gc.c 19.1 KB
Newer Older
T
Tetsuo Handa 已提交
1 2 3 4 5 6 7 8 9 10 11
/*
 * security/tomoyo/gc.c
 *
 * Implementation of the Domain-Based Mandatory Access Control.
 *
 * Copyright (C) 2005-2010  NTT DATA CORPORATION
 *
 */

#include "common.h"
#include <linux/kthread.h>
12
#include <linux/slab.h>
T
Tetsuo Handa 已提交
13

T
Tetsuo Handa 已提交
14 15 16 17 18 19 20 21 22 23 24 25 26 27
/* The list for "struct tomoyo_io_buffer". */
static LIST_HEAD(tomoyo_io_buffer_list);
/* Lock for protecting tomoyo_io_buffer_list. */
static DEFINE_SPINLOCK(tomoyo_io_buffer_list_lock);

/* Size of an element. */
static const u8 tomoyo_element_size[TOMOYO_MAX_POLICY] = {
	[TOMOYO_ID_GROUP] = sizeof(struct tomoyo_group),
	[TOMOYO_ID_PATH_GROUP] = sizeof(struct tomoyo_path_group),
	[TOMOYO_ID_NUMBER_GROUP] = sizeof(struct tomoyo_number_group),
	[TOMOYO_ID_AGGREGATOR] = sizeof(struct tomoyo_aggregator),
	[TOMOYO_ID_TRANSITION_CONTROL] =
	sizeof(struct tomoyo_transition_control),
	[TOMOYO_ID_MANAGER] = sizeof(struct tomoyo_manager),
28
	/* [TOMOYO_ID_CONDITION] = "struct tomoyo_condition"->size, */
T
Tetsuo Handa 已提交
29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121
	/* [TOMOYO_ID_NAME] = "struct tomoyo_name"->size, */
	/* [TOMOYO_ID_ACL] =
	   tomoyo_acl_size["struct tomoyo_acl_info"->type], */
	[TOMOYO_ID_DOMAIN] = sizeof(struct tomoyo_domain_info),
};

/* Size of a domain ACL element. */
static const u8 tomoyo_acl_size[] = {
	[TOMOYO_TYPE_PATH_ACL] = sizeof(struct tomoyo_path_acl),
	[TOMOYO_TYPE_PATH2_ACL] = sizeof(struct tomoyo_path2_acl),
	[TOMOYO_TYPE_PATH_NUMBER_ACL] = sizeof(struct tomoyo_path_number_acl),
	[TOMOYO_TYPE_MKDEV_ACL] = sizeof(struct tomoyo_mkdev_acl),
	[TOMOYO_TYPE_MOUNT_ACL] = sizeof(struct tomoyo_mount_acl),
};

/**
 * tomoyo_struct_used_by_io_buffer - Check whether the list element is used by /sys/kernel/security/tomoyo/ users or not.
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns true if @element is used by /sys/kernel/security/tomoyo/ users,
 * false otherwise.
 */
static bool tomoyo_struct_used_by_io_buffer(const struct list_head *element)
{
	struct tomoyo_io_buffer *head;
	bool in_use = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	list_for_each_entry(head, &tomoyo_io_buffer_list, list) {
		head->users++;
		spin_unlock(&tomoyo_io_buffer_list_lock);
		if (mutex_lock_interruptible(&head->io_sem)) {
			in_use = true;
			goto out;
		}
		if (head->r.domain == element || head->r.group == element ||
		    head->r.acl == element || &head->w.domain->list == element)
			in_use = true;
		mutex_unlock(&head->io_sem);
out:
		spin_lock(&tomoyo_io_buffer_list_lock);
		head->users--;
		if (in_use)
			break;
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	return in_use;
}

/**
 * tomoyo_name_used_by_io_buffer - Check whether the string is used by /sys/kernel/security/tomoyo/ users or not.
 *
 * @string: String to check.
 * @size:   Memory allocated for @string .
 *
 * Returns true if @string is used by /sys/kernel/security/tomoyo/ users,
 * false otherwise.
 */
static bool tomoyo_name_used_by_io_buffer(const char *string,
					  const size_t size)
{
	struct tomoyo_io_buffer *head;
	bool in_use = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	list_for_each_entry(head, &tomoyo_io_buffer_list, list) {
		int i;
		head->users++;
		spin_unlock(&tomoyo_io_buffer_list_lock);
		if (mutex_lock_interruptible(&head->io_sem)) {
			in_use = true;
			goto out;
		}
		for (i = 0; i < TOMOYO_MAX_IO_READ_QUEUE; i++) {
			const char *w = head->r.w[i];
			if (w < string || w > string + size)
				continue;
			in_use = true;
			break;
		}
		mutex_unlock(&head->io_sem);
out:
		spin_lock(&tomoyo_io_buffer_list_lock);
		head->users--;
		if (in_use)
			break;
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	return in_use;
}

/* Structure for garbage collection. */
T
Tetsuo Handa 已提交
122
struct tomoyo_gc {
T
Tetsuo Handa 已提交
123
	struct list_head list;
T
Tetsuo Handa 已提交
124
	enum tomoyo_policy_id type;
T
Tetsuo Handa 已提交
125
	size_t size;
126
	struct list_head *element;
T
Tetsuo Handa 已提交
127
};
T
Tetsuo Handa 已提交
128 129 130 131
/* List of entries to be deleted. */
static LIST_HEAD(tomoyo_gc_list);
/* Length of tomoyo_gc_list. */
static int tomoyo_gc_list_len;
T
Tetsuo Handa 已提交
132

T
Tetsuo Handa 已提交
133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150
/**
 * tomoyo_add_to_gc - Add an entry to to be deleted list.
 *
 * @type:    One of values in "enum tomoyo_policy_id".
 * @element: Pointer to "struct list_head".
 *
 * Returns true on success, false otherwise.
 *
 * Caller holds tomoyo_policy_lock mutex.
 *
 * Adding an entry needs kmalloc(). Thus, if we try to add thousands of
 * entries at once, it will take too long time. Thus, do not add more than 128
 * entries per a scan. But to be able to handle worst case where all entries
 * are in-use, we accept one more entry per a scan.
 *
 * If we use singly linked list using "struct list_head"->prev (which is
 * LIST_POISON2), we can avoid kmalloc().
 */
151
static bool tomoyo_add_to_gc(const int type, struct list_head *element)
T
Tetsuo Handa 已提交
152
{
T
Tetsuo Handa 已提交
153
	struct tomoyo_gc *entry = kzalloc(sizeof(*entry), GFP_ATOMIC);
T
Tetsuo Handa 已提交
154 155 156
	if (!entry)
		return false;
	entry->type = type;
T
Tetsuo Handa 已提交
157 158 159 160 161 162 163 164 165
	if (type == TOMOYO_ID_ACL)
		entry->size = tomoyo_acl_size[
			      container_of(element,
					   typeof(struct tomoyo_acl_info),
					   list)->type];
	else if (type == TOMOYO_ID_NAME)
		entry->size = strlen(container_of(element,
						  typeof(struct tomoyo_name),
						  head.list)->entry.name) + 1;
166 167 168 169
	else if (type == TOMOYO_ID_CONDITION)
		entry->size =
			container_of(element, typeof(struct tomoyo_condition),
				     head.list)->size;
T
Tetsuo Handa 已提交
170 171
	else
		entry->size = tomoyo_element_size[type];
T
Tetsuo Handa 已提交
172
	entry->element = element;
T
Tetsuo Handa 已提交
173
	list_add(&entry->list, &tomoyo_gc_list);
174
	list_del_rcu(element);
T
Tetsuo Handa 已提交
175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196
	return tomoyo_gc_list_len++ < 128;
}

/**
 * tomoyo_element_linked_by_gc - Validate next element of an entry.
 *
 * @element: Pointer to an element.
 * @size:    Size of @element in byte.
 *
 * Returns true if @element is linked by other elements in the garbage
 * collector's queue, false otherwise.
 */
static bool tomoyo_element_linked_by_gc(const u8 *element, const size_t size)
{
	struct tomoyo_gc *p;
	list_for_each_entry(p, &tomoyo_gc_list, list) {
		const u8 *ptr = (const u8 *) p->element->next;
		if (ptr < element || element + size < ptr)
			continue;
		return true;
	}
	return false;
T
Tetsuo Handa 已提交
197 198
}

T
Tetsuo Handa 已提交
199 200 201 202 203 204 205
/**
 * tomoyo_del_transition_control - Delete members in "struct tomoyo_transition_control".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
206
static void tomoyo_del_transition_control(struct list_head *element)
T
Tetsuo Handa 已提交
207
{
208
	struct tomoyo_transition_control *ptr =
209
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
210 211 212 213
	tomoyo_put_name(ptr->domainname);
	tomoyo_put_name(ptr->program);
}

T
Tetsuo Handa 已提交
214 215 216 217 218 219 220
/**
 * tomoyo_del_aggregator - Delete members in "struct tomoyo_aggregator".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
221
static void tomoyo_del_aggregator(struct list_head *element)
222
{
T
Tetsuo Handa 已提交
223
	struct tomoyo_aggregator *ptr =
224
		container_of(element, typeof(*ptr), head.list);
225 226 227 228
	tomoyo_put_name(ptr->original_name);
	tomoyo_put_name(ptr->aggregated_name);
}

T
Tetsuo Handa 已提交
229 230 231 232 233 234 235
/**
 * tomoyo_del_manager - Delete members in "struct tomoyo_manager".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
236
static void tomoyo_del_manager(struct list_head *element)
T
Tetsuo Handa 已提交
237
{
T
Tetsuo Handa 已提交
238
	struct tomoyo_manager *ptr =
239
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
240 241 242
	tomoyo_put_name(ptr->manager);
}

T
Tetsuo Handa 已提交
243 244 245 246 247 248 249
/**
 * tomoyo_del_acl - Delete members in "struct tomoyo_acl_info".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
250
static void tomoyo_del_acl(struct list_head *element)
T
Tetsuo Handa 已提交
251
{
252 253
	struct tomoyo_acl_info *acl =
		container_of(element, typeof(*acl), list);
254
	tomoyo_put_condition(acl->cond);
T
Tetsuo Handa 已提交
255
	switch (acl->type) {
T
Tetsuo Handa 已提交
256
	case TOMOYO_TYPE_PATH_ACL:
T
Tetsuo Handa 已提交
257
		{
T
Tetsuo Handa 已提交
258
			struct tomoyo_path_acl *entry
T
Tetsuo Handa 已提交
259
				= container_of(acl, typeof(*entry), head);
260
			tomoyo_put_name_union(&entry->name);
T
Tetsuo Handa 已提交
261 262
		}
		break;
T
Tetsuo Handa 已提交
263
	case TOMOYO_TYPE_PATH2_ACL:
T
Tetsuo Handa 已提交
264
		{
T
Tetsuo Handa 已提交
265
			struct tomoyo_path2_acl *entry
T
Tetsuo Handa 已提交
266
				= container_of(acl, typeof(*entry), head);
267 268
			tomoyo_put_name_union(&entry->name1);
			tomoyo_put_name_union(&entry->name2);
T
Tetsuo Handa 已提交
269 270
		}
		break;
271 272 273 274 275 276 277 278
	case TOMOYO_TYPE_PATH_NUMBER_ACL:
		{
			struct tomoyo_path_number_acl *entry
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->name);
			tomoyo_put_number_union(&entry->number);
		}
		break;
T
Tetsuo Handa 已提交
279
	case TOMOYO_TYPE_MKDEV_ACL:
280
		{
T
Tetsuo Handa 已提交
281
			struct tomoyo_mkdev_acl *entry
282 283 284 285 286 287 288
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->name);
			tomoyo_put_number_union(&entry->mode);
			tomoyo_put_number_union(&entry->major);
			tomoyo_put_number_union(&entry->minor);
		}
		break;
T
Tetsuo Handa 已提交
289 290 291 292 293 294 295 296 297 298
	case TOMOYO_TYPE_MOUNT_ACL:
		{
			struct tomoyo_mount_acl *entry
				= container_of(acl, typeof(*entry), head);
			tomoyo_put_name_union(&entry->dev_name);
			tomoyo_put_name_union(&entry->dir_name);
			tomoyo_put_name_union(&entry->fs_type);
			tomoyo_put_number_union(&entry->flags);
		}
		break;
T
Tetsuo Handa 已提交
299 300 301
	}
}

T
Tetsuo Handa 已提交
302 303 304 305 306 307 308
/**
 * tomoyo_del_domain - Delete members in "struct tomoyo_domain_info".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns true if deleted, false otherwise.
 */
309
static bool tomoyo_del_domain(struct list_head *element)
T
Tetsuo Handa 已提交
310
{
311 312
	struct tomoyo_domain_info *domain =
		container_of(element, typeof(*domain), list);
T
Tetsuo Handa 已提交
313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339
	struct tomoyo_acl_info *acl;
	struct tomoyo_acl_info *tmp;
	/*
	 * Since we don't protect whole execve() operation using SRCU,
	 * we need to recheck domain->users at this point.
	 *
	 * (1) Reader starts SRCU section upon execve().
	 * (2) Reader traverses tomoyo_domain_list and finds this domain.
	 * (3) Writer marks this domain as deleted.
	 * (4) Garbage collector removes this domain from tomoyo_domain_list
	 *     because this domain is marked as deleted and used by nobody.
	 * (5) Reader saves reference to this domain into
	 *     "struct linux_binprm"->cred->security .
	 * (6) Reader finishes SRCU section, although execve() operation has
	 *     not finished yet.
	 * (7) Garbage collector waits for SRCU synchronization.
	 * (8) Garbage collector kfree() this domain because this domain is
	 *     used by nobody.
	 * (9) Reader finishes execve() operation and restores this domain from
	 *     "struct linux_binprm"->cred->security.
	 *
	 * By updating domain->users at (5), we can solve this race problem
	 * by rechecking domain->users at (8).
	 */
	if (atomic_read(&domain->users))
		return false;
	list_for_each_entry_safe(acl, tmp, &domain->acl_info_list, list) {
340
		tomoyo_del_acl(&acl->list);
T
Tetsuo Handa 已提交
341 342 343 344 345 346
		tomoyo_memory_free(acl);
	}
	tomoyo_put_name(domain->domainname);
	return true;
}

347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367
/**
 * tomoyo_del_condition - Delete members in "struct tomoyo_condition".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
void tomoyo_del_condition(struct list_head *element)
{
	struct tomoyo_condition *cond = container_of(element, typeof(*cond),
						     head.list);
	const u16 condc = cond->condc;
	const u16 numbers_count = cond->numbers_count;
	unsigned int i;
	const struct tomoyo_condition_element *condp
		= (const struct tomoyo_condition_element *) (cond + 1);
	struct tomoyo_number_union *numbers_p
		= (struct tomoyo_number_union *) (condp + condc);
	for (i = 0; i < numbers_count; i++)
		tomoyo_put_number_union(numbers_p++);
}
T
Tetsuo Handa 已提交
368

T
Tetsuo Handa 已提交
369 370 371 372 373 374 375
/**
 * tomoyo_del_name - Delete members in "struct tomoyo_name".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
376
static void tomoyo_del_name(struct list_head *element)
T
Tetsuo Handa 已提交
377
{
T
Tetsuo Handa 已提交
378
	const struct tomoyo_name *ptr =
T
Tetsuo Handa 已提交
379
		container_of(element, typeof(*ptr), head.list);
T
Tetsuo Handa 已提交
380 381
}

T
Tetsuo Handa 已提交
382 383 384 385 386 387 388
/**
 * tomoyo_del_path_group - Delete members in "struct tomoyo_path_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
389
static void tomoyo_del_path_group(struct list_head *element)
390
{
391
	struct tomoyo_path_group *member =
392
		container_of(element, typeof(*member), head.list);
393 394 395
	tomoyo_put_name(member->member_name);
}

T
Tetsuo Handa 已提交
396 397 398 399 400 401 402
/**
 * tomoyo_del_group - Delete "struct tomoyo_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
403
static void tomoyo_del_group(struct list_head *element)
404
{
405
	struct tomoyo_group *group =
T
Tetsuo Handa 已提交
406
		container_of(element, typeof(*group), head.list);
407 408 409
	tomoyo_put_name(group->group_name);
}

T
Tetsuo Handa 已提交
410 411 412 413 414 415 416
/**
 * tomoyo_del_number_group - Delete members in "struct tomoyo_number_group".
 *
 * @element: Pointer to "struct list_head".
 *
 * Returns nothing.
 */
417
static void tomoyo_del_number_group(struct list_head *element)
418
{
419 420
	struct tomoyo_number_group *member =
		container_of(element, typeof(*member), head.list);
421 422
}

T
Tetsuo Handa 已提交
423 424 425 426 427 428 429 430 431 432
/**
 * tomoyo_collect_member - Delete elements with "struct tomoyo_acl_head".
 *
 * @id:          One of values in "enum tomoyo_policy_id".
 * @member_list: Pointer to "struct list_head".
 *
 * Returns true if some elements are deleted, false otherwise.
 */
static bool tomoyo_collect_member(const enum tomoyo_policy_id id,
				  struct list_head *member_list)
433 434 435 436 437 438 439 440 441 442 443
{
	struct tomoyo_acl_head *member;
	list_for_each_entry(member, member_list, list) {
		if (!member->is_deleted)
			continue;
		if (!tomoyo_add_to_gc(id, &member->list))
			return false;
	}
        return true;
}

T
Tetsuo Handa 已提交
444 445 446 447 448 449 450 451
/**
 * tomoyo_collect_acl - Delete elements in "struct tomoyo_domain_info".
 *
 * @list: Pointer to "struct list_head".
 *
 * Returns true if some elements are deleted, false otherwise.
 */
static bool tomoyo_collect_acl(struct list_head *list)
452 453
{
	struct tomoyo_acl_info *acl;
T
Tetsuo Handa 已提交
454
	list_for_each_entry(acl, list, list) {
455 456 457 458 459 460 461 462
		if (!acl->is_deleted)
			continue;
		if (!tomoyo_add_to_gc(TOMOYO_ID_ACL, &acl->list))
			return false;
	}
	return true;
}

T
Tetsuo Handa 已提交
463 464 465 466 467
/**
 * tomoyo_collect_entry - Scan lists for deleted elements.
 *
 * Returns nothing.
 */
T
Tetsuo Handa 已提交
468 469
static void tomoyo_collect_entry(void)
{
470
	int i;
471 472 473
	enum tomoyo_policy_id id;
	struct tomoyo_policy_namespace *ns;
	int idx;
474 475
	if (mutex_lock_interruptible(&tomoyo_policy_lock))
		return;
476
	idx = tomoyo_read_lock();
T
Tetsuo Handa 已提交
477 478 479
	{
		struct tomoyo_domain_info *domain;
		list_for_each_entry_rcu(domain, &tomoyo_domain_list, list) {
T
Tetsuo Handa 已提交
480
			if (!tomoyo_collect_acl(&domain->acl_info_list))
481
				goto unlock;
T
Tetsuo Handa 已提交
482 483 484 485 486 487 488
			if (!domain->is_deleted || atomic_read(&domain->users))
				continue;
			/*
			 * Nobody is referring this domain. But somebody may
			 * refer this domain after successful execve().
			 * We recheck domain->users after SRCU synchronization.
			 */
489
			if (!tomoyo_add_to_gc(TOMOYO_ID_DOMAIN, &domain->list))
490
				goto unlock;
T
Tetsuo Handa 已提交
491 492
		}
	}
493 494 495
	list_for_each_entry_rcu(ns, &tomoyo_namespace_list, namespace_list) {
		for (id = 0; id < TOMOYO_MAX_POLICY; id++)
			if (!tomoyo_collect_member(id, &ns->policy_list[id]))
496
				goto unlock;
497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521
		for (i = 0; i < TOMOYO_MAX_ACL_GROUPS; i++)
			if (!tomoyo_collect_acl(&ns->acl_group[i]))
				goto unlock;
		for (i = 0; i < TOMOYO_MAX_GROUP; i++) {
			struct list_head *list = &ns->group_list[i];
			struct tomoyo_group *group;
			switch (i) {
			case 0:
				id = TOMOYO_ID_PATH_GROUP;
				break;
			default:
				id = TOMOYO_ID_NUMBER_GROUP;
				break;
			}
			list_for_each_entry(group, list, head.list) {
				if (!tomoyo_collect_member
				    (id, &group->member_list))
					goto unlock;
				if (!list_empty(&group->member_list) ||
				    atomic_read(&group->head.users))
					continue;
				if (!tomoyo_add_to_gc(TOMOYO_ID_GROUP,
						      &group->head.list))
					goto unlock;
			}
T
Tetsuo Handa 已提交
522 523
		}
	}
524 525 526 527
	id = TOMOYO_ID_CONDITION;
	for (i = 0; i < TOMOYO_MAX_HASH + 1; i++) {
		struct list_head *list = !i ?
			&tomoyo_condition_list : &tomoyo_name_list[i - 1];
528 529 530
		struct tomoyo_shared_acl_head *ptr;
		list_for_each_entry(ptr, list, list) {
			if (atomic_read(&ptr->users))
531
				continue;
532
			if (!tomoyo_add_to_gc(id, &ptr->list))
533
				goto unlock;
534
		}
535
		id = TOMOYO_ID_NAME;
536
	}
537 538
unlock:
	tomoyo_read_unlock(idx);
539
	mutex_unlock(&tomoyo_policy_lock);
T
Tetsuo Handa 已提交
540 541
}

T
Tetsuo Handa 已提交
542 543 544 545 546 547
/**
 * tomoyo_kfree_entry - Delete entries in tomoyo_gc_list.
 *
 * Returns true if some entries were kfree()d, false otherwise.
 */
static bool tomoyo_kfree_entry(void)
T
Tetsuo Handa 已提交
548
{
T
Tetsuo Handa 已提交
549 550
	struct tomoyo_gc *p;
	struct tomoyo_gc *tmp;
T
Tetsuo Handa 已提交
551
	bool result = false;
T
Tetsuo Handa 已提交
552

T
Tetsuo Handa 已提交
553
	list_for_each_entry_safe(p, tmp, &tomoyo_gc_list, list) {
554
		struct list_head *element = p->element;
T
Tetsuo Handa 已提交
555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579

		/*
		 * list_del_rcu() in tomoyo_add_to_gc() guarantees that the
		 * list element became no longer reachable from the list which
		 * the element was originally on (e.g. tomoyo_domain_list).
		 * Also, synchronize_srcu() in tomoyo_gc_thread() guarantees
		 * that the list element became no longer referenced by syscall
		 * users.
		 *
		 * However, there are three users which may still be using the
		 * list element. We need to defer until all of these users
		 * forget the list element.
		 *
		 * Firstly, defer until "struct tomoyo_io_buffer"->r.{domain,
		 * group,acl} and "struct tomoyo_io_buffer"->w.domain forget
		 * the list element.
		 */
		if (tomoyo_struct_used_by_io_buffer(element))
			continue;
		/*
		 * Secondly, defer until all other elements in the
		 * tomoyo_gc_list list forget the list element.
		 */
		if (tomoyo_element_linked_by_gc((const u8 *) element, p->size))
			continue;
T
Tetsuo Handa 已提交
580
		switch (p->type) {
581 582
		case TOMOYO_ID_TRANSITION_CONTROL:
			tomoyo_del_transition_control(element);
T
Tetsuo Handa 已提交
583
			break;
584
		case TOMOYO_ID_AGGREGATOR:
585
			tomoyo_del_aggregator(element);
586
			break;
T
Tetsuo Handa 已提交
587
		case TOMOYO_ID_MANAGER:
588
			tomoyo_del_manager(element);
T
Tetsuo Handa 已提交
589
			break;
590 591 592
		case TOMOYO_ID_CONDITION:
			tomoyo_del_condition(element);
			break;
T
Tetsuo Handa 已提交
593
		case TOMOYO_ID_NAME:
T
Tetsuo Handa 已提交
594 595 596 597 598 599 600 601
			/*
			 * Thirdly, defer until all "struct tomoyo_io_buffer"
			 * ->r.w[] forget the list element.
			 */
			if (tomoyo_name_used_by_io_buffer(
			    container_of(element, typeof(struct tomoyo_name),
					 head.list)->entry.name, p->size))
				continue;
602
			tomoyo_del_name(element);
T
Tetsuo Handa 已提交
603 604
			break;
		case TOMOYO_ID_ACL:
605
			tomoyo_del_acl(element);
T
Tetsuo Handa 已提交
606 607
			break;
		case TOMOYO_ID_DOMAIN:
608
			if (!tomoyo_del_domain(element))
T
Tetsuo Handa 已提交
609 610
				continue;
			break;
611
		case TOMOYO_ID_PATH_GROUP:
612
			tomoyo_del_path_group(element);
613
			break;
614 615
		case TOMOYO_ID_GROUP:
			tomoyo_del_group(element);
616 617
			break;
		case TOMOYO_ID_NUMBER_GROUP:
618
			tomoyo_del_number_group(element);
T
Tetsuo Handa 已提交
619
			break;
T
Tetsuo Handa 已提交
620 621
		case TOMOYO_MAX_POLICY:
			break;
T
Tetsuo Handa 已提交
622
		}
623
		tomoyo_memory_free(element);
T
Tetsuo Handa 已提交
624 625
		list_del(&p->list);
		kfree(p);
T
Tetsuo Handa 已提交
626 627
		tomoyo_gc_list_len--;
		result = true;
T
Tetsuo Handa 已提交
628
	}
T
Tetsuo Handa 已提交
629
	return result;
T
Tetsuo Handa 已提交
630 631
}

T
Tetsuo Handa 已提交
632 633 634 635 636 637 638 639 640 641 642
/**
 * tomoyo_gc_thread - Garbage collector thread function.
 *
 * @unused: Unused.
 *
 * In case OOM-killer choose this thread for termination, we create this thread
 * as a short live thread whenever /sys/kernel/security/tomoyo/ interface was
 * close()d.
 *
 * Returns 0.
 */
T
Tetsuo Handa 已提交
643 644
static int tomoyo_gc_thread(void *unused)
{
T
Tetsuo Handa 已提交
645 646 647 648
	/* Garbage collector thread is exclusive. */
	static DEFINE_MUTEX(tomoyo_gc_mutex);
	if (!mutex_trylock(&tomoyo_gc_mutex))
		goto out;
T
Tetsuo Handa 已提交
649
	daemonize("GC for TOMOYO");
T
Tetsuo Handa 已提交
650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668
	do {
		tomoyo_collect_entry();
		if (list_empty(&tomoyo_gc_list))
			break;
		synchronize_srcu(&tomoyo_ss);
	} while (tomoyo_kfree_entry());
	{
		struct tomoyo_io_buffer *head;
		struct tomoyo_io_buffer *tmp;

		spin_lock(&tomoyo_io_buffer_list_lock);
		list_for_each_entry_safe(head, tmp, &tomoyo_io_buffer_list,
					 list) {
			if (head->users)
				continue;
			list_del(&head->list);
			kfree(head->read_buf);
			kfree(head->write_buf);
			kfree(head);
T
Tetsuo Handa 已提交
669
		}
T
Tetsuo Handa 已提交
670
		spin_unlock(&tomoyo_io_buffer_list_lock);
T
Tetsuo Handa 已提交
671
	}
T
Tetsuo Handa 已提交
672 673 674 675
	mutex_unlock(&tomoyo_gc_mutex);
out:
	/* This acts as do_exit(0). */
	return 0;
T
Tetsuo Handa 已提交
676 677
}

T
Tetsuo Handa 已提交
678 679 680 681 682 683 684 685 686
/**
 * tomoyo_notify_gc - Register/unregister /sys/kernel/security/tomoyo/ users.
 *
 * @head:        Pointer to "struct tomoyo_io_buffer".
 * @is_register: True if register, false if unregister.
 *
 * Returns nothing.
 */
void tomoyo_notify_gc(struct tomoyo_io_buffer *head, const bool is_register)
T
Tetsuo Handa 已提交
687
{
T
Tetsuo Handa 已提交
688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710
	bool is_write = false;

	spin_lock(&tomoyo_io_buffer_list_lock);
	if (is_register) {
		head->users = 1;
		list_add(&head->list, &tomoyo_io_buffer_list);
	} else {
		is_write = head->write_buf != NULL;
		if (!--head->users) {
			list_del(&head->list);
			kfree(head->read_buf);
			kfree(head->write_buf);
			kfree(head);
		}
	}
	spin_unlock(&tomoyo_io_buffer_list_lock);
	if (is_write) {
		struct task_struct *task = kthread_create(tomoyo_gc_thread,
							  NULL,
							  "GC for TOMOYO");
		if (!IS_ERR(task))
			wake_up_process(task);
	}
T
Tetsuo Handa 已提交
711
}