| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 1 | /** | 
|  | 2 | * eCryptfs: Linux filesystem encryption layer | 
|  | 3 | * | 
|  | 4 | * Copyright (C) 2008 International Business Machines Corp. | 
|  | 5 | *   Author(s): Michael A. Halcrow <mhalcrow@us.ibm.com> | 
|  | 6 | * | 
|  | 7 | * This program is free software; you can redistribute it and/or | 
|  | 8 | * modify it under the terms of the GNU General Public License version | 
|  | 9 | * 2 as published by the Free Software Foundation. | 
|  | 10 | * | 
|  | 11 | * This program is distributed in the hope that it will be useful, but | 
|  | 12 | * WITHOUT ANY WARRANTY; without even the implied warranty of | 
|  | 13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU | 
|  | 14 | * General Public License for more details. | 
|  | 15 | * | 
|  | 16 | * You should have received a copy of the GNU General Public License | 
|  | 17 | * along with this program; if not, write to the Free Software | 
|  | 18 | * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA | 
|  | 19 | * 02111-1307, USA. | 
|  | 20 | */ | 
|  | 21 |  | 
|  | 22 | #include <linux/fs.h> | 
|  | 23 | #include <linux/hash.h> | 
|  | 24 | #include <linux/random.h> | 
|  | 25 | #include <linux/miscdevice.h> | 
|  | 26 | #include <linux/poll.h> | 
|  | 27 | #include <linux/wait.h> | 
|  | 28 | #include <linux/module.h> | 
|  | 29 | #include "ecryptfs_kernel.h" | 
|  | 30 |  | 
|  | 31 | static atomic_t ecryptfs_num_miscdev_opens; | 
|  | 32 |  | 
|  | 33 | /** | 
|  | 34 | * ecryptfs_miscdev_poll | 
|  | 35 | * @file: dev file (ignored) | 
|  | 36 | * @pt: dev poll table (ignored) | 
|  | 37 | * | 
|  | 38 | * Returns the poll mask | 
|  | 39 | */ | 
|  | 40 | static unsigned int | 
|  | 41 | ecryptfs_miscdev_poll(struct file *file, poll_table *pt) | 
|  | 42 | { | 
|  | 43 | struct ecryptfs_daemon *daemon; | 
|  | 44 | unsigned int mask = 0; | 
|  | 45 | int rc; | 
|  | 46 |  | 
|  | 47 | mutex_lock(&ecryptfs_daemon_hash_mux); | 
|  | 48 | /* TODO: Just use file->private_data? */ | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 49 | rc = ecryptfs_find_daemon_by_euid(&daemon, current->euid, | 
|  | 50 | current->nsproxy->user_ns); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 51 | BUG_ON(rc || !daemon); | 
|  | 52 | mutex_lock(&daemon->mux); | 
|  | 53 | mutex_unlock(&ecryptfs_daemon_hash_mux); | 
|  | 54 | if (daemon->flags & ECRYPTFS_DAEMON_ZOMBIE) { | 
|  | 55 | printk(KERN_WARNING "%s: Attempt to poll on zombified " | 
|  | 56 | "daemon\n", __func__); | 
|  | 57 | goto out_unlock_daemon; | 
|  | 58 | } | 
|  | 59 | if (daemon->flags & ECRYPTFS_DAEMON_IN_READ) | 
|  | 60 | goto out_unlock_daemon; | 
|  | 61 | if (daemon->flags & ECRYPTFS_DAEMON_IN_POLL) | 
|  | 62 | goto out_unlock_daemon; | 
|  | 63 | daemon->flags |= ECRYPTFS_DAEMON_IN_POLL; | 
|  | 64 | mutex_unlock(&daemon->mux); | 
|  | 65 | poll_wait(file, &daemon->wait, pt); | 
|  | 66 | mutex_lock(&daemon->mux); | 
|  | 67 | if (!list_empty(&daemon->msg_ctx_out_queue)) | 
|  | 68 | mask |= POLLIN | POLLRDNORM; | 
|  | 69 | out_unlock_daemon: | 
|  | 70 | daemon->flags &= ~ECRYPTFS_DAEMON_IN_POLL; | 
|  | 71 | mutex_unlock(&daemon->mux); | 
|  | 72 | return mask; | 
|  | 73 | } | 
|  | 74 |  | 
|  | 75 | /** | 
|  | 76 | * ecryptfs_miscdev_open | 
|  | 77 | * @inode: inode of miscdev handle (ignored) | 
|  | 78 | * @file: file for miscdev handle (ignored) | 
|  | 79 | * | 
|  | 80 | * Returns zero on success; non-zero otherwise | 
|  | 81 | */ | 
|  | 82 | static int | 
|  | 83 | ecryptfs_miscdev_open(struct inode *inode, struct file *file) | 
|  | 84 | { | 
|  | 85 | struct ecryptfs_daemon *daemon = NULL; | 
|  | 86 | int rc; | 
|  | 87 |  | 
|  | 88 | mutex_lock(&ecryptfs_daemon_hash_mux); | 
|  | 89 | rc = try_module_get(THIS_MODULE); | 
|  | 90 | if (rc == 0) { | 
|  | 91 | rc = -EIO; | 
|  | 92 | printk(KERN_ERR "%s: Error attempting to increment module use " | 
|  | 93 | "count; rc = [%d]\n", __func__, rc); | 
|  | 94 | goto out_unlock_daemon_list; | 
|  | 95 | } | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 96 | rc = ecryptfs_find_daemon_by_euid(&daemon, current->euid, | 
|  | 97 | current->nsproxy->user_ns); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 98 | if (rc || !daemon) { | 
|  | 99 | rc = ecryptfs_spawn_daemon(&daemon, current->euid, | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 100 | current->nsproxy->user_ns, | 
|  | 101 | task_pid(current)); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 102 | if (rc) { | 
|  | 103 | printk(KERN_ERR "%s: Error attempting to spawn daemon; " | 
|  | 104 | "rc = [%d]\n", __func__, rc); | 
|  | 105 | goto out_module_put_unlock_daemon_list; | 
|  | 106 | } | 
|  | 107 | } | 
|  | 108 | mutex_lock(&daemon->mux); | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 109 | if (daemon->pid != task_pid(current)) { | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 110 | rc = -EINVAL; | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 111 | printk(KERN_ERR "%s: pid [0x%p] has registered with euid [%d], " | 
|  | 112 | "but pid [0x%p] has attempted to open the handle " | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 113 | "instead\n", __func__, daemon->pid, daemon->euid, | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 114 | task_pid(current)); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 115 | goto out_unlock_daemon; | 
|  | 116 | } | 
|  | 117 | if (daemon->flags & ECRYPTFS_DAEMON_MISCDEV_OPEN) { | 
|  | 118 | rc = -EBUSY; | 
|  | 119 | printk(KERN_ERR "%s: Miscellaneous device handle may only be " | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 120 | "opened once per daemon; pid [0x%p] already has this " | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 121 | "handle open\n", __func__, daemon->pid); | 
|  | 122 | goto out_unlock_daemon; | 
|  | 123 | } | 
|  | 124 | daemon->flags |= ECRYPTFS_DAEMON_MISCDEV_OPEN; | 
|  | 125 | atomic_inc(&ecryptfs_num_miscdev_opens); | 
|  | 126 | out_unlock_daemon: | 
|  | 127 | mutex_unlock(&daemon->mux); | 
|  | 128 | out_module_put_unlock_daemon_list: | 
|  | 129 | if (rc) | 
|  | 130 | module_put(THIS_MODULE); | 
|  | 131 | out_unlock_daemon_list: | 
|  | 132 | mutex_unlock(&ecryptfs_daemon_hash_mux); | 
|  | 133 | return rc; | 
|  | 134 | } | 
|  | 135 |  | 
|  | 136 | /** | 
|  | 137 | * ecryptfs_miscdev_release | 
|  | 138 | * @inode: inode of fs/ecryptfs/euid handle (ignored) | 
|  | 139 | * @file: file for fs/ecryptfs/euid handle (ignored) | 
|  | 140 | * | 
|  | 141 | * This keeps the daemon registered until the daemon sends another | 
|  | 142 | * ioctl to fs/ecryptfs/ctl or until the kernel module unregisters. | 
|  | 143 | * | 
|  | 144 | * Returns zero on success; non-zero otherwise | 
|  | 145 | */ | 
|  | 146 | static int | 
|  | 147 | ecryptfs_miscdev_release(struct inode *inode, struct file *file) | 
|  | 148 | { | 
|  | 149 | struct ecryptfs_daemon *daemon = NULL; | 
|  | 150 | int rc; | 
|  | 151 |  | 
|  | 152 | mutex_lock(&ecryptfs_daemon_hash_mux); | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 153 | rc = ecryptfs_find_daemon_by_euid(&daemon, current->euid, | 
|  | 154 | current->nsproxy->user_ns); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 155 | BUG_ON(rc || !daemon); | 
|  | 156 | mutex_lock(&daemon->mux); | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 157 | BUG_ON(daemon->pid != task_pid(current)); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 158 | BUG_ON(!(daemon->flags & ECRYPTFS_DAEMON_MISCDEV_OPEN)); | 
|  | 159 | daemon->flags &= ~ECRYPTFS_DAEMON_MISCDEV_OPEN; | 
|  | 160 | atomic_dec(&ecryptfs_num_miscdev_opens); | 
|  | 161 | mutex_unlock(&daemon->mux); | 
|  | 162 | rc = ecryptfs_exorcise_daemon(daemon); | 
|  | 163 | if (rc) { | 
|  | 164 | printk(KERN_CRIT "%s: Fatal error whilst attempting to " | 
|  | 165 | "shut down daemon; rc = [%d]. Please report this " | 
|  | 166 | "bug.\n", __func__, rc); | 
|  | 167 | BUG(); | 
|  | 168 | } | 
|  | 169 | module_put(THIS_MODULE); | 
|  | 170 | mutex_unlock(&ecryptfs_daemon_hash_mux); | 
|  | 171 | return rc; | 
|  | 172 | } | 
|  | 173 |  | 
|  | 174 | /** | 
|  | 175 | * ecryptfs_send_miscdev | 
|  | 176 | * @data: Data to send to daemon; may be NULL | 
|  | 177 | * @data_size: Amount of data to send to daemon | 
|  | 178 | * @msg_ctx: Message context, which is used to handle the reply. If | 
|  | 179 | *           this is NULL, then we do not expect a reply. | 
|  | 180 | * @msg_type: Type of message | 
|  | 181 | * @msg_flags: Flags for message | 
|  | 182 | * @daemon: eCryptfs daemon object | 
|  | 183 | * | 
|  | 184 | * Add msg_ctx to queue and then, if it exists, notify the blocked | 
|  | 185 | * miscdevess about the data being available. Must be called with | 
|  | 186 | * ecryptfs_daemon_hash_mux held. | 
|  | 187 | * | 
|  | 188 | * Returns zero on success; non-zero otherwise | 
|  | 189 | */ | 
|  | 190 | int ecryptfs_send_miscdev(char *data, size_t data_size, | 
|  | 191 | struct ecryptfs_msg_ctx *msg_ctx, u8 msg_type, | 
|  | 192 | u16 msg_flags, struct ecryptfs_daemon *daemon) | 
|  | 193 | { | 
|  | 194 | int rc = 0; | 
|  | 195 |  | 
|  | 196 | mutex_lock(&msg_ctx->mux); | 
|  | 197 | if (data) { | 
|  | 198 | msg_ctx->msg = kmalloc((sizeof(*msg_ctx->msg) + data_size), | 
|  | 199 | GFP_KERNEL); | 
|  | 200 | if (!msg_ctx->msg) { | 
|  | 201 | rc = -ENOMEM; | 
|  | 202 | printk(KERN_ERR "%s: Out of memory whilst attempting " | 
| Michael Halcrow | f66e883 | 2008-04-29 00:59:51 -0700 | [diff] [blame] | 203 | "to kmalloc(%Zd, GFP_KERNEL)\n", __func__, | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 204 | (sizeof(*msg_ctx->msg) + data_size)); | 
|  | 205 | goto out_unlock; | 
|  | 206 | } | 
|  | 207 | } else | 
|  | 208 | msg_ctx->msg = NULL; | 
|  | 209 | msg_ctx->msg->index = msg_ctx->index; | 
|  | 210 | msg_ctx->msg->data_len = data_size; | 
|  | 211 | msg_ctx->type = msg_type; | 
|  | 212 | if (data) { | 
|  | 213 | memcpy(msg_ctx->msg->data, data, data_size); | 
|  | 214 | msg_ctx->msg_size = (sizeof(*msg_ctx->msg) + data_size); | 
|  | 215 | } else | 
|  | 216 | msg_ctx->msg_size = 0; | 
|  | 217 | mutex_lock(&daemon->mux); | 
|  | 218 | list_add_tail(&msg_ctx->daemon_out_list, &daemon->msg_ctx_out_queue); | 
|  | 219 | daemon->num_queued_msg_ctx++; | 
|  | 220 | wake_up_interruptible(&daemon->wait); | 
|  | 221 | mutex_unlock(&daemon->mux); | 
|  | 222 | out_unlock: | 
|  | 223 | mutex_unlock(&msg_ctx->mux); | 
|  | 224 | return rc; | 
|  | 225 | } | 
|  | 226 |  | 
|  | 227 | /** | 
|  | 228 | * ecryptfs_miscdev_read - format and send message from queue | 
|  | 229 | * @file: fs/ecryptfs/euid miscdevfs handle (ignored) | 
|  | 230 | * @buf: User buffer into which to copy the next message on the daemon queue | 
|  | 231 | * @count: Amount of space available in @buf | 
|  | 232 | * @ppos: Offset in file (ignored) | 
|  | 233 | * | 
|  | 234 | * Pulls the most recent message from the daemon queue, formats it for | 
|  | 235 | * being sent via a miscdevfs handle, and copies it into @buf | 
|  | 236 | * | 
|  | 237 | * Returns the number of bytes copied into the user buffer | 
|  | 238 | */ | 
| Michael Halcrow | f66e883 | 2008-04-29 00:59:51 -0700 | [diff] [blame] | 239 | static ssize_t | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 240 | ecryptfs_miscdev_read(struct file *file, char __user *buf, size_t count, | 
|  | 241 | loff_t *ppos) | 
|  | 242 | { | 
|  | 243 | struct ecryptfs_daemon *daemon; | 
|  | 244 | struct ecryptfs_msg_ctx *msg_ctx; | 
|  | 245 | size_t packet_length_size; | 
|  | 246 | u32 counter_nbo; | 
|  | 247 | char packet_length[3]; | 
|  | 248 | size_t i; | 
|  | 249 | size_t total_length; | 
|  | 250 | int rc; | 
|  | 251 |  | 
|  | 252 | mutex_lock(&ecryptfs_daemon_hash_mux); | 
|  | 253 | /* TODO: Just use file->private_data? */ | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 254 | rc = ecryptfs_find_daemon_by_euid(&daemon, current->euid, | 
|  | 255 | current->nsproxy->user_ns); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 256 | BUG_ON(rc || !daemon); | 
|  | 257 | mutex_lock(&daemon->mux); | 
|  | 258 | if (daemon->flags & ECRYPTFS_DAEMON_ZOMBIE) { | 
|  | 259 | rc = 0; | 
|  | 260 | printk(KERN_WARNING "%s: Attempt to read from zombified " | 
|  | 261 | "daemon\n", __func__); | 
|  | 262 | goto out_unlock_daemon; | 
|  | 263 | } | 
|  | 264 | if (daemon->flags & ECRYPTFS_DAEMON_IN_READ) { | 
|  | 265 | rc = 0; | 
|  | 266 | goto out_unlock_daemon; | 
|  | 267 | } | 
|  | 268 | /* This daemon will not go away so long as this flag is set */ | 
|  | 269 | daemon->flags |= ECRYPTFS_DAEMON_IN_READ; | 
|  | 270 | mutex_unlock(&ecryptfs_daemon_hash_mux); | 
|  | 271 | check_list: | 
|  | 272 | if (list_empty(&daemon->msg_ctx_out_queue)) { | 
|  | 273 | mutex_unlock(&daemon->mux); | 
|  | 274 | rc = wait_event_interruptible( | 
|  | 275 | daemon->wait, !list_empty(&daemon->msg_ctx_out_queue)); | 
|  | 276 | mutex_lock(&daemon->mux); | 
|  | 277 | if (rc < 0) { | 
|  | 278 | rc = 0; | 
|  | 279 | goto out_unlock_daemon; | 
|  | 280 | } | 
|  | 281 | } | 
|  | 282 | if (daemon->flags & ECRYPTFS_DAEMON_ZOMBIE) { | 
|  | 283 | rc = 0; | 
|  | 284 | goto out_unlock_daemon; | 
|  | 285 | } | 
|  | 286 | if (list_empty(&daemon->msg_ctx_out_queue)) { | 
|  | 287 | /* Something else jumped in since the | 
|  | 288 | * wait_event_interruptable() and removed the | 
|  | 289 | * message from the queue; try again */ | 
|  | 290 | goto check_list; | 
|  | 291 | } | 
|  | 292 | BUG_ON(current->euid != daemon->euid); | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 293 | BUG_ON(current->nsproxy->user_ns != daemon->user_ns); | 
|  | 294 | BUG_ON(task_pid(current) != daemon->pid); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 295 | msg_ctx = list_first_entry(&daemon->msg_ctx_out_queue, | 
|  | 296 | struct ecryptfs_msg_ctx, daemon_out_list); | 
|  | 297 | BUG_ON(!msg_ctx); | 
|  | 298 | mutex_lock(&msg_ctx->mux); | 
|  | 299 | if (msg_ctx->msg) { | 
|  | 300 | rc = ecryptfs_write_packet_length(packet_length, | 
|  | 301 | msg_ctx->msg_size, | 
|  | 302 | &packet_length_size); | 
|  | 303 | if (rc) { | 
|  | 304 | rc = 0; | 
|  | 305 | printk(KERN_WARNING "%s: Error writing packet length; " | 
|  | 306 | "rc = [%d]\n", __func__, rc); | 
|  | 307 | goto out_unlock_msg_ctx; | 
|  | 308 | } | 
|  | 309 | } else { | 
|  | 310 | packet_length_size = 0; | 
|  | 311 | msg_ctx->msg_size = 0; | 
|  | 312 | } | 
|  | 313 | /* miscdevfs packet format: | 
|  | 314 | *  Octet 0: Type | 
|  | 315 | *  Octets 1-4: network byte order msg_ctx->counter | 
|  | 316 | *  Octets 5-N0: Size of struct ecryptfs_message to follow | 
|  | 317 | *  Octets N0-N1: struct ecryptfs_message (including data) | 
|  | 318 | * | 
|  | 319 | *  Octets 5-N1 not written if the packet type does not | 
|  | 320 | *  include a message */ | 
|  | 321 | total_length = (1 + 4 + packet_length_size + msg_ctx->msg_size); | 
|  | 322 | if (count < total_length) { | 
|  | 323 | rc = 0; | 
|  | 324 | printk(KERN_WARNING "%s: Only given user buffer of " | 
|  | 325 | "size [%Zd], but we need [%Zd] to read the " | 
|  | 326 | "pending message\n", __func__, count, total_length); | 
|  | 327 | goto out_unlock_msg_ctx; | 
|  | 328 | } | 
|  | 329 | i = 0; | 
|  | 330 | buf[i++] = msg_ctx->type; | 
|  | 331 | counter_nbo = cpu_to_be32(msg_ctx->counter); | 
|  | 332 | memcpy(&buf[i], (char *)&counter_nbo, 4); | 
|  | 333 | i += 4; | 
|  | 334 | if (msg_ctx->msg) { | 
|  | 335 | memcpy(&buf[i], packet_length, packet_length_size); | 
|  | 336 | i += packet_length_size; | 
|  | 337 | rc = copy_to_user(&buf[i], msg_ctx->msg, msg_ctx->msg_size); | 
|  | 338 | if (rc) { | 
|  | 339 | printk(KERN_ERR "%s: copy_to_user returned error " | 
|  | 340 | "[%d]\n", __func__, rc); | 
|  | 341 | goto out_unlock_msg_ctx; | 
|  | 342 | } | 
|  | 343 | i += msg_ctx->msg_size; | 
|  | 344 | } | 
|  | 345 | rc = i; | 
|  | 346 | list_del(&msg_ctx->daemon_out_list); | 
|  | 347 | kfree(msg_ctx->msg); | 
|  | 348 | msg_ctx->msg = NULL; | 
|  | 349 | /* We do not expect a reply from the userspace daemon for any | 
|  | 350 | * message type other than ECRYPTFS_MSG_REQUEST */ | 
|  | 351 | if (msg_ctx->type != ECRYPTFS_MSG_REQUEST) | 
|  | 352 | ecryptfs_msg_ctx_alloc_to_free(msg_ctx); | 
|  | 353 | out_unlock_msg_ctx: | 
|  | 354 | mutex_unlock(&msg_ctx->mux); | 
|  | 355 | out_unlock_daemon: | 
|  | 356 | daemon->flags &= ~ECRYPTFS_DAEMON_IN_READ; | 
|  | 357 | mutex_unlock(&daemon->mux); | 
|  | 358 | return rc; | 
|  | 359 | } | 
|  | 360 |  | 
|  | 361 | /** | 
|  | 362 | * ecryptfs_miscdev_helo | 
|  | 363 | * @euid: effective user id of miscdevess sending helo packet | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 364 | * @user_ns: The namespace in which @euid applies | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 365 | * @pid: miscdevess id of miscdevess sending helo packet | 
|  | 366 | * | 
|  | 367 | * Returns zero on success; non-zero otherwise | 
|  | 368 | */ | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 369 | static int ecryptfs_miscdev_helo(uid_t euid, struct user_namespace *user_ns, | 
|  | 370 | struct pid *pid) | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 371 | { | 
|  | 372 | int rc; | 
|  | 373 |  | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 374 | rc = ecryptfs_process_helo(ECRYPTFS_TRANSPORT_MISCDEV, euid, user_ns, | 
|  | 375 | pid); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 376 | if (rc) | 
|  | 377 | printk(KERN_WARNING "Error processing HELO; rc = [%d]\n", rc); | 
|  | 378 | return rc; | 
|  | 379 | } | 
|  | 380 |  | 
|  | 381 | /** | 
|  | 382 | * ecryptfs_miscdev_quit | 
|  | 383 | * @euid: effective user id of miscdevess sending quit packet | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 384 | * @user_ns: The namespace in which @euid applies | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 385 | * @pid: miscdevess id of miscdevess sending quit packet | 
|  | 386 | * | 
|  | 387 | * Returns zero on success; non-zero otherwise | 
|  | 388 | */ | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 389 | static int ecryptfs_miscdev_quit(uid_t euid, struct user_namespace *user_ns, | 
|  | 390 | struct pid *pid) | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 391 | { | 
|  | 392 | int rc; | 
|  | 393 |  | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 394 | rc = ecryptfs_process_quit(euid, user_ns, pid); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 395 | if (rc) | 
|  | 396 | printk(KERN_WARNING | 
|  | 397 | "Error processing QUIT message; rc = [%d]\n", rc); | 
|  | 398 | return rc; | 
|  | 399 | } | 
|  | 400 |  | 
|  | 401 | /** | 
|  | 402 | * ecryptfs_miscdev_response - miscdevess response to message previously sent to daemon | 
|  | 403 | * @data: Bytes comprising struct ecryptfs_message | 
|  | 404 | * @data_size: sizeof(struct ecryptfs_message) + data len | 
|  | 405 | * @euid: Effective user id of miscdevess sending the miscdev response | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 406 | * @user_ns: The namespace in which @euid applies | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 407 | * @pid: Miscdevess id of miscdevess sending the miscdev response | 
|  | 408 | * @seq: Sequence number for miscdev response packet | 
|  | 409 | * | 
|  | 410 | * Returns zero on success; non-zero otherwise | 
|  | 411 | */ | 
|  | 412 | static int ecryptfs_miscdev_response(char *data, size_t data_size, | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 413 | uid_t euid, struct user_namespace *user_ns, | 
|  | 414 | struct pid *pid, u32 seq) | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 415 | { | 
|  | 416 | struct ecryptfs_message *msg = (struct ecryptfs_message *)data; | 
|  | 417 | int rc; | 
|  | 418 |  | 
|  | 419 | if ((sizeof(*msg) + msg->data_len) != data_size) { | 
|  | 420 | printk(KERN_WARNING "%s: (sizeof(*msg) + msg->data_len) = " | 
|  | 421 | "[%Zd]; data_size = [%Zd]. Invalid packet.\n", __func__, | 
|  | 422 | (sizeof(*msg) + msg->data_len), data_size); | 
|  | 423 | rc = -EINVAL; | 
|  | 424 | goto out; | 
|  | 425 | } | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 426 | rc = ecryptfs_process_response(msg, euid, user_ns, pid, seq); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 427 | if (rc) | 
|  | 428 | printk(KERN_ERR | 
|  | 429 | "Error processing response message; rc = [%d]\n", rc); | 
|  | 430 | out: | 
|  | 431 | return rc; | 
|  | 432 | } | 
|  | 433 |  | 
|  | 434 | /** | 
|  | 435 | * ecryptfs_miscdev_write - handle write to daemon miscdev handle | 
|  | 436 | * @file: File for misc dev handle (ignored) | 
|  | 437 | * @buf: Buffer containing user data | 
|  | 438 | * @count: Amount of data in @buf | 
|  | 439 | * @ppos: Pointer to offset in file (ignored) | 
|  | 440 | * | 
|  | 441 | * miscdevfs packet format: | 
|  | 442 | *  Octet 0: Type | 
|  | 443 | *  Octets 1-4: network byte order msg_ctx->counter (0's for non-response) | 
|  | 444 | *  Octets 5-N0: Size of struct ecryptfs_message to follow | 
|  | 445 | *  Octets N0-N1: struct ecryptfs_message (including data) | 
|  | 446 | * | 
|  | 447 | * Returns the number of bytes read from @buf | 
|  | 448 | */ | 
|  | 449 | static ssize_t | 
|  | 450 | ecryptfs_miscdev_write(struct file *file, const char __user *buf, | 
|  | 451 | size_t count, loff_t *ppos) | 
|  | 452 | { | 
|  | 453 | u32 counter_nbo, seq; | 
|  | 454 | size_t packet_size, packet_size_length, i; | 
|  | 455 | ssize_t sz = 0; | 
|  | 456 | char *data; | 
|  | 457 | int rc; | 
|  | 458 |  | 
|  | 459 | if (count == 0) | 
|  | 460 | goto out; | 
|  | 461 | data = kmalloc(count, GFP_KERNEL); | 
|  | 462 | if (!data) { | 
|  | 463 | printk(KERN_ERR "%s: Out of memory whilst attempting to " | 
|  | 464 | "kmalloc([%Zd], GFP_KERNEL)\n", __func__, count); | 
|  | 465 | goto out; | 
|  | 466 | } | 
|  | 467 | rc = copy_from_user(data, buf, count); | 
|  | 468 | if (rc) { | 
|  | 469 | printk(KERN_ERR "%s: copy_from_user returned error [%d]\n", | 
|  | 470 | __func__, rc); | 
|  | 471 | goto out_free; | 
|  | 472 | } | 
|  | 473 | sz = count; | 
|  | 474 | i = 0; | 
|  | 475 | switch (data[i++]) { | 
|  | 476 | case ECRYPTFS_MSG_RESPONSE: | 
|  | 477 | if (count < (1 + 4 + 1 + sizeof(struct ecryptfs_message))) { | 
|  | 478 | printk(KERN_WARNING "%s: Minimum acceptable packet " | 
|  | 479 | "size is [%Zd], but amount of data written is " | 
|  | 480 | "only [%Zd]. Discarding response packet.\n", | 
|  | 481 | __func__, | 
|  | 482 | (1 + 4 + 1 + sizeof(struct ecryptfs_message)), | 
|  | 483 | count); | 
|  | 484 | goto out_free; | 
|  | 485 | } | 
|  | 486 | memcpy((char *)&counter_nbo, &data[i], 4); | 
|  | 487 | seq = be32_to_cpu(counter_nbo); | 
|  | 488 | i += 4; | 
|  | 489 | rc = ecryptfs_parse_packet_length(&data[i], &packet_size, | 
|  | 490 | &packet_size_length); | 
|  | 491 | if (rc) { | 
|  | 492 | printk(KERN_WARNING "%s: Error parsing packet length; " | 
|  | 493 | "rc = [%d]\n", __func__, rc); | 
|  | 494 | goto out_free; | 
|  | 495 | } | 
|  | 496 | i += packet_size_length; | 
|  | 497 | if ((1 + 4 + packet_size_length + packet_size) != count) { | 
|  | 498 | printk(KERN_WARNING "%s: (1 + packet_size_length([%Zd])" | 
|  | 499 | " + packet_size([%Zd]))([%Zd]) != " | 
|  | 500 | "count([%Zd]). Invalid packet format.\n", | 
|  | 501 | __func__, packet_size_length, packet_size, | 
|  | 502 | (1 + packet_size_length + packet_size), count); | 
|  | 503 | goto out_free; | 
|  | 504 | } | 
|  | 505 | rc = ecryptfs_miscdev_response(&data[i], packet_size, | 
|  | 506 | current->euid, | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 507 | current->nsproxy->user_ns, | 
|  | 508 | task_pid(current), seq); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 509 | if (rc) | 
|  | 510 | printk(KERN_WARNING "%s: Failed to deliver miscdev " | 
|  | 511 | "response to requesting operation; rc = [%d]\n", | 
|  | 512 | __func__, rc); | 
|  | 513 | break; | 
|  | 514 | case ECRYPTFS_MSG_HELO: | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 515 | rc = ecryptfs_miscdev_helo(current->euid, | 
|  | 516 | current->nsproxy->user_ns, | 
|  | 517 | task_pid(current)); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 518 | if (rc) { | 
|  | 519 | printk(KERN_ERR "%s: Error attempting to process " | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 520 | "helo from pid [0x%p]; rc = [%d]\n", __func__, | 
|  | 521 | task_pid(current), rc); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 522 | goto out_free; | 
|  | 523 | } | 
|  | 524 | break; | 
|  | 525 | case ECRYPTFS_MSG_QUIT: | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 526 | rc = ecryptfs_miscdev_quit(current->euid, | 
|  | 527 | current->nsproxy->user_ns, | 
|  | 528 | task_pid(current)); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 529 | if (rc) { | 
|  | 530 | printk(KERN_ERR "%s: Error attempting to process " | 
| Michael Halcrow | 6a3fd92 | 2008-04-29 00:59:52 -0700 | [diff] [blame] | 531 | "quit from pid [0x%p]; rc = [%d]\n", __func__, | 
|  | 532 | task_pid(current), rc); | 
| Michael Halcrow | 8bf2deb | 2008-04-29 00:59:50 -0700 | [diff] [blame] | 533 | goto out_free; | 
|  | 534 | } | 
|  | 535 | break; | 
|  | 536 | default: | 
|  | 537 | ecryptfs_printk(KERN_WARNING, "Dropping miscdev " | 
|  | 538 | "message of unrecognized type [%d]\n", | 
|  | 539 | data[0]); | 
|  | 540 | break; | 
|  | 541 | } | 
|  | 542 | out_free: | 
|  | 543 | kfree(data); | 
|  | 544 | out: | 
|  | 545 | return sz; | 
|  | 546 | } | 
|  | 547 |  | 
|  | 548 |  | 
|  | 549 | static const struct file_operations ecryptfs_miscdev_fops = { | 
|  | 550 | .open    = ecryptfs_miscdev_open, | 
|  | 551 | .poll    = ecryptfs_miscdev_poll, | 
|  | 552 | .read    = ecryptfs_miscdev_read, | 
|  | 553 | .write   = ecryptfs_miscdev_write, | 
|  | 554 | .release = ecryptfs_miscdev_release, | 
|  | 555 | }; | 
|  | 556 |  | 
|  | 557 | static struct miscdevice ecryptfs_miscdev = { | 
|  | 558 | .minor = MISC_DYNAMIC_MINOR, | 
|  | 559 | .name  = "ecryptfs", | 
|  | 560 | .fops  = &ecryptfs_miscdev_fops | 
|  | 561 | }; | 
|  | 562 |  | 
|  | 563 | /** | 
|  | 564 | * ecryptfs_init_ecryptfs_miscdev | 
|  | 565 | * | 
|  | 566 | * Messages sent to the userspace daemon from the kernel are placed on | 
|  | 567 | * a queue associated with the daemon. The next read against the | 
|  | 568 | * miscdev handle by that daemon will return the oldest message placed | 
|  | 569 | * on the message queue for the daemon. | 
|  | 570 | * | 
|  | 571 | * Returns zero on success; non-zero otherwise | 
|  | 572 | */ | 
|  | 573 | int ecryptfs_init_ecryptfs_miscdev(void) | 
|  | 574 | { | 
|  | 575 | int rc; | 
|  | 576 |  | 
|  | 577 | atomic_set(&ecryptfs_num_miscdev_opens, 0); | 
|  | 578 | mutex_lock(&ecryptfs_daemon_hash_mux); | 
|  | 579 | rc = misc_register(&ecryptfs_miscdev); | 
|  | 580 | if (rc) | 
|  | 581 | printk(KERN_ERR "%s: Failed to register miscellaneous device " | 
|  | 582 | "for communications with userspace daemons; rc = [%d]\n", | 
|  | 583 | __func__, rc); | 
|  | 584 | mutex_unlock(&ecryptfs_daemon_hash_mux); | 
|  | 585 | return rc; | 
|  | 586 | } | 
|  | 587 |  | 
|  | 588 | /** | 
|  | 589 | * ecryptfs_destroy_ecryptfs_miscdev | 
|  | 590 | * | 
|  | 591 | * All of the daemons must be exorcised prior to calling this | 
|  | 592 | * function. | 
|  | 593 | */ | 
|  | 594 | void ecryptfs_destroy_ecryptfs_miscdev(void) | 
|  | 595 | { | 
|  | 596 | BUG_ON(atomic_read(&ecryptfs_num_miscdev_opens) != 0); | 
|  | 597 | misc_deregister(&ecryptfs_miscdev); | 
|  | 598 | } |