You need to sign in or sign up before continuing.
gc.c 19.7 KB
Newer Older
T
Tetsuo Handa 已提交
1 2 3 4 5 6 7 8 9 10 11
/*
 * security/tomoyo/gc.c
 *
 * Implementation of the Domain-Based Mandatory Access Control.
 *
 * Copyright (C) 2005-2010  NTT DATA CORPORATION
 *
 */

#include "common.h"
#include <linux/kthread.h>
12
#include <linux/slab.h>
T
Tetsuo Handa 已提交
13

T
Tetsuo Handa 已提交
14 15 16 17 18 19 20 21 22 23 24 25 26 27
/* The list for "struct tomoyo_io_buffer". */
static LIST_HEAD(tomoyo_io_buffer_list);
/* Lock for protecting tomoyo_io_buffer_list. */
static DEFINE_SPINLOCK(tomoyo_io_buffer_list_lock);

/* Size of an element. */
static const u8 tomoyo_element_size[TOMOYO_MAX_POLICY] = {
	[TOMOYO_ID_GROUP] = sizeof(struct tomoyo_group),
	[TOMOYO_ID_PATH_GROUP] = sizeof(struct tomoyo_path_group),
	[TOMOYO_ID_NUMBER_GROUP] = sizeof(struct tomoyo_number_group),
	[TOMOYO_ID_AGGREGATOR] = sizeof(struct tomoyo_aggregator),
	[TOMOYO_ID_TRANSITION_CONTROL] =
	sizeof(struct tomoyo_transition_control),
	[TOMOYO_ID_MANAGER] = sizeof(struct tomoyo_manager),
28
	/* [TOMOYO_ID_CONDITION] = "struct tomoyo_condition"->size, */
T
Tetsuo Handa 已提交
29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121
	/* [TOMOYO_ID_NAME] = "struct tomoyo_name"->size, */
	/* [TOMOYO_ID_ACL] =
	   tomoyo_acl_size["struct tomoyo_acl_info"->type], */
	[TOMOYO_ID_DOMAIN] = sizeof(struct tomoyo_domain_info),
};

/* Size of a domain ACL element. */
static const u8 tomoyo_acl_size[] = {
	[TOMOYO_TYPE_PATH_ACL] = sizeof(struct tomoyo_path_acl),
	[TOMOYO_TYPE_PATH2_ACL] = sizeof(struct tomoyo_path2_acl),
	[TOMOYO_TYPE_PATH_NUMBER_ACL] = sizeof(struct tomoyo_path_number_acl),
	[TOMOYO_TYPE_MKDEV_ACL] = sizeof(struct tomoyo_mkdev_acl),
	[TOMOYO_TYPE_MOUNT_ACL] = sizeof(struct tomoyo_mount_acl),
};

/**
 * tomoyo_struct_used_by_io_buffer - Check whether the list element is used by /sys/kernel/security/tomoyo/ users or not.
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns true if @element is used by /sys/kernel/security/tomoyo/ users,
 * false otherwise.
 */
static bool tomoyo_struct_used_by_io_buffer(const struct list_head *element)
{
	struct tomoyo_io_buffer *head;
	bool in_use = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	list_for_each_entry(head, &tomoyo_io_buffer_list, list) {
		head->users++;
		spin_unlock(&tomoyo_io_buffer_list_lock);
		if (mutex_lock_interruptible(&head->io_sem)) {
			in_use = true;
			goto out;
		}
		if (head->r.domain == element || head->r.group == element ||
		    head->r.acl == element || &head->w.domain->list == element)
			in_use = true;
		mutex_unlock(&head->io_sem);
out:
		spin_lock(&tomoyo_io_buffer_list_lock);
		head->users--;
		if (in_use)
			break;
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	return in_use;
}

/**
 * tomoyo_name_used_by_io_buffer - Check whether the string is used by /sys/kernel/security/tomoyo/ users or not.
 *
 * @string: String to check.
 * @size:   Memory allocated for @string .
 *
 * Returns true if @string is used by /sys/kernel/security/tomoyo/ users,
 * false otherwise.
 */
static bool tomoyo_name_used_by_io_buffer(const char *string,
					  const size_t size)
{
	struct tomoyo_io_buffer *head;
	bool in_use = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	list_for_each_entry(head, &tomoyo_io_buffer_list, list) {
		int i;
		head->users++;
		spin_unlock(&tomoyo_io_buffer_list_lock);
		if (mutex_lock_interruptible(&head->io_sem)) {
			in_use = true;
			goto out;
		}
		for (i = 0; i < TOMOYO_MAX_IO_READ_QUEUE; i++) {
			const char *w = head->r.w[i];
			if (w < string || w > string + size)
				continue;
			in_use = true;
			break;
		}
		mutex_unlock(&head->io_sem);
out:
		spin_lock(&tomoyo_io_buffer_list_lock);
		head->users--;
		if (in_use)
			break;
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	return in_use;
}

/* Structure for garbage collection. */
T
Tetsuo Handa 已提交
122
struct tomoyo_gc {
T
Tetsuo Handa 已提交
123
	struct list_head list;
T
Tetsuo Handa 已提交
124
	enum tomoyo_policy_id type;
T
Tetsuo Handa 已提交
125
	size_t size;
126
	struct list_head *element;
T
Tetsuo Handa 已提交
127
};
T
Tetsuo Handa 已提交
128 129 130 131
/* List of entries to be deleted. */
static LIST_HEAD(tomoyo_gc_list);
/* Length of tomoyo_gc_list. */
static int tomoyo_gc_list_len;
T
Tetsuo Handa 已提交
132

T
Tetsuo Handa 已提交
133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150
/**
 * tomoyo_add_to_gc - Add an entry to to be deleted list.
 *
 * @type:    One of values in "enum tomoyo_policy_id".
 * @element: Pointer to "struct list_head".
 *
 * Returns true on success, false otherwise.
 *
 * Caller holds tomoyo_policy_lock mutex.
 *
 * Adding an entry needs kmalloc(). Thus, if we try to add thousands of
 * entries at once, it will take too long time. Thus, do not add more than 128
 * entries per a scan. But to be able to handle worst case where all entries
 * are in-use, we accept one more entry per a scan.
 *
 * If we use singly linked list using "struct list_head"->prev (which is
 * LIST_POISON2), we can avoid kmalloc().
 */
151
static bool tomoyo_add_to_gc(const int type, struct list_head *element)
T
Tetsuo Handa 已提交
152
{
T
Tetsuo Handa 已提交
153
	struct tomoyo_gc *entry = kzalloc(sizeof(*entry), GFP_ATOMIC);
T
Tetsuo Handa 已提交
154 155 156
	if (!entry)
		return false;
	entry->type = type;
T
Tetsuo Handa 已提交
157 158 159 160 161 162 163 164 165
	if (type == TOMOYO_ID_ACL)
		entry->size = tomoyo_acl_size[
			      container_of(element,
					   typeof(struct tomoyo_acl_info),
					   list)->type];
	else if (type == TOMOYO_ID_NAME)
		entry->size = strlen(container_of(element,
						  typeof(struct tomoyo_name),
						  head.list)->entry.name) + 1;
166 167 168 169
	else if (type == TOMOYO_ID_CONDITION)
		entry->size =
			container_of(element, typeof(struct tomoyo_condition),
				     head.list)->size;
T
Tetsuo Handa 已提交
170 171
	else
		entry->size = tomoyo_element_size[type];
T
Tetsuo Handa 已提交
172
	entry->element = element;
T
Tetsuo Handa 已提交
173
	list_add(&entry->list, &tomoyo_gc_list);
174
	list_del_rcu(element);
T
Tetsuo Handa 已提交
175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196
	return tomoyo_gc_list_len++ < 128;
}

/**
 * tomoyo_element_linked_by_gc - Validate next element of an entry.
 *
 * @element: Pointer to an element.
 * @size:    Size of @element in byte.
 *
 * Returns true if @element is linked by other elements in the garbage
 * collector's queue, false otherwise.
 */
static bool tomoyo_element_linked_by_gc(const u8 *element, const size_t size)
{
	struct tomoyo_gc *p;
	list_for_each_entry(p, &tomoyo_gc_list, list) {
		const u8 *ptr = (const u8 *) p->element->next;
		if (ptr < element || element + size < ptr)
			continue;
		return true;
	}
	return false;
T
Tetsuo Handa 已提交
197 198
}

T
Tetsuo Handa 已提交
199 200 201 202 203 204 205
/**
 * tomoyo_del_transition_control - Delete members in "struct tomoyo_transition_control".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
206
static void tomoyo_del_transition_control(struct list_head *element)
T
Tetsuo Handa 已提交
207
{
208
	struct tomoyo_transition_control *ptr =
209
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
210 211 212 213
	tomoyo_put_name(ptr->domainname);
	tomoyo_put_name(ptr->program);
}

T
Tetsuo Handa 已提交
214 215 216 217 218 219 220
/**
 * tomoyo_del_aggregator - Delete members in "struct tomoyo_aggregator".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
221
static void tomoyo_del_aggregator(struct list_head *element)
222
{
T
Tetsuo Handa 已提交
223
	struct tomoyo_aggregator *ptr =
224
		container_of(element, typeof(*ptr), head.list);
225 226 227 228
	tomoyo_put_name(ptr->original_name);
	tomoyo_put_name(ptr->aggregated_name);
}

T
Tetsuo Handa 已提交
229 230 231 232 233 234 235
/**
 * tomoyo_del_manager - Delete members in "struct tomoyo_manager".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
236
static void tomoyo_del_manager(struct list_head *element)
T
Tetsuo Handa 已提交
237
{
T
Tetsuo Handa 已提交
238
	struct tomoyo_manager *ptr =
239
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
240 241 242
	tomoyo_put_name(ptr->manager);
}

T
Tetsuo Handa 已提交
243 244 245 246 247 248 249
/**
 * tomoyo_del_acl - Delete members in "struct tomoyo_acl_info".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
250
static void tomoyo_del_acl(struct list_head *element)
T
Tetsuo Handa 已提交
251
{
252 253
	struct tomoyo_acl_info *acl =
		container_of(element, typeof(*acl), list);
254
	tomoyo_put_condition(acl->cond);
T
Tetsuo Handa 已提交
255
	switch (acl->type) {
T
Tetsuo Handa 已提交
256
	case TOMOYO_TYPE_PATH_ACL:
T
Tetsuo Handa 已提交
257
		{
T
Tetsuo Handa 已提交
258
			struct tomoyo_path_acl *entry
T
Tetsuo Handa 已提交
259
				= container_of(acl, typeof(*entry), head);
260
			tomoyo_put_name_union(&entry->name);
T
Tetsuo Handa 已提交
261 262
		}
		break;
T
Tetsuo Handa 已提交
263
	case TOMOYO_TYPE_PATH2_ACL:
T
Tetsuo Handa 已提交
264
		{
T
Tetsuo Handa 已提交
265
			struct tomoyo_path2_acl *entry
T
Tetsuo Handa 已提交
266
				= container_of(acl, typeof(*entry), head);
267 268
			tomoyo_put_name_union(&entry->name1);
			tomoyo_put_name_union(&entry->name2);
T
Tetsuo Handa 已提交
269 270
		}
		break;
271 272 273 274 275 276 277 278
	case TOMOYO_TYPE_PATH_NUMBER_ACL:
		{
			struct tomoyo_path_number_acl *entry
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->name);
			tomoyo_put_number_union(&entry->number);
		}
		break;
T
Tetsuo Handa 已提交
279
	case TOMOYO_TYPE_MKDEV_ACL:
280
		{
T
Tetsuo Handa 已提交
281
			struct tomoyo_mkdev_acl *entry
282 283 284 285 286 287 288
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->name);
			tomoyo_put_number_union(&entry->mode);
			tomoyo_put_number_union(&entry->major);
			tomoyo_put_number_union(&entry->minor);
		}
		break;
T
Tetsuo Handa 已提交
289 290 291 292 293 294 295 296 297 298
	case TOMOYO_TYPE_MOUNT_ACL:
		{
			struct tomoyo_mount_acl *entry
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->dev_name);
			tomoyo_put_name_union(&entry->dir_name);
			tomoyo_put_name_union(&entry->fs_type);
			tomoyo_put_number_union(&entry->flags);
		}
		break;
T
Tetsuo Handa 已提交
299 300 301
	}
}

T
Tetsuo Handa 已提交
302 303 304 305 306 307 308
/**
 * tomoyo_del_domain - Delete members in "struct tomoyo_domain_info".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns true if deleted, false otherwise.
 */
309
static bool tomoyo_del_domain(struct list_head *element)
T
Tetsuo Handa 已提交
310
{
311 312
	struct tomoyo_domain_info *domain =
		container_of(element, typeof(*domain), list);
T
Tetsuo Handa 已提交
313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339
	struct tomoyo_acl_info *acl;
	struct tomoyo_acl_info *tmp;
	/*
	 * Since we don't protect whole execve() operation using SRCU,
	 * we need to recheck domain->users at this point.
	 *
	 * (1) Reader starts SRCU section upon execve().
	 * (2) Reader traverses tomoyo_domain_list and finds this domain.
	 * (3) Writer marks this domain as deleted.
	 * (4) Garbage collector removes this domain from tomoyo_domain_list
	 *     because this domain is marked as deleted and used by nobody.
	 * (5) Reader saves reference to this domain into
	 *     "struct linux_binprm"->cred->security .
	 * (6) Reader finishes SRCU section, although execve() operation has
	 *     not finished yet.
	 * (7) Garbage collector waits for SRCU synchronization.
	 * (8) Garbage collector kfree() this domain because this domain is
	 *     used by nobody.
	 * (9) Reader finishes execve() operation and restores this domain from
	 *     "struct linux_binprm"->cred->security.
	 *
	 * By updating domain->users at (5), we can solve this race problem
	 * by rechecking domain->users at (8).
	 */
	if (atomic_read(&domain->users))
		return false;
	list_for_each_entry_safe(acl, tmp, &domain->acl_info_list, list) {
340
		tomoyo_del_acl(&acl->list);
T
Tetsuo Handa 已提交
341 342 343 344 345 346
		tomoyo_memory_free(acl);
	}
	tomoyo_put_name(domain->domainname);
	return true;
}

347 348 349 350 351 352 353 354 355 356 357 358 359
/**
 * tomoyo_del_condition - Delete members in "struct tomoyo_condition".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
void tomoyo_del_condition(struct list_head *element)
{
	struct tomoyo_condition *cond = container_of(element, typeof(*cond),
						     head.list);
	const u16 condc = cond->condc;
	const u16 numbers_count = cond->numbers_count;
360
	const u16 names_count = cond->names_count;
361 362
	const u16 argc = cond->argc;
	const u16 envc = cond->envc;
363 364 365 366 367
	unsigned int i;
	const struct tomoyo_condition_element *condp
		= (const struct tomoyo_condition_element *) (cond + 1);
	struct tomoyo_number_union *numbers_p
		= (struct tomoyo_number_union *) (condp + condc);
368 369
	struct tomoyo_name_union *names_p
		= (struct tomoyo_name_union *) (numbers_p + numbers_count);
370 371 372 373
	const struct tomoyo_argv *argv
		= (const struct tomoyo_argv *) (names_p + names_count);
	const struct tomoyo_envp *envp
		= (const struct tomoyo_envp *) (argv + argc);
374 375
	for (i = 0; i < numbers_count; i++)
		tomoyo_put_number_union(numbers_p++);
376 377
	for (i = 0; i < names_count; i++)
		tomoyo_put_name_union(names_p++);
378 379 380 381 382 383
	for (i = 0; i < argc; argv++, i++)
		tomoyo_put_name(argv->value);
	for (i = 0; i < envc; envp++, i++) {
		tomoyo_put_name(envp->name);
		tomoyo_put_name(envp->value);
	}
384
}
T
Tetsuo Handa 已提交
385

T
Tetsuo Handa 已提交
386 387 388 389 390 391 392
/**
 * tomoyo_del_name - Delete members in "struct tomoyo_name".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
393
static void tomoyo_del_name(struct list_head *element)
T
Tetsuo Handa 已提交
394
{
T
Tetsuo Handa 已提交
395
	const struct tomoyo_name *ptr =
T
Tetsuo Handa 已提交
396
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
397 398
}

T
Tetsuo Handa 已提交
399 400 401 402 403 404 405
/**
 * tomoyo_del_path_group - Delete members in "struct tomoyo_path_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
406
static void tomoyo_del_path_group(struct list_head *element)
407
{
408
	struct tomoyo_path_group *member =
409
		container_of(element, typeof(*member), head.list);
410 411 412
	tomoyo_put_name(member->member_name);
}

T
Tetsuo Handa 已提交
413 414 415 416 417 418 419
/**
 * tomoyo_del_group - Delete "struct tomoyo_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
420
static void tomoyo_del_group(struct list_head *element)
421
{
422
	struct tomoyo_group *group =
T
Tetsuo Handa 已提交
423
		container_of(element, typeof(*group), head.list);
424 425 426
	tomoyo_put_name(group->group_name);
}

T
Tetsuo Handa 已提交
427 428 429 430 431 432 433
/**
 * tomoyo_del_number_group - Delete members in "struct tomoyo_number_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
434
static void tomoyo_del_number_group(struct list_head *element)
435
{
436 437
	struct tomoyo_number_group *member =
		container_of(element, typeof(*member), head.list);
438 439
}

T
Tetsuo Handa 已提交
440 441 442 443 444 445 446 447 448 449
/**
 * tomoyo_collect_member - Delete elements with "struct tomoyo_acl_head".
 *
 * @id:          One of values in "enum tomoyo_policy_id".
 * @member_list: Pointer to "struct list_head".
 *
 * Returns true if some elements are deleted, false otherwise.
 */
static bool tomoyo_collect_member(const enum tomoyo_policy_id id,
				  struct list_head *member_list)
450 451 452 453 454 455 456 457 458 459 460
{
	struct tomoyo_acl_head *member;
	list_for_each_entry(member, member_list, list) {
		if (!member->is_deleted)
			continue;
		if (!tomoyo_add_to_gc(id, &member->list))
			return false;
	}
        return true;
}

T
Tetsuo Handa 已提交
461 462 463 464 465 466 467 468
/**
 * tomoyo_collect_acl - Delete elements in "struct tomoyo_domain_info".
 *
 * @list: Pointer to "struct list_head".
 *
 * Returns true if some elements are deleted, false otherwise.
 */
static bool tomoyo_collect_acl(struct list_head *list)
469 470
{
	struct tomoyo_acl_info *acl;
T
Tetsuo Handa 已提交
471
	list_for_each_entry(acl, list, list) {
472 473 474 475 476 477 478 479
		if (!acl->is_deleted)
			continue;
		if (!tomoyo_add_to_gc(TOMOYO_ID_ACL, &acl->list))
			return false;
	}
	return true;
}

T
Tetsuo Handa 已提交
480 481 482 483 484
/**
 * tomoyo_collect_entry - Scan lists for deleted elements.
 *
 * Returns nothing.
 */
T
Tetsuo Handa 已提交
485 486
static void tomoyo_collect_entry(void)
{
487
	int i;
488 489 490
	enum tomoyo_policy_id id;
	struct tomoyo_policy_namespace *ns;
	int idx;
491 492
	if (mutex_lock_interruptible(&tomoyo_policy_lock))
		return;
493
	idx = tomoyo_read_lock();
T
Tetsuo Handa 已提交
494 495 496
	{
		struct tomoyo_domain_info *domain;
		list_for_each_entry_rcu(domain, &tomoyo_domain_list, list) {
T
Tetsuo Handa 已提交
497
			if (!tomoyo_collect_acl(&domain->acl_info_list))
498
				goto unlock;
T
Tetsuo Handa 已提交
499 500 501 502 503 504 505
			if (!domain->is_deleted || atomic_read(&domain->users))
				continue;
			/*
			 * Nobody is referring this domain. But somebody may
			 * refer this domain after successful execve().
			 * We recheck domain->users after SRCU synchronization.
			 */
506
			if (!tomoyo_add_to_gc(TOMOYO_ID_DOMAIN, &domain->list))
507
				goto unlock;
T
Tetsuo Handa 已提交
508 509
		}
	}
510 511 512
	list_for_each_entry_rcu(ns, &tomoyo_namespace_list, namespace_list) {
		for (id = 0; id < TOMOYO_MAX_POLICY; id++)
			if (!tomoyo_collect_member(id, &ns->policy_list[id]))
513
				goto unlock;
514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538
		for (i = 0; i < TOMOYO_MAX_ACL_GROUPS; i++)
			if (!tomoyo_collect_acl(&ns->acl_group[i]))
				goto unlock;
		for (i = 0; i < TOMOYO_MAX_GROUP; i++) {
			struct list_head *list = &ns->group_list[i];
			struct tomoyo_group *group;
			switch (i) {
			case 0:
				id = TOMOYO_ID_PATH_GROUP;
				break;
			default:
				id = TOMOYO_ID_NUMBER_GROUP;
				break;
			}
			list_for_each_entry(group, list, head.list) {
				if (!tomoyo_collect_member
				    (id, &group->member_list))
					goto unlock;
				if (!list_empty(&group->member_list) ||
				    atomic_read(&group->head.users))
					continue;
				if (!tomoyo_add_to_gc(TOMOYO_ID_GROUP,
						      &group->head.list))
					goto unlock;
			}
T
Tetsuo Handa 已提交
539 540
		}
	}
541 542 543 544
	id = TOMOYO_ID_CONDITION;
	for (i = 0; i < TOMOYO_MAX_HASH + 1; i++) {
		struct list_head *list = !i ?
			&tomoyo_condition_list : &tomoyo_name_list[i - 1];
545 546 547
		struct tomoyo_shared_acl_head *ptr;
		list_for_each_entry(ptr, list, list) {
			if (atomic_read(&ptr->users))
548
				continue;
549
			if (!tomoyo_add_to_gc(id, &ptr->list))
550
				goto unlock;
551
		}
552
		id = TOMOYO_ID_NAME;
553
	}
554 555
unlock:
	tomoyo_read_unlock(idx);
556
	mutex_unlock(&tomoyo_policy_lock);
T
Tetsuo Handa 已提交
557 558
}

T
Tetsuo Handa 已提交
559 560 561 562 563 564
/**
 * tomoyo_kfree_entry - Delete entries in tomoyo_gc_list.
 *
 * Returns true if some entries were kfree()d, false otherwise.
 */
static bool tomoyo_kfree_entry(void)
T
Tetsuo Handa 已提交
565
{
T
Tetsuo Handa 已提交
566 567
	struct tomoyo_gc *p;
	struct tomoyo_gc *tmp;
T
Tetsuo Handa 已提交
568
	bool result = false;
T
Tetsuo Handa 已提交
569

T
Tetsuo Handa 已提交
570
	list_for_each_entry_safe(p, tmp, &tomoyo_gc_list, list) {
571
		struct list_head *element = p->element;
T
Tetsuo Handa 已提交
572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596

		/*
		 * list_del_rcu() in tomoyo_add_to_gc() guarantees that the
		 * list element became no longer reachable from the list which
		 * the element was originally on (e.g. tomoyo_domain_list).
		 * Also, synchronize_srcu() in tomoyo_gc_thread() guarantees
		 * that the list element became no longer referenced by syscall
		 * users.
		 *
		 * However, there are three users which may still be using the
		 * list element. We need to defer until all of these users
		 * forget the list element.
		 *
		 * Firstly, defer until "struct tomoyo_io_buffer"->r.{domain,
		 * group,acl} and "struct tomoyo_io_buffer"->w.domain forget
		 * the list element.
		 */
		if (tomoyo_struct_used_by_io_buffer(element))
			continue;
		/*
		 * Secondly, defer until all other elements in the
		 * tomoyo_gc_list list forget the list element.
		 */
		if (tomoyo_element_linked_by_gc((const u8 *) element, p->size))
			continue;
T
Tetsuo Handa 已提交
597
		switch (p->type) {
598 599
		case TOMOYO_ID_TRANSITION_CONTROL:
			tomoyo_del_transition_control(element);
T
Tetsuo Handa 已提交
600
			break;
601
		case TOMOYO_ID_AGGREGATOR:
602
			tomoyo_del_aggregator(element);
603
			break;
T
Tetsuo Handa 已提交
604
		case TOMOYO_ID_MANAGER:
605
			tomoyo_del_manager(element);
T
Tetsuo Handa 已提交
606
			break;
607 608 609
		case TOMOYO_ID_CONDITION:
			tomoyo_del_condition(element);
			break;
T
Tetsuo Handa 已提交
610
		case TOMOYO_ID_NAME:
T
Tetsuo Handa 已提交
611 612 613 614 615 616 617 618
			/*
			 * Thirdly, defer until all "struct tomoyo_io_buffer"
			 * ->r.w[] forget the list element.
			 */
			if (tomoyo_name_used_by_io_buffer(
			    container_of(element, typeof(struct tomoyo_name),
					 head.list)->entry.name, p->size))
				continue;
619
			tomoyo_del_name(element);
T
Tetsuo Handa 已提交
620 621
			break;
		case TOMOYO_ID_ACL:
622
			tomoyo_del_acl(element);
T
Tetsuo Handa 已提交
623 624
			break;
		case TOMOYO_ID_DOMAIN:
625
			if (!tomoyo_del_domain(element))
T
Tetsuo Handa 已提交
626 627
				continue;
			break;
628
		case TOMOYO_ID_PATH_GROUP:
629
			tomoyo_del_path_group(element);
630
			break;
631 632
		case TOMOYO_ID_GROUP:
			tomoyo_del_group(element);
633 634
			break;
		case TOMOYO_ID_NUMBER_GROUP:
635
			tomoyo_del_number_group(element);
T
Tetsuo Handa 已提交
636
			break;
T
Tetsuo Handa 已提交
637 638
		case TOMOYO_MAX_POLICY:
			break;
T
Tetsuo Handa 已提交
639
		}
640
		tomoyo_memory_free(element);
T
Tetsuo Handa 已提交
641 642
		list_del(&p->list);
		kfree(p);
T
Tetsuo Handa 已提交
643 644
		tomoyo_gc_list_len--;
		result = true;
T
Tetsuo Handa 已提交
645
	}
T
Tetsuo Handa 已提交
646
	return result;
T
Tetsuo Handa 已提交
647 648
}

T
Tetsuo Handa 已提交
649 650 651 652 653 654 655 656 657 658 659
/**
 * tomoyo_gc_thread - Garbage collector thread function.
 *
 * @unused: Unused.
 *
 * In case OOM-killer choose this thread for termination, we create this thread
 * as a short live thread whenever /sys/kernel/security/tomoyo/ interface was
 * close()d.
 *
 * Returns 0.
 */
T
Tetsuo Handa 已提交
660 661
static int tomoyo_gc_thread(void *unused)
{
T
Tetsuo Handa 已提交
662 663 664 665
	/* Garbage collector thread is exclusive. */
	static DEFINE_MUTEX(tomoyo_gc_mutex);
	if (!mutex_trylock(&tomoyo_gc_mutex))
		goto out;
T
Tetsuo Handa 已提交
666
	daemonize("GC for TOMOYO");
T
Tetsuo Handa 已提交
667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685
	do {
		tomoyo_collect_entry();
		if (list_empty(&tomoyo_gc_list))
			break;
		synchronize_srcu(&tomoyo_ss);
	} while (tomoyo_kfree_entry());
	{
		struct tomoyo_io_buffer *head;
		struct tomoyo_io_buffer *tmp;

		spin_lock(&tomoyo_io_buffer_list_lock);
		list_for_each_entry_safe(head, tmp, &tomoyo_io_buffer_list,
					 list) {
			if (head->users)
				continue;
			list_del(&head->list);
			kfree(head->read_buf);
			kfree(head->write_buf);
			kfree(head);
T
Tetsuo Handa 已提交
686
		}
T
Tetsuo Handa 已提交
687
		spin_unlock(&tomoyo_io_buffer_list_lock);
T
Tetsuo Handa 已提交
688
	}
T
Tetsuo Handa 已提交
689 690 691 692
	mutex_unlock(&tomoyo_gc_mutex);
out:
	/* This acts as do_exit(0). */
	return 0;
T
Tetsuo Handa 已提交
693 694
}

T
Tetsuo Handa 已提交
695 696 697 698 699 700 701 702 703
/**
 * tomoyo_notify_gc - Register/unregister /sys/kernel/security/tomoyo/ users.
 *
 * @head:        Pointer to "struct tomoyo_io_buffer".
 * @is_register: True if register, false if unregister.
 *
 * Returns nothing.
 */
void tomoyo_notify_gc(struct tomoyo_io_buffer *head, const bool is_register)
T
Tetsuo Handa 已提交
704
{
T
Tetsuo Handa 已提交
705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727
	bool is_write = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	if (is_register) {
		head->users = 1;
		list_add(&head->list, &tomoyo_io_buffer_list);
	} else {
		is_write = head->write_buf != NULL;
		if (!--head->users) {
			list_del(&head->list);
			kfree(head->read_buf);
			kfree(head->write_buf);
			kfree(head);
		}
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	if (is_write) {
		struct task_struct *task = kthread_create(tomoyo_gc_thread,
							  NULL,
							  "GC for TOMOYO");
		if (!IS_ERR(task))
			wake_up_process(task);
	}
T
Tetsuo Handa 已提交
728
}