tun: reserves space for network in skb
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / drivers / net / tun.c
CommitLineData
1da177e4
LT
1/*
2 * TUN - Universal TUN/TAP device driver.
3 * Copyright (C) 1999-2002 Maxim Krasnyansky <maxk@qualcomm.com>
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
9 *
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * $Id: tun.c,v 1.15 2002/03/01 02:44:24 maxk Exp $
16 */
17
18/*
19 * Changes:
20 *
ff4cc3ac
MK
21 * Mike Kershaw <dragorn@kismetwireless.net> 2005/08/14
22 * Add TUNSETLINK ioctl to set the link encapsulation
23 *
1da177e4 24 * Mark Smith <markzzzsmith@yahoo.com.au>
f271b2cc 25 * Use random_ether_addr() for tap MAC address.
1da177e4
LT
26 *
27 * Harald Roelle <harald.roelle@ifi.lmu.de> 2004/04/20
28 * Fixes in packet dropping, queue length setting and queue wakeup.
29 * Increased default tx queue length.
30 * Added ethtool API.
31 * Minor cleanups
32 *
33 * Daniel Podlejski <underley@underley.eu.org>
34 * Modifications for 2.3.99-pre5 kernel.
35 */
36
6b8a66ee
JP
37#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
38
1da177e4
LT
39#define DRV_NAME "tun"
40#define DRV_VERSION "1.6"
41#define DRV_DESCRIPTION "Universal TUN/TAP device driver"
42#define DRV_COPYRIGHT "(C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>"
43
1da177e4
LT
44#include <linux/module.h>
45#include <linux/errno.h>
46#include <linux/kernel.h>
47#include <linux/major.h>
48#include <linux/slab.h>
49#include <linux/poll.h>
50#include <linux/fcntl.h>
51#include <linux/init.h>
52#include <linux/skbuff.h>
53#include <linux/netdevice.h>
54#include <linux/etherdevice.h>
55#include <linux/miscdevice.h>
56#include <linux/ethtool.h>
57#include <linux/rtnetlink.h>
50857e2a 58#include <linux/compat.h>
1da177e4
LT
59#include <linux/if.h>
60#include <linux/if_arp.h>
61#include <linux/if_ether.h>
62#include <linux/if_tun.h>
63#include <linux/crc32.h>
d647a591 64#include <linux/nsproxy.h>
f43798c2 65#include <linux/virtio_net.h>
99405162 66#include <linux/rcupdate.h>
881d966b 67#include <net/net_namespace.h>
79d17604 68#include <net/netns/generic.h>
f019a7a5 69#include <net/rtnetlink.h>
33dccbb0 70#include <net/sock.h>
1da177e4
LT
71
72#include <asm/system.h>
73#include <asm/uaccess.h>
74
14daa021
RR
75/* Uncomment to enable debugging */
76/* #define TUN_DEBUG 1 */
77
1da177e4
LT
78#ifdef TUN_DEBUG
79static int debug;
14daa021 80
6b8a66ee
JP
81#define tun_debug(level, tun, fmt, args...) \
82do { \
83 if (tun->debug) \
84 netdev_printk(level, tun->dev, fmt, ##args); \
85} while (0)
86#define DBG1(level, fmt, args...) \
87do { \
88 if (debug == 2) \
89 printk(level fmt, ##args); \
90} while (0)
14daa021 91#else
6b8a66ee
JP
92#define tun_debug(level, tun, fmt, args...) \
93do { \
94 if (0) \
95 netdev_printk(level, tun->dev, fmt, ##args); \
96} while (0)
97#define DBG1(level, fmt, args...) \
98do { \
99 if (0) \
100 printk(level fmt, ##args); \
101} while (0)
14daa021
RR
102#endif
103
f271b2cc
MK
104#define FLT_EXACT_COUNT 8
105struct tap_filter {
106 unsigned int count; /* Number of addrs. Zero means disabled */
107 u32 mask[2]; /* Mask of the hashed addrs */
108 unsigned char addr[FLT_EXACT_COUNT][ETH_ALEN];
109};
110
631ab46b 111struct tun_file {
c70f1829 112 atomic_t count;
631ab46b 113 struct tun_struct *tun;
36b50bab 114 struct net *net;
631ab46b
EB
115};
116
33dccbb0
HX
117struct tun_sock;
118
14daa021 119struct tun_struct {
631ab46b 120 struct tun_file *tfile;
f271b2cc 121 unsigned int flags;
14daa021
RR
122 uid_t owner;
123 gid_t group;
124
14daa021 125 struct net_device *dev;
88255375
MM
126 u32 set_features;
127#define TUN_USER_FEATURES (NETIF_F_HW_CSUM|NETIF_F_TSO_ECN|NETIF_F_TSO| \
128 NETIF_F_TSO6|NETIF_F_UFO)
f271b2cc 129 struct fasync_struct *fasync;
14daa021 130
f271b2cc 131 struct tap_filter txflt;
33dccbb0 132 struct socket socket;
43815482 133 struct socket_wq wq;
d9d52b51
MT
134
135 int vnet_hdr_sz;
136
14daa021
RR
137#ifdef TUN_DEBUG
138 int debug;
1da177e4 139#endif
14daa021 140};
1da177e4 141
33dccbb0
HX
142struct tun_sock {
143 struct sock sk;
144 struct tun_struct *tun;
145};
146
147static inline struct tun_sock *tun_sk(struct sock *sk)
148{
149 return container_of(sk, struct tun_sock, sk);
150}
151
a7385ba2
EB
152static int tun_attach(struct tun_struct *tun, struct file *file)
153{
631ab46b 154 struct tun_file *tfile = file->private_data;
38231b7a 155 int err;
a7385ba2
EB
156
157 ASSERT_RTNL();
158
38231b7a
EB
159 netif_tx_lock_bh(tun->dev);
160
161 err = -EINVAL;
162 if (tfile->tun)
163 goto out;
164
165 err = -EBUSY;
166 if (tun->tfile)
167 goto out;
168
169 err = 0;
631ab46b
EB
170 tfile->tun = tun;
171 tun->tfile = tfile;
05c2828c 172 tun->socket.file = file;
bee31369 173 netif_carrier_on(tun->dev);
c70f1829 174 dev_hold(tun->dev);
89f56d1e 175 sock_hold(tun->socket.sk);
c70f1829 176 atomic_inc(&tfile->count);
a7385ba2 177
38231b7a
EB
178out:
179 netif_tx_unlock_bh(tun->dev);
180 return err;
a7385ba2
EB
181}
182
631ab46b
EB
183static void __tun_detach(struct tun_struct *tun)
184{
631ab46b 185 /* Detach from net device */
38231b7a 186 netif_tx_lock_bh(tun->dev);
bee31369 187 netif_carrier_off(tun->dev);
631ab46b 188 tun->tfile = NULL;
05c2828c 189 tun->socket.file = NULL;
38231b7a 190 netif_tx_unlock_bh(tun->dev);
631ab46b
EB
191
192 /* Drop read queue */
89f56d1e 193 skb_queue_purge(&tun->socket.sk->sk_receive_queue);
c70f1829
EB
194
195 /* Drop the extra count on the net device */
196 dev_put(tun->dev);
197}
198
199static void tun_detach(struct tun_struct *tun)
200{
201 rtnl_lock();
202 __tun_detach(tun);
203 rtnl_unlock();
631ab46b
EB
204}
205
206static struct tun_struct *__tun_get(struct tun_file *tfile)
207{
c70f1829
EB
208 struct tun_struct *tun = NULL;
209
210 if (atomic_inc_not_zero(&tfile->count))
211 tun = tfile->tun;
212
213 return tun;
631ab46b
EB
214}
215
216static struct tun_struct *tun_get(struct file *file)
217{
218 return __tun_get(file->private_data);
219}
220
221static void tun_put(struct tun_struct *tun)
222{
c70f1829
EB
223 struct tun_file *tfile = tun->tfile;
224
225 if (atomic_dec_and_test(&tfile->count))
226 tun_detach(tfile->tun);
631ab46b
EB
227}
228
6b8a66ee 229/* TAP filtering */
f271b2cc
MK
230static void addr_hash_set(u32 *mask, const u8 *addr)
231{
232 int n = ether_crc(ETH_ALEN, addr) >> 26;
233 mask[n >> 5] |= (1 << (n & 31));
234}
235
236static unsigned int addr_hash_test(const u32 *mask, const u8 *addr)
237{
238 int n = ether_crc(ETH_ALEN, addr) >> 26;
239 return mask[n >> 5] & (1 << (n & 31));
240}
241
242static int update_filter(struct tap_filter *filter, void __user *arg)
243{
244 struct { u8 u[ETH_ALEN]; } *addr;
245 struct tun_filter uf;
246 int err, alen, n, nexact;
247
248 if (copy_from_user(&uf, arg, sizeof(uf)))
249 return -EFAULT;
250
251 if (!uf.count) {
252 /* Disabled */
253 filter->count = 0;
254 return 0;
255 }
256
257 alen = ETH_ALEN * uf.count;
258 addr = kmalloc(alen, GFP_KERNEL);
259 if (!addr)
260 return -ENOMEM;
261
262 if (copy_from_user(addr, arg + sizeof(uf), alen)) {
263 err = -EFAULT;
264 goto done;
265 }
266
267 /* The filter is updated without holding any locks. Which is
268 * perfectly safe. We disable it first and in the worst
269 * case we'll accept a few undesired packets. */
270 filter->count = 0;
271 wmb();
272
273 /* Use first set of addresses as an exact filter */
274 for (n = 0; n < uf.count && n < FLT_EXACT_COUNT; n++)
275 memcpy(filter->addr[n], addr[n].u, ETH_ALEN);
276
277 nexact = n;
278
cfbf84fc
AW
279 /* Remaining multicast addresses are hashed,
280 * unicast will leave the filter disabled. */
f271b2cc 281 memset(filter->mask, 0, sizeof(filter->mask));
cfbf84fc
AW
282 for (; n < uf.count; n++) {
283 if (!is_multicast_ether_addr(addr[n].u)) {
284 err = 0; /* no filter */
285 goto done;
286 }
f271b2cc 287 addr_hash_set(filter->mask, addr[n].u);
cfbf84fc 288 }
f271b2cc
MK
289
290 /* For ALLMULTI just set the mask to all ones.
291 * This overrides the mask populated above. */
292 if ((uf.flags & TUN_FLT_ALLMULTI))
293 memset(filter->mask, ~0, sizeof(filter->mask));
294
295 /* Now enable the filter */
296 wmb();
297 filter->count = nexact;
298
299 /* Return the number of exact filters */
300 err = nexact;
301
302done:
303 kfree(addr);
304 return err;
305}
306
307/* Returns: 0 - drop, !=0 - accept */
308static int run_filter(struct tap_filter *filter, const struct sk_buff *skb)
309{
310 /* Cannot use eth_hdr(skb) here because skb_mac_hdr() is incorrect
311 * at this point. */
312 struct ethhdr *eh = (struct ethhdr *) skb->data;
313 int i;
314
315 /* Exact match */
316 for (i = 0; i < filter->count; i++)
317 if (!compare_ether_addr(eh->h_dest, filter->addr[i]))
318 return 1;
319
320 /* Inexact match (multicast only) */
321 if (is_multicast_ether_addr(eh->h_dest))
322 return addr_hash_test(filter->mask, eh->h_dest);
323
324 return 0;
325}
326
327/*
328 * Checks whether the packet is accepted or not.
329 * Returns: 0 - drop, !=0 - accept
330 */
331static int check_filter(struct tap_filter *filter, const struct sk_buff *skb)
332{
333 if (!filter->count)
334 return 1;
335
336 return run_filter(filter, skb);
337}
338
1da177e4
LT
339/* Network device part of the driver */
340
7282d491 341static const struct ethtool_ops tun_ethtool_ops;
1da177e4 342
c70f1829
EB
343/* Net device detach from fd. */
344static void tun_net_uninit(struct net_device *dev)
345{
346 struct tun_struct *tun = netdev_priv(dev);
347 struct tun_file *tfile = tun->tfile;
348
349 /* Inform the methods they need to stop using the dev.
350 */
351 if (tfile) {
43815482 352 wake_up_all(&tun->wq.wait);
c70f1829
EB
353 if (atomic_dec_and_test(&tfile->count))
354 __tun_detach(tun);
355 }
356}
357
9c3fea6a
HX
358static void tun_free_netdev(struct net_device *dev)
359{
360 struct tun_struct *tun = netdev_priv(dev);
361
89f56d1e 362 sock_put(tun->socket.sk);
9c3fea6a
HX
363}
364
1da177e4
LT
365/* Net device open. */
366static int tun_net_open(struct net_device *dev)
367{
368 netif_start_queue(dev);
369 return 0;
370}
371
372/* Net device close. */
373static int tun_net_close(struct net_device *dev)
374{
375 netif_stop_queue(dev);
376 return 0;
377}
378
379/* Net device start xmit */
424efe9c 380static netdev_tx_t tun_net_xmit(struct sk_buff *skb, struct net_device *dev)
1da177e4
LT
381{
382 struct tun_struct *tun = netdev_priv(dev);
383
6b8a66ee 384 tun_debug(KERN_INFO, tun, "tun_net_xmit %d\n", skb->len);
1da177e4
LT
385
386 /* Drop packet if interface is not attached */
631ab46b 387 if (!tun->tfile)
1da177e4
LT
388 goto drop;
389
f271b2cc
MK
390 /* Drop if the filter does not like it.
391 * This is a noop if the filter is disabled.
392 * Filter can be enabled only for the TAP devices. */
393 if (!check_filter(&tun->txflt, skb))
394 goto drop;
395
99405162
MT
396 if (tun->socket.sk->sk_filter &&
397 sk_filter(tun->socket.sk, skb))
398 goto drop;
399
89f56d1e 400 if (skb_queue_len(&tun->socket.sk->sk_receive_queue) >= dev->tx_queue_len) {
1da177e4
LT
401 if (!(tun->flags & TUN_ONE_QUEUE)) {
402 /* Normal queueing mode. */
403 /* Packet scheduler handles dropping of further packets. */
404 netif_stop_queue(dev);
405
406 /* We won't see all dropped packets individually, so overrun
407 * error is more appropriate. */
09f75cd7 408 dev->stats.tx_fifo_errors++;
1da177e4
LT
409 } else {
410 /* Single queue mode.
411 * Driver handles dropping of all packets itself. */
412 goto drop;
413 }
414 }
415
0110d6f2
MT
416 /* Orphan the skb - required as we might hang on to it
417 * for indefinite time. */
418 skb_orphan(skb);
419
f271b2cc 420 /* Enqueue packet */
89f56d1e 421 skb_queue_tail(&tun->socket.sk->sk_receive_queue, skb);
1da177e4
LT
422
423 /* Notify and wake up reader process */
424 if (tun->flags & TUN_FASYNC)
425 kill_fasync(&tun->fasync, SIGIO, POLL_IN);
43815482 426 wake_up_interruptible_poll(&tun->wq.wait, POLLIN |
05c2828c 427 POLLRDNORM | POLLRDBAND);
6ed10654 428 return NETDEV_TX_OK;
1da177e4
LT
429
430drop:
09f75cd7 431 dev->stats.tx_dropped++;
1da177e4 432 kfree_skb(skb);
6ed10654 433 return NETDEV_TX_OK;
1da177e4
LT
434}
435
f271b2cc 436static void tun_net_mclist(struct net_device *dev)
1da177e4 437{
f271b2cc
MK
438 /*
439 * This callback is supposed to deal with mc filter in
440 * _rx_ path and has nothing to do with the _tx_ path.
441 * In rx path we always accept everything userspace gives us.
442 */
1da177e4
LT
443}
444
4885a504
ES
445#define MIN_MTU 68
446#define MAX_MTU 65535
447
448static int
449tun_net_change_mtu(struct net_device *dev, int new_mtu)
450{
451 if (new_mtu < MIN_MTU || new_mtu + dev->hard_header_len > MAX_MTU)
452 return -EINVAL;
453 dev->mtu = new_mtu;
454 return 0;
455}
456
88255375
MM
457static u32 tun_net_fix_features(struct net_device *dev, u32 features)
458{
459 struct tun_struct *tun = netdev_priv(dev);
460
461 return (features & tun->set_features) | (features & ~TUN_USER_FEATURES);
462}
463
758e43b7 464static const struct net_device_ops tun_netdev_ops = {
c70f1829 465 .ndo_uninit = tun_net_uninit,
758e43b7
SH
466 .ndo_open = tun_net_open,
467 .ndo_stop = tun_net_close,
00829823 468 .ndo_start_xmit = tun_net_xmit,
758e43b7 469 .ndo_change_mtu = tun_net_change_mtu,
88255375 470 .ndo_fix_features = tun_net_fix_features,
758e43b7
SH
471};
472
473static const struct net_device_ops tap_netdev_ops = {
c70f1829 474 .ndo_uninit = tun_net_uninit,
758e43b7
SH
475 .ndo_open = tun_net_open,
476 .ndo_stop = tun_net_close,
00829823 477 .ndo_start_xmit = tun_net_xmit,
758e43b7 478 .ndo_change_mtu = tun_net_change_mtu,
88255375 479 .ndo_fix_features = tun_net_fix_features,
758e43b7
SH
480 .ndo_set_multicast_list = tun_net_mclist,
481 .ndo_set_mac_address = eth_mac_addr,
482 .ndo_validate_addr = eth_validate_addr,
483};
484
1da177e4
LT
485/* Initialize net device. */
486static void tun_net_init(struct net_device *dev)
487{
488 struct tun_struct *tun = netdev_priv(dev);
6aa20a22 489
1da177e4
LT
490 switch (tun->flags & TUN_TYPE_MASK) {
491 case TUN_TUN_DEV:
758e43b7
SH
492 dev->netdev_ops = &tun_netdev_ops;
493
1da177e4
LT
494 /* Point-to-Point TUN Device */
495 dev->hard_header_len = 0;
496 dev->addr_len = 0;
497 dev->mtu = 1500;
498
499 /* Zero header length */
6aa20a22 500 dev->type = ARPHRD_NONE;
1da177e4
LT
501 dev->flags = IFF_POINTOPOINT | IFF_NOARP | IFF_MULTICAST;
502 dev->tx_queue_len = TUN_READQ_SIZE; /* We prefer our own queue length */
503 break;
504
505 case TUN_TAP_DEV:
7a0a9608 506 dev->netdev_ops = &tap_netdev_ops;
1da177e4 507 /* Ethernet TAP Device */
1da177e4 508 ether_setup(dev);
36226a8d 509
f271b2cc 510 random_ether_addr(dev->dev_addr);
36226a8d 511
1da177e4
LT
512 dev->tx_queue_len = TUN_READQ_SIZE; /* We prefer our own queue length */
513 break;
514 }
515}
516
517/* Character device part */
518
519/* Poll */
520static unsigned int tun_chr_poll(struct file *file, poll_table * wait)
6aa20a22 521{
b2430de3
EB
522 struct tun_file *tfile = file->private_data;
523 struct tun_struct *tun = __tun_get(tfile);
3c8a9c63 524 struct sock *sk;
33dccbb0 525 unsigned int mask = 0;
1da177e4
LT
526
527 if (!tun)
eac9e902 528 return POLLERR;
1da177e4 529
89f56d1e 530 sk = tun->socket.sk;
3c8a9c63 531
6b8a66ee 532 tun_debug(KERN_INFO, tun, "tun_chr_poll\n");
1da177e4 533
43815482 534 poll_wait(file, &tun->wq.wait, wait);
6aa20a22 535
89f56d1e 536 if (!skb_queue_empty(&sk->sk_receive_queue))
1da177e4
LT
537 mask |= POLLIN | POLLRDNORM;
538
33dccbb0
HX
539 if (sock_writeable(sk) ||
540 (!test_and_set_bit(SOCK_ASYNC_NOSPACE, &sk->sk_socket->flags) &&
541 sock_writeable(sk)))
542 mask |= POLLOUT | POLLWRNORM;
543
c70f1829
EB
544 if (tun->dev->reg_state != NETREG_REGISTERED)
545 mask = POLLERR;
546
631ab46b 547 tun_put(tun);
1da177e4
LT
548 return mask;
549}
550
f42157cb
RR
551/* prepad is the amount to reserve at front. len is length after that.
552 * linear is a hint as to how much to copy (usually headers). */
33dccbb0
HX
553static inline struct sk_buff *tun_alloc_skb(struct tun_struct *tun,
554 size_t prepad, size_t len,
555 size_t linear, int noblock)
f42157cb 556{
89f56d1e 557 struct sock *sk = tun->socket.sk;
f42157cb 558 struct sk_buff *skb;
33dccbb0 559 int err;
f42157cb 560
82862742
HX
561 sock_update_classid(sk);
562
f42157cb 563 /* Under a page? Don't bother with paged skb. */
0eca93bc 564 if (prepad + len < PAGE_SIZE || !linear)
33dccbb0 565 linear = len;
f42157cb 566
33dccbb0
HX
567 skb = sock_alloc_send_pskb(sk, prepad + linear, len - linear, noblock,
568 &err);
f42157cb 569 if (!skb)
33dccbb0 570 return ERR_PTR(err);
f42157cb
RR
571
572 skb_reserve(skb, prepad);
573 skb_put(skb, linear);
33dccbb0
HX
574 skb->data_len = len - linear;
575 skb->len += len - linear;
f42157cb
RR
576
577 return skb;
578}
579
1da177e4 580/* Get packet from user space buffer */
33dccbb0 581static __inline__ ssize_t tun_get_user(struct tun_struct *tun,
6f26c9a7 582 const struct iovec *iv, size_t count,
33dccbb0 583 int noblock)
1da177e4 584{
09640e63 585 struct tun_pi pi = { 0, cpu_to_be16(ETH_P_IP) };
1da177e4 586 struct sk_buff *skb;
a504b86e 587 size_t len = count, align = NET_SKB_PAD;
f43798c2 588 struct virtio_net_hdr gso = { 0 };
6f26c9a7 589 int offset = 0;
1da177e4
LT
590
591 if (!(tun->flags & TUN_NO_PI)) {
592 if ((len -= sizeof(pi)) > count)
593 return -EINVAL;
594
6f26c9a7 595 if (memcpy_fromiovecend((void *)&pi, iv, 0, sizeof(pi)))
1da177e4 596 return -EFAULT;
6f26c9a7 597 offset += sizeof(pi);
1da177e4
LT
598 }
599
f43798c2 600 if (tun->flags & TUN_VNET_HDR) {
d9d52b51 601 if ((len -= tun->vnet_hdr_sz) > count)
f43798c2
RR
602 return -EINVAL;
603
6f26c9a7 604 if (memcpy_fromiovecend((void *)&gso, iv, offset, sizeof(gso)))
f43798c2
RR
605 return -EFAULT;
606
4909122f
HX
607 if ((gso.flags & VIRTIO_NET_HDR_F_NEEDS_CSUM) &&
608 gso.csum_start + gso.csum_offset + 2 > gso.hdr_len)
609 gso.hdr_len = gso.csum_start + gso.csum_offset + 2;
610
f43798c2
RR
611 if (gso.hdr_len > len)
612 return -EINVAL;
d9d52b51 613 offset += tun->vnet_hdr_sz;
f43798c2
RR
614 }
615
e01bf1c8 616 if ((tun->flags & TUN_TYPE_MASK) == TUN_TAP_DEV) {
a504b86e 617 align += NET_IP_ALIGN;
0eca93bc
HX
618 if (unlikely(len < ETH_HLEN ||
619 (gso.hdr_len && gso.hdr_len < ETH_HLEN)))
e01bf1c8
RR
620 return -EINVAL;
621 }
6aa20a22 622
33dccbb0
HX
623 skb = tun_alloc_skb(tun, align, len, gso.hdr_len, noblock);
624 if (IS_ERR(skb)) {
625 if (PTR_ERR(skb) != -EAGAIN)
626 tun->dev->stats.rx_dropped++;
627 return PTR_ERR(skb);
1da177e4
LT
628 }
629
6f26c9a7 630 if (skb_copy_datagram_from_iovec(skb, 0, iv, offset, len)) {
09f75cd7 631 tun->dev->stats.rx_dropped++;
8f22757e 632 kfree_skb(skb);
1da177e4 633 return -EFAULT;
8f22757e 634 }
1da177e4 635
f43798c2
RR
636 if (gso.flags & VIRTIO_NET_HDR_F_NEEDS_CSUM) {
637 if (!skb_partial_csum_set(skb, gso.csum_start,
638 gso.csum_offset)) {
639 tun->dev->stats.rx_frame_errors++;
640 kfree_skb(skb);
641 return -EINVAL;
642 }
88255375 643 }
f43798c2 644
1da177e4
LT
645 switch (tun->flags & TUN_TYPE_MASK) {
646 case TUN_TUN_DEV:
f09f7ee2
AWC
647 if (tun->flags & TUN_NO_PI) {
648 switch (skb->data[0] & 0xf0) {
649 case 0x40:
650 pi.proto = htons(ETH_P_IP);
651 break;
652 case 0x60:
653 pi.proto = htons(ETH_P_IPV6);
654 break;
655 default:
656 tun->dev->stats.rx_dropped++;
657 kfree_skb(skb);
658 return -EINVAL;
659 }
660 }
661
459a98ed 662 skb_reset_mac_header(skb);
1da177e4 663 skb->protocol = pi.proto;
4c13eb66 664 skb->dev = tun->dev;
1da177e4
LT
665 break;
666 case TUN_TAP_DEV:
667 skb->protocol = eth_type_trans(skb, tun->dev);
668 break;
6403eab1 669 }
1da177e4 670
f43798c2
RR
671 if (gso.gso_type != VIRTIO_NET_HDR_GSO_NONE) {
672 pr_debug("GSO!\n");
673 switch (gso.gso_type & ~VIRTIO_NET_HDR_GSO_ECN) {
674 case VIRTIO_NET_HDR_GSO_TCPV4:
675 skb_shinfo(skb)->gso_type = SKB_GSO_TCPV4;
676 break;
677 case VIRTIO_NET_HDR_GSO_TCPV6:
678 skb_shinfo(skb)->gso_type = SKB_GSO_TCPV6;
679 break;
e36aa25a
SS
680 case VIRTIO_NET_HDR_GSO_UDP:
681 skb_shinfo(skb)->gso_type = SKB_GSO_UDP;
682 break;
f43798c2
RR
683 default:
684 tun->dev->stats.rx_frame_errors++;
685 kfree_skb(skb);
686 return -EINVAL;
687 }
688
689 if (gso.gso_type & VIRTIO_NET_HDR_GSO_ECN)
690 skb_shinfo(skb)->gso_type |= SKB_GSO_TCP_ECN;
691
692 skb_shinfo(skb)->gso_size = gso.gso_size;
693 if (skb_shinfo(skb)->gso_size == 0) {
694 tun->dev->stats.rx_frame_errors++;
695 kfree_skb(skb);
696 return -EINVAL;
697 }
698
699 /* Header must be checked, and gso_segs computed. */
700 skb_shinfo(skb)->gso_type |= SKB_GSO_DODGY;
701 skb_shinfo(skb)->gso_segs = 0;
702 }
6aa20a22 703
1da177e4 704 netif_rx_ni(skb);
6aa20a22 705
09f75cd7
JG
706 tun->dev->stats.rx_packets++;
707 tun->dev->stats.rx_bytes += len;
1da177e4
LT
708
709 return count;
6aa20a22 710}
1da177e4 711
ee0b3e67
BP
712static ssize_t tun_chr_aio_write(struct kiocb *iocb, const struct iovec *iv,
713 unsigned long count, loff_t pos)
1da177e4 714{
33dccbb0 715 struct file *file = iocb->ki_filp;
ab46d779 716 struct tun_struct *tun = tun_get(file);
631ab46b 717 ssize_t result;
1da177e4
LT
718
719 if (!tun)
720 return -EBADFD;
721
6b8a66ee 722 tun_debug(KERN_INFO, tun, "tun_chr_write %ld\n", count);
1da177e4 723
6f26c9a7 724 result = tun_get_user(tun, iv, iov_length(iv, count),
33dccbb0 725 file->f_flags & O_NONBLOCK);
631ab46b
EB
726
727 tun_put(tun);
728 return result;
1da177e4
LT
729}
730
1da177e4
LT
731/* Put packet to the user space buffer */
732static __inline__ ssize_t tun_put_user(struct tun_struct *tun,
733 struct sk_buff *skb,
43b39dcd 734 const struct iovec *iv, int len)
1da177e4
LT
735{
736 struct tun_pi pi = { 0, skb->protocol };
737 ssize_t total = 0;
738
739 if (!(tun->flags & TUN_NO_PI)) {
740 if ((len -= sizeof(pi)) < 0)
741 return -EINVAL;
742
743 if (len < skb->len) {
744 /* Packet will be striped */
745 pi.flags |= TUN_PKT_STRIP;
746 }
6aa20a22 747
43b39dcd 748 if (memcpy_toiovecend(iv, (void *) &pi, 0, sizeof(pi)))
1da177e4
LT
749 return -EFAULT;
750 total += sizeof(pi);
6aa20a22 751 }
1da177e4 752
f43798c2
RR
753 if (tun->flags & TUN_VNET_HDR) {
754 struct virtio_net_hdr gso = { 0 }; /* no info leak */
d9d52b51 755 if ((len -= tun->vnet_hdr_sz) < 0)
f43798c2
RR
756 return -EINVAL;
757
758 if (skb_is_gso(skb)) {
759 struct skb_shared_info *sinfo = skb_shinfo(skb);
760
761 /* This is a hint as to how much should be linear. */
762 gso.hdr_len = skb_headlen(skb);
763 gso.gso_size = sinfo->gso_size;
764 if (sinfo->gso_type & SKB_GSO_TCPV4)
765 gso.gso_type = VIRTIO_NET_HDR_GSO_TCPV4;
766 else if (sinfo->gso_type & SKB_GSO_TCPV6)
767 gso.gso_type = VIRTIO_NET_HDR_GSO_TCPV6;
e36aa25a
SS
768 else if (sinfo->gso_type & SKB_GSO_UDP)
769 gso.gso_type = VIRTIO_NET_HDR_GSO_UDP;
ef3db4a5 770 else {
6b8a66ee 771 pr_err("unexpected GSO type: "
ef3db4a5
MT
772 "0x%x, gso_size %d, hdr_len %d\n",
773 sinfo->gso_type, gso.gso_size,
774 gso.hdr_len);
775 print_hex_dump(KERN_ERR, "tun: ",
776 DUMP_PREFIX_NONE,
777 16, 1, skb->head,
778 min((int)gso.hdr_len, 64), true);
779 WARN_ON_ONCE(1);
780 return -EINVAL;
781 }
f43798c2
RR
782 if (sinfo->gso_type & SKB_GSO_TCP_ECN)
783 gso.gso_type |= VIRTIO_NET_HDR_GSO_ECN;
784 } else
785 gso.gso_type = VIRTIO_NET_HDR_GSO_NONE;
786
787 if (skb->ip_summed == CHECKSUM_PARTIAL) {
788 gso.flags = VIRTIO_NET_HDR_F_NEEDS_CSUM;
55508d60 789 gso.csum_start = skb_checksum_start_offset(skb);
f43798c2
RR
790 gso.csum_offset = skb->csum_offset;
791 } /* else everything is zero */
792
43b39dcd
MT
793 if (unlikely(memcpy_toiovecend(iv, (void *)&gso, total,
794 sizeof(gso))))
f43798c2 795 return -EFAULT;
d9d52b51 796 total += tun->vnet_hdr_sz;
f43798c2
RR
797 }
798
1da177e4
LT
799 len = min_t(int, skb->len, len);
800
43b39dcd 801 skb_copy_datagram_const_iovec(skb, 0, iv, total, len);
05c2828c 802 total += skb->len;
1da177e4 803
09f75cd7
JG
804 tun->dev->stats.tx_packets++;
805 tun->dev->stats.tx_bytes += len;
1da177e4
LT
806
807 return total;
808}
809
05c2828c
MT
810static ssize_t tun_do_read(struct tun_struct *tun,
811 struct kiocb *iocb, const struct iovec *iv,
812 ssize_t len, int noblock)
1da177e4 813{
1da177e4
LT
814 DECLARE_WAITQUEUE(wait, current);
815 struct sk_buff *skb;
05c2828c 816 ssize_t ret = 0;
1da177e4 817
6b8a66ee 818 tun_debug(KERN_INFO, tun, "tun_chr_read\n");
1da177e4 819
43815482 820 add_wait_queue(&tun->wq.wait, &wait);
1da177e4 821 while (len) {
1da177e4
LT
822 current->state = TASK_INTERRUPTIBLE;
823
824 /* Read frames from the queue */
89f56d1e 825 if (!(skb=skb_dequeue(&tun->socket.sk->sk_receive_queue))) {
05c2828c 826 if (noblock) {
1da177e4
LT
827 ret = -EAGAIN;
828 break;
829 }
830 if (signal_pending(current)) {
831 ret = -ERESTARTSYS;
832 break;
833 }
c70f1829
EB
834 if (tun->dev->reg_state != NETREG_REGISTERED) {
835 ret = -EIO;
836 break;
837 }
1da177e4
LT
838
839 /* Nothing to read, let's sleep */
840 schedule();
841 continue;
842 }
843 netif_wake_queue(tun->dev);
844
43b39dcd 845 ret = tun_put_user(tun, skb, iv, len);
f271b2cc
MK
846 kfree_skb(skb);
847 break;
1da177e4
LT
848 }
849
850 current->state = TASK_RUNNING;
43815482 851 remove_wait_queue(&tun->wq.wait, &wait);
1da177e4 852
05c2828c
MT
853 return ret;
854}
855
856static ssize_t tun_chr_aio_read(struct kiocb *iocb, const struct iovec *iv,
857 unsigned long count, loff_t pos)
858{
859 struct file *file = iocb->ki_filp;
860 struct tun_file *tfile = file->private_data;
861 struct tun_struct *tun = __tun_get(tfile);
862 ssize_t len, ret;
863
864 if (!tun)
865 return -EBADFD;
866 len = iov_length(iv, count);
867 if (len < 0) {
868 ret = -EINVAL;
869 goto out;
870 }
871
872 ret = tun_do_read(tun, iocb, iv, len, file->f_flags & O_NONBLOCK);
873 ret = min_t(ssize_t, ret, len);
631ab46b
EB
874out:
875 tun_put(tun);
1da177e4
LT
876 return ret;
877}
878
1da177e4
LT
879static void tun_setup(struct net_device *dev)
880{
881 struct tun_struct *tun = netdev_priv(dev);
882
1da177e4 883 tun->owner = -1;
8c644623 884 tun->group = -1;
1da177e4 885
1da177e4 886 dev->ethtool_ops = &tun_ethtool_ops;
9c3fea6a 887 dev->destructor = tun_free_netdev;
1da177e4
LT
888}
889
f019a7a5
EB
890/* Trivial set of netlink ops to allow deleting tun or tap
891 * device with netlink.
892 */
893static int tun_validate(struct nlattr *tb[], struct nlattr *data[])
894{
895 return -EINVAL;
896}
897
898static struct rtnl_link_ops tun_link_ops __read_mostly = {
899 .kind = DRV_NAME,
900 .priv_size = sizeof(struct tun_struct),
901 .setup = tun_setup,
902 .validate = tun_validate,
903};
904
33dccbb0
HX
905static void tun_sock_write_space(struct sock *sk)
906{
907 struct tun_struct *tun;
43815482 908 wait_queue_head_t *wqueue;
33dccbb0
HX
909
910 if (!sock_writeable(sk))
911 return;
912
33dccbb0
HX
913 if (!test_and_clear_bit(SOCK_ASYNC_NOSPACE, &sk->sk_socket->flags))
914 return;
915
43815482
ED
916 wqueue = sk_sleep(sk);
917 if (wqueue && waitqueue_active(wqueue))
918 wake_up_interruptible_sync_poll(wqueue, POLLOUT |
05c2828c 919 POLLWRNORM | POLLWRBAND);
c722c625 920
80924e5f 921 tun = tun_sk(sk)->tun;
33dccbb0
HX
922 kill_fasync(&tun->fasync, SIGIO, POLL_OUT);
923}
924
925static void tun_sock_destruct(struct sock *sk)
926{
80924e5f 927 free_netdev(tun_sk(sk)->tun->dev);
33dccbb0
HX
928}
929
05c2828c
MT
930static int tun_sendmsg(struct kiocb *iocb, struct socket *sock,
931 struct msghdr *m, size_t total_len)
932{
933 struct tun_struct *tun = container_of(sock, struct tun_struct, socket);
934 return tun_get_user(tun, m->msg_iov, total_len,
935 m->msg_flags & MSG_DONTWAIT);
936}
937
938static int tun_recvmsg(struct kiocb *iocb, struct socket *sock,
939 struct msghdr *m, size_t total_len,
940 int flags)
941{
942 struct tun_struct *tun = container_of(sock, struct tun_struct, socket);
943 int ret;
944 if (flags & ~(MSG_DONTWAIT|MSG_TRUNC))
945 return -EINVAL;
946 ret = tun_do_read(tun, iocb, m->msg_iov, total_len,
947 flags & MSG_DONTWAIT);
948 if (ret > total_len) {
949 m->msg_flags |= MSG_TRUNC;
950 ret = flags & MSG_TRUNC ? ret : total_len;
951 }
952 return ret;
953}
954
955/* Ops structure to mimic raw sockets with tun */
956static const struct proto_ops tun_socket_ops = {
957 .sendmsg = tun_sendmsg,
958 .recvmsg = tun_recvmsg,
959};
960
33dccbb0
HX
961static struct proto tun_proto = {
962 .name = "tun",
963 .owner = THIS_MODULE,
964 .obj_size = sizeof(struct tun_sock),
965};
f019a7a5 966
980c9e8c
DW
967static int tun_flags(struct tun_struct *tun)
968{
969 int flags = 0;
970
971 if (tun->flags & TUN_TUN_DEV)
972 flags |= IFF_TUN;
973 else
974 flags |= IFF_TAP;
975
976 if (tun->flags & TUN_NO_PI)
977 flags |= IFF_NO_PI;
978
979 if (tun->flags & TUN_ONE_QUEUE)
980 flags |= IFF_ONE_QUEUE;
981
982 if (tun->flags & TUN_VNET_HDR)
983 flags |= IFF_VNET_HDR;
984
985 return flags;
986}
987
988static ssize_t tun_show_flags(struct device *dev, struct device_attribute *attr,
989 char *buf)
990{
991 struct tun_struct *tun = netdev_priv(to_net_dev(dev));
992 return sprintf(buf, "0x%x\n", tun_flags(tun));
993}
994
995static ssize_t tun_show_owner(struct device *dev, struct device_attribute *attr,
996 char *buf)
997{
998 struct tun_struct *tun = netdev_priv(to_net_dev(dev));
999 return sprintf(buf, "%d\n", tun->owner);
1000}
1001
1002static ssize_t tun_show_group(struct device *dev, struct device_attribute *attr,
1003 char *buf)
1004{
1005 struct tun_struct *tun = netdev_priv(to_net_dev(dev));
1006 return sprintf(buf, "%d\n", tun->group);
1007}
1008
1009static DEVICE_ATTR(tun_flags, 0444, tun_show_flags, NULL);
1010static DEVICE_ATTR(owner, 0444, tun_show_owner, NULL);
1011static DEVICE_ATTR(group, 0444, tun_show_group, NULL);
1012
d647a591 1013static int tun_set_iff(struct net *net, struct file *file, struct ifreq *ifr)
1da177e4 1014{
33dccbb0 1015 struct sock *sk;
1da177e4
LT
1016 struct tun_struct *tun;
1017 struct net_device *dev;
1018 int err;
1019
74a3e5a7
EB
1020 dev = __dev_get_by_name(net, ifr->ifr_name);
1021 if (dev) {
2b980dbd
PM
1022 const struct cred *cred = current_cred();
1023
f85ba780
DW
1024 if (ifr->ifr_flags & IFF_TUN_EXCL)
1025 return -EBUSY;
74a3e5a7
EB
1026 if ((ifr->ifr_flags & IFF_TUN) && dev->netdev_ops == &tun_netdev_ops)
1027 tun = netdev_priv(dev);
1028 else if ((ifr->ifr_flags & IFF_TAP) && dev->netdev_ops == &tap_netdev_ops)
1029 tun = netdev_priv(dev);
1030 else
1031 return -EINVAL;
1032
2b980dbd
PM
1033 if (((tun->owner != -1 && cred->euid != tun->owner) ||
1034 (tun->group != -1 && !in_egroup_p(tun->group))) &&
1035 !capable(CAP_NET_ADMIN))
1036 return -EPERM;
d7e9660a 1037 err = security_tun_dev_attach(tun->socket.sk);
2b980dbd
PM
1038 if (err < 0)
1039 return err;
1040
a7385ba2
EB
1041 err = tun_attach(tun, file);
1042 if (err < 0)
1043 return err;
6aa20a22 1044 }
1da177e4
LT
1045 else {
1046 char *name;
1047 unsigned long flags = 0;
1048
ca6bb5d7
DW
1049 if (!capable(CAP_NET_ADMIN))
1050 return -EPERM;
2b980dbd
PM
1051 err = security_tun_dev_create();
1052 if (err < 0)
1053 return err;
ca6bb5d7 1054
1da177e4
LT
1055 /* Set dev type */
1056 if (ifr->ifr_flags & IFF_TUN) {
1057 /* TUN device */
1058 flags |= TUN_TUN_DEV;
1059 name = "tun%d";
1060 } else if (ifr->ifr_flags & IFF_TAP) {
1061 /* TAP device */
1062 flags |= TUN_TAP_DEV;
1063 name = "tap%d";
6aa20a22 1064 } else
36989b90 1065 return -EINVAL;
6aa20a22 1066
1da177e4
LT
1067 if (*ifr->ifr_name)
1068 name = ifr->ifr_name;
1069
1070 dev = alloc_netdev(sizeof(struct tun_struct), name,
1071 tun_setup);
1072 if (!dev)
1073 return -ENOMEM;
1074
fc54c658 1075 dev_net_set(dev, net);
f019a7a5 1076 dev->rtnl_link_ops = &tun_link_ops;
758e43b7 1077
1da177e4
LT
1078 tun = netdev_priv(dev);
1079 tun->dev = dev;
1080 tun->flags = flags;
f271b2cc 1081 tun->txflt.count = 0;
d9d52b51 1082 tun->vnet_hdr_sz = sizeof(struct virtio_net_hdr);
1da177e4 1083
33dccbb0
HX
1084 err = -ENOMEM;
1085 sk = sk_alloc(net, AF_UNSPEC, GFP_KERNEL, &tun_proto);
1086 if (!sk)
1087 goto err_free_dev;
1088
43815482
ED
1089 tun->socket.wq = &tun->wq;
1090 init_waitqueue_head(&tun->wq.wait);
05c2828c 1091 tun->socket.ops = &tun_socket_ops;
33dccbb0
HX
1092 sock_init_data(&tun->socket, sk);
1093 sk->sk_write_space = tun_sock_write_space;
33dccbb0 1094 sk->sk_sndbuf = INT_MAX;
33dccbb0 1095
80924e5f 1096 tun_sk(sk)->tun = tun;
33dccbb0 1097
2b980dbd
PM
1098 security_tun_dev_post_create(sk);
1099
1da177e4
LT
1100 tun_net_init(dev);
1101
88255375
MM
1102 dev->hw_features = NETIF_F_SG | NETIF_F_FRAGLIST |
1103 TUN_USER_FEATURES;
1104 dev->features = dev->hw_features;
1105
1da177e4
LT
1106 err = register_netdevice(tun->dev);
1107 if (err < 0)
9c3fea6a
HX
1108 goto err_free_sk;
1109
980c9e8c
DW
1110 if (device_create_file(&tun->dev->dev, &dev_attr_tun_flags) ||
1111 device_create_file(&tun->dev->dev, &dev_attr_owner) ||
1112 device_create_file(&tun->dev->dev, &dev_attr_group))
6b8a66ee 1113 pr_err("Failed to create tun sysfs files\n");
980c9e8c 1114
9c3fea6a 1115 sk->sk_destruct = tun_sock_destruct;
a7385ba2
EB
1116
1117 err = tun_attach(tun, file);
1118 if (err < 0)
9c3fea6a 1119 goto failed;
1da177e4
LT
1120 }
1121
6b8a66ee 1122 tun_debug(KERN_INFO, tun, "tun_set_iff\n");
1da177e4
LT
1123
1124 if (ifr->ifr_flags & IFF_NO_PI)
1125 tun->flags |= TUN_NO_PI;
a26af1e0
NF
1126 else
1127 tun->flags &= ~TUN_NO_PI;
1da177e4
LT
1128
1129 if (ifr->ifr_flags & IFF_ONE_QUEUE)
1130 tun->flags |= TUN_ONE_QUEUE;
a26af1e0
NF
1131 else
1132 tun->flags &= ~TUN_ONE_QUEUE;
1da177e4 1133
f43798c2
RR
1134 if (ifr->ifr_flags & IFF_VNET_HDR)
1135 tun->flags |= TUN_VNET_HDR;
1136 else
1137 tun->flags &= ~TUN_VNET_HDR;
1138
e35259a9
MK
1139 /* Make sure persistent devices do not get stuck in
1140 * xoff state.
1141 */
1142 if (netif_running(tun->dev))
1143 netif_wake_queue(tun->dev);
1144
1da177e4
LT
1145 strcpy(ifr->ifr_name, tun->dev->name);
1146 return 0;
1147
33dccbb0
HX
1148 err_free_sk:
1149 sock_put(sk);
1da177e4
LT
1150 err_free_dev:
1151 free_netdev(dev);
1152 failed:
1153 return err;
1154}
1155
876bfd4d
HX
1156static int tun_get_iff(struct net *net, struct tun_struct *tun,
1157 struct ifreq *ifr)
e3b99556 1158{
6b8a66ee 1159 tun_debug(KERN_INFO, tun, "tun_get_iff\n");
e3b99556
MM
1160
1161 strcpy(ifr->ifr_name, tun->dev->name);
1162
980c9e8c 1163 ifr->ifr_flags = tun_flags(tun);
e3b99556
MM
1164
1165 return 0;
1166}
1167
5228ddc9
RR
1168/* This is like a cut-down ethtool ops, except done via tun fd so no
1169 * privs required. */
88255375 1170static int set_offload(struct tun_struct *tun, unsigned long arg)
5228ddc9 1171{
88255375 1172 u32 features = 0;
5228ddc9
RR
1173
1174 if (arg & TUN_F_CSUM) {
88255375 1175 features |= NETIF_F_HW_CSUM;
5228ddc9
RR
1176 arg &= ~TUN_F_CSUM;
1177
1178 if (arg & (TUN_F_TSO4|TUN_F_TSO6)) {
1179 if (arg & TUN_F_TSO_ECN) {
1180 features |= NETIF_F_TSO_ECN;
1181 arg &= ~TUN_F_TSO_ECN;
1182 }
1183 if (arg & TUN_F_TSO4)
1184 features |= NETIF_F_TSO;
1185 if (arg & TUN_F_TSO6)
1186 features |= NETIF_F_TSO6;
1187 arg &= ~(TUN_F_TSO4|TUN_F_TSO6);
1188 }
e36aa25a
SS
1189
1190 if (arg & TUN_F_UFO) {
1191 features |= NETIF_F_UFO;
1192 arg &= ~TUN_F_UFO;
1193 }
5228ddc9
RR
1194 }
1195
1196 /* This gives the user a way to test for new features in future by
1197 * trying to set them. */
1198 if (arg)
1199 return -EINVAL;
1200
88255375
MM
1201 tun->set_features = features;
1202 netdev_update_features(tun->dev);
5228ddc9
RR
1203
1204 return 0;
1205}
1206
50857e2a
AB
1207static long __tun_chr_ioctl(struct file *file, unsigned int cmd,
1208 unsigned long arg, int ifreq_len)
1da177e4 1209{
36b50bab 1210 struct tun_file *tfile = file->private_data;
631ab46b 1211 struct tun_struct *tun;
1da177e4 1212 void __user* argp = (void __user*)arg;
99405162 1213 struct sock_fprog fprog;
1da177e4 1214 struct ifreq ifr;
33dccbb0 1215 int sndbuf;
d9d52b51 1216 int vnet_hdr_sz;
f271b2cc 1217 int ret;
1da177e4
LT
1218
1219 if (cmd == TUNSETIFF || _IOC_TYPE(cmd) == 0x89)
50857e2a 1220 if (copy_from_user(&ifr, argp, ifreq_len))
1da177e4
LT
1221 return -EFAULT;
1222
631ab46b
EB
1223 if (cmd == TUNGETFEATURES) {
1224 /* Currently this just means: "what IFF flags are valid?".
1225 * This is needed because we never checked for invalid flags on
1226 * TUNSETIFF. */
1227 return put_user(IFF_TUN | IFF_TAP | IFF_NO_PI | IFF_ONE_QUEUE |
1228 IFF_VNET_HDR,
1229 (unsigned int __user*)argp);
1230 }
1231
876bfd4d
HX
1232 rtnl_lock();
1233
36b50bab 1234 tun = __tun_get(tfile);
1da177e4 1235 if (cmd == TUNSETIFF && !tun) {
1da177e4
LT
1236 ifr.ifr_name[IFNAMSIZ-1] = '\0';
1237
876bfd4d 1238 ret = tun_set_iff(tfile->net, file, &ifr);
1da177e4 1239
876bfd4d
HX
1240 if (ret)
1241 goto unlock;
1da177e4 1242
50857e2a 1243 if (copy_to_user(argp, &ifr, ifreq_len))
876bfd4d
HX
1244 ret = -EFAULT;
1245 goto unlock;
1da177e4
LT
1246 }
1247
876bfd4d 1248 ret = -EBADFD;
1da177e4 1249 if (!tun)
876bfd4d 1250 goto unlock;
1da177e4 1251
6b8a66ee 1252 tun_debug(KERN_INFO, tun, "tun_chr_ioctl cmd %d\n", cmd);
1da177e4 1253
631ab46b 1254 ret = 0;
1da177e4 1255 switch (cmd) {
e3b99556 1256 case TUNGETIFF:
876bfd4d 1257 ret = tun_get_iff(current->nsproxy->net_ns, tun, &ifr);
e3b99556 1258 if (ret)
631ab46b 1259 break;
e3b99556 1260
50857e2a 1261 if (copy_to_user(argp, &ifr, ifreq_len))
631ab46b 1262 ret = -EFAULT;
e3b99556
MM
1263 break;
1264
1da177e4
LT
1265 case TUNSETNOCSUM:
1266 /* Disable/Enable checksum */
1da177e4 1267
88255375
MM
1268 /* [unimplemented] */
1269 tun_debug(KERN_INFO, tun, "ignored: set checksum %s\n",
6b8a66ee 1270 arg ? "disabled" : "enabled");
1da177e4
LT
1271 break;
1272
1273 case TUNSETPERSIST:
1274 /* Disable/Enable persist mode */
1275 if (arg)
1276 tun->flags |= TUN_PERSIST;
1277 else
1278 tun->flags &= ~TUN_PERSIST;
1279
6b8a66ee
JP
1280 tun_debug(KERN_INFO, tun, "persist %s\n",
1281 arg ? "enabled" : "disabled");
1da177e4
LT
1282 break;
1283
1284 case TUNSETOWNER:
1285 /* Set owner of the device */
1286 tun->owner = (uid_t) arg;
1287
6b8a66ee 1288 tun_debug(KERN_INFO, tun, "owner set to %d\n", tun->owner);
1da177e4
LT
1289 break;
1290
8c644623
GG
1291 case TUNSETGROUP:
1292 /* Set group of the device */
1293 tun->group= (gid_t) arg;
1294
6b8a66ee 1295 tun_debug(KERN_INFO, tun, "group set to %d\n", tun->group);
8c644623
GG
1296 break;
1297
ff4cc3ac
MK
1298 case TUNSETLINK:
1299 /* Only allow setting the type when the interface is down */
1300 if (tun->dev->flags & IFF_UP) {
6b8a66ee
JP
1301 tun_debug(KERN_INFO, tun,
1302 "Linktype set failed because interface is up\n");
48abfe05 1303 ret = -EBUSY;
ff4cc3ac
MK
1304 } else {
1305 tun->dev->type = (int) arg;
6b8a66ee
JP
1306 tun_debug(KERN_INFO, tun, "linktype set to %d\n",
1307 tun->dev->type);
48abfe05 1308 ret = 0;
ff4cc3ac 1309 }
631ab46b 1310 break;
ff4cc3ac 1311
1da177e4
LT
1312#ifdef TUN_DEBUG
1313 case TUNSETDEBUG:
1314 tun->debug = arg;
1315 break;
1316#endif
5228ddc9 1317 case TUNSETOFFLOAD:
88255375 1318 ret = set_offload(tun, arg);
631ab46b 1319 break;
5228ddc9 1320
f271b2cc
MK
1321 case TUNSETTXFILTER:
1322 /* Can be set only for TAPs */
631ab46b 1323 ret = -EINVAL;
f271b2cc 1324 if ((tun->flags & TUN_TYPE_MASK) != TUN_TAP_DEV)
631ab46b 1325 break;
c0e5a8c2 1326 ret = update_filter(&tun->txflt, (void __user *)arg);
631ab46b 1327 break;
1da177e4
LT
1328
1329 case SIOCGIFHWADDR:
b595076a 1330 /* Get hw address */
f271b2cc
MK
1331 memcpy(ifr.ifr_hwaddr.sa_data, tun->dev->dev_addr, ETH_ALEN);
1332 ifr.ifr_hwaddr.sa_family = tun->dev->type;
50857e2a 1333 if (copy_to_user(argp, &ifr, ifreq_len))
631ab46b
EB
1334 ret = -EFAULT;
1335 break;
1da177e4
LT
1336
1337 case SIOCSIFHWADDR:
f271b2cc 1338 /* Set hw address */
6b8a66ee
JP
1339 tun_debug(KERN_DEBUG, tun, "set hw address: %pM\n",
1340 ifr.ifr_hwaddr.sa_data);
40102371 1341
40102371 1342 ret = dev_set_mac_address(tun->dev, &ifr.ifr_hwaddr);
631ab46b 1343 break;
33dccbb0
HX
1344
1345 case TUNGETSNDBUF:
89f56d1e 1346 sndbuf = tun->socket.sk->sk_sndbuf;
33dccbb0
HX
1347 if (copy_to_user(argp, &sndbuf, sizeof(sndbuf)))
1348 ret = -EFAULT;
1349 break;
1350
1351 case TUNSETSNDBUF:
1352 if (copy_from_user(&sndbuf, argp, sizeof(sndbuf))) {
1353 ret = -EFAULT;
1354 break;
1355 }
1356
89f56d1e 1357 tun->socket.sk->sk_sndbuf = sndbuf;
33dccbb0
HX
1358 break;
1359
d9d52b51
MT
1360 case TUNGETVNETHDRSZ:
1361 vnet_hdr_sz = tun->vnet_hdr_sz;
1362 if (copy_to_user(argp, &vnet_hdr_sz, sizeof(vnet_hdr_sz)))
1363 ret = -EFAULT;
1364 break;
1365
1366 case TUNSETVNETHDRSZ:
1367 if (copy_from_user(&vnet_hdr_sz, argp, sizeof(vnet_hdr_sz))) {
1368 ret = -EFAULT;
1369 break;
1370 }
1371 if (vnet_hdr_sz < (int)sizeof(struct virtio_net_hdr)) {
1372 ret = -EINVAL;
1373 break;
1374 }
1375
1376 tun->vnet_hdr_sz = vnet_hdr_sz;
1377 break;
1378
99405162
MT
1379 case TUNATTACHFILTER:
1380 /* Can be set only for TAPs */
1381 ret = -EINVAL;
1382 if ((tun->flags & TUN_TYPE_MASK) != TUN_TAP_DEV)
1383 break;
1384 ret = -EFAULT;
1385 if (copy_from_user(&fprog, argp, sizeof(fprog)))
1386 break;
1387
1388 ret = sk_attach_filter(&fprog, tun->socket.sk);
1389 break;
1390
1391 case TUNDETACHFILTER:
1392 /* Can be set only for TAPs */
1393 ret = -EINVAL;
1394 if ((tun->flags & TUN_TYPE_MASK) != TUN_TAP_DEV)
1395 break;
1396 ret = sk_detach_filter(tun->socket.sk);
1397 break;
1398
1da177e4 1399 default:
631ab46b
EB
1400 ret = -EINVAL;
1401 break;
ee289b64 1402 }
1da177e4 1403
876bfd4d
HX
1404unlock:
1405 rtnl_unlock();
1406 if (tun)
1407 tun_put(tun);
631ab46b 1408 return ret;
1da177e4
LT
1409}
1410
50857e2a
AB
1411static long tun_chr_ioctl(struct file *file,
1412 unsigned int cmd, unsigned long arg)
1413{
1414 return __tun_chr_ioctl(file, cmd, arg, sizeof (struct ifreq));
1415}
1416
1417#ifdef CONFIG_COMPAT
1418static long tun_chr_compat_ioctl(struct file *file,
1419 unsigned int cmd, unsigned long arg)
1420{
1421 switch (cmd) {
1422 case TUNSETIFF:
1423 case TUNGETIFF:
1424 case TUNSETTXFILTER:
1425 case TUNGETSNDBUF:
1426 case TUNSETSNDBUF:
1427 case SIOCGIFHWADDR:
1428 case SIOCSIFHWADDR:
1429 arg = (unsigned long)compat_ptr(arg);
1430 break;
1431 default:
1432 arg = (compat_ulong_t)arg;
1433 break;
1434 }
1435
1436 /*
1437 * compat_ifreq is shorter than ifreq, so we must not access beyond
1438 * the end of that structure. All fields that are used in this
1439 * driver are compatible though, we don't need to convert the
1440 * contents.
1441 */
1442 return __tun_chr_ioctl(file, cmd, arg, sizeof(struct compat_ifreq));
1443}
1444#endif /* CONFIG_COMPAT */
1445
1da177e4
LT
1446static int tun_chr_fasync(int fd, struct file *file, int on)
1447{
631ab46b 1448 struct tun_struct *tun = tun_get(file);
1da177e4
LT
1449 int ret;
1450
1451 if (!tun)
1452 return -EBADFD;
1453
6b8a66ee 1454 tun_debug(KERN_INFO, tun, "tun_chr_fasync %d\n", on);
1da177e4
LT
1455
1456 if ((ret = fasync_helper(fd, file, on, &tun->fasync)) < 0)
9d319522 1457 goto out;
6aa20a22 1458
1da177e4 1459 if (on) {
609d7fa9 1460 ret = __f_setown(file, task_pid(current), PIDTYPE_PID, 0);
1da177e4 1461 if (ret)
9d319522 1462 goto out;
1da177e4 1463 tun->flags |= TUN_FASYNC;
6aa20a22 1464 } else
1da177e4 1465 tun->flags &= ~TUN_FASYNC;
9d319522
JC
1466 ret = 0;
1467out:
631ab46b 1468 tun_put(tun);
9d319522 1469 return ret;
1da177e4
LT
1470}
1471
1472static int tun_chr_open(struct inode *inode, struct file * file)
1473{
631ab46b 1474 struct tun_file *tfile;
deed49fb 1475
6b8a66ee 1476 DBG1(KERN_INFO, "tunX: tun_chr_open\n");
631ab46b
EB
1477
1478 tfile = kmalloc(sizeof(*tfile), GFP_KERNEL);
1479 if (!tfile)
1480 return -ENOMEM;
c70f1829 1481 atomic_set(&tfile->count, 0);
631ab46b 1482 tfile->tun = NULL;
36b50bab 1483 tfile->net = get_net(current->nsproxy->net_ns);
631ab46b 1484 file->private_data = tfile;
1da177e4
LT
1485 return 0;
1486}
1487
1488static int tun_chr_close(struct inode *inode, struct file *file)
1489{
631ab46b 1490 struct tun_file *tfile = file->private_data;
f0a4d0e5 1491 struct tun_struct *tun;
1da177e4 1492
f0a4d0e5 1493 tun = __tun_get(tfile);
631ab46b 1494 if (tun) {
d23e4365
HX
1495 struct net_device *dev = tun->dev;
1496
6b8a66ee 1497 tun_debug(KERN_INFO, tun, "tun_chr_close\n");
1da177e4 1498
631ab46b 1499 __tun_detach(tun);
1da177e4 1500
3ad2f3fb 1501 /* If desirable, unregister the netdevice. */
d23e4365
HX
1502 if (!(tun->flags & TUN_PERSIST)) {
1503 rtnl_lock();
1504 if (dev->reg_state == NETREG_REGISTERED)
1505 unregister_netdevice(dev);
1506 rtnl_unlock();
1507 }
631ab46b 1508 }
1da177e4 1509
9c3fea6a
HX
1510 tun = tfile->tun;
1511 if (tun)
89f56d1e 1512 sock_put(tun->socket.sk);
9c3fea6a 1513
36b50bab 1514 put_net(tfile->net);
631ab46b 1515 kfree(tfile);
1da177e4
LT
1516
1517 return 0;
1518}
1519
d54b1fdb 1520static const struct file_operations tun_fops = {
6aa20a22 1521 .owner = THIS_MODULE,
1da177e4 1522 .llseek = no_llseek,
ee0b3e67
BP
1523 .read = do_sync_read,
1524 .aio_read = tun_chr_aio_read,
1525 .write = do_sync_write,
1526 .aio_write = tun_chr_aio_write,
1da177e4 1527 .poll = tun_chr_poll,
50857e2a
AB
1528 .unlocked_ioctl = tun_chr_ioctl,
1529#ifdef CONFIG_COMPAT
1530 .compat_ioctl = tun_chr_compat_ioctl,
1531#endif
1da177e4
LT
1532 .open = tun_chr_open,
1533 .release = tun_chr_close,
6aa20a22 1534 .fasync = tun_chr_fasync
1da177e4
LT
1535};
1536
1537static struct miscdevice tun_miscdev = {
1538 .minor = TUN_MINOR,
1539 .name = "tun",
e454cea2 1540 .nodename = "net/tun",
1da177e4 1541 .fops = &tun_fops,
1da177e4
LT
1542};
1543
1544/* ethtool interface */
1545
1546static int tun_get_settings(struct net_device *dev, struct ethtool_cmd *cmd)
1547{
1548 cmd->supported = 0;
1549 cmd->advertising = 0;
70739497 1550 ethtool_cmd_speed_set(cmd, SPEED_10);
1da177e4
LT
1551 cmd->duplex = DUPLEX_FULL;
1552 cmd->port = PORT_TP;
1553 cmd->phy_address = 0;
1554 cmd->transceiver = XCVR_INTERNAL;
1555 cmd->autoneg = AUTONEG_DISABLE;
1556 cmd->maxtxpkt = 0;
1557 cmd->maxrxpkt = 0;
1558 return 0;
1559}
1560
1561static void tun_get_drvinfo(struct net_device *dev, struct ethtool_drvinfo *info)
1562{
1563 struct tun_struct *tun = netdev_priv(dev);
1564
1565 strcpy(info->driver, DRV_NAME);
1566 strcpy(info->version, DRV_VERSION);
1567 strcpy(info->fw_version, "N/A");
1568
1569 switch (tun->flags & TUN_TYPE_MASK) {
1570 case TUN_TUN_DEV:
1571 strcpy(info->bus_info, "tun");
1572 break;
1573 case TUN_TAP_DEV:
1574 strcpy(info->bus_info, "tap");
1575 break;
1576 }
1577}
1578
1579static u32 tun_get_msglevel(struct net_device *dev)
1580{
1581#ifdef TUN_DEBUG
1582 struct tun_struct *tun = netdev_priv(dev);
1583 return tun->debug;
1584#else
1585 return -EOPNOTSUPP;
1586#endif
1587}
1588
1589static void tun_set_msglevel(struct net_device *dev, u32 value)
1590{
1591#ifdef TUN_DEBUG
1592 struct tun_struct *tun = netdev_priv(dev);
1593 tun->debug = value;
1594#endif
1595}
1596
7282d491 1597static const struct ethtool_ops tun_ethtool_ops = {
1da177e4
LT
1598 .get_settings = tun_get_settings,
1599 .get_drvinfo = tun_get_drvinfo,
1600 .get_msglevel = tun_get_msglevel,
1601 .set_msglevel = tun_set_msglevel,
bee31369 1602 .get_link = ethtool_op_get_link,
1da177e4
LT
1603};
1604
79d17604 1605
1da177e4
LT
1606static int __init tun_init(void)
1607{
1608 int ret = 0;
1609
6b8a66ee
JP
1610 pr_info("%s, %s\n", DRV_DESCRIPTION, DRV_VERSION);
1611 pr_info("%s\n", DRV_COPYRIGHT);
1da177e4 1612
f019a7a5 1613 ret = rtnl_link_register(&tun_link_ops);
79d17604 1614 if (ret) {
6b8a66ee 1615 pr_err("Can't register link_ops\n");
f019a7a5 1616 goto err_linkops;
79d17604
PE
1617 }
1618
1da177e4 1619 ret = misc_register(&tun_miscdev);
79d17604 1620 if (ret) {
6b8a66ee 1621 pr_err("Can't register misc device %d\n", TUN_MINOR);
79d17604
PE
1622 goto err_misc;
1623 }
f019a7a5 1624 return 0;
79d17604 1625err_misc:
f019a7a5
EB
1626 rtnl_link_unregister(&tun_link_ops);
1627err_linkops:
1da177e4
LT
1628 return ret;
1629}
1630
1631static void tun_cleanup(void)
1632{
6aa20a22 1633 misc_deregister(&tun_miscdev);
f019a7a5 1634 rtnl_link_unregister(&tun_link_ops);
1da177e4
LT
1635}
1636
05c2828c
MT
1637/* Get an underlying socket object from tun file. Returns error unless file is
1638 * attached to a device. The returned object works like a packet socket, it
1639 * can be used for sock_sendmsg/sock_recvmsg. The caller is responsible for
1640 * holding a reference to the file for as long as the socket is in use. */
1641struct socket *tun_get_socket(struct file *file)
1642{
1643 struct tun_struct *tun;
1644 if (file->f_op != &tun_fops)
1645 return ERR_PTR(-EINVAL);
1646 tun = tun_get(file);
1647 if (!tun)
1648 return ERR_PTR(-EBADFD);
1649 tun_put(tun);
1650 return &tun->socket;
1651}
1652EXPORT_SYMBOL_GPL(tun_get_socket);
1653
1da177e4
LT
1654module_init(tun_init);
1655module_exit(tun_cleanup);
1656MODULE_DESCRIPTION(DRV_DESCRIPTION);
1657MODULE_AUTHOR(DRV_COPYRIGHT);
1658MODULE_LICENSE("GPL");
1659MODULE_ALIAS_MISCDEV(TUN_MINOR);
578454ff 1660MODULE_ALIAS("devname:net/tun");