af_netlink.c 63.1 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3
/*
 * NETLINK      Kernel-user communication protocol.
 *
4
 * 		Authors:	Alan Cox <alan@lxorguk.ukuu.org.uk>
L
Linus Torvalds 已提交
5
 * 				Alexey Kuznetsov <kuznet@ms2.inr.ac.ru>
6
 * 				Patrick McHardy <kaber@trash.net>
L
Linus Torvalds 已提交
7 8 9 10 11
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
12
 *
L
Linus Torvalds 已提交
13 14 15 16
 * Tue Jun 26 14:36:48 MEST 2001 Herbert "herp" Rosmanith
 *                               added netlink_proto_exit
 * Tue Jan 22 18:32:44 BRST 2002 Arnaldo C. de Melo <acme@conectiva.com.br>
 * 				 use nlk_sk, as sk->protinfo is on a diet 8)
17 18 19 20 21 22
 * Fri Jul 22 19:51:12 MEST 2005 Harald Welte <laforge@gnumonks.org>
 * 				 - inc module use count of module that owns
 * 				   the kernel socket in case userspace opens
 * 				   socket of same protocol
 * 				 - remove all module support, since netlink is
 * 				   mandatory if CONFIG_NET=y these days
L
Linus Torvalds 已提交
23 24 25 26
 */

#include <linux/module.h>

27
#include <linux/capability.h>
L
Linus Torvalds 已提交
28 29 30 31 32 33 34 35 36 37 38 39 40 41 42
#include <linux/kernel.h>
#include <linux/init.h>
#include <linux/signal.h>
#include <linux/sched.h>
#include <linux/errno.h>
#include <linux/string.h>
#include <linux/stat.h>
#include <linux/socket.h>
#include <linux/un.h>
#include <linux/fcntl.h>
#include <linux/termios.h>
#include <linux/sockios.h>
#include <linux/net.h>
#include <linux/fs.h>
#include <linux/slab.h>
43
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
44 45 46 47 48 49 50 51 52 53 54 55 56
#include <linux/skbuff.h>
#include <linux/netdevice.h>
#include <linux/rtnetlink.h>
#include <linux/proc_fs.h>
#include <linux/seq_file.h>
#include <linux/notifier.h>
#include <linux/security.h>
#include <linux/jhash.h>
#include <linux/jiffies.h>
#include <linux/random.h>
#include <linux/bitops.h>
#include <linux/mm.h>
#include <linux/types.h>
A
Andrew Morton 已提交
57
#include <linux/audit.h>
58
#include <linux/mutex.h>
59
#include <linux/vmalloc.h>
60
#include <linux/if_arp.h>
61
#include <linux/rhashtable.h>
62
#include <asm/cacheflush.h>
63
#include <linux/hash.h>
64
#include <linux/genetlink.h>
A
Andrew Morton 已提交
65

66
#include <net/net_namespace.h>
L
Linus Torvalds 已提交
67 68
#include <net/sock.h>
#include <net/scm.h>
69
#include <net/netlink.h>
L
Linus Torvalds 已提交
70

71
#include "af_netlink.h"
L
Linus Torvalds 已提交
72

73 74 75
struct listeners {
	struct rcu_head		rcu;
	unsigned long		masks[0];
76 77
};

78
/* state bits */
79
#define NETLINK_S_CONGESTED		0x0
80

81
static inline int netlink_is_kernel(struct sock *sk)
82
{
83
	return nlk_sk(sk)->flags & NETLINK_F_KERNEL_SOCKET;
84 85
}

86
struct netlink_table *nl_table __read_mostly;
87
EXPORT_SYMBOL_GPL(nl_table);
L
Linus Torvalds 已提交
88 89 90

static DECLARE_WAIT_QUEUE_HEAD(nl_table_wait);

91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128
static struct lock_class_key nlk_cb_mutex_keys[MAX_LINKS];

static const char *const nlk_cb_mutex_key_strings[MAX_LINKS + 1] = {
	"nlk_cb_mutex-ROUTE",
	"nlk_cb_mutex-1",
	"nlk_cb_mutex-USERSOCK",
	"nlk_cb_mutex-FIREWALL",
	"nlk_cb_mutex-SOCK_DIAG",
	"nlk_cb_mutex-NFLOG",
	"nlk_cb_mutex-XFRM",
	"nlk_cb_mutex-SELINUX",
	"nlk_cb_mutex-ISCSI",
	"nlk_cb_mutex-AUDIT",
	"nlk_cb_mutex-FIB_LOOKUP",
	"nlk_cb_mutex-CONNECTOR",
	"nlk_cb_mutex-NETFILTER",
	"nlk_cb_mutex-IP6_FW",
	"nlk_cb_mutex-DNRTMSG",
	"nlk_cb_mutex-KOBJECT_UEVENT",
	"nlk_cb_mutex-GENERIC",
	"nlk_cb_mutex-17",
	"nlk_cb_mutex-SCSITRANSPORT",
	"nlk_cb_mutex-ECRYPTFS",
	"nlk_cb_mutex-RDMA",
	"nlk_cb_mutex-CRYPTO",
	"nlk_cb_mutex-SMC",
	"nlk_cb_mutex-23",
	"nlk_cb_mutex-24",
	"nlk_cb_mutex-25",
	"nlk_cb_mutex-26",
	"nlk_cb_mutex-27",
	"nlk_cb_mutex-28",
	"nlk_cb_mutex-29",
	"nlk_cb_mutex-30",
	"nlk_cb_mutex-31",
	"nlk_cb_mutex-MAX_LINKS"
};

L
Linus Torvalds 已提交
129
static int netlink_dump(struct sock *sk);
130
static void netlink_skb_destructor(struct sk_buff *skb);
L
Linus Torvalds 已提交
131

132
/* nl_table locking explained:
133
 * Lookup and traversal are protected with an RCU read-side lock. Insertion
Y
Ying Xue 已提交
134
 * and removal are protected with per bucket lock while using RCU list
135 136 137 138
 * modification primitives and may run in parallel to RCU protected lookups.
 * Destruction of the Netlink socket may only occur *after* nl_table_lock has
 * been acquired * either during or after the socket has been removed from
 * the list and after an RCU grace period.
139
 */
140 141
DEFINE_RWLOCK(nl_table_lock);
EXPORT_SYMBOL_GPL(nl_table_lock);
L
Linus Torvalds 已提交
142 143
static atomic_t nl_table_users = ATOMIC_INIT(0);

144 145
#define nl_deref_protected(X) rcu_dereference_protected(X, lockdep_is_held(&nl_table_lock));

W
WANG Cong 已提交
146
static BLOCKING_NOTIFIER_HEAD(netlink_chain);
L
Linus Torvalds 已提交
147

148 149 150
static DEFINE_SPINLOCK(netlink_tap_lock);
static struct list_head netlink_tap_all __read_mostly;

151 152
static const struct rhashtable_params netlink_rhashtable_params;

153
static inline u32 netlink_group_mask(u32 group)
154 155 156 157
{
	return group ? 1 << (group - 1) : 0;
}

158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175
static struct sk_buff *netlink_to_full_skb(const struct sk_buff *skb,
					   gfp_t gfp_mask)
{
	unsigned int len = skb_end_offset(skb);
	struct sk_buff *new;

	new = alloc_skb(len, gfp_mask);
	if (new == NULL)
		return NULL;

	NETLINK_CB(new).portid = NETLINK_CB(skb).portid;
	NETLINK_CB(new).dst_group = NETLINK_CB(skb).dst_group;
	NETLINK_CB(new).creds = NETLINK_CB(skb).creds;

	memcpy(skb_put(new, len), skb->data, len);
	return new;
}

176 177 178 179 180 181 182 183 184
int netlink_add_tap(struct netlink_tap *nt)
{
	if (unlikely(nt->dev->type != ARPHRD_NETLINK))
		return -EINVAL;

	spin_lock(&netlink_tap_lock);
	list_add_rcu(&nt->list, &netlink_tap_all);
	spin_unlock(&netlink_tap_lock);

185
	__module_get(nt->module);
186 187 188 189 190

	return 0;
}
EXPORT_SYMBOL_GPL(netlink_add_tap);

191
static int __netlink_remove_tap(struct netlink_tap *nt)
192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209
{
	bool found = false;
	struct netlink_tap *tmp;

	spin_lock(&netlink_tap_lock);

	list_for_each_entry(tmp, &netlink_tap_all, list) {
		if (nt == tmp) {
			list_del_rcu(&nt->list);
			found = true;
			goto out;
		}
	}

	pr_warn("__netlink_remove_tap: %p not found\n", nt);
out:
	spin_unlock(&netlink_tap_lock);

210
	if (found)
211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226
		module_put(nt->module);

	return found ? 0 : -ENODEV;
}

int netlink_remove_tap(struct netlink_tap *nt)
{
	int ret;

	ret = __netlink_remove_tap(nt);
	synchronize_net();

	return ret;
}
EXPORT_SYMBOL_GPL(netlink_remove_tap);

227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242
static bool netlink_filter_tap(const struct sk_buff *skb)
{
	struct sock *sk = skb->sk;

	/* We take the more conservative approach and
	 * whitelist socket protocols that may pass.
	 */
	switch (sk->sk_protocol) {
	case NETLINK_ROUTE:
	case NETLINK_USERSOCK:
	case NETLINK_SOCK_DIAG:
	case NETLINK_NFLOG:
	case NETLINK_XFRM:
	case NETLINK_FIB_LOOKUP:
	case NETLINK_NETFILTER:
	case NETLINK_GENERIC:
V
Varka Bhadram 已提交
243
		return true;
244 245
	}

V
Varka Bhadram 已提交
246
	return false;
247 248
}

249 250 251 252
static int __netlink_deliver_tap_skb(struct sk_buff *skb,
				     struct net_device *dev)
{
	struct sk_buff *nskb;
253
	struct sock *sk = skb->sk;
254 255 256
	int ret = -ENOMEM;

	dev_hold(dev);
257

258
	if (is_vmalloc_addr(skb->head))
259 260 261
		nskb = netlink_to_full_skb(skb, GFP_ATOMIC);
	else
		nskb = skb_clone(skb, GFP_ATOMIC);
262 263
	if (nskb) {
		nskb->dev = dev;
264
		nskb->protocol = htons((u16) sk->sk_protocol);
265 266
		nskb->pkt_type = netlink_is_kernel(sk) ?
				 PACKET_KERNEL : PACKET_USER;
267
		skb_reset_network_header(nskb);
268 269 270 271 272 273 274 275 276 277 278 279 280 281
		ret = dev_queue_xmit(nskb);
		if (unlikely(ret > 0))
			ret = net_xmit_errno(ret);
	}

	dev_put(dev);
	return ret;
}

static void __netlink_deliver_tap(struct sk_buff *skb)
{
	int ret;
	struct netlink_tap *tmp;

282 283 284
	if (!netlink_filter_tap(skb))
		return;

285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301
	list_for_each_entry_rcu(tmp, &netlink_tap_all, list) {
		ret = __netlink_deliver_tap_skb(skb, tmp->dev);
		if (unlikely(ret))
			break;
	}
}

static void netlink_deliver_tap(struct sk_buff *skb)
{
	rcu_read_lock();

	if (unlikely(!list_empty(&netlink_tap_all)))
		__netlink_deliver_tap(skb);

	rcu_read_unlock();
}

302 303 304 305 306 307 308
static void netlink_deliver_tap_kernel(struct sock *dst, struct sock *src,
				       struct sk_buff *skb)
{
	if (!(netlink_is_kernel(dst) && netlink_is_kernel(src)))
		netlink_deliver_tap(skb);
}

309 310 311 312
static void netlink_overrun(struct sock *sk)
{
	struct netlink_sock *nlk = nlk_sk(sk);

313 314 315
	if (!(nlk->flags & NETLINK_F_RECV_NO_ENOBUFS)) {
		if (!test_and_set_bit(NETLINK_S_CONGESTED,
				      &nlk_sk(sk)->state)) {
316 317 318 319 320 321 322 323 324 325 326 327
			sk->sk_err = ENOBUFS;
			sk->sk_error_report(sk);
		}
	}
	atomic_inc(&sk->sk_drops);
}

static void netlink_rcv_wake(struct sock *sk)
{
	struct netlink_sock *nlk = nlk_sk(sk);

	if (skb_queue_empty(&sk->sk_receive_queue))
328 329
		clear_bit(NETLINK_S_CONGESTED, &nlk->state);
	if (!test_bit(NETLINK_S_CONGESTED, &nlk->state))
330 331 332
		wake_up_interruptible(&nlk->wait);
}

333 334
static void netlink_skb_destructor(struct sk_buff *skb)
{
335
	if (is_vmalloc_addr(skb->head)) {
336 337 338 339
		if (!skb->cloned ||
		    !atomic_dec_return(&(skb_shinfo(skb)->dataref)))
			vfree(skb->head);

340 341
		skb->head = NULL;
	}
342 343
	if (skb->sk != NULL)
		sock_rfree(skb);
344 345 346 347 348 349 350 351 352 353 354
}

static void netlink_skb_set_owner_r(struct sk_buff *skb, struct sock *sk)
{
	WARN_ON(skb->sk != NULL);
	skb->sk = sk;
	skb->destructor = netlink_skb_destructor;
	atomic_add(skb->truesize, &sk->sk_rmem_alloc);
	sk_mem_charge(sk, skb->truesize);
}

355
static void netlink_sock_destruct(struct sock *sk)
L
Linus Torvalds 已提交
356
{
357 358
	struct netlink_sock *nlk = nlk_sk(sk);

359
	if (nlk->cb_running) {
360 361
		if (nlk->cb.done)
			nlk->cb.done(&nlk->cb);
362 363
		module_put(nlk->cb.module);
		kfree_skb(nlk->cb.skb);
364 365
	}

L
Linus Torvalds 已提交
366 367 368
	skb_queue_purge(&sk->sk_receive_queue);

	if (!sock_flag(sk, SOCK_DEAD)) {
369
		printk(KERN_ERR "Freeing alive netlink socket %p\n", sk);
L
Linus Torvalds 已提交
370 371
		return;
	}
372 373 374 375

	WARN_ON(atomic_read(&sk->sk_rmem_alloc));
	WARN_ON(atomic_read(&sk->sk_wmem_alloc));
	WARN_ON(nlk_sk(sk)->groups);
L
Linus Torvalds 已提交
376 377
}

378 379 380 381 382
static void netlink_sock_destruct_work(struct work_struct *work)
{
	struct netlink_sock *nlk = container_of(work, struct netlink_sock,
						work);

383
	sk_free(&nlk->sk);
384 385
}

386 387
/* This lock without WQ_FLAG_EXCLUSIVE is good on UP and it is _very_ bad on
 * SMP. Look, when several writers sleep and reader wakes them up, all but one
L
Linus Torvalds 已提交
388 389 390 391
 * immediately hit write lock and grab all the cpus. Exclusive sleep solves
 * this, _but_ remember, it adds useless work on UP machines.
 */

392
void netlink_table_grab(void)
393
	__acquires(nl_table_lock)
L
Linus Torvalds 已提交
394
{
395 396
	might_sleep();

397
	write_lock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
398 399 400 401 402

	if (atomic_read(&nl_table_users)) {
		DECLARE_WAITQUEUE(wait, current);

		add_wait_queue_exclusive(&nl_table_wait, &wait);
403
		for (;;) {
L
Linus Torvalds 已提交
404 405 406
			set_current_state(TASK_UNINTERRUPTIBLE);
			if (atomic_read(&nl_table_users) == 0)
				break;
407
			write_unlock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
408
			schedule();
409
			write_lock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
410 411 412 413 414 415 416
		}

		__set_current_state(TASK_RUNNING);
		remove_wait_queue(&nl_table_wait, &wait);
	}
}

417
void netlink_table_ungrab(void)
418
	__releases(nl_table_lock)
L
Linus Torvalds 已提交
419
{
420
	write_unlock_irq(&nl_table_lock);
L
Linus Torvalds 已提交
421 422 423
	wake_up(&nl_table_wait);
}

424
static inline void
L
Linus Torvalds 已提交
425 426 427 428 429 430 431 432 433
netlink_lock_table(void)
{
	/* read_lock() synchronizes us to netlink_table_grab */

	read_lock(&nl_table_lock);
	atomic_inc(&nl_table_users);
	read_unlock(&nl_table_lock);
}

434
static inline void
L
Linus Torvalds 已提交
435 436 437 438 439 440
netlink_unlock_table(void)
{
	if (atomic_dec_and_test(&nl_table_users))
		wake_up(&nl_table_wait);
}

441
struct netlink_compare_arg
L
Linus Torvalds 已提交
442
{
443
	possible_net_t pnet;
444 445
	u32 portid;
};
L
Linus Torvalds 已提交
446

447 448 449
/* Doing sizeof directly may yield 4 extra bytes on 64-bit. */
#define netlink_compare_arg_len \
	(offsetof(struct netlink_compare_arg, portid) + sizeof(u32))
450 451 452

static inline int netlink_compare(struct rhashtable_compare_arg *arg,
				  const void *ptr)
L
Linus Torvalds 已提交
453
{
454 455
	const struct netlink_compare_arg *x = arg->key;
	const struct netlink_sock *nlk = ptr;
L
Linus Torvalds 已提交
456

457
	return nlk->portid != x->portid ||
458 459 460 461 462 463 464 465 466
	       !net_eq(sock_net(&nlk->sk), read_pnet(&x->pnet));
}

static void netlink_compare_arg_init(struct netlink_compare_arg *arg,
				     struct net *net, u32 portid)
{
	memset(arg, 0, sizeof(*arg));
	write_pnet(&arg->pnet, net);
	arg->portid = portid;
L
Linus Torvalds 已提交
467 468
}

469 470
static struct sock *__netlink_lookup(struct netlink_table *table, u32 portid,
				     struct net *net)
L
Linus Torvalds 已提交
471
{
472
	struct netlink_compare_arg arg;
L
Linus Torvalds 已提交
473

474 475 476
	netlink_compare_arg_init(&arg, net, portid);
	return rhashtable_lookup_fast(&table->hash, &arg,
				      netlink_rhashtable_params);
L
Linus Torvalds 已提交
477 478
}

479
static int __netlink_insert(struct netlink_table *table, struct sock *sk)
Y
Ying Xue 已提交
480
{
481
	struct netlink_compare_arg arg;
Y
Ying Xue 已提交
482

483
	netlink_compare_arg_init(&arg, sock_net(sk), nlk_sk(sk)->portid);
484 485 486
	return rhashtable_lookup_insert_key(&table->hash, &arg,
					    &nlk_sk(sk)->node,
					    netlink_rhashtable_params);
Y
Ying Xue 已提交
487 488
}

489
static struct sock *netlink_lookup(struct net *net, int protocol, u32 portid)
L
Linus Torvalds 已提交
490
{
491 492
	struct netlink_table *table = &nl_table[protocol];
	struct sock *sk;
L
Linus Torvalds 已提交
493

494 495 496 497 498
	rcu_read_lock();
	sk = __netlink_lookup(table, portid, net);
	if (sk)
		sock_hold(sk);
	rcu_read_unlock();
L
Linus Torvalds 已提交
499

500
	return sk;
L
Linus Torvalds 已提交
501 502
}

503
static const struct proto_ops netlink_ops;
L
Linus Torvalds 已提交
504

505 506 507 508 509 510
static void
netlink_update_listeners(struct sock *sk)
{
	struct netlink_table *tbl = &nl_table[sk->sk_protocol];
	unsigned long mask;
	unsigned int i;
511 512 513 514 515
	struct listeners *listeners;

	listeners = nl_deref_protected(tbl->listeners);
	if (!listeners)
		return;
516

517
	for (i = 0; i < NLGRPLONGS(tbl->groups); i++) {
518
		mask = 0;
519
		sk_for_each_bound(sk, &tbl->mc_list) {
520 521 522
			if (i < NLGRPLONGS(nlk_sk(sk)->ngroups))
				mask |= nlk_sk(sk)->groups[i];
		}
523
		listeners->masks[i] = mask;
524 525 526 527 528
	}
	/* this function is only called with the netlink table "grabbed", which
	 * makes sure updates are visible before bind or setsockopt return. */
}

529
static int netlink_insert(struct sock *sk, u32 portid)
L
Linus Torvalds 已提交
530
{
531
	struct netlink_table *table = &nl_table[sk->sk_protocol];
532
	int err;
L
Linus Torvalds 已提交
533

Y
Ying Xue 已提交
534
	lock_sock(sk);
L
Linus Torvalds 已提交
535

536 537
	err = nlk_sk(sk)->portid == portid ? 0 : -EBUSY;
	if (nlk_sk(sk)->bound)
L
Linus Torvalds 已提交
538 539 540
		goto err;

	err = -ENOMEM;
541 542
	if (BITS_PER_LONG > 32 &&
	    unlikely(atomic_read(&table->hash.nelems) >= UINT_MAX))
L
Linus Torvalds 已提交
543 544
		goto err;

545
	nlk_sk(sk)->portid = portid;
546
	sock_hold(sk);
547

548 549
	err = __netlink_insert(table, sk);
	if (err) {
550 551 552 553 554
		/* In case the hashtable backend returns with -EBUSY
		 * from here, it must not escape to the caller.
		 */
		if (unlikely(err == -EBUSY))
			err = -EOVERFLOW;
555 556
		if (err == -EEXIST)
			err = -EADDRINUSE;
Y
Ying Xue 已提交
557
		sock_put(sk);
558
		goto err;
559 560
	}

561 562 563
	/* We need to ensure that the socket is hashed and visible. */
	smp_wmb();
	nlk_sk(sk)->bound = portid;
564

L
Linus Torvalds 已提交
565
err:
Y
Ying Xue 已提交
566
	release_sock(sk);
L
Linus Torvalds 已提交
567 568 569 570 571
	return err;
}

static void netlink_remove(struct sock *sk)
{
572 573 574
	struct netlink_table *table;

	table = &nl_table[sk->sk_protocol];
575 576
	if (!rhashtable_remove_fast(&table->hash, &nlk_sk(sk)->node,
				    netlink_rhashtable_params)) {
577 578 579 580
		WARN_ON(atomic_read(&sk->sk_refcnt) == 1);
		__sock_put(sk);
	}

L
Linus Torvalds 已提交
581
	netlink_table_grab();
582
	if (nlk_sk(sk)->subscriptions) {
L
Linus Torvalds 已提交
583
		__sk_del_bind_node(sk);
584 585
		netlink_update_listeners(sk);
	}
586 587
	if (sk->sk_protocol == NETLINK_GENERIC)
		atomic_inc(&genl_sk_destructing_cnt);
L
Linus Torvalds 已提交
588 589 590 591 592 593 594 595 596
	netlink_table_ungrab();
}

static struct proto netlink_proto = {
	.name	  = "NETLINK",
	.owner	  = THIS_MODULE,
	.obj_size = sizeof(struct netlink_sock),
};

597
static int __netlink_create(struct net *net, struct socket *sock,
598 599
			    struct mutex *cb_mutex, int protocol,
			    int kern)
L
Linus Torvalds 已提交
600 601 602
{
	struct sock *sk;
	struct netlink_sock *nlk;
603 604 605

	sock->ops = &netlink_ops;

606
	sk = sk_alloc(net, PF_NETLINK, GFP_KERNEL, &netlink_proto, kern);
607 608 609 610 611 612
	if (!sk)
		return -ENOMEM;

	sock_init_data(sock, sk);

	nlk = nlk_sk(sk);
E
Eric Dumazet 已提交
613
	if (cb_mutex) {
614
		nlk->cb_mutex = cb_mutex;
E
Eric Dumazet 已提交
615
	} else {
616 617
		nlk->cb_mutex = &nlk->cb_def_mutex;
		mutex_init(nlk->cb_mutex);
618 619 620
		lockdep_set_class_and_name(nlk->cb_mutex,
					   nlk_cb_mutex_keys + protocol,
					   nlk_cb_mutex_key_strings[protocol]);
621
	}
622 623 624 625 626 627 628
	init_waitqueue_head(&nlk->wait);

	sk->sk_destruct = netlink_sock_destruct;
	sk->sk_protocol = protocol;
	return 0;
}

629 630
static int netlink_create(struct net *net, struct socket *sock, int protocol,
			  int kern)
631 632
{
	struct module *module = NULL;
633
	struct mutex *cb_mutex;
634
	struct netlink_sock *nlk;
635 636
	int (*bind)(struct net *net, int group);
	void (*unbind)(struct net *net, int group);
637
	int err = 0;
L
Linus Torvalds 已提交
638 639 640 641 642 643

	sock->state = SS_UNCONNECTED;

	if (sock->type != SOCK_RAW && sock->type != SOCK_DGRAM)
		return -ESOCKTNOSUPPORT;

644
	if (protocol < 0 || protocol >= MAX_LINKS)
L
Linus Torvalds 已提交
645 646
		return -EPROTONOSUPPORT;

647
	netlink_lock_table();
648
#ifdef CONFIG_MODULES
649
	if (!nl_table[protocol].registered) {
650
		netlink_unlock_table();
651
		request_module("net-pf-%d-proto-%d", PF_NETLINK, protocol);
652
		netlink_lock_table();
653
	}
654 655 656 657
#endif
	if (nl_table[protocol].registered &&
	    try_module_get(nl_table[protocol].module))
		module = nl_table[protocol].module;
658 659
	else
		err = -EPROTONOSUPPORT;
660
	cb_mutex = nl_table[protocol].cb_mutex;
661
	bind = nl_table[protocol].bind;
662
	unbind = nl_table[protocol].unbind;
663
	netlink_unlock_table();
664

665 666 667
	if (err < 0)
		goto out;

668
	err = __netlink_create(net, sock, cb_mutex, protocol, kern);
669
	if (err < 0)
670 671
		goto out_module;

672
	local_bh_disable();
673
	sock_prot_inuse_add(net, &netlink_proto, 1);
674 675
	local_bh_enable();

676 677
	nlk = nlk_sk(sock->sk);
	nlk->module = module;
678
	nlk->netlink_bind = bind;
679
	nlk->netlink_unbind = unbind;
680 681
out:
	return err;
L
Linus Torvalds 已提交
682

683 684 685
out_module:
	module_put(module);
	goto out;
L
Linus Torvalds 已提交
686 687
}

688 689 690
static void deferred_put_nlk_sk(struct rcu_head *head)
{
	struct netlink_sock *nlk = container_of(head, struct netlink_sock, rcu);
691 692 693 694 695 696 697 698 699 700
	struct sock *sk = &nlk->sk;

	if (!atomic_dec_and_test(&sk->sk_refcnt))
		return;

	if (nlk->cb_running && nlk->cb.done) {
		INIT_WORK(&nlk->work, netlink_sock_destruct_work);
		schedule_work(&nlk->work);
		return;
	}
701

702
	sk_free(sk);
703 704
}

L
Linus Torvalds 已提交
705 706 707 708 709 710 711 712 713
static int netlink_release(struct socket *sock)
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk;

	if (!sk)
		return 0;

	netlink_remove(sk);
714
	sock_orphan(sk);
L
Linus Torvalds 已提交
715 716
	nlk = nlk_sk(sk);

717 718 719 720
	/*
	 * OK. Socket is unlinked, any packets that arrive now
	 * will be purged.
	 */
L
Linus Torvalds 已提交
721

722 723 724 725 726 727 728 729 730 731 732 733 734 735
	/* must not acquire netlink_table_lock in any way again before unbind
	 * and notifying genetlink is done as otherwise it might deadlock
	 */
	if (nlk->netlink_unbind) {
		int i;

		for (i = 0; i < nlk->ngroups; i++)
			if (test_bit(i, nlk->groups))
				nlk->netlink_unbind(sock_net(sk), i + 1);
	}
	if (sk->sk_protocol == NETLINK_GENERIC &&
	    atomic_dec_return(&genl_sk_destructing_cnt) == 0)
		wake_up(&genl_sk_destructing_waitq);

L
Linus Torvalds 已提交
736 737 738 739 740
	sock->sk = NULL;
	wake_up_interruptible_all(&nlk->wait);

	skb_queue_purge(&sk->sk_write_queue);

741
	if (nlk->portid && nlk->bound) {
L
Linus Torvalds 已提交
742
		struct netlink_notify n = {
743
						.net = sock_net(sk),
L
Linus Torvalds 已提交
744
						.protocol = sk->sk_protocol,
745
						.portid = nlk->portid,
L
Linus Torvalds 已提交
746
					  };
W
WANG Cong 已提交
747
		blocking_notifier_call_chain(&netlink_chain,
748
				NETLINK_URELEASE, &n);
749
	}
750

751
	module_put(nlk->module);
752

753
	if (netlink_is_kernel(sk)) {
754
		netlink_table_grab();
755 756
		BUG_ON(nl_table[sk->sk_protocol].registered == 0);
		if (--nl_table[sk->sk_protocol].registered == 0) {
757 758 759 760 761
			struct listeners *old;

			old = nl_deref_protected(nl_table[sk->sk_protocol].listeners);
			RCU_INIT_POINTER(nl_table[sk->sk_protocol].listeners, NULL);
			kfree_rcu(old, rcu);
762
			nl_table[sk->sk_protocol].module = NULL;
763
			nl_table[sk->sk_protocol].bind = NULL;
764
			nl_table[sk->sk_protocol].unbind = NULL;
765
			nl_table[sk->sk_protocol].flags = 0;
766 767
			nl_table[sk->sk_protocol].registered = 0;
		}
768
		netlink_table_ungrab();
E
Eric Dumazet 已提交
769
	}
770

771 772 773
	kfree(nlk->groups);
	nlk->groups = NULL;

774
	local_bh_disable();
775
	sock_prot_inuse_add(sock_net(sk), &netlink_proto, -1);
776
	local_bh_enable();
777
	call_rcu(&nlk->rcu, deferred_put_nlk_sk);
L
Linus Torvalds 已提交
778 779 780 781 782 783
	return 0;
}

static int netlink_autobind(struct socket *sock)
{
	struct sock *sk = sock->sk;
784
	struct net *net = sock_net(sk);
785
	struct netlink_table *table = &nl_table[sk->sk_protocol];
786
	s32 portid = task_tgid_vnr(current);
L
Linus Torvalds 已提交
787
	int err;
H
Herbert Xu 已提交
788 789
	s32 rover = -4096;
	bool ok;
L
Linus Torvalds 已提交
790 791 792

retry:
	cond_resched();
793
	rcu_read_lock();
H
Herbert Xu 已提交
794 795 796
	ok = !__netlink_lookup(table, portid, net);
	rcu_read_unlock();
	if (!ok) {
797
		/* Bind collision, search negative portid values. */
H
Herbert Xu 已提交
798 799 800 801
		if (rover == -4096)
			/* rover will be in range [S32_MIN, -4097] */
			rover = S32_MIN + prandom_u32_max(-4096 - S32_MIN);
		else if (rover >= -4096)
802
			rover = -4097;
H
Herbert Xu 已提交
803
		portid = rover--;
804
		goto retry;
L
Linus Torvalds 已提交
805 806
	}

807
	err = netlink_insert(sk, portid);
L
Linus Torvalds 已提交
808 809
	if (err == -EADDRINUSE)
		goto retry;
810 811 812 813 814 815

	/* If 2 threads race to autobind, that is fine.  */
	if (err == -EBUSY)
		err = 0;

	return err;
L
Linus Torvalds 已提交
816 817
}

818 819 820 821 822 823 824 825 826 827 828 829 830
/**
 * __netlink_ns_capable - General netlink message capability test
 * @nsp: NETLINK_CB of the socket buffer holding a netlink command from userspace.
 * @user_ns: The user namespace of the capability to use
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap in the user namespace @user_ns.
 */
bool __netlink_ns_capable(const struct netlink_skb_parms *nsp,
			struct user_namespace *user_ns, int cap)
{
831 832 833
	return ((nsp->flags & NETLINK_SKB_DST) ||
		file_ns_capable(nsp->sk->sk_socket->file, user_ns, cap)) &&
		ns_capable(user_ns, cap);
834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884
}
EXPORT_SYMBOL(__netlink_ns_capable);

/**
 * netlink_ns_capable - General netlink message capability test
 * @skb: socket buffer holding a netlink command from userspace
 * @user_ns: The user namespace of the capability to use
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap in the user namespace @user_ns.
 */
bool netlink_ns_capable(const struct sk_buff *skb,
			struct user_namespace *user_ns, int cap)
{
	return __netlink_ns_capable(&NETLINK_CB(skb), user_ns, cap);
}
EXPORT_SYMBOL(netlink_ns_capable);

/**
 * netlink_capable - Netlink global message capability test
 * @skb: socket buffer holding a netlink command from userspace
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap in all user namespaces.
 */
bool netlink_capable(const struct sk_buff *skb, int cap)
{
	return netlink_ns_capable(skb, &init_user_ns, cap);
}
EXPORT_SYMBOL(netlink_capable);

/**
 * netlink_net_capable - Netlink network namespace message capability test
 * @skb: socket buffer holding a netlink command from userspace
 * @cap: The capability to use
 *
 * Test to see if the opener of the socket we received the message
 * from had when the netlink socket was created and the sender of the
 * message has has the capability @cap over the network namespace of
 * the socket we received the message from.
 */
bool netlink_net_capable(const struct sk_buff *skb, int cap)
{
	return netlink_ns_capable(skb, sock_net(skb->sk)->user_ns, cap);
}
EXPORT_SYMBOL(netlink_net_capable);

885
static inline int netlink_allowed(const struct socket *sock, unsigned int flag)
886
{
887
	return (nl_table[sock->sk->sk_protocol].flags & flag) ||
888
		ns_capable(sock_net(sock->sk)->user_ns, CAP_NET_ADMIN);
889
}
L
Linus Torvalds 已提交
890

891 892 893 894 895 896 897 898 899 900 901 902
static void
netlink_update_subscriptions(struct sock *sk, unsigned int subscriptions)
{
	struct netlink_sock *nlk = nlk_sk(sk);

	if (nlk->subscriptions && !subscriptions)
		__sk_del_bind_node(sk);
	else if (!nlk->subscriptions && subscriptions)
		sk_add_bind_node(sk, &nl_table[sk->sk_protocol].mc_list);
	nlk->subscriptions = subscriptions;
}

903
static int netlink_realloc_groups(struct sock *sk)
904 905 906
{
	struct netlink_sock *nlk = nlk_sk(sk);
	unsigned int groups;
907
	unsigned long *new_groups;
908 909
	int err = 0;

910 911
	netlink_table_grab();

912
	groups = nl_table[sk->sk_protocol].groups;
913
	if (!nl_table[sk->sk_protocol].registered) {
914
		err = -ENOENT;
915 916
		goto out_unlock;
	}
917

918 919
	if (nlk->ngroups >= groups)
		goto out_unlock;
920

921 922 923 924 925
	new_groups = krealloc(nlk->groups, NLGRPSZ(groups), GFP_ATOMIC);
	if (new_groups == NULL) {
		err = -ENOMEM;
		goto out_unlock;
	}
926
	memset((char *)new_groups + NLGRPSZ(nlk->ngroups), 0,
927 928 929
	       NLGRPSZ(groups) - NLGRPSZ(nlk->ngroups));

	nlk->groups = new_groups;
930
	nlk->ngroups = groups;
931 932 933
 out_unlock:
	netlink_table_ungrab();
	return err;
934 935
}

936
static void netlink_undo_bind(int group, long unsigned int groups,
937
			      struct sock *sk)
938
{
939
	struct netlink_sock *nlk = nlk_sk(sk);
940 941 942 943 944 945
	int undo;

	if (!nlk->netlink_unbind)
		return;

	for (undo = 0; undo < group; undo++)
946
		if (test_bit(undo, &groups))
947
			nlk->netlink_unbind(sock_net(sk), undo + 1);
948 949
}

950 951
static int netlink_bind(struct socket *sock, struct sockaddr *addr,
			int addr_len)
L
Linus Torvalds 已提交
952 953
{
	struct sock *sk = sock->sk;
954
	struct net *net = sock_net(sk);
L
Linus Torvalds 已提交
955 956 957
	struct netlink_sock *nlk = nlk_sk(sk);
	struct sockaddr_nl *nladdr = (struct sockaddr_nl *)addr;
	int err;
958
	long unsigned int groups = nladdr->nl_groups;
959
	bool bound;
960

961 962 963
	if (addr_len < sizeof(struct sockaddr_nl))
		return -EINVAL;

L
Linus Torvalds 已提交
964 965 966 967
	if (nladdr->nl_family != AF_NETLINK)
		return -EINVAL;

	/* Only superuser is allowed to listen multicasts */
968
	if (groups) {
969
		if (!netlink_allowed(sock, NL_CFG_F_NONROOT_RECV))
970
			return -EPERM;
971 972 973
		err = netlink_realloc_groups(sk);
		if (err)
			return err;
974
	}
L
Linus Torvalds 已提交
975

976 977 978 979 980
	bound = nlk->bound;
	if (bound) {
		/* Ensure nlk->portid is up-to-date. */
		smp_rmb();

981
		if (nladdr->nl_pid != nlk->portid)
L
Linus Torvalds 已提交
982
			return -EINVAL;
983
	}
984 985 986 987 988 989 990

	if (nlk->netlink_bind && groups) {
		int group;

		for (group = 0; group < nlk->ngroups; group++) {
			if (!test_bit(group, &groups))
				continue;
991
			err = nlk->netlink_bind(net, group + 1);
992 993
			if (!err)
				continue;
994
			netlink_undo_bind(group, groups, sk);
995 996 997 998
			return err;
		}
	}

999 1000 1001 1002
	/* No need for barriers here as we return to user-space without
	 * using any of the bound attributes.
	 */
	if (!bound) {
L
Linus Torvalds 已提交
1003
		err = nladdr->nl_pid ?
1004
			netlink_insert(sk, nladdr->nl_pid) :
L
Linus Torvalds 已提交
1005
			netlink_autobind(sock);
1006
		if (err) {
1007
			netlink_undo_bind(nlk->ngroups, groups, sk);
L
Linus Torvalds 已提交
1008
			return err;
1009
		}
L
Linus Torvalds 已提交
1010 1011
	}

1012
	if (!groups && (nlk->groups == NULL || !(u32)nlk->groups[0]))
L
Linus Torvalds 已提交
1013 1014 1015
		return 0;

	netlink_table_grab();
1016
	netlink_update_subscriptions(sk, nlk->subscriptions +
1017
					 hweight32(groups) -
1018
					 hweight32(nlk->groups[0]));
1019
	nlk->groups[0] = (nlk->groups[0] & ~0xffffffffUL) | groups;
1020
	netlink_update_listeners(sk);
L
Linus Torvalds 已提交
1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031
	netlink_table_ungrab();

	return 0;
}

static int netlink_connect(struct socket *sock, struct sockaddr *addr,
			   int alen, int flags)
{
	int err = 0;
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1032
	struct sockaddr_nl *nladdr = (struct sockaddr_nl *)addr;
L
Linus Torvalds 已提交
1033

1034 1035 1036
	if (alen < sizeof(addr->sa_family))
		return -EINVAL;

L
Linus Torvalds 已提交
1037 1038
	if (addr->sa_family == AF_UNSPEC) {
		sk->sk_state	= NETLINK_UNCONNECTED;
1039
		nlk->dst_portid	= 0;
1040
		nlk->dst_group  = 0;
L
Linus Torvalds 已提交
1041 1042 1043 1044 1045
		return 0;
	}
	if (addr->sa_family != AF_NETLINK)
		return -EINVAL;

1046
	if ((nladdr->nl_groups || nladdr->nl_pid) &&
1047
	    !netlink_allowed(sock, NL_CFG_F_NONROOT_SEND))
L
Linus Torvalds 已提交
1048 1049
		return -EPERM;

1050 1051 1052 1053
	/* No need for barriers here as we return to user-space without
	 * using any of the bound attributes.
	 */
	if (!nlk->bound)
L
Linus Torvalds 已提交
1054 1055 1056 1057
		err = netlink_autobind(sock);

	if (err == 0) {
		sk->sk_state	= NETLINK_CONNECTED;
1058
		nlk->dst_portid = nladdr->nl_pid;
1059
		nlk->dst_group  = ffs(nladdr->nl_groups);
L
Linus Torvalds 已提交
1060 1061 1062 1063 1064
	}

	return err;
}

1065 1066
static int netlink_getname(struct socket *sock, struct sockaddr *addr,
			   int *addr_len, int peer)
L
Linus Torvalds 已提交
1067 1068 1069
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1070
	DECLARE_SOCKADDR(struct sockaddr_nl *, nladdr, addr);
1071

L
Linus Torvalds 已提交
1072 1073 1074 1075 1076
	nladdr->nl_family = AF_NETLINK;
	nladdr->nl_pad = 0;
	*addr_len = sizeof(*nladdr);

	if (peer) {
1077
		nladdr->nl_pid = nlk->dst_portid;
1078
		nladdr->nl_groups = netlink_group_mask(nlk->dst_group);
L
Linus Torvalds 已提交
1079
	} else {
1080
		nladdr->nl_pid = nlk->portid;
1081
		nladdr->nl_groups = nlk->groups ? nlk->groups[0] : 0;
L
Linus Torvalds 已提交
1082 1083 1084 1085
	}
	return 0;
}

1086 1087 1088 1089 1090 1091 1092 1093
static int netlink_ioctl(struct socket *sock, unsigned int cmd,
			 unsigned long arg)
{
	/* try to hand this ioctl down to the NIC drivers.
	 */
	return -ENOIOCTLCMD;
}

1094
static struct sock *netlink_getsockbyportid(struct sock *ssk, u32 portid)
L
Linus Torvalds 已提交
1095 1096 1097 1098
{
	struct sock *sock;
	struct netlink_sock *nlk;

1099
	sock = netlink_lookup(sock_net(ssk), ssk->sk_protocol, portid);
L
Linus Torvalds 已提交
1100 1101 1102 1103 1104
	if (!sock)
		return ERR_PTR(-ECONNREFUSED);

	/* Don't bother queuing skb if kernel socket has no input function */
	nlk = nlk_sk(sock);
1105
	if (sock->sk_state == NETLINK_CONNECTED &&
1106
	    nlk->dst_portid != nlk_sk(ssk)->portid) {
L
Linus Torvalds 已提交
1107 1108 1109 1110 1111 1112 1113 1114
		sock_put(sock);
		return ERR_PTR(-ECONNREFUSED);
	}
	return sock;
}

struct sock *netlink_getsockbyfilp(struct file *filp)
{
A
Al Viro 已提交
1115
	struct inode *inode = file_inode(filp);
L
Linus Torvalds 已提交
1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128
	struct sock *sock;

	if (!S_ISSOCK(inode->i_mode))
		return ERR_PTR(-ENOTSOCK);

	sock = SOCKET_I(inode)->sk;
	if (sock->sk_family != AF_NETLINK)
		return ERR_PTR(-EINVAL);

	sock_hold(sock);
	return sock;
}

1129 1130
static struct sk_buff *netlink_alloc_large_skb(unsigned int size,
					       int broadcast)
1131 1132 1133 1134
{
	struct sk_buff *skb;
	void *data;

1135
	if (size <= NLMSG_GOODSIZE || broadcast)
1136 1137
		return alloc_skb(size, GFP_KERNEL);

1138 1139
	size = SKB_DATA_ALIGN(size) +
	       SKB_DATA_ALIGN(sizeof(struct skb_shared_info));
1140 1141 1142

	data = vmalloc(size);
	if (data == NULL)
1143
		return NULL;
1144

E
Eric Dumazet 已提交
1145
	skb = __build_skb(data, size);
1146 1147
	if (skb == NULL)
		vfree(data);
E
Eric Dumazet 已提交
1148
	else
1149
		skb->destructor = netlink_skb_destructor;
1150 1151 1152 1153

	return skb;
}

L
Linus Torvalds 已提交
1154 1155 1156 1157 1158 1159 1160 1161 1162 1163
/*
 * Attach a skb to a netlink socket.
 * The caller must hold a reference to the destination socket. On error, the
 * reference is dropped. The skb is not send to the destination, just all
 * all error checks are performed and memory in the queue is reserved.
 * Return values:
 * < 0: error. skb freed, reference to sock dropped.
 * 0: continue
 * 1: repeat lookup - reference dropped while waiting for socket memory.
 */
1164
int netlink_attachskb(struct sock *sk, struct sk_buff *skb,
P
Patrick McHardy 已提交
1165
		      long *timeo, struct sock *ssk)
L
Linus Torvalds 已提交
1166 1167 1168 1169 1170
{
	struct netlink_sock *nlk;

	nlk = nlk_sk(sk);

1171
	if ((atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf ||
1172
	     test_bit(NETLINK_S_CONGESTED, &nlk->state))) {
L
Linus Torvalds 已提交
1173
		DECLARE_WAITQUEUE(wait, current);
P
Patrick McHardy 已提交
1174
		if (!*timeo) {
1175
			if (!ssk || netlink_is_kernel(ssk))
L
Linus Torvalds 已提交
1176 1177 1178 1179 1180 1181 1182 1183 1184 1185
				netlink_overrun(sk);
			sock_put(sk);
			kfree_skb(skb);
			return -EAGAIN;
		}

		__set_current_state(TASK_INTERRUPTIBLE);
		add_wait_queue(&nlk->wait, &wait);

		if ((atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf ||
1186
		     test_bit(NETLINK_S_CONGESTED, &nlk->state)) &&
L
Linus Torvalds 已提交
1187
		    !sock_flag(sk, SOCK_DEAD))
P
Patrick McHardy 已提交
1188
			*timeo = schedule_timeout(*timeo);
L
Linus Torvalds 已提交
1189 1190 1191 1192 1193 1194 1195

		__set_current_state(TASK_RUNNING);
		remove_wait_queue(&nlk->wait, &wait);
		sock_put(sk);

		if (signal_pending(current)) {
			kfree_skb(skb);
P
Patrick McHardy 已提交
1196
			return sock_intr_errno(*timeo);
L
Linus Torvalds 已提交
1197 1198 1199
		}
		return 1;
	}
1200
	netlink_skb_set_owner_r(skb, sk);
L
Linus Torvalds 已提交
1201 1202 1203
	return 0;
}

1204
static int __netlink_sendskb(struct sock *sk, struct sk_buff *skb)
L
Linus Torvalds 已提交
1205 1206 1207
{
	int len = skb->len;

1208 1209
	netlink_deliver_tap(skb);

1210
	skb_queue_tail(&sk->sk_receive_queue, skb);
1211
	sk->sk_data_ready(sk);
1212 1213 1214 1215 1216 1217 1218
	return len;
}

int netlink_sendskb(struct sock *sk, struct sk_buff *skb)
{
	int len = __netlink_sendskb(sk, skb);

L
Linus Torvalds 已提交
1219 1220 1221 1222 1223 1224 1225 1226 1227 1228
	sock_put(sk);
	return len;
}

void netlink_detachskb(struct sock *sk, struct sk_buff *skb)
{
	kfree_skb(skb);
	sock_put(sk);
}

1229
static struct sk_buff *netlink_trim(struct sk_buff *skb, gfp_t allocation)
L
Linus Torvalds 已提交
1230 1231 1232
{
	int delta;

1233
	WARN_ON(skb->sk != NULL);
1234
	delta = skb->end - skb->tail;
1235
	if (is_vmalloc_addr(skb->head) || delta * 2 < skb->truesize)
L
Linus Torvalds 已提交
1236 1237 1238 1239 1240 1241
		return skb;

	if (skb_shared(skb)) {
		struct sk_buff *nskb = skb_clone(skb, allocation);
		if (!nskb)
			return skb;
1242
		consume_skb(skb);
L
Linus Torvalds 已提交
1243 1244 1245
		skb = nskb;
	}

1246 1247 1248
	pskb_expand_head(skb, 0, -delta,
			 (allocation & ~__GFP_DIRECT_RECLAIM) |
			 __GFP_NOWARN | __GFP_NORETRY);
L
Linus Torvalds 已提交
1249 1250 1251
	return skb;
}

1252 1253
static int netlink_unicast_kernel(struct sock *sk, struct sk_buff *skb,
				  struct sock *ssk)
1254 1255 1256 1257 1258 1259 1260
{
	int ret;
	struct netlink_sock *nlk = nlk_sk(sk);

	ret = -ECONNREFUSED;
	if (nlk->netlink_rcv != NULL) {
		ret = skb->len;
1261
		netlink_skb_set_owner_r(skb, sk);
1262
		NETLINK_CB(skb).sk = ssk;
1263
		netlink_deliver_tap_kernel(sk, ssk, skb);
1264
		nlk->netlink_rcv(skb);
1265 1266 1267
		consume_skb(skb);
	} else {
		kfree_skb(skb);
1268 1269 1270 1271 1272 1273
	}
	sock_put(sk);
	return ret;
}

int netlink_unicast(struct sock *ssk, struct sk_buff *skb,
1274
		    u32 portid, int nonblock)
L
Linus Torvalds 已提交
1275 1276 1277 1278 1279 1280 1281 1282 1283
{
	struct sock *sk;
	int err;
	long timeo;

	skb = netlink_trim(skb, gfp_any());

	timeo = sock_sndtimeo(ssk, nonblock);
retry:
1284
	sk = netlink_getsockbyportid(ssk, portid);
L
Linus Torvalds 已提交
1285 1286 1287 1288
	if (IS_ERR(sk)) {
		kfree_skb(skb);
		return PTR_ERR(sk);
	}
1289
	if (netlink_is_kernel(sk))
1290
		return netlink_unicast_kernel(sk, skb, ssk);
1291

1292
	if (sk_filter(sk, skb)) {
W
Wang Chen 已提交
1293
		err = skb->len;
1294 1295 1296 1297 1298
		kfree_skb(skb);
		sock_put(sk);
		return err;
	}

1299
	err = netlink_attachskb(sk, skb, &timeo, ssk);
L
Linus Torvalds 已提交
1300 1301 1302 1303 1304
	if (err == 1)
		goto retry;
	if (err)
		return err;

1305
	return netlink_sendskb(sk, skb);
L
Linus Torvalds 已提交
1306
}
1307
EXPORT_SYMBOL(netlink_unicast);
L
Linus Torvalds 已提交
1308

1309 1310 1311
int netlink_has_listeners(struct sock *sk, unsigned int group)
{
	int res = 0;
1312
	struct listeners *listeners;
1313

1314
	BUG_ON(!netlink_is_kernel(sk));
1315 1316 1317 1318

	rcu_read_lock();
	listeners = rcu_dereference(nl_table[sk->sk_protocol].listeners);

1319
	if (listeners && group - 1 < nl_table[sk->sk_protocol].groups)
1320
		res = test_bit(group - 1, listeners->masks);
1321 1322 1323

	rcu_read_unlock();

1324 1325 1326 1327
	return res;
}
EXPORT_SYMBOL_GPL(netlink_has_listeners);

1328
static int netlink_broadcast_deliver(struct sock *sk, struct sk_buff *skb)
L
Linus Torvalds 已提交
1329 1330 1331 1332
{
	struct netlink_sock *nlk = nlk_sk(sk);

	if (atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf &&
1333
	    !test_bit(NETLINK_S_CONGESTED, &nlk->state)) {
1334
		netlink_skb_set_owner_r(skb, sk);
1335
		__netlink_sendskb(sk, skb);
1336
		return atomic_read(&sk->sk_rmem_alloc) > (sk->sk_rcvbuf >> 1);
L
Linus Torvalds 已提交
1337 1338 1339 1340 1341 1342
	}
	return -1;
}

struct netlink_broadcast_data {
	struct sock *exclude_sk;
1343
	struct net *net;
1344
	u32 portid;
L
Linus Torvalds 已提交
1345 1346
	u32 group;
	int failure;
1347
	int delivery_failure;
L
Linus Torvalds 已提交
1348 1349
	int congested;
	int delivered;
A
Al Viro 已提交
1350
	gfp_t allocation;
L
Linus Torvalds 已提交
1351
	struct sk_buff *skb, *skb2;
1352 1353
	int (*tx_filter)(struct sock *dsk, struct sk_buff *skb, void *data);
	void *tx_data;
L
Linus Torvalds 已提交
1354 1355
};

1356 1357
static void do_one_broadcast(struct sock *sk,
				    struct netlink_broadcast_data *p)
L
Linus Torvalds 已提交
1358 1359 1360 1361 1362
{
	struct netlink_sock *nlk = nlk_sk(sk);
	int val;

	if (p->exclude_sk == sk)
1363
		return;
L
Linus Torvalds 已提交
1364

1365
	if (nlk->portid == p->portid || p->group - 1 >= nlk->ngroups ||
1366
	    !test_bit(p->group - 1, nlk->groups))
1367
		return;
L
Linus Torvalds 已提交
1368

1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379
	if (!net_eq(sock_net(sk), p->net)) {
		if (!(nlk->flags & NETLINK_F_LISTEN_ALL_NSID))
			return;

		if (!peernet_has_id(sock_net(sk), p->net))
			return;

		if (!file_ns_capable(sk->sk_socket->file, p->net->user_ns,
				     CAP_NET_BROADCAST))
			return;
	}
1380

L
Linus Torvalds 已提交
1381 1382
	if (p->failure) {
		netlink_overrun(sk);
1383
		return;
L
Linus Torvalds 已提交
1384 1385 1386 1387
	}

	sock_hold(sk);
	if (p->skb2 == NULL) {
1388
		if (skb_shared(p->skb)) {
L
Linus Torvalds 已提交
1389 1390
			p->skb2 = skb_clone(p->skb, p->allocation);
		} else {
1391 1392 1393 1394 1395 1396
			p->skb2 = skb_get(p->skb);
			/*
			 * skb ownership may have been set when
			 * delivered to a previous socket.
			 */
			skb_orphan(p->skb2);
L
Linus Torvalds 已提交
1397 1398 1399 1400 1401 1402
		}
	}
	if (p->skb2 == NULL) {
		netlink_overrun(sk);
		/* Clone failed. Notify ALL listeners. */
		p->failure = 1;
1403
		if (nlk->flags & NETLINK_F_BROADCAST_SEND_ERROR)
1404
			p->delivery_failure = 1;
1405 1406 1407
		goto out;
	}
	if (p->tx_filter && p->tx_filter(sk, p->skb2, p->tx_data)) {
1408 1409
		kfree_skb(p->skb2);
		p->skb2 = NULL;
1410 1411 1412
		goto out;
	}
	if (sk_filter(sk, p->skb2)) {
1413 1414
		kfree_skb(p->skb2);
		p->skb2 = NULL;
1415 1416 1417 1418 1419 1420
		goto out;
	}
	NETLINK_CB(p->skb2).nsid = peernet2id(sock_net(sk), p->net);
	NETLINK_CB(p->skb2).nsid_is_set = true;
	val = netlink_broadcast_deliver(sk, p->skb2);
	if (val < 0) {
L
Linus Torvalds 已提交
1421
		netlink_overrun(sk);
1422
		if (nlk->flags & NETLINK_F_BROADCAST_SEND_ERROR)
1423
			p->delivery_failure = 1;
L
Linus Torvalds 已提交
1424 1425 1426 1427 1428
	} else {
		p->congested |= val;
		p->delivered = 1;
		p->skb2 = NULL;
	}
1429
out:
L
Linus Torvalds 已提交
1430 1431 1432
	sock_put(sk);
}

1433
int netlink_broadcast_filtered(struct sock *ssk, struct sk_buff *skb, u32 portid,
1434 1435 1436
	u32 group, gfp_t allocation,
	int (*filter)(struct sock *dsk, struct sk_buff *skb, void *data),
	void *filter_data)
L
Linus Torvalds 已提交
1437
{
1438
	struct net *net = sock_net(ssk);
L
Linus Torvalds 已提交
1439 1440 1441 1442 1443 1444
	struct netlink_broadcast_data info;
	struct sock *sk;

	skb = netlink_trim(skb, allocation);

	info.exclude_sk = ssk;
1445
	info.net = net;
1446
	info.portid = portid;
L
Linus Torvalds 已提交
1447 1448
	info.group = group;
	info.failure = 0;
1449
	info.delivery_failure = 0;
L
Linus Torvalds 已提交
1450 1451 1452 1453 1454
	info.congested = 0;
	info.delivered = 0;
	info.allocation = allocation;
	info.skb = skb;
	info.skb2 = NULL;
1455 1456
	info.tx_filter = filter;
	info.tx_data = filter_data;
L
Linus Torvalds 已提交
1457 1458 1459 1460 1461

	/* While we sleep in clone, do not allow to change socket list */

	netlink_lock_table();

1462
	sk_for_each_bound(sk, &nl_table[ssk->sk_protocol].mc_list)
L
Linus Torvalds 已提交
1463 1464
		do_one_broadcast(sk, &info);

1465
	consume_skb(skb);
1466

L
Linus Torvalds 已提交
1467 1468
	netlink_unlock_table();

1469 1470
	if (info.delivery_failure) {
		kfree_skb(info.skb2);
1471
		return -ENOBUFS;
E
Eric Dumazet 已提交
1472 1473
	}
	consume_skb(info.skb2);
1474

L
Linus Torvalds 已提交
1475
	if (info.delivered) {
1476
		if (info.congested && gfpflags_allow_blocking(allocation))
L
Linus Torvalds 已提交
1477 1478 1479 1480 1481
			yield();
		return 0;
	}
	return -ESRCH;
}
1482 1483
EXPORT_SYMBOL(netlink_broadcast_filtered);

1484
int netlink_broadcast(struct sock *ssk, struct sk_buff *skb, u32 portid,
1485 1486
		      u32 group, gfp_t allocation)
{
1487
	return netlink_broadcast_filtered(ssk, skb, portid, group, allocation,
1488 1489
		NULL, NULL);
}
1490
EXPORT_SYMBOL(netlink_broadcast);
L
Linus Torvalds 已提交
1491 1492 1493

struct netlink_set_err_data {
	struct sock *exclude_sk;
1494
	u32 portid;
L
Linus Torvalds 已提交
1495 1496 1497 1498
	u32 group;
	int code;
};

1499
static int do_one_set_err(struct sock *sk, struct netlink_set_err_data *p)
L
Linus Torvalds 已提交
1500 1501
{
	struct netlink_sock *nlk = nlk_sk(sk);
1502
	int ret = 0;
L
Linus Torvalds 已提交
1503 1504 1505 1506

	if (sk == p->exclude_sk)
		goto out;

O
Octavian Purdila 已提交
1507
	if (!net_eq(sock_net(sk), sock_net(p->exclude_sk)))
1508 1509
		goto out;

1510
	if (nlk->portid == p->portid || p->group - 1 >= nlk->ngroups ||
1511
	    !test_bit(p->group - 1, nlk->groups))
L
Linus Torvalds 已提交
1512 1513
		goto out;

1514
	if (p->code == ENOBUFS && nlk->flags & NETLINK_F_RECV_NO_ENOBUFS) {
1515 1516 1517 1518
		ret = 1;
		goto out;
	}

L
Linus Torvalds 已提交
1519 1520 1521
	sk->sk_err = p->code;
	sk->sk_error_report(sk);
out:
1522
	return ret;
L
Linus Torvalds 已提交
1523 1524
}

1525 1526 1527
/**
 * netlink_set_err - report error to broadcast listeners
 * @ssk: the kernel netlink socket, as returned by netlink_kernel_create()
1528
 * @portid: the PORTID of a process that we want to skip (if any)
1529
 * @group: the broadcast group that will notice the error
1530
 * @code: error code, must be negative (as usual in kernelspace)
1531 1532
 *
 * This function returns the number of broadcast listeners that have set the
1533
 * NETLINK_NO_ENOBUFS socket option.
1534
 */
1535
int netlink_set_err(struct sock *ssk, u32 portid, u32 group, int code)
L
Linus Torvalds 已提交
1536 1537 1538
{
	struct netlink_set_err_data info;
	struct sock *sk;
1539
	int ret = 0;
L
Linus Torvalds 已提交
1540 1541

	info.exclude_sk = ssk;
1542
	info.portid = portid;
L
Linus Torvalds 已提交
1543
	info.group = group;
1544 1545
	/* sk->sk_err wants a positive error value */
	info.code = -code;
L
Linus Torvalds 已提交
1546 1547 1548

	read_lock(&nl_table_lock);

1549
	sk_for_each_bound(sk, &nl_table[ssk->sk_protocol].mc_list)
1550
		ret += do_one_set_err(sk, &info);
L
Linus Torvalds 已提交
1551 1552

	read_unlock(&nl_table_lock);
1553
	return ret;
L
Linus Torvalds 已提交
1554
}
1555
EXPORT_SYMBOL(netlink_set_err);
L
Linus Torvalds 已提交
1556

1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573
/* must be called with netlink table grabbed */
static void netlink_update_socket_mc(struct netlink_sock *nlk,
				     unsigned int group,
				     int is_new)
{
	int old, new = !!is_new, subscriptions;

	old = test_bit(group - 1, nlk->groups);
	subscriptions = nlk->subscriptions - old + new;
	if (new)
		__set_bit(group - 1, nlk->groups);
	else
		__clear_bit(group - 1, nlk->groups);
	netlink_update_subscriptions(&nlk->sk, subscriptions);
	netlink_update_listeners(&nlk->sk);
}

1574
static int netlink_setsockopt(struct socket *sock, int level, int optname,
1575
			      char __user *optval, unsigned int optlen)
1576 1577 1578
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1579 1580
	unsigned int val = 0;
	int err;
1581 1582 1583 1584

	if (level != SOL_NETLINK)
		return -ENOPROTOOPT;

1585
	if (optlen >= sizeof(int) &&
1586
	    get_user(val, (unsigned int __user *)optval))
1587 1588 1589 1590 1591
		return -EFAULT;

	switch (optname) {
	case NETLINK_PKTINFO:
		if (val)
1592
			nlk->flags |= NETLINK_F_RECV_PKTINFO;
1593
		else
1594
			nlk->flags &= ~NETLINK_F_RECV_PKTINFO;
1595 1596 1597 1598
		err = 0;
		break;
	case NETLINK_ADD_MEMBERSHIP:
	case NETLINK_DROP_MEMBERSHIP: {
1599
		if (!netlink_allowed(sock, NL_CFG_F_NONROOT_RECV))
1600
			return -EPERM;
1601 1602 1603
		err = netlink_realloc_groups(sk);
		if (err)
			return err;
1604 1605
		if (!val || val - 1 >= nlk->ngroups)
			return -EINVAL;
1606
		if (optname == NETLINK_ADD_MEMBERSHIP && nlk->netlink_bind) {
1607
			err = nlk->netlink_bind(sock_net(sk), val);
1608 1609 1610
			if (err)
				return err;
		}
1611
		netlink_table_grab();
1612 1613
		netlink_update_socket_mc(nlk, val,
					 optname == NETLINK_ADD_MEMBERSHIP);
1614
		netlink_table_ungrab();
1615
		if (optname == NETLINK_DROP_MEMBERSHIP && nlk->netlink_unbind)
1616
			nlk->netlink_unbind(sock_net(sk), val);
1617

1618 1619 1620
		err = 0;
		break;
	}
1621 1622
	case NETLINK_BROADCAST_ERROR:
		if (val)
1623
			nlk->flags |= NETLINK_F_BROADCAST_SEND_ERROR;
1624
		else
1625
			nlk->flags &= ~NETLINK_F_BROADCAST_SEND_ERROR;
1626 1627
		err = 0;
		break;
1628 1629
	case NETLINK_NO_ENOBUFS:
		if (val) {
1630 1631
			nlk->flags |= NETLINK_F_RECV_NO_ENOBUFS;
			clear_bit(NETLINK_S_CONGESTED, &nlk->state);
1632
			wake_up_interruptible(&nlk->wait);
E
Eric Dumazet 已提交
1633
		} else {
1634
			nlk->flags &= ~NETLINK_F_RECV_NO_ENOBUFS;
E
Eric Dumazet 已提交
1635
		}
1636 1637
		err = 0;
		break;
1638 1639 1640 1641 1642 1643 1644 1645 1646 1647
	case NETLINK_LISTEN_ALL_NSID:
		if (!ns_capable(sock_net(sk)->user_ns, CAP_NET_BROADCAST))
			return -EPERM;

		if (val)
			nlk->flags |= NETLINK_F_LISTEN_ALL_NSID;
		else
			nlk->flags &= ~NETLINK_F_LISTEN_ALL_NSID;
		err = 0;
		break;
1648 1649 1650 1651 1652 1653 1654
	case NETLINK_CAP_ACK:
		if (val)
			nlk->flags |= NETLINK_F_CAP_ACK;
		else
			nlk->flags &= ~NETLINK_F_CAP_ACK;
		err = 0;
		break;
J
Johannes Berg 已提交
1655 1656 1657 1658 1659 1660 1661
	case NETLINK_EXT_ACK:
		if (val)
			nlk->flags |= NETLINK_F_EXT_ACK;
		else
			nlk->flags &= ~NETLINK_F_EXT_ACK;
		err = 0;
		break;
1662 1663 1664 1665 1666 1667 1668
	default:
		err = -ENOPROTOOPT;
	}
	return err;
}

static int netlink_getsockopt(struct socket *sock, int level, int optname,
1669
			      char __user *optval, int __user *optlen)
1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
	int len, val, err;

	if (level != SOL_NETLINK)
		return -ENOPROTOOPT;

	if (get_user(len, optlen))
		return -EFAULT;
	if (len < 0)
		return -EINVAL;

	switch (optname) {
	case NETLINK_PKTINFO:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
1688
		val = nlk->flags & NETLINK_F_RECV_PKTINFO ? 1 : 0;
H
Heiko Carstens 已提交
1689 1690 1691
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
1692 1693
		err = 0;
		break;
1694 1695 1696 1697
	case NETLINK_BROADCAST_ERROR:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
1698
		val = nlk->flags & NETLINK_F_BROADCAST_SEND_ERROR ? 1 : 0;
1699 1700 1701 1702 1703
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
		err = 0;
		break;
1704 1705 1706 1707
	case NETLINK_NO_ENOBUFS:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
1708
		val = nlk->flags & NETLINK_F_RECV_NO_ENOBUFS ? 1 : 0;
1709 1710 1711 1712 1713
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
		err = 0;
		break;
1714 1715 1716 1717
	case NETLINK_LIST_MEMBERSHIPS: {
		int pos, idx, shift;

		err = 0;
1718
		netlink_lock_table();
1719 1720 1721 1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732
		for (pos = 0; pos * 8 < nlk->ngroups; pos += sizeof(u32)) {
			if (len - pos < sizeof(u32))
				break;

			idx = pos / sizeof(unsigned long);
			shift = (pos % sizeof(unsigned long)) * 8;
			if (put_user((u32)(nlk->groups[idx] >> shift),
				     (u32 __user *)(optval + pos))) {
				err = -EFAULT;
				break;
			}
		}
		if (put_user(ALIGN(nlk->ngroups / 8, sizeof(u32)), optlen))
			err = -EFAULT;
1733
		netlink_unlock_table();
1734 1735
		break;
	}
1736 1737 1738 1739 1740 1741 1742 1743 1744 1745
	case NETLINK_CAP_ACK:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
		val = nlk->flags & NETLINK_F_CAP_ACK ? 1 : 0;
		if (put_user(len, optlen) ||
		    put_user(val, optval))
			return -EFAULT;
		err = 0;
		break;
J
Johannes Berg 已提交
1746 1747 1748 1749 1750 1751 1752 1753 1754
	case NETLINK_EXT_ACK:
		if (len < sizeof(int))
			return -EINVAL;
		len = sizeof(int);
		val = nlk->flags & NETLINK_F_EXT_ACK ? 1 : 0;
		if (put_user(len, optlen) || put_user(val, optval))
			return -EFAULT;
		err = 0;
		break;
1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768
	default:
		err = -ENOPROTOOPT;
	}
	return err;
}

static void netlink_cmsg_recv_pktinfo(struct msghdr *msg, struct sk_buff *skb)
{
	struct nl_pktinfo info;

	info.group = NETLINK_CB(skb).dst_group;
	put_cmsg(msg, SOL_NETLINK, NETLINK_PKTINFO, sizeof(info), &info);
}

1769 1770 1771 1772 1773 1774 1775 1776 1777 1778
static void netlink_cmsg_listen_all_nsid(struct sock *sk, struct msghdr *msg,
					 struct sk_buff *skb)
{
	if (!NETLINK_CB(skb).nsid_is_set)
		return;

	put_cmsg(msg, SOL_NETLINK, NETLINK_LISTEN_ALL_NSID, sizeof(int),
		 &NETLINK_CB(skb).nsid);
}

1779
static int netlink_sendmsg(struct socket *sock, struct msghdr *msg, size_t len)
L
Linus Torvalds 已提交
1780 1781 1782
{
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
1783
	DECLARE_SOCKADDR(struct sockaddr_nl *, addr, msg->msg_name);
1784
	u32 dst_portid;
1785
	u32 dst_group;
L
Linus Torvalds 已提交
1786 1787 1788
	struct sk_buff *skb;
	int err;
	struct scm_cookie scm;
1789
	u32 netlink_skb_flags = 0;
L
Linus Torvalds 已提交
1790 1791 1792 1793

	if (msg->msg_flags&MSG_OOB)
		return -EOPNOTSUPP;

C
Christoph Hellwig 已提交
1794
	err = scm_send(sock, msg, &scm, true);
L
Linus Torvalds 已提交
1795 1796 1797 1798
	if (err < 0)
		return err;

	if (msg->msg_namelen) {
1799
		err = -EINVAL;
L
Linus Torvalds 已提交
1800
		if (addr->nl_family != AF_NETLINK)
1801
			goto out;
1802
		dst_portid = addr->nl_pid;
1803
		dst_group = ffs(addr->nl_groups);
1804
		err =  -EPERM;
1805
		if ((dst_group || dst_portid) &&
1806
		    !netlink_allowed(sock, NL_CFG_F_NONROOT_SEND))
1807
			goto out;
1808
		netlink_skb_flags |= NETLINK_SKB_DST;
L
Linus Torvalds 已提交
1809
	} else {
1810
		dst_portid = nlk->dst_portid;
1811
		dst_group = nlk->dst_group;
L
Linus Torvalds 已提交
1812 1813
	}

1814
	if (!nlk->bound) {
L
Linus Torvalds 已提交
1815 1816 1817
		err = netlink_autobind(sock);
		if (err)
			goto out;
1818 1819 1820
	} else {
		/* Ensure nlk is hashed and visible. */
		smp_rmb();
L
Linus Torvalds 已提交
1821 1822 1823 1824 1825 1826
	}

	err = -EMSGSIZE;
	if (len > sk->sk_sndbuf - 32)
		goto out;
	err = -ENOBUFS;
1827
	skb = netlink_alloc_large_skb(len, dst_group);
1828
	if (skb == NULL)
L
Linus Torvalds 已提交
1829 1830
		goto out;

1831
	NETLINK_CB(skb).portid	= nlk->portid;
1832
	NETLINK_CB(skb).dst_group = dst_group;
C
Christoph Hellwig 已提交
1833
	NETLINK_CB(skb).creds	= scm.creds;
1834
	NETLINK_CB(skb).flags	= netlink_skb_flags;
L
Linus Torvalds 已提交
1835 1836

	err = -EFAULT;
A
Al Viro 已提交
1837
	if (memcpy_from_msg(skb_put(skb, len), msg, len)) {
L
Linus Torvalds 已提交
1838 1839 1840 1841 1842 1843 1844 1845 1846 1847
		kfree_skb(skb);
		goto out;
	}

	err = security_netlink_send(sk, skb);
	if (err) {
		kfree_skb(skb);
		goto out;
	}

1848
	if (dst_group) {
L
Linus Torvalds 已提交
1849
		atomic_inc(&skb->users);
1850
		netlink_broadcast(sk, skb, dst_portid, dst_group, GFP_KERNEL);
L
Linus Torvalds 已提交
1851
	}
1852
	err = netlink_unicast(sk, skb, dst_portid, msg->msg_flags&MSG_DONTWAIT);
L
Linus Torvalds 已提交
1853 1854

out:
C
Christoph Hellwig 已提交
1855
	scm_destroy(&scm);
L
Linus Torvalds 已提交
1856 1857 1858
	return err;
}

1859
static int netlink_recvmsg(struct socket *sock, struct msghdr *msg, size_t len,
L
Linus Torvalds 已提交
1860 1861 1862 1863 1864 1865 1866
			   int flags)
{
	struct scm_cookie scm;
	struct sock *sk = sock->sk;
	struct netlink_sock *nlk = nlk_sk(sk);
	int noblock = flags&MSG_DONTWAIT;
	size_t copied;
J
Johannes Berg 已提交
1867
	struct sk_buff *skb, *data_skb;
1868
	int err, ret;
L
Linus Torvalds 已提交
1869 1870 1871 1872 1873 1874

	if (flags&MSG_OOB)
		return -EOPNOTSUPP;

	copied = 0;

1875 1876
	skb = skb_recv_datagram(sk, flags, noblock, &err);
	if (skb == NULL)
L
Linus Torvalds 已提交
1877 1878
		goto out;

J
Johannes Berg 已提交
1879 1880
	data_skb = skb;

1881 1882 1883
#ifdef CONFIG_COMPAT_NETLINK_MESSAGES
	if (unlikely(skb_shinfo(skb)->frag_list)) {
		/*
J
Johannes Berg 已提交
1884 1885 1886
		 * If this skb has a frag_list, then here that means that we
		 * will have to use the frag_list skb's data for compat tasks
		 * and the regular skb's data for normal (non-compat) tasks.
1887
		 *
J
Johannes Berg 已提交
1888 1889 1890 1891
		 * If we need to send the compat skb, assign it to the
		 * 'data_skb' variable so that it will be used below for data
		 * copying. We keep 'skb' for everything else, including
		 * freeing both later.
1892
		 */
J
Johannes Berg 已提交
1893 1894
		if (flags & MSG_CMSG_COMPAT)
			data_skb = skb_shinfo(skb)->frag_list;
1895 1896 1897
	}
#endif

E
Eric Dumazet 已提交
1898 1899 1900
	/* Record the max length of recvmsg() calls for future allocations */
	nlk->max_recvmsg_len = max(nlk->max_recvmsg_len, len);
	nlk->max_recvmsg_len = min_t(size_t, nlk->max_recvmsg_len,
1901
				     SKB_WITH_OVERHEAD(32768));
E
Eric Dumazet 已提交
1902

J
Johannes Berg 已提交
1903
	copied = data_skb->len;
L
Linus Torvalds 已提交
1904 1905 1906 1907 1908
	if (len < copied) {
		msg->msg_flags |= MSG_TRUNC;
		copied = len;
	}

J
Johannes Berg 已提交
1909
	skb_reset_transport_header(data_skb);
1910
	err = skb_copy_datagram_msg(data_skb, 0, msg, copied);
L
Linus Torvalds 已提交
1911 1912

	if (msg->msg_name) {
1913
		DECLARE_SOCKADDR(struct sockaddr_nl *, addr, msg->msg_name);
L
Linus Torvalds 已提交
1914 1915
		addr->nl_family = AF_NETLINK;
		addr->nl_pad    = 0;
1916
		addr->nl_pid	= NETLINK_CB(skb).portid;
1917
		addr->nl_groups	= netlink_group_mask(NETLINK_CB(skb).dst_group);
L
Linus Torvalds 已提交
1918 1919 1920
		msg->msg_namelen = sizeof(*addr);
	}

1921
	if (nlk->flags & NETLINK_F_RECV_PKTINFO)
1922
		netlink_cmsg_recv_pktinfo(msg, skb);
1923 1924
	if (nlk->flags & NETLINK_F_LISTEN_ALL_NSID)
		netlink_cmsg_listen_all_nsid(sk, msg, skb);
1925

C
Christoph Hellwig 已提交
1926 1927
	memset(&scm, 0, sizeof(scm));
	scm.creds = *NETLINK_CREDS(skb);
1928
	if (flags & MSG_TRUNC)
J
Johannes Berg 已提交
1929
		copied = data_skb->len;
1930

L
Linus Torvalds 已提交
1931 1932
	skb_free_datagram(sk, skb);

1933 1934
	if (nlk->cb_running &&
	    atomic_read(&sk->sk_rmem_alloc) <= sk->sk_rcvbuf / 2) {
1935 1936
		ret = netlink_dump(sk);
		if (ret) {
1937
			sk->sk_err = -ret;
1938 1939 1940
			sk->sk_error_report(sk);
		}
	}
L
Linus Torvalds 已提交
1941

C
Christoph Hellwig 已提交
1942
	scm_recv(sock, msg, &scm, flags);
L
Linus Torvalds 已提交
1943 1944 1945 1946 1947
out:
	netlink_rcv_wake(sk);
	return err ? : copied;
}

1948
static void netlink_data_ready(struct sock *sk)
L
Linus Torvalds 已提交
1949
{
1950
	BUG();
L
Linus Torvalds 已提交
1951 1952 1953
}

/*
1954
 *	We export these functions to other modules. They provide a
L
Linus Torvalds 已提交
1955 1956 1957 1958 1959
 *	complete set of kernel non-blocking support for message
 *	queueing.
 */

struct sock *
1960 1961
__netlink_kernel_create(struct net *net, int unit, struct module *module,
			struct netlink_kernel_cfg *cfg)
L
Linus Torvalds 已提交
1962 1963 1964
{
	struct socket *sock;
	struct sock *sk;
1965
	struct netlink_sock *nlk;
1966
	struct listeners *listeners = NULL;
1967 1968
	struct mutex *cb_mutex = cfg ? cfg->cb_mutex : NULL;
	unsigned int groups;
L
Linus Torvalds 已提交
1969

1970
	BUG_ON(!nl_table);
L
Linus Torvalds 已提交
1971

1972
	if (unit < 0 || unit >= MAX_LINKS)
L
Linus Torvalds 已提交
1973 1974 1975 1976
		return NULL;

	if (sock_create_lite(PF_NETLINK, SOCK_DGRAM, unit, &sock))
		return NULL;
1977 1978

	if (__netlink_create(net, sock, cb_mutex, unit, 1) < 0)
1979 1980 1981
		goto out_sock_release_nosk;

	sk = sock->sk;
1982

1983
	if (!cfg || cfg->groups < 32)
1984
		groups = 32;
1985 1986
	else
		groups = cfg->groups;
1987

1988
	listeners = kzalloc(sizeof(*listeners) + NLGRPSZ(groups), GFP_KERNEL);
1989 1990 1991
	if (!listeners)
		goto out_sock_release;

L
Linus Torvalds 已提交
1992
	sk->sk_data_ready = netlink_data_ready;
1993 1994
	if (cfg && cfg->input)
		nlk_sk(sk)->netlink_rcv = cfg->input;
L
Linus Torvalds 已提交
1995

1996
	if (netlink_insert(sk, 0))
1997
		goto out_sock_release;
1998

1999
	nlk = nlk_sk(sk);
2000
	nlk->flags |= NETLINK_F_KERNEL_SOCKET;
2001 2002

	netlink_table_grab();
2003 2004
	if (!nl_table[unit].registered) {
		nl_table[unit].groups = groups;
2005
		rcu_assign_pointer(nl_table[unit].listeners, listeners);
2006 2007
		nl_table[unit].cb_mutex = cb_mutex;
		nl_table[unit].module = module;
2008 2009
		if (cfg) {
			nl_table[unit].bind = cfg->bind;
2010
			nl_table[unit].unbind = cfg->unbind;
2011
			nl_table[unit].flags = cfg->flags;
2012 2013
			if (cfg->compare)
				nl_table[unit].compare = cfg->compare;
2014
		}
2015
		nl_table[unit].registered = 1;
2016 2017
	} else {
		kfree(listeners);
2018
		nl_table[unit].registered++;
2019
	}
2020
	netlink_table_ungrab();
2021 2022
	return sk;

2023
out_sock_release:
2024
	kfree(listeners);
2025
	netlink_kernel_release(sk);
2026 2027 2028
	return NULL;

out_sock_release_nosk:
2029
	sock_release(sock);
2030
	return NULL;
L
Linus Torvalds 已提交
2031
}
2032
EXPORT_SYMBOL(__netlink_kernel_create);
2033 2034 2035 2036

void
netlink_kernel_release(struct sock *sk)
{
2037 2038 2039 2040
	if (sk == NULL || sk->sk_socket == NULL)
		return;

	sock_release(sk->sk_socket);
2041 2042 2043
}
EXPORT_SYMBOL(netlink_kernel_release);

2044
int __netlink_change_ngroups(struct sock *sk, unsigned int groups)
2045
{
2046
	struct listeners *new, *old;
2047 2048 2049 2050 2051 2052
	struct netlink_table *tbl = &nl_table[sk->sk_protocol];

	if (groups < 32)
		groups = 32;

	if (NLGRPSZ(tbl->groups) < NLGRPSZ(groups)) {
2053 2054
		new = kzalloc(sizeof(*new) + NLGRPSZ(groups), GFP_ATOMIC);
		if (!new)
2055
			return -ENOMEM;
2056
		old = nl_deref_protected(tbl->listeners);
2057 2058 2059
		memcpy(new->masks, old->masks, NLGRPSZ(tbl->groups));
		rcu_assign_pointer(tbl->listeners, new);

2060
		kfree_rcu(old, rcu);
2061 2062 2063
	}
	tbl->groups = groups;

2064 2065 2066 2067 2068 2069 2070 2071 2072 2073 2074 2075 2076 2077 2078 2079 2080 2081 2082 2083 2084
	return 0;
}

/**
 * netlink_change_ngroups - change number of multicast groups
 *
 * This changes the number of multicast groups that are available
 * on a certain netlink family. Note that it is not possible to
 * change the number of groups to below 32. Also note that it does
 * not implicitly call netlink_clear_multicast_users() when the
 * number of groups is reduced.
 *
 * @sk: The kernel netlink socket, as returned by netlink_kernel_create().
 * @groups: The new number of groups.
 */
int netlink_change_ngroups(struct sock *sk, unsigned int groups)
{
	int err;

	netlink_table_grab();
	err = __netlink_change_ngroups(sk, groups);
2085
	netlink_table_ungrab();
2086

2087 2088 2089
	return err;
}

2090 2091 2092 2093 2094
void __netlink_clear_multicast_users(struct sock *ksk, unsigned int group)
{
	struct sock *sk;
	struct netlink_table *tbl = &nl_table[ksk->sk_protocol];

2095
	sk_for_each_bound(sk, &tbl->mc_list)
2096 2097 2098
		netlink_update_socket_mc(nlk_sk(sk), group, 0);
}

2099
struct nlmsghdr *
2100
__nlmsg_put(struct sk_buff *skb, u32 portid, u32 seq, int type, int len, int flags)
2101 2102
{
	struct nlmsghdr *nlh;
2103
	int size = nlmsg_msg_size(len);
2104

2105
	nlh = (struct nlmsghdr *)skb_put(skb, NLMSG_ALIGN(size));
2106 2107 2108
	nlh->nlmsg_type = type;
	nlh->nlmsg_len = size;
	nlh->nlmsg_flags = flags;
2109
	nlh->nlmsg_pid = portid;
2110 2111
	nlh->nlmsg_seq = seq;
	if (!__builtin_constant_p(size) || NLMSG_ALIGN(size) - size != 0)
2112
		memset(nlmsg_data(nlh) + len, 0, NLMSG_ALIGN(size) - size);
2113 2114 2115 2116
	return nlh;
}
EXPORT_SYMBOL(__nlmsg_put);

L
Linus Torvalds 已提交
2117 2118 2119 2120 2121 2122 2123 2124 2125
/*
 * It looks a bit ugly.
 * It would be better to create kernel thread.
 */

static int netlink_dump(struct sock *sk)
{
	struct netlink_sock *nlk = nlk_sk(sk);
	struct netlink_callback *cb;
2126
	struct sk_buff *skb = NULL;
L
Linus Torvalds 已提交
2127
	struct nlmsghdr *nlh;
2128
	struct module *module;
2129
	int len, err = -ENOBUFS;
2130
	int alloc_min_size;
2131
	int alloc_size;
L
Linus Torvalds 已提交
2132

2133
	mutex_lock(nlk->cb_mutex);
2134
	if (!nlk->cb_running) {
2135 2136
		err = -EINVAL;
		goto errout_skb;
L
Linus Torvalds 已提交
2137 2138
	}

2139
	if (atomic_read(&sk->sk_rmem_alloc) >= sk->sk_rcvbuf)
2140
		goto errout_skb;
E
Eric Dumazet 已提交
2141 2142 2143 2144 2145 2146

	/* NLMSG_GOODSIZE is small to avoid high order allocations being
	 * required, but it makes sense to _attempt_ a 16K bytes allocation
	 * to reduce number of system calls on dump operations, if user
	 * ever provided a big enough buffer.
	 */
2147 2148 2149 2150 2151
	cb = &nlk->cb;
	alloc_min_size = max_t(int, cb->min_dump_alloc, NLMSG_GOODSIZE);

	if (alloc_min_size < nlk->max_recvmsg_len) {
		alloc_size = nlk->max_recvmsg_len;
2152 2153 2154
		skb = alloc_skb(alloc_size,
				(GFP_KERNEL & ~__GFP_DIRECT_RECLAIM) |
				__GFP_NOWARN | __GFP_NORETRY);
E
Eric Dumazet 已提交
2155
	}
2156 2157
	if (!skb) {
		alloc_size = alloc_min_size;
2158
		skb = alloc_skb(alloc_size, GFP_KERNEL);
2159
	}
2160
	if (!skb)
2161
		goto errout_skb;
2162 2163 2164 2165 2166 2167 2168 2169 2170 2171 2172

	/* Trim skb to allocated size. User is expected to provide buffer as
	 * large as max(min_dump_alloc, 16KiB (mac_recvmsg_len capped at
	 * netlink_recvmsg())). dump will pack as many smaller messages as
	 * could fit within the allocated skb. skb is typically allocated
	 * with larger space than required (could be as much as near 2x the
	 * requested size with align to next power of 2 approach). Allowing
	 * dump to use the excess space makes it difficult for a user to have a
	 * reasonable static buffer based on the expected largest dump of a
	 * single netdev. The outcome is MSG_TRUNC error.
	 */
2173
	skb_reserve(skb, skb_tailroom(skb) - alloc_size);
2174
	netlink_skb_set_owner_r(skb, sk);
2175

L
Linus Torvalds 已提交
2176 2177 2178
	len = cb->dump(skb, cb);

	if (len > 0) {
2179
		mutex_unlock(nlk->cb_mutex);
2180 2181 2182

		if (sk_filter(sk, skb))
			kfree_skb(skb);
2183 2184
		else
			__netlink_sendskb(sk, skb);
L
Linus Torvalds 已提交
2185 2186 2187
		return 0;
	}

2188 2189 2190 2191
	nlh = nlmsg_put_answer(skb, cb, NLMSG_DONE, sizeof(len), NLM_F_MULTI);
	if (!nlh)
		goto errout_skb;

2192 2193
	nl_dump_check_consistent(cb, nlh);

2194 2195
	memcpy(nlmsg_data(nlh), &len, sizeof(len));

2196 2197
	if (sk_filter(sk, skb))
		kfree_skb(skb);
2198 2199
	else
		__netlink_sendskb(sk, skb);
L
Linus Torvalds 已提交
2200

2201 2202
	if (cb->done)
		cb->done(cb);
L
Linus Torvalds 已提交
2203

2204
	nlk->cb_running = false;
2205 2206
	module = cb->module;
	skb = cb->skb;
2207
	mutex_unlock(nlk->cb_mutex);
2208 2209
	module_put(module);
	consume_skb(skb);
L
Linus Torvalds 已提交
2210
	return 0;
2211

2212
errout_skb:
2213
	mutex_unlock(nlk->cb_mutex);
2214 2215
	kfree_skb(skb);
	return err;
L
Linus Torvalds 已提交
2216 2217
}

2218 2219 2220
int __netlink_dump_start(struct sock *ssk, struct sk_buff *skb,
			 const struct nlmsghdr *nlh,
			 struct netlink_dump_control *control)
L
Linus Torvalds 已提交
2221 2222 2223 2224
{
	struct netlink_callback *cb;
	struct sock *sk;
	struct netlink_sock *nlk;
2225
	int ret;
L
Linus Torvalds 已提交
2226

2227
	atomic_inc(&skb->users);
2228

2229
	sk = netlink_lookup(sock_net(ssk), ssk->sk_protocol, NETLINK_CB(skb).portid);
L
Linus Torvalds 已提交
2230
	if (sk == NULL) {
2231 2232
		ret = -ECONNREFUSED;
		goto error_free;
L
Linus Torvalds 已提交
2233
	}
2234

2235
	nlk = nlk_sk(sk);
2236
	mutex_lock(nlk->cb_mutex);
2237
	/* A dump is in progress... */
2238
	if (nlk->cb_running) {
2239
		ret = -EBUSY;
2240
		goto error_unlock;
L
Linus Torvalds 已提交
2241
	}
2242
	/* add reference of module which cb->dump belongs to */
2243
	if (!try_module_get(control->module)) {
2244
		ret = -EPROTONOSUPPORT;
2245
		goto error_unlock;
2246 2247
	}

2248 2249
	cb = &nlk->cb;
	memset(cb, 0, sizeof(*cb));
2250
	cb->start = control->start;
2251 2252 2253 2254 2255 2256 2257 2258 2259 2260
	cb->dump = control->dump;
	cb->done = control->done;
	cb->nlh = nlh;
	cb->data = control->data;
	cb->module = control->module;
	cb->min_dump_alloc = control->min_dump_alloc;
	cb->skb = skb;

	nlk->cb_running = true;

2261
	mutex_unlock(nlk->cb_mutex);
L
Linus Torvalds 已提交
2262

2263 2264 2265
	if (cb->start)
		cb->start(cb);

2266
	ret = netlink_dump(sk);
L
Linus Torvalds 已提交
2267
	sock_put(sk);
2268

2269 2270 2271
	if (ret)
		return ret;

2272 2273 2274 2275
	/* We successfully started a dump, by returning -EINTR we
	 * signal not to send ACK even if it was requested.
	 */
	return -EINTR;
2276 2277 2278 2279 2280 2281 2282

error_unlock:
	sock_put(sk);
	mutex_unlock(nlk->cb_mutex);
error_free:
	kfree_skb(skb);
	return ret;
L
Linus Torvalds 已提交
2283
}
2284
EXPORT_SYMBOL(__netlink_dump_start);
L
Linus Torvalds 已提交
2285

J
Johannes Berg 已提交
2286 2287
void netlink_ack(struct sk_buff *in_skb, struct nlmsghdr *nlh, int err,
		 const struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
2288 2289 2290 2291
{
	struct sk_buff *skb;
	struct nlmsghdr *rep;
	struct nlmsgerr *errmsg;
2292
	size_t payload = sizeof(*errmsg);
J
Johannes Berg 已提交
2293
	size_t tlvlen = 0;
2294
	struct netlink_sock *nlk = nlk_sk(NETLINK_CB(in_skb).sk);
J
Johannes Berg 已提交
2295
	unsigned int flags = 0;
L
Linus Torvalds 已提交
2296

2297
	/* Error messages get the original request appened, unless the user
J
Johannes Berg 已提交
2298 2299
	 * requests to cap the error message, and get extra error data if
	 * requested.
2300
	 */
J
Johannes Berg 已提交
2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312 2313 2314
	if (err) {
		if (!(nlk->flags & NETLINK_F_CAP_ACK))
			payload += nlmsg_len(nlh);
		else
			flags |= NLM_F_CAPPED;
		if (nlk->flags & NETLINK_F_EXT_ACK && extack) {
			if (extack->_msg)
				tlvlen += nla_total_size(strlen(extack->_msg) + 1);
			if (extack->bad_attr)
				tlvlen += nla_total_size(sizeof(u32));
		}
	} else {
		flags |= NLM_F_CAPPED;
	}
L
Linus Torvalds 已提交
2315

J
Johannes Berg 已提交
2316 2317 2318 2319
	if (tlvlen)
		flags |= NLM_F_ACK_TLVS;

	skb = nlmsg_new(payload + tlvlen, GFP_KERNEL);
L
Linus Torvalds 已提交
2320 2321 2322
	if (!skb) {
		struct sock *sk;

2323
		sk = netlink_lookup(sock_net(in_skb->sk),
2324
				    in_skb->sk->sk_protocol,
2325
				    NETLINK_CB(in_skb).portid);
L
Linus Torvalds 已提交
2326 2327 2328 2329 2330 2331 2332 2333
		if (sk) {
			sk->sk_err = ENOBUFS;
			sk->sk_error_report(sk);
			sock_put(sk);
		}
		return;
	}

2334
	rep = __nlmsg_put(skb, NETLINK_CB(in_skb).portid, nlh->nlmsg_seq,
J
Johannes Berg 已提交
2335
			  NLMSG_ERROR, payload, flags);
2336
	errmsg = nlmsg_data(rep);
L
Linus Torvalds 已提交
2337
	errmsg->error = err;
2338
	memcpy(&errmsg->msg, nlh, payload > sizeof(*errmsg) ? nlh->nlmsg_len : sizeof(*nlh));
J
Johannes Berg 已提交
2339 2340 2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 2351 2352 2353 2354

	if (err && nlk->flags & NETLINK_F_EXT_ACK && extack) {
		if (extack->_msg)
			WARN_ON(nla_put_string(skb, NLMSGERR_ATTR_MSG,
					       extack->_msg));
		if (extack->bad_attr &&
		    !WARN_ON((u8 *)extack->bad_attr < in_skb->data ||
			     (u8 *)extack->bad_attr >= in_skb->data +
						       in_skb->len))
			WARN_ON(nla_put_u32(skb, NLMSGERR_ATTR_OFFS,
					    (u8 *)extack->bad_attr -
					    in_skb->data));
	}

	nlmsg_end(skb, rep);

2355
	netlink_unicast(in_skb->sk, skb, NETLINK_CB(in_skb).portid, MSG_DONTWAIT);
L
Linus Torvalds 已提交
2356
}
2357
EXPORT_SYMBOL(netlink_ack);
L
Linus Torvalds 已提交
2358

2359
int netlink_rcv_skb(struct sk_buff *skb, int (*cb)(struct sk_buff *,
J
Johannes Berg 已提交
2360 2361
						   struct nlmsghdr *,
						   struct netlink_ext_ack *))
2362
{
J
Johannes Berg 已提交
2363
	struct netlink_ext_ack extack = {};
2364 2365 2366 2367
	struct nlmsghdr *nlh;
	int err;

	while (skb->len >= nlmsg_total_size(0)) {
2368 2369
		int msglen;

2370
		nlh = nlmsg_hdr(skb);
2371
		err = 0;
2372

2373
		if (nlh->nlmsg_len < NLMSG_HDRLEN || skb->len < nlh->nlmsg_len)
2374 2375
			return 0;

2376 2377
		/* Only requests are handled by the kernel */
		if (!(nlh->nlmsg_flags & NLM_F_REQUEST))
2378
			goto ack;
2379 2380 2381

		/* Skip control messages */
		if (nlh->nlmsg_type < NLMSG_MIN_TYPE)
2382
			goto ack;
2383

J
Johannes Berg 已提交
2384
		err = cb(skb, nlh, &extack);
2385 2386 2387 2388
		if (err == -EINTR)
			goto skip;

ack:
2389
		if (nlh->nlmsg_flags & NLM_F_ACK || err)
J
Johannes Berg 已提交
2390
			netlink_ack(skb, nlh, err, &extack);
2391

2392
skip:
2393
		msglen = NLMSG_ALIGN(nlh->nlmsg_len);
2394 2395 2396
		if (msglen > skb->len)
			msglen = skb->len;
		skb_pull(skb, msglen);
2397 2398 2399 2400
	}

	return 0;
}
2401
EXPORT_SYMBOL(netlink_rcv_skb);
2402

2403 2404 2405 2406
/**
 * nlmsg_notify - send a notification netlink message
 * @sk: netlink socket to use
 * @skb: notification message
2407
 * @portid: destination netlink portid for reports or 0
2408 2409 2410 2411
 * @group: destination multicast group or 0
 * @report: 1 to report back, 0 to disable
 * @flags: allocation flags
 */
2412
int nlmsg_notify(struct sock *sk, struct sk_buff *skb, u32 portid,
2413 2414 2415 2416 2417
		 unsigned int group, int report, gfp_t flags)
{
	int err = 0;

	if (group) {
2418
		int exclude_portid = 0;
2419 2420 2421

		if (report) {
			atomic_inc(&skb->users);
2422
			exclude_portid = portid;
2423 2424
		}

2425 2426
		/* errors reported via destination sk->sk_err, but propagate
		 * delivery errors if NETLINK_BROADCAST_ERROR flag is set */
2427
		err = nlmsg_multicast(sk, skb, exclude_portid, group, flags);
2428 2429
	}

2430 2431 2432
	if (report) {
		int err2;

2433
		err2 = nlmsg_unicast(sk, skb, portid);
2434 2435 2436
		if (!err || err == -ESRCH)
			err = err2;
	}
2437 2438 2439

	return err;
}
2440
EXPORT_SYMBOL(nlmsg_notify);
2441

L
Linus Torvalds 已提交
2442 2443
#ifdef CONFIG_PROC_FS
struct nl_seq_iter {
2444
	struct seq_net_private p;
2445
	struct rhashtable_iter hti;
L
Linus Torvalds 已提交
2446 2447 2448
	int link;
};

2449
static int netlink_walk_start(struct nl_seq_iter *iter)
L
Linus Torvalds 已提交
2450
{
2451
	int err;
L
Linus Torvalds 已提交
2452

2453 2454
	err = rhashtable_walk_init(&nl_table[iter->link].hash, &iter->hti,
				   GFP_KERNEL);
2455 2456 2457
	if (err) {
		iter->link = MAX_LINKS;
		return err;
L
Linus Torvalds 已提交
2458
	}
2459 2460 2461

	err = rhashtable_walk_start(&iter->hti);
	return err == -EAGAIN ? 0 : err;
L
Linus Torvalds 已提交
2462 2463
}

2464
static void netlink_walk_stop(struct nl_seq_iter *iter)
L
Linus Torvalds 已提交
2465
{
2466 2467
	rhashtable_walk_stop(&iter->hti);
	rhashtable_walk_exit(&iter->hti);
L
Linus Torvalds 已提交
2468 2469
}

2470
static void *__netlink_seq_next(struct seq_file *seq)
L
Linus Torvalds 已提交
2471
{
2472
	struct nl_seq_iter *iter = seq->private;
2473
	struct netlink_sock *nlk;
L
Linus Torvalds 已提交
2474

2475 2476 2477
	do {
		for (;;) {
			int err;
L
Linus Torvalds 已提交
2478

2479
			nlk = rhashtable_walk_next(&iter->hti);
2480

2481 2482 2483
			if (IS_ERR(nlk)) {
				if (PTR_ERR(nlk) == -EAGAIN)
					continue;
2484

2485 2486
				return nlk;
			}
L
Linus Torvalds 已提交
2487

2488 2489
			if (nlk)
				break;
L
Linus Torvalds 已提交
2490

2491 2492 2493
			netlink_walk_stop(iter);
			if (++iter->link >= MAX_LINKS)
				return NULL;
2494

2495 2496 2497
			err = netlink_walk_start(iter);
			if (err)
				return ERR_PTR(err);
L
Linus Torvalds 已提交
2498
		}
2499
	} while (sock_net(&nlk->sk) != seq_file_net(seq));
L
Linus Torvalds 已提交
2500

2501 2502
	return nlk;
}
L
Linus Torvalds 已提交
2503

2504 2505 2506 2507 2508 2509 2510 2511 2512 2513 2514 2515 2516 2517 2518 2519 2520 2521 2522 2523 2524 2525 2526
static void *netlink_seq_start(struct seq_file *seq, loff_t *posp)
{
	struct nl_seq_iter *iter = seq->private;
	void *obj = SEQ_START_TOKEN;
	loff_t pos;
	int err;

	iter->link = 0;

	err = netlink_walk_start(iter);
	if (err)
		return ERR_PTR(err);

	for (pos = *posp; pos && obj && !IS_ERR(obj); pos--)
		obj = __netlink_seq_next(seq);

	return obj;
}

static void *netlink_seq_next(struct seq_file *seq, void *v, loff_t *pos)
{
	++*pos;
	return __netlink_seq_next(seq);
L
Linus Torvalds 已提交
2527 2528 2529 2530
}

static void netlink_seq_stop(struct seq_file *seq, void *v)
{
2531 2532 2533 2534 2535 2536
	struct nl_seq_iter *iter = seq->private;

	if (iter->link >= MAX_LINKS)
		return;

	netlink_walk_stop(iter);
L
Linus Torvalds 已提交
2537 2538 2539 2540 2541
}


static int netlink_seq_show(struct seq_file *seq, void *v)
{
E
Eric Dumazet 已提交
2542
	if (v == SEQ_START_TOKEN) {
L
Linus Torvalds 已提交
2543 2544
		seq_puts(seq,
			 "sk       Eth Pid    Groups   "
2545
			 "Rmem     Wmem     Dump     Locks     Drops     Inode\n");
E
Eric Dumazet 已提交
2546
	} else {
L
Linus Torvalds 已提交
2547 2548 2549
		struct sock *s = v;
		struct netlink_sock *nlk = nlk_sk(s);

2550
		seq_printf(seq, "%pK %-3d %-6u %08x %-8d %-8d %d %-8d %-8d %-8lu\n",
L
Linus Torvalds 已提交
2551 2552
			   s,
			   s->sk_protocol,
2553
			   nlk->portid,
2554
			   nlk->groups ? (u32)nlk->groups[0] : 0,
2555 2556
			   sk_rmem_alloc_get(s),
			   sk_wmem_alloc_get(s),
2557
			   nlk->cb_running,
2558
			   atomic_read(&s->sk_refcnt),
2559 2560
			   atomic_read(&s->sk_drops),
			   sock_i_ino(s)
L
Linus Torvalds 已提交
2561 2562 2563 2564 2565 2566
			);

	}
	return 0;
}

2567
static const struct seq_operations netlink_seq_ops = {
L
Linus Torvalds 已提交
2568 2569 2570 2571 2572 2573 2574 2575 2576
	.start  = netlink_seq_start,
	.next   = netlink_seq_next,
	.stop   = netlink_seq_stop,
	.show   = netlink_seq_show,
};


static int netlink_seq_open(struct inode *inode, struct file *file)
{
2577 2578
	return seq_open_net(inode, file, &netlink_seq_ops,
				sizeof(struct nl_seq_iter));
2579 2580
}

2581
static const struct file_operations netlink_seq_fops = {
L
Linus Torvalds 已提交
2582 2583 2584 2585
	.owner		= THIS_MODULE,
	.open		= netlink_seq_open,
	.read		= seq_read,
	.llseek		= seq_lseek,
2586
	.release	= seq_release_net,
L
Linus Torvalds 已提交
2587 2588 2589 2590 2591 2592
};

#endif

int netlink_register_notifier(struct notifier_block *nb)
{
W
WANG Cong 已提交
2593
	return blocking_notifier_chain_register(&netlink_chain, nb);
L
Linus Torvalds 已提交
2594
}
2595
EXPORT_SYMBOL(netlink_register_notifier);
L
Linus Torvalds 已提交
2596 2597 2598

int netlink_unregister_notifier(struct notifier_block *nb)
{
W
WANG Cong 已提交
2599
	return blocking_notifier_chain_unregister(&netlink_chain, nb);
L
Linus Torvalds 已提交
2600
}
2601
EXPORT_SYMBOL(netlink_unregister_notifier);
2602

2603
static const struct proto_ops netlink_ops = {
L
Linus Torvalds 已提交
2604 2605 2606 2607 2608 2609 2610 2611
	.family =	PF_NETLINK,
	.owner =	THIS_MODULE,
	.release =	netlink_release,
	.bind =		netlink_bind,
	.connect =	netlink_connect,
	.socketpair =	sock_no_socketpair,
	.accept =	sock_no_accept,
	.getname =	netlink_getname,
2612
	.poll =		datagram_poll,
2613
	.ioctl =	netlink_ioctl,
L
Linus Torvalds 已提交
2614 2615
	.listen =	sock_no_listen,
	.shutdown =	sock_no_shutdown,
2616 2617
	.setsockopt =	netlink_setsockopt,
	.getsockopt =	netlink_getsockopt,
L
Linus Torvalds 已提交
2618 2619
	.sendmsg =	netlink_sendmsg,
	.recvmsg =	netlink_recvmsg,
2620
	.mmap =		sock_no_mmap,
L
Linus Torvalds 已提交
2621 2622 2623
	.sendpage =	sock_no_sendpage,
};

2624
static const struct net_proto_family netlink_family_ops = {
L
Linus Torvalds 已提交
2625 2626 2627 2628 2629
	.family = PF_NETLINK,
	.create = netlink_create,
	.owner	= THIS_MODULE,	/* for consistency 8) */
};

2630
static int __net_init netlink_net_init(struct net *net)
2631 2632
{
#ifdef CONFIG_PROC_FS
2633
	if (!proc_create("netlink", 0, net->proc_net, &netlink_seq_fops))
2634 2635 2636 2637 2638
		return -ENOMEM;
#endif
	return 0;
}

2639
static void __net_exit netlink_net_exit(struct net *net)
2640 2641
{
#ifdef CONFIG_PROC_FS
2642
	remove_proc_entry("netlink", net->proc_net);
2643 2644 2645
#endif
}

2646 2647
static void __init netlink_add_usersock_entry(void)
{
2648
	struct listeners *listeners;
2649 2650
	int groups = 32;

2651
	listeners = kzalloc(sizeof(*listeners) + NLGRPSZ(groups), GFP_KERNEL);
2652
	if (!listeners)
2653
		panic("netlink_add_usersock_entry: Cannot allocate listeners\n");
2654 2655 2656 2657

	netlink_table_grab();

	nl_table[NETLINK_USERSOCK].groups = groups;
2658
	rcu_assign_pointer(nl_table[NETLINK_USERSOCK].listeners, listeners);
2659 2660
	nl_table[NETLINK_USERSOCK].module = THIS_MODULE;
	nl_table[NETLINK_USERSOCK].registered = 1;
2661
	nl_table[NETLINK_USERSOCK].flags = NL_CFG_F_NONROOT_SEND;
2662 2663 2664 2665

	netlink_table_ungrab();
}

2666
static struct pernet_operations __net_initdata netlink_net_ops = {
2667 2668 2669 2670
	.init = netlink_net_init,
	.exit = netlink_net_exit,
};

2671
static inline u32 netlink_hash(const void *data, u32 len, u32 seed)
2672 2673 2674 2675
{
	const struct netlink_sock *nlk = data;
	struct netlink_compare_arg arg;

2676
	netlink_compare_arg_init(&arg, sock_net(&nlk->sk), nlk->portid);
2677
	return jhash2((u32 *)&arg, netlink_compare_arg_len / sizeof(u32), seed);
2678 2679 2680 2681 2682 2683 2684
}

static const struct rhashtable_params netlink_rhashtable_params = {
	.head_offset = offsetof(struct netlink_sock, node),
	.key_len = netlink_compare_arg_len,
	.obj_hashfn = netlink_hash,
	.obj_cmpfn = netlink_compare,
2685
	.automatic_shrinking = true,
2686 2687
};

L
Linus Torvalds 已提交
2688 2689 2690 2691 2692 2693 2694 2695
static int __init netlink_proto_init(void)
{
	int i;
	int err = proto_register(&netlink_proto, 0);

	if (err != 0)
		goto out;

2696
	BUILD_BUG_ON(sizeof(struct netlink_skb_parms) > FIELD_SIZEOF(struct sk_buff, cb));
L
Linus Torvalds 已提交
2697

2698
	nl_table = kcalloc(MAX_LINKS, sizeof(*nl_table), GFP_KERNEL);
2699 2700
	if (!nl_table)
		goto panic;
L
Linus Torvalds 已提交
2701 2702

	for (i = 0; i < MAX_LINKS; i++) {
2703 2704
		if (rhashtable_init(&nl_table[i].hash,
				    &netlink_rhashtable_params) < 0) {
2705 2706
			while (--i > 0)
				rhashtable_destroy(&nl_table[i].hash);
L
Linus Torvalds 已提交
2707
			kfree(nl_table);
2708
			goto panic;
L
Linus Torvalds 已提交
2709 2710 2711
		}
	}

2712 2713
	INIT_LIST_HEAD(&netlink_tap_all);

2714 2715
	netlink_add_usersock_entry();

L
Linus Torvalds 已提交
2716
	sock_register(&netlink_family_ops);
2717
	register_pernet_subsys(&netlink_net_ops);
2718
	/* The netlink device handler may be needed early. */
L
Linus Torvalds 已提交
2719 2720 2721
	rtnetlink_init();
out:
	return err;
2722 2723
panic:
	panic("netlink_init: Cannot allocate nl_table\n");
L
Linus Torvalds 已提交
2724 2725 2726
}

core_initcall(netlink_proto_init);