323 324 325 326 327
			sk->sk_err = ENOBUFS;
			sk->sk_error_report(sk);
		}
	}
	atomic_inc(&sk->sk_drops);
}

static void netlink_rcv_wake(struct sock *sk)
{
	struct netlink_sock *nlk = nlk_sk(sk);

	if (skb_queue_empty(&sk->sk_receive_queue))
328 329
		clear_bit(NETLINK_S_CONGESTED, &nlk->state);
	if (!test_bit(NETLINK_S_CONGESTED, &nlk->state))
330 331 332
		wake_up_interruptible(&nlk->wait);
}

333 334
static void netlink_skb_destructor(struct sk_buff *skb)
{
335
	if (is_vmalloc_addr(skb->head)) {
336 337 338 339
		if (!skb->cloned ||
		    !atomic_dec_return(&(skb_shinfo(skb)->dataref)))
			vfree(skb->head);

340 341
		skb->head = NULL;
	}
342 343
	if (skb->sk != NULL)
		sock_rfree(skb);
344 345 346 347 348 349 350 351 352 353 354
}

static void netlink_skb_set_owner_r(struct sk_buff *skb, struct sock *sk)
{
	WARN_ON(skb->sk != NULL);
	skb->sk = sk;
	skb->destructor = netlink_skb_destructor;
	atomic_add(skb->truesize, &sk->sk_rmem_alloc);
	sk_mem_charge(sk, skb->truesize);
}

355
static void netlink_sock_destruct(struct sock *sk)
L
Linus Torvalds 已提交
356
{
357 358
	struct netlink_sock *nlk = nlk_sk(sk);

359
	if (nlk->cb_running) {
360 361
		if (nlk->cb.done)
			nlk->cb.done(&nlk->cb);
362 363
		module_put(nlk->cb.module);
		kfree_skb(nlk->cb.skb);
364 365
	}

L
Linus Torvalds 已提交
366 367 368
	skb_queue_purge(&sk->sk_receive_queue);

	if (!sock_flag(sk, SOCK_DEAD)) {
369
		printk(KERN_ERR "Freeing alive netlink socket %p\n", sk);
L
Linus Torvalds 已提交
370 371
		return;
	}
372 373 374 375

	WARN_ON(atomic_read(&sk->sk_rmem_alloc));
	WARN_ON(atomic_read(&sk->sk_wmem_alloc));
	WARN_ON(nlk_sk(sk)->groups);
L
Linus Torvalds 已提交
376 377
}

378 379 380 381 382
static void netlink_sock_destruct_work(struct work_struct *work)
{
	struct netlink_sock *nlk = container_of(work, struct netlink_sock,
						work);

383
	sk_free(&nlk->sk);
384 385
}

386 387
/* This lock without WQ_FLAG_EXCLUSIVE is good on UP and it is _very_ bad on
 * SMP. Look, when several writers sleep and reader wakes them up, all but one
L
Linus Torvalds 已提交
388 389 390 391
 * immediately hit write lock and grab all the cpus. Exclusive sleep solves
 * this, _but_ remember, it adds useless work on UP machines.
 */

392
void netlink_table_grab(void)
393
	__acquires(nl_table_lock)
L
Linus Torvalds 已提交
394
{
395 396
	might_sleep();

397
	write_lock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
398 399 400 401 402

	if (atomic_read(&nl_table_users)) {
		DECLARE_WAITQUEUE(wait, current);

		add_wait_queue_exclusive(&nl_table_wait, &wait);
403
		for (;;) {
L
Linus Torvalds 已提交
404 405 406
			set_current_state(TASK_UNINTERRUPTIBLE);
			if (atomic_read(&nl_table_users) == 0)
				break;
407
			write_unlock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
408
			schedule();
409
			write_lock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
410 411 412 413 414 415 416
		}

		__set_current_state(TASK_RUNNING);
		remove_wait_queue(&nl_table_wait, &wait);
	}
}

417
void netlink_table_ungrab(void)
418
	__releases(nl_table_lock)
L
Linus Torvalds 已提交
419
{
420
	write_unlock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
421 422 423
	wake_up(&nl_table_wait);
}

424
static inline void
L
Linus Torvalds 已提交
425 426 427 428 429 430 431 432 433
netlink_lock_table(void)
{
	/* read_lock() synchronizes us to netlink_table_grab */

	read_lock(&nl_table_lock);
	atomic_inc(&nl_table_users);
	read_unlock(&nl_table_lock);
}

434
static inline void
L
Linus Torvalds 已提交
435 436 437 438 439 440
netlink_unlock_table(void)
{
	if (atomic_dec_and_test(&nl_table_users))
		wake_up(&nl_table_wait);
}

441
struct netlink_compare_arg
L
Linus Torvalds 已提交
442
{
443
	possible_net_t pnet;
444 445
	u32 portid;
};
L
Linus Torvalds 已提交
446

447 448 449
/* Doing sizeof directly may yield 4 extra bytes on 64-bit. */
#define netlink_compare_arg_len \
	(offsetof(struct netlink_compare_arg, portid) + sizeof(u32))
450 451 452

static inline int netlink_compare(struct rhashtable_compare_arg *arg,
				  const void *ptr)
L
Linus Torvalds 已提交
453
{
454 455
	const struct netlink_compare_arg *x = arg->key;
	const struct netlink_sock *nlk = ptr;
L
Linus Torvalds 已提交
456

457
	return nlk->portid != x->portid ||
458 459 460 461 462 463 464 465 466
	       !net_eq(sock_net(&nlk->sk), read_pnet(&x->pnet));
}

static void netlink_compare_arg_init(struct netlink_compare_arg *arg,
				     struct net *net, u32 portid)
{
	memset(arg, 0, sizeof(*arg));
	write_pnet(&arg->pnet, net);
	arg->portid = portid;
L
Linus Torvalds 已提交
467 468
}

469 470
static struct sock *__netlink_lookup(struct netlink_table *table, u32 portid,
				     struct net *net)
L
Linus Torvalds 已提交
471
{
472
	struct netlink_compare_arg arg;
L
Linus Torvalds 已提交
473

474 475 476
	netlink_compare_arg_init(&arg, net, portid);
	return rhashtable_lookup_fast(&table->hash, &arg,
				      netlink_rhashtable_params);
L
Linus Torvalds 已提交
477 478
}

479
static int __netlink_insert(struct netlink_table *table, struct sock *sk)
Y
Ying Xue 已提交
480
{
481
	struct netlink_compare_arg arg;
Y
Ying Xue 已提交
482

483
	netlink_compare_arg_init(&arg, sock_net(sk), nlk_sk(sk)->portid);
484 485 486
	return rhashtable_lookup_insert_key(&table->hash, &arg,
					    &nlk_sk(sk)->node,
					    netlink_rhashtable_params);
Y
Ying Xue 已提交
487 488
}

489
static struct sock *netlink_lookup(struct net *net, int protocol, u32 portid)
L
Linus Torvalds 已提交
490
{
491 492
	struct netlink_table *table = &nl_table[protocol];
	struct sock *sk;
L
Linus Torvalds 已提交
493

494 495 496 497 498
	rcu_read_lock();
	sk = __netlink_lookup(table, portid, net);
	if (sk)
		sock_hold(sk);
	rcu_read_unlock();
L
Linus Torvalds 已提交
499

500
	return sk;
L
Linus Torvalds 已提交
501 502
}

503
static const struct proto_ops netlink_ops;
L
Linus Torvalds 已提交
504

505 506 507 508 509 510
static void
netlink_update_listeners(struct sock *sk)
{
	struct netlink_table *tbl = &nl_table[sk->sk_protocol];
	unsigned long mask;
	unsigned int i;
511 512 513 514 515
	struct listeners *listeners;

	listeners = nl_deref_protected(tbl->listeners);
	if (!listeners)
		return;
516

517
	for (i = 0; i < NLGRPLONGS(tbl->groups); i++) {
518
		mask = 0;
519
		sk_for_each_bound(sk, &tbl->mc_list) {
520 521 522
			if (i < NLGRPLONGS(nlk_sk(sk)->ngroups))
				mask |= nlk_sk(sk)->groups[i];
		}
523
		listeners->masks[i] = mask;
524 525 526 527 528
	}
	/* this function is only called with the netlink table "grabbed", which
	 * makes sure updates are visible before bind or setsockopt return. */
}

529
static int netlink_insert(struct sock *sk, u32 portid)
L
Linus Torvalds 已提交
530
{
531
	struct netlink_table *table = &nl_table[sk->sk_protocol];
532
	int err;
L
Linus Torvalds 已提交
533

Y
Ying Xue 已提交
534
	lock_sock(sk);
L
Linus Torvalds 已提交
535

536 537
	err = nlk_sk(sk)->portid == portid ? 0 : -EBUSY;
	if (nlk_sk(sk)->bound)
L
Linus Torvalds 已提交
538 539 540
		goto err;

	err = -ENOMEM;
541 542
	if (BITS_PER_LONG > 32 &&
	    unlikely(atomic_read(&table->hash.nelems) >= UINT_MAX))
L
Linus Torvalds 已提交
543 544
		goto err;

545
	nlk_sk(sk)->portid = portid;
546
	sock_hold(sk);
547

548 549
	err = __netlink_insert(table, sk);
	if (err) {
550 551 552 553 554
		/* In case the hashtable backend returns with -EBUSY
		 * from here, it must not escape to the caller.
		 */
		if (unlikely(err == -EBUSY))
			err = -EOVERFLOW;
555 556
		if (err == -EEXIST)
			err = -EADDRINUSE;
Y
Ying Xue 已提交
557
		sock_put(sk);
558
		goto err;
559 560
	}

561 562 563
	/* We need to ensure that the socket is hashed and visible. */
	smp_wmb();
	nlk_sk(sk)->bound = portid;
564

L
Linus Torvalds 已提交
565
err:
Y
Ying Xue 已提交
566
	release_sock(sk);
L
Linus Torvalds 已提交
567 568 569 570 571
	return err;
}

static void netlink_remove(struct sock *sk)
{
572 573 574
	struct netlink_table *table;

	table = &nl_table[sk->sk_protocol];
575 576
	if (!rhashtable_remove_fast(&table->hash, &nlk_sk(sk)->node,
				    netlink_rhashtable_params)) {
577 578 579 580
		WARN_ON(atomic_read(&sk->sk_refcnt) == 1);
		__sock_put(sk);
	}

L
Linus Torvalds 已提交
581
	netlink_table_grab();
582
	if (nlk_sk(sk)->subscriptions) {
L
Linus Torvalds 已提交
583
		__sk_del_bind_node(sk);
584 585
		netlink_update_listeners(sk);
	}
586 587
	if (sk->sk_protocol == NETLINK_GENERIC)
		atomic_inc(&genl_sk_destructing_cnt);
L
Linus Torvalds 已提交
588 589 590 591 592 593 594 595 596
	netlink_table_ungrab();
}

static struct proto netlink_proto = {
	.name	  = "NETLINK",
	.owner	  = THIS_MODULE,
	.obj_size = sizeof(struct netlink_sock),
};

597
static int __netlink_create(struct net *net, struct socket *sock,
598 599
			    struct mutex *cb_mutex, int protocol,
			    int kern)
L
Linus Torvalds 已提交
600 601 602
{
	struct sock *sk;
	struct netlink_sock *nlk;
603 604 605

	sock->ops = &netlink_ops;

606
	sk = sk_alloc(net, PF_NETLINK, GFP_KERNEL, &netlink_proto, kern);
607 608 609 610 611 612
	if (!sk)
		return -ENOMEM;

	sock_init_data(sock, sk);

	nlk = nlk_sk(sk);
E
Eric Dumazet 已提交
613
	if (cb_mutex) {
614
		nlk->cb_mutex = cb_mutex;
E
Eric Dumazet 已提交
615
	} else {
616 617
		nlk->cb_mutex = &nlk->cb_def_mutex;
		mutex_init(nlk->cb_mutex);
618 619 620
		lockdep_set_class_and_name(nlk->cb_mutex,
					   nlk_cb_mutex_keys + protocol,
					   nlk_cb_mutex_key_strings[protocol]);
621
	}
622 623 624 625 626 627 628
	init_waitqueue_head(&nlk->wait);

	sk->sk_destruct = netlink_sock_destruct;
	sk->sk_protocol = protocol;
	return 0;
}

629 630
static int netlink_create(struct net *net, struct socket *sock, int protocol,
			  int kern)
631 632
{
	struct module *module = NULL;
633
	struct mutex *cb_mutex;
634
	struct netlink_sock *nlk;
635 636
	int (*bind)(struct net *net, int group);
	void (*unbind)(struct net *net, int group);
637
	int err = 0;
L
Linus Torvalds 已提交
638 639 640 641 642 643

	sock->state = SS_UNCONNECTED;

	if (sock->type != SOCK_RAW && sock->type != SOCK_DGRAM)
		return -ESOCKTNOSUPPORT;

644
	if (protocol < 0 || protocol >= MAX_LINKS)
L
Linus Torvalds 已提交
645 646
		return -EPROTONOSUPPORT;

647
	netlink_lock_table();
648
#ifdef CONFIG_MODULES
649
	if (!nl_table[protocol].registered) {
650
		netlink_unlock_table();
651
		request_module("net-pf-%d-proto-%d", PF_NETLINK, protocol);
652
		netlink_lock_table();
653
	}
654 655 656 657
#endif
	if (nl_table[protocol].registered &&
	    try_module_get(nl_table[protocol].module))
		module = nl_table[protocol].module;
658 659
	else
		err = -EPROTONOSUPPORT;
660
	cb_mutex = nl_table[protocol].cb_mutex;
661
	bind = nl_table[protocol].bind;
662
	unbind = nl_table[protocol].unbind;
663
	netlink_unlock_table();
664

665 666 667
	if (err < 0)
		goto out;

668
	err = __netlink_create(net, sock, cb_mutex, protocol, kern);
669
	if (err < 0)
670 671
		goto out_module;

672
	local_bh_disable();
673
	sock_prot_inuse_add(net, &netlink_proto, 1);
674 675
	local_bh_enable();

676 677
	nlk = nlk_sk(sock->sk);
	nlk->module = module;
678
	nlk->netlink_bind = bind;
679
	nlk->netlink_unbind = unbind;
680 681
out:
	return err;
L
Linus Torvalds 已提交
682

683 684 685
out_module:
	module_put(module);
	goto out;
L
Linus Torvalds 已提交
686 687
}

688 689 690
static void deferred_put_nlk_sk(struct rcu_head *head)
{
	struct netlink_sock *nlk = container_of(head, struct netlink_sock, rcu);
691 692 693 694 695 696 697 698 699 700
	struct sock *sk = &nlk->sk;

	if (!atomic_dec_and_test(&sk->sk_refcnt))
		return;

	if (nlk->cb_running && nlk->cb.done) {
		INIT_WORK(&nlk->work, netlink_sock_destruct_work);
		schedule_work(&nlk->work);
		return;
	}
701

702
	sk_free(sk);
703 704
}

L
Linus Torvalds 已提交
705 706 707 708 709 710 711 712 713
static int netlink_release(struct socket *sock)
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk;

	if (!sk)
		return 0;

	netlink_remove(sk);
714
	sock_orphan(sk);
L
Linus Torvalds 已提交
715 716
	nlk = nlk_sk(sk);

717 718 719 720
	/*
	 * OK. Socket is unlinked, any packets that arrive now
	 * will be purged.
	 */
L
Linus Torvalds 已提交
721

722 723 724 725 726 727 728 729 730 731 732 733 734 735
	/* must not acquire netlink_table_lock in any way again before unbind
	 * and notifying genetlink is done as otherwise it might deadlock
	 */
	if (nlk->netlink_unbind) {
		int i;

		for (i = 0; i < nlk->ngroups; i++)
			if (test_bit(i, nlk->groups))
				nlk->netlink_unbind(sock_net(sk), i + 1);
	}
	if (sk->sk_protocol == NETLINK_GENERIC &&
	    atomic_dec_return(&genl_sk_destructing_cnt) == 0)
		wake_up(&genl_sk_destructing_waitq);

L
Linus Torvalds 已提交
736 737 738 739 740
	sock->sk = NULL;
	wake_up_interruptible_all(&nlk->wait);

	skb_queue_purge(&sk->sk_write_queue);

741
	if (nlk->portid && nlk->bound) {
L
Linus Torvalds 已提交
742
		struct netlink_notify n = {
743
						.net = sock_net(sk),
L
Linus Torvalds 已提交
744
						.protocol = sk->sk_protocol,
745
						.portid = nlk->portid,
L
Linus Torvalds 已提交
746
					  };
W
WANG Cong 已提交
747
		blocking_notifier_call_chain(&netlink_chain,
748
				NETLINK_URELEASE, &n);
749
	}
750

751
	module_put(nlk->module);
752

753
	if (netlink_is_kernel(sk)) {
754
		netlink_table_grab();
755 756
		BUG_ON(nl_table[sk->sk_protocol].registered == 0);
		if (--nl_table[sk->sk_protocol].registered == 0) {
757 758 759 760 761
			struct listeners *old;

			old = nl_deref_protected(nl_table[sk->sk_protocol].listeners);
			RCU_INIT_POINTER(nl_table[sk->sk_protocol].listeners, NULL);
			kfree_rcu(old, rcu);
762
			nl_table[sk->sk_protocol].module = NULL;
763
			nl_table[sk->sk_protocol].bind = NULL;
764
			nl_table[sk->sk_protocol].unbind = NULL;
765
			nl_table[sk->sk_protocol].flags = 0;
766 767
			nl_table[sk->sk_protocol].registered = 0;
		}
768
		netlink_table_ungrab();
E
Eric Dumazet 已提交
769
	}
770

771 772 773
	kfree(nlk->groups);
	nlk->groups = NULL;

774
	local_bh_disable();
775
	sock_prot_inuse_add(sock_net(sk), &netlink_proto, -1);
776
	local_bh_enable();
777
	call_rcu(&nlk->rcu, deferred_put_nlk_sk);
L
Linus Torvalds 已提交
778 779 780 781 782 783
	return 0;
}

static int netlink_autobind(struct socket *sock)
{
	struct sock *sk = sock->sk;
784
	struct net *net = sock_net(sk);
785
	struct netlink_table *table = &nl_table[sk->sk_protocol];
786
	s32 portid = task_tgid_vnr(current);
L
Linus Torvalds 已提交
787
	int err;
H
Herbert Xu 已提交
788 789
	s32 rover = -4096;
	bool ok;
L
Linus Torvalds 已提交
790 791 792

retry:
	cond_resched();
793
	rcu_read_lock();
H
Herbert Xu 已提交
794 795 796
	ok = !__netlink_lookup(table, portid, net);
	rcu_read_unlock();
	if (!ok) {
797
		/* Bind collision, search negative portid values. */
H
Herbert Xu 已提交
798 799 800 801
		if (rover == -4096)
			/* rover will be in range [S32_MIN, -4097] */
			rover = S32_MIN + prandom_u32_max(-4096 - S32_MIN);
		else if (rover >= -4096)
802
			rover = -4097;
H
Herbert Xu 已提交
803
		portid = rover--;
804
		goto retry;
L
Linus Torvalds 已提交
805 806
	}

807
	err = netlink_insert(sk, portid);
L
Linus Torvalds 已提交
808 809
	if (err == -EADDRINUSE)
		goto retry;
810 811 812 813 814 815

	/* If 2 threads race to autobind, that is fine.  */
	if (err == -EBUSY)
		err = 0;

	return err;
L
Linus Torvalds 已提交
816 817
}

818 819 820 821 822 823 824 825 826 827 828 829 830
/**
 * __netlink_ns_capable - General netlink message capability test
 * @nsp: NETLINK_CB of the socket buffer holding a netlink command from userspace.
 * @user_ns: The user namespace of the capability to use
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap in the user namespace @user_ns.
 */
bool __netlink_ns_capable(const struct netlink_skb_parms *nsp,
			struct user_namespace *user_ns, int cap)
{
831 832 833
	return ((nsp->flags & NETLINK_SKB_DST) ||
		file_ns_capable(nsp->sk->sk_socket->file, user_ns, cap)) &&
		ns_capable(user_ns, cap);
834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884
}
EXPORT_SYMBOL(__netlink_ns_capable);

/**
 * netlink_ns_capable - General netlink message capability test
 * @skb: socket buffer holding a netlink command from userspace
 * @user_ns: The user namespace of the capability to use
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap in the user namespace @user_ns.
 */
bool netlink_ns_capable(const struct sk_buff *skb,
			struct user_namespace *user_ns, int cap)
{
	return __netlink_ns_capable(&NETLINK_CB(skb), user_ns, cap);
}
EXPORT_SYMBOL(netlink_ns_capable);

/**
 * netlink_capable - Netlink global message capability test
 * @skb: socket buffer holding a netlink command from userspace
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap in all user namespaces.
 */
bool netlink_capable(const struct sk_buff *skb, int cap)
{
	return netlink_ns_capable(skb, &init_user_ns, cap);
}
EXPORT_SYMBOL(netlink_capable);

/**
 * netlink_net_capable - Netlink network namespace message capability test
 * @skb: socket buffer holding a netlink command from userspace
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap over the network namespace of
 * the socket we received the message from.
 */
bool netlink_net_capable(const struct sk_buff *skb, int cap)
{
	return netlink_ns_capable(skb, sock_net(skb->sk)->user_ns, cap);
}
EXPORT_SYMBOL(netlink_net_capable);

885
static inline int netlink_allowed(const struct socket *sock, unsigned int flag)
886
{
887
	return (nl_table[sock->sk->sk_protocol].flags & flag) ||
888
		ns_capable(sock_net(sock->sk)->user_ns, CAP_NET_ADMIN);
889
}
L
Linus Torvalds 已提交
890

891 892 893 894 895 896 897 898 899 900 901 902
static void
netlink_update_subscriptions(struct sock *sk, unsigned int subscriptions)
{
	struct netlink_sock *nlk = nlk_sk(sk);

	if (nlk->subscriptions && !subscriptions)
		__sk_del_bind_node(sk);
	else if (!nlk->subscriptions && subscriptions)
		sk_add_bind_node(sk, &nl_table[sk->sk_protocol].mc_list);
	nlk->subscriptions = subscriptions;
}

903
static int netlink_realloc_groups(struct sock *sk)
904 905 906
{
	struct netlink_sock *nlk = nlk_sk(sk);
	unsigned int groups;
907
	unsigned long *new_groups;
908 909
	int err = 0;

910 911
	netlink_table_grab();

912
	groups = nl_table[sk->sk_protocol].groups;
913
	if (!nl_table[sk->sk_protocol].registered) {
914
		err = -ENOENT;
915 916
		goto out_unlock;
	}
917

918 919
	if (nlk->ngroups >= groups)
		goto out_unlock;
920

921 922 923 924 925
	new_groups = krealloc(nlk->groups, NLGRPSZ(groups), GFP_ATOMIC);
	if (new_groups == NULL) {
		err = -ENOMEM;
		goto out_unlock;
	}
926
	memset((char *)new_groups + NLGRPSZ(nlk->ngroups), 0,
927 928 929
	       NLGRPSZ(groups) - NLGRPSZ(nlk->ngroups));

	nlk->groups = new_groups;
930
	nlk->ngroups = groups;
931 932 933
 out_unlock:
	netlink_table_ungrab();
	return err;
934 935
}

936
static void netlink_undo_bind(int group, long unsigned int groups,
937
			      struct sock *sk)
938
{
939
	struct netlink_sock *nlk = nlk_sk(sk);
940 941 942 943 944 945
	int undo;

	if (!nlk->netlink_unbind)
		return;

	for (undo = 0; undo < group; undo++)
946
		if (test_bit(undo, &groups))
947
			nlk->netlink_unbind(sock_net(sk), undo + 1);
948 949
}

950 951
static int netlink_bind(struct socket *sock, struct sockaddr *addr,
			int addr_len)
L
Linus Torvalds 已提交
952 953
{
	struct sock *sk = sock->sk;
954
	struct net *net = sock_net(sk);
L
Linus Torvalds 已提交
955 956 957
	struct netlink_sock *nlk = nlk_sk(sk);
	struct sockaddr_nl *nladdr = (struct sockaddr_nl *)addr;
	int err;
958
	long unsigned int groups = nladdr->nl_groups;
959
	bool bound;
960

961 962 963
	if (addr_len < sizeof(struct sockaddr_nl))
		return -EINVAL;

L
Linus Torvalds 已提交
964 965 966 967
	if (nladdr->nl_family != AF_NETLINK)
		return -EINVAL;

	/* Only superuser is allowed to listen multicasts */
968
	if (groups) {
969
		if (!netlink_allowed(sock, NL_CFG_F_NONROOT_RECV))
970
			return -EPERM;
971 972 973
		err = netlink_realloc_groups(sk);
		if (err)
			return err;
974
	}
L
Linus Torvalds 已提交
975

976 977 978 979 980
	bound = nlk->bound;
	if (bound) {
		/* Ensure nlk->portid is up-to-date. */
		smp_rmb();

981
		if (nladdr->nl_pid != nlk->portid)
L
Linus Torvalds 已提交
982
			return -EINVAL;
983
	}
984 985 986 987 988 989 990

	if (nlk->netlink_bind && groups) {
		int group;

		for (group = 0; group < nlk->ngroups; group++) {
			if (!test_bit(group, &groups))
				continue;
991
			err = nlk->netlink_bind(net, group + 1);
992 993
			if (!err)
				continue;
994
			netlink_undo_bind(group, groups, sk);
995 996 997 998
			return err;
		}
	}

999 1000 1001 1002
	/* No need for barriers here as we return to user-space without
	 * using any of the bound attributes.
	 */
	if (!bound) {
L
Linus Torvalds 已提交
1003
		err = nladdr->nl_pid ?
1004
			netlink_insert(sk, nladdr->nl_pid) :
L
Linus Torvalds 已提交
1005
			netlink_autobind(sock);
1006
		if (err) {
1007
			netlink_undo_bind(nlk->ngroups, groups, sk);
L
Linus Torvalds 已提交
1008
			return err;
1009
		}
L
Linus Torvalds 已提交
1010 1011
	}

1012
	if (!groups && (nlk->groups == NULL || !(u32)nlk->groups[0]))
L
Linus Torvalds 已提交
1013 1014 1015
		return 0;

	netlink_table_grab();
1016
	netlink_update_subscriptions(sk, nlk->subscriptions +
1017
					 hweight32(groups) -
1018
					 hweight32(nlk->groups[0]));
1019
	nlk->groups[0] = (nlk->groups[0] & ~0xffffffffUL) | groups;
1020
	netlink_update_listeners(sk);
L
Linus Torvalds 已提交
1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031
	netlink_table_ungrab();

	return 0;
}

static int netlink_connect(struct socket *sock, struct sockaddr *addr,
			   int alen, int flags)
{
	int err = 0;
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1032
	struct sockaddr_nl *nladdr = (struct sockaddr_nl *)addr;
L
Linus Torvalds 已提交
1033

1034 1035 1036
	if (alen < sizeof(addr->sa_family))
		return -EINVAL;

L
Linus Torvalds 已提交
1037 1038
	if (addr->sa_family == AF_UNSPEC) {
		sk->sk_state	= NETLINK_UNCONNECTED;
1039
		nlk->dst_portid	= 0;
1040
		nlk->dst_group  = 0;
L
Linus Torvalds 已提交
1041 1042 1043 1044 1045
		return 0;
	}
	if (addr->sa_family != AF_NETLINK)
		return -EINVAL;

1046
	if ((nladdr->nl_groups || nladdr->nl_pid) &&
1047
	    !netlink_allowed(sock, NL_CFG_F_NONROOT_SEND))
L
Linus Torvalds 已提交
1048 1049
		return -EPERM;

1050 1051 1052 1053
	/* No need for barriers here as we return to user-space without
	 * using any of the bound attributes.
	 */
	if (!nlk->bound)
L
Linus Torvalds 已提交
1054 1055 1056 1057
		err = netlink_autobind(sock);

	if (err == 0) {
		sk->sk_state	= NETLINK_CONNECTED;
1058
		nlk->dst_portid = nladdr->nl_pid;
1059
		nlk->dst_group  = ffs(nladdr->nl_groups);
L
Linus Torvalds 已提交
1060 1061 1062 1063 1064
	}

	return err;
}

1065 1066
static int netlink_getname(struct socket *sock, struct sockaddr *addr,
			   int *addr_len, int peer)
L
Linus Torvalds 已提交
1067 1068 1069
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1070
	DECLARE_SOCKADDR(struct sockaddr_nl *, nladdr, addr);
1071

L
Linus Torvalds 已提交
1072 1073 1074 1075 1076
	nladdr->nl_family = AF_NETLINK;
	nladdr->nl_pad = 0;
	*addr_len = sizeof(*nladdr);

	if (peer) {
1077
		nladdr->nl_pid = nlk->dst_portid;
1078
		nladdr->nl_groups = netlink_group_mask(nlk->dst_group);
L
Linus Torvalds 已提交
1079
	} else {
1080
		nladdr->nl_pid = nlk->portid;
1081
		nladdr->nl_groups = nlk->groups ? nlk->groups[0] : 0;
L
Linus Torvalds 已提交
1082 1083 1084 1085
	}
	return 0;
}

1086 1087 1088 1089 1090 1091 1092 1093
static int netlink_ioctl(struct socket *sock, unsigned int cmd,
			 unsigned long arg)
{
	/* try to hand this ioctl down to the NIC drivers.
	 */
	return -ENOIOCTLCMD;
}

1094
static struct sock *netlink_getsockbyportid(struct sock *ssk, u32 portid)
L
Linus Torvalds 已提交
1095 1096 1097 1098
{
	struct sock *sock;
	struct netlink_sock *nlk;

1099
	sock = netlink_lookup(sock_net(ssk), ssk->sk_protocol, portid);
L
Linus Torvalds 已提交
1100 1101 1102 1103 1104
	if (!sock)
		return ERR_PTR(-ECONNREFUSED);

	/* Don't bother queuing skb if kernel socket has no input function */
	nlk = nlk_sk(sock);
1105
	if (sock->sk_state == NETLINK_CONNECTED &&
1106
	    nlk->dst_portid != nlk_sk(ssk)->portid) {
L
Linus Torvalds 已提交
1107 1108 1109 1110 1111 1112 1113 1114
		sock_put(sock);
		return ERR_PTR(-ECONNREFUSED);
	}
	return sock;
}

struct sock *netlink_getsockbyfilp(struct file *filp)
{
A
Al Viro 已提交
1115
	struct inode *inode = file_inode(filp);
L
Linus Torvalds 已提交
1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128
	struct sock *sock;

	if (!S_ISSOCK(inode->i_mode))
		return ERR_PTR(-ENOTSOCK);

	sock = SOCKET_I(inode)->sk;
	if (sock->sk_family != AF_NETLINK)
		return ERR_PTR(-EINVAL);

	sock_hold(sock);
	return sock;
}

1129 1130
static struct sk_buff *netlink_alloc_large_skb(unsigned int size,
					       int broadcast)
1131 1132 1133 1134
{
	struct sk_buff *skb;
	void *data;

1135
	if (size <= NLMSG_GOODSIZE || broadcast)
1136 1137
		return alloc_skb(size, GFP_KERNEL);

1138 1139
	size = SKB_DATA_ALIGN(size) +
	       SKB_DATA_ALIGN(sizeof(struct skb_shared_info));
1140 1141 1142

	data = vmalloc(size);
	if (data == NULL)
1143
		return NULL;
1144

E
Eric Dumazet 已提交
1145
	skb = __build_skb(data, size);
1146 1147
	if (skb == NULL)
		vfree(data);
E
Eric Dumazet 已提交
1148
	else
1149
		skb->destructor = netlink_skb_destructor;
1150 1151 1152 1153

	return skb;
}

L
Linus Torvalds 已提交
1154 1155 1156 1157 1158 1159 1160 1161 1162 1163
/*
 * Attach a skb to a netlink socket.
 * The caller must hold a reference to the destination socket. On error, the
 * reference is dropped. The skb is not send to the destination, just all
 * all error checks are performed and memory in the queue is reserved.
 * Return values:
 * < 0: error. skb freed, reference to sock dropped.
 * 0: continue
 * 1: repeat lookup - reference dropped while waiting for socket memory.
 */
1164
int netlink_attachskb(struct sock *sk, struct sk_buff *skb,
P
Patrick McHardy 已提交
1165
		      long *timeo, struct sock *ssk)
L
Linus Torvalds 已提交
1166 1167 1168 1169 1170
{
	struct netlink_sock *nlk;

	nlk = nlk_sk(sk);

1171
	if ((atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf ||
1172
	     test_bit(NETLINK_S_CONGESTED, &nlk->state))) {
L
Linus Torvalds 已提交
1173
		DECLARE_WAITQUEUE(wait, current);
P
Patrick McHardy 已提交
1174
		if (!*timeo) {
1175
			if (!ssk || netlink_is_kernel(ssk))
L
Linus Torvalds 已提交
1176 1177 1178 1179 1180 1181 1182 1183 1184 1185
				netlink_overrun(sk);
			sock_put(sk);
			kfree_skb(skb);
			return -EAGAIN;
		}

		__set_current_state(TASK_INTERRUPTIBLE);
		add_wait_queue(&nlk->wait, &wait);

		if ((atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf ||
1186
		     test_bit(NETLINK_S_CONGESTED, &nlk->state)) &&
L
Linus Torvalds 已提交
1187
		    !sock_flag(sk, SOCK_DEAD))
P
Patrick McHardy 已提交
1188
			*timeo = schedule_timeout(*timeo);
L
Linus Torvalds 已提交
1189 1190 1191 1192 1193 1194 1195

		__set_current_state(TASK_RUNNING);
		remove_wait_queue(&nlk->wait, &wait);
		sock_put(sk);

		if (signal_pending(current)) {
			kfree_skb(skb);
P
Patrick McHardy 已提交
1196
			return sock_intr_errno(*timeo);
L
Linus Torvalds 已提交
1197 1198 1199
		}
		return 1;
	}
1200
	netlink_skb_set_owner_r(skb, sk);
L
Linus Torvalds 已提交
1201 1202 1203
	return 0;
}

1204
static int __netlink_sendskb(struct sock *sk, struct sk_buff *skb)
L
Linus Torvalds 已提交
1205 1206 1207
{
	int len = skb->len;

1208 1209
	netlink_deliver_tap(skb);

1210
	skb_queue_tail(&sk->sk_receive_queue, skb);
1211
	sk->sk_data_ready(sk);
1212 1213 1214 1215 1216 1217 1218
	return len;
}

int netlink_sendskb(struct sock *sk, struct sk_buff *skb)
{
	int len = __netlink_sendskb(sk, skb);

L
Linus Torvalds 已提交
1219 1220 1221 1222 1223 1224 1225 1226 1227 1228
	sock_put(sk);
	return len;
}

void netlink_detachskb(struct sock *sk, struct sk_buff *skb)
{
	kfree_skb(skb);
	sock_put(sk);
}

1229
static struct sk_buff *netlink_trim(struct sk_buff *skb, gfp_t allocation)
L
Linus Torvalds 已提交
1230 1231 1232
{
	int delta;

1233
	WARN_ON(skb->sk != NULL);
1234
	delta = skb->end - skb->tail;
1235
	if (is_vmalloc_addr(skb->head) || delta * 2 < skb->truesize)
L
Linus Torvalds 已提交
1236 1237 1238 1239 1240 1241
		return skb;

	if (skb_shared(skb)) {
		struct sk_buff *nskb = skb_clone(skb, allocation);
		if (!nskb)
			return skb;
1242
		consume_skb(skb);
L
Linus Torvalds 已提交
1243 1244 1245
		skb = nskb;
	}

1246 1247 1248
	pskb_expand_head(skb, 0, -delta,
			 (allocation & ~__GFP_DIRECT_RECLAIM) |
			 __GFP_NOWARN | __GFP_NORETRY);
L
Linus Torvalds 已提交
1249 1250 1251
	return skb;
}

1252 1253
static int netlink_unicast_kernel(struct sock *sk, struct sk_buff *skb,
				  struct sock *ssk)
1254 1255 1256 1257 1258 1259 1260
{
	int ret;
	struct netlink_sock *nlk = nlk_sk(sk);

	ret = -ECONNREFUSED;
	if (nlk->netlink_rcv != NULL) {
		ret = skb->len;
1261
		netlink_skb_set_owner_r(skb, sk);
1262
		NETLINK_CB(skb).sk = ssk;
1263
		netlink_deliver_tap_kernel(sk, ssk, skb);
1264
		nlk->netlink_rcv(skb);
1265 1266 1267
		consume_skb(skb);
	} else {
		kfree_skb(skb);
1268 1269 1270 1271 1272 1273
	}
	sock_put(sk);
	return ret;
}

int netlink_unicast(struct sock *ssk, struct sk_buff *skb,
1274
		    u32 portid, int nonblock)
L
Linus Torvalds 已提交
1275 1276 1277 1278 1279 1280 1281 1282 1283
{
	struct sock *sk;
	int err;
	long timeo;

	skb = netlink_trim(skb, gfp_any());

	timeo = sock_sndtimeo(ssk, nonblock);
retry:
1284
	sk = netlink_getsockbyportid(ssk, portid);
L
Linus Torvalds 已提交
1285 1286 1287 1288
	if (IS_ERR(sk)) {
		kfree_skb(skb);
		return PTR_ERR(sk);
	}
1289
	if (netlink_is_kernel(sk))
1290
		return netlink_unicast_kernel(sk, skb, ssk);
1291

1292
	if (sk_filter(sk, skb)) {
W
Wang Chen 已提交
1293
		err = skb->len;
1294 1295 1296 1297 1298
		kfree_skb(skb);
		sock_put(sk);
		return err;
	}

1299
	err = netlink_attachskb(sk, skb, &timeo, ssk);
L
Linus Torvalds 已提交
1300 1301 1302 1303 1304
	if (err == 1)
		goto retry;
	if (err)
		return err;

1305
	return netlink_sendskb(sk, skb);
L
Linus Torvalds 已提交
1306
}
1307
EXPORT_SYMBOL(netlink_unicast);
L
Linus Torvalds 已提交
1308

1309 1310 1311
int netlink_has_listeners(struct sock *sk, unsigned int group)
{
	int res = 0;
1312
	struct listeners *listeners;
1313

1314
	BUG_ON(!netlink_is_kernel(sk));
1315 1316 1317 1318

	rcu_read_lock();
	listeners = rcu_dereference(nl_table[sk->sk_protocol].listeners);

1319
	if (listeners && group - 1 < nl_table[sk->sk_protocol].groups)
1320
		res = test_bit(group - 1, listeners->masks);
1321 1322 1323

	rcu_read_unlock();

1324 1325 1326 1327
	return res;
}
EXPORT_SYMBOL_GPL(netlink_has_listeners);

1328
static int netlink_broadcast_deliver(struct sock *sk, struct sk_buff *skb)
L
Linus Torvalds 已提交
1329 1330 1331 1332
{
	struct netlink_sock *nlk = nlk_sk(sk);

	if (atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf &&
1333
	    !test_bit(NETLINK_S_CONGESTED, &nlk->state)) {
1334
		netlink_skb_set_owner_r(skb, sk);
1335
		__netlink_sendskb(sk, skb);
1336
		return atomic_read(&sk->sk_rmem_alloc) > (sk->sk_rcvbuf >> 1);
L
Linus Torvalds 已提交
1337 1338 1339 1340 1341 1342
	}
	return -1;
}

struct netlink_broadcast_data {
	struct sock *exclude_sk;
1343
	struct net *net;
1344
	u32 portid;
L
Linus Torvalds 已提交
1345 1346
	u32 group;
	int failure;
1347
	int delivery_failure;
L
Linus Torvalds 已提交
1348 1349
	int congested;
	int delivered;
A
Al Viro 已提交
1350
	gfp_t allocation;
L
Linus Torvalds 已提交
1351
	struct sk_buff *skb, *skb2;
1352 1353
	int (*tx_filter)(struct sock *dsk, struct sk_buff *skb, void *data);
	void *tx_data;
L
Linus Torvalds 已提交
1354 1355
};

1356 1357
static void do_one_broadcast(struct sock *sk,
				    struct netlink_broadcast_data *p)
L
Linus Torvalds 已提交
1358 1359 1360 1361 1362
{
	struct netlink_sock *nlk = nlk_sk(sk);
	int val;

	if (p->exclude_sk == sk)
1363
		return;
L
Linus Torvalds 已提交
1364

1365
	if (nlk->portid == p->portid || p->group - 1 >= nlk->ngroups ||
1366
	    !test_bit(p->group - 1, nlk->groups))
1367
		return;
L
Linus Torvalds 已提交
1368

1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379
	if (!net_eq(sock_net(sk), p->net)) {
		if (!(nlk->flags & NETLINK_F_LISTEN_ALL_NSID))
			return;

		if (!peernet_has_id(sock_net(sk), p->net))
			return;

		if (!file_ns_capable(sk->sk_socket->file, p->net->user_ns,
				     CAP_NET_BROADCAST))
			return;
	}
1380

L
Linus Torvalds 已提交
1381 1382
	if (p->failure) {
		netlink_overrun(sk);
1383
		return;
L
Linus Torvalds 已提交
1384 1385 1386 1387
	}

	sock_hold(sk);
	if (p->skb2 == NULL) {
1388
		if (skb_shared(p->skb)) {
L
Linus Torvalds 已提交
1389 1390
			p->skb2 = skb_clone(p->skb, p->allocation);
		} else {
1391 1392 1393 1394 1395 1396
			p->skb2 = skb_get(p->skb);
			/*
			 * skb ownership may have been set when
			 * delivered to a previous socket.
			 */
			skb_orphan(p->skb2);
L
Linus Torvalds 已提交
1397 1398 1399 1400 1401 1402
		}
	}
	if (p->skb2 == NULL) {
		netlink_overrun(sk);
		/* Clone failed. Notify ALL listeners. */
		p->failure = 1;
1403
		if (nlk->flags & NETLINK_F_BROADCAST_SEND_ERROR)
1404
			p->delivery_failure = 1;
1405 1406 1407
		goto out;
	}
	if (p->tx_filter && p->tx_filter(sk, p->skb2, p->tx_data)) {
1408 1409
		kfree_skb(p->skb2);
		p->skb2 = NULL;
1410 1411 1412
		goto out;
	}
	if (sk_filter(sk, p->skb2)) {
1413 1414
		kfree_skb(p->skb2);
		p->skb2 = NULL;
1415 1416 1417 1418 1419 1420
		goto out;
	}
	NETLINK_CB(p->skb2).nsid = peernet2id(sock_net(sk), p->net);
	NETLINK_CB(p->skb2).nsid_is_set = true;
	val = netlink_broadcast_deliver(sk, p->skb2);
	if (val < 0) {
L
Linus Torvalds 已提交
1421
		netlink_overrun(sk);
1422
		if (nlk->flags & NETLINK_F_BROADCAST_SEND_ERROR)
1423
			p->delivery_failure = 1;
L
Linus Torvalds 已提交
1424 1425 1426 1427 1428
	} else {
		p->congested |= val;
		p->delivered = 1;
		p->skb2 = NULL;
	}
1429
out:
L
Linus Torvalds 已提交
1430 1431 1432
	sock_put(sk);
}

1433
int netlink_broadcast_filtered(struct sock *ssk, struct sk_buff *skb, u32 portid,
1434 1435 1436
	u32 group, gfp_t allocation,
	int (*filter)(struct sock *dsk, struct sk_buff *skb, void *data),
	void *filter_data)
L
Linus Torvalds 已提交
1437
{
1438
	struct net *net = sock_net(ssk);
L
Linus Torvalds 已提交
1439 1440 1441 1442 1443 1444
	struct netlink_broadcast_data info;
	struct sock *sk;

	skb = netlink_trim(skb, allocation);

	info.exclude_sk = ssk;
1445
	info.net = net;
1446
	info.portid = portid;
L
Linus Torvalds 已提交
1447 1448
	info.group = group;
	info.failure = 0;
1449
	info.delivery_failure = 0;
L
Linus Torvalds 已提交
1450 1451 1452 1453 1454
	info.congested = 0;
	info.delivered = 0;
	info.allocation = allocation;
	info.skb = skb;
	info.skb2 = NULL;
1455 1456
	info.tx_filter = filter;
	info.tx_data = filter_data;
L
Linus Torvalds 已提交
1457 1458 1459 1460 1461

	/* While we sleep in clone, do not allow to change socket list */

	netlink_lock_table();

1462
	sk_for_each_bound(sk, &nl_table[ssk->sk_protocol].mc_list)
L
Linus Torvalds 已提交
1463 1464
		do_one_broadcast(sk, &info);

1465
	consume_skb(skb);
1466

L
Linus Torvalds 已提交
1467 1468
	netlink_unlock_table();

1469 1470
	if (info.delivery_failure) {
		kfree_skb(info.skb2);
1471
		return -ENOBUFS;
E
Eric Dumazet 已提交
1472 1473
	}
	consume_skb(info.skb2);
1474

L
Linus Torvalds 已提交
1475
	if (info.delivered) {
1476
		if (info.congested && gfpflags_allow_blocking(allocation))
L
Linus Torvalds 已提交
1477 1478 1479 1480 1481
			yield();
		return 0;
	}
	return -ESRCH;
}
1482 1483
EXPORT_SYMBOL(netlink_broadcast_filtered);

1484
int netlink_broadcast(struct sock *ssk, struct sk_buff *skb, u32 portid,
1485 1486
		      u32 group, gfp_t allocation)
{
1487
	return netlink_broadcast_filtered(ssk, skb, portid, group, allocation,
1488 1489
		NULL, NULL);
}
1490
EXPORT_SYMBOL(netlink_broadcast);
L
Linus Torvalds 已提交
1491 1492 1493

struct netlink_set_err_data {
	struct sock *exclude_sk;
1494
	u32 portid;
L
Linus Torvalds 已提交
1495 1496 1497 1498
	u32 group;
	int code;
};

1499
static int do_one_set_err(struct sock *sk, struct netlink_set_err_data *p)
L
Linus Torvalds 已提交
1500 1501
{
	struct netlink_sock *nlk = nlk_sk(sk);
1502
	int ret = 0;
L
Linus Torvalds 已提交
1503 1504 1505 1506

	if (sk == p->exclude_sk)
		goto out;

O
Octavian Purdila 已提交
1507
	if (!net_eq(sock_net(sk), sock_net(p->exclude_sk)))
1508 1509
		goto out;

1510
	if (nlk->portid == p->portid || p->group - 1 >= nlk->ngroups ||
1511
	    !test_bit(p->group - 1, nlk->groups))
L
Linus Torvalds 已提交
1512 1513
		goto out;

1514
	if (p->code == ENOBUFS && nlk->flags & NETLINK_F_RECV_NO_ENOBUFS) {
1515 1516 1517 1518
		ret = 1;
		goto out;
	}

L
Linus Torvalds 已提交
1519 1520 1521
	sk->sk_err = p->code;
	sk->sk_error_report(sk);
out:
1522
	return ret;
L
Linus Torvalds 已提交
1523 1524
}

1525 1526 1527
/**
 * netlink_set_err - report error to broadcast listeners
 * @ssk: the kernel netlink socket, as returned by netlink_kernel_create()
1528
 * @portid: the PORTID of a process that we want to skip (if any)
1529
 * @group: the broadcast group that will notice the error
1530
 * @code: error code, must be negative (as usual in kernelspace)
1531 1532
 *
 * This function returns the number of broadcast listeners that have set the
1533
 * NETLINK_NO_ENOBUFS socket option.
1534
 */
1535
int netlink_set_err(struct sock *ssk, u32 portid, u32 group, int code)
L
Linus Torvalds 已提交
1536 1537 1538
{
	struct netlink_set_err_data info;
	struct sock *sk;
1539
	int ret = 0;
L
Linus Torvalds 已提交
1540 1541

	info.exclude_sk = ssk;
1542
	info.portid = portid;
L
Linus Torvalds 已提交
1543
	info.group = group;
1544 1545
	/* sk->sk_err wants a positive error value */
	info.code = -code;
L
Linus Torvalds 已提交
1546 1547 1548

	read_lock(&nl_table_lock);

1549
	sk_for_each_bound(sk, &nl_table[ssk->sk_protocol].mc_list)
1550
		ret += do_one_set_err(sk, &info);
L
Linus Torvalds 已提交
1551 1552

	read_unlock(&nl_table_lock);
1553
	return ret;
L
Linus Torvalds 已提交
1554
}
1555
EXPORT_SYMBOL(netlink_set_err);
L
Linus Torvalds 已提交
1556

1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573
/* must be called with netlink table grabbed */
static void netlink_update_socket_mc(struct netlink_sock *nlk,
				     unsigned int group,
				     int is_new)
{
	int old, new = !!is_new, subscriptions;

	old = test_bit(group - 1, nlk->groups);
	subscriptions = nlk->subscriptions - old + new;
	if (new)
		__set_bit(group - 1, nlk->groups);
	else
		__clear_bit(group - 1, nlk->groups);
	netlink_update_subscriptions(&nlk->sk, subscriptions);
	netlink_update_listeners(&nlk->sk);
}

1574
static int netlink_setsockopt(struct socket *sock, int level, int optname,
1575
			      char __user *optval, unsigned int optlen)
1576 1577 1578
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1579 1580
	unsigned int val = 0;
	int err;
1581 1582 1583 1584

	if (level != SOL_NETLINK)
		return -ENOPROTOOPT;

1585
	if (optlen >= sizeof(int) &&
1586
	    get_user(val, (unsigned int __user *)optval))
1587 1588 1589 1590 1591
		return -EFAULT;

	switch (optname) {
	case NETLINK_PKTINFO:
		if (val)
1592
			nlk->flags |= NETLINK_F_RECV_PKTINFO;
1593
		else
1594
			nlk->flags &= ~NETLINK_F_RECV_PKTINFO;
1595 1596 1597 1598
		err = 0;
		break;
	case NETLINK_ADD_MEMBERSHIP:
	case NETLINK_DROP_MEMBERSHIP: {
1599
		if (!netlink_allowed(sock, NL_CFG_F_NONROOT_RECV))
1600
			return -EPERM;
1601 1602 1603
		err = netlink_realloc_groups(sk);
		if (err)
			return err;
1604 1605
		if (!val || val - 1 >= nlk->ngroups)
			return -EINVAL;
1606
		if (optname == NETLINK_ADD_MEMBERSHIP && nlk->netlink_bind) {
1607
			err = nlk->netlink_bind(sock_net(sk), val);
1608 1609 1610
			if (err)
				return err;
		}
1611
		netlink_table_grab();
1612 1613
		netlink_update_socket_mc(nlk, val,
					 optname == NETLINK_ADD_MEMBERSHIP);
1614
		netlink_table_ungrab();
1615
		if (optname == NETLINK_DROP_MEMBERSHIP && nlk->netlink_unbind)
1616
			nlk->netlink_unbind(sock_net(sk), val);
1617

1618 1619 1620
		err = 0;
		break;
	}
1621 1622
	case NETLINK_BROADCAST_ERROR:
		if (val)
1623
			nlk->flags |= NETLINK_F_BROADCAST_SEND_ERROR;
1624
		else
1625
			nlk->flags &= ~NETLINK_F_BROADCAST_SEND_ERROR;
1626 1627
		err = 0;
		break;
1628 1629
	case NETLINK_NO_ENOBUFS:
		if (val) {
1630 1631
			nlk->flags |= NETLINK_F_RECV_NO_ENOBUFS;
			clear_bit(NETLINK_S_CONGESTED, &nlk->state);
1632
			wake_up_interruptible(&nlk->wait);
E
Eric Dumazet 已提交
1633
		} else {
1634
			nlk->flags &= ~NETLINK_F_RECV_NO_ENOBUFS;
E
Eric Dumazet 已提交
1635
		}
1636 1637
		err = 0;
		break;
1638 1639 1640 1641 1642 1643 1644 1645 1646 1647
	case NETLINK_LISTEN_ALL_NSID:
		if (!ns_capable(sock_net(sk)->user_ns, CAP_NET_BROADCAST))
			return -EPERM;

		if (val)
			nlk->flags |= NETLINK_F_LISTEN_ALL_NSID;
		else
			nlk->flags &= ~NETLINK_F_LISTEN_ALL_NSID;
		err = 0;
		break;
1648 1649 1650 1651 1652 1653 1654
	case NETLINK_CAP_ACK:
		if (val)
			nlk->flags |= NETLINK_F_CAP_ACK;
		else
			nlk->flags &= ~NETLINK_F_CAP_ACK;
		err = 0;
		break;
1655 1656 1657 1658 1659 1660 1661
	default:
		err = -ENOPROTOOPT;
	}
	return err;
}

static int netlink_getsockopt(struct socket *sock, int level, int optname,
1662
			      char __user *optval, int __user *optlen)
1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
	int len, val, err;

	if (level != SOL_NETLINK)
		return -ENOPROTOOPT;

	if (get_user(len, optlen))
		return -EFAULT;
	if (len < 0)
		return -EINVAL;

	switch (optname) {
	case NETLINK_PKTINFO:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
1681
		val = nlk->flags & NETLINK_F_RECV_PKTINFO ? 1 : 0;
H
Heiko Carstens 已提交
1682 1683 1684
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
1685 1686
		err = 0;
		break;
1687 1688 1689 1690
	case NETLINK_BROADCAST_ERROR:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
1691
		val = nlk->flags & NETLINK_F_BROADCAST_SEND_ERROR ? 1 : 0;
1692 1693 1694 1695 1696
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
		err = 0;
		break;
1697 1698 1699 1700
	case NETLINK_NO_ENOBUFS:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
1701
		val = nlk->flags & NETLINK_F_RECV_NO_ENOBUFS ? 1 : 0;
1702 1703 1704 1705 1706
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
		err = 0;
		break;
1707 1708 1709 1710
	case NETLINK_LIST_MEMBERSHIPS: {
		int pos, idx, shift;

		err = 0;
1711
		netlink_lock_table();
1712 1713 1714 1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725
		for (pos = 0; pos * 8 < nlk->ngroups; pos += sizeof(u32)) {
			if (len - pos < sizeof(u32))
				break;

			idx = pos / sizeof(unsigned long);
			shift = (pos % sizeof(unsigned long)) * 8;
			if (put_user((u32)(nlk->groups[idx] >> shift),
				     (u32 __user *)(optval + pos))) {
				err = -EFAULT;
				break;
			}
		}
		if (put_user(ALIGN(nlk->ngroups / 8, sizeof(u32)), optlen))
			err = -EFAULT;
1726
		netlink_unlock_table();
1727 1728
		break;
	}
1729 1730 1731 1732 1733 1734 1735 1736 1737 1738
	case NETLINK_CAP_ACK:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
		val = nlk->flags & NETLINK_F_CAP_ACK ? 1 : 0;
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
		err = 0;
		break;
1739 1740 1741 1742 1743 1744 1745 1746 1747 1748 1749 1750 1751 1752
	default:
		err = -ENOPROTOOPT;
	}
	return err;
}

static void netlink_cmsg_recv_pktinfo(struct msghdr *msg, struct sk_buff *skb)
{
	struct nl_pktinfo info;

	info.group = NETLINK_CB(skb).dst_group;
	put_cmsg(msg, SOL_NETLINK, NETLINK_PKTINFO, sizeof(info), &info);
}

1753 1754 1755 1756 1757 1758 1759 1760 1761 1762
static void netlink_cmsg_listen_all_nsid(struct sock *sk, struct msghdr *msg,
					 struct sk_buff *skb)
{
	if (!NETLINK_CB(skb).nsid_is_set)
		return;

	put_cmsg(msg, SOL_NETLINK, NETLINK_LISTEN_ALL_NSID, sizeof(int),
		 &NETLINK_CB(skb).nsid);
}

1763
static int netlink_sendmsg(struct socket *sock, struct msghdr *msg, size_t len)
L
Linus Torvalds 已提交
1764 1765 1766
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1767
	DECLARE_SOCKADDR(struct sockaddr_nl *, addr, msg->msg_name);
1768
	u32 dst_portid;
1769
	u32 dst_group;
L
Linus Torvalds 已提交
1770 1771 1772
	struct sk_buff *skb;
	int err;
	struct scm_cookie scm;
1773
	u32 netlink_skb_flags = 0;
L
Linus Torvalds 已提交
1774 1775 1776 1777

	if (msg->msg_flags&MSG_OOB)
		return -EOPNOTSUPP;

C
Christoph Hellwig 已提交
1778
	err = scm_send(sock, msg, &scm, true);
L
Linus Torvalds 已提交
1779 1780 1781 1782
	if (err < 0)
		return err;

	if (msg->msg_namelen) {
1783
		err = -EINVAL;
L
Linus Torvalds 已提交
1784
		if (addr->nl_family != AF_NETLINK)
1785
			goto out;
1786
		dst_portid = addr->nl_pid;
1787
		dst_group = ffs(addr->nl_groups);
1788
		err =  -EPERM;
1789
		if ((dst_group || dst_portid) &&
1790
		    !netlink_allowed(sock, NL_CFG_F_NONROOT_SEND))
1791
			goto out;
1792
		netlink_skb_flags |= NETLINK_SKB_DST;
L
Linus Torvalds 已提交
1793
	} else {
1794
		dst_portid = nlk->dst_portid;
1795
		dst_group = nlk->dst_group;
L
Linus Torvalds 已提交
1796 1797
	}

1798
	if (!nlk->bound) {
L
Linus Torvalds 已提交
1799 1800 1801
		err = netlink_autobind(sock);
		if (err)
			goto out;
1802 1803 1804
	} else {
		/* Ensure nlk is hashed and visible. */
		smp_rmb();
L
Linus Torvalds 已提交
1805 1806 1807 1808 1809 1810
	}

	err = -EMSGSIZE;
	if (len > sk->sk_sndbuf - 32)
		goto out;
	err = -ENOBUFS;
1811
	skb = netlink_alloc_large_skb(len, dst_group);
1812
	if (skb == NULL)
L
Linus Torvalds 已提交
1813 1814
		goto out;

1815
	NETLINK_CB(skb).portid	= nlk->portid;
1816
	NETLINK_CB(skb).dst_group = dst_group;
C
Christoph Hellwig 已提交
1817
	NETLINK_CB(skb).creds	= scm.creds;
1818
	NETLINK_CB(skb).flags	= netlink_skb_flags;
L
Linus Torvalds 已提交
1819 1820

	err = -EFAULT;
A
Al Viro 已提交
1821
	if (memcpy_from_msg(skb_put(skb, len), msg, len)) {
L
Linus Torvalds 已提交
1822 1823 1824 1825 1826 1827 1828 1829 1830 1831
		kfree_skb(skb);
		goto out;
	}

	err = security_netlink_send(sk, skb);
	if (err) {
		kfree_skb(skb);
		goto out;
	}

1832
	if (dst_group) {
L
Linus Torvalds 已提交
1833
		atomic_inc(&skb->users);
1834
		netlink_broadcast(sk, skb, dst_portid, dst_group, GFP_KERNEL);
L
Linus Torvalds 已提交
1835
	}
1836
	err = netlink_unicast(sk, skb, dst_portid, msg->msg_flags&MSG_DONTWAIT);
L
Linus Torvalds 已提交
1837 1838

out:
C
Christoph Hellwig 已提交
1839
	scm_destroy(&scm);
L
Linus Torvalds 已提交
1840 1841 1842
	return err;
}

1843
static int netlink_recvmsg(struct socket *sock, struct msghdr *msg, size_t len,
L
Linus Torvalds 已提交
1844 1845 1846 1847 1848 1849 1850
			   int flags)
{
	struct scm_cookie scm;
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
	int noblock = flags&MSG_DONTWAIT;
	size_t copied;
J
Johannes Berg 已提交
1851
	struct sk_buff *skb, *data_skb;
1852
	int err, ret;
L
Linus Torvalds 已提交
1853 1854 1855 1856 1857 1858

	if (flags&MSG_OOB)
		return -EOPNOTSUPP;

	copied = 0;

1859 1860
	skb = skb_recv_datagram(sk, flags, noblock, &err);
	if (skb == NULL)
L
Linus Torvalds 已提交
1861 1862
		goto out;

J
Johannes Berg 已提交
1863 1864
	data_skb = skb;

1865 1866 1867
#ifdef CONFIG_COMPAT_NETLINK_MESSAGES
	if (unlikely(skb_shinfo(skb)->frag_list)) {
		/*
J
Johannes Berg 已提交
1868 1869 1870
		 * If this skb has a frag_list, then here that means that we
		 * will have to use the frag_list skb's data for compat tasks
		 * and the regular skb's data for normal (non-compat) tasks.
1871
		 *
J
Johannes Berg 已提交
1872 1873 1874 1875
		 * If we need to send the compat skb, assign it to the
		 * 'data_skb' variable so that it will be used below for data
		 * copying. We keep 'skb' for everything else, including
		 * freeing both later.
1876
		 */
J
Johannes Berg 已提交
1877 1878
		if (flags & MSG_CMSG_COMPAT)
			data_skb = skb_shinfo(skb)->frag_list;
1879 1880 1881
	}
#endif

E
Eric Dumazet 已提交
1882 1883 1884
	/* Record the max length of recvmsg() calls for future allocations */
	nlk->max_recvmsg_len = max(nlk->max_recvmsg_len, len);
	nlk->max_recvmsg_len = min_t(size_t, nlk->max_recvmsg_len,
1885
				     SKB_WITH_OVERHEAD(32768));
E
Eric Dumazet 已提交
1886

J
Johannes Berg 已提交
1887
	copied = data_skb->len;
L
Linus Torvalds 已提交
1888 1889 1890 1891 1892
	if (len < copied) {
		msg->msg_flags |= MSG_TRUNC;
		copied = len;
	}

J
Johannes Berg 已提交
1893
	skb_reset_transport_header(data_skb);
1894
	err = skb_copy_datagram_msg(data_skb, 0, msg, copied);
L
Linus Torvalds 已提交
1895 1896

	if (msg->msg_name) {
1897
		DECLARE_SOCKADDR(struct sockaddr_nl *, addr, msg->msg_name);
L
Linus Torvalds 已提交
1898 1899
		addr->nl_family = AF_NETLINK;
		addr->nl_pad    = 0;
1900
		addr->nl_pid	= NETLINK_CB(skb).portid;
1901
		addr->nl_groups	= netlink_group_mask(NETLINK_CB(skb).dst_group);
L
Linus Torvalds 已提交
1902 1903 1904
		msg->msg_namelen = sizeof(*addr);
	}

1905
	if (nlk->flags & NETLINK_F_RECV_PKTINFO)
1906
		netlink_cmsg_recv_pktinfo(msg, skb);
1907 1908
	if (nlk->flags & NETLINK_F_LISTEN_ALL_NSID)
		netlink_cmsg_listen_all_nsid(sk, msg, skb);
1909

C
Christoph Hellwig 已提交
1910 1911
	memset(&scm, 0, sizeof(scm));
	scm.creds = *NETLINK_CREDS(skb);
1912
	if (flags & MSG_TRUNC)
J
Johannes Berg 已提交
1913
		copied = data_skb->len;
1914

L
Linus Torvalds 已提交
1915 1916
	skb_free_datagram(sk, skb);

1917 1918
	if (nlk->cb_running &&
	    atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf / 2) {
1919 1920
		ret = netlink_dump(sk);
		if (ret) {
1921
			sk->sk_err = -ret;
1922 1923 1924
			sk->sk_error_report(sk);
		}
	}
L
Linus Torvalds 已提交
1925

C
Christoph Hellwig 已提交
1926
	scm_recv(sock, msg, &scm, flags);
L
Linus Torvalds 已提交
1927 1928 1929 1930 1931
out:
	netlink_rcv_wake(sk);
	return err ? : copied;
}

1932
static void netlink_data_ready(struct sock *sk)
L
Linus Torvalds 已提交
1933
{
1934
	BUG();
L
Linus Torvalds 已提交
1935 1936 1937
}

/*
1938
 *	We export these functions to other modules. They provide a
L
Linus Torvalds 已提交
1939 1940 1941 1942 1943
 *	complete set of kernel non-blocking support for message
 *	queueing.
 */

struct sock *
1944 1945
__netlink_kernel_create(struct net *net, int unit, struct module *module,
			struct netlink_kernel_cfg *cfg)
L
Linus Torvalds 已提交
1946 1947 1948
{
	struct socket *sock;
	struct sock *sk;
1949
	struct netlink_sock *nlk;
1950
	struct listeners *listeners = NULL;
1951 1952
	struct mutex *cb_mutex = cfg ? cfg->cb_mutex : NULL;
	unsigned int groups;
L
Linus Torvalds 已提交
1953

1954
	BUG_ON(!nl_table);
L
Linus Torvalds 已提交
1955

1956
	if (unit < 0 || unit >= MAX_LINKS)
L
Linus Torvalds 已提交
1957 1958 1959 1960
		return NULL;

	if (sock_create_lite(PF_NETLINK, SOCK_DGRAM, unit, &sock))
		return NULL;
1961 1962

	if (__netlink_create(net, sock, cb_mutex, unit, 1) < 0)
1963 1964 1965
		goto out_sock_release_nosk;

	sk = sock->sk;
1966

1967
	if (!cfg || cfg->groups < 32)
1968
		groups = 32;
1969 1970
	else
		groups = cfg->groups;
1971

1972
	listeners = kzalloc(sizeof(*listeners) + NLGRPSZ(groups), GFP_KERNEL);
1973 1974 1975
	if (!listeners)
		goto out_sock_release;

L
Linus Torvalds 已提交
1976
	sk->sk_data_ready = netlink_data_ready;
1977 1978
	if (cfg && cfg->input)
		nlk_sk(sk)->netlink_rcv = cfg->input;
L
Linus Torvalds 已提交
1979

1980
	if (netlink_insert(sk, 0))
1981
		goto out_sock_release;
1982

1983
	nlk = nlk_sk(sk);
1984
	nlk->flags |= NETLINK_F_KERNEL_SOCKET;
1985 1986

	netlink_table_grab();
1987 1988
	if (!nl_table[unit].registered) {
		nl_table[unit].groups = groups;
1989
		rcu_assign_pointer(nl_table[unit].listeners, listeners);
1990 1991
		nl_table[unit].cb_mutex = cb_mutex;
		nl_table[unit].module = module;
1992 1993
		if (cfg) {
			nl_table[unit].bind = cfg->bind;
1994
			nl_table[unit].unbind = cfg->unbind;
1995
			nl_table[unit].flags = cfg->flags;
1996 1997
			if (cfg->compare)
				nl_table[unit].compare = cfg->compare;
1998
		}
1999
		nl_table[unit].registered = 1;
2000 2001
	} else {
		kfree(listeners);
2002
		nl_table[unit].registered++;
2003
	}
2004
	netlink_table_ungrab();
2005 2006
	return sk;

2007
out_sock_release:
2008
	kfree(listeners);
2009
	netlink_kernel_release(sk);
2010 2011 2012
	return NULL;

out_sock_release_nosk:
2013
	sock_release(sock);
2014
	return NULL;
L
Linus Torvalds 已提交
2015
}
2016
EXPORT_SYMBOL(__netlink_kernel_create);
2017 2018 2019 2020

void
netlink_kernel_release(struct sock *sk)
{
2021 2022 2023 2024
	if (sk == NULL || sk->sk_socket == NULL)
		return;

	sock_release(sk->sk_socket);
2025 2026 2027
}
EXPORT_SYMBOL(netlink_kernel_release);

2028
int __netlink_change_ngroups(struct sock *sk, unsigned int groups)
2029
{
2030
	struct listeners *new, *old;
2031 2032 2033 2034 2035 2036
	struct netlink_table *tbl = &nl_table[sk->sk_protocol];

	if (groups < 32)
		groups = 32;

	if (NLGRPSZ(tbl->groups) < NLGRPSZ(groups)) {
2037 2038
		new = kzalloc(sizeof(*new) + NLGRPSZ(groups), GFP_ATOMIC);
		if (!new)
2039
			return -ENOMEM;
2040
		old = nl_deref_protected(tbl->listeners);
2041 2042 2043
		memcpy(new->masks, old->masks, NLGRPSZ(tbl->groups));
		rcu_assign_pointer(tbl->listeners, new);

2044
		kfree_rcu(old, rcu);
2045 2046 2047
	}
	tbl->groups = groups;

2048 2049 2050 2051 2052 2053 2054 2055 2056 2057 2058 2059 2060 2061 2062 2063 2064 2065 2066 2067 2068
	return 0;
}

/**
 * netlink_change_ngroups - change number of multicast groups
 *
 * This changes the number of multicast groups that are available
 * on a certain netlink family. Note that it is not possible to
 * change the number of groups to below 32. Also note that it does
 * not implicitly call netlink_clear_multicast_users() when the
 * number of groups is reduced.
 *
 * @sk: The kernel netlink socket, as returned by netlink_kernel_create().
 * @groups: The new number of groups.
 */
int netlink_change_ngroups(struct sock *sk, unsigned int groups)
{
	int err;

	netlink_table_grab();
	err = __netlink_change_ngroups(sk, groups);
2069
	netlink_table_ungrab();
2070

2071 2072 2073
	return err;
}

2074 2075 2076 2077 2078
void __netlink_clear_multicast_users(struct sock *ksk, unsigned int group)
{
	struct sock *sk;
	struct netlink_table *tbl = &nl_table[ksk->sk_protocol];

2079
	sk_for_each_bound(sk, &tbl->mc_list)
2080 2081 2082
		netlink_update_socket_mc(nlk_sk(sk), group, 0);
}

2083
struct nlmsghdr *
2084
__nlmsg_put(struct sk_buff *skb, u32 portid, u32 seq, int type, int len, int flags)
2085 2086
{
	struct nlmsghdr *nlh;
2087
	int size = nlmsg_msg_size(len);
2088

2089
	nlh = (struct nlmsghdr *)skb_put(skb, NLMSG_ALIGN(size));
2090 2091 2092
	nlh->nlmsg_type = type;
	nlh->nlmsg_len = size;
	nlh->nlmsg_flags = flags;
2093
	nlh->nlmsg_pid = portid;
2094 2095
	nlh->nlmsg_seq = seq;
	if (!__builtin_constant_p(size) || NLMSG_ALIGN(size) - size != 0)
2096
		memset(nlmsg_data(nlh) + len, 0, NLMSG_ALIGN(size) - size);
2097 2098 2099 2100
	return nlh;
}
EXPORT_SYMBOL(__nlmsg_put);

L
Linus Torvalds 已提交
2101 2102 2103 2104 2105 2106 2107 2108 2109
/*
 * It looks a bit ugly.
 * It would be better to create kernel thread.
 */

static int netlink_dump(struct sock *sk)
{
	struct netlink_sock *nlk = nlk_sk(sk);
	struct netlink_callback *cb;
2110
	struct sk_buff *skb = NULL;
L
Linus Torvalds 已提交
2111
	struct nlmsghdr *nlh;
2112
	struct module *module;
2113
	int len, err = -ENOBUFS;
2114
	int alloc_min_size;
2115
	int alloc_size;
L
Linus Torvalds 已提交
2116

2117
	mutex_lock(nlk->cb_mutex);
2118
	if (!nlk->cb_running) {
2119 2120
		err = -EINVAL;
		goto errout_skb;
L
Linus Torvalds 已提交
2121 2122
	}

2123
	if (atomic_read(&sk->sk_rmem_alloc) >= sk->sk_rcvbuf)
2124
		goto errout_skb;
E
Eric Dumazet 已提交
2125 2126 2127 2128 2129 2130

	/* NLMSG_GOODSIZE is small to avoid high order allocations being
	 * required, but it makes sense to _attempt_ a 16K bytes allocation
	 * to reduce number of system calls on dump operations, if user
	 * ever provided a big enough buffer.
	 */
2131 2132 2133 2134 2135
	cb = &nlk->cb;
	alloc_min_size = max_t(int, cb->min_dump_alloc, NLMSG_GOODSIZE);

	if (alloc_min_size < nlk->max_recvmsg_len) {
		alloc_size = nlk->max_recvmsg_len;
2136 2137 2138
		skb = alloc_skb(alloc_size,
				(GFP_KERNEL & ~__GFP_DIRECT_RECLAIM) |
				__GFP_NOWARN | __GFP_NORETRY);
E
Eric Dumazet 已提交
2139
	}
2140 2141
	if (!skb) {
		alloc_size = alloc_min_size;
2142
		skb = alloc_skb(alloc_size, GFP_KERNEL);
2143
	}
2144
	if (!skb)
2145
		goto errout_skb;
2146 2147 2148 2149 2150 2151 2152 2153 2154 2155 2156

	/* Trim skb to allocated size. User is expected to provide buffer as
	 * large as max(min_dump_alloc, 16KiB (mac_recvmsg_len capped at
	 * netlink_recvmsg())). dump will pack as many smaller messages as
	 * could fit within the allocated skb. skb is typically allocated
	 * with larger space than required (could be as much as near 2x the
	 * requested size with align to next power of 2 approach). Allowing
	 * dump to use the excess space makes it difficult for a user to have a
	 * reasonable static buffer based on the expected largest dump of a
	 * single netdev. The outcome is MSG_TRUNC error.
	 */
2157
	skb_reserve(skb, skb_tailroom(skb) - alloc_size);
2158
	netlink_skb_set_owner_r(skb, sk);
2159

L
Linus Torvalds 已提交
2160 2161 2162
	len = cb->dump(skb, cb);

	if (len > 0) {
2163
		mutex_unlock(nlk->cb_mutex);
2164 2165 2166

		if (sk_filter(sk, skb))
			kfree_skb(skb);
2167 2168
		else
			__netlink_sendskb(sk, skb);
L
Linus Torvalds 已提交
2169 2170 2171
		return 0;
	}

2172 2173 2174 2175
	nlh = nlmsg_put_answer(skb, cb, NLMSG_DONE, sizeof(len), NLM_F_MULTI);
	if (!nlh)
		goto errout_skb;

2176 2177
	nl_dump_check_consistent(cb, nlh);

2178 2179
	memcpy(nlmsg_data(nlh), &len, sizeof(len));

2180 2181
	if (sk_filter(sk, skb))
		kfree_skb(skb);
2182 2183
	else
		__netlink_sendskb(sk, skb);
L
Linus Torvalds 已提交
2184

2185 2186
	if (cb->done)
		cb->done(cb);
L
Linus Torvalds 已提交
2187

2188
	nlk->cb_running = false;
2189 2190
	module = cb->module;
	skb = cb->skb;
2191
	mutex_unlock(nlk->cb_mutex);
2192 2193
	module_put(module);
	consume_skb(skb);
L
Linus Torvalds 已提交
2194
	return 0;
2195

2196
errout_skb:
2197
	mutex_unlock(nlk->cb_mutex);
2198 2199
	kfree_skb(skb);
	return err;
L
Linus Torvalds 已提交
2200 2201
}

2202 2203 2204
int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb,
			 const struct nlmsghdr *nlh,
			 struct netlink_dump_control *control)
L
Linus Torvalds 已提交
2205 2206 2207 2208
{
	struct netlink_callback *cb;
	struct sock *sk;
	struct netlink_sock *nlk;
2209
	int ret;
L
Linus Torvalds 已提交
2210

2211
	atomic_inc(&skb->users);
2212

2213
	sk = netlink_lookup(sock_net(ssk), ssk->sk_protocol, NETLINK_CB(skb).portid);
L
Linus Torvalds 已提交
2214
	if (sk == NULL) {
2215 2216
		ret = -ECONNREFUSED;
		goto error_free;
L
Linus Torvalds 已提交
2217
	}
2218

2219
	nlk = nlk_sk(sk);
2220
	mutex_lock(nlk->cb_mutex);
2221
	/* A dump is in progress... */
2222
	if (nlk->cb_running) {
2223
		ret = -EBUSY;
2224
		goto error_unlock;
L
Linus Torvalds 已提交
2225
	}
2226
	/* add reference of module which cb->dump belongs to */
2227
	if (!try_module_get(control->module)) {
2228
		ret = -EPROTONOSUPPORT;
2229
		goto error_unlock;
2230 2231
	}

2232 2233
	cb = &nlk->cb;
	memset(cb, 0, sizeof(*cb));
2234
	cb->start = control->start;
2235 2236 2237 2238 2239 2240 2241 2242 2243 2244
	cb->dump = control->dump;
	cb->done = control->done;
	cb->nlh = nlh;
	cb->data = control->data;
	cb->module = control->module;
	cb->min_dump_alloc = control->min_dump_alloc;
	cb->skb = skb;

	nlk->cb_running = true;

2245
	mutex_unlock(nlk->cb_mutex);
L
Linus Torvalds 已提交
2246

2247 2248 2249
	if (cb->start)
		cb->start(cb);

2250
	ret = netlink_dump(sk);
L
Linus Torvalds 已提交
2251
	sock_put(sk);
2252

2253 2254 2255
	if (ret)
		return ret;

2256 2257 2258 2259
	/* We successfully started a dump, by returning -EINTR we
	 * signal not to send ACK even if it was requested.
	 */
	return -EINTR;
2260 2261 2262 2263 2264 2265 2266

error_unlock:
	sock_put(sk);
	mutex_unlock(nlk->cb_mutex);
error_free:
	kfree_skb(skb);
	return ret;
L
Linus Torvalds 已提交
2267
}
2268
EXPORT_SYMBOL(__netlink_dump_start);
L
Linus Torvalds 已提交
2269 2270 2271 2272 2273 2274

void netlink_ack(struct sk_buff *in_skb, struct nlmsghdr *nlh, int err)
{
	struct sk_buff *skb;
	struct nlmsghdr *rep;
	struct nlmsgerr *errmsg;
2275
	size_t payload = sizeof(*errmsg);
2276
	struct netlink_sock *nlk = nlk_sk(NETLINK_CB(in_skb).sk);
L
Linus Torvalds 已提交
2277

2278 2279 2280 2281
	/* Error messages get the original request appened, unless the user
	 * requests to cap the error message.
	 */
	if (!(nlk->flags & NETLINK_F_CAP_ACK) && err)
2282
		payload += nlmsg_len(nlh);
L
Linus Torvalds 已提交
2283

2284
	skb = nlmsg_new(payload, GFP_KERNEL);
L
Linus Torvalds 已提交
2285 2286 2287
	if (!skb) {
		struct sock *sk;

2288
		sk = netlink_lookup(sock_net(in_skb->sk),
2289
				    in_skb->sk->sk_protocol,
2290
				    NETLINK_CB(in_skb).portid);
L
Linus Torvalds 已提交
2291 2292 2293 2294 2295 2296 2297 2298
		if (sk) {
			sk->sk_err = ENOBUFS;
			sk->sk_error_report(sk);
			sock_put(sk);
		}
		return;
	}

2299
	rep = __nlmsg_put(skb, NETLINK_CB(in_skb).portid, nlh->nlmsg_seq,
2300
			  NLMSG_ERROR, payload, 0);
2301
	errmsg = nlmsg_data(rep);
L
Linus Torvalds 已提交
2302
	errmsg->error = err;
2303
	memcpy(&errmsg->msg, nlh, payload > sizeof(*errmsg) ? nlh->nlmsg_len : sizeof(*nlh));
2304
	netlink_unicast(in_skb->sk, skb, NETLINK_CB(in_skb).portid, MSG_DONTWAIT);
L
Linus Torvalds 已提交
2305
}
2306
EXPORT_SYMBOL(netlink_ack);
L
Linus Torvalds 已提交
2307

2308
int netlink_rcv_skb(struct sk_buff *skb, int (*cb)(struct sk_buff *,
2309
						     struct nlmsghdr *))
2310 2311 2312 2313 2314
{
	struct nlmsghdr *nlh;
	int err;

	while (skb->len >= nlmsg_total_size(0)) {
2315 2316
		int msglen;

2317
		nlh = nlmsg_hdr(skb);
2318
		err = 0;
2319

2320
		if (nlh->nlmsg_len < NLMSG_HDRLEN || skb->len < nlh->nlmsg_len)
2321 2322
			return 0;

2323 2324
		/* Only requests are handled by the kernel */
		if (!(nlh->nlmsg_flags & NLM_F_REQUEST))
2325
			goto ack;
2326 2327 2328

		/* Skip control messages */
		if (nlh->nlmsg_type < NLMSG_MIN_TYPE)
2329
			goto ack;
2330

2331
		err = cb(skb, nlh);
2332 2333 2334 2335
		if (err == -EINTR)
			goto skip;

ack:
2336
		if (nlh->nlmsg_flags & NLM_F_ACK || err)
2337 2338
			netlink_ack(skb, nlh, err);

2339
skip:
2340
		msglen = NLMSG_ALIGN(nlh->nlmsg_len);
2341 2342 2343
		if (msglen > skb->len)
			msglen = skb->len;
		skb_pull(skb, msglen);
2344 2345 2346 2347
	}

	return 0;
}
2348
EXPORT_SYMBOL(netlink_rcv_skb);
2349

2350 2351 2352 2353
/**
 * nlmsg_notify - send a notification netlink message
 * @sk: netlink socket to use
 * @skb: notification message
2354
 * @portid: destination netlink portid for reports or 0
2355 2356 2357 2358
 * @group: destination multicast group or 0
 * @report: 1 to report back, 0 to disable
 * @flags: allocation flags
 */
2359
int nlmsg_notify(struct sock *sk, struct sk_buff *skb, u32 portid,
2360 2361 2362 2363 2364
		 unsigned int group, int report, gfp_t flags)
{
	int err = 0;

	if (group) {
2365
		int exclude_portid = 0;
2366 2367 2368

		if (report) {
			atomic_inc(&skb->users);
2369
			exclude_portid = portid;
2370 2371
		}

2372 2373
		/* errors reported via destination sk->sk_err, but propagate
		 * delivery errors if NETLINK_BROADCAST_ERROR flag is set */
2374
		err = nlmsg_multicast(sk, skb, exclude_portid, group, flags);
2375 2376
	}

2377 2378 2379
	if (report) {
		int err2;

2380
		err2 = nlmsg_unicast(sk, skb, portid);
2381 2382 2383
		if (!err || err == -ESRCH)
			err = err2;
	}
2384 2385 2386

	return err;
}
2387
EXPORT_SYMBOL(nlmsg_notify);
2388

L
Linus Torvalds 已提交
2389 2390
#ifdef CONFIG_PROC_FS
struct nl_seq_iter {
2391
	struct seq_net_private p;
2392
	struct rhashtable_iter hti;
L
Linus Torvalds 已提交
2393 2394 2395
	int link;
};

2396
static int netlink_walk_start(struct nl_seq_iter *iter)
L
Linus Torvalds 已提交
2397
{
2398
	int err;
L
Linus Torvalds 已提交
2399

2400 2401
	err = rhashtable_walk_init(&nl_table[iter->link].hash, &iter->hti,
				   GFP_KERNEL);
2402 2403 2404
	if (err) {
		iter->link = MAX_LINKS;
		return err;
L
Linus Torvalds 已提交
2405
	}
2406 2407 2408

	err = rhashtable_walk_start(&iter->hti);
	return err == -EAGAIN ? 0 : err;
L
Linus Torvalds 已提交
2409 2410
}

2411
static void netlink_walk_stop(struct nl_seq_iter *iter)
L
Linus Torvalds 已提交
2412
{
2413 2414
	rhashtable_walk_stop(&iter->hti);
	rhashtable_walk_exit(&iter->hti);
L
Linus Torvalds 已提交
2415 2416
}

2417
static void *__netlink_seq_next(struct seq_file *seq)
L
Linus Torvalds 已提交
2418
{
2419
	struct nl_seq_iter *iter = seq->private;
2420
	struct netlink_sock *nlk;
L
Linus Torvalds 已提交
2421

2422 2423 2424
	do {
		for (;;) {
			int err;
L
Linus Torvalds 已提交
2425

2426
			nlk = rhashtable_walk_next(&iter->hti);
2427

2428 2429 2430
			if (IS_ERR(nlk)) {
				if (PTR_ERR(nlk) == -EAGAIN)
					continue;
2431

2432 2433
				return nlk;
			}
L
Linus Torvalds 已提交
2434

2435 2436
			if (nlk)
				break;
L
Linus Torvalds 已提交
2437

2438 2439 2440
			netlink_walk_stop(iter);
			if (++iter->link >= MAX_LINKS)
				return NULL;
2441

2442 2443 2444
			err = netlink_walk_start(iter);
			if (err)
				return ERR_PTR(err);
L
Linus Torvalds 已提交
2445
		}
2446
	} while (sock_net(&nlk->sk) != seq_file_net(seq));
L
Linus Torvalds 已提交
2447

2448 2449
	return nlk;
}
L
Linus Torvalds 已提交
2450

2451 2452 2453 2454 2455 2456 2457 2458 2459 2460 2461 2462 2463 2464 2465 2466 2467 2468 2469 2470 2471 2472 2473
static void *netlink_seq_start(struct seq_file *seq, loff_t *posp)
{
	struct nl_seq_iter *iter = seq->private;
	void *obj = SEQ_START_TOKEN;
	loff_t pos;
	int err;

	iter->link = 0;

	err = netlink_walk_start(iter);
	if (err)
		return ERR_PTR(err);

	for (pos = *posp; pos && obj && !IS_ERR(obj); pos--)
		obj = __netlink_seq_next(seq);

	return obj;
}

static void *netlink_seq_next(struct seq_file *seq, void *v, loff_t *pos)
{
	++*pos;
	return __netlink_seq_next(seq);
L
Linus Torvalds 已提交
2474 2475 2476 2477
}

static void netlink_seq_stop(struct seq_file *seq, void *v)
{
2478 2479 2480 2481 2482 2483
	struct nl_seq_iter *iter = seq->private;

	if (iter->link >= MAX_LINKS)
		return;

	netlink_walk_stop(iter);
L
Linus Torvalds 已提交
2484 2485 2486 2487 2488
}


static int netlink_seq_show(struct seq_file *seq, void *v)
{
E
Eric Dumazet 已提交
2489
	if (v == SEQ_START_TOKEN) {
L
Linus Torvalds 已提交
2490 2491
		seq_puts(seq,
			 "sk       Eth Pid    Groups   "
2492
			 "Rmem     Wmem     Dump     Locks     Drops     Inode\n");
E
Eric Dumazet 已提交
2493
	} else {
L
Linus Torvalds 已提交
2494 2495 2496
		struct sock *s = v;
		struct netlink_sock *nlk = nlk_sk(s);

2497
		seq_printf(seq, "%pK %-3d %-6u %08x %-8d %-8d %d %-8d %-8d %-8lu\n",
L
Linus Torvalds 已提交
2498 2499
			   s,
			   s->sk_protocol,
2500
			   nlk->portid,
2501
			   nlk->groups ? (u32)nlk->groups[0] : 0,
2502 2503
			   sk_rmem_alloc_get(s),
			   sk_wmem_alloc_get(s),
2504
			   nlk->cb_running,
2505
			   atomic_read(&s->sk_refcnt),
2506 2507
			   atomic_read(&s->sk_drops),
			   sock_i_ino(s)
L
Linus Torvalds 已提交
2508 2509 2510 2511 2512 2513
			);

	}
	return 0;
}

2514
static const struct seq_operations netlink_seq_ops = {
L
Linus Torvalds 已提交
2515 2516 2517 2518 2519 2520 2521 2522 2523
	.start  = netlink_seq_start,
	.next   = netlink_seq_next,
	.stop   = netlink_seq_stop,
	.show   = netlink_seq_show,
};


static int netlink_seq_open(struct inode *inode, struct file *file)
{
2524 2525
	return seq_open_net(inode, file, &netlink_seq_ops,
				sizeof(struct nl_seq_iter));
2526 2527
}

2528
static const struct file_operations netlink_seq_fops = {
L
Linus Torvalds 已提交
2529 2530 2531 2532
	.owner		= THIS_MODULE,
	.open		= netlink_seq_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
2533
	.release	= seq_release_net,
L
Linus Torvalds 已提交
2534 2535 2536 2537 2538 2539
};

#endif

int netlink_register_notifier(struct notifier_block *nb)
{
W
WANG Cong 已提交
2540
	return blocking_notifier_chain_register(&netlink_chain, nb);
L
Linus Torvalds 已提交
2541
}
2542
EXPORT_SYMBOL(netlink_register_notifier);
L
Linus Torvalds 已提交
2543 2544 2545

int netlink_unregister_notifier(struct notifier_block *nb)
{
W
WANG Cong 已提交
2546
	return blocking_notifier_chain_unregister(&netlink_chain, nb);
L
Linus Torvalds 已提交
2547
}
2548
EXPORT_SYMBOL(netlink_unregister_notifier);
2549

2550
static const struct proto_ops netlink_ops = {
L
Linus Torvalds 已提交
2551 2552 2553 2554 2555 2556 2557 2558
	.family =	PF_NETLINK,
	.owner =	THIS_MODULE,
	.release =	netlink_release,
	.bind =		netlink_bind,
	.connect =	netlink_connect,
	.socketpair =	sock_no_socketpair,
	.accept =	sock_no_accept,
	.getname =	netlink_getname,
2559
	.poll =		datagram_poll,
2560
	.ioctl =	netlink_ioctl,
L
Linus Torvalds 已提交
2561 2562
	.listen =	sock_no_listen,
	.shutdown =	sock_no_shutdown,
2563 2564
	.setsockopt =	netlink_setsockopt,
	.getsockopt =	netlink_getsockopt,
L
Linus Torvalds 已提交
2565 2566
	.sendmsg =	netlink_sendmsg,
	.recvmsg =	netlink_recvmsg,
2567
	.mmap =		sock_no_mmap,
L
Linus Torvalds 已提交
2568 2569 2570
	.sendpage =	sock_no_sendpage,
};

2571
static const struct net_proto_family netlink_family_ops = {
L
Linus Torvalds 已提交
2572 2573 2574 2575 2576
	.family = PF_NETLINK,
	.create = netlink_create,
	.owner	= THIS_MODULE,	/* for consistency 8) */
};

2577
static int __net_init netlink_net_init(struct net *net)
2578 2579
{
#ifdef CONFIG_PROC_FS
2580
	if (!proc_create("netlink", 0, net->proc_net, &netlink_seq_fops))
2581 2582 2583 2584 2585
		return -ENOMEM;
#endif
	return 0;
}

2586
static void __net_exit netlink_net_exit(struct net *net)
2587 2588
{
#ifdef CONFIG_PROC_FS
2589
	remove_proc_entry("netlink", net->proc_net);
2590 2591 2592
#endif
}

2593 2594
static void __init netlink_add_usersock_entry(void)
{
2595
	struct listeners *listeners;
2596 2597
	int groups = 32;

2598
	listeners = kzalloc(sizeof(*listeners) + NLGRPSZ(groups), GFP_KERNEL);
2599
	if (!listeners)
2600
		panic("netlink_add_usersock_entry: Cannot allocate listeners\n");
2601 2602 2603 2604

	netlink_table_grab();

	nl_table[NETLINK_USERSOCK].groups = groups;
2605
	rcu_assign_pointer(nl_table[NETLINK_USERSOCK].listeners, listeners);
2606 2607
	nl_table[NETLINK_USERSOCK].module = THIS_MODULE;
	nl_table[NETLINK_USERSOCK].registered = 1;
2608
	nl_table[NETLINK_USERSOCK].flags = NL_CFG_F_NONROOT_SEND;
2609 2610 2611 2612

	netlink_table_ungrab();
}

2613
static struct pernet_operations __net_initdata netlink_net_ops = {
2614 2615 2616 2617
	.init = netlink_net_init,
	.exit = netlink_net_exit,
};

2618
static inline u32 netlink_hash(const void *data, u32 len, u32 seed)
2619 2620 2621 2622
{
	const struct netlink_sock *nlk = data;
	struct netlink_compare_arg arg;

2623
	netlink_compare_arg_init(&arg, sock_net(&nlk->sk), nlk->portid);
2624
	return jhash2((u32 *)&arg, netlink_compare_arg_len / sizeof(u32), seed);
2625 2626 2627 2628 2629 2630 2631
}

static const struct rhashtable_params netlink_rhashtable_params = {
	.head_offset = offsetof(struct netlink_sock, node),
	.key_len = netlink_compare_arg_len,
	.obj_hashfn = netlink_hash,
	.obj_cmpfn = netlink_compare,
2632
	.automatic_shrinking = true,
2633 2634
};

L
Linus Torvalds 已提交
2635 2636 2637 2638 2639 2640 2641 2642
static int __init netlink_proto_init(void)
{
	int i;
	int err = proto_register(&netlink_proto, 0);

	if (err != 0)
		goto out;

2643
	BUILD_BUG_ON(sizeof(struct netlink_skb_parms) > FIELD_SIZEOF(struct sk_buff, cb));
L
Linus Torvalds 已提交
2644

2645
	nl_table = kcalloc(MAX_LINKS, sizeof(*nl_table), GFP_KERNEL);
2646 2647
	if (!nl_table)
		goto panic;
L
Linus Torvalds 已提交
2648 2649

	for (i = 0; i < MAX_LINKS; i++) {
2650 2651
		if (rhashtable_init(&nl_table[i].hash,
				    &netlink_rhashtable_params) < 0) {
2652 2653
			while (--i > 0)
				rhashtable_destroy(&nl_table[i].hash);
L
Linus Torvalds 已提交
2654
			kfree(nl_table);
2655
			goto panic;
L
Linus Torvalds 已提交
2656 2657 2658
		}
	}

2659 2660
	INIT_LIST_HEAD(&netlink_tap_all);

2661 2662
	netlink_add_usersock_entry();

L
Linus Torvalds 已提交
2663
	sock_register(&netlink_family_ops);
2664
	register_pernet_subsys(&netlink_net_ops);
2665
	/* The netlink device handler may be needed early. */
L
Linus Torvalds 已提交
2666 2667 2668
	rtnetlink_init();
out:
	return err;
2669 2670
panic:
	panic("netlink_init: Cannot allocate nl_table\n");
L
Linus Torvalds 已提交
2671 2672 2673
}

core_initcall(netlink_proto_init);