policy.c 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488
  1. // SPDX-License-Identifier: GPL-2.0
  2. /*
  3. * NETLINK Policy advertisement to userspace
  4. *
  5. * Authors: Johannes Berg <johannes@sipsolutions.net>
  6. *
  7. * Copyright 2019 Intel Corporation
  8. */
  9. #include <linux/kernel.h>
  10. #include <linux/errno.h>
  11. #include <linux/types.h>
  12. #include <net/netlink.h>
  13. #define INITIAL_POLICIES_ALLOC 10
  14. struct netlink_policy_dump_state {
  15. unsigned int policy_idx;
  16. unsigned int attr_idx;
  17. unsigned int n_alloc;
  18. struct {
  19. const struct nla_policy *policy;
  20. unsigned int maxtype;
  21. } policies[] __counted_by(n_alloc);
  22. };
  23. static int add_policy(struct netlink_policy_dump_state **statep,
  24. const struct nla_policy *policy,
  25. unsigned int maxtype)
  26. {
  27. struct netlink_policy_dump_state *state = *statep;
  28. unsigned int old_n_alloc, n_alloc, i;
  29. if (!policy || !maxtype)
  30. return 0;
  31. for (i = 0; i < state->n_alloc; i++) {
  32. if (state->policies[i].policy == policy &&
  33. state->policies[i].maxtype == maxtype)
  34. return 0;
  35. if (!state->policies[i].policy) {
  36. state->policies[i].policy = policy;
  37. state->policies[i].maxtype = maxtype;
  38. return 0;
  39. }
  40. }
  41. n_alloc = state->n_alloc + INITIAL_POLICIES_ALLOC;
  42. state = krealloc(state, struct_size(state, policies, n_alloc),
  43. GFP_KERNEL);
  44. if (!state)
  45. return -ENOMEM;
  46. old_n_alloc = state->n_alloc;
  47. state->n_alloc = n_alloc;
  48. memset(&state->policies[old_n_alloc], 0,
  49. flex_array_size(state, policies, n_alloc - old_n_alloc));
  50. state->policies[old_n_alloc].policy = policy;
  51. state->policies[old_n_alloc].maxtype = maxtype;
  52. *statep = state;
  53. return 0;
  54. }
  55. /**
  56. * netlink_policy_dump_get_policy_idx - retrieve policy index
  57. * @state: the policy dump state
  58. * @policy: the policy to find
  59. * @maxtype: the policy's maxattr
  60. *
  61. * Returns: the index of the given policy in the dump state
  62. *
  63. * Call this to find a policy index when you've added multiple and e.g.
  64. * need to tell userspace which command has which policy (by index).
  65. *
  66. * Note: this will WARN and return 0 if the policy isn't found, which
  67. * means it wasn't added in the first place, which would be an
  68. * internal consistency bug.
  69. */
  70. int netlink_policy_dump_get_policy_idx(struct netlink_policy_dump_state *state,
  71. const struct nla_policy *policy,
  72. unsigned int maxtype)
  73. {
  74. unsigned int i;
  75. if (WARN_ON(!policy || !maxtype))
  76. return 0;
  77. for (i = 0; i < state->n_alloc; i++) {
  78. if (state->policies[i].policy == policy &&
  79. state->policies[i].maxtype == maxtype)
  80. return i;
  81. }
  82. WARN_ON(1);
  83. return 0;
  84. }
  85. static struct netlink_policy_dump_state *alloc_state(void)
  86. {
  87. struct netlink_policy_dump_state *state;
  88. state = kzalloc(struct_size(state, policies, INITIAL_POLICIES_ALLOC),
  89. GFP_KERNEL);
  90. if (!state)
  91. return ERR_PTR(-ENOMEM);
  92. state->n_alloc = INITIAL_POLICIES_ALLOC;
  93. return state;
  94. }
  95. /**
  96. * netlink_policy_dump_add_policy - add a policy to the dump
  97. * @pstate: state to add to, may be reallocated, must be %NULL the first time
  98. * @policy: the new policy to add to the dump
  99. * @maxtype: the new policy's max attr type
  100. *
  101. * Returns: 0 on success, a negative error code otherwise.
  102. *
  103. * Call this to allocate a policy dump state, and to add policies to it. This
  104. * should be called from the dump start() callback.
  105. *
  106. * Note: on failures, any previously allocated state is freed.
  107. */
  108. int netlink_policy_dump_add_policy(struct netlink_policy_dump_state **pstate,
  109. const struct nla_policy *policy,
  110. unsigned int maxtype)
  111. {
  112. struct netlink_policy_dump_state *state = *pstate;
  113. unsigned int policy_idx;
  114. int err;
  115. if (!state) {
  116. state = alloc_state();
  117. if (IS_ERR(state))
  118. return PTR_ERR(state);
  119. }
  120. /*
  121. * walk the policies and nested ones first, and build
  122. * a linear list of them.
  123. */
  124. err = add_policy(&state, policy, maxtype);
  125. if (err)
  126. goto err_try_undo;
  127. for (policy_idx = 0;
  128. policy_idx < state->n_alloc && state->policies[policy_idx].policy;
  129. policy_idx++) {
  130. const struct nla_policy *policy;
  131. unsigned int type;
  132. policy = state->policies[policy_idx].policy;
  133. for (type = 0;
  134. type <= state->policies[policy_idx].maxtype;
  135. type++) {
  136. switch (policy[type].type) {
  137. case NLA_NESTED:
  138. case NLA_NESTED_ARRAY:
  139. err = add_policy(&state,
  140. policy[type].nested_policy,
  141. policy[type].len);
  142. if (err)
  143. goto err_try_undo;
  144. break;
  145. default:
  146. break;
  147. }
  148. }
  149. }
  150. *pstate = state;
  151. return 0;
  152. err_try_undo:
  153. /* Try to preserve reasonable unwind semantics - if we're starting from
  154. * scratch clean up fully, otherwise record what we got and caller will.
  155. */
  156. if (!*pstate)
  157. netlink_policy_dump_free(state);
  158. else
  159. *pstate = state;
  160. return err;
  161. }
  162. static bool
  163. netlink_policy_dump_finished(struct netlink_policy_dump_state *state)
  164. {
  165. return state->policy_idx >= state->n_alloc ||
  166. !state->policies[state->policy_idx].policy;
  167. }
  168. /**
  169. * netlink_policy_dump_loop - dumping loop indicator
  170. * @state: the policy dump state
  171. *
  172. * Returns: %true if the dump continues, %false otherwise
  173. *
  174. * Note: this frees the dump state when finishing
  175. */
  176. bool netlink_policy_dump_loop(struct netlink_policy_dump_state *state)
  177. {
  178. return !netlink_policy_dump_finished(state);
  179. }
  180. int netlink_policy_dump_attr_size_estimate(const struct nla_policy *pt)
  181. {
  182. /* nested + type */
  183. int common = 2 * nla_attr_size(sizeof(u32));
  184. switch (pt->type) {
  185. case NLA_UNSPEC:
  186. case NLA_REJECT:
  187. /* these actually don't need any space */
  188. return 0;
  189. case NLA_NESTED:
  190. case NLA_NESTED_ARRAY:
  191. /* common, policy idx, policy maxattr */
  192. return common + 2 * nla_attr_size(sizeof(u32));
  193. case NLA_U8:
  194. case NLA_U16:
  195. case NLA_U32:
  196. case NLA_U64:
  197. case NLA_MSECS:
  198. case NLA_S8:
  199. case NLA_S16:
  200. case NLA_S32:
  201. case NLA_S64:
  202. case NLA_SINT:
  203. case NLA_UINT:
  204. /* maximum is common, u64 min/max with padding */
  205. return common +
  206. 2 * (nla_attr_size(0) + nla_attr_size(sizeof(u64)));
  207. case NLA_BITFIELD32:
  208. return common + nla_attr_size(sizeof(u32));
  209. case NLA_STRING:
  210. case NLA_NUL_STRING:
  211. case NLA_BINARY:
  212. /* maximum is common, u32 min-length/max-length */
  213. return common + 2 * nla_attr_size(sizeof(u32));
  214. case NLA_FLAG:
  215. return common;
  216. }
  217. /* this should then cause a warning later */
  218. return 0;
  219. }
  220. static int
  221. __netlink_policy_dump_write_attr(struct netlink_policy_dump_state *state,
  222. struct sk_buff *skb,
  223. const struct nla_policy *pt,
  224. int nestattr)
  225. {
  226. int estimate = netlink_policy_dump_attr_size_estimate(pt);
  227. enum netlink_attribute_type type;
  228. struct nlattr *attr;
  229. attr = nla_nest_start(skb, nestattr);
  230. if (!attr)
  231. return -ENOBUFS;
  232. switch (pt->type) {
  233. default:
  234. case NLA_UNSPEC:
  235. case NLA_REJECT:
  236. /* skip - use NLA_MIN_LEN to advertise such */
  237. nla_nest_cancel(skb, attr);
  238. return -ENODATA;
  239. case NLA_NESTED:
  240. type = NL_ATTR_TYPE_NESTED;
  241. fallthrough;
  242. case NLA_NESTED_ARRAY:
  243. if (pt->type == NLA_NESTED_ARRAY)
  244. type = NL_ATTR_TYPE_NESTED_ARRAY;
  245. if (state && pt->nested_policy && pt->len &&
  246. (nla_put_u32(skb, NL_POLICY_TYPE_ATTR_POLICY_IDX,
  247. netlink_policy_dump_get_policy_idx(state,
  248. pt->nested_policy,
  249. pt->len)) ||
  250. nla_put_u32(skb, NL_POLICY_TYPE_ATTR_POLICY_MAXTYPE,
  251. pt->len)))
  252. goto nla_put_failure;
  253. break;
  254. case NLA_U8:
  255. case NLA_U16:
  256. case NLA_U32:
  257. case NLA_U64:
  258. case NLA_UINT:
  259. case NLA_MSECS: {
  260. struct netlink_range_validation range;
  261. if (pt->type == NLA_U8)
  262. type = NL_ATTR_TYPE_U8;
  263. else if (pt->type == NLA_U16)
  264. type = NL_ATTR_TYPE_U16;
  265. else if (pt->type == NLA_U32)
  266. type = NL_ATTR_TYPE_U32;
  267. else if (pt->type == NLA_U64)
  268. type = NL_ATTR_TYPE_U64;
  269. else
  270. type = NL_ATTR_TYPE_UINT;
  271. if (pt->validation_type == NLA_VALIDATE_MASK) {
  272. if (nla_put_u64_64bit(skb, NL_POLICY_TYPE_ATTR_MASK,
  273. pt->mask,
  274. NL_POLICY_TYPE_ATTR_PAD))
  275. goto nla_put_failure;
  276. break;
  277. }
  278. nla_get_range_unsigned(pt, &range);
  279. if (nla_put_u64_64bit(skb, NL_POLICY_TYPE_ATTR_MIN_VALUE_U,
  280. range.min, NL_POLICY_TYPE_ATTR_PAD) ||
  281. nla_put_u64_64bit(skb, NL_POLICY_TYPE_ATTR_MAX_VALUE_U,
  282. range.max, NL_POLICY_TYPE_ATTR_PAD))
  283. goto nla_put_failure;
  284. break;
  285. }
  286. case NLA_S8:
  287. case NLA_S16:
  288. case NLA_S32:
  289. case NLA_S64:
  290. case NLA_SINT: {
  291. struct netlink_range_validation_signed range;
  292. if (pt->type == NLA_S8)
  293. type = NL_ATTR_TYPE_S8;
  294. else if (pt->type == NLA_S16)
  295. type = NL_ATTR_TYPE_S16;
  296. else if (pt->type == NLA_S32)
  297. type = NL_ATTR_TYPE_S32;
  298. else if (pt->type == NLA_S64)
  299. type = NL_ATTR_TYPE_S64;
  300. else
  301. type = NL_ATTR_TYPE_SINT;
  302. nla_get_range_signed(pt, &range);
  303. if (nla_put_s64(skb, NL_POLICY_TYPE_ATTR_MIN_VALUE_S,
  304. range.min, NL_POLICY_TYPE_ATTR_PAD) ||
  305. nla_put_s64(skb, NL_POLICY_TYPE_ATTR_MAX_VALUE_S,
  306. range.max, NL_POLICY_TYPE_ATTR_PAD))
  307. goto nla_put_failure;
  308. break;
  309. }
  310. case NLA_BITFIELD32:
  311. type = NL_ATTR_TYPE_BITFIELD32;
  312. if (nla_put_u32(skb, NL_POLICY_TYPE_ATTR_BITFIELD32_MASK,
  313. pt->bitfield32_valid))
  314. goto nla_put_failure;
  315. break;
  316. case NLA_STRING:
  317. case NLA_NUL_STRING:
  318. case NLA_BINARY:
  319. if (pt->type == NLA_STRING)
  320. type = NL_ATTR_TYPE_STRING;
  321. else if (pt->type == NLA_NUL_STRING)
  322. type = NL_ATTR_TYPE_NUL_STRING;
  323. else
  324. type = NL_ATTR_TYPE_BINARY;
  325. if (pt->validation_type == NLA_VALIDATE_RANGE ||
  326. pt->validation_type == NLA_VALIDATE_RANGE_WARN_TOO_LONG) {
  327. struct netlink_range_validation range;
  328. nla_get_range_unsigned(pt, &range);
  329. if (range.min &&
  330. nla_put_u32(skb, NL_POLICY_TYPE_ATTR_MIN_LENGTH,
  331. range.min))
  332. goto nla_put_failure;
  333. if (range.max < U16_MAX &&
  334. nla_put_u32(skb, NL_POLICY_TYPE_ATTR_MAX_LENGTH,
  335. range.max))
  336. goto nla_put_failure;
  337. } else if (pt->len &&
  338. nla_put_u32(skb, NL_POLICY_TYPE_ATTR_MAX_LENGTH,
  339. pt->len)) {
  340. goto nla_put_failure;
  341. }
  342. break;
  343. case NLA_FLAG:
  344. type = NL_ATTR_TYPE_FLAG;
  345. break;
  346. }
  347. if (nla_put_u32(skb, NL_POLICY_TYPE_ATTR_TYPE, type))
  348. goto nla_put_failure;
  349. nla_nest_end(skb, attr);
  350. WARN_ON(attr->nla_len > estimate);
  351. return 0;
  352. nla_put_failure:
  353. nla_nest_cancel(skb, attr);
  354. return -ENOBUFS;
  355. }
  356. /**
  357. * netlink_policy_dump_write_attr - write a given attribute policy
  358. * @skb: the message skb to write to
  359. * @pt: the attribute's policy
  360. * @nestattr: the nested attribute ID to use
  361. *
  362. * Returns: 0 on success, an error code otherwise; -%ENODATA is
  363. * special, indicating that there's no policy data and
  364. * the attribute is generally rejected.
  365. */
  366. int netlink_policy_dump_write_attr(struct sk_buff *skb,
  367. const struct nla_policy *pt,
  368. int nestattr)
  369. {
  370. return __netlink_policy_dump_write_attr(NULL, skb, pt, nestattr);
  371. }
  372. /**
  373. * netlink_policy_dump_write - write current policy dump attributes
  374. * @skb: the message skb to write to
  375. * @state: the policy dump state
  376. *
  377. * Returns: 0 on success, an error code otherwise
  378. */
  379. int netlink_policy_dump_write(struct sk_buff *skb,
  380. struct netlink_policy_dump_state *state)
  381. {
  382. const struct nla_policy *pt;
  383. struct nlattr *policy;
  384. bool again;
  385. int err;
  386. send_attribute:
  387. again = false;
  388. pt = &state->policies[state->policy_idx].policy[state->attr_idx];
  389. policy = nla_nest_start(skb, state->policy_idx);
  390. if (!policy)
  391. return -ENOBUFS;
  392. err = __netlink_policy_dump_write_attr(state, skb, pt, state->attr_idx);
  393. if (err == -ENODATA) {
  394. nla_nest_cancel(skb, policy);
  395. again = true;
  396. goto next;
  397. } else if (err) {
  398. goto nla_put_failure;
  399. }
  400. /* finish and move state to next attribute */
  401. nla_nest_end(skb, policy);
  402. next:
  403. state->attr_idx += 1;
  404. if (state->attr_idx > state->policies[state->policy_idx].maxtype) {
  405. state->attr_idx = 0;
  406. state->policy_idx++;
  407. }
  408. if (again) {
  409. if (netlink_policy_dump_finished(state))
  410. return -ENODATA;
  411. goto send_attribute;
  412. }
  413. return 0;
  414. nla_put_failure:
  415. nla_nest_cancel(skb, policy);
  416. return -ENOBUFS;
  417. }
  418. /**
  419. * netlink_policy_dump_free - free policy dump state
  420. * @state: the policy dump state to free
  421. *
  422. * Call this from the done() method to ensure dump state is freed.
  423. */
  424. void netlink_policy_dump_free(struct netlink_policy_dump_state *state)
  425. {
  426. kfree(state);
  427. }