Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 9368a53c authored by Gao feng's avatar Gao feng Committed by Pablo Neira Ayuso
Browse files

netfilter: nfnetlink_log: add net namespace support for nfnetlink_log



This patch makes /proc/net/netfilter/nfnetlink_log pernet.
Moreover, there's a pernet instance table and lock.

Signed-off-by: default avatarGao feng <gaofeng@cn.fujitsu.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent 35543067
Loading
Loading
Loading
Loading
+117 −60
Original line number Original line Diff line number Diff line
@@ -32,6 +32,7 @@
#include <linux/slab.h>
#include <linux/slab.h>
#include <net/sock.h>
#include <net/sock.h>
#include <net/netfilter/nf_log.h>
#include <net/netfilter/nf_log.h>
#include <net/netns/generic.h>
#include <net/netfilter/nfnetlink_log.h>
#include <net/netfilter/nfnetlink_log.h>


#include <linux/atomic.h>
#include <linux/atomic.h>
@@ -56,6 +57,7 @@ struct nfulnl_instance {
	unsigned int qlen;		/* number of nlmsgs in skb */
	unsigned int qlen;		/* number of nlmsgs in skb */
	struct sk_buff *skb;		/* pre-allocatd skb */
	struct sk_buff *skb;		/* pre-allocatd skb */
	struct timer_list timer;
	struct timer_list timer;
	struct net *net;
	struct user_namespace *peer_user_ns;	/* User namespace of the peer process */
	struct user_namespace *peer_user_ns;	/* User namespace of the peer process */
	int peer_portid;			/* PORTID of the peer process */
	int peer_portid;			/* PORTID of the peer process */


@@ -71,25 +73,34 @@ struct nfulnl_instance {
	struct rcu_head rcu;
	struct rcu_head rcu;
};
};


static DEFINE_SPINLOCK(instances_lock);
static atomic_t global_seq;

#define INSTANCE_BUCKETS	16
#define INSTANCE_BUCKETS	16
static struct hlist_head instance_table[INSTANCE_BUCKETS];
static unsigned int hash_init;
static unsigned int hash_init;


static int nfnl_log_net_id __read_mostly;

struct nfnl_log_net {
	spinlock_t instances_lock;
	struct hlist_head instance_table[INSTANCE_BUCKETS];
	atomic_t global_seq;
};

static struct nfnl_log_net *nfnl_log_pernet(struct net *net)
{
	return net_generic(net, nfnl_log_net_id);
}

static inline u_int8_t instance_hashfn(u_int16_t group_num)
static inline u_int8_t instance_hashfn(u_int16_t group_num)
{
{
	return ((group_num & 0xff) % INSTANCE_BUCKETS);
	return ((group_num & 0xff) % INSTANCE_BUCKETS);
}
}


static struct nfulnl_instance *
static struct nfulnl_instance *
__instance_lookup(u_int16_t group_num)
__instance_lookup(struct nfnl_log_net *log, u_int16_t group_num)
{
{
	struct hlist_head *head;
	struct hlist_head *head;
	struct nfulnl_instance *inst;
	struct nfulnl_instance *inst;


	head = &instance_table[instance_hashfn(group_num)];
	head = &log->instance_table[instance_hashfn(group_num)];
	hlist_for_each_entry_rcu(inst, head, hlist) {
	hlist_for_each_entry_rcu(inst, head, hlist) {
		if (inst->group_num == group_num)
		if (inst->group_num == group_num)
			return inst;
			return inst;
@@ -104,12 +115,12 @@ instance_get(struct nfulnl_instance *inst)
}
}


static struct nfulnl_instance *
static struct nfulnl_instance *
instance_lookup_get(u_int16_t group_num)
instance_lookup_get(struct nfnl_log_net *log, u_int16_t group_num)
{
{
	struct nfulnl_instance *inst;
	struct nfulnl_instance *inst;


	rcu_read_lock_bh();
	rcu_read_lock_bh();
	inst = __instance_lookup(group_num);
	inst = __instance_lookup(log, group_num);
	if (inst && !atomic_inc_not_zero(&inst->use))
	if (inst && !atomic_inc_not_zero(&inst->use))
		inst = NULL;
		inst = NULL;
	rcu_read_unlock_bh();
	rcu_read_unlock_bh();
@@ -119,7 +130,11 @@ instance_lookup_get(u_int16_t group_num)


static void nfulnl_instance_free_rcu(struct rcu_head *head)
static void nfulnl_instance_free_rcu(struct rcu_head *head)
{
{
	kfree(container_of(head, struct nfulnl_instance, rcu));
	struct nfulnl_instance *inst =
		container_of(head, struct nfulnl_instance, rcu);

	put_net(inst->net);
	kfree(inst);
	module_put(THIS_MODULE);
	module_put(THIS_MODULE);
}
}


@@ -133,13 +148,15 @@ instance_put(struct nfulnl_instance *inst)
static void nfulnl_timer(unsigned long data);
static void nfulnl_timer(unsigned long data);


static struct nfulnl_instance *
static struct nfulnl_instance *
instance_create(u_int16_t group_num, int portid, struct user_namespace *user_ns)
instance_create(struct net *net, u_int16_t group_num,
		int portid, struct user_namespace *user_ns)
{
{
	struct nfulnl_instance *inst;
	struct nfulnl_instance *inst;
	struct nfnl_log_net *log = nfnl_log_pernet(net);
	int err;
	int err;


	spin_lock_bh(&instances_lock);
	spin_lock_bh(&log->instances_lock);
	if (__instance_lookup(group_num)) {
	if (__instance_lookup(log, group_num)) {
		err = -EEXIST;
		err = -EEXIST;
		goto out_unlock;
		goto out_unlock;
	}
	}
@@ -163,6 +180,7 @@ instance_create(u_int16_t group_num, int portid, struct user_namespace *user_ns)


	setup_timer(&inst->timer, nfulnl_timer, (unsigned long)inst);
	setup_timer(&inst->timer, nfulnl_timer, (unsigned long)inst);


	inst->net = get_net(net);
	inst->peer_user_ns = user_ns;
	inst->peer_user_ns = user_ns;
	inst->peer_portid = portid;
	inst->peer_portid = portid;
	inst->group_num = group_num;
	inst->group_num = group_num;
@@ -174,14 +192,15 @@ instance_create(u_int16_t group_num, int portid, struct user_namespace *user_ns)
	inst->copy_range 	= NFULNL_COPY_RANGE_MAX;
	inst->copy_range 	= NFULNL_COPY_RANGE_MAX;


	hlist_add_head_rcu(&inst->hlist,
	hlist_add_head_rcu(&inst->hlist,
		       &instance_table[instance_hashfn(group_num)]);
		       &log->instance_table[instance_hashfn(group_num)]);



	spin_unlock_bh(&instances_lock);
	spin_unlock_bh(&log->instances_lock);


	return inst;
	return inst;


out_unlock:
out_unlock:
	spin_unlock_bh(&instances_lock);
	spin_unlock_bh(&log->instances_lock);
	return ERR_PTR(err);
	return ERR_PTR(err);
}
}


@@ -210,11 +229,12 @@ __instance_destroy(struct nfulnl_instance *inst)
}
}


static inline void
static inline void
instance_destroy(struct nfulnl_instance *inst)
instance_destroy(struct nfnl_log_net *log,
		 struct nfulnl_instance *inst)
{
{
	spin_lock_bh(&instances_lock);
	spin_lock_bh(&log->instances_lock);
	__instance_destroy(inst);
	__instance_destroy(inst);
	spin_unlock_bh(&instances_lock);
	spin_unlock_bh(&log->instances_lock);
}
}


static int
static int
@@ -336,7 +356,7 @@ __nfulnl_send(struct nfulnl_instance *inst)
		if (!nlh)
		if (!nlh)
			goto out;
			goto out;
	}
	}
	status = nfnetlink_unicast(inst->skb, &init_net, inst->peer_portid,
	status = nfnetlink_unicast(inst->skb, inst->net, inst->peer_portid,
				   MSG_DONTWAIT);
				   MSG_DONTWAIT);


	inst->qlen = 0;
	inst->qlen = 0;
@@ -370,7 +390,8 @@ nfulnl_timer(unsigned long data)
/* This is an inline function, we don't really care about a long
/* This is an inline function, we don't really care about a long
 * list of arguments */
 * list of arguments */
static inline int
static inline int
__build_packet_message(struct nfulnl_instance *inst,
__build_packet_message(struct nfnl_log_net *log,
			struct nfulnl_instance *inst,
			const struct sk_buff *skb,
			const struct sk_buff *skb,
			unsigned int data_len,
			unsigned int data_len,
			u_int8_t pf,
			u_int8_t pf,
@@ -536,7 +557,7 @@ __build_packet_message(struct nfulnl_instance *inst,
	/* global sequence number */
	/* global sequence number */
	if ((inst->flags & NFULNL_CFG_F_SEQ_GLOBAL) &&
	if ((inst->flags & NFULNL_CFG_F_SEQ_GLOBAL) &&
	    nla_put_be32(inst->skb, NFULA_SEQ_GLOBAL,
	    nla_put_be32(inst->skb, NFULA_SEQ_GLOBAL,
			 htonl(atomic_inc_return(&global_seq))))
			 htonl(atomic_inc_return(&log->global_seq))))
		goto nla_put_failure;
		goto nla_put_failure;


	if (data_len) {
	if (data_len) {
@@ -592,13 +613,15 @@ nfulnl_log_packet(u_int8_t pf,
	const struct nf_loginfo *li;
	const struct nf_loginfo *li;
	unsigned int qthreshold;
	unsigned int qthreshold;
	unsigned int plen;
	unsigned int plen;
	struct net *net = dev_net(in ? in : out);
	struct nfnl_log_net *log = nfnl_log_pernet(net);


	if (li_user && li_user->type == NF_LOG_TYPE_ULOG)
	if (li_user && li_user->type == NF_LOG_TYPE_ULOG)
		li = li_user;
		li = li_user;
	else
	else
		li = &default_loginfo;
		li = &default_loginfo;


	inst = instance_lookup_get(li->u.ulog.group);
	inst = instance_lookup_get(log, li->u.ulog.group);
	if (!inst)
	if (!inst)
		return;
		return;


@@ -680,7 +703,7 @@ nfulnl_log_packet(u_int8_t pf,


	inst->qlen++;
	inst->qlen++;


	__build_packet_message(inst, skb, data_len, pf,
	__build_packet_message(log, inst, skb, data_len, pf,
				hooknum, in, out, prefix, plen);
				hooknum, in, out, prefix, plen);


	if (inst->qlen >= qthreshold)
	if (inst->qlen >= qthreshold)
@@ -709,24 +732,24 @@ nfulnl_rcv_nl_event(struct notifier_block *this,
		   unsigned long event, void *ptr)
		   unsigned long event, void *ptr)
{
{
	struct netlink_notify *n = ptr;
	struct netlink_notify *n = ptr;
	struct nfnl_log_net *log = nfnl_log_pernet(n->net);


	if (event == NETLINK_URELEASE && n->protocol == NETLINK_NETFILTER) {
	if (event == NETLINK_URELEASE && n->protocol == NETLINK_NETFILTER) {
		int i;
		int i;


		/* destroy all instances for this portid */
		/* destroy all instances for this portid */
		spin_lock_bh(&instances_lock);
		spin_lock_bh(&log->instances_lock);
		for  (i = 0; i < INSTANCE_BUCKETS; i++) {
		for  (i = 0; i < INSTANCE_BUCKETS; i++) {
			struct hlist_node *t2;
			struct hlist_node *t2;
			struct nfulnl_instance *inst;
			struct nfulnl_instance *inst;
			struct hlist_head *head = &instance_table[i];
			struct hlist_head *head = &log->instance_table[i];


			hlist_for_each_entry_safe(inst, t2, head, hlist) {
			hlist_for_each_entry_safe(inst, t2, head, hlist) {
				if ((net_eq(n->net, &init_net)) &&
				if (n->portid == inst->peer_portid)
				    (n->portid == inst->peer_portid))
					__instance_destroy(inst);
					__instance_destroy(inst);
			}
			}
		}
		}
		spin_unlock_bh(&instances_lock);
		spin_unlock_bh(&log->instances_lock);
	}
	}
	return NOTIFY_DONE;
	return NOTIFY_DONE;
}
}
@@ -768,6 +791,7 @@ nfulnl_recv_config(struct sock *ctnl, struct sk_buff *skb,
	struct nfulnl_instance *inst;
	struct nfulnl_instance *inst;
	struct nfulnl_msg_config_cmd *cmd = NULL;
	struct nfulnl_msg_config_cmd *cmd = NULL;
	struct net *net = sock_net(ctnl);
	struct net *net = sock_net(ctnl);
	struct nfnl_log_net *log = nfnl_log_pernet(net);
	int ret = 0;
	int ret = 0;


	if (nfula[NFULA_CFG_CMD]) {
	if (nfula[NFULA_CFG_CMD]) {
@@ -784,7 +808,7 @@ nfulnl_recv_config(struct sock *ctnl, struct sk_buff *skb,
		}
		}
	}
	}


	inst = instance_lookup_get(group_num);
	inst = instance_lookup_get(log, group_num);
	if (inst && inst->peer_portid != NETLINK_CB(skb).portid) {
	if (inst && inst->peer_portid != NETLINK_CB(skb).portid) {
		ret = -EPERM;
		ret = -EPERM;
		goto out_put;
		goto out_put;
@@ -798,7 +822,7 @@ nfulnl_recv_config(struct sock *ctnl, struct sk_buff *skb,
				goto out_put;
				goto out_put;
			}
			}


			inst = instance_create(group_num,
			inst = instance_create(net, group_num,
					       NETLINK_CB(skb).portid,
					       NETLINK_CB(skb).portid,
					       sk_user_ns(NETLINK_CB(skb).ssk));
					       sk_user_ns(NETLINK_CB(skb).ssk));
			if (IS_ERR(inst)) {
			if (IS_ERR(inst)) {
@@ -812,7 +836,7 @@ nfulnl_recv_config(struct sock *ctnl, struct sk_buff *skb,
				goto out;
				goto out;
			}
			}


			instance_destroy(inst);
			instance_destroy(log, inst);
			goto out_put;
			goto out_put;
		default:
		default:
			ret = -ENOTSUPP;
			ret = -ENOTSUPP;
@@ -895,55 +919,68 @@ static const struct nfnetlink_subsystem nfulnl_subsys = {


#ifdef CONFIG_PROC_FS
#ifdef CONFIG_PROC_FS
struct iter_state {
struct iter_state {
	struct seq_net_private p;
	unsigned int bucket;
	unsigned int bucket;
};
};


static struct hlist_node *get_first(struct iter_state *st)
static struct hlist_node *get_first(struct net *net, struct iter_state *st)
{
{
	struct nfnl_log_net *log;
	if (!st)
	if (!st)
		return NULL;
		return NULL;


	log = nfnl_log_pernet(net);

	for (st->bucket = 0; st->bucket < INSTANCE_BUCKETS; st->bucket++) {
	for (st->bucket = 0; st->bucket < INSTANCE_BUCKETS; st->bucket++) {
		if (!hlist_empty(&instance_table[st->bucket]))
		struct hlist_head *head = &log->instance_table[st->bucket];
			return rcu_dereference_bh(hlist_first_rcu(&instance_table[st->bucket]));

		if (!hlist_empty(head))
			return rcu_dereference_bh(hlist_first_rcu(head));
	}
	}
	return NULL;
	return NULL;
}
}


static struct hlist_node *get_next(struct iter_state *st, struct hlist_node *h)
static struct hlist_node *get_next(struct net *net, struct iter_state *st,
				   struct hlist_node *h)
{
{
	h = rcu_dereference_bh(hlist_next_rcu(h));
	h = rcu_dereference_bh(hlist_next_rcu(h));
	while (!h) {
	while (!h) {
		struct nfnl_log_net *log;
		struct hlist_head *head;

		if (++st->bucket >= INSTANCE_BUCKETS)
		if (++st->bucket >= INSTANCE_BUCKETS)
			return NULL;
			return NULL;


		h = rcu_dereference_bh(hlist_first_rcu(&instance_table[st->bucket]));
		log = nfnl_log_pernet(net);
		head = &log->instance_table[st->bucket];
		h = rcu_dereference_bh(hlist_first_rcu(head));
	}
	}
	return h;
	return h;
}
}


static struct hlist_node *get_idx(struct iter_state *st, loff_t pos)
static struct hlist_node *get_idx(struct net *net, struct iter_state *st,
				  loff_t pos)
{
{
	struct hlist_node *head;
	struct hlist_node *head;
	head = get_first(st);
	head = get_first(net, st);


	if (head)
	if (head)
		while (pos && (head = get_next(st, head)))
		while (pos && (head = get_next(net, st, head)))
			pos--;
			pos--;
	return pos ? NULL : head;
	return pos ? NULL : head;
}
}


static void *seq_start(struct seq_file *seq, loff_t *pos)
static void *seq_start(struct seq_file *s, loff_t *pos)
	__acquires(rcu_bh)
	__acquires(rcu_bh)
{
{
	rcu_read_lock_bh();
	rcu_read_lock_bh();
	return get_idx(seq->private, *pos);
	return get_idx(seq_file_net(s), s->private, *pos);
}
}


static void *seq_next(struct seq_file *s, void *v, loff_t *pos)
static void *seq_next(struct seq_file *s, void *v, loff_t *pos)
{
{
	(*pos)++;
	(*pos)++;
	return get_next(s->private, v);
	return get_next(seq_file_net(s), s->private, v);
}
}


static void seq_stop(struct seq_file *s, void *v)
static void seq_stop(struct seq_file *s, void *v)
@@ -972,7 +1009,7 @@ static const struct seq_operations nful_seq_ops = {


static int nful_open(struct inode *inode, struct file *file)
static int nful_open(struct inode *inode, struct file *file)
{
{
	return seq_open_private(file, &nful_seq_ops,
	return seq_open_net(inode, file, &nful_seq_ops,
			    sizeof(struct iter_state));
			    sizeof(struct iter_state));
}
}


@@ -981,17 +1018,43 @@ static const struct file_operations nful_file_ops = {
	.open	 = nful_open,
	.open	 = nful_open,
	.read	 = seq_read,
	.read	 = seq_read,
	.llseek	 = seq_lseek,
	.llseek	 = seq_lseek,
	.release = seq_release_private,
	.release = seq_release_net,
};
};


#endif /* PROC_FS */
#endif /* PROC_FS */


static int __init nfnetlink_log_init(void)
static int __net_init nfnl_log_net_init(struct net *net)
{
{
	int i, status = -ENOMEM;
	unsigned int i;
	struct nfnl_log_net *log = nfnl_log_pernet(net);


	for (i = 0; i < INSTANCE_BUCKETS; i++)
	for (i = 0; i < INSTANCE_BUCKETS; i++)
		INIT_HLIST_HEAD(&instance_table[i]);
		INIT_HLIST_HEAD(&log->instance_table[i]);
	spin_lock_init(&log->instances_lock);

#ifdef CONFIG_PROC_FS
	if (!proc_create("nfnetlink_log", 0440,
			 net->nf.proc_netfilter, &nful_file_ops))
		return -ENOMEM;
#endif
	return 0;
}

static void __net_exit nfnl_log_net_exit(struct net *net)
{
	remove_proc_entry("nfnetlink_log", net->nf.proc_netfilter);
}

static struct pernet_operations nfnl_log_net_ops = {
	.init	= nfnl_log_net_init,
	.exit	= nfnl_log_net_exit,
	.id	= &nfnl_log_net_id,
	.size	= sizeof(struct nfnl_log_net),
};

static int __init nfnetlink_log_init(void)
{
	int status = -ENOMEM;


	/* it's not really all that important to have a random value, so
	/* it's not really all that important to have a random value, so
	 * we can do this from the init function, even if there hasn't
	 * we can do this from the init function, even if there hasn't
@@ -1001,29 +1064,25 @@ static int __init nfnetlink_log_init(void)
	netlink_register_notifier(&nfulnl_rtnl_notifier);
	netlink_register_notifier(&nfulnl_rtnl_notifier);
	status = nfnetlink_subsys_register(&nfulnl_subsys);
	status = nfnetlink_subsys_register(&nfulnl_subsys);
	if (status < 0) {
	if (status < 0) {
		printk(KERN_ERR "log: failed to create netlink socket\n");
		pr_err("log: failed to create netlink socket\n");
		goto cleanup_netlink_notifier;
		goto cleanup_netlink_notifier;
	}
	}


	status = nf_log_register(NFPROTO_UNSPEC, &nfulnl_logger);
	status = nf_log_register(NFPROTO_UNSPEC, &nfulnl_logger);
	if (status < 0) {
	if (status < 0) {
		printk(KERN_ERR "log: failed to register logger\n");
		pr_err("log: failed to register logger\n");
		goto cleanup_subsys;
		goto cleanup_subsys;
	}
	}


#ifdef CONFIG_PROC_FS
	status = register_pernet_subsys(&nfnl_log_net_ops);
	if (!proc_create("nfnetlink_log", 0440,
	if (status < 0) {
			 proc_net_netfilter, &nful_file_ops)) {
		pr_err("log: failed to register pernet ops\n");
		status = -ENOMEM;
		goto cleanup_logger;
		goto cleanup_logger;
	}
	}
#endif
	return status;
	return status;


#ifdef CONFIG_PROC_FS
cleanup_logger:
cleanup_logger:
	nf_log_unregister(&nfulnl_logger);
	nf_log_unregister(&nfulnl_logger);
#endif
cleanup_subsys:
cleanup_subsys:
	nfnetlink_subsys_unregister(&nfulnl_subsys);
	nfnetlink_subsys_unregister(&nfulnl_subsys);
cleanup_netlink_notifier:
cleanup_netlink_notifier:
@@ -1033,10 +1092,8 @@ static int __init nfnetlink_log_init(void)


static void __exit nfnetlink_log_fini(void)
static void __exit nfnetlink_log_fini(void)
{
{
	unregister_pernet_subsys(&nfnl_log_net_ops);
	nf_log_unregister(&nfulnl_logger);
	nf_log_unregister(&nfulnl_logger);
#ifdef CONFIG_PROC_FS
	remove_proc_entry("nfnetlink_log", proc_net_netfilter);
#endif
	nfnetlink_subsys_unregister(&nfulnl_subsys);
	nfnetlink_subsys_unregister(&nfulnl_subsys);
	netlink_unregister_notifier(&nfulnl_rtnl_notifier);
	netlink_unregister_notifier(&nfulnl_rtnl_notifier);
}
}